diff --git a/test_data/macOS/2023.3CX/libffmpeg.dirty.mdiff b/test_data/macOS/2023.3CX/libffmpeg.dirty.mdiff index 154628aa2..95f6e82bd 100644 Binary files a/test_data/macOS/2023.3CX/libffmpeg.dirty.mdiff and b/test_data/macOS/2023.3CX/libffmpeg.dirty.mdiff differ diff --git a/third_party/yara/YARAForge/RELEASE b/third_party/yara/YARAForge/RELEASE index 444c7cbae..42eedaf32 100644 --- a/third_party/yara/YARAForge/RELEASE +++ b/third_party/yara/YARAForge/RELEASE @@ -1 +1 @@ -20240804 +20240901 diff --git a/third_party/yara/YARAForge/yara-rules-full.yar b/third_party/yara/YARAForge/yara-rules-full.yar index f5874be39..b76f61d32 100644 --- a/third_party/yara/YARAForge/yara-rules-full.yar +++ b/third_party/yara/YARAForge/yara-rules-full.yar @@ -5,24 +5,24 @@ * Rule Package Information * Name: full * Description: Default YARA Rule Package - Full - * YARA-Forge Version: 0.8.1 + * YARA-Forge Version: 0.9.0 * YARA-QA Commit: 6d0cfc3b5356c3a58f79d98077ad505e4493785c * Minimum Quality: 20 * Force Include Importance Level: 50 * Force Exclude Importance Level: 0 * Minimum Age (in days): 0 * Minimum Score: 40 - * Creation Date: 2024-08-04 - * Number of Rules: 11793 - * Skipped: 0 (age), 234 (quality), 4 (score), 0 (importance) + * Creation Date: 2024-09-01 + * Number of Rules: 12046 + * Skipped: 0 (age), 223 (quality), 4 (score), 0 (importance) */ /* * YARA Rule Set * Repository Name: ReversingLabs * Repository: https://github.com/reversinglabs/reversinglabs-yara-rules/ - * Retrieval Date: 2024-08-04 - * Git Commit: fb48728b76c37152bb200afb51847f82f75c50c7 - * Number of Rules: 1210 + * Retrieval Date: 2024-09-01 + * Git Commit: 5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0 + * Number of Rules: 1212 * Skipped: 0 (age), 0 (quality), 0 (score), 0 (importance) * * @@ -48,6 +48,477 @@ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. */ +import "elf" + +rule REVERSINGLABS_Linux_Virus_Vit : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Vit virus." + author = "ReversingLabs" + id = "4515fe43-4c5a-521d-82b7-273823f0c64e" + date = "2024-09-01" + date = "2024-09-01" + modified = "2023-06-07" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/virus/Linux.Virus.Vit.yara#L3-L36" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "2fba7a081dfca85aee5c7f3b33414b799ed52ca6aa5bbf031da040aaa75acde9" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Virus" + tc_detection_factor = 5 + importance = 25 + + strings: + $vit_entry_point = { + 55 89 E5 81 EC 40 31 00 00 57 56 50 53 51 52 C7 85 D8 CE FF FF 00 00 00 00 C7 85 D4 + CE FF FF 00 00 00 00 C7 85 FC CF FF FF CA 08 00 00 C7 85 F8 CF FF FF B8 06 00 00 C7 + 85 F4 CF FF FF AD 08 00 00 C7 85 F0 CF FF FF 50 06 00 00 6A 00 6A 00 8B 45 08 50 E8 + 18 FA FF FF 89 C6 83 C4 0C 85 F6 0F 8C E6 01 00 00 6A 00 68 ?? ?? ?? ?? 56 E8 2E FA + FF FF 83 C4 0C 85 C0 0F 8C C4 01 00 00 8B 85 FC CF FF FF 50 8D 85 00 D0 FF FF 50 56 + E8 2A FA FF FF 89 C2 8B 85 FC CF FF FF 83 C4 0C 39 C2 0F 85 9D 01 00 00 56 E8 E1 F9 + FF FF BE FF FF FF FF 6A 00 6A 00 E9 + } + $vit_str = "vi324.tmp" + + condition: + uint32(0)==0x464C457F and $vit_entry_point at elf.entry_point and $vit_str +} +import "pe" + +rule REVERSINGLABS_Win32_Virus_Cmay : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Cmay virus." + author = "ReversingLabs" + id = "d61e09f1-1d3f-5e1e-9884-25f1a465e88d" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/virus/Win32.Virus.Cmay.yara#L3-L73" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "f3bdf772eb80c632a913621732d12ae4a02bc7d3ba41f51711aa329be2ca6220" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Virus" + tc_detection_name = "Cmay" + tc_detection_factor = 5 + importance = 25 + + strings: + $cmay_body_1 = { + 60 66 9C E8 00 00 00 00 5D 8B C5 81 ED ?? ?? ?? ?? 2D 08 00 00 00 2D + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 3A 02 00 00 0F 82 7C 03 00 00 8D B5 + ?? ?? ?? ?? 8D BD ?? ?? ?? ?? E8 4F 02 00 00 E8 05 00 00 00 E9 61 03 + 00 00 8D BD ?? ?? ?? ?? C6 85 ?? ?? ?? ?? 03 6A 7F 57 FF 95 ?? ?? ?? + ?? 83 C7 7F 6A 7F 57 FF 95 ?? ?? ?? ?? 83 C7 7F 57 6A 7F FF 95 ?? ?? + ?? ?? 8D BD ?? ?? ?? ?? 80 BD ?? ?? ?? ?? 00 0F 84 20 03 00 00 FE 8D + ?? ?? ?? ?? 57 FF 95 ?? ?? ?? ?? 83 C7 7F 8D 9D ?? ?? ?? ?? 53 8D 9D + ?? ?? ?? ?? 53 FF 95 ?? ?? ?? ?? 83 F8 FF 74 CA 89 85 ?? ?? ?? ?? FF + 85 ?? ?? ?? ?? E8 C0 02 00 00 83 F8 FF 74 75 E8 70 02 00 00 85 C0 74 + 6C 8B 85 ?? ?? ?? ?? 8B 50 3C 3B 95 ?? ?? ?? ?? 73 5B 03 D0 8B 02 35 + 96 23 00 00 3D C6 66 00 00 75 4B 81 7A 4C 53 54 30 00 74 42 52 FF B5 + ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 5A FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? + E8 79 00 00 00 8F 85 ?? ?? ?? ?? 8F 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? + 05 7E 0E 80 BD ?? ?? ?? ?? 00 0F 85 40 FF FF FF C3 57 8D BD ?? ?? ?? + ?? B9 04 01 00 00 32 C0 F3 AA 5F FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? + FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? + ?? 8D 9D ?? ?? ?? ?? 53 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 85 C0 74 + 05 E9 2A FF FF FF E9 E9 FE FF FF 8B B5 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? + 8B 5A 3C E8 87 01 00 00 89 B5 ?? ?? ?? ?? E8 8B 01 00 00 33 DB 8B 95 + ?? ?? ?? ?? 8B 42 3C 03 D0 0F B7 42 06 48 6B C0 28 0F B7 5A 14 83 C3 + 18 03 DA 03 C3 8B 58 10 03 58 14 03 9D ?? ?? ?? ?? 53 8B 4A 28 89 8D + ?? ?? ?? ?? 8B 4A 34 89 8D ?? ?? ?? ?? 8B 48 0C 03 48 10 89 8D ?? ?? + ?? ?? 89 4A 28 8B 70 10 81 C6 ?? ?? ?? ?? 8B 5A 3C E8 1D 01 00 00 89 + 70 10 89 70 08 03 70 0C 89 72 50 81 48 24 20 00 00 A0 C7 42 4C 53 54 + } + $cmay_body_2 = { + 30 00 5B B9 ?? ?? ?? ?? FC 8B FB 8D B5 ?? ?? ?? ?? F3 A4 FF B5 ?? ?? + ?? ?? FF 95 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? FF 95 ?? ?? ?? ?? C3 50 51 B9 05 00 00 00 8B 44 24 2E 25 00 + 00 FF FF 66 81 38 4D 5A 74 09 2D 00 00 01 00 E2 F2 EB 06 89 85 ?? ?? + ?? ?? 59 58 74 01 F9 C3 56 8B 95 ?? ?? ?? ?? 8B 72 3C 03 F2 8B 76 78 + 03 F2 83 C6 1C AD 03 C2 89 85 ?? ?? ?? ?? AD 03 C2 89 85 ?? ?? ?? ?? + AD 03 C2 89 85 ?? ?? ?? ?? 5E 57 E8 16 00 00 00 5F 89 07 83 C7 04 80 + 3E 88 C7 85 ?? ?? ?? ?? 00 00 00 00 75 E5 C3 8B DE 80 3E 00 74 03 46 + EB F8 46 8B CE 2B CB 8B F3 8B BD ?? ?? ?? ?? 57 8B 3F 03 FA 51 F3 A6 + 74 0F 8B F3 59 5F 83 C7 04 FF 85 ?? ?? ?? ?? EB E7 59 5F 8B 85 ?? ?? + ?? ?? D1 E0 03 85 ?? ?? ?? ?? 33 DB 66 8B 18 C1 E3 02 03 9D ?? ?? ?? + ?? 8B 1B 03 DA 8B C3 C3 50 52 33 D2 8B C6 F7 F3 2B DA 03 F3 5A 58 C3 + 8B 85 ?? ?? ?? ?? 6A 00 50 6A 00 6A 04 6A 00 FF B5 ?? ?? ?? ?? FF 95 + ?? ?? ?? ?? 85 C0 74 1E 89 85 ?? ?? ?? ?? 6A 00 6A 00 6A 00 6A 02 FF + B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 85 C0 75 02 33 C0 89 85 ?? ?? ?? ?? + C3 33 C0 50 68 80 00 00 00 6A 03 50 40 50 68 00 00 00 C0 8D B5 ?? ?? + ?? ?? 56 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C3 85 ED 0F 84 2A 04 00 + 00 33 C0 05 ?? ?? ?? ?? 05 ?? ?? ?? ?? FF E0 + } + + condition: + uint16(0)==0x5A4D and ($cmay_body_1 at pe.entry_point) and $cmay_body_2 +} +import "pe" + +rule REVERSINGLABS_Win32_Virus_Deadcode : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects DeadCode virus." + author = "ReversingLabs" + id = "89ec2e39-a163-5ba6-9b19-9c94b1923d47" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/virus/Win32.Virus.DeadCode.yara#L3-L76" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6ac2e48daaed222f0a19afd4d03a02834705e0e3762db3217f68569554171846" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Virus" + tc_detection_name = "DeadCode" + tc_detection_factor = 5 + importance = 25 + + strings: + $deadcode_ep_1 = { + 64 67 FF 36 30 00 58 8B 40 08 FF 70 48 5B FF 70 4C 5A 03 40 44 + FF E0 + } + $deadcode_marker = { + DE C0 AD DE + } + $deadcode_ep_2 = { + 2B C0 85 C0 74 0E 64 67 FF 36 00 00 64 67 89 26 00 00 89 00 E8 + ED FF FF FF 8B 74 24 0C 64 67 A1 30 00 8B 40 08 8B 58 48 8B 50 + 4C 03 40 44 89 86 B8 00 00 00 89 86 B0 00 00 00 89 9E A4 00 00 + 00 89 96 A8 00 00 00 2B C0 C3 + } + $deadcode_ep_3 = { + B8 DE C0 AD DE 50 5A 64 67 A1 30 00 8B 40 08 8B 58 48 8B 50 4C + 03 40 44 FF D0 + } + $deadcode_body_1 = { + 8B D0 8B EA 81 C5 ?? ?? ?? ?? 89 85 A4 00 00 00 89 9D C0 00 00 00 E8 56 01 00 00 89 + 45 00 8D 75 04 81 C2 ?? ?? ?? ?? 6A 19 FF 75 00 52 56 E8 CE 01 00 00 64 67 A1 30 00 + 8B 40 08 89 85 88 00 00 00 C7 85 D0 00 00 00 ?? ?? ?? ?? E8 09 00 00 00 8B 64 24 08 + E9 03 01 00 00 33 D2 64 FF 32 64 89 22 83 BD C0 00 00 00 00 75 2F 6A 04 68 00 10 00 + 00 68 40 01 00 00 6A 00 FF 55 08 50 8F 45 78 E8 2A 03 00 00 68 00 40 00 00 68 40 01 + 00 00 FF 75 78 FF 55 28 E9 C3 00 00 00 8B 85 A4 00 00 00 05 ?? ?? ?? ?? 8D B5 B4 00 + 00 00 56 6A 00 55 50 68 00 00 10 00 6A 00 FF 55 30 89 85 AC 00 00 00 6A 04 68 00 10 + 00 00 6A 54 6A 00 FF 55 08 89 85 A8 00 00 00 64 67 A1 30 00 8B 40 10 8B 40 3C 8B B5 + A8 00 00 00 8D 7E 10 56 57 6A 00 6A 00 6A 04 6A 01 6A 00 6A 00 50 6A 00 FF 55 50 85 + C0 74 5D FF 76 04 8F 85 B0 00 00 00 64 67 A1 30 00 8B 40 08 8B D8 03 5B 3C 8B 5B 28 + 03 D8 8B 8D A4 00 00 00 81 ?? ?? ?? ?? 8D 85 B4 00 00 00 50 6A ?? 51 53 FF 36 FF 55 + 4C FF 76 04 FF 55 54 8D B5 AC 00 00 00 6A FF 6A 01 56 6A 02 FF 55 34 68 00 40 00 00 + 6A 54 FF B5 A8 00 00 00 FF 55 28 33 D2 64 8F 02 5A E8 DB 01 00 00 E8 F5 00 00 00 6A + 00 FF 55 3C 64 67 8B 36 00 00 AD 83 F8 FF 74 04 8B F0 EB F6 8B 7E 04 81 E7 00 00 FF + FF 66 81 3F 4D 5A 74 08 81 EF 00 00 01 00 EB F1 8B DF 03 5B 3C 66 81 3B 50 45 74 02 + EB E3 8B C7 C3 55 8B EC 8B 75 0C AC 84 C0 75 FB 2B 75 0C 8B CE 8B 5D 08 03 5B 3C 8B + 5B 78 03 5D 08 8B 53 20 03 55 08 2B C0 8B 32 03 75 08 8B 7D 0C 51 FC F3 A6 59 74 06 + } + $deadcode_body_2 = { + 83 C2 04 40 EB EB 8B 73 24 03 75 08 2B D2 66 8B 14 46 8B 73 1C 03 75 08 8B 04 96 03 + 45 08 8B E5 5D C2 08 00 55 8B EC 8B 7D 08 8B 75 0C 8B 4D 14 51 56 57 56 FF 75 10 E8 + 91 FF FF FF 5F 5E 59 AB AC 84 C0 75 FB E2 E9 8B E5 5D C2 10 00 8B 6C 24 04 6A 04 68 + 00 10 00 00 68 40 01 00 00 6A 00 FF 55 08 85 C0 74 18 89 45 78 E8 63 01 00 00 68 00 + 40 00 00 68 40 01 00 00 FF 75 78 FF 55 28 6A 00 FF 55 40 C3 + } + + condition: + uint16(0)==0x5A4D and ((($deadcode_ep_1 at pe.entry_point) and ($deadcode_marker at 0x40)) or (($deadcode_ep_2 at pe.entry_point) and ($deadcode_marker at 0x40)) or (($deadcode_ep_3 at pe.entry_point) and ($deadcode_marker at 0x40)) or ($deadcode_body_1 and $deadcode_body_2)) +} +import "pe" + +rule REVERSINGLABS_Win32_Virus_Greenp : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Greenp virus." + author = "ReversingLabs" + id = "5751e91c-652b-59bd-93b8-ece677ad4911" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/virus/Win32.Virus.Greenp.yara#L3-L46" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ca6df34ee2ad9d93e35b0d1a2d4765f681f3981ffe2786bbc822c3090212fd02" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Virus" + tc_detection_name = "Greenp" + tc_detection_factor = 5 + importance = 25 + + strings: + $greenp_body_1 = { + 68 ?? ?? ?? ?? 60 FC E8 4E 05 00 00 E8 31 04 00 00 0F 82 93 00 00 00 80 BD ?? ?? ?? ?? 01 75 63 FF 95 ?? ?? ?? ?? 6A 01 + 50 FF 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A 00 6A 00 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 EC 18 8B FC + 6A 00 6A 00 6A 00 57 FF 95 ?? ?? ?? ?? 85 C0 74 10 57 FF 95 ?? ?? ?? ?? 57 FF 95 ?? ?? ?? ?? EB DF 68 ?? ?? ?? ?? 6A 00 + FF 95 ?? ?? ?? ?? 83 C4 18 EB 27 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 85 C0 75 16 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? + ?? 85 C0 74 05 E8 81 00 00 00 61 58 FF E0 ?? E8 04 00 00 00 [4] 8B 3C 24 81 EC 00 01 00 00 8B F4 56 68 00 01 00 00 FF + 95 ?? ?? ?? ?? AC AA 81 C4 00 01 00 00 FF 95 ?? ?? ?? ?? 83 F8 03 75 2D 83 EC 10 8B F4 56 8D 46 04 50 8D 46 08 50 8D 46 + 0C 50 4F 57 FF 95 ?? ?? ?? ?? 8B 46 04 2B D2 F7 66 08 F7 66 0C 83 C4 10 3D 00 00 40 06 C3 [27] 81 EC ?? ?? ?? ?? 8B F4 + 68 ?? ?? ?? ?? 56 FF 95 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 8A 17 88 14 06 40 47 80 FA 00 75 F4 68 ?? ?? ?? ?? 6A 00 FF 95 ?? + ?? ?? ?? 97 56 57 B9 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 3A 02 00 00 5F B8 ?? ?? ?? ?? 99 68 ?? ?? ?? ?? 59 F7 F1 40 F7 E1 + 8B 57 3C 03 D7 0F B7 5A 14 8D 5C 13 40 8B 72 28 03 72 34 89 B5 ?? ?? ?? ?? C7 42 10 80 67 D5 40 FF 73 10 01 43 10 8B 43 + 10 05 ?? ?? ?? ?? 89 43 08 58 03 43 0C 89 42 28 52 B8 ?? ?? ?? ?? 99 68 ?? ?? ?? ?? 59 F7 F1 40 F7 E1 5A 01 43 10 01 42 + 50 81 42 50 ?? ?? ?? ?? 57 C6 85 ?? ?? ?? ?? 01 81 C7 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? B9 ?? ?? ?? ?? FC F3 A4 C6 85 ?? ?? + ?? ?? 00 5F 5E 6A 00 6A 00 6A 02 6A 00 6A 00 68 00 00 00 C0 56 FF 95 ?? ?? ?? ?? 93 50 8B C4 6A 00 50 B8 ?? ?? ?? ?? 99 + } + $greenp_body_2 = { + 68 ?? ?? ?? ?? 59 F7 F1 40 F7 E1 50 57 53 FF 95 ?? ?? ?? ?? 58 57 FF 95 ?? ?? ?? ?? 53 FF 95 ?? ?? ?? ?? 6A 00 56 FF 95 + ?? ?? ?? ?? 50 50 8B FC 8D 57 04 2B C0 52 57 50 68 3F 00 0F 00 50 50 50 8D 85 ?? ?? ?? ?? 50 68 02 00 00 80 FF 95 ?? ?? + ?? ?? 85 C0 75 1E 6A 0C 56 6A 01 6A 00 8D 85 ?? ?? ?? ?? 50 FF 37 FF 95 ?? ?? ?? ?? FF 37 FF 95 ?? ?? ?? ?? 81 C4 ?? ?? + ?? ?? C3 + } + + condition: + uint16(0)==0x5A4D and ($greenp_body_1 at pe.entry_point) and $greenp_body_2 +} +import "pe" + +rule REVERSINGLABS_Win32_Virus_Negt : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Negt virus." + author = "ReversingLabs" + id = "80e83105-dd98-5fad-9119-f851ec3199af" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/virus/Win32.Virus.Negt.yara#L3-L94" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "43057ef111fc505678606386c8d428653da391f4b65844d81479ca05e3517346" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Virus" + tc_detection_name = "Negt" + tc_detection_factor = 5 + importance = 25 + + strings: + $negt_body_and_infector_1 = { + 6A 00 E8 99 08 00 00 A3 ?? ?? ?? ?? 68 04 01 00 00 68 ?? ?? ?? ?? 6A 00 E8 7D 08 00 00 6A 00 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? E8 48 08 00 00 BB 00 00 00 00 8D 05 ?? ?? ?? ?? FE 00 68 ?? ?? ?? ?? E8 2D 00 00 00 43 83 FB 18 7C E8 E8 92 08 00 00 + 3C 9F 7F 17 6A 01 68 ?? ?? ?? ?? 6A 00 68 ?? ?? ?? ?? 6A 00 6A 00 E8 7D 08 00 00 6A 00 E8 10 08 00 00 55 8B EC 81 C4 B8 + FD FF FF FF 75 08 E8 35 08 00 00 0B C0 0F 84 C2 00 00 00 8D 85 C2 FE FF FF 50 68 ?? ?? ?? ?? E8 F2 07 00 00 89 85 BC FE + FF FF 83 BD BC FE FF FF FF 0F 84 9E 00 00 00 8D 9D EE FE FF FF 53 E8 21 08 00 00 8B F3 BB 00 00 00 00 F7 D3 68 ?? ?? ?? + ?? 56 E8 01 08 00 00 23 D8 68 ?? ?? ?? ?? 56 E8 F4 07 00 00 23 D8 68 ?? ?? ?? ?? 56 E8 E7 07 00 00 23 D8 68 ?? ?? ?? ?? + 56 E8 DA 07 00 00 23 D8 68 ?? ?? ?? ?? 56 E8 CD 07 00 00 23 D8 83 FB 00 74 28 FF 75 08 68 ?? ?? ?? ?? E8 BF 07 00 00 8D + 85 EE FE FF FF 50 68 ?? ?? ?? ?? E8 A2 07 00 00 68 ?? ?? ?? ?? E8 08 01 00 00 8D 85 C2 FE FF FF 50 FF B5 BC FE FF FF E8 + 50 07 00 00 83 F8 00 0F 85 62 FF FF FF FF B5 BC FE FF FF E8 30 07 00 00 8D 85 C2 FE FF FF 50 68 ?? ?? ?? ?? E8 25 07 00 + 00 89 85 BC FE FF FF 83 BD BC FE FF FF FF 0F 84 AF 00 00 00 8D BD C2 FE FF FF 8B 07 66 83 E0 10 0F 84 82 00 00 00 8D 9D + } + $negt_body_and_infector_2 = { + EE FE FF FF 53 E8 42 07 00 00 8B F3 BB 00 00 00 00 F7 D3 68 ?? ?? ?? ?? 56 E8 22 07 00 00 23 D8 68 ?? ?? ?? ?? 56 E8 15 + 07 00 00 23 D8 68 ?? ?? ?? ?? 56 E8 08 07 00 00 23 D8 83 FB 00 74 41 FF 75 08 8D 85 B8 FD FF FF 50 E8 F8 06 00 00 8D 85 + EE FE FF FF 50 8D 85 B8 FD FF FF 50 E8 D9 06 00 00 68 ?? ?? ?? ?? 8D 85 B8 FD FF FF 50 E8 C8 06 00 00 60 8D 85 B8 FD FF + FF 50 E8 63 FE FF FF 61 8D 85 C2 FE FF FF 50 FF B5 BC FE FF FF E8 72 06 00 00 83 F8 00 0F 85 51 FF FF FF FF B5 BC FE FF + FF E8 52 06 00 00 C9 C2 04 00 55 8B EC 81 C4 E4 E9 FF FF 51 6A 00 68 80 00 00 00 6A 03 6A 00 6A 03 68 00 00 00 C0 FF 75 + 08 E8 1E 06 00 00 83 F8 FF 75 05 E9 AE 03 00 00 89 45 FC 6A 00 6A 00 6A 3C FF 75 FC E8 45 06 00 00 6A 00 8D 45 F0 50 6A + 04 8D 45 F4 50 FF 75 FC E8 25 06 00 00 6A 00 6A 00 FF 75 F4 FF 75 FC E8 22 06 00 00 6A 00 8D 45 F0 50 68 20 01 00 00 68 + ?? ?? ?? ?? FF 75 FC E8 FE 05 00 00 8B 5D F4 83 EB 0B 6A 00 6A 00 53 FF 75 FC E8 F7 05 00 00 6A 00 8D 45 F0 50 6A 0B 68 + ?? ?? ?? ?? FF 75 FC E8 D6 05 00 00 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 E5 05 00 00 0B C0 75 05 E9 12 03 00 00 81 3D ?? ?? + ?? ?? 50 45 00 00 74 05 E9 01 03 00 00 0F B7 05 ?? ?? ?? ?? B9 28 00 00 00 F7 E1 03 45 F4 83 C0 18 0F B7 0D ?? ?? ?? ?? + 03 C1 83 C0 28 3B 05 ?? ?? ?? ?? 76 05 E9 D4 02 00 00 A1 ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? ?? ?? ?? A3 ?? ?? ?? ?? 0F B7 + } + $negt_body_and_infector_3 = { + 05 ?? ?? ?? ?? B9 28 00 00 00 F7 E1 83 C0 04 03 45 F4 83 C0 14 05 E0 00 00 00 89 45 EC C7 05 ?? ?? ?? ?? 2E 45 41 54 C7 + 05 ?? ?? ?? ?? 55 02 00 00 FF 35 ?? ?? ?? ?? 8F 05 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 99 F7 F1 40 F7 E1 A3 ?? + ?? ?? ?? 8B 45 EC 83 E8 18 6A 00 6A 00 50 FF 75 FC E8 10 05 00 00 6A 00 8D 45 F0 50 6A 04 8D 45 E8 50 FF 75 FC E8 F0 04 + 00 00 6A 00 8D 45 F0 50 6A 04 8D 45 E4 50 FF 75 FC E8 DC 04 00 00 8B 45 E8 03 45 E4 A3 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? 00 + 00 00 00 C7 05 ?? ?? ?? ?? 00 00 00 00 66 C7 05 ?? ?? ?? ?? 00 00 66 C7 05 ?? ?? ?? ?? 00 00 C7 05 ?? ?? ?? ?? 20 00 00 + E0 6A 00 6A 00 FF 75 EC FF 75 FC E8 9E 04 00 00 6A 00 8D 45 F0 50 6A 28 68 ?? ?? ?? ?? FF 75 FC E8 8F 04 00 00 68 ?? ?? + ?? ?? E8 61 04 00 00 68 ?? ?? ?? ?? E8 63 04 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 48 04 00 00 A3 ?? + ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 33 04 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 1E 04 00 00 + A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 09 04 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 F4 03 + 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 DF 03 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 + CA 03 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 B5 03 00 00 A3 ?? ?? ?? ?? 6A 02 6A 00 6A 00 FF 75 FC E8 + BA 03 00 00 6A 00 8D 45 F0 50 FF 35 ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 50 FF 75 FC E8 A5 03 00 00 66 FF 05 ?? ?? ?? ?? A1 ?? + ?? ?? ?? 8B 0D ?? ?? ?? ?? 99 F7 F1 40 F7 E1 03 05 ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? ?? ?? ?? A3 ?? ?? ?? ?? 6A 00 6A 00 + } + $negt_body_and_infector_4 = { + FF 75 F4 FF 75 FC E8 63 03 00 00 6A 00 8D 45 F0 50 68 F8 00 00 00 68 ?? ?? ?? ?? FF 75 FC E8 51 03 00 00 83 6D F4 0B 6A + 00 6A 00 FF 75 F4 FF 75 FC E8 38 03 00 00 6A 00 8D 45 F0 50 6A 0B 68 ?? ?? ?? ?? FF 75 FC E8 29 03 00 00 6A 00 6A 20 6A + 03 6A 00 6A 01 68 00 00 00 80 68 ?? ?? ?? ?? E8 C8 02 00 00 89 45 F8 6A 00 6A 00 6A 00 FF 75 F8 E8 F9 02 00 00 6A 00 8D + 45 F0 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 75 F8 E8 D3 02 00 00 8B 75 F0 6A 02 6A 00 6A 00 FF 75 FC E8 CE 02 00 00 + 6A 00 8D 45 F0 50 56 8D 85 ?? ?? ?? ?? 50 FF 75 FC E8 BE 02 00 00 FF 75 FC E8 62 02 00 00 FF 75 F8 E8 5A 02 00 00 59 C9 + C2 04 00 E8 00 00 00 00 5D 81 ED ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 68 00 01 00 00 FF B5 ?? ?? ?? ?? 6A 00 + FF 95 ?? ?? ?? ?? 6A 00 6A 20 6A 03 6A 00 6A 01 68 00 00 00 80 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A + 00 6A 20 6A 02 6A 00 6A 03 68 00 00 00 C0 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A 00 FF B5 ?? ?? ?? + ?? FF 95 ?? ?? ?? ?? 2D ?? ?? ?? ?? 6A 00 6A 00 50 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 6A 00 8D 85 ?? ?? ?? ?? 50 68 00 + 01 00 00 FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 83 FB 00 74 1E 8D 85 ?? ?? ?? ?? 6A 00 + 50 53 FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? EB B7 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? + FF 95 ?? ?? ?? ?? 6A 00 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 03 85 ?? ?? ?? ?? 50 C3 + } + $negt_infector = { + E8 00 00 00 00 5D 81 ED ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 68 00 01 00 00 FF B5 ?? ?? ?? ?? 6A 00 FF 95 ?? + ?? ?? ?? 6A 00 6A 20 6A 03 6A 00 6A 01 68 00 00 00 80 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A 00 6A 20 + 6A 02 6A 00 6A 03 68 00 00 00 C0 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A 00 FF B5 ?? ?? ?? ?? FF 95 + ?? ?? ?? ?? 2D ?? ?? ?? ?? 6A 00 6A 00 50 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 6A 00 8D 85 ?? ?? ?? ?? 50 68 00 01 00 00 + FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 83 FB 00 74 1E 8D 85 ?? ?? ?? ?? 6A 00 50 53 FF + B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? EB B7 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? + ?? ?? ?? 6A 00 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 03 85 ?? ?? ?? ?? 50 C3 + } + + condition: + uint16(0)==0x5A4D and (($negt_infector at pe.entry_point) or (($negt_body_and_infector_1 at pe.entry_point) and $negt_body_and_infector_2 and $negt_body_and_infector_3 and $negt_body_and_infector_4)) +} +import "pe" + +rule REVERSINGLABS_Win32_Virus_Mocket : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Mocket virus." + author = "ReversingLabs" + id = "878c2162-9a79-52e6-af7b-95f9667f9e78" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/virus/Win32.Virus.Mocket.yara#L3-L58" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "af16974396efe7a1a46aa39b812482dcc49d0fe95db6640c1703db479e7ea9dc" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Virus" + tc_detection_name = "Mocket" + tc_detection_factor = 5 + importance = 25 + + strings: + $mocket_body_1 = { + E8 00 00 00 00 5B 81 EB ?? ?? ?? ?? 8B 34 24 81 E6 00 00 FF FF E8 31 00 00 00 89 83 ?? ?? ?? ?? E8 4C 00 00 00 89 83 ?? + ?? ?? ?? E8 A2 00 00 00 E8 CD 00 00 00 E8 05 01 00 00 87 CB E3 0C B8 ?? ?? ?? ?? 05 ?? ?? ?? ?? FF E0 C3 66 81 3E 4D 5A + 75 0E 8B 7E 3C 03 FE 66 81 3F 50 45 75 02 96 C3 81 EE 00 00 01 00 81 FE 00 00 00 70 73 DD 33 C0 C3 8B 70 3C 03 F0 8B 76 + 78 03 F0 56 8B 76 20 03 F0 8B C6 33 D2 33 C9 8A 8B ?? ?? ?? ?? 8D BB ?? ?? ?? ?? 8B 34 02 03 B3 ?? ?? ?? ?? 83 C2 04 F3 + A6 75 E2 5E 8B C6 83 EA 04 D1 EA 8B 40 24 03 83 ?? ?? ?? ?? 33 C9 66 8B 0C 02 8B C6 8B 40 1C 03 83 ?? ?? ?? ?? C1 E1 02 + 8B 04 01 03 83 ?? ?? ?? ?? C3 8D BB ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? 57 8B 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? FF D0 89 06 + 83 C6 04 B9 FF FF FF FF 32 C0 F2 AE 80 3F 90 75 DD C3 8D BB ?? ?? ?? ?? 57 68 80 00 00 00 8B 83 ?? ?? ?? ?? FF D0 81 C7 + 80 00 00 00 57 68 80 00 00 00 8B 83 ?? ?? ?? ?? FF D0 81 C7 80 00 00 00 57 68 80 00 00 00 8B 83 ?? ?? ?? ?? FF D0 C3 33 + C9 B1 03 8D BB ?? ?? ?? ?? 57 8B 83 ?? ?? ?? ?? FF D0 E8 01 00 00 00 C3 C7 83 ?? ?? ?? ?? 00 00 00 00 8D 83 ?? ?? ?? ?? + } + $mocket_body_2 = { + 50 8D 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? FF D0 40 0B C0 74 53 48 89 83 ?? ?? ?? ?? E8 48 00 00 00 FE 83 ?? ?? ?? ?? 80 + BB ?? ?? ?? ?? 0A 74 29 8D BB ?? ?? ?? ?? B9 ?? ?? ?? ?? 32 C0 F3 AA 8D 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? 50 8B 83 ?? + ?? ?? ?? FF D0 0B C0 75 C3 8B 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? FF D0 C3 60 8D B3 ?? ?? ?? ?? 56 8B 83 ?? ?? ?? ?? FF + D0 89 83 ?? ?? ?? ?? 68 80 00 00 00 56 8B 83 ?? ?? ?? ?? FF D0 E8 B7 01 00 00 40 0B C0 0F 84 75 01 00 00 48 89 83 ?? ?? + ?? ?? 8B 8B ?? ?? ?? ?? E8 B4 01 00 00 0B C0 0F 84 4D 01 00 00 89 83 ?? ?? ?? ?? 8B 8B ?? ?? ?? ?? E8 B4 01 00 00 0B C0 + 0F 84 26 01 00 00 89 83 ?? ?? ?? ?? 8B 70 3C 03 F0 66 81 3E 50 45 0F 85 F7 00 00 00 81 7E 4C 4B 43 4F 4D 0F 84 EA 00 00 + 00 8B 4E 3C 51 8B 46 28 89 83 ?? ?? ?? ?? 8B 46 34 89 83 ?? ?? ?? ?? FF B3 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 FF B3 ?? + ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 59 8B 83 ?? ?? ?? ?? 05 ?? ?? ?? ?? E8 5C 01 00 00 89 83 ?? ?? ?? ?? 91 E8 21 01 00 00 + 40 0B C0 0F 84 B9 00 00 00 48 89 83 ?? ?? ?? ?? 8B 8B ?? ?? ?? ?? E8 1F 01 00 00 0B C0 0F 84 91 00 00 00 89 83 ?? ?? ?? + } + $mocket_body_3 = { + ?? 8B 70 3C 03 F0 8B FE 83 C6 78 8B 57 74 C1 E2 03 03 F2 0F B7 47 06 48 6B C0 28 03 F0 8B 56 10 8B CA 03 56 14 52 8B C1 + 03 46 0C 89 47 28 8B 46 10 05 ?? ?? ?? ?? 8B 4F 3C E8 EA 00 00 00 89 46 10 89 46 08 8B 46 10 03 46 0C 89 47 50 81 4E 24 + 20 00 00 A0 C7 47 4C 4B 43 4F 4D 8D B3 ?? ?? ?? ?? 5A 87 FA 03 BB ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 A4 EB 0B 8B 8B ?? ?? ?? + ?? E8 41 00 00 00 FF B3 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 FF B3 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 FF B3 ?? ?? ?? ?? + 8B 83 ?? ?? ?? ?? FF D0 FF B3 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? FF D0 61 C3 33 C0 50 50 51 FF B3 ?? ?? + ?? ?? 8B 83 ?? ?? ?? ?? FF D0 FF B3 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 C3 33 C0 50 50 6A 03 50 6A 01 68 00 00 00 C0 56 + 8B 83 ?? ?? ?? ?? FF D0 C3 6A 00 51 6A 00 6A 04 6A 00 8B 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? FF D0 C3 51 6A 00 6A 00 6A + 02 FF B3 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 C3 33 D2 F7 F1 0B D2 74 01 40 F7 E1 C3 + } + + condition: + uint16(0)==0x5A4D and ($mocket_body_1 at pe.entry_point) and $mocket_body_2 and $mocket_body_3 +} +import "pe" + +rule REVERSINGLABS_Win32_Virus_Awfull : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Awfull virus." + author = "ReversingLabs" + id = "34104923-b401-5d39-883b-aa9a5a8e64f3" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/virus/Win32.Virus.Awfull.yara#L3-L33" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "84a4faee4cbbb3387ad25bd9230c6482b8db461bc008312bc782f23e3df2eae3" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Virus" + tc_detection_name = "Awfull" + tc_detection_factor = 5 + importance = 25 + + strings: + $awfull_body = { + 60 E8 ?? 00 00 00 8B 64 24 08 EB ?? [0-256] + 33 D2 64 FF 32 64 89 22 33 C0 C7 00 00 00 00 00 33 D2 64 8F 02 + 5A 64 (8B 0D | 67 8B 0E ) 14 00 [0-2] E3 03 FA + EB FD 61 E8 00 00 00 00 5D 81 ED ?? ?? ?? ?? 0B ED 74 ?? + [0-128] (BE | 8B 35) ?? ?? ?? ?? 03 F5 B9 ?? ?? ?? ?? + 56 5F AC F6 D0 AA 49 E3 02 EB F7 + } + + condition: + uint16(0)==0x5A4D and ($awfull_body at pe.entry_point) +} +import "pe" + +rule REVERSINGLABS_Win32_Virus_Elerad : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Elerad virus." + author = "ReversingLabs" + id = "0307a136-ea2c-584c-bfda-f41e2c46fd09" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/virus/Win32.Virus.Elerad.yara#L3-L33" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "930594bf99daf55ef02542ce7b393c1c23ead75946b3da3b555102a2e7142e33" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Virus" + tc_detection_name = "Elerad" + tc_detection_factor = 5 + importance = 25 + + strings: + $elerad_body = { + EB 77 60 E8 09 00 00 00 8B 64 24 08 E9 DD 01 00 00 33 D2 64 FF 32 64 89 22 50 8B D8 B9 FF 00 00 00 81 38 2E 65 78 65 74 + 08 40 E2 F5 E9 BD 01 00 00 32 D2 38 50 04 0F 85 B2 01 00 00 33 D2 80 38 5C 74 07 3B C3 74 07 48 E2 F4 88 10 8B D0 58 BE + 00 00 E6 77 BF 23 C1 AB 00 EB 3E 60 E8 09 00 00 00 8B 64 24 08 E9 84 01 00 00 33 D2 64 FF 32 64 89 22 BE 00 00 E6 77 EB + 20 68 ?? ?? ?? ?? 60 8B 74 24 24 E8 09 00 00 00 8B 64 24 08 E9 5D 01 00 00 33 D2 64 FF 32 64 89 22 E8 00 00 00 00 5D 81 + ED ?? ?? ?? ?? 81 FF 23 C1 AB 00 75 0C 89 95 22 12 40 00 89 85 1E 12 40 00 BA ?? ?? ?? ?? B9 09 02 00 00 8D 85 D0 10 40 + 00 31 10 83 C0 04 E2 F9 + } + + condition: + uint16(0)==0x5A4D and ($elerad_body at pe.entry_point) +} rule REVERSINGLABS_Win32_PUA_Domaiq : TC_DETECTION MALICIOUS MALWARE FILE { meta: @@ -57,8 +528,8 @@ rule REVERSINGLABS_Win32_PUA_Domaiq : TC_DETECTION MALICIOUS MALWARE FILE date = "2020-07-28" modified = "2020-07-28" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/pua/Win32.PUA.Domaiq.yara#L1-L169" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/pua/Win32.PUA.Domaiq.yara#L1-L169" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e291a639aa027a2257eec2853e40a222afabf23b32898326a1d5b48be823202c" score = 75 quality = 90 @@ -192,6 +663,470 @@ rule REVERSINGLABS_Win32_PUA_Domaiq : TC_DETECTION MALICIOUS MALWARE FILE condition: uint16(0)==0x5A4D and $payload and ($NSIS_CheckIntegrity or ($UPX_Decompression and $UPX_Encrypting) or $NSIS_ErrorPart or $dumping_functionv2014 or $dumping_functionMidVersion or ($exception1 and $exception2 and $exceptionallock) or $dumping_functionP or $dumping_functionE or $dumping_functionB or $dumping_function111 or $dumping_function2 or $lib_loader) } +rule REVERSINGLABS_Win32_Downloader_Dlmarlboro : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects dlMarlboro downloader." + author = "ReversingLabs" + id = "4c99b5a4-dc6b-579b-b1bd-bd4c93c6e68c" + date = "2020-07-23" + modified = "2020-07-23" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/downloader/Win32.Downloader.dlMarlboro.yara#L1-L79" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "465a3b3a9686889001ac0b929d0349e44b6015eaeed3386361366def5013164a" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Downloader" + tc_detection_name = "dlMarlboro" + tc_detection_factor = 3 + importance = 25 + + strings: + $ping_apnic = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 0F 57 + C0 F3 0F 7F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D + 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? + 8D 85 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $download_bin_1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 65 ?? 8B F2 8B C1 89 85 ?? + ?? ?? ?? 8B 7D ?? 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? + ?? ?? 83 EC ?? 8B CC 6A ?? 6A ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 56 C6 01 + ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? F6 84 + 05 ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? FF 50 ?? 8D 4D ?? 51 8B + C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B D7 8B C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D6 8B C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 + ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 55 + ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 55 ?? C6 + 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? F6 84 05 ?? ?? + ?? ?? ?? 74 ?? 83 EC ?? 8D 45 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? BA ?? ?? ?? + ?? 8B C8 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? B3 ?? EB ?? 32 DB + } + $download_bin_2 = { + C7 45 ?? ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? + ?? ?? 83 C4 ?? 84 DB 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 8D 80 ?? ?? ?? ?? 89 + 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 03 + C8 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 + C4 ?? 8B 8D ?? ?? ?? ?? 8B F0 85 C9 74 ?? 8B 01 FF 50 ?? 85 C0 74 ?? 8B 10 8B C8 6A + ?? FF 12 8B 06 8B CE 6A ?? 8B 40 ?? FF D0 50 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 5D ?? 83 C4 ?? 8B 7D ?? 8B 08 8B 49 ?? F6 44 01 ?? ?? 75 ?? 8B 75 ?? 8D 4D ?? + 83 FB ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? 0F 43 CF 3B F0 0F 42 C6 50 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 75 ?? 83 FE ?? 73 ?? 83 C8 ?? EB ?? 33 C0 83 FE ?? 0F 95 C0 85 C0 0F 94 + C0 84 C0 0F 94 C0 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 + E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? + ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 56 E8 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 FB ?? 72 ?? 57 E8 ?? ?? ?? ?? 83 C4 + ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 + ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 EB ?? 8B 8D ?? ?? ?? + ?? 8B 01 FF 50 ?? 8B 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? C3 8B 85 ?? ?? + ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 + 5D C3 + } + + condition: + uint16(0)==0x5A4D and $ping_apnic and $download_bin_1 and $download_bin_2 +} +rule REVERSINGLABS_Win64_Infostealer_Daolpu : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Daolpu infostealer." + author = "ReversingLabs" + id = "bf815556-6ccf-506a-b858-5f4c18282c05" + date = "2024-08-26" + modified = "2024-08-26" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/infostealer/Win64.Infostealer.Daolpu.yara#L1-L322" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "5ffd0427c6c8e666cfabc48426e7771595a7024548706f37a1de3538e4e2d559" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Infostealer" + tc_detection_name = "Daolpu" + tc_detection_factor = 5 + importance = 25 + + strings: + $network_communication = { + 48 89 5C 24 ?? 48 89 6C 24 ?? 48 89 7C 24 ?? 41 56 48 83 EC ?? 48 8B D9 49 8B E8 B9 + ?? ?? ?? ?? 4C 8B F2 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B F8 48 85 C0 0F 84 ?? ?? ?? + ?? 4C 8D 05 ?? ?? ?? ?? 48 89 74 24 ?? BA ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 83 + 7B ?? ?? 4C 8D 43 ?? 76 ?? 4D 8B 00 BA ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? BA ?? ?? + ?? ?? 48 8B CF 44 8D 42 ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8B + CF E8 ?? ?? ?? ?? 45 33 C0 BA ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? 48 8B CF E8 ?? ?? + ?? ?? 48 8B C8 48 8B F0 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8B C8 48 8B D8 E8 ?? + ?? ?? ?? 49 83 7E ?? ?? 49 8D 56 ?? 76 ?? 48 8B 12 48 8B CB E8 ?? ?? ?? ?? 48 8B CE + E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8B C8 48 8B D8 E8 ?? ?? ?? ?? 48 83 7D ?? ?? + 48 8D 55 ?? 76 ?? 48 8B 12 49 C7 C0 ?? ?? ?? ?? 48 8B CB E8 ?? ?? ?? ?? 48 8B CE E8 + ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8B C8 48 8B D8 E8 ?? ?? ?? ?? 49 C7 C0 ?? ?? ?? + ?? 48 8D 15 ?? ?? ?? ?? 48 8B CB E8 ?? ?? ?? ?? 4C 8B C6 BA ?? ?? ?? ?? 48 8B CF E8 + ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? 8B E8 85 C0 75 ?? 48 8D 1D ?? ?? ?? ?? 48 8D 05 + ?? ?? ?? ?? EB ?? 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CD 48 + 8B D8 E8 ?? ?? ?? ?? 48 8B D0 48 8B CB E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8B + CE E8 ?? ?? ?? ?? 48 8B 74 24 ?? 48 8B CF E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 5C 24 + ?? 33 C0 48 8B 6C 24 ?? 48 8B 7C 24 ?? 48 83 C4 ?? 41 5E C3 + } + $find_sensitive_files_p1 = { + 48 89 5C 24 ?? 55 56 57 41 54 41 55 41 56 41 57 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? + ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 85 ?? ?? ?? ?? 4C 8B F2 48 8B F9 45 33 + E4 4C 89 65 ?? 0F 57 C0 0F 11 45 ?? 0F 57 C9 F3 0F 7F 4D ?? 49 C7 C0 ?? ?? ?? ?? 49 + FF C0 66 46 39 24 41 75 ?? 48 8B D7 48 8D 4D ?? E8 ?? ?? ?? ?? 90 41 B8 ?? ?? ?? ?? + 48 8D 15 ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 48 8D 4D ?? 48 83 7D ?? ?? 48 0F 47 + 4D ?? 48 8D 55 ?? FF 15 ?? ?? ?? ?? 4C 8B F8 0F 57 C0 F3 0F 7F 45 ?? 0F 57 C9 F3 0F + 7F 4D ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 60 ?? 48 89 45 ?? 48 8D 4D ?? 48 89 08 + 49 83 FF ?? 0F 84 ?? ?? ?? ?? 4C 8D 2D ?? ?? ?? ?? F6 45 ?? ?? 0F 84 ?? ?? ?? ?? 0F + B7 4D ?? 0F B7 45 ?? 66 83 F9 ?? 75 ?? 66 85 C0 0F 84 ?? ?? ?? ?? 66 3B C9 75 ?? 66 + 3B C1 75 ?? 66 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 4C 89 64 24 ?? 0F 57 C0 0F 11 44 24 ?? + 4C 89 65 ?? 4C 89 65 ?? 49 C7 C0 ?? ?? ?? ?? 66 0F 1F 84 00 ?? ?? 00 00 49 FF C0 66 + 42 83 3C 47 ?? 75 ?? 48 8B D7 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 41 B8 ?? ?? ?? ?? 48 + 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8D 45 ?? 49 C7 C0 ?? ?? ?? ?? 0F + 1F 44 00 ?? 49 FF C0 66 42 83 3C 40 ?? 75 ?? 48 8D 55 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? + ?? 48 8D 4C 24 ?? 48 83 7D ?? ?? 48 0F 47 4C 24 ?? 49 8B D6 E8 ?? ?? ?? ?? 90 48 8D + 4C 24 ?? E8 ?? ?? ?? ?? 4C 8B 45 ?? 49 83 F8 ?? 76 ?? 48 8B 54 24 ?? 48 8D 4C 24 ?? + E8 ?? ?? ?? ?? 4C 89 65 ?? 48 C7 45 ?? ?? ?? ?? ?? 66 44 89 64 24 ?? 48 8B 4C 24 ?? + 4C 89 64 24 ?? E9 ?? ?? ?? ?? 4C 89 65 ?? 0F 57 C0 0F 11 45 ?? 4C 89 65 ?? 4C 89 65 + ?? 48 8D 45 ?? 49 C7 C0 ?? ?? ?? ?? 49 FF C0 66 42 83 3C 40 ?? 75 ?? 48 8D 55 ?? 48 + } + $find_sensitive_files_p2 = { + 8D 4D ?? E8 ?? ?? ?? ?? 90 4C 8D 55 ?? 48 8B 5D ?? 48 8B 75 ?? 48 83 FE ?? 4C 0F 47 + D3 4C 8B 5D ?? 49 83 FB ?? 72 ?? 49 8D 4B ?? 48 C7 C0 ?? ?? ?? ?? 48 3B C8 48 0F 42 + C1 4D 8D 0C 42 4D 8B C1 4D 2B C5 66 41 83 39 ?? 75 ?? BA ?? ?? ?? ?? 49 8B C5 42 0F + B7 0C 00 66 3B 08 75 ?? 48 83 C0 ?? 48 83 EA ?? 75 ?? 4D 2B CA 49 D1 F9 EB ?? 4D 3B + CA 74 ?? 49 83 E9 ?? 49 83 E8 ?? EB ?? 49 C7 C1 ?? ?? ?? ?? 49 83 F9 ?? 0F 84 ?? ?? + ?? ?? 49 FF C1 4C 89 64 24 ?? 0F 57 C0 0F 11 44 24 ?? 4C 89 65 ?? 4C 89 65 ?? 4D 3B + D9 0F 82 ?? ?? ?? ?? 4D 2B D9 49 C7 C0 ?? ?? ?? ?? 4D 3B D8 4D 0F 42 C3 48 8D 45 ?? + 48 83 FE ?? 48 0F 47 C3 4A 8D 14 48 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8D 4C 24 ?? + 48 83 7D ?? ?? 48 0F 47 4C 24 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 48 8D 4C 24 ?? 48 83 7D ?? ?? 48 0F 47 4C 24 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 8D 4C 24 ?? 48 83 7D ?? ?? 48 0F 47 4C 24 ?? 48 + 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 8D 4C 24 ?? 48 83 7D ?? + ?? 48 0F 47 4C 24 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 + 8D 4C 24 ?? 48 83 7D ?? ?? 48 0F 47 4C 24 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 + C0 74 ?? 48 8D 4C 24 ?? 48 83 7D ?? ?? 48 0F 47 4C 24 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 85 C0 74 ?? 48 8D 4C 24 ?? 48 83 7D ?? ?? 48 0F 47 4C 24 ?? 48 8D 15 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 4C 24 ?? 48 83 7D ?? ?? 48 0F 47 4C 24 ?? 48 + 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 4C 89 64 24 ?? 0F 57 C0 0F + 11 44 24 ?? 4C 89 64 24 ?? 4C 89 64 24 ?? 49 C7 C0 ?? ?? ?? ?? 49 FF C0 66 42 83 3C + } + $find_sensitive_files_p3 = { + 47 ?? 75 ?? 48 8B D7 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 41 B8 ?? ?? ?? ?? 48 8D 15 ?? + ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 48 + 8D 55 ?? 48 83 7D ?? ?? 48 0F 47 55 ?? 4C 8B 45 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 + 8B D0 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 4C 8B 44 24 ?? 49 + 83 F8 ?? 76 ?? 48 8B 54 24 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 4C 89 64 24 ?? 48 C7 44 + 24 ?? ?? ?? ?? ?? 66 44 89 64 24 ?? 48 8B 4C 24 ?? 4C 89 64 24 ?? BA ?? ?? ?? ?? E8 + ?? ?? ?? ?? 90 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 4C 8B 44 24 ?? 49 83 F8 ?? 76 ?? 48 8B + 54 24 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 4C 89 64 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 66 + 44 89 64 24 ?? 48 8B 4C 24 ?? 4C 89 64 24 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 49 8B 46 + ?? 49 3B 46 ?? 74 ?? 48 8D 55 ?? 48 8B C8 E8 ?? ?? ?? ?? 49 8B 5E ?? BA ?? ?? ?? ?? + 48 8D 4D ?? E8 ?? ?? ?? ?? 49 8B 0E 48 83 C1 ?? 48 8B 01 48 85 C0 74 ?? 48 39 58 ?? + 72 ?? 77 ?? 4C 89 20 48 8B 40 ?? 48 89 01 EB ?? 48 8D 48 ?? 48 8B 01 48 85 C0 75 ?? + 48 8D 4D ?? E8 ?? ?? ?? ?? 49 83 46 ?? ?? EB ?? 4C 8D 45 ?? 48 8B D0 49 8B CE E8 ?? + ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B 45 ?? 49 83 F8 ?? 76 ?? 48 8B 55 ?? 48 + 8D 4D ?? E8 ?? ?? ?? ?? 4C 89 65 ?? 48 C7 45 ?? ?? ?? ?? ?? 66 44 89 65 ?? 48 8B 4D + ?? 4C 89 65 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 4C 8B + 45 ?? 49 83 F8 ?? 76 ?? 48 8B 54 24 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 4C 89 65 ?? 48 + C7 45 ?? ?? ?? ?? ?? 66 44 89 64 24 ?? 48 8B 4C 24 ?? 4C 89 64 24 ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B 45 ?? 49 83 F8 ?? 76 ?? 48 8B 55 + ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 89 65 ?? 48 C7 45 ?? ?? ?? ?? ?? 66 44 89 65 ?? 48 + } + $parse_firefox_configuration_p1 = { + 48 89 5C 24 ?? 48 89 74 24 ?? 48 89 7C 24 ?? 55 41 54 41 55 41 56 41 57 48 8D AC 24 + ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 85 ?? ?? ?? ?? + 48 8B F1 48 89 4C 24 ?? 45 33 ED 44 89 6C 24 ?? 0F 57 C0 0F 11 01 0F 11 41 ?? 4C 89 + 29 4C 89 69 ?? 4C 89 69 ?? 4C 89 69 ?? 41 8D 4D ?? E8 ?? ?? ?? ?? 4C 89 68 ?? 48 89 + 06 48 89 30 C7 44 24 ?? ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 4D ?? E8 ?? + ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 4C 8B 75 ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 49 2B C6 + 48 83 F8 ?? 0F 82 ?? ?? ?? ?? 4C 8D 65 ?? 48 83 7D ?? ?? 4C 0F 47 65 ?? 4C 89 6C 24 + ?? 0F 57 C0 0F 11 44 24 ?? 0F 57 C9 F3 0F 7F 4C 24 ?? 4D 8D 7E ?? 41 8D 5D ?? 48 8D + 7C 24 ?? 48 8D 44 24 ?? 48 89 85 ?? ?? ?? ?? 8D 4B ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? + ?? ?? 48 8D 4C 24 ?? 48 89 08 4C 89 68 ?? 48 89 44 24 ?? 8D 4B ?? 4C 3B FB 76 ?? 49 + 8B DF 48 83 CB ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 3B D8 76 ?? 48 8B D8 EB ?? 48 3B + D9 48 0F 42 D9 48 8D 4B ?? E8 ?? ?? ?? ?? 48 8B F8 48 89 44 24 ?? 4C 89 7C 24 ?? 48 + 89 5C 24 ?? 4D 8B C6 49 8B D4 48 8B CF E8 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 66 42 89 04 + 37 0F B6 05 ?? ?? ?? ?? 42 88 44 37 ?? 42 C6 04 3F ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D + 54 24 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 4C 8B 44 24 ?? + 49 83 F8 ?? 76 ?? 49 FF C0 48 8B 54 24 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 66 0F 6F 05 + ?? ?? 12 00 F3 0F 7F 44 24 ?? C6 44 24 ?? ?? 48 8B 4C 24 ?? 4C 89 6C 24 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 0F 57 C0 0F 11 45 ?? + 0F 11 45 ?? 48 8D 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? ?? ?? 90 + } + $parse_firefox_configuration_p2 = { + 4C 89 6C 24 ?? 0F 57 C0 0F 11 44 24 ?? 4C 89 6C 24 ?? 4C 89 6C 24 ?? 48 8B 7D ?? 4C + 8D 75 ?? 48 83 7D ?? ?? 4C 0F 47 75 ?? 49 BC ?? ?? ?? ?? ?? ?? ?? ?? 49 3B FC 0F 87 + ?? ?? ?? ?? 48 8D 44 24 ?? 48 89 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 + 85 ?? ?? ?? ?? 48 8D 4C 24 ?? 48 89 08 4C 89 68 ?? 48 89 44 24 ?? 48 83 FF ?? 77 ?? + 48 89 7C 24 ?? BA ?? ?? ?? ?? 48 89 54 24 ?? 41 0F 10 06 0F 11 44 24 ?? EB ?? 48 8B + DF 48 83 CB ?? 49 3B DC 76 ?? 49 8B DC EB ?? 48 83 FB ?? B8 ?? ?? ?? ?? 48 0F 42 D8 + 48 8D 4B ?? E8 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 7C 24 ?? 48 89 5C 24 ?? 4C 8D 47 ?? + 49 8B D6 48 8B C8 E8 ?? ?? ?? ?? 90 48 8B 54 24 ?? F2 0F 10 05 ?? ?? ?? ?? F2 0F 11 + 85 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 48 8D 4C 24 ?? 48 83 FA ?? 48 + 0F 47 4C 24 ?? FF 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 + 85 C0 75 ?? FF 15 ?? ?? ?? ?? 8B D0 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 4C 24 + ?? E8 ?? ?? ?? ?? 4C 8B 44 24 ?? 49 83 F8 ?? 76 ?? 49 FF C0 48 8B 54 24 ?? 48 8D 4C + 24 ?? E8 ?? ?? ?? ?? 4C 89 6C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? 48 8B + 4C 24 ?? 4C 89 6C 24 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 85 DB 75 ?? 48 8D 15 ?? ?? + ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? + ?? ?? 48 89 05 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 89 05 + ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 89 05 ?? ?? ?? ?? 48 + 8D 15 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 89 05 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? + ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 89 05 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8B CB FF + 15 ?? ?? ?? ?? 48 89 05 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8B CB FF 15 + } + $parse_firefox_configuration_p3 = { + 4C 8B 7D ?? 49 8B C4 49 2B C7 48 83 F8 ?? 0F 82 ?? ?? ?? ?? 4C 8D 65 ?? 48 83 7D ?? + ?? 4C 0F 47 65 ?? 4C 89 6C 24 ?? 0F 57 C0 0F 11 44 24 ?? 0F 57 C9 F3 0F 7F 4D ?? 4D + 8D 77 ?? BB ?? ?? ?? ?? 48 8D 7C 24 ?? 48 8D 44 24 ?? 48 89 85 ?? ?? ?? ?? 8D 4B ?? + E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 4C 24 ?? 48 89 08 4C 89 68 ?? 48 89 44 24 + ?? 4C 3B F3 76 ?? 49 8B DE 48 83 CB ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 3B D8 76 ?? + 48 8B D8 EB ?? 48 83 FB ?? B8 ?? ?? ?? ?? 48 0F 42 D8 48 8D 4B ?? E8 ?? ?? ?? ?? 48 + 8B F8 48 89 44 24 ?? 4C 89 75 ?? 48 89 5D ?? 4D 8B C7 49 8B D4 48 8B CF E8 ?? ?? ?? + ?? 42 C7 04 3F ?? ?? ?? ?? 42 C6 04 37 ?? C7 44 24 ?? ?? ?? ?? ?? 48 8B 05 ?? ?? ?? + ?? 48 8D 4C 24 ?? 48 83 7D ?? ?? 48 0F 47 4C 24 ?? FF D0 4C 8B 75 ?? 48 8B 5D ?? 49 + 3B DE 0F 84 ?? ?? ?? ?? 48 83 C3 ?? 0F 1F 40 ?? 48 8D 43 ?? 48 8D 4D ?? 48 3B C8 74 + ?? 48 8B D3 48 83 7B ?? ?? 76 ?? 48 8B 13 4C 8B 43 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 48 + 8D 53 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? + ?? 49 C7 C0 ?? ?? ?? ?? 0F 1F 40 ?? 49 FF C0 42 80 3C 00 ?? 75 ?? 48 8B D0 48 8D 4D + ?? E8 ?? ?? ?? ?? 48 8D 53 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? + 48 8B C8 E8 ?? ?? ?? ?? 49 C7 C0 ?? ?? ?? ?? 0F 1F 44 00 ?? 49 FF C0 42 80 3C 00 ?? + 75 ?? 48 8B D0 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 7E ?? 48 3B 7E ?? 74 ?? 48 + 89 BD ?? ?? ?? ?? 48 8D 55 ?? 48 8B CF E8 ?? ?? ?? ?? 90 48 8D 4F ?? 48 8D 55 ?? E8 + ?? ?? ?? ?? 90 48 8D 4F ?? 48 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B 56 ?? 4C 8B + C2 48 8B CE E8 ?? ?? ?? ?? 48 83 46 ?? ?? EB ?? 4C 8D 45 ?? 48 8B D7 48 8B CE E8 ?? + ?? ?? ?? 48 83 C3 ?? 48 8D 43 ?? 49 3B C6 0F 85 ?? ?? ?? ?? 48 8D 4C 24 + } + $collect_browser_passwords_p1 = { + 48 89 5C 24 ?? 55 56 57 41 54 41 55 41 56 41 57 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? + ?? ?? ?? 0F 29 B4 24 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 85 ?? ?? ?? ?? + 48 63 DA 48 8B F9 48 89 4D ?? C7 44 24 ?? ?? ?? ?? ?? 0F 57 C0 0F 11 01 0F 11 41 ?? + 45 33 ED 4C 89 29 4C 89 69 ?? 4C 89 69 ?? 4C 89 69 ?? 41 8D 4D ?? E8 ?? ?? ?? ?? 4C + 89 68 ?? 48 89 07 48 89 38 C7 44 24 ?? ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 + 8D 0C 9B 4C 8D 05 ?? ?? ?? ?? 49 8D 50 ?? 48 8D 14 CA 49 83 7C C8 ?? ?? 76 ?? 48 8B + 12 4D 8B 44 C8 ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8B D0 48 8D 4D ?? E8 ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B 45 ?? 49 83 F8 ?? 76 ?? 49 FF C0 + 48 8B 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 12 00 F3 0F 7F 45 ?? C6 45 + ?? ?? 48 8B 4D ?? 4C 89 6D ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? + ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 48 8D 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 8B CB E8 ?? + ?? ?? ?? 4C 8B E0 4C 89 6D ?? 4C 89 6D ?? 0F 57 C0 0F 11 45 ?? 0F 57 C9 F3 0F 7F 4D + ?? 41 B8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 4C 89 6D ?? + 48 8D 4D ?? 48 83 7D ?? ?? 48 0F 47 4D ?? 48 8D 55 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? + 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B D8 48 8B 4D ?? FF 15 + ?? ?? ?? ?? 48 8B D0 48 8B CB E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? + 48 8D 55 ?? 48 83 7D ?? ?? 48 0F 47 55 ?? 4C 89 6C 24 ?? 4C 8D 4D ?? 41 B8 ?? ?? ?? + ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? EB ?? 48 8B 4D ?? + FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 66 0F 1F 84 00 ?? ?? 00 00 33 D2 48 8B + 4D ?? FF 15 ?? ?? ?? ?? 4C 8B F8 BA ?? ?? ?? ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? 48 8B + } + $collect_browser_passwords_p2 = { + F0 BA ?? ?? ?? ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? 4C 8B F0 BA ?? ?? ?? ?? 48 8B 4D ?? + FF 15 ?? ?? ?? ?? 48 8B D8 BA ?? ?? ?? ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? BA ?? ?? ?? + ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 C7 C0 ?? ?? ?? ?? + 48 FF C0 80 3C 03 ?? 75 ?? 48 83 F8 ?? 0F 86 ?? ?? ?? ?? 41 0F 10 34 24 4C 89 6C 24 + ?? 0F 57 C0 0F 11 44 24 ?? 4C 89 6C 24 ?? 4C 89 6C 24 ?? 49 C7 C0 ?? ?? ?? ?? 66 0F + 1F 44 00 ?? 49 FF C0 42 80 3C 03 ?? 75 ?? 48 8B D3 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 0F + 29 74 24 ?? 4C 8D 44 24 ?? 48 8D 54 24 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 15 ?? + ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B C8 49 8B D7 E8 ?? ?? ?? ?? 48 8B + C8 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B C8 + 48 8B D6 E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 8B C8 49 8B D6 E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8D + 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 55 ?? 48 83 7D ?? ?? 48 0F + 47 55 ?? 4C 8B 45 ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8B C8 E8 ?? + ?? ?? ?? 49 C7 C0 ?? ?? ?? ?? 49 FF C0 42 80 3C 06 ?? 75 ?? 48 8B D6 48 8D 4D ?? E8 + ?? ?? ?? ?? 49 C7 C0 ?? ?? ?? ?? 49 FF C0 43 80 3C 06 ?? 75 ?? 49 8B D6 48 8D 4D ?? + E8 ?? ?? ?? ?? 48 8D 55 ?? 48 83 7D ?? ?? 48 0F 47 55 ?? 4C 8B 45 ?? 48 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 8B 5F ?? 48 3B 5F ?? 74 ?? 48 89 5C 24 ?? 48 8D 55 ?? 48 8B + } + $collect_browser_passwords_p3 = { + CB E8 ?? ?? ?? ?? 90 48 8D 4B ?? 48 8D 55 ?? E8 ?? ?? ?? ?? 90 48 8D 4B ?? 48 8D 95 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B 57 ?? 4C 8B C2 48 8B CF E8 ?? ?? ?? ?? 48 83 47 + ?? ?? EB ?? 4C 8D 45 ?? 48 8B D3 48 8B CF E8 ?? ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? ?? + ?? 4C 8B 45 ?? 49 83 F8 ?? 76 ?? 49 FF C0 48 8B 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 4C + 89 6D ?? 48 C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 48 8B 4D ?? 4C 89 6D ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? ?? ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? 83 F8 ?? + 0F 84 ?? ?? ?? ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? 49 8B CC E8 ?? ?? ?? + ?? 90 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B 45 ?? 49 83 F8 ?? 76 ?? 49 FF C0 48 8B 55 ?? + 48 8D 4D ?? E8 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 12 00 48 8B 4D ?? F3 0F 7F 45 ?? C6 45 + ?? ?? 4C 89 6D ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B + 45 ?? 49 83 F8 ?? 76 ?? 49 FF C0 48 8B 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 66 0F 6F 05 + ?? ?? 12 00 48 8B 4D ?? F3 0F 7F 45 ?? C6 45 ?? ?? 4C 89 6D ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B 45 ?? 49 83 F8 ?? 76 ?? 49 FF C0 48 8B + 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 12 00 48 8B 4D ?? F3 0F 7F 45 ?? + C6 45 ?? ?? 4C 89 6D ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B C7 48 8B 8D ?? ?? ?? + ?? 48 33 CC E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 0F 28 B4 24 ?? ?? ?? ?? 48 81 C4 + ?? ?? ?? ?? 41 5F 41 5E 41 5D 41 5C 5F 5E 5D C3 + } + $collect_cookies_p1 = { + 48 89 5C 24 ?? 55 56 57 41 54 41 55 41 56 41 57 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? + ?? ?? ?? 0F 29 B4 24 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 85 ?? ?? ?? ?? + 48 63 DA 4C 8B F1 48 89 4D ?? C7 44 24 ?? ?? ?? ?? ?? 0F 57 C0 0F 11 01 0F 11 41 ?? + 33 FF 48 89 39 48 89 79 ?? 48 89 79 ?? 48 89 79 ?? 8D 4F ?? E8 ?? ?? ?? ?? 48 89 78 + ?? 49 89 06 4C 89 30 C7 44 24 ?? ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 0C + 9B 4C 8D 05 ?? ?? ?? ?? 49 8D 50 ?? 48 8D 14 CA 49 83 7C C8 ?? ?? 76 ?? 48 8B 12 4D + 8B 44 C8 ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8B D0 48 8D 4D ?? E8 ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B 45 ?? 49 83 F8 ?? 76 ?? 49 FF C0 48 8B + 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 12 00 F3 0F 7F 45 ?? C6 45 ?? ?? + 48 8B 4D ?? 48 89 7D ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? ?? ?? + 84 C0 0F 84 ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 7D ?? 48 89 7D ?? + 0F 57 C0 0F 11 45 ?? 0F 57 C9 F3 0F 7F 4D ?? 41 B8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? + 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 89 7D ?? 48 8D 4D ?? 48 83 7D ?? ?? 48 0F 47 4D ?? + 48 8D 55 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 48 8B D8 48 8B 4D ?? FF 15 ?? ?? ?? ?? 48 8B D0 48 8B CB E8 ?? ?? ?? + ?? 48 8B C8 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 55 ?? 48 83 7D ?? ?? 48 0F 47 55 ?? + 48 89 7C 24 ?? 4C 8D 4D ?? 41 B8 ?? ?? ?? ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? 85 C0 74 + ?? 48 8D 15 ?? ?? ?? ?? EB ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? + ?? 0F 1F 80 ?? ?? ?? ?? 33 D2 48 8B 4D ?? FF 15 ?? ?? ?? ?? 48 8B F0 BA ?? ?? ?? ?? + 48 8B 4D ?? FF 15 ?? ?? ?? ?? 48 8B F8 BA ?? ?? ?? ?? 48 8B 4D ?? FF 15 + } + $collect_cookies_p2 = { + 4C 8B F8 BA ?? ?? ?? ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? 48 8B D8 BA ?? ?? ?? ?? 48 8B + 4D ?? FF 15 ?? ?? ?? ?? 4C 8B E0 BA ?? ?? ?? ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? 44 8B + E8 48 85 F6 75 ?? 48 85 FF 75 ?? 48 85 DB 0F 84 ?? ?? ?? ?? 48 C7 C1 ?? ?? ?? ?? 48 + FF C1 80 3C 0E ?? 75 ?? 48 85 C9 75 ?? 48 C7 C0 ?? ?? ?? ?? 0F 1F 84 00 ?? ?? ?? ?? + 48 FF C0 80 3C 07 ?? 75 ?? 48 85 C0 75 ?? 48 C7 C0 ?? ?? ?? ?? 48 FF C0 80 3C 03 ?? + 75 ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 45 85 ED 0F 8E ?? ?? + ?? ?? 48 C7 C0 ?? ?? ?? ?? 48 FF C0 80 3C 03 ?? 75 ?? 48 83 F8 ?? 0F 86 ?? ?? ?? ?? + 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B C8 48 8B D6 E8 ?? ?? + ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 48 8B C8 48 8B D7 E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8B 44 24 ?? 0F 10 30 + 45 33 ED 4C 89 6C 24 ?? 0F 57 C0 0F 11 44 24 ?? 4C 89 6C 24 ?? 4C 89 6C 24 ?? 49 C7 + C0 ?? ?? ?? ?? 0F 1F 80 ?? ?? ?? ?? 49 FF C0 46 38 2C 03 75 ?? 48 8B D3 48 8D 4C 24 + ?? E8 ?? ?? ?? ?? 0F 29 74 24 ?? 4C 8D 44 24 ?? 48 8D 54 24 ?? 48 8D 4D ?? E8 ?? ?? + ?? ?? 90 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 55 ?? 48 83 + 7D ?? ?? 48 0F 47 55 ?? 4C 8B 45 ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? + 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B C8 49 8B D7 E8 ?? ?? + ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 48 8B C8 49 8B D4 E8 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8B C8 E8 + } + $collect_cookies_p3 = { + 49 C7 C0 ?? ?? ?? ?? 90 49 FF C0 42 80 3C 06 ?? 75 ?? 48 8B D6 48 8D 4D ?? E8 ?? ?? + ?? ?? 49 C7 C0 ?? ?? ?? ?? 0F 1F 00 49 FF C0 42 80 3C 07 ?? 75 ?? 48 8B D7 48 8D 4D + ?? E8 ?? ?? ?? ?? 49 C7 C0 ?? ?? ?? ?? 0F 1F 00 49 FF C0 43 80 3C 07 ?? 75 ?? 49 8B + D7 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 49 C7 C0 ?? ?? ?? ?? 49 FF C0 43 80 3C 04 ?? + 75 ?? 49 8B D4 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 55 ?? 48 83 7D ?? ?? 48 0F + 47 55 ?? 4C 8B 45 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 49 8B 56 ?? 4C 8D 45 ?? 49 3B 56 ?? + 74 ?? E8 ?? ?? ?? ?? 49 8B 56 ?? 4C 8B C2 49 8B CE E8 ?? ?? ?? ?? 49 81 46 ?? ?? ?? + ?? ?? EB ?? 49 8B CE E8 ?? ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B 45 ?? 49 83 + F8 ?? 76 ?? 49 FF C0 48 8B 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 89 6D ?? 48 C7 45 ?? + ?? ?? ?? ?? C6 45 ?? ?? 48 8B 4D ?? 4C 89 6D ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 + 8D 4D ?? E8 ?? ?? ?? ?? 48 8B 4D ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 33 + FF 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B 45 ?? 49 83 F8 ?? 76 ?? 49 FF C0 48 8B 55 ?? 48 + 8D 4D ?? E8 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 12 00 48 8B 4D ?? F3 0F 7F 45 ?? C6 45 ?? + ?? 48 89 7D ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B 45 + ?? 49 83 F8 ?? 76 ?? 49 FF C0 48 8B 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 66 0F 6F 05 ?? + ?? 12 00 48 8B 4D ?? F3 0F 7F 45 ?? C6 45 ?? ?? 48 89 7D ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 90 49 8B C6 48 8B 8D ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? + ?? 0F 28 B4 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5E 41 5D 41 5C 5F 5E 5D C3 + } + + condition: + uint16(0)==0x5A4D and (($network_communication) and ( all of ($find_sensitive_files_p*)) and ( all of ($parse_firefox_configuration_p*)) and ( all of ($collect_browser_passwords_p*)) and ( all of ($collect_cookies_p*))) +} +rule REVERSINGLABS_Win32_Infostealer_Multigrainpos : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects MultigrainPOS infostealer." + author = "ReversingLabs" + id = "595c04af-802f-556d-b22b-23cac79b256e" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/infostealer/Win32.Infostealer.MultigrainPOS.yara#L1-L88" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "9808c95b850a54677c4132057b8372cabf0159920b7e0e6834a83f0d39c088fa" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Infostealer" + tc_detection_name = "MultigrainPOS" + tc_detection_factor = 5 + importance = 25 + + strings: + $data_exfiltration_v10_1 = { + 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 8B 1D ?? ?? ?? ?? 56 57 8B 3D ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 6A ?? 8D 4D ?? 51 6A ?? 6A ?? 8D 45 ?? 0F + 43 45 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 85 C0 75 ?? 8B 45 ?? 50 8B 70 ?? FF D7 81 + FE ?? ?? ?? ?? 74 ?? 81 FE ?? ?? ?? ?? 75 ?? 83 7D ?? ?? 5F 5E 5B 72 ?? FF 75 ?? E8 + ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 33 CD B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B E5 5D C2 ?? ?? + FF 75 ?? FF D7 68 ?? ?? ?? ?? FF D3 EB + } + $memory_scraping_v10_1 = { + 6A ?? 56 8B CF E8 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? 56 8B CF E8 ?? ?? ?? ?? 8B 8D ?? ?? + ?? ?? EB ?? 3C ?? 7C ?? 3C ?? 7E ?? 8A 46 ?? 3C ?? 7C ?? 3C ?? 7E ?? 3C ?? 74 + } + $process_search_v10_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 68 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? + 85 C0 74 ?? 8B 3D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF D7 85 C0 74 ?? 8B 1D ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 50 FF D3 85 C0 74 ?? 8D + 85 ?? ?? ?? ?? 50 56 FF D7 85 C0 75 + } + $service_creation_v10_1 = { + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 8D 4C 24 ?? C7 44 24 ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 33 C0 5E 8B 4C 24 ?? 33 CC E8 ?? ?? + ?? ?? 8B E5 5D C3 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D6 8D 44 24 ?? 50 C7 44 24 ?? + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + FF 15 + } + $process_search_v11_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 8B 7D ?? FF 15 ?? + ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? EB ?? 8D 49 ?? 68 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 6A ?? + FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? FF D3 EB ?? 8D 8D + ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 33 C0 68 ?? ?? ?? ?? 50 66 89 + 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C9 EB ?? 8D A4 24 ?? + ?? ?? ?? EB ?? 8D 49 ?? 0F B7 84 0D ?? ?? ?? ?? 66 89 84 0D ?? ?? ?? ?? 8D 49 ?? 66 + 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 + } + $memory_scraping_v11_1 = { + 6A ?? 56 8B CF E8 ?? ?? ?? ?? 6A ?? 56 8B CF E8 ?? ?? ?? ?? EB ?? 3C ?? 75 ?? 6A ?? + 56 8B CF E8 ?? ?? ?? ?? 6A ?? 56 8B CF E8 + } + $data_exfiltration_v11_1 = { + 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 8A 5D ?? 56 57 8B 3D ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 6A ?? 8D 4D ?? 51 6A ?? 6A ?? 8D 45 ?? 0F 43 45 ?? + 6A ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 85 C0 75 ?? 8B 45 ?? 50 8B 70 ?? FF D7 81 FE ?? ?? + ?? ?? 74 ?? 81 FE ?? ?? ?? ?? 74 ?? 84 DB 74 ?? 33 F6 83 7D ?? ?? 72 ?? FF 75 ?? E8 + ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 5F 8B C6 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C2 ?? ?? + FF 75 ?? FF D7 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 84 DB 74 ?? EB ?? BE ?? ?? ?? ?? EB + } + $service_creation_v11_1 = { + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 8D 4C 24 ?? C7 44 24 ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 33 C0 8B 4C 24 ?? 33 CC E8 ?? ?? ?? + ?? 8B E5 5D C3 8D 44 24 ?? 50 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 + } + + condition: + uint16(0)==0x5A4D and (($data_exfiltration_v10_1 and $memory_scraping_v10_1 and $process_search_v10_1 and $service_creation_v10_1) or ($process_search_v11_1 and $memory_scraping_v11_1 and $data_exfiltration_v11_1 and $service_creation_v11_1)) +} rule REVERSINGLABS_Win32_Infostealer_Lumarstealer : TC_DETECTION MALICIOUS MALWARE FILE { meta: @@ -201,8 +1136,8 @@ rule REVERSINGLABS_Win32_Infostealer_Lumarstealer : TC_DETECTION MALICIOUS MALWA date = "2023-12-07" modified = "2023-12-07" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/infostealer/Win32.Infostealer.LumarStealer.yara#L1-L190" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/infostealer/Win32.Infostealer.LumarStealer.yara#L1-L190" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0bc9e12396b1e85f69b965e9ea50960c59c50aba40317fb4de8f6abd092ec7d2" score = 75 quality = 90 @@ -367,141 +1302,6 @@ rule REVERSINGLABS_Win32_Infostealer_Lumarstealer : TC_DETECTION MALICIOUS MALWA condition: uint16(0)==0x5A4D and ( all of ($collect_os_information_p*)) and ( all of ($send_data_to_c2_p*)) and ( all of ($find_files_p*)) and ( all of ($find_crypto_wallets_*)) } -rule REVERSINGLABS_Win32_Infostealer_Multigrainpos : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects MultigrainPOS infostealer." - author = "ReversingLabs" - id = "595c04af-802f-556d-b22b-23cac79b256e" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/infostealer/Win32.Infostealer.MultigrainPOS.yara#L1-L88" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "9808c95b850a54677c4132057b8372cabf0159920b7e0e6834a83f0d39c088fa" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Infostealer" - tc_detection_name = "MultigrainPOS" - tc_detection_factor = 5 - importance = 25 - - strings: - $data_exfiltration_v10_1 = { - 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 8B 1D ?? ?? ?? ?? 56 57 8B 3D ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 6A ?? 8D 4D ?? 51 6A ?? 6A ?? 8D 45 ?? 0F - 43 45 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 85 C0 75 ?? 8B 45 ?? 50 8B 70 ?? FF D7 81 - FE ?? ?? ?? ?? 74 ?? 81 FE ?? ?? ?? ?? 75 ?? 83 7D ?? ?? 5F 5E 5B 72 ?? FF 75 ?? E8 - ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 33 CD B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B E5 5D C2 ?? ?? - FF 75 ?? FF D7 68 ?? ?? ?? ?? FF D3 EB - } - $memory_scraping_v10_1 = { - 6A ?? 56 8B CF E8 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? 56 8B CF E8 ?? ?? ?? ?? 8B 8D ?? ?? - ?? ?? EB ?? 3C ?? 7C ?? 3C ?? 7E ?? 8A 46 ?? 3C ?? 7C ?? 3C ?? 7E ?? 3C ?? 74 - } - $process_search_v10_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 68 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? - 85 C0 74 ?? 8B 3D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF D7 85 C0 74 ?? 8B 1D ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 50 FF D3 85 C0 74 ?? 8D - 85 ?? ?? ?? ?? 50 56 FF D7 85 C0 75 - } - $service_creation_v10_1 = { - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 8D 4C 24 ?? C7 44 24 ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 33 C0 5E 8B 4C 24 ?? 33 CC E8 ?? ?? - ?? ?? 8B E5 5D C3 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D6 8D 44 24 ?? 50 C7 44 24 ?? - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - FF 15 - } - $process_search_v11_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 8B 7D ?? FF 15 ?? - ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? EB ?? 8D 49 ?? 68 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 6A ?? - FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? FF D3 EB ?? 8D 8D - ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 33 C0 68 ?? ?? ?? ?? 50 66 89 - 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C9 EB ?? 8D A4 24 ?? - ?? ?? ?? EB ?? 8D 49 ?? 0F B7 84 0D ?? ?? ?? ?? 66 89 84 0D ?? ?? ?? ?? 8D 49 ?? 66 - 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 - } - $memory_scraping_v11_1 = { - 6A ?? 56 8B CF E8 ?? ?? ?? ?? 6A ?? 56 8B CF E8 ?? ?? ?? ?? EB ?? 3C ?? 75 ?? 6A ?? - 56 8B CF E8 ?? ?? ?? ?? 6A ?? 56 8B CF E8 - } - $data_exfiltration_v11_1 = { - 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 8A 5D ?? 56 57 8B 3D ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 6A ?? 8D 4D ?? 51 6A ?? 6A ?? 8D 45 ?? 0F 43 45 ?? - 6A ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 85 C0 75 ?? 8B 45 ?? 50 8B 70 ?? FF D7 81 FE ?? ?? - ?? ?? 74 ?? 81 FE ?? ?? ?? ?? 74 ?? 84 DB 74 ?? 33 F6 83 7D ?? ?? 72 ?? FF 75 ?? E8 - ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 5F 8B C6 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C2 ?? ?? - FF 75 ?? FF D7 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 84 DB 74 ?? EB ?? BE ?? ?? ?? ?? EB - } - $service_creation_v11_1 = { - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 8D 4C 24 ?? C7 44 24 ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 33 C0 8B 4C 24 ?? 33 CC E8 ?? ?? ?? - ?? 8B E5 5D C3 8D 44 24 ?? 50 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 - } - - condition: - uint16(0)==0x5A4D and (($data_exfiltration_v10_1 and $memory_scraping_v10_1 and $process_search_v10_1 and $service_creation_v10_1) or ($process_search_v11_1 and $memory_scraping_v11_1 and $data_exfiltration_v11_1 and $service_creation_v11_1)) -} -rule REVERSINGLABS_Win32_Infostealer_Stealc : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects StealC infostealer." - author = "ReversingLabs" - id = "b53bbf15-3e94-513c-91a9-83dda421063b" - date = "2023-06-07" - modified = "2023-06-07" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/infostealer/Win32.Infostealer.StealC.yara#L1-L57" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "bea1cf370150387eb185deff726e10e660e7eb571c20d22878def08b36f457bf" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Infostealer" - tc_detection_name = "StealC" - tc_detection_factor = 5 - importance = 25 - - strings: - $resolve_windows_api = { - 55 8B EC 51 83 65 ?? ?? 56 64 A1 ?? ?? ?? ?? 8B 40 ?? 8B 40 ?? 8B 00 8B 00 8B 40 ?? - 89 45 ?? 8B 75 ?? 89 35 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? - ?? ?? ?? A3 ?? ?? ?? ?? 56 FF D0 FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 - } - $load_sqlite3_functions = { - 55 8B EC 83 EC ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 50 89 45 ?? 89 4D ?? 8B 4D ?? 8D - 45 ?? 50 89 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8D 45 ?? 57 89 45 ?? 8B 7D ?? - B9 ?? ?? ?? ?? 33 C0 F3 AA 5F 33 C0 C9 C3 8B 45 ?? 85 C0 74 ?? 53 8B 58 ?? 56 8B 70 - ?? FF 35 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B C6 E8 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? - A3 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B C6 E8 ?? ?? - ?? ?? FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? A3 - } - $check_license_expiration_date = { - 55 8B EC 83 E4 ?? 83 EC ?? 57 33 C0 66 89 44 24 ?? 83 64 24 ?? ?? 8D 7C 24 ?? AB AB - AB 66 AB 33 C0 66 89 44 24 ?? 8D 7C 24 ?? AB AB AB 66 AB 33 C0 21 44 24 ?? 8D 7C 24 - ?? AB 8D 7C 24 ?? AB 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8D 7C 24 ?? E8 ?? ?? ?? ?? 8D - 4C 24 ?? 51 8D 4C 24 ?? 51 8D 4C 24 ?? 51 FF 35 ?? ?? ?? ?? FF 30 FF 15 ?? ?? ?? ?? - 8B 44 24 ?? 83 C4 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? - 8D 44 24 ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 3B 44 24 ?? 72 ?? 77 ?? - 8B 44 24 ?? 3B 44 24 ?? 76 ?? 6A ?? FF 15 ?? ?? ?? ?? 5F 8B E5 5D C3 - } - - condition: - uint16(0)==0x5A4D and ($resolve_windows_api) and ($load_sqlite3_functions) and ($check_license_expiration_date) -} rule REVERSINGLABS_Win32_Infostealer_Projecthookpos : TC_DETECTION MALICIOUS MALWARE FILE { meta: @@ -511,8 +1311,8 @@ rule REVERSINGLABS_Win32_Infostealer_Projecthookpos : TC_DETECTION MALICIOUS MAL date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/infostealer/Win32.Infostealer.ProjectHookPOS.yara#L1-L98" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/infostealer/Win32.Infostealer.ProjectHookPOS.yara#L1-L98" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b7534c9e905256aaf80f04b746a92c50689437b288f7e393ef13fde1740c4a4e" score = 75 quality = 90 @@ -597,874 +1397,127 @@ rule REVERSINGLABS_Win32_Infostealer_Projecthookpos : TC_DETECTION MALICIOUS MAL condition: uint16(0)==0x5A4D and ($calc_luhn and $track_1_reverse and $check_validity_1 and $encode_and_send_1 and $form_create_1 and $form_create_2 and $form_create_3) } -rule REVERSINGLABS_Win32_Trojan_Emotet : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Infostealer_Stealc : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Emotet trojan." + description = "Yara rule that detects StealC infostealer." author = "ReversingLabs" - id = "9742743d-753a-582b-9701-7278c8ed0e4e" - date = "2021-11-16" - modified = "2021-11-16" + id = "b53bbf15-3e94-513c-91a9-83dda421063b" + date = "2023-06-07" + modified = "2023-06-07" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/trojan/Win32.Trojan.Emotet.yara#L1-L182" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "747d603c9849a66782c95050a4a634ffdb4ce2882adcfc5d63e1f1ea1651b25e" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/infostealer/Win32.Infostealer.StealC.yara#L1-L57" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "bea1cf370150387eb185deff726e10e660e7eb571c20d22878def08b36f457bf" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" status = "RELEASED" sharing = "TLP:WHITE" category = "MALWARE" - tc_detection_type = "Trojan" - tc_detection_name = "Emotet" + tc_detection_type = "Infostealer" + tc_detection_name = "StealC" tc_detection_factor = 5 importance = 25 strings: - $decrypt_resource_v1 = { - 55 8B EC 83 EC ?? 53 8B D9 8B C2 56 57 89 45 ?? 8B 3B 33 F8 8B C7 89 7D ?? 83 E0 ?? - 75 ?? 8D 77 ?? EB ?? 8B F7 2B F0 83 C6 ?? 8D 0C 36 E8 ?? ?? ?? ?? 8B D0 89 55 ?? 85 - D2 74 ?? 83 65 ?? ?? 8D 43 ?? 83 65 ?? ?? C1 EE ?? 8D 0C B0 8B F2 8B D9 2B D8 83 C3 - ?? C1 EB ?? 3B C1 0F 47 5D ?? 85 DB 74 ?? 8B 55 ?? 8B F8 8B 0F 8D 7F ?? 33 CA 0F B6 - C1 66 89 06 8B C1 C1 E8 ?? 8D 76 ?? 0F B6 C0 66 89 46 ?? C1 E9 ?? 0F B6 C1 66 89 46 - ?? C1 E9 ?? 0F B6 C1 66 89 46 ?? 8B 45 ?? 40 89 45 ?? 3B C3 72 ?? 8B 7D ?? 8B 55 ?? - 33 C0 66 89 04 7A 5F 5E 8B C2 5B 8B E5 5D C3 - } - $generate_filename_v1 = { - 56 57 33 C0 BF ?? ?? ?? ?? 57 50 50 6A ?? 50 FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 8B F0 56 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? - ?? 83 C4 ?? 8B CE 5F 5E E9 - } - $decrypt_resource_v2 = { - 55 8B EC 83 EC ?? 8B 41 ?? 8B 11 33 C2 53 56 8D 71 ?? 89 55 ?? 8D 58 ?? 89 45 ?? 83 - C6 ?? F6 C3 ?? 74 ?? 83 E3 ?? 83 C3 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? - 8B C8 E8 ?? ?? ?? ?? FF D0 8D 14 1B B9 ?? ?? ?? ?? 52 6A ?? 50 E8 ?? ?? ?? ?? BA ?? - ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? FF D0 89 45 ?? 85 C0 74 ?? C1 EB ?? 8B C8 57 33 C0 8D - 14 9E 33 DB 8B FA 2B FE 83 C7 ?? C1 EF ?? 3B F2 0F 47 F8 85 FF 74 ?? 8B 16 8D 49 ?? - 33 55 ?? 8D 76 ?? 0F B6 C2 43 66 89 41 ?? 8B C2 C1 E8 ?? 0F B6 C0 66 89 41 ?? C1 EA - ?? 0F B6 C2 66 89 41 ?? C1 EA ?? 0F B6 C2 66 89 41 ?? 3B DF 72 ?? 8B 45 ?? 33 D2 8B - 4D ?? 5F 66 89 14 41 8B C1 5E 5B 8B E5 5D C3 - } - $generate_filename_v2 = { - 55 8B EC 81 EC ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 51 6A ?? B9 ?? ?? ?? ?? - E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? FF D0 85 C0 0F 88 ?? ?? ?? ?? 56 - B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B F0 8D 85 ?? ?? ?? ?? 8D [1-5] 51 - 51 50 56 8D [1-5] 68 ?? ?? ?? ?? 51 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B - C8 E8 ?? ?? ?? ?? FF D0 83 C4 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 - E8 ?? ?? ?? ?? FF D0 56 6A ?? 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 - E8 ?? ?? ?? ?? FF D0 B8 ?? ?? ?? ?? 5E 8B E5 5D C3 33 C0 8B E5 5D C3 - } - $decrypt_resource_v3 = { - 56 8B F1 BA [6-9] B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF D0 56 6A ?? 50 68 ?? ?? ?? ?? - BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF D0 5E C3 - } - $generate_filename_v3 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B F1 8B FA 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? BB ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 8D 85 ?? ?? ?? ?? BB ?? ?? ?? ?? 8B D3 56 50 BE ?? ?? ?? ?? [2-5] 8B CE E8 ?? - ?? ?? ?? 59 FF D0 57 8D 85 ?? ?? ?? ?? 8B D3 50 [2-5] 8B CE E8 ?? ?? ?? ?? 59 FF D0 - 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 - ?? ?? ?? ?? 89 45 ?? B8 ?? ?? ?? ?? 66 89 45 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 59 FF D0 F7 D8 5F 1B C0 5E 40 5B 8B E5 5D C3 - } - $decrypt_resource_v4 = { - 56 57 8B FA E8 ?? ?? ?? ?? 8B F0 A1 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? - ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 56 FF D0 8B 0D ?? ?? ?? ?? - 89 44 B9 ?? A1 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? - 8B C8 E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF D0 8B F8 A1 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? - ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 56 6A ?? 57 - FF D0 5F 5E C3 - } - $generate_filename_snippet_v4 = { - A1 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? - ?? ?? ?? A3 ?? ?? ?? ?? 56 53 FF D0 A1 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? E8 ?? - ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 56 FF D0 5F 5E 33 C9 8D - 04 43 66 89 08 5D 5B 59 C3 - } - $decrypt_resource_snippet_v5 = { - C1 EE ?? 33 C0 55 33 ED 8B D3 8D 0C B7 8B F1 2B F7 83 C6 ?? C1 EE ?? 3B F9 0F 47 F0 - 85 F6 74 ?? 8B 5C 24 ?? 8B 0F 8D 7F ?? 33 CB 0F B6 C1 66 89 02 8B C1 C1 E8 ?? 8D 52 - ?? 0F B6 C0 66 89 42 ?? C1 E9 ?? 0F B6 C1 C1 E9 ?? 45 66 89 42 ?? 0F B6 C1 66 89 42 - ?? 3B EE 72 ?? 8B 5C 24 ?? 8B 44 24 ?? 33 C9 5D 66 89 0C 43 5F 5E 8B C3 5B 83 C4 ?? - C3 - } - $decrypt_resource_snippet_v6 = { - C1 EE ?? 33 C0 55 33 ED 8B D3 8D 0C B7 8B F1 2B F7 83 C6 ?? C1 EE ?? 3B F9 0F 47 F0 - 85 F6 74 ?? 8B 5C 24 ?? 8B 0F 8D 7F ?? 33 CB 88 0A 8B C1 C1 E8 ?? 8D 52 ?? C1 E9 ?? - 88 42 ?? 88 4A ?? C1 E9 ?? 45 88 4A ?? 3B EE 72 ?? 8B 5C 24 ?? 8B 44 24 ?? 5D C6 04 - 03 ?? 5F 5E 8B C3 5B 83 C4 ?? C3 - } - $liblzf_decompression_1 = { - 83 EC ?? 8B 44 24 ?? 53 55 8D 2C 11 89 4C 24 ?? 8B 54 24 ?? 33 DB 03 C2 89 6C 24 ?? - 56 89 44 24 ?? 0F B6 41 ?? 8D 72 ?? 0F B6 11 C1 E2 ?? 0B D0 8D 45 ?? 89 44 24 ?? 57 - 8B F9 3B C8 0F 83 ?? ?? ?? ?? 0F B6 47 ?? C1 E2 ?? 0B D0 6B C2 ?? 8B CA C1 E9 ?? 33 - CA 89 54 24 ?? 8B 54 24 ?? C1 E9 ?? 2B C8 8B 44 24 ?? 81 E1 ?? ?? ?? ?? 8B 2C 88 8B - C7 2B 44 24 ?? 03 6C 24 ?? 89 04 8A 8B C7 8B 54 24 ?? 2B C5 48 89 44 24 ?? 3D ?? ?? - ?? ?? 0F 8D ?? ?? ?? ?? 3B EA 0F 86 ?? ?? ?? ?? 8A 45 ?? 3A 47 ?? 0F 85 ?? ?? ?? ?? - 0F B6 55 ?? 8D 4F ?? 0F B6 45 ?? 89 4C 24 ?? 0F B6 09 C1 E2 ?? 0B D0 C1 E1 ?? 0F B6 - 07 0B C8 3B D1 0F 85 ?? ?? ?? ?? 8B 44 24 ?? B9 ?? ?? ?? ?? 2B C7 3B C1 6A ?? 0F 47 - C1 89 44 24 ?? 8D 46 ?? 5A 3B 44 24 ?? 72 ?? 33 C9 8B C6 85 DB 0F 94 C1 2B C1 83 C0 - ?? 3B 44 24 ?? 0F 83 ?? ?? ?? ?? 8B C6 8D 4B ?? 2B C3 88 48 ?? 33 C0 85 DB 8B 5C 24 - ?? 0F 94 C0 2B F0 83 FB ?? 0F 86 ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 0F 85 ?? ?? - ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 0F 85 ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 0F 85 - ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 0F 85 ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 - } - $liblzf_decompression_2 = { - 0F 85 ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 0F 85 ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A - 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 - ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 - ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? - 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8D 0C 3A 2B EF 42 41 3B D3 - 73 ?? 8A 04 29 3A 01 74 ?? 8B 5C 24 ?? 83 EA ?? 83 FA ?? 73 ?? 8B CB 8A C2 C1 F9 ?? - C0 E0 ?? 02 C8 88 0E 46 EB ?? 8B C3 C1 F8 ?? 2C ?? 88 06 8D 42 ?? 88 46 ?? 83 C6 ?? - 8B 7C 24 ?? 8B 44 24 ?? 47 88 1E 03 FA 33 DB 83 C6 ?? 3B F8 72 ?? 8B 6C 24 ?? 8D 46 - ?? 3B 44 24 ?? 76 ?? 33 C0 EB ?? 3B 74 24 ?? 73 ?? 8A 07 43 88 06 46 8B 44 24 ?? 47 - 83 FB ?? 75 ?? C6 46 ?? ?? 33 DB 46 3B F8 73 ?? 8B 54 24 ?? E9 ?? ?? ?? ?? 8A 07 43 - 88 06 46 47 83 FB ?? 75 ?? C6 46 ?? ?? 33 DB 46 3B FD 72 ?? 8B CE 8D 53 ?? 2B CB 88 - 51 ?? 33 C9 85 DB 0F 94 C1 2B F1 2B 74 24 ?? 8B C6 5F 5E 5D 5B 83 C4 ?? C3 + $resolve_windows_api = { + 55 8B EC 51 83 65 ?? ?? 56 64 A1 ?? ?? ?? ?? 8B 40 ?? 8B 40 ?? 8B 00 8B 00 8B 40 ?? + 89 45 ?? 8B 75 ?? 89 35 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? + ?? ?? ?? A3 ?? ?? ?? ?? 56 FF D0 FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 } - $decrypt_resource_snippet_v7 = { - C1 EE ?? 3B F9 0F 47 F0 85 F6 74 ?? 8B 5C 24 ?? 8B 0F 8D 7F ?? 33 CB 0F B6 C1 66 89 - 02 8B C1 C1 E8 ?? 8D 52 ?? 0F B6 C0 66 89 42 ?? C1 E9 ?? 0F B6 C1 C1 E9 ?? 45 66 89 - 42 ?? 0F B6 C1 66 89 42 ?? 3B EE 72 ?? 8B 5C 24 ?? 8B 44 24 ?? 33 C9 5D 66 89 0C 43 - 5F 5E 8B C3 5B 83 C4 ?? C3 + $load_sqlite3_functions = { + 55 8B EC 83 EC ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 50 89 45 ?? 89 4D ?? 8B 4D ?? 8D + 45 ?? 50 89 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8D 45 ?? 57 89 45 ?? 8B 7D ?? + B9 ?? ?? ?? ?? 33 C0 F3 AA 5F 33 C0 C9 C3 8B 45 ?? 85 C0 74 ?? 53 8B 58 ?? 56 8B 70 + ?? FF 35 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B C6 E8 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? + A3 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B C6 E8 ?? ?? + ?? ?? FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? A3 } - $state_machine_snippet_v7 = { - 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B - 94 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 8D 84 24 - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B 54 24 ?? - 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 8D 94 - 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF 74 24 - ?? 8B F0 FF B4 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? F7 DE 8B 94 24 ?? ?? ?? ?? 1B F6 - 81 E6 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? - ?? ?? ?? 8B 94 24 ?? ?? ?? ?? 8B 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 + $check_license_expiration_date = { + 55 8B EC 83 E4 ?? 83 EC ?? 57 33 C0 66 89 44 24 ?? 83 64 24 ?? ?? 8D 7C 24 ?? AB AB + AB 66 AB 33 C0 66 89 44 24 ?? 8D 7C 24 ?? AB AB AB 66 AB 33 C0 21 44 24 ?? 8D 7C 24 + ?? AB 8D 7C 24 ?? AB 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8D 7C 24 ?? E8 ?? ?? ?? ?? 8D + 4C 24 ?? 51 8D 4C 24 ?? 51 8D 4C 24 ?? 51 FF 35 ?? ?? ?? ?? FF 30 FF 15 ?? ?? ?? ?? + 8B 44 24 ?? 83 C4 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? + 8D 44 24 ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 3B 44 24 ?? 72 ?? 77 ?? + 8B 44 24 ?? 3B 44 24 ?? 76 ?? 6A ?? FF 15 ?? ?? ?? ?? 5F 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($decrypt_resource_v1 and $generate_filename_v1) or ($decrypt_resource_v2 and $generate_filename_v2) or ($decrypt_resource_v3 and $generate_filename_v3) or ($decrypt_resource_v4 and $generate_filename_snippet_v4) or ($decrypt_resource_snippet_v5 and all of ($liblzf_decompression_*)) or ($decrypt_resource_snippet_v6 and all of ($liblzf_decompression_*)) or ($decrypt_resource_snippet_v7 and $state_machine_snippet_v7) + uint16(0)==0x5A4D and ($resolve_windows_api) and ($load_sqlite3_functions) and ($check_license_expiration_date) } -rule REVERSINGLABS_Win32_Trojan_Hermeticwiper : TC_DETECTION MALICIOUS MALWARE FILE +import "pe" + +rule REVERSINGLABS_Cert_Blocklist_05E2E6A4Cd09Ea54D665B075Fe22A256 : INFO FILE { meta: - description = "Yara rule that detects HermeticWiper trojan." + description = "The digital certificate has leaked." author = "ReversingLabs" - id = "252dfb3d-9d4e-51a4-80c9-64e17922d997" - date = "2022-02-24" - modified = "2022-02-24" + id = "824c6b2f-081a-5f38-b949-d802f59e6ced" + date = "2023-11-08" + modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/trojan/Win32.Trojan.HermeticWiper.yara#L1-L50" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0fa519ce8285ffe4e49c2a301e8a0fd0516a05dc6b41ee0b010fdc76dd6e195e" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L27-L43" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "43da21d9c7ae9bfcc7fe4ee69f9d46cbce1954785d56c1d424b36deb8afe592e" score = 75 quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + tags = "INFO, FILE" status = "RELEASED" sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Trojan" - tc_detection_name = "HermeticWiper" - tc_detection_factor = 5 + category = "INFO" importance = 25 - strings: - $corrupt_physical_drive = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 51 68 ?? ?? ?? ?? 0F 57 C0 89 55 ?? 8D 85 ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 33 F6 66 0F D6 45 ?? 33 FF 89 75 ?? 50 0F - 11 45 ?? 89 7D ?? 0F 11 45 ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 8D 55 ?? 8D 8D ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? - BF ?? ?? ?? ?? 57 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8B F0 8D 45 ?? - 50 57 56 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? - 75 ?? 66 0F 1F 44 00 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 81 C7 ?? ?? - ?? ?? 33 F6 81 FF ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 57 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 57 56 6A ?? 6A ?? 68 ?? - ?? ?? ?? 53 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 85 F6 0F 84 ?? ?? ?? - ?? 8B 06 C7 45 ?? ?? ?? ?? ?? 83 F8 ?? 74 ?? 85 C0 74 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? - 83 7E ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 55 ?? 8D 46 ?? 89 45 ?? 66 90 - 8B 00 85 C0 74 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 52 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 8B F8 89 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 8B 45 ?? 6A ?? 6A ?? FF 70 ?? FF 70 - ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 57 53 FF - 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 55 ?? 81 FA ?? ?? ?? ?? 72 ?? 66 83 7F ?? - ?? 75 ?? 85 D2 0F B7 C2 B9 ?? ?? ?? ?? 0F 45 C8 66 89 4F ?? 8B 45 ?? FF 70 ?? FF 70 - ?? FF 75 ?? FF 75 ?? 57 53 FF 55 ?? 8B 55 ?? 8B 4D ?? 8B 45 ?? 41 05 ?? ?? ?? ?? 89 - 4D ?? 89 45 ?? 3B 4E ?? 0F 82 ?? ?? ?? ?? 8B 7D ?? EB ?? FF 15 ?? ?? ?? ?? 33 FF 85 - DB 74 ?? 83 FB ?? 74 ?? 53 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 85 F6 74 ?? 56 6A ?? - FF D3 8B 35 ?? ?? ?? ?? 50 FF D6 EB ?? FF 15 ?? ?? ?? ?? 8B 7D ?? EB ?? 33 C0 5F 5E - 5B 8B E5 5D C2 ?? ?? 8B 35 ?? ?? ?? ?? 85 FF 74 ?? 57 6A ?? FF D3 50 FF D6 8B 45 ?? - 5F 5E 5B 8B E5 5D C2 - } + condition: + uint16(0)==0x5A4D and for any i in (0..pe.number_of_signatures) : (pe.signatures[i].subject contains "*.google.com" and pe.signatures[i].serial=="05:e2:e6:a4:cd:09:ea:54:d6:65:b0:75:fe:22:a2:56" and 1308182400<=pe.signatures[i].not_after) +} +import "pe" + +rule REVERSINGLABS_Cert_Blocklist_77019A082385E4B73F569569C9F87Bb8 : INFO FILE +{ + meta: + description = "Certificate used for digitally signing malware." + author = "ReversingLabs" + id = "4046a31b-d7c8-5c63-b5b2-2179b0817b03" + date = "2023-11-08" + modified = "2023-11-08" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L45-L61" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "8613986005bdd30d92e633fa2058be5c43f1c530b9dc6d80ec953f12f6d66ce7" + score = 75 + quality = 90 + tags = "INFO, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "INFO" + importance = 25 condition: - uint16(0)==0x5A4D and ($corrupt_physical_drive) + uint16(0)==0x5A4D and for any i in (0..pe.number_of_signatures) : (pe.signatures[i].subject contains "AND LLC" and pe.signatures[i].serial=="77:01:9a:08:23:85:e4:b7:3f:56:95:69:c9:f8:7b:b8" and 1308182400<=pe.signatures[i].not_after) } -rule REVERSINGLABS_Win32_Trojan_Bibiwiper : TC_DETECTION MALICIOUS MALWARE FILE +import "pe" + +rule REVERSINGLABS_Cert_Blocklist_4F2Ef29Ca5F96E5777B82C62F34Fd3A6 : INFO FILE { meta: - description = "Yara rule that detects BiBiWiper trojan." + description = "The digital certificate has leaked." author = "ReversingLabs" - id = "8462ceb8-ec54-5f92-a3e7-c96e52647ca7" - date = "2023-11-28" - modified = "2023-11-28" + id = "6cfb6ae0-8eba-503b-8bb7-ac72746d9aa2" + date = "2023-11-08" + modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/trojan/Win32.Trojan.BiBiWiper.yara#L1-L102" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "d75954c05a8f82ad90a4adf6a2a3748928488ddebe40d8f8a790bfcde0b02a11" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L63-L79" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "e8f27c4a72f416a16acabb1de606fdde7dc694256809fdb952a25313dda0d34e" score = 75 quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + tags = "INFO, FILE" status = "RELEASED" sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Trojan" - tc_detection_name = "BiBiWiper" - tc_detection_factor = 5 - importance = 25 - - strings: - $delete_shadow_copies_p1 = { - 48 89 5C 24 ?? 55 48 8D 6C 24 ?? 48 81 EC ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 - 48 89 45 ?? 33 DB 48 C7 44 24 ?? ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 5C 24 ?? 48 - 8D 4C 24 ?? 48 89 5C 24 ?? 44 8D 43 ?? E8 ?? ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 - ?? 48 8B 54 24 ?? 48 0F 43 4C 24 ?? 48 03 D1 48 8D 4C 24 ?? 48 83 7C 24 ?? ?? 48 0F - 43 4C 24 ?? E8 ?? ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 ?? 48 8D 55 ?? 48 0F 43 4C - 24 ?? 48 2B D1 0F B6 01 88 04 0A 48 8D 49 ?? 84 C0 75 ?? 0F 57 C0 C7 44 24 ?? ?? ?? - ?? ?? 48 8D 45 ?? 45 33 C9 48 89 44 24 ?? 48 8D 55 ?? 48 8D 44 24 ?? 45 33 C0 48 89 - 44 24 ?? 33 C9 48 89 5C 24 ?? 48 89 5C 24 ?? 0F 11 45 ?? C7 44 24 ?? ?? ?? ?? ?? 89 - 5C 24 ?? 0F 11 44 24 ?? 66 89 5D ?? 0F 11 45 ?? 0F 11 45 ?? 0F 11 45 ?? 0F 11 45 ?? - FF 15 ?? ?? ?? ?? 48 8B 54 24 ?? 48 83 FA ?? 72 ?? 48 8B 4C 24 ?? 48 FF C2 48 8B C1 - 48 81 FA ?? ?? ?? ?? 72 ?? 48 8B 49 ?? 48 83 C2 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? - 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 5C 24 ?? 48 8D 15 ?? ?? ?? - ?? 48 89 5C 24 ?? 48 8D 4C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 83 7C - 24 ?? ?? 48 8D 4C 24 ?? 48 8B 54 24 ?? 48 0F 43 4C 24 ?? 48 03 D1 48 8D 4C 24 ?? 48 - 83 7C 24 ?? ?? 48 0F 43 4C 24 ?? E8 ?? ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 ?? 48 - 8D 55 ?? 48 0F 43 4C 24 ?? 48 2B D1 0F B6 01 88 04 0A 48 8D 49 ?? 84 C0 75 ?? 0F 57 - C0 C7 44 24 ?? ?? ?? ?? ?? 48 8D 45 ?? 45 33 C9 48 89 44 24 ?? 48 8D 55 ?? 48 8D 44 - 24 ?? 45 33 C0 48 89 44 24 ?? 33 C9 48 89 5C 24 ?? 48 89 5C 24 ?? 0F 11 45 ?? C7 44 - 24 ?? ?? ?? ?? ?? 89 5C 24 ?? 0F 11 44 24 ?? 66 89 5D ?? 0F 11 45 ?? 0F 11 45 ?? 0F - } - $delete_shadow_copies_p2 = { - 11 45 ?? 0F 11 45 ?? FF 15 ?? ?? ?? ?? 48 8B 54 24 ?? 48 83 FA ?? 72 ?? 48 8B 4C 24 - ?? 48 FF C2 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 8B 49 ?? 48 83 C2 ?? 48 2B C1 48 - 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 5C 24 - ?? 48 8D 15 ?? ?? ?? ?? 48 89 5C 24 ?? 48 8D 4C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 ?? 48 8B 54 24 ?? 48 0F 43 4C 24 ?? 48 03 - D1 48 8D 4C 24 ?? 48 83 7C 24 ?? ?? 48 0F 43 4C 24 ?? E8 ?? ?? ?? ?? 48 83 7C 24 ?? - ?? 48 8D 4C 24 ?? 48 8D 55 ?? 48 0F 43 4C 24 ?? 48 2B D1 90 0F B6 01 88 04 0A 48 8D - 49 ?? 84 C0 75 ?? 0F 57 C0 C7 44 24 ?? ?? ?? ?? ?? 48 8D 45 ?? 45 33 C9 48 89 44 24 - ?? 48 8D 55 ?? 48 8D 44 24 ?? 45 33 C0 48 89 44 24 ?? 33 C9 48 89 5C 24 ?? 48 89 5C - 24 ?? 0F 11 45 ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? 0F 11 44 24 ?? 66 89 5D ?? 0F - 11 45 ?? 0F 11 45 ?? 0F 11 45 ?? 0F 11 45 ?? FF 15 ?? ?? ?? ?? 48 8B 54 24 ?? 48 83 - FA ?? 72 ?? 48 8B 4C 24 ?? 48 FF C2 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 8B 49 ?? - 48 83 C2 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 B8 - ?? ?? ?? ?? 48 89 5C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 89 5C 24 ?? 48 8D 4C 24 ?? 48 C7 - 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 ?? 48 8B 54 24 ?? - 48 0F 43 4C 24 ?? 48 03 D1 48 8D 4C 24 ?? 48 83 7C 24 ?? ?? 48 0F 43 4C 24 ?? E8 ?? - ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 ?? 48 8D 55 ?? 48 0F 43 4C 24 ?? 48 2B D1 90 - 0F B6 01 88 04 0A 48 8D 49 ?? 84 C0 75 ?? 0F 57 C0 C7 44 24 ?? ?? ?? ?? ?? 48 8D 45 - ?? 45 33 C9 48 89 44 24 ?? 48 8D 55 ?? 48 8D 44 24 ?? 45 33 C0 48 89 44 24 ?? 33 C9 - 48 89 5C 24 ?? 48 89 5C 24 ?? 0F 11 45 ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 - } - $destroy_files_p1 = { - 48 89 5C 24 ?? 55 56 57 41 54 41 55 41 56 41 57 48 83 EC ?? 48 8B 05 ?? ?? ?? ?? 48 - 33 C4 48 89 44 24 ?? 4D 8B E9 4D 8B E0 4C 8B F9 48 63 BC 24 ?? ?? ?? ?? 33 F6 89 74 - 24 ?? 48 8B 05 ?? ?? ?? ?? 48 FF C0 48 89 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 B8 - ?? ?? ?? ?? ?? ?? ?? ?? 48 F7 E9 48 C1 FA ?? 48 8B C2 48 C1 E8 ?? 48 03 D0 48 69 C2 - ?? ?? ?? ?? 48 3B C8 75 ?? 4C 8B 05 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8D 0D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 C1 E3 ?? 33 D2 49 8B C4 49 F7 F5 48 - 8B E8 48 2B EB 83 FF ?? 7E ?? 48 8D 47 ?? 48 0F AF C3 33 D2 49 F7 F4 EB ?? 48 8B D6 - 45 33 C0 49 8B CF E8 ?? ?? ?? ?? 49 8B CF E8 ?? ?? ?? ?? 48 63 C8 49 3B CC 0F 87 ?? - ?? ?? ?? 49 8B C4 48 2B C1 49 8B FC 48 2B F9 48 3B D8 48 0F 42 FB 48 8B CF E8 ?? ?? - ?? ?? 48 89 44 24 ?? 0F 57 C0 4C 63 F7 F3 0F 7F 44 24 ?? 48 89 74 24 ?? 85 FF 74 ?? - 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 4C 3B F0 0F 87 ?? ?? ?? ?? 49 81 FE ?? ?? ?? ?? 72 - } - $destroy_files_p2 = { - 49 8D 4E ?? 49 3B CE 0F 86 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B C8 48 85 C0 0F 84 ?? ?? - ?? ?? 48 83 C0 ?? 48 83 E0 ?? 48 89 48 ?? EB ?? 49 8B CE E8 ?? ?? ?? ?? 48 89 44 24 - ?? 4A 8D 1C 30 48 89 5C 24 ?? 4D 8B C6 33 D2 48 8B C8 E8 ?? ?? ?? ?? 48 89 5C 24 ?? - C7 44 24 ?? ?? ?? ?? ?? 85 FF 7E ?? 48 8B DE 44 8B F7 66 0F 1F 44 00 ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 88 04 0B 48 8D 5B ?? 49 83 EE ?? 75 ?? 4D 85 ED 7E - ?? 4D 8B CF 41 B8 ?? ?? ?? ?? 48 8B D7 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 49 8B CF E8 ?? - ?? ?? ?? 48 63 C8 48 8D 04 29 48 03 C7 49 3B C4 76 ?? 49 8B FC 48 2B F9 48 2B FD 48 - 85 FF 7E ?? 41 B8 ?? ?? ?? ?? 48 8B D5 49 8B CF E8 ?? ?? ?? ?? FF C6 48 63 C6 49 3B - C5 7C ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8B 4C 24 ?? 48 85 C9 74 ?? 48 8B 54 24 - ?? 48 2B D1 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 - 83 C0 ?? 48 83 F8 ?? 77 ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 33 CC E8 ?? ?? ?? ?? 48 - 8B 9C 24 ?? ?? ?? ?? 48 83 C4 ?? 41 5F 41 5E 41 5D 41 5C 5F 5E 5D C3 - } - - condition: - uint16(0)==0x5A4D and ( all of ($delete_shadow_copies_p*)) and ( all of ($destroy_files_p*)) -} -rule REVERSINGLABS_Win32_Trojan_Isaacwiper : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects IsaacWiper trojan." - author = "ReversingLabs" - id = "c0924e5e-a942-57a3-a9f9-e6be6efa4c73" - date = "2022-03-02" - modified = "2022-03-02" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/trojan/Win32.Trojan.IsaacWiper.yara#L1-L76" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "c9fa43f44c33816a66f61255d101294da63df1afc5a27ed5817072040cd1eec5" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Trojan" - tc_detection_name = "IsaacWiper" - tc_detection_factor = 5 - importance = 25 - - strings: - $enumerate_physical_drives = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 33 F6 89 55 ?? 57 89 4D ?? B3 ?? C7 45 ?? ?? ?? ?? - ?? 89 75 ?? 84 DB 0F 84 ?? ?? ?? ?? 8B D6 8D 4D ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? - ?? ?? 6A ?? 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? D1 E8 8D - 8D ?? ?? ?? ?? BF ?? ?? ?? ?? 89 45 ?? 2B F8 83 C4 ?? 66 83 7D ?? ?? 8D 0C 41 8D 45 - ?? 74 ?? 83 C0 ?? 66 83 38 ?? 75 ?? 8D 55 ?? 2B C2 D1 F8 8D 04 45 ?? ?? ?? ?? 50 8B - C2 8D 14 3F 50 E8 ?? ?? ?? ?? D1 E8 83 C4 ?? 3B C7 8D 48 ?? 0F 46 C1 8B 4D ?? 03 C8 - 89 4D ?? 83 F9 ?? 73 ?? 8B 3D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? - 6A ?? 68 ?? ?? ?? ?? 50 B3 ?? FF D7 83 F8 ?? 74 ?? 46 50 89 75 ?? FF 15 ?? ?? ?? ?? - E9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 32 DB E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 83 - ?? ?? ?? ?? 0F B7 85 ?? ?? ?? ?? 66 85 C0 0F 95 C1 66 85 C0 0F 84 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 66 89 45 ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? D1 E8 8D 4D ?? BE ?? ?? ?? ?? 89 45 ?? 2B F0 83 C4 ?? 66 83 - 7D ?? ?? 8D 0C 41 8D 45 ?? 74 ?? 83 C0 ?? 66 83 38 ?? 75 ?? 8D 55 ?? 2B C2 D1 F8 8D - 04 45 ?? ?? ?? ?? 50 8B C2 8D 14 36 50 E8 ?? ?? ?? ?? D1 E8 83 C4 ?? 3B C6 8D 48 ?? - 0F 46 C1 8B 4D ?? 03 C8 89 4D ?? 83 F9 ?? 0F 83 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? - 6A ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 FF D7 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? 6A ?? 8D 45 - ?? C7 45 ?? ?? ?? ?? ?? 50 6A ?? 8D 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 56 FF 15 ?? - ?? ?? ?? 83 F8 ?? 0F 94 C3 75 ?? 33 C0 83 7D ?? ?? 0F 44 45 ?? 89 45 ?? 56 FF 15 ?? - ?? ?? ?? 84 DB EB ?? 84 C9 0F 84 ?? ?? ?? ?? 8B 5D ?? 8B D3 8B 4D ?? 6A ?? E8 ?? ?? - ?? ?? 8B 7D ?? 8A C8 83 C4 ?? 33 F6 84 C9 74 ?? 3B F3 74 ?? 6A ?? 8B D6 8B CF E8 ?? - ?? ?? ?? 8A C8 83 C4 ?? 46 83 C7 ?? 84 C9 75 ?? 46 84 C9 74 ?? 8B 5D ?? 3B F3 73 ?? - 6A ?? 8B D6 8B CF E8 ?? ?? ?? ?? 8A C8 83 C4 ?? 46 83 C7 ?? 84 C9 75 ?? 8A C1 5F 5E - 5B 8B E5 5D C3 - } - $corrupt_drive_thread = { - 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 8B 5D ?? 56 57 85 DB 0F 84 ?? ?? - ?? ?? 83 7B ?? ?? 0F 85 ?? ?? ?? ?? 8B 43 ?? 8D 4C 24 ?? 03 C0 BA ?? ?? ?? ?? 50 53 - E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 C4 ?? D1 E8 33 C9 66 89 4C 44 ?? 8D 44 24 ?? 50 - FF D7 8B 35 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 6A ?? 8D 44 24 ?? 50 - FF 15 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 66 83 7C 24 ?? ?? 8D 44 24 - ?? 74 ?? 90 83 C0 ?? 66 83 38 ?? 75 ?? 8D 4C 24 ?? BA ?? ?? ?? ?? 2B C1 D1 F8 8D 04 - 45 ?? ?? ?? ?? 50 8B C1 8D 8C 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? - ?? ?? ?? 50 FF D7 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 6A ?? 6A ?? 6A ?? - 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 89 74 24 - ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 8B 7B ?? 8B 5B ?? C7 44 24 ?? ?? ?? ?? ?? 85 DB 75 ?? - 81 FF ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 89 84 24 ?? ?? ?? ?? B8 ?? ?? ?? ?? 8B 8C 84 ?? ?? ?? ?? 8B D1 C1 EA ?? 33 D1 69 - CA ?? ?? ?? ?? 03 C8 89 8C 84 ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? BA ?? ?? ?? ?? 8D - B4 24 ?? ?? ?? ?? 89 94 24 ?? ?? ?? ?? 0F 1F 80 ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 75 ?? - 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 94 24 ?? ?? ?? ?? 8B 8C 94 ?? ?? ?? ?? 8B C1 - C1 E8 ?? 42 33 C8 89 94 24 ?? ?? ?? ?? 8B C1 25 ?? ?? ?? ?? C1 E0 ?? 33 C8 8B C1 25 - ?? ?? ?? ?? C1 E0 ?? 33 C8 8B C1 C1 E8 ?? 33 C1 89 06 83 C6 ?? 8D 84 24 ?? ?? ?? ?? - 3B F0 72 ?? 8B 74 24 ?? 8D 44 24 ?? 6A ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 - 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 44 24 ?? 3D ?? ?? ?? ?? 75 ?? 2B F8 83 DB ?? E9 - ?? ?? ?? ?? 8B C7 0B C3 74 ?? 57 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 - 24 ?? 6A ?? 50 57 8D 84 24 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? - 5F 5E 33 C0 5B 8B E5 5D C2 - } - - condition: - uint16(0)==0x5A4D and ($enumerate_physical_drives and $corrupt_drive_thread) -} -rule REVERSINGLABS_Win32_Trojan_Caddywiper : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects CaddyWiper trojan." - author = "ReversingLabs" - id = "ad437f29-4ad8-5a88-a0b6-03de55e7375f" - date = "2022-03-15" - modified = "2022-03-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/trojan/Win32.Trojan.CaddyWiper.yara#L1-L95" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "178ff4171c09866f6b303bdff234beff1116d268995ee4dc236332e472d645b1" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Trojan" - tc_detection_name = "CaddyWiper" - tc_detection_factor = 5 - importance = 25 - - strings: - $destroy_if_not_controller = { - 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 83 39 ?? 75 ?? EB ?? 8D 55 ?? 52 FF 55 ?? - C6 45 ?? 43 C6 45 ?? 3A C6 45 ?? 5C C6 45 ?? 55 C6 45 ?? 73 C6 45 ?? 65 C6 45 ?? 72 - C6 45 ?? 73 C6 45 ?? 00 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? C6 45 ?? ?? - C6 45 ?? ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 4D ?? 83 C1 ?? 89 4D ?? 83 7D - ?? ?? 73 ?? 8D 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8A 45 ?? 04 ?? 88 45 ?? EB ?? E8 ?? - ?? ?? ?? 8B E5 5D C3 - } - $erase_drive_data = { - C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8D 4D ?? 89 8D ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? - 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 95 ?? ?? ?? ?? 89 45 ?? 83 - 7D ?? ?? 74 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? 51 68 ?? ?? ?? ?? 8B 55 ?? 52 FF 55 ?? 8B 45 ?? 50 FF 55 ?? 8A 4D ?? 88 4D ?? 8A - 55 ?? 80 EA ?? 88 55 ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 E9 ?? 89 8D ?? ?? ?? - ?? 85 C0 0F 85 ?? ?? ?? ?? 8B E5 5D C3 - } - $erase_drives_recursively_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? FF FF FF FF C6 85 ?? ?? ?? ?? 2A C6 85 - ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 5C C6 85 ?? ?? ?? ?? 00 8D 85 ?? ?? ?? ?? 50 8B 4D - ?? 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? - ?? ?? 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? 00 00 00 00 - C6 85 ?? ?? ?? ?? 46 C6 85 ?? ?? ?? ?? 69 C6 85 ?? ?? ?? ?? 6E C6 85 ?? ?? ?? ?? 64 - C6 85 ?? ?? ?? ?? 46 C6 85 ?? ?? ?? ?? 69 C6 85 ?? ?? ?? ?? 72 C6 85 ?? ?? ?? ?? 73 - C6 85 ?? ?? ?? ?? 74 C6 85 ?? ?? ?? ?? 46 C6 85 ?? ?? ?? ?? 69 C6 85 ?? ?? ?? ?? 6C - C6 85 ?? ?? ?? ?? 65 C6 85 ?? ?? ?? ?? 41 C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 6B - C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 65 C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 72 - C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 6E C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 65 - C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 6C C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 33 - C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 32 C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 2E - C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 64 C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 6C - C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 6C C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 00 - C6 85 ?? ?? ?? ?? 00 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 E8 - } - $erase_drives_recursively_2_p1 = { - 8D 45 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 8D 95 ?? - ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? - ?? ?? 75 ?? E9 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 E1 ?? 0F 84 ?? ?? ?? ?? 0F BE 95 ?? - ?? ?? ?? 83 FA ?? 75 ?? 0F BE 85 ?? ?? ?? ?? 85 C0 74 ?? 0F BE 8D ?? ?? ?? ?? 83 F9 - ?? 75 ?? E9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 E2 ?? 75 ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? - 74 ?? E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 - E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 8D 95 ?? ?? - ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8D 95 ?? - ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 - } - $erase_drives_recursively_2_p2 = { - C0 75 ?? E9 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? 51 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? E9 ?? - ?? ?? ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? - ?? ?? ?? 73 ?? E9 ?? ?? ?? ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 76 ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 6A ?? FF 95 ?? ?? ?? - ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 - ?? 6A ?? 6A ?? 6A ?? 8B 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? - 51 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 FF 95 ?? ?? ?? ?? - 8B 95 ?? ?? ?? ?? 52 FF 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 55 ?? 8D 8D ?? ?? ?? - ?? 51 8B 95 ?? ?? ?? ?? 52 FF 95 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 50 FF 95 ?? ?? ?? ?? 8B E5 5D C3 - } - - condition: - uint16(0)==0x5A4D and ($destroy_if_not_controller) and ($erase_drive_data) and ( all of ($erase_drives_recursively_*)) -} -rule REVERSINGLABS_Linux_Trojan_Acidrain : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects AcidRain trojan." - author = "ReversingLabs" - id = "802c7eb7-d407-5b07-a6b4-4648d3ad80e9" - date = "2024-05-10" - modified = "2024-05-10" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/trojan/Linux.Trojan.AcidRain.yara#L1-L67" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "5b47a0de8bda09d217f8a148e561f3da7ce4945f011f4a9b5dbbca88157d3080" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Trojan" - tc_detection_name = "AcidRain" - tc_detection_factor = 5 - importance = 25 - - strings: - $destroy_files_using_ioctls = { - 55 89 E5 57 BF ?? ?? ?? ?? 56 53 81 EC ?? ?? ?? ?? 89 7C 24 ?? 8B 45 ?? 89 04 24 E8 - ?? ?? ?? ?? 85 C0 89 C3 78 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 25 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 81 C4 ?? ?? ?? ?? 5B 5E 5F 5D - C3 8D 45 ?? BE ?? ?? ?? ?? 89 44 24 ?? 89 74 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 4D ?? - 8B 55 ?? C7 45 ?? ?? ?? ?? ?? 85 C9 89 55 ?? 74 ?? 8D 75 ?? 8D B6 ?? ?? ?? ?? 8D BF - ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 74 24 ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? B8 ?? ?? - ?? ?? 89 74 24 ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 01 D0 39 45 - ?? 89 45 ?? 77 ?? 81 FA ?? ?? ?? ?? BF ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 45 ?? C7 45 - ?? ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 75 ?? EB ?? 31 C9 89 4C 24 ?? 8B 45 ?? 89 - 1C 24 89 44 24 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 7C 24 ?? 89 1C 24 89 44 24 ?? E8 - ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 01 D0 39 45 ?? 89 45 ?? 76 ?? B8 ?? ?? ?? ?? 89 74 24 - ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 74 24 ?? 89 44 24 ?? 89 1C - 24 E8 ?? ?? ?? ?? 80 7D ?? ?? 75 ?? A1 ?? ?? ?? ?? 89 7D ?? 89 45 ?? 8B 45 ?? 89 45 - ?? 8D 45 ?? 89 44 24 ?? B8 ?? ?? ?? ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 55 ?? - 8B 45 ?? 01 D0 39 45 ?? 89 45 ?? 77 ?? 8D 74 26 ?? 8D BC 27 ?? ?? ?? ?? 31 FF 89 1C - 24 E8 ?? ?? ?? ?? 31 C0 89 44 24 ?? 89 7C 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 75 ?? C7 - 45 ?? ?? ?? ?? ?? 85 F6 74 ?? 8D 75 ?? 8D 76 ?? B9 ?? ?? ?? ?? 89 74 24 ?? 89 4C 24 - ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 01 D0 39 45 ?? 89 45 ?? 77 ?? 89 1C 24 - E8 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 5B 5E 5F 5D C3 - } - $destroy_files_using_overwrite = { - 55 89 E5 83 EC ?? 89 5D ?? 8B 5D ?? 8D 45 ?? 89 75 ?? 89 7D ?? C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 5D ?? 8B 75 - ?? 8B 7D ?? 89 EC 5D C3 - } - $redundant_reboot_attempts = { - C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F - 84 ?? ?? ?? ?? 8D B6 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 85 C0 0F - 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 8D 76 ?? 0F 84 ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 04 - 24 E8 ?? ?? ?? ?? 31 D2 83 C4 ?? 89 D0 59 5B 5E 5F 5D 8D 61 ?? C3 - } - - condition: - uint32(0)==0x464C457F and ($destroy_files_using_ioctls) and ($destroy_files_using_overwrite) and ($redundant_reboot_attempts) -} -rule REVERSINGLABS_Linux_Trojan_Bibiwiper : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects BiBiWiper trojan." - author = "ReversingLabs" - id = "c370dde0-71ff-5832-b131-6d61beb02b9b" - date = "2023-11-28" - modified = "2023-11-28" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/trojan/Linux.Trojan.BiBiWiper.yara#L1-L76" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "8f290141d5da660463dede6df571d774448e136e2993a0a4c706245464e1239e" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Trojan" - tc_detection_name = "BiBiWiper" - tc_detection_factor = 5 - importance = 25 - - strings: - $destroy_files_p1 = { - 55 48 89 E5 53 48 81 EC ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 48 89 B5 ?? ?? ?? ?? 48 89 - 95 ?? ?? ?? ?? 48 89 8D ?? ?? ?? ?? 4C 89 85 ?? ?? ?? ?? 44 89 8D ?? ?? ?? ?? 48 8B - 05 ?? ?? ?? ?? 48 83 C0 ?? 48 89 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 BA ?? ?? ?? - ?? ?? ?? ?? ?? 48 89 C8 48 F7 EA 48 89 D0 48 C1 F8 ?? 48 89 CA 48 C1 FA ?? 48 29 D0 - 48 69 D0 ?? ?? ?? ?? 48 89 C8 48 29 D0 48 85 C0 0F 94 C0 84 C0 74 ?? E8 ?? ?? ?? ?? - 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 - D6 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? - ?? 48 8D 85 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 CE 48 89 C7 - E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 89 - CE 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? - ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8D - 8D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? ?? - 48 8D 8D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 CE 48 89 C7 E8 ?? ?? - ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 D6 48 89 C7 E8 ?? ?? ?? ?? 48 - 89 C3 48 8D 8D ?? ?? ?? ?? 48 8D 45 ?? BA ?? ?? ?? ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? - ?? 48 8D 45 ?? 48 89 DE 48 89 C7 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C7 E8 - } - $destroy_files_p2 = { - 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? - ?? ?? 48 8B 85 ?? ?? ?? ?? 48 C1 E0 ?? 48 89 45 ?? 48 8B B5 ?? ?? ?? ?? 48 8B 85 ?? - ?? ?? ?? BA ?? ?? ?? ?? 48 F7 F6 48 8B 55 ?? 48 29 D0 48 89 45 ?? 83 BD ?? ?? ?? ?? - ?? 7E ?? 8B 85 ?? ?? ?? ?? 83 E8 ?? 48 98 48 0F AF 45 ?? BA ?? ?? ?? ?? 48 F7 B5 ?? - ?? ?? ?? 48 89 D0 48 89 C1 48 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 CE 48 89 C7 E8 - ?? ?? ?? ?? EB ?? 48 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? - ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 48 39 - 85 ?? ?? ?? ?? 73 ?? BB ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 55 ?? 48 8B 85 ?? ?? ?? ?? - 48 29 D0 48 89 45 ?? 48 8B 45 ?? 48 89 45 ?? 48 8D 55 ?? 48 8D 45 ?? 48 89 D6 48 89 - C7 E8 ?? ?? ?? ?? 48 8B 00 48 89 45 ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 - ?? 48 8B 45 ?? 89 C2 48 8D 85 ?? ?? ?? ?? 89 D6 48 89 C7 E8 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 5D ?? 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 - } - $destroy_files_p3 = { - 89 C7 48 8B 85 ?? ?? ?? ?? 48 89 C1 BA ?? ?? ?? ?? 48 89 DE E8 ?? ?? ?? ?? 48 8B 85 - ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 55 ?? 48 8B 45 ?? 48 01 C2 48 - 8B 45 ?? 48 01 D0 48 39 85 ?? ?? ?? ?? 73 ?? 48 8B 55 ?? 48 8B 85 ?? ?? ?? ?? 48 29 - D0 48 8B 55 ?? 48 29 D0 48 89 45 ?? 48 83 7D ?? ?? 7E ?? 48 8B 4D ?? 48 8B 85 ?? ?? - ?? ?? BA ?? ?? ?? ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? ?? 83 45 ?? ?? 8B 45 ?? 48 98 48 - 39 85 ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? EB ?? 90 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 - 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? BB ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 - C7 E8 ?? ?? ?? ?? 83 FB ?? E9 ?? ?? ?? ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 - ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? EB ?? 48 89 - C3 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 D8 48 89 C7 E8 ?? ?? ?? ?? 48 - 89 C3 48 8D 45 ?? 48 89 C7 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 - C7 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? EB ?? - 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? - ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 D8 48 89 C7 E8 ?? ?? ?? ?? 48 8B 5D ?? C9 C3 - } - - condition: - uint32(0)==0x464C457F and ( all of ($destroy_files_p*)) -} -rule REVERSINGLABS_Win32_Trojan_Dridex : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Dridex trojan." - author = "ReversingLabs" - id = "bc68aca1-69e6-57e6-9277-70c89fda1e5d" - date = "2020-09-16" - modified = "2020-09-16" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/trojan/Win32.Trojan.Dridex.yara#L1-L80" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "7eddc8f33846dfb61302b7d7fddd8dec59a1bde05b14135c14131a02e2c19600" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Trojan" - tc_detection_name = "Dridex" - tc_detection_factor = 5 - importance = 25 - - strings: - $resolve_api_wrapper_1 = { - 56 57 8B FA 8B F1 8B CF E8 ?? ?? ?? ?? 85 C0 75 ?? 81 FE ?? ?? ?? ?? 75 ?? 33 C0 5F - 5E C3 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 8B CE E8 ?? ?? ?? ?? 84 C0 74 ?? 8B CE E8 ?? - ?? ?? ?? 85 C0 74 ?? 8B D7 ?? ?? ?? ?? E9 - } - $resolve_api_wrapper_2 = { - 57 53 8B FA 8B D9 8B CF E8 ?? ?? ?? ?? 85 C0 75 ?? 81 FB ?? ?? ?? ?? 74 ?? 8B CB E8 - ?? ?? ?? ?? 85 C0 74 ?? 8B C8 8B D7 E8 ?? ?? ?? ?? 5B 5F C3 8B CB E8 ?? ?? ?? ?? 84 - C0 74 ?? 8B CB E8 ?? ?? ?? ?? 85 C0 75 ?? 33 C0 EB - } - $resolve_api_wrapper_3 = { - 55 8B EC 57 8B 7D ?? 57 E8 ?? ?? ?? ?? 85 C0 75 ?? 56 8B 75 ?? 81 FE ?? ?? ?? ?? 74 - ?? 56 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B CE E8 ?? ?? ?? ?? 84 C0 74 ?? 56 E8 ?? ?? ?? ?? - 85 C0 75 ?? 5E 33 C0 5F 5D C2 ?? ?? 57 50 E8 ?? ?? ?? ?? 5E 5F 5D C2 - } - $resolve_api_wrapper_4 = { - 55 8B EC FF 75 ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 56 8B 75 ?? 81 FE ?? ?? ?? ?? 74 ?? 56 - E8 ?? ?? ?? ?? 85 C0 75 ?? 8B CE E8 ?? ?? ?? ?? 84 C0 74 ?? 56 E8 ?? ?? ?? ?? 85 C0 - 74 ?? 5E 89 45 ?? 5D E9 - } - $find_first_file_snippet_1 = { - 53 56 8B F1 57 33 DB 32 C9 89 5E ?? 33 FF E8 ?? ?? ?? ?? 83 38 ?? 7C ?? [4-6] BA ?? - ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 4E ?? 57 6A ?? 6A ?? 8D 56 ?? - 52 53 51 FF D0 - } - $find_first_file_snippet_2 = { - 57 53 55 8B E9 33 C9 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? - ?? 8B 18 E8 ?? ?? ?? ?? 8B C8 85 C9 74 ?? 33 D2 83 FB ?? 6A ?? 5B 8D 7D ?? 0F 4C DA - 8B C2 53 52 52 57 0F 9D C0 50 FF 75 ?? FF D1 - } - $find_first_file_snippet_3 = { - 53 56 8B F1 33 DB 57 32 C9 89 5E ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B - 38 E8 ?? ?? ?? ?? 8B D0 85 D2 74 ?? 6A ?? 33 C0 83 FF ?? 59 0F 4C C8 8D 46 ?? 51 53 - 53 50 33 C0 83 FF ?? 0F 9D C0 50 FF 76 ?? FF D2 - } - $find_first_file_snippet_4 = { - 53 56 8B F1 57 33 DB 32 C9 89 5E ?? 33 FF E8 ?? ?? ?? ?? 83 38 ?? 7C ?? 8D 7B ?? 8D - 5F ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 4E ?? 57 6A ?? 6A - ?? 8D 56 ?? 52 53 51 CC C3 - } - $find_first_file_snippet_5 = { - 56 8B F1 32 C9 57 C7 46 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 8B 38 E8 ?? ?? ?? ?? 8B D0 85 D2 74 ?? 33 C0 B9 ?? ?? ?? ?? 83 FF ?? 0F 4C C8 51 50 - 50 8D 46 ?? 50 33 C0 83 FF ?? 0F 9D C0 50 FF 76 ?? FF D2 - } - - condition: - uint16(0)==0x5A4D and ( any of ($resolve_api_wrapper_*) and any of ($find_first_file_snippet_*)) -} -rule REVERSINGLABS_Win32_Trojan_Trickbot : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects TrickBot trojan." - author = "ReversingLabs" - id = "4ed253cc-0398-542b-a2b7-c42a0b9431fb" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/trojan/Win32.Trojan.TrickBot.yara#L1-L46" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "e10f16c70f1ff7cf11d3e25f06e4c5d9e20c51688582d2b51322f768a8e06d7e" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Trojan" - tc_detection_name = "TrickBot" - tc_detection_factor = 5 - importance = 25 - - strings: - $entry_setup = { - 58 (68 | 8B) [6-8] 59 [1-3] E2 ?? 57 8B (C7 | EC) 8B (C7 | EC) 05 ?? ?? ?? ?? 68 [4-5] - 89 45 [1-2] 8B D7 [3-4] 8B C1 66 AD 85 C0 74 ?? 3B (C1 | C8) (72 | 77) ?? 2B C1 (C1 | D1) - [2-4] 8B CF 03 C8 81 C1 ?? ?? ?? ?? 8B 01 59 03 D0 52 EB ?? 89 45 ?? 8B C5 B9 ?? ?? - ?? ?? C1 E1 ?? 2B C1 8B 00 89 45 ?? 6A ?? 8B D0 59 FF D2 89 68 ?? 6A ?? 8B D0 FF D2 - } - $decrypt_function_snippet = { - 58 8B C8 75 ?? 58 2B F0 50 8B D8 49 75 ?? 59 58 59 5E 5F 5B C3 - } - $decrypt_function_snippet_wrapper = { - 55 BD ?? ?? ?? ?? 50 51 52 6A ?? FF 45 ?? 8B 45 ?? 59 F7 E1 8D 8D ?? ?? ?? ?? 03 C8 - 89 4D ?? 8F 41 ?? 8F 41 ?? 8F 41 ?? 8F 41 ?? 8F 01 89 79 ?? 89 71 ?? 8B D1 59 89 4A - ?? 55 2B C0 8B C8 8B 02 8B F8 58 41 41 41 41 50 2B C1 8B 00 3B C7 72 ?? 58 C1 E9 ?? - 49 89 4A ?? E3 ?? FF 55 ?? 8B 55 ?? 8B 4A ?? FF 55 ?? 50 51 50 6A ?? 59 FF 55 ?? FF - D0 - } - - condition: - uint16(0)==0x5A4D and $entry_setup and ($decrypt_function_snippet or $decrypt_function_snippet_wrapper) -} -rule REVERSINGLABS_Win32_Downloader_Dlmarlboro : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects dlMarlboro downloader." - author = "ReversingLabs" - id = "4c99b5a4-dc6b-579b-b1bd-bd4c93c6e68c" - date = "2020-07-23" - modified = "2020-07-23" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/downloader/Win32.Downloader.dlMarlboro.yara#L1-L79" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "465a3b3a9686889001ac0b929d0349e44b6015eaeed3386361366def5013164a" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Downloader" - tc_detection_name = "dlMarlboro" - tc_detection_factor = 3 - importance = 25 - - strings: - $ping_apnic = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 0F 57 - C0 F3 0F 7F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D - 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? - 8D 85 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $download_bin_1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 65 ?? 8B F2 8B C1 89 85 ?? - ?? ?? ?? 8B 7D ?? 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? - ?? ?? 83 EC ?? 8B CC 6A ?? 6A ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 56 C6 01 - ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? F6 84 - 05 ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? FF 50 ?? 8D 4D ?? 51 8B - C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B D7 8B C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D6 8B C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 - ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 55 - ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 55 ?? C6 - 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? F6 84 05 ?? ?? - ?? ?? ?? 74 ?? 83 EC ?? 8D 45 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? BA ?? ?? ?? - ?? 8B C8 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? B3 ?? EB ?? 32 DB - } - $download_bin_2 = { - C7 45 ?? ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? - ?? ?? 83 C4 ?? 84 DB 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 8D 80 ?? ?? ?? ?? 89 - 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 03 - C8 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 - C4 ?? 8B 8D ?? ?? ?? ?? 8B F0 85 C9 74 ?? 8B 01 FF 50 ?? 85 C0 74 ?? 8B 10 8B C8 6A - ?? FF 12 8B 06 8B CE 6A ?? 8B 40 ?? FF D0 50 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 5D ?? 83 C4 ?? 8B 7D ?? 8B 08 8B 49 ?? F6 44 01 ?? ?? 75 ?? 8B 75 ?? 8D 4D ?? - 83 FB ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? 0F 43 CF 3B F0 0F 42 C6 50 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 75 ?? 83 FE ?? 73 ?? 83 C8 ?? EB ?? 33 C0 83 FE ?? 0F 95 C0 85 C0 0F 94 - C0 84 C0 0F 94 C0 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 - E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? - ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 56 E8 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 FB ?? 72 ?? 57 E8 ?? ?? ?? ?? 83 C4 - ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 - ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 EB ?? 8B 8D ?? ?? ?? - ?? 8B 01 FF 50 ?? 8B 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? C3 8B 85 ?? ?? - ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 - 5D C3 - } - - condition: - uint16(0)==0x5A4D and $ping_apnic and $download_bin_1 and $download_bin_2 -} -import "pe" - -rule REVERSINGLABS_Cert_Blocklist_05E2E6A4Cd09Ea54D665B075Fe22A256 : INFO FILE -{ - meta: - description = "The digital certificate has leaked." - author = "ReversingLabs" - id = "824c6b2f-081a-5f38-b949-d802f59e6ced" - date = "2023-11-08" - modified = "2023-11-08" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L27-L43" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "43da21d9c7ae9bfcc7fe4ee69f9d46cbce1954785d56c1d424b36deb8afe592e" - score = 75 - quality = 90 - tags = "INFO, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "INFO" - importance = 25 - - condition: - uint16(0)==0x5A4D and for any i in (0..pe.number_of_signatures) : (pe.signatures[i].subject contains "*.google.com" and pe.signatures[i].serial=="05:e2:e6:a4:cd:09:ea:54:d6:65:b0:75:fe:22:a2:56" and 1308182400<=pe.signatures[i].not_after) -} -import "pe" - -rule REVERSINGLABS_Cert_Blocklist_77019A082385E4B73F569569C9F87Bb8 : INFO FILE -{ - meta: - description = "Certificate used for digitally signing malware." - author = "ReversingLabs" - id = "4046a31b-d7c8-5c63-b5b2-2179b0817b03" - date = "2023-11-08" - modified = "2023-11-08" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L45-L61" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "8613986005bdd30d92e633fa2058be5c43f1c530b9dc6d80ec953f12f6d66ce7" - score = 75 - quality = 90 - tags = "INFO, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "INFO" - importance = 25 - - condition: - uint16(0)==0x5A4D and for any i in (0..pe.number_of_signatures) : (pe.signatures[i].subject contains "AND LLC" and pe.signatures[i].serial=="77:01:9a:08:23:85:e4:b7:3f:56:95:69:c9:f8:7b:b8" and 1308182400<=pe.signatures[i].not_after) -} -import "pe" - -rule REVERSINGLABS_Cert_Blocklist_4F2Ef29Ca5F96E5777B82C62F34Fd3A6 : INFO FILE -{ - meta: - description = "The digital certificate has leaked." - author = "ReversingLabs" - id = "6cfb6ae0-8eba-503b-8bb7-ac72746d9aa2" - date = "2023-11-08" - modified = "2023-11-08" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L63-L79" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "e8f27c4a72f416a16acabb1de606fdde7dc694256809fdb952a25313dda0d34e" - score = 75 - quality = 90 - tags = "INFO, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "INFO" + category = "INFO" importance = 25 condition: @@ -1481,8 +1534,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Cc1Db2Ad0A290A4Bfe7A5F336D6800C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L81-L97" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L81-L97" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c9f91edb525a02041bc20dff25ec58323f8fabd4d2a2eca63238ecb10ccef2a6" score = 75 quality = 90 @@ -1506,8 +1559,8 @@ rule REVERSINGLABS_Cert_Blocklist_13C8351Aece71C731158980F575F4133 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L99-L115" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L99-L115" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f96723845adc8030b72c119311103d5c2cf136e79de226d31141d8b925ce8e75" score = 75 quality = 90 @@ -1531,8 +1584,8 @@ rule REVERSINGLABS_Cert_Blocklist_4531954F6265304055F66Ce4F624F95B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L117-L133" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L117-L133" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "58d3a2a5e3f6730f329bddb171ad6332794fa95848825b892c3b8324f503ae89" score = 75 quality = 90 @@ -1556,8 +1609,8 @@ rule REVERSINGLABS_Cert_Blocklist_0E808F231515Bc519Eea1A73Cdf3266F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L135-L151" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L135-L151" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "05e466e304ed7a8f5c1c93aac4a4b7019d6fb1e07aeb45d078b657f838d1f3bd" score = 75 quality = 90 @@ -1581,8 +1634,8 @@ rule REVERSINGLABS_Cert_Blocklist_36Be4Ad457F062Fa77D87595B8Ccc8Cf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L153-L169" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L153-L169" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d19a6f22a1e702a4da69c867195722adf8f1dd84539f2c584af428fe4b1caf79" score = 75 quality = 90 @@ -1606,8 +1659,8 @@ rule REVERSINGLABS_Cert_Blocklist_75A38507Bf403B152125B8F5Ce1B97Ad : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L171-L187" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L171-L187" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "af21cee3ee92268c3aa0106a245e5a00c5ba892fca3e4fd2dc55e302ed5d470a" score = 75 quality = 90 @@ -1631,8 +1684,8 @@ rule REVERSINGLABS_Cert_Blocklist_4Effa8B216E24B16202940C1Bc2Fa8A5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L189-L205" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L189-L205" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b5282fc85bbbee50c5307fff923e9e477fed8c011288e2ebd61c4b3ee801bc62" score = 75 quality = 90 @@ -1656,8 +1709,8 @@ rule REVERSINGLABS_Cert_Blocklist_57D7153A89Bbf4729Be87F3C927043Aa : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L207-L223" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L207-L223" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a8de7951bd25c8a9346ef341d8bf9c9147f9fa6913e952be40fb43d3d7a370c1" score = 75 quality = 90 @@ -1681,8 +1734,8 @@ rule REVERSINGLABS_Cert_Blocklist_028E1Deccf93D38Ecf396118Dfe908B4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L225-L241" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L225-L241" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b07c797652ef19c7e0b23c3eddbbbf2700160d743d71a0005b950160474638d8" score = 75 quality = 90 @@ -1706,8 +1759,8 @@ rule REVERSINGLABS_Cert_Blocklist_40575Df73Eaa1B6140C7Ef62C08Bf216 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L243-L259" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L243-L259" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7da8e98f38413e5cbb18e3c7771c530afb766dd9fbeb8fdd2264617aff24f920" score = 75 quality = 90 @@ -1731,8 +1784,8 @@ rule REVERSINGLABS_Cert_Blocklist_049Ce8C47F1F0E650Cb086F0Cfa7Ca53 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L261-L277" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L261-L277" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9ae4a236e1252afc1db6fae4e388a53ebde7e724cc07c213d4bfc176cf0a0096" score = 75 quality = 90 @@ -1756,8 +1809,8 @@ rule REVERSINGLABS_Cert_Blocklist_29F42680E653Cf8Fafd0E935553F7E86 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L279-L295" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L279-L295" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6c726e4c2933a6472d256a18ea5265660ff035d05036ab9cae3409ab5a7c7598" score = 75 quality = 90 @@ -1781,8 +1834,8 @@ rule REVERSINGLABS_Cert_Blocklist_0C15 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L297-L313" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L297-L313" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1ee88813270dddeeedd90edbce9be2ce74303a6799ee64b0e9bfaea7377d3b2d" score = 75 quality = 90 @@ -1806,8 +1859,8 @@ rule REVERSINGLABS_Cert_Blocklist_0C0F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L315-L331" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L315-L331" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0f8fda07dc362b7e04892446f1abe1e5f5717ee715824a2c1f6550096c366701" score = 75 quality = 90 @@ -1831,8 +1884,8 @@ rule REVERSINGLABS_Cert_Blocklist_06A164Ec5978497741Ee6Cec9966871B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L333-L349" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L333-L349" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8a27015d94a3bd8543a8ca9202831ffc9c9e65f61bf26ed6825c3e746b6af0d4" score = 75 quality = 90 @@ -1856,8 +1909,8 @@ rule REVERSINGLABS_Cert_Blocklist_1121Ed568764E75Be35574448Feadefcd3Bc : INFO FI date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L351-L367" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L351-L367" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3316a2536920c5aa9dd627cec7678e6fe33c722b4830dd740009c20dd013c9ab" score = 75 quality = 90 @@ -1881,8 +1934,8 @@ rule REVERSINGLABS_Cert_Blocklist_6Ed2450Ceac0F72E73Fda1727E66E654 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L369-L385" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L369-L385" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0e5af7795c825367d441c8abc2aa835fa83083eb8ee1f723c7d2dacff1ca88ff" score = 75 quality = 90 @@ -1906,8 +1959,8 @@ rule REVERSINGLABS_Cert_Blocklist_32665079C5A5854A6833623Ca77Ff5Ac : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L387-L403" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L387-L403" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6b734ca733c5fbadcb490ffd4c19c951e0fc17dd9b660eca948b126038c42cdb" score = 75 quality = 90 @@ -1931,8 +1984,8 @@ rule REVERSINGLABS_Cert_Blocklist_01A90094C83412C00Cf98Dd2Eb0D7042 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L405-L421" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L405-L421" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5a3de0e6de5cda39e40988f9e2324cbee3e059aff5ceaf7fd819de8bf7215808" score = 75 quality = 90 @@ -1956,8 +2009,8 @@ rule REVERSINGLABS_Cert_Blocklist_55Efe24B9674855Baf16E67716479C71 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L423-L439" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L423-L439" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2cf7a76ae3c3a698564013ff545c74d0319face5aa19416c93bf10f45f84f8c9" score = 75 quality = 90 @@ -1981,8 +2034,8 @@ rule REVERSINGLABS_Cert_Blocklist_094Bf19D509D3074913995160B195B6C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L441-L457" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L441-L457" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3c1ed012716f36876d9375838befb9821b87cafc6aca57a0f18392f80f5ba325" score = 75 quality = 90 @@ -2006,8 +2059,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A77Cf3Ba49B64E6Cbe5Fb4A6A6Aacc6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L459-L475" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L459-L475" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3bebc4a36b57526505167d8f075d468e4775d66c81ce08644c506d9be94efba0" score = 75 quality = 90 @@ -2031,8 +2084,8 @@ rule REVERSINGLABS_Cert_Blocklist_1F4C22Da1107D20C1Eda04569D58E573 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L477-L493" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L477-L493" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fe19c4b21c3b70ec571461ca6d9c370a971c01f2d68e3c3916aa1fa0f13b20f8" score = 75 quality = 90 @@ -2056,8 +2109,8 @@ rule REVERSINGLABS_Cert_Blocklist_4Fe68D48634893D18De040D8F1C289D2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L495-L511" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L495-L511" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "41feebc8800a084ac369b5c5721b1362d371bd503b67823986bad2839157a4b0" score = 75 quality = 90 @@ -2081,8 +2134,8 @@ rule REVERSINGLABS_Cert_Blocklist_6767Def972D6Ea702D8C8A53Af1832D3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L513-L529" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L513-L529" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "aa7f997449b4b8dcf488cfb7f45ee98ca540d39fb861f5b01ff4bb4aa1875b72" score = 75 quality = 90 @@ -2106,8 +2159,8 @@ rule REVERSINGLABS_Cert_Blocklist_06477E3425F1448995Ced539789E6842 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L531-L547" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L531-L547" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c0bc7808bb6bcc8273a887203c1b47d1a49fcb7719863e6bc97b5c7404a254f7" score = 75 quality = 90 @@ -2131,8 +2184,8 @@ rule REVERSINGLABS_Cert_Blocklist_0450A7C1C36951Da09C8Ad0E7F716Ff2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L549-L565" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L549-L565" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cb594607ceef1b8d79145ad3905fb2c38d2ed3f3e6c8a0a793fc2dc9d0a21855" score = 75 quality = 90 @@ -2156,8 +2209,8 @@ rule REVERSINGLABS_Cert_Blocklist_0F9Fbdab9B39645Cf3211F87Abb5Ddb7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L567-L583" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L567-L583" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ba5885c7769b5ead261815880033b0df50dc4f7684fdb37398ab01bfebda0e37" score = 75 quality = 90 @@ -2181,8 +2234,8 @@ rule REVERSINGLABS_Cert_Blocklist_4211D2E4F0E87127319302C55B85Bcf2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L585-L601" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L585-L601" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "edf9bbface7fe943dfa4f5a6e8469802ccdbd3de9d3e6b8fabebb024c21bb9a9" score = 75 quality = 90 @@ -2206,8 +2259,8 @@ rule REVERSINGLABS_Cert_Blocklist_07B44Cdbfffb78De05F4261672A67312 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L603-L619" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L603-L619" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c88a8543782fc49d8aa68f3fc8052bd3316d10118dfb2ef2eef5006de657b6f1" score = 75 quality = 90 @@ -2231,8 +2284,8 @@ rule REVERSINGLABS_Cert_Blocklist_4F8B9A1Ba5E60C754Dbb40Ddee7905E2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L621-L637" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L621-L637" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2a0d07d47cd41db5dc170a29607b6c1f2e3b7c0785f83b211f68f9cb9368e350" score = 75 quality = 90 @@ -2256,8 +2309,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A389B95Ee736Dd13Bc0Ed743Fd74D2F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L639-L655" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L639-L655" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8b83e4aa47cea7cadf4b4a9f4e044478a62f4233e082fb52f9ed906d80a552aa" score = 75 quality = 90 @@ -2281,8 +2334,8 @@ rule REVERSINGLABS_Cert_Blocklist_1A3Faaeb3A8B93B2394Fec36345996E6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L657-L673" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L657-L673" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a3bd9aaba8dbdb340b5d3013684584524eb08b11339985ba6ca0291b8c8bc692" score = 75 quality = 90 @@ -2306,8 +2359,8 @@ rule REVERSINGLABS_Cert_Blocklist_1A35Acce5B0C77206B1C3Dc2A6A2417C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L675-L691" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L675-L691" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ce161fdd511e0efa042516ead09c6ab5f8dcf54f2087cdccbfed8e7cdfbd25b2" score = 75 quality = 90 @@ -2331,8 +2384,8 @@ rule REVERSINGLABS_Cert_Blocklist_6Eb40Ea11Eaac847B050De9B59E25Bdc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L693-L709" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L693-L709" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d0e7ab78fb42c9a8f19cba8e6a8b15d584651a23f1088e1f311589d46145e963" score = 75 quality = 90 @@ -2356,8 +2409,8 @@ rule REVERSINGLABS_Cert_Blocklist_6724340Ddbc7252F7Fb714B812A5C04D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L711-L727" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L711-L727" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bc72c2ca5f81198684233e23260831da5b9ef4e7ac5a25abbdb303eecc38bd53" score = 75 quality = 90 @@ -2381,8 +2434,8 @@ rule REVERSINGLABS_Cert_Blocklist_0813Ee9B7B9D7C46001D6Bc8784Df1Dd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L729-L745" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L729-L745" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1a25a2f25fa8d5075113cbafb73e80e741268d6b2f9e629fd54ffca9e82409b0" score = 75 quality = 90 @@ -2406,8 +2459,8 @@ rule REVERSINGLABS_Cert_Blocklist_530591C61B5E1212F659138B7Cea0A97 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L747-L763" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L747-L763" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0ef01e542d145475713bbd373bdcdae5f25bfd823a60e7d40fe9a6b6039c83e0" score = 75 quality = 90 @@ -2431,8 +2484,8 @@ rule REVERSINGLABS_Cert_Blocklist_07270Ff9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L765-L781" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L765-L781" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8f0da7c330464184fa1d5bf8d51dd8ad2e8637710a36972dcab03629cb57e910" score = 75 quality = 90 @@ -2456,8 +2509,8 @@ rule REVERSINGLABS_Cert_Blocklist_0727100D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L783-L799" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L783-L799" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a09f4004ed002b90d67a3baddde74832e6c7b70e8b330347ef169460750aa344" score = 75 quality = 90 @@ -2481,8 +2534,8 @@ rule REVERSINGLABS_Cert_Blocklist_07271003 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L801-L817" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L801-L817" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "14c201b4fdda5b3553732a173a3d6705129c54f2a50d26997d63a77be8504285" score = 75 quality = 90 @@ -2506,8 +2559,8 @@ rule REVERSINGLABS_Cert_Blocklist_013134Bf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L819-L835" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L819-L835" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1ade100c310c22bce25bcc6687855bd4eb6364b64cf31514b2548509a16e4a36" score = 75 quality = 90 @@ -2531,8 +2584,8 @@ rule REVERSINGLABS_Cert_Blocklist_01314476 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L837-L853" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L837-L853" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6f2f3f3ae009fbb9ebe589fc6b640be89c4a7b734eda515f182c7e9c9ffb4779" score = 75 quality = 90 @@ -2556,8 +2609,8 @@ rule REVERSINGLABS_Cert_Blocklist_013169B0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L855-L871" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L855-L871" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "354421ebad7fd0b73c9ba63630c91d481901ca9ec39be3c6b66843221e4b5aad" score = 75 quality = 90 @@ -2581,8 +2634,8 @@ rule REVERSINGLABS_Cert_Blocklist_0C76Da9C910C4E2C9Efe15D058933C4C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L873-L889" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L873-L889" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "883e93bff42161ba68f69fb17f7e78377d7f3cb6b6cdf72cffb4166466f8bc7b" score = 75 quality = 90 @@ -2606,8 +2659,8 @@ rule REVERSINGLABS_Cert_Blocklist_469C2Caf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L891-L907" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L891-L907" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2490dbd74a5d3eede494d284f96af835c270d2fb0752b887aadbaf92bf34e6d4" score = 75 quality = 90 @@ -2631,8 +2684,8 @@ rule REVERSINGLABS_Cert_Blocklist_469C3Cc9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L909-L925" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L909-L925" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7327b7cbeb616bc46c82975aed6b3ea1caafa74fd431e2d98ca55b00851e22c8" score = 75 quality = 90 @@ -2656,8 +2709,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A82Bd1E144E8814D75B1A5527Bebf3E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L927-L943" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L927-L943" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2534e58ce1e5adbb10dbacb664d40cc32faec341bdb93b926cc85b666cc7b77e" score = 75 quality = 90 @@ -2681,8 +2734,8 @@ rule REVERSINGLABS_Cert_Blocklist_469C2Cb0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L945-L961" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L945-L961" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "67ff84475cbe231f97daa3ce623689e7936db8e56be562778f8a4c1ebf7bf316" score = 75 quality = 90 @@ -2706,8 +2759,8 @@ rule REVERSINGLABS_Cert_Blocklist_4C0E636A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L963-L979" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L963-L979" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "20169cf9ce3f271a22d1376bcf0ff0914f43937738c9ed61fd8e40179405136b" score = 75 quality = 90 @@ -2731,8 +2784,8 @@ rule REVERSINGLABS_Cert_Blocklist_072714A9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L981-L997" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L981-L997" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8bea4cfb60056446043ef90a7d01ecc52d82d9e7005a145a4daa61a522ecd2ae" score = 75 quality = 90 @@ -2756,8 +2809,8 @@ rule REVERSINGLABS_Cert_Blocklist_00D8F35F4Eb7872B2Dab0692E315382Fb0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L999-L1017" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L999-L1017" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "463757c59c32859163ea80e694e1f39239c857124aad3895f22f83b47645910c" score = 75 quality = 90 @@ -2781,8 +2834,8 @@ rule REVERSINGLABS_Cert_Blocklist_750E40Ff97F047Edf556C7084Eb1Abfd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1019-L1035" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1019-L1035" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "21c2468905514e1725a206814b0c61c576cf7f97f184bac857bca9283f49a957" score = 75 quality = 90 @@ -2806,8 +2859,8 @@ rule REVERSINGLABS_Cert_Blocklist_1B5190F73724399C9254Cd424637996A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1037-L1053" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1037-L1053" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "08f287ccda93e03a7e796d5625ab35ef0de782d07e5db4e2264f612fc5ebaa21" score = 75 quality = 90 @@ -2831,8 +2884,8 @@ rule REVERSINGLABS_Cert_Blocklist_00Ebaa11D62E2481081820 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1055-L1072" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1055-L1072" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2fafc6775ec88b5a1000afbc7234fbef6b03e9eaf866dae660dd2d749996cb5c" score = 75 quality = 90 @@ -2856,8 +2909,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Aab11Dee52F1B19D056 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1074-L1089" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1074-L1089" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1f1215143dc828596e6d7eeff99983755b17eaeb3ab9d7643abdbb48e9957c78" score = 75 quality = 90 @@ -2881,8 +2934,8 @@ rule REVERSINGLABS_Cert_Blocklist_6102B01900000000002F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1091-L1106" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1091-L1106" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6c42daa8b8730541bb422ac860ec4b0830e00fdb732e4bb503054dbcae1ff6d4" score = 75 quality = 90 @@ -2906,8 +2959,8 @@ rule REVERSINGLABS_Cert_Blocklist_01E2B4F759811C64379Fca0Be76D2Dce : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1108-L1124" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1108-L1124" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0dff7a9f2e152c20427ea231449b942a040e964cb7dad90271d2865290535326" score = 75 quality = 90 @@ -2931,8 +2984,8 @@ rule REVERSINGLABS_Cert_Blocklist_03E5A010B05C9287F823C2585F547B80 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1126-L1142" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1126-L1142" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1d57b640ee313ad4d53dc64ce4df3e4ed57976e7750cfd80d62bf9982d964d26" score = 75 quality = 90 @@ -2956,8 +3009,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Fe7Df6C4B9A33B83D04E23E98A77Cce : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1144-L1160" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1144-L1160" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "da5ed07def8d0c04ea58aacd90f9fa5588f868f6d0057b9148587f2f0b381f25" score = 75 quality = 90 @@ -2981,8 +3034,8 @@ rule REVERSINGLABS_Cert_Blocklist_065569A3E261409128A40Affa90D6D10 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1162-L1178" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1162-L1178" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f8d68758704e41325e95ec69334aaf7fabe08a6d5557e0a81bac2f02d3ab5977" score = 75 quality = 90 @@ -3006,8 +3059,8 @@ rule REVERSINGLABS_Cert_Blocklist_0979616733E062C544Df0Abd315E3B92 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1180-L1196" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1180-L1196" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "034b233d6b6dd82ad9fa1ec99db1effa3daaa5bb478d448133c479ac728117ad" score = 75 quality = 90 @@ -3031,8 +3084,8 @@ rule REVERSINGLABS_Cert_Blocklist_7D3250B27E0547C77307030491B42802 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1198-L1214" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1198-L1214" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "65f036921dfb9cbce3275aefb7111711e50874440096b2e3c3b55190cfc14ddb" score = 75 quality = 90 @@ -3056,8 +3109,8 @@ rule REVERSINGLABS_Cert_Blocklist_00D1836Bd37C331A67 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1216-L1234" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1216-L1234" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8af1d10085c5be8924eb6e4ea3a9b8e936c7706d8ec43d42f24a9a293c7f9d27" score = 75 quality = 90 @@ -3081,8 +3134,8 @@ rule REVERSINGLABS_Cert_Blocklist_2Ca028D1A4De0Eb743135Edecf74D7Af : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1236-L1252" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1236-L1252" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "60b6351194e23153d425eaa0c25f840080a29abb5eb1bbcd41bb76a3d4130edd" score = 75 quality = 90 @@ -3106,8 +3159,8 @@ rule REVERSINGLABS_Cert_Blocklist_Dbb14Dcf973Eada14Ece7Ea79C895C11 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1254-L1270" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1254-L1270" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c73c83f5cb6d840b887e1aa41e96a29529f975434ac27a5aa57f2e14b342f63d" score = 75 quality = 90 @@ -3131,8 +3184,8 @@ rule REVERSINGLABS_Cert_Blocklist_F8C2239De3977B8D4A3Dcbedc9031A51 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1272-L1288" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1272-L1288" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "aa4f39790bc58b0a50e05e7670abad654d7f3d73e500bd5f054fece4a979ebfa" score = 75 quality = 90 @@ -3156,8 +3209,8 @@ rule REVERSINGLABS_Cert_Blocklist_Caad8222705D3Fb3430E114A31C8C6A4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1290-L1306" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1290-L1306" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "35c4f46322da4f5b9f938c1098c8e57effc8abfc03db865190c343df7b8990ea" score = 75 quality = 90 @@ -3181,8 +3234,8 @@ rule REVERSINGLABS_Cert_Blocklist_B191812516E6618D49E6Ccf5E63Dc343 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1308-L1324" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1308-L1324" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "40c03e683b4b8e8a23ca84da7dfd3bd998d3708b27b7df7a22f25fb364c3a69b" score = 75 quality = 90 @@ -3206,8 +3259,8 @@ rule REVERSINGLABS_Cert_Blocklist_4Ba7Fb8Ee1Deff8F4A1525E1E0580057 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1326-L1342" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1326-L1342" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "324157b9fec2653cb8874c7a1a5b6e39b121992cd52856b8c4a2a8b7cee86a69" score = 75 quality = 90 @@ -3231,8 +3284,8 @@ rule REVERSINGLABS_Cert_Blocklist_2Df9F7Eb6Cdc5Ca243B33122E3941E25 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1344-L1360" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1344-L1360" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "703eccd5573fe42f03ec82887660d50e942156d840394746c90ba87d82507803" score = 75 quality = 90 @@ -3256,8 +3309,8 @@ rule REVERSINGLABS_Cert_Blocklist_58A541D50F9E2Fab4380C6A2Ed433B82 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1362-L1378" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1362-L1378" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "69ddc58b6fec159d6eded8c78237a6a0626b1aedb58b0c9867b758fd09db46ad" score = 75 quality = 90 @@ -3281,8 +3334,8 @@ rule REVERSINGLABS_Cert_Blocklist_5F273626859Ae4Bc4Becbbeb71E2Ab2D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1380-L1396" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1380-L1396" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c8be504f075041508f299b1df03d9cb9e58d9a89f49b7a926676033d18b108ba" score = 75 quality = 90 @@ -3306,8 +3359,8 @@ rule REVERSINGLABS_Cert_Blocklist_B1Ad46Ce4Db160B348C24F66C9663178 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1398-L1414" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1398-L1414" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "59ce2b7a2e881853d07446b3dda74b296f2be09651364d0e131552cf76dab751" score = 75 quality = 90 @@ -3331,8 +3384,8 @@ rule REVERSINGLABS_Cert_Blocklist_256541E204619033F8B09F9Eb7C88Ef8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1416-L1432" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1416-L1432" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e33cedf1dd24ac73f77461de0cef25cad57909be2a69469fec450ead7da85c65" score = 75 quality = 90 @@ -3356,8 +3409,8 @@ rule REVERSINGLABS_Cert_Blocklist_00E8Cc18Cf100B6B27443Ef26319398734 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1434-L1452" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1434-L1452" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "68e9df056109cae41d981090c7a98ddc192a445647d7475569ddbe4118e570c5" score = 75 quality = 90 @@ -3381,8 +3434,8 @@ rule REVERSINGLABS_Cert_Blocklist_62Af28A7657Ba8Ab10Fa8E2D47250C69 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1454-L1470" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1454-L1470" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c3c034cb4e2c65e2269fbfd9c045eb294badde60389ae62ed694ea4d61c5eb35" score = 75 quality = 90 @@ -3406,8 +3459,8 @@ rule REVERSINGLABS_Cert_Blocklist_04C8Eca7243208A110Dea926C7Ad89Ce : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1472-L1488" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1472-L1488" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0012436e83704397026a8b2e500e5d61915e0f4c8ad4100176e200a975562e8f" score = 75 quality = 90 @@ -3431,8 +3484,8 @@ rule REVERSINGLABS_Cert_Blocklist_157C3A4A6Bcf35Cf8453E6B6C0072E1D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1490-L1506" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1490-L1506" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2a68051ab6d0b967f08e44d91b9f13d75587ea0f16e2a5536ccf5898445e1a58" score = 75 quality = 90 @@ -3456,8 +3509,8 @@ rule REVERSINGLABS_Cert_Blocklist_04422F12037Bc2032521Dbb6Ae02Ea0E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1508-L1524" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1508-L1524" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "381d749d24121d6634656fd33adcda5c3e500ee77a6333f525f351a2ee589e2c" score = 75 quality = 90 @@ -3481,8 +3534,8 @@ rule REVERSINGLABS_Cert_Blocklist_65Eae6C98111Dc40Bf4F962Bf27227F2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1526-L1542" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1526-L1542" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "20c0f4e9783586e68ff363fe6a72398f6ea27aef5d25f98872d1203ce1a0c9bd" score = 75 quality = 90 @@ -3506,8 +3559,8 @@ rule REVERSINGLABS_Cert_Blocklist_12D5A4B29Fe6156D4195Fba55Ae0D9A9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1544-L1560" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1544-L1560" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "860550745f6dbcd7dd0925d9b8f04e8e08e8b7c06343a4c070e131a815c42e12" score = 75 quality = 90 @@ -3531,8 +3584,8 @@ rule REVERSINGLABS_Cert_Blocklist_0087D60D1E2B9374Eb7A735Dce4Bbdae56 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1562-L1580" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1562-L1580" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d6e0d22e926a237f1cc6b71c6f8ce01e497723032c9efba1e6af7327a786b608" score = 75 quality = 90 @@ -3556,8 +3609,8 @@ rule REVERSINGLABS_Cert_Blocklist_0860C8A7Ed18C3F030A32722Fd2B220C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1582-L1598" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1582-L1598" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3c777fb157a6669bfdf3143e77f69265e09458a2b42b75b72680eb043da71e85" score = 75 quality = 90 @@ -3581,8 +3634,8 @@ rule REVERSINGLABS_Cert_Blocklist_2Fdadd0740572270203F8138692C4A83 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1600-L1616" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1600-L1616" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "18ce7ed721a454c5bb3cd6ab26df703b1e08b94b8c518055feffa38ad42afa50" score = 75 quality = 90 @@ -3606,8 +3659,8 @@ rule REVERSINGLABS_Cert_Blocklist_4Fc13D6220C629043A26F81B1Cad72D8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1618-L1634" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1618-L1634" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5572c278f6c9be62b2bba09ea610fd170438c6893ee5283ff4a5b3bb2852b07b" score = 75 quality = 90 @@ -3631,8 +3684,8 @@ rule REVERSINGLABS_Cert_Blocklist_3457A918C6D3701B2Eaca6A92474A7Cc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1636-L1652" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1636-L1652" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "70d4bece52a86bfe8958f6d4195b833cea609596e3b68bb90087c262501bd462" score = 75 quality = 90 @@ -3656,8 +3709,8 @@ rule REVERSINGLABS_Cert_Blocklist_621Ed8265B0Ad872D9F4B4Ed6D560513 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1654-L1670" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1654-L1670" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c133d6eea5d27e597d0a656c7c930a5ca84adb46aa2fec66381b6b5c759e22aa" score = 75 quality = 90 @@ -3681,8 +3734,8 @@ rule REVERSINGLABS_Cert_Blocklist_56E22B992B4C7F1Afeac1D63B492Bf54 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1672-L1688" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1672-L1688" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ef058c0ec352260fa3db0fc74331d1da3c9eb8d161cef7635632fd7c569198c6" score = 75 quality = 90 @@ -3706,8 +3759,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Bc3Bae4118D46F3Fdd9Beeeab749Fee : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1690-L1706" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1690-L1706" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fcbda27f8bf4dca8aa32103bb344380c82f0c701c25766df94c182ef94805a12" score = 75 quality = 90 @@ -3731,8 +3784,8 @@ rule REVERSINGLABS_Cert_Blocklist_0F0449F7691E5B4C8E74E71Cae822179 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1708-L1724" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1708-L1724" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f8d3593b357f27240a4399e877ae9044f783bb944ad47ec9fe8bbecc63be864c" score = 75 quality = 90 @@ -3756,8 +3809,8 @@ rule REVERSINGLABS_Cert_Blocklist_43Db4448D870D7Bdc275F36A01Fba36F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1726-L1742" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1726-L1742" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "951e35e2c3f1bd90a33f8b76b6ede5686ee9b9c97a4c71df5b9dff15956209c5" score = 75 quality = 90 @@ -3781,8 +3834,8 @@ rule REVERSINGLABS_Cert_Blocklist_2880A7F7Ff2D334Aa08744A8754Fab2C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1744-L1760" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1744-L1760" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "03c7e1251c44e8824ae3b648a95cf34f4c56db65d76806306a062a343981d87f" score = 75 quality = 90 @@ -3806,8 +3859,8 @@ rule REVERSINGLABS_Cert_Blocklist_0492F5C18E26Fa0Cd7E15067674Aff1C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1762-L1778" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1762-L1778" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d47d59d7680000d6c35181be2d9b034c2ecb7ca754a39c8e11750ddd7246b47c" score = 75 quality = 90 @@ -3831,8 +3884,8 @@ rule REVERSINGLABS_Cert_Blocklist_6Aa668Cd6A9De1Fdd476Ea8225326937 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1780-L1796" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1780-L1796" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "706e16995af40a6c9176dcbca07fb406f2efe4d47dbd9629d1a6b1ab1d09b045" score = 75 quality = 90 @@ -3856,8 +3909,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Cb06Dccb482255728671Ea12Ac41620 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1798-L1814" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1798-L1814" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e0867ffe2ddd28282fe78b27b3b12ebac525b33a27dd242bc6f55bcd2e066a18" score = 75 quality = 90 @@ -3881,8 +3934,8 @@ rule REVERSINGLABS_Cert_Blocklist_370C2467C41D6019Bbecd72E00C5D73D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1816-L1832" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1816-L1832" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2b99522b75ee83d85b30146cb292b5a8a46dc300fb43dd9d39d9ca96c9d32d9b" score = 75 quality = 90 @@ -3906,8 +3959,8 @@ rule REVERSINGLABS_Cert_Blocklist_5067339614C5Cc219C489D40420F3Bf9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1834-L1850" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1834-L1850" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1716087285a093a3467583f79d7ae9bee641997227e6d4f95047905aedcc97c6" score = 75 quality = 90 @@ -3931,8 +3984,8 @@ rule REVERSINGLABS_Cert_Blocklist_6E32531Ae83992F0573120A5E78De271 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1852-L1868" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1852-L1868" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2b6d54ea8395c3666906b2e60c30b970c2c1b6f55ded874cbcc22dc79391fb34" score = 75 quality = 90 @@ -3956,8 +4009,8 @@ rule REVERSINGLABS_Cert_Blocklist_6967A89Bcf6Efef160Aaeebbff376C0A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1870-L1886" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1870-L1886" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "deb7465e453aa5838f81e15e270abc958a65e1a6051a88a5910244edbe874451" score = 75 quality = 90 @@ -3981,8 +4034,8 @@ rule REVERSINGLABS_Cert_Blocklist_7473D95405D2B0B3A8F28785Ce6E74Ca : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1888-L1904" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1888-L1904" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e15b990b13617017ca2d1f8caf03d8ff3785ca9b860bf11f81af5dadf17a9be5" score = 75 quality = 90 @@ -4006,8 +4059,8 @@ rule REVERSINGLABS_Cert_Blocklist_04F380F97579F1702A85E0169Bbdfd78 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1906-L1922" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1906-L1922" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "73dc6e36fdaf5c80b33f20f2a9157805ce1d0218f3898104de16522ee9cfd51b" score = 75 quality = 90 @@ -4031,8 +4084,8 @@ rule REVERSINGLABS_Cert_Blocklist_04D6B8Cc6Dce353Fcf3Ae8A532Be7255 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1924-L1940" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1924-L1940" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a316ad7f554428d02a850fb3bb04f349d30ecd2ccd4597e7a63461bf5e866e6f" score = 75 quality = 90 @@ -4056,8 +4109,8 @@ rule REVERSINGLABS_Cert_Blocklist_191322A00200F793 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1942-L1958" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1942-L1958" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1b816785f86189817c124636e50a0f369ec85cfd898223c4ba43758a877f1cf3" score = 75 quality = 90 @@ -4081,8 +4134,8 @@ rule REVERSINGLABS_Cert_Blocklist_451C9D0B413E6E8Df175 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1960-L1976" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1960-L1976" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7c94d87f79c9add4d7bf2a63d0774449319aa56cbc631dd9b0f19ed9bb9837d4" score = 75 quality = 90 @@ -4106,8 +4159,8 @@ rule REVERSINGLABS_Cert_Blocklist_03943858218F35Adb7073A6027555621 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1978-L1994" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1978-L1994" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "93369d51b73591559494a48fafa5e4f7d46301ecaa379d8de70a70ac4d2d2728" score = 75 quality = 90 @@ -4131,8 +4184,8 @@ rule REVERSINGLABS_Cert_Blocklist_09813Ee7318452C28A1F6426D1Cee12D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L1996-L2012" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L1996-L2012" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "89eb019192f822f9fe070403161d81e425fb8acdbc80e55fa516b5607eb8f8c7" score = 75 quality = 90 @@ -4156,8 +4209,8 @@ rule REVERSINGLABS_Cert_Blocklist_476Bf24A4B1E9F4Bc2A61B152115E1Fe : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2014-L2030" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2014-L2030" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0ec0f44d2a7a53ad5653334378b631abde1834ebfcf72efcdcce353c6b9ae17d" score = 75 quality = 90 @@ -4181,8 +4234,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Bd55818C5971B63Dc45Cf57Cbeb950B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2032-L2048" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2032-L2048" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5aa41a2d6a86a30559b36818602e1bdf2bfd38b799a4869c26c150052d6d788c" score = 75 quality = 90 @@ -4206,8 +4259,8 @@ rule REVERSINGLABS_Cert_Blocklist_4C0B2E9D2Ef909D15270D4Dd7Fa5A4A5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2050-L2066" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2050-L2066" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9c74eb025bb413503b97ffdba6f19eadecf3789ce3a5d5419f84e32e25c9b5b1" score = 75 quality = 90 @@ -4231,8 +4284,8 @@ rule REVERSINGLABS_Cert_Blocklist_5E3D76Dc7E273E2F313Fc0775847A2A2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2068-L2084" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2068-L2084" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b943057fc3e97cfccadb4b8f61289a93b659aacf2a40217fcf519d4882e70708" score = 75 quality = 90 @@ -4256,8 +4309,8 @@ rule REVERSINGLABS_Cert_Blocklist_47D5D5372Bcb1562B4C9F4C2Bdf13587 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2086-L2102" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2086-L2102" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fb4994647a2ed95c73625d90315c9b6deb6fb3b81b4aa6e847b0193f0a76650c" score = 75 quality = 90 @@ -4281,8 +4334,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Ac10E68F1Ce519E84Ddcd28B11Fa542 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2104-L2120" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2104-L2120" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "dac3b6b7609ec1e82afe4f9c6c14e2d32b6f5d8d49c59d6c605f2a94d71bc107" score = 75 quality = 90 @@ -4306,8 +4359,8 @@ rule REVERSINGLABS_Cert_Blocklist_31062E483E0106B18C982F0053185C36 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2122-L2138" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2122-L2138" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e45fc5b4d1b9f5cd35c56aad381e26e30675a9d99747cd318f3c77ea2af0e14a" score = 75 quality = 90 @@ -4331,8 +4384,8 @@ rule REVERSINGLABS_Cert_Blocklist_20D0Ee42Fc901E6B3A8Fefe8C1E6087A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2140-L2156" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2140-L2156" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2225302de1e8fe9f2ad064e19b2b1d9faf90c7cafbebff6ddd0921bf57c5f9e6" score = 75 quality = 90 @@ -4356,8 +4409,8 @@ rule REVERSINGLABS_Cert_Blocklist_127251B32B9A50Bd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2158-L2174" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2158-L2174" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8552ce9e9ab8d6b1025ab3c6e7b2485ef855236114c426475fde0b5f2e231ec9" score = 75 quality = 90 @@ -4381,8 +4434,8 @@ rule REVERSINGLABS_Cert_Blocklist_48Cad4E6966E22D6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2176-L2192" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2176-L2192" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7733b8a97d9f3538db04309a2e3f9df6cb64930b0b6f7f241c3e629be2dd7804" score = 75 quality = 90 @@ -4406,8 +4459,8 @@ rule REVERSINGLABS_Cert_Blocklist_5E15205F180442Cc6C3C0F03E1A33D9F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2194-L2210" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2194-L2210" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1ca238b5da4ff9940425c99f55542c931ccdf0ea3b0a2acbf00ffbbb54171ae0" score = 75 quality = 90 @@ -4431,8 +4484,8 @@ rule REVERSINGLABS_Cert_Blocklist_4C8E3B1613F73542F7106F272094Eb23 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2212-L2228" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2212-L2228" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "15c21b783409d904a0b4971dbdcbd0740083d13f3c633ee77c87df46d3aca748" score = 75 quality = 90 @@ -4456,8 +4509,8 @@ rule REVERSINGLABS_Cert_Blocklist_2Ce2Bd0Ad3Cfde9Ea73Eec7Ca30400Da : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2230-L2246" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2230-L2246" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a879ecd957acd29e8a5bad6c97cd10453ab857949680b522735bd77eb561d2ee" score = 75 quality = 90 @@ -4481,8 +4534,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Fbc30Db127A536C34D7A0Fa81B48193 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2248-L2264" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2248-L2264" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6b109b5636aa297a6e07f9d9213f7f07a7767b58442d03dc2f34f8a9b3eaba2b" score = 75 quality = 90 @@ -4506,8 +4559,8 @@ rule REVERSINGLABS_Cert_Blocklist_08448Bd6Ee9105Ae31228Ea5Fe496F63 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2266-L2282" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2266-L2282" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9bc044b4fdf381274a2c31bc997dcdfd553595d92de7b33dc472353a00011711" score = 75 quality = 90 @@ -4531,8 +4584,8 @@ rule REVERSINGLABS_Cert_Blocklist_02F17566Ef568Dc06C9A379Ea2F4Faea : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2284-L2300" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2284-L2300" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e3ec8a6de817354862880301e78a999f45f02c2fa8512bba6d27c9776f1a3417" score = 75 quality = 90 @@ -4556,8 +4609,8 @@ rule REVERSINGLABS_Cert_Blocklist_7D824Ba1F7F730319C50D64C9A7Ed507 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2302-L2318" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2302-L2318" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "407611603974c910d9a6a0ed71ecdf54ddcc59abb0f48c60846e61d6d4191933" score = 75 quality = 90 @@ -4581,8 +4634,8 @@ rule REVERSINGLABS_Cert_Blocklist_77A64759F12766E363D779998C71Bdc9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2320-L2336" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2320-L2336" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2bf3d99ddec6b76da1ca60a9285767a5b34b84455db58195fc5d8fd8a22c9f8a" score = 75 quality = 90 @@ -4606,8 +4659,8 @@ rule REVERSINGLABS_Cert_Blocklist_0B0D17Ec1449B4B2D38Fcb0F20Fbcd3A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2338-L2354" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2338-L2354" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3121f2c49d0d4c396023924521f2c980045b6f07d082e49447429e9cd640e0ef" score = 75 quality = 90 @@ -4631,8 +4684,8 @@ rule REVERSINGLABS_Cert_Blocklist_Fe9404Dc73Cf1C2Ba1450B8398305557 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2356-L2374" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2356-L2374" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c0132d71de1384f6e534dd154eba88c4a51c43b7dfe984f3064ba4feffa4dd5a" score = 75 quality = 90 @@ -4656,8 +4709,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Cb2D523A6Bf7A066642C578De1C9Be4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2376-L2392" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2376-L2392" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5a786b9ade5a59b8a1e0bbef1eb3dcb65404dcee19d572dc60f9ec9f45e4755b" score = 75 quality = 90 @@ -4681,8 +4734,8 @@ rule REVERSINGLABS_Cert_Blocklist_3A6Ccabb1C62F3Be3Eb03869Fa43Dc4A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2394-L2410" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2394-L2410" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ccb603c8a5f4fb63876e78d763f80a97098c23aa10673c7b04a48026268f57d3" score = 75 quality = 90 @@ -4706,8 +4759,8 @@ rule REVERSINGLABS_Cert_Blocklist_864196F01971Dbec7002B48642A7013A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2412-L2430" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2412-L2430" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a3173bb08e673caaa64ab22854840a135e891044b165bbc67733c951ec6aa991" score = 75 quality = 90 @@ -4731,8 +4784,8 @@ rule REVERSINGLABS_Cert_Blocklist_4Fda1E121B61Adeca936A6Aebe079303 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2432-L2448" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2432-L2448" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "70a04c83e79c98024bacf1688bb46d80c9b8491e25dd32d6d92bf3cf61c62e48" score = 75 quality = 90 @@ -4756,8 +4809,8 @@ rule REVERSINGLABS_Cert_Blocklist_03866Deb183Abfbf4Ff458D4De7Bd73A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2450-L2466" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2450-L2466" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "90d09d0d2d01500e0670277d0e8de574feecf7443cf4d077912b1166a9c14c43" score = 75 quality = 90 @@ -4781,8 +4834,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Be41B34127Ca9E6270830D2070Db426 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2468-L2484" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2468-L2484" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b66c4b9264be70d53838442a3112c4bacbdf2dda90840d71c3eb949e630b3f17" score = 75 quality = 90 @@ -4806,8 +4859,8 @@ rule REVERSINGLABS_Cert_Blocklist_9B108B8A1Daa0D5581F59Fcee0447901 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2486-L2504" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2486-L2504" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "696e3da511f74f9cfb10b96130a36ae9f48c22f1e0deb76092db1262980ab3ac" score = 75 quality = 90 @@ -4831,8 +4884,8 @@ rule REVERSINGLABS_Cert_Blocklist_5F8203C430Fc7Db4E61F6684F6829Ffc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2506-L2522" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2506-L2522" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cd22d1beea12d1f6c50f69e76074c2582ce5567887056c43d4d6c87d33fce1bf" score = 75 quality = 90 @@ -4856,8 +4909,8 @@ rule REVERSINGLABS_Cert_Blocklist_6B6Daef5Be29F20Ddce4B0F5E9Fa6Ea5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2524-L2540" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2524-L2540" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "edd2f302d2fac65f6a93372a24c3f80757f2b175af661032917366e9629c5491" score = 75 quality = 90 @@ -4881,8 +4934,8 @@ rule REVERSINGLABS_Cert_Blocklist_57D6Dff1Ef96F01B9430666B2733Cc87 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2542-L2558" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2542-L2558" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "40d22137e9c5345859c5f000166da2a3117bcfcc19b4c5e81083cad80dfa6ee4" score = 75 quality = 90 @@ -4906,8 +4959,8 @@ rule REVERSINGLABS_Cert_Blocklist_0166B65038D61E5435B48204Cae4795A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2560-L2576" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2560-L2576" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4e289eda4d5381250bcd6e36daade6f1e1803b6d16578d7eaee4454cef6981d0" score = 75 quality = 90 @@ -4931,8 +4984,8 @@ rule REVERSINGLABS_Cert_Blocklist_784F226B45C3Bd8E4089243D747D1F59 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2578-L2594" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2578-L2594" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "df8ca35a07ec6815d1efb68fa6fbf8f80c57032ecb99d0b038da0604ceffe8cf" score = 75 quality = 90 @@ -4956,8 +5009,8 @@ rule REVERSINGLABS_Cert_Blocklist_11690F05604445Fae0De539Eeeeec584 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2596-L2612" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2596-L2612" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b66257f562f698559910eb9576f8fdf0ce3a750cc0a96a27e2ec1a18872ad13f" score = 75 quality = 90 @@ -4981,8 +5034,8 @@ rule REVERSINGLABS_Cert_Blocklist_Aa146Bff4B832Bdbfe30B84580356763 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2614-L2632" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2614-L2632" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "37abe7a4fd773fd34f5d7dbe725ba4edcfb8ebb501dc41f386b8b0629161051f" score = 75 quality = 90 @@ -5006,8 +5059,8 @@ rule REVERSINGLABS_Cert_Blocklist_E86F46B60142092Aae81B8F6Fa3D9C7C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2634-L2652" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2634-L2652" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6de16a44bc84fbf8f1d3d82526e1d7f8fd4ae3da6deaa471c77d2c8df47a14b0" score = 75 quality = 90 @@ -5031,8 +5084,8 @@ rule REVERSINGLABS_Cert_Blocklist_1A0Fd2A4Ef4C2A36Ab9C5E8F792A35E2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2654-L2670" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2654-L2670" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8e768415998a6a92961986cb0a9d310514d928be93b3e5a9aaa9ec71bf5886ad" score = 75 quality = 90 @@ -5056,8 +5109,8 @@ rule REVERSINGLABS_Cert_Blocklist_53Bb753B79A99E61A6E822Ac52460C70 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2672-L2688" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2672-L2688" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "24ff4f46fa6e85c25e130459f9b8d6907cf6cd51098e0cf45ec11d54d7de509b" score = 75 quality = 90 @@ -5081,8 +5134,8 @@ rule REVERSINGLABS_Cert_Blocklist_83F68Fc6834Bf8Bd2C801A2D1F1Acc76 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2690-L2708" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2690-L2708" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "35552242f9f0a56b45e30e6f376877446f33e24690ff5d7b03dc776fab178afd" score = 75 quality = 90 @@ -5106,8 +5159,8 @@ rule REVERSINGLABS_Cert_Blocklist_F385E765Acfb95605C9B35Ca4C32F80E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2710-L2728" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2710-L2728" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c73c8f1913d3423a52f5e77751813460ae9200eb3cb1cc6e2ec30f37f0da8152" score = 75 quality = 90 @@ -5131,8 +5184,8 @@ rule REVERSINGLABS_Cert_Blocklist_F62C9C4Efc81Caf0D5A2608009D48018 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2730-L2748" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2730-L2748" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "08fcff795297c0608b1a1d71465279cbf76d4dff06de2a2262a58debbb2f9e0d" score = 75 quality = 90 @@ -5156,8 +5209,8 @@ rule REVERSINGLABS_Cert_Blocklist_Cc8D902Da36587C9B2113Cd76C3C3F8D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2750-L2768" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2750-L2768" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "25e524d23ccc1c06f602a086369ffd44b8c97b76c29f068764081339556b3465" score = 75 quality = 90 @@ -5181,8 +5234,8 @@ rule REVERSINGLABS_Cert_Blocklist_328Bdcc0F679C4649147Fbb3Eb0E9Bc6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2770-L2786" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2770-L2786" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6d9e1f25ca252ca9dda7714c52a2e57fd3b5dca08cd2a45c9dec18a31d3bb342" score = 75 quality = 90 @@ -5206,8 +5259,8 @@ rule REVERSINGLABS_Cert_Blocklist_5F78149Eb4F75Eb17404A8143Aaeaed7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2788-L2804" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2788-L2804" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0c7c9e8d2a9304e0407b8a1a29977312a9ba766a4052c6b874855fa187c85585" score = 75 quality = 90 @@ -5231,8 +5284,8 @@ rule REVERSINGLABS_Cert_Blocklist_629D120Dd84F9C1688D4Da40366Fab7A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2806-L2822" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2806-L2822" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "187f6ef0de869500526d1b0d5c6f6762b0a939e06781e633a602834687c64023" score = 75 quality = 90 @@ -5256,8 +5309,8 @@ rule REVERSINGLABS_Cert_Blocklist_039E5D0E3297F574Db99E1D9503853D9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2824-L2840" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2824-L2840" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2f150f60b7dce583fc68705f0b29a7c8684f1b69020275b2ec1ac6beeaa63952" score = 75 quality = 90 @@ -5281,8 +5334,8 @@ rule REVERSINGLABS_Cert_Blocklist_Bc32Bbe5Bbb4F06F490C50651Cd5Da50 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2842-L2860" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2842-L2860" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "104be481b7d4b1cb3c43c72314afc3641983838b5177c34a88d6da0d0e7b89c9" score = 75 quality = 90 @@ -5306,8 +5359,8 @@ rule REVERSINGLABS_Cert_Blocklist_3E1656Dfcaacfed7C2D2564355698Aa3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2862-L2878" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2862-L2878" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ba7cca8d71f571644cabd3d491cddefffd05ca7a838f262a343a01e4a09bb72a" score = 75 quality = 90 @@ -5331,8 +5384,8 @@ rule REVERSINGLABS_Cert_Blocklist_4Bf1D68E926E2Dd8966008C44F95Ea1C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2880-L2896" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2880-L2896" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "44b5aae8380e3590ebb6e2365e89b3827432e8330e5290dc8f8603a00bcf62f6" score = 75 quality = 90 @@ -5356,8 +5409,8 @@ rule REVERSINGLABS_Cert_Blocklist_149C12083C145E28155510Cfc19Db0Fe : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2898-L2914" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2898-L2914" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f616fc470e223d65ac4c984394a38d566265ab37829ff566012de0a1527396c2" score = 75 quality = 90 @@ -5381,8 +5434,8 @@ rule REVERSINGLABS_Cert_Blocklist_77E0117E8B2B8Faa84Bed961019D5Ef8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2916-L2932" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2916-L2932" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bea94b9da8c176f22a66fe7a4545dcc3a38f727a75a0bc7920d9aece8e24b9b7" score = 75 quality = 90 @@ -5406,8 +5459,8 @@ rule REVERSINGLABS_Cert_Blocklist_4F3Feb4Baf377Aea90A463C5Dee63884 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2934-L2950" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2934-L2950" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "56c37e758db33aa40e9a2c1c5a4eb14c2c370f614e838d86bf20c64f79e2a746" score = 75 quality = 90 @@ -5431,8 +5484,8 @@ rule REVERSINGLABS_Cert_Blocklist_3D2580E89526F7852B570654Efd9A8Bf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2952-L2968" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2952-L2968" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0f46fcfc8ee06756646899450daa254d3e5261bdc5c2339f20d01971608fff7b" score = 75 quality = 90 @@ -5456,8 +5509,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Fffe432A53Ff03B9223F88Be1B83D9D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2970-L2986" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2970-L2986" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e7dbe6b95877f9473661ccf26fa6e5142147609adfe0a9bb8b493875325710af" score = 75 quality = 90 @@ -5481,8 +5534,8 @@ rule REVERSINGLABS_Cert_Blocklist_832E161Aea5206D815F973E5A1Feb3E7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L2988-L3006" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L2988-L3006" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "da908de031c78aa012809988e44dea564d32b88b65a2010925c1af85d578a68a" score = 75 quality = 90 @@ -5506,8 +5559,8 @@ rule REVERSINGLABS_Cert_Blocklist_09Aecea45Bfd40Ce7D62D7D711916D7D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3008-L3024" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3008-L3024" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d1c6bfb10a244ba866c8aabdff6055388afa8096fd4bd77bb21f781794333e9b" score = 75 quality = 90 @@ -5531,8 +5584,8 @@ rule REVERSINGLABS_Cert_Blocklist_4Ff4Eda5Fa641E70162713426401F438 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3026-L3042" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3026-L3042" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "58f5e163d9807520497ba55e42c048020f6b7653ed71f3954e7ffb490f4de0e4" score = 75 quality = 90 @@ -5556,8 +5609,8 @@ rule REVERSINGLABS_Cert_Blocklist_067Dffc5E3026Eb4C62971C98Ac8A900 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3044-L3060" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3044-L3060" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2b7c4cded14afd8ba3feabb6debaa1317917b811b44e22aa8a0b3ea00d689141" score = 75 quality = 90 @@ -5581,8 +5634,8 @@ rule REVERSINGLABS_Cert_Blocklist_B1Da219688E51Fd0Bfac2C891D56Cbb8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3062-L3080" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3062-L3080" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "03549214940a8689213bd2eb891da1c1991627c81c8b7f26860141c397409d46" score = 75 quality = 90 @@ -5606,8 +5659,8 @@ rule REVERSINGLABS_Cert_Blocklist_7289B0F9Bd641E3E352Dc3183F8De6Be : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3082-L3098" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3082-L3098" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "42b068e85b3aff5e6dd5ec4979f546dc5338ebf8719d86c0641ffb8353959af9" score = 75 quality = 90 @@ -5631,8 +5684,8 @@ rule REVERSINGLABS_Cert_Blocklist_Fd7B7A8678A67181A54Bc7499Eba44Da : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3100-L3118" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3100-L3118" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f1e26ea26890043be2c8b9c35ba2e6758b60fe173f00bf4c77cc5289ce0d5600" score = 75 quality = 90 @@ -5656,8 +5709,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ebbdd6Cdeda40Ca64513280Ecd625C54 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3120-L3138" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3120-L3138" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1d419f2fe2a9bf744bdde48adc50e0bc48746f1576f96570385a2a1c9ba92d21" score = 75 quality = 90 @@ -5681,8 +5734,8 @@ rule REVERSINGLABS_Cert_Blocklist_61Da676C1Dcfcf188276E2C70D68082E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3140-L3156" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3140-L3156" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4f8af4a5c9812e6559218e387e32bc02cb0adcd40d9d4963fefc929f6101ae9a" score = 75 quality = 90 @@ -5706,8 +5759,8 @@ rule REVERSINGLABS_Cert_Blocklist_767436921B2698Bd18400A24B01341B6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3158-L3174" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3158-L3174" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "759bbbc5929463ad68d5dcd28b30401b9ff680f522172ed8d5d7dd3772e07587" score = 75 quality = 90 @@ -5731,8 +5784,8 @@ rule REVERSINGLABS_Cert_Blocklist_3E795531B3265510F935187Eca59920A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3176-L3192" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3176-L3192" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d597e88314f9f20283b40058dd74167d0d72f7518277a57f26c15e44b670b386" score = 75 quality = 90 @@ -5756,8 +5809,8 @@ rule REVERSINGLABS_Cert_Blocklist_8F40B1485309A064A28B96Bfa3F55F36 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3194-L3212" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3194-L3212" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "58dd47bfd2acd698bc27fb03eb51e4b8598ef6c71f7193e3cc4eea63982855f0" score = 75 quality = 90 @@ -5781,8 +5834,8 @@ rule REVERSINGLABS_Cert_Blocklist_B2120Facadbb92Cc0A176759604C6A0F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3214-L3232" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3214-L3232" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "08462b1bd3d45824aeea901a4db19365c28d8b8b0f594657df7a59250111729b" score = 75 quality = 90 @@ -5806,8 +5859,8 @@ rule REVERSINGLABS_Cert_Blocklist_4F407Eb50803845Cc43937823E1344C0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3234-L3250" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3234-L3250" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4d5a2b0619be902d8a437f204ae1b87222c73d3186930809b1f694bad429aea8" score = 75 quality = 90 @@ -5831,8 +5884,8 @@ rule REVERSINGLABS_Cert_Blocklist_6922Bb5De88E4127E1Ac6969E6A199F5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3252-L3268" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3252-L3268" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "39dbaa232ea9125934b3682d780e3821d12e771f2b844d027d99a432fe249d9f" score = 75 quality = 90 @@ -5856,8 +5909,8 @@ rule REVERSINGLABS_Cert_Blocklist_73065Efa163B7901Fa1Ccb0A54E80540 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3270-L3286" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3270-L3286" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e420c37c04aa676c266a4c2c228063239815c173a83c39d426c5a674648f1934" score = 75 quality = 90 @@ -5881,8 +5934,8 @@ rule REVERSINGLABS_Cert_Blocklist_4842Afad00904Ed8C98811E652Ccb3B7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3288-L3304" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3288-L3304" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2b5c7c13369c7b89f1ea5474de3644a12bf6412cb3fa8ade5b66de280fb10cbf" score = 75 quality = 90 @@ -5906,8 +5959,8 @@ rule REVERSINGLABS_Cert_Blocklist_5A59A686B4A904D0Fca07153Ea6Db6Cc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3306-L3322" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3306-L3322" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7597b2ba870ec58ac0786a97fb92956406fe019c81f6176cc1a581988d3a9632" score = 75 quality = 90 @@ -5931,8 +5984,8 @@ rule REVERSINGLABS_Cert_Blocklist_0B6D8152F4A06Ba781C6677Eea5Ab74B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3324-L3340" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3324-L3340" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bd20cf8e4cab2117361dbe05ae2efe813e7f55667b1f3825cd893313d98dcb5f" score = 75 quality = 90 @@ -5956,8 +6009,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Ad60Cea73E1Dd1A3E6C02D9B339C380 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3342-L3358" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3342-L3358" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fb83cf25be19e7cccd2c8369c3a37a90af72cb2f76db3619b8311d2a851335a8" score = 75 quality = 90 @@ -5981,8 +6034,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Df2Dfed47C6Fd6542131847Cffbc102 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3360-L3376" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3360-L3376" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fc6adbfd45ff6ac465aecb3db862421f02170e977fc044017f3ddc306a9f7a37" score = 75 quality = 90 @@ -6006,8 +6059,8 @@ rule REVERSINGLABS_Cert_Blocklist_74Fedf0F8398060Fa8378C6D174465C8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3378-L3394" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3378-L3394" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "406821c7990f05fdad91704f6418304f53dd4800bc4b41912177a1695858fade" score = 75 quality = 90 @@ -6031,8 +6084,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Bd6A5Bba28E7C1Ca44880159Dace237 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3396-L3412" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3396-L3412" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f885c782148947d09133a3cc65319e02204c21d6c6d911b360840f25f37601dc" score = 75 quality = 90 @@ -6056,8 +6109,8 @@ rule REVERSINGLABS_Cert_Blocklist_C04F8F1E00C69E96A51Bf14Aab1C6Ae0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3414-L3432" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3414-L3432" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c2b5ffa305b761b57dd91c0acea0d8f82bec6b7d3608be10a20ea63621f3f3e8" score = 75 quality = 90 @@ -6081,8 +6134,8 @@ rule REVERSINGLABS_Cert_Blocklist_23F537Ce13C6Cccdfd3F8Ce81Fb981Cb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3434-L3450" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3434-L3450" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d347bce3eddd0cac276a7504955f0342ae44fd93d238e514af5b1fdc208b68fc" score = 75 quality = 90 @@ -6106,8 +6159,8 @@ rule REVERSINGLABS_Cert_Blocklist_73Ecfdbb99Aec176Ddfcf7958D120E1A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3452-L3468" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3452-L3468" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d911156707cef97acf79c096b5d4a4db166ddf05237168f1ecffb0c0a2ebd8fa" score = 75 quality = 90 @@ -6131,8 +6184,8 @@ rule REVERSINGLABS_Cert_Blocklist_675129Bb174A5B05E330Cc09F8Bbd70A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3470-L3486" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3470-L3486" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d989ea5233e8a64bffa0e29645c3458ef1f5173158ced7814c3b473b92ef49f4" score = 75 quality = 90 @@ -6156,8 +6209,8 @@ rule REVERSINGLABS_Cert_Blocklist_De13Fe2Dbb8F890287E1780Aff6Ffd22 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3488-L3504" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3488-L3504" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ebd983bcfa1e5d54af9d9e07d80d05f4752040eab92e63cd986db789fa07026f" score = 75 quality = 90 @@ -6181,8 +6234,8 @@ rule REVERSINGLABS_Cert_Blocklist_Da000D18949C247D4Ddfc2585Cc8Bd0F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3506-L3524" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3506-L3524" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3453f13e633a2c233f78d0389c655bb5304e567407b3e0c5c47e5e7127c345ca" score = 75 quality = 90 @@ -6206,8 +6259,8 @@ rule REVERSINGLABS_Cert_Blocklist_06E842D3Ea6249D783D6B55E29C060C7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3526-L3542" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3526-L3542" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9f71de0119527c8580f9e47e3fba07242814c5a537d727d4541fd7a802b0cb86" score = 75 quality = 90 @@ -6231,8 +6284,8 @@ rule REVERSINGLABS_Cert_Blocklist_06473C3C19D9E1A9429B58B6Faec2967 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3544-L3560" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3544-L3560" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f9ca49ce65d213dce803806956c0ce1da0c4068bea173daae9cb06dab0a86268" score = 75 quality = 90 @@ -6256,8 +6309,8 @@ rule REVERSINGLABS_Cert_Blocklist_39F56251Df2088223Cc03494084E6081 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3562-L3578" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3562-L3578" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c87850f91758a5bb3bdf6f6d7de9a3f53077d64cebdde541ac0742d3cea4f4e0" score = 75 quality = 90 @@ -6281,8 +6334,8 @@ rule REVERSINGLABS_Cert_Blocklist_1362E56D34Dc7B501E17Fa1Ac3C3E3D9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3580-L3596" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3580-L3596" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0415c5a49076bab23dfc29ef2d6168b93d6bfde07a89ccb0368d2c967422407a" score = 75 quality = 90 @@ -6306,8 +6359,8 @@ rule REVERSINGLABS_Cert_Blocklist_4B83593Fc78D92Cfaa9Bdf3F97383964 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3598-L3614" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3598-L3614" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "775e41fc102cbaeb9374984380b0e073de2a0075b9a200f8ab644bd1369ba015" score = 75 quality = 90 @@ -6331,8 +6384,8 @@ rule REVERSINGLABS_Cert_Blocklist_C7505E7464E00Ec1Dccd8D1B466D15Ff : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3616-L3634" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3616-L3634" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7c5c84cb9071eff6a1bd7062506b807466bb4a432d1ed073961898c6c08cc4bd" score = 75 quality = 90 @@ -6356,8 +6409,8 @@ rule REVERSINGLABS_Cert_Blocklist_Cbf91988Fb83511De1B3A7A520712E9C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3636-L3654" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3636-L3654" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5862a8ec43d2e545f36b815ada2bb31c4384a8161c6956a31f3bd517532923fd" score = 75 quality = 90 @@ -6381,8 +6434,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ce3675Ae4Abfe688870Bcacb63060F4F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3656-L3674" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3656-L3674" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0c6f2ef55bef283a3f915fd8c1ced27c3c665f7f490caeea0f180c2d7fa2b2b5" score = 75 quality = 90 @@ -6406,8 +6459,8 @@ rule REVERSINGLABS_Cert_Blocklist_9813229Efe0046D23542Cc7569D5A403 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3676-L3694" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3676-L3694" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0d8f0df83572b8d31f29cb76f44d524fd1ae0467d2d99af959e45694524d18e8" score = 75 quality = 90 @@ -6431,8 +6484,8 @@ rule REVERSINGLABS_Cert_Blocklist_86E5A9B9E89E5075C475006D0Ca03832 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3696-L3714" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3696-L3714" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5ba0b0f1b104eb11023590b8ef2b9cc747372bc9310a754694d45d3b3ce293e9" score = 75 quality = 90 @@ -6456,8 +6509,8 @@ rule REVERSINGLABS_Cert_Blocklist_075Dca9Ca84B93E8A89B775128F90302 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3716-L3732" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3716-L3732" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "32af21e71fb3475c50de4cd8a24fa0aec1ee67bc01c1a3720c12f9ce822833c3" score = 75 quality = 90 @@ -6481,8 +6534,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Ddce8Cdc91B5B649Bb4B45Ffbba6C6C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3734-L3750" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3734-L3750" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "622e6ed08ca26908539519f37cf493f8030100bd5e88cb05e851b7d56b0f4c0d" score = 75 quality = 90 @@ -6506,8 +6559,8 @@ rule REVERSINGLABS_Cert_Blocklist_9Bd614D5869Bb66C96B67E154D517384 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3752-L3770" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3752-L3770" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d9eea38a1340797cef129b12cf2bb46c444e6f312db7356260f0ac0d9e63183d" score = 75 quality = 90 @@ -6531,8 +6584,8 @@ rule REVERSINGLABS_Cert_Blocklist_540Cea639D5D48669B7F2F64 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3772-L3788" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3772-L3788" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3d3774f10ff9949ea13a7892662438b84b3eb895fc986092649fa9b192170d48" score = 75 quality = 90 @@ -6556,8 +6609,8 @@ rule REVERSINGLABS_Cert_Blocklist_03A7748A4355020A652466B5E02E07De : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3790-L3806" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3790-L3806" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6dc6d0fd2b702939847981ff31c2d8103227ccd0c19f999849ff89c64a90f92f" score = 75 quality = 90 @@ -6581,8 +6634,8 @@ rule REVERSINGLABS_Cert_Blocklist_B881A72D4117Bbc38B81D3C65C792C1A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3808-L3826" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3808-L3826" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bad2a06090f077ebc635d21446b47c9f115fe477567afb3d5994043f5a7883b1" score = 75 quality = 90 @@ -6606,8 +6659,8 @@ rule REVERSINGLABS_Cert_Blocklist_08653Ef2Ed9E6Ebb56Ffa7E93F963235 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3828-L3844" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3828-L3844" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5ae8d2fb03cd0f945c2f5eb86de4e5da4fbb1cdf233d8a808157304538ced872" score = 75 quality = 90 @@ -6631,8 +6684,8 @@ rule REVERSINGLABS_Cert_Blocklist_9C4816D900A6Ecdbe54Adf72B19Ebcf5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3846-L3864" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3846-L3864" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "92e8130f444417d5bc3788721280338bbed33e3362104de0cf27bc7c1fc30d0e" score = 75 quality = 90 @@ -6656,8 +6709,8 @@ rule REVERSINGLABS_Cert_Blocklist_269174F9Fe7C6Ed4E1D19B26C3F5B35F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3866-L3882" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3866-L3882" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "95c9720d6311c2fe7026b6cac092d59967479e6c9382eac1d26f7745efa92860" score = 75 quality = 90 @@ -6681,8 +6734,8 @@ rule REVERSINGLABS_Cert_Blocklist_523Fb4036368Dc26192D68827F2D889B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3884-L3900" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3884-L3900" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f1886a046305637d335c493972560de56d8186bf99183aed5e2040b2e530fc22" score = 75 quality = 90 @@ -6706,8 +6759,8 @@ rule REVERSINGLABS_Cert_Blocklist_84F842F6D33Cd2F25B88Dd1710E21137 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3902-L3920" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3902-L3920" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5aad8e95d1306626b63d767fce4706104330dd776b75c09cc404227863564307" score = 75 quality = 90 @@ -6731,8 +6784,8 @@ rule REVERSINGLABS_Cert_Blocklist_4Fbcaa289Ba925B4E247809B6B028202 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3922-L3938" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3922-L3938" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c41a4f9ccda54b9735313edf9042b831e6eaca149c089f74a823cee6719e1064" score = 75 quality = 90 @@ -6756,8 +6809,8 @@ rule REVERSINGLABS_Cert_Blocklist_1F2E8Effbb08C7Dbcc7A7F2D835457B5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3940-L3956" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3940-L3956" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0b446641617d435c3d312592957e19c3d391b0149eafcf9ac2da51e8d9080eb4" score = 75 quality = 90 @@ -6781,8 +6834,8 @@ rule REVERSINGLABS_Cert_Blocklist_Aeba4C39306Fdd022849867801645814 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3958-L3976" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3958-L3976" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "82c149f1d8ef93a0df2035690c5cdca935236687bc36a35a84c3d6610eb6902c" score = 75 quality = 90 @@ -6806,8 +6859,8 @@ rule REVERSINGLABS_Cert_Blocklist_028D50Ae0C554B49148E82Db5B1C2699 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3978-L3994" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3978-L3994" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e3cc0066cad56d78a3f42e092befa3b0855b2ed33c8465c5ecbb19fec082d35e" score = 75 quality = 90 @@ -6831,8 +6884,8 @@ rule REVERSINGLABS_Cert_Blocklist_684F478C7259Dde0Cfe2260112Ca9846 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L3996-L4012" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L3996-L4012" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "59654ba1df27029a04ef3b1a1bb54f6c15b727f2013923a11a729752b8829743" score = 75 quality = 90 @@ -6856,8 +6909,8 @@ rule REVERSINGLABS_Cert_Blocklist_0B7C32208A954A483Dd102E1Be094867 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4014-L4030" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4014-L4030" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "49e2208a7d2b5684283c1dfc9856f864d16b50f951f58e0252c97419819a46ec" score = 75 quality = 90 @@ -6881,8 +6934,8 @@ rule REVERSINGLABS_Cert_Blocklist_3E72Daf2B9A4449E946009E5084A8E76 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4032-L4048" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4032-L4048" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f1a7bf6c18e0ebf8aef53feb7d7789ce87c96e00962c64e07a37d968702d2fa5" score = 75 quality = 90 @@ -6906,8 +6959,8 @@ rule REVERSINGLABS_Cert_Blocklist_11Edd343E21C36Ac985555D85C16135F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4050-L4066" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4050-L4066" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "17feeed4be074a30572eb12fc81dc15d1b06f2d3f7b4b4fb4443391c62ac4d9b" score = 75 quality = 90 @@ -6931,8 +6984,8 @@ rule REVERSINGLABS_Cert_Blocklist_093Fe63D1A5F68F14Ecaac871A03F7A3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4068-L4084" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4068-L4084" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "333c58a9af2d94604b637ab0a7280b6688a89ff73e30a93a8daed040fab7f620" score = 75 quality = 90 @@ -6956,8 +7009,8 @@ rule REVERSINGLABS_Cert_Blocklist_Bb26B7B6634D5Db548C437B5085B01C1 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4086-L4104" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4086-L4104" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "58d574b196f84416eb04000205cd8f4817618003f2948bb0eb7d951c282ef6ff" score = 75 quality = 90 @@ -6981,8 +7034,8 @@ rule REVERSINGLABS_Cert_Blocklist_29128A56E7B3Bfb230742591Ac8B4718 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4106-L4122" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4106-L4122" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5a89fec015e56ddddaed75be91a87288dcd27841937d26e3416187913c4f0b85" score = 75 quality = 90 @@ -7006,8 +7059,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Bfbfdfef43608730Ee14779Ee3Ee2Cb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4124-L4140" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4124-L4140" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f8f233b78e9d3558b0cd7978e3c5fa32645a3bb706c6fdec7f1e4195cf513f10" score = 75 quality = 90 @@ -7031,8 +7084,8 @@ rule REVERSINGLABS_Cert_Blocklist_62205361A758B00572D417Cba014F007 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4142-L4158" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4142-L4158" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ebf28921c81191bcf6130baf6532122bb320cc916e38ab225f0acdcb57ea00f3" score = 75 quality = 90 @@ -7056,8 +7109,8 @@ rule REVERSINGLABS_Cert_Blocklist_4B47D18Dbea57Abd1563Ddf89F87A6C2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4160-L4176" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4160-L4176" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2e464f4e9bfe0c9510a78552acffb241d2435ea9bf3f5f2501353d7f8f280d78" score = 75 quality = 90 @@ -7081,8 +7134,8 @@ rule REVERSINGLABS_Cert_Blocklist_Be41E2C7Bb2493044B9241Abb732599D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4178-L4196" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4178-L4196" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "eb5d94b80fd030d14dc26878895c61761825f3c77209ca0280e88dcd1800f9c2" score = 75 quality = 90 @@ -7106,8 +7159,8 @@ rule REVERSINGLABS_Cert_Blocklist_15C5Af15Afecf1C900Cbab0Ca9165629 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4198-L4214" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4198-L4214" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5c54f32dbac271b2b60ec40bd052b5566a512cd2bcb4255057b21262806882d2" score = 75 quality = 90 @@ -7131,8 +7184,8 @@ rule REVERSINGLABS_Cert_Blocklist_476De2F108D20B43Ba3Bae6F331Af8F1 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4216-L4232" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4216-L4232" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e5edf3e15b2139ba6cd85f2cfea63b53f7fa36a3fd7224a4a9ccbe5de6eb6f1d" score = 75 quality = 90 @@ -7156,8 +7209,8 @@ rule REVERSINGLABS_Cert_Blocklist_08Ddcc67F8Cad6929607E4Cda29B3503 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4234-L4250" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4234-L4250" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4cd975312ca825b51f34f5c89184a56526877436224c1e7407d715b28ebfd9d5" score = 75 quality = 90 @@ -7181,8 +7234,8 @@ rule REVERSINGLABS_Cert_Blocklist_052242Ace583Adf2A3B96Adcb04D0812 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4252-L4268" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4252-L4268" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e1593a2bf375912e411d5f19d9e232c6b87f0897bb6f1c0b0539380b34b05af5" score = 75 quality = 90 @@ -7206,8 +7259,8 @@ rule REVERSINGLABS_Cert_Blocklist_Bebef5C533Ce92Efc402Fab8605C43Ec : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4270-L4288" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4270-L4288" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "daa57ad622799467c60693060e6c9eea18bdf0bb26f178e8b03453aab486ccf4" score = 75 quality = 90 @@ -7231,8 +7284,8 @@ rule REVERSINGLABS_Cert_Blocklist_1D3F39F481Fe067F8A9289Bb49E05A04 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4290-L4306" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4290-L4306" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2fdf8b59d302d2ce81a1e9a5715138adc1ec45bd86871c4c2e46412407e329f9" score = 75 quality = 90 @@ -7256,8 +7309,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Be35D025E65Cc7A4Ee01F72 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4308-L4324" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4308-L4324" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "dad7ab834a67d36c0b63e45922aea566dc0aaf922be2b74161616b3caea83fdc" score = 75 quality = 90 @@ -7281,8 +7334,8 @@ rule REVERSINGLABS_Cert_Blocklist_351Fe2Efdc0Ac56A0C822Cf8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4326-L4342" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4326-L4342" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "46b87c3531e01ba150f056ec3270564426363ef8c58256eeedbcab247c7625e4" score = 75 quality = 90 @@ -7306,8 +7359,8 @@ rule REVERSINGLABS_Cert_Blocklist_9Cfbb4C69008821Aaacecde97Ee149Ab : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4344-L4362" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4344-L4362" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d74b13eeb5d0a57c5dd3257480230c504a68a8422e77a46bb2e101abb2c7f282" score = 75 quality = 90 @@ -7331,8 +7384,8 @@ rule REVERSINGLABS_Cert_Blocklist_C04F5D17Af872Cb2C37E3367Fe761D0D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4364-L4382" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4364-L4382" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4a4d60aa3722a710fe23d5e11c55a28bfe721bb4e797b041d58f62a994487799" score = 75 quality = 90 @@ -7356,8 +7409,8 @@ rule REVERSINGLABS_Cert_Blocklist_02C5351936Abe405Ac760228A40387E8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4384-L4400" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4384-L4400" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5a990f8d1a3f467cdafa0f625bc162745d9201e15ce43fdc93cd6b1730572e89" score = 75 quality = 90 @@ -7381,8 +7434,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Ecd829Adcc55D9D6Afe30Dc371Ebda6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4402-L4420" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4402-L4420" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "02955f4df7deccab52cdd82fd04d5012db7440f85c87d750fa9f81ff85e2dab0" score = 75 quality = 90 @@ -7406,8 +7459,8 @@ rule REVERSINGLABS_Cert_Blocklist_B0167124Ca59149E64D292Eb4B142014 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4422-L4440" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4422-L4440" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "10d980d4a71dab4679376f5a6d6a6999e0b59af4f25587a7b8d1ef52a7808cc9" score = 75 quality = 90 @@ -7431,8 +7484,8 @@ rule REVERSINGLABS_Cert_Blocklist_112613B7B5F696Cf377680F6463Fcc8C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4442-L4458" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4442-L4458" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "50fd35617e059a5fe9d9e0fdb4b880c20e406357bbb2d037f9e6e9db47b8e49f" score = 75 quality = 90 @@ -7456,8 +7509,8 @@ rule REVERSINGLABS_Cert_Blocklist_B3F906E5E6B2Cf61C5E51Be79B4E8777 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4460-L4478" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4460-L4478" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "037e154854c1128fb73d2221c2b7d7211d977492378614fcf4fde959207e34b3" score = 75 quality = 90 @@ -7481,8 +7534,8 @@ rule REVERSINGLABS_Cert_Blocklist_566Ac16A57B132D3F64Dced14De790Ee : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4480-L4496" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4480-L4496" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "48f4d334614f6c413907d51f4d6312554b13c4f5a3c03070ceba48baa13a8247" score = 75 quality = 90 @@ -7506,8 +7559,8 @@ rule REVERSINGLABS_Cert_Blocklist_D2Caf7908Aaebfa1A8F3E2136Fece024 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4498-L4516" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4498-L4516" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cf4d17274ef36d61e78578d34634bf6e5fb0fb857a9a92184916b0f3b8484568" score = 75 quality = 90 @@ -7531,8 +7584,8 @@ rule REVERSINGLABS_Cert_Blocklist_E04A344B397F752A45B128A594A3D6B5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4518-L4536" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4518-L4536" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0489577c6050f0c5d1dad5bda8c4f3c895902b932cd0324087712ccb83f14680" score = 75 quality = 90 @@ -7556,8 +7609,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Bcaed3Ef678F2F9Bf38D09E149B8D70 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4538-L4554" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4538-L4554" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "dbf85cbd1d92823287749dac312f95576900753f60a694347b31b1e3aaa288a8" score = 75 quality = 90 @@ -7581,8 +7634,8 @@ rule REVERSINGLABS_Cert_Blocklist_56D576A062491Ea0A5877Ced418203A1 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4556-L4572" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4556-L4572" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "19bd6834b432f3dc8786b449241082b359275559a112a8ef4a51efe185b256dc" score = 75 quality = 90 @@ -7606,8 +7659,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Fcba260Df7Da602Ecf4D4D6Fc89D5Dd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4574-L4590" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4574-L4590" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4e9a3e516342820248ebf9b3605b8ce2dbf1d9b4255a5b74f7369dd2f1cdd9d8" score = 75 quality = 90 @@ -7631,8 +7684,8 @@ rule REVERSINGLABS_Cert_Blocklist_4152169F22454Ed604D03555B7Afb175 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4592-L4608" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4592-L4608" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fbb2124b934c270739f564317526d5b23b996364372426485d7c994a83293866" score = 75 quality = 90 @@ -7656,8 +7709,8 @@ rule REVERSINGLABS_Cert_Blocklist_01C88Ccbd219500139D1Af138A9E898E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4610-L4626" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4610-L4626" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d1acb0a7d6e20158797e77c066be42548cee9293fa94f24f936a95977ac16d91" score = 75 quality = 90 @@ -7681,8 +7734,8 @@ rule REVERSINGLABS_Cert_Blocklist_41D05676E0D31908Be4Dead3486Aeae3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4628-L4644" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4628-L4644" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c4905f02c74df6d05b3f9a6fe2c4f5f32a02bb10da4db929314be043be76d703" score = 75 quality = 90 @@ -7706,8 +7759,8 @@ rule REVERSINGLABS_Cert_Blocklist_8Cff807Edaf368A60E4106906D8Df319 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4646-L4664" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4646-L4664" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6fc98519faf218d90bb4e01821e6014e009c0b525cfd3c906a64ef82bc20beda" score = 75 quality = 90 @@ -7731,8 +7784,8 @@ rule REVERSINGLABS_Cert_Blocklist_A3E62Be1572293Ad618F58A8Aa32857F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4666-L4684" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4666-L4684" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f849898465bc651f19f6f1b54315c061466d8c5860ecf1a07f54c8c8292f6a95" score = 75 quality = 90 @@ -7756,8 +7809,8 @@ rule REVERSINGLABS_Cert_Blocklist_672D4428450Afcc24Fc60969A5063A3E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4686-L4702" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4686-L4702" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8f5927e96109184bad7de4513994fd1021fe1cc5977e60fa72d808df95cb4516" score = 75 quality = 90 @@ -7781,8 +7834,8 @@ rule REVERSINGLABS_Cert_Blocklist_Df479E14A70C7970A4De3Dd3E4Bb0318 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4704-L4722" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4704-L4722" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "35b1f04cf5d5d1d89db537bf75737e3af5945e594f4d4231e9ae3e7fba52fc0d" score = 75 quality = 90 @@ -7806,8 +7859,8 @@ rule REVERSINGLABS_Cert_Blocklist_2924785Fd7990B2D510675176Dae2Bed : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4724-L4740" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4724-L4740" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e308ca5f24ed5811e947289caf9aa820a16b08ea183c7aa9826f8a726fb5c3cf" score = 75 quality = 90 @@ -7831,8 +7884,8 @@ rule REVERSINGLABS_Cert_Blocklist_F4D2Def53Bccb0Dd2B7D54E4853A2Fc5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4742-L4760" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4742-L4760" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9991f44b8e984bd79269c44999481258d94bec9c21b154b63c6c30ae52344b3c" score = 75 quality = 90 @@ -7856,8 +7909,8 @@ rule REVERSINGLABS_Cert_Blocklist_03Bf9Ef4Cf037A2385649026C3Da9D3E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4762-L4778" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4762-L4778" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "14196bad586b1349e6e8a1eb5621ce0d8d346ff8021c8ef80804de1533fd40d9" score = 75 quality = 90 @@ -7881,8 +7934,8 @@ rule REVERSINGLABS_Cert_Blocklist_790177A54209D55560A55Db97C5900D6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4780-L4796" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4780-L4796" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "07c8e21fe604b481beebae784eb49e32bebee70e749581a55313bfbc757752e2" score = 75 quality = 90 @@ -7906,8 +7959,8 @@ rule REVERSINGLABS_Cert_Blocklist_048F7B5F67D8E2B3030F75Eb7Be2713D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4798-L4814" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4798-L4814" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6d1b47f3c9d7b90a5470f83a848adeebff2cf9341a1eb41ca8b45d08b469b17f" score = 75 quality = 90 @@ -7931,8 +7984,8 @@ rule REVERSINGLABS_Cert_Blocklist_082023879112289Bf351D297Cc8Efcfc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4816-L4832" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4816-L4832" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "58bec160445765ce45a26bf9d96ba6cfe61eee31e0953009d40a7ec64920c677" score = 75 quality = 90 @@ -7956,8 +8009,8 @@ rule REVERSINGLABS_Cert_Blocklist_0D53690631Dd186C56Be9026Eb931Ae2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4834-L4850" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4834-L4850" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3d0a80c062800f935fa3837755e8a91245e01a4e2450a05fecab5564cb62c15c" score = 75 quality = 90 @@ -7981,8 +8034,8 @@ rule REVERSINGLABS_Cert_Blocklist_32119925A6Ce4710Aecc4006C28E749F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4852-L4868" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4852-L4868" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ca812cdfbb7ca984fae1e16159eb0eeb1e65767fcc6aa07eeb84966853146f9d" score = 75 quality = 90 @@ -8006,8 +8059,8 @@ rule REVERSINGLABS_Cert_Blocklist_2C90Eaf4De3Afc03Ba924C719435C2A3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4870-L4888" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4870-L4888" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5bb78a5e39f9d023cf63edabdc83d4965fc79f6f04f9fea9bcf2a53223fbd4ca" score = 75 quality = 90 @@ -8031,8 +8084,8 @@ rule REVERSINGLABS_Cert_Blocklist_Aff762E907F0644E76Ed8A7485Fb12A1 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4890-L4908" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4890-L4908" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ad05389e0eb30cb894b03842d213b8c956f66357a913c73d8d8b79f8336bf980" score = 75 quality = 90 @@ -8056,8 +8109,8 @@ rule REVERSINGLABS_Cert_Blocklist_D8530214Ca0F512946496B5164C61201 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4910-L4928" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4910-L4928" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "377962915586c9f5a5737c24b698c96efc2e819e52ee16109c405f9af2d57e7f" score = 75 quality = 90 @@ -8081,8 +8134,8 @@ rule REVERSINGLABS_Cert_Blocklist_661Ba8F3C9D1B348413484E9A49502F7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4930-L4948" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4930-L4948" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4840b311c1e2c0ae14bb2cf6fa8d96ab1a434ceac861db540697f3aed1a6833f" score = 75 quality = 90 @@ -8106,8 +8159,8 @@ rule REVERSINGLABS_Cert_Blocklist_51Aead5A9Ab2D841B449Fa82De3A8A00 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4950-L4966" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4950-L4966" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e53095aab9d6c2745125e8cd933334ebc2e51a9725714d31a46baa74b8e42ed9" score = 75 quality = 90 @@ -8131,8 +8184,8 @@ rule REVERSINGLABS_Cert_Blocklist_03B630F9645531F8868Dae8Ac0F8Cfe6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4968-L4984" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4968-L4984" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6d2f4346760bf52a438c4c996e92a2641bebfd536248776383d7c8394e094e6a" score = 75 quality = 90 @@ -8156,8 +8209,8 @@ rule REVERSINGLABS_Cert_Blocklist_6F8373Cf89F1B49138F4328118487F9E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L4986-L5002" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L4986-L5002" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f926c2f73d47d463721a0cad48d9866192df55d71867941a40cba7e0b7725102" score = 75 quality = 90 @@ -8181,8 +8234,8 @@ rule REVERSINGLABS_Cert_Blocklist_E38259Cf24Cc702Ce441B683Ad578911 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5004-L5022" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5004-L5022" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2428df14a18f4aed1a3db85c1fb43a847fae8a922c6dc948f3bc514dc4cae09c" score = 75 quality = 90 @@ -8206,8 +8259,8 @@ rule REVERSINGLABS_Cert_Blocklist_Bdc81Bc76090Dae0Eee2E1Eb744A4F9A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5024-L5042" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5024-L5042" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4fc3e57bedb6fb7c96e6a1ee2ad2aec3860716ac714d52ea58b86be4bbda4660" score = 75 quality = 90 @@ -8231,8 +8284,8 @@ rule REVERSINGLABS_Cert_Blocklist_B2E730B0526F36Faf7D093D48D6D9997 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5044-L5062" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5044-L5062" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f74cc94428d7739abf6ee76f6cbd53aa47cea815a014de0d786fe53b15f66201" score = 75 quality = 90 @@ -8256,8 +8309,8 @@ rule REVERSINGLABS_Cert_Blocklist_7156Ec47Ef01Ab8359Ef4304E5Af1A05 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5064-L5080" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5064-L5080" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7bb093287dd309ce12859eca9a9fc98095b3d52ec860626fe6e743bace262fde" score = 75 quality = 90 @@ -8281,8 +8334,8 @@ rule REVERSINGLABS_Cert_Blocklist_13794371C052Ec0559E9B492Abb25C26 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5082-L5098" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5082-L5098" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7383d1fb1fa6e49f8fa9e1eecfe3fcedb8a11702fbd3700630a11b12da29fedf" score = 75 quality = 90 @@ -8306,8 +8359,8 @@ rule REVERSINGLABS_Cert_Blocklist_5C7E78F53C31D6Aa5B45De14B47Eb5C4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5100-L5116" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5100-L5116" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7521abc5c93f0336af4fab95268962aa3d3fb48fed6a8ba7fdb98e373158b327" score = 75 quality = 90 @@ -8331,8 +8384,8 @@ rule REVERSINGLABS_Cert_Blocklist_Dadf44E4046372313Ee97B8E394C4079 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5118-L5136" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5118-L5136" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "170533935b91776ec2413106c55ed4a01c33f32a469a855824cac796f2e132a0" score = 75 quality = 90 @@ -8356,8 +8409,8 @@ rule REVERSINGLABS_Cert_Blocklist_F8C2E08438Bb0E9Adc955E4B493E5821 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5138-L5156" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5138-L5156" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5dbe554032c945c46ffd61ef1e0deb59d396a70dd63994bf44c65d849ec8220a" score = 75 quality = 90 @@ -8381,8 +8434,8 @@ rule REVERSINGLABS_Cert_Blocklist_70E1Ebd170Db8102D8C28E58392E5632 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5158-L5174" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5158-L5174" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e1738eddc1da0876a373ee7f35bff155d56c1b98a23cb117c0e7a966f8fa3c92" score = 75 quality = 90 @@ -8406,8 +8459,8 @@ rule REVERSINGLABS_Cert_Blocklist_09C89De6F64A7Fdf657E69353C5Fdd44 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5176-L5192" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5176-L5192" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1cb57cd68cda91754307d2e4d94ea011975bbfff0f15134081a5aa11870b0db1" score = 75 quality = 90 @@ -8431,8 +8484,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ffff2Ce862378B26440Df49Ca9175B70 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5194-L5212" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5194-L5212" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8ed7b0643b07ce4954f570157e1534ee1ed647717cce00fe7f2b572c9b5d0042" score = 75 quality = 90 @@ -8456,8 +8509,8 @@ rule REVERSINGLABS_Cert_Blocklist_3223B4616C2687C04865Bee8321726A8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5214-L5230" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5214-L5230" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fcb0a14866b3612c5ec5a7db7a3333e20a4605695b3d019eef84de85d7b3ea4d" score = 75 quality = 90 @@ -8481,8 +8534,8 @@ rule REVERSINGLABS_Cert_Blocklist_7709D2Df39E9A4F7Db2F3Cbc29B49743 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5232-L5248" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5232-L5248" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c9ade45e0f9fb737a08ffa94d1fff89471a1cbcbacc139730fab88e382226d0b" score = 75 quality = 90 @@ -8506,8 +8559,8 @@ rule REVERSINGLABS_Cert_Blocklist_E29690E14518874D2Dcf00234Ae94F1F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5250-L5268" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5250-L5268" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ef84815798b213dc49a142e3076cc6dd680dccabe72643fc86234024a46468f9" score = 75 quality = 90 @@ -8531,8 +8584,8 @@ rule REVERSINGLABS_Cert_Blocklist_Cfac705C7E6845904F99995324F7562C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5270-L5288" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5270-L5288" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "68bcfe60c2e7154f427c20d0471ede99e55c8200149a4438d5a2a75982fcd419" score = 75 quality = 90 @@ -8556,8 +8609,8 @@ rule REVERSINGLABS_Cert_Blocklist_A7989F8Be0C82D35A19E7B3Dd4Be30E5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5290-L5308" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5290-L5308" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a50129908a471e6692bcf663abd5ef52861d4a46fdf528f39efe816ee6150edf" score = 75 quality = 90 @@ -8581,8 +8634,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Fa13Ae98E17Ae23Fcfe7Ae873D0C120 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5310-L5326" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5310-L5326" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "415f39f82b6a45acd196ccf246ec660806a8d66c61df8c7d2850e5b244118d04" score = 75 quality = 90 @@ -8606,8 +8659,8 @@ rule REVERSINGLABS_Cert_Blocklist_3696883055975D571199C6B5D48F3Cd5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5328-L5344" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5328-L5344" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d6f77b9ca928167341a35b83e353886d4db8dfcecf45cde0f0f93d65059b5200" score = 75 quality = 90 @@ -8631,8 +8684,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ee678930D5Bdfaa2Ab0172Fa4C10Ae07 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5346-L5364" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5346-L5364" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f1e254450fdbe94172a4fa2d2727c3ade5ae436cf4c0c1153a15e9a2f64f2452" score = 75 quality = 90 @@ -8656,8 +8709,8 @@ rule REVERSINGLABS_Cert_Blocklist_D7C432E8D4Edef515Bfb9D1C214Ff0F5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5366-L5384" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5366-L5384" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "63741513f3ab2f51ecd66dc973239c9dc194b86504fe26b2dd4a7f31299e5497" score = 75 quality = 90 @@ -8681,8 +8734,8 @@ rule REVERSINGLABS_Cert_Blocklist_5B440A47E8Ce3Dd202271E5C7A666C78 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5386-L5402" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5386-L5402" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "eb4387d58e391c356ed774d8c13bb4bbb2befed585bb44674459d3ef519aec58" score = 75 quality = 90 @@ -8706,8 +8759,8 @@ rule REVERSINGLABS_Cert_Blocklist_B82C6553B2186C219797621Aaa233Edb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5404-L5422" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5404-L5422" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "72e3e1740a4adc4315d2dd9c9f7b8cee2d89c3006014dec663b70d3419f43ca3" score = 75 quality = 90 @@ -8731,8 +8784,8 @@ rule REVERSINGLABS_Cert_Blocklist_F360F7Ad0Ed065Fec0B44F98E04481A0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5424-L5442" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5424-L5442" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2a25f1121f492dec461e570ff56acb0e3957cdf9100002f2ff0b6c3d3b35fee5" score = 75 quality = 90 @@ -8756,8 +8809,8 @@ rule REVERSINGLABS_Cert_Blocklist_Fe41941464B9992A69B7317418Ae8Eb7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5444-L5462" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5444-L5462" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bd5131f2b44deec6a7a68577b80ef4d066c331da2976539ce52ac6cff8d5560e" score = 75 quality = 90 @@ -8781,8 +8834,8 @@ rule REVERSINGLABS_Cert_Blocklist_0C14B611A44A1Bae0E8C7581651845B6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5464-L5480" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5464-L5480" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7f6028181e33e4ba8264ee367169e7259e19ff49dcae9a337a4ba78c06b459e6" score = 75 quality = 90 @@ -8806,8 +8859,8 @@ rule REVERSINGLABS_Cert_Blocklist_690910Dc89D7857C3500Fb74Bed2B08D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5482-L5498" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5482-L5498" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3c5da6238279296854eb95ecaed802f453e80c6bceb71c3fa587df0f7d40cf96" score = 75 quality = 90 @@ -8831,8 +8884,8 @@ rule REVERSINGLABS_Cert_Blocklist_Fd41E6Bd7428D3008C8A05F68C9Ac6F2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5500-L5518" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5500-L5518" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e387664dc9aa746e127b4efb2ef43675f8fb6df66e99d33ef765e8fa306a4f18" score = 75 quality = 90 @@ -8856,8 +8909,8 @@ rule REVERSINGLABS_Cert_Blocklist_C7079866C0E48B01246Ba0C148E70D4D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5520-L5538" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5520-L5538" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cc144760e0ca21fd98b55ac222db540900def61f54e9644f8cab5f711ec7bf24" score = 75 quality = 90 @@ -8881,8 +8934,8 @@ rule REVERSINGLABS_Cert_Blocklist_D591Da22F33C800A7024Aecff2Cd6C6D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5540-L5558" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5540-L5558" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "30e421d5ea3c5693c5c9bd0e3dd997ceda9755d17e3fb16d2a8e6c4a327ae32f" score = 75 quality = 90 @@ -8906,8 +8959,8 @@ rule REVERSINGLABS_Cert_Blocklist_B36E0F2053Caee9C3B966F7Be0B40Fc3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5560-L5578" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5560-L5578" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2444c78aefdb9e8c8004598a318db016d7e781ede6da2ba3ee85316456c3e77b" score = 75 quality = 90 @@ -8931,8 +8984,8 @@ rule REVERSINGLABS_Cert_Blocklist_5B320A2F46C99C1Ba1357Bee : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5580-L5596" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5580-L5596" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "12797f80bce9d64c6c07e185aa309a0c4f910835745a7f2cc1874fb1211624d8" score = 75 quality = 90 @@ -8956,8 +9009,8 @@ rule REVERSINGLABS_Cert_Blocklist_08D4352185317271C1Cec9D05C279Af7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5598-L5614" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5598-L5614" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b240962ab23729b241413ed1e53ac6541bf6b8a673c57522efd0cfe0c7eb9dd4" score = 75 quality = 90 @@ -8981,8 +9034,8 @@ rule REVERSINGLABS_Cert_Blocklist_B514E4C5309Ef9F27Add05Bedd4339A0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5616-L5634" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5616-L5634" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "665b280218528bbe3d5c65d043266469e5288587ed9d85d01797bef7ce132a6f" score = 75 quality = 90 @@ -9006,8 +9059,8 @@ rule REVERSINGLABS_Cert_Blocklist_13C7B92282Aae782Bfb00Baf879935F4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5636-L5652" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5636-L5652" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d4edbb446a51e5153ba88d6757d5fb610303eac3fd4bdd3b987b508dc618d2dc" score = 75 quality = 90 @@ -9031,8 +9084,8 @@ rule REVERSINGLABS_Cert_Blocklist_D627F1000D12485995514Bfbdefc55D9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5654-L5672" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5654-L5672" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7ca590d71997879d17054a936238dd5273a52f3438d1b231a75927abfb118ffd" score = 75 quality = 90 @@ -9056,8 +9109,8 @@ rule REVERSINGLABS_Cert_Blocklist_5Fb6Bae8834Edd8D3D58818Edc86D7D7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5674-L5690" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5674-L5690" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a8cec0479bfd53f34e291d56538187c05375e80d20af7f0af08f0db8e1d6ed22" score = 75 quality = 90 @@ -9081,8 +9134,8 @@ rule REVERSINGLABS_Cert_Blocklist_E5Ad42C509A7C24605530D35832C091E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5692-L5710" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5692-L5710" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2d57d1c171734d0da167ce7eba47aecd88cd15063488d79659804c6c2fae00a2" score = 75 quality = 90 @@ -9106,8 +9159,8 @@ rule REVERSINGLABS_Cert_Blocklist_8E3D89C682F7C0Dad70110Cb7B7C8263 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5712-L5730" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5712-L5730" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a0f42c5492469e7f132b000aead2d674fed4ea9c0e168579fd55a6c89b45ae4d" score = 75 quality = 90 @@ -9131,8 +9184,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ef2D35F2Ae82A767A16Be582Ab0D1Ba0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5732-L5750" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5732-L5750" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0709290aeb18bcb855518e150c2768c24ab311f5c727cdc4c40145b879ff88b6" score = 75 quality = 90 @@ -9156,8 +9209,8 @@ rule REVERSINGLABS_Cert_Blocklist_039668034826Df47E6207Ec9Daed57C3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5752-L5768" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5752-L5768" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "792860feec6e599ba22ae3869ef132cf5b7be2e0572e23503e293444fd7c382d" score = 75 quality = 90 @@ -9181,8 +9234,8 @@ rule REVERSINGLABS_Cert_Blocklist_07Bb6A9D1C642C5973C16D5353B17Ca4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5770-L5786" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5770-L5786" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b98dcd4f0ebe870a9dad55cac5b0db81be6062216337b75a74a0aff8436df57f" score = 75 quality = 90 @@ -9206,8 +9259,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A1Dc99E4D5264C45A5090F93242A30A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5788-L5804" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5788-L5804" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1985c9c4f4a93c3088eaec3031df93cf87a9d7ee36b94322330caf3c21982f3c" score = 75 quality = 90 @@ -9231,8 +9284,8 @@ rule REVERSINGLABS_Cert_Blocklist_018093Cfad72Cdf402Eecbe18B33Ec71 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5806-L5822" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5806-L5822" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ac398ef89e691158742598777c320832a750a7410904448778afc7ef3c63c255" score = 75 quality = 90 @@ -9256,8 +9309,8 @@ rule REVERSINGLABS_Cert_Blocklist_569E03988Af60D80Ce60728940850D9B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5824-L5842" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5824-L5842" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3ea894d9e088c2123f9ec87cbf097e2275fae18cad26e926641fe64921808b1e" score = 75 quality = 90 @@ -9281,8 +9334,8 @@ rule REVERSINGLABS_Cert_Blocklist_418F6D959A8A0F82Bef07Ceba3603E52 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5844-L5862" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5844-L5862" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6c13c5e85d6e053319193d1d94f216eeec64405c86d15971419078a1ce6c8ac9" score = 75 quality = 90 @@ -9306,8 +9359,8 @@ rule REVERSINGLABS_Cert_Blocklist_5378C5Bbeba0D3309A35Bb47F63037F7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5864-L5882" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5864-L5882" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a96acf93ca6da4d3bf5177b51996825cd3ea70443577622deccdd11fde579c31" score = 75 quality = 90 @@ -9331,8 +9384,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Bab6A2Aa84B495D9E554A4C42C0126D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5884-L5900" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5884-L5900" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "79b6df421c78fd3e2f05a60f7d875e02519297a0278614c9f63dff8b1b2a2d18" score = 75 quality = 90 @@ -9356,8 +9409,8 @@ rule REVERSINGLABS_Cert_Blocklist_6314001C3235Cd59Bcc3F5278C518804 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5902-L5918" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5902-L5918" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4320f3884c0f7e4939e8988a4e83b8028a5e01fb425ae4faa2273134db835813" score = 75 quality = 90 @@ -9381,8 +9434,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Ed8Ade5D73B73Dade6943D557Ff87E5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5920-L5936" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5920-L5936" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7796b6e7da900be8634e7f1e51cda1275ab1e7c2709af7ecaa8777ab0b518494" score = 75 quality = 90 @@ -9406,8 +9459,8 @@ rule REVERSINGLABS_Cert_Blocklist_0292C7D574132Ba5C0441D1C7Ffcb805 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5938-L5954" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5938-L5954" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d2bcf72f4c5829d161bc40e820eb0b1a85deaa49b749422d5429e27b7fb2b1fe" score = 75 quality = 90 @@ -9431,8 +9484,8 @@ rule REVERSINGLABS_Cert_Blocklist_1F23F001458716D435Cca1A55D660Ec5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5956-L5972" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5956-L5972" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bacfb4b7900ab57d23474e0422bd74fff113296b8db37e8eae3bd456443d28d6" score = 75 quality = 90 @@ -9456,8 +9509,8 @@ rule REVERSINGLABS_Cert_Blocklist_6E0Ccbdfb4777E10Ea6221B90Dc350C2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5974-L5990" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5974-L5990" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "08a1ff7cc3a7680fdbb3235a7b46709cd4ba530a9afeab4344671db9fe893cc4" score = 75 quality = 90 @@ -9481,8 +9534,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Ed1847A2Ae5D71Def1E833Fddd33D38 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L5992-L6008" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L5992-L6008" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0ec5eb8ff1f630284fabfba5c58dd563d471343ace718f79dad08cfe75c3070d" score = 75 quality = 90 @@ -9506,8 +9559,8 @@ rule REVERSINGLABS_Cert_Blocklist_97Df46Acb26B7C81A13Cc467B47688C8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6010-L6028" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6010-L6028" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6f6e0e175caee83eaec2dacedaf564b642195a8815cfd0d4564f581070b0c545" score = 75 quality = 90 @@ -9531,8 +9584,8 @@ rule REVERSINGLABS_Cert_Blocklist_186D49Fac34Ce99775B8E7Ffbf50679D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6030-L6046" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6030-L6046" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0444a5052ee384451ebd85918bbc6bf6d6a75334899a63a8b5828ef06cb9c7ca" score = 75 quality = 90 @@ -9556,8 +9609,8 @@ rule REVERSINGLABS_Cert_Blocklist_B1Aea98Bf0Ce789B6C952310F14Edde0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6048-L6066" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6048-L6066" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6e78750d6aca91e9e6d8f2651a5682ccdab5cd20ee3a74e1f8582eb7bc45d614" score = 75 quality = 90 @@ -9581,8 +9634,8 @@ rule REVERSINGLABS_Cert_Blocklist_2Dcd0699Da08915Dde6D044Cb474157C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6068-L6084" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6068-L6084" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e1a3f27b8b9b642fe1ca73ec54d225f4470b53d0d06f2eea55ad1ad43ec67b39" score = 75 quality = 90 @@ -9606,8 +9659,8 @@ rule REVERSINGLABS_Cert_Blocklist_4B03Cabe6A0481F17A2Dbeb9Aefad425 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6086-L6102" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6086-L6102" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6986e7bd90842647ec6a168c30dca2d5ae8ae5b1c1014f966dd596a78859ac6e" score = 75 quality = 90 @@ -9631,8 +9684,8 @@ rule REVERSINGLABS_Cert_Blocklist_64Cd303Fa289790Afa03C403E9240002 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6104-L6120" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6104-L6120" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f51556a8a12affbd7f7633bf8daa50e6332fa3d3448ea08853cf8ed28e593680" score = 75 quality = 90 @@ -9656,8 +9709,8 @@ rule REVERSINGLABS_Cert_Blocklist_07Cef66A71C35Bc3Aed6D100C6493863 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6122-L6138" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6122-L6138" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e741fc13fe4d03b145ed1d86e738b415a7260eae5b0908c6991c9ea9896f14cf" score = 75 quality = 90 @@ -9681,8 +9734,8 @@ rule REVERSINGLABS_Cert_Blocklist_Be77Fe5C58B7A360Add6A3Fced4E8334 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6140-L6158" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6140-L6158" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cea0d217206562c0045843405802d3b2fad01bdb2a4cfb52057625b43f5f8eee" score = 75 quality = 90 @@ -9706,8 +9759,8 @@ rule REVERSINGLABS_Cert_Blocklist_F097E59809Ae2E771B7B9Ae5Fc3408D7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6160-L6178" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6160-L6178" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9e23ff26d3e1ea181e48fc23383e3717804858bc517a31ec508fa0753730c78e" score = 75 quality = 90 @@ -9731,8 +9784,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Cf1Ed2A6Ff4Bee621Efdf725Ea174B7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6180-L6196" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6180-L6196" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7030c122905105c72833cfcb41692bd9a67cf456e3309afce0b8f9e65c6aa5c1" score = 75 quality = 90 @@ -9756,8 +9809,8 @@ rule REVERSINGLABS_Cert_Blocklist_1249Aa2Ada4967969B71Ce63Bf187C38 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6198-L6214" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6198-L6214" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f84568cfe6304af0307a34bfed6dd346a74e714005b5e6f22a354b14f853ec65" score = 75 quality = 90 @@ -9781,8 +9834,8 @@ rule REVERSINGLABS_Cert_Blocklist_D59A05955A4A421500F9561Ce983Aac4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6216-L6234" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6216-L6234" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b7ed87a03f20872669369cc3cad4eae40ba597f06222194bd67262c094083ec1" score = 75 quality = 90 @@ -9806,8 +9859,8 @@ rule REVERSINGLABS_Cert_Blocklist_539015999E304A5952985A994F9C3A53 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6236-L6252" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6236-L6252" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "feeb1710bd5b048c689a2e45575529624cd1622dcc73db8fe7de6c133fdc5698" score = 75 quality = 90 @@ -9831,8 +9884,8 @@ rule REVERSINGLABS_Cert_Blocklist_0B1926A5E8Ae50A0Efa504F005F93869 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6254-L6270" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6254-L6270" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1cbdf39a873c83d2b55723215fb4930a3ce23b6cab2d71a6cd5f16b2721e30f9" score = 75 quality = 90 @@ -9856,8 +9909,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A23B660E7322E54D7Bd0E5Acc890966 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6272-L6288" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6272-L6288" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "17996dd0ec81623dbd4eeea98f9bbe37c11c911ca840833ecb9301bb0a9ddb52" score = 75 quality = 90 @@ -9881,8 +9934,8 @@ rule REVERSINGLABS_Cert_Blocklist_6Cfa5050C819C4Acbb8Fa75979688Dff : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6290-L6308" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6290-L6308" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cffc234be78446191dd5f5990db9f17c7e28eeaa3e16f1eb8ad4ed1e58fdc25e" score = 75 quality = 90 @@ -9906,8 +9959,8 @@ rule REVERSINGLABS_Cert_Blocklist_044E05Bb1A01A1Cbb50Cfb6Cd24E5D6B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6310-L6326" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6310-L6326" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "40c80d3b6bedb0b3454e14501745a6e82b6ea9ac202748867a2e937fb79c6f6c" score = 75 quality = 90 @@ -9931,8 +9984,8 @@ rule REVERSINGLABS_Cert_Blocklist_B7F19B13De9Bee8A52Ff365Ced6F67Fa : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6328-L6346" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6328-L6346" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a8d2a92b44cdd7b123907a6a77ba0fc9fde4961f9ac846b36f1e87730a1efae6" score = 75 quality = 90 @@ -9956,8 +10009,8 @@ rule REVERSINGLABS_Cert_Blocklist_B61B8E71514059Adc604Da05C283E514 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6348-L6366" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6348-L6366" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1255cef74082c9cad41ac8e7d62e740f69e6ba44171bb45655a68ee5db204e57" score = 75 quality = 90 @@ -9981,8 +10034,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ece6Cbf67Dc41635A5E5D075F286Af23 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6368-L6386" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6368-L6386" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f560e6f4a65eaac8db1d8accb0748de17048e66ccf989468e6350a3ec1d70dc8" score = 75 quality = 90 @@ -10006,8 +10059,8 @@ rule REVERSINGLABS_Cert_Blocklist_014A98D697B44F43Ded21F18Eb6Ad0Ba : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6388-L6404" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6388-L6404" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9f1cc61b944974696113912bc1d1a0b45b9911fa4d6de382a48c0d22d2d20953" score = 75 quality = 90 @@ -10031,8 +10084,8 @@ rule REVERSINGLABS_Cert_Blocklist_063A7D09107Eddd8Aa1F733634C6591B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6406-L6422" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6406-L6422" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "19f11e1d9ce95eb4bc75387a0118c230388a13cd07b02e00ea1d65cdcc0b2bd7" score = 75 quality = 90 @@ -10056,8 +10109,8 @@ rule REVERSINGLABS_Cert_Blocklist_1E74Cfe7De8C5F57840A61034414Ca9F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6424-L6442" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6424-L6442" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d82220d908283f1707ec15882503b02cb8dc80095279a9e7d6cbdd113c25d8ae" score = 75 quality = 90 @@ -10081,8 +10134,8 @@ rule REVERSINGLABS_Cert_Blocklist_75Cf729F8A740Bbdef183A1C4D86A02F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6444-L6460" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6444-L6460" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "691fadaa653ecd29e60f2db39b7c5154d7c85f388f72eccd0a4b5fe42eaee0dd" score = 75 quality = 90 @@ -10106,8 +10159,8 @@ rule REVERSINGLABS_Cert_Blocklist_2F64677254D3844Efdac2922123D05D1 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6462-L6478" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6462-L6478" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f9f1f629e03563ece0fe5186b199e2f030dce7f58fb259de1aeb7387c76fa902" score = 75 quality = 90 @@ -10131,8 +10184,8 @@ rule REVERSINGLABS_Cert_Blocklist_32Fbf8Cfa43Dca3F85Efabe96Dfefa49 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6480-L6496" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6480-L6496" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "73d80e6a0dc2316524a55a9627792b9b4488d238ef529f1767de182956b0865e" score = 75 quality = 90 @@ -10156,8 +10209,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ef9D0Cf071D463Cd63D13083046A7B8D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6498-L6516" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6498-L6516" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2923979811504f78a79a2480600285a2697845e51870a44ed231a81e79807121" score = 75 quality = 90 @@ -10181,8 +10234,8 @@ rule REVERSINGLABS_Cert_Blocklist_115Cf1353A0E33E19099A4867A4C750A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6518-L6536" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6518-L6536" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2a3353c655531b113dc019a86288310881e3bbcb6c03670a805f22b185e09e6c" score = 75 quality = 90 @@ -10206,8 +10259,8 @@ rule REVERSINGLABS_Cert_Blocklist_5Cf3778Bb11115A884E192A7Cb807599 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6538-L6556" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6538-L6556" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4242ef4a30bb09463ec5a6df9367915788a2aa782df6c463bcf966d2aad63c1d" score = 75 quality = 90 @@ -10231,8 +10284,8 @@ rule REVERSINGLABS_Cert_Blocklist_82Cb93593B658100Cdd7A00C874287F2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6558-L6576" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6558-L6576" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c77881e0365c9fc398097d0b6e077330a5f0fcbb53279bfde96b3c01df914c55" score = 75 quality = 90 @@ -10256,8 +10309,8 @@ rule REVERSINGLABS_Cert_Blocklist_9A8Bcfd05F86B15D0C99F50Cf414Bd00 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6578-L6596" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6578-L6596" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "803d70dddeff51b753b577ea196b12570847c6875ae676a2d12cf1ca9323be34" score = 75 quality = 90 @@ -10281,8 +10334,8 @@ rule REVERSINGLABS_Cert_Blocklist_95E5793F2Abe0B4Ec9Be54Fd24F76Ae5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6598-L6616" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6598-L6616" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bd198665ae952e11c91adc329908e3cd55a55365875200cd81d2f71fd092f1fe" score = 75 quality = 90 @@ -10306,8 +10359,8 @@ rule REVERSINGLABS_Cert_Blocklist_133565779808C3B79D8E3F70A9C3Ffac : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6618-L6634" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6618-L6634" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b9fb2e3cc150b0278e67c673f7c01174c30b2cc4458c9c5e573661071795b793" score = 75 quality = 90 @@ -10331,8 +10384,8 @@ rule REVERSINGLABS_Cert_Blocklist_7E0Ccda0Ef37Acef6C2Ebe4538627E5C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6636-L6654" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6636-L6654" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f13f9b70a2a3187522e4fff45a8a425863ad6242f82592aa9319c8d5fddeeefa" score = 75 quality = 90 @@ -10356,8 +10409,8 @@ rule REVERSINGLABS_Cert_Blocklist_Bad35Fd70025D46C56B89E32B1A3954C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6656-L6674" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6656-L6674" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1020250fc5030e50bc1e7d0f0c5a77e462a53f47bfcc4383c682b34fed567492" score = 75 quality = 90 @@ -10381,8 +10434,8 @@ rule REVERSINGLABS_Cert_Blocklist_7B91468122273Aa32B7Cfc80C331Ea13 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6676-L6692" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6676-L6692" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "49d6fd8b325df4bc688275a09cee35e1040172eb6f3680aa2b6f0f3640c0782e" score = 75 quality = 90 @@ -10406,8 +10459,8 @@ rule REVERSINGLABS_Cert_Blocklist_3E267B5D14Cdf1F645C1Ec545Cec3Aee : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6694-L6710" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6694-L6710" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e36ae57d715a71aa7d26dd003d647dfa7ab16d64e5411b6c49831544fc482645" score = 75 quality = 90 @@ -10431,8 +10484,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ae6D3C0269Ef6497E14379C51A8507Ba : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6712-L6730" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6712-L6730" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "23570962c80bddce28a3dee9d4d864cf3cf64018eec6fbcbdd3ca2658c9f660f" score = 75 quality = 90 @@ -10456,8 +10509,8 @@ rule REVERSINGLABS_Cert_Blocklist_Fd8C468Cc1B45C9Cfb41Cbd8C835Cc9E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6732-L6750" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6732-L6750" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "230d33f0d1d31d4cb76bf3b13f109d3cc9ace846daef145e1dc7666b33c8a42a" score = 75 quality = 90 @@ -10481,8 +10534,8 @@ rule REVERSINGLABS_Cert_Blocklist_7C061Baa3118327255161F6A7Fa4E21D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6752-L6770" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6752-L6770" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4193fce69af03b3521a3cc442b762c52f8585b44fa6b0bd78b9ace171b807ed4" score = 75 quality = 90 @@ -10506,8 +10559,8 @@ rule REVERSINGLABS_Cert_Blocklist_04332C16724Ffeda5868D22Af56Aea43 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6772-L6788" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6772-L6788" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6b62d5c7a3c6e3096797cd2f515d86045fa77682638bda44175d05c5b6c5bbc0" score = 75 quality = 90 @@ -10531,8 +10584,8 @@ rule REVERSINGLABS_Cert_Blocklist_030012F134E64347669F3256C7D050C5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6790-L6806" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6790-L6806" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1a55856bfa4c632b2b0404686dc7ba5e7238b619dd4d2eb68c3d291bc86e52c4" score = 75 quality = 90 @@ -10556,8 +10609,8 @@ rule REVERSINGLABS_Cert_Blocklist_Fa3Dcac19B884B44Ef4F81541184D6B0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6808-L6826" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6808-L6826" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "324de84cb8c2f5402c9326749e3456e11312828df2523954fd84f7fb3298fdf3" score = 75 quality = 90 @@ -10581,8 +10634,8 @@ rule REVERSINGLABS_Cert_Blocklist_0E6F4Cb8B06E01C3Bd296Ace3A95F814 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6828-L6844" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6828-L6844" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f3184a9d1fe2a1cf2dcc04d26c284aa9a651d2f00aa28642d7f951550a050138" score = 75 quality = 90 @@ -10606,8 +10659,8 @@ rule REVERSINGLABS_Cert_Blocklist_085B70224253486624Fc36Fa658A1E32 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6846-L6862" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6846-L6862" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "50ff48a421a109f8c6bf92032691d9b673945bc591005004ff17dc18c97d4aea" score = 75 quality = 90 @@ -10631,8 +10684,8 @@ rule REVERSINGLABS_Cert_Blocklist_51Cd5393514F7Ace2B407C3Dbfb09D8D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6864-L6880" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6864-L6880" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4cd08b9113a7c1f4f2d438ac59ad0be503daded3a08b8c8e8ce3e0dfdddf259e" score = 75 quality = 90 @@ -10656,8 +10709,8 @@ rule REVERSINGLABS_Cert_Blocklist_B72179C027B9037Ee220E81Ab18Fe56D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6882-L6900" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6882-L6900" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1416768011ff824307d112bdeecce1ad50d1f673e92bef8fddbbeb58ff98b1b1" score = 75 quality = 90 @@ -10681,8 +10734,8 @@ rule REVERSINGLABS_Cert_Blocklist_07B74C70C4Aa092648B7F0D1A8A3A28F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6902-L6918" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6902-L6918" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "97759fa2e519936115f0493e251f9abc0cce3ada437776a5a370388512235491" score = 75 quality = 90 @@ -10706,8 +10759,8 @@ rule REVERSINGLABS_Cert_Blocklist_4C8Def294478B7D59Ee95C61Fae3D965 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6920-L6936" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6920-L6936" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3b7b10afa5f0212bd494ba8fe32bef18f2bbd77c8ab2ad498b9557a0575cc177" score = 75 quality = 90 @@ -10731,8 +10784,8 @@ rule REVERSINGLABS_Cert_Blocklist_7D36Cbb64Bc9Add17Ba71737D3Ecceca : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6938-L6954" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6938-L6954" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5874860582ed5be6908dca38e6ecae831eeeb0c2b768e8065ada9fd5ac2bda89" score = 75 quality = 90 @@ -10756,8 +10809,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ad255D4Ebefa751F3782587396C08629 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6956-L6974" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6956-L6974" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "43f44cbedf37094416628c9df23767be3b036519f93222812597777a146ecb24" score = 75 quality = 90 @@ -10781,8 +10834,8 @@ rule REVERSINGLABS_Cert_Blocklist_262Ca7Ae19D688138E75932832B18F9D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6976-L6992" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6976-L6992" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a5bb946c6199cd47a087ac26f0a996261318d1830191ea7c0e7797ff03984558" score = 75 quality = 90 @@ -10806,8 +10859,8 @@ rule REVERSINGLABS_Cert_Blocklist_59A57E8Ba3Dcf2B6F59981Fda14B03 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L6994-L7010" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L6994-L7010" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6e77c7d0bd7e5e9bc8880cc6ffc3f5f4f738e3dde22c270ad7a6f6672a99de53" score = 75 quality = 90 @@ -10831,8 +10884,8 @@ rule REVERSINGLABS_Cert_Blocklist_Aebe117A13B8Bca21685Df48C74F584D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7012-L7030" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7012-L7030" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e7fbc1f32adec39c94dc046933e152cd6d3946da4a168306484b7b6bc7f26fb6" score = 75 quality = 90 @@ -10856,8 +10909,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Dcd19A94535F034Ee36Af4676740633 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7032-L7048" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7032-L7048" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7079d4f1973ad4de21e1f88282c94b11c4d63f8bad12b35ef76a481e154d9da3" score = 75 quality = 90 @@ -10881,8 +10934,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ca4822E6905Aa4Fca9E28523F04F14A3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7050-L7068" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7050-L7068" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9633f3494e9ece3a698d47c5ba2b7ee7f82cee4be36ac418c969c36285c4963c" score = 75 quality = 90 @@ -10906,8 +10959,8 @@ rule REVERSINGLABS_Cert_Blocklist_24C1Ef800F275Ab2780280C595De3464 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7070-L7086" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7070-L7086" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7536ec92f388234bea3b33bee4af52e0e0ce9cd86b1c8321a503f70bfe5faa76" score = 75 quality = 90 @@ -10931,8 +10984,8 @@ rule REVERSINGLABS_Cert_Blocklist_6401831B46588B9D872B02076C3A7B00 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7088-L7104" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7088-L7104" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cb84b27391fa0260061bc5444039967e83f2134f7b56f9cccf6a421d4a65a577" score = 75 quality = 90 @@ -10956,8 +11009,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A01A91Cce63Ede5Eaa3Dac4883Aea05 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7106-L7122" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7106-L7122" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "58a26b44e485814fa645bfa490f3442745884026bb7a70327d4f51645ad3f69c" score = 75 quality = 90 @@ -10981,8 +11034,8 @@ rule REVERSINGLABS_Cert_Blocklist_54Cd7Ae1C27F1421136Ed25088F4979A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7124-L7140" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7124-L7140" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c7cd84a225216ff1464a147c2572de2b0a2f69f7a315cdebef5ad2bab843b72a" score = 75 quality = 90 @@ -11006,8 +11059,8 @@ rule REVERSINGLABS_Cert_Blocklist_F2D693Aad63E6920782A0027Dfc97D91 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7142-L7160" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7142-L7160" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8f29e65b39608518d16f708faef68db37b6e179c567819dccb6681adcec262e3" score = 75 quality = 90 @@ -11031,8 +11084,8 @@ rule REVERSINGLABS_Cert_Blocklist_F8E8F6C92Ba666B0688A8Cacce9Acccf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7162-L7180" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7162-L7180" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "aa419bc044be55d4c94481998be4e9c0310416740084eb8376842cf5416d78bf" score = 75 quality = 90 @@ -11056,8 +11109,8 @@ rule REVERSINGLABS_Cert_Blocklist_E3D5089D4B8F01Aadce2731062Fb0Cce : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7182-L7200" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7182-L7200" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7f10b86f156ccac695f480661dfea8bcc455477afd9575230c2f8510327d1996" score = 75 quality = 90 @@ -11081,8 +11134,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Ed801843Fa001B8Add52D3A97B25931 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7202-L7218" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7202-L7218" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b7c9424520afe16bd4769e1be84163ac37b8fb37433931f2e362d90cacc01093" score = 75 quality = 90 @@ -11106,8 +11159,8 @@ rule REVERSINGLABS_Cert_Blocklist_D9E834182Dec62C654E775E809Ac1D1B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7220-L7238" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7220-L7238" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3d8075e34fa3dc221bc2abc2630a93f32efbdde6df270a77b1d6b64d8ce56133" score = 75 quality = 90 @@ -11131,8 +11184,8 @@ rule REVERSINGLABS_Cert_Blocklist_801689896Ed339237464A41A2900A969 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7240-L7258" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7240-L7258" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a371092cbf5a1a0c8051ba2b4c9dd758d829a2f0c21c86d1920164a0ae7751e6" score = 75 quality = 90 @@ -11156,8 +11209,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Fd3661533Eef209153C9Afec3Ba4D8A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7260-L7276" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7260-L7276" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ce6c07b8ae54db03e4fa2739856a8d3dc2051c051a10c3c73501dad4296dde97" score = 75 quality = 90 @@ -11181,8 +11234,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Ced87Bd70B092Cb93B182Fac32655F6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7278-L7294" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7278-L7294" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4e2c967b9502d9009c61831f019ba19367b866e898ca1246a1099d75ad0eb4d5" score = 75 quality = 90 @@ -11206,8 +11259,8 @@ rule REVERSINGLABS_Cert_Blocklist_047801D5B55C800B48411Fd8C320Ca5B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7296-L7312" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7296-L7312" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ef26b4e3c658f53f3048d10bd1b7a2a198cd402e1b7c60e84adadb4f236ccb5d" score = 75 quality = 90 @@ -11231,8 +11284,8 @@ rule REVERSINGLABS_Cert_Blocklist_0F0Ed5318848703405D40F7C62D0F39A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7314-L7330" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7314-L7330" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "484932ddfe614fd5ab22361ab281cda62803c98279f938aa5237237fae6a95d6" score = 75 quality = 90 @@ -11256,8 +11309,8 @@ rule REVERSINGLABS_Cert_Blocklist_4E7545C9Fc5938F5198Ab9F1749Ca31C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7332-L7348" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7332-L7348" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f6be57eb6744ad6d239a0a2cc1ec8c39c9dfd4e4eeb3be9e699516c259f617f0" score = 75 quality = 90 @@ -11281,8 +11334,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Ddd3796A427B42F2E52D7C7Af0Ca54F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7350-L7366" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7350-L7366" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "804ab8c44e5d97d8e14f852d61094e90d1e3ace66316781e9e79ab46fc7db8e7" score = 75 quality = 90 @@ -11306,8 +11359,8 @@ rule REVERSINGLABS_Cert_Blocklist_03B27D7F4Ee21A462A064A17Eef70D6C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7368-L7384" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7368-L7384" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b303751e354c346f73368de94b66a960dd12efa0730d2ab14af743810669ac81" score = 75 quality = 90 @@ -11331,8 +11384,8 @@ rule REVERSINGLABS_Cert_Blocklist_B0A308Fc2E71Ac4Ac40677B9C27Ccbad : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7386-L7404" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7386-L7404" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "21fd7625399c939b6d03100b731709616d206a3811197af2b86991be9d89b4eb" score = 75 quality = 90 @@ -11356,8 +11409,8 @@ rule REVERSINGLABS_Cert_Blocklist_61B11Ef9726Ab2E78132E01Bd791B336 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7406-L7422" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7406-L7422" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1a8e72f31039a5a5602d0314f017a2596a23e4a796dc66167dfefc0c9790e3e3" score = 75 quality = 90 @@ -11381,8 +11434,8 @@ rule REVERSINGLABS_Cert_Blocklist_8Fe807310D98357A59382090634B93F0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7424-L7442" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7424-L7442" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0ec56bd4783c854efef863050ff729fd99efa98b7b19e04e56a080ee3e75cd90" score = 75 quality = 90 @@ -11406,8 +11459,8 @@ rule REVERSINGLABS_Cert_Blocklist_B97F66Bb221772Dc07Ef1D4Bed8F6085 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7444-L7462" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7444-L7462" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "794dc27ff9b2588d3f2c31cdb83e53616c604aa41da7d8c895034e1cf9da5dd8" score = 75 quality = 90 @@ -11431,8 +11484,8 @@ rule REVERSINGLABS_Cert_Blocklist_Fed006Fbf85Cd1C6Ba6B4345B198E1E6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7464-L7482" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7464-L7482" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0360c6760f1018f9388ef5639ab2306879134f33da12677f954fa31b8a71aa16" score = 75 quality = 90 @@ -11456,8 +11509,8 @@ rule REVERSINGLABS_Cert_Blocklist_Aa28C9Bd16D9D304F18Af223B27Bfa1E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7484-L7502" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7484-L7502" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "feaa8d645eea46c7cbbba4ba86c92184df7515a50f1f905ab818c59079a0c96a" score = 75 quality = 90 @@ -11481,8 +11534,8 @@ rule REVERSINGLABS_Cert_Blocklist_19Beff8A6C129663E5E8C18953Dc1F67 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7504-L7520" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7504-L7520" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0ec031c781ebad7447cfc53ce791aacc8f24e38f039c84e2ee547de64729ae76" score = 75 quality = 90 @@ -11506,8 +11559,8 @@ rule REVERSINGLABS_Cert_Blocklist_029685Cda1C8233D2409A31206F78F9F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7522-L7538" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7522-L7538" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d541ce73e5039541ea221f27cc4d033f0c477e41a148206c26cc39ae07c4caaa" score = 75 quality = 90 @@ -11531,8 +11584,8 @@ rule REVERSINGLABS_Cert_Blocklist_D609B6C95428954A999A8A99D4F198Af : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7540-L7558" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7540-L7558" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a124f80d599051ecd7c17e6818d181ea018db14c9f0514bbcc5b677ba3656d65" score = 75 quality = 90 @@ -11556,8 +11609,8 @@ rule REVERSINGLABS_Cert_Blocklist_D3356318924C8C42959Bf1D1574E6482 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7560-L7578" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7560-L7578" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a672054a776d0715fc888578bcb559d24ef54b4c523f7d49a39ded2586c3140a" score = 75 quality = 90 @@ -11581,8 +11634,8 @@ rule REVERSINGLABS_Cert_Blocklist_31D852F5Fca1A5966B5Ed08A14825C54 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7580-L7596" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7580-L7596" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8c98b856d53e6862e94042bb133f5739bddcec2e208e43961b23e244584c6ee4" score = 75 quality = 90 @@ -11606,8 +11659,8 @@ rule REVERSINGLABS_Cert_Blocklist_17D99Cc2F5B29522D422332E681F3E18 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7598-L7614" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7598-L7614" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "55cc1634cdc5209d68b98fdb0d9e97e0a34346cdcb10f243d13217cda01195f1" score = 75 quality = 90 @@ -11631,8 +11684,8 @@ rule REVERSINGLABS_Cert_Blocklist_6A568F85De2061F67Ded98707D4988Df : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7616-L7632" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7616-L7632" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "793be308a4df55c3b325e1ee3185159c4155f6dfabc311216d3763bd43680bd4" score = 75 quality = 90 @@ -11656,8 +11709,8 @@ rule REVERSINGLABS_Cert_Blocklist_038Fc745523B41B40D653B83Aa381B80 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7634-L7650" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7634-L7650" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "016ca6dcb5c7c56c80e4486b84d97fb3869a959ef3e8392e4376a0a0de06092f" score = 75 quality = 90 @@ -11681,8 +11734,8 @@ rule REVERSINGLABS_Cert_Blocklist_30Af0D0E6D8201A5369664C5Ebbb010F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7652-L7668" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7652-L7668" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "018e5a0fbeeaded2569b83e2f91230e0055a5ffa2059b7a064a5c2eda55ed2de" score = 75 quality = 90 @@ -11706,8 +11759,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ac0A7B9420B369Af3Ddb748385B981 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7670-L7688" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7670-L7688" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2bc31eaa64be487cb85873a64b7462d90d1c28839def070ce5db7ae555383421" score = 75 quality = 90 @@ -11731,8 +11784,8 @@ rule REVERSINGLABS_Cert_Blocklist_C167F04B338B1E8747B92C2197403C43 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7690-L7708" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7690-L7708" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8e0a11efc739baefe23a3d77e4eefc9dc23c74821c91fc219822dbc5dbb468b1" score = 75 quality = 90 @@ -11756,8 +11809,8 @@ rule REVERSINGLABS_Cert_Blocklist_9272607Cfc982B782A5D36C4B78F5E7B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7710-L7728" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7710-L7728" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2b1d6f27fb513542589a5c9011e501a9d298282bba6882eac0fc7bf3e6ebb291" score = 75 quality = 90 @@ -11781,8 +11834,8 @@ rule REVERSINGLABS_Cert_Blocklist_45Eb9187A2505D8E6C842E6D366Ad0C8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7730-L7746" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7730-L7746" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4ae755e814ae2488d4bd6b8136ab6d78e4809a2ddacb7f88cf1d2b64c1488898" score = 75 quality = 90 @@ -11806,8 +11859,8 @@ rule REVERSINGLABS_Cert_Blocklist_56Fff139Df5Ae7E788E5D72196Dd563A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7748-L7764" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7748-L7764" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4b58c83901605d8b43519f1bc2d4ac8dc10c794f027681378b2bee2a8ff81604" score = 75 quality = 90 @@ -11831,8 +11884,8 @@ rule REVERSINGLABS_Cert_Blocklist_E161F76Da3B5E4623892C8E6Fda1Ea3D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7766-L7784" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7766-L7784" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "883545593b48aa11c11f7fa1a1f77c62321ea86067f1ed108dcd00c8c6cd3495" score = 75 quality = 90 @@ -11856,8 +11909,8 @@ rule REVERSINGLABS_Cert_Blocklist_9Ae5B177Ac3A7Ce2Aadf1C891B574924 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7786-L7804" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7786-L7804" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "03ac299459a1aaf2e4a2e62884cd321e16100fee78b4b0e271acdd8a4e32525c" score = 75 quality = 90 @@ -11881,8 +11934,8 @@ rule REVERSINGLABS_Cert_Blocklist_A03Ea3A4Fa772B17037A0B80F1F968Aa : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7806-L7824" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7806-L7824" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e2044c6ddb80f3add13dfc3b623d0460ce8e9a66c5a98582f80d906edbbbd829" score = 75 quality = 90 @@ -11906,8 +11959,8 @@ rule REVERSINGLABS_Cert_Blocklist_333Ca7D100B139B0D9C1A97Cb458E226 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7826-L7842" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7826-L7842" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b3a31a54132fd8ca2c11b7806503207a4197f16af78693387bac56879b5e1448" score = 75 quality = 90 @@ -11931,8 +11984,8 @@ rule REVERSINGLABS_Cert_Blocklist_9245D1511923F541844Faa3C6Bfebcbe : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7844-L7862" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7844-L7862" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b965e897b42c39841e663cc144cf6e4a81fc9bcb64ce3a15a7ca021e95866b08" score = 75 quality = 90 @@ -11956,8 +12009,8 @@ rule REVERSINGLABS_Cert_Blocklist_2888Cf0F953A4A3640Ee4Cfc6304D9D4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7864-L7880" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7864-L7880" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a9ee8534d89b8ac8705bb1777718513a28e4531ed398f482f46a72f2760af161" score = 75 quality = 90 @@ -11981,8 +12034,8 @@ rule REVERSINGLABS_Cert_Blocklist_C8Edcfe8Be174C2F204D858C5B91Dea5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7882-L7900" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7882-L7900" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b3e6927abfce69548374bfd430a3ae3a1c5a8d05f0f40e43091b4d12025c5b1a" score = 75 quality = 90 @@ -12006,8 +12059,8 @@ rule REVERSINGLABS_Cert_Blocklist_9Faf8705A3Eaef9340800Cc4Fd38597C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7902-L7920" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7902-L7920" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "66a340f169e401705ba229d2d4548cef1a57bf1d2d320b108d12b2049b063b92" score = 75 quality = 90 @@ -12031,8 +12084,8 @@ rule REVERSINGLABS_Cert_Blocklist_0940Fa9A4080F35052B2077333769C2F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7922-L7938" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7922-L7938" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "45636ea33751fea61572539fe6f28bccd05df9b6b9e7f2d77bb738f7c69c53a2" score = 75 quality = 90 @@ -12056,8 +12109,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ea720222D92Dc8D48E3B3C3B0Fc360A6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7940-L7958" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7940-L7958" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c60e1ccf178f03f930a3bc41e9a92be20df0362f067ed1fcfc7c93627a056d75" score = 75 quality = 90 @@ -12081,8 +12134,8 @@ rule REVERSINGLABS_Cert_Blocklist_4743E140C05B33F0449023946Bd05Acb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7960-L7976" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7960-L7976" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "69ce1512d7df4926ee2b470b18fbe51a2aa81e07b37b2536617d6353045e0d19" score = 75 quality = 90 @@ -12106,8 +12159,8 @@ rule REVERSINGLABS_Cert_Blocklist_A496Bc774575C31Abec861B68C36Dcb6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7978-L7996" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7978-L7996" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f82214f982c9972e547f77966c44e935e9de701cc9108ceca34a4fede850d243" score = 75 quality = 90 @@ -12131,8 +12184,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A55C15F733Bf1633E9Ffae8A6E3B37D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L7998-L8014" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L7998-L8014" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "89ca9f1c5cf0b029748528d8c5bb65f89ee05877bfdc13b4ce3d2d3e7feafb5d" score = 75 quality = 90 @@ -12156,8 +12209,8 @@ rule REVERSINGLABS_Cert_Blocklist_C650Ae531100A91389A7F030228B3095 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8016-L8034" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8016-L8034" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "186b66283491cfebcaade57b1010ce4304c08ddb131153984210c2c7025961aa" score = 75 quality = 90 @@ -12181,8 +12234,8 @@ rule REVERSINGLABS_Cert_Blocklist_3990362C34015Ce4C23Ecc3377Fd3C06 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8036-L8052" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8036-L8052" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0625800fcb166b56cab2e16d0d757983a6f880b68627ed8c3c38419dd9a32999" score = 75 quality = 90 @@ -12206,8 +12259,8 @@ rule REVERSINGLABS_Cert_Blocklist_121Fca3Cfa4Bd011669F5Cc4E053Aa3F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8054-L8070" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8054-L8070" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1edd5be3f970202be15080cd7ef19c0cce7fcba73cb6120d7cb7d518e877cf85" score = 75 quality = 90 @@ -12231,8 +12284,8 @@ rule REVERSINGLABS_Cert_Blocklist_D338F8A490E37E6C2Be80A0E349929Fa : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8072-L8090" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8072-L8090" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "39d9695803e96508b5ad12a7d9f8b65d13288dbe94b21a4952e096dd576e11ce" score = 75 quality = 90 @@ -12256,8 +12309,8 @@ rule REVERSINGLABS_Cert_Blocklist_2C1Ee9B583310B5E34A1Ee6945A34B26 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8092-L8108" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8092-L8108" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7752e49e8848863d78c5de03c3d194498765d80da00a84c5164c7a9010d13474" score = 75 quality = 90 @@ -12281,8 +12334,8 @@ rule REVERSINGLABS_Cert_Blocklist_D875B3E3F2Db6C3Eb426E24946066111 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8110-L8128" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8110-L8128" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9e181271d46c828b9ec266331e077b3b4891a193c71173447da383fad91ae878" score = 75 quality = 90 @@ -12306,8 +12359,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ad0A958Cdf188Bed43154A54Bf23Afba : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8130-L8148" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8130-L8148" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "07e53e59f90aa3cd3a98dbca2627672606f6c6f8f3bda8456e32122463729c4b" score = 75 quality = 90 @@ -12331,8 +12384,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Cee26C125B8C188F316C3Fa78D9C2F1 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8150-L8166" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8150-L8166" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5c64f8e40c31822ce8d2e34f96ccc977085e429f0c068a5f6b44099117837de1" score = 75 quality = 90 @@ -12356,8 +12409,8 @@ rule REVERSINGLABS_Cert_Blocklist_4C687A0022C36F89E253F91D1F6954E2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8168-L8184" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8168-L8184" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "287c0c7a25e33e0e7def6efa23dbd2efba7c4ac3aa8f5deb8568a60a95e08bbe" score = 75 quality = 90 @@ -12381,8 +12434,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ca646B4275406Df639Cf603756F63D77 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8186-L8204" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8186-L8204" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a690e3f6a656835984e47d999271fe441a5fbf424208da8d5b3c9ddcef47b70e" score = 75 quality = 90 @@ -12406,8 +12459,8 @@ rule REVERSINGLABS_Cert_Blocklist_Addbec454B5479Cabd940A72Df4500Af : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8206-L8224" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8206-L8224" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "799629791646c524d170b900339b87474aed73b7156a8c4dd20f7c13cbe97929" score = 75 quality = 90 @@ -12431,8 +12484,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ac307E5257Bb814B818D3633B630326F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8226-L8244" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8226-L8244" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "10819bd2194fface6db812f8c6770c306c183386d2d9ba97467a5b55fd997194" score = 75 quality = 90 @@ -12456,8 +12509,8 @@ rule REVERSINGLABS_Cert_Blocklist_0D83E7F47189Cdbfc7Fa3E5F58882329 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8246-L8262" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8246-L8262" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b344f9fd6d8378b7d77a34b14c5f37eea253f3d13a8eb0777925f195fb3cf502" score = 75 quality = 90 @@ -12481,8 +12534,8 @@ rule REVERSINGLABS_Cert_Blocklist_58Aa64564A50E8B2D6E31D5Cd6250Fde : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8264-L8280" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8264-L8280" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f6b50ebf707b67650fe832d81c6fe8d2411cd83432ef94432d181db0c29aa48b" score = 75 quality = 90 @@ -12506,8 +12559,8 @@ rule REVERSINGLABS_Cert_Blocklist_2Aa0Ae245B487C8926C88Ee6D736D1Ca : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8282-L8298" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8282-L8298" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5a362175600552983ae838ca18aa378dc748b8b68bd8b67a9387794d983ed1a2" score = 75 quality = 90 @@ -12531,8 +12584,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Aec3D3F752A38617C1D7A677D0B5591 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8300-L8316" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8300-L8316" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b299833a19944ca6943ba9c974ec95369c57cd61acc8b2e1b5310edd077762c2" score = 75 quality = 90 @@ -12556,8 +12609,8 @@ rule REVERSINGLABS_Cert_Blocklist_A7E1Dc5352C3852C5523030F57F2425C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8318-L8336" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8318-L8336" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "79c42c9a4eeeb69a62a16590e2b0b63818785509a40d543c7efe27ec6baaa19e" score = 75 quality = 90 @@ -12581,8 +12634,8 @@ rule REVERSINGLABS_Cert_Blocklist_Bbd4Dc3768A51Aa2B3059C1Bad569276 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8338-L8356" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8338-L8356" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f336570834e0663c6e589fa22b3541f4f79c40ff945dd91f1fd1258a96adeceb" score = 75 quality = 90 @@ -12606,8 +12659,8 @@ rule REVERSINGLABS_Cert_Blocklist_08622B9Dd9D78E67678Ecc21E026522E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8358-L8374" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8358-L8374" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "09507b09b035195b74434f56041588f67245fa097183228dffc612bb4901825b" score = 75 quality = 90 @@ -12631,8 +12684,8 @@ rule REVERSINGLABS_Cert_Blocklist_E69A6De0074Ece38C2F30F0D4A808456 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8376-L8394" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8376-L8394" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "21d8641d2394120847044f0e6f4d868095a1e30c0b594a3d045877ab9b3808a1" score = 75 quality = 90 @@ -12656,8 +12709,8 @@ rule REVERSINGLABS_Cert_Blocklist_8385684419Ab26A3F2640B1496E1Fe94 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8396-L8414" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8396-L8414" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "24f75badc335160a8053a4c7e8bbd8ddbd3266c3a18059a937d5989df97ae9d9" score = 75 quality = 90 @@ -12681,8 +12734,8 @@ rule REVERSINGLABS_Cert_Blocklist_21E3Cae5B77C41528658Ada08509C392 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8416-L8432" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8416-L8432" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2e24ed0bd0bf3c36cae4bf106a2c17386bfb58b76372068be9745c2d501f30fc" score = 75 quality = 90 @@ -12706,8 +12759,8 @@ rule REVERSINGLABS_Cert_Blocklist_2Abd2Eef14D480Dfea9Ca9Fdd823Cf03 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8434-L8450" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8434-L8450" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2dfc220c44d3dda28a253e5115ae9a087b6ddbf1a7ca1e9bcae5bd9ac5b2e1a0" score = 75 quality = 90 @@ -12731,8 +12784,8 @@ rule REVERSINGLABS_Cert_Blocklist_86909B91F07F9316984D888D1E28Ab76 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8452-L8470" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8452-L8470" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "abd84492ed008125688a53e20d51780fa0b8c2309dcf751ff76a03d6f337beaa" score = 75 quality = 90 @@ -12756,8 +12809,8 @@ rule REVERSINGLABS_Cert_Blocklist_D1B8F1Fe56381Befdb2E73Ffef2A4B28 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8472-L8490" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8472-L8490" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c118cb46914e7a6df8dd33dd14d5f9cf2692d98311503ec850cc66f02c20839e" score = 75 quality = 90 @@ -12781,8 +12834,8 @@ rule REVERSINGLABS_Cert_Blocklist_D4Ef1Ab6Ab5D3Cb35E4Efb7984Def7A2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8492-L8510" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8492-L8510" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ecc2f6bfda1a0afd016f0a5183c0d1cdfe5d5e06c893a7d9a3d7cb7f9bc4bf16" score = 75 quality = 90 @@ -12806,8 +12859,8 @@ rule REVERSINGLABS_Cert_Blocklist_066276Af2F2C7E246D3B1Cab1B4Aa42E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8512-L8528" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8512-L8528" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "30d4fa2cbc75d3a6258cdf0374159f25ea152c39784f8b7e9c461978df865dc0" score = 75 quality = 90 @@ -12831,8 +12884,8 @@ rule REVERSINGLABS_Cert_Blocklist_65Cd323C2483668B90A44A711D2A6B98 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8530-L8546" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8530-L8546" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "653aff6f3913f1bf51e90e7a835dbb5441457175797cefdddd234a6c2c0f11ad" score = 75 quality = 90 @@ -12856,8 +12909,8 @@ rule REVERSINGLABS_Cert_Blocklist_5A17D5De74Fd8F09Df596Df3123139Bb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8548-L8564" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8548-L8564" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7ed62740fe191d961ad32b2a79463cc9cbce557ea757e413860f7b4974904c03" score = 75 quality = 90 @@ -12881,8 +12934,8 @@ rule REVERSINGLABS_Cert_Blocklist_15Da61D7E1A631803431561674Fb9B90 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8566-L8582" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8566-L8582" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "75d2c3b47fe9c863812f2c98fc565af9050b909a03528e2ea4a96542a3ec0c0d" score = 75 quality = 90 @@ -12906,8 +12959,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Ab21306B11Ff280A93Fc445876988Ab : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8584-L8600" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8584-L8600" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0cda954aa807336a6737716d0fa43d696376c240ab7be9d8477baf8800604bf1" score = 75 quality = 90 @@ -12931,8 +12984,8 @@ rule REVERSINGLABS_Cert_Blocklist_634E16E38F12E9A71Aca08E4C6B2Dbb9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8602-L8618" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8602-L8618" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "08950f276e5cf3fe4b5f7421ba671dfd72585aac3bbed7868fdb0e5aa90ec10e" score = 75 quality = 90 @@ -12956,8 +13009,8 @@ rule REVERSINGLABS_Cert_Blocklist_289051A83F350A2C600187C99B6C0A73 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8620-L8636" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8620-L8636" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cd5d6f95f0cfdbf8d37ea78d061ce00512b6cb7c899152b1640673494d539dd1" score = 75 quality = 90 @@ -12981,8 +13034,8 @@ rule REVERSINGLABS_Cert_Blocklist_818631110B5D14331Dac7E6Ad998B902 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8638-L8656" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8638-L8656" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5e0de3848adf933632c2eb8cf5ead61d6470237386ba8b48d57a278d99dba324" score = 75 quality = 90 @@ -13006,8 +13059,8 @@ rule REVERSINGLABS_Cert_Blocklist_277Cd16De5D61B9398B645Afe41C09C7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8658-L8674" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8658-L8674" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "696467d699dec060b205f36f53dbe157b241823757d72798b35235d6530fd193" score = 75 quality = 90 @@ -13031,8 +13084,8 @@ rule REVERSINGLABS_Cert_Blocklist_D0Eda76C13D30C97015708790Bb94214 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8676-L8694" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8676-L8694" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2112ebfb7c9ebbbccb20cefcd23bb49142da770feb16ee8eef5eb27646226785" score = 75 quality = 90 @@ -13056,8 +13109,8 @@ rule REVERSINGLABS_Cert_Blocklist_6333Ed618F88A05B4D82Ad7Bf66Cb0Fa : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8696-L8712" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8696-L8712" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b088ac4b74a8cf3dddb67c8de2b7c3c5f537287a0454c0030c0eb4069c465c7d" score = 75 quality = 90 @@ -13081,8 +13134,8 @@ rule REVERSINGLABS_Cert_Blocklist_3B777165B125Bccc181D0Bac3F5B55B3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8714-L8730" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8714-L8730" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "80aff3d6f45f5847d5d39b170b9d0e70168d02569ca6d86a2c39150399d290fc" score = 75 quality = 90 @@ -13106,8 +13159,8 @@ rule REVERSINGLABS_Cert_Blocklist_5B37Ac3479283B6F9D75Ddf0F8742D06 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8732-L8748" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8732-L8748" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b7abd389ac31cd970e6611c7c303714fdd658f45d4857ad524f5e8368edbb875" score = 75 quality = 90 @@ -13131,8 +13184,8 @@ rule REVERSINGLABS_Cert_Blocklist_3112C69D460C781Fd649C71E61Bfec82 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8750-L8766" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8750-L8766" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ed31b0a24d18a451163867f0f49df12af3ca0768f250ac8ce66d41405393130d" score = 75 quality = 90 @@ -13156,8 +13209,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A5B4F67Ad8B22Afc2Debe6Ce5F8F679 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8768-L8784" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8768-L8784" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "938efb7ee19970484aded5cd46b2ff730f8882706bec3f062bdebde3cc9a4799" score = 75 quality = 90 @@ -13181,8 +13234,8 @@ rule REVERSINGLABS_Cert_Blocklist_Df45B36C9D0Bd248C3F9494E7Ca822 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8786-L8804" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8786-L8804" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9c03522376b0d807cd36a0641e474d770bc3b4f8221f26d232878d2d320d072b" score = 75 quality = 90 @@ -13206,8 +13259,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Ae3C4Eccecda2127D43Be390A850Dda : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8806-L8822" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8806-L8822" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8a2ff4f7a5ac996127778b1670e79291bddcb5dee6e7da2b540fd254537ee27e" score = 75 quality = 90 @@ -13231,8 +13284,8 @@ rule REVERSINGLABS_Cert_Blocklist_2E36360538624C9B1Afd78A2Fb756028 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8824-L8840" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8824-L8840" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9cbb50c7d383048fd506506fa9ee8bf7c6d82feaf21bcde4008ab99b82e234a7" score = 75 quality = 90 @@ -13256,8 +13309,8 @@ rule REVERSINGLABS_Cert_Blocklist_Addb899F8229Fd53E6435E08Bbd3A733 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8842-L8860" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8842-L8860" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ecb8e31b8c56b92cef601618e0adc2f6d88999318805b92389693aa9e8050d18" score = 75 quality = 90 @@ -13281,8 +13334,8 @@ rule REVERSINGLABS_Cert_Blocklist_C1A1Db95D7Bf80290Aa6E82D8F8F996A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8862-L8880" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8862-L8880" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "84c7c0e53facadcdfd752e9cf3811fbfd6aac4bef4109acf430a67b6dcd37bfc" score = 75 quality = 90 @@ -13306,8 +13359,8 @@ rule REVERSINGLABS_Cert_Blocklist_C667Ffe3A5B0A5Ae7Cf3A9E41682E91B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8882-L8900" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8882-L8900" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "be2cd688f2d7c458ee764bd7a7250e0116328702db5585b444d631f05cdc701b" score = 75 quality = 90 @@ -13331,8 +13384,8 @@ rule REVERSINGLABS_Cert_Blocklist_E0A83917660D05Cf476374659D3C7B85 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8902-L8920" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8902-L8920" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f60753ecb775d664e07e78611568799eaf06fb4742bcef3bf0c28202daf98c50" score = 75 quality = 90 @@ -13356,8 +13409,8 @@ rule REVERSINGLABS_Cert_Blocklist_Afc5522898143Aafaab7Fd52304Cf00C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8922-L8940" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8922-L8940" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bfcf2fbbd9be97202eeb44c0f81f0a0713d4d30c466f2b170231c7f9df0e9e6d" score = 75 quality = 90 @@ -13381,8 +13434,8 @@ rule REVERSINGLABS_Cert_Blocklist_8B3333D32B2C2A1D33B41Ba5Db9D4D2D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8942-L8960" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8942-L8960" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cdb3f1983ed17df22d17c6321bc2ead2c391d70fdca4a9f6f4784f62196b85d0" score = 75 quality = 90 @@ -13406,8 +13459,8 @@ rule REVERSINGLABS_Cert_Blocklist_Fbb1198Bd8Bddb0D693Eb72A8613Fe3F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8962-L8980" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8962-L8980" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2e004116d0f8df5a625b190127655926336fc74b4cce4ae40cd516a135e5d719" score = 75 quality = 90 @@ -13431,8 +13484,8 @@ rule REVERSINGLABS_Cert_Blocklist_846F77D9919Fc4405Aefe1701309Bd67 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L8982-L9000" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L8982-L9000" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6739049a61183d506daf9aaf44a3b15cbf2234c6af307ec95bc07fa3d8501105" score = 75 quality = 90 @@ -13456,8 +13509,8 @@ rule REVERSINGLABS_Cert_Blocklist_0939C2Bad859C0432E8E98A6C0162C02 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9002-L9018" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9002-L9018" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3c48241e52e58600bfa0385742831dba59d9cbd959cd6853fe8e030f5df79c23" score = 75 quality = 90 @@ -13481,8 +13534,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Fba0E19919Ac50D700Ba60250D02C8B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9020-L9036" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9020-L9036" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8c803111df930056bdc3ef7560f07bf4d255b93286d01ecc55f790e72565ba5d" score = 75 quality = 90 @@ -13506,8 +13559,8 @@ rule REVERSINGLABS_Cert_Blocklist_A758504E7971869D0Aec2775Fffa03D5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9038-L9056" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9038-L9056" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "dcb1ac4c7dcbebd0a432515da82e4a97be6c6c2a54f9d642aa8c1a2bcbdce5de" score = 75 quality = 90 @@ -13531,8 +13584,8 @@ rule REVERSINGLABS_Cert_Blocklist_37A67Cf754Ee5Ae284B4Cf8B9D651604 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9058-L9074" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9058-L9074" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "22cb71eebbb212a4436847c11c7ca9cefaf118086b024014c12498a6a5953af5" score = 75 quality = 90 @@ -13556,8 +13609,8 @@ rule REVERSINGLABS_Cert_Blocklist_119Acead668Bad57A48B4F42F294F8F0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9076-L9092" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9076-L9092" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "61c49c60fc4fd5d654a6376fcee43e986a5351f085a5652a3c8888774557e053" score = 75 quality = 90 @@ -13581,8 +13634,8 @@ rule REVERSINGLABS_Cert_Blocklist_7A6D30A6Eb2Fa0C3369283725704Ac4C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9094-L9110" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9094-L9110" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "788abb53ed7974d87c1b1bdbe31dcd3e852ea64745d94780d78d1217ee0206fe" score = 75 quality = 90 @@ -13606,8 +13659,8 @@ rule REVERSINGLABS_Cert_Blocklist_670C3494206B9F0C18714Fdcffaaa42F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9112-L9128" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9112-L9128" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3b1e244b5f543a05beb2475020aa20dfc723f4dce3a5a0a963db1672d3295721" score = 75 quality = 90 @@ -13631,8 +13684,8 @@ rule REVERSINGLABS_Cert_Blocklist_0E8Aa328Af207Ce8Bcae1Dc15C626188 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9130-L9146" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9130-L9146" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4022abb8efbda944e35ff529c5b3b3c9f6370127a945f3eec1310149bb5d06e4" score = 75 quality = 90 @@ -13656,8 +13709,8 @@ rule REVERSINGLABS_Cert_Blocklist_Cfad6Be1D823B4Eacb803B720F525A7D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9148-L9166" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9148-L9166" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d8005774e6011d8198039a6588834cd0b13dd728103b63c3ea8b6e0dc3878f05" score = 75 quality = 90 @@ -13681,8 +13734,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Ebcb54B7E0E6410B28610De0743D4Dd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9168-L9184" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9168-L9184" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c9444ff9e13192bf300afac12554bc4cc2defb37bb5b57906b6163db378c515a" score = 75 quality = 90 @@ -13706,8 +13759,8 @@ rule REVERSINGLABS_Cert_Blocklist_01106Cc293772Ca905A2B6Eff02Bf0F5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9186-L9202" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9186-L9202" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "81e19c06de4546a2cee974230ef7aa15291f20f2e6b6f89c9b12107c26836b5e" score = 75 quality = 90 @@ -13731,8 +13784,8 @@ rule REVERSINGLABS_Cert_Blocklist_05Bb162F6Efe852B7Bd4712Fd737A61E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9204-L9220" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9204-L9220" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d2fcbce0826c1478338827376d2c7869e5b38dc6d5e737a2f986600c6f71b1e6" score = 75 quality = 90 @@ -13756,8 +13809,8 @@ rule REVERSINGLABS_Cert_Blocklist_6171990Ba1C8E71049Ebb296A35Bd160 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9222-L9238" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9222-L9238" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e922bb850b7c5c70db80e6a2b99310eac48d3b10b94a7259899facd681916bfa" score = 75 quality = 90 @@ -13781,8 +13834,8 @@ rule REVERSINGLABS_Cert_Blocklist_2114Ca3Bd2Afd63D7Fa29D744992B043 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9240-L9256" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9240-L9256" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "241fe5a9f233fa36a665d22b38fd360bee21bc9832c15ac9c9d9b17adc3bb306" score = 75 quality = 90 @@ -13806,8 +13859,8 @@ rule REVERSINGLABS_Cert_Blocklist_6Aaa62208A3A78Bfac1443007D031E61 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9258-L9274" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9258-L9274" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7ba7f69514230fe636efc0a12fb9ac489a5a80ca1f5bcdb050dd30ee8f69659c" score = 75 quality = 90 @@ -13831,8 +13884,8 @@ rule REVERSINGLABS_Cert_Blocklist_09450B8F73Ea43E39D2Cdd56049Dbe40 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9276-L9292" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9276-L9292" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "22b344b8befc00b0154d225603c81c6058399770f54cb6a09d0f7908c5c8188c" score = 75 quality = 90 @@ -13856,8 +13909,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Efd9Bd4B4281C6522D96011Df46C9C4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9294-L9310" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9294-L9310" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8f8a5e3457c05c5e70e33041c5b0b971cf8f19313d47055fd760ed17d94c8794" score = 75 quality = 90 @@ -13881,8 +13934,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Dd7D4A785990584D8C0837659173272 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9312-L9328" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9312-L9328" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d18a479f07f2bdb890437e2bcb0213abdfb0eb684cdaf17c5eb0583039f2edb4" score = 75 quality = 90 @@ -13906,8 +13959,8 @@ rule REVERSINGLABS_Cert_Blocklist_0C59D46580F039Af2C4Ab6Ba0Ffed197 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9330-L9346" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9330-L9346" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "32eea2a436f386ef44a00ef72be8be7d4070b02f84ba71c7ee1ca407fddce8ec" score = 75 quality = 90 @@ -13931,8 +13984,8 @@ rule REVERSINGLABS_Cert_Blocklist_0448Ec8D26597F99912138500Cc41C1B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9348-L9364" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9348-L9364" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "001556c31cfb0d94978adc48dc0d24c83666512348c65508975cc9e1a119aeae" score = 75 quality = 90 @@ -13956,8 +14009,8 @@ rule REVERSINGLABS_Cert_Blocklist_0108Cbaee60728F5Bf06E45A56D6F170 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9366-L9382" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9366-L9382" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "52027548e20c819e73ea5e9afd87faaca4498bc39e54dd30ad99a24e3ace57fd" score = 75 quality = 90 @@ -13981,8 +14034,8 @@ rule REVERSINGLABS_Cert_Blocklist_038D56A12153E8B5C74C69Bff65Cbe3F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9384-L9400" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9384-L9400" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ed3a81231f93f9d2ae462481503ba37072c3800dd1379baae11737f093a27af1" score = 75 quality = 90 @@ -14006,8 +14059,8 @@ rule REVERSINGLABS_Cert_Blocklist_060D94E2Ccae84536654D9Daf39Fef1E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9402-L9418" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9402-L9418" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "49000f3a3ce1ad9aef87162d7527b8f062e0aa12276b82c7335f0ccc14b7d38a" score = 75 quality = 90 @@ -14031,8 +14084,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Bc9B800F480691Bd6B60963466B0C75 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9420-L9436" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9420-L9436" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6a498fd30c611976e9aad2f9b85b13c3c29246582cdfefc800615db88e40dac2" score = 75 quality = 90 @@ -14056,8 +14109,8 @@ rule REVERSINGLABS_Cert_Blocklist_0C4324Ff41F0A7B16Ffcc93Dffa8Fa99 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9438-L9454" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9438-L9454" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d3ce83fb0497c533a5474d46300c341677ec243686723783798bfbaec4f6e369" score = 75 quality = 90 @@ -14081,8 +14134,8 @@ rule REVERSINGLABS_Cert_Blocklist_0B980Fc8783E4F158E41829Ab21Bab81 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9456-L9472" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9456-L9472" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b0f43caec1cfc5b2d1512d7fcf0bcf1e02fc81764b4376b081f38c4de328eab2" score = 75 quality = 90 @@ -14106,8 +14159,8 @@ rule REVERSINGLABS_Cert_Blocklist_D8F515715Aeffef0A0E4E37F16C254Fa : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9474-L9492" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9474-L9492" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3c7d57a655f76a6e5ef6b0e770db7c91d0830b6b0b37caef5ef9e3e78ad1fd75" score = 75 quality = 90 @@ -14131,8 +14184,8 @@ rule REVERSINGLABS_Cert_Blocklist_D79739187C585E453C00Afc11D77B523 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9494-L9512" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9494-L9512" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6d6db87227d7be559afa67c4f2b65b01f26741fdf337d920241a633bb036426f" score = 75 quality = 90 @@ -14156,8 +14209,8 @@ rule REVERSINGLABS_Cert_Blocklist_961Cecb0227845317549E9343A980E91 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9514-L9532" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9514-L9532" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c74512e95e2d6aedecb1dbd30fac6fde40d1e9520c89b785519694d9bc9ba854" score = 75 quality = 90 @@ -14181,8 +14234,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Ef6392B2993A6F67578299659467Ea8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9534-L9550" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9534-L9550" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f6b454a575ea7635d5edebffe3c9c83e95312ee33245e733987532348258733e" score = 75 quality = 90 @@ -14206,8 +14259,8 @@ rule REVERSINGLABS_Cert_Blocklist_A918455C0D4Da7Ca474F41F11A7Cf38C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9552-L9570" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9552-L9570" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ea30d85c057f9363ce29d4c024097c50a8752dd2095481181322fe5d5c92bb4b" score = 75 quality = 90 @@ -14231,8 +14284,8 @@ rule REVERSINGLABS_Cert_Blocklist_936Bc256D2057Ca9B9Ec3034C3Ed0Ee6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9572-L9590" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9572-L9590" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7e90c29bcfe4632e70b61a0cf2ab48a3de986bd5c6c730f64a363f4f3d79a3f4" score = 75 quality = 90 @@ -14256,8 +14309,8 @@ rule REVERSINGLABS_Cert_Blocklist_Afe8Fee94B41422E01E4897Bcd52D0A4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9592-L9610" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9592-L9610" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "02c55b182bc9843334baed9c0a7cca2c88cd1de00ca9b47b10ec79b7a5acf9bb" score = 75 quality = 90 @@ -14281,8 +14334,8 @@ rule REVERSINGLABS_Cert_Blocklist_718E89Ddb33257Ea77Ba74Be7F2Baf1D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9612-L9628" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9612-L9628" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2f0defa1e1d905d937677e96f2a0955d9737f6976596932cc093fdecfea3fdb0" score = 75 quality = 90 @@ -14306,8 +14359,8 @@ rule REVERSINGLABS_Cert_Blocklist_4D3E38F4Aebbc32257450726B29Be117 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9630-L9646" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9630-L9646" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f618547942fcd9b3d1104cb5bedeecec8596fa7cc34bca838b6120085b305d73" score = 75 quality = 90 @@ -14331,8 +14384,8 @@ rule REVERSINGLABS_Cert_Blocklist_8F4C49Dae1F1Ff0Ebe9104C6F73242Bd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9648-L9666" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9648-L9666" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a8c99cc30b791a76fe3cd48184bf95ee47abb30bd200128efd2f5295ee18f7b1" score = 75 quality = 90 @@ -14356,8 +14409,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ac3C05F1Cb9453De8E7110F589Fb32C0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9668-L9686" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9668-L9686" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6328fd5dbb497c69ddc9151f85754669760b709ecbff3e8f320a40a62ca0dd2c" score = 75 quality = 90 @@ -14381,8 +14434,8 @@ rule REVERSINGLABS_Cert_Blocklist_Fbb96A90B6718810311767Ca25Ab1E48 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9688-L9706" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9688-L9706" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "431e3364a42b272d9b71b92dee44cc185ef034a45a0b72bbda82cf7e9b29c355" score = 75 quality = 90 @@ -14406,8 +14459,8 @@ rule REVERSINGLABS_Cert_Blocklist_Cfd38423Aef875A10B16644D058297E2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9708-L9726" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9708-L9726" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a2f67cbf31c9db2891892c31a7ed4ce7eccd834bfb10ae70f58e46f8e68e7c17" score = 75 quality = 90 @@ -14431,8 +14484,8 @@ rule REVERSINGLABS_Cert_Blocklist_E6C05C5A2222Bf92818324A3A7374Ad3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9728-L9746" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9728-L9746" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bea8fea49144abc109e33a5964bb8e113aa61b4cd70c72a43183cb0840429571" score = 75 quality = 90 @@ -14456,8 +14509,8 @@ rule REVERSINGLABS_Cert_Blocklist_75Ce08Bdbad44123299Dbe9D7C1D20De : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9748-L9764" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9748-L9764" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8ba66ab55f9a6755e11a7f39152aa26917271c7f6bc5ffdb42d07ad791fb47d7" score = 75 quality = 90 @@ -14481,8 +14534,8 @@ rule REVERSINGLABS_Cert_Blocklist_333705C20B56E57F60B5Eb191Eef0D90 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9766-L9782" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9766-L9782" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "30eeec467b837f6b1759cd0fd6a8bc2e8942f2400df170c671287f4159652479" score = 75 quality = 90 @@ -14506,8 +14559,8 @@ rule REVERSINGLABS_Cert_Blocklist_A2A0Ba281262Acce7A00119E25564386 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9784-L9802" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9784-L9802" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f5e3c16f6caaf5f3152d90dc48895d0bbcdb296c368beeebb96157f03a8ded40" score = 75 quality = 90 @@ -14531,8 +14584,8 @@ rule REVERSINGLABS_Cert_Blocklist_338483Cc174C16Ebc454A3803Ffd4217 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9804-L9820" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9804-L9820" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7d7dd55eaab15cf458e5e57f0e5fbebdcc9313aee05394310a5cf9d9b4def153" score = 75 quality = 90 @@ -14556,8 +14609,8 @@ rule REVERSINGLABS_Cert_Blocklist_Be89936C26Cd0D845074F6B7B47F480C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9822-L9840" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9822-L9840" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "348df24620bfe6322c410cb593f5caad67492b0b5af234ee89b0411beb4b48f9" score = 75 quality = 90 @@ -14581,8 +14634,8 @@ rule REVERSINGLABS_Cert_Blocklist_0F20A5155E53Ce20Bb644F646Ed6A2Fd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9842-L9858" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9842-L9858" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "70d57f2c24d4ae6f17339bfb998589a3b10f5dd4b19ac8a5bc99e082145c4ed0" score = 75 quality = 90 @@ -14606,8 +14659,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ea734E1Dfb6E69Ed2Bc55E513Bf95B5E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9860-L9878" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9860-L9878" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a18d1c1e5e22c1aa041a4b2d23d2aefcbedbd3517a079d578e1a143ecadb4533" score = 75 quality = 90 @@ -14631,8 +14684,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ba67B0De51Ebb9B1179804E75357Ab26 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9880-L9898" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9880-L9898" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "69b9012fc4ab9636d159de49ff452f054030c1157cf70a95512b2a0748dad7c0" score = 75 quality = 90 @@ -14656,8 +14709,8 @@ rule REVERSINGLABS_Cert_Blocklist_Cff2B275Ba8A1Dde83Ac7Ff858399A62 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9900-L9918" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9900-L9918" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d37e1d94048339a86b8fa173d3ab753fc5e79329b73df9fda5815cd622c57745" score = 75 quality = 90 @@ -14681,8 +14734,8 @@ rule REVERSINGLABS_Cert_Blocklist_D22E026C5B5966F1Cf6Ef00A7C06682E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9920-L9938" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9920-L9938" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "33a05d46b40ffdf49bfa5facca41ebdf6bedcabc1cb1f5b9bf2d043ad1c869b0" score = 75 quality = 90 @@ -14706,8 +14759,8 @@ rule REVERSINGLABS_Cert_Blocklist_3054F940C931Bad7B238A24376C6A5Cc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9940-L9956" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9940-L9956" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "21c8e8f10d1e4b9eb917c86ac868de2afcd5776a9c1d59149df1d07d8c3e14b9" score = 75 quality = 90 @@ -14731,8 +14784,8 @@ rule REVERSINGLABS_Cert_Blocklist_A617E23D6Ca8F34E2F7413Cd299Fc72B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9958-L9976" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9958-L9976" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f307a0b598f0876c003aa43db50e024698b6f93931e626c085f98553c14ec2ae" score = 75 quality = 90 @@ -14756,8 +14809,8 @@ rule REVERSINGLABS_Cert_Blocklist_387Eeb89B8Bf626Bbf4C7C9F5B998B40 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9978-L9994" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9978-L9994" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2377eeb5316d25752443735e78d0ad7de398a2677f5a0fd45fd6e6c87720d49b" score = 75 quality = 90 @@ -14781,8 +14834,8 @@ rule REVERSINGLABS_Cert_Blocklist_292Eb1133507F42E6F36C5549C189D5E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L9996-L10012" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L9996-L10012" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bc3ef217455b74900cae114d25b02325d2bef25c11873342df1dd2369cbce76a" score = 75 quality = 90 @@ -14806,8 +14859,8 @@ rule REVERSINGLABS_Cert_Blocklist_5Fbf16A33D26390A15F046C310030Cf0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10014-L10030" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10014-L10030" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "24bee3563e0867ef6702e7f57bbce7075f766410650ae5ce1e2e8c7b14a3eaca" score = 75 quality = 90 @@ -14831,8 +14884,8 @@ rule REVERSINGLABS_Cert_Blocklist_0F007898Afcba5F8Af8Ae65D01803617 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10032-L10048" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10032-L10048" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "27610bb3bf069991803611474abf44a3bf82fc9283d0412a1c24ae46a3f5352e" score = 75 quality = 90 @@ -14856,8 +14909,8 @@ rule REVERSINGLABS_Cert_Blocklist_E55Be88Ddbd93C423220468D430905Dd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10050-L10068" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10050-L10068" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "05b2f297454e7080591b85991b224193eb89fc5074eb3c2e484ceadad2de4cb7" score = 75 quality = 90 @@ -14881,8 +14934,8 @@ rule REVERSINGLABS_Cert_Blocklist_06Bcb74291D96096577Bdb1E165Dce85 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10070-L10086" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10070-L10086" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "00b7ff8f3cbc04c48c71433c384d7a7884b856f261850e33ea4413a12cf5a1b5" score = 75 quality = 90 @@ -14906,8 +14959,8 @@ rule REVERSINGLABS_Cert_Blocklist_C8442A8185082Ef1Ed7Dc3Fff2176Aa7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10088-L10106" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10088-L10106" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "74b1b48f0179187ea7bb8ef4663bf13da47f5c6405ecc5589706184564c05727" score = 75 quality = 90 @@ -14931,8 +14984,8 @@ rule REVERSINGLABS_Cert_Blocklist_0406C4A1521A38C8D0C4Aa214388E4Dc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10108-L10124" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10108-L10124" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f6780751ae553771eb57201a8672847a24512e6279b6a4fd843d8ee2f326860a" score = 75 quality = 90 @@ -14956,8 +15009,8 @@ rule REVERSINGLABS_Cert_Blocklist_12705Fb66Bc22C68372A1C4E5Fa662E2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10126-L10142" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10126-L10142" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f10316a26e2d34400b7c2e403eab18ab6c1cc94b35f0ac8a3f490d101d29dc8d" score = 75 quality = 90 @@ -14981,8 +15034,8 @@ rule REVERSINGLABS_Cert_Blocklist_3B0914E2982Be8980Aa23F49848555E5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10144-L10160" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10144-L10160" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ea7d9fa7817751fef775765b54be5dd4d00c15ca50ac10fb40fb46cc3634c7b0" score = 75 quality = 90 @@ -15006,8 +15059,8 @@ rule REVERSINGLABS_Cert_Blocklist_029Bf7E1Cb09Fe277564Bd27C267De5A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10162-L10178" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10162-L10178" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3f64372d11d61c669580d90cdf2201e7f2904fb3d73d27be2ff1559c9c37614a" score = 75 quality = 90 @@ -15031,8 +15084,8 @@ rule REVERSINGLABS_Cert_Blocklist_D3Aee8Abb9948844A3Ac1C04Cc7E6Bdf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10180-L10198" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10180-L10198" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3f3f1d5c871d2b73627d4281ac5bcd08799fb47f94155e82795d97c87de35e40" score = 75 quality = 90 @@ -15056,8 +15109,8 @@ rule REVERSINGLABS_Cert_Blocklist_734819463C1195Bd6E135Ce4D5Bf49Bc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10200-L10216" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10200-L10216" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a63c05cca23b61ba6eabda2b60c617b966a2669fd3a0da30354792e5c1ae2140" score = 75 quality = 90 @@ -15081,8 +15134,8 @@ rule REVERSINGLABS_Cert_Blocklist_Db95B22362D46A73C39E0Ac924883C5B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10218-L10236" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10218-L10236" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "895983bcb7f3a0c5ce54504f4a2ff8d652137434b8951380d756de6556d0844e" score = 75 quality = 90 @@ -15106,8 +15159,8 @@ rule REVERSINGLABS_Cert_Blocklist_0C48732873Ac8Ccebaf8F0E1E8329Cec : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10238-L10254" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10238-L10254" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7c9476a4119e013c8bb3c14b607090d592feaa5f2fc0f78d810555681d4a3733" score = 75 quality = 90 @@ -15131,8 +15184,8 @@ rule REVERSINGLABS_Cert_Blocklist_C51F4Cf4D82Bc920421E1Ad93E39D490 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10256-L10274" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10256-L10274" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cef717e7fe3eb0fb958d405caaf98fa51b22b150ccbf1286d3b4634e9df81ade" score = 75 quality = 90 @@ -15156,8 +15209,8 @@ rule REVERSINGLABS_Cert_Blocklist_C96086F1894E6420D2B4Bdeea834C4D7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10276-L10294" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10276-L10294" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "949bbd41ad4c83a05c1f004786cd296e2af80a3a559955ec90a4675cdfa04258" score = 75 quality = 90 @@ -15181,8 +15234,8 @@ rule REVERSINGLABS_Cert_Blocklist_06Fa27A121Cc82230C3013Ee634B6C62 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10296-L10312" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10296-L10312" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "23ac7a97e7632536ed27cf9078b6bc1a734f1e991a20a228734b45117582f367" score = 75 quality = 90 @@ -15206,8 +15259,8 @@ rule REVERSINGLABS_Cert_Blocklist_9Dd3B2F7957Ba99F4B04Fcdbe03B7Aac : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10314-L10332" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10314-L10332" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d4f1b75dddd47fe8a19bd8e794b4930bdcaf54d63db57422db0a9b631d4f488d" score = 75 quality = 90 @@ -15231,8 +15284,8 @@ rule REVERSINGLABS_Cert_Blocklist_061051Ff2A8Afab10347A6F1Ff08Ecb6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10334-L10350" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10334-L10350" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "db3ac3ee326c60e9abc94a2fb53d801637f044e7ab72d69e53958799e48747b7" score = 75 quality = 90 @@ -15256,8 +15309,8 @@ rule REVERSINGLABS_Cert_Blocklist_Eda2429083Bfafb04E6E7Bdda1B08834 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10352-L10370" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10352-L10370" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4f7d5c6929fe364c8868fddb28dd7bbf7cdcf3896d57836466af1a538190d11c" score = 75 quality = 90 @@ -15281,8 +15334,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A590154B5980E566314122987Dea548 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10372-L10388" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10372-L10388" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d5fdf2bc61fadf3e73bcf1695c48ebc465e614cdd2310f9e5f40648d9615afc4" score = 75 quality = 90 @@ -15306,8 +15359,8 @@ rule REVERSINGLABS_Cert_Blocklist_69A72F5591Ad78A0825Fbb9402Ab9543 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10390-L10406" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10390-L10406" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "72ca07b7722f9506c5c42b5e58c5ce9b3a7d607164a5f265015769f2831cd588" score = 75 quality = 90 @@ -15331,8 +15384,8 @@ rule REVERSINGLABS_Cert_Blocklist_0883Db137021B51F3A2A08A76A4Bc066 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10408-L10424" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10408-L10424" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5e3c8654169830790665992f5d7669d0ca6c1c8048580b3ae70331ad2a763a6c" score = 75 quality = 90 @@ -15356,8 +15409,8 @@ rule REVERSINGLABS_Cert_Blocklist_2B921Aaaba777B5A99507196C6F1C46C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10426-L10442" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10426-L10442" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a00eb9837f7700d83862dff2077d85c68c24621d7aacf857b42587dc37976465" score = 75 quality = 90 @@ -15381,8 +15434,8 @@ rule REVERSINGLABS_Cert_Blocklist_0332D5C942869Bdcabf5A8266197Cd14 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10444-L10460" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10444-L10460" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "726ac44dd8109fcd0a9120f6c0673b8ecf7d5b3a4bb81976f48402e21502201a" score = 75 quality = 90 @@ -15406,8 +15459,8 @@ rule REVERSINGLABS_Cert_Blocklist_4679C5398A279318365Fd77A84445699 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10462-L10478" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10462-L10478" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bdb68be92b3ba6b5eaa6e8e963529c0b9213942ba2552c687496ad5d12d5b472" score = 75 quality = 90 @@ -15431,8 +15484,8 @@ rule REVERSINGLABS_Cert_Blocklist_101D6A5A29D9A77807553Ceac669D853 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10480-L10496" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10480-L10496" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bce92750f71477ecfa7b8213724344708066c0e6133a47cd6758bbd9f8f9da5f" score = 75 quality = 90 @@ -15456,8 +15509,8 @@ rule REVERSINGLABS_Cert_Blocklist_6000F8C02B0A15B1E53B8399845Faddf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10498-L10514" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10498-L10514" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "00ceb241555154cab97ef616042dbd966f3a8fae257e142dfe6bad9559bd1724" score = 75 quality = 90 @@ -15481,8 +15534,8 @@ rule REVERSINGLABS_Cert_Blocklist_121070Be1E782F206985543Bc7Bc58B6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10516-L10532" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10516-L10532" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a5d603cf64c8a16fa12daf9c6b5d0850e6145fb39b38442ed724ec0f849b8be9" score = 75 quality = 90 @@ -15506,8 +15559,8 @@ rule REVERSINGLABS_Cert_Blocklist_5226A724Cfa0B4Bc0164Ecda3F02A3Dc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10534-L10550" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10534-L10550" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0ba1155b30761f48674aaa82a70a06fea30cced6518f089f3f9f173a4eb06a09" score = 75 quality = 90 @@ -15531,8 +15584,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A7Be7722B65A866Ebcd3Bd7F8F10825 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10552-L10568" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10552-L10568" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c4aa22241ef72d454db4ec0fb0933abfa7b1d8d1029b45410475832cda4a2af4" score = 75 quality = 90 @@ -15556,8 +15609,8 @@ rule REVERSINGLABS_Cert_Blocklist_05634456Dbedb3556Ca8415E64815C5D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10570-L10586" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10570-L10586" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f5941c74821c0cd76633393d0346a9de2c7bccc666dc20b34c5b4d733faefc8f" score = 75 quality = 90 @@ -15581,8 +15634,8 @@ rule REVERSINGLABS_Cert_Blocklist_2E07A8D6E3B25Ae010C8Ed2C4Ab0Fb37 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10588-L10604" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10588-L10604" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bad2144c9cde02a75fa968e3c24178f3ba73b0addb2b4967f24733b933e0eeb6" score = 75 quality = 90 @@ -15606,8 +15659,8 @@ rule REVERSINGLABS_Cert_Blocklist_30B4Eeebd88Fd205Acc8577Bbaed8655 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10606-L10622" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10606-L10622" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "673ec5a1cacb9a7be101a4a533baf5a1eab4e6dd8721c69e56636701c5303c72" score = 75 quality = 90 @@ -15631,8 +15684,8 @@ rule REVERSINGLABS_Cert_Blocklist_B3391A6C1B3C6836533959E2384Ab4Ca : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10624-L10642" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10624-L10642" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "38e38acfbfbf63b7179d2f8656f70224afa9269a7bdecd10ccbbbd92a6a216d3" score = 75 quality = 90 @@ -15656,8 +15709,8 @@ rule REVERSINGLABS_Cert_Blocklist_05D50A0E09Bb9A836Ffb90A3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10644-L10660" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10644-L10660" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1bd1960cd6dd8bf83472dc2b1809b84ceb3db68a5e6c3ba68f28ad922230b2ed" score = 75 quality = 90 @@ -15681,8 +15734,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A2787Fbb4627C91611573E323584113 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10662-L10678" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10662-L10678" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "efa352beafb56b95a89554bc8929f8e01a4da46eef1f6cf8a1487a2a06bc1b3e" score = 75 quality = 90 @@ -15706,8 +15759,8 @@ rule REVERSINGLABS_Cert_Blocklist_1D36C4F439D651503589318F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10680-L10696" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10680-L10696" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "73dc3c01041d50100a8d5519afe1a80f470c30175f9ad1bf76ac287ac199a959" score = 75 quality = 90 @@ -15731,8 +15784,8 @@ rule REVERSINGLABS_Cert_Blocklist_26F855A25890B749578F13E4B9459768 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10698-L10714" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10698-L10714" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "35bfa39ef8f03d10af884f288278ea6ad3aff31cbae111057c2b619c6dc0a752" score = 75 quality = 90 @@ -15756,8 +15809,8 @@ rule REVERSINGLABS_Cert_Blocklist_0F1Ae2239Bb96C5Aef49D0Ae50266912 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10716-L10732" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10716-L10732" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4f88df4fc2f4cd89aa177ce09caab3e2660267ae883f7ab54c22a9ba1657bad0" score = 75 quality = 90 @@ -15781,8 +15834,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Deea179F5757Fe529043577762419Df : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10734-L10750" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10734-L10750" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "67c3d3496caf54ca0b1afc4d1dcc902e2f3632ac6708f85e163d427b567d098f" score = 75 quality = 90 @@ -15806,8 +15859,8 @@ rule REVERSINGLABS_Cert_Blocklist_5B1F9Ec88D185631Ab032Dbfd5166C0D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10752-L10768" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10752-L10768" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "dec9d43c6911deb5f35c45692bfd6ef47f85d955f5e59041e58a1f0d2fc306e3" score = 75 quality = 90 @@ -15831,8 +15884,8 @@ rule REVERSINGLABS_Cert_Blocklist_58Af00Ce542760Fc116B41Fa92E18589 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10770-L10786" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10770-L10786" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0ff773d252e5e0402171ae15d7ab43bcfd313eb8c326ed5f128a89ec43386a52" score = 75 quality = 90 @@ -15856,8 +15909,8 @@ rule REVERSINGLABS_Cert_Blocklist_25Ba18A267D6D8E08Ebc6E2457D58D1E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10788-L10804" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10788-L10804" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "174fe170c26a8197486e7b390d9fce4da61fb68ee5dc9486d43dbeb3cf659c3a" score = 75 quality = 90 @@ -15881,8 +15934,8 @@ rule REVERSINGLABS_Cert_Blocklist_12Df5Ff3460979Cec1288D874A9Fbf83 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10806-L10822" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10806-L10822" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3d4b5e56962d04bc35451eeab4c1870c8653c9afcbb28dc6bad7cfb1711e9df1" score = 75 quality = 90 @@ -15906,8 +15959,8 @@ rule REVERSINGLABS_Cert_Blocklist_Df2547B2Cab5689A81D61De80Eaaa3A2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10824-L10842" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10824-L10842" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cde89ae5b77ff6833fe642bdd74e81763ef068e31c07e7881906e4e4a5939942" score = 75 quality = 90 @@ -15931,8 +15984,8 @@ rule REVERSINGLABS_Cert_Blocklist_28B691272719B1Ee : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10844-L10860" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10844-L10860" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0bd973f415b7cfa0858c705c4486da9f181c7259af01d1cff486fb6b8e8e775b" score = 75 quality = 90 @@ -15956,8 +16009,8 @@ rule REVERSINGLABS_Cert_Blocklist_1C897216E58E83Cbe74Ad03284E1Fb82 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10862-L10878" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10862-L10878" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6b3b2708d3a442fa6425e60ae900c94fc22fbfdb47f290ff56e9d349d99fd85f" score = 75 quality = 90 @@ -15981,8 +16034,8 @@ rule REVERSINGLABS_Cert_Blocklist_5A364C4957D93406F76321C2316F42F0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10880-L10896" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10880-L10896" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fe3a2b906debb3f03e6a403829fca02c751754e9a02442a962c66defb84aed83" score = 75 quality = 90 @@ -16006,8 +16059,8 @@ rule REVERSINGLABS_Cert_Blocklist_E7E7F7180666546Ce7A8Da32119F5Ce1 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10898-L10916" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10898-L10916" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "940f6508208998593f309ffeeeda20ab475d427c952a14871b6e58e17d2a4c85" score = 75 quality = 90 @@ -16031,8 +16084,8 @@ rule REVERSINGLABS_Cert_Blocklist_062B2827500C5Df35A83F661B3Af5Dd3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10918-L10934" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10918-L10934" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4edc263b08b21428b5f2f4f14f9582c0f96f79cb49fbba563c103bf8bb2037a6" score = 75 quality = 90 @@ -16056,8 +16109,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Bf27695Fd20B588F2B2F173B6Caf2Ba : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10936-L10952" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10936-L10952" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "94d8739761b6a8ee91550be47432b046609b076aab6e57996de123a0fcaba73e" score = 75 quality = 90 @@ -16081,8 +16134,8 @@ rule REVERSINGLABS_Cert_Blocklist_1B248C8508042D36Bbd5D92D189C61D8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10954-L10970" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10954-L10970" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2c063d0878a8bf6cd637e1dac2cb9164beb52c951e01858a7c3c9c4c1a853f54" score = 75 quality = 90 @@ -16106,8 +16159,8 @@ rule REVERSINGLABS_Cert_Blocklist_032660Ee1D49Ad35086027473E2614E5E724 : INFO FI date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10972-L10988" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10972-L10988" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8d1435d2fa70db12cde2f9098e35ca1737f5aac36bac91329b28f03aad090e90" score = 75 quality = 90 @@ -16131,8 +16184,8 @@ rule REVERSINGLABS_Cert_Blocklist_043052956E1E6Dbd5F6Ae3D8B82Cad2A2Ed8 : INFO FI date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L10990-L11006" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L10990-L11006" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c29fb109c741437a3739f1c42aadace8f612ef1e3ea90e3e2bdd8a92c85e766a" score = 75 quality = 90 @@ -16156,8 +16209,8 @@ rule REVERSINGLABS_Cert_Blocklist_Dbc03Ca7E6Ae6Db6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11008-L11026" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11008-L11026" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0077b9c46ddd98a4929878ba4ba9476ed7fb1d7bf6e30c3ae0f950445d01e8f3" score = 75 quality = 90 @@ -16181,8 +16234,8 @@ rule REVERSINGLABS_Cert_Blocklist_7D27332C3Cb3A382A4Fd232C5C66A2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11028-L11044" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11028-L11044" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c1c50015db7f97b530819b40e2578463a6021bfff8e2582858a4c3fbd1a9b9bc" score = 75 quality = 90 @@ -16206,8 +16259,8 @@ rule REVERSINGLABS_Cert_Blocklist_82D224323Efa65060B641F51Fadfef02 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11046-L11064" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11046-L11064" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9d361c91ed24b6c20a7b35957e26f208ce8e0a3d79c5a6fed6278acd826ccf49" score = 75 quality = 90 @@ -16231,8 +16284,8 @@ rule REVERSINGLABS_Cert_Blocklist_890570B6B0E2868A53Be3F8F904A88Ee : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11066-L11084" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11066-L11084" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fb7af8ec09da2fecaaaed8c7770966f11ef8a44a131553a9d1412387db2fb7ea" score = 75 quality = 90 @@ -16256,8 +16309,8 @@ rule REVERSINGLABS_Cert_Blocklist_2642Fe865F7566Ce3123A5142C207094 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11086-L11102" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11086-L11102" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1ad4adf8b05a6cc065d289e6963480d37a92712a318744a30a16aad22380f238" score = 75 quality = 90 @@ -16281,8 +16334,8 @@ rule REVERSINGLABS_Cert_Blocklist_4A2E337Fff23E5B2A1321Ffde56D1759 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11104-L11120" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11104-L11120" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bc2df95ddf1ef3d5f83d14852e1cf6cbf4b71bfbe88fc97c2a4553e8581ddf47" score = 75 quality = 90 @@ -16306,8 +16359,8 @@ rule REVERSINGLABS_Cert_Blocklist_92D9B92F8Cf7A1Ba8B2C025Be730C300 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11122-L11140" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11122-L11140" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2a0be6157e589705ad19756971bd865edad2d54760d03c2e6f47a461b402ad68" score = 75 quality = 90 @@ -16331,8 +16384,8 @@ rule REVERSINGLABS_Cert_Blocklist_B8164F7143E1A313003Ab0C834562F1F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11142-L11160" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11142-L11160" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a42fec2e0e8d37948420f16907f39c3d502c535be98024d04a777dfbc633004d" score = 75 quality = 90 @@ -16356,8 +16409,8 @@ rule REVERSINGLABS_Cert_Blocklist_24E4A2B3Db6Be1007B9Ddc91995Bc0C8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11162-L11178" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11162-L11178" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "861691ce7bae4366f3b35d01c84bb0031b54653869f52eaccf20808b1b55d2af" score = 75 quality = 90 @@ -16381,8 +16434,8 @@ rule REVERSINGLABS_Cert_Blocklist_881573Fc67Ff7395Dde5Bccfbce5B088 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11180-L11198" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11180-L11198" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ce489a4a2f07181d6fbf295f426deeaf51310e061bac2e56d65b37eeb397ff9a" score = 75 quality = 90 @@ -16406,8 +16459,8 @@ rule REVERSINGLABS_Cert_Blocklist_53E1F226Cb77574F8Fbeb5682Da091Bb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11200-L11216" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11200-L11216" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "591846225d5faf3ee8f3102acaad066f0187219044077bbdaf32345613b00965" score = 75 quality = 90 @@ -16431,8 +16484,8 @@ rule REVERSINGLABS_Cert_Blocklist_0772B4D1D63233D2B8771997Bc8Da5C4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11218-L11234" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11218-L11234" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "30586a643b29f3c943b3f35bb1639c5b9fa48ecbd776775086e35af502aa4a7a" score = 75 quality = 90 @@ -16456,8 +16509,8 @@ rule REVERSINGLABS_Cert_Blocklist_02B6656292310B84022Db5541Bc48Faf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11236-L11252" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11236-L11252" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "40b570b28e10ebd2a1ba515dc3fa45bdb5c0b76044e4dda7a6819976072a67a2" score = 75 quality = 90 @@ -16481,8 +16534,8 @@ rule REVERSINGLABS_Cert_Blocklist_64C2505C7306639Fc8Eae544B0305338 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11254-L11270" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11254-L11270" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9b6fb002d603135391958668be0ef805e441928a035c9c4da4bb9915aa3086e8" score = 75 quality = 90 @@ -16506,8 +16559,8 @@ rule REVERSINGLABS_Cert_Blocklist_2F96A89Bfec6E44Dd224E8Fd7E72D9Bb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11272-L11288" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11272-L11288" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c0c8e5c0e2e120ee6b055e9a6b2af3d424bed0832c2619beab658fe01757f69f" score = 75 quality = 90 @@ -16531,8 +16584,8 @@ rule REVERSINGLABS_Cert_Blocklist_B649A966410F62999C939384Af553919 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11290-L11308" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11290-L11308" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "623a2f931198eacf44fd233065e96a4dcadb5b3bbc7ca56df2b6ae9eafc4faa5" score = 75 quality = 90 @@ -16556,8 +16609,8 @@ rule REVERSINGLABS_Cert_Blocklist_45245Eef53Fcf38169C715Cf68F44452 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11310-L11326" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11310-L11326" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7e0c3147e657802e457f6df271b7f5a64c81fd13f936a8935aa991022e4ab238" score = 75 quality = 90 @@ -16581,8 +16634,8 @@ rule REVERSINGLABS_Cert_Blocklist_1895433Ee9E2Bd48619D75132262616F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11328-L11344" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11328-L11344" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f00a29ff5dddae40225ab62cb2d4b9dec1539ad58c8cd27d686480eecdb3e31d" score = 75 quality = 90 @@ -16606,8 +16659,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Ffc9825644Caf5B1F521780C5C7F42C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11346-L11362" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11346-L11362" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1a9263c809f5633d01d4d4d0091c8dc214bad73af0eff3c9a94b33bca513f26d" score = 75 quality = 90 @@ -16631,8 +16684,8 @@ rule REVERSINGLABS_Cert_Blocklist_8D52Fb12A2511E86Bbb0Ba75C517Eab0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11364-L11382" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11364-L11382" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "023830ab3d71ed8ecf8f0e271c56dc267dcd000f5ff156c70d31089cd7010da8" score = 75 quality = 90 @@ -16656,8 +16709,8 @@ rule REVERSINGLABS_Cert_Blocklist_332Bd5801E8415585E72C87E0E2Ec71D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11384-L11400" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11384-L11400" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3648c3a8dbcdbd24746b9fa8cb3071d5f5019e5917848d88437158c6cb165445" score = 75 quality = 90 @@ -16681,8 +16734,8 @@ rule REVERSINGLABS_Cert_Blocklist_E3B80C0932B52A708477939B0D32186F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11402-L11420" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11402-L11420" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "acdfce4dc25cbc9e9817453d5cf56c7d319bebdf7a039ea47412ec3b2f68cb02" score = 75 quality = 90 @@ -16706,8 +16759,8 @@ rule REVERSINGLABS_Cert_Blocklist_C79F817F082986Bef3209F6723C8Da97 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11422-L11440" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11422-L11440" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a5960f4c2ed768ccc5779d3754f51463c7b14a3a887c690944add23fba464f1a" score = 75 quality = 90 @@ -16731,8 +16784,8 @@ rule REVERSINGLABS_Cert_Blocklist_1E5Efa53A14599Cc82F56F0790E20B17 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11442-L11458" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11442-L11458" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "78cbfeb5d7b58029a5b4107f2a59e892ff9d71788cf74e88ac823cb85ba35a94" score = 75 quality = 90 @@ -16756,8 +16809,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Cf2D0B5Bfdd68Cf777A0C12F806A569 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11460-L11476" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11460-L11476" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4d8fd52cd12f9512c0b148f9915860152f108884d29617a5fbfd62500d3a14c4" score = 75 quality = 90 @@ -16781,8 +16834,8 @@ rule REVERSINGLABS_Cert_Blocklist_F675139Ea68B897A865A98F8E4611F00 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11478-L11496" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11478-L11496" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2306e90d376f5de8a4eb6d4a696bc1781686d7094cb0a2db48019ee93c1bf60a" score = 75 quality = 90 @@ -16806,8 +16859,8 @@ rule REVERSINGLABS_Cert_Blocklist_4728189Fa0F57793484Cdf764F5E283D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11498-L11514" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11498-L11514" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9ec7e84c77583bd52ccfb8d6d5831f3634ed0a401d8103376c4775b7f2c43d81" score = 75 quality = 90 @@ -16831,8 +16884,8 @@ rule REVERSINGLABS_Cert_Blocklist_9Bd81A9Adaf71F1Ff081C1F4A05D7Fd7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11516-L11534" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11516-L11534" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e275a1fd2eb931030fa8b5fc11cd1b335835aaa553a42455053cb93fef5e6e72" score = 75 quality = 90 @@ -16856,8 +16909,8 @@ rule REVERSINGLABS_Cert_Blocklist_C81319D20C6F1F1Aec3398522189D90C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11536-L11554" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11536-L11554" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2a9f13f5e79a12f7e9d9d4a0dcaac065e1fc5167c67bc9f3fd7ba1c374b26d96" score = 75 quality = 90 @@ -16881,8 +16934,8 @@ rule REVERSINGLABS_Cert_Blocklist_C318D876768258A696Ab9Dd825E27Acd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11556-L11574" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11556-L11574" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "691b57929c93d14f8700e0e61170b9248499fd36b80aec90f2054c32d6a3a9eb" score = 75 quality = 90 @@ -16906,8 +16959,8 @@ rule REVERSINGLABS_Cert_Blocklist_06Df5C318759D6Ea9D090Bfb2Faf1D94 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11576-L11592" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11576-L11592" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5f151ee5781a15cca4394fdd8200162eae47e9d088a0b1551c9ed22ce11473a2" score = 75 quality = 90 @@ -16931,8 +16984,8 @@ rule REVERSINGLABS_Cert_Blocklist_02De1Cc6C487954592F1Bf574Ca2B000 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11594-L11610" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11594-L11610" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "40b78005d343684d08bb93e92c51eee10e674e8deb9eec290bc9ffe3b23061b1" score = 75 quality = 90 @@ -16956,8 +17009,8 @@ rule REVERSINGLABS_Cert_Blocklist_A32B8B4F1Be43C23Eb2848Ab4Ef06Bb2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11612-L11630" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11612-L11630" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "dd7d44349baaf4a2e2f61b38cef31f288110bb03944fd4593f52a0ab03b9d172" score = 75 quality = 90 @@ -16981,8 +17034,8 @@ rule REVERSINGLABS_Cert_Blocklist_626735Ed30E50E3E0553986D806Bfc54 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11632-L11648" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11632-L11648" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0a2acf8528a12fd05cf58c2ed5224f7472d14251b342ce4df6d9c10c6a6decfc" score = 75 quality = 90 @@ -17006,8 +17059,8 @@ rule REVERSINGLABS_Cert_Blocklist_34D42E871Ddb1C92Fa20B55B384E1259 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11650-L11666" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11650-L11666" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8af5f4abe6425713b7c1fd17deaa78b2cfd6ef73ad960bce883e95661c2dbb56" score = 75 quality = 90 @@ -17031,8 +17084,8 @@ rule REVERSINGLABS_Cert_Blocklist_08D4Dc90047B8470Ccaf3924Dfbd8B5F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11668-L11684" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11668-L11684" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "569db2f6d6f4da9985c57812a03f91bce88f2150b17659249e0f746a0d15150b" score = 75 quality = 90 @@ -17056,8 +17109,8 @@ rule REVERSINGLABS_Cert_Blocklist_C2Fc83D458E653837Fcfc132C9B03062 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11686-L11704" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11686-L11704" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "836cec8d8396680dd64f95d4dd41f7f5876cb4268d983238a01d2e0990cce74a" score = 75 quality = 90 @@ -17081,8 +17134,8 @@ rule REVERSINGLABS_Cert_Blocklist_54C793D2224Bdd6Ca527Bb2B7B9Dfe9D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11706-L11722" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11706-L11722" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "81c9c1d841d4aae3de229cc499ee84920d89928590a3eb157f7a7a7fbc46b4a8" score = 75 quality = 90 @@ -17106,8 +17159,8 @@ rule REVERSINGLABS_Cert_Blocklist_8Cece6Df54Cf6Ad63596546D77Ba3581 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11724-L11742" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11724-L11742" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d6b5bca36ef492ce9b79be905c86c66d43ef38701dafeed977229034119bd00d" score = 75 quality = 90 @@ -17131,8 +17184,8 @@ rule REVERSINGLABS_Cert_Blocklist_984E84Cfe362E278F558E2C70Aaafac2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11744-L11762" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11744-L11762" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e7a8f3dff77121df53d5f932f861e15208b0607ba77712f40927bc14b17a53cd" score = 75 quality = 90 @@ -17156,8 +17209,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ff52Eb011Bb748Fee75153Cbe1E50Dd6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11764-L11782" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11764-L11782" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8c80ed4e4f77df34ff9fcc712deda4c1bbedc588f2b01d02aa705e368fb98c5e" score = 75 quality = 90 @@ -17181,8 +17234,8 @@ rule REVERSINGLABS_Cert_Blocklist_84A4A0D0657E217B176B455E2465Aee0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11784-L11802" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11784-L11802" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "92f6e90bd21182bece68ac1651105f96a18c5b1497d30e0040a978e349341bdb" score = 75 quality = 90 @@ -17206,8 +17259,8 @@ rule REVERSINGLABS_Cert_Blocklist_B8F726508Cf1D7B7913Bf4Bbd1E5C19C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11804-L11822" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11804-L11822" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ec05c7e41e309aff00ae819c63f5bdc8e4172c611779da345efd211e48c9efb1" score = 75 quality = 90 @@ -17231,8 +17284,8 @@ rule REVERSINGLABS_Cert_Blocklist_6A241Ffe96A6349Df608D22C02942268 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11824-L11840" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11824-L11840" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "79db8be7ca3ed80eb1e3a9401e8fec2b83da8b95b16789ed0b59bb7f4639a94d" score = 75 quality = 90 @@ -17256,8 +17309,8 @@ rule REVERSINGLABS_Cert_Blocklist_Aa1D84779792B57F91Fe7A4Bde041942 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11842-L11860" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11842-L11860" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "682af8c799acaca531724c5b3184b855e64ec4531fcc333a485ba2f63331cdae" score = 75 quality = 90 @@ -17281,8 +17334,8 @@ rule REVERSINGLABS_Cert_Blocklist_3C98B6872Fbb1F4Ae37A4Caa749D24C2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11862-L11878" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11862-L11878" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c534ad306f85e12eca2336e998120deb4ba8d0d63b8331986ec7fe4ac69ba65a" score = 75 quality = 90 @@ -17306,8 +17359,8 @@ rule REVERSINGLABS_Cert_Blocklist_E4E795Fd1Fd25595B869Ce22Aa7Dc49F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11880-L11898" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11880-L11898" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ced47bd69b58de9e6b2aa7518ccceca088884acb79c0803c3defe6b115a0abb6" score = 75 quality = 90 @@ -17331,8 +17384,8 @@ rule REVERSINGLABS_Cert_Blocklist_E953Ada7E8F1438E5F7680Ff599Ae43E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11900-L11918" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11900-L11918" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7cb7d77abefd35f0756c5aa0983f7403cca4cbacd94dcc6b510c929bc96c8309" score = 75 quality = 90 @@ -17356,8 +17409,8 @@ rule REVERSINGLABS_Cert_Blocklist_28C57Df09Ce7Cc3Fde2243Beb4D00101 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11920-L11936" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11920-L11936" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "84402dc0a58fca36424d8d6d13c60b80342bb3792f4e32e23878530264358726" score = 75 quality = 90 @@ -17381,8 +17434,8 @@ rule REVERSINGLABS_Cert_Blocklist_2D8Cfcf04209Dc7F771D8D18E462C35A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11938-L11954" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11938-L11954" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2b784e46268d78046365400ef914d7ca673503c93962d0b0740ca2ac9faf7857" score = 75 quality = 90 @@ -17406,8 +17459,8 @@ rule REVERSINGLABS_Cert_Blocklist_016836311Fc39Fbb8E6F308Bb03Cc2B3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11956-L11972" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11956-L11972" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c5f6372a207d02283840e745619e93194d954eedff7bae34aadcb645b1cb78fc" score = 75 quality = 90 @@ -17431,8 +17484,8 @@ rule REVERSINGLABS_Cert_Blocklist_435Abf46053A0A445C54217A8C233A7F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11974-L11990" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11974-L11990" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "839f55e8fe7a86aad406e657fdef48925543b5d3884927104fd3786444a8fccc" score = 75 quality = 90 @@ -17456,8 +17509,8 @@ rule REVERSINGLABS_Cert_Blocklist_B2F9C693A2E6634565F63C79B01Dd8F8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L11992-L12010" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L11992-L12010" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f5ec67c082be21a2495ef90fd0a6d4fc4b1379c4903dcc051d39cf1913d5cf20" score = 75 quality = 90 @@ -17481,8 +17534,8 @@ rule REVERSINGLABS_Cert_Blocklist_54A6D33F73129E0Ef059Ccf51Be0C35E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12012-L12028" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12012-L12028" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6fbed9c8537ea2baeb58044a934fc9741730b8a3ae4d059c23b033973d7ff7d3" score = 75 quality = 90 @@ -17506,8 +17559,8 @@ rule REVERSINGLABS_Cert_Blocklist_142Aac4217E22B525C8587589773Ba9B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12030-L12046" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12030-L12046" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f169925c27f5e0f8d5f658b83d1b9fa4548c4443b16bd4d7f87aa2b8e44bf06b" score = 75 quality = 90 @@ -17531,8 +17584,8 @@ rule REVERSINGLABS_Cert_Blocklist_239664C12Baeb5A6D787912888051392 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12048-L12064" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12048-L12064" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ab2c228088a4c11b3a0f1a5f0acf181cc31e548781cb3f1205475bfbe39c7236" score = 75 quality = 90 @@ -17556,8 +17609,8 @@ rule REVERSINGLABS_Cert_Blocklist_0218Ebfd5A9Bfd55D2F661F0D18D1D71 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12066-L12082" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12066-L12082" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4aabe3beab0055b6ef8f6114c5236940f5693b44e94efd14132b450bb9232c03" score = 75 quality = 90 @@ -17581,8 +17634,8 @@ rule REVERSINGLABS_Cert_Blocklist_35590Ebe4A02Dc23317D8Ce47A947A9B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12084-L12100" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12084-L12100" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2d4bc88943cdc8af00effab745e64e60ef662c668a0b2193c256d11831ef1554" score = 75 quality = 90 @@ -17606,8 +17659,8 @@ rule REVERSINGLABS_Cert_Blocklist_Aa07D4F2857119Cee514A0Bd412F8201 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12102-L12120" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12102-L12120" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fbbea89f2070b2a527bba6199022fbffd269e664b000988a59adf4ca0d4a9f22" score = 75 quality = 90 @@ -17631,8 +17684,8 @@ rule REVERSINGLABS_Cert_Blocklist_40F5660A90301E7A8A8C3B42 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12122-L12138" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12122-L12138" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3573d1d5f11df106f1f6f44f8b0164992f2a50707c6df7b08b05ed9ea7d9173b" score = 75 quality = 90 @@ -17656,8 +17709,8 @@ rule REVERSINGLABS_Cert_Blocklist_0400C7614F86D75Fe4Ee3F6192B6Feda : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12140-L12156" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12140-L12156" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "47735267e9a0fb8107f6c4008bacc8aada1705f6714a0447dacc3928fc20cad6" score = 75 quality = 90 @@ -17681,8 +17734,8 @@ rule REVERSINGLABS_Cert_Blocklist_E573D9C8B403C41Bd59Ffa0A8Efd4168 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12158-L12176" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12158-L12176" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "425126b90fe2ab7c1ec7bf2fd5a91e4438a81992f20f99ed87ec62e7f20043cd" score = 75 quality = 90 @@ -17706,8 +17759,8 @@ rule REVERSINGLABS_Cert_Blocklist_B06Bc166Fc765Dacd2F7448C8Cdd9205 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12178-L12196" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12178-L12196" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2c47166f02c7f94bb4f82296e3220ff7ca3c6c53566d855b2fe77cb842a5fb43" score = 75 quality = 90 @@ -17731,8 +17784,8 @@ rule REVERSINGLABS_Cert_Blocklist_E9268Ed63A7D7E9Dfd40A664Ddfbaf18 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12198-L12216" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12198-L12216" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fc840c0b37867c3b0aa80d4dc609feaaab77d3f0c6f84c8bb2ea7c5a6461ebb8" score = 75 quality = 90 @@ -17756,8 +17809,8 @@ rule REVERSINGLABS_Cert_Blocklist_425Dc3E0Ca8Bcdce19D00D87E3F0Ba28 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12218-L12234" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12218-L12234" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "67a975f2806825bf0da27fcaf33c2ff497fe9bb2af12c22ff505b49070516960" score = 75 quality = 90 @@ -17781,8 +17834,8 @@ rule REVERSINGLABS_Cert_Blocklist_Afc0Ddb7Bdc8207E8C3B7204018Eecd3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12236-L12254" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12236-L12254" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "302e2d6b31ca5c2c33c4ec7294630fd88a9c40f70ddecdc606ccff27b24e1cd4" score = 75 quality = 90 @@ -17806,8 +17859,8 @@ rule REVERSINGLABS_Cert_Blocklist_38989Ec61Ecdb7391Ff5647F7D58Ad18 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12256-L12272" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12256-L12272" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1795812d4daa458b157280cac7a9b13e9b67a2d78eac077691bbce2bf8aeec34" score = 75 quality = 90 @@ -17831,8 +17884,8 @@ rule REVERSINGLABS_Cert_Blocklist_Bc6C43D206A360F2D6B58537C456B709 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12274-L12292" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12274-L12292" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "eb5288d2b96ff7a7783c2b2b02f9f1168784352ed84ad6463dce00c12daca6cb" score = 75 quality = 90 @@ -17856,8 +17909,8 @@ rule REVERSINGLABS_Cert_Blocklist_4929Ab561C812Af93Ddb9758B545F546 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12294-L12310" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12294-L12310" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "12235e324b92b83e9cfaed7cbcff5d093b8b1d7528dd5ac327159cde6e9a4d1f" score = 75 quality = 90 @@ -17881,8 +17934,8 @@ rule REVERSINGLABS_Cert_Blocklist_25C6Dbce3D5499F65D9Df16E9007465D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12312-L12328" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12312-L12328" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "978f05f86734c63afe1e5929a58f3cfff75ef749ffda07252db90b6fe12508ec" score = 75 quality = 90 @@ -17906,8 +17959,8 @@ rule REVERSINGLABS_Cert_Blocklist_Bc6A1812E001362469541108973Bbd52 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12330-L12348" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12330-L12348" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9b678e9fb1e1eda3ac8e027b5e449af446de4379fea46ef7ff820240c73795ee" score = 75 quality = 90 @@ -17931,8 +17984,8 @@ rule REVERSINGLABS_Cert_Blocklist_Bde1D6Dc3622724F427A39E6A34F5124 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12350-L12368" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12350-L12368" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f1cf0b6855269a771447a0b38f4a02996b6527d7df4b143b69598ed591719ca0" score = 75 quality = 90 @@ -17956,8 +18009,8 @@ rule REVERSINGLABS_Cert_Blocklist_5C9F5F96726A6E6Fc3B8Bb153Ac82Af2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12370-L12386" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12370-L12386" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a61bcc4a90a75a429366e3f93929005b67325eccc6cad3df6b7a0c3692597828" score = 75 quality = 90 @@ -17981,8 +18034,8 @@ rule REVERSINGLABS_Cert_Blocklist_6E889Bb3B7F7194B674C6A0335A608E0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12388-L12404" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12388-L12404" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fa2a47f4fb822089fcc958850ce516c8c5d95a6d9b575f3b1d1d4a2ceb2537e4" score = 75 quality = 90 @@ -18006,8 +18059,8 @@ rule REVERSINGLABS_Cert_Blocklist_0F62F760704Bdf8Dc30C7Baa7376F484 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12406-L12422" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12406-L12422" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d54d52e116b9404782ce80664f218d2e142577dac672c53c41b82f0466c7375a" score = 75 quality = 90 @@ -18031,8 +18084,8 @@ rule REVERSINGLABS_Cert_Blocklist_071202Dbfda40B629C5E7Acac947C2D3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12424-L12440" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12424-L12440" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cc51b0ae6a59f68e61ee0b4ff33ea0e1ee9ef04e4c994e1c98da6befab62a5b9" score = 75 quality = 90 @@ -18056,8 +18109,8 @@ rule REVERSINGLABS_Cert_Blocklist_98Ab9585C04D7F0E4Cf4De98C14B684D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12442-L12460" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12442-L12460" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ba43dd15b13623bb99d88c93fb9e751deb95a546325a1142d9137b25430d07fd" score = 75 quality = 90 @@ -18081,8 +18134,8 @@ rule REVERSINGLABS_Cert_Blocklist_4631713E66E91347F0388B98Cf747794 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12462-L12478" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12462-L12478" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cb517cda67150b7e17ee3bd946903e8e8eca81742a362032249a2f2387e71c50" score = 75 quality = 90 @@ -18106,8 +18159,8 @@ rule REVERSINGLABS_Cert_Blocklist_E963F8983D21B4C1A69C66A9D37498E5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12480-L12498" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12480-L12498" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b7c715e28f003351d10ba53657e9e667b635a0e4433276d91d26f4482a61191d" score = 75 quality = 90 @@ -18131,8 +18184,8 @@ rule REVERSINGLABS_Cert_Blocklist_6E44Fcedd49F22F7A28Cecc99104F61A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12500-L12516" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12500-L12516" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "caff0cbca45c0dffb673367585824783371f2f4e31a0c9629afb7de708098892" score = 75 quality = 90 @@ -18156,8 +18209,8 @@ rule REVERSINGLABS_Cert_Blocklist_35B49Ee870Aea532E6Ef0A4987105C8F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12518-L12534" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12518-L12534" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a9d8e9db453f40e32a0cb6412db8885db54053fdf3d7908b884361a493f97b1f" score = 75 quality = 90 @@ -18181,8 +18234,8 @@ rule REVERSINGLABS_Cert_Blocklist_063Dcd7D7B0Bc77Cac844C7213Be3989 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12536-L12552" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12536-L12552" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "091d00b0731f0a3d9917eee945249f001e4b5b1b603cad2fc21eed70ec86aa99" score = 75 quality = 90 @@ -18206,8 +18259,8 @@ rule REVERSINGLABS_Cert_Blocklist_6F8777Aa866142Ad7120E5E1C9321E37 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12554-L12570" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12554-L12570" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ca3ff0c7192ba90932d35d053712816555dea051ce15d29a7ccf4e37da989899" score = 75 quality = 90 @@ -18231,8 +18284,8 @@ rule REVERSINGLABS_Cert_Blocklist_4A7F07C5D4Ad2E23F9E8E03F0E229Dd4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12572-L12588" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12572-L12588" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6dc2bfac77117e294cacc772f7bfaea8b2e3caa26a0afd3729d517e91ca20ea5" score = 75 quality = 90 @@ -18256,8 +18309,8 @@ rule REVERSINGLABS_Cert_Blocklist_F5F9C8F8C33E4Ce84Dd48Fcb03Ccb075 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12590-L12608" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12590-L12608" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ac3bab3f5a93099f39b0862b419346d1eb3d0f75d86e121ba30626d496c46c57" score = 75 quality = 90 @@ -18281,8 +18334,8 @@ rule REVERSINGLABS_Cert_Blocklist_57Fc55239F21F139978609E323097132 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12610-L12626" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12610-L12626" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "030bb847e524e672ee382e0284ba3f027920f60c70bbd153d4b9cdd2669e6a99" score = 75 quality = 90 @@ -18306,8 +18359,8 @@ rule REVERSINGLABS_Cert_Blocklist_Eeefec4308Abe63323600E1608F5E6F2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12628-L12646" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12628-L12646" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "71ab4bd7e85155bfbc1612941c5f15c409629b116258c38b79bd808512df006a" score = 75 quality = 90 @@ -18331,8 +18384,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Ecd460Ce14Bd8Ef2926Da2Cd9A44176 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12648-L12664" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12648-L12664" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "58fa244c125415ef7a3cf0feb79add4db7c84f94c23e5d27e840fb17c18d67ef" score = 75 quality = 90 @@ -18356,8 +18409,8 @@ rule REVERSINGLABS_Cert_Blocklist_5E75E997F3D70Bb8C182D56B25B7D836 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12666-L12682" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12666-L12682" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a2c6a57759fb0717951f83a32c00deeae82cad772b6cb7f60fa96232b6b82560" score = 75 quality = 90 @@ -18381,8 +18434,8 @@ rule REVERSINGLABS_Cert_Blocklist_D5690D94F15315E143Db10Af35497Dc5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12684-L12702" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12684-L12702" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4ac17d0f0e4ef2bb5f6cda8e7cb07a641d49c83465a0a80c46ff6e0e752d1847" score = 75 quality = 90 @@ -18406,8 +18459,8 @@ rule REVERSINGLABS_Cert_Blocklist_8223C74185Add0927246F5E33Ebac467 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12704-L12722" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12704-L12722" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f700b4f7cdfda9f678c3a5259d4293640c50567ec277c5b3db69756534e2007f" score = 75 quality = 90 @@ -18431,8 +18484,8 @@ rule REVERSINGLABS_Cert_Blocklist_Dd9E9E1D7C573714E3F567C5380Ae6D0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12724-L12742" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12724-L12742" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7bbcdb989d53bafbb2bdb694be72d4f7305323c01e8f1eafcb7cd889df165ff6" score = 75 quality = 90 @@ -18456,8 +18509,8 @@ rule REVERSINGLABS_Cert_Blocklist_3D5E71 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12744-L12760" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12744-L12760" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "aa73ac6569e4bb0084d7b148b2186ec2737a691a133319b21b666aa16bca9f2d" score = 75 quality = 90 @@ -18481,8 +18534,8 @@ rule REVERSINGLABS_Cert_Blocklist_C33187Fe848A65E8484Ea492Cb2Cbb18 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12762-L12780" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12762-L12780" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b66d67b74d73a143cb5301b232abd5f0f84f058223d4494b924a25dffb49037a" score = 75 quality = 90 @@ -18506,8 +18559,8 @@ rule REVERSINGLABS_Cert_Blocklist_6Fc143Ba34Cabf1De7A4C7F8F4Cdad6D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12782-L12798" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12782-L12798" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ffe25e4478a2245d4e5b330bb9300fb6cb48afb0fe3bd72bd62a589eeee3fe89" score = 75 quality = 90 @@ -18531,8 +18584,8 @@ rule REVERSINGLABS_Cert_Blocklist_6Ac6268B2E431A2C1369346D175D0E30 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12800-L12816" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12800-L12816" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "27efaba9bd9cd116f640007c1e951bb77757efbe148b5f953e71d6621d7f16b2" score = 75 quality = 90 @@ -18556,8 +18609,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Fc4D9178B8Df2C19E269Ac6F43Dd708 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12818-L12834" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12818-L12834" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "41dfe37b464d337268a8bb0e23124df7b50ab966038e8ad33bda81a4d86040ca" score = 75 quality = 90 @@ -18581,8 +18634,8 @@ rule REVERSINGLABS_Cert_Blocklist_E01407871E2146C9Baab1Ae7Ab8Ab172 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12836-L12854" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12836-L12854" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1801e7f15bd5f916fc08d263a845d296d334ca9de1040008f619719c1b5c0a3b" score = 75 quality = 90 @@ -18606,8 +18659,8 @@ rule REVERSINGLABS_Cert_Blocklist_Effc6D19D6Fc85872E4E5B3Ccee6D301 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12856-L12874" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12856-L12874" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a746c4193f1264cb96eae0ea85c2c76b5caf3b72ca950f76af426b4d68d210b3" score = 75 quality = 90 @@ -18631,8 +18684,8 @@ rule REVERSINGLABS_Cert_Blocklist_2F4A25D52B16Eb4C9Dfe71Ebbd8121Bb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12876-L12892" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12876-L12892" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7b237ae0574afeafcc05f71512c09d3170edbee20e512a1b0af5b431923dc25c" score = 75 quality = 90 @@ -18656,8 +18709,8 @@ rule REVERSINGLABS_Cert_Blocklist_6889Aab6202Bcc5F11Caedf4D04F435B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12894-L12910" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12894-L12910" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b2261ed8001929be8f80f73cc0c5076138f4794c73cbffd63773da5fc44639a8" score = 75 quality = 90 @@ -18681,8 +18734,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Be63083Fbb1787B445Da97583721419 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12912-L12928" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12912-L12928" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f39f5a632544bc01c3b4c9e2f2dd33f7109c44375f54011a34181e10da79debc" score = 75 quality = 90 @@ -18706,8 +18759,8 @@ rule REVERSINGLABS_Cert_Blocklist_6E2D3449272B6B96B8B9F728E87580D5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12930-L12946" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12930-L12946" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0155a8c71bf8426bbb980798772b04c145df5b8c4b60ff1a610a1236a47547ef" score = 75 quality = 90 @@ -18731,8 +18784,8 @@ rule REVERSINGLABS_Cert_Blocklist_268C0D7028A154Ac3B6349C5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12948-L12964" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12948-L12964" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8311b36f008e31b7ac27b439fa46da4c90ab4be6c7c89426f8e1939963bc3d7d" score = 75 quality = 90 @@ -18756,8 +18809,8 @@ rule REVERSINGLABS_Cert_Blocklist_2Daa8D629Cc0410A9482E62A0F8Bf8Fc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12966-L12982" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12966-L12982" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cfb2631bc1832f65fb9d77c812bf2a1e05121e825254bd57ae8b21e7b10b2344" score = 75 quality = 90 @@ -18781,8 +18834,8 @@ rule REVERSINGLABS_Cert_Blocklist_9A727E200Ea76570 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L12984-L13002" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L12984-L13002" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "337dc486f2bdca1f7682887d5e5c0f82961850a8fd9c9a20b9a43a75334070d8" score = 75 quality = 90 @@ -18806,8 +18859,8 @@ rule REVERSINGLABS_Cert_Blocklist_0954A3C876Df9262Cde5817F9870F0C6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13004-L13020" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13004-L13020" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "164b064a9df31d4a122236dfee7b713417a44d47a7f304b2bf55686a7f038feb" score = 75 quality = 90 @@ -18831,8 +18884,8 @@ rule REVERSINGLABS_Cert_Blocklist_3C30930E53Bb026F9A5D7440155F7118 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13022-L13038" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13022-L13038" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "260a58669043d21ee0ffccbdee95c9d04ef338497685d42f1951660f658a164d" score = 75 quality = 90 @@ -18856,8 +18909,8 @@ rule REVERSINGLABS_Cert_Blocklist_432Eefc0D4Dc0326Eb277A518Cc4310A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13040-L13056" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13040-L13056" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d5a0b7f19f66f18b5ef1c548276b675ead74fed6be94310c303bfad6c85f18be" score = 75 quality = 90 @@ -18881,8 +18934,8 @@ rule REVERSINGLABS_Cert_Blocklist_470D6Ce21A6940320261F09E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13058-L13074" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13058-L13074" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cae1d381bf2018a0ce56feb245d01f2bfea55b67894264d32d78dbb41873c792" score = 75 quality = 90 @@ -18906,8 +18959,8 @@ rule REVERSINGLABS_Cert_Blocklist_7E6Bc7E5A49E2C28E6F5D042 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13076-L13092" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13076-L13092" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f378c490ff4f32fc095c822f75abac44a8d94327404cd97546c63e7441e07632" score = 75 quality = 90 @@ -18931,8 +18984,8 @@ rule REVERSINGLABS_Cert_Blocklist_4C5020899147C850196C4Ebf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13094-L13110" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13094-L13110" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "112e834a24c50d639f8607740faa609f1a36539058357544e5dbcddf841f3116" score = 75 quality = 90 @@ -18956,8 +19009,8 @@ rule REVERSINGLABS_Cert_Blocklist_4Efcf7Adc21F070E590D49Ddb8081397 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13112-L13128" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13112-L13128" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d60a5bbd50484d620ab60cfd40840abc541c2b7bc1005a9076b69ddd1b938652" score = 75 quality = 90 @@ -18981,8 +19034,8 @@ rule REVERSINGLABS_Cert_Blocklist_Cbd37C0A651913Ee25A6860D7D5Ccdf2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13130-L13148" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13130-L13148" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "77cc439aea6eaa5a835b6b1aa50904c1df0d5379228e424ab2d68a3cb654834c" score = 75 quality = 90 @@ -19006,8 +19059,8 @@ rule REVERSINGLABS_Cert_Blocklist_5Fe0Ad6B03C57Ab67A352159004Ca3Db : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13150-L13166" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13150-L13166" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6f2489421f2effa2089b744f7e137818935fe2339d9216a42686012c51da677b" score = 75 quality = 90 @@ -19031,8 +19084,8 @@ rule REVERSINGLABS_Cert_Blocklist_642Ad8E5Ef8B3Ac767F0D5C1A999Bdaa : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13168-L13184" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13168-L13184" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d42d40ca381b99b68a3384cecf585aab2acca66d4e13503d337b1605d587d0b5" score = 75 quality = 90 @@ -19056,8 +19109,8 @@ rule REVERSINGLABS_Cert_Blocklist_5333D3079D8Afda715703775E1389991 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13186-L13202" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13186-L13202" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "98bd9d35c4e196a11943826115ab495833f7ef1d95f9736cc24255d6dd4fd21c" score = 75 quality = 90 @@ -19081,8 +19134,8 @@ rule REVERSINGLABS_Cert_Blocklist_139A7Ee1F1A7735C151089755Df5D373 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13204-L13220" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13204-L13220" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "86072fef7d1488dc257c3ca8fbb99620ec06f8ecb671b4e20d09d0ce6cc8601d" score = 75 quality = 90 @@ -19106,8 +19159,8 @@ rule REVERSINGLABS_Cert_Blocklist_74Dbe83082E1B3Dfa29F9C24 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13222-L13238" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13222-L13238" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1fdf6471d0b869df1a8630108cdaf1cc97d33e91d4726073913cdc54c7cf0042" score = 75 quality = 90 @@ -19131,8 +19184,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A466553A6391Aafd181B400266C7B18 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13240-L13256" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13240-L13256" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cb21e5759887904d6a38cd1b363610ebc0bfd9a357050c602210468992815cbe" score = 75 quality = 90 @@ -19156,8 +19209,8 @@ rule REVERSINGLABS_Cert_Blocklist_0D3Dec8794Fa7228D1Ee40Eeb8187149 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13258-L13274" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13258-L13274" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "20084dc0b069d65755f859f5aef4be5599d1f066ba006199d3ce803b0d8f041e" score = 75 quality = 90 @@ -19181,8 +19234,8 @@ rule REVERSINGLABS_Cert_Blocklist_24Af70B5D17A63Ad053E5821 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13276-L13292" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13276-L13292" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d78f709067c83169484d9dd6e1dd8a88852362da028551d4e55e5703a22e04a7" score = 75 quality = 90 @@ -19206,8 +19259,8 @@ rule REVERSINGLABS_Cert_Blocklist_402E9Fcba61E5Eaf9C0C7B3Bfd6259D9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13294-L13310" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13294-L13310" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1bfc2610745a98ebcf0f77504815d9d1c448697fbe407d6c2e075219b401de50" score = 75 quality = 90 @@ -19231,8 +19284,8 @@ rule REVERSINGLABS_Cert_Blocklist_2C84F9136059E96134F8766670Eacd52 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13312-L13328" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13312-L13328" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d6778630dcc3e4fe2816e6dee1b823e616f53de8a924057495c7c252948a71b4" score = 75 quality = 90 @@ -19256,8 +19309,8 @@ rule REVERSINGLABS_Cert_Blocklist_6716A9C195987D5Cfe53A094779461E7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13330-L13346" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13330-L13346" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "648fd70432a791b3e589f5eda1b1510045b465623914a9762ff3dfb4a3e022f8" score = 75 quality = 90 @@ -19281,8 +19334,8 @@ rule REVERSINGLABS_Cert_Blocklist_876C00Bd665Df98B35554F67A5C1C32A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13348-L13366" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13348-L13366" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "90bde1313db78d4166e8c87e7e4111c576880922b1c983f3a842ea030d38a0da" score = 75 quality = 90 @@ -19306,8 +19359,8 @@ rule REVERSINGLABS_Cert_Blocklist_4B093Cb60D4B992266F550934A4Ac7D0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13368-L13384" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13368-L13384" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4b634bc706638d72f2d036d41cf092cac538e930d7d407eebc225b482fd64f51" score = 75 quality = 90 @@ -19331,8 +19384,8 @@ rule REVERSINGLABS_Cert_Blocklist_2050B54146B011Ed30F60F61 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13386-L13402" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13386-L13402" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "74749317fcefcdb698046a6f42c6c6e05cc1eab1370b3b1fd7d025f49de4a032" score = 75 quality = 90 @@ -19356,8 +19409,8 @@ rule REVERSINGLABS_Cert_Blocklist_73E2F34C9C2435F29Bbe0A3C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13404-L13420" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13404-L13420" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "503429e737e8bdad735cf88e2bb2877d1f52b2c38be101a7a129c02db608a347" score = 75 quality = 90 @@ -19381,8 +19434,8 @@ rule REVERSINGLABS_Cert_Blocklist_68C457D7495D2A8D0D7B9042836135C2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13422-L13438" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13422-L13438" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3eb63f75f258eec611fa4288302f0ce5e47149ca876265a4a4b65dc33313aaa6" score = 75 quality = 90 @@ -19406,8 +19459,8 @@ rule REVERSINGLABS_Cert_Blocklist_6B72Ca367D40Fbef16E73E6Eba6A9A59 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13440-L13456" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13440-L13456" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2b20c16dafcd891c36b28b36093cd3ad3a15f3795f0f2adda61fb0db2835d02d" score = 75 quality = 90 @@ -19431,8 +19484,8 @@ rule REVERSINGLABS_Cert_Blocklist_736B7663D322533413F36E3E7E55F920 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13458-L13474" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13458-L13474" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "44e86319106a4bf8edba6c1be2f90d68b3d1ef4591f0cc23921a0dc4da4a407b" score = 75 quality = 90 @@ -19456,8 +19509,8 @@ rule REVERSINGLABS_Cert_Blocklist_54A170102461Fdc967Acfafe4Bbbc7F0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13476-L13492" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13476-L13492" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ddae18d566fa2fd077f51d0afff74fb8a8e525f88f23908c7402a4b2c092ad24" score = 75 quality = 90 @@ -19481,8 +19534,8 @@ rule REVERSINGLABS_Cert_Blocklist_0C501B8B113209C96C8119Cf7A6B8B79 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13494-L13510" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13494-L13510" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "dca37fda83650979566fb6ffbedaf713955a3c7f03ecc62e2e155475b7ca00e4" score = 75 quality = 90 @@ -19506,8 +19559,8 @@ rule REVERSINGLABS_Cert_Blocklist_0300Ee4A4C52443147821A8186D04309 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13512-L13528" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13512-L13528" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8476ece98427c1ffd99d820c25fe664397de2c393473f7d5ee0846d8d840fd9e" score = 75 quality = 90 @@ -19531,8 +19584,8 @@ rule REVERSINGLABS_Cert_Blocklist_202Cf8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13530-L13546" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13530-L13546" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "671a4b522761fdff75d1c0c608e8cfb21c7ab538c8c30c8620315bc58ed358e6" score = 75 quality = 90 @@ -19556,8 +19609,8 @@ rule REVERSINGLABS_Cert_Blocklist_6651Cc8B4850D4Dec61961503Ea7956B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13548-L13564" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13548-L13564" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "29bfe9c8b340b55a9daa2644e8d55b2b783cc95c85541732e6e0decca8c10ff6" score = 75 quality = 90 @@ -19581,8 +19634,8 @@ rule REVERSINGLABS_Cert_Blocklist_25Bef28467E4750331D2F403458113B8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13566-L13582" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13566-L13582" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "dc59fdecf60f3781e92cfe8469be2e0c1cb1cfdd3e9f9757d159667437cb37f5" score = 75 quality = 90 @@ -19606,8 +19659,8 @@ rule REVERSINGLABS_Cert_Blocklist_0296Cf3314F434C5B74D0C3E36616Dd1 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13584-L13600" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13584-L13600" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "acf3b7460c79fa71c1b131b26a40bbc286c9da0a5fe7071bbe8b386a3ca91de4" score = 75 quality = 90 @@ -19631,8 +19684,8 @@ rule REVERSINGLABS_Cert_Blocklist_045D57D63E13775C8F812E1864797F5A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13602-L13618" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13602-L13618" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d3e61e9a43f5b17ebb08b71dc39648d1f20273a18214f39605f365f9f0f72c10" score = 75 quality = 90 @@ -19656,8 +19709,8 @@ rule REVERSINGLABS_Cert_Blocklist_6D633Df9Bb6015Fc3Ecea99Dff309Ee7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13620-L13636" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13620-L13636" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "84e2f427ee79b47db8d0e5f1e2217a7e1c1ea64047e01b4ea6db69f529501f36" score = 75 quality = 90 @@ -19681,8 +19734,8 @@ rule REVERSINGLABS_Cert_Blocklist_22E2A66E63B8Cb4Ec6989Bf7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13638-L13654" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13638-L13654" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2099c508d1fd986f34f14aa396a5aaa136e2cdd2226099acdca9c14f6f6342eb" score = 75 quality = 90 @@ -19706,8 +19759,8 @@ rule REVERSINGLABS_Cert_Blocklist_654B406De388Ec2Aec253Ff2Ba4C4Bbd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13656-L13672" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13656-L13672" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a1aadaded55c8b0d85ac09ba9ab27fefaeec2969cdabaf26ff0c41bf33422ddc" score = 75 quality = 90 @@ -19731,8 +19784,8 @@ rule REVERSINGLABS_Cert_Blocklist_78D1817Ebcf338B4E9C810F9740A726B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13674-L13690" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13674-L13690" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "62e59130ef0ac35b17a265bb8bc2031cac6a75c11925ccb21eb4601b8fbe1a63" score = 75 quality = 90 @@ -19756,8 +19809,8 @@ rule REVERSINGLABS_Cert_Blocklist_45Fbcdb1Fbd3D702Fb77257B45D8C58E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13692-L13708" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13692-L13708" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "441e10f49515d75ee9e8983ba4321377fee13a91ca5eeddc08b393136ce8ccfd" score = 75 quality = 90 @@ -19781,8 +19834,8 @@ rule REVERSINGLABS_Cert_Blocklist_4B5D8Ed5Ca011679F141F124 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13710-L13726" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13710-L13726" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "39ff0d5fd711524ce181596033d1d51579cd086eb20b87722aebf39623bbaa17" score = 75 quality = 90 @@ -19806,8 +19859,8 @@ rule REVERSINGLABS_Cert_Blocklist_33671F1Bcbd0F5E231Fc386F4895000E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13728-L13744" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13728-L13744" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9199c8d76e3390ec9038808b4e88b803b3f3d6966af6206d0c9968d9ab673f31" score = 75 quality = 90 @@ -19831,8 +19884,8 @@ rule REVERSINGLABS_Cert_Blocklist_32Bc299F0694C19Ec21E71265B1D7E17 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13746-L13762" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13746-L13762" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cb522e3084d382c451a8b040095e75582675f90dbb588e370f2f0054f4c2d14b" score = 75 quality = 90 @@ -19856,8 +19909,8 @@ rule REVERSINGLABS_Cert_Blocklist_7B75C6B0A09Afdb9787F6Dff75Ae7844 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13764-L13780" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13764-L13780" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8fd125a526b3433fbb8a5c6fa74ce0b0e2de8ff789880c355625d4140cd902a2" score = 75 quality = 90 @@ -19881,8 +19934,8 @@ rule REVERSINGLABS_Cert_Blocklist_167Fd1295B3Bb102Dbb37292C838E7Cd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13782-L13798" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13782-L13798" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1cc7d441291fd9c4dc37320d411f94fb362523d47d37ab35c20b3ac9d4cd75cb" score = 75 quality = 90 @@ -19906,8 +19959,8 @@ rule REVERSINGLABS_Cert_Blocklist_253Ad25E39Abe8F8Fda9Fcf6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13800-L13816" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13800-L13816" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1d46ccaa136cd7be30ffbf0eb09eb6485c543ff4bdbe99fa7ea3846841cbd41b" score = 75 quality = 90 @@ -19931,8 +19984,8 @@ rule REVERSINGLABS_Cert_Blocklist_A9C1523Cb2C73A82771D318124963E87 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13818-L13836" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13818-L13836" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "87e314d14361f56935b7a8fb93468cfaf2c73e16c25d68a61ec80ad9334d3115" score = 75 quality = 90 @@ -19956,8 +20009,8 @@ rule REVERSINGLABS_Cert_Blocklist_68E1B2C210B19Bb1F2A24176709B165B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13838-L13854" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13838-L13854" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8e88ad992c58d37ff1ac34e2d9cf121f3bc692ae78c0ad79140974abdec2f317" score = 75 quality = 90 @@ -19981,8 +20034,8 @@ rule REVERSINGLABS_Cert_Blocklist_5C88313Bd98Bde99C9B9Ac1408A63249 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13856-L13872" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13856-L13872" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f958e46e00bf4ab8ecf071502bcda63a84265029bc9c72cea1eaaf72e9003a84" score = 75 quality = 90 @@ -20006,8 +20059,8 @@ rule REVERSINGLABS_Cert_Blocklist_7A632A6Ecfc6C49Ec1F42F76 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13874-L13890" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13874-L13890" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "038badeab61c00476b79684308bf91f8a63716641f2be16fe0a3b25ebd3a9a1e" score = 75 quality = 90 @@ -20031,8 +20084,8 @@ rule REVERSINGLABS_Cert_Blocklist_F57Df6A6Eee3854D513D0Ba8585049B7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13892-L13910" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13892-L13910" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "09d5998960fb65eda56cd698c5ff50d87ba7a811cbb128bc7485c0f124e14cba" score = 75 quality = 90 @@ -20056,8 +20109,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Ac5Ac5D323122E6D8E92D6E191B1432 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13912-L13928" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13912-L13928" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d5e62d3cdfacfaea70f9ee11230501bb9c4099508077d50a2a143cb69476f02a" score = 75 quality = 90 @@ -20081,8 +20134,8 @@ rule REVERSINGLABS_Cert_Blocklist_2433D9Df7Efbccb870Ee5904D62A0101 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13930-L13946" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13930-L13946" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "92a2effe1b94345f52130e4cb1db181f1990e58eaefb9c74375c14249cc1be22" score = 75 quality = 90 @@ -20106,8 +20159,8 @@ rule REVERSINGLABS_Cert_Blocklist_462Baada57570F70Df76D10B9E7Bf2B7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13948-L13964" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13948-L13964" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c48207907339ce3fb7b6bc630097761a24495a9d4e69d421f2bdb36ddc92abcb" score = 75 quality = 90 @@ -20131,8 +20184,8 @@ rule REVERSINGLABS_Cert_Blocklist_83320D93Dd8Cf16D11F99B1078B0A7Cb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13966-L13984" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13966-L13984" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "94ec5e05357767cc0c4cd1fc8ff6d1a366359ba699c43f3710204d761e7e707f" score = 75 quality = 90 @@ -20156,8 +20209,8 @@ rule REVERSINGLABS_Cert_Blocklist_10Bae1D20Cb4Cc36A0Ffac86 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L13986-L14002" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L13986-L14002" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "44e91fbf4da8e81859a21408ee9f1971f1e8f48d22553fcaa6469156d4a0670b" score = 75 quality = 90 @@ -20181,8 +20234,8 @@ rule REVERSINGLABS_Cert_Blocklist_230716Bfe915Dd6203B2E2A35674C2Ee : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14004-L14020" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14004-L14020" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0197ff46ceb1017488da4383436fd0ddc375904f36cc16c5a8ef21d633ec387c" score = 75 quality = 90 @@ -20206,8 +20259,8 @@ rule REVERSINGLABS_Cert_Blocklist_36A77D37E68E02Fd3D043C7197E044Ca : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14022-L14038" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14022-L14038" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fc13ac5880cc2c8eac9ff8d09f6c5c2055b2de54d460a284936a4f6cd78192e8" score = 75 quality = 90 @@ -20231,8 +20284,8 @@ rule REVERSINGLABS_Cert_Blocklist_73Bff2Fb714F986C1707165F0B0F2E0E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14040-L14056" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14040-L14056" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d79ab926cbc0049d39f5f4c6e57afc71b1a30311a4816fdb66a9c2e257cc84af" score = 75 quality = 90 @@ -20256,8 +20309,8 @@ rule REVERSINGLABS_Cert_Blocklist_33B24170694Ca0Cf4D2Bdf4Aadf475A3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14058-L14074" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14058-L14074" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "795bcb46b41ded084e4d12d98e335748ec1db3e0abbbb2d933e819d955075138" score = 75 quality = 90 @@ -20281,8 +20334,8 @@ rule REVERSINGLABS_Cert_Blocklist_3A9Bdec10E00E780316Baaebfe7A772C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14076-L14092" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14076-L14092" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ea9bc11efd2969f6b7112338f2b084ea3551e072e46b1162bd47b08be549cdd4" score = 75 quality = 90 @@ -20306,8 +20359,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Cad9C37F7Affa8F4D8229F97607E265 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14094-L14110" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14094-L14110" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0f88989c64bece23e7eccf8022e038fdd9c360766de71268cf71616f74adc56c" score = 75 quality = 90 @@ -20331,8 +20384,8 @@ rule REVERSINGLABS_Cert_Blocklist_098A57 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14112-L14128" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14112-L14128" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5e203f87dd4608ba5d583e02ce86fbe230e45fff86a7a697766e149d0cf6f436" score = 75 quality = 90 @@ -20356,8 +20409,8 @@ rule REVERSINGLABS_Cert_Blocklist_5389Cc6286Da3Bfa1Dc4Df498Bf68361 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14130-L14146" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14130-L14146" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d25d998c980f47f4da065155451503dcbc677ad041af85a6ed7060ecadec66b3" score = 75 quality = 90 @@ -20381,8 +20434,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ed9Caeb7911B31Bd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14148-L14166" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14148-L14166" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "02cfdf883212387a465af3e692b29b8d0eb8249e0a260f18bec2f662d775b606" score = 75 quality = 90 @@ -20406,8 +20459,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Fd2B19A941B7009Cc728A37Cb1B10B9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14168-L14184" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14168-L14184" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6b5cc47f4df9e57c59bc66c32188e02390d4855a1b9e56bd7471fd641a245c3c" score = 75 quality = 90 @@ -20431,8 +20484,8 @@ rule REVERSINGLABS_Cert_Blocklist_2D88C0Af1Fe2609961C171213C03Bd23 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14186-L14202" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14186-L14202" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2d181b9b517732f14d196c1a6c5661d8de4dbbfe6f120954dd3f9dcad00ff0fe" score = 75 quality = 90 @@ -20456,8 +20509,8 @@ rule REVERSINGLABS_Cert_Blocklist_6E7Cc176062D91225Cfdcbdf5B5F0Ea5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14204-L14220" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14204-L14220" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1d2ffa7ec3559061432c2aff23f568cb580fb9093d0af7d8a6a0b91add89c9cc" score = 75 quality = 90 @@ -20481,8 +20534,8 @@ rule REVERSINGLABS_Cert_Blocklist_Cecedd2Efc985C2Dbf0019669D270079 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14222-L14240" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14222-L14240" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1dfb5959db6929643126a850de84e54a84d7197518cde475c802987721b71020" score = 75 quality = 90 @@ -20506,8 +20559,8 @@ rule REVERSINGLABS_Cert_Blocklist_61Fe6F00Bd79684210534050Ff46Bc92 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14242-L14258" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14242-L14258" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e8ebc5de081e2d1e653493a2d85699ebfb5227b7fab656468025c2043903f597" score = 75 quality = 90 @@ -20531,8 +20584,8 @@ rule REVERSINGLABS_Cert_Blocklist_0323Cc4E38735B0E6Efba76Ea25C73B7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14260-L14276" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14260-L14276" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "48bda7f61c9705ae70add3940f10d65fc7f7a776cec91a244f0e5bde07303831" score = 75 quality = 90 @@ -20556,8 +20609,8 @@ rule REVERSINGLABS_Cert_Blocklist_1F9Aca069Ac1B6Bfb0E14861Ec857Bf6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14278-L14294" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14278-L14294" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d7c9a471455768a00deeb73900bf80a98f0b2c9da1fd09d568e2998deaf404d2" score = 75 quality = 90 @@ -20581,8 +20634,8 @@ rule REVERSINGLABS_Cert_Blocklist_3E9D26Dcf703Ca3B140D7E7Ad48312E2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14296-L14312" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14296-L14312" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d8f70ba61509f3df34705bea0bfcb4cce3e92a33f0f1b65315d886eb5592f152" score = 75 quality = 90 @@ -20606,8 +20659,8 @@ rule REVERSINGLABS_Cert_Blocklist_4E2523E76Ea455941E75Fb8240474A75 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14314-L14330" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14314-L14330" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e89f722345fda82fd894d34169d1463997ae1d567d46badbf3138faa04cf8fa4" score = 75 quality = 90 @@ -20631,8 +20684,8 @@ rule REVERSINGLABS_Cert_Blocklist_6102468293Ba7308D17Efb43Ad6Bfb58 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14332-L14348" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14332-L14348" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c1ae1562595ac6515a071a16195b46db6fad4ee0fe9757d366ee78b914e1de7f" score = 75 quality = 90 @@ -20656,8 +20709,8 @@ rule REVERSINGLABS_Cert_Blocklist_6Ded1A7Ff6Da152A98A57A2F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14350-L14366" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14350-L14366" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "20ec1e8e0570eb216304fd8453df315a26d9c170224177c325c10cbefc1993fb" score = 75 quality = 90 @@ -20681,8 +20734,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Ce65Ea057B975D2C17Eaf2C2297B1Eb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14368-L14384" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14368-L14384" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e17988cb2503e285cfe2ea74d7bc61c577d828e14fd5d8d8062e469dc75c449e" score = 75 quality = 90 @@ -20706,8 +20759,8 @@ rule REVERSINGLABS_Cert_Blocklist_5D085A9A288549D09Edc4941 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14386-L14402" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14386-L14402" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "dff7c2d727acca753b030d05028590e1a5577121bb2b4c0dcfcb70b4c9d77cbf" score = 75 quality = 90 @@ -20731,8 +20784,8 @@ rule REVERSINGLABS_Cert_Blocklist_7D20Dec3797A1Ac30649Ebb184265B79 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14404-L14420" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14404-L14420" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "78c0575a1c9ecf37ef5bac0612c20f96b8641875b0ba786979adc8a77f001a5e" score = 75 quality = 90 @@ -20756,8 +20809,8 @@ rule REVERSINGLABS_Cert_Blocklist_187D92861076E469B5B7A19E2A9Fd4Ba : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14422-L14438" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14422-L14438" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7383a7fb31a0a913dff1740015ff702642fbb41d8e5a528a8684c80e66026e9d" score = 75 quality = 90 @@ -20781,8 +20834,8 @@ rule REVERSINGLABS_Cert_Blocklist_199A9476Feca3C004Ff889D34545De07 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14440-L14456" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14440-L14456" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "39c6efefcbd78d5e08ffd8d3989cab3bdf273a1847b2a961f9e68c9ee95e85b6" score = 75 quality = 90 @@ -20806,8 +20859,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Efe65 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14458-L14474" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14458-L14474" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f849b6899b6766807cfddf99ecb809fe923f35f04de09b62235da352ce6e6e24" score = 75 quality = 90 @@ -20831,8 +20884,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Af7E2B6A3Deb99291Dcaf66 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14476-L14492" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14476-L14492" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "270b5655a0f54abceb520eaca714ed4f6d4de720883e2759acd5bb2f027dfd2b" score = 75 quality = 90 @@ -20856,8 +20909,8 @@ rule REVERSINGLABS_Cert_Blocklist_45E27C4Dfa5E6175566A13B1B6Ddf3F5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14494-L14510" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14494-L14510" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9bcbb84207984b259463482f094bf0f3815f0d74317b6b864dab44769ff5e7e8" score = 75 quality = 90 @@ -20881,8 +20934,8 @@ rule REVERSINGLABS_Cert_Blocklist_37D36A4E61C0Ac68Ceb8Bfcef2Dbf283 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14512-L14528" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14512-L14528" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "41e126600aae5646b808ed0a4294faa9a63e47842e9cde4fee9e5e65919af7ee" score = 75 quality = 90 @@ -20906,8 +20959,8 @@ rule REVERSINGLABS_Cert_Blocklist_4321De10738278B93683Ca542407F103 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14530-L14546" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14530-L14546" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2787375605310877891ef924268f4660d1c8aa020e00674c1b1d7eb3c4f5b2fb" score = 75 quality = 90 @@ -20931,8 +20984,8 @@ rule REVERSINGLABS_Cert_Blocklist_2A6B2Df210Be14F4E18E10C7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14548-L14564" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14548-L14564" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "24ae1664c35b7947e2e638bf620d9ab572c70df9cdc1403cc00b422a45ff9194" score = 75 quality = 90 @@ -20956,8 +21009,8 @@ rule REVERSINGLABS_Cert_Blocklist_412Ab2A50E8028Ddcbc499Ddf45F2045 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14566-L14582" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14566-L14582" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a5b85d13dee51d68af28394ecee3dcc2efe7add4d26c2a8033d1855b33ac6271" score = 75 quality = 90 @@ -20981,8 +21034,8 @@ rule REVERSINGLABS_Cert_Blocklist_0747F6A8C3542F954B113Fd98C7607Cf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14584-L14600" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14584-L14600" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9d5e5c98f3ef372532cfc4f544d5d3f620dc2e49d8b6e1c96df29d2a38042019" score = 75 quality = 90 @@ -21006,8 +21059,8 @@ rule REVERSINGLABS_Cert_Blocklist_2572B484Fa0A61Be7288D785D7Bda7D3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14602-L14618" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14602-L14618" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d6b23ba706a640a1e76ad7ab0a70c845c9366ac8355eea5439f76f6993c9c6be" score = 75 quality = 90 @@ -21031,8 +21084,8 @@ rule REVERSINGLABS_Cert_Blocklist_6726Bd04204746C46857887F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14620-L14636" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14620-L14636" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "11d25dff7e05e6f97725e919cc6c978d7f2e64a91cf04b72461c71d592dfc2dc" score = 75 quality = 90 @@ -21056,8 +21109,8 @@ rule REVERSINGLABS_Cert_Blocklist_4463D8B31E0F87C14233D4D0D2C487A0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14638-L14654" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14638-L14654" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "04ce664fceb4a617294e860d5364d8a4ce8e055fd2baebb8be69f258d9c70ac7" score = 75 quality = 90 @@ -21081,8 +21134,8 @@ rule REVERSINGLABS_Cert_Blocklist_387982605E542D6D52F231Ca6F5657Cc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14656-L14672" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14656-L14672" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d55cfd45bc0d330c0ed433a882874e4633ffbaa0d68288bea9058fe269d75ed9" score = 75 quality = 90 @@ -21106,8 +21159,8 @@ rule REVERSINGLABS_Cert_Blocklist_E0134C41E7Eda6863C4Eee5B003976Dd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14674-L14692" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14674-L14692" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fbe34baf52e3fa7d7cdfcfaef9b8851c4cbeb46d17eeade61750e59cf0c13291" score = 75 quality = 90 @@ -21131,8 +21184,8 @@ rule REVERSINGLABS_Cert_Blocklist_5B47A4739Dd8Ffe81D9B5307 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14694-L14710" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14694-L14710" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5f35f520d4af26fa648553894a5b0db043d0c32302d94f531b6cb48691396a92" score = 75 quality = 90 @@ -21156,8 +21209,8 @@ rule REVERSINGLABS_Cert_Blocklist_4F5A9Bf75Da76B949645475473793A7D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14712-L14728" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14712-L14728" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8c58d30b1b6ef80409d9da5f5f4bc26a8818b01cc388b5966c8b68ed0e4c5a2a" score = 75 quality = 90 @@ -21181,8 +21234,8 @@ rule REVERSINGLABS_Cert_Blocklist_081Df56C9A48D02571F08907 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14730-L14746" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14730-L14746" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "25d91f09e0731ab09a05855442b72589eb30e1c7d5e4c0a7af760eea540d786f" score = 75 quality = 90 @@ -21206,8 +21259,8 @@ rule REVERSINGLABS_Cert_Blocklist_77D5C1A3E623575999C74409Dc19753C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14748-L14764" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14748-L14764" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "54921ce39a0876511b33ac6fa088c3342e2ea7fa037423fe72825bfe9c83bce6" score = 75 quality = 90 @@ -21231,8 +21284,8 @@ rule REVERSINGLABS_Cert_Blocklist_E9756B3F38B1172Ea89Fdbdfdba5F979 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14766-L14784" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14766-L14784" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "997a9433f907896d82f22ae323bf9cfe9aa04a2a49c5505e98adbb34277fcc15" score = 75 quality = 90 @@ -21256,8 +21309,8 @@ rule REVERSINGLABS_Cert_Blocklist_09Fb28 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14786-L14802" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14786-L14802" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5ed65d33b73977e869460ba51271aff94811fa2f41e4a2993c47233add2f38dd" score = 75 quality = 90 @@ -21281,8 +21334,8 @@ rule REVERSINGLABS_Cert_Blocklist_197Dc32D915458953562D2Fe78Bf2468 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14804-L14820" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14804-L14820" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e61284a74765592fe97b90ca1c260efa46ea31286e6d09ab32d6c664b8271f2a" score = 75 quality = 90 @@ -21306,8 +21359,8 @@ rule REVERSINGLABS_Cert_Blocklist_7C0Be3D14787351E3156F5F37F2B3663 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14822-L14838" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14822-L14838" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "66c2cd84fccedd2afef00495c49d0c2844e2e5e190e6a859d2970e8ddb4a35c2" score = 75 quality = 90 @@ -21331,8 +21384,8 @@ rule REVERSINGLABS_Cert_Blocklist_05054Fdea356F3Dd7Db479Fa : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14840-L14856" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14840-L14856" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "02ec52e060a6b8b3edfad0a1f5b1f2d6c409645d5233612d0d353ad74bcd4568" score = 75 quality = 90 @@ -21356,8 +21409,8 @@ rule REVERSINGLABS_Cert_Blocklist_08Aaa069E92517F21Ce67Ca713F6Ea63 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14858-L14874" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14858-L14874" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "28ad7e9c75a701425003cde4a7eb10fa471394628cd5004412778d8d7cddb50b" score = 75 quality = 90 @@ -21381,8 +21434,8 @@ rule REVERSINGLABS_Cert_Blocklist_1B7B54E0Dd4D7E45A0B46834De52658D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14876-L14892" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14876-L14892" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5febbce8c39440bfc4846f509f0b1dd4f71a8b4dc24fa18afb561d26e53c2446" score = 75 quality = 90 @@ -21406,8 +21459,8 @@ rule REVERSINGLABS_Cert_Blocklist_B63E4299D0B0E2Dcdaeb976167A23235 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14894-L14912" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14894-L14912" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "da7415d0bc0245dea6a4ec325da5140c79c723c20fb7c04ff14f59a3089a5c88" score = 75 quality = 90 @@ -21431,8 +21484,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Dabae616705F5A51152Eac48423F354 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14914-L14930" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14914-L14930" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0bb14ececa3a78e1a2e71cfdee8bc57678251b15151d156ef5fa754b2438ee35" score = 75 quality = 90 @@ -21456,8 +21509,8 @@ rule REVERSINGLABS_Cert_Blocklist_50D08F3C9Bf86Fba52Cf592B4Fe6Eacf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14932-L14948" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14932-L14948" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ca613e4b45b9bb1ef7564b9fc6321bccc0f683298de692a3db2bf841db9010ef" score = 75 quality = 90 @@ -21481,8 +21534,8 @@ rule REVERSINGLABS_Cert_Blocklist_7C7Fc3616F3157A28F702Cc1Df275Dcd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14950-L14966" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14950-L14966" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c2dcea21c7a3e3aef6408f11c23edbce6d8f655f298654552a607a9b0caabb28" score = 75 quality = 90 @@ -21506,8 +21559,8 @@ rule REVERSINGLABS_Cert_Blocklist_73Ed1B2F4Bf8Dd37A8Ad9Bb775774592 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14968-L14984" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14968-L14984" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "69865935e07ea255a5d690e170911b33574ea61550b00bebc2ceff91ba9a33da" score = 75 quality = 90 @@ -21531,8 +21584,8 @@ rule REVERSINGLABS_Cert_Blocklist_211B5Dfe65Bc6F34Bc9D3A54 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L14986-L15002" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L14986-L15002" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cf2e4c0dd98efb77c28b63641196c83e60afc0d6ab64802743c351581506dbb5" score = 75 quality = 90 @@ -21556,8 +21609,8 @@ rule REVERSINGLABS_Cert_Blocklist_5400D1C1406528B1Ef625976 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15004-L15020" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15004-L15020" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fbdd37e050d68c4287e897f050a673aea071df105a35b07475d3233da3f03feb" score = 75 quality = 90 @@ -21581,8 +21634,8 @@ rule REVERSINGLABS_Cert_Blocklist_013472D7D665557Bfa0Dc21B350A361B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15022-L15038" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15022-L15038" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ab908ef0fca56753bcba8bc85e2fdf5859b4e226c179ec5c6eb6eb3dc4014a8e" score = 75 quality = 90 @@ -21606,8 +21659,8 @@ rule REVERSINGLABS_Cert_Blocklist_66C758A22Bfbbce327616815616Ddd07 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15040-L15056" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15040-L15056" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "37f0f64e2d84ef6591e1f07a05abca35b37827d26c828269fb5f38d8546a60a7" score = 75 quality = 90 @@ -21631,8 +21684,8 @@ rule REVERSINGLABS_Cert_Blocklist_E61B0366D940896430Bcfe3E93Baac5B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15058-L15076" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15058-L15076" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1b1fd0c2237446ab22c7359d1e89d822a4b9b6ad345447740154d7d52635c2ea" score = 75 quality = 90 @@ -21656,8 +21709,8 @@ rule REVERSINGLABS_Cert_Blocklist_6294B8Acc35Dea7D32A95Ac5D4536F8F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15078-L15094" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15078-L15094" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ac92ff8e533121071a620ca5280ae66629576f9c4af9831ddac5bb487e4348af" score = 75 quality = 90 @@ -21681,8 +21734,8 @@ rule REVERSINGLABS_Cert_Blocklist_485E4626C32493C16283Cfd9E30D17Ad : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15096-L15112" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15096-L15112" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "faf860786e8473493d24abf6e61cf0b906e98d786516be6d2098181368214020" score = 75 quality = 90 @@ -21706,8 +21759,8 @@ rule REVERSINGLABS_Cert_Blocklist_D0312F9177Cd46B943Df3Ef22Db4608B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15114-L15132" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15114-L15132" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2eb955e91c927980cee031c6284e48bad315e891c32cdaf41b844090e841c44d" score = 75 quality = 90 @@ -21731,8 +21784,8 @@ rule REVERSINGLABS_Cert_Blocklist_202702 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15134-L15150" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15134-L15150" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bc097e97c1c4c4a71cbf66be811636fecfa23682cb2cc47ab1fcd680a646fb14" score = 75 quality = 90 @@ -21756,8 +21809,8 @@ rule REVERSINGLABS_Cert_Blocklist_369A02E5D90B2649040E7F87 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15152-L15168" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15152-L15168" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e2a2e231914f166410580a42ca9d4aac18c5cba94d1f11d22e7acd6d375851d8" score = 75 quality = 90 @@ -21781,8 +21834,8 @@ rule REVERSINGLABS_Cert_Blocklist_60497070Ff4A83Bc87Bdea24Da5B431D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15170-L15186" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15170-L15186" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "30998e3f5299a37cdee83b1232249b84dbb3c154ef99237da5ce1b16f9db5da3" score = 75 quality = 90 @@ -21806,8 +21859,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A333E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15188-L15204" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15188-L15204" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f76d21e0ae2cf9b28825c813fc509d533c10aba38f8f0c2884365047c1272c1f" score = 75 quality = 90 @@ -21831,8 +21884,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Cb6519B2528D006D1Da987153Dad2B3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15206-L15222" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15206-L15222" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "776402fc3a7de4843373bc1981f965fe9c2a9f1fe2374b142a96952fd05a591b" score = 75 quality = 90 @@ -21856,8 +21909,8 @@ rule REVERSINGLABS_Cert_Blocklist_621E696C3A6371E77A678Cbf0Ee34Ab2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15224-L15240" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15224-L15240" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "67c9fd92681d6dd1172509113e167e74e07f1f86fd62456758b3e3930180b528" score = 75 quality = 90 @@ -21881,8 +21934,8 @@ rule REVERSINGLABS_Cert_Blocklist_21B991 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15242-L15258" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15242-L15258" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "54ca9b19adfc9357a3fb74f0670ad929319c4d06a7de7ae400f8285a31052276" score = 75 quality = 90 @@ -21906,8 +21959,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Cc37De5Dbed097F98F56Dbc : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15260-L15276" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15260-L15276" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a2d04275b9fe37308c8f1dca75f4cc3c4a8985930f901e1f46e3ddc2977eea32" score = 75 quality = 90 @@ -21931,8 +21984,8 @@ rule REVERSINGLABS_Cert_Blocklist_50F66Ab0D7Ed19B69D48F635E69572Fa : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15278-L15294" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15278-L15294" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "28f71c0572e769d4a0cb289071912bc79cddfd98a3a8161c5400c7bee7090bf5" score = 75 quality = 90 @@ -21956,8 +22009,8 @@ rule REVERSINGLABS_Cert_Blocklist_11212F502836A784752160351Defb136Cf09 : INFO FI date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15296-L15312" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15296-L15312" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "63d4c1aaafdf6de14d0ae78035644cf6b0fefab8b0063d2566ca38af9f9498d2" score = 75 quality = 90 @@ -21981,8 +22034,8 @@ rule REVERSINGLABS_Cert_Blocklist_2C16Be9A7Ce2A23Ab7A4B4Eb7Da3400C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15314-L15330" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15314-L15330" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "917f324cbe91718efc9b2f41ef947fa8f1a501dde319936774d702d57b1e6b37" score = 75 quality = 90 @@ -22006,8 +22059,8 @@ rule REVERSINGLABS_Cert_Blocklist_22Accad235Fb1Ac7422Ebe5Ea7Ac9Bc5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15332-L15348" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15332-L15348" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b348c502aeae036f6d17283260ed4479427f89c8c25f2b6d59e137e90694dbe4" score = 75 quality = 90 @@ -22031,8 +22084,8 @@ rule REVERSINGLABS_Cert_Blocklist_4D29757C4Fbfc32B97091D96E3723002 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15350-L15366" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15350-L15366" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "78ede4b02cb1b07500cd0c4f1f33da598938940d0f58430edda00d79b19b16a5" score = 75 quality = 90 @@ -22056,8 +22109,8 @@ rule REVERSINGLABS_Cert_Blocklist_3A949Ef03D9Dd2D150B24B274Ff6D7B4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15368-L15384" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15368-L15384" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "88c63a921a300e1b985d084c3ab1a2485713b4c674dafd419d092e5562f121d7" score = 75 quality = 90 @@ -22081,8 +22134,8 @@ rule REVERSINGLABS_Cert_Blocklist_954D0577D5Ce8999E0387A5364829F66 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15386-L15404" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15386-L15404" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "84ddc08a0a55200f644778a0e3482f15e82d74c524f12a7ad91b1c3d4acfc731" score = 75 quality = 90 @@ -22106,8 +22159,8 @@ rule REVERSINGLABS_Cert_Blocklist_Df5121Dc99D1Ab6B7E5229F6832123Ef : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15406-L15424" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15406-L15424" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3b5e5b81890f1dea3dc0858cade54e7f88a21861818be79c3e7fba066f80d491" score = 75 quality = 90 @@ -22131,8 +22184,8 @@ rule REVERSINGLABS_Cert_Blocklist_760Cef386B63406751Ae83A9Eae92342 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15426-L15442" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15426-L15442" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "43b56736afe081a1215db67b933413d7fbafbfc1be8213b330668578921ebca7" score = 75 quality = 90 @@ -22156,8 +22209,8 @@ rule REVERSINGLABS_Cert_Blocklist_5C2625Fa836A64F4882C56Cc7A45F0Ed : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15444-L15460" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15444-L15460" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "85e187684d62c33ef6f69323b837ef2d44facab8278b512d7bd6afd49eaed976" score = 75 quality = 90 @@ -22181,8 +22234,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Df6Fa580F84493C414Ee0E431086737 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15462-L15478" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15462-L15478" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ef244587c9eb1e1cb2f8a9c161e5dd9ff70e9764586f16e011334400ee400ed9" score = 75 quality = 90 @@ -22206,8 +22259,8 @@ rule REVERSINGLABS_Cert_Blocklist_309D2E115F1Fe2993Ee2E063 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15480-L15496" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15480-L15496" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "15fdb95fe5429cdc0263615c2b7c90d21f37b52954c5ce568c1293cd3a544730" score = 75 quality = 90 @@ -22231,8 +22284,8 @@ rule REVERSINGLABS_Cert_Blocklist_90E33C1068F54913315B6Ce9311141B9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15498-L15516" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15498-L15516" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4a97171c6dfaa8d249ab0be1ce264b596d266ff4697d869a4d1f90cc0e2c49b7" score = 75 quality = 90 @@ -22256,8 +22309,8 @@ rule REVERSINGLABS_Cert_Blocklist_3F15C3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15518-L15534" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15518-L15534" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "03ea946fa99ed7a6ab23cb26dbf514b6c062d63371c9e2a5ddf999acd1954955" score = 75 quality = 90 @@ -22281,8 +22334,8 @@ rule REVERSINGLABS_Cert_Blocklist_285Eccbd1D0000E640B84307Ef88Cd9F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15536-L15552" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15536-L15552" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "267df1c327b65938b2b82a53ec8345290659560c69c9a70f2866fe7bd73513a7" score = 75 quality = 90 @@ -22306,8 +22359,8 @@ rule REVERSINGLABS_Cert_Blocklist_55Ab71A3F9Dde3Ef20C788Dd1D5Ff6C3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15554-L15570" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15554-L15570" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4bee740eaf359462cd85c6232160c6b1fc3df67acfe731da9978f0b8a304a93f" score = 75 quality = 90 @@ -22331,8 +22384,8 @@ rule REVERSINGLABS_Cert_Blocklist_4Beca26210737A5442Ff8B47 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15572-L15588" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15572-L15588" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7a1130413ae8807dc1ec96a6b1c3bac705a1520f7268db2848b997f6f3f9fc9b" score = 75 quality = 90 @@ -22356,8 +22409,8 @@ rule REVERSINGLABS_Cert_Blocklist_0F203839A9C63B8798A7Cb31 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15590-L15606" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15590-L15606" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "604ba3fa671cc98e42caf80d07bc9650d193f898413517b46482f183b0f7008a" score = 75 quality = 90 @@ -22381,8 +22434,8 @@ rule REVERSINGLABS_Cert_Blocklist_Dc992Ea8E6Bb4926931Df656D5Eef8A0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15608-L15626" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15608-L15626" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2b261624677a1c4a1ef539106bedcef30f272fda3d833d4c8095e9797d592e1f" score = 75 quality = 90 @@ -22406,8 +22459,8 @@ rule REVERSINGLABS_Cert_Blocklist_41Bd49Bb456644D8183B3Dae72Ec8F22 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15628-L15644" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15628-L15644" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0516af7b27d244f21c9cea62fe599725d412e385e34f5f3f4f618d565365d321" score = 75 quality = 90 @@ -22431,8 +22484,8 @@ rule REVERSINGLABS_Cert_Blocklist_A8D40Da6708679C08Aebddea6D3F6B8A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15646-L15664" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15646-L15664" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "27ec32791eaeccb8aa95d023c4fc8943f0435c32d8a17bde98d7d0b02ba17e59" score = 75 quality = 90 @@ -22456,8 +22509,8 @@ rule REVERSINGLABS_Cert_Blocklist_307642E1F3A92C6Cc2E7Fb6E18F2Ddcb : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15666-L15682" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15666-L15682" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8c96fbd10672b0b258a80f3abaf0320540c5ff0a4636f011cfe7cfa8ccc482d0" score = 75 quality = 90 @@ -22481,8 +22534,8 @@ rule REVERSINGLABS_Cert_Blocklist_52379131A1C69263C795A7D398Db0997 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15684-L15700" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15684-L15700" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "245e994024e08add755ec704b895286c115ac00eb5aeecde98fce96f35f6e9e0" score = 75 quality = 90 @@ -22506,8 +22559,8 @@ rule REVERSINGLABS_Cert_Blocklist_44312Cb9A927B4111360762B4D4Bdd6D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15702-L15718" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15702-L15718" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8e34636ed815812af478dd01eacd5298fa2cfeb420ee2f45e055f557534cae71" score = 75 quality = 90 @@ -22531,8 +22584,8 @@ rule REVERSINGLABS_Cert_Blocklist_123A5074069162F4Ed68Fc7D48F464C2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15720-L15736" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15720-L15736" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f55835c7404edab96bc5c8fe3844f3380f1f6bc8b43da1d51213de899629e8f5" score = 75 quality = 90 @@ -22556,8 +22609,8 @@ rule REVERSINGLABS_Cert_Blocklist_64Eb04B8Def382B5Efa75F63E0E85Ad0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15738-L15754" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15738-L15754" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "03adb8a9bf2a8f0633b34d5c39816b47e60b9e598208f7de79ad9d9a7ab8cc5e" score = 75 quality = 90 @@ -22581,8 +22634,8 @@ rule REVERSINGLABS_Cert_Blocklist_76D8D908Eed2F9857Dc5676A680Ceac9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15756-L15772" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15756-L15772" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "87f9930967d5832d3003672eeb89669b54feed1ca2ea5eec478c50e3cb7a7571" score = 75 quality = 90 @@ -22606,8 +22659,8 @@ rule REVERSINGLABS_Cert_Blocklist_083E3F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15774-L15790" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15774-L15790" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "6977d48a2e31235d780cba1b84b39a90e409ee8ea5555e01cbc34989ecd3882d" score = 75 quality = 90 @@ -22631,8 +22684,8 @@ rule REVERSINGLABS_Cert_Blocklist_79227311Acdd575759198Dbd3544Cca7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15792-L15808" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15792-L15808" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "73e920d51faf7150329ce189d1693c29a2285a02d54fee27e5af5afe3238295b" score = 75 quality = 90 @@ -22656,8 +22709,8 @@ rule REVERSINGLABS_Cert_Blocklist_13Ae38C9Ae21A8576C0D024D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15810-L15826" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15810-L15826" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7be892eaf9e2e31442f7ef5ffd296dd17696d6c95d20eb2758ede2c553b05f38" score = 75 quality = 90 @@ -22681,8 +22734,8 @@ rule REVERSINGLABS_Cert_Blocklist_557B0Abf44045827F1F36Efbc96271Ec : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15828-L15844" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15828-L15844" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "633e8d6b44d62443d991738fa82b9742ac5634051bba5d0cdb3d6b35d66bdc8f" score = 75 quality = 90 @@ -22706,8 +22759,8 @@ rule REVERSINGLABS_Cert_Blocklist_7903870184E18A80899740845A15E2B2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15846-L15862" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15846-L15862" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ad32491b463d0b3b4c85ed78e81bb69802e5f90ae835f73e270b28f02b36f840" score = 75 quality = 90 @@ -22731,8 +22784,8 @@ rule REVERSINGLABS_Cert_Blocklist_5Fba9B373F812C16Aef531D4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15864-L15880" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15864-L15880" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8b7340359778e3aa56f6ea300973af74eb77efd54108d2ca2b6b8f04d89a1c39" score = 75 quality = 90 @@ -22756,8 +22809,8 @@ rule REVERSINGLABS_Cert_Blocklist_616A5205238590B01D7B761E444E4Ad9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15882-L15898" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15882-L15898" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "463ccd3ace9021569a7a6d5fcbaadf34b15d2b07baf3df526b271b547cf2bbc5" score = 75 quality = 90 @@ -22781,8 +22834,8 @@ rule REVERSINGLABS_Cert_Blocklist_29Be2278113Dd062Eadca32De6B242D0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15900-L15916" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15900-L15916" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3df7afba9eda9022a64647ce2a91119d0bdf6fe5b164a1e82b1819409024fbee" score = 75 quality = 90 @@ -22806,8 +22859,8 @@ rule REVERSINGLABS_Cert_Blocklist_05F70A557Afd4A443F44D0Baf0Bc8C60 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15918-L15934" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15918-L15934" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3945f515b65ca3ffb6c2b64c884bb2790d703a277e1a5ba128c81bc63ed20a25" score = 75 quality = 90 @@ -22831,8 +22884,8 @@ rule REVERSINGLABS_Cert_Blocklist_4E0665D61997072294A70C662F72Eae3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15936-L15952" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15936-L15952" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f07cdfd522db0a92fe1dba30f158b2c89bb5424bdcdfda50ae42fcfddeac19ba" score = 75 quality = 90 @@ -22856,8 +22909,8 @@ rule REVERSINGLABS_Cert_Blocklist_74702Dff5D4056B847D009A2265Fb1B3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15954-L15970" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15954-L15970" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8acc57bbf334a48043dbee6fab7b7a54a44801b2ccd0ccd9d14194689c75c021" score = 75 quality = 90 @@ -22881,8 +22934,8 @@ rule REVERSINGLABS_Cert_Blocklist_353B1Cf7866Ee0B0Acdd532D0Bb1A220 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15972-L15988" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15972-L15988" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "aa8f0fe1517134b6e562c2accc46420a4f0afd77c3a7bbe98d551c54e68ed4c7" score = 75 quality = 90 @@ -22906,8 +22959,8 @@ rule REVERSINGLABS_Cert_Blocklist_093Ff2870Fa33Eaf47259457Ee58C2E0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L15990-L16006" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L15990-L16006" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1aafe547b8645f07498bac6f0ffd6d5aefbac160aa7a6fb8d1d891e70701ce99" score = 75 quality = 90 @@ -22931,8 +22984,8 @@ rule REVERSINGLABS_Cert_Blocklist_719C17A823839Dca813Ee85888B3B39A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16008-L16024" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16008-L16024" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a160ada48048e11632082e7538459554d77d31539e53709cd897f3c454af8236" score = 75 quality = 90 @@ -22956,8 +23009,8 @@ rule REVERSINGLABS_Cert_Blocklist_6Dc86Ebf5863568E2237B2D89582D705 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16026-L16042" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16026-L16042" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f24cdf890bd0b51a83ca333c37bc22068ab1f7e7ef36b36d94a133773097bd37" score = 75 quality = 90 @@ -22981,8 +23034,8 @@ rule REVERSINGLABS_Cert_Blocklist_214Df59Fe53874Cc011Dd45727035F51 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16044-L16060" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16044-L16060" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "96269f41f82621aee029f343acfce70c781bf7713588dfe78fac35a3d1d3f7cd" score = 75 quality = 90 @@ -23006,8 +23059,8 @@ rule REVERSINGLABS_Cert_Blocklist_37Ca4F66Fdcc8732992723199859886C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16062-L16078" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16062-L16078" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "190dffc36c17c27c43337d7914683b7bab3ff18a50de5278ed2a66f04b9e395d" score = 75 quality = 90 @@ -23031,8 +23084,8 @@ rule REVERSINGLABS_Cert_Blocklist_Be2F22C152Bb218B898C4029056816A9 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16080-L16098" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16080-L16098" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cd99e4d97d9a60f409cf072bbae254486c307ae3cb6e34c5cd9648c972615f36" score = 75 quality = 90 @@ -23056,8 +23109,8 @@ rule REVERSINGLABS_Cert_Blocklist_Fc7065Abf8303Fb472B8Af85918F5C24 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16100-L16118" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16100-L16118" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f57ae32d7efd9cd4c0a207897e30b871dc32405c5b9ad844c9bb7eee4827cc5a" score = 75 quality = 90 @@ -23081,8 +23134,8 @@ rule REVERSINGLABS_Cert_Blocklist_698Ff388Adb50B88Afb832E76B0A0Ad1 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16120-L16136" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16120-L16136" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b29bc69c8fd9543dba8f7d2a18d52b1bcbb8a8ae6f553d8b232ca74709b9addc" score = 75 quality = 90 @@ -23106,8 +23159,8 @@ rule REVERSINGLABS_Cert_Blocklist_391Ae38670Ab188A5De26E07 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16138-L16154" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16138-L16154" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f7ccfadab650ae3b6f950c9d1b35f86aa4a4e6c05479c014ab18881a405678f0" score = 75 quality = 90 @@ -23131,8 +23184,8 @@ rule REVERSINGLABS_Cert_Blocklist_D08D83Ff118Df3777E371C5C482Cce7B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16156-L16174" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16156-L16174" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5fdaf01c6a23057ab976e3ad2a8b40558b16693161410b0f30d7b884de7e3985" score = 75 quality = 90 @@ -23156,8 +23209,8 @@ rule REVERSINGLABS_Cert_Blocklist_06Ce209477F1Ac19A2049Bdc5846A831 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16176-L16192" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16176-L16192" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "24474c4033a8cad1690160da64b75a1eec570f56e830967256c19574bde59384" score = 75 quality = 90 @@ -23181,8 +23234,8 @@ rule REVERSINGLABS_Cert_Blocklist_447F449121B883211663B7B7E2Ead868 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16194-L16210" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16194-L16210" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "f473a939d1a27cf53c09d0e4a3753a9444ae3674a55d5b0feafeef6b75dd487f" score = 75 quality = 90 @@ -23206,8 +23259,8 @@ rule REVERSINGLABS_Cert_Blocklist_6366A9Ac97Df4De17366943C9B291Aaa : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16212-L16228" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16212-L16228" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "dcdfb78d4d779b1cabcdf5b2da1fa27aaa9faaed4d4967630ce45f30304fe227" score = 75 quality = 90 @@ -23231,8 +23284,8 @@ rule REVERSINGLABS_Cert_Blocklist_66E3F0B4459F15Ac7F2A2B44990Dd709 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16230-L16246" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16230-L16246" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a563f1485ae8887c46f45d1366f676894c7db55954671825b37372f786ce0d3d" score = 75 quality = 90 @@ -23256,8 +23309,8 @@ rule REVERSINGLABS_Cert_Blocklist_610039D6349Ee531E4Caa3A65D100C7D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16248-L16264" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16248-L16264" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e6b6a90cf40283d2e4d2d9c5732a078c9f2f117e3639ab5c0dd6c5323cb7c9ff" score = 75 quality = 90 @@ -23281,8 +23334,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Caa0D0Dadf32A2404A75195Ae47820A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16266-L16282" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16266-L16282" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ab71e485c0b541fae79d246d34b1f4fb146747c1c3fb723aa87a7a32378ff974" score = 75 quality = 90 @@ -23306,8 +23359,8 @@ rule REVERSINGLABS_Cert_Blocklist_140D2C515E8Ee9739Bb5F1B2637Dc478 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16284-L16300" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16284-L16300" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e6724fe80959592c8741621ce604518d3e964cee5941257a99dda78b9c8bbdac" score = 75 quality = 90 @@ -23331,8 +23384,8 @@ rule REVERSINGLABS_Cert_Blocklist_58015Acd501Fc9C344264Eace2Ce5730 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16302-L16318" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16302-L16318" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7c1bec5059d40fc326bb08775888ed169abc746228eeb42c897f479992c5acab" score = 75 quality = 90 @@ -23356,8 +23409,8 @@ rule REVERSINGLABS_Cert_Blocklist_0B7279068Beb15Ffe8060D2C56153C35 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16320-L16336" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16320-L16336" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ca00f1adacd6ff16e54b85be38c3a4545a10c76548e0647f7f3f6cfa4dff412d" score = 75 quality = 90 @@ -23381,8 +23434,8 @@ rule REVERSINGLABS_Cert_Blocklist_0Bc0F18Da36702E302Db170D91Dc9202 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16338-L16354" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16338-L16354" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d9ee2cf63a4edb28f894ea49a5b4df9b818d5764d9a74721b1d5222f53859462" score = 75 quality = 90 @@ -23406,8 +23459,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ca9B6F49B8B41204A174C751C73Dc393 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16356-L16374" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16356-L16374" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0b6558a7a1b78d471aaadced959ba91e411df50e3cc08e447fe9bd97f9e5cced" score = 75 quality = 90 @@ -23431,8 +23484,8 @@ rule REVERSINGLABS_Cert_Blocklist_Aaf65B8E7A2E68Bc8C9E8F27331B795C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16376-L16394" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16376-L16394" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "390d074da09d8e5b4bb2a6f4157a5125474ab5c22de62729d4fc4075edade289" score = 75 quality = 90 @@ -23456,8 +23509,8 @@ rule REVERSINGLABS_Cert_Blocklist_C6Ed0Efe2844Fa44Aae350C6845C3331 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16396-L16414" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16396-L16414" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5c4afcd8ceb5cc2f1df2303183ede2081b86365eeee7d4e1319a8ed9a45bbf0b" score = 75 quality = 90 @@ -23481,8 +23534,8 @@ rule REVERSINGLABS_Cert_Blocklist_Ede6Cfbf9Fa18337B0Fdb49C1F693020 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16416-L16434" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16416-L16434" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "a7f18d0028cbc0001a196bc915b7881244a5833dd65f96dd7d2e8ab1b0622e0c" score = 75 quality = 90 @@ -23506,8 +23559,8 @@ rule REVERSINGLABS_Cert_Blocklist_Eda0F47B3B38E781Cdf6Ef6Be5D3F6Ee : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16436-L16454" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16436-L16454" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "af3cd543a6feec3118ba4e5fdc8455584aa763bd8339f036ab332977fc0fb20e" score = 75 quality = 90 @@ -23531,8 +23584,8 @@ rule REVERSINGLABS_Cert_Blocklist_5Da173Eb1Ac76340Ac058E1Ff4Bf5E1B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16456-L16472" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16456-L16472" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "71da69fca275caead6a822e6587e0a07fc882f712afeafe18f4a595c269f6737" score = 75 quality = 90 @@ -23556,8 +23609,8 @@ rule REVERSINGLABS_Cert_Blocklist_1380A7Ccf2Bf36Bc496B00D8 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16474-L16490" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16474-L16490" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "88708d7d139a9d6e92f78df460b527a1ae6a404d0bcccb801c8c8cb1263a46c6" score = 75 quality = 90 @@ -23581,8 +23634,8 @@ rule REVERSINGLABS_Cert_Blocklist_02Eaf27E6F1575E365Fc7Fe4E0Be43F7 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16492-L16508" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16492-L16508" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "333a43bdfbc400727b8eae1efeb03484b959fc45ed6b8b0dd5e6a553fa27e87f" score = 75 quality = 90 @@ -23606,8 +23659,8 @@ rule REVERSINGLABS_Cert_Blocklist_6Eb02Ac2Beb9611Ed57Eb12E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16510-L16526" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16510-L16526" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7f2a6c61ae82fec6829924d11190da776aebdd3d72c7e001fdc29b215649261c" score = 75 quality = 90 @@ -23631,8 +23684,8 @@ rule REVERSINGLABS_Cert_Blocklist_010000000001297Dba69Dd : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16528-L16544" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16528-L16544" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bbc3e740d5043d1811ff44c7366c69192fb78c95215b30fd4f4c782812ad591c" score = 75 quality = 90 @@ -23656,8 +23709,8 @@ rule REVERSINGLABS_Cert_Blocklist_7Def22Ef4C645B1Decfb36B6D3539Dbf : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16546-L16562" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16546-L16562" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "655ed87ee65f937c7cec95085fe612f8d733e0853c87aa50b4aa1fda9e5f7a5d" score = 75 quality = 90 @@ -23681,8 +23734,8 @@ rule REVERSINGLABS_Cert_Blocklist_3E39C2Ccc494438Bb8C2560F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16564-L16580" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16564-L16580" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "3b4a55149b3895eeea5f96297d1fc9787eb74e2fcef8170148ef1a2ced334311" score = 75 quality = 90 @@ -23706,8 +23759,8 @@ rule REVERSINGLABS_Cert_Blocklist_6E3B09F43C3A0Fd53B7D600F08Fae2B5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16582-L16598" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16582-L16598" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "86b06519858dce4b77cb870905297a1fd1c767053fd07c0b0469eb7fc3ba6b32" score = 75 quality = 90 @@ -23731,8 +23784,8 @@ rule REVERSINGLABS_Cert_Blocklist_21220646C639D62C16992F46 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16600-L16616" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16600-L16616" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "87202c29867e6410d59c1e3b5ab09a24ebac5c68c61d7b932b91a91dcf3707e2" score = 75 quality = 90 @@ -23756,8 +23809,8 @@ rule REVERSINGLABS_Cert_Blocklist_738663F2C9E4Adb3Ad5306Aa5E7Cc548 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16618-L16634" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16618-L16634" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "518a22e31432ee42e6aceb861815f7f9e84f2430b7fb3a78b498e45c584584ab" score = 75 quality = 90 @@ -23781,8 +23834,8 @@ rule REVERSINGLABS_Cert_Blocklist_4280F2C8Ce1D98E5F8Da7Ecb005Eeae5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16636-L16652" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16636-L16652" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4cc8f00a9704f595f3e48375942a19cd6f8d6c0e53afc932a61f5a4326be4bcb" score = 75 quality = 90 @@ -23806,8 +23859,8 @@ rule REVERSINGLABS_Cert_Blocklist_2946397Be9C5Ae44E95C99Af : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16654-L16670" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16654-L16670" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b7b4925482fcc47dea81eb3d84af31cc572f1b19080b98dda330b0bf6d7c80f4" score = 75 quality = 90 @@ -23831,8 +23884,8 @@ rule REVERSINGLABS_Cert_Blocklist_2Df453588177Cf1C0C297Ff4 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16672-L16688" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16672-L16688" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "b0c82388fd87a89841d190ce4020cc5a2ea21c9d765ceca6bc25d64162479231" score = 75 quality = 90 @@ -23856,8 +23909,8 @@ rule REVERSINGLABS_Cert_Blocklist_0619C5E39A4Fc60A32F9B07F6A4Ca328 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16690-L16706" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16690-L16706" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "75e3dfd593d7fdc268de54430be617c015957a624f2ca36bc0036d4cbde5b686" score = 75 quality = 90 @@ -23881,8 +23934,8 @@ rule REVERSINGLABS_Cert_Blocklist_2Bffef48E6A321B418041310Fdb9B0D0 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16708-L16724" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16708-L16724" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "30a079b55b75b292f7af4f5ae99184cbb3cca1ce4cf20f2f5c961b533673db00" score = 75 quality = 90 @@ -23906,8 +23959,8 @@ rule REVERSINGLABS_Cert_Blocklist_34Ec9565805F34204C6966Fb81E36Ba1 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16726-L16742" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16726-L16742" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e434a02f5b9b22a25d8fe7a0bb7bd81b1cd8bc5356b4b626e3bfceb3f554a085" score = 75 quality = 90 @@ -23931,8 +23984,8 @@ rule REVERSINGLABS_Cert_Blocklist_B2B934B7F01E0Ac1E577814992243709 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16744-L16762" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16744-L16762" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "37b254ab76d144c09cc7b622dba59f5e372bf01ae12ce260a06143abb52062f6" score = 75 quality = 90 @@ -23956,8 +24009,8 @@ rule REVERSINGLABS_Cert_Blocklist_3A1B397Fd9451E3B5891Fc69681Ed73D : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16764-L16780" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16764-L16780" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ca43c7bacd8cb5a896c3135abf4a131bdb4a7f5093e64c8d1df743fad0c1c64a" score = 75 quality = 90 @@ -23981,8 +24034,8 @@ rule REVERSINGLABS_Cert_Blocklist_1Eb816Aa49E4894D9E9F78729E53Cd48 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16782-L16798" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16782-L16798" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "4e22568612aec050c7f78b81ba6749528a9c25c0ba43e14260a581a9bea7a2f0" score = 75 quality = 90 @@ -24006,8 +24059,8 @@ rule REVERSINGLABS_Cert_Blocklist_383Ca88D6D9379C740609560 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16800-L16816" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16800-L16816" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ce41d046a7ca320d034fa226b5e8c22022cc6bfc97eb9ef294b1aca232aaacef" score = 75 quality = 90 @@ -24031,8 +24084,8 @@ rule REVERSINGLABS_Cert_Blocklist_6731Cb1430F18B8C0C43Ab40E1154169 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16818-L16834" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16818-L16834" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "c05349166919ffc18ac6ecb61b822a8365f87a82164c5e110ef94345bdc4de6f" score = 75 quality = 90 @@ -24056,8 +24109,8 @@ rule REVERSINGLABS_Cert_Blocklist_159505E6456B9A9352F7C47168D89B96 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16836-L16852" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16836-L16852" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d6d0d5c86dd88afa29fb3c7cc3c0ab2e3401637a23e062ee9bab693a715cf16f" score = 75 quality = 90 @@ -24081,8 +24134,8 @@ rule REVERSINGLABS_Cert_Blocklist_04A0E92B0B9Ebbb797Df6Ef52Bd5Ad05 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16854-L16870" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16854-L16870" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ff2a2d06c48bd3426fa42526d966152e3e7166c4170b4e08bb65ee5d876eda93" score = 75 quality = 90 @@ -24106,8 +24159,8 @@ rule REVERSINGLABS_Cert_Blocklist_25F222Ab2613Dc4270B2Aabc2519A101 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16872-L16888" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16872-L16888" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "2c6673f6821c4ba11fc015cf3e9edefeb7c45209bc9dcd18501c4681444a9b9e" score = 75 quality = 90 @@ -24131,8 +24184,8 @@ rule REVERSINGLABS_Cert_Blocklist_212Ca239866F88C3D5B000B3004A569C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16890-L16906" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16890-L16906" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "23ab2343b17dce74fb4166a690ca5dd300b3ed20d3a6b43b922f456410d3035d" score = 75 quality = 90 @@ -24156,8 +24209,8 @@ rule REVERSINGLABS_Cert_Blocklist_18B700A319Aa98Ae71B279D4E8030B82 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16908-L16924" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16908-L16924" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e201498acfd9afebc68321887a806bb5c1d74c64a7cd93530feae2a944bd30fa" score = 75 quality = 90 @@ -24181,8 +24234,8 @@ rule REVERSINGLABS_Cert_Blocklist_169138A86954Be1D9B264F47 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16926-L16942" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16926-L16942" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1584e39b4e2025611bcb7bbbd92b97d25d12ddbb1e5c282db87730a03f7f56b1" score = 75 quality = 90 @@ -24206,8 +24259,8 @@ rule REVERSINGLABS_Cert_Blocklist_33412168Eeb3C0E4C7Dd0508A9Ffecd5 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16944-L16960" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16944-L16960" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d634af0637c3349fe1718ee807b8a75007ab46b141494331901a22ce54e9fc5d" score = 75 quality = 90 @@ -24231,8 +24284,8 @@ rule REVERSINGLABS_Cert_Blocklist_422Ab71Ac7Fb125Ad7171B0C99510B0E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16962-L16978" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16962-L16978" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "7366e5064a9a9f66260730575327e404eadea096ba3f6cf28c83c47bef9bca58" score = 75 quality = 90 @@ -24256,8 +24309,8 @@ rule REVERSINGLABS_Cert_Blocklist_6F18946E5B773B7E32D9E7B4Fb8D434C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16980-L16996" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16980-L16996" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fa285c17b43d1acdb05888074ecb16047209ade8f7f6191274f58eca7438dadf" score = 75 quality = 90 @@ -24281,8 +24334,8 @@ rule REVERSINGLABS_Cert_Blocklist_3596Dfc23B9A42C66700982250Da2906 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L16998-L17014" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L16998-L17014" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "1b69bf520fde5255069cf8752d5c67716e9bc297ddde1566551a563a563197ea" score = 75 quality = 90 @@ -24306,8 +24359,8 @@ rule REVERSINGLABS_Cert_Blocklist_486Bbddc8C5Ee99F051Ecaeb3F99D2A3 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17016-L17032" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17016-L17032" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "75855e26ba4e01b56a551a006e789c6032cfb02c6f6125a9bdf8becb848db5b2" score = 75 quality = 90 @@ -24331,8 +24384,8 @@ rule REVERSINGLABS_Cert_Blocklist_11211Eea9D0D1D1A325B5Eae1B2B1951120F : INFO FI date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17034-L17050" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17034-L17050" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "bafab986605be61d25a6764042937bc5d8c55196ea8ea9aa9360764d9681351b" score = 75 quality = 90 @@ -24356,8 +24409,8 @@ rule REVERSINGLABS_Cert_Blocklist_172Fea8Cb06Ffced6Bfac7F2F6B77754 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17052-L17068" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17052-L17068" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8e1e3e7d002ce084600c5444dc9b0bad8771370cb7919a3bb5ebc899040e4cf2" score = 75 quality = 90 @@ -24381,8 +24434,8 @@ rule REVERSINGLABS_Cert_Blocklist_3Ee50Bb98Fadca2D662A0920E76685A2 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17070-L17086" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17070-L17086" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "d232923ed962fbf4a9a30890778c2380d6c6967a693c6f77c2f558bb4347e60e" score = 75 quality = 90 @@ -24406,8 +24459,8 @@ rule REVERSINGLABS_Cert_Blocklist_21Bfddb6A66435D1Adce2Ceb23Ed7C9A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17088-L17104" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17088-L17104" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "22ad68974a1c6729da369c26372ba93c25ddf68df880580c727bf2d3ee2d3a86" score = 75 quality = 90 @@ -24431,8 +24484,8 @@ rule REVERSINGLABS_Cert_Blocklist_5B1C3F7Bbaa91Ca49B06A5C1004Ee5Be : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17106-L17122" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17106-L17122" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "9a8d9acc87668a6fbd9fdd52b6ef69d18de8f19d8f3d3ca8eeb630c6e8c25c65" score = 75 quality = 90 @@ -24456,8 +24509,8 @@ rule REVERSINGLABS_Cert_Blocklist_0A2089 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17124-L17140" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17124-L17140" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "07ce4d39af1e56fbbfa400cf139956826999043480f93c0fc43ed056f6420d7f" score = 75 quality = 90 @@ -24481,8 +24534,8 @@ rule REVERSINGLABS_Cert_Blocklist_1F84E030A0Ed10D5Ffe2B81B : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17142-L17158" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17142-L17158" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "097655cb2965ae71efb905ddf20ed30c240d25e03d08a1b6c87b472533ccc9d8" score = 75 quality = 90 @@ -24506,8 +24559,8 @@ rule REVERSINGLABS_Cert_Blocklist_88346267057C0A82E2F39851D1B9694C : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17160-L17178" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17160-L17178" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "60acdbad8ad3e1d4a863ce160d93abd0b5e2b214858cba84f7a1b907d2491486" score = 75 quality = 90 @@ -24531,8 +24584,8 @@ rule REVERSINGLABS_Cert_Blocklist_A46F9D8784778Baa48167C48Bbc56F30 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17180-L17198" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17180-L17198" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fffb6309355bc6764b0ab033db5964599c86c9a2f6d8985975a07f6b3ebb40ed" score = 75 quality = 90 @@ -24556,8 +24609,8 @@ rule REVERSINGLABS_Cert_Blocklist_525B5529Db20D17A85Be284D6B7952Ea : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17200-L17216" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17200-L17216" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "8fd406004b634e4826659b1dff88c61074fd321969b9fd63ea45d8e9608b35f1" score = 75 quality = 90 @@ -24581,8 +24634,8 @@ rule REVERSINGLABS_Cert_Blocklist_70Ae0E517D2Ef6D5Eed06B56730A1A9A : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17218-L17234" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17218-L17234" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "017eed878daf706eb96b638a8d1f4428466bc1d00ce27f32628bd249a658a813" score = 75 quality = 90 @@ -24606,8 +24659,8 @@ rule REVERSINGLABS_Cert_Blocklist_57C3717C5E2Ce9A2E0Cf0340C03F458E : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17236-L17252" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17236-L17252" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "fd710146874528c43ad8a9f847b7704c44ba4564cf79e20e6b23aa98b0ee2ea5" score = 75 quality = 90 @@ -24631,8 +24684,8 @@ rule REVERSINGLABS_Cert_Blocklist_0761110Efe0B688C469D687512828C1F : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17254-L17270" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17254-L17270" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "0ba60e1f58c7335ba5aa261031d09ee83a0ee51e05f8f26078b2a5c776ad0add" score = 75 quality = 90 @@ -24656,8 +24709,8 @@ rule REVERSINGLABS_Cert_Blocklist_08Aa03F385F870E3A6D243B74B1Dadf6 : INFO FILE date = "2023-11-08" modified = "2023-11-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/certificate/blocklist.yara#L17272-L17288" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/certificate/blocklist.yara#L17272-L17288" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "ef49a28a93d31c55dd2dfd3bec645f757a0a1a7eb8718ce92cf47bf9af126aed" score = 75 quality = 90 @@ -24670,6 +24723,722 @@ rule REVERSINGLABS_Cert_Blocklist_08Aa03F385F870E3A6D243B74B1Dadf6 : INFO FILE condition: uint16(0)==0x5A4D and for any i in (0..pe.number_of_signatures) : (pe.signatures[i].subject contains "\\xE4\\xB8\\x9C\\xE8\\x8E\\x9E\\xE5\\xB8\\x82\\xE8\\x85\\xBE\\xE4\\xBA\\x91\\xE8\\xAE\\xA1\\xE7\\xAE\\x97\\xE6\\x9C\\xBA\\xE7\\xA7\\x91\\xE6\\x8A\\x80\\xE6\\x9C\\x89\\xE9\\x99\\x90\\xE5\\x85\\xAC\\xE5\\x8F\\xB8" and pe.signatures[i].serial=="08:aa:03:f3:85:f8:70:e3:a6:d2:43:b7:4b:1d:ad:f6" and 1352678400<=pe.signatures[i].not_after) } +rule REVERSINGLABS_Win32_Trojan_Dridex : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Dridex trojan." + author = "ReversingLabs" + id = "bc68aca1-69e6-57e6-9277-70c89fda1e5d" + date = "2020-09-16" + modified = "2020-09-16" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/trojan/Win32.Trojan.Dridex.yara#L1-L80" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "7eddc8f33846dfb61302b7d7fddd8dec59a1bde05b14135c14131a02e2c19600" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Trojan" + tc_detection_name = "Dridex" + tc_detection_factor = 5 + importance = 25 + + strings: + $resolve_api_wrapper_1 = { + 56 57 8B FA 8B F1 8B CF E8 ?? ?? ?? ?? 85 C0 75 ?? 81 FE ?? ?? ?? ?? 75 ?? 33 C0 5F + 5E C3 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 8B CE E8 ?? ?? ?? ?? 84 C0 74 ?? 8B CE E8 ?? + ?? ?? ?? 85 C0 74 ?? 8B D7 ?? ?? ?? ?? E9 + } + $resolve_api_wrapper_2 = { + 57 53 8B FA 8B D9 8B CF E8 ?? ?? ?? ?? 85 C0 75 ?? 81 FB ?? ?? ?? ?? 74 ?? 8B CB E8 + ?? ?? ?? ?? 85 C0 74 ?? 8B C8 8B D7 E8 ?? ?? ?? ?? 5B 5F C3 8B CB E8 ?? ?? ?? ?? 84 + C0 74 ?? 8B CB E8 ?? ?? ?? ?? 85 C0 75 ?? 33 C0 EB + } + $resolve_api_wrapper_3 = { + 55 8B EC 57 8B 7D ?? 57 E8 ?? ?? ?? ?? 85 C0 75 ?? 56 8B 75 ?? 81 FE ?? ?? ?? ?? 74 + ?? 56 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B CE E8 ?? ?? ?? ?? 84 C0 74 ?? 56 E8 ?? ?? ?? ?? + 85 C0 75 ?? 5E 33 C0 5F 5D C2 ?? ?? 57 50 E8 ?? ?? ?? ?? 5E 5F 5D C2 + } + $resolve_api_wrapper_4 = { + 55 8B EC FF 75 ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 56 8B 75 ?? 81 FE ?? ?? ?? ?? 74 ?? 56 + E8 ?? ?? ?? ?? 85 C0 75 ?? 8B CE E8 ?? ?? ?? ?? 84 C0 74 ?? 56 E8 ?? ?? ?? ?? 85 C0 + 74 ?? 5E 89 45 ?? 5D E9 + } + $find_first_file_snippet_1 = { + 53 56 8B F1 57 33 DB 32 C9 89 5E ?? 33 FF E8 ?? ?? ?? ?? 83 38 ?? 7C ?? [4-6] BA ?? + ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 4E ?? 57 6A ?? 6A ?? 8D 56 ?? + 52 53 51 FF D0 + } + $find_first_file_snippet_2 = { + 57 53 55 8B E9 33 C9 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? + ?? 8B 18 E8 ?? ?? ?? ?? 8B C8 85 C9 74 ?? 33 D2 83 FB ?? 6A ?? 5B 8D 7D ?? 0F 4C DA + 8B C2 53 52 52 57 0F 9D C0 50 FF 75 ?? FF D1 + } + $find_first_file_snippet_3 = { + 53 56 8B F1 33 DB 57 32 C9 89 5E ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B + 38 E8 ?? ?? ?? ?? 8B D0 85 D2 74 ?? 6A ?? 33 C0 83 FF ?? 59 0F 4C C8 8D 46 ?? 51 53 + 53 50 33 C0 83 FF ?? 0F 9D C0 50 FF 76 ?? FF D2 + } + $find_first_file_snippet_4 = { + 53 56 8B F1 57 33 DB 32 C9 89 5E ?? 33 FF E8 ?? ?? ?? ?? 83 38 ?? 7C ?? 8D 7B ?? 8D + 5F ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 4E ?? 57 6A ?? 6A + ?? 8D 56 ?? 52 53 51 CC C3 + } + $find_first_file_snippet_5 = { + 56 8B F1 32 C9 57 C7 46 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 8B 38 E8 ?? ?? ?? ?? 8B D0 85 D2 74 ?? 33 C0 B9 ?? ?? ?? ?? 83 FF ?? 0F 4C C8 51 50 + 50 8D 46 ?? 50 33 C0 83 FF ?? 0F 9D C0 50 FF 76 ?? FF D2 + } + + condition: + uint16(0)==0x5A4D and ( any of ($resolve_api_wrapper_*) and any of ($find_first_file_snippet_*)) +} +rule REVERSINGLABS_Win32_Trojan_Emotet : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Emotet trojan." + author = "ReversingLabs" + id = "9742743d-753a-582b-9701-7278c8ed0e4e" + date = "2021-11-16" + modified = "2021-11-16" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/trojan/Win32.Trojan.Emotet.yara#L1-L182" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "747d603c9849a66782c95050a4a634ffdb4ce2882adcfc5d63e1f1ea1651b25e" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Trojan" + tc_detection_name = "Emotet" + tc_detection_factor = 5 + importance = 25 + + strings: + $decrypt_resource_v1 = { + 55 8B EC 83 EC ?? 53 8B D9 8B C2 56 57 89 45 ?? 8B 3B 33 F8 8B C7 89 7D ?? 83 E0 ?? + 75 ?? 8D 77 ?? EB ?? 8B F7 2B F0 83 C6 ?? 8D 0C 36 E8 ?? ?? ?? ?? 8B D0 89 55 ?? 85 + D2 74 ?? 83 65 ?? ?? 8D 43 ?? 83 65 ?? ?? C1 EE ?? 8D 0C B0 8B F2 8B D9 2B D8 83 C3 + ?? C1 EB ?? 3B C1 0F 47 5D ?? 85 DB 74 ?? 8B 55 ?? 8B F8 8B 0F 8D 7F ?? 33 CA 0F B6 + C1 66 89 06 8B C1 C1 E8 ?? 8D 76 ?? 0F B6 C0 66 89 46 ?? C1 E9 ?? 0F B6 C1 66 89 46 + ?? C1 E9 ?? 0F B6 C1 66 89 46 ?? 8B 45 ?? 40 89 45 ?? 3B C3 72 ?? 8B 7D ?? 8B 55 ?? + 33 C0 66 89 04 7A 5F 5E 8B C2 5B 8B E5 5D C3 + } + $generate_filename_v1 = { + 56 57 33 C0 BF ?? ?? ?? ?? 57 50 50 6A ?? 50 FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 8B F0 56 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? + ?? 83 C4 ?? 8B CE 5F 5E E9 + } + $decrypt_resource_v2 = { + 55 8B EC 83 EC ?? 8B 41 ?? 8B 11 33 C2 53 56 8D 71 ?? 89 55 ?? 8D 58 ?? 89 45 ?? 83 + C6 ?? F6 C3 ?? 74 ?? 83 E3 ?? 83 C3 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? + 8B C8 E8 ?? ?? ?? ?? FF D0 8D 14 1B B9 ?? ?? ?? ?? 52 6A ?? 50 E8 ?? ?? ?? ?? BA ?? + ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? FF D0 89 45 ?? 85 C0 74 ?? C1 EB ?? 8B C8 57 33 C0 8D + 14 9E 33 DB 8B FA 2B FE 83 C7 ?? C1 EF ?? 3B F2 0F 47 F8 85 FF 74 ?? 8B 16 8D 49 ?? + 33 55 ?? 8D 76 ?? 0F B6 C2 43 66 89 41 ?? 8B C2 C1 E8 ?? 0F B6 C0 66 89 41 ?? C1 EA + ?? 0F B6 C2 66 89 41 ?? C1 EA ?? 0F B6 C2 66 89 41 ?? 3B DF 72 ?? 8B 45 ?? 33 D2 8B + 4D ?? 5F 66 89 14 41 8B C1 5E 5B 8B E5 5D C3 + } + $generate_filename_v2 = { + 55 8B EC 81 EC ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 51 6A ?? B9 ?? ?? ?? ?? + E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? FF D0 85 C0 0F 88 ?? ?? ?? ?? 56 + B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B F0 8D 85 ?? ?? ?? ?? 8D [1-5] 51 + 51 50 56 8D [1-5] 68 ?? ?? ?? ?? 51 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B + C8 E8 ?? ?? ?? ?? FF D0 83 C4 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 + E8 ?? ?? ?? ?? FF D0 56 6A ?? 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 + E8 ?? ?? ?? ?? FF D0 B8 ?? ?? ?? ?? 5E 8B E5 5D C3 33 C0 8B E5 5D C3 + } + $decrypt_resource_v3 = { + 56 8B F1 BA [6-9] B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF D0 56 6A ?? 50 68 ?? ?? ?? ?? + BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF D0 5E C3 + } + $generate_filename_v3 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B F1 8B FA 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? BB ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 8D 85 ?? ?? ?? ?? BB ?? ?? ?? ?? 8B D3 56 50 BE ?? ?? ?? ?? [2-5] 8B CE E8 ?? + ?? ?? ?? 59 FF D0 57 8D 85 ?? ?? ?? ?? 8B D3 50 [2-5] 8B CE E8 ?? ?? ?? ?? 59 FF D0 + 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 + ?? ?? ?? ?? 89 45 ?? B8 ?? ?? ?? ?? 66 89 45 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 59 FF D0 F7 D8 5F 1B C0 5E 40 5B 8B E5 5D C3 + } + $decrypt_resource_v4 = { + 56 57 8B FA E8 ?? ?? ?? ?? 8B F0 A1 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? + ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 56 FF D0 8B 0D ?? ?? ?? ?? + 89 44 B9 ?? A1 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? + 8B C8 E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF D0 8B F8 A1 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? + ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 56 6A ?? 57 + FF D0 5F 5E C3 + } + $generate_filename_snippet_v4 = { + A1 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? + ?? ?? ?? A3 ?? ?? ?? ?? 56 53 FF D0 A1 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? E8 ?? + ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 56 FF D0 5F 5E 33 C9 8D + 04 43 66 89 08 5D 5B 59 C3 + } + $decrypt_resource_snippet_v5 = { + C1 EE ?? 33 C0 55 33 ED 8B D3 8D 0C B7 8B F1 2B F7 83 C6 ?? C1 EE ?? 3B F9 0F 47 F0 + 85 F6 74 ?? 8B 5C 24 ?? 8B 0F 8D 7F ?? 33 CB 0F B6 C1 66 89 02 8B C1 C1 E8 ?? 8D 52 + ?? 0F B6 C0 66 89 42 ?? C1 E9 ?? 0F B6 C1 C1 E9 ?? 45 66 89 42 ?? 0F B6 C1 66 89 42 + ?? 3B EE 72 ?? 8B 5C 24 ?? 8B 44 24 ?? 33 C9 5D 66 89 0C 43 5F 5E 8B C3 5B 83 C4 ?? + C3 + } + $decrypt_resource_snippet_v6 = { + C1 EE ?? 33 C0 55 33 ED 8B D3 8D 0C B7 8B F1 2B F7 83 C6 ?? C1 EE ?? 3B F9 0F 47 F0 + 85 F6 74 ?? 8B 5C 24 ?? 8B 0F 8D 7F ?? 33 CB 88 0A 8B C1 C1 E8 ?? 8D 52 ?? C1 E9 ?? + 88 42 ?? 88 4A ?? C1 E9 ?? 45 88 4A ?? 3B EE 72 ?? 8B 5C 24 ?? 8B 44 24 ?? 5D C6 04 + 03 ?? 5F 5E 8B C3 5B 83 C4 ?? C3 + } + $liblzf_decompression_1 = { + 83 EC ?? 8B 44 24 ?? 53 55 8D 2C 11 89 4C 24 ?? 8B 54 24 ?? 33 DB 03 C2 89 6C 24 ?? + 56 89 44 24 ?? 0F B6 41 ?? 8D 72 ?? 0F B6 11 C1 E2 ?? 0B D0 8D 45 ?? 89 44 24 ?? 57 + 8B F9 3B C8 0F 83 ?? ?? ?? ?? 0F B6 47 ?? C1 E2 ?? 0B D0 6B C2 ?? 8B CA C1 E9 ?? 33 + CA 89 54 24 ?? 8B 54 24 ?? C1 E9 ?? 2B C8 8B 44 24 ?? 81 E1 ?? ?? ?? ?? 8B 2C 88 8B + C7 2B 44 24 ?? 03 6C 24 ?? 89 04 8A 8B C7 8B 54 24 ?? 2B C5 48 89 44 24 ?? 3D ?? ?? + ?? ?? 0F 8D ?? ?? ?? ?? 3B EA 0F 86 ?? ?? ?? ?? 8A 45 ?? 3A 47 ?? 0F 85 ?? ?? ?? ?? + 0F B6 55 ?? 8D 4F ?? 0F B6 45 ?? 89 4C 24 ?? 0F B6 09 C1 E2 ?? 0B D0 C1 E1 ?? 0F B6 + 07 0B C8 3B D1 0F 85 ?? ?? ?? ?? 8B 44 24 ?? B9 ?? ?? ?? ?? 2B C7 3B C1 6A ?? 0F 47 + C1 89 44 24 ?? 8D 46 ?? 5A 3B 44 24 ?? 72 ?? 33 C9 8B C6 85 DB 0F 94 C1 2B C1 83 C0 + ?? 3B 44 24 ?? 0F 83 ?? ?? ?? ?? 8B C6 8D 4B ?? 2B C3 88 48 ?? 33 C0 85 DB 8B 5C 24 + ?? 0F 94 C0 2B F0 83 FB ?? 0F 86 ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 0F 85 ?? ?? + ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 0F 85 ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 0F 85 + ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 0F 85 ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 + } + $liblzf_decompression_2 = { + 0F 85 ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 0F 85 ?? ?? ?? ?? 8A 45 ?? 6A ?? 5A 3A + 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 + ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 + ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? + 6A ?? 5A 3A 47 ?? 75 ?? 8A 45 ?? 6A ?? 5A 3A 47 ?? 75 ?? 8D 0C 3A 2B EF 42 41 3B D3 + 73 ?? 8A 04 29 3A 01 74 ?? 8B 5C 24 ?? 83 EA ?? 83 FA ?? 73 ?? 8B CB 8A C2 C1 F9 ?? + C0 E0 ?? 02 C8 88 0E 46 EB ?? 8B C3 C1 F8 ?? 2C ?? 88 06 8D 42 ?? 88 46 ?? 83 C6 ?? + 8B 7C 24 ?? 8B 44 24 ?? 47 88 1E 03 FA 33 DB 83 C6 ?? 3B F8 72 ?? 8B 6C 24 ?? 8D 46 + ?? 3B 44 24 ?? 76 ?? 33 C0 EB ?? 3B 74 24 ?? 73 ?? 8A 07 43 88 06 46 8B 44 24 ?? 47 + 83 FB ?? 75 ?? C6 46 ?? ?? 33 DB 46 3B F8 73 ?? 8B 54 24 ?? E9 ?? ?? ?? ?? 8A 07 43 + 88 06 46 47 83 FB ?? 75 ?? C6 46 ?? ?? 33 DB 46 3B FD 72 ?? 8B CE 8D 53 ?? 2B CB 88 + 51 ?? 33 C9 85 DB 0F 94 C1 2B F1 2B 74 24 ?? 8B C6 5F 5E 5D 5B 83 C4 ?? C3 + } + $decrypt_resource_snippet_v7 = { + C1 EE ?? 3B F9 0F 47 F0 85 F6 74 ?? 8B 5C 24 ?? 8B 0F 8D 7F ?? 33 CB 0F B6 C1 66 89 + 02 8B C1 C1 E8 ?? 8D 52 ?? 0F B6 C0 66 89 42 ?? C1 E9 ?? 0F B6 C1 C1 E9 ?? 45 66 89 + 42 ?? 0F B6 C1 66 89 42 ?? 3B EE 72 ?? 8B 5C 24 ?? 8B 44 24 ?? 33 C9 5D 66 89 0C 43 + 5F 5E 8B C3 5B 83 C4 ?? C3 + } + $state_machine_snippet_v7 = { + 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B + 94 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 8D 84 24 + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B 54 24 ?? + 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 8D 94 + 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF 74 24 + ?? 8B F0 FF B4 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? F7 DE 8B 94 24 ?? ?? ?? ?? 1B F6 + 81 E6 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? + ?? ?? ?? 8B 94 24 ?? ?? ?? ?? 8B 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 + } + + condition: + uint16(0)==0x5A4D and ($decrypt_resource_v1 and $generate_filename_v1) or ($decrypt_resource_v2 and $generate_filename_v2) or ($decrypt_resource_v3 and $generate_filename_v3) or ($decrypt_resource_v4 and $generate_filename_snippet_v4) or ($decrypt_resource_snippet_v5 and all of ($liblzf_decompression_*)) or ($decrypt_resource_snippet_v6 and all of ($liblzf_decompression_*)) or ($decrypt_resource_snippet_v7 and $state_machine_snippet_v7) +} +rule REVERSINGLABS_Win32_Trojan_Isaacwiper : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects IsaacWiper trojan." + author = "ReversingLabs" + id = "c0924e5e-a942-57a3-a9f9-e6be6efa4c73" + date = "2022-03-02" + modified = "2022-03-02" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/trojan/Win32.Trojan.IsaacWiper.yara#L1-L76" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "c9fa43f44c33816a66f61255d101294da63df1afc5a27ed5817072040cd1eec5" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Trojan" + tc_detection_name = "IsaacWiper" + tc_detection_factor = 5 + importance = 25 + + strings: + $enumerate_physical_drives = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 33 F6 89 55 ?? 57 89 4D ?? B3 ?? C7 45 ?? ?? ?? ?? + ?? 89 75 ?? 84 DB 0F 84 ?? ?? ?? ?? 8B D6 8D 4D ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? + ?? ?? 6A ?? 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? D1 E8 8D + 8D ?? ?? ?? ?? BF ?? ?? ?? ?? 89 45 ?? 2B F8 83 C4 ?? 66 83 7D ?? ?? 8D 0C 41 8D 45 + ?? 74 ?? 83 C0 ?? 66 83 38 ?? 75 ?? 8D 55 ?? 2B C2 D1 F8 8D 04 45 ?? ?? ?? ?? 50 8B + C2 8D 14 3F 50 E8 ?? ?? ?? ?? D1 E8 83 C4 ?? 3B C7 8D 48 ?? 0F 46 C1 8B 4D ?? 03 C8 + 89 4D ?? 83 F9 ?? 73 ?? 8B 3D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? + 6A ?? 68 ?? ?? ?? ?? 50 B3 ?? FF D7 83 F8 ?? 74 ?? 46 50 89 75 ?? FF 15 ?? ?? ?? ?? + E9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 32 DB E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 83 + ?? ?? ?? ?? 0F B7 85 ?? ?? ?? ?? 66 85 C0 0F 95 C1 66 85 C0 0F 84 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 66 89 45 ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? D1 E8 8D 4D ?? BE ?? ?? ?? ?? 89 45 ?? 2B F0 83 C4 ?? 66 83 + 7D ?? ?? 8D 0C 41 8D 45 ?? 74 ?? 83 C0 ?? 66 83 38 ?? 75 ?? 8D 55 ?? 2B C2 D1 F8 8D + 04 45 ?? ?? ?? ?? 50 8B C2 8D 14 36 50 E8 ?? ?? ?? ?? D1 E8 83 C4 ?? 3B C6 8D 48 ?? + 0F 46 C1 8B 4D ?? 03 C8 89 4D ?? 83 F9 ?? 0F 83 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? + 6A ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 FF D7 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? 6A ?? 8D 45 + ?? C7 45 ?? ?? ?? ?? ?? 50 6A ?? 8D 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 56 FF 15 ?? + ?? ?? ?? 83 F8 ?? 0F 94 C3 75 ?? 33 C0 83 7D ?? ?? 0F 44 45 ?? 89 45 ?? 56 FF 15 ?? + ?? ?? ?? 84 DB EB ?? 84 C9 0F 84 ?? ?? ?? ?? 8B 5D ?? 8B D3 8B 4D ?? 6A ?? E8 ?? ?? + ?? ?? 8B 7D ?? 8A C8 83 C4 ?? 33 F6 84 C9 74 ?? 3B F3 74 ?? 6A ?? 8B D6 8B CF E8 ?? + ?? ?? ?? 8A C8 83 C4 ?? 46 83 C7 ?? 84 C9 75 ?? 46 84 C9 74 ?? 8B 5D ?? 3B F3 73 ?? + 6A ?? 8B D6 8B CF E8 ?? ?? ?? ?? 8A C8 83 C4 ?? 46 83 C7 ?? 84 C9 75 ?? 8A C1 5F 5E + 5B 8B E5 5D C3 + } + $corrupt_drive_thread = { + 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 8B 5D ?? 56 57 85 DB 0F 84 ?? ?? + ?? ?? 83 7B ?? ?? 0F 85 ?? ?? ?? ?? 8B 43 ?? 8D 4C 24 ?? 03 C0 BA ?? ?? ?? ?? 50 53 + E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 C4 ?? D1 E8 33 C9 66 89 4C 44 ?? 8D 44 24 ?? 50 + FF D7 8B 35 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 6A ?? 8D 44 24 ?? 50 + FF 15 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 66 83 7C 24 ?? ?? 8D 44 24 + ?? 74 ?? 90 83 C0 ?? 66 83 38 ?? 75 ?? 8D 4C 24 ?? BA ?? ?? ?? ?? 2B C1 D1 F8 8D 04 + 45 ?? ?? ?? ?? 50 8B C1 8D 8C 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? + ?? ?? ?? 50 FF D7 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 6A ?? 6A ?? 6A ?? + 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 89 74 24 + ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 8B 7B ?? 8B 5B ?? C7 44 24 ?? ?? ?? ?? ?? 85 DB 75 ?? + 81 FF ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 89 84 24 ?? ?? ?? ?? B8 ?? ?? ?? ?? 8B 8C 84 ?? ?? ?? ?? 8B D1 C1 EA ?? 33 D1 69 + CA ?? ?? ?? ?? 03 C8 89 8C 84 ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? BA ?? ?? ?? ?? 8D + B4 24 ?? ?? ?? ?? 89 94 24 ?? ?? ?? ?? 0F 1F 80 ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 75 ?? + 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 94 24 ?? ?? ?? ?? 8B 8C 94 ?? ?? ?? ?? 8B C1 + C1 E8 ?? 42 33 C8 89 94 24 ?? ?? ?? ?? 8B C1 25 ?? ?? ?? ?? C1 E0 ?? 33 C8 8B C1 25 + ?? ?? ?? ?? C1 E0 ?? 33 C8 8B C1 C1 E8 ?? 33 C1 89 06 83 C6 ?? 8D 84 24 ?? ?? ?? ?? + 3B F0 72 ?? 8B 74 24 ?? 8D 44 24 ?? 6A ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 + 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 44 24 ?? 3D ?? ?? ?? ?? 75 ?? 2B F8 83 DB ?? E9 + ?? ?? ?? ?? 8B C7 0B C3 74 ?? 57 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 + 24 ?? 6A ?? 50 57 8D 84 24 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? + 5F 5E 33 C0 5B 8B E5 5D C2 + } + + condition: + uint16(0)==0x5A4D and ($enumerate_physical_drives and $corrupt_drive_thread) +} +rule REVERSINGLABS_Win32_Trojan_Trickbot : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects TrickBot trojan." + author = "ReversingLabs" + id = "4ed253cc-0398-542b-a2b7-c42a0b9431fb" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/trojan/Win32.Trojan.TrickBot.yara#L1-L46" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "e10f16c70f1ff7cf11d3e25f06e4c5d9e20c51688582d2b51322f768a8e06d7e" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Trojan" + tc_detection_name = "TrickBot" + tc_detection_factor = 5 + importance = 25 + + strings: + $entry_setup = { + 58 (68 | 8B) [6-8] 59 [1-3] E2 ?? 57 8B (C7 | EC) 8B (C7 | EC) 05 ?? ?? ?? ?? 68 [4-5] + 89 45 [1-2] 8B D7 [3-4] 8B C1 66 AD 85 C0 74 ?? 3B (C1 | C8) (72 | 77) ?? 2B C1 (C1 | D1) + [2-4] 8B CF 03 C8 81 C1 ?? ?? ?? ?? 8B 01 59 03 D0 52 EB ?? 89 45 ?? 8B C5 B9 ?? ?? + ?? ?? C1 E1 ?? 2B C1 8B 00 89 45 ?? 6A ?? 8B D0 59 FF D2 89 68 ?? 6A ?? 8B D0 FF D2 + } + $decrypt_function_snippet = { + 58 8B C8 75 ?? 58 2B F0 50 8B D8 49 75 ?? 59 58 59 5E 5F 5B C3 + } + $decrypt_function_snippet_wrapper = { + 55 BD ?? ?? ?? ?? 50 51 52 6A ?? FF 45 ?? 8B 45 ?? 59 F7 E1 8D 8D ?? ?? ?? ?? 03 C8 + 89 4D ?? 8F 41 ?? 8F 41 ?? 8F 41 ?? 8F 41 ?? 8F 01 89 79 ?? 89 71 ?? 8B D1 59 89 4A + ?? 55 2B C0 8B C8 8B 02 8B F8 58 41 41 41 41 50 2B C1 8B 00 3B C7 72 ?? 58 C1 E9 ?? + 49 89 4A ?? E3 ?? FF 55 ?? 8B 55 ?? 8B 4A ?? FF 55 ?? 50 51 50 6A ?? 59 FF 55 ?? FF + D0 + } + + condition: + uint16(0)==0x5A4D and $entry_setup and ($decrypt_function_snippet or $decrypt_function_snippet_wrapper) +} +rule REVERSINGLABS_Linux_Trojan_Bibiwiper : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects BiBiWiper trojan." + author = "ReversingLabs" + id = "c370dde0-71ff-5832-b131-6d61beb02b9b" + date = "2023-11-28" + modified = "2023-11-28" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/trojan/Linux.Trojan.BiBiWiper.yara#L1-L76" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "8f290141d5da660463dede6df571d774448e136e2993a0a4c706245464e1239e" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Trojan" + tc_detection_name = "BiBiWiper" + tc_detection_factor = 5 + importance = 25 + + strings: + $destroy_files_p1 = { + 55 48 89 E5 53 48 81 EC ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 48 89 B5 ?? ?? ?? ?? 48 89 + 95 ?? ?? ?? ?? 48 89 8D ?? ?? ?? ?? 4C 89 85 ?? ?? ?? ?? 44 89 8D ?? ?? ?? ?? 48 8B + 05 ?? ?? ?? ?? 48 83 C0 ?? 48 89 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 BA ?? ?? ?? + ?? ?? ?? ?? ?? 48 89 C8 48 F7 EA 48 89 D0 48 C1 F8 ?? 48 89 CA 48 C1 FA ?? 48 29 D0 + 48 69 D0 ?? ?? ?? ?? 48 89 C8 48 29 D0 48 85 C0 0F 94 C0 84 C0 74 ?? E8 ?? ?? ?? ?? + 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 + D6 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? + ?? 48 8D 85 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 CE 48 89 C7 + E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 89 + CE 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? + ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8D + 8D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? ?? + 48 8D 8D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 CE 48 89 C7 E8 ?? ?? + ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 D6 48 89 C7 E8 ?? ?? ?? ?? 48 + 89 C3 48 8D 8D ?? ?? ?? ?? 48 8D 45 ?? BA ?? ?? ?? ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? + ?? 48 8D 45 ?? 48 89 DE 48 89 C7 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C7 E8 + } + $destroy_files_p2 = { + 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? + ?? ?? 48 8B 85 ?? ?? ?? ?? 48 C1 E0 ?? 48 89 45 ?? 48 8B B5 ?? ?? ?? ?? 48 8B 85 ?? + ?? ?? ?? BA ?? ?? ?? ?? 48 F7 F6 48 8B 55 ?? 48 29 D0 48 89 45 ?? 83 BD ?? ?? ?? ?? + ?? 7E ?? 8B 85 ?? ?? ?? ?? 83 E8 ?? 48 98 48 0F AF 45 ?? BA ?? ?? ?? ?? 48 F7 B5 ?? + ?? ?? ?? 48 89 D0 48 89 C1 48 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 CE 48 89 C7 E8 + ?? ?? ?? ?? EB ?? 48 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? + ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 48 39 + 85 ?? ?? ?? ?? 73 ?? BB ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 55 ?? 48 8B 85 ?? ?? ?? ?? + 48 29 D0 48 89 45 ?? 48 8B 45 ?? 48 89 45 ?? 48 8D 55 ?? 48 8D 45 ?? 48 89 D6 48 89 + C7 E8 ?? ?? ?? ?? 48 8B 00 48 89 45 ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 + ?? 48 8B 45 ?? 89 C2 48 8D 85 ?? ?? ?? ?? 89 D6 48 89 C7 E8 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 5D ?? 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 + } + $destroy_files_p3 = { + 89 C7 48 8B 85 ?? ?? ?? ?? 48 89 C1 BA ?? ?? ?? ?? 48 89 DE E8 ?? ?? ?? ?? 48 8B 85 + ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 55 ?? 48 8B 45 ?? 48 01 C2 48 + 8B 45 ?? 48 01 D0 48 39 85 ?? ?? ?? ?? 73 ?? 48 8B 55 ?? 48 8B 85 ?? ?? ?? ?? 48 29 + D0 48 8B 55 ?? 48 29 D0 48 89 45 ?? 48 83 7D ?? ?? 7E ?? 48 8B 4D ?? 48 8B 85 ?? ?? + ?? ?? BA ?? ?? ?? ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? ?? 83 45 ?? ?? 8B 45 ?? 48 98 48 + 39 85 ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? EB ?? 90 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 + 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? BB ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 + C7 E8 ?? ?? ?? ?? 83 FB ?? E9 ?? ?? ?? ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 + ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? EB ?? 48 89 + C3 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 D8 48 89 C7 E8 ?? ?? ?? ?? 48 + 89 C3 48 8D 45 ?? 48 89 C7 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 + C7 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? EB ?? + 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? + ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 D8 48 89 C7 E8 ?? ?? ?? ?? 48 8B 5D ?? C9 C3 + } + + condition: + uint32(0)==0x464C457F and ( all of ($destroy_files_p*)) +} +rule REVERSINGLABS_Win32_Trojan_Caddywiper : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects CaddyWiper trojan." + author = "ReversingLabs" + id = "ad437f29-4ad8-5a88-a0b6-03de55e7375f" + date = "2022-03-15" + modified = "2022-03-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/trojan/Win32.Trojan.CaddyWiper.yara#L1-L95" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "178ff4171c09866f6b303bdff234beff1116d268995ee4dc236332e472d645b1" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Trojan" + tc_detection_name = "CaddyWiper" + tc_detection_factor = 5 + importance = 25 + + strings: + $destroy_if_not_controller = { + 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 83 39 ?? 75 ?? EB ?? 8D 55 ?? 52 FF 55 ?? + C6 45 ?? 43 C6 45 ?? 3A C6 45 ?? 5C C6 45 ?? 55 C6 45 ?? 73 C6 45 ?? 65 C6 45 ?? 72 + C6 45 ?? 73 C6 45 ?? 00 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? C6 45 ?? ?? + C6 45 ?? ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 4D ?? 83 C1 ?? 89 4D ?? 83 7D + ?? ?? 73 ?? 8D 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8A 45 ?? 04 ?? 88 45 ?? EB ?? E8 ?? + ?? ?? ?? 8B E5 5D C3 + } + $erase_drive_data = { + C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8D 4D ?? 89 8D ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? + 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 95 ?? ?? ?? ?? 89 45 ?? 83 + 7D ?? ?? 74 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? 51 68 ?? ?? ?? ?? 8B 55 ?? 52 FF 55 ?? 8B 45 ?? 50 FF 55 ?? 8A 4D ?? 88 4D ?? 8A + 55 ?? 80 EA ?? 88 55 ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 E9 ?? 89 8D ?? ?? ?? + ?? 85 C0 0F 85 ?? ?? ?? ?? 8B E5 5D C3 + } + $erase_drives_recursively_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? FF FF FF FF C6 85 ?? ?? ?? ?? 2A C6 85 + ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 5C C6 85 ?? ?? ?? ?? 00 8D 85 ?? ?? ?? ?? 50 8B 4D + ?? 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? + ?? ?? 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? 00 00 00 00 + C6 85 ?? ?? ?? ?? 46 C6 85 ?? ?? ?? ?? 69 C6 85 ?? ?? ?? ?? 6E C6 85 ?? ?? ?? ?? 64 + C6 85 ?? ?? ?? ?? 46 C6 85 ?? ?? ?? ?? 69 C6 85 ?? ?? ?? ?? 72 C6 85 ?? ?? ?? ?? 73 + C6 85 ?? ?? ?? ?? 74 C6 85 ?? ?? ?? ?? 46 C6 85 ?? ?? ?? ?? 69 C6 85 ?? ?? ?? ?? 6C + C6 85 ?? ?? ?? ?? 65 C6 85 ?? ?? ?? ?? 41 C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 6B + C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 65 C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 72 + C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 6E C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 65 + C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 6C C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 33 + C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 32 C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 2E + C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 64 C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 6C + C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 6C C6 85 ?? ?? ?? ?? 00 C6 85 ?? ?? ?? ?? 00 + C6 85 ?? ?? ?? ?? 00 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 E8 + } + $erase_drives_recursively_2_p1 = { + 8D 45 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 8D 95 ?? + ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? + ?? ?? 75 ?? E9 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 E1 ?? 0F 84 ?? ?? ?? ?? 0F BE 95 ?? + ?? ?? ?? 83 FA ?? 75 ?? 0F BE 85 ?? ?? ?? ?? 85 C0 74 ?? 0F BE 8D ?? ?? ?? ?? 83 F9 + ?? 75 ?? E9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 E2 ?? 75 ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? + 74 ?? E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 + E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 8D 95 ?? ?? + ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8D 95 ?? + ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 + } + $erase_drives_recursively_2_p2 = { + C0 75 ?? E9 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? 51 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? E9 ?? + ?? ?? ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? + ?? ?? ?? 73 ?? E9 ?? ?? ?? ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 76 ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 6A ?? FF 95 ?? ?? ?? + ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 + ?? 6A ?? 6A ?? 6A ?? 8B 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? + 51 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 FF 95 ?? ?? ?? ?? + 8B 95 ?? ?? ?? ?? 52 FF 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 55 ?? 8D 8D ?? ?? ?? + ?? 51 8B 95 ?? ?? ?? ?? 52 FF 95 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 50 FF 95 ?? ?? ?? ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and ($destroy_if_not_controller) and ($erase_drive_data) and ( all of ($erase_drives_recursively_*)) +} +rule REVERSINGLABS_Win32_Trojan_Bibiwiper : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects BiBiWiper trojan." + author = "ReversingLabs" + id = "8462ceb8-ec54-5f92-a3e7-c96e52647ca7" + date = "2023-11-28" + modified = "2023-11-28" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/trojan/Win32.Trojan.BiBiWiper.yara#L1-L102" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "d75954c05a8f82ad90a4adf6a2a3748928488ddebe40d8f8a790bfcde0b02a11" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Trojan" + tc_detection_name = "BiBiWiper" + tc_detection_factor = 5 + importance = 25 + + strings: + $delete_shadow_copies_p1 = { + 48 89 5C 24 ?? 55 48 8D 6C 24 ?? 48 81 EC ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 + 48 89 45 ?? 33 DB 48 C7 44 24 ?? ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 5C 24 ?? 48 + 8D 4C 24 ?? 48 89 5C 24 ?? 44 8D 43 ?? E8 ?? ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 + ?? 48 8B 54 24 ?? 48 0F 43 4C 24 ?? 48 03 D1 48 8D 4C 24 ?? 48 83 7C 24 ?? ?? 48 0F + 43 4C 24 ?? E8 ?? ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 ?? 48 8D 55 ?? 48 0F 43 4C + 24 ?? 48 2B D1 0F B6 01 88 04 0A 48 8D 49 ?? 84 C0 75 ?? 0F 57 C0 C7 44 24 ?? ?? ?? + ?? ?? 48 8D 45 ?? 45 33 C9 48 89 44 24 ?? 48 8D 55 ?? 48 8D 44 24 ?? 45 33 C0 48 89 + 44 24 ?? 33 C9 48 89 5C 24 ?? 48 89 5C 24 ?? 0F 11 45 ?? C7 44 24 ?? ?? ?? ?? ?? 89 + 5C 24 ?? 0F 11 44 24 ?? 66 89 5D ?? 0F 11 45 ?? 0F 11 45 ?? 0F 11 45 ?? 0F 11 45 ?? + FF 15 ?? ?? ?? ?? 48 8B 54 24 ?? 48 83 FA ?? 72 ?? 48 8B 4C 24 ?? 48 FF C2 48 8B C1 + 48 81 FA ?? ?? ?? ?? 72 ?? 48 8B 49 ?? 48 83 C2 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? + 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 5C 24 ?? 48 8D 15 ?? ?? ?? + ?? 48 89 5C 24 ?? 48 8D 4C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 83 7C + 24 ?? ?? 48 8D 4C 24 ?? 48 8B 54 24 ?? 48 0F 43 4C 24 ?? 48 03 D1 48 8D 4C 24 ?? 48 + 83 7C 24 ?? ?? 48 0F 43 4C 24 ?? E8 ?? ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 ?? 48 + 8D 55 ?? 48 0F 43 4C 24 ?? 48 2B D1 0F B6 01 88 04 0A 48 8D 49 ?? 84 C0 75 ?? 0F 57 + C0 C7 44 24 ?? ?? ?? ?? ?? 48 8D 45 ?? 45 33 C9 48 89 44 24 ?? 48 8D 55 ?? 48 8D 44 + 24 ?? 45 33 C0 48 89 44 24 ?? 33 C9 48 89 5C 24 ?? 48 89 5C 24 ?? 0F 11 45 ?? C7 44 + 24 ?? ?? ?? ?? ?? 89 5C 24 ?? 0F 11 44 24 ?? 66 89 5D ?? 0F 11 45 ?? 0F 11 45 ?? 0F + } + $delete_shadow_copies_p2 = { + 11 45 ?? 0F 11 45 ?? FF 15 ?? ?? ?? ?? 48 8B 54 24 ?? 48 83 FA ?? 72 ?? 48 8B 4C 24 + ?? 48 FF C2 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 8B 49 ?? 48 83 C2 ?? 48 2B C1 48 + 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 5C 24 + ?? 48 8D 15 ?? ?? ?? ?? 48 89 5C 24 ?? 48 8D 4C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 ?? 48 8B 54 24 ?? 48 0F 43 4C 24 ?? 48 03 + D1 48 8D 4C 24 ?? 48 83 7C 24 ?? ?? 48 0F 43 4C 24 ?? E8 ?? ?? ?? ?? 48 83 7C 24 ?? + ?? 48 8D 4C 24 ?? 48 8D 55 ?? 48 0F 43 4C 24 ?? 48 2B D1 90 0F B6 01 88 04 0A 48 8D + 49 ?? 84 C0 75 ?? 0F 57 C0 C7 44 24 ?? ?? ?? ?? ?? 48 8D 45 ?? 45 33 C9 48 89 44 24 + ?? 48 8D 55 ?? 48 8D 44 24 ?? 45 33 C0 48 89 44 24 ?? 33 C9 48 89 5C 24 ?? 48 89 5C + 24 ?? 0F 11 45 ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? 0F 11 44 24 ?? 66 89 5D ?? 0F + 11 45 ?? 0F 11 45 ?? 0F 11 45 ?? 0F 11 45 ?? FF 15 ?? ?? ?? ?? 48 8B 54 24 ?? 48 83 + FA ?? 72 ?? 48 8B 4C 24 ?? 48 FF C2 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 8B 49 ?? + 48 83 C2 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 B8 + ?? ?? ?? ?? 48 89 5C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 89 5C 24 ?? 48 8D 4C 24 ?? 48 C7 + 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 ?? 48 8B 54 24 ?? + 48 0F 43 4C 24 ?? 48 03 D1 48 8D 4C 24 ?? 48 83 7C 24 ?? ?? 48 0F 43 4C 24 ?? E8 ?? + ?? ?? ?? 48 83 7C 24 ?? ?? 48 8D 4C 24 ?? 48 8D 55 ?? 48 0F 43 4C 24 ?? 48 2B D1 90 + 0F B6 01 88 04 0A 48 8D 49 ?? 84 C0 75 ?? 0F 57 C0 C7 44 24 ?? ?? ?? ?? ?? 48 8D 45 + ?? 45 33 C9 48 89 44 24 ?? 48 8D 55 ?? 48 8D 44 24 ?? 45 33 C0 48 89 44 24 ?? 33 C9 + 48 89 5C 24 ?? 48 89 5C 24 ?? 0F 11 45 ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 + } + $destroy_files_p1 = { + 48 89 5C 24 ?? 55 56 57 41 54 41 55 41 56 41 57 48 83 EC ?? 48 8B 05 ?? ?? ?? ?? 48 + 33 C4 48 89 44 24 ?? 4D 8B E9 4D 8B E0 4C 8B F9 48 63 BC 24 ?? ?? ?? ?? 33 F6 89 74 + 24 ?? 48 8B 05 ?? ?? ?? ?? 48 FF C0 48 89 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 B8 + ?? ?? ?? ?? ?? ?? ?? ?? 48 F7 E9 48 C1 FA ?? 48 8B C2 48 C1 E8 ?? 48 03 D0 48 69 C2 + ?? ?? ?? ?? 48 3B C8 75 ?? 4C 8B 05 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8D 0D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 C1 E3 ?? 33 D2 49 8B C4 49 F7 F5 48 + 8B E8 48 2B EB 83 FF ?? 7E ?? 48 8D 47 ?? 48 0F AF C3 33 D2 49 F7 F4 EB ?? 48 8B D6 + 45 33 C0 49 8B CF E8 ?? ?? ?? ?? 49 8B CF E8 ?? ?? ?? ?? 48 63 C8 49 3B CC 0F 87 ?? + ?? ?? ?? 49 8B C4 48 2B C1 49 8B FC 48 2B F9 48 3B D8 48 0F 42 FB 48 8B CF E8 ?? ?? + ?? ?? 48 89 44 24 ?? 0F 57 C0 4C 63 F7 F3 0F 7F 44 24 ?? 48 89 74 24 ?? 85 FF 74 ?? + 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 4C 3B F0 0F 87 ?? ?? ?? ?? 49 81 FE ?? ?? ?? ?? 72 + } + $destroy_files_p2 = { + 49 8D 4E ?? 49 3B CE 0F 86 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B C8 48 85 C0 0F 84 ?? ?? + ?? ?? 48 83 C0 ?? 48 83 E0 ?? 48 89 48 ?? EB ?? 49 8B CE E8 ?? ?? ?? ?? 48 89 44 24 + ?? 4A 8D 1C 30 48 89 5C 24 ?? 4D 8B C6 33 D2 48 8B C8 E8 ?? ?? ?? ?? 48 89 5C 24 ?? + C7 44 24 ?? ?? ?? ?? ?? 85 FF 7E ?? 48 8B DE 44 8B F7 66 0F 1F 44 00 ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 88 04 0B 48 8D 5B ?? 49 83 EE ?? 75 ?? 4D 85 ED 7E + ?? 4D 8B CF 41 B8 ?? ?? ?? ?? 48 8B D7 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 49 8B CF E8 ?? + ?? ?? ?? 48 63 C8 48 8D 04 29 48 03 C7 49 3B C4 76 ?? 49 8B FC 48 2B F9 48 2B FD 48 + 85 FF 7E ?? 41 B8 ?? ?? ?? ?? 48 8B D5 49 8B CF E8 ?? ?? ?? ?? FF C6 48 63 C6 49 3B + C5 7C ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8B 4C 24 ?? 48 85 C9 74 ?? 48 8B 54 24 + ?? 48 2B D1 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 + 83 C0 ?? 48 83 F8 ?? 77 ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 33 CC E8 ?? ?? ?? ?? 48 + 8B 9C 24 ?? ?? ?? ?? 48 83 C4 ?? 41 5F 41 5E 41 5D 41 5C 5F 5E 5D C3 + } + + condition: + uint16(0)==0x5A4D and ( all of ($delete_shadow_copies_p*)) and ( all of ($destroy_files_p*)) +} +rule REVERSINGLABS_Linux_Trojan_Acidrain : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects AcidRain trojan." + author = "ReversingLabs" + id = "802c7eb7-d407-5b07-a6b4-4648d3ad80e9" + date = "2024-05-10" + modified = "2024-05-10" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/trojan/Linux.Trojan.AcidRain.yara#L1-L67" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "5b47a0de8bda09d217f8a148e561f3da7ce4945f011f4a9b5dbbca88157d3080" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Trojan" + tc_detection_name = "AcidRain" + tc_detection_factor = 5 + importance = 25 + + strings: + $destroy_files_using_ioctls = { + 55 89 E5 57 BF ?? ?? ?? ?? 56 53 81 EC ?? ?? ?? ?? 89 7C 24 ?? 8B 45 ?? 89 04 24 E8 + ?? ?? ?? ?? 85 C0 89 C3 78 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 25 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 81 C4 ?? ?? ?? ?? 5B 5E 5F 5D + C3 8D 45 ?? BE ?? ?? ?? ?? 89 44 24 ?? 89 74 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 4D ?? + 8B 55 ?? C7 45 ?? ?? ?? ?? ?? 85 C9 89 55 ?? 74 ?? 8D 75 ?? 8D B6 ?? ?? ?? ?? 8D BF + ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 74 24 ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? B8 ?? ?? + ?? ?? 89 74 24 ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 01 D0 39 45 + ?? 89 45 ?? 77 ?? 81 FA ?? ?? ?? ?? BF ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 45 ?? C7 45 + ?? ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 75 ?? EB ?? 31 C9 89 4C 24 ?? 8B 45 ?? 89 + 1C 24 89 44 24 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 7C 24 ?? 89 1C 24 89 44 24 ?? E8 + ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 01 D0 39 45 ?? 89 45 ?? 76 ?? B8 ?? ?? ?? ?? 89 74 24 + ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 74 24 ?? 89 44 24 ?? 89 1C + 24 E8 ?? ?? ?? ?? 80 7D ?? ?? 75 ?? A1 ?? ?? ?? ?? 89 7D ?? 89 45 ?? 8B 45 ?? 89 45 + ?? 8D 45 ?? 89 44 24 ?? B8 ?? ?? ?? ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 55 ?? + 8B 45 ?? 01 D0 39 45 ?? 89 45 ?? 77 ?? 8D 74 26 ?? 8D BC 27 ?? ?? ?? ?? 31 FF 89 1C + 24 E8 ?? ?? ?? ?? 31 C0 89 44 24 ?? 89 7C 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 75 ?? C7 + 45 ?? ?? ?? ?? ?? 85 F6 74 ?? 8D 75 ?? 8D 76 ?? B9 ?? ?? ?? ?? 89 74 24 ?? 89 4C 24 + ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 01 D0 39 45 ?? 89 45 ?? 77 ?? 89 1C 24 + E8 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 5B 5E 5F 5D C3 + } + $destroy_files_using_overwrite = { + 55 89 E5 83 EC ?? 89 5D ?? 8B 5D ?? 8D 45 ?? 89 75 ?? 89 7D ?? C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? 89 44 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 5D ?? 8B 75 + ?? 8B 7D ?? 89 EC 5D C3 + } + $redundant_reboot_attempts = { + C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F + 84 ?? ?? ?? ?? 8D B6 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 85 C0 0F + 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 8D 76 ?? 0F 84 ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 04 + 24 E8 ?? ?? ?? ?? 31 D2 83 C4 ?? 89 D0 59 5B 5E 5F 5D 8D 61 ?? C3 + } + + condition: + uint32(0)==0x464C457F and ($destroy_files_using_ioctls) and ($destroy_files_using_overwrite) and ($redundant_reboot_attempts) +} +rule REVERSINGLABS_Win32_Trojan_Hermeticwiper : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects HermeticWiper trojan." + author = "ReversingLabs" + id = "252dfb3d-9d4e-51a4-80c9-64e17922d997" + date = "2022-02-24" + modified = "2022-02-24" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/trojan/Win32.Trojan.HermeticWiper.yara#L1-L50" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0fa519ce8285ffe4e49c2a301e8a0fd0516a05dc6b41ee0b010fdc76dd6e195e" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Trojan" + tc_detection_name = "HermeticWiper" + tc_detection_factor = 5 + importance = 25 + + strings: + $corrupt_physical_drive = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 51 68 ?? ?? ?? ?? 0F 57 C0 89 55 ?? 8D 85 ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 33 F6 66 0F D6 45 ?? 33 FF 89 75 ?? 50 0F + 11 45 ?? 89 7D ?? 0F 11 45 ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 8D 55 ?? 8D 8D ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? + BF ?? ?? ?? ?? 57 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8B F0 8D 45 ?? + 50 57 56 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? + 75 ?? 66 0F 1F 44 00 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 81 C7 ?? ?? + ?? ?? 33 F6 81 FF ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 57 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 57 56 6A ?? 6A ?? 68 ?? + ?? ?? ?? 53 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 85 F6 0F 84 ?? ?? ?? + ?? 8B 06 C7 45 ?? ?? ?? ?? ?? 83 F8 ?? 74 ?? 85 C0 74 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? + 83 7E ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 55 ?? 8D 46 ?? 89 45 ?? 66 90 + 8B 00 85 C0 74 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 52 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 8B F8 89 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 8B 45 ?? 6A ?? 6A ?? FF 70 ?? FF 70 + ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 57 53 FF + 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 55 ?? 81 FA ?? ?? ?? ?? 72 ?? 66 83 7F ?? + ?? 75 ?? 85 D2 0F B7 C2 B9 ?? ?? ?? ?? 0F 45 C8 66 89 4F ?? 8B 45 ?? FF 70 ?? FF 70 + ?? FF 75 ?? FF 75 ?? 57 53 FF 55 ?? 8B 55 ?? 8B 4D ?? 8B 45 ?? 41 05 ?? ?? ?? ?? 89 + 4D ?? 89 45 ?? 3B 4E ?? 0F 82 ?? ?? ?? ?? 8B 7D ?? EB ?? FF 15 ?? ?? ?? ?? 33 FF 85 + DB 74 ?? 83 FB ?? 74 ?? 53 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 85 F6 74 ?? 56 6A ?? + FF D3 8B 35 ?? ?? ?? ?? 50 FF D6 EB ?? FF 15 ?? ?? ?? ?? 8B 7D ?? EB ?? 33 C0 5F 5E + 5B 8B E5 5D C2 ?? ?? 8B 35 ?? ?? ?? ?? 85 FF 74 ?? 57 6A ?? FF D3 50 FF D6 8B 45 ?? + 5F 5E 5B 8B E5 5D C2 + } + + condition: + uint16(0)==0x5A4D and ($corrupt_physical_drive) +} import "pe" rule REVERSINGLABS_Win32_Exploit_CVE20200601 : TC_DETECTION MALICIOUS EXPLOIT CVE_2020_0601 FILE @@ -24681,8 +25450,8 @@ rule REVERSINGLABS_Win32_Exploit_CVE20200601 : TC_DETECTION MALICIOUS EXPLOIT CV date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/exploit/Win32.Exploit.CVE20200601.yara#L3-L253" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/exploit/Win32.Exploit.CVE20200601.yara#L3-L253" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "e4d915560ad72e0fde63276f9ffece00535c7983125efaa8298adc11d5e54817" score = 75 quality = 88 @@ -24898,18 +25667,18 @@ rule REVERSINGLABS_Win32_Exploit_CVE20200601 : TC_DETECTION MALICIOUS EXPLOIT CV condition: uint16(0)==0x5A4D and ($oid_prime_explicit) and ( any of ($ecc_public_key_*)) and (pe.number_of_signatures>0) } -rule REVERSINGLABS_Win32_Ransomware_Sepsis : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win64_Ransomware_Blackbasta : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Sepsis ransomware." + description = "Yara rule that detects BlackBasta ransomware." author = "ReversingLabs" - id = "0c26d6e0-1d64-5f47-8e21-6710a531bc74" - date = "2020-07-15" - modified = "2020-07-15" + id = "7a4ad567-0612-5a9c-8a06-4d615bc7e24a" + date = "2022-12-13" + modified = "2022-12-13" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Sepsis.yara#L1-L126" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "171ad074a780b45195c6e02b111b3883c58a4028e635c4d6b8ce27c5e05e35d7" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.BlackBasta.yara#L1-L293" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "79c81a4470e9eabbd714b1a91621c7b2bbe42d5371ba2c799529662d5f5c479a" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -24917,116 +25686,246 @@ rule REVERSINGLABS_Win32_Ransomware_Sepsis : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Sepsis" + tc_detection_name = "BlackBasta" tc_detection_factor = 5 importance = 25 strings: - $search_files_1 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 8B 5D ?? 8D 84 24 ?? ?? ?? ?? 56 57 8B 3D ?? - ?? ?? ?? 68 ?? ?? ?? ?? 53 50 FF D7 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 8D 4C 24 ?? 89 44 24 ?? 51 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 + $find_files = { + 48 8B 44 24 ?? 83 A0 ?? ?? ?? ?? ?? 44 8B C9 EB ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 44 38 + 75 ?? 74 ?? 48 8B 44 24 ?? 83 A0 ?? ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? EB ?? 44 38 75 ?? + 74 ?? 48 8B 44 24 ?? 83 A0 ?? ?? ?? ?? ?? 45 8B CE 4C 8D 44 24 ?? 48 8B CF 48 8D 54 + 24 ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 4C 8D 45 ?? 85 C0 44 89 74 24 ?? 4C 89 74 24 ?? + 49 0F 45 CE 45 33 C9 33 D2 FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 75 ?? 4D 8B CC 45 + 33 C0 33 D2 48 8B CF E8 ?? ?? ?? ?? 8B D8 44 38 74 24 ?? 74 ?? 48 8B 4C 24 ?? E8 ?? + ?? ?? ?? 8B C3 E9 ?? ?? ?? ?? 49 8B 74 24 ?? 49 2B 34 24 48 C1 FE ?? 33 D2 4C 89 75 + ?? 48 8D 4D ?? 4C 89 75 ?? 4C 89 75 ?? 4C 89 75 ?? 4C 89 75 ?? 44 88 75 ?? E8 ?? ?? + ?? ?? 48 8B 45 ?? B9 ?? ?? ?? ?? 39 48 ?? 75 ?? 44 38 75 ?? 74 ?? 48 8B 45 ?? 83 A0 + ?? ?? ?? ?? ?? 44 8B C9 EB ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 44 38 75 ?? 74 ?? 48 8B 45 + ?? 83 A0 ?? ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? EB ?? 44 38 75 ?? 74 ?? 48 8B 45 ?? 83 A0 + ?? ?? ?? ?? ?? 45 8B CE 4C 8D 44 24 ?? 48 8D 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B + 75 ?? 33 D2 85 C0 49 8B CE 48 0F 45 CA 80 39 ?? 75 ?? 8A 41 ?? 84 C0 75 ?? 38 55 ?? + 74 ?? 49 8B CE E8 ?? ?? ?? ?? EB ?? 3C ?? 75 ?? 38 51 ?? 74 ?? 4D 8B CC 4D 8B C5 48 + 8B D7 E8 ?? ?? ?? ?? 44 8B E8 85 C0 75 ?? 38 45 ?? 74 ?? 49 8B CE E8 ?? ?? ?? ?? 4C + 8B 6C 24 ?? 48 8D 55 ?? 48 8B CB FF 15 ?? ?? ?? ?? 45 33 F6 85 C0 0F 85 ?? ?? ?? ?? + 49 8B 04 24 49 8B 54 24 ?? 48 2B D0 48 C1 FA ?? 48 3B F2 74 ?? 48 2B D6 48 8D 0C F0 + 4C 8D 0D ?? ?? ?? ?? 45 8D 46 ?? E8 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 44 38 74 + 24 ?? 74 ?? 48 8B 4C 24 } - $search_files_2 = { - 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 - ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 - 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 - ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 - 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? 68 ?? ?? ?? - ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? F6 44 24 ?? ?? 8D 44 24 ?? 50 53 8D 84 24 ?? ?? - ?? ?? 50 74 ?? FF D7 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? EB ?? FF D7 8D 44 24 ?? - 50 FF 15 ?? ?? ?? ?? 8B D0 8D 7A + $find_system_volumes_v1_p1 = { + 48 89 4C 24 ?? 55 53 56 57 41 56 41 57 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? + 48 8B F1 45 33 FF 44 89 7C 24 ?? 4C 89 39 4C 89 79 ?? 4C 89 79 ?? C7 44 24 ?? ?? ?? + ?? ?? BA ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 4C 8B F0 0F 1F 00 4C 8D 8D ?? + ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 44 89 7C 24 ?? 4C 89 7C 24 ?? 48 8D 85 ?? ?? ?? ?? 48 89 44 24 + ?? 4C 89 7C 24 ?? 45 33 C9 45 33 C0 33 D2 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? F7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 8D 14 00 48 8D BD ?? ?? ?? ?? 48 03 FA 4C 89 7C 24 ?? 4C 89 + 7C 24 ?? 4C 89 7C 24 ?? 4C 89 7C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? 48 + 8D 9D ?? ?? ?? ?? 48 D1 FA 48 83 FA ?? 72 ?? 45 33 C0 48 8D 4C 24 ?? E8 } - $search_files_3 = { - 66 8B 0A 83 C2 ?? 66 85 C9 75 ?? 2B D7 D1 FA 83 FA ?? 75 ?? 66 83 78 ?? ?? 74 ?? 8D - 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 15 - ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B 8B - E5 5D C2 + $find_system_volumes_v1_p2 = { + 4C 89 7C 24 ?? 48 8D 44 24 ?? 48 89 85 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 3B C7 74 + ?? 66 66 66 0F 1F 84 00 ?? ?? 00 00 44 0F B6 0B 48 8B 4C 24 ?? 48 8B 54 24 ?? 48 3B + CA 73 ?? 48 8D 41 ?? 48 89 44 24 ?? 48 8D 44 24 ?? 48 83 FA ?? 48 0F 43 44 24 ?? 44 + 88 0C 08 C6 44 08 ?? ?? EB ?? 45 33 C0 41 8D 50 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 + 83 C3 ?? 48 3B DF 75 ?? 4C 89 BD ?? ?? ?? ?? 48 8B 46 ?? 48 3B 46 ?? 74 ?? 4C 89 38 + 4C 89 78 ?? 4C 89 78 ?? 41 B8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B C8 E8 ?? ?? ?? ?? 4C + 89 7C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? 48 83 46 ?? ?? EB ?? 4C 8D 44 + 24 ?? 48 8B D0 48 8B CE E8 ?? ?? ?? ?? 90 48 8B 54 24 ?? 48 83 FA ?? 72 ?? 48 FF C2 + 48 8B 4C 24 ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 + 48 83 C0 ?? 48 83 F8 ?? 77 ?? E8 ?? ?? ?? ?? 4C 89 7C 24 ?? 48 C7 44 24 ?? ?? ?? ?? + ?? C6 44 24 ?? ?? 41 B8 ?? ?? ?? ?? 48 8D 54 24 ?? 49 8B CE FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? 49 8B CE FF 15 ?? ?? ?? ?? 48 8B C6 48 81 C4 } - $search_files_4 = { - 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 - ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 - 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 - ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 - 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 - ?? 50 FF D6 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? F6 44 24 ?? - ?? 8D 44 24 ?? 50 53 8D 84 24 ?? ?? ?? ?? 50 74 ?? FF D7 8D 84 24 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? EB ?? FF D7 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8B D0 8D 7A ?? 66 8B 0A 83 - C2 ?? 66 85 C9 75 ?? 2B D7 D1 FA 83 FA ?? 75 ?? 66 83 78 ?? ?? 74 ?? 8D 8C 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? - 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B 8B E5 5D C2 + $set_default_icon_p1 = { + 48 89 5C 24 ?? 48 89 4C 24 ?? 55 56 57 41 54 41 55 41 56 41 57 48 81 EC ?? ?? ?? ?? + 48 8B F1 45 33 ED 44 89 6C 24 ?? 4C 8B 35 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 4C 8B F8 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 8B C8 49 2B CE 49 3B CF 0F 82 ?? ?? + ?? ?? 4C 8D 25 ?? ?? ?? ?? 48 83 3D ?? ?? ?? ?? ?? 4C 0F 43 25 ?? ?? ?? ?? 4C 89 6C + 24 ?? 4C 89 6C 24 ?? 4C 89 6C 24 ?? 4B 8D 2C 37 BB ?? ?? ?? ?? 48 8D 7C 24 ?? 48 3B + EB 0F 86 ?? ?? ?? ?? 48 8B DD 48 83 CB ?? 48 3B D8 76 ?? 48 8B D8 48 B8 ?? ?? ?? ?? + ?? ?? ?? ?? 48 8D 0C 00 EB ?? B8 ?? ?? ?? ?? 48 3B D8 48 0F 42 D8 48 8D 4B ?? 48 B8 + ?? ?? ?? ?? ?? ?? ?? ?? 48 3B C8 0F 87 ?? ?? ?? ?? 48 03 C9 48 81 F9 ?? ?? ?? ?? 72 + ?? 48 8D 41 ?? 48 3B C1 0F 86 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? + ?? ?? ?? 48 8D 78 ?? 48 83 E7 ?? 48 89 47 ?? EB ?? 48 85 C9 74 ?? E8 ?? ?? ?? ?? 48 + 8B F8 EB ?? 49 8B FD 48 89 7C 24 ?? 48 89 6C 24 ?? 48 89 5C 24 ?? 4B 8D 1C 36 4C 8B } - $encrypt_files_1 = { - BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 6A ?? FF D6 0F 10 05 ?? ?? ?? ?? 8B F8 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 50 0F 11 07 89 3D ?? ?? ?? ?? 0F 10 05 ?? ?? ?? ?? 0F 11 47 ?? 0F 10 05 ?? - ?? ?? ?? 0F 11 47 ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 8D - 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 FF E9 ?? ?? ?? ?? 8D 45 ?? 50 8D - 45 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? FF 15 ?? ?? - ?? ?? 85 C0 75 ?? 33 FF E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 45 ?? 50 - FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 FF E9 ?? ?? ?? ?? 8D 45 ?? 50 FF 75 ?? 6A ?? FF 75 - ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 FF EB ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B CF 8D 51 + $set_default_icon_p2 = { + C3 49 8B D4 48 8B CF E8 ?? ?? ?? ?? 48 8D 0C 3B 4F 8D 04 3F 48 8D 15 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 66 44 89 2C 6F BB ?? ?? ?? ?? 89 5C 24 ?? 48 8D 54 24 ?? 48 83 7C 24 ?? + ?? 48 0F 43 54 24 ?? 48 8D 84 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 84 24 ?? ?? ?? ?? + 48 89 44 24 ?? 4C 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 44 89 6C 24 ?? 45 33 C9 45 33 + C0 48 C7 C1 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 48 8B CE 48 83 7E ?? ?? 72 ?? + 48 8B 0E 8B 46 ?? 03 C0 89 44 24 ?? 48 89 4C 24 ?? 44 8B CB 45 33 C0 48 8D 15 ?? ?? + ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 45 33 C9 45 33 C0 33 D2 B9 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 45 33 C9 45 33 C0 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? EB ?? 4C 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 4C 24 + ?? 45 33 C9 44 8B C0 33 D2 B9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 E3 ?? 89 5C 24 ?? 48 + 8B 54 24 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B C1 48 81 + FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 77 ?? + E8 ?? ?? ?? ?? 4C 89 6C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 66 44 89 6C 24 ?? 48 8B CE + E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5E 41 5D 41 5C + 5F 5E 5D C3 } - $encrypt_files_2 = { - 8A 01 41 84 C0 75 ?? 2B CA 8D 45 ?? 51 50 6A ?? 6A ?? 6A ?? 6A ?? FF 75 ?? 89 4D ?? - 89 4D ?? FF D3 85 C0 75 ?? 33 FF EB ?? FF 75 ?? FF D6 FF 75 ?? 8B F0 6A ?? 56 E8 ?? - ?? ?? ?? FF 75 ?? 57 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? FF 75 ?? 50 56 6A ?? 6A ?? - 6A ?? FF 75 ?? FF D3 8B F8 F7 DF 1B FF 23 FE 8B 35 ?? ?? ?? ?? 8B D7 8D 4A ?? 66 90 - 8A 02 42 84 C0 75 ?? 2B D1 8B CF E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8D 50 ?? 8A 08 40 84 - C9 75 ?? 2B C2 57 A3 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 81 3D ?? ?? ?? ?? ?? ?? - ?? ?? 0F 82 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 + $cmd_prompt = { + 48 89 5C 24 ?? 48 89 7C 24 ?? 55 48 8B EC 48 83 EC ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 + 48 89 45 ?? 48 8B D9 4C 8D 05 ?? ?? ?? ?? 33 FF 48 8D 4D ?? 33 D2 48 89 7D ?? E8 ?? + ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 48 85 DB 75 ?? 48 8B 4D ?? 48 85 C9 0F 84 ?? ?? + ?? ?? 33 D2 E8 ?? ?? ?? ?? 48 8B 4D ?? 8B D8 E8 ?? ?? ?? ?? 85 DB 40 0F 94 C7 E9 ?? + ?? ?? ?? 48 8B 45 ?? 48 8D 0D ?? ?? ?? ?? 48 89 45 ?? 48 89 4D ?? 48 89 5D ?? 48 89 + 7D ?? 48 85 C0 74 ?? E8 ?? ?? ?? ?? 8B 18 E8 ?? ?? ?? ?? 45 33 C9 4C 8D 45 ?? 33 C9 + 89 38 48 8B 55 ?? E8 ?? ?? ?? ?? 48 8B F8 83 F8 ?? 74 ?? E8 ?? ?? ?? ?? 89 18 EB ?? + E8 ?? ?? ?? ?? 83 38 ?? 74 ?? E8 ?? ?? ?? ?? 83 38 ?? 74 ?? 48 8B 4D ?? E8 ?? ?? ?? + ?? 83 CF ?? EB ?? E8 ?? ?? ?? ?? 89 18 48 8D 15 ?? ?? ?? ?? 45 33 C9 4C 8D 45 ?? 48 + 89 55 ?? 33 C9 E8 ?? ?? ?? ?? 48 8B F8 48 8B 4D ?? E8 ?? ?? ?? ?? 8B C7 48 8B 4D ?? + 48 33 CC E8 ?? ?? ?? ?? 4C 8D 5C 24 ?? 49 8B 5B ?? 49 8B 7B ?? 49 8B E3 5D C3 } - $encrypt_files_3 = { - 55 8B EC 83 EC ?? 57 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B C1 68 ?? ?? ?? ?? 50 - 89 45 ?? FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 75 ?? 0B C0 5F 8B E5 5D C3 53 6A ?? 57 FF - 15 ?? ?? ?? ?? 8B D8 83 FB ?? 75 ?? FF 75 ?? 57 FF 15 ?? ?? ?? ?? 8B D8 56 B8 ?? ?? - ?? ?? 6A ?? 3B D8 0F 47 D8 53 6A ?? 6A ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? - 75 ?? 5E 5B 0B C0 5F 8B E5 5D C3 6A ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 56 8B - 35 ?? ?? ?? ?? 89 45 ?? FF D6 57 FF D6 E8 ?? ?? ?? ?? 0F 10 05 ?? ?? ?? ?? 0F 11 05 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B F8 BE ?? ?? ?? ?? 0F 10 05 ?? ?? ?? ?? 0F 11 - 05 ?? ?? ?? ?? 85 DB 74 + $exclude_from_encryption = { + 66 89 75 ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D + 4D ?? E8 ?? ?? ?? ?? 90 45 33 C0 48 8D 55 ?? 48 8B CB E8 ?? ?? ?? ?? 48 8B F8 48 8B + 55 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4D ?? 48 8B C1 48 81 FA ?? ?? + ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 48 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? 66 89 75 ?? 48 83 FF ?? 0F 85 + ?? ?? ?? ?? 48 89 75 ?? 48 89 75 ?? 48 89 75 ?? 48 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? + 66 89 75 ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D + 4D ?? E8 ?? ?? ?? ?? 90 45 33 C0 48 8D 55 ?? 48 8B CB E8 ?? ?? ?? ?? 48 8B F8 48 8B + 55 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4D ?? 48 8B C1 48 81 FA ?? ?? + ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 48 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? 66 89 75 ?? 48 83 FF ?? 0F 85 + ?? ?? ?? ?? 48 89 75 ?? 48 89 75 ?? 48 89 75 ?? 48 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? + 66 89 75 ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D + 4D ?? E8 ?? ?? ?? ?? 90 45 33 C0 48 8D 55 ?? 48 8B CB E8 ?? ?? ?? ?? 48 8B F8 48 8B + 55 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4D ?? 48 8B C1 48 81 FA ?? ?? + ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 } - $encrypt_files_4 = { - 8A 0C 06 8D 40 ?? 30 48 ?? 83 EA ?? 75 ?? 8B CF E8 ?? ?? ?? ?? 8B F7 83 C7 ?? 83 EB - ?? 75 ?? 8B 45 ?? 0F 10 06 50 0F 11 05 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 83 C4 ?? 8B F2 + $encrypt_files_v1 = { + 41 83 CC ?? 44 89 64 24 ?? 48 8D 8C 24 ?? ?? ?? ?? 48 83 FF ?? 48 0F 43 8C 24 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 8B F8 41 83 E4 ?? 44 89 64 24 ?? 48 8B 94 24 ?? ?? ?? ?? 48 + 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? + ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 89 94 24 ?? ?? ?? ?? 48 8B 49 + ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 9C 24 ?? + ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 9C 24 ?? ?? 00 00 40 F6 C7 ?? 74 + ?? 49 8B CF E8 ?? ?? ?? ?? 90 48 BE ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 3D ?? ?? ?? ?? 4C + 8D 35 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? E9 ?? ?? ?? ?? 49 8B CF E8 ?? ?? ?? ?? C6 84 + 24 ?? ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B F0 48 + 89 9C 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 4C 8B 70 ?? 48 + 83 78 ?? ?? 72 ?? 48 8B 30 48 8D 8C 24 ?? ?? ?? ?? 49 83 FE ?? 73 ?? 41 B8 ?? ?? ?? + ?? 48 8B D6 E8 ?? ?? ?? ?? 4C 89 B4 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? + ?? EB ?? 4C 89 AC 24 ?? ?? ?? ?? 49 8B FE 48 83 CF ?? 48 89 BC 24 ?? ?? ?? ?? 49 3B + FD 49 0F 47 FD 48 8D 57 ?? E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 4E 8D 04 75 ?? ?? + ?? ?? 48 8B D6 48 8B C8 E8 ?? ?? ?? ?? 4C 89 B4 24 ?? ?? ?? ?? 48 89 BC 24 } - $encrypt_files_5 = { - 66 8B 02 83 C2 ?? 66 85 C0 75 ?? BB ?? ?? ?? ?? 2B D6 8D 7B ?? 66 8B 47 ?? 83 C7 ?? - 66 85 C0 75 ?? 8B CA C1 E9 ?? F3 A5 8B CA 83 E1 ?? 83 C3 ?? F3 A4 66 8B 43 ?? 83 C3 - ?? 66 85 C0 75 ?? 8B FB B9 ?? ?? ?? ?? 8B 5D ?? BE ?? ?? ?? ?? 68 ?? ?? ?? ?? F3 A5 - 53 FF 15 ?? ?? ?? ?? 6A ?? 8B F0 6A ?? 56 FF 15 ?? ?? ?? ?? 56 FF 35 ?? ?? ?? ?? 6A - ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? - 53 FF 15 ?? ?? ?? ?? 5E 5B 33 C0 5F 8B E5 5D C3 + $find_system_volumes_v2 = { + BA ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 48 8B F8 0F 1F 44 00 ?? 4C 8D 8D ?? + ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 89 74 24 ?? 48 89 74 24 ?? 48 8D 85 ?? ?? ?? ?? 48 89 44 24 ?? + 48 89 74 24 ?? 45 33 C9 45 33 C0 33 D2 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 + 0F 84 ?? ?? ?? ?? F7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 4C 8D 04 00 48 8D 85 ?? ?? ?? ?? 49 03 C0 48 89 74 24 ?? 48 89 74 + 24 ?? 48 89 74 24 ?? 48 89 74 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 66 89 74 24 ?? 48 8D + 8D ?? ?? ?? ?? 48 3B C8 74 ?? 49 D1 F8 48 8D 95 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? + ?? ?? 90 48 8B 43 ?? 48 3B 43 ?? 74 ?? 48 89 30 48 89 70 ?? 48 89 70 ?? 41 B8 ?? ?? + ?? ?? 48 8D 54 24 ?? 48 8B C8 E8 ?? ?? ?? ?? 48 89 74 24 ?? 48 C7 44 24 ?? ?? ?? ?? + ?? 66 89 74 24 ?? 48 83 43 ?? ?? EB ?? 4C 8D 44 24 ?? 48 8B D0 48 8B CB E8 ?? ?? ?? + ?? 90 48 8B 54 24 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B + C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 + ?? 77 ?? E8 ?? ?? ?? ?? 48 89 74 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 66 89 74 24 ?? 41 + B8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B CF FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 + 8B CF FF 15 ?? ?? ?? ?? 48 8B C3 48 8B 9C 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5F 5E + 5D C3 + } + $drop_ransom_note = { + 48 83 3D ?? ?? ?? ?? ?? 48 0F 43 15 ?? ?? ?? ?? 4C 8B 05 ?? ?? ?? ?? 48 8D 4D ?? E8 + ?? ?? ?? ?? 48 8B D8 4C 89 75 ?? 4C 89 75 ?? 4C 89 75 ?? 45 8D 46 ?? 48 8B D0 48 8D + 4D ?? E8 ?? ?? ?? ?? 4C 89 73 ?? 48 C7 43 ?? ?? ?? ?? ?? 66 44 89 33 BE ?? ?? ?? ?? + 89 75 ?? 83 E6 ?? 89 75 ?? 48 8B 55 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 + 8B 4D ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 + C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 75 ?? 48 C7 45 ?? ?? ?? ?? + ?? 66 44 89 75 ?? 48 8D 4D ?? 48 83 7D ?? ?? 48 0F 43 4D ?? 4C 89 74 24 ?? C7 44 24 + ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 45 33 C9 45 33 C0 BA ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 48 8B D8 48 83 F8 ?? 74 ?? 4C 89 74 24 ?? 45 33 C9 41 B8 ?? ?? ?? ?? 48 8D 15 + ?? ?? ?? ?? 48 8B C8 FF 15 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 83 E6 ?? 89 75 ?? + 48 8B 55 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4D ?? 48 8B C1 48 81 FA + ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? 66 44 89 75 ?? 48 8B 57 + ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 0F 48 81 FA ?? ?? ?? ?? 72 ?? 48 + 83 C2 ?? 4C 8B 41 ?? 49 2B C8 48 8D 41 ?? 48 83 F8 ?? 77 ?? 49 8B C8 E8 ?? ?? ?? ?? + 4C 89 77 ?? 48 C7 47 ?? ?? ?? ?? ?? 66 44 89 37 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? + 49 8B 73 ?? 49 8B 7B + } + $encrypt_files_v2_p1 = { + BA ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 75 ?? 48 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 90 48 8D 05 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 + 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 85 C9 0F 84 ?? ?? ?? ?? 49 8B FA 49 8B D1 4D 85 D2 + 74 ?? 4C 8B C1 4D 2B C1 0F B7 02 66 41 39 04 10 75 ?? 48 83 C2 ?? 48 83 EF ?? 75 ?? + 49 2B CB 48 D1 F9 E9 ?? ?? ?? ?? 48 83 C1 ?? E9 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 + 8B CB FF 15 ?? ?? ?? ?? 85 C0 75 ?? 48 8B CB FF 15 ?? ?? ?? ?? 90 48 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 90 48 8D 05 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? + 48 89 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 8B BD ?? ?? ?? ?? B2 ?? 48 8D 4C 24 ?? E8 ?? + ?? ?? ?? B2 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 0B 00 F3 0F 7F 45 ?? + 48 89 75 ?? 48 89 75 ?? 48 8D 45 ?? 48 89 85 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 ?? + C6 45 ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 45 ?? 48 C7 45 ?? ?? ?? ?? ?? C6 45 + ?? ?? 48 8D 45 ?? 83 E0 ?? 48 8D 44 05 ?? 48 89 45 ?? 89 75 ?? C7 45 ?? ?? ?? ?? ?? + 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 05 ?? + ?? ?? ?? 48 89 44 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 + 44 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 + 8D 05 ?? ?? ?? ?? 48 89 45 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 + C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C + 8B E8 48 89 44 24 ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B F8 48 89 85 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 49 + } + $encrypt_files_v2_p2 = { + 8B D5 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8B D7 48 8D 0D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8B CF 41 B8 ?? ?? ?? ?? 49 8B D5 + 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 49 8B D5 48 8B 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 83 C1 ?? 41 B8 ?? ?? ?? ?? 48 8B D7 E8 ?? ?? ?? ?? + BF ?? ?? ?? ?? 4C 3B FF 0F 8D ?? ?? ?? ?? F2 0F 10 35 ?? ?? ?? ?? 48 8B FE 49 8B C7 + 48 2B C7 48 99 83 E2 ?? 48 03 C2 48 C1 F8 ?? 4C 8B F0 F2 0F 59 35 ?? ?? ?? ?? 0F 57 + C0 F2 48 0F 2A C0 F2 0F 59 F0 F2 48 0F 2C CE 48 85 C9 0F 85 ?? ?? ?? ?? 4D 85 FF 0F + 8E ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 ?? 48 8D 54 24 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? + 90 48 8D 35 ?? ?? ?? ?? 48 89 75 ?? 4C 8D 35 ?? ?? ?? ?? 4C 89 75 ?? 48 8D 05 ?? ?? + ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 + ?? 4D 8B CF 45 33 C0 48 8B D3 48 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 49 + 81 FF ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? F2 0F 10 35 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 + ?? 48 8D 54 24 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 + 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? + 48 89 85 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 ?? 4C 8B CF 45 33 C0 48 8B D3 49 8B CE + E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 99 48 F7 F9 4C 8B E8 48 85 C0 75 ?? 48 8D 45 ?? 48 + } + $encrypt_files_v2_p3 = { + 89 44 24 ?? 48 8D 54 24 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 35 ?? ?? ?? ?? 48 89 + 75 ?? 4C 8D 35 ?? ?? ?? ?? 4C 89 75 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? + ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 ?? 4D 8B CF 45 33 C0 48 8B D3 + 48 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8B 6C 24 ?? E9 ?? ?? ?? ?? 4D 85 F6 0F 8E ?? + ?? ?? ?? 4D 8B FD 49 C1 E7 ?? 4C 8B A5 ?? ?? ?? ?? 90 48 8D 45 ?? 48 89 44 24 ?? 48 + 8D 54 24 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 + ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 + 85 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 ?? 41 B9 ?? ?? ?? ?? 4C 8B C7 48 8B D3 49 8B + CC E8 ?? ?? ?? ?? 49 03 F5 49 03 FF 49 3B F6 7C ?? 4C 8B A5 ?? ?? ?? ?? 4C 8B 6C 24 + ?? 48 8D 35 ?? ?? ?? ?? 4C 8D 35 ?? ?? ?? ?? 4C 8D 8D ?? ?? ?? ?? 4C 8B C3 48 8B 95 + ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 4D 8B C4 + 48 8D 95 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B 95 ?? ?? ?? ?? 48 + 85 D2 74 ?? 48 8B FA 33 C0 B9 ?? ?? ?? ?? F3 AA 48 8B CA E8 ?? ?? ?? ?? 90 4D 85 ED + 74 ?? 49 8B FD 33 C0 B9 ?? ?? ?? ?? F3 AA 49 8B CD E8 ?? ?? ?? ?? 90 48 89 74 24 ?? + 4C 89 74 24 } condition: - uint16(0)==0x5A4D and ( all of ($search_files_*)) and ( all of ($encrypt_files_*)) + uint16(0)==0x5A4D and ((($find_files) and ( all of ($find_system_volumes_v1_p*)) and ( all of ($set_default_icon_p*)) and ($cmd_prompt) and ($exclude_from_encryption) and ($encrypt_files_v1)) or (($find_files) and ($cmd_prompt) and ($find_system_volumes_v2) and ($drop_ransom_note) and ( all of ($encrypt_files_v2_p*)))) } -rule REVERSINGLABS_Win32_Ransomware_Thanatos : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Delphimorix : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Thanatos ransomware." + description = "Yara rule that detects Delphimorix ransomware." author = "ReversingLabs" - id = "190adbd0-30a7-5619-ab70-3ab031ece2f7" - date = "2020-11-13" - modified = "2020-11-13" + id = "1f964601-9819-5597-ba6e-db3a30e3aa5a" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Thanatos.yara#L1-L85" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "a51fa9cf1a08e4cd252a8b385be3bfde909585e2a799baaede977e40ecff5313" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Delphimorix.yara#L1-L67" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6d401d488d57b2d75e93a1dfd47ece687a5791d1f0a52768300f4af8a8787212" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -25034,81 +25933,283 @@ rule REVERSINGLABS_Win32_Ransomware_Thanatos : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Thanatos" + tc_detection_name = "Delphimorix" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 57 50 89 85 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? 51 FF D6 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 89 85 ?? ?? ?? ?? EB ?? 8D 49 ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 83 C4 ?? C6 03 ?? FF - 15 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 B9 ?? ?? - ?? ?? F7 F9 52 53 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 4F 75 ?? 8B 95 ?? ?? ?? - ?? 52 8D 85 ?? ?? ?? ?? 50 C6 43 ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? 51 FF D6 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 FF D6 F6 85 ?? ?? ?? ?? ?? - 74 ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D7 85 C0 0F 84 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 FF D7 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 - 50 8D 8D ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8D BD - ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8B F8 72 ?? 8B - 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 FF ?? 74 ?? 53 8D 9D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? - ?? 8B E5 5D C3 + $encrypt_files = { + 55 8B EC 83 C4 ?? 53 56 57 33 D2 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 + 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 6A ?? 8B + 4D ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 68 ?? ?? ?? ?? 8D 45 ?? B9 ?? ?? ?? + ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 4D ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8B C3 + 8B 10 FF 12 52 50 B9 ?? ?? ?? ?? 8B D3 8B C6 E8 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B + C6 E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 + ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 59 59 5D C3 + } + $find_files_p1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? + ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 8B D9 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? + ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 80 7C 02 + ?? ?? 75 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B D0 4A 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? + ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 8B D0 83 CA ?? 3B D0 75 ?? 80 FB ?? 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 + } + $find_files_p2 = { + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CB 8B 55 ?? E8 ?? ?? ?? ?? E9 ?? + ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B + C6 83 C8 ?? 3B C6 75 ?? 80 FB ?? 75 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? FF 75 ?? 68 ?? ?? ?? + ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 8B CB 8B 55 ?? E8 ?? ?? ?? ?? EB ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? C3 + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) +} +rule REVERSINGLABS_Linux_Ransomware_Luckyjoe : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects LuckyJoe ransomware." + author = "ReversingLabs" + id = "8dc98d71-b79d-5b09-9383-11f2b57baeb5" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Linux.Ransomware.LuckyJoe.yara#L1-L146" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "1e7df2c45bee072af233cf8f355a84ec931fe96afa3fbdcd225dded1b75ea961" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "LuckyJoe" + tc_detection_factor = 5 + importance = 25 + + strings: + $main_call_p1 = { + 55 48 89 E5 48 81 EC ?? ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? 48 + C7 45 ?? ?? ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? + 48 89 45 ?? 48 8B 55 ?? 48 8B 45 ?? 48 89 D6 48 89 C7 E8 ?? ?? ?? ?? 48 8D 75 ?? 48 + 8B 45 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? BE ?? ?? + ?? ?? BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 89 C7 E8 + ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? + ?? 48 89 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? E8 ?? ?? + ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 35 ?? ?? ?? ?? 48 83 EC ?? 48 8B 45 + ?? 6A ?? 41 B9 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 C7 + E8 ?? ?? ?? ?? 48 83 C4 ?? 48 8B 15 ?? ?? ?? ?? 48 8B 45 ?? 48 89 D6 48 89 C7 E8 ?? + ?? ?? ?? 48 8B 45 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? + ?? ?? 48 98 48 89 45 ?? 48 8B 45 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 + } + $main_call_p2 = { + 89 C7 E8 ?? ?? ?? ?? 48 98 48 89 45 ?? 48 8B 45 ?? 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? + ?? 48 89 45 ?? 48 8B 45 ?? 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 + ?? 89 C2 48 8B 4D ?? 48 8B 45 ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 89 C2 + 48 8B 4D ?? 48 8B 45 ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? ?? 48 8B 55 ?? 48 8B 45 ?? 48 + 01 D0 C6 00 ?? 48 8B 55 ?? 48 8B 45 ?? 48 01 D0 C6 00 ?? 48 8B 45 ?? 48 8B 55 ?? 48 + 89 D6 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 83 7D ?? ?? 75 ?? BF ?? ?? ?? ?? E8 ?? + ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C6 BF ?? ?? ?? ?? B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? B8 + ?? ?? ?? ?? E9 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 45 ?? + 48 83 7D ?? ?? 74 ?? 48 8B 55 ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 B8 + } + $main_call_p3 = { + E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 79 ?? 48 8B 45 ?? 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? + ?? ?? E9 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 89 C7 E8 ?? ?? + ?? ?? 48 C7 45 ?? ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 45 + ?? 48 83 7D ?? ?? 74 ?? EB ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? + ?? ?? 48 8B 55 ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 89 45 ?? 83 7D ?? ?? 79 ?? 48 8B 45 ?? 89 C7 E8 ?? ?? ?? ?? EB ?? 48 8B 45 ?? 48 89 + C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 89 C7 E8 ?? ?? ?? ?? EB ?? BF ?? ?? ?? ?? E8 ?? ?? ?? + ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? + ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 48 98 48 8B 84 + C5 ?? ?? ?? ?? 48 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 48 98 + 48 8B 84 C5 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 83 45 ?? ?? 83 7D ?? ?? 74 ?? BF ?? + ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 + ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? C9 C3 } $encrypt_files_p1 = { - 55 8B EC 83 EC ?? 53 56 57 68 ?? ?? ?? ?? 33 DB 6A ?? 53 8B F0 53 8D 45 ?? 33 FF 50 - 89 7D ?? 89 5D ?? 89 5D ?? 89 5D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 55 - ?? 8D 4D ?? 51 53 53 68 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B - C6 8D 50 ?? 8A 08 40 84 C9 75 ?? 53 2B C2 50 8B 45 ?? 56 50 FF 15 ?? ?? ?? ?? 85 C0 - 0F 84 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8D 4D ?? 51 6A ?? 52 68 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 50 8D 4D ?? 51 53 53 6A ?? 53 8B - 1D ?? ?? ?? ?? 52 89 45 ?? FF D3 85 C0 74 ?? 8B 45 ?? 8B 3D ?? ?? ?? ?? 50 6A ?? FF - D7 50 FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 8B 4D ?? 8B 55 ?? 8B 02 51 50 56 E8 ?? ?? - ?? ?? 8B 4D ?? 8B 45 ?? 83 C4 ?? 51 8D 55 ?? 52 56 6A ?? 6A ?? 6A ?? 50 FF D3 85 C0 - 74 ?? 8B 5D ?? 8B 0B 51 6A ?? FF D7 50 FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 89 10 89 - 33 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 7D ?? 33 DB 8B 55 ?? 52 FF - 15 ?? ?? ?? ?? 8B 45 ?? 53 50 FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C2 + 55 48 89 E5 53 48 81 EC ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? BA ?? + ?? ?? ?? B9 ?? ?? ?? ?? 48 89 C7 48 89 D6 F3 48 A5 48 89 F2 48 89 F8 0F B7 0A 66 89 + 08 48 8D 40 ?? 48 8D 52 ?? 48 C7 45 ?? ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + 48 C7 45 ?? ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 89 D7 + F3 48 AB 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 83 7D ?? ?? 75 + ?? 48 8B 85 ?? ?? ?? ?? 48 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? + ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 D6 48 89 C7 + E8 ?? ?? ?? ?? 48 8B 45 ?? 0F B6 40 ?? 3C ?? 0F 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? + 48 89 C7 E8 ?? ?? ?? ?? 48 89 C3 48 8B 45 ?? 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 + 01 D8 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 85 ?? ?? ?? ?? BE ?? ?? + ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 84 C0 74 ?? 48 8B 45 ?? 48 8D 48 ?? 48 8B 95 ?? ?? ?? + ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 48 8B 45 + ?? 48 8D 48 ?? 48 8B 95 ?? ?? ?? ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8B 4D ?? 48 8D 85 ?? ?? ?? ?? 48 89 CE 48 + 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? EB ?? 48 8B 45 ?? 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? + ?? 48 89 C2 48 8B 45 ?? 48 89 C6 48 89 D7 E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 45 ?? 48 } $encrypt_files_p2 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 45 ?? 33 F6 56 68 ?? ?? ?? ?? - 6A ?? 56 6A ?? 68 ?? ?? ?? ?? 53 89 85 ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? 89 B5 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 56 57 FF 15 ?? ?? ?? ?? 8B F0 - 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? - ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 56 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 50 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 E8 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 6A ?? 52 E8 ?? - ?? ?? ?? 83 C4 ?? 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 8D B5 ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 83 C4 ?? 39 70 ?? 72 ?? 8B - 00 50 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 39 B5 ?? ?? ?? ?? - 72 ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 95 ?? ?? - ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 8B 95 ?? ?? ?? ?? 6A ?? 8D - 8D ?? ?? ?? ?? 51 8B 8D ?? ?? ?? ?? 52 51 50 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? - 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? - ?? ?? 8B E5 5D C2 + 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? + ?? EB ?? 48 8D 95 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C6 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 + 89 45 ?? 48 83 7D ?? ?? 75 ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 + 8B 45 ?? 0F B6 40 ?? 3C ?? 0F 85 ?? ?? ?? ?? 48 8B 45 ?? 48 83 C0 ?? BE ?? ?? ?? ?? + 48 89 C7 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 8B 45 ?? 48 83 C0 ?? BE ?? ?? ?? + ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 8B 45 ?? 48 83 C0 ?? 48 89 45 + ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 C3 48 8B 45 ?? 48 89 C7 E8 ?? + ?? ?? ?? 48 01 D8 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 85 ?? ?? ?? + ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 84 C0 74 ?? 48 8B 45 ?? 48 8D 48 ?? 48 8B + 95 ?? ?? ?? ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB + ?? 48 8B 45 ?? 48 8D 48 ?? 48 8B 95 ?? ?? ?? ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 + C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 83 7D ?? ?? 0F + 85 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5D C3 + } + $encrypt_internal_message_p1 = { + 55 48 89 E5 53 48 83 EC ?? 48 89 7D ?? 48 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? BF ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 89 45 ?? 48 8B + 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 83 C0 ?? 48 98 48 89 C7 E8 ?? ?? ?? + ?? 48 89 45 ?? 8B 45 ?? 83 C0 ?? 48 63 D0 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? + ?? ?? ?? 8B 45 ?? 48 63 D0 48 8B 4D ?? 48 8B 45 ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? ?? + 8B 45 ?? 48 98 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 8B 45 ?? 83 E8 ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 66 0F EF C0 F2 0F 2A 45 ?? + 66 0F EF C9 F2 0F 2A 4D ?? F2 0F 5E C1 E8 ?? ?? ?? ?? F2 0F 2C C0 89 45 ?? 8B 45 ?? + 0F AF 45 ?? 48 98 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 8B 45 ?? 0F AF 45 ?? 48 63 D0 + 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 8B 45 ?? 0F AF 45 ?? 89 C3 48 8B + 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 C6 8B 45 ?? 89 C1 89 DA BF ?? ?? ?? ?? B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? E9 ?? ?? ?? ?? 8B 45 ?? 2B 45 ?? 3B 45 ?? 7D ?? 8B 45 ?? 2B 45 ?? 89 45 ?? 8B 45 + ?? 48 63 D0 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 8B 45 ?? 2B 45 ?? 89 + } + $encrypt_internal_message_p2 = { + C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 48 63 D0 48 8B 45 ?? 48 8D + 34 02 48 8B 4D ?? 48 8B 55 ?? 8B 45 ?? 41 B8 ?? ?? ?? ?? 89 C7 E8 ?? ?? ?? ?? 89 45 + ?? 8B 45 ?? 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? E8 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C2 48 8B 45 ?? 48 89 C6 48 89 D7 E8 ?? ?? ?? ?? 48 + 8B 05 ?? ?? ?? ?? 48 8B 55 ?? BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? + 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? + ?? ?? 8B 45 ?? 48 63 D0 8B 45 ?? 48 63 C8 48 8B 45 ?? 48 01 C1 48 8B 45 ?? 48 89 C6 + 48 89 CF E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 C6 BF ?? ?? ?? ?? + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 01 45 ?? 8B 45 ?? 01 45 ?? 48 8B 45 ?? 48 89 + C7 E8 ?? ?? ?? ?? 83 45 ?? ?? 8B 45 ?? 3B 45 ?? 0F 8E ?? ?? ?? ?? 48 8B 45 ?? 48 89 + C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 8B 4D ?? 48 8B 45 ?? BA ?? ?? + ?? ?? 89 CE 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? + 48 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 45 ?? 48 83 C4 ?? 5B 5D + C3 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) + uint32(0)==0x464C457F and ( all of ($main_call_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($encrypt_internal_message_p*)) } -rule REVERSINGLABS_Win32_Ransomware_HDMR : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win64_Ransomware_Whiteblackcrypt : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects HDMR ransomware." + description = "Yara rule that detects WhiteBlackCrypt ransomware." author = "ReversingLabs" - id = "97b5020c-6cb1-5ec6-84a4-2f35eae761c2" + id = "9855c10d-563d-54e0-bc79-945daef947de" + date = "2021-07-05" + modified = "2021-07-05" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.WhiteBlackCrypt.yara#L1-L91" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "37b95cc3412f2f2d02d19c4c15b529c4f67453cb195627b5bab2f353e7602354" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "WhiteBlackCrypt" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files = { + 41 57 41 56 41 55 41 54 55 57 56 53 48 83 EC ?? 4C 8D 3D ?? ?? ?? ?? 45 31 F6 49 89 + CD E8 ?? ?? ?? ?? 48 85 C0 49 89 C4 0F 84 ?? ?? ?? ?? 4C 89 E1 E8 ?? ?? ?? ?? 48 85 + C0 0F 84 ?? ?? ?? ?? 48 8D 68 ?? 4C 89 FA 48 89 E9 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D + 15 ?? ?? ?? ?? 48 89 E9 E8 ?? ?? ?? ?? 85 C0 74 ?? 44 89 F0 48 83 C9 ?? 48 89 EF F2 + AE 4C 89 EF 48 89 CB 48 83 C9 ?? F2 AE 48 F7 D3 48 F7 D1 01 D9 48 63 D9 48 89 D9 E8 + ?? ?? ?? ?? 48 89 D9 4C 89 EA 48 89 C6 48 89 C7 44 89 F0 F3 AA 48 89 F1 E8 ?? ?? ?? + ?? 48 8D 15 ?? ?? ?? ?? 48 89 F1 E8 ?? ?? ?? ?? 48 89 EA 48 89 F1 E8 ?? ?? ?? ?? 48 + 89 F1 E8 ?? ?? ?? ?? 48 89 F1 85 C0 74 ?? E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? 48 89 + F1 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 89 E1 48 83 C4 ?? 5B 5E 5F 5D 41 5C 41 5D 41 5E + 41 5F E9 ?? ?? ?? ?? 48 83 C4 ?? 5B 5E 5F 5D 41 5C 41 5D 41 5E 41 5F C3 + } + $encrypt_files = { + 41 55 41 54 55 57 56 53 48 83 EC ?? 48 8D 15 ?? ?? ?? ?? 31 F6 4C 8D 2D ?? ?? ?? ?? + 48 89 CD E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 89 C3 E8 ?? ?? ?? ?? 48 89 C7 49 89 D9 41 + B8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 F9 E8 ?? ?? ?? ?? 85 C0 49 89 C4 74 ?? 81 FE ?? + ?? ?? ?? 7F ?? 45 89 E0 48 89 FA 4C 89 E9 E8 ?? ?? ?? ?? 45 31 C0 89 F2 48 89 D9 E8 + ?? ?? ?? ?? 44 01 E6 4D 63 C4 48 89 F9 49 89 D9 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 45 31 + C0 89 F2 48 89 D9 E8 ?? ?? ?? ?? EB ?? 48 89 F9 48 89 EF E8 ?? ?? ?? ?? 48 89 D9 E8 + ?? ?? ?? ?? 31 C0 48 83 C9 ?? F2 AE 48 89 CE 48 F7 D6 48 89 F1 48 83 C1 ?? E8 ?? ?? + ?? ?? 48 89 EA 48 89 C1 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? + 48 89 E9 48 89 C2 48 83 C4 ?? 5B 5E 5F 5D 41 5C 41 5D E9 + } + $register_service_p1 = { + 57 56 53 48 81 EC ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 31 C0 41 B9 ?? ?? ?? ?? 48 8D 94 + 24 ?? ?? ?? ?? 48 89 CB B9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 89 D7 F3 AB 48 8D + 44 24 ?? 48 89 54 24 ?? 48 C7 C1 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 15 ?? ?? ?? ?? 48 + C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 80 BC 24 ?? ?? ?? ?? ?? 48 8B 35 ?? ?? ?? + ?? 0F 85 ?? ?? ?? ?? 48 8D 9C 24 ?? ?? ?? ?? 31 C9 41 B8 ?? ?? ?? ?? 48 89 DA FF 15 + ?? ?? ?? ?? 48 8D 44 24 ?? 45 31 C0 41 B9 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 15 ?? ?? + ?? ?? 48 C7 C1 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 48 8D 05 ?? ?? ?? ?? 48 8B + 4C 24 ?? 41 B9 ?? ?? ?? ?? 45 31 C0 C7 44 24 ?? ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 + 89 44 24 ?? FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? + 45 31 C0 48 89 D9 FF 15 ?? ?? ?? ?? 31 C0 E9 ?? ?? ?? ?? 31 C9 FF D6 48 85 C0 79 ?? + B9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 31 C9 BA ?? ?? + ?? ?? 48 C1 E0 ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? + ?? 48 8D 35 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? + 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 89 B4 24 ?? ?? ?? ?? 48 8D + } + $register_service_p2 = { + 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 + 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 41 B9 ?? ?? ?? ?? 48 89 F2 48 89 1D ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 89 5C 24 ?? + 48 8B 35 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? + ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF D6 B9 ?? ?? ?? ?? 48 89 C3 FF 15 ?? + ?? ?? ?? BA ?? ?? ?? ?? 48 89 D9 49 89 C0 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D + 54 24 ?? 48 89 C1 FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 41 B9 ?? ?? + ?? ?? 4C 8B 05 ?? ?? ?? ?? 48 89 5C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? + ?? ?? ?? ?? 48 89 44 24 ?? 8B 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? 99 F7 F9 2D ?? ?? ?? ?? 89 44 24 ?? 8B 44 24 ?? 99 F7 F9 31 C9 48 8D 15 ?? ?? ?? + ?? 2D ?? ?? ?? ?? 89 44 24 ?? FF D6 BA ?? ?? ?? ?? 48 89 D9 FF 15 ?? ?? ?? ?? 48 89 + D9 FF 15 ?? ?? ?? ?? 48 8B 35 ?? ?? ?? ?? 48 8D 5C 24 ?? 45 31 C9 45 31 C0 31 D2 48 + 89 D9 FF D6 85 C0 74 ?? 48 89 D9 FF 15 ?? ?? ?? ?? 48 89 D9 FF 15 ?? ?? ?? ?? EB ?? + 8B 84 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5E 5F C3 + } + + condition: + uint16(0)==0x5A4D and ( all of ($register_service_p*)) and ($find_files) and ($encrypt_files) +} +rule REVERSINGLABS_Win32_Ransomware_Cuba : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Cuba ransomware." + author = "ReversingLabs" + id = "b2c81849-9fa6-58b6-b6fe-4d9a5f0923ea" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.HDMR.yara#L1-L161" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "035c6596db8dc14a663679c1f7e682b85963927cc034b01e390cc22fdee3334a" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Cuba.yara#L1-L126" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0a8dea6e38a6407897b994ea119bc8b0712a94363b7b3942dcd32c65ee5548d4" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -25116,149 +26217,182 @@ rule REVERSINGLABS_Win32_Ransomware_HDMR : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "HDMR" + tc_detection_name = "Cuba" tc_detection_factor = 5 importance = 25 strings: $find_files_p1 = { - 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? - ?? ?? 53 56 8B 75 ?? 57 33 C0 68 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? 51 89 74 24 ?? - 66 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 56 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 52 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 8D 8C 24 ?? ?? ?? ?? 51 FF 15 ?? ?? - ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? EB - ?? 8D 49 ?? 8B 74 24 ?? F6 44 24 ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 44 24 ?? - 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 - ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? - 8D 44 24 ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 - C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D + 51 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8B D7 8D 4D ?? E8 ?? + ?? ?? ?? 83 C4 ?? C6 45 ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 72 ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? + 0F B7 00 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? + 0F B7 40 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 + ?? 0F B7 40 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? 83 7D ?? ?? 8D 45 ?? 0F 43 + 45 ?? 0F B7 40 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? B0 ?? EB ?? 32 C0 84 C0 + 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D3 C6 + 45 ?? ?? 8B C8 E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 55 ?? 83 FA ?? 0F 82 ?? ?? ?? ?? 8B 4D + ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 + ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8D 55 ?? + 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 75 ?? 8B 5D ?? 83 FB ?? 8B 7D ?? 8B 45 ?? 0F + 43 F7 83 F8 ?? 75 ?? B9 ?? ?? ?? ?? 8B D0 2B F1 66 8B 04 0E 66 3B 01 75 ?? 83 C1 ?? + 83 EA ?? 75 ?? E9 ?? ?? ?? ?? 8B 45 ?? 83 FB ?? 8D 75 ?? 0F 43 F7 83 F8 ?? 75 ?? B9 + ?? ?? ?? ?? 8B D0 2B F1 66 8B 04 0E 66 3B 01 75 ?? 83 C1 ?? 83 EA ?? 75 ?? E9 ?? ?? + ?? ?? 8B 45 ?? 83 FB ?? 8D 75 ?? 0F 43 F7 83 F8 ?? 75 ?? B9 ?? ?? ?? ?? 8B D0 2B F1 } $find_files_p2 = { - 54 24 ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 44 24 - ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 4C 24 - ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 54 24 - ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 44 24 - ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? 68 - ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 54 24 ?? 68 ?? ?? - ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 33 C0 68 ?? ?? ?? ?? 50 8D - 8C 24 ?? ?? ?? ?? 51 66 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 54 24 ?? 52 - 56 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 51 - E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 83 - C4 ?? 85 F6 74 ?? 8B 44 24 ?? 8D 54 24 ?? 52 50 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? - 8B 0D ?? ?? ?? ?? 83 C4 ?? 3B 0D ?? ?? ?? ?? 7C ?? 8D 49 ?? 6A ?? FF 15 ?? ?? ?? ?? - 8B 15 ?? ?? ?? ?? 3B 15 ?? ?? ?? ?? 7D ?? 68 ?? ?? ?? ?? FF D7 FF 05 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF D3 6A ?? 6A ?? 56 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 8B 74 24 ?? 8D 44 24 ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? 56 FF 15 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D - C3 + 66 8B 04 0E 66 3B 01 75 ?? 83 C1 ?? 83 EA ?? 75 ?? E9 ?? ?? ?? ?? 8B 45 ?? 83 FB ?? + 8D 75 ?? 0F 43 F7 83 F8 ?? 75 ?? B9 ?? ?? ?? ?? 8B D0 2B F1 66 8B 04 0E 66 3B 01 75 + ?? 83 C1 ?? 83 EA ?? 75 ?? E9 ?? ?? ?? ?? 8B 45 ?? 83 FB ?? 8D 75 ?? 0F 43 F7 83 F8 + ?? 75 ?? B9 ?? ?? ?? ?? 8B D0 2B F1 66 8B 04 0E 66 3B 01 75 ?? 83 C1 ?? 83 EA ?? 75 + ?? EB ?? 83 7D ?? ?? 75 ?? 8B 55 ?? 8D 45 ?? 8B 4D ?? 83 FA ?? 0F 43 C1 66 83 38 ?? + 75 ?? 83 FA ?? 8D 45 ?? 0F 43 C1 66 83 78 ?? ?? 75 ?? 83 FA ?? 8D 45 ?? 0F 43 C1 66 + 83 78 ?? ?? 75 ?? 83 FA ?? 8D 45 ?? 0F 43 C1 66 83 78 ?? ?? 74 ?? 8B 8D ?? ?? ?? ?? + 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 5D ?? 8B 7D ?? C6 45 ?? ?? 83 FB ?? 72 ?? 8D 0C 5D ?? + ?? ?? ?? 8B C7 81 F9 ?? ?? ?? ?? 72 ?? 8B 7F ?? 83 C1 ?? 2B C7 83 C0 ?? 83 F8 ?? 0F + 87 ?? ?? ?? ?? 51 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B BD ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B + 9D ?? ?? ?? ?? C6 45 ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B + C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? + ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 88 45 ?? 8B 55 ?? C7 45 + ?? ?? ?? ?? ?? 66 89 45 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA + ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? + ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 + } + $enum_resources = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 + 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B DA 89 5D ?? 8D 45 ?? C7 45 ?? ?? ?? + ?? ?? 50 51 6A ?? 6A ?? 6A ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 32 + C0 E9 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 89 75 ?? 85 F6 74 ?? 66 90 + FF 75 ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 56 8D 45 ?? 50 FF 75 ?? FF 15 + ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 FF 39 7D ?? 76 ?? 83 C6 ?? 83 7E ?? ?? 0F 85 + ?? ?? ?? ?? 83 3E ?? 0F 85 ?? ?? ?? ?? 8B 56 ?? 33 C0 66 89 45 ?? 8B C2 C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 58 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C3 8D 4D + ?? D1 F8 50 52 E8 ?? ?? ?? ?? 8B 5D ?? 8D 45 ?? 50 8B CB C7 45 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? + 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 + E8 ?? ?? ?? ?? 83 C4 ?? F7 46 ?? ?? ?? ?? ?? 74 ?? 8D 4E ?? 8B D3 E8 ?? ?? ?? ?? 47 + 83 C6 ?? 3B 7D ?? 0F 82 ?? ?? ?? ?? 8B 75 ?? E9 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF + 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 94 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B + 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } $encrypt_files_p1 = { - 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? - ?? ?? 53 56 57 33 C0 8B D9 68 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? 51 89 5C 24 ?? 66 - 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 94 24 ?? ?? ?? ?? 52 6A ?? 6A ?? 6A - ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 66 83 BC 24 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? BF ?? ?? - ?? ?? 33 F6 8D 84 24 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? - ?? 83 C6 ?? 83 C7 ?? 81 FE ?? ?? ?? ?? 72 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? 51 - 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 0F 8C ?? ?? ?? ?? 8B - 7C 24 ?? 7F ?? 83 FF ?? 0F 82 ?? ?? ?? ?? 8B F0 89 7C 24 ?? 89 74 24 ?? 85 C0 7C ?? - 7F ?? 83 FF ?? 76 ?? 6A ?? 6A ?? 6A ?? 53 C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 33 C0 50 8D 54 24 ?? 52 89 44 24 ?? 89 44 24 ?? 66 89 44 24 ?? 88 44 24 ?? 6A ?? 8D - 44 24 ?? 50 53 C6 44 24 ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B C7 83 E8 - ?? 8B CE 83 D9 ?? 33 F6 39 44 24 ?? 75 ?? 3B F1 75 ?? 8B 4C 24 ?? 3B 0D ?? ?? ?? ?? - 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 54 24 ?? 6A ?? 52 C6 44 + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 + 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 8B 7D ?? 0F 57 C0 66 0F 13 45 ?? + C7 45 ?? ?? ?? ?? ?? 8B C7 83 7F ?? ?? 72 ?? 8B 07 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? + 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? 83 FB ?? 75 ?? FF 15 ?? ?? + ?? ?? 32 DB E9 ?? ?? ?? ?? 8D 8E ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 + ?? 8D 8E ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 8E ?? ?? ?? ?? 6A ?? 8D + 41 ?? 50 6A ?? 8D 56 ?? 51 52 89 55 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 53 FF 15 + ?? ?? ?? ?? 8B 4D ?? 8B 45 ?? 85 C9 7F ?? 7C ?? 3D ?? ?? ?? ?? 77 ?? 8D 45 ?? 8B CE + 50 E8 ?? ?? ?? ?? EB ?? 85 C9 7F ?? 7C ?? 3D ?? ?? ?? ?? 77 ?? 6A ?? EB ?? 6A ?? 8D + 45 ?? 8B CE 50 E8 ?? ?? ?? ?? 8B 75 ?? 8A D8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 83 + CE ?? 89 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D7 8D 4D ?? E8 ?? ?? ?? ?? + 83 C4 ?? 8D 45 ?? 83 7D ?? ?? 0F 43 45 ?? 83 7F ?? ?? 72 ?? 8B 3F 50 57 FF 15 ?? ?? + ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? + 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? + 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? 83 FE ?? 74 ?? 56 FF 15 + ?? ?? ?? ?? 8A C3 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? + ?? ?? 8B E5 5D C2 ?? ?? E8 ?? ?? ?? ?? CC CC CC 55 8B EC 83 E4 ?? 81 EC } $encrypt_files_p2 = { - 24 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 79 ?? 48 0D ?? - ?? ?? ?? 40 88 44 34 ?? 46 83 FE ?? 7C ?? 8B 44 24 ?? BE ?? ?? ?? ?? 85 C0 0F 8F ?? - ?? ?? ?? 0F 8C ?? ?? ?? ?? 81 FF ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 85 C0 0F 8C ?? ?? ?? - ?? 7F ?? 85 FF 0F 84 ?? ?? ?? ?? 85 C0 7F ?? 7C ?? 3B FE 73 ?? 6A ?? 6A ?? 50 57 E8 - ?? ?? ?? ?? 8B F7 2B F0 56 E8 ?? ?? ?? ?? 8B F8 33 C0 83 C4 ?? 89 44 24 ?? 89 44 24 - ?? 3B F8 74 ?? 50 8D 44 24 ?? 50 56 57 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 39 74 24 ?? - 75 ?? 6A ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 56 57 8D 44 24 ?? E8 ?? ?? ?? ?? 83 C4 - ?? 6A ?? 8D 4C 24 ?? 51 56 57 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 FF 15 - ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? - ?? ?? 8B E5 5D C3 53 FF 15 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 - C4 ?? 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 6A ?? 68 ?? ?? - ?? ?? 50 57 E8 ?? ?? ?? ?? 8B C8 89 44 24 ?? B8 ?? ?? ?? ?? F7 E9 C1 FA ?? 8B C2 C1 - E8 ?? 03 C2 69 C0 ?? ?? ?? ?? 8B D1 2B D0 85 D2 7E ?? 41 89 4C 24 ?? 33 C0 89 44 24 - ?? 3B C8 0F 8E ?? ?? ?? ?? 89 44 24 ?? EB ?? 90 8B 7C 24 ?? 8B 44 24 ?? 8B 4C 24 + A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 8B 5D ?? 56 57 8B F9 89 5C 24 ?? 6A ?? + 8D 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 51 8B 17 8B 47 ?? 2B C2 50 52 FF 33 FF 15 ?? ?? + ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 89 43 ?? 32 C0 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 + CC E8 ?? ?? ?? ?? 8B E5 5D C2 ?? ?? 8B 44 24 ?? 8B 57 ?? 8B 0F 89 44 24 ?? 89 54 24 + ?? 89 4C 24 ?? 85 C0 7E ?? 8B D8 8B 47 ?? 8B F3 2B 47 ?? 3B D8 52 0F 43 F0 8D 47 ?? + 56 51 50 E8 ?? ?? ?? ?? 56 FF 74 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 2B DE + 8B 54 24 ?? 03 CE 83 C4 ?? 89 4C 24 ?? 85 DB 7F ?? 8B 5C 24 ?? 6A ?? 6A ?? 0F 57 C0 + 66 0F 13 44 24 ?? FF 74 24 ?? FF 74 24 ?? FF 33 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? + 85 C0 75 ?? FF D6 89 43 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? A1 ?? + ?? ?? ?? 8D 4C 24 ?? 89 44 24 ?? 83 C4 ?? A1 ?? ?? ?? ?? 89 44 24 ?? A1 ?? ?? ?? ?? + 89 44 24 ?? 8D 87 ?? ?? ?? ?? 50 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 4C 24 ?? ?? 8D 44 24 ?? 6A ?? 50 68 ?? ?? ?? ?? 8D 44 24 ?? C7 44 24 + ?? ?? ?? ?? ?? 50 FF 33 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF D6 89 43 ?? 6A ?? 8D 44 24 + ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 74 24 ?? FF 37 FF 33 FF 15 ?? ?? ?? ?? 85 C0 75 ?? + FF D6 89 43 ?? 32 C0 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C2 + ?? ?? 8B 8C 24 ?? ?? ?? ?? B0 ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D C2 } - $encrypt_files_p3 = { - 99 2B F8 1B CA 89 7C 24 ?? 89 4C 24 ?? 0F 88 ?? ?? ?? ?? 7F ?? 85 FF 0F 84 ?? ?? ?? - ?? 8B C6 99 3B CA 7F ?? 7C ?? 3B F8 73 ?? 6A ?? 6A ?? 51 57 E8 ?? ?? ?? ?? 8B F7 2B - F0 85 F6 0F 8E ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B F8 33 C0 83 C4 ?? 89 44 24 ?? 89 44 - 24 ?? 3B F8 0F 84 ?? ?? ?? ?? 50 8D 44 24 ?? 50 56 57 53 FF 15 ?? ?? ?? ?? 85 C0 0F - 84 ?? ?? ?? ?? 39 74 24 ?? 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 8B CE F7 D9 51 53 FF 15 ?? - ?? ?? ?? 56 57 8D 44 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 54 24 ?? 52 56 57 53 FF - 15 ?? ?? ?? ?? 85 C0 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 81 FE ?? ?? ?? ?? 7C ?? 83 7C - 24 ?? ?? 7C ?? 7F ?? 81 7C 24 ?? ?? ?? ?? ?? 72 ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF - 15 ?? ?? ?? ?? 8B 44 24 ?? 81 44 24 ?? ?? ?? ?? ?? 40 89 44 24 ?? 3B 44 24 ?? 0F 8C - ?? ?? ?? ?? EB ?? 53 FF 15 ?? ?? ?? ?? EB ?? 53 FF 15 ?? ?? ?? ?? 85 FF 74 ?? 57 E8 - ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 68 + + condition: + uint16(0)==0x5A4D and ($enum_resources) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Timetime : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects TimeTime ransomware." + author = "ReversingLabs" + id = "27bff941-01ce-5bf7-a9d8-d01d2db3bfd3" + date = "2022-02-21" + modified = "2022-02-21" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.TimeTime.yara#L1-L75" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "43867dd793bc84e6f39ca2de1aff4047a742b295dc4df94cd337bd2ef89e4a62" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "TimeTime" + tc_detection_factor = 5 + importance = 25 + + strings: + $rename_files = { + 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 2B ?? 12 ?? 28 ?? ?? ?? ?? 0B 00 07 28 ?? ?? ?? + ?? 16 FE 01 0C 08 2C ?? 2B ?? 00 00 07 07 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 00 00 DE ?? 26 00 00 DE ?? 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 00 DC 2A } - $encrypt_files_p4 = { - 8D 84 24 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? B9 ?? ?? ?? ?? 8D - 74 24 ?? 8D BC 24 ?? ?? ?? ?? F3 A5 8B 4C 24 ?? 6A ?? 89 8C 24 ?? ?? ?? ?? 8B D0 8D - 4C 24 ?? 51 C1 FA ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? A1 ?? - ?? ?? ?? 52 53 C7 44 24 ?? ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 53 FF - 15 ?? ?? ?? ?? 33 C0 68 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? 51 66 89 84 24 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 74 24 ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 8D 94 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 94 24 ?? ?? ?? ?? 52 56 FF 15 ?? ?? ?? ?? 5F 5E - 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 53 FF 15 ?? ?? ?? ?? 8B 8C - 24 ?? ?? ?? ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + $find_files = { + 00 73 ?? ?? ?? ?? 0A 00 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 07 2C ?? 06 0C DD ?? ?? ?? + ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0D 09 2C ?? 06 0C DD ?? ?? ?? ?? 02 72 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 06 0C DD ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 13 ?? 11 ?? 2C ?? 06 0C DD ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C + ?? 06 0C DD ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 06 0C DD ?? + ?? ?? ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 06 0C DD ?? ?? ?? ?? 02 72 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 06 0C DD ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 06 0C DE ?? 00 02 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 + ?? 11 ?? 9A 13 ?? 00 06 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 + 32 ?? 00 02 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 13 ?? 00 06 11 ?? 28 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? 00 DE ?? 13 ?? + 00 00 DE ?? 06 0C 2B ?? 08 2A } - $find_MS_xchange_backups_p1 = { - 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? - ?? ?? 53 56 57 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? - 8B 1D ?? ?? ?? ?? B0 ?? 88 44 24 ?? 88 44 24 ?? B0 ?? 83 C4 ?? C6 44 24 ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 66 C7 44 24 ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? 88 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 66 C7 44 24 ?? ?? ?? C6 44 24 ?? ?? 88 44 24 - ?? 88 44 24 ?? BE ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B FF 68 ?? ?? ?? ?? 8D 8C 24 - ?? ?? ?? ?? 6A ?? 51 C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 56 8D 54 24 ?? - 52 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 8D 4C 24 ?? 6A ?? 51 - E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 33 D2 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? - 8D 44 24 ?? 50 8D 4C 24 ?? 51 52 52 52 52 52 52 66 89 54 24 ?? 8D 94 24 ?? ?? ?? ?? - 52 6A ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF D3 6A ?? FF D7 83 C6 ?? - FF 4C 24 ?? 0F 85 ?? ?? ?? ?? BE ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 8D 49 ?? - 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 50 C6 84 24 ?? ?? ?? ?? ?? E8 + $encrypt_folder = { + 00 02 28 ?? ?? ?? ?? 0A 00 06 6F ?? ?? ?? ?? 0B 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 0C + 00 00 08 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 FE 01 0D 09 2C ?? 00 16 13 ?? 16 13 ?? 08 73 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 8C ?? ?? ?? ?? 17 8C ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 08 19 + 73 ?? ?? ?? ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 00 DE ?? + 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? 00 DC 11 ?? 16 FE 01 11 ?? 5F 11 ?? 5F 13 ?? 11 ?? 2C + ?? 00 08 28 ?? ?? ?? ?? 00 00 00 00 DE ?? 26 00 00 DE ?? 00 12 ?? 28 ?? ?? ?? ?? 3A ?? + ?? ?? ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 2A } - $find_MS_xchange_backups_p2 = { - 83 C4 ?? 56 8D 4C 24 ?? 51 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 6A - ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 33 C9 8D 54 24 ?? 52 89 44 24 - ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 8D 44 24 ?? 50 51 51 51 51 51 51 66 89 4C 24 - ?? 8D 8C 24 ?? ?? ?? ?? 51 6A ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF - D3 6A ?? FF D7 83 C6 ?? FF 4C 24 ?? 0F 85 ?? ?? ?? ?? 33 D2 68 ?? ?? ?? ?? 52 8D 84 - 24 ?? ?? ?? ?? 50 66 89 94 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 B1 ?? EB ?? 8D 49 ?? - 30 88 ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 6A ?? - 51 C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? - ?? 52 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 51 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? 56 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 54 24 ?? 6A ?? 52 E8 ?? ?? - ?? ?? 83 C4 ?? 33 C0 8D 4C 24 ?? 51 8D 54 24 ?? 52 50 50 50 50 50 50 89 44 24 ?? 89 - 44 24 ?? 89 44 24 ?? 89 44 24 ?? 66 89 44 24 ?? 8D 84 24 ?? ?? ?? ?? 50 6A ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF D3 8B 8C 24 ?? ?? ?? ?? 5F 5E 5B 33 CC - E8 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files = { + 00 02 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 08 2C ?? 38 ?? ?? ?? ?? 02 7E ?? ?? ?? ?? 6F ?? + ?? ?? ?? 0D 09 2C ?? 2B ?? 02 28 ?? ?? ?? ?? 0A 06 8E 69 8D ?? ?? ?? ?? 0B 16 13 ?? 2B + ?? 00 06 11 ?? 91 13 ?? 11 ?? 17 58 D1 13 ?? 11 ?? D2 13 ?? 07 11 ?? 11 ?? 9C 00 11 ?? + 17 58 13 ?? 11 ?? 07 8E 69 FE 04 13 ?? 11 ?? 2D ?? 02 07 28 ?? ?? ?? ?? 00 02 02 7E ?? + ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 02 28 ?? ?? ?? ?? 00 02 28 ?? ?? ?? ?? 00 7E + ?? ?? ?? ?? 02 6F ?? ?? ?? ?? 00 2A } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($find_MS_xchange_backups_p*)) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($encrypt_folder) and ($rename_files) } -rule REVERSINGLABS_Win32_Ransomware_Darkside : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Gpcode : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects DarkSide ransomware." + description = "Yara rule that detects Gpcode ransomware." author = "ReversingLabs" - id = "061b00cb-9b70-521f-ab3f-7e6b3c129194" - date = "2021-05-17" - modified = "2021-05-17" + id = "168833dd-44ab-59e1-a610-b9219b2907ff" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.DarkSide.yara#L1-L94" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "128af9a1b143e4b0928dd2b243e69497be906175f44815cc5703f17cce48ec9d" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Gpcode.yara#L1-L67" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "329309873977f73a8ebe758018ebc8ba42e15c3c7cbb9a65865631d235f5bb48" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -25266,70 +26400,338 @@ rule REVERSINGLABS_Win32_Ransomware_Darkside : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "DarkSide" + tc_detection_name = "GPCode" tc_detection_factor = 5 importance = 25 strings: - $find_files_v1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 51 52 56 57 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - 83 7D ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 04 45 ?? ?? ?? - ?? 50 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? - ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? E8 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? - ?? ?? ?? 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8D 9D ?? ?? - ?? ?? 83 3B ?? 74 ?? 81 3B ?? ?? ?? ?? 74 ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8D 85 ?? ?? - ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 83 7D ?? - ?? 74 ?? FF 75 ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 45 ?? 5F 5E 5A 59 5B - 8B E5 5D C2 + $drive_loop = { + B9 19 00 00 00 BB 01 00 00 00 D3 E3 23 D8 74 ?? 80 + C1 ?? 88 0D ?? ?? ?? ?? 80 E9 ?? C7 05 ?? ?? ?? ?? + ?? ?? ?? ?? 50 51 E8 ?? ?? ?? ?? 59 58 49 7D } - $enumerate_drives = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 51 52 56 57 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 8B D8 85 DB 74 ?? C1 EB ?? 8D B5 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 F8 - ?? 74 ?? 83 F8 ?? 75 ?? 56 E8 ?? ?? ?? ?? 8D 76 ?? 4B 85 DB 75 ?? 5F 5E 5A 59 5B 8B - E5 5D C3 55 8B EC 81 EC ?? ?? ?? ?? 53 51 52 56 57 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? C7 - 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 - ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 66 A9 ?? ?? 74 ?? 6A ?? 8D 85 ?? ?? - ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 40 ?? 50 FF 15 ?? ?? ?? - ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 - ?? ?? ?? ?? 85 C0 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 5A 59 5B 8B E5 5D C2 + $encrypt_routine = { + FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? [0-10] + E9 ?? ?? ?? ?? 6A ?? [1-10] FF 75 ?? FF 35 ?? ?? + ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? + ?? ?? ?? 68 ?? ?? ?? ?? [1-10] FF 35 ?? ?? ?? ?? + 6A ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? (E8 | FF 15) + ?? ?? ?? ?? 0B C0 75 ?? (EB | E9) [1-4] 6A ?? + [2-10] FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? + 75 ?? [10-40] FF 35 ?? ?? ?? ?? FF 75 ?? E8 } - $escalate_privileges = { - 55 8B EC 83 C4 ?? 53 51 52 56 57 8D 45 ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 0F - 85 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 8D 45 ?? 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 - ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8D 45 ?? 50 - FF 75 ?? FF 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 75 ?? AD 8B F8 83 - 7E ?? ?? 74 ?? C7 46 ?? ?? ?? ?? ?? 83 C6 ?? 4F 85 FF 75 ?? 6A ?? 6A ?? 6A ?? FF 75 - ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 5A 59 5B 8B E5 5D C3 + $set_ransom_wallpaper = { + 0F B6 05 ?? ?? ?? ?? 83 F8 01 0F 85 ?? ?? ?? ?? + B9 ?? ?? ?? ?? BF ?? ?? ?? ?? 51 57 [2-20] 5F + 59 25 ?? ?? ?? ?? C1 E8 ?? 83 C0 ?? AA E2 ?? 33 + C0 AA 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? (E8 | FF 15) } - $enumerate_netshare = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 51 52 56 57 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 7D ?? 8D 45 ?? 50 8D 45 ?? 50 8D 45 ?? 50 6A ?? - 8D 45 ?? 50 6A ?? 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 75 ?? 83 7E ?? ?? 75 ?? 68 ?? - ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 C7 03 ?? ?? ?? ?? C7 43 ?? - ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? 8D 47 ?? 50 53 FF 15 ?? ?? ?? - ?? 83 C4 ?? 53 FF 15 ?? ?? ?? ?? FF 36 53 FF 15 ?? ?? ?? ?? 83 C4 ?? 53 E8 ?? ?? ?? - ?? 53 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 C6 ?? FF 4D ?? 83 7D ?? ?? 75 ?? - FF 15 ?? ?? ?? ?? 5F 5E 5A 59 5B 8B E5 5D C2 + $read_config_file = { + 55 8B EC 83 C4 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A + ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? + ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 89 45 ?? 50 6A ?? + E8 ?? ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 89 45 ?? FF + 75 ?? 6A ?? E8 ?? ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 + 89 45 ?? 50 E8 ?? ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 + 89 45 ?? FF 75 ?? 6A ?? E8 ?? ?? ?? ?? 0B C0 75 04 + 33 C0 C9 C3 89 45 ?? 8B D8 FF 75 ?? FF 75 ?? FF 75 + ?? E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 5D ?? + 6A ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C3 ?? 8B + 45 ?? 83 E8 ?? 50 53 E8 ?? ?? ?? ?? 8A 03 A2 ?? ?? + ?? ?? 83 C3 ?? 8A 03 A2 ?? ?? ?? ?? 83 C3 } - $find_files_v2 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 51 52 56 57 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D BD - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 83 C4 ?? 57 FF 15 ?? ?? ?? ?? - 83 C4 ?? 66 83 7C 47 ?? ?? 74 ?? 66 C7 04 47 ?? ?? 83 C7 ?? C7 04 47 ?? ?? ?? ?? C7 - 44 47 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 66 A9 ?? ?? 74 ?? - 8D 9D ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 83 C4 - ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 83 C4 ?? 83 C0 ?? 53 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 56 - E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 75 ?? - FF 15 ?? ?? ?? ?? 5F 5E 5A 59 5B 8B E5 5D C2 + + condition: + uint16(0)==0x5A4D and ($drive_loop and $encrypt_routine and $set_ransom_wallpaper and $read_config_file) +} +rule REVERSINGLABS_Win32_Ransomware_Bananacrypt : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects BananaCrypt ransomware." + author = "ReversingLabs" + id = "9e47d094-d7fc-57dd-826c-5321d0219273" + date = "2020-09-14" + modified = "2020-09-14" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.BananaCrypt.yara#L1-L103" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6bde4430e438947b0d7f10c4de11216929ec03af81b3d74f8b7bb8ed134d08d2" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "BananaCrypt" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 55 89 E5 57 56 53 89 C3 81 EC ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 55 ?? 89 8D ?? ?? ?? + ?? 85 D2 74 ?? 8B 45 ?? 85 C0 0F 85 ?? ?? ?? ?? 31 F6 0F B6 13 84 D2 0F 84 ?? ?? ?? + ?? 8D 43 ?? 88 95 ?? ?? ?? ?? 8D 8B ?? ?? ?? ?? 8D BD ?? ?? ?? ?? EB ?? 83 C0 ?? 83 + C7 ?? 88 57 ?? 39 C1 74 ?? 0F B6 10 84 D2 75 ?? 89 BD ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + C6 00 ?? 89 1C 24 E8 ?? ?? ?? ?? 85 C0 89 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 89 F0 84 + C0 0F 85 ?? ?? ?? ?? 8D 5D ?? 8D 76 ?? 8D BC 27 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 + 24 E8 ?? ?? ?? ?? 85 C0 89 C6 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D BD ?? ?? ?? ?? + 39 F9 89 C8 76 ?? 0F B6 41 ?? 89 CF 3C ?? 0F 95 C1 3C ?? 0F 95 C2 84 D1 0F 84 ?? ?? + ?? ?? 3C ?? 0F 84 ?? ?? ?? ?? 8D 47 ?? C6 07 ?? 8D 7E ?? 39 D8 89 BD ?? ?? ?? ?? 73 + ?? 0F B6 56 ?? 84 D2 74 ?? 89 F9 8B BD ?? ?? ?? ?? EB ?? 90 0F B6 11 84 D2 74 ?? 83 + C0 ?? 83 C1 ?? 88 50 ?? 39 D8 75 ?? 89 BD ?? ?? ?? ?? C6 00 ?? 8D 85 ?? ?? ?? ?? 31 + FF 89 04 24 E8 ?? ?? ?? ?? 85 C0 89 C2 74 ?? 80 38 ?? 74 ?? 8B 85 ?? ?? ?? ?? 66 90 + 83 C7 ?? 80 3C 3A ?? 75 ?? 89 85 ?? ?? ?? ?? 89 54 24 ?? C7 04 24 ?? ?? ?? ?? 89 95 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 46 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 3D ?? ?? ?? ?? 8B 95 + ?? ?? ?? ?? 74 ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 7C 24 ?? 89 14 24 89 + } + $encrypt_files_p2 = { + 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? C7 04 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 C6 8D 85 ?? ?? ?? ?? 89 F1 89 04 24 E8 ?? ?? ?? ?? + 83 EC ?? 89 F1 E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? 89 C7 8D + 40 ?? 83 F8 ?? 76 ?? 89 F1 83 05 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 3C 24 89 44 24 ?? E8 ?? ?? ?? ?? 89 F1 E8 ?? + ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 + ?? ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 89 + F1 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B + B5 ?? ?? ?? ?? BF ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 A6 0F 84 ?? ?? ?? ?? 8B B5 ?? ?? ?? + ?? BF ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 A6 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 8D ?? ?? ?? ?? + 8B 95 ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 04 24 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 + ?? ?? ?? ?? 8D 74 26 ?? 8B 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 + E8 ?? ?? ?? ?? 8D 65 ?? B8 ?? ?? ?? ?? 5B 5E 5F 5D C3 8B 45 ?? 89 1C 24 89 44 24 ?? + 8B 45 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 89 C6 E9 ?? ?? ?? ?? 8D 65 ?? 31 C0 5B 5E 5F 5D + C3 8D 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E9 + } + $find_files_p1 = { + 8D 4C 24 ?? 83 E4 ?? FF 71 ?? 55 89 E5 57 56 53 51 81 EC ?? ?? ?? ?? 8B 31 8B 79 ?? + E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 FE ?? 7E ?? 89 74 24 ?? C7 04 + 24 ?? ?? ?? ?? 31 DB E8 ?? ?? ?? ?? 8B 04 9F 89 5C 24 ?? 83 C3 ?? C7 04 24 ?? ?? ?? + ?? 89 44 24 ?? E8 ?? ?? ?? ?? 39 DE 75 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 47 ?? 89 04 24 + E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 89 + 44 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D BD ?? + ?? ?? ?? F3 A5 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 04 24 C7 85 + } + $find_files_p2 = { + 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 C3 E8 ?? ?? ?? ?? + 8D 44 03 ?? 89 04 24 E8 ?? ?? ?? ?? 89 C3 8B 85 ?? ?? ?? ?? 89 1C 24 89 44 24 ?? E8 + ?? ?? ?? ?? 89 DA 8B 0A 83 C2 ?? 8D 81 ?? ?? ?? ?? F7 D1 21 C8 25 ?? ?? ?? ?? 74 ?? + A9 ?? ?? ?? ?? 74 ?? 89 C1 00 C1 83 DA ?? C7 02 ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C7 + 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 84 C0 74 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 65 ?? 31 C0 59 5B 5E + 5F 5D 8D 61 ?? C3 C1 E8 ?? 83 C2 ?? EB ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D BD ?? ?? ?? ?? BE ?? ?? ?? ?? 89 04 24 B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 29 + F9 89 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? 29 CE 81 C1 ?? ?? ?? ?? C1 E9 ?? 89 45 ?? F3 + } + $find_files_p3 = { + A5 89 1C 24 E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 89 C6 74 ?? 89 44 24 ?? C7 44 24 ?? ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 34 24 E8 ?? + ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 + ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 04 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 85 C0 89 C6 0F 84 ?? ?? ?? ?? 89 44 24 + ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? + ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? E9 } condition: - uint16(0)==0x5A4D and (($find_files_v1 and $enumerate_drives and $escalate_privileges) or ($find_files_v2 and $enumerate_netshare)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Targetcompany : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects TargetCompany ransomware." + author = "ReversingLabs" + id = "7e6983f9-2aca-5cfa-aad6-38aa64fa2062" + date = "2021-09-27" + modified = "2021-09-27" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.TargetCompany.yara#L1-L141" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "05fa81afa8aa1e3b9955ad24a274ddef4fb32d678902af7aae6d6c67ed3bf0fd" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "TargetCompany" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 59 53 68 ?? ?? ?? ?? 6A ?? 53 6A + ?? 68 ?? ?? ?? ?? 56 FF D7 89 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 56 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 + BD ?? ?? ?? ?? ?? 75 ?? BF ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 56 8D 75 ?? E8 ?? ?? ?? + ?? 50 89 5D ?? E8 ?? ?? ?? ?? 53 6A ?? E8 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? E9 ?? ?? + ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 + E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 53 68 + ?? ?? ?? ?? 6A ?? 53 6A ?? 68 ?? ?? ?? ?? 56 FF D7 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? + ?? 6A ?? 5F 53 57 56 FF B5 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 57 52 50 + 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 33 FF 3B F3 89 85 + ?? ?? ?? ?? 7F ?? 7C ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 77 ?? 33 FF 47 EB ?? B9 ?? ?? + ?? ?? 3B C1 73 ?? 53 51 56 FF B5 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 50 + } + $encrypt_files_p2 = { + 56 FF B5 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 89 95 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 3B FB 8B 3D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? + 89 9D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 59 89 85 ?? ?? ?? ?? 3B C3 0F 84 ?? ?? ?? ?? 53 8D 8D ?? ?? ?? ?? 51 FF B5 ?? + ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 FF B5 ?? ?? ?? ?? 8D 4D + ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 53 53 53 FF B5 ?? + ?? ?? ?? FF D7 53 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? FF D6 E9 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 89 85 ?? ?? ?? ?? 3B C3 0F 84 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B C3 0F 86 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 53 53 FF B5 ?? + ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF D7 53 8D 85 ?? ?? ?? ?? 50 FF B5 ?? + ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 FF B5 ?? + ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 53 + FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF D7 53 8D 85 ?? ?? ?? ?? 50 + FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF D6 8B 85 ?? ?? ?? ?? 01 85 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 11 85 ?? ?? ?? ?? FF 8D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? + FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 6A ?? 53 53 33 C0 50 FF B5 ?? ?? ?? ?? FF D7 8B + BD ?? ?? ?? ?? 53 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 45 ?? 50 57 FF D6 53 8D 85 ?? ?? ?? + ?? 50 6A ?? 8D 45 ?? 50 57 FF D6 53 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 57 FF + D6 57 FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 + } + $remote_connection_p1 = { + 55 8B EC 83 EC ?? 53 56 33 F6 57 8D 5D ?? 89 75 ?? E8 ?? ?? ?? ?? 89 75 ?? 56 56 56 + FF 75 ?? 56 FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? 3B DE 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 FF 6A ?? 8D + 45 ?? 50 FF 74 BD ?? 53 FF 15 ?? ?? ?? ?? 47 83 FF ?? 72 ?? 56 56 6A ?? 56 56 FF 75 + ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 89 45 ?? 3B C6 0F 84 ?? ?? ?? ?? 33 C9 80 7D ?? ?? + B8 ?? ?? ?? ?? 0F 95 C1 56 49 23 C8 03 C8 81 C9 ?? ?? ?? ?? 51 56 56 56 FF 75 ?? 89 + 4D ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B D8 3B DE 0F 84 ?? ?? ?? ?? 6A ?? + 5F 8D 45 ?? 50 8D 45 ?? 50 6A ?? 53 89 7D ?? 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? + 81 4D ?? ?? ?? ?? ?? 57 8D 45 ?? 50 6A ?? 53 FF 15 ?? ?? ?? ?? FF 75 ?? 8B 45 ?? FF + 75 ?? F7 D8 1B C0 50 FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 33 FF 56 56 8D 45 ?? + 50 53 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 03 C7 50 FF 75 ?? E8 ?? ?? ?? + ?? 59 59 8D 4D ?? 51 FF 75 ?? 89 45 ?? 03 C7 50 53 FF 15 ?? ?? ?? ?? 03 7D ?? 39 75 + ?? 75 ?? 53 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? + 39 75 ?? 75 ?? 33 C0 40 39 45 ?? 74 ?? 89 45 ?? E9 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? + ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 5F 5E 5B C9 C3 + } + $remote_connection_p2 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 8D 9D ?? ?? ?? ?? + 8B F9 E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 45 + ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 85 F6 75 + ?? B8 ?? ?? ?? ?? 50 8D 45 ?? 50 57 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 8B F8 85 F6 74 ?? 56 E8 ?? ?? ?? ?? 59 85 FF 74 ?? 57 E8 ?? ?? ?? ?? 59 FF B5 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B 4D ?? 5F 5E 33 + CD 5B E8 ?? ?? ?? ?? C9 C3 + } + $generate_key = { + 0F 31 0F AF C8 0F AF CE 0F AF 8D ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 53 33 FF 47 57 53 53 + 8D 85 ?? ?? ?? ?? 50 89 8D ?? ?? ?? ?? FF D6 3B C3 75 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? + ?? ?? 75 ?? 6A ?? 57 53 53 8D 85 ?? ?? ?? ?? 50 FF D6 3B C3 74 ?? 8D 85 ?? ?? ?? ?? + 50 6A ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 59 53 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B C7 + B9 ?? ?? ?? ?? 8B 11 8B F2 C1 EE ?? 33 F2 69 F6 ?? ?? ?? ?? 03 F0 89 71 ?? 83 C1 ?? + 40 81 F9 ?? ?? ?? ?? 7C ?? 57 A3 ?? ?? ?? ?? FF 15 + } + $find_files_p1 = { + 8D 85 ?? ?? ?? ?? 53 53 50 53 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? + 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF + D6 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 + FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 C4 ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 33 F6 0F B7 + C6 FF 34 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? 46 66 83 FE ?? 72 ?? 6A ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? + ?? 0F 84 ?? ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 0F B7 B5 ?? ?? ?? ?? 8D 34 B5 + } + $find_files_p2 = { + FF 36 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 50 FF D3 FF 36 89 85 ?? ?? + ?? ?? FF D3 8B 8D ?? ?? ?? ?? 3B C8 0F 84 ?? ?? ?? ?? FF 85 ?? ?? ?? ?? 66 83 BD ?? + ?? ?? ?? ?? 72 ?? C6 85 ?? ?? ?? ?? ?? 0F B6 85 ?? ?? ?? ?? FF 34 85 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? FE 85 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? + ?? 72 ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 59 85 F6 74 ?? 6A ?? 59 FF B5 ?? ?? ?? ?? 33 C0 + 8B FE F3 AB 66 8B 85 ?? ?? ?? ?? 66 89 46 ?? FF D3 8D 44 00 ?? 50 E8 ?? ?? ?? ?? 59 + FF B5 ?? ?? ?? ?? 89 46 ?? 50 FF 15 ?? ?? ?? ?? 56 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BF ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF B5 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 83 C4 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 EB ?? 56 FF 15 ?? ?? ?? + ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B + 4D ?? 5F 5E 33 CD 33 C0 5B E8 ?? ?? ?? ?? C9 C2 + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($generate_key) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Acepy : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Acepy ransomware." + author = "ReversingLabs" + id = "3ffb45b1-6bde-5bf8-957e-433b9488ba91" + date = "2022-08-04" + modified = "2022-08-04" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Acepy.yara#L1-L69" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "92c543a0b8c3c884f83647119d32c7b46f5fe839694bb8a8de0146c5c77bc587" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Acepy" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files = { + E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? + 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? B9 ?? ?? ?? ?? 51 50 E8 ?? ?? ?? ?? + 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B 45 ?? 8B 08 51 E8 ?? ?? ?? ?? + 83 C4 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? + E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? + B8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 + 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? + ?? ?? B8 ?? ?? ?? ?? C9 C3 + } + $encrypt_files = { + 55 89 E5 81 EC ?? ?? ?? ?? 90 B8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 89 45 ?? 8B 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? + ?? ?? B8 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? B8 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 50 8B 45 ?? + 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 40 50 B8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 89 45 ?? 8B 45 ?? 50 B8 ?? ?? ?? ?? 50 8B 45 ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? B8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 4D ?? 39 C8 0F 83 ?? ?? ?? ?? E9 ?? ?? ?? ?? + 8B 45 ?? 89 C1 40 89 45 ?? EB ?? 8B 45 ?? 8B 4D ?? 01 C1 8B 45 ?? 8B 55 ?? 01 C2 8B + 45 ?? 50 89 4D ?? 89 55 ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 45 ?? 8B 4D ?? 31 D2 + F7 F1 8B 45 ?? 01 D0 8B 4D ?? 0F BE 09 0F BE 10 31 D1 8B 45 ?? 88 08 EB ?? B8 ?? ?? + ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 B9 ?? ?? ?? ?? 51 50 E8 ?? + ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 B8 ?? ?? ?? ?? 50 8B 45 ?? 50 8B 45 ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? C9 C3 + } + $drop_ransom_note = { + 55 89 E5 81 EC ?? ?? ?? ?? 90 B8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 89 45 ?? 8B 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? + ?? ?? B8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 50 B8 ?? ?? ?? ?? 50 B8 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? + ?? ?? C9 C3 + } + + condition: + uint16(0)==0x5A4D and (($find_files) and ($encrypt_files) and ($drop_ransom_note)) } rule REVERSINGLABS_Win32_Ransomware_Satana : TC_DETECTION MALICIOUS MALWARE FILE { @@ -25340,8 +26742,8 @@ rule REVERSINGLABS_Win32_Ransomware_Satana : TC_DETECTION MALICIOUS MALWARE FILE date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Satana.yara#L1-L123" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Satana.yara#L1-L123" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "5deb6ac2e8b64fb6f7af8c41a9b9e695668ca66c96c65f0c7350b11cd4ae0c50" score = 75 quality = 90 @@ -25446,18 +26848,18 @@ rule REVERSINGLABS_Win32_Ransomware_Satana : TC_DETECTION MALICIOUS MALWARE FILE condition: uint16(0)==0x5A4D and ($remote_connection and ( all of ($search_files_p*)) and ( all of ($encrypt_files_p*))) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Pacman : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Lorenz : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Pacman ransomware." + description = "Yara rule that detects Lorenz ransomware." author = "ReversingLabs" - id = "a440769b-030b-5b72-a6f2-cf478dd7acd2" - date = "2021-08-12" - modified = "2021-08-12" + id = "cc97dd15-d518-5d9f-9384-3dcf81e34e81" + date = "2022-10-24" + modified = "2022-10-24" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Pacman.yara#L1-L68" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0634303a4db2631edb40a9435444f3bdc4bc6eb745c7e43a54478e54e7507403" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Lorenz.yara#L1-L252" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "b8668fcc560d264c37e3fbb52d5a5f1223a282abd9e984b3109efe9ab454be9f" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -25465,232 +26867,211 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Pacman : TC_DETECTION MALICIOUS MALW sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Pacman" + tc_detection_name = "Lorenz" tc_detection_factor = 5 importance = 25 strings: - $pacman_find_encrypted_1 = { - 28 0A 00 00 06 [0-2] 6F 0D 00 00 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] 28 - 29 02 00 06 1F 1C 28 0E 04 00 06 [0-2] 7E 13 00 00 04 20 0F 03 00 00 28 2F 00 00 06 25 - 26 28 5D 02 00 06 [0-2] 28 6D 01 00 06 [0-2] 0B 07 13 06 16 13 05 2B 31 11 06 11 05 9A - 0C 28 0A 00 00 06 [0-2] 6F 0D 00 00 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] - 08 28 55 02 00 06 [0-2] 26 11 05 17 D6 13 05 11 05 11 06 8E B7 32 C7 1D 45 01 00 00 00 - F6 FF FF FF 17 2D 06 D0 1E 01 00 06 26 16 0A 38 BC 01 00 00 28 0A 00 00 06 [0-2] 6F 0D - 00 00 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] 06 28 AA 04 00 06 [0-2] 14 20 - B0 0F 00 00 28 2F 00 00 06 [0-2] 1F 0A 8D 76 00 00 01 13 07 11 07 16 20 BF 0F 00 00 28 - 2F 00 00 06 [0-2] A2 11 07 17 20 C2 0F 00 00 28 2F 00 00 06 [0-2] A2 11 07 18 20 C5 0F - 00 00 28 2F 00 00 06 [0-2] A2 11 07 19 20 C8 0F 00 00 28 2F 00 00 06 [0-2] A2 11 07 1A - 20 CB 0F 00 00 28 2F 00 00 06 [0-2] A2 11 07 1B 20 CE 0F 00 00 28 2F 00 00 06 [0-2] A2 - } - $pacman_find_encrypted_2 = { - 11 07 1C 20 D1 0F 00 00 28 2F 00 00 06 [0-2] A2 11 07 1D 20 D4 0F 00 00 28 2F 00 00 06 - [0-2] A2 11 07 1E 20 C2 0F 00 00 28 2F 00 00 06 [0-2] A2 11 07 1F 09 20 D7 0F 00 00 28 - 2F 00 00 06 [0-2] A2 11 07 14 14 14 28 7A 04 00 06 [0-2] 28 E2 05 00 06 [0-2] 0D 28 07 - 00 00 06 28 1A 04 00 06 [0-2] 28 0A 00 00 06 [0-2] 6F 0D 00 00 06 [0-2] 6F 33 00 00 06 - [0-2] 28 FD 01 00 06 [0-2] 06 28 AA 04 00 06 [0-2] 28 E2 05 00 06 [0-2] 28 36 05 00 06 - [0-2] 2C 78 1A 45 01 00 00 00 F6 FF FF FF 7E 16 00 00 04 28 9D 02 00 06 [0-2] 28 0A 00 - 00 06 [0-2] 6F 0D 00 00 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] 06 28 AA 04 - 00 06 [0-2] 28 E2 05 00 06 [0-2] 09 16 28 23 01 00 06 28 0A 00 00 06 [0-2] 6F 0D 00 00 - 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] 06 28 AA 04 00 06 [0-2] 28 E2 05 00 - 06 [0-2] 28 66 04 00 06 DE 0F 25 28 4E 04 00 06 13 04 28 02 03 00 06 DE 00 06 17 D6 0A - 06 28 0A 00 00 06 [0-2] 6F 0D 00 00 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] - 28 E2 04 00 06 [0-2] 3F 1B FE FF FF 1B 45 01 00 00 00 F6 FF FF FF 28 28 00 00 06 2A + $encrypt_files_v1_p1 = { + BE ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? A5 6A ?? 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? + ?? ?? A5 A5 A4 8B 35 ?? ?? ?? ?? FF D6 89 85 ?? ?? ?? ?? 33 C0 50 68 ?? ?? ?? ?? 6A + ?? 50 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D6 68 ?? ?? ?? ?? 6A ?? 6A ?? 89 85 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 85 C0 75 + ?? FF D6 8B 3D ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? FF D7 EB ?? 8B 3D ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 + C0 75 ?? FF D6 6A ?? FF B5 ?? ?? ?? ?? FF D7 6A ?? 6A ?? 53 FF B5 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 85 C0 75 ?? FF D6 8D 85 ?? ?? ?? ?? 33 DB 50 53 FF B5 ?? ?? ?? ?? 68 ?? + ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF D6 53 FF B5 ?? ?? ?? ?? + FF D7 6A ?? 8D 45 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? + ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 53 8B 9D ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B + 0D ?? ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 89 4D ?? 66 8B 0D ?? ?? ?? ?? 66 89 4D ?? 8D 4D + ?? 89 85 ?? ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 6A ?? 50 2B CA 8D 45 ?? 51 50 56 FF 15 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 68 + ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 33 C0 50 50 } - $pacman_encrypt = { - 28 65 02 00 06 [0-2] 0A 16 13 05 20 00 04 00 00 13 07 06 11 07 28 2A 05 00 06 [0-2] 2C - 19 1C 45 01 00 00 00 F6 FF FF FF 17 2D 06 D0 20 01 00 06 26 11 07 13 05 2B 15 11 07 15 - D6 13 07 11 07 17 2F D0 17 45 01 00 00 00 F6 FF FF FF 20 DA 0F 00 00 28 2F 00 00 06 [0-2] - 11 05 28 9D 02 00 06 [0-2] 28 E2 02 00 06 [0-2] 28 6E 03 00 06 06 28 0A 03 00 06 [0-2] - 0B 14 13 04 14 0D 1F 0E 8D 25 00 00 01 13 0B 11 0B 16 ?? 9C 11 0B 17 ?? 9C 11 0B 18 - ?? 9C 11 0B 19 ?? 9C 11 0B 1A ?? 9C 11 0B 1B ?? 9C 11 0B 1C ?? 9C 11 0B 1D ?? 9C 11 0B - 1E 20 ?? ?? ?? ?? 9C 11 0B 1F 09 20 ?? ?? ?? ?? 9C 11 0B 1F 0A 20 ?? ?? ?? ?? 9C 11 0B - 1F 0B 1F ?? 9C 11 0B 1F 0C 1F ?? 9C 11 0B 1F 0D 1F ?? 9C 11 0B 13 06 02 11 06 11 05 07 - 12 04 12 03 28 1F 01 00 06 05 2C 18 18 45 01 00 00 00 F6 FF FF FF 06 11 04 09 28 96 03 - 00 06 [0-2] 0C 2B 0C 06 11 04 09 28 7E 05 00 06 [0-2] 0C 04 08 17 28 45 01 00 06 [0-2] - 13 08 20 01 04 00 00 8D 25 00 00 01 13 09 03 11 09 16 20 00 04 00 00 28 3A 03 00 06 [0-2] - 13 0A 11 0A 16 33 0C 1D 45 01 00 00 00 F6 FF FF FF DE 24 11 08 11 09 16 11 0A 28 F6 04 - 00 06 2B CF 11 08 2C 11 18 45 01 00 00 00 F6 FF FF FF 11 08 28 1E 03 00 06 DC DE 0C 28 - 4E 04 00 06 28 02 03 00 06 DE 00 08 28 1E 03 00 06 2A + $encrypt_files_v1_p2 = { + 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 D2 42 3B C2 75 ?? 83 BD ?? ?? ?? ?? ?? + 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 33 D2 42 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 03 8D + ?? ?? ?? ?? 3B 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 6A ?? 89 8D ?? ?? ?? ?? 0F 44 C2 8D + 8D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 51 8D 4D ?? 51 6A ?? 50 6A ?? FF B5 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 85 C0 74 ?? 83 A5 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF B5 ?? + ?? ?? ?? 8D 45 ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8D 45 ?? 6A ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? + 85 C0 0F 85 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? FF D7 FF B5 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 53 FF D6 8B 85 ?? ?? ?? + ?? 50 FF D6 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F + 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 } - - condition: - uint16(0)==0x5A4D and ($pacman_find_encrypted_1 and $pacman_find_encrypted_2 and $pacman_encrypt) -} -rule REVERSINGLABS_Win32_Ransomware_Wsir : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects WsIR ransomware." - author = "ReversingLabs" - id = "cb4ab736-9421-5b92-b4a5-c5db0b61725a" - date = "2022-08-02" - modified = "2022-08-02" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.WsIR.yara#L1-L73" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "c22c01f93945c7721ebfe5e7a09c3bf2b9d0ad95740bc0a76b4e61741f61d82c" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "WsIR" - tc_detection_factor = 5 - importance = 25 - - strings: - $find_files = { - 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 53 - 55 8B E9 8D 4C 24 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 4C 24 ?? C7 84 24 ?? ?? ?? ?? ?? - ?? ?? ?? 8B 41 ?? 85 C0 74 ?? 8D 54 24 ?? 6A ?? 52 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B 00 - 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4C 24 ?? 85 C0 0F 95 C3 E8 ?? ?? ?? ?? - 84 DB 74 ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? E8 - ?? ?? ?? ?? 8B 4C 24 ?? 8D 44 24 ?? 50 51 FF 15 ?? ?? ?? ?? 83 F8 ?? 89 44 24 ?? 75 - ?? 8D 4C 24 ?? 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 56 8B B4 24 ?? ?? - ?? ?? 57 8B 3D ?? ?? ?? ?? BB ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? 8D 54 24 ?? 68 ?? ?? - ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 45 ?? 8D 54 24 ?? 52 6A ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 50 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? 89 4C 24 ?? 89 5C 24 ?? FF D7 8B 54 24 ?? 8D 4C 24 ?? 51 52 FF 15 ?? ?? - ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 56 6A ?? 68 - ?? ?? ?? ?? 51 FF D7 8D 4C 24 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 5F - 5E 8B 8C 24 ?? ?? ?? ?? 5D 5B 64 89 0D ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C2 + $find_files_v1_p1 = { + FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 6A ?? 0F 57 C0 C6 45 + ?? ?? 6A ?? 6A ?? 0F 11 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 + C0 74 ?? 89 18 89 58 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 08 8B 3D ?? ?? ?? ?? + 8B B5 ?? ?? ?? ?? C6 45 ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F + 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF + D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 + C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 8D } - $encrypt_files = { - FF 75 ?? 8B 5D ?? FF 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? ?? - ?? FF 75 ?? 8B 5D ?? FF 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? - ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 - C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B - 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? - 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 89 45 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? - E9 + $find_files_v1_p2 = { + 8B 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 56 8B D0 C6 45 ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? 59 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 75 ?? 68 ?? ?? ?? + ?? 0F 43 75 ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 56 50 89 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B B5 ?? ?? ?? ?? 83 C4 ?? F6 85 ?? ?? ?? ?? ?? 75 ?? 56 8D 4D ?? E8 ?? ?? ?? + ?? 8D 45 ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 56 E8 + ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 59 74 ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 7D ?? ?? 8D 75 ?? 68 ?? ?? ?? ?? 0F 43 75 ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? + ?? 56 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8D 4D ?? E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 + B8 ?? ?? ?? ?? C3 C7 45 ?? ?? ?? ?? ?? 33 DB 8B 85 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 89 + 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F + 85 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8D 8D } - $exec_proc = { - 52 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 1D ?? ?? - ?? ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 FF D3 8D 4C 24 ?? 8D 54 24 ?? 51 52 68 ?? ?? ?? - ?? 8B CF E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 8D 4C 24 ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B - F0 83 C4 ?? 85 F6 75 ?? 8D 54 24 ?? 52 FF 15 ?? ?? ?? ?? 8D 74 04 ?? EB ?? 8D 57 ?? - 8D 4C 24 ?? 52 E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 48 ?? 85 C9 0F 85 ?? ?? ?? ?? 8D 4C 24 - ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 EB ?? C6 06 ?? 68 ?? ?? ?? - ?? 56 FF D3 8B 44 24 ?? 50 56 FF D3 8D 4C 24 ?? 55 51 FF 15 ?? ?? ?? ?? 8B F0 33 D2 - 83 FE ?? 0F 9F C2 8D 4C 24 ?? 8B F2 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 5D 8B C6 5B 8B 8C 24 ?? ?? ?? ?? 5F 5E 64 89 0D ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C2 + $create_scheduled_task_v1 = { + FF 15 ?? ?? ?? ?? 33 FF 85 C0 74 ?? 8B CF 8A 84 0D ?? ?? ?? ?? 88 84 0D ?? ?? ?? ?? + 41 84 C0 75 ?? 8D BD ?? ?? ?? ?? 4F 8A 47 ?? 47 84 C0 75 ?? BE ?? ?? ?? ?? A5 A5 66 + A5 33 FF 57 68 ?? ?? ?? ?? 6A ?? 57 57 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 8B 4B ?? 8B F0 89 BD ?? ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8D 85 ?? + ?? ?? ?? 2B CA 50 51 FF 73 ?? 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 83 C4 ?? 8B + F2 8A 02 42 84 C0 75 ?? 8D BD ?? ?? ?? ?? 2B D6 4F 8A 47 ?? 47 84 C0 75 ?? 8B CA C1 + E9 ?? F3 A5 8B CA 83 E1 ?? F3 A4 8D 8D ?? ?? ?? ?? 49 8A 41 ?? 41 84 C0 75 ?? 66 A1 + ?? ?? ?? ?? 33 DB 8B 35 ?? ?? ?? ?? BF ?? ?? ?? ?? 66 89 01 A0 ?? ?? ?? ?? 53 53 88 + 41 ?? 8D 85 ?? ?? ?? ?? 50 57 53 53 FF D6 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 53 53 68 + ?? ?? ?? ?? 57 53 53 FF D6 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } - - condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($exec_proc) -} -rule REVERSINGLABS_Win32_Ransomware_Networm : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Networm ransomware." - author = "ReversingLabs" - id = "3b17b97d-c882-5f65-8b89-847e2300873c" - date = "2021-07-05" - modified = "2021-07-05" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Networm.yara#L1-L103" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ff9bcb9868522f9d4abf2ab9f94d5b7c9b009e5c6d0cf832c7d052f18e048b31" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Networm" - tc_detection_factor = 5 - importance = 25 - - strings: - $find_files = { - 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F1 89 B5 ?? ?? ?? ?? 8B 7D ?? 33 DB - 6A ?? 59 33 C0 89 5D ?? 89 4D ?? 66 89 45 ?? 89 5D ?? 89 5D ?? 89 4D ?? 66 89 45 ?? - 68 ?? ?? ?? ?? 8B D7 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 4D ?? 3B C8 - 74 ?? 88 9D ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 7D ?? ?? 8D 8D ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF 15 ?? ?? ?? ?? - 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 66 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 8D - 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D7 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 8D - ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - C6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? F6 85 - ?? ?? ?? ?? ?? 8D 45 ?? 74 ?? 6A ?? 50 8B CE E8 ?? ?? ?? ?? 8B F0 85 F6 0F 85 ?? ?? - ?? ?? 8B B5 ?? ?? ?? ?? EB ?? 83 7D ?? ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 FF 15 ?? ?? - ?? ?? 85 C0 74 ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? - 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 53 FF 15 ?? ?? - ?? ?? 8B 1D ?? ?? ?? ?? FF D3 8B F0 83 FE ?? 75 ?? 83 7F ?? ?? 8B C7 72 ?? 8B 07 68 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 83 7F ?? ?? 72 ?? 8B 3F 57 FF 15 ?? ?? - ?? ?? 85 C0 75 ?? FF D3 8B F0 EB ?? FF 15 ?? ?? ?? ?? EB ?? 33 F6 8D 4D ?? E8 ?? ?? - ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? C2 + $remote_connection_v1 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 8B + 5D ?? 8D 44 24 ?? 56 57 8B 7D ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A + ?? 6A ?? 6A ?? 58 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 74 ?? 6A ?? 58 53 66 89 44 24 + ?? FF 15 ?? ?? ?? ?? FF 75 ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? 66 89 44 24 ?? 8D 44 24 + ?? 6A ?? 50 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 8B CF 8D 51 ?? 8A 01 41 84 C0 75 ?? + 6A ?? 2B CA 51 57 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 33 C0 8B 8C 24 ?? ?? ?? ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D C2 } - $remote_connection_p1 = { - 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 8B 5D ?? 56 57 6A ?? 8B FA 8B F1 - FF 15 ?? ?? ?? ?? 33 C0 50 50 89 45 ?? 89 45 ?? 8D 45 ?? 50 8D 45 ?? 50 6A ?? 57 56 - FF 15 ?? ?? ?? ?? 8B D3 8B C8 E8 ?? ?? ?? ?? 83 3B ?? 8B F0 75 ?? 68 ?? ?? ?? ?? EB - ?? 81 3B ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? EB ?? 81 3B ?? ?? ?? - ?? 74 ?? 81 3B ?? ?? ?? ?? 74 ?? 85 F6 74 ?? 83 C8 ?? EB ?? 83 65 ?? ?? 8D 75 ?? 8B - 45 ?? 8B FB C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? A5 A5 A5 8B 4D ?? 5F 5E 33 CD 5B E8 ?? - ?? ?? ?? C9 C3 + $check_mutex_v1 = { + E8 ?? ?? ?? ?? 59 59 56 C6 45 ?? ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 50 FF B5 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 7D ?? ?? 7E ?? 8B 57 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 59 FF 77 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B C8 C6 45 ?? ?? E8 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 50 56 FF D3 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? + 56 FF 15 ?? ?? ?? ?? 8B F8 FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 94 C0 85 FF 74 ?? 84 + C0 74 ?? 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 56 } - $remote_connection_p2 = { - 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 8B 5D ?? 56 57 6A ?? 8B FA 8B F1 - FF 15 ?? ?? ?? ?? 33 C0 50 50 50 89 45 ?? 8D 45 ?? 50 FF 75 ?? 57 56 FF 15 ?? ?? ?? - ?? 8B D3 8B C8 E8 ?? ?? ?? ?? 83 3B ?? 8B F0 75 ?? 68 ?? ?? ?? ?? EB ?? 81 3B ?? ?? - ?? ?? 75 ?? 68 ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 85 F6 74 ?? 83 C8 ?? EB ?? 83 65 ?? - ?? 8D 75 ?? 8B 45 ?? 8B FB C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? A5 A5 A5 8B 4D ?? 5F 5E - 33 CD 5B E8 ?? ?? ?? ?? C9 C3 + $find_files_v2 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? 00 00 00 00 83 EC ?? 53 + 56 57 89 65 ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 + ?? ?? 8D 4D ?? 54 E8 ?? ?? ?? ?? 83 EC ?? 8D 4D ?? 54 E8 ?? ?? ?? ?? 83 EC ?? 8D 4D + ?? 54 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? E8 ?? + ?? ?? ?? 83 EC ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? + 3B 45 ?? 0F 87 ?? ?? ?? ?? 83 EC ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? + 51 50 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B F0 8D 45 ?? 3B C6 74 ?? 8B 45 ?? 83 F8 + ?? 72 ?? 6A ?? 40 50 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 56 + 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B + 7D ?? 33 F6 8B 5D ?? 83 FE ?? 73 ?? 8B 0C B5 ?? ?? ?? ?? 8D 45 ?? 83 FF ?? 0F 43 C3 + 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 + ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 74 ?? 46 EB ?? 8D 4D ?? E8 ?? ?? + ?? ?? B0 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C2 ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? 8B 4D ?? 32 C0 5F 5E 64 89 0D ?? ?? ?? ?? 5B 8B E5 5D C2 ?? ?? 8D 45 } - $encrypt_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? - 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 8B 45 ?? 83 F8 ?? C7 45 ?? ?? ?? ?? ?? 0F - 94 C7 83 F8 ?? 0F 94 C3 83 F8 ?? 75 ?? B8 ?? ?? ?? ?? EB ?? 0F B6 C3 83 F0 ?? 8D 04 - 45 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 6A ?? FF 76 ?? FF 15 ?? ?? ?? ?? 8B C8 89 4E ?? - 85 C9 0F 84 ?? ?? ?? ?? 84 FF 74 ?? BF ?? ?? ?? ?? EB ?? 0F B6 C3 8D 3C 45 ?? ?? ?? - ?? 8B 56 ?? 8B 46 ?? 85 D2 7C ?? 0F 8F ?? ?? ?? ?? 85 C0 72 ?? 85 D2 7C ?? 0F 8F ?? - ?? ?? ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 83 F8 ?? 74 ?? 89 55 ?? EB ?? 0F 57 C0 66 0F 13 - 45 ?? 8B 45 ?? FF 75 ?? 50 FF 75 ?? FF 75 ?? 57 51 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D - 4D ?? 89 46 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? - 59 5F 5E 5B 8B E5 5D C2 + $encrypt_files_v2_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? 00 00 00 00 51 B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 53 56 57 C7 45 ?? ?? ?? ?? ?? 8B F1 8B 7D ?? 8D 4D ?? 89 65 ?? + 57 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 8B CE 50 E8 + ?? ?? ?? ?? 8B D8 C6 45 ?? ?? 8D 4D ?? 89 5D ?? E8 ?? ?? ?? ?? 8B 75 ?? 56 E8 ?? ?? + ?? ?? 83 C4 ?? 56 53 50 E8 ?? ?? ?? ?? 8B 75 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 + 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 83 C4 ?? 49 0F 1F 40 ?? 8A 41 ?? 8D 49 ?? 84 C0 + 75 ?? A1 ?? ?? ?? ?? ?? ?? ?? ?? 00 00 08 89 ?? ?? ?? ?? 4E 00 6A ?? 6A ?? 89 41 ?? + A1 ?? ?? ?? ?? ?? ?? ?? ?? 08 A0 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? 88 + 41 ?? FF D6 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 89 45 ?? 8D 85 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 50 FF D6 68 ?? ?? ?? ?? 6A ?? 6A ?? 89 45 ?? 8D 45 ?? 6A ?? 50 FF 15 ?? ?? + ?? ?? 8B 35 ?? ?? ?? ?? 85 C0 75 ?? FF D6 8B 1D ?? ?? ?? ?? 6A ?? FF 75 ?? FF D3 EB + ?? 8B 1D ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? + ?? 85 C0 75 ?? FF D6 6A ?? FF 75 ?? FF D3 6A ?? 6A ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? + 85 C0 75 ?? FF D6 8D 45 ?? 50 6A ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? + ?? 85 C0 75 ?? FF D6 6A ?? FF 75 ?? FF D3 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 } - $encrypt_files_p2 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 56 A1 ?? ?? ?? ?? 33 C5 - 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 83 7E ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? - ?? 8B 4D ?? 85 C9 74 ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? EB ?? 8B 45 ?? 85 C0 74 ?? 0F - 8E ?? ?? ?? ?? 83 F8 ?? 7E ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? EB ?? F6 C1 ?? C7 45 ?? ?? - ?? ?? ?? B8 ?? ?? ?? ?? 0F 95 C0 40 89 45 ?? 83 7D ?? ?? 7F ?? 0F 8C ?? ?? ?? ?? 83 - 7D ?? ?? 0F 82 ?? ?? ?? ?? 83 7D ?? ?? 7F ?? 0F 8C ?? ?? ?? ?? 83 7D ?? ?? 0F 82 ?? - ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 8D 45 ?? 8B - CE 50 E8 ?? ?? ?? ?? 8D 45 ?? 8B CE 50 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 8B E5 5D C2 ?? ?? 8D 45 ?? 6A - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 C6 45 ?? - ?? E8 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 8D 4D ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 45 - ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 C6 - 45 ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 68 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 + $encrypt_files_v2_p2 = { + E8 ?? ?? ?? ?? 8B 7D ?? 83 C4 ?? 33 F6 C7 45 ?? ?? ?? ?? ?? 33 DB 89 5D ?? 56 57 FF + 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 4D ?? 66 8B 0D ?? ?? 4E 00 66 89 4D ?? 8D 4D ?? + 89 45 ?? 8D 51 ?? 89 5D ?? 8A 01 41 84 C0 75 ?? 6A ?? 8D 45 ?? 2B CA 50 51 8D 45 ?? + 50 FF 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? FF 75 ?? FF 75 ?? FF + 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? + ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 66 0F 1F 44 00 ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 03 + F0 33 C9 3B 75 ?? 75 ?? 85 C9 75 ?? 33 DB 83 F8 ?? 0F 95 C3 68 ?? ?? ?? ?? 8D 45 ?? + 50 8D 85 ?? ?? ?? ?? 50 6A ?? 53 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? + 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF 75 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? + ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 8D 45 ?? 6A ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F + 85 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? + FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 57 FF D6 FF 75 ?? FF D6 8B 4D ?? 5F 5E 64 89 0D + ?? ?? ?? ?? 5B 8B E5 5D C2 ?? ?? 8D 45 + } + $remote_connection_v2 = { + 55 8B EC 51 53 56 57 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 56 + FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D8 6A ?? + 53 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B F8 6A ?? 57 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? + 8D 45 ?? 50 57 FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 53 FF D6 57 FF D6 5F 5E + 33 C0 5B 8B E5 5D C3 + } + $drop_ransom_note_v2_p1 = { + 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 89 45 ?? + C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 6A ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 85 C0 74 ?? C7 00 ?? ?? ?? ?? C7 + 40 ?? ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 89 08 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? ?? ?? ?? ?? 87 FB 00 00 00 A0 ?? ?? + ?? ?? 88 87 ?? ?? ?? ?? 8B F7 8D 4E ?? 0F 1F 40 ?? 8A 06 46 84 C0 75 ?? 2B F1 8D 46 + ?? 50 E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 DB 74 ?? 56 57 53 E8 ?? ?? ?? ?? 6A ?? 8D 04 + 33 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F3 8D 4E ?? 0F 1F 44 00 ?? 8A 06 46 + 84 C0 75 ?? 2B F1 8D 86 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 56 + 53 57 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 04 37 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 8B F7 8D 4E ?? 8A 06 46 84 C0 75 ?? 2B F1 8D 86 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B + D8 83 C4 ?? 85 DB 74 ?? 56 57 53 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 04 33 68 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F3 8D 4E ?? 8A 06 46 84 C0 75 ?? 2B F1 8D 46 ?? 50 + } + $drop_ransom_note_v2_p2 = { + E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 56 53 57 E8 ?? ?? ?? ?? 6A ?? 8D 04 37 68 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F7 8D 4E ?? 0F 1F 00 8A 06 46 84 C0 75 ?? + 2B F1 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 DB 74 ?? 56 57 53 E8 ?? ?? ?? ?? + F3 0F 7E 05 ?? ?? ?? ?? 83 C4 ?? 66 0F D6 04 33 8B F3 8D 4E ?? 8A 06 46 84 C0 75 ?? + 2B F1 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 56 53 57 E8 ?? ?? ?? ?? + 6A ?? 8D 04 37 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F7 8D 4E ?? 8A 06 46 84 + C0 75 ?? 2B F1 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 DB 74 ?? 56 57 53 E8 ?? + ?? ?? ?? 6A ?? 8D 04 33 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F3 8D 4E ?? 66 + 90 8A 06 46 84 C0 75 ?? 2B F1 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? + 56 53 57 E8 ?? ?? ?? ?? 6A ?? 8D 04 37 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B + CF 5B 8D 51 ?? 0F 1F 40 ?? 8A 01 41 84 C0 75 ?? 8B 75 ?? 8D 45 ?? 6A ?? 50 2B CA 51 + 57 56 FF 15 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 56 FF 15 ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? 8B 4D ?? 5F 5E 64 89 0D ?? ?? ?? ?? 8B E5 5D C2 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ((( all of ($encrypt_files_v1_p*)) and ( all of ($find_files_v1_p*)) and ($create_scheduled_task_v1) and ($remote_connection_v1) and ($check_mutex_v1)) or (($find_files_v2) and ( all of ($encrypt_files_v2_p*)) and ($remote_connection_v2) and ( all of ($drop_ransom_note_v2_p*)))) } -rule REVERSINGLABS_Win32_Ransomware_Ryuk : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Dmalocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Ryuk ransomware." + description = "Yara rule that detects DMALocker ransomware." author = "ReversingLabs" - id = "179c9277-0bdc-522a-a822-cf93febff408" + id = "3ddef0f1-61c9-59f6-a02c-35768c2cd4d6" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Ryuk.yara#L1-L199" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "bf93892b281be20917656e242cbb0f3b3694439556b7e5e40a424ba1aa909105" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.DMALocker.yara#L1-L149" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "107dbc4cacd9d451e9c6fe8aa91cd612f70ac767ee70f74f3a77d1e5548b054f" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -25698,186 +27079,140 @@ rule REVERSINGLABS_Win32_Ransomware_Ryuk : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Ryuk" + tc_detection_name = "DMALocker" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? - 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 - FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? - ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? - ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 D2 89 55 ?? 0F 57 C0 66 0F 13 - 45 ?? 83 7D ?? ?? 74 ?? 8D 45 ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8D 55 ?? 52 8B 45 - ?? 50 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? 83 7D ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? ?? - ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 0F 57 C0 66 0F 13 45 ?? 83 7D ?? ?? 77 ?? 81 7D - ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 6A ?? 6A ?? 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? - 6A ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 45 ?? - 89 55 ?? 83 7D ?? ?? 72 ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 76 ?? 6A ?? 6A ?? 8B 4D ?? 51 - 8B 55 ?? 52 E8 ?? ?? ?? ?? 6A ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 - 50 E8 ?? ?? ?? ?? 89 45 ?? 89 55 ?? 83 7D ?? ?? 77 ?? 72 ?? 81 7D ?? ?? ?? ?? ?? 77 - ?? 83 7D ?? ?? 77 ?? 72 ?? 83 7D ?? ?? 73 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 76 ?? 83 7D ?? ?? 77 ?? 72 - ?? 81 7D ?? ?? ?? ?? ?? 73 ?? 6A ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 6A - ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 45 ?? 89 - 55 ?? EB ?? 83 7D ?? ?? 77 ?? 72 ?? 81 7D ?? ?? ?? ?? ?? 73 ?? 6A ?? 6A ?? 8B 55 ?? - 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? - 52 50 E8 ?? ?? ?? ?? 89 45 ?? 89 55 ?? 83 7D ?? ?? 77 ?? 72 ?? 81 7D + $dmalock_v1_encrypt_files_1 = { + 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? + ?? ?? A3 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 + F8 ?? 75 ?? 32 C0 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8A 9D ?? ?? ?? + ?? 33 C0 84 DB 74 ?? EB ?? 8D [2-5] 8A 90 ?? ?? ?? ?? 84 D2 74 ?? 8A 8C 05 + ?? ?? ?? ?? 3A CA 74 ?? 80 F1 ?? 3A CA 75 ?? 40 80 BC 05 ?? ?? ?? ?? ?? 75 ?? 8A 8C + 05 ?? ?? ?? ?? 3A 88 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 33 C0 84 DB 74 ?? 8A 90 ?? ?? ?? + ?? 84 D2 74 ?? 8A 8C 05 ?? ?? ?? ?? 3A CA } - $encrypt_files_p2 = { - 77 ?? 83 7D ?? ?? 77 ?? 72 ?? 83 7D ?? ?? 77 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? 8B 4D ?? 89 8D ?? ?? ?? ?? 8B 55 ?? 89 95 ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 72 ?? - 83 7D ?? ?? 73 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 7D - ?? ?? 0F 84 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 77 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 0F - 86 ?? ?? ?? ?? 8B 4D ?? 81 E9 ?? ?? ?? ?? 89 4D ?? 6A ?? 6A ?? 8B 55 ?? 52 8B 45 ?? - 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? B8 ?? - ?? ?? ?? E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - 6A ?? 8D 95 ?? ?? ?? ?? 52 6A ?? 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? - 89 45 ?? 83 7D ?? ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? - 8B 55 ?? 83 C2 ?? 89 55 ?? 83 7D ?? ?? 0F 83 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? - ?? 8B 45 ?? 0F BE 8C 05 ?? ?? ?? ?? 83 F9 ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 0F BE 84 15 - ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 4D ?? 0F BE 94 0D ?? ?? ?? ?? 83 FA ?? 0F - 85 ?? ?? ?? ?? 8B 45 ?? 0F BE 8C 05 ?? ?? ?? ?? 83 F9 ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? - 0F BE 84 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 4D ?? 0F BE 94 0D ?? ?? ?? ?? - 83 FA ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 8D ?? - ?? ?? ?? 8B 15 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 66 A1 ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 BD ?? - ?? ?? ?? ?? 75 ?? 8B 45 ?? 89 45 ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? - 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8B 55 ?? 52 8B 45 ?? - 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? E9 + $dmalock_v1_encrypt_files_2 = { + EB ?? 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B BD ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? 52 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? + ?? 8B 4D ?? 5F 5E 33 CD B0 ?? 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } - $encrypt_files_p3 = { - 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? - ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 55 ?? 52 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 - FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? - ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D - ?? ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 6A ?? 6A ?? 6A - ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 50 8B 45 ?? 50 FF 15 ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B - 55 ?? 52 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? - 8D 45 ?? 50 6A ?? 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? - ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? - 51 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 6A ?? - 68 ?? ?? ?? ?? 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 6A ?? 68 + $dmalock_v1_encrypt_files_3 = { + 74 ?? 80 F1 ?? 3A CA 75 ?? 40 80 BC 05 ?? ?? ?? ?? ?? 75 ?? 8A 8C 05 ?? ?? ?? ?? 3A + 88 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 56 8D 95 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 52 E8 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 83 C4 ?? A8 ?? 74 ?? A8 ?? 0F 85 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 56 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B 55 + ?? 8B 85 ?? ?? ?? ?? 52 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 } - $encrypt_files_p4 = { - 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 89 45 ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? EB ?? 8B 4D ?? 83 C1 ?? 89 4D ?? 8B 55 ?? 3B 55 ?? 0F 87 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 3B 45 ?? 75 ?? 8B 4D ?? 89 4D ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 69 55 ?? ?? ?? ?? ?? 52 8B 45 ?? 50 FF 15 - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? - ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B - 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? - ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? - ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A ?? 6A ?? 8B 4D ?? 51 6A - ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? - 51 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 55 ?? 52 8D 45 ?? 50 8B 4D ?? - 51 6A ?? 8B 55 ?? 52 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4D ?? 51 FF - 15 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A - ?? 69 45 ?? ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? - ?? ?? ?? ?? 75 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? B8 ?? - ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8B 45 ?? - 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 55 - ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 + $dmalock_v1_enum_shares_and_discs_type_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 57 68 ?? ?? + ?? ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B ?? 83 C4 ?? 89 ?? ?? ?? ?? ?? C6 85 ?? + ?? ?? ?? ?? 85 ?? 0F 84 ?? ?? ?? ?? ?? 32 DB E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? ?? + 8B F8 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 ?? 6A ?? 89 45 ?? 66 89 45 ?? 88 45 ?? 8D 45 ?? + 6A ?? 50 88 5D ?? E8 ?? ?? ?? ?? 6A ?? 8D 4D ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 75 ?? B3 ?? 6A ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 DB 74 ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 32 C0 5F 5E 5B 8B 4D ?? 33 CD + E8 ?? ?? ?? ?? 8B E5 5D C3 8D 95 ?? ?? ?? ?? 52 ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 83 BD ?? ?? ?? ?? ?? 77 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 72 ?? C6 + 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? + 8B 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 51 52 68 } - $encrypt_files_p5 = { - E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8A 0D ?? ?? ?? ?? 88 4D ?? 33 D2 89 55 - ?? 89 55 ?? 89 55 ?? 89 55 ?? 88 55 ?? 6A ?? 6A ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? - ?? 83 7D ?? ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 33 C9 89 8D ?? ?? ?? ?? 6A ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 - 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 89 95 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 E8 ?? - ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? - ?? 51 8D 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? - 83 C4 ?? 8D 4D ?? 51 8D 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8D 45 ?? 50 8D 4D ?? - 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8D 45 ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 50 8D 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? - 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 - ?? ?? ?? ?? 8D 55 ?? 52 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? - 50 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? - ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 55 ?? 52 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 8B 4D - ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B + $dmalock_v1_enum_shares_and_discs_type_2 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 8B 5D ?? 56 57 + 8D 8D ?? ?? ?? ?? 51 50 6A ?? 6A ?? 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 33 C0 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 ?? ?? 8B 95 ?? ?? ?? + ?? 52 6A ?? FF 15 ?? ?? ?? ?? 8B F8 89 BD ?? ?? ?? ?? 85 FF 75 ?? 50 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 ?? + ?? 8D A4 24 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 6A ?? 57 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 57 8D 95 ?? ?? ?? ?? 52 50 FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 39 85 ?? ?? ?? ?? 76 ?? 8D 77 ?? EB ?? 8D A4 24 + ?? ?? ?? ?? 83 7E ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 51 + C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 0E 8B C1 83 C4 ?? 8D 78 ?? 8B FF 8A 10 40 84 + D2 75 ?? 2B C7 50 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 8B 06 83 C4 ?? 8D 50 ?? 90 + 8A 08 40 84 C9 75 ?? 2B C2 6A ?? 8D 84 05 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 8B 4D ?? 83 C4 ?? 51 8D 95 ?? ?? ?? ?? 53 52 E8 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 83 + C4 ?? 8B 46 ?? 83 E0 ?? 3C ?? 75 ?? 8B 4D ?? 51 53 8D 56 ?? 52 E8 ?? ?? ?? ?? 85 C0 + 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 40 83 C6 ?? 89 85 ?? + ?? ?? ?? 3B 85 ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? E9 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 50 + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 8B 4D ?? F7 D8 5F 1B C0 5E 33 CD 40 5B E8 ?? ?? ?? ?? 8B E5 5D C2 } - $encrypt_files_p6 = { - 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 8D 8D ?? ?? ?? ?? 51 8B 55 ?? - 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D - ?? 51 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 81 7D ?? ?? - ?? ?? ?? 0F 86 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 D2 89 55 ?? 0F 57 C0 66 0F 13 45 - ?? 6A ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? - ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 8D 95 ?? ?? - ?? ?? 52 6A ?? 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? - 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? - ?? B8 ?? ?? ?? ?? EB ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 55 ?? - 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D - ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? EB ?? B8 - ?? ?? ?? ?? 8B E5 5D C3 + $dmalock_v1_enum_shares_and_discs_type_3 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 57 68 ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? A3 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? 6A ?? 51 8B D8 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? A3 ?? ?? ?? ?? BF ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? F7 C3 ?? ?? ?? ?? 76 ?? 57 8D 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? + ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B F0 56 68 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 FE ?? 74 ?? 83 FE ?? 74 ?? 83 FE ?? 75 ?? 8B + 55 ?? 8B 85 ?? ?? ?? ?? 52 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 47 D1 EB + FF 8D ?? ?? ?? ?? 75 ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } - $remote_connection = { - 55 8B EC 81 EC ?? ?? ?? ?? 8B 45 ?? C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 51 6A ?? 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? - 89 45 ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? - ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8D 4D ?? 51 8B 55 ?? 52 6A ?? 6A ?? 6A ?? E8 - ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 45 ?? EB ?? 8B 4D ?? 8B 51 ?? - 89 55 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? 89 45 ?? C7 45 ?? ?? ?? ?? - ?? 8B 4D ?? 8B 51 ?? 89 55 ?? EB ?? 8B 45 ?? 8B 48 ?? 89 4D ?? 83 7D ?? ?? 0F 84 ?? - ?? ?? ?? 8B 55 ?? 83 C2 ?? 89 55 ?? 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 83 C1 ?? 51 E8 ?? - ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? B9 ?? - ?? ?? ?? 6B D1 ?? 8D 8C 15 ?? ?? ?? ?? 3B C1 74 ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? - 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 0F 57 C0 66 0F 13 45 ?? C7 45 ?? ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 83 C8 ?? E9 ?? ?? - ?? ?? 8D 55 ?? 89 55 ?? 8D 45 ?? 50 8B 4D ?? 0F B6 51 ?? 52 E8 + $dmalock_v2_enum_logical_disks = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 33 DB 68 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 53 50 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F BE 4D ?? 51 8D 95 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 88 9D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? + ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 85 C0 75 ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? + B0 ?? 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 4D ?? 8A C3 33 CD 5B E8 ?? ?? + ?? ?? 8B E5 5D C3 } - $find_files_p1 = { - 8B FF 55 8B EC 51 8B 4D ?? 53 57 33 DB 8D 51 ?? 66 8B 01 83 C1 ?? 66 3B C3 75 ?? 8B - 7D ?? 2B CA D1 F9 83 C8 ?? 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 56 8D 5F ?? - 03 D9 6A ?? 53 E8 ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? - ?? 83 C4 ?? 85 C0 75 ?? FF 75 ?? 2B DF 8D 04 7E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 75 ?? 8B 4D ?? 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5F - 5B 8B E5 5D C3 33 C0 50 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? - ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 55 ?? 8B 4D ?? 53 8B 5D ?? 56 57 6A ?? 5E 6A ?? - 89 95 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 5F EB ?? 0F B7 01 66 3B 85 ?? ?? ?? - ?? 74 ?? 66 3B C6 74 ?? 66 3B C7 74 ?? 83 E9 ?? 3B CB 75 ?? 0F B7 31 66 3B F7 75 ?? - 8D 43 ?? 3B C8 74 ?? 52 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 6A ?? - 8B C6 33 FF 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 8B C7 + $dmalock_v4_remote_server_communication = { + 85 FF 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 83 FB ?? 0F + 87 ?? ?? ?? ?? FF 24 9D ?? ?? ?? ?? 8B 46 ?? 50 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 + C4 ?? B0 ?? C3 8B 4E ?? 8B 56 ?? 51 52 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 + ?? C3 8B 46 ?? 8B 4E ?? 50 51 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? C3 8B + 56 ?? 8B 46 ?? 52 50 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? C3 8B 4E ?? 8B + 56 ?? 51 52 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? C3 8B 46 ?? 8B 4E ?? 8B + 56 ?? 50 51 52 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? C3 8B 46 ?? 8B 4E ?? + 50 51 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? C3 32 C0 C3 } - $find_files_p2 = { - EB ?? 33 C0 40 2B CB 0F B6 C0 D1 F9 41 F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 - 57 53 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? 8B 85 ?? ?? ?? ?? 50 57 57 53 E8 ?? ?? - ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD - 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 8D ?? ?? ?? ?? 6A ?? 8B 41 ?? 2B 01 C1 F8 ?? 89 85 - ?? ?? ?? ?? 58 66 39 85 ?? ?? ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 66 39 85 ?? ?? - ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 51 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 8B 8D - ?? ?? ?? ?? 85 C0 6A ?? 58 75 ?? 8B C1 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 - ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? - 83 C4 ?? E9 + $dmalock_v4_encrypt_file_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 57 68 ?? ?? + ?? ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 0F 84 ?? ?? ?? ?? 56 + 32 DB E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 56 8B F8 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 56 + 6A ?? 89 45 ?? 89 45 ?? 66 89 45 ?? 8D 45 ?? 6A ?? 50 88 5D ?? E8 ?? ?? ?? ?? 6A ?? + 8D 4D ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B3 ?? 6A ?? 57 56 E8 + ?? ?? ?? ?? 83 C4 ?? 84 DB 74 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5F 5E 5B 8B 4D ?? + 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $dmalock_v4_encrypt_file_2 = { + 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 6A ?? 52 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 89 B5 ?? ?? ?? + ?? 85 F6 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B + D8 6A ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 83 3D ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? 0F 85 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 89 B5 ?? ?? ?? ?? 85 F6 74 + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 46 ?? 85 C0 74 ?? 8B 75 ?? B9 ?? ?? ?? + ?? 8B F8 F3 A5 66 A5 8B B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 46 + ?? EB ?? 33 F6 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 7E ?? 57 89 35 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8B C6 E8 ?? ?? ?? ?? 84 C0 74 ?? 8B 4E ?? 8B 17 56 6A + ?? 6A ?? 68 ?? ?? ?? ?? 51 52 FF 15 ?? ?? ?? ?? 85 C0 74 ?? C6 46 ?? ?? 8B B5 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 53 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 56 6A ?? 6A ?? 68 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 56 52 6A ?? 53 E8 ?? ?? ?? ?? 8B 45 ?? + 8B 8D ?? ?? ?? ?? 56 50 6A ?? 51 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 5F 5E 33 + CD B8 ?? ?? ?? ?? 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($remote_connection) + uint16(0)==0x5A4D and ($dmalock_v1_encrypt_files_1 and $dmalock_v1_encrypt_files_2 and $dmalock_v1_encrypt_files_3 and $dmalock_v1_enum_shares_and_discs_type_1) or ($dmalock_v1_encrypt_files_1 and $dmalock_v1_encrypt_files_2 and $dmalock_v1_encrypt_files_3 and $dmalock_v1_enum_shares_and_discs_type_2) or ($dmalock_v1_encrypt_files_1 and $dmalock_v1_encrypt_files_2 and $dmalock_v1_encrypt_files_3 and $dmalock_v1_enum_shares_and_discs_type_3) or ($dmalock_v1_encrypt_files_1 and $dmalock_v1_encrypt_files_3 and $dmalock_v1_enum_shares_and_discs_type_1 and $dmalock_v2_enum_logical_disks) or ($dmalock_v4_encrypt_file_1 and $dmalock_v4_encrypt_file_2 and $dmalock_v4_remote_server_communication and $dmalock_v2_enum_logical_disks) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Venom : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Zerolocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Venom ransomware." + description = "Yara rule that detects ZeroLocker ransomware." author = "ReversingLabs" - id = "72149ec2-888e-5bed-baf1-0ec44e48328e" - date = "2022-06-06" - modified = "2022-06-06" + id = "291b5640-387c-54d9-97a6-13823932fa60" + date = "2021-08-12" + modified = "2021-08-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Venom.yara#L1-L68" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "5817ece6a1cc304835f7fc243c4cfdc3c7cacd2251a9ac294a6662b58d2552e8" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.ZeroLocker.yara#L1-L70" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "147e4b390bcfaff8f05059c1d9a98b50f544fc32e820406417894fe5046e0f71" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -25885,61 +27220,72 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Venom : TC_DETECTION MALICIOUS MALWA sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Venom" + tc_detection_name = "ZeroLocker" tc_detection_factor = 5 importance = 25 strings: - $setup_env = { - 00 28 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 07 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 1B - 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 1F ?? 28 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 07 6F ?? ?? - ?? ?? 13 ?? 2B ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 00 06 11 ?? 28 ?? ?? ?? ?? 00 00 12 ?? 28 - ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 72 ?? ?? ?? ?? 1F - ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 1F ?? - 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 1F ?? 28 ?? ?? ?? ?? 72 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 72 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 0C 72 ?? ?? ?? ?? 20 ?? ?? ?? ?? 19 7E ?? ?? ?? ?? 19 16 7E ?? ?? ?? - ?? 28 ?? ?? ?? ?? 0D 09 08 20 ?? ?? ?? ?? 12 ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 17 28 - ?? ?? ?? ?? 00 2A + $encrypt_routine_1 = { + 00 28 5B 00 00 0A 20 ?? 07 00 00 28 60 00 00 06 13 09 20 ?? 07 00 00 28 60 00 00 06 13 + 0B 02 03 20 ?? 07 00 00 28 60 00 00 06 20 ?? 07 00 00 28 60 00 00 06 73 ?? 00 00 0A 7D + 1B 00 00 04 20 ?? 07 00 00 28 60 00 00 06 13 0B 02 04 20 ?? 07 00 00 28 60 00 00 06 20 + ?? 07 00 00 28 60 00 00 06 73 ?? 00 00 0A 7D 1C 00 00 04 20 ?? 07 00 00 28 60 00 00 06 + 13 0B 02 7B 1C 00 00 04 20 ?? 07 00 00 28 60 00 00 06 6A 6F ?? 00 00 0A 00 20 ?? 07 00 + 00 28 60 00 00 06 13 0B 20 ?? 07 00 00 28 60 00 00 06 8D 1E 00 00 01 0A 20 ?? 07 00 00 + 28 60 00 00 06 13 0B 20 ?? 07 00 00 28 60 00 00 06 6A 13 04 20 ?? 07 00 00 28 60 00 00 + 06 13 0B 02 7B 1B 00 00 04 6F ?? 00 00 0A [0-2] 13 05 20 ?? 07 00 00 28 60 00 00 06 13 + 0B 73 ?? 00 00 0A 0C 20 ?? 07 00 00 28 60 00 00 06 13 0B 00 0E 05 20 ?? 07 00 00 28 60 + 00 00 06 59 13 0C 11 0C 45 02 00 00 00 02 00 00 00 ?? 00 00 00 2B ?? 00 20 ?? 07 00 00 + 28 60 00 00 06 13 0B 02 7B 1C 00 00 04 08 05 0E 04 6F ?? 00 00 0A [0-2] 20 ?? 07 00 00 + 28 60 00 00 06 73 ?? 00 00 0A 0B 2B ?? 00 20 ?? 07 00 00 28 60 00 00 06 13 0B 02 7B 1C + 00 00 04 08 05 0E 04 6F ?? 00 00 0A [0-2] 20 ?? 07 00 00 28 60 00 00 06 73 ?? 00 00 0A + 0B 00 2B 62 20 ?? 07 00 00 28 60 00 00 06 13 0B 02 7B 1B 00 00 04 06 20 ?? 07 00 00 28 + 60 00 00 06 20 ?? 07 00 00 28 60 00 00 06 6F ?? 00 00 0A [0-2] 0D 20 ?? 07 00 00 28 60 } - $find_files = { - 00 00 00 03 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 06 07 9A 0C 00 00 08 72 ?? ?? ?? ?? 6F ?? ?? - ?? ?? 16 FE 01 0D 09 2C ?? 00 08 02 28 ?? ?? ?? ?? 00 00 00 DE ?? 26 00 00 DE ?? 00 07 - 17 58 0B 07 06 8E 69 32 ?? 00 03 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 13 - ?? 00 11 ?? 02 28 ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? 00 DE ?? - 26 00 00 DE ?? 2A + $encrypt_routine_2 = { + 00 00 06 13 0B 07 06 20 ?? 07 00 00 28 60 00 00 06 09 6F ?? 00 00 0A 00 20 ?? 07 00 00 + 28 60 00 00 06 13 0B 11 04 09 6A D6 13 04 00 20 ?? 07 00 00 28 60 00 00 06 13 0B 11 04 + 11 05 FE 04 13 0D 11 0D 2D 86 ?? 45 01 00 00 00 F6 FF FF FF 17 2D 06 D0 4F 00 00 06 26 + 20 ?? 07 00 00 28 60 00 00 06 13 0B 07 6F ?? 00 00 0A 00 20 ?? 07 00 00 28 60 00 00 06 + 13 0B 02 7B 1B 00 00 04 6F ?? 00 00 0A 00 20 ?? 07 00 00 28 60 00 00 06 13 0B 02 7B 1C + 00 00 04 6F ?? 00 00 0A 00 20 ?? 07 00 00 28 60 00 00 06 13 0B 0E 05 20 ?? 07 00 00 28 + 60 00 00 06 FE 01 13 0D 11 0D 2C 32 ?? 45 01 00 00 00 F6 FF FF FF 20 ?? 07 00 00 28 60 + 00 00 06 13 0B 03 73 ?? 00 00 0A 13 06 20 ?? 07 00 00 28 60 00 00 06 13 0B 11 06 6F ?? + 00 00 0A 00 00 20 ?? 07 00 00 28 60 00 00 06 13 0B 0E 05 20 ?? 07 00 00 28 60 00 00 06 + FE 01 13 0D 11 0D 2C ?? [0-20] 20 ?? 07 00 00 28 60 00 00 06 13 0B 03 73 ?? 00 00 0A 13 + 07 20 ?? 07 00 00 28 60 00 00 06 13 0B 11 07 6F ?? 00 00 0A 00 00 20 ?? ?? 00 00 28 60 + 00 00 06 13 0B 02 7B 1B 00 00 04 6F ?? 00 00 0A 00 20 ?? ?? 00 00 28 60 00 00 06 13 0B + 02 7B 1C 00 00 04 6F ?? 00 00 0A 00 DD 3B 01 00 00 11 0A 2B 0D 11 0A 20 ?? ?? 00 00 28 } - $encrypt_files = { - 00 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 03 6F ?? ?? ?? ?? 0B 02 72 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 18 73 ?? ?? ?? ?? 0C 73 ?? ?? ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 20 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 00 09 18 6F ?? ?? ?? ?? 00 07 06 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? - 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 11 ?? 09 6F - ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 17 6F ?? ?? ?? ?? 00 08 06 16 06 - 8E 69 6F ?? ?? ?? ?? 00 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 02 19 73 ?? ?? ?? - ?? 13 ?? 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? 13 ?? 00 2B ?? 00 11 ?? 11 ?? 16 11 ?? 6F ?? ?? - ?? ?? 00 00 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 25 13 ?? 16 FE 02 13 ?? 11 ?? 2D - ?? 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 - DE ?? DE ?? 00 11 ?? 6F ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? 00 00 02 28 ?? ?? ?? ?? 00 00 - DE ?? 26 00 00 DE ?? 00 DC 2A + $encrypt_routine_3 = { + 60 00 00 06 58 20 ?? 08 00 00 28 60 00 00 06 13 0A 45 26 00 00 00 00 00 00 00 ?? FC FF + FF ?? FC FF FF ?? FC FF FF ?? FC FF FF ?? FC FF FF ?? FC FF FF ?? FC FF FF ?? ?? FF FF + ?? FD FF FF ?? FD FF FF ?? FD FF FF 00 00 00 00 ?? FD FF FF ?? FD FF FF ?? FD FF FF ?? + FD FF FF ?? FD FF FF ?? FD FF FF ?? ?? FF FF ?? FD FF FF ?? FD FF FF ?? FD FF FF ?? ?? + FF FF ?? FE FF FF ?? FE FF FF ?? FE FF FF ?? FE FF FF ?? FE FF FF ?? FE FF FF ?? FE FF + FF ?? FE FF FF E8 FE FF FF FC FE FF FF 10 FF FF FF 11 FF FF FF 29 FF FF FF 41 FF FF FF + DE 6D 11 0B 13 0A 11 09 20 ?? 08 00 00 28 60 00 00 06 30 16 ?? 45 01 00 00 00 F6 FF FF + FF 20 ?? 08 00 00 28 60 00 00 06 2B 02 11 09 45 02 00 00 00 00 00 00 00 11 FF FF FF DE + 34 75 4B 00 00 01 14 FE 03 11 09 20 ?? 08 00 00 28 60 00 00 06 FE 03 5F 11 0A 20 ?? 08 + 00 00 28 60 00 00 06 FE 01 5F FE 11 74 4B 00 00 01 28 57 00 00 0A DE 93 20 ?? 08 00 00 + 28 60 00 00 06 28 ?? 00 00 0A } condition: - uint16(0)==0x5A4D and ($setup_env) and ($find_files) and ($encrypt_files) + uint16(0)==0x5A4D and ($encrypt_routine_1 and $encrypt_routine_2 and $encrypt_routine_3) } -rule REVERSINGLABS_Win32_Ransomware_Blackcat : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Ako : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects BlackCat ransomware." + description = "Yara rule that detects Ako ransomware." author = "ReversingLabs" - id = "e623340d-8df8-5f13-b75f-379bd0038f64" - date = "2022-02-14" - modified = "2022-02-14" + id = "00d67696-998c-5bc3-95e7-0320ca558cdb" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.BlackCat.yara#L1-L109" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "24932baa625aedd14b5776ba3209c9ee330e84538c5267eeb5e09e352f655835" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Ako.yara#L1-L152" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "488e9b528f75fcfaa8dd19859801e6e5a73575c33cd70c98ebaa9ae93025018b" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -25947,96 +27293,142 @@ rule REVERSINGLABS_Win32_Ransomware_Blackcat : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "BlackCat" + tc_detection_name = "Ako" tc_detection_factor = 5 importance = 25 strings: - $remote_connection_p1 = { - 8B 44 24 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? A1 ?? - ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 - ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? - ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 83 F8 ?? A1 ?? ?? ?? ?? 0F 45 C1 8B 0D ?? ?? - ?? ?? 0F 45 CA 8D 54 24 ?? 89 94 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? - ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 - 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? - ?? ?? ?? 56 51 FF 50 ?? 83 C4 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 56 68 ?? ?? ?? ?? - FF 74 24 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? - ?? ?? 6A ?? 56 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 - ?? E8 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 56 68 ?? ?? ?? ?? 68 ?? ?? - ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? 85 + $encrypt_network_shares_win32_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 4D ?? 8B 45 ?? 50 8D 4D ?? E8 ?? ?? + ?? ?? 8B 4D ?? 81 C1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F B6 C8 85 C9 0F 85 ?? ?? ?? ?? 8B + 4D ?? E8 ?? ?? ?? ?? 0F B6 D0 85 D2 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 45 + ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? E8 ?? ?? ?? ?? 0F B6 D0 85 D2 0F + 85 ?? ?? ?? ?? 8D 45 ?? 50 8B 4D ?? 83 C1 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B 4D ?? E8 ?? ?? ?? ?? 50 8D 95 + ?? ?? ?? ?? 52 8B 4D ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? E8 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 52 + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 + E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 } - $remote_connection_p2 = { - C0 89 44 24 ?? 0F 88 ?? ?? ?? ?? 8B 8B ?? ?? ?? ?? 74 ?? A1 ?? ?? ?? ?? 89 CB 85 C0 - 75 ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 74 24 ?? 6A ?? 50 E8 - ?? ?? ?? ?? 85 C0 89 D9 75 ?? E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 8B 5C 24 ?? 89 44 24 ?? - 53 51 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 44 24 ?? 89 F1 8D 54 24 ?? 89 44 24 ?? 89 5C 24 - ?? 89 5C 24 ?? C6 44 24 ?? ?? E8 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? 8B 84 24 ?? ?? ?? ?? 8B 9C 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? - ?? ?? ?? 3D ?? ?? ?? ?? 0F 43 C1 6A ?? 50 53 FF 74 24 ?? E8 ?? ?? ?? ?? 83 F8 ?? 89 - 44 24 ?? 75 ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 74 ?? 53 6A ?? FF 35 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 83 7C 24 ?? ?? 74 ?? FF 74 24 ?? 6A ?? FF 35 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 8B 5C 24 ?? 0F 84 ?? ?? ?? ?? 80 BB ?? ?? ?? ?? - ?? 0F 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB + $encrypt_network_shares_win32_p2 = { + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 50 8D 95 ?? + ?? ?? ?? 52 8B 4D ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? E8 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? 52 + 8B 4D ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? + E8 ?? ?? ?? ?? 0F B6 C8 85 C9 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 55 ?? + 83 C2 ?? 89 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 39 45 ?? 73 ?? 83 7D ?? ?? 76 ?? 8B 45 } - $enum_procs = { - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 39 F7 74 ?? - 69 C7 ?? ?? ?? ?? 89 4D ?? 01 C8 68 ?? ?? ?? ?? 89 DE 53 50 E8 ?? ?? ?? ?? 83 C4 ?? - 47 8D 85 ?? ?? ?? ?? 89 7D ?? 50 8B 5D ?? 53 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 89 - F3 89 C6 EB ?? 8D 4D ?? 89 F2 E8 ?? ?? ?? ?? 8B 4D ?? 8B 7D ?? EB ?? 31 FF 8B 75 ?? - 85 FF 75 ?? E9 ?? ?? ?? ?? 31 FF 53 E8 ?? ?? ?? ?? 8B 75 ?? 85 FF 0F 84 ?? ?? ?? ?? - 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 69 C7 ?? ?? ?? ?? 8B 4D ?? 8D BD ?? ?? ?? ?? 01 F0 89 - 45 ?? 8B 45 ?? 8D 04 40 8D 04 81 89 45 ?? EB + $encrypt_network_shares_win32_p3 = { + 33 D2 B9 ?? ?? ?? ?? F7 F1 85 D2 75 ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 8D 4D ?? E8 + ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? 89 45 ?? EB ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? + 8D 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 55 ?? 52 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + 8B 4D ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8B 4D ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 50 8D 95 ?? ?? ?? ?? 52 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? + ?? 50 8B 4D ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 8D + 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? 8A 45 ?? EB ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? 32 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D + C2 } - $find_files = { - 57 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 53 56 E8 ?? ?? ?? - ?? 83 F8 ?? 89 45 ?? 0F 84 ?? ?? ?? ?? 89 75 ?? A1 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? - ?? ?? 85 C0 0F 84 ?? ?? ?? ?? A3 ?? ?? ?? ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 85 C0 0F - 84 ?? ?? ?? ?? 89 C6 8B 45 ?? 8B 4D ?? 89 46 ?? 8B 45 ?? 89 46 ?? 8B 45 ?? 89 46 ?? - 8D 41 ?? C7 06 ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 89 CB 50 E8 ?? ?? - ?? ?? 83 C4 ?? 8B 45 ?? 89 43 ?? 89 73 ?? 8B 75 ?? 31 C0 C7 43 ?? ?? ?? ?? ?? F7 45 - ?? ?? ?? ?? ?? 89 03 75 ?? 83 7D ?? ?? 74 ?? 57 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 7D ?? ?? 75 ?? 83 7D ?? ?? 74 ?? 83 7D ?? ?? 74 ?? FF 75 ?? 6A ?? FF 35 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 5E 5F 5B 5D C3 + $find_files_win32_p1 = { + 8B FF 55 8B EC 51 8B 4D ?? 53 57 33 DB 8D 51 ?? 66 8B 01 83 C1 ?? 66 3B C3 75 ?? 8B + 7D ?? 2B CA D1 F9 8B C7 41 F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 56 8D 5F ?? 03 + D9 6A ?? 53 E8 ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? + 83 C4 ?? 85 C0 75 ?? FF 75 ?? 2B DF 8D 04 7E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? + 85 C0 75 ?? 8B 7D ?? 8B CF E8 ?? ?? ?? ?? 8B D8 85 DB 74 ?? 56 E8 ?? ?? ?? ?? 59 EB + ?? 8B 47 ?? 89 30 83 47 ?? ?? 33 DB 6A ?? E8 ?? ?? ?? ?? 59 8B C3 5E 5F 5B 8B E5 5D + C3 33 C0 50 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? + ?? ?? 33 C5 89 45 ?? 8B 55 ?? 8B 4D ?? 53 8B 5D ?? 89 8D ?? ?? ?? ?? 56 57 3B D3 74 + ?? 0F B7 02 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 84 C0 75 ?? 83 EA ?? 3B D3 75 ?? 8B } - $encrypt_files_p1 = { - B8 ?? ?? ?? ?? 8D 4D ?? 8D 95 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 7D ?? 8B 75 - ?? 8D 4D ?? 89 FA 56 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? 8B 5D ?? 89 - 45 ?? 8B 45 ?? 83 F8 ?? 72 ?? 85 DB 74 ?? 0F B7 0B 81 F9 ?? ?? ?? ?? 75 ?? 8B 4B ?? - 89 C2 29 CA 72 ?? 83 FA ?? 72 ?? 85 DB 74 ?? 81 3C 0B ?? ?? ?? ?? 75 ?? 0F B7 54 0B - ?? 81 FA ?? ?? ?? ?? 75 ?? 0F B7 54 0B ?? 83 EA ?? 89 55 ?? BA ?? ?? ?? ?? 19 D2 89 - 55 ?? 72 ?? 83 F9 ?? 76 + $find_files_win32_p2 = { + 8D ?? ?? ?? ?? 0F B7 32 83 FE ?? 75 ?? 8D 43 ?? 3B D0 74 ?? 51 33 FF 57 57 53 E8 ?? + ?? ?? ?? 83 C4 ?? EB ?? 56 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 2B D3 0F B6 C0 D1 FA 42 + F7 D8 68 ?? ?? ?? ?? 1B C0 33 FF 23 C2 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 + ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B + 85 ?? ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 + ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B + 48 ?? 2B 08 C1 F9 ?? 6A ?? 89 8D ?? ?? ?? ?? 59 66 39 8D ?? ?? ?? ?? 75 ?? 66 39 BD + ?? ?? ?? ?? 74 ?? 66 39 8D ?? ?? ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 50 FF B5 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? + ?? 50 56 FF 15 ?? ?? ?? ?? 6A ?? 85 C0 8B 85 ?? ?? ?? ?? 59 75 ?? 8B 10 8B 40 ?? 8B + 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 + 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 } - $encrypt_files_p2 = { - 53 E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 5D ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 57 - 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 51 ?? 29 D0 8B 55 ?? 0F 92 - 45 ?? 83 7D ?? ?? 75 ?? 80 7D ?? ?? 75 ?? 39 C2 77 ?? B8 ?? ?? ?? ?? F7 64 0B ?? 8B - 55 ?? 70 ?? 39 C2 72 ?? 8B 44 0B ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 45 ?? 8B 85 ?? - ?? ?? ?? 89 45 ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? - 89 45 ?? 89 10 89 48 ?? 8B 45 ?? 89 45 ?? 53 E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? - 8B 45 ?? 8B 4D ?? 29 45 ?? 3B 4D ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? E8 ?? ?? ?? - ?? 8B 45 ?? 8B 4D ?? 89 45 ?? 89 4D ?? E9 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8B 35 ?? ?? - ?? ?? 8B 45 ?? F2 0F 10 45 ?? 85 F6 89 85 ?? ?? ?? ?? F2 0F 11 85 ?? ?? ?? ?? 0F 84 - ?? ?? ?? ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 8D 0C C0 8D 3C 49 01 C7 01 F7 EB + $encrypt_files_win32_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 4D ?? 83 7D ?? ?? 74 ?? 83 7D ?? ?? + 75 ?? 32 C0 E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 50 8B 4D ?? E8 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 73 ?? 32 C0 E9 ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? 33 C9 89 4D ?? 8D 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 32 + C0 E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8B 8D ?? ?? ?? ?? + 51 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 33 D2 89 55 ?? C7 45 ?? ?? ?? ?? ?? 33 C0 89 45 ?? 0F 57 C0 66 0F 13 85 ?? + ?? ?? ?? EB ?? 8B 8D ?? ?? ?? ?? 81 C1 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 D2 ?? 89 8D + ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B 45 ?? 0F 8F ?? ?? ?? ?? 7C ?? 8B + 8D ?? ?? ?? ?? 3B 4D ?? 0F 83 ?? ?? ?? ?? 0F 57 C0 66 0F 13 45 ?? 6A ?? 8D 55 ?? 52 + } + $encrypt_files_win32_p2 = { + 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? C6 45 ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8A 45 ?? E9 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 + 68 ?? ?? ?? ?? 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 C0 + 75 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8A 45 ?? E9 ?? ?? + ?? ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 + 75 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8A 45 ?? E9 ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 05 ?? ?? ?? ?? 89 45 ?? 8B 4D ?? 3B 4D ?? + 0F 83 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 03 45 ?? 50 6A ?? 8D 4D ?? + E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8D 45 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 6A ?? 8B 4D ?? 51 8B 4D ?? E8 ?? ?? ?? ?? 0F B6 D0 + 85 D2 75 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8A 45 ?? E9 + ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 8D ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 50 8B 55 + ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? 8A 45 ?? E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? EB ?? E9 ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 4D + ?? 8B 95 ?? ?? ?? ?? 89 55 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 89 85 + } + $encrypt_files_win32_p3 = { + 8B 8D ?? ?? ?? ?? 89 4D ?? 8B 95 ?? ?? ?? ?? 89 55 ?? 6A ?? 8D 45 ?? 50 8B 4D ?? 51 + 8B 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 + 8B 4D ?? 83 C1 ?? E8 ?? ?? ?? ?? 50 8B 4D ?? 83 C1 ?? E8 ?? ?? ?? ?? 50 8B 55 ?? 52 + FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 4D ?? 83 C1 ?? E8 ?? ?? ?? ?? 39 45 ?? 75 ?? 0F 57 + C0 66 0F 13 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 4D + ?? 89 4D ?? 8B 55 ?? 89 55 ?? 6A ?? 8D 45 ?? 50 6A ?? 8D 4D ?? 51 8B 55 ?? 52 FF 15 + ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 75 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? 8A 45 ?? EB ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? 8A 45 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B + E5 5D C2 } condition: - uint16(0)==0x5A4D and ($enum_procs) and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_win32_p*)) and ( all of ($encrypt_files_win32_p*)) and ( all of ($encrypt_network_shares_win32_p*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Apis : TC_DETECTION MALICIOUS MALWARE FILE +import "pe" + +rule REVERSINGLABS_Win32_Ransomware_Cryptolocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Apis ransomware." + description = "Yara rule that detects CryptoLocker ransomware." author = "ReversingLabs" - id = "63791250-e21e-53d1-932c-9b5d16a7cad9" - date = "2021-11-25" - modified = "2021-11-25" + id = "8cc3ac4b-9179-5e2c-97e1-65304f9dfe22" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Apis.yara#L1-L75" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0915469884a268f124da348d6a182eb4a0f69063d4041b46628794ab011227ef" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.CryptoLocker.yara#L3-L154" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "08430b0c5689840d592bdda5dbc2ed06e0d0fa1e2c0f19aff4316580c6a0b23d" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -26044,68 +27436,139 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Apis : TC_DETECTION MALICIOUS MALWAR sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Apis" + tc_detection_name = "CryptoLocker" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 0A 06 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 2C ?? 06 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E - 69 32 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 7E ?? ?? ?? ?? - 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 0D 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 - ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 7E - ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? - 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 07 28 ?? ?? - ?? ?? 08 28 ?? ?? ?? ?? 09 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 - ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? - 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 2A + $file_loop_1 = { + 55 8B EC 83 EC ?? 53 56 8B D9 57 89 5D ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 32 C9 83 7D ?? ?? 88 4D ?? 0F 86 45 01 + 00 00 8B 5D ?? 0F 57 C0 66 0F 13 45 ?? 84 C9 74 08 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? FF 75 ?? FF 33 FF 15 ?? + ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 FF 33 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B 75 ?? + 6A ?? 8B 49 ?? 6A ?? 52 56 8B 01 6A ?? 89 55 ?? 8B 00 FF D0 84 C0 0F 84 E6 00 00 00 FF 15 ?? ?? ?? ?? 8B 7D ?? 33 D2 89 + 45 ?? 8B D8 85 FF 72 18 77 08 81 FE ?? ?? ?? ?? 76 0E B8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB 05 8B C6 89 7D ?? 3B D0 73 + 0F 8B 45 ?? 8D 0C 13 8B 40 ?? 88 0C 02 42 EB CC 8B 5D ?? 85 FF 8B FE 75 04 85 F6 74 6B 85 DB 77 0E 72 08 81 FF ?? ?? ?? + ?? 73 04 8B F7 EB 05 BE ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 45 ?? 56 FF 70 ?? 8B 45 ?? FF 30 FF 15 ?? ?? ?? ?? 85 C0 74 ?? + 39 75 ?? 75 ?? 8B 45 ?? 2B FE 8B 55 ?? 83 DB ?? 2B D7 8B 48 ?? 8B 45 ?? 1B C3 50 8B 31 52 FF 75 ?? FF 75 ?? 8B 06 6A ?? + FF D0 84 C0 74 34 85 DB 77 AD 72 04 85 FF 75 95 8B 5D ?? FF 33 FF 15 ?? ?? ?? ?? 8A 4D ?? FE C1 0F B6 C1 88 4D ?? 3B 45 + ?? 0F 82 C6 FE FF FF B0 ?? 5F 5E 5B 8B E5 5D C2 } - $encrypt_files = { - 02 28 ?? ?? ?? ?? 0A 17 0B 16 0C 38 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 06 08 9A 28 - ?? ?? ?? ?? 7D ?? ?? ?? ?? 06 08 9A 28 ?? ?? ?? ?? 0D 7E ?? ?? ?? ?? 11 ?? FE 06 ?? ?? - ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 09 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 - ?? ?? ?? ?? 06 08 9A 73 ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 11 ?? 6F - ?? ?? ?? ?? 20 ?? ?? ?? ?? 6A 2F ?? 28 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? - 18 5B 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 06 08 9A 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 06 08 9A 06 08 9A 72 ?? ?? ?? ?? 1A 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2B ?? - 28 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 1A 5B 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 13 ?? 06 08 9A 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 06 08 9A 06 08 9A 72 ?? ?? ?? ?? 1A - 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 07 2C ?? 16 0B 02 72 ?? ?? ?? ?? 7E ?? ?? - ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 08 17 58 0C 08 06 8E - 69 3F ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 28 ?? ?? ?? ?? - 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? DE ?? 26 DE ?? 2A + $file_loop_2 = { + 55 8B EC 83 EC ?? 53 56 8B D9 57 89 5D ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 32 C9 83 7D ?? ?? 88 4D ?? 0F 86 50 01 + 00 00 8B 5D ?? 0F 57 C0 66 0F 13 45 ?? 84 C9 74 08 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? FF 75 ?? FF 33 FF 15 ?? + ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 FF 33 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B 49 ?? + 8B 75 ?? 8B 01 6A ?? 8B 00 6A ?? 52 56 6A ?? 89 55 ?? FF D0 84 C0 0F 84 F1 00 00 00 FF 15 ?? ?? ?? ?? 8B 7D ?? 89 45 ?? + 33 D2 8B D8 85 FF 72 18 77 08 81 FE ?? ?? ?? ?? 76 0E B8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB 05 8B C6 89 7D ?? 3B D0 73 + 10 8B 45 ?? 8D 0C 13 8B 40 ?? 42 88 4C 02 ?? EB CB 8B 5D ?? 85 FF 8B FE 75 04 85 F6 74 75 85 DB 77 11 72 08 81 FF ?? ?? + ?? ?? 73 07 8B F7 89 5D ?? EB 0C BE ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 45 ?? 56 FF 70 ?? 8B 45 ?? FF + 30 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 39 75 ?? 75 ?? 8B 45 ?? 8B 55 ?? 8B 48 ?? 8B 45 ?? 2B FE 8B 31 83 DB ?? 2B D7 1B C3 50 + 8B 06 52 FF 75 ?? FF 75 ?? 6A ?? FF D0 84 C0 74 34 85 DB 77 A6 72 04 85 FF 75 8B 8B 5D ?? FF 33 FF 15 ?? ?? ?? ?? 8A 4D + ?? FE C1 0F B6 C1 88 4D ?? 3B 45 ?? 0F 82 BB FE FF FF B0 ?? 5F 5E 5B 8B E5 5D C2 } - $setup_env = { - 28 ?? ?? ?? ?? 2C ?? 17 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? - ?? 2C ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? - ?? 2C ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 2B ?? 7E ?? ?? ?? ?? 2C ?? - 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? - 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2D ?? 14 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? - 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 7E ?? - ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2A + $file_loop_3 = { + 55 8B EC 83 EC ?? 53 56 8B C1 57 89 45 ?? E8 ?? ?? ?? ?? 84 C0 0F 84 62 01 00 00 8B 5D ?? 32 C0 0F 57 C0 88 45 ?? 66 0F + 13 45 ?? EB 03 8D 49 ?? 84 C0 74 08 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? FF 75 ?? FF 33 FF 15 ?? ?? ?? ?? 85 C0 + 0F 84 27 01 00 00 8D 45 ?? 50 FF 33 FF 15 ?? ?? ?? ?? 85 C0 0F 84 13 01 00 00 8B 4D ?? 8B 55 ?? 8B 49 ?? 8B 75 ?? 8B 01 + 6A ?? 8B 00 6A ?? 52 56 6A ?? 89 55 ?? FF D0 84 C0 0F 84 EE 00 00 00 FF 15 ?? ?? ?? ?? 8B 7D ?? 89 45 ?? 33 D2 8B D8 90 + 85 FF 72 18 77 08 81 FE ?? ?? ?? ?? 76 0E B8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB 05 8B C6 89 7D ?? 3B D0 73 10 8B 45 ?? + 8D 0C 13 8B 40 ?? 42 88 4C 02 ?? EB CB 8B 5D ?? 85 FF 8B FE 75 04 85 F6 74 75 85 DB 77 11 72 08 81 FF ?? ?? ?? ?? 73 07 + 8B F7 89 5D ?? EB 0C BE ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 45 ?? 56 FF 70 ?? 8B 45 ?? FF 30 FF 15 ?? + ?? ?? ?? 85 C0 74 5E 39 75 ?? 75 59 8B 45 ?? 8B 55 ?? 8B 48 ?? 8B 45 ?? 2B FE 8B 31 83 DB ?? 2B D7 1B C3 50 8B 06 52 FF + 75 ?? FF 75 ?? 6A ?? FF D0 84 C0 74 30 85 DB 77 A6 72 04 85 FF 75 8B 8B 5D ?? FF 33 FF 15 ?? ?? ?? ?? 8A 45 ?? FE C0 88 + 45 ?? 3C ?? 0F 82 BE FE FF FF B0 ?? 5F 5E 5B 8B E5 5D C2 + } + $encrypt_data_1 = { + 55 8B EC 56 8B 75 ?? 57 8B F9 39 75 ?? 73 09 5F 83 C8 ?? 5E 5D C2 ?? ?? 8B 07 53 85 C0 74 58 48 83 F8 ?? 77 48 8B 5D ?? + 8B 45 ?? 3B D8 74 0B 56 50 53 E8 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? 8D 45 ?? 89 75 ?? 50 8B 45 ?? 53 6A ?? 0F B6 C0 50 6A ?? + FF 77 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 83 CA ?? 85 C0 5B 0F 44 CA 5F 8B C1 5E 5D C2 ?? ?? 5B 5F 83 C8 ?? 5E 5D C2 ?? ?? 8B + 47 ?? 33 D2 89 45 ?? 8B 47 ?? 85 F6 74 26 8B 7D ?? 8B DE 8B 4D ?? 8B F0 2B F9 8A 04 0F 8D 49 ?? 32 04 32 88 41 ?? 8D 42 + ?? 33 D2 F7 75 ?? 4B 75 E9 8B 75 ?? 5B 5F 8B C6 5E 5D C2 + } + $encrypt_data_2 = { + 55 8B EC 56 8B 75 ?? 57 8B F9 39 75 ?? 73 09 5F 83 C8 ?? 5E 5D C2 ?? ?? 8B 07 53 85 C0 74 56 48 83 F8 ?? 77 46 8B 5D ?? + 8B 45 ?? 3B D8 74 0B 56 50 53 E8 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? 8D 45 ?? 50 0F B6 45 ?? 53 6A ?? 50 6A ?? FF 77 ?? 89 75 + ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 83 CA ?? 85 C0 5B 0F 44 CA 5F 8B C1 5E 5D C2 ?? ?? 5B 5F 83 C8 ?? 5E 5D C2 ?? ?? 8B 47 ?? + 33 D2 89 45 ?? 8B 47 ?? 85 F6 74 26 8B 4D ?? 8B 7D ?? 8B DE 2B F9 8B F0 8A 04 0F 32 04 32 8D 49 ?? 88 41 ?? 8D 42 ?? 33 + D2 F7 75 ?? 4B 75 E9 8B 75 ?? 5B 5F 8B C6 5E 5D C2 + } + $encrypt_data_3 = { + 55 8B EC 53 56 8B 75 ?? 8B D9 39 75 ?? 72 4C 83 3B ?? 77 47 8B 45 ?? 57 8B 7D ?? 3B F8 74 0B 56 50 57 E8 ?? ?? ?? ?? 83 + C4 ?? FF 75 ?? 8D 45 ?? 50 0F B6 45 ?? 57 6A ?? 50 6A ?? FF 73 ?? 89 75 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 83 CA ?? 85 C0 5F + 0F 44 CA 5E 8B C1 5B 5D C2 ?? ?? 5E 83 C8 ?? 5B 5D C2 + } + $decrypt_data_1 = { + 55 8B EC 53 56 57 8B F9 8B 07 85 C0 74 53 48 83 F8 ?? 77 55 8B 75 ?? 39 75 ?? 72 4D 8B 5D ?? 8B 45 ?? 3B D8 74 0B 56 50 + 53 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 89 75 ?? 50 8B 45 ?? 53 6A ?? 0F B6 C0 50 6A ?? FF 77 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? + 83 CA ?? 85 C0 5F 0F 44 CA 5E 8B C1 5B 5D C2 ?? ?? 8B 75 ?? 39 75 ?? 73 0A 5F 5E 83 C8 ?? 5B 5D C2 ?? ?? 8B 47 ?? 33 D2 + 89 45 ?? 8B 47 ?? 85 F6 74 28 8B 7D ?? 8B DE 8B 4D ?? 8B F0 2B F9 8B FF 8A 04 0F 8D 49 ?? 32 04 32 88 41 ?? 8D 42 ?? 33 + D2 F7 75 ?? 4B 75 E9 8B 75 ?? 5F 8B C6 5E 5B 5D C2 + } + $decrypt_data_2 = { + 55 8B EC 53 56 57 8B F9 8B 07 85 C0 74 51 48 83 F8 ?? 77 53 8B 75 ?? 39 75 ?? 72 4B 8B 5D ?? 8B 45 ?? 3B D8 74 0B 56 50 + 53 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 0F B6 45 ?? 53 6A ?? 50 6A ?? FF 77 ?? 89 75 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 83 CA + ?? 85 C0 5F 0F 44 CA 5E 8B C1 5B 5D C2 ?? ?? 8B 75 ?? 39 75 ?? 73 0A 5F 5E 83 C8 ?? 5B 5D C2 ?? ?? 8B 47 ?? 33 D2 89 45 + ?? 8B 47 ?? 85 F6 74 2A 8B 4D ?? 8B 7D ?? 8B DE 2B F9 8B F0 8D 64 24 ?? 8A 04 0F 32 04 32 8D 49 ?? 88 41 ?? 8D 42 ?? 33 + D2 F7 75 ?? 4B 75 E9 8B 75 ?? 5F 8B C6 5E 5B 5D C2 + } + $decrypt_data_3 = { + 55 8B EC 53 8B D9 83 3B ?? 77 56 56 8B 75 ?? 39 75 ?? 73 09 5E 83 C8 ?? 5B 5D C2 ?? ?? 8B 45 ?? 57 8B 7D ?? 3B F8 74 0B + 56 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 0F B6 45 ?? 57 6A ?? 50 6A ?? FF 73 ?? 89 75 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? + 83 CA ?? 85 C0 5F 0F 44 CA 5E 8B C1 5B 5D C2 ?? ?? 83 C8 ?? 5B 5D C2 + } + $decrypt_strings_1 = { + 55 8B EC 53 56 8B D9 8B F2 57 33 C9 33 FF 2B DE 8B 45 ?? 8D 14 31 8A 04 07 02 C1 32 04 13 88 02 8D 47 ?? 33 D2 F7 75 ?? + 8B FA F6 C1 ?? 75 0B 8B C1 D1 E8 66 83 3C 46 ?? 74 03 41 EB D3 D1 E9 5F 5E 5B 8D 41 ?? 5D C3 + } + $decrypt_strings_2 = { + 55 8B EC 53 56 8B D9 57 8B F2 33 C9 33 FF 2B DE 8B 45 ?? 8D 14 31 8A 04 07 02 C1 32 04 13 88 02 8D 47 ?? 33 D2 F7 75 ?? + 8B FA F6 C1 ?? 75 0B 8B C1 D1 E8 66 83 3C 46 ?? 74 03 41 EB D3 5F D1 E9 5E 8D 41 ?? 5B 5D C3 + } + $decrypt_1 = { + A1 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 8C B7 00 00 00 33 D2 8B 0C 95 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? ?? 81 E1 ?? ?? ?? ?? 33 0C + 95 ?? ?? ?? ?? 8B C1 D1 E9 83 E0 ?? 33 0C 85 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? ?? 89 0C 95 ?? ?? ?? ?? 42 81 FA ?? ?? ?? ?? + 7C C0 81 FA ?? ?? ?? ?? 7D 39 56 8D 34 95 ?? ?? ?? ?? 8B 0E 33 4E ?? 81 E1 ?? ?? ?? ?? 33 0E 8B C1 D1 E9 83 E0 ?? 8B 04 + 85 ?? ?? ?? ?? 33 86 ?? ?? ?? ?? 33 C1 89 06 83 C6 ?? 81 FE ?? ?? ?? ?? 7C D0 5E 8B 0D ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 81 + E1 ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 8B C1 D1 E9 83 E0 ?? 33 0C 85 ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 33 C0 89 0D ?? ?? ?? ?? 8B + 0C 85 ?? ?? ?? ?? 40 A3 ?? ?? ?? ?? 8B C1 C1 E8 ?? 33 C8 8B C1 25 ?? ?? ?? ?? C1 E0 ?? 33 C8 8B C1 25 ?? ?? ?? ?? C1 E0 + ?? 33 C8 8B C1 C1 E8 ?? 33 C1 C3 + } + $decrypt_2 = { + A1 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 8C C7 00 00 00 33 D2 EB 0C 8D A4 24 ?? ?? ?? ?? EB 03 8D 49 ?? 8B 0C 95 ?? ?? ?? ?? 33 + 0C 95 ?? ?? ?? ?? 42 81 E1 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? ?? 8B C1 83 E0 ?? D1 E9 33 0C 85 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? + ?? 89 0C 95 ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 7C C0 81 FA ?? ?? ?? ?? 7D 3B 56 8D 34 95 ?? ?? ?? ?? 8B 0E 33 4E ?? 83 C6 ?? + 81 E1 ?? ?? ?? ?? 33 4E ?? 8B C1 83 E0 ?? D1 E9 8B 04 85 ?? ?? ?? ?? 33 86 ?? ?? ?? ?? 33 C1 89 46 ?? 81 FE ?? ?? ?? ?? + 7C CE 5E 8B 0D ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 81 E1 ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 8B C1 83 E0 ?? D1 E9 33 0C 85 ?? ?? ?? + ?? 33 0D ?? ?? ?? ?? 33 C0 89 0D ?? ?? ?? ?? 8B 0C 85 ?? ?? ?? ?? 40 A3 ?? ?? ?? ?? 8B C1 C1 E8 ?? 33 C8 8B C1 25 ?? ?? + ?? ?? C1 E0 ?? 33 C8 8B C1 25 ?? ?? ?? ?? C1 E0 ?? 33 C8 8B C1 C1 E8 ?? 33 C1 C3 + } + $decrypt_3 = { + A1 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 8C C7 00 00 00 33 D2 EB 0C 8D A4 24 ?? ?? ?? ?? EB 03 8D 49 ?? 8B 0C 95 ?? ?? ?? ?? 33 + 0C 95 ?? ?? ?? ?? 42 81 E1 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? ?? 8B C1 83 E0 ?? D1 E9 33 0C 85 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? + ?? 89 0C 95 ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 7C C0 81 FA ?? ?? ?? ?? 7D 3B 56 8D 34 95 ?? ?? ?? ?? 8B 0E 33 4E ?? 83 C6 ?? + 81 E1 ?? ?? ?? ?? 33 4E ?? 8B C1 83 E0 ?? D1 E9 8B 04 85 ?? ?? ?? ?? 33 86 ?? ?? ?? ?? 33 C1 89 46 ?? 81 FE ?? ?? ?? ?? + 7C CE 5E 8B 0D ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 81 E1 ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 8B C1 83 E0 ?? D1 E9 33 0C 85 ?? ?? ?? + ?? 33 0D ?? ?? ?? ?? 33 C0 89 0D ?? ?? ?? ?? 8B 0C 85 ?? ?? ?? ?? 40 A3 ?? ?? ?? ?? 8B C1 C1 E8 ?? 33 C8 8B C1 25 ?? ?? + ?? ?? C1 E0 ?? 33 C8 8B C1 25 ?? ?? ?? ?? C1 E0 ?? 33 C8 8B C1 C1 E8 ?? 33 C1 C3 + } + $entrypoint_all = { + 83 EC ?? E8 ?? ?? ?? ?? 50 FF 15 } condition: - uint16(0)==0x5A4D and ($setup_env) and ($find_files) and ($encrypt_files) + uint16(0)==0x5A4D and ((($file_loop_1 and $encrypt_data_1 and $decrypt_data_1 and $decrypt_strings_1 and $decrypt_1) or ($file_loop_2 and $encrypt_data_2 and $decrypt_data_2 and $decrypt_strings_2 and $decrypt_2) or ($file_loop_3 and $encrypt_data_3 and $decrypt_data_3 and $decrypt_3)) and ($entrypoint_all at pe.entry_point)) } -rule REVERSINGLABS_Win32_Ransomware_5Ss5C : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Sifreli : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects 5ss5c ransomware." + description = "Yara rule that detects Sifreli ransomware." author = "ReversingLabs" - id = "c69f44de-8e48-518d-87bf-d21d11223a2f" - date = "2020-07-15" - modified = "2020-07-15" + id = "974f81e2-6907-54da-97e3-3116c41b5ed4" + date = "2020-10-08" + modified = "2020-10-08" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.5ss5c.yara#L1-L267" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "74fcec568906a01dade7091c63cffbe4afa49c4705d9c1f21d10b4eee655a805" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Sifreli.yara#L1-L119" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "48f6cc678bea81afece0ae203fb27b61e2c6e4f7188a3bd260190f568c9a8a06" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -26113,249 +27576,108 @@ rule REVERSINGLABS_Win32_Ransomware_5Ss5C : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "5ss5c" + tc_detection_name = "Sifreli" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B FA 89 BD ?? ?? ?? ?? 8B F1 - 8B 5D ?? 33 C0 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 45 ?? 89 45 ?? 6A ?? 89 45 ?? - 89 45 ?? 89 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 4D ?? 83 C4 ?? C7 00 ?? ?? ?? ?? C7 40 - ?? ?? ?? ?? ?? 8B 45 ?? 89 08 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? - 57 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 4D - ?? C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8B 45 ?? 89 08 C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 6A ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 4D ?? C7 00 ?? ?? ?? ?? C7 40 ?? - ?? ?? ?? ?? 8B 45 ?? 89 08 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 - 45 ?? ?? 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 83 C4 ?? C7 - 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 08 C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 0F 57 C0 8B 43 ?? 66 0F D6 - } - $find_files_p2 = { - 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? C6 45 - ?? ?? 8B 3B 85 FF 74 ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? 8B 47 ?? 8D 8D ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 89 47 ?? 89 7D ?? E8 ?? ?? ?? ?? 6A - ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 3B - C8 74 ?? 83 78 ?? ?? 8D 48 ?? 72 ?? 8B 09 FF 70 ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 51 - 50 FF 15 ?? ?? ?? ?? 8B C8 89 8D ?? ?? ?? ?? 83 F9 ?? 0F 84 ?? ?? ?? ?? 8B D8 66 66 - 0F 1F 84 00 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? - 8B 8D ?? ?? ?? ?? 0F 43 45 ?? C7 45 ?? ?? ?? ?? ?? C6 00 ?? 8D 41 ?? 83 79 ?? ?? 72 - ?? 8B 00 FF 71 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? 8B D0 8D 79 ?? 8A 01 41 84 C0 75 ?? 2B CF 8D 85 ?? ?? ?? ?? 51 - 50 8B CA E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 F6 85 ?? - ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 33 FF FF B7 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 - C0 0F 85 ?? ?? ?? ?? 83 C7 ?? 81 FF ?? ?? ?? ?? 72 ?? 68 ?? ?? ?? ?? 50 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? - ?? ?? ?? 8B 9D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 83 CB ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 50 89 9D ?? ?? ?? ?? 89 5D ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 - } - $find_files_p3 = { - 45 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 6A ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 51 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 85 C0 75 - ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 8B 40 ?? 03 C8 33 C0 39 41 ?? 0F 94 C0 - 8D 04 85 ?? ?? ?? ?? 0B 41 ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 55 ?? 83 7D ?? ?? 8D - 8D ?? ?? ?? ?? FF 75 ?? 0F 43 55 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 8B - 40 ?? 03 C8 33 C0 39 41 ?? 0F 94 C0 8D 04 85 ?? ?? ?? ?? 0B 41 ?? 50 E8 ?? ?? ?? ?? - 8B 5D ?? 8D 55 ?? 53 FF B5 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 8B 85 ?? - ?? ?? ?? 8B 40 ?? 85 FF 0F 85 ?? ?? ?? ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? - 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 51 - ?? 0F 1F 80 ?? ?? ?? ?? 8A 01 41 84 C0 75 ?? 2B CA 8D 85 ?? ?? ?? ?? 51 50 8D 4D - } - $find_files_p4 = { - E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 8D 85 ?? ?? ?? - ?? 51 50 8D 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 83 7D ?? ?? 8B FC 0F 43 45 ?? C7 - 07 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D ?? 85 DB 74 ?? 6A ?? - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? 8D 8D ?? ?? ?? ?? 89 - 47 ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 83 EC ?? 83 7D ?? ?? 8B FC 0F - 43 4D ?? 03 C1 C7 07 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D ?? - 85 DB 74 ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? 8D - 8D ?? ?? ?? ?? 89 47 ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 83 7D ?? ?? - 8B FC 0F 43 45 ?? C7 07 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D - ?? 85 DB 74 ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? - 8D 8D ?? ?? ?? ?? 89 47 ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? BA ?? ?? ?? ?? C6 45 - } - $find_files_p5 = { - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? - ?? 8D 55 ?? 83 7D ?? ?? 8B 4D ?? 0F 43 55 ?? C7 45 ?? ?? ?? ?? ?? 89 4D ?? 83 F9 ?? - 72 ?? 49 83 C8 ?? 3B C8 89 4D ?? 0F 42 C1 03 C2 0F 1F 40 ?? 80 38 ?? 75 ?? 0F B6 08 - 80 F9 ?? 75 ?? 33 C9 EB ?? 1B C9 83 C9 ?? 85 C9 74 ?? 3B C2 74 ?? 48 EB ?? 2B C2 EB - ?? 83 C8 ?? 6A ?? 8D 78 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - 83 C4 ?? C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 08 C6 45 ?? ?? - 8B 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? - ?? ?? 3B C7 0F 82 ?? ?? ?? ?? 2B C7 C7 45 ?? ?? ?? ?? ?? 83 C9 ?? 89 45 ?? 83 F8 ?? - 0F 42 C8 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 51 03 C7 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 83 8D ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? FF B5 ?? ?? ?? ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - } - $find_files_p6 = { - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 83 7D ?? ?? 8B FC 0F 43 45 ?? C7 07 - ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D ?? 85 DB 74 ?? 6A ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? 8D 8D ?? ?? ?? ?? 89 47 - ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 83 EC ?? 83 7D ?? ?? 8B FC 0F 43 - 4D ?? 03 C1 C7 07 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D ?? 85 - DB 74 ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? 8D 8D - ?? ?? ?? ?? 89 47 ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 83 7D ?? ?? 8B - FC 0F 43 45 ?? C7 07 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D ?? - 85 DB 74 ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? 8D - 8D ?? ?? ?? ?? 89 47 ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? BA ?? ?? ?? ?? C6 45 ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? - 33 FF 66 66 0F 1F 84 00 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? FF B7 ?? ?? ?? ?? 0F 43 45 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? - ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 83 C7 ?? 83 FF - ?? 72 ?? 8B 5D ?? 85 DB 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 46 ?? 8D 4D ?? 51 39 46 ?? 74 ?? 8B C8 E8 ?? ?? ?? - ?? 8B 7E ?? 8D 8D ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B 0E 8D 41 ?? F7 D9 1B C9 23 C8 - } - $find_files_p7 = { - 74 ?? 8B 01 85 C0 74 ?? 39 78 ?? 72 ?? 77 ?? C7 00 ?? ?? ?? ?? 8B 01 8B 40 ?? 89 01 - EB ?? 8D 48 ?? 8B 01 85 C0 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 46 ?? ?? EB ?? - 50 8B CE E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 85 C0 75 ?? 8B 46 ?? 8D 4D ?? 51 39 46 ?? 74 ?? 8B C8 E8 ?? ?? ?? ?? 8B 7E ?? 8D 8D - ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B 0E 8D 41 ?? F7 D9 1B C9 23 C8 74 ?? 8B 01 85 C0 - 74 ?? 66 0F 1F 44 00 ?? 39 78 ?? 72 ?? 77 ?? C7 00 ?? ?? ?? ?? 8B 01 8B 40 ?? 89 01 - EB ?? 8D 48 ?? 8B 01 85 C0 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 46 ?? ?? EB ?? - 50 8B CE E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 8D ?? ?? ?? ?? ?? 8B D8 8B 7D ?? 85 FF 74 ?? 8B 3F 8B CB E8 ?? ?? ?? ?? 3B - } - $find_files_p8 = { - C7 74 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 - ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? CC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 43 ?? 3B 45 ?? 74 ?? 8D 85 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B3 ?? EB ?? 32 DB 8B 85 ?? - ?? ?? ?? A8 ?? 74 ?? 83 E0 ?? 89 85 ?? ?? ?? ?? 6A ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 84 DB 0F - 84 ?? ?? ?? ?? 8B 46 ?? 8D 4D ?? 51 39 46 ?? 0F 84 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? - 8B 7E ?? 8D 8D ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B 0E 8D 41 ?? F7 D9 1B C9 23 C8 74 - ?? 8B 01 85 C0 74 ?? 90 39 78 ?? 72 ?? 77 ?? C7 00 ?? ?? ?? ?? 8B 01 8B 40 ?? 89 01 - EB ?? 8D 48 ?? 8B 01 85 C0 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 46 ?? ?? E9 ?? - ?? ?? ?? 83 FB ?? 0F 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 83 8D ?? ?? ?? ?? ?? 8B D8 8B 7D ?? 85 FF 74 ?? 8B 3F 8B CB E8 ?? - ?? ?? ?? 3B C7 74 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? CC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 43 ?? 3B 45 ?? 75 ?? 8D + $find_files = { + 55 8B EC 83 EC ?? 53 56 57 8B 7D ?? 8B C7 8D 50 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? + 2B C2 D1 F8 8D 44 00 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? + 6A ?? 50 FF D6 8B D8 89 5D ?? 85 DB 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? + ?? ?? ?? 8B 0D ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 51 FF D6 8B F8 85 FF 0F 84 ?? ?? ?? + ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? ?? ?? 3D ?? ?? + ?? ?? 1B C0 40 A3 ?? ?? ?? ?? EB ?? A1 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 57 50 53 FF 15 + ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 90 F6 07 ?? 74 + ?? BB ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 47 ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 + 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 33 DB EB ?? + 1B C0 83 D8 ?? 85 C0 74 ?? B9 ?? ?? ?? ?? 8D 47 ?? 8D 49 ?? 66 8B 10 66 3B 11 75 ?? + 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 + EB ?? 1B C0 83 D8 ?? 85 C0 74 ?? 8B 55 ?? 8B 4D ?? 52 8D 47 ?? 50 8B 07 50 53 68 ?? + ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 55 ?? 57 52 FF 15 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 5D ?? EB ?? C7 45 ?? ?? ?? ?? + ?? 8B 0D ?? ?? ?? ?? 57 6A ?? 51 FF 15 ?? ?? ?? ?? EB ?? C7 45 ?? ?? ?? ?? ?? 8B 15 + ?? ?? ?? ?? 53 6A ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 5F 5E 5B 8B E5 5D C3 5F 5E B8 ?? + ?? ?? ?? 5B 8B E5 5D C3 } - $find_files_p9 = { - 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B3 ?? EB ?? 32 - DB 8B 85 ?? ?? ?? ?? A8 ?? 74 ?? 83 E0 ?? 89 85 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? - C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? C6 45 ?? ?? 84 DB 0F 84 ?? ?? ?? ?? 8B 46 ?? 8D 4D ?? 51 39 46 ?? 0F 84 ?? - ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 8B 7E ?? 8D 4D ?? 6A ?? E8 ?? ?? ?? ?? 8B 0E 8D 41 ?? - F7 D9 1B C9 23 C8 74 ?? 8B 01 85 C0 74 ?? 39 78 ?? 72 ?? 77 ?? C7 00 ?? ?? ?? ?? 8B - 01 8B 40 ?? 89 01 EB ?? 8D 48 ?? 8B 01 85 C0 75 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 46 ?? - ?? E9 ?? ?? ?? ?? 83 FB ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 46 ?? 8D 4D ?? 51 39 46 ?? 74 ?? 8B C8 E8 ?? ?? - ?? ?? 8B 7E ?? 8D 4D ?? 6A ?? E8 ?? ?? ?? ?? 8B 0E 8D 41 ?? F7 D9 1B C9 23 C8 74 ?? - 8B 01 85 C0 74 ?? 66 0F 1F 44 00 ?? 39 78 ?? 72 ?? 77 ?? C7 00 ?? ?? ?? ?? 8B 01 8B + $remote_connection_p1 = { + 55 8B EC 83 EC ?? 53 33 DB 8D 45 ?? 89 5D ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 8B 45 ?? 8B 4D ?? 56 57 50 51 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 8B 55 ?? 8B + 4D ?? 52 57 E8 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? 8B 45 ?? 6A + ?? 50 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B D6 E8 ?? ?? ?? ?? 85 C0 74 ?? + C7 45 ?? ?? ?? ?? ?? 56 FF D3 8D 4D ?? 51 8D 55 ?? 52 6A ?? 57 C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 57 8B F0 FF D3 85 F6 74 ?? 8B 45 ?? 50 FF D3 + 8B 5D ?? 83 7D ?? ?? 8B 35 ?? ?? ?? ?? 74 ?? 8B 4D ?? 8B 15 ?? ?? ?? ?? 51 6A ?? 52 + FF D6 8B 45 ?? 85 C0 74 ?? 50 A1 ?? ?? ?? ?? 6A ?? 50 FF D6 5F 5E 8B C3 5B 8B E5 5D + C3 8B C3 5B 8B E5 5D C3 } - $find_files_p10 = { - 40 ?? 89 01 EB ?? 8D 48 ?? 8B 01 85 C0 75 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 46 ?? ?? EB - ?? 50 8B CE E8 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? - ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? - 75 ?? 33 FF 6A ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F - 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B - 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? E8 + $remote_connection_p2 = { + 55 8B EC 83 EC ?? 56 57 68 ?? ?? ?? ?? 33 FF 57 57 57 57 FF 15 ?? ?? ?? ?? 8B F0 85 + F6 74 ?? 8B 3D ?? ?? ?? ?? B8 ?? ?? ?? ?? 6A ?? 89 45 ?? 89 45 ?? 8D 45 ?? 50 6A ?? + 56 C7 45 ?? ?? ?? ?? ?? FF D7 6A ?? 8D 4D ?? 51 6A ?? 56 FF D7 6A ?? 8D 55 ?? 52 6A + ?? 56 FF D7 8B 45 ?? 8B 4D ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 50 51 56 FF 15 ?? ?? ?? + ?? 8B F8 85 FF 75 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 5F 5E 8B E5 5D C3 } - $encrypt_files_p1 = { - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 44 24 ?? 55 8B 6C 24 ?? 56 8B - 74 24 ?? 57 8B 7C 24 ?? 85 F6 0F 8E ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? - 83 C4 ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 57 E8 - ?? ?? ?? ?? 83 C4 ?? 89 44 24 ?? 85 C0 75 ?? A1 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? ?? - ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 83 C8 ?? 5F 5E 5D 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C3 8B 4C 24 ?? 8B C1 - 83 E8 ?? 74 ?? 51 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? - 83 C4 ?? 85 C0 75 ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A - ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 - ?? 83 C8 ?? 5F 5E 5D 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C3 68 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? A1 ?? ?? ?? ?? 85 C0 75 + $remote_connection_p3 = { + 55 8B EC 83 EC ?? 53 56 8B F0 33 C0 89 06 57 89 46 ?? 89 46 ?? 6A ?? 50 89 46 ?? 8D + 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 51 6A ?? BF ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 89 7D ?? 89 7D ?? 89 7D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 8B 4D ?? 8B 1D ?? ?? ?? ?? 8D 4C 09 ?? 33 C0 85 C9 74 ?? 8B 15 ?? ?? ?? ?? + 51 50 52 FF D3 89 06 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 51 52 50 E8 ?? ?? ?? + ?? 8B 06 8B 55 ?? 33 C9 66 89 0C 50 8B 4D ?? 83 C4 ?? 85 C9 74 ?? 8B 45 ?? 66 83 38 + ?? 75 ?? 83 45 ?? ?? 2B CF 89 4D ?? 85 C9 75 ?? 8B 55 ?? 8D 7C 0A ?? 8D 54 3F ?? 33 + C0 85 D2 74 ?? 52 50 A1 ?? ?? ?? ?? 50 FF D3 8B 4D ?? 89 46 ?? 85 C0 74 ?? 51 8B 4D + ?? 51 83 C0 ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8B 4E ?? 52 8B 55 ?? 50 8D 44 51 + ?? 50 E8 ?? ?? ?? ?? 8B 46 ?? B9 ?? ?? ?? ?? 66 89 08 33 D2 66 89 14 78 66 8B 45 ?? + 83 C4 ?? 83 7D ?? ?? 66 89 46 ?? 75 ?? 83 4E ?? ?? 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D + C3 8B 36 85 F6 74 ?? 8B 0D ?? ?? ?? ?? 56 6A ?? 51 FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B + 8B E5 5D C3 } - $encrypt_files_p2 = { - E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 83 C8 ?? 5F 5E 5D 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C3 33 C9 - 85 F6 7E ?? 8D 56 ?? 53 8B 5C 24 ?? 03 D7 66 0F 1F 44 00 ?? 8A 04 19 8D 52 ?? 41 88 - 42 ?? 3B CE 7C ?? 5B 8D 44 24 ?? 89 74 24 ?? 50 8B 44 24 ?? 57 6A ?? 6A ?? 6A ?? FF - 70 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? - ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 44 - 24 ?? 50 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? FF 74 24 ?? 57 E8 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 83 C8 ?? 5F 5E 5D 8B 4C 24 ?? 33 CC - E8 ?? ?? ?? ?? 83 C4 ?? C3 8B 74 24 ?? 56 57 55 E8 ?? ?? ?? ?? 56 57 E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4C 24 ?? 8B C6 5F 5E 5D - 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C3 + $encrypt_files_1 = { + 8B C3 8D 50 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 57 8B F8 8D 4C 3F ?? 33 + C0 85 C9 74 ?? 51 50 A1 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 8B F0 8B CB + 2B F3 8D 9B ?? ?? ?? ?? 0F B7 11 66 89 14 0E 83 C1 ?? 66 85 D2 75 ?? B9 ?? ?? ?? ?? + 8D 34 3F 2B F1 03 F0 EB ?? 8D 49 ?? 0F B7 11 66 89 14 0E 83 C1 ?? 66 85 D2 75 ?? 5E + 5F C3 } - $remote_connection_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 6A ?? E8 ?? - ?? ?? ?? FF 35 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? - E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8B D8 FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 83 - C4 ?? 49 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? 83 3D ?? ?? - ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 89 41 ?? 8B F2 A1 ?? ?? ?? ?? 89 - 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? 8A 02 42 84 C0 75 ?? 8D BD ?? - ?? ?? ?? 2B D6 4F 8A 47 ?? 47 84 C0 75 ?? 8B CA C1 E9 ?? F3 A5 8B CA 83 E1 ?? F3 A4 - 8D 8D ?? ?? ?? ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? - 8B F2 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? 66 90 8A 02 42 84 - C0 75 ?? 8D BD ?? ?? ?? ?? 2B D6 4F 8A 47 ?? 47 84 C0 75 ?? 8B CA C1 E9 ?? F3 A5 8B - CA 83 E1 ?? F3 A4 8D 8D ?? ?? ?? ?? 49 0F 1F 00 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? - ?? ?? ?? 8B F3 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? 8A 03 43 - 84 C0 75 ?? 8D BD ?? ?? ?? ?? 2B DE 4F 8A 47 ?? 47 84 C0 75 ?? 8B CB C1 E9 ?? F3 A5 - 8B CB 83 E1 ?? F3 A4 8D 8D ?? ?? ?? ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? - ?? 8B 95 ?? ?? ?? ?? 8B F2 89 01 A1 ?? ?? ?? ?? 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? 0F + $encrypt_files_2 = { + 83 E8 ?? 53 56 57 8B DA 74 ?? 48 74 ?? 5F 5E 33 C0 5B C3 53 51 33 F6 E8 ?? ?? ?? ?? + 83 C4 ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 8B F0 33 FF 85 F6 74 ?? 56 53 FF 15 ?? ?? ?? ?? + 85 C0 74 ?? BF ?? ?? ?? ?? A1 ?? ?? ?? ?? 56 6A ?? 50 FF 15 ?? ?? ?? ?? 8B F7 5F 8B + C6 5E 5B C3 53 51 33 F6 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 8B F0 33 + FF 85 F6 74 ?? 56 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? BF ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? + 56 6A ?? 51 FF 15 ?? ?? ?? ?? 8B F7 5F 8B C6 5E 5B C3 ?? ?? 55 8B EC 8B 4D ?? 8B 41 + ?? 83 F8 ?? 0F 8F ?? ?? ?? ?? F7 45 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 40 53 89 41 ?? + 8B 45 ?? 83 E8 ?? 56 57 74 ?? 48 0F 85 ?? ?? ?? ?? 8B 7D ?? 33 F6 8D 9B ?? ?? ?? ?? + 8B 86 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 C6 ?? 83 + FE ?? 72 ?? 8B 5D ?? E8 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 8B 4D ?? 51 56 E8 ?? ?? ?? ?? + 83 C4 ?? EB ?? 8B 41 ?? 83 E8 ?? 74 ?? 48 75 ?? 8B 75 ?? E8 ?? ?? ?? ?? EB ?? 8B 75 + ?? 8B C6 E8 ?? ?? ?? ?? F7 D8 1B C0 F7 D8 85 C0 74 ?? 8B 5D ?? 8B FE E8 ?? ?? ?? ?? + 8B F0 85 F6 74 ?? 8B 7D ?? 8B 47 ?? 8B 0F 8B D6 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 47 ?? + 85 C0 74 ?? 50 FF 15 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B 45 ?? FF 48 ?? 5F 5E 5B B8 + ?? ?? ?? ?? 5D C3 } - $remote_connection_p2 = { - 1F 44 00 ?? 8A 02 42 84 C0 75 ?? 8D BD ?? ?? ?? ?? 2B D6 4F 8A 47 ?? 47 84 C0 75 ?? - 8B CA C1 E9 ?? F3 A5 8B CA 83 E1 ?? F3 A4 8D 8D ?? ?? ?? ?? 49 0F 1F 00 8A 41 ?? 8D - 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 - ?? A0 ?? ?? ?? ?? 6A ?? 88 41 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? 83 C4 ?? C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 08 C7 45 - ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 51 ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 0F 1F 00 8A 01 41 84 C0 75 ?? 2B CA 8D 85 ?? - ?? ?? ?? 51 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B D8 85 - DB 74 ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B F0 85 F6 - 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 56 - FF 15 ?? ?? ?? ?? 56 FF D7 53 FF D7 FF B5 ?? ?? ?? ?? FF D7 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B - 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files_3 = { + 8B C6 8D 50 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 83 C0 ?? 85 C0 7E ?? EB + ?? 8D 49 ?? 66 83 3C 46 ?? 74 ?? 48 85 C0 7F ?? 33 C0 C3 8D 44 46 ?? 85 C0 74 ?? 83 + C0 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_*)) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Crypmic : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Satan : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Crypmic ransomware." + description = "Yara rule that detects Satan ransomware." author = "ReversingLabs" - id = "0d5c2141-c0ca-53c8-91fd-ec2d5f163df2" + id = "7ec379d8-172c-52ee-9284-6898dd446468" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Crypmic.yara#L1-L56" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ee97c4d35cee68e080a4e9e0a21ecd3698da638463881a58f5daaf906ef86f75" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Satan.yara#L1-L152" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0074090c2a6cc483deffdc83dc1c0bfbd150e201c27e54f998dd2c0a7660f917" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -26363,56 +27685,143 @@ rule REVERSINGLABS_Win32_Ransomware_Crypmic : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Crypmic" + tc_detection_name = "Satan" tc_detection_factor = 5 importance = 25 strings: - $search_and_encrypt_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 B8 ?? ?? ?? ?? 57 8B F9 89 7D ?? C7 45 ?? ?? ?? ?? - ?? 89 45 ?? 8D 50 ?? 68 ?? ?? ?? ?? 6A ?? FF 77 ?? 66 89 85 ?? ?? ?? ?? 8B 47 ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF D0 66 8B 95 ?? ?? ?? ?? 33 F6 33 - C9 89 45 ?? 66 3B F2 74 ?? 0F B7 D2 41 66 89 14 06 8D 34 09 33 DB 0F B7 94 35 ?? ?? - ?? ?? 66 3B DA 75 ?? BA ?? ?? ?? ?? 66 89 14 48 8D 1C 48 8D 8D ?? ?? ?? ?? 51 C7 43 - ?? ?? ?? ?? ?? 50 8B 47 ?? FF D0 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? - ?? 74 ?? 66 8B 8D ?? ?? ?? ?? 66 83 F9 ?? 74 ?? 66 83 BD ?? ?? ?? ?? ?? 74 ?? 33 D2 - 33 C0 66 3B D1 74 ?? 0F B7 C9 8B FF 40 66 89 4C 1A ?? 8D 14 00 C7 45 ?? ?? ?? ?? ?? - 0F B7 8C 15 ?? ?? ?? ?? 66 39 4D ?? 75 ?? 8B 55 ?? 33 C9 66 89 4C 43 ?? 68 ?? ?? ?? - ?? 8B CF E8 ?? ?? ?? ?? 83 C4 ?? 01 45 ?? 8D 85 ?? ?? ?? ?? 50 8B 47 ?? 56 FF D0 85 - C0 75 ?? 8B 47 ?? 56 FF D0 8D 85 ?? ?? ?? ?? 50 FF 75 ?? C7 43 ?? ?? ?? ?? ?? 8B 47 + $remote_connection = { + 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 + E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 + C4 ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? FF B5 ?? + ?? ?? ?? 89 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B F0 6A ?? + 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 FF D3 8B 3D ?? ?? ?? ?? 6A ?? 56 FF D7 8D 45 ?? 50 + 8D 45 ?? 50 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 50 89 85 ?? ?? ?? + ?? FF D3 8B 9D ?? ?? ?? ?? 6A ?? 53 FF D7 68 ?? ?? ?? ?? 33 FF E8 ?? ?? ?? ?? 83 C4 + ?? 8B F0 57 68 ?? ?? ?? ?? 6A ?? 57 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? 39 7D ?? 76 ?? 68 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 53 FF 15 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 6A ?? 51 50 + 56 FF B5 ?? ?? ?? ?? 03 F8 FF 15 ?? ?? ?? ?? 39 7D ?? 77 ?? 8B 85 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 83 C4 ?? 53 FF D6 FF B5 ?? + ?? ?? ?? FF D6 FF B5 ?? ?? ?? ?? FF D6 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 + 5D C3 } - $search_and_encrypt_2 = { - 33 F6 89 75 ?? FF D0 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? EB ?? 8D 9B ?? ?? ?? ?? - F6 85 ?? ?? ?? ?? ?? 75 ?? 66 8B BD ?? ?? ?? ?? 33 F6 8B 8E ?? ?? ?? ?? 8D 95 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 83 FF ?? 75 ?? - EB ?? 8D 9B ?? ?? ?? ?? 66 8B 48 ?? 83 C0 ?? 83 C2 ?? 66 3B 0A 74 ?? 66 83 38 ?? 0F - 85 ?? ?? ?? ?? 66 83 3A ?? 0F 85 ?? ?? ?? ?? 83 C6 ?? 81 FE ?? ?? ?? ?? 72 ?? 8B 7D - ?? 8B 75 ?? 8B 45 ?? 8D 8D ?? ?? ?? ?? 51 50 8B 47 ?? FF D0 85 C0 8B 45 ?? 0F 85 ?? - ?? ?? ?? 50 8B 47 ?? FF D0 85 F6 74 ?? 8B 55 ?? 33 C0 8B CF 66 89 43 ?? E8 ?? ?? ?? - ?? FF 75 ?? 8B 47 ?? 6A ?? FF 77 ?? FF D0 8B 45 ?? 8B 5D ?? 03 C6 03 D8 8B 45 ?? 40 - 89 5D ?? 89 45 ?? BA ?? ?? ?? ?? 83 F8 ?? 0F 8E ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 8B 47 ?? 68 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B CF E8 - ?? ?? ?? ?? 83 C4 ?? 03 C3 5F 5E 5B 8B E5 5D C3 33 C9 33 C0 66 3B CF 74 ?? 0F B7 CF - 33 D2 8D 9B ?? ?? ?? ?? 40 66 89 4C 1A ?? 8D 14 00 33 F6 0F B7 8C 15 ?? ?? ?? ?? 66 - 3B F1 75 ?? 8B 75 ?? FF 75 ?? 8B 7D ?? 33 C9 46 57 66 89 4C 43 ?? 89 75 ?? E8 ?? ?? - ?? ?? E9 + $search_processes = { + 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 51 50 + FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 0F 1F + 44 00 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 8B 4C B5 ?? + 8D 85 ?? ?? ?? ?? 0F 1F 44 00 ?? 8A 11 3A 10 75 ?? 84 D2 74 ?? 8A 51 ?? 3A 50 ?? 75 + ?? 83 C1 ?? 83 C0 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 75 ?? FF B5 ?? ?? + ?? ?? 50 68 ?? ?? ?? ?? FF D7 6A ?? 50 FF D3 46 83 FE ?? 76 ?? 8D 85 ?? ?? ?? ?? 50 + FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B + E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $encrypt_files = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? + ?? ?? 31 45 ?? 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 4D ?? 8B 4D + ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? 83 CB ?? 89 + 5D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 F6 89 75 ?? 89 75 ?? 56 68 ?? ?? + ?? ?? 6A ?? 56 6A ?? 6A ?? 51 8B 3D ?? ?? ?? ?? FF D7 89 45 ?? 3B C3 0F 84 ?? ?? ?? + ?? 56 68 ?? ?? ?? ?? 6A ?? 56 6A ?? 6A ?? FF 75 ?? FF D7 8B D8 89 5D ?? 83 FB ?? 0F + 84 ?? ?? ?? ?? 8B 7D ?? 8B 07 85 C0 0F 84 ?? ?? ?? ?? 8D 4D ?? 51 56 56 68 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 50 FF + 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? + FF 75 ?? 68 ?? ?? ?? ?? FF 37 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 32 C0 89 45 ?? 88 + 45 ?? 33 FF 89 7D ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 FF 75 + ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 0F B6 C0 81 7D ?? ?? ?? ?? ?? + B9 ?? ?? ?? ?? 0F 42 C1 89 45 ?? 88 45 ?? 68 ?? ?? ?? ?? 8D 4D ?? 51 56 6A ?? 0F B6 + C0 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 85 FF 75 ?? 57 8D 45 ?? 50 68 ?? + ?? ?? ?? FF 35 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 56 53 FF + 15 ?? ?? ?? ?? 85 C0 74 ?? 47 89 7D ?? 8B 45 ?? 84 C0 0F 84 ?? ?? ?? ?? 80 7D ?? ?? + 74 ?? 83 05 ?? ?? ?? ?? ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8A 45 ?? + 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 + } + $search_files_in_specific_folders_p1 = { + 51 8D 85 ?? ?? ?? ?? 8B CE 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 8B F0 F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 80 7D ?? ?? 0F 84 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? + ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 + C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? + 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F + 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 83 FF + } + $search_files_in_specific_folders_p2 = { + 75 ?? FF 75 ?? 8D 55 ?? 8B CB 57 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 + F6 0F 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 FF ?? 0F 85 ?? ?? ?? ?? FF 75 ?? 8D 55 ?? 8B + CB 57 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 0F 85 ?? ?? ?? ?? E9 ?? + ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 33 C9 EB ?? 8D 8D ?? ?? ?? ?? 8D 51 ?? 8A 01 41 + 84 C0 75 ?? 2B CA 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 83 EC ?? 8D + 4D ?? E8 ?? ?? ?? ?? 6A ?? 40 8D 4D ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 + 8D 45 ?? 3B C6 74 ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 + C4 ?? 56 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + EC ?? C6 45 ?? ?? 8D 4D ?? 54 E8 ?? ?? ?? ?? 83 EC ?? 8D 4D ?? 54 E8 ?? ?? ?? ?? 83 + EC ?? 8D 4D ?? 54 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 FF ?? 75 ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? 50 + 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 84 + C0 8D 8D ?? ?? ?? ?? 0F 94 C3 EB ?? 83 FF ?? 75 ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? 50 8D + 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 8A D8 + } + $search_files_in_specific_folders_p3 = { + 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 84 DB 8B 9D ?? ?? ?? ?? 74 ?? 8D 45 ?? + 8B CB 50 E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? + 83 F8 ?? 0F 84 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 + ?? 33 F6 8D 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF B5 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 85 ?? ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 45 ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? + E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? + C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? + ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF 75 ?? E8 ?? ?? + ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? C7 45 + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C6 8B 4D ?? 64 89 0D ?? ?? + ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and (( all of ($search_and_encrypt_*))) + uint16(0)==0x5A4D and ($search_processes and ( all of ($search_files_in_specific_folders_p*)) and $encrypt_files and $remote_connection) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Zerolocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Globeimposter : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects ZeroLocker ransomware." + description = "Yara rule that detects GlobeImposter ransomware." author = "ReversingLabs" - id = "291b5640-387c-54d9-97a6-13823932fa60" - date = "2021-08-12" - modified = "2021-08-12" + id = "6634a554-b4bb-503d-a4f1-9997b4caa1f0" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.ZeroLocker.yara#L1-L70" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "147e4b390bcfaff8f05059c1d9a98b50f544fc32e820406417894fe5046e0f71" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.GlobeImposter.yara#L1-L171" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "4345a767f270428f3b509fdad5a96bf9b494b190d3a836c4bf53dfd75da5bacb" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -26420,72 +27829,151 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Zerolocker : TC_DETECTION MALICIOUS sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "ZeroLocker" + tc_detection_name = "GlobeImposter" tc_detection_factor = 5 importance = 25 strings: - $encrypt_routine_1 = { - 00 28 5B 00 00 0A 20 ?? 07 00 00 28 60 00 00 06 13 09 20 ?? 07 00 00 28 60 00 00 06 13 - 0B 02 03 20 ?? 07 00 00 28 60 00 00 06 20 ?? 07 00 00 28 60 00 00 06 73 ?? 00 00 0A 7D - 1B 00 00 04 20 ?? 07 00 00 28 60 00 00 06 13 0B 02 04 20 ?? 07 00 00 28 60 00 00 06 20 - ?? 07 00 00 28 60 00 00 06 73 ?? 00 00 0A 7D 1C 00 00 04 20 ?? 07 00 00 28 60 00 00 06 - 13 0B 02 7B 1C 00 00 04 20 ?? 07 00 00 28 60 00 00 06 6A 6F ?? 00 00 0A 00 20 ?? 07 00 - 00 28 60 00 00 06 13 0B 20 ?? 07 00 00 28 60 00 00 06 8D 1E 00 00 01 0A 20 ?? 07 00 00 - 28 60 00 00 06 13 0B 20 ?? 07 00 00 28 60 00 00 06 6A 13 04 20 ?? 07 00 00 28 60 00 00 - 06 13 0B 02 7B 1B 00 00 04 6F ?? 00 00 0A [0-2] 13 05 20 ?? 07 00 00 28 60 00 00 06 13 - 0B 73 ?? 00 00 0A 0C 20 ?? 07 00 00 28 60 00 00 06 13 0B 00 0E 05 20 ?? 07 00 00 28 60 - 00 00 06 59 13 0C 11 0C 45 02 00 00 00 02 00 00 00 ?? 00 00 00 2B ?? 00 20 ?? 07 00 00 - 28 60 00 00 06 13 0B 02 7B 1C 00 00 04 08 05 0E 04 6F ?? 00 00 0A [0-2] 20 ?? 07 00 00 - 28 60 00 00 06 73 ?? 00 00 0A 0B 2B ?? 00 20 ?? 07 00 00 28 60 00 00 06 13 0B 02 7B 1C - 00 00 04 08 05 0E 04 6F ?? 00 00 0A [0-2] 20 ?? 07 00 00 28 60 00 00 06 73 ?? 00 00 0A - 0B 00 2B 62 20 ?? 07 00 00 28 60 00 00 06 13 0B 02 7B 1B 00 00 04 06 20 ?? 07 00 00 28 - 60 00 00 06 20 ?? 07 00 00 28 60 00 00 06 6F ?? 00 00 0A [0-2] 0D 20 ?? 07 00 00 28 60 + $encrypt_files_1 = { + 81 EC ?? ?? ?? ?? 83 24 24 ?? 6A ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 44 24 + ?? 50 E8 ?? ?? ?? ?? 8D 04 24 50 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 8B 1D ?? + ?? ?? ?? 55 56 57 8B 3D ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? 50 E8 ?? ?? + ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 8D 84 24 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 50 89 74 24 ?? FF D3 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 8B E8 83 FD ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D7 85 C0 0F 84 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 33 C0 66 89 84 + 74 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF D3 6A ?? 8D 44 24 ?? 50 E8 + ?? ?? ?? ?? F6 44 24 ?? ?? 8B F0 74 ?? 6A ?? 56 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D3 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? + 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 44 24 ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? + 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 8D 44 24 ?? + 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? A8 ?? 74 ?? 83 E0 ?? 50 8D 84 24 ?? ?? + ?? ?? 50 FF 15 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 50 FF B4 24 + ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 8D 84 24 ?? ?? ?? ?? + 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? + 50 FF D3 6A ?? 8D 84 24 ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D + 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 74 24 ?? 59 8D 44 24 ?? 50 + 55 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 E8 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C2 } - $encrypt_routine_2 = { - 00 00 06 13 0B 07 06 20 ?? 07 00 00 28 60 00 00 06 09 6F ?? 00 00 0A 00 20 ?? 07 00 00 - 28 60 00 00 06 13 0B 11 04 09 6A D6 13 04 00 20 ?? 07 00 00 28 60 00 00 06 13 0B 11 04 - 11 05 FE 04 13 0D 11 0D 2D 86 ?? 45 01 00 00 00 F6 FF FF FF 17 2D 06 D0 4F 00 00 06 26 - 20 ?? 07 00 00 28 60 00 00 06 13 0B 07 6F ?? 00 00 0A 00 20 ?? 07 00 00 28 60 00 00 06 - 13 0B 02 7B 1B 00 00 04 6F ?? 00 00 0A 00 20 ?? 07 00 00 28 60 00 00 06 13 0B 02 7B 1C - 00 00 04 6F ?? 00 00 0A 00 20 ?? 07 00 00 28 60 00 00 06 13 0B 0E 05 20 ?? 07 00 00 28 - 60 00 00 06 FE 01 13 0D 11 0D 2C 32 ?? 45 01 00 00 00 F6 FF FF FF 20 ?? 07 00 00 28 60 - 00 00 06 13 0B 03 73 ?? 00 00 0A 13 06 20 ?? 07 00 00 28 60 00 00 06 13 0B 11 06 6F ?? - 00 00 0A 00 00 20 ?? 07 00 00 28 60 00 00 06 13 0B 0E 05 20 ?? 07 00 00 28 60 00 00 06 - FE 01 13 0D 11 0D 2C ?? [0-20] 20 ?? 07 00 00 28 60 00 00 06 13 0B 03 73 ?? 00 00 0A 13 - 07 20 ?? 07 00 00 28 60 00 00 06 13 0B 11 07 6F ?? 00 00 0A 00 00 20 ?? ?? 00 00 28 60 - 00 00 06 13 0B 02 7B 1B 00 00 04 6F ?? 00 00 0A 00 20 ?? ?? 00 00 28 60 00 00 06 13 0B - 02 7B 1C 00 00 04 6F ?? 00 00 0A 00 DD 3B 01 00 00 11 0A 2B 0D 11 0A 20 ?? ?? 00 00 28 + $search_files_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 8B F8 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D8 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 F6 + 8D 85 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 DB 74 ?? F6 C3 ?? 74 ?? 8D 85 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 75 ?? 6A ?? 6A + ?? C6 85 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 + 04 B7 51 50 FF 15 ?? ?? ?? ?? 46 FE 85 ?? ?? ?? ?? D1 EB 75 ?? EB ?? 68 ?? ?? ?? ?? + FF 34 B7 FF 15 ?? ?? ?? ?? 85 C0 74 } - $encrypt_routine_3 = { - 60 00 00 06 58 20 ?? 08 00 00 28 60 00 00 06 13 0A 45 26 00 00 00 00 00 00 00 ?? FC FF - FF ?? FC FF FF ?? FC FF FF ?? FC FF FF ?? FC FF FF ?? FC FF FF ?? FC FF FF ?? ?? FF FF - ?? FD FF FF ?? FD FF FF ?? FD FF FF 00 00 00 00 ?? FD FF FF ?? FD FF FF ?? FD FF FF ?? - FD FF FF ?? FD FF FF ?? FD FF FF ?? ?? FF FF ?? FD FF FF ?? FD FF FF ?? FD FF FF ?? ?? - FF FF ?? FE FF FF ?? FE FF FF ?? FE FF FF ?? FE FF FF ?? FE FF FF ?? FE FF FF ?? FE FF - FF ?? FE FF FF E8 FE FF FF FC FE FF FF 10 FF FF FF 11 FF FF FF 29 FF FF FF 41 FF FF FF - DE 6D 11 0B 13 0A 11 09 20 ?? 08 00 00 28 60 00 00 06 30 16 ?? 45 01 00 00 00 F6 FF FF - FF 20 ?? 08 00 00 28 60 00 00 06 2B 02 11 09 45 02 00 00 00 00 00 00 00 11 FF FF FF DE - 34 75 4B 00 00 01 14 FE 03 11 09 20 ?? 08 00 00 28 60 00 00 06 FE 03 5F 11 0A 20 ?? 08 - 00 00 28 60 00 00 06 FE 01 5F FE 11 74 4B 00 00 01 28 57 00 00 0A DE 93 20 ?? 08 00 00 - 28 60 00 00 06 28 ?? 00 00 0A + $encrypt_files_2 = { + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 24 24 ?? 53 55 56 57 E8 ?? ?? ?? ?? 8B D0 8D 4C 24 + ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 1D ?? ?? ?? + ?? 8B 35 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 84 24 ?? ?? + ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 89 7C 24 ?? + FF D3 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B E8 83 FD ?? 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 33 C0 66 89 84 7C ?? ?? ?? ?? 8D 44 + 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF D3 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B F8 33 D2 F6 44 + 24 ?? ?? 8B CF 74 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 + ?? ?? ?? ?? 50 FF D3 8D 94 24 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? + 42 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 + 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 50 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 + ?? A8 ?? 74 ?? 83 E0 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 51 6A ?? 5A 8B + CF E8 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8D 84 24 ?? ?? + ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 84 24 ?? ?? + ?? ?? 50 FF D3 6A ?? 8D 84 24 ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 8B 7C 24 ?? 59 8D 44 24 ?? + 50 55 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? E8 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C2 + } + $kill_specific_processes_2 = { + 81 EC ?? ?? ?? ?? 56 57 6A ?? 5E 56 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 + 74 24 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 8D 84 24 ?? + ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 53 55 BE ?? ?? ?? + ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 8B E8 33 D2 85 ED 7E ?? 0F BE 0C 1A E8 ?? ?? ?? ?? 88 04 1A 42 3B D5 7C ?? FF 36 + 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 83 C6 ?? 81 FE ?? ?? ?? ?? 7C ?? 85 C0 74 ?? 33 DB + 53 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? FF B4 + 24 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 68 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 56 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 8D + 44 24 ?? 50 53 53 68 ?? ?? ?? ?? 53 53 53 8D 84 24 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? + ?? 8D 84 24 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? + ?? ?? ?? 5D 5B 5F 5E 81 C4 ?? ?? ?? ?? C2 + } + $kill_specific_processes_1 = { + 81 EC ?? ?? ?? ?? 55 56 57 6A ?? 5E 56 33 ED 8D 44 24 ?? 55 50 E8 ?? ?? ?? ?? 83 C4 + ?? 89 74 24 ?? 55 6A ?? E8 ?? ?? ?? ?? 8B F8 89 7C 24 ?? 83 FF ?? 0F 84 ?? ?? ?? ?? + 53 8D 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 8B 5C + 24 ?? 83 BC 24 ?? ?? ?? ?? ?? 8B F5 7E ?? 55 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? + 8B E8 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 DB 89 44 24 ?? 85 C0 7E ?? 8B F8 + 0F BE 0C 2B 51 E8 ?? ?? ?? ?? 88 04 2B 43 3B DF 7C ?? 8B 84 24 ?? ?? ?? ?? FF 34 B0 + 55 FF 15 ?? ?? ?? ?? 8B D8 85 DB 75 ?? 46 50 5D 3B B4 24 ?? ?? ?? ?? 7C ?? 8B 7C 24 + ?? 33 ED 85 DB 74 ?? 55 68 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 55 50 FF + 15 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 C4 + ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 56 8D 44 24 ?? 50 FF 15 ?? ?? ?? + ?? 8D 44 24 ?? 50 8D 44 24 ?? 50 55 55 68 ?? ?? ?? ?? 55 55 55 8D 84 24 ?? ?? ?? ?? + 50 55 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? + ?? ?? 57 FF 15 ?? ?? ?? ?? 5B 5F 5E 5D 81 C4 ?? ?? ?? ?? C2 + } + $encrypt_files_3 = { + 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 33 C0 66 89 84 74 ?? ?? + ?? ?? 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF D3 6A ?? 8D 44 24 ?? 50 E8 ?? ?? ?? + ?? F6 44 24 ?? ?? 8B F0 74 ?? 6A ?? 56 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D3 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? 50 E8 ?? + ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 44 24 ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 44 24 ?? 50 FF + D7 85 C0 0F 84 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 8D 44 24 ?? 50 FF + D7 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? A8 ?? 74 ?? 83 E0 ?? 50 8D 84 24 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? FF 74 24 ?? 6A ?? 56 E8 ?? ?? ?? ?? 50 FF 74 24 ?? 8D 84 24 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 8D 84 24 ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D3 6A ?? 8D 84 24 + ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 74 24 ?? 59 8D 44 24 ?? 50 55 FF 15 + } + $search_files_2 = { + 53 55 56 57 8B 3D ?? ?? ?? ?? 6A ?? 6A ?? FF D7 50 FF 15 ?? ?? ?? ?? 8B E8 FF 15 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8B D8 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 33 F6 8D 84 24 ?? ?? + ?? ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 DB 74 ?? F6 C3 ?? 74 ?? 8D 84 24 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 75 ?? 6A ?? 6A ?? C6 84 + 24 ?? ?? ?? ?? ?? FF D7 50 FF 15 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 89 44 B5 ?? 51 50 + FF 15 ?? ?? ?? ?? 46 FE 84 24 ?? ?? ?? ?? D1 EB 75 ?? 33 FF 85 F6 7E ?? 8B 9C 24 ?? + ?? ?? ?? 8D 44 24 ?? 2B E8 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 8C + 24 ?? ?? ?? ?? 89 48 ?? 8D 0C BD ?? ?? ?? ?? 03 CD 89 58 ?? 8B 4C 0C ?? 89 08 33 C9 + 51 51 50 68 ?? ?? ?? ?? 51 51 FF 15 ?? ?? ?? ?? 89 44 BC ?? 47 3B FE 7C ?? 6A ?? 6A + ?? 8D 44 24 ?? 50 56 FF 15 + } + $kill_specific_processes_3 = { + E8 ?? ?? ?? ?? 83 C4 ?? 89 74 24 ?? 55 6A ?? E8 ?? ?? ?? ?? 8B F8 89 7C 24 ?? 83 FF + ?? 0F 84 ?? ?? ?? ?? 53 8D 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 50 57 + E8 ?? ?? ?? ?? 8B 5C 24 ?? 83 BC 24 ?? ?? ?? ?? ?? 8B F5 7E ?? 55 8D 84 24 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? 8B E8 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 DB 89 44 24 + ?? 85 C0 7E ?? 8B F8 0F BE 0C 2B 51 E8 ?? ?? ?? ?? 88 04 2B 43 3B DF 7C ?? 8B 84 24 + ?? ?? ?? ?? FF 34 B0 55 FF 15 ?? ?? ?? ?? 8B D8 85 DB 75 ?? 46 50 5D 3B B4 24 ?? ?? + ?? ?? 7C ?? 8B 7C 24 ?? 33 ED 85 DB 74 ?? 55 68 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 55 50 FF 15 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 56 FF + 15 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 56 8D 44 24 + ?? 50 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 44 24 ?? 50 55 55 68 ?? ?? ?? ?? 55 55 55 + 8D 84 24 ?? ?? ?? ?? 50 55 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? + ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 } condition: - uint16(0)==0x5A4D and ($encrypt_routine_1 and $encrypt_routine_2 and $encrypt_routine_3) + uint16(0)==0x5A4D and (($search_files_1 and $encrypt_files_1 and $kill_specific_processes_1) or ($search_files_1 and $encrypt_files_2 and $kill_specific_processes_2) or ($search_files_2 and $encrypt_files_3 and $kill_specific_processes_3)) } -rule REVERSINGLABS_Win32_Ransomware_Blackmoon : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Networm : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects BlackMoon ransomware." + description = "Yara rule that detects Networm ransomware." author = "ReversingLabs" - id = "95ebb6c4-b0c9-5f9a-8424-a2f4d33953eb" - date = "2020-11-11" - modified = "2020-11-11" + id = "3b17b97d-c882-5f65-8b89-847e2300873c" + date = "2021-07-05" + modified = "2021-07-05" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.BlackMoon.yara#L1-L70" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "428409096a8637978bf2a1efb3238e4ba87715a909693b0cd26c0f689d567a09" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Networm.yara#L1-L103" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ff9bcb9868522f9d4abf2ab9f94d5b7c9b009e5c6d0cf832c7d052f18e048b31" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -26493,66 +27981,94 @@ rule REVERSINGLABS_Win32_Ransomware_Blackmoon : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "BlackMoon" + tc_detection_name = "Networm" tc_detection_factor = 5 importance = 25 strings: $find_files = { - 81 EC ?? ?? ?? ?? 53 8B 9C 24 ?? ?? ?? ?? 55 56 8B 33 57 8B BC 24 ?? ?? ?? ?? 33 ED - 85 FF 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 76 ?? 85 F6 74 ?? 83 FE ?? 74 ?? 56 FF - 15 ?? ?? ?? ?? 8D 44 24 ?? 50 57 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 89 33 74 ?? 8B 84 - 24 ?? ?? ?? ?? 85 C0 74 ?? 8B 4C 24 ?? 83 E1 ?? 80 F9 ?? 74 ?? EB ?? 8B 94 24 ?? ?? - ?? ?? 8B 44 24 ?? 85 C2 74 ?? BD ?? ?? ?? ?? 85 F6 74 ?? 83 FE ?? 74 ?? 85 ED 75 ?? - 8B 84 24 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 85 C0 8D 44 24 ?? 50 56 74 ?? FF D7 85 C0 74 - ?? 8B 4C 24 ?? 83 E1 ?? 80 F9 ?? 75 ?? 8D 54 24 ?? 52 56 FF D7 85 C0 75 ?? 5F 5E 5D - 33 C0 5B 81 C4 ?? ?? ?? ?? C3 FF D7 85 C0 74 ?? 8B 9C 24 ?? ?? ?? ?? 85 5C 24 ?? 75 - ?? 8D 4C 24 ?? 51 56 FF D7 85 C0 75 ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 8D 54 24 ?? - 52 E8 ?? ?? ?? ?? 40 50 E8 ?? ?? ?? ?? 8B D0 8D 7C 24 ?? 83 C9 ?? 33 C0 83 C4 ?? F2 - AE F7 D1 2B F9 8B C1 8B F7 8B FA C1 E9 ?? F3 A5 8B C8 8B C2 83 E1 ?? F3 A4 5F 5E 5D - 5B 81 C4 ?? ?? ?? ?? C3 + 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F1 89 B5 ?? ?? ?? ?? 8B 7D ?? 33 DB + 6A ?? 59 33 C0 89 5D ?? 89 4D ?? 66 89 45 ?? 89 5D ?? 89 5D ?? 89 4D ?? 66 89 45 ?? + 68 ?? ?? ?? ?? 8B D7 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 4D ?? 3B C8 + 74 ?? 88 9D ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 7D ?? ?? 8D 8D ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF 15 ?? ?? ?? ?? + 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 66 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 8D + 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D7 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 8D + ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + C6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? F6 85 + ?? ?? ?? ?? ?? 8D 45 ?? 74 ?? 6A ?? 50 8B CE E8 ?? ?? ?? ?? 8B F0 85 F6 0F 85 ?? ?? + ?? ?? 8B B5 ?? ?? ?? ?? EB ?? 83 7D ?? ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 FF 15 ?? ?? + ?? ?? 85 C0 74 ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? + 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 53 FF 15 ?? ?? + ?? ?? 8B 1D ?? ?? ?? ?? FF D3 8B F0 83 FE ?? 75 ?? 83 7F ?? ?? 8B C7 72 ?? 8B 07 68 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 83 7F ?? ?? 72 ?? 8B 3F 57 FF 15 ?? ?? + ?? ?? 85 C0 75 ?? FF D3 8B F0 EB ?? FF 15 ?? ?? ?? ?? EB ?? 33 F6 8D 4D ?? E8 ?? ?? + ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? C2 + } + $remote_connection_p1 = { + 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 8B 5D ?? 56 57 6A ?? 8B FA 8B F1 + FF 15 ?? ?? ?? ?? 33 C0 50 50 89 45 ?? 89 45 ?? 8D 45 ?? 50 8D 45 ?? 50 6A ?? 57 56 + FF 15 ?? ?? ?? ?? 8B D3 8B C8 E8 ?? ?? ?? ?? 83 3B ?? 8B F0 75 ?? 68 ?? ?? ?? ?? EB + ?? 81 3B ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? EB ?? 81 3B ?? ?? ?? + ?? 74 ?? 81 3B ?? ?? ?? ?? 74 ?? 85 F6 74 ?? 83 C8 ?? EB ?? 83 65 ?? ?? 8D 75 ?? 8B + 45 ?? 8B FB C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? A5 A5 A5 8B 4D ?? 5F 5E 33 CD 5B E8 ?? + ?? ?? ?? C9 C3 + } + $remote_connection_p2 = { + 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 8B 5D ?? 56 57 6A ?? 8B FA 8B F1 + FF 15 ?? ?? ?? ?? 33 C0 50 50 50 89 45 ?? 8D 45 ?? 50 FF 75 ?? 57 56 FF 15 ?? ?? ?? + ?? 8B D3 8B C8 E8 ?? ?? ?? ?? 83 3B ?? 8B F0 75 ?? 68 ?? ?? ?? ?? EB ?? 81 3B ?? ?? + ?? ?? 75 ?? 68 ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 85 F6 74 ?? 83 C8 ?? EB ?? 83 65 ?? + ?? 8D 75 ?? 8B 45 ?? 8B FB C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? A5 A5 A5 8B 4D ?? 5F 5E + 33 CD 5B E8 ?? ?? ?? ?? C9 C3 } $encrypt_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? - 6A ?? 8B 5D ?? 8B 03 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 5D ?? 8B 03 85 C0 75 ?? - B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? DB - 45 ?? DD 5D ?? DD 45 ?? DB 45 ?? DD 5D ?? DC 65 ?? DD 5D ?? DD 45 ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 6A ?? 50 68 ?? ?? ?? ?? 6A ?? 8B 5D ?? 8B 03 85 C0 75 ?? B8 ?? ?? ?? - ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 45 ?? 50 8B - 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 8B 5D - ?? 8B 03 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? + 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 8B 45 ?? 83 F8 ?? C7 45 ?? ?? ?? ?? ?? 0F + 94 C7 83 F8 ?? 0F 94 C3 83 F8 ?? 75 ?? B8 ?? ?? ?? ?? EB ?? 0F B6 C3 83 F0 ?? 8D 04 + 45 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 6A ?? FF 76 ?? FF 15 ?? ?? ?? ?? 8B C8 89 4E ?? + 85 C9 0F 84 ?? ?? ?? ?? 84 FF 74 ?? BF ?? ?? ?? ?? EB ?? 0F B6 C3 8D 3C 45 ?? ?? ?? + ?? 8B 56 ?? 8B 46 ?? 85 D2 7C ?? 0F 8F ?? ?? ?? ?? 85 C0 72 ?? 85 D2 7C ?? 0F 8F ?? + ?? ?? ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 83 F8 ?? 74 ?? 89 55 ?? EB ?? 0F 57 C0 66 0F 13 + 45 ?? 8B 45 ?? FF 75 ?? 50 FF 75 ?? FF 75 ?? 57 51 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D + 4D ?? 89 46 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? + 59 5F 5E 5B 8B E5 5D C2 } $encrypt_files_p2 = { - 83 C4 ?? 89 45 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 - 45 ?? 68 ?? ?? ?? ?? 6A ?? 8B 5D ?? 8B 03 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? - ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? - ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? - 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? 68 ?? ?? ?? - ?? 8B 5D ?? FF 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? ?? ?? 6A - ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? - B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 - DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? - 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B E5 5D C2 + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 56 A1 ?? ?? ?? ?? 33 C5 + 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 83 7E ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? + ?? 8B 4D ?? 85 C9 74 ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? EB ?? 8B 45 ?? 85 C0 74 ?? 0F + 8E ?? ?? ?? ?? 83 F8 ?? 7E ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? EB ?? F6 C1 ?? C7 45 ?? ?? + ?? ?? ?? B8 ?? ?? ?? ?? 0F 95 C0 40 89 45 ?? 83 7D ?? ?? 7F ?? 0F 8C ?? ?? ?? ?? 83 + 7D ?? ?? 0F 82 ?? ?? ?? ?? 83 7D ?? ?? 7F ?? 0F 8C ?? ?? ?? ?? 83 7D ?? ?? 0F 82 ?? + ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 8D 45 ?? 8B + CE 50 E8 ?? ?? ?? ?? 8D 45 ?? 8B CE 50 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 8B E5 5D C2 ?? ?? 8D 45 ?? 6A + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 C6 45 ?? + ?? E8 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 8D 4D ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 45 + ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 C6 + 45 ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 68 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Policerecords : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_NB65 : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects PoliceRecords ransomware." + description = "Yara rule that detects NB65 ransomware." author = "ReversingLabs" - id = "bacd3f98-a069-58ca-8423-01fcef7d4062" - date = "2022-08-02" - modified = "2022-08-02" + id = "1aba009e-8065-5fb0-98e7-a595cb324076" + date = "2022-06-01" + modified = "2022-06-01" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.PoliceRecords.yara#L1-L79" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "55cb1a5d030c47abb1a9ca9970fb19b3124128e409bc9515c173c33b2bb49a16" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.NB65.yara#L1-L68" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "f8a0e265fc72a9f017b37ce4b6dbb878285a5d298ab1b8c69f9fde7159426981" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -26560,68 +28076,61 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Policerecords : TC_DETECTION MALICIO sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "PoliceRecords" + tc_detection_name = "NB65" tc_detection_factor = 5 importance = 25 strings: $encrypt_files = { - 00 72 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 07 06 6F ?? ?? ?? ?? 0C 04 0D 09 18 73 ?? ?? ?? - ?? 13 ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 08 08 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? - 03 19 73 ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 11 ?? D2 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? - 25 13 ?? 15 FE 01 16 FE 01 13 ?? 11 ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? - ?? 00 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 26 00 00 DE ?? 2A + E8 ?? ?? ?? ?? 89 45 ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? + C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? + C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? + C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? + C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8A 45 ?? 80 7D ?? ?? 75 ?? 33 C9 90 8A 44 0D ?? + 0F B6 C0 83 E8 ?? 6B C0 ?? 99 F7 FB 8D 42 ?? 99 F7 FB 88 54 0D ?? 41 83 F9 ?? 72 ?? + 8D 45 ?? 89 45 ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 50 + ?? 33 C9 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 81 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D0 + 85 C0 75 ?? 33 F6 66 90 A1 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? + 8D 50 ?? 33 C9 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 81 ?? ?? ?? ?? FF B4 B5 ?? ?? ?? + ?? 57 FF D0 85 C0 75 ?? 46 83 FE ?? 7C ?? 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 } $find_files = { - 11 ?? 11 ?? 9A 13 ?? 00 00 07 11 ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 00 11 ?? 28 ?? ?? ?? ?? 00 00 DE ?? 26 00 00 DE ?? 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E - 69 32 ?? 00 DE ?? 26 00 00 DE ?? 17 8D ?? ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 0C 16 13 ?? - 2B ?? 00 00 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 08 11 ?? 9A 28 ?? ?? ?? ?? 00 - 72 ?? ?? ?? ?? 08 11 ?? 9A 28 ?? ?? ?? ?? 18 28 ?? ?? ?? ?? 00 00 DE ?? 26 00 00 DE ?? - 00 11 ?? 17 58 13 ?? 11 ?? 08 8E 69 FE 04 13 ?? 11 ?? 2D ?? 00 00 72 ?? ?? ?? ?? 1D 28 - ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 1D 28 ?? ?? ?? ?? 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 DE ?? 26 00 00 DE ?? 7E ?? ?? - ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0D 09 72 ?? ?? ?? ?? 17 8C ?? ?? ?? ?? 1A 6F ?? ?? - ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 16 8C - ?? ?? ?? ?? 1A 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 - ?? 72 ?? ?? ?? ?? 17 8C ?? ?? ?? ?? 1A 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 17 8C ?? ?? ?? ?? 1A 6F ?? ?? ?? ?? 00 7E ?? - ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 6F - ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? - 72 ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 00 07 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? - 13 ?? 11 ?? 6F ?? ?? ?? ?? 00 73 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 26 2A - } - $desktop_kill_tick = { - 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 0A 06 72 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 0B 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 08 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 09 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 13 ?? 07 28 ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 07 28 ?? ?? ?? ?? 00 - 00 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 11 ?? 28 ?? ?? ?? ?? 00 00 02 7B ?? ?? ?? - ?? 6F ?? ?? ?? ?? 00 2A + 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 + 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? + 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? + 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 80 BD ?? ?? + ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? + 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 8B 85 ?? ?? ?? ?? 75 ?? + 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 } - $drop_ransom_note = { - 00 16 28 ?? ?? ?? ?? 0A 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 00 07 72 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 00 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 72 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 00 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 - 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 DE ?? 07 2C ?? - 07 6F ?? ?? ?? ?? 00 DC 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 26 2A + $enum_procs = { + 33 C9 66 90 8A 84 0D ?? ?? ?? ?? 0F B6 C0 83 E8 ?? 8D 04 C0 99 F7 BD ?? ?? ?? ?? 8D + 42 ?? 99 F7 BD ?? ?? ?? ?? 88 94 0D ?? ?? ?? ?? 41 83 F9 ?? 72 ?? A1 ?? ?? ?? ?? 8B + 40 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 33 D2 33 C9 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 41 + ?? 8D 8D ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? 51 FF D0 85 C0 75 ?? 6A ?? E8 ?? ?? ?? ?? + 83 C4 ?? 85 C0 74 ?? C7 00 ?? ?? ?? ?? 8D 50 ?? 8B 8D ?? ?? ?? ?? 89 08 C7 02 ?? ?? + ?? ?? 8B 4E ?? 89 48 ?? 8B 4E ?? 89 01 89 56 ?? 8D 85 ?? ?? ?? ?? 50 57 FF D3 85 C0 + 0F 85 ?? ?? ?? ?? 5B A1 ?? ?? ?? ?? 8B 40 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 33 D2 33 C9 + E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 41 ?? 57 FF D0 8B 4D ?? 5F 33 CD 5E E8 ?? ?? ?? + ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($desktop_kill_tick) and ($drop_ransom_note) + uint16(0)==0x5A4D and ($find_files) and ($enum_procs) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Ophionlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Blackcat : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects OphionLocker ransomware." + description = "Yara rule that detects BlackCat ransomware." author = "ReversingLabs" - id = "75335749-66bd-539e-92b3-dd92c0b332d8" - date = "2020-07-15" - modified = "2020-07-15" + id = "e623340d-8df8-5f13-b75f-379bd0038f64" + date = "2022-02-14" + modified = "2022-02-14" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.OphionLocker.yara#L1-L105" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3c54a948a6a45ec5f5bc32fbbdbc8822f402b1332e9109b20b90635464dbe2ac" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.BlackCat.yara#L1-L109" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "24932baa625aedd14b5776ba3209c9ee330e84538c5267eeb5e09e352f655835" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -26629,104 +28138,96 @@ rule REVERSINGLABS_Win32_Ransomware_Ophionlocker : TC_DETECTION MALICIOUS MALWAR sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "OphionLocker" + tc_detection_name = "BlackCat" tc_detection_factor = 5 importance = 25 strings: - $ol_do_filetypes_1 = { - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 53 56 57 33 DB 53 89 5D ?? 53 89 5D ?? 89 5D ?? E8 ?? ?? ?? ?? 89 45 ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + $remote_connection_p1 = { + 8B 44 24 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? A1 ?? + ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 + ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? + ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 83 F8 ?? A1 ?? ?? ?? ?? 0F 45 C1 8B 0D ?? ?? + ?? ?? 0F 45 CA 8D 54 24 ?? 89 94 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? + ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 + 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? + ?? ?? ?? 56 51 FF 50 ?? 83 C4 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 56 68 ?? ?? ?? ?? + FF 74 24 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? + ?? ?? 6A ?? 56 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 + ?? E8 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 56 68 ?? ?? ?? ?? 68 ?? ?? + ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? 85 } - $ol_do_filetypes_2 = { - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - C6 45 ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? FF 75 ?? 8D 4D ?? 89 5D ?? 50 - 8D 85 ?? ?? ?? ?? 89 5D ?? 50 53 89 5D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 - ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC 89 65 ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 45 ?? 8B CC 8D 75 ?? 50 E8 ?? ?? - ?? ?? 8B CE C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 58 89 45 ?? 89 5D ?? 88 5D ?? 89 45 ?? 89 - 5D ?? 88 5D ?? 83 C4 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 4D ?? 8B 39 E9 00 01 00 00 8B 77 ?? - 8D 47 ?? 89 45 ?? 3B 77 ?? 0F 84 EC 00 00 00 8B F8 68 ?? ?? ?? ?? 8B D7 8D 4D ?? E8 ?? ?? ?? ?? 56 8B D0 C6 45 ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 50 8D 4D ?? E8 ?? ?? ?? ?? 53 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 6A ?? 8D 4D + $remote_connection_p2 = { + C0 89 44 24 ?? 0F 88 ?? ?? ?? ?? 8B 8B ?? ?? ?? ?? 74 ?? A1 ?? ?? ?? ?? 89 CB 85 C0 + 75 ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 74 24 ?? 6A ?? 50 E8 + ?? ?? ?? ?? 85 C0 89 D9 75 ?? E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 8B 5C 24 ?? 89 44 24 ?? + 53 51 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 44 24 ?? 89 F1 8D 54 24 ?? 89 44 24 ?? 89 5C 24 + ?? 89 5C 24 ?? C6 44 24 ?? ?? E8 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? 8B 84 24 ?? ?? ?? ?? 8B 9C 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? + ?? ?? ?? 3D ?? ?? ?? ?? 0F 43 C1 6A ?? 50 53 FF 74 24 ?? E8 ?? ?? ?? ?? 83 F8 ?? 89 + 44 24 ?? 75 ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 74 ?? 53 6A ?? FF 35 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 83 7C 24 ?? ?? 74 ?? FF 74 24 ?? 6A ?? FF 35 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 8B 5C 24 ?? 0F 84 ?? ?? ?? ?? 80 BB ?? ?? ?? ?? + ?? 0F 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB } - $ol_do_filetypes_3 = { - ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B CC 89 65 ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? - 89 65 ?? 8D 45 ?? 83 EC ?? 8B CC 50 E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? - 81 C4 ?? ?? ?? ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 53 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC 89 65 ?? 50 E8 ?? - ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C6 ?? 83 C4 ?? 3B 77 ?? 0F - 85 1C FF FF FF 8B 4D ?? 8B 7D ?? 8B 3F 89 7D ?? 3B F9 0F 85 F5 FE FF FF 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 - ?? ?? 8D 85 ?? ?? ?? ?? 89 65 ?? 8B CC BA ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC E8 ?? ?? ?? ?? C6 45 - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 8B CC 89 65 ?? BA ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B - CC E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 33 F6 8D 8D - ?? ?? ?? ?? 53 46 56 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 53 56 8D 4D ?? E8 ?? ?? ?? ?? 53 56 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 53 56 8D 4D ?? E8 ?? ?? - ?? ?? 8B 4D ?? 5F 5E 64 89 0D ?? ?? ?? ?? 5B 8B E5 5D C3 + $enum_procs = { + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 39 F7 74 ?? + 69 C7 ?? ?? ?? ?? 89 4D ?? 01 C8 68 ?? ?? ?? ?? 89 DE 53 50 E8 ?? ?? ?? ?? 83 C4 ?? + 47 8D 85 ?? ?? ?? ?? 89 7D ?? 50 8B 5D ?? 53 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 89 + F3 89 C6 EB ?? 8D 4D ?? 89 F2 E8 ?? ?? ?? ?? 8B 4D ?? 8B 7D ?? EB ?? 31 FF 8B 75 ?? + 85 FF 75 ?? E9 ?? ?? ?? ?? 31 FF 53 E8 ?? ?? ?? ?? 8B 75 ?? 85 FF 0F 84 ?? ?? ?? ?? + 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 69 C7 ?? ?? ?? ?? 8B 4D ?? 8D BD ?? ?? ?? ?? 01 F0 89 + 45 ?? 8B 45 ?? 8D 04 40 8D 04 81 89 45 ?? EB } - $ol_ecies_key_1 = { - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 53 56 57 8B F9 33 DB 89 5D ?? 8D 8D ?? ?? ?? ?? 89 7D ?? 89 5D ?? E8 ?? - ?? ?? ?? 33 F6 8D 85 ?? ?? ?? ?? 46 8D 8D ?? ?? ?? ?? 50 BA ?? ?? ?? ?? 89 75 ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B - CC 8B D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 56 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? - ?? ?? BE ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 50 56 FF 75 ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 85 C0 0F 85 40 03 00 00 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 50 51 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 51 - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? 8B B4 05 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? FF 50 ?? 50 8B 85 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 03 C8 FF 56 ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? FF 50 ?? 8D 55 ?? 8B C8 E8 ?? ?? ?? ?? 53 6A ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? BB ?? - ?? ?? ?? 8D 4D ?? 53 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? FF 50 ?? 83 7D ?? ?? 8D 4D ?? 8B F0 - 0F 43 4D ?? 51 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 95 ?? ?? ?? ?? 8B 06 52 8B 48 ?? 03 CE 8B 01 FF 50 ?? - C6 45 ?? ?? 8B 8D ?? ?? ?? ?? 85 C9 74 0D 8B 01 6A ?? 8B 40 ?? 03 C8 8B 01 FF 10 33 F6 C6 45 ?? ?? 56 6A ?? 8D 4D ?? E8 - ?? ?? ?? ?? 83 EC ?? 8B CC 53 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D0 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? + $find_files = { + 57 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 53 56 E8 ?? ?? ?? + ?? 83 F8 ?? 89 45 ?? 0F 84 ?? ?? ?? ?? 89 75 ?? A1 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? + ?? ?? 85 C0 0F 84 ?? ?? ?? ?? A3 ?? ?? ?? ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 85 C0 0F + 84 ?? ?? ?? ?? 89 C6 8B 45 ?? 8B 4D ?? 89 46 ?? 8B 45 ?? 89 46 ?? 8B 45 ?? 89 46 ?? + 8D 41 ?? C7 06 ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 89 CB 50 E8 ?? ?? + ?? ?? 83 C4 ?? 8B 45 ?? 89 43 ?? 89 73 ?? 8B 75 ?? 31 C0 C7 43 ?? ?? ?? ?? ?? F7 45 + ?? ?? ?? ?? ?? 89 03 75 ?? 83 7D ?? ?? 74 ?? 57 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 7D ?? ?? 75 ?? 83 7D ?? ?? 74 ?? 83 7D ?? ?? 74 ?? FF 75 ?? 6A ?? FF 35 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 5E 5F 5B 5D C3 } - $ol_ecies_key_2 = { - 56 6A ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8B CC 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 6A ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 53 - E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 - ?? ?? 50 8D 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 59 50 8D 4D ?? E8 ?? ?? ?? ?? 56 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? - 56 E8 ?? ?? ?? ?? 59 50 56 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 E8 - ?? ?? ?? ?? 59 50 56 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 - E8 ?? ?? ?? ?? 59 50 56 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 33 F6 C6 45 ?? ?? 56 50 8D 4D ?? E8 ?? ?? - ?? ?? 56 6A ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC BA ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 95 ?? ?? ?? ?? 8B CC 89 65 ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 53 E8 ?? - ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 56 6A ?? E8 ?? ?? ?? ?? 56 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? - 56 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + $encrypt_files_p1 = { + B8 ?? ?? ?? ?? 8D 4D ?? 8D 95 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 7D ?? 8B 75 + ?? 8D 4D ?? 89 FA 56 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? 8B 5D ?? 89 + 45 ?? 8B 45 ?? 83 F8 ?? 72 ?? 85 DB 74 ?? 0F B7 0B 81 F9 ?? ?? ?? ?? 75 ?? 8B 4B ?? + 89 C2 29 CA 72 ?? 83 FA ?? 72 ?? 85 DB 74 ?? 81 3C 0B ?? ?? ?? ?? 75 ?? 0F B7 54 0B + ?? 81 FA ?? ?? ?? ?? 75 ?? 0F B7 54 0B ?? 83 EA ?? 89 55 ?? BA ?? ?? ?? ?? 19 D2 89 + 55 ?? 72 ?? 83 F9 ?? 76 } - $ol_ecies_key_3 = { - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? EB 30 83 EC ?? 8D 55 ?? 8B CC 89 65 ?? E8 - ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC BB ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 51 8D 4F ?? - E8 ?? ?? ?? ?? 8D 77 ?? C7 07 ?? ?? ?? ?? C7 06 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 53 8D 4D ?? C7 45 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 46 ?? C6 45 ?? ?? 85 C0 74 05 8D 4E ?? EB 02 33 C9 8D 55 ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 4D ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? 8B 06 8B CE FF 50 ?? 6A ?? 68 ?? ?? ?? ?? 8B 08 8B 49 ?? 03 C8 8B 01 FF 50 ?? 53 E8 ?? ?? ?? ?? 59 6A ?? - 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8B C7 5F 5E 64 89 0D ?? ?? ?? ?? 5B - 8B E5 5D C3 + $encrypt_files_p2 = { + 53 E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 5D ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 57 + 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 51 ?? 29 D0 8B 55 ?? 0F 92 + 45 ?? 83 7D ?? ?? 75 ?? 80 7D ?? ?? 75 ?? 39 C2 77 ?? B8 ?? ?? ?? ?? F7 64 0B ?? 8B + 55 ?? 70 ?? 39 C2 72 ?? 8B 44 0B ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 45 ?? 8B 85 ?? + ?? ?? ?? 89 45 ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? + 89 45 ?? 89 10 89 48 ?? 8B 45 ?? 89 45 ?? 53 E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? + 8B 45 ?? 8B 4D ?? 29 45 ?? 3B 4D ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? E8 ?? ?? ?? + ?? 8B 45 ?? 8B 4D ?? 89 45 ?? 89 4D ?? E9 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8B 35 ?? ?? + ?? ?? 8B 45 ?? F2 0F 10 45 ?? 85 F6 89 85 ?? ?? ?? ?? F2 0F 11 85 ?? ?? ?? ?? 0F 84 + ?? ?? ?? ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 8D 0C C0 8D 3C 49 01 C7 01 F7 EB } condition: - uint16(0)==0x5A4D and (($ol_do_filetypes_1 and $ol_do_filetypes_2 and $ol_do_filetypes_3) and ($ol_ecies_key_1 and $ol_ecies_key_2 and $ol_ecies_key_3)) + uint16(0)==0x5A4D and ($enum_procs) and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Zhen : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Wastedlocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Zhen ransomware." + description = "Yara rule that detects WastedLocker ransomware." author = "ReversingLabs" - id = "ce6bc48d-934b-582c-8ce7-3dd595cbf5dd" - date = "2021-04-28" - modified = "2021-04-28" + id = "68090960-9878-5836-8caa-bf8f408a474e" + date = "2020-12-07" + modified = "2020-12-07" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Zhen.yara#L1-L176" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "17b24e7baeccd90b8695eb8d21d9ee4a317806ed7713252d315d06bee3f93e65" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Wastedlocker.yara#L1-L86" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0899d3cc3bcea8eae60689a54f34e57bdc52088c879c8420b8e6d0b1969cb186" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -26734,164 +28235,81 @@ rule REVERSINGLABS_Win32_Ransomware_Zhen : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Zhen" + tc_detection_name = "WastedLocker" tc_detection_factor = 5 importance = 25 strings: $find_files_p1 = { - FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 95 - ?? ?? ?? ?? 8B 4D ?? B8 ?? ?? ?? ?? 2B 41 ?? C1 E0 ?? 8B 4D ?? 8B 49 ?? 03 C8 FF 15 - ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D ?? 51 6A ?? FF 15 ?? ?? - ?? ?? 8D 55 ?? 8B 4D ?? 83 C1 ?? FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? 8D 55 ?? 52 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D - 4D ?? 51 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 - E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 8B 4D + 55 8B EC 83 EC ?? 83 65 ?? ?? 57 68 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 8B F8 85 FF 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 45 ?? 53 8B 5D ?? 8D 04 41 89 45 ?? + C7 00 ?? ?? ?? ?? 8B 43 ?? 57 51 89 45 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 89 45 ?? 0F 84 + ?? ?? ?? ?? 56 8D 47 ?? 66 83 38 ?? 75 ?? 0F B7 4F ?? 66 85 C9 0F 84 ?? ?? ?? ?? 66 + 83 F9 ?? 75 ?? 66 83 7F ?? ?? 0F 84 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B F0 + 8D 14 0E B8 ?? ?? ?? ?? 3B D0 89 55 ?? 0F 83 ?? ?? ?? ?? F6 07 ?? 0F 85 ?? ?? ?? ?? + 8B 45 ?? 85 C0 74 ?? 83 7F ?? ?? 75 ?? 39 47 ?? 0F 82 ?? ?? ?? ?? 8D 44 36 ?? 50 8D + 47 ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 85 C9 74 ?? 8B 45 ?? 83 C0 ?? 50 + E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 85 C9 74 ?? 8B 45 ?? 83 C0 ?? 50 E8 + ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 03 C6 8D 44 00 ?? 83 C0 ?? 50 6A ?? FF + 35 ?? ?? ?? ?? 89 45 ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? FF 75 ?? 6A + ?? 56 E8 ?? ?? ?? ?? 8B 45 ?? 8D 44 00 ?? 50 FF 75 ?? 8D 46 ?? 50 89 76 ?? 89 36 E8 + ?? ?? ?? ?? 8B 45 ?? 89 46 ?? 8B 45 ?? 89 46 ?? 8B 07 89 46 ?? 8B 47 ?? 89 46 ?? 8B } $find_files_p2 = { - 8B 11 8B 45 ?? 50 FF 92 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 85 - ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? 8D 4D ?? 51 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 - ?? 52 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 E8 - ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 - ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 11 89 95 ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B C4 8B 4D ?? 89 08 8B 55 ?? 89 50 ?? 8B 4D ?? 89 48 ?? 8B 55 - ?? 89 50 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C4 8B 4D ?? 89 08 8B 55 ?? 89 50 ?? 8B - 4D ?? 89 48 ?? 8B 55 ?? 89 50 ?? 8B 85 ?? ?? ?? ?? 8B 08 8B 95 ?? ?? ?? ?? 52 FF 91 - ?? ?? ?? ?? DB E2 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? EB ?? 8D - 4D ?? FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? - ?? C3 C3 8B 45 ?? 8B 08 8B 55 ?? 52 FF 51 ?? 8B 45 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? - 5F 5E 5B 8B E5 5D C2 + 47 ?? 89 46 ?? 8B 47 ?? 89 46 ?? 8B 47 ?? 83 C4 ?? 89 46 ?? 83 3B ?? 74 ?? 53 FF 15 + ?? ?? ?? ?? 8D 43 ?? 8B 48 ?? 89 06 89 4E ?? 89 31 89 70 ?? FF 43 ?? 83 7B ?? ?? 74 + ?? 8B 43 ?? 83 F8 ?? 75 ?? FF 73 ?? FF 15 ?? ?? ?? ?? 83 3B ?? 0F 84 ?? ?? ?? ?? 53 + FF 15 ?? ?? ?? ?? EB ?? C7 45 ?? ?? ?? ?? ?? EB ?? F6 45 ?? ?? 74 ?? 8D 4C 0E ?? 3B + C8 73 ?? 8D 04 36 50 8D 47 ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 8B 45 ?? 8D 04 41 + 66 83 60 ?? ?? 83 C4 ?? 83 7D ?? ?? 66 C7 00 ?? ?? 74 ?? 83 C1 ?? 51 8B 4D ?? E8 ?? + ?? ?? ?? 85 C0 75 ?? 8B 4D ?? FF 75 ?? 8B 45 ?? 53 FF 75 ?? 8D 44 06 ?? FF 75 ?? 50 + 51 E8 ?? ?? ?? ?? 89 45 ?? EB ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 ?? F6 45 ?? ?? + 74 ?? 83 65 ?? ?? 83 7D ?? ?? 75 ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 43 + ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5E 57 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 5B EB + ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 5F C9 C2 } $encrypt_files_p1 = { - 55 8B EC 83 EC ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 53 56 57 89 65 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 08 8B 55 ?? 52 FF 51 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 66 89 45 ?? 8D 4D ?? FF 15 ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 8B 11 52 66 8B 45 ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? 6A ?? 66 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 83 E8 ?? 50 6A ?? 6A ?? - 8D 55 ?? 52 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 66 - 8B 45 ?? 50 8D 4D ?? 51 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 8B - 55 ?? 52 FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 8D 4D ?? 51 8B 55 ?? 8B - 02 8B 4D ?? 51 FF 50 ?? 89 45 ?? 83 7D ?? ?? 7D ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 - 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? EB ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 51 FF 15 ?? ?? ?? ?? 66 89 45 - ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 8B 02 50 66 8B 4D ?? 51 + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 FF 75 ?? 8B 3D ?? ?? ?? ?? FF 75 ?? FF D7 85 C0 + 0F 84 ?? ?? ?? ?? FF 75 ?? 8D 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 89 45 ?? 75 ?? FF 75 ?? + FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 74 ?? F6 C3 ?? 74 ?? 83 E0 ?? 50 FF 75 ?? FF 15 ?? + ?? ?? ?? 85 C0 75 ?? 33 DB 85 DB 89 5D ?? 0F 84 ?? ?? ?? ?? FF 75 ?? 8D 75 ?? E8 ?? + ?? ?? ?? 89 45 ?? EB ?? 83 65 ?? ?? 33 C9 39 4D ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 39 4D ?? 74 ?? 8B 45 ?? 8B 10 8B 40 ?? C1 65 ?? ?? 89 55 ?? 89 45 + ?? EB ?? C7 45 ?? ?? ?? ?? ?? 89 4D ?? 89 4D ?? 8B 45 ?? 89 45 ?? 89 4D ?? 89 4D ?? + 8B 5D ?? 33 F6 8B 45 ?? 85 C0 89 45 ?? 74 ?? 3B D8 73 ?? 89 5D ?? 2B 45 ?? 89 45 ?? + 75 ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 8B 7D ?? 8D 45 ?? 50 57 8D 47 ?? 50 FF 75 + ?? 8B 45 ?? 03 C6 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 03 75 ?? 85 C0 89 45 ?? 0F } $encrypt_files_p2 = { - 6A ?? 6A ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? FF 15 ?? - ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 8B 11 8B 45 ?? 50 FF 52 ?? 89 45 ?? 83 7D - ?? ?? 7D ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? - EB ?? C7 45 ?? ?? ?? ?? ?? 66 8B 45 ?? 50 8D 4D ?? 51 68 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 8B 55 ?? 52 8D 45 ?? 50 68 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 8B 4D ?? 51 FF 15 ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? FF 15 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 8B 55 ?? 52 FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? 8B 45 ?? 8B 08 51 8D 55 ?? 52 FF 15 ?? ?? ?? ?? 50 8B 45 ?? 8B 08 51 8D 55 ?? 52 - FF 15 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 45 ?? 50 8B 4D ?? 51 FF 15 - ?? ?? ?? ?? 8B 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D ?? 51 8D 55 ?? 52 6A ?? - FF 15 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? FF 15 ?? ?? ?? ?? - 68 ?? ?? ?? ?? EB ?? 8D 45 ?? 50 8D 4D ?? 51 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 4D - ?? FF 15 ?? ?? ?? ?? C3 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? FF 15 - ?? ?? ?? ?? C3 8B 4D ?? 8B 11 8B 45 ?? 50 FF 52 ?? 8B 4D ?? 66 8B 55 ?? 66 89 11 8B - 45 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C2 - } - $scan_network_p1 = { - 55 8B EC 83 EC ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 53 56 57 89 65 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 08 8B 55 ?? 52 FF 51 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 08 8B 55 ?? 52 - FF 91 ?? ?? ?? ?? 50 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 4D ?? 51 8B - 95 ?? ?? ?? ?? 8B 02 8B 8D ?? ?? ?? ?? 51 FF 90 ?? ?? ?? ?? DB E2 89 85 ?? ?? ?? ?? - 83 BD ?? ?? ?? ?? ?? 7D ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 8B 85 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D 4D ?? FF - 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8D - 4D ?? 51 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8D - 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 8D - 4D ?? 51 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? - 8B 08 8B 55 ?? 52 FF 91 ?? ?? ?? ?? 50 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? 8D 4D ?? 51 8B 95 ?? ?? ?? ?? 8B 02 8B 8D ?? ?? ?? ?? 51 FF 90 ?? ?? ?? ?? DB E2 - 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 95 ?? - ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 95 ?? ?? - ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8D 45 ?? 50 FF - } - $scan_network_p2 = { - 15 ?? ?? ?? ?? 8D 4D ?? 51 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 95 - ?? ?? ?? ?? 52 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 8D 4D ?? FF - 15 ?? ?? ?? ?? 8D 4D ?? 51 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? - ?? ?? ?? 8B 45 ?? B9 ?? ?? ?? ?? 2B 48 ?? 8B 55 ?? 8B 42 ?? 8B 0C 88 51 FF 15 ?? ?? - ?? ?? DD 9D ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? 2B 42 ?? 8B 4D ?? 8B 51 ?? 8B 04 82 - 50 FF 15 ?? ?? ?? ?? DC AD ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B 4D ?? BA ?? ?? ?? ?? 2B - 51 ?? 8B 45 ?? 8B 48 ?? 8B 14 91 52 FF 15 ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B 45 ?? B9 - ?? ?? ?? ?? 2B 48 ?? 8B 55 ?? 8B 42 ?? 8B 0C 88 51 FF 15 ?? ?? ?? ?? DC AD ?? ?? ?? - ?? DC 0D ?? ?? ?? ?? DC 85 ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? 2B - 42 ?? 8B 4D ?? 8B 51 ?? 8B 04 82 50 FF 15 ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B 4D ?? BA - ?? ?? ?? ?? 2B 51 ?? 8B 45 ?? 8B 48 ?? 8B 14 91 52 FF 15 ?? ?? ?? ?? DC AD ?? ?? ?? - ?? DC 0D ?? ?? ?? ?? DC 0D ?? ?? ?? ?? DC 85 ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B 45 ?? - 33 C9 2B 48 ?? 8B 55 ?? 8B 42 ?? 8B 0C 88 51 FF 15 ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B - 55 ?? 33 C0 2B 42 ?? 8B 4D ?? 8B 51 ?? 8B 04 82 50 FF 15 ?? ?? ?? ?? DC AD ?? ?? ?? - ?? DC 0D ?? ?? ?? ?? DC 0D ?? ?? ?? ?? DC 0D ?? ?? ?? ?? DC 85 ?? ?? ?? ?? DD 5D ?? - C7 45 ?? ?? ?? ?? ?? DD 45 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 89 41 ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 - } - $scan_network_p3 = { - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? - ?? 52 8D 85 ?? ?? ?? ?? 50 8D 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E9 ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - 8B 95 ?? ?? ?? ?? 8B 02 89 85 ?? ?? ?? ?? 8B 4D ?? 8B 11 8B 45 ?? 50 FF 92 ?? ?? ?? - ?? 50 8D 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 FF 15 - ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 8B 11 8B 85 ?? ?? ?? ?? 50 FF 52 ?? DB E2 89 85 ?? - ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 6A ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8B 95 - ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? 8B 45 ?? 89 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8D 55 ?? 52 - FF 15 ?? ?? ?? ?? 50 8B 85 ?? ?? ?? ?? 8B 08 8B 95 ?? ?? ?? ?? 52 FF 51 ?? DB E2 89 - 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 6A ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 - } - $scan_network_p4 = { - 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 - 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 8B 11 8B 45 ?? 50 FF 92 ?? ?? ?? ?? 50 8D 4D ?? 51 - FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8B 95 ?? ?? ?? ?? 8B 02 8B 8D ?? ?? ?? ?? - 51 FF 50 ?? DB E2 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 6A ?? 68 ?? ?? ?? ?? - 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 9B 68 ?? ?? ?? ?? EB ?? 8D - 4D ?? FF 15 ?? ?? ?? ?? 8D 4D ?? 51 8D 55 ?? 52 8D 45 ?? 50 6A ?? FF 15 ?? ?? ?? ?? - 83 C4 ?? 8D 4D ?? 51 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? C3 8D 85 ?? ?? ?? - ?? 50 8D 8D ?? ?? ?? ?? 51 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? FF 15 ?? ?? ?? - ?? 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? FF 15 ?? ?? ?? ?? C3 8B 4D - ?? 8B 11 8B 45 ?? 50 FF 52 ?? 8B 4D ?? 66 8B 55 ?? 66 89 11 8B 45 ?? 8B 4D ?? 64 89 - 0D ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C2 + 85 ?? ?? ?? ?? 2B 5D ?? 75 ?? EB ?? 8B 7D ?? 8B 45 ?? 0B 45 ?? 0F 84 ?? ?? ?? ?? 33 + C0 3B 45 ?? 77 ?? 72 ?? 3B 5D ?? 73 ?? 8B C3 EB ?? 8B 45 ?? 29 45 ?? 8B 4D ?? 83 5D + ?? ?? 0B 4D ?? 75 ?? 8B 4D ?? 89 4D ?? 03 F0 2B D8 0F 85 ?? ?? ?? ?? 8B 45 ?? 8B 4D + ?? 0F AC C8 ?? C1 E9 ?? 85 C0 74 ?? B9 ?? ?? ?? ?? F7 E1 29 45 ?? 19 55 ?? 01 45 ?? + 11 55 ?? 83 7D ?? ?? 75 ?? 8D 75 ?? E8 ?? ?? ?? ?? 85 C0 89 45 ?? 0F 84 ?? ?? ?? ?? + 8B 7D ?? 8D 47 ?? 50 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 39 75 ?? 74 ?? 83 7D ?? + ?? 74 ?? 8B 4D ?? 8B 45 ?? 8B D1 0B D0 74 ?? 0F AC C1 ?? C1 E8 ?? 83 4F ?? ?? 89 4F + ?? 89 75 ?? 39 75 ?? 74 ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 39 + 75 ?? 74 ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? EB ?? 8B 45 ?? 89 45 ?? 85 DB 0F 85 + ?? ?? ?? ?? E9 ?? ?? ?? ?? 01 75 ?? 83 55 ?? ?? E9 ?? ?? ?? ?? FF 75 ?? FF 75 ?? FF + D7 EB ?? FF 15 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 5F 5E 5B C9 C2 } condition: - uint16(0)==0x5A4D and ( all of ($scan_network_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Monalisa : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Cryptofortress : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Monalisa ransomware." + description = "Yara rule that detects CryptoFortress ransomware." author = "ReversingLabs" - id = "34addb63-2426-59a2-b79b-052a9161d361" - date = "2022-05-13" - modified = "2022-05-13" + id = "460289b1-f775-5e0b-8c44-4f6e5c92da60" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Monalisa.yara#L1-L83" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0bcb79dff111ec05ac93bbe9a777546bd6234dc60d9f6982c03cd0bc3b26b038" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.CryptoFortress.yara#L1-L162" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "474893b63523de5ff9eb8a0c91b0677b99ce65056af7f5d02a73e43fa65453c9" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -26899,72 +28317,147 @@ rule REVERSINGLABS_Win32_Ransomware_Monalisa : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Monalisa" + tc_detection_name = "CryptoFortress" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 A1 ?? ?? ?? ?? 33 - C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 75 ?? 83 EC ?? C7 45 ?? ?? ?? ?? ?? 8B CC 89 65 - ?? 8D 45 ?? B3 ?? 51 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 89 65 ?? 33 C0 6A - ?? 68 ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 66 89 01 E8 ?? ?? ?? ?? - 83 EC ?? C6 45 ?? ?? 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8A D3 88 5D ?? 8B CE E8 ?? ?? - ?? ?? 8B 55 ?? 83 C4 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? - ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? - 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? - ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 5B 8B E5 5D C3 + $enum_drives = { + 55 8B EC 83 C4 ?? 56 57 C7 45 ?? ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 8D 7D ?? B2 ?? B9 ?? ?? ?? ?? A9 ?? ?? ?? ?? 74 ?? 88 17 47 D1 E8 FE C2 49 + 75 ?? C6 07 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B F8 8D 75 ?? 8A 16 88 55 ?? 8D 45 ?? 50 + FF 15 ?? ?? ?? ?? 8D 55 ?? C6 42 ?? ?? 83 F8 ?? 75 ?? 60 8D 45 ?? 50 8D 45 ?? 50 6A + ?? 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? + 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 05 ?? ?? ?? ?? 61 46 4F 75 ?? A1 ?? ?? ?? ?? A3 + ?? ?? ?? ?? A1 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 5F 5E C9 C3 } - $write_proc_mem = { - 8D 45 ?? 50 FF 76 ?? 8B 46 ?? 03 C7 50 8B 06 03 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? - 85 C0 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 3E 0F B7 41 ?? 48 3B D8 75 ?? 8B 51 ?? - EB ?? 8B 4D ?? 8B 35 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 56 ?? 8B 4E ?? 2B D7 8B C1 25 ?? - ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? EB ?? 8B C1 25 ?? ?? ?? ?? 3D ?? ?? ?? - ?? 75 ?? B8 ?? ?? ?? ?? EB ?? 8B C1 25 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? - ?? EB ?? 8B C1 25 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? EB ?? F7 C1 ?? ?? - ?? ?? 74 ?? B8 ?? ?? ?? ?? EB ?? F7 C1 ?? ?? ?? ?? 74 ?? B8 ?? ?? ?? ?? EB ?? 85 C9 - B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 48 C1 8D 4D ?? 51 50 8B 45 ?? 52 03 C7 50 FF 75 ?? - FF 15 + $enum_shared_resources = { + 55 8B EC 83 C4 ?? 8D 45 ?? 50 FF 75 ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 0B C0 0F + 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 FF 75 ?? 8D 45 ?? 50 FF 75 ?? FF 15 + ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 3D ?? ?? ?? ?? 74 ?? 8B 4D ?? 51 8D 49 ?? 6B C9 ?? 8B + 45 ?? 8D 0C 01 6A ?? 51 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? FF 75 ?? E8 ?? + ?? ?? ?? 83 F8 ?? 76 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 0B C0 74 ?? FF 75 ?? E8 ?? ?? ?? ?? EB ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 49 75 ?? EB + ?? EB ?? E9 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? FF + 15 ?? ?? ?? ?? C9 C2 + } + $find_files = { + 55 8B EC 81 C4 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 40 0F 84 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 83 E0 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 + 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? C6 00 ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? C6 00 ?? 2B 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? + E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 8D ?? ?? ?? ?? C7 04 08 ?? ?? ?? ?? E8 ?? ?? ?? ?? 58 8B 8D ?? ?? ?? ?? C7 44 08 ?? + ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 + 0F 84 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF B5 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F + 85 ?? ?? ?? ?? 8B 4D ?? 0B C9 75 ?? 6A ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 45 ?? + 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 49 8B 1D ?? ?? ?? ?? 51 53 + FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 59 EB ?? 53 E8 ?? ?? ?? ?? 03 D8 + 83 C3 ?? 59 E2 ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 8B 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 0B + C9 75 ?? 3B D0 72 ?? EB ?? EB ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? + FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 75 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF B5 + ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF B5 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C9 C3 } $encrypt_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 50 - 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B C1 83 F8 ?? 0F 82 ?? - ?? ?? ?? 83 3D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 51 0F 43 05 ?? ?? ?? ?? 50 6A ?? 68 ?? - ?? ?? ?? 51 FF 75 ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 33 C9 C7 05 ?? ?? ?? ?? ?? ?? ?? - ?? 0F 10 00 0F 11 05 ?? ?? ?? ?? F3 0F 7E 40 ?? 66 0F D6 05 ?? ?? ?? ?? C7 40 ?? ?? - ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 66 89 08 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? - ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 - ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 - 89 0D ?? ?? ?? ?? 59 8B E5 5D C3 + 55 8B EC 83 C4 ?? 53 33 C0 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 + 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? FF 35 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 89 45 ?? FF 75 ?? E8 ?? ?? ?? ?? 33 C0 50 50 6A ?? 50 6A ?? 68 ?? ?? ?? ?? + FF 75 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? E9 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 8D 45 + ?? 50 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? + 83 7D ?? ?? 75 ?? 83 7D ?? ?? 73 ?? E9 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? BB ?? ?? ?? ?? + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? BB ?? ?? ?? ?? B8 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B D2 75 ?? 0B C9 75 ?? B9 ?? ?? ?? ?? 89 4D ?? 89 55 ?? + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 4D ?? 89 55 ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 89 4D ?? 89 55 ?? 0B DB 75 ?? 0B C0 74 ?? 83 45 ?? ?? 83 55 ?? ?? FF 75 ?? + FF 75 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 81 7D ?? ?? ?? + ?? ?? 76 ?? B8 ?? ?? ?? ?? EB ?? 8B 45 ?? 6B C0 ?? 89 45 ?? 6A ?? 8D 45 ?? 50 FF 75 + ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? 0B C0 74 ?? E9 ?? ?? ?? ?? + 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 FF 75 ?? 6A ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? E8 ?? ?? + ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? 0B C0 74 ?? E9 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF + 75 ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? DF 6D ?? DA 45 + ?? DF 7D ?? C7 45 ?? ?? ?? ?? ?? DF 6D ?? DA 65 ?? DF 7D ?? C7 45 ?? ?? ?? ?? ?? DF + 6D ?? DA 65 ?? DF 7D ?? 83 7D ?? ?? 75 ?? 83 7D ?? ?? 74 ?? E9 ?? ?? ?? ?? 8F 45 ?? + 8F 45 ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? + ?? ?? 0B C0 74 ?? EB ?? 6A ?? 8D 45 ?? 50 6A ?? 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? + ?? 0B C0 75 ?? EB ?? 6A ?? 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? + ?? 0B C0 75 ?? EB ?? EB ?? 8D 45 ?? 50 8D 45 ?? 50 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? + ?? ?? FF 75 ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? EB ?? 8D 45 ?? 50 8D 45 ?? 50 8D 45 ?? + 50 FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5B C9 C2 } - $generate_key = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 - 45 ?? 56 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B 75 ?? - 8B 0C 88 A1 ?? ?? ?? ?? 3B 81 ?? ?? ?? ?? 7F ?? 56 FF 75 ?? FF 35 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 85 C0 74 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 8B 4D ?? 33 CD E8 ?? ?? - ?? ?? 8B E5 5D C2 ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 3D ?? ?? ?? ?? ?? - 75 ?? B9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? ?? ?? - 8D 4D ?? E8 ?? ?? ?? ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 45 ?? 50 E8 + $read_config_file = { + 55 8B EC 83 C4 ?? [0-20] 6A ?? 68 ?? ?? ?? ?? 6A + ?? (E8 | FF 15) ?? ?? ?? ?? 0B C0 75 ?? 33 C0 C9 + C3 89 45 ?? 50 6A ?? (E8 | FF 15) ?? ?? ?? ?? 0B + C0 75 04 33 C0 C9 C3 89 45 ?? FF 75 ?? 6A ?? + (E8 | FF 15) ?? ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 + 89 45 ?? 50 (E8 | FF 15) ?? ?? ?? ?? 0B C0 75 04 + 33 C0 C9 C3 89 45 ?? FF 75 ?? 6A ?? (E8 | FF 15) + ?? ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 89 45 ?? 8B + D8 FF 75 ?? FF 75 ?? FF 75 ?? (E8 | FF 15) ?? ?? + ?? ?? FF 75 ?? (E8 | FF 15) ?? ?? ?? ?? 8B 5D ?? + 6A ?? 53 68 ?? ?? ?? ?? (E8 | FF 15) ?? ?? ?? ?? + 83 C3 ?? 8B 45 ?? 83 (E8 | FF 15) ?? 50 53 + (E8 | FF 15) ?? ?? ?? ?? 8A 03 A2 ?? ?? ?? ?? 83 + C3 ?? 8A 03 A2 ?? ?? ?? ?? 83 C3 + } + $file_type_loop = { + 51 53 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 + ?? 75 03 59 EB ?? 53 E8 ?? ?? ?? ?? 03 D8 83 C3 + ?? 59 E2 DC [20-40] FF B5 ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 0B C0 75 44 FF B5 ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF B5 + ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 + } + $encrypt_routine = { + FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? + [0-10] E9 ?? ?? ?? ?? 6A ?? [1-10] FF 75 ?? + FF (35 | 75) [1-4] FF 75 ?? (E8 | FF 15) + ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? 68 ?? + ?? ?? ?? [1-10] FF (35 | 75) [1-4] 6A ?? + 6A ?? 6A ?? FF 35 ?? ?? ?? ?? (E8 | FF 15) ?? + ?? ?? ?? 0B C0 75 ?? (EB | E9) [1-4] 6A ?? + [2-10] FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 + ?? 75 ?? [10-40] FF (35 | 75) [1-4] FF 75 ?? + (E8 |FF 15) } condition: - uint16(0)==0x5A4D and ($find_files) and ($write_proc_mem) and ($generate_key) and ($encrypt_files) + uint16(0)==0x5A4D and (($read_config_file and $file_type_loop and $encrypt_routine) or ($enum_drives and $enum_shared_resources and $find_files and $encrypt_files)) } -rule REVERSINGLABS_Win32_Ransomware_Gomer : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Hentaioniichan : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Gomer ransomware." + description = "Yara rule that detects Hentai Oniichan ransomware." author = "ReversingLabs" - id = "b76ac856-2abe-531d-b093-461569b9afb7" - date = "2020-10-08" - modified = "2020-10-08" + id = "cd5e916f-7195-5bb6-abff-b08231053f9a" + date = "2021-03-05" + modified = "2021-03-05" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Gomer.yara#L1-L106" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "a53d37fcb877a12a4969a6ea1aaa67fc4106c3fbdd80a4fd39ad5a66a9df47fc" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.HentaiOniichan.yara#L1-L140" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "153526e5a2f05bc8e3f77d83eefce6b4cd962ea093b6f1c0ab8fcabe8d8a7ad9" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -26972,97 +28465,127 @@ rule REVERSINGLABS_Win32_Ransomware_Gomer : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Gomer" + tc_detection_name = "HentaiOniichan" tc_detection_factor = 5 importance = 25 strings: $find_files_p1 = { - 8B FF 55 8B EC 51 8B 4D ?? 53 57 33 DB 8D 51 ?? 66 8B 01 83 C1 ?? 66 3B C3 75 ?? 8B - 7D ?? 2B CA D1 F9 83 C8 ?? 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 56 8D 5F ?? - 03 D9 6A ?? 53 E8 ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? - ?? 83 C4 ?? 85 C0 75 ?? FF 75 ?? 2B DF 8D 04 7E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 75 ?? 8B 4D ?? 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5F - 5B 8B E5 5D C3 33 C0 50 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? - ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 55 ?? 8B 4D ?? 53 8B 5D ?? 56 57 6A ?? 5E 6A ?? - 89 95 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 5F EB ?? 0F B7 01 66 3B 85 ?? ?? ?? - ?? 74 ?? 66 3B C6 74 ?? 66 3B C7 74 ?? 83 E9 ?? 3B CB 75 ?? 0F B7 31 66 3B F7 75 ?? - 8D 43 ?? 3B C8 74 ?? 52 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 6A ?? - 8B C6 33 FF 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 8B C7 + 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 4D ?? 8B 55 ?? 53 + 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 74 ?? + 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 ?? ?? ?? ?? 8A 01 88 85 ?? ?? ?? + ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? + ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 8A C3 75 ?? B0 ?? 2B + CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D ?? ?? ?? ?? 56 1B C0 89 9D ?? ?? ?? ?? + 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? F7 D8 } $find_files_p2 = { - EB ?? 33 C0 40 2B CB 0F B6 C0 D1 F9 41 F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 - 57 53 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? 8B 85 ?? ?? ?? ?? 50 57 57 53 E8 ?? ?? - ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD - 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 8D ?? ?? ?? ?? 6A ?? 8B 41 ?? 2B 01 C1 F8 ?? 89 85 - ?? ?? ?? ?? 58 66 39 85 ?? ?? ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 66 39 85 ?? ?? - ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 51 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 8B 8D - ?? ?? ?? ?? 85 C0 6A ?? 58 75 ?? 8B C1 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 - ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? - 83 C4 ?? E9 + 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 + ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? + ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 ?? 8A 48 ?? 84 C9 74 ?? + 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? + ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? + ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? + 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 8B D8 56 FF 15 ?? ?? ?? + ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B C3 8B 4D ?? + 5F 33 CD 5B E8 ?? ?? ?? ?? C9 C3 } - $encrypt_files = { - 55 8B EC 51 8B 45 ?? 53 56 57 8B F9 8B 4F ?? 89 4D ?? 3B C1 77 ?? 8B DF 83 F9 ?? 72 - ?? 8B 1F 8D 34 00 89 47 ?? 56 FF 75 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 04 1E - 8B C7 5F 5E 5B 8B E5 5D C2 ?? ?? 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 8B F0 83 CE ?? 81 - FE ?? ?? ?? ?? 76 ?? BE ?? ?? ?? ?? EB ?? 8B D1 B8 ?? ?? ?? ?? D1 EA 2B C2 3B C8 76 - ?? BE ?? ?? ?? ?? EB ?? 8D 04 0A 3B F0 0F 42 F0 8D 46 ?? 8D 0C 00 3D ?? ?? ?? ?? 76 - ?? 83 C9 ?? EB ?? 81 F9 ?? ?? ?? ?? 72 ?? 8D 41 ?? 83 CA ?? 3B C1 0F 46 C2 50 E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8D 58 ?? 83 E3 ?? 89 43 ?? EB ?? 85 C9 74 ?? 51 E8 ?? - ?? ?? ?? 83 C4 ?? 8B D8 EB ?? 33 DB 8B 45 ?? 89 77 ?? 89 47 ?? 8D 34 00 56 FF 75 ?? - 53 E8 ?? ?? ?? ?? 33 C0 83 C4 ?? 66 89 04 1E 8B 45 ?? 83 F8 ?? 72 ?? 8D 0C 45 ?? ?? - ?? ?? 8B 07 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 77 ?? - 8B C2 51 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 1F 8B C7 5F 5E 5B 8B E5 5D C2 ?? ?? E8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? CC CC CC CC CC B8 ?? ?? ?? ?? C3 + $inject_code_into_process = { + 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F8 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 0F 1F 84 00 ?? ?? ?? ?? 8B C6 8D 8D + ?? ?? ?? ?? 66 8B 11 66 3B 10 75 ?? 66 85 D2 74 ?? 66 8B 51 ?? 66 3B 50 ?? 75 ?? 83 + C1 ?? 83 C0 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 75 ?? FF B5 ?? ?? ?? + ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? FF 15 ?? ?? ?? ?? 39 85 ?? ?? ?? ?? + 74 ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? C6 45 ?? + ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 + ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? + ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 + ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 8D ?? + ?? ?? ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 3B 8D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 8B + 4D ?? 85 C9 74 ?? 51 8B D0 E8 ?? ?? ?? ?? 8B 4D ?? B8 ?? ?? ?? ?? 8B 75 ?? 83 C4 ?? + 2B CE F7 E9 C1 FA ?? 8B C2 C1 E8 ?? 03 C2 8D 0C 40 8B C6 C1 E1 ?? 81 F9 ?? ?? ?? ?? + 72 ?? 8B 76 ?? 83 C1 ?? 2B C6 83 C0 ?? 83 F8 ?? 77 ?? 51 56 E8 ?? ?? ?? ?? 83 C4 ?? + 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D 8B E3 + 5B C3 E8 } - $enum_drives_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 - 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 4D ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? FF 15 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 6A ?? 33 C0 C7 - 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? C6 - 45 ?? ?? BF ?? ?? ?? ?? 8D 45 ?? 0F A3 38 0F 83 ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 8D - 47 ?? 0F 43 4D ?? 66 89 01 8D 45 ?? 83 7D ?? ?? 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 83 - F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 33 C9 C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? 66 89 4D ?? C6 45 ?? ?? 83 F8 ?? 75 ?? 6A ?? 68 ?? ?? ?? ?? EB ?? - 83 F8 ?? 75 ?? 6A ?? 68 ?? ?? ?? ?? EB ?? 83 F8 ?? 75 ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 55 ?? 56 8D 4D ?? E8 ?? ?? - ?? ?? 8B 4D ?? B8 ?? ?? ?? ?? 2B CE C6 45 ?? ?? F7 E9 83 C4 ?? C1 FA ?? 8B DA C1 EB - ?? 03 DA 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? - ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? - ?? ?? 83 C4 ?? FF 35 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 55 ?? 56 8D 4D ?? E8 ?? ?? ?? - ?? 8B 4D ?? B8 ?? ?? ?? ?? 2B CE 89 7D ?? F7 E9 83 C4 ?? 89 5D ?? C1 FA ?? 8D 4D + $remote_connection_p1 = { + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? C7 45 + ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 28 45 + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 29 45 ?? 0F 28 45 + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF 85 ?? ?? ?? ?? 50 0F 29 45 ?? E8 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 + ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + 0F 28 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF 85 ?? ?? ?? ?? 0F 29 45 ?? + C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + 0F 28 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF 85 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 29 45 } - $enum_drives_p2 = { - 8B C2 C1 E8 ?? 03 C2 89 45 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? FF 75 - ?? 50 51 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B - 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 - C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 47 83 FF ?? 0F 8C ?? - ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 89 5D ?? C6 45 ?? ?? 8B 4D ?? 8B 31 - 3B F1 0F 84 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? FF 75 ?? 8B C8 C6 45 - ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F8 C6 45 ?? ?? 8B 4E ?? 89 4F ?? 8B 4E ?? 89 4F ?? 8D - 4F ?? 8B 46 ?? 89 47 ?? 8D 46 ?? 3B C8 74 ?? 83 78 ?? ?? 8B D0 72 ?? 8B 10 FF 70 ?? - 52 E8 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 57 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 + $remote_connection_p2 = { + 0F 28 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF 85 ?? ?? ?? ?? 50 0F 29 45 + ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 0F 43 95 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 8B 40 ?? 03 C8 33 C0 39 41 + ?? 0F 94 C0 8D 04 85 ?? ?? ?? ?? 0B 41 ?? 50 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? B8 ?? + ?? ?? ?? 2B C1 83 F8 ?? 0F 82 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 51 + 0F 43 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? + 0F 43 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 83 BD ?? ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 03 C1 50 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? + E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 + 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 C4 ?? 8B F0 83 FA ?? 72 ?? 8B + 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? + 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 + } + $encrypt_files = { + 8B FF 55 8B EC 83 EC ?? 8B 4D ?? 89 4D ?? 53 56 8B 75 ?? 57 8B 7D ?? 89 7D ?? 85 C9 + 0F 84 ?? ?? ?? ?? 85 FF 75 ?? E8 ?? ?? ?? ?? 83 20 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C8 ?? E9 ?? ?? ?? ?? 8B C6 8B D6 C1 FA ?? 83 E0 ?? 6B C0 ?? 89 + 55 ?? 8B 14 95 ?? ?? ?? ?? 89 45 ?? 8A 5C 02 ?? 80 FB ?? 74 ?? 80 FB ?? 75 ?? 8B C1 + F7 D0 A8 ?? 74 ?? 8B 45 ?? F6 44 02 ?? ?? 74 ?? 6A ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? + 83 C4 ?? 56 E8 ?? ?? ?? ?? 59 84 C0 74 ?? 84 DB 74 ?? FE CB 80 FB ?? 0F 87 ?? ?? ?? + ?? FF 75 ?? 8D 45 ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 E9 ?? ?? ?? ?? FF 75 ?? 8D + 45 ?? 57 56 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8B 45 ?? 8B 0C 85 ?? ?? ?? ?? 8B 45 ?? + 80 7C 01 ?? ?? 7D ?? 0F BE C3 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 83 E8 ?? 0F 85 ?? ?? ?? + ?? FF 75 ?? 8D 45 ?? 57 56 50 E8 ?? ?? ?? ?? EB ?? FF 75 ?? 8D 45 ?? 57 56 50 E8 ?? + ?? ?? ?? EB ?? FF 75 ?? 8D 45 ?? 57 56 50 E8 ?? ?? ?? ?? EB ?? 8B 4C 01 ?? 8D 7D ?? + 33 C0 AB 6A ?? AB AB 8D 45 ?? 50 FF 75 ?? FF 75 ?? 51 FF 15 ?? ?? ?? ?? 85 C0 75 ?? + FF 15 ?? ?? ?? ?? 89 45 ?? 8D 75 ?? 8D 7D ?? A5 A5 A5 8B 45 ?? 85 C0 75 ?? 8B 45 ?? + 85 C0 74 ?? 6A ?? 5E 3B C6 75 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 + 30 E9 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 E9 ?? ?? ?? ?? 8B 7D ?? 8B 45 ?? 8B 4D ?? 8B + 04 85 ?? ?? ?? ?? F6 44 08 ?? ?? 74 ?? 80 3F ?? 74 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 20 ?? E9 ?? ?? ?? ?? 2B 45 ?? EB ?? 33 C0 5F 5E 5B C9 C3 } condition: - uint16(0)==0x5A4D and ( all of ($enum_drives_p*)) and ( all of ($find_files_p*)) and ($encrypt_files) + uint16(0)==0x5A4D and ($inject_code_into_process) and ( all of ($find_files_p*)) and ($encrypt_files) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Redeemer : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_DMR : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Redeemer ransomware." + description = "Yara rule that detects DMR ransomware." author = "ReversingLabs" - id = "080ab595-862b-5dc2-aaff-a0efd819a9fa" - date = "2022-01-17" - modified = "2022-01-17" + id = "45d8f91f-d2d0-5c6e-a29e-b8c9c29dc296" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Redeemer.yara#L1-L105" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "28287f6620a2f7a90057d1f97947e065721119e26398fe659331dc5fe99761de" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.DMR.yara#L1-L214" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "55e19f3017c2cc8355c27f9a516e611b58b108f15bfed41b88d5662b55677a59" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -27070,96 +28593,202 @@ rule REVERSINGLABS_Win32_Ransomware_Redeemer : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Redeemer" + tc_detection_name = "DMR" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? - 8B BD ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C6 ?? 89 B5 ?? ?? - ?? ?? 89 B5 ?? ?? ?? ?? 3B F7 0F 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? 8B 3D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 89 A5 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC ?? - C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 84 C0 0F 85 ?? ?? ?? ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 89 A5 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? ?? ?? ?? C6 45 - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 75 ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 89 A5 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? ?? - ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 75 ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B - CC 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 + $find_files_p1 = { + 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 4D ?? 8B 55 ?? 53 + 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 74 ?? + 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 ?? ?? ?? ?? 8A 01 88 85 ?? ?? ?? + ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? + ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 8A C3 75 ?? B0 ?? 2B + CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D ?? ?? ?? ?? 56 1B C0 89 9D ?? ?? ?? ?? + 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? F7 D8 + 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 + ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? + ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 ?? 8A 48 ?? 84 C9 74 + } + $find_files_p2 = { + 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? + ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? + ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? + 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 8B D8 56 FF 15 ?? ?? ?? + ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B C3 8B 4D ?? + 5F 33 CD 5B E8 ?? ?? ?? ?? C9 C3 } $encrypt_files_p1 = { - 80 FB ?? 0F 85 ?? ?? ?? ?? 83 EC ?? 8D 55 ?? 8B CC 89 A5 ?? ?? ?? ?? 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? - C7 41 ?? ?? ?? ?? ?? 83 79 ?? ?? C7 41 ?? ?? ?? ?? ?? 72 ?? 8B 01 EB ?? 8B C1 33 D2 - 6A ?? 66 89 10 8D 45 ?? 52 50 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 8B CC C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 83 - 79 ?? ?? C7 41 ?? ?? ?? ?? ?? 72 ?? 8B 01 EB ?? 8B C1 33 D2 6A ?? 66 89 10 8D 45 ?? - 52 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 8D 45 ?? 3B C6 - 74 ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 33 C0 C7 45 ?? - ?? ?? ?? ?? 56 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? C6 45 + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 89 B5 ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? 8D 45 ?? 83 7D ?? ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8D 55 ?? FF B5 ?? ?? ?? + ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? + 8B 55 ?? 88 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA + ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 + E8 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 83 C4 ?? 84 C0 0F 84 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? + ?? 8D 55 ?? FF B5 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 45 ?? + 83 7D ?? ?? 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 83 E0 ?? 8D 4D ?? 83 7D ?? ?? 50 0F 43 } $encrypt_files_p2 = { - 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 35 ?? ?? ?? ?? 33 C0 83 7D ?? ?? 66 89 85 ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? - 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF D6 85 C0 0F 85 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 72 ?? 8B 00 50 FF D6 8B 85 ?? ?? ?? - ?? 83 F8 ?? 72 ?? 40 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? E9 ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 C7 45 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 45 ?? 83 C4 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 33 - C0 C7 45 ?? ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? 8D - 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E - 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 E8 + 4D ?? 51 FF 15 ?? ?? ?? ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 8D 8D + ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? + ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D BE ?? + ?? ?? ?? C6 45 ?? ?? 83 7F ?? ?? 8B C7 89 BD ?? ?? ?? ?? 72 ?? 8B 07 83 7F ?? ?? 75 + ?? 0F B6 00 3C ?? 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 75 ?? C7 86 ?? ?? ?? ?? ?? + ?? ?? ?? B8 ?? ?? ?? ?? EB ?? 8B 86 ?? ?? ?? ?? 6A ?? 50 8D 4D ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 8B 86 ?? ?? + ?? ?? 83 7D ?? ?? 99 0F 43 4D ?? 52 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? + ?? ?? ?? 8B 55 ?? 3B CA 77 ?? 83 7D ?? ?? 8D 45 ?? 89 4D ?? 0F 43 45 ?? C6 04 01 ?? + EB ?? 8B 45 ?? 8B F9 2B FA 2B C2 3B F8 77 ?? 83 7D ?? ?? 8D 75 ?? 57 0F 43 75 ?? 03 } - $modify_processes_p1 = { - 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 + $encrypt_files_p3 = { + F2 89 4D ?? 6A ?? 56 E8 ?? ?? ?? ?? C6 04 3E ?? 83 C4 ?? 8B B5 ?? ?? ?? ?? EB ?? 6A + ?? 57 C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 8B BD ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? 6A ?? 8B 40 ?? 03 C8 33 C0 39 41 ?? 0F 94 C0 8D 04 85 ?? ?? ?? ?? 0B 41 ?? 50 E8 + ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? + 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 50 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 89 8D ?? ?? ?? ?? 8B 01 FF 50 ?? 8D + 85 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? C6 45 ?? ?? 8B 8D ?? ?? ?? ?? 85 C9 74 ?? 8B 01 8B 40 ?? FF D0 85 C0 74 ?? 8B + 08 6A ?? 8B 11 8B C8 FF D2 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 33 D2 8B 40 ?? 03 C8 + B8 ?? ?? ?? ?? 39 51 ?? 0F 45 C2 EB ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? + 03 C8 33 C0 39 41 ?? 0F 94 C0 8D 04 85 ?? ?? ?? ?? 0B 41 ?? 6A ?? 50 E8 ?? ?? ?? ?? + 81 C6 ?? ?? ?? ?? 8D 45 ?? 3B F0 74 ?? 83 7D ?? ?? 8B CE FF 75 ?? 0F 43 45 ?? 50 E8 + ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 } - $modify_processes_p2 = { - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 99 B9 ?? ?? ?? ?? F7 F9 6A ?? 8D 8D ?? ?? ?? ?? 6A ?? 8D 04 52 8D 04 C1 - 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 0F - 43 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D B5 - ?? ?? ?? ?? 0F 43 95 ?? ?? ?? ?? 0F 43 B5 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 83 C8 ?? - 50 56 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 B9 ?? ?? ?? ?? F7 F9 6A ?? 8D 8D ?? ?? ?? - ?? 6A ?? 8D 04 52 8D 04 C1 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 85 ?? ?? - ?? ?? 8B CC 89 A5 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC FF 37 E8 - ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? C6 45 ?? ?? 8D 85 ?? ?? - ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 8B 4D ?? 64 89 - 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 FF 77 + $encrypt_files_p4 = { + C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 7F ?? ?? 8B 47 ?? 72 ?? 8B 3F 83 F8 ?? 75 + ?? 0F B6 07 3C ?? 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 8B BD ?? ?? ?? ?? 85 C0 75 ?? 8D + 45 ?? 50 83 EC ?? 8D 87 ?? ?? ?? ?? 8B CC 89 A5 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC + ?? C6 45 ?? ?? 8B CC 56 E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? EB ?? 8B BD ?? ?? + ?? ?? 8D 45 ?? 3B F0 74 ?? 83 7D ?? ?? 8B CE FF 75 ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? + 8D 45 ?? 3B C6 74 ?? 83 7E ?? ?? 8B C6 72 ?? 8B 06 FF 76 ?? 8D 4D ?? 50 E8 ?? ?? ?? + ?? 6A ?? 68 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 83 7E ?? ?? 8B C6 72 ?? 8B 06 C7 46 ?? + ?? ?? ?? ?? 8D 55 ?? C6 00 ?? 8D 8D ?? ?? ?? ?? 83 7D ?? ?? FF 75 ?? 0F 43 55 ?? E8 + ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? 6A ?? 8B 40 ?? 03 C8 33 C0 39 41 ?? 0F 94 C0 8D 04 85 ?? ?? ?? ?? + 0B 41 ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 8B F0 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D + 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 8B C8 C6 + 45 ?? ?? 8B 41 ?? 8B 51 ?? 2B C2 83 F8 ?? 72 ?? 83 79 ?? ?? 8D 42 ?? 89 41 ?? 8B C1 + 72 ?? 8B 01 66 C7 04 02 ?? ?? EB ?? 6A ?? 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? FF B5 + ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B C8 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? 0F 10 01 0F 11 85 ?? ?? ?? ?? F3 0F 7E 41 ?? 66 0F D6 85 ?? ?? ?? ?? + C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C6 01 ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 8B + } + $encrypt_files_p5 = { + C2 8B 8D ?? ?? ?? ?? 2B C1 83 F8 ?? 72 ?? 8D 41 ?? 83 FA ?? 89 85 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? C7 04 01 ?? ?? ?? ?? C6 44 01 ?? ?? 8D 85 ?? ?? ?? + ?? EB ?? 6A ?? 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? FF B5 ?? ?? ?? + ?? 6A ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + 0F 10 00 0F 11 85 ?? ?? ?? ?? F3 0F 7E 40 ?? 66 0F D6 85 ?? ?? ?? ?? C7 40 ?? ?? ?? + ?? ?? C7 40 ?? ?? ?? ?? ?? C6 00 ?? 8D 47 ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 10 00 0F 11 + 85 ?? ?? ?? ?? F3 0F 7E 40 ?? 66 0F D6 85 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? + ?? ?? ?? ?? C6 00 ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 8B C2 8B 8D ?? ?? ?? ?? 2B C1 83 + F8 ?? 72 ?? 8D 41 ?? 83 FA ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? + ?? 66 C7 04 08 ?? ?? 8D 85 ?? ?? ?? ?? EB ?? 6A ?? 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 10 00 0F 11 85 ?? ?? ?? ?? F3 0F 7E 40 ?? 66 + 0F D6 85 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C6 00 ?? C6 45 + } + $encrypt_files_p6 = { + 8B BD ?? ?? ?? ?? 8B C7 8B 8D ?? ?? ?? ?? 2B C1 8B 56 ?? 3B D0 76 ?? 8B 46 ?? 2B C2 + 3B C1 72 ?? 83 FF ?? 8D 85 ?? ?? ?? ?? 51 0F 43 85 ?? ?? ?? ?? 8B CE 50 6A ?? E8 ?? + ?? ?? ?? EB ?? 56 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 10 00 0F 11 85 ?? ?? ?? ?? F3 0F 7E 40 ?? 66 0F D6 85 + ?? ?? ?? ?? C6 00 ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? + ?? ?? ?? 8B C2 8B 8D ?? ?? ?? ?? 2B C1 6A ?? 68 ?? ?? ?? ?? 83 F8 ?? 72 ?? 83 FA ?? + 8D B5 ?? ?? ?? ?? 8D 41 ?? 0F 43 B5 ?? ?? ?? ?? 03 F1 89 85 ?? ?? ?? ?? 56 E8 ?? ?? + ?? ?? 83 C4 ?? C6 46 ?? ?? 8D 85 ?? ?? ?? ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? FF B5 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 0F 10 00 0F 11 45 ?? F3 0F 7E 40 ?? 66 + 0F D6 45 ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C6 00 ?? C6 45 ?? ?? 8B 95 ?? + ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? + 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 + ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? + 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? + ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? + ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 + } + $encrypt_files_p7 = { + FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 + 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? + ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 + ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? + 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? + 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? + 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? + 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B + } + $encrypt_files_p8 = { + 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? + ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 + ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? 66 89 85 ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? + ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 + ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? + 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 + ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 EC ?? 66 89 85 ?? ?? ?? ?? 8D 45 ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? 8B CC 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 + C6 45 ?? ?? 83 7E ?? ?? 72 ?? 8B 36 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 72 ?? 8B 00 56 50 E8 ?? ?? + ?? ?? 8B 95 ?? ?? ?? ?? 83 C4 ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? + ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? + ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? + ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 + } + $encrypt_files_p9 = { + 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? + 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 + F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D + ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 + ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 + ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? + 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? + ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 + ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? + 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? + 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 + ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 + 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? + 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($modify_processes_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Cring : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win64_Ransomware_Vovalex : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Cring ransomware." + description = "Yara rule that detects Vovalex ransomware." author = "ReversingLabs" - id = "76530a6d-145b-5316-8200-4b191d0754fd" - date = "2021-08-12" - modified = "2021-08-12" + id = "dd4d7969-1afc-5e5d-9324-89f432523173" + date = "2021-03-12" + modified = "2021-03-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Cring.yara#L1-L66" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "05cf60ad39c9dcc592345f13b63c99b153b9253297a8ad9e52e0439081d8c796" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Vovalex.yara#L1-L81" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0c0f065224988bcba45b5aba2dceb080479b0bab235d544daabc3cae72e48318" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -27167,62 +28796,77 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Cring : TC_DETECTION MALICIOUS MALWA sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Cring" + tc_detection_name = "Vovalex" tc_detection_factor = 5 importance = 25 strings: + $encrypt_files = { + 48 8D 95 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B BD ?? ?? ?? ?? + 48 89 BD ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 + 89 85 ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 + 8B 9D ?? ?? ?? ?? 48 8B 53 ?? 48 8B 03 48 89 85 ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 + 8D 8D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 83 F8 ?? 75 ?? 48 8B B5 ?? + ?? ?? ?? 48 8B 56 ?? 48 8B 06 48 89 85 ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 8D 95 ?? + ?? ?? ?? 8B 8D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 8B 9D ?? ?? ?? + ?? 48 8B 53 ?? 48 8B 03 48 89 85 ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? + ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 48 83 + EC ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 9D ?? ?? ?? ?? 48 89 9D ?? ?? + ?? ?? 48 8D B5 ?? ?? ?? ?? 56 48 89 85 ?? ?? ?? ?? 48 89 9D ?? ?? ?? ?? 48 8D 15 ?? + ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? + 48 89 8D ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 9D ?? ?? ?? ?? + 48 89 9D ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 0D + ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 85 ?? ?? ?? ?? 48 89 95 ?? + ?? ?? ?? 4C 8D 8D ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 1D ?? + ?? ?? ?? 48 89 9D ?? ?? ?? ?? 4C 8D 85 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 89 8D ?? + ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? + ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 + } $find_files_p1 = { - 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 06 07 9A 0C 08 6F ?? ?? ?? ?? 19 2E ?? 08 6F ?? ?? ?? ?? - 18 33 ?? 08 6F ?? ?? ?? ?? 2C ?? 08 6F ?? ?? ?? ?? 02 17 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 0D 2B ?? 09 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 2D ?? DE ?? 09 2C ?? 09 6F - ?? ?? ?? ?? DC 07 17 58 0B 07 06 8E 69 32 ?? 2A + 48 89 C6 48 8D 0D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 C1 48 83 + EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 06 48 89 56 ?? 48 8D 0D ?? ?? ?? ?? 48 83 EC + ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 C1 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 + 46 ?? 48 89 56 ?? 48 8D 0D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 + C1 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 46 ?? 48 89 56 ?? 48 8D 0D ?? ?? ?? + ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 C1 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 + C4 ?? 48 89 46 ?? 48 89 56 ?? 48 8D 0D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 + C4 ?? 48 89 C1 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 46 ?? 48 89 56 ?? 48 8D + 0D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 C1 48 83 EC ?? E8 ?? ?? + ?? ?? 48 83 C4 ?? 48 89 46 ?? 48 89 56 ?? 48 89 B5 ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 89 95 ?? ?? + ?? ?? BA ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 } $find_files_p2 = { - 02 7B ?? ?? ?? ?? 0B 07 45 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 16 0A DD ?? - ?? ?? ?? 02 15 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? - ?? ?? 14 0C 02 7B ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C DE ?? 26 DE ?? 08 2C - ?? 02 08 7D ?? ?? ?? ?? 02 16 7D ?? ?? ?? ?? 2B ?? 02 7B ?? ?? ?? ?? 02 7B ?? ?? ?? ?? - 9A 0D 02 09 7D ?? ?? ?? ?? 02 17 7D ?? ?? ?? ?? 17 0A DD ?? ?? ?? ?? 02 15 7D ?? ?? ?? - ?? 02 02 7B ?? ?? ?? ?? 17 58 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 8E 69 - 32 ?? 02 14 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 39 ?? ?? ?? ?? 14 0C 02 7B ?? ?? ?? ?? 28 - ?? ?? ?? ?? 0C DE ?? 26 DE ?? 08 39 ?? ?? ?? ?? 02 08 7D ?? ?? ?? ?? 02 16 7D ?? ?? ?? - ?? 38 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 9A 13 ?? 02 11 ?? 02 7B ?? ?? ?? - ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 1F ?? 7D ?? ?? ?? - ?? 2B ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 02 11 ?? 7D ?? ?? ?? ?? 02 18 7D ?? ?? - ?? ?? 17 0A DE ?? 02 1F ?? 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 02 28 - ?? ?? ?? ?? 02 14 7D ?? ?? ?? ?? 02 02 7B ?? ?? ?? ?? 17 58 7D ?? ?? ?? ?? 02 7B ?? ?? - ?? ?? 02 7B ?? ?? ?? ?? 8E 69 3F ?? ?? ?? ?? 02 14 7D ?? ?? ?? ?? 16 0A DE ?? 02 28 ?? - ?? ?? ?? DC 06 2A - } - $encrypt_files = { - 16 0A 73 ?? ?? ?? ?? 0B 07 6F ?? ?? ?? ?? 1E 5B 8D ?? ?? ?? ?? 0C 07 6F ?? ?? ?? ?? 1E - 5B 8D ?? ?? ?? ?? 0D 73 ?? ?? ?? ?? 13 ?? 11 ?? 08 6F ?? ?? ?? ?? 11 ?? 09 6F ?? ?? ?? - ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 08 8E 69 09 8E 69 58 8D ?? ?? ?? ?? 13 ?? - 08 11 ?? 08 8E 69 28 ?? ?? ?? ?? 09 16 11 ?? 08 8E 69 09 8E 69 28 ?? ?? ?? ?? 11 ?? 04 - 28 ?? ?? ?? ?? 13 ?? 11 ?? 8E 69 28 ?? ?? ?? ?? 13 ?? 07 08 09 6F ?? ?? ?? ?? 13 ?? 02 - 19 73 ?? ?? ?? ?? 13 ?? 03 18 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 17 73 ?? ?? ?? ?? 13 ?? - 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 11 - ?? 11 ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 11 ?? - 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 11 ?? 2C ?? 11 ?? 6F - ?? ?? ?? ?? DC 17 0A DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC 06 2A + 89 C3 48 8B 95 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 03 48 89 53 ?? 48 8D 15 ?? ?? + ?? ?? BF ?? ?? ?? ?? 48 89 7B ?? 48 89 53 ?? 48 8D 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 + 89 43 ?? 48 89 4B ?? 48 89 9D ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 45 31 C0 + 4C 89 85 ?? ?? ?? ?? 4C 8D A5 ?? ?? ?? ?? 49 C7 04 24 ?? ?? ?? ?? 49 8B 14 24 48 89 + 95 ?? ?? ?? ?? 4C 89 85 ?? ?? ?? ?? 4C 8D AD ?? ?? ?? ?? 49 B9 ?? ?? ?? ?? ?? ?? ?? + ?? 4D 89 4D ?? 49 8B 4D ?? 48 89 8D ?? ?? ?? ?? 4C 89 85 ?? ?? ?? ?? 4C 8D B5 ?? ?? + ?? ?? 4D 89 06 49 8B 16 48 8D 8D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? + 45 31 C0 41 3B C0 7E ?? 41 BF ?? ?? ?? ?? 4C 89 85 ?? ?? ?? ?? 4C 8D 8D ?? ?? ?? ?? + 4D 69 D7 ?? ?? ?? ?? 4D 89 11 4C 89 D2 48 8D 8D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? + ?? 48 83 C4 ?? 45 31 C0 41 3B C0 79 ?? 4C 89 85 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 + C7 01 ?? ?? ?? ?? 48 8B 01 48 89 85 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 8D 8D ?? ?? + ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 85 C0 7E ?? 48 8B 9D ?? ?? ?? ?? 48 B8 + ?? ?? ?? ?? ?? ?? ?? ?? 48 F7 EB } condition: uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Motocos : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Lechiffre : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Motocos ransomware." + description = "Yara rule that detects LeChiffre ransomware." author = "ReversingLabs" - id = "cda44b86-c747-5b48-acd8-e68311ab24a3" - date = "2021-09-17" - modified = "2021-09-17" + id = "5d2698fe-9a0b-549d-9a83-72e2ccfc1966" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Motocos.yara#L1-L75" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "34b99847f029a291808f08ba6e6ae62a54e6fed5acc928fe4828054801786881" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.LeChiffre.yara#L1-L123" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0b96f5f48700f2cba22da91187b3111946074e9cc58a502f25d7b96059a043cb" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -27230,68 +28874,122 @@ rule REVERSINGLABS_Win32_Ransomware_Motocos : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Motocos" + tc_detection_name = "LeChiffre" tc_detection_factor = 5 importance = 25 strings: - $generate_key = { - 55 8B EC 83 C4 ?? 53 89 4D ?? 89 55 ?? 8B D8 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? - ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 83 7D ?? ?? 74 ?? 8B 45 ?? 8B 15 - ?? ?? ?? ?? 8B 12 E8 ?? ?? ?? ?? 75 ?? B9 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 89 45 ?? 33 D2 55 68 ?? ?? - ?? ?? 64 FF 32 64 89 22 8B 4D ?? 8B 55 ?? 8B C3 E8 ?? ?? ?? ?? 89 45 ?? 33 D2 55 68 - ?? ?? ?? ?? 64 FF 32 64 89 22 8B 45 ?? 85 C0 74 ?? 83 E8 ?? 8B 00 8B D8 89 5D ?? 80 - 7D ?? ?? 75 ?? 8B 5D ?? 03 DB 53 8D 45 ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? 53 8D 45 ?? 50 8B 45 ?? 50 6A ?? 80 7D ?? ?? F5 1B C0 50 6A ?? 8B 45 - ?? 50 E8 ?? ?? ?? ?? 83 F8 ?? 1B C0 40 84 C0 75 ?? B9 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? - ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 50 8D 45 ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 8B 55 ?? 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 - 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? - 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? C3 E9 ?? ?? - ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? - 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5B 8B E5 5D C2 + $remote_connection_1 = { + 55 8B EC 33 C9 51 51 51 51 51 51 51 53 56 57 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF + 30 64 89 20 8B 45 ?? 33 D2 E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 + ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? + E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 50 ?? 8B 45 + ?? 8B 08 FF 51 ?? 8B 45 ?? 8B 10 FF 52 ?? 8B F0 4E 85 F6 7C ?? 46 33 DB 8D 4D ?? 8B + D3 8B 45 ?? 8B 38 FF 57 ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 7E ?? 8D 45 + ?? 50 8D 4D ?? 8B D3 8B 45 ?? 8B 38 FF 57 ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 E8 ?? 50 8D 4D ?? 8B D3 8B 45 ?? 8B 38 FF 57 ?? 8B 45 ?? BA ?? ?? ?? ?? 59 E8 ?? + ?? ?? ?? 43 4E 75 ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? + 8B 45 ?? E8 ?? ?? ?? ?? C3 } - $encrypt_files = { - 55 8B EC 83 C4 ?? 53 56 57 33 C9 89 4D ?? 89 4D ?? 89 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? - 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 C6 45 ?? ?? 33 D2 55 68 ?? ?? ?? ?? 64 FF - 32 64 89 22 B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B D8 8B C3 8B D8 F6 C3 ?? 74 ?? 66 83 E3 ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B C3 - E8 ?? ?? ?? ?? 8B D0 B1 ?? 8B 45 ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8B 4D ?? B2 ?? A1 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 D2 - 55 68 ?? ?? ?? ?? 64 FF 32 64 89 22 8B 45 ?? 8B 10 FF 12 8B C8 8B 55 ?? A1 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B C8 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 88 45 ?? 33 C0 5A 59 59 64 - 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? - ?? EB ?? 80 7D ?? ?? 75 ?? 8D 45 ?? 50 8B 45 ?? 89 45 ?? C6 45 ?? ?? B8 ?? ?? ?? ?? - 89 45 ?? C6 45 ?? ?? 8D 55 ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? - E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 F8 ?? 1B C0 40 88 45 - ?? 33 C0 5A 59 59 64 89 10 E9 ?? ?? ?? ?? E9 + $remote_connection_2 = { + 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 + C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8B 45 ?? 8B 80 ?? ?? ?? ?? 66 BE ?? ?? E8 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 + ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 55 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 4D ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C3 + } + $remote_connection_3 = { + E8 ?? ?? ?? ?? 8B 45 ?? 8B 80 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 E8 ?? ?? + ?? ?? DD 5D ?? 9B FF 75 ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? + ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? + 8B 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? FF + 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 4D + ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B + 45 ?? E8 ?? ?? ?? ?? C3 + } + $encrypt_files_1 = { + E8 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? + 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 + ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 55 ?? + 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? 83 7B ?? ?? 0F 84 ?? ?? ?? ?? 8B 13 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B + 03 E8 ?? ?? ?? ?? 84 C0 75 ?? 8B 03 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? FF 86 ?? ?? + ?? ?? B2 ?? 8B 86 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 8B 03 E8 ?? ?? ?? ?? FF 75 ?? + 68 ?? ?? ?? ?? 8B 43 ?? C1 E8 ?? 33 D2 52 50 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? + ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 86 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 03 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? C3 + } + $encrypt_files_2 = { + E8 ?? ?? ?? ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? 8B 12 8B 92 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? 8B 55 ?? E8 ?? ?? ?? ?? 3D ?? + ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? FF 70 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? + ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 8B 40 + ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? + ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 + FF 30 64 89 20 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 + 8B 90 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 + C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? + ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 + 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + A1 ?? ?? ?? ?? 8B 00 8B 90 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 8B 45 ?? E8 + ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 8B 45 + ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + C3 E9 ?? ?? ?? ?? EB ?? 8B E5 5D C3 } $find_files = { - 55 8B EC 83 C4 ?? 53 56 57 33 C9 89 4D ?? 8B FA 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 - FF 30 64 89 20 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 85 DB 7C ?? 8B 45 ?? 66 - 83 3C 58 ?? 75 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? E8 ?? ?? ?? ?? - 8B 75 ?? 85 F6 74 ?? 83 EE ?? 8B 36 8D 45 ?? 50 8D 53 ?? 8B CE 8B 45 ?? E8 ?? ?? ?? - ?? 8B C7 8B 55 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 - ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8B C7 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 - ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 59 59 5D C3 + E8 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B 55 ?? 8B C3 E8 ?? ?? ?? ?? + 84 C0 0F 85 ?? ?? ?? ?? 33 C0 89 43 ?? 8B 43 ?? E8 ?? ?? ?? ?? 8B F0 85 F6 7C ?? 46 + 33 FF 8B 43 ?? C7 04 B8 ?? ?? ?? ?? 47 4E 75 ?? 8B 43 ?? 8B 40 ?? E8 ?? ?? ?? ?? 8B + F0 85 F6 7C ?? 46 33 FF 8B 43 ?? 8B 40 ?? 8B 14 B8 8D 8D ?? ?? ?? ?? 8B 45 ?? E8 ?? + ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B 43 ?? 8B 53 ?? 89 14 B8 47 4E 75 + ?? 8B 73 ?? 4E 85 F6 7C ?? 46 33 FF 80 7B ?? ?? 0F 85 ?? ?? ?? ?? 8D 04 BF 8B 53 ?? + 8D 04 C2 89 43 ?? 89 45 ?? 8D 8D ?? ?? ?? ?? 8B 45 ?? 8B 10 8B 45 ?? E8 ?? ?? ?? ?? + 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B + 45 ?? 33 D2 E8 ?? ?? ?? ?? 47 4E 75 ?? 8B 43 ?? 8B 40 ?? 80 78 ?? ?? 0F 84 ?? ?? ?? + ?? 80 7B ?? ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? BA ?? ?? ?? + ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 89 45 + ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 F6 85 ?? + ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 + ?? ?? ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C3 + E8 ?? ?? ?? ?? 80 7B ?? ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? + ?? C3 E9 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($generate_key) and ($find_files) and ($encrypt_files) + uint16(0)==0x5A4D and $find_files and $encrypt_files_1 and $encrypt_files_2 and $remote_connection_1 and $remote_connection_2 and $remote_connection_3 } -rule REVERSINGLABS_Win32_Ransomware_Rokku : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Linux_Ransomware_Gwisinlocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Rokku ransomware." + description = "Yara rule that detects GwisinLocker ransomware." author = "ReversingLabs" - id = "8722ed4a-b480-57ec-bba7-ce7d0f3704b9" - date = "2020-07-15" - modified = "2020-07-15" + id = "9f00e1b4-3692-5824-b614-724073532c1f" + date = "2022-10-11" + modified = "2022-10-11" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Rokku.yara#L1-L147" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "fefb342f8a9afac3b40c343b830f334225ff4198d55504846aa855acf5dfc9ba" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Linux.Ransomware.GwisinLocker.yara#L1-L354" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "c23c0b73bbefbd644ffe1398e1f14eec3a89945cb3c3ccbc6f46c57046b53505" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -27299,454 +28997,308 @@ rule REVERSINGLABS_Win32_Ransomware_Rokku : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Rokku" + tc_detection_name = "GwisinLocker" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_p1 = { - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 55 8B E9 C7 44 24 ?? ?? ?? ?? ?? 33 DB 89 6C 24 ?? - 56 0F 57 C0 66 C7 44 24 ?? ?? ?? 57 66 0F 13 44 24 ?? B2 ?? 88 5C 24 ?? 8B CB 8A C1 - 02 C2 30 44 0C ?? 41 83 F9 ?? 73 ?? 8A 54 24 ?? EB ?? 8B CD 88 5C 24 ?? E8 ?? ?? ?? - ?? 8D 54 24 ?? 8B C8 E8 ?? ?? ?? ?? 85 C0 75 ?? 40 E9 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 51 BE ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B D6 E8 ?? ?? ?? ?? 59 56 BE - ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8D 4C 24 ?? 6A - ?? 8B D5 E8 ?? ?? ?? ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 8B C1 8B 94 24 ?? ?? ?? ?? 0B C2 0F 84 ?? - ?? ?? ?? 6A ?? 5D 3B D3 77 ?? 81 F9 ?? ?? ?? ?? 76 ?? 2B CD 1B D3 52 51 55 8D 4C 24 - ?? E8 ?? ?? ?? ?? 83 C4 ?? 3B C5 0F 85 ?? ?? ?? ?? 8B CD 8B C3 8A 90 ?? ?? ?? ?? 49 - 8A B0 ?? ?? ?? ?? 3A D6 75 ?? 40 85 C9 75 ?? 8B CB EB ?? 0F B6 C6 0F B6 CA 2B C8 85 - C9 0F 84 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 8B D6 50 B9 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 88 19 41 83 E8 ?? 75 ?? - 8B 6C 24 ?? 8B 7C 24 ?? 8B 84 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 2B C7 1B CD 3B EB + $init_key_v1 = { + 55 57 56 53 E8 ?? ?? ?? ?? 81 C3 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 8D 74 24 ?? 56 E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 31 FF 83 EC ?? 56 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 89 + F8 5B 5E 5F 5D C3 66 90 31 D2 31 C0 89 54 04 ?? 83 C0 ?? 83 F8 ?? 72 ?? 83 EC ?? 8D + 83 ?? ?? ?? ?? 50 8D 83 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 C5 8D 7C 24 ?? 85 + C0 74 ?? 50 6A ?? 6A ?? 57 E8 ?? ?? ?? ?? 89 2C 24 E8 ?? ?? ?? ?? 83 C4 ?? 83 EC ?? + 6A ?? 57 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? C7 04 24 ?? ?? ?? ?? 83 EC ?? 8D 44 + 24 ?? 50 FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 6A ?? FF B3 + ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 56 FF B3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 + 0F 94 C0 0F B6 C0 89 C7 E9 } - $encrypt_files_p2 = { - 7C ?? 7F ?? 81 FF ?? ?? ?? ?? 72 ?? 8B AC 24 ?? ?? ?? ?? 0F 57 C0 8B BC 24 ?? ?? ?? - ?? 8B 4C 24 ?? 55 57 66 0F 13 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 59 59 8B 4C 24 ?? - 3B CB 77 ?? 3B C3 77 ?? 8B F3 EB ?? 3B CB 77 ?? 72 ?? 3D ?? ?? ?? ?? 72 ?? B8 ?? ?? - ?? ?? 55 57 50 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 85 F6 0F 88 ?? ?? ?? ?? 74 - ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 56 50 8B D0 E8 ?? ?? ?? ?? 55 57 56 BA ?? ?? ?? ?? - 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 88 ?? ?? ?? ?? 99 03 F8 13 EA E9 ?? ?? - ?? ?? 6A ?? 58 89 1D ?? ?? ?? ?? 83 E8 ?? 75 ?? 8B C7 89 1D ?? ?? ?? ?? 0B C5 BE ?? - ?? ?? ?? 74 ?? 51 8D 54 24 ?? E8 ?? ?? ?? ?? 59 B9 ?? ?? ?? ?? 3B F1 74 ?? 56 51 BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 55 57 BD ?? ?? ?? ?? 8B D1 55 8D 4C 24 ?? E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 0F 88 ?? ?? ?? ?? EB ?? BD ?? ?? ?? ?? 6A ?? 59 8B C1 BA ?? - ?? ?? ?? C6 02 ?? 42 83 E8 ?? 75 ?? B8 ?? ?? ?? ?? C6 00 ?? 40 83 E9 ?? 75 ?? 6A ?? - 58 B9 ?? ?? ?? ?? C6 01 ?? 41 83 E8 ?? 75 ?? C6 06 ?? 46 83 ED ?? 75 ?? 6A ?? 8D 44 - 24 ?? 59 C6 00 ?? 40 83 E9 ?? 75 ?? B1 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? 8B C3 30 4C 04 ?? 40 83 F8 ?? 73 ?? 8A 4C 24 ?? EB ?? 8B 4C 24 ?? 8D 54 24 ?? - 88 5C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? 8B F0 E8 ?? ?? ?? ?? 8B 4C 24 ?? 8B D6 E8 ?? - ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 33 DB 43 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B C3 EB ?? 8D 4C - 24 ?? E8 ?? ?? ?? ?? 33 C0 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 + $encrypt_files_v1_p1 = { + 55 B9 ?? ?? ?? ?? 57 56 53 E8 ?? ?? ?? ?? 81 C3 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 8B 84 + 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 8D 44 24 ?? 83 EC ?? 89 44 24 ?? 89 + C7 31 C0 F3 AB C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? 6A ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 84 24 ?? ?? ?? ?? 89 44 + 24 ?? 8D 84 24 ?? ?? ?? ?? 89 44 24 ?? 31 FF 83 EC ?? 68 ?? ?? ?? ?? FF 74 24 ?? E8 + ?? ?? ?? ?? 58 5A 6A ?? FF 74 24 ?? E8 ?? ?? ?? ?? 59 5E 6A ?? FF 74 24 ?? E8 ?? ?? + ?? ?? 81 C4 ?? ?? ?? ?? 89 F8 5B 5E 5F 5D C3 8D 74 26 ?? 90 83 EC ?? 6A ?? 8D 84 24 + ?? ?? ?? ?? 89 44 24 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D B4 24 ?? ?? ?? ?? 89 74 24 ?? + 85 C0 74 ?? 83 EC ?? 6A ?? FF 74 24 ?? 56 E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? 59 5E 50 + 89 C5 FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? 89 C6 83 C4 ?? 85 C0 0F 84 ?? + ?? ?? ?? 83 EC ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 89 C7 FF B4 24 ?? + ?? ?? ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 94 24 ?? ?? ?? ?? 01 FA 89 D0 8B 54 + 24 ?? 89 10 0F B7 54 24 ?? 66 89 50 ?? 0F B6 54 24 ?? 88 50 ?? 8B 94 24 ?? ?? ?? ?? + C6 44 3A ?? ?? BF ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? + ?? ?? ?? B9 ?? ?? ?? ?? 83 C4 ?? 39 C1 B9 ?? ?? ?? ?? 19 D1 7D ?? 83 EC ?? FF B4 24 + ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 83 EC ?? FF 74 + 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8D 74 26 ?? 90 83 EC ?? 56 E8 ?? ?? ?? + ?? 58 5A 55 FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? 89 C6 83 C4 ?? 85 C0 0F } - $encrypt_files_p3 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 55 56 57 6A ?? 5E 56 BF ?? ?? ?? ?? 57 FF 15 - ?? ?? ?? ?? 51 BB ?? ?? ?? ?? BD ?? ?? ?? ?? 8B D3 8B CD E8 ?? ?? ?? ?? 59 56 57 FF - 15 ?? ?? ?? ?? 51 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B C6 C6 07 ?? 47 - 83 E8 ?? 75 ?? BF ?? ?? ?? ?? BA ?? ?? ?? ?? 53 8B CF E8 ?? ?? ?? ?? 59 6A ?? 58 C6 - 03 ?? 43 83 E8 ?? 75 ?? B9 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 3B E9 74 ?? 55 51 8B D6 - E8 ?? ?? ?? ?? 83 C4 ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 3B C1 74 ?? 50 51 8B D6 E8 ?? - ?? ?? ?? 83 C4 ?? 6A ?? 5B 53 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8D 44 24 ?? B9 ?? ?? - ?? ?? 50 51 8B D3 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 83 C4 ?? 3B C8 74 ?? - 51 50 6A ?? 5A 8B C8 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 3B C1 74 - ?? 50 51 8B D6 E8 ?? ?? ?? ?? 83 C4 ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 3B C1 74 ?? 50 - 51 6A ?? 5A E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 6A ?? 5B 3B C1 74 - ?? 50 51 8B D3 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 3B C1 74 ?? 50 - 51 6A ?? 5A E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 8B D7 50 8D 4C 24 ?? E8 ?? ?? ?? ?? - 59 BA ?? ?? ?? ?? 8D 4C 24 ?? 6A ?? 52 E8 ?? ?? ?? ?? 59 59 83 64 24 ?? ?? 83 EB ?? - 75 ?? 21 9C 24 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 59 C6 00 ?? 40 83 E9 ?? 75 ?? 8B C6 C6 - 45 ?? ?? 45 83 E8 ?? 75 ?? C6 07 ?? 47 83 EE ?? 75 ?? 33 C0 5F 40 5E 5D 5B 8B E5 5D - C3 + $encrypt_files_v1_p2 = { + 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 8B 74 24 + ?? 8B 7C 24 ?? 89 D1 89 74 24 ?? 89 7C 24 ?? 83 C4 ?? 39 F0 19 F9 7D ?? 89 44 24 ?? + 89 54 24 ?? 8B 7C 24 ?? 8B 74 24 ?? 89 F9 89 F5 C1 F9 ?? 89 C8 89 4C 24 ?? 31 CD 8B + 74 24 ?? C1 F8 ?? 89 44 24 ?? 89 E8 29 F0 8B 74 24 ?? 89 C7 83 E7 ?? 31 CF 89 F8 8B + 7C 24 ?? 29 F0 8B 74 24 ?? 89 FA 19 FA 8B 7C 24 ?? 29 C6 89 74 24 ?? 19 D7 83 EC ?? + 89 7C 24 ?? 8D 44 24 ?? 50 E8 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? + B9 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 31 C0 F3 AB 89 94 24 ?? ?? ?? ?? 56 6A ?? FF 74 + 24 ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 C7 85 C0 0F 84 ?? ?? ?? ?? 83 + EC ?? FF 74 24 ?? E8 ?? ?? ?? ?? 5F 5D FF B4 24 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 + ?? 89 C7 85 C0 0F 84 ?? ?? ?? ?? 8B B4 24 ?? ?? ?? ?? 8B 54 24 ?? 31 FF 8B 44 24 ?? + 89 7C 24 ?? 89 74 24 ?? 8D 74 24 ?? 89 D7 89 74 24 ?? 8D B3 ?? ?? ?? ?? 09 C7 89 74 } - $find_files_p1 = { - 55 8B EC 83 EC ?? 53 56 6A ?? 59 E8 ?? ?? ?? ?? 8B F0 66 C7 45 ?? ?? ?? 33 DB 89 35 - ?? ?? ?? ?? B1 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B C3 C7 45 ?? ?? ?? ?? - ?? 66 C7 45 ?? ?? ?? 02 C8 30 4C 05 ?? 40 83 F8 ?? 73 ?? 8A 4D ?? EB ?? 8D 45 ?? 88 - 5D ?? 50 8D 55 ?? 8B CE E8 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? B0 ?? 59 B1 ?? 88 5D ?? - 32 C1 88 4D ?? 88 45 ?? 8B CB 0F 11 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - 66 C7 45 ?? ?? ?? 88 5D ?? 8A 45 ?? 30 44 0D ?? 41 83 F9 ?? 72 ?? 8B 0D ?? ?? ?? ?? - 8D 45 ?? 50 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 B1 ?? 88 5D ?? B0 ?? 88 4D ?? 32 C1 - C7 45 ?? ?? ?? ?? ?? 88 45 ?? 8B C3 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 80 44 - 05 ?? ?? 40 83 F8 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? E8 ?? ?? ?? ?? 59 - 6A ?? 33 C9 C7 45 ?? ?? ?? ?? ?? 5B B0 ?? 88 5D ?? 32 C3 88 4D ?? 88 45 ?? 8B C1 C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 88 4D ?? 80 44 05 ?? ?? 40 83 F8 ?? 72 ?? 8B - 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? E8 ?? ?? ?? ?? 59 6A ?? 88 5D ?? B2 ?? 66 C7 45 - ?? ?? ?? 33 C9 66 C7 45 ?? ?? ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 5B 8D - 04 0A 30 44 0D ?? 41 3B CB 73 ?? 8A 55 ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 - ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 59 6A ?? 33 C9 C6 45 ?? ?? 58 34 ?? 88 4D ?? 88 45 + $encrypt_files_v1_p3 = { + 24 ?? 0F 84 ?? ?? ?? ?? 8B 4C 24 ?? 8B 6C 24 ?? 89 4C 24 ?? EB ?? 66 90 83 EC ?? 31 + ED FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF 74 24 ?? FF 74 + 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 31 D2 6A ?? 8B 84 24 ?? ?? ?? ?? 52 F7 D8 + 50 57 E8 ?? ?? ?? ?? 57 FF B4 24 ?? ?? ?? ?? 6A ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 44 24 ?? 8B BC 24 ?? ?? ?? ?? 8B 54 24 ?? 29 F8 19 EA 89 44 24 ?? 89 D6 89 54 + 24 ?? 83 C4 ?? 09 C6 74 ?? 39 84 24 ?? ?? ?? ?? 89 E9 8B 7C 24 ?? 19 D1 0F 4C 84 24 + ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? ?? + ?? 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 57 + FF B4 24 ?? ?? ?? ?? 6A ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 39 84 24 ?? + ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 EC ?? BF ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 + ?? E9 ?? ?? ?? ?? 83 EC ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? E9 } - $find_files_p2 = { - B2 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 8D 04 0A 30 44 0D - ?? 41 83 F9 ?? 73 ?? 8A 55 ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? C6 45 ?? - ?? E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 80 F3 ?? C6 45 ?? ?? 88 5D ?? 8D 55 ?? - 33 DB C6 45 ?? ?? 50 88 5D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 59 59 6A ?? 58 34 ?? C6 45 ?? ?? 88 45 ?? B2 ?? 88 5D ?? 8B CB C7 45 ?? ?? ?? ?? - ?? 66 C7 45 ?? ?? ?? 88 5D ?? 8D 04 0A 30 44 0D ?? 41 83 F9 ?? 73 ?? 8A 55 ?? EB ?? - 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 66 C7 45 ?? ?? ?? - 8B C3 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 80 44 05 ?? ?? - 40 83 F8 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? E8 ?? ?? ?? ?? B0 ?? C6 45 - ?? ?? 34 ?? 88 5D ?? 59 88 45 ?? B1 ?? C7 45 ?? ?? ?? ?? ?? 8B C3 C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 88 5D ?? 30 4C 05 ?? 40 83 F8 ?? 73 ?? 8A - 4D ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 0F 28 05 - ?? ?? ?? ?? 59 66 C7 45 ?? ?? ?? 8B CB 0F 11 45 ?? C7 45 ?? ?? ?? ?? ?? 88 5D ?? 8A - 45 ?? 30 44 0D ?? 41 83 F9 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? 88 5D ?? - E8 ?? ?? ?? ?? 59 5E 5B 8B E5 5D C3 + $find_files_v1_p1 = { + 55 89 C5 57 E8 ?? ?? ?? ?? 81 C7 ?? ?? ?? ?? 56 53 81 EC ?? ?? ?? ?? 89 54 24 ?? 8B + B4 24 ?? ?? ?? ?? 89 7C 24 ?? 89 FB 89 4C 24 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 44 24 + ?? C7 44 24 ?? ?? ?? ?? ?? 85 C0 74 ?? 8D 58 ?? 80 7C 05 ?? ?? 0F 45 D8 89 5C 24 ?? + 8B BC 24 ?? ?? ?? ?? 83 E7 ?? 74 ?? 83 EC ?? 8D 44 24 ?? 89 44 24 ?? 50 55 6A ?? 8B + 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 5C 24 ?? E8 ?? ?? ?? ?? 8B 00 83 F8 + ?? 0F 85 ?? ?? ?? ?? BF ?? ?? ?? ?? C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 8D + B4 26 ?? ?? ?? ?? 66 90 83 EC ?? 8D 44 24 ?? 89 44 24 ?? 50 55 6A ?? 8B 5C 24 ?? E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 78 ?? 8B 84 24 ?? ?? ?? ?? 25 ?? ?? ?? ?? 3D ?? ?? ?? ?? + 0F 84 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? C6 44 24 ?? ?? 31 FF C7 44 24 ?? + ?? ?? ?? ?? 8B 54 24 ?? 8B 44 24 ?? F6 84 24 ?? ?? ?? ?? ?? 74 ?? 85 F6 0F 84 ?? ?? + ?? ?? 8B 4E ?? 8B 5E ?? 31 D1 31 C3 09 CB 0F 84 ?? ?? ?? ?? 31 FF 81 C4 ?? ?? ?? ?? + 89 F8 5B 5E 5F 5D C3 8D 74 26 ?? 90 8B 5C 24 ?? E8 ?? ?? ?? ?? 89 C7 8B 00 83 F8 ?? + 0F 85 ?? ?? ?? ?? 83 EC ?? FF 74 24 ?? 55 6A ?? 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? + 85 C0 0F 85 ?? ?? ?? ?? BF ?? ?? ?? ?? C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? E9 ?? + ?? ?? ?? 8D 74 26 ?? 90 89 54 24 ?? 8B 94 24 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? + ?? ?? 89 74 24 ?? 89 44 24 ?? 89 54 24 ?? 85 F6 0F 84 ?? ?? ?? ?? 8B 46 ?? 8B 4C 24 + ?? 83 C0 ?? 83 C1 ?? 89 44 24 ?? 89 44 24 ?? 8B 46 ?? 89 4C 24 ?? 89 4C 24 ?? 89 44 } - $find_folders = { - 55 8B EC 83 EC ?? 53 56 6A ?? 59 E8 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? 33 DB 8B F0 66 - C7 45 ?? ?? ?? 89 35 ?? ?? ?? ?? 8B CB 0F 11 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 66 C7 45 ?? ?? ?? 88 5D ?? 8A 45 ?? 30 44 0D ?? 41 83 F9 ?? 72 ?? 8D 45 ?? - 88 5D ?? 50 8D 55 ?? 8B CE E8 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? B0 ?? 59 B1 ?? 88 5D - ?? 32 C1 88 4D ?? 88 45 ?? 8B CB 0F 11 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? 66 C7 45 ?? ?? ?? 8A 45 ?? 30 44 0D ?? 41 83 F9 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 - ?? 50 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 B1 ?? 88 5D ?? B0 ?? 88 4D ?? 32 C1 C7 45 - ?? ?? ?? ?? ?? 88 45 ?? B2 ?? C7 45 ?? ?? ?? ?? ?? 8B CB 66 C7 45 ?? ?? ?? 88 5D ?? - 8D 04 0A 30 44 0D ?? 41 83 F9 ?? 73 ?? 8A 55 ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 - 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 B1 ?? 88 5D ?? B0 ?? 88 4D ?? 32 C1 C7 45 ?? ?? - ?? ?? ?? 88 45 ?? 8B C3 C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 88 5D ?? 80 44 05 ?? - ?? 40 83 F8 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? E8 ?? ?? ?? ?? 59 66 C7 - 45 ?? ?? ?? 8B C3 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 80 44 - 05 ?? ?? 40 83 F8 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? E8 ?? ?? ?? ?? 59 - 66 C7 45 ?? ?? ?? B1 ?? C7 45 ?? ?? ?? ?? ?? 8B C3 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 66 C7 45 ?? ?? ?? 30 4C 05 ?? 40 83 F8 ?? 73 ?? 8A 4D ?? EB ?? 8B 0D ?? ?? - ?? ?? 8D 45 ?? 50 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 66 C7 45 ?? ?? ?? B2 ?? C7 45 - ?? ?? ?? ?? ?? 8B CB C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 8D - 04 0A 30 44 0D ?? 41 83 F9 ?? 73 ?? 8A 55 ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D - 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 5E 5B 8B E5 5D C3 + $find_files_v1_p2 = { + 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 83 FF ?? 0F 84 ?? ?? ?? ?? 8B + 84 24 ?? ?? ?? ?? 83 E0 ?? 89 44 24 ?? 75 ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 74 24 ?? + 55 8B 44 24 ?? FF D0 89 C7 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 85 F6 74 ?? 8B 84 24 ?? + ?? ?? ?? 8B 5C 24 ?? 89 6C 24 ?? 8B 4C 24 ?? 8B BC 24 ?? ?? ?? ?? 89 C5 EB ?? 8D B6 + ?? ?? ?? ?? 8B 36 85 F6 74 ?? 8B 46 ?? 8B 56 ?? 31 D8 31 CA 09 C2 75 ?? 8B 46 ?? 8B + 56 ?? 31 E8 31 FA 09 C2 0F 84 ?? ?? ?? ?? 8B 36 85 F6 75 ?? 8B 6C 24 ?? 8B 7C 24 ?? + 85 FF 74 ?? 80 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? 8B 44 24 ?? C6 44 05 ?? ?? 8B 44 24 ?? + 85 C0 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 74 24 ?? 55 8B 44 24 ?? FF D0 + 83 C4 ?? 89 C7 81 C4 ?? ?? ?? ?? 89 F8 5B 5E 5F 5D C3 66 90 83 EC ?? 6A ?? 55 8B 5C + 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 89 44 24 ?? 89 C7 E8 ?? ?? ?? ?? 8B 00 89 44 24 ?? + 83 C4 ?? 85 FF 79 ?? 83 F8 ?? 0F B6 4C 24 ?? BA ?? ?? ?? ?? 0F 94 C0 84 C0 B8 ?? ?? + ?? ?? 0F 44 44 24 ?? 0F 45 CA 89 44 24 ?? 88 4C 24 ?? 8B 44 24 ?? 85 C0 0F 85 ?? ?? + ?? ?? 83 EC ?? FF 74 24 ?? 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8D B4 + 26 ?? ?? ?? ?? 8D 76 ?? 89 54 24 ?? 8B 94 24 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 89 54 24 ?? 8B 44 24 ?? C7 44 24 ?? ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 48 ?? 89 4C 24 ?? 89 4C 24 ?? 85 C0 74 ?? 80 7C 05 + ?? ?? 74 ?? E9 ?? ?? ?? ?? 8D 76 ?? 80 7C 05 ?? ?? 0F 85 ?? ?? ?? ?? 83 E8 ?? 75 ?? + 31 D2 89 54 24 ?? E9 ?? ?? ?? ?? 8D 74 26 ?? 90 89 54 24 ?? 8B 94 24 ?? ?? ?? ?? 89 } - - condition: - uint16(0)==0x5A4D and ($find_folders and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*))) -} -rule REVERSINGLABS_Win32_Ransomware_Killdisk : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects KillDisk ransomware." - author = "ReversingLabs" - id = "bd04ac88-987a-58f0-8f0a-508662b3c930" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.KillDisk.yara#L1-L80" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6148e6fc1363ff8995a9100e07139bfa658c72892db4d30a973bad0f2b3e6c3f" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "KillDisk" - tc_detection_factor = 5 - importance = 25 - - strings: - $encrypt_files = { - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 55 8B AC 24 ?? ?? ?? - ?? 56 57 33 FF 8B F1 3B F7 89 7D ?? 89 7D ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 56 - FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 95 C0 84 C0 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 56 8D - 4C 24 ?? 89 7C 24 ?? 89 7C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 74 ?? B8 ?? ?? ?? ?? - E9 ?? ?? ?? ?? 8B 5C 24 ?? 3B DF 8B 44 24 ?? 89 45 ?? 89 5D ?? 77 ?? 83 F8 ?? 0F 82 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 6A ?? 57 6A ?? 68 ?? ?? ?? ?? 56 FF 15 - ?? ?? ?? ?? 8B E8 3B EF 0F 84 ?? ?? ?? ?? 83 FD ?? 0F 84 ?? ?? ?? ?? 8B 0D ?? ?? ?? - ?? 33 C0 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 - 44 24 ?? 89 44 24 ?? 8D 44 24 ?? 50 6A ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 54 - 24 ?? 57 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 54 24 ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 85 C0 0F - 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D - 4C 24 ?? 51 8D 54 24 ?? 89 7C 24 ?? 52 8D BC 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 85 C0 0F 84 ?? ?? ?? ?? 8B 74 24 ?? 6A ?? 8B C6 05 ?? ?? ?? ?? 50 8B CB 83 D1 ?? 51 - 6A ?? 6A ?? 55 FF 15 ?? ?? ?? ?? 85 C0 89 44 24 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 - ?? ?? ?? ?? 8D 4C 24 ?? 51 53 56 8B F8 E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 0F 84 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 8D 54 24 ?? 6A ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? B9 ?? ?? ?? ?? 8D B4 - 24 ?? ?? ?? ?? 8D 7C 24 ?? 8D 44 24 ?? F3 A5 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 08 89 8C 24 ?? ?? ?? ?? 8B 50 ?? 89 94 24 ?? ?? ?? ?? 8B 48 ?? 89 8C 24 - ?? ?? ?? ?? 8B 50 ?? 89 94 24 ?? ?? ?? ?? 8B 48 ?? 89 8C 24 ?? ?? ?? ?? 8B 50 ?? 8D - 74 24 ?? 89 94 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 6A ?? 6A ?? 53 50 55 FF 15 - ?? ?? ?? ?? 6A ?? 8D 4C 24 ?? 51 68 ?? ?? ?? ?? 8D 54 24 ?? 52 55 C7 44 24 ?? ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 8B F0 8B 44 24 ?? F7 DE 1B F6 83 E6 ?? 50 83 C6 ?? FF 15 ?? - ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 8B C6 EB ?? 8B 44 24 ?? 50 BE ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 55 FF 15 ?? ?? ?? ?? 8B C6 EB ?? 55 BE ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B C6 EB - ?? 55 BE ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B C6 EB ?? 55 BE ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 8B C6 EB ?? BE ?? ?? ?? ?? 8B C6 EB ?? B8 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E - 5D 5B 33 CC E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 + $find_files_v1_p3 = { + 44 24 ?? 8B 84 24 ?? ?? ?? ?? 89 74 24 ?? 89 44 24 ?? 89 54 24 ?? E9 ?? ?? ?? ?? 90 + 8B 84 24 ?? ?? ?? ?? BF ?? ?? ?? ?? C6 44 24 ?? ?? 83 E0 ?? 83 F8 ?? 19 C0 83 E0 ?? + 83 C0 ?? 89 44 24 ?? E9 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 90 8B 74 24 ?? 85 F6 0F 88 + ?? ?? ?? ?? 83 EC ?? FF 74 24 ?? 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 C6 85 C0 0F + 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B 44 24 ?? 89 44 24 ?? 8D B4 26 ?? ?? ?? ?? 8D 76 ?? + 83 EC ?? 56 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 80 78 ?? ?? + 0F 84 ?? ?? ?? ?? 83 EC ?? 8D 78 ?? 57 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 3B 44 24 + ?? 0F 83 ?? ?? ?? ?? 8B 44 24 ?? 83 EC ?? C6 44 05 ?? ?? 57 8B 44 24 ?? 01 E8 50 8B + 5C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 5A 5B 8D 48 ?? 8D 44 24 ?? 50 89 E8 FF B4 24 ?? + ?? ?? ?? 8B 54 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 EC ?? 89 C7 + 56 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 66 90 80 78 ?? ?? 0F 84 ?? ?? + ?? ?? 66 83 78 ?? ?? 0F 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D B6 ?? ?? ?? ?? 80 7C 05 ?? + ?? 8D 48 ?? 89 C2 0F 84 ?? ?? ?? ?? 85 C9 0F 84 ?? ?? ?? ?? 80 7C 05 ?? ?? 8D 50 ?? + 75 ?? E9 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 66 90 89 C2 85 D2 0F 84 ?? ?? ?? ?? 80 7C + 15 ?? ?? 8D 42 ?? 75 ?? E9 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? + 31 FF C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 EC ?? 56 8B 5C 24 ?? + E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B 07 E9 ?? ?? ?? ?? 8B 7C 24 ?? 89 FB BF ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C7 00 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? + ?? ?? ?? BF } - $app_whitelisting_1 = { - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 55 56 57 32 DB FF 15 - ?? ?? ?? ?? 6A ?? 6A ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? 8B E8 85 ED 89 6C 24 ?? 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4C 24 ?? - 51 55 C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 64 24 ?? - 8B 54 24 ?? 3B 54 24 ?? 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? 33 FF E8 ?? ?? ?? ?? 85 C0 - 0F 86 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B C1 - 2B C3 C1 F8 ?? 3B C7 0F 86 ?? ?? ?? ?? 3B D9 8B F3 76 ?? E8 ?? ?? ?? ?? 8B 1D ?? ?? - ?? ?? 8B 0D ?? ?? ?? ?? 89 74 24 ?? 8D 34 BE 3B F1 B8 ?? ?? ?? ?? 8B E8 77 ?? 3B F3 - 73 ?? E8 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 3B 75 ?? 72 ?? E8 ?? ?? ?? ?? 8B 1D ?? ?? ?? - ?? 8B 44 24 ?? 39 06 74 ?? B8 ?? ?? ?? ?? 83 C7 ?? E8 ?? ?? ?? ?? 3B F8 72 ?? 8B 6C - 24 ?? 8B 74 24 ?? FF 15 ?? ?? ?? ?? 3B F0 74 ?? 85 F6 74 ?? 56 6A ?? 6A ?? FF 15 ?? - ?? ?? ?? 8B F0 85 F6 74 ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? EB ?? 8B - 6C 24 ?? 8D 4C 24 ?? 51 55 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? B3 ?? 55 FF 15 - ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E 5D 8A C3 5B 33 CC E8 ?? ?? ?? ?? 81 C4 ?? ?? - ?? ?? C3 + $kill_processes_v1_p1 = { + 55 BA ?? ?? ?? ?? B8 ?? ?? ?? ?? BD ?? ?? ?? ?? 57 89 E9 56 53 E8 ?? ?? ?? ?? 81 C3 + ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 66 89 54 24 ?? 8D 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C6 44 24 + ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 ?? + C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? 8B 83 ?? ?? ?? ?? + 89 44 24 ?? 8B 83 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? F3 A5 8D B4 24 ?? ?? ?? ?? C6 44 } - $app_whitelisting_2 = { - 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 56 A1 ?? ?? ?? ?? 33 C4 50 8D 44 - 24 ?? 64 A3 ?? ?? ?? ?? 8D 44 24 ?? 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 70 ?? C7 44 - 24 ?? ?? ?? ?? ?? 56 C7 06 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 74 ?? 8B 36 EB - ?? 33 F6 6A ?? 56 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 8B 44 24 ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 7C 24 ?? ?? 72 ?? 8B 4C 24 - ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 64 89 0D - ?? ?? ?? ?? 59 5E 83 C4 ?? C3 + $kill_processes_v1_p2 = { + 24 ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 89 F7 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 CD C7 44 24 ?? ?? ?? + ?? ?? B9 ?? ?? ?? ?? 89 E8 F3 AB FF B4 24 ?? ?? ?? ?? 89 F7 8D 44 24 ?? 50 56 E8 ?? + ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 B9 ?? ?? ?? ?? F3 AB FF B4 24 ?? ?? + ?? ?? 89 F7 8D 44 24 ?? 50 56 E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 + B9 ?? ?? ?? ?? F3 AB FF B4 24 ?? ?? ?? ?? 89 F7 8D 44 24 ?? 50 56 E8 ?? ?? ?? ?? 89 + 34 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 B9 ?? ?? ?? ?? F3 AB FF B4 24 ?? ?? ?? ?? 89 F7 + 8D 44 24 ?? 50 56 E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 B9 ?? ?? ?? + ?? F3 AB FF B4 24 ?? ?? ?? ?? 89 F7 8D 84 24 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 89 34 + 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 B9 ?? ?? ?? ?? F3 AB FF B4 24 ?? ?? ?? ?? 89 F7 8D + 44 24 ?? 50 56 E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 B9 ?? ?? ?? ?? + F3 AB FF B4 24 ?? ?? ?? ?? 8D 44 24 ?? 50 56 E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? + 81 C4 ?? ?? ?? ?? 5B 5E 5F 5D C3 } - - condition: - uint16(0)==0x5A4D and $encrypt_files and $app_whitelisting_1 and $app_whitelisting_2 -} -rule REVERSINGLABS_Win32_Ransomware_Magniber : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Magniber ransomware." - author = "ReversingLabs" - id = "07b6c938-aa25-5ff6-95d2-9e0f84c41b41" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Magniber.yara#L1-L114" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "05b516f9b466489ea3a30e2fe5eb08290e85ece7a63e29e8bbbeb81c87d0a6f1" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Magniber" - tc_detection_factor = 5 - importance = 25 - - strings: - $remote_connection = { - E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B 55 - ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF - 15 ?? ?? ?? ?? 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 6A ?? 6A ?? 6A ?? 6A ?? - 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 6A - ?? 8D 45 ?? 50 8D 4D ?? 51 68 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 83 7D ?? ?? - 74 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? - ?? 8B 55 ?? 83 C2 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D - ?? ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 33 C0 EB ?? - C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? - ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 + $shut_down_esxi_v1 = { + 55 B8 ?? ?? ?? ?? BD ?? ?? ?? ?? 57 89 C1 56 53 E8 ?? ?? ?? ?? 81 C3 ?? ?? ?? ?? 81 + EC ?? ?? ?? ?? 8D 7C 24 ?? C7 44 24 ?? 65 73 78 63 C7 44 24 ?? 6C 69 20 76 C7 44 24 + ?? 6D 20 70 72 8D B3 ?? ?? ?? ?? C7 44 24 ?? 6F 63 65 73 F3 A5 8D B4 24 ?? ?? ?? ?? + C7 44 24 ?? 73 20 6B 69 83 EC ?? 89 F7 C7 44 24 ?? 6C 6C 20 2D C7 44 24 ?? 2D 74 79 + 70 C7 44 24 ?? 65 3D 66 6F C7 44 24 ?? 72 63 65 20 C7 44 24 ?? 2D 2D 77 6F 89 C8 B9 + ?? ?? ?? ?? C7 44 24 ?? 72 6C 64 2D C7 44 24 ?? 69 64 3D 22 C7 84 24 ?? ?? ?? ?? 25 + 73 22 00 C7 44 24 ?? 5B 45 53 58 C7 44 24 ?? 69 5D 20 53 C7 44 24 ?? 68 75 74 74 C7 + 44 24 ?? 69 6E 67 20 C7 44 24 ?? 64 6F 77 6E F3 AB C7 44 24 ?? 20 2D 20 25 8D 83 ?? + ?? ?? ?? 66 89 6C 24 ?? C6 44 24 ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 0F 84 ?? ?? ?? ?? BF ?? ?? ?? ?? 89 C5 8D 44 24 ?? 66 89 7C 24 ?? 31 FF } - $encrypt_files_1 = { - 55 8B EC 83 EC ?? 56 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? - ?? ?? ?? 89 45 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 8B 55 ?? 03 55 ?? 8D 44 12 - ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? EB - ?? 8B 4D ?? 83 C1 ?? 89 4D ?? 8B 55 ?? 3B 55 ?? 7D ?? 8B 45 ?? 8B 4D ?? 8B 55 ?? 8B - 75 ?? 66 8B 14 56 66 89 14 41 EB ?? B8 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 66 89 04 4A C7 - 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 3B 4D ?? 7D ?? 8B 55 ?? - 03 55 ?? 8B 45 ?? 8B 4D ?? 8B 75 ?? 66 8B 0C 4E 66 89 4C 50 ?? EB ?? 8B 55 ?? 03 55 - ?? 33 C0 8B 4D ?? 66 89 44 51 ?? 8D 55 ?? 52 8D 45 ?? 50 8D 4D ?? 51 8B 55 ?? 52 8B + $kill_processes_v2_p1 = { + 41 54 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? 45 31 E4 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 55 48 89 + FD 53 48 81 EC ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 00 00 48 89 84 24 ?? ?? ?? ?? B8 ?? ?? + ?? ?? 48 8D 9C 24 ?? ?? ?? ?? 48 8D B4 24 ?? ?? ?? ?? 0F 29 84 24 ?? ?? ?? ?? 66 0F + 6F 05 ?? ?? 00 00 48 89 DF 66 89 44 24 ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 0F 29 44 24 + ?? 66 0F 6F 05 ?? ?? 00 00 66 89 54 24 ?? 48 89 EA 0F 29 44 24 ?? 66 0F 6F 05 ?? ?? + 00 00 66 89 8C 24 ?? ?? 00 00 B9 ?? ?? ?? ?? 0F 29 44 24 ?? 66 0F 6F 05 ?? ?? 00 00 + C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 0F 29 84 24 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 00 00 C6 + 84 24 ?? ?? ?? ?? ?? 0F 29 84 24 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 00 00 C7 44 24 ?? ?? + ?? ?? ?? 0F 29 84 24 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 00 00 C6 44 24 ?? ?? 0F 29 84 24 + ?? ?? ?? ?? C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? C7 84 24 ?? ?? ?? + ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 48 89 44 24 ?? 48 B8 } - $encrypt_files_2 = { - 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? - ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 83 - 7D ?? ?? 75 ?? 33 C0 E9 ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 - 75 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 - ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 45 - ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 66 0F 57 C0 66 0F 13 45 ?? 6A ?? 8D 4D ?? 51 6A ?? - 8B 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 99 8B 4D ?? - 2B 4D ?? 8B 75 ?? 1B 75 ?? 89 45 ?? 89 55 ?? 89 4D ?? 89 75 ?? 8B 55 ?? 3B 55 ?? 7C - ?? 7F ?? 8B 45 ?? 3B 45 ?? 76 ?? 8B 4D ?? 2B 4D ?? 8B 55 ?? 1B 55 ?? 89 4D ?? 89 55 - ?? EB ?? 8B 45 ?? 99 89 45 ?? 89 55 ?? 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B + $kill_processes_v2_p2 = { + 48 89 44 24 ?? 4C 89 E0 F3 48 AB 48 89 DF C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 89 E0 48 89 DF B9 ?? + ?? ?? ?? F3 48 AB 48 8D 74 24 ?? 48 89 EA 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? + ?? ?? 4C 89 E0 48 89 DF B9 ?? ?? ?? ?? F3 48 AB 48 8D 74 24 ?? 48 89 EA 48 89 DF E8 + ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 89 E0 48 89 DF B9 ?? ?? ?? ?? F3 48 AB 48 8D + 74 24 ?? 48 89 EA 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 89 E0 48 89 DF + B9 ?? ?? ?? ?? F3 48 AB 48 8D B4 24 ?? ?? ?? ?? 48 89 EA 48 89 DF E8 ?? ?? ?? ?? 48 + 89 DF E8 ?? ?? ?? ?? 4C 89 E0 48 89 DF B9 ?? ?? ?? ?? F3 48 AB 48 8D 74 24 ?? 48 89 + EA 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 89 E0 48 89 DF B9 ?? ?? ?? ?? + F3 48 AB 48 8D 74 24 ?? 48 89 EA 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 + 81 C4 ?? ?? ?? ?? 5B 5D 41 5C C3 } - $encrypt_files_3 = { - 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 33 C0 E9 ?? ?? ?? ?? 83 7D ?? - ?? 75 ?? E9 ?? ?? ?? ?? 8B 4D ?? 3B 4D ?? 73 ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 89 55 - ?? 8B 45 ?? 50 8D 4D ?? 51 6A ?? 6A ?? 8B 55 ?? 52 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? - ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8B 4D ?? 51 8D 55 ?? 52 8B 45 ?? 50 6A ?? 8B 4D ?? 51 - 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 - ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? EB ?? - E9 ?? ?? ?? ?? 8B 45 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 7D ?? ?? - 74 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? - 83 7D ?? ?? 74 ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D ?? 51 8B 55 ?? 52 FF 15 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 3B 45 ?? 7C ?? 7F ?? 8B 4D ?? 3B 4D ?? - 76 ?? 83 7D ?? ?? 74 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? - 8B 4D ?? 51 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? - 83 C4 ?? B8 ?? ?? ?? ?? EB + $encrypt_files_v2_p1 = { + 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 41 57 66 0F EF C0 49 89 FF 41 56 49 89 D6 41 55 49 89 + F5 BE ?? ?? ?? ?? 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 8D 5C 24 ?? 48 89 4C 24 ?? 48 + 8D AC 24 ?? ?? ?? ?? 48 89 DF 4C 89 04 24 0F 29 44 24 ?? 0F 29 44 24 ?? 0F 29 44 24 + ?? 48 C7 44 24 ?? ?? ?? ?? ?? 0F 29 44 24 ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? 85 C0 75 + ?? 45 31 E4 48 89 EF BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 DF BE ?? ?? ?? ?? E8 ?? ?? + ?? ?? 48 8D 7B ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 44 89 E0 5B 5D + 41 5C 41 5D 41 5E 41 5F C3 0F 1F 80 ?? ?? ?? ?? 48 8D 7B ?? BE ?? ?? ?? ?? E8 ?? ?? + ?? ?? 85 C0 74 ?? BA ?? ?? ?? ?? 48 89 DE 48 89 EF E8 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? + ?? 4C 89 FF E8 ?? ?? ?? ?? 48 89 44 24 ?? 48 85 C0 0F 84 ?? ?? ?? ?? 4C 89 FF E8 ?? + ?? ?? ?? 4C 89 FE 4C 89 EF 48 89 C2 49 89 C4 E8 ?? ?? ?? ?? 8B 54 24 ?? 4B 8D 44 25 + ?? 31 F6 89 10 0F B7 54 24 ?? 66 89 50 ?? 0F B6 54 24 ?? 88 50 ?? BA ?? ?? ?? ?? 43 + C6 44 25 ?? ?? 4C 8B 64 24 ?? 4C 89 E7 E8 ?? ?? ?? ?? 4C 89 E7 4C 89 64 24 ?? 45 31 + E4 E8 ?? ?? ?? ?? 48 83 F8 ?? 7E ?? 4C 89 EE 4C 89 FF E8 ?? ?? ?? ?? 85 C0 74 ?? 48 + 8B 7C 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 66 0F 1F 44 00 ?? 48 8B 7C 24 ?? E8 ?? ?? + ?? ?? 48 8D 35 ?? ?? ?? ?? 4C 89 EF E8 ?? ?? ?? ?? 48 89 44 24 ?? 49 89 C4 48 85 C0 } - $search_files = { - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 83 7D ?? ?? 7D ?? 8B 4D ?? 8B 94 - 8D ?? ?? ?? ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 33 C0 E9 ?? ?? ?? - ?? EB ?? 8B 4D ?? 8B 55 ?? 8B 81 ?? ?? ?? ?? 3B 82 ?? ?? ?? ?? 76 ?? B8 ?? ?? ?? ?? - E9 ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 75 ?? B8 ?? - ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 8B 8D ?? ?? ?? ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? - 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? 50 - FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 8B 4D ?? 83 C1 ?? 51 FF 15 ?? ?? ?? ?? - 85 C0 75 ?? EB ?? 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 83 C1 - ?? 51 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 74 ?? 8B 4D ?? 81 79 ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? - ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8B 4D ?? - 81 79 ?? ?? ?? ?? ?? 75 ?? 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? - ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 03 45 ?? 89 - 45 ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 6A ?? 8B 4D ?? 81 C1 ?? ?? ?? ?? 51 8B 55 ?? - 81 C2 ?? ?? ?? ?? 52 8B 45 ?? 05 ?? ?? ?? ?? 50 8B 4D ?? 81 C1 ?? ?? ?? ?? 51 8B 55 - ?? 81 C2 ?? ?? ?? ?? 52 8B 45 ?? 05 ?? ?? ?? ?? 50 8B 4D ?? 81 C1 ?? ?? ?? ?? 51 8B - 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 + $encrypt_files_v2_p2 = { + 0F 84 ?? ?? ?? ?? 31 F6 BA ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 4C 89 E7 4C 89 64 24 + ?? E8 ?? ?? ?? ?? 48 39 44 24 ?? 48 0F 4E 44 24 ?? 48 8D 7C 24 ?? 48 89 C1 48 C1 F9 + ?? 48 C1 E9 ?? 48 8D 14 08 83 E2 ?? 48 29 CA 48 29 D0 48 89 44 24 ?? E8 ?? ?? ?? ?? + 48 8D BC 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 89 DE 48 89 44 24 ?? 31 C0 BA ?? ?? ?? ?? + F3 48 AB 48 8D 84 24 ?? ?? ?? ?? 48 8B 3C 24 48 89 C1 48 89 44 24 ?? E8 ?? ?? ?? ?? + 41 89 C4 85 C0 0F 84 ?? ?? ?? ?? 48 8B 7C 24 ?? E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 4C 89 + EE E8 ?? ?? ?? ?? 41 89 C4 85 C0 0F 84 ?? ?? ?? ?? 48 8B 44 24 ?? 4C 8D 64 24 ?? 48 + 85 C0 75 ?? E9 ?? ?? ?? ?? 0F 1F 80 ?? ?? ?? ?? 4D 89 F1 4D 89 E8 4C 89 E9 4C 89 E2 + 48 89 EE 48 8D 3D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 F6 BA ?? ?? ?? ?? 4C 89 FF 48 F7 + DE E8 ?? ?? ?? ?? 4C 89 F9 4C 89 F2 BE ?? ?? ?? ?? 4C 89 EF E8 ?? ?? ?? ?? 48 8B 44 + 24 ?? 4C 29 F0 48 89 44 24 ?? 74 ?? 49 39 C6 4C 8B 7C 24 ?? BE ?? ?? ?? ?? 4C 89 EF + 4C 0F 47 F0 66 0F 6F 4C 24 ?? 4C 89 F9 4C 89 F2 0F 29 4C 24 ?? E8 ?? ?? ?? ?? 4C 39 + F0 74 ?? 48 8B 7C 24 ?? 41 BC ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 89 FE 4C + 89 EF E8 ?? ?? ?? ?? E9 } - - condition: - uint16(0)==0x5A4D and ($search_files and ( all of ($encrypt_files_*)) and $remote_connection) -} -rule REVERSINGLABS_Win32_Ransomware_Serpent : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Serpent ransomware." - author = "ReversingLabs" - id = "0757ad7c-b2b1-5323-960a-55ffe3eaed12" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Serpent.yara#L1-L122" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "5e1917e8d23a5edc65ac423f3d18cc78c3848bd6c1ccc67d052eb37172857081" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Serpent" - tc_detection_factor = 5 - importance = 25 - - strings: - $do_dll_stuff_and_create_thread = { - 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 89 D2 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 89 FF 90 90 6A ?? 53 E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 68 ?? - ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? BB ?? ?? ?? ?? 4B 75 ?? BA - ?? ?? ?? ?? 66 0F 6E D2 89 FF 89 C9 31 D2 66 0F 7E D2 89 15 ?? ?? ?? ?? 81 3D ?? ?? - ?? ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? BB ?? ?? ?? ?? 4B 75 ?? BB ?? ?? ?? ?? 89 C9 4B - 75 ?? 89 C9 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? BB ?? ?? ?? ?? 4B - 75 ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 79 ?? E8 ?? - ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 79 ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 4B - 75 ?? 89 FF 90 BB ?? ?? ?? ?? 89 C9 4B 75 ?? 90 90 BB ?? ?? ?? ?? 4B 75 ?? BB ?? ?? - ?? ?? 4B 75 ?? BB ?? ?? ?? ?? 4B 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 90 BB ?? ?? ?? ?? 89 D2 4B 75 ?? 6A ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? BA ?? - ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 90 89 C9 BB ?? ?? ?? ?? 89 FF 4B 75 ?? 68 ?? ?? ?? ?? - 6A ?? 56 E8 ?? ?? ?? ?? BB ?? ?? ?? ?? 89 D2 4B 75 ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 33 - C0 A3 ?? ?? ?? ?? 64 8B 35 ?? ?? ?? ?? 89 35 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? - 90 89 F6 90 BB ?? ?? ?? ?? 89 DB 4B 75 ?? 89 D2 89 C0 BB ?? ?? ?? ?? 89 D2 4B 75 ?? - C7 05 ?? ?? ?? ?? ?? ?? ?? ?? BB ?? ?? ?? ?? 89 FF 4B 75 ?? 89 C0 0F 31 90 89 C7 0F - 31 90 89 C0 29 F8 89 D2 89 DB 77 ?? 90 90 89 C9 89 F6 8B 3D ?? ?? ?? ?? 90 90 89 C9 - 89 F6 90 03 3D ?? ?? ?? ?? 90 90 89 C9 89 F6 FF D7 89 F6 90 90 BB ?? ?? ?? ?? 4B 75 - ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? C3 + $find_files_v2_p1 = { + 41 57 4D 89 C7 41 56 49 89 FE 41 55 49 89 FD 41 54 55 53 89 CB 48 81 EC ?? ?? ?? ?? + 48 89 34 24 89 54 24 ?? 41 8B 55 ?? 49 83 C5 ?? 8D 82 ?? ?? ?? ?? F7 D2 21 D0 25 ?? + ?? ?? ?? 74 ?? 89 C2 C1 EA ?? A9 ?? ?? ?? ?? 0F 44 C2 49 8D 55 ?? 4C 0F 44 EA 89 C6 + 40 00 C6 49 83 DD ?? 31 ED 4D 29 F5 74 ?? 49 8D 6D ?? 43 80 7C 2E ?? ?? 49 0F 45 ED + 48 8D 44 24 ?? 41 89 DC 4C 89 F6 48 89 44 24 ?? 48 89 C2 BF ?? ?? ?? ?? 41 83 E4 ?? + 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 00 83 F8 + ?? 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 45 31 DB 41 BC ?? ?? ?? ?? 48 8B 44 24 ?? F6 C3 + ?? 0F 85 ?? ?? ?? ?? 48 89 44 24 ?? 48 8B 44 24 ?? 4C 89 7C 24 ?? 48 89 44 24 ?? 4D + 85 FF 0F 84 ?? ?? ?? ?? 41 8B 47 ?? 8D 55 ?? 89 54 24 ?? 83 C0 ?? 89 44 24 ?? 89 44 + 24 ?? 41 8B 47 ?? 89 44 24 ?? 45 31 C0 C7 44 24 ?? ?? ?? ?? ?? 83 F9 ?? 0F 84 ?? ?? + ?? ?? 89 D8 83 E0 ?? 89 44 24 ?? 75 ?? 44 88 5C 24 ?? 44 89 E2 48 8D 4C 24 ?? 4C 89 + F7 48 8B 74 24 ?? 48 8B 04 24 44 89 44 24 ?? FF D0 44 8B 44 24 ?? 44 0F B6 5C 24 ?? + 85 C0 89 C2 75 ?? 4D 85 FF 0F 84 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 54 24 ?? EB ?? 0F + 1F 44 00 ?? 4D 8B 3F 4D 85 FF 0F 84 ?? ?? ?? ?? 49 39 47 ?? 75 ?? 49 39 57 ?? 75 ?? + 31 D2 48 81 C4 ?? ?? ?? ?? 89 D0 5B 5D 41 5C 41 5D 41 5E 41 5F C3 66 90 E8 ?? ?? ?? + ?? 85 C0 78 ?? 8B 44 24 ?? 25 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 3D ?? ?? + ?? ?? 0F 84 ?? ?? ?? ?? 31 C9 45 31 DB 45 31 E4 48 8B 44 24 ?? F6 C3 ?? 0F 84 ?? ?? + ?? ?? 4D 85 FF 0F 84 ?? ?? ?? ?? 49 39 47 ?? 75 ?? 48 89 44 24 ?? 48 8B 44 24 ?? 4C } - $find_files = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 C0 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? - ?? ?? ?? 89 85 ?? ?? ?? ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8B 45 - ?? 8B 58 ?? 83 7B ?? ?? 75 ?? 8D 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 8D 55 ?? - A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 73 ?? 6A ?? 8D 45 ?? 50 8B 43 ?? 50 E8 ?? ?? ?? ?? - 81 7D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? - 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 43 ?? 89 85 ?? ?? ?? ?? C6 85 ?? ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C6 85 ?? - ?? ?? ?? ?? 8B 45 ?? 89 85 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? C6 85 - ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 95 ?? ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 8D ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 EB ?? 8B 43 ?? 89 - 85 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8B 45 ?? 89 85 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? - 89 B5 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 95 ?? ?? ?? ?? - A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B D8 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 + $find_files_v2_p2 = { + 89 7C 24 ?? 48 89 44 24 ?? E9 ?? ?? ?? ?? 66 2E 0F 1F 84 00 ?? ?? 00 00 E8 ?? ?? ?? + ?? 49 89 C4 8B 00 83 F8 ?? 0F 85 ?? ?? ?? ?? 48 8B 54 24 ?? 4C 89 F6 BF ?? ?? ?? ?? + E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 45 31 DB 41 BC ?? ?? ?? ?? EB + ?? 0F 1F 00 8B 4C 24 ?? 85 C9 74 ?? 45 84 DB 0F 85 ?? ?? ?? ?? 8B 44 24 ?? 43 C6 04 + 2E ?? 85 C0 0F 84 ?? ?? ?? ?? 44 89 E2 48 8D 4C 24 ?? 48 8B 74 24 ?? 4C 89 F7 48 8B + 04 24 FF D0 89 C2 E9 ?? ?? ?? ?? 90 31 F6 4C 89 F7 31 C0 44 88 5C 24 ?? E8 ?? ?? ?? + ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 7C 24 ?? 44 0F B6 5C 24 ?? 44 8B 00 85 FF 79 ?? 41 + 83 F8 ?? BA ?? ?? ?? ?? 0F 94 C0 84 C0 B8 ?? ?? ?? ?? 44 0F 45 DA 44 0F 45 E0 8B 74 + 24 ?? 85 F6 0F 85 ?? ?? ?? ?? 8B 7C 24 ?? 44 88 5C 24 ?? 44 89 44 24 ?? E8 ?? ?? ?? + ?? 44 0F B6 5C 24 ?? 44 8B 44 24 ?? E9 ?? ?? ?? ?? 0F 1F 00 48 89 44 24 ?? 48 8B 44 + 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 89 44 24 ?? 8D 45 ?? C7 44 24 ?? ?? ?? ?? ?? 89 + 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 48 85 ED 74 ?? 41 80 3C 2E ?? 48 89 E8 74 ?? E9 ?? + ?? ?? ?? 0F 1F 44 00 ?? 41 80 3C 06 ?? 0F 85 ?? ?? ?? ?? 48 83 E8 ?? 75 ?? 31 D2 89 } - $remote_connection = { - 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 FF 05 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 85 ?? - ?? ?? ?? 8D 83 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 66 8B 83 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? - ?? ?? 8D 55 ?? 33 C0 8A 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 51 ?? 68 ?? ?? ?? ?? 66 8B 83 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? - ?? ?? 8D 55 ?? 33 C0 8A 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 51 ?? 8D 45 ?? 8D 93 ?? ?? ?? - ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 55 ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 51 ?? 8D 45 ?? 8D 93 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 83 ?? ?? ?? - ?? 8B 08 FF 51 ?? 8D 55 ?? 0F B7 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 51 ?? 8D 55 ?? 0F B7 - 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 - ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 51 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 6A ?? - 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 81 FE ?? ?? ?? ?? 76 ?? E8 ?? ?? ?? ?? 66 89 B3 ?? - ?? ?? ?? 66 C7 45 ?? ?? ?? 66 C7 45 ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 0F B7 C6 50 E8 ?? ?? ?? ?? 66 81 BB ?? ?? ?? ?? ?? ?? 75 ?? 8D 4D ?? 66 BA - ?? ?? 8B C3 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? 50 0F B7 83 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? FF 0D ?? ?? ?? - ?? 83 3D ?? ?? ?? ?? ?? 75 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 + $find_files_v2_p3 = { + 54 24 ?? E9 ?? ?? ?? ?? 0F 1F 40 ?? 89 D8 B9 ?? ?? ?? ?? 41 BB ?? ?? ?? ?? 83 E0 ?? + 83 F8 ?? 45 19 E4 41 83 E4 ?? 41 83 C4 ?? E9 ?? ?? ?? ?? 0F 1F 44 00 ?? 8B 54 24 ?? + 85 D2 0F 88 ?? ?? ?? ?? 8B 7C 24 ?? E8 ?? ?? ?? ?? 49 89 C7 48 85 C0 0F 84 ?? ?? ?? + ?? B8 ?? ?? ?? ?? 44 89 64 24 ?? 4C 29 E8 48 89 44 24 ?? 48 8D 44 24 ?? 48 89 44 24 + ?? 8B 44 24 ?? 83 E8 ?? 89 44 24 ?? 4C 89 FF E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? + ?? 80 78 ?? ?? 74 ?? 4C 8D 60 ?? 4C 89 E7 E8 ?? ?? ?? ?? 48 3B 44 24 ?? 0F 83 ?? ?? + ?? ?? 41 C6 04 2E ?? 49 8D 7C 2E ?? 4C 89 E6 E8 ?? ?? ?? ?? 4C 8B 44 24 ?? 8B 54 24 + ?? 89 D9 48 8B 34 24 4C 89 F7 E8 ?? ?? ?? ?? 85 C0 74 ?? 4C 89 FF 89 04 24 E8 ?? ?? + ?? ?? 8B 14 24 E9 ?? ?? ?? ?? 66 90 80 78 ?? ?? 74 ?? 66 83 78 ?? ?? 75 ?? EB ?? 90 + 41 80 7C 06 ?? ?? 48 8D 70 ?? 89 C2 0F 84 ?? ?? ?? ?? 48 85 F6 0F 84 ?? ?? ?? ?? 41 + 80 7C 06 ?? ?? 48 8D 50 ?? 75 ?? E9 ?? ?? ?? ?? 0F 1F 40 ?? 48 89 C2 48 85 D2 0F 84 + ?? ?? ?? ?? 41 80 7C 16 ?? ?? 48 8D 42 ?? 75 ?? E9 ?? ?? ?? ?? 0F 1F 00 45 85 E4 0F + 84 ?? ?? ?? ?? 31 C9 45 31 DB 41 BC ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 89 FF 44 8B 64 24 + ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 41 8B 04 24 E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 FF + C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? E9 ?? ?? ?? ?? BA ?? ?? ?? ?? E9 ?? + ?? ?? ?? 48 89 F2 E9 ?? ?? ?? ?? 44 89 04 24 E8 ?? ?? ?? ?? 44 8B 04 24 BA ?? ?? ?? + ?? 44 89 00 E9 ?? ?? ?? ?? 8B 7C 24 ?? E8 ?? ?? ?? ?? 83 CA ?? E9 } - $remote_ftp_connection = { - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? 8B 45 ?? 66 - 8B 80 ?? ?? ?? ?? 66 3D ?? ?? 7E ?? 66 3D ?? ?? 7D ?? 8B 45 ?? 66 83 B8 ?? ?? ?? ?? - ?? 74 ?? 8B 5D ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8B 4D ?? B2 ?? A1 ?? - ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 66 81 B8 ?? ?? ?? ?? ?? ?? 75 ?? B9 - ?? ?? ?? ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 88 ?? ?? ?? ?? 8D 45 ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? 8B 45 ?? 66 8B 80 - ?? ?? ?? ?? 66 3D ?? ?? 7E ?? 66 3D ?? ?? 7D ?? 8B 45 ?? 66 83 B8 ?? ?? ?? ?? ?? 74 - ?? 8B 5D ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8B 4D ?? B2 ?? A1 ?? ?? ?? - ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 B8 ?? ?? ?? ?? ?? 74 ?? 8B 45 ?? 83 B8 - ?? ?? ?? ?? ?? 75 ?? 8B 45 ?? 66 83 B8 ?? ?? ?? ?? ?? 74 ?? 8D 55 ?? 8B 5D ?? 8B 83 - ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8B 45 ?? 83 B8 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 - ?? 8A 80 ?? ?? ?? ?? 2C ?? 72 ?? 74 ?? FE C8 74 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B - 45 ?? FF B0 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 45 ?? FF B0 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? EB ?? 8B 45 ?? 8B 88 - ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 - FF 53 ?? EB ?? 8B 45 ?? 8B 88 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? 8B 45 ?? 83 B8 ?? ?? ?? ?? ?? 74 ?? 8B 45 ?? - 80 B8 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 88 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 88 ?? ?? ?? - ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? - 8B 45 ?? 66 8B 80 ?? ?? ?? ?? 66 3D ?? ?? 7E ?? 66 3D ?? ?? 7D ?? 8B 45 ?? 66 83 B8 - ?? ?? ?? ?? ?? 74 ?? 8B 5D ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8B 4D ?? - B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 66 81 B8 ?? ?? ?? ?? ?? - ?? 75 ?? B9 ?? ?? ?? ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 88 ?? ?? ?? ?? 8D - 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? 8B 45 - ?? 66 8B 80 ?? ?? ?? ?? 66 3D ?? ?? 7E ?? 66 3D ?? ?? 7D ?? 8B 45 ?? 66 83 B8 ?? ?? - ?? ?? ?? 74 ?? 8B 5D ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8B 4D ?? B2 ?? - A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 66 83 B8 ?? ?? ?? ?? ?? 74 ?? - 8B 5D ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? FF 93 + $init_key_v2 = { + 48 85 FF 0F 84 ?? ?? ?? ?? 48 85 F6 0F 84 ?? ?? ?? ?? 41 56 41 55 41 54 55 48 89 F5 + 53 48 89 FB 48 81 EC ?? ?? ?? ?? 4C 8D 64 24 ?? 4C 89 E7 E8 ?? ?? ?? ?? 85 C0 75 ?? + 66 0F EF C0 48 8D 35 ?? ?? ?? ?? 48 8D 3D ?? ?? ?? ?? 49 89 E6 0F 29 04 24 0F 29 44 + 24 ?? E8 ?? ?? ?? ?? 49 89 C5 48 85 C0 74 ?? 4C 89 F7 48 89 C1 BA ?? ?? ?? ?? BE ?? + ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 EF E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 4C 89 F6 4C 89 E7 E8 + ?? ?? ?? ?? 85 C0 74 ?? 31 C0 48 81 C4 ?? ?? ?? ?? 5B 5D 41 5C 41 5D 41 5E C3 66 2E + 0F 1F 84 00 ?? ?? 00 00 31 C0 C3 0F 1F 44 00 ?? 48 89 EA 48 89 DE 4C 89 E7 E8 ?? ?? + ?? ?? 85 C0 75 ?? 4C 89 E7 E8 ?? ?? ?? ?? 89 E8 EB } condition: - uint16(0)==0x5A4D and $do_dll_stuff_and_create_thread and $find_files and $remote_connection and $remote_ftp_connection + uint32(0)==0x464C457F and ((( all of ($find_files_v1_p*)) and ( all of ($kill_processes_v1_p*)) and ($init_key_v1) and ( all of ($encrypt_files_v1_p*)) and ($shut_down_esxi_v1)) or (( all of ($find_files_v2_p*)) and ( all of ($kill_processes_v2_p*)) and ($init_key_v2) and ( all of ($encrypt_files_v2_p*)))) } -rule REVERSINGLABS_Win32_Ransomware_Ransomplus : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Matsnu : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects RansomPlus ransomware." + description = "Yara rule that detects Matsnu ransomware." author = "ReversingLabs" - id = "ee96eab6-104d-560f-adae-6d5f0ba5d469" + id = "2f0bddd5-bd48-5d38-84f4-2dbccbe04a46" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.RansomPlus.yara#L1-L95" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "8ab18c6bcb939eac0e74f015dea773141b5086c5fcb4783666eeac1f395bc208" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Matsnu.yara#L1-L116" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "76ef1b4a292f27ccd904e80f0279a7a327f7399a21f2266ef3ea959e5339ffac" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -27754,96 +29306,116 @@ rule REVERSINGLABS_Win32_Ransomware_Ransomplus : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "RansomPlus" + tc_detection_name = "Matsnu" tc_detection_factor = 5 importance = 25 strings: - $find_files_1_0 = { - 55 8B EC 83 E4 ?? 83 EC ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 EC ?? - 8B CC 6A ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? C6 01 ?? E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B CC 6A ?? 68 ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? - ?? ?? ?? C6 01 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CC 6A ?? 68 ?? ?? ?? ?? C7 41 ?? - ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C6 01 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CC 6A ?? - 68 ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C6 01 ?? E8 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 8B E5 5D C2 + $remote_connection = { + 55 89 E5 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C6 45 ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5B 8D 83 ?? ?? ?? ?? 8B 00 6A ?? 50 + FF 93 ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? 8B 36 8D 7D ?? 57 56 FF 93 ?? ?? ?? ?? 85 C0 74 + ?? 57 8D BB ?? ?? ?? ?? 89 07 5F EB ?? 8D B3 ?? ?? ?? ?? 8B 36 57 8D BB ?? ?? ?? ?? + 89 37 5F 68 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? EB ?? 8D BD ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A + ?? 57 FF 93 ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? 8B 36 8D BD ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 + 57 FF 93 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 50 57 FF 93 ?? ?? ?? ?? 85 + C0 74 ?? C6 00 ?? 8D BD ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? 8D 93 ?? ?? + ?? ?? FF 75 ?? 52 51 56 57 FF 93 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 8D 4D ?? 51 57 E8 ?? + ?? ?? ?? 85 C0 74 ?? 89 45 ?? 8D 4D ?? 51 50 E8 ?? ?? ?? ?? 85 C0 75 ?? FF 75 ?? FF + 93 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 89 85 ?? ?? ?? ?? FF 75 ?? FF 93 ?? ?? ?? + ?? 8B 45 ?? 8B 75 ?? 89 06 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 83 BD ?? + ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + 68 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? 8B 36 8D 83 ?? ?? ?? ?? 50 56 FF + 93 ?? ?? ?? ?? 85 C0 74 ?? 40 57 8D BB ?? ?? ?? ?? 89 07 5F E9 ?? ?? ?? ?? 8D B3 ?? + ?? ?? ?? 8B 36 57 8D BB ?? ?? ?? ?? 89 37 5F 68 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? E9 ?? + ?? ?? ?? 8D 83 ?? ?? ?? ?? 8B 00 50 FF 93 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? + ?? ?? C9 C2 } - $find_files_1_1 = { - 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 72 ?? 8B 00 8D 8D ?? ?? ?? ?? 51 50 FF 15 ?? - ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 F9 ?? 72 ?? 8B 95 ?? ?? ?? ?? - 41 81 F9 ?? ?? ?? ?? 72 ?? F6 C2 ?? 74 ?? E8 ?? ?? ?? ?? 8B 42 ?? 3B C2 72 ?? E8 ?? - ?? ?? ?? 2B D0 83 FA ?? 73 ?? E8 ?? ?? ?? ?? 83 FA ?? 76 ?? E8 ?? ?? ?? ?? 8B D0 52 - E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C6 85 ?? ?? ?? ?? ?? 83 FB ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 32 DB E9 ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? C6 45 ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? - ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 + $crypto_file = { + 55 89 E5 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? + C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 5D ?? E8 + ?? ?? ?? ?? 5B 8D 83 ?? ?? ?? ?? 8B 00 85 C0 74 ?? 89 45 ?? 8D 83 ?? ?? ?? ?? 8B 00 + 85 C0 74 ?? 8D 7D ?? 8D 75 ?? 8D 4D ?? 51 56 57 FF 75 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? + 89 45 ?? 83 7D ?? ?? 74 ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? EB ?? FF 75 ?? FF 75 ?? + FF 93 ?? ?? ?? ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? EB ?? C7 45 ?? ?? ?? ?? ?? 8B 45 + ?? 8B 5D ?? C9 C2 } - $find_files_1_2 = { - 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? - 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? - 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 75 ?? 33 C9 EB - ?? 8D 8D ?? ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 51 8D 85 ?? ?? ?? ?? 50 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 55 ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 EC ?? - 8B CC C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 83 79 ?? ?? 72 ?? 8B 01 EB ?? 8B C1 - 6A ?? C6 00 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 - 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 75 ?? 33 C9 EB ?? 8D 8D - ?? ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 51 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? 8B 95 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 83 FE ?? 0F 43 C2 0F 43 CA 89 85 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 03 C1 83 FE ?? 8B F8 0F 43 DA 33 C9 2B FB 33 F6 3B D8 0F 47 F9 85 - FF 74 ?? 0F BE 04 33 50 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 C4 ?? 88 04 31 46 3B F7 - 75 ?? 33 C0 89 85 ?? ?? ?? ?? 8B 94 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 80 3A ?? 75 ?? 33 C9 EB ?? 8B CA 8D - 71 ?? 8A 01 41 84 C0 75 ?? 2B CE 51 52 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? - 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 F9 ?? 0F - 43 C2 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 C2 03 85 ?? ?? ?? ?? 83 F9 ?? 8B F8 - 0F 43 DA 33 F6 2B FB 3B D8 0F 47 FE 85 FF 74 + $crypt_file = { + 55 89 E5 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 5B 8D BD ?? ?? ?? ?? FF 75 ?? 57 FF 93 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 8D B3 ?? ?? ?? + ?? 56 57 FF 93 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 57 FF 93 ?? ?? ?? ?? 89 45 ?? 8D 85 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 FF 93 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 51 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 30 FF 93 ?? + ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 8D 4D ?? 8D 85 ?? ?? ?? ?? 6A ?? + FF 31 50 FF 36 FF 93 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 8D B5 ?? ?? ?? ?? 51 6A ?? FF 36 68 ?? ?? ?? ?? FF 30 FF 93 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 93 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 89 45 + ?? 6A ?? FF 75 ?? FF 93 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF + 75 ?? FF 93 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 89 45 ?? 8D 7D ?? 8D 75 ?? 8D 55 + ?? 52 56 57 FF 75 ?? FF 93 ?? ?? ?? ?? 8B 45 ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D + 45 ?? 6A ?? 50 FF 75 ?? FF 75 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + FF 75 ?? FF 93 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? FF 75 + ?? FF 75 ?? E8 ?? ?? ?? ?? 8D 7D ?? 8D B5 ?? ?? ?? ?? FF 75 ?? 57 FF 75 ?? 6A ?? 6A + ?? 6A ?? FF 36 FF 93 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? + ?? ?? FF 75 ?? FF 93 ?? ?? ?? ?? 83 F8 ?? 74 ?? 89 45 ?? 8D 45 ?? 6A ?? 50 FF 75 ?? + FF 75 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 85 C0 74 ?? 8D 7D ?? 8D 75 ?? 8D 55 ?? 52 56 57 + FF 75 ?? FF 93 ?? ?? ?? ?? FF 75 ?? FF 93 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D B3 ?? + ?? ?? ?? FF 06 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 93 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 50 FF 93 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 6A ?? 50 FF 93 ?? ?? ?? ?? + 83 7D ?? ?? 74 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? FF 93 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? C9 C2 } - $encrypt_files = { - 8A 01 41 84 C0 75 ?? 2B CA C6 85 ?? ?? ?? ?? ?? 33 C0 88 84 05 ?? ?? ?? ?? 40 3D ?? - ?? ?? ?? 72 ?? 33 F6 8B C6 33 D2 F7 F1 8A 04 3A 02 C1 30 84 35 ?? ?? ?? ?? 46 81 FE - ?? ?? ?? ?? 72 ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 55 ?? 8B F8 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B - D8 85 FF 74 ?? 85 DB 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 57 68 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 8B F0 8D 85 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 53 56 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 57 E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? - 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? 83 F8 - ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B - 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? - E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D - ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? - 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? - ?? ?? 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 F8 - ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B - C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? - ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B - 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $enum_files_1 = { + 89 E5 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5B E8 ?? + ?? ?? ?? 8D 7D ?? 6A ?? FF 75 ?? 57 FF 93 ?? ?? ?? ?? 8D 7D ?? 57 FF 93 ?? ?? ?? ?? + 83 F8 ?? 74 ?? EB ?? 8D 75 ?? 56 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? C9 C2 + } + $enum_files_2 = { + 55 89 E5 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? + 66 C7 45 ?? ?? ?? C6 45 ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5B 83 7D ?? ?? 0F 84 + ?? ?? ?? ?? FF 75 ?? FF 93 ?? ?? ?? ?? 83 C0 ?? 89 45 ?? 40 50 6A ?? FF 93 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 89 45 ?? FF 75 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 8D 75 ?? 56 + FF 75 ?? FF 93 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 57 FF 75 ?? FF 93 ?? ?? ?? ?? 83 F8 ?? + 0F 84 ?? ?? ?? ?? 89 45 ?? 6A ?? FF 93 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 8D 55 ?? 8D B5 + ?? ?? ?? ?? 52 56 FF 93 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 55 ?? 8D B5 ?? ?? ?? ?? 52 + 56 FF 93 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? FF 93 ?? ?? ?? ?? 40 89 45 ?? 8D BD + ?? ?? ?? ?? 57 FF 93 ?? ?? ?? ?? 03 45 ?? 89 45 ?? 40 50 6A ?? FF 93 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 89 45 ?? FF 75 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 8D 75 ?? 56 FF 75 + ?? FF 93 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 56 FF 75 ?? FF 93 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? A9 ?? ?? ?? ?? 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 85 C0 75 ?? FF 75 ?? E8 ?? ?? ?? ?? + EB ?? 8D B5 ?? ?? ?? ?? FF 75 ?? 56 FF 75 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 + ?? FF 93 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 57 FF 75 ?? FF 93 ?? ?? + ?? ?? 85 C0 74 ?? E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF + 75 ?? FF 93 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 83 7D ?? ?? 74 + ?? FF 75 ?? FF 93 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? C9 C2 } condition: - uint16(0)==0x5A4D and $find_files_1_0 and $find_files_1_1 and $find_files_1_2 and $encrypt_files + uint16(0)==0x5A4D and $enum_files_1 and $enum_files_2 and $crypto_file and $crypt_file and $remote_connection } -rule REVERSINGLABS_Win32_Ransomware_Dualshot : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Bluelocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Dualshot ransomware." + description = "Yara rule that detects BlueLocker ransomware." author = "ReversingLabs" - id = "17828c85-0f1b-581b-842a-24e6f26e0b4d" - date = "2020-11-20" - modified = "2020-11-20" + id = "145ff05e-c90d-598a-a3d5-220bd6df718a" + date = "2022-08-04" + modified = "2022-08-04" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Dualshot.yara#L1-L112" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "a401369357901f42ad83227b025d3b14b3acd1f50705da82afbe8e4f85501919" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.BlueLocker.yara#L1-L130" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "fbe5f246f4554e63b5da6a0aca169e8221a84fce18fd437ae7ad9b068e9ca576" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -27851,197 +29423,524 @@ rule REVERSINGLABS_Win32_Ransomware_Dualshot : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Dualshot" + tc_detection_name = "BlueLocker" tc_detection_factor = 5 importance = 25 strings: - $internal_encrypt_file = { - 02 28 ?? ?? ?? ?? 0A 02 28 ?? ?? ?? ?? 0B 02 28 ?? ?? ?? ?? 0C 02 28 ?? ?? ?? ?? 03 28 - ?? ?? ?? ?? 0D 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 25 09 16 09 8E 69 6F ?? - ?? ?? ?? 6F ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 06 28 ?? ?? ?? ?? 02 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 07 28 ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 28 ?? ?? ?? - ?? 02 1B 19 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 00 02 28 ?? ?? ?? ?? DE ?? 26 - DE ?? 2A - } $encrypt_files_p1 = { - 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? - 8E 69 32 ?? DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 11 ?? 13 - ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 11 ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? - 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? 72 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? - ?? ?? 72 ?? ?? ?? ?? 08 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? - ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 25 28 ?? ?? ?? ?? 11 - ?? 6F ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 8E 69 6F ?? ?? ?? ?? 6F ?? ?? - ?? ?? 06 72 ?? ?? ?? ?? 12 ?? 6F ?? ?? ?? ?? 26 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 08 1F ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 - ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 72 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 16 6F ?? - ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 11 ?? - 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 DE ?? - 26 DE ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 08 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 13 ?? 12 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 1B 8D ?? ?? ?? ?? 25 16 28 ?? ?? ?? ?? 6F ?? - ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 11 ?? A2 25 19 72 ?? ?? ?? ?? A2 25 1A 11 ?? - A2 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 09 2C ?? 73 ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 16 6F - ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 2B ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 11 ?? - 72 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2A + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 8B 75 ?? 57 + 8B 7D ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 56 89 55 ?? 89 75 ?? + 89 45 ?? 89 7D ?? FF 15 ?? ?? ?? ?? 8B D8 C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 53 FF 15 + ?? ?? ?? ?? 8B 55 ?? 33 C9 0B C8 89 55 ?? 89 4D ?? 83 FB ?? 75 ?? 0B C3 5F 5E 5B 8B + 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 6A ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B + F0 FF 15 ?? ?? ?? ?? 33 C9 03 F0 83 C6 ?? 0F 92 C1 F7 D9 0B CE 51 E8 ?? ?? ?? ?? 8B + F0 83 C4 ?? 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 50 FF 75 ?? + 56 E8 ?? ?? ?? ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 E8 + ?? ?? ?? ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 85 C9 0F 8C ?? ?? + ?? ?? 8B 45 ?? 0F 8F ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 85 C9 0F 8F ?? ?? + ?? ?? 7C ?? 3D ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 8B 55 ?? 8D + 4D ?? D1 E8 89 45 ?? E8 ?? ?? ?? ?? 0F B6 4F ?? 0F 57 C0 0F B6 47 ?? C1 E1 ?? 0B C8 } $encrypt_files_p2 = { - 02 16 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 02 17 9A 28 ?? ?? ?? ?? 13 ?? 02 - 18 9A 28 ?? ?? ?? ?? 2C ?? 02 18 9A 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 02 18 9A 1B 19 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 02 18 - 9A 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 2A 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 08 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 12 ?? 6F ?? ?? ?? ?? 26 07 72 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 18 8D ?? ?? - ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 00 - 1B 8D ?? ?? ?? ?? 25 16 28 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 08 20 ?? ?? ?? - ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 72 ?? ?? ?? ?? A2 - 25 1A 11 ?? 08 11 ?? 8E 69 6F ?? ?? ?? ?? 9A A2 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 11 ?? 6F ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 16 6F - ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 - ?? 1F ?? 3F ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 16 6F ?? ?? ?? ?? 25 17 - 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 2A + 66 0F 13 45 ?? 0F B6 47 ?? C1 E1 ?? 0B C8 C7 45 ?? ?? ?? ?? ?? 0F B6 07 C1 E1 ?? 0B + C8 C7 45 ?? ?? ?? ?? ?? 0F B6 47 ?? 89 4D ?? 0F B6 4F ?? C1 E1 ?? 0B C8 0F B6 47 ?? + 6A ?? 6A ?? FF 75 ?? C1 E1 ?? FF 75 ?? 0B C8 0F B6 47 ?? 8B 3D ?? ?? ?? ?? C1 E1 ?? + 0B C8 53 89 4D ?? FF D7 33 F6 8D 45 ?? 56 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 0F 1F 40 ?? FF 75 ?? BA ?? ?? ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 33 C0 F7 D9 13 C0 6A ?? 6A ?? F7 D8 50 51 53 FF D7 6A + ?? 8D 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 8B 45 ?? 03 F0 3B 75 ?? 0F 87 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 6A ?? 8D + 45 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? E9 ?? ?? ?? + ?? 85 C9 7F ?? 7C ?? 3D ?? ?? ?? ?? 73 ?? 8B 75 ?? 8B CB 57 8B D6 E8 ?? ?? ?? ?? 8B + 3D ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B 75 ?? 8B CB 57 8B D6 E8 ?? ?? ?? ?? 8B 3D + ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 0F B6 4F ?? 0F + } + $encrypt_files_p3 = { + 57 C0 0F B6 47 ?? C1 E1 ?? 0B C8 66 0F 13 45 ?? 0F B6 47 ?? C1 E1 ?? 0B C8 C7 45 ?? + ?? ?? ?? ?? 0F B6 07 C1 E1 ?? 0B C8 C7 45 ?? ?? ?? ?? ?? 0F B6 47 ?? 89 4D ?? 0F B6 + 4F ?? C1 E1 ?? 0B C8 0F B6 47 ?? 6A ?? 6A ?? FF 75 ?? C1 E1 ?? FF 75 ?? 0B C8 0F B6 + 47 ?? 8B 3D ?? ?? ?? ?? C1 E1 ?? 0B C8 53 89 4D ?? FF D7 8B 35 ?? ?? ?? ?? 8D 45 ?? + 6A ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF D6 85 C0 74 ?? FF 75 ?? BA ?? ?? ?? ?? + 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 33 C0 F7 D9 13 C0 6A ?? 6A ?? F7 D8 50 51 + 53 FF D7 6A ?? 8D 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? + 81 7D ?? ?? ?? ?? ?? 72 ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF D6 + 85 C0 75 ?? 8B 75 ?? 6A ?? 0F 57 C0 6A ?? 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 53 FF D7 + 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 C7 45 ?? ?? ?? ?? ?? 83 C4 ?? 89 55 ?? C7 + 45 ?? ?? ?? ?? ?? 85 D2 74 ?? 8B FA B9 ?? ?? ?? ?? F3 A5 8B 4D ?? 68 ?? ?? ?? ?? 8B + 01 8B 49 ?? 89 82 ?? ?? ?? ?? 8D 45 ?? 50 52 6A ?? 6A ?? 6A ?? FF 75 ?? 89 8A ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 8B 75 ?? 85 C0 74 ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 56 53 FF 15 + ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 EB ?? 83 CE ?? 85 DB 74 ?? 53 FF 15 ?? + ?? ?? ?? 8B 7D ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? EB ?? 8B 7D ?? 57 E8 ?? ?? ?? ?? 8B + 4D ?? 83 C4 ?? 8B C6 33 CD 5F 5E 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } $find_files_p1 = { - 73 ?? ?? ?? ?? 0A 06 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 72 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2D ?? 72 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 2C ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 0C 28 ?? ?? ?? ?? 16 28 ?? ?? - ?? ?? 02 8E 39 ?? ?? ?? ?? 02 16 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 16 0D - 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 17 0D 20 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 1F ?? 1B 28 ?? ?? ?? ?? 25 6F ?? ?? ?? ?? 13 ?? 6F ?? ?? ?? ?? 13 ?? 28 - ?? ?? ?? ?? 72 ?? ?? ?? ?? 08 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? - 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 25 11 ?? 16 11 - ?? 8E 69 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 8D ?? ?? ?? ?? 13 ?? 1C 8D ?? ?? ?? ?? 25 16 - 72 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 72 ?? ?? ?? ?? - A2 25 1A 72 ?? ?? ?? ?? A2 25 1B 72 ?? ?? ?? ?? A2 13 ?? 1F ?? 8D ?? ?? ?? ?? 25 16 72 - ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 72 ?? ?? ?? ?? A2 - 25 1A 72 ?? ?? ?? ?? A2 25 1B 72 ?? ?? ?? ?? A2 25 1C 72 ?? ?? ?? ?? A2 25 1D 72 ?? ?? - ?? ?? A2 25 1E 72 ?? ?? ?? ?? A2 25 1F ?? 72 ?? ?? ?? ?? A2 25 1F ?? 72 + FF 74 B4 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 46 83 + FE ?? 7C ?? FF 74 24 ?? FF D7 68 ?? ?? ?? ?? 8B F0 FF D7 03 F0 8D 84 24 ?? ?? ?? ?? + 6A ?? 50 FF D7 8D 0C 06 33 C0 83 C1 ?? 0F 92 C0 F7 D8 0B C1 50 E8 ?? ?? ?? ?? 8B F0 + 83 C4 ?? 85 F6 0F 84 ?? ?? ?? ?? FF 74 24 ?? FF D7 48 50 FF 74 24 ?? 56 E8 ?? ?? ?? + ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 56 E8 ?? ?? + ?? ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? + 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 8B 7C 24 ?? 83 C4 ?? 83 C7 ?? 57 FF 15 ?? ?? ?? + ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B C8 83 C4 ?? 85 C9 74 ?? 8B 54 24 ?? C7 01 ?? ?? ?? + ?? C7 41 ?? ?? ?? ?? ?? 83 7A ?? ?? 75 ?? 89 4A ?? 89 4A ?? 57 89 31 FF 15 ?? ?? ?? + ?? E9 ?? ?? ?? ?? 8B 42 ?? 89 48 ?? 8B 42 ?? 8B 40 ?? 89 42 ?? 89 30 57 FF 15 ?? ?? + ?? ?? E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 33 F6 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 74 B4 ?? 8D 84 24 } $find_files_p2 = { - A2 13 ?? 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 6F ?? ?? ?? ?? 1C 32 ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? - 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 72 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? - 72 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 13 ?? - 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 72 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? - ?? ?? 2C ?? 12 ?? 11 ?? 8E 69 17 58 28 ?? ?? ?? ?? 11 ?? 11 ?? 16 6F ?? ?? ?? ?? 11 ?? - A2 2B + 50 FF D3 85 C0 0F 85 ?? ?? ?? ?? 46 83 FE ?? 7C ?? 6A ?? FF 74 24 ?? FF D7 8B F0 8D + 84 24 ?? ?? ?? ?? 50 FF D7 03 F0 33 C0 83 C6 ?? 0F 92 C0 F7 D8 0B C6 50 E8 ?? ?? ?? + ?? 8B F0 83 C4 ?? 85 F6 0F 84 ?? ?? ?? ?? FF 74 24 ?? FF D7 48 50 FF 74 24 ?? 56 E8 + ?? ?? ?? ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 56 + E8 ?? ?? ?? ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? 56 E8 ?? ?? ?? ?? EB ?? 6A ?? 6A ?? E8 ?? ?? + ?? ?? 8B D8 83 C4 ?? 85 DB 75 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 57 EB ?? 57 68 ?? ?? ?? + ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 53 6A ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? + 85 C0 74 ?? 8B 54 24 ?? 53 57 56 E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? + 57 E8 ?? ?? ?? ?? 83 C4 ?? 53 E8 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 83 C4 ?? 8B 35 ?? ?? + ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 74 24 ?? FF 15 + } + $create_crypt_context = { + 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? + ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 83 C8 ?? 8B 4D ?? 33 CD E8 ?? ?? ?? + ?? 8B E5 5D C2 ?? ?? 56 8B 35 ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? + ?? 6A ?? 50 FF D6 85 C0 75 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 8D 45 ?? 50 FF + D6 85 C0 75 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 8D 45 ?? 50 FF D6 85 C0 75 ?? + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 8D 45 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 6A + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? 68 ?? ?? ?? ?? 56 6A ?? + FF 15 ?? ?? ?? ?? 8D 45 ?? 89 35 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D + 04 45 ?? ?? ?? ?? 50 FF 35 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? + ?? ?? ?? 85 C0 75 ?? 50 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 8B 45 ?? 5E 85 C0 74 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? + 33 C0 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($internal_encrypt_file) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($create_crypt_context) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Ladon : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Blackbasta : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Ladon ransomware." + description = "Yara rule that detects BlackBasta ransomware." author = "ReversingLabs" - id = "ebc8f957-cdcf-54eb-bd02-74088cf51768" - date = "2020-07-15" - modified = "2020-07-15" + id = "7c451fde-b8b1-5a35-855e-7e30f3e75cbb" + date = "2022-12-13" + modified = "2022-12-13" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Ladon.yara#L1-L101" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "979e3f3bf6a67bf10b6bfdd2eeb722d8836096076b7e88c6d4aca041a1a9eecb" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.BlackBasta.yara#L1-L531" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "c68671e51489af00e9e0cf28373e5ec01bda042653dbcca8843357eede41f27f" score = 75 - quality = 90 + quality = 88 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" status = "RELEASED" sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Ladon" + tc_detection_name = "BlackBasta" tc_detection_factor = 5 importance = 25 strings: $find_files = { - F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 - 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 - 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? - 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 57 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? 8D 85 - ?? ?? ?? ?? 53 56 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 FF 85 DB 74 ?? 90 8B 45 ?? 8B - 34 B8 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 66 8B 08 66 3B 0E 75 ?? 66 85 C9 74 ?? - 66 8B 48 ?? 66 3B 4E ?? 75 ?? 83 C0 ?? 83 C6 ?? 66 85 C9 75 ?? 33 C0 EB ?? 1B C0 83 - C8 ?? 85 C0 74 ?? 47 3B FB 72 ?? 8B 75 ?? 8B 7D ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF - 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 75 ?? 33 DB 83 F8 ?? 0F - 95 C3 FF 15 ?? ?? ?? ?? 5E 8B C3 5B 5F 8B E5 5D C3 - } - $encrypt_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 FF 75 ?? 33 DB 89 5D ?? E8 ?? ?? ?? ?? 8B F8 83 - C4 ?? 89 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 83 3F ?? 0F 85 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? - FF 77 ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 0F 84 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? FF - 77 ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? FF - 77 ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? FF - 77 ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? FF - 77 ?? E8 ?? ?? ?? ?? 8B C8 83 C4 ?? 89 4D ?? 85 C9 0F 84 ?? ?? ?? ?? 83 3E ?? 0F 85 - ?? ?? ?? ?? 8B 45 ?? 83 38 ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 83 38 ?? 0F 85 ?? ?? ?? ?? - 8B 45 ?? 83 38 ?? 0F 85 ?? ?? ?? ?? 83 39 ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 70 - ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? FF 75 ?? 33 FF C7 45 - ?? ?? ?? ?? ?? 89 5D ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? 83 3E ?? 75 ?? 57 - 68 ?? ?? ?? ?? FF 76 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? FF 70 ?? 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 - ?? 8D 45 ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? 8D 7B ?? A1 ?? - ?? ?? ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 1D ?? ?? ?? ?? 85 F6 74 ?? 56 E8 - ?? ?? ?? ?? 83 C4 ?? 8B C7 5F 5E 5B 8B E5 5D C3 FF 76 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 78 ?? 85 FF 74 ?? 8B 47 ?? 89 45 + 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? + ?? 83 C4 ?? 8B F0 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B C6 + E9 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 41 ?? 2B 01 C1 F8 ?? 89 85 ?? ?? ?? ?? 89 9D ?? + ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 + 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 + ?? 8A 48 ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? + ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? + 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 } - $encrypt_files_p2 = { - 8B 70 ?? 8D 4E ?? 8A 06 46 84 C0 75 ?? 2B F1 8D 04 75 ?? ?? ?? ?? 50 6A ?? FF 15 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 84 9D ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 0C 75 - ?? ?? ?? ?? 51 50 8D 46 ?? 50 8B 45 ?? FF 70 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 3F - 43 85 FF 75 ?? 68 ?? ?? ?? ?? C7 84 9D ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? E8 ?? ?? ?? ?? 8B 7D ?? 8B 77 ?? 8D 4E ?? 8A 06 46 84 C0 75 ?? 2B F1 8D 46 ?? 50 - 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B C8 89 4D ?? 85 C9 0F 84 ?? ?? ?? ?? - 8B C6 99 6A ?? 2B C2 D1 F8 6A ?? 89 45 ?? 8D 45 ?? 50 51 6A ?? 56 FF 77 ?? FF 15 ?? - ?? ?? ?? 8B 7D ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 57 8B 7D ?? 8B F0 57 56 FF 15 ?? ?? ?? ?? 56 FF 15 - ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 57 6A ?? FF 15 ?? ?? - ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 45 ?? FF 70 ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? - ?? ?? 8B 7D ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 05 ?? ?? ?? - ?? ?? ?? ?? ?? 85 FF 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 85 DB 74 ?? FF B4 B5 ?? - ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 46 3B F3 72 ?? 8B 45 ?? 5F 5E - 5B 8B E5 5D C3 + $encrypt_files_v1 = { + 6A ?? E8 ?? ?? ?? ?? 8B F8 89 BD ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 89 B5 ?? ?? + ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 57 E8 ?? ?? ?? ?? 6A ?? 57 56 E8 ?? ?? ?? ?? 8D 4F + ?? 6A ?? 51 53 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A + ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 FF B5 ?? ?? ?? ?? 57 53 56 83 EC ?? 8B F4 89 A5 + ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 6A ?? 56 8D 4D ?? E8 ?? + ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A + ?? FF B5 ?? ?? ?? ?? 57 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? + ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 + ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 80 BD ?? ?? ?? ?? ?? + 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 } - $remote_connection = { - 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 50 68 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B E5 5D C3 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - C6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 85 C0 0F 88 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 78 ?? 56 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? - 85 F6 74 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? - 83 C4 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5E 8B E5 5D C3 + $cmd_prompt = { + 8B FF 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? ?? ?? ?? ?? FC 53 56 8B 75 ?? 8D 45 ?? 33 DB + 68 ?? ?? ?? ?? 53 50 89 5D ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 83 F8 ?? 0F 84 ?? + ?? ?? ?? 85 F6 75 ?? 53 39 5D ?? 75 ?? E8 ?? ?? ?? ?? 59 33 C0 E9 ?? ?? ?? ?? FF 75 + ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 E8 ?? ?? ?? ?? 33 C0 83 C4 ?? 85 F6 0F 94 C0 E9 ?? + ?? ?? ?? 8B 45 ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 89 75 ?? 89 5D ?? 57 85 C0 74 ?? E8 + ?? ?? ?? ?? 8B 38 E8 ?? ?? ?? ?? 53 89 18 8D 45 ?? 50 FF 75 ?? 53 E8 ?? ?? ?? ?? 83 + C4 ?? 8B F0 E8 ?? ?? ?? ?? 83 FE ?? 74 ?? 89 38 EB ?? 83 38 ?? 74 ?? E8 ?? ?? ?? ?? + 83 38 ?? 74 ?? 83 CE ?? FF 75 ?? E8 ?? ?? ?? ?? 59 EB ?? E8 ?? ?? ?? ?? 89 38 53 8D + 45 ?? B9 ?? ?? ?? ?? 50 51 53 89 4D ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 E8 ?? ?? ?? ?? + 83 C4 ?? 8B C6 5F 8B 4D ?? 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 53 + } + $ldap_connect = { + C6 45 ?? ?? 8D 45 ?? 83 7D ?? ?? 0F 43 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? + 50 6A ?? 53 8B 35 ?? ?? ?? ?? FF D6 C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 53 FF D6 + 6A ?? 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 83 C4 ?? + 85 C0 74 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? + 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 83 C4 ?? + 8B F0 89 75 ?? 8D 45 ?? 50 8D 45 ?? 50 6A ?? 6A ?? 56 53 FF 15 ?? ?? ?? ?? 83 C4 ?? + 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 0F 84 ?? + ?? ?? ?? FF 75 ?? 57 53 FF 15 ?? ?? ?? ?? 83 C4 ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? 8B + 06 85 C0 0F 84 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? 50 8B 4D + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 36 68 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? 8B C8 89 4D ?? 8B 01 8B 40 ?? C6 45 ?? ?? 8B 44 08 ?? 8B 58 ?? 89 5D + ?? 8B 03 8B CB FF 50 ?? 83 4D ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 10 6A ?? + 8B C8 FF 52 ?? 0F B7 C0 89 45 ?? 83 65 ?? ?? C6 45 ?? ?? 85 DB 74 ?? 8B 03 8B CB FF + 50 ?? 8B C8 85 C9 74 ?? 8B 01 6A ?? FF 10 8B 45 ?? 50 8B 4D ?? E8 ?? ?? ?? ?? 8B 4D + ?? E8 ?? ?? ?? ?? 8B 5D ?? 56 FF 15 + } + $encrypt_files_v2 = { + 8D 45 ?? 50 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 6A ?? 57 53 FF 75 ?? 83 EC ?? 8B + F4 89 A5 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 6A ?? 56 8D 4D + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 8B 45 ?? 89 45 ?? 6A ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF 75 + ?? 57 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 E8 + ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 + } + $encrypt_files_v3 = { + 6A ?? E8 ?? ?? ?? ?? 8B F8 89 BD ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 89 B5 ?? ?? + ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 57 E8 ?? ?? ?? ?? 6A ?? 57 56 E8 ?? ?? ?? ?? 8D 4F + ?? 6A ?? 51 53 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A + ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 6A ?? 57 53 56 83 EC ?? 8B F4 89 A5 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 6A ?? 56 8D 4D ?? E8 ?? ?? ?? ?? C6 + 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF B5 ?? + ?? ?? ?? 57 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 57 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 53 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? + 83 C4 ?? C6 45 ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 + ?? ?? 8D 8D ?? ?? ?? ?? E8 + } + $encrypt_files_v4 = { + 8D 45 ?? 50 E8 ?? ?? ?? ?? 0F 10 45 ?? 0F 11 45 ?? 0F 10 45 ?? 0F 11 45 ?? 8B 45 ?? + 8B 4D ?? 89 45 ?? 89 4D ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? + 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 56 57 8D 45 ?? 50 8D 45 ?? 50 83 EC ?? 8B + F4 89 A5 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 6A ?? 56 8D 4D + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 6A ?? FF B5 ?? ?? ?? ?? 57 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 + ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? EB ?? 8D 85 + ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? C6 45 ?? ?? + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? C6 45 ?? ?? 8B 8D ?? ?? ?? ?? 83 F9 ?? 72 ?? 8D 0C 4D ?? ?? ?? ?? 89 8D ?? ?? + ?? ?? 8B 95 ?? ?? ?? ?? 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 8B + 50 ?? 2B C2 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 66 89 85 ?? ?? FF FF C6 + 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 + } + $drop_ransom_note_v1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? 03 00 00 A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? 45 FC 00 00 00 00 + 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 + BD ?? ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A + ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 + BD ?? ?? ?? ?? ?? 74 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? + 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? + 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 + 5D C3 + } + $exclude_from_encryption_v1 = { + 83 FE ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D + ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 FE ?? 0F 85 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 50 E8 + ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 FE ?? 0F 85 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B + F0 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 FE ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D + 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? + 8D 4D ?? E8 ?? ?? ?? ?? 83 FE ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? 83 FE ?? 75 ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D + } + $exclude_from_encryption_v2_p1 = { + 50 C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 05 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? + ?? ?? C6 45 ?? ?? 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B F0 C6 + 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 FE ?? 74 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + C6 45 ?? ?? 6A ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 FE ?? 74 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E9 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 8D 4D ?? + E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 FE ?? 74 ?? C6 + } + $exclude_from_encryption_v2_p2 = { + 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B F0 C6 45 ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 FE ?? 74 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 51 8B C8 E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 8D 4D + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? FF B5 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? B9 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 84 C0 0F 44 CA 8D 45 ?? 50 E8 ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 80 BD ?? ?? ?? + ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? C6 45 ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 + } + $encrypt_files_v5_p1 = { + 50 F2 0F 11 45 ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 74 ?? 8D 45 ?? 50 56 FF 15 ?? ?? + ?? ?? 85 C0 75 ?? 56 FF 15 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? + 8B 8D ?? ?? ?? ?? 85 C9 74 ?? 8B 01 6A ?? FF 10 C7 45 ?? ?? ?? ?? ?? 8D 4B ?? E8 ?? + ?? ?? ?? 8B 4D ?? 5F 64 89 0D ?? ?? ?? ?? 5E 8B E5 5D 8B E3 5B C2 ?? ?? 8B 7D ?? 83 + C1 ?? 8B 35 ?? ?? ?? ?? 8B 45 ?? E9 ?? ?? ?? ?? 8B 45 ?? 8D 8D ?? ?? ?? ?? 8B 7D ?? + 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? 8D 8D ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 89 45 ?? 83 E0 ?? 03 C1 C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? + C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 6A ?? + E8 ?? ?? ?? ?? 6A ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 89 45 ?? C6 45 ?? ?? 6A ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 89 45 ?? C6 45 ?? ?? B9 ?? ?? ?? ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 6A ?? + FF 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF 75 ?? 6A ?? FF 75 ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? 6A ?? FF 75 ?? 83 + } + $encrypt_files_v5_p2 = { + C0 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 85 C0 0F 8F ?? ?? ?? ?? 7C ?? 81 FF ?? ?? + ?? ?? 0F 83 ?? ?? ?? ?? F2 0F 10 05 ?? ?? ?? ?? F2 0F 11 45 ?? 0F 57 C0 66 0F 13 45 + ?? 8B 4D ?? 8B 55 ?? 89 4D ?? 8B CF 89 55 ?? 2B 4D ?? 6A ?? 6A ?? 1B C2 50 51 E8 ?? + ?? ?? ?? F2 0F 10 45 ?? 8B CA F2 0F 59 05 ?? ?? ?? ?? 89 4D ?? 8B C8 89 45 ?? F2 0F + 11 45 ?? E8 ?? ?? ?? ?? F2 0F 59 45 ?? E8 ?? ?? ?? ?? 8B C8 0B CA 0F 85 ?? ?? ?? ?? + 39 4D ?? 0F 8C ?? ?? ?? ?? 7F ?? 85 FF 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? + 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 85 + C0 0F 8C ?? ?? ?? ?? 7F ?? 81 FF ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? F2 0F 10 05 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 89 45 ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? F2 0F 11 45 ?? 50 + E8 ?? ?? ?? ?? C6 45 ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 56 C6 45 ?? ?? 8B 4D + ?? E8 ?? ?? ?? ?? 8B 45 ?? 33 D2 C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 52 50 FF 75 ?? + FF 75 ?? E8 ?? ?? ?? ?? 8B C8 89 45 ?? 0B CA 89 55 ?? 75 ?? 8D 85 ?? ?? ?? ?? 89 45 + ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 50 FF 75 ?? 57 + 6A ?? 6A ?? 56 C6 45 ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 0F 57 + C0 66 0F 13 45 ?? 0F 8C ?? ?? ?? ?? 7F ?? 83 7D ?? ?? 0F 86 ?? ?? ?? ?? 8B 45 ?? 8B + 7D ?? 89 45 ?? 66 66 0F 1F 84 00 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? 8D 8D ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 8B CF 0F A4 C8 ?? 6A ?? C1 E1 ?? 03 + 4D ?? 6A ?? 13 45 ?? 50 51 56 C6 45 ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 03 7D ?? 8B 45 ?? + 13 45 ?? 89 45 ?? 3B 45 ?? 0F 8C ?? ?? ?? ?? 7F ?? 3B 7D ?? 0F 82 + } + $encrypt_files_v6_p1 = { + E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 85 F6 0F 8F ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 6A + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 03 48 ?? 8B 01 FF 50 ?? 83 7B ?? ?? 8D 43 ?? + F2 0F 10 05 ?? ?? ?? ?? 0F 43 43 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? + ?? ?? 50 F2 0F 11 45 ?? FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 74 ?? 8D 45 ?? 50 57 FF 15 + ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C6 45 ?? ?? 8B 8D ?? ?? ?? ?? 85 C9 74 ?? 8B 01 6A ?? FF 10 C6 45 ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? 8D 4B ?? E8 ?? ?? ?? ?? 8B 4D ?? 5F 64 89 0D ?? ?? ?? ?? 5E 8B E5 5D 8B E3 5B + C2 ?? ?? 85 F6 0F 84 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 8B CF 76 ?? 8B FE 2B 7D ?? 66 + 8B 04 0F 66 3B 01 75 ?? 83 C1 ?? 83 EA ?? 75 ?? 2B 75 ?? D1 FE E9 ?? ?? ?? ?? 8B 7D + ?? 83 C6 ?? 8B 15 ?? ?? ?? ?? 8B 45 ?? E9 ?? ?? ?? ?? 8B 45 ?? 8D 8D ?? ?? ?? ?? 8B + 75 ?? 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 + } + $encrypt_files_v6_p2 = { + 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? 8D 8D + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 89 45 ?? 83 E0 ?? 03 C1 C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 89 85 ?? ?? + ?? ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? + 6A ?? E8 ?? ?? ?? ?? 6A ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 89 45 ?? C6 45 ?? ?? 6A ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 C4 ?? 89 45 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? FF 75 ?? E8 ?? ?? ?? + ?? 6A ?? FF 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF 75 ?? 6A ?? FF 75 ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? 6A ?? + FF 75 ?? 83 C0 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 85 C0 0F 8F ?? ?? ?? ?? 7C + } + $encrypt_files_v6_p3 = { + 81 FE ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? F2 0F 10 05 ?? ?? ?? ?? F2 0F 11 45 ?? 0F 57 C0 + 66 0F 13 45 ?? 8B 4D ?? 8B 55 ?? 89 4D ?? 8B CE 89 55 ?? 2B 4D ?? 6A ?? 6A ?? 1B C2 + 50 51 E8 ?? ?? ?? ?? F2 0F 10 45 ?? 8B CA F2 0F 59 05 ?? ?? ?? ?? 89 4D ?? 8B C8 89 + 45 ?? F2 0F 11 45 ?? E8 ?? ?? ?? ?? F2 0F 59 45 ?? E8 ?? ?? ?? ?? 8B C8 0B CA 0F 85 + ?? ?? ?? ?? 39 4D ?? 0F 8C ?? ?? ?? ?? 7F ?? 85 F6 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 89 45 ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? E9 ?? + ?? ?? ?? 85 C0 0F 8C ?? ?? ?? ?? 7F ?? 81 FE ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? F2 0F 10 + 05 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? F2 0F + 11 45 ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 57 C6 45 + ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 33 D2 C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 52 + 50 FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B C8 89 45 ?? 0B CA 89 55 ?? 75 ?? 8D 85 ?? ?? + ?? ?? 89 45 ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 50 + FF 75 ?? 56 6A ?? 6A ?? 57 C6 45 ?? ?? 8B 4D + } + $set_default_icon_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? 83 EC ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 + 89 45 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? + ?? B0 ?? C7 45 ?? ?? ?? ?? ?? 33 C9 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 98 + 66 31 44 4D ?? 41 83 F9 ?? 73 ?? 8A 45 ?? EB ?? 33 C0 56 66 89 45 ?? C6 45 ?? ?? 8D + 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B F0 C7 45 + ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 56 50 C7 45 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 33 C0 C7 46 ?? ?? ?? ?? ?? 83 C4 ?? C7 46 ?? ?? ?? ?? ?? 66 89 06 C7 45 ?? + ?? ?? ?? ?? C6 45 ?? ?? 8B 4D ?? 83 F9 ?? 72 ?? 8B 55 ?? 8D 0C 4D ?? ?? ?? ?? 8B C2 + } + $set_default_icon_p2 = { + 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? + 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 51 8D 4D ?? C7 45 ?? ?? + ?? ?? ?? 51 6A ?? 68 ?? ?? ?? ?? 33 C0 83 7D ?? ?? 6A ?? 66 89 45 ?? 8D 45 ?? 0F 43 + 45 ?? 6A ?? 6A ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 83 7D ?? ?? 8D 4D + ?? 8B 45 ?? 0F 43 4D ?? 03 C0 50 51 6A ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF + 75 ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF D6 6A + ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D6 B8 ?? ?? ?? ?? 89 45 ?? 83 E0 ?? 89 45 + ?? C6 45 ?? ?? 8B 4D ?? 5E 83 F9 ?? 72 ?? 8B 55 ?? 8D 0C 4D ?? ?? ?? ?? 8B C2 81 F9 + ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 77 ?? 51 52 E8 ?? ?? ?? + ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C7 45 ?? ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 8B E5 5D C3 + } + $find_system_volumes = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? 81 EC ?? ?? + ?? ?? 53 56 57 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 75 ?? C7 06 ?? ?? ?? ?? + C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B F8 66 90 + 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? F7 45 ?? ?? ?? ?? ?? 0F 85 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 D2 C7 45 ?? ?? ?? ?? ?? 66 89 55 ?? + 83 C4 ?? 8D 95 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 0C 00 C7 45 ?? ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 03 C1 C7 45 ?? ?? ?? ?? ?? 3B D0 74 ?? D1 F9 8B C2 + 51 50 8D 4D ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 8B 46 ?? 3B 46 ?? 74 ?? + 6A ?? 51 50 C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 83 46 ?? ?? 66 89 45 ?? + EB ?? 51 50 8B CE E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 4D ?? 83 F9 ?? 72 ?? 8B 55 ?? 8D 0C + 4D ?? ?? ?? ?? 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 + ?? 77 ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? 66 89 45 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF D3 85 C0 0F 85 ?? ?? ?? ?? + 57 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B C6 5F 5E 5B 64 89 0D ?? ?? ?? ?? 8B E5 5D C3 + } + $drop_ransom_note_v2_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? 83 EC ?? 53 + 56 57 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 7D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? B9 ?? ?? ?? ?? 8B D8 2B CF 83 C4 ?? 3B CB 0F 82 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? + 8D 0C 3B C7 45 ?? ?? ?? ?? ?? 0F 43 45 ?? BE ?? ?? ?? ?? 89 45 ?? 8D 45 ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 4D ?? 89 45 ?? 3B CE 76 ?? 8B F1 83 CE ?? 81 FE + ?? ?? ?? ?? 76 ?? BE ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? 3B F0 0F 42 F0 8D 46 ?? 50 8D + 4D ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 0C 3B 89 45 ?? 89 75 ?? 8D 34 3F 56 FF 75 ?? 89 4D + ?? 50 E8 ?? ?? ?? ?? 8B 7D ?? 8D 04 1B 50 68 ?? ?? ?? ?? 8D 0C 3E 51 E8 ?? ?? ?? ?? + 8B 45 ?? 33 C9 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 66 89 0C 47 C6 45 ?? ?? B8 ?? ?? ?? ?? + 83 3D ?? ?? ?? ?? ?? 8D 4D ?? FF 35 ?? ?? ?? ?? 0F 43 05 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 8B F0 C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 56 50 C7 45 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? 83 C4 ?? 66 + } + $drop_ransom_note_v2_p2 = { + 89 06 BE ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 75 ?? 83 E6 ?? 89 75 ?? C6 45 ?? ?? 8B + 4D ?? 83 F9 ?? 72 ?? 8B 55 ?? 8D 0C 4D ?? ?? ?? ?? 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 8B + 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 51 52 E8 ?? ?? ?? ?? 83 C4 + ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 6A ?? 66 89 45 + ?? 8D 45 ?? 0F 43 45 ?? 6A ?? 68 ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 8B F8 83 FF ?? 74 ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? + ?? 57 FF 15 ?? ?? ?? ?? 83 E6 ?? 89 75 ?? C6 45 ?? ?? 8B 4D ?? 5F 5E 5B 83 F9 ?? 72 + ?? 8B 55 ?? 8D 0C 4D ?? ?? ?? ?? 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B + C2 83 C0 ?? 83 F8 ?? 77 ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D + ?? 64 89 0D ?? ?? ?? ?? 8B E5 5D C3 + } + $encrypt_files_v5 = { + 50 FF 15 ?? ?? ?? ?? 8B D8 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 C3 ?? 74 + ?? C6 45 ?? ?? 80 7D ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 + ?? ?? 8D 8D ?? ?? ?? ?? 51 8B C8 E8 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 4D ?? E8 ?? ?? ?? + ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D + ?? ?? ?? ?? 51 8B C8 E8 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D + 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B F8 83 FF ?? 75 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 8D 0C 41 89 4D ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 89 45 ?? 89 45 ?? 8D + 04 78 89 45 ?? 51 50 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 8D 45 + } + $find_system_volumes_v2_p1 = { + C7 45 ?? ?? ?? ?? ?? 89 7D ?? FF 15 ?? ?? ?? ?? 8B D8 8D 45 ?? 50 68 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A + ?? 6A ?? 8D 45 ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 85 C0 0F 84 ?? ?? ?? ?? F7 45 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 51 8D 8D ?? ?? ?? ?? 8D 04 41 50 8B C1 8D 4D ?? 50 + E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8B 4D ?? 3B 4D ?? 74 ?? 6A ?? 56 51 C7 01 ?? ?? ?? + ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 46 ?? ?? ?? + ?? ?? C7 46 ?? ?? ?? ?? ?? C6 06 ?? 83 45 ?? ?? EB ?? 56 51 8D 4D ?? E8 ?? ?? ?? ?? + C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? + ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 75 ?? 33 C9 89 4D ?? B8 ?? + ?? ?? ?? 8B 4D ?? 2B CE F7 E9 C1 FA ?? 8B C2 C1 E8 ?? 03 C2 0F 84 ?? ?? ?? ?? 33 DB + 8D 4D ?? 8D 04 33 89 4D ?? C6 45 ?? ?? 8D 4D ?? 51 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 8D 4D ?? 83 CF ?? 89 7D ?? C7 45 ?? ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? C6 45 ?? + ?? 83 E7 ?? 89 7D ?? C6 45 ?? ?? 8D 45 ?? 8B 35 ?? ?? ?? ?? 3B 35 ?? ?? ?? ?? 74 ?? + 6A ?? 50 56 89 75 ?? C7 06 ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C6 + } + $find_system_volumes_v2_p2 = { + 45 ?? ?? 8B 45 ?? 89 46 ?? C6 45 ?? ?? 83 05 ?? ?? ?? ?? ?? EB ?? 50 56 B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 4D ?? 83 F9 ?? 72 ?? 8B 55 ?? 8D 0C 4D ?? ?? ?? ?? + 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? + ?? ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 33 C0 8B 75 ?? 83 C3 ?? FF 45 ?? 2B CE + 66 89 45 ?? B8 ?? ?? ?? ?? F7 E9 C7 45 ?? ?? ?? ?? ?? C1 FA ?? 8B C2 C7 45 ?? ?? ?? + ?? ?? C1 E8 ?? 03 C2 39 45 ?? 0F 82 ?? ?? ?? ?? 83 E7 ?? 89 7D ?? C7 45 ?? ?? ?? ?? + ?? 8D 4D ?? E8 ?? ?? ?? ?? 5F 5B EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 68 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 6A ?? C7 45 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? F3 + 0F 7E 05 ?? ?? ?? ?? 8B F0 2B 75 ?? 66 0F D6 45 ?? 90 8B 55 ?? 8B 4D ?? E8 ?? ?? ?? + ?? 83 3D ?? ?? ?? ?? ?? F2 0F 10 0D ?? ?? ?? ?? F2 0F 59 C1 F2 0F 59 C1 F2 0F 59 C1 + F2 0F 11 45 ?? 74 ?? E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 3B C8 74 ?? 6A ?? 51 FF 35 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 0F 57 C0 66 0F 13 05 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? F2 0F 10 45 ?? 83 EC ?? F2 0F 11 44 24 ?? 66 0F 6E C6 + F3 0F E6 C0 C1 EE } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($remote_connection) + uint16(0)==0x5A4D and ((($find_files) and ($encrypt_files_v1) and ($cmd_prompt) and ($exclude_from_encryption_v1)) or (($find_files) and ($cmd_prompt) and ($ldap_connect) and ($encrypt_files_v2) and ($exclude_from_encryption_v1)) or (($find_files) and ($cmd_prompt) and ($ldap_connect) and ($encrypt_files_v3) and ($exclude_from_encryption_v1)) or (($find_files) and ($encrypt_files_v4) and ($drop_ransom_note_v1) and ( all of ($exclude_from_encryption_v2_p*))) or (($find_files) and ($exclude_from_encryption_v1) and ( any of ($encrypt_files_v5)) and ( all of ($find_system_volumes_v2_p*))) or (( all of ($encrypt_files_v5_p*)) and ( all of ($set_default_icon_p*)) and ($find_system_volumes) and ( all of ($drop_ransom_note_v2_p*)) and ($find_files)) or (( all of ($encrypt_files_v6_p*)) and ( all of ($set_default_icon_p*)) and ( all of ($drop_ransom_note_v2_p*)) and ($find_files))) } -rule REVERSINGLABS_Win32_Ransomware_Regretlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Winword64 : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects RegretLocker ransomware." + description = "Yara rule that detects WinWord64 ransomware." author = "ReversingLabs" - id = "c4e515cc-b0c2-57b2-a230-619ec01ac8d4" - date = "2021-04-02" - modified = "2021-04-02" + id = "a5f7967d-58f4-5fdd-b67f-5f5dbfec0f4b" + date = "2021-02-11" + modified = "2021-02-11" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.RegretLocker.yara#L1-L206" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3927dfecacd74f60a169f82b68df5747daa90eaba77f24c5e730ce4c48d426a3" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.WinWord64.yara#L1-L215" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "73d8c4f1b3bed365320b26332f1f1b49404d8e6536f3e25042f5f64e5bc09bd4" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -28049,193 +29948,201 @@ rule REVERSINGLABS_Win32_Ransomware_Regretlocker : TC_DETECTION MALICIOUS MALWAR sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "RegretLocker" + tc_detection_name = "WinWord64" tc_detection_factor = 5 importance = 25 strings: $remote_connection_p1 = { - 55 8B EC 8B 41 ?? 8B 55 ?? 3B C2 72 ?? 2B C2 56 8B 75 ?? 3B C6 0F 42 F0 83 79 ?? ?? - 72 ?? 8B 09 56 03 CA 51 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 5E 5D C2 ?? ?? E8 ?? - ?? ?? ?? CC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 83 65 ?? ?? 8D 45 ?? 53 - 56 57 50 E8 ?? ?? ?? ?? 83 65 ?? ?? 50 E8 ?? ?? ?? ?? 83 4D ?? ?? 8A D8 59 59 8D 4D - ?? E8 ?? ?? ?? ?? 84 DB 0F 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? - C7 45 ?? ?? ?? ?? ?? 8B CC 6A ?? 83 61 ?? ?? C7 41 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 88 - 19 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 - E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 59 59 8B 8D ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 6A ?? 5B 3B CB C6 45 ?? ?? 0F 43 C2 80 78 ?? - ?? 75 ?? 3B CB 8D 85 ?? ?? ?? ?? 0F 43 C2 80 78 ?? ?? 75 ?? 3B CB 8D 85 ?? ?? ?? ?? - 0F 43 C2 80 78 ?? ?? 75 ?? 3B CB 8D 85 ?? ?? ?? ?? 0F 43 C2 80 78 ?? ?? 75 ?? 3B CB - 8D 85 ?? ?? ?? ?? 0F 43 C2 80 78 ?? ?? 75 ?? 83 BD ?? ?? ?? ?? ?? 0F 84 + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? A1 ?? ?? ?? + ?? 33 DB 83 3D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 0F 43 0D ?? ?? ?? ?? + 03 C1 89 9D ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 43 0D ?? ?? ?? ?? 51 + 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 53 89 5D ?? 8D 85 ?? ?? ?? ?? 83 BD ?? ?? + ?? ?? ?? 53 0F 43 85 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? + 85 DB 0F 84 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? A1 ?? ?? ?? ?? 0F 43 0D + ?? ?? ?? ?? 03 C1 83 3D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 43 0D ?? ?? ?? ?? 51 50 51 + 8D 4D ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 6A ?? 0F 43 45 ?? 68 ?? ?? ?? ?? 50 53 + FF 15 ?? ?? ?? ?? 8B 55 ?? 8B D8 89 9D ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 + ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? + 76 ?? FF 15 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? 66 89 45 ?? 85 DB 0F 84 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? B9 ?? ?? + ?? ?? A1 ?? ?? ?? ?? 0F 43 0D ?? ?? ?? ?? 03 C1 83 3D ?? ?? ?? ?? ?? B9 } $remote_connection_p2 = { - 8D 45 ?? 50 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B C8 C7 04 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 84 C0 75 ?? 8B BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 3B FB 8D B5 ?? ?? ?? ?? 8B 9D - ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 0F 43 C3 83 FF ?? 0F 43 F3 0F 43 D3 33 C9 8A 40 ?? 3A - 46 ?? 0F BE 42 ?? 0F 94 C1 3B C8 75 ?? 83 FF ?? 8D 85 ?? ?? ?? ?? 0F 43 C3 80 78 ?? - ?? 75 ?? 83 FF ?? 8D 85 ?? ?? ?? ?? 0F 43 C3 80 78 ?? ?? 74 ?? 32 DB EB ?? B3 ?? F6 - 45 ?? ?? 74 ?? 8D 4D ?? E8 ?? ?? ?? ?? 84 DB 74 ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 6A ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 5F 6A ?? 33 DB 89 BD - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 89 65 ?? 53 89 59 ?? 89 79 ?? 68 ?? ?? ?? ?? - 88 19 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 8D 85 ?? ?? ?? ?? 50 89 59 ?? 89 59 - ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B B5 ?? ?? ?? ?? C6 45 ?? ?? 83 FE ?? 77 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 84 C0 74 ?? 6A ?? 5E 83 EC ?? 8B CC 89 65 ?? 53 89 59 ?? 89 79 ?? 68 ?? ?? - ?? ?? 88 19 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 8D 85 ?? ?? ?? ?? 50 89 59 ?? - 89 59 ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 + 0F 43 0D ?? ?? ?? ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D BD ?? + ?? ?? ?? 83 BD ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? A1 ?? ?? ?? ?? 0F 43 BD ?? ?? ?? ?? 83 + 3D ?? ?? ?? ?? ?? 0F 43 0D ?? ?? ?? ?? 03 C1 83 3D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F + 43 0D ?? ?? ?? ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 85 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 57 53 FF 15 ?? ?? ?? + ?? 8B 55 ?? 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? + 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 + E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 88 45 ?? 8B 95 ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? + ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 ?? + FF 15 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? C6 45 ?? ?? 8D 4D ?? 83 7D ?? ?? 8B 45 ?? 0F 43 4D ?? 03 C1 83 7D ?? ?? 8D 4D + ?? 0F 43 4D ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? + ?? 83 BD ?? ?? ?? ?? ?? 8D 4D ?? 68 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? B9 ?? ?? + ?? ?? 83 3D ?? ?? ?? ?? ?? 8B 75 ?? 8B C6 0F 43 0D ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B } $remote_connection_p3 = { - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 83 EE ?? 75 ?? 8B B5 ?? ?? ?? ?? 8D 46 ?? 83 F8 ?? 77 ?? 68 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 50 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 59 59 89 5D ?? 89 7D ?? 88 9D ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 89 - 5D ?? 89 5D ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 59 8B - F0 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 89 5D ?? 89 7D ?? 88 5D ?? E8 ?? ?? ?? - ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 56 83 C1 ?? - E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? FF 35 ?? - ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 59 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 + 55 ?? 2B C2 57 51 3B F8 77 ?? 8D 04 3A 83 FE ?? 89 45 ?? 8D 45 ?? 0F 43 45 ?? 8D 34 + 10 56 E8 ?? ?? ?? ?? 83 C4 ?? C6 04 37 ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 + ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 75 ?? 8B C6 + 8B BD ?? ?? ?? ?? 0F 43 CF 8B 55 ?? 2B C2 8B 9D ?? ?? ?? ?? 53 51 3B D8 77 ?? 8D 04 + 1A 83 FE ?? 89 45 ?? 8D 45 ?? 0F 43 45 ?? 8D 34 10 56 E8 ?? ?? ?? ?? 83 C4 ?? C6 04 + 1E ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8B BD + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? B9 ?? ?? ?? ?? 83 3D ?? ?? + ?? ?? ?? 8B 75 ?? 8B C6 0F 43 0D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 55 ?? 2B C2 53 51 + 3B D8 77 ?? 8D 04 1A 83 FE ?? 89 45 ?? 8D 45 ?? 0F 43 45 ?? 8D 34 10 56 E8 ?? ?? ?? + ?? 83 C4 ?? C6 04 33 ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? 53 E8 + ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B 45 ?? 0F 43 + D3 8B 75 ?? 2B C6 8B 8D ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D 04 0E 89 45 ?? + 8D 45 ?? 0F 43 45 ?? 03 F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? C6 04 06 ?? + EB ?? C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 8B 9D ?? ?? + ?? ?? 83 3D ?? ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 8B } $remote_connection_p4 = { - 89 5D ?? 89 7D ?? 88 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D - ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? 50 83 C1 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 51 51 8B CC 89 65 ?? 8D 45 ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? 50 8D 45 ?? 89 4D ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 6A - ?? 89 59 ?? C7 41 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 88 19 E8 ?? ?? ?? ?? 8D 45 ?? C6 45 - ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? 8B 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 0F 43 85 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 74 ?? 50 53 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 85 ?? ?? ?? ?? 8B 75 ?? 0F 43 85 ?? ?? - ?? ?? 6A ?? 6A ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 74 ?? 40 8D 8D ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 8B 75 ?? 56 E8 ?? ?? ?? ?? 59 53 FF 75 ?? 8D 8D ?? ?? ?? ?? A3 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 4D ?? A1 ?? ?? ?? ?? 68 ?? ?? ?? ?? 88 1C 01 E8 ?? ?? - ?? ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? A3 ?? ?? ?? ?? 59 8B 75 ?? - 8D 4D ?? C6 45 ?? ?? FF 76 ?? E8 ?? ?? ?? ?? 8B 45 ?? C6 45 ?? ?? 89 70 ?? 8B 45 ?? - 89 30 8B 45 ?? 89 70 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 58 50 68 ?? ?? ?? ?? 83 EC ?? 89 + 45 ?? 8B 75 ?? 2B C6 89 8D ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D 04 0E 89 45 + ?? 8D 45 ?? 0F 43 45 ?? 03 F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? C6 04 30 + ?? EB ?? C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 8B 95 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B D0 83 78 ?? ?? 72 ?? 8B 10 + 8B 48 ?? 8B 45 ?? 8B 75 ?? 2B C6 89 8D ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D + 04 0E 89 45 ?? 8D 45 ?? 0F 43 45 ?? 03 F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 + ?? C6 04 30 ?? EB ?? C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? + ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? + ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 ?? FF 15 ?? ?? ?? ?? 52 + 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? BA ?? ?? ?? ?? 83 3D + ?? ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 8B 45 ?? 8B 75 ?? 2B C6 89 8D + ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D 04 0E 89 45 ?? 8D 45 ?? 0F 43 45 ?? 03 + F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? C6 04 30 ?? EB ?? C6 85 ?? ?? ?? ?? + ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 55 ?? 8B 4D ?? 0F 43 + 55 ?? 8B 45 ?? 8B 75 ?? 2B C6 89 8D ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D 04 + 0E 89 45 ?? 8D 45 ?? 0F 43 45 ?? 03 F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? + C6 04 30 ?? EB ?? C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? + 83 3D ?? ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 8B 45 ?? + 8B 75 ?? 2B C6 89 8D ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D 04 31 89 45 ?? 8D } $remote_connection_p5 = { - 5D ?? 8B CC FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B F8 6A ?? 58 - FF 35 ?? ?? ?? ?? 85 FF 0F 44 F8 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 59 6A ?? 5E 6A ?? 68 - ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 89 5D ?? 89 75 ?? 88 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? - C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? 50 83 C1 ?? E8 - ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? - ?? ?? ?? 8D 4D ?? 89 5D ?? 89 75 ?? 88 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 - 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 85 ?? ?? ?? ?? 50 83 C1 ?? E8 ?? ?? - ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 8B F0 6A ?? - 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 89 5D ?? C7 45 ?? ?? ?? ?? ?? 88 5D ?? E8 ?? ?? - ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 56 83 C1 - ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 45 - ?? 50 E8 ?? ?? ?? ?? 59 8B F0 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 89 5D ?? C7 - 45 ?? ?? ?? ?? ?? 88 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D - ?? E8 ?? ?? ?? ?? 8B 4D ?? 56 83 C1 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D - ?? C6 45 ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 45 ?? 57 50 E8 ?? ?? ?? ?? 83 C4 - ?? 8B F0 6A ?? 58 6A ?? 5F 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? 88 45 ?? 89 5D ?? 89 7D ?? - 88 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? - 8B 4D ?? 56 83 C1 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 - ?? ?? ?? ?? 51 51 8B CC 89 65 ?? 8D 45 ?? 89 4D ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 - EC ?? C6 45 ?? ?? 8B CC 6A ?? 89 59 ?? 89 79 ?? 68 ?? ?? ?? ?? 88 19 E8 + 45 ?? 0F 43 45 ?? 03 F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? C6 04 30 ?? EB + ?? C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? + ?? 85 F6 74 ?? 8B 45 ?? 8D 4D ?? 83 7D ?? ?? 6A ?? 0F 43 4D ?? 50 50 51 6A ?? FF B5 + ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 8D ?? + ?? ?? ?? 51 68 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 F6 8B 35 ?? + ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 50 FF D6 8B 85 ?? ?? ?? ?? 85 C0 74 ?? 50 FF D6 8B + 85 ?? ?? ?? ?? 85 C0 74 ?? 50 FF D6 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA + ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 + E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + C6 45 ?? ?? 83 F8 ?? 72 ?? 8D 48 ?? 8B C3 81 F9 ?? ?? ?? ?? 72 ?? 8B 5B ?? 83 C1 ?? + 2B C3 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 51 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? + ?? ?? 83 F8 ?? 72 ?? 8D 48 ?? 8B C7 81 F9 ?? ?? ?? ?? 72 ?? 8B 7F ?? 83 C1 ?? 2B C7 + } + $remote_connection_p6 = { + 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 51 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? + 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 + F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 + ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? + 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 4D ?? + 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 + 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? + ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 ?? FF 15 ?? ?? ?? ?? 52 + 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD + E8 ?? ?? ?? ?? 8B E5 5D C3 } $encrypt_files_p1 = { - 8B FB 89 5D ?? 89 7D ?? 89 5D ?? 8B 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? C6 45 ?? ?? 89 - 45 ?? 3B F0 74 ?? 56 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 3B DF 74 ?? - 8B 08 89 0F 8B 48 ?? 89 4F ?? 83 20 ?? 83 60 ?? ?? 83 C7 ?? 89 7D ?? EB ?? 50 57 8D - 4D ?? E8 ?? ?? ?? ?? 8B 5D ?? 8B 7D ?? 83 7D ?? ?? C6 45 ?? ?? 0F 85 ?? ?? ?? ?? 6A - ?? 58 03 F0 3B 75 ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8B B5 ?? ?? ?? ?? - C6 45 ?? ?? 8B 06 89 45 ?? EB ?? 8D 48 ?? 8D 41 ?? 50 51 68 ?? ?? ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? C6 45 ?? ?? 3B DF 74 ?? 8B 08 89 0F 8B 48 ?? 89 4F ?? 83 20 ?? 83 60 ?? - ?? 83 C7 ?? 89 7D ?? EB ?? 50 57 8D 4D ?? E8 ?? ?? ?? ?? 8B 5D ?? 8B 7D ?? 83 7D ?? - ?? C6 45 ?? ?? 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 3B C6 75 ?? 8B 75 - ?? EB ?? 83 7E ?? ?? 74 ?? 8B CE E8 ?? ?? ?? ?? 83 C6 ?? 3B F7 75 ?? 0F 57 C0 68 ?? - ?? ?? ?? 66 0F 13 45 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 2B 05 ?? ?? ?? ?? 6A ?? 59 99 - F7 F9 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 83 C4 ?? 8B 1D ?? ?? ?? ?? 8B - 75 ?? 8B 7D ?? 89 45 ?? 3B D8 74 ?? 83 EC ?? 8B CC 53 83 61 ?? ?? 83 61 ?? ?? E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 03 F8 83 D6 ?? 6A ?? 58 03 D8 3B 5D ?? 75 ?? 0F AC - F7 ?? C1 EE ?? 56 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 C4 ?? 8B 35 - ?? ?? ?? ?? EB ?? 83 7E ?? ?? 8B C6 72 ?? 8B 06 6A ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 6A ?? 58 03 F0 3B F7 75 ?? 68 ?? ?? ?? ?? E8 + FF 15 ?? ?? ?? ?? 83 7D ?? ?? 8D 55 ?? 8B 4D ?? 0F 43 55 ?? 03 CA 89 85 ?? ?? ?? ?? + 83 7D ?? ?? 8D 45 ?? 51 0F 43 45 ?? 51 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 83 + 7F ?? ?? 72 ?? 8B 3F 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? + ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 + ?? FF 15 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? 83 7D ?? ?? 8D 4D ?? 66 89 85 ?? ?? ?? ?? 0F 43 4D ?? 8B 45 ?? 03 C1 C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 0F 43 4D ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B F0 83 7E ?? ?? 72 ?? 8B 36 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? + ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 + C0 ?? 83 F8 ?? 76 ?? FF 15 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 50 6A ?? 68 ?? ?? ?? ?? 57 8B 3D ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? FF D7 89 85 ?? ?? ?? ?? 83 + F8 ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 56 FF + D7 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C9 BA } $encrypt_files_p2 = { - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 53 56 8B 75 ?? 8D 8D ?? ?? ?? ?? 57 - 56 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 33 DB 50 8D 45 ?? 89 5D ?? 50 E8 ?? ?? ?? ?? 59 - 59 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8B CC 6A ?? 89 59 ?? C7 41 - ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 88 19 E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? 8A D8 E8 ?? ?? ?? ?? 84 DB 74 ?? 33 DB E9 ?? - ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 59 59 85 - C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? - ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? 83 EC ?? 33 DB 8B CC 89 5D ?? 56 E8 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 89 45 ?? B9 ?? ?? ?? ?? BF ?? ?? ?? ?? 3B C1 0F 42 C8 3B C7 89 - 4D ?? 0F 42 F8 89 7D ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 39 9D ?? ?? ?? ?? 75 ?? 83 EC ?? 8B CC 56 E8 ?? ?? ?? - ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 83 7E ?? ?? C6 45 ?? ?? 72 ?? 8B 36 E8 - ?? ?? ?? ?? FF 30 E8 ?? ?? ?? ?? 56 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D - ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 77 ?? 56 E8 ?? ?? ?? ?? 56 89 45 ?? E8 ?? ?? ?? - ?? 8B 4D ?? 56 53 51 89 45 ?? E8 ?? ?? ?? ?? 56 53 FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? - 83 C4 ?? 89 5D ?? 8B D3 85 C0 0F 84 ?? ?? ?? ?? 8B C8 2B CA 39 4D ?? 8B C1 8B F1 0F - 46 45 ?? 3B F9 89 45 ?? 0F 46 F7 8B 7D ?? 2B CE 89 75 ?? 39 4D ?? 0F 46 4D ?? 89 4D - ?? 85 FF 75 ?? 53 56 FF 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 0C 3E 8B + 8D 40 ?? F7 E2 0F 90 C1 F7 D9 0B C8 51 E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? BA ?? ?? + ?? ?? 8B 0D ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 03 CA 89 85 ?? ?? ?? ?? 83 3D ?? ?? ?? + ?? ?? B8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 0F 43 05 ?? ?? ?? ?? 51 50 8B CE E8 ?? ?? ?? + ?? A1 ?? ?? ?? ?? 83 C4 ?? 33 C9 68 ?? ?? ?? ?? 6A ?? 56 66 89 0C 46 8D 85 ?? ?? ?? + ?? 51 50 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? FF B5 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 + 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? + ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 + C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 0F 82 ?? ?? ?? ?? 8B 4D ?? 42 + 8B C1 81 FA ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? + 0F 86 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? + FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? + 8D 45 ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? E9 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? + 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 FF 33 F6 57 FF B5 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 57 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 } $encrypt_files_p3 = { - C4 89 4D ?? 89 08 8D 8D ?? ?? ?? ?? 89 58 ?? 89 58 ?? 89 58 ?? 89 58 ?? 89 58 ?? E8 - ?? ?? ?? ?? 53 FF 75 ?? 8D 8D ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 FF 75 - ?? 8D 8D ?? ?? ?? ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 EC ?? 8B D4 8B D8 - 33 C0 03 CF 89 0A 8D 8D ?? ?? ?? ?? 89 42 ?? 89 42 ?? 89 42 ?? 89 42 ?? 89 42 ?? E8 - ?? ?? ?? ?? 6A ?? FF 75 ?? 8D 8D ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8B 7D ?? 2B 75 ?? 03 - 7D ?? 56 57 E8 ?? ?? ?? ?? 59 59 6A ?? 56 57 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 - ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? 2B 45 ?? 01 45 ?? 53 E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 83 C4 ?? 8B 40 ?? 8B 84 05 ?? ?? ?? ?? C1 E8 ?? A8 ?? 74 ?? 83 EC ?? - 8B CC FF 75 ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 83 7E ?? ?? - C6 45 ?? ?? 72 ?? 8B 36 E8 ?? ?? ?? ?? FF 30 E8 ?? ?? ?? ?? 56 50 68 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8B 7D ?? - 89 55 ?? 6A ?? 5B 3B D0 0F 82 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? - E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 59 59 FF 75 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 EC - ?? C6 45 ?? ?? 8B CC 6A ?? 89 59 ?? C7 41 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 88 19 E8 ?? - ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 8B 48 ?? C6 45 ?? ?? 72 ?? - 8B 00 51 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? - 8D 45 ?? 0F 43 45 ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC 50 89 59 ?? - 89 59 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? B3 ?? E8 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? FF 75 ?? 56 E8 ?? ?? ?? ?? 59 59 8A D8 8D 4D ?? E8 - ?? ?? ?? ?? 8B 4D ?? 8A C3 5F 5E 64 89 0D ?? ?? ?? ?? 5B C9 C3 + 8B 85 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 03 F8 8D 85 ?? ?? ?? ?? 3B + BD ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 0F 44 F1 50 6A ?? 56 6A ?? FF B5 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 + FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 + ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? + ?? 6A ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + B9 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? + ?? 8B 35 ?? ?? ?? ?? FF D6 FF B5 ?? ?? ?? ?? FF D6 C6 85 ?? ?? ?? ?? ?? E9 ?? ?? ?? + ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8A 85 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 + 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } $find_files = { - 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 83 C8 ?? 57 8B 7D ?? - 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? - ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? - FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 4D ?? - 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 C0 50 - 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 - 89 45 ?? 8B 4D ?? 53 8B 5D ?? 56 8B 75 ?? 57 89 B5 ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 - ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 53 E8 ?? ?? ?? ?? 59 59 8B C8 3B CB 75 ?? 8A 11 80 FA - ?? 75 ?? 8D 43 ?? 3B C8 74 ?? 56 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 FF - 80 FA ?? 74 ?? 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8B C7 EB ?? 33 C0 40 0F B6 C0 2B CB 41 - F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? - ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 - FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? - 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 - 74 ?? 80 F9 ?? 75 ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? - ?? 85 C0 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B - C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 - ?? E9 + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F9 89 BD ?? ?? ?? ?? 33 C0 89 + 85 ?? ?? ?? ?? 38 47 ?? 0F 85 ?? ?? ?? ?? 8B 07 8B 08 8D 85 ?? ?? ?? ?? 50 8D 49 ?? + E8 ?? ?? ?? ?? 83 38 ?? 0F 85 ?? ?? ?? ?? 83 7F ?? ?? 74 ?? 8B 07 8B 08 8D 85 ?? ?? + ?? ?? 50 8D 49 ?? E8 ?? ?? ?? ?? 83 38 ?? 0F 84 ?? ?? ?? ?? 8B 07 8D 8D ?? ?? ?? ?? + 8B 30 8D 46 ?? 50 E8 ?? ?? ?? ?? 8D 46 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? B8 ?? ?? ?? + ?? 8B 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? + ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 + ?? FF 15 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 07 8B + 30 8B 46 ?? 8B 00 85 C0 74 ?? 8D 8D ?? ?? ?? ?? 51 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 83 C4 ?? 66 83 38 ?? 75 ?? 8B 46 ?? FF 30 FF 15 ?? ?? ?? ?? 8B 46 ?? 83 C4 + ?? C7 00 ?? ?? ?? ?? EB ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D + 4E ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? C6 45 ?? ?? 81 7F ?? ?? ?? ?? ?? 8B 37 8B 36 75 ?? 68 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 8B 46 ?? 89 85 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? C6 45 ?? ?? 6A ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 8D 85 ?? ?? ?? ?? 8D 4F ?? 50 E8 } condition: uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Horsedeal : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Sigrun : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Horsedeal ransomware." + description = "Yara rule that detects Sigrun ransomware." author = "ReversingLabs" - id = "c722bc5b-756e-5d46-8530-e20ebb73737c" - date = "2020-10-01" - modified = "2020-10-01" + id = "fa627192-ed80-5115-a028-014f67f4571d" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Horsedeal.yara#L1-L106" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "fa8c425b08606399b5dc7673f3898e3dba7efb6a62e56db8f500cf5072bb590b" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Sigrun.yara#L1-L111" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ea29ec64cdfc0c714fe0acdce5878cb1302dd5aa916811121c644948ce275935" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -28243,94 +30150,101 @@ rule REVERSINGLABS_Win32_Ransomware_Horsedeal : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Horsedeal" + tc_detection_name = "Sigrun" tc_detection_factor = 5 importance = 25 strings: - $search_processes = { - 55 8B EC 81 EC ?? ?? ?? ?? 56 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 74 ?? 8D - 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 53 - FF 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF B5 ?? ?? ?? - ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 74 ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 53 FF - 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5B 56 FF 15 ?? - ?? ?? ?? 5E C9 C3 + $find_files = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 83 7D ?? ?? 53 56 57 8B DA C7 44 24 ?? ?? ?? ?? + ?? 8B F1 75 ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 8B 7C 24 ?? 89 7C 24 ?? 85 C0 75 ?? 85 FF + 75 ?? 5F 5E 5B 8B E5 5D C3 C7 44 24 ?? ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? + A1 ?? ?? ?? ?? 89 44 24 ?? A1 ?? ?? ?? ?? 89 44 24 ?? 0F B7 06 66 89 44 24 ?? 83 F8 + ?? 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 56 + FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 8D 04 46 89 44 24 ?? FF D7 8D + 44 24 ?? 50 56 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 D2 89 44 24 ?? 66 89 11 83 F8 ?? 75 + ?? B8 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 + ?? 8D 44 24 ?? 50 56 FF D7 F6 44 24 ?? ?? 74 ?? 83 7C 24 ?? ?? 74 ?? BA ?? ?? ?? ?? + 8B CE E8 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF D7 6A ?? 8B D3 8B CE E8 ?? ?? + ?? ?? EB ?? 68 ?? ?? ?? ?? 56 FF D7 6A ?? 8B D3 8B CE E8 ?? ?? ?? ?? EB ?? 53 8D 54 + 24 ?? 8B CE E8 ?? ?? ?? ?? 83 C4 ?? 8B 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 + 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 5E + 33 C0 5B 8B E5 5D C3 } - $enum_resources = { - 55 8B EC 83 E4 ?? 83 EC ?? 83 0C 24 ?? 8D 44 24 ?? 53 56 57 50 FF 75 ?? C7 44 24 ?? - ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4C 24 ?? E8 ?? ?? ?? - ?? 8B F0 85 F6 74 ?? EB ?? 33 DB 39 5C 24 ?? 76 ?? 8D 7E ?? F6 47 ?? ?? 74 ?? 8D 47 - ?? 50 E8 ?? ?? ?? ?? EB ?? FF 37 E8 ?? ?? ?? ?? 43 83 C7 ?? 59 3B 5C 24 ?? 72 ?? 8D - 44 24 ?? 50 56 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B CE E8 ?? - ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 + $encrypt_files_1 = { + 55 8B EC 83 EC ?? 53 57 68 ?? ?? ?? ?? 8B FA 8B D9 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 5F 33 C0 5B 8B E5 5D C3 + 56 8D 45 ?? 33 F6 50 56 56 57 53 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 8D 45 ?? + C7 45 ?? ?? ?? ?? ?? 50 8D 45 ?? 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 45 ?? 68 ?? + ?? ?? ?? 50 FF 75 ?? C7 00 ?? ?? ?? ?? 56 6A ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 8B F0 + FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 68 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 8B C6 5E 5F 5B 8B E5 5D C3 } - $find_files = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 53 56 8B 35 ?? ?? ?? ?? 57 - 8B 7D ?? 74 ?? 68 ?? ?? ?? ?? 57 FF D6 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? - ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 53 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? - ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 8D 44 24 ?? 50 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 83 - C4 ?? A8 ?? 74 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? 68 ?? ?? ?? ?? 8D - 44 24 ?? 50 FF D6 85 C0 74 ?? 53 E8 ?? ?? ?? ?? 59 EB ?? 8B 44 24 ?? A8 ?? 74 ?? 68 - ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? - 50 FF D6 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? 8B CB E8 ?? ?? - ?? ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 - ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? - ?? ?? 83 C4 ?? 33 FF 57 68 ?? ?? ?? ?? 6A ?? 57 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? - ?? ?? 8B F0 89 74 24 ?? 83 FE ?? 74 ?? 57 8B 3D ?? ?? ?? ?? 8D 44 24 ?? 50 68 ?? ?? - ?? ?? FF D7 50 68 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 6A ?? 8D 44 24 ?? 50 FF 35 - ?? ?? ?? ?? FF D7 8B 7C 24 ?? 50 FF 35 ?? ?? ?? ?? 57 FF D6 57 FF 15 ?? ?? ?? ?? 8B - CB E8 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 + $encrypt_files_2 = { + 55 8B EC 53 56 57 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B DA 8B F9 FF 15 ?? ?? + ?? ?? 57 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 C4 ?? 8B CF E8 ?? ?? ?? ?? 85 + C0 74 ?? 68 ?? ?? ?? ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 33 C0 5F 5E 5B 5D C3 8B CF E8 ?? + ?? ?? ?? 85 C0 75 ?? 83 7B ?? ?? 72 ?? 8B 55 ?? 8B CF E8 ?? ?? ?? ?? 85 C0 74 ?? 56 + 57 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 5F 5E B8 ?? ?? ?? ?? + 5B 5D C3 } - $encrypt_files_p1 = { - 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 56 8B 35 ?? ?? ?? ?? 57 FF 35 ?? ?? ?? ?? - 8B F9 89 7D ?? FF D6 FF 35 ?? ?? ?? ?? 8B D8 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 50 FF - D6 3B C3 0F 84 ?? ?? ?? ?? 6A ?? 59 33 DB 89 4D ?? 8B C3 88 9C 05 ?? ?? ?? ?? 40 3D - ?? ?? ?? ?? 72 ?? 8D 85 ?? ?? ?? ?? 50 51 FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 - 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CB 89 45 ?? 8A 84 0D ?? ?? ?? ?? 88 44 0D ?? - 41 83 F9 ?? 72 ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 53 6A ?? 53 FF 35 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 6A ?? 58 50 53 6A ?? 68 ?? ?? ?? ?? - 57 89 45 ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 83 65 ?? ?? 57 FF D6 - 8D 0C 47 83 E9 ?? 66 83 39 ?? 75 ?? FF 35 ?? ?? ?? ?? 2B CF 83 C1 ?? D1 F9 8D 04 4F - 50 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? FF 35 ?? ?? ?? ?? FF D6 FF 75 ?? 8B F0 FF - 15 ?? ?? ?? ?? 3B C6 75 ?? 33 F6 46 EB ?? 8B 75 ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? - 8B 4D ?? 8B 45 ?? 85 C9 7F ?? 7C ?? 3D ?? ?? ?? ?? 77 ?? 33 F6 46 85 F6 74 ?? 8B 35 - ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + $encrypt_files_3 = { + 55 8B EC 83 EC ?? 56 57 E8 ?? ?? ?? ?? 85 C0 75 ?? 83 C8 ?? 5F 5E 8B E5 5D C3 8D 45 + ?? 50 8D 45 ?? 50 8D 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 8D 4D ?? 8B D7 E8 + ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 85 C0 74 ?? 8B 4D ?? 85 C9 74 ?? 8B 45 ?? 85 C0 74 ?? + C6 04 08 ?? 8B 4D ?? 68 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 + ?? FF D6 8B CF E8 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 05 ?? ?? ?? ?? + ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D6 68 ?? ?? ?? ?? 6A ?? + 57 FF D6 5F 33 C0 5E 8B E5 5D C3 } - $encrypt_files_p2 = { - 53 FF 15 ?? ?? ?? ?? 6A ?? FF 75 ?? 8D 55 ?? 6A ?? FF 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 99 6A ?? 6A ?? 52 50 53 FF D7 6A ?? 8D 45 ?? 50 FF - 75 ?? 8D 85 ?? ?? ?? ?? 50 53 FF D6 81 7D ?? ?? ?? ?? ?? 74 ?? E9 ?? ?? ?? ?? 6A ?? - 6A ?? 51 0F 57 C0 50 66 0F 13 45 ?? E8 ?? ?? ?? ?? 8B 4D ?? 2D ?? ?? ?? ?? 8B 35 ?? - ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 DA ?? 89 45 ?? 8B 45 ?? 2D ?? ?? ?? ?? 89 55 ?? 89 45 - ?? 8D 45 ?? 83 D9 ?? 89 45 ?? 89 4D ?? 6A ?? 6A ?? FF 70 ?? FF 30 53 FF D7 6A ?? 8D - 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 6A ?? FF 75 ?? 8D - 55 ?? 6A ?? FF 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 99 6A - ?? 6A ?? 52 50 53 FF D7 6A ?? 8D 45 ?? 50 FF 75 ?? 8D 85 ?? ?? ?? ?? 50 53 FF D6 8B - 45 ?? 83 C0 ?? 83 6D ?? ?? 89 45 ?? 75 ?? 8B 7D ?? 0F 57 C0 6A ?? 6A ?? 66 0F 13 45 - ?? FF 75 ?? C7 45 ?? ?? ?? ?? ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A - ?? 8D 45 ?? 50 53 FF D6 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF - D6 53 FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 68 ?? ?? ?? - ?? 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 C4 ?? 56 57 FF 15 ?? ?? - ?? ?? 8B CE E8 ?? ?? ?? ?? 5F 5E 5B C9 C3 + $enum_resources_1 = { + 55 8B EC 83 E4 ?? 83 EC ?? 53 56 57 8B 3D ?? ?? ?? ?? 8B F1 6A ?? 68 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 6A ?? 89 54 24 ?? 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? FF D7 8B 1D ?? ?? + ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 85 F6 0F 85 ?? ?? + ?? ?? 8D 44 24 ?? 50 6A ?? 6A ?? 6A ?? 6A ?? FF D3 85 C0 0F 85 ?? ?? ?? ?? 8D 44 24 + ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 74 24 ?? 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF + 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 49 ?? 33 DB 39 5C 24 ?? 0F 86 + ?? ?? ?? ?? 8B 74 24 ?? 83 C6 ?? 83 7E ?? ?? 75 ?? 8B 06 6A ?? 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 6A ?? 89 44 24 ?? FF D7 8B F8 85 FF 74 ?? FF 74 24 ?? 68 ?? ?? ?? ?? 57 FF + 15 ?? ?? ?? ?? 8B 55 ?? 83 C4 ?? 8B CF 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? + 6A ?? 57 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? F6 46 ?? ?? 74 ?? FF 75 ?? 8B 54 24 ?? + 8D 4E ?? E8 ?? ?? ?? ?? 83 C4 ?? 43 83 C6 ?? 3B 5C 24 ?? 72 ?? 8D 44 24 ?? C7 44 24 + ?? ?? ?? ?? ?? 50 FF 74 24 ?? 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 74 24 ?? FF + } + $enum_resources_2 = { + 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 74 24 ?? FF 74 24 ?? FF + 15 ?? ?? ?? ?? 8D 44 24 ?? 50 56 6A ?? 6A ?? 6A ?? FF D3 8B F0 85 F6 0F 85 ?? ?? ?? + ?? 8B 74 24 ?? 8D 44 24 ?? 50 56 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 74 24 ?? + C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 9B ?? ?? ?? ?? + 33 DB 39 5C 24 ?? 0F 86 ?? ?? ?? ?? 83 C6 ?? 90 83 7E ?? ?? 75 ?? 8B 06 6A ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 89 44 24 ?? FF D7 8B F8 85 FF 74 ?? FF 74 24 ?? 68 ?? + ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B 55 ?? 83 C4 ?? 8B CF 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? + 68 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? F6 46 ?? ?? 74 ?? FF 75 ?? 8B 54 24 ?? 8D + 4E ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 3D ?? ?? ?? ?? 43 83 C6 ?? 3B 5C 24 ?? 72 ?? 8B 74 + 24 ?? 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 56 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? + 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF 74 24 + ?? FF 15 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 6A ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 8B + C6 5E 5B 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($enum_resources) and ($search_processes) and ($find_files) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ( all of ($enum_resources_*)) and ($find_files) and ( all of ($encrypt_files_*)) } -rule REVERSINGLABS_Win32_Ransomware_Ouroboros : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Chupacabra : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Ouroboros ransomware." + description = "Yara rule that detects ChupaCabra ransomware." author = "ReversingLabs" - id = "af0b9311-a7dd-56e8-a004-0828af5af5ef" - date = "2020-07-15" - modified = "2020-07-15" + id = "e44a101d-53c3-51f2-84ca-f6a5858c169b" + date = "2021-10-12" + modified = "2021-10-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Ouroboros.yara#L1-L175" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "b573f303318452010ff46f21a02b6290820f9a27bf4c51b72f6ed15263b5f433" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.ChupaCabra.yara#L1-L90" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "7f247778e0bd8057670abf42b2d1011ebae891ffcb21ebad50060f9a7986bf93" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -28338,158 +30252,81 @@ rule REVERSINGLABS_Win32_Ransomware_Ouroboros : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Ouroboros" + tc_detection_name = "ChupaCabra" tc_detection_factor = 5 importance = 25 strings: - $remote_connection_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 56 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 75 ?? 8D 8D ?? ?? ?? ?? 6A ?? 68 - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? - 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? - ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 - } - $remote_connection_p2 = { - C6 45 ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? - C6 45 ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 - ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8B - 95 ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? - ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? - ?? ?? 83 C4 ?? FF 75 ?? 8D 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 75 ?? 8D 8D ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 8D 45 ?? C6 85 ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? 50 8B CE C7 06 ?? ?? ?? ?? C6 46 ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 83 FA ?? - 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 - } - $remote_connection_p3 = { - F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? FF 70 ?? 8D 45 ?? 50 8B C8 E8 ?? ?? ?? ?? 6A ?? FF - 75 ?? E8 ?? ?? ?? ?? 8B 55 ?? 83 C4 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? - ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? - ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 - FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 - ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? FF 70 ?? 8D 45 ?? 50 8B C8 E8 ?? ?? ?? ?? 6A - ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 C4 ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? - ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 - ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 85 C9 74 ?? 8B 95 ?? ?? ?? - ?? 8B C1 2B D1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F - 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 C4 ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B C6 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $remote_connection_p4 = { - 8B 55 ?? C7 06 ?? ?? ?? ?? C6 46 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? - ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? - ?? ?? ?? 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? FF - 70 ?? 8D 45 ?? 50 8B C8 E8 ?? ?? ?? ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 55 ?? 83 C4 - ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 - 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA - ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 - E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? - ?? FF 70 ?? 8D 45 ?? 50 8B C8 E8 ?? ?? ?? ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 95 ?? - ?? ?? ?? 83 C4 ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? - 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 8D - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? - ?? ?? ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C1 2B D1 81 FA ?? ?? ?? ?? 0F - 82 ?? ?? ?? ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 86 ?? ?? ?? ?? E8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? E8 - } - $find_files = { - 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 83 C8 ?? 57 8B 7D ?? - 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? - ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? - FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 4D ?? - 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 C0 50 - 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 - 89 45 ?? 8B 4D ?? 53 8B 5D ?? 56 8B 75 ?? 57 89 B5 ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 - ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 53 E8 ?? ?? ?? ?? 59 59 8B C8 3B CB 75 ?? 8A 11 80 FA - ?? 75 ?? 8D 43 ?? 3B C8 74 ?? 56 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 FF - 80 FA ?? 74 ?? 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8B C7 EB ?? 33 C0 40 0F B6 C0 2B CB 41 - F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? - ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 - FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? - 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 - 74 ?? 80 F9 ?? 75 ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? - ?? 85 C0 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B - C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 - ?? E9 - } $encrypt_files_p1 = { - 83 EC ?? 8B 44 24 ?? 53 55 56 8B F1 89 44 24 ?? 57 8B 7C 24 ?? 8B 6E ?? 3B FD 77 ?? - 8B DE 83 FD ?? 72 ?? 8B 1E 57 50 53 89 7E ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 04 1F ?? 8B - C6 5F 5E 5D 5B 83 C4 ?? C2 ?? ?? 81 FF ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 8B DF 83 CB ?? - 81 FB ?? ?? ?? ?? 76 ?? BB ?? ?? ?? ?? EB ?? 8B CD B8 ?? ?? ?? ?? D1 E9 2B C1 3B E8 - 76 ?? BB ?? ?? ?? ?? EB ?? 8D 04 29 3B D8 0F 42 D8 33 C9 8B C3 83 C0 ?? 0F 92 C1 F7 - D9 0B C8 51 8B CE E8 ?? ?? ?? ?? 57 FF 74 24 ?? 89 44 24 ?? 50 89 7E ?? 89 5E ?? E8 - ?? ?? ?? ?? 8B 5C 24 ?? 83 C4 ?? C6 04 1F ?? 83 FD ?? 72 ?? 8B 06 45 81 FD ?? ?? ?? - ?? 72 ?? 8B 48 ?? 83 C5 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 8B C1 55 50 E8 ?? ?? ?? ?? - 83 C4 ?? 5F 89 1E 8B C6 5E 5D 5B 83 C4 ?? C2 ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? CC - CC CC CC CC 83 EC ?? 53 55 8B 6C 24 ?? 56 57 8B F9 8B 4C 24 ?? 89 4C 24 ?? 8B 5F ?? - 3B EB 77 ?? 89 7C 24 ?? 8B C7 83 FB ?? 72 ?? 8B 07 89 44 24 ?? 8D 34 6D + 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 7E ?? ?? ?? ?? 28 + ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 14 0A 14 0B 7E ?? ?? ?? ?? 7E ?? ?? + ?? ?? 73 ?? ?? ?? ?? 0C 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 09 73 ?? ?? ?? ?? 13 ?? 73 ?? + ?? ?? ?? 0A 06 08 06 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 11 ?? 28 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 06 06 6F ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 + ?? 11 ?? 16 73 ?? ?? ?? ?? 13 ?? 11 ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 0B DE + ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 11 ?? 2C ?? + 11 ?? 6F ?? ?? ?? ?? DC 06 2C ?? 06 6F ?? ?? ?? ?? DC 07 2A } $encrypt_files_p2 = { - 89 6F ?? 56 51 50 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 33 C9 66 89 0C 06 8B C7 5F 5E - 5D 5B 83 C4 ?? C2 ?? ?? 81 FD ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 8B F5 83 CE ?? 81 FE ?? - ?? ?? ?? 76 ?? BE ?? ?? ?? ?? EB ?? 8B CB B8 ?? ?? ?? ?? D1 E9 2B C1 3B D8 76 ?? BE - ?? ?? ?? ?? EB ?? 8D 04 19 3B F0 0F 42 F0 33 C9 8B C6 83 C0 ?? 0F 92 C1 F7 D9 0B C8 - 51 8B CF E8 ?? ?? ?? ?? 89 77 ?? 8D 34 6D ?? ?? ?? ?? 56 FF 74 24 ?? 89 44 24 ?? 50 - 89 6F ?? E8 ?? ?? ?? ?? 8B 6C 24 ?? 33 C0 83 C4 ?? 66 89 04 2E 83 FB ?? 72 ?? 8B 07 - 8D 1C 5D ?? ?? ?? ?? 81 FB ?? ?? ?? ?? 72 ?? 8B 48 ?? 83 C3 ?? 2B C1 83 C0 ?? 83 F8 - ?? 77 ?? 8B C1 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 2F 8B C7 5F 5E 5D 5B 83 C4 ?? C2 ?? - ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? CC 8B 44 24 ?? 83 EC ?? 83 E0 ?? 89 41 ?? 8B 49 ?? - 23 C8 75 ?? 83 C4 ?? C2 ?? ?? 56 F6 C1 ?? 74 ?? BE ?? ?? ?? ?? EB ?? F6 C1 ?? BE ?? - ?? ?? ?? B8 ?? ?? ?? ?? 0F 44 F0 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4C - 24 ?? 50 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 E8 ?? ?? ?? ?? 5E + 02 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6A 30 ?? 02 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 0A 02 06 28 ?? ?? ?? ?? 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 38 ?? ?? + ?? ?? 02 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6A 30 ?? 20 ?? ?? ?? ?? 8D ?? ?? + ?? ?? 0B 02 19 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0C 08 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? + ?? ?? ?? 0D 09 07 09 8E 69 28 ?? ?? ?? ?? DE ?? 08 2C ?? 08 6F ?? ?? ?? ?? DC 02 19 28 + ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 07 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? + ?? ?? ?? DC 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 26 02 28 + ?? ?? ?? ?? 13 ?? 11 ?? 17 5F 17 33 ?? 11 ?? 17 28 ?? ?? ?? ?? 13 ?? 02 11 ?? 28 ?? ?? + ?? ?? 02 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6A 30 ?? 02 28 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 13 ?? 02 11 ?? 28 ?? ?? ?? ?? 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 38 ?? ?? ?? ?? 02 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6A 30 ?? 20 ?? ?? ?? + ?? 8D ?? ?? ?? ?? 13 ?? 02 19 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 02 19 28 + ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F + ?? ?? ?? ?? DC 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? DE ?? 26 DE ?? + 2A } - $encrypt_files_angus_version = { - 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 03 C1 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 0F 43 - 8D ?? ?? ?? ?? 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? B9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 39 8D ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? C6 85 ?? ?? ?? ?? ?? 0F 42 8D ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 51 0F 43 85 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? - ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? - ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E8 + $find_files_p1 = { + 02 28 ?? ?? ?? ?? 0A 02 28 ?? ?? ?? ?? 0B 16 0C 2B ?? 06 08 9A 28 ?? ?? ?? ?? 72 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 08 9A 28 ?? ?? ?? ?? 08 17 58 0C 08 06 8E 69 32 ?? 16 0D + 2B ?? 07 09 9A 28 ?? ?? ?? ?? 09 17 58 0D 09 07 8E 69 32 ?? DE ?? 26 DE ?? 2A + } + $find_files_p2 = { + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? + ?? 1F ?? 8D ?? ?? ?? ?? 25 16 1E 28 ?? ?? ?? ?? A2 25 17 1F ?? 28 ?? ?? ?? ?? A2 25 18 + 1F ?? 28 ?? ?? ?? ?? A2 25 19 1F ?? 28 ?? ?? ?? ?? A2 25 1A 1F ?? 28 ?? ?? ?? ?? A2 25 + 1B 1B 28 ?? ?? ?? ?? A2 25 1C 1C 28 ?? ?? ?? ?? A2 25 1D 1F ?? 28 ?? ?? ?? ?? A2 25 1E + 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? + A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1B 28 ?? + ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? + 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? + A2 0A 16 0B 2B ?? 06 07 9A 28 ?? ?? ?? ?? 07 17 58 0B 07 06 8E 69 32 ?? 2A + } + $drop_ransom_note = { + 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 39 ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 1B 8D ?? ?? + ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 7E ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 7E + ?? ?? ?? ?? A2 25 1A 72 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 20 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 1B 8D ?? ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 7E ?? ?? ?? + ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 7E ?? ?? ?? ?? A2 25 1A 72 ?? ?? ?? ?? A2 28 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 26 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 26 73 ?? ?? ?? ?? 0A 7E ?? ?? ?? ?? 0B 06 07 6F ?? ?? ?? ?? 26 2A } condition: - uint16(0)==0x5A4D and ($find_files) and (( all of ($encrypt_files_p*)) or ($encrypt_files_angus_version)) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($drop_ransom_note) } -rule REVERSINGLABS_Win32_Ransomware_Balaclava : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Retis : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Balaclava ransomware." + description = "Yara rule that detects Retis ransomware." author = "ReversingLabs" - id = "1a17f2e8-f161-55bc-b44e-f8f47ebd9869" - date = "2020-10-01" - modified = "2020-10-01" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Balaclava.yara#L1-L113" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "01b43e6ea7ceebdbdda7e1f7c5bd2439a460b8aed4a1837755fa3679e9893ff3" + id = "3d1de7c2-abb7-5411-a598-6bc68229a22a" + date = "2021-08-12" + modified = "2021-08-12" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Retis.yara#L1-L74" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3e3429041acc5730b009916efbcd35c7cfd2b2877dc1d2cf980f7fb7d399d532" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -28497,104 +30334,70 @@ rule REVERSINGLABS_Win32_Ransomware_Balaclava : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Balaclava" + tc_detection_name = "Retis" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 55 8B EC 83 EC ?? 53 56 8B 75 ?? 33 D2 57 6A ?? 5B 8B 7E ?? 89 55 ?? 8D 4F ?? 66 8B - 07 03 FB 66 3B C2 75 ?? 2B F9 B9 ?? ?? ?? ?? D1 FF E8 ?? ?? ?? ?? 50 FF 76 ?? 89 45 - ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 50 FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B - 45 ?? 83 C0 ?? 89 45 ?? 8B D8 33 D2 8D 4B ?? 66 8B 03 83 C3 ?? 66 3B C2 75 ?? 2B D9 - D1 FB 8D 04 3B 3D ?? ?? ?? ?? 7C ?? 8D 04 45 ?? ?? ?? ?? 50 39 56 ?? 74 ?? FF 76 ?? - 52 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? EB ?? 52 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? - ?? ?? 39 46 ?? 74 ?? 89 46 ?? 8B 46 ?? 33 C9 66 89 0C 78 8B 55 ?? F7 02 ?? ?? ?? ?? - 0F 85 ?? ?? ?? ?? 33 D2 8B C2 6A ?? 89 45 ?? 59 89 4D ?? 3B C1 7F ?? 03 C1 8B 4D ?? - 99 2B C2 D1 F8 89 45 ?? 8B 14 85 ?? ?? ?? ?? 66 8B 01 66 3B 02 75 ?? 66 85 C0 74 ?? - 66 8B 41 ?? 66 3B 42 ?? 75 ?? 83 C1 ?? 83 C2 ?? 66 85 C0 75 ?? 33 D2 8B C2 EB ?? 1B - C0 83 C8 ?? 33 D2 85 C0 0F 84 ?? ?? ?? ?? 79 ?? 8B 4D ?? 8B 45 ?? 49 EB ?? 8B 45 ?? - 8B 4D ?? 40 89 45 ?? EB ?? 8B 45 ?? F6 00 ?? 0F 84 ?? ?? ?? ?? 8D 04 5D ?? ?? ?? ?? - 50 8B 46 ?? FF 75 ?? 8D 04 78 83 C0 ?? 50 E8 ?? ?? ?? ?? 8B 4E ?? 83 C4 ?? 8B 46 ?? - 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 - ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7E ?? ?? 74 - ?? 83 7E ?? ?? 7E ?? FF 76 ?? 8B 4E ?? FF 76 ?? E8 ?? ?? ?? ?? 59 59 8B 4E ?? 8D 14 - } - $find_files_p2 = { - 3B A1 ?? ?? ?? ?? 56 89 44 51 ?? 66 A1 ?? ?? ?? ?? 66 89 44 51 ?? FF 46 ?? E8 ?? ?? - ?? ?? FF 4E ?? E9 ?? ?? ?? ?? 39 56 ?? 0F 85 ?? ?? ?? ?? 8D 04 5D ?? ?? ?? ?? 50 8B - 46 ?? FF 75 ?? 8D 04 78 83 C0 ?? 50 E8 ?? ?? ?? ?? 8B 5E ?? 83 C4 ?? 8B CB B8 ?? ?? - ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? - 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B CB 8D - 51 ?? 66 8B 01 83 C1 ?? 66 3B 45 ?? 75 ?? 2B CA D1 F9 83 F9 ?? 72 ?? 8B CB 8D 51 ?? - 66 8B 01 83 C1 ?? 66 3B 45 ?? 75 ?? 2B CA D1 F9 83 C1 ?? 68 ?? ?? ?? ?? 8D 04 4B 50 - FF 15 ?? ?? ?? ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 00 A8 ?? 74 ?? 83 E0 ?? - 50 FF 76 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BB ?? ?? ?? ?? 53 FF - 15 ?? ?? ?? ?? EB ?? 85 C0 75 ?? 6A ?? 53 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 0D ?? - ?? ?? ?? 6A ?? 58 3B C8 A1 ?? ?? ?? ?? 74 ?? 83 F8 ?? 74 ?? FF 76 ?? A1 ?? ?? ?? ?? - 33 D2 6A ?? 03 C1 59 F7 F1 FF 34 95 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 05 ?? ?? ?? ?? - FF 05 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 46 ?? 6A - ?? 59 66 89 4C 78 ?? 33 C9 8B 46 ?? 66 89 0C 78 FF 75 ?? 8B 5D ?? 53 FF 15 ?? ?? ?? - ?? 85 C0 74 ?? 8B 45 ?? E9 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 5D ?? 33 FF 39 7E ?? - 75 ?? 89 3E 53 FF 15 ?? ?? ?? ?? 8B DF 8B 4D ?? E8 ?? ?? ?? ?? 5F 5E 8B C3 5B 8B E5 - 5D C2 - } - $encrypt_files_p1 = { - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 55 ?? 8B C1 89 45 ?? C7 45 ?? ?? ?? - ?? ?? 33 F6 89 75 ?? 83 4D ?? ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 75 - ?? 56 68 ?? ?? ?? ?? 6A ?? 56 56 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? - 83 FB ?? 74 ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 0B 45 ?? 74 ?? - 8B FE EB ?? 33 FF 47 89 7D ?? 85 FF 0F 85 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 - 45 ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? FF 75 ?? FF D0 8B C8 A1 ?? ?? ?? ?? EB ?? 8B - CE 85 C9 0F 84 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? FF 75 ?? FF D0 EB ?? 8B C6 85 C0 0F 84 - ?? ?? ?? ?? 56 8D 45 ?? 50 68 ?? ?? ?? ?? 8B 7D ?? 57 53 FF 15 ?? ?? ?? ?? 85 C0 75 - ?? 83 CF ?? 89 7D ?? E9 ?? ?? ?? ?? 8B 45 ?? 3B C6 7C ?? 8B 4D ?? 7F ?? 81 F9 ?? ?? - ?? ?? 76 ?? 81 E9 ?? ?? ?? ?? 1B C6 50 51 33 D2 8B CB E8 ?? ?? ?? ?? 59 59 23 C2 89 + $search_files = { + 00 00 04 6F ?? ?? ?? ?? 0B 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 0C 00 08 28 ?? ?? ?? ?? + 0A 72 ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 03 6F ?? ?? ?? + ?? 0D 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 00 00 72 ?? ?? ?? ?? 11 ?? 72 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 06 72 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? + ?? 17 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? + 12 ?? 28 ?? ?? ?? ?? 13 07 00 11 ?? 73 ?? ?? ?? ?? 13 ?? 02 11 ?? 28 ?? ?? ?? ?? 16 FE + ?? 13 ?? 11 ?? 2C ?? 00 02 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 1F ?? 28 ?? ?? ?? ?? + 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? + ?? 00 00 2B ?? 00 1F ?? 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 28 ?? ?? ?? + ?? 00 72 ?? ?? ?? ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 00 12 ?? + 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE ?? ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 00 DE + ?? 26 00 00 DE ?? 00 12 ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE ?? ?? ?? ?? ?? + 6F ?? ?? ?? ?? 00 DC 00 12 ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE ?? ?? ?? ?? + ?? 6F ?? ?? ?? ?? 00 DC 2A } - $encrypt_files_p2 = { - 75 ?? 85 F6 75 ?? 56 8D 45 ?? 50 68 ?? ?? ?? ?? 8B 45 ?? 03 C7 50 53 FF 15 ?? ?? ?? - ?? 8B FE 89 7D ?? EB ?? 56 56 6A ?? 5A 8B CB E8 ?? ?? ?? ?? 59 59 23 C2 8B FE 89 7D - ?? 85 FF 75 ?? 56 8D 45 ?? 50 6A ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? - ?? ?? 8B 4D ?? FF 71 ?? FF 71 ?? 8D 41 ?? 50 FF 71 ?? 6A ?? 5A 8B 4D ?? E8 ?? ?? ?? - ?? 83 C4 ?? 0F B6 C0 23 F8 89 7D ?? 0F 85 ?? ?? ?? ?? 56 8D 45 ?? 50 8B 45 ?? FF 70 - ?? FF 70 ?? 53 FF 15 ?? ?? ?? ?? 56 8D 45 ?? 50 8B 45 ?? FF 70 ?? FF 70 ?? 53 FF 15 - ?? ?? ?? ?? 51 8B 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8D 45 ?? 50 8B 55 ?? 52 - 8B 4D ?? 8B 45 ?? 03 C1 50 52 51 51 8B 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 75 ?? 56 8D 45 ?? 50 6A ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 53 FF 15 ?? ?? - ?? ?? 56 56 33 D2 8B CB E8 ?? ?? ?? ?? 59 59 56 8D 45 ?? 50 FF 75 ?? FF 75 ?? 53 FF - 15 ?? ?? ?? ?? 83 7D ?? ?? 76 ?? 8B 45 ?? 2D ?? ?? ?? ?? 8B 4D ?? 1B CE 51 50 33 D2 - 8B CB E8 ?? ?? ?? ?? 59 59 56 8D 45 ?? 50 FF 75 ?? 8B 45 ?? 03 45 ?? 50 53 FF 15 ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 4D ?? ?? E8 ?? ?? ?? ?? 8B C7 E8 ?? ?? ?? ?? C3 + $search_drives = { + 00 28 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 00 06 0C 16 0D 2B ?? 08 09 9A 13 ?? 00 + 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 07 11 ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? + ?? 6F ?? ?? ?? ?? 00 00 00 09 17 58 0D 09 08 8E 69 32 ?? 07 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 26 00 07 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? + 13 ?? 00 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 00 00 03 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? + 12 ?? 28 ?? ?? ?? ?? 13 ?? 00 00 72 ?? ?? ?? ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 00 11 ?? 72 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? + ?? 17 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? + 12 ?? 28 ?? ?? ?? ?? 13 ?? 00 02 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 1F ?? + 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 00 11 ?? 6F + ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE ?? + ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 00 DE ?? 26 00 00 DE ?? 00 12 ?? 28 ?? ?? ?? + ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE ?? ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 00 12 ?? + 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE ?? ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 + DC 2A } - $find_volumes = { - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 33 DB 53 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 56 53 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 89 7D ?? 83 FF ?? 0F 84 ?? ?? ?? - ?? 89 5D ?? 6A ?? 5B 8D B5 ?? ?? ?? ?? 8D 4E ?? 33 D2 66 8B 06 83 C6 ?? 66 3B C2 75 - ?? 2B F1 D1 FE 66 39 9D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 66 39 9D ?? ?? ?? ?? 75 ?? 66 - 83 BD ?? ?? ?? ?? ?? 75 ?? 66 39 9D ?? ?? ?? ?? 75 ?? 66 39 9C 75 ?? ?? ?? ?? 75 ?? - 33 C0 66 89 84 75 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 66 89 9C 75 ?? ?? ?? ?? 85 C0 74 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 4D ?? ?? E8 ?? ?? ?? ?? EB ?? 8B 7D ?? 57 FF 15 ?? - ?? ?? ?? 8B 65 ?? E8 ?? ?? ?? ?? C3 + $encrypt_files = { + 00 03 19 17 73 ?? ?? ?? ?? 0A 06 6F ?? ?? ?? ?? D4 8D ?? ?? ?? ?? 0B 06 07 + 16 07 8E 69 6F ?? ?? ?? ?? 26 06 6F ?? ?? ?? ?? 00 03 18 18 73 ?? ?? ?? ?? + 0C 73 ?? ?? ?? ?? 0D 09 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F + ?? ?? ?? ?? 00 09 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? + ?? ?? 00 09 6F ?? ?? ?? ?? 13 ?? 08 11 ?? 17 73 ?? ?? ?? ?? 13 ?? 11 ?? 07 + 16 07 8E 69 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? 00 + 03 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 2A } condition: - uint16(0)==0x5A4D and ($find_volumes) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($search_files and $search_drives and $encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Desucrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Ophionlocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects DesuCrypt ransomware." + description = "Yara rule that detects OphionLocker ransomware." author = "ReversingLabs" - id = "b9b3ce2b-f184-5bfa-8e1c-a7b996ac708a" + id = "75335749-66bd-539e-92b3-dd92c0b332d8" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.DesuCrypt.yara#L1-L93" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "bd3ba8ea0fc16aad859a73628d0eda180d49298162fe239acf81c7c4e371eaad" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.OphionLocker.yara#L1-L105" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3c54a948a6a45ec5f5bc32fbbdbc8822f402b1332e9109b20b90635464dbe2ac" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -28602,77 +30405,91 @@ rule REVERSINGLABS_Win32_Ransomware_Desucrypt : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "DesuCrypt" + tc_detection_name = "OphionLocker" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 - F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? ?? - ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? FF - 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 5D ?? 8B - CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 EB ?? 8B - 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 FF - 57 57 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 - C5 89 45 ?? 8B 4D ?? 53 8B 5D ?? 57 8B 7D ?? 89 9D ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 - ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8A 11 80 FA - ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 53 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 DB - 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8A C3 80 FA ?? 75 ?? B0 ?? 0F B6 C0 2B CF 41 F7 D8 56 - 1B C0 23 C1 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? - 83 C4 ?? 8D 85 ?? ?? ?? ?? 53 53 53 50 53 57 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? - ?? 83 FE ?? 75 ?? 50 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 83 FE ?? 74 ?? 56 FF 15 - ?? ?? ?? ?? 8B C3 5E 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 - C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? - 80 F9 ?? 75 ?? 38 9D ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 - 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 + $ol_do_filetypes_1 = { + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 53 56 57 33 DB 53 89 5D ?? 53 89 5D ?? 89 5D ?? E8 ?? ?? ?? ?? 89 45 ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? } - $encrypt_files = { - 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? - ?? ?? 53 56 57 8B D9 89 54 24 ?? B9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? BE ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? 8D 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? F3 A5 6A ?? 6A ?? 8D - 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 66 A5 50 6A ?? 6A ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? - ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 - E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B - E5 5D C3 8D 44 24 ?? 50 8D 44 24 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 74 24 ?? 8D 84 24 ?? - ?? ?? ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? - ?? ?? EB ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? - ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5F - 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 8D 44 24 ?? 50 FF 74 24 - ?? 6A ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? - ?? E9 ?? ?? ?? ?? 8B 43 ?? 8B 3D ?? ?? ?? ?? 50 89 44 24 ?? 89 44 24 ?? 8D 44 24 ?? - 50 6A ?? 6A ?? 6A ?? 6A ?? FF 74 24 ?? FF D7 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 51 BA - ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 33 C0 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 - FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 FF 74 24 ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 - ?? 83 7B ?? ?? 72 ?? 8B 1B FF 74 24 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? FF - 74 24 ?? 50 56 6A ?? 6A ?? 6A ?? FF 74 24 ?? FF D7 85 C0 0F 84 ?? ?? ?? ?? 8B 4C 24 - ?? 8B 44 24 ?? 5F 89 01 8B C6 8B 8C 24 ?? ?? ?? ?? 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 - 5D C3 + $ol_do_filetypes_2 = { + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + C6 45 ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? FF 75 ?? 8D 4D ?? 89 5D ?? 50 + 8D 85 ?? ?? ?? ?? 89 5D ?? 50 53 89 5D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 + ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC 89 65 ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 45 ?? 8B CC 8D 75 ?? 50 E8 ?? ?? + ?? ?? 8B CE C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 58 89 45 ?? 89 5D ?? 88 5D ?? 89 45 ?? 89 + 5D ?? 88 5D ?? 83 C4 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 4D ?? 8B 39 E9 00 01 00 00 8B 77 ?? + 8D 47 ?? 89 45 ?? 3B 77 ?? 0F 84 EC 00 00 00 8B F8 68 ?? ?? ?? ?? 8B D7 8D 4D ?? E8 ?? ?? ?? ?? 56 8B D0 C6 45 ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 50 8D 4D ?? E8 ?? ?? ?? ?? 53 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 6A ?? 8D 4D } - $enum_shares = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 - 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 89 75 ?? 8B 45 ?? 8D 4D ?? 51 50 - 6A ?? 6A ?? 6A ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 89 7D ?? 85 FF 0F 84 ?? ?? - ?? ?? 8D 45 ?? 50 57 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 0F 1F 40 ?? 33 DB 39 5D ?? 0F 8E ?? ?? ?? ?? 83 C7 ?? 66 90 F7 47 ?? ?? ?? ?? ?? 74 - ?? 8D 47 ?? 89 45 ?? 8B 06 8B 48 ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 01 8D 55 ?? 52 FF 50 - ?? E9 ?? ?? ?? ?? 8B 17 33 C0 66 89 45 ?? 8B C2 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? 8D 70 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C6 D1 F8 83 F8 ?? 77 ?? 8D 34 00 - 89 45 ?? 56 52 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 44 35 ?? EB ?? 52 C6 - 45 ?? ?? 8D 4D ?? FF 75 ?? 50 E8 ?? ?? ?? ?? 8B 75 ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? - 50 8B 4E ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 43 83 C7 ?? - 3B 5D ?? 0F 8C ?? ?? ?? ?? 8B 7D ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 57 8D 45 ?? C7 - 45 ?? ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 57 FF 15 ?? - ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D - ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 + $ol_do_filetypes_3 = { + ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B CC 89 65 ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? + 89 65 ?? 8D 45 ?? 83 EC ?? 8B CC 50 E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? + 81 C4 ?? ?? ?? ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 53 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC 89 65 ?? 50 E8 ?? + ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C6 ?? 83 C4 ?? 3B 77 ?? 0F + 85 1C FF FF FF 8B 4D ?? 8B 7D ?? 8B 3F 89 7D ?? 3B F9 0F 85 F5 FE FF FF 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 + ?? ?? 8D 85 ?? ?? ?? ?? 89 65 ?? 8B CC BA ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC E8 ?? ?? ?? ?? C6 45 + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 8B CC 89 65 ?? BA ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B + CC E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 33 F6 8D 8D + ?? ?? ?? ?? 53 46 56 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 53 56 8D 4D ?? E8 ?? ?? ?? ?? 53 56 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 53 56 8D 4D ?? E8 ?? ?? + ?? ?? 8B 4D ?? 5F 5E 64 89 0D ?? ?? ?? ?? 5B 8B E5 5D C3 + } + $ol_ecies_key_1 = { + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 53 56 57 8B F9 33 DB 89 5D ?? 8D 8D ?? ?? ?? ?? 89 7D ?? 89 5D ?? E8 ?? + ?? ?? ?? 33 F6 8D 85 ?? ?? ?? ?? 46 8D 8D ?? ?? ?? ?? 50 BA ?? ?? ?? ?? 89 75 ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B + CC 8B D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 56 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? + ?? ?? BE ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 50 56 FF 75 ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 85 C0 0F 85 40 03 00 00 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 50 51 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 51 + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? 8B B4 05 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? FF 50 ?? 50 8B 85 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 03 C8 FF 56 ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? FF 50 ?? 8D 55 ?? 8B C8 E8 ?? ?? ?? ?? 53 6A ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? BB ?? + ?? ?? ?? 8D 4D ?? 53 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? FF 50 ?? 83 7D ?? ?? 8D 4D ?? 8B F0 + 0F 43 4D ?? 51 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 95 ?? ?? ?? ?? 8B 06 52 8B 48 ?? 03 CE 8B 01 FF 50 ?? + C6 45 ?? ?? 8B 8D ?? ?? ?? ?? 85 C9 74 0D 8B 01 6A ?? 8B 40 ?? 03 C8 8B 01 FF 10 33 F6 C6 45 ?? ?? 56 6A ?? 8D 4D ?? E8 + ?? ?? ?? ?? 83 EC ?? 8B CC 53 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D0 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? + } + $ol_ecies_key_2 = { + 56 6A ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8B CC 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 6A ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 53 + E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 + ?? ?? 50 8D 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 59 50 8D 4D ?? E8 ?? ?? ?? ?? 56 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? + 56 E8 ?? ?? ?? ?? 59 50 56 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 E8 + ?? ?? ?? ?? 59 50 56 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 + E8 ?? ?? ?? ?? 59 50 56 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 33 F6 C6 45 ?? ?? 56 50 8D 4D ?? E8 ?? ?? + ?? ?? 56 6A ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC BA ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 95 ?? ?? ?? ?? 8B CC 89 65 ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 53 E8 ?? + ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 56 6A ?? E8 ?? ?? ?? ?? 56 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? + 56 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + } + $ol_ecies_key_3 = { + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? EB 30 83 EC ?? 8D 55 ?? 8B CC 89 65 ?? E8 + ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC BB ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 51 8D 4F ?? + E8 ?? ?? ?? ?? 8D 77 ?? C7 07 ?? ?? ?? ?? C7 06 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 53 8D 4D ?? C7 45 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 46 ?? C6 45 ?? ?? 85 C0 74 05 8D 4E ?? EB 02 33 C9 8D 55 ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 4D ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? 8B 06 8B CE FF 50 ?? 6A ?? 68 ?? ?? ?? ?? 8B 08 8B 49 ?? 03 C8 8B 01 FF 50 ?? 53 E8 ?? ?? ?? ?? 59 6A ?? + 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8B C7 5F 5E 64 89 0D ?? ?? ?? ?? 5B + 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($find_files and $encrypt_files and $enum_shares) + uint16(0)==0x5A4D and (($ol_do_filetypes_1 and $ol_do_filetypes_2 and $ol_do_filetypes_3) and ($ol_ecies_key_1 and $ol_ecies_key_2 and $ol_ecies_key_3)) } rule REVERSINGLABS_Win32_Ransomware_Medusalocker : TC_DETECTION MALICIOUS MALWARE FILE { @@ -28683,8 +30500,8 @@ rule REVERSINGLABS_Win32_Ransomware_Medusalocker : TC_DETECTION MALICIOUS MALWAR date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.MedusaLocker.yara#L1-L174" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.MedusaLocker.yara#L1-L174" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "73f915d476d1411d2e008d00c5ffa03596e3b62bcdbc4d91dc7226599a066c08" score = 75 quality = 90 @@ -28827,20 +30644,18 @@ rule REVERSINGLABS_Win32_Ransomware_Medusalocker : TC_DETECTION MALICIOUS MALWAR condition: uint16(0)==0x5A4D and ($kill_processes_call) and ($kill_processes) and ($enum_resources) and ( all of ($search_files_*)) and ( all of ($encrypt_files_p*)) and ($enum_resources_call) } -import "pe" - -rule REVERSINGLABS_Win32_Ransomware_Bitcrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Thanos : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects BitCrypt ransomware." + description = "Yara rule that detects Thanos ransomware." author = "ReversingLabs" - id = "f00a0fd8-31a9-5ee6-b560-09ccf6fe490b" - date = "2020-07-15" - modified = "2020-07-15" + id = "e607255d-45a6-573d-956e-f6faa2aa7e9f" + date = "2021-08-12" + modified = "2021-08-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.BitCrypt.yara#L3-L112" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "66cfe16a182e7f20d6358be9569ada5e6c36c94d44781d8c741638e1b174d44e" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Thanos.yara#L1-L106" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "f6bc0c2188a04d2fb2a82a6b6d6cdf7763c32047bec725fe07f01415edf0b4cd" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -28848,106 +30663,97 @@ rule REVERSINGLABS_Win32_Ransomware_Bitcrypt : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "BitCrypt" + tc_detection_name = "Thanos" tc_detection_factor = 5 importance = 25 strings: - $bc_bcdedit = { - 55 8B EC 6A ?? 53 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B D8 BA ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C3 - E8 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 BA ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8D 45 - ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? - ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? C3 - } - $bc_enum_drives_a_z = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 D2 89 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B F0 33 C0 55 68 ?? ?? ?? - ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 06 B3 ?? 8D 85 ?? ?? ?? ?? 8B D3 E8 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? - 8D 45 ?? B1 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B D3 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 E8 ?? 75 1B 8D 85 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? - ?? 8B 06 8B 08 FF 51 ?? 43 80 FB ?? 0F 85 65 FF FF FF 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? C3 - } - $bc_do_extensions_1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D - ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 4D ?? 89 55 ?? 89 45 ?? 8B 7D ?? 8B 5D ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 85 ?? - ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 85 81 01 00 00 E8 ?? ?? ?? ?? BA ?? - ?? ?? ?? 33 C0 E8 ?? ?? ?? ?? 8B F0 8B C3 8B 14 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB 28 A0 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? - 50 8B 03 33 C9 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B 13 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 85 C0 75 C8 EB 28 A0 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8B 03 33 C9 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B - C3 E8 ?? ?? ?? ?? 8B 13 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 C8 FF 75 ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? DB 85 ?? ?? ?? ?? 83 C4 ?? DB 3C - } - $bc_do_extensions_2 = { - 24 9B 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8B C7 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 13 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 17 8D 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? B3 ?? EB 02 33 DB 33 C0 5A 59 59 64 89 10 EB 0C E9 ?? ?? ?? ?? 33 DB E8 ?? ?? - ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB D0 8B C3 5F 5E 5B 8B E5 5D C2 - } - $bc_do_files_1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 4D ?? 89 55 ?? 8B F0 - 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B3 ?? 8B 06 E8 ?? ?? ?? ?? - 89 45 ?? 8B 16 8D 85 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B F8 85 FF 0F 85 91 00 00 00 F6 85 ?? ?? ?? ?? ?? 75 73 56 8D B5 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 A5 - 5E 8B 85 ?? ?? ?? ?? 89 45 ?? 8B 85 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 33 D2 E8 ?? ?? ?? ?? 83 C4 ?? DD 1C 24 9B 8D 45 ?? E8 - ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 36 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? - ?? ?? 8B 45 ?? 8B 40 ?? 8B 00 8B 08 FF 51 ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 85 FF 0F 84 6F FF FF FF 8D 85 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 84 DB 0F 84 B7 00 00 00 8B 16 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D + $find_files_p1 = { + 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 FE 01 2B ?? 16 00 13 ?? 11 ?? 2D ?? DD + ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 08 6F ?? ?? ?? ?? 6C 7E ?? ?? ?? ?? + 28 ?? ?? ?? ?? 23 ?? ?? ?? ?? ?? ?? ?? ?? 5A 23 ?? ?? ?? ?? ?? ?? ?? ?? 5A 35 ?? 7E ?? + ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE 01 2B ?? 17 00 13 ?? 11 ?? 2D ?? 00 06 08 + 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 2B ?? 08 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 7E ?? + ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE 01 2B ?? 17 00 13 ?? 11 ?? 2D ?? 00 06 08 + 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 00 DE ?? 26 00 00 DE ?? 26 00 00 DE ?? 00 00 00 11 + ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 3A ?? ?? ?? ?? DE ?? 11 ?? 14 FE 01 13 ?? 11 ?? 2D ?? 11 + ?? 6F ?? ?? ?? ?? 00 DC 00 00 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 38 + ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 0D 00 07 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 2D ?? 07 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D + ?? 07 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 07 6F ?? ?? ?? + ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 07 6F ?? ?? ?? ?? 6F } - $bc_do_files_2 = { - 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 85 FF 75 7E F6 85 ?? ?? ?? ?? ?? 74 64 8B 85 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 74 52 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 40 FF 36 FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B - C6 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 50 8B C6 8B 55 ?? E8 57 FE FF FF 59 84 C0 75 04 33 DB EB 21 8B 55 ?? 42 8B C6 - B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 85 FF 74 82 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 - 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 + $find_files_p2 = { + 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 07 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 16 FE 01 2B ?? 16 00 13 ?? 11 ?? 2D ?? 38 ?? ?? ?? ?? 00 00 09 72 ?? ?? ?? + ?? 17 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 0C 00 00 + 08 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 08 6F ?? + ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 08 6F ?? ?? ?? ?? + 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 6F ?? ?? + ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A } - $bc_main_1 = { - 55 8B EC B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 F9 53 56 57 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 - 89 20 33 C0 A3 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? - ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? - ?? ?? ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? - ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 8D 45 ?? 8B 0D ?? ?? ?? ?? - 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 75 7A 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B + $find_files_p3 = { + 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 08 6F ?? ?? + ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 6F + ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 08 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 00 6F + ?? ?? ?? ?? 2D ?? 08 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 08 6F ?? ?? ?? + ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 08 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 2D ?? 08 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 08 6F ?? ?? ?? ?? 72 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 16 FE 01 2B ?? 16 00 13 ?? 11 ?? 2D ?? DD ?? ?? ?? ?? 08 6F ?? ?? + ?? ?? 28 ?? ?? ?? ?? 2C ?? 08 6F ?? ?? ?? ?? 6C 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 23 ?? ?? + ?? ?? ?? ?? ?? ?? 5A 23 ?? ?? ?? ?? ?? ?? ?? ?? 5A 35 ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 16 FE 01 2B ?? 17 00 13 ?? 11 ?? 2D ?? 00 06 08 6F ?? ?? ?? ?? 6F ?? ?? + ?? ?? 00 00 2B ?? 08 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 16 FE 01 2B ?? 17 00 13 ?? 11 ?? 2D ?? 00 06 08 6F ?? ?? ?? ?? 6F ?? ?? + ?? ?? 00 00 00 DE ?? 26 00 00 DE ?? 26 00 00 DE ?? 00 00 00 11 ?? 6F ?? ?? ?? ?? 13 ?? + 11 ?? 3A ?? ?? ?? ?? DE ?? 11 ?? 14 FE 01 13 ?? 11 ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 00 DC + 00 00 DE ?? 26 00 00 DE ?? 26 00 00 DE ?? 00 00 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 3A ?? + ?? ?? ?? DE ?? 11 ?? 14 FE 01 13 ?? 11 ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 00 DC 00 00 DE ?? + 26 00 00 DE ?? 26 00 00 DE ?? 26 00 00 DE ?? 26 00 00 DE ?? 00 06 13 ?? 2B ?? 11 ?? 2A } - $bc_main_2 = { - 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 8D 45 ?? 8B 0D ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 33 C0 E8 ?? ?? ?? ?? 8B 45 ?? 50 8D 45 ?? 8B 0D ?? ?? ?? ?? 8B 15 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 58 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB 11 BA ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B D8 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 80 FB ?? 0F 85 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? B2 ?? A1 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 75 ED A1 ?? ?? ?? ?? 8B 10 FF 52 ?? 83 F8 ?? 0F - 8E ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 10 FF 52 ?? 99 F7 3D ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 10 FF 52 ?? 99 F7 3D - ?? ?? ?? ?? 89 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 48 85 C0 7C ?? 40 89 45 ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? + $encrypt_files = { + 73 ?? ?? ?? ?? 13 ?? 11 ?? 03 7D ?? ?? ?? ?? 11 ?? 04 7D ?? ?? ?? ?? 11 ?? 05 7D ?? ?? + ?? ?? 11 ?? 0E ?? 7D ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 11 ?? 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? + 80 ?? ?? ?? ?? 02 16 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE 01 13 ?? 11 ?? 2D ?? 00 28 + ?? ?? ?? ?? 0A 06 8E 69 16 FE 02 16 FE 01 13 ?? 11 ?? 2D ?? 00 16 0B 2B ?? 00 06 07 9A + 6F ?? ?? ?? ?? 16 FE 01 13 ?? 11 ?? 2D ?? 00 7E ?? ?? ?? ?? 06 07 9A 6F ?? ?? ?? ?? 6F + ?? ?? ?? ?? 13 ?? 11 ?? 2D ?? 00 7E ?? ?? ?? ?? 06 07 9A 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? + 00 00 00 00 07 17 58 0B 07 06 8E 69 FE 04 13 ?? 11 ?? 2D ?? 00 00 2B ?? 00 16 0B 2B ?? + 00 7E ?? ?? ?? ?? 02 07 9A 6F ?? ?? ?? ?? 13 ?? 11 ?? 2D ?? 00 7E ?? ?? ?? ?? 02 07 9A + 6F ?? ?? ?? ?? 00 00 00 07 17 58 0B 07 02 8E 69 FE 04 13 ?? 11 ?? 2D ?? 00 7E ?? ?? ?? + ?? 72 ?? ?? ?? ?? 00 6F ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 16 FE 01 2B ?? 17 00 13 ?? 11 ?? 2D ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 00 6F ?? ?? ?? + ?? 26 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 14 0D 73 ?? ?? ?? ?? 13 + ?? 11 ?? 11 ?? 7D ?? ?? ?? ?? 11 ?? 12 ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 00 7E ?? ?? ?? + ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE 01 13 ?? 11 ?? 2D ?? 00 09 2D ?? 11 ?? FE 06 ?? + ?? ?? ?? 73 ?? ?? ?? ?? 0D 2B ?? 09 73 ?? ?? ?? ?? 0C 08 1A 6F ?? ?? ?? ?? 00 08 16 6F + ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? 00 00 2B ?? 00 11 ?? 7B ?? ?? ?? + ?? 11 ?? 7B ?? ?? ?? ?? 11 ?? 7B ?? ?? ?? ?? 11 ?? 7B ?? ?? ?? ?? 11 ?? 7B ?? ?? ?? ?? + 28 ?? ?? ?? ?? 00 00 00 12 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE + 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 00 00 2A } - $bc_main2 = { - E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 45 ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D - ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $remote_connection = { + 00 00 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 19 6F ?? ?? ?? ?? + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 07 02 28 ?? ?? ?? ?? 06 28 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 06 28 ?? ?? ?? ?? 0C DE ?? 26 00 00 DE ?? 00 7E ?? + ?? ?? ?? 0C 2B ?? 00 08 2A } condition: - uint16(0)==0x5A4D and ($bc_main_1 at pe.entry_point) and $bc_main_2 and $bc_main2 and $bc_bcdedit and $bc_enum_drives_a_z and $bc_do_extensions_1 and $bc_do_extensions_2 and $bc_do_files_1 and $bc_do_files_2 + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) and ($remote_connection) } -rule REVERSINGLABS_Win32_Ransomware_Gibon : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Shadowcryptor : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Gibon ransomware." + description = "Yara rule that detects ShadowCryptor ransomware." author = "ReversingLabs" - id = "3f1a5bee-8fc0-5596-b898-e97073731930" - date = "2020-07-15" - modified = "2020-07-15" + id = "983e8927-4829-540f-9697-886226fd54ce" + date = "2021-02-11" + modified = "2021-02-11" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Gibon.yara#L1-L122" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "cace0f35529307487f39aace6ae8989c7b878f82ebe890b256dfac563551a099" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.ShadowCryptor.yara#L1-L89" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "875150db9fc36cd992988bba7d0c05487418b901980bf428ebd427c82fbcacd7" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -28955,116 +30761,81 @@ rule REVERSINGLABS_Win32_Ransomware_Gibon : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Gibon" + tc_detection_name = "ShadowCryptor" tc_detection_factor = 5 importance = 25 strings: - $remote_server_connection_1_0 = { - 53 8B DC 83 EC ?? 83 E4 ?? 83 C4 ?? 55 8B 6B ?? 89 6C 24 ?? 8B EC 6A ?? 68 ?? ?? ?? - ?? 64 A1 ?? ?? ?? ?? 50 53 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 - ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? BA ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? 85 C0 74 ?? BA ?? ?? - ?? ?? E9 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? - 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 B9 ?? ?? ?? ?? 83 FE ?? 75 ?? BA ?? ?? ?? ?? E9 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? 6A ?? 66 89 85 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 56 FF 15 ?? ?? ?? ?? 8B - 3D ?? ?? ?? ?? 85 C0 79 ?? FF D7 50 51 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 8B 43 ?? - 83 C0 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 7B ?? ?? 8D 43 ?? FF 73 ?? 0F 43 43 ?? 8D 8D ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 - } - $remote_server_connection_1_1 = { - E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? - ?? ?? ?? 8B 53 ?? 8D 4B ?? 83 FA ?? 0F 43 4B ?? 8D 41 ?? 89 85 ?? ?? ?? ?? 90 8A 01 - 41 84 C0 75 ?? 2B 8D ?? ?? ?? ?? 8D 43 ?? 6A ?? 83 FA ?? 51 0F 43 43 ?? 50 56 FF 15 - ?? ?? ?? ?? 85 C0 79 ?? FF D7 50 51 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 8B C8 E8 ?? ?? ?? ?? EB ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? - 83 F8 ?? 0F 85 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? BE ?? ?? ?? ?? 8B 43 ?? 83 F8 ?? 72 ?? 8B 4B ?? 40 3D ?? ?? ?? ?? 72 - ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 - ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 8B 4D - ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D 8B E3 5B C3 - } - $encryption_loop_1_0 = { - 66 8B 01 66 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EE ?? 75 ?? C6 85 ?? ?? ?? ?? ?? E9 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 8B 40 ?? 03 C8 8B 51 ?? 83 CA ?? - 8B C2 83 C8 ?? 83 79 ?? ?? 0F 45 C2 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 32 C0 0F 85 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 C7 45 ?? ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? 83 CB ?? 68 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? 8B D7 8B 9D ?? ?? ?? ?? 83 CB ?? 83 7F ?? ?? 89 9D ?? ?? ?? ?? 89 - 9D ?? ?? ?? ?? 72 ?? 8B 17 83 78 ?? ?? 8B C8 72 ?? 8B 08 8B 70 ?? 3B 77 ?? 75 ?? 85 - F6 0F 84 + $find_files = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 8D 45 ?? 83 7D ?? ?? 0F 57 C0 66 0F 13 85 ?? ?? ?? ?? 0F 43 45 ?? 50 8D 85 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B + BD ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? EB ?? + 8D A4 24 ?? ?? ?? ?? 90 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D3 85 C0 0F 84 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D3 85 C0 0F 84 ?? ?? ?? ?? 33 C0 83 7D + ?? ?? 66 89 85 ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 85 + ?? ?? ?? ?? 83 F8 ?? 74 ?? A8 ?? 74 ?? 50 8D 85 ?? ?? ?? ?? 50 51 8B 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? EB ?? 51 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 51 8B 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 83 C7 ?? 83 D6 ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 + 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D6 8B C7 8B 4D ?? 64 89 0D ?? ?? + ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 } - $encryption_loop_1_1 = { - 66 8B 01 66 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EE ?? 75 ?? C6 85 ?? ?? ?? ?? ?? EB ?? - 32 C0 74 ?? C6 85 ?? ?? ?? ?? ?? EB ?? C6 85 ?? ?? ?? ?? ?? F6 C3 ?? 74 ?? 83 E3 ?? - 8D 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 C3 ?? 74 ?? 83 E3 ?? 8D 8D ?? - ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 C3 ?? 74 ?? 83 E3 ?? 8D 8D ?? ?? ?? ?? - 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 C3 ?? 74 ?? 83 E3 ?? 8D 8D ?? ?? ?? ?? 89 9D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 32 C0 75 ?? 83 E3 ?? 8D 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 32 C0 C7 45 ?? ?? ?? ?? ?? 75 ?? 83 E3 ?? 8D 8D ?? ?? ?? ?? 89 9D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 51 FF B5 ?? ?? ?? ?? BA - ?? ?? ?? ?? C6 45 ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 95 + $encrypt_files = { + 55 8B EC 83 E4 ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? + 33 C4 89 44 24 ?? 53 56 57 A1 ?? ?? ?? ?? 33 C4 50 8D 44 24 ?? 64 A3 ?? ?? ?? ?? 8B + F1 8D 46 ?? 50 8D 4E ?? E8 ?? ?? ?? ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? + ?? ?? ?? 66 89 44 24 ?? 89 44 24 ?? 39 46 ?? 0F 84 ?? ?? ?? ?? 8D A4 24 ?? ?? ?? ?? + 80 7E ?? ?? 0F 85 ?? ?? ?? ?? 51 8D 44 24 ?? 50 8D 44 24 ?? 50 8D 4E ?? E8 ?? ?? ?? + ?? 8B C8 E8 ?? ?? ?? ?? 8B D0 8B 02 85 C0 74 ?? 8B 00 8B 48 ?? 8B 40 ?? 49 23 4A ?? + 8B 04 88 8D 4C 24 ?? 3B C8 74 ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 46 ?? 8B 4E ?? 48 + 03 C8 8B 46 ?? 48 23 C8 8B 46 ?? 8B 3C 88 83 7F ?? ?? 72 ?? FF 37 E8 ?? ?? ?? ?? 83 + C4 ?? 33 C0 C7 47 ?? ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 66 89 07 FF 4E ?? 75 ?? 89 46 + ?? 83 EC ?? 8B CC 6A ?? 89 41 ?? 33 C0 C7 41 ?? ?? ?? ?? ?? 50 66 89 01 8D 44 24 ?? + 50 E8 ?? ?? ?? ?? 51 8B CE E8 ?? ?? ?? ?? 8B C8 0B CA 74 ?? 01 46 ?? 11 56 ?? 83 7C + 24 ?? ?? 8D 54 24 ?? 0F 43 54 24 ?? 83 EC ?? 8B FC 33 C0 C7 47 ?? ?? ?? ?? ?? C7 47 + ?? ?? ?? ?? ?? 66 89 07 66 39 02 74 ?? 8B C2 8D 48 ?? 89 4C 24 ?? 66 8B 08 83 C0 ?? + 66 85 C9 75 ?? 2B 44 24 ?? D1 F8 50 52 8B CF E8 ?? ?? ?? ?? 8B 4E ?? 83 79 ?? ?? 8D + 41 ?? 72 ?? 8B 00 8B 91 ?? ?? ?? ?? 81 C1 ?? ?? ?? ?? 83 79 ?? ?? 72 ?? 8B 09 50 E8 + ?? ?? ?? ?? 83 C4 ?? 83 7E ?? ?? 0F 85 ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? FF 74 24 ?? + E8 ?? ?? ?? ?? 83 C4 ?? 8B 4C 24 ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4C 24 ?? 33 + CC E8 ?? ?? ?? ?? 8B E5 5D C3 } - $encryption_loop_1_2 = { - 57 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? - ?? ?? ?? C3 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 FF B5 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E - 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 51 FF B5 ?? ?? ?? ?? BA ?? ?? ?? ?? 51 - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 69 0F ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? - ?? ?? BA ?? ?? ?? ?? 03 48 ?? 8D 85 ?? ?? ?? ?? 50 51 E8 ?? ?? ?? ?? 85 C0 74 ?? BA - ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 + $terminate_antivirus_processes_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B D9 C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 33 C0 C7 43 ?? ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 66 89 03 89 + 45 ?? 50 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 } - $encryption_loop_1_3 = { - 69 37 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 03 70 ?? E8 ?? ?? ?? ?? 8B 95 ?? - ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 81 CB ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 78 ?? 8D - 4A ?? 89 08 8D 4A ?? 89 48 ?? 8D 4A ?? 89 48 ?? 8D 4A ?? 89 48 ?? 8D 4A ?? 89 48 ?? - B9 ?? ?? ?? ?? F3 A5 66 A5 C7 80 ?? ?? ?? ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? - ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - C6 45 ?? ?? 8B B5 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 56 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? ?? ?? ?? 83 C4 - ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B BD ?? - ?? ?? ?? 8B 8D ?? ?? ?? ?? FF 07 8B 07 89 41 ?? 69 17 ?? ?? ?? ?? 8B 41 ?? 80 A4 02 - ?? ?? ?? ?? ?? 8B 01 48 39 07 75 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 83 C4 ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F - 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E8 - ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8A 11 8B - C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? C3 + $terminate_antivirus_processes_p2 = { + 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 49 ?? 33 F6 8B BC B5 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 57 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 39 43 ?? 74 ?? 6A ?? 68 ?? + ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 66 83 3F ?? 75 ?? 33 C0 EB ?? 8B C7 8D 50 ?? 8D 49 ?? + 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 50 57 8B CB E8 ?? ?? ?? ?? 46 83 FE ?? + 72 ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 56 FF + 15 ?? ?? ?? ?? 8B C3 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? + ?? ?? ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($remote_server_connection_1_0 and $remote_server_connection_1_1 and ( all of ($encryption_loop_1_*))) + uint16(0)==0x5A4D and ( all of ($terminate_antivirus_processes_p*)) and ($find_files) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Spora : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Cincoo : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Spora ransomware." + description = "Yara rule that detects Cincoo ransomware." author = "ReversingLabs" - id = "f07ee1d4-d99b-5cbf-a1f0-a3802d9e3b47" - date = "2020-07-15" - modified = "2020-07-15" + id = "c7c2773c-5056-5127-8af7-7f5c5a8ea8a1" + date = "2022-06-21" + modified = "2022-06-21" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Spora.yara#L1-L124" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "4e18bb42277ce9194bf75fa45d95ea7e2bd51c5d7791d3d6e013fc07626e65b0" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Cincoo.yara#L1-L78" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6a7562cae90754ea75a9fb98ce73ebdb9acf1ad7f28f2240abe6cb592d717ca3" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -29072,122 +30843,71 @@ rule REVERSINGLABS_Win32_Ransomware_Spora : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Spora" + tc_detection_name = "Cincoo" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files = { - 55 8D 6C 24 ?? 81 EC ?? ?? ?? ?? 57 FF 75 ?? 33 FF 89 7D ?? FF 15 ?? ?? ?? ?? 83 F8 - ?? 0F 84 ?? ?? ?? ?? A8 ?? 74 ?? 83 E0 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 53 56 57 BE - ?? ?? ?? ?? 56 6A ?? 57 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB - ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 53 89 7D ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 0F - 82 ?? ?? ?? ?? 6A ?? 57 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? - ?? 57 8D 45 ?? 50 56 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 39 75 - ?? 0F 85 ?? ?? ?? ?? 57 8D 45 ?? 50 6A ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F - 84 ?? ?? ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 56 8D 45 ?? 50 57 FF 15 ?? ?? ?? ?? 3B - 45 ?? 0F 84 ?? ?? ?? ?? 39 7D ?? 74 ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? B9 ?? ?? - ?? ?? 3B C1 72 ?? 89 4D ?? EB ?? 83 E0 ?? 89 45 ?? 57 FF 75 ?? 57 6A ?? 57 53 FF 15 - ?? ?? ?? ?? 89 45 ?? 3B C7 0F 84 ?? ?? ?? ?? FF 75 ?? 57 57 6A ?? 50 FF 15 ?? ?? ?? - ?? 89 45 ?? 3B C7 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 57 6A ?? 57 FF - 75 ?? 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 8D 45 ?? 50 8D 45 ?? 50 57 6A ?? 57 - FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? FF 75 ?? 8D 45 ?? 50 FF 75 ?? 57 57 - 57 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 8D 45 ?? 50 57 FF 15 ?? ?? ?? ?? 6A ?? - 57 57 53 89 45 ?? FF 15 ?? ?? ?? ?? 57 8D 45 ?? 50 56 8B 35 ?? ?? ?? ?? 8D 45 ?? 50 - 53 FF D6 57 8D 45 ?? 50 6A ?? 8D 45 ?? 50 53 FF D6 C7 45 ?? ?? ?? ?? ?? FF 75 ?? FF - 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? EB ?? C7 45 ?? - ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 5E 5B 8B 45 ?? 5F 83 C5 ?? C9 C2 - } - $create_key_file = { - 55 8D 6C 24 ?? 81 EC ?? ?? ?? ?? 56 8D 45 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? 33 F6 89 75 ?? C7 45 ?? ?? ?? ?? ?? 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F - 84 ?? ?? ?? ?? 57 8D 45 ?? 50 8D 45 ?? 50 56 6A ?? 56 FF 75 ?? BF ?? ?? ?? ?? 89 7D - ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 57 8B 3D ?? ?? ?? ?? 8D 45 ?? 50 8D 45 - ?? 50 56 6A ?? 56 FF 35 ?? ?? ?? ?? FF D7 FF 75 ?? FF 15 ?? ?? ?? ?? 83 E0 ?? 83 C0 - ?? 50 89 45 ?? 8D 45 ?? 50 FF 75 ?? 56 56 56 FF 75 ?? FF D7 85 C0 0F 84 ?? ?? ?? ?? - 53 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF D3 8B F8 3B FE 0F 84 ?? ?? ?? ?? 56 6A - ?? 57 56 FF 15 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8D 04 47 50 - FF 15 ?? ?? ?? ?? 83 C4 ?? 56 6A ?? 6A ?? 56 56 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? - 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 56 8D 4D ?? 51 FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? - ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 3B 45 ?? 0F 85 ?? ?? ?? ?? 56 8D 45 ?? 50 68 - ?? ?? ?? ?? 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 81 7D ?? - ?? ?? ?? ?? 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? C7 45 ?? ?? ?? ?? ?? 57 68 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF D3 8B D8 3B DE 74 ?? 89 75 ?? 8B 45 - ?? 56 FF 74 85 ?? 53 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? FF 75 ?? 68 ?? ?? ?? ?? 53 FF - 15 ?? ?? ?? ?? 8D 04 43 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 56 53 57 FF 15 ?? ?? ?? ?? FF - 45 ?? 83 7D ?? ?? 72 ?? 53 FF 15 ?? ?? ?? ?? EB ?? FF 75 ?? FF 15 ?? ?? ?? ?? 57 FF - 15 ?? ?? ?? ?? 5B FF 75 ?? FF 15 ?? ?? ?? ?? 5F 8B 45 ?? 5E 83 C5 ?? C9 C2 - } - $create_key = { - 55 8D 6C 24 ?? 81 EC ?? ?? ?? ?? 56 8D 45 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 53 57 8D 45 ?? 50 8D 45 ?? 50 - 33 DB 53 6A ?? 53 FF 75 ?? BE ?? ?? ?? ?? 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? 56 8B 35 ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 53 6A ?? 53 FF 35 ?? ?? ?? ?? - FF D6 FF 75 ?? FF 15 ?? ?? ?? ?? 83 E0 ?? 83 C0 ?? 50 89 45 ?? 8D 45 ?? 50 FF 75 ?? - 53 53 53 FF 75 ?? FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 4D ?? 8B 35 ?? ?? ?? ?? - 03 C8 51 6A ?? FF D6 8B F8 89 7D ?? 3B FB 0F 84 ?? ?? ?? ?? FF 75 ?? FF 75 ?? 57 FF - 15 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? 50 8B 45 ?? 03 C7 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 83 - C4 ?? 8D 45 ?? 50 8B 45 ?? 53 6A ?? 03 C8 51 57 8B 3D ?? ?? ?? ?? FF D7 85 C0 74 ?? - FF 75 ?? 6A ?? FF D6 8B F0 3B F3 74 ?? 8B 4D ?? 8D 45 ?? 50 8B 45 ?? 56 6A ?? 03 C8 - 51 FF 75 ?? FF D7 33 FF 38 1E 74 ?? 8B C6 80 38 ?? 75 ?? 40 40 8A 08 88 0C 37 47 40 - 38 18 75 ?? 88 1C 37 EB ?? 8B 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? EB ?? 8B 75 ?? FF 75 - ?? FF 15 ?? ?? ?? ?? 5F 5B EB ?? 8B 75 ?? 8B C6 5E 83 C5 ?? C9 C2 + $find_files = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? + 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 55 ?? 8B D9 83 7B ?? ?? 8B F3 8B 45 ?? 8B 7D + ?? 89 45 ?? 72 ?? 8B 33 8D 4E ?? 66 8B 06 83 C6 ?? 66 85 C0 75 ?? 2B F1 D1 FE 0F 84 + ?? ?? ?? ?? 3B 73 ?? 0F 85 ?? ?? ?? ?? 88 45 ?? 8D 55 ?? FF 75 ?? 8D 4D ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? C7 45 ?? ?? ?? ?? + ?? 50 8B CB E8 ?? ?? ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B + C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? + ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7B ?? ?? 72 ?? 8B 1B 8B 75 ?? 57 56 53 E8 ?? ?? + ?? ?? 85 C0 75 ?? 8B 36 8B CF E8 ?? ?? ?? ?? 84 C0 74 ?? 57 56 E8 ?? ?? ?? ?? 85 C0 + 75 ?? 8B CF E8 ?? ?? ?? ?? 84 C0 75 ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E + 5B 8B E5 5D C3 } - $create_lst_file = { - 55 8D 6C 24 ?? 81 EC ?? ?? ?? ?? 53 56 68 ?? ?? ?? ?? 33 F6 6A ?? 89 75 ?? FF 15 ?? - ?? ?? ?? 8B D8 3B DE 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 57 8B 45 ?? 8B 38 8D 45 - ?? 50 53 83 C7 ?? FF 15 ?? ?? ?? ?? 03 C0 50 53 FF 75 ?? FF 17 8B 45 ?? 8B 08 8D 55 - ?? 52 6A ?? 68 ?? ?? ?? ?? 50 FF 51 ?? 53 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 45 ?? 8B 08 - 8D 55 ?? 52 6A ?? 68 ?? ?? ?? ?? 50 FF 51 ?? 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? - 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 89 45 ?? 3B C6 0F 84 ?? ?? ?? ?? - 8B 3D ?? ?? ?? ?? 56 56 56 56 6A ?? 50 56 68 ?? ?? ?? ?? FF D7 89 45 ?? 3B C6 0F 84 - ?? ?? ?? ?? 83 C0 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 3B C6 0F 84 ?? ?? ?? ?? 56 - 56 FF 75 ?? 50 6A ?? FF 75 ?? 56 68 ?? ?? ?? ?? FF D7 8D 45 ?? 50 6A ?? 68 ?? ?? ?? - ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 E0 ?? 83 - C0 ?? 89 45 ?? 8D 45 ?? 50 8D 45 ?? 50 56 6A ?? 56 FF 75 ?? BF ?? ?? ?? ?? 89 7D ?? - FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 57 8D 45 ?? 50 8D 45 ?? 50 56 6A ?? 56 FF - 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? 50 FF 75 ?? 56 56 - 56 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 56 6A ?? 53 56 FF 15 ?? ?? ?? - ?? FF 75 ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8D 04 43 50 FF 15 ?? ?? ?? ?? 83 C4 - ?? 57 53 FF 15 ?? ?? ?? ?? 56 6A ?? 6A ?? 56 56 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? - 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 56 8D 4D ?? 51 FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? - ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 3B 45 ?? 0F 85 ?? ?? ?? ?? 56 8D 45 ?? 50 57 - 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 39 7D ?? 75 ?? FF 75 ?? C7 45 ?? - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 75 ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 3B FE 74 ?? 56 6A ?? 57 56 FF 15 ?? ?? ?? ?? 85 C0 - 74 ?? FF 75 ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8D 04 47 50 FF 15 ?? ?? ?? ?? 83 - C4 ?? 56 57 53 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? EB ?? FF 75 ?? FF 15 ?? ?? ?? - ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? - 5F 8B 45 ?? 8B 08 50 FF 51 ?? 53 FF 15 ?? ?? ?? ?? 8B 45 ?? 5E 5B 83 C5 ?? C9 C2 + $encrypt_files = { + 55 8B EC 83 EC ?? 8B 45 ?? 53 8B D9 89 45 ?? B9 ?? ?? ?? ?? 8B C1 56 8B 53 ?? 2B C2 + 8B 75 ?? 89 55 ?? 57 3B C6 0F 82 ?? ?? ?? ?? 8B 7B ?? 8D 04 32 8B F0 89 45 ?? 83 CE + ?? 89 7D ?? 3B F1 76 ?? 8B F1 EB ?? 8B C7 D1 E8 2B C8 3B F9 76 ?? BE ?? ?? ?? ?? EB + ?? 03 C7 3B F0 0F 42 F0 33 C9 8B C6 83 C0 ?? 0F 92 C1 F7 D9 0B C8 81 F9 ?? ?? ?? ?? + 72 ?? 8D 41 ?? 3B C1 0F 86 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? + ?? ?? 8B 55 ?? 8D 78 ?? 83 E7 ?? 89 47 ?? EB ?? 85 C9 74 ?? 51 E8 ?? ?? ?? ?? 8B 55 + ?? 83 C4 ?? 8B F8 EB ?? 33 FF 8B 45 ?? 89 43 ?? 8B 45 ?? 89 73 ?? 8D 34 3A 03 C6 83 + 7D ?? ?? 89 45 ?? 52 72 ?? 8B 33 56 57 E8 ?? ?? ?? ?? FF 75 ?? 8B 45 ?? FF 75 ?? 03 + C7 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 4D ?? 41 C6 00 ?? 81 F9 ?? ?? ?? ?? 72 ?? + 8B 56 ?? 83 C1 ?? 2B F2 8D 46 ?? 83 F8 ?? 77 ?? 8B F2 51 56 E8 ?? ?? ?? ?? 83 C4 ?? + 89 3B 8B C3 5F 5E 5B 8B E5 5D C2 ?? ?? 53 57 E8 ?? ?? ?? ?? FF 75 ?? FF 75 ?? 56 E8 + ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? C6 00 ?? 8B C3 89 3B 5F 5E 5B 8B E5 5D C2 ?? ?? E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? CC CC CC 56 8B F1 FF 76 ?? E8 ?? ?? ?? ?? 8B + 4E ?? 83 F9 ?? 72 ?? 8B 06 8D 0C 4D ?? ?? ?? ?? 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 + C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 77 ?? 8B C2 51 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 46 ?? ?? + ?? ?? ?? 33 C0 C7 46 ?? ?? ?? ?? ?? 66 89 06 5E C3 E8 ?? ?? ?? ?? CC CC CC CC CC CC + 8B 09 85 C9 74 ?? 8B 01 6A ?? FF 10 C3 } - $enumerate_resources = { - 55 8B EC 83 EC ?? 8D 45 ?? 50 FF 75 ?? 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 0F 85 - ?? ?? ?? ?? 53 8B 1D ?? ?? ?? ?? 56 57 BE ?? ?? ?? ?? 56 6A ?? FF D3 8B F8 89 7D ?? - 85 FF [2-8] 83 4D ?? ?? 8D 45 ?? 50 57 8D 45 ?? 50 FF 75 ?? 89 75 ?? E8 - ?? ?? ?? ?? 85 C0 75 ?? 39 45 ?? 74 ?? 8D 77 ?? F6 46 ?? ?? 74 ?? 8D 46 ?? 50 [0-3] - E8 ?? ?? ?? ?? EB ?? 83 7E ?? ?? 75 ?? FF 36 FF 15 ?? ?? ?? ?? 8D 44 00 ?? 50 6A - ?? FF D3 8B F8 85 FF 74 ?? FF 36 57 FF 15 ?? ?? ?? ?? [0-5] 57 E8 ?? ?? ?? - ?? 57 FF 15 ?? ?? ?? ?? 83 C6 ?? FF 4D ?? 75 ?? 8B 7D ?? 57 FF 15 ?? ?? ?? ?? FF 75 - ?? E8 ?? ?? ?? ?? 5F 5E 5B C9 C2 + $drop_ransom_note = { + 52 51 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 74 ?? 8D 4D ?? C6 46 ?? ?? + E8 ?? ?? ?? ?? 8B 45 ?? E9 ?? ?? ?? ?? 8B CE C6 45 ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 8D + 4E ?? 50 E8 ?? ?? ?? ?? 81 CF ?? ?? ?? ?? 89 BD ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? + ?? ?? 8B C2 8B 8D ?? ?? ?? ?? 2B C1 89 8D ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 83 F8 ?? + 72 ?? 83 FA ?? 8D B5 ?? ?? ?? ?? 8D 41 ?? 0F 43 B5 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D + 04 0E 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? C6 44 30 ?? ?? 8D 85 ?? ?? ?? ?? + EB } condition: - uint16(0)==0x5A4D and (($create_key_file and $create_lst_file and $enumerate_resources and $encrypt_files) or ($create_key and $enumerate_resources and $encrypt_files)) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($drop_ransom_note) } -rule REVERSINGLABS_Win32_Ransomware_Crypren : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Zeppelin : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Crypren ransomware." + description = "Yara rule that detects Zeppelin ransomware." author = "ReversingLabs" - id = "9a6ff190-b26b-5b75-9103-95a3b2e80701" + id = "f5cf514d-4dd0-58b7-82d0-5cb516a139a3" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Crypren.yara#L1-L144" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "7047d48782762e42544063fde6f2be62eb19f22853ea84abb5bce67c962da172" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Zeppelin.yara#L1-L109" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "8fb07e49d2ff9d497fb36a5d901748315ae519f5ef845d1a5ec6341d0eb1f68c" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -29195,131 +30915,97 @@ rule REVERSINGLABS_Win32_Ransomware_Crypren : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Crypren" + tc_detection_name = "Zeppelin" tc_detection_factor = 5 importance = 25 strings: - $enum_directories_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 - 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 - 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - } - $enum_directories_p2 = { - 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 - 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 85 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 - } - $enum_directories_p3 = { - 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 - ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D BD ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? 90 83 7F ?? ?? 8B 5F ?? 72 ?? 8B 37 EB ?? 8B F7 83 7D ?? ?? 8D - 45 ?? 8B D3 0F 43 45 ?? 3B CB 0F 42 D1 85 D2 74 ?? 83 EA ?? 72 ?? 8D 9B ?? ?? ?? ?? - 8B 08 3B 0E 75 ?? 83 C0 ?? 83 C6 ?? 83 EA ?? 73 ?? 83 FA ?? 74 ?? 8A 08 3A 0E 75 ?? - 83 FA ?? 74 ?? 8A 48 ?? 3A 4E ?? 75 ?? 83 FA ?? 74 ?? 8A 48 ?? 3A 4E ?? 75 ?? 83 FA - ?? 74 ?? 8A 40 ?? 3A 46 ?? 74 ?? 1B C0 83 C8 ?? EB ?? 33 C0 8B 4D ?? 85 C0 75 ?? 3B - CB 73 ?? 83 C8 ?? EB ?? 33 C0 3B CB 0F 95 C0 85 C0 0F 94 C0 84 C0 75 ?? 8B 85 ?? ?? - ?? ?? 83 C7 ?? 40 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 82 ?? ?? ?? ?? B3 ?? EB ?? 32 DB 68 - ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? - 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8A C3 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E - 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $search_files_p1 = { + 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 + 89 20 8D 45 ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 8B 45 ?? E8 ?? + ?? ?? ?? 8B D8 8B 45 ?? E8 ?? ?? ?? ?? 2B D8 43 53 8B 45 ?? E8 ?? ?? ?? ?? 8B D0 42 + 8B 45 ?? 59 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? FF 30 FF 75 ?? 68 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? 83 F8 + ?? 7C ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 + ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + C3 } - $encrypt_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 33 FF C6 45 ?? ?? 83 7D ?? ?? 8D 45 ?? 6A - ?? 0F 43 45 ?? 8D 8D ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 6A ?? - 0F 43 45 ?? 8D 8D ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8B - 94 0D ?? ?? ?? ?? 85 D2 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? 39 BC 05 ?? ?? - ?? ?? 0F 85 ?? ?? ?? ?? F6 C2 ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 03 C8 8D 45 ?? - 50 E8 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? C6 45 ?? ?? 8B F0 - 85 C9 74 ?? 8B 11 FF 52 ?? 85 C0 74 ?? 8B 10 8B C8 6A ?? FF 12 8B 06 8B CE 6A ?? 8B - 40 ?? FF D0 88 45 ?? 8D 45 ?? FF 75 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 4D ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 39 75 ?? 76 ?? EB ?? 8D A4 24 - ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 8D 4D ?? 0F 43 45 ?? 83 7D ?? ?? 0F 43 4D ?? 33 D2 + $search_files_p2 = { + 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? + ?? 64 FF 30 64 89 20 F6 85 ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 + ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 45 ?? 50 + 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 8D + ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? + 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? + ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5B 8B E5 5D C3 } - $encrypt_files_p2 = { - 0F BE 1C 30 8B C7 F7 75 ?? 8A 0C 0A 0F BE C1 03 C3 3D ?? ?? ?? ?? 7C ?? 25 ?? ?? ?? - ?? 79 ?? 48 0D ?? ?? ?? ?? 40 EB ?? 02 D9 0F B6 C3 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 46 83 C4 ?? 47 3B 75 ?? 72 ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 8B 48 ?? F6 84 0D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? - ?? ?? 83 C4 ?? 83 7D ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 72 - ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D - ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C6 45 ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D - ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $kill_processes = { + 55 8B EC 33 C9 51 51 51 51 51 51 51 51 53 56 57 84 D2 74 ?? 83 C4 ?? E8 ?? ?? ?? ?? + 88 55 ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 D2 55 68 ?? ?? ?? ?? + 64 FF 32 64 89 22 8D 55 ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B D8 8B 45 ?? 89 58 ?? 8B C3 B2 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? + C6 40 ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 74 ?? 83 E8 ?? 8B 00 8B F0 85 F6 + 7E ?? BB ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? 0F B6 54 1A ?? E8 ?? ?? ?? ?? 8B 45 ?? 50 8D + 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 58 E8 ?? ?? ?? ?? 75 ?? 8D 55 ?? 8B 45 + ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8B 40 ?? 8B 08 FF 51 ?? 8D 45 ?? E8 ?? ?? ?? ?? + EB ?? 8D 45 ?? 8B 55 ?? 0F B6 54 1A ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? E8 ?? ?? ?? + ?? 43 4E 75 ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? B1 ?? 33 + D2 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? + 8B 45 ?? 80 7D ?? ?? 74 ?? E8 ?? ?? ?? ?? 64 8F 05 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 5F + 5E 5B 8B E5 5D C3 } - $enum_drives_p1 = { - 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 + $enum_shares = { + 55 8B EC B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 ?? 51 53 56 57 89 45 ?? 8B 45 ?? E8 ?? ?? + ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 + 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 4D ?? 33 + D2 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 89 45 ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B + 45 ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 55 ?? B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 10 FF 52 ?? 48 85 + C0 0F 8C ?? ?? ?? ?? 40 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 8B 55 ?? 8B 45 ?? 8B + 18 FF 53 ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 33 C0 55 68 ?? ?? ?? ?? 64 + FF 30 64 89 20 FF 75 ?? 68 ?? ?? ?? ?? 8D 4D ?? 33 D2 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 + ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? + 8D 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 + 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 75 ?? FF 45 ?? + FF 4D ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A + 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? + ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB + ?? 5F 5E 5B 8B E5 5D C3 } - $enum_drives_p2 = { - E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 - 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D - 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 - ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 + $encrypt_files = { + 55 8B EC 83 C4 ?? 53 56 33 DB 89 5D ?? 84 D2 74 ?? 83 C4 ?? E8 ?? ?? ?? ?? 8B D9 88 + 55 ?? 8B F0 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 D2 8B C6 E8 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 88 5E ?? 88 5E ?? 56 6A ?? 8D 46 ?? 50 B9 ?? ?? ?? ?? 33 D2 33 C0 E8 ?? + ?? ?? ?? 8B D8 89 5E ?? 85 DB 75 ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? + 89 45 ?? C6 45 ?? ?? 8D 45 ?? 50 6A ?? 8B 0D ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? + ?? C3 } condition: - uint16(0)==0x5A4D and (( all of ($enum_directories_p*)) and ( all of ($enum_drives_p*)) and ( all of ($encrypt_files_p*))) + uint16(0)==0x5A4D and ($kill_processes) and ($enum_shares) and ( all of ($search_files_p*)) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_FLKR : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Tblocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects FLKR ransomware." + description = "Yara rule that detects TBLocker ransomware." author = "ReversingLabs" - id = "7f3abcd0-8dfa-5914-9ad0-566c16c2e2ab" + id = "91793018-baf6-5e70-83b6-8793482c3bec" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.FLKR.yara#L1-L71" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "4ab00ba82baceec9899556d3a774ec08c83c10930cec194e18e3b4e16ebacb58" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.TBLocker.yara#L1-L85" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "81f0077655ac0e59cd8dc05be602ae500c938668bd57d3cf4a51fbff2a5b6b83" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -29327,73 +31013,79 @@ rule REVERSINGLABS_Win32_Ransomware_FLKR : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "FLKR" + tc_detection_name = "TBLocker" tc_detection_factor = 5 importance = 25 strings: - $search_and_encrypt_p1 = { - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 55 56 57 8B BC 24 ?? - ?? ?? ?? 57 89 7C 24 ?? FF 15 ?? ?? ?? ?? 8B 2D ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 89 44 - 24 ?? FF D5 8D 44 24 ?? 50 57 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? - ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? 51 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 54 24 ?? 52 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 8D 4C 24 ?? 51 - 57 C6 04 07 ?? FF D5 F6 44 24 ?? ?? 0F 84 ?? ?? ?? ?? 8D 5C 24 ?? E8 ?? ?? ?? ?? 84 - C0 0F 85 ?? ?? ?? ?? 8A 0F 33 D2 84 C9 74 ?? BE ?? ?? ?? ?? 8B C7 2B F7 88 0C 06 8A - 48 ?? 40 42 84 C9 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? C6 82 ?? ?? ?? ?? ?? C6 82 ?? - ?? ?? ?? ?? FF D5 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 - 74 ?? 56 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 - ?? 68 ?? ?? ?? ?? 57 FF D5 57 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 C0 38 44 24 ?? 74 + $main_ransomware_function_p1 = { + 00 02 16 28 ?? ?? ?? ?? 00 02 17 28 ?? ?? ?? ?? 00 02 16 28 ?? ?? ?? ?? 00 02 16 28 ?? ?? ?? ?? 00 02 + 16 28 ?? ?? ?? ?? 00 02 28 ?? ?? ?? ?? 00 00 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 16 FE ?? 0A 06 2C ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 72 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 18 16 15 28 ?? ?? ?? ?? 26 00 00 28 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 16 FE ?? 0B 07 39 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE ?? 0C 08 2C ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 00 00 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 6F ?? + ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 00 DE ?? 25 + 28 ?? ?? ?? ?? 0D 00 28 ?? ?? ?? ?? DE ?? 00 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 17 28 ?? ?? ?? ?? + 00 02 18 28 ?? ?? ?? ?? 00 02 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? + 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 02 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 59 } - $search_and_encrypt_p2 = { - 40 80 7C 04 ?? ?? 75 ?? 8A 4C 04 ?? 80 F9 ?? 75 ?? 80 7C 04 ?? ?? 75 ?? 80 7C 04 ?? - ?? 75 ?? 80 7C 04 ?? ?? 74 ?? 80 F9 ?? 75 ?? B3 ?? 38 5C 04 ?? 75 ?? 80 7C 04 ?? ?? - 75 ?? 80 7C 04 ?? ?? 75 ?? 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? FF 05 ?? ?? ?? ?? E9 ?? - ?? ?? ?? FF 05 ?? ?? ?? ?? E9 ?? ?? ?? ?? B3 ?? B2 ?? 80 F9 ?? 75 ?? 38 5C 04 ?? 75 - ?? 80 7C 04 ?? ?? 75 ?? 38 5C 04 ?? 75 ?? 32 D2 80 F9 ?? 75 ?? 80 7C 04 ?? ?? 75 ?? - 80 7C 04 ?? ?? 75 ?? 80 7C 04 ?? ?? 75 ?? 32 D2 80 F9 ?? 75 ?? 80 7C 04 ?? ?? 75 ?? - 80 7C 04 ?? ?? 75 ?? 80 7C 04 ?? ?? 0F 84 ?? ?? ?? ?? 84 D2 0F 84 ?? ?? ?? ?? 8A 0F - 33 D2 84 C9 74 ?? 8D B4 24 ?? ?? ?? ?? 8B C7 2B F7 8D A4 24 ?? ?? ?? ?? 88 0C 06 8A - 48 ?? 40 42 84 C9 75 ?? A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 0F B6 - 05 ?? ?? ?? ?? C6 84 14 ?? ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 89 94 24 ?? ?? ?? ?? 8B 15 - ?? ?? ?? ?? 88 84 24 ?? ?? ?? ?? 33 C0 6A ?? 89 8C 24 ?? ?? ?? ?? 89 94 24 ?? ?? ?? - ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 88 84 24 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 68 ?? ?? ?? ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B 0D ?? - ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B E8 A1 ?? ?? ?? ?? 89 8C 24 ?? ?? ?? ?? 8B 0D ?? ?? ?? - ?? 89 84 24 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 89 94 24 ?? ?? ?? ?? 66 8B 15 ?? ?? ?? - ?? 89 8C 24 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? 8D 74 24 ?? 89 6C 24 ?? 66 89 + $main_ransomware_function_p2 = { + 28 ?? ?? ?? ?? B7 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? + ?? 5B 28 ?? ?? ?? ?? B7 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? + ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 02 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6C 23 + ?? ?? ?? ?? ?? ?? ?? ?? 5B 59 28 ?? ?? ?? ?? B7 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? + ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 23 ?? ?? ?? ?? ?? ?? ?? ?? 5A 28 ?? ?? ?? ?? B7 73 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 00 02 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6C 23 ?? ?? + ?? ?? ?? ?? ?? ?? 5B 02 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 59 28 ?? ?? ?? + ?? B7 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F ?? DA 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 00 02 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? + ?? ?? 5B 02 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 59 28 ?? ?? ?? ?? B7 28 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 23 ?? ?? ?? ?? ?? + ?? ?? ?? 5A 28 ?? ?? ?? ?? B7 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F } - $search_and_encrypt_p3 = { - 94 24 ?? ?? ?? ?? 88 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 51 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 0F 84 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? - 52 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 - E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 56 - 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 6A ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 - 8D 84 24 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 6A - ?? 51 E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 - ?? 56 E8 ?? ?? ?? ?? 8B 7C 24 ?? 83 C4 ?? FF 05 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 - FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 2B F0 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 03 - C6 50 8D 8C 24 ?? ?? ?? ?? 51 8B D1 52 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 85 C0 75 ?? FF 05 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 55 E8 ?? ?? - ?? ?? 8B 2D ?? ?? ?? ?? 83 C4 ?? 8B 74 24 ?? 8D 4C 24 ?? 51 56 FF 15 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? 56 FF 15 + $search_files = { + 00 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 03 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 38 ?? ?? ?? ?? 06 6F ?? ?? ?? + ?? 0B 07 07 6F ?? ?? ?? ?? 17 DA 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 16 FE + ?? 0C 08 2C ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE ?? 0D 09 2C ?? 00 02 07 07 72 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 07 28 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? + ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 16 14 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? DE ?? 00 00 00 00 00 00 06 6F + ?? ?? ?? ?? 13 ?? 11 ?? 3A ?? ?? ?? ?? DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? 00 DC DE ?? 25 28 ?? ?? ?? ?? + 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 03 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? + 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 11 ?? 6F ?? + ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 17 DA 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? + ?? ?? ?? 16 FE ?? 13 ?? 11 ?? 2C ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE ?? 13 ?? + 11 ?? 2C ?? 00 02 11 ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 11 ?? + 28 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 16 14 28 ?? ?? ?? ?? 26 28 ?? + ?? ?? ?? DE ?? 00 00 00 00 00 00 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 3A ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 + ?? 6F ?? ?? ?? ?? 00 DC DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 00 11 ?? 17 D6 13 ?? + 11 ?? 11 ?? 8E 69 FE ?? 13 ?? 11 ?? 3A ?? ?? ?? ?? 2A + } + $encrypt_files = { + 00 00 03 19 17 73 ?? ?? ?? ?? 0A 04 18 18 73 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? 0C 08 28 ?? ?? ?? ?? 05 6F + ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 08 28 ?? ?? ?? ?? 05 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? + 0D 07 09 17 73 ?? ?? ?? ?? 13 ?? 06 6F ?? ?? ?? ?? 17 6A DA B7 17 D6 8D ?? ?? ?? ?? 13 ?? 06 11 ?? 16 + 11 ?? 8E 69 6F ?? ?? ?? ?? 26 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 07 + 6F ?? ?? ?? ?? 00 06 6F ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 2A } condition: - uint16(0)==0x5A4D and ( all of ($search_and_encrypt_p*)) + uint16(0)==0x5A4D and (( all of ($main_ransomware_function_p*)) and $search_files and $encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_PXJ : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Ghostbin : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects PXJ ransomware." + description = "Yara rule that detects Ghostbin ransomware." author = "ReversingLabs" - id = "c1549905-5b31-55c0-a275-0ab8133b3504" - date = "2020-07-15" - modified = "2020-07-15" + id = "4d576854-7a30-527d-9a7a-f22018183540" + date = "2021-09-06" + modified = "2021-09-06" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.PXJ.yara#L1-L158" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "e88d27dcd7ad3af459bd7e34fcc827822365441446b0e4e7bbec399c9a948cb7" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Ghostbin.yara#L1-L61" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3881e1c83ac2a31fdd8a081d3e6e6ea759771dbc183c3af9528930619bcddf9e" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -29401,147 +31093,54 @@ rule REVERSINGLABS_Win32_Ransomware_PXJ : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "PXJ" + tc_detection_name = "Ghostbin" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 8B D9 68 ?? ?? ?? ?? - 33 F6 8D 8D ?? ?? ?? ?? 33 C0 56 51 89 9D ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? 53 8D 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? - ?? 51 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? - ?? ?? 8A 85 ?? ?? ?? ?? A8 ?? 0F 85 ?? ?? ?? ?? A8 ?? 0F 84 ?? ?? ?? ?? 53 8D 85 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? E9 ?? ?? - ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? 66 8B - 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? - 3B C6 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 - } - $find_files_p2 = { - 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 C0 EB - ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 9F ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B FF - 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 - ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 8B FF 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 - ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? - ?? ?? ?? 53 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? - ?? ?? 52 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8B D1 83 C4 ?? 0B D0 89 B5 ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? 74 ?? 50 51 8D - 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 3A C1 75 ?? 01 8F ?? ?? ?? ?? 11 - B7 ?? ?? ?? ?? EB ?? 01 8F ?? ?? ?? ?? 11 B7 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? 51 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 8B 4D ?? 5E 33 CD B0 ?? 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $encrypt_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 - ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 45 ?? 6A ?? 68 - ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 89 85 ?? ?? ?? ?? 8B 45 ?? 68 ?? ?? ?? ?? 50 89 85 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 4D - ?? 8B 55 ?? 51 52 E8 ?? ?? ?? ?? 0B C2 74 ?? 53 FF 15 ?? ?? ?? ?? B0 ?? E9 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 33 DB 8D 85 ?? ?? ?? ?? 53 50 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 53 51 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 33 F6 6A ?? 53 E8 ?? ?? ?? ?? 88 44 35 ?? - 46 83 FE ?? 7C ?? 8D 55 ?? 52 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? B8 ?? - ?? ?? ?? 8D B5 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B CE 89 5D ?? E8 ?? ?? ?? ?? 81 EC ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B F4 89 A5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? 6A ?? 51 - } - $encrypt_files_p2 = { - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 72 ?? 8B 95 - ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B B5 ?? ?? ?? ?? 53 53 33 C9 51 33 C0 50 56 - FF 15 ?? ?? ?? ?? 85 C0 75 ?? 56 FF 15 ?? ?? ?? ?? 32 C0 E9 ?? ?? ?? ?? 53 8D 85 ?? - ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 56 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? - ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? - 8B 3D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B C3 0F 84 ?? ?? ?? ?? 6A ?? F7 D8 99 53 52 50 - 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 - 8D 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 8D 8D ?? ?? ?? ?? 51 50 8D - 95 ?? ?? ?? ?? 52 56 FF D7 85 C0 0F 84 ?? ?? ?? ?? 39 9D ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 39 9D ?? ?? ?? ?? 77 ?? 81 BD ?? - ?? ?? ?? ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 11 9D ?? ?? ?? ?? 8B 9D - ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 33 D2 52 52 52 33 C9 51 50 - FF 15 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B C6 8D - } - $encrypt_files_p3 = { - 48 ?? 8B FF 66 8B 10 83 C0 ?? 66 85 D2 75 ?? 2B C1 6A ?? D1 F8 8D 8D ?? ?? ?? ?? 51 - 8D 14 00 8B 83 ?? ?? ?? ?? 52 56 50 FF D7 8B 93 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? - 51 6A ?? 68 ?? ?? ?? ?? 52 FF D7 8B 93 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? - 8D 4D ?? 51 52 FF D7 8B 8B ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? - ?? 51 FF D7 8B 8B ?? ?? ?? ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 6A ?? 8D 85 ?? ?? ?? ?? 50 - 51 FF D7 8B B5 ?? ?? ?? ?? 6A ?? 33 C9 51 51 B8 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? - 85 C0 74 ?? 33 DB EB ?? 83 85 ?? ?? ?? ?? ?? 11 9D ?? ?? ?? ?? 53 8D 95 ?? ?? ?? ?? - 52 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? - ?? 8B 9D ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 51 52 8D BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B 95 - ?? ?? ?? ?? 83 C4 ?? 52 FF 15 ?? ?? ?? ?? 33 C9 51 51 33 C0 51 50 8B 83 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 8B 8B ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 56 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 94 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B - 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 + $setup_env = { + 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 06 07 9A 0C + 08 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 18 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 + 28 ?? ?? ?? ?? 2C ?? 08 6F ?? ?? ?? ?? 19 FE 01 08 6F ?? ?? ?? ?? 18 FE 01 60 2C ?? 08 + 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 07 17 D6 0B 07 06 8E 69 32 ?? 00 72 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 2C ?? 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? + ?? DE ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 72 + ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 1F ?? 16 28 ?? ?? ?? ?? 26 DE ?? 28 ?? ?? ?? ?? 28 ?? ?? + ?? ?? DE ?? 2A } - $delete_volumes_snapshots_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 45 ?? 6A ?? 33 FF 57 57 89 - 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? FF D6 57 68 ?? - ?? ?? ?? FF D6 57 68 ?? ?? ?? ?? FF D6 57 68 ?? ?? ?? ?? FF D6 57 68 ?? ?? ?? ?? FF - D6 57 57 8D 8D ?? ?? ?? ?? 51 57 89 BD ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 57 68 ?? ?? ?? ?? - 6A ?? 57 57 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F - 84 ?? ?? ?? ?? 83 EC ?? 8B F4 89 7E ?? C7 46 ?? ?? ?? ?? ?? BF ?? ?? ?? ?? B8 ?? ?? - ?? ?? 89 A5 ?? ?? ?? ?? C6 06 ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 33 FF 89 7D ?? 83 78 ?? ?? 72 ?? 8B 00 8D 50 ?? 8D 9B ?? ?? ?? ?? 8A 08 40 84 - C9 75 ?? 2B C2 57 8D 95 ?? ?? ?? ?? 52 50 83 EC ?? 8B F4 89 7E ?? C7 46 ?? ?? ?? ?? - ?? BF ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 A5 ?? ?? ?? ?? 88 0E E8 ?? ?? ?? ?? 8D B5 ?? ?? - ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 83 C4 ?? 39 70 ?? 72 ?? 8B 00 50 53 FF 15 ?? ?? - ?? ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? - ?? ?? ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 53 FF - 15 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B C7 8B FF 66 8B 10 66 3B 11 75 ?? - 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 + $encrypt_files = { + 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0A 25 6F ?? ?? ?? ?? 25 06 28 ?? ?? ?? ?? 03 6F ?? ?? ?? + ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 6F ?? ?? ?? ?? 0C 6F ?? ?? ?? + ?? 02 16 02 8E 69 6F ?? ?? ?? ?? 0B 07 8E 69 17 59 1F ?? 58 17 58 8D ?? ?? ?? ?? 0D 08 + 09 1F ?? 28 ?? ?? ?? ?? 07 16 09 1F ?? 07 8E 69 28 ?? ?? ?? ?? 09 2A } - $delete_volumes_snapshots_p2 = { - EB ?? 1B C0 83 D8 ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 89 85 - ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? EB ?? 8D 64 24 ?? 8B BD ?? ?? ?? ?? BA ?? ?? ?? ?? 8B - CE D3 E2 85 95 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 4E ?? 66 89 8D ?? ?? ?? ?? 33 C9 6A - ?? 51 8D 95 ?? ?? ?? ?? 52 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? - 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8D 9F ?? - ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 6A ?? 52 E8 ?? ?? ?? ?? 83 - C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 83 EC ?? B8 ?? ?? ?? ?? 8B CC 89 A5 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? - ?? ?? 83 78 ?? ?? 72 ?? 8B 00 8D 50 ?? 8D A4 24 ?? ?? ?? ?? 8A 08 40 84 C9 75 ?? 33 - FF 57 8D 8D ?? ?? ?? ?? 51 2B C2 50 83 EC ?? B8 ?? ?? ?? ?? 8B CC 89 A5 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 83 C4 ?? 39 70 ?? 72 - ?? 8B 00 50 53 FF 15 ?? ?? ?? ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? - ?? ?? ?? 83 C4 ?? BE ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 89 B5 ?? - ?? ?? ?? 89 BD ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 72 ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 53 89 B5 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 8B B5 ?? ?? ?? ?? 46 89 B5 ?? ?? ?? ?? 83 FE ?? 0F 8C ?? ?? ?? ?? EB ?? 57 - 8D 9F ?? ?? ?? ?? E8 ?? ?? ?? ?? B0 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B - 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 + $find_files = { + 02 17 8D ?? ?? ?? ?? 25 16 1F ?? 9D 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 6F ?? ?? ?? ?? 28 + ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 0A 16 0B + 2B ?? 06 07 9A 0C 7E ?? ?? ?? ?? 08 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 08 28 ?? ?? ?? + ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 08 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 08 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 28 ?? + ?? ?? ?? 08 28 ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 0D 28 ?? ?? ?? ?? DE ?? 07 17 D6 0B + 07 06 8E 69 32 ?? 02 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 28 ?? ?? ?? ?? + 11 ?? 17 D6 13 ?? 11 ?? 11 ?? 8E 69 32 ?? DE ?? 25 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? + DE ?? 2A } condition: - uint16(0)==0x5A4D and ( all of ($delete_volumes_snapshots_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($setup_env) and ($find_files) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Gpgqwerty : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Princesslocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects GPGQwerty ransomware." + description = "Yara rule that detects PrincessLocker ransomware." author = "ReversingLabs" - id = "8848e00a-a695-575b-a29d-fc9521859e12" + id = "b76ef137-aa0b-5fd3-9876-2459cb6535ff" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.GPGQwerty.yara#L1-L83" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "e59adadd66b4d242ac7337ce4b3c3ec6c60724f4cf5b86305f1e31b88745928c" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.PrincessLocker.yara#L1-L92" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "5be4ca3bd0b0afed1d2f3a59e2951d74a8de94c5a4d5a2c6cc29add49eab9ec0" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -29549,79 +31148,95 @@ rule REVERSINGLABS_Win32_Ransomware_Gpgqwerty : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "GPGQwerty" + tc_detection_name = "PrincessLocker" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 56 53 89 D3 81 EC ?? ?? ?? ?? 8D 54 24 ?? 89 04 24 89 54 24 ?? E8 ?? ?? ?? ?? 83 EC - ?? 83 F8 ?? 89 C6 74 ?? 31 C0 8D 4B ?? 66 89 43 ?? 31 C0 EB ?? 0F B7 43 ?? 83 C0 ?? - 66 3D ?? ?? 66 89 43 ?? 83 D1 ?? 0F B7 C0 0F B6 44 04 ?? 84 C0 88 01 75 ?? 8B 44 24 - ?? 24 ?? 83 F8 ?? 76 ?? C7 43 ?? ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 89 F0 5B 5E C3 66 90 - 89 43 ?? 81 C4 ?? ?? ?? ?? 89 F0 5B 5E C3 E8 ?? ?? ?? ?? 89 C3 E8 ?? ?? ?? ?? 83 F8 - ?? 89 03 74 ?? E8 ?? ?? ?? ?? 81 38 ?? ?? ?? ?? 74 ?? E8 ?? ?? ?? ?? 83 38 ?? 74 ?? - E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? EB ?? E8 ?? - ?? ?? ?? C7 00 ?? ?? ?? ?? EB ?? 90 56 53 89 D3 81 EC ?? ?? ?? ?? 8D 54 24 ?? 89 04 - 24 89 54 24 ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 89 C6 74 ?? 31 C0 8D 4B ?? 66 89 43 ?? - 31 C0 EB ?? 0F B7 43 ?? 83 C0 ?? 66 3D ?? ?? 66 89 43 ?? 83 D1 ?? 0F B7 C0 0F B6 44 - 04 ?? 84 C0 88 01 75 ?? 8B 44 24 ?? 24 ?? 83 F8 ?? 77 ?? 89 43 ?? 81 C4 ?? ?? ?? ?? - 89 F0 5B 5E C3 8D B4 26 ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 89 F0 5B - 5E C3 E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 81 C4 ?? ?? ?? - ?? 89 F0 5B 5E C3 + $encrypt_files = { + 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + 6A ?? 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? 83 7D ?? ?? 0F 43 45 + ?? 50 53 FF D7 6A ?? FF B5 ?? ?? ?? ?? 8B F0 FF 15 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? + FF B5 ?? ?? ?? ?? FF D6 85 C0 75 ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 6A ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 85 C0 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? + 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 50 53 FF D7 68 ?? ?? ?? + ?? 8D 4D ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 68 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 89 9D ?? ?? ?? ?? 85 DB 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D + 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? A1 ?? ?? + ?? ?? 8B 30 89 B5 ?? ?? ?? ?? 3B F0 0F 84 ?? ?? ?? ?? 33 C9 C6 45 ?? ?? 6A ?? 51 8D + 46 ?? 66 89 8D ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? + ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 83 BD ?? ?? ?? ?? ?? 72 ?? FF B5 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 7D ?? ?? + 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 50 FF 75 ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 83 EC ?? C6 45 ?? ?? 8B CC + 33 C0 6A ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 50 66 89 01 8D 85 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? + C3 C7 45 ?? ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 68 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 + 45 ?? ?? 83 BD ?? ?? ?? ?? ?? 72 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? + 68 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D BD ?? ?? + ?? ?? 6A ?? 6A ?? 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 83 BD + ?? ?? ?? ?? ?? 6A ?? 0F 43 BD ?? ?? ?? ?? 6A ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 + 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? + ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 8B F8 83 FF + ?? 0F 84 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? + ?? ?? 50 FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 85 + ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 48 39 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? + 0F B6 C9 0F 46 C8 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? 0F B6 C1 6A ?? 50 6A ?? FF + B5 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 FF B5 + ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 FF 15 } - $find_files_p2 = { - 8B 45 ?? 89 45 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 95 C0 84 - C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? - ?? 85 C0 74 ?? 8B 45 ?? 83 C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 - C0 74 ?? C6 85 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 ?? - ?? ?? ?? 8B 45 ?? 83 C0 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 94 C0 84 C0 0F 84 - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 83 - C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 45 - ?? 83 C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 8B 45 ?? 83 C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? - ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E8 + $remote_connection_1 = { + 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 84 DB 0F 85 ?? ?? ?? + ?? 6A ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 88 5D ?? C7 45 ?? ?? + ?? ?? ?? 66 C7 45 ?? ?? ?? 88 5D ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? BA ?? ?? ?? ?? 89 45 ?? E8 ?? ?? ?? ?? 8B F0 8D 55 ?? C6 45 ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B D0 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 56 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 } - $encrypt_files = { - C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 - C0 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 89 44 - 24 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? - ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 C2 B8 - ?? ?? ?? ?? 89 D7 F2 AE 89 C8 F7 D0 8D 50 ?? 8D 85 ?? ?? ?? ?? 01 D0 66 C7 00 ?? ?? - 8B 45 ?? 83 E8 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 + $remote_connection_2 = { + BA ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 66 C7 45 ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 8D 55 ?? C6 45 + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 BA ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B F0 8D 55 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 + 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 8B D0 C6 45 ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 53 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? + ?? 51 8B D0 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 50 E8 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) + uint16(0)==0x5A4D and $encrypt_files and $remote_connection_1 and $remote_connection_2 } -rule REVERSINGLABS_Win32_Ransomware_Kawaiilocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_ONI : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects KawaiiLocker ransomware." + description = "Yara rule that detects Oni ransomware." author = "ReversingLabs" - id = "8c368e2d-3c6f-5c4b-880b-ebdb06dcf901" - date = "2020-08-17" - modified = "2020-08-17" + id = "9190aee2-1119-546e-82ca-a7aba44a9d7f" + date = "2024-09-01" + date = "2024-09-01" + modified = "2020-12-07" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.KawaiiLocker.yara#L1-L135" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "d86b41ef1c43da55869ad26facd5efdf232277f0e33483690a69a04c4ba8f7da" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Oni.yara#L1-L82" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "685abf5a5edba5bae19faaf6521ce617370cdab1404fe84d846e82a60182dfff" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -29629,136 +31244,74 @@ rule REVERSINGLABS_Win32_Ransomware_Kawaiilocker : TC_DETECTION MALICIOUS MALWAR sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "KawaiiLocker" tc_detection_factor = 5 importance = 25 strings: - $search_files = { - 55 8B EC 51 B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 ?? 51 87 4D ?? 53 56 57 88 4D ?? 89 55 - ?? 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8B 45 ?? E8 ?? - ?? ?? ?? 8B 55 ?? 80 7C 02 ?? ?? 75 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B D0 4A 8D 45 ?? E8 - ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F - 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B D0 83 CA ?? 3B D0 75 ?? 80 7D ?? ?? 0F 85 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8A 4D - ?? 8B 55 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? BE ?? ?? ?? ?? BB ?? ?? ?? ?? FF 75 ?? 68 - ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 13 E8 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? FF 75 ?? 68 ?? - ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D - 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 85 C0 75 ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? - FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 95 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 08 FF 51 ?? 83 C3 ?? 4E 0F 85 ?? ?? ?? ?? - E9 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8B C7 83 C8 ?? 3B C7 75 ?? 80 7D ?? ?? 0F 85 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8A 4D - ?? 8B 55 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? BE ?? ?? ?? ?? BB ?? ?? ?? ?? FF 75 ?? 68 - ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 13 E8 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? FF 75 ?? 68 ?? - ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D - 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 85 C0 75 ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? - FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 95 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 08 FF 51 ?? 83 C3 ?? 4E 0F 85 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? - E8 ?? ?? ?? ?? C3 - } - $remote_connection = { - 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? B2 - ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 45 ?? 50 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 59 E8 ?? ?? ?? ?? - 8D 4D ?? BA ?? ?? ?? ?? 33 C0 E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 75 - ?? 8D 4D ?? BA ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? FF 75 ?? 8D 45 ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 - ?? 8B 50 ?? 8B 45 ?? 8B 08 FF 51 ?? 8D 55 ?? 8B 45 ?? 8B 08 FF 51 ?? 8B 45 ?? 8D 55 - ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? E8 ?? ?? - ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B C3 8B 55 ?? E8 ?? ?? ?? ?? - 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $find_files = { + 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? + 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? + 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? + ?? 53 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? F6 85 ?? ?? ?? ?? + ?? 0F 84 ?? ?? ?? ?? 83 EC ?? 8B D4 C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C6 02 + ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 33 C9 EB ?? 8D 8D ?? ?? ?? ?? 8D 71 ?? 90 8A 01 41 84 + C0 75 ?? 2B CE 51 8D 85 ?? ?? ?? ?? 8B CA 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 84 C0 74 ?? 83 EC ?? 8D 45 ?? 8B CC 6A ?? 6A ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? + ?? ?? 50 C6 01 ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC 6A ?? 6A ?? C7 41 ?? ?? ?? + ?? ?? C7 41 ?? ?? ?? ?? ?? 50 C6 01 ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF + 15 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 75 + ?? 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 ?? 72 ?? 83 F9 ?? 77 ?? 8B C8 51 E8 ?? ?? ?? ?? + 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 F8 ?? 72 + ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 75 ?? 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 + ?? 72 ?? 83 F9 ?? 77 ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 5F 5E 33 CD 5B E8 + ?? ?? ?? ?? 8B E5 5D C3 } $encrypt_files = { - 55 8B EC 6A ?? 6A ?? 6A ?? 53 56 57 BB ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 - 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 - ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 10 FF 52 - ?? 8B F0 8B C3 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 - ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B DE 4B 85 DB 7C ?? 43 33 F6 8D 55 ?? 33 C0 E8 ?? ?? ?? ?? 8B 45 - ?? 8D 55 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? - ?? ?? 8B 08 FF 51 ?? 8D 4D ?? 8B D6 A1 ?? ?? ?? ?? 8B 38 FF 57 ?? 8B 45 ?? B1 ?? BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 46 4B 75 ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 6A ?? E8 ?? ?? ?? ?? 6A ?? E8 + 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 57 8B 3D ?? ?? ?? ?? 8D 45 ?? 68 + ?? ?? ?? ?? 6A ?? 33 F6 89 55 ?? 56 56 50 89 4D ?? 89 75 ?? FF D7 85 C0 75 ?? 68 ?? + ?? ?? ?? 6A ?? 50 50 8D 45 ?? 50 FF D7 8B 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 53 8D 45 ?? + 89 75 ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D0 E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 + DB 74 ?? 8D 45 ?? 50 6A ?? 6A ?? FF 75 ?? 53 57 FF 15 ?? ?? ?? ?? 53 6A ?? FF 15 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? + ?? ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? 8B F0 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 56 6A ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? + 8B 4D ?? 85 C9 74 ?? 8B 45 ?? 89 01 53 FF 15 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? + 5B 8B 4D ?? 8B C6 5F 33 CD 5E E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $search_processes = { + 6A ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 + ?? ?? ?? ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? + ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 B9 + ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 44 24 ?? ?? 8D 84 24 ?? ?? ?? ?? FF 74 24 ?? C7 05 ?? + ?? ?? ?? ?? ?? ?? ?? 50 8D 44 24 ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 50 C7 05 ?? ?? ?? + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? 83 EE ?? 4F 83 7E + ?? ?? 72 ?? 8B 1E 8B CE 56 E8 ?? ?? ?? ?? 8B 46 ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C3 ?? + 75 ?? 8B 43 ?? 3B C3 73 ?? 2B D8 83 FB ?? 72 ?? 83 FB ?? 77 ?? 8B D8 53 E8 ?? ?? ?? + ?? 83 C4 ?? C7 46 ?? ?? ?? ?? ?? 83 7E ?? ?? C7 46 ?? ?? ?? ?? ?? 72 ?? 8B 06 EB ?? + 8B C6 8B CE C6 00 ?? E8 ?? ?? ?? ?? 85 FF 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 5F 5E 5B 8B E5 5D C3 E8 ?? ?? ?? ?? CC CC CC CC CC B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? B9 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? C7 05 ?? ?? ?? ?? + ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 C3 } condition: - uint16(0)==0x5A4D and $search_files and $encrypt_files and $remote_connection + uint16(0)==0x5A4D and ($search_processes) and ($find_files) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Marlboro : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Redeemer : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Marlboro ransomware." + description = "Yara rule that detects Redeemer ransomware." author = "ReversingLabs" - id = "7cd3b436-47e3-5711-9b59-cef70efe3b45" - date = "2020-07-23" - modified = "2020-07-23" + id = "080ab595-862b-5dc2-aaff-a0efd819a9fa" + date = "2022-01-17" + modified = "2022-01-17" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Marlboro.yara#L1-L117" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "d36c3cf52af47e9f638f58aabc19298e8c58831c3083f82e4c194319503eeaaa" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Redeemer.yara#L1-L105" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "28287f6620a2f7a90057d1f97947e065721119e26398fe659331dc5fe99761de" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -29766,111 +31319,96 @@ rule REVERSINGLABS_Win32_Ransomware_Marlboro : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Marlboro" + tc_detection_name = "Redeemer" tc_detection_factor = 5 importance = 25 strings: - $ping_apnic = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 0F 57 - C0 F3 0F 7F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D - 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? - 8D 85 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $remote_server_connection_1 = { - BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D7 8B C8 E8 ?? ?? ?? ?? BA ?? ?? - ?? ?? 8B C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D6 8B - C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 55 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 55 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8B 40 ?? F6 84 05 ?? ?? ?? ?? ?? 74 ?? 83 EC ?? 8D 45 ?? 8D 4D ?? - 50 E8 ?? ?? ?? ?? C6 45 ?? ?? BA ?? ?? ?? ?? 8B C8 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 + $find_files = { + 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? + 8B BD ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C6 ?? 89 B5 ?? ?? + ?? ?? 89 B5 ?? ?? ?? ?? 3B F7 0F 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? 8B 3D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 89 A5 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC ?? + C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 84 C0 0F 85 ?? ?? ?? ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 89 A5 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? ?? ?? ?? C6 45 + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 75 ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 89 A5 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? ?? + ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 75 ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B + CC 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 } - $remote_server_connection_2 = { - 84 C0 74 ?? B3 ?? EB ?? 32 DB C7 45 ?? ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 83 7D - ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 DB 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3D ?? ?? ?? - ?? 74 ?? 8D 80 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? [0-3] 8B 85 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 03 C8 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 50 C6 - 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 C4 ?? 8B 8D ?? ?? ?? ?? 8B F0 85 C9 74 ?? 8B - 01 FF 50 ?? 85 C0 74 ?? 8B 10 8B C8 6A ?? FF 12 8B 06 8B CE 6A ?? 8B 40 ?? FF D0 + $encrypt_files_p1 = { + 80 FB ?? 0F 85 ?? ?? ?? ?? 83 EC ?? 8D 55 ?? 8B CC 89 A5 ?? ?? ?? ?? 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? + C7 41 ?? ?? ?? ?? ?? 83 79 ?? ?? C7 41 ?? ?? ?? ?? ?? 72 ?? 8B 01 EB ?? 8B C1 33 D2 + 6A ?? 66 89 10 8D 45 ?? 52 50 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 8B CC C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 83 + 79 ?? ?? C7 41 ?? ?? ?? ?? ?? 72 ?? 8B 01 EB ?? 8B C1 33 D2 6A ?? 66 89 10 8D 45 ?? + 52 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 8D 45 ?? 3B C6 + 74 ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 33 C0 C7 45 ?? + ?? ?? ?? ?? 56 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? C6 45 } - $remote_server_connection_3 = { - 50 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 5D ?? 83 C4 ?? 8B 7D ?? 8B 08 8B 49 - ?? F6 44 01 ?? ?? 75 ?? 8B 75 ?? 8D 4D ?? 83 FB ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? 0F - 43 CF 3B F0 0F 42 C6 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 83 FE ?? 73 ?? 83 C8 ?? - EB ?? 33 C0 83 FE ?? 0F 95 C0 85 C0 0F 94 C0 84 C0 0F 94 C0 84 C0 0F 85 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - B5 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 83 FB ?? 72 + $encrypt_files_p2 = { + 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 35 ?? ?? ?? ?? 33 C0 83 7D ?? ?? 66 89 85 ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? + 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF D6 85 C0 0F 85 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 72 ?? 8B 00 50 FF D6 8B 85 ?? ?? ?? + ?? 83 F8 ?? 72 ?? 40 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? E9 ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 C7 45 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 45 ?? 83 C4 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 33 + C0 C7 45 ?? ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? 8D + 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E + 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 E8 } - $remote_server_connection_4 = { - 57 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 7D - ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B - C6 EB ?? 8B 8D ?? ?? ?? ?? 8B 01 FF 50 ?? 8B 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? B8 ?? - ?? ?? ?? C3 8B 85 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 - CD E8 ?? ?? ?? ?? 8B E5 5D + $modify_processes_p1 = { + 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 } - $encrypt_file = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 51 C7 45 ?? ?? ?? ?? ?? 8D 55 ?? - 8B 35 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - C6 45 ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? 83 7D ?? ?? 51 0F 43 45 ?? 8D 8D ?? ?? ?? - ?? 6A ?? 50 E8 ?? ?? ?? ?? 85 C0 8D 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BF ?? ?? ?? ?? - 8B 40 ?? 75 ?? 03 C8 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 ?? 0B C7 EB ?? 03 C8 33 C0 39 - 41 ?? 0F 44 C7 6A ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 51 0F 43 45 ?? 8D 8D ?? - ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 85 C0 8D 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? - 75 ?? 03 C8 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 ?? 83 C8 ?? EB ?? 03 C8 33 C0 39 41 ?? - 0F 44 C7 6A ?? 50 E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 83 EC - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 6A ?? 83 EC ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8D 8D ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 8B 08 8B 49 ?? F6 44 01 ?? ?? 75 ?? 8D 64 24 ?? 51 8D 55 ?? - 8B CE E8 ?? ?? ?? ?? 51 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 - ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 08 8B 49 ?? F6 44 01 ?? ?? 74 ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 03 - C8 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 ?? 83 C8 ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 03 C8 - 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 ?? 83 C8 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 8D - 45 ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? - C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? - ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 C4 ?? 8B 85 ?? - ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 - ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? - C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? - ?? ?? 8D 45 ?? 50 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 72 ?? FF - 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? C7 45 ?? ?? ?? - ?? ?? 66 89 45 ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? - ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $modify_processes_p2 = { + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 99 B9 ?? ?? ?? ?? F7 F9 6A ?? 8D 8D ?? ?? ?? ?? 6A ?? 8D 04 52 8D 04 C1 + 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 0F + 43 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D B5 + ?? ?? ?? ?? 0F 43 95 ?? ?? ?? ?? 0F 43 B5 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 83 C8 ?? + 50 56 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 B9 ?? ?? ?? ?? F7 F9 6A ?? 8D 8D ?? ?? ?? + ?? 6A ?? 8D 04 52 8D 04 C1 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 85 ?? ?? + ?? ?? 8B CC 89 A5 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC FF 37 E8 + ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? C6 45 ?? ?? 8D 85 ?? ?? + ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 8B 4D ?? 64 89 + 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 FF 77 } condition: - uint16(0)==0x5A4D and $ping_apnic and $remote_server_connection_1 and $remote_server_connection_2 and $remote_server_connection_3 and $remote_server_connection_4 and $encrypt_file + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($modify_processes_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Ragnarok : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Infodot : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Ragnarok ransomware." + description = "Yara rule that detects InfoDot ransomware." author = "ReversingLabs" - id = "263a671e-dfdb-5ab8-9bb9-355c76a88c10" - date = "2020-07-15" - modified = "2020-07-15" + id = "2f6447f4-523b-5ea1-a16d-d68bb9bcc79d" + date = "2021-02-16" + modified = "2021-02-16" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Ragnarok.yara#L1-L110" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "aaa17ab98b59a5c8c71a2b82a9bf29dd3a1a1719deaf08a3bafa77895bc10311" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.InfoDot.yara#L1-L115" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "24a1c25c1d70c21323417ae0892c613361c4bfc829737ef86b6fa7616ae668c6" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -29878,101 +31416,109 @@ rule REVERSINGLABS_Win32_Ransomware_Ragnarok : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Ragnarok" + tc_detection_name = "InfoDot" tc_detection_factor = 5 importance = 25 strings: $find_files_p1 = { - 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 - F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 5F 8B E5 5D C3 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 - ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 - 75 ?? FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B - 5D ?? 8B CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 - EB ?? 8B 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B EB ?? 33 FF - 57 57 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 - C5 89 45 ?? 8B 4D ?? 8B 55 ?? 53 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C - ?? 74 ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 - ?? ?? ?? ?? 8A 01 88 85 ?? ?? ?? ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 - 57 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? - 74 ?? 3C ?? 8A C3 75 ?? B0 ?? 2B CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D ?? ?? - ?? ?? 56 1B C0 89 9D ?? ?? ?? ?? 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? - ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B FA 8B D9 89 9D ?? ?? ?? ?? + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 53 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 8D 85 ?? ?? ?? ?? 50 FF D3 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? EB + ?? 8D 49 ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 + ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 + ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? + ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 + ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 + C0 74 ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B FF 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 + ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 + 83 C8 ?? 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 53 8D 85 ?? ?? ?? ?? 50 FF 15 } $find_files_p2 = { - 83 C4 ?? 8D 8D ?? ?? ?? ?? F7 D8 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF - 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 - ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? - 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? - ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 - 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 - 38 ?? 75 ?? 8A 48 ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? - ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? - ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? - 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? - 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 59 8B D8 56 FF 15 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 59 8B C3 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + 8B D7 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 57 8B 3D ?? ?? ?? ?? 56 50 FF D7 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? + 50 FF D3 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 9B ?? ?? ?? ?? F6 85 ?? ?? + ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? + ?? 50 56 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 8D 85 ?? ?? ?? ?? 50 FF D7 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 66 39 85 ?? ?? ?? ?? 75 ?? 33 C9 + EB ?? 8D 8D ?? ?? ?? ?? 8D 51 ?? 90 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 51 + 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 51 50 E8 ?? ?? ?? ?? 99 83 C4 ?? 0B + C2 75 ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? 83 CB ?? 83 BD ?? ?? ?? ?? ?? 72 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 BA ?? ?? ?? ?? 8B CF 8D A4 24 + ?? ?? ?? ?? 66 8B 31 66 3B 32 75 ?? 66 85 F6 74 ?? 66 8B 41 ?? 66 3B 42 ?? 75 ?? 83 } - $encrypt_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 8B 4D ?? 56 57 89 - 85 ?? ?? ?? ?? 33 FF 33 C0 89 8D ?? ?? ?? ?? 6A ?? 51 89 85 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 8D 70 ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? 8A 0E - 3A 08 75 ?? 84 C9 74 ?? 8A 4E ?? 3A 48 ?? 75 ?? 83 C6 ?? 83 C0 ?? 84 C9 75 ?? 33 C0 - EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 53 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 - 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 8B 40 ?? 8B F8 E8 ?? ?? ?? ?? - 33 D2 B9 ?? ?? ?? ?? F7 F1 8A 04 3A 88 04 1E 46 83 FE ?? 7C ?? FF B5 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 33 C9 23 F9 89 8D ?? ?? ?? ?? 3D ?? ?? ?? ?? - 0F 87 ?? ?? ?? ?? 48 83 E0 ?? 83 C0 ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? - ?? ?? FF B5 ?? ?? ?? ?? 8B F0 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF + $find_files_p3 = { + C1 ?? 83 C2 ?? 66 85 C0 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 + ?? ?? ?? ?? 8B C7 8D 9B ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 + ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 + C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B C7 8D 9B ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? + 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 + EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B C7 8D 9B ?? ?? ?? ?? + 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 + ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? + 8B C7 8D 9B ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 + ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? + ?? ?? ?? B8 ?? ?? ?? ?? 66 8B 0F 66 3B 08 75 ?? 66 85 C9 74 ?? 66 8B 4F ?? 66 3B 48 + ?? 75 ?? 83 C7 ?? 83 C0 ?? 66 85 C9 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 85 DB 7F ?? 8B 95 ?? ?? ?? ?? 7C ?? 81 } - $encrypt_files_p2 = { - 0F 84 ?? ?? ?? ?? 57 FF B5 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 57 8B F0 E8 ?? ?? ?? - ?? 83 C4 ?? 33 FF 3B B5 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 33 C0 3B 85 ?? ?? ?? ?? 0F 85 - ?? ?? ?? ?? 53 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? - ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 50 53 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 85 ?? ?? ?? - ?? 57 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 3D ?? ?? ?? ?? 75 ?? 57 6A ?? - 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 57 FF B5 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? - ?? 83 C4 ?? 3B 85 ?? ?? ?? ?? 75 ?? 57 E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 33 FF 56 E8 - ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 85 C0 74 ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 5B 85 C0 74 ?? - 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 FF 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 5F 33 CD - 5E E8 ?? ?? ?? ?? 8B E5 5D C3 + $find_files_p4 = { + FA ?? ?? ?? ?? 73 ?? 3B D8 0F 8F ?? ?? ?? ?? 7C ?? 3B D1 73 ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 EC ?? 8D 95 ?? ?? ?? ?? 8B CC 51 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? + ?? 83 C4 ?? 84 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 3B D8 7F + ?? 7C ?? 8B 85 ?? ?? ?? ?? 3B C1 73 ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? 8B 3D ?? + ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? + ?? 85 C0 8B 85 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 64 89 0D + ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } - $disable_fw_and_delete_shadow_volumes = { - 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 74 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A - ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? 50 6A ?? FF D7 E9 ?? ?? - ?? ?? 6A ?? FF 35 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? - 50 FF 35 ?? ?? ?? ?? FF D3 6A ?? FF 35 ?? ?? ?? ?? 8B F0 E8 ?? ?? ?? ?? 8B 48 ?? 51 - FF 35 ?? ?? ?? ?? FF D3 8B F8 8D 85 ?? ?? ?? ?? 50 FF D6 8D 45 ?? 50 8D 85 ?? ?? ?? - ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 40 ?? 50 6A ?? FF 95 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A - ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 35 ?? - ?? ?? ?? 8B 40 ?? 50 6A ?? FF D6 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? - 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? 50 6A ?? - FF D6 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? - ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? 50 6A ?? FF D6 + $encrypt_files = { + 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 8B F1 C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 74 ?? 83 C8 ?? 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 56 8D 85 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 0F 57 + C0 68 ?? ?? ?? ?? 50 F3 0F 7F 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? + ?? ?? ?? 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? + 57 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 8B FF + 81 FF ?? ?? ?? ?? 75 ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 + 50 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 6A ?? 50 E8 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 6A ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 + ?? 8B C7 25 ?? ?? ?? ?? 79 ?? 48 83 C8 ?? 40 BE ?? ?? ?? ?? 2B F0 8D 85 ?? ?? ?? ?? + 56 03 C7 56 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 03 F7 8D 85 ?? ?? + ?? ?? 56 50 50 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 6A ?? 50 E8 ?? + ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? + 83 C4 ?? 33 CD 33 C0 5F 5E E8 ?? ?? ?? ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($disable_fw_and_delete_shadow_volumes) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Koxic : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Crysis : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Koxic ransomware." + description = "Yara rule that detects Crysis ransomware." author = "ReversingLabs" - id = "73c4afb0-cfa8-5bc5-bca3-49a7710f4ab9" - date = "2022-04-21" - modified = "2022-04-21" + id = "bba2bbf5-ff77-5ec4-ae7f-afae1b564fb7" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Koxic.yara#L1-L87" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "739faf047b95fd538422a42943fcaad6538549bf4cf33ed91385c61365af4f09" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Crysis.yara#L1-L108" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3c9250206f94ac65c1fc24e83cf8cdd76d10066086ef1f34ec14791d237c0263" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -29980,79 +31526,103 @@ rule REVERSINGLABS_Win32_Ransomware_Koxic : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Koxic" + tc_detection_name = "Crysis" tc_detection_factor = 5 importance = 25 strings: - $enum_shares_p1 = { - 8B 45 ?? 50 6A ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 55 ?? 52 8B 45 ?? 50 8D 4D - ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 3B 4D ?? 0F 83 ?? ?? ?? ?? 8B - 55 ?? C1 E2 ?? 8B 45 ?? 83 7C 10 ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 4D ?? C1 - E1 ?? 8B 55 ?? 8B 44 0A ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8B 4D ?? C1 E1 ?? 8B 55 ?? 8B 44 0A ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? 8B 4D ?? C1 E1 ?? 8B 55 ?? 8B 44 0A ?? 50 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? C1 E0 ?? 8B 4D ?? 8B + $remote_connection_1 = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 6A ?? + 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 6A ?? 6A ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? B9 + ?? ?? ?? ?? 66 89 4D ?? 6A ?? FF 15 ?? ?? ?? ?? 66 89 45 ?? 8B 55 ?? 52 FF 15 ?? ?? + ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 8B 51 ?? 8B 45 ?? 83 3C 82 ?? + 74 ?? 8B 4D ?? 0F BF 51 ?? 52 8B 45 ?? 8B 48 ?? 8B 55 ?? 8B 04 91 50 8D 4D ?? 51 E8 + ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A + ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 50 8B 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? + 6A ?? 8D 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? EB ?? E9 ?? ?? ?? ?? 8B 45 ?? 8B E5 5D C3 } - $enum_shares_p2 = { - 54 01 ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? - 0F B6 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - 51 FF 15 ?? ?? ?? ?? 83 E8 ?? 89 45 ?? EB ?? 8B 55 ?? 83 EA ?? 89 55 ?? 83 7D ?? ?? - 0F 8C ?? ?? ?? ?? 8B 45 ?? 0F B7 8C 45 ?? ?? ?? ?? 83 F9 ?? 0F 85 ?? ?? ?? ?? 8B 55 - ?? 0F B7 84 55 ?? ?? ?? ?? 83 F8 ?? 75 ?? C6 45 ?? ?? EB ?? 8B 4D ?? 8D 94 4D ?? ?? - ?? ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 C9 8B 55 ?? 66 89 8C 55 ?? ?? FF - FF 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 - ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 8B 4D ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 - ?? ?? ?? ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? EB ?? E9 ?? ?? ?? ?? 8B 55 ?? 83 EA ?? 89 - 55 ?? E9 ?? ?? ?? ?? EB ?? 8B 45 ?? C1 E0 ?? 8B 4D ?? 8B 54 01 ?? 83 E2 ?? 74 ?? 8B - 45 ?? C1 E0 ?? 8B 4D ?? 8B 54 01 ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 - ?? C1 E0 ?? 03 45 ?? B9 ?? ?? ?? ?? 6B D1 ?? 89 44 15 ?? B8 ?? ?? ?? ?? C1 E0 ?? 8B - 4D ?? 89 4C 05 ?? BA ?? ?? ?? ?? D1 E2 8B 45 ?? 89 44 15 ?? 8D 4D ?? 51 E8 ?? ?? ?? - ?? 83 C4 ?? E9 ?? ?? ?? ?? EB ?? 81 7D ?? ?? ?? ?? ?? 74 ?? EB ?? 81 7D ?? ?? ?? ?? - ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 - C0 75 ?? B8 ?? ?? ?? ?? EB ?? 33 C0 + $enumerate_files = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 33 DB 81 7D ?? ?? ?? ?? ?? 56 57 89 5C 24 ?? + 0F 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 7D ?? + 57 8B F0 FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 6A ?? + 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 8E ?? ?? ?? ?? 8D 44 24 ?? 50 56 + FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 5D ?? 8D 4C 24 ?? 51 68 + ?? ?? ?? ?? 57 6A ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 7E ?? F6 44 24 + ?? ?? 74 ?? 66 83 7C 24 ?? ?? 74 ?? 53 8D 54 24 ?? 52 8B D6 8B CF FF 55 ?? 85 C0 7E + ?? 8B 45 ?? 8B 4D ?? 40 50 53 51 56 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 53 8D 54 24 ?? 52 + 8B D6 8B CF FF 55 ?? 85 C0 7E ?? FF 44 24 ?? 8B 4C 24 ?? 8D 44 24 ?? 50 51 FF 15 ?? + ?? ?? ?? 85 C0 7F ?? 8B 54 24 ?? 52 FF 15 ?? ?? ?? ?? 8B 5C 24 ?? 56 6A ?? FF 15 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 5F 5E 8B C3 5B 8B E5 5D C3 } - $find_files = { - 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 33 D2 8B 45 ?? 66 89 10 - 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 33 C0 E9 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 0F B6 C0 83 F8 ?? 75 ?? E9 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 8D 44 02 ?? 3D ?? ?? ?? ?? - 72 ?? E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 8B - 48 ?? 81 79 ?? ?? ?? ?? ?? 76 ?? 6A ?? FF 15 ?? ?? ?? ?? EB ?? 8B 95 ?? ?? ?? ?? 83 - E2 ?? 74 ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8B 0D ?? ?? ?? ?? 51 - FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 0D - ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? C1 E2 ?? 8B 45 ?? 89 44 15 ?? 8D 4D - ?? 51 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 - C0 75 ?? 6A ?? A1 + $enumerate_resources = { + FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + 8D 55 ?? 52 8B 45 ?? 50 8D 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 3B 4D ?? 0F 83 + ?? ?? ?? ?? 8B 55 ?? C1 E2 ?? 8B 45 ?? 83 7C 10 ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? ?? + ?? ?? 8B 55 ?? C1 E2 ?? 8B 4D ?? 8B 75 ?? 8B 54 16 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B + 45 ?? 50 8B 4D ?? 51 8B 55 ?? C1 E2 ?? 8B 45 ?? 8B 4C 10 ?? 51 E8 ?? ?? ?? ?? 83 C4 + ?? 8B 55 ?? C1 E2 ?? 8B 45 ?? 8B 4C 10 ?? 83 E1 ?? 74 ?? 8B 55 ?? 52 8B 45 ?? 50 8B + 4D ?? 51 8B 55 ?? C1 E2 ?? 03 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8D + 4D ?? 51 8B 55 ?? 52 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 8B 4D ?? 51 8D 55 ?? 52 8B 45 ?? + 50 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 4D ?? 83 + C1 ?? 89 4D ?? 8B 55 ?? 3B 55 ?? 0F 83 ?? ?? ?? ?? 8B 45 ?? C1 E0 ?? 8B 4D ?? 83 7C + 01 ?? ?? 75 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 55 ?? C1 E2 ?? 8B 4D ?? 8B 75 ?? 8B + 54 16 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? C1 E2 ?? 8B 45 + ?? 8B 4C 10 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C1 E2 ?? 8B 45 ?? 8B 4C 10 ?? 83 + E1 ?? 74 ?? 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? C1 E2 ?? 03 55 ?? 52 E8 ?? + ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? + ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 5E 8B E5 5D C3 } $encrypt_files = { - 8D 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 7F ?? 7C ?? 83 7D ?? ?? 73 ?? - E9 ?? ?? ?? ?? 6A ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 4D ?? 2B C8 8B - 45 ?? 1B C2 89 4D ?? 89 45 ?? 6A ?? 8B 4D ?? 51 8B 55 ?? 52 6A ?? 6A ?? 8B 45 ?? 50 - FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 72 ?? - 81 7D ?? ?? ?? ?? ?? 73 ?? 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 6A ?? 8B 4D ?? 51 FF - 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? - ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? EB ?? E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? - EB ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 8B 4D ?? 51 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 - 45 + 55 8B EC 81 EC ?? ?? ?? ?? 53 8B D8 33 C0 56 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 8B + 45 ?? 6A ?? 50 8D 4D ?? 51 8D 77 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B + D3 83 E2 ?? 2B DA 83 EB ?? 83 C4 ?? 89 5D ?? 8B 1D ?? ?? ?? ?? 50 FF D3 89 45 ?? 83 + F8 ?? 0F 84 ?? ?? ?? ?? 8B 4D ?? 51 FF D3 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 81 C2 + ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 8B 45 ?? A8 ?? 74 ?? 83 E0 ?? 50 8B + 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 51 + FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 33 C0 + 33 C9 51 50 53 89 45 ?? 89 45 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? + ?? 75 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 33 C9 51 8D 55 ?? 52 33 C0 50 51 53 FF 15 ?? + ?? ?? ?? 8B 45 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 55 ?? 8B 45 ?? 6A ?? 8D 4D ?? 51 52 57 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? 8B 4D ?? 85 C9 74 ?? 8B 45 ?? 85 C0 75 ?? 3B 4D ?? 73 ?? 8B D1 83 E2 ?? B8 ?? ?? + ?? ?? 2B C2 89 45 ?? 57 03 C1 8D 8D ?? ?? ?? ?? 57 51 E8 ?? ?? ?? ?? 8B 4D ?? 03 4D + ?? 83 C4 ?? 6A ?? 8D 55 ?? 52 51 57 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B + 45 ?? 03 45 ?? 39 45 ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 6A ?? 8D 4D ?? 51 52 57 + 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? 57 E8 ?? ?? ?? ?? 8B 45 + ?? 83 C4 ?? C7 47 ?? ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 85 C0 74 ?? 8B 4D ?? 51 50 56 + C7 47 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 03 F0 01 45 ?? 8B 55 ?? 6A ?? + 52 56 E8 ?? ?? ?? ?? 8B 45 ?? 6A ?? 50 83 C6 ?? 56 E8 ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 + 83 C6 ?? 56 E8 ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 83 C6 ?? 56 E8 ?? ?? ?? ?? 8B 45 ?? 68 + ?? ?? ?? ?? 50 83 C6 ?? 56 E8 ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 83 EE ?? 56 E8 ?? ?? ?? + ?? 83 C4 ?? 6A ?? 8D 55 ?? 52 83 C6 ?? 2B F7 56 57 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? + 39 75 ?? 75 ?? 53 FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 83 7D + ?? ?? 7E ?? 8B 75 ?? 33 C9 51 8D 55 ?? 52 33 C0 50 51 56 FF 15 ?? ?? ?? ?? 56 FF 15 + ?? ?? ?? ?? 8B 5D ?? 53 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 7E ?? 8B 45 ?? 8B 4D ?? 50 51 + FF 15 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 5E 5B 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ( all of ($enum_shares_p*)) + uint16(0)==0x5A4D and ($enumerate_resources and $enumerate_files and $encrypt_files and $remote_connection_1) } -rule REVERSINGLABS_Win32_Ransomware_Prometey : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Zerocrypt : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Prometey ransomware." + description = "Yara rule that detects ZeroCrypt ransomware." author = "ReversingLabs" - id = "a5902fc6-2752-520f-be84-df9ea7b1e27d" - date = "2021-06-07" - modified = "2021-06-07" + id = "89e47d7f-1ac4-570d-8ae1-30f0acc21462" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Prometey.yara#L1-L156" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "f14c9605e2d375176b461fd396be66754b0ace7dcaada8ca33ad86f6eda10b73" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.ZeroCrypt.yara#L1-L94" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "947925206ded187eac31c5046d75ab017869ae3f8dc906f2e5536d4db219f108" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -30060,145 +31630,96 @@ rule REVERSINGLABS_Win32_Ransomware_Prometey : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Prometey" + tc_detection_name = "ZeroCrypt" tc_detection_factor = 5 importance = 25 strings: - $remote_connection_p1 = { - 55 8D AC 24 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 85 ?? ?? ?? ?? 53 56 57 50 8D 45 ?? 64 A3 - ?? ?? ?? ?? 6A ?? 5E 8D 85 ?? ?? ?? ?? 89 75 ?? 50 BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? - ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? - E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 5B 8D 4D ?? 88 5D ?? E8 ?? ?? - ?? ?? 39 9D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 03 - C1 39 9D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 51 50 51 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 95 ?? ?? ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? 59 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 39 9D ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 03 C1 39 9D ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? 0F 43 8D ?? ?? ?? ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 - ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 33 DB 53 53 53 53 50 88 5D + $encrypt_file_1 = { + 55 8B EC 83 E4 ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? + ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 56 57 A1 ?? ?? ?? ?? 33 C4 50 8D 84 24 ?? ?? + ?? ?? 64 A3 ?? ?? ?? ?? 8B F2 8B F9 68 ?? ?? ?? ?? 8B D7 8D 4C 24 ?? E8 ?? ?? ?? ?? + 83 C4 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 8B D0 56 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? C6 84 24 ?? ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? FF 74 24 ?? E8 ?? ?? ?? ?? + 83 C4 ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? 83 7E ?? ?? C7 44 24 ?? ?? ?? ?? ?? 66 89 44 + 24 ?? 72 ?? 8B 16 EB ?? 8B D6 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? + ?? ?? 33 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 + 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 84 24 ?? ?? ?? ?? + C6 84 24 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 8B D6 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B F0 C6 84 24 ?? ?? ?? ?? ?? 8B + D7 68 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 84 24 ?? ?? ?? ?? ?? 8B D0 + 56 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 84 24 ?? ?? ?? ?? ?? 8B D0 68 ?? ?? ?? ?? + 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 C6 84 24 ?? ?? ?? ?? ?? 8D 84 24 ?? ?? ?? + ?? 3B C6 74 ?? 83 BC 24 ?? ?? ?? ?? ?? 72 ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 33 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 56 8D 8C 24 ?? ?? ?? ?? C7 84 24 ?? ?? + ?? ?? ?? ?? ?? ?? 66 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 83 + 7C 24 ?? ?? 72 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 ?? C6 84 24 ?? ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? + FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? 66 89 44 24 ?? C6 84 24 ?? ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? FF 74 24 ?? E8 ?? + ?? ?? ?? 83 C4 ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 } - $remote_connection_p2 = { - FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 53 56 53 53 6A ?? 68 ?? ?? - ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B D8 85 DB 74 ?? 6A ?? 68 ?? ?? ?? ?? - 33 C0 50 50 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? - 33 C0 50 50 50 50 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 - E8 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? - 8D 4D ?? E8 ?? ?? ?? ?? 56 FF D7 53 FF D7 FF 75 ?? FF D7 80 7D ?? ?? 74 ?? 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 59 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 8D - ?? ?? ?? ?? 33 CD E8 ?? ?? ?? ?? 81 C5 ?? ?? ?? ?? C9 C3 8B 85 ?? ?? ?? ?? 85 C0 0F - 84 ?? ?? ?? ?? 3D ?? ?? ?? ?? 73 ?? 8D 95 ?? ?? ?? ?? C6 84 05 ?? ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? E9 ?? ?? ?? ?? E8 + $encrypt_file_2 = { + C6 84 24 ?? ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? + 33 C0 C7 44 24 ?? ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? 66 89 44 + 24 ?? 8D B4 24 ?? ?? ?? ?? 0F 43 BC 24 ?? ?? ?? ?? 8D 44 24 ?? 83 BC 24 ?? ?? ?? ?? + ?? 50 0F 43 B4 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 57 56 8B 00 FF D0 85 C0 68 ?? ?? ?? ?? 0F 95 C3 E8 ?? ?? ?? ?? 83 C4 ?? 85 + C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 84 DB 0F 84 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? + 8D 44 24 ?? 8D B4 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 0F 43 B4 24 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 56 8B 00 FF D0 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 6A + ?? 50 E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 + 84 24 ?? ?? ?? ?? ?? 8D 4C 24 ?? 6A ?? 83 EC ?? E8 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 4C + 24 ?? E8 ?? ?? ?? ?? 6A ?? 83 EC ?? 8D 8C 24 ?? ?? ?? ?? 8B 58 ?? 03 18 E8 ?? ?? ?? + ?? 6A ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 44 24 ?? ?? ?? ?? + ?? 8D 44 24 ?? 50 E8 ?? ?? ?? ?? 33 C9 8B 00 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 + 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? + ?? ?? ?? 66 89 8C 24 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 89 84 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? + ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8B F8 8D 4C 24 ?? 57 BE ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 4C 24 ?? 8B 41 ?? F6 84 04 ?? ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? BA ?? ?? ?? ?? + 03 C8 8B F3 33 C0 39 41 ?? 0F 44 C2 83 E0 ?? 89 41 ?? 85 41 ?? 74 ?? 6A ?? E8 ?? ?? + ?? ?? 56 57 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 83 EC ?? 8D 8C 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 6A ?? 56 57 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? F3 0F 6F 00 F3 0F 7F 07 E8 ?? ?? ?? ?? F3 0F 6F } - $find_files_p1 = { - 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 5D ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? - ?? BA ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 65 ?? ?? 8D 4D ?? 8B D3 C7 04 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? - 51 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? - ?? 33 C0 8D 7D ?? AB AB AB 33 C0 89 45 ?? 89 45 ?? 89 45 ?? C6 45 ?? ?? F6 85 ?? ?? - ?? ?? ?? 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8B 95 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 59 8B D0 C6 45 ?? ?? 8B 4A - ?? 8B 7A ?? 2B CF 39 4E ?? 76 ?? 8B 46 ?? 2B 46 ?? 3B C7 72 ?? 83 7A ?? ?? 72 ?? 8B - 12 57 52 51 8B CE E8 ?? ?? ?? ?? EB ?? 56 8B CA E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? - ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? FF B5 ?? ?? ?? ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8D - 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 8B 45 ?? 0F 43 4D ?? 8D 04 41 8D 4D ?? 0F 43 4D - ?? 51 50 51 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 83 7D ?? ?? 8D 7D - ?? 8B 9D ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 83 7D ?? ?? 8B 45 ?? 0F 43 7D ?? 89 8D ?? - ?? ?? ?? 3B D8 77 ?? 85 DB 75 ?? 8B F3 EB ?? 0F BE 09 2B C3 40 89 8D ?? ?? ?? ?? 03 - } - $find_files_p2 = { - C7 89 85 ?? ?? ?? ?? 2B C7 50 51 57 EB ?? 53 FF B5 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 74 ?? 8B 85 ?? ?? ?? ?? 46 2B C6 50 FF B5 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? - 8B F0 83 C4 ?? 85 F6 75 ?? 83 CE ?? 33 DB 56 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8D 45 ?? 89 5D ?? 50 8D 4D ?? 89 5D - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 7D ?? 83 7D ?? ?? 8B 55 ?? 0F 43 7D ?? 85 D2 74 ?? - 83 C9 ?? 8D 42 ?? 3B C1 0F 42 C8 03 CF EB ?? 2B F7 EB ?? 3B CF 74 ?? 49 80 39 ?? 75 - ?? 2B CF EB ?? 83 C9 ?? 83 F9 ?? 0F 84 ?? ?? ?? ?? 8D 79 ?? 89 5D ?? C7 45 ?? ?? ?? - ?? ?? 88 5D ?? 3B D7 0F 82 ?? ?? ?? ?? 2B D7 8D 45 ?? 83 C9 ?? 83 FA ?? 0F 42 CA 83 - 7D ?? ?? 51 0F 43 45 ?? 8D 4D ?? 03 C7 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC - 8D 45 ?? 50 89 59 ?? 89 59 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 59 59 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 51 51 8D 45 ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 6A ?? 53 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? BB ?? ?? ?? ?? 8B 78 ?? 03 38 3B FB 7D ?? 81 FE ?? ?? ?? ?? 76 ?? 8D - } - $find_files_p3 = { - 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 3B FB 7D ?? 81 FE ?? ?? ?? ?? - 76 ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 83 7D ?? ?? 8B 45 ?? 0F 43 4D - ?? 8D 04 41 50 51 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? C6 45 - ?? ?? 56 BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? - ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? C6 45 ?? ?? E8 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? - ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? 83 7D ?? ?? 51 0F 43 45 ?? 51 50 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 56 BA ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 56 8B C8 C6 45 ?? ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 85 - } - $find_files_p4 = { - 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B C8 C6 45 ?? ?? E8 ?? ?? ?? ?? 50 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 85 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 8B 45 - ?? 8D 4D ?? 51 3B 45 ?? 74 ?? 8B C8 E8 ?? ?? ?? ?? 83 45 ?? ?? EB ?? 50 8D 4D ?? E8 - ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B 9D ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 FF 15 ?? - ?? ?? ?? 8B 7D ?? 8B 75 ?? 6A ?? 5B 3B F7 74 ?? 56 E8 ?? ?? ?? ?? 03 F3 59 3B F7 75 - ?? 8B 7D ?? 8B 75 ?? 85 F6 74 ?? 3B F7 74 ?? 8B CE E8 ?? ?? ?? ?? 03 F3 3B F7 75 ?? - 8B 75 ?? 8B 45 ?? 2B C6 99 F7 FB 6B C0 ?? 50 56 E8 ?? ?? ?? ?? 59 59 8D 4D ?? E8 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 - } - $encrypt_files = { - 8B FF 55 8B EC 57 FF 75 ?? E8 ?? ?? ?? ?? 59 8B 4D ?? 8B F8 8B 49 ?? 90 F6 C1 ?? 75 - ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 8B 45 ?? 6A ?? 59 83 C0 ?? F0 09 08 83 C8 ?? E9 - ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? 90 C1 E8 ?? A8 ?? 74 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? - ?? EB ?? 8B 45 ?? 8B 40 ?? 90 A8 ?? 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 59 8B 4D ?? 83 61 - ?? ?? 84 C0 8B 45 ?? 74 ?? 8B 48 ?? 89 08 8B 45 ?? 6A ?? 59 83 C0 ?? F0 21 08 8B 45 - ?? 53 6A ?? 5B 83 C0 ?? F0 09 18 8B 45 ?? 6A ?? 59 83 C0 ?? F0 21 08 8B 45 ?? 83 60 - ?? ?? 8B 45 ?? 8B 40 ?? 90 A9 ?? ?? ?? ?? 75 ?? 56 8B 75 ?? 6A ?? E8 ?? ?? ?? ?? 59 - 3B F0 74 ?? 8B 75 ?? 53 E8 ?? ?? ?? ?? 59 3B F0 75 ?? 57 E8 ?? ?? ?? ?? 59 85 C0 75 - ?? FF 75 ?? E8 ?? ?? ?? ?? 59 5E FF 75 ?? 8B 5D ?? 53 E8 ?? ?? ?? ?? 59 59 84 C0 75 - ?? 8B 45 ?? 6A ?? 59 83 C0 ?? F0 09 08 83 C8 ?? EB ?? 0F B6 C3 5B 5F 5D C3 + $encrypt_file_3 = { + 00 F3 0F 7F 47 ?? F3 0F 6F 40 ?? F3 0F 7F 47 ?? F3 0F 6F 40 ?? 8D 84 24 ?? ?? ?? ?? + 50 51 F3 0F 7F 47 ?? 57 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 + ?? 85 F6 74 ?? 6A ?? 83 EC ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF B4 24 ?? + ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 85 C0 75 ?? 8B 44 24 ?? 8D 4C 24 ?? 8B 40 ?? 03 C8 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 + ?? 83 C8 ?? 83 E0 ?? 89 41 ?? 85 41 ?? 74 ?? 6A ?? E8 ?? ?? ?? ?? 85 F6 74 ?? 56 E8 + ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B3 ?? C6 84 24 ?? ?? ?? ?? ?? 8D 8C + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 89 44 24 ?? C6 84 24 ?? + ?? ?? ?? ?? 50 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 32 DB + C6 84 24 ?? ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 72 ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? 33 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? + ?? 66 89 84 24 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 72 ?? FF + B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? + ?? 83 BC 24 ?? ?? ?? ?? ?? 72 ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 + C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 84 24 ?? ?? ?? ?? 8A C3 C7 84 24 ?? ?? ?? ?? + ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 8C 24 ?? ?? ?? + ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and $encrypt_file_1 and $encrypt_file_2 and $encrypt_file_3 } -rule REVERSINGLABS_Win32_Ransomware_Maktub : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Ransoc : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Maktub ransomware." + description = "Yara rule that detects Ransoc ransomware." author = "ReversingLabs" - id = "23ca4232-77ff-5519-b6b0-ccec6cb35fe1" + id = "a990754e-eafa-5501-a123-bcbd5aa26ca6" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Maktub.yara#L1-L116" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ee3213213e9521f7d19ce6340cd2f98057c22b1188ceefc30c17c18b6ec54e20" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Ransoc.yara#L1-L114" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "1f48f1b713c18b099e863d8a11e872ae84df0ea355f01cba765e8333d8d98575" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -30206,118 +31727,115 @@ rule REVERSINGLABS_Win32_Ransomware_Maktub : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Maktub" + tc_detection_name = "Ransoc" tc_detection_factor = 5 importance = 25 strings: + $scan_for_services = { + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 66 A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 66 39 2D ?? ?? ?? ?? 73 ?? 66 01 1D ?? ?? ?? ?? 03 F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B9 ?? ?? ?? ?? 66 89 + 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 39 2D ?? ?? ?? ?? 73 ?? 66 01 1D ?? ?? ?? ?? 03 F3 + E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 + C0 75 ?? BA ?? ?? ?? ?? 66 89 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 39 2D ?? ?? ?? ?? 73 + ?? 66 01 1D ?? ?? ?? ?? 03 F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 66 A3 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 66 39 2D ?? ?? ?? ?? 73 ?? 66 01 1D ?? ?? ?? ?? 03 F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B9 ?? ?? ?? ?? 66 + 89 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 39 2D ?? ?? ?? ?? 73 ?? 66 01 1D ?? ?? ?? ?? 03 + F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 85 C0 75 ?? BA ?? ?? ?? ?? 66 89 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 FF 66 39 2D ?? ?? + ?? ?? 73 ?? A1 ?? ?? ?? ?? 50 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 66 01 1D ?? ?? ?? ?? 8B + FB 03 F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 75 ?? BA ?? ?? ?? ?? 66 89 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 39 2D ?? ?? + ?? ?? 73 ?? 85 FF 75 ?? A1 ?? ?? ?? ?? 50 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 66 + 01 1D ?? ?? ?? ?? 03 F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? BA ?? ?? ?? ?? 66 89 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? + EB ?? 85 FF 74 ?? 8D 44 24 ?? 50 E8 + } + $remote_connection = { + 8B 44 24 ?? 83 EC ?? 53 8B 5C 24 ?? 56 8B 74 24 ?? 50 56 E8 ?? ?? ?? ?? 8B D8 83 C4 + ?? 83 FB ?? 75 ?? 5E B8 ?? ?? ?? ?? 5B 83 C4 ?? C3 8B 4C 24 ?? 55 8B 6C 24 ?? 57 55 + 56 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 56 FF 15 ?? ?? ?? ?? 50 56 53 E8 + ?? ?? ?? ?? 56 8B F8 E8 ?? ?? ?? ?? 83 C4 ?? 83 FF ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 8D + 47 ?? 5F 5D 5E 5B 83 C4 ?? C3 8B 44 24 ?? 85 C0 74 ?? 85 ED 74 ?? 55 50 53 E8 ?? ?? + ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 5F 5D 5E B8 ?? ?? ?? ?? 5B 83 C4 + ?? C3 8D 54 24 ?? 52 E8 ?? ?? ?? ?? 8B 2D ?? ?? ?? ?? 83 C4 ?? 8D 49 ?? 8B 74 24 ?? + 8B C6 2B 44 24 ?? 75 ?? 8D 4C 24 ?? 6A ?? 51 E8 ?? ?? ?? ?? 8B 74 24 ?? 83 C4 ?? 2B + 74 24 ?? 6A ?? 56 8D 54 24 ?? 56 52 E8 ?? ?? ?? ?? 83 C4 ?? 50 53 FF D5 8B F8 85 FF + 78 ?? 2B C6 01 44 24 ?? EB ?? 29 74 24 ?? 83 FF ?? 74 ?? 85 FF 75 ?? 53 FF 15 ?? ?? + ?? ?? 85 FF 79 ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 5F 5D 5E B8 ?? ?? ?? ?? 5B + 83 C4 ?? C3 8D 54 24 ?? 6A ?? 52 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 68 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 8B F0 85 F6 75 ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 5F 5D + 8D 46 ?? 5E 5B 83 C4 ?? C3 8B 54 24 ?? 83 C2 ?? 6A ?? 52 E8 ?? ?? ?? ?? 8B 4C 24 ?? + 8B 54 24 ?? 8B F8 8B 44 24 ?? 2B F0 83 C6 ?? 2B CE 51 03 F0 56 52 E8 ?? ?? ?? ?? 8D + 44 24 ?? 50 E8 + } $encrypt_files = { - 55 8B EC 83 EC ?? 53 8B 1D ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 8D 8B ?? ?? ?? ?? E8 ?? ?? - ?? ?? 51 8D B3 ?? ?? ?? ?? 8B CB 56 E8 ?? ?? ?? ?? 85 C0 74 ?? 50 8B 43 ?? FF D0 8D - 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8B 43 ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - B3 ?? ?? ?? ?? FF D0 85 C0 74 ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8B 43 ?? 6A - ?? 6A ?? 6A ?? 6A ?? FF 75 ?? C7 45 ?? ?? ?? ?? ?? FF D0 85 C0 75 ?? FF 75 ?? 8B 43 - ?? FF D0 5E 33 C0 5B 8B E5 5D C3 A1 ?? ?? ?? ?? 57 8B 7D ?? 85 C0 75 ?? FF 15 ?? ?? - ?? ?? A3 ?? ?? ?? ?? 57 6A ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B F8 89 7D ?? 85 C9 74 - ?? 8B D1 33 C0 C1 E9 ?? F3 AB 8B CA 83 E1 ?? F3 AA 8B 7D ?? B9 ?? ?? ?? ?? 3B FE 76 - ?? 8D 46 ?? 3B F8 73 ?? 8D 57 ?? 8D 70 ?? 8B FF 8A 06 8D 52 ?? 88 42 ?? 8D 76 ?? 49 - 75 ?? EB ?? 8B D7 2B D6 8A 06 8D 76 ?? 88 44 32 ?? 49 75 ?? E8 ?? ?? ?? ?? 89 83 ?? - ?? ?? ?? 8D 4F ?? 8B 83 ?? ?? ?? ?? 89 47 ?? FF B3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 8D 45 ?? FF 75 ?? 50 8B 43 ?? 57 6A ?? 6A ?? 6A ?? FF 75 ?? FF D0 85 C0 75 ?? A1 - ?? ?? ?? ?? 85 C0 75 ?? A1 ?? ?? ?? ?? FF D0 A3 ?? ?? ?? ?? 57 6A ?? 50 FF 15 ?? ?? - ?? ?? FF 75 ?? 8B 43 ?? FF D0 5F 5E 33 C0 5B 8B E5 5D C3 FF 75 ?? 8D 45 ?? 57 50 E8 - ?? ?? ?? ?? 50 8D 8B ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? - ?? 85 C0 75 ?? A1 ?? ?? ?? ?? FF D0 A3 ?? ?? ?? ?? 57 6A ?? 50 FF 15 ?? ?? ?? ?? FF - 75 ?? 8B 43 ?? FF D0 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 - } - $search_files = { - 55 8B EC 83 EC ?? 53 56 57 8B F9 68 ?? ?? ?? ?? FF 75 ?? 8B 47 ?? FF D0 85 C0 0F 84 - ?? ?? ?? ?? 8B 47 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? - FF D0 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 4F ?? 8D 45 ?? 50 0F 57 C0 53 66 0F 13 45 - ?? FF D1 85 C0 0F 84 ?? ?? ?? ?? 8B 75 ?? 8B C6 0B 45 ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 6A ?? 50 8D 4D ?? C7 45 ?? ?? ?? ?? ?? FF - 72 ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 87 ?? ?? ?? ?? - 8B 55 ?? 8D 4A ?? C7 45 ?? ?? ?? ?? ?? 89 4D ?? FF 70 ?? 50 FF 31 8D 4D ?? E8 ?? ?? - ?? ?? 8B 45 ?? 83 C0 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 7F ?? A1 ?? ?? ?? ?? 85 C0 75 ?? - FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 75 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 8B 45 ?? 85 C0 - 7C ?? 7F ?? 81 FE ?? ?? ?? ?? 72 ?? 50 8B 45 ?? 56 53 8B 1D ?? ?? ?? ?? 33 F6 51 8D - 48 ?? 89 65 ?? 39 31 7C ?? 51 8D 70 ?? FF D3 8B 4D ?? 8D 46 ?? 51 33 F6 89 65 ?? 89 - 01 8B 45 ?? 39 70 ?? 8D 48 ?? 7C ?? 51 8D 70 ?? FF D3 8B 4D ?? 8D 46 ?? 89 01 8B CF - E8 ?? ?? ?? ?? 8B 75 ?? 8B F8 E9 ?? ?? ?? ?? 8B 75 ?? 8B 47 ?? 6A ?? 6A ?? 6A ?? 6A - ?? 6A ?? 68 ?? ?? ?? ?? 56 FF D0 89 45 ?? 83 F8 ?? 75 ?? 8B 47 ?? 53 FF D0 33 FF E9 - ?? ?? ?? ?? 51 8D 87 ?? ?? ?? ?? 8B CF 50 E8 ?? ?? ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? - ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 4D ?? C7 45 - ?? ?? ?? ?? ?? 51 FF 75 ?? 50 8B 47 ?? 53 FF D0 85 C0 75 ?? 8B 4D ?? E9 ?? ?? ?? ?? - 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 45 ?? C7 45 ?? - ?? ?? ?? ?? 50 FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 85 C0 74 ?? E8 ?? ?? ?? ?? - 8B 45 ?? 6A ?? 89 45 ?? 8D 45 ?? 50 8B 47 ?? 6A ?? 6A ?? 6A ?? 6A ?? FF 75 ?? FF D0 - 85 C0 75 ?? 8B 4D ?? EB ?? FF 75 ?? 8D 45 ?? 50 FF 75 ?? 8B 47 ?? 6A ?? 6A ?? 6A ?? - FF 75 ?? FF D0 85 C0 75 ?? 8B 4D ?? EB ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF - 75 ?? 8B 45 ?? 50 FF 75 ?? 8B 47 ?? FF D0 8B 4D ?? 85 C0 74 ?? 8B 45 ?? 3B 45 ?? 74 - ?? E8 ?? ?? ?? ?? FF 75 ?? 8B 47 ?? FF D0 8B 47 ?? 53 FF D0 FF 75 ?? 8B 47 ?? FF D0 - 8B 47 ?? 56 FF D0 33 FF E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 8B 47 ?? FF D0 FF 75 - ?? 8B 47 ?? FF D0 8B 47 ?? 53 FF D0 51 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CF E8 ?? - ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 51 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CF E8 ?? - ?? ?? ?? 6A ?? 51 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 51 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 8D 45 - ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? FF 75 ?? 8B 47 ?? FF D0 85 C0 75 ?? - 8B 47 ?? 56 FF D0 33 FF EB ?? BF ?? ?? ?? ?? 83 C6 ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? - 85 C0 7F ?? A1 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B 1D ?? ?? - ?? ?? 56 6A ?? 50 FF D3 EB ?? 8B 47 ?? 53 FF D0 33 FF 8B 1D ?? ?? ?? ?? 8B 75 ?? 83 - C6 ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 7F ?? A1 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? - ?? ?? ?? A3 ?? ?? ?? ?? 56 6A ?? 50 FF D3 8B C7 5F 5E 5B 8B E5 5D C2 - } - $previous_encrypt_files = { - 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8D 4D - ?? 89 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF - 77 ?? FF D3 8D 4D ?? 89 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 - 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 - 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D - 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? - FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF - 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? - ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 - B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 - 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 - 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D - 4D ?? E8 ?? ?? ?? ?? FF 30 FF 15 ?? ?? ?? ?? 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF B7 - ?? ?? ?? ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? - ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF B7 ?? ?? ?? ?? FF D3 8B F0 8D - 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? FF 30 FF 15 ?? ?? ?? ?? 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF B7 ?? - ?? ?? ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? - ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF B7 ?? ?? ?? ?? FF D3 8B F0 8D 4D - ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? - E8 ?? ?? ?? ?? FF 30 FF B7 ?? ?? ?? ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 6A ?? 8D B7 ?? ?? ?? ?? FF 30 8B 47 ?? 6A ?? 56 FF D0 85 C0 8D 4D ?? 0F 94 C3 E8 - ?? ?? ?? ?? 84 DB 74 ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? - FF 30 8B 47 ?? 6A ?? 56 FF D0 85 C0 8D 4D ?? 0F 94 C3 E8 ?? ?? ?? ?? 84 DB 0F 85 ?? - ?? ?? ?? 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 - } + 81 EC ?? ?? ?? ?? 53 55 56 8B 35 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? + 8B F8 FF D6 8B 8C 24 ?? ?? ?? ?? 8B E8 8B 84 24 ?? ?? ?? ?? 50 51 57 8D 94 24 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 50 + E8 ?? ?? ?? ?? 8B BC 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 83 C4 ?? 89 4C 24 ?? BB ?? + ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? EB ?? 8D 49 ?? 55 68 ?? ?? ?? ?? 83 FB ?? 7E ?? 8D + 94 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 74 24 ?? 8D BC 24 ?? ?? ?? ?? 52 F3 A5 E8 ?? ?? + ?? ?? 8B BC 24 ?? ?? ?? ?? 88 9C 2C ?? ?? ?? ?? 8D 75 ?? EB ?? 8D 84 24 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 88 9C 2C ?? ?? ?? ?? 8D 75 ?? 83 C4 ?? 6A ?? 8D 4C 24 ?? 6A ?? 51 + E8 ?? ?? ?? ?? 6A ?? 8D 94 24 ?? ?? ?? ?? 52 8D 44 24 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 8D 44 24 ?? B9 ?? ?? ?? ?? 80 30 ?? 40 49 75 ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 6A ?? + 8D 54 24 ?? 52 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 56 8D 8C 24 ?? ?? ?? ?? 51 8D + 94 24 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 4C 24 ?? 51 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 44 24 ?? B9 ?? ?? ?? ?? 8B FF 80 30 ?? 40 49 75 ?? 8D 54 24 ?? 52 + E8 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 8D 8C 24 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 6A ?? 8D + 54 24 ?? 52 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 51 8D 54 24 + ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B F7 83 FF ?? 72 ?? BE ?? ?? ?? ?? 8B 4C 24 ?? 56 8D + 44 24 ?? 50 51 E8 ?? ?? ?? ?? 01 74 24 ?? 2B FE 83 C4 ?? 43 89 BC 24 ?? ?? ?? ?? 85 + FF 0F 85 ?? ?? ?? ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 + } + $find_files = { + 83 EC ?? 53 55 56 57 33 DB 68 ?? ?? ?? ?? 6A ?? 89 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? + ?? 8B E8 8D 44 24 ?? 50 89 6C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? 55 51 E8 ?? ?? ?? ?? + 8B 74 24 ?? 6A ?? 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 55 68 ?? ?? ?? + ?? 89 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B F8 57 8D 54 24 ?? 52 8D 44 24 ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 89 44 24 ?? 3B C3 75 ?? 8B 4C 24 ?? 51 8D 54 24 ?? 52 E8 ?? ?? + ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? + ?? ?? 8B 44 24 ?? 50 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 4C 24 ?? + 51 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 54 24 ?? 52 56 E8 ?? ?? ?? + ?? 83 C4 ?? 33 FF 39 5C 24 ?? 76 ?? 8D 64 24 ?? 8B 44 24 ?? 8B 0C B8 51 56 E8 ?? ?? + ?? ?? 47 83 C4 ?? 3B 7C 24 ?? 72 ?? 39 5C 24 ?? 75 ?? 8B 44 24 ?? 3B C3 74 ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 54 24 ?? 52 56 E8 ?? ?? ?? + ?? 8B 44 24 ?? 83 C4 ?? 89 5C 24 ?? 3B C3 0F 86 ?? ?? ?? ?? EB ?? 8D 9B ?? ?? ?? ?? + 8B 44 24 ?? 8B 4C 24 ?? 8B 1C 88 53 55 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 57 68 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 8B E8 E8 ?? ?? ?? ?? 6A ?? 56 89 44 24 ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 53 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 56 E8 ?? ?? ?? ?? 33 C0 8D 54 24 ?? 55 52 C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 89 84 + 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 + 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 50 56 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8D 44 24 ?? 50 56 + E8 ?? ?? ?? ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? + ?? 8B 5C 24 ?? E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 55 E8 ?? ?? ?? ?? 8B D3 52 E8 ?? ?? + ?? ?? 8B 4C 24 ?? 8B 44 24 ?? 8B 6C 24 ?? 41 83 C4 ?? 89 4C 24 ?? 3B C8 0F 82 ?? ?? + ?? ?? 33 DB 33 F6 3B C3 76 ?? 8B 44 24 ?? 8B 0C B0 51 E8 ?? ?? ?? ?? 46 83 C4 ?? 3B + 74 24 ?? 72 ?? 8D 54 24 ?? 52 E8 ?? ?? ?? ?? 55 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? + 3B C3 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 44 24 ?? 5F 5E 5D 3B C3 5B 74 ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 83 C4 ?? C3 + } condition: - uint16(0)==0x5A4D and $search_files and $previous_encrypt_files and $encrypt_files + uint16(0)==0x5A4D and $scan_for_services and $find_files and $encrypt_files and $remote_connection } -rule REVERSINGLABS_Win32_Ransomware_Tblocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Chichi : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects TBLocker ransomware." + description = "Yara rule that detects ChiChi ransomware." author = "ReversingLabs" - id = "91793018-baf6-5e70-83b6-8793482c3bec" - date = "2020-07-15" - modified = "2020-07-15" + id = "95062789-a55d-5c1c-a359-206b58f311e5" + date = "2022-02-14" + modified = "2022-02-14" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.TBLocker.yara#L1-L85" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "81f0077655ac0e59cd8dc05be602ae500c938668bd57d3cf4a51fbff2a5b6b83" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.ChiChi.yara#L1-L66" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "863a30e4c708e13ea0f4c6ad42a919de463926508783d6552c0cec746730baa5" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -30325,79 +31843,59 @@ rule REVERSINGLABS_Win32_Ransomware_Tblocker : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "TBLocker" + tc_detection_name = "ChiChi" tc_detection_factor = 5 importance = 25 strings: - $main_ransomware_function_p1 = { - 00 02 16 28 ?? ?? ?? ?? 00 02 17 28 ?? ?? ?? ?? 00 02 16 28 ?? ?? ?? ?? 00 02 16 28 ?? ?? ?? ?? 00 02 - 16 28 ?? ?? ?? ?? 00 02 28 ?? ?? ?? ?? 00 00 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 16 FE ?? 0A 06 2C ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 72 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 18 16 15 28 ?? ?? ?? ?? 26 00 00 28 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 16 FE ?? 0B 07 39 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE ?? 0C 08 2C ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 00 00 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 6F ?? - ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 00 DE ?? 25 - 28 ?? ?? ?? ?? 0D 00 28 ?? ?? ?? ?? DE ?? 00 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 17 28 ?? ?? ?? ?? - 00 02 18 28 ?? ?? ?? ?? 00 02 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? - 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 02 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 59 - } - $main_ransomware_function_p2 = { - 28 ?? ?? ?? ?? B7 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? - ?? 5B 28 ?? ?? ?? ?? B7 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? - ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 02 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6C 23 - ?? ?? ?? ?? ?? ?? ?? ?? 5B 59 28 ?? ?? ?? ?? B7 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? - ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 23 ?? ?? ?? ?? ?? ?? ?? ?? 5A 28 ?? ?? ?? ?? B7 73 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 00 02 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6C 23 ?? ?? - ?? ?? ?? ?? ?? ?? 5B 02 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 59 28 ?? ?? ?? - ?? B7 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F ?? DA 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 00 02 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? - ?? ?? 5B 02 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 59 28 ?? ?? ?? ?? B7 28 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6C 23 ?? ?? ?? ?? ?? ?? ?? ?? 5B 23 ?? ?? ?? ?? ?? - ?? ?? ?? 5A 28 ?? ?? ?? ?? B7 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F - } - $search_files = { - 00 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 03 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 38 ?? ?? ?? ?? 06 6F ?? ?? ?? - ?? 0B 07 07 6F ?? ?? ?? ?? 17 DA 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 16 FE - ?? 0C 08 2C ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE ?? 0D 09 2C ?? 00 02 07 07 72 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 07 28 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? - ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 16 14 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? DE ?? 00 00 00 00 00 00 06 6F - ?? ?? ?? ?? 13 ?? 11 ?? 3A ?? ?? ?? ?? DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? 00 DC DE ?? 25 28 ?? ?? ?? ?? - 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 03 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? - 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 11 ?? 6F ?? - ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 17 DA 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? - ?? ?? ?? 16 FE ?? 13 ?? 11 ?? 2C ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE ?? 13 ?? - 11 ?? 2C ?? 00 02 11 ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 11 ?? - 28 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 16 14 28 ?? ?? ?? ?? 26 28 ?? - ?? ?? ?? DE ?? 00 00 00 00 00 00 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 3A ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 - ?? 6F ?? ?? ?? ?? 00 DC DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 00 11 ?? 17 D6 13 ?? - 11 ?? 11 ?? 8E 69 FE ?? 13 ?? 11 ?? 3A ?? ?? ?? ?? 2A + $generate_key = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? + 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B D9 8B 7D ?? C7 45 ?? ?? ?? ?? ?? 89 7D ?? 85 + FF 75 ?? 33 F6 EB ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 89 75 ?? 6A ?? 8D 4D ?? C7 45 + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 56 8D + 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? 85 C0 74 + ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 8B 03 8B CB 57 56 FF 50 ?? C7 45 ?? ?? ?? ?? ?? 85 F6 + 74 ?? 83 FF ?? 8D 45 ?? 8D 4D ?? 8B FE 0F 46 C8 32 C0 56 8B 09 F3 AA E8 ?? ?? ?? ?? + 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C2 } $encrypt_files = { - 00 00 03 19 17 73 ?? ?? ?? ?? 0A 04 18 18 73 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? 0C 08 28 ?? ?? ?? ?? 05 6F - ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 08 28 ?? ?? ?? ?? 05 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? - 0D 07 09 17 73 ?? ?? ?? ?? 13 ?? 06 6F ?? ?? ?? ?? 17 6A DA B7 17 D6 8D ?? ?? ?? ?? 13 ?? 06 11 ?? 16 - 11 ?? 8E 69 6F ?? ?? ?? ?? 26 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 07 - 6F ?? ?? ?? ?? 00 06 6F ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 2A + 55 8B EC 51 53 56 57 8B D9 68 ?? ?? ?? ?? 53 89 5D ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? + ?? ?? 53 FF D6 68 ?? ?? ?? ?? 8B F8 FF D6 8B 1D ?? ?? ?? ?? 03 F8 03 FF 83 C7 ?? 57 + 6A ?? FF 35 ?? ?? ?? ?? FF D3 8B F0 85 F6 74 ?? 8B 7D ?? 57 56 FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 56 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5B + 8B E5 5D C3 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? + ?? 56 6A ?? FF 35 ?? ?? ?? ?? 8B F8 FF 15 ?? ?? ?? ?? 83 FF ?? 74 ?? 8B CF E8 ?? ?? + ?? ?? 5F 5E 5B 8B E5 5D C3 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 + } + $find_files = { + 6A ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 56 FF 15 ?? + ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF 74 24 ?? 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF + D7 8D 44 24 ?? 50 53 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 + ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 33 F6 FF B6 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 83 C6 ?? 81 FE ?? ?? ?? ?? 72 ?? FF 74 24 ?? 8B 74 24 ?? + 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 56 FF 15 ?? + ?? ?? ?? F6 44 24 ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? + ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 83 E8 ?? 78 ?? 66 83 + 7C 44 ?? ?? 74 ?? 83 E8 ?? 79 ?? EB ?? 8D 74 24 ?? 8D 34 46 68 ?? ?? ?? ?? 56 FF 15 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 } condition: - uint16(0)==0x5A4D and (( all of ($main_ransomware_function_p*)) and $search_files and $encrypt_files) + uint16(0)==0x5A4D and ($find_files) and ($generate_key) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Fuxsocy : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Mcburglar : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects FuxSocy ransomware." + description = "Yara rule that detects McBurglar ransomware." author = "ReversingLabs" - id = "f4a45469-9d51-523f-8238-c7044f353cf6" - date = "2021-03-01" - modified = "2021-03-01" + id = "11816401-87c3-5aff-b161-da0fa4eb4bca" + date = "2021-09-27" + modified = "2021-09-27" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.FuxSocy.yara#L1-L114" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "8b3c04eb5d60fcc82e47cb8e78da0a98642666546d6799baef24b56926e3aceb" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.McBurglar.yara#L1-L75" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "57fefcdc1528fc1c8da36a431cd09774e33ea08a394ac4f8d19a27504e72676d" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -30405,108 +31903,63 @@ rule REVERSINGLABS_Win32_Ransomware_Fuxsocy : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "FuxSocy" + tc_detection_name = "McBurglar" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_1 = { - 83 EC ?? 53 55 57 89 54 24 ?? 8B 54 24 ?? 51 33 DB E8 ?? ?? ?? ?? 8B E8 59 85 ED 0F - 84 ?? ?? ?? ?? 8B 44 24 ?? 89 5C 24 ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B CB E9 - ?? ?? ?? ?? 53 53 FF 74 24 ?? 41 FF 74 24 ?? BF ?? ?? ?? ?? FF 74 24 ?? 3B C7 0F 42 - F8 2B C7 89 4C 24 ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? 53 8D 44 24 ?? 50 57 FF 74 24 ?? - FF 74 24 ?? FF 15 ?? ?? ?? ?? 57 FF 74 24 ?? 8D 54 24 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? - 59 59 57 8D 44 24 ?? 50 FF 74 24 ?? 33 C0 39 44 24 ?? 53 0F 94 C0 89 7C 24 ?? 50 53 - 55 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 53 53 FF 74 24 ?? FF 74 24 ?? FF 74 24 ?? FF 15 ?? - ?? ?? ?? 53 8D 44 24 ?? 50 57 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 01 7C 24 ?? - 8B 4C 24 ?? 11 5C 24 ?? F6 C1 ?? 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 8B 44 24 - ?? 85 C0 0F 85 ?? ?? ?? ?? EB ?? 88 5C 24 ?? FF 74 24 ?? 8B 54 24 ?? 8B 4C 24 ?? E8 - ?? ?? ?? ?? 59 8B 4C 24 ?? 55 89 41 ?? FF 15 ?? ?? ?? ?? 8A 5C 24 ?? 5F 5D 8A C3 5B - 83 C4 ?? C3 + $setup_env = { + 00 7E ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 7E ?? ?? ?? + ?? 1B 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? + ?? 00 7E ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 00 28 ?? ?? + ?? ?? 00 2A } - $encrypt_files_2 = { - 83 EC ?? 53 55 56 8B 74 24 ?? 8B C1 8B 36 57 89 54 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? - 8B F8 33 D2 8D 5F ?? 8B C6 F7 F3 33 C9 85 D2 0F 95 C1 89 54 24 ?? 33 D2 03 C8 89 4C - 24 ?? 0F AF CF 89 4C 24 ?? E8 ?? ?? ?? ?? 8B E8 89 6C 24 ?? 85 ED 0F 84 ?? ?? ?? ?? - 33 D2 8B CF E8 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 83 64 24 ?? ?? - 48 89 6C 24 ?? 89 44 24 ?? 74 ?? 53 FF 74 24 ?? 89 5C 24 ?? 56 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 44 24 ?? 57 50 56 33 C0 50 50 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? 33 C9 85 FF 74 ?? 8B 54 24 ?? 8D 6E ?? 03 EF 8A 45 ?? 4D 88 04 11 41 3B CF - 72 ?? 8B 6C 24 ?? 8B 44 24 ?? 03 44 24 ?? 01 5C 24 ?? 89 44 24 ?? 8B 44 24 ?? 40 89 - 44 24 ?? 3B 44 24 ?? 72 ?? 8B 44 24 ?? 85 C0 0F 45 D8 53 FF 74 24 ?? 89 5C 24 ?? 56 - E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 57 50 56 6A ?? 6A ?? 6A ?? FF 74 24 ?? FF 15 ?? - ?? ?? ?? 8B D8 F7 DB 1A DB 80 E3 ?? 33 C9 85 FF 74 ?? 8B 6C 24 ?? 8D 56 ?? 03 D7 8A - 02 4A 88 04 29 41 3B CF 72 ?? 8B 6C 24 ?? 8B CE E8 ?? ?? ?? ?? 84 DB 75 ?? 8B CD E8 - ?? ?? ?? ?? 33 ED EB ?? 32 DB EB ?? 8B 4C 24 ?? 8B 44 24 ?? 89 01 5F 5E 8B C5 5D 5B - 83 C4 ?? C3 + $encrypt_files_p1 = { + 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 2B ?? 73 ?? ?? ?? ?? 0B 07 12 ?? 28 ?? ?? ?? ?? + 7D ?? ?? ?? ?? 00 07 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 + 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 2A } - $find_files_1 = { - 81 EC ?? ?? ?? ?? 53 56 57 8B BC 24 ?? ?? ?? ?? 8B F2 89 74 24 ?? 8B D9 85 FF 0F 84 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 8B D7 C1 E2 ?? 8B - CE E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 - 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D3 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 84 C0 - 0F 84 ?? ?? ?? ?? 55 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D - 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B E8 - 83 FD ?? 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8B 44 - 24 ?? 83 E0 ?? 74 ?? F6 84 24 ?? ?? ?? ?? ?? 75 ?? 85 C0 75 ?? F6 84 24 ?? ?? ?? ?? - ?? 74 ?? 33 F6 85 FF 74 ?? 8B 44 24 ?? FF 34 B0 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 - C0 75 ?? 46 3B F7 72 ?? EB ?? FF B4 24 ?? ?? ?? ?? 8D 44 24 ?? 50 53 FF 94 24 ?? ?? - ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 74 ?? FF B4 24 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 8B 74 24 ?? F6 44 24 ?? ?? 74 ?? F6 84 24 ?? ?? ?? ?? ?? 74 - ?? 8D 44 24 ?? 50 8B D3 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 84 C0 74 ?? 83 BC 24 - ?? ?? ?? ?? ?? 74 ?? FF B4 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B - D6 FF B4 24 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? - ?? FF B4 24 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 55 FF 15 ?? ?? ?? - ?? 85 C0 0F 85 ?? ?? ?? ?? EB ?? 83 64 24 ?? ?? 55 FF 15 ?? ?? ?? ?? 5D 5F 5E 5B 81 - C4 ?? ?? ?? ?? C3 + $encrypt_files_p2 = { + 00 28 ?? ?? ?? ?? 0A 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 18 73 ?? ?? ?? ?? 0B 73 ?? ?? ?? + ?? 0C 28 ?? ?? ?? ?? 03 6F ?? ?? ?? ?? 0D 73 ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 00 11 ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 11 ?? 18 6F ?? ?? ?? ?? 00 09 06 + 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? + ?? 6F ?? ?? ?? ?? 00 11 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? + ?? 00 11 ?? 1A 6F ?? ?? ?? ?? 00 07 06 16 06 8E 69 6F ?? ?? ?? ?? 00 07 11 ?? 6F ?? ?? + ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 02 19 73 ?? ?? ?? ?? 13 ?? 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? + 13 ?? 00 2B ?? 00 11 ?? 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 11 ?? 16 11 ?? 8E 69 + 6F ?? ?? ?? ?? 25 13 ?? 16 FE 02 13 ?? 11 ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 13 + ?? 00 72 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 DE ?? DE + ?? 00 11 ?? 6F ?? ?? ?? ?? 00 07 6F ?? ?? ?? ?? 00 00 DC 2A } - $find_files_2 = { - 81 EC ?? ?? ?? ?? 8D 44 24 ?? 53 55 56 68 ?? ?? ?? ?? 50 8B D9 FF 15 ?? ?? ?? ?? 8B - F0 85 F6 0F 84 ?? ?? ?? ?? 8D 6C 24 ?? 8D 6C 75 ?? 33 C0 66 89 44 74 ?? 68 ?? ?? ?? - ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 59 E8 ?? ?? ?? ?? 83 C0 ?? 6A ?? 59 66 89 - 45 ?? E8 ?? ?? ?? ?? 83 C0 ?? 66 89 44 74 ?? 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? 50 - FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 FF 15 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 84 C0 74 ?? 8D 84 24 ?? ?? ?? ?? 50 55 FF 15 ?? ?? ?? ?? 83 64 24 ?? ?? 8D 44 - 24 ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 53 - FF 15 ?? ?? ?? ?? 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 + $find_files = { + 00 00 02 28 ?? ?? ?? ?? 0A 00 06 0C 16 0D 2B ?? 08 09 9A 13 ?? 00 11 ?? 28 ?? ?? ?? ?? + 00 00 09 17 58 0D 09 08 8E 69 32 ?? 02 28 ?? ?? ?? ?? 0B 00 07 13 ?? 16 13 ?? 2B ?? 11 + ?? 11 ?? 9A 13 ?? 00 11 ?? 28 ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 + ?? 00 DE ?? 26 00 00 DE ?? 2A } - $find_files_3 = { - 81 EC ?? ?? ?? ?? 53 55 56 8B D9 57 8B FA 85 DB 74 ?? 33 D2 E8 ?? ?? ?? ?? 8B F0 85 - F6 0F 84 ?? ?? ?? ?? 57 56 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 83 C4 ?? 8B CE E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 C6 43 ?? ?? FF 15 ?? ?? ?? ?? - 0D ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? EB ?? 57 FF 15 ?? ?? ?? ?? 0D ?? ?? ?? ?? 50 57 FF - 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D7 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 84 C0 0F - 84 ?? ?? ?? ?? 8B B4 24 ?? ?? ?? ?? 80 7E ?? ?? 75 ?? 8B 15 ?? ?? ?? ?? 8D 8C 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 8B E8 83 FD ?? 0F 84 ?? ?? ?? ?? 83 64 24 ?? ?? 6A ?? FF 35 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 84 C0 - 0F 85 ?? ?? ?? ?? F7 44 24 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 56 - 57 FF 15 ?? ?? ?? ?? 50 8B D7 8B CB E8 ?? ?? ?? ?? 59 59 89 44 24 ?? 85 C0 0F 84 ?? - ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? F6 44 - 24 ?? ?? 74 ?? 80 7E ?? ?? 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 56 FF B4 24 ?? - ?? ?? ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 59 59 EB ?? 80 7E ?? ?? 74 ?? 85 DB 74 ?? 83 7C - 24 ?? ?? 7C ?? 7F ?? 81 7C 24 ?? ?? ?? ?? ?? 72 ?? 80 3E ?? 74 ?? 6A ?? 8D 44 24 ?? - 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 8D 44 24 ?? 50 FF 74 24 ?? FF 94 24 ?? ?? ?? ?? - 83 C4 ?? 85 C0 74 ?? 8D 44 24 ?? 50 55 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 55 - FF 15 ?? ?? ?? ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 + $generate_salt = { + 00 1F ?? 8D ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 00 16 0C 2B ?? 00 07 06 6F ?? ?? ?? ?? 00 + 00 08 17 58 0C 08 1F ?? FE 04 0D 09 2D ?? 00 DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? 00 DC 06 + 13 ?? 2B ?? 11 ?? 2A } condition: - uint16(0)==0x5A4D and ( all of ($find_files_*)) and ( all of ($encrypt_files_*)) + uint16(0)==0x5A4D and ($setup_env) and ($find_files) and ($generate_salt) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Invert : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Gpgqwerty : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Invert ransomware." + description = "Yara rule that detects GPGQwerty ransomware." author = "ReversingLabs" - id = "7ef77946-a902-5dc6-9b3c-b7b6a687eb96" - date = "2021-11-11" - modified = "2021-11-11" + id = "8848e00a-a695-575b-a29d-fc9521859e12" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Invert.yara#L1-L66" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "1608b8bbfc03b18a79752e60f211da7d7703862bc06b2ddf094074ae5efd0d14" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.GPGQwerty.yara#L1-L83" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "e59adadd66b4d242ac7337ce4b3c3ec6c60724f4cf5b86305f1e31b88745928c" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -30514,61 +31967,79 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Invert : TC_DETECTION MALICIOUS MALW sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Invert" + tc_detection_name = "GPGQwerty" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files = { - 73 ?? ?? ?? ?? 0A 06 04 7D ?? ?? ?? ?? 00 00 02 28 ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 25 2D - ?? 26 06 06 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 0C 7D ?? ?? ?? ?? 08 7E ?? ?? ?? ?? 25 - 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 - ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? - FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D - ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 2B ?? 07 6F ?? ?? ?? ?? 0D 00 00 09 03 28 ?? ?? - ?? ?? 13 ?? 11 ?? 2C ?? 00 7E ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 26 00 00 DE ?? 26 00 00 DE - ?? 00 07 6F ?? ?? ?? ?? 2D ?? DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? 00 DC 2A + $find_files_p1 = { + 56 53 89 D3 81 EC ?? ?? ?? ?? 8D 54 24 ?? 89 04 24 89 54 24 ?? E8 ?? ?? ?? ?? 83 EC + ?? 83 F8 ?? 89 C6 74 ?? 31 C0 8D 4B ?? 66 89 43 ?? 31 C0 EB ?? 0F B7 43 ?? 83 C0 ?? + 66 3D ?? ?? 66 89 43 ?? 83 D1 ?? 0F B7 C0 0F B6 44 04 ?? 84 C0 88 01 75 ?? 8B 44 24 + ?? 24 ?? 83 F8 ?? 76 ?? C7 43 ?? ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 89 F0 5B 5E C3 66 90 + 89 43 ?? 81 C4 ?? ?? ?? ?? 89 F0 5B 5E C3 E8 ?? ?? ?? ?? 89 C3 E8 ?? ?? ?? ?? 83 F8 + ?? 89 03 74 ?? E8 ?? ?? ?? ?? 81 38 ?? ?? ?? ?? 74 ?? E8 ?? ?? ?? ?? 83 38 ?? 74 ?? + E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? EB ?? E8 ?? + ?? ?? ?? C7 00 ?? ?? ?? ?? EB ?? 90 56 53 89 D3 81 EC ?? ?? ?? ?? 8D 54 24 ?? 89 04 + 24 89 54 24 ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 89 C6 74 ?? 31 C0 8D 4B ?? 66 89 43 ?? + 31 C0 EB ?? 0F B7 43 ?? 83 C0 ?? 66 3D ?? ?? 66 89 43 ?? 83 D1 ?? 0F B7 C0 0F B6 44 + 04 ?? 84 C0 88 01 75 ?? 8B 44 24 ?? 24 ?? 83 F8 ?? 77 ?? 89 43 ?? 81 C4 ?? ?? ?? ?? + 89 F0 5B 5E C3 8D B4 26 ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 89 F0 5B + 5E C3 E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 81 C4 ?? ?? ?? + ?? 89 F0 5B 5E C3 } - $find_files = { - 00 73 ?? ?? ?? ?? 0A 00 28 ?? ?? ?? ?? 18 8D ?? ?? ?? ?? 25 16 28 ?? ?? ?? ?? A2 25 17 - 72 ?? ?? ?? ?? A2 17 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 2B ?? 12 ?? 28 ?? - ?? ?? ?? 0C 00 06 08 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 26 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE - ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 26 06 - 0D 2B ?? 09 2A + $find_files_p2 = { + 8B 45 ?? 89 45 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 95 C0 84 + C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? + ?? 85 C0 74 ?? 8B 45 ?? 83 C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 + C0 74 ?? C6 85 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 ?? + ?? ?? ?? 8B 45 ?? 83 C0 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 94 C0 84 C0 0F 84 + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 83 + C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 45 + ?? 83 C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 8B 45 ?? 83 C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? + ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E8 } - $get_file_list = { - 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 06 2C - ?? 00 02 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 38 ?? ?? - ?? ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0B - 00 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 2B ?? 12 ?? 28 ?? ?? ?? ?? 0D 00 07 09 6F ?? ?? - ?? ?? 00 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 - DC 00 DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? 00 DC 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 18 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 18 28 ?? ?? ?? ?? 00 02 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F - ?? ?? ?? ?? 00 00 2A + $encrypt_files = { + C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 + C0 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 89 44 + 24 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? + ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 C2 B8 + ?? ?? ?? ?? 89 D7 F2 AE 89 C8 F7 D0 8D 50 ?? 8D 85 ?? ?? ?? ?? 01 D0 66 C7 00 ?? ?? + 8B 45 ?? 83 E8 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 } condition: - uint16(0)==0x5A4D and ($get_file_list) and ($find_files) and ($encrypt_files) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) } -import "pe" - -rule REVERSINGLABS_Win32_Ransomware_Cryptolocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Cring : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects CryptoLocker ransomware." + description = "Yara rule that detects Cring ransomware." author = "ReversingLabs" - id = "8cc3ac4b-9179-5e2c-97e1-65304f9dfe22" - date = "2020-07-15" - modified = "2020-07-15" + id = "76530a6d-145b-5316-8200-4b191d0754fd" + date = "2021-08-12" + modified = "2021-08-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.CryptoLocker.yara#L3-L154" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "08430b0c5689840d592bdda5dbc2ed06e0d0fa1e2c0f19aff4316580c6a0b23d" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Cring.yara#L1-L66" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "05cf60ad39c9dcc592345f13b63c99b153b9253297a8ad9e52e0439081d8c796" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -30576,139 +32047,151 @@ rule REVERSINGLABS_Win32_Ransomware_Cryptolocker : TC_DETECTION MALICIOUS MALWAR sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "CryptoLocker" + tc_detection_name = "Cring" tc_detection_factor = 5 importance = 25 strings: - $file_loop_1 = { - 55 8B EC 83 EC ?? 53 56 8B D9 57 89 5D ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 32 C9 83 7D ?? ?? 88 4D ?? 0F 86 45 01 - 00 00 8B 5D ?? 0F 57 C0 66 0F 13 45 ?? 84 C9 74 08 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? FF 75 ?? FF 33 FF 15 ?? - ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 FF 33 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B 75 ?? - 6A ?? 8B 49 ?? 6A ?? 52 56 8B 01 6A ?? 89 55 ?? 8B 00 FF D0 84 C0 0F 84 E6 00 00 00 FF 15 ?? ?? ?? ?? 8B 7D ?? 33 D2 89 - 45 ?? 8B D8 85 FF 72 18 77 08 81 FE ?? ?? ?? ?? 76 0E B8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB 05 8B C6 89 7D ?? 3B D0 73 - 0F 8B 45 ?? 8D 0C 13 8B 40 ?? 88 0C 02 42 EB CC 8B 5D ?? 85 FF 8B FE 75 04 85 F6 74 6B 85 DB 77 0E 72 08 81 FF ?? ?? ?? - ?? 73 04 8B F7 EB 05 BE ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 45 ?? 56 FF 70 ?? 8B 45 ?? FF 30 FF 15 ?? ?? ?? ?? 85 C0 74 ?? - 39 75 ?? 75 ?? 8B 45 ?? 2B FE 8B 55 ?? 83 DB ?? 2B D7 8B 48 ?? 8B 45 ?? 1B C3 50 8B 31 52 FF 75 ?? FF 75 ?? 8B 06 6A ?? - FF D0 84 C0 74 34 85 DB 77 AD 72 04 85 FF 75 95 8B 5D ?? FF 33 FF 15 ?? ?? ?? ?? 8A 4D ?? FE C1 0F B6 C1 88 4D ?? 3B 45 - ?? 0F 82 C6 FE FF FF B0 ?? 5F 5E 5B 8B E5 5D C2 - } - $file_loop_2 = { - 55 8B EC 83 EC ?? 53 56 8B D9 57 89 5D ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 32 C9 83 7D ?? ?? 88 4D ?? 0F 86 50 01 - 00 00 8B 5D ?? 0F 57 C0 66 0F 13 45 ?? 84 C9 74 08 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? FF 75 ?? FF 33 FF 15 ?? - ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 FF 33 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B 49 ?? - 8B 75 ?? 8B 01 6A ?? 8B 00 6A ?? 52 56 6A ?? 89 55 ?? FF D0 84 C0 0F 84 F1 00 00 00 FF 15 ?? ?? ?? ?? 8B 7D ?? 89 45 ?? - 33 D2 8B D8 85 FF 72 18 77 08 81 FE ?? ?? ?? ?? 76 0E B8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB 05 8B C6 89 7D ?? 3B D0 73 - 10 8B 45 ?? 8D 0C 13 8B 40 ?? 42 88 4C 02 ?? EB CB 8B 5D ?? 85 FF 8B FE 75 04 85 F6 74 75 85 DB 77 11 72 08 81 FF ?? ?? - ?? ?? 73 07 8B F7 89 5D ?? EB 0C BE ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 45 ?? 56 FF 70 ?? 8B 45 ?? FF - 30 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 39 75 ?? 75 ?? 8B 45 ?? 8B 55 ?? 8B 48 ?? 8B 45 ?? 2B FE 8B 31 83 DB ?? 2B D7 1B C3 50 - 8B 06 52 FF 75 ?? FF 75 ?? 6A ?? FF D0 84 C0 74 34 85 DB 77 A6 72 04 85 FF 75 8B 8B 5D ?? FF 33 FF 15 ?? ?? ?? ?? 8A 4D - ?? FE C1 0F B6 C1 88 4D ?? 3B 45 ?? 0F 82 BB FE FF FF B0 ?? 5F 5E 5B 8B E5 5D C2 - } - $file_loop_3 = { - 55 8B EC 83 EC ?? 53 56 8B C1 57 89 45 ?? E8 ?? ?? ?? ?? 84 C0 0F 84 62 01 00 00 8B 5D ?? 32 C0 0F 57 C0 88 45 ?? 66 0F - 13 45 ?? EB 03 8D 49 ?? 84 C0 74 08 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? FF 75 ?? FF 33 FF 15 ?? ?? ?? ?? 85 C0 - 0F 84 27 01 00 00 8D 45 ?? 50 FF 33 FF 15 ?? ?? ?? ?? 85 C0 0F 84 13 01 00 00 8B 4D ?? 8B 55 ?? 8B 49 ?? 8B 75 ?? 8B 01 - 6A ?? 8B 00 6A ?? 52 56 6A ?? 89 55 ?? FF D0 84 C0 0F 84 EE 00 00 00 FF 15 ?? ?? ?? ?? 8B 7D ?? 89 45 ?? 33 D2 8B D8 90 - 85 FF 72 18 77 08 81 FE ?? ?? ?? ?? 76 0E B8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB 05 8B C6 89 7D ?? 3B D0 73 10 8B 45 ?? - 8D 0C 13 8B 40 ?? 42 88 4C 02 ?? EB CB 8B 5D ?? 85 FF 8B FE 75 04 85 F6 74 75 85 DB 77 11 72 08 81 FF ?? ?? ?? ?? 73 07 - 8B F7 89 5D ?? EB 0C BE ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 45 ?? 56 FF 70 ?? 8B 45 ?? FF 30 FF 15 ?? - ?? ?? ?? 85 C0 74 5E 39 75 ?? 75 59 8B 45 ?? 8B 55 ?? 8B 48 ?? 8B 45 ?? 2B FE 8B 31 83 DB ?? 2B D7 1B C3 50 8B 06 52 FF - 75 ?? FF 75 ?? 6A ?? FF D0 84 C0 74 30 85 DB 77 A6 72 04 85 FF 75 8B 8B 5D ?? FF 33 FF 15 ?? ?? ?? ?? 8A 45 ?? FE C0 88 - 45 ?? 3C ?? 0F 82 BE FE FF FF B0 ?? 5F 5E 5B 8B E5 5D C2 - } - $encrypt_data_1 = { - 55 8B EC 56 8B 75 ?? 57 8B F9 39 75 ?? 73 09 5F 83 C8 ?? 5E 5D C2 ?? ?? 8B 07 53 85 C0 74 58 48 83 F8 ?? 77 48 8B 5D ?? - 8B 45 ?? 3B D8 74 0B 56 50 53 E8 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? 8D 45 ?? 89 75 ?? 50 8B 45 ?? 53 6A ?? 0F B6 C0 50 6A ?? - FF 77 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 83 CA ?? 85 C0 5B 0F 44 CA 5F 8B C1 5E 5D C2 ?? ?? 5B 5F 83 C8 ?? 5E 5D C2 ?? ?? 8B - 47 ?? 33 D2 89 45 ?? 8B 47 ?? 85 F6 74 26 8B 7D ?? 8B DE 8B 4D ?? 8B F0 2B F9 8A 04 0F 8D 49 ?? 32 04 32 88 41 ?? 8D 42 - ?? 33 D2 F7 75 ?? 4B 75 E9 8B 75 ?? 5B 5F 8B C6 5E 5D C2 - } - $encrypt_data_2 = { - 55 8B EC 56 8B 75 ?? 57 8B F9 39 75 ?? 73 09 5F 83 C8 ?? 5E 5D C2 ?? ?? 8B 07 53 85 C0 74 56 48 83 F8 ?? 77 46 8B 5D ?? - 8B 45 ?? 3B D8 74 0B 56 50 53 E8 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? 8D 45 ?? 50 0F B6 45 ?? 53 6A ?? 50 6A ?? FF 77 ?? 89 75 - ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 83 CA ?? 85 C0 5B 0F 44 CA 5F 8B C1 5E 5D C2 ?? ?? 5B 5F 83 C8 ?? 5E 5D C2 ?? ?? 8B 47 ?? - 33 D2 89 45 ?? 8B 47 ?? 85 F6 74 26 8B 4D ?? 8B 7D ?? 8B DE 2B F9 8B F0 8A 04 0F 32 04 32 8D 49 ?? 88 41 ?? 8D 42 ?? 33 - D2 F7 75 ?? 4B 75 E9 8B 75 ?? 5B 5F 8B C6 5E 5D C2 - } - $encrypt_data_3 = { - 55 8B EC 53 56 8B 75 ?? 8B D9 39 75 ?? 72 4C 83 3B ?? 77 47 8B 45 ?? 57 8B 7D ?? 3B F8 74 0B 56 50 57 E8 ?? ?? ?? ?? 83 - C4 ?? FF 75 ?? 8D 45 ?? 50 0F B6 45 ?? 57 6A ?? 50 6A ?? FF 73 ?? 89 75 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 83 CA ?? 85 C0 5F - 0F 44 CA 5E 8B C1 5B 5D C2 ?? ?? 5E 83 C8 ?? 5B 5D C2 - } - $decrypt_data_1 = { - 55 8B EC 53 56 57 8B F9 8B 07 85 C0 74 53 48 83 F8 ?? 77 55 8B 75 ?? 39 75 ?? 72 4D 8B 5D ?? 8B 45 ?? 3B D8 74 0B 56 50 - 53 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 89 75 ?? 50 8B 45 ?? 53 6A ?? 0F B6 C0 50 6A ?? FF 77 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? - 83 CA ?? 85 C0 5F 0F 44 CA 5E 8B C1 5B 5D C2 ?? ?? 8B 75 ?? 39 75 ?? 73 0A 5F 5E 83 C8 ?? 5B 5D C2 ?? ?? 8B 47 ?? 33 D2 - 89 45 ?? 8B 47 ?? 85 F6 74 28 8B 7D ?? 8B DE 8B 4D ?? 8B F0 2B F9 8B FF 8A 04 0F 8D 49 ?? 32 04 32 88 41 ?? 8D 42 ?? 33 - D2 F7 75 ?? 4B 75 E9 8B 75 ?? 5F 8B C6 5E 5B 5D C2 - } - $decrypt_data_2 = { - 55 8B EC 53 56 57 8B F9 8B 07 85 C0 74 51 48 83 F8 ?? 77 53 8B 75 ?? 39 75 ?? 72 4B 8B 5D ?? 8B 45 ?? 3B D8 74 0B 56 50 - 53 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 0F B6 45 ?? 53 6A ?? 50 6A ?? FF 77 ?? 89 75 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 83 CA - ?? 85 C0 5F 0F 44 CA 5E 8B C1 5B 5D C2 ?? ?? 8B 75 ?? 39 75 ?? 73 0A 5F 5E 83 C8 ?? 5B 5D C2 ?? ?? 8B 47 ?? 33 D2 89 45 - ?? 8B 47 ?? 85 F6 74 2A 8B 4D ?? 8B 7D ?? 8B DE 2B F9 8B F0 8D 64 24 ?? 8A 04 0F 32 04 32 8D 49 ?? 88 41 ?? 8D 42 ?? 33 - D2 F7 75 ?? 4B 75 E9 8B 75 ?? 5F 8B C6 5E 5B 5D C2 - } - $decrypt_data_3 = { - 55 8B EC 53 8B D9 83 3B ?? 77 56 56 8B 75 ?? 39 75 ?? 73 09 5E 83 C8 ?? 5B 5D C2 ?? ?? 8B 45 ?? 57 8B 7D ?? 3B F8 74 0B - 56 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 0F B6 45 ?? 57 6A ?? 50 6A ?? FF 73 ?? 89 75 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? - 83 CA ?? 85 C0 5F 0F 44 CA 5E 8B C1 5B 5D C2 ?? ?? 83 C8 ?? 5B 5D C2 + $find_files_p1 = { + 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 06 07 9A 0C 08 6F ?? ?? ?? ?? 19 2E ?? 08 6F ?? ?? ?? ?? + 18 33 ?? 08 6F ?? ?? ?? ?? 2C ?? 08 6F ?? ?? ?? ?? 02 17 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 0D 2B ?? 09 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 2D ?? DE ?? 09 2C ?? 09 6F + ?? ?? ?? ?? DC 07 17 58 0B 07 06 8E 69 32 ?? 2A } - $decrypt_strings_1 = { - 55 8B EC 53 56 8B D9 8B F2 57 33 C9 33 FF 2B DE 8B 45 ?? 8D 14 31 8A 04 07 02 C1 32 04 13 88 02 8D 47 ?? 33 D2 F7 75 ?? - 8B FA F6 C1 ?? 75 0B 8B C1 D1 E8 66 83 3C 46 ?? 74 03 41 EB D3 D1 E9 5F 5E 5B 8D 41 ?? 5D C3 + $find_files_p2 = { + 02 7B ?? ?? ?? ?? 0B 07 45 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 16 0A DD ?? + ?? ?? ?? 02 15 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? + ?? ?? 14 0C 02 7B ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C DE ?? 26 DE ?? 08 2C + ?? 02 08 7D ?? ?? ?? ?? 02 16 7D ?? ?? ?? ?? 2B ?? 02 7B ?? ?? ?? ?? 02 7B ?? ?? ?? ?? + 9A 0D 02 09 7D ?? ?? ?? ?? 02 17 7D ?? ?? ?? ?? 17 0A DD ?? ?? ?? ?? 02 15 7D ?? ?? ?? + ?? 02 02 7B ?? ?? ?? ?? 17 58 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 8E 69 + 32 ?? 02 14 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 39 ?? ?? ?? ?? 14 0C 02 7B ?? ?? ?? ?? 28 + ?? ?? ?? ?? 0C DE ?? 26 DE ?? 08 39 ?? ?? ?? ?? 02 08 7D ?? ?? ?? ?? 02 16 7D ?? ?? ?? + ?? 38 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 9A 13 ?? 02 11 ?? 02 7B ?? ?? ?? + ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 1F ?? 7D ?? ?? ?? + ?? 2B ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 02 11 ?? 7D ?? ?? ?? ?? 02 18 7D ?? ?? + ?? ?? 17 0A DE ?? 02 1F ?? 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 02 28 + ?? ?? ?? ?? 02 14 7D ?? ?? ?? ?? 02 02 7B ?? ?? ?? ?? 17 58 7D ?? ?? ?? ?? 02 7B ?? ?? + ?? ?? 02 7B ?? ?? ?? ?? 8E 69 3F ?? ?? ?? ?? 02 14 7D ?? ?? ?? ?? 16 0A DE ?? 02 28 ?? + ?? ?? ?? DC 06 2A } - $decrypt_strings_2 = { - 55 8B EC 53 56 8B D9 57 8B F2 33 C9 33 FF 2B DE 8B 45 ?? 8D 14 31 8A 04 07 02 C1 32 04 13 88 02 8D 47 ?? 33 D2 F7 75 ?? - 8B FA F6 C1 ?? 75 0B 8B C1 D1 E8 66 83 3C 46 ?? 74 03 41 EB D3 5F D1 E9 5E 8D 41 ?? 5B 5D C3 + $encrypt_files = { + 16 0A 73 ?? ?? ?? ?? 0B 07 6F ?? ?? ?? ?? 1E 5B 8D ?? ?? ?? ?? 0C 07 6F ?? ?? ?? ?? 1E + 5B 8D ?? ?? ?? ?? 0D 73 ?? ?? ?? ?? 13 ?? 11 ?? 08 6F ?? ?? ?? ?? 11 ?? 09 6F ?? ?? ?? + ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 08 8E 69 09 8E 69 58 8D ?? ?? ?? ?? 13 ?? + 08 11 ?? 08 8E 69 28 ?? ?? ?? ?? 09 16 11 ?? 08 8E 69 09 8E 69 28 ?? ?? ?? ?? 11 ?? 04 + 28 ?? ?? ?? ?? 13 ?? 11 ?? 8E 69 28 ?? ?? ?? ?? 13 ?? 07 08 09 6F ?? ?? ?? ?? 13 ?? 02 + 19 73 ?? ?? ?? ?? 13 ?? 03 18 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 17 73 ?? ?? ?? ?? 13 ?? + 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 11 + ?? 11 ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 11 ?? + 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 11 ?? 2C ?? 11 ?? 6F + ?? ?? ?? ?? DC 17 0A DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC 06 2A } - $decrypt_1 = { - A1 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 8C B7 00 00 00 33 D2 8B 0C 95 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? ?? 81 E1 ?? ?? ?? ?? 33 0C - 95 ?? ?? ?? ?? 8B C1 D1 E9 83 E0 ?? 33 0C 85 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? ?? 89 0C 95 ?? ?? ?? ?? 42 81 FA ?? ?? ?? ?? - 7C C0 81 FA ?? ?? ?? ?? 7D 39 56 8D 34 95 ?? ?? ?? ?? 8B 0E 33 4E ?? 81 E1 ?? ?? ?? ?? 33 0E 8B C1 D1 E9 83 E0 ?? 8B 04 - 85 ?? ?? ?? ?? 33 86 ?? ?? ?? ?? 33 C1 89 06 83 C6 ?? 81 FE ?? ?? ?? ?? 7C D0 5E 8B 0D ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 81 - E1 ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 8B C1 D1 E9 83 E0 ?? 33 0C 85 ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 33 C0 89 0D ?? ?? ?? ?? 8B - 0C 85 ?? ?? ?? ?? 40 A3 ?? ?? ?? ?? 8B C1 C1 E8 ?? 33 C8 8B C1 25 ?? ?? ?? ?? C1 E0 ?? 33 C8 8B C1 25 ?? ?? ?? ?? C1 E0 - ?? 33 C8 8B C1 C1 E8 ?? 33 C1 C3 + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Harpoonlocker : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects HarpoonLocker ransomware." + author = "ReversingLabs" + id = "3605d354-5a33-54b1-83ad-ad514c78357b" + date = "2022-01-27" + modified = "2022-01-27" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.HarpoonLocker.yara#L1-L96" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "20587f9dce5981934498d9979843a090224ba649def8b694adf7799b7060cc25" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "HarpoonLocker" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 14 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? + ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 25 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 6F + ?? ?? ?? ?? 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 73 ?? ?? ?? ?? 25 06 07 9A 7D + ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 14 28 ?? ?? ?? ?? 26 07 17 58 0B 07 06 8E + 69 32 ?? 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 2B ?? 73 ?? ?? ?? ?? 0D + 09 12 ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 09 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 14 28 ?? ?? ?? + ?? 26 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? DC 12 ?? + 12 ?? 28 ?? ?? ?? ?? 12 ?? 12 ?? 28 ?? ?? ?? ?? 11 ?? 11 ?? 59 13 ?? 72 ?? ?? ?? ?? 11 + ?? 8C ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 2C ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 2B ?? 2A } - $decrypt_2 = { - A1 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 8C C7 00 00 00 33 D2 EB 0C 8D A4 24 ?? ?? ?? ?? EB 03 8D 49 ?? 8B 0C 95 ?? ?? ?? ?? 33 - 0C 95 ?? ?? ?? ?? 42 81 E1 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? ?? 8B C1 83 E0 ?? D1 E9 33 0C 85 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? - ?? 89 0C 95 ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 7C C0 81 FA ?? ?? ?? ?? 7D 3B 56 8D 34 95 ?? ?? ?? ?? 8B 0E 33 4E ?? 83 C6 ?? - 81 E1 ?? ?? ?? ?? 33 4E ?? 8B C1 83 E0 ?? D1 E9 8B 04 85 ?? ?? ?? ?? 33 86 ?? ?? ?? ?? 33 C1 89 46 ?? 81 FE ?? ?? ?? ?? - 7C CE 5E 8B 0D ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 81 E1 ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 8B C1 83 E0 ?? D1 E9 33 0C 85 ?? ?? ?? - ?? 33 0D ?? ?? ?? ?? 33 C0 89 0D ?? ?? ?? ?? 8B 0C 85 ?? ?? ?? ?? 40 A3 ?? ?? ?? ?? 8B C1 C1 E8 ?? 33 C8 8B C1 25 ?? ?? - ?? ?? C1 E0 ?? 33 C8 8B C1 25 ?? ?? ?? ?? C1 E0 ?? 33 C8 8B C1 C1 E8 ?? 33 C1 C3 + $encrypt_files_p2 = { + 12 ?? FE 15 ?? ?? ?? ?? 12 ?? FE 15 ?? ?? ?? ?? 12 ?? FE 15 ?? ?? ?? ?? 02 16 12 ?? 28 + ?? ?? ?? ?? 26 08 7B ?? ?? ?? ?? 0D 08 7B ?? ?? ?? ?? 20 ?? ?? ?? ?? 35 ?? 08 7B ?? ?? + ?? ?? 16 36 ?? DD ?? ?? ?? ?? 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 72 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 10 ?? 03 03 6F ?? ?? ?? ?? 03 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? + 13 ?? 1F ?? 8D ?? ?? ?? ?? 13 ?? 03 6F ?? ?? ?? ?? 16 11 ?? 16 1F ?? 28 ?? ?? ?? ?? 03 + 6F ?? ?? ?? ?? 16 11 ?? 1F ?? 1F ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 1F ?? 6A + 13 ?? 17 13 ?? 09 6E 13 ?? 2B ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 59 13 ?? 11 ?? 11 ?? 30 + ?? 02 19 17 7E ?? ?? ?? ?? 19 20 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? + 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? DD ?? ?? ?? ?? 11 ?? 7E ?? ?? ?? ?? 1A 16 09 20 ?? + ?? ?? ?? 58 14 28 ?? ?? ?? ?? 0A 06 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? DD ?? ?? ?? ?? + 06 1F ?? 16 16 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? + DD ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 26 16 13 ?? 16 13 ?? 2B ?? 11 ?? 20 ?? ?? ?? ?? 2F + ?? 09 6E 11 ?? 6A 59 13 ?? 11 ?? D4 8D ?? ?? ?? ?? 13 ?? 11 ?? 17 58 11 ?? 33 ?? 11 ?? + D4 8D ?? ?? ?? ?? 13 ?? 07 11 ?? 28 ?? ?? ?? ?? 11 ?? 16 11 ?? 8E 69 28 ?? ?? ?? ?? 11 + ?? 18 5D 2D ?? 11 ?? 8E 69 1F ?? 33 ?? 11 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 16 07 11 + ?? 28 ?? ?? ?? ?? 11 ?? 8E 69 28 ?? ?? ?? ?? 11 ?? 11 ?? 8E 69 58 13 ?? 11 ?? 17 58 13 + ?? 11 ?? 11 ?? 3F ?? ?? ?? ?? 11 ?? 20 ?? ?? ?? ?? 32 ?? 11 ?? 16 07 09 28 ?? ?? ?? ?? + 11 ?? 8E 69 28 ?? ?? ?? ?? 2B ?? 11 ?? 16 07 11 ?? 28 ?? ?? ?? ?? 11 ?? 8E 69 28 ?? ?? + ?? ?? DE ?? 26 DE ?? 26 DE ?? 00 07 28 ?? ?? ?? ?? 26 DE ?? 26 DE ?? 00 06 28 ?? ?? ?? + ?? 26 DE ?? 26 DE ?? DC 2A } - $decrypt_3 = { - A1 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 8C C7 00 00 00 33 D2 EB 0C 8D A4 24 ?? ?? ?? ?? EB 03 8D 49 ?? 8B 0C 95 ?? ?? ?? ?? 33 - 0C 95 ?? ?? ?? ?? 42 81 E1 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? ?? 8B C1 83 E0 ?? D1 E9 33 0C 85 ?? ?? ?? ?? 33 0C 95 ?? ?? ?? - ?? 89 0C 95 ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 7C C0 81 FA ?? ?? ?? ?? 7D 3B 56 8D 34 95 ?? ?? ?? ?? 8B 0E 33 4E ?? 83 C6 ?? - 81 E1 ?? ?? ?? ?? 33 4E ?? 8B C1 83 E0 ?? D1 E9 8B 04 85 ?? ?? ?? ?? 33 86 ?? ?? ?? ?? 33 C1 89 46 ?? 81 FE ?? ?? ?? ?? - 7C CE 5E 8B 0D ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 81 E1 ?? ?? ?? ?? 33 0D ?? ?? ?? ?? 8B C1 83 E0 ?? D1 E9 33 0C 85 ?? ?? ?? - ?? 33 0D ?? ?? ?? ?? 33 C0 89 0D ?? ?? ?? ?? 8B 0C 85 ?? ?? ?? ?? 40 A3 ?? ?? ?? ?? 8B C1 C1 E8 ?? 33 C8 8B C1 25 ?? ?? - ?? ?? C1 E0 ?? 33 C8 8B C1 25 ?? ?? ?? ?? C1 E0 ?? 33 C8 8B C1 C1 E8 ?? 33 C1 C3 + $find_files = { + 73 ?? ?? ?? ?? 0A 06 02 7D ?? ?? ?? ?? 7E ?? ?? ?? ?? 06 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 2C ?? 2A 00 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? + ?? ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 14 0B 06 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B DE ?? 26 + DE ?? 07 2C ?? 07 8E 16 FE 01 2B ?? 17 0C 06 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 16 13 + ?? 2B ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 11 ?? 9A 7D ?? ?? ?? ?? 08 2C ?? 11 ?? 7B ?? + ?? ?? ?? 28 ?? ?? ?? ?? 2B ?? 11 ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 14 28 ?? ?? ?? ?? + 26 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? DE ?? 26 DE ?? 08 2C ?? DD ?? ?? ?? ?? 28 + ?? ?? ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 17 + 6F ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 07 13 ?? 16 13 ?? 2B ?? 73 ?? ?? ?? + ?? 13 ?? 11 ?? 11 ?? 11 ?? 9A 7D ?? ?? ?? ?? 11 ?? 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? + 7E ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 7E ?? ?? ?? ?? 11 ?? FE 06 ?? + ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2D ?? 11 ?? 7B ?? ?? ?? ?? 09 28 ?? ?? ?? ?? DE + ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? 00 09 6F ?? ?? ?? ?? DE ?? 26 DE + ?? DE ?? 26 DE ?? 2A } - $entrypoint_all = { - 83 EC ?? E8 ?? ?? ?? ?? 50 FF 15 + $change_boot = { + 02 8E 2C ?? 02 16 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 2A 02 16 9A 72 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2A 02 16 9A 72 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 2C ?? 17 80 ?? ?? ?? ?? 16 80 ?? ?? ?? ?? 02 16 9A 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 2C ?? 17 80 ?? ?? ?? ?? 02 16 9A 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 28 ?? + ?? ?? ?? 2A 28 ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? + ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2A 28 ?? ?? ?? ?? 2A } condition: - uint16(0)==0x5A4D and ((($file_loop_1 and $encrypt_data_1 and $decrypt_data_1 and $decrypt_strings_1 and $decrypt_1) or ($file_loop_2 and $encrypt_data_2 and $decrypt_data_2 and $decrypt_strings_2 and $decrypt_2) or ($file_loop_3 and $encrypt_data_3 and $decrypt_data_3 and $decrypt_3)) and ($entrypoint_all at pe.entry_point)) + uint16(0)==0x5A4D and ($change_boot) and ($find_files) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Crysis : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Rokku : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Crysis ransomware." + description = "Yara rule that detects Rokku ransomware." author = "ReversingLabs" - id = "bba2bbf5-ff77-5ec4-ae7f-afae1b564fb7" + id = "8722ed4a-b480-57ec-bba7-ce7d0f3704b9" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Crysis.yara#L1-L108" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3c9250206f94ac65c1fc24e83cf8cdd76d10066086ef1f34ec14791d237c0263" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Rokku.yara#L1-L147" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "fefb342f8a9afac3b40c343b830f334225ff4198d55504846aa855acf5dfc9ba" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -30716,103 +32199,137 @@ rule REVERSINGLABS_Win32_Ransomware_Crysis : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Crysis" + tc_detection_name = "Rokku" tc_detection_factor = 5 importance = 25 strings: - $remote_connection_1 = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 6A ?? - 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 6A ?? 6A ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? B9 - ?? ?? ?? ?? 66 89 4D ?? 6A ?? FF 15 ?? ?? ?? ?? 66 89 45 ?? 8B 55 ?? 52 FF 15 ?? ?? - ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 8B 51 ?? 8B 45 ?? 83 3C 82 ?? - 74 ?? 8B 4D ?? 0F BF 51 ?? 52 8B 45 ?? 8B 48 ?? 8B 55 ?? 8B 04 91 50 8D 4D ?? 51 E8 - ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A - ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 50 8B 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? - 6A ?? 8D 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? EB ?? E9 ?? ?? ?? ?? 8B 45 ?? 8B E5 5D C3 + $encrypt_files_p1 = { + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 55 8B E9 C7 44 24 ?? ?? ?? ?? ?? 33 DB 89 6C 24 ?? + 56 0F 57 C0 66 C7 44 24 ?? ?? ?? 57 66 0F 13 44 24 ?? B2 ?? 88 5C 24 ?? 8B CB 8A C1 + 02 C2 30 44 0C ?? 41 83 F9 ?? 73 ?? 8A 54 24 ?? EB ?? 8B CD 88 5C 24 ?? E8 ?? ?? ?? + ?? 8D 54 24 ?? 8B C8 E8 ?? ?? ?? ?? 85 C0 75 ?? 40 E9 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 51 BE ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B D6 E8 ?? ?? ?? ?? 59 56 BE + ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8D 4C 24 ?? 6A + ?? 8B D5 E8 ?? ?? ?? ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 8B C1 8B 94 24 ?? ?? ?? ?? 0B C2 0F 84 ?? + ?? ?? ?? 6A ?? 5D 3B D3 77 ?? 81 F9 ?? ?? ?? ?? 76 ?? 2B CD 1B D3 52 51 55 8D 4C 24 + ?? E8 ?? ?? ?? ?? 83 C4 ?? 3B C5 0F 85 ?? ?? ?? ?? 8B CD 8B C3 8A 90 ?? ?? ?? ?? 49 + 8A B0 ?? ?? ?? ?? 3A D6 75 ?? 40 85 C9 75 ?? 8B CB EB ?? 0F B6 C6 0F B6 CA 2B C8 85 + C9 0F 84 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 8B D6 50 B9 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 88 19 41 83 E8 ?? 75 ?? + 8B 6C 24 ?? 8B 7C 24 ?? 8B 84 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 2B C7 1B CD 3B EB } - $enumerate_files = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 33 DB 81 7D ?? ?? ?? ?? ?? 56 57 89 5C 24 ?? - 0F 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 7D ?? - 57 8B F0 FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 6A ?? - 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 8E ?? ?? ?? ?? 8D 44 24 ?? 50 56 - FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 5D ?? 8D 4C 24 ?? 51 68 - ?? ?? ?? ?? 57 6A ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 7E ?? F6 44 24 - ?? ?? 74 ?? 66 83 7C 24 ?? ?? 74 ?? 53 8D 54 24 ?? 52 8B D6 8B CF FF 55 ?? 85 C0 7E - ?? 8B 45 ?? 8B 4D ?? 40 50 53 51 56 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 53 8D 54 24 ?? 52 - 8B D6 8B CF FF 55 ?? 85 C0 7E ?? FF 44 24 ?? 8B 4C 24 ?? 8D 44 24 ?? 50 51 FF 15 ?? - ?? ?? ?? 85 C0 7F ?? 8B 54 24 ?? 52 FF 15 ?? ?? ?? ?? 8B 5C 24 ?? 56 6A ?? FF 15 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 5F 5E 8B C3 5B 8B E5 5D C3 + $encrypt_files_p2 = { + 7C ?? 7F ?? 81 FF ?? ?? ?? ?? 72 ?? 8B AC 24 ?? ?? ?? ?? 0F 57 C0 8B BC 24 ?? ?? ?? + ?? 8B 4C 24 ?? 55 57 66 0F 13 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 59 59 8B 4C 24 ?? + 3B CB 77 ?? 3B C3 77 ?? 8B F3 EB ?? 3B CB 77 ?? 72 ?? 3D ?? ?? ?? ?? 72 ?? B8 ?? ?? + ?? ?? 55 57 50 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 85 F6 0F 88 ?? ?? ?? ?? 74 + ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 56 50 8B D0 E8 ?? ?? ?? ?? 55 57 56 BA ?? ?? ?? ?? + 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 88 ?? ?? ?? ?? 99 03 F8 13 EA E9 ?? ?? + ?? ?? 6A ?? 58 89 1D ?? ?? ?? ?? 83 E8 ?? 75 ?? 8B C7 89 1D ?? ?? ?? ?? 0B C5 BE ?? + ?? ?? ?? 74 ?? 51 8D 54 24 ?? E8 ?? ?? ?? ?? 59 B9 ?? ?? ?? ?? 3B F1 74 ?? 56 51 BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 55 57 BD ?? ?? ?? ?? 8B D1 55 8D 4C 24 ?? E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 0F 88 ?? ?? ?? ?? EB ?? BD ?? ?? ?? ?? 6A ?? 59 8B C1 BA ?? + ?? ?? ?? C6 02 ?? 42 83 E8 ?? 75 ?? B8 ?? ?? ?? ?? C6 00 ?? 40 83 E9 ?? 75 ?? 6A ?? + 58 B9 ?? ?? ?? ?? C6 01 ?? 41 83 E8 ?? 75 ?? C6 06 ?? 46 83 ED ?? 75 ?? 6A ?? 8D 44 + 24 ?? 59 C6 00 ?? 40 83 E9 ?? 75 ?? B1 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? 8B C3 30 4C 04 ?? 40 83 F8 ?? 73 ?? 8A 4C 24 ?? EB ?? 8B 4C 24 ?? 8D 54 24 ?? + 88 5C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? 8B F0 E8 ?? ?? ?? ?? 8B 4C 24 ?? 8B D6 E8 ?? + ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 33 DB 43 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B C3 EB ?? 8D 4C + 24 ?? E8 ?? ?? ?? ?? 33 C0 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 } - $enumerate_resources = { - FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - 8D 55 ?? 52 8B 45 ?? 50 8D 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 3B 4D ?? 0F 83 - ?? ?? ?? ?? 8B 55 ?? C1 E2 ?? 8B 45 ?? 83 7C 10 ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? ?? - ?? ?? 8B 55 ?? C1 E2 ?? 8B 4D ?? 8B 75 ?? 8B 54 16 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B - 45 ?? 50 8B 4D ?? 51 8B 55 ?? C1 E2 ?? 8B 45 ?? 8B 4C 10 ?? 51 E8 ?? ?? ?? ?? 83 C4 - ?? 8B 55 ?? C1 E2 ?? 8B 45 ?? 8B 4C 10 ?? 83 E1 ?? 74 ?? 8B 55 ?? 52 8B 45 ?? 50 8B - 4D ?? 51 8B 55 ?? C1 E2 ?? 03 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8D - 4D ?? 51 8B 55 ?? 52 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 8B 4D ?? 51 8D 55 ?? 52 8B 45 ?? - 50 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 4D ?? 83 - C1 ?? 89 4D ?? 8B 55 ?? 3B 55 ?? 0F 83 ?? ?? ?? ?? 8B 45 ?? C1 E0 ?? 8B 4D ?? 83 7C - 01 ?? ?? 75 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 55 ?? C1 E2 ?? 8B 4D ?? 8B 75 ?? 8B - 54 16 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? C1 E2 ?? 8B 45 - ?? 8B 4C 10 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C1 E2 ?? 8B 45 ?? 8B 4C 10 ?? 83 - E1 ?? 74 ?? 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? C1 E2 ?? 03 55 ?? 52 E8 ?? - ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? - ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 5E 8B E5 5D C3 + $encrypt_files_p3 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 55 56 57 6A ?? 5E 56 BF ?? ?? ?? ?? 57 FF 15 + ?? ?? ?? ?? 51 BB ?? ?? ?? ?? BD ?? ?? ?? ?? 8B D3 8B CD E8 ?? ?? ?? ?? 59 56 57 FF + 15 ?? ?? ?? ?? 51 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B C6 C6 07 ?? 47 + 83 E8 ?? 75 ?? BF ?? ?? ?? ?? BA ?? ?? ?? ?? 53 8B CF E8 ?? ?? ?? ?? 59 6A ?? 58 C6 + 03 ?? 43 83 E8 ?? 75 ?? B9 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 3B E9 74 ?? 55 51 8B D6 + E8 ?? ?? ?? ?? 83 C4 ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 3B C1 74 ?? 50 51 8B D6 E8 ?? + ?? ?? ?? 83 C4 ?? 6A ?? 5B 53 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8D 44 24 ?? B9 ?? ?? + ?? ?? 50 51 8B D3 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 83 C4 ?? 3B C8 74 ?? + 51 50 6A ?? 5A 8B C8 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 3B C1 74 + ?? 50 51 8B D6 E8 ?? ?? ?? ?? 83 C4 ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 3B C1 74 ?? 50 + 51 6A ?? 5A E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 6A ?? 5B 3B C1 74 + ?? 50 51 8B D3 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 3B C1 74 ?? 50 + 51 6A ?? 5A E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 8B D7 50 8D 4C 24 ?? E8 ?? ?? ?? ?? + 59 BA ?? ?? ?? ?? 8D 4C 24 ?? 6A ?? 52 E8 ?? ?? ?? ?? 59 59 83 64 24 ?? ?? 83 EB ?? + 75 ?? 21 9C 24 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 59 C6 00 ?? 40 83 E9 ?? 75 ?? 8B C6 C6 + 45 ?? ?? 45 83 E8 ?? 75 ?? C6 07 ?? 47 83 EE ?? 75 ?? 33 C0 5F 40 5E 5D 5B 8B E5 5D + C3 } - $encrypt_files = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 8B D8 33 C0 56 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 8B - 45 ?? 6A ?? 50 8D 4D ?? 51 8D 77 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B - D3 83 E2 ?? 2B DA 83 EB ?? 83 C4 ?? 89 5D ?? 8B 1D ?? ?? ?? ?? 50 FF D3 89 45 ?? 83 - F8 ?? 0F 84 ?? ?? ?? ?? 8B 4D ?? 51 FF D3 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 81 C2 - ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 8B 45 ?? A8 ?? 74 ?? 83 E0 ?? 50 8B - 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 51 - FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 33 C0 - 33 C9 51 50 53 89 45 ?? 89 45 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? - ?? 75 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 33 C9 51 8D 55 ?? 52 33 C0 50 51 53 FF 15 ?? - ?? ?? ?? 8B 45 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 55 ?? 8B 45 ?? 6A ?? 8D 4D ?? 51 52 57 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? 8B 4D ?? 85 C9 74 ?? 8B 45 ?? 85 C0 75 ?? 3B 4D ?? 73 ?? 8B D1 83 E2 ?? B8 ?? ?? - ?? ?? 2B C2 89 45 ?? 57 03 C1 8D 8D ?? ?? ?? ?? 57 51 E8 ?? ?? ?? ?? 8B 4D ?? 03 4D - ?? 83 C4 ?? 6A ?? 8D 55 ?? 52 51 57 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B - 45 ?? 03 45 ?? 39 45 ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 6A ?? 8D 4D ?? 51 52 57 - 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? 57 E8 ?? ?? ?? ?? 8B 45 - ?? 83 C4 ?? C7 47 ?? ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 85 C0 74 ?? 8B 4D ?? 51 50 56 - C7 47 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 03 F0 01 45 ?? 8B 55 ?? 6A ?? - 52 56 E8 ?? ?? ?? ?? 8B 45 ?? 6A ?? 50 83 C6 ?? 56 E8 ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 - 83 C6 ?? 56 E8 ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 83 C6 ?? 56 E8 ?? ?? ?? ?? 8B 45 ?? 68 - ?? ?? ?? ?? 50 83 C6 ?? 56 E8 ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 83 EE ?? 56 E8 ?? ?? ?? - ?? 83 C4 ?? 6A ?? 8D 55 ?? 52 83 C6 ?? 2B F7 56 57 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? - 39 75 ?? 75 ?? 53 FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 83 7D - ?? ?? 7E ?? 8B 75 ?? 33 C9 51 8D 55 ?? 52 33 C0 50 51 56 FF 15 ?? ?? ?? ?? 56 FF 15 - ?? ?? ?? ?? 8B 5D ?? 53 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 7E ?? 8B 45 ?? 8B 4D ?? 50 51 - FF 15 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 5E 5B 8B E5 5D C3 + $find_files_p1 = { + 55 8B EC 83 EC ?? 53 56 6A ?? 59 E8 ?? ?? ?? ?? 8B F0 66 C7 45 ?? ?? ?? 33 DB 89 35 + ?? ?? ?? ?? B1 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B C3 C7 45 ?? ?? ?? ?? + ?? 66 C7 45 ?? ?? ?? 02 C8 30 4C 05 ?? 40 83 F8 ?? 73 ?? 8A 4D ?? EB ?? 8D 45 ?? 88 + 5D ?? 50 8D 55 ?? 8B CE E8 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? B0 ?? 59 B1 ?? 88 5D ?? + 32 C1 88 4D ?? 88 45 ?? 8B CB 0F 11 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + 66 C7 45 ?? ?? ?? 88 5D ?? 8A 45 ?? 30 44 0D ?? 41 83 F9 ?? 72 ?? 8B 0D ?? ?? ?? ?? + 8D 45 ?? 50 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 B1 ?? 88 5D ?? B0 ?? 88 4D ?? 32 C1 + C7 45 ?? ?? ?? ?? ?? 88 45 ?? 8B C3 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 80 44 + 05 ?? ?? 40 83 F8 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? E8 ?? ?? ?? ?? 59 + 6A ?? 33 C9 C7 45 ?? ?? ?? ?? ?? 5B B0 ?? 88 5D ?? 32 C3 88 4D ?? 88 45 ?? 8B C1 C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 88 4D ?? 80 44 05 ?? ?? 40 83 F8 ?? 72 ?? 8B + 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? E8 ?? ?? ?? ?? 59 6A ?? 88 5D ?? B2 ?? 66 C7 45 + ?? ?? ?? 33 C9 66 C7 45 ?? ?? ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 5B 8D + 04 0A 30 44 0D ?? 41 3B CB 73 ?? 8A 55 ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 + ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 59 6A ?? 33 C9 C6 45 ?? ?? 58 34 ?? 88 4D ?? 88 45 + } + $find_files_p2 = { + B2 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 8D 04 0A 30 44 0D + ?? 41 83 F9 ?? 73 ?? 8A 55 ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? C6 45 ?? + ?? E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 80 F3 ?? C6 45 ?? ?? 88 5D ?? 8D 55 ?? + 33 DB C6 45 ?? ?? 50 88 5D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 59 59 6A ?? 58 34 ?? C6 45 ?? ?? 88 45 ?? B2 ?? 88 5D ?? 8B CB C7 45 ?? ?? ?? ?? + ?? 66 C7 45 ?? ?? ?? 88 5D ?? 8D 04 0A 30 44 0D ?? 41 83 F9 ?? 73 ?? 8A 55 ?? EB ?? + 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 66 C7 45 ?? ?? ?? + 8B C3 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 80 44 05 ?? ?? + 40 83 F8 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? E8 ?? ?? ?? ?? B0 ?? C6 45 + ?? ?? 34 ?? 88 5D ?? 59 88 45 ?? B1 ?? C7 45 ?? ?? ?? ?? ?? 8B C3 C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 88 5D ?? 30 4C 05 ?? 40 83 F8 ?? 73 ?? 8A + 4D ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 0F 28 05 + ?? ?? ?? ?? 59 66 C7 45 ?? ?? ?? 8B CB 0F 11 45 ?? C7 45 ?? ?? ?? ?? ?? 88 5D ?? 8A + 45 ?? 30 44 0D ?? 41 83 F9 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? 88 5D ?? + E8 ?? ?? ?? ?? 59 5E 5B 8B E5 5D C3 + } + $find_folders = { + 55 8B EC 83 EC ?? 53 56 6A ?? 59 E8 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? 33 DB 8B F0 66 + C7 45 ?? ?? ?? 89 35 ?? ?? ?? ?? 8B CB 0F 11 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 66 C7 45 ?? ?? ?? 88 5D ?? 8A 45 ?? 30 44 0D ?? 41 83 F9 ?? 72 ?? 8D 45 ?? + 88 5D ?? 50 8D 55 ?? 8B CE E8 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? B0 ?? 59 B1 ?? 88 5D + ?? 32 C1 88 4D ?? 88 45 ?? 8B CB 0F 11 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? 66 C7 45 ?? ?? ?? 8A 45 ?? 30 44 0D ?? 41 83 F9 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 + ?? 50 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 B1 ?? 88 5D ?? B0 ?? 88 4D ?? 32 C1 C7 45 + ?? ?? ?? ?? ?? 88 45 ?? B2 ?? C7 45 ?? ?? ?? ?? ?? 8B CB 66 C7 45 ?? ?? ?? 88 5D ?? + 8D 04 0A 30 44 0D ?? 41 83 F9 ?? 73 ?? 8A 55 ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 + 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 B1 ?? 88 5D ?? B0 ?? 88 4D ?? 32 C1 C7 45 ?? ?? + ?? ?? ?? 88 45 ?? 8B C3 C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 88 5D ?? 80 44 05 ?? + ?? 40 83 F8 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? E8 ?? ?? ?? ?? 59 66 C7 + 45 ?? ?? ?? 8B C3 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 80 44 + 05 ?? ?? 40 83 F8 ?? 72 ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D 55 ?? E8 ?? ?? ?? ?? 59 + 66 C7 45 ?? ?? ?? B1 ?? C7 45 ?? ?? ?? ?? ?? 8B C3 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 66 C7 45 ?? ?? ?? 30 4C 05 ?? 40 83 F8 ?? 73 ?? 8A 4D ?? EB ?? 8B 0D ?? ?? + ?? ?? 8D 45 ?? 50 8D 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 66 C7 45 ?? ?? ?? B2 ?? C7 45 + ?? ?? ?? ?? ?? 8B CB C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 8D + 04 0A 30 44 0D ?? 41 83 F9 ?? 73 ?? 8A 55 ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 45 ?? 50 8D + 55 ?? 88 5D ?? E8 ?? ?? ?? ?? 59 5E 5B 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($enumerate_resources and $enumerate_files and $encrypt_files and $remote_connection_1) + uint16(0)==0x5A4D and ($find_folders and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*))) } -rule REVERSINGLABS_Win32_Ransomware_Hakunamatata : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Sanwai : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects HakunaMatata ransomware." + description = "Yara rule that detects Sanwai ransomware." author = "ReversingLabs" - id = "17438fcd-7a51-5fb6-96ac-38523bc1744f" - date = "2020-11-11" - modified = "2020-11-11" + id = "01912621-4a34-5e34-8542-5b561e8da567" + date = "2021-11-11" + modified = "2021-11-11" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.HakunaMatata.yara#L1-L373" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "e363ff93fce286d60a3f5ea20ba3ec03564b7a5321c3f6448cc82187f23e8a9f" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Sanwai.yara#L1-L71" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "a7a95b2403fe539dce0d856cc1c04d15440677ea39c0a22e818b42333a64e92c" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -30820,717 +32337,914 @@ rule REVERSINGLABS_Win32_Ransomware_Hakunamatata : TC_DETECTION MALICIOUS MALWAR sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "HakunaMatata" + tc_detection_name = "Sanwai" tc_detection_factor = 5 importance = 25 strings: + $find_files = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? + 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 55 ?? 8B D9 83 7B ?? ?? 8B F3 8B 45 ?? 8B 7D + ?? 89 45 ?? 72 ?? 8B 33 8D 4E ?? 66 8B 06 83 C6 ?? 66 85 C0 75 ?? 2B F1 D1 FE 0F 84 + ?? ?? ?? ?? 3B 73 ?? 0F 85 ?? ?? ?? ?? 88 45 ?? 8D 55 ?? FF 75 ?? 8D 4D ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? C7 45 ?? ?? ?? ?? + ?? 50 8B CB E8 ?? ?? ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B + C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 ?? FF 15 ?? + ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7B ?? ?? 72 ?? 8B 1B 8B 75 ?? 57 56 53 E8 + ?? ?? ?? ?? 85 C0 75 ?? 8B 36 8B CF E8 ?? ?? ?? ?? 84 C0 74 ?? 57 56 E8 ?? ?? ?? ?? + 85 C0 75 ?? 8B CF E8 ?? ?? ?? ?? 84 C0 75 ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 + 5F 5E 5B 8B E5 5D C3 83 F8 ?? 75 ?? 8B 4D ?? D1 E9 F6 C1 ?? B9 ?? ?? ?? ?? 0F 45 C1 + 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C3 B8 ?? ?? ?? ?? 8B 4D ?? 64 89 + 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C3 + } + $import_key = { + 8D 44 24 ?? 50 6A ?? 6A ?? 6A ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 5E 85 + C0 75 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 32 C0 5F 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? + 83 C4 ?? C3 8B 44 24 ?? FF 74 24 ?? 8B 08 8B 40 ?? 89 47 ?? 8D 44 24 ?? 50 57 6A ?? + 6A ?? 6A ?? FF 74 24 ?? 89 0F FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 6A ?? + FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? B0 ?? 5F 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C3 + } $encrypt_files = { - 55 89 E5 57 56 53 81 EC ?? ?? ?? ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? - 85 C0 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 89 14 24 89 C1 E8 ?? - ?? ?? ?? 83 EC ?? 84 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? 83 7D ?? - ?? 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B - 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 - EC ?? 85 C0 0F 95 C0 84 C0 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 89 45 ?? 89 55 ?? 8B - 45 ?? 8B 40 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 50 ?? 8B 45 ?? 89 54 24 - ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 50 ?? 89 D0 C1 E0 ?? - 01 D0 01 C0 89 45 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? C7 44 24 ?? ?? ?? ?? - ?? 8D 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 - A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 0F 94 C0 84 C0 74 ?? C7 45 ?? ?? ?? ?? ?? E9 ?? - ?? ?? ?? 8B 45 ?? 8B 40 ?? BA ?? ?? ?? ?? 8B 4D ?? 8B 5D ?? 39 DA 72 ?? 39 DA 77 ?? - 39 C8 76 ?? 89 C8 89 DA 89 45 ?? 8B 55 ?? 8B 45 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 4D ?? - 89 4C 24 ?? 89 54 24 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? - 83 F8 ?? 0F 94 C0 84 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B 45 ?? 89 4C 24 ?? 89 - 54 24 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 C6 8B 45 ?? 89 C1 BB - ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 89 CF 31 C7 89 7D ?? 89 DF 31 D7 89 7D ?? 8B 45 ?? 0B - 45 ?? 85 C0 0F 94 C0 0F B6 C8 8B 55 ?? 8B 45 ?? 89 44 24 ?? 8D 45 ?? 89 44 24 ?? 89 - F0 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 14 24 - A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? A1 ?? ?? ?? ?? FF D0 89 45 ?? 8B 45 ?? 85 C0 - 79 ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? C7 44 24 ?? ?? ?? ?? ?? - 8D 4D ?? 89 4C 24 ?? 89 54 24 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 - 83 EC ?? 85 C0 0F 94 C0 84 C0 74 ?? C7 45 ?? ?? ?? ?? ?? 90 EB ?? 8B 4D ?? 8B 5D ?? - 8B 45 ?? BA ?? ?? ?? ?? 29 C1 19 D3 89 C8 89 DA 89 45 ?? 89 55 ?? 8B 45 ?? BA ?? ?? - ?? ?? 01 45 ?? 11 55 ?? 8B 45 ?? 8B 55 ?? 89 C6 83 F6 ?? 89 75 ?? 89 D0 80 F4 ?? 89 - 45 ?? 8B 55 ?? 8B 4D ?? 89 C8 09 D0 85 C0 74 ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - 8B 45 ?? 85 C0 74 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 74 ?? 8B 45 ?? - 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 - 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? - ?? EB ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 - EC ?? 8B 45 ?? 8D 65 ?? 5B 5E 5F 5D C2 - } - $encrypt_files_2 = { - 55 89 E5 56 53 81 EC ?? ?? ?? ?? 89 4D ?? 8B 45 ?? 89 85 ?? ?? ?? ?? 8B 45 ?? 89 85 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? 85 C0 0F 84 ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 89 04 24 89 D1 E8 ?? ?? ?? ?? 83 EC ?? 84 C0 0F 84 ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 - 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF - D0 83 EC ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 89 - 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 0F 95 C0 84 C0 0F 84 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 89 45 ?? 89 55 ?? 8B 45 ?? 8B 55 ?? 89 45 ?? 89 55 ?? - 8B 85 ?? ?? ?? ?? 80 F4 ?? 89 C3 8B 85 ?? ?? ?? ?? 80 F4 ?? 89 C6 89 F0 09 D8 85 C0 - 74 ?? 8B 45 ?? 8B 55 ?? 3B 95 ?? ?? ?? ?? 72 ?? 3B 95 ?? ?? ?? ?? 77 ?? 3B 85 ?? ?? - ?? ?? 76 ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 45 ?? 89 55 ?? 8B 45 ?? 8B 40 ?? - 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 40 ?? 8B 55 ?? 89 44 24 ?? C7 44 24 ?? - ?? ?? ?? ?? 89 14 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 50 ?? 89 D0 C1 E0 ?? 01 D0 01 C0 89 - 45 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 - 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? - FF D0 83 EC ?? 85 C0 0F 94 C0 84 C0 74 ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 - ?? 8B 40 ?? BA ?? ?? ?? ?? 8B 4D ?? 8B 5D ?? 39 DA 72 ?? 39 DA 77 ?? 39 C8 76 ?? 89 - C8 89 DA 89 45 ?? 8B 4D ?? 8B 55 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 89 - 4C 24 ?? 89 54 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 83 F8 ?? 0F 94 - C0 84 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B 45 ?? 89 4C 24 ?? 89 54 24 ?? 89 04 - 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 C1 BB ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? - 89 CE 31 C6 89 B5 ?? ?? ?? ?? 89 DE 31 D6 89 B5 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B B5 - ?? ?? ?? ?? 89 D8 09 F0 85 C0 0F 94 C0 88 45 ?? 8B 55 ?? 0F B6 4D ?? 8B 5D ?? 8B 45 - ?? 89 44 24 ?? 8D 45 ?? 89 44 24 ?? 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? - C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? A1 ?? ?? ?? - ?? FF D0 89 45 ?? 8B 45 ?? 85 C0 79 ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 4D ?? - 8B 55 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 8B 45 - ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 0F 94 C0 84 C0 74 ?? C7 45 ?? ?? ?? - ?? ?? 90 EB ?? 8B 4D ?? 8B 5D ?? 8B 45 ?? BA ?? ?? ?? ?? 29 C1 19 D3 89 C8 89 DA 89 - 45 ?? 89 55 ?? 8B 45 ?? BA ?? ?? ?? ?? 01 45 ?? 11 55 ?? 8B 45 ?? 8B 55 ?? 89 C6 83 - F6 ?? 89 B5 ?? ?? ?? ?? 89 D0 80 F4 ?? 89 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B B5 ?? - ?? ?? ?? 89 F0 09 D8 85 C0 74 ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 80 F4 ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 80 F4 ?? 89 85 ?? ?? ?? ?? 8B 9D ?? - ?? ?? ?? 8B B5 ?? ?? ?? ?? 89 F0 09 D8 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 2B - 45 ?? 1B 55 ?? 89 45 ?? 89 55 ?? 8B 45 ?? 8B 40 ?? 89 C1 BB ?? ?? ?? ?? 8B 45 ?? 8B - 55 ?? 39 D3 72 ?? 39 D3 77 ?? 39 C1 76 ?? 89 C1 89 D3 89 4D ?? 8B 45 ?? C7 44 24 ?? - ?? ?? ?? ?? 8D 55 ?? 89 54 24 ?? 8B 55 ?? 89 54 24 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 - A1 ?? ?? ?? ?? FF D0 83 EC ?? 83 F8 ?? 0F 94 C0 84 C0 0F 84 ?? ?? ?? ?? 8B 55 ?? 8B - 45 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 4D ?? 89 4C 24 ?? 89 54 24 ?? 89 44 24 ?? 8B 45 ?? - 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 0F 94 C0 84 C0 74 ?? C7 45 ?? ?? ?? ?? - ?? EB ?? 8B 45 ?? 8B 55 ?? 8B 4D ?? BB ?? ?? ?? ?? 29 C8 19 DA 89 45 ?? 89 55 ?? 8B - 45 ?? 8B 55 ?? 89 C3 80 F7 ?? 89 9D ?? ?? ?? ?? 89 D0 80 F4 ?? 89 85 ?? ?? ?? ?? 8B - 9D ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 89 F0 09 D8 85 C0 74 ?? E9 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 8B 45 ?? 85 C0 74 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 74 ?? - 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B - 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 89 04 24 E8 - ?? ?? ?? ?? EB ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? - FF D0 83 EC ?? 8B 45 ?? 8D 65 ?? 5B 5E 5D C2 - } - $search_files = { - E8 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 95 C0 88 45 ?? 80 7D ?? ?? 74 ?? C7 44 24 ?? ?? ?? - ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? - 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? 83 45 ?? ?? EB ?? A1 ?? - ?? ?? ?? FF D0 89 C3 C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 - 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? 89 1C 24 89 C1 E8 ?? ?? ?? ?? 83 EC - ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 - ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? 8B 45 ?? 89 - C1 E8 ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 89 D9 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - 89 1C 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 85 C0 74 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 - ?? ?? ?? ?? 90 8D 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 89 C1 - E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? EB ?? 90 8D 85 - ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 0F 95 - C0 84 C0 74 ?? E9 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? - ?? ?? A1 ?? ?? ?? ?? FF D0 89 C3 C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? 89 1C 24 89 C1 E8 ?? ?? - ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? - ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? C7 - 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? BB ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 - ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 83 7D ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 05 ?? - ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 85 C0 74 ?? B8 ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? 84 C0 - 74 ?? 8D 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 89 C2 8B 85 ?? ?? ?? ?? 89 14 24 89 C1 - E8 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 89 C2 8B 45 ?? 89 04 24 89 D1 E8 ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 - ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? - ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 - } - $search_files_2 = { - FF 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 89 C3 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 50 ?? 81 C2 ?? ?? ?? ?? 8B 42 ?? - 83 E0 ?? 83 C8 ?? 89 42 ?? 89 1C 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 89 C3 8B - 00 89 DA 03 50 ?? 8B 42 ?? 83 E0 ?? 83 C8 ?? 89 42 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? - ?? ?? 89 C1 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 FF 15 ?? ?? ?? - ?? 83 EC ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 83 BB ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? - 89 04 24 89 D9 E8 ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 - ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 - 04 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 89 04 24 E8 ?? ?? ?? ?? 89 C1 E8 ?? ?? - ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 EC ?? 89 04 24 E8 ?? ?? ?? ?? 89 C1 E8 - } - $remote_connection = { - 55 89 E5 53 81 EC ?? ?? ?? ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 89 44 24 ?? C7 - 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F0 ?? 84 C0 0F 85 ?? ?? ?? ?? 8D 45 ?? 89 C1 E8 - ?? ?? ?? ?? 8B 45 ?? 8B 00 89 45 ?? 8D 45 ?? 89 44 24 ?? 8D 45 ?? 89 44 24 ?? 8D 45 - ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? - 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 89 45 ?? 83 7D ?? ?? 74 ?? 81 7D ?? ?? ?? - ?? ?? 75 ?? 8B 45 ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 39 45 ?? 77 ?? 8D 45 ?? - 89 C1 E8 ?? ?? ?? ?? 8B 45 ?? 8B 10 8D 45 ?? 8D 4D ?? 89 4C 24 ?? 89 14 24 89 C1 E8 - ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8D 50 ?? 8D 45 ?? 89 04 24 89 D1 E8 ?? ?? ?? ?? 83 EC - ?? 8D 45 ?? 89 C1 E8 ?? ?? ?? ?? 8D 45 ?? 89 C1 E8 ?? ?? ?? ?? 83 45 ?? ?? 83 45 ?? - ?? EB ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 81 7D ?? ?? ?? ?? ?? 75 ?? E9 ?? - ?? ?? ?? 8D 45 ?? 83 C0 ?? 89 C1 E8 ?? ?? ?? ?? 85 C0 0F 95 C0 84 C0 74 ?? 8B 45 ?? - 05 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 50 ?? 8D 45 ?? 89 04 24 89 D1 E8 - ?? ?? ?? ?? 83 EC ?? 8B 45 ?? 05 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 90 8D 45 ?? 89 - C1 E8 ?? ?? ?? ?? EB ?? 89 C3 8D 45 ?? 89 C1 E8 ?? ?? ?? ?? EB ?? 89 C3 8D 45 ?? 89 - C1 E8 ?? ?? ?? ?? EB ?? 89 C3 8D 45 ?? 89 C1 E8 ?? ?? ?? ?? 89 D8 89 04 24 E8 ?? ?? - ?? ?? 90 8B 5D ?? C9 C2 - } - $remote_connection_2 = { - 55 89 E5 57 56 53 83 EC ?? 89 4D ?? 8B 5D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 45 ?? 89 44 24 ?? C7 04 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 8B 03 89 45 ?? EB ?? 83 EC ?? 89 45 ?? 85 C0 74 ?? 3D ?? ?? - ?? ?? 74 ?? 81 7D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 8D 45 ?? 89 - 44 24 ?? 8D 45 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? C7 44 24 - ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? EB ?? 8B 45 ?? 89 45 ?? 83 7D ?? ?? - 74 ?? BE ?? ?? ?? ?? 8D 7D ?? EB ?? 83 EC ?? 8D 45 ?? 89 04 24 8D 4D ?? E8 ?? ?? ?? - ?? 83 EC ?? 8B 45 ?? 39 F8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 83 C6 ?? 39 75 ?? 72 ?? 8B - 45 ?? 8B 5C B0 ?? 89 7D ?? B8 ?? ?? ?? ?? 85 DB 74 ?? 89 1C 24 E8 ?? ?? ?? ?? 8D 04 - 43 C6 44 24 ?? ?? 89 44 24 ?? 89 1C 24 8D 4D ?? E8 ?? ?? ?? ?? EB ?? 8B 45 ?? 89 04 - 24 E8 ?? ?? ?? ?? 83 EC ?? E9 ?? ?? ?? ?? 8B 45 ?? 2B 45 ?? C1 F8 ?? 69 C0 ?? ?? ?? - ?? 85 C0 74 ?? 8B 7D ?? 8D 9F ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 47 ?? 3B 47 ?? - 74 ?? 85 C0 74 ?? 8B 55 ?? 89 10 8D 48 ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? - 8B 45 ?? 83 40 ?? ?? 89 1C 24 E8 ?? ?? ?? ?? EB ?? 8B 4D ?? 83 C1 ?? 8D 45 ?? 89 04 - 24 E8 ?? ?? ?? ?? 83 EC ?? EB ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 65 ?? 5B 5E 5F 5D C2 - } - $encrypt_files_3 = { - 55 57 56 53 83 EC ?? 8B 41 ?? 85 C0 75 ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? - ?? BE ?? ?? ?? ?? 89 F0 83 C4 ?? 5B 5E 5F 5D C2 ?? ?? 89 CB C7 44 24 ?? ?? ?? ?? ?? - 8D 54 24 ?? 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 FF - 15 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C7 BE ?? ?? - ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? - ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C2 89 44 24 ?? - 83 F8 ?? 74 ?? 8D 44 24 ?? 89 44 24 ?? 89 14 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C6 85 - C0 75 ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 3C 24 FF 15 ?? ?? ?? ?? - 83 EC ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 85 F6 0F 84 ?? ?? ?? ?? 8B - 84 24 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 8B 54 24 ?? 89 44 24 ?? 89 54 24 ?? 8B 43 ?? 89 04 - 24 E8 ?? ?? ?? ?? 89 44 24 ?? 8B 73 ?? 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 - E8 ?? ?? ?? ?? 8D 04 B6 01 C0 89 44 24 ?? 89 04 24 E8 ?? ?? ?? ?? 89 C5 C7 44 24 ?? - ?? ?? ?? ?? 8D 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 - 44 24 ?? 89 3C 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 - ?? 8B 54 24 ?? 8B 0D ?? ?? ?? ?? 89 4C 24 ?? 89 7C 24 ?? 89 C6 89 D7 89 5C 24 ?? E9 - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 89 44 24 ?? 89 5C 24 ?? 8B 44 24 ?? - 89 44 24 ?? 8B 4C 24 ?? 89 0C 24 FF 54 24 ?? 83 EC ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 89 - 5C 24 ?? 8B 44 24 ?? 89 44 24 ?? 89 2C 24 E8 ?? ?? ?? ?? 89 5C 24 ?? 89 5C 24 ?? C7 - 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8D 44 24 ?? 89 44 24 ?? 89 6C 24 ?? C7 - 44 24 ?? ?? ?? ?? ?? 89 DA 31 F2 09 FA 0F 94 C0 0F B6 C0 89 44 24 ?? C7 44 24 ?? ?? - ?? ?? ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C3 FF 15 ?? ?? ?? ?? 85 - C0 78 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? 89 - 6C 24 ?? 8B 4C 24 ?? 89 0C 24 FF 15 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? 2B 74 24 ?? 1B - 7C 24 ?? 89 FA 09 F2 74 ?? 8B 44 24 ?? 8B 58 ?? B8 ?? ?? ?? ?? 39 F8 0F 82 ?? ?? ?? - ?? 39 F3 0F 47 DE E9 ?? ?? ?? ?? 8B 7C 24 ?? 89 DE EB ?? 8B 7C 24 ?? BE ?? ?? ?? ?? - 85 ED 74 ?? 89 2C 24 E8 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 0F 84 ?? ?? ?? ?? 89 04 24 E8 - ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 7C 24 ?? BE ?? ?? ?? ?? EB - } - $encrypt_files_4 = { - FF 15 ?? ?? ?? ?? 83 EC ?? 89 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 - 34 24 89 54 24 ?? 89 44 24 ?? 89 4C 24 ?? FF 95 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 84 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 29 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 19 95 ?? ?? ?? ?? 8B - 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 D0 89 CA 09 C2 0F 84 ?? ?? ?? ?? 31 D2 3B 95 ?? - ?? ?? ?? 8B 43 ?? 89 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 72 ?? 77 ?? 8B 8D ?? ?? ?? ?? - 39 C8 76 ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 89 44 24 ?? 8D 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 89 54 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? - 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 89 04 24 E8 ?? ?? ?? ?? 89 34 24 8B 35 ?? ?? ?? ?? FF D6 8B 85 ?? ?? ?? ?? 83 EC - ?? 89 04 24 FF D6 8B 85 ?? ?? ?? ?? 83 EC ?? 89 04 24 FF 15 ?? ?? ?? ?? 8B 8D ?? ?? - ?? ?? 83 EC ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 - 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? C7 04 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 40 ?? 8B 88 ?? ?? ?? ?? 85 C9 74 ?? 8B 01 C7 - 04 24 ?? ?? ?? ?? FF 50 ?? 83 EC ?? 0F B7 C0 B9 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? - 83 EC ?? 89 C1 E8 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 89 04 24 FF 15 - } - $search_files_3 = { - FF 15 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 75 ?? 8B 85 - ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 FF D7 83 - EC ?? 85 C0 0F 84 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? EB ?? 90 8D B4 26 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 83 C3 ?? 8B 50 ?? 8B 40 ?? 89 85 ?? ?? ?? ?? 29 D0 C1 F8 ?? 69 C0 ?? - ?? ?? ?? 39 C3 0F 83 ?? ?? ?? ?? 8D 04 5B 8D 34 C5 ?? ?? ?? ?? 8B 04 C2 89 44 24 ?? - 8B 85 ?? ?? ?? ?? 89 04 24 FF D7 83 EC ?? 85 C0 74 ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? 8B - 1C 30 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? C7 04 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 5C - 24 ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 40 ?? 8B 88 - ?? ?? ?? ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 01 C7 04 24 ?? ?? ?? ?? FF 50 ?? 83 EC ?? 0F - B7 C0 B9 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 89 C1 E8 ?? ?? ?? ?? 31 F6 E9 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 - ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 89 5C 24 - ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? E9 ?? ?? ?? ?? 90 8D 74 26 ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 - E8 - } - $install_service = { - FF 15 ?? ?? ?? ?? 83 EC ?? 85 C0 89 C1 89 44 24 ?? 0F 84 ?? ?? ?? ?? 8B 84 24 ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 0C 24 89 44 24 ?? FF 15 ?? ?? ?? ?? 83 EC ?? 85 C0 - 89 C3 0F 84 ?? ?? ?? ?? 89 04 24 A1 ?? ?? ?? ?? 8D 6C 24 ?? 8D 7C 24 ?? C7 44 24 ?? - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 6C 24 ?? 89 7C 24 ?? 89 44 24 ?? FF D0 83 EC - ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 83 E0 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? A1 ?? ?? - ?? ?? 89 44 24 ?? FF D0 8B 74 24 ?? 89 44 24 ?? 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? B8 - ?? ?? ?? ?? F7 64 24 ?? B8 ?? ?? ?? ?? C1 EA ?? 81 FA ?? ?? ?? ?? 0F 47 D0 B8 ?? ?? - ?? ?? 81 FA ?? ?? ?? ?? 0F 42 D0 89 14 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 6C 24 ?? C7 - 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 FF 54 24 ?? 83 EC - ?? 85 C0 74 ?? 3B 74 24 ?? 8B 44 24 ?? 72 ?? FF D0 2B 44 24 ?? 3B 44 24 ?? 76 ?? 89 - 1C 24 8B 1D ?? ?? ?? ?? FF D3 83 EC ?? 8B 44 24 ?? 89 04 24 FF D3 83 EC ?? 83 C4 ?? - 5B 5E 5F 5D C2 ?? ?? 8D B4 26 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 - EC ?? 83 C4 ?? 5B 5E 5F 5D C2 ?? ?? 8D B6 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? 89 1C 24 FF 15 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? 89 6C 24 ?? C7 44 - 24 ?? ?? ?? ?? ?? 89 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 FF 54 24 ?? 83 EC ?? - 85 C0 0F 84 ?? ?? ?? ?? 8D B6 ?? ?? ?? ?? 8B 44 24 ?? FF D0 8B 74 24 ?? 89 44 24 ?? - 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? F7 64 24 ?? B8 ?? ?? ?? ?? C1 EA ?? - 81 FA ?? ?? ?? ?? 0F 47 D0 B8 ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 0F 42 D0 89 14 24 FF 15 - ?? ?? ?? ?? 83 EC ?? 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? C7 44 24 ?? ?? - ?? ?? ?? 89 1C 24 FF 54 24 ?? 83 EC ?? 85 C0 0F 84 ?? ?? ?? ?? 3B 74 24 ?? 72 ?? 8B - 44 24 ?? FF D0 2B 44 24 ?? 3B 44 24 ?? 76 ?? E9 - } - $encrypt_files_5 = { - FF 15 ?? ?? ?? ?? 83 EC ?? 89 C7 BE ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 FF - 15 ?? ?? ?? ?? 83 EC ?? 89 C2 89 44 24 ?? 83 F8 ?? 74 ?? 8D 44 24 ?? 89 44 24 ?? 89 - 14 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C6 85 C0 75 ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? - ?? ?? 83 EC ?? 89 3C 24 FF 15 ?? ?? ?? ?? 83 EC ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? - ?? ?? 83 EC ?? 85 F6 0F 84 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? - E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 8B 54 24 - ?? 89 44 24 ?? 89 54 24 ?? 8B 43 ?? 89 04 24 E8 ?? ?? ?? ?? 89 44 24 ?? 8B 73 ?? 89 - 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D 04 B6 01 C0 89 44 24 ?? - 89 04 24 E8 ?? ?? ?? ?? 89 C5 C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 89 44 24 ?? C7 44 - 24 ?? ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 89 3C 24 FF 15 ?? ?? ?? ?? 83 EC - ?? 89 C6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 8B 54 24 ?? 8B 0D ?? ?? ?? ?? 89 4C 24 - ?? 89 7C 24 ?? 89 C6 89 D7 89 5C 24 ?? E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 - 24 ?? 89 44 24 ?? 89 5C 24 ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 0C 24 FF 54 24 - ?? 83 EC ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 89 5C 24 ?? 8B 44 24 ?? 89 44 24 ?? 89 2C 24 - E8 ?? ?? ?? ?? 89 5C 24 ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 - ?? 8D 44 24 ?? 89 44 24 ?? 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 DA 31 F2 09 FA 0F - 94 C0 0F B6 C0 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? - ?? ?? 83 EC ?? 89 C3 FF 15 ?? ?? ?? ?? 85 C0 78 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 - ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? 89 6C 24 ?? 8B 4C 24 ?? 89 0C 24 FF 15 - } - $search_files_4 = { - FF 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 89 C3 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 50 ?? 81 C2 ?? ?? ?? ?? 8B 42 ?? - 83 E0 ?? 83 C8 ?? 89 42 ?? 89 1C 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 89 C3 8B - 00 89 DA 03 50 ?? 8B 42 ?? 83 E0 ?? 83 C8 ?? 89 42 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? - ?? ?? 89 C1 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 FF 15 ?? ?? ?? - ?? 83 EC ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 83 BB ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? - 89 04 24 89 D9 E8 ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 - ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 - 04 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 89 04 24 E8 ?? ?? ?? ?? 89 C1 E8 ?? ?? - ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 EC ?? 89 04 24 E8 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 3B BD ?? - ?? ?? ?? 75 ?? EB ?? 83 EC ?? 83 C7 ?? 39 BD ?? ?? ?? ?? 74 ?? 8B 45 ?? 89 44 24 ?? - 89 3C 24 89 D9 E8 ?? ?? ?? ?? EB ?? BE ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? - ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 8D 95 ?? ?? ?? ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 - ?? ?? ?? ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 89 F0 8D 65 ?? 5B 5E 5F 5D C2 - } - $remote_connection_3 = { - 55 89 E5 57 56 53 83 EC ?? 89 4D ?? 8B 5D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 45 ?? 89 44 24 ?? C7 04 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 8B 03 89 45 ?? EB ?? 83 EC ?? 89 45 ?? 85 C0 74 ?? 3D ?? ?? - ?? ?? 74 ?? 81 7D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 8D 45 ?? 89 - 44 24 ?? 8D 45 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? C7 44 24 - ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? EB ?? 8B 45 ?? 89 45 ?? 83 7D ?? ?? - 74 ?? BE ?? ?? ?? ?? 8D 7D ?? EB ?? 83 EC ?? 8D 45 ?? 89 04 24 8D 4D ?? E8 ?? ?? ?? - ?? 83 EC ?? 8B 45 ?? 39 F8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 83 C6 ?? 39 75 ?? 72 ?? 8B - 45 ?? 8B 5C B0 ?? 89 7D ?? B8 ?? ?? ?? ?? 85 DB 74 ?? 89 1C 24 E8 ?? ?? ?? ?? 8D 04 - 43 C6 44 24 ?? ?? 89 44 24 ?? 89 1C 24 8D 4D ?? E8 ?? ?? ?? ?? EB ?? 8B 45 ?? 89 04 - 24 E8 ?? ?? ?? ?? 83 EC ?? E9 ?? ?? ?? ?? 8B 45 ?? 2B 45 ?? C1 F8 ?? 69 C0 ?? ?? ?? - ?? 85 C0 74 ?? 8B 7D ?? 8D 9F ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 47 ?? 3B 47 ?? - 74 ?? 85 C0 74 ?? 8B 55 ?? 89 10 8D 48 ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? - 8B 45 ?? 83 40 ?? ?? 89 1C 24 E8 ?? ?? ?? ?? EB ?? 8B 4D ?? 83 C1 ?? 8D 45 ?? 89 04 - 24 E8 ?? ?? ?? ?? 83 EC ?? EB ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 65 ?? 5B 5E 5F 5D C2 ?? - ?? 89 C3 8B 45 ?? 8D 55 ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? 89 1C 24 E8 ?? ?? ?? ?? 89 C3 EB ?? 53 83 EC ?? 8B 5C 24 ?? 8D 43 ?? 89 04 24 8B - 0B E8 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? C7 04 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 83 C4 ?? 5B C3 + 8B 01 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EE ?? 73 ?? 8A 01 3A 02 75 ?? 83 FE ?? 74 ?? + 8A 41 ?? 3A 42 ?? 75 ?? 8A 41 ?? 3A 42 ?? 75 ?? 8A 41 ?? 3A 42 ?? 75 ?? 33 C0 EB ?? + 1B C0 83 C8 ?? 85 C0 75 ?? 8B 5D ?? 8B 7D ?? C6 85 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B + BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B CF E8 ?? ?? ?? ?? 51 C6 45 ?? ?? 8D 4D ?? 8B + 9D ?? ?? ?? ?? 51 83 CB ?? 8B C8 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 CB ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 83 CB ?? 83 7D ?? ?? 89 9D ?? ?? ?? ?? 0F 43 4D ?? 83 + 7D ?? ?? 89 9D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 8B 01 3B + 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EE ?? 73 ?? 8A 01 3A 02 75 ?? 83 FE ?? 74 ?? 8A 41 ?? + 3A 42 ?? 75 ?? 8A 41 ?? 3A 42 ?? 75 ?? 8A 41 ?? 3A 42 ?? 75 ?? 33 C0 EB ?? 1B C0 83 + C8 ?? 85 C0 75 ?? 8B 5D ?? 8B 7D ?? C6 85 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 45 ?? 8B + CF 50 E8 ?? ?? ?? ?? 51 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 51 83 CB ?? 8B C8 89 9D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 7D ?? 8D 4D ?? 81 CB ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 8B 5D ?? + 83 FB ?? 0F 43 CF 83 7D ?? ?? 0F 85 } condition: - uint16(0)==0x5A4D and (($search_files and $encrypt_files and $remote_connection) or ($encrypt_files_2 and $remote_connection and $search_files) or ($search_files_2 and $encrypt_files_3 and $remote_connection_2) or ($install_service and $search_files_3 and $encrypt_files_4) or ($search_files_4 and $encrypt_files_5 and $remote_connection_3)) + uint16(0)==0x5A4D and ($find_files) and ($import_key) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Shadowcryptor : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Gandcrab : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects ShadowCryptor ransomware." + description = "Yara rule that detects GandCrab ransomware." author = "ReversingLabs" - id = "983e8927-4829-540f-9697-886226fd54ce" - date = "2021-02-11" - modified = "2021-02-11" + id = "a09ed7e6-f3a6-5f44-9d5b-a9c529cf1190" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.ShadowCryptor.yara#L1-L89" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "875150db9fc36cd992988bba7d0c05487418b901980bf428ebd427c82fbcacd7" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.GandCrab.yara#L1-L892" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "79381635681482fc90defe4e10e97bf16d534837518fc06ae579822e9d77b461" score = 75 - quality = 90 + quality = 88 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" status = "RELEASED" sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "ShadowCryptor" + tc_detection_name = "GandCrab" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 8D 45 ?? 83 7D ?? ?? 0F 57 C0 66 0F 13 85 ?? ?? ?? ?? 0F 43 45 ?? 50 8D 85 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B - BD ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? EB ?? - 8D A4 24 ?? ?? ?? ?? 90 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D3 85 C0 0F 84 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D3 85 C0 0F 84 ?? ?? ?? ?? 33 C0 83 7D - ?? ?? 66 89 85 ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 85 - ?? ?? ?? ?? 83 F8 ?? 74 ?? A8 ?? 74 ?? 50 8D 85 ?? ?? ?? ?? 50 51 8B 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? EB ?? 51 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 51 8B 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 83 C7 ?? 83 D6 ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 - 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D6 8B C7 8B 4D ?? 64 89 0D ?? ?? - ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 + $remote_connection = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B F9 89 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? 85 DB 74 ?? 33 C0 + 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? + 57 FF 15 ?? ?? ?? ?? 8D 4D ?? 8D 34 45 ?? ?? ?? ?? 8D 46 ?? 50 E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 56 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? + 8B D8 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 89 45 ?? FF D6 57 53 FF D6 + 6A ?? 59 BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 A5 8B 35 ?? ?? ?? ?? 53 FF D6 33 FF 8D + 85 ?? ?? ?? ?? 21 BD ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 83 EC ?? + FF 75 ?? 53 FF D6 8B 75 ?? 8D 4D ?? 50 53 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 85 + C0 74 ?? 47 83 7D ?? ?? 74 ?? 8B 4D ?? 8D 55 ?? 83 65 ?? ?? E8 ?? ?? ?? ?? 85 C0 74 + ?? 8B 45 ?? 85 C0 74 ?? 8B 4D ?? 89 01 EB ?? 33 FF 68 ?? ?? ?? ?? 6A ?? 56 FF 15 ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? + FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 } - $encrypt_files = { - 55 8B EC 83 E4 ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? - 33 C4 89 44 24 ?? 53 56 57 A1 ?? ?? ?? ?? 33 C4 50 8D 44 24 ?? 64 A3 ?? ?? ?? ?? 8B - F1 8D 46 ?? 50 8D 4E ?? E8 ?? ?? ?? ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? - ?? ?? ?? 66 89 44 24 ?? 89 44 24 ?? 39 46 ?? 0F 84 ?? ?? ?? ?? 8D A4 24 ?? ?? ?? ?? - 80 7E ?? ?? 0F 85 ?? ?? ?? ?? 51 8D 44 24 ?? 50 8D 44 24 ?? 50 8D 4E ?? E8 ?? ?? ?? - ?? 8B C8 E8 ?? ?? ?? ?? 8B D0 8B 02 85 C0 74 ?? 8B 00 8B 48 ?? 8B 40 ?? 49 23 4A ?? - 8B 04 88 8D 4C 24 ?? 3B C8 74 ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 46 ?? 8B 4E ?? 48 - 03 C8 8B 46 ?? 48 23 C8 8B 46 ?? 8B 3C 88 83 7F ?? ?? 72 ?? FF 37 E8 ?? ?? ?? ?? 83 - C4 ?? 33 C0 C7 47 ?? ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 66 89 07 FF 4E ?? 75 ?? 89 46 - ?? 83 EC ?? 8B CC 6A ?? 89 41 ?? 33 C0 C7 41 ?? ?? ?? ?? ?? 50 66 89 01 8D 44 24 ?? - 50 E8 ?? ?? ?? ?? 51 8B CE E8 ?? ?? ?? ?? 8B C8 0B CA 74 ?? 01 46 ?? 11 56 ?? 83 7C - 24 ?? ?? 8D 54 24 ?? 0F 43 54 24 ?? 83 EC ?? 8B FC 33 C0 C7 47 ?? ?? ?? ?? ?? C7 47 - ?? ?? ?? ?? ?? 66 89 07 66 39 02 74 ?? 8B C2 8D 48 ?? 89 4C 24 ?? 66 8B 08 83 C0 ?? - 66 85 C9 75 ?? 2B 44 24 ?? D1 F8 50 52 8B CF E8 ?? ?? ?? ?? 8B 4E ?? 83 79 ?? ?? 8D - 41 ?? 72 ?? 8B 00 8B 91 ?? ?? ?? ?? 81 C1 ?? ?? ?? ?? 83 79 ?? ?? 72 ?? 8B 09 50 E8 - ?? ?? ?? ?? 83 C4 ?? 83 7E ?? ?? 0F 85 ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? FF 74 24 ?? - E8 ?? ?? ?? ?? 83 C4 ?? 8B 4C 24 ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4C 24 ?? 33 - CC E8 ?? ?? ?? ?? 8B E5 5D C3 + $remote_connection_v2 = { + 55 8B EC 83 EC ?? 53 56 8B D9 89 55 ?? 57 8D 4D ?? 89 5D ?? E8 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 53 89 45 ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 3C 45 + ?? ?? ?? ?? 8D 47 ?? 50 6A ?? FF D6 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B D8 + FF D6 89 45 ?? 85 DB 74 ?? 8D 47 ?? 3B F8 73 ?? 8B F3 EB ?? 33 F6 FF 75 ?? 56 FF 15 + ?? ?? ?? ?? F3 0F 6F 05 ?? ?? ?? ?? 56 F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F + 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 + ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? FF + 15 ?? ?? ?? ?? 8D 45 ?? 33 FF 50 FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 68 ?? ?? ?? ?? 83 + EC ?? 68 ?? ?? ?? ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 50 56 8B 75 ?? 8D 4D ?? 68 ?? ?? + ?? ?? 56 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? BF ?? ?? ?? ?? 74 ?? 8B 4D ?? 8D 55 + ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 85 C0 74 ?? 8B 4D ?? 89 + 01 EB ?? 33 FF 68 ?? ?? ?? ?? 6A ?? 56 8B 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? 6A ?? + FF 75 ?? FF D6 68 ?? ?? ?? ?? 6A ?? 53 FF D6 8B 45 ?? 85 C0 74 ?? 50 FF 15 ?? ?? ?? + ?? 8B C7 5F 5E 5B 8B E5 5D C3 } - $terminate_antivirus_processes_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B D9 C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 33 C0 C7 43 ?? ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 66 89 03 89 - 45 ?? 50 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 + $crypt_files = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 51 33 C0 89 4C 24 ?? 40 8B DA 50 51 50 + 83 EC ?? 89 5C 24 ?? 50 51 50 51 50 51 50 51 50 83 EC ?? 50 51 50 8D 8C 24 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B 75 ?? 8B + F8 03 F3 8D 4E ?? 8D 0C CF C1 E1 ?? 51 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 04 B7 8D 04 C5 + ?? ?? ?? ?? 50 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B 75 ?? 89 44 24 ?? 8D 0C F5 ?? ?? ?? ?? + 51 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 0C DD ?? ?? ?? ?? 8B F8 51 8D 4C 24 ?? E8 ?? ?? ?? + ?? 8B D8 89 5C 24 ?? 85 FF 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 57 68 ?? ?? ?? ?? 56 FF + 75 ?? 8D 0C 36 8B 35 ?? ?? ?? ?? 89 4C 24 ?? FF D6 8B 4C 24 ?? 8D 04 09 89 44 24 ?? + 8D 44 24 ?? 50 53 68 ?? ?? ?? ?? 51 FF 74 24 ?? FF D6 53 8B 1D ?? ?? ?? ?? FF D3 57 + 8B F0 FF D3 83 C0 ?? 8D 4C 24 ?? 03 C6 50 E8 ?? ?? ?? ?? 57 FF D3 40 8D 4C 24 ?? 50 + E8 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? FF D3 40 8D 4C 24 ?? 50 E8 ?? ?? ?? ?? 33 F6 + 89 44 24 ?? 8B CE 57 89 4C 24 ?? FF D3 85 C0 74 ?? 8B 54 24 ?? 89 54 24 ?? 8B 44 24 + ?? 8A 0C 38 80 F9 ?? 74 ?? 80 F9 ?? 74 ?? 88 0A 42 89 54 24 ?? 40 57 89 44 24 ?? FF + D3 8B 4C 24 ?? 8B 54 24 ?? 3B C8 72 ?? 8B 7C 24 ?? 57 FF D3 85 C0 74 ?? 8B 4C 24 ?? + 89 4C 24 ?? 8A 04 3E 3C ?? 74 ?? 3C ?? 74 ?? 88 01 41 89 4C 24 ?? 57 46 FF D3 8B 4C + 24 ?? 3B F0 72 ?? 8B 7C 24 ?? 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D3 8B 35 ?? ?? + ?? ?? 57 FF D6 8D 4C 24 ?? 8D 3C 47 57 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D3 57 FF + D6 FF 74 24 ?? 8D 34 47 FF 15 ?? ?? ?? ?? 50 56 6A ?? FF 74 24 ?? 6A ?? 68 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D3 57 FF 15 ?? ?? ?? ?? FF 74 24 ?? 8D 34 + 47 FF 15 ?? ?? ?? ?? 50 56 6A ?? FF 74 24 ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 57 FF D3 8B 74 24 ?? 8B 1D ?? ?? ?? ?? 56 FF D3 C1 E0 ?? 8D 4C 24 ?? + 83 C0 ?? 50 E8 ?? ?? ?? ?? 56 FF D3 8D 4C 24 ?? 8D 04 C5 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 56 89 44 24 ?? FF D3 8B 5C 24 ?? 8B F0 8B CB 8D 3C 36 8B D7 E8 ?? ?? ?? ?? 8D 44 + 24 ?? 8B CE 8B 74 24 ?? 50 56 68 ?? ?? ?? ?? 57 C1 E1 ?? 53 89 4C 24 ?? FF 15 ?? ?? + ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 56 FF D3 83 C0 ?? 8D 4C 24 ?? + 50 E8 ?? ?? ?? ?? 56 FF D3 40 8D 4C 24 ?? 50 E8 ?? ?? ?? ?? 89 44 24 ?? 33 F6 8B 44 + 24 ?? 8B FE 50 FF D3 85 C0 74 ?? 8B 54 24 ?? 89 54 24 ?? 8B 44 24 ?? 8A 0C 07 80 F9 + ?? 74 ?? 80 F9 ?? 74 ?? 88 0A 42 89 54 24 ?? 50 47 FF D3 8B 54 24 ?? 3B F8 72 ?? 8B + 7C 24 ?? 57 FF D3 50 FF 74 24 ?? 6A ?? 57 56 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? + 8D 54 24 ?? 89 74 24 ?? 8B CF E8 ?? ?? ?? ?? 59 85 C0 75 ?? 8D 4C 24 ?? E8 ?? ?? ?? + ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? EB ?? 8B 4C 24 ?? 85 C9 74 + ?? 8B 45 ?? 89 08 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? + E8 ?? ?? ?? ?? 33 F6 46 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 5F 8B + C6 5E 5B 8B E5 5D C3 } - $terminate_antivirus_processes_p2 = { - 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 49 ?? 33 F6 8B BC B5 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 57 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 39 43 ?? 74 ?? 6A ?? 68 ?? - ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 66 83 3F ?? 75 ?? 33 C0 EB ?? 8B C7 8D 50 ?? 8D 49 ?? - 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 50 57 8B CB E8 ?? ?? ?? ?? 46 83 FE ?? - 72 ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 56 FF - 15 ?? ?? ?? ?? 8B C3 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? - ?? ?? ?? 8B E5 5D C3 + $crypt_files_v2 = { + 8B 55 ?? 8B 1D ?? ?? ?? ?? 8D 04 12 89 44 24 ?? 8D 44 24 ?? 50 51 68 ?? ?? ?? ?? 52 + FF 75 ?? FF D3 8D 04 36 89 44 24 ?? 8D 44 24 ?? 50 57 68 ?? ?? ?? ?? 56 FF 74 24 ?? + FF D3 8B 1D ?? ?? ?? ?? 57 FF D3 FF 74 24 ?? 8B F0 FF D3 6A ?? 83 C0 ?? 68 ?? ?? ?? + ?? 03 F0 56 6A ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? 89 44 24 ?? C7 44 24 ?? + ?? ?? ?? ?? FF D3 8B 54 24 ?? 40 85 D2 74 ?? 3B C6 73 ?? 8D 0C 02 89 44 24 ?? 89 4C + 24 ?? 89 54 24 ?? EB ?? C7 44 24 ?? ?? ?? ?? ?? 57 FF D3 40 83 7C 24 ?? ?? 74 ?? 03 + 44 24 ?? 3B C6 72 ?? C7 44 24 ?? ?? ?? ?? ?? FF 74 24 ?? 33 F6 FF D3 85 C0 74 ?? 8B + 7C 24 ?? EB ?? 8D 9B ?? ?? ?? ?? 8B 4C 24 ?? 8A 04 0E 3C ?? 74 ?? 3C ?? 74 ?? 88 07 + 47 51 46 FF D3 3B F0 72 ?? 8B 7C 24 ?? 57 33 F6 FF D3 85 C0 74 ?? 8B 4C 24 ?? 89 4C + 24 ?? 90 8A 04 3E 3C ?? 74 ?? 3C ?? 74 ?? 88 01 41 89 4C 24 ?? 57 46 FF D3 8B 4C 24 + ?? 3B F0 72 ?? 8B 74 24 ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D7 56 FF 15 ?? ?? + ?? ?? 8D 4C 24 ?? 8D 34 46 56 89 74 24 ?? E8 ?? ?? ?? ?? 8D 54 24 ?? C7 44 24 ?? ?? + ?? ?? ?? 8D 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 50 FF 15 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D7 8B 7C 24 ?? 57 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 56 FF 15 ?? ?? ?? ?? 8B 74 24 ?? 56 FF 74 24 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A + ?? 57 8B 3D ?? ?? ?? ?? FF D7 68 ?? ?? ?? ?? 6A ?? 56 FF D7 8B 74 24 ?? 68 ?? ?? ?? + ?? 56 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 56 FF D7 FF 74 24 ?? 8D 34 46 FF D3 50 56 + 6A ?? FF 74 24 ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 74 24 ?? 68 ?? ?? ?? ?? + 56 FF 15 ?? ?? ?? ?? 56 FF D7 8B 7C 24 ?? 57 8D 34 46 FF D3 50 56 6A ?? 57 6A ?? 68 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 + ?? 8B 35 ?? ?? ?? ?? FF D6 8B F8 6A ?? C1 E7 ?? 68 ?? ?? ?? ?? 83 C7 ?? 57 6A ?? FF + 15 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? FF D6 8D 0C C5 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 + 74 ?? 3B CF 73 ?? 8B F8 EB ?? 33 FF FF 74 24 ?? FF D6 8B 0D ?? ?? ?? ?? 89 44 24 ?? + 85 C9 74 ?? 68 ?? ?? ?? ?? 6A ?? 51 FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? + ?? ?? FF D6 83 C0 ?? 50 6A ?? FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8B 44 24 ?? 8B 4C 24 ?? 8D 34 00 + 8B D6 E8 ?? ?? ?? ?? 8B 4C 24 ?? 8D 04 CD ?? ?? ?? ?? 89 44 24 ?? 8D 44 24 ?? 50 57 + 68 ?? ?? ?? ?? 56 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 57 FF + D3 6A ?? 68 ?? ?? ?? ?? 8D 70 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 57 89 44 24 ?? FF D3 8D + 48 ?? 8B 44 24 ?? 85 C0 74 ?? 89 44 24 ?? 3B CE 72 ?? C7 44 24 ?? ?? ?? ?? ?? 57 33 + F6 FF D3 85 C0 74 ?? 8B 4C 24 ?? 89 4C 24 ?? 8A 04 3E 3C ?? 74 ?? 3C ?? 74 ?? 88 01 + 41 89 4C 24 ?? 57 46 FF D3 8B 4C 24 ?? 3B F0 72 ?? 8B 74 24 ?? 56 FF D3 50 FF 74 24 + ?? 6A ?? 56 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 51 8D 54 24 ?? C7 44 24 ?? + ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? + ?? 50 8B 44 24 ?? 50 FF D3 8B 44 24 ?? 68 ?? ?? ?? ?? 6A ?? 50 FF D3 68 ?? ?? ?? ?? + 6A ?? FF 74 24 ?? FF D3 68 ?? ?? ?? ?? 6A ?? FF 74 24 ?? FF D3 8D 4C 24 ?? E8 ?? ?? + ?? ?? 33 C0 5F 5E 5B 8B E5 5D C3 } - - condition: - uint16(0)==0x5A4D and ( all of ($terminate_antivirus_processes_p*)) and ($find_files) and ($encrypt_files) -} -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Eternity : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Eternity ransomware." - author = "ReversingLabs" - id = "7bb0f3b0-a8c0-5239-a1b4-532d403f59bc" - date = "2022-07-22" - modified = "2022-07-22" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Eternity.yara#L1-L74" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "a2298a26e9bbe2b779eb2afeeda28d4321bc2d26db46bbb377bf86abaf8fa929" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Eternity" - tc_detection_factor = 5 - importance = 25 - - strings: $find_files = { - 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? - ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 06 6F ?? ?? ?? ?? 0C 2B ?? 08 - 6F ?? ?? ?? ?? 0D 09 03 04 28 ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 2D ?? DE ?? 08 2C ?? 08 6F - ?? ?? ?? ?? DC 02 28 ?? ?? ?? ?? 0B 07 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 - ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? - 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 - ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? - 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 03 04 28 ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 17 58 - 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 2A + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 89 55 ?? 8B F9 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? + ?? ?? 8B CF E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 57 8D 1C 47 89 5D ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF + 15 ?? ?? ?? ?? 8B F0 33 C0 89 75 ?? 66 89 03 83 FE ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? + ?? ?? 8B 5D ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 85 ?? + ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 68 ?? ?? ?? ?? 57 FF 15 + ?? ?? ?? ?? 8B 55 ?? 8B CF 53 FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? FF 75 + ?? 8B 03 8D 95 ?? ?? ?? ?? 8B 73 ?? 51 8B CF 89 45 ?? E8 ?? ?? ?? ?? 01 03 59 11 53 + ?? 59 3B 73 ?? 77 ?? 72 ?? 8B 45 ?? 3B 03 73 ?? 8B 45 ?? FF 00 8B 75 ?? 8B 45 ?? 33 + C9 66 89 08 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 56 FF + 15 ?? ?? ?? ?? 33 C0 5F 5E 5B 8B E5 5D C3 } - $encrypt_files = { - 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 0A 02 - 28 ?? ?? ?? ?? 0B 07 06 28 ?? ?? ?? ?? 0C 02 19 28 ?? ?? ?? ?? 0D 09 16 6A 6F ?? ?? ?? - ?? 09 6F ?? ?? ?? ?? 02 1C 73 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? - ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 11 ?? - 08 16 08 8E 69 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 17 58 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 02 6F - ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 2A + $find_files_v2 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 89 55 ?? 8B F9 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? + ?? ?? 8B CF E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? + ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 8D 1C 47 89 5D ?? FF D6 8D 85 ?? ?? ?? ?? 50 + 57 FF 15 ?? ?? ?? ?? 33 C9 89 45 ?? 66 89 0B 83 F8 ?? 75 ?? B8 ?? ?? ?? ?? 5F 5E 5B + 8B E5 5D C3 8B 5D ?? EB ?? 8D A4 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 57 FF D6 F6 85 ?? ?? ?? ?? ?? 74 ?? 68 + ?? ?? ?? ?? 57 FF D6 8B 55 ?? 8B CF 53 FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? EB + ?? FF 75 ?? 8B 03 8D 95 ?? ?? ?? ?? 8B 73 ?? 51 8B CF 89 45 ?? E8 ?? ?? ?? ?? 83 C4 + ?? 01 03 11 53 ?? 3B 73 ?? 77 ?? 72 ?? 8B 45 ?? 3B 03 73 ?? 8B 45 ?? FF 00 8B 35 ?? + ?? ?? ?? 8B 45 ?? 33 C9 66 89 08 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B 8B E5 5D C3 } - $aes_encrypt = { - 14 0A 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? 0C 73 ?? ?? - ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 03 07 20 ?? - ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? - ?? ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 17 6F ?? ?? ?? - ?? 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 11 ?? 02 16 02 8E 69 6F ?? ?? ?? ?? 11 - ?? 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 08 6F ?? ?? ?? ?? 0A DE ?? - 09 2C ?? 09 6F ?? ?? ?? ?? DC 08 2C ?? 08 6F ?? ?? ?? ?? DC 06 2A + $search_antivirus_processes = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 B8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A + ?? 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? 8B F8 53 6A ?? + 89 7D ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 89 1E 83 FF ?? 74 ?? 56 57 FF 15 ?? ?? + ?? ?? 33 DB 8D 7E ?? 57 FF B4 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 76 ?? + 50 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? + FF 15 ?? ?? ?? ?? 43 83 FB ?? 72 ?? 8B 7D ?? 56 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 85 + F6 74 ?? 68 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 + 5D C3 } - $encrypt_pass = { - 72 ?? ?? ?? ?? 0A 06 73 ?? ?? ?? ?? 0B D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0C - 08 07 6F ?? ?? ?? ?? A5 ?? ?? ?? ?? 0D 73 ?? ?? ?? ?? 13 ?? 11 ?? 09 6F ?? ?? ?? ?? 7E - ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? - 16 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 2A + $search_antivirus_processes_v2 = { + C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? + ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? + C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? + ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? + ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8B F0 6A ?? 89 74 24 ?? FF 15 ?? ?? ?? ?? 8B D8 85 DB 74 ?? C7 03 ?? + ?? ?? ?? 83 FE ?? 74 ?? 53 56 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8D 4B ?? 33 F6 EB + ?? 8D A4 24 ?? ?? ?? ?? 90 51 FF 74 B4 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 73 ?? 50 + 6A ?? FF 15 ?? ?? ?? ?? 8B F8 85 FF 74 ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 57 8B 3D ?? ?? + ?? ?? FF D7 EB ?? 8B 3D ?? ?? ?? ?? 46 8D 4B ?? 83 FE ?? 72 ?? 8B 74 24 ?? 53 56 FF + 15 ?? ?? ?? ?? 8D 4B ?? 85 C0 75 ?? 85 DB 74 ?? 68 ?? ?? ?? ?? 6A ?? 53 FF 15 ?? ?? + ?? ?? 56 FF D7 5F 5E 5B 8B E5 5D C3 } - - condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($aes_encrypt) and ($encrypt_pass) -} -rule REVERSINGLABS_Win32_Ransomware_Sifreli : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Sifreli ransomware." - author = "ReversingLabs" - id = "974f81e2-6907-54da-97e3-3116c41b5ed4" - date = "2020-10-08" - modified = "2020-10-08" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Sifreli.yara#L1-L119" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "48f6cc678bea81afece0ae203fb27b61e2c6e4f7188a3bd260190f568c9a8a06" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Sifreli" - tc_detection_factor = 5 - importance = 25 - - strings: - $find_files = { - 55 8B EC 83 EC ?? 53 56 57 8B 7D ?? 8B C7 8D 50 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? - 2B C2 D1 F8 8D 44 00 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? - 6A ?? 50 FF D6 8B D8 89 5D ?? 85 DB 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? - ?? ?? ?? 8B 0D ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 51 FF D6 8B F8 85 FF 0F 84 ?? ?? ?? - ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? ?? ?? 3D ?? ?? - ?? ?? 1B C0 40 A3 ?? ?? ?? ?? EB ?? A1 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 57 50 53 FF 15 - ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 90 F6 07 ?? 74 - ?? BB ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 47 ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 - 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 33 DB EB ?? - 1B C0 83 D8 ?? 85 C0 74 ?? B9 ?? ?? ?? ?? 8D 47 ?? 8D 49 ?? 66 8B 10 66 3B 11 75 ?? - 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 - EB ?? 1B C0 83 D8 ?? 85 C0 74 ?? 8B 55 ?? 8B 4D ?? 52 8D 47 ?? 50 8B 07 50 53 68 ?? - ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 55 ?? 57 52 FF 15 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 5D ?? EB ?? C7 45 ?? ?? ?? ?? - ?? 8B 0D ?? ?? ?? ?? 57 6A ?? 51 FF 15 ?? ?? ?? ?? EB ?? C7 45 ?? ?? ?? ?? ?? 8B 15 - ?? ?? ?? ?? 53 6A ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 5F 5E 5B 8B E5 5D C3 5F 5E B8 ?? - ?? ?? ?? 5B 8B E5 5D C3 + $find_files_v2_1 = { + 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 85 C0 74 + ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D3 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? + ?? F7 D8 1B C0 40 75 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 8B CE E8 ?? + ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 8D 3C 46 89 7D ?? FF D3 8D 85 ?? ?? + ?? ?? 50 56 FF 15 ?? ?? ?? ?? 33 C9 89 45 ?? 66 89 0F 83 F8 ?? 75 ?? B8 ?? ?? ?? ?? + 5F 5E 5B 8B E5 5D C3 8B 7D ?? EB ?? 8D 9B ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF D3 F6 85 ?? ?? + ?? ?? ?? 74 ?? 83 7D ?? ?? 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D3 8B 55 ?? 8B CE 6A ?? 57 FF 75 ?? FF 75 ?? E8 ?? ?? + ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D3 8B 55 ?? 8B CE 6A ?? 57 FF 75 + ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B 07 6A ?? 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 89 45 ?? 8B 47 ?? 6A ?? 89 45 ?? FF 15 ?? ?? ?? ?? 56 8B D8 68 ?? ?? ?? ?? + 53 FF 15 ?? ?? ?? ?? 83 C4 ?? 8B CB E8 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 6A ?? + 53 FF 15 ?? ?? ?? ?? 0F 57 C0 66 0F 13 45 ?? 8B 45 ?? 8B 4D ?? EB ?? 83 BD ?? ?? ?? + ?? ?? 0F 57 C0 66 0F 13 45 ?? 72 ?? 51 FF 75 ?? 8B CB E8 ?? ?? ?? ?? 83 C4 ?? 89 55 + ?? EB ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 68 ?? ?? ?? ?? 6A ?? 53 89 45 ?? FF 15 ?? ?? ?? + ?? 8B 45 ?? 8B 4D ?? 01 0F 11 47 ?? 8B 45 ?? 3B 47 ?? 77 ?? 72 ?? 8B 45 ?? 3B 07 73 + ?? 8B 45 ?? FF 00 8B 1D ?? ?? ?? ?? 8B 45 ?? 33 C9 66 89 08 8D 85 ?? ?? ?? ?? 50 FF + 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 33 + C0 5B 8B E5 5D C3 } - $remote_connection_p1 = { - 55 8B EC 83 EC ?? 53 33 DB 8D 45 ?? 89 5D ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 8B 45 ?? 8B 4D ?? 56 57 50 51 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 8B 55 ?? 8B - 4D ?? 52 57 E8 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? 8B 45 ?? 6A - ?? 50 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B D6 E8 ?? ?? ?? ?? 85 C0 74 ?? - C7 45 ?? ?? ?? ?? ?? 56 FF D3 8D 4D ?? 51 8D 55 ?? 52 6A ?? 57 C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 57 8B F0 FF D3 85 F6 74 ?? 8B 45 ?? 50 FF D3 - 8B 5D ?? 83 7D ?? ?? 8B 35 ?? ?? ?? ?? 74 ?? 8B 4D ?? 8B 15 ?? ?? ?? ?? 51 6A ?? 52 - FF D6 8B 45 ?? 85 C0 74 ?? 50 A1 ?? ?? ?? ?? 6A ?? 50 FF D6 5F 5E 8B C3 5B 8B E5 5D - C3 8B C3 5B 8B E5 5D C3 + $crypt_files_v2_1 = { + FF 15 ?? ?? ?? ?? 33 D2 89 44 24 ?? 89 44 24 ?? 8D 0C B7 8D 0C CD ?? ?? ?? ?? 85 C0 + 74 ?? 3B CB 73 ?? 8D 3C 01 89 44 24 ?? 89 7C 24 ?? 8B D1 EB ?? 89 54 24 ?? 8B F8 8B + 4D ?? 8D 34 CD ?? ?? ?? ?? 85 C0 74 ?? 8D 0C 32 89 4C 24 ?? 3B CB 73 ?? 8B 54 24 ?? + 8B CF 89 7C 24 ?? 03 FE 89 7C 24 ?? EB ?? 33 C9 89 4C 24 ?? 8B 74 24 ?? 85 C0 74 ?? + 8D 04 F5 ?? ?? ?? ?? 03 C2 3B C3 72 ?? 33 FF 89 7C 24 ?? 8B 1D ?? ?? ?? ?? 85 C9 0F + 84 ?? ?? ?? ?? 8B 55 ?? 8B 1D ?? ?? ?? ?? 8D 04 12 89 44 24 ?? 8D 44 24 ?? 50 51 68 + ?? ?? ?? ?? 52 FF 75 ?? FF D3 8D 04 36 89 44 24 ?? 8D 44 24 ?? 50 57 68 ?? ?? ?? ?? + 56 FF 74 24 ?? FF D3 8B 1D ?? ?? ?? ?? 57 FF D3 FF 74 24 ?? 8B F0 FF D3 6A ?? 83 C6 + ?? 03 C6 68 ?? ?? ?? ?? 50 6A ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? 8B F0 C7 + 44 24 ?? ?? ?? ?? ?? 89 74 24 ?? 89 74 24 ?? FF D3 40 85 F6 74 ?? 3B 44 24 ?? 73 ?? + 8D 0C 06 89 44 24 ?? 89 4C 24 ?? 89 74 24 ?? EB ?? C7 44 24 ?? ?? ?? ?? ?? 57 FF D3 + 40 85 F6 74 ?? 03 44 24 ?? 3B 44 24 ?? 72 ?? C7 44 24 ?? ?? ?? ?? ?? FF 74 24 ?? 33 + F6 FF D3 85 C0 74 ?? 8B 4C 24 ?? 8B 7C 24 ?? 89 4C 24 ?? 8A 04 3E 3C ?? 74 ?? 3C ?? + 74 ?? 88 01 41 89 4C 24 ?? 57 46 FF D3 8B 4C 24 ?? 3B F0 72 ?? 8B 7C 24 ?? 57 33 F6 + FF D3 85 C0 74 ?? 8B 4C 24 ?? 89 4C 24 ?? EB ?? 8D 49 ?? 8A 04 3E 3C ?? 74 ?? 3C ?? + 74 ?? 88 01 41 89 4C 24 ?? 57 46 FF D3 8B 4C 24 ?? 3B F0 72 ?? 8B 74 24 ?? 8B 1D ?? + ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D3 56 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? 8D 3C 46 57 E8 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D3 68 ?? ?? ?? ?? 57 FF D3 68 ?? ?? ?? ?? 57 FF D3 68 + ?? ?? ?? ?? 57 FF D3 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF D6 68 + ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? 57 FF D3 57 FF 15 ?? ?? ?? ?? + FF 74 24 ?? 8D 34 47 FF 15 ?? ?? ?? ?? 50 56 6A ?? FF 74 24 ?? 6A ?? 68 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D3 57 FF 15 ?? ?? ?? ?? FF 74 24 ?? 8D 34 47 + FF 15 ?? ?? ?? ?? 50 56 6A ?? FF 74 24 ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 + C0 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? 66 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 74 24 ?? 58 58 8D 44 24 ?? 50 57 FF + D3 8B 5C 24 ?? 8B 35 ?? ?? ?? ?? 53 FF D6 6A ?? C1 E0 ?? 83 C0 ?? 68 ?? ?? ?? ?? 50 + 6A ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? 8B F8 53 89 7C 24 ?? FF D6 8D 04 C5 ?? ?? ?? ?? + 85 FF 74 ?? 3B 44 24 ?? 72 ?? 33 FF 53 FF D6 8B 0D ?? ?? ?? ?? 8B F0 89 74 24 ?? 85 + C9 74 ?? 68 ?? ?? ?? ?? 6A ?? 51 FF 15 ?? ?? ?? ?? 8B 5C 24 ?? 6A ?? 68 ?? ?? ?? ?? + 53 FF 15 ?? ?? ?? ?? 83 C0 ?? 50 6A ?? FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? 85 C0 74 ?? + 53 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8B 5C 24 ?? 03 F6 8B D6 8B CB E8 ?? + ?? ?? ?? 8B 4C 24 ?? 8D 04 CD ?? ?? ?? ?? 89 44 24 ?? 8D 44 24 ?? 50 57 68 ?? ?? ?? + ?? 56 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 57 FF D3 + 6A ?? 68 ?? ?? ?? ?? 8D 70 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 57 89 44 24 ?? FF D3 8D 48 + ?? 8B 44 24 ?? 85 C0 74 ?? 89 44 24 ?? 3B CE 72 ?? C7 44 24 ?? ?? ?? ?? ?? 57 33 F6 + FF D3 85 C0 74 ?? 8B 4C 24 ?? 89 4C 24 ?? 8A 04 3E 3C ?? 74 ?? 3C ?? 74 ?? 88 01 41 + 89 4C 24 ?? 57 46 FF D3 8B 4C 24 ?? 3B F0 72 ?? 8B 74 24 ?? 56 FF D3 50 FF 74 24 ?? + 6A ?? 56 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 7C 24 ?? 8D 54 24 ?? 6A ?? 57 8B + CE C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 1D ?? ?? ?? ?? 68 + ?? ?? ?? ?? 50 8B 44 24 ?? 50 FF D3 68 ?? ?? ?? ?? 6A ?? FF 74 24 ?? FF D3 68 ?? ?? + ?? ?? 6A ?? FF 74 24 ?? FF D3 33 F6 EB ?? 8B 4C 24 ?? 85 C9 74 ?? 8B 45 ?? 89 08 8B + 44 24 ?? 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 FF D3 68 ?? ?? ?? ?? 6A ?? FF 74 + 24 ?? FF D3 68 ?? ?? ?? ?? 6A ?? FF 74 24 ?? FF D3 EB ?? 8B 7C 24 ?? 83 7C 24 ?? ?? + 75 ?? 68 ?? ?? ?? ?? 6A ?? 57 FF D3 BE ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 74 24 ?? + FF D3 8D 4C 24 ?? E8 ?? ?? ?? ?? 5F 8B C6 5E 5B 8B E5 5D C3 } - $remote_connection_p2 = { - 55 8B EC 83 EC ?? 56 57 68 ?? ?? ?? ?? 33 FF 57 57 57 57 FF 15 ?? ?? ?? ?? 8B F0 85 - F6 74 ?? 8B 3D ?? ?? ?? ?? B8 ?? ?? ?? ?? 6A ?? 89 45 ?? 89 45 ?? 8D 45 ?? 50 6A ?? - 56 C7 45 ?? ?? ?? ?? ?? FF D7 6A ?? 8D 4D ?? 51 6A ?? 56 FF D7 6A ?? 8D 55 ?? 52 6A - ?? 56 FF D7 8B 45 ?? 8B 4D ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 50 51 56 FF 15 ?? ?? ?? - ?? 8B F8 85 FF 75 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 5F 5E 8B E5 5D C3 + $remote_connection_v2_1 = { + 53 89 45 ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 3C 45 ?? ?? + ?? ?? 8D 47 ?? 50 6A ?? FF D6 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B D8 FF D6 + 89 45 ?? 85 DB 74 ?? 8D 47 ?? 3B F8 73 ?? 8B F3 EB ?? 33 F6 FF 75 ?? 56 FF 15 ?? ?? + ?? ?? F3 0F 6F 05 ?? ?? ?? ?? 56 F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 + ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? F3 + 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? FF 15 ?? + ?? ?? ?? 8D 45 ?? 33 FF 50 FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 68 ?? ?? ?? ?? 83 EC ?? + 68 ?? ?? ?? ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 50 56 FF 75 ?? 8B 75 ?? 8D 4D ?? 56 E8 + ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? BF ?? ?? ?? ?? 74 ?? 8B 4D ?? 8D 55 ?? C7 45 ?? + ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 85 C0 74 ?? 8B 4D ?? 89 01 EB ?? 33 + FF 68 ?? ?? ?? ?? 6A ?? 56 8B 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF + D6 68 ?? ?? ?? ?? 6A ?? 53 FF D6 8B 45 ?? 85 C0 74 ?? 50 FF 15 ?? ?? ?? ?? 8B C7 5F + 5E 5B 8B E5 5D C3 } - $remote_connection_p3 = { - 55 8B EC 83 EC ?? 53 56 8B F0 33 C0 89 06 57 89 46 ?? 89 46 ?? 6A ?? 50 89 46 ?? 8D - 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 51 6A ?? BF ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 89 7D ?? 89 7D ?? 89 7D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? 8B 4D ?? 8B 1D ?? ?? ?? ?? 8D 4C 09 ?? 33 C0 85 C9 74 ?? 8B 15 ?? ?? ?? ?? - 51 50 52 FF D3 89 06 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 51 52 50 E8 ?? ?? ?? - ?? 8B 06 8B 55 ?? 33 C9 66 89 0C 50 8B 4D ?? 83 C4 ?? 85 C9 74 ?? 8B 45 ?? 66 83 38 - ?? 75 ?? 83 45 ?? ?? 2B CF 89 4D ?? 85 C9 75 ?? 8B 55 ?? 8D 7C 0A ?? 8D 54 3F ?? 33 - C0 85 D2 74 ?? 52 50 A1 ?? ?? ?? ?? 50 FF D3 8B 4D ?? 89 46 ?? 85 C0 74 ?? 51 8B 4D - ?? 51 83 C0 ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8B 4E ?? 52 8B 55 ?? 50 8D 44 51 - ?? 50 E8 ?? ?? ?? ?? 8B 46 ?? B9 ?? ?? ?? ?? 66 89 08 33 D2 66 89 14 78 66 8B 45 ?? - 83 C4 ?? 83 7D ?? ?? 66 89 46 ?? 75 ?? 83 4E ?? ?? 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D - C3 8B 36 85 F6 74 ?? 8B 0D ?? ?? ?? ?? 56 6A ?? 51 FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B - 8B E5 5D C3 + $search_antivirus_processes_v4_1_2 = { + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? 8B F8 53 6A ?? + 89 7D ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 89 1E 83 FF ?? 74 ?? 56 57 FF 15 ?? ?? + ?? ?? 33 DB 8D 7E ?? 57 FF B4 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 76 ?? + 50 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? + FF 15 ?? ?? ?? ?? 43 83 FB ?? 72 ?? 8B 7D ?? 56 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 85 + F6 74 ?? 68 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 + 5D C3 } - $encrypt_files_1 = { - 8B C3 8D 50 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 57 8B F8 8D 4C 3F ?? 33 - C0 85 C9 74 ?? 51 50 A1 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 8B F0 8B CB - 2B F3 8D 9B ?? ?? ?? ?? 0F B7 11 66 89 14 0E 83 C1 ?? 66 85 D2 75 ?? B9 ?? ?? ?? ?? - 8D 34 3F 2B F1 03 F0 EB ?? 8D 49 ?? 0F B7 11 66 89 14 0E 83 C1 ?? 66 85 D2 75 ?? 5E - 5F C3 + $find_files_v4_1_2 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 33 FF 89 54 24 ?? 8B F1 89 7C 24 ?? 39 + 7D ?? 75 ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 85 C0 75 ?? 85 DB 75 ?? 33 C0 E9 + ?? ?? ?? ?? 33 DB 43 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 66 83 3E ?? 74 ?? 8D 54 24 ?? + 89 7C 24 ?? 8B CE E8 ?? ?? ?? ?? 89 44 24 ?? 39 7C 24 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 56 8D 04 46 89 44 24 ?? FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 56 FF 15 ?? + ?? ?? ?? 8B 4C 24 ?? 33 D2 89 44 24 ?? 66 89 11 83 F8 ?? 75 ?? BF ?? ?? ?? ?? E9 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? + 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 44 24 ?? 50 56 FF 15 ?? ?? ?? ?? F6 + 44 24 ?? ?? 74 ?? 85 DB 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? + ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8B 54 24 ?? 8B CE E8 ?? ?? ?? ?? EB ?? 68 ?? ?? + ?? ?? 56 FF 15 ?? ?? ?? ?? 57 EB ?? FF 74 24 ?? 8D 54 24 ?? 8B CE E8 ?? ?? ?? ?? 59 + 8B 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 + ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B C7 5F 5E + 5B 8B E5 5D C3 } - $encrypt_files_2 = { - 83 E8 ?? 53 56 57 8B DA 74 ?? 48 74 ?? 5F 5E 33 C0 5B C3 53 51 33 F6 E8 ?? ?? ?? ?? - 83 C4 ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 8B F0 33 FF 85 F6 74 ?? 56 53 FF 15 ?? ?? ?? ?? - 85 C0 74 ?? BF ?? ?? ?? ?? A1 ?? ?? ?? ?? 56 6A ?? 50 FF 15 ?? ?? ?? ?? 8B F7 5F 8B - C6 5E 5B C3 53 51 33 F6 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 8B F0 33 - FF 85 F6 74 ?? 56 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? BF ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? - 56 6A ?? 51 FF 15 ?? ?? ?? ?? 8B F7 5F 8B C6 5E 5B C3 ?? ?? 55 8B EC 8B 4D ?? 8B 41 - ?? 83 F8 ?? 0F 8F ?? ?? ?? ?? F7 45 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 40 53 89 41 ?? - 8B 45 ?? 83 E8 ?? 56 57 74 ?? 48 0F 85 ?? ?? ?? ?? 8B 7D ?? 33 F6 8D 9B ?? ?? ?? ?? - 8B 86 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 C6 ?? 83 - FE ?? 72 ?? 8B 5D ?? E8 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 8B 4D ?? 51 56 E8 ?? ?? ?? ?? - 83 C4 ?? EB ?? 8B 41 ?? 83 E8 ?? 74 ?? 48 75 ?? 8B 75 ?? E8 ?? ?? ?? ?? EB ?? 8B 75 - ?? 8B C6 E8 ?? ?? ?? ?? F7 D8 1B C0 F7 D8 85 C0 74 ?? 8B 5D ?? 8B FE E8 ?? ?? ?? ?? - 8B F0 85 F6 74 ?? 8B 7D ?? 8B 47 ?? 8B 0F 8B D6 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 47 ?? - 85 C0 74 ?? 50 FF 15 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B 45 ?? FF 48 ?? 5F 5E 5B B8 - ?? ?? ?? ?? 5D C3 + $crypt_files_v4_1_2 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 89 4D ?? 33 DB 57 B9 ?? ?? ?? ?? 89 5D ?? 8B F2 E8 + ?? ?? ?? ?? 8B F8 8D 55 ?? 56 57 8D 4D ?? 89 7D ?? E8 ?? ?? ?? ?? 59 59 85 C0 0F 84 + ?? ?? ?? ?? 53 53 6A ?? 53 53 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE + ?? 0F 84 ?? ?? ?? ?? 6A ?? 58 88 5D ?? 48 75 ?? 51 51 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 89 45 ?? B9 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 89 5D ?? 89 + 5D ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 89 5D ?? 53 8D + 45 ?? 50 68 ?? ?? ?? ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D + ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 45 ?? 81 F9 ?? ?? ?? ?? 6A ?? 5A 0F 42 C2 01 8F ?? ?? + ?? ?? 8B 55 ?? 8D 8D ?? ?? ?? ?? 11 9F ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 50 FF 75 ?? 89 + 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 33 C9 F7 D8 41 99 51 53 52 50 56 FF 15 ?? ?? ?? + ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 53 8D 45 ?? 50 FF 75 ?? FF 75 ?? 56 FF 15 ?? ?? ?? + ?? 85 C0 75 ?? 8B 7D ?? 6A ?? FF 15 ?? ?? ?? ?? 53 8D 45 ?? 50 FF 75 ?? 57 56 FF 15 + ?? ?? ?? ?? 85 C0 74 ?? 8B 7D ?? 8B 4D ?? 85 C9 0F 84 ?? ?? ?? ?? 53 8D 45 ?? 50 68 + ?? ?? ?? ?? 57 56 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B D8 E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? + ?? ?? 56 FF 15 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 5F 5E 8B C3 5B 8B E5 5D C3 33 C0 8D + 48 ?? 89 4D ?? EB } - $encrypt_files_3 = { - 8B C6 8D 50 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 83 C0 ?? 85 C0 7E ?? EB - ?? 8D 49 ?? 66 83 3C 46 ?? 74 ?? 48 85 C0 7F ?? 33 C0 C3 8D 44 46 ?? 85 C0 74 ?? 83 - C0 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? C3 + $remote_connection_v4_1_2 = { + 55 8B EC 83 EC ?? 53 8B 1D ?? ?? ?? ?? 56 8B F1 57 83 7E ?? ?? 74 ?? FF 76 ?? FF D3 + 8B CE E8 ?? ?? ?? ?? 33 FF 57 57 6A ?? 57 57 FF 75 ?? FF 75 ?? FF 76 ?? FF 15 ?? ?? + ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? + 83 C4 ?? B8 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 44 C8 57 51 57 57 68 + ?? ?? ?? ?? 56 8B 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? FF + 75 ?? FF 75 ?? FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 33 FF 47 EB ?? FF + 15 ?? ?? ?? ?? 8B 45 ?? 50 FF D3 56 FF D3 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B + E5 5D C2 } - - condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_*)) and ( all of ($remote_connection_p*)) -} -rule REVERSINGLABS_Win32_Ransomware_Sigrun : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Sigrun ransomware." - author = "ReversingLabs" - id = "fa627192-ed80-5115-a028-014f67f4571d" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Sigrun.yara#L1-L111" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ea29ec64cdfc0c714fe0acdce5878cb1302dd5aa916811121c644948ce275935" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Sigrun" - tc_detection_factor = 5 - importance = 25 - - strings: - $find_files = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 83 7D ?? ?? 53 56 57 8B DA C7 44 24 ?? ?? ?? ?? - ?? 8B F1 75 ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 8B 7C 24 ?? 89 7C 24 ?? 85 C0 75 ?? 85 FF - 75 ?? 5F 5E 5B 8B E5 5D C3 C7 44 24 ?? ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? - A1 ?? ?? ?? ?? 89 44 24 ?? A1 ?? ?? ?? ?? 89 44 24 ?? 0F B7 06 66 89 44 24 ?? 83 F8 - ?? 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 56 - FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 8D 04 46 89 44 24 ?? FF D7 8D - 44 24 ?? 50 56 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 D2 89 44 24 ?? 66 89 11 83 F8 ?? 75 - ?? B8 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 - ?? 8D 44 24 ?? 50 56 FF D7 F6 44 24 ?? ?? 74 ?? 83 7C 24 ?? ?? 74 ?? BA ?? ?? ?? ?? - 8B CE E8 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF D7 6A ?? 8B D3 8B CE E8 ?? ?? - ?? ?? EB ?? 68 ?? ?? ?? ?? 56 FF D7 6A ?? 8B D3 8B CE E8 ?? ?? ?? ?? EB ?? 53 8D 54 - 24 ?? 8B CE E8 ?? ?? ?? ?? 83 C4 ?? 8B 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 - 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 5E - 33 C0 5B 8B E5 5D C3 + $url_parameters_setup_v4_1_2 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 FF 15 ?? ?? ?? ?? 33 FF 57 57 57 FF 15 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 57 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? + ?? ?? ?? 83 EC ?? 33 DB 43 53 83 EC ?? 53 51 53 51 53 51 53 51 53 83 EC ?? 53 51 53 + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 0C 45 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 85 C0 74 ?? 50 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF + D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? + ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 FF 35 ?? ?? ?? + ?? 8B 35 ?? ?? ?? ?? FF D6 FF 35 ?? ?? ?? ?? 03 C0 A3 ?? ?? ?? ?? FF D6 03 C0 8B D0 + E8 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 57 57 57 68 ?? ?? ?? ?? 57 57 FF 15 ?? ?? ?? ?? + 8B 35 ?? ?? ?? ?? 8B F8 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF D6 BB ?? ?? ?? ?? 53 + FF D6 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 53 FF D6 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? + FF D6 E8 ?? ?? ?? ?? 85 FF 74 ?? 6A ?? 57 FF 15 ?? ?? ?? ?? E8 } - $encrypt_files_1 = { - 55 8B EC 83 EC ?? 53 57 68 ?? ?? ?? ?? 8B FA 8B D9 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 5F 33 C0 5B 8B E5 5D C3 - 56 8D 45 ?? 33 F6 50 56 56 57 53 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 8D 45 ?? - C7 45 ?? ?? ?? ?? ?? 50 8D 45 ?? 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 45 ?? 68 ?? - ?? ?? ?? 50 FF 75 ?? C7 00 ?? ?? ?? ?? 56 6A ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 8B F0 - FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 68 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 8B C6 5E 5F 5B 8B E5 5D C3 + $url_parameters_setup_v4 = { + 55 8B EC 81 EC ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 6A ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 50 FF + 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 45 ?? E8 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 04 45 ?? ?? ?? ?? 50 6A ?? FF 15 ?? + ?? ?? ?? A3 ?? ?? ?? ?? 85 C0 75 ?? 50 FF 15 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF + 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? + ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? + ?? FF D6 FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 03 C0 8B D0 E8 ?? ?? ?? ?? 6A ?? FF 15 + ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? + ?? FF D6 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF D6 + 68 ?? ?? ?? ?? FF D6 E8 ?? ?? ?? ?? E8 } - $encrypt_files_2 = { - 55 8B EC 53 56 57 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B DA 8B F9 FF 15 ?? ?? - ?? ?? 57 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 C4 ?? 8B CF E8 ?? ?? ?? ?? 85 - C0 74 ?? 68 ?? ?? ?? ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 33 C0 5F 5E 5B 5D C3 8B CF E8 ?? - ?? ?? ?? 85 C0 75 ?? 83 7B ?? ?? 72 ?? 8B 55 ?? 8B CF E8 ?? ?? ?? ?? 85 C0 74 ?? 56 - 57 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 5F 5E B8 ?? ?? ?? ?? - 5B 5D C3 + $search_antivirus_processes_v4 = { + 55 8B EC 83 EC ?? 53 56 8B 35 ?? ?? ?? ?? 57 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A + ?? FF D6 8B 5D ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 89 03 C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? FF D6 8B F8 89 7D ?? 85 FF 74 ?? 6A ?? 6A ?? C7 07 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 5F 5E + 33 C0 5B 8B E5 5D C2 ?? ?? 33 C9 33 F6 57 50 89 4D ?? 89 4D ?? 89 4D ?? 89 75 ?? FF + 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 49 ?? 85 F6 0F 85 ?? ?? ?? ?? 83 C7 ?? EB + ?? 8D 49 ?? 57 FF 74 B5 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 46 83 FE ?? 72 ?? 8B 75 ?? + EB ?? 83 7D ?? ?? 57 FF 33 C7 45 ?? ?? ?? ?? ?? 75 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? + ?? FF 33 FF 15 ?? ?? ?? ?? EB ?? 8B 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 33 FF D6 + FF 45 ?? 57 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B 75 ?? 8D 0C 41 B8 ?? ?? ?? ?? 81 F9 ?? ?? + ?? ?? 89 4D ?? 0F 47 F0 89 75 ?? 8B 7D ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? + FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 03 66 83 38 ?? 74 + ?? 50 FF 15 ?? ?? ?? ?? 8B 0B 33 D2 66 89 54 41 ?? 8B 45 ?? 8B 4D ?? 89 08 8B 35 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 FF D6 FF 75 ?? FF 15 ?? ?? ?? ?? 8B 7D ?? 85 FF 75 + ?? 68 ?? ?? ?? ?? 57 FF 33 FF D6 8B C7 5F 5E 5B 8B E5 5D C2 } - $encrypt_files_3 = { - 55 8B EC 83 EC ?? 56 57 E8 ?? ?? ?? ?? 85 C0 75 ?? 83 C8 ?? 5F 5E 8B E5 5D C3 8D 45 - ?? 50 8D 45 ?? 50 8D 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 8D 4D ?? 8B D7 E8 - ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 85 C0 74 ?? 8B 4D ?? 85 C9 74 ?? 8B 45 ?? 85 C0 74 ?? - C6 04 08 ?? 8B 4D ?? 68 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 - ?? FF D6 8B CF E8 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 05 ?? ?? ?? ?? - ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D6 68 ?? ?? ?? ?? 6A ?? - 57 FF D6 5F 33 C0 5E 8B E5 5D C3 + $find_files_v4 = { + C7 44 24 ?? ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 66 83 3E ?? 0F 84 ?? ?? ?? + ?? 8D 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 89 44 24 + ?? 0F 85 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 8D 04 + 46 89 44 24 ?? FF D7 8D 44 24 ?? 50 56 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 D2 89 44 24 + ?? 66 89 11 83 F8 ?? 75 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5F 5E 5B 8B + E5 5D C3 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 44 24 ?? 50 56 FF D7 F6 + 44 24 ?? ?? 74 ?? 83 7C 24 ?? ?? 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 74 + ?? 68 ?? ?? ?? ?? 56 FF D7 6A ?? 8B D3 8B CE E8 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? 56 + FF D7 6A ?? 8B D3 8B CE E8 ?? ?? ?? ?? EB ?? 53 8D 54 24 ?? 8B CE E8 ?? ?? ?? ?? 83 + C4 ?? 8B 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 5E + 33 C0 5B 8B E5 5D C3 } - $enum_resources_1 = { - 55 8B EC 83 E4 ?? 83 EC ?? 53 56 57 8B 3D ?? ?? ?? ?? 8B F1 6A ?? 68 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 6A ?? 89 54 24 ?? 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? FF D7 8B 1D ?? ?? - ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 85 F6 0F 85 ?? ?? - ?? ?? 8D 44 24 ?? 50 6A ?? 6A ?? 6A ?? 6A ?? FF D3 85 C0 0F 85 ?? ?? ?? ?? 8D 44 24 - ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 74 24 ?? 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF - 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 49 ?? 33 DB 39 5C 24 ?? 0F 86 - ?? ?? ?? ?? 8B 74 24 ?? 83 C6 ?? 83 7E ?? ?? 75 ?? 8B 06 6A ?? 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 6A ?? 89 44 24 ?? FF D7 8B F8 85 FF 74 ?? FF 74 24 ?? 68 ?? ?? ?? ?? 57 FF - 15 ?? ?? ?? ?? 8B 55 ?? 83 C4 ?? 8B CF 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? - 6A ?? 57 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? F6 46 ?? ?? 74 ?? FF 75 ?? 8B 54 24 ?? - 8D 4E ?? E8 ?? ?? ?? ?? 83 C4 ?? 43 83 C6 ?? 3B 5C 24 ?? 72 ?? 8D 44 24 ?? C7 44 24 - ?? ?? ?? ?? ?? 50 FF 74 24 ?? 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 74 24 ?? FF + $crypt_files_v4 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 6A ?? 68 ?? ?? ?? ?? 33 DB 89 4D ?? 68 ?? ?? ?? + ?? 53 8B F2 89 5D ?? FF 15 ?? ?? ?? ?? 8B F8 8D 55 ?? 56 57 8D 4D ?? 89 7D ?? E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 33 C0 5F 5E 5B + 8B E5 5D C3 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? + 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? 88 5D ?? 48 75 ?? 8B 45 ?? 89 85 ?? + ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 8B + 45 ?? 89 45 ?? 8B 45 ?? 6A ?? 89 45 ?? 8B 45 ?? 68 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 68 + ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 89 5D ?? 89 5D ?? 8B 1D ?? ?? ?? ?? 6A ?? C7 05 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? FF D3 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? + 89 45 ?? FF D3 33 C9 8B D8 89 4D ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? FF 75 ?? 56 FF + 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 3D + ?? ?? ?? ?? BA ?? ?? ?? ?? 0F 42 CA 01 87 ?? ?? ?? ?? 8B 55 ?? 83 97 ?? ?? ?? ?? ?? + 8B 7D ?? 89 4D ?? 8D 8D ?? ?? ?? ?? 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B C7 F7 D8 99 6A + ?? 6A ?? 52 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 + 57 53 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 57 + 53 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 4D ?? 8B 7D ?? 85 C9 0F 84 ?? ?? ?? ?? 6A ?? + 8D 45 ?? 50 68 ?? ?? ?? ?? 57 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? 89 + 45 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? + ?? 8B 5D ?? 68 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 5F 5E 8B C3 5B 8B E5 5D C3 } - $enum_resources_2 = { - 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 74 24 ?? FF 74 24 ?? FF - 15 ?? ?? ?? ?? 8D 44 24 ?? 50 56 6A ?? 6A ?? 6A ?? FF D3 8B F0 85 F6 0F 85 ?? ?? ?? - ?? 8B 74 24 ?? 8D 44 24 ?? 50 56 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 74 24 ?? - C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 9B ?? ?? ?? ?? - 33 DB 39 5C 24 ?? 0F 86 ?? ?? ?? ?? 83 C6 ?? 90 83 7E ?? ?? 75 ?? 8B 06 6A ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 89 44 24 ?? FF D7 8B F8 85 FF 74 ?? FF 74 24 ?? 68 ?? - ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B 55 ?? 83 C4 ?? 8B CF 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? - 68 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? F6 46 ?? ?? 74 ?? FF 75 ?? 8B 54 24 ?? 8D - 4E ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 3D ?? ?? ?? ?? 43 83 C6 ?? 3B 5C 24 ?? 72 ?? 8B 74 - 24 ?? 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 56 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? - 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF 74 24 - ?? FF 15 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 6A ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 8B - C6 5E 5B 8B E5 5D C3 + $crypt_files_v3 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 45 ?? C7 45 + ?? ?? ?? ?? ?? 50 6A ?? 8B D9 8B CA 6A ?? E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 6A ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF D6 8B F8 C7 45 ?? ?? ?? ?? ?? 53 57 89 7D ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 57 FF 15 ?? ?? + ?? ?? 66 0F 6F 05 ?? ?? ?? ?? BA ?? ?? ?? ?? F3 0F 7F 85 ?? ?? ?? ?? 51 66 0F 6F 05 + ?? ?? ?? ?? 8D 4D ?? F3 0F 7F 45 ?? C6 45 ?? ?? 66 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 + ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF D6 F3 0F 6F 85 ?? ?? ?? ?? 8B F8 6A ?? 68 ?? ?? + ?? ?? 68 ?? ?? ?? ?? F3 0F 7F 07 6A ?? F3 0F 6F 45 ?? 89 7D ?? F3 0F 7F 47 ?? FF D6 + F3 0F 6F 45 ?? 68 ?? ?? ?? ?? 89 45 ?? F3 0F 7F 00 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 + 57 FF 75 ?? C7 45 ?? ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 C4 ?? + 85 C0 75 ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? EB ?? 68 ?? + ?? ?? ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? + FF 15 ?? ?? ?? ?? 0F 57 C0 66 0F 13 45 ?? 8B 75 ?? 8B 5D ?? E9 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? + ?? 6A ?? FF 75 ?? FF D7 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D7 0F 57 C0 66 0F 13 45 ?? + 8B 75 ?? 8B 5D ?? E9 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF D6 6A ?? 8B D8 + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? C7 03 ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? FF D6 8B + 3D ?? ?? ?? ?? 33 F6 33 C9 89 45 ?? 89 4D ?? EB ?? 8B 45 ?? 6A ?? 8D 4D ?? 51 68 ?? + ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 + ?? ?? ?? ?? 3D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + 0F 42 F1 01 03 83 53 ?? ?? 8B 45 ?? 89 45 ?? 89 45 ?? A8 ?? 74 ?? 8B FF 40 A8 ?? 75 + ?? 89 45 ?? 6A ?? 68 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? FF 75 ?? 89 45 ?? FF 75 + ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 89 45 ?? 6A ?? 68 ?? ?? ?? ?? 50 6A ?? FF 15 + ?? ?? ?? ?? 85 C0 74 ?? 8B 55 ?? 8B 4D ?? 50 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 8D 45 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D7 8B 4D ?? 8B 45 ?? + F7 D9 6A ?? 83 D0 ?? 6A ?? F7 D8 50 51 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 + ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 + ?? BE ?? ?? ?? ?? 89 75 ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D7 85 F6 0F 84 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D7 8B 4D ?? 8B 75 ?? 85 C9 75 ?? 51 8D 45 ?? 50 + 68 ?? ?? ?? ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? FF 75 + ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A ?? 53 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? + ?? ?? ?? 8B 03 8B 73 ?? 68 ?? ?? ?? ?? 6A ?? 53 89 45 ?? FF D7 68 ?? ?? ?? ?? 6A ?? + FF 75 ?? FF D7 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D7 8B 5D ?? 68 ?? ?? ?? ?? 6A ?? FF + 75 ?? FF D7 5F 8B D6 8B C3 5E 5B 8B E5 5D C3 + } + $search_antivirus_processes_v5 = { + 8B 7D ?? 6A ?? 53 6A ?? 33 DB 89 07 53 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF + D6 8B F0 85 F6 75 ?? 33 C0 E9 ?? ?? ?? ?? 53 6A ?? C7 06 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 89 45 ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? 53 56 FF 15 ?? ?? ?? ?? EB ?? 56 33 C9 89 + 5D ?? 50 89 5D ?? 89 4D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 0F + 85 ?? ?? ?? ?? 33 C0 8D 4E ?? 89 45 ?? 51 FF 74 85 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? + 8B 45 ?? 8D 4E ?? 40 89 45 ?? 83 F8 ?? 72 ?? EB ?? 33 C0 39 45 ?? 8D 58 ?? 8D 46 ?? + 50 FF 37 75 ?? FF 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 37 FF 15 + ?? ?? ?? ?? FF 45 ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 6A ?? 8D 0C 41 8B 45 ?? + 81 F9 ?? ?? ?? ?? 89 4D ?? 59 0F 47 C1 89 45 ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 + 74 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 85 DB 74 ?? 8B 07 33 C9 66 39 08 + 74 ?? 50 FF 15 ?? ?? ?? ?? 8B 0F 33 D2 66 89 54 41 ?? 8B 45 ?? 8B 4D ?? 89 08 68 ?? + ?? ?? ?? 33 C0 50 56 8B 35 ?? ?? ?? ?? FF D6 FF 75 ?? FF 15 ?? ?? ?? ?? 85 DB 75 ?? + 68 ?? ?? ?? ?? 33 C0 50 FF 37 FF D6 8B C3 5F 5E 5B 8B E5 5D C2 + } + $find_files_v5 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 33 FF 89 54 24 ?? 8B F1 89 7C 24 ?? 39 + 7D ?? 75 ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 85 C0 75 ?? 85 DB 75 ?? 33 C0 E9 + ?? ?? ?? ?? 33 DB 43 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 66 83 3E ?? 74 ?? 8D 54 24 ?? + 89 7C 24 ?? 8B CE E8 ?? ?? ?? ?? 89 44 24 ?? 39 7C 24 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 56 8D 04 46 89 44 24 ?? FF 15 ?? ?? ?? ?? 6A ?? 57 57 8D 44 24 ?? 50 + 6A ?? 56 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 D2 89 44 24 ?? 66 89 11 83 F8 ?? 75 ?? BF + ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 + ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 44 24 ?? 50 56 FF + 15 ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? 85 DB 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? + 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8B 54 24 ?? 8B CE E8 ?? ?? ?? + ?? EB ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 57 EB ?? FF 74 24 ?? 8D 54 24 ?? 8B CE + E8 ?? ?? ?? ?? 59 8B 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? + ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? + ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 + } + $crypt_files_v5 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B D9 89 55 ?? 33 FF 89 5D ?? 21 7D ?? B9 ?? ?? + ?? ?? 89 7D ?? E8 ?? ?? ?? ?? 8B F0 89 75 ?? 85 F6 75 ?? 33 C0 E9 ?? ?? ?? ?? FF 75 + ?? 8D 55 ?? 56 8D 4D ?? E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8B CE E8 ?? ?? ?? ?? EB ?? + 33 C0 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B D8 83 FB + ?? 75 ?? 33 C0 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? + ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? FF 70 ?? FF 70 ?? 6A ?? 6A ?? 53 FF 15 + ?? ?? ?? ?? 6A ?? 58 C6 45 ?? ?? 48 75 ?? 51 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 8E ?? ?? ?? ?? 21 7D ?? 21 7D ?? 41 89 45 ?? + 8B 45 ?? 89 45 ?? E8 ?? ?? ?? ?? 8B 8E ?? ?? ?? ?? 83 C1 ?? 89 45 ?? E8 ?? ?? ?? ?? + 89 45 ?? 33 FF 6A ?? 8D 45 ?? 50 FF B6 ?? ?? ?? ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 3B 86 ?? ?? ?? ?? 8B 55 ?? 6A + ?? 59 0F 42 F9 83 7D ?? ?? 8D 8D ?? ?? ?? ?? 0F 45 7D ?? 01 86 ?? ?? ?? ?? 89 7D ?? + 83 96 ?? ?? ?? ?? ?? 8B 45 ?? 50 FF 75 ?? 89 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 33 + C9 F7 D8 41 99 51 6A ?? 52 50 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 + ?? 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 75 ?? 8B 7D ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? + 8D 45 ?? 50 57 56 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 75 ?? 8B 7D ?? 33 C0 40 01 86 + ?? ?? ?? ?? 83 96 ?? ?? ?? ?? ?? EB ?? 33 C0 8D 78 ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7D + ?? ?? 74 ?? 6A ?? 6A ?? 0F 57 C0 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? + ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B F8 89 7D ?? + E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? + 85 FF 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? 83 65 ?? ?? 83 65 ?? ?? 8B 35 ?? + ?? ?? ?? FF D6 8D 0C 45 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F8 33 C0 40 83 67 ?? + ?? 88 07 FF D6 FF 75 ?? 03 C0 89 47 ?? FF D6 8D 04 45 ?? ?? ?? ?? 50 FF 75 ?? 8D 47 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF 75 ?? FF D6 8D 04 45 ?? ?? ?? ?? 50 57 8D 45 + ?? 50 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 89 01 8B CF E8 ?? ?? ?? ?? 8B 7D ?? 8B 45 ?? FF + 70 ?? FF 70 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B + 8B E5 5D C3 + } + $remote_connection_v5 = { + 55 8B EC 83 EC ?? 53 8B 1D ?? ?? ?? ?? 56 8B F1 57 83 7E ?? ?? 74 ?? FF 76 ?? FF D3 + 8B CE E8 ?? ?? ?? ?? 33 FF 57 57 6A ?? 57 57 FF 75 ?? FF 75 ?? FF 76 ?? FF 15 ?? ?? + ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? + 83 C4 ?? B8 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 44 C8 57 51 57 57 68 + ?? ?? ?? ?? 56 8B 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? FF + 75 ?? FF 75 ?? FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 33 FF 47 EB ?? FF + 15 ?? ?? ?? ?? 8B 45 ?? 50 FF D3 56 FF D3 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B + E5 5D C2 + } + $remote_connection_v5_0_1 = { + 55 8B EC 83 EC ?? 53 8B 1D ?? ?? ?? ?? 56 8B F1 57 83 7E ?? ?? 74 ?? FF 76 ?? FF D3 + 8B CE E8 ?? ?? ?? ?? 33 FF 57 57 6A ?? 57 57 FF 75 ?? FF 75 ?? FF 76 ?? FF 15 ?? ?? + ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? + 83 C4 ?? B8 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 44 C8 57 51 57 57 68 + ?? ?? ?? ?? 56 8B 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? FF + 75 ?? FF 75 ?? FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? ?? ?? 33 C9 41 85 C0 8B 45 ?? 0F 45 + F9 50 FF D3 56 FF D3 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C2 + } + $url_parameters_setup_v5 = { + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 + ?? 8B 45 ?? 8D 8C 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? + 75 ?? 6A ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + D1 E0 A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? D1 E0 8B D0 8B 0D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A + ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? + ?? 73 ?? 83 65 ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A + ?? FF 75 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? + ?? ?? 83 7D ?? ?? 74 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B E5 5D C3 + } + $url_parameters_setup_v5_0_1 = { + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 + ?? 8B 45 ?? 8D 8C 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? + 75 ?? 6A ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + D1 E0 A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? D1 E0 8B D0 8B 0D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A + ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? + ?? 73 ?? 83 65 ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A + ?? FF 75 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? + ?? ?? 83 7D ?? ?? 74 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B E5 5D C3 + } + $crypt_files_v5_0_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B D9 89 55 ?? 33 FF 89 5D ?? 21 7D ?? B9 ?? ?? + ?? ?? 89 7D ?? E8 ?? ?? ?? ?? 8B F0 33 C0 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 50 68 ?? + ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 75 ?? 33 C0 + 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB + ?? 0F 84 ?? ?? ?? ?? 8B 7D ?? FF 77 ?? FF 77 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 6A + ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8D 45 ?? 50 68 + ?? ?? ?? ?? 56 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 81 BE ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? + 81 BE ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? FF 77 ?? FF 77 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? + ?? 53 FF 15 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? 6A ?? 6A ?? 0F 57 + C0 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? FF 75 ?? 83 65 ?? ?? 8D 55 + ?? 56 8D 4D ?? E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A ?? 58 C6 45 ?? ?? 48 75 ?? 51 68 + ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 8E ?? ?? + ?? ?? 83 65 ?? ?? 83 65 ?? ?? 41 89 45 ?? 8B 45 ?? 89 45 ?? E8 ?? ?? ?? ?? 8B 8E ?? + ?? ?? ?? 83 C1 ?? 89 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 33 FF 6A ?? 8D 45 ?? 50 FF B6 ?? + ?? ?? ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 + ?? ?? ?? ?? 3B 86 ?? ?? ?? ?? 8B 55 ?? 6A ?? 59 0F 42 F9 83 7D ?? ?? 8D 8D ?? ?? ?? + ?? 0F 45 7D ?? 01 86 ?? ?? ?? ?? 89 7D ?? 83 96 ?? ?? ?? ?? ?? 8B 45 ?? 50 FF 75 ?? + 89 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 33 C9 F7 D8 41 99 51 6A ?? 52 50 53 FF 15 ?? + ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 75 + ?? 8B 7D ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 57 56 53 FF 15 ?? ?? ?? ?? 85 + C0 74 ?? 8B 75 ?? 8B 7D ?? 33 C0 40 01 86 ?? ?? ?? ?? 83 96 ?? ?? ?? ?? ?? EB ?? 33 + C0 8D 78 ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 6A ?? 6A ?? 0F 57 C0 66 0F 13 + 45 ?? FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 53 + FF 15 ?? ?? ?? ?? 8B 4D ?? 8B F8 89 7D ?? E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B + CE E8 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? + FF 75 ?? 83 65 ?? ?? 83 65 ?? ?? 8B 35 ?? ?? ?? ?? FF D6 8D 0C 45 ?? ?? ?? ?? E8 ?? + ?? ?? ?? FF 75 ?? 8B F8 33 C0 40 83 67 ?? ?? 88 07 FF D6 FF 75 ?? 03 C0 89 47 ?? FF + D6 8D 04 45 ?? ?? ?? ?? 50 FF 75 ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF 75 + ?? FF D6 8D 04 45 ?? ?? ?? ?? 50 57 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 89 01 + 8B CF E8 ?? ?? ?? ?? 8B 7D ?? 8B 45 ?? FF 70 ?? FF 70 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? + ?? ?? 53 FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 + } + $find_files_v5_0_1 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 33 FF 89 54 24 ?? 8B F1 89 7C 24 ?? 39 + 7D ?? 75 ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 85 C0 75 ?? 85 DB 75 ?? 33 C0 E9 + ?? ?? ?? ?? 33 DB 43 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 66 83 3E ?? 74 ?? 8D 54 24 ?? + 89 7C 24 ?? 8B CE E8 ?? ?? ?? ?? 89 44 24 ?? 39 7C 24 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 56 8D 04 46 89 44 24 ?? FF 15 ?? ?? ?? ?? 6A ?? 57 57 8D 44 24 ?? 50 + 6A ?? 56 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 D2 89 44 24 ?? 66 89 11 83 F8 ?? 75 ?? BF + ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 + ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 44 24 ?? 50 56 FF + 15 ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? 85 DB 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? + 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8B 54 24 ?? 8B CE E8 ?? ?? ?? + ?? EB ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 57 EB ?? FF 74 24 ?? 8D 54 24 ?? 8B CE + E8 ?? ?? ?? ?? 59 8B 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? + ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? + ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 + } + $search_antivirus_processes_v5_0_1 = { + 55 8B EC 83 EC ?? 53 56 8B 35 ?? ?? ?? ?? BB ?? ?? ?? ?? 57 6A ?? 53 68 ?? ?? ?? ?? + 33 C0 50 FF D6 8B 7D ?? 6A ?? 53 6A ?? 33 DB 89 07 53 C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? FF D6 8B F0 85 F6 75 ?? 33 C0 E9 ?? ?? ?? ?? 53 6A ?? C7 06 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? 53 56 FF 15 ?? ?? ?? ?? EB + ?? 56 33 C9 89 5D ?? 50 89 5D ?? 89 4D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 33 C0 8D 4E ?? 89 45 ?? 51 FF 74 85 ?? FF 15 ?? ?? ?? + ?? 85 C0 74 ?? 8B 45 ?? 8D 4E ?? 40 89 45 ?? 83 F8 ?? 72 ?? EB ?? 33 C0 39 45 ?? 8D + 58 ?? 8D 46 ?? 50 FF 37 75 ?? FF 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? + ?? FF 37 FF 15 ?? ?? ?? ?? FF 45 ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 6A ?? 8D + 0C 41 8B 45 ?? 81 F9 ?? ?? ?? ?? 89 4D ?? 59 0F 47 C1 89 45 ?? 56 FF 75 ?? FF 15 ?? + ?? ?? ?? 85 C0 74 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 85 DB 74 ?? 8B 07 + 33 C9 66 39 08 74 ?? 50 FF 15 ?? ?? ?? ?? 8B 0F 33 D2 66 89 54 41 ?? 8B 45 ?? 8B 4D + ?? 89 08 68 ?? ?? ?? ?? 33 C0 50 56 8B 35 ?? ?? ?? ?? FF D6 FF 75 ?? FF 15 ?? ?? ?? + ?? 85 DB 75 ?? 68 ?? ?? ?? ?? 33 C0 50 FF 37 FF D6 8B C3 5F 5E 5B 8B E5 5D C2 + } + $set_url_parameters_v5_0_2 = { + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 + ?? 8B 45 ?? 8D 8C 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? + 75 ?? 6A ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + D1 E0 A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? D1 E0 8B D0 8B 0D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A + ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? + ?? 73 ?? 83 65 ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A + ?? FF 75 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? + ?? ?? 83 7D ?? ?? 74 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B E5 5D C3 + } + $set_url_parameters_v5_0_3 = { + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 + ?? 8B 45 ?? 8D 8C 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? + 75 ?? 6A ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + D1 E0 A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? D1 E0 8B D0 8B 0D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 73 ?? 83 65 ?? ?? 68 ?? ?? ?? ?? 8D + 45 ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A ?? FF 75 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? + 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? + ?? ?? 83 7D ?? ?? 74 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B E5 5D C3 + } + $search_antivirus_processes_v5_0_2 = { + 55 8B EC 83 EC ?? 53 56 8B 35 ?? ?? ?? ?? BB ?? ?? ?? ?? 57 6A ?? 53 68 ?? ?? ?? ?? + 33 C0 50 FF D6 8B 7D ?? 6A ?? 53 6A ?? 33 DB 89 07 53 C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? FF D6 8B F0 85 F6 75 ?? 33 C0 E9 ?? ?? ?? ?? 53 6A ?? C7 06 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? 53 56 FF 15 ?? ?? ?? ?? EB + ?? 56 33 C9 89 5D ?? 50 89 5D ?? 89 4D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 33 C0 8D 4E ?? 89 45 ?? 51 FF 74 85 ?? FF 15 ?? ?? ?? + ?? 85 C0 74 ?? 8B 45 ?? 8D 4E ?? 40 89 45 ?? 83 F8 ?? 72 ?? EB ?? 33 C0 39 45 ?? 8D + 58 ?? 8D 46 ?? 50 FF 37 75 ?? FF 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? + ?? FF 37 FF 15 ?? ?? ?? ?? FF 45 ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 6A ?? 8D + 0C 41 8B 45 ?? 81 F9 ?? ?? ?? ?? 89 4D ?? 59 0F 47 C1 89 45 ?? 56 FF 75 ?? FF 15 ?? + ?? ?? ?? 85 C0 74 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 85 DB 74 ?? 8B 07 + 33 C9 66 39 08 74 ?? 50 FF 15 ?? ?? ?? ?? 8B 0F 33 D2 66 89 54 41 ?? 8B 45 ?? 8B 4D + ?? 89 08 68 ?? ?? ?? ?? 33 C0 50 56 8B 35 ?? ?? ?? ?? FF D6 FF 75 ?? FF 15 ?? ?? ?? + ?? 85 DB 75 ?? 68 ?? ?? ?? ?? 33 C0 50 FF 37 FF D6 8B C3 5F 5E 5B 8B E5 5D C2 + } + $find_files_v5_0_2 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 33 FF 89 54 24 ?? 8B F1 89 7C 24 ?? 39 + 7D ?? 75 ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 85 C0 75 ?? 85 DB 75 ?? 33 C0 E9 + ?? ?? ?? ?? 33 DB 43 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 66 83 3E ?? 74 ?? 8D 54 24 ?? + 89 7C 24 ?? 8B CE E8 ?? ?? ?? ?? 89 44 24 ?? 39 7C 24 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 56 8D 04 46 89 44 24 ?? FF 15 ?? ?? ?? ?? 6A ?? 57 57 8D 44 24 ?? 50 + 6A ?? 56 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 75 ?? 8D 44 24 ?? 50 56 FF 15 ?? ?? + ?? ?? 89 44 24 ?? 8B 4C 24 ?? 33 D2 66 89 11 83 F8 ?? 75 ?? BF ?? ?? ?? ?? E9 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 8D + 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 44 24 ?? 50 56 FF 15 ?? ?? ?? ?? F6 44 + 24 ?? ?? 74 ?? 85 DB 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? + ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8B 54 24 ?? 8B CE E8 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? + ?? 56 FF 15 ?? ?? ?? ?? 57 EB ?? FF 74 24 ?? 8D 54 24 ?? 8B CE E8 ?? ?? ?? ?? 59 8B + 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? + ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B + 8B E5 5D C3 + } + $crypt_files_v5_0_2 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B D9 89 55 ?? 33 FF 89 5D ?? 21 7D ?? B9 ?? ?? + ?? ?? 89 7D ?? E8 ?? ?? ?? ?? 8B F0 33 C0 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 50 68 ?? + ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 75 ?? 33 C0 + 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB + ?? 0F 84 ?? ?? ?? ?? 8B 7D ?? FF 77 ?? FF 77 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 6A + ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8D 45 ?? 50 68 + ?? ?? ?? ?? 56 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 81 BE ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? + 81 BE ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? FF 77 ?? FF 77 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? + ?? 53 FF 15 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? 6A ?? 6A ?? 0F 57 + C0 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? FF 75 ?? 83 65 ?? ?? 8D 55 + ?? 56 8D 4D ?? E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A ?? 58 C6 45 ?? ?? 48 75 ?? 51 68 + ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 8E ?? ?? + ?? ?? 83 65 ?? ?? 83 65 ?? ?? 41 89 45 ?? 8B 45 ?? 89 45 ?? E8 ?? ?? ?? ?? 8B 8E ?? + ?? ?? ?? 83 C1 ?? 89 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 33 FF 6A ?? 8D 45 ?? 50 FF B6 ?? + ?? ?? ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 + ?? ?? ?? ?? 3B 86 ?? ?? ?? ?? 8B 55 ?? 6A ?? 59 0F 42 F9 83 7D ?? ?? 8D 8D ?? ?? ?? + ?? 0F 45 7D ?? 01 86 ?? ?? ?? ?? 89 7D ?? 83 96 ?? ?? ?? ?? ?? 8B 45 ?? 50 FF 75 ?? + 89 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 33 C9 F7 D8 41 99 51 6A ?? 52 50 53 FF 15 ?? + ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 75 + ?? 8B 7D ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 57 56 53 FF 15 ?? ?? ?? ?? 85 + C0 74 ?? 8B 75 ?? 8B 7D ?? 33 C0 40 01 86 ?? ?? ?? ?? 83 96 ?? ?? ?? ?? ?? EB ?? 33 + C0 8D 78 ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 6A ?? 6A ?? 0F 57 C0 66 0F 13 + 45 ?? FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 53 + FF 15 ?? ?? ?? ?? 8B 4D ?? 8B F8 89 7D ?? E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B + CE E8 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? + FF 75 ?? 83 65 ?? ?? 83 65 ?? ?? 8B 35 ?? ?? ?? ?? FF D6 8D 0C 45 ?? ?? ?? ?? E8 ?? + ?? ?? ?? FF 75 ?? 8B F8 33 C0 40 83 67 ?? ?? 88 07 FF D6 FF 75 ?? 03 C0 89 47 ?? FF + D6 8D 04 45 ?? ?? ?? ?? 50 FF 75 ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF 75 + ?? FF D6 8D 04 45 ?? ?? ?? ?? 50 57 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 89 01 + 8B CF E8 ?? ?? ?? ?? 8B 7D ?? 8B 45 ?? FF 70 ?? FF 70 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? + ?? ?? 53 FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 + } + $remote_connection_v5_0_2 = { + 55 8B EC 83 EC ?? 53 8B 1D ?? ?? ?? ?? 56 8B F1 57 83 7E ?? ?? 74 ?? FF 76 ?? FF D3 + 8B CE E8 ?? ?? ?? ?? 33 FF 57 57 6A ?? 57 57 FF 75 ?? FF 75 ?? FF 76 ?? FF 15 ?? ?? + ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? + 83 C4 ?? B8 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 44 C8 57 51 57 57 68 + ?? ?? ?? ?? 56 8B 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? FF + 75 ?? FF 75 ?? FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? ?? ?? 33 C9 41 85 C0 8B 45 ?? 0F 45 + F9 50 FF D3 56 FF D3 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C2 + } + $crypt_files_v5_0_3 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B F9 89 55 ?? 33 DB B9 ?? ?? ?? ?? 89 5D ?? E8 + ?? ?? ?? ?? 8B F0 89 75 ?? 85 F6 75 ?? 33 C0 E9 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 6A ?? + 53 53 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 6A ?? 53 + 6A ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 53 8D 45 ?? 50 68 ?? ?? ?? ?? + 56 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 81 BE ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 81 BE ?? ?? + ?? ?? ?? ?? ?? ?? 75 ?? 8B 45 ?? FF 70 ?? FF 70 ?? 53 53 57 FF 15 ?? ?? ?? ?? 57 FF + 15 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 53 53 0F 57 C0 66 0F 13 45 ?? FF + 75 ?? FF 75 ?? 57 FF 15 ?? ?? ?? ?? FF 75 ?? 8D 55 ?? 89 5D ?? 56 8D 4D ?? E8 ?? ?? + ?? ?? 59 59 85 C0 74 ?? 6A ?? 58 88 5D ?? 48 75 ?? 51 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 8E ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 41 + 8B 45 ?? 89 85 ?? ?? ?? ?? 89 5D ?? 89 5D ?? E8 ?? ?? ?? ?? 8B 8E ?? ?? ?? ?? 83 C1 + ?? 89 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 89 5D ?? 53 8D 45 ?? 50 FF B6 ?? ?? ?? ?? FF 75 + ?? 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 85 C9 0F 84 ?? ?? ?? ?? 3B + 8E ?? ?? ?? ?? 8B 45 ?? 6A ?? 5A 0F 42 C2 39 5D ?? 8B 55 ?? 0F 45 45 ?? 01 8E ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? 89 45 ?? 11 9E ?? ?? ?? ?? 8B 45 ?? 8B 75 ?? 50 56 89 45 ?? + E8 ?? ?? ?? ?? 8B 45 ?? 59 59 33 C9 F7 D8 41 99 51 53 52 50 57 FF 15 ?? ?? ?? ?? 8B + C3 89 5D ?? 83 F8 ?? 7D ?? 53 8D 45 ?? 50 FF 75 ?? 56 57 FF 15 ?? ?? ?? ?? 85 C0 75 + ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 45 ?? 40 89 45 ?? EB ?? 8B 75 ?? 33 C0 8B 4D ?? 40 01 + 86 ?? ?? ?? ?? 11 9E ?? ?? ?? ?? EB ?? 33 C0 8D 48 ?? 89 4D ?? 85 C9 0F 84 ?? ?? ?? + ?? 39 5D ?? 74 ?? 6A ?? 53 0F 57 C0 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 57 FF 15 ?? ?? + ?? ?? 53 8D 45 ?? 50 68 ?? ?? ?? ?? 56 57 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B D8 E8 ?? ?? + ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 83 FF ?? 74 ?? 8B 45 ?? 57 83 08 + ?? FF 15 ?? ?? ?? ?? 8B C3 5F 5E 5B 8B E5 5D C3 + } + $remote_connection_v5_0_3 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 68 ?? ?? ?? ?? 33 DB 8D 85 ?? ?? ?? ?? 8B F1 53 + 50 89 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B FB 0F B7 04 5E 66 85 C0 74 ?? 83 F8 ?? 75 ?? + 83 C3 ?? 56 89 5D ?? FF 15 ?? ?? ?? ?? 3B D8 73 ?? 8D 14 1B 0F B7 04 32 EB ?? 66 83 + F8 ?? 74 ?? 43 0F B7 04 5E 66 85 C0 75 ?? EB ?? 8B CB 2B 4D ?? 74 ?? 03 F2 8D BD ?? + ?? ?? ?? D1 E9 F3 A5 13 C9 66 F3 A5 8B 75 ?? 8D 43 ?? 8D 04 46 50 8D 85 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 33 FF 47 43 85 FF 74 ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 15 ?? ?? ?? + ?? 8D 7D ?? 6A ?? 59 BE ?? ?? ?? ?? F3 A5 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 85 + FF 74 ?? 51 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 83 EC ?? 57 FF 15 ?? ?? ?? + ?? 50 57 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B CF 8B + F0 E8 ?? ?? ?? ?? EB ?? 33 F6 83 7D ?? ?? 74 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 8B C6 + 5E 5B 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ( all of ($enum_resources_*)) and ($find_files) and ( all of ($encrypt_files_*)) + uint16(0)==0x5A4D and (($search_antivirus_processes and $find_files and $crypt_files and $remote_connection) or ($find_files_v2 and $crypt_files_v2 and $search_antivirus_processes_v2 and $remote_connection_v2) or ($search_antivirus_processes_v2 and $find_files_v2_1 and $crypt_files_v2_1 and $remote_connection_v2_1) or ($search_antivirus_processes_v4_1_2 and $find_files_v4_1_2 and $crypt_files_v4_1_2 and $remote_connection_v4_1_2 and $url_parameters_setup_v4_1_2) or ($search_antivirus_processes_v4 and $find_files_v4 and $crypt_files_v4 and $url_parameters_setup_v4) or ($search_antivirus_processes_v2 and $find_files_v2_1 and $remote_connection_v2_1 and $crypt_files_v3) or ($search_antivirus_processes_v5 and $find_files_v5 and $crypt_files_v5 and $remote_connection_v5 and $url_parameters_setup_v5) or ($search_antivirus_processes_v5_0_1 and $find_files_v5_0_1 and $crypt_files_v5_0_1 and $url_parameters_setup_v5_0_1 and $remote_connection_v5_0_1) or ($search_antivirus_processes_v5_0_2 and $find_files_v5_0_2 and $crypt_files_v5_0_2 and $set_url_parameters_v5_0_2 and $remote_connection_v5_0_2) or ($search_antivirus_processes_v5_0_2 and $find_files_v5_0_2 and $crypt_files_v5_0_3 and $set_url_parameters_v5_0_3 and $remote_connection_v5_0_3)) } -rule REVERSINGLABS_Win32_Ransomware_Armage : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win64_Ransomware_Solaso : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Armage ransomware." + description = "Yara rule that detects Solaso ransomware." author = "ReversingLabs" - id = "94cf639b-7d9e-51ca-b547-e0d591581df2" - date = "2020-07-15" - modified = "2020-07-15" + id = "53f56ad8-ccdf-58f0-a5d9-e58f2c18ac76" + date = "2021-11-02" + modified = "2021-11-02" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Armage.yara#L1-L128" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "aa8ddcbb0fdcad15e603e000db1d4f86eae7d42efce1c1d21dc3dd57ee9f4319" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Solaso.yara#L1-L171" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "368a80a9f2e264d17c61d6ed4c22baec838ba0b0bc2e5c79344830bf861aa5a2" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -31538,118 +33252,161 @@ rule REVERSINGLABS_Win32_Ransomware_Armage : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Armage" + tc_detection_name = "Solaso" tc_detection_factor = 5 importance = 25 strings: + $find_files_p1 = { + C6 85 ?? ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 45 ?? 4C 89 AD ?? ?? ?? ?? 48 8D 85 + ?? ?? ?? ?? 48 89 45 ?? B1 ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 90 4C 8D 05 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 90 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8D + 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B BD + ?? ?? ?? ?? 4C 8B BD ?? ?? ?? ?? 49 3B FF 0F 84 ?? ?? ?? ?? 66 0F 1F 44 00 ?? 48 8D + 95 ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? 90 48 8D 95 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? + ?? 48 0F 43 95 ?? ?? ?? ?? 4C 8B 85 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 48 8B C8 E8 ?? ?? ?? ?? 4C 89 AD ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 + ?? ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 48 0F 43 95 ?? ?? ?? ?? + 4C 8B 85 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B CF 48 83 7F ?? ?? 72 + ?? 48 8B 0F BA ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? + 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 44 24 ?? 4C 89 AD ?? + ?? ?? ?? 4C 89 AD ?? ?? ?? ?? 48 8B B5 ?? ?? ?? ?? 4C 8D B5 ?? ?? ?? ?? 48 83 BD ?? + ?? ?? ?? ?? 4C 0F 43 B5 ?? ?? ?? ?? 48 83 FE ?? 73 ?? 41 0F 10 06 0F 11 85 ?? ?? ?? + ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 + } + $find_files_p2 = { + 8B DE 48 83 CB ?? 48 3B D8 48 0F 47 D8 48 8D 4B ?? 48 81 F9 ?? ?? ?? ?? 72 ?? 48 8D + 41 ?? 48 3B C1 0F 86 ?? ?? ?? ?? 0F AE E8 48 8B C8 E8 ?? ?? ?? ?? 48 8B C8 48 85 C0 + 0F 84 ?? ?? ?? ?? 48 83 C0 ?? 48 83 E0 ?? 48 89 48 ?? EB ?? 48 85 C9 74 ?? 0F AE E8 + E8 ?? ?? ?? ?? EB ?? 49 8B C5 48 89 85 ?? ?? ?? ?? 4C 8D 46 ?? 49 8B D6 48 8B C8 E8 + ?? ?? ?? ?? 48 89 9D ?? ?? ?? ?? 48 89 B5 ?? ?? ?? ?? 4C 89 6D ?? 4C 89 6D ?? 48 8B + B5 ?? ?? ?? ?? 4C 8D B5 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 4C 0F 43 B5 ?? ?? ?? ?? + 48 83 FE ?? 73 ?? 41 0F 10 06 0F 11 45 ?? 48 C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 + B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 45 ?? 48 8B DE 48 83 CB ?? 48 89 5D ?? 48 3B D8 48 + 0F 47 D8 48 8D 4B ?? 48 81 F9 ?? ?? ?? ?? 72 ?? 48 8D 41 ?? 48 3B C1 0F 86 ?? ?? ?? + ?? 0F AE E8 48 8B C8 E8 ?? ?? ?? ?? 48 8B C8 48 85 C0 0F 84 ?? ?? ?? ?? 48 83 C0 ?? + 48 83 E0 ?? 48 89 48 ?? EB ?? 48 85 C9 74 ?? 0F AE E8 E8 ?? ?? ?? ?? EB ?? 49 8B C5 + 48 89 45 ?? 4C 8D 46 ?? 49 8B D6 48 8B C8 E8 ?? ?? ?? ?? 48 89 5D ?? 48 89 75 ?? 4C + 8D 85 ?? ?? ?? ?? 48 8D 55 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 8D + } $encrypt_files_p1 = { - 55 89 E5 53 8D 5D ?? 81 EC ?? ?? ?? ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 89 5D ?? 8D 5D - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 65 ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 45 - ?? 8D 50 ?? 8D 48 ?? C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C6 40 ?? ?? 89 50 ?? 89 - 95 ?? ?? ?? ?? 8D 50 ?? 89 50 ?? 89 95 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 5D ?? 83 EC ?? 89 5D ?? - 8B 41 ?? 8B 51 ?? 8D 4D ?? 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 45 ?? 8D 5D ?? 83 EC ?? 89 5C 24 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 45 ?? 8D 5D ?? 39 D8 74 ?? 89 04 24 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? 89 42 ?? 8B 55 ?? 89 4C 24 ?? 89 04 24 29 CA 89 54 24 - ?? E8 ?? ?? ?? ?? 8B 55 ?? 89 42 ?? 8B 42 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 55 ?? 89 42 - ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 55 ?? - 8B 42 ?? 89 04 24 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 8D ?? - ?? ?? ?? 89 4C 24 ?? 89 85 ?? ?? ?? ?? 89 44 24 ?? 8B 55 ?? 8B 42 ?? 89 04 24 E8 ?? - ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 4C 24 ?? 89 8D ?? ?? ?? ?? 89 4C 24 ?? 8B 85 ?? ?? ?? - ?? 89 44 24 ?? 8B 55 ?? 8B 42 ?? 89 04 24 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 44 24 - ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 89 5C 24 ?? 8B 8D ?? - ?? ?? ?? 89 4C 24 ?? 89 85 ?? ?? ?? ?? 89 44 24 ?? 8B 55 ?? 8B 42 ?? 89 04 24 E8 ?? - ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? 8D 45 ?? 89 04 24 E8 + 48 63 53 ?? 48 89 B5 ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 45 33 + C0 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 55 ?? 48 83 BD ?? ?? ?? ?? ?? 48 0F 43 55 ?? + 4C 63 43 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 89 4B ?? 48 85 C9 0F 84 + ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 3B CA 77 ?? 48 89 8D ?? ?? ?? ?? 48 8D 45 ?? 48 + 83 BD ?? ?? ?? ?? ?? 48 0F 43 45 ?? C6 04 01 ?? EB ?? 48 8B F1 48 2B F2 4C 8B 85 ?? + ?? ?? ?? 49 8B C0 48 2B C2 48 3B F0 77 ?? 48 89 8D ?? ?? ?? ?? 48 8D 7D ?? 49 83 F8 + ?? 48 0F 43 7D ?? 48 03 FA 4C 8B C6 33 D2 48 8B CF E8 ?? ?? ?? ?? C6 04 37 ?? EB ?? + 0F AE E8 C6 44 24 ?? ?? 4C 8B CE 48 8B D6 48 8D 4D ?? E8 ?? ?? ?? ?? 33 F6 8B 43 ?? + 99 41 F7 FD B9 ?? ?? ?? ?? 85 C0 0F 45 C8 89 4B ?? 83 F9 ?? 0F 8C ?? ?? ?? ?? 4C 63 + C9 4C 8D 45 ?? 48 8D 54 24 ?? E8 ?? ?? ?? ?? 48 8B F8 48 3B D8 74 ?? 48 8B 0B 48 85 } $encrypt_files_p2 = { - 8B 55 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? 8D 4A ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D - 55 ?? 83 EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? - ?? 8B 40 ?? 8B 80 ?? ?? ?? ?? 85 C0 89 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 80 78 ?? ?? 74 ?? 0F BE 40 ?? 89 04 24 B9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 EC ?? 89 C1 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? - 8B 45 ?? 85 C0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 5D - ?? C9 C3 90 8B 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 8B 00 8B 50 ?? B8 ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 74 ?? C7 04 24 ?? ?? ?? ?? 8B 8D ?? - ?? ?? ?? FF D2 83 EC ?? 0F BE C0 E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C5 ?? 8B 45 ?? 89 - 85 ?? ?? ?? ?? 8B 45 ?? 85 C0 74 ?? 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 83 - E8 ?? 74 ?? 0F 0B 8B 45 ?? 8D 55 ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 - C0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? 3B 85 ?? ?? ?? ?? 74 ?? 89 04 24 - E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? 39 85 ?? ?? ?? ?? 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 39 D0 - 75 ?? EB + C9 74 ?? 48 8B 53 ?? E8 ?? ?? ?? ?? 48 8B 0B 48 8B 53 ?? 48 2B D1 48 83 E2 ?? 48 81 + FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 4C 8B 41 ?? 49 2B C8 48 8D 41 ?? 48 83 F8 ?? 0F 87 + ?? ?? ?? ?? 49 8B C8 E8 ?? ?? ?? ?? 48 89 33 48 89 73 ?? 48 89 73 ?? 48 8B 07 48 89 + 03 48 8B 47 ?? 48 89 43 ?? 48 8B 47 ?? 48 89 43 ?? 48 89 37 48 89 77 ?? 48 89 77 ?? + 48 8B 4C 24 ?? 48 85 C9 74 ?? 48 8B 54 24 ?? E8 ?? ?? ?? ?? 48 8B 54 24 ?? 48 8B 4C + 24 ?? 48 2B D1 48 83 E2 ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 + ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 74 24 ?? + 0F 57 C0 F3 0F 7F 44 24 ?? EB ?? 48 8B 0B 48 8D 45 ?? 48 3B C8 74 ?? 48 8D 55 ?? 48 + 83 BD ?? ?? ?? ?? ?? 48 0F 43 55 ?? 4C 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B CB E8 + ?? ?? ?? ?? 45 33 C0 48 8D 15 ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 83 7B ?? ?? 74 + ?? 33 FF 0F 1F 40 ?? 66 0F 1F 84 00 ?? ?? 00 00 4C 8B 03 4C 03 C7 49 8B D0 49 83 78 + ?? ?? 72 ?? 49 8B 10 4D 8B 40 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 48 63 CE 48 C1 E1 ?? 48 } - $find_files_p1 = { - 55 89 E5 81 EC ?? ?? ?? ?? 8D 55 ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 89 55 ?? 8D 55 ?? 89 65 ?? 89 14 24 E8 ?? ?? ?? ?? 8B 45 ?? - 8B 4D ?? 83 C0 ?? 8B 51 ?? 89 45 ?? 8D 45 ?? 89 45 ?? 8B 45 ?? 89 55 ?? 8B 00 89 C1 - 89 45 ?? 01 D1 74 ?? 85 C0 75 ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 45 ?? 83 F8 ?? 89 45 ?? 0F 87 ?? ?? ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 8B - 45 ?? 8D 55 ?? 0F B6 00 88 45 ?? B8 ?? ?? ?? ?? 89 45 ?? C6 04 02 ?? B8 ?? ?? ?? ?? - 2B 45 ?? 83 F8 ?? 0F 86 ?? ?? ?? ?? 8D 4D ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 EC ?? 89 44 24 ?? 8B 45 ?? 89 - 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 83 EC ?? 89 81 ?? ?? ?? - ?? 8D 4D ?? 39 CA 74 ?? 89 14 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 80 ?? ?? ?? ?? 83 F8 + $encrypt_files_p3 = { + 03 0B 45 33 C0 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 0B 48 03 CF 48 C7 41 ?? ?? + ?? ?? ?? 48 83 79 ?? ?? 72 ?? 48 8B 09 C6 01 ?? FF C6 48 83 C7 ?? 3B 73 ?? 75 ?? 48 + 8D 55 ?? 48 83 BD ?? ?? ?? ?? ?? 48 0F 43 55 ?? 4C 8B 85 ?? ?? ?? ?? 48 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 90 48 8B 95 ?? ?? ?? ?? 48 83 FA ?? 72 ?? 48 FF C2 48 8B 4D ?? + 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 + 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 63 48 ?? 33 F6 F6 44 0C + ?? ?? 75 ?? E9 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 83 FA ?? 72 ?? 48 FF C2 48 8B 4D + ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? + 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 3D ?? ?? ?? ?? 48 8D 4C 24 ?? E8 + ?? ?? ?? ?? BB ?? ?? ?? ?? 48 85 C0 75 ?? 48 8B 44 24 ?? 48 63 48 ?? 48 8D 44 24 ?? + 48 03 C8 41 8B D4 48 83 79 ?? ?? 0F 45 D3 0B 51 ?? 45 33 C0 E8 ?? ?? ?? ?? 48 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 85 C0 75 ?? 48 8B 85 ?? ?? ?? ?? 48 63 48 ?? 48 8D 85 + ?? ?? ?? ?? 48 03 C8 48 83 79 ?? ?? 44 0F 45 E3 44 0B 61 ?? 45 33 C0 41 8B D4 E8 ?? + ?? ?? ?? 90 48 8B 85 ?? ?? ?? ?? 48 63 48 ?? 48 89 BC 0D ?? ?? ?? ?? 48 8B 85 ?? ?? + ?? ?? 48 63 48 ?? 8D 91 ?? ?? ?? ?? 89 94 0D ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 63 48 ?? 48 8D 05 ?? ?? ?? ?? 48 89 84 0D ?? ?? ?? + ?? 48 8B 85 ?? ?? ?? ?? 48 63 48 ?? 8D 51 ?? 89 94 0D ?? ?? ?? ?? 48 8D 1D ?? ?? ?? + ?? 48 89 9D ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B 44 24 ?? 48 63 } - $find_files_p2 = { - 8B 45 ?? 0F 95 00 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? C9 C2 ?? ?? 8D 76 ?? 8D 45 ?? 8B - 4D ?? 89 4C 24 ?? 8B 4D ?? 89 04 24 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? E9 - ?? ?? ?? ?? 8D 45 ?? 8D 4D ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B 55 ?? 83 EC ?? 89 45 ?? 89 55 ?? EB ?? C7 04 24 ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C5 ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 85 C0 74 ?? 83 E8 - ?? 74 ?? 0F 0B 8B 45 ?? 8D 55 ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 - 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 66 90 55 89 E5 57 56 8D 45 ?? 53 83 EC ?? - 89 45 ?? 8D 45 ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? 89 65 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 5D ?? C6 45 ?? ?? 8B 83 ?? ?? ?? - ?? 83 F8 ?? 74 ?? 8D 53 ?? 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 EC ?? 85 C0 0F 95 45 ?? 0F B6 45 ?? 8B 75 ?? 88 06 8B 45 ?? 89 04 24 E8 ?? ?? ?? - ?? 0F B6 45 ?? 8D 65 ?? 5B 5E 5F 5D C3 + $encrypt_files_p4 = { + 48 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 0C ?? 48 8B 44 24 ?? 48 63 48 ?? 8D 91 ?? ?? ?? + ?? 89 54 0C ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 63 48 ?? 48 8D 05 ?? + ?? ?? ?? 48 89 44 0C ?? 48 8B 44 24 ?? 48 63 48 ?? 8D 51 ?? 89 54 0C ?? 48 89 5D ?? + 48 8D 4D ?? E8 ?? ?? ?? ?? 90 49 8B 57 ?? 48 83 FA ?? 72 ?? 49 8B 0F 48 FF C2 48 81 + FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 4C 8B 41 ?? 49 2B C8 48 8D 41 ?? 48 83 F8 ?? 0F 87 + ?? ?? ?? ?? 49 8B C8 E8 ?? ?? ?? ?? 49 89 77 ?? 49 C7 47 ?? ?? ?? ?? ?? 41 C6 07 ?? + 49 8B 56 ?? 48 83 FA ?? 72 ?? 48 FF C2 49 8B 0E 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 + ?? 4C 8B 41 ?? 49 2B C8 48 8D 41 ?? 48 83 F8 ?? 77 ?? 49 8B C8 E8 ?? ?? ?? ?? 49 89 + 76 ?? 49 C7 46 ?? ?? ?? ?? ?? 41 C6 06 ?? 48 8B 8D ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? + ?? 48 8B 9C 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5E 41 5D 41 5C 5F 5E 5D C3 + E8 } - $enum_resources_p1 = { - 55 B8 ?? ?? ?? ?? 89 E5 E8 ?? ?? ?? ?? 29 C4 8D 45 ?? 89 8D ?? ?? ?? ?? 89 A5 ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 44 24 ?? 8B 45 - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C9 C2 ?? ?? - 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 44 - 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 85 C0 75 ?? 8D 85 ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 85 C0 75 ?? EB - ?? 8D B4 26 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? F6 40 ?? ?? 0F 85 ?? ?? ?? ?? 83 85 ?? ?? - ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B 85 ?? ?? ?? ?? 0F 83 + $encrypt_files_p5 = { + 48 8B C4 48 89 58 ?? 48 89 70 ?? 48 89 78 ?? 4C 89 40 ?? 55 41 54 41 55 41 56 41 57 + 48 8D 68 ?? 48 81 EC ?? ?? ?? ?? 45 8B E1 49 8B D8 44 8B 4D ?? 48 8B FA 44 8B 45 ?? + 48 8B F1 41 8B D4 48 8D 4D ?? E8 ?? ?? ?? ?? 0F 10 00 F2 0F 10 48 ?? 0F 11 45 ?? 66 + 0F 73 D8 ?? 66 49 0F 7E C7 F2 0F 11 4D ?? 49 C1 EF ?? F2 0F 11 4D ?? 4C 89 7D ?? 41 + 83 FF ?? 75 ?? E8 ?? ?? ?? ?? 33 F6 89 30 83 0F ?? E8 ?? ?? ?? ?? 8B 00 E9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 89 07 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? 33 F6 89 30 83 0F ?? E8 ?? ?? + ?? ?? C7 00 ?? ?? ?? ?? EB ?? 8B 4D ?? 4C 8D 4D ?? 4C 8B 75 ?? 41 8B C4 48 8B 55 ?? + 45 8B C7 C1 E8 ?? 49 C1 EE ?? F7 D0 44 0B 75 ?? 83 E0 ?? C7 06 ?? ?? ?? ?? 33 F6 48 + 89 74 24 ?? 44 89 74 24 ?? 89 4C 24 ?? 48 8B CB 48 C1 EA ?? C7 45 ?? ?? ?? ?? ?? 48 + 89 75 ?? 89 45 ?? 4C 89 75 ?? FF 15 ?? ?? ?? ?? 8B 5D ?? B9 ?? ?? ?? ?? 4C 8B E8 48 + 83 F8 ?? 75 ?? 8B C3 23 C1 3B C1 75 ?? 41 F6 C4 ?? 74 ?? 8B 4D ?? 4C 8D 4D ?? 48 89 + 74 24 ?? 0F BA F3 ?? 89 5D ?? 45 8B C7 48 8B 55 ?? 44 89 74 24 ?? 89 4C 24 ?? 48 8B } - $enum_resources_p2 = { - 8B 85 ?? ?? ?? ?? F6 40 ?? ?? 74 ?? 8B 40 ?? 89 C2 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 85 D2 89 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? 74 ?? 89 14 24 E8 ?? ?? ?? ?? 03 85 ?? ?? - ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 8B 48 ?? 3B 48 ?? 0F 84 ?? ?? ?? - ?? 85 C9 74 ?? 8D 41 ?? 8B 95 ?? ?? ?? ?? 89 01 8B 85 ?? ?? ?? ?? 01 C2 89 04 24 89 - 54 24 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 8B - 48 ?? 8B 85 ?? ?? ?? ?? 83 C1 ?? 89 48 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 39 C8 - 0F 84 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? F6 40 ?? ?? 0F 84 ?? ?? - ?? ?? 89 04 24 8B 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC - ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 0C 24 89 44 24 ?? 8B 8D ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? EB + $encrypt_files_p6 = { + 4D ?? 48 C1 EA ?? FF 15 ?? ?? ?? ?? 4C 8B E8 48 83 F8 ?? 75 ?? 48 63 0F 4C 8D 3D ?? + ?? ?? ?? 48 8B C1 83 E1 ?? 48 C1 F8 ?? 48 8D 0C C9 49 8B 04 C7 80 64 C8 ?? ?? FF 15 + ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? 85 C0 75 + ?? FF 15 ?? ?? ?? ?? 8B C8 8B D8 E8 ?? ?? ?? ?? 48 63 17 4C 8D 3D ?? ?? ?? ?? 48 8B + CA 83 E2 ?? 48 C1 F9 ?? 48 8D 14 D2 49 8B 0C CF 80 64 D1 ?? ?? 49 8B CD FF 15 ?? ?? + ?? ?? 85 DB 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E9 ?? ?? ?? ?? 44 8A + 75 ?? 83 F8 ?? 75 ?? 41 80 CE ?? EB ?? 83 F8 ?? 75 ?? 41 80 CE ?? 8B 0F 49 8B D5 E8 + ?? ?? ?? ?? 48 63 0F 4C 8D 3D ?? ?? ?? ?? 48 8B C1 41 80 CE ?? 48 C1 F8 ?? 83 E1 ?? + 44 88 75 ?? 49 8B 04 C7 48 8D 0C C9 44 88 74 C8 ?? 48 63 0F 48 8B C1 83 E1 ?? 48 C1 + F8 ?? 48 8D 0C C9 49 8B 04 C7 40 88 74 C8 ?? 41 F6 C4 ?? 74 ?? 8B 0F E8 ?? ?? ?? ?? + 89 45 ?? 85 C0 74 ?? 8B 0F E8 ?? ?? ?? ?? 8B 45 ?? E9 ?? ?? ?? ?? 0F 10 45 ?? 4C 8D + 4D ?? 8B 0F F2 0F 10 4D ?? 48 8D 55 ?? 45 8B C4 0F 29 45 ?? 40 88 75 ?? F2 0F 11 4D + ?? E8 ?? ?? ?? ?? 48 63 0F 89 45 ?? 85 C0 75 ?? 48 8B C1 48 C1 F9 ?? 83 E0 ?? 49 8B + } + $encrypt_files_p7 = { + 0C CF 48 8D 14 C0 8A 45 ?? 88 44 D1 ?? 48 63 0F 48 8B C1 83 E1 ?? 48 C1 F8 ?? 48 8D + 14 C9 49 8B 0C C7 41 8B C4 C1 E8 ?? 24 ?? 80 64 D1 ?? ?? 08 44 D1 ?? 41 F6 C6 ?? 75 + ?? 41 F6 C4 ?? 74 ?? 48 63 0F 48 8B C1 83 E1 ?? 48 C1 F8 ?? 48 8D 0C C9 49 8B 04 C7 + 80 4C C8 ?? ?? B9 ?? ?? ?? ?? 8B C3 23 C1 3B C1 0F 85 ?? ?? ?? ?? 41 F6 C4 ?? 0F 84 + ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? 48 8B 4D ?? 4C 8D 4D ?? 44 8B 45 ?? 0F BA F3 + ?? 48 89 74 24 ?? 89 4C 24 ?? 8B 4D ?? 89 4C 24 ?? 48 8B 4D ?? 89 5D ?? 48 8B 55 ?? + 48 C1 EA ?? FF 15 ?? ?? ?? ?? 48 8B D0 48 83 F8 ?? 75 ?? FF 15 ?? ?? ?? ?? 8B C8 E8 + ?? ?? ?? ?? 48 63 0F 48 8B C1 83 E1 ?? 48 C1 F8 ?? 48 8D 0C C9 49 8B 04 C7 80 64 C8 + ?? ?? 8B 0F E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 63 0F 48 8B C1 48 C1 F8 ?? 83 E1 ?? 49 + 8B 04 C7 48 8D 0C C9 48 89 54 C8 ?? 33 C0 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? 49 8B + 73 ?? 49 8B 7B ?? 49 8B E3 41 5F 41 5E 41 5D 41 5C 5D C3 } condition: - uint16(0)==0x5A4D and ( all of ($enum_resources_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Saturn : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win64_Ransomware_Awesomescott : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Saturn ransomware." + description = "Yara rule that detects AwesomeScott ransomware." author = "ReversingLabs" - id = "70a8d937-aee5-54d8-9409-c5d2d0830a2b" - date = "2020-10-19" - modified = "2020-10-19" + id = "36d3b801-dbdb-585a-ac80-1827a6749c87" + date = "2020-09-16" + modified = "2020-09-16" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Saturn.yara#L1-L105" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "efa748346ad8c46e654542d302e81d633a2d12f421636c477431a12a34636132" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.AwesomeScott.yara#L1-L101" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ed8096a4abbd015f79f4ec7239cd4070194ad70fa03da6714e499a41f9fb9423" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -31657,99 +33414,104 @@ rule REVERSINGLABS_Win32_Ransomware_Saturn : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Saturn" + tc_detection_name = "AwesomeScott" tc_detection_factor = 5 importance = 25 strings: - $find_files_1 = { - 6A ?? C6 45 ?? ?? 8D 4D ?? 8B 3B 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? 3B C8 74 ?? - 83 78 ?? ?? 8B C8 72 ?? 8B 08 FF 70 ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 - 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 - ?? ?? 8D 4D ?? 6A ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 - ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A - } - $find_files_2_p1 = { - 68 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? - ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? FF B5 - ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 8D 4D ?? 83 7D ?? ?? 8B 55 ?? 0F 43 4D ?? 50 51 E8 - ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 85 ?? ?? ?? ?? FF 75 - ?? 0F 43 85 ?? ?? ?? ?? 8D 4D ?? 83 7D ?? ?? 8B 55 ?? 0F 43 4D ?? 50 51 E8 ?? ?? ?? - ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? FF 75 ?? 0F 43 45 ?? 8D - 4D ?? 83 7D ?? ?? 8B 55 ?? 0F 43 4D ?? 50 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 - ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? FF 75 ?? 0F 43 45 ?? 8D 4D ?? 83 7D ?? ?? 8B 55 ?? - 0F 43 4D ?? 50 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 51 8D 85 ?? ?? - ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 51 8D 85 ?? ?? ?? ?? 50 - 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? - E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? - ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 - } - $find_files_2_p2 = { - F8 ?? 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 8D ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF - 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 5D ?? 8B F0 80 - BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 00 - ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B D0 - 8D 71 ?? 8A 01 41 84 C0 75 ?? 2B CE 8D 85 ?? ?? ?? ?? 51 50 8B CA E8 ?? ?? ?? ?? F6 - 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 84 DB 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 95 - ?? ?? ?? ?? 53 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 0F 84 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C6 E9 - } $encrypt_files_p1 = { - 6A ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 89 9D ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 6A ?? FF B5 - ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? - 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? FF D6 8B D8 - 83 FB ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 57 - FF D6 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? - ?? ?? B9 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 - A5 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? - FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? - ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 6A ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? 8B F0 FF 15 ?? - ?? ?? ?? 85 F6 0F 95 C3 E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 F6 89 B5 ?? ?? ?? ?? 56 53 FF - } + 48 8B C4 48 89 58 ?? 48 89 68 ?? 48 89 70 ?? 57 41 54 41 55 41 56 41 57 48 83 EC ?? + 45 33 FF 4C 8B F2 49 8B D8 4C 89 78 ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 4C + 89 78 ?? 4C 89 78 ?? 4C 89 78 ?? 4C 89 78 ?? B8 ?? ?? ?? ?? 48 8B F1 45 33 C9 44 8B + C0 8B D0 49 8B CE 45 32 ED 48 83 CD ?? 49 8B FF FF 15 ?? ?? ?? ?? 4C 8B E0 48 3B C5 + 75 ?? FF 15 ?? ?? ?? ?? 8B D8 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 48 ?? E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 8D 48 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 83 C0 ?? 44 8B C3 48 8B C8 E8 ?? ?? + ?? ?? E9 ?? ?? ?? ?? 45 33 C9 4C 89 7C 24 ?? 48 8B CB 41 8D 51 ?? 45 8D 41 ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B E8 48 83 F8 ?? 75 + ?? FF 15 ?? ?? ?? ?? 8B D8 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 48 ?? E8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 8D 48 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 83 C0 ?? 44 8B C3 48 8B C8 E8 ?? ?? ?? + ?? E9 ?? ?? ?? ?? BB ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 8D 4C 24 ?? 33 D2 44 8B CB + } $encrypt_files_p2 = { - 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 56 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF D7 85 C0 0F 84 ?? ?? ?? ?? 8D 56 ?? 8B 85 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 03 C8 8D 85 ?? ?? ?? ?? - 3B 8D ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 50 6A ?? 0F 44 F2 56 6A ?? - FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 - ?? ?? ?? ?? 6A ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF D7 BA ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 53 FF D6 FF B5 - ?? ?? ?? ?? FF D6 B3 ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? - ?? ?? ?? 72 ?? F6 C1 ?? 75 ?? 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 ?? 72 ?? 83 F9 ?? 77 - ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8A C3 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B - 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 + 44 89 7C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? + 4C 8D 05 ?? ?? ?? ?? 48 8D 4C 24 ?? 44 8B CB 33 D2 C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 4C + 24 ?? 48 8D 44 24 ?? 45 33 C9 45 33 C0 BA ?? ?? ?? ?? 48 89 44 24 ?? FF 15 ?? ?? ?? + ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 0D ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8D 15 ?? ?? ?? ?? 44 8B C0 45 33 C9 FF 15 + ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 8B + 44 24 ?? 48 8B 4C 24 ?? 48 8D 44 24 ?? 41 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 44 24 + ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? E9 ?? ?? ?? + ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B F8 48 85 C0 75 ?? 41 B8 ?? ?? ?? ?? 48 8D 15 + ?? ?? ?? ?? E9 ?? ?? ?? ?? 32 DB 90 4C 8D 4C 24 ?? 41 B8 ?? ?? ?? ?? 48 8B D7 49 8B + CC 4C 89 7C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 81 7C 24 ?? ?? ?? ?? ?? + 48 8B 4C 24 ?? B8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 0F B6 DB 0F 42 D8 48 8D 44 24 + ?? 45 33 C9 48 89 44 24 ?? 44 0F B6 C3 33 D2 48 89 7C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 + } + $encrypt_files_p3 = { + 74 ?? 44 8B 44 24 ?? 4C 8D 4C 24 ?? 48 8B D7 48 8B CD 4C 89 7C 24 ?? FF 15 ?? ?? ?? + ?? 85 C0 74 ?? 84 DB 0F 84 ?? ?? ?? ?? 41 B5 ?? EB ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? + ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 48 8D + 15 ?? ?? ?? ?? 44 8B C0 48 8B CE E8 ?? ?? ?? ?? 4D 85 E4 74 ?? 49 8B CC FF 15 ?? ?? + ?? ?? 48 85 ED 74 ?? 48 8B CD FF 15 ?? ?? ?? ?? 48 85 FF 74 ?? 48 8B CF E8 ?? ?? ?? + ?? 48 8B 4C 24 ?? 48 85 C9 74 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 8B + D8 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 48 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C + 8D 05 ?? ?? ?? ?? 48 8D 48 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 + 8D 15 ?? ?? ?? ?? 48 83 C0 ?? 44 8B C3 48 8B C8 E8 ?? ?? ?? ?? 4C 89 7C 24 ?? 48 8B + 4C 24 ?? 48 85 C9 74 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 8B D8 E8 ?? + ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 48 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? + ?? ?? ?? 48 8D 48 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 15 ?? + ?? ?? ?? 48 83 C0 ?? 44 8B C3 48 8B C8 E8 ?? ?? ?? ?? 48 8B 4C 24 } + $find_files = { + E8 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 33 F6 33 D2 41 B8 ?? ?? ?? ?? 66 89 B4 24 ?? + ?? 00 00 E8 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 8B D7 FF 15 + ?? ?? ?? ?? 48 8D 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 83 + F8 ?? 0F 84 ?? ?? ?? ?? 0F 1F 40 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? 41 B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? 41 + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? 4C 8D 44 + 24 ?? 48 8D 8C 24 ?? ?? ?? ?? 48 8B D7 FF 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? + ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D + 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? + ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? + ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 + 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C + 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? + FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 + ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? + ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? + 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? 8B 44 24 ?? A8 ?? 0F 85 ?? ?? ?? ?? A8 ?? 0F 85 ?? ?? ?? ?? 48 8D + 8C 24 ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? 66 89 B4 24 ?? ?? 00 00 E8 ?? ?? ?? ?? 48 + 8D 8C 24 ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? 66 89 B4 24 ?? ?? 00 00 E8 ?? ?? ?? ?? + 4C 8D 44 24 ?? 48 8D 8C 24 ?? ?? ?? ?? 48 8B D7 FF 15 ?? ?? ?? ?? 4C 8D 84 24 ?? ?? + ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 39 74 24 ?? 76 + ?? 4C 8D 0D ?? ?? ?? ?? 4C 8D 84 24 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 8D 4C 24 + ?? E8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 48 8B CB FF 15 + } condition: - uint16(0)==0x5A4D and ( all of ($find_files_*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and $find_files and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Sanwai : TC_DETECTION MALICIOUS MALWARE FILE +import "pe" + +rule REVERSINGLABS_Win32_Ransomware_Bitcrypt : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Sanwai ransomware." + description = "Yara rule that detects BitCrypt ransomware." author = "ReversingLabs" - id = "01912621-4a34-5e34-8542-5b561e8da567" - date = "2021-11-11" - modified = "2021-11-11" + id = "f00a0fd8-31a9-5ee6-b560-09ccf6fe490b" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Sanwai.yara#L1-L71" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "a7a95b2403fe539dce0d856cc1c04d15440677ea39c0a22e818b42333a64e92c" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.BitCrypt.yara#L3-L112" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "66cfe16a182e7f20d6358be9569ada5e6c36c94d44781d8c741638e1b174d44e" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -31757,64 +33519,106 @@ rule REVERSINGLABS_Win32_Ransomware_Sanwai : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Sanwai" + tc_detection_name = "BitCrypt" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? - 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 55 ?? 8B D9 83 7B ?? ?? 8B F3 8B 45 ?? 8B 7D - ?? 89 45 ?? 72 ?? 8B 33 8D 4E ?? 66 8B 06 83 C6 ?? 66 85 C0 75 ?? 2B F1 D1 FE 0F 84 - ?? ?? ?? ?? 3B 73 ?? 0F 85 ?? ?? ?? ?? 88 45 ?? 8D 55 ?? FF 75 ?? 8D 4D ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? C7 45 ?? ?? ?? ?? - ?? 50 8B CB E8 ?? ?? ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B - C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 ?? FF 15 ?? - ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7B ?? ?? 72 ?? 8B 1B 8B 75 ?? 57 56 53 E8 - ?? ?? ?? ?? 85 C0 75 ?? 8B 36 8B CF E8 ?? ?? ?? ?? 84 C0 74 ?? 57 56 E8 ?? ?? ?? ?? - 85 C0 75 ?? 8B CF E8 ?? ?? ?? ?? 84 C0 75 ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 - 5F 5E 5B 8B E5 5D C3 83 F8 ?? 75 ?? 8B 4D ?? D1 E9 F6 C1 ?? B9 ?? ?? ?? ?? 0F 45 C1 - 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C3 B8 ?? ?? ?? ?? 8B 4D ?? 64 89 - 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C3 + $bc_bcdedit = { + 55 8B EC 6A ?? 53 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B D8 BA ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C3 + E8 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 BA ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8D 45 + ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? + ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? C3 } - $import_key = { - 8D 44 24 ?? 50 6A ?? 6A ?? 6A ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 5E 85 - C0 75 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 32 C0 5F 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? - 83 C4 ?? C3 8B 44 24 ?? FF 74 24 ?? 8B 08 8B 40 ?? 89 47 ?? 8D 44 24 ?? 50 57 6A ?? - 6A ?? 6A ?? FF 74 24 ?? 89 0F FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 6A ?? - FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? B0 ?? 5F 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C3 + $bc_enum_drives_a_z = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 D2 89 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B F0 33 C0 55 68 ?? ?? ?? + ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 06 B3 ?? 8D 85 ?? ?? ?? ?? 8B D3 E8 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? + 8D 45 ?? B1 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B D3 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 E8 ?? 75 1B 8D 85 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? + ?? 8B 06 8B 08 FF 51 ?? 43 80 FB ?? 0F 85 65 FF FF FF 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? C3 } - $encrypt_files = { - 8B 01 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EE ?? 73 ?? 8A 01 3A 02 75 ?? 83 FE ?? 74 ?? - 8A 41 ?? 3A 42 ?? 75 ?? 8A 41 ?? 3A 42 ?? 75 ?? 8A 41 ?? 3A 42 ?? 75 ?? 33 C0 EB ?? - 1B C0 83 C8 ?? 85 C0 75 ?? 8B 5D ?? 8B 7D ?? C6 85 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B - BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B CF E8 ?? ?? ?? ?? 51 C6 45 ?? ?? 8D 4D ?? 8B - 9D ?? ?? ?? ?? 51 83 CB ?? 8B C8 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 CB ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 83 CB ?? 83 7D ?? ?? 89 9D ?? ?? ?? ?? 0F 43 4D ?? 83 - 7D ?? ?? 89 9D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 8B 01 3B - 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EE ?? 73 ?? 8A 01 3A 02 75 ?? 83 FE ?? 74 ?? 8A 41 ?? - 3A 42 ?? 75 ?? 8A 41 ?? 3A 42 ?? 75 ?? 8A 41 ?? 3A 42 ?? 75 ?? 33 C0 EB ?? 1B C0 83 - C8 ?? 85 C0 75 ?? 8B 5D ?? 8B 7D ?? C6 85 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 45 ?? 8B - CF 50 E8 ?? ?? ?? ?? 51 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 51 83 CB ?? 8B C8 89 9D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 7D ?? 8D 4D ?? 81 CB ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 8B 5D ?? - 83 FB ?? 0F 43 CF 83 7D ?? ?? 0F 85 + $bc_do_extensions_1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D + ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 4D ?? 89 55 ?? 89 45 ?? 8B 7D ?? 8B 5D ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 85 ?? + ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 85 81 01 00 00 E8 ?? ?? ?? ?? BA ?? + ?? ?? ?? 33 C0 E8 ?? ?? ?? ?? 8B F0 8B C3 8B 14 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB 28 A0 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? + 50 8B 03 33 C9 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B 13 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 85 C0 75 C8 EB 28 A0 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8B 03 33 C9 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B + C3 E8 ?? ?? ?? ?? 8B 13 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 C8 FF 75 ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? DB 85 ?? ?? ?? ?? 83 C4 ?? DB 3C + } + $bc_do_extensions_2 = { + 24 9B 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8B C7 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 13 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 17 8D 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? B3 ?? EB 02 33 DB 33 C0 5A 59 59 64 89 10 EB 0C E9 ?? ?? ?? ?? 33 DB E8 ?? ?? + ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB D0 8B C3 5F 5E 5B 8B E5 5D C2 + } + $bc_do_files_1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 4D ?? 89 55 ?? 8B F0 + 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B3 ?? 8B 06 E8 ?? ?? ?? ?? + 89 45 ?? 8B 16 8D 85 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B F8 85 FF 0F 85 91 00 00 00 F6 85 ?? ?? ?? ?? ?? 75 73 56 8D B5 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 A5 + 5E 8B 85 ?? ?? ?? ?? 89 45 ?? 8B 85 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 33 D2 E8 ?? ?? ?? ?? 83 C4 ?? DD 1C 24 9B 8D 45 ?? E8 + ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 36 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? + ?? ?? 8B 45 ?? 8B 40 ?? 8B 00 8B 08 FF 51 ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 85 FF 0F 84 6F FF FF FF 8D 85 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 84 DB 0F 84 B7 00 00 00 8B 16 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D + } + $bc_do_files_2 = { + 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 85 FF 75 7E F6 85 ?? ?? ?? ?? ?? 74 64 8B 85 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 74 52 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 40 FF 36 FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B + C6 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 50 8B C6 8B 55 ?? E8 57 FE FF FF 59 84 C0 75 04 33 DB EB 21 8B 55 ?? 42 8B C6 + B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 85 FF 74 82 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 + 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 + } + $bc_main_1 = { + 55 8B EC B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 F9 53 56 57 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 + 89 20 33 C0 A3 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? + ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? + ?? ?? ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? + ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 8D 45 ?? 8B 0D ?? ?? ?? ?? + 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 75 7A 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B + } + $bc_main_2 = { + 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 8D 45 ?? 8B 0D ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 33 C0 E8 ?? ?? ?? ?? 8B 45 ?? 50 8D 45 ?? 8B 0D ?? ?? ?? ?? 8B 15 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 58 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB 11 BA ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B D8 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 80 FB ?? 0F 85 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? B2 ?? A1 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 75 ED A1 ?? ?? ?? ?? 8B 10 FF 52 ?? 83 F8 ?? 0F + 8E ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 10 FF 52 ?? 99 F7 3D ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 10 FF 52 ?? 99 F7 3D + ?? ?? ?? ?? 89 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 48 85 C0 7C ?? 40 89 45 ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? + } + $bc_main2 = { + E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 45 ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D + ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and ($find_files) and ($import_key) and ($encrypt_files) + uint16(0)==0x5A4D and ($bc_main_1 at pe.entry_point) and $bc_main_2 and $bc_main2 and $bc_bcdedit and $bc_enum_drives_a_z and $bc_do_extensions_1 and $bc_do_extensions_2 and $bc_do_files_1 and $bc_do_files_2 } -rule REVERSINGLABS_Win64_Ransomware_Hermeticransom : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Clop : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects HermeticRansom ransomware." + description = "Yara rule that detects Clop ransomware." author = "ReversingLabs" - id = "6aaf89f4-0cf8-5f0e-b89d-01ac7edd06c0" - date = "2022-05-13" - modified = "2022-05-13" + id = "0ea63119-3773-5404-b332-8e3966fd35df" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.HermeticRansom.yara#L1-L105" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "123d569a9d9b9d855b3baafd6194f102d82a594fd7a2bba073843a8654a317cb" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Clop.yara#L1-L109" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0b63db16a4b1cae27a97d0ff9df692a63f1a11120ffac69c05a5c71fbd224007" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -31822,97 +33626,100 @@ rule REVERSINGLABS_Win64_Ransomware_Hermeticransom : TC_DETECTION MALICIOUS MALW sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "HermeticRansom" + tc_detection_name = "Clop" tc_detection_factor = 5 importance = 25 strings: - $drop_ransom_note = { - 65 48 8B 0C 25 ?? ?? ?? ?? 48 8B 89 ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 48 3B 41 ?? - 0F 86 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 89 AC 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 0F 10 04 24 0F 11 44 24 ?? 0F 10 44 24 ?? 0F 11 44 24 ?? 0F 10 44 - 24 ?? 0F 11 04 24 E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 8D BC 24 ?? ?? ?? - ?? 48 8D 35 ?? ?? ?? ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? E8 ?? ?? ?? ?? 48 8B 6D ?? 48 - 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? - ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 8B 0D ?? - ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 C7 04 24 ?? ?? ?? ?? 48 - 8D 84 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 44 24 ?? 48 8B 4C 24 ?? 48 89 8C 24 ?? ?? - ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 14 24 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 - 8B 44 24 ?? 48 8B 4C 24 ?? 48 8D 94 24 ?? ?? ?? ?? 48 89 14 24 48 89 4C 24 ?? 48 89 - 44 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 C7 04 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 4C 24 - ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 - 8B 44 24 ?? 48 8B 4C 24 ?? 48 89 0C 24 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 4C - 24 ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 44 24 ?? C7 04 24 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? - ?? 48 89 54 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 - } $encrypt_files_p1 = { - E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 89 8C 24 ?? - ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 1D ?? ?? ?? ?? 48 8B 35 ?? ?? ?? ?? 48 89 14 24 - 48 89 74 24 ?? 48 89 5C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 89 54 24 ?? 48 C7 44 24 ?? ?? - ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 1D ?? ?? ?? ?? 48 89 5C 24 ?? 48 89 54 24 ?? E8 - ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 8B 54 24 ?? 48 8B 9C 24 ?? ?? ?? ?? 48 - 85 DB 0F 85 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 4C 24 ?? 48 89 94 24 ?? ?? ?? ?? 48 8D - 05 ?? ?? ?? ?? 48 89 04 24 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 04 24 48 8B 44 24 ?? 48 89 C1 48 C1 F8 ?? 48 - C1 E8 ?? 48 01 C8 48 C1 F8 ?? 48 89 84 24 ?? ?? ?? ?? 48 C1 E0 ?? 48 29 C1 48 89 4C - 24 ?? 48 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 89 04 24 0F 57 C0 0F - 11 44 24 ?? E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 83 F8 ?? 7E ?? B8 ?? ?? ?? ?? - 48 89 84 24 ?? ?? ?? ?? 31 C9 EB ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? - 48 39 C1 0F 8D ?? ?? ?? ?? 48 89 CA 48 C1 E1 ?? 48 FF C2 48 89 D3 48 C1 E2 ?? 48 39 - D1 0F 87 ?? ?? ?? ?? 48 8B 74 24 ?? 48 39 F2 0F 87 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? - ?? 48 8B 05 ?? ?? ?? ?? 48 8B 1D ?? ?? ?? ?? 48 8B 3D ?? ?? ?? ?? 48 89 3C 24 48 89 + 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 6A ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? + 83 C4 ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 83 BD ?? + ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 6A ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 8D ?? ?? ?? + ?? 51 FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? + ?? 8B 88 ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 8B 82 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 8B + 91 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 E8 + ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? + ?? 52 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 83 BD ?? ?? ?? ?? ?? 74 ?? + 68 ?? ?? ?? ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 + ?? 68 ?? ?? ?? ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? + 74 ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? + ?? ?? 52 FF 15 } $encrypt_files_p2 = { - 5C 24 ?? 48 89 44 24 ?? 48 29 CE 48 89 F3 48 F7 DE 48 C1 FE ?? 48 21 CE 48 8B BC 24 - ?? ?? ?? ?? 48 01 FE 48 89 74 24 ?? 48 29 CA 48 89 54 24 ?? 48 89 5C 24 ?? E8 ?? ?? - ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 8B 54 24 ?? 48 8B 5C 24 ?? 48 85 DB 0F 85 ?? - ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 89 1C 24 48 89 44 24 ?? 48 89 4C 24 ?? 48 89 54 - 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 83 F8 ?? 0F 8D ?? ?? ?? ?? 48 C1 E0 ?? 48 8B - 4C 24 ?? 48 39 C8 0F 87 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 1D ?? ?? ?? ?? 48 8B - 35 ?? ?? ?? ?? 48 89 14 24 48 89 5C 24 ?? 48 89 74 24 ?? 48 8B 54 24 ?? 48 29 C2 48 - 89 D3 48 F7 DA 48 C1 FA ?? 48 21 C2 48 8B B4 24 ?? ?? ?? ?? 48 01 F2 48 89 54 24 ?? - 48 29 C1 48 89 4C 24 ?? 48 89 5C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? - 48 8B 54 24 ?? 48 8B 5C 24 ?? 48 85 DB 74 ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 8C 24 ?? - ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 - 81 C4 ?? ?? ?? ?? C3 48 8B 9C 24 ?? ?? ?? ?? 48 89 1C 24 48 89 44 24 ?? 48 89 4C 24 - ?? 48 89 54 24 ?? E8 ?? ?? ?? ?? 48 8B 84 24 + 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 50 8D + 4D ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 52 FF + 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8B 0D ?? ?? ?? ?? 51 8D 95 ?? + ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 + ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 6A ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? + ?? 85 C0 75 ?? 33 C0 E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 6A ?? + 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? + ?? 85 C0 75 ?? 33 C0 E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A + ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 C0 E9 ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 6A ?? 8B + 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 C0 E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? 85 D2 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8B 8D + ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 6A ?? 6A ?? E8 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 50 + 68 ?? ?? ?? ?? 8D 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 6A ?? 6A ?? E8 ?? ?? + ?? ?? 50 8B 15 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 C0 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B + E5 5D C2 + } + $encrypt_files_p3 = { + 55 8B EC 83 EC ?? 6A ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B + 4D ?? 51 8D 55 ?? 52 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 + ?? FF 15 ?? ?? ?? ?? 33 C0 EB ?? 8B 4D ?? 51 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 + ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 8D 4D ?? + 51 8B 55 ?? 52 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? + ?? ?? ?? 33 C0 EB ?? 8B 4D ?? 8B 55 ?? 89 11 33 C0 8B E5 5D C3 } $find_files = { - 65 48 8B 0C 25 ?? ?? ?? ?? 48 8B 89 ?? ?? ?? ?? 48 3B 61 ?? 0F 86 ?? ?? ?? ?? 48 83 - EC ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? 48 C7 04 24 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? - 48 89 44 24 ?? 48 8B 8C 24 ?? ?? ?? ?? 48 89 4C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 89 54 - 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 1D ?? ?? ?? ?? 48 89 54 - 24 ?? 48 89 5C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 89 54 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? - E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 44 24 ?? 48 8B 4C 24 ?? 48 89 4C 24 ?? 48 8B 94 - 24 ?? ?? ?? ?? 48 89 14 24 48 8B 9C 24 ?? ?? ?? ?? 48 89 5C 24 ?? 48 89 44 24 ?? 48 - 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 8B 84 24 ?? - ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 48 89 04 24 48 89 4C 24 ?? 48 C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 85 C9 75 - ?? 48 89 44 24 ?? 48 89 04 24 E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 85 C0 74 ?? 48 8B 44 - 24 ?? 48 89 04 24 E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 48 8B 6C 24 ?? 48 83 C4 ?? - C3 48 8B 44 24 ?? 48 89 04 24 E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 48 8B 6C 24 ?? - 48 83 C4 ?? C3 48 89 04 24 E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 48 8B 6C 24 ?? 48 - 83 C4 ?? C3 48 8B 44 24 + 8D 95 ?? ?? ?? ?? 52 6A ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 + 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? + 8D 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD + ?? ?? ?? ?? ?? 75 ?? EB ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 + C0 76 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 83 C4 ?? EB ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 6A ?? 68 + ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? 6A ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? + 51 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 8B 85 ?? ?? + ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 E8 + } + $uninstall_eset_av = { + 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 86 ?? ?? ?? ?? 8D 4D ?? 51 68 ?? ?? ?? ?? 8D + 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 68 ?? + ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 8D ?? + ?? ?? ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 7D ?? 68 ?? ?? ?? + ?? 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? + ?? ?? 6A ?? 6A ?? 6A ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? + FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 6A + ?? 6A ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? E9 ?? + ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($drop_ransom_note) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($uninstall_eset_av) } -rule REVERSINGLABS_Win32_Ransomware_Howareyou : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Dearcry : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects HowAreYou ransomware." + description = "Yara rule that detects DearCry ransomware." author = "ReversingLabs" - id = "998fbebe-099d-5779-ad4a-91b7b6c8ad6b" - date = "2021-06-14" - modified = "2021-06-14" + id = "6e2097e0-6495-5185-bbbc-e8168fa0ca7f" + date = "2021-03-12" + modified = "2021-03-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.HowAreYou.yara#L1-L205" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "90568365aac61d120886f9efa9822ccc23df79a1a55e522c81db6e77477c4f04" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.DearCry.yara#L1-L96" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "40dde232255018e1bc0aadf2378a7a86a99327d13dda58d8ffc5bb38e164de26" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -31920,191 +33727,91 @@ rule REVERSINGLABS_Win32_Ransomware_Howareyou : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "HowAreYou" + tc_detection_name = "DearCry" tc_detection_factor = 5 importance = 25 strings: - $remote_connection_p1 = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? 8B 05 ?? - ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 85 C9 0F 85 ?? ?? ?? ?? 8D 0D ?? ?? - ?? ?? 89 08 8B 05 ?? ?? ?? ?? 8D 0D ?? ?? ?? ?? 89 0C 24 89 44 24 ?? E8 ?? ?? ?? ?? - 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 8B 6C 24 ?? 85 C9 74 ?? 74 ?? 8B 49 - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? 8D 44 24 - ?? 89 04 24 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 E8 ?? - ?? ?? ?? 83 C4 ?? C3 89 54 24 ?? 89 5C 24 ?? 89 6C 24 ?? 8D 05 ?? ?? ?? ?? 89 04 24 - C7 44 24 ?? ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? - E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 85 D2 74 ?? 74 ?? 8B - 4A ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? 8D 05 - ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 89 D1 + $drop_ransom_note_p1 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? A1 ?? + ?? ?? ?? 53 56 57 33 DB 68 ?? ?? ?? ?? 50 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 89 1D ?? ?? + ?? ?? 89 1D ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 89 1D ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 89 44 24 ?? E8 + ?? ?? ?? ?? 8B F0 6A ?? 68 ?? ?? ?? ?? 89 74 24 ?? E8 ?? ?? ?? ?? 8B F8 89 7C 24 ?? + E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 3B F3 0F 84 ?? ?? ?? ?? 3B FB 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 5C 24 ?? B8 ?? ?? ?? ?? 33 F6 8B FF + 38 18 74 ?? 50 E8 ?? ?? ?? ?? 8D BE ?? ?? ?? ?? 83 C4 ?? 8B D7 8A 08 88 0A 40 42 84 + C9 75 ?? 8B C7 33 F6 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 74 ?? 0F BE 14 37 52 E8 ?? + ?? ?? ?? 88 04 37 8B C7 83 C4 ?? 46 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 3B F0 72 ?? + 8B 74 24 ?? 46 89 74 24 ?? 69 F6 ?? ?? ?? ?? 8D 86 ?? ?? ?? ?? 3B C3 75 ?? 6A ?? 68 } - $remote_connection_p2 = { - EB ?? 89 4C 24 ?? 89 5C 24 ?? 84 03 89 4C 24 ?? C7 04 24 ?? ?? ?? ?? 8D 43 ?? 89 44 - 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 ?? 8B 48 ?? 8B 54 24 ?? 89 54 - 24 ?? 8B 54 24 ?? 89 54 24 ?? 8B 54 24 ?? 89 54 24 ?? 8B 54 24 ?? 89 14 24 FF D1 8B - 44 24 ?? 8B 4C 24 ?? 85 C0 74 ?? 74 ?? 8B 40 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? 89 44 24 ?? 89 4C 24 ?? 8D 05 ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? - ?? 8D 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? - ?? ?? 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 8D 05 ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C - 24 ?? 8B 5B ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 8B 44 24 ?? 89 04 24 FF D3 90 E8 - ?? ?? ?? ?? 83 C4 ?? C3 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 89 04 24 8D 05 ?? ?? ?? ?? 89 - 44 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 + $drop_ransom_note_p2 = { + 89 5C 24 ?? E8 ?? ?? ?? ?? 53 8B F0 53 8D 44 24 ?? 50 56 E8 ?? ?? ?? ?? 56 89 44 24 + ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 8B F8 3B C3 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 85 C0 0F 86 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? 53 51 88 5C 24 ?? E8 ?? ?? ?? + ?? 83 C4 ?? 8D 54 24 ?? 52 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 8A 44 1C ?? 3C ?? 7C ?? 3C ?? 7E ?? 3C ?? 0F 8C ?? ?? ?? ?? 3C ?? 0F 8F ?? ?? ?? ?? + 0F BE C0 50 8D 4C 24 ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 83 C4 ?? + 8D 54 24 ?? 52 FF D6 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? 8B + 4C 24 ?? 8B 54 24 ?? 8B 44 24 ?? 51 52 50 6A ?? 8D 4C 24 ?? 51 57 E8 ?? ?? ?? ?? 0F + BE 54 1C ?? 68 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? B8 ?? ?? ?? ?? 8D 50 + ?? 8D 49 ?? 8A 08 40 84 C9 75 ?? 56 2B C2 50 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 + E8 ?? ?? ?? ?? 83 C4 ?? 43 81 FB ?? ?? ?? ?? 0F 8C ?? ?? ?? ?? 33 DB 57 } $find_files_p1 = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 8D 44 24 ?? 3B 41 ?? 0F 86 ?? ?? ?? ?? 81 EC - ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 8B 8C 24 ?? ?? ?? ?? 89 4C 24 ?? E8 ?? ?? - ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 85 C9 0F 85 ?? ?? ?? ?? 89 54 - 24 ?? 89 9C 24 ?? ?? ?? ?? 31 C0 31 C9 31 ED 31 F6 EB ?? 8B 7C 24 ?? 47 8B 9C 24 ?? - ?? ?? ?? 89 CD 89 C6 89 F8 89 D1 8B 54 24 ?? 39 D0 0F 8D ?? ?? ?? ?? 89 44 24 ?? 89 - 4C 24 ?? 89 AC 24 ?? ?? ?? ?? 89 74 24 ?? 8D 0C C3 8B 11 89 94 24 ?? ?? ?? ?? 8B 49 - ?? 89 8C 24 ?? ?? ?? ?? 8B 6A ?? 89 0C 24 FF D5 0F B6 44 24 ?? 84 C0 0F 84 ?? ?? ?? - ?? 8B 84 24 ?? ?? ?? ?? 8B 40 ?? 8B 8C 24 ?? ?? ?? ?? 89 0C 24 FF D0 8B 44 24 ?? 8B - 4C 24 ?? 89 0C 24 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 85 C0 0F 86 ?? - ?? ?? ?? 0F B6 11 80 FA ?? 75 ?? 8B 44 24 ?? 8B 8C 24 ?? ?? ?? ?? 8B 54 24 ?? E9 ?? - ?? ?? ?? 80 FA ?? 74 ?? 89 44 24 ?? 89 8C 24 ?? ?? ?? ?? 89 0C 24 89 44 24 ?? 8B 15 - ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 2D ?? ?? ?? ?? 89 6C 24 ?? 89 5C 24 ?? 89 54 24 ?? - E8 ?? ?? ?? ?? 0F B6 44 24 ?? 84 C0 74 ?? 8B 44 24 ?? 8B 8C 24 ?? ?? ?? ?? 8B 54 24 - ?? E9 ?? ?? ?? ?? 8B 44 24 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 8B 11 + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 31 45 ?? 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 + A3 ?? ?? ?? ?? 89 65 ?? 8B 45 ?? 89 85 ?? ?? ?? ?? 8B 75 ?? 89 B5 ?? ?? ?? ?? 8B 4D + ?? 89 8D ?? ?? ?? ?? 8B 55 ?? 89 95 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? + ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 85 ?? ?? ?? ?? ?? 68 + ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 85 ?? ?? ?? ?? ?? + 8B C6 8D 50 ?? 8D 49 ?? 8A 08 40 84 C9 75 ?? 2B C2 80 7C 06 ?? ?? 74 ?? 8B C6 8D 50 + ?? 8A 08 40 84 C9 75 ?? 2B C2 80 7C 06 ?? ?? 74 ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? 52 EB ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 + 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 6A + ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 8B C6 + 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 8B D0 8D 85 ?? ?? ?? ?? 8D 78 ?? 8A 08 40 84 C9 + 75 ?? 2B C7 03 C2 3D ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 6A ?? 6A ?? 8D 4D ?? 51 E8 ?? ?? + ?? ?? 83 C4 ?? 8B C3 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 83 F8 ?? 76 ?? B8 ?? ?? ?? + ?? EB ?? 8B C3 8D 50 ?? 8D 64 24 ?? 8A 08 40 84 C9 75 ?? 2B C2 50 53 8D 55 ?? 52 E8 } $find_files_p2 = { - 81 FA ?? ?? ?? ?? 75 ?? 0F B7 51 ?? 66 81 FA ?? ?? 75 ?? 0F B6 51 ?? 80 FA ?? 0F 84 - ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8B 94 24 ?? ?? ?? ?? 89 54 24 ?? 8B 9C 24 ?? ?? ?? - ?? 89 5C 24 ?? 8D 2D ?? ?? ?? ?? 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 89 - 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 04 24 89 4C 24 ?? E8 ?? ?? ?? ?? - 8B 44 24 ?? 8D 48 ?? 8B 54 24 ?? 8B 5C 24 ?? 8B 6C 24 ?? 39 E9 7F ?? 8B B4 24 ?? ?? - ?? ?? 8D 7C C6 ?? 89 1F 8D 04 C6 8B 1D ?? ?? ?? ?? 85 DB 75 ?? 89 10 89 E8 89 CA 89 - F1 E9 ?? ?? ?? ?? 89 B4 24 ?? ?? ?? ?? 89 4C 24 ?? 89 6C 24 ?? 89 04 24 89 54 24 ?? - E8 ?? ?? ?? ?? 8B 4C 24 ?? 8B 6C 24 ?? 8B B4 24 ?? ?? ?? ?? EB ?? 89 94 24 ?? ?? ?? - ?? 89 5C 24 ?? 8D 15 ?? ?? ?? ?? 89 14 24 8B 9C 24 ?? ?? ?? ?? 89 5C 24 ?? 89 44 24 - ?? 89 6C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 74 24 ?? 8B 44 24 ?? 8B 6C 24 ?? 8D 48 - ?? 8B 44 24 ?? 8B 94 24 ?? ?? ?? ?? 8B 5C 24 ?? E9 ?? ?? ?? ?? 8D 54 24 ?? 89 14 24 - 8B 94 24 ?? ?? ?? ?? 89 54 24 ?? 8B 9C 24 ?? ?? ?? ?? 89 5C 24 ?? 8D 2D ?? ?? ?? ?? - 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 - ?? 8B 4C 24 ?? 89 0C 24 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 8C 24 ?? ?? ?? ?? - E9 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 8B 40 ?? 8B - } - $find_files_p3 = { - 8C 24 ?? ?? ?? ?? 89 0C 24 FF D0 8B 44 24 ?? 8B 4C 24 ?? 89 0C 24 89 44 24 ?? E8 ?? - ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 89 04 24 89 4C 24 ?? 8B 15 - ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 2D ?? ?? ?? ?? 89 6C 24 ?? 89 5C 24 ?? 89 54 24 ?? - E8 ?? ?? ?? ?? 0F B6 44 24 ?? 84 C0 74 ?? 8B 44 24 ?? 8B 8C 24 ?? ?? ?? ?? 8B 54 24 - ?? E9 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 8B 4C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 - 24 ?? 89 84 24 ?? ?? ?? ?? 8B 4C 24 ?? 89 4C 24 ?? C7 04 24 ?? ?? ?? ?? 8B 94 24 ?? - ?? ?? ?? 89 54 24 ?? 8B 9C 24 ?? ?? ?? ?? 89 5C 24 ?? 8D 2D ?? ?? ?? ?? 89 6C 24 ?? - C7 44 24 ?? ?? ?? ?? ?? 8B 74 24 ?? 89 74 24 ?? 8B 74 24 ?? 89 74 24 ?? E8 ?? ?? ?? - ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8B 94 24 ?? ?? ?? ?? 89 14 24 8B - 5C 24 ?? 89 5C 24 ?? 8B 2D ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 89 6C 24 - ?? 89 74 24 ?? 89 7C 24 ?? E8 ?? ?? ?? ?? 0F B6 44 24 ?? 84 C0 0F 84 ?? ?? ?? ?? 8B - 84 24 ?? ?? ?? ?? 85 C0 0F 86 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 0F B6 08 83 C1 ?? 88 - 4C 24 ?? 0F B6 08 83 C1 ?? 88 4C 24 ?? 8D 0D ?? ?? ?? ?? 89 0C 24 8B 15 ?? ?? ?? ?? - 89 54 24 ?? 8D 54 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 48 ?? 8D 51 ?? 8B - 18 8B 40 ?? 39 C2 0F 8F ?? ?? ?? ?? 89 9C 24 ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? 8D - } - $find_files_p4 = { - 6C CB ?? 8B 74 24 ?? 89 75 ?? 8B 2D ?? ?? ?? ?? 8D 0C CB 85 ED 75 ?? 8B 6C 24 ?? 89 - 29 8D 05 ?? ?? ?? ?? 89 04 24 8B 0D ?? ?? ?? ?? 89 4C 24 ?? 8D 4C 24 ?? 89 4C 24 ?? - E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 48 ?? 8B 4C 24 ?? 89 48 ?? 8B 0D ?? ?? ?? - ?? 85 C9 75 ?? 8B 8C 24 ?? ?? ?? ?? 89 08 8B 6C 24 ?? 8B 4C 24 ?? 8B B4 24 ?? ?? ?? - ?? E9 ?? ?? ?? ?? 89 04 24 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? EB ?? 89 - 0C 24 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? EB ?? 89 4C 24 ?? 8D 2D ?? ?? ?? ?? 89 - 2C 24 89 5C 24 ?? 89 4C 24 ?? 89 44 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 8B - 44 24 ?? 8B 4C 24 ?? 8D 50 ?? 89 C8 8B 4C 24 ?? E9 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? - 89 04 24 8B 44 24 ?? 89 44 24 ?? 8B 05 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B 15 ?? ?? ?? - ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 0F B6 44 24 ?? 84 C0 74 ?? 8B - 44 24 ?? 8B 8C 24 ?? ?? ?? ?? 8B 54 24 ?? E9 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 85 C0 - 0F 86 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 0F B6 08 88 4C 24 ?? 0F B6 08 88 4C 24 ?? 8D - } - $find_files_p5 = { - 0D ?? ?? ?? ?? 89 0C 24 8B 15 ?? ?? ?? ?? 89 54 24 ?? 8D 54 24 ?? 89 54 24 ?? E8 ?? - ?? ?? ?? 8B 44 24 ?? 8B 48 ?? 8D 51 ?? 8B 18 8B 40 ?? 39 C2 0F 8F ?? ?? ?? ?? 89 9C - 24 ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? 8D 6C CB ?? 8B 74 24 ?? 89 75 ?? 8B 2D ?? ?? - ?? ?? 8D 0C CB 85 ED 75 ?? 8B 6C 24 ?? 89 29 8D 05 ?? ?? ?? ?? 89 04 24 8B 0D ?? ?? - ?? ?? 89 4C 24 ?? 8D 4C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 - 48 ?? 8B 4C 24 ?? 89 48 ?? 8B 0D ?? ?? ?? ?? 85 C9 75 ?? 8B 8C 24 ?? ?? ?? ?? 89 08 - E9 ?? ?? ?? ?? 89 04 24 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? - ?? 89 0C 24 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? EB ?? 89 4C 24 ?? 8D 2D ?? ?? ?? - ?? 89 2C 24 89 5C 24 ?? 89 4C 24 ?? 89 44 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 - ?? 8B 44 24 ?? 8B 4C 24 ?? 8D 50 ?? 89 C8 8B 4C 24 ?? E9 ?? ?? ?? ?? 89 AC 24 ?? ?? - ?? ?? 89 8C 24 ?? ?? ?? ?? 89 B4 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? - C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 89 8C 24 ?? ?? ?? - ?? 89 84 24 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 E8 - } - $encrypt_files_p1 = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 8D 44 24 ?? 3B 41 ?? 0F 86 ?? ?? ?? ?? 81 EC - ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? - ?? ?? ?? ?? 8B 40 ?? 89 04 24 8D 84 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 84 - 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 8D 15 ?? ?? ?? ?? 39 CA 0F 85 ?? ?? ?? ?? 8B 48 - ?? 89 4C 24 ?? 8B 00 89 84 24 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? 89 4C 24 - ?? 8B 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 89 54 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B 44 - 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? C6 44 24 ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? - ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 8D 54 24 ?? 89 54 24 ?? 8B 94 24 ?? ?? ?? ?? - 89 54 24 ?? 8B 5C 24 ?? 89 5C 24 ?? 8D AC 24 ?? ?? ?? ?? 89 6C 24 ?? 89 4C 24 ?? 89 - 44 24 ?? C7 04 24 ?? ?? ?? ?? 8D 2D ?? ?? ?? ?? 89 6C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F - 85 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 8B 4C 24 ?? 89 4C 24 ?? C7 44 24 ?? ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? - 85 D2 0F 85 ?? ?? ?? ?? 89 44 24 ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? 8D 0D ?? ?? ?? - ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 8B 44 24 - ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 85 D2 0F 85 ?? ?? - ?? ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? E8 - } - $encrypt_files_p2 = { - 85 C0 0F 85 ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8B 54 - 24 ?? 89 54 24 ?? 89 14 24 89 4C 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C - 24 ?? 85 C9 0F 85 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? - 89 14 24 89 4C 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? - 8B 5C 24 ?? 85 C9 0F 85 ?? ?? ?? ?? 89 1C 24 89 54 24 ?? 8B 44 24 ?? 89 44 24 ?? 8B - 4C 24 ?? 89 4C 24 ?? 8B 54 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? - 8B 4C 24 ?? 89 4C 24 ?? 8D 15 ?? ?? ?? ?? 89 14 24 8B 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? - ?? 8B 2D ?? ?? ?? ?? 89 54 24 ?? 89 5C 24 ?? 89 6C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? - 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8D 15 ?? ?? ?? ?? 89 14 24 C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 84 24 ?? ?? ?? ?? 8B 4C 24 - ?? 89 4C 24 ?? 8B 54 24 ?? 89 54 24 ?? 8B 5C 24 ?? 89 1C 24 8B 6C 24 ?? 89 6C 24 ?? - 8B 6C 24 ?? 89 6C 24 ?? 8B 6C 24 ?? 89 6C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 - ?? 85 C0 0F 85 ?? ?? ?? ?? 31 C0 EB ?? 8B 4C 24 ?? 8B 54 24 ?? 8D 04 0A 89 44 24 ?? - 8B 4C 24 ?? 89 0C 24 8B 94 24 ?? ?? ?? ?? 89 54 24 ?? 8B 5C 24 ?? 89 5C 24 ?? 8B 6C - 24 ?? 89 6C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8B - 54 24 ?? 89 54 24 ?? 85 C9 74 ?? 8B 1D ?? ?? ?? ?? 39 D9 0F 85 ?? ?? ?? ?? 89 0C 24 - } - $encrypt_files_p3 = { - 89 54 24 ?? 8B 05 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 0F B6 44 24 ?? 84 C0 0F 84 - ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 04 24 8B 4C 24 ?? 89 4C 24 ?? 89 4C 24 ?? E8 ?? ?? - ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 8B 6C 24 ?? 39 EB 0F 87 ?? ?? - ?? ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 8B 74 24 ?? 8B 7E ?? 89 44 24 ?? 89 4C 24 - ?? 89 54 24 ?? 8B B4 24 ?? ?? ?? ?? 89 74 24 ?? 89 5C 24 ?? 89 6C 24 ?? 8B 6C 24 ?? - 89 2C 24 FF D7 8B 44 24 ?? 8B 48 ?? 8B 54 24 ?? 89 54 24 ?? 8B 5C 24 ?? 89 5C 24 ?? - 8B 6C 24 ?? 89 6C 24 ?? 8B 74 24 ?? 89 34 24 FF D1 8B 44 24 ?? 89 04 24 8B 4C 24 ?? - 89 4C 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8B 4C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 - ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 4C 24 ?? 39 C1 0F 85 ?? ?? ?? ?? 89 - 0C 24 8B 44 24 ?? 89 44 24 ?? 8B 05 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 0F B6 44 - 24 ?? 84 C0 0F 84 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 8B 44 24 ?? 89 44 24 ?? - C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 - C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 44 24 ?? B9 ?? ?? ?? ?? F7 E9 8B 44 24 ?? 01 C2 C1 F8 ?? C1 FA ?? 29 C2 89 D0 - 89 D3 F7 E9 8D 04 13 C1 F8 ?? C1 FB ?? 29 D8 83 C0 ?? 89 44 24 ?? 31 C9 EB ?? 8B 54 - 24 ?? 8D 4A ?? 8B 44 24 ?? 39 C1 7D ?? 89 4C 24 ?? 8B 44 24 ?? 89 04 24 8D 0D ?? ?? - ?? ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 74 ?? 90 - E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 90 + 83 C4 ?? 33 FF 8D 45 ?? 8D 50 ?? 90 8A 08 40 84 C9 75 ?? 2B C2 74 ?? EB ?? 8D 49 ?? + 0F BE 44 3D ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 88 44 3D ?? 47 8D 45 ?? 8D 50 ?? 8D A4 24 + ?? ?? ?? ?? 8A 08 40 84 C9 75 ?? 2B C2 3B F8 72 ?? 8D 4D ?? 51 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8A 10 3A + 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 C0 EB + ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 + E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 8D 50 ?? 8D A4 24 ?? ?? ?? ?? 8A 08 40 84 C9 75 ?? 2B + C2 80 7C 30 ?? ?? 74 ?? 8B C6 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 80 7C 30 ?? ?? 74 + ?? 8D 85 ?? ?? ?? ?? 50 56 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 EB ?? 8D 95 ?? ?? ?? + ?? 52 56 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 8B BD ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 + ?? 68 ?? ?? ?? ?? 6A ?? 8B 9D ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 53 57 8B 55 ?? + 52 8D BD ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? + E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? C3 8B 65 ?? C7 45 ?? ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? E9 + ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B C6 8D 50 ?? 8B FF } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ( all of ($drop_ransom_note_p*)) and ( all of ($find_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Jormungand : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Reveton : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Jormungand ransomware." + description = "Yara rule that detects Reveton ransomware." author = "ReversingLabs" - id = "418c3d9f-2338-593f-a8ec-a1e25afa50d4" - date = "2021-10-22" - modified = "2021-10-22" + id = "14446b94-cd57-5930-b0af-b21091b61f68" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Jormungand.yara#L1-L135" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "049eb4533b37d8d72e50dd1e803a897758386643770d47b3e7690f58e44d5236" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Reveton.yara#L1-L118" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "2d316c558cdb5591788ef89c6e20327882a118f2928f4a31fb5b8b3083931ac5" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -32112,122 +33819,111 @@ rule REVERSINGLABS_Win32_Ransomware_Jormungand : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Jormungand" + tc_detection_name = "Reveton" tc_detection_factor = 5 importance = 25 strings: - $drop_ransom_note = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 8D 44 24 ?? 3B 41 ?? 0F 86 ?? ?? ?? ?? 81 EC - ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 89 04 24 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? - ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 - 84 24 ?? ?? ?? ?? 8B 4C 24 ?? 89 4C 24 ?? 8D 54 24 ?? 89 14 24 8B 94 24 ?? ?? ?? ?? - 89 54 24 ?? 8B 94 24 ?? ?? ?? ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? - 8B 54 24 ?? 8B 9C 24 ?? ?? ?? ?? 89 1C 24 8B 9C 24 ?? ?? ?? ?? 89 5C 24 ?? 89 44 24 - ?? 89 4C 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 84 24 ?? ?? ?? ?? 8B 4C 24 - ?? 89 4C 24 ?? 8B 54 24 ?? 89 54 24 ?? C7 04 24 ?? ?? ?? ?? 8B 9C 24 ?? ?? ?? ?? 89 - 5C 24 ?? 8B 9C 24 ?? ?? ?? ?? 89 5C 24 ?? 8D 1D ?? ?? ?? ?? 89 5C 24 ?? C7 44 24 ?? - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 04 24 89 4C 24 ?? C7 44 24 ?? - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 84 24 ?? ?? ?? ?? - 8D 4C 24 ?? 89 0C 24 8B 8C 24 ?? ?? ?? ?? 89 4C 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8B 4C - 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 44 24 ?? 89 4C 24 ?? 8D - 44 24 ?? 89 04 24 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? - ?? ?? 8B 44 24 ?? 8B 4C 24 ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? 89 4C 24 ?? E8 ?? ?? - ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 9C 24 ?? ?? ?? ?? 89 1C 24 89 44 24 ?? - 89 4C 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? - 81 C4 ?? ?? ?? ?? C3 E8 + $http_connection_1 = { + C6 45 ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? + ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 8B C3 E8 ?? ?? ?? ?? 50 8B 45 + ?? 50 E8 ?? ?? ?? ?? 8B D8 85 DB 74 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 C0 + 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8B 06 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? 50 68 + ?? ?? ?? ?? 8B 45 ?? 50 53 E8 ?? ?? ?? ?? 8B 55 ?? 8B 06 8B 4D ?? E8 ?? ?? ?? ?? 83 + 7D ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 + ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8B 45 ?? 50 E8 } - $encrypt_files_aes = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? 8B 44 24 - ?? 89 04 24 8B 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 - ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 85 D2 74 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? 89 54 24 ?? 89 5C 24 ?? 83 C4 ?? C3 89 44 24 ?? 89 4C 24 ?? 8B 50 ?? - 89 0C 24 FF D2 8B 44 24 ?? 8B 4C 24 ?? 89 0C 24 8B 4C 24 ?? 89 4C 24 ?? 8B 4C 24 ?? - 89 4C 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 - ?? 8B 54 24 ?? 89 54 24 ?? C7 04 24 ?? ?? ?? ?? 8D 1D ?? ?? ?? ?? 89 5C 24 ?? C7 44 - 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 89 - 1C 24 8B 5C 24 ?? 89 5C 24 ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B - 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8D 15 ?? ?? ?? ?? 89 14 24 8B 54 24 ?? - 89 54 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 - ?? 8B 54 24 ?? 89 54 24 ?? 8B 5C 24 ?? 8B 5B ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? - 8B 6C 24 ?? 89 6C 24 ?? 8B 6C 24 ?? 89 6C 24 ?? 8B 6C 24 ?? 89 6C 24 ?? 8B 6C 24 ?? - 89 2C 24 FF D3 8B 05 ?? ?? ?? ?? 89 04 24 8B 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 - 24 ?? 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 44 24 ?? 89 - 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 83 C4 ?? C3 E8 + $raw_socket_connection_1_1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 4D + ?? 89 55 ?? 8B F0 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 DB 8D 45 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 8B F8 85 FF 0F 8E ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B CF E8 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 } - $encrypt_files_rsa = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? C7 04 24 - ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 89 14 24 89 4C 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B - 44 24 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 48 ?? 8B 50 ?? 8B 40 ?? 89 0C 24 89 54 24 ?? 89 - 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 85 D2 75 ?? - 8D 15 ?? ?? ?? ?? 39 D0 0F 85 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 89 04 - 24 89 54 24 ?? 89 4C 24 ?? 8B 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? 8B 44 24 - ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 8B 6C - 24 ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 89 5C 24 ?? 89 6C 24 ?? 83 C4 ?? C3 C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 89 5C - 24 ?? 83 C4 ?? C3 8D 05 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 44 24 ?? C7 40 ?? ?? - ?? ?? ?? 8B 0D ?? ?? ?? ?? 85 C9 75 ?? 8D 0D ?? ?? ?? ?? 89 08 C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 0D ?? ?? ?? ?? 89 4C 24 ?? 89 - 44 24 ?? 83 C4 ?? C3 89 44 24 ?? 89 04 24 8D 0D ?? ?? ?? ?? 89 4C 24 ?? E8 ?? ?? ?? - ?? 8B 44 24 ?? EB ?? 89 04 24 89 54 24 ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? - ?? 0F 0B + $raw_socket_connection_1_2 = { + C6 85 ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 80 BD ?? ?? ?? + ?? ?? 74 ?? 33 C0 EB ?? B0 ?? 84 C0 75 ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? + ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? E9 + ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? FE C8 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 66 C7 85 ?? ?? ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? FE C8 74 ?? 2C ?? 74 + ?? E9 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? + ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8A 95 + ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? E8 } - $find_files = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? C7 44 24 - ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8D 05 ?? ?? - ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 44 24 ?? 89 04 24 8B 44 24 ?? 89 44 - 24 ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 0D ?? ?? ?? - ?? 8B 15 ?? ?? ?? ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 8B 05 ?? ?? ?? ?? 8B 0D ?? - ?? ?? ?? 8B 15 ?? ?? ?? ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 90 E8 ?? ?? ?? ?? 83 - C4 ?? C3 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 E8 + $raw_socket_connection_1_3 = { + 66 89 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 0F B6 BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 + ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CF + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 + C0 75 ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 40 ?? 8B 00 8B 00 + 89 85 ?? ?? ?? ?? 8A 94 3D ?? ?? ?? ?? 8A 84 3D ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 89 85 + ?? ?? ?? ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 + ?? ?? ?? ?? E8 } - $remote_connection_p1 = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? C7 04 24 - ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D - 05 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? C7 40 ?? ?? ?? ?? ?? - 8D 0D ?? ?? ?? ?? 89 0C 24 E8 ?? ?? ?? ?? 8B 44 24 ?? C6 40 ?? ?? 8B 0D ?? ?? ?? ?? - 8B 54 24 ?? 8D 5A ?? 85 C9 0F 85 ?? ?? ?? ?? 89 42 ?? 8D 05 ?? ?? ?? ?? 89 04 24 E8 - ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8D 0D - ?? ?? ?? ?? 89 08 8B 0D ?? ?? ?? ?? 8D 50 ?? 85 C9 0F 85 ?? ?? ?? ?? 8B 4C 24 ?? 89 - 48 ?? C7 04 24 ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B - 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 - ?? ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 - 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8D 15 ?? ?? ?? ?? 89 14 24 E8 ?? ?? ?? ?? - 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 48 ?? 8B 0D ?? ?? ?? ?? 85 C9 0F 85 ?? ?? ?? - ?? 8B 4C 24 ?? 89 08 C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C7 40 + $raw_socket_connection_1_4 = { + 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 8B + 00 50 E8 ?? ?? ?? ?? 40 75 ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? + ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? 8B 45 ?? 8B 00 + 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 8B 00 50 E8 } - $remote_connection_p2 = { - C7 04 24 ?? ?? ?? ?? 8D 0D ?? ?? ?? ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 4C 24 - ?? 89 4C 24 ?? 8B 4C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 4C - 24 ?? 89 44 24 ?? 8D 05 ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? ?? 8D 05 ?? ?? ?? - ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C - 24 ?? 8B 54 24 ?? 89 0C 24 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 8B 44 24 - ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 89 0C - 24 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 75 ?? 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 - 8B 48 ?? 84 01 8B 40 ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? 8D 41 ?? 89 44 24 ?? E8 ?? - ?? ?? ?? 85 C0 75 ?? EB ?? 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 89 04 24 8B 4C 24 ?? 89 4C - 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? E9 ?? ?? ?? ?? 89 14 24 8B 44 24 ?? 89 44 24 ?? E8 - ?? ?? ?? ?? E9 ?? ?? ?? ?? 89 1C 24 89 44 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 90 E8 - ?? ?? ?? ?? 83 C4 ?? C3 E8 + $raw_socket_connection_1_5 = { + C6 85 ?? ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? + ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 66 + 8B 85 ?? ?? ?? ?? 8B D0 66 81 E2 ?? ?? 88 95 ?? ?? ?? ?? 0F B7 C0 C1 E8 ?? 88 85 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? + ?? ?? 40 74 ?? B3 ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? + ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 + 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? + ?? ?? ?? C3 + } + $file_search_1_1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 89 55 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 89 C3 85 DB 74 + ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 FF D3 85 C0 74 ?? 8B 45 ?? 50 8D + 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 ?? 80 38 ?? 75 ?? + 8B 45 ?? 80 78 ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? E8 + } + $file_search_1_2 = { + 8B F0 80 3E ?? 0F 84 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F0 80 3E ?? 0F 84 ?? ?? + ?? ?? EB ?? 8B 75 ?? 83 C6 ?? 8B DE 2B 5D ?? 8D 43 ?? 50 8B 45 ?? 50 8D 85 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F8 8B C7 2B C6 8B D0 + 03 D3 42 81 FA ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 40 50 56 8D 85 ?? ?? ?? ?? 03 C3 50 E8 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 + } + $file_search_1_3 = { + 8B F0 83 FE ?? 74 ?? 56 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 53 ?? + 03 C2 40 3D ?? ?? ?? ?? 7F ?? C6 84 1D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B C3 48 50 8D + 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 03 C3 40 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 40 03 D8 8B F7 80 3E ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 8D 85 ?? ?? ?? + ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 5F 5E 5B 8B E5 5D C3 + } + $raw_socket_connection_2 = { + 55 8B EC 83 C4 ?? 53 56 8B F2 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? + ?? 64 FF 30 64 89 20 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 83 FB ?? 74 ?? 8D 45 ?? + 33 C9 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 8B C6 86 E0 66 89 45 ?? 8B 45 + ?? E8 ?? ?? ?? ?? 89 45 ?? 6A ?? 8D 45 ?? 50 53 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B C3 E8 + ?? ?? ?? ?? 83 CB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? + C3 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_*)) and ( all of ($remote_connection_p*)) and ($drop_ransom_note) + uint16(0)==0x5A4D and (($http_connection_1 and $file_search_1_1 and $file_search_1_2 and $file_search_1_3 and $raw_socket_connection_1_1 and $raw_socket_connection_1_2 and $raw_socket_connection_1_3 and $raw_socket_connection_1_4 and $raw_socket_connection_1_5) or ($raw_socket_connection_2 and $file_search_1_1 and $file_search_1_2 and $file_search_1_3)) } -rule REVERSINGLABS_Win32_Ransomware_Hydracrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Erica : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects HydraCrypt ransomware." + description = "Yara rule that detects Erica ransomware." author = "ReversingLabs" - id = "2e780f7c-8d6d-51c8-b65e-330cc3b17bb7" + id = "38f57157-bd49-5a63-8c69-497eb9efe274" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.HydraCrypt.yara#L1-L174" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "910a6f23f06cecb8d3115ebfed42a66412dbd0d3a519e39f21df81b0c2028f48" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Erica.yara#L1-L76" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "93512091943f3a3b395c38fa3b0f5ecdbbf1cdf967ccfea4d7145c940076e046" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -32235,155 +33931,72 @@ rule REVERSINGLABS_Win32_Ransomware_Hydracrypt : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "HydraCrypt" + tc_detection_name = "Erica" tc_detection_factor = 5 importance = 25 strings: - $remote_connection_1 = { - 55 8B EC 83 EC ?? 53 56 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 BE ?? ?? ?? ?? 56 - 33 DB 53 53 6A ?? 68 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? 6A ?? 89 45 ?? E8 ?? ?? ?? ?? - 59 59 53 53 6A ?? 53 53 6A ?? FF 75 ?? FF 75 ?? FF D0 89 45 ?? 3B C3 0F 84 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 53 56 53 53 68 ?? ?? ?? ?? FF 75 ?? 68 - ?? ?? ?? ?? FF 75 ?? FF D0 89 45 ?? 3B C3 0F 84 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 6A ?? - E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 6A ?? FF D0 8B F0 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? - ?? FF 75 ?? 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? FF 75 ?? 56 E8 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? FF 75 ?? 56 E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? - BF ?? ?? ?? ?? 57 89 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 56 50 57 FF 75 ?? E8 ?? ?? ?? ?? - 83 C4 ?? 5F 39 5D ?? 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 59 39 5D ?? 74 ?? FF 75 ?? E8 ?? - ?? ?? ?? 59 39 5D ?? 5E 5B 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 59 C9 C3 - } - $remote_connection_2 = { - 55 8B EC 83 EC ?? 53 56 57 6A ?? 59 68 ?? ?? ?? ?? 33 DB BE ?? ?? ?? ?? 8D 7D ?? 6A - ?? 89 5D ?? F3 A5 E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 53 53 53 8D 4D ?? 51 FF D0 8B - F8 3B FB 75 ?? 33 C0 E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 53 68 - ?? ?? ?? ?? 53 53 FF 75 ?? 57 FF D0 8B F0 3B F3 75 ?? 53 E8 ?? ?? ?? ?? 59 EB ?? 68 - ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 6A ?? 8D 4D ?? 51 FF D0 68 ?? ?? ?? ?? 6A ?? - E8 ?? ?? ?? ?? 59 59 8D 4D ?? 51 6A ?? 8D 4D ?? 51 56 FF D0 39 5D ?? 75 ?? 57 E8 ?? - ?? ?? ?? 56 E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 33 C0 83 C4 ?? 40 EB ?? 68 ?? ?? - ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 4D ?? 51 FF D0 33 C9 3B C8 1B C0 - F7 D8 5F 5E 5B C9 C3 - } - $remote_connection_3 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 BE ?? ?? ?? ?? 8D 7D ?? A5 A5 33 DB 66 A5 53 8D - 45 ?? 53 50 A4 E8 ?? ?? ?? ?? 59 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 83 C4 ?? BE ?? ?? ?? ?? 56 53 FF D0 56 - 50 89 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? - ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? FF D0 BF ?? ?? ?? ?? 57 50 89 45 ?? E8 ?? ?? ?? - ?? 59 59 85 DB 7E ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 59 59 8B C3 6A ?? 99 59 - F7 F9 85 D2 75 ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 6A ?? - E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 8B 45 ?? 0F B6 04 03 - 50 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 55 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? - ?? ?? ?? 83 C4 ?? 43 3B DE 7C ?? E8 ?? ?? ?? ?? 8B F0 E8 ?? ?? ?? ?? 50 56 8D 85 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 55 ?? 83 C4 ?? 83 7D ?? ?? BB ?? ?? ?? ?? BE ?? ?? ?? - ?? 75 ?? 53 56 57 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? - 75 ?? 53 56 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F - 5E 5B C9 C3 - } - $encrypt_files_1 = { - 8A 45 ?? 04 ?? 66 98 66 89 45 ?? 0F B7 C0 50 8D 45 ?? 68 ?? ?? ?? ?? 50 FF 55 ?? 68 - ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 51 FF D0 8B F0 83 FE ?? 74 ?? 83 - FE ?? 74 ?? 83 FE ?? 75 ?? FF 75 ?? 8D 45 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 83 FE ?? 74 ?? 83 FE ?? 75 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 57 6A ?? E8 ?? ?? ?? - ?? 59 59 68 ?? ?? ?? ?? FF D0 FF 45 ?? 83 7D ?? ?? 0F 8C ?? ?? ?? ?? 83 3D ?? ?? ?? - ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 BE - ?? ?? ?? ?? 56 6A ?? E8 ?? ?? ?? ?? 59 59 53 53 8D 8D ?? ?? ?? ?? 51 53 FF D0 8D 85 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 - ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? - 75 ?? E8 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 53 FF D0 56 6A - ?? E8 ?? ?? ?? ?? 59 59 53 6A ?? 8D 8D ?? ?? ?? ?? 51 53 FF D0 8D 85 ?? ?? ?? ?? 50 - 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 55 ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 - C4 ?? 6A ?? 53 53 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 53 FF D0 57 6A ?? E8 ?? ?? ?? - ?? 59 59 68 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 53 FF D0 5F - 5E 33 C0 5B C9 C2 - } - $encrypt_files_2 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 BE ?? ?? ?? ?? 8D 7D ?? A5 A5 33 DB 66 A5 53 8D - 45 ?? 53 50 A4 E8 ?? ?? ?? ?? 59 50 E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 7D ?? A5 A5 89 - 45 ?? 8D 45 ?? 50 66 A5 E8 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A - ?? 89 45 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 FF D0 BE ?? ?? ?? ?? 8D 7D ?? A5 A5 66 A5 BE - ?? ?? ?? ?? 8D 7D ?? A5 A5 A5 53 89 45 ?? 8D 45 ?? 53 50 66 A5 E8 ?? ?? ?? ?? 59 50 - E8 ?? ?? ?? ?? 8B F0 8D 45 ?? 50 E8 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 6A ?? 8D 8D ?? ?? ?? ?? 51 53 FF D0 BF ?? - ?? ?? ?? 57 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 55 ?? 68 ?? - ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 8D 8D ?? ?? ?? ?? 51 FF D0 68 ?? ?? ?? ?? - 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 53 53 FF D0 8B F0 53 56 E8 ?? ?? ?? ?? 59 - 59 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 FF - D0 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF - } - $encrypt_files_3 = { - D0 E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? - ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 85 C0 75 ?? BE ?? ?? ?? - ?? EB ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? FF D0 56 E8 ?? ?? - ?? ?? 59 3C ?? 75 ?? BE ?? ?? ?? ?? 56 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF D0 56 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D0 - E8 ?? ?? ?? ?? 56 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF - D0 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF - D0 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? - ?? ?? 83 C4 ?? 53 6A ?? 8D 8D ?? ?? ?? ?? 51 53 FF D0 68 ?? ?? ?? ?? 57 8D 85 ?? ?? - ?? ?? 50 BE ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 50 FF 55 ?? 68 ?? ?? ?? ?? 57 8D 85 ?? - ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 56 50 FF 55 ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 - C4 ?? 68 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 7D ?? A5 68 ?? ?? ?? - ?? 6A ?? 66 A5 E8 ?? ?? ?? ?? 83 C4 ?? 53 FF D0 6A ?? FF 75 ?? A3 ?? ?? ?? ?? FF 55 - ?? 6A ?? FF 75 ?? 8B F0 FF 55 ?? FF 75 ?? 89 45 ?? 53 E8 ?? ?? ?? ?? 8D 45 ?? 50 FF - } - $encrypt_files_4 = { - 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 66 85 C0 75 ?? 33 C0 40 E9 ?? ?? ?? ?? 8B 3D - ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 8B C8 8B 45 ?? 53 57 99 53 53 - 2B C2 68 ?? ?? ?? ?? D1 F8 2D ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 8B C6 99 2B C2 D1 F8 2D - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 53 FF D1 A3 ?? ?? ?? ?? E8 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? 51 FF D0 E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 - BE ?? ?? ?? ?? 85 C0 75 ?? 56 6A ?? E8 ?? ?? ?? ?? 59 59 53 53 53 68 ?? ?? ?? ?? 53 - 53 FF D0 56 6A ?? E8 ?? ?? ?? ?? 59 59 53 53 53 68 ?? ?? ?? ?? 53 53 FF D0 39 1D ?? - ?? ?? ?? 75 ?? 6A ?? 58 EB ?? 6A ?? 59 33 C0 68 ?? ?? ?? ?? 89 5D ?? 8D 7D ?? 6A ?? - F3 AB E8 ?? ?? ?? ?? 59 59 6A ?? FF D0 EB ?? 83 F8 ?? 74 ?? 68 ?? ?? ?? ?? 6A ?? E8 - ?? ?? ?? ?? 59 59 8D 4D ?? 51 FF D0 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 8D 4D - ?? 51 FF D0 6A ?? 59 8D 75 ?? BF ?? ?? ?? ?? F3 A5 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? - ?? 59 59 53 53 53 8D 4D ?? 51 FF D0 3B C3 75 ?? 8B 45 ?? 5F 5E 5B C9 C2 ?? ?? 6A ?? - E9 + $encrypt_files_p1 = { + 55 8B EC 83 C4 ?? 53 56 57 89 4D ?? 8B F2 8B D8 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 + ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 89 45 ?? 8A 43 ?? 2C ?? 72 ?? 74 ?? EB ?? BF ?? + ?? ?? ?? EB ?? BF ?? ?? ?? ?? EB ?? BF ?? ?? ?? ?? 33 DB 68 ?? ?? ?? ?? 8B 45 ?? 50 + 8B 45 ?? 50 6A ?? 56 E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 45 ?? 50 6A ?? 6A ?? 57 8B 06 50 + E8 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? + 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 50 6A ?? 8B 45 ?? 50 8B 45 ?? 50 + 8B 06 50 E8 ?? ?? ?? ?? 85 C0 75 ?? BB ?? ?? ?? ?? EB ?? BB ?? ?? ?? ?? EB ?? BB ?? + ?? ?? ?? EB ?? BB ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 33 C0 5A + 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 } - $remote_connection_4 = { - 55 8B EC 51 51 53 56 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 33 F6 56 56 56 6A ?? - 68 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? 6A ?? 8B D8 E8 ?? ?? ?? ?? 59 59 56 56 6A ?? 56 - 56 6A ?? FF 75 ?? 53 FF D0 68 ?? ?? ?? ?? 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 59 59 56 68 - ?? ?? ?? ?? 56 56 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? FF D0 68 ?? ?? ?? - ?? 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 59 59 56 56 56 56 FF 75 ?? FF D0 53 E8 ?? ?? ?? ?? - FF 75 ?? E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 5E 5B C9 C3 + $encrypt_files_p2 = { + 8D 40 ?? 55 8B EC 83 C4 ?? 53 33 DB 89 5D ?? 89 5D ?? 8B D9 89 55 ?? 89 45 ?? 33 C0 + 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 89 45 ?? 33 C0 89 45 ?? 33 C0 89 45 ?? 33 + C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? 50 8B 45 ?? 8D 50 ?? 8B 45 ?? 33 C9 + E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 83 C0 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B + 40 ?? E8 ?? ?? ?? ?? 8B D0 4A 8B 45 ?? 83 C0 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? E8 + ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 8B 45 ?? 8B 48 ?? 8B 45 ?? 8D 50 ?? 8B 45 ?? E8 ?? + ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 85 C0 75 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 + ?? ?? ?? ?? 8B 45 ?? 50 53 8B 45 ?? 50 8B 45 ?? 50 8D 4D ?? 8D 55 ?? 8B 45 ?? E8 ?? + ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? + 8B 45 ?? 50 8D 45 ?? 50 8B 45 ?? 83 C0 ?? E8 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 8B 45 + ?? 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? 8B 45 ?? 83 C0 ?? 8B 55 ?? + E8 ?? ?? ?? ?? 8B 45 ?? 50 8D 45 ?? 50 8B 45 ?? 83 C0 ?? E8 ?? ?? ?? ?? 50 6A ?? 6A + ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? 85 C0 74 ?? C7 45 ?? ?? ?? + ?? ?? 8B 45 ?? 83 C0 ?? 8B 55 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? E8 ?? ?? ?? ?? EB + ?? 8B 45 ?? 8B 50 ?? 8B 45 ?? 83 C0 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? + ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 6A ?? 8B 45 + ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 8D 50 ?? 8B 45 ?? 8B 4D ?? E8 ?? ?? + ?? ?? C3 } - $remote_connection_5 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 33 FF 68 ?? ?? ?? ?? 47 57 E8 ?? ?? ?? ?? 59 59 - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 FF 75 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? BE ?? ?? ?? ?? 56 57 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 - FF D0 56 57 E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 56 57 E8 - ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 68 ?? ?? ?? ?? 6A ?? E8 - ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? 51 6A ?? FF D0 BE ?? ?? ?? ?? 85 C0 74 ?? 56 57 - E8 ?? ?? ?? ?? 59 59 6A ?? FF D0 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 6A ?? 57 - 6A ?? FF D0 8B D8 85 DB 7D ?? 56 57 E8 ?? ?? ?? ?? 59 59 6A ?? FF D0 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 59 6A ?? 8D 4D ?? - 51 FF D0 6A ?? 58 66 89 45 ?? 8B 46 ?? 8B 00 8B 00 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 66 - 89 45 ?? 6A ?? 8D 45 ?? 50 53 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 8D ?? ?? ?? ?? 51 FF D0 6A ?? 50 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 53 E8 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? FF D0 5F 5E 5B C9 C3 + $find_files = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 DB 89 9D ?? ?? ?? ?? 89 5D ?? 8B D9 89 55 ?? 89 + 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF + 30 64 89 20 8B C3 E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? + 80 7C 02 ?? ?? 74 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 + ?? 80 38 ?? 75 ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? + ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 85 F6 0F 95 C0 EB ?? F7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? 77 ?? 83 3B ?? 74 ?? 8B C3 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + FF 33 FF 75 ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? 8B C3 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? + ?? ?? F7 D8 1B C0 F7 D8 84 C0 75 ?? 56 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and (($encrypt_files_1 and $remote_connection_1 and $remote_connection_2 and $remote_connection_3) or ($encrypt_files_2 and $encrypt_files_3 and $encrypt_files_4 and $remote_connection_4 and $remote_connection_5)) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Satan : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Mafia : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Satan ransomware." + description = "Yara rule that detects Mafia ransomware." author = "ReversingLabs" - id = "7ec379d8-172c-52ee-9284-6898dd446468" + id = "67f09000-751f-539a-b222-25b1502c2728" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Satan.yara#L1-L152" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0074090c2a6cc483deffdc83dc1c0bfbd150e201c27e54f998dd2c0a7660f917" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Mafia.yara#L1-L142" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "5c17b799f0b4f1f8f72a2e4203a6606f7783ceec2034694f8a21ff65e5afdb26" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -32391,143 +34004,131 @@ rule REVERSINGLABS_Win32_Ransomware_Satan : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Satan" + tc_detection_name = "Mafia" tc_detection_factor = 5 importance = 25 strings: - $remote_connection = { - 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 - E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 - C4 ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? FF B5 ?? - ?? ?? ?? 89 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B F0 6A ?? - 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 FF D3 8B 3D ?? ?? ?? ?? 6A ?? 56 FF D7 8D 45 ?? 50 - 8D 45 ?? 50 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 50 89 85 ?? ?? ?? - ?? FF D3 8B 9D ?? ?? ?? ?? 6A ?? 53 FF D7 68 ?? ?? ?? ?? 33 FF E8 ?? ?? ?? ?? 83 C4 - ?? 8B F0 57 68 ?? ?? ?? ?? 6A ?? 57 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? 39 7D ?? 76 ?? 68 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 53 FF 15 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 6A ?? 51 50 - 56 FF B5 ?? ?? ?? ?? 03 F8 FF 15 ?? ?? ?? ?? 39 7D ?? 77 ?? 8B 85 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 83 C4 ?? 53 FF D6 FF B5 ?? - ?? ?? ?? FF D6 FF B5 ?? ?? ?? ?? FF D6 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 - 5D C3 + $find_files = { + 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? + ?? ?? 53 56 57 68 ?? ?? ?? ?? 8D 44 24 ?? 8B F1 6A ?? 50 89 74 24 ?? C7 44 24 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 33 C9 68 ?? ?? ?? ?? 51 8D 94 24 ?? ?? ?? ?? 52 66 89 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 68 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? 51 66 89 84 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? + ?? 83 C4 ?? 8D 44 24 ?? 50 8D 8C 24 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? + 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? + ?? ?? ?? 8B 35 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 68 ?? ?? ?? ?? 8D + 8C 24 ?? ?? ?? ?? 6A ?? 51 E8 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 8D 84 24 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? 51 FF D6 B8 ?? ?? + ?? ?? 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 56 81 EC ?? ?? + ?? ?? B9 ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? 8B FC F3 A5 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? + ?? 8D 54 24 ?? 52 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 44 24 ?? 50 81 EC ?? ?? ?? ?? + B9 ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? 8B FC F3 A5 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 8D + 4C 24 ?? 51 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 53 FF 15 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? + ?? 5F 5E 5B 33 CC 33 C0 E8 ?? ?? ?? ?? 8B E5 5D C3 } - $search_processes = { - 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 51 50 - FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 0F 1F - 44 00 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 8B 4C B5 ?? - 8D 85 ?? ?? ?? ?? 0F 1F 44 00 ?? 8A 11 3A 10 75 ?? 84 D2 74 ?? 8A 51 ?? 3A 50 ?? 75 - ?? 83 C1 ?? 83 C0 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 75 ?? FF B5 ?? ?? - ?? ?? 50 68 ?? ?? ?? ?? FF D7 6A ?? 50 FF D3 46 83 FE ?? 76 ?? 8D 85 ?? ?? ?? ?? 50 - FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B - E8 ?? ?? ?? ?? 8B E5 5D C3 + $remote_connection_p1 = { + 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 33 C0 57 + 68 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 66 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 6A ?? 52 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? 6A ?? 51 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? + 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 52 E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 83 C4 ?? 33 C0 68 ?? + ?? ?? ?? 50 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 51 E8 ?? + ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 33 C0 89 85 } - $encrypt_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? - ?? ?? 31 45 ?? 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 4D ?? 8B 4D - ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? 83 CB ?? 89 - 5D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 F6 89 75 ?? 89 75 ?? 56 68 ?? ?? - ?? ?? 6A ?? 56 6A ?? 6A ?? 51 8B 3D ?? ?? ?? ?? FF D7 89 45 ?? 3B C3 0F 84 ?? ?? ?? - ?? 56 68 ?? ?? ?? ?? 6A ?? 56 6A ?? 6A ?? FF 75 ?? FF D7 8B D8 89 5D ?? 83 FB ?? 0F - 84 ?? ?? ?? ?? 8B 7D ?? 8B 07 85 C0 0F 84 ?? ?? ?? ?? 8D 4D ?? 51 56 56 68 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 50 FF - 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? - FF 75 ?? 68 ?? ?? ?? ?? FF 37 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 32 C0 89 45 ?? 88 - 45 ?? 33 FF 89 7D ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 FF 75 - ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 0F B6 C0 81 7D ?? ?? ?? ?? ?? - B9 ?? ?? ?? ?? 0F 42 C1 89 45 ?? 88 45 ?? 68 ?? ?? ?? ?? 8D 4D ?? 51 56 6A ?? 0F B6 - C0 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 85 FF 75 ?? 57 8D 45 ?? 50 68 ?? - ?? ?? ?? FF 35 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 56 53 FF - 15 ?? ?? ?? ?? 85 C0 74 ?? 47 89 7D ?? 8B 45 ?? 84 C0 0F 84 ?? ?? ?? ?? 80 7D ?? ?? - 74 ?? 83 05 ?? ?? ?? ?? ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8A 45 ?? - 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 + $remote_connection_p2 = { + 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? + ?? 66 89 95 ?? ?? ?? ?? 8B 48 ?? 8B 11 8B 02 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8D + 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF + 15 ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? + 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 50 ?? 8B FF 8A 08 40 84 C9 75 ?? 6A + ?? 2B C2 50 8D 8D ?? ?? ?? ?? 51 56 FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 95 ?? + ?? ?? ?? 52 56 FF D3 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 + C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D7 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 50 + 8D 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF + D7 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 51 E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8D + 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 FF D7 + 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 6A ?? 52 E8 ?? ?? ?? ?? 53 8D 85 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 FF D7 68 ?? ?? ?? ?? 8D 95 + ?? ?? ?? ?? 6A ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 40 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? EB + ?? 68 ?? ?? ?? ?? FF D7 56 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? + 8B E5 5D C3 68 } - $search_files_in_specific_folders_p1 = { - 51 8D 85 ?? ?? ?? ?? 8B CE 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 8B F0 F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 80 7D ?? ?? 0F 84 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? - ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 - C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? - 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F - 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 83 FF + $encrypt_files_p1 = { + 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? + ?? ?? 53 56 8B 75 ?? 57 68 ?? ?? ?? ?? 33 DB 8D 8C 24 ?? ?? ?? ?? 33 C0 53 51 66 89 + 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 54 24 ?? 53 52 89 5C 24 + ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 44 24 ?? 53 50 89 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 + ?? 33 C0 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 53 51 89 5C 24 ?? 89 44 24 ?? 89 44 24 + ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 88 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 53 52 88 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 53 50 88 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 33 C9 53 52 66 89 8C 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 4D ?? 8B C1 83 C4 ?? 48 74 ?? 48 74 ?? 8B 45 ?? 8B 55 ?? 50 52 51 56 FF + 15 ?? ?? ?? ?? 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C2 } - $search_files_in_specific_folders_p2 = { - 75 ?? FF 75 ?? 8D 55 ?? 8B CB 57 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 - F6 0F 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 FF ?? 0F 85 ?? ?? ?? ?? FF 75 ?? 8D 55 ?? 8B - CB 57 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 0F 85 ?? ?? ?? ?? E9 ?? - ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 33 C9 EB ?? 8D 8D ?? ?? ?? ?? 8D 51 ?? 8A 01 41 - 84 C0 75 ?? 2B CA 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 83 EC ?? 8D - 4D ?? E8 ?? ?? ?? ?? 6A ?? 40 8D 4D ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 - 8D 45 ?? 3B C6 74 ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 - C4 ?? 56 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - EC ?? C6 45 ?? ?? 8D 4D ?? 54 E8 ?? ?? ?? ?? 83 EC ?? 8D 4D ?? 54 E8 ?? ?? ?? ?? 83 - EC ?? 8D 4D ?? 54 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 FF ?? 75 ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? 50 - 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 84 - C0 8D 8D ?? ?? ?? ?? 0F 94 C3 EB ?? 83 FF ?? 75 ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? 50 8D - 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 8A D8 + $encrypt_files_p2 = { + 53 FF 15 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E 5B 33 CC 33 C0 E8 ?? ?? ?? ?? 8B E5 + 5D C2 ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 33 F6 E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 79 ?? 48 0D ?? ?? ?? ?? 40 + 88 86 ?? ?? ?? ?? 46 83 FE ?? 7C ?? 33 F6 E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 79 ?? 48 0D + ?? ?? ?? ?? 40 88 86 ?? ?? ?? ?? 46 83 FE ?? 7C ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8D 49 ?? 0F B6 83 ?? ?? ?? ?? 6A + ?? 8D 94 24 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? 51 8D 94 + 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 83 C4 ?? 8B C8 + 8A 10 40 84 D2 75 ?? 8D BC 24 ?? ?? ?? ?? 2B C1 8B F1 4F 8A 4F ?? 47 84 C9 75 ?? 8B + C8 C1 E9 ?? F3 A5 8B C8 83 E1 ?? 8D 84 24 ?? ?? ?? ?? F3 A4 8B C8 8A 10 40 84 D2 75 + ?? BF ?? ?? ?? ?? 2B C1 8B F1 4F 8A 4F ?? 47 84 C9 75 ?? 8B C8 C1 E9 ?? F3 A5 8B C8 } - $search_files_in_specific_folders_p3 = { - 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 84 DB 8B 9D ?? ?? ?? ?? 74 ?? 8D 45 ?? - 8B CB 50 E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? - 83 F8 ?? 0F 84 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 - ?? 33 F6 8D 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF B5 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 85 ?? ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 45 ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? - E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? - C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? - ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 6A ?? 50 FF 75 ?? E8 ?? ?? - ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? C7 45 - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C6 8B 4D ?? 64 89 0D ?? ?? - ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files_p3 = { + 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 83 E1 ?? 6A ?? 50 F3 A4 E8 ?? ?? ?? ?? 83 C4 ?? + 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 6A ?? 51 E8 ?? ?? ?? ?? 43 83 C4 ?? 83 FB ?? 0F + 8C ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? + ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 DB EB ?? 8D A4 24 ?? ?? ?? ?? EB ?? 8D 49 ?? + 0F B6 83 ?? ?? ?? ?? 6A ?? 8D 94 24 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C + 24 ?? ?? ?? ?? 51 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 8D 84 24 ?? + ?? ?? ?? 83 C4 ?? 8B C8 8A 10 40 84 D2 75 ?? 8D BC 24 ?? ?? ?? ?? 2B C1 8B F1 4F 8A + 4F ?? 47 84 C9 75 ?? 8B C8 C1 E9 ?? F3 A5 8B C8 83 E1 ?? 8D 84 24 ?? ?? ?? ?? F3 A4 + 8B C8 8A 10 40 84 D2 75 ?? BF ?? ?? ?? ?? 2B C1 8B F1 4F 8A 4F ?? 47 84 C9 75 ?? 8B + } + $encrypt_files_p4 = { + C8 C1 E9 ?? F3 A5 8B C8 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 83 E1 ?? 6A ?? 50 F3 A4 + E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 6A ?? 51 E8 ?? ?? ?? ?? + 43 83 C4 ?? 83 FB ?? 0F 8C ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? BF ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? + 56 FF D3 83 C4 ?? 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 6A ?? 6A ?? 56 68 ?? ?? ?? ?? + 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 89 44 8C ?? 41 89 4C 24 ?? 47 83 C6 + ?? 83 FF ?? 7E ?? 8B 54 24 ?? 6A ?? 6A ?? 8D 4C 24 ?? 51 52 FF 15 ?? ?? ?? ?? 8D 44 + 24 ?? 50 8D 4C 24 ?? 51 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? FF 15 } condition: - uint16(0)==0x5A4D and ($search_processes and ( all of ($search_files_in_specific_folders_p*)) and $encrypt_files and $remote_connection) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Janelle : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Henry : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Janelle ransomware." + description = "Yara rule that detects Henry ransomware." author = "ReversingLabs" - id = "4fef3be5-8332-5ce2-b1e9-3993e6963331" - date = "2021-12-16" - modified = "2021-12-16" + id = "63627f2b-3205-5790-ba97-8e0d1da39d7c" + date = "2021-06-14" + modified = "2021-06-14" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Janelle.yara#L1-L96" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "49f1eac82930606183ab9cf1d5c6c42534d58735876134793e9712e78eb5a4c7" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Henry.yara#L1-L80" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "e6ab2a8a344d40407118e29ff78f5a0144f42a0fbdee19a80b341b59f056d292" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -32535,88 +34136,69 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Janelle : TC_DETECTION MALICIOUS MAL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Janelle" + tc_detection_name = "Henry" tc_detection_factor = 5 importance = 25 strings: - $setup_env_p1 = { - 00 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 73 ?? ?? ?? ?? 0A 06 02 7D ?? ?? - ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 2B ?? 08 6F - ?? ?? ?? ?? 74 ?? ?? ?? ?? 0D 00 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 6F - ?? ?? ?? ?? 6F ?? ?? ?? ?? 26 00 08 6F ?? ?? ?? ?? 2D ?? DE ?? 08 75 ?? ?? ?? ?? 13 ?? - 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? 00 DC 02 7B ?? ?? ?? ?? 16 6F ?? ?? ?? ?? 00 16 28 ?? - ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE 01 13 ?? 11 ?? 2C ?? 00 16 - 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 16 28 ?? - ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 28 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 02 16 28 ?? ?? ?? ?? 00 00 28 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 6F ?? ?? ?? ?? 16 FE 02 16 FE 01 13 ?? 11 ?? 2C ?? 00 28 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? - 12 ?? 23 ?? ?? ?? ?? ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? - ?? 00 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 23 ?? ?? ?? ?? ?? ?? ?? ?? 28 ?? ?? ?? - ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 02 - } - $setup_env_p2 = { - 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 7B ?? ?? ?? ?? 28 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 2B ?? 00 16 28 ?? ?? ?? ?? 72 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 72 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 - 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 28 ?? ?? ?? ?? 16 28 - ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 28 ?? ?? ?? ?? 02 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 00 06 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 7D ?? ?? ?? ?? 16 28 ?? ?? ?? ?? - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 28 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 - ?? 11 ?? 2C ?? 00 02 17 7D ?? ?? ?? ?? 06 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? - ?? 25 17 6F ?? ?? ?? ?? 00 6F ?? ?? ?? ?? 00 06 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 02 - 7B ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? - ?? ?? 00 00 2A - } $find_files = { - 73 ?? ?? ?? ?? 0A 06 02 7D ?? ?? ?? ?? 06 04 7D ?? ?? ?? ?? 06 05 7D ?? ?? ?? ?? 00 00 - 03 28 ?? ?? ?? ?? 0B 00 07 0C 16 0D 2B ?? 08 09 9A 13 ?? 00 02 11 ?? 06 7B ?? ?? ?? ?? - 28 ?? ?? ?? ?? 00 00 09 17 58 0D 09 08 8E 69 32 ?? 06 7B ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? - 00 00 00 03 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 06 7D ?? ?? - ?? ?? 11 ?? 11 ?? 11 ?? 9A 7D ?? ?? ?? ?? 00 11 ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 - ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 00 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? - 8E 69 32 ?? 00 DE ?? 13 ?? 00 72 ?? ?? ?? ?? 03 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 DE - ?? 00 00 DE ?? 26 00 72 ?? ?? ?? ?? 03 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 DE ?? 2A + 02 6F ?? ?? ?? ?? 0A 16 0B 2B ?? 06 07 9A 0C 08 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? + ?? ?? DE ?? 26 DE ?? 07 17 58 0B 07 06 8E 69 32 ?? 02 6F ?? ?? ?? ?? 0D 16 0B 38 ?? ?? + ?? ?? 09 07 9A 13 ?? 11 ?? 6F ?? ?? ?? ?? 19 17 73 ?? ?? ?? ?? 25 6F ?? ?? ?? ?? D4 8D + ?? ?? ?? ?? 13 ?? 25 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 26 6F ?? ?? ?? ?? 11 ?? 6F ?? + ?? ?? ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 18 18 73 ?? ?? ?? ?? 25 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 6F ?? ?? ?? + ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 07 17 58 0B 07 09 8E 69 3F ?? ?? + ?? ?? 2A } $encrypt_files = { - 00 28 ?? ?? ?? ?? 0A 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 18 73 ?? ?? ?? ?? 0B 28 ?? ?? ?? - ?? 04 6F ?? ?? ?? ?? 0C 73 ?? ?? ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 20 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 00 09 18 6F ?? ?? ?? ?? 00 08 06 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? - 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 11 ?? 09 6F - ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 1A 6F ?? ?? ?? ?? 00 07 06 16 06 - 8E 69 6F ?? ?? ?? ?? 00 07 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 03 19 73 ?? ?? ?? - ?? 13 ?? 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? 13 ?? 00 2B ?? 00 28 ?? ?? ?? ?? 00 11 ?? 11 ?? - 16 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 25 13 ?? 16 FE - 02 13 ?? 11 ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 13 ?? 00 72 ?? ?? ?? ?? 11 ?? 6F - ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 DE ?? DE ?? 00 11 ?? 6F ?? ?? ?? ?? 00 - 07 6F ?? ?? ?? ?? 00 00 DC 2A + 02 8E 2D ?? 72 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 03 28 ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 73 + ?? ?? ?? ?? 7A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 28 ?? + ?? ?? ?? 0D 73 ?? ?? ?? ?? 13 ?? 03 08 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 1F ?? 6F ?? ?? ?? + ?? 07 6F ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 17 73 ?? ?? ?? ?? 25 02 16 02 8E 69 6F ?? ?? ?? + ?? 25 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 0A 11 ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? + 25 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 FE ?? 09 6F ?? ?? ?? ?? DC 06 2A + } + $setup_environment = { + 02 28 ?? ?? ?? ?? 1B 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 73 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 1F ?? 28 + ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 02 28 ?? ?? ?? ?? 2A + } + $init_components = { + 02 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 02 + 7B ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 22 ?? ?? ?? ?? 16 19 + 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 20 ?? ?? ?? ?? 1F ?? 73 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? + ?? ?? 20 ?? ?? ?? ?? 1F ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 16 6F ?? ?? + ?? ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 17 6F ?? ?? ?? + ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 22 ?? ?? ?? ?? 16 19 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 20 ?? ?? ?? ?? 1F ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 + 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 20 ?? ?? ?? ?? 20 ?? ?? + ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 02 7B ?? ?? ?? + ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 22 ?? ?? ?? ?? 22 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 02 17 28 ?? ?? ?? ?? 02 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 02 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 02 7B ?? ?? + ?? ?? 6F ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 02 02 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 16 28 ?? ?? ?? ?? 02 28 ?? ?? + ?? ?? 2A } condition: - uint16(0)==0x5A4D and ( all of ($setup_env_p*)) and ($find_files) and ($encrypt_files) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($setup_environment) and ($init_components) } -rule REVERSINGLABS_Win32_Ransomware_FCT : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Dusk : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects FCT ransomware." + description = "Yara rule that detects Dusk ransomware." author = "ReversingLabs" - id = "ea3d5514-d6f2-5fd0-9247-a3f6b920d8d9" - date = "2020-07-15" - modified = "2020-07-15" + id = "cde30f40-f13c-53da-8656-cc293433aa36" + date = "2021-08-12" + modified = "2021-08-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.FCT.yara#L1-L86" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "b158ad56c92a926f7398a27b3576c259e39c9716ef192fa5944ce3cffdc6d7d0" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Dusk.yara#L1-L73" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "b6b0b3be7c17115dc5f225a13228f8a4811d84ae095c3ceba2d89f569f2d40c7" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -32624,81 +34206,65 @@ rule REVERSINGLABS_Win32_Ransomware_FCT : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "FCT" + tc_detection_name = "Dusk" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 6A ?? 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? 6A ?? E8 ?? ?? - ?? ?? 83 7D ?? ?? 8D 8D ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF 15 ?? ?? ?? ?? 89 - 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 6A ?? 51 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 33 DB 8B 55 ?? 33 C9 8B 75 - ?? 89 9D ?? ?? ?? ?? 85 D2 74 ?? 66 90 83 7D ?? ?? 8D 45 ?? 0F 43 C6 0F BE 04 08 41 - 03 D8 3B CA 72 ?? 89 9D ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? - ?? ?? ?? 66 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B CF C7 45 ?? ?? ?? ?? ?? 33 C0 - C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? 8D 51 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 - F9 51 57 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 75 ?? 8B C6 8B 55 ?? 2B C2 83 F8 ?? - 72 ?? 83 FE ?? 8D 45 ?? 8D 4A ?? BB ?? ?? ?? ?? 0F 43 45 ?? 89 4D ?? 66 89 1C 50 33 - D2 66 89 14 48 EB ?? 6A ?? 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? - ?? ?? 6A ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 51 + $encrypt_files_p1 = { + 03 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 06 6F ?? ?? ?? ?? + 0A 06 28 ?? ?? ?? ?? 0B 03 07 28 ?? ?? ?? ?? 03 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? + ?? ?? ?? DE ?? 26 DE ?? 2A } - $find_files_p2 = { - 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 - ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? - 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 9D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B BD ?? ?? ?? ?? E9 ?? ?? ?? ?? 53 FF 15 ?? ?? - ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 55 ?? 8D 48 ?? 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 8B 52 - ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 77 ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 - FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 - C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D - ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 E8 + $encrypt_files_p2 = { + 14 0A 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? 0C 73 ?? ?? + ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 03 07 20 ?? + ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? + ?? ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 17 6F ?? ?? ?? + ?? 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 11 ?? 02 16 02 8E 69 6F ?? ?? ?? ?? 11 + ?? 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 08 6F ?? ?? ?? ?? 0A DE ?? + 09 2C ?? 09 6F ?? ?? ?? ?? DC 08 2C ?? 08 6F ?? ?? ?? ?? DC 06 2A } - $encrypt_files_p1 = { - 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 51 57 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? - ?? 8B 75 ?? 8B C6 8B 55 ?? 2B C2 83 F8 ?? 72 ?? 83 FE ?? 8D 45 ?? 8D 4A ?? BB ?? ?? - ?? ?? 0F 43 45 ?? 89 4D ?? 66 89 1C 50 33 D2 66 89 14 48 EB ?? 6A ?? 68 ?? ?? ?? ?? - C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? 8D 51 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 8B 5D ?? 2B CA 8B 55 ?? 8B C3 D1 F9 2B - C2 3B C8 77 ?? 83 FB ?? 8D 04 09 50 8D 75 ?? 0F 43 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 3C - 0A 89 7D ?? 8D 04 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 04 7E EB ?? 51 8D 85 ?? - ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 81 BD - ?? ?? ?? ?? ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 6A ?? 0F 43 45 ?? 68 - ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F - 84 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B F2 85 F6 74 + $dusk_delete_itself = { + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 1A 8D ?? ?? ?? ?? 25 16 + 72 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? 03 28 ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 25 19 72 ?? ?? ?? ?? A2 0B 06 07 28 ?? ?? ?? + ?? 06 06 28 ?? ?? ?? ?? 18 60 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 06 73 ?? ?? + ?? ?? 25 17 6F ?? ?? ?? ?? 25 16 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 04 28 ?? ?? ?? ?? 28 + ?? ?? ?? ?? DE ?? 26 DE ?? 2A } - $encrypt_files_p2 = { - 6A ?? 8D 45 ?? 50 A1 ?? ?? ?? ?? 2B C6 56 03 C1 50 57 FF 15 ?? ?? ?? ?? 2B 75 ?? 74 - ?? 8B 8D ?? ?? ?? ?? EB ?? 57 FF 15 ?? ?? ?? ?? C6 45 ?? ?? 33 C0 8B 9D ?? ?? ?? ?? - BA ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 83 CB ?? 8B 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - 89 95 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 8D 48 ?? 3B CA 76 ?? C6 85 ?? ?? ?? ?? ?? FF B5 - ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 95 ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 0F 43 4D ?? 3B C2 77 ?? 8D 34 00 89 85 ?? - ?? ?? ?? 83 FA ?? 8D BD ?? ?? ?? ?? 56 0F 43 BD ?? ?? ?? ?? 51 57 E8 ?? ?? ?? ?? 83 - C4 ?? 33 C0 66 89 04 37 EB ?? 50 51 C6 85 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C2 8B 8D ?? ?? ?? ?? 2B C1 83 F8 ?? - 72 ?? 83 FA ?? 8D B5 ?? ?? ?? ?? 6A ?? 0F 43 B5 ?? ?? ?? ?? 8D 79 ?? 68 ?? ?? ?? ?? - 89 BD ?? ?? ?? ?? 8D 04 4E 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 04 7E EB ?? 6A ?? - 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 6A ?? E8 ?? - ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 45 ?? 0F 43 8D ?? ?? ?? ?? 83 7D - ?? ?? 51 0F 43 45 ?? 50 FF 15 + $find_files = { + 20 ?? ?? ?? ?? 72 ?? ?? ?? ?? A2 25 20 ?? ?? ?? ?? 72 ?? ?? ?? ?? A2 25 20 ?? ?? ?? ?? + 72 ?? ?? ?? ?? A2 0A 1F ?? 8D ?? ?? ?? ?? 25 16 1F ?? 28 ?? ?? ?? ?? A2 25 17 1E 28 ?? + ?? ?? ?? A2 25 18 1F ?? 28 ?? ?? ?? ?? A2 25 19 1F ?? 28 ?? ?? ?? ?? A2 25 1A 1F ?? 28 + ?? ?? ?? ?? A2 25 1B 1B 28 ?? ?? ?? ?? A2 25 1C 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? A2 25 1D 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? + ?? A2 25 1E 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 25 1F ?? 72 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 0B 16 0C 2B ?? 07 08 9A 0D + 1F ?? 28 ?? ?? ?? ?? 13 ?? 09 72 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 + ?? 11 ?? 9A 28 ?? ?? ?? ?? 13 ?? 06 11 ?? 28 ?? ?? ?? ?? 2C ?? 02 11 ?? 11 ?? 9A 11 ?? + 28 ?? ?? ?? ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? 00 02 09 28 ?? ?? ?? ?? DE ?? + 26 DE ?? 08 17 58 0C 08 07 8E 69 32 ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 26 DE ?? 26 DE ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 20 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 2A } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($dusk_delete_itself) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Timecrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Mountlocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects TimeCrypt ransomware." + description = "Yara rule that detects MountLocker ransomware." author = "ReversingLabs" - id = "38a0c383-8be6-5258-aa93-0cf09b18e5f7" - date = "2021-12-06" - modified = "2021-12-06" + id = "8ce7e5c4-9eca-5dd2-ab92-39b915900d72" + date = "2021-03-25" + modified = "2021-03-25" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.TimeCrypt.yara#L1-L69" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6849d6d5010d7bcb4052c10d5bd7cc29320ffc986f36289b272a1e9a8d14fab9" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.MountLocker.yara#L1-L86" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "d203217c229d54802e96e19dc66d38ecb0443d19e0492efe337df471a99559dc" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -32706,58 +34272,81 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Timecrypt : TC_DETECTION MALICIOUS M sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "TimeCrypt" + tc_detection_name = "MountLocker" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 7E ?? ?? ?? ?? 0A 16 0B 38 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0C 08 06 07 9A 7D ?? ?? ?? ?? 73 - ?? ?? ?? ?? 0D 09 08 7D ?? ?? ?? ?? 09 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 7D ?? ?? ?? ?? 09 - 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 28 ?? - ?? ?? ?? 09 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 09 7B ?? ?? - ?? ?? 72 ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 7B ?? ?? ?? ?? - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 2B ?? 09 7B ?? ?? ?? ?? 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 2C ?? 1B 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 2B ?? 1F ?? 28 ?? ?? ?? ?? 73 - ?? ?? ?? ?? 13 ?? 11 ?? 2D ?? 2A 11 ?? 6F ?? ?? ?? ?? 09 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 26 11 ?? 6F ?? ?? ?? ?? 09 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 26 07 17 58 0B 07 06 8E 69 3F ?? ?? ?? ?? 2A + $encrypt_files_p1 = { + 55 8B EC 83 E4 ?? 83 EC ?? 53 56 57 8B 3D ?? ?? ?? ?? 8B DA 8B F1 FF D7 89 44 24 ?? + 33 C0 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? 56 89 54 24 ?? 89 44 24 ?? FF 15 + ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? 51 50 FF 15 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? FF 74 24 ?? FF 74 24 ?? 6A ?? 6A ?? FF 74 24 ?? FF + 15 ?? ?? ?? ?? 89 44 24 ?? 85 C0 0F 84 ?? ?? ?? ?? 33 C9 0F 31 89 44 8C ?? 41 83 F9 + ?? 72 ?? FF 75 ?? 8B D3 8D 4C 24 ?? E8 ?? ?? ?? ?? 89 44 24 ?? 59 85 C0 74 ?? 8D 4C + 24 ?? E8 ?? ?? ?? ?? 89 44 24 ?? 8B 7C 24 ?? 8B 44 24 ?? 89 7C 24 ?? 89 44 24 ?? 8B + 35 ?? ?? ?? ?? 8B DE 8B 15 ?? ?? ?? ?? 03 DF 8B CA 89 54 24 ?? 13 C8 BF ?? ?? ?? ?? + 8B C6 F0 0F C7 0F 8B 7C 24 ?? 3B C6 8B 44 24 ?? 75 ?? 3B 54 24 ?? 75 ?? FF 74 24 ?? + 8B 35 ?? ?? ?? ?? FF D6 FF 74 24 ?? FF D6 8B 3D ?? ?? ?? ?? FF D7 8B F8 8B C2 2B 7C + 24 ?? 89 7C 24 ?? 1B 44 24 ?? 89 44 24 ?? 75 ?? 85 FF 0F 84 ?? ?? ?? ?? 8B 35 ?? ?? + ?? ?? 8B DE 8B 15 ?? ?? ?? ?? 03 DF 8B CA 89 54 24 ?? 13 C8 BF ?? ?? ?? ?? 8B C6 F0 + 0F C7 0F 8B 7C 24 ?? 3B C6 8B 44 24 ?? 75 ?? 3B 54 24 ?? 75 ?? 50 57 FF 74 24 ?? FF + 74 24 ?? E8 ?? ?? ?? ?? 89 44 24 ?? 8B C2 81 E2 ?? ?? ?? ?? 25 ?? ?? ?? ?? 89 54 24 + ?? DF 6C 24 ?? 83 64 24 ?? ?? 89 44 24 ?? DF 6C 24 ?? D9 E0 DE C1 D9 5C 24 ?? D9 44 + 24 ?? D9 05 ?? ?? ?? ?? D8 D9 DF E0 F6 C4 ?? 7A ?? D9 1D ?? ?? ?? ?? EB ?? DD D8 8B + 44 24 ?? EB ?? 8B 44 24 ?? 85 C0 8B 35 ?? ?? ?? ?? 74 ?? 50 FF D6 FF 74 24 ?? FF D6 + 33 C0 5F 5E 5B 8B E5 5D C3 } - $encrypt_files = { - 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 73 ?? ?? ?? ?? 0A 06 03 6F ?? ?? ?? ?? 06 02 6F - ?? ?? ?? ?? 26 06 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 06 2C ?? 06 6F - ?? ?? ?? ?? DC 02 17 28 ?? ?? ?? ?? DE ?? 26 DE ?? 2A + $encrypt_files_p2 = { + 55 8B EC 83 EC ?? 53 56 57 33 FF 6A ?? 8B F7 5B 0F 31 6A ?? 89 86 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 83 C6 ?? 3B F3 72 ?? 8B D3 B9 ?? ?? ?? ?? 8A 01 88 41 ?? 41 83 EA ?? 75 + ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 57 8D 45 ?? 89 5D ?? 50 89 7D ?? 89 7D ?? FF + 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 57 57 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 68 ?? ?? + ?? ?? 57 6A ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? 8B F0 FF 15 ?? ?? ?? ?? 57 FF + 75 ?? FF 15 ?? ?? ?? ?? 85 F6 74 ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? 33 C0 40 + EB ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5F 5E + 5B 8B E5 5D C3 } - $send_http_request = { - 1C 8D ?? ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 02 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 - 03 A2 25 1A 72 ?? ?? ?? ?? A2 25 1B 04 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 0A 73 ?? ?? ?? - ?? 25 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 6F - ?? ?? ?? ?? 26 DE ?? 26 DE ?? 2A + $find_files_p1 = { + 53 55 56 8B 74 24 ?? 8B EA 57 8B F9 6A ?? 83 26 ?? 58 66 89 44 6F ?? 8D 5F ?? 33 C0 + 66 89 44 6F ?? 8D 87 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 53 89 44 24 ?? FF D0 33 C9 66 89 + 4C 6F ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 39 4F ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 + F8 ?? 0F 85 ?? ?? ?? ?? 8D 46 ?? 50 6A ?? 8D 4E ?? 51 8D 56 ?? 52 8D 46 ?? 50 6A ?? + 6A ?? 8D 5F ?? 53 FF 15 ?? ?? ?? ?? F7 D8 1B C0 83 C0 ?? 89 06 74 ?? 8B CB E8 ?? ?? + ?? ?? 85 C0 74 ?? 6A ?? 58 66 89 44 6F ?? 33 C0 66 89 44 6F ?? 8D 87 ?? ?? ?? ?? 50 + 53 FF 54 24 ?? 33 C9 66 89 4C 6F ?? 83 F8 ?? 75 ?? 39 0E 74 ?? 51 FF 76 ?? FF 76 ?? + FF 76 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 83 3E ?? 74 ?? FF 76 ?? FF 15 ?? ?? ?? ?? + 83 26 ?? 83 C8 ?? 5F 5E 5D 5B C3 } - $send_dns_request = { - 1C 8D ?? ?? ?? ?? 25 16 04 28 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 03 A2 25 19 - 72 ?? ?? ?? ?? A2 25 1A 02 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? - 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? A2 25 1B 72 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 26 DE ?? 26 DE ?? 2A + $find_files_p2 = { + 55 8B EC 83 E4 ?? 83 EC ?? 53 55 56 8B F1 57 FF 46 ?? 8D 7E ?? 8B 07 8D 5E ?? 89 44 + 24 ?? 8B 46 ?? 53 89 07 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? 89 44 24 ?? 51 8B D0 8B CE E8 + ?? ?? ?? ?? 8B E8 59 83 FD ?? 75 ?? 33 C0 E9 ?? ?? ?? ?? 53 8D 86 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 8D 9E ?? ?? ?? ?? F6 03 ?? 74 ?? 8B 54 24 ?? 8B CE E8 ?? ?? ?? ?? EB + ?? 8D 86 ?? ?? ?? ?? 50 8B 44 24 ?? 05 ?? ?? ?? ?? 8D 04 46 50 FF 15 ?? ?? ?? ?? FF + 76 ?? 57 6A ?? FF 16 83 C4 ?? 85 C0 74 ?? 53 55 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 55 FF + 15 ?? ?? ?? ?? 83 7E ?? ?? 8D 5E ?? 74 ?? 83 7C 24 ?? ?? 74 ?? 6A ?? FF 74 24 ?? FF + 74 24 ?? FF 74 24 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 83 7C 24 ?? ?? 74 ?? FF 74 24 + ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 C0 89 0F 40 5F 5E 5D 5B 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($send_http_request) and ($send_dns_request) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Retmydata : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Crypmic : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects RetMyData ransomware." + description = "Yara rule that detects Crypmic ransomware." author = "ReversingLabs" - id = "f7a091d9-7ace-5aad-95b4-d5101fa7fdea" + id = "0d5c2141-c0ca-53c8-91fd-ec2d5f163df2" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.RetMyData.yara#L1-L79" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "54ce38d75e9ab82a77b9c338f75e180e19ac745f149289c7478a4aa3b44d70fd" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Crypmic.yara#L1-L56" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ee97c4d35cee68e080a4e9e0a21ecd3698da638463881a58f5daaf906ef86f75" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -32765,72 +34354,56 @@ rule REVERSINGLABS_Win32_Ransomware_Retmydata : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "RetMyData" + tc_detection_name = "Crypmic" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 55 89 E5 57 56 53 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 29 C4 8D 9D ?? ?? ?? ?? 8B 04 04 - C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 89 44 24 ?? 89 C7 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 89 1C 24 89 44 24 ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 40 51 51 0F 84 ?? ?? ?? ?? 8D - B5 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 85 - C0 74 ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 85 C0 74 ?? F6 85 ?? ?? ?? - ?? ?? 89 74 24 ?? 89 7C 24 ?? 74 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? - 89 D8 E8 ?? ?? ?? ?? EB ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? BA ?? ?? - ?? ?? 89 D8 E8 ?? ?? ?? ?? 85 C0 75 ?? 89 D8 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 44 - 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 52 52 0F 85 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 50 8D 65 ?? 5B 5E 5F 5D C3 55 BA ?? ?? ?? ?? 89 - E5 53 51 89 C3 E8 ?? ?? ?? ?? 48 74 ?? 5A 89 D8 5B 5D E9 ?? ?? ?? ?? 58 5B 5D C3 - } - $enum_resources = { - 55 89 E5 57 56 53 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 29 C4 8D 95 ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? 8B 04 04 C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? C7 44 24 ?? ?? ?? - ?? ?? C7 04 24 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? - 83 EC ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 31 F6 89 - 44 24 ?? 8D 85 ?? ?? ?? ?? 89 5C 24 ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? - ?? ?? ?? 83 EC ?? 3B B5 ?? ?? ?? ?? 7D ?? 83 7B ?? ?? 75 ?? 8B 43 ?? C7 44 24 ?? ?? - ?? ?? ?? 89 3C 24 89 44 24 ?? E8 ?? ?? ?? ?? 89 F8 E8 ?? ?? ?? ?? 89 D8 46 83 C3 ?? - E8 ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 50 8D 65 ?? 5B 5E 5F - 5D C3 + $search_and_encrypt_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 B8 ?? ?? ?? ?? 57 8B F9 89 7D ?? C7 45 ?? ?? ?? ?? + ?? 89 45 ?? 8D 50 ?? 68 ?? ?? ?? ?? 6A ?? FF 77 ?? 66 89 85 ?? ?? ?? ?? 8B 47 ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF D0 66 8B 95 ?? ?? ?? ?? 33 F6 33 + C9 89 45 ?? 66 3B F2 74 ?? 0F B7 D2 41 66 89 14 06 8D 34 09 33 DB 0F B7 94 35 ?? ?? + ?? ?? 66 3B DA 75 ?? BA ?? ?? ?? ?? 66 89 14 48 8D 1C 48 8D 8D ?? ?? ?? ?? 51 C7 43 + ?? ?? ?? ?? ?? 50 8B 47 ?? FF D0 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? + ?? 74 ?? 66 8B 8D ?? ?? ?? ?? 66 83 F9 ?? 74 ?? 66 83 BD ?? ?? ?? ?? ?? 74 ?? 33 D2 + 33 C0 66 3B D1 74 ?? 0F B7 C9 8B FF 40 66 89 4C 1A ?? 8D 14 00 C7 45 ?? ?? ?? ?? ?? + 0F B7 8C 15 ?? ?? ?? ?? 66 39 4D ?? 75 ?? 8B 55 ?? 33 C9 66 89 4C 43 ?? 68 ?? ?? ?? + ?? 8B CF E8 ?? ?? ?? ?? 83 C4 ?? 01 45 ?? 8D 85 ?? ?? ?? ?? 50 8B 47 ?? 56 FF D0 85 + C0 75 ?? 8B 47 ?? 56 FF D0 8D 85 ?? ?? ?? ?? 50 FF 75 ?? C7 43 ?? ?? ?? ?? ?? 8B 47 } - $encrypt_files = { - 55 89 E5 57 56 53 89 C3 81 EC ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 - C0 89 C2 A3 ?? ?? ?? ?? 75 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 31 - C0 89 D7 F3 AB 85 DB 75 ?? A1 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? - ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 89 5C 24 ?? 8D 9D ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 89 3C - 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C - 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 - 24 E8 ?? ?? ?? ?? 89 74 24 ?? 89 3C 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 EC - ?? 83 F8 ?? 89 C3 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 89 7C 24 ?? 89 34 24 EB ?? 8D - BD ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? C7 44 24 ?? ?? ?? - ?? ?? 89 1C 24 89 44 24 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 85 C0 75 ?? 89 - 1C 24 E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 - ?? ?? ?? ?? EB ?? F7 D8 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? - 89 1C 24 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 83 EC ?? BA ?? ?? ?? ?? C7 04 24 ?? ?? ?? - ?? B8 ?? ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 - 74 24 ?? 89 1C 24 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 83 EC ?? - FF 8D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 65 ?? 5B 5E 5F 5D C3 + $search_and_encrypt_2 = { + 33 F6 89 75 ?? FF D0 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? EB ?? 8D 9B ?? ?? ?? ?? + F6 85 ?? ?? ?? ?? ?? 75 ?? 66 8B BD ?? ?? ?? ?? 33 F6 8B 8E ?? ?? ?? ?? 8D 95 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 83 FF ?? 75 ?? + EB ?? 8D 9B ?? ?? ?? ?? 66 8B 48 ?? 83 C0 ?? 83 C2 ?? 66 3B 0A 74 ?? 66 83 38 ?? 0F + 85 ?? ?? ?? ?? 66 83 3A ?? 0F 85 ?? ?? ?? ?? 83 C6 ?? 81 FE ?? ?? ?? ?? 72 ?? 8B 7D + ?? 8B 75 ?? 8B 45 ?? 8D 8D ?? ?? ?? ?? 51 50 8B 47 ?? FF D0 85 C0 8B 45 ?? 0F 85 ?? + ?? ?? ?? 50 8B 47 ?? FF D0 85 F6 74 ?? 8B 55 ?? 33 C0 8B CF 66 89 43 ?? E8 ?? ?? ?? + ?? FF 75 ?? 8B 47 ?? 6A ?? FF 77 ?? FF D0 8B 45 ?? 8B 5D ?? 03 C6 03 D8 8B 45 ?? 40 + 89 5D ?? 89 45 ?? BA ?? ?? ?? ?? 83 F8 ?? 0F 8E ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 8B 47 ?? 68 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B CF E8 + ?? ?? ?? ?? 83 C4 ?? 03 C3 5F 5E 5B 8B E5 5D C3 33 C9 33 C0 66 3B CF 74 ?? 0F B7 CF + 33 D2 8D 9B ?? ?? ?? ?? 40 66 89 4C 1A ?? 8D 14 00 33 F6 0F B7 8C 15 ?? ?? ?? ?? 66 + 3B F1 75 ?? 8B 75 ?? FF 75 ?? 8B 7D ?? 33 C9 46 57 66 89 4C 43 ?? 89 75 ?? E8 ?? ?? + ?? ?? E9 } condition: - uint16(0)==0x5A4D and ($enum_resources) and ($find_files) and ($encrypt_files) + uint16(0)==0x5A4D and (( all of ($search_and_encrypt_*))) } -rule REVERSINGLABS_Win32_Ransomware_Paradise : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Sherminator : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Paradise ransomware." + description = "Yara rule that detects Sherminator ransomware." author = "ReversingLabs" - id = "9a92a05c-5f26-59ed-9934-a24bb7c31d8d" + id = "99792a22-8027-557f-927f-30eac4d1e690" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Paradise.yara#L1-L81" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "fc029bee999ec72416ac91d8386d4d270070035ad078bcab1dec11eea032c10b" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Sherminator.yara#L1-L157" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "22ac61b95f6ca4530e81a23fdd05be93e368647ca7100097a94eae3c6ce3b7d1" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -32838,82 +34411,145 @@ rule REVERSINGLABS_Win32_Ransomware_Paradise : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Paradise" + tc_detection_name = "Sherminator" tc_detection_factor = 5 importance = 25 strings: - $search_files = { - 53 56 57 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 59 89 75 ?? 85 F6 - 0F 84 ?? ?? ?? ?? FF 75 ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? 53 56 FF - D7 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 0F 84 ?? ?? - ?? ?? 83 65 ?? ?? 8B 45 ?? 8B 74 85 ?? 8D 95 ?? ?? ?? ?? 85 F6 74 ?? 0F B7 02 83 F8 - ?? 72 ?? 8D 48 ?? 83 F8 ?? 76 ?? 8B C8 0F B7 06 83 F8 ?? 72 ?? 83 F8 ?? 77 ?? 83 C0 - ?? 3B C8 0F B7 02 75 ?? 66 85 C0 74 ?? 83 C2 ?? 83 C6 ?? EB ?? 0F B7 02 EB ?? 66 3B - 06 1B C0 83 E0 ?? 40 EB ?? 33 C0 85 C0 0F 84 ?? ?? ?? ?? FF 45 ?? 83 7D ?? ?? 72 ?? - 8B 75 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? 68 ?? ?? ?? ?? 53 56 FF D7 83 C4 ?? F6 85 ?? - ?? ?? ?? ?? 74 ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? BA ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 80 3D ?? ?? ?? ?? ?? 74 ?? BA - ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? EB ?? F6 85 ?? ?? ?? - ?? ?? 74 ?? A1 ?? ?? ?? ?? 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 85 C0 75 ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? BA ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? - ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? 68 - ?? ?? ?? ?? 53 FF 75 ?? FF D7 83 C4 ?? FF 75 ?? E8 ?? ?? ?? ?? 59 FF 75 ?? FF 15 ?? - ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 59 5F 5E 5B C9 C3 + $enum_resources_p1 = { + 55 89 E5 57 53 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 + ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 89 45 ?? 83 7D ?? + ?? 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? C7 44 24 ?? + ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 + ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 89 54 + 24 ?? 8B 55 ?? 89 54 24 ?? 8D 55 ?? 89 54 24 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 89 + 45 ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 ?? 89 + } + $enum_resources_p2 = { + 45 ?? 8B 45 ?? C1 E0 ?? 89 C2 8B 45 ?? 01 D0 8B 40 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 + ?? C1 E0 ?? 89 C2 8B 45 ?? 01 D0 8B 40 ?? 89 04 24 E8 ?? ?? ?? ?? 83 C0 ?? 8B 15 ?? + ?? ?? ?? 8B 0D ?? ?? ?? ?? C1 E1 ?? 8D 1C 0A C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? + ?? ?? ?? 89 03 A1 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? C1 E2 ?? 01 D0 8B 00 85 C0 0F 84 ?? + ?? ?? ?? 8B 45 ?? C1 E0 ?? 89 C2 8B 45 ?? 01 D0 8B 50 ?? A1 ?? ?? ?? ?? 8B 0D ?? ?? + ?? ?? C1 E1 ?? 01 C8 8B 00 89 54 24 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 15 + ?? ?? ?? ?? C1 E2 ?? 01 D0 8B 10 89 D0 B9 ?? ?? ?? ?? 89 C3 B8 ?? ?? ?? ?? 89 DF F2 + AE 89 C8 F7 D0 83 E8 ?? 01 D0 66 C7 00 ?? ?? A1 ?? ?? ?? ?? 83 C0 ?? A3 ?? ?? ?? ?? + 8B 45 ?? C1 E0 ?? 89 C2 8B 45 ?? 01 D0 8B 40 ?? 83 E0 ?? 85 C0 74 ?? 8B 45 ?? C1 E0 + ?? 89 C2 8B 45 ?? 01 D0 89 04 24 E8 ?? ?? ?? ?? EB ?? 90 83 45 ?? ?? 8B 45 ?? 39 45 + ?? 0F 82 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? + ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 90 90 8D 65 ?? 5B 5F 5D C3 } $encrypt_files_p1 = { - 56 57 6A ?? BE ?? ?? ?? ?? 5F E8 ?? ?? ?? ?? 89 45 ?? 6A ?? 8D 45 ?? 50 56 E8 ?? ?? - ?? ?? 83 C4 ?? 83 C6 ?? 4F 75 ?? 33 F6 39 75 ?? 74 ?? 8D 45 ?? 50 A1 ?? ?? ?? ?? 0F - B7 88 ?? ?? ?? ?? 56 56 51 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 59 89 4D - ?? 33 C0 8A 90 ?? ?? ?? ?? 88 90 ?? ?? ?? ?? 3B C6 75 ?? 33 C0 40 3B C1 72 ?? 68 ?? - ?? ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 6A ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? - FF 15 ?? ?? ?? ?? 5F 5E C9 C3 56 FF 75 ?? FF 15 ?? ?? ?? ?? 56 FF 15 + 55 89 E5 57 83 EC ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 C0 ?? C7 44 24 ?? ?? ?? ?? + ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? + ?? A1 ?? ?? ?? ?? FF D0 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 + ?? B9 ?? ?? ?? ?? 89 C2 B8 ?? ?? ?? ?? 89 D7 F2 AE 89 C8 F7 D0 8D 50 ?? 8B 45 ?? 01 + D0 66 C7 00 ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? + 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 + 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 89 55 + ?? 83 7D ?? ?? 7F ?? 83 7D ?? ?? 78 ?? 83 7D ?? ?? 77 ?? C7 44 24 ?? ?? ?? ?? ?? 8B + 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 44 24 + ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? + 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 C7 45 ?? ?? ?? ?? ?? DF 6D ?? + DD 5D ?? DD 45 ?? DD 05 ?? ?? ?? ?? DF E9 DD D8 76 ?? 8B 45 ?? 89 45 ?? EB ?? C7 45 + ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 + 7D ?? ?? 75 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC } $encrypt_files_p2 = { - 53 56 57 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 33 DB - 53 53 8D 44 24 ?? 50 89 5C 24 ?? FF D6 85 C0 75 ?? 68 ?? ?? ?? ?? 6A ?? 53 53 8D 44 - 24 ?? 50 FF D6 85 C0 75 ?? 89 5C 24 ?? 39 5C 24 ?? 75 ?? 53 FF 15 ?? ?? ?? ?? A1 ?? - ?? ?? ?? 0F B6 80 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF - 74 24 ?? E8 ?? ?? ?? ?? 59 53 FF 74 24 ?? FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 53 53 - 53 53 C6 05 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 88 1D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 59 33 C0 88 98 ?? ?? ?? ?? 3B C3 75 ?? 33 C0 40 83 F8 ?? 72 ?? 6A ?? 5E - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 - ?? 6A ?? 53 53 8D 44 24 ?? 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 4E 75 ?? 8B 3D ?? - ?? ?? ?? 81 C7 ?? ?? ?? ?? 6A ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 85 C0 75 ?? 57 E8 - ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C3 + 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF + D0 C7 45 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 15 ?? + ?? ?? ?? A1 ?? ?? ?? ?? 8D 4D ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? C7 + 44 24 ?? ?? ?? ?? ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 75 ?? C7 04 24 ?? + ?? ?? ?? A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? + ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? + ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 C7 04 24 ?? ?? ?? ?? A1 + ?? ?? ?? ?? FF D0 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 + 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 75 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 + 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B + 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 + ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? + ?? ?? 89 45 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 + 7D ?? ?? 74 ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 + 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 44 24 ?? 8B 45 } - $http_remote_connection = { - 53 56 57 FF 75 ?? 33 FF 8D 75 ?? 89 7D ?? E8 ?? ?? ?? ?? 59 89 7D ?? 57 57 57 FF 75 - ?? 57 FF 15 ?? ?? ?? ?? 89 45 ?? 3B C7 0F 84 ?? ?? ?? ?? 57 57 6A ?? 57 57 FF 75 ?? - FF 75 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 3B C7 0F 84 ?? ?? ?? ?? 33 C9 80 7D ?? ?? 57 - 0F 95 C1 B8 ?? ?? ?? ?? 49 23 C8 03 C8 51 57 57 57 FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? - FF 15 ?? ?? ?? ?? 8B D8 3B DF 74 ?? 57 57 57 57 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 33 - F6 57 57 8D 45 ?? 50 53 89 7D ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 03 C6 3B C7 - 75 ?? 89 7D ?? EB ?? 50 39 7D ?? 75 ?? E8 ?? ?? ?? ?? 59 EB ?? FF 75 ?? 6A ?? FF 15 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 FF 75 ?? 8B 45 ?? 03 C6 50 53 - FF 15 ?? ?? ?? ?? 03 75 ?? 39 7D ?? 75 ?? 53 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? - ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 39 7D ?? 75 ?? 33 C0 40 39 45 ?? 74 ?? 89 45 ?? E9 - ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 5F 5E 5B - C9 C3 + $encrypt_files_p3 = { + 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC + ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 + 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? + A1 ?? ?? ?? ?? FF D0 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? 39 55 ?? 7F ?? 39 55 ?? 7C ?? 39 + 45 ?? 77 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? C7 44 24 + ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? + 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 89 54 24 ?? 8D 55 ?? 89 54 24 ?? 8B 55 ?? + 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 55 ?? 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 + 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 8B 55 ?? 89 54 24 ?? 89 44 24 ?? C7 44 + 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? 29 45 ?? + 19 55 ?? 83 7D ?? ?? 0F 8F ?? ?? ?? ?? 83 7D ?? ?? 78 ?? 83 7D ?? ?? 0F 87 ?? ?? ?? + ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 + 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? + ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 + } + $find_files_p1 = { + 55 89 E5 57 53 81 EC ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 C0 ?? C7 44 24 + ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? 89 04 24 + E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 44 + 24 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? B9 ?? ?? ?? ?? 89 C2 B8 ?? ?? ?? ?? + 89 D7 F2 AE 89 C8 F7 D0 8D 50 ?? 8B 45 ?? 01 D0 C7 00 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? 83 7D ?? ?? 0F + 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 85 C0 0F 84 ?? ?? ?? ?? 0F B6 95 ?? ?? ?? + ?? 0F B6 05 ?? ?? ?? ?? 0F B6 D2 0F B6 C0 29 C2 89 D0 85 C0 0F 84 ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? + ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? + 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 + E0 ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 C3 8D 85 ?? ?? ?? + ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 01 D8 83 C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 + } + $find_files_p2 = { + E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? + 89 04 24 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 E8 + ?? ?? ?? ?? 8B 45 ?? B9 ?? ?? ?? ?? 89 C2 B8 ?? ?? ?? ?? 89 D7 F2 AE 89 C8 F7 D0 8D + 50 ?? 8B 45 ?? 01 D0 66 C7 00 ?? ?? A1 ?? ?? ?? ?? 8B 55 ?? 89 54 24 ?? 89 44 24 ?? + C7 04 24 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 + 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? + ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 + } + $find_files_p3 = { + 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 + 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 89 04 + 24 E8 ?? ?? ?? ?? 89 C3 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 01 D8 83 + C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8B + 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 44 + 24 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 55 ?? 89 54 24 ?? 89 44 24 + ?? C7 04 24 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 EB ?? 90 EB ?? 90 EB ?? 90 EB ?? 90 EB + ?? 90 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? + 85 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 + 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 } condition: - uint16(0)==0x5A4D and $search_files and $http_remote_connection and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ( all of ($enum_resources_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Wormlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Zeoticus : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects WormLocker ransomware." + description = "Yara rule that detects Zeoticus ransomware." author = "ReversingLabs" - id = "6d7b55b7-2e1b-56e0-950f-07a2d3fa17ae" - date = "2021-08-12" - modified = "2021-08-12" + id = "483b20a4-2c16-5509-a503-2462a53d4d31" + date = "2021-03-19" + modified = "2021-03-19" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.WormLocker.yara#L1-L69" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "87a4f805de78d7e7dffb176302407453108ca01552c682aeee38f8d0201263c9" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Zeoticus.yara#L1-L90" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "adf42b96139ad98f4253f3eba2c4af1be9545825605e0851185cc15284d9e9a0" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -32921,61 +34557,82 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Wormlocker : TC_DETECTION MALICIOUS sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "WormLocker" + tc_detection_name = "Zeoticus" tc_detection_factor = 5 importance = 25 strings: - $set_environment = { - 73 ?? ?? ?? ?? 0A 06 02 7D ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 0B 72 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 0C 08 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 02 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 73 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? - ?? ?? ?? 72 ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 00 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 00 09 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 00 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 7B ?? ?? - ?? ?? 6F ?? ?? ?? ?? 00 06 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 20 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 00 13 ?? 11 ?? 06 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 - 11 ?? 17 6F ?? ?? ?? ?? 00 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 2A + $enum_shares_p1 = { + 53 55 8B 2D ?? ?? ?? ?? 8B C1 56 57 8B 3D ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 4C 24 ?? 51 8D 4C 24 ?? 51 + 8D 4C 24 ?? 51 6A ?? 8D 4C 24 ?? 51 6A ?? 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? 85 C0 74 + ?? 3D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 83 7C 24 ?? ?? 8B 5C 24 ?? 89 5C 24 ?? C7 44 24 + ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 33 F6 39 73 ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + 33 FF D5 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 33 FF D5 85 C0 0F 84 ?? ?? ?? ?? + 68 ?? ?? ?? ?? FF 33 FF D5 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 33 FF D5 85 C0 + 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 33 FF D5 85 C0 0F 84 ?? ?? ?? ?? FF 33 8D 44 24 + ?? FF 74 24 ?? 68 ?? ?? ?? ?? 50 FF D7 A1 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 83 C4 ?? 89 04 8D ?? ?? ?? ?? 8D 4C 24 ?? 51 } - $find_files = { - 00 28 ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 0C 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 28 ?? ?? ?? - ?? 0D 08 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 13 ?? 73 ?? ?? - ?? ?? 13 ?? 72 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 00 11 ?? 09 11 ?? 9A 11 ?? 6F ?? ?? ?? - ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 09 8E 69 FE 04 13 ?? 11 ?? 2D ?? 16 13 ?? 2B ?? 00 11 - ?? 11 ?? 11 ?? 9A 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 FE 04 - 13 ?? 11 ?? 2D ?? 2A + $enum_shares_p2 = { + 50 FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8D 04 85 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 56 FF 34 + 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 56 FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 04 8D ?? + ?? ?? ?? 41 FF 05 ?? ?? ?? ?? 89 0D ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 FF 85 C0 7E ?? 8D + 5F ?? 8D 44 24 ?? 50 FF 34 BD ?? ?? ?? ?? FF D5 85 C0 0F 44 F3 47 3B 3D ?? ?? ?? ?? + 7C ?? 8B 5C 24 ?? 85 F6 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 0D ?? ?? + ?? ?? 8B 3D ?? ?? ?? ?? 89 04 8D ?? ?? ?? ?? 8D 4C 24 ?? 51 68 ?? ?? ?? ?? 50 FF D7 + A1 ?? ?? ?? ?? 83 C4 ?? 8D 04 85 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 6A ?? FF 34 85 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 04 8D ?? ?? + ?? ?? 41 FF 05 ?? ?? ?? ?? 89 0D ?? ?? ?? ?? EB ?? 8B 3D ?? ?? ?? ?? 8B 74 24 ?? 83 + C3 ?? 46 89 5C 24 ?? 89 74 24 ?? 3B 74 24 ?? 0F 82 ?? ?? ?? ?? 8B 5C 24 ?? 53 FF 15 + ?? ?? ?? ?? 81 7C 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 0F 84 ?? ?? ?? ?? 5F 5E 5D 5B 81 C4 + ?? ?? ?? ?? C3 } - $encrypt_files_p1 = { - 00 14 0A 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? 0C 00 73 - ?? ?? ?? ?? 0D 00 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 00 03 07 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? - ?? ?? 6F ?? ?? ?? ?? 00 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? - 00 09 17 6F ?? ?? ?? ?? 00 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 00 11 ?? 02 16 - 02 8E 69 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? - ?? ?? 00 DC 08 6F ?? ?? ?? ?? 0A 00 DE ?? 09 2C ?? 09 6F ?? ?? ?? ?? 00 DC 00 DE ?? 08 - 2C ?? 08 6F ?? ?? ?? ?? 00 DC 06 13 ?? 2B ?? 11 ?? 2A + $encrypt_files = { + 68 ?? ?? ?? ?? 6A ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? A3 ?? ?? + ?? ?? FF D0 68 ?? ?? ?? ?? 6A ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B F0 E8 ?? ?? ?? ?? + 83 C4 ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF D7 83 + C4 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D + 04 45 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 68 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? + FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 83 FB ?? 75 ?? E8 ?? ?? ?? ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? EB ?? 83 FB ?? 75 ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? + 56 6A ?? FF 35 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D6 E8 ?? + ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? FF B4 24 ?? ?? ?? ?? 51 E8 ?? ?? ?? + ?? 83 C4 ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 } - $encrypt_files_p2 = { - 00 03 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? 0B 28 ?? ?? ?? ?? 07 6F ?? ?? - ?? ?? 0B 06 07 28 ?? ?? ?? ?? 0C 03 0D 09 08 28 ?? ?? ?? ?? 00 2A + $find_files = { + 81 EC ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 68 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? 8D 51 ?? 66 8B 01 + 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 66 83 7C 24 ?? ?? 56 8D 71 ?? 0F 85 ?? ?? ?? ?? + 55 8B 2D ?? ?? ?? ?? 57 8B 3D ?? ?? ?? ?? 66 90 66 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? + 66 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? 66 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? 66 83 7C 74 + ?? ?? 0F 85 ?? ?? ?? ?? 33 C0 66 89 44 74 ?? 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 + 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? 66 89 4C 74 ?? 85 C0 74 ?? 33 F6 90 + FF 34 B5 ?? ?? ?? ?? FF D7 83 F8 ?? 74 ?? 46 83 FE ?? 72 ?? 8D 44 24 ?? 50 FF 34 B5 + ?? ?? ?? ?? FF D5 68 ?? ?? ?? ?? 8D 44 24 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D + 4C 24 ?? 8D 51 ?? 66 90 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 66 83 7C 24 ?? + ?? 8D 71 ?? 0F 84 ?? ?? ?? ?? 5F 5D 53 FF 15 ?? ?? ?? ?? 5E 5B 81 C4 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and ($set_environment) and ($find_files) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ( all of ($enum_shares_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Reveton : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win64_Ransomware_Cactus : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Reveton ransomware." + description = "Yara rule that detects Cactus ransomware." author = "ReversingLabs" - id = "14446b94-cd57-5930-b0af-b21091b61f68" - date = "2020-07-15" - modified = "2020-07-15" + id = "f391919a-b433-5f8d-8051-f0467118fa1b" + date = "2023-12-15" + modified = "2023-12-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Reveton.yara#L1-L118" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "2d316c558cdb5591788ef89c6e20327882a118f2928f4a31fb5b8b3083931ac5" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Cactus.yara#L1-L190" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "2953b67e926cb653df0de208b098da3d5c16e6690842ab28fbf8c37cd16f54d7" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -32983,111 +34640,174 @@ rule REVERSINGLABS_Win32_Ransomware_Reveton : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Reveton" + tc_detection_name = "Cactus" tc_detection_factor = 5 importance = 25 strings: - $http_connection_1 = { - C6 45 ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? - ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 8B C3 E8 ?? ?? ?? ?? 50 8B 45 - ?? 50 E8 ?? ?? ?? ?? 8B D8 85 DB 74 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 C0 - 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8B 06 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? 50 68 - ?? ?? ?? ?? 8B 45 ?? 50 53 E8 ?? ?? ?? ?? 8B 55 ?? 8B 06 8B 4D ?? E8 ?? ?? ?? ?? 83 - 7D ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 - ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8B 45 ?? 50 E8 - } - $raw_socket_connection_1_1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 4D - ?? 89 55 ?? 8B F0 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 DB 8D 45 ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 8B F8 85 FF 0F 8E ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B CF E8 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 - } - $raw_socket_connection_1_2 = { - C6 85 ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 80 BD ?? ?? ?? - ?? ?? 74 ?? 33 C0 EB ?? B0 ?? 84 C0 75 ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? - ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? E9 - ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? FE C8 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 66 C7 85 ?? ?? ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? FE C8 74 ?? 2C ?? 74 - ?? E9 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? - ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8A 95 - ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? E8 + $encrypt_files_p1 = { + 55 41 57 41 56 41 55 41 54 56 53 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 29 C4 48 8D AC 24 + ?? ?? ?? ?? 48 89 8D ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 4C 89 85 ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C1 E8 ?? + ?? ?? ?? 48 98 48 89 C1 E8 ?? ?? ?? ?? 48 89 45 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 + 89 85 ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C1 4C 8D 4D + ?? 4C 8D 45 ?? 48 8B 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 + 89 54 24 ?? 48 8B 95 ?? ?? ?? ?? 48 89 54 24 ?? 48 89 CA 48 89 C1 E8 ?? ?? ?? ?? 48 + 8D 45 ?? 48 8B 95 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 + ?? 48 8B 95 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 + 89 C1 E8 ?? ?? ?? ?? 48 89 C3 48 8B 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DA + 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA + ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 C2 + 48 8D 85 ?? ?? ?? ?? 41 89 D8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 41 B8 ?? + ?? ?? ?? BA ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 8B 45 ?? 4C 63 C0 48 8B 45 ?? 48 8D } - $raw_socket_connection_1_3 = { - 66 89 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 0F B6 BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 - ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CF - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 - C0 75 ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 40 ?? 8B 00 8B 00 - 89 85 ?? ?? ?? ?? 8A 94 3D ?? ?? ?? ?? 8A 84 3D ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 89 85 - ?? ?? ?? ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 - ?? ?? ?? ?? E8 + $encrypt_files_p2 = { + 95 ?? ?? ?? ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 4C 8B 85 ?? ?? ?? ?? 48 8B 85 ?? + ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? + ?? 48 83 C0 ?? BA ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 8D 95 + ?? ?? ?? ?? 48 8D 4A ?? 41 B8 ?? ?? ?? ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? + ?? 41 B8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 29 + C2 48 89 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 48 98 48 39 85 ?? ?? ?? ?? 0F 8D ?? ?? ?? + ?? 48 89 E0 48 89 C6 48 8B 85 ?? ?? ?? ?? 48 8D 50 ?? 48 85 C0 48 0F 48 C2 48 C1 F8 + ?? 48 C1 E0 ?? 48 89 85 ?? ?? ?? ?? 48 8B 9D ?? ?? ?? ?? 48 8D 43 ?? 48 89 85 ?? ?? + ?? ?? 48 89 D8 49 89 C4 41 BD ?? ?? ?? ?? 48 89 D8 49 89 C6 41 BF ?? ?? ?? ?? 48 89 + D8 48 83 C0 ?? 48 C1 E8 ?? 48 C1 E0 ?? E8 ?? ?? ?? ?? 48 29 C4 48 8D 44 24 ?? 48 83 + C0 ?? 48 89 85 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 8D 85 ?? ?? + ?? ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 41 89 D9 4C 8B 85 ?? ?? ?? ?? 48 89 E9 48 8D + 55 ?? 48 8B 85 ?? ?? ?? ?? 44 89 4C 24 ?? 4D 89 C1 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? + 48 8B 85 ?? ?? ?? ?? F7 D8 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 48 63 D0 48 8D 85 ?? + ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 8B 45 ?? 4C 63 C0 48 8D 45 ?? 48 + 8D 95 ?? ?? ?? ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 2B 85 + ?? ?? ?? ?? 48 89 C2 48 8D 85 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 } - $raw_socket_connection_1_4 = { - 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 8B - 00 50 E8 ?? ?? ?? ?? 40 75 ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? - ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? 8B 45 ?? 8B 00 - 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 8B 00 50 E8 + $encrypt_files_p3 = { + 48 89 DA 48 8B 85 ?? ?? ?? ?? 48 01 D0 48 89 85 ?? ?? ?? ?? 90 48 89 F4 E9 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 48 63 C8 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 49 89 C8 48 + 89 C1 E8 ?? ?? ?? ?? 4C 8D 85 ?? ?? ?? ?? 48 89 E9 48 8D 55 ?? 48 8B 85 ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? 4D 89 C1 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + F7 D8 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 48 63 D0 48 8D 85 ?? ?? ?? ?? 41 B8 ?? ?? + ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 8B 45 ?? 4C 63 C0 48 8D 45 ?? 48 8D 95 ?? ?? ?? ?? 48 + 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 05 ?? ?? ?? ?? 48 89 85 ?? + ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 05 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 83 F0 ?? 84 + C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 48 98 48 8D 55 ?? 48 01 C2 48 89 E9 48 8B 85 ?? ?? ?? + ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 8B 45 ?? 4C 63 C0 48 8D 45 ?? 48 8D 95 ?? ?? ?? + ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 8B 45 ?? 4C 63 C0 48 8B 45 ?? 48 8D 95 ?? ?? + ?? ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 4C 8B 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? + 48 8D 95 ?? ?? ?? ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 83 + C0 ?? BA ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? + ?? 48 8D 4A ?? 41 B8 ?? ?? ?? ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 + } + $encrypt_files_p4 = { + C1 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 + E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 41 B8 + ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 89 + C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 84 DB 74 ?? 48 8D 45 ?? 48 89 C1 E8 + ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? + 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DA 48 89 C1 48 8B 05 ?? ?? ?? ?? + FF D0 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D + 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 F4 48 89 C3 EB ?? 48 89 C3 48 8D + 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? + ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? + ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 90 48 8D A5 ?? ?? + ?? ?? 5B 5E 41 5C 41 5D 41 5E 41 5F 5D C3 } - $raw_socket_connection_1_5 = { - C6 85 ?? ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? - ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 66 - 8B 85 ?? ?? ?? ?? 8B D0 66 81 E2 ?? ?? 88 95 ?? ?? ?? ?? 0F B7 C0 C1 E8 ?? 88 85 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? - ?? ?? 40 74 ?? B3 ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? - ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 - 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? - ?? ?? ?? C3 + $find_files_p1 = { + 55 56 53 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 29 C4 48 8D AC 24 ?? ?? ?? ?? 48 89 8D ?? + ?? ?? ?? 48 8D 45 ?? BB ?? ?? ?? ?? 48 89 C6 EB ?? 48 89 F1 E8 ?? ?? ?? ?? 48 83 EB + ?? 48 83 C6 ?? 48 85 DB 79 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 85 C0 + 0F 95 C0 84 C0 74 ?? 48 8B 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? + ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? + ?? ?? ?? E9 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? + 84 C0 74 ?? 48 8D 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 + ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? + ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? + ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + E9 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 84 C0 74 ?? 48 8D 45 ?? 8B 95 ?? ?? ?? ?? 48 63 + D2 48 C1 E2 ?? 48 01 C2 48 8D 85 ?? ?? ?? ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 + E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 } - $file_search_1_1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 89 55 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 89 C3 85 DB 74 - ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 FF D3 85 C0 74 ?? 8B 45 ?? 50 8D - 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 ?? 80 38 ?? 75 ?? - 8B 45 ?? 80 78 ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? E8 + $find_files_p2 = { + 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 8B 95 ?? ?? ?? ?? 48 63 D2 48 C1 E2 ?? 48 01 C2 48 + 8D 85 ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D + 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? + 83 85 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B 85 ?? ?? ?? ?? 0F 8C ?? ?? ?? ?? C6 05 ?? + ?? ?? ?? ?? 48 8D 5D ?? 48 81 C3 ?? ?? ?? ?? 48 8D 45 ?? 48 39 C3 74 ?? 48 83 EB ?? + 48 89 D9 E8 ?? ?? ?? ?? EB ?? 90 E9 ?? ?? ?? ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 + C1 E8 ?? ?? ?? ?? 48 89 DE EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? + ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DE EB ?? 48 89 + C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DE EB ?? 48 89 C3 48 8D 85 ?? + ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DE EB ?? 48 89 C6 48 8D 5D ?? 48 81 C3 ?? ?? + ?? ?? 48 8D 45 ?? 48 39 C3 74 ?? 48 83 EB ?? 48 89 D9 E8 ?? ?? ?? ?? EB ?? 90 48 89 + F0 48 89 C1 E8 ?? ?? ?? ?? 90 48 81 C4 ?? ?? ?? ?? 5B 5E 5D C3 } - $file_search_1_2 = { - 8B F0 80 3E ?? 0F 84 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F0 80 3E ?? 0F 84 ?? ?? - ?? ?? EB ?? 8B 75 ?? 83 C6 ?? 8B DE 2B 5D ?? 8D 43 ?? 50 8B 45 ?? 50 8D 85 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F8 8B C7 2B C6 8B D0 - 03 D3 42 81 FA ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 40 50 56 8D 85 ?? ?? ?? ?? 03 C3 50 E8 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 + $check_processes = { + 55 53 48 83 EC ?? 48 8D 6C 24 ?? 48 89 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? EB ?? 8B 45 ?? 48 98 48 8D 14 C5 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 8B 1C 02 48 + 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DA 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 48 85 + C0 0F 95 C0 84 C0 74 ?? B8 ?? ?? ?? ?? EB ?? 83 45 ?? ?? 8B 45 ?? 3B 45 ?? 7C ?? B8 + ?? ?? ?? ?? 48 83 C4 ?? 5B 5D C3 } - $file_search_1_3 = { - 8B F0 83 FE ?? 74 ?? 56 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 53 ?? - 03 C2 40 3D ?? ?? ?? ?? 7F ?? C6 84 1D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B C3 48 50 8D - 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 03 C3 40 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 40 03 D8 8B F7 80 3E ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 8D 85 ?? ?? ?? - ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 5F 5E 5B 8B E5 5D C3 + $kill_file_processes_p1 = { + 55 56 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 8D ?? ?? ?? ?? C6 85 ?? + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF C0 + 0F 11 45 ?? F3 0F 6F 4D ?? 0F 11 8D ?? ?? ?? ?? F3 0F 6F 55 ?? 0F 11 95 ?? ?? ?? ?? + F3 0F 6F 5D ?? 0F 11 9D ?? ?? ?? ?? F3 0F 6F 65 ?? 0F 11 A5 ?? ?? ?? ?? 0F B7 45 ?? + 66 89 85 ?? ?? 00 00 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 49 89 D0 BA ?? ?? ?? + ?? 48 89 C1 E8 ?? ?? ?? ?? 85 C0 0F 94 C0 84 C0 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 48 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 41 B9 + ?? ?? ?? ?? 4C 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 85 C0 0F 94 C0 + 84 C0 0F 84 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 4C + 8D 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 89 4C 24 ?? 41 B9 ?? + ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? + 8B 85 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? BB ?? ?? ?? ?? + E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 C0 48 69 F0 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? FF + D0 49 89 F0 BA ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 48 89 85 ?? ?? ?? ?? + 48 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? BB ?? ?? ?? ?? + E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 4C 8B 8D ?? ?? + ?? ?? 4C 8D 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 89 4C 24 } - $raw_socket_connection_2 = { - 55 8B EC 83 C4 ?? 53 56 8B F2 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? - ?? 64 FF 30 64 89 20 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 83 FB ?? 74 ?? 8D 45 ?? - 33 C9 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 8B C6 86 E0 66 89 45 ?? 8B 45 - ?? E8 ?? ?? ?? ?? 89 45 ?? 6A ?? 8D 45 ?? 50 53 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B C3 E8 - ?? ?? ?? ?? 83 CB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? - C3 + $kill_file_processes_p2 = { + 89 C1 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 85 ?? ?? ?? ?? + 85 C0 75 ?? 48 8B 05 ?? ?? ?? ?? FF D0 48 8B 95 ?? ?? ?? ?? 49 89 D0 BA ?? ?? ?? ?? + 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 8B 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? BB ?? ?? + ?? ?? E9 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? FF D0 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 + 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 48 + 98 48 69 D0 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 01 D0 8B 00 39 85 ?? ?? ?? ?? 75 ?? + 48 8B 05 ?? ?? ?? ?? FF D0 48 8B 95 ?? ?? ?? ?? 49 89 D0 BA ?? ?? ?? ?? 48 89 C1 48 + 8B 05 ?? ?? ?? ?? FF D0 8B 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? BB ?? ?? ?? ?? E9 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 48 98 48 69 D0 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 01 D0 + 8B 00 41 89 C0 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? FF D0 48 89 85 ?? + ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8D 55 ?? 48 8B 85 ?? ?? ?? ?? + 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? + ?? ?? ?? FF D0 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 + 8D 55 ?? 48 8D 45 ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 + E8 ?? ?? ?? ?? 48 8D 45 ?? 49 C7 C0 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? + ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C0 ?? 48 63 C8 48 8D 45 ?? 48 8D 55 + ?? 49 C7 C1 ?? ?? ?? ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8D 85 ?? ?? + ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 } condition: - uint16(0)==0x5A4D and (($http_connection_1 and $file_search_1_1 and $file_search_1_2 and $file_search_1_3 and $raw_socket_connection_1_1 and $raw_socket_connection_1_2 and $raw_socket_connection_1_3 and $raw_socket_connection_1_4 and $raw_socket_connection_1_5) or ($raw_socket_connection_2 and $file_search_1_1 and $file_search_1_2 and $file_search_1_3)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($check_processes) and ( all of ($kill_file_processes_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Sarbloh : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Meow : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Sarbloh ransomware." + description = "Yara rule that detects Meow ransomware." author = "ReversingLabs" - id = "532abd77-f091-5c54-87a3-7e8be5253efd" - date = "2021-05-21" - modified = "2021-05-21" + id = "7cebb04d-1cda-5ad1-b412-8b38df7b2550" + date = "2022-10-24" + modified = "2022-10-24" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Sarbloh.yara#L1-L88" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "7259aa9d1fe657db220ee50f1610e6439ff61673d92f46ebc3b8cadd990f002c" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Meow.yara#L1-L84" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "b00753d2b150a815279297ddf40d70051d25de1c32bb90f5b706ea7fd36bb871" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -33095,153 +34815,76 @@ rule REVERSINGLABS_Win32_Ransomware_Sarbloh : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Sarbloh" + tc_detection_name = "Meow" tc_detection_factor = 5 importance = 25 strings: $encrypt_files_p1 = { - 8B 45 ?? C6 00 ?? 8B 45 ?? 40 89 45 ?? 39 75 ?? 72 ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? - ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 52 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 75 - ?? 81 FE ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 8B D8 89 5D ?? 85 DB 0F 84 ?? ?? ?? ?? C1 E6 ?? 56 6A ?? 89 75 ?? FF 15 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 7D ?? 8D 85 ?? ?? ?? ?? - 6A ?? 6A ?? 50 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 8B - 8D ?? ?? ?? ?? 8B C1 8B 55 ?? 0B C2 89 4D ?? 89 55 ?? 0F 84 ?? ?? ?? ?? 0F 57 C0 66 - 0F 13 45 ?? 85 D2 0F 8C ?? ?? ?? ?? 7F ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? - 8B 45 ?? 89 45 ?? EB ?? 8B 75 ?? 8B 7D ?? 6A ?? 6A ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? - 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 8B 45 ?? 8B 4D ?? 89 4D ?? 89 45 ?? - 85 C0 0F 8C ?? ?? ?? ?? 7F ?? 85 C9 0F 82 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 8D 85 - ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 6A ?? 6A ?? 56 8B 75 ?? - 8D 45 ?? 56 50 6A ?? 6A ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 85 C0 0F - 85 ?? ?? ?? ?? 8B 75 ?? EB ?? 33 F6 8B 45 ?? 8B 4D ?? 89 75 ?? 89 4D ?? 89 45 ?? 85 - C0 0F 8C ?? ?? ?? ?? 7F ?? 85 C9 0F 82 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 8D 85 ?? - ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 33 FF 85 C0 0F 88 ?? ?? ?? ?? 85 F6 0F 84 + 72 ?? 8D 45 ?? BA ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 68 ?? ?? ?? ?? 57 FF D0 85 C0 75 ?? 33 F6 6A ?? 68 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? FF B4 B5 ?? ?? ?? ?? 57 FF D0 85 C0 75 ?? 46 83 FE ?? 7C + ?? 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 5F 5E 33 C0 5B 8B E5 5D C3 CC 55 8B EC 83 EC + ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 57 C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? + ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? + ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? + ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8A 45 ?? 80 7D ?? ?? + 75 } $encrypt_files_p2 = { - 8B 75 ?? 8D 45 ?? 56 50 53 52 6A ?? 52 FF 75 ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 56 53 8D 45 ?? 50 6A ?? 6A ?? 6A ?? FF 75 ?? - FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 8B 4D ?? - 81 C7 ?? ?? ?? ?? 3B 7D ?? 72 ?? 8B 75 ?? 03 75 ?? 8B 45 ?? 83 D0 ?? 89 75 ?? 89 45 - ?? 3B 45 ?? 0F 8C ?? ?? ?? ?? 7F ?? 3B B5 ?? ?? ?? ?? 8B 75 ?? 0F 82 ?? ?? ?? ?? 8D - 45 ?? 50 6A ?? 6A ?? 6A ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? F7 D8 6A ?? 1B DB 8D 45 - ?? 23 5D ?? 50 6A ?? 6A ?? 6A ?? 6A ?? FF 75 ?? 89 5D ?? 89 5D ?? FF 15 ?? ?? ?? ?? - F7 D8 1B F6 23 75 ?? 56 6A ?? 89 75 ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 - 85 FF 0F 84 ?? ?? ?? ?? 8D 45 ?? 89 5D ?? 50 57 6A ?? 6A ?? 6A ?? FF 75 ?? FF 15 ?? - ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 56 8D 45 ?? 89 5D ?? 50 57 6A ?? 6A ?? 6A ?? FF 75 - ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 56 57 8D 45 ?? 50 6A ?? 6A - ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 85 C0 78 ?? 39 75 ?? 75 ?? - 8B 85 ?? ?? ?? ?? 6A ?? 6A ?? 89 85 ?? ?? ?? ?? 8B 45 ?? 6A ?? 89 85 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 8D 45 ?? 89 9D ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? FF 75 ?? 89 B5 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 85 C0 78 ?? 33 C0 B9 ?? ?? ?? ?? 83 - 7D ?? ?? 0F 44 C1 89 45 ?? 89 7D ?? 83 7D ?? ?? 74 ?? 8B 4D ?? 03 4D ?? 39 4D ?? 73 - ?? 90 8B 45 ?? C6 00 ?? 8B 45 ?? 40 89 45 ?? 39 4D ?? 72 ?? 57 6A ?? FF 15 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 8B 5D ?? 8B 7D ?? 8B 75 ?? EB - } - $find_files_p1 = { - 55 8B EC 83 EC ?? 53 56 8B 75 ?? 57 8B F9 83 3E ?? 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 8D - 45 ?? 50 52 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 89 45 ?? 8D - 45 ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 57 C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 0F 89 4D ?? 85 C0 78 ?? - 83 F9 ?? 74 ?? FF 75 ?? BB ?? ?? ?? ?? C7 06 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 50 - FF 15 ?? ?? ?? ?? 8B 55 ?? EB ?? FF 75 ?? C7 06 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 8B 17 33 DB 89 55 ?? C7 45 - ?? ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 4D ?? 81 C1 ?? ?? ?? ?? 39 4D ?? 73 + 8B 45 ?? 40 89 45 ?? 8B 45 ?? 99 F7 F9 85 D2 74 ?? E9 ?? ?? ?? ?? 8B 45 ?? 25 ?? ?? + ?? ?? 79 ?? 48 83 C8 ?? 83 C0 ?? 74 ?? 8B 4D ?? 8D 46 ?? 03 CF 0F AF C8 89 4D ?? 8B + 45 ?? 25 ?? ?? ?? ?? 79 ?? 48 83 C8 ?? 83 C0 ?? 75 ?? B9 ?? ?? ?? ?? 90 8B 45 ?? 99 + F7 F9 8B 45 ?? 85 D2 74 ?? 48 EB ?? 40 89 45 ?? 8B 45 ?? 25 ?? ?? ?? ?? 79 ?? 48 83 + C8 ?? 83 C0 ?? 74 ?? EB ?? 8B 45 ?? B9 ?? ?? ?? ?? 99 F7 F9 85 D2 74 ?? 8B 45 ?? 8D + 4E ?? 83 C0 ?? 99 F7 F9 B9 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 99 F7 F9 85 D2 75 ?? 8B 45 + ?? 99 F7 7D ?? 8B 45 ?? 85 D2 74 ?? 40 EB ?? 48 89 45 ?? 8B 45 ?? 99 F7 F9 85 D2 74 + ?? 6A ?? 68 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 FF + D0 C7 45 ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 45 ?? 99 F7 F9 8B 45 ?? 85 D2 74 ?? 83 C0 + ?? 03 C3 89 45 ?? 8B 45 ?? 25 ?? ?? ?? ?? 79 ?? 48 83 C8 ?? 83 C0 ?? 0F 85 } - $find_files_p2 = { - 8B 45 ?? C6 00 ?? 8B 45 ?? 40 89 45 ?? 39 4D ?? 72 ?? 53 6A ?? 6A ?? 6A ?? 68 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? 6A ?? 52 FF 15 ?? ?? ?? ?? 8B F8 33 DB - 89 5D ?? 81 FF ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 55 ?? 85 FF 78 ?? 8B 4D ?? 8B 35 ?? - ?? ?? ?? 2B CB 0F 84 ?? ?? ?? ?? 83 E9 ?? 0F 85 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B C1 - C1 E8 ?? F7 D0 A8 ?? 74 ?? F7 C1 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 FE ?? 74 ?? 83 FE - ?? 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 33 C0 + $drop_ransom_note = { + 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 51 53 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 + FF 74 ?? 8B CF E8 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 85 F6 74 ?? 6A + ?? 68 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF D0 6A ?? + 68 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A + ?? 6A ?? 68 ?? ?? ?? ?? 56 FF D0 8B F0 BA ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 89 35 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 56 FF D0 B9 ?? ?? ?? ?? 8D BD ?? + ?? ?? ?? BE ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? F3 A5 68 ?? ?? ?? ?? 6A ?? 50 66 A5 A4 E8 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 33 CD B8 ?? + ?? ?? ?? 5F 5B 5E E8 ?? ?? ?? ?? 8B E5 5D C3 } - - condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) -} -rule REVERSINGLABS_Win32_Ransomware_Wasplocker : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects WaspLocker ransomware." - author = "ReversingLabs" - id = "596bf965-700a-58f5-b0e5-61ec57c23a3e" - date = "2022-06-28" - modified = "2022-06-28" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.WaspLocker.yara#L1-L76" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "852ec52328fca36d651e3176ac33a57ce26cefecadc2aad27235548e5b9813c1" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "WaspLocker" - tc_detection_factor = 5 - importance = 25 - - strings: $find_files = { - 50 50 8D 8D ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? 51 50 50 50 56 FF 15 ?? ?? ?? ?? 85 C0 - 75 ?? 57 53 E8 ?? ?? ?? ?? 8D 4E ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - A8 ?? 75 ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? A8 ?? 0F 85 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 85 C0 74 ?? 3B 85 ?? ?? ?? ?? 76 ?? 8D 85 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 2B 95 ?? ?? ?? ?? 59 03 C2 B9 ?? ?? ?? ?? 3B C1 - 7D ?? 8D 85 ?? ?? ?? ?? 2B CA 50 51 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 - 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 75 ?? EB ?? 85 DB 0F 84 - ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? 85 FF 75 ?? 33 C0 EB ?? 57 E8 ?? ?? ?? ?? 59 50 57 - 8D 4B ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 4E ?? E8 ?? ?? ?? ?? 33 C0 40 E8 ?? ?? ?? - ?? C2 ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? CC 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 - F6 89 75 ?? 33 FF 89 7D ?? 21 75 ?? 21 75 ?? 39 3D ?? ?? ?? ?? 75 ?? 8D 45 ?? 50 E8 - ?? ?? ?? ?? 8B F8 89 7D ?? 85 FF 74 ?? FF 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B F0 89 75 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? C2 - } - $drop_aux_files = { - A1 ?? ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 68 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 6A ?? 66 89 41 ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 56 6A ?? FF 15 ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? 85 C0 74 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 50 FF 15 - ?? ?? ?? ?? 8B F8 85 FF 74 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B - F0 83 C4 ?? 85 F6 74 ?? 56 FF B5 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? 6A ?? 6A ?? 56 - E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 - ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? - ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? - ?? ?? 56 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 6A ?? 56 FF 15 ?? ?? - ?? ?? 50 89 85 ?? ?? ?? ?? E8 - } - $drop_ransom_notes = { - 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 84 C0 - 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E8 - ?? ?? ?? ?? 8B C8 85 C9 0F 84 ?? ?? ?? ?? 8B 01 8B 40 ?? FF D0 83 C0 ?? 89 85 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 8B C8 85 C9 0F 84 ?? ?? ?? ?? 8B 01 8B 40 ?? FF D0 83 C0 ?? 89 85 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 84 C0 75 ?? B9 ?? ?? ?? ?? 8D - 51 ?? 90 8A 01 41 84 C0 75 ?? 2B CA 51 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B C8 85 C9 0F 84 ?? ?? ?? ?? 8B 01 8B 40 ?? FF D0 83 - C0 ?? 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 84 C0 75 + 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF + B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 + 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 ?? 8A 48 ?? 84 C9 74 ?? 80 F9 + ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 + C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? + ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? 74 ?? + FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 8B D8 56 FF 15 } condition: - uint16(0)==0x5A4D and ($find_files) and ($drop_aux_files) and ($drop_ransom_notes) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($drop_ransom_note) } -rule REVERSINGLABS_Linux_Ransomware_Kraken : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_HDMR : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Kraken ransomware." + description = "Yara rule that detects HDMR ransomware." author = "ReversingLabs" - id = "7c302c2e-6ffc-5f51-90f4-c4ebd6c1c28b" + id = "97b5020c-6cb1-5ec6-84a4-2f35eae761c2" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Kraken.yara#L1-L151" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "4a3867aba4dbdce5d008331a3058f57b00db246975fc4d77b79ab49d5f0bbb15" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.HDMR.yara#L1-L161" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "035c6596db8dc14a663679c1f7e682b85963927cc034b01e390cc22fdee3334a" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -33249,138 +34892,149 @@ rule REVERSINGLABS_Linux_Ransomware_Kraken : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Kraken" + tc_detection_name = "HDMR" tc_detection_factor = 5 importance = 25 strings: - $enum_volumes = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? 04 ?? 00 A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? 50 45 4C 00 C7 45 - FC 00 00 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? - ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 0F 1F 84 00 ?? ?? ?? ?? - 8A 06 84 C0 0F 84 ?? ?? ?? ?? 3C ?? 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B D6 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 EC ?? 8B D4 - C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? 83 7A ?? ?? 72 ?? 8B 02 EB ?? 8B C2 C6 00 - ?? 80 3E ?? 75 ?? 33 C9 EB ?? 8B CE 8D 79 ?? 8A 01 41 84 C0 75 ?? 2B CF 51 56 8B CA - E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B D6 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 C6 ?? E9 ?? ?? ?? ?? BA ?? - ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 83 EC ?? 8B CC C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 83 79 ?? - ?? 72 ?? 8B 01 EB ?? 8B C1 6A ?? 68 ?? ?? ?? ?? C6 00 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 - ?? ?? ?? ?? 8B E5 5D C3 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? B8 ?? ?? ?? ?? C3 + $find_files_p1 = { + 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? + ?? ?? 53 56 8B 75 ?? 57 33 C0 68 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? 51 89 74 24 ?? + 66 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 56 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 52 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 8D 8C 24 ?? ?? ?? ?? 51 FF 15 ?? ?? + ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? EB + ?? 8D 49 ?? 8B 74 24 ?? F6 44 24 ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 44 24 ?? + 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 + ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? + 8D 44 24 ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 + C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D } - $enum_shares_p1 = { - 50 56 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 32 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F - 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 66 0F 1F 44 00 ?? FF 75 ?? 6A ?? FF - 15 ?? ?? ?? ?? 8B F0 8D 45 ?? 50 56 8D 45 ?? 89 75 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? - 85 C0 0F 85 ?? ?? ?? ?? 33 FF 0F 1F 40 ?? 3B 7D ?? 0F 83 ?? ?? ?? ?? 8B C7 C1 E0 ?? - 03 F0 F7 46 ?? ?? ?? ?? ?? 74 ?? 6A ?? E8 ?? ?? ?? ?? 0F 10 06 83 C4 ?? 8B C8 0F 11 - 00 0F 10 46 ?? 0F 11 40 ?? E8 ?? ?? ?? ?? 8B 75 ?? B3 ?? 47 EB ?? F7 46 ?? ?? ?? ?? - ?? 0F 84 ?? ?? ?? ?? 8B 56 ?? 85 D2 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C6 45 ?? ?? 80 3A ?? 75 ?? 33 C9 EB ?? 8B CA 8D 71 ?? 8A 01 41 84 C0 75 - ?? 2B CE 51 52 8D 4D ?? E8 ?? ?? ?? ?? 51 8D 55 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? 83 C4 ?? 8B F0 BA ?? ?? ?? ?? C6 45 ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D6 8B - C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 83 C4 ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B + $find_files_p2 = { + 54 24 ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 44 24 + ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 4C 24 + ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 54 24 + ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 44 24 + ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? 68 + ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 54 24 ?? 68 ?? ?? + ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 33 C0 68 ?? ?? ?? ?? 50 8D + 8C 24 ?? ?? ?? ?? 51 66 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 54 24 ?? 52 + 56 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 51 + E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 83 + C4 ?? 85 F6 74 ?? 8B 44 24 ?? 8D 54 24 ?? 52 50 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? + 8B 0D ?? ?? ?? ?? 83 C4 ?? 3B 0D ?? ?? ?? ?? 7C ?? 8D 49 ?? 6A ?? FF 15 ?? ?? ?? ?? + 8B 15 ?? ?? ?? ?? 3B 15 ?? ?? ?? ?? 7D ?? 68 ?? ?? ?? ?? FF D7 FF 05 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF D3 6A ?? 6A ?? 56 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 8B 74 24 ?? 8D 44 24 ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? 56 FF 15 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D + C3 } - $enum_shares_p2 = { - 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? E8 - ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B C8 - 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 EC ?? 8D 55 ?? 8B CC 51 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? - ?? ?? ?? 83 C4 ?? 8D 55 ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 BA ?? ?? ?? ?? - C6 45 ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D6 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? C6 45 ?? ?? 83 C4 ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 - C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? - E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 - ?? ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 F8 ?? 72 ?? - 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? - E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B - C8 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? - 8B 75 ?? B3 ?? 47 E9 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? BA - ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8A C3 E9 ?? ?? - ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? - ?? ?? ?? C3 + $encrypt_files_p1 = { + 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? + ?? ?? 53 56 57 33 C0 8B D9 68 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? 51 89 5C 24 ?? 66 + 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 94 24 ?? ?? ?? ?? 52 6A ?? 6A ?? 6A + ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 66 83 BC 24 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? BF ?? ?? + ?? ?? 33 F6 8D 84 24 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? + ?? 83 C6 ?? 83 C7 ?? 81 FE ?? ?? ?? ?? 72 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? 51 + 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 0F 8C ?? ?? ?? ?? 8B + 7C 24 ?? 7F ?? 83 FF ?? 0F 82 ?? ?? ?? ?? 8B F0 89 7C 24 ?? 89 74 24 ?? 85 C0 7C ?? + 7F ?? 83 FF ?? 76 ?? 6A ?? 6A ?? 6A ?? 53 C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 33 C0 50 8D 54 24 ?? 52 89 44 24 ?? 89 44 24 ?? 66 89 44 24 ?? 88 44 24 ?? 6A ?? 8D + 44 24 ?? 50 53 C6 44 24 ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B C7 83 E8 + ?? 8B CE 83 D9 ?? 33 F6 39 44 24 ?? 75 ?? 3B F1 75 ?? 8B 4C 24 ?? 3B 0D ?? ?? ?? ?? + 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 54 24 ?? 6A ?? 52 C6 44 } - $find_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? A1 ?? ?? ?? ?? ?? ?? ?? - ?? EC 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? 45 FC 00 00 00 00 8D 4D ?? - C6 45 ?? ?? 8B 75 ?? 83 FE ?? 8B 7D ?? 8B 55 ?? 0F 43 CF 6A ?? 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 C4 ?? 8D 4D ?? 85 C0 0F 84 ?? ?? ?? ?? 83 FE ?? 6A ?? 0F 43 CF 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 85 C0 0F 84 ?? ?? ?? ?? 83 FE ?? 6A ?? 0F 43 - CF 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 85 C0 0F 84 ?? ?? ?? ?? 83 FE ?? - 6A ?? 0F 43 CF 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 0F 57 - C0 C7 45 ?? ?? ?? ?? ?? 66 0F D6 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? 83 FE ?? C6 45 ?? ?? 8D 4D ?? 0F 43 CF E8 ?? ?? ?? ?? 8B F0 89 75 - ?? 85 F6 0F 84 ?? ?? ?? ?? 8D 45 ?? 8B D6 50 8B CE E8 ?? ?? ?? ?? 8B 5D ?? 83 C4 ?? - 85 DB 0F 84 ?? ?? ?? ?? 8D 7B ?? B9 ?? ?? ?? ?? 8B C7 66 0F 1F 44 00 ?? 8A 10 3A 11 - 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 F6 EB ?? - 1B F6 83 CE ?? B9 ?? ?? ?? ?? 8B C7 0F 1F 40 ?? 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 - ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 3B F0 8B - 75 ?? 0F 85 ?? ?? ?? ?? 8B 43 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 4D ?? 57 3D ?? ?? ?? ?? - 75 ?? E8 ?? ?? ?? ?? 50 8D 55 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 EC - ?? C6 45 ?? ?? 8B CC 8B D0 51 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D - ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 EC ?? C6 45 ?? ?? 8B CC 8D 55 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? 83 C4 - ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 75 ?? E9 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? - 83 EC ?? 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? BA ?? ?? ?? - ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? B8 ?? ?? ?? ?? C3 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? E8 ?? ?? ?? - ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD - E8 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files_p2 = { + 24 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 79 ?? 48 0D ?? + ?? ?? ?? 40 88 44 34 ?? 46 83 FE ?? 7C ?? 8B 44 24 ?? BE ?? ?? ?? ?? 85 C0 0F 8F ?? + ?? ?? ?? 0F 8C ?? ?? ?? ?? 81 FF ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 85 C0 0F 8C ?? ?? ?? + ?? 7F ?? 85 FF 0F 84 ?? ?? ?? ?? 85 C0 7F ?? 7C ?? 3B FE 73 ?? 6A ?? 6A ?? 50 57 E8 + ?? ?? ?? ?? 8B F7 2B F0 56 E8 ?? ?? ?? ?? 8B F8 33 C0 83 C4 ?? 89 44 24 ?? 89 44 24 + ?? 3B F8 74 ?? 50 8D 44 24 ?? 50 56 57 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 39 74 24 ?? + 75 ?? 6A ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 56 57 8D 44 24 ?? E8 ?? ?? ?? ?? 83 C4 + ?? 6A ?? 8D 4C 24 ?? 51 56 57 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 FF 15 + ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? + ?? ?? 8B E5 5D C3 53 FF 15 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 + C4 ?? 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 6A ?? 68 ?? ?? + ?? ?? 50 57 E8 ?? ?? ?? ?? 8B C8 89 44 24 ?? B8 ?? ?? ?? ?? F7 E9 C1 FA ?? 8B C2 C1 + E8 ?? 03 C2 69 C0 ?? ?? ?? ?? 8B D1 2B D0 85 D2 7E ?? 41 89 4C 24 ?? 33 C0 89 44 24 + ?? 3B C8 0F 8E ?? ?? ?? ?? 89 44 24 ?? EB ?? 90 8B 7C 24 ?? 8B 44 24 ?? 8B 4C 24 } - $encrypt_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? A1 ?? ?? ?? ?? ?? ?? ?? - ?? EC 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? 45 FC 00 00 00 00 C6 45 ?? - ?? 83 05 ?? ?? ?? ?? ?? 83 15 ?? ?? ?? ?? ?? 83 EC ?? 8B CC C7 41 ?? ?? ?? ?? ?? C7 - 41 ?? ?? ?? ?? ?? 83 79 ?? ?? 72 ?? 8B 01 EB ?? 8B C1 6A ?? C6 00 ?? 8D 45 ?? 6A ?? - 50 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 EC ?? C6 45 ?? ?? 8B CC C7 41 - ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 83 79 ?? ?? 72 ?? 8B 01 EB ?? 8B C1 6A ?? C6 00 - ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D - 4D ?? 83 3D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 8B 7D ?? 0F 43 05 ?? ?? ?? ?? 83 FF ?? FF - 35 ?? ?? ?? ?? 8B 75 ?? 0F 43 CE 8B 55 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? - ?? ?? ?? 83 FF ?? 8D 4D ?? 6A ?? 0F 43 CE 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 - C0 0F 84 ?? ?? ?? ?? 83 FF ?? 8D 4D ?? 6A ?? 0F 43 CE 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 FF ?? 8D 4D ?? 6A ?? 0F 43 CE 68 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 + $encrypt_files_p3 = { + 99 2B F8 1B CA 89 7C 24 ?? 89 4C 24 ?? 0F 88 ?? ?? ?? ?? 7F ?? 85 FF 0F 84 ?? ?? ?? + ?? 8B C6 99 3B CA 7F ?? 7C ?? 3B F8 73 ?? 6A ?? 6A ?? 51 57 E8 ?? ?? ?? ?? 8B F7 2B + F0 85 F6 0F 8E ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B F8 33 C0 83 C4 ?? 89 44 24 ?? 89 44 + 24 ?? 3B F8 0F 84 ?? ?? ?? ?? 50 8D 44 24 ?? 50 56 57 53 FF 15 ?? ?? ?? ?? 85 C0 0F + 84 ?? ?? ?? ?? 39 74 24 ?? 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 8B CE F7 D9 51 53 FF 15 ?? + ?? ?? ?? 56 57 8D 44 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 54 24 ?? 52 56 57 53 FF + 15 ?? ?? ?? ?? 85 C0 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 81 FE ?? ?? ?? ?? 7C ?? 83 7C + 24 ?? ?? 7C ?? 7F ?? 81 7C 24 ?? ?? ?? ?? ?? 72 ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF + 15 ?? ?? ?? ?? 8B 44 24 ?? 81 44 24 ?? ?? ?? ?? ?? 40 89 44 24 ?? 3B 44 24 ?? 0F 8C + ?? ?? ?? ?? EB ?? 53 FF 15 ?? ?? ?? ?? EB ?? 53 FF 15 ?? ?? ?? ?? 85 FF 74 ?? 57 E8 + ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 68 } - $encrypt_files_p2 = { - 84 C0 0F 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? - ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 - ?? 6A ?? 0F 43 45 ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B - D8 83 FB ?? 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 6A ?? 8B F0 8B FA 8D 45 ?? 50 68 ?? - ?? ?? ?? FF 35 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 2B C6 1B D7 01 05 - ?? ?? ?? ?? 11 15 ?? ?? ?? ?? 83 65 ?? ?? 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 8B FA - 8B F0 8B 55 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 2B C6 6A ?? 1B D7 01 05 ?? ?? ?? ?? - 8B 45 ?? 11 15 ?? ?? ?? ?? 01 05 ?? ?? ?? ?? 6A ?? 83 15 ?? ?? ?? ?? ?? 6A ?? 53 FF - 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 6A ?? 8B F0 8B FA 8D 45 ?? 50 FF 75 ?? FF 35 ?? ?? - ?? ?? 53 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 2B C6 53 1B D7 01 05 ?? ?? ?? ?? 11 15 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 51 8D 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C8 83 C4 ?? 83 - 79 ?? ?? 72 ?? 8B 09 83 7D ?? ?? 8D 45 ?? 51 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? 83 05 ?? ?? ?? ?? ?? 83 15 ?? ?? ?? ?? ?? EB ?? 53 FF 15 ?? ?? ?? - ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? - 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files_p4 = { + 8D 84 24 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? B9 ?? ?? ?? ?? 8D + 74 24 ?? 8D BC 24 ?? ?? ?? ?? F3 A5 8B 4C 24 ?? 6A ?? 89 8C 24 ?? ?? ?? ?? 8B D0 8D + 4C 24 ?? 51 C1 FA ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? A1 ?? + ?? ?? ?? 52 53 C7 44 24 ?? ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 53 FF + 15 ?? ?? ?? ?? 33 C0 68 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? 51 66 89 84 24 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 74 24 ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 8D 94 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 94 24 ?? ?? ?? ?? 52 56 FF 15 ?? ?? ?? ?? 5F 5E + 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 53 FF 15 ?? ?? ?? ?? 8B 8C + 24 ?? ?? ?? ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $find_MS_xchange_backups_p1 = { + 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? + ?? ?? 53 56 57 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? + 8B 1D ?? ?? ?? ?? B0 ?? 88 44 24 ?? 88 44 24 ?? B0 ?? 83 C4 ?? C6 44 24 ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 66 C7 44 24 ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? 88 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 66 C7 44 24 ?? ?? ?? C6 44 24 ?? ?? 88 44 24 + ?? 88 44 24 ?? BE ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B FF 68 ?? ?? ?? ?? 8D 8C 24 + ?? ?? ?? ?? 6A ?? 51 C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 56 8D 54 24 ?? + 52 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 8D 4C 24 ?? 6A ?? 51 + E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 33 D2 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? + 8D 44 24 ?? 50 8D 4C 24 ?? 51 52 52 52 52 52 52 66 89 54 24 ?? 8D 94 24 ?? ?? ?? ?? + 52 6A ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF D3 6A ?? FF D7 83 C6 ?? + FF 4C 24 ?? 0F 85 ?? ?? ?? ?? BE ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 8D 49 ?? + 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 50 C6 84 24 ?? ?? ?? ?? ?? E8 + } + $find_MS_xchange_backups_p2 = { + 83 C4 ?? 56 8D 4C 24 ?? 51 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 6A + ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 33 C9 8D 54 24 ?? 52 89 44 24 + ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 8D 44 24 ?? 50 51 51 51 51 51 51 66 89 4C 24 + ?? 8D 8C 24 ?? ?? ?? ?? 51 6A ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF + D3 6A ?? FF D7 83 C6 ?? FF 4C 24 ?? 0F 85 ?? ?? ?? ?? 33 D2 68 ?? ?? ?? ?? 52 8D 84 + 24 ?? ?? ?? ?? 50 66 89 94 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 B1 ?? EB ?? 8D 49 ?? + 30 88 ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 6A ?? + 51 C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? + ?? 52 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 51 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? 56 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 54 24 ?? 6A ?? 52 E8 ?? ?? + ?? ?? 83 C4 ?? 33 C0 8D 4C 24 ?? 51 8D 54 24 ?? 52 50 50 50 50 50 50 89 44 24 ?? 89 + 44 24 ?? 89 44 24 ?? 89 44 24 ?? 66 89 44 24 ?? 8D 84 24 ?? ?? ?? ?? 50 6A ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF D3 8B 8C 24 ?? ?? ?? ?? 5F 5E 5B 33 CC + E8 ?? ?? ?? ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($enum_volumes and $find_files and ( all of ($enum_shares_p*)) and ( all of ($encrypt_files_p*))) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($find_MS_xchange_backups_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Infodot : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Monalisa : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects InfoDot ransomware." + description = "Yara rule that detects Monalisa ransomware." author = "ReversingLabs" - id = "2f6447f4-523b-5ea1-a16d-d68bb9bcc79d" - date = "2021-02-16" - modified = "2021-02-16" + id = "34addb63-2426-59a2-b79b-052a9161d361" + date = "2022-05-13" + modified = "2022-05-13" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.InfoDot.yara#L1-L115" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "24a1c25c1d70c21323417ae0892c613361c4bfc829737ef86b6fa7616ae668c6" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Monalisa.yara#L1-L83" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0bcb79dff111ec05ac93bbe9a777546bd6234dc60d9f6982c03cd0bc3b26b038" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -33388,109 +35042,72 @@ rule REVERSINGLABS_Win32_Ransomware_Infodot : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "InfoDot" + tc_detection_name = "Monalisa" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B FA 8B D9 89 9D ?? ?? ?? ?? - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 53 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 8D 85 ?? ?? ?? ?? 50 FF D3 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? EB - ?? 8D 49 ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 - ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 - ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? - ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 - ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 - C0 74 ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B FF 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 - ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 - 83 C8 ?? 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 53 8D 85 ?? ?? ?? ?? 50 FF 15 - } - $find_files_p2 = { - 8B D7 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 57 8B 3D ?? ?? ?? ?? 56 50 FF D7 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? - 50 FF D3 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 9B ?? ?? ?? ?? F6 85 ?? ?? - ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? - ?? 50 56 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 8D 85 ?? ?? ?? ?? 50 FF D7 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 66 39 85 ?? ?? ?? ?? 75 ?? 33 C9 - EB ?? 8D 8D ?? ?? ?? ?? 8D 51 ?? 90 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 51 - 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 51 50 E8 ?? ?? ?? ?? 99 83 C4 ?? 0B - C2 75 ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? 83 CB ?? 83 BD ?? ?? ?? ?? ?? 72 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 BA ?? ?? ?? ?? 8B CF 8D A4 24 - ?? ?? ?? ?? 66 8B 31 66 3B 32 75 ?? 66 85 F6 74 ?? 66 8B 41 ?? 66 3B 42 ?? 75 ?? 83 - } - $find_files_p3 = { - C1 ?? 83 C2 ?? 66 85 C0 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 - ?? ?? ?? ?? 8B C7 8D 9B ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 - ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 - C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B C7 8D 9B ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? - 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 - EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B C7 8D 9B ?? ?? ?? ?? - 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 - ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? - 8B C7 8D 9B ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 - ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? - ?? ?? ?? B8 ?? ?? ?? ?? 66 8B 0F 66 3B 08 75 ?? 66 85 C9 74 ?? 66 8B 4F ?? 66 3B 48 - ?? 75 ?? 83 C7 ?? 83 C0 ?? 66 85 C9 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 85 DB 7F ?? 8B 95 ?? ?? ?? ?? 7C ?? 81 + $find_files = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 A1 ?? ?? ?? ?? 33 + C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 75 ?? 83 EC ?? C7 45 ?? ?? ?? ?? ?? 8B CC 89 65 + ?? 8D 45 ?? B3 ?? 51 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 89 65 ?? 33 C0 6A + ?? 68 ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 66 89 01 E8 ?? ?? ?? ?? + 83 EC ?? C6 45 ?? ?? 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8A D3 88 5D ?? 8B CE E8 ?? ?? + ?? ?? 8B 55 ?? 83 C4 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? + ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? + 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? + ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 5B 8B E5 5D C3 } - $find_files_p4 = { - FA ?? ?? ?? ?? 73 ?? 3B D8 0F 8F ?? ?? ?? ?? 7C ?? 3B D1 73 ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 EC ?? 8D 95 ?? ?? ?? ?? 8B CC 51 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? - ?? 83 C4 ?? 84 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 3B D8 7F - ?? 7C ?? 8B 85 ?? ?? ?? ?? 3B C1 73 ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? 8B 3D ?? - ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? - ?? 85 C0 8B 85 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 64 89 0D - ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $write_proc_mem = { + 8D 45 ?? 50 FF 76 ?? 8B 46 ?? 03 C7 50 8B 06 03 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? + 85 C0 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 3E 0F B7 41 ?? 48 3B D8 75 ?? 8B 51 ?? + EB ?? 8B 4D ?? 8B 35 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 56 ?? 8B 4E ?? 2B D7 8B C1 25 ?? + ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? EB ?? 8B C1 25 ?? ?? ?? ?? 3D ?? ?? ?? + ?? 75 ?? B8 ?? ?? ?? ?? EB ?? 8B C1 25 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? + ?? EB ?? 8B C1 25 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? EB ?? F7 C1 ?? ?? + ?? ?? 74 ?? B8 ?? ?? ?? ?? EB ?? F7 C1 ?? ?? ?? ?? 74 ?? B8 ?? ?? ?? ?? EB ?? 85 C9 + B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 48 C1 8D 4D ?? 51 50 8B 45 ?? 52 03 C7 50 FF 75 ?? + FF 15 } $encrypt_files = { - 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 8B F1 C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 74 ?? 83 C8 ?? 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 56 8D 85 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 0F 57 - C0 68 ?? ?? ?? ?? 50 F3 0F 7F 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? - ?? ?? ?? 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? - 57 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 8B FF - 81 FF ?? ?? ?? ?? 75 ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 - 50 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 6A ?? 50 E8 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 6A ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 - ?? 8B C7 25 ?? ?? ?? ?? 79 ?? 48 83 C8 ?? 40 BE ?? ?? ?? ?? 2B F0 8D 85 ?? ?? ?? ?? - 56 03 C7 56 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 03 F7 8D 85 ?? ?? - ?? ?? 56 50 50 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 6A ?? 50 E8 ?? - ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? - 83 C4 ?? 33 CD 33 C0 5F 5E E8 ?? ?? ?? ?? 8B E5 5D C3 + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 50 + 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B C1 83 F8 ?? 0F 82 ?? + ?? ?? ?? 83 3D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 51 0F 43 05 ?? ?? ?? ?? 50 6A ?? 68 ?? + ?? ?? ?? 51 FF 75 ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 33 C9 C7 05 ?? ?? ?? ?? ?? ?? ?? + ?? 0F 10 00 0F 11 05 ?? ?? ?? ?? F3 0F 7E 40 ?? 66 0F D6 05 ?? ?? ?? ?? C7 40 ?? ?? + ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 66 89 08 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? + ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 + ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 + 89 0D ?? ?? ?? ?? 59 8B E5 5D C3 + } + $generate_key = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 + 45 ?? 56 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B 75 ?? + 8B 0C 88 A1 ?? ?? ?? ?? 3B 81 ?? ?? ?? ?? 7F ?? 56 FF 75 ?? FF 35 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 85 C0 74 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 8B 4D ?? 33 CD E8 ?? ?? + ?? ?? 8B E5 5D C2 ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 3D ?? ?? ?? ?? ?? + 75 ?? B9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? ?? ?? + 8D 4D ?? E8 ?? ?? ?? ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 45 ?? 50 E8 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) + uint16(0)==0x5A4D and ($find_files) and ($write_proc_mem) and ($generate_key) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Montserrat : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Wildfire : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Montserrat ransomware." + description = "Yara rule that detects WildFire ransomware." author = "ReversingLabs" - id = "deeb5f1a-1329-5964-93e1-8ca6a20fcd89" - date = "2020-07-15" - modified = "2020-07-15" + id = "0c44f017-703c-5db7-b777-62fcd181af9a" + date = "2021-08-12" + modified = "2021-08-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Montserrat.yara#L1-L118" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "c8782a8cb2b87e76ff1f804ee8affd01405827d0914ea725bb0e9ddace7dde10" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.WildFire.yara#L1-L77" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "d3be2eac7967853aae6e1317d9c22d95a3dc4b3e5bf8acbe97a7bbeabc9eab38" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -33498,108 +35115,78 @@ rule REVERSINGLABS_Win32_Ransomware_Montserrat : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Montserrat" + tc_detection_name = "WildFire" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 8B FF 55 8B EC 51 8B 4D ?? 53 57 33 DB 8D 51 ?? 66 8B 01 83 C1 ?? 66 3B C3 75 ?? 8B - 7D ?? 2B CA D1 F9 83 C8 ?? 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 56 8D 5F ?? - 03 D9 6A ?? 53 E8 ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? - ?? 83 C4 ?? 85 C0 75 ?? FF 75 ?? 2B DF 8D 04 7E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 75 ?? 8B 4D ?? 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5F - 5B 8B E5 5D C3 33 C0 50 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? - ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 55 ?? 8B 4D ?? 53 8B 5D ?? 56 57 6A ?? 5E 6A ?? - 89 95 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 5F EB ?? 0F B7 01 66 3B 85 ?? ?? ?? - ?? 74 ?? 66 3B C6 74 ?? 66 3B C7 74 ?? 83 E9 ?? 3B CB 75 ?? 0F B7 31 66 3B F7 75 ?? - 8D 43 ?? 3B C8 74 ?? 52 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 6A ?? - 8B C6 33 FF 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 8B C7 - } - $find_files_p2 = { - EB ?? 33 C0 40 2B CB 0F B6 C0 D1 F9 41 F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 - 57 53 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? 8B 85 ?? ?? ?? ?? 50 57 57 53 E8 ?? ?? - ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD - 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 8D ?? ?? ?? ?? 6A ?? 8B 41 ?? 2B 01 C1 F8 ?? 89 85 - ?? ?? ?? ?? 58 66 39 85 ?? ?? ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 66 39 85 ?? ?? - ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 51 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 8B 8D - ?? ?? ?? ?? 85 C0 6A ?? 58 75 ?? 8B C1 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 - ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? - 83 C4 ?? E9 - } - $encrypt_files_p1 = { - 8B FF 55 8B EC 83 EC ?? 53 56 57 FF 75 ?? 8D 45 ?? FF 75 ?? FF 75 ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 8D 7D ?? 8B F0 6A ?? 59 F3 A5 83 CE ?? 39 75 ?? 75 ?? E8 ?? ?? ?? ?? 83 - 20 ?? 8B 45 ?? 89 30 E8 ?? ?? ?? ?? 8B 00 E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 5D ?? 89 - 03 3B C6 75 ?? E8 ?? ?? ?? ?? 83 20 ?? 89 33 E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? EB ?? - 8B 45 ?? 8D 75 ?? 83 65 ?? ?? 33 C9 41 C7 45 ?? ?? ?? ?? ?? 83 EC ?? 89 08 8B 45 ?? - C1 E8 ?? F7 D0 23 C1 6A ?? 59 89 45 ?? 8B FC 8D 45 ?? 50 FF 75 ?? F3 A5 E8 ?? ?? ?? - ?? 8B F8 83 C4 ?? 89 7D ?? BA ?? ?? ?? ?? 83 FF ?? 75 ?? 8B 4D ?? 8B C1 23 C2 3B C2 - 75 ?? F6 45 ?? ?? 74 ?? 83 EC ?? 8D 45 ?? 81 E1 ?? ?? ?? ?? 8D 75 ?? 89 4D ?? 6A ?? - 59 8B FC 50 FF 75 ?? F3 A5 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 89 7D ?? 83 FF ?? 75 ?? 8B - 0B 8B C1 83 E1 ?? C1 F8 ?? 6B C9 ?? 8B 04 85 ?? ?? ?? ?? 80 64 08 ?? ?? FF 15 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 59 E9 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? - ?? ?? ?? 8B F0 56 E8 ?? ?? ?? ?? 59 8B 0B 8B C1 83 E1 ?? C1 F8 ?? 6B C9 ?? 57 8B 04 - 85 ?? ?? ?? ?? 80 64 08 ?? ?? FF 15 ?? ?? ?? ?? 85 F6 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? - ?? C7 00 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 F8 ?? 75 ?? 8A 45 ?? 0C ?? EB ?? 83 F8 ?? 8A + $encrypt_files = { + 00 02 19 17 73 ?? ?? ?? ?? 0A 1B 8D ?? ?? ?? ?? 25 16 02 16 02 [5-10] 6F ?? ?? ?? ?? + 6F ?? ?? ?? ?? A2 25 17 [5-10] A2 25 18 7E ?? ?? ?? ?? A2 25 19 [5-10] A2 25 1A 02 02 + [5-10] 6F ?? ?? ?? ?? 17 D6 6F ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 0B 07 [5-10] 28 ?? ?? ?? + ?? 1A 18 73 ?? ?? ?? ?? 0C 08 21 00 00 00 00 00 00 00 00 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? + 8D ?? ?? ?? ?? 0D 21 00 00 00 00 00 00 00 00 13 ?? 06 6F ?? ?? ?? ?? 13 ?? 73 ?? ?? ?? + ?? 13 ?? 08 11 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? + 2B ?? 06 09 16 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 09 16 11 ?? 6F ?? ?? ?? ?? 11 + ?? 11 ?? 6A D6 13 ?? 11 ?? 11 ?? FE ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 08 + 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 17 D6 80 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? DE ?? 28 ?? ?? ?? + ?? 28 ?? ?? ?? ?? DE ?? 2A } - $encrypt_files_p2 = { - 45 ?? 75 ?? 0C ?? 57 FF 33 88 45 ?? E8 ?? ?? ?? ?? 8A 55 ?? 59 59 8B 0B 80 CA ?? 8B - C1 88 55 ?? 83 E1 ?? C1 F8 ?? 6B C9 ?? 88 55 ?? 8B 04 85 ?? ?? ?? ?? 88 54 08 ?? 8B - 0B 8B C1 83 E1 ?? C1 F8 ?? 6B C9 ?? F6 45 ?? ?? 8B 04 85 ?? ?? ?? ?? C6 44 08 ?? ?? - 74 ?? FF 33 E8 ?? ?? ?? ?? 8B F0 59 85 F6 75 ?? 8D 45 ?? C6 45 ?? ?? 50 FF 75 ?? 8D - 75 ?? 83 EC ?? 6A ?? 59 8B FC FF 33 F3 A5 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B F0 - FF 33 E8 ?? ?? ?? ?? 59 8B C6 E9 ?? ?? ?? ?? 8B 03 8B C8 83 E0 ?? C1 F9 ?? 6B D0 ?? - 8A 45 ?? 8B 0C 8D ?? ?? ?? ?? 88 44 11 ?? 8B 0B 8B C1 C1 F8 ?? 83 E1 ?? 6B D1 ?? 8B - 0C 85 ?? ?? ?? ?? 8B 45 ?? C1 E8 ?? 32 44 11 ?? 24 ?? 30 44 11 ?? F6 45 ?? ?? 75 ?? - F6 45 ?? ?? 74 ?? 8B 0B 8B C1 83 E1 ?? C1 F8 ?? 6B C9 ?? 8B 04 85 ?? ?? ?? ?? 80 4C - 08 ?? ?? 8B 75 ?? B9 ?? ?? ?? ?? 8B C6 23 C1 3B C1 0F 85 ?? ?? ?? ?? F6 45 ?? ?? 74 - ?? FF 75 ?? FF 15 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 81 E6 ?? ?? ?? ?? 89 75 ?? 8D 75 ?? - 6A ?? 59 8B FC 50 FF 75 ?? F3 A5 E8 ?? ?? ?? ?? 8B D0 83 C4 ?? 83 FA ?? 75 ?? FF 15 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 0B 8B C1 83 E1 ?? C1 F8 ?? 6B C9 ?? 8B 04 85 ?? ?? - ?? ?? 80 64 08 ?? ?? FF 33 E8 ?? ?? ?? ?? 59 E9 ?? ?? ?? ?? 8B 0B 8B C1 C1 F8 ?? 83 - E1 ?? 6B C9 ?? 8B 04 85 ?? ?? ?? ?? 89 54 08 ?? 33 C0 5F 5E 5B 8B E5 5D C3 + $enum_drives = { + 00 00 28 ?? ?? ?? ?? 1F ?? 0A 18 0C 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F + ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 19 0C 28 ?? ?? ?? ?? 0D 1A + 0C 09 13 ?? 16 13 ?? 11 ?? 11 ?? 8E 69 FE ?? 2C ?? 11 ?? 11 ?? 9A 13 ?? 1B 0C 11 ?? + 6F ?? ?? ?? ?? 2C ?? 1C 0C 11 ?? 6F ?? ?? ?? ?? 19 FE ?? 16 FE ?? 65 18 60 1A 60 11 + ?? 6F ?? ?? ?? ?? 21 ?? ?? ?? ?? ?? ?? ?? ?? FE ?? 16 FE ?? 65 5F 16 FE ?? 2C ?? 1D + 0C 11 ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 1E 0C 11 ?? 6F ?? ?? ?? ?? + 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 1F ?? 0C 11 ?? 17 D6 13 ?? 2B } - $shutdown_services_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 65 ?? 8B F9 8B 75 ?? 8B 1D - ?? ?? ?? ?? FF D3 83 7E ?? ?? 89 45 ?? 72 ?? 8B 36 6A ?? 56 FF 37 FF 15 ?? ?? ?? ?? - 8B F0 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 8D 45 ?? 50 6A ?? 56 FF 15 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? 8B - 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 ?? - ?? 83 F8 ?? 75 ?? 66 90 FF 77 ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 8D 45 ?? 50 6A - ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF D3 2B 45 ?? 3B - 47 ?? 0F 87 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8B CF E8 - ?? ?? ?? ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 75 ?? 50 6A ?? 56 FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 + $file_search = { + A2 25 20 ?? ?? ?? ?? [5-10] A2 25 20 ?? ?? ?? ?? [5-10] A2 25 20 ?? ?? ?? ?? [5-10] + A2 25 20 ?? ?? ?? ?? [5-10] A2 25 20 ?? ?? ?? ?? [5-10] A2 0D 19 0C 19 8D ?? ?? ?? ?? + 25 16 [5-10] A2 25 17 [5-10] A2 25 18 [5-10] A2 13 04 1A 0C 02 28 ?? ?? ?? ?? 13 ?? 1B + 0C 11 ?? 8E 69 17 DA 13 ?? 16 13 ?? 11 ?? 11 ?? (30 | 3D) [1-4] 1C 0C 11 ?? 11 ?? 9A 28 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 1D 0C 09 11 ?? 6F ?? ?? ?? ?? 11 ?? 11 ?? 9A [5-10] 6F + ?? ?? ?? ?? 16 FE ?? 5F 11 ?? 11 ?? 9A 1F ?? 28 ?? ?? ?? ?? [5-10] 28 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 16 FE ?? 5F 11 ?? [5-10] 16 28 ?? ?? ?? ?? 16 FE ?? 5F 2C ?? 1E 0C 11 ?? 11 ?? + 9A 28 ?? ?? ?? ?? 1F ?? 0C 11 ?? 17 D6 13 ?? (38 | 2B) [1-4] 1F ?? 0C 02 28 ?? ?? ?? ?? + 13 ?? 1F ?? 0C 11 ?? 8E 69 17 DA 13 ?? 16 13 ?? 11 ?? 11 ?? 30 ?? 1F ?? 0C 11 ?? 11 ?? + 11 ?? 9A 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 FE ?? 2C ?? 1F ?? 0C 11 ?? 11 ?? 9A 28 ?? ?? + ?? ?? 1F ?? 0C 11 ?? 17 D6 13 ?? 2B ?? 1F ?? 0C 02 17 8D ?? ?? ?? ?? 25 16 1F ?? 9D 6F + ?? ?? ?? ?? 8E 69 17 DA 18 FE ?? 16 FE ?? 2C ?? 1F ?? 0C 02 16 28 ?? ?? ?? ?? DD ?? ?? + ?? ?? 07 17 58 16 0B 45 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? + ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? + ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? + ?? ?? ?? ?? ?? ?? ?? ?? ?? DE } - $shutdown_services_p2 = { - FF 77 ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 8D 45 ?? 50 6A ?? 56 FF 15 ?? ?? ?? ?? - 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? FF D3 2B 45 ?? 3B 47 ?? 0F 87 - ?? ?? ?? ?? 83 7D ?? ?? 75 ?? E9 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 - ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 + $remote_server_communication_1 = { + 00 7E ?? ?? ?? ?? 73 ?? ?? ?? ?? 16 7E ?? ?? ?? ?? 8E 69 6F ?? ?? ?? ?? 9A [5-10] 28 ?? + ?? ?? ?? 0B 02 [5-10] 16 28 ?? ?? ?? ?? 16 FE ?? 3A ?? ?? ?? ?? 02 [5-10] 16 28 ?? ?? ?? + ?? 16 FE ?? 39 ?? ?? ?? ?? 1D 8D ?? ?? ?? ?? 25 16 [5-10] A2 25 17 02 A2 25 18 [5-10] A2 + 25 19 7E ?? ?? ?? ?? A2 25 1A [5-10] A2 25 1B 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 25 1C [5-10] + A2 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? + [5-10] 11 ?? 28 ?? ?? ?? ?? 13 ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 07 + 28 ?? ?? ?? ?? 74 ?? ?? ?? ?? 13 ?? 11 ?? [5-10] 6F ?? ?? ?? ?? 11 ?? [5-10] 6F ?? ?? ?? ?? + 11 ?? 11 ?? 8E 69 6A 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 16 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? + ?? 13 ?? 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? + 74 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($shutdown_services_p*)) + uint16(0)==0x5A4D and $enum_drives and $file_search and $encrypt_files and $remote_server_communication_1 } -rule REVERSINGLABS_Win32_Ransomware_Avaddon : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win64_Ransomware_DST : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Avaddon ransomware." + description = "Yara rule that detects DST ransomware." author = "ReversingLabs" - id = "f3a57482-5799-594b-bcfa-1137ca04dfd5" - date = "2020-10-19" - modified = "2020-10-19" + id = "bcc9933d-14eb-5f83-a136-5f009c7a3282" + date = "2021-12-06" + modified = "2021-12-06" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Avaddon.yara#L1-L148" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "1b2c449d5bad02dd06cb4a980fcca1feaf02b1d8127096bb39deecbc544272a6" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.DST.yara#L1-L170" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "b658093232a2265d425e3b38758268c116bbac51fa5eed372b5b4f00de4c6880" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -33607,132 +35194,158 @@ rule REVERSINGLABS_Win32_Ransomware_Avaddon : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Avaddon" + tc_detection_name = "DST" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 8B FF 55 8B EC 51 8B 4D ?? 53 57 33 DB 8D 51 ?? 66 8B 01 83 C1 ?? 66 3B C3 75 ?? 8B - 7D ?? 2B CA D1 F9 8B C7 41 F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 5F 5B C9 C3 56 8D 5F - ?? 03 D9 6A ?? 53 E8 ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? - ?? ?? 83 C4 ?? 85 C0 75 ?? FF 75 ?? 2B DF 8D 04 7E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 75 ?? 8B 7D ?? 8B CF E8 ?? ?? ?? ?? 8B D8 85 DB 74 ?? 56 E8 ?? ?? ?? ?? - 59 EB ?? 8B 47 ?? 89 30 83 47 ?? ?? 33 DB 6A ?? E8 ?? ?? ?? ?? 59 8B C3 5E EB ?? 33 - C0 50 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 8B 55 ?? 8B 4D ?? 53 8B 5D ?? 89 8D ?? ?? ?? ?? 56 57 3B D3 74 ?? 0F - B7 02 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 84 C0 75 ?? 83 EA ?? 3B D3 75 ?? 8B 8D ?? - ?? ?? ?? 0F B7 32 83 FE ?? 75 ?? 8D 43 ?? 3B D0 74 ?? 51 33 FF 57 57 53 E8 ?? ?? ?? - ?? 83 C4 ?? E9 ?? ?? ?? ?? 56 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 2B D3 0F B6 C0 D1 FA - 42 F7 D8 1B C0 33 FF 57 57 23 C2 57 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 53 FF - 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 - C4 ?? 8B F8 E9 ?? ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 6A ?? 89 8D ?? ?? ?? ?? 59 66 39 - 8D ?? ?? ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 66 39 8D ?? ?? ?? ?? 75 ?? 66 39 BD - ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 6A ?? 85 C0 8B 85 ?? ?? ?? - ?? 59 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? - ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8B F8 56 FF 15 ?? ?? ?? - ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 - } $encrypt_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 8B 45 ?? 8B - 7D ?? 85 C0 0F 84 ?? ?? ?? ?? 83 FF ?? 0F 84 ?? ?? ?? ?? 6A ?? 8D 4D ?? C7 45 ?? ?? - ?? ?? ?? 51 6A ?? 6A ?? 6A ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 + 4C 8D A4 24 ?? ?? ?? ?? 4D 3B 66 ?? 0F 86 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 89 AC + 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? + ?? 48 89 BC 24 ?? ?? ?? ?? 44 0F 11 BC 24 ?? ?? ?? ?? 48 85 DB 0F 84 ?? ?? ?? ?? 48 + 89 9C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? 48 89 4C 24 ?? + 31 C9 31 FF E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 85 DB + 0F 85 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 44 0F 11 BC 24 ?? ?? ?? ?? 48 8D 0D ?? ?? + ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? + ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 0F 1F 00 + E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 31 C0 48 8B 9C 24 ?? ?? ?? ?? 48 8B 8C 24 ?? + ?? ?? ?? 48 8D 3D ?? ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? BF ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 85 DB 0F 85 + ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 44 0F 11 BC 24 ?? ?? ?? ?? 48 8D 0D } $encrypt_files_p2 = { - 6A ?? 8D 45 ?? 0F 57 C0 50 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 57 FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 6A ?? 51 8D 45 ?? 0F 43 45 ?? 68 ?? ?? ?? - ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 - ?? 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 33 F6 39 75 ?? 0F 86 ?? ?? ?? ?? 83 - 7D ?? ?? 8D 45 ?? 8D 4D ?? 0F 43 45 ?? 83 7D ?? ?? 68 ?? ?? ?? ?? 0F 43 4D ?? 03 C6 - 50 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 8D 45 ?? 0F - 43 45 ?? 53 51 50 6A ?? 6A ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? 83 7D ?? ?? 8D 4D ?? 6A ?? 51 8D 45 ?? 0F 43 45 ?? 53 50 57 FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? 3B 75 ?? 0F 82 ?? ?? ?? ?? 83 7D ?? ?? 74 + 48 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 8C 24 + ?? ?? ?? ?? 48 89 4C 24 ?? 48 8D 44 24 ?? E8 ?? ?? ?? ?? 90 85 C0 0F 85 ?? ?? ?? ?? + 48 8D 05 ?? ?? ?? ?? BB ?? ?? ?? ?? 48 89 D9 E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? + BB ?? ?? ?? ?? 48 89 D9 E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? + ?? 48 85 DB 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? BB ?? ?? ?? ?? 48 89 D9 E8 ?? + ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? 48 85 C9 0F 85 ?? ?? ?? ?? + 48 89 5C 24 ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B 51 ?? 48 8B 84 24 ?? ?? + ?? ?? FF D2 48 8B 0D ?? ?? ?? ?? 83 B9 ?? ?? ?? ?? ?? 75 ?? 48 89 C2 48 C1 E0 ?? 48 + 8D 70 ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 D1 48 F7 EE 48 8D 14 CA 48 8D 52 ?? 48 } $encrypt_files_p3 = { - 8B 45 ?? 89 45 ?? 8B 45 ?? 6A ?? 89 45 ?? 8D 45 ?? 50 51 52 57 89 55 ?? 89 4D ?? FF - 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 9D ?? ?? ?? ?? 83 7B ?? ?? 8D 43 ?? 72 ?? 8B 00 6A ?? - 8D 4D ?? 51 FF 73 ?? 50 57 FF D6 85 C0 74 ?? 8B 4B ?? 39 4D ?? 75 ?? 8B 45 ?? 89 85 - ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 6A ?? 89 45 ?? 8D 45 ?? 50 6A ?? 8D 85 ?? ?? - ?? ?? 89 4D ?? 50 57 C7 45 ?? ?? ?? ?? ?? FF D6 85 C0 74 ?? 83 7D ?? ?? 75 ?? B3 ?? - EB ?? 32 DB 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 - ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 - 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? - ?? ?? ?? 83 C4 ?? 8A C3 EB ?? 32 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D - ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 + C1 FA ?? 48 C1 FE ?? 48 29 F2 EB ?? 48 8D 70 ?? 48 89 C1 48 B8 ?? ?? ?? ?? ?? ?? ?? + ?? 48 F7 EE 48 8D 14 0A 48 8D 52 ?? 48 D1 FA 48 C1 FE ?? 48 29 F2 48 C1 E2 ?? 48 8D + 4A ?? 48 89 4C 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 CB E8 ?? ?? ?? ?? 48 89 C3 48 8B 4C + 24 ?? 48 89 CF 48 8B 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 + 8C 24 ?? ?? ?? ?? 48 85 DB 0F 85 ?? ?? ?? ?? 31 C0 48 8B 9C 24 ?? ?? ?? ?? 48 8B 4C + 24 ?? 48 8D 3D ?? ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 D9 48 89 C3 48 8B 84 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 85 + DB 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? BB ?? ?? ?? ?? 48 89 D9 31 FF 48 8B 74 + 24 ?? 4C 8B 84 24 ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? ?? 4C 8B 94 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 66 0F 1F 44 00 ?? 48 85 DB 0F + 85 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 C3 48 8D 0D ?? ?? ?? ?? 48 8B BC 24 ?? + ?? ?? ?? 31 F6 45 31 C0 4D 89 C1 48 8D 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 9C 24 ?? + ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 84 24 + ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 85 C0 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? + ?? 31 DB 31 C9 E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 85 + DB 74 ?? 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC + 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 48 8B 94 24 ?? ?? ?? ?? 48 8B 72 ?? 48 8B 42 + ?? 48 8B 56 ?? 31 DB 31 C9 48 89 CF FF D2 48 8B 15 ?? ?? ?? ?? 48 89 CF 48 89 D9 48 } - $remote_connection_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 45 ?? 33 C9 8B 75 ?? 89 85 ?? - ?? ?? ?? 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? 66 89 8D ?? ?? ?? ?? 89 4D ?? 39 4E ?? 0F 84 ?? ?? ?? ?? 66 39 4E ?? 0F 86 ?? ?? - ?? ?? 39 4E ?? 0F 84 ?? ?? ?? ?? 39 4E ?? 0F 84 ?? ?? ?? ?? 8B 06 8D 8D ?? ?? ?? ?? - 8B 7E ?? BA ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 78 ?? ?? 72 ?? 8B 00 6A - ?? 6A ?? 57 FF B5 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B F8 89 BD ?? - ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? - ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? - ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 - 89 85 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7E ?? ?? 8D 46 ?? 0F B7 4E ?? 72 ?? 8B + $encrypt_files_p4 = { + 89 C3 48 89 D0 E8 ?? ?? ?? ?? 48 89 D9 48 89 C3 48 8B 84 24 ?? ?? ?? ?? 0F 1F 40 ?? + E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 90 E8 ?? ?? ?? ?? 48 + 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? + ?? ?? C3 90 0F 1F 40 ?? E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? + ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? + ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 + E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? + ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? + ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 + 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? + C3 90 66 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC + 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 + 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? + ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 + ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 + 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? + ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 66 90 + E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? + ?? 48 81 C4 ?? ?? ?? ?? C3 48 89 44 24 ?? 48 89 5C 24 ?? 48 89 4C 24 ?? 48 89 7C 24 + ?? E8 } - $remote_connection_p2 = { - 00 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 51 50 57 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 7E ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B D0 83 7A ?? ?? 72 ?? 8B 12 83 7E ?? ?? 8D 4E ?? 72 ?? 8B 09 83 7E ?? ?? 8D 46 ?? - 72 ?? 8B 00 6A ?? 57 6A ?? 6A ?? 52 51 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 95 - ?? ?? ?? ?? 8B F8 89 BD ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? - ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 - ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 8B 46 ?? 85 C0 - 75 ?? 50 50 50 50 57 FF 15 ?? ?? ?? ?? EB ?? 83 C6 ?? 83 7E ?? ?? 72 ?? 8B 36 50 56 - 6A ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 + $find_files_p1 = { + 4C 8D A4 24 ?? ?? ?? ?? 4D 3B 66 ?? 0F 86 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 89 AC + 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? + ?? 48 89 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 85 DB 7E ?? 48 89 5C 24 ?? 31 C9 EB ?? + 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 48 8B 9C 24 ?? ?? ?? ?? 48 8D 43 ?? + 48 89 4C 24 ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 10 48 89 54 24 ?? 48 8B 58 ?? 48 89 5C + 24 ?? 48 8B 72 ?? 48 89 D8 FF D6 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 + 8B 8C 24 ?? ?? ?? ?? 48 8D 3D ?? ?? ?? ?? BE ?? ?? ?? ?? 49 89 C0 49 89 D9 31 C0 48 + 8B 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 5C 24 ?? 48 8B 4C 24 ?? 48 + 8B 51 ?? 48 8B 44 24 ?? FF D2 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 8D + 4B ?? 66 90 E9 ?? ?? ?? ?? 48 29 CB 48 89 DA 48 F7 DB 48 C1 FB ?? 48 21 D9 48 01 C1 + 48 89 8C 24 ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? EB ?? 31 D2 31 C9 48 89 C8 48 89 D3 + E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? + 48 8B 3D ?? ?? ?? ?? 48 8B 35 ?? ?? ?? ?? 66 90 E8 ?? ?? ?? ?? 84 C0 74 ?? 48 8D BC + 24 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? ?? 0F 1F 84 00 ?? ?? ?? ?? 48 89 6C 24 ?? 48 8D 6C } - $enum_resources_p1 = { - 33 D2 89 7D ?? 89 7D ?? 89 75 ?? 89 45 ?? 89 45 ?? 89 4D ?? 89 55 ?? 89 55 ?? 39 56 - ?? 0F 84 ?? ?? ?? ?? 89 55 ?? 89 55 ?? 89 55 ?? 89 55 ?? 83 7E ?? ?? 8B C6 72 ?? 8B - 06 8D 4D ?? 51 8D 4D ?? 51 8D 4D ?? 51 6A ?? 8D 4D ?? 51 6A ?? 50 FF 15 ?? ?? ?? ?? - 89 45 ?? 85 C0 74 ?? 3D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8B 45 ?? 89 45 ?? - C7 45 ?? ?? ?? ?? ?? 0F 82 + $find_files_p2 = { + 24 ?? E8 ?? ?? ?? ?? 48 8B 6D ?? 48 8D 84 24 ?? ?? ?? ?? 31 C9 0F 1F 00 E9 ?? ?? ?? + ?? 48 8B 4C 24 ?? 48 8B 49 ?? 48 8B 44 24 ?? FF D1 84 C0 74 ?? 48 8B 44 24 ?? 48 8B + 5C 24 ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 FF C1 48 8B 54 24 + ?? 0F 1F 00 48 39 CA 0F 8F ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 FF C9 48 85 C9 0F 8C ?? ?? + ?? ?? 0F B6 14 08 66 90 80 FA ?? 0F 84 ?? ?? ?? ?? 80 FA ?? 0F 84 ?? ?? ?? ?? 80 FA + ?? 75 ?? E9 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8D 42 ?? 48 89 4C 24 ?? 48 89 84 + 24 ?? ?? ?? ?? 48 8B 10 48 89 54 24 ?? 48 8B 70 ?? 48 89 74 24 ?? 48 8B 5C 24 ?? 48 + 8B 44 24 ?? E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 8B 44 + 24 ?? 48 8B 5C 24 ?? E8 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? + 48 89 DF 48 89 D3 48 89 C2 48 89 C8 48 89 D1 E8 ?? ?? ?? ?? 0F 1F 84 00 ?? ?? ?? ?? + 48 85 C0 0F 8D ?? ?? ?? ?? 48 8B 4C 24 ?? 48 FF C1 48 83 F9 ?? 0F 8C ?? ?? ?? ?? 48 + 8B 4C 24 ?? 48 89 8C 24 ?? ?? ?? ?? 48 8B 54 24 ?? 48 89 94 24 ?? ?? ?? ?? 48 8B 84 + 24 ?? ?? ?? ?? 48 8D 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 89 44 24 ?? + 48 89 5C 24 ?? 48 89 4C 24 ?? 66 90 E8 } - $enum_resources_p2 = { - 8D 4D ?? D1 F8 50 52 E8 ?? ?? ?? ?? 8B 7D ?? 8D 4D ?? 8B 75 ?? 83 FF ?? 8B 55 ?? 6A - ?? 68 ?? ?? ?? ?? 0F 43 CE 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? - 8B 7D ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 33 C0 8B 75 ?? 66 89 85 ?? ?? ?? ?? 83 CE ?? - 8B 47 ?? 83 C0 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 - 75 ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7F ?? - ?? 8B C7 72 ?? 8B 07 FF 77 ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 + $kill_procs_p1 = { + 4C 8D A4 24 ?? ?? ?? ?? 4D 3B 66 ?? 0F 86 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 89 AC + 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 90 E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 + 89 5C 24 ?? 31 C9 66 90 EB ?? 48 8B 54 24 ?? 48 8D 4A ?? 48 8B 84 24 ?? ?? ?? ?? 48 + 8B 5C 24 ?? 0F 1F 84 00 ?? ?? ?? ?? 48 39 CB 0F 8E ?? ?? ?? ?? 48 89 4C 24 ?? 48 C1 + E1 ?? 48 8B 1C 08 48 89 5C 24 ?? 48 8B 4C 08 ?? 48 89 4C 24 ?? 48 8B 73 ?? 48 89 C8 + FF D6 48 89 1D ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? 48 89 05 ?? ?? ?? ?? EB ?? 48 + 8D 3D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B 49 ?? 48 8B 44 24 ?? FF D1 48 + 89 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 8B + 3D ?? ?? ?? ?? 48 89 C3 48 8D 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 + 89 08 48 8D BC 24 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 48 A5 48 8D BC + 24 ?? ?? ?? ?? 48 8D 7F ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? E8 ?? ?? ?? ?? 48 8B 6D ?? + 48 8D 05 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + EB ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 48 8D 84 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 66 0F 1F 84 00 ?? ?? 00 00 48 85 C9 0F 84 ?? ?? ?? + ?? 48 8B 94 24 ?? ?? ?? ?? 48 8B 12 48 89 54 24 ?? 48 8B 01 48 89 44 24 ?? 48 8B 59 + ?? 48 89 5C 24 ?? 48 8D 8C 24 ?? ?? ?? ?? 31 F6 EB ?? 48 8B 94 24 ?? ?? ?? ?? 48 83 } - $enum_resources_p3 = { - 53 8B DC 83 EC ?? 83 E4 ?? 83 C4 ?? 55 8B 6B ?? 89 6C 24 ?? 8B EC 6A ?? 68 ?? ?? ?? - ?? 64 A1 ?? ?? ?? ?? 50 53 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 57 50 8D 45 ?? - 64 A3 ?? ?? ?? ?? 8B 43 ?? 8D 4D ?? 89 45 ?? 89 45 ?? 66 8B 43 ?? 6A ?? 68 ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? - 8D 4D ?? 8D 45 ?? 0F 43 45 ?? 51 50 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 7D ?? 8D 45 ?? - 8B 75 ?? 8D 4D ?? 8B 55 ?? 83 FF ?? 0F 43 45 ?? 0F 43 CA 8D 04 70 89 45 ?? 8D 45 ?? - 0F 43 45 ?? 8D 04 70 3B C8 74 ?? 66 83 39 ?? 74 ?? 83 C1 ?? 3B C8 75 ?? 3B C8 74 ?? - 8D 51 ?? 3B D0 74 + $kill_procs_p2 = { + C2 ?? 48 8B 44 24 ?? 48 8B 5C 24 ?? 48 89 CE 48 89 D1 48 89 74 24 ?? 48 89 8C 24 ?? + ?? ?? ?? 48 8B 11 48 89 54 24 ?? 48 8B 79 ?? 48 89 7C 24 ?? E8 ?? ?? ?? ?? 48 8B 4C + 24 ?? 48 8B 7C 24 ?? 90 E8 ?? ?? ?? ?? 48 85 C0 0F 8C ?? ?? ?? ?? 48 8B 44 24 ?? BB + ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 89 C7 48 89 DE 31 C0 48 8D 1D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 44 0F 11 39 48 8D 94 24 ?? ?? ?? ?? 44 0F + 11 3A 48 8D 15 ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? + ?? 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? BB ?? ?? ?? + ?? BF ?? ?? ?? ?? 48 89 FE E8 ?? ?? ?? ?? 48 89 44 24 ?? 44 0F 11 BC 24 ?? ?? ?? ?? + 48 8D 0D ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 1D ?? ?? + ?? ?? BF ?? ?? ?? ?? 48 89 FE 48 8D 05 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 48 8B 44 24 ?? 90 E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 FF C1 48 83 F9 ?? 0F 8C ?? + ?? ?? ?? E9 ?? ?? ?? ?? 0F 1F 40 ?? E8 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($enum_resources_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ( all of ($kill_procs_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Linux_Ransomware_Redalert : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Alcatraz : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects RedAlert ransomware." + description = "Yara rule that detects Alcatraz ransomware." author = "ReversingLabs" - id = "ec7567bf-2c39-529f-ae93-74270a161827" - date = "2022-09-01" - modified = "2022-09-01" + id = "7ff37483-ae63-5c82-a355-81ef68e2f663" + date = "2020-07-28" + modified = "2020-07-28" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Linux.Ransomware.RedAlert.yara#L1-L146" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "fe0d10c2ef1dacdb5374f319e470274b91f4f171db49de8c89e8aaa9aa75a45c" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Alcatraz.yara#L1-L91" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ddd35c8da0c08bce17cacfba8bb8a8b8a8c08c3e59261a88a79c63b03d29000f" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -33740,133 +35353,192 @@ rule REVERSINGLABS_Linux_Ransomware_Redalert : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "RedAlert" + tc_detection_name = "Alcatraz" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_p1 = { - 41 57 41 56 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 89 74 24 ?? BE ?? ?? ?? ?? 48 - 89 54 24 ?? 48 89 4C 24 ?? 4C 89 44 24 ?? E8 ?? ?? ?? ?? 48 85 C0 48 89 C5 75 ?? BF - ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 48 89 C7 E8 ?? ?? ?? ?? 83 F8 ?? 89 C3 75 ?? BF ?? - ?? ?? ?? E8 ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 31 C0 E9 ?? ?? ?? ?? 48 8D 54 24 ?? - 89 C6 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? FF C0 75 ?? BF ?? ?? ?? ?? EB ?? 4C 8B B4 24 ?? - ?? ?? ?? 4D 85 F6 7F ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 DF E8 ?? ?? ?? ?? EB ?? 49 - 81 FE ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 0F 97 44 24 ?? 49 81 FE ?? ?? ?? ?? 0F 97 - 44 24 ?? 80 7C 24 ?? ?? 74 ?? BA ?? ?? ?? ?? 4C 89 F0 C7 44 24 ?? ?? ?? ?? ?? 48 89 - D3 31 D2 48 F7 F3 48 6B C8 ?? 48 89 4C 24 ?? 49 81 FE ?? ?? ?? ?? 77 ?? 4D 89 F4 41 - BD ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 41 BC ?? ?? ?? ?? 45 31 ED C7 44 24 ?? - ?? ?? ?? ?? 4D 63 FD C7 44 24 ?? ?? ?? ?? ?? 4C 0F AF 7C 24 ?? E9 ?? ?? ?? ?? 80 7C - 24 ?? ?? 74 ?? 45 85 ED 74 ?? 80 7C 24 ?? ?? 74 ?? 41 8D 45 ?? 3B 44 24 ?? 4C 89 FE - 75 ?? 49 8D B6 ?? ?? ?? ?? EB ?? 31 F6 31 D2 48 89 EF E8 ?? ?? ?? ?? 48 63 7C 24 ?? - 48 89 E9 4C 89 E2 48 03 7C 24 ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 39 E0 74 ?? BF ?? - ?? ?? ?? EB ?? 44 01 64 24 ?? 41 FF C5 44 3B 6C 24 ?? 0F 85 ?? ?? ?? ?? 48 8D 9C 24 - ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 84 C0 74 ?? BF ?? - ?? ?? ?? EB ?? 48 8D BC 24 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 DE E8 ?? ?? ?? ?? 85 C0 - 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 63 6C 24 ?? 45 89 E7 44 89 64 24 ?? 4C 0F AF - 6C 24 ?? C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 8B 4C 24 ?? 41 B8 - ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 84 + $encrypt_files = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A + ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? 8B 4D ?? 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 83 C8 ?? E9 + ?? ?? ?? ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? + ?? ?? ?? ?? 75 ?? 83 C8 ?? E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 + BD ?? ?? ?? ?? ?? 75 ?? 83 C8 ?? E9 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8B 8D ?? + ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 8D ?? ?? + ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 + ?? 83 C8 ?? E9 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? + ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 0F B6 D0 85 D2 75 ?? 83 7D ?? ?? 74 ?? 6A + ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? EB ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? + 75 ?? 83 C8 ?? EB ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? + ?? 51 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? + 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } - $encrypt_files_p2 = { - C0 75 ?? 48 8B 54 24 ?? 48 8B 7C 24 ?? 48 89 E9 BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F B7 - 15 ?? ?? ?? ?? 48 39 D0 75 ?? 48 8B 44 24 ?? 48 89 E9 BE ?? ?? ?? ?? 0F B7 50 ?? 48 - 8B 38 E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 0F B7 51 ?? 48 39 D0 74 ?? BF ?? ?? ?? ?? E9 ?? - ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 4C 03 7C 24 ?? 44 3B 6C 24 ?? 0F 8C ?? ?? ?? ?? E9 - ?? ?? ?? ?? BF ?? ?? ?? ?? EB ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 80 7C - 24 ?? ?? 74 ?? 83 7C 24 ?? ?? 74 ?? 80 7C 24 ?? ?? 74 ?? 8B 44 24 ?? 4C 89 EE FF C0 - 3B 44 24 ?? 75 ?? 49 8D B6 ?? ?? ?? ?? EB ?? 31 F6 31 D2 48 89 EF E8 ?? ?? ?? ?? 48 - 63 44 24 ?? 48 8B 5C 24 ?? 48 8D B4 24 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? 31 C9 31 - D2 45 89 E1 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 01 C3 48 8D 84 24 ?? - ?? ?? ?? 49 89 D8 48 89 1C 24 48 89 44 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 48 89 E9 4C 89 E2 BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 39 E0 0F 85 ?? ?? ?? ?? - FF 44 24 ?? 8B 54 24 ?? 8B 4C 24 ?? 01 54 24 ?? 39 4C 24 ?? 75 ?? 31 F6 BA ?? ?? ?? - ?? 48 89 EF E8 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? 48 89 E9 BA ?? ?? ?? ?? BE ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8A 5C 24 ?? 48 83 F8 ?? B0 ?? 0F 44 D8 44 3B 7C 24 ?? 88 5C 24 - ?? 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 44 03 7C 24 ?? 4C 03 6C 24 ?? 8B 44 24 ?? 39 - 44 24 ?? 0F 8C ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 0F B6 44 24 ?? 48 81 C4 ?? ?? ?? - ?? 5B 5D 41 5C 41 5D 41 5E 41 5F C3 + $remote_server = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 6A ?? 6A ?? 68 ?? ?? ?? + ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 6A ?? 6A + ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D + ?? ?? 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 + ?? 83 7D ?? ?? 74 ?? 6A ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 + ?? 83 C8 ?? E9 ?? ?? ?? ?? 8B 4D ?? 83 C1 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 + 7D ?? ?? 75 ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 55 ?? 83 C2 ?? 52 6A ?? 8B 45 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 FF 15 + ?? ?? ?? ?? 85 C0 75 ?? 83 C8 ?? E9 ?? ?? ?? ?? EB ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B + 55 ?? 83 C2 ?? 89 55 ?? 8B 45 ?? 3B 45 ?? 73 ?? 8B 4D ?? 03 4D ?? 0F BE 11 83 FA ?? + 74 ?? 8B 45 ?? 03 45 ?? 0F BE 08 83 F9 ?? 74 ?? 8B 55 ?? 03 55 ?? 8B 45 ?? 03 45 ?? + 8A 08 88 0A EB ?? 8B 55 ?? 03 55 ?? C6 02 ?? EB ?? EB ?? EB ?? 83 7D ?? ?? 0F 87 ?? + ?? ?? ?? 83 7D ?? ?? 75 ?? 83 C8 ?? EB ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 FF 15 ?? ?? + ?? ?? 83 7D ?? ?? 74 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 55 ?? 52 + FF 15 ?? ?? ?? ?? 8B E5 5D C3 } - $find_files_p1 = { - 41 57 FC 41 56 41 55 41 54 49 89 FC 55 53 48 83 EC ?? 48 8B 84 24 ?? ?? ?? ?? 48 89 - 4C 24 ?? 48 83 C9 ?? 48 89 74 24 ?? 4C 89 44 24 ?? 4C 89 4C 24 ?? 88 54 24 ?? 48 89 - 44 24 ?? 48 8B 84 24 ?? ?? ?? ?? 44 8A BC 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 8B 84 24 - ?? ?? ?? ?? 48 89 44 24 ?? 48 8B 84 24 ?? ?? ?? ?? 48 89 44 24 ?? 31 C0 F2 AE 4C 89 - E7 48 F7 D1 4C 8D 71 ?? E8 ?? ?? ?? ?? 48 85 C0 48 89 44 24 ?? 0F 85 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 38 E8 ?? ?? ?? ?? 48 83 C4 ?? 4C 89 E6 48 89 C2 5B 5D 41 5C 41 5D 41 - 5E 41 5F BF ?? ?? ?? ?? 31 C0 E9 ?? ?? ?? ?? 45 84 FF 48 8D 6B ?? 74 ?? 0F B6 4B ?? - 48 89 EA 4C 89 E6 BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 80 7B ?? ?? 0F 85 ?? ?? ?? ?? - 80 7C 24 ?? ?? 0F 84 ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 85 C0 0F 84 - ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? BE ?? ?? - ?? ?? 48 89 EF E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FC 31 C0 48 83 C9 ?? 48 89 EF - F2 AE 4C 89 F0 48 29 C8 48 3B 44 24 ?? 76 ?? 48 8B 3D ?? ?? ?? ?? 48 89 E9 4C 89 E2 - BE ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4B 8D 1C 34 48 89 EE 48 8D 7B ?? - C6 03 ?? E8 ?? ?? ?? ?? 41 0F B6 C7 4C 8B 4C 24 ?? 4C 8B 44 24 ?? 89 44 24 ?? 48 8B - 44 24 ?? BA ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B 74 24 ?? 4C 89 E7 48 89 44 24 ?? 48 8B + $remote_server_2 = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? 89 45 ?? A1 ?? ?? ?? ?? 50 8B 0D ?? ?? ?? ?? 51 8B 15 ?? ?? ?? ?? 52 + A1 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 8B 0D ?? ?? ?? ?? 51 68 + ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? + 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 89 45 ?? 83 7D ?? ?? 74 ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? + ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 68 + ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? + ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? + 6A ?? 6A ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 6A ?? 8B 55 ?? + 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D + 45 ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 C0 E9 ?? ?? ?? ?? 8B 55 ?? 83 + C2 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 75 ?? C7 45 ?? ?? ?? ?? ?? 33 + C0 E9 ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 50 6A ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 + C0 EB ?? EB ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 68 ?? ?? ?? ?? 8B 4D ?? + 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 74 ?? B8 ?? ?? ?? ?? EB ?? 83 7D ?? ?? 0F 87 ?? + ?? ?? ?? 83 7D ?? ?? 75 ?? 83 C8 ?? EB ?? 83 7D ?? ?? 74 ?? 8B 55 ?? 52 FF 15 ?? ?? + ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 4D ?? 51 + FF 15 ?? ?? ?? ?? 8B E5 5D C3 } - $find_files_p2 = { - 44 24 ?? 48 89 44 24 ?? 48 8B 44 24 ?? 48 89 44 24 ?? 48 8B 44 24 ?? 48 89 04 24 E8 - ?? ?? ?? ?? E9 ?? ?? ?? ?? 45 84 FF 0F 85 ?? ?? ?? ?? FC 48 83 C9 ?? 48 89 EF 44 88 - F8 F2 AE 48 8B 54 24 ?? 48 89 EF 48 89 CB 48 8B 4C 24 ?? 48 F7 D3 48 89 DE 4C 8D 6B - ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 48 89 EA 4C 89 E6 BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? - E9 ?? ?? ?? ?? 4C 89 EA BE ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? 48 89 DE 48 89 EF E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 4B 8D 1C 34 48 89 EA 4C - 89 E6 BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 48 8D 7B ?? 48 89 EE C6 03 ?? E8 ?? ?? ?? - ?? 0F B7 0D ?? ?? ?? ?? 4C 89 E7 4C 8B 44 24 ?? 48 8B 54 24 ?? 48 8B 74 24 ?? FF 15 - ?? ?? ?? ?? 84 C0 BF ?? ?? ?? ?? 74 ?? 48 8B 7C 24 ?? B9 ?? ?? ?? ?? 4C 89 E2 BE ?? - ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 48 8B 74 24 ?? 4C 89 E7 E8 ?? ?? ?? ?? 85 C0 74 ?? BF - ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 41 8D 56 ?? - 4C 89 E6 E8 ?? ?? ?? ?? C6 03 ?? 48 8B 7C 24 ?? E8 ?? ?? ?? ?? 48 85 C0 48 89 C3 0F - 85 ?? ?? ?? ?? 48 8B 7C 24 ?? 48 83 C4 ?? 5B 5D 41 5C 41 5D 41 5E 41 5F E9 + + condition: + uint16(0)==0x5A4D and $encrypt_files and $remote_server and $remote_server_2 +} +rule REVERSINGLABS_Win32_Ransomware_Zoldon : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Zoldon ransomware." + author = "ReversingLabs" + id = "5d28e6f0-9d6b-54f4-81ed-aadb58352c80" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Zoldon.yara#L1-L107" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "4821b8506e7ba00987978f2744da1c532e03d73f3275cb15e39cdf87f6018223" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Zoldon" + tc_detection_factor = 5 + importance = 25 + + strings: + $main_encrypt_function_p1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? + ?? 89 8D ?? ?? ?? ?? 89 4D ?? 89 8D ?? ?? ?? ?? 89 4D ?? 89 4D ?? 89 55 ?? 89 45 ?? + 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 + 64 89 20 E8 ?? ?? ?? ?? DD 5D ?? 9B 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? FF 75 ?? FF + 75 ?? 8D 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? B2 ?? + A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? B1 ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? + 3C ?? 0F 85 ?? ?? ?? ?? B0 ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? + 84 C0 0F 85 ?? ?? ?? ?? 8B 4D ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? C6 + 80 ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 66 C7 45 } - $setup_environment = { - 55 48 89 E5 41 56 49 89 F6 BE ?? ?? ?? ?? 41 55 41 54 53 48 89 FB 48 83 EC ?? E8 ?? - ?? ?? ?? 48 85 C0 49 89 C4 75 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 7D ?? E8 ?? ?? - ?? ?? 84 C0 BF ?? ?? ?? ?? 74 ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 85 C0 49 - 89 C4 74 ?? 0F B7 55 ?? 48 8B 7D ?? 48 89 C1 BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F B7 55 - ?? 48 8B 7D ?? 4C 89 E1 BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F B7 55 ?? 31 C9 39 C2 0F 85 - ?? ?? ?? ?? E9 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? BF ?? ?? ?? - ?? 49 89 E5 E8 ?? ?? ?? ?? 66 8B 3D ?? ?? 22 00 66 03 3D ?? ?? 22 00 66 8B 05 ?? ?? - 22 00 66 89 7D ?? 0F B7 FF 66 89 45 ?? E8 ?? ?? ?? ?? 0F B7 7D ?? 48 89 45 ?? E8 ?? - ?? ?? ?? 0F B7 55 ?? 48 8B 7D ?? 4C 89 E1 BE ?? ?? ?? ?? 48 89 45 ?? E8 ?? ?? ?? ?? - 0F B7 55 ?? 48 8B 7D ?? 4C 89 E1 BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 75 ?? BF ?? ?? - ?? ?? 31 C0 E8 ?? ?? ?? ?? 0F B7 45 ?? 0F B7 35 ?? ?? ?? ?? 31 C9 48 8B 7D ?? 48 83 - C0 ?? 25 ?? ?? ?? ?? 48 29 C4 48 8D 5C 24 ?? 48 83 E3 ?? 48 89 DA E8 ?? ?? ?? ?? 48 - 89 DE BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 0F B7 3D ?? ?? ?? ?? BE ?? ?? ?? ?? 48 03 - 7D ?? E8 ?? ?? ?? ?? 66 39 05 ?? ?? 22 00 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 - EC 31 C9 EB ?? 4C 89 E7 E8 ?? ?? ?? ?? 48 8D 75 ?? B9 ?? ?? ?? ?? 4C 89 F7 FC F3 A5 - B1 ?? EB ?? 4C 89 EC EB ?? 48 8D 65 ?? 89 C8 5B 41 5C 41 5D 41 5E C9 C3 + $main_encrypt_function_p2 = { + 8D 85 ?? ?? ?? ?? 66 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 66 83 7D + ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 66 8B 55 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 66 FF 45 ?? 66 83 7D + ?? ?? 75 ?? 8B 4D ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 95 ?? ?? ?? ?? 33 C9 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 + 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? + E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 } - $make_configuration = { - 41 56 BE ?? ?? ?? ?? 49 89 FE BF ?? ?? ?? ?? 41 55 41 54 55 53 48 83 EC ?? E8 ?? ?? - ?? ?? 84 C0 88 C3 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 31 FF EB ?? BF ?? ?? ?? ?? E8 - ?? ?? ?? ?? BA ?? ?? ?? ?? 0F B7 F0 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 - ?? ?? ?? ?? B9 ?? ?? ?? ?? 49 89 C4 48 89 C2 BE ?? ?? ?? ?? BF ?? ?? ?? ?? 66 C7 00 - ?? ?? C6 40 ?? ?? E8 ?? ?? ?? ?? 4C 89 E6 BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 48 89 - E6 4C 89 E7 E8 ?? ?? ?? ?? 84 C0 75 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? - E8 ?? ?? ?? ?? FC 88 D8 BF ?? ?? ?? ?? 48 83 C9 ?? F2 AE 48 F7 D1 48 FF C9 8D 59 ?? - 83 C1 ?? 48 63 F9 E8 ?? ?? ?? ?? 48 85 C0 48 89 C5 0F 84 ?? ?? ?? ?? 48 8D 78 ?? 48 - 63 D3 BE ?? ?? ?? ?? C6 00 ?? E8 ?? ?? ?? ?? 48 89 EF BE ?? ?? ?? ?? E8 ?? ?? ?? ?? - 48 85 C0 48 89 C3 BF ?? ?? ?? ?? 74 ?? 0F B7 54 24 ?? 48 8B 7C 24 ?? 48 89 C1 BE ?? - ?? ?? ?? E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? BF ?? ?? ?? - ?? E8 ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? 4C 89 F7 48 89 E6 B9 ?? ?? ?? ?? FC F3 A5 - 48 83 C4 ?? 5B 5D 41 5C 41 5D 41 5E C3 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 + $write_zoldon_regkey = { + 55 8B EC 83 C4 ?? 53 56 33 DB 89 5D ?? 88 4D ?? 8B DA 8B F0 33 C0 55 68 ?? ?? ?? ?? + 64 FF 30 64 89 20 8D 45 ?? 8B D3 E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B D8 84 DB + 75 ?? 8D 45 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 89 45 ?? 80 7D ?? + ?? 74 ?? 83 7D ?? ?? 75 ?? 8D 45 ?? 50 8B 46 ?? 50 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 + 8B D3 8B C6 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D0 8B C6 E8 ?? ?? ?? ?? 88 45 ?? EB + ?? 8D 45 ?? 50 8D 45 ?? 50 6A ?? 8B 46 ?? 50 6A ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? + ?? 50 8B D3 8B C6 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D0 8B C6 E8 ?? ?? ?? ?? 88 45 + ?? 80 7D ?? ?? 74 ?? 83 7E ?? ?? 0F 95 C0 84 D8 74 ?? FF 76 ?? 68 ?? ?? ?? ?? FF 75 + ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? 33 + C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 + } + $find_files_p1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? + ?? 89 8D ?? ?? ?? ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 55 ?? + 89 45 ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? + 64 FF 30 64 89 20 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 + C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 F6 85 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 + ?? 80 B8 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 + 74 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? + ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 + 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 8B + } + $find_files_p2 = { + 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? E9 + ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? + ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? ?? ?? ?? E9 ?? ?? + ?? ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D + 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? + ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? + ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 74 ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D + 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? + ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? + ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 85 C0 0F 84 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 + ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8B E5 5D C3 } condition: - uint32(0)==0x464C457F and ($setup_environment) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($make_configuration) + uint16(0)==0x5A4D and ($write_zoldon_regkey) and ( all of ($find_files_p*)) and ( all of ($main_encrypt_function_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Winword64 : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Babuk : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects WinWord64 ransomware." + description = "Yara rule that detects Babuk ransomware." author = "ReversingLabs" - id = "a5f7967d-58f4-5fdd-b67f-5f5dbfec0f4b" - date = "2021-02-11" - modified = "2021-02-11" + id = "8a96f400-193f-5fd1-ba03-4da464345e1c" + date = "2021-01-26" + modified = "2021-01-26" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.WinWord64.yara#L1-L215" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "73d8c4f1b3bed365320b26332f1f1b49404d8e6536f3e25042f5f64e5bc09bd4" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Babuk.yara#L1-L117" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "70327b3f9d0b0505ade7ee6de6d7facf56820c7e8477bd172f738f374311144f" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -33874,201 +35546,108 @@ rule REVERSINGLABS_Win32_Ransomware_Winword64 : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "WinWord64" + tc_detection_name = "Babuk" tc_detection_factor = 5 importance = 25 strings: - $remote_connection_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? A1 ?? ?? ?? - ?? 33 DB 83 3D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 0F 43 0D ?? ?? ?? ?? - 03 C1 89 9D ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 43 0D ?? ?? ?? ?? 51 - 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 53 89 5D ?? 8D 85 ?? ?? ?? ?? 83 BD ?? ?? - ?? ?? ?? 53 0F 43 85 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? - 85 DB 0F 84 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? A1 ?? ?? ?? ?? 0F 43 0D - ?? ?? ?? ?? 03 C1 83 3D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 43 0D ?? ?? ?? ?? 51 50 51 - 8D 4D ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 6A ?? 0F 43 45 ?? 68 ?? ?? ?? ?? 50 53 - FF 15 ?? ?? ?? ?? 8B 55 ?? 8B D8 89 9D ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 - ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? - 76 ?? FF 15 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? 66 89 45 ?? 85 DB 0F 84 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? B9 ?? ?? - ?? ?? A1 ?? ?? ?? ?? 0F 43 0D ?? ?? ?? ?? 03 C1 83 3D ?? ?? ?? ?? ?? B9 + $find_files = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 50 8B + 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? + 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 95 ?? + ?? ?? ?? 83 C2 ?? 89 95 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 73 ?? 8B 85 ?? ?? ?? ?? 8B + 0C 85 ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? E9 ?? ?? ?? + ?? E9 ?? ?? ?? ?? EB ?? 8B 45 ?? 50 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? + 51 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 E2 ?? 74 ?? 83 7D ?? ?? 77 ?? 8B 45 ?? 83 + C0 ?? 50 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? EB ?? 8B 8D ?? ?? ?? ?? 83 E9 ?? 89 8D ?? ?? ?? ?? 83 BD ?? + ?? ?? ?? ?? 7C ?? 8B 95 ?? ?? ?? ?? 0F B7 84 55 ?? ?? ?? ?? 83 F8 ?? 75 ?? 68 ?? ?? + ?? ?? 8B 8D ?? ?? ?? ?? 8D 94 4D ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? EB ?? + EB ?? EB ?? EB ?? EB ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? + ?? 51 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 50 FF 15 } - $remote_connection_p2 = { - 0F 43 0D ?? ?? ?? ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D BD ?? - ?? ?? ?? 83 BD ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? A1 ?? ?? ?? ?? 0F 43 BD ?? ?? ?? ?? 83 - 3D ?? ?? ?? ?? ?? 0F 43 0D ?? ?? ?? ?? 03 C1 83 3D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F - 43 0D ?? ?? ?? ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 85 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 57 53 FF 15 ?? ?? ?? - ?? 8B 55 ?? 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? - 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 - E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 88 45 ?? 8B 95 ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? - ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 ?? - FF 15 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? C6 45 ?? ?? 8D 4D ?? 83 7D ?? ?? 8B 45 ?? 0F 43 4D ?? 03 C1 83 7D ?? ?? 8D 4D - ?? 0F 43 4D ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? - ?? 83 BD ?? ?? ?? ?? ?? 8D 4D ?? 68 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? B9 ?? ?? - ?? ?? 83 3D ?? ?? ?? ?? ?? 8B 75 ?? 8B C6 0F 43 0D ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B + $encrypt_files_p1 = { + 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A + ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD + ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 + ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 8C ?? ?? + ?? ?? 7F ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B + 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 52 50 E8 ?? ?? ?? + ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 0F 57 C0 66 0F 13 85 ?? ?? ?? ?? EB ?? 8B 8D + ?? ?? ?? ?? 83 C1 ?? 8B 95 ?? ?? ?? ?? 83 D2 ?? 89 8D ?? ?? ?? ?? 89 95 ?? ?? ?? ?? + 83 BD ?? ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 7C ?? 83 BD ?? ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 } - $remote_connection_p3 = { - 55 ?? 2B C2 57 51 3B F8 77 ?? 8D 04 3A 83 FE ?? 89 45 ?? 8D 45 ?? 0F 43 45 ?? 8D 34 - 10 56 E8 ?? ?? ?? ?? 83 C4 ?? C6 04 37 ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 - ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 75 ?? 8B C6 - 8B BD ?? ?? ?? ?? 0F 43 CF 8B 55 ?? 2B C2 8B 9D ?? ?? ?? ?? 53 51 3B D8 77 ?? 8D 04 - 1A 83 FE ?? 89 45 ?? 8D 45 ?? 0F 43 45 ?? 8D 34 10 56 E8 ?? ?? ?? ?? 83 C4 ?? C6 04 - 1E ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8B BD - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? B9 ?? ?? ?? ?? 83 3D ?? ?? - ?? ?? ?? 8B 75 ?? 8B C6 0F 43 0D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 55 ?? 2B C2 53 51 - 3B D8 77 ?? 8D 04 1A 83 FE ?? 89 45 ?? 8D 45 ?? 0F 43 45 ?? 8D 34 10 56 E8 ?? ?? ?? - ?? 83 C4 ?? C6 04 33 ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? 53 E8 - ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B 45 ?? 0F 43 - D3 8B 75 ?? 2B C6 8B 8D ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D 04 0E 89 45 ?? - 8D 45 ?? 0F 43 45 ?? 03 F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? C6 04 06 ?? - EB ?? C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 8B 9D ?? ?? - ?? ?? 83 3D ?? ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 8B - } - $remote_connection_p4 = { - 45 ?? 8B 75 ?? 2B C6 89 8D ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D 04 0E 89 45 - ?? 8D 45 ?? 0F 43 45 ?? 03 F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? C6 04 30 - ?? EB ?? C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 8B 95 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B D0 83 78 ?? ?? 72 ?? 8B 10 - 8B 48 ?? 8B 45 ?? 8B 75 ?? 2B C6 89 8D ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D - 04 0E 89 45 ?? 8D 45 ?? 0F 43 45 ?? 03 F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 - ?? C6 04 30 ?? EB ?? C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? - ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? - ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 ?? FF 15 ?? ?? ?? ?? 52 - 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? BA ?? ?? ?? ?? 83 3D - ?? ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 8B 45 ?? 8B 75 ?? 2B C6 89 8D - ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D 04 0E 89 45 ?? 8D 45 ?? 0F 43 45 ?? 03 - F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? C6 04 30 ?? EB ?? C6 85 ?? ?? ?? ?? - ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 55 ?? 8B 4D ?? 0F 43 - 55 ?? 8B 45 ?? 8B 75 ?? 2B C6 89 8D ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D 04 - 0E 89 45 ?? 8D 45 ?? 0F 43 45 ?? 03 F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? - C6 04 30 ?? EB ?? C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? - 83 3D ?? ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 8B 45 ?? - 8B 75 ?? 2B C6 89 8D ?? ?? ?? ?? 51 52 3B C8 77 ?? 83 7D ?? ?? 8D 04 31 89 45 ?? 8D - } - $remote_connection_p5 = { - 45 ?? 0F 43 45 ?? 03 F0 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? C6 04 30 ?? EB - ?? C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? - ?? 85 F6 74 ?? 8B 45 ?? 8D 4D ?? 83 7D ?? ?? 6A ?? 0F 43 4D ?? 50 50 51 6A ?? FF B5 - ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 8D ?? - ?? ?? ?? 51 68 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 F6 8B 35 ?? - ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 50 FF D6 8B 85 ?? ?? ?? ?? 85 C0 74 ?? 50 FF D6 8B - 85 ?? ?? ?? ?? 85 C0 74 ?? 50 FF D6 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA - ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 - E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - C6 45 ?? ?? 83 F8 ?? 72 ?? 8D 48 ?? 8B C3 81 F9 ?? ?? ?? ?? 72 ?? 8B 5B ?? 83 C1 ?? - 2B C3 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 51 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? - ?? ?? 83 F8 ?? 72 ?? 8D 48 ?? 8B C7 81 F9 ?? ?? ?? ?? 72 ?? 8B 7F ?? 83 C1 ?? 2B C7 - } - $remote_connection_p6 = { - 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 51 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? - 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 - F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 - ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? - 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 4D ?? - 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 - 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? - ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 ?? FF 15 ?? ?? ?? ?? 52 - 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD - E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $encrypt_files_p1 = { - FF 15 ?? ?? ?? ?? 83 7D ?? ?? 8D 55 ?? 8B 4D ?? 0F 43 55 ?? 03 CA 89 85 ?? ?? ?? ?? - 83 7D ?? ?? 8D 45 ?? 51 0F 43 45 ?? 51 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 83 - 7F ?? ?? 72 ?? 8B 3F 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? - ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 - ?? FF 15 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? 83 7D ?? ?? 8D 4D ?? 66 89 85 ?? ?? ?? ?? 0F 43 4D ?? 8B 45 ?? 03 C1 C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 0F 43 4D ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B F0 83 7E ?? ?? 72 ?? 8B 36 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? - ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 - C0 ?? 83 F8 ?? 76 ?? FF 15 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 50 6A ?? 68 ?? ?? ?? ?? 57 8B 3D ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? FF D7 89 85 ?? ?? ?? ?? 83 - F8 ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 56 FF - D7 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C9 BA - } - $encrypt_files_p2 = { - 8D 40 ?? F7 E2 0F 90 C1 F7 D9 0B C8 51 E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? BA ?? ?? - ?? ?? 8B 0D ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 03 CA 89 85 ?? ?? ?? ?? 83 3D ?? ?? ?? - ?? ?? B8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 0F 43 05 ?? ?? ?? ?? 51 50 8B CE E8 ?? ?? ?? - ?? A1 ?? ?? ?? ?? 83 C4 ?? 33 C9 68 ?? ?? ?? ?? 6A ?? 56 66 89 0C 46 8D 85 ?? ?? ?? - ?? 51 50 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? FF B5 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 - 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? - ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 - C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 0F 82 ?? ?? ?? ?? 8B 4D ?? 42 - 8B C1 81 FA ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? - 0F 86 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? - FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? - 8D 45 ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? E9 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? - 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 FF 33 F6 57 FF B5 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 57 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 + $encrypt_files_p2 = { + E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 68 + ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? + 51 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 52 + FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 8C ?? ?? ?? + ?? 7F ?? 83 BD ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 + ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? + ?? ?? 74 ?? 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 68 ?? ?? + ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? + ?? ?? 50 8B 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 } $encrypt_files_p3 = { - 8B 85 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 03 F8 8D 85 ?? ?? ?? ?? 3B - BD ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 0F 44 F1 50 6A ?? 56 6A ?? FF B5 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 - FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 - ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? - ?? 6A ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - B9 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? - ?? 8B 35 ?? ?? ?? ?? FF D6 FF B5 ?? ?? ?? ?? FF D6 C6 85 ?? ?? ?? ?? ?? E9 ?? ?? ?? - ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8A 85 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 - 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + C4 ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 68 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 8B 45 + ?? 50 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF + 15 ?? ?? ?? ?? 6A ?? 8B 85 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? + ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? 6A ?? 6A ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 51 6A ?? 8D 95 ?? ?? ?? + ?? 52 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 8D 45 ?? 50 6A + ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? + ?? ?? 52 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? EB ?? 8B 8D ?? ?? ?? ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? + 3B 95 ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 69 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 BC 05 ?? ?? ?? + ?? ?? 0F 84 ?? ?? ?? ?? 69 8D ?? ?? ?? ?? ?? ?? ?? ?? 81 BC 0D ?? ?? ?? ?? ?? ?? ?? + ?? 74 ?? FF 15 ?? ?? ?? ?? 69 95 ?? ?? ?? ?? ?? ?? ?? ?? 3B 84 15 ?? ?? ?? ?? 74 ?? + 69 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 8C 05 ?? ?? ?? ?? 51 6A ?? 68 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 FF + 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 8D ?? ?? ?? + ?? 51 FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } - $find_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F9 89 BD ?? ?? ?? ?? 33 C0 89 - 85 ?? ?? ?? ?? 38 47 ?? 0F 85 ?? ?? ?? ?? 8B 07 8B 08 8D 85 ?? ?? ?? ?? 50 8D 49 ?? - E8 ?? ?? ?? ?? 83 38 ?? 0F 85 ?? ?? ?? ?? 83 7F ?? ?? 74 ?? 8B 07 8B 08 8D 85 ?? ?? - ?? ?? 50 8D 49 ?? E8 ?? ?? ?? ?? 83 38 ?? 0F 84 ?? ?? ?? ?? 8B 07 8D 8D ?? ?? ?? ?? - 8B 30 8D 46 ?? 50 E8 ?? ?? ?? ?? 8D 46 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? B8 ?? ?? ?? - ?? 8B 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? - ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 76 - ?? FF 15 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 07 8B - 30 8B 46 ?? 8B 00 85 C0 74 ?? 8D 8D ?? ?? ?? ?? 51 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 83 C4 ?? 66 83 38 ?? 75 ?? 8B 46 ?? FF 30 FF 15 ?? ?? ?? ?? 8B 46 ?? 83 C4 - ?? C7 00 ?? ?? ?? ?? EB ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D - 4E ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? C6 45 ?? ?? 81 7F ?? ?? ?? ?? ?? 8B 37 8B 36 75 ?? 68 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 8B 46 ?? 89 85 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? C6 45 ?? ?? 6A ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 8D 85 ?? ?? ?? ?? 8D 4F ?? 50 E8 + $enum_resources = { + 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? 8D 45 ?? 50 8B 4D ?? 51 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D 45 + ?? 50 8B 4D ?? 51 8D 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 75 ?? C7 45 ?? ?? ?? + ?? ?? EB ?? 8B 4D ?? 83 C1 ?? 89 4D ?? 8B 55 ?? 3B 55 ?? 73 ?? 8B 45 ?? C1 E0 ?? 8B + 4D ?? 8B 54 01 ?? 83 E2 ?? 74 ?? 8B 45 ?? C1 E0 ?? 03 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? EB ?? 6A ?? 8B 4D ?? C1 E1 ?? 8B 55 ?? 8B 44 0A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB + ?? EB ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 4D ?? 33 + CD E8 ?? ?? ?? ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($enum_resources) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Dusk : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Buran : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Dusk ransomware." + description = "Yara rule that detects Buran ransomware." author = "ReversingLabs" - id = "cde30f40-f13c-53da-8656-cc293433aa36" - date = "2021-08-12" - modified = "2021-08-12" + id = "c2a36a8b-5c21-5c31-994d-b424c038dd21" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Dusk.yara#L1-L73" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "b6b0b3be7c17115dc5f225a13228f8a4811d84ae095c3ceba2d89f569f2d40c7" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Buran.yara#L1-L91" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "5606e0acecd99ccf2feaa995353211302903a09bb2c4ec65903566215e2d5ca4" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -34076,66 +35655,83 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Dusk : TC_DETECTION MALICIOUS MALWAR sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Dusk" + tc_detection_name = "Buran" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_p1 = { - 03 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 06 6F ?? ?? ?? ?? - 0A 06 28 ?? ?? ?? ?? 0B 03 07 28 ?? ?? ?? ?? 03 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? - ?? ?? ?? DE ?? 26 DE ?? 2A + $find_files = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D + ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? + 89 5D ?? 89 5D ?? 88 8D ?? ?? ?? ?? 88 95 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? E8 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF + 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? + ?? 8B 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 33 + C0 5A 59 59 64 89 10 E9 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? + 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 + C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 + 74 ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 33 C9 8B 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5A 59 59 + 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 } - $encrypt_files_p2 = { - 14 0A 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? 0C 73 ?? ?? - ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 03 07 20 ?? - ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? - ?? ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 17 6F ?? ?? ?? - ?? 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 11 ?? 02 16 02 8E 69 6F ?? ?? ?? ?? 11 - ?? 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 08 6F ?? ?? ?? ?? 0A DE ?? - 09 2C ?? 09 6F ?? ?? ?? ?? DC 08 2C ?? 08 6F ?? ?? ?? ?? DC 06 2A + $encrypt_files = { + 53 56 57 55 BB ?? ?? ?? ?? BF ?? ?? ?? ?? 80 7B ?? ?? 75 ?? 83 3F ?? 74 ?? 8B 07 89 + C6 33 C0 89 07 FF D6 83 3F ?? 75 ?? 83 3D ?? ?? ?? ?? ?? 74 ?? E8 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 33 C0 A3 ?? ?? ?? ?? 80 7B ?? ?? 75 ?? 83 3D ?? ?? ?? ?? ?? 75 ?? 33 C0 89 + 43 ?? E8 ?? ?? ?? ?? 80 7B ?? ?? 76 ?? 83 3D ?? ?? ?? ?? ?? 74 ?? 8B 7B ?? 85 FF 74 + ?? 8B C7 E8 ?? ?? ?? ?? 8B 6B ?? 8B 75 ?? 3B 75 ?? 74 ?? 85 F6 74 ?? 56 E8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 80 7B ?? ?? 75 ?? FF 53 ?? 80 7B ?? ?? 74 ?? E8 ?? ?? ?? ?? 83 3B + ?? 75 ?? 83 3D ?? ?? ?? ?? ?? 74 ?? FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 8B 03 8B F0 8B FB B9 ?? ?? ?? ?? F3 A5 E9 ?? ?? ?? ?? 5D 5F 5E 5B C3 A3 } - $dusk_delete_itself = { - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 1A 8D ?? ?? ?? ?? 25 16 - 72 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? 03 28 ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 25 19 72 ?? ?? ?? ?? A2 0B 06 07 28 ?? ?? ?? - ?? 06 06 28 ?? ?? ?? ?? 18 60 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 06 73 ?? ?? - ?? ?? 25 17 6F ?? ?? ?? ?? 25 16 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 04 28 ?? ?? ?? ?? 28 - ?? ?? ?? ?? DE ?? 26 DE ?? 2A + $remote_connection_p1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 50 83 C4 ?? 53 56 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? + ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 5D ?? 8B D9 89 55 ?? 89 + 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF + 30 64 89 20 8B C3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 89 45 + ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 BE ?? ?? + ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? + ?? 0F 84 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? B8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 6A ?? 56 6A ?? 6A ?? 6A ?? 8B 45 ?? E8 } - $find_files = { - 20 ?? ?? ?? ?? 72 ?? ?? ?? ?? A2 25 20 ?? ?? ?? ?? 72 ?? ?? ?? ?? A2 25 20 ?? ?? ?? ?? - 72 ?? ?? ?? ?? A2 0A 1F ?? 8D ?? ?? ?? ?? 25 16 1F ?? 28 ?? ?? ?? ?? A2 25 17 1E 28 ?? - ?? ?? ?? A2 25 18 1F ?? 28 ?? ?? ?? ?? A2 25 19 1F ?? 28 ?? ?? ?? ?? A2 25 1A 1F ?? 28 - ?? ?? ?? ?? A2 25 1B 1B 28 ?? ?? ?? ?? A2 25 1C 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? A2 25 1D 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? - ?? A2 25 1E 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 25 1F ?? 72 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 0B 16 0C 2B ?? 07 08 9A 0D - 1F ?? 28 ?? ?? ?? ?? 13 ?? 09 72 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 - ?? 11 ?? 9A 28 ?? ?? ?? ?? 13 ?? 06 11 ?? 28 ?? ?? ?? ?? 2C ?? 02 11 ?? 11 ?? 9A 11 ?? - 28 ?? ?? ?? ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? 00 02 09 28 ?? ?? ?? ?? DE ?? - 26 DE ?? 08 17 58 0C 08 07 8E 69 32 ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 26 DE ?? 26 DE ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 20 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 2A + $remote_connection_p2 = { + 50 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 + ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C9 B2 ?? A1 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 95 ?? ?? ?? ?? B8 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? + ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 75 ?? 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? + E8 ?? ?? ?? ?? 8B 45 ?? 8B 70 ?? 85 F6 74 ?? 83 EE ?? 8B 36 68 ?? ?? ?? ?? 56 8B 45 + ?? 8B 40 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B + 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 EB ?? 83 7D ?? ?? 74 ?? 8D 95 ?? + ?? ?? ?? 8B 4D ?? 8B 45 ?? 8B 30 FF 56 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 75 ?? C6 85 ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? + B9 ?? ?? ?? ?? 8B 45 ?? 8B 30 FF 56 ?? 8B C3 8B 55 ?? 8B 52 ?? E8 ?? ?? ?? ?? 33 C0 + 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C3 E9 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($dusk_delete_itself) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Oct : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Wasplocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Oct ransomware." + description = "Yara rule that detects WaspLocker ransomware." author = "ReversingLabs" - id = "e811a0ba-52df-5e88-ab71-df91d5cb584a" - date = "2024-10-04" - date = "2024-10-04" - modified = "2021-08-12" + id = "596bf965-700a-58f5-b0e5-61ec57c23a3e" + date = "2022-06-28" + modified = "2022-06-28" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Oct.yara#L1-L68" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3973794d6bf26eaa752cfc70a217c059a190c63a0dd92b06de7c0893d92d9e88" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.WaspLocker.yara#L1-L76" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "852ec52328fca36d651e3176ac33a57ce26cefecadc2aad27235548e5b9813c1" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -34143,62 +35739,69 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Oct : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" + tc_detection_name = "WaspLocker" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files = { - 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 03 0B 07 18 73 ?? ?? ?? ?? 0C 73 - ?? ?? ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 04 06 - 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F - ?? ?? ?? ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 19 6F ?? - ?? ?? ?? 09 17 6F ?? ?? ?? ?? 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 02 19 73 ?? - ?? ?? ?? 13 ?? 2B ?? 11 ?? 11 ?? D2 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 25 13 ?? 15 33 - ?? 11 ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 02 28 ?? ?? ?? ?? DE ?? - 13 ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 2A - } $find_files = { - 16 0A 38 ?? ?? ?? ?? 16 0B 2B ?? 02 06 9A 28 ?? ?? ?? ?? 2C ?? 02 06 9A 73 ?? ?? ?? ?? - 0C 08 72 ?? ?? ?? ?? 03 07 9A 28 ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 0D 09 13 ?? 16 13 ?? 2B - ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 05 28 ?? ?? ?? ?? 1E - 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 17 58 13 ?? 11 ?? - 11 ?? 8E 69 32 ?? 07 17 58 0B 07 03 8E 69 32 ?? 06 17 58 0A 06 02 8E 69 3F ?? ?? ?? ?? - 2A + 50 50 8D 8D ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? 51 50 50 50 56 FF 15 ?? ?? ?? ?? 85 C0 + 75 ?? 57 53 E8 ?? ?? ?? ?? 8D 4E ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + A8 ?? 75 ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? A8 ?? 0F 85 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 85 C0 74 ?? 3B 85 ?? ?? ?? ?? 76 ?? 8D 85 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 2B 95 ?? ?? ?? ?? 59 03 C2 B9 ?? ?? ?? ?? 3B C1 + 7D ?? 8D 85 ?? ?? ?? ?? 2B CA 50 51 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 + 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 75 ?? EB ?? 85 DB 0F 84 + ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? 85 FF 75 ?? 33 C0 EB ?? 57 E8 ?? ?? ?? ?? 59 50 57 + 8D 4B ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 4E ?? E8 ?? ?? ?? ?? 33 C0 40 E8 ?? ?? ?? + ?? C2 ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? CC 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 + F6 89 75 ?? 33 FF 89 7D ?? 21 75 ?? 21 75 ?? 39 3D ?? ?? ?? ?? 75 ?? 8D 45 ?? 50 E8 + ?? ?? ?? ?? 8B F8 89 7D ?? 85 FF 74 ?? FF 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B F0 89 75 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? C2 } - $collect_env_and_start_enc_proc = { - 19 8D ?? ?? ?? ?? 0B 07 16 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 07 17 1B - 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 07 18 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? - ?? 28 ?? ?? ?? ?? A2 07 1F ?? 8D ?? ?? ?? ?? 0C 08 16 72 ?? ?? ?? ?? A2 08 17 72 ?? ?? - ?? ?? A2 08 18 72 ?? ?? ?? ?? A2 08 19 72 ?? ?? ?? ?? A2 08 1A 72 ?? ?? ?? ?? A2 08 1B - 72 ?? ?? ?? ?? A2 08 1C 72 ?? ?? ?? ?? A2 08 1D 72 ?? ?? ?? ?? A2 08 1E 72 ?? ?? ?? ?? - A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 - 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? - 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? - ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? - ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 72 ?? ?? ?? ?? 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0A - 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? DC 72 ?? ?? ?? ?? 16 - 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 72 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 2A + $drop_aux_files = { + A1 ?? ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 68 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 6A ?? 66 89 41 ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 56 6A ?? FF 15 ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? 85 C0 74 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 50 FF 15 + ?? ?? ?? ?? 8B F8 85 FF 74 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B + F0 83 C4 ?? 85 F6 74 ?? 56 FF B5 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? 6A ?? 6A ?? 56 + E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 + ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? + ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? + ?? ?? 56 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 6A ?? 56 FF 15 ?? ?? + ?? ?? 50 89 85 ?? ?? ?? ?? E8 + } + $drop_ransom_notes = { + 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 84 C0 + 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E8 + ?? ?? ?? ?? 8B C8 85 C9 0F 84 ?? ?? ?? ?? 8B 01 8B 40 ?? FF D0 83 C0 ?? 89 85 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 8B C8 85 C9 0F 84 ?? ?? ?? ?? 8B 01 8B 40 ?? FF D0 83 C0 ?? 89 85 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 84 C0 75 ?? B9 ?? ?? ?? ?? 8D + 51 ?? 90 8A 01 41 84 C0 75 ?? 2B CA 51 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B C8 85 C9 0F 84 ?? ?? ?? ?? 8B 01 8B 40 ?? FF D0 83 + C0 ?? 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 84 C0 75 } condition: - uint16(0)==0x5A4D and ($collect_env_and_start_enc_proc) and ($find_files) and ($encrypt_files) + uint16(0)==0x5A4D and ($find_files) and ($drop_aux_files) and ($drop_ransom_notes) } -import "pe" - -rule REVERSINGLABS_Win32_Ransomware_Wannacry : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_PXJ : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects WannaCry ransomware." + description = "Yara rule that detects PXJ ransomware." author = "ReversingLabs" - id = "61734d47-2525-5e3a-94b4-60493dfe2b93" + id = "c1549905-5b31-55c0-a275-0ab8133b3504" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.WannaCry.yara#L3-L135" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "fed58b533a9f7c3eb1b3e4f8fbe1f519aab94d1c066ae6937c21876693be0eac" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.PXJ.yara#L1-L158" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "e88d27dcd7ad3af459bd7e34fcc827822365441446b0e4e7bbec399c9a948cb7" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -34206,125 +35809,147 @@ rule REVERSINGLABS_Win32_Ransomware_Wannacry : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "WannaCry" + tc_detection_name = "PXJ" tc_detection_factor = 5 importance = 25 strings: - $main_1 = { - A0 ?? ?? ?? ?? 56 57 6A ?? 88 85 ?? ?? ?? ?? 59 33 C0 8D BD ?? ?? ?? ?? F3 AB 66 AB - AA 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 6A ?? 50 FF D6 59 85 C0 59 74 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF D6 59 88 - 18 59 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 59 - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 53 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5F 5E 85 - C0 74 ?? 8D 45 ?? 8D 8D ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 89 5D - } - $main_2 = { - 68 ?? ?? ?? ?? 33 DB 50 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF 15 - ?? ?? ?? ?? 83 38 ?? 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 00 FF 70 ?? E8 ?? ?? - ?? ?? 59 85 C0 59 75 ?? 53 E8 ?? ?? ?? ?? 85 C0 59 74 ?? BE ?? ?? ?? ?? 53 8D 85 ?? - ?? ?? ?? 56 50 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? E8 ?? ?? ?? ?? - 85 C0 0F 85 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF D6 59 85 C0 - 59 74 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF D6 59 88 18 59 8D 85 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 53 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 53 68 ?? ?? ?? ?? E8 - } - $main_3 = { - 83 EC ?? 56 57 B9 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 7C 24 ?? 33 C0 F3 A5 A4 89 44 24 ?? - 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 66 89 44 24 ?? 50 50 50 6A ?? 50 88 - 44 24 ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 4C 24 ?? 8B F0 6A ?? 51 56 - FF 15 ?? ?? ?? ?? 8B F8 56 8B 35 ?? ?? ?? ?? 85 FF 75 ?? FF D6 6A ?? FF D6 E8 - } - $start_service_3 = { - 83 EC ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 - 38 ?? 7D ?? E8 ?? ?? ?? ?? 83 C4 ?? C3 57 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? - ?? 8B F8 85 FF 74 ?? 53 56 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B 1D - ?? ?? ?? ?? 8B F0 85 F6 74 ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 56 FF D3 57 FF D3 5E - 5B 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 5F 83 C4 ?? C3 - } - $main_4 = { - 83 EC ?? 57 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 85 FF 74 ?? 53 56 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B F0 85 F6 74 ?? - 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 56 FF D3 57 FF D3 5E 5B 8D 44 24 ?? C7 44 24 ?? ?? - ?? ?? ?? 50 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 33 C0 5F 83 C4 ?? C2 - } - $main_5 = { - 68 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 - FF D6 59 85 C0 59 74 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF D6 59 88 18 59 8D 85 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 53 53 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5F 5E 85 C0 74 ?? 8D 45 ?? 8D - 8D ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 89 5D ?? E8 ?? ?? ?? ?? 3B C3 74 ?? FF 75 ?? 50 E8 - ?? ?? ?? ?? 59 3B C3 59 74 ?? 68 ?? ?? ?? ?? 50 E8 + $find_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 8B D9 68 ?? ?? ?? ?? + 33 F6 8D 8D ?? ?? ?? ?? 33 C0 56 51 89 9D ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? 53 8D 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? + ?? 51 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? + ?? ?? 8A 85 ?? ?? ?? ?? A8 ?? 0F 85 ?? ?? ?? ?? A8 ?? 0F 84 ?? ?? ?? ?? 53 8D 85 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? E9 ?? ?? + ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? 66 8B + 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? + 3B C6 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 } - $main_6 = { - FF 74 24 ?? FF 74 24 ?? FF 74 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? C2 + $find_files_p2 = { + 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 C0 EB + ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 9F ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B FF + 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 + ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 8B FF 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 + ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? + ?? ?? ?? 53 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? + ?? ?? 52 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8B D1 83 C4 ?? 0B D0 89 B5 ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? 74 ?? 50 51 8D + 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 3A C1 75 ?? 01 8F ?? ?? ?? ?? 11 + B7 ?? ?? ?? ?? EB ?? 01 8F ?? ?? ?? ?? 11 B7 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? 51 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 8B 4D ?? 5E 33 CD B0 ?? 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } - $set_reg_key_6 = { - 68 ?? ?? ?? ?? F3 AB 66 AB AA 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 8B 2D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 83 C4 ?? 33 FF 89 7C 24 ?? 85 FF 75 ?? 8D 4C - 24 ?? 8D 54 24 ?? 51 52 68 ?? ?? ?? ?? EB ?? 8D 44 24 ?? 8D 4C 24 ?? 50 51 68 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 85 - C9 74 ?? 8D 94 24 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? FF D5 8D BC 24 ?? ?? ?? ?? 83 C9 ?? - 33 C0 F2 AE F7 D1 8D 84 24 ?? ?? ?? ?? 51 8B 4C 24 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? - 51 FF D3 8B 7C 24 ?? 8B F0 F7 DE 1B F6 46 EB ?? 8D 54 24 ?? 8D 8C 24 ?? ?? ?? ?? 52 - 51 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 C7 44 24 ?? ?? ?? ?? ?? FF 15 + $encrypt_files_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 + ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 45 ?? 6A ?? 68 + ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 89 85 ?? ?? ?? ?? 8B 45 ?? 68 ?? ?? ?? ?? 50 89 85 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 4D + ?? 8B 55 ?? 51 52 E8 ?? ?? ?? ?? 0B C2 74 ?? 53 FF 15 ?? ?? ?? ?? B0 ?? E9 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 33 DB 8D 85 ?? ?? ?? ?? 53 50 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 53 51 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 33 F6 6A ?? 53 E8 ?? ?? ?? ?? 88 44 35 ?? + 46 83 FE ?? 7C ?? 8D 55 ?? 52 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? B8 ?? + ?? ?? ?? 8D B5 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B CE 89 5D ?? E8 ?? ?? ?? ?? 81 EC ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B F4 89 A5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? 6A ?? 51 } - $download_tor_6 = { - 81 EC ?? ?? ?? ?? 53 55 56 57 E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? A0 ?? ?? ?? ?? - B9 ?? ?? ?? ?? 88 44 24 ?? 33 C0 8D 7C 24 ?? 8B 35 ?? ?? ?? ?? F3 AB 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 66 AB 68 ?? ?? ?? ?? 8D 4C 24 ?? 33 ED 68 ?? ?? ?? ?? 51 89 2D ?? ?? - ?? ?? 89 2D ?? ?? ?? ?? AA FF D6 8B 1D ?? ?? ?? ?? 83 C4 ?? 8D 54 24 ?? 52 FF D3 83 - F8 ?? 0F 85 ?? ?? ?? ?? 55 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 - C0 75 ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 A0 ?? ?? ?? ?? B9 ?? ?? ?? ?? 88 84 24 ?? - ?? ?? ?? 33 C0 8D BC 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? F3 AB 66 AB 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 AA FF D6 83 C4 ?? 8D 94 24 ?? ?? ?? - ?? 52 FF D3 83 F8 ?? 75 ?? 5F 5E 5D 32 C0 5B 81 C4 ?? ?? ?? ?? C3 + $encrypt_files_p2 = { + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 72 ?? 8B 95 + ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B B5 ?? ?? ?? ?? 53 53 33 C9 51 33 C0 50 56 + FF 15 ?? ?? ?? ?? 85 C0 75 ?? 56 FF 15 ?? ?? ?? ?? 32 C0 E9 ?? ?? ?? ?? 53 8D 85 ?? + ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 56 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? + ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? + 8B 3D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B C3 0F 84 ?? ?? ?? ?? 6A ?? F7 D8 99 53 52 50 + 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 + 8D 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 8D 8D ?? ?? ?? ?? 51 50 8D + 95 ?? ?? ?? ?? 52 56 FF D7 85 C0 0F 84 ?? ?? ?? ?? 39 9D ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 39 9D ?? ?? ?? ?? 77 ?? 81 BD ?? + ?? ?? ?? ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 11 9D ?? ?? ?? ?? 8B 9D + ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 33 D2 52 52 52 33 C9 51 50 + FF 15 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B C6 8D } - $main_7 = { - 68 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 - FF D6 59 85 C0 59 74 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF D6 59 88 18 59 8D 85 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 53 53 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5F 5E 85 C0 74 ?? 8D 45 ?? 8D - 8D ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 53 8F 45 ?? E8 ?? ?? ?? ?? 39 44 24 ?? 74 ?? 89 44 - 24 ?? 83 EC ?? 2B C3 58 74 ?? FF 75 ?? 50 E8 ?? ?? ?? ?? 59 89 44 24 ?? 83 EC ?? 2B - C3 58 59 74 ?? 68 ?? ?? ?? ?? 50 E8 + $encrypt_files_p3 = { + 48 ?? 8B FF 66 8B 10 83 C0 ?? 66 85 D2 75 ?? 2B C1 6A ?? D1 F8 8D 8D ?? ?? ?? ?? 51 + 8D 14 00 8B 83 ?? ?? ?? ?? 52 56 50 FF D7 8B 93 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? + 51 6A ?? 68 ?? ?? ?? ?? 52 FF D7 8B 93 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? + 8D 4D ?? 51 52 FF D7 8B 8B ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? + ?? 51 FF D7 8B 8B ?? ?? ?? ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 6A ?? 8D 85 ?? ?? ?? ?? 50 + 51 FF D7 8B B5 ?? ?? ?? ?? 6A ?? 33 C9 51 51 B8 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? + 85 C0 74 ?? 33 DB EB ?? 83 85 ?? ?? ?? ?? ?? 11 9D ?? ?? ?? ?? 53 8D 95 ?? ?? ?? ?? + 52 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? + ?? 8B 9D ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 51 52 8D BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B 95 + ?? ?? ?? ?? 83 C4 ?? 52 FF 15 ?? ?? ?? ?? 33 C9 51 51 33 C0 51 50 8B 83 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 8B 8B ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 56 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 94 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B + 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 } - $main_8 = { - 68 ?? ?? ?? ?? F3 AB 66 AB AA 8D 44 24 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? - ?? 8D 4C 24 ?? 6A ?? 51 FF D6 83 C4 ?? 85 C0 74 ?? 8D 54 24 ?? 6A ?? 52 FF D6 83 C4 - ?? C6 00 ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 5F - 5E 85 C0 74 ?? 8D 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 54 24 ?? 52 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 - ?? 68 ?? ?? ?? ?? 50 E8 + $delete_volumes_snapshots_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 45 ?? 6A ?? 33 FF 57 57 89 + 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? FF D6 57 68 ?? + ?? ?? ?? FF D6 57 68 ?? ?? ?? ?? FF D6 57 68 ?? ?? ?? ?? FF D6 57 68 ?? ?? ?? ?? FF + D6 57 57 8D 8D ?? ?? ?? ?? 51 57 89 BD ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 57 68 ?? ?? ?? ?? + 6A ?? 57 57 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F + 84 ?? ?? ?? ?? 83 EC ?? 8B F4 89 7E ?? C7 46 ?? ?? ?? ?? ?? BF ?? ?? ?? ?? B8 ?? ?? + ?? ?? 89 A5 ?? ?? ?? ?? C6 06 ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 33 FF 89 7D ?? 83 78 ?? ?? 72 ?? 8B 00 8D 50 ?? 8D 9B ?? ?? ?? ?? 8A 08 40 84 + C9 75 ?? 2B C2 57 8D 95 ?? ?? ?? ?? 52 50 83 EC ?? 8B F4 89 7E ?? C7 46 ?? ?? ?? ?? + ?? BF ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 A5 ?? ?? ?? ?? 88 0E E8 ?? ?? ?? ?? 8D B5 ?? ?? + ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 83 C4 ?? 39 70 ?? 72 ?? 8B 00 50 53 FF 15 ?? ?? + ?? ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? + ?? ?? ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 53 FF + 15 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B C7 8B FF 66 8B 10 66 3B 11 75 ?? + 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 } - $entrypoint_all = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? - ?? 83 EC ?? 53 56 57 89 65 ?? 33 DB 89 5D ?? 6A ?? FF 15 ?? ?? ?? ?? 59 83 0D ?? ?? - ?? ?? ?? 83 0D ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 08 FF 15 ?? ?? - ?? ?? 8B 0D ?? ?? ?? ?? 89 08 A1 ?? ?? ?? ?? 8B 00 A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 39 - 1D ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 FF 35 ?? ?? ?? - ?? 8D 45 ?? 50 8D 45 ?? 50 8D 45 ?? 50 FF 15 + $delete_volumes_snapshots_p2 = { + EB ?? 1B C0 83 D8 ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 89 85 + ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? EB ?? 8D 64 24 ?? 8B BD ?? ?? ?? ?? BA ?? ?? ?? ?? 8B + CE D3 E2 85 95 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 4E ?? 66 89 8D ?? ?? ?? ?? 33 C9 6A + ?? 51 8D 95 ?? ?? ?? ?? 52 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? + 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8D 9F ?? + ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 6A ?? 52 E8 ?? ?? ?? ?? 83 + C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 83 EC ?? B8 ?? ?? ?? ?? 8B CC 89 A5 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? + ?? ?? 83 78 ?? ?? 72 ?? 8B 00 8D 50 ?? 8D A4 24 ?? ?? ?? ?? 8A 08 40 84 C9 75 ?? 33 + FF 57 8D 8D ?? ?? ?? ?? 51 2B C2 50 83 EC ?? B8 ?? ?? ?? ?? 8B CC 89 A5 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 83 C4 ?? 39 70 ?? 72 + ?? 8B 00 50 53 FF 15 ?? ?? ?? ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? + ?? ?? ?? 83 C4 ?? BE ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 89 B5 ?? + ?? ?? ?? 89 BD ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 72 ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 53 89 B5 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 8B B5 ?? ?? ?? ?? 46 89 B5 ?? ?? ?? ?? 83 FE ?? 0F 8C ?? ?? ?? ?? EB ?? 57 + 8D 9F ?? ?? ?? ?? E8 ?? ?? ?? ?? B0 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B + 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 } condition: - uint16(0)==0x5A4D and ($entrypoint_all at pe.entry_point) and ($main_1 or $main_2 or ($main_3 and $start_service_3) or $main_4 or $main_5 or ($main_6 and ($set_reg_key_6 or $download_tor_6)) or $main_7 or $main_8) + uint16(0)==0x5A4D and ( all of ($delete_volumes_snapshots_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Hddcryptor : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Thanatos : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects HDDCryptor ransomware." + description = "Yara rule that detects Thanatos ransomware." author = "ReversingLabs" - id = "2c6a8ca3-0f7a-52b7-af6d-74fa9407feca" - date = "2020-07-15" - modified = "2020-07-15" + id = "190adbd0-30a7-5619-ab70-3ab031ece2f7" + date = "2020-11-13" + modified = "2020-11-13" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.HDDCryptor.yara#L1-L157" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "47915f315bb4956507362f56024f5632cb1bcec569ceaf77fe9d7cb9c25d1d8a" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Thanatos.yara#L1-L85" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "a51fa9cf1a08e4cd252a8b385be3bfde909585e2a799baaede977e40ecff5313" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -34332,127 +35957,81 @@ rule REVERSINGLABS_Win32_Ransomware_Hddcryptor : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "HDDCryptor" + tc_detection_name = "Thanatos" tc_detection_factor = 5 importance = 25 strings: - $deploy_components = { - B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 66 83 BD ?? ?? ?? ?? ?? 6A ?? 53 0F 85 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 6A ?? 68 ?? - ?? ?? ?? BA ?? ?? ?? ?? 8B CB 8B F0 E8 ?? ?? ?? ?? 8B F8 6A ?? 0F AF FE 68 ?? ?? ?? - ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 8B F0 6A ?? 0F AF F7 68 ?? ?? ?? ?? BA ?? ?? - ?? ?? 8B CB E8 ?? ?? ?? ?? 8B F8 6A ?? 0F AF FE 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB - E8 ?? ?? ?? ?? 8B F0 6A ?? 0F AF F7 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? - ?? 6A ?? 68 ?? ?? ?? ?? E9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BA ?? - ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB 8B F0 E8 ?? - ?? ?? ?? 8B F8 6A ?? 0F AF FE 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 8B - F0 6A ?? 0F AF F7 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 8B F8 6A ?? 0F - AF FE 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 8B F0 6A ?? 0F AF F7 68 ?? - ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B F8 BA ?? ?? ?? - ?? 0F AF FE 8B CB E8 - } - $get_shares_info = { - E8 ?? ?? ?? ?? 83 C4 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? EB ?? FF 15 ?? ?? - ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF D6 8D 44 24 ?? 50 C7 44 24 ?? - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - FF 15 - } - $encrypt_discs = { - 68 ?? ?? ?? ?? FF 74 24 ?? 0F 57 C0 66 0F 7F 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 33 C9 EB ?? 8D 49 ?? 0F B7 81 ?? ?? ?? ?? 66 89 84 0C ?? ?? ?? ?? 8D 49 ?? 66 - 85 C0 75 ?? 8D 8C 24 ?? ?? ?? ?? 83 C1 ?? 66 8B 41 ?? 8D 49 ?? 66 85 C0 75 ?? A1 ?? - ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 - ?? A1 ?? ?? ?? ?? 89 41 ?? 0F B7 05 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 66 89 41 - ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - D7 B9 ?? ?? ?? ?? E8 - } - $create_diskcryptor_service = { - 83 EC ?? 53 55 56 57 68 ?? ?? ?? ?? 33 ED 8B F2 55 55 8B F9 FF 15 ?? ?? ?? ?? 85 C0 - 74 ?? 55 55 55 55 55 FF 74 24 ?? 55 6A ?? 5B 53 6A ?? 68 ?? ?? ?? ?? 56 57 50 FF 15 - ?? ?? ?? ?? 8B F0 89 5C 24 ?? B8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 33 - C9 89 44 24 ?? 41 8D 44 24 ?? 89 4C 24 ?? 89 44 24 ?? 8D 44 24 ?? 50 53 56 89 4C 24 - ?? C7 44 24 ?? ?? ?? ?? ?? 89 6C 24 ?? FF 15 ?? ?? ?? ?? 8B C6 5F 5E 5D 5B 83 C4 ?? - C3 - } - $extract_diskcryptor_from_resources = { - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 55 56 8B B4 24 ?? ?? - ?? ?? 33 C0 57 50 89 54 24 ?? 8B E9 FF 15 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 8B D8 56 - 0F B7 C9 51 53 FF 15 ?? ?? ?? ?? 8B F0 56 53 FF 15 ?? ?? ?? ?? 56 53 8B F8 FF 15 ?? - ?? ?? ?? 57 89 44 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? 8B F0 E8 ?? ?? ?? ?? 59 FF 74 - 24 ?? 8B D8 56 53 E8 ?? ?? ?? ?? 8B 54 24 ?? 33 FF 83 C4 ?? 8B CF 85 D2 7E ?? 8A 04 - 19 3C ?? 7C ?? 3C ?? 7F ?? 04 ?? 3C ?? 76 ?? 2C ?? 88 04 19 41 3B CA 7C ?? 33 C0 68 - ?? ?? ?? ?? 66 89 44 24 ?? 8D 44 24 ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F5 66 8B 45 - ?? 83 C5 ?? 66 3B C7 75 ?? 8D 7C 24 ?? 2B EE 83 EF ?? 33 C9 66 8B 47 ?? 83 C7 ?? 66 - 3B C1 75 ?? 8B CD C1 E9 ?? F3 A5 8B CD 83 E1 ?? F3 A4 8D 7C 24 ?? 83 EF ?? 33 ED 66 - 8B 47 ?? 8D 7F ?? 66 3B C5 75 ?? A1 ?? ?? ?? ?? 8B 54 24 ?? 8B F2 89 07 66 8B 02 83 - C2 ?? 66 3B C5 75 ?? 8D 7C 24 ?? 2B D6 83 EF ?? 66 8B 47 ?? 83 C7 ?? 66 3B C5 75 ?? - 8B CA 8D 44 24 ?? C1 E9 ?? F3 A5 55 55 6A ?? 55 55 8B CA 83 E1 ?? 68 ?? ?? ?? ?? F3 - A4 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 74 ?? 55 8D 44 24 ?? 50 FF 74 24 ?? 53 56 FF - 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 33 C0 40 EB ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 - C0 8B 8C 24 ?? ?? ?? ?? 5F 5E 5D 5B 33 CC E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 - } - $encrypt_files_using_diskcryptor_p1 = { - 55 8B EC 83 E4 ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? - ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 56 57 A1 ?? ?? ?? ?? 33 C4 50 8D 84 24 ?? ?? - ?? ?? 64 A3 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D3 83 7D ?? ?? 73 ?? B9 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 8B 75 ?? BA ?? ?? ?? ?? 8B 4E ?? 8A 01 41 88 02 42 84 C0 75 ?? 8B 4E ?? BA - ?? ?? ?? ?? 8A 01 41 88 02 42 84 C0 75 ?? 6A ?? 59 BE ?? ?? ?? ?? C7 05 ?? ?? ?? ?? - ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? F3 A5 68 ?? ?? ?? ?? - 33 F6 8D 84 24 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 54 24 ?? 89 B4 24 ?? ?? ?? ?? - 8D 4C 24 ?? E8 ?? ?? ?? ?? 56 6A ?? 8D 4C 24 ?? C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 7C 24 ?? ?? 8D 44 24 ?? 56 0F 43 44 24 ?? 56 6A ?? 56 56 68 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D3 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 33 DB C7 44 + $find_files = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 57 50 89 85 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? 51 FF D6 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 89 85 ?? ?? ?? ?? EB ?? 8D 49 ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 83 C4 ?? C6 03 ?? FF + 15 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 B9 ?? ?? + ?? ?? F7 F9 52 53 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 4F 75 ?? 8B 95 ?? ?? ?? + ?? 52 8D 85 ?? ?? ?? ?? 50 C6 43 ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? 51 FF D6 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 FF D6 F6 85 ?? ?? ?? ?? ?? + 74 ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D7 85 C0 0F 84 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 FF D7 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 + 50 8D 8D ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8D BD + ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8B F8 72 ?? 8B + 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 FF ?? 74 ?? 53 8D 9D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? + ?? 8B E5 5D C3 } - $encrypt_files_using_diskcryptor_p2 = { - 24 ?? ?? ?? ?? ?? 50 89 5C 24 ?? 89 5C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 53 FF 15 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B D0 59 59 85 D2 - 75 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 59 8B D0 8D BC 24 ?? ?? ?? ?? 83 EF ?? 66 - 8B 47 ?? 8D 7F ?? 66 3B C3 75 ?? A1 ?? ?? ?? ?? 83 C2 ?? 89 07 8B F2 66 8B 02 83 C2 - ?? 66 3B C3 75 ?? 8D BC 24 ?? ?? ?? ?? 2B D6 83 EF ?? 66 8B 47 ?? 83 C7 ?? 66 3B C3 - 75 ?? 8B CA 8D 84 24 ?? ?? ?? ?? C1 E9 ?? F3 A5 8B CA 83 E1 ?? F3 A4 51 50 83 EC ?? - 8B CC 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 C6 84 - 24 ?? ?? ?? ?? ?? 83 7E ?? ?? 72 ?? 8B 36 83 EC ?? 8B CC 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 72 ?? 8B 00 8B D6 8B C8 - E8 ?? ?? ?? ?? 59 59 53 6A ?? 8D 4C 24 ?? 8B F0 E8 ?? ?? ?? ?? 53 6A ?? 8D 4C 24 ?? - C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 74 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B F3 EB ?? FF 15 ?? ?? ?? ?? 8B F0 53 6A ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? - 8B C6 EB ?? 53 6A ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 33 C0 8B 8C 24 ?? ?? ?? ?? 64 89 0D - ?? ?? ?? ?? 59 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files_p1 = { + 55 8B EC 83 EC ?? 53 56 57 68 ?? ?? ?? ?? 33 DB 6A ?? 53 8B F0 53 8D 45 ?? 33 FF 50 + 89 7D ?? 89 5D ?? 89 5D ?? 89 5D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 55 + ?? 8D 4D ?? 51 53 53 68 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B + C6 8D 50 ?? 8A 08 40 84 C9 75 ?? 53 2B C2 50 8B 45 ?? 56 50 FF 15 ?? ?? ?? ?? 85 C0 + 0F 84 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8D 4D ?? 51 6A ?? 52 68 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 50 8D 4D ?? 51 53 53 6A ?? 53 8B + 1D ?? ?? ?? ?? 52 89 45 ?? FF D3 85 C0 74 ?? 8B 45 ?? 8B 3D ?? ?? ?? ?? 50 6A ?? FF + D7 50 FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 8B 4D ?? 8B 55 ?? 8B 02 51 50 56 E8 ?? ?? + ?? ?? 8B 4D ?? 8B 45 ?? 83 C4 ?? 51 8D 55 ?? 52 56 6A ?? 6A ?? 6A ?? 50 FF D3 85 C0 + 74 ?? 8B 5D ?? 8B 0B 51 6A ?? FF D7 50 FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 89 10 89 + 33 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 7D ?? 33 DB 8B 55 ?? 52 FF + 15 ?? ?? ?? ?? 8B 45 ?? 53 50 FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C2 } - $reboot = { - 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 8D 45 ?? 50 6A ?? FF 15 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 C0 EB ?? 8D 45 ?? 33 F6 50 68 ?? ?? ?? ?? 56 - FF 15 ?? ?? ?? ?? 56 56 56 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 56 FF 75 ?? C7 45 ?? ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 6A ?? FF 15 - ?? ?? ?? ?? F7 D8 1B C0 F7 D8 8B 4D ?? 33 CD 5E E8 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files_p2 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 45 ?? 33 F6 56 68 ?? ?? ?? ?? + 6A ?? 56 6A ?? 68 ?? ?? ?? ?? 53 89 85 ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? 89 B5 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 56 57 FF 15 ?? ?? ?? ?? 8B F0 + 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? + ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 56 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 50 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 E8 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 6A ?? 52 E8 ?? + ?? ?? ?? 83 C4 ?? 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 8D B5 ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 83 C4 ?? 39 70 ?? 72 ?? 8B + 00 50 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 39 B5 ?? ?? ?? ?? + 72 ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 95 ?? ?? + ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 8B 95 ?? ?? ?? ?? 6A ?? 8D + 8D ?? ?? ?? ?? 51 8B 8D ?? ?? ?? ?? 52 51 50 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? + 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? + ?? ?? 8B E5 5D C2 } condition: - uint16(0)==0x5A4D and ((($deploy_components) and ($get_shares_info) and ($encrypt_discs)) or (($extract_diskcryptor_from_resources) and ($create_diskcryptor_service) and ( all of ($encrypt_files_using_diskcryptor_p*)) and ($reboot))) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Mafia : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Ryuk : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Mafia ransomware." + description = "Yara rule that detects Ryuk ransomware." author = "ReversingLabs" - id = "67f09000-751f-539a-b222-25b1502c2728" + id = "179c9277-0bdc-522a-a822-cf93febff408" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Mafia.yara#L1-L142" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "5c17b799f0b4f1f8f72a2e4203a6606f7783ceec2034694f8a21ff65e5afdb26" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Ryuk.yara#L1-L199" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "bf93892b281be20917656e242cbb0f3b3694439556b7e5e40a424ba1aa909105" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -34460,131 +36039,186 @@ rule REVERSINGLABS_Win32_Ransomware_Mafia : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Mafia" + tc_detection_name = "Ryuk" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? - ?? ?? 53 56 57 68 ?? ?? ?? ?? 8D 44 24 ?? 8B F1 6A ?? 50 89 74 24 ?? C7 44 24 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 33 C9 68 ?? ?? ?? ?? 51 8D 94 24 ?? ?? ?? ?? 52 66 89 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 68 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? 51 66 89 84 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? - ?? 83 C4 ?? 8D 44 24 ?? 50 8D 8C 24 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? - 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? - ?? ?? ?? 8B 35 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 68 ?? ?? ?? ?? 8D - 8C 24 ?? ?? ?? ?? 6A ?? 51 E8 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 8D 84 24 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? 51 FF D6 B8 ?? ?? - ?? ?? 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 56 81 EC ?? ?? - ?? ?? B9 ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? 8B FC F3 A5 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? - ?? 8D 54 24 ?? 52 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 44 24 ?? 50 81 EC ?? ?? ?? ?? - B9 ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? 8B FC F3 A5 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 8D - 4C 24 ?? 51 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 53 FF 15 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? - ?? 5F 5E 5B 33 CC 33 C0 E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $remote_connection_p1 = { - 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 33 C0 57 - 68 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 66 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 6A ?? 52 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? 6A ?? 51 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? - 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 52 E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 83 C4 ?? 33 C0 68 ?? - ?? ?? ?? 50 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 51 E8 ?? - ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 33 C0 89 85 - } - $remote_connection_p2 = { - 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? - ?? 66 89 95 ?? ?? ?? ?? 8B 48 ?? 8B 11 8B 02 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8D - 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF - 15 ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? - 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 50 ?? 8B FF 8A 08 40 84 C9 75 ?? 6A - ?? 2B C2 50 8D 8D ?? ?? ?? ?? 51 56 FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 95 ?? - ?? ?? ?? 52 56 FF D3 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 - C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D7 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 50 - 8D 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF - D7 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 51 E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8D - 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 FF D7 - 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 6A ?? 52 E8 ?? ?? ?? ?? 53 8D 85 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 FF D7 68 ?? ?? ?? ?? 8D 95 - ?? ?? ?? ?? 6A ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 40 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? EB - ?? 68 ?? ?? ?? ?? FF D7 56 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? - 8B E5 5D C3 68 - } $encrypt_files_p1 = { - 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? - ?? ?? 53 56 8B 75 ?? 57 68 ?? ?? ?? ?? 33 DB 8D 8C 24 ?? ?? ?? ?? 33 C0 53 51 66 89 - 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 54 24 ?? 53 52 89 5C 24 - ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 44 24 ?? 53 50 89 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 - ?? 33 C0 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 53 51 89 5C 24 ?? 89 44 24 ?? 89 44 24 - ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 88 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 53 52 88 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 53 50 88 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 33 C9 53 52 66 89 8C 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 4D ?? 8B C1 83 C4 ?? 48 74 ?? 48 74 ?? 8B 45 ?? 8B 55 ?? 50 52 51 56 FF - 15 ?? ?? ?? ?? 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C2 + 55 8B EC 81 EC ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? + 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 + FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? + ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? + ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 D2 89 55 ?? 0F 57 C0 66 0F 13 + 45 ?? 83 7D ?? ?? 74 ?? 8D 45 ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8D 55 ?? 52 8B 45 + ?? 50 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? 83 7D ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? ?? + ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 0F 57 C0 66 0F 13 45 ?? 83 7D ?? ?? 77 ?? 81 7D + ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 6A ?? 6A ?? 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? + 6A ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 45 ?? + 89 55 ?? 83 7D ?? ?? 72 ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 76 ?? 6A ?? 6A ?? 8B 4D ?? 51 + 8B 55 ?? 52 E8 ?? ?? ?? ?? 6A ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 + 50 E8 ?? ?? ?? ?? 89 45 ?? 89 55 ?? 83 7D ?? ?? 77 ?? 72 ?? 81 7D ?? ?? ?? ?? ?? 77 + ?? 83 7D ?? ?? 77 ?? 72 ?? 83 7D ?? ?? 73 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 76 ?? 83 7D ?? ?? 77 ?? 72 + ?? 81 7D ?? ?? ?? ?? ?? 73 ?? 6A ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 6A + ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 45 ?? 89 + 55 ?? EB ?? 83 7D ?? ?? 77 ?? 72 ?? 81 7D ?? ?? ?? ?? ?? 73 ?? 6A ?? 6A ?? 8B 55 ?? + 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? + 52 50 E8 ?? ?? ?? ?? 89 45 ?? 89 55 ?? 83 7D ?? ?? 77 ?? 72 ?? 81 7D } $encrypt_files_p2 = { - 53 FF 15 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E 5B 33 CC 33 C0 E8 ?? ?? ?? ?? 8B E5 - 5D C2 ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 33 F6 E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 79 ?? 48 0D ?? ?? ?? ?? 40 - 88 86 ?? ?? ?? ?? 46 83 FE ?? 7C ?? 33 F6 E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 79 ?? 48 0D - ?? ?? ?? ?? 40 88 86 ?? ?? ?? ?? 46 83 FE ?? 7C ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8D 49 ?? 0F B6 83 ?? ?? ?? ?? 6A - ?? 8D 94 24 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? 51 8D 94 - 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 83 C4 ?? 8B C8 - 8A 10 40 84 D2 75 ?? 8D BC 24 ?? ?? ?? ?? 2B C1 8B F1 4F 8A 4F ?? 47 84 C9 75 ?? 8B - C8 C1 E9 ?? F3 A5 8B C8 83 E1 ?? 8D 84 24 ?? ?? ?? ?? F3 A4 8B C8 8A 10 40 84 D2 75 - ?? BF ?? ?? ?? ?? 2B C1 8B F1 4F 8A 4F ?? 47 84 C9 75 ?? 8B C8 C1 E9 ?? F3 A5 8B C8 + 77 ?? 83 7D ?? ?? 77 ?? 72 ?? 83 7D ?? ?? 77 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? 8B 4D ?? 89 8D ?? ?? ?? ?? 8B 55 ?? 89 95 ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 72 ?? + 83 7D ?? ?? 73 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 7D + ?? ?? 0F 84 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 77 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 0F + 86 ?? ?? ?? ?? 8B 4D ?? 81 E9 ?? ?? ?? ?? 89 4D ?? 6A ?? 6A ?? 8B 55 ?? 52 8B 45 ?? + 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? B8 ?? + ?? ?? ?? E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + 6A ?? 8D 95 ?? ?? ?? ?? 52 6A ?? 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? + 89 45 ?? 83 7D ?? ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? + 8B 55 ?? 83 C2 ?? 89 55 ?? 83 7D ?? ?? 0F 83 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? + ?? 8B 45 ?? 0F BE 8C 05 ?? ?? ?? ?? 83 F9 ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 0F BE 84 15 + ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 4D ?? 0F BE 94 0D ?? ?? ?? ?? 83 FA ?? 0F + 85 ?? ?? ?? ?? 8B 45 ?? 0F BE 8C 05 ?? ?? ?? ?? 83 F9 ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? + 0F BE 84 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 4D ?? 0F BE 94 0D ?? ?? ?? ?? + 83 FA ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 8D ?? + ?? ?? ?? 8B 15 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 66 A1 ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 BD ?? + ?? ?? ?? ?? 75 ?? 8B 45 ?? 89 45 ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? + 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8B 55 ?? 52 8B 45 ?? + 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? E9 } $encrypt_files_p3 = { - 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 83 E1 ?? 6A ?? 50 F3 A4 E8 ?? ?? ?? ?? 83 C4 ?? - 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 6A ?? 51 E8 ?? ?? ?? ?? 43 83 C4 ?? 83 FB ?? 0F - 8C ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? - ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 DB EB ?? 8D A4 24 ?? ?? ?? ?? EB ?? 8D 49 ?? - 0F B6 83 ?? ?? ?? ?? 6A ?? 8D 94 24 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C - 24 ?? ?? ?? ?? 51 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 8D 84 24 ?? - ?? ?? ?? 83 C4 ?? 8B C8 8A 10 40 84 D2 75 ?? 8D BC 24 ?? ?? ?? ?? 2B C1 8B F1 4F 8A - 4F ?? 47 84 C9 75 ?? 8B C8 C1 E9 ?? F3 A5 8B C8 83 E1 ?? 8D 84 24 ?? ?? ?? ?? F3 A4 - 8B C8 8A 10 40 84 D2 75 ?? BF ?? ?? ?? ?? 2B C1 8B F1 4F 8A 4F ?? 47 84 C9 75 ?? 8B + 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? + ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 55 ?? 52 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 + FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? + ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D + ?? ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 6A ?? 6A ?? 6A + ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 50 8B 45 ?? 50 FF 15 ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B + 55 ?? 52 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? + 8D 45 ?? 50 6A ?? 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? + ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? + 51 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 6A ?? + 68 ?? ?? ?? ?? 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 6A ?? 68 } $encrypt_files_p4 = { - C8 C1 E9 ?? F3 A5 8B C8 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 83 E1 ?? 6A ?? 50 F3 A4 - E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 6A ?? 51 E8 ?? ?? ?? ?? - 43 83 C4 ?? 83 FB ?? 0F 8C ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? BF ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? - 56 FF D3 83 C4 ?? 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 6A ?? 6A ?? 56 68 ?? ?? ?? ?? - 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 89 44 8C ?? 41 89 4C 24 ?? 47 83 C6 - ?? 83 FF ?? 7E ?? 8B 54 24 ?? 6A ?? 6A ?? 8D 4C 24 ?? 51 52 FF 15 ?? ?? ?? ?? 8D 44 - 24 ?? 50 8D 4C 24 ?? 51 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? FF 15 + 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 89 45 ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? EB ?? 8B 4D ?? 83 C1 ?? 89 4D ?? 8B 55 ?? 3B 55 ?? 0F 87 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 3B 45 ?? 75 ?? 8B 4D ?? 89 4D ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 69 55 ?? ?? ?? ?? ?? 52 8B 45 ?? 50 FF 15 + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? + ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B + 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? + ?? ?? 75 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? + ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A ?? 6A ?? 8B 4D ?? 51 6A + ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? + 51 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 55 ?? 52 8D 45 ?? 50 8B 4D ?? + 51 6A ?? 8B 55 ?? 52 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4D ?? 51 FF + 15 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A + ?? 69 45 ?? ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? + ?? ?? ?? ?? 75 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? B8 ?? + ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8B 45 ?? + 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 55 + ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 + } + $encrypt_files_p5 = { + E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8A 0D ?? ?? ?? ?? 88 4D ?? 33 D2 89 55 + ?? 89 55 ?? 89 55 ?? 89 55 ?? 88 55 ?? 6A ?? 6A ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? + ?? 83 7D ?? ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 33 C9 89 8D ?? ?? ?? ?? 6A ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 + 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 89 95 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 E8 ?? + ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? + ?? 51 8D 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? + 83 C4 ?? 8D 4D ?? 51 8D 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8D 45 ?? 50 8D 4D ?? + 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8D 45 ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 50 8D 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? + 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 + ?? ?? ?? ?? 8D 55 ?? 52 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? + 50 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? + ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 55 ?? 52 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 8B 4D + ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B + } + $encrypt_files_p6 = { + 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 8D 8D ?? ?? ?? ?? 51 8B 55 ?? + 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D + ?? 51 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 81 7D ?? ?? + ?? ?? ?? 0F 86 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 D2 89 55 ?? 0F 57 C0 66 0F 13 45 + ?? 6A ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? + ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 8D 95 ?? ?? + ?? ?? 52 6A ?? 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? + 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? + ?? B8 ?? ?? ?? ?? EB ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 55 ?? + 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D + ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? EB ?? B8 + ?? ?? ?? ?? 8B E5 5D C3 + } + $remote_connection = { + 55 8B EC 81 EC ?? ?? ?? ?? 8B 45 ?? C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 51 6A ?? 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? + 89 45 ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? + ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8D 4D ?? 51 8B 55 ?? 52 6A ?? 6A ?? 6A ?? E8 + ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 45 ?? EB ?? 8B 4D ?? 8B 51 ?? + 89 55 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? 89 45 ?? C7 45 ?? ?? ?? ?? + ?? 8B 4D ?? 8B 51 ?? 89 55 ?? EB ?? 8B 45 ?? 8B 48 ?? 89 4D ?? 83 7D ?? ?? 0F 84 ?? + ?? ?? ?? 8B 55 ?? 83 C2 ?? 89 55 ?? 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 83 C1 ?? 51 E8 ?? + ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? B9 ?? + ?? ?? ?? 6B D1 ?? 8D 8C 15 ?? ?? ?? ?? 3B C1 74 ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? + 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 0F 57 C0 66 0F 13 45 ?? C7 45 ?? ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 83 C8 ?? E9 ?? ?? + ?? ?? 8D 55 ?? 89 55 ?? 8D 45 ?? 50 8B 4D ?? 0F B6 51 ?? 52 E8 + } + $find_files_p1 = { + 8B FF 55 8B EC 51 8B 4D ?? 53 57 33 DB 8D 51 ?? 66 8B 01 83 C1 ?? 66 3B C3 75 ?? 8B + 7D ?? 2B CA D1 F9 83 C8 ?? 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 56 8D 5F ?? + 03 D9 6A ?? 53 E8 ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? + ?? 83 C4 ?? 85 C0 75 ?? FF 75 ?? 2B DF 8D 04 7E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 75 ?? 8B 4D ?? 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5F + 5B 8B E5 5D C3 33 C0 50 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? + ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 55 ?? 8B 4D ?? 53 8B 5D ?? 56 57 6A ?? 5E 6A ?? + 89 95 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 5F EB ?? 0F B7 01 66 3B 85 ?? ?? ?? + ?? 74 ?? 66 3B C6 74 ?? 66 3B C7 74 ?? 83 E9 ?? 3B CB 75 ?? 0F B7 31 66 3B F7 75 ?? + 8D 43 ?? 3B C8 74 ?? 52 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 6A ?? + 8B C6 33 FF 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 8B C7 + } + $find_files_p2 = { + EB ?? 33 C0 40 2B CB 0F B6 C0 D1 F9 41 F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 + 57 53 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? 8B 85 ?? ?? ?? ?? 50 57 57 53 E8 ?? ?? + ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD + 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 8D ?? ?? ?? ?? 6A ?? 8B 41 ?? 2B 01 C1 F8 ?? 89 85 + ?? ?? ?? ?? 58 66 39 85 ?? ?? ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 66 39 85 ?? ?? + ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 51 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 8B 8D + ?? ?? ?? ?? 85 C0 6A ?? 58 75 ?? 8B C1 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 + ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? + 83 C4 ?? E9 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($remote_connection) } -rule REVERSINGLABS_Win32_Ransomware_Fenixlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Jemd : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects FenixLocker ransomware." + description = "Yara rule that detects Jemd ransomware." author = "ReversingLabs" - id = "4868ced4-885d-548c-993c-ae25ab188172" + id = "ef981ffa-8801-50f0-9441-5f2bfcf44133" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.FenixLocker.yara#L1-L143" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "72712616df2c73c5c17696a7c5cb93f767910acf5f49cda27373fccfa29c5a4d" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Jemd.yara#L1-L105" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "552e0fc118031e953dee2e7c6bf8234a5a90de8c34b0e2724dfe99f2b28b8c51" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -34592,142 +36226,96 @@ rule REVERSINGLABS_Win32_Ransomware_Fenixlocker : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "FenixLocker" + tc_detection_name = "Jemd" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_1 = { - 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 68 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 8B F1 E8 ?? ?? ?? ?? 83 C4 - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 6A ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 8D 85 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? - E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5E 8B 4D ?? 33 CD E8 ?? ?? - ?? ?? 8B E5 5D C3 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 33 C0 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8D 85 ?? ?? ?? ?? 50 - FF B5 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? - ?? ?? 50 68 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 46 ?? 50 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 85 C0 0F 84 ?? ?? ?? ?? 57 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8B F8 - 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 83 7E ?? ?? 72 ?? 8B 36 FF B5 ?? ?? ?? ?? 56 57 E8 - ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 50 57 6A ?? 6A ?? 6A ?? FF - B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B - E5 5D C3 8B 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 01 8B C7 8B 4D ?? 5F 33 CD 5E E8 ?? - ?? ?? ?? 8B E5 5D C3 + $find_files_1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 33 DB 89 9D ?? ?? ?? ?? 89 4D ?? 89 55 ?? 89 45 ?? 8B + 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? + 64 FF 30 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 83 F8 ?? 75 + ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B + 45 ?? 50 8B 45 ?? 50 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? B1 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 } - $encrypt_files_2 = { - B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 - ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? - F6 85 ?? ?? ?? ?? ?? 8D 55 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B D0 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? - 8B F8 C6 45 ?? ?? 8B 4D ?? 8B 55 ?? 41 3B D1 77 ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 8B 55 - ?? 8B 4D ?? 4A 8B 45 ?? 23 CA 03 C1 89 4D ?? 8B 4D ?? 23 D0 83 3C 91 ?? 8D 34 95 ?? - ?? ?? ?? 75 ?? 6A ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 89 04 31 8B 4D ?? 8B 0C 31 85 - C9 74 ?? 57 E8 ?? ?? ?? ?? FF 45 ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 - 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B - C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 - C4 ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 - ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? - ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F - 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B BD ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 85 F6 0F 8E ?? ?? - ?? ?? 68 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? - ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? - 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? - ?? ?? ?? 8B 40 ?? F6 84 05 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? - ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? - 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F - 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 - E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? 6A ?? 8B 40 ?? 03 C8 8B 51 ?? 83 CA ?? 8B C2 83 C8 ?? 83 79 ?? - ?? 0F 45 C2 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? FF 15 ?? ?? ?? ?? 57 FF - 15 ?? ?? ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? B0 ?? 8B 4D ?? 64 89 0D ?? ?? ?? - ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $find_files_2 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 4D ?? + 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? + ?? ?? 8D B5 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 E8 ?? ?? ?? ?? 89 + C3 BB ?? ?? ?? ?? 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4B 75 ?? 33 DB 8D 45 ?? 33 C9 BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 8A 14 1E 88 54 05 ?? 40 43 80 3C 1E ?? 74 ?? 83 F8 + ?? 7E ?? 43 8D 85 ?? ?? ?? ?? 8D 55 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 45 ?? 50 8D 85 ?? ?? ?? ?? 8D 55 ?? B9 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 80 7C 1E + ?? ?? 75 ?? 80 3C 1E ?? 74 ?? 81 FB ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? 33 C0 5A 59 59 64 + 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? C3 } - $encrypt_files_3 = { - E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B D0 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 - ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? ?? - 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F - 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 83 FE ?? 0F - 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? 8A 11 3A 10 75 ?? 84 D2 74 ?? 8A 51 ?? 3A 50 ?? 75 ?? 83 C1 ?? - 83 C0 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? - 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? - ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? - 8D 4D ?? 0F 43 4D ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 7E ?? 83 7D ?? ?? 8D 4D ?? 8D - 45 ?? 0F 43 4D ?? 83 7D ?? ?? 51 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? - 46 EB ?? 85 F6 75 ?? 83 F8 ?? B8 ?? ?? ?? ?? 0F 45 F0 89 B5 ?? ?? ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 0F 82 ?? ?? ?? ?? 8B 4D ?? 40 3D ?? ?? ?? - ?? 72 ?? F6 C1 ?? 75 ?? 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 ?? 72 ?? 83 F9 ?? 77 ?? 8B - C8 51 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? E8 + $encrypt_files_p1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? + ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 8B D9 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? + ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 + 89 20 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 80 7C 02 ?? ?? 75 ?? 8B 45 ?? E8 ?? ?? ?? ?? + 8B D0 4A 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 + ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B D0 83 CA ?? 3B D0 75 ?? 80 + FB ?? 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 50 + 8B 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CB 8B 55 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? FF } - $encrypt_files_4 = { - 8B BD ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? 85 F6 0F 8E ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 - ?? ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 - ?? 40 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8B 40 ?? - F6 84 05 ?? ?? ?? ?? ?? 75 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? - E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? 8B 40 ?? 03 C8 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 ?? 83 C8 ?? 6A ?? 50 E8 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D - 41 ?? 89 84 0D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 83 - 7D ?? ?? 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 75 ?? - E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 + $encrypt_files_p2 = { + 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B B5 ?? ?? ?? + ?? 8B C6 83 C8 ?? 3B C6 75 ?? 80 FB ?? 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B + 45 ?? 50 8B 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CB 8B 55 ?? E8 ?? ?? ?? ?? EB ?? FF + 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B + 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? C3 } - $encrypt_files_5 = { - FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? - ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? - ?? ?? B0 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B - E5 5D C3 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B D0 8D 4D ?? E8 ?? ?? ?? - ?? 83 C4 ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 8D ?? ?? ?? ?? 50 FF - B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C6 85 ?? ?? ?? ?? ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 4D ?? C7 - 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? - ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 8D 4D ?? 0F 43 4D ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 7E ?? 83 7D ?? ?? 8D 4D ?? 8D 45 ?? 0F 43 4D ?? 83 7D ?? ?? 51 0F 43 45 ?? - 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 46 89 B5 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? - 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 0F 82 ?? ?? ?? - ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? E9 + $main_routine = { + 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 + ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? B0 ?? E8 ?? + ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? + ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 50 8D 55 ?? 66 + B8 ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? B1 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? + A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B + 0D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 8B 08 FF 51 ?? 8D 55 ?? + 33 C0 E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 8B 08 FF + 51 } condition: - uint16(0)==0x5A4D and ($encrypt_files_1 and $encrypt_files_2 and $encrypt_files_3) or ($encrypt_files_1 and $encrypt_files_4 and $encrypt_files_5) + uint16(0)==0x5A4D and ($main_routine) and ( all of ($find_files_*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Sherminator : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Defray : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Sherminator ransomware." + description = "Yara rule that detects Defray ransomware." author = "ReversingLabs" - id = "99792a22-8027-557f-927f-30eac4d1e690" + id = "bc9e2dfe-168b-5b99-8523-07bfdcba44f2" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Sherminator.yara#L1-L157" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "22ac61b95f6ca4530e81a23fdd05be93e368647ca7100097a94eae3c6ce3b7d1" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Defray.yara#L1-L157" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "82d883c77f49e50edbc7af05a108d4d54a46dca7661e4d0cd8aeffa19cb8df98" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -34735,145 +36323,142 @@ rule REVERSINGLABS_Win32_Ransomware_Sherminator : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Sherminator" + tc_detection_name = "Defray" tc_detection_factor = 5 importance = 25 strings: - $enum_resources_p1 = { - 55 89 E5 57 53 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 - ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 89 45 ?? 83 7D ?? - ?? 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? C7 44 24 ?? - ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 - ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 89 54 - 24 ?? 8B 55 ?? 89 54 24 ?? 8D 55 ?? 89 54 24 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 89 - 45 ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 ?? 89 - } - $enum_resources_p2 = { - 45 ?? 8B 45 ?? C1 E0 ?? 89 C2 8B 45 ?? 01 D0 8B 40 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 - ?? C1 E0 ?? 89 C2 8B 45 ?? 01 D0 8B 40 ?? 89 04 24 E8 ?? ?? ?? ?? 83 C0 ?? 8B 15 ?? - ?? ?? ?? 8B 0D ?? ?? ?? ?? C1 E1 ?? 8D 1C 0A C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? - ?? ?? ?? 89 03 A1 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? C1 E2 ?? 01 D0 8B 00 85 C0 0F 84 ?? - ?? ?? ?? 8B 45 ?? C1 E0 ?? 89 C2 8B 45 ?? 01 D0 8B 50 ?? A1 ?? ?? ?? ?? 8B 0D ?? ?? - ?? ?? C1 E1 ?? 01 C8 8B 00 89 54 24 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 15 - ?? ?? ?? ?? C1 E2 ?? 01 D0 8B 10 89 D0 B9 ?? ?? ?? ?? 89 C3 B8 ?? ?? ?? ?? 89 DF F2 - AE 89 C8 F7 D0 83 E8 ?? 01 D0 66 C7 00 ?? ?? A1 ?? ?? ?? ?? 83 C0 ?? A3 ?? ?? ?? ?? - 8B 45 ?? C1 E0 ?? 89 C2 8B 45 ?? 01 D0 8B 40 ?? 83 E0 ?? 85 C0 74 ?? 8B 45 ?? C1 E0 - ?? 89 C2 8B 45 ?? 01 D0 89 04 24 E8 ?? ?? ?? ?? EB ?? 90 83 45 ?? ?? 8B 45 ?? 39 45 - ?? 0F 82 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? - ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 90 90 8D 65 ?? 5B 5F 5D C3 + $find_files = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 68 ?? ?? ?? ?? 33 + F6 89 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B D9 56 50 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 83 + C4 ?? 2B D3 8B CB 89 95 ?? ?? ?? ?? 0F B7 01 66 89 04 0A 8D 49 ?? 66 85 C0 75 ?? 8D + BD ?? ?? ?? ?? 83 EF ?? 66 8B 47 ?? 83 C7 ?? 66 3B C6 75 ?? BE ?? ?? ?? ?? 68 ?? ?? + ?? ?? 53 A5 A5 66 A5 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 33 F6 8B 1D ?? ?? ?? ?? + 83 FB ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? + 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 8B C6 + EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B + 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 + 85 D2 75 ?? 8B C6 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B + 95 ?? ?? ?? ?? 0F B7 01 66 89 04 0A 8D 49 ?? 66 85 C0 75 ?? 8D BD ?? ?? ?? ?? 83 EF + ?? 33 C9 66 8B 47 ?? 8D 7F ?? 66 3B C1 75 ?? A1 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 89 07 + 8B F2 66 8B 02 83 C2 ?? 66 3B C1 75 ?? 8D BD ?? ?? ?? ?? 2B D6 83 EF ?? 66 8B 47 ?? + 83 C7 ?? 66 3B C1 75 ?? 8B CA C1 E9 ?? F3 A5 8B CA 83 E1 ?? F6 85 ?? ?? ?? ?? ?? F3 + A4 74 ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? F7 85 ?? ?? ?? ?? + ?? ?? ?? ?? 75 ?? 8B 8D ?? ?? ?? ?? 66 8B 85 ?? ?? ?? ?? 66 89 04 59 43 89 1D ?? ?? + ?? ?? 33 F6 8B 9D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 + ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } - $encrypt_files_p1 = { - 55 89 E5 57 83 EC ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 C0 ?? C7 44 24 ?? ?? ?? ?? - ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? - ?? A1 ?? ?? ?? ?? FF D0 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 - ?? B9 ?? ?? ?? ?? 89 C2 B8 ?? ?? ?? ?? 89 D7 F2 AE 89 C8 F7 D0 8D 50 ?? 8B 45 ?? 01 - D0 66 C7 00 ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? - 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 - 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 89 55 - ?? 83 7D ?? ?? 7F ?? 83 7D ?? ?? 78 ?? 83 7D ?? ?? 77 ?? C7 44 24 ?? ?? ?? ?? ?? 8B - 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 44 24 - ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? - 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 C7 45 ?? ?? ?? ?? ?? DF 6D ?? - DD 5D ?? DD 45 ?? DD 05 ?? ?? ?? ?? DF E9 DD D8 76 ?? 8B 45 ?? 89 45 ?? EB ?? C7 45 - ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 - 7D ?? ?? 75 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC + $find_special_folders = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 BE ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 56 33 DB 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 56 53 50 E8 + ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 56 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? + ?? ?? BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 6A ?? 59 68 ?? ?? ?? ?? 53 F3 A5 50 E8 ?? ?? + ?? ?? 83 C4 ?? 8D BD ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 59 F3 A5 68 + ?? ?? ?? ?? 53 50 66 A5 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D + BD ?? ?? ?? ?? 6A ?? 59 68 ?? ?? ?? ?? 53 F3 A5 50 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 83 C4 ?? 53 6A ?? 50 53 FF D6 53 6A ?? 8D 85 ?? ?? ?? ?? 50 53 FF + D6 53 6A ?? 8D 85 ?? ?? ?? ?? 50 53 FF D6 8D BD ?? ?? ?? ?? 83 EF ?? 66 8B 47 ?? 83 + C7 ?? 66 3B C3 75 ?? 6A ?? 59 BE ?? ?? ?? ?? F3 A5 8D BD ?? ?? ?? ?? 83 EF ?? 66 8B + 47 ?? 83 C7 ?? 66 3B C3 75 ?? 6A ?? 59 BE ?? ?? ?? ?? F3 A5 8D BD ?? ?? ?? ?? 83 EF + ?? 66 8B 47 ?? 83 C7 ?? 66 3B C3 75 ?? BE ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? A5 A5 A5 A5 + 66 A5 E8 ?? ?? ?? ?? 84 C0 74 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } - $encrypt_files_p2 = { - 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF - D0 C7 45 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 15 ?? - ?? ?? ?? A1 ?? ?? ?? ?? 8D 4D ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? C7 - 44 24 ?? ?? ?? ?? ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 75 ?? C7 04 24 ?? - ?? ?? ?? A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? - ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? - ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 C7 04 24 ?? ?? ?? ?? A1 - ?? ?? ?? ?? FF D0 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 - 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 75 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 - 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B - 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 - ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? - ?? ?? 89 45 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 - 7D ?? ?? 74 ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 - 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 44 24 ?? 8B 45 + $remote_connection = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 57 89 85 ?? + ?? ?? ?? 33 DB 8B 45 ?? 8B FA 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 + 50 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? A0 ?? ?? ?? ?? 88 45 ?? 8D 85 ?? + ?? ?? ?? 53 53 53 53 50 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? + 85 DB 74 ?? 33 C0 50 50 6A ?? 50 50 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? ?? 8B F8 85 + FF 74 ?? 33 C0 50 68 ?? ?? ?? ?? 50 50 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 45 ?? 50 + 57 FF 15 ?? ?? ?? ?? 8B D8 85 DB 74 ?? 8B 95 ?? ?? ?? ?? 33 C9 85 D2 74 ?? 8B CA 8D + 41 ?? 89 85 ?? ?? ?? ?? 8A 01 41 84 C0 75 ?? 2B 8D ?? ?? ?? ?? 51 52 6A ?? 6A ?? 53 + FF 15 ?? ?? ?? ?? 53 FF D6 8B 9D ?? ?? ?? ?? 57 FF D6 53 FF D6 8B 4D ?? 5F 5E 33 CD + 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } - $encrypt_files_p3 = { - 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC - ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 - 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? - A1 ?? ?? ?? ?? FF D0 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? 39 55 ?? 7F ?? 39 55 ?? 7C ?? 39 - 45 ?? 77 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? C7 44 24 - ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? - 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 89 54 24 ?? 8D 55 ?? 89 54 24 ?? 8B 55 ?? - 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 55 ?? 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 - 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 8B 55 ?? 89 54 24 ?? 89 44 24 ?? C7 44 - 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? 29 45 ?? - 19 55 ?? 83 7D ?? ?? 0F 8F ?? ?? ?? ?? 83 7D ?? ?? 78 ?? 83 7D ?? ?? 0F 87 ?? ?? ?? - ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 - 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? - ?? FF D0 83 EC ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 + $encrypt_files_1 = { + 55 8B EC 51 51 83 4D ?? ?? 83 4D ?? ?? 57 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 + ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 75 ?? 6A ?? 58 EB ?? 56 8D 45 ?? 50 + 57 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 75 ?? 6A ?? EB ?? 8B 75 ?? 3B C6 0F 42 F0 83 7D + ?? ?? 74 ?? 6A ?? 8D 45 ?? 50 56 FF 75 ?? 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? 5E + 57 FF 15 ?? ?? ?? ?? EB ?? 57 FF 15 ?? ?? ?? ?? 3B 75 ?? 6A ?? 58 0F 45 F0 8B C6 EB + ?? 57 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5E 5F 8B E5 5D C2 } - $find_files_p1 = { - 55 89 E5 57 53 81 EC ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 C0 ?? C7 44 24 - ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? 89 04 24 - E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 44 - 24 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? B9 ?? ?? ?? ?? 89 C2 B8 ?? ?? ?? ?? - 89 D7 F2 AE 89 C8 F7 D0 8D 50 ?? 8B 45 ?? 01 D0 C7 00 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? 83 7D ?? ?? 0F - 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 85 C0 0F 84 ?? ?? ?? ?? 0F B6 95 ?? ?? ?? - ?? 0F B6 05 ?? ?? ?? ?? 0F B6 D2 0F B6 C0 29 C2 89 D0 85 C0 0F 84 ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? - ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? - 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 - E0 ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 C3 8D 85 ?? ?? ?? - ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 01 D8 83 C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 + $encrypt_files_2_p1 = { + 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 33 C0 89 85 ?? ?? ?? + ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 45 ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? C6 45 ?? ?? 50 89 85 ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 59 33 C0 8D 7D ?? + F3 AB 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 85 C0 74 ?? FF 15 ?? ?? ?? ?? 50 + 68 ?? ?? ?? ?? 83 CE ?? EB ?? 6A ?? 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 85 + C0 74 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 5E 6A ?? 8B D6 59 E8 ?? ?? ?? ?? + 59 59 E9 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 85 F6 75 ?? 6A ?? 5E E9 ?? ?? ?? ?? 80 BD ?? + ?? ?? ?? ?? B8 ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? 3B F0 0F 47 F0 8D 85 ?? ?? ?? ?? 50 + 56 8B C8 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 FF B5 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? 8B F8 85 FF 79 ?? FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 6A ?? 5A 6A ?? 59 E8 ?? ?? ?? + ?? 59 59 BE ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? + FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 5A 6A ?? 59 E8 ?? ?? ?? ?? 59 59 6A ?? E9 + ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 8D 55 ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C7 8B DF 25 ?? ?? ?? ?? 79 ?? 48 83 C8 ?? 40 74 ?? 8B } - $find_files_p2 = { - E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? - 89 04 24 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 E8 - ?? ?? ?? ?? 8B 45 ?? B9 ?? ?? ?? ?? 89 C2 B8 ?? ?? ?? ?? 89 D7 F2 AE 89 C8 F7 D0 8D - 50 ?? 8B 45 ?? 01 D0 66 C7 00 ?? ?? A1 ?? ?? ?? ?? 8B 55 ?? 89 54 24 ?? 89 44 24 ?? - C7 04 24 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 - 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? - ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 + $encrypt_files_2_p2 = { + B5 ?? ?? ?? ?? 43 46 8B C3 25 ?? ?? ?? ?? 79 ?? 48 83 C8 ?? 40 75 ?? 89 B5 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 53 8B C8 E8 ?? ?? ?? ?? 33 D2 85 FF 7E ?? 8B 85 ?? ?? ?? ?? + 8A 0C 10 8B 85 ?? ?? ?? ?? 88 0C 10 42 3B D7 7C ?? 3B FB 7D ?? 8B C3 2B C7 50 8B 85 + ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 03 C7 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 + 53 8B C8 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 8B + 95 ?? ?? ?? ?? 8D 45 ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 + ?? 6A ?? E9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 53 FF B5 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 59 59 85 C0 75 ?? 6A ?? 33 FF 5A 8B 85 ?? ?? ?? ?? 8A 4C 3D ?? 88 0C 38 + 47 3B FA 7C ?? 8D 75 ?? 6A ?? 2B F2 5F 8B 85 ?? ?? ?? ?? 8A 0C 32 88 0C 10 42 3B D7 + 7C ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 83 EC ?? 8D + 85 ?? ?? ?? ?? 50 51 8B 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 } - $find_files_p3 = { - 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 - 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 89 04 - 24 E8 ?? ?? ?? ?? 89 C3 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 04 24 E8 ?? ?? ?? ?? 01 D8 83 - C0 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8B - 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 C0 ?? 89 44 - 24 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 55 ?? 89 54 24 ?? 89 44 24 - ?? C7 04 24 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 EB ?? 90 EB ?? 90 EB ?? 90 EB ?? 90 EB - ?? 90 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? - 85 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 - 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 + $encrypt_files_2_p3 = { + 85 C0 79 ?? 6A ?? E9 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? BA ?? ?? ?? ?? 2B F7 8B 85 ?? ?? + ?? ?? 8A 0C 37 88 0C 38 47 3B FA 7C ?? 8B B5 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8A 8C 02 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 88 0C 10 42 81 FA ?? ?? ?? ?? 7C ?? 83 BD ?? ?? ?? ?? ?? + 74 ?? 8D 4D ?? E8 ?? ?? ?? ?? 84 C0 75 ?? BE ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B C6 E9 ?? ?? ?? ?? 51 6A ?? 53 FF B5 ?? ?? ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? 8B F8 85 FF 79 ?? FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 6A ?? 5A 6A ?? 59 E8 + ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 87 ?? ?? ?? ?? + E9 ?? ?? ?? ?? 51 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B + F8 85 FF 79 ?? FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 6A ?? 5A 6A ?? 59 E8 ?? ?? ?? ?? 59 + 59 EB ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 01 34 85 + ?? ?? ?? ?? FF 04 85 ?? ?? ?? ?? 33 FF 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B C7 E8 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and ( all of ($enum_resources_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($find_files) and ($find_special_folders) and ($encrypt_files_1) and ( all of ($encrypt_files_2_p*)) and ($remote_connection) } -rule REVERSINGLABS_Win32_Ransomware_Vegalocker : TC_DETECTION MALICIOUS MALWARE FILE +import "pe" + +rule REVERSINGLABS_Win32_Ransomware_Dirtydecrypt : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects VegaLocker ransomware." + description = "Yara rule that detects DirtyDecrypt ransomware." author = "ReversingLabs" - id = "53eec8d1-bab0-5556-92c0-1b70eb763fa5" + id = "f4d69c3e-a082-5bc9-bf72-4cc330d3de74" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.VegaLocker.yara#L1-L100" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "8616e72fc435676179e83a304d4111c8f29ebf3cd79ff5b2d229cca8fc97c2a3" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.DirtyDecrypt.yara#L3-L112" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "eb6a1c376b0739848b523e741d0d1ebdbc87056d51931fb94c744aa094d6479f" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -34881,153 +36466,105 @@ rule REVERSINGLABS_Win32_Ransomware_Vegalocker : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "VegaLocker" + tc_detection_name = "DirtyDecrypt" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 89 55 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? - ?? 89 C3 85 DB 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 FF D3 85 C0 74 - ?? 8B 45 ?? 50 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 - ?? 80 38 ?? 75 ?? 8B 45 ?? 80 78 ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? E8 ?? ?? - ?? ?? 8B F0 80 3E ?? 0F 84 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F0 80 3E ?? 0F 84 - ?? ?? ?? ?? EB ?? 8B 75 ?? 83 C6 ?? 8B DE 2B 5D ?? 8D 43 ?? 50 8B 45 ?? 50 8D 85 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F8 8B C7 2B C6 - 03 C3 40 3D ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 8B C7 2B C6 40 50 56 8D 85 ?? ?? ?? ?? 03 - C3 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 89 45 - ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? - 8D 53 ?? 03 C2 40 3D ?? ?? ?? ?? 7F ?? C6 84 1D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B C3 - 48 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 03 C3 40 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 40 03 D8 8B F7 80 3E ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 8D 85 - ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 5F 5E 5B 8B E5 5D C3 + $dd_ep = { + 55 8B EC 83 EC ?? E8 ?? ?? ?? ?? 85 C0 0F 84 BF 00 00 00 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 + 1F 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 07 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB + 09 8B 4D ?? 83 C1 ?? 89 4D ?? 83 7D ?? ?? 73 15 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 89 44 95 ?? EB DC 6A ?? 68 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? + 8B 15 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A + ?? 8D 55 ?? 52 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 33 C0 8B E5 5D C2 ?? ?? } - $encrypt_files_p1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D - ?? ?? ?? ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 55 ?? 89 45 ?? 8D 45 ?? E8 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 - FF 30 64 89 20 C6 85 ?? ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 85 - ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 E9 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 55 68 - ?? ?? ?? ?? 64 FF 30 64 89 20 6A ?? 8B 4D ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 - 45 ?? 8B 45 ?? 8B 10 FF 12 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? - 33 D2 8B 45 ?? 8B 08 FF 51 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B - 45 ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C6 - 85 ?? ?? ?? ?? ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 - 64 89 10 EB ?? E9 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 + $dd_hash = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 D5 00 00 00 83 7D ?? ?? 0F 84 CB 00 00 00 83 7D ?? ?? 0F 84 C1 + 00 00 00 83 7D ?? ?? 0F 84 B7 00 00 00 83 7D ?? ?? 0F 84 AD 00 00 00 83 7D ?? ?? 0F 84 A3 00 00 00 C7 45 ?? ?? ?? ?? ?? + 8D 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 C0 75 02 EB 6F 83 7D ?? ?? 76 2A 6A ?? 6A ?? 8B + 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 02 EB 51 8B 4D ?? 83 E9 ?? 89 4D ?? 8B 55 ?? 83 C2 ?? 89 55 ?? 6A ?? 8B + 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 02 EB 25 6A ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B + 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 33 C9 0F 85 74 FF FF FF 83 7D ?? ?? 74 0A 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 8B + E5 5D C2 ?? ?? } - $encrypt_files_p2 = { - 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 8B 4D ?? B2 ?? - A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 10 FF 12 89 85 ?? ?? ?? ?? 89 95 - ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 83 BD ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? EB ?? - 0F 8E ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 76 ?? EB - ?? 7E ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 85 ?? - ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? - ?? 8D 45 ?? E8 ?? ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 85 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 83 FB ?? 7F ?? - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? - ?? 8D 45 ?? E8 ?? ?? ?? ?? 43 83 FB ?? 75 ?? 8B 85 ?? ?? ?? ?? 8B D0 8D 45 ?? E8 ?? - ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B D0 8B 8D ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 83 - BD ?? ?? ?? ?? ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 8D 45 ?? BA + $dd_getkey = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 31 C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8D 4D ?? 51 6A ?? 8B 55 + ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 07 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? C1 E8 ?? 89 45 ?? 8B 45 ?? 8B E5 5D C2 ?? ?? } - $encrypt_files_p3 = { - E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? - EB ?? 8D 45 ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 33 D2 8B 45 ?? 8B - 08 FF 51 ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 8D 45 ?? - E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 55 E8 ?? ?? ?? ?? 59 55 E8 ?? ?? - ?? ?? 59 EB ?? 55 E8 ?? ?? ?? ?? 59 A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? - ?? 8B 45 ?? E8 ?? ?? ?? ?? 55 E8 ?? ?? ?? ?? 59 C6 85 ?? ?? ?? ?? ?? 8B 45 ?? E8 ?? - ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? - 64 FF 30 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $dd_destroykey = { + 55 8B EC 83 7D ?? ?? 74 0A 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 5D C2 } - - condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) -} -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Povlsomware : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Povlsomware ransomware." - author = "ReversingLabs" - id = "317d7cca-4fe8-55ab-8f5f-e42be727ec26" - date = "2021-08-12" - modified = "2021-08-12" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Povlsomware.yara#L1-L64" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "465dc1b1d7e9eb3091f36efb51029cd3383d05ece054e814b18f379e58c7e457" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Povlsomware" - tc_detection_factor = 5 - importance = 25 - - strings: - $setup_attack = { - 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? - ?? ?? 73 ?? ?? ?? ?? 0A 06 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 2C ?? - 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 8E 69 80 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? - 0C 16 0D 2B ?? 08 09 9A 13 ?? 00 7E ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 00 00 09 17 58 0D - 09 08 8E 69 32 ?? 00 38 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 - ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 1A 6F ?? ?? ?? - ?? 00 11 ?? 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? - 13 ?? 2B ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 00 00 11 ?? 28 ?? ?? ?? ?? 00 00 DE ?? 26 00 00 - DE ?? 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC - 28 ?? ?? ?? ?? 00 00 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 00 2A + $dd_importkey = { + 55 8B EC 51 C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? 8B 4D ?? 8B 51 ?? 52 8B 45 ?? 8B 08 51 8B 55 ?? 52 FF 15 ?? ?? + ?? ?? 8B 45 ?? 8B E5 5D C2 ?? ?? } - $find_files = { - 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? - ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 00 06 6F ?? ?? ?? ?? 0C 2B ?? - 08 6F ?? ?? ?? ?? 0D 00 7E ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 00 00 08 6F ?? ?? ?? ?? 2D ?? - DE ?? 08 2C ?? 08 6F ?? ?? ?? ?? 00 DC 02 28 ?? ?? ?? ?? 0B 00 07 13 ?? 16 13 ?? 38 ?? - ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 00 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 16 FE 01 2B ?? 16 13 ?? 11 ?? 2C ?? 00 11 ?? 03 28 ?? ?? ?? ?? 00 00 00 - DE ?? 26 00 00 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 2A + $dd_decrypt = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 22 01 00 00 83 7D ?? ?? 0F 84 18 01 00 00 83 7D ?? ?? 0F 84 0E + 01 00 00 83 7D ?? ?? 0F 84 04 01 00 00 83 7D ?? ?? 0F 84 FA 00 00 00 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 33 D2 + F7 75 ?? 0F AF 45 ?? 89 45 ?? 8B 4D ?? 89 4D ?? 8B 55 ?? 8B 02 03 45 ?? 89 45 ?? 8B 4D ?? 8B 11 03 55 ?? 52 8B 45 ?? 8B + 08 51 6A ?? E8 ?? ?? ?? ?? 8B 55 ?? 89 02 8B 45 ?? 83 38 ?? 0F 84 A7 00 00 00 8B 4D ?? 8B 11 8B 45 ?? 03 10 89 55 ?? 83 + 7D ?? ?? 74 61 6A ?? 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 45 ?? + 89 45 ?? 8D 4D ?? 51 8B 55 ?? 52 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 02 EB 1D 8B 4D ?? 03 4D ?? 89 + 4D ?? 8B 55 ?? 2B 55 ?? 89 55 ?? 8B 45 ?? 03 45 ?? 89 45 ?? EB 99 83 7D ?? ?? 75 15 8B 4D ?? 89 4D ?? 8B 55 ?? 8B 45 ?? + 2B 02 8B 4D ?? 89 01 EB 18 8B 55 ?? 8B 02 50 8B 4D ?? 8B 11 52 6A ?? E8 ?? ?? ?? ?? 8B 4D ?? 89 01 8B 45 ?? 8B E5 5D C2 + ?? ?? } - $encrypt_files = { - 00 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 06 2C ?? 2B ?? 02 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 6F ?? ?? ?? ?? 0B 07 2C ?? 2B ?? 02 28 ?? ?? ?? ?? 00 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 17 58 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 02 6F ?? ?? ?? - ?? 00 7E ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 2A + $dd_encrypt = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 89 01 00 00 83 7D ?? ?? 0F 84 7F 01 00 00 83 7D ?? ?? 0F 84 75 + 01 00 00 83 7D ?? ?? 0F 84 6B 01 00 00 83 7D ?? ?? 0F 84 61 01 00 00 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 8B 4D ?? 83 E9 + ?? 89 4D ?? 8B 55 ?? 89 55 ?? 6A ?? 8D 45 ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 C0 0F 84 26 01 + 00 00 8B 55 ?? 3B 55 ?? 76 08 8B 45 ?? 89 45 ?? EB 06 8B 4D ?? 89 4D ?? 8B 55 ?? 89 55 ?? 8B 45 ?? 33 D2 F7 75 ?? 0F AF + 45 ?? 8B 4D ?? 8B 11 03 D0 03 55 ?? 89 55 ?? 8B 45 ?? 50 8B 4D ?? 8B 11 52 6A ?? E8 ?? ?? ?? ?? 8B 4D ?? 89 01 8B 55 ?? + 83 3A ?? 0F 84 CF 00 00 00 8B 45 ?? 8B 08 8B 55 ?? 03 0A 89 4D ?? 83 7D ?? ?? 0F 84 84 00 00 00 8B 45 ?? 3B 45 ?? 73 08 + 8B 4D ?? 89 4D ?? EB 06 8B 55 ?? 89 55 ?? 8B 45 ?? 89 45 ?? 6A ?? 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B + 4D ?? 89 4D ?? 8B 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 02 EB 2D 8B + 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 55 ?? 03 55 ?? 89 55 ?? 8B 45 ?? 2B 45 ?? 89 45 ?? 8B 4D ?? 03 4D ?? 89 4D ?? E9 + 72 FF FF FF 83 7D ?? ?? 75 16 8B 55 ?? 8B 45 ?? 2B 02 8B 4D ?? 89 01 C7 45 ?? ?? ?? ?? ?? EB 18 8B 55 ?? 8B 02 50 8B 4D + ?? 8B 11 52 6A ?? E8 ?? ?? ?? ?? 8B 4D ?? 89 01 8B 45 ?? 8B E5 5D C2 ?? ?? + } + $dd_provparam = { + 55 8B EC 83 EC ?? 83 7D ?? ?? 0F 84 94 00 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A ?? 6A ?? + 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 C0 74 3F 8B 55 ?? 83 C2 ?? 52 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 2A 6A ?? 8D 45 ?? + 50 8B 4D ?? 51 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 10 8B 45 ?? 50 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8B + 4D ?? 51 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 74 1D 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 E8 + ?? ?? ?? ?? 8B E5 5D C2 ?? ?? + } + $dd_acquirecontext = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 0B 8B 45 ?? 0D ?? ?? ?? ?? 89 45 ?? C7 45 ?? + ?? ?? ?? ?? 83 7D ?? ?? 75 07 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 03 45 ?? 50 6A ?? 6A ?? 6A ?? 8D 4D ?? 51 E8 ?? ?? ?? + ?? 8B 55 ?? 52 6A ?? 8B 45 ?? 50 8D 4D ?? 51 8D 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 39 8B 45 ?? 83 C8 ?? 50 6A ?? 8B 4D + ?? 51 8D 55 ?? 52 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 1A 6A ?? 6A ?? 6A ?? 8D 4D ?? 51 8D 55 ?? 52 FF 15 ?? ?? ?? ?? + 85 C0 75 02 EB 0E 6A ?? FF 15 ?? ?? ?? ?? 83 7D ?? ?? 74 9D 8B 45 ?? 8B E5 5D C2 ?? ?? + } + $dd_mrwhite = { + 55 8B EC 81 EC ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 64 01 00 00 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8D + 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 12 83 3D ?? ?? ?? ?? ?? 74 09 83 3D ?? ?? ?? ?? ?? 75 05 E9 13 + 01 00 00 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 85 C0 75 05 E9 F0 00 00 00 8B 95 + ?? ?? ?? ?? 52 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 + 05 E9 C0 00 00 00 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 85 C0 74 09 83 BD ?? ?? ?? ?? ?? 73 05 E9 9B + 00 00 00 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 + 75 02 EB 72 8B 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 02 83 C0 ?? 3B 85 ?? ?? ?? ?? 76 02 EB 51 8B 8D ?? + ?? ?? ?? 83 39 ?? 74 3E 0F B7 95 ?? ?? ?? ?? 83 FA ?? 75 32 8B 85 ?? ?? ?? ?? 8B 08 51 8B 95 ?? ?? ?? ?? 83 C2 ?? 52 6A + ?? 8D 85 ?? ?? ?? ?? 50 8B 0D ?? ?? ?? ?? 51 8B 15 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 89 45 ?? 33 C0 0F 85 CD FE FF FF 8D 8D + ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 8B 45 ?? 8B E5 5D C2 ?? ?? } condition: - uint16(0)==0x5A4D and ($setup_attack) and ($find_files) and ($encrypt_files) + uint16(0)==0x5A4D and ($dd_ep at pe.entry_point) and $dd_hash and $dd_getkey and $dd_destroykey and $dd_importkey and $dd_decrypt and $dd_encrypt and $dd_provparam and $dd_acquirecontext and $dd_mrwhite } -rule REVERSINGLABS_Win32_Ransomware_Braincrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Policerecords : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects BrainCrypt ransomware." + description = "Yara rule that detects PoliceRecords ransomware." author = "ReversingLabs" - id = "190798d5-594d-5b80-aa0e-8d7ff167f1c0" - date = "2020-07-15" - modified = "2020-07-15" + id = "bacd3f98-a069-58ca-8423-01fcef7d4062" + date = "2022-08-02" + modified = "2022-08-02" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.BrainCrypt.yara#L1-L121" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "85866d6ffa136bf3ed27bbab55ae5430af4a1363930ebacab0df9ad24f8734cb" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.PoliceRecords.yara#L1-L79" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "55cb1a5d030c47abb1a9ca9970fb19b3124128e409bc9515c173c33b2bb49a16" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -35035,119 +36572,68 @@ rule REVERSINGLABS_Win32_Ransomware_Braincrypt : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "BrainCrypt" + tc_detection_name = "PoliceRecords" tc_detection_factor = 5 importance = 25 strings: - $get_files_for_encryption_32 = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? 80 7C 24 - ?? ?? 74 ?? 8B 5C 24 ?? 89 1C 24 8B 5C 24 ?? 89 5C 24 ?? BB ?? ?? ?? ?? 89 5C 24 ?? - E8 ?? ?? ?? ?? 83 C4 ?? C3 83 3D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? - 83 C3 ?? FC 8B 0B 89 0C 24 8B 4B ?? 89 4C 24 ?? 83 3D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? - ?? 8B 1D ?? ?? ?? ?? 83 C3 ?? 8D 7C 24 ?? FC 8B 0B 89 0F 8B 4B ?? 89 4F ?? E8 ?? ?? - ?? ?? 8B 5C 24 ?? 89 1D ?? ?? ?? ?? 8B 5C 24 ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 89 1D ?? - ?? ?? ?? 8B 5C 24 ?? 89 1C 24 8B 5C 24 ?? 89 5C 24 ?? BB ?? ?? ?? ?? 89 5C 24 ?? E8 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 0C 24 8B 44 24 ?? C7 04 24 ?? ?? ?? ?? 89 4C 24 ?? 89 - 4C 24 ?? 89 44 24 ?? 89 44 24 ?? BB ?? ?? ?? ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 5C 24 ?? FC 8B 0B 89 0C 24 8B 4B ?? 89 4C 24 ?? E8 ?? ?? ?? ?? E9 - ?? ?? ?? ?? BD ?? ?? ?? ?? 89 2C 24 89 5C 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 0F 0B E8 ?? ?? ?? ?? 0F 0B E8 ?? ?? ?? ?? E9 - } - $encrypt_file_32 = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? 8B 5C 24 - ?? 89 1C 24 8B 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B 54 24 ?? 8B 4C 24 ?? 8B 44 24 - ?? 89 54 24 ?? 89 14 24 89 4C 24 ?? 89 4C 24 ?? 89 44 24 ?? 89 44 24 ?? 8B 5C 24 ?? - 89 5C 24 ?? 8B 5C 24 ?? 89 5C 24 ?? 8B 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B 54 24 - ?? 8B 4C 24 ?? 8B 44 24 ?? 8B 5C 24 ?? 89 1C 24 8B 5C 24 ?? 89 5C 24 ?? 89 54 24 ?? - 89 54 24 ?? 89 4C 24 ?? 89 4C 24 ?? 89 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 C4 ?? C3 E8 ?? ?? ?? ?? E9 - } - $attach_to_server_32 = { - 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? 31 DB 89 - 5C 24 ?? 89 5C 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 89 CF 83 F9 ?? - 0F 84 ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 89 4C 24 ?? 89 0C 24 83 3C 24 ?? 0F 84 ?? ?? - ?? ?? 8B 5C 24 ?? 89 5C 24 ?? 8B 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 89 - 1C 24 83 3C 24 ?? 0F 84 ?? ?? ?? ?? BB ?? ?? ?? ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 89 1C 24 83 3C 24 ?? 0F 84 ?? ?? ?? ?? BB ?? ?? ?? ?? - 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 89 1C 24 83 3C 24 ?? - 0F 84 ?? ?? ?? ?? 8B 5C 24 ?? 89 5C 24 ?? 8B 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B - 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 31 DB 89 5C 24 ?? 89 5C 24 ?? 31 ED 39 E8 0F 85 - ?? ?? ?? ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 4C 24 ?? 89 0C 24 89 44 24 ?? 89 44 24 - ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 48 ?? 8B 68 - ?? 89 6C 24 ?? 89 6C 24 ?? 89 4C 24 ?? 83 F9 ?? 0F 84 ?? ?? ?? ?? 8D 59 ?? C7 04 24 - ?? ?? ?? ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? C7 04 24 ?? ?? ?? - ?? 8B 44 24 ?? 83 F8 ?? 74 ?? 83 C0 ?? 8D 7C 24 ?? FC 8B 08 89 0F 8B 48 ?? 89 4F ?? - E8 ?? ?? ?? ?? 8D 5C 24 ?? FC 8B 0B 89 0C 24 8B 4B ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B - 54 24 ?? 8B 4C 24 ?? 8B 44 24 ?? C7 04 24 ?? ?? ?? ?? 89 54 24 ?? 89 54 24 ?? 89 4C - 24 ?? 89 4C 24 ?? 89 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 89 5C 24 ?? 8B - 5C 24 ?? 89 5C 24 ?? 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 + $encrypt_files = { + 00 72 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 07 06 6F ?? ?? ?? ?? 0C 04 0D 09 18 73 ?? ?? ?? + ?? 13 ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 08 08 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? + 03 19 73 ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 11 ?? D2 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? + 25 13 ?? 15 FE 01 16 FE 01 13 ?? 11 ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? + ?? 00 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 26 00 00 DE ?? 2A } - $get_files_for_encryption_64 = { - 65 48 8B 0C 25 ?? ?? ?? ?? 48 8B 89 ?? ?? ?? ?? 48 3B 61 ?? 0F 86 ?? ?? ?? ?? 48 83 - EC ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? 0F B6 44 24 ?? 84 C0 0F 85 ?? ?? ?? ?? 48 8B 05 - ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 83 F9 ?? 0F 86 ?? ?? ?? ?? 48 8B 48 ?? 48 8B 40 - ?? 48 89 0C 24 48 89 44 24 ?? 48 8B 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 83 F9 ?? - 0F 86 ?? ?? ?? ?? 48 8B 48 ?? 48 8B 40 ?? 48 89 4C 24 ?? 48 89 44 24 ?? E8 ?? ?? ?? - ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 89 0D ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 84 C9 0F 85 - ?? ?? ?? ?? 48 89 05 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 04 24 48 8B 44 24 ?? 48 89 44 - 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 04 24 - 48 8B 4C 24 ?? 48 C7 04 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 4C 24 ?? 48 8D 05 ?? ?? - ?? ?? 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B - 4C 24 ?? 48 89 04 24 48 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 6C 24 ?? 48 83 C4 ?? C3 48 - 8D 0D ?? ?? ?? ?? 48 89 0C 24 48 89 44 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 0F 0B 48 8B 44 24 ?? 48 89 04 24 48 8B 44 24 ?? 48 89 44 24 ?? 48 8D 05 ?? ?? - ?? ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? E9 + $find_files = { + 11 ?? 11 ?? 9A 13 ?? 00 00 07 11 ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 00 11 ?? 28 ?? ?? ?? ?? 00 00 DE ?? 26 00 00 DE ?? 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E + 69 32 ?? 00 DE ?? 26 00 00 DE ?? 17 8D ?? ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 0C 16 13 ?? + 2B ?? 00 00 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 08 11 ?? 9A 28 ?? ?? ?? ?? 00 + 72 ?? ?? ?? ?? 08 11 ?? 9A 28 ?? ?? ?? ?? 18 28 ?? ?? ?? ?? 00 00 DE ?? 26 00 00 DE ?? + 00 11 ?? 17 58 13 ?? 11 ?? 08 8E 69 FE 04 13 ?? 11 ?? 2D ?? 00 00 72 ?? ?? ?? ?? 1D 28 + ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 1D 28 ?? ?? ?? ?? 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 DE ?? 26 00 00 DE ?? 7E ?? ?? + ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0D 09 72 ?? ?? ?? ?? 17 8C ?? ?? ?? ?? 1A 6F ?? ?? + ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 16 8C + ?? ?? ?? ?? 1A 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 + ?? 72 ?? ?? ?? ?? 17 8C ?? ?? ?? ?? 1A 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 17 8C ?? ?? ?? ?? 1A 6F ?? ?? ?? ?? 00 7E ?? + ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 6F + ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? + 72 ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 00 07 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? + 13 ?? 11 ?? 6F ?? ?? ?? ?? 00 73 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 26 2A } - $attach_to_server_64 = { - 65 48 8B 0C 25 ?? ?? ?? ?? 48 8B 89 ?? ?? ?? ?? 48 3B 61 ?? 0F 86 ?? ?? ?? ?? 48 83 - EC ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? - ?? ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 04 24 E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 48 89 - 7C 24 ?? 84 07 0F 57 C0 48 83 C7 ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? E8 ?? ?? ?? ?? 48 - 8B 6D ?? 48 8B 44 24 ?? 48 89 04 24 48 8B 4C 24 ?? 48 89 4C 24 ?? 48 8B 4C 24 ?? 48 - 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 04 24 48 8D 0D ?? ?? ?? ?? 48 89 4C - 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 04 24 48 8D 0D - ?? ?? ?? ?? 48 89 4C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? - 48 89 04 24 48 8B 4C 24 ?? 48 89 4C 24 ?? 48 8B 4C 24 ?? 48 89 4C 24 ?? E8 ?? ?? ?? - ?? 48 8B 44 24 ?? 48 8B 48 ?? 48 8B 10 48 8B 58 ?? 48 8B 40 ?? 48 39 CB 0F 87 ?? ?? - ?? ?? 48 29 D9 48 29 D8 48 85 C0 0F 84 ?? ?? ?? ?? 48 C7 04 24 ?? ?? ?? ?? 48 01 DA - 48 89 54 24 ?? 48 89 4C 24 ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C - 24 ?? 48 89 0C 24 48 89 44 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 44 24 ?? 48 8B - 48 ?? 48 8B 50 ?? 84 01 48 89 54 24 ?? C7 04 24 ?? ?? ?? ?? 48 83 C1 ?? 48 89 4C 24 - ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 04 24 48 8B 44 - 24 ?? 48 8B 48 ?? 48 8B 40 ?? 48 89 4C 24 ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? 48 8B 44 - 24 ?? 48 8B 4C 24 ?? 48 89 04 24 48 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B - 4C 24 ?? 48 8B 54 24 ?? 48 C7 04 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 4C 24 ?? 48 89 - 54 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 89 44 24 ?? 48 89 8C 24 ?? - ?? ?? ?? 90 E8 ?? ?? ?? ?? 48 8B 6C 24 ?? 48 83 C4 ?? C3 90 E8 ?? ?? ?? ?? 48 8B 6C - 24 ?? 48 83 C4 ?? C3 31 DB E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 0B E8 ?? ?? ?? ?? E9 + $desktop_kill_tick = { + 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 0A 06 72 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 0B 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 08 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 09 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 13 ?? 07 28 ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 07 28 ?? ?? ?? ?? 00 + 00 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 11 ?? 28 ?? ?? ?? ?? 00 00 02 7B ?? ?? ?? + ?? 6F ?? ?? ?? ?? 00 2A } - $encrypt_file_64 = { - 65 48 8B 0C 25 ?? ?? ?? ?? 48 8B 89 ?? ?? ?? ?? 48 3B 61 ?? 0F 86 ?? ?? ?? ?? 48 83 - EC ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? 48 8B 44 24 ?? 48 89 04 24 48 8B 44 24 ?? 48 89 - 44 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 8B 54 24 ?? 48 89 04 24 48 - 89 4C 24 ?? 48 89 54 24 ?? 48 8B 44 24 ?? 48 89 44 24 ?? 48 8B 84 24 ?? ?? ?? ?? 48 - 89 44 24 ?? 48 8B 84 24 ?? ?? ?? ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 - 8B 4C 24 ?? 48 8B 54 24 ?? 48 8B 5C 24 ?? 48 89 1C 24 48 8B 5C 24 ?? 48 89 5C 24 ?? - 48 89 44 24 ?? 48 89 4C 24 ?? 48 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 48 8B 6C 24 ?? 48 83 C4 ?? C3 E8 ?? ?? ?? ?? E9 + $drop_ransom_note = { + 00 16 28 ?? ?? ?? ?? 0A 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 00 07 72 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 00 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 72 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 00 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 + 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 DE ?? 07 2C ?? + 07 6F ?? ?? ?? ?? 00 DC 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 26 2A } condition: - uint16(0)==0x5A4D and (($get_files_for_encryption_32 and $encrypt_file_32 and $attach_to_server_32) or ($get_files_for_encryption_64 and $encrypt_file_64 and $attach_to_server_64)) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($desktop_kill_tick) and ($drop_ransom_note) } -rule REVERSINGLABS_Win32_Ransomware_Clop : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Cryakl : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Clop ransomware." + description = "Yara rule that detects Cryakl ransomware." author = "ReversingLabs" - id = "0ea63119-3773-5404-b332-8e3966fd35df" + id = "5c668278-458e-5b13-83c4-63beab5249ed" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Clop.yara#L1-L109" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0b63db16a4b1cae27a97d0ff9df692a63f1a11120ffac69c05a5c71fbd224007" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Cryakl.yara#L1-L64" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "51d50ab1ce021e2facbca3a35af372186287a8d69b66651c9804234a409d9932" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -35155,100 +36641,64 @@ rule REVERSINGLABS_Win32_Ransomware_Clop : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Clop" + tc_detection_name = "Cryakl" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_p1 = { - 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 6A ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? - 83 C4 ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 83 BD ?? - ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 6A ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 8D ?? ?? ?? - ?? 51 FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? - ?? 8B 88 ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 8B 82 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 8B - 91 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 E8 - ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? - ?? 52 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 83 BD ?? ?? ?? ?? ?? 74 ?? - 68 ?? ?? ?? ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 - ?? 68 ?? ?? ?? ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? - 74 ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? - ?? ?? 52 FF 15 - } - $encrypt_files_p2 = { - 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 50 8D - 4D ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 52 FF - 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8B 0D ?? ?? ?? ?? 51 8D 95 ?? - ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 - ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 6A ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? - ?? 85 C0 75 ?? 33 C0 E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 6A ?? - 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? - ?? 85 C0 75 ?? 33 C0 E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A - ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 C0 E9 ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 6A ?? 8B - 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 C0 E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? 85 D2 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8B 8D - ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 6A ?? 6A ?? E8 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 50 - 68 ?? ?? ?? ?? 8D 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 6A ?? 6A ?? E8 ?? ?? - ?? ?? 50 8B 15 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 C0 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B - E5 5D C2 - } - $encrypt_files_p3 = { - 55 8B EC 83 EC ?? 6A ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B - 4D ?? 51 8D 55 ?? 52 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 - ?? FF 15 ?? ?? ?? ?? 33 C0 EB ?? 8B 4D ?? 51 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 - ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 8D 4D ?? - 51 8B 55 ?? 52 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? - ?? ?? ?? 33 C0 EB ?? 8B 4D ?? 8B 55 ?? 89 11 33 C0 8B E5 5D C3 - } - $find_files = { - 8D 95 ?? ?? ?? ?? 52 6A ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 - 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? - 8D 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD - ?? ?? ?? ?? ?? 75 ?? EB ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 - C0 76 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 83 C4 ?? EB ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 6A ?? 68 - ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? 6A ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? - 51 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 8B 85 ?? ?? - ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 E8 + $enum_and_encrypt_files_1 = { + 8B 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 5A E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 5A E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 5A E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 5A E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF + 30 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 80 7C 02 ?? ?? 74 ?? 8D 45 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? + E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 83 E0 ?? 83 F8 ?? 75 ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 8B 10 FF 92 ?? ?? ?? ?? + 84 C0 0F 84 ?? ?? ?? ?? FF 75 ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 } - $uninstall_eset_av = { - 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 86 ?? ?? ?? ?? 8D 4D ?? 51 68 ?? ?? ?? ?? 8D - 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 68 ?? - ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 8D ?? - ?? ?? ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 7D ?? 68 ?? ?? ?? - ?? 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? - ?? ?? 6A ?? 6A ?? 6A ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? - FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 6A - ?? 6A ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? E9 ?? - ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 + $enum_and_encrypt_files_2 = { + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8D 95 ?? + ?? ?? ?? 33 C0 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 58 E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? + C6 45 ?? ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 8B 10 FF 52 ?? 8B D8 + 4B 85 DB 0F 8C ?? ?? ?? ?? 43 33 F6 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8D 8D ?? + ?? ?? ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 8B D6 8B 38 FF 57 ?? 8B + 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 58 E8 ?? ?? ?? ?? 75 ?? C6 45 ?? ?? + 46 4B 0F 85 ?? ?? ?? ?? 80 7D ?? ?? 0F 84 ?? ?? ?? ?? A1 ?? ?? ?? ?? 50 A1 ?? ?? ?? + ?? 50 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 8B 0D ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 15 ?? ?? ?? + ?? 83 C0 ?? 83 D2 ?? 89 05 ?? ?? ?? ?? 89 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? + ?? ?? 8B 10 FF 92 ?? ?? ?? ?? 84 C0 75 ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? + ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($uninstall_eset_av) + uint16(0)==0x5A4D and (( all of ($enum_and_encrypt_files_*))) } -rule REVERSINGLABS_Win32_Ransomware_Sevensevenseven : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Moisha : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects SevenSevenSeven ransomware." + description = "Yara rule that detects Moisha ransomware." author = "ReversingLabs" - id = "049531bd-9505-5da1-9512-980383c8c5ec" - date = "2020-07-15" - modified = "2020-07-15" + id = "c72f654f-955e-5ff6-ac91-19fbb858265c" + date = "2022-10-11" + modified = "2022-10-11" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.SevenSevenSeven.yara#L1-L148" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "583a8ac746cd749bd3927f10c864a3ac84f82f8bbd8d0ebf117e22b016d7ca94" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Moisha.yara#L1-L86" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "89cefbbb8ec722216721bb43eb14cc33fcd4671585051359a06b62236cbf3a6c" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -35256,124 +36706,77 @@ rule REVERSINGLABS_Win32_Ransomware_Sevensevenseven : TC_DETECTION MALICIOUS MAL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "SevenSevenSeven" + tc_detection_name = "Moisha" tc_detection_factor = 5 importance = 25 strings: - $file_search_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? - ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 45 ?? 53 56 57 89 65 ?? BE ?? ?? ?? ?? 89 75 - ?? 33 DB 89 5D ?? 88 5D ?? 89 75 ?? 89 5D ?? 88 5D ?? 89 75 ?? 88 5D ?? 68 ?? ?? ?? - ?? 8B 45 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 53 50 8D 4D ?? E8 - ?? ?? ?? ?? BF ?? ?? ?? ?? 39 BD ?? ?? ?? ?? 72 ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? - ?? 83 C4 ?? 39 7D ?? 8B 45 ?? 73 ?? 8D 45 ?? 8D 8D ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? - ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? EB ?? BE ?? ?? ?? ?? 90 6A ?? 53 8D - 4D ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8B 45 ?? 50 8D 8D ?? ?? ?? - ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? - 53 50 8D 4D ?? E8 ?? ?? ?? ?? 39 BD ?? ?? ?? ?? 72 ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 89 B5 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? 39 BD ?? ?? ?? - ?? 72 ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 B5 ?? ?? ?? ?? 89 9D ?? ?? - ?? ?? 88 9D ?? ?? ?? ?? 39 7D ?? 8B 75 ?? 73 ?? 8D 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? - ?? ?? ?? 85 C0 74 ?? B8 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 - } - $file_search_p2 = { - 74 ?? B8 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? F7 D8 1B C0 F7 D8 3B - C3 0F 85 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 - ?? 8B 45 ?? 3A C3 0F 84 ?? ?? ?? ?? 50 8D 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 3B - F3 0F 84 ?? ?? ?? ?? 39 7D ?? 72 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 39 7D ?? 72 - ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 89 5D ?? 88 5D ?? 39 7D - ?? 0F 82 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 E9 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 38 1E 74 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? - ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF - 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 89 5D ?? - 39 7D ?? 8B 45 ?? 73 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? EB - ?? B8 ?? ?? ?? ?? C3 + $find_files_p1 = { + 73 ?? ?? ?? ?? 0A 02 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 2B ?? 07 6F ?? ?? ?? ?? 0C 08 28 + ?? ?? ?? ?? 2D ?? 06 08 6F ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 2D ?? DE ?? 07 2C ?? 07 6F ?? + ?? ?? ?? DC DE ?? 26 DE ?? 06 2A } - $encrypt_file_1 = { - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 55 8B AC 24 ?? ?? ?? ?? 56 55 89 84 24 ?? ?? ?? ?? - 33 F6 FF 15 ?? ?? ?? ?? 33 C9 85 C0 76 ?? 8D 9B ?? ?? ?? ?? 80 3C 29 ?? 75 ?? 46 41 - 3B C8 72 ?? 83 FE ?? 75 ?? 5E 33 C0 5D 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? - ?? ?? ?? C3 57 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 8B - F8 83 FF ?? 75 ?? 5F 5E 33 C0 5D 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? - ?? C3 53 6A ?? 57 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 73 ?? 57 FF 15 ?? ?? ?? ?? 5B 5F - 5E 33 C0 5D 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 53 6A ?? FF 15 - ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 57 8B F0 FF 15 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 53 56 - 57 FF 15 ?? ?? ?? ?? 33 C0 85 DB 76 ?? 8D 49 ?? 80 34 30 ?? 40 3B C3 72 ?? 6A ?? 6A - ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 6A ?? 8D 4C 24 ?? 51 53 56 57 FF 15 ?? ?? ?? ?? 57 FF - 15 ?? ?? ?? ?? 8D 54 24 ?? 52 FF 15 ?? ?? ?? ?? 0F B7 44 24 ?? 0F B7 4C 24 ?? 0F B7 - 54 24 ?? 68 ?? ?? ?? ?? 50 0F B7 44 24 ?? 51 0F B7 4C 24 ?? 52 0F B7 54 24 ?? 50 51 - 52 55 8D 44 24 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? 51 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 C4 ?? 8D 54 24 ?? 52 55 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B - 8C 24 ?? ?? ?? ?? 5B 5F 5E B8 ?? ?? ?? ?? 5D E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 + $find_files_p2 = { + 02 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 0A 06 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? + 0B 2B ?? 07 6F ?? ?? ?? ?? 0C 08 6F ?? ?? ?? ?? 0D 03 09 6F ?? ?? ?? ?? 04 2C ?? 04 09 + 6F ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 2D ?? DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC 06 6F ?? ?? + ?? ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 03 04 + 28 ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? + ?? ?? ?? DC 02 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 03 11 ?? 6F ?? ?? ?? ?? 04 2C ?? 04 + 11 ?? 6F ?? ?? ?? ?? 2A } - $encrypt_file_2 = { - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 55 8B AC 24 ?? ?? ?? ?? 56 55 89 84 24 ?? ?? ?? ?? - 33 F6 FF 15 ?? ?? ?? ?? 33 C9 85 C0 76 ?? 8D 9B ?? ?? ?? ?? 80 3C 29 ?? 75 ?? 46 41 - 3B C8 72 ?? 83 FE ?? 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 55 FF 15 ?? - ?? ?? ?? 8B F0 83 FE ?? 75 ?? 5E 33 C0 5D 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 - ?? ?? ?? ?? C3 53 6A ?? 56 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 73 ?? 56 FF 15 ?? ?? ?? - ?? 5B 5E 33 C0 5D 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 57 8D 83 - ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 8B F8 FF 15 ?? ?? ?? ?? - 6A ?? 8D 4C 24 ?? 51 53 57 56 FF 15 ?? ?? ?? ?? 8B CB C1 E9 ?? 41 74 ?? 8D 47 ?? B2 - ?? 80 70 ?? ?? 80 70 ?? ?? 80 30 ?? 80 70 ?? ?? 80 70 ?? ?? 80 70 ?? ?? 80 70 ?? ?? - 30 50 ?? 83 C0 ?? 49 75 ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8D 54 24 ?? - 52 53 57 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? - 0F B7 4C 24 ?? 0F B7 54 24 ?? 0F B7 44 24 ?? 68 ?? ?? ?? ?? 51 0F B7 4C 24 ?? 52 0F - B7 54 24 ?? 50 0F B7 44 24 ?? 51 52 50 55 8D 4C 24 ?? 68 ?? ?? ?? ?? 51 FF 15 ?? ?? - ?? ?? 8D 54 24 ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 55 FF 15 - ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5B 5E B8 ?? ?? ?? ?? 5D E8 - ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 + $find_files_p3 = { + 73 ?? ?? ?? ?? 0A 06 03 7D ?? ?? ?? ?? 06 04 7D ?? ?? ?? ?? 06 05 7D ?? ?? ?? ?? 02 28 + ?? ?? ?? ?? 39 ?? ?? ?? ?? 06 02 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 06 7B ?? + ?? ?? ?? 2C ?? 06 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 31 ?? 06 7B ?? ?? ?? ?? 2C ?? 06 FE + 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0B 07 17 6F ?? ?? ?? ?? 07 17 6F ?? ?? ?? + ?? 7E ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 07 6F ?? ?? ?? ?? DE ?? 26 DE ?? 02 28 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 2B ?? 12 ?? 28 ?? ?? ?? ?? 0D 09 6F ?? ?? ?? ?? 06 7B + ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 12 ?? 28 + ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? DC 2A } - $remote_server_1 = { - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 53 55 56 57 68 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 8D 8C 24 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 33 FF 57 6A ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 89 44 24 ?? 33 DB - BD ?? ?? ?? ?? 8B 44 24 ?? BA ?? ?? ?? ?? 8B CB D3 E2 85 D0 0F 84 ?? ?? ?? ?? 8A CB - 8D 54 24 ?? 80 C1 ?? 52 88 4C 24 ?? 66 C7 44 24 ?? ?? ?? FF D6 83 F8 ?? 74 ?? 8D 44 - 24 ?? 50 FF D6 83 F8 ?? 75 ?? 8D 44 24 ?? 89 6C 24 ?? 89 7C 24 ?? C6 44 24 ?? ?? 8D - 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 50 8D 4C 24 ?? 51 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 54 - 24 ?? 6A ?? 52 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 83 F8 ?? 72 ?? 8B 44 24 ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 89 6C 24 ?? 89 7C 24 ?? C6 44 24 ?? ?? 43 83 FB ?? 0F 8C ?? ?? - ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? - ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E 5D 33 C0 5B E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C2 + $import_priv_key = { + 02 73 ?? ?? ?? ?? 13 ?? 11 ?? 73 ?? ?? ?? ?? 13 ?? 16 13 ?? 16 13 ?? 16 13 ?? 11 ?? 6F + ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? 33 ?? 11 ?? 6F ?? ?? ?? ?? 26 2B ?? 11 ?? 20 ?? + ?? ?? ?? 33 ?? 11 ?? 6F ?? ?? ?? ?? 26 2B ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 11 ?? 6F + ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? 2E ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 11 ?? 6F + ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 11 ?? 28 ?? ?? ?? ?? 13 + ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 0A 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? + 0B 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 0C 11 ?? 28 ?? ?? ?? ?? 13 ?? + 11 ?? 11 ?? 6F ?? ?? ?? ?? 0D 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 13 + ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 + ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? + ?? 13 ?? 12 ?? FE 15 ?? ?? ?? ?? 12 ?? 06 7D ?? ?? ?? ?? 12 ?? 07 7D ?? ?? ?? ?? 12 ?? + 08 7D ?? ?? ?? ?? 12 ?? 09 7D ?? ?? ?? ?? 12 ?? 11 ?? 7D ?? ?? ?? ?? 12 ?? 11 ?? 7D ?? + ?? ?? ?? 12 ?? 11 ?? 7D ?? ?? ?? ?? 12 ?? 11 ?? 7D ?? ?? ?? ?? 11 ?? 13 ?? DE ?? 11 ?? + 6F ?? ?? ?? ?? DC 11 ?? 2A } - $remote_server_2 = { - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 57 33 FF 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 89 84 - 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 66 83 7C 24 ?? ?? - 0F 85 ?? ?? ?? ?? 66 83 7C 24 ?? ?? 0F 87 ?? ?? ?? ?? 53 55 56 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? - 8D 94 24 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 57 6A ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 89 44 24 ?? 33 DB BD ?? ?? - ?? ?? 8B CB B8 ?? ?? ?? ?? D3 E0 8B 4C 24 ?? 85 C1 0F 84 ?? ?? ?? ?? 8A D3 8D 44 24 - ?? 80 C2 ?? 50 88 54 24 ?? 66 C7 44 24 ?? ?? ?? FF D6 83 F8 ?? 74 ?? 8D 4C 24 ?? 51 - FF D6 83 F8 ?? 75 ?? 8D 44 24 ?? 89 6C 24 ?? 89 7C 24 ?? C6 44 24 ?? ?? 8D 50 ?? 8A - 08 40 84 C9 75 ?? 2B C2 50 8D 54 24 ?? 52 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? 6A - ?? 50 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 83 F8 ?? 72 ?? 8B 4C 24 ?? 51 E8 ?? ?? ?? - ?? 83 C4 ?? 89 6C 24 ?? 89 7C 24 ?? C6 44 24 ?? ?? 43 83 FB ?? 0F 8C ?? ?? ?? ?? E8 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B - 8C 24 ?? ?? ?? ?? 5E 5D 5B 33 C0 5F E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C2 ?? ?? 57 FF - 15 + $encrypt_files = { + 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? 0A 14 0B 14 0C 16 0D 20 ?? ?? ?? ?? 13 ?? 03 19 17 1D 28 + ?? ?? ?? ?? 0B 03 19 18 1D 28 ?? ?? ?? ?? 0C 02 7B ?? ?? ?? ?? 08 17 6F ?? ?? ?? ?? 13 + ?? 07 06 16 06 8E 69 6F ?? ?? ?? ?? 13 ?? 11 ?? 16 31 ?? 11 ?? 06 16 11 ?? 6F ?? ?? ?? + ?? 11 ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 04 11 ?? 6F ?? ?? ?? ?? 04 6F ?? ?? ?? ?? + 13 ?? 11 ?? 8E 69 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 08 08 6F ?? ?? ?? ?? 16 6F ?? ?? ?? + ?? 26 08 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 08 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 08 + 6F ?? ?? ?? ?? 17 0D DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC DE ?? 13 ?? DE ?? 07 2C + ?? 07 6F ?? ?? ?? ?? 08 2C ?? 08 6F ?? ?? ?? ?? 09 26 DC 2A } condition: - uint16(0)==0x5A4D and ( all of ($file_search_p*)) and ((($encrypt_file_1) and ($remote_server_1)) or (($encrypt_file_2) and ($remote_server_2))) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($import_priv_key) and ($encrypt_files) } -rule REVERSINGLABS_Win64_Ransomware_Seedlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Antefrigus : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects SeedLocker ransomware." + description = "Yara rule that detects AnteFrigus ransomware." author = "ReversingLabs" - id = "efa3dd2e-faf4-5882-aef8-85189e65f0f9" - date = "2020-07-15" - modified = "2020-07-15" + id = "903ac92c-1a4a-5645-92db-d00b3bfd6ada" + date = "2021-03-05" + modified = "2021-03-05" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.SeedLocker.yara#L1-L91" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "a478efcfb03e3eeebe72d9a71629456cf061c3c779fbdde99539854caf8c7c33" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.AnteFrigus.yara#L1-L210" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "b84c01da0ee97a4eb8bf099c71094f994feb4c7185ad75b8b2ccda5eee283a92" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -35381,92 +36784,196 @@ rule REVERSINGLABS_Win64_Ransomware_Seedlocker : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "SeedLocker" + tc_detection_name = "AnteFrigus" tc_detection_factor = 5 importance = 25 strings: - $search_files = { - 48 89 5C 24 ?? 48 89 7C 24 ?? 55 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 8B - 05 ?? ?? ?? ?? 48 33 C4 48 89 85 ?? ?? ?? ?? 48 8B F9 4C 8D 05 ?? ?? ?? ?? 4C 8B C9 - BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8D 8D ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 0F 84 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? - 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF - 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 44 24 ?? 4C 8B CF 4C 8D 05 ?? ?? ?? ?? 48 89 44 24 - ?? BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? F6 44 24 ?? ?? 48 8D 8D ?? - ?? ?? ?? 74 ?? 48 8D 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? EB ?? FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 0F 85 - ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? - ?? 48 33 CC E8 ?? ?? ?? ?? 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? 49 8B 7B ?? 49 8B E3 - 5D C3 + $find_files_p1 = { + 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 68 ?? ?? ?? ?? 8B D0 + 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 83 65 ?? ?? 8D 8D ?? ?? ?? ?? 83 7D ?? ?? 8D 45 + ?? 51 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 33 C0 8D 7D + ?? AB AB AB 33 C0 89 45 ?? 89 45 ?? 89 45 ?? C6 45 ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + 68 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 59 8B D0 C6 45 ?? ?? 8B 4A ?? 8B 7A ?? 2B + CF 39 4E ?? 76 ?? 8B 46 ?? 2B 46 ?? 3B C7 72 ?? 83 7A ?? ?? 72 ?? 8B 12 57 52 51 8B + CE E8 ?? ?? ?? ?? EB ?? 56 8B CA E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 85 ?? + ?? ?? ?? ?? 8D 45 ?? FF B5 ?? ?? ?? ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + 83 7D ?? ?? 8D 4D ?? 8B 45 ?? 0F 43 4D ?? 8D 04 41 8D 4D ?? 0F 43 4D ?? 51 50 51 8D + 4D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 83 65 ?? ?? 8D 4D ?? 83 65 ?? ?? 50 E8 ?? + ?? ?? ?? C6 45 ?? ?? 8D 75 ?? 83 7D ?? ?? 8B 55 ?? 0F 43 75 ?? 85 D2 74 ?? 83 C9 ?? + 8D 42 ?? 3B C1 0F 42 C8 03 CE EB ?? 3B CE 74 ?? 49 80 39 ?? 75 ?? 2B CE EB ?? 83 C9 + ?? 83 F9 ?? 0F 84 ?? ?? ?? ?? 83 65 ?? ?? 8D 71 ?? C7 45 ?? ?? ?? ?? ?? C6 45 } - $encrypt_files_p1 = { - FF 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 63 C8 48 8D 85 ?? ?? ?? - ?? 48 8D 04 48 48 83 C0 ?? 66 83 38 ?? 75 ?? 45 33 FF 4C 8D 05 ?? ?? ?? ?? 66 44 89 - 38 45 33 C9 48 83 C0 ?? 4C 89 7C 24 ?? 48 89 05 ?? ?? ?? ?? 33 D2 48 8D 05 ?? ?? ?? - ?? 44 89 7C 24 ?? 33 C9 48 89 05 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 D2 45 8D 47 ?? 33 - C9 FF 15 ?? ?? ?? ?? 48 8B F0 48 85 C0 74 ?? 48 8B 1D ?? ?? ?? ?? 48 81 C3 ?? ?? ?? - ?? EB ?? 48 8B CB FF 15 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8B D3 48 8B CE 44 8B F0 FF - 15 ?? ?? ?? ?? 48 8B F8 48 85 C0 74 ?? 4C 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8B C8 - FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 41 8D 46 ?? 48 63 C8 48 8D 1C 4B 66 44 - 39 3B 75 ?? 48 8B CE FF 15 ?? ?? ?? ?? 33 D2 8D 4A ?? FF 15 ?? ?? ?? ?? 48 8B F8 48 - 83 F8 ?? 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 48 8B 1D ?? ?? ?? ?? 48 81 - C3 ?? ?? ?? ?? EB ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B D3 48 8D 4C 24 ?? 44 8B F0 FF - 15 ?? ?? ?? ?? 85 C0 75 ?? 44 8B 44 24 ?? 8D 48 ?? 33 D2 FF 15 ?? ?? ?? ?? 48 8B F0 - 48 83 F8 ?? 74 ?? 33 D2 48 8B C8 FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 41 8D - 46 ?? 48 63 C8 48 8D 1C 4B 66 44 39 3B 75 ?? 48 8D 54 24 ?? 48 8B CF FF 15 ?? ?? ?? - ?? 85 C0 75 ?? 48 8B CF FF 15 ?? ?? ?? ?? 33 D2 48 8D 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 48 8D 35 ?? ?? ?? ?? 48 + $find_files_p2 = { + 3B D6 0F 82 ?? ?? ?? ?? 2B D6 8D 45 ?? 83 C9 ?? 83 FA ?? 0F 42 CA 83 7D ?? ?? 51 0F + 43 45 ?? 8D 4D ?? 03 C6 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 8D 45 ?? 50 83 + 61 ?? ?? 83 61 ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 51 51 8D 45 ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? + 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? BF ?? ?? ?? ?? 8B 70 ?? 03 30 3B F7 7D ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 3B F7 7D ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 8B 45 ?? 8D 4D ?? 51 3B 45 ?? 74 ?? 8B C8 E8 ?? ?? + ?? ?? 83 45 ?? ?? EB ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? + C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? + ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 7D ?? 8B 75 ?? 6A ?? 5B 3B F7 74 ?? 56 E8 ?? ?? ?? + ?? 03 F3 59 3B F7 75 ?? 8B 7D ?? 8B 75 ?? 85 F6 74 ?? 3B F7 74 ?? 8B CE E8 ?? ?? ?? + ?? 03 F3 3B F7 75 ?? 8B 75 ?? 8B 45 ?? 2B C6 99 F7 FB 6B C0 ?? 50 56 E8 ?? ?? ?? ?? + 59 59 8D 4D ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E8 + } + $remote_connection_p1 = { + 55 8D AC 24 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 85 ?? ?? ?? ?? 53 56 57 50 8D 45 ?? 64 A3 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 BA ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? + ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 0F 43 + 8D ?? ?? ?? ?? 03 F9 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? 0F 43 B5 ?? ?? ?? ?? 33 C0 66 89 85 ?? ?? ?? ?? 33 DB 8B C7 89 9D + } + $remote_connection_p2 = { + 2B C6 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? C6 45 ?? ?? EB ?? 66 0F BE 06 8D + 8D ?? ?? ?? ?? 0F B7 C0 50 E8 ?? ?? ?? ?? 46 3B F7 75 ?? 53 53 53 53 68 ?? ?? ?? ?? + C6 45 ?? ?? 88 5D ?? FF 15 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 6A ?? 33 C0 50 + 6A ?? 50 50 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 89 45 ?? 85 + C0 74 ?? 6A ?? 68 ?? ?? ?? ?? 33 C9 51 51 51 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 8B F0 85 F6 74 ?? 33 C0 50 50 50 50 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 + ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? + 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 56 FF D7 FF 75 ?? FF D7 53 FF + D7 80 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 8D ?? ?? ?? ?? 33 CD E8 ?? ?? ?? ?? 81 + C5 ?? ?? ?? ?? C9 C3 8B 85 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 3D ?? ?? ?? ?? 73 ?? + 8D 95 ?? ?? ?? ?? C6 84 05 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? + E9 ?? ?? ?? ?? E8 + } + $encrypt_files_p1 = { + 66 39 03 0F 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 33 C0 8D 8D ?? + ?? ?? ?? 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? + ?? 8D 95 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 0F 43 95 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 5B C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 39 9D ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 8D 04 41 8D 8D ?? ?? ?? ?? 0F 43 8D ?? ?? ?? + ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 + 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 BA ?? ?? ?? ?? 8D + 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? + 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? + ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D } $encrypt_files_p2 = { - 8D 8D ?? ?? ?? ?? 48 89 B5 ?? ?? ?? ?? 44 8D 42 ?? E8 ?? ?? ?? ?? 4C 8B 05 ?? ?? ?? - ?? 48 8D 8D ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? BB ?? ?? ?? ?? 4C 89 BD - ?? ?? ?? ?? 44 8B CB C7 44 24 ?? ?? ?? ?? ?? 45 33 C0 48 8D 8D ?? ?? ?? ?? 33 D2 FF - 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? 48 8D 44 24 ?? 45 - 33 C9 45 33 C0 48 89 44 24 ?? 8D 53 ?? 33 C9 FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? - 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? - ?? 3D ?? ?? ?? ?? 75 ?? 44 8B CB C7 44 24 ?? ?? ?? ?? ?? 45 33 C0 48 8D 8D ?? ?? ?? - ?? 33 D2 FF 15 ?? ?? ?? ?? 48 8B BD ?? ?? ?? ?? 48 85 FF 0F 84 ?? ?? ?? ?? 48 8B 0D - ?? ?? ?? ?? 41 8B DF 48 81 C1 ?? ?? ?? ?? 45 8B F7 FF 15 ?? ?? ?? ?? 85 C0 7E ?? 49 - 8B F7 48 8B 05 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? BA ?? ?? ?? ?? 0F BE 8C 06 ?? ?? ?? - ?? 44 0F BE 8C 06 ?? ?? ?? ?? 89 4C 24 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 - 48 8D 8D ?? ?? ?? ?? 44 8D 42 ?? E8 ?? ?? ?? ?? 8B CB 48 8D 76 ?? FF C3 41 83 C6 ?? - 88 84 0D ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 81 C1 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 44 + 8D ?? ?? ?? ?? 83 C4 ?? 3B C8 74 ?? 33 C9 88 4D ?? 8D 8D ?? ?? ?? ?? FF 75 ?? 50 E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 56 E8 + ?? ?? ?? ?? 56 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 33 C0 59 89 85 ?? + ?? ?? ?? 89 8D ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 88 + 85 ?? ?? ?? ?? BF ?? ?? ?? ?? C6 45 ?? ?? 57 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 8D 4D + ?? E8 ?? ?? ?? ?? 33 C0 C6 45 ?? ?? 57 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 59 99 F7 F9 8D 4D ?? + 52 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 59 99 F7 F9 8D 8D ?? ?? ?? ?? 52 E8 ?? ?? ?? + ?? 83 EB ?? 75 ?? 8D 95 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 57 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 51 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? + ?? ?? ?? 39 9D ?? ?? ?? ?? 74 ?? 83 BD ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? FF B5 ?? ?? + ?? ?? 0F 43 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 56 8D 4D ?? E8 ?? ?? ?? ?? 59 8D 8D ?? + ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 56 8D 45 ?? + C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 } $encrypt_files_p3 = { - 3B F0 7C ?? 48 8D 35 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 45 33 C9 48 89 44 24 ?? 48 8D - 95 ?? ?? ?? ?? 44 8B C3 44 89 7C 24 ?? 48 8B CF FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? - ?? ?? 48 8B 1D ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 4C 8B C3 E8 ?? - ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 45 33 C9 C7 44 24 ?? ?? ?? ?? ?? - 48 89 44 24 ?? 33 D2 48 8D 85 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 48 89 44 24 ?? 45 8D 41 - ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 41 8B DF 44 39 BD ?? ?? ?? ?? 76 ?? 8B C3 4C 8D 05 - ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 44 0F B6 8C 05 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF C3 3B 9D ?? ?? - ?? ?? 72 ?? 48 8B 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 D2 48 8B CF FF 15 ?? ?? ?? ?? - 48 8B 05 ?? ?? ?? ?? 4C 8D 8D ?? ?? ?? ?? 48 83 C0 ?? 4C 8D 05 ?? ?? ?? ?? BA ?? ?? - ?? ?? 48 89 44 24 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 06 00 48 - 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 66 44 89 BD ?? ?? 00 00 F3 0F 7F 85 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 48 8D 8D ?? ?? ?? ?? 48 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 48 8B 8D ?? ?? ?? ?? - 48 33 CC E8 ?? ?? ?? ?? 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? 49 8B 73 ?? 49 8B 7B ?? - 49 8B E3 41 5F 41 5E 5D C3 + 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 56 8D 45 ?? C6 45 ?? ?? 50 8D 85 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? + ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? + E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? 8B F3 39 B5 ?? ?? ?? ?? 76 ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 8A 04 30 04 ?? 88 45 ?? FF 75 ?? E8 ?? ?? ?? + ?? 46 3B B5 ?? ?? ?? ?? 72 ?? 8B F3 39 B5 ?? ?? ?? ?? 76 ?? 83 BD ?? ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 8A 04 30 2C ?? 88 45 ?? FF 75 + ?? E8 ?? ?? ?? ?? 46 3B B5 ?? ?? ?? ?? 72 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 50 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 57 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 59 59 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 51 0F 43 + } + $encrypt_files_p4 = { + 85 ?? ?? ?? ?? 51 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? BE ?? ?? + ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 56 50 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? + ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D + ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? + C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 + ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B D0 C6 45 ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? + ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? + 59 59 68 ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 8D 8D ?? + ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 51 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 8D 8D ?? + ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 8D + } + $encrypt_files_p5 = { + 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? + ?? 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 51 0F 43 85 ?? ?? ?? ?? 51 50 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? + ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 56 50 8D 45 ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D + ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D + } + $encrypt_files_p6 = { + E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 89 65 ?? 50 89 59 ?? 89 59 ?? E8 ?? ?? ?? ?? 83 + EC ?? C6 45 ?? ?? 8B CC 89 65 ?? 8D 85 ?? ?? ?? ?? 50 89 59 ?? 89 59 ?? E8 ?? ?? ?? + ?? 83 EC ?? C6 45 ?? ?? 8B CC 89 65 ?? 8D 85 ?? ?? ?? ?? 50 89 59 ?? 89 59 ?? E8 ?? + ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 8D 85 ?? ?? ?? ?? 50 89 59 ?? 89 59 ?? E8 ?? ?? + ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? 83 C4 ?? 8B F0 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 95 ?? + ?? ?? ?? 03 CA 83 BD ?? ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 2B C8 51 50 56 E8 ?? ?? ?? + ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 53 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? + 68 } condition: - uint16(0)==0x5A4D and $search_files and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Pay2Key : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Zhen : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Pay2Key ransomware." + description = "Yara rule that detects Zhen ransomware." author = "ReversingLabs" - id = "2e482222-0483-5fe3-bb87-cfadda8e7e7a" - date = "2021-04-14" - modified = "2021-04-14" + id = "ce6bc48d-934b-582c-8ce7-3dd595cbf5dd" + date = "2021-04-28" + modified = "2021-04-28" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Pay2Key.yara#L1-L99" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "2497504f3afc99523cb29e51652a24f4374316d57d4baf5cde8d22e75a425585" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Zhen.yara#L1-L176" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "17b24e7baeccd90b8695eb8d21d9ee4a317806ed7713252d315d06bee3f93e65" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -35474,92 +36981,164 @@ rule REVERSINGLABS_Win32_Ransomware_Pay2Key : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Pay2Key" + tc_detection_name = "Zhen" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 83 C8 ?? 57 8B 7D ?? - 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? - ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? - FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 4D ?? - 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 C0 50 - 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 - 89 45 ?? 8B 4D ?? 53 8B 5D ?? 56 8B 75 ?? 57 89 B5 ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 - ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 53 E8 ?? ?? ?? ?? 59 59 8B C8 3B CB 75 ?? 8A 11 80 FA - ?? 75 ?? 8D 43 ?? 3B C8 74 ?? 56 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 FF - 80 FA ?? 74 ?? 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8B C7 EB ?? 33 C0 40 0F B6 C0 2B CB 41 - F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? - ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 - FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? - 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 - 74 ?? 80 F9 ?? 75 ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? - ?? 85 C0 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B - C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 - ?? E9 + $find_files_p1 = { + FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 95 + ?? ?? ?? ?? 8B 4D ?? B8 ?? ?? ?? ?? 2B 41 ?? C1 E0 ?? 8B 4D ?? 8B 49 ?? 03 C8 FF 15 + ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D ?? 51 6A ?? FF 15 ?? ?? + ?? ?? 8D 55 ?? 8B 4D ?? 83 C1 ?? FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? 8D 55 ?? 52 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D + 4D ?? 51 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 + E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 8B 4D } - $encrypt_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? - 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B D9 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - 8B 43 ?? 2B 43 ?? 75 ?? 8B 75 ?? 8B 45 ?? 8B 4D ?? C7 45 ?? ?? ?? ?? ?? 89 06 89 4E - ?? 8B 4D ?? 89 4E ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B C6 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C2 ?? ?? 83 7B ?? ?? 74 - ?? 8B 45 ?? 2B 45 ?? 50 E8 ?? ?? ?? ?? 8B 75 ?? 8B F8 8B 55 ?? 2B F2 56 52 57 E8 ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? - 56 89 75 ?? E8 ?? ?? ?? ?? 56 57 50 89 45 ?? E8 ?? ?? ?? ?? 8B 75 ?? 8D 45 ?? 83 C4 - ?? 50 56 6A ?? 6A ?? 6A ?? FF 73 ?? FF 15 ?? ?? ?? ?? 8D 4D ?? 85 C0 75 ?? 8B 75 ?? - 89 45 ?? 89 45 ?? 89 45 ?? 89 06 89 46 ?? 89 46 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? 8B C6 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C2 ?? ?? FF 75 ?? E8 - ?? ?? ?? ?? FF 75 ?? 56 8B 75 ?? 56 E8 ?? ?? ?? ?? 8B 7D ?? 83 C4 ?? 8B 4D ?? 8B 45 - ?? C7 45 ?? ?? ?? ?? ?? 89 4F ?? 8D 4D ?? 89 37 89 47 ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 8B 4D ?? 64 89 0D ?? ?? - ?? ?? 59 5F 5E 5B 8B E5 5D C2 + $find_files_p2 = { + 8B 11 8B 45 ?? 50 FF 92 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 85 + ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? 8D 4D ?? 51 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 + ?? 52 E8 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 E8 + ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 + ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 11 89 95 ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B C4 8B 4D ?? 89 08 8B 55 ?? 89 50 ?? 8B 4D ?? 89 48 ?? 8B 55 + ?? 89 50 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C4 8B 4D ?? 89 08 8B 55 ?? 89 50 ?? 8B + 4D ?? 89 48 ?? 8B 55 ?? 89 50 ?? 8B 85 ?? ?? ?? ?? 8B 08 8B 95 ?? ?? ?? ?? 52 FF 91 + ?? ?? ?? ?? DB E2 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? EB ?? 8D + 4D ?? FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? + ?? C3 C3 8B 45 ?? 8B 08 8B 55 ?? 52 FF 51 ?? 8B 45 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? + 5F 5E 5B 8B E5 5D C2 } - $remote_connection_p1 = { - 55 8B EC 83 EC ?? 56 57 6A ?? 8B F2 8B F9 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? C7 - 45 ?? ?? ?? ?? ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 6A ?? 56 57 FF 15 ?? ?? ?? ?? - 8B 75 ?? 8B C8 8B D6 E8 ?? ?? ?? ?? 8B 0E 8B F8 83 F9 ?? 75 ?? 68 ?? ?? ?? ?? 8B CE - E8 ?? ?? ?? ?? EB ?? 81 F9 ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? EB - ?? 81 F9 ?? ?? ?? ?? 74 ?? 81 F9 ?? ?? ?? ?? 74 ?? 85 FF 74 ?? 5F 83 C8 ?? 5E 8B E5 - 5D C3 + $encrypt_files_p1 = { + 55 8B EC 83 EC ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 53 56 57 89 65 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 08 8B 55 ?? 52 FF 51 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 66 89 45 ?? 8D 4D ?? FF 15 ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 8B 11 52 66 8B 45 ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? 6A ?? 66 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 83 E8 ?? 50 6A ?? 6A ?? + 8D 55 ?? 52 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 66 + 8B 45 ?? 50 8D 4D ?? 51 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 8B + 55 ?? 52 FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 8D 4D ?? 51 8B 55 ?? 8B + 02 8B 4D ?? 51 FF 50 ?? 89 45 ?? 83 7D ?? ?? 7D ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 + 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? EB ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 51 FF 15 ?? ?? ?? ?? 66 89 45 + ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 8B 02 50 66 8B 4D ?? 51 } - $remote_connection_p2 = { - 55 8B EC 51 53 56 8B F1 57 8B 46 ?? 83 C0 ?? 50 FF 15 ?? ?? ?? ?? 80 7D ?? ?? 6A ?? - 74 ?? 8B 4E ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 5F 5E 5B 59 5D C2 ?? ?? 8B 45 ?? 8B 08 - 83 F9 ?? 75 ?? 8B 4E ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 5F 5E 5B 59 5D C2 ?? - ?? 8B 45 ?? 8B 7D ?? 57 89 45 ?? 8D 45 ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF 75 - ?? FF 75 ?? 51 FF 15 ?? ?? ?? ?? 8B D8 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? B8 ?? ?? ?? - ?? EB ?? 3D ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 44 C1 85 DB 74 ?? 3D ?? ?? ?? ?? 74 ?? FF - 75 ?? 8B 4E ?? 50 57 E8 ?? ?? ?? ?? 5F 5E 5B 59 5D C2 ?? ?? 8B 4E ?? 57 E8 ?? ?? ?? - ?? 5F 5E 5B 59 5D C2 + $encrypt_files_p2 = { + 6A ?? 6A ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? FF 15 ?? + ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 8B 11 8B 45 ?? 50 FF 52 ?? 89 45 ?? 83 7D + ?? ?? 7D ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? + EB ?? C7 45 ?? ?? ?? ?? ?? 66 8B 45 ?? 50 8D 4D ?? 51 68 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 8D 4D ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 8B 55 ?? 52 8D 45 ?? 50 68 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 8B 4D ?? 51 FF 15 ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? FF 15 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 8B 55 ?? 52 FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? 8B 45 ?? 8B 08 51 8D 55 ?? 52 FF 15 ?? ?? ?? ?? 50 8B 45 ?? 8B 08 51 8D 55 ?? 52 + FF 15 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 45 ?? 50 8B 4D ?? 51 FF 15 + ?? ?? ?? ?? 8B 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D ?? 51 8D 55 ?? 52 6A ?? + FF 15 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? FF 15 ?? ?? ?? ?? + 68 ?? ?? ?? ?? EB ?? 8D 45 ?? 50 8D 4D ?? 51 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 4D + ?? FF 15 ?? ?? ?? ?? C3 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? FF 15 + ?? ?? ?? ?? C3 8B 4D ?? 8B 11 8B 45 ?? 50 FF 52 ?? 8B 4D ?? 66 8B 55 ?? 66 89 11 8B + 45 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C2 } - $remote_connection_p3 = { - 55 8B EC 83 EC ?? 56 57 6A ?? 8B F2 8B F9 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 45 - ?? C7 45 ?? ?? ?? ?? ?? 50 FF 75 ?? 56 57 FF 15 ?? ?? ?? ?? 8B 75 ?? 8B C8 8B D6 E8 - ?? ?? ?? ?? 8B 0E 8B F8 83 F9 ?? 75 ?? 68 ?? ?? ?? ?? EB ?? 81 F9 ?? ?? ?? ?? 75 ?? - 68 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 FF 74 ?? 5F 83 C8 ?? 5E 8B E5 5D C3 + $scan_network_p1 = { + 55 8B EC 83 EC ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? B8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 53 56 57 89 65 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 08 8B 55 ?? 52 FF 51 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 08 8B 55 ?? 52 + FF 91 ?? ?? ?? ?? 50 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 4D ?? 51 8B + 95 ?? ?? ?? ?? 8B 02 8B 8D ?? ?? ?? ?? 51 FF 90 ?? ?? ?? ?? DB E2 89 85 ?? ?? ?? ?? + 83 BD ?? ?? ?? ?? ?? 7D ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 8B 85 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D 4D ?? FF + 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8D + 4D ?? 51 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8D + 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 8D + 4D ?? 51 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? + 8B 08 8B 55 ?? 52 FF 91 ?? ?? ?? ?? 50 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? 8D 4D ?? 51 8B 95 ?? ?? ?? ?? 8B 02 8B 8D ?? ?? ?? ?? 51 FF 90 ?? ?? ?? ?? DB E2 + 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 95 ?? + ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 95 ?? ?? + ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8D 45 ?? 50 FF + } + $scan_network_p2 = { + 15 ?? ?? ?? ?? 8D 4D ?? 51 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 95 + ?? ?? ?? ?? 52 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 8D 4D ?? FF + 15 ?? ?? ?? ?? 8D 4D ?? 51 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? + ?? ?? ?? 8B 45 ?? B9 ?? ?? ?? ?? 2B 48 ?? 8B 55 ?? 8B 42 ?? 8B 0C 88 51 FF 15 ?? ?? + ?? ?? DD 9D ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? 2B 42 ?? 8B 4D ?? 8B 51 ?? 8B 04 82 + 50 FF 15 ?? ?? ?? ?? DC AD ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B 4D ?? BA ?? ?? ?? ?? 2B + 51 ?? 8B 45 ?? 8B 48 ?? 8B 14 91 52 FF 15 ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B 45 ?? B9 + ?? ?? ?? ?? 2B 48 ?? 8B 55 ?? 8B 42 ?? 8B 0C 88 51 FF 15 ?? ?? ?? ?? DC AD ?? ?? ?? + ?? DC 0D ?? ?? ?? ?? DC 85 ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? 2B + 42 ?? 8B 4D ?? 8B 51 ?? 8B 04 82 50 FF 15 ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B 4D ?? BA + ?? ?? ?? ?? 2B 51 ?? 8B 45 ?? 8B 48 ?? 8B 14 91 52 FF 15 ?? ?? ?? ?? DC AD ?? ?? ?? + ?? DC 0D ?? ?? ?? ?? DC 0D ?? ?? ?? ?? DC 85 ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B 45 ?? + 33 C9 2B 48 ?? 8B 55 ?? 8B 42 ?? 8B 0C 88 51 FF 15 ?? ?? ?? ?? DD 9D ?? ?? ?? ?? 8B + 55 ?? 33 C0 2B 42 ?? 8B 4D ?? 8B 51 ?? 8B 04 82 50 FF 15 ?? ?? ?? ?? DC AD ?? ?? ?? + ?? DC 0D ?? ?? ?? ?? DC 0D ?? ?? ?? ?? DC 0D ?? ?? ?? ?? DC 85 ?? ?? ?? ?? DD 5D ?? + C7 45 ?? ?? ?? ?? ?? DD 45 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 89 41 ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 + } + $scan_network_p3 = { + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? + ?? 52 8D 85 ?? ?? ?? ?? 50 8D 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E9 ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + 8B 95 ?? ?? ?? ?? 8B 02 89 85 ?? ?? ?? ?? 8B 4D ?? 8B 11 8B 45 ?? 50 FF 92 ?? ?? ?? + ?? 50 8D 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 FF 15 + ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 8B 11 8B 85 ?? ?? ?? ?? 50 FF 52 ?? DB E2 89 85 ?? + ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 6A ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8B 95 + ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? 8B 45 ?? 89 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8D 55 ?? 52 + FF 15 ?? ?? ?? ?? 50 8B 85 ?? ?? ?? ?? 8B 08 8B 95 ?? ?? ?? ?? 52 FF 51 ?? DB E2 89 + 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 6A ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 + } + $scan_network_p4 = { + 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 + 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 8B 11 8B 45 ?? 50 FF 92 ?? ?? ?? ?? 50 8D 4D ?? 51 + FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8B 95 ?? ?? ?? ?? 8B 02 8B 8D ?? ?? ?? ?? + 51 FF 50 ?? DB E2 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7D ?? 6A ?? 68 ?? ?? ?? ?? + 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 9B 68 ?? ?? ?? ?? EB ?? 8D + 4D ?? FF 15 ?? ?? ?? ?? 8D 4D ?? 51 8D 55 ?? 52 8D 45 ?? 50 6A ?? FF 15 ?? ?? ?? ?? + 83 C4 ?? 8D 4D ?? 51 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? C3 8D 85 ?? ?? ?? + ?? 50 8D 8D ?? ?? ?? ?? 51 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? FF 15 ?? ?? ?? + ?? 8D 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? FF 15 ?? ?? ?? ?? C3 8B 4D + ?? 8B 11 8B 45 ?? 50 FF 52 ?? 8B 4D ?? 66 8B 55 ?? 66 89 11 8B 45 ?? 8B 4D ?? 64 89 + 0D ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C2 } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ( all of ($scan_network_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -import "pe" - -rule REVERSINGLABS_Win32_Ransomware_Petya : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Retmydata : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Petya ransomware." + description = "Yara rule that detects RetMyData ransomware." author = "ReversingLabs" - id = "93d9fb33-88d1-50ec-bf99-1888201c0ec2" + id = "f7a091d9-7ace-5aad-95b4-d5101fa7fdea" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Petya.yara#L3-L58" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "d2adafcb21b627d614eab79e64e2b96ad09fae796d0670452a19490d8781ce99" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.RetMyData.yara#L1-L79" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "54ce38d75e9ab82a77b9c338f75e180e19ac745f149289c7478a4aa3b44d70fd" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -35567,56 +37146,72 @@ rule REVERSINGLABS_Win32_Ransomware_Petya : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Petya" + tc_detection_name = "RetMyData" tc_detection_factor = 5 importance = 25 strings: - $entry_point = { - 55 8B EC 56 8B 75 ?? 57 83 FE ?? 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? 56 FF 75 ?? E8 ?? ?? ?? ?? 8B F8 85 F6 75 ?? E8 ?? - ?? ?? ?? 8B C7 5F 5E 5D C2 - } - $shutdown_pattern = { - 55 8B EC 83 EC ?? 8D 45 ?? 56 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 - 75 ?? 33 C0 EB ?? 8D 45 ?? 33 F6 50 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 56 56 56 8D - 45 ?? C7 45 ?? ?? ?? ?? ?? 50 56 FF 75 ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 8D 4D ?? 51 6A ?? 56 56 56 68 ?? ?? ?? ?? FF D0 33 C0 83 C4 ?? 40 5E 8B - E5 5D C3 + $find_files = { + 55 89 E5 57 56 53 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 29 C4 8D 9D ?? ?? ?? ?? 8B 04 04 + C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 89 44 24 ?? 89 C7 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 89 1C 24 89 44 24 ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 40 51 51 0F 84 ?? ?? ?? ?? 8D + B5 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 85 + C0 74 ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 85 C0 74 ?? F6 85 ?? ?? ?? + ?? ?? 89 74 24 ?? 89 7C 24 ?? 74 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? + 89 D8 E8 ?? ?? ?? ?? EB ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? BA ?? ?? + ?? ?? 89 D8 E8 ?? ?? ?? ?? 85 C0 75 ?? 89 D8 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 44 + 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 52 52 0F 85 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 50 8D 65 ?? 5B 5E 5F 5D C3 55 BA ?? ?? ?? ?? 89 + E5 53 51 89 C3 E8 ?? ?? ?? ?? 48 74 ?? 5A 89 D8 5B 5D E9 ?? ?? ?? ?? 58 5B 5D C3 } - $sectionxxxx_pattern = { - 83 EC ?? 53 55 8B C2 89 4C 24 ?? 56 57 8B C8 89 44 24 ?? 33 D2 E8 ?? ?? ?? ?? 85 C0 - 74 ?? 0F B7 48 ?? 8B FA 83 C1 ?? 03 C8 0F B7 40 ?? 89 44 24 ?? 85 C0 74 ?? BE ?? ?? - ?? ?? 2B F1 80 39 ?? 8D 59 ?? 6A ?? 5D 75 ?? 85 ED 74 ?? 0F BE 2C 1E 0F BE 03 43 3B - E8 74 ?? 83 C1 ?? 83 EE ?? 47 3B 7C 24 ?? 72 ?? 8B CA 85 C9 74 ?? 8B 51 ?? 8B 5C 24 - ?? 8B FB 03 54 24 ?? 8B F2 8B 4A ?? A5 83 C1 ?? 03 CA 89 4B ?? A5 A5 8B 43 ?? 8D 72 - ?? 89 43 ?? 8B 43 ?? 89 43 ?? B8 ?? ?? ?? ?? 89 73 ?? 66 39 01 74 ?? 8B 7A ?? 8B 2A - 03 7A ?? 74 ?? 33 DB 43 2B DE 33 D2 8D 0C 33 8B C5 F7 F1 30 16 46 4F 75 ?? B2 ?? 5F - 5E 5D 0F B6 C2 5B 83 C4 ?? C3 + $enum_resources = { + 55 89 E5 57 56 53 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 29 C4 8D 95 ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? 8B 04 04 C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? C7 44 24 ?? ?? ?? + ?? ?? C7 04 24 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? + 83 EC ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 31 F6 89 + 44 24 ?? 8D 85 ?? ?? ?? ?? 89 5C 24 ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? + ?? ?? ?? 83 EC ?? 3B B5 ?? ?? ?? ?? 7D ?? 83 7B ?? ?? 75 ?? 8B 43 ?? C7 44 24 ?? ?? + ?? ?? ?? 89 3C 24 89 44 24 ?? E8 ?? ?? ?? ?? 89 F8 E8 ?? ?? ?? ?? 89 D8 46 83 C3 ?? + E8 ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 50 8D 65 ?? 5B 5E 5F + 5D C3 } - $crypt_gen_pattern = { - 55 8B EC 53 57 8B 7D ?? 8D 45 ?? 68 ?? ?? ?? ?? 6A ?? 33 DB 53 53 50 89 1F FF 15 ?? - ?? ?? ?? 85 C0 75 ?? 6A ?? 58 EB ?? 56 FF 75 ?? 8B 75 ?? 56 FF 75 ?? FF 15 ?? ?? ?? - ?? 85 C0 75 ?? 6A ?? 58 EB ?? 53 FF 75 ?? FF 15 ?? ?? ?? ?? 89 37 33 C0 5E 5F 5B 5D - C3 + $encrypt_files = { + 55 89 E5 57 56 53 89 C3 81 EC ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 + C0 89 C2 A3 ?? ?? ?? ?? 75 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 31 + C0 89 D7 F3 AB 85 DB 75 ?? A1 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? + ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 89 5C 24 ?? 8D 9D ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 89 3C + 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C + 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 + 24 E8 ?? ?? ?? ?? 89 74 24 ?? 89 3C 24 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 EC + ?? 83 F8 ?? 89 C3 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 89 7C 24 ?? 89 34 24 EB ?? 8D + BD ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? C7 44 24 ?? ?? ?? + ?? ?? 89 1C 24 89 44 24 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 85 C0 75 ?? 89 + 1C 24 E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 + ?? ?? ?? ?? EB ?? F7 D8 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? + 89 1C 24 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 83 EC ?? BA ?? ?? ?? ?? C7 04 24 ?? ?? ?? + ?? B8 ?? ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 + 74 24 ?? 89 1C 24 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 83 EC ?? + FF 8D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 65 ?? 5B 5E 5F 5D C3 } condition: - uint16(0)==0x5A4D and ($entry_point at pe.entry_point) and $shutdown_pattern and $sectionxxxx_pattern and $crypt_gen_pattern + uint16(0)==0x5A4D and ($enum_resources) and ($find_files) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Nefilim : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Denizkizi : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Nefilim ransomware." + description = "Yara rule that detects DenizKizi ransomware." author = "ReversingLabs" - id = "aec298c1-abf8-5446-9dbb-795f9fcf8e94" + id = "e16a00d6-d5b8-5702-9cd7-d037b0ff46a3" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Nefilim.yara#L1-L150" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "fae0350e51aee2777475d2222848b30fd39fa39ceea260132b0c7fbc536b3a86" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.DenizKizi.yara#L1-L88" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "fbeb01263d6f68141e094ba8fb1c1a54c601ab24292f5c6b0eb8cb0c49f46afc" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -35624,135 +37219,81 @@ rule REVERSINGLABS_Win32_Ransomware_Nefilim : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Nefilim" + tc_detection_name = "DenizKizi" tc_detection_factor = 5 importance = 25 strings: - $create_encryption_key = { - 55 8B EC 51 A1 ?? ?? ?? ?? C1 E8 ?? 6B C0 ?? 56 50 E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? - ?? 8B F0 A1 ?? ?? ?? ?? 59 89 75 ?? 73 ?? B8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 33 F6 59 59 39 35 ?? ?? ?? ?? 75 ?? 53 57 8B 3D ?? ?? ?? ?? 56 6A ?? 56 BE - ?? ?? ?? ?? 56 BB ?? ?? ?? ?? 53 FF D7 85 C0 75 ?? 6A ?? 6A ?? 50 56 53 FF D7 85 C0 - 75 ?? 50 FF 15 ?? ?? ?? ?? 5F 33 F6 5B A1 ?? ?? ?? ?? C1 E8 ?? 6B C0 ?? 68 ?? ?? ?? - ?? 56 56 50 FF 75 ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 56 EB ?? 5E C9 - C3 - } - $encrypt_encryption_key = { - 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 68 ?? ?? ?? ?? 8D 45 ?? 8D 4D ?? E8 - ?? ?? ?? ?? 83 78 ?? ?? 59 72 ?? 8B 00 53 56 57 33 DB 53 53 6A ?? 53 53 68 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 33 FF 8D 75 ?? 89 45 ?? E8 ?? ?? ?? ?? 39 5D ?? 0F 84 - ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? BF ?? ?? ?? ?? 57 FF D3 99 83 E2 ?? 03 C2 C1 F8 ?? 6B - C0 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 57 8B F0 FF D3 50 57 E8 ?? ?? - ?? ?? 59 59 57 FF D3 99 83 E2 ?? 03 C2 C1 F8 ?? 6B C0 ?? 89 45 ?? 8D 45 ?? 50 56 6A - ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 85 C0 75 ?? FF 15 ?? ?? ?? - ?? 8D 45 ?? 50 57 FF D3 99 83 E2 ?? 03 C2 C1 F8 ?? 6B C0 ?? 50 56 FF 75 ?? FF 15 ?? - ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 6A ?? 33 FF 8D 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 - } - $encrypt_files_p1 = { - 55 8B EC 83 E4 ?? 83 EC ?? A1 ?? ?? ?? ?? 33 C4 89 44 24 ?? 83 7D ?? ?? 8B 45 ?? 53 - 56 57 73 ?? 8D 45 ?? 33 DB 53 53 6A ?? 53 53 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 - 44 24 ?? 3B C3 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? 51 50 FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? - 6B C0 ?? 83 C0 ?? 83 F8 ?? 0F 8E ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 6A ?? 89 44 24 ?? - E8 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? BE - ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 56 89 44 24 ?? E8 ?? ?? ?? ?? FF 74 24 ?? 8B 54 24 ?? - 89 44 24 ?? E8 ?? ?? ?? ?? FF 74 24 ?? 8B 54 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? FF 15 ?? - ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 7E ?? 68 ?? ?? ?? ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 6A ?? - 33 FF E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 53 53 FF 74 24 ?? FF 74 24 ?? - FF 74 24 ?? FF D7 53 FF 15 ?? ?? ?? ?? 53 8D 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? - FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 - F8 ?? 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 53 03 C6 53 13 CB 51 50 FF 74 24 ?? - FF D7 53 8D 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B 44 24 ?? 8B - } - $encrypt_files_p2 = { - 4C 24 ?? 53 05 ?? ?? ?? ?? 53 13 CB 51 50 FF 74 24 ?? FF D7 53 E8 ?? ?? ?? ?? 0B C2 - 59 74 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 6A ?? 33 FF 8D 74 24 ?? E8 ?? ?? - ?? ?? 8B 3D ?? ?? ?? ?? 53 8D 44 24 ?? 50 FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 74 - 24 ?? FF 15 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 3B C3 0F 8C ?? ?? ?? ?? 7F ?? 81 F9 - ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 89 5C 24 ?? 89 5C 24 ?? 3B C3 0F 8C ?? ?? ?? ?? 7F ?? - 3B CB 0F 86 ?? ?? ?? ?? BE ?? ?? ?? ?? EB ?? 8B 4C 24 ?? 2B 4C 24 ?? 1B 44 24 ?? 89 - 44 24 ?? 0F 88 ?? ?? ?? ?? 7F ?? 81 F9 ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 56 53 FF 15 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 53 53 FF 74 24 ?? 89 44 24 ?? FF 74 24 ?? FF 74 24 ?? - FF D7 53 8D 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 8B - 54 24 ?? 51 56 FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 53 FF 74 24 ?? FF 74 24 ?? FF - 74 24 ?? FF D7 53 8D 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? FF 74 24 ?? 53 50 FF 15 ?? ?? ?? ?? 81 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? - 11 5C 24 ?? 39 44 24 ?? 0F 8C ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 8B 4C 24 ?? 39 4C 24 ?? - 0F 82 ?? ?? ?? ?? E9 ?? ?? ?? ?? 3B C3 0F 8C ?? ?? ?? ?? 7F ?? 81 F9 ?? ?? ?? ?? 0F - } - $encrypt_files_p3 = { - 86 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 74 24 ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 E8 ?? ?? - ?? ?? 59 89 44 24 ?? FF 15 ?? ?? ?? ?? 53 53 33 C9 51 33 C0 50 FF 74 24 ?? FF D7 53 - 8D 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 8B 54 24 ?? - 51 56 FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 53 33 C0 50 50 FF 74 24 ?? FF D7 53 8D - 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? - 59 E9 ?? ?? ?? ?? 51 53 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? FF 15 ?? - ?? ?? ?? 53 53 33 C0 50 53 FF 74 24 ?? FF D7 53 8D 44 24 ?? 50 FF 74 24 ?? FF 74 24 - ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 8B 4C 24 - ?? 8B 54 24 ?? 51 FF 74 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 53 33 C0 50 53 - FF 74 24 ?? FF D7 53 8D 44 24 ?? 50 FF 74 24 ?? FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? - ?? ?? FF 74 24 ?? 53 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 33 FF 8D 74 24 ?? - E8 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? FF 74 24 ?? - E8 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 8D 45 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 72 ?? 8B 00 83 7D ?? ?? 8B - 4D ?? 73 ?? 8D 4D ?? 50 51 FF 15 ?? ?? ?? ?? 6A ?? 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? - 6A ?? 33 FF 8D 75 ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 - 5D C3 - } - $find_files_1 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 56 - 57 6A ?? 5E 33 C0 33 FF 6A ?? 66 89 44 24 ?? 57 8D 45 ?? 8D 4C 24 ?? 89 74 24 ?? 89 - 7C 24 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 66 - 89 44 24 ?? 66 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? 03 44 24 ?? 8D 4C 24 ?? 89 74 24 ?? - 89 7C 24 ?? 89 74 24 ?? 89 7C 24 ?? E8 ?? ?? ?? ?? 57 8D 44 24 ?? 50 83 C8 ?? 8D 74 - 24 ?? E8 ?? ?? ?? ?? 57 8D 84 24 ?? ?? ?? ?? 50 83 C8 ?? E8 ?? ?? ?? ?? 8B DE 8D 44 - 24 ?? E8 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 8B 44 24 ?? 73 ?? 8D 44 24 - ?? 8D 8C 24 ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? - ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 + $find_files = { + 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? + ?? 64 FF 30 64 89 20 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 7E ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? + 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B + 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 F6 85 ?? ?? ?? + ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 + ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 8B E5 5D C3 } - $find_files_2 = { - D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? F6 - 84 24 ?? ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 4C 24 ?? 8D 44 24 ?? 74 ?? E8 ?? ?? - ?? ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 59 8B D8 59 8D 44 24 ?? E8 ?? ?? ?? ?? 6A ?? 33 - FF 8D 74 24 ?? E8 ?? ?? ?? ?? 6A ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 83 EC ?? 8B CC 21 79 - ?? 33 C0 6A ?? C7 41 ?? ?? ?? ?? ?? 66 89 01 50 8D 44 24 ?? E8 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 59 8D 44 24 ?? E8 ?? ?? ?? ?? 6A - ?? 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 50 8D - 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 6A ?? 5F 39 7C 24 ?? 73 ?? 8D 44 24 ?? 8B 35 ?? - ?? ?? ?? 68 + $encrypt_files = { + 55 8B EC 83 C4 ?? 53 56 57 33 DB 89 5D ?? 89 4D ?? 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? + ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 + FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 89 45 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? + ?? 64 FF 30 64 89 20 33 C9 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 0D ?? ?? + ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C9 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 + 45 ?? 8B 0D ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? + ?? ?? 8B 45 ?? 8B 10 FF 12 52 50 8B 45 ?? 8B 10 FF 52 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 10 FF 12 50 8B 4D ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? + 8B 45 ?? 8B 10 FF 52 ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 10 FF 12 50 + 8B 4D ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 10 FF 52 ?? 8B 55 ?? 8B 45 ?? + E8 ?? ?? ?? ?? 8D 45 ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? + ?? 8B 45 ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C3 } - $find_files_3 = { - 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 39 7C 24 ?? 73 ?? 8D 44 24 ?? 68 ?? ?? - ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 39 7C 24 ?? 73 ?? 8D 44 24 ?? 68 - ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 39 7C 24 ?? 73 ?? 8D 44 24 - ?? 68 ?? ?? ?? ?? 50 FF D6 85 C0 74 ?? 8B 44 24 ?? 39 7C 24 ?? 73 ?? 8D 44 24 ?? 68 - ?? ?? ?? ?? 50 FF D6 85 C0 74 ?? 8B 44 24 ?? 39 7C 24 ?? 73 ?? 8D 44 24 ?? 68 ?? ?? - ?? ?? 50 FF D6 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 74 ?? - 8B 4C 24 ?? 39 7C 24 ?? 73 ?? 8D 4C 24 ?? 83 EC ?? 8B C4 51 E8 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? 6A ?? 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 74 - 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 33 DB - 43 53 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? 53 8D B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 8D - 74 24 ?? E8 ?? ?? ?? ?? 53 8D 75 ?? E8 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E 5B 33 - CC E8 ?? ?? ?? ?? 8B E5 5D C3 + $delete_shadow_copies = { + 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 + 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B + 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? + ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? + ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B + 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? + ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? + ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B + 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? + ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? + ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B + 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? + ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 8B + E5 5D C3 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_*)) and ($create_encryption_key) and ($encrypt_encryption_key) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($delete_shadow_copies) } -rule REVERSINGLABS_Win32_Ransomware_Bkransomware : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_District : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects BKRansomware ransomware." + description = "Yara rule that detects District ransomware." author = "ReversingLabs" - id = "88dc5c4a-046a-52e2-b108-0a90b91d4fb6" + id = "fc6abbc7-66f9-56e6-8106-5f360f25b092" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.BKRansomware.yara#L1-L79" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3118098f05a13bd161af0cb1ec322878b371ff70b9f3815a04115a214c0965a2" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.District.yara#L1-L194" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "9ce395636fd7719f503726df82998e1ac72e9e80fd7a4534bd2251ac9283af38" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -35760,225 +37301,177 @@ rule REVERSINGLABS_Win32_Ransomware_Bkransomware : TC_DETECTION MALICIOUS MALWAR sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "BKRansomware" + tc_detection_name = "District" tc_detection_factor = 5 importance = 25 strings: - $search_files = { - 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B F9 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? - 57 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? EB ?? 8D A4 24 ?? ?? ?? ?? 90 - 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? - 8B B5 ?? ?? ?? ?? 83 FE ?? 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B - 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 - 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 74 ?? B8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - 66 8B 11 66 3B 10 75 ?? 66 85 D2 74 ?? 66 8B 51 ?? 66 3B 50 ?? 75 ?? 83 C1 ?? 83 C0 - ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 57 8D - 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 83 FE ?? 74 ?? - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? - 50 57 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 - FF 15 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } $encrypt_files_p1 = { - 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 57 6A ?? 68 - ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B F9 68 ?? ?? ?? ?? 57 89 BD ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 56 6A ?? 53 FF 15 ?? ?? ?? - ?? 8B F0 68 ?? ?? ?? ?? 57 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? - ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 - C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? - ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? - 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 - C0 75 ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 F6 0F 8E ?? ?? ?? ?? 33 + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 + 24 ?? 8B F1 8D 4D ?? 50 E8 ?? ?? ?? ?? 40 C7 44 24 ?? ?? ?? ?? ?? 6A ?? 33 C9 C7 44 + 24 ?? ?? ?? ?? ?? 50 8D 45 ?? 66 89 4C 24 ?? 50 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 EC ?? + C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 40 C7 84 24 ?? ?? ?? + ?? ?? ?? ?? ?? 33 C9 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 50 51 8D 45 ?? 66 89 8C 24 ?? + ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 8D + 44 24 ?? 8D 4C 24 ?? 50 E8 ?? ?? ?? ?? 40 C7 44 24 ?? ?? ?? ?? ?? 6A ?? 33 C9 C7 44 + 24 ?? ?? ?? ?? ?? 50 8D 44 24 ?? 66 89 4C 24 ?? 50 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 EC + ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 8D 4C 24 ?? 50 E8 ?? ?? ?? ?? 33 C9 C7 44 24 + ?? ?? ?? ?? ?? 50 51 8D 44 24 ?? 66 89 4C 24 ?? 50 8D 4C 24 ?? C7 44 24 ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? 6A ?? 50 66 89 44 24 ?? 8D 4C 24 ?? + 8D 45 ?? C7 44 24 ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 56 8D 4C 24 ?? E8 ?? + ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 6A ?? 0F 43 45 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? + ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 66 0F 6E C0 F3 0F E6 C0 C1 E8 ?? F2 0F 58 04 C5 + ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 56 E8 ?? ?? ?? ?? 56 8B D8 } $encrypt_files_p2 = { - FF 8D 49 ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 68 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? 33 F6 8D 51 ?? EB ?? 8D 49 ?? 8A 01 41 84 C0 75 ?? 2B CA 74 ?? BB ?? ?? ?? ?? - 8A 84 35 ?? ?? ?? ?? 3C ?? 7C ?? 3C ?? 7F ?? 0F BE C0 83 E8 ?? 99 F7 FB 80 C2 ?? EB - ?? 3C ?? 7C ?? 3C ?? 7F ?? 0F BE C0 83 E8 ?? 99 F7 FB 80 C2 ?? 88 94 35 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 46 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 3B F0 72 ?? 8B 9D ?? ?? ?? - ?? 6A ?? 6A ?? 57 53 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 51 ?? 8D 9B ?? ?? ?? ?? - 8A 01 41 84 C0 75 ?? 6A ?? 8D 85 ?? ?? ?? ?? 2B CA 50 51 8D 85 ?? ?? ?? ?? 50 53 FF - 15 ?? ?? ?? ?? 03 BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 3B BD ?? ?? ?? ?? 0F 8C ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 53 FF 15 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 57 8D 85 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? - 5E 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + E8 ?? ?? ?? ?? 83 C4 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 0F 1F 40 ?? 0F 1F 84 00 + ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 6A ?? A3 ?? ?? ?? ?? 8D 44 24 ?? 50 56 + 53 57 89 0D ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 56 FF 74 24 ?? 8B D3 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? F7 D8 6A + ?? 6A ?? 50 57 FF 15 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 56 FF 74 24 ?? 57 FF 15 ?? ?? + ?? ?? 83 6C 24 ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 + FF 15 ?? ?? ?? ?? 83 7C 24 ?? ?? 8D 4C 24 ?? 8D 45 ?? 0F 43 4C 24 ?? 83 7D ?? ?? 51 + 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 83 F8 ?? 72 ?? 40 8D 4C 24 ?? 50 FF 74 + 24 ?? E8 ?? ?? ?? ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 ?? 8B 44 24 ?? C7 44 + 24 ?? ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 4C 24 ?? 50 FF 74 24 ?? E8 ?? ?? ?? ?? 33 C0 + C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 ?? 8B 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 83 F8 ?? + 72 ?? 40 8D 4C 24 ?? 50 FF 74 24 ?? E8 ?? ?? ?? ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? 66 + 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 4C 24 + ?? 50 FF 74 24 ?? E8 ?? ?? ?? ?? 33 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 44 24 + ?? 8B 44 24 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 4C 24 ?? 50 FF + 74 24 ?? E8 ?? ?? ?? ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 ?? 89 44 24 ?? 8B + 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 77 ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 + C1 ?? 75 ?? 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 ?? 72 ?? 83 F9 ?? 77 ?? 8B C8 51 E8 ?? + ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C2 } - - condition: - uint16(0)==0x5A4D and ($search_files) and ( all of ($encrypt_files_p*)) -} -rule REVERSINGLABS_Win32_Ransomware_Bam2021 : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Bam2021 ransomware." - author = "ReversingLabs" - id = "31ae99e3-223c-51fb-97c1-353ff063057f" - date = "2021-09-17" - modified = "2021-09-17" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Bam2021.yara#L1-L167" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "5b717510991b78f07806e88f3dfe1c27d6ec1ec21af61a7c4f1edf7c915785d5" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Bam2021" - tc_detection_factor = 5 - importance = 25 - - strings: - $enum_shares = { - 83 EC ?? 53 55 8B 2D ?? ?? ?? ?? 56 57 68 ?? ?? ?? ?? FF D5 8B 74 24 ?? 6A ?? 56 C7 - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4C 24 - ?? 8D 44 24 ?? 50 51 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 89 06 33 C0 5F 5E - 5D 5B 83 C4 ?? C2 ?? ?? 8B 54 24 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 8B F8 89 7C 24 ?? 85 - FF 75 ?? 89 06 8B 44 24 ?? 50 6A ?? 57 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 8D 4C 24 - ?? 51 57 8D 54 24 ?? 52 50 E8 ?? ?? ?? ?? 8B F0 85 F6 0F 85 ?? ?? ?? ?? 33 DB 39 5C - 24 ?? 76 ?? 8D 77 ?? 90 33 C0 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 - 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 8B 06 50 C7 44 24 ?? ?? ?? ?? ?? 89 44 24 - ?? FF D5 6A ?? 6A ?? 6A ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 3E E8 ?? ?? - ?? ?? 8B 7C 24 ?? 8B 54 24 ?? 6A ?? 6A ?? 52 E8 ?? ?? ?? ?? 8B 46 ?? 83 E0 ?? 3C ?? - 75 ?? 8B 4C 24 ?? 8B 44 24 ?? 51 8D 56 ?? 52 50 E8 ?? ?? ?? ?? 43 83 C6 ?? 3B 5C 24 - ?? 0F 82 ?? ?? ?? ?? E9 ?? ?? ?? ?? 81 FE ?? ?? ?? ?? 74 ?? 56 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 89 31 57 FF 15 ?? ?? ?? ?? 8B 54 24 ?? 52 E8 ?? ?? ?? - ?? 8B F0 85 F6 74 ?? 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 89 30 33 - C0 5F 5E 5D 5B 83 C4 ?? C2 + $find_files = { + 53 55 56 57 6A ?? 8B F1 E8 ?? ?? ?? ?? 83 C4 ?? 8D 9E ?? ?? ?? ?? 8B E8 53 68 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 53 50 89 45 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D BE ?? ?? ?? + ?? 0F 1F 80 ?? ?? ?? ?? F6 03 ?? 57 74 ?? 8B CE E8 ?? ?? ?? ?? 84 C0 75 ?? 57 E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 50 8B CE E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? 84 C0 74 + ?? 8B CE E8 ?? ?? ?? ?? 53 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 80 7C 24 ?? ?? 75 + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 55 E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5D + 5B C2 } - $find_files_p1 = { - 8D 94 24 ?? ?? ?? ?? 52 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 - ?? 0F 84 ?? ?? ?? ?? 8B 7C 24 ?? EB ?? 8D A4 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 84 24 - ?? ?? ?? ?? 8D 64 24 ?? 66 8B 10 66 3B 11 75 ?? 66 3B D5 74 ?? 66 8B 50 ?? 66 3B 51 - ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D5 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 3B C5 0F 84 ?? - ?? ?? ?? B9 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 90 66 8B 10 66 3B 11 75 ?? 66 3B D5 74 - ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D5 75 ?? 33 C0 EB ?? 1B C0 - 83 D8 ?? 3B C5 0F 84 ?? ?? ?? ?? F6 84 24 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 8C 24 - ?? ?? ?? ?? 51 BB ?? ?? ?? ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 9C 24 ?? ?? - ?? ?? 8D 74 24 ?? C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 55 8D 8C 24 - ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? 8B 54 24 ?? - 52 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C6 84 24 ?? ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? 89 6C 24 ?? 66 89 44 24 ?? 72 ?? 8B 4C 24 ?? 51 E8 ?? ?? ?? ?? - 83 C4 ?? 8B 54 24 ?? 8B 44 24 ?? 42 3B C2 77 ?? 8D 5C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 - ?? 8B 4C 24 ?? 8B 54 24 ?? 8D 34 0A 3B C6 77 ?? 2B F0 8B 44 24 ?? 39 2C B0 75 ?? 6A - ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 89 04 B1 8B 54 24 ?? 8B 0C B2 89 4C 24 ?? 89 + $enum_resources_1_p1 = { + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 55 56 57 33 C0 C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 + ?? 8B DA 8D 44 24 ?? 89 5C 24 ?? 50 51 6A ?? 6A ?? 6A ?? C7 44 24 ?? ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 85 C0 74 ?? 3D ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? + 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? BE ?? ?? + ?? ?? E9 ?? ?? ?? ?? 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 50 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 3D + ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? + ?? ?? ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 ED 89 + 6C 24 ?? 39 6C 24 ?? 0F 86 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 85 DB 0F 8E ?? ?? ?? ?? C1 + E5 ?? 8B F3 89 6C 24 ?? 89 5C 24 ?? 0F 1F 84 00 ?? ?? ?? ?? 83 BC 2C ?? ?? ?? ?? ?? + 0F 85 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 74 ?? 8B 84 2C ?? ?? ?? ?? 66 83 78 ?? ?? 8D + 50 ?? 74 ?? 8D B4 24 ?? ?? ?? ?? 8D 48 ?? 8A 01 8D 52 ?? 88 06 8D 76 ?? 66 83 3A } - $find_files_p2 = { - 4C 24 ?? C6 84 24 ?? ?? ?? ?? ?? 3B CD 74 ?? 33 C0 C7 41 ?? ?? ?? ?? ?? 89 69 ?? 6A - ?? 66 89 41 ?? 55 8D 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? FF 44 - 24 ?? E9 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 73 ?? 8D 84 24 ?? - ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 51 50 68 ?? ?? ?? ?? 6A ?? 8D 94 24 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 47 ?? 50 8D 8C 24 ?? ?? ?? ?? 51 FF 15 ?? ?? - ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? BE ?? ?? ?? ?? 8B 16 52 8D 84 24 ?? - ?? ?? ?? 50 FF D3 85 C0 75 ?? 83 C6 ?? 81 FE ?? ?? ?? ?? 7C ?? E9 ?? ?? ?? ?? 57 8D - 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C0 ?? 8D 94 24 ?? ?? ?? ?? 2B D0 0F - B7 08 66 89 0C 02 83 C0 ?? 66 3B CD 75 ?? 33 C0 EB ?? 8D A4 24 ?? ?? ?? ?? 8D 49 ?? - 0F B7 8C 04 ?? ?? ?? ?? 66 89 8C 04 ?? ?? ?? ?? 83 C0 ?? 66 3B CD 75 ?? 33 C0 8D 9B - ?? ?? ?? ?? 0F B7 88 ?? ?? ?? ?? 66 89 8C 04 ?? ?? ?? ?? 83 C0 ?? 66 3B CD 75 ?? 8B - 5C 24 ?? 6A ?? B9 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 54 24 ?? 8D 8C - 24 ?? ?? ?? ?? 51 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 ?? 50 FF 15 + $enum_resources_1_p2 = { + 8D 49 ?? 75 ?? 8B 74 24 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 + 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B4 2C ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 6A ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 ?? FF 70 ?? 8B 40 ?? 83 E0 ?? 50 8D 84 24 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 74 24 ?? 83 C4 ?? C6 44 24 ?? ?? 8B 56 ?? + F6 C2 ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 + A1 ?? ?? ?? ?? 66 89 41 ?? F6 C2 ?? 74 ?? 8D 4C 24 ?? 49 0F 1F 44 00 ?? 8A 41 ?? 8D + 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? A0 ?? ?? ?? ?? + 88 41 ?? F6 C2 ?? 74 ?? 8D 4C 24 ?? 49 0F 1F 00 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? + ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 66 89 41 ?? A0 ?? ?? ?? ?? + 88 41 ?? F6 C2 ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? + 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F6 C2 ?? 74 ?? 8D 4C 24 ?? 49 66 0F 1F 44 00 ?? + 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F6 } - $encrypt_files_p1 = { - 55 8B EC 83 E4 ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? - ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 56 57 A1 ?? ?? ?? ?? 33 C4 50 8D 84 24 ?? ?? - ?? ?? 64 A3 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 DB 3B C3 75 ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 - 83 C4 ?? 3B F3 74 ?? 68 ?? ?? ?? ?? 8D 46 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 - EB ?? 33 C0 A3 ?? ?? ?? ?? 8D 4C 24 ?? 51 8B F8 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 - 24 ?? ?? ?? ?? 33 D2 53 89 9C 24 ?? ?? ?? ?? 50 66 89 94 24 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 33 C9 53 52 66 89 8C 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 33 C0 53 51 66 89 84 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 33 D2 53 50 66 89 54 - 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 33 C9 53 52 66 89 - 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 47 ?? 83 C4 ?? 50 89 5C 24 ?? 89 44 24 ?? E8 ?? - ?? ?? ?? 53 53 8D 84 24 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 83 EC ?? 8B + $enum_resources_1_p3 = { + C2 ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 A1 ?? + ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? F6 C2 ?? 74 ?? 8D + 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 + 89 41 ?? 84 D2 79 ?? 8D 4C 24 ?? 49 0F 1F 40 ?? 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? + ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 66 + 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? + ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 + ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? + ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 66 + 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D + 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 + ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? + ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? F7 C2 ?? ?? ?? ?? 74 } - $encrypt_files_p2 = { - F4 33 C9 8D 84 24 ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? 89 5E ?? 89 64 24 ?? 66 89 4E ?? - 8D 50 ?? 90 66 8B 08 83 C0 ?? 66 3B CB 75 ?? 2B C2 D1 F8 50 8D 84 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 53 6A ?? 8D 94 24 ?? ?? ?? ?? 52 53 FF 15 ?? ?? ?? ?? - 85 C0 74 ?? 83 EC ?? 8B F4 33 C0 C7 46 ?? ?? ?? ?? ?? 89 5E ?? 66 89 46 ?? 8D 84 24 - ?? ?? ?? ?? 89 64 24 ?? 8D 50 ?? EB ?? 8D 49 ?? 66 8B 08 83 C0 ?? 66 3B CB 75 ?? 2B - C2 D1 F8 50 8D 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 53 6A ?? 8D 8C 24 - ?? ?? ?? ?? 51 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 83 EC ?? 8B F4 33 D2 C7 46 ?? ?? ?? - ?? ?? 89 5E ?? 8D 84 24 ?? ?? ?? ?? 66 89 56 ?? 89 64 24 ?? 8D 50 ?? EB ?? 8D 49 ?? - 66 8B 08 83 C0 ?? 66 3B CB 75 ?? 2B C2 D1 F8 50 8D 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 57 E8 ?? ?? ?? ?? 53 6A ?? 8D 44 24 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? - ?? ?? 8D 4C 24 ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 EC ?? 8B F4 33 D2 C7 46 ?? ?? - ?? ?? ?? 89 5E ?? 8D 44 24 ?? 66 89 56 ?? 89 64 24 ?? 8D 50 ?? 8D A4 24 ?? ?? ?? ?? - 66 8B 08 83 C0 ?? 66 3B CB 75 ?? 2B C2 D1 F8 50 8D 44 24 ?? E8 ?? ?? ?? ?? 57 E8 ?? - ?? ?? ?? 53 6A ?? 8D 84 24 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? - ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 EC ?? 8B F4 33 D2 C7 + $enum_resources_2_p1 = { + 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 A1 ?? ?? ?? + ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 ?? ?? ?? ?? + 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 A1 ?? ?? ?? + ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? + 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 ?? ?? + ?? ?? 74 ?? 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 + 66 A1 ?? ?? ?? ?? 66 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C + 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 + 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? + ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A + 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 + ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 + A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? F7 C2 ?? ?? + ?? ?? 74 ?? 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 } - $encrypt_files_p3 = { - 46 ?? ?? ?? ?? ?? 89 5E ?? 8D 84 24 ?? ?? ?? ?? 66 89 56 ?? 89 64 24 ?? 8D 50 ?? 90 - 66 8B 08 83 C0 ?? 66 3B CB 75 ?? 2B C2 D1 F8 50 8D 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 57 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 8D 44 24 ?? 50 53 6A ?? 53 53 53 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 89 5C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4C 24 ?? 51 FF 15 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B F8 53 - 57 E8 ?? ?? ?? ?? 8B 74 24 ?? 83 C4 ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8D 54 - 24 ?? 52 57 8B CE E8 ?? ?? ?? ?? 8B 74 24 ?? E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 74 24 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 8B 8C 24 ?? ?? ?? ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 8C 24 ?? - ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + $enum_resources_2_p2 = { + 01 A1 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D + 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 + 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? + ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 + 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 + C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 + 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? 85 D2 79 + ?? 8D 4C 24 ?? 49 66 0F 1F 44 00 ?? 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 + 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A0 ?? ?? + ?? ?? 88 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 + 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? 8D 4C 24 ?? 8D 51 ?? 8A 01 + 41 84 C0 75 ?? 2B CA 56 88 44 0C ?? FF D7 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 8D } - $generate_key = { - 50 C7 44 24 ?? ?? ?? ?? ?? F3 A5 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5D B8 ?? ?? ?? - ?? 5B 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C2 ?? ?? 8B 44 24 ?? 8D 4C 24 ?? 51 - 6A ?? 6A ?? 6A ?? 8D 54 24 ?? 52 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5D B8 ?? ?? - ?? ?? 5B 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C2 ?? ?? 8B 54 24 ?? 6A ?? 8D 4C - 24 ?? 51 6A ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5D B8 ?? ?? ?? ?? 5B 8B 4C 24 - ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C2 ?? ?? 8B 54 24 ?? 6A ?? 8D 44 24 ?? 50 8D 4C 24 - ?? 51 6A ?? 52 C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5D B8 ?? - ?? ?? ?? 5B 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C2 ?? ?? 8B 44 24 ?? C1 E8 ?? - 89 44 24 ?? 03 C3 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 5F 5E 5D B8 ?? ?? ?? - ?? 5B 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C2 ?? ?? 53 55 56 E8 ?? ?? ?? ?? 8B - 4C 24 ?? 83 C4 ?? 89 5C 24 ?? 83 C3 ?? 53 8D 44 24 ?? 50 56 6A ?? 6A ?? 6A ?? 51 FF - 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5D B8 ?? ?? ?? ?? 5B 8B 4C 24 ?? 33 CC E8 ?? ?? ?? - ?? 83 C4 ?? C2 ?? ?? 8B 7C 24 ?? 8B 54 24 ?? 57 56 52 E8 ?? ?? ?? ?? 8B 44 24 ?? 56 - 89 38 E8 ?? ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 5F 5E 5D 5B 33 CC 33 C0 E8 ?? ?? ?? ?? 83 - C4 ?? C2 + $enum_resources_2_p3 = { + 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 74 24 ?? FF D7 8B BC 2C ?? ?? ?? ?? 33 D2 + 8B CF 8D 71 ?? 8A 01 41 84 C0 75 ?? 2B CE 8D 43 ?? 03 C1 74 ?? 8B 6C 24 ?? 8B DF 8B + CB 42 8D 71 ?? 0F 1F 00 8A 01 41 84 C0 75 ?? 2B CE 8D 45 ?? 03 C1 3B D0 72 ?? 8B 6C + 24 ?? 8B 5C 24 ?? 8B CF 33 D2 8D 71 ?? 8A 01 41 84 C0 75 ?? 2B CE 8D 43 ?? 03 C1 74 + ?? 8B 9C 2C ?? ?? ?? ?? 8B 6C 24 ?? 0F 1F 40 ?? 8B CB 42 8D 71 ?? 8A 01 41 84 C0 75 + ?? 2B CE 8D 45 ?? 03 C1 3B D0 72 ?? 8B 6C 24 ?? 8B 5C 24 ?? 33 D2 8D 4F ?? 8A 07 47 + 84 C0 75 ?? 2B F9 8D 43 ?? 03 C7 74 ?? 8B BC 2C ?? ?? ?? ?? 0F 1F 40 ?? 8B C7 42 8D + 70 ?? 8A 08 40 84 C9 75 ?? 2B C6 40 03 C3 3B D0 72 ?? 8B 3D ?? ?? ?? ?? 8B 74 24 ?? + 83 EE ?? 89 74 24 ?? 0F 85 ?? ?? ?? ?? 8B 6C 24 ?? 8B F5 C1 E6 ?? 8B 84 34 ?? ?? ?? + ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? FF 24 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 + ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 94 34 ?? ?? ?? ?? 66 83 3A ?? 75 ?? 33 C9 EB ?? 8B CA } - $remote_connection = { - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 57 8D 44 24 ?? 50 68 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 89 46 ?? 83 - F8 ?? 74 ?? 8B 46 ?? 8D 7E ?? 83 E8 ?? 83 78 ?? ?? 7E ?? 8B 48 ?? 51 8B CF E8 ?? ?? - ?? ?? 8B 3F 57 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 54 24 ?? 52 89 44 24 ?? FF 15 ?? ?? - ?? ?? 85 C0 75 ?? 8B 46 ?? 50 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 C0 5F 8B 8C 24 - ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 8B 48 ?? 8B 11 8B 02 0F B7 56 - ?? B9 ?? ?? ?? ?? 52 89 44 24 ?? 66 89 4C 24 ?? FF 15 ?? ?? ?? ?? 8B 4E ?? 66 89 44 - 24 ?? 6A ?? 8D 44 24 ?? 50 51 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? FF 15 ?? ?? ?? ?? 8B - 56 ?? 52 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 C0 5F 8B 8C 24 ?? ?? ?? ?? 33 CC E8 - ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 8B 8C 24 ?? ?? ?? ?? 5F 33 CC B8 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 + $enum_resources_2_p4 = { + 8D 79 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CF D1 F9 51 52 8D 4C 24 ?? E8 ?? ?? ?? + ?? 8D 44 24 ?? B9 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 94 34 ?? ?? ?? ?? + 66 83 3A ?? 75 ?? 33 C9 EB ?? 8B CA 8D 79 ?? 0F 1F 44 00 ?? 66 8B 01 83 C1 ?? 66 85 + C0 75 ?? EB ?? 8B 94 34 ?? ?? ?? ?? 66 83 3A ?? 75 ?? 33 C9 EB ?? 8B CA 8D 79 ?? 66 + 8B 01 83 C1 ?? 66 85 C0 75 ?? EB ?? 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? EB ?? 68 ?? + ?? ?? ?? EB ?? 68 ?? ?? ?? ?? EB ?? 8B 94 34 ?? ?? ?? ?? 66 83 3A ?? 75 ?? 33 C9 E9 + ?? ?? ?? ?? 8B CA 8D 79 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? E9 ?? ?? ?? ?? 68 ?? ?? + ?? ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? F6 84 34 ?? ?? ?? ?? ?? 74 ?? 8D + 8C 24 ?? ?? ?? ?? 8D 53 ?? 03 CE E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 45 89 6C 24 ?? 3B + 6C 24 ?? 0F 82 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 33 F6 8B 44 24 ?? 83 F8 ?? + 72 ?? 8B 4C 24 ?? 40 3D ?? ?? ?? ?? 77 ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 75 ?? + 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 ?? 72 ?? 83 F9 ?? 77 ?? 8B C8 51 E8 ?? ?? ?? ?? 83 + C4 ?? 5F 8B C6 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and ($enum_shares) and ( all of ($find_files_p*)) and ($generate_key) and ( all of ($encrypt_files_p*)) and ($remote_connection) + uint16(0)==0x5A4D and ( all of ($encrypt_files_p*)) and ($find_files) and ( all of ($enum_resources_1_p*)) and ( all of ($enum_resources_2_p*)) } -rule REVERSINGLABS_Win64_Ransomware_Pandora : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Jormungand : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Pandora ransomware." + description = "Yara rule that detects Jormungand ransomware." author = "ReversingLabs" - id = "18182bbe-1678-5d0b-a7ee-80c4bbaee99e" - date = "2022-06-01" - modified = "2022-06-01" + id = "418c3d9f-2338-593f-a8ec-a1e25afa50d4" + date = "2021-10-22" + modified = "2021-10-22" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Pandora.yara#L1-L95" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6576bde36ae9a9bc2e9dd878db788c608083b84d96d31e6898f48a264c6b7f1a" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Jormungand.yara#L1-L135" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "049eb4533b37d8d72e50dd1e803a897758386643770d47b3e7690f58e44d5236" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -35986,187 +37479,122 @@ rule REVERSINGLABS_Win64_Ransomware_Pandora : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Pandora" + tc_detection_name = "Jormungand" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 41 57 41 56 41 55 41 54 56 57 55 53 48 83 EC ?? 48 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? - ?? 45 31 F6 41 BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? - ?? 48 89 4C 24 ?? 45 31 C0 41 81 FA ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 0F - 4C CA 41 0F 94 C0 48 8B 8C 08 ?? ?? ?? ?? 48 01 F1 31 D2 31 DB 41 81 FA ?? ?? ?? ?? - 0F 9C C2 0F 95 C3 41 BD ?? ?? ?? ?? 49 29 D5 41 81 FA ?? ?? ?? ?? BF ?? ?? ?? ?? BA - ?? ?? ?? ?? 48 0F 4C FA 4C 8D 4C 9B ?? 41 BB ?? ?? ?? ?? BA ?? ?? ?? ?? 4C 0F 44 DA - 49 83 C8 ?? 31 DB 31 D2 41 81 FA ?? ?? ?? ?? 0F 9C C3 4C 8D 64 1B ?? 0F 94 C2 48 83 - F2 ?? 31 DB 41 81 FA ?? ?? ?? ?? 0F 94 C3 48 8D 1C DB 48 83 C3 ?? EB ?? 0F 1F 40 ?? - 4A 8B AC C0 ?? ?? ?? ?? 48 01 F5 FF E5 FF E1 4A 8B AC E0 ?? ?? ?? ?? 48 01 F5 FF E5 - 48 8B AC D8 ?? ?? ?? ?? 48 01 F5 FF E5 0F 1F 80 ?? ?? ?? ?? 48 8B AC F8 ?? ?? ?? ?? - 48 01 F5 FF E5 4A 8B AC E8 ?? ?? ?? ?? 48 01 F5 FF E5 4A 8B AC D8 ?? ?? ?? ?? 48 01 + $drop_ransom_note = { + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 8D 44 24 ?? 3B 41 ?? 0F 86 ?? ?? ?? ?? 81 EC + ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 89 04 24 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? + ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 + 84 24 ?? ?? ?? ?? 8B 4C 24 ?? 89 4C 24 ?? 8D 54 24 ?? 89 14 24 8B 94 24 ?? ?? ?? ?? + 89 54 24 ?? 8B 94 24 ?? ?? ?? ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? + 8B 54 24 ?? 8B 9C 24 ?? ?? ?? ?? 89 1C 24 8B 9C 24 ?? ?? ?? ?? 89 5C 24 ?? 89 44 24 + ?? 89 4C 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 84 24 ?? ?? ?? ?? 8B 4C 24 + ?? 89 4C 24 ?? 8B 54 24 ?? 89 54 24 ?? C7 04 24 ?? ?? ?? ?? 8B 9C 24 ?? ?? ?? ?? 89 + 5C 24 ?? 8B 9C 24 ?? ?? ?? ?? 89 5C 24 ?? 8D 1D ?? ?? ?? ?? 89 5C 24 ?? C7 44 24 ?? + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 04 24 89 4C 24 ?? C7 44 24 ?? + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 84 24 ?? ?? ?? ?? + 8D 4C 24 ?? 89 0C 24 8B 8C 24 ?? ?? ?? ?? 89 4C 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8B 4C + 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 44 24 ?? 89 4C 24 ?? 8D + 44 24 ?? 89 04 24 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? + ?? ?? 8B 44 24 ?? 8B 4C 24 ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? 89 4C 24 ?? E8 ?? ?? + ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 9C 24 ?? ?? ?? ?? 89 1C 24 89 44 24 ?? + 89 4C 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? + 81 C4 ?? ?? ?? ?? C3 E8 } - $find_files_p2 = { - F5 FF E5 66 0F 1F 84 00 ?? ?? 00 00 48 8B AC D0 ?? ?? ?? ?? 48 01 F5 FF E5 4A 8B AC - C8 ?? ?? ?? ?? 48 01 F5 FF E5 44 89 74 24 ?? 48 63 4C 24 ?? 48 8B 54 24 ?? 48 8B 8C - CA ?? ?? ?? ?? 48 89 4C 24 ?? 48 8B 4C 24 ?? 8B 54 24 ?? BD ?? ?? ?? ?? 01 EA 44 8B - 54 24 ?? BD ?? ?? ?? ?? 41 01 EA 66 83 39 ?? 44 0F 45 D2 E9 ?? ?? ?? ?? 45 31 FF EB - ?? 66 2E 0F 1F 84 00 ?? ?? 00 00 90 41 BF ?? ?? ?? ?? 44 8B 54 24 ?? 41 81 C2 ?? ?? - ?? ?? E9 ?? ?? ?? ?? 66 0F 1F 84 00 ?? ?? 00 00 44 8B 74 24 ?? 41 83 C6 ?? 48 8B 54 - 24 ?? 48 8B 05 ?? ?? ?? ?? 48 8B 80 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 01 C8 48 8B 4C 24 - ?? FF D0 8B 4C 24 ?? BA ?? ?? ?? ?? 01 D1 44 8B 54 24 ?? BA ?? ?? ?? ?? 41 01 D2 85 - C0 44 0F 44 D1 E9 ?? ?? ?? ?? 44 89 F8 48 83 C4 ?? 5B 5D 5F 5E 41 5C 41 5D 41 5E 41 - 5F C3 - } - $generate_key = { - 41 57 41 56 41 55 41 54 56 57 55 53 48 81 EC ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 - 8D B4 24 ?? ?? ?? ?? 48 89 74 24 ?? 48 8B 44 24 ?? 48 8B 05 ?? ?? ?? ?? 48 C7 C5 ?? - ?? ?? ?? 48 8B 80 ?? ?? ?? ?? 48 01 E8 41 BC ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 4C 01 - E1 BA ?? ?? ?? ?? 48 03 15 ?? ?? ?? ?? FF D0 48 8B 05 ?? ?? ?? ?? 48 8B 4C 24 ?? 0F - B7 90 ?? ?? ?? ?? 66 89 51 ?? 48 8B 80 ?? ?? ?? ?? 48 89 01 48 8B 05 ?? ?? ?? ?? 48 - 8B 80 ?? ?? ?? ?? 48 01 E8 48 8B 0D ?? ?? ?? ?? 4C 01 E1 FF D0 48 8B 05 ?? ?? ?? ?? - 48 8B 80 ?? ?? ?? ?? 48 01 E8 48 8B 0D ?? ?? ?? ?? 4C 01 E1 FF D0 48 8B 05 ?? ?? ?? - ?? 48 8B 80 ?? ?? ?? ?? 48 01 E8 48 89 F1 FF D0 48 98 4C 8B 05 ?? ?? ?? ?? 4D 01 E0 - 48 8B 0D ?? ?? ?? ?? 48 8B 99 ?? ?? ?? ?? 48 01 EB 48 8B 0D ?? ?? ?? ?? 4C 01 E1 48 - 89 44 24 ?? 48 8D 15 ?? ?? ?? ?? 49 89 F1 FF D3 89 84 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? - 45 31 ED 41 BE ?? ?? ?? ?? 41 BF ?? ?? ?? ?? BB ?? ?? ?? ?? EB ?? 81 F9 ?? ?? ?? ?? - BA ?? ?? ?? ?? BF ?? ?? ?? ?? 48 0F 44 D7 48 8B 04 10 4C 01 F0 FF E0 + $encrypt_files_aes = { + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? 8B 44 24 + ?? 89 04 24 8B 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 + ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 85 D2 74 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? 89 54 24 ?? 89 5C 24 ?? 83 C4 ?? C3 89 44 24 ?? 89 4C 24 ?? 8B 50 ?? + 89 0C 24 FF D2 8B 44 24 ?? 8B 4C 24 ?? 89 0C 24 8B 4C 24 ?? 89 4C 24 ?? 8B 4C 24 ?? + 89 4C 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 + ?? 8B 54 24 ?? 89 54 24 ?? C7 04 24 ?? ?? ?? ?? 8D 1D ?? ?? ?? ?? 89 5C 24 ?? C7 44 + 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 89 + 1C 24 8B 5C 24 ?? 89 5C 24 ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B + 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8D 15 ?? ?? ?? ?? 89 14 24 8B 54 24 ?? + 89 54 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 + ?? 8B 54 24 ?? 89 54 24 ?? 8B 5C 24 ?? 8B 5B ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? + 8B 6C 24 ?? 89 6C 24 ?? 8B 6C 24 ?? 89 6C 24 ?? 8B 6C 24 ?? 89 6C 24 ?? 8B 6C 24 ?? + 89 2C 24 FF D3 8B 05 ?? ?? ?? ?? 89 04 24 8B 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 + 24 ?? 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 44 24 ?? 89 + 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 83 C4 ?? C3 E8 } - $drop_ransom_note = { - 48 8B 05 ?? ?? ?? ?? 48 8B 80 ?? ?? ?? ?? BD ?? ?? ?? ?? 48 01 E8 48 8B 0D ?? ?? ?? - ?? BE ?? ?? ?? ?? 48 01 F1 48 8B 15 ?? ?? ?? ?? BF ?? ?? ?? ?? 48 01 FA FF D0 48 8B - 0D ?? ?? ?? ?? 48 01 F1 48 8B 05 ?? ?? ?? ?? 48 8B 90 ?? ?? ?? ?? 48 01 EA FF D2 48 - 8B 15 ?? ?? ?? ?? 48 01 F2 48 8B 8C 24 ?? ?? ?? ?? 48 8B 35 ?? ?? ?? ?? 48 8B B6 ?? - ?? ?? ?? 48 01 EE 48 C7 44 24 ?? ?? ?? ?? ?? 41 89 C0 4C 8D 4C 24 ?? FF D6 BE ?? ?? - ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 8B 90 ?? ?? ?? ?? 41 BE ?? ?? - ?? ?? 48 01 EA FF D2 BF ?? ?? ?? ?? 8B 4C 24 ?? B8 ?? ?? ?? ?? 01 C1 E9 ?? ?? ?? ?? - 81 F9 ?? ?? ?? ?? BA ?? ?? ?? ?? BD ?? ?? ?? ?? 48 0F 44 D5 48 8B 04 10 4C 01 E0 FF - E0 8B 44 24 ?? 83 C0 ?? 89 44 24 ?? 8B 4C 24 ?? B8 ?? ?? ?? ?? 01 C1 E9 ?? ?? ?? ?? - 81 F9 ?? ?? ?? ?? BA ?? ?? ?? ?? BD ?? ?? ?? ?? 48 0F 44 D5 48 8B 04 10 4C 01 E0 FF - E0 8B 4C 24 ?? B8 ?? ?? ?? ?? 01 C1 E9 ?? ?? ?? ?? 81 F9 ?? ?? ?? ?? BA ?? ?? ?? ?? - BD ?? ?? ?? ?? 48 0F 44 D5 48 8B 04 10 4C 01 E0 FF E0 8B 4C 24 ?? B8 ?? ?? ?? ?? 01 - C1 C7 44 24 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 81 F9 ?? ?? ?? ?? BA ?? ?? ?? ?? BD ?? ?? - ?? ?? 48 0F 44 D5 48 8B 04 10 4C 01 E0 FF E0 48 8B 05 ?? ?? ?? ?? 48 8B 88 ?? ?? ?? - ?? 48 8B 05 ?? ?? ?? ?? 48 8B 80 ?? ?? ?? ?? 4C 01 F0 C7 44 24 ?? ?? ?? ?? ?? 48 8D - 54 24 ?? 4C 8D 84 24 ?? ?? ?? ?? 4C 8D 4C 24 ?? FF D0 BF ?? ?? ?? ?? 8B 54 24 ?? B9 - ?? ?? ?? ?? 01 CA 8B 4C 24 ?? BD ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? - 48 8B 84 24 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 31 C0 48 81 - C4 ?? ?? ?? ?? 5B 5D 5F 5E 41 5C 41 5D 41 5E 41 5F C3 + $encrypt_files_rsa = { + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? C7 04 24 + ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 89 14 24 89 4C 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B + 44 24 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 48 ?? 8B 50 ?? 8B 40 ?? 89 0C 24 89 54 24 ?? 89 + 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 85 D2 75 ?? + 8D 15 ?? ?? ?? ?? 39 D0 0F 85 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 89 04 + 24 89 54 24 ?? 89 4C 24 ?? 8B 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? 8B 44 24 + ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 8B 6C + 24 ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 89 5C 24 ?? 89 6C 24 ?? 83 C4 ?? C3 C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 89 5C + 24 ?? 83 C4 ?? C3 8D 05 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 44 24 ?? C7 40 ?? ?? + ?? ?? ?? 8B 0D ?? ?? ?? ?? 85 C9 75 ?? 8D 0D ?? ?? ?? ?? 89 08 C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 0D ?? ?? ?? ?? 89 4C 24 ?? 89 + 44 24 ?? 83 C4 ?? C3 89 44 24 ?? 89 04 24 8D 0D ?? ?? ?? ?? 89 4C 24 ?? E8 ?? ?? ?? + ?? 8B 44 24 ?? EB ?? 89 04 24 89 54 24 ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? + ?? 0F 0B } - - condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($generate_key) and ($drop_ransom_note) -} -rule REVERSINGLABS_Win64_Ransomware_Hotcoffee : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects HotCoffee ransomware." - author = "ReversingLabs" - id = "11b26b91-96ae-58d3-8a8a-02a3e7d0b82e" - date = "2021-11-25" - modified = "2021-11-25" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.HotCoffee.yara#L1-L111" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "15ae428c37fcc5a09d324fd9be5a8df3a812e6459cb1ce8eec56eabf785b4c05" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "HotCoffee" - tc_detection_factor = 5 - importance = 25 - - strings: $find_files = { - 48 85 C9 74 ?? B8 ?? ?? ?? ?? 48 2B C1 48 85 C9 48 0F 44 C6 BA ?? ?? ?? ?? 48 2B D0 - 48 8D 8D ?? ?? ?? ?? 48 8D 0C 41 74 ?? 48 05 ?? ?? ?? ?? 48 03 C2 4C 8D 0D ?? ?? ?? - ?? 4C 2B C9 0F 1F 44 00 ?? 48 85 C0 74 ?? 45 0F B7 04 09 66 45 85 C0 74 ?? 66 44 89 - 01 48 83 C1 ?? 48 FF C8 48 83 EA ?? 75 ?? 48 8D 41 ?? 48 85 D2 48 0F 45 C1 66 89 30 - 48 8D 95 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 48 0F 43 95 ?? ?? ?? ?? 48 8D 44 24 ?? - 48 89 44 24 ?? 41 B8 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 4C 8B 44 24 ?? BA ?? - ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 44 24 ?? 48 8B 4C 24 ?? 48 3B - C8 74 ?? FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 66 39 30 74 ?? 48 83 - C0 ?? 48 83 E9 ?? 75 ?? 48 85 C9 74 ?? B8 ?? ?? ?? ?? 48 2B C1 48 85 C9 48 0F 44 C6 - BA ?? ?? ?? ?? 48 2B D0 48 8D 8D ?? ?? ?? ?? 48 8D 0C 41 74 ?? 48 05 ?? ?? ?? ?? 48 - 03 C2 4C 8D 0D ?? ?? ?? ?? 4C 2B C9 48 85 C0 74 ?? 45 0F B7 04 09 66 45 85 C0 74 ?? - 66 44 89 01 48 83 C1 ?? 48 FF C8 48 83 EA ?? 75 ?? 48 8D 41 ?? 48 85 D2 48 0F 45 C1 - 66 89 30 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 4C 8B E0 48 89 - 44 24 ?? 48 83 F8 ?? 75 ?? 48 8B 95 ?? ?? ?? ?? 48 83 FA ?? 72 ?? 48 FF C2 48 8B 8D - ?? ?? ?? ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 - 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 - } - $encrypt_files_p1 = { - B9 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 90 66 83 38 ?? 74 ?? 48 83 C0 ?? 48 83 E9 ?? 75 - ?? 48 85 C9 74 ?? 41 B8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 4C 2B C1 BA ?? ?? ?? ?? 48 - 85 C9 4C 0F 44 C3 4A 8D 04 40 49 2B D0 74 ?? 49 8D 88 ?? ?? ?? ?? 48 03 CA 4C 8D 0D - ?? ?? ?? ?? 4C 2B C8 66 90 48 85 C9 74 ?? 45 0F B7 04 01 66 45 85 C0 74 ?? 66 44 89 - 00 48 FF C9 48 83 C0 ?? 48 83 EA ?? 75 ?? 48 85 D2 48 8D 48 ?? 48 0F 45 C8 66 89 19 - 48 89 5C 24 ?? 45 33 C9 C7 44 24 ?? ?? ?? ?? ?? 44 8B C7 8B D7 C7 44 24 ?? ?? ?? ?? - ?? 49 8B CC FF 15 ?? ?? ?? ?? 45 33 C9 48 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D - 8D ?? ?? ?? ?? 44 8B C7 C7 44 24 ?? ?? ?? ?? ?? 48 8B F0 41 8D 51 ?? FF 15 ?? ?? ?? - ?? 41 B9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 33 D2 48 8D 0D ?? - ?? ?? ?? 4C 8B F0 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? 41 B9 ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 33 D2 48 8D 0D ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 45 33 C9 48 89 44 24 ?? 45 - } - $encrypt_files_p2 = { - 33 C0 BA ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B - 15 ?? ?? ?? ?? 45 33 C9 48 8B 8D ?? ?? ?? ?? 44 8B C0 FF 15 ?? ?? ?? ?? 4C 8B 85 ?? - ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 44 8B CF BA ?? ?? ?? ?? 48 89 44 - 24 ?? FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 32 DB 41 BD ?? ?? ?? ?? 48 - 8B F8 66 66 66 0F 1F 84 00 ?? ?? 00 00 4C 8D 8D ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? - ?? 41 B8 ?? ?? ?? ?? 48 8B D7 48 8B CE FF 15 ?? ?? ?? ?? 81 BD ?? ?? ?? ?? ?? ?? ?? - ?? 48 8D 85 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 89 44 24 ?? - 0F B6 DB 41 0F 42 DD 48 89 7C 24 ?? 44 0F B6 C3 45 33 C9 33 D2 FF 15 ?? ?? ?? ?? 44 - 8B 85 ?? ?? ?? ?? 4C 8D 8D ?? ?? ?? ?? 48 8B D7 48 C7 44 24 ?? ?? ?? ?? ?? 49 8B CE - FF 15 ?? ?? ?? ?? 84 DB 0F 84 ?? ?? ?? ?? 4C 8B 6C 24 ?? 48 85 F6 74 ?? 48 8B CE FF - 15 ?? ?? ?? ?? 4D 85 F6 + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? C7 44 24 + ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8D 05 ?? ?? + ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 44 24 ?? 89 04 24 8B 44 24 ?? 89 44 + 24 ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 0D ?? ?? ?? + ?? 8B 15 ?? ?? ?? ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 8B 05 ?? ?? ?? ?? 8B 0D ?? + ?? ?? ?? 8B 15 ?? ?? ?? ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 90 E8 ?? ?? ?? ?? 83 + C4 ?? C3 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 E8 } - $drop_ransom_note = { - 48 85 C9 74 ?? B8 ?? ?? ?? ?? 48 2B C1 48 85 C9 49 0F 44 C6 BA ?? ?? ?? ?? 48 2B D0 - 48 8D 8D ?? ?? ?? ?? 48 8D 0C 41 74 ?? 48 05 ?? ?? ?? ?? 48 03 C2 4C 8D 0D ?? ?? ?? - ?? 4C 2B C9 66 90 48 85 C0 74 ?? 46 0F B7 04 09 66 45 85 C0 74 ?? 66 44 89 01 48 83 - C1 ?? 48 FF C8 48 83 EA ?? 75 ?? 48 8D 41 ?? 48 85 D2 48 0F 45 C1 66 44 89 30 4C 89 - 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 45 33 C9 45 33 C0 BA ?? ?? - ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 49 C7 C0 ?? ?? ?? ?? 49 FF C0 - 46 38 34 06 75 ?? 4C 89 74 24 ?? 4C 8D 8D ?? ?? ?? ?? 48 8B D6 48 8B CB FF 15 ?? ?? - ?? ?? 48 85 DB 74 ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CE E8 ?? ?? ?? ?? 90 48 8B 95 - ?? ?? ?? ?? 48 83 FA ?? 72 ?? 48 FF C2 48 8B 4D ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 - ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 33 F6 48 89 B5 ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 40 88 75 ?? 48 - 8B 95 ?? ?? ?? ?? 48 83 FA ?? 0F 82 ?? ?? ?? ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 8D ?? - ?? ?? ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 48 83 C2 ?? 48 8B 49 ?? 48 - 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 86 ?? ?? ?? ?? FF 15 + $remote_connection_p1 = { + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? C7 04 24 + ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D + 05 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? C7 40 ?? ?? ?? ?? ?? + 8D 0D ?? ?? ?? ?? 89 0C 24 E8 ?? ?? ?? ?? 8B 44 24 ?? C6 40 ?? ?? 8B 0D ?? ?? ?? ?? + 8B 54 24 ?? 8D 5A ?? 85 C9 0F 85 ?? ?? ?? ?? 89 42 ?? 8D 05 ?? ?? ?? ?? 89 04 24 E8 + ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8D 0D + ?? ?? ?? ?? 89 08 8B 0D ?? ?? ?? ?? 8D 50 ?? 85 C9 0F 85 ?? ?? ?? ?? 8B 4C 24 ?? 89 + 48 ?? C7 04 24 ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B + 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 + ?? ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 + 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8D 15 ?? ?? ?? ?? 89 14 24 E8 ?? ?? ?? ?? + 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 48 ?? 8B 0D ?? ?? ?? ?? 85 C9 0F 85 ?? ?? ?? + ?? 8B 4C 24 ?? 89 08 C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C7 40 } - $enum_drives = { - 48 89 5D ?? 48 C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? FF 15 ?? ?? ?? ?? 8B F8 0F A3 DF 0F - 83 ?? ?? ?? ?? 8D 4B ?? 48 C7 45 ?? ?? ?? ?? ?? 88 4D ?? 48 C7 45 ?? ?? ?? ?? ?? 66 - C7 45 ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 3B 05 ?? ?? ?? ?? 74 ?? 48 8D 55 ?? 48 8B C8 - E8 ?? ?? ?? ?? 48 83 05 ?? ?? ?? ?? ?? EB ?? 4C 8D 45 ?? 48 8B D0 48 8D 0D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 90 48 8B 45 ?? 48 83 F8 ?? 72 ?? 48 8D 50 ?? 48 8B 4D ?? 48 8B C1 - 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? - 77 ?? E8 ?? ?? ?? ?? FF C3 83 FB ?? 0F 8C ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? - E8 ?? ?? ?? ?? 90 33 C0 48 8B 4D ?? 48 33 CC E8 ?? ?? ?? ?? 4C 8D 5C 24 ?? 49 8B 5B - ?? 49 8B 7B ?? 49 8B E3 5D C3 FF 15 + $remote_connection_p2 = { + C7 04 24 ?? ?? ?? ?? 8D 0D ?? ?? ?? ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 4C 24 + ?? 89 4C 24 ?? 8B 4C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 4C + 24 ?? 89 44 24 ?? 8D 05 ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? ?? 8D 05 ?? ?? ?? + ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C + 24 ?? 8B 54 24 ?? 89 0C 24 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 8B 44 24 + ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 89 0C + 24 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 75 ?? 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 + 8B 48 ?? 84 01 8B 40 ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? 8D 41 ?? 89 44 24 ?? E8 ?? + ?? ?? ?? 85 C0 75 ?? EB ?? 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 89 04 24 8B 4C 24 ?? 89 4C + 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? E9 ?? ?? ?? ?? 89 14 24 8B 44 24 ?? 89 44 24 ?? E8 + ?? ?? ?? ?? E9 ?? ?? ?? ?? 89 1C 24 89 44 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 90 E8 + ?? ?? ?? ?? 83 C4 ?? C3 E8 } condition: - uint16(0)==0x5A4D and ($enum_drives) and ($find_files) and ( all of ($encrypt_files_p*)) and ($drop_ransom_note) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_*)) and ( all of ($remote_connection_p*)) and ($drop_ransom_note) } -rule REVERSINGLABS_Win32_Ransomware_Notpetya : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Goodwill : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects NotPetya ransomware." + description = "Yara rule that detects GoodWill ransomware." author = "ReversingLabs" - id = "ea655048-4ef7-5dd7-872e-f1c2e38234cf" - date = "2020-07-15" - modified = "2020-07-15" + id = "66358802-450b-5276-8088-b3550519b1e8" + date = "2022-06-28" + modified = "2022-06-28" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.NotPetya.yara#L1-L73" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "328f0e527fee2145879ee13c003d375db832f7f3eacf7a1eb303393c1c8b5a36" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.GoodWill.yara#L1-L89" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "94e2950f415ba737fe5ca9d32a3d850dd5744e547c4ca094ad28545e19033cb2" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -36174,304 +37602,64 @@ rule REVERSINGLABS_Win32_Ransomware_Notpetya : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "NotPetya" + tc_detection_name = "GoodWill" tc_detection_factor = 5 importance = 25 strings: $encrypt_file = { - 8B EC 83 EC ?? 53 56 57 33 F6 56 56 6A ?? 56 56 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? - ?? ?? 8B F8 89 7D ?? 83 FF ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 57 FF 15 ?? ?? ?? ?? 89 - 75 ?? 39 75 ?? 7C ?? B8 ?? ?? ?? ?? 7F ?? 39 45 ?? 76 ?? 89 45 ?? 8B D8 56 53 56 6A - ?? 56 57 FF 15 ?? ?? ?? ?? 89 45 ?? 3B C6 74 ?? FF 75 ?? 56 56 6A ?? 50 FF 15 ?? ?? - ?? ?? 8B F8 3B FE 74 ?? 53 8D 45 ?? 50 8B 45 ?? 57 56 FF 75 ?? 56 FF 70 ?? FF 15 ?? - ?? ?? ?? 85 C0 74 ?? FF 75 ?? 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? FF 75 ?? FF - 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 5B C9 C2 ?? ?? 8B 45 ?? 89 45 ?? C1 - E8 ?? 8D 58 ?? C7 45 ?? ?? ?? ?? ?? C1 E3 ?? E9 - } - $main = { - 55 8B EC 8B 45 ?? 53 56 8B 35 ?? ?? ?? ?? 57 BF ?? ?? ?? ?? 57 6A ?? BB ?? ?? ?? ?? - 53 83 C0 ?? 6A ?? 50 FF D6 85 C0 75 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? 57 6A - ?? 6A ?? EB ?? 3D ?? ?? ?? ?? 75 ?? 6A ?? 6A ?? 53 8B 45 ?? 6A ?? 83 C0 ?? 50 FF D6 - 85 C0 74 ?? 8B 75 ?? 8B C6 E8 ?? ?? ?? ?? 85 C0 74 ?? 56 6A ?? 56 E8 ?? ?? ?? ?? 56 - E8 ?? ?? ?? ?? FF 76 ?? FF 15 ?? ?? ?? ?? 6A ?? FF 76 ?? FF 15 ?? ?? ?? ?? EB ?? 8B - 75 ?? 56 FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B 5D C2 - } - $encryption_loop = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 83 7D ?? ?? 53 56 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? FF 75 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 44 - 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? - ?? ?? 8B 1D ?? ?? ?? ?? 8B 75 ?? 8B 46 ?? 85 C0 74 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 44 24 ?? 66 8B 10 - 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 - D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 44 24 - ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 - C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 44 24 ?? - 50 FF 75 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? F6 44 - 24 ?? ?? 74 ?? F7 44 24 ?? ?? ?? ?? ?? 75 ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? - FF D3 85 C0 75 ?? 8B 45 ?? 56 48 50 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? EB ?? 8D - 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? 8D 51 ?? 66 8B 31 83 C1 ?? 66 85 F6 75 ?? - 2B CA D1 F9 8D 4C 4C ?? 3B C1 74 ?? 50 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF D3 85 C0 74 ?? FF 75 - ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? - ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5E 5B 8B E5 5D C2 + 02 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 06 6F + ?? ?? ?? ?? 0A 06 28 ?? ?? ?? ?? 0B 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 02 72 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 07 28 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? DE ?? 26 72 ?? + ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 2A } - $shutdown = { - 68 ?? ?? ?? ?? 8B CA 8B D0 0F B7 45 ?? 03 C2 33 D2 F7 F6 0F B7 75 ?? 8D 85 ?? ?? ?? - ?? 50 03 F1 8B FA FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? F6 05 ?? ?? ?? - ?? ?? B8 ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? 56 57 8D 8D ?? ?? ?? ?? 51 50 8D 85 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? EB ?? 8D 85 ?? ?? ?? ?? 50 56 57 - 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 85 ?? ?? - ?? ?? 50 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 5F 5E 8B C3 5B C9 C3 + $aes_encrypt = { + 14 0A 03 0B 73 ?? ?? ?? ?? 0C 73 ?? ?? ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 20 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 03 07 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? + ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? + ?? ?? 6F ?? ?? ?? ?? 09 17 6F ?? ?? ?? ?? 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? + 11 ?? 02 16 02 8E 69 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? + ?? ?? ?? DC 08 6F ?? ?? ?? ?? 0A DE ?? 09 2C ?? 09 6F ?? ?? ?? ?? DC 08 2C ?? 08 6F ?? + ?? ?? ?? DC 06 2A } - - condition: - uint16(0)==0x5A4D and $encrypt_file and $main and $encryption_loop and $shutdown -} -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Namaste : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Namaste ransomware." - author = "ReversingLabs" - id = "e85d7ec3-367b-5bde-a570-8caa1f6cd61b" - date = "2021-08-12" - modified = "2021-08-12" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Namaste.yara#L1-L81" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "5a952276f41b5524bcb82a9ceb076983d2faf2864b3bbd0a06d49bbd5edc1e0e" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Namaste" - tc_detection_factor = 5 - importance = 25 - - strings: $find_files_p1 = { - 03 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 02 06 07 9A 28 ?? ?? ?? ?? 07 17 58 0B 07 06 8E 69 32 - ?? DE ?? 26 DE ?? 00 03 28 ?? ?? ?? ?? 0C 16 0D 2B ?? 08 09 9A 13 ?? 02 11 ?? 28 ?? ?? - ?? ?? 17 28 ?? ?? ?? ?? 09 17 58 0D 09 08 8E 69 32 ?? DE ?? 26 DE ?? 2A + 28 ?? ?? ?? ?? 0A 1F ?? 28 ?? ?? ?? ?? 0B 18 8D ?? ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 + 17 72 ?? ?? ?? ?? A2 0C 06 0D 16 13 ?? 38 ?? ?? ?? ?? 09 11 ?? 9A 13 ?? 11 ?? 6F ?? ?? + ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? DD ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 + ?? 28 ?? ?? ?? ?? 08 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 28 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 17 28 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 7D ?? ?? + ?? ?? 11 ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 19 6F ?? ?? ?? ?? 6F ?? + ?? ?? ?? DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? + ?? DC DE ?? 26 DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? + ?? ?? ?? DC 11 ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? 73 ?? ?? ?? ?? 13 ?? + 11 ?? 11 ?? 6F ?? ?? ?? ?? 7D ?? ?? ?? ?? 11 ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? + ?? ?? ?? 25 19 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? + DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? + 8E 69 3F ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 09 8E 69 3F ?? ?? ?? ?? 08 } $find_files_p2 = { - 02 7B ?? ?? ?? ?? 2D ?? 03 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 17 2A 03 6F ?? ?? ?? ?? - 0A 06 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 72 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 - 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? - ?? ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 - 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? - ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 16 2A 02 7B ?? ?? ?? ?? 2C ?? 03 72 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 16 2A 02 7B ?? ?? ?? ?? 2D ?? 03 72 ?? ?? ?? ?? 6F ?? ?? - ?? ?? 2D ?? 16 2A 03 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 03 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 20 ?? ?? ?? ?? 6A 31 ?? 16 0C DE ?? DE ?? 26 DE ?? 02 28 ?? ?? ?? ?? 07 28 ?? ?? ?? ?? - 2A 08 2A - } - $encrypt_files_p1 = { - 02 03 28 ?? ?? ?? ?? 2C ?? 02 7B ?? ?? ?? ?? 2C ?? 02 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 02 7B ?? ?? ?? ?? 03 6F ?? ?? ?? ?? 02 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 2B ?? 02 03 72 - ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 02 7B ?? ?? ?? ?? 2C ?? 03 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 2C ?? 02 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 2A - } - $encrypt_files_p2 = { - 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 02 20 ?? ?? ?? - ?? 7D ?? ?? ?? ?? 02 17 7D ?? ?? ?? ?? 02 17 7D ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? - ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 02 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 1B 28 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 02 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 02 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 1F - ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 2B ?? 12 ?? 28 ?? ?? ?? ?? 0B 02 07 - 28 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? - DC 02 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2A - } - $encrypt_files_p3 = { - 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? 26 73 ?? ?? ?? ?? 0A 06 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 06 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 18 6F ?? ?? ?? ?? 04 14 73 ?? ?? ?? ?? 0B 06 07 06 - 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 07 06 6F ?? ?? ?? ?? 1E 5B 6F ?? - ?? ?? ?? 6F ?? ?? ?? ?? 06 1A 6F ?? ?? ?? ?? 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 18 73 ?? - ?? ?? ?? 0C 08 06 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 0D 03 19 73 ?? ?? ?? ?? 13 ?? 20 ?? - ?? ?? ?? 8D ?? ?? ?? ?? 13 ?? 2B ?? 09 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 11 ?? 11 ?? 16 11 - ?? 8E 69 6F ?? ?? ?? ?? 25 13 ?? 16 30 ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 09 - 2C ?? 09 6F ?? ?? ?? ?? DC 08 2C ?? 08 6F ?? ?? ?? ?? DC 03 28 ?? ?? ?? ?? 2A - } - - condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) -} -rule REVERSINGLABS_Win32_Ransomware_IFN643 : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects IFN643 ransomware." - author = "ReversingLabs" - id = "a4d211a7-6735-541e-885d-555bbc11e2cf" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.IFN643.yara#L1-L90" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ced234018f1f05601dd3be55eaecd2a1e116ad0b7bb9e0292434f11f19916ebe" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "IFN643" - tc_detection_factor = 5 - importance = 25 - - strings: - $search_files_1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 89 B5 ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8B D6 C7 45 ?? ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 - ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? - 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 8D 8D ?? - ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB - ?? 0F 84 - } - $search_files_2 = { - 80 BD ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 75 ?? 33 - C0 EB ?? 8D 85 ?? ?? ?? ?? 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 50 8D 85 ?? ?? ?? ?? - 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D6 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B D0 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 8B C8 C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B 0D ?? ?? ?? ?? F7 - E9 C1 FA ?? 8B C2 C1 E8 ?? 03 C2 83 F8 ?? 0F 83 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 85 C0 0F 8E ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D6 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 4D ?? C6 45 ?? ?? 51 8B D0 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8B 85 ?? - ?? ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? - ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? - 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? - 8B 35 ?? ?? ?? ?? 33 DB 2B CE C7 85 ?? ?? ?? ?? ?? ?? ?? ?? F7 E9 C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? C1 FA ?? 8B C2 C6 85 ?? ?? ?? ?? ?? C1 E8 ?? 03 C2 74 ?? 33 FF ?? ?? ?? - 8D 45 ?? 8D 0C 37 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 83 7D ?? ?? 89 45 ?? 8D 45 ?? 0F 43 - 45 ?? C6 00 ?? 8B 35 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B CE 43 F7 E9 83 - C7 ?? C1 FA ?? 8B C2 C1 E8 ?? 03 C2 3B D8 72 ?? 83 7D ?? ?? 76 ?? 8D 45 ?? B9 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B 0D ?? ?? ?? ?? F7 E9 C1 - FA ?? 8B C2 C1 E8 ?? 03 C2 83 F8 ?? 0F 83 ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? - 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F - 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 - E8 ?? ?? ?? ?? 83 C4 ?? 8B 9D ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? - ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 - F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? - 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B - 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? - 8B 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 - ?? E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 - ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 - ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? - 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 - ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 - ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E - 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $encrypt_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? - 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 65 ?? 8B C2 89 45 ?? 8B F9 8B 75 ?? 89 75 ?? - C7 45 ?? ?? ?? ?? ?? 90 3B F8 0F 84 ?? ?? ?? ?? 89 75 ?? C6 45 ?? ?? 85 F6 74 ?? 8B - 17 C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? 83 7E ?? ?? C7 46 - ?? ?? ?? ?? ?? 72 ?? 8B 06 EB ?? 8B C6 C6 00 ?? 80 3A ?? 75 ?? 33 C0 EB ?? 8B C2 8D - 58 ?? 66 90 8A 08 40 84 C9 75 ?? 2B C3 50 52 8B CE E8 ?? ?? ?? ?? 8B 45 ?? 83 C6 ?? - C6 45 ?? ?? 89 75 ?? 83 C7 ?? EB ?? 8B 55 ?? 51 8B 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A - ?? 6A ?? E8 ?? ?? ?? ?? 8B C6 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C3 - 2B 49 ?? E9 ?? ?? ?? ?? 2B 49 ?? E9 ?? ?? ?? ?? 2B 49 ?? E9 ?? ?? ?? ?? 2B 49 ?? E9 - ?? ?? ?? ?? 33 C0 57 8B F9 40 F0 0F C1 05 ?? ?? ?? ?? 75 ?? 56 BE ?? ?? ?? ?? 56 E8 - ?? ?? ?? ?? 83 C6 ?? 59 81 FE ?? ?? ?? ?? 7C ?? 5E 8B C7 5F C3 - } - - condition: - uint16(0)==0x5A4D and $search_files_1 and $search_files_2 and $encrypt_files -} -rule REVERSINGLABS_Win64_Ransomware_Wintenzz : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Wintenzz ransomware." - author = "ReversingLabs" - id = "6bf569e8-b050-51ef-a948-0eb294248d63" - date = "2021-11-02" - modified = "2021-11-02" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Wintenzz.yara#L1-L83" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ff4bdf2f6ee185b98d0014b3066806fe7e25ea94f46837948bc5262440bf8a56" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Wintenzz" - tc_detection_factor = 5 - importance = 25 - - strings: - $find_files = { - 48 8D 75 ?? 41 B8 ?? ?? ?? ?? 48 89 F1 31 D2 E8 ?? ?? ?? ?? 48 89 F9 48 89 F2 E8 ?? - ?? ?? ?? 48 83 F8 ?? 0F 84 ?? ?? ?? ?? 48 89 C6 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? - ?? ?? 0F 28 85 ?? ?? ?? ?? 0F 29 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? - ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? 0F 11 00 0F 28 85 ?? ?? ?? - ?? 0F 11 40 ?? 48 8B 8D ?? ?? ?? ?? 48 89 48 ?? 49 89 77 ?? 49 89 47 ?? 41 C7 47 ?? - ?? ?? ?? ?? 49 8D 4F ?? 48 8D 55 ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 B6 ?? 31 C0 - 49 89 07 48 85 DB 75 ?? EB ?? E8 ?? ?? ?? ?? 48 C1 E0 ?? 49 89 47 ?? 49 C7 47 ?? ?? - ?? ?? ?? B8 ?? ?? ?? ?? 31 F6 49 89 07 48 85 DB 74 ?? 48 01 DB 74 ?? 41 B8 ?? ?? ?? - ?? 48 89 F9 48 89 DA E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 D2 74 ?? 41 B8 ?? ?? - ?? ?? 4C 89 F1 E8 ?? ?? ?? ?? 40 84 F6 75 ?? 48 8B 8D ?? ?? ?? ?? 48 85 C9 74 ?? 48 - 8B 95 ?? ?? ?? ?? 48 85 D2 74 ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 F8 48 81 C4 - ?? ?? ?? ?? 5B 5F 5E 41 5E 41 5F 5D C3 BA - } - $encrypt_files_p1 = { - 4C 89 75 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D - 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 C7 45 ?? ?? ?? ?? ?? - 48 C7 45 ?? ?? ?? ?? ?? 48 89 7D ?? 48 C7 45 ?? ?? ?? ?? ?? 48 8D 4D ?? 48 8D 55 ?? - E8 ?? ?? ?? ?? 0F 10 45 ?? 0F 29 45 ?? 48 8B 45 ?? 48 89 45 ?? 48 8D 4D ?? 48 8D 55 - ?? E8 ?? ?? ?? ?? 48 85 DB 74 ?? BA ?? ?? ?? ?? 48 89 D9 E8 ?? ?? ?? ?? 48 85 C0 75 - ?? BA ?? ?? ?? ?? 48 89 D9 E8 - } - $encrypt_files_p2 = { - 86 97 ?? ?? ?? ?? C0 74 3C ?? ?? C1 E8 ?? 28 03 00 48 ?? C0 74 2F ?? ?? FA 03 75 ?? - 48 8D 0D ?? ?? ?? ?? 48 39 C8 0F 84 ?? ?? ?? ?? 0F B7 08 81 F1 ?? ?? ?? ?? 0F B6 40 - ?? 83 F0 ?? 66 09 C8 0F 84 ?? ?? ?? ?? 48 8B 4D ?? 48 8B 55 ?? E8 ?? ?? ?? ?? 48 85 - C0 74 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 83 FA ?? 75 ?? 48 8D 0D ?? ?? ?? - ?? 48 39 C8 0F 84 ?? ?? ?? ?? 81 38 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8B 4D ?? 48 8B - 55 ?? E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 83 FA - ?? 75 ?? 48 8D 0D ?? ?? ?? ?? 48 39 C8 0F 84 ?? ?? ?? ?? 0F B7 08 81 F1 ?? ?? ?? ?? - 0F B6 40 ?? 83 F0 ?? 66 09 C8 0F 84 ?? ?? ?? ?? 48 8B 4D ?? 48 8B 55 ?? E8 ?? ?? ?? - ?? 48 85 C0 74 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 83 FA ?? 75 ?? 48 8D 0D - ?? ?? ?? ?? 48 39 C8 0F 84 ?? ?? ?? ?? 0F B7 08 81 F1 ?? ?? ?? ?? 0F B6 40 ?? 83 F0 - ?? 66 09 C8 0F 84 ?? ?? ?? ?? 48 8B 4D + 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 07 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 + ?? 2B ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 17 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? + 2B ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 7D ?? ?? ?? ?? 11 ?? FE 06 ?? ?? + ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 19 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? + 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC DE ?? 26 + DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 07 11 ?? 28 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? + 7D ?? ?? ?? ?? 11 ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 19 6F ?? ?? ?? + ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F + ?? ?? ?? ?? DC DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 2A } - $drop_ransom_note = { - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 D2 74 ?? 48 8B 8D ?? ?? - ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 D2 74 ?? 48 8B 8D - ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 D2 74 ?? 48 - 8B 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 D2 74 - ?? 48 8B 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 - D2 74 ?? 48 8B 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? - 48 85 D2 74 ?? 48 8B 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? - ?? ?? 48 85 D2 74 ?? 48 8B 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 84 F6 - 0F 85 ?? ?? ?? ?? 48 8B 55 ?? 48 85 D2 74 ?? 41 B8 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 48 8B 55 ?? 48 85 D2 74 ?? 41 B8 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 48 8B 55 + $remote_connection = { + 73 ?? ?? ?? ?? 0A 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 17 28 ?? ?? ?? + ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 1C 6F ?? ?? ?? ?? 2B ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? + 1C 6F ?? ?? ?? ?? 06 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 17 0B DE ?? 26 72 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 07 2A } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_*)) and ($drop_ransom_note) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_file) and ($aes_encrypt) and ($remote_connection) } rule REVERSINGLABS_Win32_Ransomware_Termite : TC_DETECTION MALICIOUS MALWARE FILE { @@ -36482,8 +37670,8 @@ rule REVERSINGLABS_Win32_Ransomware_Termite : TC_DETECTION MALICIOUS MALWARE FIL date = "2020-08-31" modified = "2020-08-31" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Termite.yara#L1-L151" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Termite.yara#L1-L151" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "df273de81fc58cb0bacf021ee539ec6dbfa1f1a3e13bd46519ee313595cafb4c" score = 75 quality = 90 @@ -36617,18 +37805,18 @@ rule REVERSINGLABS_Win32_Ransomware_Termite : TC_DETECTION MALICIOUS MALWARE FIL condition: uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Dharma : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Sifrelendi : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Dharma ransomware." + description = "Yara rule that detects Sifrelendi ransomware." author = "ReversingLabs" - id = "8157b20b-717c-581f-83c1-5fc8d2312238" + id = "b9083b7c-eb09-52da-a240-39b51df892f9" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Dharma.yara#L1-L108" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6f33281523b462aaff68bb04f2f6869c3e6cd60cd9306ed80bb0c3e3b699f315" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Sifrelendi.yara#L1-L67" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "430d3877c10c86fcb19b5624dd8886d61e54ccd0453678329309b49712c6d5c6" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -36636,108 +37824,64 @@ rule REVERSINGLABS_Win32_Ransomware_Dharma : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Dharma" + tc_detection_name = "Sifrelendi" tc_detection_factor = 5 importance = 25 strings: - $file_search = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? - 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D 4D ?? 51 8B 55 - ?? 52 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? - 75 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? 81 7D ?? ?? ?? ?? ?? 76 ?? 8B - 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B - 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D - ?? ?? 75 ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 - 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? - 89 45 ?? 8B 45 ?? 8B E5 5D C3 - } - $file_encrypt_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? 8B 45 ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 C1 ?? 89 4D ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 8B 45 ?? 33 D2 B9 ?? ?? ?? ?? F7 F1 8B 45 ?? 2B C2 83 E8 ?? 89 45 ?? 8B - 4D ?? 51 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? - ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 05 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 83 ?? ?? - ?? ?? 8B 4D ?? 83 E1 ?? 74 ?? 8B 55 ?? 83 E2 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 6A ?? - 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? - ?? 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 89 55 ?? 8B 45 ?? 89 85 ?? ?? ?? - ?? 8B 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8B 85 ?? ?? ?? ?? 50 8B 8D - ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? - 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 - ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 4D ?? 51 - E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? - ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 8B 45 ?? 50 8B 4D - ?? 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B - 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 83 7D - ?? ?? 75 ?? 8B 4D ?? 3B 4D ?? 73 ?? 8B 45 ?? 33 D2 B9 ?? ?? ?? ?? F7 F1 B8 ?? ?? ?? - ?? 2B C2 89 45 ?? 8B 4D ?? 03 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8D 8D ?? ?? ?? ?? 51 - E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 8B 45 ?? 03 45 ?? 50 8B 4D ?? 51 - } - $file_encrypt_2 = { - 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 03 45 ?? 39 85 ?? ?? ?? ?? - 74 ?? E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? - 83 C4 ?? 8B 95 ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? - ?? 83 7D ?? ?? 74 ?? 8B 8D ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 8B 55 ?? 52 8B 45 ?? 50 - 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 03 55 ?? 89 55 ?? 8B 45 ?? 03 45 ?? 89 - 45 ?? 6A ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 83 C0 ?? 89 45 - ?? 6A ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 83 C0 ?? 89 45 ?? - 6A ?? 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 83 C0 ?? 89 - 45 ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 83 C0 ?? 89 45 - ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 05 ?? ?? - ?? ?? 89 45 ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 83 C0 - ?? 89 45 ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 2B 55 ?? 52 8B 45 ?? 50 8B 8D ?? ?? - ?? ?? 51 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 55 ?? 2B 55 ?? 39 95 ?? ?? ?? ?? 74 ?? EB ?? - EB ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? E9 ?? - ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7E ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 8D ?? ?? - ?? ?? 51 8B 95 ?? ?? ?? ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? - 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7E ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? - ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 8B E5 5D C3 + $search_files = { + E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 7E ?? 8D 85 ?? ?? ?? + ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5A 59 59 64 89 10 68 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? + ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 + 89 20 F6 85 ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 + ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? + ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 EB + ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 8B E5 5D + C3 } - $enum_shares = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 8D 45 ?? - 50 8B 4D ?? 51 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 50 8D 4D ?? 51 8B 55 ?? 52 E8 ?? - ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 - ?? 8B 4D ?? 3B 4D ?? 0F 83 ?? ?? ?? ?? 8B 55 ?? C1 E2 ?? 8B 45 ?? 83 7C 10 ?? ?? 75 - ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 50 8B 55 ?? 52 8B 45 ?? C1 E0 ?? 8B 4D ?? 8B 54 01 ?? - 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 6A ?? 8B 45 ?? 50 8B 4D ?? C1 E1 ?? 8B 55 ?? - 8B 44 0A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8B 4D ?? 51 8B 55 ?? C1 E2 ?? 8B 45 ?? - 8B 4C 10 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C1 E2 ?? 8B 45 ?? 8B 4C 10 ?? 83 E1 - ?? 74 ?? 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? C1 E1 ?? 03 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 - ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 55 ?? - 52 E8 ?? ?? ?? ?? 8D 45 ?? 50 8B 4D ?? 51 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 0F - 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 50 8D - 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB - ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 3B 4D ?? 0F 83 ?? ?? ?? ?? 8B 55 ?? C1 E2 ?? - 8B 45 ?? 83 7C 10 ?? ?? 75 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 50 8B 55 ?? 52 8B 45 ?? C1 - E0 ?? 8B 4D ?? 8B 54 01 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 6A ?? 8B 45 ?? 50 - 8B 4D ?? C1 E1 ?? 8B 55 ?? 8B 44 0A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8B 4D ?? 51 - 8B 55 ?? C1 E2 ?? 8B 45 ?? 8B 4C 10 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C1 E2 ?? - 8B 45 ?? 8B 4C 10 ?? 83 E1 ?? 74 ?? 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? C1 E1 ?? 03 4D - ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? E9 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files = { + 55 8B EC 83 C4 ?? 53 56 57 33 DB 89 5D ?? 89 4D ?? 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? + ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 + FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 89 45 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 C9 B2 ?? A1 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B F8 8B 0D ?? ?? ?? ?? 8B 55 ?? 8B C7 E8 ?? ?? ?? ?? 33 C9 B2 + ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8B 0D ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? + ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 8B 45 + ?? 8B 10 FF 12 50 8B CB 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? 8B C6 8B 10 FF 52 ?? 6A ?? 6A + ?? 8B C3 E8 ?? ?? ?? ?? 8B C3 8B 10 FF 12 50 8B 4D ?? 8B D3 8B C7 E8 ?? ?? ?? ?? 8B + C7 8B 10 FF 52 ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? + E8 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B C7 E8 ?? ?? ?? ?? 8D 45 + ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and $file_search and $enum_shares and $file_encrypt_1 and $file_encrypt_2 + uint16(0)==0x5A4D and ($search_files) and ($encrypt_files) } -rule REVERSINGLABS_Win64_Ransomware_Curator : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Braincrypt : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Curator ransomware." + description = "Yara rule that detects BrainCrypt ransomware." author = "ReversingLabs" - id = "401f1d64-afd9-55b1-8e87-b808d4679e9a" - date = "2021-04-22" - modified = "2021-04-22" + id = "190798d5-594d-5b80-aa0e-8d7ff167f1c0" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Curator.yara#L1-L94" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "8bd29195cea0f1194e27c48ed07c52100abb7dd3de2ef7f51a645d32c3527eb3" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.BrainCrypt.yara#L1-L121" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "85866d6ffa136bf3ed27bbab55ae5430af4a1363930ebacab0df9ad24f8734cb" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -36745,86 +37889,119 @@ rule REVERSINGLABS_Win64_Ransomware_Curator : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Curator" + tc_detection_name = "BrainCrypt" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_p1 = { - 44 8B CB C7 44 24 ?? ?? ?? ?? ?? 45 33 C0 48 8D 8D ?? ?? ?? ?? 33 D2 FF 15 ?? ?? ?? - ?? 48 8B BD ?? ?? ?? ?? 4C 8D 35 ?? ?? ?? ?? 48 85 FF 0F 84 ?? ?? ?? ?? 48 8B 0D ?? - ?? ?? ?? 41 8B DC 48 81 C1 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 7E ?? 45 33 F6 48 8B - 05 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? BA ?? ?? ?? ?? 41 0F BE 8C 06 ?? ?? ?? ?? 45 0F - BE 8C 06 ?? ?? ?? ?? 89 4C 24 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 48 8D 8D - ?? ?? ?? ?? 44 8D 42 ?? E8 ?? ?? ?? ?? 8B CB 4D 8D 76 ?? FF C3 41 83 C4 ?? 88 84 0D - ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 81 C1 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 44 3B E0 7C - ?? 4C 8D 35 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 45 33 E4 48 89 44 24 ?? 48 8D 95 ?? ?? - ?? ?? 45 33 C9 44 89 64 24 ?? 44 8B C3 48 8B CF FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? - ?? ?? 48 8B 1D ?? ?? ?? ?? 48 8D 4C 24 ?? 48 8B 15 ?? ?? ?? ?? 4C 8B C3 E8 ?? ?? ?? - ?? 48 8B 8D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 45 8D 44 24 ?? - 48 89 44 24 ?? 45 33 C9 48 8D 44 24 ?? 89 9D ?? ?? ?? ?? 33 D2 48 89 44 24 ?? FF 15 - ?? ?? ?? ?? 85 C0 74 ?? 41 8B DC 44 39 A5 ?? ?? ?? ?? 76 ?? 8B C3 4C 8D 05 ?? ?? ?? - ?? BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 44 0F B6 4C 04 ?? E8 ?? ?? ?? ?? 48 8D 95 ?? - ?? ?? ?? 49 8B CE FF 15 ?? ?? ?? ?? FF C3 3B 9D ?? ?? ?? ?? 72 ?? 48 8B 8D ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 33 D2 48 8B CF FF 15 ?? ?? ?? ?? B9 + $get_files_for_encryption_32 = { + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? 80 7C 24 + ?? ?? 74 ?? 8B 5C 24 ?? 89 1C 24 8B 5C 24 ?? 89 5C 24 ?? BB ?? ?? ?? ?? 89 5C 24 ?? + E8 ?? ?? ?? ?? 83 C4 ?? C3 83 3D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? + 83 C3 ?? FC 8B 0B 89 0C 24 8B 4B ?? 89 4C 24 ?? 83 3D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? + ?? 8B 1D ?? ?? ?? ?? 83 C3 ?? 8D 7C 24 ?? FC 8B 0B 89 0F 8B 4B ?? 89 4F ?? E8 ?? ?? + ?? ?? 8B 5C 24 ?? 89 1D ?? ?? ?? ?? 8B 5C 24 ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 89 1D ?? + ?? ?? ?? 8B 5C 24 ?? 89 1C 24 8B 5C 24 ?? 89 5C 24 ?? BB ?? ?? ?? ?? 89 5C 24 ?? E8 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 0C 24 8B 44 24 ?? C7 04 24 ?? ?? ?? ?? 89 4C 24 ?? 89 + 4C 24 ?? 89 44 24 ?? 89 44 24 ?? BB ?? ?? ?? ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 5C 24 ?? FC 8B 0B 89 0C 24 8B 4B ?? 89 4C 24 ?? E8 ?? ?? ?? ?? E9 + ?? ?? ?? ?? BD ?? ?? ?? ?? 89 2C 24 89 5C 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 0F 0B E8 ?? ?? ?? ?? 0F 0B E8 ?? ?? ?? ?? E9 } - $encrypt_files_p2 = { - 48 8B C4 48 89 58 ?? 48 89 70 ?? 48 89 78 ?? 55 41 54 41 55 41 56 41 57 48 8D A8 ?? - ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 2B E0 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 - 85 ?? ?? ?? ?? 45 33 E4 C7 44 24 ?? ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 44 89 25 ?? ?? ?? - ?? 48 8D 95 ?? ?? ?? ?? 44 89 25 ?? ?? ?? ?? 33 C9 44 89 25 ?? ?? ?? ?? 45 8B FC 4C - 89 25 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 63 C8 - 48 8D 85 ?? ?? ?? ?? 48 8D 04 48 48 83 C0 ?? 66 83 38 ?? 75 ?? 66 44 89 20 4C 8D 05 - ?? ?? ?? ?? 48 83 C0 ?? 4C 89 64 24 ?? 48 89 05 ?? ?? ?? ?? 45 33 C9 48 8D 05 ?? ?? - ?? ?? 44 89 64 24 ?? 33 D2 48 89 05 ?? ?? ?? ?? 33 C9 FF 15 ?? ?? ?? ?? 33 D2 33 C9 - 44 8D 42 ?? FF 15 ?? ?? ?? ?? 48 8B F0 48 85 C0 74 ?? 48 8B 1D ?? ?? ?? ?? 48 81 C3 - ?? ?? ?? ?? EB ?? 48 8B CB FF 15 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8B D3 48 8B CE 44 - 8B F0 FF 15 ?? ?? ?? ?? 48 8B F8 48 85 C0 74 ?? 4C 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? - 48 8B C8 FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 41 8D 46 + $encrypt_file_32 = { + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? 8B 5C 24 + ?? 89 1C 24 8B 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B 54 24 ?? 8B 4C 24 ?? 8B 44 24 + ?? 89 54 24 ?? 89 14 24 89 4C 24 ?? 89 4C 24 ?? 89 44 24 ?? 89 44 24 ?? 8B 5C 24 ?? + 89 5C 24 ?? 8B 5C 24 ?? 89 5C 24 ?? 8B 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B 54 24 + ?? 8B 4C 24 ?? 8B 44 24 ?? 8B 5C 24 ?? 89 1C 24 8B 5C 24 ?? 89 5C 24 ?? 89 54 24 ?? + 89 54 24 ?? 89 4C 24 ?? 89 4C 24 ?? 89 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 C4 ?? C3 E8 ?? ?? ?? ?? E9 } - $find_files = { - 48 89 5C 24 ?? 48 89 7C 24 ?? 55 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 8B - 05 ?? ?? ?? ?? 48 33 C4 48 89 85 ?? ?? ?? ?? 48 8B F9 4C 8D 05 ?? ?? ?? ?? 4C 8B C9 - BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8D 8D ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 0F 84 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? - 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF - 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 44 24 ?? 4C 8B CF 4C 8D 05 ?? ?? ?? ?? 48 89 44 24 - ?? BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? F6 44 24 ?? ?? 48 8D 8D ?? - ?? ?? ?? 74 ?? 48 8D 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? EB ?? FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 0F 85 - ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? - ?? 48 33 CC E8 ?? ?? ?? ?? 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? 49 8B 7B ?? 49 8B E3 - 5D C3 + $attach_to_server_32 = { + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? 31 DB 89 + 5C 24 ?? 89 5C 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 89 CF 83 F9 ?? + 0F 84 ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 89 4C 24 ?? 89 0C 24 83 3C 24 ?? 0F 84 ?? ?? + ?? ?? 8B 5C 24 ?? 89 5C 24 ?? 8B 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 89 + 1C 24 83 3C 24 ?? 0F 84 ?? ?? ?? ?? BB ?? ?? ?? ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 89 1C 24 83 3C 24 ?? 0F 84 ?? ?? ?? ?? BB ?? ?? ?? ?? + 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 89 1C 24 83 3C 24 ?? + 0F 84 ?? ?? ?? ?? 8B 5C 24 ?? 89 5C 24 ?? 8B 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B + 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 31 DB 89 5C 24 ?? 89 5C 24 ?? 31 ED 39 E8 0F 85 + ?? ?? ?? ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 4C 24 ?? 89 0C 24 89 44 24 ?? 89 44 24 + ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 48 ?? 8B 68 + ?? 89 6C 24 ?? 89 6C 24 ?? 89 4C 24 ?? 83 F9 ?? 0F 84 ?? ?? ?? ?? 8D 59 ?? C7 04 24 + ?? ?? ?? ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? C7 04 24 ?? ?? ?? + ?? 8B 44 24 ?? 83 F8 ?? 74 ?? 83 C0 ?? 8D 7C 24 ?? FC 8B 08 89 0F 8B 48 ?? 89 4F ?? + E8 ?? ?? ?? ?? 8D 5C 24 ?? FC 8B 0B 89 0C 24 8B 4B ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B + 54 24 ?? 8B 4C 24 ?? 8B 44 24 ?? C7 04 24 ?? ?? ?? ?? 89 54 24 ?? 89 54 24 ?? 89 4C + 24 ?? 89 4C 24 ?? 89 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 89 5C 24 ?? 8B + 5C 24 ?? 89 5C 24 ?? 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 } - $remote_connection = { - 44 0F B7 45 ?? 33 DB 48 8B 55 ?? 45 33 C9 48 89 5C 24 ?? 48 8B CE 89 5C 24 ?? C7 44 - 24 ?? ?? ?? ?? ?? 48 89 5C 24 ?? FF 15 ?? ?? ?? ?? 4C 8B F0 48 85 C0 0F 84 ?? ?? ?? - ?? 80 7D ?? ?? B9 ?? ?? ?? ?? 4C 8B 45 ?? B8 ?? ?? ?? ?? 48 8B 55 ?? 0F 44 C8 48 89 - 5C 24 ?? 45 33 C9 89 4C 24 ?? 89 4D ?? 49 8B CE 48 89 5C 24 ?? 48 89 5C 24 ?? FF 15 - ?? ?? ?? ?? 48 8B D8 48 85 C0 0F 84 ?? ?? ?? ?? 83 65 ?? ?? 4C 8D 4D ?? 4C 8D 45 ?? - C7 45 ?? ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8B C8 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 81 4D ?? - ?? ?? ?? ?? 4C 8D 45 ?? 41 B9 ?? ?? ?? ?? 48 8B CB 41 8D 51 ?? FF 15 ?? ?? ?? ?? 4C - 8B 4D ?? 48 8B C7 48 F7 D8 48 8B D7 8B 45 ?? 48 8B CB 45 1B C0 89 44 24 ?? FF 15 ?? - ?? ?? ?? 85 C0 74 ?? 33 FF 83 65 ?? ?? 48 8D 55 ?? 45 33 C9 45 33 C0 48 8B CB FF 15 - ?? ?? ?? ?? 85 C0 74 ?? 8B 55 ?? 49 8B CF 03 D7 E8 ?? ?? ?? ?? 44 8B 45 ?? 4C 8D 4D - ?? 8B D7 48 8B CB 48 03 D0 4C 8B F8 FF 15 ?? ?? ?? ?? 8B 45 ?? 03 F8 EB ?? 8B 45 + $get_files_for_encryption_64 = { + 65 48 8B 0C 25 ?? ?? ?? ?? 48 8B 89 ?? ?? ?? ?? 48 3B 61 ?? 0F 86 ?? ?? ?? ?? 48 83 + EC ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? 0F B6 44 24 ?? 84 C0 0F 85 ?? ?? ?? ?? 48 8B 05 + ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 83 F9 ?? 0F 86 ?? ?? ?? ?? 48 8B 48 ?? 48 8B 40 + ?? 48 89 0C 24 48 89 44 24 ?? 48 8B 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 83 F9 ?? + 0F 86 ?? ?? ?? ?? 48 8B 48 ?? 48 8B 40 ?? 48 89 4C 24 ?? 48 89 44 24 ?? E8 ?? ?? ?? + ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 89 0D ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 84 C9 0F 85 + ?? ?? ?? ?? 48 89 05 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 04 24 48 8B 44 24 ?? 48 89 44 + 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 04 24 + 48 8B 4C 24 ?? 48 C7 04 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 4C 24 ?? 48 8D 05 ?? ?? + ?? ?? 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B + 4C 24 ?? 48 89 04 24 48 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 6C 24 ?? 48 83 C4 ?? C3 48 + 8D 0D ?? ?? ?? ?? 48 89 0C 24 48 89 44 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 0F 0B 48 8B 44 24 ?? 48 89 04 24 48 8B 44 24 ?? 48 89 44 24 ?? 48 8D 05 ?? ?? + ?? ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? E9 + } + $attach_to_server_64 = { + 65 48 8B 0C 25 ?? ?? ?? ?? 48 8B 89 ?? ?? ?? ?? 48 3B 61 ?? 0F 86 ?? ?? ?? ?? 48 83 + EC ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? + ?? ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 04 24 E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 48 89 + 7C 24 ?? 84 07 0F 57 C0 48 83 C7 ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? E8 ?? ?? ?? ?? 48 + 8B 6D ?? 48 8B 44 24 ?? 48 89 04 24 48 8B 4C 24 ?? 48 89 4C 24 ?? 48 8B 4C 24 ?? 48 + 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 04 24 48 8D 0D ?? ?? ?? ?? 48 89 4C + 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 04 24 48 8D 0D + ?? ?? ?? ?? 48 89 4C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? + 48 89 04 24 48 8B 4C 24 ?? 48 89 4C 24 ?? 48 8B 4C 24 ?? 48 89 4C 24 ?? E8 ?? ?? ?? + ?? 48 8B 44 24 ?? 48 8B 48 ?? 48 8B 10 48 8B 58 ?? 48 8B 40 ?? 48 39 CB 0F 87 ?? ?? + ?? ?? 48 29 D9 48 29 D8 48 85 C0 0F 84 ?? ?? ?? ?? 48 C7 04 24 ?? ?? ?? ?? 48 01 DA + 48 89 54 24 ?? 48 89 4C 24 ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C + 24 ?? 48 89 0C 24 48 89 44 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 44 24 ?? 48 8B + 48 ?? 48 8B 50 ?? 84 01 48 89 54 24 ?? C7 04 24 ?? ?? ?? ?? 48 83 C1 ?? 48 89 4C 24 + ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 04 24 48 8B 44 + 24 ?? 48 8B 48 ?? 48 8B 40 ?? 48 89 4C 24 ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? 48 8B 44 + 24 ?? 48 8B 4C 24 ?? 48 89 04 24 48 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B + 4C 24 ?? 48 8B 54 24 ?? 48 C7 04 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 4C 24 ?? 48 89 + 54 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 89 44 24 ?? 48 89 8C 24 ?? + ?? ?? ?? 90 E8 ?? ?? ?? ?? 48 8B 6C 24 ?? 48 83 C4 ?? C3 90 E8 ?? ?? ?? ?? 48 8B 6C + 24 ?? 48 83 C4 ?? C3 31 DB E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 0B E8 ?? ?? ?? ?? E9 + } + $encrypt_file_64 = { + 65 48 8B 0C 25 ?? ?? ?? ?? 48 8B 89 ?? ?? ?? ?? 48 3B 61 ?? 0F 86 ?? ?? ?? ?? 48 83 + EC ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? 48 8B 44 24 ?? 48 89 04 24 48 8B 44 24 ?? 48 89 + 44 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 8B 54 24 ?? 48 89 04 24 48 + 89 4C 24 ?? 48 89 54 24 ?? 48 8B 44 24 ?? 48 89 44 24 ?? 48 8B 84 24 ?? ?? ?? ?? 48 + 89 44 24 ?? 48 8B 84 24 ?? ?? ?? ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 + 8B 4C 24 ?? 48 8B 54 24 ?? 48 8B 5C 24 ?? 48 89 1C 24 48 8B 5C 24 ?? 48 89 5C 24 ?? + 48 89 44 24 ?? 48 89 4C 24 ?? 48 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 48 8B 6C 24 ?? 48 83 C4 ?? C3 E8 ?? ?? ?? ?? E9 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($remote_connection) + uint16(0)==0x5A4D and (($get_files_for_encryption_32 and $encrypt_file_32 and $attach_to_server_32) or ($get_files_for_encryption_64 and $encrypt_file_64 and $attach_to_server_64)) } -rule REVERSINGLABS_Win32_Ransomware_Dearcry : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Conti : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects DearCry ransomware." + description = "Yara rule that detects Conti ransomware." author = "ReversingLabs" - id = "6e2097e0-6495-5185-bbbc-e8168fa0ca7f" - date = "2021-03-12" - modified = "2021-03-12" + id = "548b8836-83cb-560c-af5f-33bdb24d15ed" + date = "2020-12-14" + modified = "2020-12-14" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.DearCry.yara#L1-L96" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "40dde232255018e1bc0aadf2378a7a86a99327d13dda58d8ffc5bb38e164de26" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Conti.yara#L1-L74" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "4f2b96c8eaf8d112a7bb60647db49616935a336396c705d39d5bb51dfd90c60b" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -36832,91 +38009,70 @@ rule REVERSINGLABS_Win32_Ransomware_Dearcry : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "DearCry" + tc_detection_name = "Conti" tc_detection_factor = 5 importance = 25 strings: - $drop_ransom_note_p1 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? A1 ?? - ?? ?? ?? 53 56 57 33 DB 68 ?? ?? ?? ?? 50 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 89 1D ?? ?? - ?? ?? 89 1D ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 89 1D ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 89 44 24 ?? E8 - ?? ?? ?? ?? 8B F0 6A ?? 68 ?? ?? ?? ?? 89 74 24 ?? E8 ?? ?? ?? ?? 8B F8 89 7C 24 ?? - E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 3B F3 0F 84 ?? ?? ?? ?? 3B FB 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 5C 24 ?? B8 ?? ?? ?? ?? 33 F6 8B FF - 38 18 74 ?? 50 E8 ?? ?? ?? ?? 8D BE ?? ?? ?? ?? 83 C4 ?? 8B D7 8A 08 88 0A 40 42 84 - C9 75 ?? 8B C7 33 F6 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 74 ?? 0F BE 14 37 52 E8 ?? - ?? ?? ?? 88 04 37 8B C7 83 C4 ?? 46 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 3B F0 72 ?? - 8B 74 24 ?? 46 89 74 24 ?? 69 F6 ?? ?? ?? ?? 8D 86 ?? ?? ?? ?? 3B C3 75 ?? 6A ?? 68 - } - $drop_ransom_note_p2 = { - 89 5C 24 ?? E8 ?? ?? ?? ?? 53 8B F0 53 8D 44 24 ?? 50 56 E8 ?? ?? ?? ?? 56 89 44 24 - ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 8B F8 3B C3 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 85 C0 0F 86 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? 53 51 88 5C 24 ?? E8 ?? ?? ?? - ?? 83 C4 ?? 8D 54 24 ?? 52 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 8A 44 1C ?? 3C ?? 7C ?? 3C ?? 7E ?? 3C ?? 0F 8C ?? ?? ?? ?? 3C ?? 0F 8F ?? ?? ?? ?? - 0F BE C0 50 8D 4C 24 ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 83 C4 ?? - 8D 54 24 ?? 52 FF D6 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? 8B - 4C 24 ?? 8B 54 24 ?? 8B 44 24 ?? 51 52 50 6A ?? 8D 4C 24 ?? 51 57 E8 ?? ?? ?? ?? 0F - BE 54 1C ?? 68 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? B8 ?? ?? ?? ?? 8D 50 - ?? 8D 49 ?? 8A 08 40 84 C9 75 ?? 56 2B C2 50 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 - E8 ?? ?? ?? ?? 83 C4 ?? 43 81 FB ?? ?? ?? ?? 0F 8C ?? ?? ?? ?? 33 DB 57 + $find_files = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 8B D9 53 FF 15 ?? ?? ?? ?? 89 44 24 ?? + 8D 0C 45 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 89 7C 24 ?? 85 FF 0F 84 ?? ?? ?? ?? 8B 44 + 24 ?? B9 ?? ?? ?? ?? 53 BE ?? ?? ?? ?? 57 66 83 7C 43 ?? ?? 0F 45 F1 FF 15 ?? ?? ?? + ?? 56 57 FF 15 ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 8D 44 24 ?? 50 57 FF 15 ?? ?? ?? ?? + 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? F6 44 24 ?? ?? 74 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 54 24 ?? 8B + CB E8 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 8B CE E8 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? EB ?? + 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 54 24 ?? 8B CB E8 ?? ?? ?? ?? 8B F0 85 F6 + 74 ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 5A 8B C8 C6 01 ?? 41 + 83 EA ?? 75 ?? 83 48 ?? ?? 50 89 70 ?? A1 ?? ?? ?? ?? 52 6A ?? FF 70 ?? FF 15 ?? ?? + ?? ?? 8D 44 24 ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 4C 24 ?? E8 ?? + ?? ?? ?? 83 FF ?? 74 ?? 57 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 } - $find_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 31 45 ?? 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 - A3 ?? ?? ?? ?? 89 65 ?? 8B 45 ?? 89 85 ?? ?? ?? ?? 8B 75 ?? 89 B5 ?? ?? ?? ?? 8B 4D - ?? 89 8D ?? ?? ?? ?? 8B 55 ?? 89 95 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? - ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 85 ?? ?? ?? ?? ?? 68 - ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 85 ?? ?? ?? ?? ?? - 8B C6 8D 50 ?? 8D 49 ?? 8A 08 40 84 C9 75 ?? 2B C2 80 7C 06 ?? ?? 74 ?? 8B C6 8D 50 - ?? 8A 08 40 84 C9 75 ?? 2B C2 80 7C 06 ?? ?? 74 ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? 52 EB ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 - 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 6A - ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 8B C6 - 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 8B D0 8D 85 ?? ?? ?? ?? 8D 78 ?? 8A 08 40 84 C9 - 75 ?? 2B C7 03 C2 3D ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 6A ?? 6A ?? 8D 4D ?? 51 E8 ?? ?? - ?? ?? 83 C4 ?? 8B C3 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 83 F8 ?? 76 ?? B8 ?? ?? ?? - ?? EB ?? 8B C3 8D 50 ?? 8D 64 24 ?? 8A 08 40 84 C9 75 ?? 2B C2 50 53 8D 55 ?? 52 E8 + $encrypt_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 BB ?? ?? ?? ?? 8B F9 53 57 FF 15 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + A1 ?? ?? ?? ?? 83 F8 ?? 75 ?? 89 75 ?? 33 F6 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 5D ?? FF 74 B5 ?? 57 FF 15 ?? ?? ?? + ?? 85 C0 75 ?? 46 83 FE ?? 7C ?? 33 C0 40 EB ?? 85 C0 75 ?? 8B 35 ?? ?? ?? ?? BB ?? + ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 00 ?? 40 83 E9 ?? 75 ?? 53 56 FF 15 ?? + ?? ?? ?? 85 C0 74 ?? 2B C6 D1 F8 74 ?? 85 C0 78 ?? 40 50 56 8D 85 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 53 56 FF 15 ?? + ?? ?? ?? 8B F0 85 F6 74 ?? 83 C6 ?? EB ?? 33 C0 5F 5E 5B C9 C3 } - $find_files_p2 = { - 83 C4 ?? 33 FF 8D 45 ?? 8D 50 ?? 90 8A 08 40 84 C9 75 ?? 2B C2 74 ?? EB ?? 8D 49 ?? - 0F BE 44 3D ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 88 44 3D ?? 47 8D 45 ?? 8D 50 ?? 8D A4 24 - ?? ?? ?? ?? 8A 08 40 84 C9 75 ?? 2B C2 3B F8 72 ?? 8D 4D ?? 51 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8A 10 3A - 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 C0 EB - ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 - E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 8D 50 ?? 8D A4 24 ?? ?? ?? ?? 8A 08 40 84 C9 75 ?? 2B - C2 80 7C 30 ?? ?? 74 ?? 8B C6 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 80 7C 30 ?? ?? 74 - ?? 8D 85 ?? ?? ?? ?? 50 56 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 EB ?? 8D 95 ?? ?? ?? - ?? 52 56 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 8B BD ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 - ?? 68 ?? ?? ?? ?? 6A ?? 8B 9D ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 53 57 8B 55 ?? - 52 8D BD ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? - E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? C3 8B 65 ?? C7 45 ?? ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? E9 - ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B C6 8D 50 ?? 8B FF + $encrypt_files_p2 = { + 55 8B EC 83 EC ?? 53 56 57 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 33 DB 53 FF 15 ?? ?? + ?? ?? 8B F8 85 FF 75 ?? 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 5E 56 68 ?? ?? ?? + ?? 53 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 53 + 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 53 8D 45 + ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 53 8D 45 ?? 50 + FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 53 53 68 ?? ?? ?? + ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 6A + ?? 8D 45 ?? 50 8D 45 ?? 50 8D 45 ?? 50 8B 45 ?? FF 70 ?? FF 15 ?? ?? ?? ?? 85 C0 75 + ?? 6A ?? FF 15 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? 8B 4D ?? + 8B D7 FF 75 ?? E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8B 45 ?? FF 70 ?? FF 15 ?? ?? ?? ?? + 8B 45 ?? B9 ?? ?? ?? ?? 83 48 ?? ?? 8B 45 ?? 8B 58 ?? E8 ?? ?? ?? ?? 8B F0 85 F6 74 + ?? 53 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 56 53 FF 15 ?? ?? ?? + ?? 8B CE E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 8B 49 ?? E8 ?? ?? ?? ?? FF + 75 ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? FF + 75 ?? FF 15 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B C9 C2 } condition: - uint16(0)==0x5A4D and ( all of ($drop_ransom_note_p*)) and ( all of ($find_files_p*)) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Zoldon : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Hydracrypt : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Zoldon ransomware." + description = "Yara rule that detects HydraCrypt ransomware." author = "ReversingLabs" - id = "5d28e6f0-9d6b-54f4-81ed-aadb58352c80" + id = "2e780f7c-8d6d-51c8-b65e-330cc3b17bb7" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Zoldon.yara#L1-L107" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "4821b8506e7ba00987978f2744da1c532e03d73f3275cb15e39cdf87f6018223" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.HydraCrypt.yara#L1-L174" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "910a6f23f06cecb8d3115ebfed42a66412dbd0d3a519e39f21df81b0c2028f48" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -36924,98 +38080,155 @@ rule REVERSINGLABS_Win32_Ransomware_Zoldon : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Zoldon" + tc_detection_name = "HydraCrypt" tc_detection_factor = 5 importance = 25 strings: - $main_encrypt_function_p1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? - ?? 89 8D ?? ?? ?? ?? 89 4D ?? 89 8D ?? ?? ?? ?? 89 4D ?? 89 4D ?? 89 55 ?? 89 45 ?? - 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 - 64 89 20 E8 ?? ?? ?? ?? DD 5D ?? 9B 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? FF 75 ?? FF - 75 ?? 8D 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? B2 ?? - A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? B1 ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? - 3C ?? 0F 85 ?? ?? ?? ?? B0 ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? - 84 C0 0F 85 ?? ?? ?? ?? 8B 4D ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? C6 - 80 ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 66 C7 45 - } - $main_encrypt_function_p2 = { - 8D 85 ?? ?? ?? ?? 66 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 66 83 7D - ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 66 8B 55 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 66 FF 45 ?? 66 83 7D - ?? ?? 75 ?? 8B 4D ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 95 ?? ?? ?? ?? 33 C9 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 - 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? - E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 + $remote_connection_1 = { + 55 8B EC 83 EC ?? 53 56 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 BE ?? ?? ?? ?? 56 + 33 DB 53 53 6A ?? 68 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? 6A ?? 89 45 ?? E8 ?? ?? ?? ?? + 59 59 53 53 6A ?? 53 53 6A ?? FF 75 ?? FF 75 ?? FF D0 89 45 ?? 3B C3 0F 84 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 53 56 53 53 68 ?? ?? ?? ?? FF 75 ?? 68 + ?? ?? ?? ?? FF 75 ?? FF D0 89 45 ?? 3B C3 0F 84 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 6A ?? + E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 6A ?? FF D0 8B F0 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? + ?? FF 75 ?? 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? FF 75 ?? 56 E8 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? FF 75 ?? 56 E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? + BF ?? ?? ?? ?? 57 89 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 56 50 57 FF 75 ?? E8 ?? ?? ?? ?? + 83 C4 ?? 5F 39 5D ?? 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 59 39 5D ?? 74 ?? FF 75 ?? E8 ?? + ?? ?? ?? 59 39 5D ?? 5E 5B 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 59 C9 C3 } - $write_zoldon_regkey = { - 55 8B EC 83 C4 ?? 53 56 33 DB 89 5D ?? 88 4D ?? 8B DA 8B F0 33 C0 55 68 ?? ?? ?? ?? - 64 FF 30 64 89 20 8D 45 ?? 8B D3 E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B D8 84 DB - 75 ?? 8D 45 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 89 45 ?? 80 7D ?? - ?? 74 ?? 83 7D ?? ?? 75 ?? 8D 45 ?? 50 8B 46 ?? 50 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 - 8B D3 8B C6 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D0 8B C6 E8 ?? ?? ?? ?? 88 45 ?? EB - ?? 8D 45 ?? 50 8D 45 ?? 50 6A ?? 8B 46 ?? 50 6A ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? - ?? 50 8B D3 8B C6 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D0 8B C6 E8 ?? ?? ?? ?? 88 45 - ?? 80 7D ?? ?? 74 ?? 83 7E ?? ?? 0F 95 C0 84 D8 74 ?? FF 76 ?? 68 ?? ?? ?? ?? FF 75 - ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? 33 - C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 + $remote_connection_2 = { + 55 8B EC 83 EC ?? 53 56 57 6A ?? 59 68 ?? ?? ?? ?? 33 DB BE ?? ?? ?? ?? 8D 7D ?? 6A + ?? 89 5D ?? F3 A5 E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 53 53 53 8D 4D ?? 51 FF D0 8B + F8 3B FB 75 ?? 33 C0 E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 53 68 + ?? ?? ?? ?? 53 53 FF 75 ?? 57 FF D0 8B F0 3B F3 75 ?? 53 E8 ?? ?? ?? ?? 59 EB ?? 68 + ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 6A ?? 8D 4D ?? 51 FF D0 68 ?? ?? ?? ?? 6A ?? + E8 ?? ?? ?? ?? 59 59 8D 4D ?? 51 6A ?? 8D 4D ?? 51 56 FF D0 39 5D ?? 75 ?? 57 E8 ?? + ?? ?? ?? 56 E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 33 C0 83 C4 ?? 40 EB ?? 68 ?? ?? + ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 4D ?? 51 FF D0 33 C9 3B C8 1B C0 + F7 D8 5F 5E 5B C9 C3 } - $find_files_p1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? - ?? 89 8D ?? ?? ?? ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 55 ?? - 89 45 ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? - 64 FF 30 64 89 20 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 - C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 F6 85 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 - ?? 80 B8 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 - 74 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? - ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 - 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 8B + $remote_connection_3 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 BE ?? ?? ?? ?? 8D 7D ?? A5 A5 33 DB 66 A5 53 8D + 45 ?? 53 50 A4 E8 ?? ?? ?? ?? 59 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 83 C4 ?? BE ?? ?? ?? ?? 56 53 FF D0 56 + 50 89 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? + ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? FF D0 BF ?? ?? ?? ?? 57 50 89 45 ?? E8 ?? ?? ?? + ?? 59 59 85 DB 7E ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 59 59 8B C3 6A ?? 99 59 + F7 F9 85 D2 75 ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 6A ?? + E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 8B 45 ?? 0F B6 04 03 + 50 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 55 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? + ?? ?? ?? 83 C4 ?? 43 3B DE 7C ?? E8 ?? ?? ?? ?? 8B F0 E8 ?? ?? ?? ?? 50 56 8D 85 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 55 ?? 83 C4 ?? 83 7D ?? ?? BB ?? ?? ?? ?? BE ?? ?? ?? + ?? 75 ?? 53 56 57 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? + 75 ?? 53 56 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F + 5E 5B C9 C3 } - $find_files_p2 = { - 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? E9 - ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? - ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? ?? ?? ?? E9 ?? ?? - ?? ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D - 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? - ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? - ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 74 ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D - 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? - ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? - ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 85 C0 0F 84 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 - ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8B E5 5D C3 + $encrypt_files_1 = { + 8A 45 ?? 04 ?? 66 98 66 89 45 ?? 0F B7 C0 50 8D 45 ?? 68 ?? ?? ?? ?? 50 FF 55 ?? 68 + ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 51 FF D0 8B F0 83 FE ?? 74 ?? 83 + FE ?? 74 ?? 83 FE ?? 75 ?? FF 75 ?? 8D 45 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 83 FE ?? 74 ?? 83 FE ?? 75 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 57 6A ?? E8 ?? ?? ?? + ?? 59 59 68 ?? ?? ?? ?? FF D0 FF 45 ?? 83 7D ?? ?? 0F 8C ?? ?? ?? ?? 83 3D ?? ?? ?? + ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 BE + ?? ?? ?? ?? 56 6A ?? E8 ?? ?? ?? ?? 59 59 53 53 8D 8D ?? ?? ?? ?? 51 53 FF D0 8D 85 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 + ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? + 75 ?? E8 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 53 FF D0 56 6A + ?? E8 ?? ?? ?? ?? 59 59 53 6A ?? 8D 8D ?? ?? ?? ?? 51 53 FF D0 8D 85 ?? ?? ?? ?? 50 + 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 55 ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 + C4 ?? 6A ?? 53 53 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 53 FF D0 57 6A ?? E8 ?? ?? ?? + ?? 59 59 68 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 53 FF D0 5F + 5E 33 C0 5B C9 C2 + } + $encrypt_files_2 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 BE ?? ?? ?? ?? 8D 7D ?? A5 A5 33 DB 66 A5 53 8D + 45 ?? 53 50 A4 E8 ?? ?? ?? ?? 59 50 E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 7D ?? A5 A5 89 + 45 ?? 8D 45 ?? 50 66 A5 E8 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A + ?? 89 45 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 FF D0 BE ?? ?? ?? ?? 8D 7D ?? A5 A5 66 A5 BE + ?? ?? ?? ?? 8D 7D ?? A5 A5 A5 53 89 45 ?? 8D 45 ?? 53 50 66 A5 E8 ?? ?? ?? ?? 59 50 + E8 ?? ?? ?? ?? 8B F0 8D 45 ?? 50 E8 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 6A ?? 8D 8D ?? ?? ?? ?? 51 53 FF D0 BF ?? + ?? ?? ?? 57 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 55 ?? 68 ?? + ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 8D 8D ?? ?? ?? ?? 51 FF D0 68 ?? ?? ?? ?? + 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 53 53 FF D0 8B F0 53 56 E8 ?? ?? ?? ?? 59 + 59 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 FF + D0 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF + } + $encrypt_files_3 = { + D0 E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? + ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 85 C0 75 ?? BE ?? ?? ?? + ?? EB ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? FF D0 56 E8 ?? ?? + ?? ?? 59 3C ?? 75 ?? BE ?? ?? ?? ?? 56 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF D0 56 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D0 + E8 ?? ?? ?? ?? 56 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF + D0 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF + D0 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? + ?? ?? 83 C4 ?? 53 6A ?? 8D 8D ?? ?? ?? ?? 51 53 FF D0 68 ?? ?? ?? ?? 57 8D 85 ?? ?? + ?? ?? 50 BE ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 50 FF 55 ?? 68 ?? ?? ?? ?? 57 8D 85 ?? + ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 56 50 FF 55 ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 + C4 ?? 68 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 7D ?? A5 68 ?? ?? ?? + ?? 6A ?? 66 A5 E8 ?? ?? ?? ?? 83 C4 ?? 53 FF D0 6A ?? FF 75 ?? A3 ?? ?? ?? ?? FF 55 + ?? 6A ?? FF 75 ?? 8B F0 FF 55 ?? FF 75 ?? 89 45 ?? 53 E8 ?? ?? ?? ?? 8D 45 ?? 50 FF + } + $encrypt_files_4 = { + 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 66 85 C0 75 ?? 33 C0 40 E9 ?? ?? ?? ?? 8B 3D + ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 8B C8 8B 45 ?? 53 57 99 53 53 + 2B C2 68 ?? ?? ?? ?? D1 F8 2D ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 8B C6 99 2B C2 D1 F8 2D + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 53 FF D1 A3 ?? ?? ?? ?? E8 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? 51 FF D0 E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 + BE ?? ?? ?? ?? 85 C0 75 ?? 56 6A ?? E8 ?? ?? ?? ?? 59 59 53 53 53 68 ?? ?? ?? ?? 53 + 53 FF D0 56 6A ?? E8 ?? ?? ?? ?? 59 59 53 53 53 68 ?? ?? ?? ?? 53 53 FF D0 39 1D ?? + ?? ?? ?? 75 ?? 6A ?? 58 EB ?? 6A ?? 59 33 C0 68 ?? ?? ?? ?? 89 5D ?? 8D 7D ?? 6A ?? + F3 AB E8 ?? ?? ?? ?? 59 59 6A ?? FF D0 EB ?? 83 F8 ?? 74 ?? 68 ?? ?? ?? ?? 6A ?? E8 + ?? ?? ?? ?? 59 59 8D 4D ?? 51 FF D0 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 8D 4D + ?? 51 FF D0 6A ?? 59 8D 75 ?? BF ?? ?? ?? ?? F3 A5 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? + ?? 59 59 53 53 53 8D 4D ?? 51 FF D0 3B C3 75 ?? 8B 45 ?? 5F 5E 5B C9 C2 ?? ?? 6A ?? + E9 + } + $remote_connection_4 = { + 55 8B EC 51 51 53 56 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 33 F6 56 56 56 6A ?? + 68 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? 6A ?? 8B D8 E8 ?? ?? ?? ?? 59 59 56 56 6A ?? 56 + 56 6A ?? FF 75 ?? 53 FF D0 68 ?? ?? ?? ?? 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 59 59 56 68 + ?? ?? ?? ?? 56 56 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? FF D0 68 ?? ?? ?? + ?? 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 59 59 56 56 56 56 FF 75 ?? FF D0 53 E8 ?? ?? ?? ?? + FF 75 ?? E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 5E 5B C9 C3 + } + $remote_connection_5 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 33 FF 68 ?? ?? ?? ?? 47 57 E8 ?? ?? ?? ?? 59 59 + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 FF 75 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? BE ?? ?? ?? ?? 56 57 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 + FF D0 56 57 E8 ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 56 57 E8 + ?? ?? ?? ?? 59 59 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF D0 68 ?? ?? ?? ?? 6A ?? E8 + ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? 51 6A ?? FF D0 BE ?? ?? ?? ?? 85 C0 74 ?? 56 57 + E8 ?? ?? ?? ?? 59 59 6A ?? FF D0 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 59 59 6A ?? 57 + 6A ?? FF D0 8B D8 85 DB 7D ?? 56 57 E8 ?? ?? ?? ?? 59 59 6A ?? FF D0 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 59 6A ?? 8D 4D ?? + 51 FF D0 6A ?? 58 66 89 45 ?? 8B 46 ?? 8B 00 8B 00 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 66 + 89 45 ?? 6A ?? 8D 45 ?? 50 53 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 8D ?? ?? ?? ?? 51 FF D0 6A ?? 50 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 53 E8 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? FF D0 5F 5E 5B C9 C3 } condition: - uint16(0)==0x5A4D and ($write_zoldon_regkey) and ( all of ($find_files_p*)) and ( all of ($main_encrypt_function_p*)) + uint16(0)==0x5A4D and (($encrypt_files_1 and $remote_connection_1 and $remote_connection_2 and $remote_connection_3) or ($encrypt_files_2 and $encrypt_files_3 and $encrypt_files_4 and $remote_connection_4 and $remote_connection_5)) } -rule REVERSINGLABS_Win32_Ransomware_Knot : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Guscrypter : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Knot ransomware." + description = "Yara rule that detects GusCrypter ransomware." author = "ReversingLabs" - id = "4dfe9da5-7ab1-57dc-95fc-b05777f235b8" - date = "2021-03-19" - modified = "2021-03-19" + id = "64aa468c-ec24-58aa-8ea9-23f0cebed227" + date = "2020-11-26" + modified = "2020-11-26" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Knot.yara#L1-L118" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "a7a3e13139d68314e583ec225a5d56373a551e67d46984dcf9a228a1f7275f14" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.GusCrypter.yara#L1-L129" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "cfe6005028c0e5f5d713af2a549574203678bab2ee48acc1727702bcf91522b1" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -37023,109 +38236,119 @@ rule REVERSINGLABS_Win32_Ransomware_Knot : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Knot" + tc_detection_name = "GusCrypter" tc_detection_factor = 5 importance = 25 strings: + $find_files_p1 = { + 8A 01 41 84 C0 75 ?? 2B CA 8D 85 ?? ?? ?? ?? 51 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? + ?? 8D 45 ?? 8B 5D ?? 83 FB ?? 8B 75 ?? 8B 4D ?? 0F 43 C6 83 F9 ?? 75 ?? 80 38 ?? 0F + 84 ?? ?? ?? ?? 83 FB ?? 8D 45 ?? 0F 43 C6 83 F9 ?? 75 ?? BA ?? ?? ?? ?? 66 39 10 0F + 84 ?? ?? ?? ?? 83 FB ?? 8D 55 ?? 0F 43 D6 83 F9 ?? 75 ?? 66 81 3A ?? ?? 75 ?? 80 7A + ?? ?? 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 45 ?? 0F 43 C6 83 F9 ?? 75 ?? 81 38 ?? ?? ?? ?? + 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 55 ?? 0F 43 D6 83 F9 ?? 75 ?? 81 3A ?? ?? ?? ?? 75 ?? + 66 81 7A ?? ?? ?? 75 ?? 80 7A ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 83 FB ?? 0F + 43 CE 83 F8 ?? 75 ?? BA ?? ?? ?? ?? 8D 78 ?? 8B 01 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 + EF ?? 73 ?? 8A 01 3A 02 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 FB ?? 8D 4D ?? 0F 43 CE 83 F8 + ?? 75 ?? BA ?? ?? ?? ?? 8D 78 ?? 8B 01 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EF ?? 73 ?? + 66 8B 01 66 3B 02 75 ?? 8A 41 ?? 3A 42 ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 FB ?? 8D 4D + ?? 0F 43 CE 83 F8 ?? 75 ?? BA ?? ?? ?? ?? 8D 78 ?? 8B 01 3B 02 75 ?? 83 C1 ?? 83 C2 + ?? 83 EF ?? 73 ?? 66 8B 01 66 3B 02 75 ?? 8A 41 ?? 3A 42 ?? 0F 84 ?? ?? ?? ?? 8B 4D + ?? 8D 45 ?? 83 FB ?? 0F 43 C6 83 F9 ?? 75 ?? 81 38 ?? ?? ?? ?? 75 ?? 81 78 ?? ?? ?? + ?? ?? 75 ?? 80 78 ?? ?? 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 45 ?? 0F 43 C6 83 F9 ?? 75 + } + $find_files_p2 = { + 81 38 ?? ?? ?? ?? 75 ?? 80 78 ?? ?? 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 45 ?? 0F 43 C6 83 + F9 ?? 75 ?? 81 38 ?? ?? ?? ?? 75 ?? 81 78 ?? ?? ?? ?? ?? 75 ?? 81 78 ?? ?? ?? ?? ?? + 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 45 ?? 0F 43 C6 83 F9 ?? 75 ?? 81 38 ?? ?? ?? ?? 75 ?? + 81 78 ?? ?? ?? ?? ?? 75 ?? 81 78 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 4D ?? + 0F 43 CE 83 7D ?? ?? 75 ?? BA ?? ?? ?? ?? BF ?? ?? ?? ?? 8B 01 3B 02 75 ?? 83 C1 ?? + 83 C2 ?? 83 EF ?? 73 ?? 66 8B 01 66 3B 02 75 ?? 8A 41 ?? 3A 42 ?? 0F 84 ?? ?? ?? ?? + 83 FB ?? 8D 45 ?? 0F 43 C6 83 7D ?? ?? 75 ?? 81 38 ?? ?? ?? ?? 75 ?? 81 78 ?? ?? ?? + ?? ?? 75 ?? 81 78 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 4D ?? 0F 43 CE 83 7D + ?? ?? 75 ?? BA ?? ?? ?? ?? BF ?? ?? ?? ?? 8B 01 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EF + ?? 73 ?? 66 8B 01 66 3B 02 75 ?? 8A 41 ?? 3A 42 ?? 75 ?? B0 ?? EB ?? 32 C0 84 C0 75 + ?? 8D 85 ?? ?? ?? ?? 50 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? + ?? 8B CC 8B D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 + C4 ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? + 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? + ?? 83 C4 ?? 8B BD ?? ?? ?? ?? C6 45 ?? ?? 83 FB ?? 72 ?? 43 8B C6 81 FB ?? ?? ?? ?? + 72 ?? 8B 76 ?? 83 C3 ?? 2B C6 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 53 56 E8 ?? ?? ?? + ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF + 15 + } $encrypt_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 - FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 32 C0 E9 ?? ?? ?? ?? 6A ?? 8B 4D ?? 51 - FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 32 C0 E9 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? - 6A ?? 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 32 C0 E9 ?? ?? - ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 - ?? 32 C0 E9 ?? ?? ?? ?? 8D 4D ?? 51 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 52 - FF 15 ?? ?? ?? ?? 85 C0 75 ?? 32 C0 E9 ?? ?? ?? ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 8B - 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 32 C0 E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 - C0 75 ?? 32 C0 E9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 32 C0 E9 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 FF 15 + 88 84 05 ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 7C ?? 33 FF 33 F6 8B C6 8A 9C 35 ?? ?? ?? ?? + 99 F7 7D ?? 0F B6 04 0A 03 F8 0F B6 CB 03 F9 81 E7 ?? ?? ?? ?? 79 ?? 4F 81 CF ?? ?? + ?? ?? 47 8A 84 3D ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 88 84 35 ?? ?? ?? ?? 46 88 9C 3D ?? + ?? ?? ?? 81 FE ?? ?? ?? ?? 7C ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 + E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 DB 0F 85 ?? ?? ?? ?? 8B 4D ?? 32 D2 E8 ?? ?? ?? ?? + 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? + 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 0F 82 ?? ?? ?? ?? 8B 4D + ?? 42 8B C1 81 FA ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 + F8 ?? 0F 87 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 + ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 89 BD ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 33 F6 + 53 E8 ?? ?? ?? ?? 83 C4 ?? 88 85 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 } $encrypt_files_p2 = { - 85 C0 75 ?? 32 C0 E9 ?? ?? ?? ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF - 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 95 - ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 6A - ?? 8D 95 ?? ?? ?? ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 8B - 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 6A - ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 - ?? 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 8B 45 ?? 50 8B 4D - ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 8B 45 ?? 50 8B 8D ?? ?? ?? - ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 - ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 - FF 15 ?? ?? ?? ?? B0 ?? 8B E5 5D C3 - } - $find_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 85 - ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 0F B7 8D ?? ?? ?? ?? 83 F9 ?? 0F 84 ?? ?? - ?? ?? 8B 95 ?? ?? ?? ?? 83 E2 ?? 89 95 ?? ?? ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 83 F8 ?? 75 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 - ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? EB ?? 8B 8D ?? ?? ?? ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? - 73 ?? 8B 95 ?? ?? ?? ?? 8B 04 95 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? - 83 C4 ?? 85 C0 74 ?? C6 85 ?? ?? ?? ?? ?? EB ?? 0F B6 95 ?? ?? ?? ?? 83 FA ?? 75 + 0F BE 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 46 83 C4 ?? 83 FE ?? 7C ?? 53 E8 ?? ?? ?? + ?? 83 C4 ?? 88 85 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 83 + 7D ?? ?? 8D 4D ?? 8A 85 ?? ?? ?? ?? 0F 43 4D ?? C7 45 ?? ?? ?? ?? ?? 88 01 C6 41 ?? + ?? 33 C9 8B 75 ?? 8B C6 83 C0 ?? 0F 92 C1 F7 D9 0B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D + 4D ?? 83 7D ?? ?? 8B F8 0F 43 4D ?? 56 57 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F BE + 07 FF B5 ?? ?? ?? ?? 35 ?? ?? ?? ?? 83 C0 ?? 50 E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 8B + BD ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? + 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D + 45 ?? 83 7D ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 32 D2 C7 45 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 0F 82 ?? ?? ?? ?? 8B 4D ?? 8D 50 ?? 8B C1 + 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? + ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? + ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } - $find_files_p2 = { - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? 83 C0 ?? 89 85 ?? ?? ?? ?? 83 - BD ?? ?? ?? ?? ?? 73 ?? 8B 8D ?? ?? ?? ?? 8B 14 8D ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? C6 85 ?? ?? ?? ?? ?? EB ?? 0F B6 8D ?? ?? ?? - ?? 83 F9 ?? 0F 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? - ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? - ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? - ?? ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 95 ?? - ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? - ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? - 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? - 51 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? - 8B E5 5D C3 + $misc_checks_p1 = { + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? + 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 + F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? + ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F + 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 } - $remote_connection = { - 55 8B EC 81 EC ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A - ?? FF 15 ?? ?? ?? ?? 89 45 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? 6A ?? FF 15 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 0F B6 C0 83 F8 ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 0F B6 C8 83 F9 ?? 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 99 B9 ?? ?? ?? ?? F7 F9 81 C2 ?? ?? ?? ?? 52 8D 95 ?? ?? ?? ?? - 52 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 8D 8D - ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? - ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 - FF 15 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 6A ?? - 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 95 ?? ?? - ?? ?? 83 C2 ?? 89 95 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7F ?? 8D 85 ?? ?? ?? ?? 50 8B - 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 83 BD ?? ?? ?? ?? ?? 74 - ?? EB ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 8D 95 ?? ?? ?? ?? 52 - E8 ?? ?? ?? ?? 83 C4 ?? EB ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 6A ?? FF 15 ?? ?? ?? ?? 33 C0 8B E5 5D C2 + $misc_checks_p2 = { + 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? + ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? + 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? E9 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($remote_connection) + uint16(0)==0x5A4D and ( all of ($misc_checks_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Thanos : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win64_Ransomware_Nokoyawa : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Thanos ransomware." + description = "Yara rule that detects Nokoyawa ransomware." author = "ReversingLabs" - id = "e607255d-45a6-573d-956e-f6faa2aa7e9f" - date = "2021-08-12" - modified = "2021-08-12" + id = "31470ce4-381f-50d2-bbca-03c592e62a7d" + date = "2022-06-06" + modified = "2022-06-06" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Thanos.yara#L1-L106" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "f6bc0c2188a04d2fb2a82a6b6d6cdf7763c32047bec725fe07f01415edf0b4cd" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Nokoyawa.yara#L1-L104" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "85b7d93db06007d0043b1489b532410ccc700cf082b641fff8a09de2ffe9101d" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -37133,97 +38356,96 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Thanos : TC_DETECTION MALICIOUS MALW sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Thanos" + tc_detection_name = "Nokoyawa" tc_detection_factor = 5 importance = 25 strings: + $enum_shares = { + 48 89 4C 24 ?? 48 81 EC ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + 48 8D 44 24 ?? 48 89 44 24 ?? 4C 8B 8C 24 ?? ?? ?? ?? 45 33 C0 33 D2 B9 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 7C 24 ?? ?? 74 ?? 33 C0 E9 ?? ?? ?? ?? 8B 44 24 ?? + 8B D0 B9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 89 44 24 ?? 48 83 7C 24 ?? ?? 75 ?? 33 C0 + E9 ?? ?? ?? ?? 8B 44 24 ?? 44 8B C0 33 D2 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 4C 8D 4C 24 + ?? 4C 8B 44 24 ?? 48 8D 54 24 ?? 48 8B 4C 24 ?? FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 7C + 24 ?? ?? 0F 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 8B 44 24 ?? FF C0 89 44 24 + ?? 8B 44 24 ?? 39 44 24 ?? 73 ?? 48 8B 44 24 ?? 83 78 ?? ?? 75 ?? 8B 44 24 ?? 48 6B + C0 ?? 48 8B 4C 24 ?? 48 8B 54 01 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? + ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 48 6B C0 + ?? 48 8B 4C 24 ?? 8B 44 01 ?? 83 E0 ?? 83 F8 ?? 75 ?? 8B 44 24 ?? 48 6B C0 ?? 48 8B + 4C 24 ?? 48 03 C8 48 8B C1 48 8B C8 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? EB ?? 81 7C 24 ?? + ?? ?? ?? ?? 74 ?? EB ?? 81 7C 24 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8B 4C 24 ?? FF + 15 ?? ?? ?? ?? 48 8B 4C 24 ?? FF 15 + } $find_files_p1 = { - 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 FE 01 2B ?? 16 00 13 ?? 11 ?? 2D ?? DD - ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 08 6F ?? ?? ?? ?? 6C 7E ?? ?? ?? ?? - 28 ?? ?? ?? ?? 23 ?? ?? ?? ?? ?? ?? ?? ?? 5A 23 ?? ?? ?? ?? ?? ?? ?? ?? 5A 35 ?? 7E ?? - ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE 01 2B ?? 17 00 13 ?? 11 ?? 2D ?? 00 06 08 - 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 2B ?? 08 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 7E ?? - ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE 01 2B ?? 17 00 13 ?? 11 ?? 2D ?? 00 06 08 - 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 00 DE ?? 26 00 00 DE ?? 26 00 00 DE ?? 00 00 00 11 - ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 3A ?? ?? ?? ?? DE ?? 11 ?? 14 FE 01 13 ?? 11 ?? 2D ?? 11 - ?? 6F ?? ?? ?? ?? 00 DC 00 00 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 38 - ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 0D 00 07 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 2D ?? 07 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D - ?? 07 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 07 6F ?? ?? ?? - ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 07 6F ?? ?? ?? ?? 6F + FF 15 ?? ?? ?? ?? 48 89 44 24 ?? 48 83 7C 24 ?? ?? 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 83 + E0 ?? 85 C0 0F 84 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 84 + ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 98 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? + ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 98 48 8B D0 48 + 8D 4C 24 ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? + ?? ?? 48 98 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 48 8D 4C 24 + ?? E8 ?? ?? ?? ?? 48 98 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? + 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 98 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 3D ?? ?? + ?? ?? 74 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 98 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? + ?? 3D ?? ?? ?? ?? 75 ?? E9 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF C8 48 98 48 8B 8C 24 ?? + ?? ?? ?? 0F B7 04 41 83 F8 ?? 75 ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF C8 48 } $find_files_p2 = { - 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 07 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 16 FE 01 2B ?? 16 00 13 ?? 11 ?? 2D ?? 38 ?? ?? ?? ?? 00 00 09 72 ?? ?? ?? - ?? 17 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 0C 00 00 - 08 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 08 6F ?? - ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 08 6F ?? ?? ?? ?? - 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 6F ?? ?? - ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A - } - $find_files_p3 = { - 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 08 6F ?? ?? - ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 6F - ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 08 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 00 6F - ?? ?? ?? ?? 2D ?? 08 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 08 6F ?? ?? ?? - ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 08 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 2D ?? 08 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 08 6F ?? ?? ?? ?? 72 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 16 FE 01 2B ?? 16 00 13 ?? 11 ?? 2D ?? DD ?? ?? ?? ?? 08 6F ?? ?? - ?? ?? 28 ?? ?? ?? ?? 2C ?? 08 6F ?? ?? ?? ?? 6C 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 23 ?? ?? - ?? ?? ?? ?? ?? ?? 5A 23 ?? ?? ?? ?? ?? ?? ?? ?? 5A 35 ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 16 FE 01 2B ?? 17 00 13 ?? 11 ?? 2D ?? 00 06 08 6F ?? ?? ?? ?? 6F ?? ?? - ?? ?? 00 00 2B ?? 08 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 16 FE 01 2B ?? 17 00 13 ?? 11 ?? 2D ?? 00 06 08 6F ?? ?? ?? ?? 6F ?? ?? - ?? ?? 00 00 00 DE ?? 26 00 00 DE ?? 26 00 00 DE ?? 00 00 00 11 ?? 6F ?? ?? ?? ?? 13 ?? - 11 ?? 3A ?? ?? ?? ?? DE ?? 11 ?? 14 FE 01 13 ?? 11 ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 00 DC - 00 00 DE ?? 26 00 00 DE ?? 26 00 00 DE ?? 00 00 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 3A ?? - ?? ?? ?? DE ?? 11 ?? 14 FE 01 13 ?? 11 ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 00 DC 00 00 DE ?? - 26 00 00 DE ?? 26 00 00 DE ?? 26 00 00 DE ?? 26 00 00 DE ?? 00 06 13 ?? 2B ?? 11 ?? 2A + 98 48 8B 8C 24 ?? ?? ?? ?? 0F B7 04 41 83 F8 ?? 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF C8 48 98 48 8B 8C 24 ?? ?? ?? ?? + 0F B7 04 41 83 F8 ?? 75 ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF C8 48 98 48 8B + 8C 24 ?? ?? ?? ?? 0F B7 04 41 83 F8 ?? 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 4C + 24 ?? E8 ?? ?? ?? ?? 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 15 ?? ?? + ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 85 C0 75 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 75 ?? EB ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B 4C + 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8B 4C 24 ?? FF 15 ?? ?? ?? ?? 48 + 81 C4 } $encrypt_files = { - 73 ?? ?? ?? ?? 13 ?? 11 ?? 03 7D ?? ?? ?? ?? 11 ?? 04 7D ?? ?? ?? ?? 11 ?? 05 7D ?? ?? - ?? ?? 11 ?? 0E ?? 7D ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 11 ?? 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? - 80 ?? ?? ?? ?? 02 16 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE 01 13 ?? 11 ?? 2D ?? 00 28 - ?? ?? ?? ?? 0A 06 8E 69 16 FE 02 16 FE 01 13 ?? 11 ?? 2D ?? 00 16 0B 2B ?? 00 06 07 9A - 6F ?? ?? ?? ?? 16 FE 01 13 ?? 11 ?? 2D ?? 00 7E ?? ?? ?? ?? 06 07 9A 6F ?? ?? ?? ?? 6F - ?? ?? ?? ?? 13 ?? 11 ?? 2D ?? 00 7E ?? ?? ?? ?? 06 07 9A 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? - 00 00 00 00 07 17 58 0B 07 06 8E 69 FE 04 13 ?? 11 ?? 2D ?? 00 00 2B ?? 00 16 0B 2B ?? - 00 7E ?? ?? ?? ?? 02 07 9A 6F ?? ?? ?? ?? 13 ?? 11 ?? 2D ?? 00 7E ?? ?? ?? ?? 02 07 9A - 6F ?? ?? ?? ?? 00 00 00 07 17 58 0B 07 02 8E 69 FE 04 13 ?? 11 ?? 2D ?? 00 7E ?? ?? ?? - ?? 72 ?? ?? ?? ?? 00 6F ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 16 FE 01 2B ?? 17 00 13 ?? 11 ?? 2D ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 00 6F ?? ?? ?? - ?? 26 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 14 0D 73 ?? ?? ?? ?? 13 - ?? 11 ?? 11 ?? 7D ?? ?? ?? ?? 11 ?? 12 ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 00 7E ?? ?? ?? - ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE 01 13 ?? 11 ?? 2D ?? 00 09 2D ?? 11 ?? FE 06 ?? - ?? ?? ?? 73 ?? ?? ?? ?? 0D 2B ?? 09 73 ?? ?? ?? ?? 0C 08 1A 6F ?? ?? ?? ?? 00 08 16 6F - ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? 00 00 2B ?? 00 11 ?? 7B ?? ?? ?? - ?? 11 ?? 7B ?? ?? ?? ?? 11 ?? 7B ?? ?? ?? ?? 11 ?? 7B ?? ?? ?? ?? 11 ?? 7B ?? ?? ?? ?? - 28 ?? ?? ?? ?? 00 00 00 12 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE - 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 00 00 2A - } - $remote_connection = { - 00 00 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 19 6F ?? ?? ?? ?? - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 07 02 28 ?? ?? ?? ?? 06 28 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 06 28 ?? ?? ?? ?? 0C DE ?? 26 00 00 DE ?? 00 7E ?? - ?? ?? ?? 0C 2B ?? 00 08 2A + 48 89 4C 24 ?? 48 83 EC ?? 48 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? 45 33 C9 45 33 C0 BA ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 48 89 44 24 ?? 48 83 7C 24 ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 48 89 44 24 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 44 24 ?? B9 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 48 89 44 24 ?? BA ?? ?? ?? ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 54 24 + ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 4C 8B 44 24 ?? 48 8B 15 ?? ?? ?? ?? 48 8B 4C 24 ?? + E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 44 24 ?? 41 B8 ?? ?? ?? ?? 33 D2 + 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 C7 40 ?? ?? ?? ?? ?? 48 8B 44 24 ?? + 48 8B 4C 24 ?? 48 89 48 ?? 48 8B 44 24 ?? C7 40 ?? ?? ?? ?? ?? 48 8B 44 24 ?? 48 C7 + 40 ?? ?? ?? ?? ?? 48 8B 44 24 ?? C7 40 ?? ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? + 48 89 48 ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 89 48 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 48 8B 4C 24 ?? 48 89 41 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 89 41 ?? + 48 8B 44 24 ?? C7 40 ?? ?? ?? ?? ?? 48 8B 44 24 ?? 48 83 C0 ?? 48 8B 94 24 ?? ?? ?? + ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 98 4C 8B C0 48 8D + 15 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 48 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 83 C0 ?? + 48 8B D0 48 8B 4C 24 ?? FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 54 24 + ?? 48 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 44 24 ?? 45 33 C9 41 B8 + ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 50 ?? 48 8B 44 24 ?? 48 8B 48 ?? FF 15 ?? ?? ?? ?? + 48 8D 05 ?? ?? ?? ?? F0 FF 00 48 83 C4 ?? C3 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) and ($remote_connection) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($enum_shares) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Jemd : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Maktub : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Jemd ransomware." + description = "Yara rule that detects Maktub ransomware." author = "ReversingLabs" - id = "ef981ffa-8801-50f0-9441-5f2bfcf44133" + id = "23ca4232-77ff-5519-b6b0-ccec6cb35fe1" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Jemd.yara#L1-L105" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "552e0fc118031e953dee2e7c6bf8234a5a90de8c34b0e2724dfe99f2b28b8c51" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Maktub.yara#L1-L116" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ee3213213e9521f7d19ce6340cd2f98057c22b1188ceefc30c17c18b6ec54e20" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -37231,96 +38453,118 @@ rule REVERSINGLABS_Win32_Ransomware_Jemd : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Jemd" + tc_detection_name = "Maktub" tc_detection_factor = 5 importance = 25 strings: - $find_files_1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 33 DB 89 9D ?? ?? ?? ?? 89 4D ?? 89 55 ?? 89 45 ?? 8B - 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? - 64 FF 30 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 83 F8 ?? 75 - ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B - 45 ?? 50 8B 45 ?? 50 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? B1 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 - } - $find_files_2 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 4D ?? - 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? - ?? ?? 8D B5 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 E8 ?? ?? ?? ?? 89 - C3 BB ?? ?? ?? ?? 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4B 75 ?? 33 DB 8D 45 ?? 33 C9 BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 8A 14 1E 88 54 05 ?? 40 43 80 3C 1E ?? 74 ?? 83 F8 - ?? 7E ?? 43 8D 85 ?? ?? ?? ?? 8D 55 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 45 ?? 50 8D 85 ?? ?? ?? ?? 8D 55 ?? B9 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 80 7C 1E - ?? ?? 75 ?? 80 3C 1E ?? 74 ?? 81 FB ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? 33 C0 5A 59 59 64 - 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? C3 - } - $encrypt_files_p1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? - ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 8B D9 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? - ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 - 89 20 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 80 7C 02 ?? ?? 75 ?? 8B 45 ?? E8 ?? ?? ?? ?? - 8B D0 4A 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 - ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B D0 83 CA ?? 3B D0 75 ?? 80 - FB ?? 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 50 - 8B 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CB 8B 55 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? FF + $encrypt_files = { + 55 8B EC 83 EC ?? 53 8B 1D ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 8D 8B ?? ?? ?? ?? E8 ?? ?? + ?? ?? 51 8D B3 ?? ?? ?? ?? 8B CB 56 E8 ?? ?? ?? ?? 85 C0 74 ?? 50 8B 43 ?? FF D0 8D + 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8B 43 ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + B3 ?? ?? ?? ?? FF D0 85 C0 74 ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8B 43 ?? 6A + ?? 6A ?? 6A ?? 6A ?? FF 75 ?? C7 45 ?? ?? ?? ?? ?? FF D0 85 C0 75 ?? FF 75 ?? 8B 43 + ?? FF D0 5E 33 C0 5B 8B E5 5D C3 A1 ?? ?? ?? ?? 57 8B 7D ?? 85 C0 75 ?? FF 15 ?? ?? + ?? ?? A3 ?? ?? ?? ?? 57 6A ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B F8 89 7D ?? 85 C9 74 + ?? 8B D1 33 C0 C1 E9 ?? F3 AB 8B CA 83 E1 ?? F3 AA 8B 7D ?? B9 ?? ?? ?? ?? 3B FE 76 + ?? 8D 46 ?? 3B F8 73 ?? 8D 57 ?? 8D 70 ?? 8B FF 8A 06 8D 52 ?? 88 42 ?? 8D 76 ?? 49 + 75 ?? EB ?? 8B D7 2B D6 8A 06 8D 76 ?? 88 44 32 ?? 49 75 ?? E8 ?? ?? ?? ?? 89 83 ?? + ?? ?? ?? 8D 4F ?? 8B 83 ?? ?? ?? ?? 89 47 ?? FF B3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 8D 45 ?? FF 75 ?? 50 8B 43 ?? 57 6A ?? 6A ?? 6A ?? FF 75 ?? FF D0 85 C0 75 ?? A1 + ?? ?? ?? ?? 85 C0 75 ?? A1 ?? ?? ?? ?? FF D0 A3 ?? ?? ?? ?? 57 6A ?? 50 FF 15 ?? ?? + ?? ?? FF 75 ?? 8B 43 ?? FF D0 5F 5E 33 C0 5B 8B E5 5D C3 FF 75 ?? 8D 45 ?? 57 50 E8 + ?? ?? ?? ?? 50 8D 8B ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? + ?? 85 C0 75 ?? A1 ?? ?? ?? ?? FF D0 A3 ?? ?? ?? ?? 57 6A ?? 50 FF 15 ?? ?? ?? ?? FF + 75 ?? 8B 43 ?? FF D0 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 } - $encrypt_files_p2 = { - 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B B5 ?? ?? ?? - ?? 8B C6 83 C8 ?? 3B C6 75 ?? 80 FB ?? 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B - 45 ?? 50 8B 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CB 8B 55 ?? E8 ?? ?? ?? ?? EB ?? FF - 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B - 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? C3 + $search_files = { + 55 8B EC 83 EC ?? 53 56 57 8B F9 68 ?? ?? ?? ?? FF 75 ?? 8B 47 ?? FF D0 85 C0 0F 84 + ?? ?? ?? ?? 8B 47 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? + FF D0 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 4F ?? 8D 45 ?? 50 0F 57 C0 53 66 0F 13 45 + ?? FF D1 85 C0 0F 84 ?? ?? ?? ?? 8B 75 ?? 8B C6 0B 45 ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 6A ?? 50 8D 4D ?? C7 45 ?? ?? ?? ?? ?? FF + 72 ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 87 ?? ?? ?? ?? + 8B 55 ?? 8D 4A ?? C7 45 ?? ?? ?? ?? ?? 89 4D ?? FF 70 ?? 50 FF 31 8D 4D ?? E8 ?? ?? + ?? ?? 8B 45 ?? 83 C0 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 7F ?? A1 ?? ?? ?? ?? 85 C0 75 ?? + FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 75 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 8B 45 ?? 85 C0 + 7C ?? 7F ?? 81 FE ?? ?? ?? ?? 72 ?? 50 8B 45 ?? 56 53 8B 1D ?? ?? ?? ?? 33 F6 51 8D + 48 ?? 89 65 ?? 39 31 7C ?? 51 8D 70 ?? FF D3 8B 4D ?? 8D 46 ?? 51 33 F6 89 65 ?? 89 + 01 8B 45 ?? 39 70 ?? 8D 48 ?? 7C ?? 51 8D 70 ?? FF D3 8B 4D ?? 8D 46 ?? 89 01 8B CF + E8 ?? ?? ?? ?? 8B 75 ?? 8B F8 E9 ?? ?? ?? ?? 8B 75 ?? 8B 47 ?? 6A ?? 6A ?? 6A ?? 6A + ?? 6A ?? 68 ?? ?? ?? ?? 56 FF D0 89 45 ?? 83 F8 ?? 75 ?? 8B 47 ?? 53 FF D0 33 FF E9 + ?? ?? ?? ?? 51 8D 87 ?? ?? ?? ?? 8B CF 50 E8 ?? ?? ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? + ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 4D ?? C7 45 + ?? ?? ?? ?? ?? 51 FF 75 ?? 50 8B 47 ?? 53 FF D0 85 C0 75 ?? 8B 4D ?? E9 ?? ?? ?? ?? + 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 45 ?? C7 45 ?? + ?? ?? ?? ?? 50 FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 85 C0 74 ?? E8 ?? ?? ?? ?? + 8B 45 ?? 6A ?? 89 45 ?? 8D 45 ?? 50 8B 47 ?? 6A ?? 6A ?? 6A ?? 6A ?? FF 75 ?? FF D0 + 85 C0 75 ?? 8B 4D ?? EB ?? FF 75 ?? 8D 45 ?? 50 FF 75 ?? 8B 47 ?? 6A ?? 6A ?? 6A ?? + FF 75 ?? FF D0 85 C0 75 ?? 8B 4D ?? EB ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF + 75 ?? 8B 45 ?? 50 FF 75 ?? 8B 47 ?? FF D0 8B 4D ?? 85 C0 74 ?? 8B 45 ?? 3B 45 ?? 74 + ?? E8 ?? ?? ?? ?? FF 75 ?? 8B 47 ?? FF D0 8B 47 ?? 53 FF D0 FF 75 ?? 8B 47 ?? FF D0 + 8B 47 ?? 56 FF D0 33 FF E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 8B 47 ?? FF D0 FF 75 + ?? 8B 47 ?? FF D0 8B 47 ?? 53 FF D0 51 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CF E8 ?? + ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 51 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CF E8 ?? + ?? ?? ?? 6A ?? 51 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 51 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 8D 45 + ?? 8B CC 50 E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? FF 75 ?? 8B 47 ?? FF D0 85 C0 75 ?? + 8B 47 ?? 56 FF D0 33 FF EB ?? BF ?? ?? ?? ?? 83 C6 ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? + 85 C0 7F ?? A1 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B 1D ?? ?? + ?? ?? 56 6A ?? 50 FF D3 EB ?? 8B 47 ?? 53 FF D0 33 FF 8B 1D ?? ?? ?? ?? 8B 75 ?? 83 + C6 ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 7F ?? A1 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? + ?? ?? ?? A3 ?? ?? ?? ?? 56 6A ?? 50 FF D3 8B C7 5F 5E 5B 8B E5 5D C2 } - $main_routine = { - 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 - ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? B0 ?? E8 ?? - ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? - ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 50 8D 55 ?? 66 - B8 ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? B1 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? - A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B - 0D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 8B 08 FF 51 ?? 8D 55 ?? - 33 C0 E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 8B 08 FF - 51 + $previous_encrypt_files = { + 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8D 4D + ?? 89 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF + 77 ?? FF D3 8D 4D ?? 89 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 + 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 + 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D + 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? + FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? + ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF + 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? + ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 + B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 + 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF 77 ?? FF D3 8B F0 + 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D + 4D ?? E8 ?? ?? ?? ?? FF 30 FF 15 ?? ?? ?? ?? 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF B7 + ?? ?? ?? ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? + ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF B7 ?? ?? ?? ?? FF D3 8B F0 8D + 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? FF 30 FF 15 ?? ?? ?? ?? 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF B7 ?? + ?? ?? ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? + ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 30 FF B7 ?? ?? ?? ?? FF D3 8B F0 8D 4D + ?? 89 B7 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? + E8 ?? ?? ?? ?? FF 30 FF B7 ?? ?? ?? ?? FF D3 8B F0 8D 4D ?? 89 B7 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 6A ?? 8D B7 ?? ?? ?? ?? FF 30 8B 47 ?? 6A ?? 56 FF D0 85 C0 8D 4D ?? 0F 94 C3 E8 + ?? ?? ?? ?? 84 DB 74 ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? + FF 30 8B 47 ?? 6A ?? 56 FF D0 85 C0 8D 4D ?? 0F 94 C3 E8 ?? ?? ?? ?? 84 DB 0F 85 ?? + ?? ?? ?? 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($main_routine) and ( all of ($find_files_*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and $search_files and $previous_encrypt_files and $encrypt_files } -rule REVERSINGLABS_Win32_Ransomware_Telecrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Serpent : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects TeleCrypt ransomware." + description = "Yara rule that detects Serpent ransomware." author = "ReversingLabs" - id = "c4eada2d-72c0-5efe-bf2b-8f053348d89d" + id = "0757ad7c-b2b1-5323-960a-55ffe3eaed12" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.TeleCrypt.yara#L1-L109" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "9d856eae4369cd7ba1d88bd6ef37931e069127e2c05a84a44f5274f681e83fc0" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Serpent.yara#L1-L122" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "5e1917e8d23a5edc65ac423f3d18cc78c3848bd6c1ccc67d052eb37172857081" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -37328,107 +38572,123 @@ rule REVERSINGLABS_Win32_Ransomware_Telecrypt : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "TeleCrypt" + tc_detection_name = "Serpent" tc_detection_factor = 5 importance = 25 strings: - $encrypt_file = { - 57 E8 ?? ?? ?? ?? 89 03 EB ?? 6A ?? E8 ?? ?? ?? ?? 89 03 66 83 BB ?? ?? ?? ?? ?? 0F - 85 ?? ?? ?? ?? 8B 03 50 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 66 81 7B ?? ?? ?? 75 ?? E8 ?? - ?? ?? ?? 66 89 83 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 89 83 ?? ?? ?? ?? E9 - ?? ?? ?? ?? 0F B7 05 ?? ?? ?? ?? 66 89 83 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 43 ?? ?? ?? - ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 6A ?? 6A ?? 50 8D 43 ?? 50 E8 ?? ?? ?? ?? 83 F8 ?? 75 - ?? 66 C7 43 ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 E9 ?? ?? ?? ?? 89 03 66 81 7B ?? ?? ?? 0F - 85 ?? ?? ?? ?? 66 C7 43 ?? ?? ?? 6A ?? 8B 03 50 E8 ?? ?? ?? ?? 8B F8 83 FF ?? 75 ?? - 8B C3 E8 ?? ?? ?? ?? 8B F0 E9 ?? ?? ?? ?? 81 EF ?? ?? ?? ?? 85 FF 7D ?? 33 FF 6A ?? - 6A ?? 57 8B 03 50 E8 ?? ?? ?? ?? 40 74 ?? 6A ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? 8D 83 - ?? ?? ?? ?? 50 8B 03 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B C3 E8 ?? ?? ?? ?? 8B F0 E9 ?? - ?? ?? ?? F6 43 ?? ?? 74 ?? 83 3C 24 ?? 76 ?? 8B 14 24 4A 85 D2 72 ?? 42 33 FF 8D 83 - ?? ?? ?? ?? 80 38 ?? 75 ?? 6A ?? 6A ?? 8B C7 2B 44 24 ?? 50 8B 03 50 E8 ?? ?? ?? ?? - 40 74 ?? 8B 03 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B C3 E8 ?? ?? ?? ?? 8B F0 EB ?? 47 40 - 4A 75 ?? 66 83 BB ?? ?? ?? ?? ?? 75 ?? 0F B7 05 ?? ?? ?? ?? 66 89 83 ?? ?? ?? ?? 66 - 81 7B ?? ?? ?? 74 ?? 8B 03 50 E8 - } - $server_communication = { - 6A ?? 8D 45 ?? 50 8B 45 ?? 8B 80 ?? ?? ?? ?? 33 C9 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A - ?? 8D 45 ?? 50 FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? - ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? - 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8B 80 ?? ?? ?? ?? - 33 C9 E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? B2 ?? A1 ?? - ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 33 DB 8B CB B8 ?? ?? ?? - ?? D3 E0 85 F0 74 ?? 8D 45 ?? 8B D3 66 83 C2 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? ?? ?? 8B 08 FF 51 ?? 43 83 FB ?? 75 ?? A1 ?? ?? - ?? ?? 8B 10 FF 52 ?? 8B F0 4E 85 F6 7C ?? 46 33 DB 8D 4D ?? 8B D3 A1 ?? ?? ?? ?? 8B - 38 FF 57 ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 43 4E 75 ?? A1 ?? ?? ?? ?? 8B 10 - FF 52 ?? 8B F0 4E 85 F6 7C ?? 46 33 DB 6A ?? 6A ?? 8D 4D ?? 8B D3 A1 ?? ?? ?? ?? 8B - 38 FF 57 ?? 8B 45 ?? 8B 0D ?? ?? ?? ?? 33 D2 E8 ?? ?? ?? ?? 43 4E 75 ?? 8D 55 ?? B8 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? - ?? ?? 8B 08 FF 91 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 45 ?? 8B 80 ?? ?? ?? ?? 33 C9 BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 - ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 - } - $server_communication_1 = { - 55 8B EC 33 C9 51 51 51 51 51 53 8B D8 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 6A - ?? 8D 45 ?? 50 33 C9 BA ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 45 ?? - 50 8D 55 ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 91 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? - ?? 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 33 C9 8B 83 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 33 D2 8B 83 ?? ?? ?? ?? 8B 08 FF 91 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $do_dll_stuff_and_create_thread = { + 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 89 D2 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 89 FF 90 90 6A ?? 53 E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 68 ?? + ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? BB ?? ?? ?? ?? 4B 75 ?? BA + ?? ?? ?? ?? 66 0F 6E D2 89 FF 89 C9 31 D2 66 0F 7E D2 89 15 ?? ?? ?? ?? 81 3D ?? ?? + ?? ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? BB ?? ?? ?? ?? 4B 75 ?? BB ?? ?? ?? ?? 89 C9 4B + 75 ?? 89 C9 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? BB ?? ?? ?? ?? 4B + 75 ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 79 ?? E8 ?? + ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 79 ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 4B + 75 ?? 89 FF 90 BB ?? ?? ?? ?? 89 C9 4B 75 ?? 90 90 BB ?? ?? ?? ?? 4B 75 ?? BB ?? ?? + ?? ?? 4B 75 ?? BB ?? ?? ?? ?? 4B 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 90 BB ?? ?? ?? ?? 89 D2 4B 75 ?? 6A ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? BA ?? + ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 90 89 C9 BB ?? ?? ?? ?? 89 FF 4B 75 ?? 68 ?? ?? ?? ?? + 6A ?? 56 E8 ?? ?? ?? ?? BB ?? ?? ?? ?? 89 D2 4B 75 ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 33 + C0 A3 ?? ?? ?? ?? 64 8B 35 ?? ?? ?? ?? 89 35 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? + 90 89 F6 90 BB ?? ?? ?? ?? 89 DB 4B 75 ?? 89 D2 89 C0 BB ?? ?? ?? ?? 89 D2 4B 75 ?? + C7 05 ?? ?? ?? ?? ?? ?? ?? ?? BB ?? ?? ?? ?? 89 FF 4B 75 ?? 89 C0 0F 31 90 89 C7 0F + 31 90 89 C0 29 F8 89 D2 89 DB 77 ?? 90 90 89 C9 89 F6 8B 3D ?? ?? ?? ?? 90 90 89 C9 + 89 F6 90 03 3D ?? ?? ?? ?? 90 90 89 C9 89 F6 FF D7 89 F6 90 90 BB ?? ?? ?? ?? 4B 75 + ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? C3 } - $exec_payload = { - 55 68 ?? ?? ?? ?? 64 FF 32 64 89 22 8B 4D ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? - E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? - ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 6A ?? 6A ?? 8D 55 ?? 33 C0 E8 ?? ?? ?? ?? - 8B 45 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? C3 + $find_files = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 C0 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? + ?? ?? ?? 89 85 ?? ?? ?? ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8B 45 + ?? 8B 58 ?? 83 7B ?? ?? 75 ?? 8D 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 8D 55 ?? + A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 73 ?? 6A ?? 8D 45 ?? 50 8B 43 ?? 50 E8 ?? ?? ?? ?? + 81 7D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? + 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 43 ?? 89 85 ?? ?? ?? ?? C6 85 ?? ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C6 85 ?? + ?? ?? ?? ?? 8B 45 ?? 89 85 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? C6 85 + ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 95 ?? ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 8D ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 EB ?? 8B 43 ?? 89 + 85 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8B 45 ?? 89 85 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? + 89 B5 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 95 ?? ?? ?? ?? + A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B D8 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 } - $copy_payload = { - 55 8B EC 6A ?? 6A ?? 6A ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? B8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? B2 ?? E8 ?? - ?? ?? ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? 6A ?? 8D 55 ?? B8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 - 8D 55 ?? 33 C0 E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 5A 59 - 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $remote_connection = { + 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 FF 05 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 85 ?? + ?? ?? ?? 8D 83 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 66 8B 83 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? + ?? ?? 8D 55 ?? 33 C0 8A 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 51 ?? 68 ?? ?? ?? ?? 66 8B 83 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? + ?? ?? 8D 55 ?? 33 C0 8A 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 51 ?? 8D 45 ?? 8D 93 ?? ?? ?? + ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 55 ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 51 ?? 8D 45 ?? 8D 93 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 83 ?? ?? ?? + ?? 8B 08 FF 51 ?? 8D 55 ?? 0F B7 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 51 ?? 8D 55 ?? 0F B7 + 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 + ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 51 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 6A ?? + 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 81 FE ?? ?? ?? ?? 76 ?? E8 ?? ?? ?? ?? 66 89 B3 ?? + ?? ?? ?? 66 C7 45 ?? ?? ?? 66 C7 45 ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 0F B7 C6 50 E8 ?? ?? ?? ?? 66 81 BB ?? ?? ?? ?? ?? ?? 75 ?? 8D 4D ?? 66 BA + ?? ?? 8B C3 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? 50 0F B7 83 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? FF 0D ?? ?? ?? + ?? 83 3D ?? ?? ?? ?? ?? 75 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 } - $generate_strings_to_encrypt = { - 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? - E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D - 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? - ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? - ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? - ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 - ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 - 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? - ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? - ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? - ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B - 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? - 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 - ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 - ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? - ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? - 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 + $remote_ftp_connection = { + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? 8B 45 ?? 66 + 8B 80 ?? ?? ?? ?? 66 3D ?? ?? 7E ?? 66 3D ?? ?? 7D ?? 8B 45 ?? 66 83 B8 ?? ?? ?? ?? + ?? 74 ?? 8B 5D ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8B 4D ?? B2 ?? A1 ?? + ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 66 81 B8 ?? ?? ?? ?? ?? ?? 75 ?? B9 + ?? ?? ?? ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 88 ?? ?? ?? ?? 8D 45 ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? 8B 45 ?? 66 8B 80 + ?? ?? ?? ?? 66 3D ?? ?? 7E ?? 66 3D ?? ?? 7D ?? 8B 45 ?? 66 83 B8 ?? ?? ?? ?? ?? 74 + ?? 8B 5D ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8B 4D ?? B2 ?? A1 ?? ?? ?? + ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 B8 ?? ?? ?? ?? ?? 74 ?? 8B 45 ?? 83 B8 + ?? ?? ?? ?? ?? 75 ?? 8B 45 ?? 66 83 B8 ?? ?? ?? ?? ?? 74 ?? 8D 55 ?? 8B 5D ?? 8B 83 + ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8B 45 ?? 83 B8 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 + ?? 8A 80 ?? ?? ?? ?? 2C ?? 72 ?? 74 ?? FE C8 74 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B + 45 ?? FF B0 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 45 ?? FF B0 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? EB ?? 8B 45 ?? 8B 88 + ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 + FF 53 ?? EB ?? 8B 45 ?? 8B 88 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? 8B 45 ?? 83 B8 ?? ?? ?? ?? ?? 74 ?? 8B 45 ?? + 80 B8 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 88 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 88 ?? ?? ?? + ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? + 8B 45 ?? 66 8B 80 ?? ?? ?? ?? 66 3D ?? ?? 7E ?? 66 3D ?? ?? 7D ?? 8B 45 ?? 66 83 B8 + ?? ?? ?? ?? ?? 74 ?? 8B 5D ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8B 4D ?? + B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 66 81 B8 ?? ?? ?? ?? ?? + ?? 75 ?? B9 ?? ?? ?? ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 88 ?? ?? ?? ?? 8D + 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? 8B 45 ?? 8B 18 FF 53 ?? 8B 45 + ?? 66 8B 80 ?? ?? ?? ?? 66 3D ?? ?? 7E ?? 66 3D ?? ?? 7D ?? 8B 45 ?? 66 83 B8 ?? ?? + ?? ?? ?? 74 ?? 8B 5D ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8B 4D ?? B2 ?? + A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 66 83 B8 ?? ?? ?? ?? ?? 74 ?? + 8B 5D ?? 8B 55 ?? 8B 83 ?? ?? ?? ?? FF 93 } condition: - uint16(0)==0x5A4D and (($generate_strings_to_encrypt and $encrypt_file and $server_communication and $exec_payload) or ($encrypt_file and $server_communication_1 and $copy_payload)) + uint16(0)==0x5A4D and $do_dll_stuff_and_create_thread and $find_files and $remote_connection and $remote_ftp_connection } -rule REVERSINGLABS_Win64_Ransomware_Antiwar : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Kovter : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects AntiWar ransomware." + description = "Yara rule that detects Kovter ransomware." author = "ReversingLabs" - id = "3113ec26-e149-527b-9478-4dd86c7fa464" - date = "2022-04-21" - modified = "2022-04-21" + id = "9362ac5a-0b6c-5ac5-ac2b-59dcc1191dc6" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.AntiWar.yara#L1-L146" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "2d885f35454aaf7cb33f03c30b6681aa16cbe8353003bbae0b1e9fdecb2ff8a7" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Kovter.yara#L1-L141" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3082e036b54a73ce8397cfa6e8dc2a807c587d9f17286e75af6cdbe622fae1e1" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -37436,133 +38696,141 @@ rule REVERSINGLABS_Win64_Ransomware_Antiwar : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "AntiWar" + tc_detection_name = "Kovter" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 49 8B D7 49 8B CD FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? - 48 8D 95 ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? 4C 8B F0 48 89 44 24 ?? 48 83 F8 ?? - 0F 84 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? ?? 41 8B DC 48 8D 3D ?? ?? ?? ?? 66 90 48 8B 0F - E8 ?? ?? ?? ?? 48 8B D0 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? FF C3 48 83 C7 ?? 83 FB ?? 72 ?? 49 8B D7 49 8B CD FF 15 ?? ?? ?? ?? 48 8D 15 ?? - ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? - F6 85 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 66 0F 6F 35 ?? ?? 03 00 66 0F 6F 3D ?? ?? 03 - 00 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 C7 85 ?? ?? 00 00 ?? ?? 8B 05 ?? ?? ?? ?? 4C 8D - 3C C5 ?? ?? ?? ?? 41 BC ?? ?? ?? ?? 65 48 8B 04 25 ?? ?? ?? ?? 4A 8B 0C 38 41 8B 04 - 0C 39 05 ?? ?? ?? ?? 7E ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? - 75 ?? C6 05 ?? ?? ?? ?? ?? 0F 11 35 ?? ?? ?? ?? 0F 11 3D ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 89 05 ?? ?? ?? ?? 0F B7 85 ?? ?? ?? ?? 66 89 05 ?? ?? 04 00 48 8D 0D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 74 ?? 45 33 - C9 41 BA ?? ?? ?? ?? 4C 8D 35 ?? ?? ?? ?? 4D 2B D6 49 BB ?? ?? ?? ?? ?? ?? ?? ?? 66 - 66 0F 1F 84 00 ?? ?? 00 00 4B 8D 14 31 41 0F B6 C9 80 E1 ?? C0 E1 ?? 49 8B C3 48 D3 - } - $find_files_p2 = { - E8 30 02 4C 8D 42 ?? 41 8D 0C 12 80 E1 ?? C0 E1 ?? 49 8B D3 48 D3 EA 41 30 10 49 83 - C1 ?? 49 83 F9 ?? 72 ?? 4C 8B 74 24 ?? C6 05 ?? ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 48 8B D0 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 E8 ?? 48 63 C8 78 ?? 0F 1F 40 ?? 66 83 BC - 4D ?? ?? 00 00 ?? 74 ?? FF C8 48 83 E9 ?? 79 ?? EB ?? B3 ?? 48 98 4C 8D B5 ?? ?? ?? - ?? 4D 8D 34 46 48 8D 3D ?? ?? ?? ?? BE ?? ?? ?? ?? 45 33 ED 48 8B 0F E8 ?? ?? ?? ?? - 48 8B D0 49 8B CE FF 15 ?? ?? ?? ?? 0F B6 DB 85 C0 41 0F 44 DD 48 8D 7F ?? 48 83 EE - ?? 75 ?? 4C 8B 6C 24 ?? 4C 8B 74 24 ?? 84 DB 0F 84 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? ?? - 45 33 C0 49 8B D5 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 FF - 90 89 BD ?? ?? ?? ?? 4C 8D 85 ?? ?? ?? ?? 33 D2 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 48 8B D8 48 85 C0 0F 84 ?? ?? ?? ?? 66 0F 1F 84 00 ?? ?? 00 00 83 3D ?? ?? ?? ?? ?? - 0F 84 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 85 C9 0F 84 ?? ?? ?? ?? 83 79 ?? ?? 0F 8C - ?? ?? ?? ?? 66 0F 6F 35 ?? ?? 03 00 66 0F 6F 3D ?? ?? 03 00 66 C7 85 ?? ?? 00 00 ?? - ?? 65 48 8B 04 25 ?? ?? ?? ?? 4A 8B 0C 38 41 8B 04 0C 39 05 ?? ?? ?? ?? 7E ?? 48 8D - 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? C6 05 ?? ?? ?? ?? ?? 0F 11 - 35 ?? ?? ?? ?? 0F 11 3D ?? ?? ?? ?? 0F B7 85 ?? ?? ?? ?? 66 89 05 ?? ?? 04 00 48 8D - } - $find_files_p3 = { - 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? - ?? 74 ?? 48 8B C7 41 BA ?? ?? ?? ?? 4C 8D 35 ?? ?? ?? ?? 4D 2B D6 49 BB ?? ?? ?? ?? - ?? ?? ?? ?? 90 4E 8D 0C 30 0F B6 C8 80 E1 ?? C0 E1 ?? 4D 8B C3 49 D3 E8 45 30 01 43 - 8D 0C 11 80 E1 ?? C0 E1 ?? 49 8B D3 48 D3 EA 41 30 51 ?? 48 83 C0 ?? 48 83 F8 ?? 72 - ?? 4C 8B 74 24 ?? C6 05 ?? ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? C7 44 24 - ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 44 24 ?? 48 89 7D ?? 48 C7 45 ?? ?? ?? ?? ?? BA - ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? - ?? ?? ?? 48 89 85 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 48 C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? 66 89 BD ?? ?? 00 00 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8D 15 ?? ?? ?? ?? - 48 8D 4D ?? E8 ?? ?? ?? ?? 48 8B D6 48 85 DB 48 0F 45 D3 48 8D 4D ?? E8 ?? ?? ?? ?? - 48 8B 3D ?? ?? ?? ?? 48 8B 5F ?? 48 3B 5F ?? 74 ?? 0F 1F 84 00 ?? ?? ?? ?? 48 8B 0B + $remote_connection_1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D + ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? + 89 5D ?? 89 5D ?? 8B D9 89 55 ?? 89 45 ?? 8B 75 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? + E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 A1 ?? ?? ?? ?? 80 38 ?? 74 + ?? 8B CE 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 33 C0 + 89 45 ?? 33 C0 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 48 75 ?? B3 ?? 8D 45 ?? 50 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? + ?? ?? ?? 5A 2B C2 83 C0 ?? 50 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 83 C2 ?? + 8B 45 ?? 59 E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 5A 2B C2 50 8D + 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? + 8B D0 42 8B 45 ?? 59 E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? 8B C8 49 BA ?? ?? ?? ?? 8B 45 ?? + E8 ?? ?? ?? ?? 84 DB 0F 84 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 48 0F 8E ?? ?? ?? ?? + 6A ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8B F8 85 FF 0F 84 ?? ?? + ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 68 + ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 8D } - $find_files_p4 = { - 48 8B 01 48 8D 54 24 ?? FF 50 ?? 48 83 C3 ?? 48 3B 5F ?? 75 ?? 48 8D 05 ?? ?? ?? ?? - 48 89 44 24 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 83 FA ?? - 72 ?? 48 FF C2 48 8B 8D ?? ?? ?? ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? - 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 FF - 48 89 BD ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 40 88 BD ?? ?? ?? ?? 48 8D 4D - ?? E8 ?? ?? ?? ?? EB ?? 48 8B CB E8 ?? ?? ?? ?? 48 8B CB E8 ?? ?? ?? ?? 4C 8D 85 ?? - ?? ?? ?? 33 D2 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B D8 48 85 C0 0F 85 ?? ?? ?? - ?? 45 33 C0 49 8B D5 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 45 - 33 E4 4C 8B 7C 24 ?? 48 8D 95 ?? ?? ?? ?? 49 8B CE FF 15 ?? ?? ?? ?? 85 C0 + $remote_connection_2 = { + 45 ?? 50 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 0D ?? ?? + ?? ?? 0D ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 50 8D 45 ?? 50 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 6A + ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 ?? 8D 45 + ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? + ?? ?? ?? 8B C6 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? 01 45 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? + 83 7D ?? ?? 75 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? E9 + ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? + 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8B F8 85 FF + 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? + ?? ?? 50 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D + 45 ?? 50 8D 45 ?? 50 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 + ?? 0D ?? ?? ?? ?? 0D ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 50 8D 45 ?? 50 6A ?? 8B 45 ?? 50 + E8 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? + ?? 85 C0 74 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? + ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? + ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B C6 8B 55 ?? E8 ?? ?? ?? ?? 8B + 45 ?? 01 45 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? 50 E8 ?? ?? ?? + ?? 57 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 3E ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? + ?? ?? 48 0F 8E ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 6A + ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8B F8 + 85 FF 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? E8 + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? + ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 8B 45 + ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B } - $enum_shares = { - 48 83 EC ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 44 24 ?? 33 D2 C7 44 24 ?? ?? ?? ?? - ?? 48 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 4C 8B C9 48 89 44 24 ?? 8D 4A ?? 44 8D 42 - ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 4C 24 ?? 48 89 7C 24 ?? E8 ?? ?? ?? ?? - 48 8B F8 48 85 C0 0F 84 ?? ?? ?? ?? 48 8B 4C 24 ?? 4C 8D 4C 24 ?? 4C 8B C0 48 8D 54 - 24 ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 48 89 5C 24 ?? 33 DB 39 5C 24 ?? 76 ?? 0F 1F 84 00 - ?? ?? ?? ?? 48 8D 0C 5B 48 C1 E1 ?? 48 03 CF F6 41 ?? ?? 74 ?? E8 ?? ?? ?? ?? EB ?? - 48 8B 49 ?? E8 ?? ?? ?? ?? FF C3 3B 5C 24 ?? 72 ?? 48 8B 4C 24 ?? 4C 8D 4C 24 ?? 4C - 8B C7 48 8D 54 24 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 5C 24 ?? 48 8B CF E8 ?? ?? ?? - ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 48 8B 4C 24 ?? 48 33 CC E8 ?? ?? ?? - ?? 48 83 C4 ?? C3 + $remote_connection_3 = { + 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? + ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B C6 8B 55 ?? + E8 ?? ?? ?? ?? 8B 45 ?? 01 45 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? 83 7D ?? ?? 75 ?? 8B 45 + ?? 50 E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? + 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 + ?? E8 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8B F8 85 FF 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? + ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 57 E8 ?? + ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B + 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? + ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B C6 8B 55 + ?? E8 ?? ?? ?? ?? 8B 45 ?? 01 45 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? 83 7D ?? ?? 75 ?? 8B + 45 ?? 50 E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 } - $encrypt_files_p1 = { - 48 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 45 33 C9 45 33 C0 BA - ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 4C 8B F0 48 8B 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 49 83 FE ?? 0F 84 ?? ?? ?? ?? 41 BD ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 49 - 8B CE FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8B F8 48 85 C0 0F 84 ?? ?? - ?? ?? 4C 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 80 - A5 ?? ?? ?? ?? ?? 0F B6 8D ?? ?? ?? ?? 80 E1 ?? 80 C9 ?? 88 8D ?? ?? ?? ?? 4C 8D 85 - ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? ?? - ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 85 ?? ?? ?? ?? - BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? 45 8B C1 48 8D - 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? - ?? ?? ?? 33 D2 44 8D 42 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 44 8D 42 ?? 48 - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 44 8D 42 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 48 8B DE 45 33 C9 45 33 C0 48 8B D6 49 8B CE FF 15 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? - ?? 48 81 F9 ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 F7 E9 48 + $find_files = { + 50 E8 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 33 F6 46 81 FE ?? ?? ?? ?? 0F 87 + ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 8D 57 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 07 ?? 0F 85 ?? ?? ?? ?? F6 47 ?? ?? 0F 85 ?? ?? + ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? F7 D8 1B C0 F7 D8 84 C0 75 ?? + 6A ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 + ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 57 53 E8 ?? ?? ?? ?? F7 D8 1B C0 F7 D8 84 C0 0F 85 ?? ?? ?? ?? 83 + FB ?? 74 ?? 53 E8 ?? ?? ?? ?? 57 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? + ?? ?? 33 F6 46 81 FE ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 45 + ?? 8D 57 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F + 84 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 07 ?? 0F + 84 ?? ?? ?? ?? F6 47 ?? ?? 75 ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? FF 75 + ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? F7 D8 1B C0 F7 D8 84 C0 75 + ?? 6A ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF 75 ?? 68 + ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 57 53 E8 ?? ?? ?? ?? F7 D8 1B C0 + F7 D8 84 C0 0F 85 ?? ?? ?? ?? 83 FB ?? 74 ?? 53 E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? F7 D8 1B DB F7 DB 84 DB + 75 ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 } - $encrypt_files_p2 = { - 8B FA 48 C1 FF ?? 48 8B C7 48 C1 E8 ?? 48 03 F8 48 85 FF 0F 8E ?? ?? ?? ?? 48 89 74 - 24 ?? 4C 8D 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 49 8B D7 49 8B CE FF 15 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 89 44 24 ?? 4D 8B CF 4D 8B C7 48 8D 95 ?? ?? ?? ?? 33 C9 E8 ?? ?? ?? - ?? 45 33 C9 45 33 C0 48 8B D3 49 8B CE FF 15 ?? ?? ?? ?? 48 89 74 24 ?? 4C 8D 8D ?? - ?? ?? ?? 41 B8 ?? ?? ?? ?? 49 8B D7 49 8B CE FF 15 ?? ?? ?? ?? 48 81 C3 ?? ?? ?? ?? - 45 33 C9 45 33 C0 48 8B D3 49 8B CE FF 15 ?? ?? ?? ?? 48 83 EF ?? 0F 85 ?? ?? ?? ?? - E9 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 83 78 ?? ?? 0F 8C ?? - ?? ?? ?? 41 8B C6 48 8D 1C C5 ?? ?? ?? ?? 65 48 8B 04 25 ?? ?? ?? ?? 48 8B 0C 18 8B - 04 0F 39 05 ?? ?? ?? ?? 7E ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? - ?? 75 ?? 66 C7 05 ?? ?? 05 00 ?? ?? C6 05 ?? ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 74 ?? 80 35 ?? ?? - ?? ?? ?? 80 35 ?? ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 65 48 8B 04 25 ?? ?? ?? ?? 48 8B - 0C 18 8B 04 0F 39 05 ?? ?? ?? ?? 7E ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 3D ?? - ?? ?? ?? ?? 75 ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D + $decrypt_payload_script = { + FF 75 ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? FF + 75 ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 + ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? + ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 8B C3 BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? FF 33 FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF + 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? + ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF + 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? + ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D + 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? E8 } condition: - uint16(0)==0x5A4D and (( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($enum_shares)) + uint16(0)==0x5A4D and $find_files and $decrypt_payload_script and ( all of ($remote_connection_*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Cobralocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Ladon : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects CobraLocker ransomware." + description = "Yara rule that detects Ladon ransomware." author = "ReversingLabs" - id = "dada6370-3ae3-5931-ba9f-da56ebbcd8c8" - date = "2021-08-12" - modified = "2021-08-12" + id = "ebc8f957-cdcf-54eb-bd02-74088cf51768" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Bytecode.MSIL.Ransomware.CobraLocker.yara#L1-L59" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "95f4c645c7c237d23b5028f824f78a5f9f8f0a4737b391d877582afe08264d7e" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Ladon.yara#L1-L101" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "979e3f3bf6a67bf10b6bfdd2eeb722d8836096076b7e88c6d4aca041a1a9eecb" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -37570,56 +38838,93 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Cobralocker : TC_DETECTION MALICIOUS sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "CobraLocker" + tc_detection_name = "Ladon" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files = { - 14 0A 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? 0C 00 73 ?? - ?? ?? ?? 0D 00 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 - 03 07 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? - ?? 6F ?? ?? ?? ?? 00 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 - 09 17 6F ?? ?? ?? ?? 00 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 00 11 ?? 02 16 02 - 8E 69 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 00 DD ?? ?? ?? ?? 11 ?? 38 ?? ?? ?? ?? - 38 ?? ?? ?? ?? 39 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 00 DC 08 6F ?? ?? ?? ?? 0A 00 DD ?? - ?? ?? ?? 09 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 39 ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 00 DC 00 DD - ?? ?? ?? ?? 08 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 39 ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 00 DC 06 - 13 ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 11 ?? 2A - } $find_files = { - 16 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 0C 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 06 72 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 13 ?? 08 72 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 72 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 13 ?? 09 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? - ?? ?? ?? 16 28 ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 - 28 ?? ?? ?? ?? 13 ?? 73 ?? ?? ?? ?? 13 ?? 72 ?? ?? ?? ?? 13 ?? 16 13 ?? 38 ?? ?? ?? ?? - 00 11 ?? 11 ?? 11 ?? 9A 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 - FE 04 13 ?? 11 ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 00 11 ?? 11 ?? 11 ?? 9A 11 ?? 6F ?? ?? - ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 FE 04 13 ?? 11 ?? 38 ?? ?? ?? ?? 38 ?? - ?? ?? ?? 00 11 ?? 11 ?? 11 ?? 9A 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 - ?? 8E 69 FE 04 13 ?? 11 ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 00 11 ?? 11 ?? 11 ?? 9A 11 ?? - 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 FE 04 13 ?? 11 ?? 38 ?? ?? ?? - ?? 38 ?? ?? ?? ?? 3A ?? ?? ?? ?? 16 13 ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 3A ?? ?? ?? ?? - 16 13 ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 3A ?? ?? ?? ?? 16 13 ?? 38 ?? ?? ?? ?? 38 ?? ?? - ?? ?? 3A ?? ?? ?? ?? 2A + F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 + 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 + 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? + 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 57 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? 8D 85 + ?? ?? ?? ?? 53 56 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 FF 85 DB 74 ?? 90 8B 45 ?? 8B + 34 B8 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 66 8B 08 66 3B 0E 75 ?? 66 85 C9 74 ?? + 66 8B 48 ?? 66 3B 4E ?? 75 ?? 83 C0 ?? 83 C6 ?? 66 85 C9 75 ?? 33 C0 EB ?? 1B C0 83 + C8 ?? 85 C0 74 ?? 47 3B FB 72 ?? 8B 75 ?? 8B 7D ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF + 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 75 ?? 33 DB 83 F8 ?? 0F + 95 C3 FF 15 ?? ?? ?? ?? 5E 8B C3 5B 5F 8B E5 5D C3 + } + $encrypt_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 FF 75 ?? 33 DB 89 5D ?? E8 ?? ?? ?? ?? 8B F8 83 + C4 ?? 89 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 83 3F ?? 0F 85 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? + FF 77 ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 0F 84 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? FF + 77 ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? FF + 77 ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? FF + 77 ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? FF + 77 ?? E8 ?? ?? ?? ?? 8B C8 83 C4 ?? 89 4D ?? 85 C9 0F 84 ?? ?? ?? ?? 83 3E ?? 0F 85 + ?? ?? ?? ?? 8B 45 ?? 83 38 ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 83 38 ?? 0F 85 ?? ?? ?? ?? + 8B 45 ?? 83 38 ?? 0F 85 ?? ?? ?? ?? 83 39 ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 70 + ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? FF 75 ?? 33 FF C7 45 + ?? ?? ?? ?? ?? 89 5D ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? 83 3E ?? 75 ?? 57 + 68 ?? ?? ?? ?? FF 76 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? FF 70 ?? 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 + ?? 8D 45 ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? 8D 7B ?? A1 ?? + ?? ?? ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 1D ?? ?? ?? ?? 85 F6 74 ?? 56 E8 + ?? ?? ?? ?? 83 C4 ?? 8B C7 5F 5E 5B 8B E5 5D C3 FF 76 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 78 ?? 85 FF 74 ?? 8B 47 ?? 89 45 + } + $encrypt_files_p2 = { + 8B 70 ?? 8D 4E ?? 8A 06 46 84 C0 75 ?? 2B F1 8D 04 75 ?? ?? ?? ?? 50 6A ?? FF 15 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 84 9D ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 0C 75 + ?? ?? ?? ?? 51 50 8D 46 ?? 50 8B 45 ?? FF 70 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 3F + 43 85 FF 75 ?? 68 ?? ?? ?? ?? C7 84 9D ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? E8 ?? ?? ?? ?? 8B 7D ?? 8B 77 ?? 8D 4E ?? 8A 06 46 84 C0 75 ?? 2B F1 8D 46 ?? 50 + 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B C8 89 4D ?? 85 C9 0F 84 ?? ?? ?? ?? + 8B C6 99 6A ?? 2B C2 D1 F8 6A ?? 89 45 ?? 8D 45 ?? 50 51 6A ?? 56 FF 77 ?? FF 15 ?? + ?? ?? ?? 8B 7D ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 57 8B 7D ?? 8B F0 57 56 FF 15 ?? ?? ?? ?? 56 FF 15 + ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 57 6A ?? FF 15 ?? ?? + ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 45 ?? FF 70 ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? + ?? ?? 8B 7D ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 05 ?? ?? ?? + ?? ?? ?? ?? ?? 85 FF 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 85 DB 74 ?? FF B4 B5 ?? + ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 46 3B F3 72 ?? 8B 45 ?? 5F 5E + 5B 8B E5 5D C3 + } + $remote_connection = { + 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 50 68 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B E5 5D C3 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + C6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 85 C0 0F 88 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 78 ?? 56 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? + 85 F6 74 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? + 83 C4 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5E 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($remote_connection) } -rule REVERSINGLABS_Win32_Ransomware_Blitzkrieg : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Sage : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Blitzkrieg ransomware." + description = "Yara rule that detects Sage ransomware." author = "ReversingLabs" - id = "078f7f9d-edd4-52b4-a30e-e968542da95c" + id = "81f4c666-93f9-51bb-8dda-431ef7a81b74" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Blitzkrieg.yara#L1-L127" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "22dd16c886a1982186fe927e633be9951da7d7e664e877e11fa976696b2bc86f" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Sage.yara#L1-L77" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "69079b7176050096cdbaaaff30dd0359366b3a6a74e8bc17db348794388f71ba" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -37627,116 +38932,70 @@ rule REVERSINGLABS_Win32_Ransomware_Blitzkrieg : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Blitzkrieg" + tc_detection_name = "Sage" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files = { - 55 8B EC 83 C4 ?? 53 56 57 33 D2 89 55 ?? 89 55 ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? - 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? - ?? 64 FF 30 64 89 20 8B 45 ?? 8B 40 ?? 8B 10 FF 52 ?? 8B F0 4E 83 FE ?? 0F 8C ?? ?? - ?? ?? 8B 45 ?? 8B 48 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 A0 ?? ?? ?? ?? 88 - 43 ?? C6 43 ?? ?? 8D 4D ?? 8B 45 ?? 8B 40 ?? 8B D6 8B 38 FF 57 ?? 8B 55 ?? 8B C3 E8 - ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? 8B C3 E8 ?? ?? ?? ?? 8B D3 - 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 40 50 8D 45 ?? B9 ?? ?? ?? ?? 8B 15 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 4B ?? 89 0C - 82 4E 83 FE ?? 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 8B 45 ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 84 C0 74 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 - } - $search_files_p1 = { - E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 89 45 ?? B2 ?? A1 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? F6 40 ?? ?? 74 ?? FF 45 ?? 8B 45 ?? F6 40 - ?? ?? 74 ?? 83 45 ?? ?? 8B 45 ?? F6 40 ?? ?? 74 ?? 83 45 ?? ?? 8B 45 ?? F6 40 ?? ?? - 74 ?? 83 45 ?? ?? 8B 45 ?? F6 40 ?? ?? 74 ?? 83 45 ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 10 FF 52 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? - E8 ?? ?? ?? ?? 85 C0 7E ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 8B 52 ?? - 48 85 D2 74 ?? 3B 42 ?? 72 ?? E8 ?? ?? ?? ?? 40 80 7C 02 ?? ?? 74 ?? 8D 85 ?? ?? ?? - ?? 8B 55 ?? 8B 4D ?? 8B 49 ?? 4A 85 C9 74 ?? 3B 51 ?? 72 ?? E8 ?? ?? ?? ?? 42 8A 54 - 11 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? EB ?? 8B 55 ?? 8B 45 - ?? 8B 08 FF 51 ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 45 ?? FF 4D ?? 75 ?? 8B 45 ?? 8B 10 FF - 52 ?? 48 85 C0 0F 8C ?? ?? ?? ?? 40 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - 8B 55 ?? 8B 45 ?? 8B 18 FF 53 ?? 8B 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? - ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? 8B 8D ?? ?? ?? ?? 8B 55 - ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 - ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 85 C0 0F 8F ?? ?? ?? ?? 8B 55 ?? - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 8F ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? - ?? 84 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 8B 55 ?? B8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 85 C0 7F ?? 8B 45 ?? 8B 40 ?? 50 8B 4D ?? B2 ?? A1 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B D8 B2 ?? 8B C3 E8 ?? ?? ?? ?? 8B D3 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 - } - $search_files_p2 = { - E8 ?? ?? ?? ?? 40 50 8D 45 ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 85 D2 74 ?? 3B 42 ?? 72 ?? E8 ?? ?? ?? ?? 8B 4B - ?? 89 0C 82 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 8B - 45 ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 85 C0 79 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 - 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? - EB ?? FF 45 ?? FF 4D ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 80 78 ?? ?? 0F 84 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? - 64 FF 30 64 89 20 F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 85 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 8D 85 ?? ?? ?? ?? - 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? - 8B 48 ?? 8B 45 ?? E8 + $remote_connection = { + 83 EC ?? 8B 44 24 ?? 53 55 56 57 8B 7C 24 ?? 8B 77 ?? 50 E8 ?? ?? ?? ?? 8B 4C 24 ?? + 8B D8 51 89 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 89 44 24 + ?? C7 44 24 ?? ?? ?? ?? ?? 89 77 ?? FF 15 ?? ?? ?? ?? 8B E8 89 6C 24 ?? 85 ED 0F 84 + ?? ?? ?? ?? 8B 74 24 ?? 6A ?? 56 53 55 FF 15 ?? ?? ?? ?? 8B D8 89 5C 24 ?? 85 DB 0F + 84 ?? ?? ?? ?? 8B 4C 24 ?? 33 C0 BA ?? ?? ?? ?? 66 3B F2 0F 95 C0 48 25 ?? ?? ?? ?? + 50 6A ?? 6A ?? 6A ?? 51 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? + ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 1D ?? ?? ?? ?? 8B 2D ?? ?? ?? ?? 8B FF + 8D 54 24 ?? 52 56 FF D3 8D 44 24 ?? 50 8B 44 24 ?? 50 50 57 E8 ?? ?? ?? ?? 83 C4 ?? + 50 56 FF D5 85 C0 0F 84 ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 6A ?? 8D 4C 24 ?? 51 8D 54 + 24 ?? 52 6A ?? 68 ?? ?? ?? ?? 56 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 5C 24 ?? 8B 6C 24 ?? 56 FF 15 ?? ?? ?? ?? + 53 FF 15 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 8B 5C 24 ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? + 83 C4 ?? 8B 44 24 ?? 5F 5E 5D 5B 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 04 24 83 + C4 ?? C3 57 E8 ?? ?? ?? ?? 83 C4 } - $disable_services_p1 = { - E8 ?? ?? ?? ?? 8B F0 BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 - FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA - ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? - 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 - FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA - ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? - 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 - FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA - ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? - 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 - FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA - ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? - 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 - FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA - ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + $encrypt_files = { + 83 EC ?? 53 8B 1D ?? ?? ?? ?? 55 8B 6C 24 ?? 56 57 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 + ?? ?? ?? ?? 8D 7D ?? 57 FF D3 8B F0 83 FE ?? 74 ?? 8D 44 24 ?? 50 56 FF 15 ?? ?? ?? + ?? 89 44 24 ?? 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? 8B + 4C 24 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 51 FF D3 8B D8 83 FB ?? 75 ?? + 56 FF 15 ?? ?? ?? ?? 5F 5E 5D B8 ?? ?? ?? ?? 5B 83 C4 ?? C3 8B 54 24 ?? 6A ?? 52 57 + 56 53 E8 ?? ?? ?? ?? 83 C4 ?? 56 8B 35 ?? ?? ?? ?? 8B E8 FF D6 53 FF D6 85 ED 79 ?? + 8B 44 24 ?? 50 FF 15 ?? ?? ?? ?? 5F 5E 8B C5 5D 5B 83 C4 ?? C3 57 E8 ?? ?? ?? ?? 8B + F0 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 8B D8 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? + 6A ?? 53 51 EB ?? 8B 4C 24 ?? BA ?? ?? ?? ?? 3B 55 ?? 1B C0 83 C0 ?? 50 51 57 56 56 + E8 ?? ?? ?? ?? 83 C4 ?? 56 8B D8 FF 15 ?? ?? ?? ?? 85 DB 79 ?? 5F 5E 5D 8B C3 5B 83 + C4 ?? C3 57 E8 ?? ?? ?? ?? 8B F0 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8B + D8 53 57 FF 15 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5D 33 + C0 5B 83 C4 ?? C3 } - $disable_services_p2 = { - 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 - FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA - ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? - 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 - FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA - ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? - 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 - FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA - ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? - 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 - FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA - ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? 8B 55 ?? 8B C6 8B 08 FF 51 ?? 6A ?? 8B 45 ?? E8 ?? - ?? ?? ?? 8B D0 8D 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 33 C9 33 D2 E8 ?? ?? ?? ?? 33 C0 5A - 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $find_files = { + 53 55 8B 2D ?? ?? ?? ?? 56 57 33 FF 57 57 FF D5 8B F0 85 F6 74 ?? 85 FF 74 ?? 57 E8 + ?? ?? ?? ?? 83 C4 ?? 8D 44 36 ?? 50 6A ?? 8B DE E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 57 56 + FF D5 8B F0 3B DE 72 ?? 66 83 3F ?? 8B DF 0F 84 ?? ?? ?? ?? 8B 6C 24 ?? 53 8B FB FF + 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 8D 5C 43 ?? FF D6 85 C0 74 ?? 68 + ?? ?? ?? ?? 57 FF D6 85 C0 74 ?? 57 FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 D3 E2 F6 + C2 ?? 74 ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 57 8B F0 E8 ?? ?? ?? ?? 6A ?? 89 06 8D 46 ?? + 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4E ?? 51 C7 46 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 8D 56 ?? 52 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 55 89 46 ?? E8 ?? ?? ?? + ?? 83 C4 ?? 66 83 3B ?? 0F 85 ?? ?? ?? ?? 5F 5E 5D 5B C3 } condition: - uint16(0)==0x5A4D and (( all of ($disable_services_p*)) and ( all of ($search_files_p*)) and ($encrypt_files)) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($remote_connection) } -rule REVERSINGLABS_Win32_Ransomware_Teslarvng : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Revil : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Teslarvng ransomware." + description = "Yara rule that detects Revil ransomware." author = "ReversingLabs" - id = "7045b13e-95a5-54da-b540-75d464e7673d" - date = "2020-12-14" - modified = "2020-12-14" + id = "67c2f49e-b9dc-5900-a89d-49ba41088ac3" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Teslarvng.yara#L1-L137" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "670621aa196a80fbb694e4b1690d7da60e881c5b826133939e61cd6c2406ea98" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Revil.yara#L1-L101" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "24a79477eb797d7a7121d1248ebbece833ccd256de55729ff96084135ce8d426" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -37744,127 +39003,90 @@ rule REVERSINGLABS_Win32_Ransomware_Teslarvng : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Teslarvng" + tc_detection_name = "Revil" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_p1 = { - 53 8B DC 83 EC ?? 83 E4 ?? 83 C4 ?? 55 8B 6B ?? 89 6C 24 ?? 8B EC 6A ?? 68 ?? ?? ?? - ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? A8 ?? 00 00 A1 ?? ?? ?? ?? ?? ?? ?? ?? EC 56 57 50 - 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? C9 89 4D ?? 89 4D ?? 8B 73 ?? 8B 43 ?? 89 75 - ?? 89 45 ?? 3B F0 0F 84 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 06 8D 04 40 C1 E0 ?? 89 45 - ?? 8B 04 02 8B 40 ?? 8B 30 3B F0 0F 84 ?? ?? ?? ?? A1 ?? ?? ?? ?? ?? ?? ?? ?? 3D ?? - ?? ?? ?? 10 89 ?? ?? ?? ?? E3 ?? 00 0F 43 05 ?? ?? ?? ?? 89 45 ?? C6 45 ?? ?? 33 C0 - 83 C9 ?? 66 89 45 ?? 89 4D ?? 8D 4D ?? 8B 47 ?? 40 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7F ?? ?? 8B - C7 72 ?? 8B 07 FF 77 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? 8D 95 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 C9 68 ?? ?? ?? ?? 0F 10 00 0F 11 85 - ?? ?? ?? ?? F3 0F 7E 40 ?? 83 4D ?? ?? 66 0F D6 45 ?? 66 89 08 8D 8D ?? ?? ?? ?? C7 - 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 85 ?? - ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 6A ?? 0F 43 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? - 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 74 ?? 6A ?? 8D 4D ?? 51 - } - $encrypt_files_p2 = { - FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? - ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 65 ?? ?? C6 45 ?? ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 65 ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? - 8B 41 ?? 89 45 ?? 83 78 ?? ?? 8B 48 ?? 89 4D ?? 72 ?? 8B 00 89 45 ?? C6 45 ?? ?? 33 - C0 83 4D ?? ?? 8D 4D ?? 66 89 45 ?? 8B 47 ?? 40 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? 50 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7F ?? ?? 8B 47 - ?? 72 ?? 8B 3F 50 57 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? - 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 6A ?? 0F 43 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A - ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 74 ?? 6A ?? 8D 45 - ?? 50 FF 75 ?? FF 75 ?? 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? - ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 65 ?? ?? C6 45 ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 45 ?? 8B 36 8B 4D ?? 8B 04 02 3B 70 ?? 0F 85 ?? ?? - ?? ?? 8B 75 ?? 83 C6 ?? 89 75 ?? 3B 75 ?? 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D - 4B ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? - ?? ?? 8B E5 5D 8B E3 5B C2 - } - $find_files = { - FF D6 83 F8 ?? 0F 85 ?? ?? ?? ?? 8D 43 ?? 50 BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 83 78 ?? ?? 72 ?? 8B 00 B2 ?? 8B C8 E8 ?? ?? ?? ?? C6 - 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 - ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 0F 1F 40 ?? 8D 85 ?? ?? ?? ?? 50 - FF B5 ?? ?? ?? ?? 33 C9 8B 85 ?? ?? ?? ?? 03 8D ?? ?? ?? ?? 83 D0 ?? 50 51 FF B5 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? - ?? ?? ?? BA ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B C8 90 66 8B 31 66 3B 32 75 ?? 66 85 F6 - 74 ?? 66 8B 71 ?? 66 3B 72 ?? 75 ?? 83 C1 ?? 83 C2 ?? 66 85 F6 75 ?? 33 C9 EB ?? 1B - C9 83 C9 ?? 85 C9 74 ?? B9 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B - 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? - 85 C0 74 ?? 8B 45 ?? 8D 8D ?? ?? ?? ?? 51 3B 45 ?? 74 ?? 8B C8 E8 ?? ?? ?? ?? 83 45 - ?? ?? EB ?? 50 8D 4D ?? E8 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? FF B5 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 C4 ?? 85 F6 0F 85 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? FF D6 83 F8 ?? 0F - 84 ?? ?? ?? ?? FF D6 8B D0 + $search_files = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 8B 75 ?? 33 C0 57 8B 7D ?? 8B D8 50 56 89 45 ?? 89 + 5D ?? 89 45 ?? 89 45 ?? FF 57 ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 56 50 E8 ?? + ?? ?? ?? 53 56 FF 77 ?? FF 57 ?? 83 C4 ?? 01 47 ?? 11 57 ?? E9 ?? ?? ?? ?? 8B 45 ?? + 0B 45 ?? 74 ?? FF 33 56 E8 ?? ?? ?? ?? 8B F3 8B 5B ?? 89 5D ?? FF 36 E8 ?? ?? ?? ?? + 56 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 4D ?? 83 C0 ?? 89 45 ?? 83 D1 ?? 0B C1 89 4D + ?? 75 ?? 21 45 ?? 8B 75 ?? 33 C0 40 85 C0 0F 84 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? C7 04 + 24 ?? ?? ?? ?? 56 89 45 ?? E8 ?? ?? ?? ?? 59 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? + ?? ?? 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? F7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 8D 04 46 50 E8 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 59 59 + 74 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 57 ?? 83 C4 ?? 85 + C0 74 ?? 8D 45 ?? 56 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 77 ?? FF 57 ?? 83 + C4 ?? 01 47 ?? 11 57 ?? EB ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 50 89 45 ?? 8D 85 + ?? ?? ?? ?? 53 50 56 FF 57 ?? 83 C4 ?? 85 C0 74 ?? FF 75 ?? 8D 85 ?? ?? ?? ?? 53 50 + 56 FF 77 ?? FF 57 ?? 83 C4 ?? 01 47 ?? 11 57 ?? 83 3F ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 + FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 5D + ?? 83 3F ?? 0F 84 ?? ?? ?? ?? EB ?? 8B F3 8B 5B ?? FF 36 E8 ?? ?? ?? ?? 56 E8 ?? ?? + ?? ?? 59 59 85 DB 75 ?? 5F 5E 5B 8B E5 5D C3 } - $enum_shares_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? 00 00 00 A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? 45 FC 00 00 00 00 8D - 75 ?? 83 7D ?? ?? 6A ?? 0F 43 75 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 B8 ?? ?? ?? - ?? 56 66 89 45 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 89 45 ?? FF 15 ?? ?? ?? ?? 66 89 - 45 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 57 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 8D - 45 ?? 50 57 FF 15 ?? ?? ?? ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 45 ?? 89 7D ?? 50 - 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 6A ?? 6A ?? 89 7D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 8E ?? ?? ?? ?? 83 7D ?? ?? 0F 87 ?? ?? ?? ?? - 83 7D ?? ?? 0F 86 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 8B 75 ?? 0F - 43 4D ?? 03 F1 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 0F 43 - 4D ?? 33 C0 66 89 45 ?? 8B C6 2B C1 89 4D ?? 50 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? FF 75 ?? 8D 4D ?? 56 FF 75 ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 83 7D ?? - ?? 8D 45 ?? 6A ?? 0F 43 45 ?? 51 8D 4D ?? 51 6A ?? 8D 4D ?? 51 6A ?? 50 FF 15 ?? ?? - ?? ?? 85 C0 74 ?? 3D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 0F 57 C0 C7 45 ?? ?? ?? ?? ?? 66 + $remote_connection = { + 55 8B EC 81 EC ?? ?? ?? ?? 56 57 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? + ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 33 C0 66 89 85 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 56 56 56 56 50 FF 15 ?? ?? ?? ?? 8B F8 33 C0 89 7D ?? 85 FF 0F 84 ?? ?? + ?? ?? 66 89 45 ?? 33 C9 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 56 56 FF 75 ?? 41 89 75 ?? + 89 75 ?? 89 75 ?? 89 75 ?? 89 4D ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 + 4D ?? 89 75 ?? 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 57 FF 15 ?? ?? ?? ?? 33 C0 E9 + ?? ?? ?? ?? 8B 4D ?? 33 D2 8B 45 ?? 53 56 66 89 14 41 FF 75 ?? FF 75 ?? 57 FF 15 ?? + ?? ?? ?? 8B D8 89 5D ?? 85 DB 75 ?? 57 EB ?? 8B 45 ?? 66 39 30 75 ?? 6A ?? 59 66 89 + 08 8D 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 + C0 83 7D ?? ?? B9 ?? ?? ?? ?? 66 89 45 ?? 0F 44 C1 0D ?? ?? ?? ?? 50 56 56 56 FF 75 + ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 8B D8 85 DB 75 ?? 57 FF 15 ?? ?? ?? ?? FF 75 ?? + FF 15 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B FE 50 6A ?? 6A ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 45 ?? 56 FF 75 ?? 8D 85 + ?? ?? ?? ?? FF 75 ?? FF 75 ?? 6A ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? ?? + ?? 3D ?? ?? ?? ?? 75 ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 6A ?? 53 FF 15 ?? ?? + ?? ?? 85 C0 6A ?? 58 0F 45 F8 85 FF 75 ?? 8B 45 ?? 56 53 89 30 FF 15 ?? ?? ?? ?? 8B + 7D ?? 85 C0 74 ?? 56 8D 45 ?? 89 75 ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 56 68 ?? + ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 4D ?? F7 D8 1B C0 23 45 ?? 89 01 3D ?? ?? ?? ?? 75 + ?? FF 75 ?? 53 E8 ?? ?? ?? ?? 59 59 8B F0 57 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? + ?? ?? 53 FF 15 ?? ?? ?? ?? 8B C6 5B 5F 5E 8B E5 5D C3 } - $enum_shares_p2 = { - 0F D6 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? - ?? 33 F6 8B 55 ?? 85 D2 0F 84 ?? ?? ?? ?? 33 FF 8B 4D ?? 8B 44 39 ?? 85 C0 74 ?? 3D - ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 14 39 33 C0 66 89 45 ?? 8B C2 C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 48 ?? C7 45 ?? ?? ?? ?? ?? 89 4D ?? 66 - 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B 45 ?? 8D 4D ?? D1 F8 50 52 E8 ?? ?? ?? ?? C6 45 ?? - ?? 8B 45 ?? 3B 45 ?? 74 ?? 0F 10 45 ?? C7 40 ?? ?? ?? ?? ?? 0F 11 00 F3 0F 7E 45 ?? - 66 0F D6 40 ?? 33 C0 83 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 - ?? EB ?? 8D 4D ?? 51 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? - 8B 55 ?? 46 83 C7 ?? 3B F2 0F 82 ?? ?? ?? ?? 8B 45 ?? 8B 75 ?? 3B 45 ?? 0F 84 ?? ?? - ?? ?? FF 76 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 46 ?? 83 7D ?? ?? - 8B 7D ?? 89 45 ?? 8D 45 ?? 0F 43 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? 89 45 ?? 83 FF ?? 73 ?? 0F 10 00 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 11 - 85 ?? ?? ?? ?? EB ?? 8B F7 8D 8D ?? ?? ?? ?? B8 ?? ?? ?? ?? 83 CE ?? 3B F0 0F 47 F0 + $encrypt_files = { + 55 8B EC 51 83 7D ?? ?? 53 56 57 BB ?? ?? ?? ?? 7F ?? 7C ?? 39 5D ?? 73 ?? 8B 5D ?? + 8B 7D ?? 8D 83 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 59 59 EB ?? E8 ?? ?? ?? ?? 83 F8 ?? + 75 ?? 6A ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 85 + F6 74 ?? 89 9E ?? ?? ?? ?? 8B 5D ?? C7 45 ?? ?? ?? ?? ?? EB ?? 33 C0 EB ?? E8 ?? ?? + ?? ?? 8B 55 ?? 8B CA 4A 89 55 ?? 85 C9 74 ?? 83 F8 ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 83 + F8 ?? 74 ?? A8 ?? 74 ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? FF 75 ?? FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 56 E8 ?? + ?? ?? ?? 8B C6 59 5F 5E 5B 8B E5 5D C3 56 57 E8 ?? ?? ?? ?? 59 33 C0 EB } - $enum_shares_p3 = { - 8D 46 ?? 50 E8 ?? ?? ?? ?? 8D 0C 7D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 51 FF 75 ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 89 B5 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 8B 7D - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? - 3B F8 0F 84 ?? ?? ?? ?? 2B C7 C1 F8 ?? 69 F0 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 89 85 ?? - ?? ?? ?? 8D 0C 76 89 45 ?? 8D 04 C8 89 45 ?? 8D 85 ?? ?? ?? ?? 89 45 ?? C6 45 ?? ?? - 0F 57 C0 8B B5 ?? ?? ?? ?? 66 0F D6 45 ?? C7 45 ?? ?? ?? ?? ?? 89 75 ?? 89 75 ?? 89 - 45 ?? C6 45 ?? ?? 66 90 57 8B CE E8 ?? ?? ?? ?? 83 C6 ?? 83 C7 ?? 89 75 ?? 3B 7D ?? - 75 ?? 89 75 ?? C6 45 ?? ?? 89 75 ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8D - 85 ?? ?? ?? ?? 8B 4D ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 75 ?? FF 76 ?? E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? EB ?? - 8B 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 06 F0 FF 08 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? EB ?? 57 FF 15 ?? ?? ?? ?? 8B 75 + $enum_resources = { + 55 8B EC 83 EC ?? 8D 45 ?? 50 FF 75 ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 + ?? 33 C0 E9 ?? ?? ?? ?? 83 4D ?? ?? B8 ?? ?? ?? ?? 57 50 89 45 ?? E8 ?? ?? ?? ?? 8B + F8 59 85 FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 33 C0 EB ?? 53 56 8D 45 ?? 50 57 8D 45 + ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 75 ?? 33 DB 39 5D ?? 76 ?? 8D 77 ?? + 83 7E ?? ?? 75 ?? FF 75 ?? FF 36 E8 ?? ?? ?? ?? 59 59 F6 46 ?? ?? 74 ?? 8D 46 ?? 50 + FF 75 ?? E8 ?? ?? ?? ?? 59 59 43 83 C6 ?? 3B 5D ?? 72 ?? 8B 45 ?? 3D ?? ?? ?? ?? 75 + ?? 57 E8 ?? ?? ?? ?? 59 FF 75 ?? FF 15 ?? ?? ?? ?? F7 D8 5E 1B C0 40 5B 5F 8B E5 5D + C3 } condition: - uint16(0)==0x5A4D and ( all of ($enum_shares_p*)) and ($find_files) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($enum_resources) and ($search_files) and ($encrypt_files) and ($remote_connection) } -rule REVERSINGLABS_Win32_Ransomware_Lorenz : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Crypren : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Lorenz ransomware." + description = "Yara rule that detects Crypren ransomware." author = "ReversingLabs" - id = "cc97dd15-d518-5d9f-9384-3dcf81e34e81" - date = "2022-10-24" - modified = "2022-10-24" + id = "9a6ff190-b26b-5b75-9103-95a3b2e80701" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Lorenz.yara#L1-L252" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "b8668fcc560d264c37e3fbb52d5a5f1223a282abd9e984b3109efe9ab454be9f" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Crypren.yara#L1-L144" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "7047d48782762e42544063fde6f2be62eb19f22853ea84abb5bce67c962da172" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -37872,211 +39094,228 @@ rule REVERSINGLABS_Win32_Ransomware_Lorenz : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Lorenz" + tc_detection_name = "Crypren" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_v1_p1 = { - BE ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? A5 6A ?? 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? - ?? ?? A5 A5 A4 8B 35 ?? ?? ?? ?? FF D6 89 85 ?? ?? ?? ?? 33 C0 50 68 ?? ?? ?? ?? 6A - ?? 50 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D6 68 ?? ?? ?? ?? 6A ?? 6A ?? 89 85 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 85 C0 75 - ?? FF D6 8B 3D ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? FF D7 EB ?? 8B 3D ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 - C0 75 ?? FF D6 6A ?? FF B5 ?? ?? ?? ?? FF D7 6A ?? 6A ?? 53 FF B5 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 85 C0 75 ?? FF D6 8D 85 ?? ?? ?? ?? 33 DB 50 53 FF B5 ?? ?? ?? ?? 68 ?? - ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF D6 53 FF B5 ?? ?? ?? ?? - FF D7 6A ?? 8D 45 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? - ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 53 8B 9D ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B - 0D ?? ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 89 4D ?? 66 8B 0D ?? ?? ?? ?? 66 89 4D ?? 8D 4D - ?? 89 85 ?? ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 6A ?? 50 2B CA 8D 45 ?? 51 50 56 FF 15 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 68 - ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 33 C0 50 50 - } - $encrypt_files_v1_p2 = { - 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 D2 42 3B C2 75 ?? 83 BD ?? ?? ?? ?? ?? - 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 33 D2 42 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 03 8D - ?? ?? ?? ?? 3B 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 6A ?? 89 8D ?? ?? ?? ?? 0F 44 C2 8D - 8D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 51 8D 4D ?? 51 6A ?? 50 6A ?? FF B5 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 85 C0 74 ?? 83 A5 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF B5 ?? - ?? ?? ?? 8D 45 ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8D 45 ?? 6A ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? - 85 C0 0F 85 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? FF D7 FF B5 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 53 FF D6 8B 85 ?? ?? ?? - ?? 50 FF D6 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F - 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 - } - $find_files_v1_p1 = { - FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 6A ?? 0F 57 C0 C6 45 - ?? ?? 6A ?? 6A ?? 0F 11 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 - C0 74 ?? 89 18 89 58 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 08 8B 3D ?? ?? ?? ?? - 8B B5 ?? ?? ?? ?? C6 45 ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F - 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF - D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 - C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 8D + $enum_directories_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 + 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 + 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 } - $find_files_v1_p2 = { - 8B 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 56 8B D0 C6 45 ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? 59 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 75 ?? 68 ?? ?? ?? - ?? 0F 43 75 ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 56 50 89 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B B5 ?? ?? ?? ?? 83 C4 ?? F6 85 ?? ?? ?? ?? ?? 75 ?? 56 8D 4D ?? E8 ?? ?? ?? - ?? 8D 45 ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 56 E8 - ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 59 74 ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 7D ?? ?? 8D 75 ?? 68 ?? ?? ?? ?? 0F 43 75 ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? - ?? 56 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8D 4D ?? E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 - B8 ?? ?? ?? ?? C3 C7 45 ?? ?? ?? ?? ?? 33 DB 8B 85 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 89 - 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F - 85 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8D 8D + $enum_directories_p2 = { + 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 + 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 85 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 } - $create_scheduled_task_v1 = { - FF 15 ?? ?? ?? ?? 33 FF 85 C0 74 ?? 8B CF 8A 84 0D ?? ?? ?? ?? 88 84 0D ?? ?? ?? ?? - 41 84 C0 75 ?? 8D BD ?? ?? ?? ?? 4F 8A 47 ?? 47 84 C0 75 ?? BE ?? ?? ?? ?? A5 A5 66 - A5 33 FF 57 68 ?? ?? ?? ?? 6A ?? 57 57 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 8B 4B ?? 8B F0 89 BD ?? ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8D 85 ?? - ?? ?? ?? 2B CA 50 51 FF 73 ?? 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 83 C4 ?? 8B - F2 8A 02 42 84 C0 75 ?? 8D BD ?? ?? ?? ?? 2B D6 4F 8A 47 ?? 47 84 C0 75 ?? 8B CA C1 - E9 ?? F3 A5 8B CA 83 E1 ?? F3 A4 8D 8D ?? ?? ?? ?? 49 8A 41 ?? 41 84 C0 75 ?? 66 A1 - ?? ?? ?? ?? 33 DB 8B 35 ?? ?? ?? ?? BF ?? ?? ?? ?? 66 89 01 A0 ?? ?? ?? ?? 53 53 88 - 41 ?? 8D 85 ?? ?? ?? ?? 50 57 53 53 FF D6 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 53 53 68 - ?? ?? ?? ?? 57 53 53 FF D6 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + $enum_directories_p3 = { + 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 + ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D BD ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? 90 83 7F ?? ?? 8B 5F ?? 72 ?? 8B 37 EB ?? 8B F7 83 7D ?? ?? 8D + 45 ?? 8B D3 0F 43 45 ?? 3B CB 0F 42 D1 85 D2 74 ?? 83 EA ?? 72 ?? 8D 9B ?? ?? ?? ?? + 8B 08 3B 0E 75 ?? 83 C0 ?? 83 C6 ?? 83 EA ?? 73 ?? 83 FA ?? 74 ?? 8A 08 3A 0E 75 ?? + 83 FA ?? 74 ?? 8A 48 ?? 3A 4E ?? 75 ?? 83 FA ?? 74 ?? 8A 48 ?? 3A 4E ?? 75 ?? 83 FA + ?? 74 ?? 8A 40 ?? 3A 46 ?? 74 ?? 1B C0 83 C8 ?? EB ?? 33 C0 8B 4D ?? 85 C0 75 ?? 3B + CB 73 ?? 83 C8 ?? EB ?? 33 C0 3B CB 0F 95 C0 85 C0 0F 94 C0 84 C0 75 ?? 8B 85 ?? ?? + ?? ?? 83 C7 ?? 40 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 82 ?? ?? ?? ?? B3 ?? EB ?? 32 DB 68 + ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? + 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8A C3 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E + 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } - $remote_connection_v1 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 8B - 5D ?? 8D 44 24 ?? 56 57 8B 7D ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A - ?? 6A ?? 6A ?? 58 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 74 ?? 6A ?? 58 53 66 89 44 24 - ?? FF 15 ?? ?? ?? ?? FF 75 ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? 66 89 44 24 ?? 8D 44 24 - ?? 6A ?? 50 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 8B CF 8D 51 ?? 8A 01 41 84 C0 75 ?? - 6A ?? 2B CA 51 57 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 33 C0 8B 8C 24 ?? ?? ?? ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D C2 + $encrypt_files_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 33 FF C6 45 ?? ?? 83 7D ?? ?? 8D 45 ?? 6A + ?? 0F 43 45 ?? 8D 8D ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 6A ?? + 0F 43 45 ?? 8D 8D ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8B + 94 0D ?? ?? ?? ?? 85 D2 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? 39 BC 05 ?? ?? + ?? ?? 0F 85 ?? ?? ?? ?? F6 C2 ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 03 C8 8D 45 ?? + 50 E8 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? C6 45 ?? ?? 8B F0 + 85 C9 74 ?? 8B 11 FF 52 ?? 85 C0 74 ?? 8B 10 8B C8 6A ?? FF 12 8B 06 8B CE 6A ?? 8B + 40 ?? FF D0 88 45 ?? 8D 45 ?? FF 75 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 4D ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 39 75 ?? 76 ?? EB ?? 8D A4 24 + ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 8D 4D ?? 0F 43 45 ?? 83 7D ?? ?? 0F 43 4D ?? 33 D2 } - $check_mutex_v1 = { - E8 ?? ?? ?? ?? 59 59 56 C6 45 ?? ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 50 FF B5 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 7D ?? ?? 7E ?? 8B 57 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 59 FF 77 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B C8 C6 45 ?? ?? E8 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 50 56 FF D3 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? - 56 FF 15 ?? ?? ?? ?? 8B F8 FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 94 C0 85 FF 74 ?? 84 - C0 74 ?? 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 56 + $encrypt_files_p2 = { + 0F BE 1C 30 8B C7 F7 75 ?? 8A 0C 0A 0F BE C1 03 C3 3D ?? ?? ?? ?? 7C ?? 25 ?? ?? ?? + ?? 79 ?? 48 0D ?? ?? ?? ?? 40 EB ?? 02 D9 0F B6 C3 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 46 83 C4 ?? 47 3B 75 ?? 72 ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 8B 48 ?? F6 84 0D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? + ?? ?? 83 C4 ?? 83 7D ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 72 + ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D + ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C6 45 ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D + ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } - $find_files_v2 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? 00 00 00 00 83 EC ?? 53 - 56 57 89 65 ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 - ?? ?? 8D 4D ?? 54 E8 ?? ?? ?? ?? 83 EC ?? 8D 4D ?? 54 E8 ?? ?? ?? ?? 83 EC ?? 8D 4D - ?? 54 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? E8 ?? - ?? ?? ?? 83 EC ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? - 3B 45 ?? 0F 87 ?? ?? ?? ?? 83 EC ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? - 51 50 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B F0 8D 45 ?? 3B C6 74 ?? 8B 45 ?? 83 F8 - ?? 72 ?? 6A ?? 40 50 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 56 - 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B - 7D ?? 33 F6 8B 5D ?? 83 FE ?? 73 ?? 8B 0C B5 ?? ?? ?? ?? 8D 45 ?? 83 FF ?? 0F 43 C3 - 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 - ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 74 ?? 46 EB ?? 8D 4D ?? E8 ?? ?? - ?? ?? B0 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C2 ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? 8B 4D ?? 32 C0 5F 5E 64 89 0D ?? ?? ?? ?? 5B 8B E5 5D C2 ?? ?? 8D 45 + $enum_drives_p1 = { + 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 } - $encrypt_files_v2_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? 00 00 00 00 51 B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 53 56 57 C7 45 ?? ?? ?? ?? ?? 8B F1 8B 7D ?? 8D 4D ?? 89 65 ?? - 57 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 8B CE 50 E8 - ?? ?? ?? ?? 8B D8 C6 45 ?? ?? 8D 4D ?? 89 5D ?? E8 ?? ?? ?? ?? 8B 75 ?? 56 E8 ?? ?? - ?? ?? 83 C4 ?? 56 53 50 E8 ?? ?? ?? ?? 8B 75 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 - 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 83 C4 ?? 49 0F 1F 40 ?? 8A 41 ?? 8D 49 ?? 84 C0 - 75 ?? A1 ?? ?? ?? ?? ?? ?? ?? ?? 00 00 08 89 ?? ?? ?? ?? 4E 00 6A ?? 6A ?? 89 41 ?? - A1 ?? ?? ?? ?? ?? ?? ?? ?? 08 A0 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? 88 - 41 ?? FF D6 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 89 45 ?? 8D 85 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 50 FF D6 68 ?? ?? ?? ?? 6A ?? 6A ?? 89 45 ?? 8D 45 ?? 6A ?? 50 FF 15 ?? ?? - ?? ?? 8B 35 ?? ?? ?? ?? 85 C0 75 ?? FF D6 8B 1D ?? ?? ?? ?? 6A ?? FF 75 ?? FF D3 EB - ?? 8B 1D ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? - ?? 85 C0 75 ?? FF D6 6A ?? FF 75 ?? FF D3 6A ?? 6A ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? - 85 C0 75 ?? FF D6 8D 45 ?? 50 6A ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? - ?? 85 C0 75 ?? FF D6 6A ?? FF 75 ?? FF D3 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 + $enum_drives_p2 = { + E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 + 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D + 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 + ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 } - $encrypt_files_v2_p2 = { - E8 ?? ?? ?? ?? 8B 7D ?? 83 C4 ?? 33 F6 C7 45 ?? ?? ?? ?? ?? 33 DB 89 5D ?? 56 57 FF - 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 4D ?? 66 8B 0D ?? ?? 4E 00 66 89 4D ?? 8D 4D ?? - 89 45 ?? 8D 51 ?? 89 5D ?? 8A 01 41 84 C0 75 ?? 6A ?? 8D 45 ?? 2B CA 50 51 8D 45 ?? - 50 FF 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? FF 75 ?? FF 75 ?? FF - 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? - ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 66 0F 1F 44 00 ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 03 - F0 33 C9 3B 75 ?? 75 ?? 85 C9 75 ?? 33 DB 83 F8 ?? 0F 95 C3 68 ?? ?? ?? ?? 8D 45 ?? - 50 8D 85 ?? ?? ?? ?? 50 6A ?? 53 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? - 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF 75 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? - ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 8D 45 ?? 6A ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F - 85 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? - FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 57 FF D6 FF 75 ?? FF D6 8B 4D ?? 5F 5E 64 89 0D - ?? ?? ?? ?? 5B 8B E5 5D C2 ?? ?? 8D 45 + + condition: + uint16(0)==0x5A4D and (( all of ($enum_directories_p*)) and ( all of ($enum_drives_p*)) and ( all of ($encrypt_files_p*))) +} +rule REVERSINGLABS_Win32_Ransomware_Ransomplus : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects RansomPlus ransomware." + author = "ReversingLabs" + id = "ee96eab6-104d-560f-adae-6d5f0ba5d469" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.RansomPlus.yara#L1-L95" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "8ab18c6bcb939eac0e74f015dea773141b5086c5fcb4783666eeac1f395bc208" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "RansomPlus" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files_1_0 = { + 55 8B EC 83 E4 ?? 83 EC ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 EC ?? + 8B CC 6A ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? C6 01 ?? E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B CC 6A ?? 68 ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? + ?? ?? ?? C6 01 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CC 6A ?? 68 ?? ?? ?? ?? C7 41 ?? + ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C6 01 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CC 6A ?? + 68 ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C6 01 ?? E8 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 8B E5 5D C2 } - $remote_connection_v2 = { - 55 8B EC 51 53 56 57 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 56 - FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D8 6A ?? - 53 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B F8 6A ?? 57 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? - 8D 45 ?? 50 57 FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 53 FF D6 57 FF D6 5F 5E - 33 C0 5B 8B E5 5D C3 + $find_files_1_1 = { + 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 72 ?? 8B 00 8D 8D ?? ?? ?? ?? 51 50 FF 15 ?? + ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 F9 ?? 72 ?? 8B 95 ?? ?? ?? ?? + 41 81 F9 ?? ?? ?? ?? 72 ?? F6 C2 ?? 74 ?? E8 ?? ?? ?? ?? 8B 42 ?? 3B C2 72 ?? E8 ?? + ?? ?? ?? 2B D0 83 FA ?? 73 ?? E8 ?? ?? ?? ?? 83 FA ?? 76 ?? E8 ?? ?? ?? ?? 8B D0 52 + E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C6 85 ?? ?? ?? ?? ?? 83 FB ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 32 DB E9 ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? C6 45 ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? + ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 } - $drop_ransom_note_v2_p1 = { - 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 89 45 ?? - C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 6A ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 85 C0 74 ?? C7 00 ?? ?? ?? ?? C7 - 40 ?? ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 89 08 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? ?? ?? ?? ?? 87 FB 00 00 00 A0 ?? ?? - ?? ?? 88 87 ?? ?? ?? ?? 8B F7 8D 4E ?? 0F 1F 40 ?? 8A 06 46 84 C0 75 ?? 2B F1 8D 46 - ?? 50 E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 DB 74 ?? 56 57 53 E8 ?? ?? ?? ?? 6A ?? 8D 04 - 33 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F3 8D 4E ?? 0F 1F 44 00 ?? 8A 06 46 - 84 C0 75 ?? 2B F1 8D 86 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 56 - 53 57 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 04 37 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 8B F7 8D 4E ?? 8A 06 46 84 C0 75 ?? 2B F1 8D 86 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B - D8 83 C4 ?? 85 DB 74 ?? 56 57 53 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 04 33 68 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F3 8D 4E ?? 8A 06 46 84 C0 75 ?? 2B F1 8D 46 ?? 50 + $find_files_1_2 = { + 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? + 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? + 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 75 ?? 33 C9 EB + ?? 8D 8D ?? ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 51 8D 85 ?? ?? ?? ?? 50 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 55 ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 EC ?? + 8B CC C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 83 79 ?? ?? 72 ?? 8B 01 EB ?? 8B C1 + 6A ?? C6 00 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 + 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 75 ?? 33 C9 EB ?? 8D 8D + ?? ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 51 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? 8B 95 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 83 FE ?? 0F 43 C2 0F 43 CA 89 85 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 03 C1 83 FE ?? 8B F8 0F 43 DA 33 C9 2B FB 33 F6 3B D8 0F 47 F9 85 + FF 74 ?? 0F BE 04 33 50 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 C4 ?? 88 04 31 46 3B F7 + 75 ?? 33 C0 89 85 ?? ?? ?? ?? 8B 94 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 80 3A ?? 75 ?? 33 C9 EB ?? 8B CA 8D + 71 ?? 8A 01 41 84 C0 75 ?? 2B CE 51 52 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? + 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 F9 ?? 0F + 43 C2 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 C2 03 85 ?? ?? ?? ?? 83 F9 ?? 8B F8 + 0F 43 DA 33 F6 2B FB 3B D8 0F 47 FE 85 FF 74 } - $drop_ransom_note_v2_p2 = { - E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 56 53 57 E8 ?? ?? ?? ?? 6A ?? 8D 04 37 68 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F7 8D 4E ?? 0F 1F 00 8A 06 46 84 C0 75 ?? - 2B F1 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 DB 74 ?? 56 57 53 E8 ?? ?? ?? ?? - F3 0F 7E 05 ?? ?? ?? ?? 83 C4 ?? 66 0F D6 04 33 8B F3 8D 4E ?? 8A 06 46 84 C0 75 ?? - 2B F1 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 56 53 57 E8 ?? ?? ?? ?? - 6A ?? 8D 04 37 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F7 8D 4E ?? 8A 06 46 84 - C0 75 ?? 2B F1 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 DB 74 ?? 56 57 53 E8 ?? - ?? ?? ?? 6A ?? 8D 04 33 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F3 8D 4E ?? 66 - 90 8A 06 46 84 C0 75 ?? 2B F1 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? - 56 53 57 E8 ?? ?? ?? ?? 6A ?? 8D 04 37 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B - CF 5B 8D 51 ?? 0F 1F 40 ?? 8A 01 41 84 C0 75 ?? 8B 75 ?? 8D 45 ?? 6A ?? 50 2B CA 51 - 57 56 FF 15 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 56 FF 15 ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? 8B 4D ?? 5F 5E 64 89 0D ?? ?? ?? ?? 8B E5 5D C2 + $encrypt_files = { + 8A 01 41 84 C0 75 ?? 2B CA C6 85 ?? ?? ?? ?? ?? 33 C0 88 84 05 ?? ?? ?? ?? 40 3D ?? + ?? ?? ?? 72 ?? 33 F6 8B C6 33 D2 F7 F1 8A 04 3A 02 C1 30 84 35 ?? ?? ?? ?? 46 81 FE + ?? ?? ?? ?? 72 ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 55 ?? 8B F8 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B + D8 85 FF 74 ?? 85 DB 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 57 68 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 8B F0 8D 85 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 53 56 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 57 E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? + 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? 83 F8 + ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B + 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? + E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D + ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? + 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? + ?? ?? 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 F8 + ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B + C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? + ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B + 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ((( all of ($encrypt_files_v1_p*)) and ( all of ($find_files_v1_p*)) and ($create_scheduled_task_v1) and ($remote_connection_v1) and ($check_mutex_v1)) or (($find_files_v2) and ( all of ($encrypt_files_v2_p*)) and ($remote_connection_v2) and ( all of ($drop_ransom_note_v2_p*)))) + uint16(0)==0x5A4D and $find_files_1_0 and $find_files_1_1 and $find_files_1_2 and $encrypt_files } -rule REVERSINGLABS_Linux_Ransomware_Killdisk : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_FLKR : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects KillDisk ransomware." + description = "Yara rule that detects FLKR ransomware." author = "ReversingLabs" - id = "af6652dd-c668-5ae1-b51b-e272cb440c20" + id = "7f3abcd0-8dfa-5914-9ad0-566c16c2e2ab" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Linux.Ransomware.KillDisk.yara#L1-L144" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3ed1fb2b7b24cd4d5100d93ed53a9ab28e1482bd0998a0538d8710a962ee839f" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.FLKR.yara#L1-L71" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "4ab00ba82baceec9899556d3a774ec08c83c10930cec194e18e3b4e16ebacb58" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -38084,138 +39323,73 @@ rule REVERSINGLABS_Linux_Ransomware_Killdisk : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "KillDisk" + tc_detection_name = "FLKR" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_1 = { - 55 48 89 E5 48 81 EC ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 64 48 8B 04 25 ?? ?? ?? ?? 48 - 89 45 ?? 31 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8B 85 - ?? ?? ?? ?? 48 89 D6 48 89 C7 E8 ?? ?? ?? ?? 85 C0 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? - ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? - ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 C7 - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 05 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 85 C0 79 ?? 48 8B - 85 ?? ?? ?? ?? 48 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 85 ?? ?? - ?? ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 78 ?? 48 8B 85 ?? ?? ?? ?? BE ?? - ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 05 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? - 85 C0 79 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 45 ?? 48 8D 90 ?? ?? ?? ?? 48 85 C0 - 48 0F 48 C2 48 C1 F8 ?? 48 89 85 ?? ?? ?? ?? 48 8B 45 ?? 48 85 C0 7E ?? 48 83 BD ?? - ?? ?? ?? ?? 7F ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? - ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? 48 - 83 BD ?? ?? ?? ?? ?? 7F ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? - ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C2 48 C1 - } - $encrypt_files_2 = { - EA ?? 48 01 D0 48 D1 F8 48 C1 E0 ?? 48 89 C1 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 - CE 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? - ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 8E ?? ?? ?? - ?? 48 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 BA ?? - ?? ?? ?? ?? ?? ?? ?? 48 89 C8 48 F7 EA 48 8D 04 0A 48 C1 F8 ?? 48 89 C2 48 89 C8 48 - C1 F8 ?? 48 29 C2 48 89 D0 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B - 85 ?? ?? ?? ?? C1 E0 ?? 48 63 C8 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 CE 89 C7 E8 - ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 - ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 3B 85 ?? ?? ?? ?? 7C ?? 48 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? - 48 8B 8D ?? ?? ?? ?? 48 BA ?? ?? ?? ?? ?? ?? ?? ?? 48 89 C8 48 F7 EA 48 8D 04 0A 48 - C1 F8 ?? 48 89 C2 48 89 C8 48 C1 F8 ?? 48 29 C2 48 89 D0 89 85 ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? C1 E0 ?? 48 63 C8 8B 85 ?? ?? ?? ?? BA - ?? ?? ?? ?? 48 89 CE 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? - ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? EB ?? 83 85 ?? ?? ?? ?? ?? 83 85 ?? - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B 85 ?? ?? ?? ?? 7C ?? 8B 05 ?? ?? ?? ?? 89 C7 E8 ?? - ?? ?? ?? 8B 05 ?? ?? ?? ?? 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 8B 75 ?? 64 48 33 - 34 25 ?? ?? ?? ?? 74 ?? E8 ?? ?? ?? ?? C9 C3 - } - $search_files = { - 55 48 89 E5 48 81 EC ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 64 48 8B 04 25 ?? ?? ?? ?? 48 - 89 45 ?? 31 C0 8B 05 ?? ?? ?? ?? 83 C0 ?? 89 05 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 83 F8 - ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? - 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? - ?? ?? ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 48 8B 85 ?? ?? ?? ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 75 ?? - E9 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 83 C0 - ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 75 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? - ?? 85 C0 74 ?? 48 8B 85 ?? ?? ?? ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? - ?? 85 C0 75 ?? 83 85 ?? ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 - D6 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 C7 C1 ?? ?? ?? ?? 48 89 C2 B8 ?? - ?? ?? ?? 48 89 D7 F2 AE 48 89 C8 48 F7 D0 48 8D 50 ?? 48 8D 85 ?? ?? ?? ?? 48 01 D0 - 66 C7 00 ?? ?? 48 8B 85 ?? ?? ?? ?? 48 8D 50 ?? 48 8D 85 ?? ?? ?? ?? 48 89 D6 48 89 - C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 48 8D - 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 83 E8 ?? 89 05 ?? ?? ?? ?? - 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? - ?? ?? 0F 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? - 48 8B 4D ?? 64 48 33 0C 25 ?? ?? ?? ?? 74 ?? E8 ?? ?? ?? ?? C9 C3 - } - $subvert_grub_1 = { - 55 48 89 E5 48 81 EC ?? ?? ?? ?? 64 48 8B 04 25 ?? ?? ?? ?? 48 89 45 ?? 31 C0 48 B8 - ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 - ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? - ?? ?? ?? 48 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? - ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 - ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 - ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? 66 C7 85 ?? ?? FF FF ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? - ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? - 48 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 48 B8 ?? ?? - ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? - ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? - ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 + $search_and_encrypt_p1 = { + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 55 56 57 8B BC 24 ?? + ?? ?? ?? 57 89 7C 24 ?? FF 15 ?? ?? ?? ?? 8B 2D ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 89 44 + 24 ?? FF D5 8D 44 24 ?? 50 57 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? + ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? 51 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 54 24 ?? 52 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 8D 4C 24 ?? 51 + 57 C6 04 07 ?? FF D5 F6 44 24 ?? ?? 0F 84 ?? ?? ?? ?? 8D 5C 24 ?? E8 ?? ?? ?? ?? 84 + C0 0F 85 ?? ?? ?? ?? 8A 0F 33 D2 84 C9 74 ?? BE ?? ?? ?? ?? 8B C7 2B F7 88 0C 06 8A + 48 ?? 40 42 84 C9 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? C6 82 ?? ?? ?? ?? ?? C6 82 ?? + ?? ?? ?? ?? FF D5 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 + 74 ?? 56 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 + ?? 68 ?? ?? ?? ?? 57 FF D5 57 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 C0 38 44 24 ?? 74 } - $subvert_grub_2 = { - 48 89 85 ?? ?? ?? ?? 66 C7 85 ?? ?? FF FF ?? ?? 48 B8 ?? ?? ?? - ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? - 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? - ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? - ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? - ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 - 8B 85 ?? ?? ?? ?? 48 89 C1 BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? - ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 4C 8D 85 ?? ?? - ?? ?? 48 8D BD ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8B 85 ?? ?? - ?? ?? 48 8D B5 ?? ?? ?? ?? 56 48 8D B5 ?? ?? ?? ?? 56 4D 89 C1 49 89 F8 BE ?? ?? ?? - ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 - E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? - ?? ?? 0F 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 B9 ?? - ?? ?? ?? ?? ?? ?? ?? 48 89 08 C7 40 ?? ?? ?? ?? ?? C6 40 ?? ?? 48 8B 85 + $search_and_encrypt_p2 = { + 40 80 7C 04 ?? ?? 75 ?? 8A 4C 04 ?? 80 F9 ?? 75 ?? 80 7C 04 ?? ?? 75 ?? 80 7C 04 ?? + ?? 75 ?? 80 7C 04 ?? ?? 74 ?? 80 F9 ?? 75 ?? B3 ?? 38 5C 04 ?? 75 ?? 80 7C 04 ?? ?? + 75 ?? 80 7C 04 ?? ?? 75 ?? 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? FF 05 ?? ?? ?? ?? E9 ?? + ?? ?? ?? FF 05 ?? ?? ?? ?? E9 ?? ?? ?? ?? B3 ?? B2 ?? 80 F9 ?? 75 ?? 38 5C 04 ?? 75 + ?? 80 7C 04 ?? ?? 75 ?? 38 5C 04 ?? 75 ?? 32 D2 80 F9 ?? 75 ?? 80 7C 04 ?? ?? 75 ?? + 80 7C 04 ?? ?? 75 ?? 80 7C 04 ?? ?? 75 ?? 32 D2 80 F9 ?? 75 ?? 80 7C 04 ?? ?? 75 ?? + 80 7C 04 ?? ?? 75 ?? 80 7C 04 ?? ?? 0F 84 ?? ?? ?? ?? 84 D2 0F 84 ?? ?? ?? ?? 8A 0F + 33 D2 84 C9 74 ?? 8D B4 24 ?? ?? ?? ?? 8B C7 2B F7 8D A4 24 ?? ?? ?? ?? 88 0C 06 8A + 48 ?? 40 42 84 C9 75 ?? A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 0F B6 + 05 ?? ?? ?? ?? C6 84 14 ?? ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 89 94 24 ?? ?? ?? ?? 8B 15 + ?? ?? ?? ?? 88 84 24 ?? ?? ?? ?? 33 C0 6A ?? 89 8C 24 ?? ?? ?? ?? 89 94 24 ?? ?? ?? + ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 88 84 24 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 68 ?? ?? ?? ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B 0D ?? + ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B E8 A1 ?? ?? ?? ?? 89 8C 24 ?? ?? ?? ?? 8B 0D ?? ?? ?? + ?? 89 84 24 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 89 94 24 ?? ?? ?? ?? 66 8B 15 ?? ?? ?? + ?? 89 8C 24 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? 8D 74 24 ?? 89 6C 24 ?? 66 89 } - $subvert_grub_3 = { - 48 8D 50 ?? 48 8D 85 ?? ?? ?? ?? 48 89 D6 48 89 C7 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? - ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 85 ?? ?? ?? - ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 85 ?? ?? ?? - ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 75 ?? EB ?? 48 8D 85 ?? - ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 - 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? - ?? E9 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? - 48 83 BD ?? ?? ?? ?? ?? 74 ?? 4C 8D 85 ?? ?? ?? ?? 48 8D BD ?? ?? ?? ?? 48 8D 8D ?? - ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 8D B5 ?? ?? ?? ?? 56 48 8D B5 - ?? ?? ?? ?? 56 4D 89 C1 49 89 F8 BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 48 83 C4 ?? EB ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? - ?? 48 83 BD ?? ?? ?? ?? ?? 74 ?? 4C 8D 85 ?? ?? ?? ?? 48 8D BD ?? ?? ?? ?? 48 8D 8D - ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 8D B5 ?? ?? ?? ?? 56 48 8D - B5 ?? ?? ?? ?? 56 4D 89 C1 49 89 F8 BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 48 83 C4 ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 8B - 55 ?? 64 48 33 14 25 ?? ?? ?? ?? 74 ?? E8 ?? ?? ?? ?? C9 C3 + $search_and_encrypt_p3 = { + 94 24 ?? ?? ?? ?? 88 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 51 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 0F 84 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? + 52 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 + E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 56 + 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 6A ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 + 8D 84 24 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 6A + ?? 51 E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 + ?? 56 E8 ?? ?? ?? ?? 8B 7C 24 ?? 83 C4 ?? FF 05 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 + FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 2B F0 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 03 + C6 50 8D 8C 24 ?? ?? ?? ?? 51 8B D1 52 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 85 C0 75 ?? FF 05 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 55 E8 ?? ?? + ?? ?? 8B 2D ?? ?? ?? ?? 83 C4 ?? 8B 74 24 ?? 8D 4C 24 ?? 51 56 FF 15 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? 56 FF 15 } condition: - uint32(0)==0x464C457F and ($search_files and ( all of ($encrypt_files_*)) and ( all of ($subvert_grub_*))) + uint16(0)==0x5A4D and ( all of ($search_and_encrypt_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Targetcompany : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Garrantydecrypt : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects TargetCompany ransomware." + description = "Yara rule that detects GarrantyDecrypt ransomware." author = "ReversingLabs" - id = "7e6983f9-2aca-5cfa-aad6-38aa64fa2062" - date = "2021-09-27" - modified = "2021-09-27" + id = "0aa05f06-1773-5ce8-892d-04468f5deccc" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.TargetCompany.yara#L1-L141" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "05fa81afa8aa1e3b9955ad24a274ddef4fb32d678902af7aae6d6c67ed3bf0fd" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.GarrantyDecrypt.yara#L1-L79" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "7194c1e0e15a89f2c691a7d586b9db68295cc52a5f042d0f7eb558c326430444" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -38223,736 +39397,23 @@ rule REVERSINGLABS_Win32_Ransomware_Targetcompany : TC_DETECTION MALICIOUS MALWA sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "TargetCompany" + tc_detection_name = "GarrantyDecrypt" tc_detection_factor = 5 importance = 25 strings: $encrypt_files_p1 = { - E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 59 53 68 ?? ?? ?? ?? 6A ?? 53 6A - ?? 68 ?? ?? ?? ?? 56 FF D7 89 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 56 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 - BD ?? ?? ?? ?? ?? 75 ?? BF ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 56 8D 75 ?? E8 ?? ?? ?? - ?? 50 89 5D ?? E8 ?? ?? ?? ?? 53 6A ?? E8 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? E9 ?? ?? - ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 - E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 53 68 - ?? ?? ?? ?? 6A ?? 53 6A ?? 68 ?? ?? ?? ?? 56 FF D7 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? - ?? 6A ?? 5F 53 57 56 FF B5 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 57 52 50 - 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 25 ?? ?? ?? ?? 33 FF 3B F3 89 85 - ?? ?? ?? ?? 7F ?? 7C ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 77 ?? 33 FF 47 EB ?? B9 ?? ?? - ?? ?? 3B C1 73 ?? 53 51 56 FF B5 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 50 - } - $encrypt_files_p2 = { - 56 FF B5 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 89 95 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 3B FB 8B 3D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? - 89 9D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 59 89 85 ?? ?? ?? ?? 3B C3 0F 84 ?? ?? ?? ?? 53 8D 8D ?? ?? ?? ?? 51 FF B5 ?? - ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 FF B5 ?? ?? ?? ?? 8D 4D - ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 53 53 53 FF B5 ?? - ?? ?? ?? FF D7 53 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? FF D6 E9 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 89 85 ?? ?? ?? ?? 3B C3 0F 84 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B C3 0F 86 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 53 53 FF B5 ?? - ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF D7 53 8D 85 ?? ?? ?? ?? 50 FF B5 ?? - ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 FF B5 ?? - ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 53 - FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF D7 53 8D 85 ?? ?? ?? ?? 50 - FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF D6 8B 85 ?? ?? ?? ?? 01 85 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 11 85 ?? ?? ?? ?? FF 8D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? - FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 6A ?? 53 53 33 C0 50 FF B5 ?? ?? ?? ?? FF D7 8B - BD ?? ?? ?? ?? 53 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 45 ?? 50 57 FF D6 53 8D 85 ?? ?? ?? - ?? 50 6A ?? 8D 45 ?? 50 57 FF D6 53 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 57 FF - D6 57 FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 - } - $remote_connection_p1 = { - 55 8B EC 83 EC ?? 53 56 33 F6 57 8D 5D ?? 89 75 ?? E8 ?? ?? ?? ?? 89 75 ?? 56 56 56 - FF 75 ?? 56 FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? 3B DE 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 FF 6A ?? 8D - 45 ?? 50 FF 74 BD ?? 53 FF 15 ?? ?? ?? ?? 47 83 FF ?? 72 ?? 56 56 6A ?? 56 56 FF 75 - ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 89 45 ?? 3B C6 0F 84 ?? ?? ?? ?? 33 C9 80 7D ?? ?? - B8 ?? ?? ?? ?? 0F 95 C1 56 49 23 C8 03 C8 81 C9 ?? ?? ?? ?? 51 56 56 56 FF 75 ?? 89 - 4D ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B D8 3B DE 0F 84 ?? ?? ?? ?? 6A ?? - 5F 8D 45 ?? 50 8D 45 ?? 50 6A ?? 53 89 7D ?? 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? - 81 4D ?? ?? ?? ?? ?? 57 8D 45 ?? 50 6A ?? 53 FF 15 ?? ?? ?? ?? FF 75 ?? 8B 45 ?? FF - 75 ?? F7 D8 1B C0 50 FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 33 FF 56 56 8D 45 ?? - 50 53 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 03 C7 50 FF 75 ?? E8 ?? ?? ?? - ?? 59 59 8D 4D ?? 51 FF 75 ?? 89 45 ?? 03 C7 50 53 FF 15 ?? ?? ?? ?? 03 7D ?? 39 75 - ?? 75 ?? 53 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? - 39 75 ?? 75 ?? 33 C0 40 39 45 ?? 74 ?? 89 45 ?? E9 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? - ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 5F 5E 5B C9 C3 - } - $remote_connection_p2 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 8D 9D ?? ?? ?? ?? - 8B F9 E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 45 - ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 85 F6 75 - ?? B8 ?? ?? ?? ?? 50 8D 45 ?? 50 57 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 8B F8 85 F6 74 ?? 56 E8 ?? ?? ?? ?? 59 85 FF 74 ?? 57 E8 ?? ?? ?? ?? 59 FF B5 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B 4D ?? 5F 5E 33 - CD 5B E8 ?? ?? ?? ?? C9 C3 - } - $generate_key = { - 0F 31 0F AF C8 0F AF CE 0F AF 8D ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 53 33 FF 47 57 53 53 - 8D 85 ?? ?? ?? ?? 50 89 8D ?? ?? ?? ?? FF D6 3B C3 75 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? - ?? ?? 75 ?? 6A ?? 57 53 53 8D 85 ?? ?? ?? ?? 50 FF D6 3B C3 74 ?? 8D 85 ?? ?? ?? ?? - 50 6A ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 59 53 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8B C7 - B9 ?? ?? ?? ?? 8B 11 8B F2 C1 EE ?? 33 F2 69 F6 ?? ?? ?? ?? 03 F0 89 71 ?? 83 C1 ?? - 40 81 F9 ?? ?? ?? ?? 7C ?? 57 A3 ?? ?? ?? ?? FF 15 - } - $find_files_p1 = { - 8D 85 ?? ?? ?? ?? 53 53 50 53 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? - 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF - D6 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 - FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 C4 ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 33 F6 0F B7 - C6 FF 34 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? 46 66 83 FE ?? 72 ?? 6A ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? - ?? 0F 84 ?? ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 0F B7 B5 ?? ?? ?? ?? 8D 34 B5 - } - $find_files_p2 = { - FF 36 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 50 FF D3 FF 36 89 85 ?? ?? - ?? ?? FF D3 8B 8D ?? ?? ?? ?? 3B C8 0F 84 ?? ?? ?? ?? FF 85 ?? ?? ?? ?? 66 83 BD ?? - ?? ?? ?? ?? 72 ?? C6 85 ?? ?? ?? ?? ?? 0F B6 85 ?? ?? ?? ?? FF 34 85 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? FE 85 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? - ?? 72 ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 59 85 F6 74 ?? 6A ?? 59 FF B5 ?? ?? ?? ?? 33 C0 - 8B FE F3 AB 66 8B 85 ?? ?? ?? ?? 66 89 46 ?? FF D3 8D 44 00 ?? 50 E8 ?? ?? ?? ?? 59 - FF B5 ?? ?? ?? ?? 89 46 ?? 50 FF 15 ?? ?? ?? ?? 56 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BF ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF B5 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 83 C4 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 EB ?? 56 FF 15 ?? ?? ?? - ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B - 4D ?? 5F 5E 33 CD 33 C0 5B E8 ?? ?? ?? ?? C9 C2 - } - - condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($generate_key) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) -} -rule REVERSINGLABS_Win32_Ransomware_Erica : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Erica ransomware." - author = "ReversingLabs" - id = "38f57157-bd49-5a63-8c69-497eb9efe274" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Erica.yara#L1-L76" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "93512091943f3a3b395c38fa3b0f5ecdbbf1cdf967ccfea4d7145c940076e046" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Erica" - tc_detection_factor = 5 - importance = 25 - - strings: - $encrypt_files_p1 = { - 55 8B EC 83 C4 ?? 53 56 57 89 4D ?? 8B F2 8B D8 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 - ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 89 45 ?? 8A 43 ?? 2C ?? 72 ?? 74 ?? EB ?? BF ?? - ?? ?? ?? EB ?? BF ?? ?? ?? ?? EB ?? BF ?? ?? ?? ?? 33 DB 68 ?? ?? ?? ?? 8B 45 ?? 50 - 8B 45 ?? 50 6A ?? 56 E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 45 ?? 50 6A ?? 6A ?? 57 8B 06 50 - E8 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? - 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 50 6A ?? 8B 45 ?? 50 8B 45 ?? 50 - 8B 06 50 E8 ?? ?? ?? ?? 85 C0 75 ?? BB ?? ?? ?? ?? EB ?? BB ?? ?? ?? ?? EB ?? BB ?? - ?? ?? ?? EB ?? BB ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 33 C0 5A - 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 - } - $encrypt_files_p2 = { - 8D 40 ?? 55 8B EC 83 C4 ?? 53 33 DB 89 5D ?? 89 5D ?? 8B D9 89 55 ?? 89 45 ?? 33 C0 - 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 89 45 ?? 33 C0 89 45 ?? 33 C0 89 45 ?? 33 - C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? 50 8B 45 ?? 8D 50 ?? 8B 45 ?? 33 C9 - E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 83 C0 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B - 40 ?? E8 ?? ?? ?? ?? 8B D0 4A 8B 45 ?? 83 C0 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? E8 - ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 8B 45 ?? 8B 48 ?? 8B 45 ?? 8D 50 ?? 8B 45 ?? E8 ?? - ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 85 C0 75 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 - ?? ?? ?? ?? 8B 45 ?? 50 53 8B 45 ?? 50 8B 45 ?? 50 8D 4D ?? 8D 55 ?? 8B 45 ?? E8 ?? - ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? - 8B 45 ?? 50 8D 45 ?? 50 8B 45 ?? 83 C0 ?? E8 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 8B 45 - ?? 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? 8B 45 ?? 83 C0 ?? 8B 55 ?? - E8 ?? ?? ?? ?? 8B 45 ?? 50 8D 45 ?? 50 8B 45 ?? 83 C0 ?? E8 ?? ?? ?? ?? 50 6A ?? 6A - ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? 85 C0 74 ?? C7 45 ?? ?? ?? - ?? ?? 8B 45 ?? 83 C0 ?? 8B 55 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? E8 ?? ?? ?? ?? EB - ?? 8B 45 ?? 8B 50 ?? 8B 45 ?? 83 C0 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? - ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 6A ?? 8B 45 - ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 8D 50 ?? 8B 45 ?? 8B 4D ?? E8 ?? ?? - ?? ?? C3 - } - $find_files = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 DB 89 9D ?? ?? ?? ?? 89 5D ?? 8B D9 89 55 ?? 89 - 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF - 30 64 89 20 8B C3 E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? - 80 7C 02 ?? ?? 74 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 - ?? 80 38 ?? 75 ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? - ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 85 F6 0F 95 C0 EB ?? F7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? 77 ?? 83 3B ?? 74 ?? 8B C3 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - FF 33 FF 75 ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? 8B C3 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? - ?? ?? F7 D8 1B C0 F7 D8 84 C0 75 ?? 56 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 - } - - condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) -} -rule REVERSINGLABS_Win64_Ransomware_Nokoyawa : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Nokoyawa ransomware." - author = "ReversingLabs" - id = "31470ce4-381f-50d2-bbca-03c592e62a7d" - date = "2022-06-06" - modified = "2022-06-06" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Nokoyawa.yara#L1-L104" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "85b7d93db06007d0043b1489b532410ccc700cf082b641fff8a09de2ffe9101d" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Nokoyawa" - tc_detection_factor = 5 - importance = 25 - - strings: - $enum_shares = { - 48 89 4C 24 ?? 48 81 EC ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - 48 8D 44 24 ?? 48 89 44 24 ?? 4C 8B 8C 24 ?? ?? ?? ?? 45 33 C0 33 D2 B9 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 7C 24 ?? ?? 74 ?? 33 C0 E9 ?? ?? ?? ?? 8B 44 24 ?? - 8B D0 B9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 89 44 24 ?? 48 83 7C 24 ?? ?? 75 ?? 33 C0 - E9 ?? ?? ?? ?? 8B 44 24 ?? 44 8B C0 33 D2 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 4C 8D 4C 24 - ?? 4C 8B 44 24 ?? 48 8D 54 24 ?? 48 8B 4C 24 ?? FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 7C - 24 ?? ?? 0F 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 8B 44 24 ?? FF C0 89 44 24 - ?? 8B 44 24 ?? 39 44 24 ?? 73 ?? 48 8B 44 24 ?? 83 78 ?? ?? 75 ?? 8B 44 24 ?? 48 6B - C0 ?? 48 8B 4C 24 ?? 48 8B 54 01 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? - ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 48 6B C0 - ?? 48 8B 4C 24 ?? 8B 44 01 ?? 83 E0 ?? 83 F8 ?? 75 ?? 8B 44 24 ?? 48 6B C0 ?? 48 8B - 4C 24 ?? 48 03 C8 48 8B C1 48 8B C8 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? EB ?? 81 7C 24 ?? - ?? ?? ?? ?? 74 ?? EB ?? 81 7C 24 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8B 4C 24 ?? FF - 15 ?? ?? ?? ?? 48 8B 4C 24 ?? FF 15 - } - $find_files_p1 = { - FF 15 ?? ?? ?? ?? 48 89 44 24 ?? 48 83 7C 24 ?? ?? 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 83 - E0 ?? 85 C0 0F 84 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 84 - ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 98 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? - ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 98 48 8B D0 48 - 8D 4C 24 ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? - ?? ?? 48 98 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 48 8D 4C 24 - ?? E8 ?? ?? ?? ?? 48 98 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? - 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 98 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 3D ?? ?? - ?? ?? 74 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 98 48 8B D0 48 8D 4C 24 ?? E8 ?? ?? ?? - ?? 3D ?? ?? ?? ?? 75 ?? E9 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF C8 48 98 48 8B 8C 24 ?? - ?? ?? ?? 0F B7 04 41 83 F8 ?? 75 ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF C8 48 - } - $find_files_p2 = { - 98 48 8B 8C 24 ?? ?? ?? ?? 0F B7 04 41 83 F8 ?? 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF C8 48 98 48 8B 8C 24 ?? ?? ?? ?? - 0F B7 04 41 83 F8 ?? 75 ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF C8 48 98 48 8B - 8C 24 ?? ?? ?? ?? 0F B7 04 41 83 F8 ?? 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 4C - 24 ?? E8 ?? ?? ?? ?? 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 15 ?? ?? - ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 85 C0 75 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 85 C0 75 ?? EB ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B 4C - 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8B 4C 24 ?? FF 15 ?? ?? ?? ?? 48 - 81 C4 - } - $encrypt_files = { - 48 89 4C 24 ?? 48 83 EC ?? 48 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? 45 33 C9 45 33 C0 BA ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 48 89 44 24 ?? 48 83 7C 24 ?? ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 48 89 44 24 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 44 24 ?? B9 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 48 89 44 24 ?? BA ?? ?? ?? ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 54 24 - ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 4C 8B 44 24 ?? 48 8B 15 ?? ?? ?? ?? 48 8B 4C 24 ?? - E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 44 24 ?? 41 B8 ?? ?? ?? ?? 33 D2 - 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 C7 40 ?? ?? ?? ?? ?? 48 8B 44 24 ?? - 48 8B 4C 24 ?? 48 89 48 ?? 48 8B 44 24 ?? C7 40 ?? ?? ?? ?? ?? 48 8B 44 24 ?? 48 C7 - 40 ?? ?? ?? ?? ?? 48 8B 44 24 ?? C7 40 ?? ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? - 48 89 48 ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 89 48 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 48 8B 4C 24 ?? 48 89 41 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 89 41 ?? - 48 8B 44 24 ?? C7 40 ?? ?? ?? ?? ?? 48 8B 44 24 ?? 48 83 C0 ?? 48 8B 94 24 ?? ?? ?? - ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 98 4C 8B C0 48 8D - 15 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 48 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 83 C0 ?? - 48 8B D0 48 8B 4C 24 ?? FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 54 24 - ?? 48 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 44 24 ?? 45 33 C9 41 B8 - ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 50 ?? 48 8B 44 24 ?? 48 8B 48 ?? FF 15 ?? ?? ?? ?? - 48 8D 05 ?? ?? ?? ?? F0 FF 00 48 83 C4 ?? C3 - } - - condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($enum_shares) and ($encrypt_files) -} -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Harpoonlocker : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects HarpoonLocker ransomware." - author = "ReversingLabs" - id = "3605d354-5a33-54b1-83ad-ad514c78357b" - date = "2022-01-27" - modified = "2022-01-27" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.HarpoonLocker.yara#L1-L96" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "20587f9dce5981934498d9979843a090224ba649def8b694adf7799b7060cc25" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "HarpoonLocker" - tc_detection_factor = 5 - importance = 25 - - strings: - $encrypt_files_p1 = { - 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 14 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? - ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 25 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 6F - ?? ?? ?? ?? 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 73 ?? ?? ?? ?? 25 06 07 9A 7D - ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 14 28 ?? ?? ?? ?? 26 07 17 58 0B 07 06 8E - 69 32 ?? 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 2B ?? 73 ?? ?? ?? ?? 0D - 09 12 ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 09 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 14 28 ?? ?? ?? - ?? 26 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? DC 12 ?? - 12 ?? 28 ?? ?? ?? ?? 12 ?? 12 ?? 28 ?? ?? ?? ?? 11 ?? 11 ?? 59 13 ?? 72 ?? ?? ?? ?? 11 - ?? 8C ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 2C ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 2B ?? 2A - } - $encrypt_files_p2 = { - 12 ?? FE 15 ?? ?? ?? ?? 12 ?? FE 15 ?? ?? ?? ?? 12 ?? FE 15 ?? ?? ?? ?? 02 16 12 ?? 28 - ?? ?? ?? ?? 26 08 7B ?? ?? ?? ?? 0D 08 7B ?? ?? ?? ?? 20 ?? ?? ?? ?? 35 ?? 08 7B ?? ?? - ?? ?? 16 36 ?? DD ?? ?? ?? ?? 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 72 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 10 ?? 03 03 6F ?? ?? ?? ?? 03 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? - 13 ?? 1F ?? 8D ?? ?? ?? ?? 13 ?? 03 6F ?? ?? ?? ?? 16 11 ?? 16 1F ?? 28 ?? ?? ?? ?? 03 - 6F ?? ?? ?? ?? 16 11 ?? 1F ?? 1F ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 1F ?? 6A - 13 ?? 17 13 ?? 09 6E 13 ?? 2B ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 59 13 ?? 11 ?? 11 ?? 30 - ?? 02 19 17 7E ?? ?? ?? ?? 19 20 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? - 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? DD ?? ?? ?? ?? 11 ?? 7E ?? ?? ?? ?? 1A 16 09 20 ?? - ?? ?? ?? 58 14 28 ?? ?? ?? ?? 0A 06 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? DD ?? ?? ?? ?? - 06 1F ?? 16 16 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? - DD ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 26 16 13 ?? 16 13 ?? 2B ?? 11 ?? 20 ?? ?? ?? ?? 2F - ?? 09 6E 11 ?? 6A 59 13 ?? 11 ?? D4 8D ?? ?? ?? ?? 13 ?? 11 ?? 17 58 11 ?? 33 ?? 11 ?? - D4 8D ?? ?? ?? ?? 13 ?? 07 11 ?? 28 ?? ?? ?? ?? 11 ?? 16 11 ?? 8E 69 28 ?? ?? ?? ?? 11 - ?? 18 5D 2D ?? 11 ?? 8E 69 1F ?? 33 ?? 11 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 16 07 11 - ?? 28 ?? ?? ?? ?? 11 ?? 8E 69 28 ?? ?? ?? ?? 11 ?? 11 ?? 8E 69 58 13 ?? 11 ?? 17 58 13 - ?? 11 ?? 11 ?? 3F ?? ?? ?? ?? 11 ?? 20 ?? ?? ?? ?? 32 ?? 11 ?? 16 07 09 28 ?? ?? ?? ?? - 11 ?? 8E 69 28 ?? ?? ?? ?? 2B ?? 11 ?? 16 07 11 ?? 28 ?? ?? ?? ?? 11 ?? 8E 69 28 ?? ?? - ?? ?? DE ?? 26 DE ?? 26 DE ?? 00 07 28 ?? ?? ?? ?? 26 DE ?? 26 DE ?? 00 06 28 ?? ?? ?? - ?? 26 DE ?? 26 DE ?? DC 2A - } - $find_files = { - 73 ?? ?? ?? ?? 0A 06 02 7D ?? ?? ?? ?? 7E ?? ?? ?? ?? 06 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 2C ?? 2A 00 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? - ?? ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 14 0B 06 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B DE ?? 26 - DE ?? 07 2C ?? 07 8E 16 FE 01 2B ?? 17 0C 06 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 16 13 - ?? 2B ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 11 ?? 9A 7D ?? ?? ?? ?? 08 2C ?? 11 ?? 7B ?? - ?? ?? ?? 28 ?? ?? ?? ?? 2B ?? 11 ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 14 28 ?? ?? ?? ?? - 26 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? DE ?? 26 DE ?? 08 2C ?? DD ?? ?? ?? ?? 28 - ?? ?? ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 17 - 6F ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 07 13 ?? 16 13 ?? 2B ?? 73 ?? ?? ?? - ?? 13 ?? 11 ?? 11 ?? 11 ?? 9A 7D ?? ?? ?? ?? 11 ?? 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? - 7E ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 7E ?? ?? ?? ?? 11 ?? FE 06 ?? - ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2D ?? 11 ?? 7B ?? ?? ?? ?? 09 28 ?? ?? ?? ?? DE - ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? 00 09 6F ?? ?? ?? ?? DE ?? 26 DE - ?? DE ?? 26 DE ?? 2A - } - $change_boot = { - 02 8E 2C ?? 02 16 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 2A 02 16 9A 72 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2A 02 16 9A 72 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 2C ?? 17 80 ?? ?? ?? ?? 16 80 ?? ?? ?? ?? 02 16 9A 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 2C ?? 17 80 ?? ?? ?? ?? 02 16 9A 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 28 ?? - ?? ?? ?? 2A 28 ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? - ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2A 28 ?? ?? ?? ?? 2A - } - - condition: - uint16(0)==0x5A4D and ($change_boot) and ($find_files) and ( all of ($encrypt_files_p*)) -} -rule REVERSINGLABS_Win32_Ransomware_Lockbit : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects LockBit ransomware." - author = "ReversingLabs" - id = "9a6405dc-da1f-5426-a424-a73bceb1928c" - date = "2022-03-31" - modified = "2022-03-31" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.LockBit.yara#L1-L282" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "030222bd659c7e0e03858fa062067b1483aca3b7973cce19a1e7cdbb48d4405c" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "LockBit" - tc_detection_factor = 5 - importance = 25 - - strings: - $enum_resources_v1 = { - 55 8B EC 83 EC ?? 57 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 51 6A ?? 6A ?? 6A ?? C7 45 ?? - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? - ?? 8B F8 89 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 53 56 FF 75 ?? 6A ?? 57 E8 ?? ?? ?? ?? 83 - C4 ?? 8D 45 ?? 50 57 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 33 DB 39 5D ?? 76 ?? 8B F7 0F 1F 80 ?? ?? ?? ?? F7 46 ?? ?? ?? ?? ?? 74 ?? 8B CE E8 - ?? ?? ?? ?? 83 7F ?? ?? 74 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F8 83 C4 ?? 8B 45 - ?? FF 70 ?? FF 15 ?? ?? ?? ?? 8D 04 45 ?? ?? ?? ?? 50 8B 45 ?? FF 70 ?? 57 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 45 ?? 50 6A ?? 57 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B - 0D ?? ?? ?? ?? 89 04 8D ?? ?? ?? ?? F0 FF 05 ?? ?? ?? ?? 8B 7D ?? 43 83 C6 ?? 3B 5D - ?? 72 ?? E9 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5E 5B 85 C0 - 75 ?? B8 ?? ?? ?? ?? 5F 8B E5 5D C3 33 C0 5F 8B E5 5D C3 - } - $find_files_v1_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 8B C1 C7 45 ?? ?? ?? ?? ?? 57 50 89 45 ?? 33 C9 8D - 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 66 89 4D ?? 50 FF 15 ?? ?? ?? ?? 83 - C4 ?? 8D 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 6A ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? - ?? ?? 8B F8 89 7D ?? 83 FF ?? 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 33 C0 8B 35 ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 1F 80 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D - 45 ?? 50 FF D3 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 45 ?? 50 FF D3 85 C0 - 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 50 FF D3 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D3 85 - C0 0F 84 - } - $find_files_v1_2 = { - 45 ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? E9 ?? ?? ?? ?? 33 C9 66 39 8D ?? ?? ?? ?? 74 ?? 8D 40 ?? 41 66 83 38 ?? 75 ?? - 83 F9 ?? 0F 8E ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 56 68 ?? ?? - ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? - 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 - } - $find_files_v1_3 = { - 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? - ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? - 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 - ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? 33 C9 0F 11 45 ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? - ?? ?? 66 90 8A 45 ?? 30 44 0D ?? 41 83 F9 ?? 72 ?? 33 C0 C6 45 ?? ?? 66 89 45 ?? 8D - 45 ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 - C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF D3 85 C0 0F 84 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 - ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF D3 - 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? - ?? ?? 8B 4D ?? 8D 95 ?? ?? ?? ?? 2B D1 0F B7 01 8D 49 ?? 66 89 44 11 ?? 66 85 C0 75 - ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B F2 66 8B 02 83 C2 ?? - 66 85 C0 75 ?? 8D BD ?? ?? ?? ?? 2B D6 83 C7 ?? 0F 1F 40 ?? 66 8B 47 ?? 83 C7 ?? 66 - 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8B CA C1 E9 ?? F3 A5 8B CA 83 E1 ?? F3 A4 A8 ?? 75 ?? - A8 ?? 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 7D ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF D6 - 83 F8 ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 57 FF 15 ?? ?? ?? ?? 5F - 5E 5B 8B E5 5D C3 - } - $encrypt_files_v1_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 53 56 57 8B F9 C7 45 ?? ?? ?? - ?? ?? 89 7D ?? 66 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 - 89 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 - } - $encrypt_files_v1_2 = { - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F8 33 DB 89 7D ?? 33 F6 0F 1F 00 8B 84 - B5 ?? ?? ?? ?? 85 C0 74 ?? 57 50 FF 15 ?? ?? ?? ?? 85 C0 B8 ?? ?? ?? ?? 0F 44 D8 46 - 81 FE ?? ?? ?? ?? 7C ?? 8B 7D ?? 33 C0 66 89 85 ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 57 50 8D 85 ?? ?? ?? ?? 89 5D ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 8B 1D ?? ?? ?? ?? 83 C4 ?? 33 F6 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? - 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF D3 83 F8 ?? 75 - ?? 8B CF E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? 8B - } - $encrypt_files_v1_3 = { - CF E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 83 FE ?? 7D ?? 46 EB ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? 83 - FB ?? 75 ?? 8B 1D ?? ?? ?? ?? EB ?? FF 35 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? 53 FF - 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 F8 ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 33 C0 5F 5E 5B 8B - E5 5D C3 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 DB 75 ?? FF 75 ?? FF 15 - ?? ?? ?? ?? 33 C0 5F 5E 5B 8B E5 5D C3 8B 45 ?? 8B 75 ?? 89 43 ?? 8D 43 ?? 50 56 C7 - 43 ?? ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 53 FF 15 ?? ?? - ?? ?? 83 C4 ?? 56 FF 15 ?? ?? ?? ?? 33 C0 5F 5E 5B 8B E5 5D C3 8B 4B ?? 8B 43 ?? 85 - C9 7F ?? 7C ?? 83 F8 ?? 72 ?? 83 E8 ?? C7 43 ?? ?? ?? ?? ?? 89 43 ?? 8B 43 ?? 83 D9 - ?? 89 43 ?? 8B 43 ?? 89 43 ?? 8D 83 ?? ?? ?? ?? 6A ?? 50 89 4B ?? C7 43 ?? ?? ?? ?? - ?? 89 73 ?? E8 ?? ?? ?? ?? 6A ?? 8D 83 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 53 6A ?? 6A ?? - 8D 73 ?? 56 FF 73 ?? FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 3D ?? - ?? ?? ?? 74 ?? 56 8B 35 ?? ?? ?? ?? FF D6 83 C4 ?? 53 FF D6 83 C4 ?? FF 75 ?? FF 15 - ?? ?? ?? ?? 8B 45 ?? 5F 5E 5B 8B E5 5D C3 F0 FF 05 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? - B8 ?? ?? ?? ?? F0 0F C1 05 ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 7E ?? 8B 35 ?? ?? ?? ?? 6A - ?? FF D6 83 3D ?? ?? ?? ?? ?? 7D ?? 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 - } - $check_blacklisted_languages_v2 = { - FF D0 0F B7 C0 B9 2C 08 ?? ?? 66 3B C1 0F 84 ?? ?? ?? ?? B9 2C 04 ?? ?? 66 3B C1 74 - ?? B9 2B 04 ?? ?? 66 3B C1 74 ?? B9 23 04 ?? ?? 66 3B C1 74 ?? B9 37 04 ?? ?? 66 3B - C1 74 ?? B9 3F 04 ?? ?? 66 3B C1 74 ?? B9 40 04 ?? ?? 66 3B C1 74 ?? B9 19 08 ?? ?? - 66 3B C1 74 ?? B9 19 04 ?? ?? 66 3B C1 74 ?? B9 28 04 ?? ?? 66 3B C1 74 ?? B9 42 04 - ?? ?? 66 3B C1 74 ?? B9 43 08 ?? ?? 66 3B C1 74 ?? B9 43 04 ?? ?? 66 3B C1 74 ?? B9 - 22 04 ?? ?? 66 3B C1 0F 85 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 85 DB 0F 85 ?? ?? ?? ?? 64 - A1 ?? ?? ?? ?? 8B 40 ?? 8B 40 ?? 8B 00 8B C8 89 45 ?? 8B D0 89 4D ?? 0F B7 59 ?? 33 - FF 8B 71 ?? D1 EB C7 45 ?? ?? ?? ?? ?? 8D 04 5E 3B F0 0F 47 DF 85 DB 74 ?? 8A 0E 8D - 76 ?? 0F BE D1 80 E9 ?? 8B C2 83 C8 ?? 80 F9 ?? 0F 47 C2 47 33 45 ?? 69 C0 ?? ?? ?? - ?? 89 45 ?? 3B FB 75 ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B 01 8B - C8 89 4D ?? 3B C2 74 ?? 83 79 ?? ?? 75 ?? 33 DB 89 1D ?? ?? ?? ?? A1 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? 8B 43 ?? 8B 4C 18 ?? 8D 04 19 89 45 ?? - 3B C3 74 ?? 33 C9 89 4D ?? 39 48 ?? 74 ?? 8B 40 ?? 8B 55 ?? 03 C3 89 45 ?? 0F 1F 40 - ?? 8B 30 BF ?? ?? ?? ?? 8A 04 1E 03 F3 46 84 C0 74 ?? 0F BE D0 8D 76 ?? 2C ?? 8B CA - 83 C9 ?? 3C ?? 8A 46 ?? 0F 47 CA 33 CF 69 F9 ?? ?? ?? ?? 84 C0 75 ?? 8B 4D ?? 8B 55 - ?? 81 FF ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 41 83 C0 ?? 89 4D ?? 89 45 ?? 3B 4A - ?? 75 ?? 33 C0 A3 ?? ?? ?? ?? 6A ?? FF D0 5F 5E 5B 8B E5 5D C3 - } - $create_net_host_trav_threads_v2 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 6A ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 64 A1 ?? ?? ?? ?? 83 C4 ?? 8B 40 ?? 50 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? A3 ?? - ?? ?? ?? E8 ?? ?? ?? ?? FF D0 85 C0 78 ?? A1 ?? ?? ?? ?? 8D 0C 85 ?? ?? ?? ?? E8 ?? - ?? ?? ?? A3 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? F0 FF 0D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B 35 - } - $fnv1a_hashing_v2 = { - 55 8B EC 83 EC ?? 64 A1 ?? ?? ?? ?? 8B 40 ?? 8B 40 ?? 8B 00 8B 50 ?? A1 ?? ?? ?? ?? - 89 55 ?? 85 C0 0F 85 ?? ?? ?? ?? 85 D2 75 ?? 33 C0 A3 ?? ?? ?? ?? 8B E5 5D C3 8B 42 - ?? 8B 4C 10 ?? 8B 44 10 ?? 89 45 ?? 8D 04 11 89 45 ?? 3B C2 74 ?? 53 33 C9 56 57 89 - 4D ?? 39 48 ?? 74 ?? 8B 78 ?? 03 FA 8B 07 BE - } - $decrypt_configuration_v2_1 = { - 55 8B EC 51 53 56 57 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 03 C9 83 EA ?? 75 ?? 68 ?? ?? ?? - ?? 68 ?? ?? ?? ?? BA 25 1B 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? BA 78 0C 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? - BA 39 28 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BA F1 40 - 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BA BF 11 00 00 B9 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BA 28 02 00 00 B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BA 3B 07 00 00 B9 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BA A5 04 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? BA 0F 03 00 00 B9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 33 C9 BE ?? ?? ?? ?? 85 FF 74 ?? 8B 15 ?? - ?? ?? ?? 0F 1F 44 00 ?? 80 3C 0A ?? 8D 46 ?? 0F 45 C6 41 8B F0 3B CF 72 ?? 8D 0C B5 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 89 1D ?? ?? ?? ?? 85 DB 74 ?? 33 FF 85 F6 74 ?? 90 - B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 89 04 BB 47 3B FE 72 ?? 8B 0D ?? ?? - ?? ?? 33 F6 E8 ?? ?? ?? ?? 85 C0 74 ?? 0F 1F 80 ?? ?? ?? ?? 8B 14 B3 8A 08 8D 40 ?? - 88 0A 8D 52 ?? 84 C9 75 ?? 33 C9 E8 ?? ?? ?? ?? 46 85 C0 75 ?? C7 04 B3 ?? ?? ?? ?? - 5F 5E 5B 8B E5 5D C3 - } - $decrypt_configuration_v2_2 = { - 55 8B EC 51 53 56 57 8B F2 8B F9 6B CE ?? E8 ?? ?? ?? ?? 8B C8 33 C0 89 4D ?? 85 C9 - 0F 84 ?? ?? ?? ?? 85 F6 74 ?? 83 FE ?? 72 ?? 0F 28 0D ?? ?? ?? ?? 8B CE 83 E1 ?? 66 - 0F 1F 84 00 ?? ?? ?? ?? 0F 10 04 07 66 0F EF C1 0F 11 04 07 0F 10 44 07 ?? 66 0F EF - C1 0F 11 44 07 ?? 0F 10 44 07 ?? 66 0F EF C1 0F 11 44 07 ?? 0F 10 44 07 ?? 66 0F EF - C1 0F 11 44 07 ?? 83 C0 ?? 3B C1 72 ?? 8B 4D ?? 3B C6 73 ?? 80 34 38 5F 40 3B C6 72 - ?? 8B 5D ?? 8B D6 51 53 51 8B CF E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 0B E8 ?? ?? - ?? ?? 8B F8 8B 45 ?? 89 38 8B 45 ?? 85 FF 74 ?? 8B 0B 8B F0 F3 A4 8B C8 BE ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B C6 5F 5E 5B 8B E5 5D C3 - } - $encrypt_files_v2_p1 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 56 57 66 90 64 A1 ?? ?? ?? ?? 0F 57 C0 C7 44 24 - ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 66 0F 13 44 24 ?? 8B 40 ?? 8B 40 ?? 8B 00 8B - 50 ?? A1 ?? ?? ?? ?? 89 54 24 ?? 85 C0 0F 85 ?? ?? ?? ?? 85 D2 0F 84 ?? ?? ?? ?? 8B - 42 ?? 8B 4C 10 ?? 8D 04 11 89 44 24 ?? 3B C2 74 ?? 33 C9 89 4C 24 ?? 39 48 ?? 74 ?? - 8B 40 ?? 03 C2 89 44 24 ?? 0F 1F 80 ?? ?? ?? ?? 8B 30 BF C5 9D 1C 81 8A 04 16 03 F2 - 46 84 C0 74 ?? 0F BE D0 8D 76 ?? 2C ?? 8B CA 83 C9 ?? 3C ?? 8A 46 ?? 0F 47 CA 33 CF - 69 F9 93 01 00 01 84 C0 75 ?? 8B 54 24 ?? 8B 4C 24 ?? 81 FF ?? ?? ?? ?? 74 ?? 8B 74 - 24 ?? 41 8B 44 24 ?? 83 C0 ?? 89 4C 24 ?? 89 44 24 ?? 3B 4E ?? 75 ?? 33 C0 A3 ?? ?? - ?? ?? 6A ?? 8D 4C 24 ?? 51 8D 4C 24 ?? 51 8D 4C 24 ?? 51 FF 35 ?? ?? ?? ?? FF D0 85 - C0 0F 88 ?? ?? ?? ?? 8B 74 24 ?? 85 F6 0F 84 ?? ?? ?? ?? 8B 7C 24 ?? 8B 07 48 83 F8 - ?? 0F 87 ?? ?? ?? ?? FF 24 85 ?? ?? ?? ?? 8B 74 24 ?? 8B 46 ?? 8D 04 48 0F B7 0C 10 - 8B 46 ?? 8D 04 88 8B 04 10 03 C2 EB ?? 83 7F ?? ?? 0F 85 ?? ?? ?? ?? 83 7F ?? ?? 0F - 85 ?? ?? ?? ?? C7 07 ?? ?? ?? ?? 8B 4C 24 ?? 8B 54 24 ?? 68 ?? ?? ?? ?? 6A ?? 8B 41 - ?? 89 42 ?? 8B 41 ?? 89 42 ?? 8B 44 24 ?? 6A ?? 8B 40 ?? 8D 88 ?? ?? ?? ?? F7 D8 23 - C8 8B 44 24 ?? 89 48 ?? 8D 4C 24 ?? 8B 54 24 ?? 8B 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? - 8D 84 24 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? - ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? FF 76 ?? FF 76 ?? FF 15 ?? ?? ?? ?? 8B 4E - ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 8B 46 ?? 81 C1 ?? ?? ?? ?? 03 C1 50 E8 ?? ?? ?? ?? - 8B 4C 24 ?? 83 C4 ?? 8B 74 24 ?? 89 74 24 ?? 6A ?? 8D 41 ?? 50 FF 71 ?? 8D 41 ?? FF - } - $encrypt_files_v2_p2 = { - 71 ?? 50 51 6A ?? 6A ?? FF 76 ?? E8 ?? ?? ?? ?? FF D0 85 C0 0F 89 ?? ?? ?? ?? 83 C8 - ?? F0 0F C1 46 ?? 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 46 ?? 83 C4 ?? - 33 FF 85 C0 0F 84 ?? ?? ?? ?? 83 C6 ?? 8B 0E E8 ?? ?? ?? ?? 8B 44 24 ?? 8D 76 ?? 47 - 8B 40 ?? 3B F8 72 ?? 8B 74 24 ?? 85 C0 E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 56 ?? 8B C1 - F0 0F B1 0A 83 F8 ?? 75 ?? 8B 46 ?? 89 44 24 ?? 0F B7 46 ?? 83 C0 ?? 8B C8 89 44 24 - ?? E8 ?? ?? ?? ?? 8B F8 85 FF 74 ?? 0F B7 4E ?? 51 FF 76 ?? 8D 4F ?? 51 E8 ?? ?? ?? - ?? 0F B7 46 ?? 83 C4 ?? 89 47 ?? 0F 57 C0 8D 44 24 ?? C6 07 ?? C7 47 ?? ?? ?? ?? ?? - 6A ?? FF 74 24 ?? 66 0F 13 44 24 ?? 57 50 FF 74 24 ?? E8 ?? ?? ?? ?? FF D0 8B CF E8 - ?? ?? ?? ?? 8D 56 ?? 85 F6 0F 84 ?? ?? ?? ?? 83 C8 ?? F0 0F C1 02 0F 85 ?? ?? ?? ?? - 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 4E ?? 83 C4 ?? C7 44 24 ?? ?? ?? ?? ?? 85 C9 0F 84 - ?? ?? ?? ?? 8D 7E ?? 90 8B 0F E8 ?? ?? ?? ?? 8B 44 24 ?? 8D 7F ?? 8B 4E ?? 40 89 44 - 24 ?? 3B C1 72 ?? E9 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 8D 56 ?? 74 ?? 8D 8C 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 47 ?? 8B 57 ?? 50 50 8D 47 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B - C1 6A ?? EB ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 47 ?? 8D 8C 24 ?? ?? ?? ?? 8B - 57 ?? 50 50 8D 47 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 54 24 ?? 83 C4 ?? 83 7A ?? ?? 8B 42 ?? 0F 8F ?? - ?? ?? ?? 7C ?? 39 42 ?? 0F 87 ?? ?? ?? ?? 8B 74 24 ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 4E - } - $encrypt_files_v2_p3 = { - 8D 84 24 ?? ?? ?? ?? 83 C4 ?? 81 C1 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 8B 46 ?? 03 C1 50 - E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? C7 00 ?? ?? ?? ?? EB ?? 8B 44 24 ?? C7 00 ?? ?? - ?? ?? 8B 4C 24 ?? 8B 74 24 ?? 6A ?? 89 74 24 ?? 8D 41 ?? 50 FF 71 ?? 8D 41 ?? FF 71 - ?? 50 51 6A ?? 6A ?? FF 76 ?? E8 ?? ?? ?? ?? FF D0 85 C0 0F 89 ?? ?? ?? ?? 83 C8 ?? - F0 0F C1 46 ?? 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 46 ?? 83 C4 ?? 33 - FF 85 C0 0F 84 ?? ?? ?? ?? 83 C6 ?? 8B 0E E8 ?? ?? ?? ?? 8B 44 24 ?? 8D 76 ?? 47 8B - 40 ?? 3B F8 72 ?? 8B 74 24 ?? 85 C0 E9 ?? ?? ?? ?? 83 C8 ?? F0 0F C1 46 ?? 0F 85 ?? - ?? ?? ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 4E ?? 83 C4 ?? C7 44 24 ?? ?? ?? ?? ?? 85 - C9 0F 84 ?? ?? ?? ?? 8D 7E ?? 66 0F 1F 44 00 ?? 8B 0F E8 ?? ?? ?? ?? 8B 44 24 ?? 8D - 7F ?? 8B 4E ?? 40 89 44 24 ?? 3B C1 72 ?? E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 56 ?? 8B - C1 F0 0F B1 0A 83 F8 ?? 75 ?? 8B 46 ?? 89 44 24 ?? 0F B7 46 ?? 83 C0 ?? 8B C8 89 44 - 24 ?? E8 ?? ?? ?? ?? 8B F8 85 FF 74 ?? 0F B7 4E ?? 51 FF 76 ?? 8D 4F ?? 51 E8 ?? ?? - ?? ?? 0F B7 46 ?? 83 C4 ?? 89 47 ?? 0F 57 C0 8D 44 24 ?? C6 07 ?? C7 47 ?? ?? ?? ?? - ?? 6A ?? FF 74 24 ?? 66 0F 13 44 24 ?? 57 50 FF 74 24 ?? E8 ?? ?? ?? ?? FF D0 8B CF - E8 ?? ?? ?? ?? 8D 56 ?? 85 F6 0F 84 ?? ?? ?? ?? 83 C8 ?? F0 0F C1 02 0F 85 ?? ?? ?? - ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 4E ?? 83 C4 ?? C7 44 24 ?? ?? ?? ?? ?? 85 C9 74 - ?? 8D 7E ?? 8B 0F E8 ?? ?? ?? ?? 8B 44 24 ?? 8D 7F ?? 8B 4E ?? 40 89 44 24 ?? 3B C1 - 72 ?? 85 C9 74 ?? F0 FF 05 ?? ?? ?? ?? F0 FF 0D ?? ?? ?? ?? 8B 46 ?? 85 C0 74 ?? 50 - E8 ?? ?? ?? ?? FF D0 8D 46 ?? 50 E8 ?? ?? ?? ?? FF D0 8B CE E8 ?? ?? ?? ?? E9 ?? ?? - ?? ?? 5F 33 C0 5E 8B E5 5D C2 - } - - condition: - uint16(0)==0x5A4D and ((($enum_resources_v1) and ( all of ($find_files_v1_*)) and ( all of ($encrypt_files_v1_*))) or (($check_blacklisted_languages_v2) and ($fnv1a_hashing_v2) and ($create_net_host_trav_threads_v2) and ( all of ($decrypt_configuration_v2_*)) and ( all of ($encrypt_files_v2_p*)))) -} -rule REVERSINGLABS_Win32_Ransomware_Zeoticus : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Zeoticus ransomware." - author = "ReversingLabs" - id = "483b20a4-2c16-5509-a503-2462a53d4d31" - date = "2021-03-19" - modified = "2021-03-19" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Zeoticus.yara#L1-L90" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "adf42b96139ad98f4253f3eba2c4af1be9545825605e0851185cc15284d9e9a0" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Zeoticus" - tc_detection_factor = 5 - importance = 25 - - strings: - $enum_shares_p1 = { - 53 55 8B 2D ?? ?? ?? ?? 8B C1 56 57 8B 3D ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 4C 24 ?? 51 8D 4C 24 ?? 51 - 8D 4C 24 ?? 51 6A ?? 8D 4C 24 ?? 51 6A ?? 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? 85 C0 74 - ?? 3D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 83 7C 24 ?? ?? 8B 5C 24 ?? 89 5C 24 ?? C7 44 24 - ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 33 F6 39 73 ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - 33 FF D5 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 33 FF D5 85 C0 0F 84 ?? ?? ?? ?? - 68 ?? ?? ?? ?? FF 33 FF D5 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 33 FF D5 85 C0 - 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 33 FF D5 85 C0 0F 84 ?? ?? ?? ?? FF 33 8D 44 24 - ?? FF 74 24 ?? 68 ?? ?? ?? ?? 50 FF D7 A1 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 83 C4 ?? 89 04 8D ?? ?? ?? ?? 8D 4C 24 ?? 51 - } - $enum_shares_p2 = { - 50 FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8D 04 85 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 56 FF 34 - 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 56 FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 04 8D ?? - ?? ?? ?? 41 FF 05 ?? ?? ?? ?? 89 0D ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 FF 85 C0 7E ?? 8D - 5F ?? 8D 44 24 ?? 50 FF 34 BD ?? ?? ?? ?? FF D5 85 C0 0F 44 F3 47 3B 3D ?? ?? ?? ?? - 7C ?? 8B 5C 24 ?? 85 F6 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 0D ?? ?? - ?? ?? 8B 3D ?? ?? ?? ?? 89 04 8D ?? ?? ?? ?? 8D 4C 24 ?? 51 68 ?? ?? ?? ?? 50 FF D7 - A1 ?? ?? ?? ?? 83 C4 ?? 8D 04 85 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 6A ?? FF 34 85 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 04 8D ?? ?? - ?? ?? 41 FF 05 ?? ?? ?? ?? 89 0D ?? ?? ?? ?? EB ?? 8B 3D ?? ?? ?? ?? 8B 74 24 ?? 83 - C3 ?? 46 89 5C 24 ?? 89 74 24 ?? 3B 74 24 ?? 0F 82 ?? ?? ?? ?? 8B 5C 24 ?? 53 FF 15 - ?? ?? ?? ?? 81 7C 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 0F 84 ?? ?? ?? ?? 5F 5E 5D 5B 81 C4 - ?? ?? ?? ?? C3 - } - $encrypt_files = { - 68 ?? ?? ?? ?? 6A ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? A3 ?? ?? - ?? ?? FF D0 68 ?? ?? ?? ?? 6A ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B F0 E8 ?? ?? ?? ?? - 83 C4 ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF D7 83 - C4 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D - 04 45 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 68 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? - FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 83 FB ?? 75 ?? E8 ?? ?? ?? ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? EB ?? 83 FB ?? 75 ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? - 56 6A ?? FF 35 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D6 E8 ?? - ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? FF B4 24 ?? ?? ?? ?? 51 E8 ?? ?? ?? - ?? 83 C4 ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 - } - $find_files = { - 81 EC ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 68 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? 8D 51 ?? 66 8B 01 - 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 66 83 7C 24 ?? ?? 56 8D 71 ?? 0F 85 ?? ?? ?? ?? - 55 8B 2D ?? ?? ?? ?? 57 8B 3D ?? ?? ?? ?? 66 90 66 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? - 66 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? 66 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? 66 83 7C 74 - ?? ?? 0F 85 ?? ?? ?? ?? 33 C0 66 89 44 74 ?? 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 - 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? 66 89 4C 74 ?? 85 C0 74 ?? 33 F6 90 - FF 34 B5 ?? ?? ?? ?? FF D7 83 F8 ?? 74 ?? 46 83 FE ?? 72 ?? 8D 44 24 ?? 50 FF 34 B5 - ?? ?? ?? ?? FF D5 68 ?? ?? ?? ?? 8D 44 24 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D - 4C 24 ?? 8D 51 ?? 66 90 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 66 83 7C 24 ?? - ?? 8D 71 ?? 0F 84 ?? ?? ?? ?? 5F 5D 53 FF 15 ?? ?? ?? ?? 5E 5B 81 C4 ?? ?? ?? ?? C3 - } - - condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ( all of ($enum_shares_p*)) -} -rule REVERSINGLABS_Win32_Ransomware_Garrantydecrypt : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects GarrantyDecrypt ransomware." - author = "ReversingLabs" - id = "0aa05f06-1773-5ce8-892d-04468f5deccc" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.GarrantyDecrypt.yara#L1-L79" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "7194c1e0e15a89f2c691a7d586b9db68295cc52a5f042d0f7eb558c326430444" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "GarrantyDecrypt" - tc_detection_factor = 5 - importance = 25 - - strings: - $encrypt_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 33 DB 53 53 8D 45 ?? 50 89 5D ?? FF D6 85 C0 75 - ?? 68 ?? ?? ?? ?? 6A ?? 53 53 8D 45 ?? 50 FF D6 85 C0 74 ?? 8B 45 ?? A3 ?? ?? ?? ?? - 3B C3 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 3B F3 0F 84 ?? ?? ?? ?? 8B 7E ?? 8B 46 - ?? 33 C9 3B FB 76 ?? 89 45 ?? 8D 85 ?? ?? ?? ?? 29 45 ?? 8B 55 ?? 8D 84 0D ?? ?? ?? - ?? 8A 14 02 41 88 10 3B CF 72 ?? 68 ?? ?? ?? ?? 53 53 FF 76 ?? FF 36 FF 35 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 3B FB 74 ?? 8B 46 ?? 68 ?? ?? ?? ?? 89 45 - ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 53 6A ?? 53 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B - 45 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? FF 36 E8 - ?? ?? ?? ?? FF 76 ?? E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? 53 FF - 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 53 FF 15 + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 33 DB 53 53 8D 45 ?? 50 89 5D ?? FF D6 85 C0 75 + ?? 68 ?? ?? ?? ?? 6A ?? 53 53 8D 45 ?? 50 FF D6 85 C0 74 ?? 8B 45 ?? A3 ?? ?? ?? ?? + 3B C3 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 3B F3 0F 84 ?? ?? ?? ?? 8B 7E ?? 8B 46 + ?? 33 C9 3B FB 76 ?? 89 45 ?? 8D 85 ?? ?? ?? ?? 29 45 ?? 8B 55 ?? 8D 84 0D ?? ?? ?? + ?? 8A 14 02 41 88 10 3B CF 72 ?? 68 ?? ?? ?? ?? 53 53 FF 76 ?? FF 36 FF 35 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 3B FB 74 ?? 8B 46 ?? 68 ?? ?? ?? ?? 89 45 + ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 53 6A ?? 53 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B + 45 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? FF 36 E8 + ?? ?? ?? ?? FF 76 ?? E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? 53 FF + 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 53 FF 15 } $encrypt_files_p2 = { 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8D 45 ?? 50 6A ?? 5F 57 FF 35 ?? ?? ?? ?? FF 15 @@ -38999,18 +39460,18 @@ rule REVERSINGLABS_Win32_Ransomware_Garrantydecrypt : TC_DETECTION MALICIOUS MAL condition: uint16(0)==0x5A4D and $find_files and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Chichi : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Paradise : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects ChiChi ransomware." + description = "Yara rule that detects Paradise ransomware." author = "ReversingLabs" - id = "95062789-a55d-5c1c-a359-206b58f311e5" - date = "2022-02-14" - modified = "2022-02-14" + id = "9a92a05c-5f26-59ed-9934-a24bb7c31d8d" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.ChiChi.yara#L1-L66" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "863a30e4c708e13ea0f4c6ad42a919de463926508783d6552c0cec746730baa5" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Paradise.yara#L1-L81" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "fc029bee999ec72416ac91d8386d4d270070035ad078bcab1dec11eea032c10b" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -39018,46 +39479,131 @@ rule REVERSINGLABS_Win32_Ransomware_Chichi : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "ChiChi" + tc_detection_name = "Paradise" tc_detection_factor = 5 importance = 25 strings: - $generate_key = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? - 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B D9 8B 7D ?? C7 45 ?? ?? ?? ?? ?? 89 7D ?? 85 - FF 75 ?? 33 F6 EB ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 89 75 ?? 6A ?? 8D 4D ?? C7 45 - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 56 8D - 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? 85 C0 74 - ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 8B 03 8B CB 57 56 FF 50 ?? C7 45 ?? ?? ?? ?? ?? 85 F6 - 74 ?? 83 FF ?? 8D 45 ?? 8D 4D ?? 8B FE 0F 46 C8 32 C0 56 8B 09 F3 AA E8 ?? ?? ?? ?? - 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C2 + $search_files = { + 53 56 57 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 59 89 75 ?? 85 F6 + 0F 84 ?? ?? ?? ?? FF 75 ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? 53 56 FF + D7 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 0F 84 ?? ?? + ?? ?? 83 65 ?? ?? 8B 45 ?? 8B 74 85 ?? 8D 95 ?? ?? ?? ?? 85 F6 74 ?? 0F B7 02 83 F8 + ?? 72 ?? 8D 48 ?? 83 F8 ?? 76 ?? 8B C8 0F B7 06 83 F8 ?? 72 ?? 83 F8 ?? 77 ?? 83 C0 + ?? 3B C8 0F B7 02 75 ?? 66 85 C0 74 ?? 83 C2 ?? 83 C6 ?? EB ?? 0F B7 02 EB ?? 66 3B + 06 1B C0 83 E0 ?? 40 EB ?? 33 C0 85 C0 0F 84 ?? ?? ?? ?? FF 45 ?? 83 7D ?? ?? 72 ?? + 8B 75 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? 68 ?? ?? ?? ?? 53 56 FF D7 83 C4 ?? F6 85 ?? + ?? ?? ?? ?? 74 ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? BA ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 80 3D ?? ?? ?? ?? ?? 74 ?? BA + ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? EB ?? F6 85 ?? ?? ?? + ?? ?? 74 ?? A1 ?? ?? ?? ?? 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 85 C0 75 ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? BA ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? + ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? 68 + ?? ?? ?? ?? 53 FF 75 ?? FF D7 83 C4 ?? FF 75 ?? E8 ?? ?? ?? ?? 59 FF 75 ?? FF 15 ?? + ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 59 5F 5E 5B C9 C3 } - $encrypt_files = { - 55 8B EC 51 53 56 57 8B D9 68 ?? ?? ?? ?? 53 89 5D ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? - ?? ?? 53 FF D6 68 ?? ?? ?? ?? 8B F8 FF D6 8B 1D ?? ?? ?? ?? 03 F8 03 FF 83 C7 ?? 57 - 6A ?? FF 35 ?? ?? ?? ?? FF D3 8B F0 85 F6 74 ?? 8B 7D ?? 57 56 FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 56 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5B - 8B E5 5D C3 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? - ?? 56 6A ?? FF 35 ?? ?? ?? ?? 8B F8 FF 15 ?? ?? ?? ?? 83 FF ?? 74 ?? 8B CF E8 ?? ?? - ?? ?? 5F 5E 5B 8B E5 5D C3 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 + $encrypt_files_p1 = { + 56 57 6A ?? BE ?? ?? ?? ?? 5F E8 ?? ?? ?? ?? 89 45 ?? 6A ?? 8D 45 ?? 50 56 E8 ?? ?? + ?? ?? 83 C4 ?? 83 C6 ?? 4F 75 ?? 33 F6 39 75 ?? 74 ?? 8D 45 ?? 50 A1 ?? ?? ?? ?? 0F + B7 88 ?? ?? ?? ?? 56 56 51 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 59 89 4D + ?? 33 C0 8A 90 ?? ?? ?? ?? 88 90 ?? ?? ?? ?? 3B C6 75 ?? 33 C0 40 3B C1 72 ?? 68 ?? + ?? ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 6A ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? + FF 15 ?? ?? ?? ?? 5F 5E C9 C3 56 FF 75 ?? FF 15 ?? ?? ?? ?? 56 FF 15 + } + $encrypt_files_p2 = { + 53 56 57 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 33 DB + 53 53 8D 44 24 ?? 50 89 5C 24 ?? FF D6 85 C0 75 ?? 68 ?? ?? ?? ?? 6A ?? 53 53 8D 44 + 24 ?? 50 FF D6 85 C0 75 ?? 89 5C 24 ?? 39 5C 24 ?? 75 ?? 53 FF 15 ?? ?? ?? ?? A1 ?? + ?? ?? ?? 0F B6 80 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF + 74 24 ?? E8 ?? ?? ?? ?? 59 53 FF 74 24 ?? FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 53 53 + 53 53 C6 05 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 88 1D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 59 33 C0 88 98 ?? ?? ?? ?? 3B C3 75 ?? 33 C0 40 83 F8 ?? 72 ?? 6A ?? 5E + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 + ?? 6A ?? 53 53 8D 44 24 ?? 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 4E 75 ?? 8B 3D ?? + ?? ?? ?? 81 C7 ?? ?? ?? ?? 6A ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 85 C0 75 ?? 57 E8 + ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C3 + } + $http_remote_connection = { + 53 56 57 FF 75 ?? 33 FF 8D 75 ?? 89 7D ?? E8 ?? ?? ?? ?? 59 89 7D ?? 57 57 57 FF 75 + ?? 57 FF 15 ?? ?? ?? ?? 89 45 ?? 3B C7 0F 84 ?? ?? ?? ?? 57 57 6A ?? 57 57 FF 75 ?? + FF 75 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 3B C7 0F 84 ?? ?? ?? ?? 33 C9 80 7D ?? ?? 57 + 0F 95 C1 B8 ?? ?? ?? ?? 49 23 C8 03 C8 51 57 57 57 FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? + FF 15 ?? ?? ?? ?? 8B D8 3B DF 74 ?? 57 57 57 57 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 33 + F6 57 57 8D 45 ?? 50 53 89 7D ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 03 C6 3B C7 + 75 ?? 89 7D ?? EB ?? 50 39 7D ?? 75 ?? E8 ?? ?? ?? ?? 59 EB ?? FF 75 ?? 6A ?? FF 15 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 FF 75 ?? 8B 45 ?? 03 C6 50 53 + FF 15 ?? ?? ?? ?? 03 75 ?? 39 7D ?? 75 ?? 53 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? + ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 39 7D ?? 75 ?? 33 C0 40 39 45 ?? 74 ?? 89 45 ?? E9 + ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 5F 5E 5B + C9 C3 } + + condition: + uint16(0)==0x5A4D and $search_files and $http_remote_connection and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Khonsari : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Khonsari ransomware." + author = "ReversingLabs" + id = "c3c64256-af1f-5a9d-8a59-8d72993bb8da" + date = "2022-01-27" + modified = "2022-01-27" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Khonsari.yara#L1-L68" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "f1003b7863215bcd8e5cdce8ce40551105fb668ea2b8ac765909f9fa5373e6ca" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Khonsari" + tc_detection_factor = 5 + importance = 25 + + strings: $find_files = { - 6A ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 56 FF 15 ?? - ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF 74 24 ?? 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF - D7 8D 44 24 ?? 50 53 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 - ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 33 F6 FF B6 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 83 C6 ?? 81 FE ?? ?? ?? ?? 72 ?? FF 74 24 ?? 8B 74 24 ?? - 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 56 FF 15 ?? - ?? ?? ?? F6 44 24 ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? - ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 83 E8 ?? 78 ?? 66 83 - 7C 44 ?? ?? 74 ?? 83 E8 ?? 79 ?? EB ?? 8D 74 24 ?? 8D 34 46 68 ?? ?? ?? ?? 56 FF 15 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 + 73 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? + 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 0B + 16 0C 2B ?? 07 08 9A 0D 09 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 72 ?? + ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 09 + 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 08 17 58 0C 08 07 8E 69 32 ?? 06 1B 28 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 06 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 06 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 + ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 06 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 2D ?? 00 11 + ?? 7E ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 11 ?? 72 ?? + ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F + ?? ?? ?? ?? DC DE ?? 26 DE ?? 12 ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE 16 ?? + ?? ?? ?? 6F ?? ?? ?? ?? DC 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? + 28 ?? ?? ?? ?? 26 2A + } + $get_key = { + 73 ?? ?? ?? ?? 0A 06 12 ?? FE 15 ?? ?? ?? ?? 12 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 + ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7D + ?? ?? ?? ?? 12 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 72 ?? + ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 07 6F ?? + ?? ?? ?? 06 02 7B ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 11 + ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 06 02 7B ?? ?? ?? ?? 17 6F ?? + ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? DC 08 2A + } + $encrypt_files = { + 28 ?? ?? ?? ?? 0A 06 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 61 13 ?? 11 ?? 6F ?? ?? ?? ?? 06 20 + ?? ?? ?? ?? 20 ?? ?? ?? ?? 61 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 6F ?? ?? + ?? ?? 06 19 6F ?? ?? ?? ?? 06 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 02 7B ?? ?? ?? ?? 6F + ?? ?? ?? ?? 06 06 6F ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 02 03 07 28 ?? ?? + ?? ?? 0C DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC 06 2C ?? 06 6F ?? ?? ?? ?? DC 08 2A } condition: - uint16(0)==0x5A4D and ($find_files) and ($generate_key) and ($encrypt_files) + uint16(0)==0x5A4D and ($find_files) and ($get_key) and ($encrypt_files) } rule REVERSINGLABS_Win32_Ransomware_Teslacrypt : TC_DETECTION MALICIOUS MALWARE FILE { @@ -39068,8 +39614,8 @@ rule REVERSINGLABS_Win32_Ransomware_Teslacrypt : TC_DETECTION MALICIOUS MALWARE date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Teslacrypt.yara#L1-L665" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Teslacrypt.yara#L1-L665" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "cc054be68d833d9f29a4ebd1c202922881b0d22a2605edc7def1048dc08f6325" score = 75 quality = 65 @@ -39652,19 +40198,18 @@ rule REVERSINGLABS_Win32_Ransomware_Teslacrypt : TC_DETECTION MALICIOUS MALWARE condition: uint16(0)==0x5A4D and (($file_search_0_3_1_1 and $file_search_0_3_1_2 and $encrypt_file_0_2_6a_1 and $encrypt_file_0_2_6a_2 and $server_communication_0_2_6a_1 and $server_communication_0_2_6a_2) or ($file_search_0_3_1_1 and $file_search_0_3_1_2 and $encrypt_file_0_3_1 and $server_communication_0_3_1_1 and $server_communication_0_3_1_2) or ($file_search_0_3_3_1 and $file_search_0_3_3_2 and $encrypt_file_0_3_3_1 and $encrypt_file_0_3_3_2 and $server_communication_0_3_3_1 and $server_communication_0_3_3_2) or ($file_search_0_3_4a_1 and $file_search_0_3_4a_2 and $encrypt_file_0_3_4a_1 and $encrypt_file_0_3_4a_2 and $server_communication_0_3_4a_1 and $server_communication_0_3_4a_2) or ($file_search_0_3_5a_1 and $file_search_0_3_5a_2 and $encrypt_file_0_3_5a_1 and $encrypt_file_0_3_5a_2 and $server_communication_0_3_5a_1 and $server_communication_0_3_5a_2) or ($server_communication_2_0_4e and $search_and_encrypt_2_0_4e_1 and $search_and_encrypt_2_0_4e_2 and $search_and_encrypt_2_0_4e_3 and $search_and_encrypt_2_0_4e_4 and $search_and_encrypt_2_0_4e_5) or ($server_communication_4_0_1 and $server_communication_4_0_2 and $server_communication_4_0_3 and $file_search_4_0_1 and $file_search_4_0_2 and $file_search_4_0_3) or ($file_search_4_1b_1 and $file_search_4_1b_2 and $file_search_4_1b_3 and $server_communication_4_1b_1 and $server_communication_4_1b_2 and $server_communication_4_1b_3 and $server_communication_4_1b_4 and $server_communication_4_1b_5) or ($file_search_4_2_1 and $file_search_4_2_2 and $server_communication_4_1b_1 and $server_communication_4_2_1 and $server_communication_4_2_2 and $server_communication_4_2_3 and $server_communication_4_2_4 and $server_communication_4_2_5) or ($server_communication_4_0_1 and $server_communication_3_1 and $server_communication_3_2 and $file_search_3_1 and $file_search_3_1_1 and $file_search_3_1_2 and $search_and_encrypt_3_1 and $search_and_encrypt_3_2 and $search_and_encrypt_3_3 and $search_and_encrypt_3_4) or ($server_communication_4_0_1 and $server_communication_3_1 and $server_communication_3_2 and $file_search_3_1 and $file_search_3_2_1 and $file_search_3_2_2 and $search_and_encrypt_3_1 and $search_and_encrypt_3_2 and $search_and_encrypt_3_3 and $search_and_encrypt_3_4)) } -rule REVERSINGLABS_Win32_Ransomware_ONI : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Sepsis : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Oni ransomware." + description = "Yara rule that detects Sepsis ransomware." author = "ReversingLabs" - id = "9190aee2-1119-546e-82ca-a7aba44a9d7f" - date = "2024-08-04" - date = "2024-08-04" - modified = "2020-12-07" + id = "0c26d6e0-1d64-5f47-8e21-6710a531bc74" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Oni.yara#L1-L82" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "685abf5a5edba5bae19faaf6521ce617370cdab1404fe84d846e82a60182dfff" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Sepsis.yara#L1-L126" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "171ad074a780b45195c6e02b111b3883c58a4028e635c4d6b8ce27c5e05e35d7" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -39672,74 +40217,116 @@ rule REVERSINGLABS_Win32_Ransomware_ONI : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" + tc_detection_name = "Sepsis" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? - 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? - 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? - ?? 53 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? F6 85 ?? ?? ?? ?? - ?? 0F 84 ?? ?? ?? ?? 83 EC ?? 8B D4 C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C6 02 - ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 33 C9 EB ?? 8D 8D ?? ?? ?? ?? 8D 71 ?? 90 8A 01 41 84 - C0 75 ?? 2B CE 51 8D 85 ?? ?? ?? ?? 8B CA 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 84 C0 74 ?? 83 EC ?? 8D 45 ?? 8B CC 6A ?? 6A ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? - ?? ?? 50 C6 01 ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC 6A ?? 6A ?? C7 41 ?? ?? ?? - ?? ?? C7 41 ?? ?? ?? ?? ?? 50 C6 01 ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF - 15 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 75 - ?? 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 ?? 72 ?? 83 F9 ?? 77 ?? 8B C8 51 E8 ?? ?? ?? ?? - 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 F8 ?? 72 - ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 75 ?? 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 - ?? 72 ?? 83 F9 ?? 77 ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 5F 5E 33 CD 5B E8 - ?? ?? ?? ?? 8B E5 5D C3 + $search_files_1 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 8B 5D ?? 8D 84 24 ?? ?? ?? ?? 56 57 8B 3D ?? + ?? ?? ?? 68 ?? ?? ?? ?? 53 50 FF D7 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 8D 4C 24 ?? 89 44 24 ?? 51 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 } - $encrypt_files = { - 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 57 8B 3D ?? ?? ?? ?? 8D 45 ?? 68 - ?? ?? ?? ?? 6A ?? 33 F6 89 55 ?? 56 56 50 89 4D ?? 89 75 ?? FF D7 85 C0 75 ?? 68 ?? - ?? ?? ?? 6A ?? 50 50 8D 45 ?? 50 FF D7 8B 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 53 8D 45 ?? - 89 75 ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D0 E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 - DB 74 ?? 8D 45 ?? 50 6A ?? 6A ?? FF 75 ?? 53 57 FF 15 ?? ?? ?? ?? 53 6A ?? FF 15 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? - ?? ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? 8B F0 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 56 6A ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? - 8B 4D ?? 85 C9 74 ?? 8B 45 ?? 89 01 53 FF 15 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? - 5B 8B 4D ?? 8B C6 5F 33 CD 5E E8 ?? ?? ?? ?? 8B E5 5D C3 + $search_files_2 = { + 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 + ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 + 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 + ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 + 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? 68 ?? ?? ?? + ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? F6 44 24 ?? ?? 8D 44 24 ?? 50 53 8D 84 24 ?? ?? + ?? ?? 50 74 ?? FF D7 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? EB ?? FF D7 8D 44 24 ?? + 50 FF 15 ?? ?? ?? ?? 8B D0 8D 7A } - $search_processes = { - 6A ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 - ?? ?? ?? ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? - ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 B9 - ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 44 24 ?? ?? 8D 84 24 ?? ?? ?? ?? FF 74 24 ?? C7 05 ?? - ?? ?? ?? ?? ?? ?? ?? 50 8D 44 24 ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 50 C7 05 ?? ?? ?? - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? 83 EE ?? 4F 83 7E - ?? ?? 72 ?? 8B 1E 8B CE 56 E8 ?? ?? ?? ?? 8B 46 ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C3 ?? - 75 ?? 8B 43 ?? 3B C3 73 ?? 2B D8 83 FB ?? 72 ?? 83 FB ?? 77 ?? 8B D8 53 E8 ?? ?? ?? - ?? 83 C4 ?? C7 46 ?? ?? ?? ?? ?? 83 7E ?? ?? C7 46 ?? ?? ?? ?? ?? 72 ?? 8B 06 EB ?? - 8B C6 8B CE C6 00 ?? E8 ?? ?? ?? ?? 85 FF 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 5F 5E 5B 8B E5 5D C3 E8 ?? ?? ?? ?? CC CC CC CC CC B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? B9 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? C7 05 ?? ?? ?? ?? - ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 C3 + $search_files_3 = { + 66 8B 0A 83 C2 ?? 66 85 C9 75 ?? 2B D7 D1 FA 83 FA ?? 75 ?? 66 83 78 ?? ?? 74 ?? 8D + 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 15 + ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B 8B + E5 5D C2 + } + $search_files_4 = { + 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 + ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 + 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 + ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 + 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 + ?? 50 FF D6 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? F6 44 24 ?? + ?? 8D 44 24 ?? 50 53 8D 84 24 ?? ?? ?? ?? 50 74 ?? FF D7 8D 84 24 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? EB ?? FF D7 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8B D0 8D 7A ?? 66 8B 0A 83 + C2 ?? 66 85 C9 75 ?? 2B D7 D1 FA 83 FA ?? 75 ?? 66 83 78 ?? ?? 74 ?? 8D 8C 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? + 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B 8B E5 5D C2 + } + $encrypt_files_1 = { + BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 6A ?? FF D6 0F 10 05 ?? ?? ?? ?? 8B F8 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 50 0F 11 07 89 3D ?? ?? ?? ?? 0F 10 05 ?? ?? ?? ?? 0F 11 47 ?? 0F 10 05 ?? + ?? ?? ?? 0F 11 47 ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 8D + 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 FF E9 ?? ?? ?? ?? 8D 45 ?? 50 8D + 45 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? FF 15 ?? ?? + ?? ?? 85 C0 75 ?? 33 FF E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 45 ?? 50 + FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 FF E9 ?? ?? ?? ?? 8D 45 ?? 50 FF 75 ?? 6A ?? FF 75 + ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 FF EB ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B CF 8D 51 + } + $encrypt_files_2 = { + 8A 01 41 84 C0 75 ?? 2B CA 8D 45 ?? 51 50 6A ?? 6A ?? 6A ?? 6A ?? FF 75 ?? 89 4D ?? + 89 4D ?? FF D3 85 C0 75 ?? 33 FF EB ?? FF 75 ?? FF D6 FF 75 ?? 8B F0 6A ?? 56 E8 ?? + ?? ?? ?? FF 75 ?? 57 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? FF 75 ?? 50 56 6A ?? 6A ?? + 6A ?? FF 75 ?? FF D3 8B F8 F7 DF 1B FF 23 FE 8B 35 ?? ?? ?? ?? 8B D7 8D 4A ?? 66 90 + 8A 02 42 84 C0 75 ?? 2B D1 8B CF E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 8D 50 ?? 8A 08 40 84 + C9 75 ?? 2B C2 57 A3 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 81 3D ?? ?? ?? ?? ?? ?? + ?? ?? 0F 82 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 + } + $encrypt_files_3 = { + 55 8B EC 83 EC ?? 57 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B C1 68 ?? ?? ?? ?? 50 + 89 45 ?? FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 75 ?? 0B C0 5F 8B E5 5D C3 53 6A ?? 57 FF + 15 ?? ?? ?? ?? 8B D8 83 FB ?? 75 ?? FF 75 ?? 57 FF 15 ?? ?? ?? ?? 8B D8 56 B8 ?? ?? + ?? ?? 6A ?? 3B D8 0F 47 D8 53 6A ?? 6A ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? + 75 ?? 5E 5B 0B C0 5F 8B E5 5D C3 6A ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 56 8B + 35 ?? ?? ?? ?? 89 45 ?? FF D6 57 FF D6 E8 ?? ?? ?? ?? 0F 10 05 ?? ?? ?? ?? 0F 11 05 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B F8 BE ?? ?? ?? ?? 0F 10 05 ?? ?? ?? ?? 0F 11 + 05 ?? ?? ?? ?? 85 DB 74 + } + $encrypt_files_4 = { + 8A 0C 06 8D 40 ?? 30 48 ?? 83 EA ?? 75 ?? 8B CF E8 ?? ?? ?? ?? 8B F7 83 C7 ?? 83 EB + ?? 75 ?? 8B 45 ?? 0F 10 06 50 0F 11 05 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 83 C4 ?? 8B F2 + } + $encrypt_files_5 = { + 66 8B 02 83 C2 ?? 66 85 C0 75 ?? BB ?? ?? ?? ?? 2B D6 8D 7B ?? 66 8B 47 ?? 83 C7 ?? + 66 85 C0 75 ?? 8B CA C1 E9 ?? F3 A5 8B CA 83 E1 ?? 83 C3 ?? F3 A4 66 8B 43 ?? 83 C3 + ?? 66 85 C0 75 ?? 8B FB B9 ?? ?? ?? ?? 8B 5D ?? BE ?? ?? ?? ?? 68 ?? ?? ?? ?? F3 A5 + 53 FF 15 ?? ?? ?? ?? 6A ?? 8B F0 6A ?? 56 FF 15 ?? ?? ?? ?? 56 FF 35 ?? ?? ?? ?? 6A + ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? + 53 FF 15 ?? ?? ?? ?? 5E 5B 33 C0 5F 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($search_processes) and ($find_files) and ($encrypt_files) + uint16(0)==0x5A4D and ( all of ($search_files_*)) and ( all of ($encrypt_files_*)) } -rule REVERSINGLABS_Win32_Ransomware_Henry : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Cobralocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Henry ransomware." + description = "Yara rule that detects CobraLocker ransomware." author = "ReversingLabs" - id = "63627f2b-3205-5790-ba97-8e0d1da39d7c" - date = "2021-06-14" - modified = "2021-06-14" + id = "dada6370-3ae3-5931-ba9f-da56ebbcd8c8" + date = "2021-08-12" + modified = "2021-08-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Henry.yara#L1-L80" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "e6ab2a8a344d40407118e29ff78f5a0144f42a0fbdee19a80b341b59f056d292" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Bytecode.MSIL.Ransomware.CobraLocker.yara#L1-L59" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "95f4c645c7c237d23b5028f824f78a5f9f8f0a4737b391d877582afe08264d7e" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -39747,69 +40334,56 @@ rule REVERSINGLABS_Win32_Ransomware_Henry : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Henry" + tc_detection_name = "CobraLocker" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 02 6F ?? ?? ?? ?? 0A 16 0B 2B ?? 06 07 9A 0C 08 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? - ?? ?? DE ?? 26 DE ?? 07 17 58 0B 07 06 8E 69 32 ?? 02 6F ?? ?? ?? ?? 0D 16 0B 38 ?? ?? - ?? ?? 09 07 9A 13 ?? 11 ?? 6F ?? ?? ?? ?? 19 17 73 ?? ?? ?? ?? 25 6F ?? ?? ?? ?? D4 8D - ?? ?? ?? ?? 13 ?? 25 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 26 6F ?? ?? ?? ?? 11 ?? 6F ?? - ?? ?? ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 18 18 73 ?? ?? ?? ?? 25 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 6F ?? ?? ?? - ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 07 17 58 0B 07 09 8E 69 3F ?? ?? - ?? ?? 2A - } $encrypt_files = { - 02 8E 2D ?? 72 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 03 28 ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 73 - ?? ?? ?? ?? 7A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 28 ?? - ?? ?? ?? 0D 73 ?? ?? ?? ?? 13 ?? 03 08 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 1F ?? 6F ?? ?? ?? - ?? 07 6F ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 17 73 ?? ?? ?? ?? 25 02 16 02 8E 69 6F ?? ?? ?? - ?? 25 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 0A 11 ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? - 25 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 FE ?? 09 6F ?? ?? ?? ?? DC 06 2A - } - $setup_environment = { - 02 28 ?? ?? ?? ?? 1B 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 73 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 1F ?? 28 - ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 02 28 ?? ?? ?? ?? 2A + 14 0A 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? 0C 00 73 ?? + ?? ?? ?? 0D 00 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 + 03 07 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? + ?? 6F ?? ?? ?? ?? 00 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 + 09 17 6F ?? ?? ?? ?? 00 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 00 11 ?? 02 16 02 + 8E 69 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 00 DD ?? ?? ?? ?? 11 ?? 38 ?? ?? ?? ?? + 38 ?? ?? ?? ?? 39 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 00 DC 08 6F ?? ?? ?? ?? 0A 00 DD ?? + ?? ?? ?? 09 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 39 ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 00 DC 00 DD + ?? ?? ?? ?? 08 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 39 ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 00 DC 06 + 13 ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 11 ?? 2A } - $init_components = { - 02 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 02 - 7B ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 22 ?? ?? ?? ?? 16 19 - 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 20 ?? ?? ?? ?? 1F ?? 73 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? - ?? ?? 20 ?? ?? ?? ?? 1F ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 16 6F ?? ?? - ?? ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 17 6F ?? ?? ?? - ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 22 ?? ?? ?? ?? 16 19 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 20 ?? ?? ?? ?? 1F ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 - 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 20 ?? ?? ?? ?? 20 ?? ?? - ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 02 7B ?? ?? ?? - ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 22 ?? ?? ?? ?? 22 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 02 17 28 ?? ?? ?? ?? 02 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 02 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 02 7B ?? ?? - ?? ?? 6F ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 02 02 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 16 28 ?? ?? ?? ?? 02 28 ?? ?? - ?? ?? 2A + $find_files = { + 16 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 0C 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 06 72 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 13 ?? 08 72 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 72 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 13 ?? 09 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? + ?? ?? ?? 16 28 ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 + 28 ?? ?? ?? ?? 13 ?? 73 ?? ?? ?? ?? 13 ?? 72 ?? ?? ?? ?? 13 ?? 16 13 ?? 38 ?? ?? ?? ?? + 00 11 ?? 11 ?? 11 ?? 9A 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 + FE 04 13 ?? 11 ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 00 11 ?? 11 ?? 11 ?? 9A 11 ?? 6F ?? ?? + ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 FE 04 13 ?? 11 ?? 38 ?? ?? ?? ?? 38 ?? + ?? ?? ?? 00 11 ?? 11 ?? 11 ?? 9A 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 + ?? 8E 69 FE 04 13 ?? 11 ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 00 11 ?? 11 ?? 11 ?? 9A 11 ?? + 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 FE 04 13 ?? 11 ?? 38 ?? ?? ?? + ?? 38 ?? ?? ?? ?? 3A ?? ?? ?? ?? 16 13 ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 3A ?? ?? ?? ?? + 16 13 ?? 38 ?? ?? ?? ?? 38 ?? ?? ?? ?? 3A ?? ?? ?? ?? 16 13 ?? 38 ?? ?? ?? ?? 38 ?? ?? + ?? ?? 3A ?? ?? ?? ?? 2A } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($setup_environment) and ($init_components) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) } -rule REVERSINGLABS_Win64_Ransomware_Awesomescott : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Jamper : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects AwesomeScott ransomware." + description = "Yara rule that detects Jamper ransomware." author = "ReversingLabs" - id = "36d3b801-dbdb-585a-ac80-1827a6749c87" - date = "2020-09-16" - modified = "2020-09-16" + id = "9ba9358e-8f67-5d0e-a9bc-b3b10cd3a8b2" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.AwesomeScott.yara#L1-L101" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ed8096a4abbd015f79f4ec7239cd4070194ad70fa03da6714e499a41f9fb9423" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Jamper.yara#L1-L110" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "826f8fa7cc92b279c609a9ab6a87c32940e37b4c2476854af75bbed29cb3eaf2" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -39817,102 +40391,102 @@ rule REVERSINGLABS_Win64_Ransomware_Awesomescott : TC_DETECTION MALICIOUS MALWAR sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "AwesomeScott" + tc_detection_name = "Jamper" tc_detection_factor = 5 importance = 25 strings: $encrypt_files_p1 = { - 48 8B C4 48 89 58 ?? 48 89 68 ?? 48 89 70 ?? 57 41 54 41 55 41 56 41 57 48 83 EC ?? - 45 33 FF 4C 8B F2 49 8B D8 4C 89 78 ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 4C - 89 78 ?? 4C 89 78 ?? 4C 89 78 ?? 4C 89 78 ?? B8 ?? ?? ?? ?? 48 8B F1 45 33 C9 44 8B - C0 8B D0 49 8B CE 45 32 ED 48 83 CD ?? 49 8B FF FF 15 ?? ?? ?? ?? 4C 8B E0 48 3B C5 - 75 ?? FF 15 ?? ?? ?? ?? 8B D8 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 48 ?? E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 8D 48 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 83 C0 ?? 44 8B C3 48 8B C8 E8 ?? ?? - ?? ?? E9 ?? ?? ?? ?? 45 33 C9 4C 89 7C 24 ?? 48 8B CB 41 8D 51 ?? 45 8D 41 ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B E8 48 83 F8 ?? 75 - ?? FF 15 ?? ?? ?? ?? 8B D8 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 48 ?? E8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 8D 48 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 83 C0 ?? 44 8B C3 48 8B C8 E8 ?? ?? ?? - ?? E9 ?? ?? ?? ?? BB ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 8D 4C 24 ?? 33 D2 44 8B CB - } + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D + ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 55 ?? + 89 45 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 DB 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? 8B + 45 ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 + 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? + 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 6A ?? 8B 4D ?? B2 ?? A1 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 10 FF 12 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 83 + BD ?? ?? ?? ?? ?? 75 ?? 83 BD ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? EB ?? 0F 8E ?? ?? ?? + ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 76 ?? EB ?? 7E ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? 89 85 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 + ?? ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 85 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 83 FB ?? 7F ?? B8 + } $encrypt_files_p2 = { - 44 89 7C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? - 4C 8D 05 ?? ?? ?? ?? 48 8D 4C 24 ?? 44 8B CB 33 D2 C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 4C - 24 ?? 48 8D 44 24 ?? 45 33 C9 45 33 C0 BA ?? ?? ?? ?? 48 89 44 24 ?? FF 15 ?? ?? ?? - ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 0D ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8D 15 ?? ?? ?? ?? 44 8B C0 45 33 C9 FF 15 - ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 8B - 44 24 ?? 48 8B 4C 24 ?? 48 8D 44 24 ?? 41 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 44 24 - ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? E9 ?? ?? ?? - ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B F8 48 85 C0 75 ?? 41 B8 ?? ?? ?? ?? 48 8D 15 - ?? ?? ?? ?? E9 ?? ?? ?? ?? 32 DB 90 4C 8D 4C 24 ?? 41 B8 ?? ?? ?? ?? 48 8B D7 49 8B - CC 4C 89 7C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 81 7C 24 ?? ?? ?? ?? ?? - 48 8B 4C 24 ?? B8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 0F B6 DB 0F 42 D8 48 8D 44 24 - ?? 45 33 C9 48 89 44 24 ?? 44 0F B6 C3 33 D2 48 89 7C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 - } - $encrypt_files_p3 = { - 74 ?? 44 8B 44 24 ?? 4C 8D 4C 24 ?? 48 8B D7 48 8B CD 4C 89 7C 24 ?? FF 15 ?? ?? ?? - ?? 85 C0 74 ?? 84 DB 0F 84 ?? ?? ?? ?? 41 B5 ?? EB ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? - ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 48 8D - 15 ?? ?? ?? ?? 44 8B C0 48 8B CE E8 ?? ?? ?? ?? 4D 85 E4 74 ?? 49 8B CC FF 15 ?? ?? - ?? ?? 48 85 ED 74 ?? 48 8B CD FF 15 ?? ?? ?? ?? 48 85 FF 74 ?? 48 8B CF E8 ?? ?? ?? - ?? 48 8B 4C 24 ?? 48 85 C9 74 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 8B - D8 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 48 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C - 8D 05 ?? ?? ?? ?? 48 8D 48 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 - 8D 15 ?? ?? ?? ?? 48 83 C0 ?? 44 8B C3 48 8B C8 E8 ?? ?? ?? ?? 4C 89 7C 24 ?? 48 8B - 4C 24 ?? 48 85 C9 74 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 8B D8 E8 ?? - ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 48 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? - ?? ?? ?? 48 8D 48 ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 15 ?? - ?? ?? ?? 48 83 C0 ?? 44 8B C3 48 8B C8 E8 ?? ?? ?? ?? 48 8B 4C 24 + E8 ?? ?? ?? ?? 8B D0 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 + ?? ?? ?? ?? 43 83 FB ?? 75 ?? 8B 85 ?? ?? ?? ?? 8B D0 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 + ?? E8 ?? ?? ?? ?? 8B D0 8B 8D ?? ?? ?? ?? 8B 45 ?? 8B 18 FF 53 ?? 83 BD ?? ?? ?? ?? + ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 45 ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? 8B 18 FF 53 ?? EB ?? 8D 45 ?? + E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 33 D2 8B 45 ?? 8B 08 FF 51 ?? 83 + BD ?? ?? ?? ?? ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 8D 45 ?? E8 ?? ?? ?? ?? + 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? 8B 18 FF 53 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 B9 + ?? ?? ?? ?? 8B 45 ?? 8B 18 FF 53 ?? 55 E8 ?? ?? ?? ?? 59 55 E8 ?? ?? ?? ?? 59 EB ?? + 55 E8 ?? ?? ?? ?? 59 A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? 8B + 18 FF 53 ?? 55 E8 ?? ?? ?? ?? 59 B3 ?? 8D 45 ?? E8 ?? ?? ?? ?? 84 DB 74 ?? 8D 95 ?? + ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B + F8 57 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 56 57 E8 ?? ?? ?? ?? 33 C0 5A 59 59 + 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 } $find_files = { - E8 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 33 F6 33 D2 41 B8 ?? ?? ?? ?? 66 89 B4 24 ?? - ?? 00 00 E8 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 8B D7 FF 15 - ?? ?? ?? ?? 48 8D 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 83 - F8 ?? 0F 84 ?? ?? ?? ?? 0F 1F 40 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? 41 B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? 41 - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? 4C 8D 44 - 24 ?? 48 8D 8C 24 ?? ?? ?? ?? 48 8B D7 FF 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? - ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D - 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? - ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? - ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 - 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C - 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? - FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 - ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? - ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? - 85 C0 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? 8B 44 24 ?? A8 ?? 0F 85 ?? ?? ?? ?? A8 ?? 0F 85 ?? ?? ?? ?? 48 8D - 8C 24 ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? 66 89 B4 24 ?? ?? 00 00 E8 ?? ?? ?? ?? 48 - 8D 8C 24 ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? 66 89 B4 24 ?? ?? 00 00 E8 ?? ?? ?? ?? - 4C 8D 44 24 ?? 48 8D 8C 24 ?? ?? ?? ?? 48 8B D7 FF 15 ?? ?? ?? ?? 4C 8D 84 24 ?? ?? - ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 39 74 24 ?? 76 - ?? 4C 8D 0D ?? ?? ?? ?? 4C 8D 84 24 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 8D 4C 24 - ?? E8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 48 8B CB FF 15 - } + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 89 55 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? + ?? 89 C3 85 DB 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 FF D3 85 C0 74 + ?? 8B 45 ?? 50 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 + ?? 80 38 ?? 75 ?? 8B 45 ?? 80 78 ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? E8 ?? ?? + ?? ?? 8B F0 80 3E ?? 0F 84 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F0 80 3E ?? 0F 84 + ?? ?? ?? ?? EB ?? 8B 75 ?? 83 C6 ?? 8B DE 2B 5D ?? 8D 43 ?? 50 8B 45 ?? 50 8D 85 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F8 8B C7 2B C6 + 03 C3 40 3D ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 8B C7 2B C6 40 50 56 8D 85 ?? ?? ?? ?? 03 + C3 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 89 45 + ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? + 8D 53 ?? 03 C2 40 3D ?? ?? ?? ?? 7F ?? C6 84 1D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B C3 + 48 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 03 C3 40 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 40 03 D8 8B F7 80 3E ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 8D 85 + ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 5F 5E 5B 8B E5 5D C3 + } + $enum_resources = { + 55 8B EC 83 C4 ?? 53 56 57 33 D2 89 55 ?? 89 55 ?? 89 55 ?? 33 D2 55 68 ?? ?? ?? ?? + 64 FF 32 64 89 22 33 D2 55 68 ?? ?? ?? ?? 64 FF 32 64 89 22 8D 55 ?? 52 50 6A ?? 6A + ?? 6A ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 33 C0 5A 59 59 64 89 10 E9 ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 6A ?? E8 ?? ?? ?? ?? 89 + 45 ?? 8D 45 ?? 50 8B 45 ?? 50 8D 45 ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 83 7D + ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 48 85 C0 0F 82 ?? ?? ?? ?? 40 89 45 ?? 8B 45 ?? 8B + 58 ?? 85 DB 0F 84 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? 8B + D3 E8 ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? 0F B6 12 88 50 ?? C6 00 ?? 8D 55 ?? 8D 45 ?? E8 + ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? 0F B6 52 ?? 88 50 ?? C6 00 ?? 8D 55 ?? 8D 45 ?? B1 ?? + E8 ?? ?? ?? ?? 8D 55 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 50 8D 55 ?? B8 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B 55 ?? 58 E8 ?? ?? ?? ?? 75 ?? A1 ?? ?? ?? ?? 8B 40 ?? 8B 55 ?? 8B + 08 FF 51 ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? F7 + 40 ?? ?? ?? ?? ?? 76 ?? 8B 45 ?? E8 ?? ?? ?? ?? 83 45 ?? ?? FF 4D ?? 0F 85 ?? ?? ?? + ?? EB ?? 81 7D ?? ?? ?? ?? ?? 74 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? EB ?? 8B 45 ?? 50 E8 + ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 33 C0 + 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? + ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 + } condition: - uint16(0)==0x5A4D and $find_files and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($enum_resources) and ($find_files) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Zeppelin : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Saturn : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Zeppelin ransomware." + description = "Yara rule that detects Saturn ransomware." author = "ReversingLabs" - id = "f5cf514d-4dd0-58b7-82d0-5cb516a139a3" - date = "2020-07-15" - modified = "2020-07-15" + id = "70a8d937-aee5-54d8-9409-c5d2d0830a2b" + date = "2020-10-19" + modified = "2020-10-19" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Zeppelin.yara#L1-L109" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "8fb07e49d2ff9d497fb36a5d901748315ae519f5ef845d1a5ec6341d0eb1f68c" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Saturn.yara#L1-L105" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "efa748346ad8c46e654542d302e81d633a2d12f421636c477431a12a34636132" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -39920,97 +40494,99 @@ rule REVERSINGLABS_Win32_Ransomware_Zeppelin : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Zeppelin" + tc_detection_name = "Saturn" tc_detection_factor = 5 importance = 25 strings: - $search_files_p1 = { - 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 - 89 20 8D 45 ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 8B 45 ?? E8 ?? - ?? ?? ?? 8B D8 8B 45 ?? E8 ?? ?? ?? ?? 2B D8 43 53 8B 45 ?? E8 ?? ?? ?? ?? 8B D0 42 - 8B 45 ?? 59 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? FF 30 FF 75 ?? 68 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? 83 F8 - ?? 7C ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 - ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - C3 + $find_files_1 = { + 6A ?? C6 45 ?? ?? 8D 4D ?? 8B 3B 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? 3B C8 74 ?? + 83 78 ?? ?? 8B C8 72 ?? 8B 08 FF 70 ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 + 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 + ?? ?? 8D 4D ?? 6A ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 + ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A } - $search_files_p2 = { - 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? - ?? 64 FF 30 64 89 20 F6 85 ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 - ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 45 ?? 50 - 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 8D - ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? - 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? - ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5B 8B E5 5D C3 + $find_files_2_p1 = { + 68 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? + ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? FF B5 + ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 8D 4D ?? 83 7D ?? ?? 8B 55 ?? 0F 43 4D ?? 50 51 E8 + ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 85 ?? ?? ?? ?? FF 75 + ?? 0F 43 85 ?? ?? ?? ?? 8D 4D ?? 83 7D ?? ?? 8B 55 ?? 0F 43 4D ?? 50 51 E8 ?? ?? ?? + ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? FF 75 ?? 0F 43 45 ?? 8D + 4D ?? 83 7D ?? ?? 8B 55 ?? 0F 43 4D ?? 50 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 + ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? FF 75 ?? 0F 43 45 ?? 8D 4D ?? 83 7D ?? ?? 8B 55 ?? + 0F 43 4D ?? 50 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 51 8D 85 ?? ?? + ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 51 8D 85 ?? ?? ?? ?? 50 + 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? + E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? + ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 } - $kill_processes = { - 55 8B EC 33 C9 51 51 51 51 51 51 51 51 53 56 57 84 D2 74 ?? 83 C4 ?? E8 ?? ?? ?? ?? - 88 55 ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 D2 55 68 ?? ?? ?? ?? - 64 FF 32 64 89 22 8D 55 ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B D8 8B 45 ?? 89 58 ?? 8B C3 B2 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? - C6 40 ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 74 ?? 83 E8 ?? 8B 00 8B F0 85 F6 - 7E ?? BB ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? 0F B6 54 1A ?? E8 ?? ?? ?? ?? 8B 45 ?? 50 8D - 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 58 E8 ?? ?? ?? ?? 75 ?? 8D 55 ?? 8B 45 - ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8B 40 ?? 8B 08 FF 51 ?? 8D 45 ?? E8 ?? ?? ?? ?? - EB ?? 8D 45 ?? 8B 55 ?? 0F B6 54 1A ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? E8 ?? ?? ?? - ?? 43 4E 75 ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? B1 ?? 33 - D2 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? - 8B 45 ?? 80 7D ?? ?? 74 ?? E8 ?? ?? ?? ?? 64 8F 05 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 5F - 5E 5B 8B E5 5D C3 + $find_files_2_p2 = { + F8 ?? 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 8D ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF + 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 5D ?? 8B F0 80 + BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 00 + ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B D0 + 8D 71 ?? 8A 01 41 84 C0 75 ?? 2B CE 8D 85 ?? ?? ?? ?? 51 50 8B CA E8 ?? ?? ?? ?? F6 + 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 84 DB 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 95 + ?? ?? ?? ?? 53 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 0F 84 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C6 E9 } - $enum_shares = { - 55 8B EC B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 ?? 51 53 56 57 89 45 ?? 8B 45 ?? E8 ?? ?? - ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 - 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 4D ?? 33 - D2 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 89 45 ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B - 45 ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 55 ?? B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 10 FF 52 ?? 48 85 - C0 0F 8C ?? ?? ?? ?? 40 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 8B 55 ?? 8B 45 ?? 8B - 18 FF 53 ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 33 C0 55 68 ?? ?? ?? ?? 64 - FF 30 64 89 20 FF 75 ?? 68 ?? ?? ?? ?? 8D 4D ?? 33 D2 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 - ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? - 8D 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 - 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 75 ?? FF 45 ?? - FF 4D ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A - 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? - ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB - ?? 5F 5E 5B 8B E5 5D C3 + $encrypt_files_p1 = { + 6A ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 89 9D ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 6A ?? FF B5 + ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? + 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? FF D6 8B D8 + 83 FB ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 57 + FF D6 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? + ?? ?? B9 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 + A5 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? + FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? + ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 6A ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? 8B F0 FF 15 ?? + ?? ?? ?? 85 F6 0F 95 C3 E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 F6 89 B5 ?? ?? ?? ?? 56 53 FF } - $encrypt_files = { - 55 8B EC 83 C4 ?? 53 56 33 DB 89 5D ?? 84 D2 74 ?? 83 C4 ?? E8 ?? ?? ?? ?? 8B D9 88 - 55 ?? 8B F0 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 D2 8B C6 E8 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 88 5E ?? 88 5E ?? 56 6A ?? 8D 46 ?? 50 B9 ?? ?? ?? ?? 33 D2 33 C0 E8 ?? - ?? ?? ?? 8B D8 89 5E ?? 85 DB 75 ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? - 89 45 ?? C6 45 ?? ?? 8D 45 ?? 50 6A ?? 8B 0D ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? - ?? C3 + $encrypt_files_p2 = { + 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 56 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF D7 85 C0 0F 84 ?? ?? ?? ?? 8D 56 ?? 8B 85 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 03 C8 8D 85 ?? ?? ?? ?? + 3B 8D ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 50 6A ?? 0F 44 F2 56 6A ?? + FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 + ?? ?? ?? ?? 6A ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF D7 BA ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 53 FF D6 FF B5 + ?? ?? ?? ?? FF D6 B3 ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? + ?? ?? ?? 72 ?? F6 C1 ?? 75 ?? 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 ?? 72 ?? 83 F9 ?? 77 + ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8A C3 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B + 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 } condition: - uint16(0)==0x5A4D and ($kill_processes) and ($enum_shares) and ( all of ($search_files_p*)) and ($encrypt_files) + uint16(0)==0x5A4D and ( all of ($find_files_*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win64_Ransomware_Solaso : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Tarrak : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Solaso ransomware." + description = "Yara rule that detects TaRRaK ransomware." author = "ReversingLabs" - id = "53f56ad8-ccdf-58f0-a5d9-e58f2c18ac76" - date = "2021-11-02" - modified = "2021-11-02" + id = "a783df87-0c9b-5868-9af0-c32b11e8b71b" + date = "2021-09-06" + modified = "2021-09-06" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Solaso.yara#L1-L171" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "368a80a9f2e264d17c61d6ed4c22baec838ba0b0bc2e5c79344830bf861aa5a2" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.TaRRaK.yara#L1-L96" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "a8c4c4a501d94da94ae4a2e1eb2846e841249659be64dd45f46584885d000635" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -40018,161 +40594,81 @@ rule REVERSINGLABS_Win64_Ransomware_Solaso : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Solaso" + tc_detection_name = "TaRRaK" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - C6 85 ?? ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 45 ?? 4C 89 AD ?? ?? ?? ?? 48 8D 85 - ?? ?? ?? ?? 48 89 45 ?? B1 ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 90 4C 8D 05 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 90 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8D - 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B BD - ?? ?? ?? ?? 4C 8B BD ?? ?? ?? ?? 49 3B FF 0F 84 ?? ?? ?? ?? 66 0F 1F 44 00 ?? 48 8D - 95 ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? 90 48 8D 95 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? - ?? 48 0F 43 95 ?? ?? ?? ?? 4C 8B 85 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 48 8B C8 E8 ?? ?? ?? ?? 4C 89 AD ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 - ?? ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 48 0F 43 95 ?? ?? ?? ?? - 4C 8B 85 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B CF 48 83 7F ?? ?? 72 - ?? 48 8B 0F BA ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? - 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 44 24 ?? 4C 89 AD ?? - ?? ?? ?? 4C 89 AD ?? ?? ?? ?? 48 8B B5 ?? ?? ?? ?? 4C 8D B5 ?? ?? ?? ?? 48 83 BD ?? - ?? ?? ?? ?? 4C 0F 43 B5 ?? ?? ?? ?? 48 83 FE ?? 73 ?? 41 0F 10 06 0F 11 85 ?? ?? ?? - ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 - } - $find_files_p2 = { - 8B DE 48 83 CB ?? 48 3B D8 48 0F 47 D8 48 8D 4B ?? 48 81 F9 ?? ?? ?? ?? 72 ?? 48 8D - 41 ?? 48 3B C1 0F 86 ?? ?? ?? ?? 0F AE E8 48 8B C8 E8 ?? ?? ?? ?? 48 8B C8 48 85 C0 - 0F 84 ?? ?? ?? ?? 48 83 C0 ?? 48 83 E0 ?? 48 89 48 ?? EB ?? 48 85 C9 74 ?? 0F AE E8 - E8 ?? ?? ?? ?? EB ?? 49 8B C5 48 89 85 ?? ?? ?? ?? 4C 8D 46 ?? 49 8B D6 48 8B C8 E8 - ?? ?? ?? ?? 48 89 9D ?? ?? ?? ?? 48 89 B5 ?? ?? ?? ?? 4C 89 6D ?? 4C 89 6D ?? 48 8B - B5 ?? ?? ?? ?? 4C 8D B5 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 4C 0F 43 B5 ?? ?? ?? ?? - 48 83 FE ?? 73 ?? 41 0F 10 06 0F 11 45 ?? 48 C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 - B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 45 ?? 48 8B DE 48 83 CB ?? 48 89 5D ?? 48 3B D8 48 - 0F 47 D8 48 8D 4B ?? 48 81 F9 ?? ?? ?? ?? 72 ?? 48 8D 41 ?? 48 3B C1 0F 86 ?? ?? ?? - ?? 0F AE E8 48 8B C8 E8 ?? ?? ?? ?? 48 8B C8 48 85 C0 0F 84 ?? ?? ?? ?? 48 83 C0 ?? - 48 83 E0 ?? 48 89 48 ?? EB ?? 48 85 C9 74 ?? 0F AE E8 E8 ?? ?? ?? ?? EB ?? 49 8B C5 - 48 89 45 ?? 4C 8D 46 ?? 49 8B D6 48 8B C8 E8 ?? ?? ?? ?? 48 89 5D ?? 48 89 75 ?? 4C - 8D 85 ?? ?? ?? ?? 48 8D 55 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 8D - } $encrypt_files_p1 = { - 48 63 53 ?? 48 89 B5 ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 45 33 - C0 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 55 ?? 48 83 BD ?? ?? ?? ?? ?? 48 0F 43 55 ?? - 4C 63 43 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 89 4B ?? 48 85 C9 0F 84 - ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 3B CA 77 ?? 48 89 8D ?? ?? ?? ?? 48 8D 45 ?? 48 - 83 BD ?? ?? ?? ?? ?? 48 0F 43 45 ?? C6 04 01 ?? EB ?? 48 8B F1 48 2B F2 4C 8B 85 ?? - ?? ?? ?? 49 8B C0 48 2B C2 48 3B F0 77 ?? 48 89 8D ?? ?? ?? ?? 48 8D 7D ?? 49 83 F8 - ?? 48 0F 43 7D ?? 48 03 FA 4C 8B C6 33 D2 48 8B CF E8 ?? ?? ?? ?? C6 04 37 ?? EB ?? - 0F AE E8 C6 44 24 ?? ?? 4C 8B CE 48 8B D6 48 8D 4D ?? E8 ?? ?? ?? ?? 33 F6 8B 43 ?? - 99 41 F7 FD B9 ?? ?? ?? ?? 85 C0 0F 45 C8 89 4B ?? 83 F9 ?? 0F 8C ?? ?? ?? ?? 4C 63 - C9 4C 8D 45 ?? 48 8D 54 24 ?? E8 ?? ?? ?? ?? 48 8B F8 48 3B D8 74 ?? 48 8B 0B 48 85 + 03 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 06 07 9A 0C 73 ?? ?? ?? ?? 0D 09 08 28 ?? ?? ?? ?? 7D + ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 09 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? + 02 08 28 ?? ?? ?? ?? 07 17 58 0B 07 06 8E 69 32 ?? DE ?? 26 DE ?? 00 03 28 ?? ?? ?? ?? + 0A 16 0B 2B ?? 06 07 9A 13 ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 02 11 ?? 28 ?? ?? ?? ?? + 07 17 58 0B 07 06 8E 69 32 ?? DE ?? 26 DE ?? 2A } $encrypt_files_p2 = { - C9 74 ?? 48 8B 53 ?? E8 ?? ?? ?? ?? 48 8B 0B 48 8B 53 ?? 48 2B D1 48 83 E2 ?? 48 81 - FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 4C 8B 41 ?? 49 2B C8 48 8D 41 ?? 48 83 F8 ?? 0F 87 - ?? ?? ?? ?? 49 8B C8 E8 ?? ?? ?? ?? 48 89 33 48 89 73 ?? 48 89 73 ?? 48 8B 07 48 89 - 03 48 8B 47 ?? 48 89 43 ?? 48 8B 47 ?? 48 89 43 ?? 48 89 37 48 89 77 ?? 48 89 77 ?? - 48 8B 4C 24 ?? 48 85 C9 74 ?? 48 8B 54 24 ?? E8 ?? ?? ?? ?? 48 8B 54 24 ?? 48 8B 4C - 24 ?? 48 2B D1 48 83 E2 ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 - ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 74 24 ?? - 0F 57 C0 F3 0F 7F 44 24 ?? EB ?? 48 8B 0B 48 8D 45 ?? 48 3B C8 74 ?? 48 8D 55 ?? 48 - 83 BD ?? ?? ?? ?? ?? 48 0F 43 55 ?? 4C 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B CB E8 - ?? ?? ?? ?? 45 33 C0 48 8D 15 ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 83 7B ?? ?? 74 - ?? 33 FF 0F 1F 40 ?? 66 0F 1F 84 00 ?? ?? 00 00 4C 8B 03 4C 03 C7 49 8B D0 49 83 78 - ?? ?? 72 ?? 49 8B 10 4D 8B 40 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 48 63 CE 48 C1 E1 ?? 48 + 03 8E 69 17 59 0A 06 17 2F ?? 03 2A 03 06 95 0B 16 0D 1C 1F ?? 06 17 58 5B 58 13 ?? 2B + ?? 09 20 ?? ?? ?? ?? 58 0D 09 18 64 19 5F 13 ?? 16 13 ?? 2B ?? 03 11 ?? 17 58 95 0C 03 + 11 ?? 8F ?? ?? ?? ?? 25 4B 02 09 08 07 11 ?? 11 ?? 04 28 ?? ?? ?? ?? 58 25 13 ?? 54 11 + ?? 0B 11 ?? 17 58 13 ?? 11 ?? 06 32 ?? 03 16 95 0C 03 06 8F ?? ?? ?? ?? 25 4B 02 09 08 + 07 11 ?? 11 ?? 04 28 ?? ?? ?? ?? 58 25 13 ?? 54 11 ?? 0B 16 11 ?? 25 17 59 13 ?? 32 ?? + 03 2A } $encrypt_files_p3 = { - 03 0B 45 33 C0 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 0B 48 03 CF 48 C7 41 ?? ?? - ?? ?? ?? 48 83 79 ?? ?? 72 ?? 48 8B 09 C6 01 ?? FF C6 48 83 C7 ?? 3B 73 ?? 75 ?? 48 - 8D 55 ?? 48 83 BD ?? ?? ?? ?? ?? 48 0F 43 55 ?? 4C 8B 85 ?? ?? ?? ?? 48 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 90 48 8B 95 ?? ?? ?? ?? 48 83 FA ?? 72 ?? 48 FF C2 48 8B 4D ?? - 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 - 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 63 48 ?? 33 F6 F6 44 0C - ?? ?? 75 ?? E9 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 83 FA ?? 72 ?? 48 FF C2 48 8B 4D - ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? - 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 3D ?? ?? ?? ?? 48 8D 4C 24 ?? E8 - ?? ?? ?? ?? BB ?? ?? ?? ?? 48 85 C0 75 ?? 48 8B 44 24 ?? 48 63 48 ?? 48 8D 44 24 ?? - 48 03 C8 41 8B D4 48 83 79 ?? ?? 0F 45 D3 0B 51 ?? 45 33 C0 E8 ?? ?? ?? ?? 48 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 85 C0 75 ?? 48 8B 85 ?? ?? ?? ?? 48 63 48 ?? 48 8D 85 - ?? ?? ?? ?? 48 03 C8 48 83 79 ?? ?? 44 0F 45 E3 44 0B 61 ?? 45 33 C0 41 8B D4 E8 ?? - ?? ?? ?? 90 48 8B 85 ?? ?? ?? ?? 48 63 48 ?? 48 89 BC 0D ?? ?? ?? ?? 48 8B 85 ?? ?? - ?? ?? 48 63 48 ?? 8D 91 ?? ?? ?? ?? 89 94 0D ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 63 48 ?? 48 8D 05 ?? ?? ?? ?? 48 89 84 0D ?? ?? ?? - ?? 48 8B 85 ?? ?? ?? ?? 48 63 48 ?? 8D 51 ?? 89 94 0D ?? ?? ?? ?? 48 8D 1D ?? ?? ?? - ?? 48 89 9D ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B 44 24 ?? 48 63 + 05 1B 64 04 18 62 61 04 19 64 05 1A 62 61 58 03 04 61 0E ?? 0E ?? 19 5F 6A 0E ?? 6E 61 + D4 95 05 61 58 61 2A } $encrypt_files_p4 = { - 48 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 0C ?? 48 8B 44 24 ?? 48 63 48 ?? 8D 91 ?? ?? ?? - ?? 89 54 0C ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 63 48 ?? 48 8D 05 ?? - ?? ?? ?? 48 89 44 0C ?? 48 8B 44 24 ?? 48 63 48 ?? 8D 51 ?? 89 54 0C ?? 48 89 5D ?? - 48 8D 4D ?? E8 ?? ?? ?? ?? 90 49 8B 57 ?? 48 83 FA ?? 72 ?? 49 8B 0F 48 FF C2 48 81 - FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 4C 8B 41 ?? 49 2B C8 48 8D 41 ?? 48 83 F8 ?? 0F 87 - ?? ?? ?? ?? 49 8B C8 E8 ?? ?? ?? ?? 49 89 77 ?? 49 C7 47 ?? ?? ?? ?? ?? 41 C6 07 ?? - 49 8B 56 ?? 48 83 FA ?? 72 ?? 48 FF C2 49 8B 0E 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 - ?? 4C 8B 41 ?? 49 2B C8 48 8D 41 ?? 48 83 F8 ?? 77 ?? 49 8B C8 E8 ?? ?? ?? ?? 49 89 - 76 ?? 49 C7 46 ?? ?? ?? ?? ?? 41 C6 06 ?? 48 8B 8D ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? - ?? 48 8B 9C 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5E 41 5D 41 5C 5F 5E 5D C3 - E8 + 03 8E 2D ?? 03 2A 02 02 02 03 17 28 ?? ?? ?? ?? 02 02 7B ?? ?? ?? ?? 16 28 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 2A } - $encrypt_files_p5 = { - 48 8B C4 48 89 58 ?? 48 89 70 ?? 48 89 78 ?? 4C 89 40 ?? 55 41 54 41 55 41 56 41 57 - 48 8D 68 ?? 48 81 EC ?? ?? ?? ?? 45 8B E1 49 8B D8 44 8B 4D ?? 48 8B FA 44 8B 45 ?? - 48 8B F1 41 8B D4 48 8D 4D ?? E8 ?? ?? ?? ?? 0F 10 00 F2 0F 10 48 ?? 0F 11 45 ?? 66 - 0F 73 D8 ?? 66 49 0F 7E C7 F2 0F 11 4D ?? 49 C1 EF ?? F2 0F 11 4D ?? 4C 89 7D ?? 41 - 83 FF ?? 75 ?? E8 ?? ?? ?? ?? 33 F6 89 30 83 0F ?? E8 ?? ?? ?? ?? 8B 00 E9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 89 07 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? 33 F6 89 30 83 0F ?? E8 ?? ?? - ?? ?? C7 00 ?? ?? ?? ?? EB ?? 8B 4D ?? 4C 8D 4D ?? 4C 8B 75 ?? 41 8B C4 48 8B 55 ?? - 45 8B C7 C1 E8 ?? 49 C1 EE ?? F7 D0 44 0B 75 ?? 83 E0 ?? C7 06 ?? ?? ?? ?? 33 F6 48 - 89 74 24 ?? 44 89 74 24 ?? 89 4C 24 ?? 48 8B CB 48 C1 EA ?? C7 45 ?? ?? ?? ?? ?? 48 - 89 75 ?? 89 45 ?? 4C 89 75 ?? FF 15 ?? ?? ?? ?? 8B 5D ?? B9 ?? ?? ?? ?? 4C 8B E8 48 - 83 F8 ?? 75 ?? 8B C3 23 C1 3B C1 75 ?? 41 F6 C4 ?? 74 ?? 8B 4D ?? 4C 8D 4D ?? 48 89 - 74 24 ?? 0F BA F3 ?? 89 5D ?? 45 8B C7 48 8B 55 ?? 44 89 74 24 ?? 89 4C 24 ?? 48 8B + $find_files_p1 = { + 73 ?? ?? ?? ?? 25 02 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 + 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 2A } - $encrypt_files_p6 = { - 4D ?? 48 C1 EA ?? FF 15 ?? ?? ?? ?? 4C 8B E8 48 83 F8 ?? 75 ?? 48 63 0F 4C 8D 3D ?? - ?? ?? ?? 48 8B C1 83 E1 ?? 48 C1 F8 ?? 48 8D 0C C9 49 8B 04 C7 80 64 C8 ?? ?? FF 15 - ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? 85 C0 75 - ?? FF 15 ?? ?? ?? ?? 8B C8 8B D8 E8 ?? ?? ?? ?? 48 63 17 4C 8D 3D ?? ?? ?? ?? 48 8B - CA 83 E2 ?? 48 C1 F9 ?? 48 8D 14 D2 49 8B 0C CF 80 64 D1 ?? ?? 49 8B CD FF 15 ?? ?? - ?? ?? 85 DB 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E9 ?? ?? ?? ?? 44 8A - 75 ?? 83 F8 ?? 75 ?? 41 80 CE ?? EB ?? 83 F8 ?? 75 ?? 41 80 CE ?? 8B 0F 49 8B D5 E8 - ?? ?? ?? ?? 48 63 0F 4C 8D 3D ?? ?? ?? ?? 48 8B C1 41 80 CE ?? 48 C1 F8 ?? 83 E1 ?? - 44 88 75 ?? 49 8B 04 C7 48 8D 0C C9 44 88 74 C8 ?? 48 63 0F 48 8B C1 83 E1 ?? 48 C1 - F8 ?? 48 8D 0C C9 49 8B 04 C7 40 88 74 C8 ?? 41 F6 C4 ?? 74 ?? 8B 0F E8 ?? ?? ?? ?? - 89 45 ?? 85 C0 74 ?? 8B 0F E8 ?? ?? ?? ?? 8B 45 ?? E9 ?? ?? ?? ?? 0F 10 45 ?? 4C 8D - 4D ?? 8B 0F F2 0F 10 4D ?? 48 8D 55 ?? 45 8B C4 0F 29 45 ?? 40 88 75 ?? F2 0F 11 4D - ?? E8 ?? ?? ?? ?? 48 63 0F 89 45 ?? 85 C0 75 ?? 48 8B C1 48 C1 F9 ?? 83 E0 ?? 49 8B + $find_files_p2 = { + 73 ?? ?? ?? ?? 25 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 1B 28 ?? ?? ?? ?? 6F ?? ?? ?? + ?? 25 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 1F + ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2A } - $encrypt_files_p7 = { - 0C CF 48 8D 14 C0 8A 45 ?? 88 44 D1 ?? 48 63 0F 48 8B C1 83 E1 ?? 48 C1 F8 ?? 48 8D - 14 C9 49 8B 0C C7 41 8B C4 C1 E8 ?? 24 ?? 80 64 D1 ?? ?? 08 44 D1 ?? 41 F6 C6 ?? 75 - ?? 41 F6 C4 ?? 74 ?? 48 63 0F 48 8B C1 83 E1 ?? 48 C1 F8 ?? 48 8D 0C C9 49 8B 04 C7 - 80 4C C8 ?? ?? B9 ?? ?? ?? ?? 8B C3 23 C1 3B C1 0F 85 ?? ?? ?? ?? 41 F6 C4 ?? 0F 84 - ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? 48 8B 4D ?? 4C 8D 4D ?? 44 8B 45 ?? 0F BA F3 - ?? 48 89 74 24 ?? 89 4C 24 ?? 8B 4D ?? 89 4C 24 ?? 48 8B 4D ?? 89 5D ?? 48 8B 55 ?? - 48 C1 EA ?? FF 15 ?? ?? ?? ?? 48 8B D0 48 83 F8 ?? 75 ?? FF 15 ?? ?? ?? ?? 8B C8 E8 - ?? ?? ?? ?? 48 63 0F 48 8B C1 83 E1 ?? 48 C1 F8 ?? 48 8D 0C C9 49 8B 04 C7 80 64 C8 - ?? ?? 8B 0F E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 63 0F 48 8B C1 48 C1 F8 ?? 83 E1 ?? 49 - 8B 04 C7 48 8D 0C C9 48 89 54 C8 ?? 33 C0 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? 49 8B - 73 ?? 49 8B 7B ?? 49 8B E3 41 5F 41 5E 41 5D 41 5C 5D C3 + $change_desktop = { + 1F ?? 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 06 28 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 17 + 8C ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 8C ?? ?? ?? ?? 6F ?? ?? ?? ?? 1F ?? 16 + 06 19 28 ?? ?? ?? ?? 26 DE ?? 26 DE ?? 2A + } + $drop_ransom_note = { + 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 2A 00 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 02 7B ?? ?? + ?? ?? 6F ?? ?? ?? ?? 0D 12 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? + ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 07 06 6F ?? ?? ?? ?? 26 07 6F ?? + ?? ?? ?? 26 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 26 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? + 2B ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 07 11 ?? 6F ?? ?? ?? ?? 26 12 ?? 28 ?? ?? ?? ?? 2D ?? + DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? DC 07 6F ?? ?? ?? ?? 0C 02 28 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 02 7B ?? ?? ?? ?? 28 ?? ?? + ?? ?? 06 28 ?? ?? ?? ?? 11 ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 28 ?? ?? ?? ?? DE ?? + 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC DE ?? 26 + DE ?? 2A } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($change_desktop) and ($drop_ransom_note) } -rule REVERSINGLABS_Win32_Ransomware_Major : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Nefilim : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Major ransomware." + description = "Yara rule that detects Nefilim ransomware." author = "ReversingLabs" - id = "0c85aff8-1fb5-5e47-ae49-72445a000eaa" - date = "2021-01-26" - modified = "2021-01-26" + id = "aec298c1-abf8-5446-9dbb-795f9fcf8e94" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Major.yara#L1-L261" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "16fb7763e3806fca6937fef7e8b3d8bccd61cb39549061d359d630c7d266c270" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Nefilim.yara#L1-L150" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "fae0350e51aee2777475d2222848b30fd39fa39ceea260132b0c7fbc536b3a86" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -40180,246 +40676,135 @@ rule REVERSINGLABS_Win32_Ransomware_Major : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Major" + tc_detection_name = "Nefilim" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 33 C0 89 4D ?? 57 50 66 89 45 ?? 8D 8D ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 57 C0 C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F 13 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 - ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 - 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 4D ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? - ?? ?? 33 C9 8B F8 51 89 4D ?? 51 8D 4D ?? 89 7D ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 4D ?? - 8D 45 ?? 50 FF 77 ?? 57 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 47 ?? 89 4D ?? BB ?? ?? ?? - ?? 8B 48 ?? 89 01 8B 07 8D 4D ?? 83 C0 ?? 3B C8 74 ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 8D 45 ?? 3B C6 - } - $find_files_p2 = { - 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? - ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? - ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? - ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? 83 7E ?? - ?? 73 ?? 8B 46 ?? 83 C0 ?? 74 ?? 03 C0 50 8D 45 ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? EB - ?? 8B 06 89 45 ?? C7 06 ?? ?? ?? ?? 8B 46 ?? 89 45 ?? 8B 46 ?? 89 45 ?? C7 46 ?? ?? - ?? ?? ?? 83 7E ?? ?? C7 46 ?? ?? ?? ?? ?? 72 ?? 8B 36 33 C0 66 89 06 8B 45 ?? 83 F8 - ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 - C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? - ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 3F 8D 77 ?? 8B - 4F ?? 8B 07 89 01 8B 0F 8B 47 ?? 89 41 ?? 8B 45 ?? 48 89 45 ?? 89 45 ?? 8B 46 ?? 83 - F8 ?? 72 ?? 8B 0E 40 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 - } - $find_files_p3 = { - C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? - ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 46 ?? ?? ?? ?? - ?? 83 7E ?? ?? C7 46 ?? ?? ?? ?? ?? 72 ?? 8B 36 33 C0 57 66 89 06 E8 ?? ?? ?? ?? 83 - C4 ?? 8D 8D ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF 15 ?? ?? ?? ?? 8B - F8 89 7D ?? 83 FF ?? 0F 84 ?? ?? ?? ?? 66 66 66 0F 1F 84 00 ?? ?? ?? ?? 33 C0 C7 45 - ?? ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? 0F 84 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 8B 08 85 C9 74 ?? 8B 85 ?? ?? ?? ?? 8B 00 8D 14 41 EB ?? 8B 85 - ?? ?? ?? ?? 8B 08 8B 85 ?? ?? ?? ?? 8B 00 8D 14 48 8B 85 ?? ?? ?? ?? 8B 08 2B D1 D1 - FA 81 FA ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 8D 04 12 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 - ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 - ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? C7 00 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 00 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? 50 89 85 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 - ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 C1 - } - $find_files_p4 = { - 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? - 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 68 - ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 EC ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? 8B D4 33 C0 C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? 66 89 02 66 39 85 ?? ?? ?? - ?? 75 ?? 33 C9 EB ?? 8D 8D ?? ?? ?? ?? 8D 71 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B - CE D1 F9 51 8D 85 ?? ?? ?? ?? 8B CA 50 E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 85 C0 - 0F 84 ?? ?? ?? ?? 6A ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? - ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 83 CB ?? C7 45 ?? - ?? ?? ?? ?? 66 89 45 ?? 66 39 85 ?? ?? ?? ?? 75 ?? 33 C9 EB ?? 8D 8D ?? ?? ?? ?? 8D - 51 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? - E8 ?? ?? ?? ?? 8D 45 ?? 83 CB ?? 50 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 - 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 - } - $find_files_p5 = { - 83 CB ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 CB ?? 50 8D 85 ?? - ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 CB ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 83 CB ?? 50 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 85 C0 74 ?? - C6 45 ?? ?? F6 C3 ?? 74 ?? 8B 45 ?? 83 E3 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? - E8 ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? F6 C3 ?? - 74 ?? 8B 85 ?? ?? ?? ?? 83 E3 ?? 83 F8 ?? 72 ?? 40 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? 66 89 85 ?? ?? ?? ?? F6 C3 ?? 74 ?? 8B 85 ?? ?? ?? ?? 83 E3 ?? 83 F8 ?? 72 ?? 40 - 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? F6 C3 ?? 74 ?? 8B 85 ?? ?? - ?? ?? 83 E3 ?? 83 F8 ?? 72 ?? 40 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? - ?? ?? 8B 45 ?? 83 E3 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 33 C0 - } - $find_files_p6 = { - C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? 83 E3 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? 83 F8 ?? 72 - ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 80 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 75 ?? 8D 45 ?? 50 8D 4D ?? FF 76 ?? 56 E8 ?? ?? - ?? ?? 8B 55 ?? B9 ?? ?? ?? ?? 2B CA 83 F9 ?? 0F 82 ?? ?? ?? ?? 89 46 ?? 42 8B 48 ?? - 89 55 ?? 89 01 E9 ?? ?? ?? ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 75 ?? - 8D 45 ?? 50 8D 4D ?? FF 76 ?? 56 E8 ?? ?? ?? ?? 8B 55 ?? B9 ?? ?? ?? ?? 2B CA 83 F9 - ?? 0F 82 ?? ?? ?? ?? 89 46 ?? 42 8B 48 ?? 89 55 ?? 89 55 ?? 89 01 8B 45 ?? 83 F8 ?? - 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 8D ?? ?? ?? ?? 54 E8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? ?? ?? ?? 8B 75 - ?? 8B CE E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 45 ?? 8B CE 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 7D ?? - 8B CF E8 ?? ?? ?? ?? 8B 4D ?? 85 C9 74 ?? 8B 7D ?? E9 ?? ?? ?? ?? 8B 4D ?? 85 C9 0F - 84 ?? ?? ?? ?? 0F 1F 00 8B 45 ?? 8D 4D ?? 8B 00 83 C0 ?? 3B C8 74 ?? 6A ?? 6A ?? 50 - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 + $create_encryption_key = { + 55 8B EC 51 A1 ?? ?? ?? ?? C1 E8 ?? 6B C0 ?? 56 50 E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? + ?? 8B F0 A1 ?? ?? ?? ?? 59 89 75 ?? 73 ?? B8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 33 F6 59 59 39 35 ?? ?? ?? ?? 75 ?? 53 57 8B 3D ?? ?? ?? ?? 56 6A ?? 56 BE + ?? ?? ?? ?? 56 BB ?? ?? ?? ?? 53 FF D7 85 C0 75 ?? 6A ?? 6A ?? 50 56 53 FF D7 85 C0 + 75 ?? 50 FF 15 ?? ?? ?? ?? 5F 33 F6 5B A1 ?? ?? ?? ?? C1 E8 ?? 6B C0 ?? 68 ?? ?? ?? + ?? 56 56 50 FF 75 ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 56 EB ?? 5E C9 + C3 } - $find_files_p7 = { - 8D 45 ?? 3B C6 74 ?? 8B 4D ?? 83 F9 ?? 72 ?? 41 51 FF 75 ?? 8B C8 E8 ?? ?? ?? ?? 33 - C0 C7 45 ?? ?? ?? ?? ?? 56 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? - 8B 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? 83 7D ?? ?? 8D 8D ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF 15 ?? ?? ?? ?? 8B 75 - ?? 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 0F 1F 00 33 C0 C7 45 ?? ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 45 ?? - 6A ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF - 75 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 8D 85 ?? ?? ?? ?? 83 EC ?? F6 85 ?? ?? ?? ?? ?? 8B CC 50 0F 84 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B CF E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 5D ?? 8D 45 ?? 50 8D 4D ?? FF 73 ?? 53 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? - 2B CE 83 F9 ?? 0F 82 ?? ?? ?? ?? 89 43 ?? 46 8B 48 ?? 89 75 ?? 89 01 8B 45 ?? 83 F8 - ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 8D ?? ?? ?? ?? 54 E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 85 C0 74 - ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B CF 50 E8 ?? ?? ?? ?? 8B - 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF - 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 85 F6 0F 85 ?? - ?? ?? ?? FF 75 ?? FF 15 + $encrypt_encryption_key = { + 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 68 ?? ?? ?? ?? 8D 45 ?? 8D 4D ?? E8 + ?? ?? ?? ?? 83 78 ?? ?? 59 72 ?? 8B 00 53 56 57 33 DB 53 53 6A ?? 53 53 68 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 33 FF 8D 75 ?? 89 45 ?? E8 ?? ?? ?? ?? 39 5D ?? 0F 84 + ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? BF ?? ?? ?? ?? 57 FF D3 99 83 E2 ?? 03 C2 C1 F8 ?? 6B + C0 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 57 8B F0 FF D3 50 57 E8 ?? ?? + ?? ?? 59 59 57 FF D3 99 83 E2 ?? 03 C2 C1 F8 ?? 6B C0 ?? 89 45 ?? 8D 45 ?? 50 56 6A + ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 85 C0 75 ?? FF 15 ?? ?? ?? + ?? 8D 45 ?? 50 57 FF D3 99 83 E2 ?? 03 C2 C1 F8 ?? 6B C0 ?? 50 56 FF 75 ?? FF 15 ?? + ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 6A ?? 33 FF 8D 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 } $encrypt_files_p1 = { - FF 15 ?? ?? ?? ?? 85 C0 75 ?? 50 FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D - 45 ?? 83 7D ?? ?? 0F 43 45 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 C0 C7 45 ?? ?? - ?? ?? ?? 6A ?? 50 66 89 45 ?? 8D 4D ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 6A ?? 0F - 43 45 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 89 45 ?? FF 15 ?? ?? ?? - ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? 8B 4D ?? 01 0D ?? ?? ?? ?? 8B 55 ?? 11 15 ?? ?? ?? ?? 83 FA ?? 0F 8C ?? ?? - ?? ?? 7F ?? 85 C9 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? 66 66 0F 1F 84 00 - ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 - FF 74 ?? 8B 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 8B 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? C7 45 ?? ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 8B 4D ?? 83 C4 ?? 6A + 55 8B EC 83 E4 ?? 83 EC ?? A1 ?? ?? ?? ?? 33 C4 89 44 24 ?? 83 7D ?? ?? 8B 45 ?? 53 + 56 57 73 ?? 8D 45 ?? 33 DB 53 53 6A ?? 53 53 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 + 44 24 ?? 3B C3 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? 51 50 FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? + 6B C0 ?? 83 C0 ?? 83 F8 ?? 0F 8E ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 6A ?? 89 44 24 ?? + E8 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? BE + ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 56 89 44 24 ?? E8 ?? ?? ?? ?? FF 74 24 ?? 8B 54 24 ?? + 89 44 24 ?? E8 ?? ?? ?? ?? FF 74 24 ?? 8B 54 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? FF 15 ?? + ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 7E ?? 68 ?? ?? ?? ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 6A ?? + 33 FF E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 53 53 FF 74 24 ?? FF 74 24 ?? + FF 74 24 ?? FF D7 53 FF 15 ?? ?? ?? ?? 53 8D 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? + FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 + F8 ?? 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 53 03 C6 53 13 CB 51 50 FF 74 24 ?? + FF D7 53 8D 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B 44 24 ?? 8B } $encrypt_files_p2 = { - 50 E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 57 53 FF 15 ?? ?? ?? ?? - 8B 55 ?? 8B 4D ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 56 8D 85 - ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 6A ?? 6A ?? 50 53 FF 15 ?? - ?? ?? ?? 8B 55 ?? 8D 45 ?? 8B 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 50 56 53 FF 15 ?? ?? ?? ?? 83 6D ?? ?? 0F 85 ?? ?? ?? ?? 57 E8 ?? ?? - ?? ?? 56 E9 ?? ?? ?? ?? 8B F1 8B C2 81 C6 ?? ?? ?? ?? 83 D0 ?? 83 F8 ?? 0F 87 ?? ?? - ?? ?? 72 ?? 81 FE ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F - 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? 66 90 - 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 - 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 8B - 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 55 - ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 + 4C 24 ?? 53 05 ?? ?? ?? ?? 53 13 CB 51 50 FF 74 24 ?? FF D7 53 E8 ?? ?? ?? ?? 0B C2 + 59 74 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 6A ?? 33 FF 8D 74 24 ?? E8 ?? ?? + ?? ?? 8B 3D ?? ?? ?? ?? 53 8D 44 24 ?? 50 FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 74 + 24 ?? FF 15 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 3B C3 0F 8C ?? ?? ?? ?? 7F ?? 81 F9 + ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 89 5C 24 ?? 89 5C 24 ?? 3B C3 0F 8C ?? ?? ?? ?? 7F ?? + 3B CB 0F 86 ?? ?? ?? ?? BE ?? ?? ?? ?? EB ?? 8B 4C 24 ?? 2B 4C 24 ?? 1B 44 24 ?? 89 + 44 24 ?? 0F 88 ?? ?? ?? ?? 7F ?? 81 F9 ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 56 53 FF 15 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 53 53 FF 74 24 ?? 89 44 24 ?? FF 74 24 ?? FF 74 24 ?? + FF D7 53 8D 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 8B + 54 24 ?? 51 56 FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 53 FF 74 24 ?? FF 74 24 ?? FF + 74 24 ?? FF D7 53 8D 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? FF 74 24 ?? 53 50 FF 15 ?? ?? ?? ?? 81 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? + 11 5C 24 ?? 39 44 24 ?? 0F 8C ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 8B 4C 24 ?? 39 4C 24 ?? + 0F 82 ?? ?? ?? ?? E9 ?? ?? ?? ?? 3B C3 0F 8C ?? ?? ?? ?? 7F ?? 81 F9 ?? ?? ?? ?? 0F } $encrypt_files_p3 = { - E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? C7 45 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 8B 4D ?? 83 C4 ?? 6A ?? 50 E8 ?? ?? - ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 57 53 FF 15 ?? ?? ?? ?? 8B 55 ?? 8B - 4D ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 56 8D 85 ?? ?? ?? ?? - 57 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 6A ?? 6A ?? 50 53 FF 15 ?? ?? ?? ?? 8B - 55 ?? 8D 45 ?? 8B 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 50 56 53 FF 15 ?? ?? ?? ?? 83 6D ?? ?? 0F 85 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 56 E9 - ?? ?? ?? ?? 8B F1 8B C2 81 C6 ?? ?? ?? ?? 83 D0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 72 ?? - 81 FE ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? 66 90 68 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 8B 55 ?? 8B 4D - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 8B F0 83 C4 ?? 85 F6 74 ?? C7 45 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 + 86 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 74 24 ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 E8 ?? ?? + ?? ?? 59 89 44 24 ?? FF 15 ?? ?? ?? ?? 53 53 33 C9 51 33 C0 50 FF 74 24 ?? FF D7 53 + 8D 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 8B 54 24 ?? + 51 56 FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 53 33 C0 50 50 FF 74 24 ?? FF D7 53 8D + 44 24 ?? 50 56 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? + 59 E9 ?? ?? ?? ?? 51 53 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? FF 15 ?? + ?? ?? ?? 53 53 33 C0 50 53 FF 74 24 ?? FF D7 53 8D 44 24 ?? 50 FF 74 24 ?? FF 74 24 + ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 8B 4C 24 + ?? 8B 54 24 ?? 51 FF 74 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 53 33 C0 50 53 + FF 74 24 ?? FF D7 53 8D 44 24 ?? 50 FF 74 24 ?? FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? + ?? ?? FF 74 24 ?? 53 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 33 FF 8D 74 24 ?? + E8 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? FF 74 24 ?? + E8 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 8D 45 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 72 ?? 8B 00 83 7D ?? ?? 8B + 4D ?? 73 ?? 8D 4D ?? 50 51 FF 15 ?? ?? ?? ?? 6A ?? 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? + 6A ?? 33 FF 8D 75 ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 + 5D C3 } - $encrypt_files_p4 = { - 50 E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 8B 4D ?? 83 C4 ?? 6A ?? 50 E8 ?? ?? ?? ?? F2 0F - 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 57 53 FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? E8 ?? - ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 56 8D 85 ?? ?? ?? ?? 57 50 E8 ?? - ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 6A ?? 6A ?? 50 53 FF 15 ?? ?? ?? ?? 8B 55 ?? 8D 45 - ?? 8B 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 56 53 - FF 15 ?? ?? ?? ?? 83 6D ?? ?? 0F 85 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 56 E9 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 0F 1F 84 00 ?? ?? ?? ?? - 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B F0 83 C4 - ?? 85 F6 74 ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? 66 - 0F 1F 84 00 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 - ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 45 ?? 6A ?? 50 FF 75 ?? 56 53 FF 15 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? - ?? ?? ?? 57 56 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 6A ?? 6A ?? 50 53 FF 15 ?? - ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 57 53 FF 15 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 57 E8 - ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 0F 57 C0 66 0F 13 45 ?? 6A ?? 50 6A ?? 53 FF 15 ?? ?? - ?? ?? 8B 75 ?? 8D 45 ?? 6A ?? 50 FF B6 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? - ?? 50 FF B6 ?? ?? ?? ?? 53 FF D7 8B 35 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 6A ?? 6A ?? 6A - ?? 6A ?? FF 35 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF D6 85 C0 0F - 84 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 35 ?? ?? ?? - ?? FF D6 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 0F 1F 40 ?? 8B 45 ?? 03 C0 50 E8 ?? - ?? ?? ?? 8B F0 83 C4 ?? 80 3E ?? 74 ?? 8B 45 ?? 8B CE 85 C0 74 ?? 66 90 C6 01 ?? 8D - 49 ?? 83 E8 ?? 75 ?? 8D 45 ?? 50 56 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 56 53 FF D7 6A ?? 8D 45 ?? 50 8B 45 ?? FF B0 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 50 8B 45 ?? FF B0 ?? ?? ?? ?? 53 FF D7 53 FF 15 ?? ?? ?? - ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 83 7D ?? ?? 0F 43 45 ?? 6A ?? 50 FF 75 ?? FF - 15 + $find_files_1 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 56 + 57 6A ?? 5E 33 C0 33 FF 6A ?? 66 89 44 24 ?? 57 8D 45 ?? 8D 4C 24 ?? 89 74 24 ?? 89 + 7C 24 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 66 + 89 44 24 ?? 66 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? 03 44 24 ?? 8D 4C 24 ?? 89 74 24 ?? + 89 7C 24 ?? 89 74 24 ?? 89 7C 24 ?? E8 ?? ?? ?? ?? 57 8D 44 24 ?? 50 83 C8 ?? 8D 74 + 24 ?? E8 ?? ?? ?? ?? 57 8D 84 24 ?? ?? ?? ?? 50 83 C8 ?? E8 ?? ?? ?? ?? 8B DE 8D 44 + 24 ?? E8 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 8B 44 24 ?? 73 ?? 8D 44 24 + ?? 8D 8C 24 ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? + ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 } - $remote_connection = { - FF 15 ?? ?? ?? ?? 8B F8 89 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 8B 4D ?? 83 79 ?? ?? 72 ?? - 8B 09 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 51 57 FF 15 ?? ?? ?? ?? 8B F0 89 75 ?? 85 - F6 0F 84 ?? ?? ?? ?? 8B 4D ?? 53 83 79 ?? ?? 75 ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? BB ?? ?? ?? ?? EB ?? 51 8D 45 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BB - ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? 8B C8 6A ?? E8 ?? ?? ?? ?? 33 C9 C7 45 ?? ?? ?? ?? - ?? 66 89 4D ?? 8D 4D ?? 50 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 C3 ?? 74 ?? 8D 4D - ?? 83 E3 ?? E8 ?? ?? ?? ?? F6 C3 ?? 5B 74 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D - 4D ?? 6A ?? 68 ?? ?? ?? ?? 51 6A ?? 68 ?? ?? ?? ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 0F - 43 45 ?? 50 68 ?? ?? ?? ?? 56 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F - 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 3D ?? ?? - ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF D7 85 C0 74 ?? 8B 45 ?? - 85 C0 74 ?? C6 84 05 ?? ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 33 C9 EB ?? 8D 8D ?? - ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? - ?? ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF D7 85 C0 75 ?? 8B 7D - ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 45 - ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 83 7D - ?? ?? 8D 4D ?? 8B 45 ?? 8D 55 ?? 0F 43 4D ?? 8B 75 ?? 03 C1 83 7D ?? ?? 8D 4D ?? 52 - 0F 43 4D ?? 50 51 8B CE E8 ?? ?? ?? ?? 8B 4D ?? 83 F9 ?? 72 ?? 41 51 FF 75 ?? 8D 4D - ?? E8 + $find_files_2 = { + D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? F6 + 84 24 ?? ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 4C 24 ?? 8D 44 24 ?? 74 ?? E8 ?? ?? + ?? ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 59 8B D8 59 8D 44 24 ?? E8 ?? ?? ?? ?? 6A ?? 33 + FF 8D 74 24 ?? E8 ?? ?? ?? ?? 6A ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 83 EC ?? 8B CC 21 79 + ?? 33 C0 6A ?? C7 41 ?? ?? ?? ?? ?? 66 89 01 50 8D 44 24 ?? E8 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 59 8D 44 24 ?? E8 ?? ?? ?? ?? 6A + ?? 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 50 8D + 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 6A ?? 5F 39 7C 24 ?? 73 ?? 8D 44 24 ?? 8B 35 ?? + ?? ?? ?? 68 + } + $find_files_3 = { + 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 39 7C 24 ?? 73 ?? 8D 44 24 ?? 68 ?? ?? + ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 39 7C 24 ?? 73 ?? 8D 44 24 ?? 68 + ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 39 7C 24 ?? 73 ?? 8D 44 24 + ?? 68 ?? ?? ?? ?? 50 FF D6 85 C0 74 ?? 8B 44 24 ?? 39 7C 24 ?? 73 ?? 8D 44 24 ?? 68 + ?? ?? ?? ?? 50 FF D6 85 C0 74 ?? 8B 44 24 ?? 39 7C 24 ?? 73 ?? 8D 44 24 ?? 68 ?? ?? + ?? ?? 50 FF D6 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 74 ?? + 8B 4C 24 ?? 39 7C 24 ?? 73 ?? 8D 4C 24 ?? 83 EC ?? 8B C4 51 E8 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? 6A ?? 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 74 + 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 33 DB + 43 53 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? 53 8D B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 8D + 74 24 ?? E8 ?? ?? ?? ?? 53 8D 75 ?? E8 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E 5B 33 + CC E8 ?? ?? ?? ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and (( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and $remote_connection) + uint16(0)==0x5A4D and ( all of ($find_files_*)) and ($create_encryption_key) and ($encrypt_encryption_key) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Linux_Ransomware_Gwisinlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win64_Ransomware_Pandora : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects GwisinLocker ransomware." + description = "Yara rule that detects Pandora ransomware." author = "ReversingLabs" - id = "9f00e1b4-3692-5824-b614-724073532c1f" - date = "2022-10-11" - modified = "2022-10-11" + id = "18182bbe-1678-5d0b-a7ee-80c4bbaee99e" + date = "2022-06-01" + modified = "2022-06-01" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Linux.Ransomware.GwisinLocker.yara#L1-L354" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "c23c0b73bbefbd644ffe1398e1f14eec3a89945cb3c3ccbc6f46c57046b53505" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Pandora.yara#L1-L95" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6576bde36ae9a9bc2e9dd878db788c608083b84d96d31e6898f48a264c6b7f1a" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -40427,308 +40812,163 @@ rule REVERSINGLABS_Linux_Ransomware_Gwisinlocker : TC_DETECTION MALICIOUS MALWAR sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "GwisinLocker" + tc_detection_name = "Pandora" tc_detection_factor = 5 importance = 25 strings: - $init_key_v1 = { - 55 57 56 53 E8 ?? ?? ?? ?? 81 C3 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 8D 74 24 ?? 56 E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 31 FF 83 EC ?? 56 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 89 - F8 5B 5E 5F 5D C3 66 90 31 D2 31 C0 89 54 04 ?? 83 C0 ?? 83 F8 ?? 72 ?? 83 EC ?? 8D - 83 ?? ?? ?? ?? 50 8D 83 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 C5 8D 7C 24 ?? 85 - C0 74 ?? 50 6A ?? 6A ?? 57 E8 ?? ?? ?? ?? 89 2C 24 E8 ?? ?? ?? ?? 83 C4 ?? 83 EC ?? - 6A ?? 57 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? C7 04 24 ?? ?? ?? ?? 83 EC ?? 8D 44 - 24 ?? 50 FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 6A ?? FF B3 - ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 56 FF B3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 - 0F 94 C0 0F B6 C0 89 C7 E9 + $find_files_p1 = { + 41 57 41 56 41 55 41 54 56 57 55 53 48 83 EC ?? 48 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? + ?? 45 31 F6 41 BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? + ?? 48 89 4C 24 ?? 45 31 C0 41 81 FA ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 0F + 4C CA 41 0F 94 C0 48 8B 8C 08 ?? ?? ?? ?? 48 01 F1 31 D2 31 DB 41 81 FA ?? ?? ?? ?? + 0F 9C C2 0F 95 C3 41 BD ?? ?? ?? ?? 49 29 D5 41 81 FA ?? ?? ?? ?? BF ?? ?? ?? ?? BA + ?? ?? ?? ?? 48 0F 4C FA 4C 8D 4C 9B ?? 41 BB ?? ?? ?? ?? BA ?? ?? ?? ?? 4C 0F 44 DA + 49 83 C8 ?? 31 DB 31 D2 41 81 FA ?? ?? ?? ?? 0F 9C C3 4C 8D 64 1B ?? 0F 94 C2 48 83 + F2 ?? 31 DB 41 81 FA ?? ?? ?? ?? 0F 94 C3 48 8D 1C DB 48 83 C3 ?? EB ?? 0F 1F 40 ?? + 4A 8B AC C0 ?? ?? ?? ?? 48 01 F5 FF E5 FF E1 4A 8B AC E0 ?? ?? ?? ?? 48 01 F5 FF E5 + 48 8B AC D8 ?? ?? ?? ?? 48 01 F5 FF E5 0F 1F 80 ?? ?? ?? ?? 48 8B AC F8 ?? ?? ?? ?? + 48 01 F5 FF E5 4A 8B AC E8 ?? ?? ?? ?? 48 01 F5 FF E5 4A 8B AC D8 ?? ?? ?? ?? 48 01 } - $encrypt_files_v1_p1 = { - 55 B9 ?? ?? ?? ?? 57 56 53 E8 ?? ?? ?? ?? 81 C3 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 8B 84 - 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 8D 44 24 ?? 83 EC ?? 89 44 24 ?? 89 - C7 31 C0 F3 AB C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? 6A ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 84 24 ?? ?? ?? ?? 89 44 - 24 ?? 8D 84 24 ?? ?? ?? ?? 89 44 24 ?? 31 FF 83 EC ?? 68 ?? ?? ?? ?? FF 74 24 ?? E8 - ?? ?? ?? ?? 58 5A 6A ?? FF 74 24 ?? E8 ?? ?? ?? ?? 59 5E 6A ?? FF 74 24 ?? E8 ?? ?? - ?? ?? 81 C4 ?? ?? ?? ?? 89 F8 5B 5E 5F 5D C3 8D 74 26 ?? 90 83 EC ?? 6A ?? 8D 84 24 - ?? ?? ?? ?? 89 44 24 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D B4 24 ?? ?? ?? ?? 89 74 24 ?? - 85 C0 74 ?? 83 EC ?? 6A ?? FF 74 24 ?? 56 E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? 59 5E 50 - 89 C5 FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? 89 C6 83 C4 ?? 85 C0 0F 84 ?? - ?? ?? ?? 83 EC ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 89 C7 FF B4 24 ?? - ?? ?? ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 94 24 ?? ?? ?? ?? 01 FA 89 D0 8B 54 - 24 ?? 89 10 0F B7 54 24 ?? 66 89 50 ?? 0F B6 54 24 ?? 88 50 ?? 8B 94 24 ?? ?? ?? ?? - C6 44 3A ?? ?? BF ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? - ?? ?? ?? B9 ?? ?? ?? ?? 83 C4 ?? 39 C1 B9 ?? ?? ?? ?? 19 D1 7D ?? 83 EC ?? FF B4 24 - ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 83 EC ?? FF 74 - 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8D 74 26 ?? 90 83 EC ?? 56 E8 ?? ?? ?? - ?? 58 5A 55 FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? 89 C6 83 C4 ?? 85 C0 0F + $find_files_p2 = { + F5 FF E5 66 0F 1F 84 00 ?? ?? 00 00 48 8B AC D0 ?? ?? ?? ?? 48 01 F5 FF E5 4A 8B AC + C8 ?? ?? ?? ?? 48 01 F5 FF E5 44 89 74 24 ?? 48 63 4C 24 ?? 48 8B 54 24 ?? 48 8B 8C + CA ?? ?? ?? ?? 48 89 4C 24 ?? 48 8B 4C 24 ?? 8B 54 24 ?? BD ?? ?? ?? ?? 01 EA 44 8B + 54 24 ?? BD ?? ?? ?? ?? 41 01 EA 66 83 39 ?? 44 0F 45 D2 E9 ?? ?? ?? ?? 45 31 FF EB + ?? 66 2E 0F 1F 84 00 ?? ?? 00 00 90 41 BF ?? ?? ?? ?? 44 8B 54 24 ?? 41 81 C2 ?? ?? + ?? ?? E9 ?? ?? ?? ?? 66 0F 1F 84 00 ?? ?? 00 00 44 8B 74 24 ?? 41 83 C6 ?? 48 8B 54 + 24 ?? 48 8B 05 ?? ?? ?? ?? 48 8B 80 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 01 C8 48 8B 4C 24 + ?? FF D0 8B 4C 24 ?? BA ?? ?? ?? ?? 01 D1 44 8B 54 24 ?? BA ?? ?? ?? ?? 41 01 D2 85 + C0 44 0F 44 D1 E9 ?? ?? ?? ?? 44 89 F8 48 83 C4 ?? 5B 5D 5F 5E 41 5C 41 5D 41 5E 41 + 5F C3 } - $encrypt_files_v1_p2 = { - 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 8B 74 24 - ?? 8B 7C 24 ?? 89 D1 89 74 24 ?? 89 7C 24 ?? 83 C4 ?? 39 F0 19 F9 7D ?? 89 44 24 ?? - 89 54 24 ?? 8B 7C 24 ?? 8B 74 24 ?? 89 F9 89 F5 C1 F9 ?? 89 C8 89 4C 24 ?? 31 CD 8B - 74 24 ?? C1 F8 ?? 89 44 24 ?? 89 E8 29 F0 8B 74 24 ?? 89 C7 83 E7 ?? 31 CF 89 F8 8B - 7C 24 ?? 29 F0 8B 74 24 ?? 89 FA 19 FA 8B 7C 24 ?? 29 C6 89 74 24 ?? 19 D7 83 EC ?? - 89 7C 24 ?? 8D 44 24 ?? 50 E8 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? - B9 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 31 C0 F3 AB 89 94 24 ?? ?? ?? ?? 56 6A ?? FF 74 - 24 ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 C7 85 C0 0F 84 ?? ?? ?? ?? 83 - EC ?? FF 74 24 ?? E8 ?? ?? ?? ?? 5F 5D FF B4 24 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 - ?? 89 C7 85 C0 0F 84 ?? ?? ?? ?? 8B B4 24 ?? ?? ?? ?? 8B 54 24 ?? 31 FF 8B 44 24 ?? - 89 7C 24 ?? 89 74 24 ?? 8D 74 24 ?? 89 D7 89 74 24 ?? 8D B3 ?? ?? ?? ?? 09 C7 89 74 + $generate_key = { + 41 57 41 56 41 55 41 54 56 57 55 53 48 81 EC ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 + 8D B4 24 ?? ?? ?? ?? 48 89 74 24 ?? 48 8B 44 24 ?? 48 8B 05 ?? ?? ?? ?? 48 C7 C5 ?? + ?? ?? ?? 48 8B 80 ?? ?? ?? ?? 48 01 E8 41 BC ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 4C 01 + E1 BA ?? ?? ?? ?? 48 03 15 ?? ?? ?? ?? FF D0 48 8B 05 ?? ?? ?? ?? 48 8B 4C 24 ?? 0F + B7 90 ?? ?? ?? ?? 66 89 51 ?? 48 8B 80 ?? ?? ?? ?? 48 89 01 48 8B 05 ?? ?? ?? ?? 48 + 8B 80 ?? ?? ?? ?? 48 01 E8 48 8B 0D ?? ?? ?? ?? 4C 01 E1 FF D0 48 8B 05 ?? ?? ?? ?? + 48 8B 80 ?? ?? ?? ?? 48 01 E8 48 8B 0D ?? ?? ?? ?? 4C 01 E1 FF D0 48 8B 05 ?? ?? ?? + ?? 48 8B 80 ?? ?? ?? ?? 48 01 E8 48 89 F1 FF D0 48 98 4C 8B 05 ?? ?? ?? ?? 4D 01 E0 + 48 8B 0D ?? ?? ?? ?? 48 8B 99 ?? ?? ?? ?? 48 01 EB 48 8B 0D ?? ?? ?? ?? 4C 01 E1 48 + 89 44 24 ?? 48 8D 15 ?? ?? ?? ?? 49 89 F1 FF D3 89 84 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? + 45 31 ED 41 BE ?? ?? ?? ?? 41 BF ?? ?? ?? ?? BB ?? ?? ?? ?? EB ?? 81 F9 ?? ?? ?? ?? + BA ?? ?? ?? ?? BF ?? ?? ?? ?? 48 0F 44 D7 48 8B 04 10 4C 01 F0 FF E0 } - $encrypt_files_v1_p3 = { - 24 ?? 0F 84 ?? ?? ?? ?? 8B 4C 24 ?? 8B 6C 24 ?? 89 4C 24 ?? EB ?? 66 90 83 EC ?? 31 - ED FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF 74 24 ?? FF 74 - 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 31 D2 6A ?? 8B 84 24 ?? ?? ?? ?? 52 F7 D8 - 50 57 E8 ?? ?? ?? ?? 57 FF B4 24 ?? ?? ?? ?? 6A ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 44 24 ?? 8B BC 24 ?? ?? ?? ?? 8B 54 24 ?? 29 F8 19 EA 89 44 24 ?? 89 D6 89 54 - 24 ?? 83 C4 ?? 09 C6 74 ?? 39 84 24 ?? ?? ?? ?? 89 E9 8B 7C 24 ?? 19 D1 0F 4C 84 24 - ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? ?? - ?? 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 57 - FF B4 24 ?? ?? ?? ?? 6A ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 39 84 24 ?? - ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 EC ?? BF ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 - ?? E9 ?? ?? ?? ?? 83 EC ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? E9 + $drop_ransom_note = { + 48 8B 05 ?? ?? ?? ?? 48 8B 80 ?? ?? ?? ?? BD ?? ?? ?? ?? 48 01 E8 48 8B 0D ?? ?? ?? + ?? BE ?? ?? ?? ?? 48 01 F1 48 8B 15 ?? ?? ?? ?? BF ?? ?? ?? ?? 48 01 FA FF D0 48 8B + 0D ?? ?? ?? ?? 48 01 F1 48 8B 05 ?? ?? ?? ?? 48 8B 90 ?? ?? ?? ?? 48 01 EA FF D2 48 + 8B 15 ?? ?? ?? ?? 48 01 F2 48 8B 8C 24 ?? ?? ?? ?? 48 8B 35 ?? ?? ?? ?? 48 8B B6 ?? + ?? ?? ?? 48 01 EE 48 C7 44 24 ?? ?? ?? ?? ?? 41 89 C0 4C 8D 4C 24 ?? FF D6 BE ?? ?? + ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 8B 90 ?? ?? ?? ?? 41 BE ?? ?? + ?? ?? 48 01 EA FF D2 BF ?? ?? ?? ?? 8B 4C 24 ?? B8 ?? ?? ?? ?? 01 C1 E9 ?? ?? ?? ?? + 81 F9 ?? ?? ?? ?? BA ?? ?? ?? ?? BD ?? ?? ?? ?? 48 0F 44 D5 48 8B 04 10 4C 01 E0 FF + E0 8B 44 24 ?? 83 C0 ?? 89 44 24 ?? 8B 4C 24 ?? B8 ?? ?? ?? ?? 01 C1 E9 ?? ?? ?? ?? + 81 F9 ?? ?? ?? ?? BA ?? ?? ?? ?? BD ?? ?? ?? ?? 48 0F 44 D5 48 8B 04 10 4C 01 E0 FF + E0 8B 4C 24 ?? B8 ?? ?? ?? ?? 01 C1 E9 ?? ?? ?? ?? 81 F9 ?? ?? ?? ?? BA ?? ?? ?? ?? + BD ?? ?? ?? ?? 48 0F 44 D5 48 8B 04 10 4C 01 E0 FF E0 8B 4C 24 ?? B8 ?? ?? ?? ?? 01 + C1 C7 44 24 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 81 F9 ?? ?? ?? ?? BA ?? ?? ?? ?? BD ?? ?? + ?? ?? 48 0F 44 D5 48 8B 04 10 4C 01 E0 FF E0 48 8B 05 ?? ?? ?? ?? 48 8B 88 ?? ?? ?? + ?? 48 8B 05 ?? ?? ?? ?? 48 8B 80 ?? ?? ?? ?? 4C 01 F0 C7 44 24 ?? ?? ?? ?? ?? 48 8D + 54 24 ?? 4C 8D 84 24 ?? ?? ?? ?? 4C 8D 4C 24 ?? FF D0 BF ?? ?? ?? ?? 8B 54 24 ?? B9 + ?? ?? ?? ?? 01 CA 8B 4C 24 ?? BD ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? + 48 8B 84 24 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 31 C0 48 81 + C4 ?? ?? ?? ?? 5B 5D 5F 5E 41 5C 41 5D 41 5E 41 5F C3 } - $find_files_v1_p1 = { - 55 89 C5 57 E8 ?? ?? ?? ?? 81 C7 ?? ?? ?? ?? 56 53 81 EC ?? ?? ?? ?? 89 54 24 ?? 8B - B4 24 ?? ?? ?? ?? 89 7C 24 ?? 89 FB 89 4C 24 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 44 24 - ?? C7 44 24 ?? ?? ?? ?? ?? 85 C0 74 ?? 8D 58 ?? 80 7C 05 ?? ?? 0F 45 D8 89 5C 24 ?? - 8B BC 24 ?? ?? ?? ?? 83 E7 ?? 74 ?? 83 EC ?? 8D 44 24 ?? 89 44 24 ?? 50 55 6A ?? 8B - 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 5C 24 ?? E8 ?? ?? ?? ?? 8B 00 83 F8 - ?? 0F 85 ?? ?? ?? ?? BF ?? ?? ?? ?? C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 8D - B4 26 ?? ?? ?? ?? 66 90 83 EC ?? 8D 44 24 ?? 89 44 24 ?? 50 55 6A ?? 8B 5C 24 ?? E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 78 ?? 8B 84 24 ?? ?? ?? ?? 25 ?? ?? ?? ?? 3D ?? ?? ?? ?? - 0F 84 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? C6 44 24 ?? ?? 31 FF C7 44 24 ?? - ?? ?? ?? ?? 8B 54 24 ?? 8B 44 24 ?? F6 84 24 ?? ?? ?? ?? ?? 74 ?? 85 F6 0F 84 ?? ?? - ?? ?? 8B 4E ?? 8B 5E ?? 31 D1 31 C3 09 CB 0F 84 ?? ?? ?? ?? 31 FF 81 C4 ?? ?? ?? ?? - 89 F8 5B 5E 5F 5D C3 8D 74 26 ?? 90 8B 5C 24 ?? E8 ?? ?? ?? ?? 89 C7 8B 00 83 F8 ?? - 0F 85 ?? ?? ?? ?? 83 EC ?? FF 74 24 ?? 55 6A ?? 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? - 85 C0 0F 85 ?? ?? ?? ?? BF ?? ?? ?? ?? C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? E9 ?? - ?? ?? ?? 8D 74 26 ?? 90 89 54 24 ?? 8B 94 24 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? - ?? ?? 89 74 24 ?? 89 44 24 ?? 89 54 24 ?? 85 F6 0F 84 ?? ?? ?? ?? 8B 46 ?? 8B 4C 24 - ?? 83 C0 ?? 83 C1 ?? 89 44 24 ?? 89 44 24 ?? 8B 46 ?? 89 4C 24 ?? 89 4C 24 ?? 89 44 + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($generate_key) and ($drop_ransom_note) +} +rule REVERSINGLABS_Win64_Ransomware_Wintenzz : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Wintenzz ransomware." + author = "ReversingLabs" + id = "6bf569e8-b050-51ef-a948-0eb294248d63" + date = "2021-11-02" + modified = "2021-11-02" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Wintenzz.yara#L1-L83" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ff4bdf2f6ee185b98d0014b3066806fe7e25ea94f46837948bc5262440bf8a56" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Wintenzz" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files = { + 48 8D 75 ?? 41 B8 ?? ?? ?? ?? 48 89 F1 31 D2 E8 ?? ?? ?? ?? 48 89 F9 48 89 F2 E8 ?? + ?? ?? ?? 48 83 F8 ?? 0F 84 ?? ?? ?? ?? 48 89 C6 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? + ?? ?? 0F 28 85 ?? ?? ?? ?? 0F 29 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? 0F 11 00 0F 28 85 ?? ?? ?? + ?? 0F 11 40 ?? 48 8B 8D ?? ?? ?? ?? 48 89 48 ?? 49 89 77 ?? 49 89 47 ?? 41 C7 47 ?? + ?? ?? ?? ?? 49 8D 4F ?? 48 8D 55 ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 B6 ?? 31 C0 + 49 89 07 48 85 DB 75 ?? EB ?? E8 ?? ?? ?? ?? 48 C1 E0 ?? 49 89 47 ?? 49 C7 47 ?? ?? + ?? ?? ?? B8 ?? ?? ?? ?? 31 F6 49 89 07 48 85 DB 74 ?? 48 01 DB 74 ?? 41 B8 ?? ?? ?? + ?? 48 89 F9 48 89 DA E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 D2 74 ?? 41 B8 ?? ?? + ?? ?? 4C 89 F1 E8 ?? ?? ?? ?? 40 84 F6 75 ?? 48 8B 8D ?? ?? ?? ?? 48 85 C9 74 ?? 48 + 8B 95 ?? ?? ?? ?? 48 85 D2 74 ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 F8 48 81 C4 + ?? ?? ?? ?? 5B 5F 5E 41 5E 41 5F 5D C3 BA } - $find_files_v1_p2 = { - 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 83 FF ?? 0F 84 ?? ?? ?? ?? 8B - 84 24 ?? ?? ?? ?? 83 E0 ?? 89 44 24 ?? 75 ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 74 24 ?? - 55 8B 44 24 ?? FF D0 89 C7 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 85 F6 74 ?? 8B 84 24 ?? - ?? ?? ?? 8B 5C 24 ?? 89 6C 24 ?? 8B 4C 24 ?? 8B BC 24 ?? ?? ?? ?? 89 C5 EB ?? 8D B6 - ?? ?? ?? ?? 8B 36 85 F6 74 ?? 8B 46 ?? 8B 56 ?? 31 D8 31 CA 09 C2 75 ?? 8B 46 ?? 8B - 56 ?? 31 E8 31 FA 09 C2 0F 84 ?? ?? ?? ?? 8B 36 85 F6 75 ?? 8B 6C 24 ?? 8B 7C 24 ?? - 85 FF 74 ?? 80 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? 8B 44 24 ?? C6 44 05 ?? ?? 8B 44 24 ?? - 85 C0 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 74 24 ?? 55 8B 44 24 ?? FF D0 - 83 C4 ?? 89 C7 81 C4 ?? ?? ?? ?? 89 F8 5B 5E 5F 5D C3 66 90 83 EC ?? 6A ?? 55 8B 5C - 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 89 44 24 ?? 89 C7 E8 ?? ?? ?? ?? 8B 00 89 44 24 ?? - 83 C4 ?? 85 FF 79 ?? 83 F8 ?? 0F B6 4C 24 ?? BA ?? ?? ?? ?? 0F 94 C0 84 C0 B8 ?? ?? - ?? ?? 0F 44 44 24 ?? 0F 45 CA 89 44 24 ?? 88 4C 24 ?? 8B 44 24 ?? 85 C0 0F 85 ?? ?? - ?? ?? 83 EC ?? FF 74 24 ?? 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8D B4 - 26 ?? ?? ?? ?? 8D 76 ?? 89 54 24 ?? 8B 94 24 ?? ?? ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 89 54 24 ?? 8B 44 24 ?? C7 44 24 ?? ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 48 ?? 89 4C 24 ?? 89 4C 24 ?? 85 C0 74 ?? 80 7C 05 - ?? ?? 74 ?? E9 ?? ?? ?? ?? 8D 76 ?? 80 7C 05 ?? ?? 0F 85 ?? ?? ?? ?? 83 E8 ?? 75 ?? - 31 D2 89 54 24 ?? E9 ?? ?? ?? ?? 8D 74 26 ?? 90 89 54 24 ?? 8B 94 24 ?? ?? ?? ?? 89 - } - $find_files_v1_p3 = { - 44 24 ?? 8B 84 24 ?? ?? ?? ?? 89 74 24 ?? 89 44 24 ?? 89 54 24 ?? E9 ?? ?? ?? ?? 90 - 8B 84 24 ?? ?? ?? ?? BF ?? ?? ?? ?? C6 44 24 ?? ?? 83 E0 ?? 83 F8 ?? 19 C0 83 E0 ?? - 83 C0 ?? 89 44 24 ?? E9 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 90 8B 74 24 ?? 85 F6 0F 88 - ?? ?? ?? ?? 83 EC ?? FF 74 24 ?? 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 C6 85 C0 0F - 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B 44 24 ?? 89 44 24 ?? 8D B4 26 ?? ?? ?? ?? 8D 76 ?? - 83 EC ?? 56 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 80 78 ?? ?? - 0F 84 ?? ?? ?? ?? 83 EC ?? 8D 78 ?? 57 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 3B 44 24 - ?? 0F 83 ?? ?? ?? ?? 8B 44 24 ?? 83 EC ?? C6 44 05 ?? ?? 57 8B 44 24 ?? 01 E8 50 8B - 5C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 5A 5B 8D 48 ?? 8D 44 24 ?? 50 89 E8 FF B4 24 ?? - ?? ?? ?? 8B 54 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 EC ?? 89 C7 - 56 8B 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 66 90 80 78 ?? ?? 0F 84 ?? ?? - ?? ?? 66 83 78 ?? ?? 0F 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D B6 ?? ?? ?? ?? 80 7C 05 ?? - ?? 8D 48 ?? 89 C2 0F 84 ?? ?? ?? ?? 85 C9 0F 84 ?? ?? ?? ?? 80 7C 05 ?? ?? 8D 50 ?? - 75 ?? E9 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 66 90 89 C2 85 D2 0F 84 ?? ?? ?? ?? 80 7C - 15 ?? ?? 8D 42 ?? 75 ?? E9 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? - 31 FF C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 EC ?? 56 8B 5C 24 ?? - E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B 07 E9 ?? ?? ?? ?? 8B 7C 24 ?? 89 FB BF ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C7 00 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? - ?? ?? ?? BF - } - $kill_processes_v1_p1 = { - 55 BA ?? ?? ?? ?? B8 ?? ?? ?? ?? BD ?? ?? ?? ?? 57 89 E9 56 53 E8 ?? ?? ?? ?? 81 C3 - ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 66 89 54 24 ?? 8D 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C6 44 24 - ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 ?? - C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? 8B 83 ?? ?? ?? ?? - 89 44 24 ?? 8B 83 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? F3 A5 8D B4 24 ?? ?? ?? ?? C6 44 - } - $kill_processes_v1_p2 = { - 24 ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 89 F7 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 CD C7 44 24 ?? ?? ?? - ?? ?? B9 ?? ?? ?? ?? 89 E8 F3 AB FF B4 24 ?? ?? ?? ?? 89 F7 8D 44 24 ?? 50 56 E8 ?? - ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 B9 ?? ?? ?? ?? F3 AB FF B4 24 ?? ?? - ?? ?? 89 F7 8D 44 24 ?? 50 56 E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 - B9 ?? ?? ?? ?? F3 AB FF B4 24 ?? ?? ?? ?? 89 F7 8D 44 24 ?? 50 56 E8 ?? ?? ?? ?? 89 - 34 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 B9 ?? ?? ?? ?? F3 AB FF B4 24 ?? ?? ?? ?? 89 F7 - 8D 44 24 ?? 50 56 E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 B9 ?? ?? ?? - ?? F3 AB FF B4 24 ?? ?? ?? ?? 89 F7 8D 84 24 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 89 34 - 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 B9 ?? ?? ?? ?? F3 AB FF B4 24 ?? ?? ?? ?? 89 F7 8D - 44 24 ?? 50 56 E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 C4 ?? 89 E8 B9 ?? ?? ?? ?? - F3 AB FF B4 24 ?? ?? ?? ?? 8D 44 24 ?? 50 56 E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? - 81 C4 ?? ?? ?? ?? 5B 5E 5F 5D C3 - } - $shut_down_esxi_v1 = { - 55 B8 ?? ?? ?? ?? BD ?? ?? ?? ?? 57 89 C1 56 53 E8 ?? ?? ?? ?? 81 C3 ?? ?? ?? ?? 81 - EC ?? ?? ?? ?? 8D 7C 24 ?? C7 44 24 ?? 65 73 78 63 C7 44 24 ?? 6C 69 20 76 C7 44 24 - ?? 6D 20 70 72 8D B3 ?? ?? ?? ?? C7 44 24 ?? 6F 63 65 73 F3 A5 8D B4 24 ?? ?? ?? ?? - C7 44 24 ?? 73 20 6B 69 83 EC ?? 89 F7 C7 44 24 ?? 6C 6C 20 2D C7 44 24 ?? 2D 74 79 - 70 C7 44 24 ?? 65 3D 66 6F C7 44 24 ?? 72 63 65 20 C7 44 24 ?? 2D 2D 77 6F 89 C8 B9 - ?? ?? ?? ?? C7 44 24 ?? 72 6C 64 2D C7 44 24 ?? 69 64 3D 22 C7 84 24 ?? ?? ?? ?? 25 - 73 22 00 C7 44 24 ?? 5B 45 53 58 C7 44 24 ?? 69 5D 20 53 C7 44 24 ?? 68 75 74 74 C7 - 44 24 ?? 69 6E 67 20 C7 44 24 ?? 64 6F 77 6E F3 AB C7 44 24 ?? 20 2D 20 25 8D 83 ?? - ?? ?? ?? 66 89 6C 24 ?? C6 44 24 ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 0F 84 ?? ?? ?? ?? BF ?? ?? ?? ?? 89 C5 8D 44 24 ?? 66 89 7C 24 ?? 31 FF - } - $kill_processes_v2_p1 = { - 41 54 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? 45 31 E4 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 55 48 89 - FD 53 48 81 EC ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 00 00 48 89 84 24 ?? ?? ?? ?? B8 ?? ?? - ?? ?? 48 8D 9C 24 ?? ?? ?? ?? 48 8D B4 24 ?? ?? ?? ?? 0F 29 84 24 ?? ?? ?? ?? 66 0F - 6F 05 ?? ?? 00 00 48 89 DF 66 89 44 24 ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 0F 29 44 24 - ?? 66 0F 6F 05 ?? ?? 00 00 66 89 54 24 ?? 48 89 EA 0F 29 44 24 ?? 66 0F 6F 05 ?? ?? - 00 00 66 89 8C 24 ?? ?? 00 00 B9 ?? ?? ?? ?? 0F 29 44 24 ?? 66 0F 6F 05 ?? ?? 00 00 - C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 0F 29 84 24 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 00 00 C6 - 84 24 ?? ?? ?? ?? ?? 0F 29 84 24 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 00 00 C7 44 24 ?? ?? - ?? ?? ?? 0F 29 84 24 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 00 00 C6 44 24 ?? ?? 0F 29 84 24 - ?? ?? ?? ?? C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? C7 84 24 ?? ?? ?? - ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 48 89 44 24 ?? 48 B8 - } - $kill_processes_v2_p2 = { - 48 89 44 24 ?? 4C 89 E0 F3 48 AB 48 89 DF C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 89 E0 48 89 DF B9 ?? - ?? ?? ?? F3 48 AB 48 8D 74 24 ?? 48 89 EA 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? - ?? ?? 4C 89 E0 48 89 DF B9 ?? ?? ?? ?? F3 48 AB 48 8D 74 24 ?? 48 89 EA 48 89 DF E8 - ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 89 E0 48 89 DF B9 ?? ?? ?? ?? F3 48 AB 48 8D - 74 24 ?? 48 89 EA 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 89 E0 48 89 DF - B9 ?? ?? ?? ?? F3 48 AB 48 8D B4 24 ?? ?? ?? ?? 48 89 EA 48 89 DF E8 ?? ?? ?? ?? 48 - 89 DF E8 ?? ?? ?? ?? 4C 89 E0 48 89 DF B9 ?? ?? ?? ?? F3 48 AB 48 8D 74 24 ?? 48 89 - EA 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 89 E0 48 89 DF B9 ?? ?? ?? ?? - F3 48 AB 48 8D 74 24 ?? 48 89 EA 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 - 81 C4 ?? ?? ?? ?? 5B 5D 41 5C C3 - } - $encrypt_files_v2_p1 = { - 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 41 57 66 0F EF C0 49 89 FF 41 56 49 89 D6 41 55 49 89 - F5 BE ?? ?? ?? ?? 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 8D 5C 24 ?? 48 89 4C 24 ?? 48 - 8D AC 24 ?? ?? ?? ?? 48 89 DF 4C 89 04 24 0F 29 44 24 ?? 0F 29 44 24 ?? 0F 29 44 24 - ?? 48 C7 44 24 ?? ?? ?? ?? ?? 0F 29 44 24 ?? 48 89 44 24 ?? E8 ?? ?? ?? ?? 85 C0 75 - ?? 45 31 E4 48 89 EF BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 DF BE ?? ?? ?? ?? E8 ?? ?? - ?? ?? 48 8D 7B ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 44 89 E0 5B 5D - 41 5C 41 5D 41 5E 41 5F C3 0F 1F 80 ?? ?? ?? ?? 48 8D 7B ?? BE ?? ?? ?? ?? E8 ?? ?? - ?? ?? 85 C0 74 ?? BA ?? ?? ?? ?? 48 89 DE 48 89 EF E8 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? - ?? 4C 89 FF E8 ?? ?? ?? ?? 48 89 44 24 ?? 48 85 C0 0F 84 ?? ?? ?? ?? 4C 89 FF E8 ?? - ?? ?? ?? 4C 89 FE 4C 89 EF 48 89 C2 49 89 C4 E8 ?? ?? ?? ?? 8B 54 24 ?? 4B 8D 44 25 - ?? 31 F6 89 10 0F B7 54 24 ?? 66 89 50 ?? 0F B6 54 24 ?? 88 50 ?? BA ?? ?? ?? ?? 43 - C6 44 25 ?? ?? 4C 8B 64 24 ?? 4C 89 E7 E8 ?? ?? ?? ?? 4C 89 E7 4C 89 64 24 ?? 45 31 - E4 E8 ?? ?? ?? ?? 48 83 F8 ?? 7E ?? 4C 89 EE 4C 89 FF E8 ?? ?? ?? ?? 85 C0 74 ?? 48 - 8B 7C 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 66 0F 1F 44 00 ?? 48 8B 7C 24 ?? E8 ?? ?? - ?? ?? 48 8D 35 ?? ?? ?? ?? 4C 89 EF E8 ?? ?? ?? ?? 48 89 44 24 ?? 49 89 C4 48 85 C0 - } - $encrypt_files_v2_p2 = { - 0F 84 ?? ?? ?? ?? 31 F6 BA ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 4C 89 E7 4C 89 64 24 - ?? E8 ?? ?? ?? ?? 48 39 44 24 ?? 48 0F 4E 44 24 ?? 48 8D 7C 24 ?? 48 89 C1 48 C1 F9 - ?? 48 C1 E9 ?? 48 8D 14 08 83 E2 ?? 48 29 CA 48 29 D0 48 89 44 24 ?? E8 ?? ?? ?? ?? - 48 8D BC 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 89 DE 48 89 44 24 ?? 31 C0 BA ?? ?? ?? ?? - F3 48 AB 48 8D 84 24 ?? ?? ?? ?? 48 8B 3C 24 48 89 C1 48 89 44 24 ?? E8 ?? ?? ?? ?? - 41 89 C4 85 C0 0F 84 ?? ?? ?? ?? 48 8B 7C 24 ?? E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 4C 89 - EE E8 ?? ?? ?? ?? 41 89 C4 85 C0 0F 84 ?? ?? ?? ?? 48 8B 44 24 ?? 4C 8D 64 24 ?? 48 - 85 C0 75 ?? E9 ?? ?? ?? ?? 0F 1F 80 ?? ?? ?? ?? 4D 89 F1 4D 89 E8 4C 89 E9 4C 89 E2 - 48 89 EE 48 8D 3D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 F6 BA ?? ?? ?? ?? 4C 89 FF 48 F7 - DE E8 ?? ?? ?? ?? 4C 89 F9 4C 89 F2 BE ?? ?? ?? ?? 4C 89 EF E8 ?? ?? ?? ?? 48 8B 44 - 24 ?? 4C 29 F0 48 89 44 24 ?? 74 ?? 49 39 C6 4C 8B 7C 24 ?? BE ?? ?? ?? ?? 4C 89 EF - 4C 0F 47 F0 66 0F 6F 4C 24 ?? 4C 89 F9 4C 89 F2 0F 29 4C 24 ?? E8 ?? ?? ?? ?? 4C 39 - F0 74 ?? 48 8B 7C 24 ?? 41 BC ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 89 FE 4C - 89 EF E8 ?? ?? ?? ?? E9 - } - $find_files_v2_p1 = { - 41 57 4D 89 C7 41 56 49 89 FE 41 55 49 89 FD 41 54 55 53 89 CB 48 81 EC ?? ?? ?? ?? - 48 89 34 24 89 54 24 ?? 41 8B 55 ?? 49 83 C5 ?? 8D 82 ?? ?? ?? ?? F7 D2 21 D0 25 ?? - ?? ?? ?? 74 ?? 89 C2 C1 EA ?? A9 ?? ?? ?? ?? 0F 44 C2 49 8D 55 ?? 4C 0F 44 EA 89 C6 - 40 00 C6 49 83 DD ?? 31 ED 4D 29 F5 74 ?? 49 8D 6D ?? 43 80 7C 2E ?? ?? 49 0F 45 ED - 48 8D 44 24 ?? 41 89 DC 4C 89 F6 48 89 44 24 ?? 48 89 C2 BF ?? ?? ?? ?? 41 83 E4 ?? - 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 00 83 F8 - ?? 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 45 31 DB 41 BC ?? ?? ?? ?? 48 8B 44 24 ?? F6 C3 - ?? 0F 85 ?? ?? ?? ?? 48 89 44 24 ?? 48 8B 44 24 ?? 4C 89 7C 24 ?? 48 89 44 24 ?? 4D - 85 FF 0F 84 ?? ?? ?? ?? 41 8B 47 ?? 8D 55 ?? 89 54 24 ?? 83 C0 ?? 89 44 24 ?? 89 44 - 24 ?? 41 8B 47 ?? 89 44 24 ?? 45 31 C0 C7 44 24 ?? ?? ?? ?? ?? 83 F9 ?? 0F 84 ?? ?? - ?? ?? 89 D8 83 E0 ?? 89 44 24 ?? 75 ?? 44 88 5C 24 ?? 44 89 E2 48 8D 4C 24 ?? 4C 89 - F7 48 8B 74 24 ?? 48 8B 04 24 44 89 44 24 ?? FF D0 44 8B 44 24 ?? 44 0F B6 5C 24 ?? - 85 C0 89 C2 75 ?? 4D 85 FF 0F 84 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 54 24 ?? EB ?? 0F - 1F 44 00 ?? 4D 8B 3F 4D 85 FF 0F 84 ?? ?? ?? ?? 49 39 47 ?? 75 ?? 49 39 57 ?? 75 ?? - 31 D2 48 81 C4 ?? ?? ?? ?? 89 D0 5B 5D 41 5C 41 5D 41 5E 41 5F C3 66 90 E8 ?? ?? ?? - ?? 85 C0 78 ?? 8B 44 24 ?? 25 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 3D ?? ?? - ?? ?? 0F 84 ?? ?? ?? ?? 31 C9 45 31 DB 45 31 E4 48 8B 44 24 ?? F6 C3 ?? 0F 84 ?? ?? - ?? ?? 4D 85 FF 0F 84 ?? ?? ?? ?? 49 39 47 ?? 75 ?? 48 89 44 24 ?? 48 8B 44 24 ?? 4C - } - $find_files_v2_p2 = { - 89 7C 24 ?? 48 89 44 24 ?? E9 ?? ?? ?? ?? 66 2E 0F 1F 84 00 ?? ?? 00 00 E8 ?? ?? ?? - ?? 49 89 C4 8B 00 83 F8 ?? 0F 85 ?? ?? ?? ?? 48 8B 54 24 ?? 4C 89 F6 BF ?? ?? ?? ?? - E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 45 31 DB 41 BC ?? ?? ?? ?? EB - ?? 0F 1F 00 8B 4C 24 ?? 85 C9 74 ?? 45 84 DB 0F 85 ?? ?? ?? ?? 8B 44 24 ?? 43 C6 04 - 2E ?? 85 C0 0F 84 ?? ?? ?? ?? 44 89 E2 48 8D 4C 24 ?? 48 8B 74 24 ?? 4C 89 F7 48 8B - 04 24 FF D0 89 C2 E9 ?? ?? ?? ?? 90 31 F6 4C 89 F7 31 C0 44 88 5C 24 ?? E8 ?? ?? ?? - ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 7C 24 ?? 44 0F B6 5C 24 ?? 44 8B 00 85 FF 79 ?? 41 - 83 F8 ?? BA ?? ?? ?? ?? 0F 94 C0 84 C0 B8 ?? ?? ?? ?? 44 0F 45 DA 44 0F 45 E0 8B 74 - 24 ?? 85 F6 0F 85 ?? ?? ?? ?? 8B 7C 24 ?? 44 88 5C 24 ?? 44 89 44 24 ?? E8 ?? ?? ?? - ?? 44 0F B6 5C 24 ?? 44 8B 44 24 ?? E9 ?? ?? ?? ?? 0F 1F 00 48 89 44 24 ?? 48 8B 44 - 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 89 44 24 ?? 8D 45 ?? C7 44 24 ?? ?? ?? ?? ?? 89 - 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 48 85 ED 74 ?? 41 80 3C 2E ?? 48 89 E8 74 ?? E9 ?? - ?? ?? ?? 0F 1F 44 00 ?? 41 80 3C 06 ?? 0F 85 ?? ?? ?? ?? 48 83 E8 ?? 75 ?? 31 D2 89 + $encrypt_files_p1 = { + 4C 89 75 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D + 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 C7 45 ?? ?? ?? ?? ?? + 48 C7 45 ?? ?? ?? ?? ?? 48 89 7D ?? 48 C7 45 ?? ?? ?? ?? ?? 48 8D 4D ?? 48 8D 55 ?? + E8 ?? ?? ?? ?? 0F 10 45 ?? 0F 29 45 ?? 48 8B 45 ?? 48 89 45 ?? 48 8D 4D ?? 48 8D 55 + ?? E8 ?? ?? ?? ?? 48 85 DB 74 ?? BA ?? ?? ?? ?? 48 89 D9 E8 ?? ?? ?? ?? 48 85 C0 75 + ?? BA ?? ?? ?? ?? 48 89 D9 E8 } - $find_files_v2_p3 = { - 54 24 ?? E9 ?? ?? ?? ?? 0F 1F 40 ?? 89 D8 B9 ?? ?? ?? ?? 41 BB ?? ?? ?? ?? 83 E0 ?? - 83 F8 ?? 45 19 E4 41 83 E4 ?? 41 83 C4 ?? E9 ?? ?? ?? ?? 0F 1F 44 00 ?? 8B 54 24 ?? - 85 D2 0F 88 ?? ?? ?? ?? 8B 7C 24 ?? E8 ?? ?? ?? ?? 49 89 C7 48 85 C0 0F 84 ?? ?? ?? - ?? B8 ?? ?? ?? ?? 44 89 64 24 ?? 4C 29 E8 48 89 44 24 ?? 48 8D 44 24 ?? 48 89 44 24 - ?? 8B 44 24 ?? 83 E8 ?? 89 44 24 ?? 4C 89 FF E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? - ?? 80 78 ?? ?? 74 ?? 4C 8D 60 ?? 4C 89 E7 E8 ?? ?? ?? ?? 48 3B 44 24 ?? 0F 83 ?? ?? - ?? ?? 41 C6 04 2E ?? 49 8D 7C 2E ?? 4C 89 E6 E8 ?? ?? ?? ?? 4C 8B 44 24 ?? 8B 54 24 - ?? 89 D9 48 8B 34 24 4C 89 F7 E8 ?? ?? ?? ?? 85 C0 74 ?? 4C 89 FF 89 04 24 E8 ?? ?? - ?? ?? 8B 14 24 E9 ?? ?? ?? ?? 66 90 80 78 ?? ?? 74 ?? 66 83 78 ?? ?? 75 ?? EB ?? 90 - 41 80 7C 06 ?? ?? 48 8D 70 ?? 89 C2 0F 84 ?? ?? ?? ?? 48 85 F6 0F 84 ?? ?? ?? ?? 41 - 80 7C 06 ?? ?? 48 8D 50 ?? 75 ?? E9 ?? ?? ?? ?? 0F 1F 40 ?? 48 89 C2 48 85 D2 0F 84 - ?? ?? ?? ?? 41 80 7C 16 ?? ?? 48 8D 42 ?? 75 ?? E9 ?? ?? ?? ?? 0F 1F 00 45 85 E4 0F - 84 ?? ?? ?? ?? 31 C9 45 31 DB 41 BC ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 89 FF 44 8B 64 24 - ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 41 8B 04 24 E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 FF - C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? E9 ?? ?? ?? ?? BA ?? ?? ?? ?? E9 ?? - ?? ?? ?? 48 89 F2 E9 ?? ?? ?? ?? 44 89 04 24 E8 ?? ?? ?? ?? 44 8B 04 24 BA ?? ?? ?? - ?? 44 89 00 E9 ?? ?? ?? ?? 8B 7C 24 ?? E8 ?? ?? ?? ?? 83 CA ?? E9 + $encrypt_files_p2 = { + 86 97 ?? ?? ?? ?? C0 74 3C ?? ?? C1 E8 ?? 28 03 00 48 ?? C0 74 2F ?? ?? FA 03 75 ?? + 48 8D 0D ?? ?? ?? ?? 48 39 C8 0F 84 ?? ?? ?? ?? 0F B7 08 81 F1 ?? ?? ?? ?? 0F B6 40 + ?? 83 F0 ?? 66 09 C8 0F 84 ?? ?? ?? ?? 48 8B 4D ?? 48 8B 55 ?? E8 ?? ?? ?? ?? 48 85 + C0 74 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 83 FA ?? 75 ?? 48 8D 0D ?? ?? ?? + ?? 48 39 C8 0F 84 ?? ?? ?? ?? 81 38 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8B 4D ?? 48 8B + 55 ?? E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 83 FA + ?? 75 ?? 48 8D 0D ?? ?? ?? ?? 48 39 C8 0F 84 ?? ?? ?? ?? 0F B7 08 81 F1 ?? ?? ?? ?? + 0F B6 40 ?? 83 F0 ?? 66 09 C8 0F 84 ?? ?? ?? ?? 48 8B 4D ?? 48 8B 55 ?? E8 ?? ?? ?? + ?? 48 85 C0 74 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 83 FA ?? 75 ?? 48 8D 0D + ?? ?? ?? ?? 48 39 C8 0F 84 ?? ?? ?? ?? 0F B7 08 81 F1 ?? ?? ?? ?? 0F B6 40 ?? 83 F0 + ?? 66 09 C8 0F 84 ?? ?? ?? ?? 48 8B 4D } - $init_key_v2 = { - 48 85 FF 0F 84 ?? ?? ?? ?? 48 85 F6 0F 84 ?? ?? ?? ?? 41 56 41 55 41 54 55 48 89 F5 - 53 48 89 FB 48 81 EC ?? ?? ?? ?? 4C 8D 64 24 ?? 4C 89 E7 E8 ?? ?? ?? ?? 85 C0 75 ?? - 66 0F EF C0 48 8D 35 ?? ?? ?? ?? 48 8D 3D ?? ?? ?? ?? 49 89 E6 0F 29 04 24 0F 29 44 - 24 ?? E8 ?? ?? ?? ?? 49 89 C5 48 85 C0 74 ?? 4C 89 F7 48 89 C1 BA ?? ?? ?? ?? BE ?? - ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 EF E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 4C 89 F6 4C 89 E7 E8 - ?? ?? ?? ?? 85 C0 74 ?? 31 C0 48 81 C4 ?? ?? ?? ?? 5B 5D 41 5C 41 5D 41 5E C3 66 2E - 0F 1F 84 00 ?? ?? 00 00 31 C0 C3 0F 1F 44 00 ?? 48 89 EA 48 89 DE 4C 89 E7 E8 ?? ?? - ?? ?? 85 C0 75 ?? 4C 89 E7 E8 ?? ?? ?? ?? 89 E8 EB + $drop_ransom_note = { + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 D2 74 ?? 48 8B 8D ?? ?? + ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 D2 74 ?? 48 8B 8D + ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 D2 74 ?? 48 + 8B 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 D2 74 + ?? 48 8B 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 85 + D2 74 ?? 48 8B 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? + 48 85 D2 74 ?? 48 8B 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? + ?? ?? 48 85 D2 74 ?? 48 8B 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 84 F6 + 0F 85 ?? ?? ?? ?? 48 8B 55 ?? 48 85 D2 74 ?? 41 B8 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 48 8B 55 ?? 48 85 D2 74 ?? 41 B8 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 48 8B 55 } condition: - uint32(0)==0x464C457F and ((( all of ($find_files_v1_p*)) and ( all of ($kill_processes_v1_p*)) and ($init_key_v1) and ( all of ($encrypt_files_v1_p*)) and ($shut_down_esxi_v1)) or (( all of ($find_files_v2_p*)) and ( all of ($kill_processes_v2_p*)) and ($init_key_v2) and ( all of ($encrypt_files_v2_p*)))) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_*)) and ($drop_ransom_note) } -rule REVERSINGLABS_Win32_Ransomware_Nemty : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_MRAC : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Nemty ransomware." + description = "Yara rule that detects MRAC ransomware." author = "ReversingLabs" - id = "c56ecd32-5903-5bcc-aa69-a070f2c247c4" - date = "2020-07-15" - modified = "2020-07-15" + id = "135c3dc9-bf08-5f00-bade-7054d9f33830" + date = "2022-02-21" + modified = "2022-02-21" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Nemty.yara#L1-L205" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "dc8cfdcdea8ecb2018b1b04bb1b645f6dbdc6c07357719100677c75945edef40" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.MRAC.yara#L1-L69" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "04e8364dc9c726f4bb2d3035e5b7e8dab4cae124b2f047be6f11b865fab557a7" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -40736,184 +40976,62 @@ rule REVERSINGLABS_Win32_Ransomware_Nemty : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Nemty" + tc_detection_name = "MRAC" tc_detection_factor = 5 importance = 25 strings: - $remote_connection_p1 = { - 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 33 DB 68 ?? ?? ?? ?? 8D 75 - ?? 89 5D ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? 83 78 ?? ?? 59 59 72 ?? 8B 00 - 53 53 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 33 FF 8D 75 ?? E8 ?? ?? ?? ?? 6A - ?? 8D 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 75 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? - ?? ?? ?? 83 78 ?? ?? 59 59 72 ?? 8B 00 53 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? - ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 32 DB EB ?? B3 ?? 6A ?? 33 FF 8D 75 ?? E8 ?? ?? ?? ?? - 6A ?? 8D 75 ?? E8 ?? ?? ?? ?? 84 DB 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 75 ?? E8 ?? - ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? 83 78 ?? ?? 59 59 72 ?? 8B 00 8B 1D ?? ?? ?? ?? - 50 FF D3 6A ?? 33 FF 8D 75 ?? 89 45 ?? E8 ?? ?? ?? ?? 6A ?? 8D 75 ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 75 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? 83 78 ?? ?? 59 59 - 72 ?? 8B 00 50 FF D3 33 DB 43 53 33 FF 8D 75 ?? 89 45 ?? E8 ?? ?? ?? ?? 53 8D 75 ?? - E8 ?? ?? ?? ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 59 59 FF 75 ?? FF - } - $remote_connection_p2 = { - D6 FF 75 ?? FF D6 68 ?? ?? ?? ?? 8D 75 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? - 83 78 ?? ?? 59 59 72 ?? 8B 00 50 FF 15 ?? ?? ?? ?? 53 33 FF 8D 75 ?? E8 ?? ?? ?? ?? - 53 8D 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 75 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? - ?? ?? ?? 83 78 ?? ?? 59 59 72 ?? 8B 00 33 C9 51 51 51 50 68 ?? ?? ?? ?? 51 FF 15 ?? - ?? ?? ?? 53 33 FF 8D 75 ?? E8 ?? ?? ?? ?? 53 8D 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 8B 4D ?? 6A ?? 5A 8B C1 39 55 ?? 73 ?? 8D 45 ?? 03 45 ?? 39 55 ?? - 73 ?? 8D 4D ?? EB ?? 80 39 ?? 75 ?? C6 01 ?? 41 3B C8 75 ?? 8B 45 ?? 39 55 ?? 73 ?? - 8D 45 ?? 03 45 ?? 8B 4D ?? 39 55 ?? 73 ?? 8D 4D ?? EB ?? 80 39 ?? 75 ?? C6 01 ?? 41 - 3B C8 75 ?? 8B 45 ?? 39 55 ?? 73 ?? 8D 45 ?? 03 45 ?? 8B 4D ?? 39 55 ?? 73 ?? 8D 4D - ?? EB ?? 80 39 ?? 75 ?? C6 01 ?? 41 3B C8 75 ?? 83 EC ?? 8D 45 ?? 8B F4 50 E8 ?? ?? - ?? ?? 83 EC ?? 8B F4 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 33 - FF 8D 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 - } - $enum_resources_p1 = { - 55 8B EC 83 E4 ?? 83 EC ?? A1 ?? ?? ?? ?? 33 C4 89 44 24 ?? 53 56 57 FF 15 ?? ?? ?? - ?? 83 64 24 ?? ?? 89 44 24 ?? BB ?? ?? ?? ?? 8B 54 24 ?? 8B 4C 24 ?? D3 EA 33 C0 40 - 23 D0 0F 84 ?? ?? ?? ?? 83 64 24 ?? ?? 6A ?? 80 C1 ?? 5F 88 4C 24 ?? FF 74 24 ?? 8D - 74 24 ?? 89 7C 24 ?? C6 44 24 ?? ?? E8 ?? ?? ?? ?? 83 64 24 ?? ?? 8B 74 24 ?? 53 89 - 7C 24 ?? C6 44 24 ?? ?? E8 ?? ?? ?? ?? 59 03 C6 8D 4C 24 ?? E8 ?? ?? ?? ?? 6A ?? 8D - 44 24 ?? 50 83 C8 ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 8B F8 53 8B C6 - E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 8B 44 24 ?? 73 ?? 8B C6 50 FF 15 ?? ?? ?? ?? 6A ?? 33 - FF 8D 74 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? 59 - 8B F8 53 8D 44 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? - 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? 59 8B F8 53 - 8D 44 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 - } - $enum_resources_p2 = { - 8D 44 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 33 FF 8D - 74 24 ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? 59 8B F8 53 8D 44 24 - ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 - ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 33 FF 8D 74 24 ?? - E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 8B 44 24 ?? 73 ?? 8D 44 24 ?? 6A ?? 8D 4C 24 ?? 51 8D - 4C 24 ?? 51 50 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 0F AC C8 ?? 89 44 24 ?? 8D - 44 24 ?? BE ?? ?? ?? ?? C1 E9 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 0F AC C8 ?? - 89 44 24 ?? 8D 44 24 ?? BE ?? ?? ?? ?? C1 E9 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 2B 44 24 - ?? 8B 4C 24 ?? 1B 4C 24 ?? BE ?? ?? ?? ?? 0F AC C8 ?? 89 44 24 ?? 8D 44 24 ?? C1 E9 - ?? E8 ?? ?? ?? ?? 6A ?? 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? FF 44 24 ?? 83 7C 24 ?? ?? - 0F 8C ?? ?? ?? ?? 8B 4C 24 ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $find_files_1_p1 = { - 6A ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 - 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? - E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? - 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D - 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? - ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 - } - $find_files_1_p2 = { - C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 - ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? - ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F - 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 75 ?? 68 ?? ?? ?? - ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 75 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? - ?? 59 84 C0 75 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 75 ?? 68 ?? ?? - ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 75 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? - ?? ?? 59 84 C0 75 ?? 83 EC ?? 8D 44 24 ?? 8B F4 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 6A ?? 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? 6A ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 8D 84 - 24 ?? ?? ?? ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? - FF 15 - } - $find_files_2_p1 = { - 8D 44 24 ?? 8D 8C 24 ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 - ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F - 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? - ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 - 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? BF ?? ?? ?? ?? 57 8D - 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 57 8D 84 24 ?? ?? ?? ?? 50 FF D6 - 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 - 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 - } - $find_files_2_p2 = { - 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 - 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? - ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? E8 ?? - ?? ?? ?? 83 4C 24 ?? ?? 83 EC ?? 8B C4 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 4C - 24 ?? 8B C4 51 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 84 24 ?? ?? - ?? ?? 50 8D 44 24 ?? E8 ?? ?? ?? ?? 83 4C 24 ?? ?? 83 EC ?? 8B C4 68 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 EC ?? 8D 8C 24 ?? ?? ?? ?? 8B C4 51 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? - 83 C4 ?? 85 C0 75 ?? 32 DB EB ?? B3 ?? F6 44 24 ?? ?? 74 ?? 83 64 24 ?? ?? 6A ?? 33 - FF 8D 74 24 ?? E8 ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? 83 64 24 ?? ?? 6A ?? 33 FF 8D 74 - } - $find_files_2_p3 = { - 24 ?? E8 ?? ?? ?? ?? 84 DB 0F 85 ?? ?? ?? ?? F6 84 24 ?? ?? ?? ?? ?? 8D 84 24 ?? ?? - ?? ?? 50 0F 84 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B F0 8B - 46 ?? 59 83 C9 ?? 2B C8 83 F9 ?? 0F 86 ?? ?? ?? ?? 8D 58 ?? 6A ?? 8B C6 E8 ?? ?? ?? - ?? 84 C0 74 ?? 83 7E ?? ?? 8B 4E ?? 72 ?? 8B 06 EB ?? 8B C6 6A ?? 5A 66 89 14 48 83 - 7E ?? ?? 89 5E ?? 72 ?? 8B 06 EB ?? 8B C6 33 C9 66 89 0C 58 8B DE 8D 74 24 ?? E8 ?? - ?? ?? ?? 8B DE 8D 44 24 ?? E8 ?? ?? ?? ?? 6A ?? 33 FF E8 ?? ?? ?? ?? 6A ?? 8D 74 24 - ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 44 24 ?? 8B F4 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 44 - 24 ?? 8B F4 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8D 44 24 ?? E8 - ?? ?? ?? ?? 8D 44 24 ?? 50 8D 44 24 ?? E8 ?? ?? ?? ?? 59 6A ?? 33 FF 8D 74 24 ?? E8 - ?? ?? ?? ?? 6A ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 40 33 C9 8D 74 24 ?? E8 ?? ?? ?? ?? 8D - 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 44 24 ?? E8 ?? ?? - ?? ?? 59 6A ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 40 33 C9 - 8D 74 24 ?? E8 + $encrypt_files = { + B8 ?? ?? ?? ?? 66 8B 11 66 3B 10 75 ?? 66 85 D2 74 ?? 66 8B 51 ?? 66 3B 50 ?? 75 ?? + 83 C1 ?? 83 C0 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 8B 75 ?? 85 C0 75 ?? B1 + ?? EB ?? 32 C9 8B 45 ?? 88 4D ?? 83 F8 ?? 72 ?? 8D 0C 45 ?? ?? ?? ?? 8B C6 81 F9 ?? + ?? ?? ?? 72 ?? 8B 76 ?? 83 C1 ?? 2B C6 83 C0 ?? 83 F8 ?? 77 ?? 51 56 E8 ?? ?? ?? ?? + 8A 4D ?? 83 C4 ?? 8A C1 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? + ?? ?? ?? 8B E5 5D C2 ?? ?? E8 ?? ?? ?? ?? E8 } - $encrypt_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 8B D9 33 F6 C7 43 ?? - ?? ?? ?? ?? 89 73 ?? C6 03 ?? A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 57 2B C1 6A ?? 99 5F - F7 FF 89 9D ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? 85 C0 74 ?? 89 B5 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 83 EC ?? 03 C1 8B F4 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A - ?? 50 83 C8 ?? 8B F3 E8 ?? ?? ?? ?? 6A ?? 33 FF 8D 75 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? - ?? 8B 0D ?? ?? ?? ?? 2B C1 6A ?? 99 5E F7 FE FF 85 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? - 39 85 ?? ?? ?? ?? 72 ?? 8B 53 ?? 6A ?? 5F C6 85 ?? ?? ?? ?? ?? 3B D7 72 ?? 8B 0B EB - ?? 8B CB 8B 43 ?? 03 C1 3B D7 72 ?? 8B 0B EB ?? 8B CB 50 51 8D 85 ?? ?? ?? ?? 50 8D - 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 39 7B ?? 72 ?? 8B 03 EB ?? 8B C3 8B 5B ?? 8B - B5 ?? ?? ?? ?? 03 D8 53 FF B5 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B - 4E ?? C6 85 ?? ?? ?? ?? ?? 3B CF 72 ?? 8B 16 EB ?? 8B D6 8B 46 ?? 03 C2 3B CF 72 ?? - 8B 0E EB ?? 8B CE 50 51 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 39 7E ?? 72 ?? 8B 0E EB ?? 8B CE 8B 46 ?? 03 C1 50 FF B5 ?? ?? ?? ?? 8D 9D ?? ?? - ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B 46 ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B 4E + $import_key = { + 8D 45 ?? 50 6A ?? 6A ?? 6A ?? FF 75 ?? 56 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 + ?? 89 45 ?? 8D 4D ?? 51 50 6A ?? 6A ?? FF 75 ?? 56 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? FF 75 ?? FF 75 ?? FF 75 ?? FF + 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF + 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 6A ?? FF + 75 ?? FF D6 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A ?? FF 75 ?? FF D6 85 C0 0F + 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 6A ?? 8D 45 ?? 50 6A ?? FF 75 ?? FF D6 85 C0 0F 84 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 + ?? ?? ?? ?? 8B C8 F6 C1 ?? 75 ?? B8 ?? ?? ?? ?? EB ?? 8B C1 C1 E8 ?? 40 C1 E0 ?? 2B + C1 68 ?? ?? ?? ?? 89 45 ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 0F 84 ?? ?? ?? ?? 6A + ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 8B 45 ?? 3D ?? ?? ?? ?? 0F 92 C3 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 57 6A ?? 0F + B6 C3 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 75 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D + 45 ?? 50 FF 75 ?? 57 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? EB ?? 8B 75 ?? 84 + DB 74 } - $encrypt_files_p2 = { - 89 85 ?? ?? ?? ?? 3B CF 72 ?? 8B 16 EB ?? 8B D6 8B 46 ?? 03 C2 3B CF 72 ?? 8B 0E EB - ?? 8B CE 3B C8 74 ?? 8B B5 ?? ?? ?? ?? 2B F1 8A 11 88 14 0E 41 3B C8 75 ?? 8D 45 ?? - 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 75 ?? 8B F8 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 50 8D 45 ?? E8 ?? ?? ?? ?? 8B F0 8B 46 ?? 8B 56 ?? 59 59 8B 4F ?? 2B C2 3B C8 76 ?? - 8B 47 ?? 2B C1 3B C2 72 ?? 56 8B F7 E8 ?? ?? ?? ?? EB ?? 6A ?? 57 83 C8 ?? E8 ?? ?? - ?? ?? 8B D8 8D 75 ?? E8 ?? ?? ?? ?? 8B C6 68 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 78 ?? ?? 59 59 72 ?? 8B 00 33 DB 53 68 ?? ?? ?? ?? 6A ?? 53 53 68 ?? ?? - ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 33 FF 8D B5 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 6A ?? 8D 75 ?? E8 ?? ?? ?? ?? 6A ?? 8D 75 ?? E8 ?? ?? ?? ?? 6A ?? 8D 75 ?? E8 - ?? ?? ?? ?? 6A ?? 8D 75 ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 3B F3 74 ?? 53 53 53 56 - FF 15 ?? ?? ?? ?? 53 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 56 FF - 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 59 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 + $find_files = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 + 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 4D ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 74 ?? 32 C0 E9 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 68 ?? ?? + ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 89 06 FF + D7 85 C0 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 90 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D3 + F6 05 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 8B + 4D ?? 6A ?? 68 ?? ?? ?? ?? E8 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_1_p*)) and ( all of ($find_files_2_p*)) and ( all of ($enum_resources_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ($find_files) and ($import_key) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Ferrlock : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Ghostencryptor : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Ferrlock ransomware." + description = "Yara rule that detects GhosTEncryptor ransomware." author = "ReversingLabs" - id = "745ce529-46d0-56ed-a8fa-b41b26b068f4" - date = "2020-07-15" - modified = "2020-07-15" + id = "9f035e39-e0fe-54f3-8206-08fbbd9206b4" + date = "2021-08-12" + modified = "2021-08-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Ferrlock.yara#L1-L131" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "b94bc77489dbb74573813631009e605bc848e17995a0a512d08b194ee3020b75" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.GhosTEncryptor.yara#L1-L69" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "85c1f6e5acf746388b0a9ddeb1f0ad1d2219fff7358c9a981849863155c13e3c" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -40921,117 +41039,60 @@ rule REVERSINGLABS_Win32_Ransomware_Ferrlock : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Ferrlock" + tc_detection_name = "GhosTEncryptor" tc_detection_factor = 5 importance = 25 strings: - $search_files_p1 = { - 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 - F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? ?? - ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? FF - 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 5D ?? 8B - CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 EB ?? 8B - 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 FF - 57 57 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 - C5 89 45 ?? 8B 4D ?? 53 8B 5D ?? 57 8B 7D ?? 89 9D ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 - ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8A 11 80 FA - ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 53 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 DB - } - $search_files_p2 = { - 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8A C3 80 FA ?? 75 ?? B0 ?? 0F B6 C0 2B CF 41 F7 D8 56 - 1B C0 23 C1 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? - 83 C4 ?? 8D 85 ?? ?? ?? ?? 53 53 53 50 53 57 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? - ?? 83 FE ?? 75 ?? 50 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 83 FE ?? 74 ?? 56 FF 15 - ?? ?? ?? ?? 8B C3 5E 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 - C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? - 80 F9 ?? 75 ?? 38 9D ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 - 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 - } - $enum_rsrc = { - 6A ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 4D ?? 8B 45 ?? 8D 4D ?? 83 4D ?? ?? 51 50 6A - ?? 6A ?? 6A ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 - ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? EB ?? 33 DB 39 5D ?? 7E ?? - 8D 7E ?? F7 47 ?? ?? ?? ?? ?? 74 ?? 8D 47 ?? 89 45 ?? 8B 45 ?? 8B 00 8B 48 ?? 85 C9 - 74 ?? 8B 01 8D 55 ?? 52 FF 50 ?? EB ?? FF 37 8D 4D ?? E8 ?? ?? ?? ?? 83 65 ?? ?? 8D - 45 ?? 50 8B 45 ?? 8B 48 ?? E8 ?? ?? ?? ?? 83 4D ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 43 83 - C7 ?? 3B 5D ?? 7C ?? 83 4D ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 56 8D 45 ?? 50 FF - 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 - ?? ?? ?? ?? E8 ?? ?? ?? ?? C2 ?? ?? E8 ?? ?? ?? ?? CC 55 8B EC 6A ?? 68 ?? ?? ?? ?? - 64 A1 ?? ?? ?? ?? 50 56 A1 ?? ?? ?? ?? 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 83 - 65 ?? ?? 8B 4E ?? 85 C9 74 ?? 8B 11 3B CE 0F 95 C0 0F B6 C0 50 FF 52 ?? 83 66 ?? ?? - 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 8B E5 5D C3 + $enum_folders = { + 17 8D ?? ?? ?? ?? 0A 06 16 72 ?? ?? ?? ?? A2 03 28 ?? ?? ?? ?? 0B 16 0C 38 ?? ?? ?? ?? + 07 08 9A 0D 02 09 28 ?? ?? ?? ?? 2C ?? 09 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 09 72 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 09 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 09 72 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 2D ?? 09 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 09 72 ?? ?? ?? ?? 6F ?? ?? + ?? ?? 2D ?? 09 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 02 02 7B ?? ?? ?? ?? 09 72 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 09 28 ?? ?? ?? ?? 26 08 17 58 0C 08 07 8E 69 3F ?? + ?? ?? ?? 02 7B ?? ?? ?? ?? 06 17 6F ?? ?? ?? ?? 2A } - $create_test_file_p1 = { - 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 33 DB 8D 55 - ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 5D ?? E8 ?? ?? ?? ?? 59 8D 45 ?? C6 45 ?? ?? - 50 8D 4D ?? 89 5D ?? 89 5D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 - ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 83 CB ?? 8B 3D ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 65 ?? ?? - 8D 4D ?? 83 65 ?? ?? 56 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? FF 75 ?? 8B 45 ?? 2B 45 - ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 8B 55 ?? 8D 4D ?? 0F 43 45 ?? - 83 7D ?? ?? 0F 43 4D ?? 3B 55 ?? 75 ?? 52 50 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 85 ?? ?? - ?? ?? ?? 85 C0 74 ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? - ?? 8D 4D ?? 0F 85 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C6 ?? 3B F7 0F 85 ?? ?? - ?? ?? 83 7D ?? ?? 8D 45 ?? 8B 35 ?? ?? ?? ?? BF ?? ?? ?? ?? 0F 43 45 ?? 33 C9 51 57 + $encrypt_folder_p1 = { + 1F ?? 8D ?? ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? + ?? A2 25 19 72 ?? ?? ?? ?? A2 25 1A 72 ?? ?? ?? ?? A2 25 1B 72 ?? ?? ?? ?? A2 25 1C 72 + ?? ?? ?? ?? A2 25 1D 72 ?? ?? ?? ?? A2 25 1E 72 ?? ?? ?? ?? A2 25 1F ?? 72 ?? ?? ?? ?? + A2 25 1F ?? 72 ?? ?? ?? ?? A2 25 1F ?? 72 } - $create_test_file_p2 = { - 6A ?? 51 51 68 ?? ?? ?? ?? 50 FF D6 3B C3 0F 84 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 - 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? - 33 C9 51 57 6A ?? 51 51 68 ?? ?? ?? ?? 50 FF D6 8B F8 3B FB 0F 84 ?? ?? ?? ?? 6A ?? - 57 FF 15 ?? ?? ?? ?? 8B F0 85 F6 75 ?? 57 FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? - ?? ?? E9 ?? ?? ?? ?? 6A ?? 58 3B F0 0F 42 F0 03 F0 56 E8 ?? ?? ?? ?? 59 6A ?? 89 85 - ?? ?? ?? ?? 8D 45 ?? 50 56 8B B5 ?? ?? ?? ?? 56 57 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 75 - ?? 57 FF 15 ?? ?? ?? ?? EB ?? 83 7D ?? ?? 8D 45 ?? FF 75 ?? 0F 43 45 ?? 8D 55 ?? 50 - 8B CE E8 ?? ?? ?? ?? 59 59 33 DB 53 53 53 57 FF 15 ?? ?? ?? ?? 53 8D 45 ?? 50 FF 75 - ?? 56 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 8D 45 ?? 0F 43 - 4D ?? 83 7D ?? ?? 51 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 8D 4D ?? - E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C3 E8 ?? - ?? ?? ?? C3 + $encrypt_folder_p2 = { + A2 0A 03 28 ?? ?? ?? ?? 0B 03 28 ?? ?? ?? ?? 0C 16 0D 2B ?? 07 09 9A 28 ?? ?? ?? ?? 13 + ?? 06 11 ?? 28 ?? ?? ?? ?? 2C ?? 02 07 09 9A 04 28 ?? ?? ?? ?? 09 17 58 0D 09 07 8E 69 + 32 ?? 16 13 ?? 2B ?? 02 08 11 ?? 9A 04 28 ?? ?? ?? ?? 11 ?? 17 58 13 ?? 11 ?? 08 8E 69 + 32 ?? 2A } - $encrypt_files_p1 = { - 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 33 F6 8D 4D ?? 89 B5 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 75 ?? 8D 4D ?? 68 ?? ?? ?? ?? 89 75 ?? 89 75 ?? E8 ?? - ?? ?? ?? 68 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 7D ?? 8B D8 8B 45 - ?? 0F 43 7D ?? 59 3B D8 77 ?? 85 DB 74 ?? 2B C3 40 03 C7 89 85 ?? ?? ?? ?? 2B C7 50 - 6A ?? 57 EB ?? 53 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 85 ?? ?? - ?? ?? 46 2B C6 50 6A ?? 56 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? EB ?? 2B F7 EB - ?? 83 CE ?? 83 FE ?? 74 ?? 83 7D ?? ?? 8D 45 ?? FF 75 ?? 0F 43 45 ?? 50 51 56 8D 4D - ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 33 F6 8D 85 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 + $deep_search_p1 = { + 17 8D ?? ?? ?? ?? 0A 06 16 72 ?? ?? ?? ?? A2 7E ?? ?? ?? ?? 0B 02 0C 16 0D 38 ?? ?? ?? + ?? 08 09 9A 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 72 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? + ?? ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 11 ?? 72 } - $encrypt_files_p2 = { - 50 E8 ?? ?? ?? ?? 6A ?? 5F 89 7D ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 51 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? C6 45 ?? ?? 8B C8 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 51 0F 43 85 - ?? ?? ?? ?? 51 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 39 B5 ?? ?? ?? ?? 74 ?? 83 7D ?? ?? 8D - 55 ?? FF 75 ?? 0F 43 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 56 8B 40 ?? 03 C8 8B 51 - ?? 83 CA ?? 8B C2 0B C7 39 71 ?? 0F 44 D0 52 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 59 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $deep_search_p2 = { + 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 07 11 ?? 72 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 0B 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 09 17 58 0D 09 08 8E + 69 3F ?? ?? ?? ?? 07 06 17 6F ?? ?? ?? ?? 2A } condition: - uint16(0)==0x5A4D and ($enum_rsrc) and ( all of ($search_files_p*)) and ( all of ($create_test_file_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($enum_folders) and ( all of ($deep_search_p*)) and ( all of ($encrypt_folder_p*)) } -rule REVERSINGLABS_Win64_Ransomware_Vovalex : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Good : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Vovalex ransomware." + description = "Yara rule that detects Good ransomware." author = "ReversingLabs" - id = "dd4d7969-1afc-5e5d-9324-89f432523173" - date = "2021-03-12" - modified = "2021-03-12" + id = "e0f97200-7fe9-5811-b6cd-708ecc3a2fbc" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Vovalex.yara#L1-L81" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0c0f065224988bcba45b5aba2dceb080479b0bab235d544daabc3cae72e48318" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Good.yara#L1-L82" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6737853a77a6008f9fd2141bb6b13d595f1cb7e832be944596f709e1fcdf8003" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -41039,213 +41100,77 @@ rule REVERSINGLABS_Win64_Ransomware_Vovalex : TC_DETECTION MALICIOUS MALWARE FIL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Vovalex" + tc_detection_name = "Good" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files = { - 48 8D 95 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B BD ?? ?? ?? ?? - 48 89 BD ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 - 89 85 ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 - 8B 9D ?? ?? ?? ?? 48 8B 53 ?? 48 8B 03 48 89 85 ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 - 8D 8D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 83 F8 ?? 75 ?? 48 8B B5 ?? - ?? ?? ?? 48 8B 56 ?? 48 8B 06 48 89 85 ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 8D 95 ?? - ?? ?? ?? 8B 8D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 8B 9D ?? ?? ?? - ?? 48 8B 53 ?? 48 8B 03 48 89 85 ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? - ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 48 83 - EC ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 9D ?? ?? ?? ?? 48 89 9D ?? ?? - ?? ?? 48 8D B5 ?? ?? ?? ?? 56 48 89 85 ?? ?? ?? ?? 48 89 9D ?? ?? ?? ?? 48 8D 15 ?? - ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? - 48 89 8D ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 9D ?? ?? ?? ?? - 48 89 9D ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 0D - ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 85 ?? ?? ?? ?? 48 89 95 ?? - ?? ?? ?? 4C 8D 8D ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 1D ?? - ?? ?? ?? 48 89 9D ?? ?? ?? ?? 4C 8D 85 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 89 8D ?? - ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? - ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 + $find_files = { + FF D7 53 85 C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C3 8D + 85 ?? ?? ?? ?? 50 FF D7 53 85 C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E + 5B 8B E5 5D C3 8D 85 ?? ?? ?? ?? 50 FF D7 53 85 C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C3 8D 85 ?? ?? ?? ?? 50 FF D7 53 85 C0 75 ?? 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C3 8D 85 ?? ?? ?? ?? 50 FF D7 53 85 + C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C3 8B 3D ?? ?? ?? + ?? 33 C0 66 89 45 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? + ?? ?? ?? ?? FF D7 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 8B D8 83 FB ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 5F 5E 5B 8B E5 5D C3 } - $find_files_p1 = { - 48 89 C6 48 8D 0D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 C1 48 83 - EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 06 48 89 56 ?? 48 8D 0D ?? ?? ?? ?? 48 83 EC - ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 C1 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 - 46 ?? 48 89 56 ?? 48 8D 0D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 - C1 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 46 ?? 48 89 56 ?? 48 8D 0D ?? ?? ?? - ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 C1 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 - C4 ?? 48 89 46 ?? 48 89 56 ?? 48 8D 0D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 - C4 ?? 48 89 C1 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 46 ?? 48 89 56 ?? 48 8D - 0D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 89 C1 48 83 EC ?? E8 ?? ?? - ?? ?? 48 83 C4 ?? 48 89 46 ?? 48 89 56 ?? 48 89 B5 ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 89 95 ?? ?? - ?? ?? BA ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 + $remote_connection = { + 55 8B EC 53 8B 5D ?? 57 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 7D ?? 83 C4 ?? 8B 0F 8B + C1 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? EB ?? 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4F ?? 83 C4 ?? 8B C1 83 E8 ?? 74 ?? 83 + E8 ?? 74 ?? 83 E8 ?? 74 ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? + ?? ?? EB ?? 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 47 ?? 83 C4 ?? 83 F8 ?? 77 ?? FF 24 85 ?? ?? ?? ?? 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? FF 77 ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 47 ?? 83 C4 ?? A8 ?? 74 ?? + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 47 ?? 83 C4 ?? A8 ?? 74 ?? 68 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? 83 7F ?? ?? 75 ?? 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 FF + 77 ?? FF 15 ?? ?? ?? ?? 8D 04 45 ?? ?? ?? ?? 50 FF 77 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? + 8D 45 ?? 50 6A ?? 56 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 5E FF 77 ?? 53 68 + ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 77 ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 77 ?? 53 68 + ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 77 ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5B + 5D C3 } - $find_files_p2 = { - 89 C3 48 8B 95 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 03 48 89 53 ?? 48 8D 15 ?? ?? - ?? ?? BF ?? ?? ?? ?? 48 89 7B ?? 48 89 53 ?? 48 8D 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 - 89 43 ?? 48 89 4B ?? 48 89 9D ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 45 31 C0 - 4C 89 85 ?? ?? ?? ?? 4C 8D A5 ?? ?? ?? ?? 49 C7 04 24 ?? ?? ?? ?? 49 8B 14 24 48 89 - 95 ?? ?? ?? ?? 4C 89 85 ?? ?? ?? ?? 4C 8D AD ?? ?? ?? ?? 49 B9 ?? ?? ?? ?? ?? ?? ?? - ?? 4D 89 4D ?? 49 8B 4D ?? 48 89 8D ?? ?? ?? ?? 4C 89 85 ?? ?? ?? ?? 4C 8D B5 ?? ?? - ?? ?? 4D 89 06 49 8B 16 48 8D 8D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? - 45 31 C0 41 3B C0 7E ?? 41 BF ?? ?? ?? ?? 4C 89 85 ?? ?? ?? ?? 4C 8D 8D ?? ?? ?? ?? - 4D 69 D7 ?? ?? ?? ?? 4D 89 11 4C 89 D2 48 8D 8D ?? ?? ?? ?? 48 83 EC ?? E8 ?? ?? ?? - ?? 48 83 C4 ?? 45 31 C0 41 3B C0 79 ?? 4C 89 85 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 - C7 01 ?? ?? ?? ?? 48 8B 01 48 89 85 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 8D 8D ?? ?? - ?? ?? 48 83 EC ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 85 C0 7E ?? 48 8B 9D ?? ?? ?? ?? 48 B8 - ?? ?? ?? ?? ?? ?? ?? ?? 48 F7 EB + $encrypt_files = { + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B C8 8B F2 83 C4 ?? 2B CE 8D 71 ?? + 66 90 0F B7 0A 8D 52 ?? 66 89 4C 32 ?? 66 85 C9 75 ?? 50 FF 35 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 8B 35 ?? ?? ?? ?? 47 89 7D ?? E9 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? FF 75 ?? 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 35 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 + 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? EB ?? + 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 53 + FF D6 8B 3D ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? + 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C3 53 + FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 + 5D C3 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($remote_connection) } -rule REVERSINGLABS_Win32_Ransomware_Dragon : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects Dragon ransomware." - author = "ReversingLabs" - id = "dbeab955-f1fe-57eb-a9a4-c8c885ab7fad" - date = "2020-10-30" - modified = "2020-10-30" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Dragon.yara#L1-L149" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "7298c5681deaf04abb6a656cefc09b5ee4096ff7a5028caab1d7b107e97be90a" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Dragon" - tc_detection_factor = 5 - importance = 25 - - strings: - $remote_connection_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 56 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 85 C0 0F 85 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 88 45 ?? 83 EC ?? 89 45 ?? 8B - CC 89 A5 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC E8 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? BA ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? 56 8B D0 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 - 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? - ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? - ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? - ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 - } - $remote_connection_p2 = { - 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? - 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? - ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F - 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 8D 4D ?? 8D 55 ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? 0F 43 4D ?? 51 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 83 FA - ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? - 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B - 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? - 64 89 0D ?? ?? ?? ?? 59 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $find_files_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 83 EC ?? 89 8D ?? - ?? ?? ?? 8B D4 8D 71 ?? C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C6 02 ?? 8A 01 41 - 84 C0 75 ?? 2B CE 8B B5 ?? ?? ?? ?? 51 56 8B CA E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 8D - 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 8B 1D - } - $find_files_2 = { - 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? - 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - 8A 11 3A 10 75 ?? 84 D2 74 ?? 8A 51 ?? 3A 50 ?? 75 ?? 83 C1 ?? 83 C0 ?? 84 D2 75 ?? - 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? - ?? 56 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 51 8B D4 8D 8D ?? ?? ?? ?? - 8D 71 ?? C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C6 02 ?? 8A 01 41 84 C0 75 ?? 2B - CE 8D 85 ?? ?? ?? ?? 51 50 8B CA E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 74 ?? - 83 EC ?? 8B CC 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 57 FF D3 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B 4D ?? 5F - 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $skip_hk_china_taiwan_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? - 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 88 45 ?? 89 45 ?? 8D 4D ?? 6A ?? - 68 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 88 45 ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D - 4D ?? 83 7D ?? ?? 8D 55 ?? 0F 43 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? - 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - C6 45 ?? ?? 8D 4D ?? 6A ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 - ?? 0F 85 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? - ?? ?? 6A ?? 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? - 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 - C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 - ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 - ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 8D ?? - ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 - } - $skip_hk_china_taiwan_p2 = { - 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 - 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? - ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 - C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? - 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 55 ?? - 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 - C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 - ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 - ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 8D ?? - ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? - 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 - 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 - E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? - ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 - 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 32 C0 E9 ?? ?? ?? ?? 6A ?? E8 - ?? ?? ?? ?? E8 - } - $crypt_files = { - 8B FF 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 4D ?? 8B 45 ?? 89 45 ?? 89 - 4D ?? 56 8B 75 ?? 85 C9 75 ?? 33 C0 E9 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? ?? ?? 83 20 - ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C8 ?? E9 ?? ?? ?? ?? 53 8B C6 - 8B D6 C1 FA ?? 83 E0 ?? 57 6B F8 ?? 89 55 ?? 8B 14 95 ?? ?? ?? ?? 89 7D ?? 8A 5C 3A - ?? 80 FB ?? 74 ?? 80 FB ?? 75 ?? 8B C1 F7 D0 A8 ?? 75 ?? E8 ?? ?? ?? ?? 83 20 ?? E8 - ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? F6 44 3A ?? ?? 74 ?? 6A - ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 8D 7D ?? AB 56 AB AB E8 ?? ?? ?? ?? - 59 84 C0 74 ?? 84 DB 74 ?? FE CB 80 FB ?? 8B 5D ?? 0F 87 ?? ?? ?? ?? FF 75 ?? 8D 45 - ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 E9 ?? ?? ?? ?? FF 75 ?? 8B 5D ?? 8D 45 ?? 53 - 56 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8B 4D ?? 8B 55 ?? 8B 04 8D ?? ?? ?? ?? 80 7C 10 - ?? ?? 7D ?? 0F BE C3 8B 5D ?? 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 83 E8 ?? 75 ?? FF 75 ?? - 8D 45 ?? 53 56 50 E8 ?? ?? ?? ?? EB ?? FF 75 ?? 8D 45 ?? 53 56 50 E8 ?? ?? ?? ?? EB - ?? FF 75 ?? 8D 45 ?? 53 56 50 E8 ?? ?? ?? ?? EB ?? 8B 4C 10 ?? 8D 7D ?? 8B 5D ?? 33 - C0 AB 6A ?? AB AB 8D 45 ?? 50 FF 75 ?? 53 51 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? - ?? ?? ?? 89 45 ?? 8D 75 ?? 8D 7D ?? A5 A5 A5 8B 4D ?? 8B 55 ?? 8B 45 ?? 85 C0 75 ?? - 8B 45 ?? 85 C0 74 ?? 6A ?? 5E 3B C6 75 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 89 30 EB ?? 50 E8 ?? ?? ?? ?? 59 EB ?? 8B 04 8D ?? ?? ?? ?? F6 44 10 ?? ?? 74 - ?? 80 3B ?? 75 ?? 33 C0 EB ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 20 - ?? 83 C8 ?? EB ?? 2B 45 ?? 5F 5B 8B 4D ?? 33 CD 5E E8 ?? ?? ?? ?? 8B E5 5D C3 - } +import "pe" - condition: - uint16(0)==0x5A4D and ( all of ($skip_hk_china_taiwan_p*)) and ( all of ($find_files_*)) and ($crypt_files) and ( all of ($remote_connection_p*)) -} -rule REVERSINGLABS_Win32_Ransomware_Asn1Encoder : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Petya : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects ASN1Encoder ransomware." + description = "Yara rule that detects Petya ransomware." author = "ReversingLabs" - id = "5fa361e5-4ab0-5856-92b2-6f434e33c350" + id = "93d9fb33-88d1-50ec-bf99-1888201c0ec2" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.ASN1Encoder.yara#L1-L136" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "000fd846fa5f09af19ead4623bb5a8eb51cdb4c751013569bf070710d3e0d61d" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Petya.yara#L3-L58" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "d2adafcb21b627d614eab79e64e2b96ad09fae796d0670452a19490d8781ce99" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -41253,127 +41178,56 @@ rule REVERSINGLABS_Win32_Ransomware_Asn1Encoder : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "ASN1Encoder" + tc_detection_name = "Petya" tc_detection_factor = 5 importance = 25 strings: - $remote_connection_p1 = { - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 0F B6 - 84 34 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 2B C6 68 ?? ?? ?? ?? 03 C0 50 53 E8 ?? ?? ?? ?? - 83 C4 ?? 83 C3 ?? 46 83 FE ?? 72 ?? 8B 5C 24 ?? BE ?? ?? ?? ?? A1 ?? ?? ?? ?? 53 50 - 68 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 83 C4 ?? 50 68 ?? ?? ?? ?? 56 50 - E8 ?? ?? ?? ?? 33 C0 83 C4 ?? 8B F0 85 FF 74 ?? A1 ?? ?? ?? ?? 0F B6 04 06 50 B8 ?? - ?? ?? ?? 2B C6 68 ?? ?? ?? ?? 03 C0 50 53 E8 ?? ?? ?? ?? 83 C4 ?? 83 C3 ?? 46 3B F7 - 72 ?? 8B 5C 24 ?? A1 ?? ?? ?? ?? BE ?? ?? ?? ?? 53 50 68 ?? ?? ?? ?? 56 50 E8 ?? ?? - ?? ?? A1 ?? ?? ?? ?? 83 C4 ?? 50 68 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? C1 E8 ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 94 24 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 8B FB 8B F0 0F B6 - 84 34 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 2B C6 68 ?? ?? ?? ?? 03 C0 50 57 E8 ?? ?? ?? ?? - 83 C4 ?? 83 C7 ?? 46 83 FE ?? 72 ?? A1 ?? ?? ?? ?? 53 50 68 ?? ?? ?? ?? BB ?? ?? ?? - ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 50 68 ?? ?? - ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 50 68 ?? - ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 50 68 - ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 83 C4 ?? 33 F6 8D 51 ?? 66 8B 01 - 83 C1 ?? 66 3B C6 75 ?? 2B CA 8B 15 ?? ?? ?? ?? D1 F9 8D 72 ?? 8A 02 42 84 C0 75 ?? - 8B 3D ?? ?? ?? ?? 2B D6 8D 04 0A 8D 34 45 ?? ?? ?? ?? 56 6A ?? FF D7 50 FF 15 ?? ?? - ?? ?? 8B D8 8D 04 36 50 6A ?? 89 5C 24 ?? FF D7 50 FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? - ?? 8B F8 FF 35 ?? ?? ?? ?? 89 7C 24 ?? 68 ?? ?? ?? ?? 56 53 E8 ?? ?? ?? ?? 33 C9 89 - } - $remote_connection_p2 = { - 44 24 ?? 83 C4 ?? 89 8C 24 ?? ?? ?? ?? 8B D9 85 C0 7E ?? 8B 44 24 ?? 0F B7 04 58 66 - 89 84 24 ?? ?? ?? ?? 83 F8 ?? 75 ?? 83 EF ?? 66 8B 47 ?? 83 C7 ?? 66 3B C1 75 ?? BE - ?? ?? ?? ?? 83 C3 ?? A5 A5 66 A5 EB ?? 8D 94 24 ?? ?? ?? ?? 8B F2 66 8B 02 83 C2 ?? - 66 3B C1 75 ?? 2B D6 83 EF ?? 66 8B 47 ?? 83 C7 ?? 66 3B C1 75 ?? 8B CA C1 E9 ?? F3 - A5 8B CA 83 E1 ?? F3 A4 33 C9 8B 7C 24 ?? 43 3B 5C 24 ?? 7C ?? FF 74 24 ?? 51 FF 15 - ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 50 FF D6 FF 35 ?? ?? ?? ?? 33 C0 50 FF 15 ?? ?? ?? ?? - 50 FF D6 8B 5C 24 ?? 53 33 DB 53 FF 15 ?? ?? ?? ?? 50 FF D6 FF 74 24 ?? 53 FF 15 ?? - ?? ?? ?? 50 FF D6 FF 74 24 ?? 53 FF 15 ?? ?? ?? ?? 50 FF D6 8B 5C 24 ?? 89 3D ?? ?? - ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 33 FF E9 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? - 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 57 - FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 89 44 24 ?? 85 C0 - 0F 84 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 8B F3 89 5C 24 ?? 8D 4E ?? 8A 06 46 84 - C0 75 ?? 8B 3D ?? ?? ?? ?? 2B F1 68 ?? ?? ?? ?? 6A ?? FF D7 50 FF 15 ?? ?? ?? ?? 89 - 44 24 ?? 85 DB 0F 84 ?? ?? ?? ?? 81 FE ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 6A ?? FF D7 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 89 44 24 ?? 8D 84 24 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? - ?? ?? BA ?? ?? ?? ?? C1 E8 ?? 50 E8 ?? ?? ?? ?? 59 8D 94 24 ?? ?? ?? ?? 8D 8C 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 8B C8 8B F8 3B FE 73 ?? 81 F9 ?? ?? ?? ?? 74 ?? FF 74 - 24 ?? 8D 84 24 ?? ?? ?? ?? 50 8D 04 1F 50 E8 + $entry_point = { + 55 8B EC 56 8B 75 ?? 57 83 FE ?? 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? 56 FF 75 ?? E8 ?? ?? ?? ?? 8B F8 85 F6 75 ?? E8 ?? + ?? ?? ?? 8B C7 5F 5E 5D C2 } - $encrypt_files_p1 = { - 8B CA 8D 84 24 ?? ?? ?? ?? C1 E9 ?? F3 A5 53 68 ?? ?? ?? ?? 6A ?? 53 6A ?? 8B CA 83 - E1 ?? 68 ?? ?? ?? ?? F3 A4 50 FF 15 ?? ?? ?? ?? 8B D8 33 FF 89 5C 24 ?? 89 3D ?? ?? - ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 83 FB ?? 74 ?? 85 DB 0F 85 ?? ?? ?? ?? 33 - F6 8D 8C 24 ?? ?? ?? ?? 8B DE E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? BE ?? ?? ?? ?? 50 - 8D 44 24 ?? 8B D6 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 8B CE E8 ?? ?? ?? ?? 33 D2 - 8D 88 ?? ?? ?? ?? 8D 81 ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? 8B 44 24 ?? C1 E8 ?? 89 - 44 24 ?? 83 C0 ?? 89 44 24 ?? 8B F0 8B C1 F7 F6 40 0F AF 44 24 ?? 50 6A ?? 89 44 24 - ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? 6A ?? FF 15 ?? ?? - ?? ?? 50 FF 15 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 89 44 24 ?? E8 ?? ?? ?? ?? 8B 54 24 ?? - 8D 44 24 ?? 83 C4 ?? 81 C2 ?? ?? ?? ?? B9 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8D 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 39 5C 24 ?? 76 ?? 8B 44 24 ?? 8D - 54 24 ?? 8B 4C 24 ?? 2B C3 3B 44 24 ?? 0F 42 F0 8D 84 24 ?? ?? ?? ?? 50 8B 44 24 ?? - 8D 0C 39 68 ?? ?? ?? ?? 03 C3 56 50 E8 ?? ?? ?? ?? 03 7C 24 ?? 83 C4 ?? 03 DE 3B 7C - 24 ?? 72 ?? 33 FF 8D 84 24 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 6A ?? 57 6A ?? 68 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 5C 24 ?? 83 FB ?? 74 ?? 85 DB 74 ?? 57 8D 44 24 ?? - 89 7C 24 ?? 8B 3D ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF D7 33 F6 8D 44 + $shutdown_pattern = { + 55 8B EC 83 EC ?? 8D 45 ?? 56 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 + 75 ?? 33 C0 EB ?? 8D 45 ?? 33 F6 50 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 56 56 56 8D + 45 ?? C7 45 ?? ?? ?? ?? ?? 50 56 FF 75 ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 8D 4D ?? 51 6A ?? 56 56 56 68 ?? ?? ?? ?? FF D0 33 C0 83 C4 ?? 40 5E 8B + E5 5D C3 } - $encrypt_files_p2 = { - 24 ?? 56 50 FF 74 24 ?? FF 74 24 ?? 53 FF D7 33 FF 68 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 C4 ?? FF 74 24 ?? 57 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 50 FF D6 - FF 74 24 ?? 57 FF 15 ?? ?? ?? ?? 50 FF D6 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? - ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 6A ?? FF 15 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? 33 F6 56 53 FF 15 ?? ?? ?? ?? 3D ?? - ?? ?? ?? 76 ?? 39 35 ?? ?? ?? ?? 75 ?? 56 53 FF 15 ?? ?? ?? ?? 56 8B F8 B8 ?? ?? ?? - ?? 56 50 53 2B F8 FF 15 ?? ?? ?? ?? 57 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 56 8D 8C 24 ?? ?? ?? ?? A3 ?? ?? ?? ?? 51 57 50 53 FF 15 ?? ?? ?? ?? 33 C0 50 50 50 - 53 FF 15 ?? ?? ?? ?? 33 F6 8D 84 24 ?? ?? ?? ?? 56 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 53 FF 15 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF - 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D8 6A ?? 89 5C 24 ?? FF 15 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? 50 - FF 15 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA - ?? ?? ?? ?? C1 E8 ?? 50 E8 ?? ?? ?? ?? 59 8D 94 24 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 85 C9 75 ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? - 50 FF 15 + $sectionxxxx_pattern = { + 83 EC ?? 53 55 8B C2 89 4C 24 ?? 56 57 8B C8 89 44 24 ?? 33 D2 E8 ?? ?? ?? ?? 85 C0 + 74 ?? 0F B7 48 ?? 8B FA 83 C1 ?? 03 C8 0F B7 40 ?? 89 44 24 ?? 85 C0 74 ?? BE ?? ?? + ?? ?? 2B F1 80 39 ?? 8D 59 ?? 6A ?? 5D 75 ?? 85 ED 74 ?? 0F BE 2C 1E 0F BE 03 43 3B + E8 74 ?? 83 C1 ?? 83 EE ?? 47 3B 7C 24 ?? 72 ?? 8B CA 85 C9 74 ?? 8B 51 ?? 8B 5C 24 + ?? 8B FB 03 54 24 ?? 8B F2 8B 4A ?? A5 83 C1 ?? 03 CA 89 4B ?? A5 A5 8B 43 ?? 8D 72 + ?? 89 43 ?? 8B 43 ?? 89 43 ?? B8 ?? ?? ?? ?? 89 73 ?? 66 39 01 74 ?? 8B 7A ?? 8B 2A + 03 7A ?? 74 ?? 33 DB 43 2B DE 33 D2 8D 0C 33 8B C5 F7 F1 30 16 46 4F 75 ?? B2 ?? 5F + 5E 5D 0F B6 C2 5B 83 C4 ?? C3 } - $find_files = { - 53 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 35 ?? ?? ?? ?? FF D6 83 C4 ?? 53 8D 85 ?? - ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF D6 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 8B F0 89 75 ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? - ?? ?? 33 DB B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? - 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 8B C3 EB ?? 1B C0 83 - C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 - ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 8B - C3 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? - F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 59 BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 - A5 6A ?? 59 BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 A5 66 A5 6A ?? 59 BE ?? ?? ?? ?? 8D - BD ?? ?? ?? ?? F3 A5 66 A5 BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? A5 A5 A5 A5 50 E8 ?? ?? - ?? ?? 59 8B F0 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? - ?? ?? 50 56 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? - 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? FF 75 ?? - 8B 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B 75 ?? E9 ?? ?? ?? ?? FF 75 ?? E9 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 66 39 1F 0F 84 + $crypt_gen_pattern = { + 55 8B EC 53 57 8B 7D ?? 8D 45 ?? 68 ?? ?? ?? ?? 6A ?? 33 DB 53 53 50 89 1F FF 15 ?? + ?? ?? ?? 85 C0 75 ?? 6A ?? 58 EB ?? 56 FF 75 ?? 8B 75 ?? 56 FF 75 ?? FF 15 ?? ?? ?? + ?? 85 C0 75 ?? 6A ?? 58 EB ?? 53 FF 75 ?? FF 15 ?? ?? ?? ?? 89 37 33 C0 5E 5F 5B 5D + C3 } condition: - uint16(0)==0x5A4D and ($find_files and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*))) + uint16(0)==0x5A4D and ($entry_point at pe.entry_point) and $shutdown_pattern and $sectionxxxx_pattern and $crypt_gen_pattern } -rule REVERSINGLABS_Win32_Ransomware_Skystars : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Lockbit : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Skystars ransomware." + description = "Yara rule that detects LockBit ransomware." author = "ReversingLabs" - id = "9dc19bda-c5bd-58fb-8c4f-a7d8a6fbbce9" - date = "2020-11-20" - modified = "2020-11-20" + id = "9a6405dc-da1f-5426-a424-a73bceb1928c" + date = "2022-03-31" + modified = "2022-03-31" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Skystars.yara#L1-L97" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "352d22183b0974908ce684725fe85b4714ac5959c3bddf093b54383195881a5a" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.LockBit.yara#L1-L282" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "030222bd659c7e0e03858fa062067b1483aca3b7973cce19a1e7cdbb48d4405c" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -41381,171 +41235,243 @@ rule REVERSINGLABS_Win32_Ransomware_Skystars : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Skystars" + tc_detection_name = "LockBit" tc_detection_factor = 5 importance = 25 strings: - $search_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? - 8B 5D ?? FF 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 85 ?? ?? ?? ?? 50 - 6A ?? 6A ?? FF 75 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 5D ?? 85 DB - 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? - 83 C4 ?? 58 89 45 ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? - ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? B8 ?? - ?? ?? ?? EB ?? B8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8B 5D - ?? FF 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? - 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A - ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? - 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 5D ?? FF 33 + $enum_resources_v1 = { + 55 8B EC 83 EC ?? 57 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 51 6A ?? 6A ?? 6A ?? C7 45 ?? + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? + ?? 8B F8 89 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 53 56 FF 75 ?? 6A ?? 57 E8 ?? ?? ?? ?? 83 + C4 ?? 8D 45 ?? 50 57 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 33 DB 39 5D ?? 76 ?? 8B F7 0F 1F 80 ?? ?? ?? ?? F7 46 ?? ?? ?? ?? ?? 74 ?? 8B CE E8 + ?? ?? ?? ?? 83 7F ?? ?? 74 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F8 83 C4 ?? 8B 45 + ?? FF 70 ?? FF 15 ?? ?? ?? ?? 8D 04 45 ?? ?? ?? ?? 50 8B 45 ?? FF 70 ?? 57 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 45 ?? 50 6A ?? 57 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B + 0D ?? ?? ?? ?? 89 04 8D ?? ?? ?? ?? F0 FF 05 ?? ?? ?? ?? 8B 7D ?? 43 83 C6 ?? 3B 5D + ?? 72 ?? E9 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5E 5B 85 C0 + 75 ?? B8 ?? ?? ?? ?? 5F 8B E5 5D C3 33 C0 5F 8B E5 5D C3 } - $search_files_p2 = { - B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? - ?? ?? FF 75 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 5D ?? 85 DB 74 ?? - 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 - ?? 58 89 45 ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? - ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? - ?? EB ?? B8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8B 5D ?? FF - 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 5D - ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? - 6A ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 - ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? E9 ?? ?? ?? ?? FF 75 ?? B8 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B E5 5D C2 + $find_files_v1_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 8B C1 C7 45 ?? ?? ?? ?? ?? 57 50 89 45 ?? 33 C9 8D + 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 66 89 4D ?? 50 FF 15 ?? ?? ?? ?? 83 + C4 ?? 8D 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 6A ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? + ?? ?? 8B F8 89 7D ?? 83 FF ?? 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 33 C0 8B 35 ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 1F 80 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D + 45 ?? 50 FF D3 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 45 ?? 50 FF D3 85 C0 + 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 50 FF D3 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D3 85 + C0 0F 84 } - $encrypt_files = { - 55 8B EC 81 EC ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 5D ?? 8B 03 - 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 89 45 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? 68 - ?? ?? ?? ?? 6A ?? 8B 5D ?? 8B 03 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 5D ?? FF - 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? - ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? FF 75 ?? 68 ?? ?? - ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? - ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? - 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? - ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? - 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 - 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 50 - 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? - ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 - ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B E5 5D C2 + $find_files_v1_2 = { + 45 ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? E9 ?? ?? ?? ?? 33 C9 66 39 8D ?? ?? ?? ?? 74 ?? 8D 40 ?? 41 66 83 38 ?? 75 ?? + 83 F9 ?? 0F 8E ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 56 68 ?? ?? + ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? + 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 } - $main_routine = { - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 53 E8 - ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? - ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 5D - ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 45 ?? 50 - E8 ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? 89 45 - ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? - ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? - 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B E5 5D C3 + $find_files_v1_3 = { + 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? + ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? + 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 + ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? 33 C9 0F 11 45 ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? + ?? ?? 66 90 8A 45 ?? 30 44 0D ?? 41 83 F9 ?? 72 ?? 33 C0 C6 45 ?? ?? 66 89 45 ?? 8D + 45 ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 + C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF D3 85 C0 0F 84 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 + ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF D3 + 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF D3 85 C0 0F 84 ?? ?? + ?? ?? 8B 4D ?? 8D 95 ?? ?? ?? ?? 2B D1 0F B7 01 8D 49 ?? 66 89 44 11 ?? 66 85 C0 75 + ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B F2 66 8B 02 83 C2 ?? + 66 85 C0 75 ?? 8D BD ?? ?? ?? ?? 2B D6 83 C7 ?? 0F 1F 40 ?? 66 8B 47 ?? 83 C7 ?? 66 + 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8B CA C1 E9 ?? F3 A5 8B CA 83 E1 ?? F3 A4 A8 ?? 75 ?? + A8 ?? 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 7D ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF D6 + 83 F8 ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 57 FF 15 ?? ?? ?? ?? 5F + 5E 5B 8B E5 5D C3 } - - condition: - uint16(0)==0x5A4D and ($main_routine) and ( all of ($search_files_p*)) and ($encrypt_files) -} -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Tarrak : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects TaRRaK ransomware." - author = "ReversingLabs" - id = "a783df87-0c9b-5868-9af0-c32b11e8b71b" - date = "2021-09-06" - modified = "2021-09-06" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.TaRRaK.yara#L1-L96" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "a8c4c4a501d94da94ae4a2e1eb2846e841249659be64dd45f46584885d000635" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "TaRRaK" - tc_detection_factor = 5 - importance = 25 - - strings: - $encrypt_files_p1 = { - 03 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 06 07 9A 0C 73 ?? ?? ?? ?? 0D 09 08 28 ?? ?? ?? ?? 7D - ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 09 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? - 02 08 28 ?? ?? ?? ?? 07 17 58 0B 07 06 8E 69 32 ?? DE ?? 26 DE ?? 00 03 28 ?? ?? ?? ?? - 0A 16 0B 2B ?? 06 07 9A 13 ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 02 11 ?? 28 ?? ?? ?? ?? - 07 17 58 0B 07 06 8E 69 32 ?? DE ?? 26 DE ?? 2A + $encrypt_files_v1_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 53 56 57 8B F9 C7 45 ?? ?? ?? + ?? ?? 89 7D ?? 66 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 + 89 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 } - $encrypt_files_p2 = { - 03 8E 69 17 59 0A 06 17 2F ?? 03 2A 03 06 95 0B 16 0D 1C 1F ?? 06 17 58 5B 58 13 ?? 2B - ?? 09 20 ?? ?? ?? ?? 58 0D 09 18 64 19 5F 13 ?? 16 13 ?? 2B ?? 03 11 ?? 17 58 95 0C 03 - 11 ?? 8F ?? ?? ?? ?? 25 4B 02 09 08 07 11 ?? 11 ?? 04 28 ?? ?? ?? ?? 58 25 13 ?? 54 11 - ?? 0B 11 ?? 17 58 13 ?? 11 ?? 06 32 ?? 03 16 95 0C 03 06 8F ?? ?? ?? ?? 25 4B 02 09 08 - 07 11 ?? 11 ?? 04 28 ?? ?? ?? ?? 58 25 13 ?? 54 11 ?? 0B 16 11 ?? 25 17 59 13 ?? 32 ?? - 03 2A + $encrypt_files_v1_2 = { + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F8 33 DB 89 7D ?? 33 F6 0F 1F 00 8B 84 + B5 ?? ?? ?? ?? 85 C0 74 ?? 57 50 FF 15 ?? ?? ?? ?? 85 C0 B8 ?? ?? ?? ?? 0F 44 D8 46 + 81 FE ?? ?? ?? ?? 7C ?? 8B 7D ?? 33 C0 66 89 85 ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 57 50 8D 85 ?? ?? ?? ?? 89 5D ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 8B 1D ?? ?? ?? ?? 83 C4 ?? 33 F6 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? + 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF D3 83 F8 ?? 75 + ?? 8B CF E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? 8B } - $encrypt_files_p3 = { - 05 1B 64 04 18 62 61 04 19 64 05 1A 62 61 58 03 04 61 0E ?? 0E ?? 19 5F 6A 0E ?? 6E 61 - D4 95 05 61 58 61 2A + $encrypt_files_v1_3 = { + CF E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 83 FE ?? 7D ?? 46 EB ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? 83 + FB ?? 75 ?? 8B 1D ?? ?? ?? ?? EB ?? FF 35 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? 53 FF + 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 F8 ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 33 C0 5F 5E 5B 8B + E5 5D C3 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 DB 75 ?? FF 75 ?? FF 15 + ?? ?? ?? ?? 33 C0 5F 5E 5B 8B E5 5D C3 8B 45 ?? 8B 75 ?? 89 43 ?? 8D 43 ?? 50 56 C7 + 43 ?? ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 53 FF 15 ?? ?? + ?? ?? 83 C4 ?? 56 FF 15 ?? ?? ?? ?? 33 C0 5F 5E 5B 8B E5 5D C3 8B 4B ?? 8B 43 ?? 85 + C9 7F ?? 7C ?? 83 F8 ?? 72 ?? 83 E8 ?? C7 43 ?? ?? ?? ?? ?? 89 43 ?? 8B 43 ?? 83 D9 + ?? 89 43 ?? 8B 43 ?? 89 43 ?? 8D 83 ?? ?? ?? ?? 6A ?? 50 89 4B ?? C7 43 ?? ?? ?? ?? + ?? 89 73 ?? E8 ?? ?? ?? ?? 6A ?? 8D 83 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 53 6A ?? 6A ?? + 8D 73 ?? 56 FF 73 ?? FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 3D ?? + ?? ?? ?? 74 ?? 56 8B 35 ?? ?? ?? ?? FF D6 83 C4 ?? 53 FF D6 83 C4 ?? FF 75 ?? FF 15 + ?? ?? ?? ?? 8B 45 ?? 5F 5E 5B 8B E5 5D C3 F0 FF 05 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? + B8 ?? ?? ?? ?? F0 0F C1 05 ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 7E ?? 8B 35 ?? ?? ?? ?? 6A + ?? FF D6 83 3D ?? ?? ?? ?? ?? 7D ?? 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 } - $encrypt_files_p4 = { - 03 8E 2D ?? 03 2A 02 02 02 03 17 28 ?? ?? ?? ?? 02 02 7B ?? ?? ?? ?? 16 28 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 2A + $check_blacklisted_languages_v2 = { + FF D0 0F B7 C0 B9 2C 08 ?? ?? 66 3B C1 0F 84 ?? ?? ?? ?? B9 2C 04 ?? ?? 66 3B C1 74 + ?? B9 2B 04 ?? ?? 66 3B C1 74 ?? B9 23 04 ?? ?? 66 3B C1 74 ?? B9 37 04 ?? ?? 66 3B + C1 74 ?? B9 3F 04 ?? ?? 66 3B C1 74 ?? B9 40 04 ?? ?? 66 3B C1 74 ?? B9 19 08 ?? ?? + 66 3B C1 74 ?? B9 19 04 ?? ?? 66 3B C1 74 ?? B9 28 04 ?? ?? 66 3B C1 74 ?? B9 42 04 + ?? ?? 66 3B C1 74 ?? B9 43 08 ?? ?? 66 3B C1 74 ?? B9 43 04 ?? ?? 66 3B C1 74 ?? B9 + 22 04 ?? ?? 66 3B C1 0F 85 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 85 DB 0F 85 ?? ?? ?? ?? 64 + A1 ?? ?? ?? ?? 8B 40 ?? 8B 40 ?? 8B 00 8B C8 89 45 ?? 8B D0 89 4D ?? 0F B7 59 ?? 33 + FF 8B 71 ?? D1 EB C7 45 ?? ?? ?? ?? ?? 8D 04 5E 3B F0 0F 47 DF 85 DB 74 ?? 8A 0E 8D + 76 ?? 0F BE D1 80 E9 ?? 8B C2 83 C8 ?? 80 F9 ?? 0F 47 C2 47 33 45 ?? 69 C0 ?? ?? ?? + ?? 89 45 ?? 3B FB 75 ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B 01 8B + C8 89 4D ?? 3B C2 74 ?? 83 79 ?? ?? 75 ?? 33 DB 89 1D ?? ?? ?? ?? A1 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? 8B 43 ?? 8B 4C 18 ?? 8D 04 19 89 45 ?? + 3B C3 74 ?? 33 C9 89 4D ?? 39 48 ?? 74 ?? 8B 40 ?? 8B 55 ?? 03 C3 89 45 ?? 0F 1F 40 + ?? 8B 30 BF ?? ?? ?? ?? 8A 04 1E 03 F3 46 84 C0 74 ?? 0F BE D0 8D 76 ?? 2C ?? 8B CA + 83 C9 ?? 3C ?? 8A 46 ?? 0F 47 CA 33 CF 69 F9 ?? ?? ?? ?? 84 C0 75 ?? 8B 4D ?? 8B 55 + ?? 81 FF ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 41 83 C0 ?? 89 4D ?? 89 45 ?? 3B 4A + ?? 75 ?? 33 C0 A3 ?? ?? ?? ?? 6A ?? FF D0 5F 5E 5B 8B E5 5D C3 } - $find_files_p1 = { - 73 ?? ?? ?? ?? 25 02 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 - 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 2A + $create_net_host_trav_threads_v2 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 6A ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 64 A1 ?? ?? ?? ?? 83 C4 ?? 8B 40 ?? 50 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? A3 ?? + ?? ?? ?? E8 ?? ?? ?? ?? FF D0 85 C0 78 ?? A1 ?? ?? ?? ?? 8D 0C 85 ?? ?? ?? ?? E8 ?? + ?? ?? ?? A3 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? F0 FF 0D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B 35 } - $find_files_p2 = { - 73 ?? ?? ?? ?? 25 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 1B 28 ?? ?? ?? ?? 6F ?? ?? ?? - ?? 25 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 1F - ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2A + $fnv1a_hashing_v2 = { + 55 8B EC 83 EC ?? 64 A1 ?? ?? ?? ?? 8B 40 ?? 8B 40 ?? 8B 00 8B 50 ?? A1 ?? ?? ?? ?? + 89 55 ?? 85 C0 0F 85 ?? ?? ?? ?? 85 D2 75 ?? 33 C0 A3 ?? ?? ?? ?? 8B E5 5D C3 8B 42 + ?? 8B 4C 10 ?? 8B 44 10 ?? 89 45 ?? 8D 04 11 89 45 ?? 3B C2 74 ?? 53 33 C9 56 57 89 + 4D ?? 39 48 ?? 74 ?? 8B 78 ?? 03 FA 8B 07 BE } - $change_desktop = { - 1F ?? 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 06 28 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 17 - 8C ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 8C ?? ?? ?? ?? 6F ?? ?? ?? ?? 1F ?? 16 - 06 19 28 ?? ?? ?? ?? 26 DE ?? 26 DE ?? 2A + $decrypt_configuration_v2_1 = { + 55 8B EC 51 53 56 57 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 03 C9 83 EA ?? 75 ?? 68 ?? ?? ?? + ?? 68 ?? ?? ?? ?? BA 25 1B 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? BA 78 0C 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? + BA 39 28 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BA F1 40 + 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BA BF 11 00 00 B9 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BA 28 02 00 00 B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BA 3B 07 00 00 B9 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BA A5 04 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? BA 0F 03 00 00 B9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 33 C9 BE ?? ?? ?? ?? 85 FF 74 ?? 8B 15 ?? + ?? ?? ?? 0F 1F 44 00 ?? 80 3C 0A ?? 8D 46 ?? 0F 45 C6 41 8B F0 3B CF 72 ?? 8D 0C B5 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 89 1D ?? ?? ?? ?? 85 DB 74 ?? 33 FF 85 F6 74 ?? 90 + B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 89 04 BB 47 3B FE 72 ?? 8B 0D ?? ?? + ?? ?? 33 F6 E8 ?? ?? ?? ?? 85 C0 74 ?? 0F 1F 80 ?? ?? ?? ?? 8B 14 B3 8A 08 8D 40 ?? + 88 0A 8D 52 ?? 84 C9 75 ?? 33 C9 E8 ?? ?? ?? ?? 46 85 C0 75 ?? C7 04 B3 ?? ?? ?? ?? + 5F 5E 5B 8B E5 5D C3 } - $drop_ransom_note = { - 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 2A 00 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 02 7B ?? ?? - ?? ?? 6F ?? ?? ?? ?? 0D 12 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? - ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 07 06 6F ?? ?? ?? ?? 26 07 6F ?? - ?? ?? ?? 26 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 26 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? - 2B ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 07 11 ?? 6F ?? ?? ?? ?? 26 12 ?? 28 ?? ?? ?? ?? 2D ?? - DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? DC 07 6F ?? ?? ?? ?? 0C 02 28 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 02 7B ?? ?? ?? ?? 28 ?? ?? - ?? ?? 06 28 ?? ?? ?? ?? 11 ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 28 ?? ?? ?? ?? DE ?? - 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC DE ?? 26 - DE ?? 2A + $decrypt_configuration_v2_2 = { + 55 8B EC 51 53 56 57 8B F2 8B F9 6B CE ?? E8 ?? ?? ?? ?? 8B C8 33 C0 89 4D ?? 85 C9 + 0F 84 ?? ?? ?? ?? 85 F6 74 ?? 83 FE ?? 72 ?? 0F 28 0D ?? ?? ?? ?? 8B CE 83 E1 ?? 66 + 0F 1F 84 00 ?? ?? ?? ?? 0F 10 04 07 66 0F EF C1 0F 11 04 07 0F 10 44 07 ?? 66 0F EF + C1 0F 11 44 07 ?? 0F 10 44 07 ?? 66 0F EF C1 0F 11 44 07 ?? 0F 10 44 07 ?? 66 0F EF + C1 0F 11 44 07 ?? 83 C0 ?? 3B C1 72 ?? 8B 4D ?? 3B C6 73 ?? 80 34 38 5F 40 3B C6 72 + ?? 8B 5D ?? 8B D6 51 53 51 8B CF E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 0B E8 ?? ?? + ?? ?? 8B F8 8B 45 ?? 89 38 8B 45 ?? 85 FF 74 ?? 8B 0B 8B F0 F3 A4 8B C8 BE ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B C6 5F 5E 5B 8B E5 5D C3 + } + $encrypt_files_v2_p1 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 56 57 66 90 64 A1 ?? ?? ?? ?? 0F 57 C0 C7 44 24 + ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 66 0F 13 44 24 ?? 8B 40 ?? 8B 40 ?? 8B 00 8B + 50 ?? A1 ?? ?? ?? ?? 89 54 24 ?? 85 C0 0F 85 ?? ?? ?? ?? 85 D2 0F 84 ?? ?? ?? ?? 8B + 42 ?? 8B 4C 10 ?? 8D 04 11 89 44 24 ?? 3B C2 74 ?? 33 C9 89 4C 24 ?? 39 48 ?? 74 ?? + 8B 40 ?? 03 C2 89 44 24 ?? 0F 1F 80 ?? ?? ?? ?? 8B 30 BF C5 9D 1C 81 8A 04 16 03 F2 + 46 84 C0 74 ?? 0F BE D0 8D 76 ?? 2C ?? 8B CA 83 C9 ?? 3C ?? 8A 46 ?? 0F 47 CA 33 CF + 69 F9 93 01 00 01 84 C0 75 ?? 8B 54 24 ?? 8B 4C 24 ?? 81 FF ?? ?? ?? ?? 74 ?? 8B 74 + 24 ?? 41 8B 44 24 ?? 83 C0 ?? 89 4C 24 ?? 89 44 24 ?? 3B 4E ?? 75 ?? 33 C0 A3 ?? ?? + ?? ?? 6A ?? 8D 4C 24 ?? 51 8D 4C 24 ?? 51 8D 4C 24 ?? 51 FF 35 ?? ?? ?? ?? FF D0 85 + C0 0F 88 ?? ?? ?? ?? 8B 74 24 ?? 85 F6 0F 84 ?? ?? ?? ?? 8B 7C 24 ?? 8B 07 48 83 F8 + ?? 0F 87 ?? ?? ?? ?? FF 24 85 ?? ?? ?? ?? 8B 74 24 ?? 8B 46 ?? 8D 04 48 0F B7 0C 10 + 8B 46 ?? 8D 04 88 8B 04 10 03 C2 EB ?? 83 7F ?? ?? 0F 85 ?? ?? ?? ?? 83 7F ?? ?? 0F + 85 ?? ?? ?? ?? C7 07 ?? ?? ?? ?? 8B 4C 24 ?? 8B 54 24 ?? 68 ?? ?? ?? ?? 6A ?? 8B 41 + ?? 89 42 ?? 8B 41 ?? 89 42 ?? 8B 44 24 ?? 6A ?? 8B 40 ?? 8D 88 ?? ?? ?? ?? F7 D8 23 + C8 8B 44 24 ?? 89 48 ?? 8D 4C 24 ?? 8B 54 24 ?? 8B 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? + 8D 84 24 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? + ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? FF 76 ?? FF 76 ?? FF 15 ?? ?? ?? ?? 8B 4E + ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 8B 46 ?? 81 C1 ?? ?? ?? ?? 03 C1 50 E8 ?? ?? ?? ?? + 8B 4C 24 ?? 83 C4 ?? 8B 74 24 ?? 89 74 24 ?? 6A ?? 8D 41 ?? 50 FF 71 ?? 8D 41 ?? FF + } + $encrypt_files_v2_p2 = { + 71 ?? 50 51 6A ?? 6A ?? FF 76 ?? E8 ?? ?? ?? ?? FF D0 85 C0 0F 89 ?? ?? ?? ?? 83 C8 + ?? F0 0F C1 46 ?? 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 46 ?? 83 C4 ?? + 33 FF 85 C0 0F 84 ?? ?? ?? ?? 83 C6 ?? 8B 0E E8 ?? ?? ?? ?? 8B 44 24 ?? 8D 76 ?? 47 + 8B 40 ?? 3B F8 72 ?? 8B 74 24 ?? 85 C0 E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 56 ?? 8B C1 + F0 0F B1 0A 83 F8 ?? 75 ?? 8B 46 ?? 89 44 24 ?? 0F B7 46 ?? 83 C0 ?? 8B C8 89 44 24 + ?? E8 ?? ?? ?? ?? 8B F8 85 FF 74 ?? 0F B7 4E ?? 51 FF 76 ?? 8D 4F ?? 51 E8 ?? ?? ?? + ?? 0F B7 46 ?? 83 C4 ?? 89 47 ?? 0F 57 C0 8D 44 24 ?? C6 07 ?? C7 47 ?? ?? ?? ?? ?? + 6A ?? FF 74 24 ?? 66 0F 13 44 24 ?? 57 50 FF 74 24 ?? E8 ?? ?? ?? ?? FF D0 8B CF E8 + ?? ?? ?? ?? 8D 56 ?? 85 F6 0F 84 ?? ?? ?? ?? 83 C8 ?? F0 0F C1 02 0F 85 ?? ?? ?? ?? + 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 4E ?? 83 C4 ?? C7 44 24 ?? ?? ?? ?? ?? 85 C9 0F 84 + ?? ?? ?? ?? 8D 7E ?? 90 8B 0F E8 ?? ?? ?? ?? 8B 44 24 ?? 8D 7F ?? 8B 4E ?? 40 89 44 + 24 ?? 3B C1 72 ?? E9 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 8D 56 ?? 74 ?? 8D 8C 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 47 ?? 8B 57 ?? 50 50 8D 47 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B + C1 6A ?? EB ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 47 ?? 8D 8C 24 ?? ?? ?? ?? 8B + 57 ?? 50 50 8D 47 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 54 24 ?? 83 C4 ?? 83 7A ?? ?? 8B 42 ?? 0F 8F ?? + ?? ?? ?? 7C ?? 39 42 ?? 0F 87 ?? ?? ?? ?? 8B 74 24 ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 4E + } + $encrypt_files_v2_p3 = { + 8D 84 24 ?? ?? ?? ?? 83 C4 ?? 81 C1 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 8B 46 ?? 03 C1 50 + E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? C7 00 ?? ?? ?? ?? EB ?? 8B 44 24 ?? C7 00 ?? ?? + ?? ?? 8B 4C 24 ?? 8B 74 24 ?? 6A ?? 89 74 24 ?? 8D 41 ?? 50 FF 71 ?? 8D 41 ?? FF 71 + ?? 50 51 6A ?? 6A ?? FF 76 ?? E8 ?? ?? ?? ?? FF D0 85 C0 0F 89 ?? ?? ?? ?? 83 C8 ?? + F0 0F C1 46 ?? 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 46 ?? 83 C4 ?? 33 + FF 85 C0 0F 84 ?? ?? ?? ?? 83 C6 ?? 8B 0E E8 ?? ?? ?? ?? 8B 44 24 ?? 8D 76 ?? 47 8B + 40 ?? 3B F8 72 ?? 8B 74 24 ?? 85 C0 E9 ?? ?? ?? ?? 83 C8 ?? F0 0F C1 46 ?? 0F 85 ?? + ?? ?? ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 4E ?? 83 C4 ?? C7 44 24 ?? ?? ?? ?? ?? 85 + C9 0F 84 ?? ?? ?? ?? 8D 7E ?? 66 0F 1F 44 00 ?? 8B 0F E8 ?? ?? ?? ?? 8B 44 24 ?? 8D + 7F ?? 8B 4E ?? 40 89 44 24 ?? 3B C1 72 ?? E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 56 ?? 8B + C1 F0 0F B1 0A 83 F8 ?? 75 ?? 8B 46 ?? 89 44 24 ?? 0F B7 46 ?? 83 C0 ?? 8B C8 89 44 + 24 ?? E8 ?? ?? ?? ?? 8B F8 85 FF 74 ?? 0F B7 4E ?? 51 FF 76 ?? 8D 4F ?? 51 E8 ?? ?? + ?? ?? 0F B7 46 ?? 83 C4 ?? 89 47 ?? 0F 57 C0 8D 44 24 ?? C6 07 ?? C7 47 ?? ?? ?? ?? + ?? 6A ?? FF 74 24 ?? 66 0F 13 44 24 ?? 57 50 FF 74 24 ?? E8 ?? ?? ?? ?? FF D0 8B CF + E8 ?? ?? ?? ?? 8D 56 ?? 85 F6 0F 84 ?? ?? ?? ?? 83 C8 ?? F0 0F C1 02 0F 85 ?? ?? ?? + ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B 4E ?? 83 C4 ?? C7 44 24 ?? ?? ?? ?? ?? 85 C9 74 + ?? 8D 7E ?? 8B 0F E8 ?? ?? ?? ?? 8B 44 24 ?? 8D 7F ?? 8B 4E ?? 40 89 44 24 ?? 3B C1 + 72 ?? 85 C9 74 ?? F0 FF 05 ?? ?? ?? ?? F0 FF 0D ?? ?? ?? ?? 8B 46 ?? 85 C0 74 ?? 50 + E8 ?? ?? ?? ?? FF D0 8D 46 ?? 50 E8 ?? ?? ?? ?? FF D0 8B CE E8 ?? ?? ?? ?? E9 ?? ?? + ?? ?? 5F 33 C0 5E 8B E5 5D C2 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($change_desktop) and ($drop_ransom_note) + uint16(0)==0x5A4D and ((($enum_resources_v1) and ( all of ($find_files_v1_*)) and ( all of ($encrypt_files_v1_*))) or (($check_blacklisted_languages_v2) and ($fnv1a_hashing_v2) and ($create_net_host_trav_threads_v2) and ( all of ($decrypt_configuration_v2_*)) and ( all of ($encrypt_files_v2_p*)))) } -rule REVERSINGLABS_Win32_Ransomware_Cincoo : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Oct : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Cincoo ransomware." + description = "Yara rule that detects Oct ransomware." author = "ReversingLabs" - id = "c7c2773c-5056-5127-8af7-7f5c5a8ea8a1" - date = "2022-06-21" - modified = "2022-06-21" + id = "e811a0ba-52df-5e88-ab71-df91d5cb584a" + date = "2024-10-01" + date = "2024-10-01" + modified = "2021-08-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Cincoo.yara#L1-L78" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6a7562cae90754ea75a9fb98ce73ebdb9acf1ad7f28f2240abe6cb592d717ca3" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Oct.yara#L1-L68" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3973794d6bf26eaa752cfc70a217c059a190c63a0dd92b06de7c0893d92d9e88" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -41553,71 +41479,60 @@ rule REVERSINGLABS_Win32_Ransomware_Cincoo : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Cincoo" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? - 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 55 ?? 8B D9 83 7B ?? ?? 8B F3 8B 45 ?? 8B 7D - ?? 89 45 ?? 72 ?? 8B 33 8D 4E ?? 66 8B 06 83 C6 ?? 66 85 C0 75 ?? 2B F1 D1 FE 0F 84 - ?? ?? ?? ?? 3B 73 ?? 0F 85 ?? ?? ?? ?? 88 45 ?? 8D 55 ?? FF 75 ?? 8D 4D ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? C7 45 ?? ?? ?? ?? - ?? 50 8B CB E8 ?? ?? ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B - C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? - ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7B ?? ?? 72 ?? 8B 1B 8B 75 ?? 57 56 53 E8 ?? ?? - ?? ?? 85 C0 75 ?? 8B 36 8B CF E8 ?? ?? ?? ?? 84 C0 74 ?? 57 56 E8 ?? ?? ?? ?? 85 C0 - 75 ?? 8B CF E8 ?? ?? ?? ?? 84 C0 75 ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E - 5B 8B E5 5D C3 - } $encrypt_files = { - 55 8B EC 83 EC ?? 8B 45 ?? 53 8B D9 89 45 ?? B9 ?? ?? ?? ?? 8B C1 56 8B 53 ?? 2B C2 - 8B 75 ?? 89 55 ?? 57 3B C6 0F 82 ?? ?? ?? ?? 8B 7B ?? 8D 04 32 8B F0 89 45 ?? 83 CE - ?? 89 7D ?? 3B F1 76 ?? 8B F1 EB ?? 8B C7 D1 E8 2B C8 3B F9 76 ?? BE ?? ?? ?? ?? EB - ?? 03 C7 3B F0 0F 42 F0 33 C9 8B C6 83 C0 ?? 0F 92 C1 F7 D9 0B C8 81 F9 ?? ?? ?? ?? - 72 ?? 8D 41 ?? 3B C1 0F 86 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? - ?? ?? 8B 55 ?? 8D 78 ?? 83 E7 ?? 89 47 ?? EB ?? 85 C9 74 ?? 51 E8 ?? ?? ?? ?? 8B 55 - ?? 83 C4 ?? 8B F8 EB ?? 33 FF 8B 45 ?? 89 43 ?? 8B 45 ?? 89 73 ?? 8D 34 3A 03 C6 83 - 7D ?? ?? 89 45 ?? 52 72 ?? 8B 33 56 57 E8 ?? ?? ?? ?? FF 75 ?? 8B 45 ?? FF 75 ?? 03 - C7 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 4D ?? 41 C6 00 ?? 81 F9 ?? ?? ?? ?? 72 ?? - 8B 56 ?? 83 C1 ?? 2B F2 8D 46 ?? 83 F8 ?? 77 ?? 8B F2 51 56 E8 ?? ?? ?? ?? 83 C4 ?? - 89 3B 8B C3 5F 5E 5B 8B E5 5D C2 ?? ?? 53 57 E8 ?? ?? ?? ?? FF 75 ?? FF 75 ?? 56 E8 - ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? C6 00 ?? 8B C3 89 3B 5F 5E 5B 8B E5 5D C2 ?? ?? E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? CC CC CC 56 8B F1 FF 76 ?? E8 ?? ?? ?? ?? 8B - 4E ?? 83 F9 ?? 72 ?? 8B 06 8D 0C 4D ?? ?? ?? ?? 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 - C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 77 ?? 8B C2 51 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 46 ?? ?? - ?? ?? ?? 33 C0 C7 46 ?? ?? ?? ?? ?? 66 89 06 5E C3 E8 ?? ?? ?? ?? CC CC CC CC CC CC - 8B 09 85 C9 74 ?? 8B 01 6A ?? FF 10 C3 + 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 03 0B 07 18 73 ?? ?? ?? ?? 0C 73 + ?? ?? ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 04 06 + 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F + ?? ?? ?? ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 19 6F ?? + ?? ?? ?? 09 17 6F ?? ?? ?? ?? 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 02 19 73 ?? + ?? ?? ?? 13 ?? 2B ?? 11 ?? 11 ?? D2 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 25 13 ?? 15 33 + ?? 11 ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 02 28 ?? ?? ?? ?? DE ?? + 13 ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 2A } - $drop_ransom_note = { - 52 51 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 74 ?? 8D 4D ?? C6 46 ?? ?? - E8 ?? ?? ?? ?? 8B 45 ?? E9 ?? ?? ?? ?? 8B CE C6 45 ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 8D - 4E ?? 50 E8 ?? ?? ?? ?? 81 CF ?? ?? ?? ?? 89 BD ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? - ?? ?? 8B C2 8B 8D ?? ?? ?? ?? 2B C1 89 8D ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 83 F8 ?? - 72 ?? 83 FA ?? 8D B5 ?? ?? ?? ?? 8D 41 ?? 0F 43 B5 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D - 04 0E 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? C6 44 30 ?? ?? 8D 85 ?? ?? ?? ?? - EB + $find_files = { + 16 0A 38 ?? ?? ?? ?? 16 0B 2B ?? 02 06 9A 28 ?? ?? ?? ?? 2C ?? 02 06 9A 73 ?? ?? ?? ?? + 0C 08 72 ?? ?? ?? ?? 03 07 9A 28 ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 0D 09 13 ?? 16 13 ?? 2B + ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 05 28 ?? ?? ?? ?? 1E + 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 17 58 13 ?? 11 ?? + 11 ?? 8E 69 32 ?? 07 17 58 0B 07 03 8E 69 32 ?? 06 17 58 0A 06 02 8E 69 3F ?? ?? ?? ?? + 2A + } + $collect_env_and_start_enc_proc = { + 19 8D ?? ?? ?? ?? 0B 07 16 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 07 17 1B + 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 07 18 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? + ?? 28 ?? ?? ?? ?? A2 07 1F ?? 8D ?? ?? ?? ?? 0C 08 16 72 ?? ?? ?? ?? A2 08 17 72 ?? ?? + ?? ?? A2 08 18 72 ?? ?? ?? ?? A2 08 19 72 ?? ?? ?? ?? A2 08 1A 72 ?? ?? ?? ?? A2 08 1B + 72 ?? ?? ?? ?? A2 08 1C 72 ?? ?? ?? ?? A2 08 1D 72 ?? ?? ?? ?? A2 08 1E 72 ?? ?? ?? ?? + A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 + 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? + 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? + ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? + ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 1F ?? 72 ?? ?? ?? ?? A2 08 72 ?? ?? ?? ?? 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0A + 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? DC 72 ?? ?? ?? ?? 16 + 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 2A } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($drop_ransom_note) + uint16(0)==0x5A4D and ($collect_env_and_start_enc_proc) and ($find_files) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Cryakl : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Velso : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Cryakl ransomware." + description = "Yara rule that detects Velso ransomware." author = "ReversingLabs" - id = "5c668278-458e-5b13-83c4-63beab5249ed" + id = "72c7baaa-4f83-54c5-ba71-2b45e5eeefd2" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Cryakl.yara#L1-L64" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "51d50ab1ce021e2facbca3a35af372186287a8d69b66651c9804234a409d9932" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Velso.yara#L1-L230" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "602be848a26106a1bd46cfc515578f0628687e6cb352e609a274220a61bcb620" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -41625,64 +41540,212 @@ rule REVERSINGLABS_Win32_Ransomware_Cryakl : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Cryakl" + tc_detection_name = "Velso" tc_detection_factor = 5 importance = 25 strings: - $enum_and_encrypt_files_1 = { - 8B 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 5A E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 5A E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 5A E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 5A E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF - 30 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 80 7C 02 ?? ?? 74 ?? 8D 45 ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? - E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 83 E0 ?? 83 F8 ?? 75 ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 8B 10 FF 92 ?? ?? ?? ?? - 84 C0 0F 84 ?? ?? ?? ?? FF 75 ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 + $find_files_p1 = { + 55 89 E5 81 EC ?? ?? ?? ?? 8D 45 ?? 89 A5 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 75 ?? C6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 89 04 24 E8 ?? ?? ?? ?? 0F B6 85 ?? ?? ?? ?? C9 C3 C7 04 24 ?? ?? ?? ?? 8B 4D ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? C7 04 24 ?? ?? ?? + ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? + ?? ?? ?? 83 EC ?? 85 C0 74 ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 EC ?? + 85 C0 74 ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 84 ?? ?? + ?? ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 84 ?? ?? ?? ?? + C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 84 ?? ?? ?? ?? C7 04 + 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 85 C0 51 0F 84 ?? ?? ?? ?? C7 04 24 ?? ?? ?? + ?? 8B 4D ?? E8 ?? ?? ?? ?? 85 C0 52 0F 84 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? + E8 ?? ?? ?? ?? 85 C0 51 0F 84 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? + ?? 85 C0 52 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? + ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 04 24 8B 4D ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 39 D0 74 ?? 89 + 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? + 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 44 24 } - $enum_and_encrypt_files_2 = { - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8D 95 ?? - ?? ?? ?? 33 C0 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 58 E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? - C6 45 ?? ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 8B 10 FF 52 ?? 8B D8 - 4B 85 DB 0F 8C ?? ?? ?? ?? 43 33 F6 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8D 8D ?? - ?? ?? ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 8B D6 8B 38 FF 57 ?? 8B - 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 58 E8 ?? ?? ?? ?? 75 ?? C6 45 ?? ?? - 46 4B 0F 85 ?? ?? ?? ?? 80 7D ?? ?? 0F 84 ?? ?? ?? ?? A1 ?? ?? ?? ?? 50 A1 ?? ?? ?? - ?? 50 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 8B 0D ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 15 ?? ?? ?? - ?? 83 C0 ?? 83 D2 ?? 89 05 ?? ?? ?? ?? 89 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? - ?? ?? 8B 10 FF 92 ?? ?? ?? ?? 84 C0 75 ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? - ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 + $find_files_p2 = { + 8B 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 52 52 8D 95 + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? + EB ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 52 52 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 51 51 74 ?? + 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 52 52 74 ?? + F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 4D ?? 89 85 ?? ?? ?? ?? + 8B 45 ?? 8B 51 ?? 8D 8D ?? ?? ?? ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 51 51 89 44 24 ?? 8B 45 ?? 89 44 24 + ?? 8D 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 39 D0 74 ?? 89 04 + 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 39 D0 0F 84 ?? ?? ?? ?? 89 04 + 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? + 8D 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 89 + 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? EB + ?? 83 C5 ?? 83 BD ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 0F 87 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? FF 24 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 + } + $enum_resources_p1 = { + 55 89 E5 81 EC ?? ?? ?? ?? 8D 45 ?? 89 65 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 45 ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 EC ?? 85 C0 74 ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 + ?? C9 C2 ?? ?? 8B 45 ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 EC ?? 85 C0 89 85 ?? ?? ?? ?? 74 ?? 90 8D B4 26 ?? ?? ?? ?? 8B 45 ?? C7 + 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D 55 ?? + 89 54 24 ?? 8B 85 ?? ?? ?? ?? 8D 55 ?? 89 54 24 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 C7 + 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 + 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 EC ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? + 85 C0 0F 94 C0 0F B6 C0 89 45 ?? E9 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B + } + $enum_resources_p2 = { + 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 45 ?? EB ?? 8B 45 ?? 8B 40 ?? 89 85 + ?? ?? ?? ?? 83 E0 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 83 45 ?? ?? 8B + 85 ?? ?? ?? ?? 39 45 ?? 0F 86 ?? ?? ?? ?? 8B 45 ?? F6 40 ?? ?? 74 ?? 8D 45 ?? 8B 4D + ?? 89 45 ?? 8B 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 83 EC ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? + 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 83 EC ?? 39 D0 0F 84 + ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 8D 45 ?? 8B + 4D ?? 89 45 ?? 8B 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 EC ?? 8B 40 ?? 89 C2 89 85 ?? ?? ?? ?? 8D 45 + ?? 85 D2 89 45 ?? B8 ?? ?? ?? ?? 74 ?? 89 14 24 E8 ?? ?? ?? ?? 03 85 ?? ?? ?? ?? 89 + 44 24 ?? 8B 85 ?? ?? ?? ?? 8D 4D ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 45 ?? 83 EC ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D + 55 ?? 39 D0 0F 84 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 + } + $encrypt_files_p1 = { + 55 89 E5 81 EC ?? ?? ?? ?? 8D 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 A5 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? + C6 45 ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 + 45 ?? ?? C7 45 ?? ?? ?? ?? ?? 03 48 ?? 89 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 01 C7 04 24 ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 83 EC ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 4D ?? 83 EC ?? 89 85 ?? ?? ?? ?? 8B 45 ?? 8B 51 ?? 8D + 8D ?? ?? ?? ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? B8 ?? ?? ?? ?? 2B 85 ?? ?? ?? ?? 83 EC ?? 83 F8 ?? 0F 86 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 8D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 8D 8D ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 03 48 ?? C7 04 24 ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 83 EC ?? 39 D0 + 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B + } + $encrypt_files_p2 = { + 40 ?? 89 44 24 ?? 8B 45 ?? 8B 00 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? A1 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 89 94 05 ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C9 C3 03 48 ?? 8B 41 ?? 83 C8 ?? 89 04 24 C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? 03 48 ?? 8B 41 ?? 83 C8 ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 EC ?? E9 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C5 ?? 83 BD ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 77 ?? 8B 85 + ?? ?? ?? ?? FF 24 85 ?? ?? ?? ?? 0F 0B 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 39 D0 74 + ?? 89 04 24 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 15 ?? ?? + ?? ?? 8B 40 ?? 89 94 05 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 + } + $encrypt_files_p3 = { + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? + ?? ?? 8B 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 89 94 05 ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 + 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 55 89 E5 81 + EC ?? ?? ?? ?? 8D 45 ?? 89 65 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 45 ?? 8B 4D ?? 89 45 ?? 8B + 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 45 ?? 83 EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 4D ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? + 8B 45 ?? 8D 55 ?? 83 EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 39 + } + $encrypt_files_p4 = { + D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 55 ?? 85 D2 75 ?? C6 45 ?? ?? 8D 45 ?? 89 04 24 + E8 ?? ?? ?? ?? 0F B6 45 ?? C9 C3 8D 45 ?? 8B 4D ?? 89 45 ?? 8B 45 ?? 8B 51 ?? 8D 4D + ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 83 + EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 + 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8D 55 ?? 83 + EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 39 C8 74 ?? 89 04 24 E8 + ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 8B 4D ?? 89 45 ?? 8B 45 ?? 8B + 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 45 ?? 83 EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 4D ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? + 8D 55 ?? 83 EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 39 D0 74 ?? + 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 8B 4D ?? 89 45 + } + $encrypt_files_p5 = { + 8B 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 45 ?? 83 EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 4D ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 + ?? 8B 45 ?? 8D 55 ?? 83 EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? + 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 8B 4D + ?? 89 45 ?? 8B 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 83 EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? + ?? ?? 89 45 ?? 8B 45 ?? 8D 55 ?? 83 EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 + ?? 8D 4D ?? 39 C8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D + 45 ?? 8B 4D ?? 89 45 ?? 8B 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? + C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 83 EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 + C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8D 4D ?? 83 EC ?? 39 C8 74 ?? 89 04 24 E8 ?? ?? + ?? ?? 8B 45 ?? 8D 4D ?? 39 C8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + } + $encrypt_files_p6 = { + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 8B 00 + 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 83 F8 ?? 89 85 ?? ?? ?? ?? 0F + 84 ?? ?? ?? ?? 8D 4D ?? 89 04 24 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 EC ?? 3D ?? + ?? ?? ?? 77 ?? 83 E0 ?? 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 EC ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 + ?? 89 04 24 E8 ?? ?? ?? ?? 8D 55 ?? C7 44 24 ?? ?? ?? ?? ?? 89 C1 89 54 24 ?? 8B 45 + ?? 89 44 24 ?? 89 8D ?? ?? ?? ?? 89 4C 24 ?? 8B 95 ?? ?? ?? ?? 89 14 24 C7 45 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 83 EC ?? 3B 55 ?? 89 95 ?? ?? ?? ?? 0F 85 ?? ?? ?? + ?? 8B 45 ?? 8B 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C1 E8 ?? 89 8D ?? ?? ?? ?? 85 C0 + 89 85 ?? ?? ?? ?? 74 ?? 8B 45 ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? 89 85 ?? + ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 45 ?? ?? 83 85 ?? ?? ?? ?? + ?? 8B 55 ?? 39 95 ?? ?? ?? ?? 75 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + } + $encrypt_files_p7 = { + C7 44 24 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 4D ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 8B 8D ?? ?? ?? ?? 89 4C 24 + ?? 8B 95 ?? ?? ?? ?? 89 54 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 8D ?? + ?? ?? ?? 83 EC ?? 3B 4D ?? 74 ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 51 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 95 ?? ?? + ?? ?? 89 14 24 E8 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 89 0C 24 E8 ?? ?? ?? ?? C6 45 ?? + ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 52 + 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 + ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 8B 00 89 04 24 C7 + 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 50 8D 4D ?? 8B 45 ?? 39 C8 74 ?? 89 04 24 E8 ?? + ?? ?? ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 89 45 ?? E9 } condition: - uint16(0)==0x5A4D and (( all of ($enum_and_encrypt_files_*))) + uint16(0)==0x5A4D and ( all of ($enum_resources_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_District : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Badbeeteam : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects District ransomware." + description = "Yara rule that detects Badbeeteam ransomware." author = "ReversingLabs" - id = "fc6abbc7-66f9-56e6-8106-5f360f25b092" - date = "2020-07-15" - modified = "2020-07-15" + id = "39490b21-34b9-51cb-a3ed-672b3186a233" + date = "2020-11-13" + modified = "2020-11-13" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.District.yara#L1-L194" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "9ce395636fd7719f503726df82998e1ac72e9e80fd7a4534bd2251ac9283af38" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Badbeeteam.yara#L1-L137" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "9b5367655c7c70958332d31524833d96d03027aab693393b19f478a80482abd0" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -41690,177 +41753,127 @@ rule REVERSINGLABS_Win32_Ransomware_District : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "District" + tc_detection_name = "Badbeeteam" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_p1 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 - 24 ?? 8B F1 8D 4D ?? 50 E8 ?? ?? ?? ?? 40 C7 44 24 ?? ?? ?? ?? ?? 6A ?? 33 C9 C7 44 - 24 ?? ?? ?? ?? ?? 50 8D 45 ?? 66 89 4C 24 ?? 50 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 EC ?? - C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 40 C7 84 24 ?? ?? ?? - ?? ?? ?? ?? ?? 33 C9 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 50 51 8D 45 ?? 66 89 8C 24 ?? - ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 8D - 44 24 ?? 8D 4C 24 ?? 50 E8 ?? ?? ?? ?? 40 C7 44 24 ?? ?? ?? ?? ?? 6A ?? 33 C9 C7 44 - 24 ?? ?? ?? ?? ?? 50 8D 44 24 ?? 66 89 4C 24 ?? 50 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 EC - ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 8D 4C 24 ?? 50 E8 ?? ?? ?? ?? 33 C9 C7 44 24 - ?? ?? ?? ?? ?? 50 51 8D 44 24 ?? 66 89 4C 24 ?? 50 8D 4C 24 ?? C7 44 24 ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? 6A ?? 50 66 89 44 24 ?? 8D 4C 24 ?? - 8D 45 ?? C7 44 24 ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 56 8D 4C 24 ?? E8 ?? - ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 6A ?? 0F 43 45 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? - ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 66 0F 6E C0 F3 0F E6 C0 C1 E8 ?? F2 0F 58 04 C5 - ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 56 E8 ?? ?? ?? ?? 56 8B D8 - } - $encrypt_files_p2 = { - E8 ?? ?? ?? ?? 83 C4 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 0F 1F 40 ?? 0F 1F 84 00 - ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 6A ?? A3 ?? ?? ?? ?? 8D 44 24 ?? 50 56 - 53 57 89 0D ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 56 FF 74 24 ?? 8B D3 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? F7 D8 6A - ?? 6A ?? 50 57 FF 15 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 56 FF 74 24 ?? 57 FF 15 ?? ?? - ?? ?? 83 6C 24 ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 - FF 15 ?? ?? ?? ?? 83 7C 24 ?? ?? 8D 4C 24 ?? 8D 45 ?? 0F 43 4C 24 ?? 83 7D ?? ?? 51 - 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 83 F8 ?? 72 ?? 40 8D 4C 24 ?? 50 FF 74 - 24 ?? E8 ?? ?? ?? ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 ?? 8B 44 24 ?? C7 44 - 24 ?? ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 4C 24 ?? 50 FF 74 24 ?? E8 ?? ?? ?? ?? 33 C0 - C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 ?? 8B 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 83 F8 ?? - 72 ?? 40 8D 4C 24 ?? 50 FF 74 24 ?? E8 ?? ?? ?? ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? 66 - 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 4C 24 - ?? 50 FF 74 24 ?? E8 ?? ?? ?? ?? 33 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 44 24 - ?? 8B 44 24 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 4C 24 ?? 50 FF - 74 24 ?? E8 ?? ?? ?? ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 ?? 89 44 24 ?? 8B - 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 77 ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 - C1 ?? 75 ?? 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 ?? 72 ?? 83 F9 ?? 77 ?? 8B C8 51 E8 ?? - ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C2 - } - $find_files = { - 53 55 56 57 6A ?? 8B F1 E8 ?? ?? ?? ?? 83 C4 ?? 8D 9E ?? ?? ?? ?? 8B E8 53 68 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 53 50 89 45 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D BE ?? ?? ?? - ?? 0F 1F 80 ?? ?? ?? ?? F6 03 ?? 57 74 ?? 8B CE E8 ?? ?? ?? ?? 84 C0 75 ?? 57 E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 50 8B CE E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? 84 C0 74 - ?? 8B CE E8 ?? ?? ?? ?? 53 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 80 7C 24 ?? ?? 75 - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 55 E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5D - 5B C2 - } - $enum_resources_1_p1 = { - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 55 56 57 33 C0 C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 - ?? 8B DA 8D 44 24 ?? 89 5C 24 ?? 50 51 6A ?? 6A ?? 6A ?? C7 44 24 ?? ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 85 C0 74 ?? 3D ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? - 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? BE ?? ?? - ?? ?? E9 ?? ?? ?? ?? 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? 50 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 3D - ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? - ?? ?? ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 ED 89 - 6C 24 ?? 39 6C 24 ?? 0F 86 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 85 DB 0F 8E ?? ?? ?? ?? C1 - E5 ?? 8B F3 89 6C 24 ?? 89 5C 24 ?? 0F 1F 84 00 ?? ?? ?? ?? 83 BC 2C ?? ?? ?? ?? ?? - 0F 85 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 74 ?? 8B 84 2C ?? ?? ?? ?? 66 83 78 ?? ?? 8D - 50 ?? 74 ?? 8D B4 24 ?? ?? ?? ?? 8D 48 ?? 8A 01 8D 52 ?? 88 06 8D 76 ?? 66 83 3A - } - $enum_resources_1_p2 = { - 8D 49 ?? 75 ?? 8B 74 24 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 - 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B4 2C ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 6A ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 ?? FF 70 ?? 8B 40 ?? 83 E0 ?? 50 8D 84 24 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 74 24 ?? 83 C4 ?? C6 44 24 ?? ?? 8B 56 ?? - F6 C2 ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 - A1 ?? ?? ?? ?? 66 89 41 ?? F6 C2 ?? 74 ?? 8D 4C 24 ?? 49 0F 1F 44 00 ?? 8A 41 ?? 8D - 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? A0 ?? ?? ?? ?? - 88 41 ?? F6 C2 ?? 74 ?? 8D 4C 24 ?? 49 0F 1F 00 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? - ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 66 89 41 ?? A0 ?? ?? ?? ?? - 88 41 ?? F6 C2 ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? - 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F6 C2 ?? 74 ?? 8D 4C 24 ?? 49 66 0F 1F 44 00 ?? - 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F6 + $find_files_p1 = { + 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 + F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 5F C9 C3 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? + ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? + FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 5D ?? + 8B CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 EB ?? + 8B 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B EB ?? 33 FF 57 57 + 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 + 45 ?? 8B 4D ?? 8B 55 ?? 53 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C ?? 74 + ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 ?? ?? + ?? ?? 8A 01 88 85 ?? ?? ?? ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 57 E8 + ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? 74 ?? + 3C ?? 8A C3 75 ?? B0 ?? 2B CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D } - $enum_resources_1_p3 = { - C2 ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 A1 ?? - ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? F6 C2 ?? 74 ?? 8D - 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 - 89 41 ?? 84 D2 79 ?? 8D 4C 24 ?? 49 0F 1F 40 ?? 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? - ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 66 - 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? - ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 - ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? - ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 66 - 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D - 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 - ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? - ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? F7 C2 ?? ?? ?? ?? 74 + $find_files_p2 = { + 56 1B C0 89 9D ?? ?? ?? ?? 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? + ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 8D ?? ?? ?? ?? F7 D8 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? + ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B + D8 E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D + ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? + 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? + 75 ?? 8A 48 ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? + ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? + ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 + C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 + ?? EB ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 59 8B D8 56 FF 15 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 59 8B C3 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? C9 C3 } - $enum_resources_2_p1 = { - 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 A1 ?? ?? ?? - ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 ?? ?? ?? ?? - 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 A1 ?? ?? ?? - ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? - 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 ?? ?? - ?? ?? 74 ?? 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 - 66 A1 ?? ?? ?? ?? 66 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C - 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 - 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? - ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A - 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 - ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 - A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? F7 C2 ?? ?? - ?? ?? 74 ?? 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 + $encrypt_files_p1 = { + 59 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 F1 83 C4 ?? 84 C0 0F 85 ?? ?? ?? ?? + 51 E8 ?? ?? ?? ?? 59 B9 ?? ?? ?? ?? 89 D6 6A ?? 5A 56 50 E8 ?? ?? ?? ?? 8D 8C 24 ?? + ?? ?? ?? 83 C4 ?? 84 C0 0F 85 ?? ?? ?? ?? FF 04 24 51 57 E8 ?? ?? ?? ?? 58 59 8D 8C + 24 ?? ?? ?? ?? 8D 54 24 ?? 57 E8 ?? ?? ?? ?? 58 83 BC 24 ?? ?? ?? ?? ?? 0F 84 ?? ?? + ?? ?? 8B 84 24 ?? ?? ?? ?? F2 0F 10 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? A1 ?? ?? + ?? ?? F2 0F 11 84 24 ?? ?? ?? ?? 8B 00 83 F8 ?? 72 ?? 8D 84 24 ?? ?? ?? ?? C7 84 24 + ?? ?? ?? ?? ?? ?? ?? ?? 8D 4C 24 ?? 89 44 24 ?? 31 C0 C7 44 24 ?? ?? ?? ?? ?? 40 89 + 84 24 ?? ?? ?? ?? 83 A4 24 ?? ?? ?? ?? ?? 89 8C 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 57 E8 + ?? ?? ?? ?? 59 89 D6 B9 ?? ?? ?? ?? 6A ?? 5A 56 50 E8 ?? ?? ?? ?? 59 5A 89 F9 89 C3 + E8 ?? ?? ?? ?? 84 DB 0F 85 ?? ?? ?? ?? 6A ?? 59 8D 7C 24 ?? 8D B4 24 ?? ?? ?? ?? F3 + A5 6A ?? 59 8D BC 24 ?? ?? ?? ?? 8D 74 24 ?? 31 C0 F3 A5 E9 ?? ?? ?? ?? 8B 84 24 ?? + ?? ?? ?? 85 C0 74 ?? 8B 8C 24 ?? ?? ?? ?? 50 FF 11 83 C4 ?? 8B 84 24 ?? ?? ?? ?? 8B + 70 ?? 8B 78 ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 89 C1 89 F2 57 E8 ?? ?? ?? ?? + 58 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 9C 24 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 69 } - $enum_resources_2_p2 = { - 01 A1 ?? ?? ?? ?? 89 41 ?? 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D - 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 - 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? - ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 - 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? F7 - C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 - 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? 85 D2 79 - ?? 8D 4C 24 ?? 49 66 0F 1F 44 00 ?? 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 - 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A0 ?? ?? - ?? ?? 88 41 ?? F7 C2 ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? 49 66 90 8A 41 ?? 8D 49 ?? 84 C0 - 75 ?? A1 ?? ?? ?? ?? 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? 8D 4C 24 ?? 8D 51 ?? 8A 01 - 41 84 C0 75 ?? 2B CA 56 88 44 0C ?? FF D7 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 8D + $encrypt_files_p2 = { + 7B ?? ?? ?? ?? ?? 89 C6 83 C6 ?? 85 FF 74 ?? 83 7E ?? ?? 74 ?? 8D 46 ?? 50 E8 ?? ?? + ?? ?? 58 81 C6 ?? ?? ?? ?? 81 C7 ?? ?? ?? ?? EB ?? 83 7E ?? ?? 74 ?? 83 3E ?? 74 ?? + 8D 4E ?? E8 ?? ?? ?? ?? EB ?? 8D 46 ?? 50 E8 ?? ?? ?? ?? 58 8B 06 F0 FF 08 75 ?? 56 + E8 ?? ?? ?? ?? EB ?? 53 8D 44 24 ?? 50 E8 ?? ?? ?? ?? 58 59 8B 4C 24 ?? 85 C9 74 ?? + 8B 54 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 58 8D 9C 24 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 + 6B 5B ?? ?? 89 C7 89 C6 83 C7 ?? 85 DB 74 ?? 8D 4E ?? E8 ?? ?? ?? ?? 83 7E ?? ?? 74 + ?? 57 E8 ?? ?? ?? ?? 58 83 3F ?? 74 ?? 8D 47 ?? EB ?? 8D 46 ?? 50 E8 ?? ?? ?? ?? 58 + 83 C6 ?? 83 C7 ?? 83 C3 ?? EB ?? 8D 84 24 ?? ?? ?? ?? 50 8D 5C 24 ?? 53 E8 ?? ?? ?? + ?? 58 59 8B 4C 24 ?? 85 C9 74 ?? 8B 54 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 58 8D B4 24 + ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 6B 7E ?? ?? 89 C1 85 FF 74 ?? 8D 59 ?? 83 C1 ?? E8 + ?? ?? ?? ?? 89 D9 83 C7 ?? 8D 5C 24 ?? EB ?? 56 53 E8 ?? ?? ?? ?? 58 59 8B 4C 24 ?? + 85 C9 74 ?? 8B 54 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 58 A1 ?? ?? ?? ?? 8B 00 83 F8 ?? + 72 ?? 89 E0 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 89 C6 89 D7 68 ?? ?? ?? ?? 8D 44 + 24 ?? 50 E8 ?? ?? ?? ?? 59 59 89 B4 24 ?? ?? ?? ?? 89 BC 24 ?? ?? ?? ?? 89 84 24 ?? + ?? ?? ?? 89 94 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 6A ?? 58 89 44 24 ?? 83 64 24 + ?? ?? 8D 8C 24 ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? 68 ?? ?? ?? ?? 6A ?? 53 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B 7D ?? 8B 77 ?? 83 C7 ?? 8D 4E ?? E8 ?? + ?? ?? ?? C7 46 ?? ?? ?? ?? ?? 83 66 ?? ?? 89 F9 E8 ?? ?? ?? ?? 8D 65 ?? 5E 5F 5B 5D + C3 } - $enum_resources_2_p3 = { - 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 74 24 ?? FF D7 8B BC 2C ?? ?? ?? ?? 33 D2 - 8B CF 8D 71 ?? 8A 01 41 84 C0 75 ?? 2B CE 8D 43 ?? 03 C1 74 ?? 8B 6C 24 ?? 8B DF 8B - CB 42 8D 71 ?? 0F 1F 00 8A 01 41 84 C0 75 ?? 2B CE 8D 45 ?? 03 C1 3B D0 72 ?? 8B 6C - 24 ?? 8B 5C 24 ?? 8B CF 33 D2 8D 71 ?? 8A 01 41 84 C0 75 ?? 2B CE 8D 43 ?? 03 C1 74 - ?? 8B 9C 2C ?? ?? ?? ?? 8B 6C 24 ?? 0F 1F 40 ?? 8B CB 42 8D 71 ?? 8A 01 41 84 C0 75 - ?? 2B CE 8D 45 ?? 03 C1 3B D0 72 ?? 8B 6C 24 ?? 8B 5C 24 ?? 33 D2 8D 4F ?? 8A 07 47 - 84 C0 75 ?? 2B F9 8D 43 ?? 03 C7 74 ?? 8B BC 2C ?? ?? ?? ?? 0F 1F 40 ?? 8B C7 42 8D - 70 ?? 8A 08 40 84 C9 75 ?? 2B C6 40 03 C3 3B D0 72 ?? 8B 3D ?? ?? ?? ?? 8B 74 24 ?? - 83 EE ?? 89 74 24 ?? 0F 85 ?? ?? ?? ?? 8B 6C 24 ?? 8B F5 C1 E6 ?? 8B 84 34 ?? ?? ?? - ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? FF 24 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 - ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 94 34 ?? ?? ?? ?? 66 83 3A ?? 75 ?? 33 C9 EB ?? 8B CA + $drop_hta_file_p1 = { + 6A ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? ?? ?? ?? 59 89 D3 89 F9 89 + C2 53 E8 ?? ?? ?? ?? 58 8D B4 24 ?? ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? + ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 58 31 DB 43 53 57 E8 ?? ?? ?? ?? 59 + 5A 53 89 DF 50 E8 ?? ?? ?? ?? 59 5A 8D 5C 24 ?? 89 C2 89 D9 56 E8 ?? ?? ?? ?? 58 39 + 3B 0F 85 ?? ?? ?? ?? F2 0F 10 44 24 ?? A1 ?? ?? ?? ?? 8D 74 24 ?? 8D BC 24 ?? ?? ?? + ?? F2 0F 11 44 24 ?? 8B 00 83 F8 ?? 72 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 59 89 + 84 24 ?? ?? ?? ?? 31 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 89 94 24 ?? ?? ?? ?? 40 89 + 84 24 ?? ?? ?? ?? 83 A4 24 ?? ?? ?? ?? ?? 89 BC 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 6A ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? ?? ?? + ?? EB ?? 8B 44 24 ?? 89 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? + 8D BC 24 ?? ?? ?? ?? 57 8D B4 24 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 89 F1 E8 ?? + ?? ?? ?? 57 E8 ?? ?? ?? ?? 58 6A ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 6A } - $enum_resources_2_p4 = { - 8D 79 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CF D1 F9 51 52 8D 4C 24 ?? E8 ?? ?? ?? - ?? 8D 44 24 ?? B9 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 94 34 ?? ?? ?? ?? - 66 83 3A ?? 75 ?? 33 C9 EB ?? 8B CA 8D 79 ?? 0F 1F 44 00 ?? 66 8B 01 83 C1 ?? 66 85 - C0 75 ?? EB ?? 8B 94 34 ?? ?? ?? ?? 66 83 3A ?? 75 ?? 33 C9 EB ?? 8B CA 8D 79 ?? 66 - 8B 01 83 C1 ?? 66 85 C0 75 ?? EB ?? 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? EB ?? 68 ?? - ?? ?? ?? EB ?? 68 ?? ?? ?? ?? EB ?? 8B 94 34 ?? ?? ?? ?? 66 83 3A ?? 75 ?? 33 C9 E9 - ?? ?? ?? ?? 8B CA 8D 79 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? E9 ?? ?? ?? ?? 68 ?? ?? - ?? ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? F6 84 34 ?? ?? ?? ?? ?? 74 ?? 8D - 8C 24 ?? ?? ?? ?? 8D 53 ?? 03 CE E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 45 89 6C 24 ?? 3B - 6C 24 ?? 0F 82 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 33 F6 8B 44 24 ?? 83 F8 ?? - 72 ?? 8B 4C 24 ?? 40 3D ?? ?? ?? ?? 77 ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 75 ?? - 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 ?? 72 ?? 83 F9 ?? 77 ?? 8B C8 51 E8 ?? ?? ?? ?? 83 - C4 ?? 5F 8B C6 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 + $drop_hta_file_p2 = { + 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D B4 24 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 58 + 31 DB 43 53 56 E8 ?? ?? ?? ?? 59 5A 53 50 E8 ?? ?? ?? ?? 59 5A 8D 74 24 ?? 89 C2 89 + F1 57 E8 ?? ?? ?? ?? 58 39 1E 0F 85 ?? ?? ?? ?? F2 0F 10 44 24 ?? A1 ?? ?? ?? ?? 8D + 74 24 ?? F2 0F 11 84 24 ?? ?? ?? ?? 8B 00 83 F8 ?? 72 ?? 68 ?? ?? ?? ?? 8D 84 24 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 89 44 24 ?? 31 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? + 89 54 24 ?? 40 89 84 24 ?? ?? ?? ?? 83 A4 24 ?? ?? ?? ?? ?? 89 B4 24 ?? ?? ?? ?? 89 + 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? EB ?? 8B 44 24 ?? 89 44 24 ?? 68 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 8D 74 24 ?? 56 8D 9C 24 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? + 83 C4 ?? 89 D9 E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 58 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 + 8D BC 24 ?? ?? ?? ?? 89 C3 89 84 24 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 F9 6A ?? E8 ?? ?? + ?? ?? 58 83 64 24 ?? ?? 83 64 24 ?? ?? 57 E8 ?? ?? ?? ?? 59 8D 4C 24 ?? 51 56 6A ?? + 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 53 E8 } condition: - uint16(0)==0x5A4D and ( all of ($encrypt_files_p*)) and ($find_files) and ( all of ($enum_resources_1_p*)) and ( all of ($enum_resources_2_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($drop_hta_file_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Avoslocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Teslarvng : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects AvosLocker ransomware." + description = "Yara rule that detects Teslarvng ransomware." author = "ReversingLabs" - id = "a803283d-6424-5a64-89e6-c73a3322ba1e" - date = "2021-10-22" - modified = "2021-10-22" + id = "7045b13e-95a5-54da-b540-75d464e7673d" + date = "2020-12-14" + modified = "2020-12-14" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.AvosLocker.yara#L1-L108" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "4d81b801a95a54a35989c4a985d92578971568d1412f625bca911d0fa1eee1fe" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Teslarvng.yara#L1-L137" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "670621aa196a80fbb694e4b1690d7da60e881c5b826133939e61cd6c2406ea98" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -41868,97 +41881,127 @@ rule REVERSINGLABS_Win32_Ransomware_Avoslocker : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "AvosLocker" + tc_detection_name = "Teslarvng" tc_detection_factor = 5 importance = 25 strings: + $encrypt_files_p1 = { + 53 8B DC 83 EC ?? 83 E4 ?? 83 C4 ?? 55 8B 6B ?? 89 6C 24 ?? 8B EC 6A ?? 68 ?? ?? ?? + ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? A8 ?? 00 00 A1 ?? ?? ?? ?? ?? ?? ?? ?? EC 56 57 50 + 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? C9 89 4D ?? 89 4D ?? 8B 73 ?? 8B 43 ?? 89 75 + ?? 89 45 ?? 3B F0 0F 84 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 06 8D 04 40 C1 E0 ?? 89 45 + ?? 8B 04 02 8B 40 ?? 8B 30 3B F0 0F 84 ?? ?? ?? ?? A1 ?? ?? ?? ?? ?? ?? ?? ?? 3D ?? + ?? ?? ?? 10 89 ?? ?? ?? ?? E3 ?? 00 0F 43 05 ?? ?? ?? ?? 89 45 ?? C6 45 ?? ?? 33 C0 + 83 C9 ?? 66 89 45 ?? 89 4D ?? 8D 4D ?? 8B 47 ?? 40 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7F ?? ?? 8B + C7 72 ?? 8B 07 FF 77 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? 8D 95 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 C9 68 ?? ?? ?? ?? 0F 10 00 0F 11 85 + ?? ?? ?? ?? F3 0F 7E 40 ?? 83 4D ?? ?? 66 0F D6 45 ?? 66 89 08 8D 8D ?? ?? ?? ?? C7 + 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 85 ?? + ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 6A ?? 0F 43 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? + 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 74 ?? 6A ?? 8D 4D ?? 51 + } + $encrypt_files_p2 = { + FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? + ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 65 ?? ?? C6 45 ?? ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 65 ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? + 8B 41 ?? 89 45 ?? 83 78 ?? ?? 8B 48 ?? 89 4D ?? 72 ?? 8B 00 89 45 ?? C6 45 ?? ?? 33 + C0 83 4D ?? ?? 8D 4D ?? 66 89 45 ?? 8B 47 ?? 40 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? 50 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7F ?? ?? 8B 47 + ?? 72 ?? 8B 3F 50 57 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? + 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 6A ?? 0F 43 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A + ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 74 ?? 6A ?? 8D 45 + ?? 50 FF 75 ?? FF 75 ?? 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? + ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 65 ?? ?? C6 45 ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 45 ?? 8B 36 8B 4D ?? 8B 04 02 3B 70 ?? 0F 85 ?? ?? + ?? ?? 8B 75 ?? 83 C6 ?? 89 75 ?? 3B 75 ?? 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D + 4B ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? + ?? ?? 8B E5 5D 8B E3 5B C2 + } $find_files = { - 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF - B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 - 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 ?? 8A 48 ?? 84 C9 74 ?? 80 F9 - ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 - C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? - ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? 74 ?? - FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 8B D8 56 FF 15 + FF D6 83 F8 ?? 0F 85 ?? ?? ?? ?? 8D 43 ?? 50 BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 83 78 ?? ?? 72 ?? 8B 00 B2 ?? 8B C8 E8 ?? ?? ?? ?? C6 + 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 + ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 0F 1F 40 ?? 8D 85 ?? ?? ?? ?? 50 + FF B5 ?? ?? ?? ?? 33 C9 8B 85 ?? ?? ?? ?? 03 8D ?? ?? ?? ?? 83 D0 ?? 50 51 FF B5 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? + ?? ?? ?? BA ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B C8 90 66 8B 31 66 3B 32 75 ?? 66 85 F6 + 74 ?? 66 8B 71 ?? 66 3B 72 ?? 75 ?? 83 C1 ?? 83 C2 ?? 66 85 F6 75 ?? 33 C9 EB ?? 1B + C9 83 C9 ?? 85 C9 74 ?? B9 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B + 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? + 85 C0 74 ?? 8B 45 ?? 8D 8D ?? ?? ?? ?? 51 3B 45 ?? 74 ?? 8B C8 E8 ?? ?? ?? ?? 83 45 + ?? ?? EB ?? 50 8D 4D ?? E8 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? FF B5 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 C4 ?? 85 F6 0F 85 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? FF D6 83 F8 ?? 0F + 84 ?? ?? ?? ?? FF D6 8B D0 } - $enum_resources = { - 50 51 6A ?? 6A ?? 6A ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 85 FF 0F 84 ?? ?? ?? ?? FF 75 ?? 6A ?? 57 - E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 57 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? 33 DB 39 5D ?? 76 ?? 8D 77 ?? 83 7E ?? ?? 0F 85 ?? ?? ?? ?? 83 7E - ?? ?? 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 85 - ?? ?? ?? ?? 39 46 ?? B9 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? 8B D1 0F 45 56 ?? 8B C1 83 - 7E ?? ?? 0F 11 85 ?? ?? ?? ?? 0F 45 46 ?? 83 3E ?? 0F 28 05 ?? ?? ?? ?? 89 45 ?? 8B - C1 0F 45 06 83 7E ?? ?? 0F 11 45 ?? 89 45 ?? 8B C1 0F 28 05 ?? ?? ?? ?? 0F 45 46 ?? - 33 C9 0F 11 45 ?? 89 45 ?? 0F 28 05 ?? ?? ?? ?? 0F 11 45 ?? 8A 85 ?? ?? ?? ?? 30 84 - 0D ?? ?? ?? ?? 41 83 F9 ?? 72 ?? 52 FF 75 ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? FF 75 ?? - FF 75 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 3E ?? 0F 84 ?? ?? ?? ?? FF 36 E8 ?? ?? ?? ?? - 59 83 F8 ?? 0F 86 ?? ?? ?? ?? 8B 06 80 78 ?? ?? 75 ?? B1 ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? 33 C0 66 C7 45 ?? ?? ?? C6 45 ?? ?? 30 4C 05 ?? 40 83 F8 ?? 73 ?? - 8A 4D ?? EB ?? 8D 45 ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 59 FF 36 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 65 ?? ?? 50 51 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? - C6 45 ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 83 4D ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? EB ?? B1 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? - C6 45 ?? ?? 30 4C 05 ?? 40 83 F8 ?? 73 ?? 8A 4D ?? EB ?? 8D 45 ?? C6 45 ?? ?? 50 E8 - ?? ?? ?? ?? 59 F7 46 ?? ?? ?? ?? ?? 74 ?? 8D 4E ?? E8 ?? ?? ?? ?? 43 83 C6 ?? 3B 5D - ?? 0F 82 ?? ?? ?? ?? E9 ?? ?? ?? ?? FF 75 ?? FF 15 + $enum_shares_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? 00 00 00 A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? 45 FC 00 00 00 00 8D + 75 ?? 83 7D ?? ?? 6A ?? 0F 43 75 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 B8 ?? ?? ?? + ?? 56 66 89 45 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 89 45 ?? FF 15 ?? ?? ?? ?? 66 89 + 45 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 57 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 8D + 45 ?? 50 57 FF 15 ?? ?? ?? ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 45 ?? 89 7D ?? 50 + 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 6A ?? 6A ?? 89 7D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 8E ?? ?? ?? ?? 83 7D ?? ?? 0F 87 ?? ?? ?? ?? + 83 7D ?? ?? 0F 86 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 8B 75 ?? 0F + 43 4D ?? 03 F1 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 0F 43 + 4D ?? 33 C0 66 89 45 ?? 8B C6 2B C1 89 4D ?? 50 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? FF 75 ?? 8D 4D ?? 56 FF 75 ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 83 7D ?? + ?? 8D 45 ?? 6A ?? 0F 43 45 ?? 51 8D 4D ?? 51 6A ?? 8D 4D ?? 51 6A ?? 50 FF 15 ?? ?? + ?? ?? 85 C0 74 ?? 3D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 0F 57 C0 C7 45 ?? ?? ?? ?? ?? 66 } - $import_key = { - 50 53 53 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 50 68 ?? ?? - ?? ?? FF D6 50 53 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? B1 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B C3 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 30 8C 05 ?? ?? - ?? ?? 40 83 F8 ?? 73 ?? 8A 8D ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 88 9D ?? ?? ?? ?? - 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? 59 0F 11 85 ?? ?? ?? ?? - 59 0F 28 05 ?? ?? ?? ?? 8B CB 0F 11 85 ?? ?? ?? ?? 66 C7 85 ?? ?? ?? ?? ?? ?? 88 9D - ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 30 84 0D ?? ?? ?? ?? 41 83 F9 ?? 72 ?? 88 9D ?? ?? ?? - ?? FF D6 50 8D 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? FF 36 8D 45 ?? 89 9D ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? FF 76 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 8D ?? - ?? ?? ?? 83 C4 ?? 8B D7 50 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 84 C0 75 ?? 0F 28 05 ?? ?? ?? ?? 8B CB 0F 11 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 0F 28 05 ?? ?? ?? ?? 0F 11 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 C7 - 85 ?? ?? ?? ?? ?? ?? 88 9D ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 30 84 0D ?? ?? ?? ?? 41 83 - F9 ?? 72 ?? 8D 85 ?? ?? ?? ?? 88 9D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8D 45 ?? 50 E8 - ?? ?? ?? ?? 59 8D 4D ?? 85 C0 74 ?? 88 19 41 83 E8 ?? 75 ?? 39 9D ?? ?? ?? ?? 74 ?? - FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 + $enum_shares_p2 = { + 0F D6 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? + ?? 33 F6 8B 55 ?? 85 D2 0F 84 ?? ?? ?? ?? 33 FF 8B 4D ?? 8B 44 39 ?? 85 C0 74 ?? 3D + ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 14 39 33 C0 66 89 45 ?? 8B C2 C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 48 ?? C7 45 ?? ?? ?? ?? ?? 89 4D ?? 66 + 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B 45 ?? 8D 4D ?? D1 F8 50 52 E8 ?? ?? ?? ?? C6 45 ?? + ?? 8B 45 ?? 3B 45 ?? 74 ?? 0F 10 45 ?? C7 40 ?? ?? ?? ?? ?? 0F 11 00 F3 0F 7E 45 ?? + 66 0F D6 40 ?? 33 C0 83 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 + ?? EB ?? 8D 4D ?? 51 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? + 8B 55 ?? 46 83 C7 ?? 3B F2 0F 82 ?? ?? ?? ?? 8B 45 ?? 8B 75 ?? 3B 45 ?? 0F 84 ?? ?? + ?? ?? FF 76 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 46 ?? 83 7D ?? ?? + 8B 7D ?? 89 45 ?? 8D 45 ?? 0F 43 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? 89 45 ?? 83 FF ?? 73 ?? 0F 10 00 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 11 + 85 ?? ?? ?? ?? EB ?? 8B F7 8D 8D ?? ?? ?? ?? B8 ?? ?? ?? ?? 83 CE ?? 3B F0 0F 47 F0 } - $encrypt_files = { - 50 51 51 FF B5 ?? ?? ?? ?? 51 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? - ?? ?? 8B BD ?? ?? ?? ?? 57 89 BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 59 85 F6 0F 84 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CE 85 C0 74 ?? C6 01 ?? 41 83 E8 ?? 75 ?? 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 59 83 C0 ?? 74 ?? 39 85 ?? ?? ?? ?? 72 ?? 50 8D 85 ?? ?? ?? - ?? 50 56 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? FF B5 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 - C4 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 59 57 40 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 6A ?? FF B5 ?? ?? ?? ?? 6A - ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? D1 EF 6A ?? 5A 74 ?? - 8B 9D ?? ?? ?? ?? 4B 03 DE 8A 03 8A 0C 32 88 04 32 42 88 0B 4B 3B D7 72 ?? 8B 9D ?? - ?? ?? ?? 8B BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 03 C3 56 50 E8 ?? ?? ?? ?? 03 DF 56 - 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? - ?? 47 81 C6 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 50 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 - B9 ?? ?? ?? ?? F7 F1 83 C4 ?? 40 3B F8 0F 82 + $enum_shares_p3 = { + 8D 46 ?? 50 E8 ?? ?? ?? ?? 8D 0C 7D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 51 FF 75 ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 89 B5 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 8B 7D + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? + 3B F8 0F 84 ?? ?? ?? ?? 2B C7 C1 F8 ?? 69 F0 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 89 85 ?? + ?? ?? ?? 8D 0C 76 89 45 ?? 8D 04 C8 89 45 ?? 8D 85 ?? ?? ?? ?? 89 45 ?? C6 45 ?? ?? + 0F 57 C0 8B B5 ?? ?? ?? ?? 66 0F D6 45 ?? C7 45 ?? ?? ?? ?? ?? 89 75 ?? 89 75 ?? 89 + 45 ?? C6 45 ?? ?? 66 90 57 8B CE E8 ?? ?? ?? ?? 83 C6 ?? 83 C7 ?? 89 75 ?? 3B 7D ?? + 75 ?? 89 75 ?? C6 45 ?? ?? 89 75 ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8D + 85 ?? ?? ?? ?? 8B 4D ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 75 ?? FF 76 ?? E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? EB ?? + 8B 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 06 F0 FF 08 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? EB ?? 57 FF 15 ?? ?? ?? ?? 8B 75 } condition: - uint16(0)==0x5A4D and ($enum_resources) and ($find_files) and ($import_key) and ($encrypt_files) + uint16(0)==0x5A4D and ( all of ($enum_shares_p*)) and ($find_files) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Nanolocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Badblock : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects NanoLocker ransomware." + description = "Yara rule that detects BadBlock ransomware." author = "ReversingLabs" - id = "a31dad2e-2738-527b-a6e9-322757e2ec30" + id = "a5afb7d6-4bc1-5465-a35d-fe40e7f11c3e" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.NanoLocker.yara#L1-L79" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "7fdb021f22d97bf8a00fd856ef913695a0d6fbaad1138b5a5cc2cc8768b130be" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.BadBlock.yara#L1-L100" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "421e6a3772eeec6ef0cbb2427b7e044b450a2b2146cee2ca7d8c3a3a92918557" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -41966,79 +42009,97 @@ rule REVERSINGLABS_Win32_Ransomware_Nanolocker : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "NanoLocker" + tc_detection_name = "BadBlock" tc_detection_factor = 5 importance = 25 strings: - $encrypt_file_1 = { - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? E8 - ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 05 ?? ?? ?? ?? ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 - 05 ?? ?? ?? ?? ?? 8D 3D ?? ?? ?? ?? 33 C9 C6 07 ?? 47 41 81 F9 ?? ?? ?? ?? 75 ?? C7 - 05 ?? ?? ?? ?? ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 0F 84 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 6A - ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 6A - ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? - ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 0F 84 ?? ?? ?? ?? 81 3D - ?? ?? ?? ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? 56 E8 - ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 56 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 03 F0 46 8A 06 3C ?? 0F 85 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 - } - $encrypt_file_2 = { - A3 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 - ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 81 3D ?? ?? ?? ?? - ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 6A ?? - E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? - ?? ?? ?? 2D ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? A3 ?? - ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 6A ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? - ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? - ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 35 ?? - ?? ?? ?? E8 - } - $remote_server_1 = { - E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? ?? - ?? ?? 83 F8 ?? 72 ?? C6 05 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF - 35 ?? ?? ?? ?? E8 + $encrypt_files = { + 55 8B EC 83 C4 ?? 53 56 57 33 DB 89 5D ?? 89 5D ?? 89 5D ?? 89 4D ?? 89 55 ?? 8B D8 + 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? 8B 45 ?? + 8B 40 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C3 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 55 + ?? 8B 45 ?? 8B 40 ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 + ?? B2 ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D + 45 ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? + ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B D0 8B 45 ?? 85 C0 74 ?? 83 E8 ?? 8B 00 6A ?? 50 52 + 8B 45 ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 8B 45 ?? 50 + E8 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 + 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 10 FF 12 89 45 ?? 89 55 ?? E9 ?? ?? + ?? ?? 83 7D ?? ?? 75 ?? 81 7D ?? ?? ?? ?? ?? 73 ?? EB ?? 7D ?? 8B 45 ?? 89 45 ?? 8B + 45 ?? 89 45 ?? EB ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B D8 8B C3 + E8 ?? ?? ?? ?? 8B F0 8B D6 8B CB 8B 45 ?? 8B 38 FF 57 ?? 89 45 ?? 8B 45 ?? 8B 10 FF + 12 52 50 8B 45 ?? E8 ?? ?? ?? ?? 3B 54 24 ?? 75 ?? 3B 04 24 5A 58 72 ?? EB ?? 5A 58 + 7C ?? 8B 45 ?? 50 8D 45 ?? 50 56 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? EB ?? + 8B 45 ?? 50 8D 45 ?? 50 56 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? E8 + ?? ?? ?? ?? 52 50 8B C3 99 29 04 24 19 54 24 ?? 58 5A 52 50 8B 45 ?? E8 ?? ?? ?? ?? + 8B D6 8B 4D ?? 8B 45 ?? 8B 38 FF 57 ?? 8B C3 99 29 45 ?? 19 55 ?? 8B D3 8B C6 E8 ?? + ?? ?? ?? 83 7D ?? ?? 75 ?? 83 7D ?? ?? 0F 87 ?? ?? ?? ?? EB ?? 0F 8F ?? ?? ?? ?? A1 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B + 48 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? A1 ?? ?? ?? ?? 8B 00 8B 80 ?? + ?? ?? ?? 8B 80 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 18 FF 53 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 + C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB + ?? E8 ?? ?? ?? ?? EB ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? + ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? + EB ?? 5F 5E 5B 8B E5 5D C3 } - $remote_server_2 = { - E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? A3 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? 68 ?? - ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 + $search_files = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D + ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 55 ?? 89 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 + 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B + 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 0F 94 C3 E9 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 66 83 38 ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? A1 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? A1 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 85 C0 75 ?? 8B 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 85 ?? + ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 0D ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 66 + 83 38 ?? 74 ?? B9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 + 75 ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? + 8B C6 8B 08 FF 51 ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 94 C3 84 DB 0F 85 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C6 8B 10 FF 52 ?? 8B D8 4B 85 DB 7C ?? + 43 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C6 8B 38 FF + 57 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? E8 ?? ?? ?? ?? FF 85 ?? ?? ?? ?? 4B 75 ?? 8B C6 E8 ?? ?? ?? ?? 33 C0 5A 59 59 + 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 } - $enum_shares_and_encrypt_files = { - E8 ?? ?? ?? ?? C1 C8 ?? BA ?? ?? ?? ?? 23 D0 60 83 FA ?? 75 ?? 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 F8 ?? 76 ?? 83 F8 ?? 74 ?? 8D 35 ?? ?? ?? ?? 60 68 ?? ?? ?? ?? 56 68 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 61 8A 06 46 0A C0 75 ?? 8A 06 0A C0 75 ?? 61 D1 C8 8A 1D ?? - ?? ?? ?? FE C3 88 1D ?? ?? ?? ?? 80 FB ?? 76 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 35 ?? ?? - ?? ?? E8 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? - FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 + $remote_connection = { + A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? + 8D 4D ?? 8B 45 ?? 8B 90 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8B 08 FF + 51 ?? 8B 45 ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? + 05 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 + 89 20 6A ?? 8D 45 ?? 50 8D 4D ?? 8B 15 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? + 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? + 8B 45 ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 + 74 ?? C7 45 ?? ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 83 EB ?? 8B 1B 68 ?? ?? ?? ?? 8B CB + BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? + 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 8B 90 ?? ?? ?? ?? 8D 45 + ?? 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? B2 ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 8B 45 + ?? 8B 90 ?? ?? ?? ?? 8D 45 ?? 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 8B 75 ?? 85 F6 74 ?? 83 EE ?? 8B 36 68 ?? ?? ?? ?? 8B CE BA ?? ?? ?? ?? 8B 45 ?? + E8 ?? ?? ?? ?? 33 C0 A3 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 + 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and $encrypt_file_1 and $encrypt_file_2 and $remote_server_1 and $remote_server_2 and $enum_shares_and_encrypt_files + uint16(0)==0x5A4D and ($search_files and $encrypt_files and $remote_connection) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Khonsari : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Juicylemon : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Khonsari ransomware." + description = "Yara rule that detects JuicyLemon ransomware." author = "ReversingLabs" - id = "c3c64256-af1f-5a9d-8a59-8d72993bb8da" - date = "2022-01-27" - modified = "2022-01-27" + id = "35e4bbd6-422b-562e-98fc-fe932270dbb8" + date = "2020-08-17" + modified = "2020-08-17" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Khonsari.yara#L1-L68" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "f1003b7863215bcd8e5cdce8ce40551105fb668ea2b8ac765909f9fa5373e6ca" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.JuicyLemon.yara#L1-L116" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "596d89843793307f4940dbb85b2e7081f02250f6adfdcd01f2d3c5f2b8b90875" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -42046,61 +42107,118 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Khonsari : TC_DETECTION MALICIOUS MA sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Khonsari" + tc_detection_name = "JuicyLemon" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 73 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? - 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 0B - 16 0C 2B ?? 07 08 9A 0D 09 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 72 ?? - ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 09 - 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 08 17 58 0C 08 07 8E 69 32 ?? 06 1B 28 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 06 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 06 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 - ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 06 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 2D ?? 00 11 - ?? 7E ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 11 ?? 72 ?? - ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F - ?? ?? ?? ?? DC DE ?? 26 DE ?? 12 ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE 16 ?? - ?? ?? ?? 6F ?? ?? ?? ?? DC 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? - 28 ?? ?? ?? ?? 26 2A + $remote_connection_1 = { + 55 8B EC 83 C4 ?? 53 56 57 89 4D ?? 8B FA 8B F0 C6 45 ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? + 6A ?? FF 15 ?? ?? ?? ?? 8B D8 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 57 56 53 FF 15 ?? ?? ?? + ?? 8B F0 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 56 FF 15 + ?? ?? ?? ?? 8B F8 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 6A ?? 68 ?? ?? ?? ?? 57 FF + 15 ?? ?? ?? ?? 85 C0 74 ?? C6 45 ?? ?? 57 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 53 + FF 15 ?? ?? ?? ?? 8A 45 ?? 5F 5E 5B 59 59 5D C2 } - $get_key = { - 73 ?? ?? ?? ?? 0A 06 12 ?? FE 15 ?? ?? ?? ?? 12 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 - ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7D - ?? ?? ?? ?? 12 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 72 ?? - ?? ?? ?? 13 ?? 11 ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 07 6F ?? - ?? ?? ?? 06 02 7B ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 11 - ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 06 02 7B ?? ?? ?? ?? 17 6F ?? - ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? DC 08 2A + $remote_connection_2 = { + 55 8B EC 33 C9 51 51 51 51 51 51 51 53 56 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? + 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 DB 8D 55 ?? 8B + 45 ?? E8 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? + ?? 66 BE ?? ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? 66 BE ?? ?? 8D 45 ?? E8 + ?? ?? ?? ?? 50 8D 45 ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 50 8D 45 ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B D6 + 59 E8 ?? ?? ?? ?? 84 C0 74 ?? B3 ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 } - $encrypt_files = { - 28 ?? ?? ?? ?? 0A 06 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 61 13 ?? 11 ?? 6F ?? ?? ?? ?? 06 20 - ?? ?? ?? ?? 20 ?? ?? ?? ?? 61 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 13 ?? 11 ?? 6F ?? ?? - ?? ?? 06 19 6F ?? ?? ?? ?? 06 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 02 7B ?? ?? ?? ?? 6F - ?? ?? ?? ?? 06 06 6F ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 02 03 07 28 ?? ?? - ?? ?? 0C DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC 06 2C ?? 06 6F ?? ?? ?? ?? DC 08 2A + $find_files_and_encrypt = { + E8 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 14 B2 E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 88 45 ?? 46 4B 75 ?? A1 ?? ?? ?? ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 75 ?? 80 7D ?? ?? 75 ?? 8B 5D ?? 4B 85 DB 7C ?? 43 33 F6 8D 85 + ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 14 B2 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 55 ?? E8 + ?? ?? ?? ?? 46 4B 75 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? 5A E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 + A1 ?? ?? ?? ?? 8B 00 FF D0 8B 1D ?? ?? ?? ?? 57 A1 ?? ?? ?? ?? 8B 00 FF D0 85 DB 74 + ?? 6A ?? A1 ?? ?? ?? ?? 8B 00 FF D0 EB ?? B3 ?? 8D 85 ?? ?? ?? ?? 8B D3 80 C2 ?? E8 + ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 8B 00 FF + D0 83 F8 ?? 76 ?? 83 F8 ?? 74 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8D 85 ?? + ?? ?? ?? 8B D3 80 C2 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 95 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 57 A1 ?? ?? ?? ?? 8B 00 FF D0 FF 05 ?? + ?? ?? ?? 57 A1 ?? ?? ?? ?? 8B 00 FF D0 8D 46 ?? 50 6A ?? 56 68 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 6A ?? A1 ?? ?? ?? ?? 8B 00 FF D0 4B 80 FB ?? 0F 85 ?? ?? ?? ?? 57 A1 ?? ?? ?? + ?? 8B 00 FF D0 8B 1D ?? ?? ?? ?? 57 A1 ?? ?? ?? ?? 8B 00 FF D0 85 DB 74 ?? 6A ?? A1 + ?? ?? ?? ?? 8B 00 FF D0 EB ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8D 46 ?? BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 A1 ?? ?? ?? ?? 8B 00 FF D0 FF 05 ?? ?? ?? ?? 57 A1 ?? + ?? ?? ?? 8B 00 FF D0 8D 46 ?? 50 6A ?? 56 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? A1 ?? + ?? ?? ?? 8B 00 FF D0 57 A1 ?? ?? ?? ?? 8B 00 FF D0 8B 1D ?? ?? ?? ?? 57 A1 ?? ?? ?? + ?? 8B 00 FF D0 85 DB 74 ?? 6A ?? A1 ?? ?? ?? ?? 8B 00 FF D0 EB ?? A1 ?? ?? ?? ?? BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 52 50 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? 50 B8 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 5A 59 E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? + ?? ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 89 45 ?? C6 45 ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? 8B + 5D ?? 4B 85 DB 7C ?? 43 33 F6 80 7D ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? + 8B 14 B2 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? + ?? ?? 8B 15 ?? ?? ?? ?? 8B 14 B2 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? + ?? ?? 88 45 ?? 46 4B 75 ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? 80 7D + ?? ?? 75 ?? 8B 5D ?? 4B 85 DB 7C ?? 43 33 F6 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B + 14 B2 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 46 4B 75 ?? BA ?? ?? + ?? ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B C8 B8 ?? ?? ?? ?? 5A E8 ?? ?? ?? ?? BA ?? ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B D0 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 + 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C8 B8 ?? ?? ?? + ?? 5A E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 8B D3 B8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? FF 35 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 50 8B D3 B8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8B D3 B8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? A1 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? + E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? A1 ?? ?? ?? ?? E8 + ?? ?? ?? ?? B2 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? + A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 + ?? ?? ?? ?? 75 ?? E8 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and ($find_files) and ($get_key) and ($encrypt_files) + uint16(0)==0x5A4D and $find_files_and_encrypt and $remote_connection_1 and $remote_connection_2 } -rule REVERSINGLABS_Win32_Ransomware_Marsjoke : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Motocos : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects MarsJoke ransomware." + description = "Yara rule that detects Motocos ransomware." author = "ReversingLabs" - id = "8164c586-f548-5414-9df8-61e0c51cbe29" - date = "2020-07-15" - modified = "2020-07-15" + id = "cda44b86-c747-5b48-acd8-e68311ab24a3" + date = "2021-09-17" + modified = "2021-09-17" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.MarsJoke.yara#L1-L157" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "298b2fd99793a15b3537853289e1337648d3fa84f12038e6f6831741404b7c5c" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Motocos.yara#L1-L75" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "34b99847f029a291808f08ba6e6ae62a54e6fed5acc928fe4828054801786881" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -42108,159 +42226,68 @@ rule REVERSINGLABS_Win32_Ransomware_Marsjoke : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "MarsJoke" + tc_detection_name = "Motocos" tc_detection_factor = 5 importance = 25 strings: - $search_and_encrypt_files = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 8B 45 - ?? 53 56 89 44 24 ?? 8B 45 ?? 57 89 44 24 ?? 8B 45 ?? BE ?? ?? ?? ?? 33 DB 56 89 44 - 24 ?? 8D 84 24 ?? ?? ?? ?? 8B F9 53 50 89 7C 24 ?? 66 89 9C 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? 56 8D 84 24 ?? ?? ?? ?? 53 50 66 89 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 57 8D 4C 24 ?? 88 5C 24 ?? E8 ?? - ?? ?? ?? 83 C4 ?? 84 C0 0F 85 ?? ?? ?? ?? 38 5C 24 ?? 0F 85 ?? ?? ?? ?? 8D 84 24 ?? - ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 59 59 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 - 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 59 59 BE ?? ?? ?? - ?? 56 8D 84 24 ?? ?? ?? ?? 50 FF D7 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 56 FF - 74 24 ?? FF D7 FF 74 24 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 - ?? 84 C0 8D 84 24 ?? ?? ?? ?? 75 ?? 50 FF 15 ?? ?? ?? ?? FF 74 24 ?? E9 ?? ?? ?? ?? - 6A ?? 50 FF D7 53 68 ?? ?? ?? ?? 6A ?? 53 6A ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 89 44 24 ?? 75 ?? 56 8D 84 24 ?? ?? ?? ?? 50 FF D7 8D - 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 E9 ?? ?? ?? ?? 8D 4C - 24 ?? 51 50 FF 15 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? FF 74 24 ?? FF 74 24 ?? E8 ?? ?? ?? - ?? 89 5C 24 ?? 33 DB 68 ?? ?? ?? ?? 89 44 24 ?? 8D 84 24 ?? ?? ?? ?? 53 50 89 54 24 - ?? 89 4C 24 ?? 66 89 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? FF 74 24 ?? 8D 84 24 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 - 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 56 8D 84 24 ?? ?? ?? ?? 50 FF - D7 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 53 56 6A ?? 53 6A ?? 68 ?? ?? ?? ?? 8D - 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 89 44 24 ?? 75 ?? 56 8D 84 24 ?? ?? - ?? ?? 50 FF D7 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? E9 ?? - ?? ?? ?? 6A ?? 59 33 C0 66 89 9C 24 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? F3 AB 6A ?? FF - 74 24 ?? 66 AB 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 8D 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BF ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? - ?? 57 53 50 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 0B 44 24 ?? 74 ?? 83 44 - 24 ?? ?? 11 5C 24 ?? EB ?? 89 7C 24 ?? 89 5C 24 ?? BF ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? - 59 50 57 8B 7C 24 ?? 57 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 89 47 ?? 8B 44 24 ?? 53 - 89 47 ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? 57 FF 74 24 ?? C7 47 ?? ?? ?? ?? ?? 88 5C 24 - ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? C6 44 24 ?? ?? E9 ?? ?? ?? ?? 8B 7C 24 ?? 3B FB 89 - 5C 24 ?? 0F 8C ?? ?? ?? ?? 7F ?? 39 5C 24 ?? 0F 86 ?? ?? ?? ?? 8B 74 24 ?? 83 EE ?? - 1B FB 89 74 24 ?? 89 7C 24 ?? 89 5C 24 ?? 33 C0 EB ?? 8B 7C 24 ?? 8B 74 24 ?? 39 74 - 24 ?? 75 ?? 3B C7 75 ?? 8B 44 24 ?? 89 44 24 ?? EB ?? C7 44 24 ?? ?? ?? ?? ?? 68 ?? - ?? ?? ?? 53 FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 8D 44 24 ?? 50 FF 74 24 ?? FF 74 - 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 6A ?? 58 39 44 24 ?? 73 ?? 89 44 24 ?? 39 74 24 - ?? 75 ?? 33 C0 3B C7 75 ?? 39 5C 24 ?? 7C ?? 7F ?? 83 7C 24 ?? ?? 76 ?? 8B 44 24 ?? - 83 E0 ?? 74 ?? 8B 4C 24 ?? 2B C8 03 C9 89 4C 24 ?? 6A ?? 68 ?? ?? ?? ?? FF 74 24 ?? - 53 FF 15 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 - ?? 50 81 EC ?? ?? ?? ?? 6A ?? 59 8B FC FF B4 24 ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? FF - B4 24 ?? ?? ?? ?? F3 A5 8B B4 24 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? - 53 8D 44 24 ?? 50 FF 74 24 ?? 56 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 68 ?? ?? ?? ?? - 53 56 74 ?? FF 15 ?? ?? ?? ?? FF 44 24 ?? 8B 44 24 ?? 89 44 24 ?? 33 C0 3B 44 24 ?? - 0F 8C ?? ?? ?? ?? 7F ?? 8B 4C 24 ?? 3B 4C 24 ?? 0F 82 ?? ?? ?? ?? EB ?? C6 44 24 ?? - ?? FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 74 24 ?? FF 15 ?? ?? ?? ?? - FF 74 24 ?? 8B 3D ?? ?? ?? ?? FF D7 FF 74 24 ?? FF D7 56 8D 84 24 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 38 5C 24 ?? 8D 84 24 - ?? ?? ?? ?? 75 ?? 6A ?? FF 74 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 FF 74 24 ?? 68 ?? ?? - ?? ?? 75 ?? E8 ?? ?? ?? ?? 59 59 8D 84 24 ?? ?? ?? ?? 50 FF D6 EB ?? E8 ?? ?? ?? ?? - 59 59 B0 ?? EB ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 32 C0 8B 8C 24 ?? ?? ?? ?? - 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + $generate_key = { + 55 8B EC 83 C4 ?? 53 89 4D ?? 89 55 ?? 8B D8 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? + ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 83 7D ?? ?? 74 ?? 8B 45 ?? 8B 15 + ?? ?? ?? ?? 8B 12 E8 ?? ?? ?? ?? 75 ?? B9 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 89 45 ?? 33 D2 55 68 ?? ?? + ?? ?? 64 FF 32 64 89 22 8B 4D ?? 8B 55 ?? 8B C3 E8 ?? ?? ?? ?? 89 45 ?? 33 D2 55 68 + ?? ?? ?? ?? 64 FF 32 64 89 22 8B 45 ?? 85 C0 74 ?? 83 E8 ?? 8B 00 8B D8 89 5D ?? 80 + 7D ?? ?? 75 ?? 8B 5D ?? 03 DB 53 8D 45 ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? 53 8D 45 ?? 50 8B 45 ?? 50 6A ?? 80 7D ?? ?? F5 1B C0 50 6A ?? 8B 45 + ?? 50 E8 ?? ?? ?? ?? 83 F8 ?? 1B C0 40 84 C0 75 ?? B9 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? + ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 50 8D 45 ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 8B 55 ?? 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 + 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? + 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? C3 E9 ?? ?? + ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? + 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5B 8B E5 5D C2 } - $remote_connection_2 = { - 55 8D 6C 24 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? - 53 56 57 BE ?? ?? ?? ?? 56 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 04 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 56 89 BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 83 A5 ?? - ?? ?? ?? ?? 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? - ?? BE ?? ?? ?? ?? 56 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 FF B5 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? - E8 ?? ?? ?? ?? 6A ?? 6A ?? 8B C3 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? - ?? 57 E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A - ?? 8D 5D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? - ?? ?? 56 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 83 A5 ?? ?? ?? ?? ?? BF ?? ?? ?? ?? 57 - 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? - 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 66 83 A5 ?? ?? ?? ?? ?? 57 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? - ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A - ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 8D 85 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B C3 - 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 50 - E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 59 59 5F 5E 5B 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 59 83 BD ?? ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B 4D ?? 8B 85 ?? - ?? ?? ?? 33 CD E8 ?? ?? ?? ?? 83 C5 ?? C9 C3 + $encrypt_files = { + 55 8B EC 83 C4 ?? 53 56 57 33 C9 89 4D ?? 89 4D ?? 89 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? + 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 C6 45 ?? ?? 33 D2 55 68 ?? ?? ?? ?? 64 FF + 32 64 89 22 B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B D8 8B C3 8B D8 F6 C3 ?? 74 ?? 66 83 E3 ?? B2 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B C3 + E8 ?? ?? ?? ?? 8B D0 B1 ?? 8B 45 ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8B 4D ?? B2 ?? A1 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 D2 + 55 68 ?? ?? ?? ?? 64 FF 32 64 89 22 8B 45 ?? 8B 10 FF 12 8B C8 8B 55 ?? A1 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B C8 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 88 45 ?? 33 C0 5A 59 59 64 + 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? + ?? EB ?? 80 7D ?? ?? 75 ?? 8D 45 ?? 50 8B 45 ?? 89 45 ?? C6 45 ?? ?? B8 ?? ?? ?? ?? + 89 45 ?? C6 45 ?? ?? 8D 55 ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? + E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 F8 ?? 1B C0 40 88 45 + ?? 33 C0 5A 59 59 64 89 10 E9 ?? ?? ?? ?? E9 } - $remote_connection_1 = { - 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 8D 85 - ?? ?? ?? ?? 50 8B F9 8B F2 68 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 33 DB 53 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 89 85 ?? ?? ?? ?? 66 C7 85 - ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 - 88 1F 50 88 1E 66 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D - 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 38 9D ?? ?? ?? - ?? 59 59 75 ?? 68 ?? ?? ?? ?? C6 07 ?? E8 ?? ?? ?? ?? 59 E9 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 59 89 85 ?? ?? ?? ?? 33 F6 BB ?? ?? ?? ?? - 56 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 FF B5 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 56 53 E8 ?? ?? ?? ?? FF 85 ?? ?? ?? ?? - 46 83 FE ?? 59 59 7C ?? EB ?? 53 E8 ?? ?? ?? ?? 59 83 BD ?? ?? ?? ?? ?? 7C ?? C6 07 - ?? 53 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 F6 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 50 66 - 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 59 56 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 50 FF - B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 56 68 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 3B C6 0F 8E ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 89 B5 ?? ?? ?? ?? 0F 84 ?? - ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 83 8D ?? ?? ?? ?? ?? 56 E8 ?? ?? - ?? ?? 59 50 56 8D B5 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 8B C8 85 C9 - 89 8D ?? ?? ?? ?? 7D ?? C6 07 ?? 51 E9 ?? ?? ?? ?? 83 F9 ?? 0F 8C ?? ?? ?? ?? 83 BD - ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 66 83 A5 ?? ?? ?? ?? ?? 33 C0 8D BD ?? ?? ?? ?? 66 - AB 40 3B C8 89 85 ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? 8D 47 ?? E8 ?? ?? ?? ?? 85 C0 59 59 0F 85 ?? ?? ?? ?? 8B 77 ?? 2B 37 - 8D 46 ?? 50 E8 ?? ?? ?? ?? 59 56 6A ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 07 8B - 8D ?? ?? ?? ?? 83 C4 ?? 03 C8 51 8B 4F ?? 2B C8 51 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 59 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 59 40 50 E8 - ?? ?? ?? ?? 59 FF B5 ?? ?? ?? ?? 8B F0 6A ?? 56 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? FF B5 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 56 53 C6 04 06 ?? - E8 ?? ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 83 8D ?? ?? ?? ?? ?? 56 E8 - ?? ?? ?? ?? 83 C4 ?? 50 56 8D B5 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 - 3B C6 59 59 0F 8C ?? ?? ?? ?? 83 F8 ?? 0F 8C ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 85 - ?? ?? ?? ?? 83 F8 ?? 7E ?? 48 8D B5 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 85 C0 59 59 75 ?? 8B 06 8B 8D ?? ?? ?? ?? 03 - C8 51 8B 4E ?? 2B C8 51 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 83 C6 ?? FF 8D ?? ?? ?? ?? 75 ?? 33 F6 39 B5 ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 59 39 B5 ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 39 B5 ?? - ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 83 C7 ?? 3B 85 ?? ?? ?? ?? 0F 8C ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 85 C0 59 59 0F 85 ?? ?? ?? ?? 39 85 ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 59 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 59 59 B0 ?? E9 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 50 53 C6 - 01 ?? E8 ?? ?? ?? ?? 59 39 B5 ?? ?? ?? ?? 59 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 59 39 B5 ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 39 B5 ?? ?? ?? ?? 74 - ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? 53 C6 00 ?? E8 ?? ?? ?? - ?? EB ?? 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C6 00 ?? EB ?? 0F - 84 ?? ?? ?? ?? C6 07 ?? FF 15 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 59 59 83 BD ?? ?? ?? - ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 32 C0 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 + $find_files = { + 55 8B EC 83 C4 ?? 53 56 57 33 C9 89 4D ?? 8B FA 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 + FF 30 64 89 20 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 85 DB 7C ?? 8B 45 ?? 66 + 83 3C 58 ?? 75 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? E8 ?? ?? ?? ?? + 8B 75 ?? 85 F6 74 ?? 83 EE ?? 8B 36 8D 45 ?? 50 8D 53 ?? 8B CE 8B 45 ?? E8 ?? ?? ?? + ?? 8B C7 8B 55 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 + ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8B C7 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 + ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 59 59 5D C3 } condition: - uint16(0)==0x5A4D and $search_and_encrypt_files and $remote_connection_1 and $remote_connection_2 + uint16(0)==0x5A4D and ($generate_key) and ($find_files) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Babuk : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Cryptojoker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Babuk ransomware." + description = "Yara rule that detects CryptoJoker ransomware." author = "ReversingLabs" - id = "8a96f400-193f-5fd1-ba03-4da464345e1c" - date = "2021-01-26" - modified = "2021-01-26" + id = "50a9280b-a352-5a2b-acee-5690e509dfd7" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Babuk.yara#L1-L117" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "70327b3f9d0b0505ade7ee6de6d7facf56820c7e8477bd172f738f374311144f" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.CryptoJoker.yara#L1-L140" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "42ee1e63ada1ae986f43a1300eda0b1fa7b54c26be31ef5637bb321defffbe40" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -42268,108 +42295,136 @@ rule REVERSINGLABS_Win32_Ransomware_Babuk : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Babuk" + tc_detection_name = "CryptoJoker" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 50 8B - 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? - 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 95 ?? - ?? ?? ?? 83 C2 ?? 89 95 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 73 ?? 8B 85 ?? ?? ?? ?? 8B - 0C 85 ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? E9 ?? ?? ?? - ?? E9 ?? ?? ?? ?? EB ?? 8B 45 ?? 50 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? - 51 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 E2 ?? 74 ?? 83 7D ?? ?? 77 ?? 8B 45 ?? 83 - C0 ?? 50 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? EB ?? 8B 8D ?? ?? ?? ?? 83 E9 ?? 89 8D ?? ?? ?? ?? 83 BD ?? - ?? ?? ?? ?? 7C ?? 8B 95 ?? ?? ?? ?? 0F B7 84 55 ?? ?? ?? ?? 83 F8 ?? 75 ?? 68 ?? ?? - ?? ?? 8B 8D ?? ?? ?? ?? 8D 94 4D ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? EB ?? - EB ?? EB ?? EB ?? EB ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? - ?? 51 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 50 FF 15 + $call_encrypt = { + 2B 02 26 16 FE 09 00 00 FE 09 01 00 FE 09 02 00 6F ?? ?? ?? ?? 2A } - $encrypt_files_p1 = { - 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A - ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD - ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 - ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 8C ?? ?? - ?? ?? 7F ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B - 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 52 50 E8 ?? ?? ?? - ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 0F 57 C0 66 0F 13 85 ?? ?? ?? ?? EB ?? 8B 8D - ?? ?? ?? ?? 83 C1 ?? 8B 95 ?? ?? ?? ?? 83 D2 ?? 89 8D ?? ?? ?? ?? 89 95 ?? ?? ?? ?? - 83 BD ?? ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 7C ?? 83 BD ?? ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 + $encrypt_files = { + 2B 02 26 16 20 04 ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 26 20 00 04 ?? ?? 73 ?? ?? ?? ?? 0C 20 05 ?? ?? ?? + 16 39 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 0B 38 ?? ?? ?? ?? 20 04 ?? ?? ?? FE ?? ?? ?? FE ?? ?? + ?? 45 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 38 ?? ?? ?? ?? 26 + 20 03 ?? ?? ?? 16 39 ?? ?? ?? ?? 26 00 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? + ?? ?? ?? 26 20 00 ?? ?? ?? 38 ?? ?? ?? ?? 00 00 08 06 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? + ?? ?? 26 20 03 ?? ?? ?? 38 ?? ?? ?? ?? 09 28 ?? ?? ?? ?? 13 04 20 04 ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? + 26 00 08 07 17 28 ?? ?? ?? ?? 0D 38 ?? ?? ?? ?? 20 03 ?? ?? ?? FE ?? ?? ?? FE ?? ?? ?? 45 ?? ?? ?? ?? ?? ?? + ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 38 ?? ?? ?? ?? 26 20 02 ?? ?? ?? 38 ?? ?? ?? ?? 11 04 + 13 05 DD ?? ?? ?? ?? 00 08 16 28 ?? ?? ?? ?? 00 00 DC 08 14 FE 01 13 06 11 06 3A ?? ?? ?? ?? 08 28 ?? ?? ?? + ?? 00 DC 00 11 05 2A } - $encrypt_files_p2 = { - E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 68 - ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? - 51 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 52 - FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 8C ?? ?? ?? - ?? 7F ?? 83 BD ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 - ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? - ?? ?? 74 ?? 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 68 ?? ?? - ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? - ?? ?? 50 8B 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + $start_process = { + 2B ?? 26 16 20 10 ?? ?? ?? 38 ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 20 ?? ?? ?? ?? + 38 ?? ?? ?? ?? 00 11 05 17 28 ?? ?? ?? ?? 20 06 ?? ?? ?? 38 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? + 0A 20 09 ?? ?? ?? 38 ?? ?? ?? ?? 00 11 05 08 28 ?? ?? ?? ?? 20 12 ?? ?? ?? 38 ?? ?? ?? ?? + 11 06 17 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 + ?? ?? ?? ?? 11 05 17 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 38 ?? ?? ?? ?? 11 06 19 20 ?? ?? ?? ?? + 28 ?? ?? ?? ?? A2 20 0F ?? ?? ?? 38 ?? ?? ?? ?? 1A 8D ?? ?? ?? ?? 13 06 20 02 ?? ?? ?? 38 + ?? ?? ?? ?? 00 11 04 28 ?? ?? ?? ?? 26 20 13 ?? ?? ?? 38 ?? ?? ?? ?? 08 09 28 ?? ?? ?? ?? + 20 07 ?? ?? ?? 38 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 05 38 ?? ?? ?? ?? 26 20 0D ?? ?? ?? 38 ?? + ?? ?? ?? 11 06 0D 38 ?? ?? ?? ?? 20 10 ?? ?? ?? FE ?? ?? ?? FE ?? ?? ?? 45 ?? ?? ?? ?? ?? + ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? + ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? + ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 20 08 ?? ?? ?? 17 3A ?? ?? ?? ?? + 26 11 06 18 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 20 00 ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? + 26 06 07 28 ?? ?? ?? ?? 0C 20 0B ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 26 11 06 16 20 ?? + ?? ?? ?? 28 ?? ?? ?? ?? A2 17 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 26 20 03 ?? ?? ?? 16 39 ?? ?? + ?? ?? 26 00 11 04 11 05 28 ?? ?? ?? ?? 20 0A ?? ?? ?? 17 3A ?? ?? ?? ?? 26 00 73 ?? ?? ?? + ?? 13 04 20 04 ?? ?? ?? 38 ?? ?? ?? ?? 2A } - $encrypt_files_p3 = { - C4 ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 68 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 8B 45 - ?? 50 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF - 15 ?? ?? ?? ?? 6A ?? 8B 85 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? - ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? 6A ?? 6A ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 51 6A ?? 8D 95 ?? ?? ?? - ?? 52 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 8D 45 ?? 50 6A - ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? - ?? ?? 52 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? EB ?? 8B 8D ?? ?? ?? ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? - 3B 95 ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 69 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 BC 05 ?? ?? ?? - ?? ?? 0F 84 ?? ?? ?? ?? 69 8D ?? ?? ?? ?? ?? ?? ?? ?? 81 BC 0D ?? ?? ?? ?? ?? ?? ?? - ?? 74 ?? FF 15 ?? ?? ?? ?? 69 95 ?? ?? ?? ?? ?? ?? ?? ?? 3B 84 15 ?? ?? ?? ?? 74 ?? - 69 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 8C 05 ?? ?? ?? ?? 51 6A ?? 68 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 6A ?? 8B 95 ?? ?? ?? ?? 52 FF - 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 8D ?? ?? ?? - ?? 51 FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $msgbox_timer = { + 00 28 ?? ?? ?? ?? 0A 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 28 ?? ?? ?? ?? 0C + 00 02 7B ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 DE 12 08 14 FE 01 + 13 04 11 04 2D ?? 08 6F ?? ?? ?? ?? 00 DC 00 02 7B ?? ?? ?? ?? 16 32 0E 02 7B + ?? ?? ?? ?? 16 FE 04 16 FE 01 2B ?? 16 00 13 04 11 04 2D ?? 00 02 7B ?? ?? ?? + ?? 6F ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 38 ?? ?? ?? ?? 02 7B ?? + ?? ?? ?? 2D ?? 02 7B ?? ?? ?? ?? 2D ?? 02 7B ?? ?? ?? ?? 16 FE 01 16 FE 01 2B + ?? 17 00 13 04 11 04 2D ?? 00 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 73 ?? ?? ?? + ?? 0D 09 17 6F ?? ?? ?? ?? 00 09 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 1F 40 28 ?? + ?? ?? ?? 26 00 38 ?? ?? ?? ?? 00 02 7B ?? ?? ?? ?? 17 FE 04 16 FE 01 13 04 11 + 04 2D ?? 00 02 1F 3B 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 17 FE 04 16 FE 01 13 04 + 11 04 2D ?? 00 02 1F 3B 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 16 FE 01 13 04 11 04 + 2D ?? 02 25 7B ?? ?? ?? ?? 17 59 7D ?? ?? ?? ?? 00 2B ?? 02 25 7B ?? ?? ?? ?? + 17 59 7D ?? ?? ?? ?? 00 2B ?? 02 25 7B ?? ?? ?? ?? 17 59 7D ?? ?? ?? ?? 02 7B + ?? ?? ?? ?? 1F 09 FE 02 16 FE 01 13 04 11 04 2D ?? 02 7B ?? ?? ?? ?? 02 7C ?? + ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 2B ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? + ?? 02 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 7B ?? + ?? ?? ?? 1F 09 FE 02 16 FE 01 13 04 11 04 2D ?? 02 7B ?? ?? ?? ?? 02 7C ?? ?? + ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 2B ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? + 02 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 7B ?? ?? + ?? ?? 1F 09 FE 02 16 FE 01 13 04 11 04 2D ?? 02 7B ?? ?? ?? ?? 02 7C ?? ?? ?? + ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 2B ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 02 + 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 2A } - $enum_resources = { - 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? 8D 45 ?? 50 8B 4D ?? 51 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D 45 - ?? 50 8B 4D ?? 51 8D 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 75 ?? C7 45 ?? ?? ?? - ?? ?? EB ?? 8B 4D ?? 83 C1 ?? 89 4D ?? 8B 55 ?? 3B 55 ?? 73 ?? 8B 45 ?? C1 E0 ?? 8B - 4D ?? 8B 54 01 ?? 83 E2 ?? 74 ?? 8B 45 ?? C1 E0 ?? 03 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? EB ?? 6A ?? 8B 4D ?? C1 E1 ?? 8B 55 ?? 8B 44 0A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB - ?? EB ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 4D ?? 33 - CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $unzip_packed_file = { + 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 0B 06 07 2E ?? 07 06 28 ?? ?? ?? ?? 2D ?? 14 + 2A 02 73 ?? ?? ?? ?? 0C 16 8D ?? ?? ?? ?? 0D 08 6F ?? ?? ?? ?? 13 04 11 04 20 + ?? ?? ?? ?? 40 ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 68 13 05 08 6F ?? ?? ?? ?? 13 06 + 08 6F ?? ?? ?? ?? 13 07 11 04 20 ?? ?? ?? ?? 33 ?? 11 05 1F 14 33 ?? 11 06 2D + ?? 11 07 1E 2E ?? 72 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 08 6F ?? ?? ?? ?? 26 08 6F + ?? ?? ?? ?? 26 08 6F ?? ?? ?? ?? 26 08 6F ?? ?? ?? ?? 13 08 08 6F ?? ?? ?? ?? + 13 09 08 6F ?? ?? ?? ?? 13 0A 11 09 16 31 ?? 11 09 8D ?? ?? ?? ?? 13 0B 08 11 + 0B 16 11 09 6F ?? ?? ?? ?? 26 11 0A 16 31 ?? 11 0A 8D ?? ?? ?? ?? 13 0C 08 11 + 0C 16 11 0A 6F ?? ?? ?? ?? 26 08 6F ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 59 D4 8D ?? + ?? ?? ?? 13 0D 08 11 0D 16 11 0D 8E 69 6F ?? ?? ?? ?? 26 11 0D 73 ?? ?? ?? ?? + 13 0E 11 08 8D ?? ?? ?? ?? 0D 11 0E 09 16 09 8E 69 6F ?? ?? ?? ?? 26 14 13 0D + 38 ?? ?? ?? ?? 11 04 1F 18 63 13 0F 11 04 11 0F 1F 18 62 59 13 04 11 04 20 ?? + ?? ?? ?? 40 ?? ?? ?? ?? 11 0F 17 33 ?? 08 6F ?? ?? ?? ?? 13 10 11 10 8D ?? ?? + ?? ?? 0D 16 13 11 2B ?? 08 6F ?? ?? ?? ?? 13 12 08 6F ?? ?? ?? ?? 13 13 11 12 + 8D ?? ?? ?? ?? 13 15 08 11 15 16 11 15 8E 69 6F ?? ?? ?? ?? 26 11 15 73 ?? ?? + ?? ?? 13 14 11 14 09 11 11 11 13 6F ?? ?? ?? ?? 26 11 11 11 13 58 13 11 11 11 + 11 10 32 ?? 11 0F 18 33 ?? 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 13 16 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 17 11 16 11 17 17 + 28 ?? ?? ?? ?? 13 18 11 18 02 1A 02 8E 69 1A 59 6F ?? ?? ?? ?? 13 19 11 19 28 + ?? ?? ?? ?? 0D DE ?? 11 18 2C ?? 11 18 6F ?? ?? ?? ?? DC 11 0F 19 33 ?? 1F 10 + 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 1A 1F 10 8D ?? ?? ?? ?? 25 + D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 1B 11 1A 11 1B 17 28 ?? ?? ?? ?? 13 1C 11 1C + 02 1A 02 8E 69 1A 59 6F ?? ?? ?? ?? 13 1D 11 1D 28 ?? ?? ?? ?? 0D DE 17 11 1C + 2C ?? 11 1C 6F ?? ?? ?? ?? DC 72 B5 0E 00 70 73 ?? ?? ?? ?? 7A 08 6F ?? ?? ?? + ?? 14 0C 09 2A + } + $resolve_assembly = { + 12 00 03 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 12 00 16 28 ?? ?? ?? ?? 0B 28 ?? ?? ?? ?? 07 + 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 72 ?? ?? ?? ?? 17 8D ?? ?? ?? ?? 13 13 11 13 16 1F + 2C 9D 11 13 6F ?? ?? ?? ?? 0D 7E ?? ?? ?? ?? 13 04 16 13 05 16 13 06 16 13 07 2B ?? + 09 11 07 9A 08 28 ?? ?? ?? ?? 2C 0A 09 11 07 17 58 9A 13 04 2B ?? 11 07 18 58 13 07 + 11 07 09 8E 69 17 59 32 ?? 11 04 6F ?? ?? ?? ?? 2D ?? 12 00 7B ?? ?? ?? ?? 6F ?? ?? + ?? ?? 2D ?? 28 ?? ?? ?? ?? 12 00 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 16 + 13 08 2B ?? 09 11 08 9A 08 28 ?? ?? ?? ?? 2C ?? 09 11 08 17 58 9A 13 04 2B ?? 11 08 + 18 58 13 08 11 08 09 8E 69 17 59 32 ?? 11 04 6F ?? ?? ?? ?? 16 3E ?? ?? ?? ?? 11 04 + 16 6F ?? ?? ?? ?? 1F 5B 33 ?? 11 04 1F 5D 6F ?? ?? ?? ?? 13 09 11 04 17 11 09 17 59 + 6F ?? ?? ?? ?? 13 0A 11 0A 1F 7A 6F ?? ?? ?? ?? 16 FE 04 16 FE 01 13 05 11 0A 1F 74 + 6F ?? ?? ?? ?? 16 FE 04 16 FE 01 13 06 11 04 11 09 17 58 6F ?? ?? ?? ?? 13 04 7E ?? + ?? ?? ?? 25 13 14 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 11 04 6F ?? ?? ?? ?? 2C ?? 7E ?? ?? + ?? ?? 11 04 6F ?? ?? ?? ?? 13 12 DD ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 04 6F ?? ?? ?? ?? + 13 0B 11 0B 39 ?? ?? ?? ?? 11 0B 6F ?? ?? ?? ?? 69 13 0C 11 0C 8D ?? ?? ?? ?? 13 0D + 11 0B 11 0D 16 11 0C 6F ?? ?? ?? ?? 26 11 05 2C ?? 11 0D 28 ?? ?? ?? ?? 13 0D 14 13 + 0E 11 06 2D ?? 11 0D 28 ?? ?? ?? ?? 13 0E DE 0C 26 17 13 06 DE ?? 26 17 13 06 DE ?? + 11 06 2C ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 04 28 ?? ?? ?? ?? 13 0F 11 0F 28 ?? ?? + ?? ?? 26 11 0F 12 00 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 10 11 10 28 ?? + ?? ?? ?? 2D ?? 11 10 28 ?? ?? ?? ?? 13 11 11 11 11 0D 16 11 0D 8E 69 6F ?? ?? ?? ?? + 11 11 6F ?? ?? ?? ?? 11 10 14 1A 28 ?? ?? ?? ?? 26 11 0F 14 1A 28 ?? ?? ?? ?? 26 11 + 10 28 ?? ?? ?? ?? 13 0E DE ?? 26 DE ?? 7E ?? ?? ?? ?? 11 04 11 0E 6F ?? ?? ?? ?? 11 + 0E 13 12 DE ?? DE ?? 11 14 28 ?? ?? ?? ?? DC 14 2A 11 12 2A } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($enum_resources) + uint16(0)==0x5A4D and (($call_encrypt and $encrypt_files and $start_process) or ($msgbox_timer) or ($unzip_packed_file and $resolve_assembly)) } -rule REVERSINGLABS_Win32_Ransomware_Guscrypter : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Asn1Encoder : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects GusCrypter ransomware." + description = "Yara rule that detects ASN1Encoder ransomware." author = "ReversingLabs" - id = "64aa468c-ec24-58aa-8ea9-23f0cebed227" - date = "2020-11-26" - modified = "2020-11-26" + id = "5fa361e5-4ab0-5856-92b2-6f434e33c350" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.GusCrypter.yara#L1-L129" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "cfe6005028c0e5f5d713af2a549574203678bab2ee48acc1727702bcf91522b1" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.ASN1Encoder.yara#L1-L136" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "000fd846fa5f09af19ead4623bb5a8eb51cdb4c751013569bf070710d3e0d61d" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -42377,106 +42432,114 @@ rule REVERSINGLABS_Win32_Ransomware_Guscrypter : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "GusCrypter" + tc_detection_name = "ASN1Encoder" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 8A 01 41 84 C0 75 ?? 2B CA 8D 85 ?? ?? ?? ?? 51 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? - ?? 8D 45 ?? 8B 5D ?? 83 FB ?? 8B 75 ?? 8B 4D ?? 0F 43 C6 83 F9 ?? 75 ?? 80 38 ?? 0F - 84 ?? ?? ?? ?? 83 FB ?? 8D 45 ?? 0F 43 C6 83 F9 ?? 75 ?? BA ?? ?? ?? ?? 66 39 10 0F - 84 ?? ?? ?? ?? 83 FB ?? 8D 55 ?? 0F 43 D6 83 F9 ?? 75 ?? 66 81 3A ?? ?? 75 ?? 80 7A - ?? ?? 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 45 ?? 0F 43 C6 83 F9 ?? 75 ?? 81 38 ?? ?? ?? ?? - 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 55 ?? 0F 43 D6 83 F9 ?? 75 ?? 81 3A ?? ?? ?? ?? 75 ?? - 66 81 7A ?? ?? ?? 75 ?? 80 7A ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 83 FB ?? 0F - 43 CE 83 F8 ?? 75 ?? BA ?? ?? ?? ?? 8D 78 ?? 8B 01 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 - EF ?? 73 ?? 8A 01 3A 02 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 FB ?? 8D 4D ?? 0F 43 CE 83 F8 - ?? 75 ?? BA ?? ?? ?? ?? 8D 78 ?? 8B 01 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EF ?? 73 ?? - 66 8B 01 66 3B 02 75 ?? 8A 41 ?? 3A 42 ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 FB ?? 8D 4D - ?? 0F 43 CE 83 F8 ?? 75 ?? BA ?? ?? ?? ?? 8D 78 ?? 8B 01 3B 02 75 ?? 83 C1 ?? 83 C2 - ?? 83 EF ?? 73 ?? 66 8B 01 66 3B 02 75 ?? 8A 41 ?? 3A 42 ?? 0F 84 ?? ?? ?? ?? 8B 4D - ?? 8D 45 ?? 83 FB ?? 0F 43 C6 83 F9 ?? 75 ?? 81 38 ?? ?? ?? ?? 75 ?? 81 78 ?? ?? ?? - ?? ?? 75 ?? 80 78 ?? ?? 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 45 ?? 0F 43 C6 83 F9 ?? 75 + $remote_connection_p1 = { + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 0F B6 + 84 34 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 2B C6 68 ?? ?? ?? ?? 03 C0 50 53 E8 ?? ?? ?? ?? + 83 C4 ?? 83 C3 ?? 46 83 FE ?? 72 ?? 8B 5C 24 ?? BE ?? ?? ?? ?? A1 ?? ?? ?? ?? 53 50 + 68 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 83 C4 ?? 50 68 ?? ?? ?? ?? 56 50 + E8 ?? ?? ?? ?? 33 C0 83 C4 ?? 8B F0 85 FF 74 ?? A1 ?? ?? ?? ?? 0F B6 04 06 50 B8 ?? + ?? ?? ?? 2B C6 68 ?? ?? ?? ?? 03 C0 50 53 E8 ?? ?? ?? ?? 83 C4 ?? 83 C3 ?? 46 3B F7 + 72 ?? 8B 5C 24 ?? A1 ?? ?? ?? ?? BE ?? ?? ?? ?? 53 50 68 ?? ?? ?? ?? 56 50 E8 ?? ?? + ?? ?? A1 ?? ?? ?? ?? 83 C4 ?? 50 68 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? C1 E8 ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 94 24 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 8B FB 8B F0 0F B6 + 84 34 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 2B C6 68 ?? ?? ?? ?? 03 C0 50 57 E8 ?? ?? ?? ?? + 83 C4 ?? 83 C7 ?? 46 83 FE ?? 72 ?? A1 ?? ?? ?? ?? 53 50 68 ?? ?? ?? ?? BB ?? ?? ?? + ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 50 68 ?? ?? + ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 50 68 ?? + ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 50 68 + ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 83 C4 ?? 33 F6 8D 51 ?? 66 8B 01 + 83 C1 ?? 66 3B C6 75 ?? 2B CA 8B 15 ?? ?? ?? ?? D1 F9 8D 72 ?? 8A 02 42 84 C0 75 ?? + 8B 3D ?? ?? ?? ?? 2B D6 8D 04 0A 8D 34 45 ?? ?? ?? ?? 56 6A ?? FF D7 50 FF 15 ?? ?? + ?? ?? 8B D8 8D 04 36 50 6A ?? 89 5C 24 ?? FF D7 50 FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? + ?? 8B F8 FF 35 ?? ?? ?? ?? 89 7C 24 ?? 68 ?? ?? ?? ?? 56 53 E8 ?? ?? ?? ?? 33 C9 89 } - $find_files_p2 = { - 81 38 ?? ?? ?? ?? 75 ?? 80 78 ?? ?? 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 45 ?? 0F 43 C6 83 - F9 ?? 75 ?? 81 38 ?? ?? ?? ?? 75 ?? 81 78 ?? ?? ?? ?? ?? 75 ?? 81 78 ?? ?? ?? ?? ?? - 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 45 ?? 0F 43 C6 83 F9 ?? 75 ?? 81 38 ?? ?? ?? ?? 75 ?? - 81 78 ?? ?? ?? ?? ?? 75 ?? 81 78 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 4D ?? - 0F 43 CE 83 7D ?? ?? 75 ?? BA ?? ?? ?? ?? BF ?? ?? ?? ?? 8B 01 3B 02 75 ?? 83 C1 ?? - 83 C2 ?? 83 EF ?? 73 ?? 66 8B 01 66 3B 02 75 ?? 8A 41 ?? 3A 42 ?? 0F 84 ?? ?? ?? ?? - 83 FB ?? 8D 45 ?? 0F 43 C6 83 7D ?? ?? 75 ?? 81 38 ?? ?? ?? ?? 75 ?? 81 78 ?? ?? ?? - ?? ?? 75 ?? 81 78 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 FB ?? 8D 4D ?? 0F 43 CE 83 7D - ?? ?? 75 ?? BA ?? ?? ?? ?? BF ?? ?? ?? ?? 8B 01 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EF - ?? 73 ?? 66 8B 01 66 3B 02 75 ?? 8A 41 ?? 3A 42 ?? 75 ?? B0 ?? EB ?? 32 C0 84 C0 75 - ?? 8D 85 ?? ?? ?? ?? 50 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? - ?? 8B CC 8B D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 - C4 ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? - 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? - ?? 83 C4 ?? 8B BD ?? ?? ?? ?? C6 45 ?? ?? 83 FB ?? 72 ?? 43 8B C6 81 FB ?? ?? ?? ?? - 72 ?? 8B 76 ?? 83 C3 ?? 2B C6 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 53 56 E8 ?? ?? ?? - ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF - 15 + $remote_connection_p2 = { + 44 24 ?? 83 C4 ?? 89 8C 24 ?? ?? ?? ?? 8B D9 85 C0 7E ?? 8B 44 24 ?? 0F B7 04 58 66 + 89 84 24 ?? ?? ?? ?? 83 F8 ?? 75 ?? 83 EF ?? 66 8B 47 ?? 83 C7 ?? 66 3B C1 75 ?? BE + ?? ?? ?? ?? 83 C3 ?? A5 A5 66 A5 EB ?? 8D 94 24 ?? ?? ?? ?? 8B F2 66 8B 02 83 C2 ?? + 66 3B C1 75 ?? 2B D6 83 EF ?? 66 8B 47 ?? 83 C7 ?? 66 3B C1 75 ?? 8B CA C1 E9 ?? F3 + A5 8B CA 83 E1 ?? F3 A4 33 C9 8B 7C 24 ?? 43 3B 5C 24 ?? 7C ?? FF 74 24 ?? 51 FF 15 + ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 50 FF D6 FF 35 ?? ?? ?? ?? 33 C0 50 FF 15 ?? ?? ?? ?? + 50 FF D6 8B 5C 24 ?? 53 33 DB 53 FF 15 ?? ?? ?? ?? 50 FF D6 FF 74 24 ?? 53 FF 15 ?? + ?? ?? ?? 50 FF D6 FF 74 24 ?? 53 FF 15 ?? ?? ?? ?? 50 FF D6 8B 5C 24 ?? 89 3D ?? ?? + ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 33 FF E9 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? + 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 57 + FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 89 44 24 ?? 85 C0 + 0F 84 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 8B F3 89 5C 24 ?? 8D 4E ?? 8A 06 46 84 + C0 75 ?? 8B 3D ?? ?? ?? ?? 2B F1 68 ?? ?? ?? ?? 6A ?? FF D7 50 FF 15 ?? ?? ?? ?? 89 + 44 24 ?? 85 DB 0F 84 ?? ?? ?? ?? 81 FE ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 6A ?? FF D7 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 89 44 24 ?? 8D 84 24 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? + ?? ?? BA ?? ?? ?? ?? C1 E8 ?? 50 E8 ?? ?? ?? ?? 59 8D 94 24 ?? ?? ?? ?? 8D 8C 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 8B C8 8B F8 3B FE 73 ?? 81 F9 ?? ?? ?? ?? 74 ?? FF 74 + 24 ?? 8D 84 24 ?? ?? ?? ?? 50 8D 04 1F 50 E8 } $encrypt_files_p1 = { - 88 84 05 ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 7C ?? 33 FF 33 F6 8B C6 8A 9C 35 ?? ?? ?? ?? - 99 F7 7D ?? 0F B6 04 0A 03 F8 0F B6 CB 03 F9 81 E7 ?? ?? ?? ?? 79 ?? 4F 81 CF ?? ?? - ?? ?? 47 8A 84 3D ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 88 84 35 ?? ?? ?? ?? 46 88 9C 3D ?? - ?? ?? ?? 81 FE ?? ?? ?? ?? 7C ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 - E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 85 DB 0F 85 ?? ?? ?? ?? 8B 4D ?? 32 D2 E8 ?? ?? ?? ?? - 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? - 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 0F 82 ?? ?? ?? ?? 8B 4D - ?? 42 8B C1 81 FA ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 - F8 ?? 0F 87 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 - ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 89 BD ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 33 F6 - 53 E8 ?? ?? ?? ?? 83 C4 ?? 88 85 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 + 8B CA 8D 84 24 ?? ?? ?? ?? C1 E9 ?? F3 A5 53 68 ?? ?? ?? ?? 6A ?? 53 6A ?? 8B CA 83 + E1 ?? 68 ?? ?? ?? ?? F3 A4 50 FF 15 ?? ?? ?? ?? 8B D8 33 FF 89 5C 24 ?? 89 3D ?? ?? + ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 83 FB ?? 74 ?? 85 DB 0F 85 ?? ?? ?? ?? 33 + F6 8D 8C 24 ?? ?? ?? ?? 8B DE E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? BE ?? ?? ?? ?? 50 + 8D 44 24 ?? 8B D6 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 8B CE E8 ?? ?? ?? ?? 33 D2 + 8D 88 ?? ?? ?? ?? 8D 81 ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? 8B 44 24 ?? C1 E8 ?? 89 + 44 24 ?? 83 C0 ?? 89 44 24 ?? 8B F0 8B C1 F7 F6 40 0F AF 44 24 ?? 50 6A ?? 89 44 24 + ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? 6A ?? FF 15 ?? ?? + ?? ?? 50 FF 15 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 89 44 24 ?? E8 ?? ?? ?? ?? 8B 54 24 ?? + 8D 44 24 ?? 83 C4 ?? 81 C2 ?? ?? ?? ?? B9 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8D 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 39 5C 24 ?? 76 ?? 8B 44 24 ?? 8D + 54 24 ?? 8B 4C 24 ?? 2B C3 3B 44 24 ?? 0F 42 F0 8D 84 24 ?? ?? ?? ?? 50 8B 44 24 ?? + 8D 0C 39 68 ?? ?? ?? ?? 03 C3 56 50 E8 ?? ?? ?? ?? 03 7C 24 ?? 83 C4 ?? 03 DE 3B 7C + 24 ?? 72 ?? 33 FF 8D 84 24 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 6A ?? 57 6A ?? 68 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 5C 24 ?? 83 FB ?? 74 ?? 85 DB 74 ?? 57 8D 44 24 ?? + 89 7C 24 ?? 8B 3D ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF D7 33 F6 8D 44 } $encrypt_files_p2 = { - 0F BE 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 46 83 C4 ?? 83 FE ?? 7C ?? 53 E8 ?? ?? ?? - ?? 83 C4 ?? 88 85 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 83 - 7D ?? ?? 8D 4D ?? 8A 85 ?? ?? ?? ?? 0F 43 4D ?? C7 45 ?? ?? ?? ?? ?? 88 01 C6 41 ?? - ?? 33 C9 8B 75 ?? 8B C6 83 C0 ?? 0F 92 C1 F7 D9 0B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D - 4D ?? 83 7D ?? ?? 8B F8 0F 43 4D ?? 56 57 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F BE - 07 FF B5 ?? ?? ?? ?? 35 ?? ?? ?? ?? 83 C0 ?? 50 E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 8B - BD ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? - 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D - 45 ?? 83 7D ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 32 D2 C7 45 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 0F 82 ?? ?? ?? ?? 8B 4D ?? 8D 50 ?? 8B C1 - 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? - ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? - ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $misc_checks_p1 = { - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? - 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 - F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? - ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F - 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + 24 ?? 56 50 FF 74 24 ?? FF 74 24 ?? 53 FF D7 33 FF 68 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 C4 ?? FF 74 24 ?? 57 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 50 FF D6 + FF 74 24 ?? 57 FF 15 ?? ?? ?? ?? 50 FF D6 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? + ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 6A ?? FF 15 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? 33 F6 56 53 FF 15 ?? ?? ?? ?? 3D ?? + ?? ?? ?? 76 ?? 39 35 ?? ?? ?? ?? 75 ?? 56 53 FF 15 ?? ?? ?? ?? 56 8B F8 B8 ?? ?? ?? + ?? 56 50 53 2B F8 FF 15 ?? ?? ?? ?? 57 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 56 8D 8C 24 ?? ?? ?? ?? A3 ?? ?? ?? ?? 51 57 50 53 FF 15 ?? ?? ?? ?? 33 C0 50 50 50 + 53 FF 15 ?? ?? ?? ?? 33 F6 8D 84 24 ?? ?? ?? ?? 56 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 53 FF 15 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF + 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D8 6A ?? 89 5C 24 ?? FF 15 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? 50 + FF 15 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA + ?? ?? ?? ?? C1 E8 ?? 50 E8 ?? ?? ?? ?? 59 8D 94 24 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 85 C9 75 ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? + 50 FF 15 } - $misc_checks_p2 = { - 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? - ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? - 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 83 F8 ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? E9 + $find_files = { + 53 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 35 ?? ?? ?? ?? FF D6 83 C4 ?? 53 8D 85 ?? + ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF D6 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 8B F0 89 75 ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? + ?? ?? 33 DB B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? + 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 8B C3 EB ?? 1B C0 83 + C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 + ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 8B + C3 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? + F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 59 BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 + A5 6A ?? 59 BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 A5 66 A5 6A ?? 59 BE ?? ?? ?? ?? 8D + BD ?? ?? ?? ?? F3 A5 66 A5 BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? A5 A5 A5 A5 50 E8 ?? ?? + ?? ?? 59 8B F0 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? + ?? ?? 50 56 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? + 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? FF 75 ?? + 8B 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B 75 ?? E9 ?? ?? ?? ?? FF 75 ?? E9 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 66 39 1F 0F 84 } condition: - uint16(0)==0x5A4D and ( all of ($misc_checks_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($find_files and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*))) } rule REVERSINGLABS_Win32_Ransomware_Outsider : TC_DETECTION MALICIOUS MALWARE FILE { @@ -42487,8 +42550,8 @@ rule REVERSINGLABS_Win32_Ransomware_Outsider : TC_DETECTION MALICIOUS MALWARE FI date = "2020-10-23" modified = "2020-10-23" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Outsider.yara#L1-L88" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Outsider.yara#L1-L88" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "80c5a93b5b72b7b66e36f1726486b0c7620588d05bd925510d76f020a40b124c" score = 75 quality = 90 @@ -42559,18 +42622,18 @@ rule REVERSINGLABS_Win32_Ransomware_Outsider : TC_DETECTION MALICIOUS MALWARE FI condition: uint16(0)==0x5A4D and ($enum_resources) and ($find_files) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Vhdlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Avoslocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects VHDLocker ransomware." + description = "Yara rule that detects AvosLocker ransomware." author = "ReversingLabs" - id = "696f8145-342b-5da5-b9ec-6f0d16afc465" - date = "2020-07-15" - modified = "2020-07-15" + id = "a803283d-6424-5a64-89e6-c73a3322ba1e" + date = "2021-10-22" + modified = "2021-10-22" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.VHDLocker.yara#L1-L152" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "39d1fbfc79d5ea866498bb1e40d2290469df774ce65b1da04a85c0e4e5b4493c" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.AvosLocker.yara#L1-L108" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "4d81b801a95a54a35989c4a985d92578971568d1412f625bca911d0fa1eee1fe" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -42578,141 +42641,97 @@ rule REVERSINGLABS_Win32_Ransomware_Vhdlocker : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "VHDLocker" + tc_detection_name = "AvosLocker" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 - ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 45 ?? 6A ?? 68 - ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 89 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 4D ?? 50 51 E8 ?? ?? - ?? ?? 83 C4 ?? 0B C2 74 ?? 53 FF 15 ?? ?? ?? ?? B0 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 33 DB 8D 95 ?? ?? ?? ?? 53 52 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 53 50 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 9D ?? ?? - ?? ?? 89 9D ?? ?? ?? ?? 33 F6 8B FF 6A ?? 53 E8 ?? ?? ?? ?? 88 44 35 ?? 46 83 FE ?? - 7C ?? 8D 4D ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? B8 ?? ?? ?? ?? 8D - B5 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8B CE 89 5D ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 8B F4 89 A5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 72 ?? 8B 8D - } - $encrypt_files_p2 = { - 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B BD ?? ?? ?? ?? 53 53 33 C9 51 33 C0 50 57 FF 15 ?? ?? - ?? ?? 85 C0 75 ?? 57 FF 15 ?? ?? ?? ?? 32 C0 E9 ?? ?? ?? ?? 53 8D 95 ?? ?? ?? ?? 52 - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? - ?? ?? ?? 89 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 35 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 3B C3 0F 84 ?? ?? ?? ?? 6A ?? F7 D8 99 53 52 50 57 FF 15 ?? - ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B 8D ?? ?? ?? ?? 8D 95 ?? ?? - ?? ?? 52 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 8D 8D ?? ?? ?? ?? 51 50 8D 95 ?? ?? ?? - ?? 52 57 FF D6 85 C0 0F 84 ?? ?? ?? ?? 39 9D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 81 BD ?? - ?? ?? ?? ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 39 9D ?? ?? ?? ?? 77 ?? 81 BD ?? ?? ?? ?? ?? - ?? ?? ?? 0F 82 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 11 9D ?? ?? ?? ?? - 83 FA ?? 0F 84 ?? ?? ?? ?? 53 53 33 C9 51 33 C0 50 52 FF 15 ?? ?? ?? ?? A1 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B C3 8D 50 ?? 66 8B 08 83 C0 ?? 66 85 C9 - } - $encrypt_files_p3 = { - 75 ?? 2B C2 6A ?? D1 F8 8D 8D ?? ?? ?? ?? 51 8D 14 00 A1 ?? ?? ?? ?? 52 53 50 FF D6 - 8B 15 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 6A ?? 68 ?? ?? ?? ?? 52 FF D6 8B 15 ?? - ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 4D ?? 51 52 FF D6 8B 0D ?? ?? ?? ?? 6A - ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 51 FF D6 8B 0D ?? ?? ?? ?? 6A ?? 8D 95 - ?? ?? ?? ?? 52 6A ?? 8D 85 ?? ?? ?? ?? 50 51 FF D6 EB ?? 8B 9D ?? ?? ?? ?? 6A ?? 33 - C9 51 51 B8 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 33 DB EB ?? 83 85 ?? ?? - ?? ?? ?? 11 9D ?? ?? ?? ?? 53 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 57 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B 4D ?? 8B 55 - ?? 8B B5 ?? ?? ?? ?? 51 52 8D BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 8D 85 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B D6 52 FF 15 ?? ?? ?? ?? 33 C9 - 51 51 33 C0 51 50 A1 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 51 FF 15 ?? - ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 94 C0 8B 4D ?? 64 - 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $find_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 68 ?? ?? ?? ?? 33 F6 - 8D 8D ?? ?? ?? ?? 33 C0 56 51 66 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 8D 95 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? - 52 FF 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? EB ?? 8D 9B - ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? A8 ?? 0F 85 ?? ?? ?? ?? A8 ?? 0F 84 ?? ?? ?? ?? 57 8D - 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? - ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? E9 - ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? - 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 + $find_files = { + 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF + B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 + 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 ?? 8A 48 ?? 84 C9 74 ?? 80 F9 + ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 + C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? + ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? 74 ?? + FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 8B D8 56 FF 15 } - $find_files_p2 = { - D8 ?? 3B C6 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 - ?? 66 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 - C0 EB ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 BB ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 90 - 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 - ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 8B FF 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 - ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? - ?? ?? ?? 57 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? - ?? ?? 52 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8B D1 83 C4 ?? 0B D0 89 B5 ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? 74 ?? 50 51 8D - 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 83 C4 ?? 3A C1 75 ?? 01 0D ?? ?? ?? - ?? 11 35 ?? ?? ?? ?? EB ?? 01 0D ?? ?? ?? ?? 11 35 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 - 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 5E 33 CD - B0 ?? 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + $enum_resources = { + 50 51 6A ?? 6A ?? 6A ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 85 FF 0F 84 ?? ?? ?? ?? FF 75 ?? 6A ?? 57 + E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 57 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? 33 DB 39 5D ?? 76 ?? 8D 77 ?? 83 7E ?? ?? 0F 85 ?? ?? ?? ?? 83 7E + ?? ?? 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 85 + ?? ?? ?? ?? 39 46 ?? B9 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? 8B D1 0F 45 56 ?? 8B C1 83 + 7E ?? ?? 0F 11 85 ?? ?? ?? ?? 0F 45 46 ?? 83 3E ?? 0F 28 05 ?? ?? ?? ?? 89 45 ?? 8B + C1 0F 45 06 83 7E ?? ?? 0F 11 45 ?? 89 45 ?? 8B C1 0F 28 05 ?? ?? ?? ?? 0F 45 46 ?? + 33 C9 0F 11 45 ?? 89 45 ?? 0F 28 05 ?? ?? ?? ?? 0F 11 45 ?? 8A 85 ?? ?? ?? ?? 30 84 + 0D ?? ?? ?? ?? 41 83 F9 ?? 72 ?? 52 FF 75 ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? FF 75 ?? + FF 75 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 3E ?? 0F 84 ?? ?? ?? ?? FF 36 E8 ?? ?? ?? ?? + 59 83 F8 ?? 0F 86 ?? ?? ?? ?? 8B 06 80 78 ?? ?? 75 ?? B1 ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? 33 C0 66 C7 45 ?? ?? ?? C6 45 ?? ?? 30 4C 05 ?? 40 83 F8 ?? 73 ?? + 8A 4D ?? EB ?? 8D 45 ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 59 FF 36 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 65 ?? ?? 50 51 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? + C6 45 ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 83 4D ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? EB ?? B1 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? + C6 45 ?? ?? 30 4C 05 ?? 40 83 F8 ?? 73 ?? 8A 4D ?? EB ?? 8D 45 ?? C6 45 ?? ?? 50 E8 + ?? ?? ?? ?? 59 F7 46 ?? ?? ?? ?? ?? 74 ?? 8D 4E ?? E8 ?? ?? ?? ?? 43 83 C6 ?? 3B 5D + ?? 0F 82 ?? ?? ?? ?? E9 ?? ?? ?? ?? FF 75 ?? FF 15 } - $get_logical_drives_list_p1 = { - 8D 85 ?? ?? ?? ?? 50 57 89 BD ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D - 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 57 68 ?? ?? ?? ?? 6A ?? 57 - 57 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? - ?? ?? 83 EC ?? 8B F4 89 7E ?? C7 46 ?? ?? ?? ?? ?? BF ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 - A5 ?? ?? ?? ?? C6 06 ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 - FF 89 7D ?? 83 78 ?? ?? 72 ?? 8B 00 8D 50 ?? 8D A4 24 ?? ?? ?? ?? 8A 08 40 84 C9 75 - ?? 57 8D 8D ?? ?? ?? ?? 2B C2 51 50 83 EC ?? 8B F4 89 7E ?? C7 46 ?? ?? ?? ?? ?? BF - ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 A5 ?? ?? ?? ?? C6 06 ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? - ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 83 C4 ?? 39 70 ?? 72 ?? 8B 00 50 53 FF 15 ?? ?? ?? - ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? - ?? ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 53 FF 15 - ?? ?? ?? ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 8D 64 24 ?? 66 8B 10 66 3B 11 75 ?? 66 85 - D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB + $import_key = { + 50 53 53 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 50 68 ?? ?? + ?? ?? FF D6 50 53 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? B1 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B C3 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 30 8C 05 ?? ?? + ?? ?? 40 83 F8 ?? 73 ?? 8A 8D ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 88 9D ?? ?? ?? ?? + 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 0F 28 05 ?? ?? ?? ?? 59 0F 11 85 ?? ?? ?? ?? + 59 0F 28 05 ?? ?? ?? ?? 8B CB 0F 11 85 ?? ?? ?? ?? 66 C7 85 ?? ?? ?? ?? ?? ?? 88 9D + ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 30 84 0D ?? ?? ?? ?? 41 83 F9 ?? 72 ?? 88 9D ?? ?? ?? + ?? FF D6 50 8D 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? FF 36 8D 45 ?? 89 9D ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? FF 76 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 8D ?? + ?? ?? ?? 83 C4 ?? 8B D7 50 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 84 C0 75 ?? 0F 28 05 ?? ?? ?? ?? 8B CB 0F 11 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 0F 28 05 ?? ?? ?? ?? 0F 11 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 C7 + 85 ?? ?? ?? ?? ?? ?? 88 9D ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 30 84 0D ?? ?? ?? ?? 41 83 + F9 ?? 72 ?? 8D 85 ?? ?? ?? ?? 88 9D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8D 45 ?? 50 E8 + ?? ?? ?? ?? 59 8D 4D ?? 85 C0 74 ?? 88 19 41 83 E8 ?? 75 ?? 39 9D ?? ?? ?? ?? 74 ?? + FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 } - $get_logical_drives_list_p2 = { - 1B C0 83 D8 ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 89 85 ?? ?? - ?? ?? 89 B5 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CE D3 E2 85 95 ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? 8D 4E ?? 66 89 8D ?? ?? ?? ?? 33 C9 6A ?? 51 8D 95 ?? ?? ?? ?? 52 C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? 66 89 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 - ?? ?? ?? ?? 6A ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? - ?? 83 EC ?? B8 ?? ?? ?? ?? 8B CC 89 A5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 C4 ?? BF ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 39 78 ?? 72 ?? 8B 00 8D - 50 ?? 8A 08 40 84 C9 75 ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 2B C2 50 83 EC ?? B8 ?? ?? ?? - ?? 8B CC 89 A5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 39 78 ?? 72 ?? 8B 00 50 53 FF 15 ?? ?? ?? ?? 39 BD ?? ?? ?? ?? 72 ?? 8B 95 ?? ?? ?? - ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? BE ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 39 BD ?? ?? ?? ?? 72 ?? 8B 85 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 53 89 B5 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C6 85 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 46 89 B5 ?? ?? ?? ?? 83 - FE ?? 0F 8C ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? B0 ?? 8B - 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files = { + 50 51 51 FF B5 ?? ?? ?? ?? 51 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? + ?? ?? 8B BD ?? ?? ?? ?? 57 89 BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 59 85 F6 0F 84 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CE 85 C0 74 ?? C6 01 ?? 41 83 E8 ?? 75 ?? 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 59 83 C0 ?? 74 ?? 39 85 ?? ?? ?? ?? 72 ?? 50 8D 85 ?? ?? ?? + ?? 50 56 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? FF B5 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 + C4 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 59 57 40 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 6A ?? FF B5 ?? ?? ?? ?? 6A + ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? D1 EF 6A ?? 5A 74 ?? + 8B 9D ?? ?? ?? ?? 4B 03 DE 8A 03 8A 0C 32 88 04 32 42 88 0B 4B 3B D7 72 ?? 8B 9D ?? + ?? ?? ?? 8B BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 03 C3 56 50 E8 ?? ?? ?? ?? 03 DF 56 + 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? + ?? 47 81 C6 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 50 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 + B9 ?? ?? ?? ?? F7 F1 83 C4 ?? 40 3B F8 0F 82 } condition: - uint16(0)==0x5A4D and ( all of ($get_logical_drives_list_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($enum_resources) and ($find_files) and ($import_key) and ($encrypt_files) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Goodwill : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Avaddon : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects GoodWill ransomware." + description = "Yara rule that detects Avaddon ransomware." author = "ReversingLabs" - id = "66358802-450b-5276-8088-b3550519b1e8" - date = "2022-06-28" - modified = "2022-06-28" + id = "f3a57482-5799-594b-bcfa-1137ca04dfd5" + date = "2020-10-19" + modified = "2020-10-19" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.GoodWill.yara#L1-L89" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "94e2950f415ba737fe5ca9d32a3d850dd5744e547c4ca094ad28545e19033cb2" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Avaddon.yara#L1-L148" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "1b2c449d5bad02dd06cb4a980fcca1feaf02b1d8127096bb39deecbc544272a6" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -42720,77 +42739,132 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Goodwill : TC_DETECTION MALICIOUS MA sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "GoodWill" + tc_detection_name = "Avaddon" tc_detection_factor = 5 importance = 25 strings: - $encrypt_file = { - 02 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 06 6F - ?? ?? ?? ?? 0A 06 28 ?? ?? ?? ?? 0B 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 02 72 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 07 28 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? DE ?? 26 72 ?? - ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 2A - } - $aes_encrypt = { - 14 0A 03 0B 73 ?? ?? ?? ?? 0C 73 ?? ?? ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 20 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 03 07 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? - ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? - ?? ?? 6F ?? ?? ?? ?? 09 17 6F ?? ?? ?? ?? 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? - 11 ?? 02 16 02 8E 69 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? - ?? ?? ?? DC 08 6F ?? ?? ?? ?? 0A DE ?? 09 2C ?? 09 6F ?? ?? ?? ?? DC 08 2C ?? 08 6F ?? - ?? ?? ?? DC 06 2A + $find_files = { + 8B FF 55 8B EC 51 8B 4D ?? 53 57 33 DB 8D 51 ?? 66 8B 01 83 C1 ?? 66 3B C3 75 ?? 8B + 7D ?? 2B CA D1 F9 8B C7 41 F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 5F 5B C9 C3 56 8D 5F + ?? 03 D9 6A ?? 53 E8 ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? + ?? ?? 83 C4 ?? 85 C0 75 ?? FF 75 ?? 2B DF 8D 04 7E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 75 ?? 8B 7D ?? 8B CF E8 ?? ?? ?? ?? 8B D8 85 DB 74 ?? 56 E8 ?? ?? ?? ?? + 59 EB ?? 8B 47 ?? 89 30 83 47 ?? ?? 33 DB 6A ?? E8 ?? ?? ?? ?? 59 8B C3 5E EB ?? 33 + C0 50 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 8B 55 ?? 8B 4D ?? 53 8B 5D ?? 89 8D ?? ?? ?? ?? 56 57 3B D3 74 ?? 0F + B7 02 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 84 C0 75 ?? 83 EA ?? 3B D3 75 ?? 8B 8D ?? + ?? ?? ?? 0F B7 32 83 FE ?? 75 ?? 8D 43 ?? 3B D0 74 ?? 51 33 FF 57 57 53 E8 ?? ?? ?? + ?? 83 C4 ?? E9 ?? ?? ?? ?? 56 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 2B D3 0F B6 C0 D1 FA + 42 F7 D8 1B C0 33 FF 57 57 23 C2 57 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 53 FF + 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 + C4 ?? 8B F8 E9 ?? ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 6A ?? 89 8D ?? ?? ?? ?? 59 66 39 + 8D ?? ?? ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 66 39 8D ?? ?? ?? ?? 75 ?? 66 39 BD + ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 6A ?? 85 C0 8B 85 ?? ?? ?? + ?? 59 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? + ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8B F8 56 FF 15 ?? ?? ?? + ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 } - $find_files_p1 = { - 28 ?? ?? ?? ?? 0A 1F ?? 28 ?? ?? ?? ?? 0B 18 8D ?? ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 - 17 72 ?? ?? ?? ?? A2 0C 06 0D 16 13 ?? 38 ?? ?? ?? ?? 09 11 ?? 9A 13 ?? 11 ?? 6F ?? ?? - ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? DD ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 - ?? 28 ?? ?? ?? ?? 08 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 28 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 17 28 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 7D ?? ?? - ?? ?? 11 ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 19 6F ?? ?? ?? ?? 6F ?? - ?? ?? ?? DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? - ?? DC DE ?? 26 DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? - ?? ?? ?? DC 11 ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? 73 ?? ?? ?? ?? 13 ?? - 11 ?? 11 ?? 6F ?? ?? ?? ?? 7D ?? ?? ?? ?? 11 ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? - ?? ?? ?? 25 19 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? - DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? - 8E 69 3F ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 09 8E 69 3F ?? ?? ?? ?? 08 + $encrypt_files_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 8B 45 ?? 8B + 7D ?? 85 C0 0F 84 ?? ?? ?? ?? 83 FF ?? 0F 84 ?? ?? ?? ?? 6A ?? 8D 4D ?? C7 45 ?? ?? + ?? ?? ?? 51 6A ?? 6A ?? 6A ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 } - $find_files_p2 = { - 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 07 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 - ?? 2B ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 17 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? - 2B ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 7D ?? ?? ?? ?? 11 ?? FE 06 ?? ?? - ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 19 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? - 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC DE ?? 26 - DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 07 11 ?? 28 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? - 7D ?? ?? ?? ?? 11 ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 19 6F ?? ?? ?? - ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F - ?? ?? ?? ?? DC DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 2A + $encrypt_files_p2 = { + 6A ?? 8D 45 ?? 0F 57 C0 50 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 57 FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 6A ?? 51 8D 45 ?? 0F 43 45 ?? 68 ?? ?? ?? + ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 + ?? 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 33 F6 39 75 ?? 0F 86 ?? ?? ?? ?? 83 + 7D ?? ?? 8D 45 ?? 8D 4D ?? 0F 43 45 ?? 83 7D ?? ?? 68 ?? ?? ?? ?? 0F 43 4D ?? 03 C6 + 50 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 8D 45 ?? 0F + 43 45 ?? 53 51 50 6A ?? 6A ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? 83 7D ?? ?? 8D 4D ?? 6A ?? 51 8D 45 ?? 0F 43 45 ?? 53 50 57 FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? 3B 75 ?? 0F 82 ?? ?? ?? ?? 83 7D ?? ?? 74 } - $remote_connection = { - 73 ?? ?? ?? ?? 0A 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 17 28 ?? ?? ?? - ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 1C 6F ?? ?? ?? ?? 2B ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? - 1C 6F ?? ?? ?? ?? 06 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 17 0B DE ?? 26 72 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 07 2A + $encrypt_files_p3 = { + 8B 45 ?? 89 45 ?? 8B 45 ?? 6A ?? 89 45 ?? 8D 45 ?? 50 51 52 57 89 55 ?? 89 4D ?? FF + 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 9D ?? ?? ?? ?? 83 7B ?? ?? 8D 43 ?? 72 ?? 8B 00 6A ?? + 8D 4D ?? 51 FF 73 ?? 50 57 FF D6 85 C0 74 ?? 8B 4B ?? 39 4D ?? 75 ?? 8B 45 ?? 89 85 + ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 6A ?? 89 45 ?? 8D 45 ?? 50 6A ?? 8D 85 ?? ?? + ?? ?? 89 4D ?? 50 57 C7 45 ?? ?? ?? ?? ?? FF D6 85 C0 74 ?? 83 7D ?? ?? 75 ?? B3 ?? + EB ?? 32 DB 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 + ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 + 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? + ?? ?? ?? 83 C4 ?? 8A C3 EB ?? 32 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D + ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 + } + $remote_connection_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 45 ?? 33 C9 8B 75 ?? 89 85 ?? + ?? ?? ?? 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? 66 89 8D ?? ?? ?? ?? 89 4D ?? 39 4E ?? 0F 84 ?? ?? ?? ?? 66 39 4E ?? 0F 86 ?? ?? + ?? ?? 39 4E ?? 0F 84 ?? ?? ?? ?? 39 4E ?? 0F 84 ?? ?? ?? ?? 8B 06 8D 8D ?? ?? ?? ?? + 8B 7E ?? BA ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 78 ?? ?? 72 ?? 8B 00 6A + ?? 6A ?? 57 FF B5 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B F8 89 BD ?? + ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? + ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? + ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 + 89 85 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7E ?? ?? 8D 46 ?? 0F B7 4E ?? 72 ?? 8B + } + $remote_connection_p2 = { + 00 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 51 50 57 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 7E ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B D0 83 7A ?? ?? 72 ?? 8B 12 83 7E ?? ?? 8D 4E ?? 72 ?? 8B 09 83 7E ?? ?? 8D 46 ?? + 72 ?? 8B 00 6A ?? 57 6A ?? 6A ?? 52 51 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 95 + ?? ?? ?? ?? 8B F8 89 BD ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? + ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 + ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 8B 46 ?? 85 C0 + 75 ?? 50 50 50 50 57 FF 15 ?? ?? ?? ?? EB ?? 83 C6 ?? 83 7E ?? ?? 72 ?? 8B 36 50 56 + 6A ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 + } + $enum_resources_p1 = { + 33 D2 89 7D ?? 89 7D ?? 89 75 ?? 89 45 ?? 89 45 ?? 89 4D ?? 89 55 ?? 89 55 ?? 39 56 + ?? 0F 84 ?? ?? ?? ?? 89 55 ?? 89 55 ?? 89 55 ?? 89 55 ?? 83 7E ?? ?? 8B C6 72 ?? 8B + 06 8D 4D ?? 51 8D 4D ?? 51 8D 4D ?? 51 6A ?? 8D 4D ?? 51 6A ?? 50 FF 15 ?? ?? ?? ?? + 89 45 ?? 85 C0 74 ?? 3D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8B 45 ?? 89 45 ?? + C7 45 ?? ?? ?? ?? ?? 0F 82 + } + $enum_resources_p2 = { + 8D 4D ?? D1 F8 50 52 E8 ?? ?? ?? ?? 8B 7D ?? 8D 4D ?? 8B 75 ?? 83 FF ?? 8B 55 ?? 6A + ?? 68 ?? ?? ?? ?? 0F 43 CE 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? + 8B 7D ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 33 C0 8B 75 ?? 66 89 85 ?? ?? ?? ?? 83 CE ?? + 8B 47 ?? 83 C0 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 + 75 ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7F ?? + ?? 8B C7 72 ?? 8B 07 FF 77 ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 + } + $enum_resources_p3 = { + 53 8B DC 83 EC ?? 83 E4 ?? 83 C4 ?? 55 8B 6B ?? 89 6C 24 ?? 8B EC 6A ?? 68 ?? ?? ?? + ?? 64 A1 ?? ?? ?? ?? 50 53 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 57 50 8D 45 ?? + 64 A3 ?? ?? ?? ?? 8B 43 ?? 8D 4D ?? 89 45 ?? 89 45 ?? 66 8B 43 ?? 6A ?? 68 ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? + 8D 4D ?? 8D 45 ?? 0F 43 45 ?? 51 50 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 7D ?? 8D 45 ?? + 8B 75 ?? 8D 4D ?? 8B 55 ?? 83 FF ?? 0F 43 45 ?? 0F 43 CA 8D 04 70 89 45 ?? 8D 45 ?? + 0F 43 45 ?? 8D 04 70 3B C8 74 ?? 66 83 39 ?? 74 ?? 83 C1 ?? 3B C8 75 ?? 3B C8 74 ?? + 8D 51 ?? 3B D0 74 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_file) and ($aes_encrypt) and ($remote_connection) + uint16(0)==0x5A4D and ($find_files) and ( all of ($enum_resources_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Win32_Ransomware_NB65 : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Nanolocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects NB65 ransomware." + description = "Yara rule that detects NanoLocker ransomware." author = "ReversingLabs" - id = "1aba009e-8065-5fb0-98e7-a595cb324076" - date = "2022-06-01" - modified = "2022-06-01" + id = "a31dad2e-2738-527b-a6e9-322757e2ec30" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.NB65.yara#L1-L68" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "f8a0e265fc72a9f017b37ce4b6dbb878285a5d298ab1b8c69f9fde7159426981" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.NanoLocker.yara#L1-L79" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "7fdb021f22d97bf8a00fd856ef913695a0d6fbaad1138b5a5cc2cc8768b130be" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -42798,61 +42872,79 @@ rule REVERSINGLABS_Win32_Ransomware_NB65 : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "NB65" + tc_detection_name = "NanoLocker" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files = { - E8 ?? ?? ?? ?? 89 45 ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? - C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? - C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? - C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? - C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8A 45 ?? 80 7D ?? ?? 75 ?? 33 C9 90 8A 44 0D ?? - 0F B6 C0 83 E8 ?? 6B C0 ?? 99 F7 FB 8D 42 ?? 99 F7 FB 88 54 0D ?? 41 83 F9 ?? 72 ?? - 8D 45 ?? 89 45 ?? A1 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 50 - ?? 33 C9 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 81 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D0 - 85 C0 75 ?? 33 F6 66 90 A1 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? - 8D 50 ?? 33 C9 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 81 ?? ?? ?? ?? FF B4 B5 ?? ?? ?? - ?? 57 FF D0 85 C0 75 ?? 46 83 FE ?? 7C ?? 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 + $encrypt_file_1 = { + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? E8 + ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 05 ?? ?? ?? ?? ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 + 05 ?? ?? ?? ?? ?? 8D 3D ?? ?? ?? ?? 33 C9 C6 07 ?? 47 41 81 F9 ?? ?? ?? ?? 75 ?? C7 + 05 ?? ?? ?? ?? ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 0F 84 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 6A + ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 6A + ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? + ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 0F 84 ?? ?? ?? ?? 81 3D + ?? ?? ?? ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? 56 E8 + ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 56 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 03 F0 46 8A 06 3C ?? 0F 85 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 } - $find_files = { - 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 - 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? - 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? - 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 80 BD ?? ?? - ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? - 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 8B 85 ?? ?? ?? ?? 75 ?? - 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 + $encrypt_file_2 = { + A3 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 + ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 81 3D ?? ?? ?? ?? + ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 6A ?? + E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? + ?? ?? ?? 2D ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? A3 ?? + ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 6A ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? + ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? + ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 35 ?? + ?? ?? ?? E8 } - $enum_procs = { - 33 C9 66 90 8A 84 0D ?? ?? ?? ?? 0F B6 C0 83 E8 ?? 8D 04 C0 99 F7 BD ?? ?? ?? ?? 8D - 42 ?? 99 F7 BD ?? ?? ?? ?? 88 94 0D ?? ?? ?? ?? 41 83 F9 ?? 72 ?? A1 ?? ?? ?? ?? 8B - 40 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 33 D2 33 C9 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 41 - ?? 8D 8D ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? 51 FF D0 85 C0 75 ?? 6A ?? E8 ?? ?? ?? ?? - 83 C4 ?? 85 C0 74 ?? C7 00 ?? ?? ?? ?? 8D 50 ?? 8B 8D ?? ?? ?? ?? 89 08 C7 02 ?? ?? - ?? ?? 8B 4E ?? 89 48 ?? 8B 4E ?? 89 01 89 56 ?? 8D 85 ?? ?? ?? ?? 50 57 FF D3 85 C0 - 0F 85 ?? ?? ?? ?? 5B A1 ?? ?? ?? ?? 8B 40 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 33 D2 33 C9 - E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 41 ?? 57 FF D0 8B 4D ?? 5F 33 CD 5E E8 ?? ?? ?? - ?? 8B E5 5D C3 + $remote_server_1 = { + E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? ?? + ?? ?? 83 F8 ?? 72 ?? C6 05 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF + 35 ?? ?? ?? ?? E8 + } + $remote_server_2 = { + E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? FF 35 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? A3 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? 68 ?? + ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 + } + $enum_shares_and_encrypt_files = { + E8 ?? ?? ?? ?? C1 C8 ?? BA ?? ?? ?? ?? 23 D0 60 83 FA ?? 75 ?? 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 F8 ?? 76 ?? 83 F8 ?? 74 ?? 8D 35 ?? ?? ?? ?? 60 68 ?? ?? ?? ?? 56 68 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 61 8A 06 46 0A C0 75 ?? 8A 06 0A C0 75 ?? 61 D1 C8 8A 1D ?? + ?? ?? ?? FE C3 88 1D ?? ?? ?? ?? 80 FB ?? 76 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 35 ?? ?? + ?? ?? E8 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? + FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 } condition: - uint16(0)==0x5A4D and ($find_files) and ($enum_procs) and ($encrypt_files) + uint16(0)==0x5A4D and $encrypt_file_1 and $encrypt_file_2 and $remote_server_1 and $remote_server_2 and $enum_shares_and_encrypt_files } -rule REVERSINGLABS_Win32_Ransomware_Encoded01 : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Ransomexx : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Encoded01 ransomware." + description = "Yara rule that detects Ransomexx ransomware." author = "ReversingLabs" - id = "923d987e-f888-5b6a-9ebd-ee1257124aed" - date = "2021-12-16" - modified = "2021-12-16" + id = "5e62660d-2696-56c7-9322-fed6ce9d36ff" + date = "2020-11-26" + modified = "2020-11-26" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Encoded01.yara#L1-L141" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "f6f872290f15f4c564911bb099824c47cb13164457e1bcdb02dee441bc2d6b6a" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Ransomexx.yara#L1-L147" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "27b4132b7f16cafc40687e96a552ce59cc24ebf7679575680f170e3beee8a0a9" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -42860,128 +42952,136 @@ rule REVERSINGLABS_Win32_Ransomware_Encoded01 : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Encoded01" + tc_detection_name = "Ransomexx" tc_detection_factor = 5 importance = 25 strings: $find_files_p1 = { - 55 8B EC 51 B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 ?? 51 87 4D ?? 53 56 57 89 4D ?? 89 55 - ?? 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? - 64 FF 30 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 8C ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 8B 15 ?? ?? ?? ?? 8B 12 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? - 8B 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 8E ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 8B 55 ?? 66 83 7C 42 ?? ?? 75 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B D0 4A 8D 45 ?? E8 ?? - ?? ?? ?? 8B 7D ?? 4F 85 FF 0F 8C ?? ?? ?? ?? 47 8D 85 ?? ?? ?? ?? 50 FF 75 ?? 68 ?? - ?? ?? ?? 8B 45 ?? 8B 55 ?? FF 34 90 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? - 33 F6 46 81 FE ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 8D - 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 0F 84 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 85 ?? - ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? FF 75 ?? 68 ?? - ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? - 8B 45 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8A 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B 7D ?? 85 FF 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B F4 B3 ?? 85 F6 74 ?? C6 46 ?? ?? B0 ?? 66 C7 06 ?? ?? 88 5E ?? 88 + 46 ?? 8B C7 8D 50 ?? 90 8A 08 40 84 C9 75 ?? 2B C2 8B D0 8B C6 8D 78 ?? 8A 08 40 84 + C9 75 ?? 2B C7 8D 84 10 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 7D ?? 68 ?? ?? ?? ?? 57 50 FF 15 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 56 8B 75 ?? 56 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 56 FF 15 ?? ?? ?? + ?? 8B F0 89 75 ?? 83 FE ?? 75 ?? FF 15 ?? ?? ?? ?? 8D A5 ?? ?? ?? ?? 5F 5E 5B 8B E5 + 5D C3 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C4 89 45 ?? 85 C0 74 ?? C6 40 ?? ?? 88 18 88 + 58 ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 49 ?? 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 + ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F + 84 ?? ?? ?? ?? 8B 4D ?? 8D 85 ?? ?? ?? ?? 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A } $find_files_p2 = { - C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 12 E8 ?? ?? ?? ?? 8B 95 - ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8A 55 ?? 8B 45 ?? E8 ?? - ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? A1 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 89 55 ?? 6A ?? 68 ?? - ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 50 ?? 8B 00 E8 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 3B 55 ?? 75 ?? 3B 45 ?? 0F 86 ?? ?? ?? ?? EB ?? 0F 8E ?? ?? ?? ?? 83 7D ?? ?? - 75 ?? 83 7D ?? ?? 0F 86 ?? ?? ?? ?? EB ?? 0F 8E ?? ?? ?? ?? 8B 45 ?? 83 38 ?? 73 ?? - 8B 45 ?? E8 ?? ?? ?? ?? 40 03 C0 50 E8 ?? ?? ?? ?? 59 89 45 ?? 83 7D ?? ?? 0F 84 ?? - ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 40 03 C0 50 8B 45 ?? E8 ?? - ?? ?? ?? 8B D0 8B 45 ?? 59 E8 ?? ?? ?? ?? 8B 45 ?? 50 6A ?? 8D 45 ?? 50 B9 ?? ?? ?? - ?? 33 D2 33 C0 E8 ?? ?? ?? ?? 8B D0 8B 45 ?? E8 ?? ?? ?? ?? EB ?? 8B 45 ?? E8 ?? ?? - ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 40 03 C0 50 E8 ?? ?? ?? ?? 59 89 45 ?? 83 7D ?? ?? 74 - ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 40 03 C0 50 8B 45 ?? E8 ?? ?? ?? - ?? 8B D0 8B 45 ?? 59 E8 ?? ?? ?? ?? 8B 45 ?? 50 6A ?? 8D 45 ?? 50 B9 ?? ?? ?? ?? 33 - D2 33 C0 E8 ?? ?? ?? ?? 8B D0 8B 45 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? EB ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? - ?? ?? ?? 74 ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 8A 45 ?? 50 8A 45 ?? 50 FF 75 ?? 68 ?? ?? - ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B - 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 83 F8 ?? 1B C0 - 40 84 C0 0F 85 ?? ?? ?? ?? 83 FB ?? 74 ?? 53 E8 ?? ?? ?? ?? 4F + 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? + ?? ?? ?? 8B C7 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 8B D0 8D 85 ?? ?? ?? ?? 8D 70 ?? + 8D 64 24 ?? 8A 08 40 84 C9 75 ?? 8B 1D ?? ?? ?? ?? 2B C6 8D 94 10 ?? ?? ?? ?? 52 6A + ?? FF D3 50 FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 56 FF + 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? + ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 6A ?? 56 FF 15 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 FF 15 ?? ?? ?? ?? 85 + C0 75 ?? 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 56 6A ?? + FF D3 50 FF 15 ?? ?? ?? ?? 8B 75 ?? 8D 8D ?? ?? ?? ?? 51 56 FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8D A5 ?? ?? ?? ?? 5F 5E + 5B 8B E5 5D C3 } - $enum_resources = { - 55 8B EC 83 C4 ?? 53 56 57 8B F9 89 55 ?? 8B F0 8B 5D ?? C6 45 ?? ?? 33 C0 89 03 33 - C0 89 07 8D 45 ?? 50 8B 45 ?? 50 6A ?? 56 6A ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 89 03 83 3B ?? 74 ?? 83 3B ?? 74 ?? - C7 07 ?? ?? ?? ?? 8B 03 33 C9 8B 55 ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 8B 03 50 57 8B 45 - ?? 50 E8 ?? ?? ?? ?? 8B F0 81 FE ?? ?? ?? ?? 75 ?? 8B C3 8B 55 ?? E8 ?? ?? ?? ?? EB - ?? BE ?? ?? ?? ?? EB ?? 81 FE ?? ?? ?? ?? 74 ?? 85 F6 0F 94 45 ?? 80 7D ?? ?? 75 ?? - 8B 03 E8 ?? ?? ?? ?? 33 C0 89 03 33 C0 89 07 8B 45 ?? 50 E8 ?? ?? ?? ?? 8A 45 ?? 5F - 5E 5B 8B E5 5D C2 + $find_files_p3 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 8B 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 8B C7 + 8D 50 ?? 90 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 8D B4 00 ?? ?? ?? ?? 8D 86 + ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? + ?? ?? 56 57 53 FF 15 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? + 51 53 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 75 ?? 8B 3D ?? ?? ?? ?? FF D7 83 F8 ?? + 0F 84 ?? ?? ?? ?? FF D7 E9 ?? ?? ?? ?? 8D A4 24 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 + 24 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? F6 44 24 ?? ?? 0F 85 ?? ?? ?? ?? 8B + 4D ?? 56 51 53 FF 15 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 56 8D 94 24 + ?? ?? ?? ?? 52 53 FF 15 ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 + ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 + 74 ?? 66 83 38 ?? 74 ?? 68 ?? ?? ?? ?? 50 FF D7 85 C0 75 ?? FF 05 ?? ?? ?? ?? E9 ?? + ?? ?? ?? 8D 7C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 39 05 ?? ?? ?? ?? 0F 84 + ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8D 4C 24 ?? 51 8D 54 24 ?? 52 FF D7 85 C0 74 ?? 8D 44 } - $remote_connection_p1 = { - BB ?? ?? ?? ?? 83 FB ?? 75 ?? 33 C0 89 45 ?? 83 FB ?? 75 ?? C7 45 ?? ?? ?? ?? ?? 8B - C6 E8 ?? ?? ?? ?? 8B C6 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 FF 33 C0 89 45 ?? 8D 45 ?? - 50 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 5A 2B C2 83 C0 - ?? 50 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 83 C2 ?? 8B 45 ?? 59 E8 ?? ?? ?? - ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 66 BA ?? - ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 5A 2B C2 50 8D 85 ?? ?? ?? ?? 8B 55 ?? - E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? 8B D0 42 8B 45 ?? 59 E8 - ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 66 BA ?? ?? E8 ?? ?? ?? ?? 8B C8 49 BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 85 FF 0F - 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 48 0F 8E ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 45 - ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 6A - ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 - 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? - 8B 45 ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 83 7D - ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 6A + $find_files_p4 = { + 24 ?? 50 8D 4C 24 ?? 51 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 0F B7 44 24 ?? 8B 0D ?? + ?? ?? ?? 3B C1 74 ?? 49 3B C1 74 ?? 8D 54 24 ?? 52 8D 44 24 ?? 50 FF D7 85 C0 74 ?? + 8D 4C 24 ?? 51 8D 54 24 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 0F B7 44 24 ?? 8B + 0D ?? ?? ?? ?? 3B C1 74 ?? 49 3B C1 74 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? + ?? ?? ?? 8B 44 24 ?? 0B 44 24 ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 6A ?? 6A ?? 50 51 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? + 80 3B ?? 75 ?? 80 7B ?? ?? 75 ?? 8B 15 ?? ?? ?? ?? 8D 3C 85 ?? ?? ?? ?? 8B 04 17 53 + 50 FF 15 ?? ?? ?? ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 3C 85 ?? ?? ?? ?? 8B 14 0F 68 ?? ?? + ?? ?? 52 FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 0C 07 68 ?? ?? ?? ?? 53 51 FF 15 ?? ?? + ?? ?? 8B 15 ?? ?? ?? ?? 8B 04 17 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 8B 54 24 ?? 8D 4C 24 ?? 51 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 + ?? 50 FF 15 ?? ?? ?? ?? 53 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 5F 5E 33 C0 + 5B 8B E5 5D C2 } - $remote_connection_p2 = { - 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 - ?? 8B 06 E8 ?? ?? ?? ?? 99 52 50 8B 45 ?? 03 C7 33 D2 3B 54 24 ?? 75 ?? 3B 04 24 5A - 58 76 ?? EB ?? 5A 58 7E ?? 8B 06 E8 ?? ?? ?? ?? 8B D0 81 C2 ?? ?? ?? ?? 8B C6 E8 ?? - ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 03 C7 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 03 7D - ?? 81 FF ?? ?? ?? ?? 77 ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? - 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? 6A - ?? 8B 45 ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? - 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? - ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? - ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 - ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? - ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B - 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 ?? 8B 06 E8 ?? ?? ?? ?? 99 52 50 - 8B 45 ?? 03 C7 33 D2 3B 54 24 ?? 75 ?? 3B 04 24 5A 58 76 ?? EB ?? 5A 58 7E ?? 8B 06 - E8 ?? ?? ?? ?? 8B D0 81 C2 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 03 - C7 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 03 7D ?? 81 FF ?? ?? ?? ?? 77 ?? 83 7D - ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 E8 + $enum_network_resources = { + 55 8B EC 8B 4D ?? 83 EC ?? 8D 45 ?? 50 51 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? 53 8B 1D ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 6A ?? C7 45 ?? ?? ?? ?? ?? + FF D3 50 FF 15 ?? ?? ?? ?? 8B F0 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 57 90 8B 4D ?? 8D + 55 ?? 52 56 8D 45 ?? 50 51 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? + ?? ?? 33 FF 39 7D ?? 76 ?? 83 C6 ?? 8D 64 24 ?? F6 46 ?? ?? 74 ?? F6 46 ?? ?? 74 ?? + 8B 06 8D 50 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 8D 94 00 ?? ?? ?? ?? 52 + 6A ?? FF D3 50 FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 04 8D ?? ?? ?? ?? 85 C0 74 ?? + 8B 16 0F B7 0A 66 89 08 83 C2 ?? 83 C0 ?? 66 85 C9 75 ?? FF 05 ?? ?? ?? ?? 8B 56 ?? + 83 E2 ?? 80 FA ?? 75 ?? 8D 46 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 47 83 C6 ?? 3B 7D ?? 72 + ?? 8B 75 ?? E9 ?? ?? ?? ?? 56 6A ?? FF D3 50 FF 15 ?? ?? ?? ?? 5F 8B 4D ?? 51 FF 15 + ?? ?? ?? ?? 5E 5B 8B E5 5D C3 } - $encrypt_files = { - 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? - E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 - ?? 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 - ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? - ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? - 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF - 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 - ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? - ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D - ?? ?? 74 + $encrypt_files_p1 = { + 55 8B EC 83 EC ?? 53 56 57 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 89 45 ?? 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? B8 ?? ?? ?? ?? 89 4D ?? E8 ?? ?? ?? + ?? 8B F4 85 F6 0F 84 ?? ?? ?? ?? 8B D6 81 EA ?? ?? ?? ?? 83 C2 ?? 89 55 ?? 8B D6 81 + EA ?? ?? ?? ?? 83 C2 ?? 89 55 ?? 8B D6 8B CE 8B FE 81 EA ?? ?? ?? ?? 33 C0 81 E9 ?? + ?? ?? ?? 81 EF ?? ?? ?? ?? 83 C2 ?? C6 46 ?? ?? 89 55 ?? 8B 5D ?? 8A D0 80 E2 ?? 02 + 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 01 ?? ?? ?? ?? 8D 50 ?? 80 E2 ?? 02 90 ?? ?? + ?? ?? 32 90 ?? ?? ?? ?? 88 94 07 ?? ?? ?? ?? 8D 50 ?? 80 E2 ?? 02 90 ?? ?? ?? ?? 32 + 90 ?? ?? ?? ?? 88 94 03 ?? ?? ?? ?? 8B 5D ?? 8D 50 ?? 80 E2 ?? 02 90 ?? ?? ?? ?? 32 + 90 ?? ?? ?? ?? 88 94 03 ?? ?? ?? ?? 8B 5D ?? 8D 50 ?? 80 E2 ?? 02 90 ?? ?? ?? ?? 32 + 90 ?? ?? ?? ?? 88 94 03 ?? ?? ?? ?? 8D 50 ?? 80 E2 ?? 02 90 ?? ?? ?? ?? 83 C0 ?? 32 + 90 ?? ?? ?? ?? 88 54 06 ?? 83 F8 ?? 0F 8C ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 4D ?? 50 51 + FF 15 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 55 ?? 52 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? C7 45 + ?? ?? ?? ?? ?? FF D6 85 C0 75 ?? 8B 3D ?? ?? ?? ?? 8D 49 ?? 68 ?? ?? ?? ?? FF D7 8D + 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF D6 85 C0 74 ?? 50 FF 15 ?? ?? ?? + ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B FC 85 FF 0F 84 ?? ?? ?? ?? 8B D7 81 EA ?? ?? ?? + ?? 83 C2 ?? 89 55 ?? 8B D7 81 EA ?? ?? ?? ?? 83 C2 ?? 89 55 ?? 8B D7 8B CF 8B F7 81 + } + $encrypt_files_p2 = { + EA ?? ?? ?? ?? 33 C0 81 E9 ?? ?? ?? ?? 81 EE ?? ?? ?? ?? 83 C2 ?? C6 47 ?? ?? 89 55 + ?? 8B 5D ?? 8A D0 80 E2 ?? 02 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 08 ?? ?? ?? ?? + 8D 50 ?? 80 E2 ?? 02 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 30 ?? ?? ?? ?? 8D 50 ?? + 80 E2 ?? 02 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 18 ?? ?? ?? ?? 8B 5D ?? 8D 50 ?? + 80 E2 ?? 02 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 18 ?? ?? ?? ?? 8B 5D ?? 8D 50 ?? + 80 E2 ?? 02 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 18 ?? ?? ?? ?? 8D 50 ?? 80 E2 ?? + 02 90 ?? ?? ?? ?? 83 C0 ?? 32 90 ?? ?? ?? ?? 88 54 07 ?? 83 F8 ?? 0F 8C ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B D8 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B C8 2B 4D ?? + B8 ?? ?? ?? ?? F7 E1 8B CA C1 E9 ?? B8 ?? ?? ?? ?? F7 E1 C1 EA ?? 8B C2 C1 E0 ?? 2B + C2 03 C0 03 C0 2B C8 8B F2 B8 ?? ?? ?? ?? F7 E6 A1 ?? ?? ?? ?? 51 C1 EA ?? 8B CA C1 + E1 ?? 2B CA 03 C9 03 C9 2B F1 56 52 8B 15 ?? ?? ?? ?? 52 50 53 57 E8 ?? ?? ?? ?? 83 + C4 ?? 85 DB 0F 84 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B D8 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B C8 2B + 4D ?? B8 ?? ?? ?? ?? F7 E1 8B CA C1 E9 ?? B8 ?? ?? ?? ?? F7 E1 C1 EA ?? 8B C2 C1 E0 + ?? 2B C2 03 C0 03 C0 2B C8 8B F2 B8 ?? ?? ?? ?? F7 E6 A1 ?? ?? ?? ?? 51 C1 EA ?? 8B + CA C1 E1 ?? 2B CA 03 C9 03 C9 2B F1 56 52 8B 15 ?? ?? ?? ?? 52 50 53 57 E8 ?? ?? ?? + ?? 83 C4 ?? 85 DB 0F 85 ?? ?? ?? ?? 8D 65 ?? 5F 5E 5B 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($enum_resources) and ( all of ($find_files_p*)) and ($encrypt_files) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ($enum_network_resources) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Loocipher : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Ragnarlocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects LooCipher ransomware." + description = "Yara rule that detects RagnarLocker ransomware." author = "ReversingLabs" - id = "b5aa2bd0-72b0-5013-a60e-9b4f1ee1de1f" + id = "3bc3765a-f1f8-59bc-bbe8-6821654b334f" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.LooCipher.yara#L1-L87" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "aa0598d63b5fad6aea0945a0aa2030d3d6e2cd9f1fea16f3dd17cdceb68323e3" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.RagnarLocker.yara#L1-L108" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "398f0e5e003f87edf90cdea718be6b10470df317214d00db4dc6c4cccc5b6748" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -42989,82 +43089,101 @@ rule REVERSINGLABS_Win32_Ransomware_Loocipher : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "LooCipher" + tc_detection_name = "RagnarLocker" tc_detection_factor = 5 importance = 25 strings: - $remote_connection = { - 6A ?? 83 EC ?? 8B CC 89 A5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 B9 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? - 50 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 68 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 - 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? - 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? E8 + $find_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 33 C0 B9 ?? ?? ?? ?? 53 8B 1D ?? ?? ?? ?? 56 8B 75 ?? 57 + 8D BD ?? ?? ?? ?? F3 AB 8B 3D ?? ?? ?? ?? 39 45 ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 8D + 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF 75 + ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF D3 } - $encrypt_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? 53 56 57 8D BD - ?? ?? ?? ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? F3 AB A1 ?? ?? ?? ?? 33 C5 89 45 ?? 50 8D - 45 ?? 64 A3 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? - 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 0F B7 4D ?? 3B C1 74 - ?? E8 ?? ?? ?? ?? 8B F0 8D 4D ?? E8 ?? ?? ?? ?? 8B C8 83 E9 ?? 8B C6 33 D2 F7 F1 89 - 55 ?? 6A ?? 8B 45 ?? 50 8D 8D ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? 8B 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 50 8D 4D ?? E8 - ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 8D 45 ?? 50 8B 4D ?? - E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 C9 ?? 89 8D ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 52 8B CD 50 8D 15 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 58 5A 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? - 33 CD E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 3B EC E8 ?? ?? ?? ?? 8B E5 5D C3 + $find_files_p2 = { + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? 83 FB ?? 75 ?? C7 45 ?? ?? ?? ?? ?? 33 F6 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? FF 74 B5 ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? + ?? 46 83 FE ?? 7C ?? 33 C0 85 C0 0F 85 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 + 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 FF 75 ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 + FF D6 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 FF D6 6A ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF D6 6A ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? + ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? + ?? ?? 8B 45 ?? 8B 1D ?? ?? ?? ?? 8B 75 ?? 50 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + 56 FF D3 } - $find_files = { - 52 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 0F B6 85 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? B9 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 0F B6 C0 85 C0 0F 84 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8B F4 89 - A5 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 50 ?? 52 8B 00 50 8B CE E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C6 45 ?? ?? B9 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 6A ?? 8D 8D ?? ?? ?? ?? 51 C6 45 ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 89 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 - B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - 68 ?? ?? ?? ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? EB ?? 83 EC ?? 8B CC - 89 A5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 - B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 8D - ?? ?? ?? ?? 89 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? EB + $find_files_p3 = { + 33 F6 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 90 FF 74 B5 ?? + 53 FF D7 85 C0 74 ?? 46 83 FE ?? 72 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 8B 45 ?? 8B 75 ?? 8D 8D ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? E9 + ?? ?? ?? ?? 5F 5E 32 C0 5B 8B E5 5D C3 FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E B0 ?? 5B 8B + E5 5D C3 + } + $encrypt_files_p1 = { + 56 8B 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 83 C4 ?? 68 ?? ?? ?? ?? 50 FF D7 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D7 56 8B 35 ?? ?? + ?? ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 FF D6 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 68 ?? ?? ?? ?? FF D6 FF 75 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8B F0 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? + ?? ?? 8B F8 C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? 56 8D 85 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 + } + $encrypt_files_p2 = { + 8D 45 ?? 50 57 68 ?? ?? ?? ?? 56 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? + 57 50 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? 8B 35 ?? ?? ?? + ?? 8D 4D ?? 6A ?? 51 FF 75 ?? FF 75 ?? 50 FF D6 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 + C4 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 50 8D 85 ?? ?? ?? ?? + 50 FF 75 ?? FF D6 8B 45 ?? 50 FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? FF D0 FF 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BF ?? ?? + ?? ?? 89 45 ?? 8D 57 ?? 8B CF D3 E8 A8 ?? 0F 84 ?? ?? ?? ?? 8D 47 ?? C7 45 ?? ?? ?? + ?? ?? 66 89 45 ?? 33 F6 33 C0 50 50 50 50 50 68 ?? ?? ?? ?? 50 66 89 45 ?? 8D 45 ?? + 50 FF 15 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? + ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 66 8B 85 ?? ?? ?? ?? 66 3B 45 ?? 75 ?? 66 8B 85 ?? ?? ?? ?? 66 3B 45 ?? B8 ?? ?? + ?? ?? 0F 44 F0 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? + ?? ?? ?? 83 EF ?? 8B 45 ?? 0F 89 ?? ?? ?? ?? 0F 57 C0 C7 85 + } + $encrypt_files_p3 = { + 0F 29 85 ?? ?? ?? ?? 0F 29 85 ?? ?? ?? ?? 0F 29 85 ?? ?? ?? ?? 0F 29 85 ?? ?? ?? ?? + 0F 29 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 68 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? 6A ?? 68 + ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A ?? FF 75 ?? FF 15 ?? ?? + ?? ?? B8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 6A ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 + FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? + 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 + C0 74 ?? FF 75 ?? 8B 35 ?? ?? ?? ?? FF D6 FF 75 ?? FF D6 6A ?? FF 15 } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($remote_connection) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -import "pe" - -rule REVERSINGLABS_Win32_Ransomware_Archiveus : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Nemty : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Archiveus ransomware." + description = "Yara rule that detects Nemty ransomware." author = "ReversingLabs" - id = "89e5af93-1153-5367-a539-6af77c99c214" + id = "c56ecd32-5903-5bcc-aa69-a070f2c247c4" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Archiveus.yara#L3-L50" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "2b8a42b98ab3e8b97d2e226e979f342a6a72f21d8f068f59c21ad95764077f8a" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Nemty.yara#L1-L205" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "dc8cfdcdea8ecb2018b1b04bb1b645f6dbdc6c07357719100677c75945edef40" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -43072,48 +43191,184 @@ rule REVERSINGLABS_Win32_Ransomware_Archiveus : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Archiveus" + tc_detection_name = "Nemty" tc_detection_factor = 5 importance = 25 strings: - $entry_point = { - 68 ?? ?? 40 00 E8 ?? ?? ?? FF + $remote_connection_p1 = { + 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 33 DB 68 ?? ?? ?? ?? 8D 75 + ?? 89 5D ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? 83 78 ?? ?? 59 59 72 ?? 8B 00 + 53 53 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 33 FF 8D 75 ?? E8 ?? ?? ?? ?? 6A + ?? 8D 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 75 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? + ?? ?? ?? 83 78 ?? ?? 59 59 72 ?? 8B 00 53 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? + ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 32 DB EB ?? B3 ?? 6A ?? 33 FF 8D 75 ?? E8 ?? ?? ?? ?? + 6A ?? 8D 75 ?? E8 ?? ?? ?? ?? 84 DB 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 75 ?? E8 ?? + ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? 83 78 ?? ?? 59 59 72 ?? 8B 00 8B 1D ?? ?? ?? ?? + 50 FF D3 6A ?? 33 FF 8D 75 ?? 89 45 ?? E8 ?? ?? ?? ?? 6A ?? 8D 75 ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 75 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? 83 78 ?? ?? 59 59 + 72 ?? 8B 00 50 FF D3 33 DB 43 53 33 FF 8D 75 ?? 89 45 ?? E8 ?? ?? ?? ?? 53 8D 75 ?? + E8 ?? ?? ?? ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 59 59 FF 75 ?? FF } - $dump_instruction = { - 8B 3D ?? ?? ?? ?? 6A ?? FF D7 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 - 74 ?? 8B 46 ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D0 8D 4D ?? FF 15 ?? ?? ?? ?? - 50 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A - ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF D7 FF 15 ?? ?? ?? ?? E9 ?? ?? - ?? ?? 8D 4D ?? 51 FF 15 ?? ?? ?? ?? 8D 55 ?? 6A ?? 52 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? - ?? ?? 6A ?? 6A ?? 6A ?? 8D 45 ?? 68 ?? ?? ?? ?? 8D 4D ?? 50 51 FF D3 50 8D 55 ?? 8D - 45 ?? 52 50 FF D3 50 FF 15 + $remote_connection_p2 = { + D6 FF 75 ?? FF D6 68 ?? ?? ?? ?? 8D 75 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? + 83 78 ?? ?? 59 59 72 ?? 8B 00 50 FF 15 ?? ?? ?? ?? 53 33 FF 8D 75 ?? E8 ?? ?? ?? ?? + 53 8D 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 75 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? + ?? ?? ?? 83 78 ?? ?? 59 59 72 ?? 8B 00 33 C9 51 51 51 50 68 ?? ?? ?? ?? 51 FF 15 ?? + ?? ?? ?? 53 33 FF 8D 75 ?? E8 ?? ?? ?? ?? 53 8D 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 8B 4D ?? 6A ?? 5A 8B C1 39 55 ?? 73 ?? 8D 45 ?? 03 45 ?? 39 55 ?? + 73 ?? 8D 4D ?? EB ?? 80 39 ?? 75 ?? C6 01 ?? 41 3B C8 75 ?? 8B 45 ?? 39 55 ?? 73 ?? + 8D 45 ?? 03 45 ?? 8B 4D ?? 39 55 ?? 73 ?? 8D 4D ?? EB ?? 80 39 ?? 75 ?? C6 01 ?? 41 + 3B C8 75 ?? 8B 45 ?? 39 55 ?? 73 ?? 8D 45 ?? 03 45 ?? 8B 4D ?? 39 55 ?? 73 ?? 8D 4D + ?? EB ?? 80 39 ?? 75 ?? C6 01 ?? 41 3B C8 75 ?? 83 EC ?? 8D 45 ?? 8B F4 50 E8 ?? ?? + ?? ?? 83 EC ?? 8B F4 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 33 + FF 8D 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 } - $extension_rule = { - 8B 13 6A ?? 68 ?? ?? ?? ?? 52 50 FF 15 ?? ?? ?? ?? D9 85 ?? ?? ?? ?? DB 85 ?? ?? ?? - ?? DD 9D ?? ?? ?? ?? DC 8D ?? ?? ?? ?? DF E0 A8 ?? 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? DC 05 ?? ?? ?? ?? DF E0 A8 ?? 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 4D ?? 89 45 - ?? FF 15 ?? ?? ?? ?? 8B 46 ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D0 8D 4D ?? FF - 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D0 8D 4D ?? FF 15 ?? ?? ?? ?? - 50 6A ?? 6A ?? 6A ?? FF 15 + $enum_resources_p1 = { + 55 8B EC 83 E4 ?? 83 EC ?? A1 ?? ?? ?? ?? 33 C4 89 44 24 ?? 53 56 57 FF 15 ?? ?? ?? + ?? 83 64 24 ?? ?? 89 44 24 ?? BB ?? ?? ?? ?? 8B 54 24 ?? 8B 4C 24 ?? D3 EA 33 C0 40 + 23 D0 0F 84 ?? ?? ?? ?? 83 64 24 ?? ?? 6A ?? 80 C1 ?? 5F 88 4C 24 ?? FF 74 24 ?? 8D + 74 24 ?? 89 7C 24 ?? C6 44 24 ?? ?? E8 ?? ?? ?? ?? 83 64 24 ?? ?? 8B 74 24 ?? 53 89 + 7C 24 ?? C6 44 24 ?? ?? E8 ?? ?? ?? ?? 59 03 C6 8D 4C 24 ?? E8 ?? ?? ?? ?? 6A ?? 8D + 44 24 ?? 50 83 C8 ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 8B F8 53 8B C6 + E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 8B 44 24 ?? 73 ?? 8B C6 50 FF 15 ?? ?? ?? ?? 6A ?? 33 + FF 8D 74 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? 59 + 8B F8 53 8D 44 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? + 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? 59 8B F8 53 + 8D 44 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 + } + $enum_resources_p2 = { + 8D 44 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 33 FF 8D + 74 24 ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 53 E8 ?? ?? ?? ?? 59 8B F8 53 8D 44 24 + ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 + ?? E8 ?? ?? ?? ?? 8D 44 24 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 33 FF 8D 74 24 ?? + E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 8B 44 24 ?? 73 ?? 8D 44 24 ?? 6A ?? 8D 4C 24 ?? 51 8D + 4C 24 ?? 51 50 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 0F AC C8 ?? 89 44 24 ?? 8D + 44 24 ?? BE ?? ?? ?? ?? C1 E9 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 0F AC C8 ?? + 89 44 24 ?? 8D 44 24 ?? BE ?? ?? ?? ?? C1 E9 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 2B 44 24 + ?? 8B 4C 24 ?? 1B 4C 24 ?? BE ?? ?? ?? ?? 0F AC C8 ?? 89 44 24 ?? 8D 44 24 ?? C1 E9 + ?? E8 ?? ?? ?? ?? 6A ?? 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? FF 44 24 ?? 83 7C 24 ?? ?? + 0F 8C ?? ?? ?? ?? 8B 4C 24 ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $find_files_1_p1 = { + 6A ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 + 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? + E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? + 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D + 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? + ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 + } + $find_files_1_p2 = { + C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 + ?? E8 ?? ?? ?? ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? + ?? 59 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 0F + 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 75 ?? 68 ?? ?? ?? + ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 75 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? + ?? 59 84 C0 75 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 75 ?? 68 ?? ?? + ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 59 84 C0 75 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? + ?? ?? 59 84 C0 75 ?? 83 EC ?? 8D 44 24 ?? 8B F4 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 6A ?? 33 FF 8D 74 24 ?? E8 ?? ?? ?? ?? 6A ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 8D 84 + 24 ?? ?? ?? ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? + FF 15 + } + $find_files_2_p1 = { + 8D 44 24 ?? 8D 8C 24 ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 + ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F + 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? + ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 + 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? BF ?? ?? ?? ?? 57 8D + 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 57 8D 84 24 ?? ?? ?? ?? 50 FF D6 + 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 + 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 + } + $find_files_2_p2 = { + 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 + 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? + ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? E8 ?? + ?? ?? ?? 83 4C 24 ?? ?? 83 EC ?? 8B C4 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 4C + 24 ?? 8B C4 51 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 84 24 ?? ?? + ?? ?? 50 8D 44 24 ?? E8 ?? ?? ?? ?? 83 4C 24 ?? ?? 83 EC ?? 8B C4 68 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 EC ?? 8D 8C 24 ?? ?? ?? ?? 8B C4 51 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? + 83 C4 ?? 85 C0 75 ?? 32 DB EB ?? B3 ?? F6 44 24 ?? ?? 74 ?? 83 64 24 ?? ?? 6A ?? 33 + FF 8D 74 24 ?? E8 ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? 83 64 24 ?? ?? 6A ?? 33 FF 8D 74 + } + $find_files_2_p3 = { + 24 ?? E8 ?? ?? ?? ?? 84 DB 0F 85 ?? ?? ?? ?? F6 84 24 ?? ?? ?? ?? ?? 8D 84 24 ?? ?? + ?? ?? 50 0F 84 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B F0 8B + 46 ?? 59 83 C9 ?? 2B C8 83 F9 ?? 0F 86 ?? ?? ?? ?? 8D 58 ?? 6A ?? 8B C6 E8 ?? ?? ?? + ?? 84 C0 74 ?? 83 7E ?? ?? 8B 4E ?? 72 ?? 8B 06 EB ?? 8B C6 6A ?? 5A 66 89 14 48 83 + 7E ?? ?? 89 5E ?? 72 ?? 8B 06 EB ?? 8B C6 33 C9 66 89 0C 58 8B DE 8D 74 24 ?? E8 ?? + ?? ?? ?? 8B DE 8D 44 24 ?? E8 ?? ?? ?? ?? 6A ?? 33 FF E8 ?? ?? ?? ?? 6A ?? 8D 74 24 + ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 44 24 ?? 8B F4 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 44 + 24 ?? 8B F4 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8D 44 24 ?? E8 + ?? ?? ?? ?? 8D 44 24 ?? 50 8D 44 24 ?? E8 ?? ?? ?? ?? 59 6A ?? 33 FF 8D 74 24 ?? E8 + ?? ?? ?? ?? 6A ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 40 33 C9 8D 74 24 ?? E8 ?? ?? ?? ?? 8D + 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 44 24 ?? E8 ?? ?? + ?? ?? 59 6A ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 40 33 C9 + 8D 74 24 ?? E8 + } + $encrypt_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 8B D9 33 F6 C7 43 ?? + ?? ?? ?? ?? 89 73 ?? C6 03 ?? A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 57 2B C1 6A ?? 99 5F + F7 FF 89 9D ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? 85 C0 74 ?? 89 B5 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 83 EC ?? 03 C1 8B F4 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A + ?? 50 83 C8 ?? 8B F3 E8 ?? ?? ?? ?? 6A ?? 33 FF 8D 75 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? + ?? 8B 0D ?? ?? ?? ?? 2B C1 6A ?? 99 5E F7 FE FF 85 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? + 39 85 ?? ?? ?? ?? 72 ?? 8B 53 ?? 6A ?? 5F C6 85 ?? ?? ?? ?? ?? 3B D7 72 ?? 8B 0B EB + ?? 8B CB 8B 43 ?? 03 C1 3B D7 72 ?? 8B 0B EB ?? 8B CB 50 51 8D 85 ?? ?? ?? ?? 50 8D + 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 39 7B ?? 72 ?? 8B 03 EB ?? 8B C3 8B 5B ?? 8B + B5 ?? ?? ?? ?? 03 D8 53 FF B5 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B + 4E ?? C6 85 ?? ?? ?? ?? ?? 3B CF 72 ?? 8B 16 EB ?? 8B D6 8B 46 ?? 03 C2 3B CF 72 ?? + 8B 0E EB ?? 8B CE 50 51 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 39 7E ?? 72 ?? 8B 0E EB ?? 8B CE 8B 46 ?? 03 C1 50 FF B5 ?? ?? ?? ?? 8D 9D ?? ?? + ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B 46 ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B 4E + } + $encrypt_files_p2 = { + 89 85 ?? ?? ?? ?? 3B CF 72 ?? 8B 16 EB ?? 8B D6 8B 46 ?? 03 C2 3B CF 72 ?? 8B 0E EB + ?? 8B CE 3B C8 74 ?? 8B B5 ?? ?? ?? ?? 2B F1 8A 11 88 14 0E 41 3B C8 75 ?? 8D 45 ?? + 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 75 ?? 8B F8 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 50 8D 45 ?? E8 ?? ?? ?? ?? 8B F0 8B 46 ?? 8B 56 ?? 59 59 8B 4F ?? 2B C2 3B C8 76 ?? + 8B 47 ?? 2B C1 3B C2 72 ?? 56 8B F7 E8 ?? ?? ?? ?? EB ?? 6A ?? 57 83 C8 ?? E8 ?? ?? + ?? ?? 8B D8 8D 75 ?? E8 ?? ?? ?? ?? 8B C6 68 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 78 ?? ?? 59 59 72 ?? 8B 00 33 DB 53 68 ?? ?? ?? ?? 6A ?? 53 53 68 ?? ?? + ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 33 FF 8D B5 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 6A ?? 8D 75 ?? E8 ?? ?? ?? ?? 6A ?? 8D 75 ?? E8 ?? ?? ?? ?? 6A ?? 8D 75 ?? E8 + ?? ?? ?? ?? 6A ?? 8D 75 ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 3B F3 74 ?? 53 53 53 56 + FF 15 ?? ?? ?? ?? 53 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 56 FF + 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 59 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 } - $instruction_string = "INSTRUCTIONS HOW TO GET YOUR FILES BACK.txt" wide condition: - uint16(0)==0x5A4D and ($entry_point at pe.entry_point) and $dump_instruction and $extension_rule and $instruction_string + uint16(0)==0x5A4D and ( all of ($find_files_1_p*)) and ( all of ($find_files_2_p*)) and ( all of ($enum_resources_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Moisha : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Farattack : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Moisha ransomware." + description = "Yara rule that detects FarAttack ransomware." author = "ReversingLabs" - id = "c72f654f-955e-5ff6-ac91-19fbb858265c" - date = "2022-10-11" - modified = "2022-10-11" + id = "7ee7121a-4ca2-513c-96dc-53b5c48d719f" + date = "2022-06-21" + modified = "2022-06-21" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Moisha.yara#L1-L86" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "89cefbbb8ec722216721bb43eb14cc33fcd4671585051359a06b62236cbf3a6c" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.FarAttack.yara#L1-L93" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "af22b8110c2b545f083b443c7a1fa7e7639324e9188eefadfe1fe70ebb1bb7fb" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -43121,77 +43376,85 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Moisha : TC_DETECTION MALICIOUS MALW sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Moisha" + tc_detection_name = "FarAttack" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 73 ?? ?? ?? ?? 0A 02 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 2B ?? 07 6F ?? ?? ?? ?? 0C 08 28 - ?? ?? ?? ?? 2D ?? 06 08 6F ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 2D ?? DE ?? 07 2C ?? 07 6F ?? - ?? ?? ?? DC DE ?? 26 DE ?? 06 2A - } - $find_files_p2 = { - 02 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 0A 06 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? - 0B 2B ?? 07 6F ?? ?? ?? ?? 0C 08 6F ?? ?? ?? ?? 0D 03 09 6F ?? ?? ?? ?? 04 2C ?? 04 09 - 6F ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 2D ?? DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC 06 6F ?? ?? - ?? ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 03 04 - 28 ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 6F ?? ?? ?? ?? 2D ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? - ?? ?? ?? DC 02 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 03 11 ?? 6F ?? ?? ?? ?? 04 2C ?? 04 - 11 ?? 6F ?? ?? ?? ?? 2A + $find_files = { + 56 FF 73 ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 50 FF 15 ?? ?? ?? ?? 56 E8 ?? + ?? ?? ?? 59 6A ?? 58 E9 ?? ?? ?? ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 03 C7 89 + 45 ?? 3D ?? ?? ?? ?? 0F 8D ?? ?? ?? ?? F7 06 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 4E ?? + 51 68 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 83 F8 ?? 0F 84 ?? ?? ?? ?? F6 06 ?? 74 ?? 8B 45 ?? 8D 04 45 ?? ?? ?? ?? 50 8D 46 ?? + 50 8B 43 ?? 8D 04 78 83 C0 ?? 50 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 83 C4 ?? 8B 53 ?? + 8B 75 ?? 8B 01 53 89 44 72 ?? 66 8B 41 ?? 8B CE 66 89 44 4A ?? FF 43 ?? 83 63 ?? ?? + E8 ?? ?? ?? ?? FF 4B ?? 83 63 ?? ?? 8B 75 ?? E9 ?? ?? ?? ?? 83 7B ?? ?? 75 ?? FF 73 + ?? FF 73 ?? FF 73 ?? FF 73 ?? 57 FF 73 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? C7 43 + ?? ?? ?? ?? ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? + ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 8D + 04 45 ?? ?? ?? ?? 50 8D 46 ?? 50 8B 43 ?? 8D 04 78 83 C0 ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 83 7E ?? ?? 75 ?? 83 7E ?? ?? 74 ?? 6A ?? E8 ?? ?? ?? ?? 8B F8 8B 45 ?? 8D 34 00 + 8D 4E ?? 51 E8 ?? ?? ?? ?? 56 89 07 FF 73 ?? 50 E8 ?? ?? ?? ?? 8B 07 33 C9 83 C4 ?? + 66 89 0C 06 8B 75 ?? 51 57 51 8B 46 ?? 89 47 ?? 8B 46 ?? 89 47 ?? 8B 45 ?? 89 47 ?? + FF 73 ?? FF 15 ?? ?? ?? ?? 8B 7D ?? 8B 4B ?? A1 ?? ?? ?? ?? 89 44 79 ?? 66 A1 ?? ?? + ?? ?? 66 89 44 79 ?? 56 FF 75 ?? FF 15 } - $find_files_p3 = { - 73 ?? ?? ?? ?? 0A 06 03 7D ?? ?? ?? ?? 06 04 7D ?? ?? ?? ?? 06 05 7D ?? ?? ?? ?? 02 28 - ?? ?? ?? ?? 39 ?? ?? ?? ?? 06 02 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 06 7B ?? - ?? ?? ?? 2C ?? 06 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 31 ?? 06 7B ?? ?? ?? ?? 2C ?? 06 FE - 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0B 07 17 6F ?? ?? ?? ?? 07 17 6F ?? ?? ?? - ?? 7E ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 07 6F ?? ?? ?? ?? DE ?? 26 DE ?? 02 28 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 2B ?? 12 ?? 28 ?? ?? ?? ?? 0D 09 6F ?? ?? ?? ?? 06 7B - ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 12 ?? 28 - ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? DC 2A + $create_key = { + 55 8B EC 56 6A ?? E8 ?? ?? ?? ?? 8B F0 59 85 F6 75 ?? 32 C0 EB ?? A1 ?? ?? ?? ?? 53 + 33 DB 85 C0 74 ?? 53 6A ?? 53 53 56 FF D0 EB ?? 8A C3 84 C0 75 ?? FF 15 ?? ?? ?? ?? + 3D ?? ?? ?? ?? 75 ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 6A ?? 53 53 56 FF D0 8A D8 84 + DB 75 ?? 56 E8 ?? ?? ?? ?? 59 32 C0 EB ?? 8B 4D ?? B0 ?? 89 71 ?? 5B 5E 5D C3 } - $import_priv_key = { - 02 73 ?? ?? ?? ?? 13 ?? 11 ?? 73 ?? ?? ?? ?? 13 ?? 16 13 ?? 16 13 ?? 16 13 ?? 11 ?? 6F - ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? 33 ?? 11 ?? 6F ?? ?? ?? ?? 26 2B ?? 11 ?? 20 ?? - ?? ?? ?? 33 ?? 11 ?? 6F ?? ?? ?? ?? 26 2B ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 11 ?? 6F - ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? 2E ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 11 ?? 6F - ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 11 ?? 28 ?? ?? ?? ?? 13 - ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 0A 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? - 0B 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 0C 11 ?? 28 ?? ?? ?? ?? 13 ?? - 11 ?? 11 ?? 6F ?? ?? ?? ?? 0D 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 13 - ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 - ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? - ?? 13 ?? 12 ?? FE 15 ?? ?? ?? ?? 12 ?? 06 7D ?? ?? ?? ?? 12 ?? 07 7D ?? ?? ?? ?? 12 ?? - 08 7D ?? ?? ?? ?? 12 ?? 09 7D ?? ?? ?? ?? 12 ?? 11 ?? 7D ?? ?? ?? ?? 12 ?? 11 ?? 7D ?? - ?? ?? ?? 12 ?? 11 ?? 7D ?? ?? ?? ?? 12 ?? 11 ?? 7D ?? ?? ?? ?? 11 ?? 13 ?? DE ?? 11 ?? - 6F ?? ?? ?? ?? DC 11 ?? 2A + $encrypt_files_p1 = { + 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B F8 89 7D ?? 83 + FF ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 0B 45 ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 48 ?? 8B 40 + ?? 83 C1 ?? 03 C1 8B 5D ?? 89 5D ?? 8B 4D ?? 89 4D ?? 99 03 D8 89 5D ?? 13 CA 89 4D + ?? 8B 55 ?? 8B 45 ?? 85 D2 7C ?? 7F ?? 3D ?? ?? ?? ?? 76 ?? 89 75 ?? EB ?? 83 65 ?? + ?? 85 D2 7C ?? 7F ?? 3D ?? ?? ?? ?? 76 ?? 89 75 ?? EB ?? 83 65 ?? ?? C7 45 ?? ?? ?? + ?? ?? 83 7D ?? ?? 74 ?? 6A ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 59 89 4D ?? 51 + 52 50 E8 ?? ?? ?? ?? 89 45 ?? 89 55 ?? 8B 4D ?? 6A ?? 53 51 6A ?? 6A ?? 57 FF 15 ?? + ?? ?? ?? 8B D8 89 5D ?? 85 DB 0F 84 ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? B8 ?? ?? + ?? ?? 89 45 ?? 89 45 ?? 33 C9 8B C1 89 45 ?? 89 45 ?? 89 4D ?? 89 4D ?? 89 45 ?? 89 + 45 ?? 89 4D ?? 8B 4D ?? FF 71 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 4D ?? FF 71 ?? FF 71 ?? 8D 41 ?? 50 + FF 71 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 8B 55 ?? 85 C0 } - $encrypt_files = { - 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? 0A 14 0B 14 0C 16 0D 20 ?? ?? ?? ?? 13 ?? 03 19 17 1D 28 - ?? ?? ?? ?? 0B 03 19 18 1D 28 ?? ?? ?? ?? 0C 02 7B ?? ?? ?? ?? 08 17 6F ?? ?? ?? ?? 13 - ?? 07 06 16 06 8E 69 6F ?? ?? ?? ?? 13 ?? 11 ?? 16 31 ?? 11 ?? 06 16 11 ?? 6F ?? ?? ?? - ?? 11 ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 04 11 ?? 6F ?? ?? ?? ?? 04 6F ?? ?? ?? ?? - 13 ?? 11 ?? 8E 69 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 08 08 6F ?? ?? ?? ?? 16 6F ?? ?? ?? - ?? 26 08 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 08 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 08 - 6F ?? ?? ?? ?? 17 0D DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC DE ?? 13 ?? DE ?? 07 2C - ?? 07 6F ?? ?? ?? ?? 08 2C ?? 08 6F ?? ?? ?? ?? 09 26 DC 2A + $encrypt_files_p2 = { + 75 ?? 89 55 ?? 21 45 ?? 8B CE 89 4D ?? 89 4D ?? EB ?? 8B 4D ?? 3B 4D ?? 0F 8D ?? ?? + ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 85 C9 74 ?? 83 7D ?? ?? 74 ?? 8D 41 ?? 3B 45 ?? 74 ?? + 8B C1 99 FF 75 ?? FF 75 ?? 52 50 E8 ?? ?? ?? ?? 8B C8 89 45 ?? C7 45 ?? ?? ?? ?? ?? + EB ?? 8B CA 81 E9 ?? ?? ?? ?? 89 4D ?? 8B 55 ?? 83 DA ?? 83 65 ?? ?? 89 55 ?? 6A ?? + 8B 45 ?? FF 70 ?? 52 51 E8 ?? ?? ?? ?? 6A ?? 8B 4D ?? FF 71 ?? 52 50 E8 ?? ?? ?? ?? + 8B C8 89 4D ?? 89 55 ?? 8B 45 ?? 2B C1 89 45 ?? 8B 4D ?? 1B CA 89 45 ?? 89 4D ?? EB + ?? 8B 55 ?? 8B C2 C1 F8 ?? FF 75 ?? FF 75 ?? 52 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? + 89 45 ?? 85 C0 75 ?? 50 FF 75 ?? FF 75 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 57 FF 15 ?? ?? + ?? ?? 8B 75 ?? 8B 7D ?? 83 4D ?? ?? E8 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 45 + ?? E8 ?? ?? ?? ?? C3 03 45 ?? 56 6A ?? 8D 4D ?? 51 50 FF 75 ?? 50 6A ?? 6A ?? 8D 85 + ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 45 ?? 40 + 89 45 ?? 3B 45 ?? 75 ?? 8B 75 ?? FF 76 ?? FF 76 ?? 8B 45 ?? 03 45 ?? 03 45 ?? 50 E8 + ?? ?? ?? ?? FF 76 ?? FF 76 ?? 8B 46 ?? 03 45 ?? 03 45 ?? 03 45 ?? 50 E8 ?? ?? ?? ?? + 83 C4 ?? 8B 7E ?? 03 7E ?? 03 7D ?? 03 7D ?? 8B 45 ?? 03 F8 8D 75 ?? A5 A5 A5 A5 6A + ?? 50 FF 15 ?? ?? ?? ?? 8B 7D ?? 33 F6 46 FF 75 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 89 4D + ?? 8B 55 ?? 8B 45 ?? E9 ?? ?? ?? ?? 53 8B 35 ?? ?? ?? ?? FF D6 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($import_priv_key) and ($encrypt_files) + uint16(0)==0x5A4D and ($find_files) and ($create_key) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Delphimorix : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Timecrypt : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Delphimorix ransomware." + description = "Yara rule that detects TimeCrypt ransomware." author = "ReversingLabs" - id = "1f964601-9819-5597-ba6e-db3a30e3aa5a" - date = "2020-07-15" - modified = "2020-07-15" + id = "38a0c383-8be6-5258-aa93-0cf09b18e5f7" + date = "2021-12-06" + modified = "2021-12-06" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Delphimorix.yara#L1-L67" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6d401d488d57b2d75e93a1dfd47ece687a5791d1f0a52768300f4af8a8787212" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.TimeCrypt.yara#L1-L69" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6849d6d5010d7bcb4052c10d5bd7cc29320ffc986f36289b272a1e9a8d14fab9" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -43199,63 +43462,58 @@ rule REVERSINGLABS_Win32_Ransomware_Delphimorix : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Delphimorix" + tc_detection_name = "TimeCrypt" tc_detection_factor = 5 importance = 25 strings: + $find_files = { + 7E ?? ?? ?? ?? 0A 16 0B 38 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0C 08 06 07 9A 7D ?? ?? ?? ?? 73 + ?? ?? ?? ?? 0D 09 08 7D ?? ?? ?? ?? 09 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 7D ?? ?? ?? ?? 09 + 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 28 ?? + ?? ?? ?? 09 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 09 7B ?? ?? + ?? ?? 72 ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 09 7B ?? ?? ?? ?? 7B ?? ?? ?? ?? + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 2B ?? 09 7B ?? ?? ?? ?? 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 2C ?? 1B 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 2B ?? 1F ?? 28 ?? ?? ?? ?? 73 + ?? ?? ?? ?? 13 ?? 11 ?? 2D ?? 2A 11 ?? 6F ?? ?? ?? ?? 09 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 26 11 ?? 6F ?? ?? ?? ?? 09 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 26 07 17 58 0B 07 06 8E 69 3F ?? ?? ?? ?? 2A + } $encrypt_files = { - 55 8B EC 83 C4 ?? 53 56 57 33 D2 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 - 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 6A ?? 8B - 4D ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 68 ?? ?? ?? ?? 8D 45 ?? B9 ?? ?? ?? - ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 4D ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8B C3 - 8B 10 FF 12 52 50 B9 ?? ?? ?? ?? 8B D3 8B C6 E8 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B - C6 E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 - ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 59 59 5D C3 + 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 73 ?? ?? ?? ?? 0A 06 03 6F ?? ?? ?? ?? 06 02 6F + ?? ?? ?? ?? 26 06 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 06 2C ?? 06 6F + ?? ?? ?? ?? DC 02 17 28 ?? ?? ?? ?? DE ?? 26 DE ?? 2A } - $find_files_p1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? - ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 8B D9 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? - ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 80 7C 02 - ?? ?? 75 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B D0 4A 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? - ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 8B D0 83 CA ?? 3B D0 75 ?? 80 FB ?? 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 + $send_http_request = { + 1C 8D ?? ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 02 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 + 03 A2 25 1A 72 ?? ?? ?? ?? A2 25 1B 04 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 0A 73 ?? ?? ?? + ?? 25 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 6F + ?? ?? ?? ?? 26 DE ?? 26 DE ?? 2A } - $find_files_p2 = { - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CB 8B 55 ?? E8 ?? ?? ?? ?? E9 ?? - ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B - C6 83 C8 ?? 3B C6 75 ?? 80 FB ?? 75 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? FF 75 ?? 68 ?? ?? ?? - ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 8B CB 8B 55 ?? E8 ?? ?? ?? ?? EB ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? - ?? ?? ?? C3 + $send_dns_request = { + 1C 8D ?? ?? ?? ?? 25 16 04 28 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 03 A2 25 19 + 72 ?? ?? ?? ?? A2 25 1A 02 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? + 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? A2 25 1B 72 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 26 DE ?? 26 DE ?? 2A } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($send_http_request) and ($send_dns_request) } -rule REVERSINGLABS_Win32_Ransomware_Velso : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Afrodita : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Velso ransomware." + description = "Yara rule that detects Afrodita ransomware." author = "ReversingLabs" - id = "72c7baaa-4f83-54c5-ba71-2b45e5eeefd2" + id = "513963fd-5f3d-5d31-a65a-37f6f5c72260" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Velso.yara#L1-L230" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "602be848a26106a1bd46cfc515578f0628687e6cb352e609a274220a61bcb620" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Afrodita.yara#L1-L119" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ce7cc445d4c1f59c25b9505fc1f7f9dd0d286ab80510e2977b50ff15433aea60" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -43263,616 +43521,352 @@ rule REVERSINGLABS_Win32_Ransomware_Velso : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Velso" + tc_detection_name = "Afrodita" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 55 89 E5 81 EC ?? ?? ?? ?? 8D 45 ?? 89 A5 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 75 ?? C6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 89 04 24 E8 ?? ?? ?? ?? 0F B6 85 ?? ?? ?? ?? C9 C3 C7 04 24 ?? ?? ?? ?? 8B 4D ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? C7 04 24 ?? ?? ?? - ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? - ?? ?? ?? 83 EC ?? 85 C0 74 ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 EC ?? - 85 C0 74 ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 84 ?? ?? - ?? ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 84 ?? ?? ?? ?? - C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 84 ?? ?? ?? ?? C7 04 - 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 85 C0 51 0F 84 ?? ?? ?? ?? C7 04 24 ?? ?? ?? - ?? 8B 4D ?? E8 ?? ?? ?? ?? 85 C0 52 0F 84 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? - E8 ?? ?? ?? ?? 85 C0 51 0F 84 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? - ?? 85 C0 52 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? - ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 04 24 8B 4D ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 39 D0 74 ?? 89 - 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? - 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 44 24 + $exclude_directories_and_drop_ransom_note = { + 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8D 8D ?? ?? + ?? ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? ?? ?? 8D 95 ?? + ?? ?? ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? + ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 75 ?? E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B + 55 ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? + ?? ?? 89 8D ?? ?? ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8D 4D ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A + ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D + 4D ?? E8 ?? ?? ?? ?? EB ?? B8 } - $find_files_p2 = { - 8B 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 52 52 8D 95 - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? - EB ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 52 52 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 51 51 74 ?? - 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 85 C0 52 52 74 ?? - F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 4D ?? 89 85 ?? ?? ?? ?? - 8B 45 ?? 8B 51 ?? 8D 8D ?? ?? ?? ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 51 51 89 44 24 ?? 8B 45 ?? 89 44 24 - ?? 8D 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 39 D0 74 ?? 89 04 - 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 39 D0 0F 84 ?? ?? ?? ?? 89 04 - 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? - 8D 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 89 - 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? EB - ?? 83 C5 ?? 83 BD ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 0F 87 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? FF 24 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 - } - $enum_resources_p1 = { - 55 89 E5 81 EC ?? ?? ?? ?? 8D 45 ?? 89 65 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 45 ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 EC ?? 85 C0 74 ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 - ?? C9 C2 ?? ?? 8B 45 ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 EC ?? 85 C0 89 85 ?? ?? ?? ?? 74 ?? 90 8D B4 26 ?? ?? ?? ?? 8B 45 ?? C7 - 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D 55 ?? - 89 54 24 ?? 8B 85 ?? ?? ?? ?? 8D 55 ?? 89 54 24 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 C7 - 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 - 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 EC ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? - 85 C0 0F 94 C0 0F B6 C0 89 45 ?? E9 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B - } - $enum_resources_p2 = { - 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 45 ?? EB ?? 8B 45 ?? 8B 40 ?? 89 85 - ?? ?? ?? ?? 83 E0 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 83 45 ?? ?? 8B - 85 ?? ?? ?? ?? 39 45 ?? 0F 86 ?? ?? ?? ?? 8B 45 ?? F6 40 ?? ?? 74 ?? 8D 45 ?? 8B 4D - ?? 89 45 ?? 8B 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 83 EC ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? - 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 83 EC ?? 39 D0 0F 84 - ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 8D 45 ?? 8B - 4D ?? 89 45 ?? 8B 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 EC ?? 8B 40 ?? 89 C2 89 85 ?? ?? ?? ?? 8D 45 - ?? 85 D2 89 45 ?? B8 ?? ?? ?? ?? 74 ?? 89 14 24 E8 ?? ?? ?? ?? 03 85 ?? ?? ?? ?? 89 - 44 24 ?? 8B 85 ?? ?? ?? ?? 8D 4D ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 45 ?? 83 EC ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D - 55 ?? 39 D0 0F 84 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 - } - $encrypt_files_p1 = { - 55 89 E5 81 EC ?? ?? ?? ?? 8D 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 A5 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? - C6 45 ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 - 45 ?? ?? C7 45 ?? ?? ?? ?? ?? 03 48 ?? 89 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 01 C7 04 24 ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 83 EC ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 4D ?? 83 EC ?? 89 85 ?? ?? ?? ?? 8B 45 ?? 8B 51 ?? 8D - 8D ?? ?? ?? ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? B8 ?? ?? ?? ?? 2B 85 ?? ?? ?? ?? 83 EC ?? 83 F8 ?? 0F 86 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 8D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 8D 8D ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 03 48 ?? C7 04 24 ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 83 EC ?? 39 D0 - 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B - } - $encrypt_files_p2 = { - 40 ?? 89 44 24 ?? 8B 45 ?? 8B 00 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? A1 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 89 94 05 ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C9 C3 03 48 ?? 8B 41 ?? 83 C8 ?? 89 04 24 C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? 03 48 ?? 8B 41 ?? 83 C8 ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 EC ?? E9 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C5 ?? 83 BD ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 77 ?? 8B 85 - ?? ?? ?? ?? FF 24 85 ?? ?? ?? ?? 0F 0B 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 39 D0 74 - ?? 89 04 24 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 15 ?? ?? - ?? ?? 8B 40 ?? 89 94 05 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 - } - $encrypt_files_p3 = { - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? - ?? ?? 8B 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 89 94 05 ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 - 04 24 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 55 89 E5 81 - EC ?? ?? ?? ?? 8D 45 ?? 89 65 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 45 ?? 8B 4D ?? 89 45 ?? 8B - 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 45 ?? 83 EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 4D ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? - 8B 45 ?? 8D 55 ?? 83 EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 39 - } - $encrypt_files_p4 = { - D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 55 ?? 85 D2 75 ?? C6 45 ?? ?? 8D 45 ?? 89 04 24 - E8 ?? ?? ?? ?? 0F B6 45 ?? C9 C3 8D 45 ?? 8B 4D ?? 89 45 ?? 8B 45 ?? 8B 51 ?? 8D 4D - ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 83 - EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 - 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8D 55 ?? 83 - EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 39 C8 74 ?? 89 04 24 E8 - ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 8B 4D ?? 89 45 ?? 8B 45 ?? 8B - 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 45 ?? 83 EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 4D ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? - 8D 55 ?? 83 EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 39 D0 74 ?? - 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 8B 4D ?? 89 45 + $drop_ransom_note_no_dir_exclusion = { + 8D 95 ?? ?? ?? ?? 52 8B 43 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 + ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 8B 95 ?? + ?? ?? ?? 52 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 33 C0 88 85 ?? ?? ?? ?? 33 C9 88 8D ?? ?? + ?? ?? 33 D2 88 95 ?? ?? ?? ?? 0F B6 85 ?? ?? ?? ?? 50 0F B6 8D ?? ?? ?? ?? 51 0F B6 + 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B C8 E8 ?? ?? ?? ?? + 50 8B 4B ?? 51 8D 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? + 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? + 6A ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 FF 15 + ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? EB ?? 8B + 5D ?? B8 ?? ?? ?? ?? C3 C7 45 } - $encrypt_files_p5 = { - 8B 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 45 ?? 83 EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 4D ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 - ?? 8B 45 ?? 8D 55 ?? 83 EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? - 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 8B 4D - ?? 89 45 ?? 8B 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 83 EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? - ?? ?? 89 45 ?? 8B 45 ?? 8D 55 ?? 83 EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 - ?? 8D 4D ?? 39 C8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D - 45 ?? 8B 4D ?? 89 45 ?? 8B 45 ?? 8B 51 ?? 8D 4D ?? 8B 00 01 C2 89 04 24 89 54 24 ?? - C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 83 EC ?? 89 44 24 ?? 8D 45 ?? 89 04 24 - C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8D 4D ?? 83 EC ?? 39 C8 74 ?? 89 04 24 E8 ?? ?? - ?? ?? 8B 45 ?? 8D 4D ?? 39 C8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + $find_files_p1 = { + 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 4D ?? 8B 55 ?? 53 + 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 74 ?? + 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 ?? ?? ?? ?? 8A 01 88 85 ?? ?? ?? + ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? + ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 8A C3 75 ?? B0 ?? 2B + CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D ?? ?? ?? ?? 56 1B C0 89 9D ?? ?? ?? ?? + 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? F7 D8 } - $encrypt_files_p6 = { - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 8B 00 - 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 83 F8 ?? 89 85 ?? ?? ?? ?? 0F - 84 ?? ?? ?? ?? 8D 4D ?? 89 04 24 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 EC ?? 3D ?? - ?? ?? ?? 77 ?? 83 E0 ?? 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 EC ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 - ?? 89 04 24 E8 ?? ?? ?? ?? 8D 55 ?? C7 44 24 ?? ?? ?? ?? ?? 89 C1 89 54 24 ?? 8B 45 - ?? 89 44 24 ?? 89 8D ?? ?? ?? ?? 89 4C 24 ?? 8B 95 ?? ?? ?? ?? 89 14 24 C7 45 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 83 EC ?? 3B 55 ?? 89 95 ?? ?? ?? ?? 0F 85 ?? ?? ?? - ?? 8B 45 ?? 8B 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C1 E8 ?? 89 8D ?? ?? ?? ?? 85 C0 - 89 85 ?? ?? ?? ?? 74 ?? 8B 45 ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? 89 85 ?? - ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 45 ?? ?? 83 85 ?? ?? ?? ?? - ?? 8B 55 ?? 39 95 ?? ?? ?? ?? 75 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + $find_files_p2 = { + 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 + ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? + ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 ?? 8A 48 ?? 84 C9 74 ?? + 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? + ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? + ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? + 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 8B D8 56 FF 15 ?? ?? ?? + ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B C3 8B 4D ?? + 5F 33 CD 5B E8 ?? ?? ?? ?? C9 C3 } - $encrypt_files_p7 = { - C7 44 24 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 4D ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 8B 8D ?? ?? ?? ?? 89 4C 24 - ?? 8B 95 ?? ?? ?? ?? 89 54 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 8D ?? - ?? ?? ?? 83 EC ?? 3B 4D ?? 74 ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 51 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 95 ?? ?? - ?? ?? 89 14 24 E8 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 89 0C 24 E8 ?? ?? ?? ?? C6 45 ?? - ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 52 - 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 44 24 - ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 8B 00 89 04 24 C7 - 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 50 8D 4D ?? 8B 45 ?? 39 C8 74 ?? 89 04 24 E8 ?? - ?? ?? ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 89 45 ?? E9 + $encrypt_files = { + 53 8B DC 83 EC ?? 83 E4 ?? 83 C4 ?? 55 8B 6B ?? 89 6C 24 ?? 8B EC 6A ?? 68 ?? ?? ?? + ?? 64 A1 ?? ?? ?? ?? 50 53 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 50 8D 45 + ?? 64 A3 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4B ?? 51 + FF 15 ?? ?? ?? ?? 83 E0 ?? 74 ?? 8B 53 ?? 52 FF 15 ?? ?? ?? ?? 83 E0 ?? 50 8B 43 ?? + 50 FF 15 ?? ?? ?? ?? 8B 4B ?? 51 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 53 + ?? 52 8D 45 ?? 50 83 EC ?? 8B CC 89 A5 ?? ?? ?? ?? 51 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? C6 45 ?? ?? 8D 55 ?? 52 8B 43 ?? 50 8D 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 + ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 8B 43 ?? 50 8D + 4D ?? 51 83 EC ?? 8B D4 89 A5 ?? ?? ?? ?? 52 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8B 43 ?? 50 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? + C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 8B 4D ?? + 33 CD E8 ?? ?? ?? ?? 8B E5 5D 8B E3 5B C2 } condition: - uint16(0)==0x5A4D and ( all of ($enum_resources_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) and (($exclude_directories_and_drop_ransom_note) or ($drop_ransom_note_no_dir_exclusion)) } -rule REVERSINGLABS_Win32_Ransomware_Blackbasta : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Major : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects BlackBasta ransomware." + description = "Yara rule that detects Major ransomware." author = "ReversingLabs" - id = "7c451fde-b8b1-5a35-855e-7e30f3e75cbb" - date = "2022-12-13" - modified = "2022-12-13" + id = "0c85aff8-1fb5-5e47-ae49-72445a000eaa" + date = "2021-01-26" + modified = "2021-01-26" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.BlackBasta.yara#L1-L531" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "c68671e51489af00e9e0cf28373e5ec01bda042653dbcca8843357eede41f27f" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Major.yara#L1-L261" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "16fb7763e3806fca6937fef7e8b3d8bccd61cb39549061d359d630c7d266c270" score = 75 - quality = 88 + quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" status = "RELEASED" sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "BlackBasta" + tc_detection_name = "Major" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? - ?? 83 C4 ?? 8B F0 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B C6 - E9 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 41 ?? 2B 01 C1 F8 ?? 89 85 ?? ?? ?? ?? 89 9D ?? - ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 - 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 - ?? 8A 48 ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? - ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? - 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 - } - $encrypt_files_v1 = { - 6A ?? E8 ?? ?? ?? ?? 8B F8 89 BD ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 89 B5 ?? ?? - ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 57 E8 ?? ?? ?? ?? 6A ?? 57 56 E8 ?? ?? ?? ?? 8D 4F - ?? 6A ?? 51 53 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A - ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 FF B5 ?? ?? ?? ?? 57 53 56 83 EC ?? 8B F4 89 A5 - ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 6A ?? 56 8D 4D ?? E8 ?? - ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A - ?? FF B5 ?? ?? ?? ?? 57 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? - ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 - ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 80 BD ?? ?? ?? ?? ?? - 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - } - $cmd_prompt = { - 8B FF 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? ?? ?? ?? ?? FC 53 56 8B 75 ?? 8D 45 ?? 33 DB - 68 ?? ?? ?? ?? 53 50 89 5D ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 83 F8 ?? 0F 84 ?? - ?? ?? ?? 85 F6 75 ?? 53 39 5D ?? 75 ?? E8 ?? ?? ?? ?? 59 33 C0 E9 ?? ?? ?? ?? FF 75 - ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 E8 ?? ?? ?? ?? 33 C0 83 C4 ?? 85 F6 0F 94 C0 E9 ?? - ?? ?? ?? 8B 45 ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 89 75 ?? 89 5D ?? 57 85 C0 74 ?? E8 - ?? ?? ?? ?? 8B 38 E8 ?? ?? ?? ?? 53 89 18 8D 45 ?? 50 FF 75 ?? 53 E8 ?? ?? ?? ?? 83 - C4 ?? 8B F0 E8 ?? ?? ?? ?? 83 FE ?? 74 ?? 89 38 EB ?? 83 38 ?? 74 ?? E8 ?? ?? ?? ?? - 83 38 ?? 74 ?? 83 CE ?? FF 75 ?? E8 ?? ?? ?? ?? 59 EB ?? E8 ?? ?? ?? ?? 89 38 53 8D - 45 ?? B9 ?? ?? ?? ?? 50 51 53 89 4D ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 E8 ?? ?? ?? ?? - 83 C4 ?? 8B C6 5F 8B 4D ?? 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 53 - } - $ldap_connect = { - C6 45 ?? ?? 8D 45 ?? 83 7D ?? ?? 0F 43 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? - 50 6A ?? 53 8B 35 ?? ?? ?? ?? FF D6 C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 53 FF D6 - 6A ?? 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 83 C4 ?? - 85 C0 74 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? - 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 83 C4 ?? - 8B F0 89 75 ?? 8D 45 ?? 50 8D 45 ?? 50 6A ?? 6A ?? 56 53 FF 15 ?? ?? ?? ?? 83 C4 ?? - 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 0F 84 ?? - ?? ?? ?? FF 75 ?? 57 53 FF 15 ?? ?? ?? ?? 83 C4 ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? 8B - 06 85 C0 0F 84 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? 50 8B 4D - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 36 68 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? 8B C8 89 4D ?? 8B 01 8B 40 ?? C6 45 ?? ?? 8B 44 08 ?? 8B 58 ?? 89 5D - ?? 8B 03 8B CB FF 50 ?? 83 4D ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 10 6A ?? - 8B C8 FF 52 ?? 0F B7 C0 89 45 ?? 83 65 ?? ?? C6 45 ?? ?? 85 DB 74 ?? 8B 03 8B CB FF - 50 ?? 8B C8 85 C9 74 ?? 8B 01 6A ?? FF 10 8B 45 ?? 50 8B 4D ?? E8 ?? ?? ?? ?? 8B 4D - ?? E8 ?? ?? ?? ?? 8B 5D ?? 56 FF 15 - } - $encrypt_files_v2 = { - 8D 45 ?? 50 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 6A ?? 57 53 FF 75 ?? 83 EC ?? 8B - F4 89 A5 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 6A ?? 56 8D 4D - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 8B 45 ?? 89 45 ?? 6A ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF 75 - ?? 57 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 E8 - ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - } - $encrypt_files_v3 = { - 6A ?? E8 ?? ?? ?? ?? 8B F8 89 BD ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 89 B5 ?? ?? - ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 57 E8 ?? ?? ?? ?? 6A ?? 57 56 E8 ?? ?? ?? ?? 8D 4F - ?? 6A ?? 51 53 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A - ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 6A ?? 57 53 56 83 EC ?? 8B F4 89 A5 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 6A ?? 56 8D 4D ?? E8 ?? ?? ?? ?? C6 - 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF B5 ?? - ?? ?? ?? 57 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 57 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 53 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? - 83 C4 ?? C6 45 ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 - ?? ?? 8D 8D ?? ?? ?? ?? E8 - } - $encrypt_files_v4 = { - 8D 45 ?? 50 E8 ?? ?? ?? ?? 0F 10 45 ?? 0F 11 45 ?? 0F 10 45 ?? 0F 11 45 ?? 8B 45 ?? - 8B 4D ?? 89 45 ?? 89 4D ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? - 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 56 57 8D 45 ?? 50 8D 45 ?? 50 83 EC ?? 8B - F4 89 A5 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 6A ?? 56 8D 4D - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 6A ?? FF B5 ?? ?? ?? ?? 57 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 - ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? EB ?? 8D 85 - ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? C6 45 ?? ?? - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? C6 45 ?? ?? 8B 8D ?? ?? ?? ?? 83 F9 ?? 72 ?? 8D 0C 4D ?? ?? ?? ?? 89 8D ?? ?? - ?? ?? 8B 95 ?? ?? ?? ?? 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 8B - 50 ?? 2B C2 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 66 89 85 ?? ?? FF FF C6 - 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 - } - $drop_ransom_note_v1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? 03 00 00 A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? 45 FC 00 00 00 00 - 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 - BD ?? ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A - ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 - BD ?? ?? ?? ?? ?? 74 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? - 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? - 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 - 5D C3 - } - $exclude_from_encryption_v1 = { - 83 FE ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D - ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 FE ?? 0F 85 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 50 E8 - ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 FE ?? 0F 85 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B - F0 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 FE ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D - 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? - 8D 4D ?? E8 ?? ?? ?? ?? 83 FE ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? 83 FE ?? 75 ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D - } - $exclude_from_encryption_v2_p1 = { - 50 C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 05 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? - ?? ?? C6 45 ?? ?? 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B F0 C6 - 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 FE ?? 74 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - C6 45 ?? ?? 6A ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 FE ?? 74 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E9 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 8D 4D ?? - E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 FE ?? 74 ?? C6 - } - $exclude_from_encryption_v2_p2 = { - 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B F0 C6 45 ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 FE ?? 74 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 51 8B C8 E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 8D 4D - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? FF B5 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? B9 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 84 C0 0F 44 CA 8D 45 ?? 50 E8 ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 80 BD ?? ?? ?? - ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? C6 45 ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 - } - $encrypt_files_v5_p1 = { - 50 F2 0F 11 45 ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 74 ?? 8D 45 ?? 50 56 FF 15 ?? ?? - ?? ?? 85 C0 75 ?? 56 FF 15 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? - 8B 8D ?? ?? ?? ?? 85 C9 74 ?? 8B 01 6A ?? FF 10 C7 45 ?? ?? ?? ?? ?? 8D 4B ?? E8 ?? - ?? ?? ?? 8B 4D ?? 5F 64 89 0D ?? ?? ?? ?? 5E 8B E5 5D 8B E3 5B C2 ?? ?? 8B 7D ?? 83 - C1 ?? 8B 35 ?? ?? ?? ?? 8B 45 ?? E9 ?? ?? ?? ?? 8B 45 ?? 8D 8D ?? ?? ?? ?? 8B 7D ?? - 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? 8D 8D ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 89 45 ?? 83 E0 ?? 03 C1 C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? - C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 6A ?? - E8 ?? ?? ?? ?? 6A ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 89 45 ?? C6 45 ?? ?? 6A ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 89 45 ?? C6 45 ?? ?? B9 ?? ?? ?? ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 6A ?? - FF 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF 75 ?? 6A ?? FF 75 ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? 6A ?? FF 75 ?? 83 - } - $encrypt_files_v5_p2 = { - C0 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 85 C0 0F 8F ?? ?? ?? ?? 7C ?? 81 FF ?? ?? - ?? ?? 0F 83 ?? ?? ?? ?? F2 0F 10 05 ?? ?? ?? ?? F2 0F 11 45 ?? 0F 57 C0 66 0F 13 45 - ?? 8B 4D ?? 8B 55 ?? 89 4D ?? 8B CF 89 55 ?? 2B 4D ?? 6A ?? 6A ?? 1B C2 50 51 E8 ?? - ?? ?? ?? F2 0F 10 45 ?? 8B CA F2 0F 59 05 ?? ?? ?? ?? 89 4D ?? 8B C8 89 45 ?? F2 0F - 11 45 ?? E8 ?? ?? ?? ?? F2 0F 59 45 ?? E8 ?? ?? ?? ?? 8B C8 0B CA 0F 85 ?? ?? ?? ?? - 39 4D ?? 0F 8C ?? ?? ?? ?? 7F ?? 85 FF 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? - 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 85 - C0 0F 8C ?? ?? ?? ?? 7F ?? 81 FF ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? F2 0F 10 05 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 89 45 ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? F2 0F 11 45 ?? 50 - E8 ?? ?? ?? ?? C6 45 ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 56 C6 45 ?? ?? 8B 4D - ?? E8 ?? ?? ?? ?? 8B 45 ?? 33 D2 C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 52 50 FF 75 ?? - FF 75 ?? E8 ?? ?? ?? ?? 8B C8 89 45 ?? 0B CA 89 55 ?? 75 ?? 8D 85 ?? ?? ?? ?? 89 45 - ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 50 FF 75 ?? 57 - 6A ?? 6A ?? 56 C6 45 ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 0F 57 - C0 66 0F 13 45 ?? 0F 8C ?? ?? ?? ?? 7F ?? 83 7D ?? ?? 0F 86 ?? ?? ?? ?? 8B 45 ?? 8B - 7D ?? 89 45 ?? 66 66 0F 1F 84 00 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? 8D 8D ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 8B CF 0F A4 C8 ?? 6A ?? C1 E1 ?? 03 - 4D ?? 6A ?? 13 45 ?? 50 51 56 C6 45 ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 03 7D ?? 8B 45 ?? - 13 45 ?? 89 45 ?? 3B 45 ?? 0F 8C ?? ?? ?? ?? 7F ?? 3B 7D ?? 0F 82 + $find_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 33 C0 89 4D ?? 57 50 66 89 45 ?? 8D 8D ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 57 C0 C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F 13 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 + ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 + 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8D 4D ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? + ?? ?? 33 C9 8B F8 51 89 4D ?? 51 8D 4D ?? 89 7D ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 4D ?? + 8D 45 ?? 50 FF 77 ?? 57 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 47 ?? 89 4D ?? BB ?? ?? ?? + ?? 8B 48 ?? 89 01 8B 07 8D 4D ?? 83 C0 ?? 3B C8 74 ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 8D 45 ?? 3B C6 } - $encrypt_files_v6_p1 = { - E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 85 F6 0F 8F ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 6A - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 03 48 ?? 8B 01 FF 50 ?? 83 7B ?? ?? 8D 43 ?? - F2 0F 10 05 ?? ?? ?? ?? 0F 43 43 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? - ?? ?? 50 F2 0F 11 45 ?? FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 74 ?? 8D 45 ?? 50 57 FF 15 - ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C6 45 ?? ?? 8B 8D ?? ?? ?? ?? 85 C9 74 ?? 8B 01 6A ?? FF 10 C6 45 ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? 8D 4B ?? E8 ?? ?? ?? ?? 8B 4D ?? 5F 64 89 0D ?? ?? ?? ?? 5E 8B E5 5D 8B E3 5B - C2 ?? ?? 85 F6 0F 84 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 8B CF 76 ?? 8B FE 2B 7D ?? 66 - 8B 04 0F 66 3B 01 75 ?? 83 C1 ?? 83 EA ?? 75 ?? 2B 75 ?? D1 FE E9 ?? ?? ?? ?? 8B 7D - ?? 83 C6 ?? 8B 15 ?? ?? ?? ?? 8B 45 ?? E9 ?? ?? ?? ?? 8B 45 ?? 8D 8D ?? ?? ?? ?? 8B - 75 ?? 6A ?? 89 45 ?? E8 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 + $find_files_p2 = { + 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? + ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? + ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? + ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? 83 7E ?? + ?? 73 ?? 8B 46 ?? 83 C0 ?? 74 ?? 03 C0 50 8D 45 ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? EB + ?? 8B 06 89 45 ?? C7 06 ?? ?? ?? ?? 8B 46 ?? 89 45 ?? 8B 46 ?? 89 45 ?? C7 46 ?? ?? + ?? ?? ?? 83 7E ?? ?? C7 46 ?? ?? ?? ?? ?? 72 ?? 8B 36 33 C0 66 89 06 8B 45 ?? 83 F8 + ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 + C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? + ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 3F 8D 77 ?? 8B + 4F ?? 8B 07 89 01 8B 0F 8B 47 ?? 89 41 ?? 8B 45 ?? 48 89 45 ?? 89 45 ?? 8B 46 ?? 83 + F8 ?? 72 ?? 8B 0E 40 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 } - $encrypt_files_v6_p2 = { - 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? 8D 8D - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 89 45 ?? 83 E0 ?? 03 C1 C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 89 85 ?? ?? - ?? ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? - 6A ?? E8 ?? ?? ?? ?? 6A ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 89 45 ?? C6 45 ?? ?? 6A ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 C4 ?? 89 45 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? FF 75 ?? E8 ?? ?? ?? - ?? 6A ?? FF 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF 75 ?? 6A ?? FF 75 ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? 6A ?? - FF 75 ?? 83 C0 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 85 C0 0F 8F ?? ?? ?? ?? 7C + $find_files_p3 = { + C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? + ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 46 ?? ?? ?? ?? + ?? 83 7E ?? ?? C7 46 ?? ?? ?? ?? ?? 72 ?? 8B 36 33 C0 57 66 89 06 E8 ?? ?? ?? ?? 83 + C4 ?? 8D 8D ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF 15 ?? ?? ?? ?? 8B + F8 89 7D ?? 83 FF ?? 0F 84 ?? ?? ?? ?? 66 66 66 0F 1F 84 00 ?? ?? ?? ?? 33 C0 C7 45 + ?? ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? 0F 84 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 8B 08 85 C9 74 ?? 8B 85 ?? ?? ?? ?? 8B 00 8D 14 41 EB ?? 8B 85 + ?? ?? ?? ?? 8B 08 8B 85 ?? ?? ?? ?? 8B 00 8D 14 48 8B 85 ?? ?? ?? ?? 8B 08 2B D1 D1 + FA 81 FA ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 8D 04 12 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 + ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 + ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? C7 00 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 00 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? 50 89 85 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 + ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 03 C0 3D ?? ?? ?? ?? 72 ?? F6 C1 } - $encrypt_files_v6_p3 = { - 81 FE ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? F2 0F 10 05 ?? ?? ?? ?? F2 0F 11 45 ?? 0F 57 C0 - 66 0F 13 45 ?? 8B 4D ?? 8B 55 ?? 89 4D ?? 8B CE 89 55 ?? 2B 4D ?? 6A ?? 6A ?? 1B C2 - 50 51 E8 ?? ?? ?? ?? F2 0F 10 45 ?? 8B CA F2 0F 59 05 ?? ?? ?? ?? 89 4D ?? 8B C8 89 - 45 ?? F2 0F 11 45 ?? E8 ?? ?? ?? ?? F2 0F 59 45 ?? E8 ?? ?? ?? ?? 8B C8 0B CA 0F 85 - ?? ?? ?? ?? 39 4D ?? 0F 8C ?? ?? ?? ?? 7F ?? 85 F6 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 89 45 ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? E9 ?? - ?? ?? ?? 85 C0 0F 8C ?? ?? ?? ?? 7F ?? 81 FE ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? F2 0F 10 - 05 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? F2 0F - 11 45 ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 57 C6 45 - ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 33 D2 C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 52 - 50 FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B C8 89 45 ?? 0B CA 89 55 ?? 75 ?? 8D 85 ?? ?? - ?? ?? 89 45 ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 50 - FF 75 ?? 56 6A ?? 6A ?? 57 C6 45 ?? ?? 8B 4D + $find_files_p4 = { + 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? + 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 68 + ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 EC ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? 8B D4 33 C0 C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? 66 89 02 66 39 85 ?? ?? ?? + ?? 75 ?? 33 C9 EB ?? 8D 8D ?? ?? ?? ?? 8D 71 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B + CE D1 F9 51 8D 85 ?? ?? ?? ?? 8B CA 50 E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 85 C0 + 0F 84 ?? ?? ?? ?? 6A ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? + ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 83 CB ?? C7 45 ?? + ?? ?? ?? ?? 66 89 45 ?? 66 39 85 ?? ?? ?? ?? 75 ?? 33 C9 EB ?? 8D 8D ?? ?? ?? ?? 8D + 51 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? + E8 ?? ?? ?? ?? 8D 45 ?? 83 CB ?? 50 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 + 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 } - $set_default_icon_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? 83 EC ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 - 89 45 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? - ?? B0 ?? C7 45 ?? ?? ?? ?? ?? 33 C9 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 98 - 66 31 44 4D ?? 41 83 F9 ?? 73 ?? 8A 45 ?? EB ?? 33 C0 56 66 89 45 ?? C6 45 ?? ?? 8D - 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B F0 C7 45 - ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 56 50 C7 45 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 33 C0 C7 46 ?? ?? ?? ?? ?? 83 C4 ?? C7 46 ?? ?? ?? ?? ?? 66 89 06 C7 45 ?? - ?? ?? ?? ?? C6 45 ?? ?? 8B 4D ?? 83 F9 ?? 72 ?? 8B 55 ?? 8D 0C 4D ?? ?? ?? ?? 8B C2 + $find_files_p5 = { + 83 CB ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 CB ?? 50 8D 85 ?? + ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 CB ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 83 CB ?? 50 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 85 C0 74 ?? + C6 45 ?? ?? F6 C3 ?? 74 ?? 8B 45 ?? 83 E3 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? + E8 ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? F6 C3 ?? + 74 ?? 8B 85 ?? ?? ?? ?? 83 E3 ?? 83 F8 ?? 72 ?? 40 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? 66 89 85 ?? ?? ?? ?? F6 C3 ?? 74 ?? 8B 85 ?? ?? ?? ?? 83 E3 ?? 83 F8 ?? 72 ?? 40 + 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? F6 C3 ?? 74 ?? 8B 85 ?? ?? + ?? ?? 83 E3 ?? 83 F8 ?? 72 ?? 40 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? + ?? ?? 8B 45 ?? 83 E3 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 33 C0 } - $set_default_icon_p2 = { - 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? - 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 51 8D 4D ?? C7 45 ?? ?? - ?? ?? ?? 51 6A ?? 68 ?? ?? ?? ?? 33 C0 83 7D ?? ?? 6A ?? 66 89 45 ?? 8D 45 ?? 0F 43 - 45 ?? 6A ?? 6A ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 83 7D ?? ?? 8D 4D - ?? 8B 45 ?? 0F 43 4D ?? 03 C0 50 51 6A ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF - 75 ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF D6 6A - ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D6 B8 ?? ?? ?? ?? 89 45 ?? 83 E0 ?? 89 45 - ?? C6 45 ?? ?? 8B 4D ?? 5E 83 F9 ?? 72 ?? 8B 55 ?? 8D 0C 4D ?? ?? ?? ?? 8B C2 81 F9 - ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 77 ?? 51 52 E8 ?? ?? ?? - ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C7 45 ?? ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 8B E5 5D C3 + $find_files_p6 = { + C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? 83 E3 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? 83 F8 ?? 72 + ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 80 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 75 ?? 8D 45 ?? 50 8D 4D ?? FF 76 ?? 56 E8 ?? ?? + ?? ?? 8B 55 ?? B9 ?? ?? ?? ?? 2B CA 83 F9 ?? 0F 82 ?? ?? ?? ?? 89 46 ?? 42 8B 48 ?? + 89 55 ?? 89 01 E9 ?? ?? ?? ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 75 ?? + 8D 45 ?? 50 8D 4D ?? FF 76 ?? 56 E8 ?? ?? ?? ?? 8B 55 ?? B9 ?? ?? ?? ?? 2B CA 83 F9 + ?? 0F 82 ?? ?? ?? ?? 89 46 ?? 42 8B 48 ?? 89 55 ?? 89 55 ?? 89 01 8B 45 ?? 83 F8 ?? + 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 8D ?? ?? ?? ?? 54 E8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? ?? ?? ?? 8B 75 + ?? 8B CE E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 45 ?? 8B CE 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 7D ?? + 8B CF E8 ?? ?? ?? ?? 8B 4D ?? 85 C9 74 ?? 8B 7D ?? E9 ?? ?? ?? ?? 8B 4D ?? 85 C9 0F + 84 ?? ?? ?? ?? 0F 1F 00 8B 45 ?? 8D 4D ?? 8B 00 83 C0 ?? 3B C8 74 ?? 6A ?? 6A ?? 50 + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 } - $find_system_volumes = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? 81 EC ?? ?? - ?? ?? 53 56 57 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 75 ?? C7 06 ?? ?? ?? ?? - C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B F8 66 90 - 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? F7 45 ?? ?? ?? ?? ?? 0F 85 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 D2 C7 45 ?? ?? ?? ?? ?? 66 89 55 ?? - 83 C4 ?? 8D 95 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 0C 00 C7 45 ?? ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 03 C1 C7 45 ?? ?? ?? ?? ?? 3B D0 74 ?? D1 F9 8B C2 - 51 50 8D 4D ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 8B 46 ?? 3B 46 ?? 74 ?? - 6A ?? 51 50 C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? E8 ?? ?? ?? - ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 83 46 ?? ?? 66 89 45 ?? - EB ?? 51 50 8B CE E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 4D ?? 83 F9 ?? 72 ?? 8B 55 ?? 8D 0C - 4D ?? ?? ?? ?? 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 - ?? 77 ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? 66 89 45 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF D3 85 C0 0F 85 ?? ?? ?? ?? - 57 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B C6 5F 5E 5B 64 89 0D ?? ?? ?? ?? 8B E5 5D C3 + $find_files_p7 = { + 8D 45 ?? 3B C6 74 ?? 8B 4D ?? 83 F9 ?? 72 ?? 41 51 FF 75 ?? 8B C8 E8 ?? ?? ?? ?? 33 + C0 C7 45 ?? ?? ?? ?? ?? 56 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? + 8B 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? 83 7D ?? ?? 8D 8D ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF 15 ?? ?? ?? ?? 8B 75 + ?? 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 0F 1F 00 33 C0 C7 45 ?? ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 45 ?? + 6A ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF + 75 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 8D 85 ?? ?? ?? ?? 83 EC ?? F6 85 ?? ?? ?? ?? ?? 8B CC 50 0F 84 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B CF E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 5D ?? 8D 45 ?? 50 8D 4D ?? FF 73 ?? 53 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? + 2B CE 83 F9 ?? 0F 82 ?? ?? ?? ?? 89 43 ?? 46 8B 48 ?? 89 75 ?? 89 01 8B 45 ?? 83 F8 + ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 8D ?? ?? ?? ?? 54 E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 85 C0 74 + ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B CF 50 E8 ?? ?? ?? ?? 8B + 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF + 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 85 F6 0F 85 ?? + ?? ?? ?? FF 75 ?? FF 15 } - $drop_ransom_note_v2_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? 83 EC ?? 53 - 56 57 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 7D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? B9 ?? ?? ?? ?? 8B D8 2B CF 83 C4 ?? 3B CB 0F 82 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? - 8D 0C 3B C7 45 ?? ?? ?? ?? ?? 0F 43 45 ?? BE ?? ?? ?? ?? 89 45 ?? 8D 45 ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 4D ?? 89 45 ?? 3B CE 76 ?? 8B F1 83 CE ?? 81 FE - ?? ?? ?? ?? 76 ?? BE ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? 3B F0 0F 42 F0 8D 46 ?? 50 8D - 4D ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 0C 3B 89 45 ?? 89 75 ?? 8D 34 3F 56 FF 75 ?? 89 4D - ?? 50 E8 ?? ?? ?? ?? 8B 7D ?? 8D 04 1B 50 68 ?? ?? ?? ?? 8D 0C 3E 51 E8 ?? ?? ?? ?? - 8B 45 ?? 33 C9 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 66 89 0C 47 C6 45 ?? ?? B8 ?? ?? ?? ?? - 83 3D ?? ?? ?? ?? ?? 8D 4D ?? FF 35 ?? ?? ?? ?? 0F 43 05 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 8B F0 C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 56 50 C7 45 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? 83 C4 ?? 66 + $encrypt_files_p1 = { + FF 15 ?? ?? ?? ?? 85 C0 75 ?? 50 FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D + 45 ?? 83 7D ?? ?? 0F 43 45 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 C0 C7 45 ?? ?? + ?? ?? ?? 6A ?? 50 66 89 45 ?? 8D 4D ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 6A ?? 0F + 43 45 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 89 45 ?? FF 15 ?? ?? ?? + ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 8B 4D ?? 01 0D ?? ?? ?? ?? 8B 55 ?? 11 15 ?? ?? ?? ?? 83 FA ?? 0F 8C ?? ?? + ?? ?? 7F ?? 85 C9 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? 66 66 0F 1F 84 00 + ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 + FF 74 ?? 8B 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 8B 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? C7 45 ?? ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 8B 4D ?? 83 C4 ?? 6A } - $drop_ransom_note_v2_p2 = { - 89 06 BE ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 75 ?? 83 E6 ?? 89 75 ?? C6 45 ?? ?? 8B - 4D ?? 83 F9 ?? 72 ?? 8B 55 ?? 8D 0C 4D ?? ?? ?? ?? 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 8B - 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 51 52 E8 ?? ?? ?? ?? 83 C4 - ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 6A ?? 66 89 45 - ?? 8D 45 ?? 0F 43 45 ?? 6A ?? 68 ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 8B F8 83 FF ?? 74 ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? - ?? 57 FF 15 ?? ?? ?? ?? 83 E6 ?? 89 75 ?? C6 45 ?? ?? 8B 4D ?? 5F 5E 5B 83 F9 ?? 72 - ?? 8B 55 ?? 8D 0C 4D ?? ?? ?? ?? 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B - C2 83 C0 ?? 83 F8 ?? 77 ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D - ?? 64 89 0D ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files_p2 = { + 50 E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 57 53 FF 15 ?? ?? ?? ?? + 8B 55 ?? 8B 4D ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 56 8D 85 + ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 6A ?? 6A ?? 50 53 FF 15 ?? + ?? ?? ?? 8B 55 ?? 8D 45 ?? 8B 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 50 56 53 FF 15 ?? ?? ?? ?? 83 6D ?? ?? 0F 85 ?? ?? ?? ?? 57 E8 ?? ?? + ?? ?? 56 E9 ?? ?? ?? ?? 8B F1 8B C2 81 C6 ?? ?? ?? ?? 83 D0 ?? 83 F8 ?? 0F 87 ?? ?? + ?? ?? 72 ?? 81 FE ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F + 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? 66 90 + 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 + 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 8B + 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 55 + ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 } - $encrypt_files_v5 = { - 50 FF 15 ?? ?? ?? ?? 8B D8 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 C3 ?? 74 - ?? C6 45 ?? ?? 80 7D ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 - ?? ?? 8D 8D ?? ?? ?? ?? 51 8B C8 E8 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 4D ?? E8 ?? ?? ?? - ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D - ?? ?? ?? ?? 51 8B C8 E8 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D - 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B F8 83 FF ?? 75 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 8D 0C 41 89 4D ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 89 45 ?? 89 45 ?? 8D - 04 78 89 45 ?? 51 50 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 8D 45 + $encrypt_files_p3 = { + E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? C7 45 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 8B 4D ?? 83 C4 ?? 6A ?? 50 E8 ?? ?? + ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 57 53 FF 15 ?? ?? ?? ?? 8B 55 ?? 8B + 4D ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 56 8D 85 ?? ?? ?? ?? + 57 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 6A ?? 6A ?? 50 53 FF 15 ?? ?? ?? ?? 8B + 55 ?? 8D 45 ?? 8B 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 50 56 53 FF 15 ?? ?? ?? ?? 83 6D ?? ?? 0F 85 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 56 E9 + ?? ?? ?? ?? 8B F1 8B C2 81 C6 ?? ?? ?? ?? 83 D0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 72 ?? + 81 FE ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? 66 90 68 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 8B 55 ?? 8B 4D + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 8B F0 83 C4 ?? 85 F6 74 ?? C7 45 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 } - $find_system_volumes_v2_p1 = { - C7 45 ?? ?? ?? ?? ?? 89 7D ?? FF 15 ?? ?? ?? ?? 8B D8 8D 45 ?? 50 68 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A - ?? 6A ?? 8D 45 ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 85 C0 0F 84 ?? ?? ?? ?? F7 45 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 51 8D 8D ?? ?? ?? ?? 8D 04 41 50 8B C1 8D 4D ?? 50 - E8 ?? ?? ?? ?? 8B F0 C6 45 ?? ?? 8B 4D ?? 3B 4D ?? 74 ?? 6A ?? 56 51 C7 01 ?? ?? ?? - ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 46 ?? ?? ?? - ?? ?? C7 46 ?? ?? ?? ?? ?? C6 06 ?? 83 45 ?? ?? EB ?? 56 51 8D 4D ?? E8 ?? ?? ?? ?? - C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? - ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 75 ?? 33 C9 89 4D ?? B8 ?? - ?? ?? ?? 8B 4D ?? 2B CE F7 E9 C1 FA ?? 8B C2 C1 E8 ?? 03 C2 0F 84 ?? ?? ?? ?? 33 DB - 8D 4D ?? 8D 04 33 89 4D ?? C6 45 ?? ?? 8D 4D ?? 51 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 8D 4D ?? 83 CF ?? 89 7D ?? C7 45 ?? ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? C6 45 ?? - ?? 83 E7 ?? 89 7D ?? C6 45 ?? ?? 8D 45 ?? 8B 35 ?? ?? ?? ?? 3B 35 ?? ?? ?? ?? 74 ?? - 6A ?? 50 56 89 75 ?? C7 06 ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? C6 + $encrypt_files_p4 = { + 50 E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 8B 4D ?? 83 C4 ?? 6A ?? 50 E8 ?? ?? ?? ?? F2 0F + 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 57 53 FF 15 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? E8 ?? + ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 56 8D 85 ?? ?? ?? ?? 57 50 E8 ?? + ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 6A ?? 6A ?? 50 53 FF 15 ?? ?? ?? ?? 8B 55 ?? 8D 45 + ?? 8B 4D ?? 6A ?? 50 E8 ?? ?? ?? ?? F2 0F 59 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 56 53 + FF 15 ?? ?? ?? ?? 83 6D ?? ?? 0F 85 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 56 E9 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 0F 1F 84 00 ?? ?? ?? ?? + 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B F0 83 C4 + ?? 85 F6 74 ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? 66 + 0F 1F 84 00 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 + ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 74 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 45 ?? 6A ?? 50 FF 75 ?? 56 53 FF 15 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? + ?? ?? ?? 57 56 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 6A ?? 6A ?? 50 53 FF 15 ?? + ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 57 53 FF 15 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 57 E8 + ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 0F 57 C0 66 0F 13 45 ?? 6A ?? 50 6A ?? 53 FF 15 ?? ?? + ?? ?? 8B 75 ?? 8D 45 ?? 6A ?? 50 FF B6 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? + ?? 50 FF B6 ?? ?? ?? ?? 53 FF D7 8B 35 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 6A ?? 6A ?? 6A + ?? 6A ?? FF 35 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF D6 85 C0 0F + 84 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 35 ?? ?? ?? + ?? FF D6 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 0F 1F 40 ?? 8B 45 ?? 03 C0 50 E8 ?? + ?? ?? ?? 8B F0 83 C4 ?? 80 3E ?? 74 ?? 8B 45 ?? 8B CE 85 C0 74 ?? 66 90 C6 01 ?? 8D + 49 ?? 83 E8 ?? 75 ?? 8D 45 ?? 50 56 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 56 53 FF D7 6A ?? 8D 45 ?? 50 8B 45 ?? FF B0 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 50 8B 45 ?? FF B0 ?? ?? ?? ?? 53 FF D7 53 FF 15 ?? ?? ?? + ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 83 7D ?? ?? 0F 43 45 ?? 6A ?? 50 FF 75 ?? FF + 15 } - $find_system_volumes_v2_p2 = { - 45 ?? ?? 8B 45 ?? 89 46 ?? C6 45 ?? ?? 83 05 ?? ?? ?? ?? ?? EB ?? 50 56 B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 4D ?? 83 F9 ?? 72 ?? 8B 55 ?? 8D 0C 4D ?? ?? ?? ?? - 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? - ?? ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 33 C0 8B 75 ?? 83 C3 ?? FF 45 ?? 2B CE - 66 89 45 ?? B8 ?? ?? ?? ?? F7 E9 C7 45 ?? ?? ?? ?? ?? C1 FA ?? 8B C2 C7 45 ?? ?? ?? - ?? ?? C1 E8 ?? 03 C2 39 45 ?? 0F 82 ?? ?? ?? ?? 83 E7 ?? 89 7D ?? C7 45 ?? ?? ?? ?? - ?? 8D 4D ?? E8 ?? ?? ?? ?? 5F 5B EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 68 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 6A ?? C7 45 ?? ?? - ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? F3 - 0F 7E 05 ?? ?? ?? ?? 8B F0 2B 75 ?? 66 0F D6 45 ?? 90 8B 55 ?? 8B 4D ?? E8 ?? ?? ?? - ?? 83 3D ?? ?? ?? ?? ?? F2 0F 10 0D ?? ?? ?? ?? F2 0F 59 C1 F2 0F 59 C1 F2 0F 59 C1 - F2 0F 11 45 ?? 74 ?? E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 3B C8 74 ?? 6A ?? 51 FF 35 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 0F 57 C0 66 0F 13 05 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? F2 0F 10 45 ?? 83 EC ?? F2 0F 11 44 24 ?? 66 0F 6E C6 - F3 0F E6 C0 C1 EE + $remote_connection = { + FF 15 ?? ?? ?? ?? 8B F8 89 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 8B 4D ?? 83 79 ?? ?? 72 ?? + 8B 09 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 51 57 FF 15 ?? ?? ?? ?? 8B F0 89 75 ?? 85 + F6 0F 84 ?? ?? ?? ?? 8B 4D ?? 53 83 79 ?? ?? 75 ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? BB ?? ?? ?? ?? EB ?? 51 8D 45 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BB + ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? 8B C8 6A ?? E8 ?? ?? ?? ?? 33 C9 C7 45 ?? ?? ?? ?? + ?? 66 89 4D ?? 8D 4D ?? 50 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 C3 ?? 74 ?? 8D 4D + ?? 83 E3 ?? E8 ?? ?? ?? ?? F6 C3 ?? 5B 74 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D + 4D ?? 6A ?? 68 ?? ?? ?? ?? 51 6A ?? 68 ?? ?? ?? ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 0F + 43 45 ?? 50 68 ?? ?? ?? ?? 56 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F + 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 3D ?? ?? + ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF D7 85 C0 74 ?? 8B 45 ?? + 85 C0 74 ?? C6 84 05 ?? ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 33 C9 EB ?? 8D 8D ?? + ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? + ?? ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF D7 85 C0 75 ?? 8B 7D + ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 45 + ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 83 7D + ?? ?? 8D 4D ?? 8B 45 ?? 8D 55 ?? 0F 43 4D ?? 8B 75 ?? 03 C1 83 7D ?? ?? 8D 4D ?? 52 + 0F 43 4D ?? 50 51 8B CE E8 ?? ?? ?? ?? 8B 4D ?? 83 F9 ?? 72 ?? 41 51 FF 75 ?? 8D 4D + ?? E8 } condition: - uint16(0)==0x5A4D and ((($find_files) and ($encrypt_files_v1) and ($cmd_prompt) and ($exclude_from_encryption_v1)) or (($find_files) and ($cmd_prompt) and ($ldap_connect) and ($encrypt_files_v2) and ($exclude_from_encryption_v1)) or (($find_files) and ($cmd_prompt) and ($ldap_connect) and ($encrypt_files_v3) and ($exclude_from_encryption_v1)) or (($find_files) and ($encrypt_files_v4) and ($drop_ransom_note_v1) and ( all of ($exclude_from_encryption_v2_p*))) or (($find_files) and ($exclude_from_encryption_v1) and ( any of ($encrypt_files_v5)) and ( all of ($find_system_volumes_v2_p*))) or (( all of ($encrypt_files_v5_p*)) and ( all of ($set_default_icon_p*)) and ($find_system_volumes) and ( all of ($drop_ransom_note_v2_p*)) and ($find_files)) or (( all of ($encrypt_files_v6_p*)) and ( all of ($set_default_icon_p*)) and ( all of ($drop_ransom_note_v2_p*)) and ($find_files))) + uint16(0)==0x5A4D and (( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and $remote_connection) } -rule REVERSINGLABS_Win32_Ransomware_Matsnu : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Eternity : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Matsnu ransomware." + description = "Yara rule that detects Eternity ransomware." author = "ReversingLabs" - id = "2f0bddd5-bd48-5d38-84f4-2dbccbe04a46" - date = "2020-07-15" - modified = "2020-07-15" + id = "7bb0f3b0-a8c0-5239-a1b4-532d403f59bc" + date = "2022-07-22" + modified = "2022-07-22" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Matsnu.yara#L1-L116" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "76ef1b4a292f27ccd904e80f0279a7a327f7399a21f2266ef3ea959e5339ffac" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Eternity.yara#L1-L74" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "a2298a26e9bbe2b779eb2afeeda28d4321bc2d26db46bbb377bf86abaf8fa929" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -43880,116 +43874,63 @@ rule REVERSINGLABS_Win32_Ransomware_Matsnu : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Matsnu" + tc_detection_name = "Eternity" tc_detection_factor = 5 importance = 25 strings: - $remote_connection = { - 55 89 E5 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C6 45 ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5B 8D 83 ?? ?? ?? ?? 8B 00 6A ?? 50 - FF 93 ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? 8B 36 8D 7D ?? 57 56 FF 93 ?? ?? ?? ?? 85 C0 74 - ?? 57 8D BB ?? ?? ?? ?? 89 07 5F EB ?? 8D B3 ?? ?? ?? ?? 8B 36 57 8D BB ?? ?? ?? ?? - 89 37 5F 68 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? EB ?? 8D BD ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A - ?? 57 FF 93 ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? 8B 36 8D BD ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 - 57 FF 93 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 50 57 FF 93 ?? ?? ?? ?? 85 - C0 74 ?? C6 00 ?? 8D BD ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? 8D 93 ?? ?? - ?? ?? FF 75 ?? 52 51 56 57 FF 93 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 8D 4D ?? 51 57 E8 ?? - ?? ?? ?? 85 C0 74 ?? 89 45 ?? 8D 4D ?? 51 50 E8 ?? ?? ?? ?? 85 C0 75 ?? FF 75 ?? FF - 93 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 89 85 ?? ?? ?? ?? FF 75 ?? FF 93 ?? ?? ?? - ?? 8B 45 ?? 8B 75 ?? 89 06 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 83 BD ?? - ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - 68 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? 8B 36 8D 83 ?? ?? ?? ?? 50 56 FF - 93 ?? ?? ?? ?? 85 C0 74 ?? 40 57 8D BB ?? ?? ?? ?? 89 07 5F E9 ?? ?? ?? ?? 8D B3 ?? - ?? ?? ?? 8B 36 57 8D BB ?? ?? ?? ?? 89 37 5F 68 ?? ?? ?? ?? FF 93 ?? ?? ?? ?? E9 ?? - ?? ?? ?? 8D 83 ?? ?? ?? ?? 8B 00 50 FF 93 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? - ?? ?? C9 C2 - } - $crypto_file = { - 55 89 E5 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? - C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 5D ?? E8 - ?? ?? ?? ?? 5B 8D 83 ?? ?? ?? ?? 8B 00 85 C0 74 ?? 89 45 ?? 8D 83 ?? ?? ?? ?? 8B 00 - 85 C0 74 ?? 8D 7D ?? 8D 75 ?? 8D 4D ?? 51 56 57 FF 75 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? - 89 45 ?? 83 7D ?? ?? 74 ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? EB ?? FF 75 ?? FF 75 ?? - FF 93 ?? ?? ?? ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? EB ?? C7 45 ?? ?? ?? ?? ?? 8B 45 - ?? 8B 5D ?? C9 C2 + $find_files = { + 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? + ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 06 6F ?? ?? ?? ?? 0C 2B ?? 08 + 6F ?? ?? ?? ?? 0D 09 03 04 28 ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 2D ?? DE ?? 08 2C ?? 08 6F + ?? ?? ?? ?? DC 02 28 ?? ?? ?? ?? 0B 07 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 + ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? + 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 + ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? + 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 03 04 28 ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 17 58 + 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 2A } - $crypt_file = { - 55 89 E5 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 5B 8D BD ?? ?? ?? ?? FF 75 ?? 57 FF 93 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 8D B3 ?? ?? ?? - ?? 56 57 FF 93 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 57 FF 93 ?? ?? ?? ?? 89 45 ?? 8D 85 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 FF 93 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 51 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 30 FF 93 ?? - ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 8D 4D ?? 8D 85 ?? ?? ?? ?? 6A ?? - FF 31 50 FF 36 FF 93 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 8D B5 ?? ?? ?? ?? 51 6A ?? FF 36 68 ?? ?? ?? ?? FF 30 FF 93 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 93 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 89 45 - ?? 6A ?? FF 75 ?? FF 93 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF - 75 ?? FF 93 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 89 45 ?? 8D 7D ?? 8D 75 ?? 8D 55 - ?? 52 56 57 FF 75 ?? FF 93 ?? ?? ?? ?? 8B 45 ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D - 45 ?? 6A ?? 50 FF 75 ?? FF 75 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - FF 75 ?? FF 93 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? FF 75 - ?? FF 75 ?? E8 ?? ?? ?? ?? 8D 7D ?? 8D B5 ?? ?? ?? ?? FF 75 ?? 57 FF 75 ?? 6A ?? 6A - ?? 6A ?? FF 36 FF 93 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? - ?? ?? FF 75 ?? FF 93 ?? ?? ?? ?? 83 F8 ?? 74 ?? 89 45 ?? 8D 45 ?? 6A ?? 50 FF 75 ?? - FF 75 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 85 C0 74 ?? 8D 7D ?? 8D 75 ?? 8D 55 ?? 52 56 57 - FF 75 ?? FF 93 ?? ?? ?? ?? FF 75 ?? FF 93 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D B3 ?? - ?? ?? ?? FF 06 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 93 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 50 FF 93 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 6A ?? 50 FF 93 ?? ?? ?? ?? - 83 7D ?? ?? 74 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? FF 93 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? C9 C2 + $encrypt_files = { + 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 0A 02 + 28 ?? ?? ?? ?? 0B 07 06 28 ?? ?? ?? ?? 0C 02 19 28 ?? ?? ?? ?? 0D 09 16 6A 6F ?? ?? ?? + ?? 09 6F ?? ?? ?? ?? 02 1C 73 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? + ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 11 ?? + 08 16 08 8E 69 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 17 58 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 02 6F + ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 2A } - $enum_files_1 = { - 89 E5 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5B E8 ?? - ?? ?? ?? 8D 7D ?? 6A ?? FF 75 ?? 57 FF 93 ?? ?? ?? ?? 8D 7D ?? 57 FF 93 ?? ?? ?? ?? - 83 F8 ?? 74 ?? EB ?? 8D 75 ?? 56 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? C9 C2 + $aes_encrypt = { + 14 0A 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? 0C 73 ?? ?? + ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 03 07 20 ?? + ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? + ?? ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 17 6F ?? ?? ?? + ?? 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 11 ?? 02 16 02 8E 69 6F ?? ?? ?? ?? 11 + ?? 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 08 6F ?? ?? ?? ?? 0A DE ?? + 09 2C ?? 09 6F ?? ?? ?? ?? DC 08 2C ?? 08 6F ?? ?? ?? ?? DC 06 2A } - $enum_files_2 = { - 55 89 E5 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? - 66 C7 45 ?? ?? ?? C6 45 ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5B 83 7D ?? ?? 0F 84 - ?? ?? ?? ?? FF 75 ?? FF 93 ?? ?? ?? ?? 83 C0 ?? 89 45 ?? 40 50 6A ?? FF 93 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 89 45 ?? FF 75 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 8D 75 ?? 56 - FF 75 ?? FF 93 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 57 FF 75 ?? FF 93 ?? ?? ?? ?? 83 F8 ?? - 0F 84 ?? ?? ?? ?? 89 45 ?? 6A ?? FF 93 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 8D 55 ?? 8D B5 - ?? ?? ?? ?? 52 56 FF 93 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 55 ?? 8D B5 ?? ?? ?? ?? 52 - 56 FF 93 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? FF 93 ?? ?? ?? ?? 40 89 45 ?? 8D BD - ?? ?? ?? ?? 57 FF 93 ?? ?? ?? ?? 03 45 ?? 89 45 ?? 40 50 6A ?? FF 93 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 89 45 ?? FF 75 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 8D 75 ?? 56 FF 75 - ?? FF 93 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 56 FF 75 ?? FF 93 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? A9 ?? ?? ?? ?? 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 85 C0 75 ?? FF 75 ?? E8 ?? ?? ?? ?? - EB ?? 8D B5 ?? ?? ?? ?? FF 75 ?? 56 FF 75 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 - ?? FF 93 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 57 FF 75 ?? FF 93 ?? ?? - ?? ?? 85 C0 74 ?? E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF - 75 ?? FF 93 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? FF 93 ?? ?? ?? ?? 83 7D ?? ?? 74 - ?? FF 75 ?? FF 93 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? C9 C2 + $encrypt_pass = { + 72 ?? ?? ?? ?? 0A 06 73 ?? ?? ?? ?? 0B D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0C + 08 07 6F ?? ?? ?? ?? A5 ?? ?? ?? ?? 0D 73 ?? ?? ?? ?? 13 ?? 11 ?? 09 6F ?? ?? ?? ?? 7E + ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? + 16 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 2A } condition: - uint16(0)==0x5A4D and $enum_files_1 and $enum_files_2 and $crypto_file and $crypt_file and $remote_connection + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($aes_encrypt) and ($encrypt_pass) } -rule REVERSINGLABS_Win32_Ransomware_Zerocrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Plague17 : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects ZeroCrypt ransomware." + description = "Yara rule that detects Plague17 ransomware." author = "ReversingLabs" - id = "89e47d7f-1ac4-570d-8ae1-30f0acc21462" - date = "2020-07-15" - modified = "2020-07-15" + id = "065c47b5-f459-529e-8046-7394a742b50a" + date = "2021-02-19" + modified = "2021-02-19" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.ZeroCrypt.yara#L1-L94" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "947925206ded187eac31c5046d75ab017869ae3f8dc906f2e5536d4db219f108" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Plague17.yara#L1-L263" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "e0e518fc83a62d70b83df273c6ba469e6f0fdf9c035126428ec7561e04437b6f" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -43997,96 +43938,245 @@ rule REVERSINGLABS_Win32_Ransomware_Zerocrypt : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "ZeroCrypt" + tc_detection_name = "Plague17" tc_detection_factor = 5 importance = 25 strings: - $encrypt_file_1 = { - 55 8B EC 83 E4 ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? - ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 56 57 A1 ?? ?? ?? ?? 33 C4 50 8D 84 24 ?? ?? - ?? ?? 64 A3 ?? ?? ?? ?? 8B F2 8B F9 68 ?? ?? ?? ?? 8B D7 8D 4C 24 ?? E8 ?? ?? ?? ?? - 83 C4 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 8B D0 56 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? C6 84 24 ?? ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? FF 74 24 ?? E8 ?? ?? ?? ?? - 83 C4 ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? 83 7E ?? ?? C7 44 24 ?? ?? ?? ?? ?? 66 89 44 - 24 ?? 72 ?? 8B 16 EB ?? 8B D6 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? - ?? ?? 33 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 - 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 84 24 ?? ?? ?? ?? - C6 84 24 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 8B D6 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B F0 C6 84 24 ?? ?? ?? ?? ?? 8B - D7 68 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 84 24 ?? ?? ?? ?? ?? 8B D0 - 56 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 84 24 ?? ?? ?? ?? ?? 8B D0 68 ?? ?? ?? ?? - 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 C6 84 24 ?? ?? ?? ?? ?? 8D 84 24 ?? ?? ?? - ?? 3B C6 74 ?? 83 BC 24 ?? ?? ?? ?? ?? 72 ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 33 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 56 8D 8C 24 ?? ?? ?? ?? C7 84 24 ?? ?? - ?? ?? ?? ?? ?? ?? 66 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 83 - 7C 24 ?? ?? 72 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 ?? C6 84 24 ?? ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? - FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? 66 89 44 24 ?? C6 84 24 ?? ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? FF 74 24 ?? E8 ?? - ?? ?? ?? 83 C4 ?? 33 C0 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 66 89 44 24 + $find_files_p1 = { + 55 89 E5 57 56 8D 85 ?? ?? ?? ?? 53 81 EC ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 31 C0 66 89 + 85 ?? ?? ?? ?? 8B 45 ?? 89 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 50 ?? 8B + 00 66 83 7C 50 ?? ?? 74 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? BA ?? ?? ?? + ?? 2B 51 ?? 39 D0 0F 87 ?? ?? ?? ?? 8B 4D ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 45 ?? 8B 7D ?? 83 EC ?? 8B 00 8B 57 ?? 8D 8D ?? ?? ?? ?? 8D 14 50 C6 44 + 24 ?? ?? 89 04 24 89 8D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 54 24 ?? E8 ?? ?? ?? ?? 83 + EC ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 2B 95 ?? ?? ?? ?? 39 D0 0F + 87 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 83 EC ?? 8D 8D ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 83 EC ?? 39 F8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 7D ?? 8D } - $encrypt_file_2 = { - C6 84 24 ?? ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? - 33 C0 C7 44 24 ?? ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? 66 89 44 - 24 ?? 8D B4 24 ?? ?? ?? ?? 0F 43 BC 24 ?? ?? ?? ?? 8D 44 24 ?? 83 BC 24 ?? ?? ?? ?? - ?? 50 0F 43 B4 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 57 56 8B 00 FF D0 85 C0 68 ?? ?? ?? ?? 0F 95 C3 E8 ?? ?? ?? ?? 83 C4 ?? 85 - C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 84 DB 0F 84 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? - 8D 44 24 ?? 8D B4 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 0F 43 B4 24 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 56 8B 00 FF D0 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 6A - ?? 50 E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 - 84 24 ?? ?? ?? ?? ?? 8D 4C 24 ?? 6A ?? 83 EC ?? E8 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 4C - 24 ?? E8 ?? ?? ?? ?? 6A ?? 83 EC ?? 8D 8C 24 ?? ?? ?? ?? 8B 58 ?? 03 18 E8 ?? ?? ?? - ?? 6A ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 44 24 ?? ?? ?? ?? - ?? 8D 44 24 ?? 50 E8 ?? ?? ?? ?? 33 C9 8B 00 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 - 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? - ?? ?? ?? 66 89 8C 24 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 89 84 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? - ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8B F8 8D 4C 24 ?? 57 BE ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 4C 24 ?? 8B 41 ?? F6 84 04 ?? ?? ?? ?? ?? 74 ?? 8D 4C 24 ?? BA ?? ?? ?? ?? - 03 C8 8B F3 33 C0 39 41 ?? 0F 44 C2 83 E0 ?? 89 41 ?? 85 41 ?? 74 ?? 6A ?? E8 ?? ?? - ?? ?? 56 57 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 83 EC ?? 8D 8C 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 6A ?? 56 57 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? F3 0F 6F 00 F3 0F 7F 07 E8 ?? ?? ?? ?? F3 0F 6F + $find_files_p2 = { + 9D ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 89 D9 8B 00 C6 44 24 ?? ?? 8B 57 ?? 89 B5 ?? ?? ?? + ?? 89 04 24 8D 14 50 89 54 24 ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 EC ?? 89 1C 24 + E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 39 F0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 89 5C 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 83 F8 ?? 89 C6 0F 84 ?? + ?? ?? ?? 8D BD ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 85 C0 74 + ?? C7 44 24 ?? ?? ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? F6 85 ?? ?? + ?? ?? ?? 89 7C 24 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 0F 85 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? 83 EC ?? 39 C8 74 ?? 89 04 24 E8 ?? ?? ?? ?? EB ?? C7 44 24 ?? + ?? ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 85 C0 75 ?? 89 5C 24 ?? 89 34 24 FF 15 ?? ?? ?? + ?? 83 EC ?? 85 C0 75 ?? 89 34 24 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 9D ?? ?? ?? + ?? 83 EC ?? 39 D8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 65 ?? 5B 5E 5F 5D C2 ?? ?? 8D 76 + ?? 8D BC 27 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 85 C0 74 } - $encrypt_file_3 = { - 00 F3 0F 7F 47 ?? F3 0F 6F 40 ?? F3 0F 7F 47 ?? F3 0F 6F 40 ?? 8D 84 24 ?? ?? ?? ?? - 50 51 F3 0F 7F 47 ?? 57 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 - ?? 85 F6 74 ?? 6A ?? 83 EC ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF B4 24 ?? - ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 85 C0 75 ?? 8B 44 24 ?? 8D 4C 24 ?? 8B 40 ?? 03 C8 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 - ?? 83 C8 ?? 83 E0 ?? 89 41 ?? 85 41 ?? 74 ?? 6A ?? E8 ?? ?? ?? ?? 85 F6 74 ?? 56 E8 - ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B3 ?? C6 84 24 ?? ?? ?? ?? ?? 8D 8C - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 89 44 24 ?? C6 84 24 ?? - ?? ?? ?? ?? 50 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 32 DB - C6 84 24 ?? ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 72 ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? 33 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? - ?? 66 89 84 24 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 72 ?? FF - B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? - ?? 83 BC 24 ?? ?? ?? ?? ?? 72 ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 - C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 84 24 ?? ?? ?? ?? 8A C3 C7 84 24 ?? ?? ?? ?? - ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 8C 24 ?? ?? ?? - ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + $find_files_p3 = { + 8B 45 ?? F6 85 ?? ?? ?? ?? ?? 89 7C 24 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 75 + ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 83 EC ?? 39 D0 0F 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? EB ?? 89 + C3 8B 85 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 39 F0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8D B5 ?? ?? ?? ?? 39 F0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? + ?? EB ?? 89 C3 8B 85 ?? ?? ?? ?? 39 F0 75 ?? EB ?? EB ?? EB ?? 89 C3 EB ?? C7 04 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB + } + $encrypt_files_p1 = { + 55 89 E5 57 56 53 81 EC ?? ?? ?? ?? 8B 45 ?? 89 8D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 00 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 83 + F8 ?? 89 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 89 C6 8D 85 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? + 89 34 24 89 44 24 ?? FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 8B 95 ?? ?? ?? ?? + 89 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 89 34 24 05 ?? ?? ?? ?? 89 85 + ?? ?? ?? ?? 89 44 24 ?? 83 D2 ?? A1 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 89 54 24 ?? 89 85 + ?? ?? ?? ?? FF D0 31 C0 83 EC ?? 83 BD ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 AB 7C ?? 0F + 8E ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 74 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? + 83 EC ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 85 C0 0F + 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 35 ?? ?? ?? ?? 0B 85 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? + 80 7D ?? ?? 0F 85 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 C3 8D 85 ?? ?? + ?? ?? 89 D9 89 04 24 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? + ?? ?? 83 EC ?? 8B B5 ?? ?? ?? ?? 89 D9 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 1E 0F A4 C2 ?? C1 E0 ?? 89 95 ?? ?? ?? ?? 89 85 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D + } + $encrypt_files_p2 = { + 85 ?? ?? ?? ?? 89 04 24 8B 0E E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 89 04 24 8B + 85 ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 + ?? 8B 0E E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 89 04 24 89 54 + 24 ?? 8B 0E 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 83 EC ?? 8B 85 ?? ?? + ?? ?? 85 FF 0F 84 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 95 + ?? ?? ?? ?? 8D BD ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? 89 44 24 ?? 8B 85 + ?? ?? ?? ?? 89 54 24 ?? 89 04 24 FF 95 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? C7 04 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 89 + 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 2B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? + 1B 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 0F AC D0 ?? C1 EA ?? 89 D3 09 + C3 0F 84 ?? ?? ?? ?? 83 C0 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? 83 D2 ?? 89 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? + 90 8D B4 26 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 74 24 ?? C7 44 + 24 ?? ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 FF 95 ?? ?? ?? ?? 8B 8D ?? + ?? ?? ?? 8B 9D ?? ?? ?? ?? 83 EC ?? 8B 95 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C + } + $encrypt_files_p3 = { + 24 ?? 89 0C 24 8B 0A E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 8B + 9D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? 89 44 24 ?? 89 54 24 ?? 89 1C 24 + FF 95 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 EC ?? 89 9D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 89 4C 24 ?? FF 15 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 83 EC ?? 8B 95 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 81 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? 83 95 ?? ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 5C + 24 ?? 89 54 24 ?? 89 04 24 FF 95 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 83 + EC ?? 81 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 D9 83 95 ?? ?? ?? ?? ?? 8B 02 89 04 24 E8 ?? + ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 EC ?? 8B 95 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D + ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 0B 89 85 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 04 24 8B 0B E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 83 EC ?? 89 04 24 8B 85 ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? 8B + 85 ?? ?? ?? ?? 89 44 24 ?? 8B 0B E8 ?? ?? ?? ?? 8B 0B 83 EC ?? E8 ?? ?? ?? ?? 8B 9D + ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 89 1C 24 FF 15 ?? ?? ?? ?? 8B + } + $encrypt_files_p4 = { + 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? 89 1C + 24 89 44 24 ?? 89 54 24 ?? FF 95 ?? ?? ?? ?? 83 EC ?? 83 85 ?? ?? ?? ?? ?? 8B 9D ?? + ?? ?? ?? 83 95 ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 31 CB 31 D0 89 DA 09 C2 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 2B 85 ?? ?? ?? ?? 8B 95 + ?? ?? ?? ?? 1B 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 74 24 ?? 89 4C 24 ?? 8B 8D ?? ?? ?? ?? + 89 C3 89 44 24 ?? 89 0C 24 FF 95 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 8B 85 ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 8B 95 ?? ?? ?? ?? 89 14 24 8B 08 E8 ?? ?? + ?? ?? 83 EC ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 7C 24 ?? 8B BD ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 89 54 24 ?? 89 3C 24 FF 95 ?? ?? ?? ?? 83 EC ?? 8B + 95 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 89 5C 24 ?? 8B 1D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? 89 74 24 ?? 89 54 24 ?? 89 3C 24 89 9D ?? ?? ?? ?? FF D3 8B 95 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 83 EC ?? B9 ?? ?? ?? ?? C7 85 + } + $encrypt_files_p5 = { + 89 DF C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F AC D0 ?? C1 EA + ?? 01 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 11 95 ?? ?? ?? ?? 31 C0 C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? F3 AB C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? C7 44 24 ?? ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 89 54 24 ?? E8 ?? ?? ?? ?? 8B BD ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 89 5C 24 ?? C7 04 24 ?? ?? ?? ?? 89 85 ?? ?? + ?? ?? 89 7C 24 ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 31 C0 F3 AB 8B BD ?? ?? ?? ?? 89 74 + 24 ?? 8D B5 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 74 24 ?? + 89 3C 24 FF 95 ?? ?? ?? ?? 83 EC ?? 89 3C 24 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 + EC ?? 8B 18 85 DB 74 ?? 89 D9 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? + ?? 8D 65 ?? 31 C0 5B 5E 5F 5D C2 ?? ?? 8D BD ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? 8B B5 + ?? ?? ?? ?? 31 D2 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? F3 AB 8B BD ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? 89 F9 C1 F9 ?? 83 E1 ?? 89 C8 01 F0 11 FA 0F AC D0 ?? C1 FA ?? 83 + } + $encrypt_files_p6 = { + C0 ?? 83 D2 ?? 0F A4 C2 ?? C1 E0 ?? 89 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 89 FA 09 F2 + 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 8D 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 F7 C6 00 ?? 83 C0 ?? 39 C2 75 ?? 89 BD + ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 C3 8B 85 ?? ?? ?? ?? 89 D9 89 04 + 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 89 18 A1 ?? ?? ?? ?? 89 44 24 ?? 8D 85 + ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 89 + 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 75 ?? 83 C0 + ?? 83 EC ?? 8B 56 ?? 39 D0 0F 87 ?? ?? ?? ?? 8B 7D ?? 29 C2 8D B5 ?? ?? ?? ?? 8D 9D + ?? ?? ?? ?? 8B 0F C6 44 24 ?? ?? 89 9D ?? ?? ?? ?? 8D 0C 41 8D 04 51 89 0C 24 89 F1 + 89 44 24 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 89 34 24 8D 48 ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 39 D8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? + 8D B5 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 8B 47 ?? 89 34 24 89 44 24 ?? E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 0F C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 90 89 34 24 8B + 0F 83 C6 ?? E8 ?? ?? ?? ?? 83 EC ?? 39 DE 75 ?? 8B BD ?? ?? ?? ?? 8B B5 + } + $encrypt_files_p7 = { + 8B 0F E8 ?? ?? ?? ?? 8B 07 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 + 04 24 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 8B 85 ?? ?? ?? ?? + 8B 9D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 8B 0F 89 95 ?? ?? ?? ?? 89 95 + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 04 24 8B 0F E8 ?? ?? ?? ?? 8B 0F 83 EC ?? E8 ?? + ?? ?? ?? 8B 0F 89 F7 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 95 ?? ?? + ?? ?? 8B 95 ?? ?? ?? ?? 89 34 24 8D B5 ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? FF 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 + EC ?? 89 3C 24 C7 44 24 ?? ?? ?? ?? ?? 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 + ?? FF 15 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 83 EC ?? 8B 85 ?? ?? ?? ?? 85 FF 0F 85 ?? ?? + ?? ?? 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 3D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + 0F 87 ?? ?? ?? ?? 3D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 3D + ?? ?? ?? ?? 0F 97 C0 0F B6 C0 89 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 65 ?? B8 ?? ?? ?? + ?? 5B 5E 5F 5D C2 ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 8D 65 + ?? B8 ?? ?? ?? ?? 5B 5E 5F 5D C2 ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 FF 15 + } + $encrypt_files_p8 = { + 83 EC ?? 8D 65 ?? 31 C0 5B 5E 5F 5D C2 ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 + 04 24 ?? ?? ?? ?? 89 C6 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 04 24 C1 F8 ?? 89 F1 89 + 44 24 ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 EC ?? 89 B5 ?? ?? ?? + ?? 89 85 ?? ?? ?? ?? 89 C3 A1 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 + ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 89 + 04 24 89 54 24 ?? 89 74 24 ?? 89 7C 24 ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B BD ?? + ?? ?? ?? 89 95 ?? ?? ?? ?? 89 54 24 ?? 89 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 + 7C 24 ?? 89 44 24 ?? 89 34 24 FF 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 89 5C 24 + ?? C7 44 24 ?? ?? ?? ?? ?? 83 C3 ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 89 44 24 ?? FF + 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 EC ?? 39 C3 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 76 ?? 81 BD ?? ?? + ?? ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? E9 ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? + E9 ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 89 C6 C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 34 24 E8 ?? + ?? ?? ?? 89 C3 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? EB + } + $remote_connection_p1 = { + 55 57 56 53 81 EC ?? ?? ?? ?? 8B 1A 39 18 0F 84 ?? ?? ?? ?? 89 54 24 ?? 89 C6 8D 5C + 24 ?? F6 05 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 DF 8B 56 ?? 89 54 24 + ?? 8B 56 ?? 89 54 24 ?? 8B 56 ?? 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 89 + 3C 24 E8 ?? ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 01 C7 89 F8 29 D8 BA ?? ?? ?? ?? 89 D5 + 29 C5 F6 05 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 06 89 44 24 ?? 8B 46 ?? 89 44 24 ?? + C7 44 24 ?? ?? ?? ?? ?? 89 6C 24 ?? 89 3C 24 E8 ?? ?? ?? ?? 89 5C 24 ?? 8B 7C 24 ?? + 8B 07 89 04 24 E8 ?? ?? ?? ?? FF 47 ?? 8B 46 ?? 01 47 ?? 8B 6E ?? 85 ED 0F 84 ?? ?? + ?? ?? 89 6C 24 ?? 8D 44 24 ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E9 ?? + ?? ?? ?? 8D B6 ?? ?? ?? ?? 8D BC 27 ?? ?? ?? ?? 85 C0 74 ?? C6 03 ?? A8 ?? 0F 85 ?? + ?? ?? ?? 8B 7D ?? 8B 75 ?? 89 2C 24 E8 ?? ?? ?? ?? 89 7C 24 ?? 89 74 24 ?? 89 44 24 + ?? C7 44 24 ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 8B 74 24 ?? 29 F0 89 44 24 ?? 8D 04 33 89 + 04 24 E8 ?? ?? ?? ?? 89 DF 8B 17 83 C7 ?? 8D 82 ?? ?? ?? ?? F7 D2 21 D0 25 ?? ?? ?? + ?? 74 ?? A9 ?? ?? ?? ?? 75 ?? C1 E8 ?? 83 C7 ?? 88 C1 00 C1 83 DF ?? 29 DF 8B 75 + } + $remote_connection_p2 = { + 89 34 24 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 29 F9 39 C1 0F 8D ?? ?? ?? ?? 8D 04 3B 83 F9 + ?? 0F 83 ?? ?? ?? ?? 85 C9 74 ?? 8A 16 88 10 F6 C1 ?? 0F 85 ?? ?? ?? ?? BA ?? ?? ?? + ?? B8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 01 D8 89 04 24 E8 ?? ?? ?? ?? + 89 5C 24 ?? 8B 44 24 ?? 8B 00 89 04 24 E8 ?? ?? ?? ?? 8B 6D ?? 85 ED 74 ?? 8D 44 24 + ?? 89 44 24 ?? 89 2C 24 E8 ?? ?? ?? ?? 85 C0 75 ?? FF 44 24 ?? 8B 44 24 ?? 83 F8 ?? + 0F 82 ?? ?? ?? ?? C7 44 03 ?? ?? ?? ?? ?? 8D 48 ?? C1 E9 ?? 89 DF B8 ?? ?? ?? ?? F3 + AB E9 ?? ?? ?? ?? 8D B6 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 5B 5E 5F 5D C3 90 8D 74 26 ?? + 8D 40 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 10 89 54 24 ?? 8B 50 ?? 89 54 24 ?? 8B 40 ?? 89 + 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 + DA 8B 0A 83 C2 ?? 8D 81 ?? ?? ?? ?? F7 D1 21 C8 25 ?? ?? ?? ?? 74 ?? A9 + } + $remote_connection_p3 = { + 75 ?? C1 E8 ?? 83 C2 ?? 88 C1 00 C1 83 DA ?? 29 DA 8D 3C 13 B8 ?? ?? ?? ?? 29 D0 E9 + ?? ?? ?? ?? 8D B6 ?? ?? ?? ?? 8D BF ?? ?? ?? ?? B8 ?? ?? ?? ?? 29 F8 89 44 24 ?? 89 + 74 24 ?? 01 DF 89 3C 24 E8 ?? ?? ?? ?? 89 D8 8B 08 83 C0 ?? 8D 91 ?? ?? ?? ?? F7 D1 + 21 CA 81 E2 ?? ?? ?? ?? 74 ?? F7 C2 ?? ?? ?? ?? 75 ?? C1 EA ?? 83 C0 ?? 88 D1 00 D1 + 83 D8 ?? 29 D8 BA ?? ?? ?? ?? 29 C2 E9 ?? ?? ?? ?? 8D 74 26 ?? 8D BC 27 ?? ?? ?? ?? + 8B 16 89 10 8B 54 0E ?? 89 54 08 ?? 8D 78 ?? 83 E7 ?? 29 F8 29 C6 01 C1 C1 E9 ?? F3 + A5 E9 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 8D BC 27 ?? ?? ?? ?? 89 54 24 ?? 8D 46 ?? 89 + 04 24 E8 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 6C 24 ?? 89 3C 24 E8 ?? + ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 01 C7 89 F8 29 D8 8B 54 24 ?? 29 C2 89 D5 E9 ?? ?? + ?? ?? 8D B4 26 ?? ?? ?? ?? 8D BC 27 ?? ?? ?? ?? 8B 44 24 ?? 66 C7 44 03 ?? ?? ?? E9 + ?? ?? ?? ?? 66 8B 54 0E ?? 66 89 54 08 ?? E9 ?? ?? ?? ?? 90 8B 54 24 ?? 8B 44 24 ?? + E9 } condition: - uint16(0)==0x5A4D and $encrypt_file_1 and $encrypt_file_2 and $encrypt_file_3 + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Cuba : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Hog : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Cuba ransomware." + description = "Yara rule that detects Hog ransomware." author = "ReversingLabs" - id = "b2c81849-9fa6-58b6-b6fe-4d9a5f0923ea" - date = "2020-07-15" - modified = "2020-07-15" + id = "b4f26acf-5ff1-5c49-8cfa-8f619af84efd" + date = "2021-10-12" + modified = "2021-10-12" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Cuba.yara#L1-L126" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0a8dea6e38a6407897b994ea119bc8b0712a94363b7b3942dcd32c65ee5548d4" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Hog.yara#L1-L70" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "c5cbc79fee9083ed3befa6b0d348f2d38064bb9012b8f0ca11afd7137243866d" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -44094,104 +44184,550 @@ rule REVERSINGLABS_Win32_Ransomware_Cuba : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Cuba" + tc_detection_name = "Hog" + tc_detection_factor = 5 + importance = 25 + + strings: + $generate_key = { + 73 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 1A 8D ?? ?? ?? ?? 0C 2B ?? 07 08 6F ?? ?? ?? ?? 08 + 16 28 ?? ?? ?? ?? 0D 06 72 ?? ?? ?? ?? 09 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 5E 28 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 26 02 25 17 59 10 ?? 16 30 ?? 06 6F ?? ?? ?? ?? 13 ?? DE ?? 07 2C ?? + 07 6F ?? ?? ?? ?? DC 11 ?? 2A + } + $find_files = { + 16 7E ?? ?? ?? ?? 73 ?? ?? ?? ?? 0A 06 16 16 6F ?? ?? ?? ?? 2D ?? DD ?? ?? ?? ?? 00 1F + ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? + ?? ?? 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 7E ?? + ?? ?? ?? 6F ?? ?? ?? ?? 17 31 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? + ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C + 2B ?? 08 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 2D ?? DE ?? 08 2C ?? 08 6F ?? + ?? ?? ?? DC 28 ?? ?? ?? ?? DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC DE ?? 26 28 ?? ?? ?? ?? + DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? DC 2A + } + $encrypt_files_p1 = { + 02 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 02 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? + ?? ?? ?? 31 ?? DD ?? ?? ?? ?? 73 ?? ?? ?? ?? 0A 06 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 06 1F ?? 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 19 + 73 ?? ?? ?? ?? 0B 02 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 08 06 6F ?? ?? ?? + ?? 17 73 ?? ?? ?? ?? 0D 08 06 6F ?? ?? ?? ?? 16 06 6F ?? ?? ?? ?? 8E 69 6F ?? ?? ?? ?? + 07 09 6F ?? ?? ?? ?? DE ?? 09 2C ?? 09 6F ?? ?? ?? ?? DC DE ?? 08 2C ?? 08 6F ?? ?? ?? + ?? DC DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? DC 02 28 ?? + ?? ?? ?? DE ?? 26 DE ?? 2A + } + $encrypt_files_p2 = { + 73 ?? ?? ?? ?? 0A 06 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 1F ?? 8D ?? ?? ?? + ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 6F ?? ?? ?? ?? 0B + 73 ?? ?? ?? ?? 0C 08 06 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 0D 09 07 16 07 8E 69 6F ?? ?? + ?? ?? 09 6F ?? ?? ?? ?? DE ?? 09 2C ?? 09 6F ?? ?? ?? ?? DC 08 6F ?? ?? ?? ?? 28 ?? ?? + ?? ?? 10 ?? DE ?? 08 2C ?? 08 6F ?? ?? ?? ?? DC 02 13 ?? DE ?? 06 2C ?? 06 6F ?? ?? ?? + ?? DC 26 DE ?? 02 2A 11 ?? 2A + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ($generate_key) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Encoded01 : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Encoded01 ransomware." + author = "ReversingLabs" + id = "923d987e-f888-5b6a-9ebd-ee1257124aed" + date = "2021-12-16" + modified = "2021-12-16" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Encoded01.yara#L1-L141" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "f6f872290f15f4c564911bb099824c47cb13164457e1bcdb02dee441bc2d6b6a" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Encoded01" tc_detection_factor = 5 importance = 25 strings: $find_files_p1 = { - 51 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8B D7 8D 4D ?? E8 ?? - ?? ?? ?? 83 C4 ?? C6 45 ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 72 ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? - 0F B7 00 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? - 0F B7 40 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 - ?? 0F B7 40 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? 83 7D ?? ?? 8D 45 ?? 0F 43 - 45 ?? 0F B7 40 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? B0 ?? EB ?? 32 C0 84 C0 - 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D3 C6 - 45 ?? ?? 8B C8 E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 55 ?? 83 FA ?? 0F 82 ?? ?? ?? ?? 8B 4D - ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 - ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8D 55 ?? - 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 75 ?? 8B 5D ?? 83 FB ?? 8B 7D ?? 8B 45 ?? 0F - 43 F7 83 F8 ?? 75 ?? B9 ?? ?? ?? ?? 8B D0 2B F1 66 8B 04 0E 66 3B 01 75 ?? 83 C1 ?? - 83 EA ?? 75 ?? E9 ?? ?? ?? ?? 8B 45 ?? 83 FB ?? 8D 75 ?? 0F 43 F7 83 F8 ?? 75 ?? B9 - ?? ?? ?? ?? 8B D0 2B F1 66 8B 04 0E 66 3B 01 75 ?? 83 C1 ?? 83 EA ?? 75 ?? E9 ?? ?? - ?? ?? 8B 45 ?? 83 FB ?? 8D 75 ?? 0F 43 F7 83 F8 ?? 75 ?? B9 ?? ?? ?? ?? 8B D0 2B F1 + 55 8B EC 51 B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 ?? 51 87 4D ?? 53 56 57 89 4D ?? 89 55 + ?? 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? + 64 FF 30 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 8C ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 8B 15 ?? ?? ?? ?? 8B 12 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? + 8B 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 8E ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 8B 55 ?? 66 83 7C 42 ?? ?? 75 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B D0 4A 8D 45 ?? E8 ?? + ?? ?? ?? 8B 7D ?? 4F 85 FF 0F 8C ?? ?? ?? ?? 47 8D 85 ?? ?? ?? ?? 50 FF 75 ?? 68 ?? + ?? ?? ?? 8B 45 ?? 8B 55 ?? FF 34 90 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? + 33 F6 46 81 FE ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 8D + 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 0F 84 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 85 ?? + ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? FF 75 ?? 68 ?? + ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? + 8B 45 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8A 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 } $find_files_p2 = { - 66 8B 04 0E 66 3B 01 75 ?? 83 C1 ?? 83 EA ?? 75 ?? E9 ?? ?? ?? ?? 8B 45 ?? 83 FB ?? - 8D 75 ?? 0F 43 F7 83 F8 ?? 75 ?? B9 ?? ?? ?? ?? 8B D0 2B F1 66 8B 04 0E 66 3B 01 75 - ?? 83 C1 ?? 83 EA ?? 75 ?? E9 ?? ?? ?? ?? 8B 45 ?? 83 FB ?? 8D 75 ?? 0F 43 F7 83 F8 - ?? 75 ?? B9 ?? ?? ?? ?? 8B D0 2B F1 66 8B 04 0E 66 3B 01 75 ?? 83 C1 ?? 83 EA ?? 75 - ?? EB ?? 83 7D ?? ?? 75 ?? 8B 55 ?? 8D 45 ?? 8B 4D ?? 83 FA ?? 0F 43 C1 66 83 38 ?? - 75 ?? 83 FA ?? 8D 45 ?? 0F 43 C1 66 83 78 ?? ?? 75 ?? 83 FA ?? 8D 45 ?? 0F 43 C1 66 - 83 78 ?? ?? 75 ?? 83 FA ?? 8D 45 ?? 0F 43 C1 66 83 78 ?? ?? 74 ?? 8B 8D ?? ?? ?? ?? - 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 5D ?? 8B 7D ?? C6 45 ?? ?? 83 FB ?? 72 ?? 8D 0C 5D ?? - ?? ?? ?? 8B C7 81 F9 ?? ?? ?? ?? 72 ?? 8B 7F ?? 83 C1 ?? 2B C7 83 C0 ?? 83 F8 ?? 0F - 87 ?? ?? ?? ?? 51 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B BD ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B - 9D ?? ?? ?? ?? C6 45 ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B - C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? - ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 88 45 ?? 8B 55 ?? C7 45 - ?? ?? ?? ?? ?? 66 89 45 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA - ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? - ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 + C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 12 E8 ?? ?? ?? ?? 8B 95 + ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8A 55 ?? 8B 45 ?? E8 ?? + ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? A1 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 89 55 ?? 6A ?? 68 ?? + ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 50 ?? 8B 00 E8 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 3B 55 ?? 75 ?? 3B 45 ?? 0F 86 ?? ?? ?? ?? EB ?? 0F 8E ?? ?? ?? ?? 83 7D ?? ?? + 75 ?? 83 7D ?? ?? 0F 86 ?? ?? ?? ?? EB ?? 0F 8E ?? ?? ?? ?? 8B 45 ?? 83 38 ?? 73 ?? + 8B 45 ?? E8 ?? ?? ?? ?? 40 03 C0 50 E8 ?? ?? ?? ?? 59 89 45 ?? 83 7D ?? ?? 0F 84 ?? + ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 40 03 C0 50 8B 45 ?? E8 ?? + ?? ?? ?? 8B D0 8B 45 ?? 59 E8 ?? ?? ?? ?? 8B 45 ?? 50 6A ?? 8D 45 ?? 50 B9 ?? ?? ?? + ?? 33 D2 33 C0 E8 ?? ?? ?? ?? 8B D0 8B 45 ?? E8 ?? ?? ?? ?? EB ?? 8B 45 ?? E8 ?? ?? + ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 40 03 C0 50 E8 ?? ?? ?? ?? 59 89 45 ?? 83 7D ?? ?? 74 + ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 40 03 C0 50 8B 45 ?? E8 ?? ?? ?? + ?? 8B D0 8B 45 ?? 59 E8 ?? ?? ?? ?? 8B 45 ?? 50 6A ?? 8D 45 ?? 50 B9 ?? ?? ?? ?? 33 + D2 33 C0 E8 ?? ?? ?? ?? 8B D0 8B 45 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? EB ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? 74 ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 8A 45 ?? 50 8A 45 ?? 50 FF 75 ?? 68 ?? ?? + ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B + 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 83 F8 ?? 1B C0 + 40 84 C0 0F 85 ?? ?? ?? ?? 83 FB ?? 74 ?? 53 E8 ?? ?? ?? ?? 4F } $enum_resources = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 - 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B DA 89 5D ?? 8D 45 ?? C7 45 ?? ?? ?? - ?? ?? 50 51 6A ?? 6A ?? 6A ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 32 - C0 E9 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 89 75 ?? 85 F6 74 ?? 66 90 - FF 75 ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 56 8D 45 ?? 50 FF 75 ?? FF 15 - ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 FF 39 7D ?? 76 ?? 83 C6 ?? 83 7E ?? ?? 0F 85 - ?? ?? ?? ?? 83 3E ?? 0F 85 ?? ?? ?? ?? 8B 56 ?? 33 C0 66 89 45 ?? 8B C2 C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 58 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C3 8D 4D - ?? D1 F8 50 52 E8 ?? ?? ?? ?? 8B 5D ?? 8D 45 ?? 50 8B CB C7 45 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? - 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 - E8 ?? ?? ?? ?? 83 C4 ?? F7 46 ?? ?? ?? ?? ?? 74 ?? 8D 4E ?? 8B D3 E8 ?? ?? ?? ?? 47 - 83 C6 ?? 3B 7D ?? 0F 82 ?? ?? ?? ?? 8B 75 ?? E9 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF - 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 94 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B - 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + 55 8B EC 83 C4 ?? 53 56 57 8B F9 89 55 ?? 8B F0 8B 5D ?? C6 45 ?? ?? 33 C0 89 03 33 + C0 89 07 8D 45 ?? 50 8B 45 ?? 50 6A ?? 56 6A ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 89 03 83 3B ?? 74 ?? 83 3B ?? 74 ?? + C7 07 ?? ?? ?? ?? 8B 03 33 C9 8B 55 ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 8B 03 50 57 8B 45 + ?? 50 E8 ?? ?? ?? ?? 8B F0 81 FE ?? ?? ?? ?? 75 ?? 8B C3 8B 55 ?? E8 ?? ?? ?? ?? EB + ?? BE ?? ?? ?? ?? EB ?? 81 FE ?? ?? ?? ?? 74 ?? 85 F6 0F 94 45 ?? 80 7D ?? ?? 75 ?? + 8B 03 E8 ?? ?? ?? ?? 33 C0 89 03 33 C0 89 07 8B 45 ?? 50 E8 ?? ?? ?? ?? 8A 45 ?? 5F + 5E 5B 8B E5 5D C2 + } + $remote_connection_p1 = { + BB ?? ?? ?? ?? 83 FB ?? 75 ?? 33 C0 89 45 ?? 83 FB ?? 75 ?? C7 45 ?? ?? ?? ?? ?? 8B + C6 E8 ?? ?? ?? ?? 8B C6 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 FF 33 C0 89 45 ?? 8D 45 ?? + 50 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 5A 2B C2 83 C0 + ?? 50 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 83 C2 ?? 8B 45 ?? 59 E8 ?? ?? ?? + ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 66 BA ?? + ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 5A 2B C2 50 8D 85 ?? ?? ?? ?? 8B 55 ?? + E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? 8B D0 42 8B 45 ?? 59 E8 + ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 66 BA ?? ?? E8 ?? ?? ?? ?? 8B C8 49 BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 85 FF 0F + 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 48 0F 8E ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 45 + ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 6A + ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 + 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? + 8B 45 ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 83 7D + ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 6A + } + $remote_connection_p2 = { + 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 + ?? 8B 06 E8 ?? ?? ?? ?? 99 52 50 8B 45 ?? 03 C7 33 D2 3B 54 24 ?? 75 ?? 3B 04 24 5A + 58 76 ?? EB ?? 5A 58 7E ?? 8B 06 E8 ?? ?? ?? ?? 8B D0 81 C2 ?? ?? ?? ?? 8B C6 E8 ?? + ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 03 C7 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 03 7D + ?? 81 FF ?? ?? ?? ?? 77 ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? + 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? 6A + ?? 8B 45 ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? + 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? + ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? + ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 + ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? + ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B + 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 ?? 8B 06 E8 ?? ?? ?? ?? 99 52 50 + 8B 45 ?? 03 C7 33 D2 3B 54 24 ?? 75 ?? 3B 04 24 5A 58 76 ?? EB ?? 5A 58 7E ?? 8B 06 + E8 ?? ?? ?? ?? 8B D0 81 C2 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 03 + C7 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 03 7D ?? 81 FF ?? ?? ?? ?? 77 ?? 83 7D + ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 E8 + } + $encrypt_files = { + 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? + E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 + ?? 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 + ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? + ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? + 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF + 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 + ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? + ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D + ?? ?? 74 + } + + condition: + uint16(0)==0x5A4D and ($enum_resources) and ( all of ($find_files_p*)) and ($encrypt_files) and ( all of ($remote_connection_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Horsedeal : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Horsedeal ransomware." + author = "ReversingLabs" + id = "c722bc5b-756e-5d46-8530-e20ebb73737c" + date = "2020-10-01" + modified = "2020-10-01" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Horsedeal.yara#L1-L106" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "fa8c425b08606399b5dc7673f3898e3dba7efb6a62e56db8f500cf5072bb590b" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Horsedeal" + tc_detection_factor = 5 + importance = 25 + + strings: + $search_processes = { + 55 8B EC 81 EC ?? ?? ?? ?? 56 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 74 ?? 8D + 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 53 + FF 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF B5 ?? ?? ?? + ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 74 ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 53 FF + 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5B 56 FF 15 ?? + ?? ?? ?? 5E C9 C3 + } + $enum_resources = { + 55 8B EC 83 E4 ?? 83 EC ?? 83 0C 24 ?? 8D 44 24 ?? 53 56 57 50 FF 75 ?? C7 44 24 ?? + ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4C 24 ?? E8 ?? ?? ?? + ?? 8B F0 85 F6 74 ?? EB ?? 33 DB 39 5C 24 ?? 76 ?? 8D 7E ?? F6 47 ?? ?? 74 ?? 8D 47 + ?? 50 E8 ?? ?? ?? ?? EB ?? FF 37 E8 ?? ?? ?? ?? 43 83 C7 ?? 59 3B 5C 24 ?? 72 ?? 8D + 44 24 ?? 50 56 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B CE E8 ?? + ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 + } + $find_files = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 53 56 8B 35 ?? ?? ?? ?? 57 + 8B 7D ?? 74 ?? 68 ?? ?? ?? ?? 57 FF D6 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? + ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 53 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? + ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 8D 44 24 ?? 50 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 83 + C4 ?? A8 ?? 74 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? 68 ?? ?? ?? ?? 8D + 44 24 ?? 50 FF D6 85 C0 74 ?? 53 E8 ?? ?? ?? ?? 59 EB ?? 8B 44 24 ?? A8 ?? 74 ?? 68 + ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? + 50 FF D6 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 74 ?? 8B CB E8 ?? ?? + ?? ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 + ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? + ?? ?? 83 C4 ?? 33 FF 57 68 ?? ?? ?? ?? 6A ?? 57 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? + ?? ?? 8B F0 89 74 24 ?? 83 FE ?? 74 ?? 57 8B 3D ?? ?? ?? ?? 8D 44 24 ?? 50 68 ?? ?? + ?? ?? FF D7 50 68 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 6A ?? 8D 44 24 ?? 50 FF 35 + ?? ?? ?? ?? FF D7 8B 7C 24 ?? 50 FF 35 ?? ?? ?? ?? 57 FF D6 57 FF 15 ?? ?? ?? ?? 8B + CB E8 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 } $encrypt_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 - 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 8B 7D ?? 0F 57 C0 66 0F 13 45 ?? - C7 45 ?? ?? ?? ?? ?? 8B C7 83 7F ?? ?? 72 ?? 8B 07 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? - 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? 83 FB ?? 75 ?? FF 15 ?? ?? - ?? ?? 32 DB E9 ?? ?? ?? ?? 8D 8E ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 - ?? 8D 8E ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 8E ?? ?? ?? ?? 6A ?? 8D - 41 ?? 50 6A ?? 8D 56 ?? 51 52 89 55 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 53 FF 15 - ?? ?? ?? ?? 8B 4D ?? 8B 45 ?? 85 C9 7F ?? 7C ?? 3D ?? ?? ?? ?? 77 ?? 8D 45 ?? 8B CE - 50 E8 ?? ?? ?? ?? EB ?? 85 C9 7F ?? 7C ?? 3D ?? ?? ?? ?? 77 ?? 6A ?? EB ?? 6A ?? 8D - 45 ?? 8B CE 50 E8 ?? ?? ?? ?? 8B 75 ?? 8A D8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 83 - CE ?? 89 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D7 8D 4D ?? E8 ?? ?? ?? ?? - 83 C4 ?? 8D 45 ?? 83 7D ?? ?? 0F 43 45 ?? 83 7F ?? ?? 72 ?? 8B 3F 50 57 FF 15 ?? ?? - ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? - 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? - 33 C0 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? 83 FE ?? 74 ?? 56 FF 15 - ?? ?? ?? ?? 8A C3 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? - ?? ?? 8B E5 5D C2 ?? ?? E8 ?? ?? ?? ?? CC CC CC 55 8B EC 83 E4 ?? 81 EC + 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 56 8B 35 ?? ?? ?? ?? 57 FF 35 ?? ?? ?? ?? + 8B F9 89 7D ?? FF D6 FF 35 ?? ?? ?? ?? 8B D8 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 50 FF + D6 3B C3 0F 84 ?? ?? ?? ?? 6A ?? 59 33 DB 89 4D ?? 8B C3 88 9C 05 ?? ?? ?? ?? 40 3D + ?? ?? ?? ?? 72 ?? 8D 85 ?? ?? ?? ?? 50 51 FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 + 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B CB 89 45 ?? 8A 84 0D ?? ?? ?? ?? 88 44 0D ?? + 41 83 F9 ?? 72 ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 53 6A ?? 53 FF 35 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 6A ?? 58 50 53 6A ?? 68 ?? ?? ?? ?? + 57 89 45 ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 83 65 ?? ?? 57 FF D6 + 8D 0C 47 83 E9 ?? 66 83 39 ?? 75 ?? FF 35 ?? ?? ?? ?? 2B CF 83 C1 ?? D1 F9 8D 04 4F + 50 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? FF 35 ?? ?? ?? ?? FF D6 FF 75 ?? 8B F0 FF + 15 ?? ?? ?? ?? 3B C6 75 ?? 33 F6 46 EB ?? 8B 75 ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? + 8B 4D ?? 8B 45 ?? 85 C9 7F ?? 7C ?? 3D ?? ?? ?? ?? 77 ?? 33 F6 46 85 F6 74 ?? 8B 35 + ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 } $encrypt_files_p2 = { - A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 8B 5D ?? 56 57 8B F9 89 5C 24 ?? 6A ?? - 8D 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 51 8B 17 8B 47 ?? 2B C2 50 52 FF 33 FF 15 ?? ?? - ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 89 43 ?? 32 C0 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 - CC E8 ?? ?? ?? ?? 8B E5 5D C2 ?? ?? 8B 44 24 ?? 8B 57 ?? 8B 0F 89 44 24 ?? 89 54 24 - ?? 89 4C 24 ?? 85 C0 7E ?? 8B D8 8B 47 ?? 8B F3 2B 47 ?? 3B D8 52 0F 43 F0 8D 47 ?? - 56 51 50 E8 ?? ?? ?? ?? 56 FF 74 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 2B DE - 8B 54 24 ?? 03 CE 83 C4 ?? 89 4C 24 ?? 85 DB 7F ?? 8B 5C 24 ?? 6A ?? 6A ?? 0F 57 C0 - 66 0F 13 44 24 ?? FF 74 24 ?? FF 74 24 ?? FF 33 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? - 85 C0 75 ?? FF D6 89 43 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? A1 ?? - ?? ?? ?? 8D 4C 24 ?? 89 44 24 ?? 83 C4 ?? A1 ?? ?? ?? ?? 89 44 24 ?? A1 ?? ?? ?? ?? - 89 44 24 ?? 8D 87 ?? ?? ?? ?? 50 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 4C 24 ?? ?? 8D 44 24 ?? 6A ?? 50 68 ?? ?? ?? ?? 8D 44 24 ?? C7 44 24 - ?? ?? ?? ?? ?? 50 FF 33 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF D6 89 43 ?? 6A ?? 8D 44 24 - ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 74 24 ?? FF 37 FF 33 FF 15 ?? ?? ?? ?? 85 C0 75 ?? - FF D6 89 43 ?? 32 C0 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C2 - ?? ?? 8B 8C 24 ?? ?? ?? ?? B0 ?? 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D C2 + 53 FF 15 ?? ?? ?? ?? 6A ?? FF 75 ?? 8D 55 ?? 6A ?? FF 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 99 6A ?? 6A ?? 52 50 53 FF D7 6A ?? 8D 45 ?? 50 FF + 75 ?? 8D 85 ?? ?? ?? ?? 50 53 FF D6 81 7D ?? ?? ?? ?? ?? 74 ?? E9 ?? ?? ?? ?? 6A ?? + 6A ?? 51 0F 57 C0 50 66 0F 13 45 ?? E8 ?? ?? ?? ?? 8B 4D ?? 2D ?? ?? ?? ?? 8B 35 ?? + ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 DA ?? 89 45 ?? 8B 45 ?? 2D ?? ?? ?? ?? 89 55 ?? 89 45 + ?? 8D 45 ?? 83 D9 ?? 89 45 ?? 89 4D ?? 6A ?? 6A ?? FF 70 ?? FF 30 53 FF D7 6A ?? 8D + 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 6A ?? FF 75 ?? 8D + 55 ?? 6A ?? FF 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? F7 D8 99 6A + ?? 6A ?? 52 50 53 FF D7 6A ?? 8D 45 ?? 50 FF 75 ?? 8D 85 ?? ?? ?? ?? 50 53 FF D6 8B + 45 ?? 83 C0 ?? 83 6D ?? ?? 89 45 ?? 75 ?? 8B 7D ?? 0F 57 C0 6A ?? 6A ?? 66 0F 13 45 + ?? FF 75 ?? C7 45 ?? ?? ?? ?? ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A + ?? 8D 45 ?? 50 53 FF D6 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF + D6 53 FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 68 ?? ?? ?? + ?? 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 C4 ?? 56 57 FF 15 ?? ?? + ?? ?? 8B CE E8 ?? ?? ?? ?? 5F 5E 5B C9 C3 } condition: - uint16(0)==0x5A4D and ($enum_resources) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($enum_resources) and ($search_processes) and ($find_files) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Sarbloh : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Sarbloh ransomware." + author = "ReversingLabs" + id = "532abd77-f091-5c54-87a3-7e8be5253efd" + date = "2021-05-21" + modified = "2021-05-21" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Sarbloh.yara#L1-L88" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "7259aa9d1fe657db220ee50f1610e6439ff61673d92f46ebc3b8cadd990f002c" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Sarbloh" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 8B 45 ?? C6 00 ?? 8B 45 ?? 40 89 45 ?? 39 75 ?? 72 ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? + ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 52 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 75 + ?? 81 FE ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 8B D8 89 5D ?? 85 DB 0F 84 ?? ?? ?? ?? C1 E6 ?? 56 6A ?? 89 75 ?? FF 15 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 7D ?? 8D 85 ?? ?? ?? ?? + 6A ?? 6A ?? 50 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 8B + 8D ?? ?? ?? ?? 8B C1 8B 55 ?? 0B C2 89 4D ?? 89 55 ?? 0F 84 ?? ?? ?? ?? 0F 57 C0 66 + 0F 13 45 ?? 85 D2 0F 8C ?? ?? ?? ?? 7F ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? + 8B 45 ?? 89 45 ?? EB ?? 8B 75 ?? 8B 7D ?? 6A ?? 6A ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? + 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 8B 45 ?? 8B 4D ?? 89 4D ?? 89 45 ?? + 85 C0 0F 8C ?? ?? ?? ?? 7F ?? 85 C9 0F 82 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 8D 85 + ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 6A ?? 6A ?? 56 8B 75 ?? + 8D 45 ?? 56 50 6A ?? 6A ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 85 C0 0F + 85 ?? ?? ?? ?? 8B 75 ?? EB ?? 33 F6 8B 45 ?? 8B 4D ?? 89 75 ?? 89 4D ?? 89 45 ?? 85 + C0 0F 8C ?? ?? ?? ?? 7F ?? 85 C9 0F 82 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? 50 8D 85 ?? + ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 33 FF 85 C0 0F 88 ?? ?? ?? ?? 85 F6 0F 84 + } + $encrypt_files_p2 = { + 8B 75 ?? 8D 45 ?? 56 50 53 52 6A ?? 52 FF 75 ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 56 53 8D 45 ?? 50 6A ?? 6A ?? 6A ?? FF 75 ?? + FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? ?? 8B 4D ?? + 81 C7 ?? ?? ?? ?? 3B 7D ?? 72 ?? 8B 75 ?? 03 75 ?? 8B 45 ?? 83 D0 ?? 89 75 ?? 89 45 + ?? 3B 45 ?? 0F 8C ?? ?? ?? ?? 7F ?? 3B B5 ?? ?? ?? ?? 8B 75 ?? 0F 82 ?? ?? ?? ?? 8D + 45 ?? 50 6A ?? 6A ?? 6A ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? F7 D8 6A ?? 1B DB 8D 45 + ?? 23 5D ?? 50 6A ?? 6A ?? 6A ?? 6A ?? FF 75 ?? 89 5D ?? 89 5D ?? FF 15 ?? ?? ?? ?? + F7 D8 1B F6 23 75 ?? 56 6A ?? 89 75 ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 + 85 FF 0F 84 ?? ?? ?? ?? 8D 45 ?? 89 5D ?? 50 57 6A ?? 6A ?? 6A ?? FF 75 ?? FF 15 ?? + ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 56 8D 45 ?? 89 5D ?? 50 57 6A ?? 6A ?? 6A ?? FF 75 + ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 56 57 8D 45 ?? 50 6A ?? 6A + ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 85 C0 78 ?? 39 75 ?? 75 ?? + 8B 85 ?? ?? ?? ?? 6A ?? 6A ?? 89 85 ?? ?? ?? ?? 8B 45 ?? 6A ?? 89 85 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 8D 45 ?? 89 9D ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? FF 75 ?? 89 B5 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 85 C0 78 ?? 33 C0 B9 ?? ?? ?? ?? 83 + 7D ?? ?? 0F 44 C1 89 45 ?? 89 7D ?? 83 7D ?? ?? 74 ?? 8B 4D ?? 03 4D ?? 39 4D ?? 73 + ?? 90 8B 45 ?? C6 00 ?? 8B 45 ?? 40 89 45 ?? 39 4D ?? 72 ?? 57 6A ?? FF 15 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 8B 5D ?? 8B 7D ?? 8B 75 ?? EB + } + $find_files_p1 = { + 55 8B EC 83 EC ?? 53 56 8B 75 ?? 57 8B F9 83 3E ?? 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 8D + 45 ?? 50 52 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 89 45 ?? 8D + 45 ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 57 C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 0F 89 4D ?? 85 C0 78 ?? + 83 F9 ?? 74 ?? FF 75 ?? BB ?? ?? ?? ?? C7 06 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 50 + FF 15 ?? ?? ?? ?? 8B 55 ?? EB ?? FF 75 ?? C7 06 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 8B 17 33 DB 89 55 ?? C7 45 + ?? ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 4D ?? 81 C1 ?? ?? ?? ?? 39 4D ?? 73 + } + $find_files_p2 = { + 8B 45 ?? C6 00 ?? 8B 45 ?? 40 89 45 ?? 39 4D ?? 72 ?? 53 6A ?? 6A ?? 6A ?? 68 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? 6A ?? 52 FF 15 ?? ?? ?? ?? 8B F8 33 DB + 89 5D ?? 81 FF ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 55 ?? 85 FF 78 ?? 8B 4D ?? 8B 35 ?? + ?? ?? ?? 2B CB 0F 84 ?? ?? ?? ?? 83 E9 ?? 0F 85 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B C1 + C1 E8 ?? F7 D0 A8 ?? 74 ?? F7 C1 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 FE ?? 74 ?? 83 FE + ?? 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 33 C0 + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Bandarchor : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects BandarChor ransomware." + author = "ReversingLabs" + id = "c645a081-7ff6-58fc-af8e-55f43f56d0ea" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.BandarChor.yara#L1-L97" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "1c0c33ef7de089fc7ed6b364c7693499d1a93f79a48d6f2a5c375e47aea176bc" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "BandarChor" + tc_detection_factor = 5 + importance = 25 + + strings: + $file_extensions_1 = { + 55 8B EC B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 F9 51 53 89 55 ?? 8B D8 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 4D ?? 8B 95 ?? + ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 83 F8 ?? 0F 85 F9 00 00 00 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 55 ?? 8B C3 E8 4F FE FF FF E9 ?? ?? ?? ?? 8D 95 + } + $file_extensions_2 = { + ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? + ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 + ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? + ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 + } + $file_extensions_3 = { + 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? + ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? + 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B + 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 + } + $file_extensions_4 = { + 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D + 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 + ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F + 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? + E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 + } + $file_extensions_5 = { + ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? + ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 + } + $parse_server_commands = { + 83 F9 ?? 0F 84 E0 00 00 00 50 53 56 57 89 C3 89 D6 89 CF 31 D2 8A 06 8A 56 ?? 3C ?? 74 25 3C ?? 74 3E 3C ?? 74 51 3C ?? + 74 5C 3C ?? 74 76 3C ?? 0F 84 84 00 00 00 3C ?? 0F 84 8B 00 00 00 E9 97 00 00 00 83 F9 ?? 89 D8 7F 0A E8 ?? ?? ?? ?? E9 + 91 00 00 00 89 CA E8 ?? ?? ?? ?? E9 85 00 00 00 83 F9 ?? 89 D8 7F 07 E8 ?? ?? ?? ?? EB 77 89 CA E8 ?? ?? ?? ?? EB 6E 89 + D8 83 C3 ?? E8 ?? ?? ?? ?? 4F 7F F3 EB 5F 55 89 D5 8B 54 2E ?? 89 D8 03 5C 2E ?? 8B 4C 2E ?? 8B 12 E8 62 FF FF FF 4F 7F + E8 5D EB 41 55 89 D5 89 D8 03 5C 2E ?? 89 F2 E8 ?? ?? ?? ?? 4F 7F F0 5D EB 2B 89 D8 83 C3 ?? E8 ?? ?? ?? ?? 4F 7F F3 EB + 1C 89 D8 89 F2 83 C3 ?? E8 ?? ?? ?? ?? 4F 7F F1 EB 0B 5F 5E 5B 58 B0 ?? E9 ?? ?? ?? ?? 5F 5E 5B 58 C3 8B C0 B9 ?? ?? ?? + ?? E9 0A FF FF FF C3 + } + + condition: + uint16(0)==0x5A4D and (($file_extensions_1 and $file_extensions_2 and $file_extensions_3 and $file_extensions_4 and $file_extensions_5) and $parse_server_commands) +} +rule REVERSINGLABS_Win32_Ransomware_Lolkek : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Lolkek ransomware." + author = "ReversingLabs" + id = "441badd6-3708-5f74-90f3-4d3a0fc45aff" + date = "2020-10-23" + modified = "2020-10-23" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Lolkek.yara#L1-L106" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "d18545b25a33bba1a6e01ab37768bd4f15fb125dcb8cbe7909d9a8bbe08e63fa" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Lolkek" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files = { + 57 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? A1 ?? + ?? ?? ?? B9 ?? ?? ?? ?? FF 0D ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 3C 85 ?? ?? ?? ?? 40 99 + F7 F9 89 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 53 8B 1D ?? ?? ?? ?? 56 8B CF E8 ?? ?? ?? ?? 85 C0 74 + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 8B F0 68 ?? ?? ?? ?? 56 FF D3 83 + C4 ?? 56 57 FF 15 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? + 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? A1 ?? ?? + ?? ?? B9 ?? ?? ?? ?? FF 0D ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 3C 85 ?? ?? ?? ?? 40 99 F7 + F9 89 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 85 FF 0F 85 ?? ?? ?? ?? 5E 5B 33 C0 5F C2 + } + $find_volumes_p1 = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 56 + 57 E8 ?? ?? ?? ?? 6A ?? 8D 84 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 6A ?? 50 C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? + ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 + 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? + ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 + ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? + ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 83 C4 ?? 89 74 24 ?? 33 + } + $find_volumes_p2 = { + FF 8B 5C BC ?? 53 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 89 9C B4 ?? ?? ?? ?? 46 47 83 FF + ?? 7C ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 0F 84 ?? ?? ?? ?? 68 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 44 24 ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 57 FF 15 ?? + ?? ?? ?? 8B D8 0F 1F 00 85 F6 74 ?? 8D 44 24 ?? 50 6A ?? 8D 84 24 ?? ?? ?? ?? 50 57 + FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 + ?? 4E 57 FF B4 B4 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? + ?? 85 C0 75 ?? 53 FF 15 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? + ?? ?? 83 C4 ?? 8B 3D ?? ?? ?? ?? 33 F6 8B 1D ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? FF + D7 33 D2 B9 ?? ?? ?? ?? F7 F1 68 ?? ?? ?? ?? 80 C2 ?? 88 94 34 ?? ?? ?? ?? FF D3 46 + 83 FE ?? 7C ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 83 C4 ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 FF 15 + } + $find_files_p1 = { + 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 + F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 5F C9 C3 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? + ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? + FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 5D ?? + 8B CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 EB ?? + 8B 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B EB ?? 33 FF 57 57 + 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 + 45 ?? 8B 4D ?? 8B 55 ?? 53 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C ?? 74 + ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 ?? ?? + ?? ?? 8A 01 88 85 ?? ?? ?? ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 57 E8 + ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? 74 ?? + 3C ?? 8A C3 75 ?? B0 ?? 2B CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D + } + $find_files_p2 = { + 56 1B C0 89 9D ?? ?? ?? ?? 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? + ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 8D ?? ?? ?? ?? F7 D8 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? + ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B + D8 E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D + ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? + 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? + 75 ?? 8A 48 ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? + ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? + ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 + C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 + ?? EB ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 59 8B D8 56 FF 15 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 59 8B C3 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? C9 C3 + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_volumes_p*)) and ( all of ($find_files_p*)) and ($encrypt_files) } rule REVERSINGLABS_Win64_Ransomware_Seth : TC_DETECTION MALICIOUS MALWARE FILE { @@ -44202,8 +44738,8 @@ rule REVERSINGLABS_Win64_Ransomware_Seth : TC_DETECTION MALICIOUS MALWARE FILE date = "2021-04-02" modified = "2021-04-02" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Seth.yara#L1-L122" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Seth.yara#L1-L122" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" logic_hash = "72a9d902eea2381f40d42faa7f1686c4ca54d364af0cbd8711697bbc1a235646" score = 75 quality = 90 @@ -44307,18 +44843,20 @@ rule REVERSINGLABS_Win64_Ransomware_Seth : TC_DETECTION MALICIOUS MALWARE FILE condition: uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Antefrigus : TC_DETECTION MALICIOUS MALWARE FILE +import "pe" + +rule REVERSINGLABS_Win32_Ransomware_Archiveus : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects AnteFrigus ransomware." + description = "Yara rule that detects Archiveus ransomware." author = "ReversingLabs" - id = "903ac92c-1a4a-5645-92db-d00b3bfd6ada" - date = "2021-03-05" - modified = "2021-03-05" + id = "89e5af93-1153-5367-a539-6af77c99c214" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.AnteFrigus.yara#L1-L210" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "b84c01da0ee97a4eb8bf099c71094f994feb4c7185ad75b8b2ccda5eee283a92" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Archiveus.yara#L3-L50" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "2b8a42b98ab3e8b97d2e226e979f342a6a72f21d8f068f59c21ad95764077f8a" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -44326,196 +44864,48 @@ rule REVERSINGLABS_Win32_Ransomware_Antefrigus : TC_DETECTION MALICIOUS MALWARE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "AnteFrigus" + tc_detection_name = "Archiveus" tc_detection_factor = 5 importance = 25 strings: - $find_files_p1 = { - 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 68 ?? ?? ?? ?? 8B D0 - 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 83 65 ?? ?? 8D 8D ?? ?? ?? ?? 83 7D ?? ?? 8D 45 - ?? 51 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 33 C0 8D 7D - ?? AB AB AB 33 C0 89 45 ?? 89 45 ?? 89 45 ?? C6 45 ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - 68 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 59 8B D0 C6 45 ?? ?? 8B 4A ?? 8B 7A ?? 2B - CF 39 4E ?? 76 ?? 8B 46 ?? 2B 46 ?? 3B C7 72 ?? 83 7A ?? ?? 72 ?? 8B 12 57 52 51 8B - CE E8 ?? ?? ?? ?? EB ?? 56 8B CA E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 85 ?? - ?? ?? ?? ?? 8D 45 ?? FF B5 ?? ?? ?? ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? - 83 7D ?? ?? 8D 4D ?? 8B 45 ?? 0F 43 4D ?? 8D 04 41 8D 4D ?? 0F 43 4D ?? 51 50 51 8D - 4D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 83 65 ?? ?? 8D 4D ?? 83 65 ?? ?? 50 E8 ?? - ?? ?? ?? C6 45 ?? ?? 8D 75 ?? 83 7D ?? ?? 8B 55 ?? 0F 43 75 ?? 85 D2 74 ?? 83 C9 ?? - 8D 42 ?? 3B C1 0F 42 C8 03 CE EB ?? 3B CE 74 ?? 49 80 39 ?? 75 ?? 2B CE EB ?? 83 C9 - ?? 83 F9 ?? 0F 84 ?? ?? ?? ?? 83 65 ?? ?? 8D 71 ?? C7 45 ?? ?? ?? ?? ?? C6 45 - } - $find_files_p2 = { - 3B D6 0F 82 ?? ?? ?? ?? 2B D6 8D 45 ?? 83 C9 ?? 83 FA ?? 0F 42 CA 83 7D ?? ?? 51 0F - 43 45 ?? 8D 4D ?? 03 C6 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 8D 45 ?? 50 83 - 61 ?? ?? 83 61 ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 51 51 8D 45 ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? - 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? BF ?? ?? ?? ?? 8B 70 ?? 03 30 3B F7 7D ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 3B F7 7D ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 8B 45 ?? 8D 4D ?? 51 3B 45 ?? 74 ?? 8B C8 E8 ?? ?? - ?? ?? 83 45 ?? ?? EB ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? - C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? - ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 7D ?? 8B 75 ?? 6A ?? 5B 3B F7 74 ?? 56 E8 ?? ?? ?? - ?? 03 F3 59 3B F7 75 ?? 8B 7D ?? 8B 75 ?? 85 F6 74 ?? 3B F7 74 ?? 8B CE E8 ?? ?? ?? - ?? 03 F3 3B F7 75 ?? 8B 75 ?? 8B 45 ?? 2B C6 99 F7 FB 6B C0 ?? 50 56 E8 ?? ?? ?? ?? - 59 59 8D 4D ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E8 - } - $remote_connection_p1 = { - 55 8D AC 24 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 - 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 85 ?? ?? ?? ?? 53 56 57 50 8D 45 ?? 64 A3 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 BA ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? - ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 0F 43 - 8D ?? ?? ?? ?? 03 F9 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? 0F 43 B5 ?? ?? ?? ?? 33 C0 66 89 85 ?? ?? ?? ?? 33 DB 8B C7 89 9D - } - $remote_connection_p2 = { - 2B C6 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 45 ?? C6 45 ?? ?? EB ?? 66 0F BE 06 8D - 8D ?? ?? ?? ?? 0F B7 C0 50 E8 ?? ?? ?? ?? 46 3B F7 75 ?? 53 53 53 53 68 ?? ?? ?? ?? - C6 45 ?? ?? 88 5D ?? FF 15 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 6A ?? 33 C0 50 - 6A ?? 50 50 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 89 45 ?? 85 - C0 74 ?? 6A ?? 68 ?? ?? ?? ?? 33 C9 51 51 51 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 8B F0 85 F6 74 ?? 33 C0 50 50 50 50 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 - ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? - 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 56 FF D7 FF 75 ?? FF D7 53 FF - D7 80 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 8D ?? ?? ?? ?? 33 CD E8 ?? ?? ?? ?? 81 - C5 ?? ?? ?? ?? C9 C3 8B 85 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 3D ?? ?? ?? ?? 73 ?? - 8D 95 ?? ?? ?? ?? C6 84 05 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? - E9 ?? ?? ?? ?? E8 - } - $encrypt_files_p1 = { - 66 39 03 0F 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 33 C0 8D 8D ?? - ?? ?? ?? 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? - ?? 8D 95 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 0F 43 95 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 5B C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 39 9D ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 8D 04 41 8D 8D ?? ?? ?? ?? 0F 43 8D ?? ?? ?? - ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 - 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 BA ?? ?? ?? ?? 8D - 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? - 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? - ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D - } - $encrypt_files_p2 = { - 8D ?? ?? ?? ?? 83 C4 ?? 3B C8 74 ?? 33 C9 88 4D ?? 8D 8D ?? ?? ?? ?? FF 75 ?? 50 E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 56 E8 - ?? ?? ?? ?? 56 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 33 C0 59 89 85 ?? - ?? ?? ?? 89 8D ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 88 - 85 ?? ?? ?? ?? BF ?? ?? ?? ?? C6 45 ?? ?? 57 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 8D 4D - ?? E8 ?? ?? ?? ?? 33 C0 C6 45 ?? ?? 57 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 59 99 F7 F9 8D 4D ?? - 52 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 59 99 F7 F9 8D 8D ?? ?? ?? ?? 52 E8 ?? ?? ?? - ?? 83 EB ?? 75 ?? 8D 95 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 57 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 51 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? - ?? ?? ?? 39 9D ?? ?? ?? ?? 74 ?? 83 BD ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? FF B5 ?? ?? - ?? ?? 0F 43 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 56 8D 4D ?? E8 ?? ?? ?? ?? 59 8D 8D ?? - ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 56 8D 45 ?? - C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 - } - $encrypt_files_p3 = { - 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 56 8D 45 ?? C6 45 ?? ?? 50 8D 85 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? - ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? - E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? 8B F3 39 B5 ?? ?? ?? ?? 76 ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 8A 04 30 04 ?? 88 45 ?? FF 75 ?? E8 ?? ?? ?? - ?? 46 3B B5 ?? ?? ?? ?? 72 ?? 8B F3 39 B5 ?? ?? ?? ?? 76 ?? 83 BD ?? ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 8A 04 30 2C ?? 88 45 ?? FF 75 - ?? E8 ?? ?? ?? ?? 46 3B B5 ?? ?? ?? ?? 72 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 50 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 57 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 59 59 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 51 0F 43 - } - $encrypt_files_p4 = { - 85 ?? ?? ?? ?? 51 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? BE ?? ?? - ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 56 50 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? - ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D - ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? - C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 - ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B D0 C6 45 ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? - ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? - 59 59 68 ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 8D 8D ?? - ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 51 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 8D 8D ?? - ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 8D + $entry_point = { + 68 ?? ?? 40 00 E8 ?? ?? ?? FF } - $encrypt_files_p5 = { - 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? - ?? 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 51 0F 43 85 ?? ?? ?? ?? 51 50 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? - ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 56 50 8D 45 ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D - ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D + $dump_instruction = { + 8B 3D ?? ?? ?? ?? 6A ?? FF D7 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 + 74 ?? 8B 46 ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D0 8D 4D ?? FF 15 ?? ?? ?? ?? + 50 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8D 4D ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A + ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF D7 FF 15 ?? ?? ?? ?? E9 ?? ?? + ?? ?? 8D 4D ?? 51 FF 15 ?? ?? ?? ?? 8D 55 ?? 6A ?? 52 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? + ?? ?? 6A ?? 6A ?? 6A ?? 8D 45 ?? 68 ?? ?? ?? ?? 8D 4D ?? 50 51 FF D3 50 8D 55 ?? 8D + 45 ?? 52 50 FF D3 50 FF 15 } - $encrypt_files_p6 = { - E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 89 65 ?? 50 89 59 ?? 89 59 ?? E8 ?? ?? ?? ?? 83 - EC ?? C6 45 ?? ?? 8B CC 89 65 ?? 8D 85 ?? ?? ?? ?? 50 89 59 ?? 89 59 ?? E8 ?? ?? ?? - ?? 83 EC ?? C6 45 ?? ?? 8B CC 89 65 ?? 8D 85 ?? ?? ?? ?? 50 89 59 ?? 89 59 ?? E8 ?? - ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 8D 85 ?? ?? ?? ?? 50 89 59 ?? 89 59 ?? E8 ?? ?? - ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? 83 C4 ?? 8B F0 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 95 ?? - ?? ?? ?? 03 CA 83 BD ?? ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 2B C8 51 50 56 E8 ?? ?? ?? - ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 53 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? - 68 + $extension_rule = { + 8B 13 6A ?? 68 ?? ?? ?? ?? 52 50 FF 15 ?? ?? ?? ?? D9 85 ?? ?? ?? ?? DB 85 ?? ?? ?? + ?? DD 9D ?? ?? ?? ?? DC 8D ?? ?? ?? ?? DF E0 A8 ?? 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? DC 05 ?? ?? ?? ?? DF E0 A8 ?? 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 4D ?? 89 45 + ?? FF 15 ?? ?? ?? ?? 8B 46 ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D0 8D 4D ?? FF + 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D0 8D 4D ?? FF 15 ?? ?? ?? ?? + 50 6A ?? 6A ?? 6A ?? FF 15 } + $instruction_string = "INSTRUCTIONS HOW TO GET YOUR FILES BACK.txt" wide condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) + uint16(0)==0x5A4D and ($entry_point at pe.entry_point) and $dump_instruction and $extension_rule and $instruction_string } -rule REVERSINGLABS_Win32_Ransomware_Conti : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Ragnarok : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Conti ransomware." + description = "Yara rule that detects Ragnarok ransomware." author = "ReversingLabs" - id = "548b8836-83cb-560c-af5f-33bdb24d15ed" - date = "2020-12-14" - modified = "2020-12-14" + id = "263a671e-dfdb-5ab8-9bb9-355c76a88c10" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Conti.yara#L1-L74" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "4f2b96c8eaf8d112a7bb60647db49616935a336396c705d39d5bb51dfd90c60b" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Ragnarok.yara#L1-L110" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "aaa17ab98b59a5c8c71a2b82a9bf29dd3a1a1719deaf08a3bafa77895bc10311" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -44523,70 +44913,101 @@ rule REVERSINGLABS_Win32_Ransomware_Conti : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Conti" + tc_detection_name = "Ragnarok" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 8B D9 53 FF 15 ?? ?? ?? ?? 89 44 24 ?? - 8D 0C 45 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 89 7C 24 ?? 85 FF 0F 84 ?? ?? ?? ?? 8B 44 - 24 ?? B9 ?? ?? ?? ?? 53 BE ?? ?? ?? ?? 57 66 83 7C 43 ?? ?? 0F 45 F1 FF 15 ?? ?? ?? - ?? 56 57 FF 15 ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 8D 44 24 ?? 50 57 FF 15 ?? ?? ?? ?? - 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? F6 44 24 ?? ?? 74 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 54 24 ?? 8B - CB E8 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 8B CE E8 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? EB ?? - 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 54 24 ?? 8B CB E8 ?? ?? ?? ?? 8B F0 85 F6 - 74 ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 5A 8B C8 C6 01 ?? 41 - 83 EA ?? 75 ?? 83 48 ?? ?? 50 89 70 ?? A1 ?? ?? ?? ?? 52 6A ?? FF 70 ?? FF 15 ?? ?? - ?? ?? 8D 44 24 ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 4C 24 ?? E8 ?? - ?? ?? ?? 83 FF ?? 74 ?? 57 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 + $find_files_p1 = { + 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 + F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 5F 8B E5 5D C3 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 + ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 + 75 ?? FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B + 5D ?? 8B CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 + EB ?? 8B 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B EB ?? 33 FF + 57 57 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 + C5 89 45 ?? 8B 4D ?? 8B 55 ?? 53 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C + ?? 74 ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 + ?? ?? ?? ?? 8A 01 88 85 ?? ?? ?? ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 + 57 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? + 74 ?? 3C ?? 8A C3 75 ?? B0 ?? 2B CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D ?? ?? + ?? ?? 56 1B C0 89 9D ?? ?? ?? ?? 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? + ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 + } + $find_files_p2 = { + 83 C4 ?? 8D 8D ?? ?? ?? ?? F7 D8 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF + 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 + ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? + 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? + ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 + 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 + 38 ?? 75 ?? 8A 48 ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? + ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? + ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? + 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? + 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 59 8B D8 56 FF 15 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 59 8B C3 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } $encrypt_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 BB ?? ?? ?? ?? 8B F9 53 57 FF 15 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - A1 ?? ?? ?? ?? 83 F8 ?? 75 ?? 89 75 ?? 33 F6 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 5D ?? FF 74 B5 ?? 57 FF 15 ?? ?? ?? - ?? 85 C0 75 ?? 46 83 FE ?? 7C ?? 33 C0 40 EB ?? 85 C0 75 ?? 8B 35 ?? ?? ?? ?? BB ?? - ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 00 ?? 40 83 E9 ?? 75 ?? 53 56 FF 15 ?? - ?? ?? ?? 85 C0 74 ?? 2B C6 D1 F8 74 ?? 85 C0 78 ?? 40 50 56 8D 85 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 53 56 FF 15 ?? - ?? ?? ?? 8B F0 85 F6 74 ?? 83 C6 ?? EB ?? 33 C0 5F 5E 5B C9 C3 + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 8B 4D ?? 56 57 89 + 85 ?? ?? ?? ?? 33 FF 33 C0 89 8D ?? ?? ?? ?? 6A ?? 51 89 85 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 8D 70 ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? 8A 0E + 3A 08 75 ?? 84 C9 74 ?? 8A 4E ?? 3A 48 ?? 75 ?? 83 C6 ?? 83 C0 ?? 84 C9 75 ?? 33 C0 + EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 53 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 + 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 8B 40 ?? 8B F8 E8 ?? ?? ?? ?? + 33 D2 B9 ?? ?? ?? ?? F7 F1 8A 04 3A 88 04 1E 46 83 FE ?? 7C ?? FF B5 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 33 C9 23 F9 89 8D ?? ?? ?? ?? 3D ?? ?? ?? ?? + 0F 87 ?? ?? ?? ?? 48 83 E0 ?? 83 C0 ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? + ?? ?? FF B5 ?? ?? ?? ?? 8B F0 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF } $encrypt_files_p2 = { - 55 8B EC 83 EC ?? 53 56 57 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 33 DB 53 FF 15 ?? ?? - ?? ?? 8B F8 85 FF 75 ?? 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 5E 56 68 ?? ?? ?? - ?? 53 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 53 - 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 53 8D 45 - ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 53 8D 45 ?? 50 - FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 53 53 68 ?? ?? ?? - ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 6A - ?? 8D 45 ?? 50 8D 45 ?? 50 8D 45 ?? 50 8B 45 ?? FF 70 ?? FF 15 ?? ?? ?? ?? 85 C0 75 - ?? 6A ?? FF 15 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? 8B 4D ?? - 8B D7 FF 75 ?? E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8B 45 ?? FF 70 ?? FF 15 ?? ?? ?? ?? - 8B 45 ?? B9 ?? ?? ?? ?? 83 48 ?? ?? 8B 45 ?? 8B 58 ?? E8 ?? ?? ?? ?? 8B F0 85 F6 74 - ?? 53 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 56 53 FF 15 ?? ?? ?? - ?? 8B CE E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 8B 49 ?? E8 ?? ?? ?? ?? FF - 75 ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? FF - 75 ?? FF 15 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B C9 C2 + 0F 84 ?? ?? ?? ?? 57 FF B5 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 57 8B F0 E8 ?? ?? ?? + ?? 83 C4 ?? 33 FF 3B B5 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 33 C0 3B 85 ?? ?? ?? ?? 0F 85 + ?? ?? ?? ?? 53 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? + ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 50 53 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 85 ?? ?? ?? + ?? 57 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 3D ?? ?? ?? ?? 75 ?? 57 6A ?? + 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 57 FF B5 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? + ?? 83 C4 ?? 3B 85 ?? ?? ?? ?? 75 ?? 57 E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 33 FF 56 E8 + ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 85 C0 74 ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 5B 85 C0 74 ?? + 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 FF 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 5F 33 CD + 5E E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $disable_fw_and_delete_shadow_volumes = { + 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 74 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A + ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? 50 6A ?? FF D7 E9 ?? ?? + ?? ?? 6A ?? FF 35 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? + 50 FF 35 ?? ?? ?? ?? FF D3 6A ?? FF 35 ?? ?? ?? ?? 8B F0 E8 ?? ?? ?? ?? 8B 48 ?? 51 + FF 35 ?? ?? ?? ?? FF D3 8B F8 8D 85 ?? ?? ?? ?? 50 FF D6 8D 45 ?? 50 8D 85 ?? ?? ?? + ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 40 ?? 50 6A ?? FF 95 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A + ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 35 ?? + ?? ?? ?? 8B 40 ?? 50 6A ?? FF D6 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? + 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? 50 6A ?? + FF D6 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? + ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 40 ?? 50 6A ?? FF D6 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) + uint16(0)==0x5A4D and ($disable_fw_and_delete_shadow_volumes) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Fantom : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Notpetya : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Fantom ransomware." + description = "Yara rule that detects NotPetya ransomware." author = "ReversingLabs" - id = "cd32de8b-2c14-5fb4-be79-365d9848f341" - date = "2021-08-12" - modified = "2021-08-12" + id = "ea655048-4ef7-5dd7-872e-f1c2e38234cf" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Fantom.yara#L1-L97" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "f2aaa9776b7ca302052b3303d45df24cc151a4efc7ea9f4bb3c1f53d10ded03a" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.NotPetya.yara#L1-L73" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "328f0e527fee2145879ee13c003d375db832f7f3eacf7a1eb303393c1c8b5a36" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -44594,91 +45015,73 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Fantom : TC_DETECTION MALICIOUS MALW sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Fantom" + tc_detection_name = "NotPetya" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_1 = { - 00 72 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? - 26 DE ?? 26 DE ?? 02 28 ?? ?? ?? ?? 13 ?? 02 28 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 02 28 - ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? [1-2] 02 72 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 [1-2] 20 - ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 6F - ?? ?? ?? ?? 13 ?? 02 11 ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 02 7B ?? ?? ?? ?? 02 7B - ?? ?? ?? ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 8D ?? ?? - ?? ?? 13 ?? 11 ?? 16 - } - $encrypt_files_2 = { - 72 ?? ?? ?? ?? A2 11 ?? 17 72 ?? ?? ?? ?? A2 11 ?? 18 72 ?? ?? ?? ?? A2 11 ?? - 19 72 ?? ?? ?? ?? A2 11 ?? 1A 72 ?? ?? ?? ?? A2 11 ?? 1B 72 ?? ?? ?? ?? A2 11 - ?? 1C 72 ?? ?? ?? ?? A2 11 ?? 1D 72 ?? ?? ?? ?? A2 11 ?? 1E 72 ?? ?? ?? ?? A2 - 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? - ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? - 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? - ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? - 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 - 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? - ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? - 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? - ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? - 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 - 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? - ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? - 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? - ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? - 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 - 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? - ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? - 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? - ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? - 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 - 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? - ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 + $encrypt_file = { + 8B EC 83 EC ?? 53 56 57 33 F6 56 56 6A ?? 56 56 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? + ?? ?? 8B F8 89 7D ?? 83 FF ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 57 FF 15 ?? ?? ?? ?? 89 + 75 ?? 39 75 ?? 7C ?? B8 ?? ?? ?? ?? 7F ?? 39 45 ?? 76 ?? 89 45 ?? 8B D8 56 53 56 6A + ?? 56 57 FF 15 ?? ?? ?? ?? 89 45 ?? 3B C6 74 ?? FF 75 ?? 56 56 6A ?? 50 FF 15 ?? ?? + ?? ?? 8B F8 3B FE 74 ?? 53 8D 45 ?? 50 8B 45 ?? 57 56 FF 75 ?? 56 FF 70 ?? FF 15 ?? + ?? ?? ?? 85 C0 74 ?? FF 75 ?? 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? FF 75 ?? FF + 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 5B C9 C2 ?? ?? 8B 45 ?? 89 45 ?? C1 + E8 ?? 8D 58 ?? C7 45 ?? ?? ?? ?? ?? C1 E3 ?? E9 } - $lockfile = { - 02 7B ?? ?? ?? ?? 16 FE ?? 3A ?? ?? ?? ?? 21 EA 17 ?? ?? ?? ?? ?? ?? ?? - 03 73 ?? ?? ?? ?? [2-4] 6F ?? ?? ?? ?? [2-4] 21 00 65 CD 1D - 00 00 00 00 FE ?? 16 FE ?? 2D ?? [2-4] FE ?? 16 FE ?? 2D ?? 03 28 - ?? ?? ?? ?? ?? 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? [1-2] 28 ?? ?? ?? ?? [1-2] - 6F ?? ?? ?? ?? [1-2] 02 ?? [1-2] 28 ?? ?? ?? ?? [1-2] 03 [1-2] 28 ?? ?? - ?? ?? 03 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? [1-2] ?? FE ?? - 16 FE ?? 2D ?? 2B ?? 03 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 2B ?? 03 28 ?? ?? ?? ?? ?? 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? [1-2] 28 ?? - ?? ?? ?? [1-2] 6F ?? ?? ?? ?? [1-2] 02 ?? [1-2] 28 ?? ?? ?? ?? [1-2] 03 - [1-2] 28 ?? ?? ?? ?? 03 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 2A + $main = { + 55 8B EC 8B 45 ?? 53 56 8B 35 ?? ?? ?? ?? 57 BF ?? ?? ?? ?? 57 6A ?? BB ?? ?? ?? ?? + 53 83 C0 ?? 6A ?? 50 FF D6 85 C0 75 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? 57 6A + ?? 6A ?? EB ?? 3D ?? ?? ?? ?? 75 ?? 6A ?? 6A ?? 53 8B 45 ?? 6A ?? 83 C0 ?? 50 FF D6 + 85 C0 74 ?? 8B 75 ?? 8B C6 E8 ?? ?? ?? ?? 85 C0 74 ?? 56 6A ?? 56 E8 ?? ?? ?? ?? 56 + E8 ?? ?? ?? ?? FF 76 ?? FF 15 ?? ?? ?? ?? 6A ?? FF 76 ?? FF 15 ?? ?? ?? ?? EB ?? 8B + 75 ?? 56 FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B 5D C2 } - $lockdir = { - 03 28 ?? ?? ?? ?? 0A 03 28 ?? ?? ?? ?? 0B 16 0C 08 06 8E 69 FE ?? 2C ?? - 00 06 08 9A 28 ?? ?? ?? ?? 0D 05 09 28 ?? ?? ?? ?? 16 FE ?? 2D ?? 02 25 - 7B ?? ?? ?? ?? 17 58 7D ?? ?? ?? ?? 02 06 08 9A 04 28 ?? ?? ?? ?? DE ?? - 26 DE ?? 26 DE ?? 08 17 58 0C 2B ?? 16 0C 08 07 8E 69 FE ?? 2C ?? 00 02 - 07 08 9A 04 05 28 ?? ?? ?? ?? 02 07 08 9A 04 28 ?? ?? ?? ?? DE ?? 26 DE - ?? 26 DE ?? 08 17 58 0C 2B ?? 2A + $encryption_loop = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 83 7D ?? ?? 53 56 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? FF 75 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 44 + 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? + ?? ?? 8B 1D ?? ?? ?? ?? 8B 75 ?? 8B 46 ?? 85 C0 74 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 44 24 ?? 66 8B 10 + 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 + D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 44 24 + ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 + C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 44 24 ?? + 50 FF 75 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? F6 44 + 24 ?? ?? 74 ?? F7 44 24 ?? ?? ?? ?? ?? 75 ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? + FF D3 85 C0 75 ?? 8B 45 ?? 56 48 50 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? EB ?? 8D + 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? 8D 51 ?? 66 8B 31 83 C1 ?? 66 85 F6 75 ?? + 2B CA D1 F9 8D 4C 4C ?? 3B C1 74 ?? 50 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF D3 85 C0 74 ?? FF 75 + ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? + ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5E 5B 8B E5 5D C2 } - $sendkey = { - 00 02 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? - 0C 08 72 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 08 72 ?? ?? ?? ?? - 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 08 72 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F - ?? ?? ?? ?? 08 72 ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 07 03 72 ?? ?? ?? ?? 08 - 6F ?? ?? ?? ?? 26 07 6F ?? ?? ?? ?? DE ?? 26 DE ?? 2A + $shutdown = { + 68 ?? ?? ?? ?? 8B CA 8B D0 0F B7 45 ?? 03 C2 33 D2 F7 F6 0F B7 75 ?? 8D 85 ?? ?? ?? + ?? 50 03 F1 8B FA FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? F6 05 ?? ?? ?? + ?? ?? B8 ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? 56 57 8D 8D ?? ?? ?? ?? 51 50 8D 85 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? EB ?? 8D 85 ?? ?? ?? ?? 50 56 57 + 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 85 ?? ?? + ?? ?? 50 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 5F 5E 8B C3 5B C9 C3 } condition: - uint16(0)==0x5A4D and (( all of ($encrypt_files_*)) and $lockfile and $lockdir and $sendkey) + uint16(0)==0x5A4D and $encrypt_file and $main and $encryption_loop and $shutdown } -rule REVERSINGLABS_Win64_Ransomware_Whiteblackcrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Vhdlocker : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects WhiteBlackCrypt ransomware." + description = "Yara rule that detects VHDLocker ransomware." author = "ReversingLabs" - id = "9855c10d-563d-54e0-bc79-945daef947de" - date = "2021-07-05" - modified = "2021-07-05" + id = "696f8145-342b-5da5-b9ec-6f0d16afc465" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.WhiteBlackCrypt.yara#L1-L91" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "37b95cc3412f2f2d02d19c4c15b529c4f67453cb195627b5bab2f353e7602354" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.VHDLocker.yara#L1-L152" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "39d1fbfc79d5ea866498bb1e40d2290469df774ce65b1da04a85c0e4e5b4493c" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -44686,202 +45089,141 @@ rule REVERSINGLABS_Win64_Ransomware_Whiteblackcrypt : TC_DETECTION MALICIOUS MAL sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "WhiteBlackCrypt" + tc_detection_name = "VHDLocker" tc_detection_factor = 5 importance = 25 strings: - $find_files = { - 41 57 41 56 41 55 41 54 55 57 56 53 48 83 EC ?? 4C 8D 3D ?? ?? ?? ?? 45 31 F6 49 89 - CD E8 ?? ?? ?? ?? 48 85 C0 49 89 C4 0F 84 ?? ?? ?? ?? 4C 89 E1 E8 ?? ?? ?? ?? 48 85 - C0 0F 84 ?? ?? ?? ?? 48 8D 68 ?? 4C 89 FA 48 89 E9 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D - 15 ?? ?? ?? ?? 48 89 E9 E8 ?? ?? ?? ?? 85 C0 74 ?? 44 89 F0 48 83 C9 ?? 48 89 EF F2 - AE 4C 89 EF 48 89 CB 48 83 C9 ?? F2 AE 48 F7 D3 48 F7 D1 01 D9 48 63 D9 48 89 D9 E8 - ?? ?? ?? ?? 48 89 D9 4C 89 EA 48 89 C6 48 89 C7 44 89 F0 F3 AA 48 89 F1 E8 ?? ?? ?? - ?? 48 8D 15 ?? ?? ?? ?? 48 89 F1 E8 ?? ?? ?? ?? 48 89 EA 48 89 F1 E8 ?? ?? ?? ?? 48 - 89 F1 E8 ?? ?? ?? ?? 48 89 F1 85 C0 74 ?? E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? 48 89 - F1 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 89 E1 48 83 C4 ?? 5B 5E 5F 5D 41 5C 41 5D 41 5E - 41 5F E9 ?? ?? ?? ?? 48 83 C4 ?? 5B 5E 5F 5D 41 5C 41 5D 41 5E 41 5F C3 + $encrypt_files_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 + ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 45 ?? 6A ?? 68 + ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 89 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 4D ?? 50 51 E8 ?? ?? + ?? ?? 83 C4 ?? 0B C2 74 ?? 53 FF 15 ?? ?? ?? ?? B0 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 33 DB 8D 95 ?? ?? ?? ?? 53 52 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 53 50 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 9D ?? ?? + ?? ?? 89 9D ?? ?? ?? ?? 33 F6 8B FF 6A ?? 53 E8 ?? ?? ?? ?? 88 44 35 ?? 46 83 FE ?? + 7C ?? 8D 4D ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? B8 ?? ?? ?? ?? 8D + B5 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8B CE 89 5D ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 8B F4 89 A5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 72 ?? 8B 8D } - $encrypt_files = { - 41 55 41 54 55 57 56 53 48 83 EC ?? 48 8D 15 ?? ?? ?? ?? 31 F6 4C 8D 2D ?? ?? ?? ?? - 48 89 CD E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 89 C3 E8 ?? ?? ?? ?? 48 89 C7 49 89 D9 41 - B8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 F9 E8 ?? ?? ?? ?? 85 C0 49 89 C4 74 ?? 81 FE ?? - ?? ?? ?? 7F ?? 45 89 E0 48 89 FA 4C 89 E9 E8 ?? ?? ?? ?? 45 31 C0 89 F2 48 89 D9 E8 - ?? ?? ?? ?? 44 01 E6 4D 63 C4 48 89 F9 49 89 D9 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 45 31 - C0 89 F2 48 89 D9 E8 ?? ?? ?? ?? EB ?? 48 89 F9 48 89 EF E8 ?? ?? ?? ?? 48 89 D9 E8 - ?? ?? ?? ?? 31 C0 48 83 C9 ?? F2 AE 48 89 CE 48 F7 D6 48 89 F1 48 83 C1 ?? E8 ?? ?? - ?? ?? 48 89 EA 48 89 C1 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? - 48 89 E9 48 89 C2 48 83 C4 ?? 5B 5E 5F 5D 41 5C 41 5D E9 + $encrypt_files_p2 = { + 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B BD ?? ?? ?? ?? 53 53 33 C9 51 33 C0 50 57 FF 15 ?? ?? + ?? ?? 85 C0 75 ?? 57 FF 15 ?? ?? ?? ?? 32 C0 E9 ?? ?? ?? ?? 53 8D 95 ?? ?? ?? ?? 52 + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? + ?? ?? ?? 89 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 35 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 3B C3 0F 84 ?? ?? ?? ?? 6A ?? F7 D8 99 53 52 50 57 FF 15 ?? + ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B 8D ?? ?? ?? ?? 8D 95 ?? ?? + ?? ?? 52 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 8D 8D ?? ?? ?? ?? 51 50 8D 95 ?? ?? ?? + ?? 52 57 FF D6 85 C0 0F 84 ?? ?? ?? ?? 39 9D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 81 BD ?? + ?? ?? ?? ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 39 9D ?? ?? ?? ?? 77 ?? 81 BD ?? ?? ?? ?? ?? + ?? ?? ?? 0F 82 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 11 9D ?? ?? ?? ?? + 83 FA ?? 0F 84 ?? ?? ?? ?? 53 53 33 C9 51 33 C0 50 52 FF 15 ?? ?? ?? ?? A1 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B C3 8D 50 ?? 66 8B 08 83 C0 ?? 66 85 C9 } - $register_service_p1 = { - 57 56 53 48 81 EC ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 31 C0 41 B9 ?? ?? ?? ?? 48 8D 94 - 24 ?? ?? ?? ?? 48 89 CB B9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 89 D7 F3 AB 48 8D - 44 24 ?? 48 89 54 24 ?? 48 C7 C1 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 15 ?? ?? ?? ?? 48 - C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 80 BC 24 ?? ?? ?? ?? ?? 48 8B 35 ?? ?? ?? - ?? 0F 85 ?? ?? ?? ?? 48 8D 9C 24 ?? ?? ?? ?? 31 C9 41 B8 ?? ?? ?? ?? 48 89 DA FF 15 - ?? ?? ?? ?? 48 8D 44 24 ?? 45 31 C0 41 B9 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 15 ?? ?? - ?? ?? 48 C7 C1 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 48 8D 05 ?? ?? ?? ?? 48 8B - 4C 24 ?? 41 B9 ?? ?? ?? ?? 45 31 C0 C7 44 24 ?? ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 - 89 44 24 ?? FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? - 45 31 C0 48 89 D9 FF 15 ?? ?? ?? ?? 31 C0 E9 ?? ?? ?? ?? 31 C9 FF D6 48 85 C0 79 ?? - B9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 31 C9 BA ?? ?? - ?? ?? 48 C1 E0 ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? - ?? 48 8D 35 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? - 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 89 B4 24 ?? ?? ?? ?? 48 8D + $encrypt_files_p3 = { + 75 ?? 2B C2 6A ?? D1 F8 8D 8D ?? ?? ?? ?? 51 8D 14 00 A1 ?? ?? ?? ?? 52 53 50 FF D6 + 8B 15 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 6A ?? 68 ?? ?? ?? ?? 52 FF D6 8B 15 ?? + ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 4D ?? 51 52 FF D6 8B 0D ?? ?? ?? ?? 6A + ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 51 FF D6 8B 0D ?? ?? ?? ?? 6A ?? 8D 95 + ?? ?? ?? ?? 52 6A ?? 8D 85 ?? ?? ?? ?? 50 51 FF D6 EB ?? 8B 9D ?? ?? ?? ?? 6A ?? 33 + C9 51 51 B8 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 33 DB EB ?? 83 85 ?? ?? + ?? ?? ?? 11 9D ?? ?? ?? ?? 53 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 57 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B 4D ?? 8B 55 + ?? 8B B5 ?? ?? ?? ?? 51 52 8D BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 8D 85 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B D6 52 FF 15 ?? ?? ?? ?? 33 C9 + 51 51 33 C0 51 50 A1 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 51 FF 15 ?? + ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 94 C0 8B 4D ?? 64 + 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } - $register_service_p2 = { - 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 - 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 41 B9 ?? ?? ?? ?? 48 89 F2 48 89 1D ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 89 5C 24 ?? - 48 8B 35 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? - ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF D6 B9 ?? ?? ?? ?? 48 89 C3 FF 15 ?? - ?? ?? ?? BA ?? ?? ?? ?? 48 89 D9 49 89 C0 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D - 54 24 ?? 48 89 C1 FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 41 B9 ?? ?? - ?? ?? 4C 8B 05 ?? ?? ?? ?? 48 89 5C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? - ?? ?? ?? ?? 48 89 44 24 ?? 8B 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? 99 F7 F9 2D ?? ?? ?? ?? 89 44 24 ?? 8B 44 24 ?? 99 F7 F9 31 C9 48 8D 15 ?? ?? ?? - ?? 2D ?? ?? ?? ?? 89 44 24 ?? FF D6 BA ?? ?? ?? ?? 48 89 D9 FF 15 ?? ?? ?? ?? 48 89 - D9 FF 15 ?? ?? ?? ?? 48 8B 35 ?? ?? ?? ?? 48 8D 5C 24 ?? 45 31 C9 45 31 C0 31 D2 48 - 89 D9 FF D6 85 C0 74 ?? 48 89 D9 FF 15 ?? ?? ?? ?? 48 89 D9 FF 15 ?? ?? ?? ?? EB ?? - 8B 84 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5E 5F C3 + $find_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 68 ?? ?? ?? ?? 33 F6 + 8D 8D ?? ?? ?? ?? 33 C0 56 51 66 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 8D 95 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? + 52 FF 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? EB ?? 8D 9B + ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? A8 ?? 0F 85 ?? ?? ?? ?? A8 ?? 0F 84 ?? ?? ?? ?? 57 8D + 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 95 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? + ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? E9 + ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? + 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 } - - condition: - uint16(0)==0x5A4D and ( all of ($register_service_p*)) and ($find_files) and ($encrypt_files) -} -rule REVERSINGLABS_Win32_Ransomware_Juicylemon : TC_DETECTION MALICIOUS MALWARE FILE -{ - meta: - description = "Yara rule that detects JuicyLemon ransomware." - author = "ReversingLabs" - id = "35e4bbd6-422b-562e-98fc-fe932270dbb8" - date = "2020-08-17" - modified = "2020-08-17" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.JuicyLemon.yara#L1-L116" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "596d89843793307f4940dbb85b2e7081f02250f6adfdcd01f2d3c5f2b8b90875" - score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "JuicyLemon" - tc_detection_factor = 5 - importance = 25 - - strings: - $remote_connection_1 = { - 55 8B EC 83 C4 ?? 53 56 57 89 4D ?? 8B FA 8B F0 C6 45 ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? - 6A ?? FF 15 ?? ?? ?? ?? 8B D8 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 57 56 53 FF 15 ?? ?? ?? - ?? 8B F0 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 56 FF 15 - ?? ?? ?? ?? 8B F8 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 6A ?? 68 ?? ?? ?? ?? 57 FF - 15 ?? ?? ?? ?? 85 C0 74 ?? C6 45 ?? ?? 57 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 53 - FF 15 ?? ?? ?? ?? 8A 45 ?? 5F 5E 5B 59 59 5D C2 + $find_files_p2 = { + D8 ?? 3B C6 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 + ?? 66 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 + C0 EB ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 BB ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 90 + 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 + ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 8B FF 66 8B 10 66 3B 11 75 ?? 66 3B D6 74 ?? 66 8B 50 ?? 66 3B 51 + ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D6 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 3B C6 0F 84 ?? + ?? ?? ?? 57 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? + ?? ?? 52 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8B D1 83 C4 ?? 0B D0 89 B5 ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? 74 ?? 50 51 8D + 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 83 C4 ?? 3A C1 75 ?? 01 0D ?? ?? ?? + ?? 11 35 ?? ?? ?? ?? EB ?? 01 0D ?? ?? ?? ?? 11 35 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 + 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 5E 33 CD + B0 ?? 5B E8 ?? ?? ?? ?? 8B E5 5D C3 } - $remote_connection_2 = { - 55 8B EC 33 C9 51 51 51 51 51 51 51 53 56 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? - 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 DB 8D 55 ?? 8B - 45 ?? E8 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? - ?? 66 BE ?? ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? 66 BE ?? ?? 8D 45 ?? E8 - ?? ?? ?? ?? 50 8D 45 ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 50 8D 45 ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B D6 - 59 E8 ?? ?? ?? ?? 84 C0 74 ?? B3 ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $get_logical_drives_list_p1 = { + 8D 85 ?? ?? ?? ?? 50 57 89 BD ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D + 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 57 68 ?? ?? ?? ?? 6A ?? 57 + 57 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? + ?? ?? 83 EC ?? 8B F4 89 7E ?? C7 46 ?? ?? ?? ?? ?? BF ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 + A5 ?? ?? ?? ?? C6 06 ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 + FF 89 7D ?? 83 78 ?? ?? 72 ?? 8B 00 8D 50 ?? 8D A4 24 ?? ?? ?? ?? 8A 08 40 84 C9 75 + ?? 57 8D 8D ?? ?? ?? ?? 2B C2 51 50 83 EC ?? 8B F4 89 7E ?? C7 46 ?? ?? ?? ?? ?? BF + ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 A5 ?? ?? ?? ?? C6 06 ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? + ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 83 C4 ?? 39 70 ?? 72 ?? 8B 00 50 53 FF 15 ?? ?? ?? + ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? + ?? ?? 39 B5 ?? ?? ?? ?? 72 ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 53 FF 15 + ?? ?? ?? ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 8D 64 24 ?? 66 8B 10 66 3B 11 75 ?? 66 85 + D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB } - $find_files_and_encrypt = { - E8 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 14 B2 E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 88 45 ?? 46 4B 75 ?? A1 ?? ?? ?? ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 75 ?? 80 7D ?? ?? 75 ?? 8B 5D ?? 4B 85 DB 7C ?? 43 33 F6 8D 85 - ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 14 B2 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 55 ?? E8 - ?? ?? ?? ?? 46 4B 75 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? 5A E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? - E8 ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 - A1 ?? ?? ?? ?? 8B 00 FF D0 8B 1D ?? ?? ?? ?? 57 A1 ?? ?? ?? ?? 8B 00 FF D0 85 DB 74 - ?? 6A ?? A1 ?? ?? ?? ?? 8B 00 FF D0 EB ?? B3 ?? 8D 85 ?? ?? ?? ?? 8B D3 80 C2 ?? E8 - ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 8B 00 FF - D0 83 F8 ?? 76 ?? 83 F8 ?? 74 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8D 85 ?? - ?? ?? ?? 8B D3 80 C2 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 95 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 57 A1 ?? ?? ?? ?? 8B 00 FF D0 FF 05 ?? - ?? ?? ?? 57 A1 ?? ?? ?? ?? 8B 00 FF D0 8D 46 ?? 50 6A ?? 56 68 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 6A ?? A1 ?? ?? ?? ?? 8B 00 FF D0 4B 80 FB ?? 0F 85 ?? ?? ?? ?? 57 A1 ?? ?? ?? - ?? 8B 00 FF D0 8B 1D ?? ?? ?? ?? 57 A1 ?? ?? ?? ?? 8B 00 FF D0 85 DB 74 ?? 6A ?? A1 - ?? ?? ?? ?? 8B 00 FF D0 EB ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8D 46 ?? BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 A1 ?? ?? ?? ?? 8B 00 FF D0 FF 05 ?? ?? ?? ?? 57 A1 ?? - ?? ?? ?? 8B 00 FF D0 8D 46 ?? 50 6A ?? 56 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? A1 ?? - ?? ?? ?? 8B 00 FF D0 57 A1 ?? ?? ?? ?? 8B 00 FF D0 8B 1D ?? ?? ?? ?? 57 A1 ?? ?? ?? - ?? 8B 00 FF D0 85 DB 74 ?? 6A ?? A1 ?? ?? ?? ?? 8B 00 FF D0 EB ?? A1 ?? ?? ?? ?? BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 52 50 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? 50 B8 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 5A 59 E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? - ?? ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 89 45 ?? C6 45 ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? 8B - 5D ?? 4B 85 DB 7C ?? 43 33 F6 80 7D ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? - 8B 14 B2 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? - ?? ?? 8B 15 ?? ?? ?? ?? 8B 14 B2 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? - ?? ?? 88 45 ?? 46 4B 75 ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? 80 7D - ?? ?? 75 ?? 8B 5D ?? 4B 85 DB 7C ?? 43 33 F6 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B - 14 B2 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 46 4B 75 ?? BA ?? ?? - ?? ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B C8 B8 ?? ?? ?? ?? 5A E8 ?? ?? ?? ?? BA ?? ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B D0 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 - 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C8 B8 ?? ?? ?? - ?? 5A E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 8B D3 B8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? FF 35 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 50 8B D3 B8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8B D3 B8 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? A1 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? - E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? A1 ?? ?? ?? ?? E8 - ?? ?? ?? ?? B2 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 75 ?? - A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 - ?? ?? ?? ?? 75 ?? E8 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $get_logical_drives_list_p2 = { + 1B C0 83 D8 ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 89 85 ?? ?? + ?? ?? 89 B5 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CE D3 E2 85 95 ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? 8D 4E ?? 66 89 8D ?? ?? ?? ?? 33 C9 6A ?? 51 8D 95 ?? ?? ?? ?? 52 C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? 66 89 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 + ?? ?? ?? ?? 6A ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? + ?? 83 EC ?? B8 ?? ?? ?? ?? 8B CC 89 A5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 C4 ?? BF ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 39 78 ?? 72 ?? 8B 00 8D + 50 ?? 8A 08 40 84 C9 75 ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 2B C2 50 83 EC ?? B8 ?? ?? ?? + ?? 8B CC 89 A5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 39 78 ?? 72 ?? 8B 00 50 53 FF 15 ?? ?? ?? ?? 39 BD ?? ?? ?? ?? 72 ?? 8B 95 ?? ?? ?? + ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? BE ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 39 BD ?? ?? ?? ?? 72 ?? 8B 85 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 53 89 B5 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C6 85 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 46 89 B5 ?? ?? ?? ?? 83 + FE ?? 0F 8C ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? B0 ?? 8B + 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and $find_files_and_encrypt and $remote_connection_1 and $remote_connection_2 + uint16(0)==0x5A4D and ( all of ($get_logical_drives_list_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Kovter : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Hermes : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Kovter ransomware." + description = "Yara rule that detects Hermes ransomware." author = "ReversingLabs" - id = "9362ac5a-0b6c-5ac5-ac2b-59dcc1191dc6" + id = "1f1f363a-5be0-59e5-b1c1-5e277922790c" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Kovter.yara#L1-L141" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3082e036b54a73ce8397cfa6e8dc2a807c587d9f17286e75af6cdbe622fae1e1" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Hermes.yara#L1-L284" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6db95c422ee2f9dd8a1795031ee8d7d5ed84e16cde47512becc006b6a849e890" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -44889,141 +45231,251 @@ rule REVERSINGLABS_Win32_Ransomware_Kovter : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Kovter" + tc_detection_name = "Hermes" tc_detection_factor = 5 importance = 25 strings: - $remote_connection_1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D - ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? - 89 5D ?? 89 5D ?? 8B D9 89 55 ?? 89 45 ?? 8B 75 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? - E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 A1 ?? ?? ?? ?? 80 38 ?? 74 - ?? 8B CE 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 33 C0 - 89 45 ?? 33 C0 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 48 75 ?? B3 ?? 8D 45 ?? 50 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? - ?? ?? ?? 5A 2B C2 83 C0 ?? 50 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 83 C2 ?? - 8B 45 ?? 59 E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 5A 2B C2 50 8D - 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? - 8B D0 42 8B 45 ?? 59 E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? 8B C8 49 BA ?? ?? ?? ?? 8B 45 ?? - E8 ?? ?? ?? ?? 84 DB 0F 84 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 48 0F 8E ?? ?? ?? ?? - 6A ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8B F8 85 FF 0F 84 ?? ?? - ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 68 - ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 8D + $hermes_find_files_v1_p1 = { + A5 A5 A5 8D BD ?? ?? ?? ?? 66 AB BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? A5 A5 66 A5 68 ?? + ?? ?? ?? 8D BD ?? ?? ?? ?? 50 AB 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 65 + ?? ?? 8B 5D ?? 8B FB 4F 4F 8D 47 ?? 66 8B 4F ?? 47 47 66 85 C9 75 ?? BE ?? ?? ?? ?? + A5 A5 8D 8D ?? ?? ?? ?? 51 50 66 A5 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 89 45 ?? E8 + ?? ?? ?? ?? 59 59 8B C8 E8 ?? ?? ?? ?? 8B CB 8B D0 E8 ?? ?? ?? ?? 2B C2 33 C9 83 7D + ?? ?? 66 89 0C 43 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? + 8B C1 6A ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? + 8B C1 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 + ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 7D ?? A5 A5 A5 A5 33 } - $remote_connection_2 = { - 45 ?? 50 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 0D ?? ?? - ?? ?? 0D ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 50 8D 45 ?? 50 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 6A - ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 ?? 8D 45 - ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? - ?? ?? ?? 8B C6 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? 01 45 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? - 83 7D ?? ?? 75 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? E9 - ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? - 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8B F8 85 FF - 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? - ?? ?? 50 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D - 45 ?? 50 8D 45 ?? 50 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 - ?? 0D ?? ?? ?? ?? 0D ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 50 8D 45 ?? 50 6A ?? 8B 45 ?? 50 - E8 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? - ?? 85 C0 74 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? - ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? - ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B C6 8B 55 ?? E8 ?? ?? ?? ?? 8B - 45 ?? 01 45 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? 83 7D ?? ?? 75 ?? 8B 45 ?? 50 E8 ?? ?? ?? - ?? 57 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 3E ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? - ?? ?? 48 0F 8E ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 6A - ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8B F8 - 85 FF 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? E8 - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? - ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 8B 45 - ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B + $hermes_find_files_v1_p2 = { + C0 6A ?? 59 6A ?? 8D 7D ?? 66 AB BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 A5 59 BE ?? ?? + ?? ?? 8D BD ?? ?? ?? ?? F3 A5 BE ?? ?? ?? ?? 8D 7D ?? A5 A5 A5 A5 6A ?? 59 8D 7D ?? + AB BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 A5 8D BD ?? ?? ?? ?? AB AB 66 AB BE ?? ?? ?? + ?? 8D 7D ?? A5 A5 A5 A5 33 C0 6A ?? 8D 7D ?? AB 59 BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? + F3 A5 66 A5 8D BD ?? ?? ?? ?? AB BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? A5 A5 A5 A5 8D BD + ?? ?? ?? ?? AB AB AB 66 AB 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 + C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 + 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 + 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D + 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 + 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 0F } - $remote_connection_3 = { - 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? - ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B C6 8B 55 ?? - E8 ?? ?? ?? ?? 8B 45 ?? 01 45 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? 83 7D ?? ?? 75 ?? 8B 45 - ?? 50 E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? - 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 - ?? E8 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8B F8 85 FF 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? - ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 57 E8 ?? - ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B - 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 74 ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? - ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B C6 8B 55 - ?? E8 ?? ?? ?? ?? 8B 45 ?? 01 45 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? 83 7D ?? ?? 75 ?? 8B - 45 ?? 50 E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $hermes_find_files_v1_p3 = { + 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 + 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F + 85 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F + 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D } - $find_files = { - 50 E8 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 33 F6 46 81 FE ?? ?? ?? ?? 0F 87 - ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 8D 57 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? - E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 07 ?? 0F 85 ?? ?? ?? ?? F6 47 ?? ?? 0F 85 ?? ?? - ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? F7 D8 1B C0 F7 D8 84 C0 75 ?? - 6A ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 - ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 57 53 E8 ?? ?? ?? ?? F7 D8 1B C0 F7 D8 84 C0 0F 85 ?? ?? ?? ?? 83 - FB ?? 74 ?? 53 E8 ?? ?? ?? ?? 57 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? - ?? ?? 33 F6 46 81 FE ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 8D 45 - ?? 8D 57 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F - 84 ?? ?? ?? ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 07 ?? 0F - 84 ?? ?? ?? ?? F6 47 ?? ?? 75 ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? FF 75 - ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? F7 D8 1B C0 F7 D8 84 C0 75 - ?? 6A ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF 75 ?? 68 - ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 57 53 E8 ?? ?? ?? ?? F7 D8 1B C0 - F7 D8 84 C0 0F 85 ?? ?? ?? ?? 83 FB ?? 74 ?? 53 E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? F7 D8 1B DB F7 DB 84 DB - 75 ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + $hermes_find_files_v1_p4 = { + 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 45 + ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? F6 85 + ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 53 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8B C8 E8 ?? ?? ?? ?? 83 F8 ?? 7E ?? 53 FF 75 + ?? FF 75 ?? E8 } - $decrypt_payload_script = { - FF 75 ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? FF - 75 ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 - ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? - ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 8B C3 BA ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? FF 33 FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF - 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? - ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF - 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? - ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D - 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? E8 + $hermes_encrypt_files_v1_p1 = { + 55 8B EC 83 EC ?? 53 56 57 FF 75 ?? FF 15 ?? ?? ?? ?? BB ?? ?? ?? ?? 3B C3 74 ?? 53 + FF 75 ?? FF 15 ?? ?? ?? ?? 33 F6 56 53 6A ?? 56 56 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? + ?? ?? ?? 89 45 ?? 3B C6 0F 84 ?? ?? ?? ?? 8D 4D ?? 51 50 FF 15 ?? ?? ?? ?? 89 45 ?? + 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 82 ?? ?? ?? ?? 56 89 45 ?? 8D 45 ?? 50 56 56 + 6A ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? BF ?? ?? ?? ?? 57 FF 75 ?? 56 + FF 15 ?? ?? ?? ?? 89 45 ?? 3B C6 74 ?? 56 8D 4D ?? 51 FF 75 ?? 89 75 ?? 50 FF 75 ?? + FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 8B 4D ?? 8D 44 08 ?? 80 38 ?? 75 ?? 80 78 ?? + ?? 75 ?? 80 78 ?? ?? 75 ?? 80 78 ?? ?? 75 ?? 80 78 ?? ?? 75 ?? 80 78 ?? ?? 75 ?? FF + 75 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 33 C0 5F 5E 5B + } + $hermes_encrypt_files_v1_p2 = { + C9 C3 FF 75 ?? 8D 45 ?? 50 51 56 6A ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 + 56 56 FF 75 ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? + ?? 6A ?? 57 FF 75 ?? 88 45 ?? 56 FF 15 ?? ?? ?? ?? 8B F8 89 7D ?? 3B FE 74 ?? FF 75 + ?? 0F BE 45 ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 56 8D 45 ?? 50 FF 75 ?? 89 75 ?? 57 FF + 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? BF ?? ?? ?? ?? 57 56 FF 75 ?? FF 15 + ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 56 53 6A ?? 56 56 68 ?? ?? ?? ?? FF 75 ?? FF + 15 ?? ?? ?? ?? 8B D8 3B DE 0F 84 ?? ?? ?? ?? 56 8D 45 ?? 50 FF 75 ?? 89 75 ?? FF 75 + ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 56 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? + 53 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 57 56 FF + 75 ?? FF 15 ?? ?? ?? ?? 33 C0 40 E9 + } + $hermes_enum_resources_v1 = { + 55 8B EC 83 EC ?? 53 56 57 8D 45 ?? 50 FF 75 ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A + ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? 6A ?? FF + 15 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? FF 75 ?? 6A ?? 53 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 45 ?? 50 53 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B + 43 ?? 66 83 38 ?? 8D 48 ?? 75 ?? 66 83 78 ?? ?? 75 ?? 6A ?? 51 E8 ?? ?? ?? ?? 59 59 + 85 C0 74 ?? 8B 43 ?? 8B D0 66 8B 08 40 40 66 85 C9 75 ?? 8B 7D ?? 2B C2 4F 4F 66 8B + 4F ?? 47 47 66 85 C9 75 ?? 8B C8 C1 E9 ?? 8B F2 F3 A5 8B C8 83 E1 ?? F3 A4 8B 7D ?? + 4F 4F 66 8B 47 ?? 47 47 66 85 C0 75 ?? BE ?? ?? ?? ?? A5 8B 43 ?? 83 E0 ?? 3C ?? 0F + 85 ?? ?? ?? ?? FF 75 ?? 53 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 33 C0 5F 5E + 5B C9 C3 33 C0 40 EB + } + $hermes_encrypt_files_v2_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 33 C0 8D BD ?? ?? ?? ?? AB 33 DB 89 5D ?? AB AB + AB 8B 7D ?? 57 FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 57 FF 15 ?? ?? ?? ?? 53 56 6A ?? + 53 53 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B F0 85 F6 75 ?? 53 FF 15 ?? ?? ?? ?? 33 + C0 E9 ?? ?? ?? ?? 33 DB 33 C0 89 5D ?? 0F 57 C0 89 45 ?? 66 0F 13 45 ?? 83 FE ?? 74 + ?? 8D 45 ?? 50 56 FF 15 ?? ?? ?? ?? 8D 45 ?? 50 56 FF 15 ?? ?? ?? ?? 8B 5D ?? 8B 45 + ?? 83 FB ?? 75 ?? 85 C0 75 ?? 33 FF 47 E9 ?? ?? ?? ?? 83 65 ?? ?? 83 7D ?? ?? 77 ?? + 81 7D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? + 6A ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 8B 4D ?? + 89 45 ?? 83 F9 ?? 72 ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 76 ?? 6A ?? 6A ?? 51 FF 75 ?? E8 + ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 45 ?? 3D ?? ?? ?? ?? 76 ?? + C7 45 ?? ?? ?? ?? ?? EB ?? 8B 55 ?? 8B C1 81 C2 ?? ?? ?? ?? 83 D0 ?? 83 F8 ?? 77 ?? + 72 ?? 81 FA ?? ?? ?? ?? 77 ?? 6A ?? 6A ?? 51 FF 75 ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 52 + 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 45 ?? EB ?? 83 F9 + } + $hermes_encrypt_files_v2_p2 = { + 77 ?? 72 ?? 81 7D ?? ?? ?? ?? ?? 73 ?? 8B 45 ?? EB ?? 8B 45 ?? 3D ?? ?? ?? ?? 0F 87 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 0F 82 ?? ?? ?? ?? 83 7D ?? ?? + 0F 82 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 83 7D ?? ?? B8 ?? ?? ?? ?? 77 ?? 39 + 45 ?? 0F 86 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? 2B D8 53 56 89 5D ?? FF 15 ?? ?? ?? ?? + 83 F8 ?? 75 ?? 6A ?? 58 E9 ?? ?? ?? ?? 33 DB 8D 45 ?? 53 50 6A ?? 8D 85 ?? ?? ?? ?? + 89 5D ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? EB ?? 8B C3 80 BC 05 ?? ?? ?? ?? + ?? 75 ?? 80 BC 05 ?? ?? ?? ?? ?? 75 ?? 80 BC 05 ?? ?? ?? ?? ?? 75 ?? 80 BC 05 ?? ?? + ?? ?? ?? 75 ?? 80 BC 05 ?? ?? ?? ?? ?? 75 ?? 80 BC 05 ?? ?? ?? ?? ?? 74 ?? 40 83 F8 + ?? 72 ?? 53 53 53 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 6A ?? E9 ?? ?? ?? + ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 58 6A ?? 66 89 45 ?? 58 66 89 45 ?? 6A ?? 58 66 89 45 + ?? 33 C0 66 89 45 ?? 8D 45 ?? 50 57 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 6A ?? 68 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 57 56 89 1E E8 ?? ?? ?? + ?? 57 56 E8 ?? ?? ?? ?? 8D 45 ?? 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 56 57 FF 15 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 53 56 FF 15 ?? ?? ?? ?? 6A ?? E9 ?? ?? ?? ?? 33 DB 8D 45 + } + $hermes_encrypt_files_v2_p3 = { + 50 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? E9 ?? ?? ?? ?? + 39 5D ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? 53 53 68 ?? ?? ?? ?? FF 75 ?? FF 75 ?? E8 + ?? ?? ?? ?? 89 5D ?? 5B 6A ?? 89 4D ?? 33 DB 89 45 ?? 89 55 ?? 5F EB ?? 8B 45 ?? 89 + 45 ?? 53 69 C0 ?? ?? ?? ?? 53 50 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 6A ?? E9 ?? ?? + ?? ?? 53 8D 45 ?? 89 5D ?? 50 6A ?? 5F 57 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? + 85 C0 75 ?? 6A ?? E9 ?? ?? ?? ?? 53 53 53 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 6A ?? + E9 ?? ?? ?? ?? 89 5D ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B + D8 85 DB 75 ?? 6A ?? E9 ?? ?? ?? ?? 8B 55 ?? 33 C9 33 C0 C7 45 ?? ?? ?? ?? ?? 89 4D + ?? 89 45 ?? 83 65 ?? ?? C7 45 ?? ?? ?? ?? ?? 3B CA 75 ?? 8B 4D ?? 89 4D ?? C7 45 ?? + ?? ?? ?? ?? 33 C9 51 51 50 56 89 4D ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? + 6A ?? 8D 45 ?? 50 FF 75 ?? 53 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 33 C9 C7 + } + $hermes_encrypt_files_v2_p4 = { + 45 ?? ?? ?? ?? ?? 51 8D 45 ?? 50 51 51 FF 75 ?? 51 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 + 0F 84 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? 50 53 6A ?? FF 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? + ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F + 84 ?? ?? ?? ?? 83 65 ?? ?? 8D 45 ?? 6A ?? 50 FF 75 ?? 53 56 FF 15 ?? ?? ?? ?? 85 C0 + 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 45 ?? 41 8B 55 ?? 05 ?? ?? ?? ?? 89 4D ?? 89 45 ?? 3B + CA 0F 86 ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 8D 7D ?? 66 C7 45 ?? ?? ?? AB AB AB + AB 66 AB 33 C0 88 45 ?? 39 45 ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? 8D 45 ?? 50 8D 45 + ?? 50 E8 ?? ?? ?? ?? 59 59 EB ?? 6A ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 33 C0 8D 7D ?? + AB 6A ?? AB 66 AB 8D 45 ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 FF 8D 45 ?? 57 50 8D + 45 ?? 89 7D ?? 50 E8 ?? ?? ?? ?? 59 50 8D 45 ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? + 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? ?? 6A ?? E9 ?? ?? ?? ?? 8D 45 ?? 50 57 57 6A + } + $hermes_encrypt_files_v2_p5 = { + FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? + ?? 6A ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 57 6A ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 + C0 75 ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? ?? 6A ?? E9 ?? ?? ?? ?? 57 8D 45 ?? 89 + 7D ?? 50 FF 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? + ?? 57 53 FF 15 ?? ?? ?? ?? 6A ?? E9 ?? ?? ?? ?? 39 7D ?? 77 ?? 81 7D ?? ?? ?? ?? ?? + 76 ?? 6A ?? 57 0F 57 C0 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 83 F8 + ?? 75 ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? ?? 6A ?? EB ?? 57 8D 45 ?? 89 7D ?? 50 + 6A ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 57 53 FF + 15 ?? ?? ?? ?? 6A ?? EB ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 53 E8 ?? ?? ?? ?? + 83 C4 ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? ?? 6A ?? 5B EB ?? 68 ?? ?? ?? ?? 6A ?? + 53 FF 15 ?? ?? ?? ?? 6A ?? 5B 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B C3 + EB ?? FF 75 ?? FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? EB ?? FF 75 ?? FF 15 ?? + ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? EB ?? FF 75 ?? FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? + ?? ?? 6A ?? 5F EB ?? 6A ?? 5F 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 6A ?? 53 FF 15 ?? ?? ?? ?? EB ?? 6A ?? E9 ?? ?? ?? ?? 6A ?? 5F 56 FF 15 ?? + ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 + } + $hermes_find_files_v2_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 8B 5D ?? 8D 85 ?? ?? ?? ?? 56 57 50 68 ?? ?? ?? ?? 53 + E8 ?? ?? ?? ?? 59 59 50 FF 15 ?? ?? ?? ?? 8B F8 68 ?? ?? ?? ?? 53 89 7D ?? E8 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 53 8B F0 E8 ?? ?? ?? ?? 2B C6 33 C9 83 C4 ?? 66 89 0C 43 83 + FF ?? 0F 84 ?? ?? ?? ?? 33 F6 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 83 F8 ?? 75 ?? + 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 57 + FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 83 + F8 ?? 75 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8D + 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 58 6A ?? 5F 6A + ?? 5A 6A ?? 66 89 45 ?? 58 6A ?? 59 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? + 66 89 45 ?? 33 C0 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 + } + $hermes_find_files_v2_p2 = { + 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 33 C0 66 89 45 ?? 58 6A ?? 66 89 45 + ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 33 C0 66 89 55 ?? + 66 89 55 ?? 5A 6A ?? 66 89 45 ?? 58 6A ?? 66 89 85 ?? ?? ?? ?? 58 6A ?? 66 89 4D ?? + 66 89 4D ?? 66 89 8D ?? ?? ?? ?? 59 66 89 85 ?? ?? ?? ?? 6A ?? 58 66 89 85 ?? ?? ?? + ?? 33 C0 66 89 7D ?? 66 89 BD ?? ?? ?? ?? 8D 7D ?? 89 75 ?? 66 89 75 ?? 66 89 55 ?? + 89 75 ?? 66 89 75 ?? 66 89 8D ?? ?? ?? ?? 66 89 8D ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? + AB 6A ?? 66 89 4D ?? 66 89 55 ?? AB 66 89 55 ?? 89 75 ?? AB 66 AB 58 6A ?? 66 89 45 + ?? 58 6A ?? 5F 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? + 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 59 66 89 45 ?? 33 C0 66 89 45 ?? 6A ?? 58 + 66 89 85 ?? ?? ?? ?? 6A ?? 58 66 89 85 ?? ?? ?? ?? 6A ?? 58 66 89 85 ?? ?? ?? ?? 6A + ?? 58 66 89 85 ?? ?? ?? ?? 6A ?? 58 66 89 85 ?? ?? ?? ?? 33 C0 66 89 7D ?? 66 89 7D + ?? 8D BD ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 66 89 8D ?? ?? ?? ?? 66 89 8D + } + $hermes_find_files_v2_p3 = { + AB AB AB 66 AB 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D + 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? + 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 + C0 0F 84 ?? ?? ?? ?? 8B 7D ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 + ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 + 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 + } + $hermes_find_files_v2_p4 = { + 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 8D 45 ?? 50 8D 85 + ?? ?? ?? ?? 50 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 45 + ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 45 ?? 50 + 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 45 ?? 50 8D + 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? EB ?? 8B 7D ?? F6 85 ?? ?? ?? + ?? ?? 74 ?? 53 E8 ?? ?? ?? ?? 59 FF 75 ?? 8D 85 ?? ?? ?? ?? FF 75 ?? FF 75 ?? 50 53 + E8 ?? ?? ?? ?? 59 59 50 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8B F0 8D + 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 2B F0 83 C4 ?? 33 C0 66 89 44 73 ?? 33 F6 8D 85 ?? + ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 5F 5E + 5B 8B E5 5D C3 + } + $hermes_enum_resources_v2 = { + 55 8B EC 83 EC ?? 53 56 57 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF 75 ?? 33 DB C7 45 ?? + ?? ?? ?? ?? 53 53 6A ?? 89 5D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? + 6A ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D + 45 ?? 50 56 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 7E ?? 6A ?? 58 66 + 39 07 75 ?? 66 39 47 ?? 75 ?? 50 8D 47 ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 57 FF + 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? F7 46 ?? ?? ?? + ?? ?? 74 ?? FF 75 ?? 56 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 33 C0 5F 5E 5B 8B E5 5D C3 + 33 C0 40 EB } condition: - uint16(0)==0x5A4D and $find_files and $decrypt_payload_script and ( all of ($remote_connection_*)) + uint16(0)==0x5A4D and ((( all of ($hermes_find_files_v1_p*)) and ( all of ($hermes_encrypt_files_v1_p*))) or (( all of ($hermes_find_files_v2_p*)) and ( all of ($hermes_encrypt_files_v2_p*)))) and ( any of ($hermes_enum_resources_v*)) } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Chupacabra : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Balaclava : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects ChupaCabra ransomware." + description = "Yara rule that detects Balaclava ransomware." author = "ReversingLabs" - id = "e44a101d-53c3-51f2-84ca-f6a5858c169b" - date = "2021-10-12" - modified = "2021-10-12" + id = "1a17f2e8-f161-55bc-b44e-f8f47ebd9869" + date = "2020-10-01" + modified = "2020-10-01" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.ChupaCabra.yara#L1-L90" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "7f247778e0bd8057670abf42b2d1011ebae891ffcb21ebad50060f9a7986bf93" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Balaclava.yara#L1-L113" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "01b43e6ea7ceebdbdda7e1f7c5bd2439a460b8aed4a1837755fa3679e9893ff3" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -45031,81 +45483,104 @@ rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Chupacabra : TC_DETECTION MALICIOUS sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "ChupaCabra" + tc_detection_name = "Balaclava" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_p1 = { - 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 7E ?? ?? ?? ?? 28 - ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 14 0A 14 0B 7E ?? ?? ?? ?? 7E ?? ?? - ?? ?? 73 ?? ?? ?? ?? 0C 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 09 73 ?? ?? ?? ?? 13 ?? 73 ?? - ?? ?? ?? 0A 06 08 06 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 11 ?? 28 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 06 06 6F ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 - ?? 11 ?? 16 73 ?? ?? ?? ?? 13 ?? 11 ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 0B DE - ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 11 ?? 2C ?? - 11 ?? 6F ?? ?? ?? ?? DC 06 2C ?? 06 6F ?? ?? ?? ?? DC 07 2A - } - $encrypt_files_p2 = { - 02 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6A 30 ?? 02 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 0A 02 06 28 ?? ?? ?? ?? 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 38 ?? ?? - ?? ?? 02 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6A 30 ?? 20 ?? ?? ?? ?? 8D ?? ?? - ?? ?? 0B 02 19 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0C 08 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? - ?? ?? ?? 0D 09 07 09 8E 69 28 ?? ?? ?? ?? DE ?? 08 2C ?? 08 6F ?? ?? ?? ?? DC 02 19 28 - ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 07 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? - ?? ?? ?? DC 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 26 02 28 - ?? ?? ?? ?? 13 ?? 11 ?? 17 5F 17 33 ?? 11 ?? 17 28 ?? ?? ?? ?? 13 ?? 02 11 ?? 28 ?? ?? - ?? ?? 02 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6A 30 ?? 02 28 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 13 ?? 02 11 ?? 28 ?? ?? ?? ?? 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 38 ?? ?? ?? ?? 02 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6A 30 ?? 20 ?? ?? ?? - ?? 8D ?? ?? ?? ?? 13 ?? 02 19 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 02 19 28 - ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? DE ?? 11 ?? 2C ?? 11 ?? 6F - ?? ?? ?? ?? DC 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? DE ?? 26 DE ?? - 2A - } $find_files_p1 = { - 02 28 ?? ?? ?? ?? 0A 02 28 ?? ?? ?? ?? 0B 16 0C 2B ?? 06 08 9A 28 ?? ?? ?? ?? 72 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 08 9A 28 ?? ?? ?? ?? 08 17 58 0C 08 06 8E 69 32 ?? 16 0D - 2B ?? 07 09 9A 28 ?? ?? ?? ?? 09 17 58 0D 09 07 8E 69 32 ?? DE ?? 26 DE ?? 2A + 55 8B EC 83 EC ?? 53 56 8B 75 ?? 33 D2 57 6A ?? 5B 8B 7E ?? 89 55 ?? 8D 4F ?? 66 8B + 07 03 FB 66 3B C2 75 ?? 2B F9 B9 ?? ?? ?? ?? D1 FF E8 ?? ?? ?? ?? 50 FF 76 ?? 89 45 + ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 50 FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B + 45 ?? 83 C0 ?? 89 45 ?? 8B D8 33 D2 8D 4B ?? 66 8B 03 83 C3 ?? 66 3B C2 75 ?? 2B D9 + D1 FB 8D 04 3B 3D ?? ?? ?? ?? 7C ?? 8D 04 45 ?? ?? ?? ?? 50 39 56 ?? 74 ?? FF 76 ?? + 52 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? EB ?? 52 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? + ?? ?? 39 46 ?? 74 ?? 89 46 ?? 8B 46 ?? 33 C9 66 89 0C 78 8B 55 ?? F7 02 ?? ?? ?? ?? + 0F 85 ?? ?? ?? ?? 33 D2 8B C2 6A ?? 89 45 ?? 59 89 4D ?? 3B C1 7F ?? 03 C1 8B 4D ?? + 99 2B C2 D1 F8 89 45 ?? 8B 14 85 ?? ?? ?? ?? 66 8B 01 66 3B 02 75 ?? 66 85 C0 74 ?? + 66 8B 41 ?? 66 3B 42 ?? 75 ?? 83 C1 ?? 83 C2 ?? 66 85 C0 75 ?? 33 D2 8B C2 EB ?? 1B + C0 83 C8 ?? 33 D2 85 C0 0F 84 ?? ?? ?? ?? 79 ?? 8B 4D ?? 8B 45 ?? 49 EB ?? 8B 45 ?? + 8B 4D ?? 40 89 45 ?? EB ?? 8B 45 ?? F6 00 ?? 0F 84 ?? ?? ?? ?? 8D 04 5D ?? ?? ?? ?? + 50 8B 46 ?? FF 75 ?? 8D 04 78 83 C0 ?? 50 E8 ?? ?? ?? ?? 8B 4E ?? 83 C4 ?? 8B 46 ?? + 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 + ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7E ?? ?? 74 + ?? 83 7E ?? ?? 7E ?? FF 76 ?? 8B 4E ?? FF 76 ?? E8 ?? ?? ?? ?? 59 59 8B 4E ?? 8D 14 } $find_files_p2 = { - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? - ?? 1F ?? 8D ?? ?? ?? ?? 25 16 1E 28 ?? ?? ?? ?? A2 25 17 1F ?? 28 ?? ?? ?? ?? A2 25 18 - 1F ?? 28 ?? ?? ?? ?? A2 25 19 1F ?? 28 ?? ?? ?? ?? A2 25 1A 1F ?? 28 ?? ?? ?? ?? A2 25 - 1B 1B 28 ?? ?? ?? ?? A2 25 1C 1C 28 ?? ?? ?? ?? A2 25 1D 1F ?? 28 ?? ?? ?? ?? A2 25 1E - 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? - A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1B 28 ?? - ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? - 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F ?? 28 ?? ?? ?? ?? - A2 0A 16 0B 2B ?? 06 07 9A 28 ?? ?? ?? ?? 07 17 58 0B 07 06 8E 69 32 ?? 2A + 3B A1 ?? ?? ?? ?? 56 89 44 51 ?? 66 A1 ?? ?? ?? ?? 66 89 44 51 ?? FF 46 ?? E8 ?? ?? + ?? ?? FF 4E ?? E9 ?? ?? ?? ?? 39 56 ?? 0F 85 ?? ?? ?? ?? 8D 04 5D ?? ?? ?? ?? 50 8B + 46 ?? FF 75 ?? 8D 04 78 83 C0 ?? 50 E8 ?? ?? ?? ?? 8B 5E ?? 83 C4 ?? 8B CB B8 ?? ?? + ?? ?? 66 8B 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? + 83 C1 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B CB 8D + 51 ?? 66 8B 01 83 C1 ?? 66 3B 45 ?? 75 ?? 2B CA D1 F9 83 F9 ?? 72 ?? 8B CB 8D 51 ?? + 66 8B 01 83 C1 ?? 66 3B 45 ?? 75 ?? 2B CA D1 F9 83 C1 ?? 68 ?? ?? ?? ?? 8D 04 4B 50 + FF 15 ?? ?? ?? ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 00 A8 ?? 74 ?? 83 E0 ?? + 50 FF 76 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BB ?? ?? ?? ?? 53 FF + 15 ?? ?? ?? ?? EB ?? 85 C0 75 ?? 6A ?? 53 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 0D ?? + ?? ?? ?? 6A ?? 58 3B C8 A1 ?? ?? ?? ?? 74 ?? 83 F8 ?? 74 ?? FF 76 ?? A1 ?? ?? ?? ?? + 33 D2 6A ?? 03 C1 59 F7 F1 FF 34 95 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 05 ?? ?? ?? ?? + FF 05 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 46 ?? 6A + ?? 59 66 89 4C 78 ?? 33 C9 8B 46 ?? 66 89 0C 78 FF 75 ?? 8B 5D ?? 53 FF 15 ?? ?? ?? + ?? 85 C0 74 ?? 8B 45 ?? E9 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 5D ?? 33 FF 39 7E ?? + 75 ?? 89 3E 53 FF 15 ?? ?? ?? ?? 8B DF 8B 4D ?? E8 ?? ?? ?? ?? 5F 5E 8B C3 5B 8B E5 + 5D C2 } - $drop_ransom_note = { - 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 39 ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 1B 8D ?? ?? - ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 7E ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 7E - ?? ?? ?? ?? A2 25 1A 72 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 20 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 1B 8D ?? ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 7E ?? ?? ?? - ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 7E ?? ?? ?? ?? A2 25 1A 72 ?? ?? ?? ?? A2 28 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 26 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 26 73 ?? ?? ?? ?? 0A 7E ?? ?? ?? ?? 0B 06 07 6F ?? ?? ?? ?? 26 2A + $encrypt_files_p1 = { + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 55 ?? 8B C1 89 45 ?? C7 45 ?? ?? ?? + ?? ?? 33 F6 89 75 ?? 83 4D ?? ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 75 + ?? 56 68 ?? ?? ?? ?? 6A ?? 56 56 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? + 83 FB ?? 74 ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 0B 45 ?? 74 ?? + 8B FE EB ?? 33 FF 47 89 7D ?? 85 FF 0F 85 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 + 45 ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? FF 75 ?? FF D0 8B C8 A1 ?? ?? ?? ?? EB ?? 8B + CE 85 C9 0F 84 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? FF 75 ?? FF D0 EB ?? 8B C6 85 C0 0F 84 + ?? ?? ?? ?? 56 8D 45 ?? 50 68 ?? ?? ?? ?? 8B 7D ?? 57 53 FF 15 ?? ?? ?? ?? 85 C0 75 + ?? 83 CF ?? 89 7D ?? E9 ?? ?? ?? ?? 8B 45 ?? 3B C6 7C ?? 8B 4D ?? 7F ?? 81 F9 ?? ?? + ?? ?? 76 ?? 81 E9 ?? ?? ?? ?? 1B C6 50 51 33 D2 8B CB E8 ?? ?? ?? ?? 59 59 23 C2 89 + } + $encrypt_files_p2 = { + 75 ?? 85 F6 75 ?? 56 8D 45 ?? 50 68 ?? ?? ?? ?? 8B 45 ?? 03 C7 50 53 FF 15 ?? ?? ?? + ?? 8B FE 89 7D ?? EB ?? 56 56 6A ?? 5A 8B CB E8 ?? ?? ?? ?? 59 59 23 C2 8B FE 89 7D + ?? 85 FF 75 ?? 56 8D 45 ?? 50 6A ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? + ?? ?? 8B 4D ?? FF 71 ?? FF 71 ?? 8D 41 ?? 50 FF 71 ?? 6A ?? 5A 8B 4D ?? E8 ?? ?? ?? + ?? 83 C4 ?? 0F B6 C0 23 F8 89 7D ?? 0F 85 ?? ?? ?? ?? 56 8D 45 ?? 50 8B 45 ?? FF 70 + ?? FF 70 ?? 53 FF 15 ?? ?? ?? ?? 56 8D 45 ?? 50 8B 45 ?? FF 70 ?? FF 70 ?? 53 FF 15 + ?? ?? ?? ?? 51 8B 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8D 45 ?? 50 8B 55 ?? 52 + 8B 4D ?? 8B 45 ?? 03 C1 50 52 51 51 8B 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 75 ?? 56 8D 45 ?? 50 6A ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 53 FF 15 ?? ?? + ?? ?? 56 56 33 D2 8B CB E8 ?? ?? ?? ?? 59 59 56 8D 45 ?? 50 FF 75 ?? FF 75 ?? 53 FF + 15 ?? ?? ?? ?? 83 7D ?? ?? 76 ?? 8B 45 ?? 2D ?? ?? ?? ?? 8B 4D ?? 1B CE 51 50 33 D2 + 8B CB E8 ?? ?? ?? ?? 59 59 56 8D 45 ?? 50 FF 75 ?? 8B 45 ?? 03 45 ?? 50 53 FF 15 ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 4D ?? ?? E8 ?? ?? ?? ?? 8B C7 E8 ?? ?? ?? ?? C3 + } + $find_volumes = { + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 33 DB 53 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 56 53 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 89 7D ?? 83 FF ?? 0F 84 ?? ?? ?? + ?? 89 5D ?? 6A ?? 5B 8D B5 ?? ?? ?? ?? 8D 4E ?? 33 D2 66 8B 06 83 C6 ?? 66 3B C2 75 + ?? 2B F1 D1 FE 66 39 9D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 66 39 9D ?? ?? ?? ?? 75 ?? 66 + 83 BD ?? ?? ?? ?? ?? 75 ?? 66 39 9D ?? ?? ?? ?? 75 ?? 66 39 9C 75 ?? ?? ?? ?? 75 ?? + 33 C0 66 89 84 75 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 66 89 9C 75 ?? ?? ?? ?? 85 C0 74 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 4D ?? ?? E8 ?? ?? ?? ?? EB ?? 8B 7D ?? 57 FF 15 ?? + ?? ?? ?? 8B 65 ?? E8 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($drop_ransom_note) + uint16(0)==0x5A4D and ($find_volumes) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Lolkek : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Flamingo : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Lolkek ransomware." + description = "Yara rule that detects Flamingo ransomware." author = "ReversingLabs" - id = "441badd6-3708-5f74-90f3-4d3a0fc45aff" - date = "2020-10-23" - modified = "2020-10-23" + id = "333ef1f9-ac54-5a3d-9b2b-50483eeb93e1" + date = "2021-04-14" + modified = "2021-04-14" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Lolkek.yara#L1-L106" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "d18545b25a33bba1a6e01ab37768bd4f15fb125dcb8cbe7909d9a8bbe08e63fa" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Flamingo.yara#L1-L54" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "446c0d332af01c0fceb0356d5ab273eb55764869cc8343468b75625e5d4d1036" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -45113,97 +45588,168 @@ rule REVERSINGLABS_Win32_Ransomware_Lolkek : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Lolkek" + tc_detection_name = "Flamingo" tc_detection_factor = 5 importance = 25 strings: + $find_files = { + 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? + 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? + ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 + ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 + C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? + 80 F9 ?? 75 ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 + 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 + C0 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F + 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 + } $encrypt_files = { - 57 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? A1 ?? - ?? ?? ?? B9 ?? ?? ?? ?? FF 0D ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 3C 85 ?? ?? ?? ?? 40 99 - F7 F9 89 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 53 8B 1D ?? ?? ?? ?? 56 8B CF E8 ?? ?? ?? ?? 85 C0 74 - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 8B F0 68 ?? ?? ?? ?? 56 FF D3 83 - C4 ?? 56 57 FF 15 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? - 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? A1 ?? ?? - ?? ?? B9 ?? ?? ?? ?? FF 0D ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 3C 85 ?? ?? ?? ?? 40 99 F7 - F9 89 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 85 FF 0F 85 ?? ?? ?? ?? 5E 5B 33 C0 5F C2 + 68 ?? ?? ?? ?? 83 EC ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B CC C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C6 85 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? + ?? ?? 83 79 ?? ?? C7 41 ?? ?? ?? ?? ?? 72 ?? 8B 01 EB ?? 8B C1 6A ?? C6 00 ?? 8D 85 + ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 50 68 ?? ?? + ?? ?? 51 6A ?? 83 EC ?? C6 45 ?? ?? 8B CC C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? + C7 41 ?? ?? ?? ?? ?? 83 79 ?? ?? C7 41 ?? ?? ?? ?? ?? 72 ?? 8B 01 EB ?? 8B C1 6A ?? + C6 00 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 8B BD ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 47 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 83 EC ?? 8B CC C7 41 ?? ?? ?? ?? + ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 83 79 ?? ?? C7 41 ?? ?? ?? ?? ?? 72 ?? + 8B 01 EB ?? 8B C1 6A ?? C6 00 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 } - $find_volumes_p1 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 56 - 57 E8 ?? ?? ?? ?? 6A ?? 8D 84 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 6A ?? 50 C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 - 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? - ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 - 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? - ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 - ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? - ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 83 C4 ?? 89 74 24 ?? 33 + + condition: + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) +} +rule REVERSINGLABS_Win32_Ransomware_Blitzkrieg : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Blitzkrieg ransomware." + author = "ReversingLabs" + id = "078f7f9d-edd4-52b4-a30e-e968542da95c" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Blitzkrieg.yara#L1-L127" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "22dd16c886a1982186fe927e633be9951da7d7e664e877e11fa976696b2bc86f" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Blitzkrieg" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files = { + 55 8B EC 83 C4 ?? 53 56 57 33 D2 89 55 ?? 89 55 ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? + 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? + ?? 64 FF 30 64 89 20 8B 45 ?? 8B 40 ?? 8B 10 FF 52 ?? 8B F0 4E 83 FE ?? 0F 8C ?? ?? + ?? ?? 8B 45 ?? 8B 48 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 A0 ?? ?? ?? ?? 88 + 43 ?? C6 43 ?? ?? 8D 4D ?? 8B 45 ?? 8B 40 ?? 8B D6 8B 38 FF 57 ?? 8B 55 ?? 8B C3 E8 + ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? 8B C3 E8 ?? ?? ?? ?? 8B D3 + 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 40 50 8D 45 ?? B9 ?? ?? ?? ?? 8B 15 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 4B ?? 89 0C + 82 4E 83 FE ?? 0F 85 ?? ?? ?? ?? 6A ?? 6A ?? 8B 45 ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 84 C0 74 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 } - $find_volumes_p2 = { - FF 8B 5C BC ?? 53 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 89 9C B4 ?? ?? ?? ?? 46 47 83 FF - ?? 7C ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 0F 84 ?? ?? ?? ?? 68 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 44 24 ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 57 FF 15 ?? - ?? ?? ?? 8B D8 0F 1F 00 85 F6 74 ?? 8D 44 24 ?? 50 6A ?? 8D 84 24 ?? ?? ?? ?? 50 57 - FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 - ?? 4E 57 FF B4 B4 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? - ?? 85 C0 75 ?? 53 FF 15 ?? ?? ?? ?? FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? - ?? ?? 83 C4 ?? 8B 3D ?? ?? ?? ?? 33 F6 8B 1D ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? FF - D7 33 D2 B9 ?? ?? ?? ?? F7 F1 68 ?? ?? ?? ?? 80 C2 ?? 88 94 34 ?? ?? ?? ?? FF D3 46 - 83 FE ?? 7C ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 83 C4 ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 FF 15 + $search_files_p1 = { + E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C0 89 45 ?? B2 ?? A1 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? F6 40 ?? ?? 74 ?? FF 45 ?? 8B 45 ?? F6 40 + ?? ?? 74 ?? 83 45 ?? ?? 8B 45 ?? F6 40 ?? ?? 74 ?? 83 45 ?? ?? 8B 45 ?? F6 40 ?? ?? + 74 ?? 83 45 ?? ?? 8B 45 ?? F6 40 ?? ?? 74 ?? 83 45 ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 10 FF 52 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? + E8 ?? ?? ?? ?? 85 C0 7E ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 8B 52 ?? + 48 85 D2 74 ?? 3B 42 ?? 72 ?? E8 ?? ?? ?? ?? 40 80 7C 02 ?? ?? 74 ?? 8D 85 ?? ?? ?? + ?? 8B 55 ?? 8B 4D ?? 8B 49 ?? 4A 85 C9 74 ?? 3B 51 ?? 72 ?? E8 ?? ?? ?? ?? 42 8A 54 + 11 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? EB ?? 8B 55 ?? 8B 45 + ?? 8B 08 FF 51 ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 45 ?? FF 4D ?? 75 ?? 8B 45 ?? 8B 10 FF + 52 ?? 48 85 C0 0F 8C ?? ?? ?? ?? 40 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + 8B 55 ?? 8B 45 ?? 8B 18 FF 53 ?? 8B 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? + ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? 8B 8D ?? ?? ?? ?? 8B 55 + ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 + ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 85 C0 0F 8F ?? ?? ?? ?? 8B 55 ?? + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 8F ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? + ?? 84 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 8B 55 ?? B8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 85 C0 7F ?? 8B 45 ?? 8B 40 ?? 50 8B 4D ?? B2 ?? A1 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B D8 B2 ?? 8B C3 E8 ?? ?? ?? ?? 8B D3 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 } - $find_files_p1 = { - 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 - F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 5F C9 C3 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? - ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? - FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 5D ?? - 8B CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 EB ?? - 8B 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B EB ?? 33 FF 57 57 - 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 - 45 ?? 8B 4D ?? 8B 55 ?? 53 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C ?? 74 - ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 ?? ?? - ?? ?? 8A 01 88 85 ?? ?? ?? ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 57 E8 - ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? 74 ?? - 3C ?? 8A C3 75 ?? B0 ?? 2B CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D + $search_files_p2 = { + E8 ?? ?? ?? ?? 40 50 8D 45 ?? B9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 85 D2 74 ?? 3B 42 ?? 72 ?? E8 ?? ?? ?? ?? 8B 4B + ?? 89 0C 82 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 8B + 45 ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 85 C0 79 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 + 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? + EB ?? FF 45 ?? FF 4D ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 80 78 ?? ?? 0F 84 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? + 64 FF 30 64 89 20 F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 85 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 8D 85 ?? ?? ?? ?? + 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? + 8B 48 ?? 8B 45 ?? E8 } - $find_files_p2 = { - 56 1B C0 89 9D ?? ?? ?? ?? 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? - ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 8D ?? ?? ?? ?? F7 D8 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? - ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B - D8 E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D - ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? - 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? - 75 ?? 8A 48 ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? - ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? - ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 - C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 - ?? EB ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 59 8B D8 56 FF 15 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 59 8B C3 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? C9 C3 + $disable_services_p1 = { + E8 ?? ?? ?? ?? 8B F0 BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 + FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? + 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 + FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? + 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 + FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? + 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 + FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? + 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 + FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + } + $disable_services_p2 = { + 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 + FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? + 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 + FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? + 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 + FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? + 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 + FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? BA + ?? ?? ?? ?? 8B C6 8B 08 FF 51 ?? 8B 55 ?? 8B C6 8B 08 FF 51 ?? 6A ?? 8B 45 ?? E8 ?? + ?? ?? ?? 8B D0 8D 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 33 C9 33 D2 E8 ?? ?? ?? ?? 33 C0 5A + 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and ( all of ($find_volumes_p*)) and ( all of ($find_files_p*)) and ($encrypt_files) + uint16(0)==0x5A4D and (( all of ($disable_services_p*)) and ( all of ($search_files_p*)) and ($encrypt_files)) } -rule REVERSINGLABS_Win32_Ransomware_Alcatraz : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Linux_Ransomware_Killdisk : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Alcatraz ransomware." + description = "Yara rule that detects KillDisk ransomware." author = "ReversingLabs" - id = "7ff37483-ae63-5c82-a355-81ef68e2f663" - date = "2020-07-28" - modified = "2020-07-28" + id = "af6652dd-c668-5ae1-b51b-e272cb440c20" + date = "2020-07-15" + modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Alcatraz.yara#L1-L91" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ddd35c8da0c08bce17cacfba8bb8a8b8a8c08c3e59261a88a79c63b03d29000f" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Linux.Ransomware.KillDisk.yara#L1-L144" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3ed1fb2b7b24cd4d5100d93ed53a9ab28e1482bd0998a0538d8710a962ee839f" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -45211,93 +45757,138 @@ rule REVERSINGLABS_Win32_Ransomware_Alcatraz : TC_DETECTION MALICIOUS MALWARE FI sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Alcatraz" + tc_detection_name = "KillDisk" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A - ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? 8B 4D ?? 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 83 C8 ?? E9 - ?? ?? ?? ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? - ?? ?? ?? ?? 75 ?? 83 C8 ?? E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 - BD ?? ?? ?? ?? ?? 75 ?? 83 C8 ?? E9 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8B 8D ?? - ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 8D ?? ?? - ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 - ?? 83 C8 ?? E9 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? - ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 0F B6 D0 85 D2 75 ?? 83 7D ?? ?? 74 ?? 6A - ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? EB ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? - 75 ?? 83 C8 ?? EB ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? - ?? 51 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? - 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files_1 = { + 55 48 89 E5 48 81 EC ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 64 48 8B 04 25 ?? ?? ?? ?? 48 + 89 45 ?? 31 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8B 85 + ?? ?? ?? ?? 48 89 D6 48 89 C7 E8 ?? ?? ?? ?? 85 C0 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? + ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? + ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 C7 + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 05 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 85 C0 79 ?? 48 8B + 85 ?? ?? ?? ?? 48 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 85 ?? ?? + ?? ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 78 ?? 48 8B 85 ?? ?? ?? ?? BE ?? + ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 05 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? + 85 C0 79 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 45 ?? 48 8D 90 ?? ?? ?? ?? 48 85 C0 + 48 0F 48 C2 48 C1 F8 ?? 48 89 85 ?? ?? ?? ?? 48 8B 45 ?? 48 85 C0 7E ?? 48 83 BD ?? + ?? ?? ?? ?? 7F ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? + ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? 48 + 83 BD ?? ?? ?? ?? ?? 7F ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? + ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C2 48 C1 } - $remote_server = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 6A ?? 6A ?? 68 ?? ?? ?? - ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 6A ?? 6A - ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D - ?? ?? 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 - ?? 83 7D ?? ?? 74 ?? 6A ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 - ?? 83 C8 ?? E9 ?? ?? ?? ?? 8B 4D ?? 83 C1 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 - 7D ?? ?? 75 ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 55 ?? 83 C2 ?? 52 6A ?? 8B 45 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 FF 15 - ?? ?? ?? ?? 85 C0 75 ?? 83 C8 ?? E9 ?? ?? ?? ?? EB ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B - 55 ?? 83 C2 ?? 89 55 ?? 8B 45 ?? 3B 45 ?? 73 ?? 8B 4D ?? 03 4D ?? 0F BE 11 83 FA ?? - 74 ?? 8B 45 ?? 03 45 ?? 0F BE 08 83 F9 ?? 74 ?? 8B 55 ?? 03 55 ?? 8B 45 ?? 03 45 ?? - 8A 08 88 0A EB ?? 8B 55 ?? 03 55 ?? C6 02 ?? EB ?? EB ?? EB ?? 83 7D ?? ?? 0F 87 ?? - ?? ?? ?? 83 7D ?? ?? 75 ?? 83 C8 ?? EB ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 FF 15 ?? ?? - ?? ?? 83 7D ?? ?? 74 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 55 ?? 52 - FF 15 ?? ?? ?? ?? 8B E5 5D C3 + $encrypt_files_2 = { + EA ?? 48 01 D0 48 D1 F8 48 C1 E0 ?? 48 89 C1 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 + CE 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? + ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 8E ?? ?? ?? + ?? 48 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 BA ?? + ?? ?? ?? ?? ?? ?? ?? 48 89 C8 48 F7 EA 48 8D 04 0A 48 C1 F8 ?? 48 89 C2 48 89 C8 48 + C1 F8 ?? 48 29 C2 48 89 D0 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B + 85 ?? ?? ?? ?? C1 E0 ?? 48 63 C8 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 CE 89 C7 E8 + ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 + ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 3B 85 ?? ?? ?? ?? 7C ?? 48 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? + 48 8B 8D ?? ?? ?? ?? 48 BA ?? ?? ?? ?? ?? ?? ?? ?? 48 89 C8 48 F7 EA 48 8D 04 0A 48 + C1 F8 ?? 48 89 C2 48 89 C8 48 C1 F8 ?? 48 29 C2 48 89 D0 89 85 ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? C1 E0 ?? 48 63 C8 8B 85 ?? ?? ?? ?? BA + ?? ?? ?? ?? 48 89 CE 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? + ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? EB ?? 83 85 ?? ?? ?? ?? ?? 83 85 ?? + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B 85 ?? ?? ?? ?? 7C ?? 8B 05 ?? ?? ?? ?? 89 C7 E8 ?? + ?? ?? ?? 8B 05 ?? ?? ?? ?? 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 8B 75 ?? 64 48 33 + 34 25 ?? ?? ?? ?? 74 ?? E8 ?? ?? ?? ?? C9 C3 } - $remote_server_2 = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? 89 45 ?? A1 ?? ?? ?? ?? 50 8B 0D ?? ?? ?? ?? 51 8B 15 ?? ?? ?? ?? 52 - A1 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 8B 0D ?? ?? ?? ?? 51 68 - ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? - 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 89 45 ?? 83 7D ?? ?? 74 ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? - ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 68 - ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? - ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? - 6A ?? 6A ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 6A ?? 8B 55 ?? - 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D - 45 ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 C0 E9 ?? ?? ?? ?? 8B 55 ?? 83 - C2 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 75 ?? C7 45 ?? ?? ?? ?? ?? 33 - C0 E9 ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 50 6A ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 - C0 EB ?? EB ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 68 ?? ?? ?? ?? 8B 4D ?? - 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 74 ?? B8 ?? ?? ?? ?? EB ?? 83 7D ?? ?? 0F 87 ?? - ?? ?? ?? 83 7D ?? ?? 75 ?? 83 C8 ?? EB ?? 83 7D ?? ?? 74 ?? 8B 55 ?? 52 FF 15 ?? ?? - ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 4D ?? 51 - FF 15 ?? ?? ?? ?? 8B E5 5D C3 + $search_files = { + 55 48 89 E5 48 81 EC ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 64 48 8B 04 25 ?? ?? ?? ?? 48 + 89 45 ?? 31 C0 8B 05 ?? ?? ?? ?? 83 C0 ?? 89 05 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 83 F8 + ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? + 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? + ?? ?? ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 48 8B 85 ?? ?? ?? ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 75 ?? + E9 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 83 C0 + ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 75 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? + ?? 85 C0 74 ?? 48 8B 85 ?? ?? ?? ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? + ?? 85 C0 75 ?? 83 85 ?? ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 + D6 48 89 C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 C7 C1 ?? ?? ?? ?? 48 89 C2 B8 ?? + ?? ?? ?? 48 89 D7 F2 AE 48 89 C8 48 F7 D0 48 8D 50 ?? 48 8D 85 ?? ?? ?? ?? 48 01 D0 + 66 C7 00 ?? ?? 48 8B 85 ?? ?? ?? ?? 48 8D 50 ?? 48 8D 85 ?? ?? ?? ?? 48 89 D6 48 89 + C7 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 48 8D + 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 83 E8 ?? 89 05 ?? ?? ?? ?? + 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? + ?? ?? 0F 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? + 48 8B 4D ?? 64 48 33 0C 25 ?? ?? ?? ?? 74 ?? E8 ?? ?? ?? ?? C9 C3 + } + $subvert_grub_1 = { + 55 48 89 E5 48 81 EC ?? ?? ?? ?? 64 48 8B 04 25 ?? ?? ?? ?? 48 89 45 ?? 31 C0 48 B8 + ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 + ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? + ?? ?? ?? 48 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? + ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 + ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 + ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? 66 C7 85 ?? ?? FF FF ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? + ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? + 48 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 48 B8 ?? ?? + ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? + ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? + ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 + } + $subvert_grub_2 = { + 48 89 85 ?? ?? ?? ?? 66 C7 85 ?? ?? FF FF ?? ?? 48 B8 ?? ?? ?? + ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? + 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? + ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? + ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? + ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 + 8B 85 ?? ?? ?? ?? 48 89 C1 BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? + ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 4C 8D 85 ?? ?? + ?? ?? 48 8D BD ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8B 85 ?? ?? + ?? ?? 48 8D B5 ?? ?? ?? ?? 56 48 8D B5 ?? ?? ?? ?? 56 4D 89 C1 49 89 F8 BE ?? ?? ?? + ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 83 C4 ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 + E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? + ?? ?? 0F 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 B9 ?? + ?? ?? ?? ?? ?? ?? ?? 48 89 08 C7 40 ?? ?? ?? ?? ?? C6 40 ?? ?? 48 8B 85 + } + $subvert_grub_3 = { + 48 8D 50 ?? 48 8D 85 ?? ?? ?? ?? 48 89 D6 48 89 C7 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? + ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 85 ?? ?? ?? + ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 85 ?? ?? ?? + ?? 48 83 C0 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 75 ?? EB ?? 48 8D 85 ?? + ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 + 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? + ?? E9 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? + 48 83 BD ?? ?? ?? ?? ?? 74 ?? 4C 8D 85 ?? ?? ?? ?? 48 8D BD ?? ?? ?? ?? 48 8D 8D ?? + ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 8D B5 ?? ?? ?? ?? 56 48 8D B5 + ?? ?? ?? ?? 56 4D 89 C1 49 89 F8 BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 48 83 C4 ?? EB ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? + ?? 48 83 BD ?? ?? ?? ?? ?? 74 ?? 4C 8D 85 ?? ?? ?? ?? 48 8D BD ?? ?? ?? ?? 48 8D 8D + ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 8D B5 ?? ?? ?? ?? 56 48 8D + B5 ?? ?? ?? ?? 56 4D 89 C1 49 89 F8 BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 48 83 C4 ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 8B + 55 ?? 64 48 33 14 25 ?? ?? ?? ?? 74 ?? E8 ?? ?? ?? ?? C9 C3 } condition: - uint16(0)==0x5A4D and $encrypt_files and $remote_server and $remote_server_2 + uint32(0)==0x464C457F and ($search_files and ( all of ($encrypt_files_*)) and ( all of ($subvert_grub_*))) } -rule REVERSINGLABS_Win32_Ransomware_Gpcode : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Makop : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Gpcode ransomware." + description = "Yara rule that detects Makop ransomware." author = "ReversingLabs" - id = "168833dd-44ab-59e1-a610-b9219b2907ff" - date = "2020-07-15" - modified = "2020-07-15" + id = "9b7d42f3-0417-5228-8b25-244224cbc414" + date = "2020-10-30" + modified = "2020-10-30" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Gpcode.yara#L1-L67" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "329309873977f73a8ebe758018ebc8ba42e15c3c7cbb9a65865631d235f5bb48" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Makop.yara#L1-L99" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0ff4739d32b4a775d07a5f22d551ed67025681d4986e4404c9a01ad4078468f3" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -45305,914 +45896,718 @@ rule REVERSINGLABS_Win32_Ransomware_Gpcode : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "GPCode" + tc_detection_name = "Makop" tc_detection_factor = 5 importance = 25 strings: - $drive_loop = { - B9 19 00 00 00 BB 01 00 00 00 D3 E3 23 D8 74 ?? 80 - C1 ?? 88 0D ?? ?? ?? ?? 80 E9 ?? C7 05 ?? ?? ?? ?? - ?? ?? ?? ?? 50 51 E8 ?? ?? ?? ?? 59 58 49 7D + $find_files_p1 = { + 8D 54 24 ?? 52 56 FF 15 ?? ?? ?? ?? 56 8B F8 6A ?? 89 7C 24 ?? FF 15 ?? ?? ?? ?? 50 + FF 15 ?? ?? ?? ?? 83 FF ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 5F 5E 5B 8B E5 5D C3 33 F6 89 74 24 ?? EB ?? 8D A4 24 ?? ?? ?? ?? 8D 64 24 ?? + 66 8B 44 24 ?? 66 85 C0 0F 84 ?? ?? ?? ?? 66 3D ?? ?? 75 ?? 66 8B 44 24 ?? 66 85 C0 + 0F 84 ?? ?? ?? ?? 66 3D ?? ?? 75 ?? 66 83 7C 24 ?? ?? 0F 84 ?? ?? ?? ?? 8D 44 24 ?? + EB ?? 8D 9B ?? ?? ?? ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 8D 54 24 ?? 2B C2 D1 F8 83 + E8 ?? 85 F6 8B F8 89 7C 24 ?? 75 ?? 8B 45 ?? 05 ?? ?? ?? ?? 03 C0 0F 84 ?? ?? ?? ?? + 50 56 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 89 44 24 ?? 8B F0 0F 84 ?? ?? ?? + ?? F6 44 24 ?? ?? 0F 84 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 38 85 FF 74 ?? 8B 1F 8D 54 24 + ?? 8B CA 2B D9 8D 49 ?? 0F B7 04 13 66 3D ?? ?? 72 ?? 66 3D ?? ?? 77 ?? 83 C0 ?? 0F + B7 C8 0F B7 02 66 3D ?? ?? 72 ?? 66 3D ?? ?? 77 ?? 83 C0 ?? 83 C2 ?? 66 85 C9 0F B7 + C0 74 ?? 66 3B C8 74 ?? 0F B7 D0 0F B7 C1 2B C2 0F 84 ?? ?? ?? ?? 8B 7F ?? 85 FF 75 + ?? 8B 7D ?? 8B 55 ?? 81 C7 ?? ?? ?? ?? 8B DE E8 ?? ?? ?? ?? 8B 4D ?? 8D 5C 4E ?? BA + ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 1C 56 8D 54 24 ?? BF ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4D ?? 8D 54 08 ?? 8B 45 ?? 52 56 50 E8 } - $encrypt_routine = { - FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? [0-10] - E9 ?? ?? ?? ?? 6A ?? [1-10] FF 75 ?? FF 35 ?? ?? - ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? - ?? ?? ?? 68 ?? ?? ?? ?? [1-10] FF 35 ?? ?? ?? ?? - 6A ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? (E8 | FF 15) - ?? ?? ?? ?? 0B C0 75 ?? (EB | E9) [1-4] 6A ?? - [2-10] FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? - 75 ?? [10-40] FF 35 ?? ?? ?? ?? FF 75 ?? E8 + $find_files_p2 = { + 83 C4 ?? E9 ?? ?? ?? ?? 8D 5C 24 ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? + 80 79 ?? ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 03 FA 81 FF ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 8B + 15 ?? ?? ?? ?? C6 44 24 ?? ?? 8B 7D ?? 81 C7 ?? ?? ?? ?? 8B DE E8 ?? ?? ?? ?? 8A 44 + 24 ?? 84 C0 75 ?? 8B 55 ?? 83 C7 ?? 8D 5E ?? E8 ?? ?? ?? ?? 8A 44 24 ?? 8A C8 8B 54 + 24 ?? F6 D9 1B C9 83 E1 ?? F6 D8 8B F1 8D BE ?? ?? ?? ?? 1B C0 83 E0 ?? 83 C0 ?? 03 + 45 ?? 8D 04 42 89 44 24 ?? 8D 58 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 8D BE + ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 8B 54 24 ?? 85 D2 8B 74 24 ?? 8B 45 ?? 77 ?? + 3B 70 ?? 77 ?? B1 ?? EB ?? 8B 55 ?? C6 44 24 ?? ?? E9 ?? ?? ?? ?? 32 C9 88 48 ?? 8B + 4C 24 ?? F6 C1 ?? 74 ?? C6 40 ?? ?? 89 48 ?? EB ?? C6 40 ?? ?? 50 89 50 ?? 89 70 ?? + 8B 44 24 ?? 50 E8 ?? ?? ?? ?? 8B 74 24 ?? 83 C4 ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? + 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 54 24 ?? 8D 4C 24 ?? 51 52 FF 15 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? EB ?? C7 44 24 ?? ?? ?? ?? ?? 8B 74 24 ?? EB ?? 56 6A ?? FF 15 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 50 FF 15 ?? ?? ?? ?? 56 6A ?? FF 15 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 } - $set_ransom_wallpaper = { - 0F B6 05 ?? ?? ?? ?? 83 F8 01 0F 85 ?? ?? ?? ?? - B9 ?? ?? ?? ?? BF ?? ?? ?? ?? 51 57 [2-20] 5F - 59 25 ?? ?? ?? ?? C1 E8 ?? 83 C0 ?? AA E2 ?? 33 - C0 AA 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 68 ?? ?? ?? ?? (E8 | FF 15) + $encrypt_files = { + 8B 50 ?? 8B 00 83 EC ?? 55 8B 2D ?? ?? ?? ?? 56 57 6A ?? 8B F9 8D 4C 24 ?? 51 52 50 + 53 FF D5 85 C0 0F 84 ?? ?? ?? ?? 8B 57 ?? 8B 47 ?? 33 F6 56 8D 4C 24 ?? 51 52 50 53 + FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 75 ?? B0 ?? 5F 5E 5D 83 + C4 ?? C3 3B 47 ?? 73 ?? 8B C8 83 E1 ?? 74 ?? BE ?? ?? ?? ?? 2B F1 8B 4F ?? 56 03 C8 + 6A ?? 51 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 8B 4F ?? 03 C6 50 8D 54 24 ?? 52 51 6A + ?? 6A ?? 89 44 24 ?? 8B 44 24 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 8B 4C 24 ?? 8B 54 24 ?? 6A ?? 6A ?? 51 52 53 FF D5 85 C0 74 ?? 8B 4C 24 ?? 8B 57 ?? + 8B 3D ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 03 CE 51 52 53 FF D7 85 C0 74 ?? 8B 44 24 ?? + 8D 0C 30 8B 44 24 ?? 3B C1 72 ?? 01 44 24 ?? 8B 44 24 ?? 8B 50 ?? 8B 00 83 54 24 ?? + ?? 6A ?? 6A ?? 52 50 53 FF D5 85 C0 74 ?? 6A ?? 8D 4C 24 ?? 51 6A ?? 8D 54 24 ?? 52 + 53 FF D7 85 C0 74 ?? 83 7C 24 ?? ?? 0F 83 ?? ?? ?? ?? 5F 5E 32 C0 5D 83 C4 ?? C3 } - $read_config_file = { - 55 8B EC 83 C4 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A - ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? - ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 89 45 ?? 50 6A ?? - E8 ?? ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 89 45 ?? FF - 75 ?? 6A ?? E8 ?? ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 - 89 45 ?? 50 E8 ?? ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 - 89 45 ?? FF 75 ?? 6A ?? E8 ?? ?? ?? ?? 0B C0 75 04 - 33 C0 C9 C3 89 45 ?? 8B D8 FF 75 ?? FF 75 ?? FF 75 - ?? E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 5D ?? - 6A ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C3 ?? 8B - 45 ?? 83 E8 ?? 50 53 E8 ?? ?? ?? ?? 8A 03 A2 ?? ?? - ?? ?? 83 C3 ?? 8A 03 A2 ?? ?? ?? ?? 83 C3 + $enum_network_resources = { + 55 8B EC 83 E4 ?? 83 EC ?? 53 56 57 68 ?? ?? ?? ?? 6A ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 8B F0 85 F6 89 74 24 ?? 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 7D ?? 8D 44 24 ?? 50 51 6A ?? + 6A ?? 57 E8 ?? ?? ?? ?? 85 C0 74 ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B + 7D ?? 68 ?? ?? ?? ?? 6A ?? 56 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 8D 54 24 ?? 52 56 8D 44 24 ?? 50 51 E8 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 85 C0 75 ?? 8B 54 24 ?? 8B 45 ?? 52 50 EB ?? 8B 4C 24 + ?? 8B 50 ?? 51 52 E8 ?? ?? ?? ?? 33 DB 83 C4 ?? 39 5C 24 ?? 76 ?? 83 C6 ?? 8D 49 ?? + 8B 46 ?? 85 C0 8B C8 75 ?? B9 ?? ?? ?? ?? 8B 46 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 51 8B + 0E 51 50 E8 ?? ?? ?? ?? 8B 46 ?? 83 C4 ?? A8 ?? 74 ?? 8B 56 ?? 85 D2 74 ?? 85 FF 7E + ?? 8B 45 ?? 85 C0 74 ?? 8B 40 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 55 ?? 8B 4D ?? 52 83 + EF ?? 57 8D 46 ?? 50 51 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? F6 06 ?? 74 ?? 50 E8 ?? ?? ?? + ?? 8B 56 ?? 8B 45 ?? 83 C4 ?? 52 50 E8 ?? ?? ?? ?? 83 C3 ?? 83 C6 ?? 3B 5C 24 ?? 0F + 82 ?? ?? ?? ?? 8B 74 24 ?? E9 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 8B 44 24 ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 } condition: - uint16(0)==0x5A4D and ($drive_loop and $encrypt_routine and $set_ransom_wallpaper and $read_config_file) + uint16(0)==0x5A4D and ($enum_network_resources) and ( all of ($find_files_p*)) and ($encrypt_files) } -rule REVERSINGLABS_Win32_Ransomware_Gandcrab : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_FCT : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects GandCrab ransomware." + description = "Yara rule that detects FCT ransomware." author = "ReversingLabs" - id = "a09ed7e6-f3a6-5f44-9d5b-a9c529cf1190" + id = "ea3d5514-d6f2-5fd0-9247-a3f6b920d8d9" date = "2020-07-15" modified = "2020-07-15" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.GandCrab.yara#L1-L892" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "79381635681482fc90defe4e10e97bf16d534837518fc06ae579822e9d77b461" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.FCT.yara#L1-L86" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "b158ad56c92a926f7398a27b3576c259e39c9716ef192fa5944ce3cffdc6d7d0" score = 75 - quality = 88 + quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" status = "RELEASED" sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "GandCrab" + tc_detection_name = "FCT" tc_detection_factor = 5 importance = 25 strings: - $remote_connection = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B F9 89 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 8B D8 89 5D ?? 85 DB 74 ?? 33 C0 - 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? - 57 FF 15 ?? ?? ?? ?? 8D 4D ?? 8D 34 45 ?? ?? ?? ?? 8D 46 ?? 50 E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 56 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? - 8B D8 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 89 45 ?? FF D6 57 53 FF D6 - 6A ?? 59 BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 A5 8B 35 ?? ?? ?? ?? 53 FF D6 33 FF 8D - 85 ?? ?? ?? ?? 21 BD ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 83 EC ?? - FF 75 ?? 53 FF D6 8B 75 ?? 8D 4D ?? 50 53 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 85 - C0 74 ?? 47 83 7D ?? ?? 74 ?? 8B 4D ?? 8D 55 ?? 83 65 ?? ?? E8 ?? ?? ?? ?? 85 C0 74 - ?? 8B 45 ?? 85 C0 74 ?? 8B 4D ?? 89 01 EB ?? 33 FF 68 ?? ?? ?? ?? 6A ?? 56 FF 15 ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? - FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 + $find_files_p1 = { + 6A ?? 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? 6A ?? E8 ?? ?? + ?? ?? 83 7D ?? ?? 8D 8D ?? ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF 15 ?? ?? ?? ?? 89 + 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 6A ?? 51 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 33 DB 8B 55 ?? 33 C9 8B 75 + ?? 89 9D ?? ?? ?? ?? 85 D2 74 ?? 66 90 83 7D ?? ?? 8D 45 ?? 0F 43 C6 0F BE 04 08 41 + 03 D8 3B CA 72 ?? 89 9D ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? + ?? ?? ?? 66 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B CF C7 45 ?? ?? ?? ?? ?? 33 C0 + C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? 8D 51 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 + F9 51 57 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 75 ?? 8B C6 8B 55 ?? 2B C2 83 F8 ?? + 72 ?? 83 FE ?? 8D 45 ?? 8D 4A ?? BB ?? ?? ?? ?? 0F 43 45 ?? 89 4D ?? 66 89 1C 50 33 + D2 66 89 14 48 EB ?? 6A ?? 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? + ?? ?? 6A ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 51 } - $remote_connection_v2 = { - 55 8B EC 83 EC ?? 53 56 8B D9 89 55 ?? 57 8D 4D ?? 89 5D ?? E8 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 53 89 45 ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 3C 45 - ?? ?? ?? ?? 8D 47 ?? 50 6A ?? FF D6 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B D8 - FF D6 89 45 ?? 85 DB 74 ?? 8D 47 ?? 3B F8 73 ?? 8B F3 EB ?? 33 F6 FF 75 ?? 56 FF 15 - ?? ?? ?? ?? F3 0F 6F 05 ?? ?? ?? ?? 56 F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F - 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 - ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? FF - 15 ?? ?? ?? ?? 8D 45 ?? 33 FF 50 FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 68 ?? ?? ?? ?? 83 - EC ?? 68 ?? ?? ?? ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 50 56 8B 75 ?? 8D 4D ?? 68 ?? ?? - ?? ?? 56 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? BF ?? ?? ?? ?? 74 ?? 8B 4D ?? 8D 55 - ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 85 C0 74 ?? 8B 4D ?? 89 - 01 EB ?? 33 FF 68 ?? ?? ?? ?? 6A ?? 56 8B 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? 6A ?? - FF 75 ?? FF D6 68 ?? ?? ?? ?? 6A ?? 53 FF D6 8B 45 ?? 85 C0 74 ?? 50 FF 15 ?? ?? ?? - ?? 8B C7 5F 5E 5B 8B E5 5D C3 + $find_files_p2 = { + 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 + ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? + 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 9D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B BD ?? ?? ?? ?? E9 ?? ?? ?? ?? 53 FF 15 ?? ?? + ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 55 ?? 8D 48 ?? 8B C2 81 F9 ?? ?? ?? ?? 72 ?? 8B 52 + ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 77 ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 + FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 + C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D + ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 E8 } - $crypt_files = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 51 33 C0 89 4C 24 ?? 40 8B DA 50 51 50 - 83 EC ?? 89 5C 24 ?? 50 51 50 51 50 51 50 51 50 83 EC ?? 50 51 50 8D 8C 24 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B 75 ?? 8B - F8 03 F3 8D 4E ?? 8D 0C CF C1 E1 ?? 51 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 04 B7 8D 04 C5 - ?? ?? ?? ?? 50 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B 75 ?? 89 44 24 ?? 8D 0C F5 ?? ?? ?? ?? - 51 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 0C DD ?? ?? ?? ?? 8B F8 51 8D 4C 24 ?? E8 ?? ?? ?? - ?? 8B D8 89 5C 24 ?? 85 FF 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 57 68 ?? ?? ?? ?? 56 FF - 75 ?? 8D 0C 36 8B 35 ?? ?? ?? ?? 89 4C 24 ?? FF D6 8B 4C 24 ?? 8D 04 09 89 44 24 ?? - 8D 44 24 ?? 50 53 68 ?? ?? ?? ?? 51 FF 74 24 ?? FF D6 53 8B 1D ?? ?? ?? ?? FF D3 57 - 8B F0 FF D3 83 C0 ?? 8D 4C 24 ?? 03 C6 50 E8 ?? ?? ?? ?? 57 FF D3 40 8D 4C 24 ?? 50 - E8 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? FF D3 40 8D 4C 24 ?? 50 E8 ?? ?? ?? ?? 33 F6 - 89 44 24 ?? 8B CE 57 89 4C 24 ?? FF D3 85 C0 74 ?? 8B 54 24 ?? 89 54 24 ?? 8B 44 24 - ?? 8A 0C 38 80 F9 ?? 74 ?? 80 F9 ?? 74 ?? 88 0A 42 89 54 24 ?? 40 57 89 44 24 ?? FF - D3 8B 4C 24 ?? 8B 54 24 ?? 3B C8 72 ?? 8B 7C 24 ?? 57 FF D3 85 C0 74 ?? 8B 4C 24 ?? - 89 4C 24 ?? 8A 04 3E 3C ?? 74 ?? 3C ?? 74 ?? 88 01 41 89 4C 24 ?? 57 46 FF D3 8B 4C - 24 ?? 3B F0 72 ?? 8B 7C 24 ?? 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D3 8B 35 ?? ?? - ?? ?? 57 FF D6 8D 4C 24 ?? 8D 3C 47 57 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D3 57 FF - D6 FF 74 24 ?? 8D 34 47 FF 15 ?? ?? ?? ?? 50 56 6A ?? FF 74 24 ?? 6A ?? 68 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D3 57 FF 15 ?? ?? ?? ?? FF 74 24 ?? 8D 34 - 47 FF 15 ?? ?? ?? ?? 50 56 6A ?? FF 74 24 ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 57 FF D3 8B 74 24 ?? 8B 1D ?? ?? ?? ?? 56 FF D3 C1 E0 ?? 8D 4C 24 ?? - 83 C0 ?? 50 E8 ?? ?? ?? ?? 56 FF D3 8D 4C 24 ?? 8D 04 C5 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 56 89 44 24 ?? FF D3 8B 5C 24 ?? 8B F0 8B CB 8D 3C 36 8B D7 E8 ?? ?? ?? ?? 8D 44 - 24 ?? 8B CE 8B 74 24 ?? 50 56 68 ?? ?? ?? ?? 57 C1 E1 ?? 53 89 4C 24 ?? FF 15 ?? ?? - ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 56 FF D3 83 C0 ?? 8D 4C 24 ?? - 50 E8 ?? ?? ?? ?? 56 FF D3 40 8D 4C 24 ?? 50 E8 ?? ?? ?? ?? 89 44 24 ?? 33 F6 8B 44 - 24 ?? 8B FE 50 FF D3 85 C0 74 ?? 8B 54 24 ?? 89 54 24 ?? 8B 44 24 ?? 8A 0C 07 80 F9 - ?? 74 ?? 80 F9 ?? 74 ?? 88 0A 42 89 54 24 ?? 50 47 FF D3 8B 54 24 ?? 3B F8 72 ?? 8B - 7C 24 ?? 57 FF D3 50 FF 74 24 ?? 6A ?? 57 56 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? - 8D 54 24 ?? 89 74 24 ?? 8B CF E8 ?? ?? ?? ?? 59 85 C0 75 ?? 8D 4C 24 ?? E8 ?? ?? ?? - ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? EB ?? 8B 4C 24 ?? 85 C9 74 - ?? 8B 45 ?? 89 08 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? - E8 ?? ?? ?? ?? 33 F6 46 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 5F 8B - C6 5E 5B 8B E5 5D C3 + $encrypt_files_p1 = { + 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 51 57 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? + ?? 8B 75 ?? 8B C6 8B 55 ?? 2B C2 83 F8 ?? 72 ?? 83 FE ?? 8D 45 ?? 8D 4A ?? BB ?? ?? + ?? ?? 0F 43 45 ?? 89 4D ?? 66 89 1C 50 33 D2 66 89 14 48 EB ?? 6A ?? 68 ?? ?? ?? ?? + C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? 8D 51 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 8B 5D ?? 2B CA 8B 55 ?? 8B C3 D1 F9 2B + C2 3B C8 77 ?? 83 FB ?? 8D 04 09 50 8D 75 ?? 0F 43 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 3C + 0A 89 7D ?? 8D 04 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 04 7E EB ?? 51 8D 85 ?? + ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 81 BD + ?? ?? ?? ?? ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 6A ?? 0F 43 45 ?? 68 + ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F + 84 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B F2 85 F6 74 } - $crypt_files_v2 = { - 8B 55 ?? 8B 1D ?? ?? ?? ?? 8D 04 12 89 44 24 ?? 8D 44 24 ?? 50 51 68 ?? ?? ?? ?? 52 - FF 75 ?? FF D3 8D 04 36 89 44 24 ?? 8D 44 24 ?? 50 57 68 ?? ?? ?? ?? 56 FF 74 24 ?? - FF D3 8B 1D ?? ?? ?? ?? 57 FF D3 FF 74 24 ?? 8B F0 FF D3 6A ?? 83 C0 ?? 68 ?? ?? ?? - ?? 03 F0 56 6A ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? 89 44 24 ?? C7 44 24 ?? - ?? ?? ?? ?? FF D3 8B 54 24 ?? 40 85 D2 74 ?? 3B C6 73 ?? 8D 0C 02 89 44 24 ?? 89 4C - 24 ?? 89 54 24 ?? EB ?? C7 44 24 ?? ?? ?? ?? ?? 57 FF D3 40 83 7C 24 ?? ?? 74 ?? 03 - 44 24 ?? 3B C6 72 ?? C7 44 24 ?? ?? ?? ?? ?? FF 74 24 ?? 33 F6 FF D3 85 C0 74 ?? 8B - 7C 24 ?? EB ?? 8D 9B ?? ?? ?? ?? 8B 4C 24 ?? 8A 04 0E 3C ?? 74 ?? 3C ?? 74 ?? 88 07 - 47 51 46 FF D3 3B F0 72 ?? 8B 7C 24 ?? 57 33 F6 FF D3 85 C0 74 ?? 8B 4C 24 ?? 89 4C - 24 ?? 90 8A 04 3E 3C ?? 74 ?? 3C ?? 74 ?? 88 01 41 89 4C 24 ?? 57 46 FF D3 8B 4C 24 - ?? 3B F0 72 ?? 8B 74 24 ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D7 56 FF 15 ?? ?? - ?? ?? 8D 4C 24 ?? 8D 34 46 56 89 74 24 ?? E8 ?? ?? ?? ?? 8D 54 24 ?? C7 44 24 ?? ?? - ?? ?? ?? 8D 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 50 FF 15 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D7 8B 7C 24 ?? 57 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 56 FF 15 ?? ?? ?? ?? 8B 74 24 ?? 56 FF 74 24 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A - ?? 57 8B 3D ?? ?? ?? ?? FF D7 68 ?? ?? ?? ?? 6A ?? 56 FF D7 8B 74 24 ?? 68 ?? ?? ?? - ?? 56 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 56 FF D7 FF 74 24 ?? 8D 34 46 FF D3 50 56 - 6A ?? FF 74 24 ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 74 24 ?? 68 ?? ?? ?? ?? - 56 FF 15 ?? ?? ?? ?? 56 FF D7 8B 7C 24 ?? 57 8D 34 46 FF D3 50 56 6A ?? 57 6A ?? 68 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 - ?? 8B 35 ?? ?? ?? ?? FF D6 8B F8 6A ?? C1 E7 ?? 68 ?? ?? ?? ?? 83 C7 ?? 57 6A ?? FF - 15 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? FF D6 8D 0C C5 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 - 74 ?? 3B CF 73 ?? 8B F8 EB ?? 33 FF FF 74 24 ?? FF D6 8B 0D ?? ?? ?? ?? 89 44 24 ?? - 85 C9 74 ?? 68 ?? ?? ?? ?? 6A ?? 51 FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? - ?? ?? FF D6 83 C0 ?? 50 6A ?? FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8B 44 24 ?? 8B 4C 24 ?? 8D 34 00 - 8B D6 E8 ?? ?? ?? ?? 8B 4C 24 ?? 8D 04 CD ?? ?? ?? ?? 89 44 24 ?? 8D 44 24 ?? 50 57 - 68 ?? ?? ?? ?? 56 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 57 FF - D3 6A ?? 68 ?? ?? ?? ?? 8D 70 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 57 89 44 24 ?? FF D3 8D - 48 ?? 8B 44 24 ?? 85 C0 74 ?? 89 44 24 ?? 3B CE 72 ?? C7 44 24 ?? ?? ?? ?? ?? 57 33 - F6 FF D3 85 C0 74 ?? 8B 4C 24 ?? 89 4C 24 ?? 8A 04 3E 3C ?? 74 ?? 3C ?? 74 ?? 88 01 - 41 89 4C 24 ?? 57 46 FF D3 8B 4C 24 ?? 3B F0 72 ?? 8B 74 24 ?? 56 FF D3 50 FF 74 24 - ?? 6A ?? 56 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 51 8D 54 24 ?? C7 44 24 ?? - ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? - ?? 50 8B 44 24 ?? 50 FF D3 8B 44 24 ?? 68 ?? ?? ?? ?? 6A ?? 50 FF D3 68 ?? ?? ?? ?? - 6A ?? FF 74 24 ?? FF D3 68 ?? ?? ?? ?? 6A ?? FF 74 24 ?? FF D3 8D 4C 24 ?? E8 ?? ?? - ?? ?? 33 C0 5F 5E 5B 8B E5 5D C3 + $encrypt_files_p2 = { + 6A ?? 8D 45 ?? 50 A1 ?? ?? ?? ?? 2B C6 56 03 C1 50 57 FF 15 ?? ?? ?? ?? 2B 75 ?? 74 + ?? 8B 8D ?? ?? ?? ?? EB ?? 57 FF 15 ?? ?? ?? ?? C6 45 ?? ?? 33 C0 8B 9D ?? ?? ?? ?? + BA ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 83 CB ?? 8B 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + 89 95 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 8D 48 ?? 3B CA 76 ?? C6 85 ?? ?? ?? ?? ?? FF B5 + ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 95 ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 0F 43 4D ?? 3B C2 77 ?? 8D 34 00 89 85 ?? + ?? ?? ?? 83 FA ?? 8D BD ?? ?? ?? ?? 56 0F 43 BD ?? ?? ?? ?? 51 57 E8 ?? ?? ?? ?? 83 + C4 ?? 33 C0 66 89 04 37 EB ?? 50 51 C6 85 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? FF B5 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C2 8B 8D ?? ?? ?? ?? 2B C1 83 F8 ?? + 72 ?? 83 FA ?? 8D B5 ?? ?? ?? ?? 6A ?? 0F 43 B5 ?? ?? ?? ?? 8D 79 ?? 68 ?? ?? ?? ?? + 89 BD ?? ?? ?? ?? 8D 04 4E 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 04 7E EB ?? 6A ?? + 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 6A ?? E8 ?? + ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 45 ?? 0F 43 8D ?? ?? ?? ?? 83 7D + ?? ?? 51 0F 43 45 ?? 50 FF 15 } - $find_files = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 89 55 ?? 8B F9 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? - ?? ?? 8B CF E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 57 8D 1C 47 89 5D ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF - 15 ?? ?? ?? ?? 8B F0 33 C0 89 75 ?? 66 89 03 83 FE ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? - ?? ?? 8B 5D ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 85 ?? - ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 68 ?? ?? ?? ?? 57 FF 15 - ?? ?? ?? ?? 8B 55 ?? 8B CF 53 FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? FF 75 - ?? 8B 03 8D 95 ?? ?? ?? ?? 8B 73 ?? 51 8B CF 89 45 ?? E8 ?? ?? ?? ?? 01 03 59 11 53 - ?? 59 3B 73 ?? 77 ?? 72 ?? 8B 45 ?? 3B 03 73 ?? 8B 45 ?? FF 00 8B 75 ?? 8B 45 ?? 33 - C9 66 89 08 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 56 FF - 15 ?? ?? ?? ?? 33 C0 5F 5E 5B 8B E5 5D C3 + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Howareyou : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects HowAreYou ransomware." + author = "ReversingLabs" + id = "998fbebe-099d-5779-ad4a-91b7b6c8ad6b" + date = "2021-06-14" + modified = "2021-06-14" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.HowAreYou.yara#L1-L205" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "90568365aac61d120886f9efa9822ccc23df79a1a55e522c81db6e77477c4f04" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "HowAreYou" + tc_detection_factor = 5 + importance = 25 + + strings: + $remote_connection_p1 = { + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 3B 61 ?? 0F 86 ?? ?? ?? ?? 83 EC ?? 8B 05 ?? + ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 85 C9 0F 85 ?? ?? ?? ?? 8D 0D ?? ?? + ?? ?? 89 08 8B 05 ?? ?? ?? ?? 8D 0D ?? ?? ?? ?? 89 0C 24 89 44 24 ?? E8 ?? ?? ?? ?? + 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 8B 6C 24 ?? 85 C9 74 ?? 74 ?? 8B 49 + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? 8D 44 24 + ?? 89 04 24 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 E8 ?? + ?? ?? ?? 83 C4 ?? C3 89 54 24 ?? 89 5C 24 ?? 89 6C 24 ?? 8D 05 ?? ?? ?? ?? 89 04 24 + C7 44 24 ?? ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? + E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 85 D2 74 ?? 74 ?? 8B + 4A ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? 8D 05 + ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 89 D1 } - $find_files_v2 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 89 55 ?? 8B F9 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? - ?? ?? 8B CF E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? - ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 8D 1C 47 89 5D ?? FF D6 8D 85 ?? ?? ?? ?? 50 - 57 FF 15 ?? ?? ?? ?? 33 C9 89 45 ?? 66 89 0B 83 F8 ?? 75 ?? B8 ?? ?? ?? ?? 5F 5E 5B - 8B E5 5D C3 8B 5D ?? EB ?? 8D A4 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 57 FF D6 F6 85 ?? ?? ?? ?? ?? 74 ?? 68 - ?? ?? ?? ?? 57 FF D6 8B 55 ?? 8B CF 53 FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? EB - ?? FF 75 ?? 8B 03 8D 95 ?? ?? ?? ?? 8B 73 ?? 51 8B CF 89 45 ?? E8 ?? ?? ?? ?? 83 C4 - ?? 01 03 11 53 ?? 3B 73 ?? 77 ?? 72 ?? 8B 45 ?? 3B 03 73 ?? 8B 45 ?? FF 00 8B 35 ?? - ?? ?? ?? 8B 45 ?? 33 C9 66 89 08 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 33 C0 5B 8B E5 5D C3 + $remote_connection_p2 = { + EB ?? 89 4C 24 ?? 89 5C 24 ?? 84 03 89 4C 24 ?? C7 04 24 ?? ?? ?? ?? 8D 43 ?? 89 44 + 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 ?? 8B 48 ?? 8B 54 24 ?? 89 54 + 24 ?? 8B 54 24 ?? 89 54 24 ?? 8B 54 24 ?? 89 54 24 ?? 8B 54 24 ?? 89 14 24 FF D1 8B + 44 24 ?? 8B 4C 24 ?? 85 C0 74 ?? 74 ?? 8B 40 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? 89 44 24 ?? 89 4C 24 ?? 8D 05 ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? + ?? 8D 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? + ?? ?? 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 8D 05 ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C + 24 ?? 8B 5B ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 8B 44 24 ?? 89 04 24 FF D3 90 E8 + ?? ?? ?? ?? 83 C4 ?? C3 90 E8 ?? ?? ?? ?? 83 C4 ?? C3 89 04 24 8D 05 ?? ?? ?? ?? 89 + 44 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 } - $search_antivirus_processes = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 B8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A - ?? 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? 8B F8 53 6A ?? - 89 7D ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 89 1E 83 FF ?? 74 ?? 56 57 FF 15 ?? ?? - ?? ?? 33 DB 8D 7E ?? 57 FF B4 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 76 ?? - 50 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? - FF 15 ?? ?? ?? ?? 43 83 FB ?? 72 ?? 8B 7D ?? 56 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 85 - F6 74 ?? 68 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 - 5D C3 + $find_files_p1 = { + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 8D 44 24 ?? 3B 41 ?? 0F 86 ?? ?? ?? ?? 81 EC + ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 8B 8C 24 ?? ?? ?? ?? 89 4C 24 ?? E8 ?? ?? + ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 85 C9 0F 85 ?? ?? ?? ?? 89 54 + 24 ?? 89 9C 24 ?? ?? ?? ?? 31 C0 31 C9 31 ED 31 F6 EB ?? 8B 7C 24 ?? 47 8B 9C 24 ?? + ?? ?? ?? 89 CD 89 C6 89 F8 89 D1 8B 54 24 ?? 39 D0 0F 8D ?? ?? ?? ?? 89 44 24 ?? 89 + 4C 24 ?? 89 AC 24 ?? ?? ?? ?? 89 74 24 ?? 8D 0C C3 8B 11 89 94 24 ?? ?? ?? ?? 8B 49 + ?? 89 8C 24 ?? ?? ?? ?? 8B 6A ?? 89 0C 24 FF D5 0F B6 44 24 ?? 84 C0 0F 84 ?? ?? ?? + ?? 8B 84 24 ?? ?? ?? ?? 8B 40 ?? 8B 8C 24 ?? ?? ?? ?? 89 0C 24 FF D0 8B 44 24 ?? 8B + 4C 24 ?? 89 0C 24 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 85 C0 0F 86 ?? + ?? ?? ?? 0F B6 11 80 FA ?? 75 ?? 8B 44 24 ?? 8B 8C 24 ?? ?? ?? ?? 8B 54 24 ?? E9 ?? + ?? ?? ?? 80 FA ?? 74 ?? 89 44 24 ?? 89 8C 24 ?? ?? ?? ?? 89 0C 24 89 44 24 ?? 8B 15 + ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 2D ?? ?? ?? ?? 89 6C 24 ?? 89 5C 24 ?? 89 54 24 ?? + E8 ?? ?? ?? ?? 0F B6 44 24 ?? 84 C0 74 ?? 8B 44 24 ?? 8B 8C 24 ?? ?? ?? ?? 8B 54 24 + ?? E9 ?? ?? ?? ?? 8B 44 24 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 8B 11 } - $search_antivirus_processes_v2 = { - C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? - ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? - C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? - ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? - ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8B F0 6A ?? 89 74 24 ?? FF 15 ?? ?? ?? ?? 8B D8 85 DB 74 ?? C7 03 ?? - ?? ?? ?? 83 FE ?? 74 ?? 53 56 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8D 4B ?? 33 F6 EB - ?? 8D A4 24 ?? ?? ?? ?? 90 51 FF 74 B4 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 73 ?? 50 - 6A ?? FF 15 ?? ?? ?? ?? 8B F8 85 FF 74 ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 57 8B 3D ?? ?? - ?? ?? FF D7 EB ?? 8B 3D ?? ?? ?? ?? 46 8D 4B ?? 83 FE ?? 72 ?? 8B 74 24 ?? 53 56 FF - 15 ?? ?? ?? ?? 8D 4B ?? 85 C0 75 ?? 85 DB 74 ?? 68 ?? ?? ?? ?? 6A ?? 53 FF 15 ?? ?? - ?? ?? 56 FF D7 5F 5E 5B 8B E5 5D C3 + $find_files_p2 = { + 81 FA ?? ?? ?? ?? 75 ?? 0F B7 51 ?? 66 81 FA ?? ?? 75 ?? 0F B6 51 ?? 80 FA ?? 0F 84 + ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 8B 94 24 ?? ?? ?? ?? 89 54 24 ?? 8B 9C 24 ?? ?? ?? + ?? 89 5C 24 ?? 8D 2D ?? ?? ?? ?? 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 89 + 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 04 24 89 4C 24 ?? E8 ?? ?? ?? ?? + 8B 44 24 ?? 8D 48 ?? 8B 54 24 ?? 8B 5C 24 ?? 8B 6C 24 ?? 39 E9 7F ?? 8B B4 24 ?? ?? + ?? ?? 8D 7C C6 ?? 89 1F 8D 04 C6 8B 1D ?? ?? ?? ?? 85 DB 75 ?? 89 10 89 E8 89 CA 89 + F1 E9 ?? ?? ?? ?? 89 B4 24 ?? ?? ?? ?? 89 4C 24 ?? 89 6C 24 ?? 89 04 24 89 54 24 ?? + E8 ?? ?? ?? ?? 8B 4C 24 ?? 8B 6C 24 ?? 8B B4 24 ?? ?? ?? ?? EB ?? 89 94 24 ?? ?? ?? + ?? 89 5C 24 ?? 8D 15 ?? ?? ?? ?? 89 14 24 8B 9C 24 ?? ?? ?? ?? 89 5C 24 ?? 89 44 24 + ?? 89 6C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 74 24 ?? 8B 44 24 ?? 8B 6C 24 ?? 8D 48 + ?? 8B 44 24 ?? 8B 94 24 ?? ?? ?? ?? 8B 5C 24 ?? E9 ?? ?? ?? ?? 8D 54 24 ?? 89 14 24 + 8B 94 24 ?? ?? ?? ?? 89 54 24 ?? 8B 9C 24 ?? ?? ?? ?? 89 5C 24 ?? 8D 2D ?? ?? ?? ?? + 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 + ?? 8B 4C 24 ?? 89 0C 24 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 8C 24 ?? ?? ?? ?? + E9 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 8B 40 ?? 8B } - $find_files_v2_1 = { - 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 85 C0 74 - ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D3 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? - ?? F7 D8 1B C0 40 75 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 8B CE E8 ?? - ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 8D 3C 46 89 7D ?? FF D3 8D 85 ?? ?? - ?? ?? 50 56 FF 15 ?? ?? ?? ?? 33 C9 89 45 ?? 66 89 0F 83 F8 ?? 75 ?? B8 ?? ?? ?? ?? - 5F 5E 5B 8B E5 5D C3 8B 7D ?? EB ?? 8D 9B ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF D3 F6 85 ?? ?? - ?? ?? ?? 74 ?? 83 7D ?? ?? 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D3 8B 55 ?? 8B CE 6A ?? 57 FF 75 ?? FF 75 ?? E8 ?? ?? - ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D3 8B 55 ?? 8B CE 6A ?? 57 FF 75 - ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B 07 6A ?? 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 89 45 ?? 8B 47 ?? 6A ?? 89 45 ?? FF 15 ?? ?? ?? ?? 56 8B D8 68 ?? ?? ?? ?? - 53 FF 15 ?? ?? ?? ?? 83 C4 ?? 8B CB E8 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 6A ?? - 53 FF 15 ?? ?? ?? ?? 0F 57 C0 66 0F 13 45 ?? 8B 45 ?? 8B 4D ?? EB ?? 83 BD ?? ?? ?? - ?? ?? 0F 57 C0 66 0F 13 45 ?? 72 ?? 51 FF 75 ?? 8B CB E8 ?? ?? ?? ?? 83 C4 ?? 89 55 - ?? EB ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 68 ?? ?? ?? ?? 6A ?? 53 89 45 ?? FF 15 ?? ?? ?? - ?? 8B 45 ?? 8B 4D ?? 01 0F 11 47 ?? 8B 45 ?? 3B 47 ?? 77 ?? 72 ?? 8B 45 ?? 3B 07 73 - ?? 8B 45 ?? FF 00 8B 1D ?? ?? ?? ?? 8B 45 ?? 33 C9 66 89 08 8D 85 ?? ?? ?? ?? 50 FF - 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 33 - C0 5B 8B E5 5D C3 + $find_files_p3 = { + 8C 24 ?? ?? ?? ?? 89 0C 24 FF D0 8B 44 24 ?? 8B 4C 24 ?? 89 0C 24 89 44 24 ?? E8 ?? + ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 89 04 24 89 4C 24 ?? 8B 15 + ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B 2D ?? ?? ?? ?? 89 6C 24 ?? 89 5C 24 ?? 89 54 24 ?? + E8 ?? ?? ?? ?? 0F B6 44 24 ?? 84 C0 74 ?? 8B 44 24 ?? 8B 8C 24 ?? ?? ?? ?? 8B 54 24 + ?? E9 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 8B 4C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 + 24 ?? 89 84 24 ?? ?? ?? ?? 8B 4C 24 ?? 89 4C 24 ?? C7 04 24 ?? ?? ?? ?? 8B 94 24 ?? + ?? ?? ?? 89 54 24 ?? 8B 9C 24 ?? ?? ?? ?? 89 5C 24 ?? 8D 2D ?? ?? ?? ?? 89 6C 24 ?? + C7 44 24 ?? ?? ?? ?? ?? 8B 74 24 ?? 89 74 24 ?? 8B 74 24 ?? 89 74 24 ?? E8 ?? ?? ?? + ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8B 94 24 ?? ?? ?? ?? 89 14 24 8B + 5C 24 ?? 89 5C 24 ?? 8B 2D ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 89 6C 24 + ?? 89 74 24 ?? 89 7C 24 ?? E8 ?? ?? ?? ?? 0F B6 44 24 ?? 84 C0 0F 84 ?? ?? ?? ?? 8B + 84 24 ?? ?? ?? ?? 85 C0 0F 86 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 0F B6 08 83 C1 ?? 88 + 4C 24 ?? 0F B6 08 83 C1 ?? 88 4C 24 ?? 8D 0D ?? ?? ?? ?? 89 0C 24 8B 15 ?? ?? ?? ?? + 89 54 24 ?? 8D 54 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 48 ?? 8D 51 ?? 8B + 18 8B 40 ?? 39 C2 0F 8F ?? ?? ?? ?? 89 9C 24 ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? 8D } - $crypt_files_v2_1 = { - FF 15 ?? ?? ?? ?? 33 D2 89 44 24 ?? 89 44 24 ?? 8D 0C B7 8D 0C CD ?? ?? ?? ?? 85 C0 - 74 ?? 3B CB 73 ?? 8D 3C 01 89 44 24 ?? 89 7C 24 ?? 8B D1 EB ?? 89 54 24 ?? 8B F8 8B - 4D ?? 8D 34 CD ?? ?? ?? ?? 85 C0 74 ?? 8D 0C 32 89 4C 24 ?? 3B CB 73 ?? 8B 54 24 ?? - 8B CF 89 7C 24 ?? 03 FE 89 7C 24 ?? EB ?? 33 C9 89 4C 24 ?? 8B 74 24 ?? 85 C0 74 ?? - 8D 04 F5 ?? ?? ?? ?? 03 C2 3B C3 72 ?? 33 FF 89 7C 24 ?? 8B 1D ?? ?? ?? ?? 85 C9 0F - 84 ?? ?? ?? ?? 8B 55 ?? 8B 1D ?? ?? ?? ?? 8D 04 12 89 44 24 ?? 8D 44 24 ?? 50 51 68 - ?? ?? ?? ?? 52 FF 75 ?? FF D3 8D 04 36 89 44 24 ?? 8D 44 24 ?? 50 57 68 ?? ?? ?? ?? - 56 FF 74 24 ?? FF D3 8B 1D ?? ?? ?? ?? 57 FF D3 FF 74 24 ?? 8B F0 FF D3 6A ?? 83 C6 - ?? 03 C6 68 ?? ?? ?? ?? 50 6A ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? 8B F0 C7 - 44 24 ?? ?? ?? ?? ?? 89 74 24 ?? 89 74 24 ?? FF D3 40 85 F6 74 ?? 3B 44 24 ?? 73 ?? - 8D 0C 06 89 44 24 ?? 89 4C 24 ?? 89 74 24 ?? EB ?? C7 44 24 ?? ?? ?? ?? ?? 57 FF D3 - 40 85 F6 74 ?? 03 44 24 ?? 3B 44 24 ?? 72 ?? C7 44 24 ?? ?? ?? ?? ?? FF 74 24 ?? 33 - F6 FF D3 85 C0 74 ?? 8B 4C 24 ?? 8B 7C 24 ?? 89 4C 24 ?? 8A 04 3E 3C ?? 74 ?? 3C ?? - 74 ?? 88 01 41 89 4C 24 ?? 57 46 FF D3 8B 4C 24 ?? 3B F0 72 ?? 8B 7C 24 ?? 57 33 F6 - FF D3 85 C0 74 ?? 8B 4C 24 ?? 89 4C 24 ?? EB ?? 8D 49 ?? 8A 04 3E 3C ?? 74 ?? 3C ?? - 74 ?? 88 01 41 89 4C 24 ?? 57 46 FF D3 8B 4C 24 ?? 3B F0 72 ?? 8B 74 24 ?? 8B 1D ?? - ?? ?? ?? 68 ?? ?? ?? ?? 56 FF D3 56 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? 8D 3C 46 57 E8 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D3 68 ?? ?? ?? ?? 57 FF D3 68 ?? ?? ?? ?? 57 FF D3 68 - ?? ?? ?? ?? 57 FF D3 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF D6 68 - ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? 57 FF D3 57 FF 15 ?? ?? ?? ?? - FF 74 24 ?? 8D 34 47 FF 15 ?? ?? ?? ?? 50 56 6A ?? FF 74 24 ?? 6A ?? 68 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF D3 57 FF 15 ?? ?? ?? ?? FF 74 24 ?? 8D 34 47 - FF 15 ?? ?? ?? ?? 50 56 6A ?? FF 74 24 ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 - C0 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? 66 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 74 24 ?? 58 58 8D 44 24 ?? 50 57 FF - D3 8B 5C 24 ?? 8B 35 ?? ?? ?? ?? 53 FF D6 6A ?? C1 E0 ?? 83 C0 ?? 68 ?? ?? ?? ?? 50 - 6A ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? 8B F8 53 89 7C 24 ?? FF D6 8D 04 C5 ?? ?? ?? ?? - 85 FF 74 ?? 3B 44 24 ?? 72 ?? 33 FF 53 FF D6 8B 0D ?? ?? ?? ?? 8B F0 89 74 24 ?? 85 - C9 74 ?? 68 ?? ?? ?? ?? 6A ?? 51 FF 15 ?? ?? ?? ?? 8B 5C 24 ?? 6A ?? 68 ?? ?? ?? ?? - 53 FF 15 ?? ?? ?? ?? 83 C0 ?? 50 6A ?? FF 15 ?? ?? ?? ?? A3 ?? ?? ?? ?? 85 C0 74 ?? - 53 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8B 5C 24 ?? 03 F6 8B D6 8B CB E8 ?? - ?? ?? ?? 8B 4C 24 ?? 8D 04 CD ?? ?? ?? ?? 89 44 24 ?? 8D 44 24 ?? 50 57 68 ?? ?? ?? - ?? 56 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 57 FF D3 - 6A ?? 68 ?? ?? ?? ?? 8D 70 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 57 89 44 24 ?? FF D3 8D 48 - ?? 8B 44 24 ?? 85 C0 74 ?? 89 44 24 ?? 3B CE 72 ?? C7 44 24 ?? ?? ?? ?? ?? 57 33 F6 - FF D3 85 C0 74 ?? 8B 4C 24 ?? 89 4C 24 ?? 8A 04 3E 3C ?? 74 ?? 3C ?? 74 ?? 88 01 41 - 89 4C 24 ?? 57 46 FF D3 8B 4C 24 ?? 3B F0 72 ?? 8B 74 24 ?? 56 FF D3 50 FF 74 24 ?? - 6A ?? 56 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 7C 24 ?? 8D 54 24 ?? 6A ?? 57 8B - CE C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 1D ?? ?? ?? ?? 68 - ?? ?? ?? ?? 50 8B 44 24 ?? 50 FF D3 68 ?? ?? ?? ?? 6A ?? FF 74 24 ?? FF D3 68 ?? ?? - ?? ?? 6A ?? FF 74 24 ?? FF D3 33 F6 EB ?? 8B 4C 24 ?? 85 C9 74 ?? 8B 45 ?? 89 08 8B - 44 24 ?? 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 FF D3 68 ?? ?? ?? ?? 6A ?? FF 74 - 24 ?? FF D3 68 ?? ?? ?? ?? 6A ?? FF 74 24 ?? FF D3 EB ?? 8B 7C 24 ?? 83 7C 24 ?? ?? - 75 ?? 68 ?? ?? ?? ?? 6A ?? 57 FF D3 BE ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 74 24 ?? - FF D3 8D 4C 24 ?? E8 ?? ?? ?? ?? 5F 8B C6 5E 5B 8B E5 5D C3 + $find_files_p4 = { + 6C CB ?? 8B 74 24 ?? 89 75 ?? 8B 2D ?? ?? ?? ?? 8D 0C CB 85 ED 75 ?? 8B 6C 24 ?? 89 + 29 8D 05 ?? ?? ?? ?? 89 04 24 8B 0D ?? ?? ?? ?? 89 4C 24 ?? 8D 4C 24 ?? 89 4C 24 ?? + E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 48 ?? 8B 4C 24 ?? 89 48 ?? 8B 0D ?? ?? ?? + ?? 85 C9 75 ?? 8B 8C 24 ?? ?? ?? ?? 89 08 8B 6C 24 ?? 8B 4C 24 ?? 8B B4 24 ?? ?? ?? + ?? E9 ?? ?? ?? ?? 89 04 24 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? EB ?? 89 + 0C 24 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? EB ?? 89 4C 24 ?? 8D 2D ?? ?? ?? ?? 89 + 2C 24 89 5C 24 ?? 89 4C 24 ?? 89 44 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 8B + 44 24 ?? 8B 4C 24 ?? 8D 50 ?? 89 C8 8B 4C 24 ?? E9 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? + 89 04 24 8B 44 24 ?? 89 44 24 ?? 8B 05 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B 15 ?? ?? ?? + ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 0F B6 44 24 ?? 84 C0 74 ?? 8B + 44 24 ?? 8B 8C 24 ?? ?? ?? ?? 8B 54 24 ?? E9 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 85 C0 + 0F 86 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 0F B6 08 88 4C 24 ?? 0F B6 08 88 4C 24 ?? 8D } - $remote_connection_v2_1 = { - 53 89 45 ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 3C 45 ?? ?? - ?? ?? 8D 47 ?? 50 6A ?? FF D6 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B D8 FF D6 - 89 45 ?? 85 DB 74 ?? 8D 47 ?? 3B F8 73 ?? 8B F3 EB ?? 33 F6 FF 75 ?? 56 FF 15 ?? ?? - ?? ?? F3 0F 6F 05 ?? ?? ?? ?? 56 F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 - ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? F3 - 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? F3 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 ?? FF 15 ?? - ?? ?? ?? 8D 45 ?? 33 FF 50 FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 68 ?? ?? ?? ?? 83 EC ?? - 68 ?? ?? ?? ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 50 56 FF 75 ?? 8B 75 ?? 8D 4D ?? 56 E8 - ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? BF ?? ?? ?? ?? 74 ?? 8B 4D ?? 8D 55 ?? C7 45 ?? - ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 85 C0 74 ?? 8B 4D ?? 89 01 EB ?? 33 - FF 68 ?? ?? ?? ?? 6A ?? 56 8B 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF - D6 68 ?? ?? ?? ?? 6A ?? 53 FF D6 8B 45 ?? 85 C0 74 ?? 50 FF 15 ?? ?? ?? ?? 8B C7 5F - 5E 5B 8B E5 5D C3 + $find_files_p5 = { + 0D ?? ?? ?? ?? 89 0C 24 8B 15 ?? ?? ?? ?? 89 54 24 ?? 8D 54 24 ?? 89 54 24 ?? E8 ?? + ?? ?? ?? 8B 44 24 ?? 8B 48 ?? 8D 51 ?? 8B 18 8B 40 ?? 39 C2 0F 8F ?? ?? ?? ?? 89 9C + 24 ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? 8D 6C CB ?? 8B 74 24 ?? 89 75 ?? 8B 2D ?? ?? + ?? ?? 8D 0C CB 85 ED 75 ?? 8B 6C 24 ?? 89 29 8D 05 ?? ?? ?? ?? 89 04 24 8B 0D ?? ?? + ?? ?? 89 4C 24 ?? 8D 4C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 89 + 48 ?? 8B 4C 24 ?? 89 48 ?? 8B 0D ?? ?? ?? ?? 85 C9 75 ?? 8B 8C 24 ?? ?? ?? ?? 89 08 + E9 ?? ?? ?? ?? 89 04 24 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? + ?? 89 0C 24 8B 44 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? EB ?? 89 4C 24 ?? 8D 2D ?? ?? ?? + ?? 89 2C 24 89 5C 24 ?? 89 4C 24 ?? 89 44 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 + ?? 8B 44 24 ?? 8B 4C 24 ?? 8D 50 ?? 89 C8 8B 4C 24 ?? E9 ?? ?? ?? ?? 89 AC 24 ?? ?? + ?? ?? 89 8C 24 ?? ?? ?? ?? 89 B4 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? + C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 89 8C 24 ?? ?? ?? + ?? 89 84 24 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 E8 } - $search_antivirus_processes_v4_1_2 = { - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? 8B F8 53 6A ?? - 89 7D ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 89 1E 83 FF ?? 74 ?? 56 57 FF 15 ?? ?? - ?? ?? 33 DB 8D 7E ?? 57 FF B4 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 76 ?? - 50 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? - FF 15 ?? ?? ?? ?? 43 83 FB ?? 72 ?? 8B 7D ?? 56 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 85 - F6 74 ?? 68 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 - 5D C3 + $encrypt_files_p1 = { + 64 8B 0D ?? ?? ?? ?? 8B 89 ?? ?? ?? ?? 8D 44 24 ?? 3B 41 ?? 0F 86 ?? ?? ?? ?? 81 EC + ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? + ?? ?? ?? ?? 8B 40 ?? 89 04 24 8D 84 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 84 + 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 8D 15 ?? ?? ?? ?? 39 CA 0F 85 ?? ?? ?? ?? 8B 48 + ?? 89 4C 24 ?? 8B 00 89 84 24 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? 89 4C 24 + ?? 8B 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 89 54 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B 44 + 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? C6 44 24 ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? + ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 8D 54 24 ?? 89 54 24 ?? 8B 94 24 ?? ?? ?? ?? + 89 54 24 ?? 8B 5C 24 ?? 89 5C 24 ?? 8D AC 24 ?? ?? ?? ?? 89 6C 24 ?? 89 4C 24 ?? 89 + 44 24 ?? C7 04 24 ?? ?? ?? ?? 8D 2D ?? ?? ?? ?? 89 6C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F + 85 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 8B 4C 24 ?? 89 4C 24 ?? C7 44 24 ?? ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? + 85 D2 0F 85 ?? ?? ?? ?? 89 44 24 ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? 8D 0D ?? ?? ?? + ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 8B 44 24 + ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 85 D2 0F 85 ?? ?? + ?? ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 44 24 ?? E8 } - $find_files_v4_1_2 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 33 FF 89 54 24 ?? 8B F1 89 7C 24 ?? 39 - 7D ?? 75 ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 85 C0 75 ?? 85 DB 75 ?? 33 C0 E9 - ?? ?? ?? ?? 33 DB 43 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 66 83 3E ?? 74 ?? 8D 54 24 ?? - 89 7C 24 ?? 8B CE E8 ?? ?? ?? ?? 89 44 24 ?? 39 7C 24 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 56 8D 04 46 89 44 24 ?? FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 56 FF 15 ?? - ?? ?? ?? 8B 4C 24 ?? 33 D2 89 44 24 ?? 66 89 11 83 F8 ?? 75 ?? BF ?? ?? ?? ?? E9 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? - 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 44 24 ?? 50 56 FF 15 ?? ?? ?? ?? F6 - 44 24 ?? ?? 74 ?? 85 DB 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? - ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8B 54 24 ?? 8B CE E8 ?? ?? ?? ?? EB ?? 68 ?? ?? - ?? ?? 56 FF 15 ?? ?? ?? ?? 57 EB ?? FF 74 24 ?? 8D 54 24 ?? 8B CE E8 ?? ?? ?? ?? 59 - 8B 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 - ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B C7 5F 5E - 5B 8B E5 5D C3 + $encrypt_files_p2 = { + 85 C0 0F 85 ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8B 54 + 24 ?? 89 54 24 ?? 89 14 24 89 4C 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C + 24 ?? 85 C9 0F 85 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? + 89 14 24 89 4C 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? + 8B 5C 24 ?? 85 C9 0F 85 ?? ?? ?? ?? 89 1C 24 89 54 24 ?? 8B 44 24 ?? 89 44 24 ?? 8B + 4C 24 ?? 89 4C 24 ?? 8B 54 24 ?? 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? + 8B 4C 24 ?? 89 4C 24 ?? 8D 15 ?? ?? ?? ?? 89 14 24 8B 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? + ?? 8B 2D ?? ?? ?? ?? 89 54 24 ?? 89 5C 24 ?? 89 6C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? + 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8D 15 ?? ?? ?? ?? 89 14 24 C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 84 24 ?? ?? ?? ?? 8B 4C 24 + ?? 89 4C 24 ?? 8B 54 24 ?? 89 54 24 ?? 8B 5C 24 ?? 89 1C 24 8B 6C 24 ?? 89 6C 24 ?? + 8B 6C 24 ?? 89 6C 24 ?? 8B 6C 24 ?? 89 6C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 + ?? 85 C0 0F 85 ?? ?? ?? ?? 31 C0 EB ?? 8B 4C 24 ?? 8B 54 24 ?? 8D 04 0A 89 44 24 ?? + 8B 4C 24 ?? 89 0C 24 8B 94 24 ?? ?? ?? ?? 89 54 24 ?? 8B 5C 24 ?? 89 5C 24 ?? 8B 6C + 24 ?? 89 6C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8B + 54 24 ?? 89 54 24 ?? 85 C9 74 ?? 8B 1D ?? ?? ?? ?? 39 D9 0F 85 ?? ?? ?? ?? 89 0C 24 } - $crypt_files_v4_1_2 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 89 4D ?? 33 DB 57 B9 ?? ?? ?? ?? 89 5D ?? 8B F2 E8 - ?? ?? ?? ?? 8B F8 8D 55 ?? 56 57 8D 4D ?? 89 7D ?? E8 ?? ?? ?? ?? 59 59 85 C0 0F 84 - ?? ?? ?? ?? 53 53 6A ?? 53 53 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE - ?? 0F 84 ?? ?? ?? ?? 6A ?? 58 88 5D ?? 48 75 ?? 51 51 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 89 45 ?? B9 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 89 5D ?? 89 - 5D ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 89 5D ?? 53 8D - 45 ?? 50 68 ?? ?? ?? ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D - ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 45 ?? 81 F9 ?? ?? ?? ?? 6A ?? 5A 0F 42 C2 01 8F ?? ?? - ?? ?? 8B 55 ?? 8D 8D ?? ?? ?? ?? 11 9F ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 50 FF 75 ?? 89 - 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 33 C9 F7 D8 41 99 51 53 52 50 56 FF 15 ?? ?? ?? - ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 53 8D 45 ?? 50 FF 75 ?? FF 75 ?? 56 FF 15 ?? ?? ?? - ?? 85 C0 75 ?? 8B 7D ?? 6A ?? FF 15 ?? ?? ?? ?? 53 8D 45 ?? 50 FF 75 ?? 57 56 FF 15 - ?? ?? ?? ?? 85 C0 74 ?? 8B 7D ?? 8B 4D ?? 85 C9 0F 84 ?? ?? ?? ?? 53 8D 45 ?? 50 68 - ?? ?? ?? ?? 57 56 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B D8 E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? - ?? ?? 56 FF 15 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 5F 5E 8B C3 5B 8B E5 5D C3 33 C0 8D - 48 ?? 89 4D ?? EB + $encrypt_files_p3 = { + 89 54 24 ?? 8B 05 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 0F B6 44 24 ?? 84 C0 0F 84 + ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 04 24 8B 4C 24 ?? 89 4C 24 ?? 89 4C 24 ?? E8 ?? ?? + ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 8B 54 24 ?? 8B 5C 24 ?? 8B 6C 24 ?? 39 EB 0F 87 ?? ?? + ?? ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 8B 74 24 ?? 8B 7E ?? 89 44 24 ?? 89 4C 24 + ?? 89 54 24 ?? 8B B4 24 ?? ?? ?? ?? 89 74 24 ?? 89 5C 24 ?? 89 6C 24 ?? 8B 6C 24 ?? + 89 2C 24 FF D7 8B 44 24 ?? 8B 48 ?? 8B 54 24 ?? 89 54 24 ?? 8B 5C 24 ?? 89 5C 24 ?? + 8B 6C 24 ?? 89 6C 24 ?? 8B 74 24 ?? 89 34 24 FF D1 8B 44 24 ?? 89 04 24 8B 4C 24 ?? + 89 4C 24 ?? 8B 4C 24 ?? 89 4C 24 ?? 8B 4C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 + ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 05 ?? ?? ?? ?? 8B 4C 24 ?? 39 C1 0F 85 ?? ?? ?? ?? 89 + 0C 24 8B 44 24 ?? 89 44 24 ?? 8B 05 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 0F B6 44 + 24 ?? 84 C0 0F 84 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 8B 44 24 ?? 89 44 24 ?? + C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 + C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 44 24 ?? B9 ?? ?? ?? ?? F7 E9 8B 44 24 ?? 01 C2 C1 F8 ?? C1 FA ?? 29 C2 89 D0 + 89 D3 F7 E9 8D 04 13 C1 F8 ?? C1 FB ?? 29 D8 83 C0 ?? 89 44 24 ?? 31 C9 EB ?? 8B 54 + 24 ?? 8D 4A ?? 8B 44 24 ?? 39 C1 7D ?? 89 4C 24 ?? 8B 44 24 ?? 89 04 24 8D 0D ?? ?? + ?? ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 74 ?? 90 + E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 90 } - $remote_connection_v4_1_2 = { - 55 8B EC 83 EC ?? 53 8B 1D ?? ?? ?? ?? 56 8B F1 57 83 7E ?? ?? 74 ?? FF 76 ?? FF D3 - 8B CE E8 ?? ?? ?? ?? 33 FF 57 57 6A ?? 57 57 FF 75 ?? FF 75 ?? FF 76 ?? FF 15 ?? ?? - ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? - 83 C4 ?? B8 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 44 C8 57 51 57 57 68 - ?? ?? ?? ?? 56 8B 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? FF - 75 ?? FF 75 ?? FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 33 FF 47 EB ?? FF - 15 ?? ?? ?? ?? 8B 45 ?? 50 FF D3 56 FF D3 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B - E5 5D C2 - } - $url_parameters_setup_v4_1_2 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 FF 15 ?? ?? ?? ?? 33 FF 57 57 57 FF 15 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 57 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? E8 ?? - ?? ?? ?? 83 EC ?? 33 DB 43 53 83 EC ?? 53 51 53 51 53 51 53 51 53 83 EC ?? 53 51 53 - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 0C 45 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 85 C0 74 ?? 50 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF - D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? - ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 FF 35 ?? ?? ?? - ?? 8B 35 ?? ?? ?? ?? FF D6 FF 35 ?? ?? ?? ?? 03 C0 A3 ?? ?? ?? ?? FF D6 03 C0 8B D0 - E8 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 57 57 57 68 ?? ?? ?? ?? 57 57 FF 15 ?? ?? ?? ?? - 8B 35 ?? ?? ?? ?? 8B F8 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF D6 BB ?? ?? ?? ?? 53 - FF D6 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 53 FF D6 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? - FF D6 E8 ?? ?? ?? ?? 85 FF 74 ?? 6A ?? 57 FF 15 ?? ?? ?? ?? E8 - } - $url_parameters_setup_v4 = { - 55 8B EC 81 EC ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 6A ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 50 FF - 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 45 ?? E8 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 04 45 ?? ?? ?? ?? 50 6A ?? FF 15 ?? - ?? ?? ?? A3 ?? ?? ?? ?? 85 C0 75 ?? 50 FF 15 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF - 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? - ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 35 ?? ?? ?? - ?? FF D6 FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 03 C0 8B D0 E8 ?? ?? ?? ?? 6A ?? FF 15 - ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? - ?? FF D6 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF D6 - 68 ?? ?? ?? ?? FF D6 E8 ?? ?? ?? ?? E8 - } - $search_antivirus_processes_v4 = { - 55 8B EC 83 EC ?? 53 56 8B 35 ?? ?? ?? ?? 57 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A - ?? FF D6 8B 5D ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 89 03 C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 - ?? ?? ?? ?? ?? FF D6 8B F8 89 7D ?? 85 FF 74 ?? 6A ?? 6A ?? C7 07 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 5F 5E - 33 C0 5B 8B E5 5D C2 ?? ?? 33 C9 33 F6 57 50 89 4D ?? 89 4D ?? 89 4D ?? 89 75 ?? FF - 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 49 ?? 85 F6 0F 85 ?? ?? ?? ?? 83 C7 ?? EB - ?? 8D 49 ?? 57 FF 74 B5 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 46 83 FE ?? 72 ?? 8B 75 ?? - EB ?? 83 7D ?? ?? 57 FF 33 C7 45 ?? ?? ?? ?? ?? 75 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? - ?? FF 33 FF 15 ?? ?? ?? ?? EB ?? 8B 35 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? FF 33 FF D6 - FF 45 ?? 57 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B 75 ?? 8D 0C 41 B8 ?? ?? ?? ?? 81 F9 ?? ?? - ?? ?? 89 4D ?? 0F 47 F0 89 75 ?? 8B 7D ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? - FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 03 66 83 38 ?? 74 - ?? 50 FF 15 ?? ?? ?? ?? 8B 0B 33 D2 66 89 54 41 ?? 8B 45 ?? 8B 4D ?? 89 08 8B 35 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 FF D6 FF 75 ?? FF 15 ?? ?? ?? ?? 8B 7D ?? 85 FF 75 - ?? 68 ?? ?? ?? ?? 57 FF 33 FF D6 8B C7 5F 5E 5B 8B E5 5D C2 - } - $find_files_v4 = { - C7 44 24 ?? ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 66 83 3E ?? 0F 84 ?? ?? ?? - ?? 8D 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 89 44 24 - ?? 0F 85 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 8D 04 - 46 89 44 24 ?? FF D7 8D 44 24 ?? 50 56 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 D2 89 44 24 - ?? 66 89 11 83 F8 ?? 75 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5F 5E 5B 8B - E5 5D C3 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 44 24 ?? 50 56 FF D7 F6 - 44 24 ?? ?? 74 ?? 83 7C 24 ?? ?? 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 74 - ?? 68 ?? ?? ?? ?? 56 FF D7 6A ?? 8B D3 8B CE E8 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? 56 - FF D7 6A ?? 8B D3 8B CE E8 ?? ?? ?? ?? EB ?? 53 8D 54 24 ?? 8B CE E8 ?? ?? ?? ?? 83 - C4 ?? 8B 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 5F 5E - 33 C0 5B 8B E5 5D C3 - } - $crypt_files_v4 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 6A ?? 68 ?? ?? ?? ?? 33 DB 89 4D ?? 68 ?? ?? ?? - ?? 53 8B F2 89 5D ?? FF 15 ?? ?? ?? ?? 8B F8 8D 55 ?? 56 57 8D 4D ?? 89 7D ?? E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 33 C0 5F 5E 5B - 8B E5 5D C3 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? - 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? 88 5D ?? 48 75 ?? 8B 45 ?? 89 85 ?? - ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 8B - 45 ?? 89 45 ?? 8B 45 ?? 6A ?? 89 45 ?? 8B 45 ?? 68 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 68 - ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 89 5D ?? 89 5D ?? 8B 1D ?? ?? ?? ?? 6A ?? C7 05 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? FF D3 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? - 89 45 ?? FF D3 33 C9 8B D8 89 4D ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? FF 75 ?? 56 FF - 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 3D - ?? ?? ?? ?? BA ?? ?? ?? ?? 0F 42 CA 01 87 ?? ?? ?? ?? 8B 55 ?? 83 97 ?? ?? ?? ?? ?? - 8B 7D ?? 89 4D ?? 8D 8D ?? ?? ?? ?? 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B C7 F7 D8 99 6A - ?? 6A ?? 52 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 - 57 53 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 57 - 53 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 4D ?? 8B 7D ?? 85 C9 0F 84 ?? ?? ?? ?? 6A ?? - 8D 45 ?? 50 68 ?? ?? ?? ?? 57 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? 89 - 45 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? - ?? 8B 5D ?? 68 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 5F 5E 8B C3 5B 8B E5 5D C3 - } - $crypt_files_v3 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 45 ?? C7 45 - ?? ?? ?? ?? ?? 50 6A ?? 8B D9 8B CA 6A ?? E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 6A ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF D6 8B F8 C7 45 ?? ?? ?? ?? ?? 53 57 89 7D ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 57 FF 15 ?? ?? - ?? ?? 66 0F 6F 05 ?? ?? ?? ?? BA ?? ?? ?? ?? F3 0F 7F 85 ?? ?? ?? ?? 51 66 0F 6F 05 - ?? ?? ?? ?? 8D 4D ?? F3 0F 7F 45 ?? C6 45 ?? ?? 66 0F 6F 05 ?? ?? ?? ?? F3 0F 7F 45 - ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF D6 F3 0F 6F 85 ?? ?? ?? ?? 8B F8 6A ?? 68 ?? ?? - ?? ?? 68 ?? ?? ?? ?? F3 0F 7F 07 6A ?? F3 0F 6F 45 ?? 89 7D ?? F3 0F 7F 47 ?? FF D6 - F3 0F 6F 45 ?? 68 ?? ?? ?? ?? 89 45 ?? F3 0F 7F 00 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 - 57 FF 75 ?? C7 45 ?? ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 C4 ?? - 85 C0 75 ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? EB ?? 68 ?? - ?? ?? ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? - FF 15 ?? ?? ?? ?? 0F 57 C0 66 0F 13 45 ?? 8B 75 ?? 8B 5D ?? E9 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? - ?? 6A ?? FF 75 ?? FF D7 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D7 0F 57 C0 66 0F 13 45 ?? - 8B 75 ?? 8B 5D ?? E9 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF D6 6A ?? 8B D8 - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? C7 03 ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? FF D6 8B - 3D ?? ?? ?? ?? 33 F6 33 C9 89 45 ?? 89 4D ?? EB ?? 8B 45 ?? 6A ?? 8D 4D ?? 51 68 ?? - ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 - ?? ?? ?? ?? 3D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - 0F 42 F1 01 03 83 53 ?? ?? 8B 45 ?? 89 45 ?? 89 45 ?? A8 ?? 74 ?? 8B FF 40 A8 ?? 75 - ?? 89 45 ?? 6A ?? 68 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? FF 75 ?? 89 45 ?? FF 75 - ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 89 45 ?? 6A ?? 68 ?? ?? ?? ?? 50 6A ?? FF 15 - ?? ?? ?? ?? 85 C0 74 ?? 8B 55 ?? 8B 4D ?? 50 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 8D 45 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D7 8B 4D ?? 8B 45 ?? - F7 D9 6A ?? 83 D0 ?? 6A ?? F7 D8 50 51 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 - ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 - ?? BE ?? ?? ?? ?? 89 75 ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D7 85 F6 0F 84 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D7 8B 4D ?? 8B 75 ?? 85 C9 75 ?? 51 8D 45 ?? 50 - 68 ?? ?? ?? ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? FF 75 - ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A ?? 53 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? - ?? ?? ?? 8B 03 8B 73 ?? 68 ?? ?? ?? ?? 6A ?? 53 89 45 ?? FF D7 68 ?? ?? ?? ?? 6A ?? - FF 75 ?? FF D7 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF D7 8B 5D ?? 68 ?? ?? ?? ?? 6A ?? FF - 75 ?? FF D7 5F 8B D6 8B C3 5E 5B 8B E5 5D C3 - } - $search_antivirus_processes_v5 = { - 8B 7D ?? 6A ?? 53 6A ?? 33 DB 89 07 53 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF - D6 8B F0 85 F6 75 ?? 33 C0 E9 ?? ?? ?? ?? 53 6A ?? C7 06 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 89 45 ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? 53 56 FF 15 ?? ?? ?? ?? EB ?? 56 33 C9 89 - 5D ?? 50 89 5D ?? 89 4D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 0F - 85 ?? ?? ?? ?? 33 C0 8D 4E ?? 89 45 ?? 51 FF 74 85 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? - 8B 45 ?? 8D 4E ?? 40 89 45 ?? 83 F8 ?? 72 ?? EB ?? 33 C0 39 45 ?? 8D 58 ?? 8D 46 ?? - 50 FF 37 75 ?? FF 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 37 FF 15 - ?? ?? ?? ?? FF 45 ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 6A ?? 8D 0C 41 8B 45 ?? - 81 F9 ?? ?? ?? ?? 89 4D ?? 59 0F 47 C1 89 45 ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 - 74 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 85 DB 74 ?? 8B 07 33 C9 66 39 08 - 74 ?? 50 FF 15 ?? ?? ?? ?? 8B 0F 33 D2 66 89 54 41 ?? 8B 45 ?? 8B 4D ?? 89 08 68 ?? - ?? ?? ?? 33 C0 50 56 8B 35 ?? ?? ?? ?? FF D6 FF 75 ?? FF 15 ?? ?? ?? ?? 85 DB 75 ?? - 68 ?? ?? ?? ?? 33 C0 50 FF 37 FF D6 8B C3 5F 5E 5B 8B E5 5D C2 - } - $find_files_v5 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 33 FF 89 54 24 ?? 8B F1 89 7C 24 ?? 39 - 7D ?? 75 ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 85 C0 75 ?? 85 DB 75 ?? 33 C0 E9 - ?? ?? ?? ?? 33 DB 43 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 66 83 3E ?? 74 ?? 8D 54 24 ?? - 89 7C 24 ?? 8B CE E8 ?? ?? ?? ?? 89 44 24 ?? 39 7C 24 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 56 8D 04 46 89 44 24 ?? FF 15 ?? ?? ?? ?? 6A ?? 57 57 8D 44 24 ?? 50 - 6A ?? 56 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 D2 89 44 24 ?? 66 89 11 83 F8 ?? 75 ?? BF - ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 - ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 44 24 ?? 50 56 FF - 15 ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? 85 DB 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? - 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8B 54 24 ?? 8B CE E8 ?? ?? ?? - ?? EB ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 57 EB ?? FF 74 24 ?? 8D 54 24 ?? 8B CE - E8 ?? ?? ?? ?? 59 8B 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? - ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? - ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Prometey : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Prometey ransomware." + author = "ReversingLabs" + id = "a5902fc6-2752-520f-be84-df9ea7b1e27d" + date = "2021-06-07" + modified = "2021-06-07" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Prometey.yara#L1-L156" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "f14c9605e2d375176b461fd396be66754b0ace7dcaada8ca33ad86f6eda10b73" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Prometey" + tc_detection_factor = 5 + importance = 25 + + strings: + $remote_connection_p1 = { + 55 8D AC 24 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 85 ?? ?? ?? ?? 53 56 57 50 8D 45 ?? 64 A3 + ?? ?? ?? ?? 6A ?? 5E 8D 85 ?? ?? ?? ?? 89 75 ?? 50 BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? + ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? + E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 5B 8D 4D ?? 88 5D ?? E8 ?? ?? + ?? ?? 39 9D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 03 + C1 39 9D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 51 50 51 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 95 ?? ?? ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? 59 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 39 9D ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 03 C1 39 9D ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? 0F 43 8D ?? ?? ?? ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 + ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 33 DB 53 53 53 53 50 88 5D } - $crypt_files_v5 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B D9 89 55 ?? 33 FF 89 5D ?? 21 7D ?? B9 ?? ?? - ?? ?? 89 7D ?? E8 ?? ?? ?? ?? 8B F0 89 75 ?? 85 F6 75 ?? 33 C0 E9 ?? ?? ?? ?? FF 75 - ?? 8D 55 ?? 56 8D 4D ?? E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8B CE E8 ?? ?? ?? ?? EB ?? - 33 C0 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B D8 83 FB - ?? 75 ?? 33 C0 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? - ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? FF 70 ?? FF 70 ?? 6A ?? 6A ?? 53 FF 15 - ?? ?? ?? ?? 6A ?? 58 C6 45 ?? ?? 48 75 ?? 51 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 8E ?? ?? ?? ?? 21 7D ?? 21 7D ?? 41 89 45 ?? - 8B 45 ?? 89 45 ?? E8 ?? ?? ?? ?? 8B 8E ?? ?? ?? ?? 83 C1 ?? 89 45 ?? E8 ?? ?? ?? ?? - 89 45 ?? 33 FF 6A ?? 8D 45 ?? 50 FF B6 ?? ?? ?? ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 3B 86 ?? ?? ?? ?? 8B 55 ?? 6A - ?? 59 0F 42 F9 83 7D ?? ?? 8D 8D ?? ?? ?? ?? 0F 45 7D ?? 01 86 ?? ?? ?? ?? 89 7D ?? - 83 96 ?? ?? ?? ?? ?? 8B 45 ?? 50 FF 75 ?? 89 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 33 - C9 F7 D8 41 99 51 6A ?? 52 50 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 - ?? 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 75 ?? 8B 7D ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? - 8D 45 ?? 50 57 56 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 75 ?? 8B 7D ?? 33 C0 40 01 86 - ?? ?? ?? ?? 83 96 ?? ?? ?? ?? ?? EB ?? 33 C0 8D 78 ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7D - ?? ?? 74 ?? 6A ?? 6A ?? 0F 57 C0 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? - ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B F8 89 7D ?? - E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? - 85 FF 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? 83 65 ?? ?? 83 65 ?? ?? 8B 35 ?? - ?? ?? ?? FF D6 8D 0C 45 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F8 33 C0 40 83 67 ?? - ?? 88 07 FF D6 FF 75 ?? 03 C0 89 47 ?? FF D6 8D 04 45 ?? ?? ?? ?? 50 FF 75 ?? 8D 47 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF 75 ?? FF D6 8D 04 45 ?? ?? ?? ?? 50 57 8D 45 - ?? 50 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 89 01 8B CF E8 ?? ?? ?? ?? 8B 7D ?? 8B 45 ?? FF - 70 ?? FF 70 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B - 8B E5 5D C3 + $remote_connection_p2 = { + FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 53 56 53 53 6A ?? 68 ?? ?? + ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B D8 85 DB 74 ?? 6A ?? 68 ?? ?? ?? ?? + 33 C0 50 50 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? + 33 C0 50 50 50 50 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 + E8 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? + 8D 4D ?? E8 ?? ?? ?? ?? 56 FF D7 53 FF D7 FF 75 ?? FF D7 80 7D ?? ?? 74 ?? 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 59 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 8D + ?? ?? ?? ?? 33 CD E8 ?? ?? ?? ?? 81 C5 ?? ?? ?? ?? C9 C3 8B 85 ?? ?? ?? ?? 85 C0 0F + 84 ?? ?? ?? ?? 3D ?? ?? ?? ?? 73 ?? 8D 95 ?? ?? ?? ?? C6 84 05 ?? ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? E9 ?? ?? ?? ?? E8 } - $remote_connection_v5 = { - 55 8B EC 83 EC ?? 53 8B 1D ?? ?? ?? ?? 56 8B F1 57 83 7E ?? ?? 74 ?? FF 76 ?? FF D3 - 8B CE E8 ?? ?? ?? ?? 33 FF 57 57 6A ?? 57 57 FF 75 ?? FF 75 ?? FF 76 ?? FF 15 ?? ?? - ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? - 83 C4 ?? B8 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 44 C8 57 51 57 57 68 - ?? ?? ?? ?? 56 8B 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? FF - 75 ?? FF 75 ?? FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 33 FF 47 EB ?? FF - 15 ?? ?? ?? ?? 8B 45 ?? 50 FF D3 56 FF D3 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B - E5 5D C2 + $find_files_p1 = { + 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 5D ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? + ?? BA ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 65 ?? ?? 8D 4D ?? 8B D3 C7 04 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? + 51 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? + ?? 33 C0 8D 7D ?? AB AB AB 33 C0 89 45 ?? 89 45 ?? 89 45 ?? C6 45 ?? ?? F6 85 ?? ?? + ?? ?? ?? 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8B 95 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 59 8B D0 C6 45 ?? ?? 8B 4A + ?? 8B 7A ?? 2B CF 39 4E ?? 76 ?? 8B 46 ?? 2B 46 ?? 3B C7 72 ?? 83 7A ?? ?? 72 ?? 8B + 12 57 52 51 8B CE E8 ?? ?? ?? ?? EB ?? 56 8B CA E8 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? + ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 45 ?? FF B5 ?? ?? ?? ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8D + 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 8B 45 ?? 0F 43 4D ?? 8D 04 41 8D 4D ?? 0F 43 4D + ?? 51 50 51 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 83 7D ?? ?? 8D 7D + ?? 8B 9D ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 83 7D ?? ?? 8B 45 ?? 0F 43 7D ?? 89 8D ?? + ?? ?? ?? 3B D8 77 ?? 85 DB 75 ?? 8B F3 EB ?? 0F BE 09 2B C3 40 89 8D ?? ?? ?? ?? 03 } - $remote_connection_v5_0_1 = { - 55 8B EC 83 EC ?? 53 8B 1D ?? ?? ?? ?? 56 8B F1 57 83 7E ?? ?? 74 ?? FF 76 ?? FF D3 - 8B CE E8 ?? ?? ?? ?? 33 FF 57 57 6A ?? 57 57 FF 75 ?? FF 75 ?? FF 76 ?? FF 15 ?? ?? - ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? - 83 C4 ?? B8 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 44 C8 57 51 57 57 68 - ?? ?? ?? ?? 56 8B 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? FF - 75 ?? FF 75 ?? FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? ?? ?? 33 C9 41 85 C0 8B 45 ?? 0F 45 - F9 50 FF D3 56 FF D3 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C2 + $find_files_p2 = { + C7 89 85 ?? ?? ?? ?? 2B C7 50 51 57 EB ?? 53 FF B5 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 74 ?? 8B 85 ?? ?? ?? ?? 46 2B C6 50 FF B5 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? + 8B F0 83 C4 ?? 85 F6 75 ?? 83 CE ?? 33 DB 56 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8D 45 ?? 89 5D ?? 50 8D 4D ?? 89 5D + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 7D ?? 83 7D ?? ?? 8B 55 ?? 0F 43 7D ?? 85 D2 74 ?? + 83 C9 ?? 8D 42 ?? 3B C1 0F 42 C8 03 CF EB ?? 2B F7 EB ?? 3B CF 74 ?? 49 80 39 ?? 75 + ?? 2B CF EB ?? 83 C9 ?? 83 F9 ?? 0F 84 ?? ?? ?? ?? 8D 79 ?? 89 5D ?? C7 45 ?? ?? ?? + ?? ?? 88 5D ?? 3B D7 0F 82 ?? ?? ?? ?? 2B D7 8D 45 ?? 83 C9 ?? 83 FA ?? 0F 42 CA 83 + 7D ?? ?? 51 0F 43 45 ?? 8D 4D ?? 03 C7 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC + 8D 45 ?? 50 89 59 ?? 89 59 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 85 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 59 59 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 51 51 8D 45 ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 6A ?? 53 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? BB ?? ?? ?? ?? 8B 78 ?? 03 38 3B FB 7D ?? 81 FE ?? ?? ?? ?? 76 ?? 8D } - $url_parameters_setup_v5 = { - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 - ?? 8B 45 ?? 8D 8C 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? - 75 ?? 6A ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - D1 E0 A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? D1 E0 8B D0 8B 0D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A - ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? - ?? 73 ?? 83 65 ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A - ?? FF 75 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? - ?? ?? 83 7D ?? ?? 74 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B E5 5D C3 + $find_files_p3 = { + 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 3B FB 7D ?? 81 FE ?? ?? ?? ?? + 76 ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 83 7D ?? ?? 8B 45 ?? 0F 43 4D + ?? 8D 04 41 50 51 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? C6 45 + ?? ?? 56 BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? + ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? C6 45 ?? ?? E8 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? + ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? 83 7D ?? ?? 51 0F 43 45 ?? 51 50 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 56 BA ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? C7 04 24 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 56 8B C8 C6 45 ?? ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 85 } - $url_parameters_setup_v5_0_1 = { - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 - ?? 8B 45 ?? 8D 8C 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? - 75 ?? 6A ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - D1 E0 A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? D1 E0 8B D0 8B 0D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A - ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? - ?? 73 ?? 83 65 ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A - ?? FF 75 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? - ?? ?? 83 7D ?? ?? 74 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B E5 5D C3 + $find_files_p4 = { + 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B C8 C6 45 ?? ?? E8 ?? ?? ?? ?? 50 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 85 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 8B 45 + ?? 8D 4D ?? 51 3B 45 ?? 74 ?? 8B C8 E8 ?? ?? ?? ?? 83 45 ?? ?? EB ?? 50 8D 4D ?? E8 + ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B 9D ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 FF 15 ?? + ?? ?? ?? 8B 7D ?? 8B 75 ?? 6A ?? 5B 3B F7 74 ?? 56 E8 ?? ?? ?? ?? 03 F3 59 3B F7 75 + ?? 8B 7D ?? 8B 75 ?? 85 F6 74 ?? 3B F7 74 ?? 8B CE E8 ?? ?? ?? ?? 03 F3 3B F7 75 ?? + 8B 75 ?? 8B 45 ?? 2B C6 99 F7 FB 6B C0 ?? 50 56 E8 ?? ?? ?? ?? 59 59 8D 4D ?? E8 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 } - $crypt_files_v5_0_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B D9 89 55 ?? 33 FF 89 5D ?? 21 7D ?? B9 ?? ?? - ?? ?? 89 7D ?? E8 ?? ?? ?? ?? 8B F0 33 C0 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 50 68 ?? - ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 75 ?? 33 C0 - 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB - ?? 0F 84 ?? ?? ?? ?? 8B 7D ?? FF 77 ?? FF 77 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 6A - ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8D 45 ?? 50 68 - ?? ?? ?? ?? 56 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 81 BE ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? - 81 BE ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? FF 77 ?? FF 77 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? - ?? 53 FF 15 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? 6A ?? 6A ?? 0F 57 - C0 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? FF 75 ?? 83 65 ?? ?? 8D 55 - ?? 56 8D 4D ?? E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A ?? 58 C6 45 ?? ?? 48 75 ?? 51 68 - ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 8E ?? ?? - ?? ?? 83 65 ?? ?? 83 65 ?? ?? 41 89 45 ?? 8B 45 ?? 89 45 ?? E8 ?? ?? ?? ?? 8B 8E ?? - ?? ?? ?? 83 C1 ?? 89 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 33 FF 6A ?? 8D 45 ?? 50 FF B6 ?? - ?? ?? ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 - ?? ?? ?? ?? 3B 86 ?? ?? ?? ?? 8B 55 ?? 6A ?? 59 0F 42 F9 83 7D ?? ?? 8D 8D ?? ?? ?? - ?? 0F 45 7D ?? 01 86 ?? ?? ?? ?? 89 7D ?? 83 96 ?? ?? ?? ?? ?? 8B 45 ?? 50 FF 75 ?? - 89 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 33 C9 F7 D8 41 99 51 6A ?? 52 50 53 FF 15 ?? - ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 75 - ?? 8B 7D ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 57 56 53 FF 15 ?? ?? ?? ?? 85 - C0 74 ?? 8B 75 ?? 8B 7D ?? 33 C0 40 01 86 ?? ?? ?? ?? 83 96 ?? ?? ?? ?? ?? EB ?? 33 - C0 8D 78 ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 6A ?? 6A ?? 0F 57 C0 66 0F 13 - 45 ?? FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 53 - FF 15 ?? ?? ?? ?? 8B 4D ?? 8B F8 89 7D ?? E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B - CE E8 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? - FF 75 ?? 83 65 ?? ?? 83 65 ?? ?? 8B 35 ?? ?? ?? ?? FF D6 8D 0C 45 ?? ?? ?? ?? E8 ?? - ?? ?? ?? FF 75 ?? 8B F8 33 C0 40 83 67 ?? ?? 88 07 FF D6 FF 75 ?? 03 C0 89 47 ?? FF - D6 8D 04 45 ?? ?? ?? ?? 50 FF 75 ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF 75 - ?? FF D6 8D 04 45 ?? ?? ?? ?? 50 57 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 89 01 - 8B CF E8 ?? ?? ?? ?? 8B 7D ?? 8B 45 ?? FF 70 ?? FF 70 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? - ?? ?? 53 FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 + $encrypt_files = { + 8B FF 55 8B EC 57 FF 75 ?? E8 ?? ?? ?? ?? 59 8B 4D ?? 8B F8 8B 49 ?? 90 F6 C1 ?? 75 + ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 8B 45 ?? 6A ?? 59 83 C0 ?? F0 09 08 83 C8 ?? E9 + ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? 90 C1 E8 ?? A8 ?? 74 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? + ?? EB ?? 8B 45 ?? 8B 40 ?? 90 A8 ?? 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 59 8B 4D ?? 83 61 + ?? ?? 84 C0 8B 45 ?? 74 ?? 8B 48 ?? 89 08 8B 45 ?? 6A ?? 59 83 C0 ?? F0 21 08 8B 45 + ?? 53 6A ?? 5B 83 C0 ?? F0 09 18 8B 45 ?? 6A ?? 59 83 C0 ?? F0 21 08 8B 45 ?? 83 60 + ?? ?? 8B 45 ?? 8B 40 ?? 90 A9 ?? ?? ?? ?? 75 ?? 56 8B 75 ?? 6A ?? E8 ?? ?? ?? ?? 59 + 3B F0 74 ?? 8B 75 ?? 53 E8 ?? ?? ?? ?? 59 3B F0 75 ?? 57 E8 ?? ?? ?? ?? 59 85 C0 75 + ?? FF 75 ?? E8 ?? ?? ?? ?? 59 5E FF 75 ?? 8B 5D ?? 53 E8 ?? ?? ?? ?? 59 59 84 C0 75 + ?? 8B 45 ?? 6A ?? 59 83 C0 ?? F0 09 08 83 C8 ?? EB ?? 0F B6 C3 5B 5F 5D C3 } - $find_files_v5_0_1 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 33 FF 89 54 24 ?? 8B F1 89 7C 24 ?? 39 - 7D ?? 75 ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 85 C0 75 ?? 85 DB 75 ?? 33 C0 E9 - ?? ?? ?? ?? 33 DB 43 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 66 83 3E ?? 74 ?? 8D 54 24 ?? - 89 7C 24 ?? 8B CE E8 ?? ?? ?? ?? 89 44 24 ?? 39 7C 24 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 56 8D 04 46 89 44 24 ?? FF 15 ?? ?? ?? ?? 6A ?? 57 57 8D 44 24 ?? 50 - 6A ?? 56 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 D2 89 44 24 ?? 66 89 11 83 F8 ?? 75 ?? BF - ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 - ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 44 24 ?? 50 56 FF - 15 ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? 85 DB 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? - 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8B 54 24 ?? 8B CE E8 ?? ?? ?? - ?? EB ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 57 EB ?? FF 74 24 ?? 8D 54 24 ?? 8B CE - E8 ?? ?? ?? ?? 59 8B 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? - ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? - ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) and ( all of ($remote_connection_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Skystars : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Skystars ransomware." + author = "ReversingLabs" + id = "9dc19bda-c5bd-58fb-8c4f-a7d8a6fbbce9" + date = "2020-11-20" + modified = "2020-11-20" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Skystars.yara#L1-L97" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "352d22183b0974908ce684725fe85b4714ac5959c3bddf093b54383195881a5a" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Skystars" + tc_detection_factor = 5 + importance = 25 + + strings: + $search_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? + 8B 5D ?? FF 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 85 ?? ?? ?? ?? 50 + 6A ?? 6A ?? FF 75 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 5D ?? 85 DB + 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? + 83 C4 ?? 58 89 45 ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? + ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? B8 ?? + ?? ?? ?? EB ?? B8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8B 5D + ?? FF 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? + 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A + ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? + 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 5D ?? FF 33 } - $search_antivirus_processes_v5_0_1 = { - 55 8B EC 83 EC ?? 53 56 8B 35 ?? ?? ?? ?? BB ?? ?? ?? ?? 57 6A ?? 53 68 ?? ?? ?? ?? - 33 C0 50 FF D6 8B 7D ?? 6A ?? 53 6A ?? 33 DB 89 07 53 C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? FF D6 8B F0 85 F6 75 ?? 33 C0 E9 ?? ?? ?? ?? 53 6A ?? C7 06 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? 53 56 FF 15 ?? ?? ?? ?? EB - ?? 56 33 C9 89 5D ?? 50 89 5D ?? 89 4D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 33 C0 8D 4E ?? 89 45 ?? 51 FF 74 85 ?? FF 15 ?? ?? ?? - ?? 85 C0 74 ?? 8B 45 ?? 8D 4E ?? 40 89 45 ?? 83 F8 ?? 72 ?? EB ?? 33 C0 39 45 ?? 8D - 58 ?? 8D 46 ?? 50 FF 37 75 ?? FF 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? - ?? FF 37 FF 15 ?? ?? ?? ?? FF 45 ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 6A ?? 8D - 0C 41 8B 45 ?? 81 F9 ?? ?? ?? ?? 89 4D ?? 59 0F 47 C1 89 45 ?? 56 FF 75 ?? FF 15 ?? - ?? ?? ?? 85 C0 74 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 85 DB 74 ?? 8B 07 - 33 C9 66 39 08 74 ?? 50 FF 15 ?? ?? ?? ?? 8B 0F 33 D2 66 89 54 41 ?? 8B 45 ?? 8B 4D - ?? 89 08 68 ?? ?? ?? ?? 33 C0 50 56 8B 35 ?? ?? ?? ?? FF D6 FF 75 ?? FF 15 ?? ?? ?? - ?? 85 DB 75 ?? 68 ?? ?? ?? ?? 33 C0 50 FF 37 FF D6 8B C3 5F 5E 5B 8B E5 5D C2 + $search_files_p2 = { + B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? + ?? ?? FF 75 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 5D ?? 85 DB 74 ?? + 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 + ?? 58 89 45 ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? + ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? + ?? EB ?? B8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8B 5D ?? FF + 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 5D + ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? + 6A ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 + ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? E9 ?? ?? ?? ?? FF 75 ?? B8 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B E5 5D C2 } - $set_url_parameters_v5_0_2 = { - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 - ?? 8B 45 ?? 8D 8C 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? - 75 ?? 6A ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - D1 E0 A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? D1 E0 8B D0 8B 0D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A - ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? - ?? 73 ?? 83 65 ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A - ?? FF 75 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? - ?? ?? 83 7D ?? ?? 74 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B E5 5D C3 + $encrypt_files = { + 55 8B EC 81 EC ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 5D ?? 8B 03 + 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 89 45 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? 68 + ?? ?? ?? ?? 6A ?? 8B 5D ?? 8B 03 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 5D ?? FF + 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? + ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? FF 75 ?? 68 ?? ?? + ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? + ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? + 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? + ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? + 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 + 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 50 + 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? + ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 + ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B E5 5D C2 } - $set_url_parameters_v5_0_3 = { - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 - ?? 8B 45 ?? 8D 8C 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? - 75 ?? 6A ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF - 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - D1 E0 A3 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? D1 E0 8B D0 8B 0D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 73 ?? 83 65 ?? ?? 68 ?? ?? ?? ?? 8D - 45 ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A ?? FF 75 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? - 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? - ?? ?? 83 7D ?? ?? 74 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B E5 5D C3 + $main_routine = { + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 53 E8 + ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? + ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 5D + ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8D 45 ?? 50 + E8 ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? 89 45 + ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? + ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? + 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B E5 5D C3 } - $search_antivirus_processes_v5_0_2 = { - 55 8B EC 83 EC ?? 53 56 8B 35 ?? ?? ?? ?? BB ?? ?? ?? ?? 57 6A ?? 53 68 ?? ?? ?? ?? - 33 C0 50 FF D6 8B 7D ?? 6A ?? 53 6A ?? 33 DB 89 07 53 C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? FF D6 8B F0 85 F6 75 ?? 33 C0 E9 ?? ?? ?? ?? 53 6A ?? C7 06 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? 53 56 FF 15 ?? ?? ?? ?? EB - ?? 56 33 C9 89 5D ?? 50 89 5D ?? 89 4D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 33 C0 8D 4E ?? 89 45 ?? 51 FF 74 85 ?? FF 15 ?? ?? ?? - ?? 85 C0 74 ?? 8B 45 ?? 8D 4E ?? 40 89 45 ?? 83 F8 ?? 72 ?? EB ?? 33 C0 39 45 ?? 8D - 58 ?? 8D 46 ?? 50 FF 37 75 ?? FF 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? - ?? FF 37 FF 15 ?? ?? ?? ?? FF 45 ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 6A ?? 8D - 0C 41 8B 45 ?? 81 F9 ?? ?? ?? ?? 89 4D ?? 59 0F 47 C1 89 45 ?? 56 FF 75 ?? FF 15 ?? - ?? ?? ?? 85 C0 74 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 85 DB 74 ?? 8B 07 - 33 C9 66 39 08 74 ?? 50 FF 15 ?? ?? ?? ?? 8B 0F 33 D2 66 89 54 41 ?? 8B 45 ?? 8B 4D - ?? 89 08 68 ?? ?? ?? ?? 33 C0 50 56 8B 35 ?? ?? ?? ?? FF D6 FF 75 ?? FF 15 ?? ?? ?? - ?? 85 DB 75 ?? 68 ?? ?? ?? ?? 33 C0 50 FF 37 FF D6 8B C3 5F 5E 5B 8B E5 5D C2 + + condition: + uint16(0)==0x5A4D and ($main_routine) and ( all of ($search_files_p*)) and ($encrypt_files) +} +rule REVERSINGLABS_Win32_Ransomware_Gibon : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Gibon ransomware." + author = "ReversingLabs" + id = "3f1a5bee-8fc0-5596-b898-e97073731930" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Gibon.yara#L1-L122" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "cace0f35529307487f39aace6ae8989c7b878f82ebe890b256dfac563551a099" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Gibon" + tc_detection_factor = 5 + importance = 25 + + strings: + $remote_server_connection_1_0 = { + 53 8B DC 83 EC ?? 83 E4 ?? 83 C4 ?? 55 8B 6B ?? 89 6C 24 ?? 8B EC 6A ?? 68 ?? ?? ?? + ?? 64 A1 ?? ?? ?? ?? 50 53 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 + ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? BA ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? 85 C0 74 ?? BA ?? ?? + ?? ?? E9 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? + 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 B9 ?? ?? ?? ?? 83 FE ?? 75 ?? BA ?? ?? ?? ?? E9 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? 6A ?? 66 89 85 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 56 FF 15 ?? ?? ?? ?? 8B + 3D ?? ?? ?? ?? 85 C0 79 ?? FF D7 50 51 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 8B 43 ?? + 83 C0 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 7B ?? ?? 8D 43 ?? FF 73 ?? 0F 43 43 ?? 8D 8D ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 } - $find_files_v5_0_2 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 33 FF 89 54 24 ?? 8B F1 89 7C 24 ?? 39 - 7D ?? 75 ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 85 C0 75 ?? 85 DB 75 ?? 33 C0 E9 - ?? ?? ?? ?? 33 DB 43 8B CE E8 ?? ?? ?? ?? 85 C0 75 ?? 66 83 3E ?? 74 ?? 8D 54 24 ?? - 89 7C 24 ?? 8B CE E8 ?? ?? ?? ?? 89 44 24 ?? 39 7C 24 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 56 8D 04 46 89 44 24 ?? FF 15 ?? ?? ?? ?? 6A ?? 57 57 8D 44 24 ?? 50 - 6A ?? 56 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 75 ?? 8D 44 24 ?? 50 56 FF 15 ?? ?? - ?? ?? 89 44 24 ?? 8B 4C 24 ?? 33 D2 66 89 11 83 F8 ?? 75 ?? BF ?? ?? ?? ?? E9 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 8D - 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8D 44 24 ?? 50 56 FF 15 ?? ?? ?? ?? F6 44 - 24 ?? ?? 74 ?? 85 DB 74 ?? BA ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? - ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8B 54 24 ?? 8B CE E8 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? - ?? 56 FF 15 ?? ?? ?? ?? 57 EB ?? FF 74 24 ?? 8D 54 24 ?? 8B CE E8 ?? ?? ?? ?? 59 8B - 44 24 ?? 33 C9 66 89 08 8D 44 24 ?? 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? - ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B - 8B E5 5D C3 + $remote_server_connection_1_1 = { + E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? + ?? ?? ?? 8B 53 ?? 8D 4B ?? 83 FA ?? 0F 43 4B ?? 8D 41 ?? 89 85 ?? ?? ?? ?? 90 8A 01 + 41 84 C0 75 ?? 2B 8D ?? ?? ?? ?? 8D 43 ?? 6A ?? 83 FA ?? 51 0F 43 43 ?? 50 56 FF 15 + ?? ?? ?? ?? 85 C0 79 ?? FF D7 50 51 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? 8B C8 E8 ?? ?? ?? ?? EB ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? + 83 F8 ?? 0F 85 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? BE ?? ?? ?? ?? 8B 43 ?? 83 F8 ?? 72 ?? 8B 4B ?? 40 3D ?? ?? ?? ?? 72 + ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 + ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 8B 4D + ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D 8B E3 5B C3 } - $crypt_files_v5_0_2 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B D9 89 55 ?? 33 FF 89 5D ?? 21 7D ?? B9 ?? ?? - ?? ?? 89 7D ?? E8 ?? ?? ?? ?? 8B F0 33 C0 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 50 68 ?? - ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 75 ?? 33 C0 - 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB - ?? 0F 84 ?? ?? ?? ?? 8B 7D ?? FF 77 ?? FF 77 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 6A - ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8D 45 ?? 50 68 - ?? ?? ?? ?? 56 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 81 BE ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? - 81 BE ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? FF 77 ?? FF 77 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? - ?? 53 FF 15 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? 6A ?? 6A ?? 0F 57 - C0 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? FF 75 ?? 83 65 ?? ?? 8D 55 - ?? 56 8D 4D ?? E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A ?? 58 C6 45 ?? ?? 48 75 ?? 51 68 - ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 8E ?? ?? - ?? ?? 83 65 ?? ?? 83 65 ?? ?? 41 89 45 ?? 8B 45 ?? 89 45 ?? E8 ?? ?? ?? ?? 8B 8E ?? - ?? ?? ?? 83 C1 ?? 89 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 33 FF 6A ?? 8D 45 ?? 50 FF B6 ?? - ?? ?? ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 85 C0 0F 84 - ?? ?? ?? ?? 3B 86 ?? ?? ?? ?? 8B 55 ?? 6A ?? 59 0F 42 F9 83 7D ?? ?? 8D 8D ?? ?? ?? - ?? 0F 45 7D ?? 01 86 ?? ?? ?? ?? 89 7D ?? 83 96 ?? ?? ?? ?? ?? 8B 45 ?? 50 FF 75 ?? - 89 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 59 59 33 C9 F7 D8 41 99 51 6A ?? 52 50 53 FF 15 ?? - ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 75 - ?? 8B 7D ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 57 56 53 FF 15 ?? ?? ?? ?? 85 - C0 74 ?? 8B 75 ?? 8B 7D ?? 33 C0 40 01 86 ?? ?? ?? ?? 83 96 ?? ?? ?? ?? ?? EB ?? 33 - C0 8D 78 ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 6A ?? 6A ?? 0F 57 C0 66 0F 13 - 45 ?? FF 75 ?? FF 75 ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 56 53 - FF 15 ?? ?? ?? ?? 8B 4D ?? 8B F8 89 7D ?? E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B - CE E8 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? - FF 75 ?? 83 65 ?? ?? 83 65 ?? ?? 8B 35 ?? ?? ?? ?? FF D6 8D 0C 45 ?? ?? ?? ?? E8 ?? - ?? ?? ?? FF 75 ?? 8B F8 33 C0 40 83 67 ?? ?? 88 07 FF D6 FF 75 ?? 03 C0 89 47 ?? FF - D6 8D 04 45 ?? ?? ?? ?? 50 FF 75 ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF 75 - ?? FF D6 8D 04 45 ?? ?? ?? ?? 50 57 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 89 01 - 8B CF E8 ?? ?? ?? ?? 8B 7D ?? 8B 45 ?? FF 70 ?? FF 70 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? - ?? ?? 53 FF 15 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 + $encryption_loop_1_0 = { + 66 8B 01 66 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EE ?? 75 ?? C6 85 ?? ?? ?? ?? ?? E9 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 8B 40 ?? 03 C8 8B 51 ?? 83 CA ?? + 8B C2 83 C8 ?? 83 79 ?? ?? 0F 45 C2 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 32 C0 0F 85 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 C7 45 ?? ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? 83 CB ?? 68 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? 8B D7 8B 9D ?? ?? ?? ?? 83 CB ?? 83 7F ?? ?? 89 9D ?? ?? ?? ?? 89 + 9D ?? ?? ?? ?? 72 ?? 8B 17 83 78 ?? ?? 8B C8 72 ?? 8B 08 8B 70 ?? 3B 77 ?? 75 ?? 85 + F6 0F 84 } - $remote_connection_v5_0_2 = { - 55 8B EC 83 EC ?? 53 8B 1D ?? ?? ?? ?? 56 8B F1 57 83 7E ?? ?? 74 ?? FF 76 ?? FF D3 - 8B CE E8 ?? ?? ?? ?? 33 FF 57 57 6A ?? 57 57 FF 75 ?? FF 75 ?? FF 76 ?? FF 15 ?? ?? - ?? ?? 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 75 ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? - 83 C4 ?? B8 ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 44 C8 57 51 57 57 68 - ?? ?? ?? ?? 56 8B 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? FF - 75 ?? FF 75 ?? FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? ?? ?? 33 C9 41 85 C0 8B 45 ?? 0F 45 - F9 50 FF D3 56 FF D3 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C2 + $encryption_loop_1_1 = { + 66 8B 01 66 3B 02 75 ?? 83 C1 ?? 83 C2 ?? 83 EE ?? 75 ?? C6 85 ?? ?? ?? ?? ?? EB ?? + 32 C0 74 ?? C6 85 ?? ?? ?? ?? ?? EB ?? C6 85 ?? ?? ?? ?? ?? F6 C3 ?? 74 ?? 83 E3 ?? + 8D 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 C3 ?? 74 ?? 83 E3 ?? 8D 8D ?? + ?? ?? ?? 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 C3 ?? 74 ?? 83 E3 ?? 8D 8D ?? ?? ?? ?? + 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 C3 ?? 74 ?? 83 E3 ?? 8D 8D ?? ?? ?? ?? 89 9D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 32 C0 75 ?? 83 E3 ?? 8D 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 32 C0 C7 45 ?? ?? ?? ?? ?? 75 ?? 83 E3 ?? 8D 8D ?? ?? ?? ?? 89 9D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 51 FF B5 ?? ?? ?? ?? BA + ?? ?? ?? ?? C6 45 ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 95 } - $crypt_files_v5_0_3 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B F9 89 55 ?? 33 DB B9 ?? ?? ?? ?? 89 5D ?? E8 - ?? ?? ?? ?? 8B F0 89 75 ?? 85 F6 75 ?? 33 C0 E9 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 6A ?? - 53 53 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 6A ?? 53 - 6A ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 53 8D 45 ?? 50 68 ?? ?? ?? ?? - 56 57 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 81 BE ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 81 BE ?? ?? - ?? ?? ?? ?? ?? ?? 75 ?? 8B 45 ?? FF 70 ?? FF 70 ?? 53 53 57 FF 15 ?? ?? ?? ?? 57 FF - 15 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 53 53 0F 57 C0 66 0F 13 45 ?? FF - 75 ?? FF 75 ?? 57 FF 15 ?? ?? ?? ?? FF 75 ?? 8D 55 ?? 89 5D ?? 56 8D 4D ?? E8 ?? ?? - ?? ?? 59 59 85 C0 74 ?? 6A ?? 58 88 5D ?? 48 75 ?? 51 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 8E ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 41 - 8B 45 ?? 89 85 ?? ?? ?? ?? 89 5D ?? 89 5D ?? E8 ?? ?? ?? ?? 8B 8E ?? ?? ?? ?? 83 C1 - ?? 89 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 89 5D ?? 53 8D 45 ?? 50 FF B6 ?? ?? ?? ?? FF 75 - ?? 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 85 C9 0F 84 ?? ?? ?? ?? 3B - 8E ?? ?? ?? ?? 8B 45 ?? 6A ?? 5A 0F 42 C2 39 5D ?? 8B 55 ?? 0F 45 45 ?? 01 8E ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? 89 45 ?? 11 9E ?? ?? ?? ?? 8B 45 ?? 8B 75 ?? 50 56 89 45 ?? - E8 ?? ?? ?? ?? 8B 45 ?? 59 59 33 C9 F7 D8 41 99 51 53 52 50 57 FF 15 ?? ?? ?? ?? 8B - C3 89 5D ?? 83 F8 ?? 7D ?? 53 8D 45 ?? 50 FF 75 ?? 56 57 FF 15 ?? ?? ?? ?? 85 C0 75 - ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 45 ?? 40 89 45 ?? EB ?? 8B 75 ?? 33 C0 8B 4D ?? 40 01 - 86 ?? ?? ?? ?? 11 9E ?? ?? ?? ?? EB ?? 33 C0 8D 48 ?? 89 4D ?? 85 C9 0F 84 ?? ?? ?? - ?? 39 5D ?? 74 ?? 6A ?? 53 0F 57 C0 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 57 FF 15 ?? ?? - ?? ?? 53 8D 45 ?? 50 68 ?? ?? ?? ?? 56 57 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B D8 E8 ?? ?? - ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 83 FF ?? 74 ?? 8B 45 ?? 57 83 08 - ?? FF 15 ?? ?? ?? ?? 8B C3 5F 5E 5B 8B E5 5D C3 + $encryption_loop_1_2 = { + 57 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? + ?? ?? ?? C3 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 FF B5 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E + 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 51 FF B5 ?? ?? ?? ?? BA ?? ?? ?? ?? 51 + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 69 0F ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? + ?? ?? BA ?? ?? ?? ?? 03 48 ?? 8D 85 ?? ?? ?? ?? 50 51 E8 ?? ?? ?? ?? 85 C0 74 ?? BA + ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 } - $remote_connection_v5_0_3 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 68 ?? ?? ?? ?? 33 DB 8D 85 ?? ?? ?? ?? 8B F1 53 - 50 89 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B FB 0F B7 04 5E 66 85 C0 74 ?? 83 F8 ?? 75 ?? - 83 C3 ?? 56 89 5D ?? FF 15 ?? ?? ?? ?? 3B D8 73 ?? 8D 14 1B 0F B7 04 32 EB ?? 66 83 - F8 ?? 74 ?? 43 0F B7 04 5E 66 85 C0 75 ?? EB ?? 8B CB 2B 4D ?? 74 ?? 03 F2 8D BD ?? - ?? ?? ?? D1 E9 F3 A5 13 C9 66 F3 A5 8B 75 ?? 8D 43 ?? 8D 04 46 50 8D 85 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 33 FF 47 43 85 FF 74 ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 15 ?? ?? ?? - ?? 8D 7D ?? 6A ?? 59 BE ?? ?? ?? ?? F3 A5 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 85 - FF 74 ?? 51 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 83 EC ?? 57 FF 15 ?? ?? ?? - ?? 50 57 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B CF 8B - F0 E8 ?? ?? ?? ?? EB ?? 33 F6 83 7D ?? ?? 74 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 8B C6 - 5E 5B 8B E5 5D C3 + $encryption_loop_1_3 = { + 69 37 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 03 70 ?? E8 ?? ?? ?? ?? 8B 95 ?? + ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 81 CB ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 78 ?? 8D + 4A ?? 89 08 8D 4A ?? 89 48 ?? 8D 4A ?? 89 48 ?? 8D 4A ?? 89 48 ?? 8D 4A ?? 89 48 ?? + B9 ?? ?? ?? ?? F3 A5 66 A5 C7 80 ?? ?? ?? ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? + ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + C6 45 ?? ?? 8B B5 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 56 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? ?? ?? ?? 83 C4 + ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B BD ?? + ?? ?? ?? 8B 8D ?? ?? ?? ?? FF 07 8B 07 89 41 ?? 69 17 ?? ?? ?? ?? 8B 41 ?? 80 A4 02 + ?? ?? ?? ?? ?? 8B 01 48 39 07 75 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 83 C4 ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F + 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E8 + ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8A 11 8B + C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? ?? ?? C3 } condition: - uint16(0)==0x5A4D and (($search_antivirus_processes and $find_files and $crypt_files and $remote_connection) or ($find_files_v2 and $crypt_files_v2 and $search_antivirus_processes_v2 and $remote_connection_v2) or ($search_antivirus_processes_v2 and $find_files_v2_1 and $crypt_files_v2_1 and $remote_connection_v2_1) or ($search_antivirus_processes_v4_1_2 and $find_files_v4_1_2 and $crypt_files_v4_1_2 and $remote_connection_v4_1_2 and $url_parameters_setup_v4_1_2) or ($search_antivirus_processes_v4 and $find_files_v4 and $crypt_files_v4 and $url_parameters_setup_v4) or ($search_antivirus_processes_v2 and $find_files_v2_1 and $remote_connection_v2_1 and $crypt_files_v3) or ($search_antivirus_processes_v5 and $find_files_v5 and $crypt_files_v5 and $remote_connection_v5 and $url_parameters_setup_v5) or ($search_antivirus_processes_v5_0_1 and $find_files_v5_0_1 and $crypt_files_v5_0_1 and $url_parameters_setup_v5_0_1 and $remote_connection_v5_0_1) or ($search_antivirus_processes_v5_0_2 and $find_files_v5_0_2 and $crypt_files_v5_0_2 and $set_url_parameters_v5_0_2 and $remote_connection_v5_0_2) or ($search_antivirus_processes_v5_0_2 and $find_files_v5_0_2 and $crypt_files_v5_0_3 and $set_url_parameters_v5_0_3 and $remote_connection_v5_0_3)) + uint16(0)==0x5A4D and ($remote_server_connection_1_0 and $remote_server_connection_1_1 and ( all of ($encryption_loop_1_*))) } -rule REVERSINGLABS_Win32_Ransomware_Sage : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win32_Ransomware_Blackmoon : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects Sage ransomware." + description = "Yara rule that detects BlackMoon ransomware." author = "ReversingLabs" - id = "81f4c666-93f9-51bb-8dda-431ef7a81b74" - date = "2020-07-15" - modified = "2020-07-15" + id = "95ebb6c4-b0c9-5f9a-8424-a2f4d33953eb" + date = "2020-11-11" + modified = "2020-11-11" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Sage.yara#L1-L77" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "69079b7176050096cdbaaaff30dd0359366b3a6a74e8bc17db348794388f71ba" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.BlackMoon.yara#L1-L70" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "428409096a8637978bf2a1efb3238e4ba87715a909693b0cd26c0f689d567a09" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -46220,70 +46615,66 @@ rule REVERSINGLABS_Win32_Ransomware_Sage : TC_DETECTION MALICIOUS MALWARE FILE sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "Sage" + tc_detection_name = "BlackMoon" tc_detection_factor = 5 importance = 25 strings: - $remote_connection = { - 83 EC ?? 8B 44 24 ?? 53 55 56 57 8B 7C 24 ?? 8B 77 ?? 50 E8 ?? ?? ?? ?? 8B 4C 24 ?? - 8B D8 51 89 5C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 89 44 24 - ?? C7 44 24 ?? ?? ?? ?? ?? 89 77 ?? FF 15 ?? ?? ?? ?? 8B E8 89 6C 24 ?? 85 ED 0F 84 - ?? ?? ?? ?? 8B 74 24 ?? 6A ?? 56 53 55 FF 15 ?? ?? ?? ?? 8B D8 89 5C 24 ?? 85 DB 0F - 84 ?? ?? ?? ?? 8B 4C 24 ?? 33 C0 BA ?? ?? ?? ?? 66 3B F2 0F 95 C0 48 25 ?? ?? ?? ?? - 50 6A ?? 6A ?? 6A ?? 51 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? - ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 1D ?? ?? ?? ?? 8B 2D ?? ?? ?? ?? 8B FF - 8D 54 24 ?? 52 56 FF D3 8D 44 24 ?? 50 8B 44 24 ?? 50 50 57 E8 ?? ?? ?? ?? 83 C4 ?? - 50 56 FF D5 85 C0 0F 84 ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 6A ?? 8D 4C 24 ?? 51 8D 54 - 24 ?? 52 6A ?? 68 ?? ?? ?? ?? 56 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8B 5C 24 ?? 8B 6C 24 ?? 56 FF 15 ?? ?? ?? ?? - 53 FF 15 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 8B 5C 24 ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? - 83 C4 ?? 8B 44 24 ?? 5F 5E 5D 5B 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 04 24 83 - C4 ?? C3 57 E8 ?? ?? ?? ?? 83 C4 + $find_files = { + 81 EC ?? ?? ?? ?? 53 8B 9C 24 ?? ?? ?? ?? 55 56 8B 33 57 8B BC 24 ?? ?? ?? ?? 33 ED + 85 FF 74 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 76 ?? 85 F6 74 ?? 83 FE ?? 74 ?? 56 FF + 15 ?? ?? ?? ?? 8D 44 24 ?? 50 57 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 89 33 74 ?? 8B 84 + 24 ?? ?? ?? ?? 85 C0 74 ?? 8B 4C 24 ?? 83 E1 ?? 80 F9 ?? 74 ?? EB ?? 8B 94 24 ?? ?? + ?? ?? 8B 44 24 ?? 85 C2 74 ?? BD ?? ?? ?? ?? 85 F6 74 ?? 83 FE ?? 74 ?? 85 ED 75 ?? + 8B 84 24 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 85 C0 8D 44 24 ?? 50 56 74 ?? FF D7 85 C0 74 + ?? 8B 4C 24 ?? 83 E1 ?? 80 F9 ?? 75 ?? 8D 54 24 ?? 52 56 FF D7 85 C0 75 ?? 5F 5E 5D + 33 C0 5B 81 C4 ?? ?? ?? ?? C3 FF D7 85 C0 74 ?? 8B 9C 24 ?? ?? ?? ?? 85 5C 24 ?? 75 + ?? 8D 4C 24 ?? 51 56 FF D7 85 C0 75 ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 8D 54 24 ?? + 52 E8 ?? ?? ?? ?? 40 50 E8 ?? ?? ?? ?? 8B D0 8D 7C 24 ?? 83 C9 ?? 33 C0 83 C4 ?? F2 + AE F7 D1 2B F9 8B C1 8B F7 8B FA C1 E9 ?? F3 A5 8B C8 8B C2 83 E1 ?? F3 A4 5F 5E 5D + 5B 81 C4 ?? ?? ?? ?? C3 } - $encrypt_files = { - 83 EC ?? 53 8B 1D ?? ?? ?? ?? 55 8B 6C 24 ?? 56 57 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 - ?? ?? ?? ?? 8D 7D ?? 57 FF D3 8B F0 83 FE ?? 74 ?? 8D 44 24 ?? 50 56 FF 15 ?? ?? ?? - ?? 89 44 24 ?? 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? 8B - 4C 24 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 51 FF D3 8B D8 83 FB ?? 75 ?? - 56 FF 15 ?? ?? ?? ?? 5F 5E 5D B8 ?? ?? ?? ?? 5B 83 C4 ?? C3 8B 54 24 ?? 6A ?? 52 57 - 56 53 E8 ?? ?? ?? ?? 83 C4 ?? 56 8B 35 ?? ?? ?? ?? 8B E8 FF D6 53 FF D6 85 ED 79 ?? - 8B 44 24 ?? 50 FF 15 ?? ?? ?? ?? 5F 5E 8B C5 5D 5B 83 C4 ?? C3 57 E8 ?? ?? ?? ?? 8B - F0 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 8B D8 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? - 6A ?? 53 51 EB ?? 8B 4C 24 ?? BA ?? ?? ?? ?? 3B 55 ?? 1B C0 83 C0 ?? 50 51 57 56 56 - E8 ?? ?? ?? ?? 83 C4 ?? 56 8B D8 FF 15 ?? ?? ?? ?? 85 DB 79 ?? 5F 5E 5D 8B C3 5B 83 - C4 ?? C3 57 E8 ?? ?? ?? ?? 8B F0 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8B - D8 53 57 FF 15 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5D 33 - C0 5B 83 C4 ?? C3 + $encrypt_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? + 6A ?? 8B 5D ?? 8B 03 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 5D ?? 8B 03 85 C0 75 ?? + B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? DB + 45 ?? DD 5D ?? DD 45 ?? DB 45 ?? DD 5D ?? DC 65 ?? DD 5D ?? DD 45 ?? E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 6A ?? 50 68 ?? ?? ?? ?? 6A ?? 8B 5D ?? 8B 03 85 C0 75 ?? B8 ?? ?? ?? + ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 45 ?? 50 8B + 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 8B 5D + ?? 8B 03 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 } - $find_files = { - 53 55 8B 2D ?? ?? ?? ?? 56 57 33 FF 57 57 FF D5 8B F0 85 F6 74 ?? 85 FF 74 ?? 57 E8 - ?? ?? ?? ?? 83 C4 ?? 8D 44 36 ?? 50 6A ?? 8B DE E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 57 56 - FF D5 8B F0 3B DE 72 ?? 66 83 3F ?? 8B DF 0F 84 ?? ?? ?? ?? 8B 6C 24 ?? 53 8B FB FF - 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 8D 5C 43 ?? FF D6 85 C0 74 ?? 68 - ?? ?? ?? ?? 57 FF D6 85 C0 74 ?? 57 FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 D3 E2 F6 - C2 ?? 74 ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 57 8B F0 E8 ?? ?? ?? ?? 6A ?? 89 06 8D 46 ?? - 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4E ?? 51 C7 46 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 8D 56 ?? 52 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 55 89 46 ?? E8 ?? ?? ?? - ?? 83 C4 ?? 66 83 3B ?? 0F 85 ?? ?? ?? ?? 5F 5E 5D 5B C3 + $encrypt_files_p2 = { + 83 C4 ?? 89 45 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 + 45 ?? 68 ?? ?? ?? ?? 6A ?? 8B 5D ?? 8B 03 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? + ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? + ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? + 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? 68 ?? ?? ?? + ?? 8B 5D ?? FF 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? ?? ?? 6A + ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? + B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 + DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? + 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B E5 5D C2 } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($remote_connection) + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) } -rule REVERSINGLABS_Win32_Ransomware_Dogecrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule REVERSINGLABS_Win64_Ransomware_Rook : TC_DETECTION MALICIOUS MALWARE FILE { meta: - description = "Yara rule that detects DogeCrypt ransomware." + description = "Yara rule that detects Rook ransomware." author = "ReversingLabs" - id = "e0ca22a5-70bb-5d2c-bce4-bac49c2a81d2" - date = "2021-04-28" - modified = "2021-04-28" + id = "60bbfd57-18bb-58b3-9abc-ab30943bbddd" + date = "2022-01-17" + modified = "2022-01-17" reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.DogeCrypt.yara#L1-L114" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "1c19862884cf1e59d12c84f5ff6f799a4087ddc8bd887e0d2ce7da053642b851" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Rook.yara#L1-L122" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "dc8b37e55b634de52855dd851dbaaf3e690adfb2e875d0e0c9ef5f4846c6ff30" score = 75 quality = 90 tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" @@ -46291,9594 +46682,13425 @@ rule REVERSINGLABS_Win32_Ransomware_Dogecrypt : TC_DETECTION MALICIOUS MALWARE F sharing = "TLP:WHITE" category = "MALWARE" tc_detection_type = "Ransomware" - tc_detection_name = "DogeCrypt" + tc_detection_name = "Rook" tc_detection_factor = 5 importance = 25 strings: - $encrypt_files_DogeCrypt_p1 = { - 50 E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? - ?? BA ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 2B C6 89 B5 ?? ?? ?? ?? 3B C8 77 ?? 83 BD ?? ?? ?? ?? - ?? 8D 3C 31 8D 04 09 89 BD ?? ?? ?? ?? 50 8B 85 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 0F 43 - B5 ?? ?? ?? ?? 52 8D 04 46 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 04 7E EB ?? 51 52 - C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? - ?? 8D 45 ?? 8B 35 ?? ?? ?? ?? 0F 43 45 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 - ?? ?? ?? ?? 50 FF D6 8B F8 83 FF ?? 74 ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A - ?? 0F 43 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF D6 8B - F0 83 FE ?? 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B - 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? - 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? - ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? - ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? - ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? - ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? - ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? - ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? - ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 + $find_files = { + 48 2B D6 48 8D 4C 24 ?? 48 FF C2 41 B8 ?? ?? ?? ?? F6 D8 4D 1B FF 4C 23 FA 33 D2 E8 + ?? ?? ?? ?? 45 33 C9 89 7C 24 ?? 4C 8D 44 24 ?? 48 89 7C 24 ?? 33 D2 48 8B CE FF 15 + ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 75 ?? 4D 8B CE 45 33 C0 33 D2 48 8B CE E8 ?? ?? ?? + ?? 8B F8 48 83 FB ?? 74 ?? 48 8B CB FF 15 ?? ?? ?? ?? 8B C7 48 8B 8C 24 ?? ?? ?? ?? + 48 33 CC E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5E 5F + 5E 5D C3 49 8B 6E ?? 49 2B 2E 48 C1 FD ?? 80 7C 24 ?? ?? 75 ?? 8A 44 24 ?? 84 C0 74 + ?? 3C ?? 75 ?? 40 38 7C 24 ?? 74 ?? 4D 8B CE 48 8D 4C 24 ?? 4D 8B C7 48 8B D6 E8 ?? + ?? ?? ?? 85 C0 75 ?? 48 8D 54 24 ?? 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 75 ?? 49 8B 06 + 49 8B 56 ?? 48 2B D0 48 C1 FA ?? 48 3B EA 0F 84 ?? ?? ?? ?? 48 2B D5 48 8D 0C E8 4C + 8D 0D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 } - $encrypt_files_DogeCrypt_p2 = { - C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 83 - FA ?? 0F 82 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? - ?? 0F 82 ?? ?? ?? ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? E9 - ?? ?? ?? ?? 90 6A ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF - 15 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? BA ?? ?? ?? ?? 81 F9 ?? ?? ?? ?? 0F 42 DA 85 C0 74 - ?? 85 C9 74 ?? 51 8D 85 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? - 53 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? EB ?? 56 8B 35 ?? ?? ?? ?? FF D6 57 - FF D6 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 52 51 E8 - ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 33 C0 66 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? - ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 - C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 - 5D C3 + $encrypt_files_p1 = { + 40 55 53 56 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? F2 0F 10 05 ?? ?? ?? ?? 0F + B6 05 ?? ?? ?? ?? F2 0F 11 44 24 ?? 88 44 24 ?? E8 ?? ?? ?? ?? 33 D2 48 8D 0D ?? ?? + ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 83 CE ?? 48 8D 4C 24 ?? 89 35 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 48 63 C8 4C 8D 4C 24 ?? 48 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8D 4C 24 + ?? FF 15 ?? ?? ?? ?? 48 63 C8 4C 8D 4C 24 ?? 48 89 4C 24 ?? E8 ?? ?? ?? ?? 0F 57 C0 + 0F 57 C9 F3 0F 7F 05 ?? ?? ?? ?? F3 0F 7F 0D ?? ?? ?? ?? F3 0F 7F 05 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 48 85 C0 48 89 05 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? 48 0F 44 0D ?? ?? ?? + ?? 48 89 0D ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF C0 48 8D 15 ?? ?? + ?? ?? 4C 63 C0 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 8D 15 ?? + ?? ?? ?? 48 89 05 ?? ?? ?? ?? 33 DB 48 8B 05 ?? ?? ?? ?? 45 33 C9 48 89 05 ?? ?? ?? + ?? 45 33 C0 48 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 44 24 ?? 48 C7 } - $find_files_DogeCrypt = { - 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 - F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? ?? - ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? FF - 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 5D ?? 8B - CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 EB ?? 8B - 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 FF - 57 57 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 - C5 89 45 ?? 8B 4D ?? 53 8B 5D ?? 57 8B 7D ?? 89 9D ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 - ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8A 11 80 FA - ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 53 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 DB - 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8A C3 80 FA ?? 75 ?? B0 ?? 0F B6 C0 2B CF 41 F7 D8 56 - 1B C0 23 C1 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? - 83 C4 ?? 8D 85 ?? ?? ?? ?? 53 53 53 50 53 57 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? - ?? 83 FE ?? 75 ?? 50 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 83 FE ?? 74 ?? 56 FF 15 - ?? ?? ?? ?? 8B C3 5E 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 - C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? - 80 F9 ?? 75 ?? 38 9D ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 - 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 + $encrypt_files_p2 = { + C1 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 5C 24 ?? C7 44 24 ?? ?? ?? + ?? ?? 89 5C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 + 8D 85 ?? ?? ?? ?? 4C 89 A4 24 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 44 24 ?? 4C 8D + 25 ?? ?? ?? ?? 4C 89 AC 24 ?? ?? ?? ?? 45 33 C9 45 33 C0 4C 89 64 24 ?? 4C 89 BC 24 + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 4C 8D 2D ?? ?? ?? ?? 83 + F8 ?? 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 89 5C 24 ?? + E8 ?? ?? ?? ?? 85 C0 78 ?? 4C 63 C8 4C 8D 85 ?? ?? ?? ?? 48 8D 44 24 ?? 4D 2B C1 48 + 89 44 24 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? 4C 89 64 24 ?? E8 ?? ?? ?? ?? + 49 8B CD FF 15 ?? ?? ?? ?? 44 8B C0 89 05 ?? ?? ?? ?? B8 ?? ?? ?? ?? 41 F7 E8 C1 FA + ?? 8B CA C1 E9 ?? 03 D1 69 CA ?? ?? ?? ?? 44 3B C1 74 ?? FF C2 4C 8D 3D ?? ?? ?? ?? + 85 D2 0F 8E ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? 49 8B DD 4C 89 B4 24 ?? ?? ?? ?? 49 } - $decrypt_DesucryptKeyContainer_DogeCrypt = { - 68 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 8D 55 ?? 83 7D ?? ?? 8B 5D ?? 8B 35 ?? ?? ?? ?? 0F 43 D3 A1 ?? ?? ?? ?? 8B - 4D ?? 2B C6 89 75 ?? 3B C8 77 ?? 83 3D ?? ?? ?? ?? ?? 8D 3C 31 8D 04 09 89 3D ?? ?? - ?? ?? 50 8B 45 ?? BE ?? ?? ?? ?? 0F 43 35 ?? ?? ?? ?? 52 8D 04 46 50 E8 ?? ?? ?? ?? - 83 C4 ?? 33 C0 66 89 04 7E EB ?? 51 52 C6 45 ?? ?? FF 75 ?? 51 B9 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 5D ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8D 0C 45 ?? ?? ?? ?? - 8B C3 81 F9 ?? ?? ?? ?? 72 ?? 8B 5B ?? 83 C1 ?? 2B C3 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? - ?? ?? 51 53 E8 ?? ?? ?? ?? 83 C4 ?? 83 3D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 6A ?? 0F 43 - 05 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 6A ?? 68 ?? ?? - ?? ?? 56 FF D3 83 F8 ?? 0F 85 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 8D 45 ?? 6A ?? - 50 C6 07 ?? FF 35 ?? ?? ?? ?? 57 56 FF D3 83 F8 ?? 75 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? - ?? ?? 57 FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? BA ?? ?? ?? ?? B9 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? - ?? ?? EB ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? - ?? ?? 8B E5 5D C3 E8 ?? ?? ?? ?? E8 + $encrypt_files_p3 = { + 8B FF 44 8B F2 0F 1F 00 48 8B 0D ?? ?? ?? ?? 8B 91 ?? ?? ?? ?? 85 D2 74 ?? 83 FA ?? + 75 ?? 48 89 7C 24 ?? 4C 8D 05 ?? ?? ?? ?? 48 89 5C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 C7 + 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 48 89 7C 24 ?? 4C 8D 05 ?? ?? ?? ?? 48 89 + 5C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 81 C7 ?? + ?? ?? ?? 48 81 C3 ?? ?? ?? ?? 49 83 EE ?? 75 ?? 4C 8B B4 24 ?? ?? ?? ?? 33 DB 48 8B + BC 24 ?? ?? ?? ?? 66 0F 1F 44 00 ?? 48 FF C6 41 80 3C 34 ?? 75 ?? 48 8B 8D ?? ?? ?? + ?? 48 8D 15 ?? ?? ?? ?? 89 74 24 ?? 41 B9 ?? ?? ?? ?? 45 33 C0 4C 89 64 24 ?? FF 15 + ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? 45 33 C0 4C 89 7C 24 ?? FF 15 ?? ?? ?? ?? EB ?? 48 8B 8D ?? ?? ?? ?? 48 + 8D 85 ?? ?? ?? ?? 48 89 44 24 ?? 4C 8D 3D ?? ?? ?? ?? 45 33 C9 4C 89 7C 24 ?? 45 33 + C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 49 8B CC FF + 15 ?? ?? ?? ?? 49 8B D4 48 8D 0D ?? ?? ?? ?? FF C0 4C 63 C0 E8 ?? ?? ?? ?? 48 8B 05 + ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 89 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 05 ?? ?? + ?? ?? 4C 8B BC 24 ?? ?? ?? ?? 4C 8B A4 24 ?? ?? ?? ?? 48 85 C0 74 ?? 48 8B 0D ?? ?? + ?? ?? FF 50 ?? 48 8B 05 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? 33 D2 44 8D 42 ?? FF D0 48 + 8B 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 48 63 85 ?? ?? ?? ?? 48 3D ?? + ?? ?? ?? 73 ?? 0F 1F 00 48 63 85 ?? ?? ?? ?? 42 C6 04 28 ?? FF 85 ?? ?? ?? ?? 48 63 + 85 ?? ?? ?? ?? 48 3D ?? ?? ?? ?? 72 ?? 4C 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? + 5E 5B 5D C3 + } + $enum_procs = { + 40 56 48 81 EC ?? ?? ?? ?? 33 D2 8D 4A ?? FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? C7 44 24 + ?? ?? ?? ?? ?? 48 8B C8 48 8B F0 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 89 9C + 24 ?? ?? ?? ?? 48 89 AC 24 ?? ?? ?? ?? 48 8D 2D ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? + 0F 1F 40 ?? 0F 1F 84 00 ?? ?? ?? ?? 33 DB 48 8B FD 66 66 66 0F 1F 84 00 ?? ?? 00 00 + 48 8B 0F 48 8D 54 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? FF C3 48 83 C7 ?? 83 FB ?? 72 + ?? EB ?? 44 8B 44 24 ?? 33 D2 8D 4A ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 85 C0 74 ?? BA + ?? ?? ?? ?? 48 8B C8 FF 15 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 48 + 8B CE FF 15 ?? ?? ?? ?? 85 C0 75 ?? 48 8B BC 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? + 48 8B 9C 24 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5E C3 + } + $enum_shares = { + 48 83 EC ?? 33 D2 C7 44 24 ?? ?? ?? ?? ?? 48 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 4C + 8B C9 48 89 44 24 ?? 8D 4A ?? 44 8D 42 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 48 89 5C 24 ?? 8B 5C 24 ?? 48 89 7C 24 ?? 66 66 0F 1F 84 00 ?? ?? 00 00 48 8B 0D ?? + ?? ?? ?? 4C 8D 43 ?? BA ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B F8 48 85 C0 74 ?? 48 8B + 4C 24 ?? 4C 8D 4C 24 ?? 4C 8B C0 48 8D 54 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 66 0F + 1F 44 00 ?? 33 DB 39 5C 24 ?? 76 ?? 0F 1F 84 00 ?? ?? ?? ?? 48 8D 0C 5B 48 C1 E1 ?? + 48 03 CF F6 41 ?? ?? 74 ?? E8 ?? ?? ?? ?? EB ?? 48 8B 49 ?? E8 ?? ?? ?? ?? FF C3 3B + 5C 24 ?? 72 ?? 48 8B 4C 24 ?? 4C 8D 4C 24 ?? 4C 8B C7 48 8D 54 24 ?? FF 15 ?? ?? ?? + ?? 85 C0 74 ?? 48 8B 0D ?? ?? ?? ?? 4C 8B C7 33 D2 FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? + FF 15 ?? ?? ?? ?? 48 8B 7C 24 ?? 48 8B 5C 24 ?? 48 83 C4 ?? C3 + } + + condition: + uint16(0)==0x5A4D and ($enum_shares) and ($enum_procs) and ($find_files) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Fenixlocker : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects FenixLocker ransomware." + author = "ReversingLabs" + id = "4868ced4-885d-548c-993c-ae25ab188172" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.FenixLocker.yara#L1-L143" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "72712616df2c73c5c17696a7c5cb93f767910acf5f49cda27373fccfa29c5a4d" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "FenixLocker" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_1 = { + 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 68 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 8B F1 E8 ?? ?? ?? ?? 83 C4 + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 6A ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 8D 85 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? + E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5E 8B 4D ?? 33 CD E8 ?? ?? + ?? ?? 8B E5 5D C3 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 33 C0 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8D 85 ?? ?? ?? ?? 50 + FF B5 ?? ?? ?? ?? 6A ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? + ?? ?? 50 68 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 46 ?? 50 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 85 C0 0F 84 ?? ?? ?? ?? 57 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8B F8 + 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 83 7E ?? ?? 72 ?? 8B 36 FF B5 ?? ?? ?? ?? 56 57 E8 + ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 50 57 6A ?? 6A ?? 6A ?? FF + B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B + E5 5D C3 8B 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 01 8B C7 8B 4D ?? 5F 33 CD 5E E8 ?? + ?? ?? ?? 8B E5 5D C3 + } + $encrypt_files_2 = { + B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 + ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? + F6 85 ?? ?? ?? ?? ?? 8D 55 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B D0 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? + 8B F8 C6 45 ?? ?? 8B 4D ?? 8B 55 ?? 41 3B D1 77 ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 8B 55 + ?? 8B 4D ?? 4A 8B 45 ?? 23 CA 03 C1 89 4D ?? 8B 4D ?? 23 D0 83 3C 91 ?? 8D 34 95 ?? + ?? ?? ?? 75 ?? 6A ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 89 04 31 8B 4D ?? 8B 0C 31 85 + C9 74 ?? 57 E8 ?? ?? ?? ?? FF 45 ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 + 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B + C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 + C4 ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 + ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? + ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F + 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B BD ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 85 F6 0F 8E ?? ?? + ?? ?? 68 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? + ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? + 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? + ?? ?? ?? 8B 40 ?? F6 84 05 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? + ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? + 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F + 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 + E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? 6A ?? 8B 40 ?? 03 C8 8B 51 ?? 83 CA ?? 8B C2 83 C8 ?? 83 79 ?? + ?? 0F 45 C2 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? FF 15 ?? ?? ?? ?? 57 FF + 15 ?? ?? ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? + ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? B0 ?? 8B 4D ?? 64 89 0D ?? ?? ?? + ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $encrypt_files_3 = { + E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B D0 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 + ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? ?? + 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F + 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 83 FE ?? 0F + 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? 8A 11 3A 10 75 ?? 84 D2 74 ?? 8A 51 ?? 3A 50 ?? 75 ?? 83 C1 ?? + 83 C0 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? + 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? + ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? + 8D 4D ?? 0F 43 4D ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 7E ?? 83 7D ?? ?? 8D 4D ?? 8D + 45 ?? 0F 43 4D ?? 83 7D ?? ?? 51 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? + 46 EB ?? 85 F6 75 ?? 83 F8 ?? B8 ?? ?? ?? ?? 0F 45 F0 89 B5 ?? ?? ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 0F 82 ?? ?? ?? ?? 8B 4D ?? 40 3D ?? ?? ?? + ?? 72 ?? F6 C1 ?? 75 ?? 8B 41 ?? 3B C1 73 ?? 2B C8 83 F9 ?? 72 ?? 83 F9 ?? 77 ?? 8B + C8 51 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? E8 + } + $encrypt_files_4 = { + 8B BD ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? 85 F6 0F 8E ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 + ?? ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 + ?? 40 8D 8D ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8B 40 ?? + F6 84 05 ?? ?? ?? ?? ?? 75 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? + E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? 8B 40 ?? 03 C8 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 ?? 83 C8 ?? 6A ?? 50 E8 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D + 41 ?? 89 84 0D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 83 + 7D ?? ?? 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? FF 75 ?? + E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 + } + $encrypt_files_5 = { + FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? + ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 F8 ?? 72 ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? + ?? ?? B0 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B + E5 5D C3 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B D0 8D 4D ?? E8 ?? ?? ?? + ?? 83 C4 ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 83 F8 ?? 72 ?? 40 8D 8D ?? ?? ?? ?? 50 FF + B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C6 85 ?? ?? ?? ?? ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 4D ?? C7 + 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? + ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 8D 4D ?? 0F 43 4D ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 7E ?? 83 7D ?? ?? 8D 4D ?? 8D 45 ?? 0F 43 4D ?? 83 7D ?? ?? 51 0F 43 45 ?? + 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 46 89 B5 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? + 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 0F 82 ?? ?? ?? + ?? 40 8D 4D ?? 50 FF 75 ?? E8 ?? ?? ?? ?? E9 + } + + condition: + uint16(0)==0x5A4D and ($encrypt_files_1 and $encrypt_files_2 and $encrypt_files_3) or ($encrypt_files_1 and $encrypt_files_4 and $encrypt_files_5) +} +rule REVERSINGLABS_Win32_Ransomware_Gomer : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Gomer ransomware." + author = "ReversingLabs" + id = "b76ac856-2abe-531d-b093-461569b9afb7" + date = "2020-10-08" + modified = "2020-10-08" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Gomer.yara#L1-L106" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "a53d37fcb877a12a4969a6ea1aaa67fc4106c3fbdd80a4fd39ad5a66a9df47fc" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Gomer" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files_p1 = { + 8B FF 55 8B EC 51 8B 4D ?? 53 57 33 DB 8D 51 ?? 66 8B 01 83 C1 ?? 66 3B C3 75 ?? 8B + 7D ?? 2B CA D1 F9 83 C8 ?? 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 56 8D 5F ?? + 03 D9 6A ?? 53 E8 ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? + ?? 83 C4 ?? 85 C0 75 ?? FF 75 ?? 2B DF 8D 04 7E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 75 ?? 8B 4D ?? 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5F + 5B 8B E5 5D C3 33 C0 50 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? + ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 55 ?? 8B 4D ?? 53 8B 5D ?? 56 57 6A ?? 5E 6A ?? + 89 95 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 5F EB ?? 0F B7 01 66 3B 85 ?? ?? ?? + ?? 74 ?? 66 3B C6 74 ?? 66 3B C7 74 ?? 83 E9 ?? 3B CB 75 ?? 0F B7 31 66 3B F7 75 ?? + 8D 43 ?? 3B C8 74 ?? 52 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 6A ?? + 8B C6 33 FF 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 8B C7 + } + $find_files_p2 = { + EB ?? 33 C0 40 2B CB 0F B6 C0 D1 F9 41 F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 + 57 53 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? 8B 85 ?? ?? ?? ?? 50 57 57 53 E8 ?? ?? + ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD + 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 8D ?? ?? ?? ?? 6A ?? 8B 41 ?? 2B 01 C1 F8 ?? 89 85 + ?? ?? ?? ?? 58 66 39 85 ?? ?? ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 66 39 85 ?? ?? + ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 51 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 8B 8D + ?? ?? ?? ?? 85 C0 6A ?? 58 75 ?? 8B C1 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 + ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? + 83 C4 ?? E9 + } + $encrypt_files = { + 55 8B EC 51 8B 45 ?? 53 56 57 8B F9 8B 4F ?? 89 4D ?? 3B C1 77 ?? 8B DF 83 F9 ?? 72 + ?? 8B 1F 8D 34 00 89 47 ?? 56 FF 75 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 04 1E + 8B C7 5F 5E 5B 8B E5 5D C2 ?? ?? 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 8B F0 83 CE ?? 81 + FE ?? ?? ?? ?? 76 ?? BE ?? ?? ?? ?? EB ?? 8B D1 B8 ?? ?? ?? ?? D1 EA 2B C2 3B C8 76 + ?? BE ?? ?? ?? ?? EB ?? 8D 04 0A 3B F0 0F 42 F0 8D 46 ?? 8D 0C 00 3D ?? ?? ?? ?? 76 + ?? 83 C9 ?? EB ?? 81 F9 ?? ?? ?? ?? 72 ?? 8D 41 ?? 83 CA ?? 3B C1 0F 46 C2 50 E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8D 58 ?? 83 E3 ?? 89 43 ?? EB ?? 85 C9 74 ?? 51 E8 ?? + ?? ?? ?? 83 C4 ?? 8B D8 EB ?? 33 DB 8B 45 ?? 89 77 ?? 89 47 ?? 8D 34 00 56 FF 75 ?? + 53 E8 ?? ?? ?? ?? 33 C0 83 C4 ?? 66 89 04 1E 8B 45 ?? 83 F8 ?? 72 ?? 8D 0C 45 ?? ?? + ?? ?? 8B 07 81 F9 ?? ?? ?? ?? 72 ?? 8B 50 ?? 83 C1 ?? 2B C2 83 C0 ?? 83 F8 ?? 77 ?? + 8B C2 51 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 1F 8B C7 5F 5E 5B 8B E5 5D C2 ?? ?? E8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? CC CC CC CC CC B8 ?? ?? ?? ?? C3 + } + $enum_drives_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 + 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 4D ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? FF 15 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 6A ?? 33 C0 C7 + 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? C6 + 45 ?? ?? BF ?? ?? ?? ?? 8D 45 ?? 0F A3 38 0F 83 ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 8D + 47 ?? 0F 43 4D ?? 66 89 01 8D 45 ?? 83 7D ?? ?? 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 83 + F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 33 C9 C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? 66 89 4D ?? C6 45 ?? ?? 83 F8 ?? 75 ?? 6A ?? 68 ?? ?? ?? ?? EB ?? + 83 F8 ?? 75 ?? 6A ?? 68 ?? ?? ?? ?? EB ?? 83 F8 ?? 75 ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 55 ?? 56 8D 4D ?? E8 ?? ?? + ?? ?? 8B 4D ?? B8 ?? ?? ?? ?? 2B CE C6 45 ?? ?? F7 E9 83 C4 ?? C1 FA ?? 8B DA C1 EB + ?? 03 DA 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? + ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? + ?? ?? 83 C4 ?? FF 35 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 55 ?? 56 8D 4D ?? E8 ?? ?? ?? + ?? 8B 4D ?? B8 ?? ?? ?? ?? 2B CE 89 7D ?? F7 E9 83 C4 ?? 89 5D ?? C1 FA ?? 8D 4D + } + $enum_drives_p2 = { + 8B C2 C1 E8 ?? 03 C2 89 45 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? FF 75 + ?? 50 51 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8B 55 ?? 83 FA ?? 72 ?? 8B + 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 + C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 47 83 FF ?? 0F 8C ?? + ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 89 5D ?? C6 45 ?? ?? 8B 4D ?? 8B 31 + 3B F1 0F 84 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? FF 75 ?? 8B C8 C6 45 + ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F8 C6 45 ?? ?? 8B 4E ?? 89 4F ?? 8B 4E ?? 89 4F ?? 8D + 4F ?? 8B 46 ?? 89 47 ?? 8D 46 ?? 3B C8 74 ?? 83 78 ?? ?? 8B D0 72 ?? 8B 10 FF 70 ?? + 52 E8 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 57 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 + } + + condition: + uint16(0)==0x5A4D and ( all of ($enum_drives_p*)) and ( all of ($find_files_p*)) and ($encrypt_files) +} +rule REVERSINGLABS_Linux_Ransomware_Kraken : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Kraken ransomware." + author = "ReversingLabs" + id = "7c302c2e-6ffc-5f51-90f4-c4ebd6c1c28b" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Kraken.yara#L1-L151" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "4a3867aba4dbdce5d008331a3058f57b00db246975fc4d77b79ab49d5f0bbb15" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Kraken" + tc_detection_factor = 5 + importance = 25 + + strings: + $enum_volumes = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? 04 ?? 00 A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? 50 45 4C 00 C7 45 + FC 00 00 00 00 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? + ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 0F 1F 84 00 ?? ?? ?? ?? + 8A 06 84 C0 0F 84 ?? ?? ?? ?? 3C ?? 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B D6 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 EC ?? 8B D4 + C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? 83 7A ?? ?? 72 ?? 8B 02 EB ?? 8B C2 C6 00 + ?? 80 3E ?? 75 ?? 33 C9 EB ?? 8B CE 8D 79 ?? 8A 01 41 84 C0 75 ?? 2B CF 51 56 8B CA + E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B D6 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 C6 ?? E9 ?? ?? ?? ?? BA ?? + ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 83 EC ?? 8B CC C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 83 79 ?? + ?? 72 ?? 8B 01 EB ?? 8B C1 6A ?? 68 ?? ?? ?? ?? C6 00 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 + ?? ?? ?? ?? 8B E5 5D C3 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? B8 ?? ?? ?? ?? C3 + } + $enum_shares_p1 = { + 50 56 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 32 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F + 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 66 0F 1F 44 00 ?? FF 75 ?? 6A ?? FF + 15 ?? ?? ?? ?? 8B F0 8D 45 ?? 50 56 8D 45 ?? 89 75 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? + 85 C0 0F 85 ?? ?? ?? ?? 33 FF 0F 1F 40 ?? 3B 7D ?? 0F 83 ?? ?? ?? ?? 8B C7 C1 E0 ?? + 03 F0 F7 46 ?? ?? ?? ?? ?? 74 ?? 6A ?? E8 ?? ?? ?? ?? 0F 10 06 83 C4 ?? 8B C8 0F 11 + 00 0F 10 46 ?? 0F 11 40 ?? E8 ?? ?? ?? ?? 8B 75 ?? B3 ?? 47 EB ?? F7 46 ?? ?? ?? ?? + ?? 0F 84 ?? ?? ?? ?? 8B 56 ?? 85 D2 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C6 45 ?? ?? 80 3A ?? 75 ?? 33 C9 EB ?? 8B CA 8D 71 ?? 8A 01 41 84 C0 75 + ?? 2B CE 51 52 8D 4D ?? E8 ?? ?? ?? ?? 51 8D 55 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? 83 C4 ?? 8B F0 BA ?? ?? ?? ?? C6 45 ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D6 8B + C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 83 C4 ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B + } + $enum_shares_p2 = { + 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? E8 + ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B C8 + 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 EC ?? 8D 55 ?? 8B CC 51 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? + ?? ?? ?? 83 C4 ?? 8D 55 ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 BA ?? ?? ?? ?? + C6 45 ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D6 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? C6 45 ?? ?? 83 C4 ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 + C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? + E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 + ?? ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 F8 ?? 72 ?? + 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? + E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B + C8 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? + 8B 75 ?? B3 ?? 47 E9 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? BA + ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8A C3 E9 ?? ?? + ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? + ?? ?? ?? C3 + } + $find_files = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? A1 ?? ?? ?? ?? ?? ?? ?? + ?? EC 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? 45 FC 00 00 00 00 8D 4D ?? + C6 45 ?? ?? 8B 75 ?? 83 FE ?? 8B 7D ?? 8B 55 ?? 0F 43 CF 6A ?? 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 C4 ?? 8D 4D ?? 85 C0 0F 84 ?? ?? ?? ?? 83 FE ?? 6A ?? 0F 43 CF 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 85 C0 0F 84 ?? ?? ?? ?? 83 FE ?? 6A ?? 0F 43 + CF 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 85 C0 0F 84 ?? ?? ?? ?? 83 FE ?? + 6A ?? 0F 43 CF 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 0F 57 + C0 C7 45 ?? ?? ?? ?? ?? 66 0F D6 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? 83 FE ?? C6 45 ?? ?? 8D 4D ?? 0F 43 CF E8 ?? ?? ?? ?? 8B F0 89 75 + ?? 85 F6 0F 84 ?? ?? ?? ?? 8D 45 ?? 8B D6 50 8B CE E8 ?? ?? ?? ?? 8B 5D ?? 83 C4 ?? + 85 DB 0F 84 ?? ?? ?? ?? 8D 7B ?? B9 ?? ?? ?? ?? 8B C7 66 0F 1F 44 00 ?? 8A 10 3A 11 + 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 F6 EB ?? + 1B F6 83 CE ?? B9 ?? ?? ?? ?? 8B C7 0F 1F 40 ?? 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 + ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 3B F0 8B + 75 ?? 0F 85 ?? ?? ?? ?? 8B 43 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 4D ?? 57 3D ?? ?? ?? ?? + 75 ?? E8 ?? ?? ?? ?? 50 8D 55 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 EC + ?? C6 45 ?? ?? 8B CC 8B D0 51 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D + ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 EC ?? C6 45 ?? ?? 8B CC 8D 55 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? 83 C4 + ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 75 ?? E9 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? + 83 EC ?? 8D 45 ?? 8B CC 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? BA ?? ?? ?? + ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? B8 ?? ?? ?? ?? C3 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? E8 ?? ?? ?? + ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD + E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $encrypt_files_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? ?? ?? ?? ?? A1 ?? ?? ?? ?? ?? ?? ?? + ?? EC 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? ?? ?? ?? ?? 45 FC 00 00 00 00 C6 45 ?? + ?? 83 05 ?? ?? ?? ?? ?? 83 15 ?? ?? ?? ?? ?? 83 EC ?? 8B CC C7 41 ?? ?? ?? ?? ?? C7 + 41 ?? ?? ?? ?? ?? 83 79 ?? ?? 72 ?? 8B 01 EB ?? 8B C1 6A ?? C6 00 ?? 8D 45 ?? 6A ?? + 50 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 EC ?? C6 45 ?? ?? 8B CC C7 41 + ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 83 79 ?? ?? 72 ?? 8B 01 EB ?? 8B C1 6A ?? C6 00 + ?? 8D 45 ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D + 4D ?? 83 3D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 8B 7D ?? 0F 43 05 ?? ?? ?? ?? 83 FF ?? FF + 35 ?? ?? ?? ?? 8B 75 ?? 0F 43 CE 8B 55 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? + ?? ?? ?? 83 FF ?? 8D 4D ?? 6A ?? 0F 43 CE 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 + C0 0F 84 ?? ?? ?? ?? 83 FF ?? 8D 4D ?? 6A ?? 0F 43 CE 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 FF ?? 8D 4D ?? 6A ?? 0F 43 CE 68 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 + } + $encrypt_files_p2 = { + 84 C0 0F 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? + ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 + ?? 6A ?? 0F 43 45 ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B + D8 83 FB ?? 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 6A ?? 8B F0 8B FA 8D 45 ?? 50 68 ?? + ?? ?? ?? FF 35 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 2B C6 1B D7 01 05 + ?? ?? ?? ?? 11 15 ?? ?? ?? ?? 83 65 ?? ?? 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 8B FA + 8B F0 8B 55 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 2B C6 6A ?? 1B D7 01 05 ?? ?? ?? ?? + 8B 45 ?? 11 15 ?? ?? ?? ?? 01 05 ?? ?? ?? ?? 6A ?? 83 15 ?? ?? ?? ?? ?? 6A ?? 53 FF + 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 6A ?? 8B F0 8B FA 8D 45 ?? 50 FF 75 ?? FF 35 ?? ?? + ?? ?? 53 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 99 2B C6 53 1B D7 01 05 ?? ?? ?? ?? 11 15 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 51 8D 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C8 83 C4 ?? 83 + 79 ?? ?? 72 ?? 8B 09 83 7D ?? ?? 8D 45 ?? 51 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? 83 05 ?? ?? ?? ?? ?? 83 15 ?? ?? ?? ?? ?? EB ?? 53 FF 15 ?? ?? ?? + ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? + 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and ($enum_volumes and $find_files and ( all of ($enum_shares_p*)) and ( all of ($encrypt_files_p*))) +} +rule REVERSINGLABS_Win32_Ransomware_Marsjoke : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects MarsJoke ransomware." + author = "ReversingLabs" + id = "8164c586-f548-5414-9df8-61e0c51cbe29" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.MarsJoke.yara#L1-L157" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "298b2fd99793a15b3537853289e1337648d3fa84f12038e6f6831741404b7c5c" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "MarsJoke" + tc_detection_factor = 5 + importance = 25 + + strings: + $search_and_encrypt_files = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 8B 45 + ?? 53 56 89 44 24 ?? 8B 45 ?? 57 89 44 24 ?? 8B 45 ?? BE ?? ?? ?? ?? 33 DB 56 89 44 + 24 ?? 8D 84 24 ?? ?? ?? ?? 8B F9 53 50 89 7C 24 ?? 66 89 9C 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C4 ?? 56 8D 84 24 ?? ?? ?? ?? 53 50 66 89 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 57 8D 4C 24 ?? 88 5C 24 ?? E8 ?? + ?? ?? ?? 83 C4 ?? 84 C0 0F 85 ?? ?? ?? ?? 38 5C 24 ?? 0F 85 ?? ?? ?? ?? 8D 84 24 ?? + ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 59 59 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 + 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 59 59 BE ?? ?? ?? + ?? 56 8D 84 24 ?? ?? ?? ?? 50 FF D7 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 56 FF + 74 24 ?? FF D7 FF 74 24 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 + ?? 84 C0 8D 84 24 ?? ?? ?? ?? 75 ?? 50 FF 15 ?? ?? ?? ?? FF 74 24 ?? E9 ?? ?? ?? ?? + 6A ?? 50 FF D7 53 68 ?? ?? ?? ?? 6A ?? 53 6A ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 89 44 24 ?? 75 ?? 56 8D 84 24 ?? ?? ?? ?? 50 FF D7 8D + 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 E9 ?? ?? ?? ?? 8D 4C + 24 ?? 51 50 FF 15 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? FF 74 24 ?? FF 74 24 ?? E8 ?? ?? ?? + ?? 89 5C 24 ?? 33 DB 68 ?? ?? ?? ?? 89 44 24 ?? 8D 84 24 ?? ?? ?? ?? 53 50 89 54 24 + ?? 89 4C 24 ?? 66 89 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? FF 74 24 ?? 8D 84 24 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 + 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 56 8D 84 24 ?? ?? ?? ?? 50 FF + D7 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 53 56 6A ?? 53 6A ?? 68 ?? ?? ?? ?? 8D + 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 89 44 24 ?? 75 ?? 56 8D 84 24 ?? ?? + ?? ?? 50 FF D7 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? E9 ?? + ?? ?? ?? 6A ?? 59 33 C0 66 89 9C 24 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? F3 AB 6A ?? FF + 74 24 ?? 66 AB 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 8D 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BF ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? + ?? 57 53 50 89 44 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 0B 44 24 ?? 74 ?? 83 44 + 24 ?? ?? 11 5C 24 ?? EB ?? 89 7C 24 ?? 89 5C 24 ?? BF ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? + 59 50 57 8B 7C 24 ?? 57 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 89 47 ?? 8B 44 24 ?? 53 + 89 47 ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? 57 FF 74 24 ?? C7 47 ?? ?? ?? ?? ?? 88 5C 24 + ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? C6 44 24 ?? ?? E9 ?? ?? ?? ?? 8B 7C 24 ?? 3B FB 89 + 5C 24 ?? 0F 8C ?? ?? ?? ?? 7F ?? 39 5C 24 ?? 0F 86 ?? ?? ?? ?? 8B 74 24 ?? 83 EE ?? + 1B FB 89 74 24 ?? 89 7C 24 ?? 89 5C 24 ?? 33 C0 EB ?? 8B 7C 24 ?? 8B 74 24 ?? 39 74 + 24 ?? 75 ?? 3B C7 75 ?? 8B 44 24 ?? 89 44 24 ?? EB ?? C7 44 24 ?? ?? ?? ?? ?? 68 ?? + ?? ?? ?? 53 FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 8D 44 24 ?? 50 FF 74 24 ?? FF 74 + 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 6A ?? 58 39 44 24 ?? 73 ?? 89 44 24 ?? 39 74 24 + ?? 75 ?? 33 C0 3B C7 75 ?? 39 5C 24 ?? 7C ?? 7F ?? 83 7C 24 ?? ?? 76 ?? 8B 44 24 ?? + 83 E0 ?? 74 ?? 8B 4C 24 ?? 2B C8 03 C9 89 4C 24 ?? 6A ?? 68 ?? ?? ?? ?? FF 74 24 ?? + 53 FF 15 ?? ?? ?? ?? FF 74 24 ?? 89 44 24 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 + ?? 50 81 EC ?? ?? ?? ?? 6A ?? 59 8B FC FF B4 24 ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? FF + B4 24 ?? ?? ?? ?? F3 A5 8B B4 24 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? + 53 8D 44 24 ?? 50 FF 74 24 ?? 56 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 68 ?? ?? ?? ?? + 53 56 74 ?? FF 15 ?? ?? ?? ?? FF 44 24 ?? 8B 44 24 ?? 89 44 24 ?? 33 C0 3B 44 24 ?? + 0F 8C ?? ?? ?? ?? 7F ?? 8B 4C 24 ?? 3B 4C 24 ?? 0F 82 ?? ?? ?? ?? EB ?? C6 44 24 ?? + ?? FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 74 24 ?? FF 15 ?? ?? ?? ?? + FF 74 24 ?? 8B 3D ?? ?? ?? ?? FF D7 FF 74 24 ?? FF D7 56 8D 84 24 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D6 38 5C 24 ?? 8D 84 24 + ?? ?? ?? ?? 75 ?? 6A ?? FF 74 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 FF 74 24 ?? 68 ?? ?? + ?? ?? 75 ?? E8 ?? ?? ?? ?? 59 59 8D 84 24 ?? ?? ?? ?? 50 FF D6 EB ?? E8 ?? ?? ?? ?? + 59 59 B0 ?? EB ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 32 C0 8B 8C 24 ?? ?? ?? ?? + 5F 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $remote_connection_2 = { + 55 8D 6C 24 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? + 53 56 57 BE ?? ?? ?? ?? 56 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 04 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 56 89 BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 83 A5 ?? + ?? ?? ?? ?? 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? + ?? BE ?? ?? ?? ?? 56 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 FF B5 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? + E8 ?? ?? ?? ?? 6A ?? 6A ?? 8B C3 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? + ?? 57 E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A + ?? 8D 5D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? + ?? ?? 56 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 83 A5 ?? ?? ?? ?? ?? BF ?? ?? ?? ?? 57 + 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? + 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 66 83 A5 ?? ?? ?? ?? ?? 57 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? + ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A + ?? 8D 5D ?? E8 ?? ?? ?? ?? 6A ?? 8D 5D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 8D 85 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B C3 + 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 50 + E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 59 59 5F 5E 5B 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 59 83 BD ?? ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B 4D ?? 8B 85 ?? + ?? ?? ?? 33 CD E8 ?? ?? ?? ?? 83 C5 ?? C9 C3 + } + $remote_connection_1 = { + 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 8D 85 + ?? ?? ?? ?? 50 8B F9 8B F2 68 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 33 DB 53 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 89 85 ?? ?? ?? ?? 66 C7 85 + ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 + 88 1F 50 88 1E 66 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D + 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 38 9D ?? ?? ?? + ?? 59 59 75 ?? 68 ?? ?? ?? ?? C6 07 ?? E8 ?? ?? ?? ?? 59 E9 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 59 89 85 ?? ?? ?? ?? 33 F6 BB ?? ?? ?? ?? + 56 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 FF B5 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 56 53 E8 ?? ?? ?? ?? FF 85 ?? ?? ?? ?? + 46 83 FE ?? 59 59 7C ?? EB ?? 53 E8 ?? ?? ?? ?? 59 83 BD ?? ?? ?? ?? ?? 7C ?? C6 07 + ?? 53 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 F6 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 56 50 66 + 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 59 56 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 50 FF + B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 56 68 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 3B C6 0F 8E ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 89 B5 ?? ?? ?? ?? 0F 84 ?? + ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 83 8D ?? ?? ?? ?? ?? 56 E8 ?? ?? + ?? ?? 59 50 56 8D B5 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 8B C8 85 C9 + 89 8D ?? ?? ?? ?? 7D ?? C6 07 ?? 51 E9 ?? ?? ?? ?? 83 F9 ?? 0F 8C ?? ?? ?? ?? 83 BD + ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 66 83 A5 ?? ?? ?? ?? ?? 33 C0 8D BD ?? ?? ?? ?? 66 + AB 40 3B C8 89 85 ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? 8D 47 ?? E8 ?? ?? ?? ?? 85 C0 59 59 0F 85 ?? ?? ?? ?? 8B 77 ?? 2B 37 + 8D 46 ?? 50 E8 ?? ?? ?? ?? 59 56 6A ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 07 8B + 8D ?? ?? ?? ?? 83 C4 ?? 03 C8 51 8B 4F ?? 2B C8 51 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 59 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 59 40 50 E8 + ?? ?? ?? ?? 59 FF B5 ?? ?? ?? ?? 8B F0 6A ?? 56 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 + C4 ?? FF B5 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 56 53 C6 04 06 ?? + E8 ?? ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 83 A5 ?? ?? ?? ?? ?? 83 8D ?? ?? ?? ?? ?? 56 E8 + ?? ?? ?? ?? 83 C4 ?? 50 56 8D B5 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 + 3B C6 59 59 0F 8C ?? ?? ?? ?? 83 F8 ?? 0F 8C ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 85 + ?? ?? ?? ?? 83 F8 ?? 7E ?? 48 8D B5 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 85 C0 59 59 75 ?? 8B 06 8B 8D ?? ?? ?? ?? 03 + C8 51 8B 4E ?? 2B C8 51 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 83 C6 ?? FF 8D ?? ?? ?? ?? 75 ?? 33 F6 39 B5 ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 59 39 B5 ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 39 B5 ?? + ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 83 C7 ?? 3B 85 ?? ?? ?? ?? 0F 8C ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 85 C0 59 59 0F 85 ?? ?? ?? ?? 39 85 ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 59 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 59 59 B0 ?? E9 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 50 53 C6 + 01 ?? E8 ?? ?? ?? ?? 59 39 B5 ?? ?? ?? ?? 59 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 59 39 B5 ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 39 B5 ?? ?? ?? ?? 74 + ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? 53 C6 00 ?? E8 ?? ?? ?? + ?? EB ?? 8D 85 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C6 00 ?? EB ?? 0F + 84 ?? ?? ?? ?? C6 07 ?? FF 15 ?? ?? ?? ?? 50 53 E8 ?? ?? ?? ?? 59 59 83 BD ?? ?? ?? + ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 32 C0 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? C9 C3 + } + + condition: + uint16(0)==0x5A4D and $search_and_encrypt_files and $remote_connection_1 and $remote_connection_2 +} +rule REVERSINGLABS_Win32_Ransomware_Dragon : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Dragon ransomware." + author = "ReversingLabs" + id = "dbeab955-f1fe-57eb-a9a4-c8c885ab7fad" + date = "2020-10-30" + modified = "2020-10-30" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Dragon.yara#L1-L149" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "7298c5681deaf04abb6a656cefc09b5ee4096ff7a5028caab1d7b107e97be90a" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Dragon" + tc_detection_factor = 5 + importance = 25 + + strings: + $remote_connection_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 56 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 85 C0 0F 85 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 88 45 ?? 83 EC ?? 89 45 ?? 8B + CC 89 A5 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC E8 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? BA ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? 56 8B D0 C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 + 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? + ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? + ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? + ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 + } + $remote_connection_p2 = { + 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? + 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? + ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F + 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 8D 4D ?? 8D 55 ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? 0F 43 4D ?? 51 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 55 ?? 83 FA + ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? + 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B + 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? + 64 89 0D ?? ?? ?? ?? 59 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $find_files_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 83 EC ?? 89 8D ?? + ?? ?? ?? 8B D4 8D 71 ?? C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C6 02 ?? 8A 01 41 + 84 C0 75 ?? 2B CE 8B B5 ?? ?? ?? ?? 51 56 8B CA E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 8D + 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 8B 1D + } + $find_files_2 = { + 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? + 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + 8A 11 3A 10 75 ?? 84 D2 74 ?? 8A 51 ?? 3A 50 ?? 75 ?? 83 C1 ?? 83 C0 ?? 84 D2 75 ?? + 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? + ?? 56 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 51 8B D4 8D 8D ?? ?? ?? ?? + 8D 71 ?? C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C6 02 ?? 8A 01 41 84 C0 75 ?? 2B + CE 8D 85 ?? ?? ?? ?? 51 50 8B CA E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 74 ?? + 83 EC ?? 8B CC 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 57 FF D3 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B 4D ?? 5F + 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $skip_hk_china_taiwan_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? + 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 88 45 ?? 89 45 ?? 8D 4D ?? 6A ?? + 68 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 88 45 ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D + 4D ?? 83 7D ?? ?? 8D 55 ?? 0F 43 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 6A ?? + 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? + C6 45 ?? ?? 8D 4D ?? 6A ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 + ?? 0F 85 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? + ?? ?? 6A ?? 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? + 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 + C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 + ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 + ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 8D ?? + ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 + } + $skip_hk_china_taiwan_p2 = { + 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 + 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? + ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 + C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? + 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 55 ?? + 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 + C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 + ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 + ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 8D ?? + ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? + 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 + 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 + E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? + ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 + 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 32 C0 E9 ?? ?? ?? ?? 6A ?? E8 + ?? ?? ?? ?? E8 + } + $crypt_files = { + 8B FF 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 4D ?? 8B 45 ?? 89 45 ?? 89 + 4D ?? 56 8B 75 ?? 85 C9 75 ?? 33 C0 E9 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? ?? ?? 83 20 + ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C8 ?? E9 ?? ?? ?? ?? 53 8B C6 + 8B D6 C1 FA ?? 83 E0 ?? 57 6B F8 ?? 89 55 ?? 8B 14 95 ?? ?? ?? ?? 89 7D ?? 8A 5C 3A + ?? 80 FB ?? 74 ?? 80 FB ?? 75 ?? 8B C1 F7 D0 A8 ?? 75 ?? E8 ?? ?? ?? ?? 83 20 ?? E8 + ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? F6 44 3A ?? ?? 74 ?? 6A + ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 8D 7D ?? AB 56 AB AB E8 ?? ?? ?? ?? + 59 84 C0 74 ?? 84 DB 74 ?? FE CB 80 FB ?? 8B 5D ?? 0F 87 ?? ?? ?? ?? FF 75 ?? 8D 45 + ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 E9 ?? ?? ?? ?? FF 75 ?? 8B 5D ?? 8D 45 ?? 53 + 56 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8B 4D ?? 8B 55 ?? 8B 04 8D ?? ?? ?? ?? 80 7C 10 + ?? ?? 7D ?? 0F BE C3 8B 5D ?? 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 83 E8 ?? 75 ?? FF 75 ?? + 8D 45 ?? 53 56 50 E8 ?? ?? ?? ?? EB ?? FF 75 ?? 8D 45 ?? 53 56 50 E8 ?? ?? ?? ?? EB + ?? FF 75 ?? 8D 45 ?? 53 56 50 E8 ?? ?? ?? ?? EB ?? 8B 4C 10 ?? 8D 7D ?? 8B 5D ?? 33 + C0 AB 6A ?? AB AB 8D 45 ?? 50 FF 75 ?? 53 51 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? + ?? ?? ?? 89 45 ?? 8D 75 ?? 8D 7D ?? A5 A5 A5 8B 4D ?? 8B 55 ?? 8B 45 ?? 85 C0 75 ?? + 8B 45 ?? 85 C0 74 ?? 6A ?? 5E 3B C6 75 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 89 30 EB ?? 50 E8 ?? ?? ?? ?? 59 EB ?? 8B 04 8D ?? ?? ?? ?? F6 44 10 ?? ?? 74 + ?? 80 3B ?? 75 ?? 33 C0 EB ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 20 + ?? 83 C8 ?? EB ?? 2B 45 ?? 5F 5B 8B 4D ?? 33 CD 5E E8 ?? ?? ?? ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and ( all of ($skip_hk_china_taiwan_p*)) and ( all of ($find_files_*)) and ($crypt_files) and ( all of ($remote_connection_p*)) +} +rule REVERSINGLABS_Win64_Ransomware_Redroman : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects RedRoman ransomware." + author = "ReversingLabs" + id = "c860586a-fa50-5bb4-a3b4-13506f9d6030" + date = "2021-05-10" + modified = "2021-05-10" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.RedRoman.yara#L1-L82" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6fb2ac0e7f7ac095766e27c057e5124406dc493c08d01a7e5381403d794c7240" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "RedRoman" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? + ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? + ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 48 89 44 24 ?? 4C 8D 8C 24 ?? ?? ?? ?? 41 B8 ?? ?? + ?? ?? BA ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 48 C7 84 + 24 ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 85 C0 75 ?? 33 D2 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 8D 84 24 ?? ?? + ?? ?? 48 89 44 24 ?? 41 B9 ?? ?? ?? ?? 45 33 C0 BA ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 6B C9 ?? 48 89 84 0C ?? ?? ?? ?? 48 C7 84 24 + ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 85 C0 75 ?? B8 ?? ?? ?? ?? 48 6B C0 ?? 48 83 BC 04 ?? + ?? ?? ?? ?? 74 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 48 89 84 + 24 ?? ?? ?? ?? EB ?? 33 D2 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? + E9 ?? ?? ?? ?? 33 D2 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B 49 ?? 48 89 01 48 8B 44 24 ?? 48 8B + 40 ?? 48 83 38 ?? 75 ?? 48 8D 15 ?? ?? ?? ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? B8 ?? ?? + ?? ?? 48 6B C0 ?? 48 83 BC 04 ?? ?? ?? ?? ?? 74 ?? B8 ?? ?? ?? ?? 48 6B C0 ?? 48 8B + 8C 04 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? B8 + } + $encrypt_files_p2 = { + 4C 8D 05 ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? 48 8B 4D ?? 48 8B 55 ?? E8 ?? ?? ?? ?? 48 89 + 55 ?? 48 89 45 ?? EB ?? 31 C0 41 89 C0 48 8B 4D ?? 48 8B 55 ?? E8 ?? ?? ?? ?? 48 89 + 45 ?? EB ?? 48 8B 45 ?? 48 83 F8 ?? 74 ?? 48 8B 55 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? EB ?? EB ?? 48 81 C4 ?? ?? ?? ?? 5D C3 48 8D 4D ?? E8 ?? ?? ?? ?? EB ?? 48 8B + 85 ?? ?? ?? ?? 48 85 C0 74 ?? EB ?? EB ?? 0F 0B 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? + ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? + ?? ?? C6 85 ?? ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? + ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? + ?? ?? ?? 0F 84 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? + 48 89 85 ?? ?? ?? ?? 48 89 8D ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? + 48 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 85 + C0 74 ?? EB ?? EB ?? 0F 0B 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? + ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? + ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? + ?? ?? 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E9 ?? ?? ?? ?? + 48 8B 85 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 89 8D + } + $find_files = { + 48 8D 9C 24 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 D9 31 D2 E8 ?? ?? ?? ?? 48 8B 0F 48 + 89 DA E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 4C 8D B4 24 ?? ?? ?? ?? 48 8D 9C 24 ?? + ?? ?? ?? 66 83 BC 24 ?? ?? 00 00 ?? 74 ?? EB ?? 0F 1F 84 00 ?? ?? ?? ?? 48 8B 0F 48 + 89 DA E8 ?? ?? ?? ?? 85 C0 74 ?? 66 83 BC 24 ?? ?? 00 00 ?? 75 ?? 0F B7 84 24 ?? ?? + ?? ?? 66 85 C0 74 ?? 66 83 F8 ?? 75 ?? 66 83 BC 24 ?? ?? 00 00 ?? 74 ?? 48 8B 47 ?? + F0 48 83 00 ?? 0F 8E ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 41 + B8 ?? ?? ?? ?? 4C 89 F1 E8 ?? ?? ?? ?? 48 C7 06 ?? ?? ?? ?? 48 8D 4E ?? 48 8D 94 24 + ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 48 + C7 06 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? 48 C7 06 ?? ?? ?? ?? C6 46 ?? ?? 89 46 ?? 48 + 89 F0 0F 28 B5 ?? ?? ?? ?? 0F 28 BD ?? ?? ?? ?? 44 0F 28 85 ?? ?? ?? ?? 44 0F 28 8D + ?? ?? ?? ?? 44 0F 28 95 ?? ?? ?? ?? 44 0F 28 9D ?? ?? ?? ?? 44 0F 28 A5 ?? ?? ?? ?? + 44 0F 28 AD ?? ?? ?? ?? 44 0F 28 B5 ?? ?? ?? ?? 44 0F 28 BD ?? ?? ?? ?? 48 8D A5 ?? + ?? ?? ?? 5B 5F 5E 41 5E 5D C3 0F 0B + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Invert : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Invert ransomware." + author = "ReversingLabs" + id = "7ef77946-a902-5dc6-9b3c-b7b6a687eb96" + date = "2021-11-11" + modified = "2021-11-11" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Invert.yara#L1-L66" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "1608b8bbfc03b18a79752e60f211da7d7703862bc06b2ddf094074ae5efd0d14" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Invert" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files = { + 73 ?? ?? ?? ?? 0A 06 04 7D ?? ?? ?? ?? 00 00 02 28 ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 25 2D + ?? 26 06 06 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 0C 7D ?? ?? ?? ?? 08 7E ?? ?? ?? ?? 25 + 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 + ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? + FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D + ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 2B ?? 07 6F ?? ?? ?? ?? 0D 00 00 09 03 28 ?? ?? + ?? ?? 13 ?? 11 ?? 2C ?? 00 7E ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 26 00 00 DE ?? 26 00 00 DE + ?? 00 07 6F ?? ?? ?? ?? 2D ?? DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? 00 DC 2A + } + $find_files = { + 00 73 ?? ?? ?? ?? 0A 00 28 ?? ?? ?? ?? 18 8D ?? ?? ?? ?? 25 16 28 ?? ?? ?? ?? A2 25 17 + 72 ?? ?? ?? ?? A2 17 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 2B ?? 12 ?? 28 ?? + ?? ?? ?? 0C 00 06 08 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 26 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE + ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 26 06 + 0D 2B ?? 09 2A + } + $get_file_list = { + 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 06 2C + ?? 00 02 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 38 ?? ?? + ?? ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0B + 00 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 2B ?? 12 ?? 28 ?? ?? ?? ?? 0D 00 07 09 6F ?? ?? + ?? ?? 00 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 + DC 00 DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? 00 DC 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 18 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 18 28 ?? ?? ?? ?? 00 02 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F + ?? ?? ?? ?? 00 00 2A + } + + condition: + uint16(0)==0x5A4D and ($get_file_list) and ($find_files) and ($encrypt_files) +} +rule REVERSINGLABS_Win32_Ransomware_Marlboro : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Marlboro ransomware." + author = "ReversingLabs" + id = "7cd3b436-47e3-5711-9b59-cef70efe3b45" + date = "2020-07-23" + modified = "2020-07-23" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Marlboro.yara#L1-L117" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "d36c3cf52af47e9f638f58aabc19298e8c58831c3083f82e4c194319503eeaaa" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Marlboro" + tc_detection_factor = 5 + importance = 25 + + strings: + $ping_apnic = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 + 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 0F 57 + C0 F3 0F 7F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D + 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? + 8D 85 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF + B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $remote_server_connection_1 = { + BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D7 8B C8 E8 ?? ?? ?? ?? BA ?? ?? + ?? ?? 8B C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D6 8B + C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 55 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 55 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8B 40 ?? F6 84 05 ?? ?? ?? ?? ?? 74 ?? 83 EC ?? 8D 45 ?? 8D 4D ?? + 50 E8 ?? ?? ?? ?? C6 45 ?? ?? BA ?? ?? ?? ?? 8B C8 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 + } + $remote_server_connection_2 = { + 84 C0 74 ?? B3 ?? EB ?? 32 DB C7 45 ?? ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 83 7D + ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 DB 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3D ?? ?? ?? + ?? 74 ?? 8D 80 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? [0-3] 8B 85 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 03 C8 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 50 C6 + 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 C4 ?? 8B 8D ?? ?? ?? ?? 8B F0 85 C9 74 ?? 8B + 01 FF 50 ?? 85 C0 74 ?? 8B 10 8B C8 6A ?? FF 12 8B 06 8B CE 6A ?? 8B 40 ?? FF D0 + } + $remote_server_connection_3 = { + 50 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 5D ?? 83 C4 ?? 8B 7D ?? 8B 08 8B 49 + ?? F6 44 01 ?? ?? 75 ?? 8B 75 ?? 8D 4D ?? 83 FB ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? 0F + 43 CF 3B F0 0F 42 C6 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 83 FE ?? 73 ?? 83 C8 ?? + EB ?? 33 C0 83 FE ?? 0F 95 C0 85 C0 0F 94 C0 84 C0 0F 94 C0 84 C0 0F 85 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + B5 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 83 FB ?? 72 + } + $remote_server_connection_4 = { + 57 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 7D + ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B + C6 EB ?? 8B 8D ?? ?? ?? ?? 8B 01 FF 50 ?? 8B 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? B8 ?? + ?? ?? ?? C3 8B 85 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 + CD E8 ?? ?? ?? ?? 8B E5 5D + } + $encrypt_file = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 51 C7 45 ?? ?? ?? ?? ?? 8D 55 ?? + 8B 35 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + C6 45 ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? 83 7D ?? ?? 51 0F 43 45 ?? 8D 8D ?? ?? ?? + ?? 6A ?? 50 E8 ?? ?? ?? ?? 85 C0 8D 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BF ?? ?? ?? ?? + 8B 40 ?? 75 ?? 03 C8 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 ?? 0B C7 EB ?? 03 C8 33 C0 39 + 41 ?? 0F 44 C7 6A ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 51 0F 43 45 ?? 8D 8D ?? + ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 85 C0 8D 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? + 75 ?? 03 C8 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 ?? 83 C8 ?? EB ?? 03 C8 33 C0 39 41 ?? + 0F 44 C7 6A ?? 50 E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 83 EC + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 6A ?? 83 EC ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8D 8D ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 8B 08 8B 49 ?? F6 44 01 ?? ?? 75 ?? 8D 64 24 ?? 51 8D 55 ?? + 8B CE E8 ?? ?? ?? ?? 51 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 + ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 08 8B 49 ?? F6 44 01 ?? ?? 74 ?? 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 03 + C8 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 ?? 83 C8 ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? 03 C8 + 8B 41 ?? 83 C8 ?? 83 79 ?? ?? 75 ?? 83 C8 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 8D + 45 ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? + C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? + ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 C4 ?? 8B 85 ?? + ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 + ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? + C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? + ?? ?? 8D 45 ?? 50 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 72 ?? FF + 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? C7 45 ?? ?? ?? + ?? ?? 66 89 45 ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? + ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and $ping_apnic and $remote_server_connection_1 and $remote_server_connection_2 and $remote_server_connection_3 and $remote_server_connection_4 and $encrypt_file +} +rule REVERSINGLABS_Win32_Ransomware_Killdisk : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects KillDisk ransomware." + author = "ReversingLabs" + id = "bd04ac88-987a-58f0-8f0a-508662b3c930" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.KillDisk.yara#L1-L80" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6148e6fc1363ff8995a9100e07139bfa658c72892db4d30a973bad0f2b3e6c3f" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "KillDisk" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files = { + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 55 8B AC 24 ?? ?? ?? + ?? 56 57 33 FF 8B F1 3B F7 89 7D ?? 89 7D ?? 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 56 + FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 95 C0 84 C0 75 ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 56 8D + 4C 24 ?? 89 7C 24 ?? 89 7C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 74 ?? B8 ?? ?? ?? ?? + E9 ?? ?? ?? ?? 8B 5C 24 ?? 3B DF 8B 44 24 ?? 89 45 ?? 89 5D ?? 77 ?? 83 F8 ?? 0F 82 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 6A ?? 57 6A ?? 68 ?? ?? ?? ?? 56 FF 15 + ?? ?? ?? ?? 8B E8 3B EF 0F 84 ?? ?? ?? ?? 83 FD ?? 0F 84 ?? ?? ?? ?? 8B 0D ?? ?? ?? + ?? 33 C0 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 + 44 24 ?? 89 44 24 ?? 8D 44 24 ?? 50 6A ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 54 + 24 ?? 57 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 54 24 ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 85 C0 0F + 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D + 4C 24 ?? 51 8D 54 24 ?? 89 7C 24 ?? 52 8D BC 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 85 C0 0F 84 ?? ?? ?? ?? 8B 74 24 ?? 6A ?? 8B C6 05 ?? ?? ?? ?? 50 8B CB 83 D1 ?? 51 + 6A ?? 6A ?? 55 FF 15 ?? ?? ?? ?? 85 C0 89 44 24 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 + ?? ?? ?? ?? 8D 4C 24 ?? 51 53 56 8B F8 E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 0F 84 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 8D 54 24 ?? 6A ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? B9 ?? ?? ?? ?? 8D B4 + 24 ?? ?? ?? ?? 8D 7C 24 ?? 8D 44 24 ?? F3 A5 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 08 89 8C 24 ?? ?? ?? ?? 8B 50 ?? 89 94 24 ?? ?? ?? ?? 8B 48 ?? 89 8C 24 + ?? ?? ?? ?? 8B 50 ?? 89 94 24 ?? ?? ?? ?? 8B 48 ?? 89 8C 24 ?? ?? ?? ?? 8B 50 ?? 8D + 74 24 ?? 89 94 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 6A ?? 6A ?? 53 50 55 FF 15 + ?? ?? ?? ?? 6A ?? 8D 4C 24 ?? 51 68 ?? ?? ?? ?? 8D 54 24 ?? 52 55 C7 44 24 ?? ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 8B F0 8B 44 24 ?? F7 DE 1B F6 83 E6 ?? 50 83 C6 ?? FF 15 ?? + ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 8B C6 EB ?? 8B 44 24 ?? 50 BE ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 55 FF 15 ?? ?? ?? ?? 8B C6 EB ?? 55 BE ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B C6 EB + ?? 55 BE ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B C6 EB ?? 55 BE ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 8B C6 EB ?? BE ?? ?? ?? ?? 8B C6 EB ?? B8 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E + 5D 5B 33 CC E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 } + $app_whitelisting_1 = { + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 55 56 57 32 DB FF 15 + ?? ?? ?? ?? 6A ?? 6A ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? 8B E8 85 ED 89 6C 24 ?? 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4C 24 ?? + 51 55 C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 64 24 ?? + 8B 54 24 ?? 3B 54 24 ?? 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? 33 FF E8 ?? ?? ?? ?? 85 C0 + 0F 86 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B C1 + 2B C3 C1 F8 ?? 3B C7 0F 86 ?? ?? ?? ?? 3B D9 8B F3 76 ?? E8 ?? ?? ?? ?? 8B 1D ?? ?? + ?? ?? 8B 0D ?? ?? ?? ?? 89 74 24 ?? 8D 34 BE 3B F1 B8 ?? ?? ?? ?? 8B E8 77 ?? 3B F3 + 73 ?? E8 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 3B 75 ?? 72 ?? E8 ?? ?? ?? ?? 8B 1D ?? ?? ?? + ?? 8B 44 24 ?? 39 06 74 ?? B8 ?? ?? ?? ?? 83 C7 ?? E8 ?? ?? ?? ?? 3B F8 72 ?? 8B 6C + 24 ?? 8B 74 24 ?? FF 15 ?? ?? ?? ?? 3B F0 74 ?? 85 F6 74 ?? 56 6A ?? 6A ?? FF 15 ?? + ?? ?? ?? 8B F0 85 F6 74 ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? EB ?? 8B + 6C 24 ?? 8D 4C 24 ?? 51 55 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? B3 ?? 55 FF 15 + ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E 5D 8A C3 5B 33 CC E8 ?? ?? ?? ?? 81 C4 ?? ?? + ?? ?? C3 + } + $app_whitelisting_2 = { + 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 56 A1 ?? ?? ?? ?? 33 C4 50 8D 44 + 24 ?? 64 A3 ?? ?? ?? ?? 8D 44 24 ?? 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 70 ?? C7 44 + 24 ?? ?? ?? ?? ?? 56 C7 06 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 C0 74 ?? 8B 36 EB + ?? 33 F6 6A ?? 56 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 8B 44 24 ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 7C 24 ?? ?? 72 ?? 8B 4C 24 + ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 64 89 0D + ?? ?? ?? ?? 59 5E 83 C4 ?? C3 + } + + condition: + uint16(0)==0x5A4D and $encrypt_files and $app_whitelisting_1 and $app_whitelisting_2 +} +rule REVERSINGLABS_Win32_Ransomware_Darkside : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects DarkSide ransomware." + author = "ReversingLabs" + id = "061b00cb-9b70-521f-ab3f-7e6b3c129194" + date = "2021-05-17" + modified = "2021-05-17" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.DarkSide.yara#L1-L94" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "128af9a1b143e4b0928dd2b243e69497be906175f44815cc5703f17cce48ec9d" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "DarkSide" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files_v1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 51 52 56 57 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + 83 7D ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 04 45 ?? ?? ?? + ?? 50 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? + ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? E8 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? + ?? ?? ?? 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8D 9D ?? ?? + ?? ?? 83 3B ?? 74 ?? 81 3B ?? ?? ?? ?? 74 ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8D 85 ?? ?? + ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 83 7D ?? + ?? 74 ?? FF 75 ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 45 ?? 5F 5E 5A 59 5B + 8B E5 5D C2 + } + $enumerate_drives = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 51 52 56 57 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 8B D8 85 DB 74 ?? C1 EB ?? 8D B5 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 F8 + ?? 74 ?? 83 F8 ?? 75 ?? 56 E8 ?? ?? ?? ?? 8D 76 ?? 4B 85 DB 75 ?? 5F 5E 5A 59 5B 8B + E5 5D C3 55 8B EC 81 EC ?? ?? ?? ?? 53 51 52 56 57 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? C7 + 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 + ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 66 A9 ?? ?? 74 ?? 6A ?? 8D 85 ?? ?? + ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 8D 40 ?? 50 FF 15 ?? ?? ?? + ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 + ?? ?? ?? ?? 85 C0 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 5A 59 5B 8B E5 5D C2 + } + $escalate_privileges = { + 55 8B EC 83 C4 ?? 53 51 52 56 57 8D 45 ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 0F + 85 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 8D 45 ?? 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 + ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8D 45 ?? 50 + FF 75 ?? FF 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 75 ?? AD 8B F8 83 + 7E ?? ?? 74 ?? C7 46 ?? ?? ?? ?? ?? 83 C6 ?? 4F 85 FF 75 ?? 6A ?? 6A ?? 6A ?? FF 75 + ?? 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 5A 59 5B 8B E5 5D C3 + } + $enumerate_netshare = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 51 52 56 57 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 7D ?? 8D 45 ?? 50 8D 45 ?? 50 8D 45 ?? 50 6A ?? + 8D 45 ?? 50 6A ?? 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 75 ?? 83 7E ?? ?? 75 ?? 68 ?? + ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 C7 03 ?? ?? ?? ?? C7 43 ?? + ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? 8D 47 ?? 50 53 FF 15 ?? ?? ?? + ?? 83 C4 ?? 53 FF 15 ?? ?? ?? ?? FF 36 53 FF 15 ?? ?? ?? ?? 83 C4 ?? 53 E8 ?? ?? ?? + ?? 53 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 C6 ?? FF 4D ?? 83 7D ?? ?? 75 ?? + FF 15 ?? ?? ?? ?? 5F 5E 5A 59 5B 8B E5 5D C2 + } + $find_files_v2 = { + 55 8B EC 81 EC ?? ?? ?? ?? 53 51 52 56 57 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D BD + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 83 C4 ?? 57 FF 15 ?? ?? ?? ?? + 83 C4 ?? 66 83 7C 47 ?? ?? 74 ?? 66 C7 04 47 ?? ?? 83 C7 ?? C7 04 47 ?? ?? ?? ?? C7 + 44 47 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 66 A9 ?? ?? 74 ?? + 8D 9D ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 83 C4 + ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 83 C4 ?? 83 C0 ?? 53 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 56 + E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 75 ?? + FF 15 ?? ?? ?? ?? 5F 5E 5A 59 5B 8B E5 5D C2 + } + + condition: + uint16(0)==0x5A4D and (($find_files_v1 and $enumerate_drives and $escalate_privileges) or ($find_files_v2 and $enumerate_netshare)) +} +rule REVERSINGLABS_Win32_Ransomware_Desucrypt : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects DesuCrypt ransomware." + author = "ReversingLabs" + id = "b9b3ce2b-f184-5bfa-8e1c-a7b996ac708a" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.DesuCrypt.yara#L1-L93" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "bd3ba8ea0fc16aad859a73628d0eda180d49298162fe239acf81c7c4e371eaad" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "DesuCrypt" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files = { + 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 + F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? ?? + ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? FF + 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 5D ?? 8B + CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 EB ?? 8B + 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 FF + 57 57 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 + C5 89 45 ?? 8B 4D ?? 53 8B 5D ?? 57 8B 7D ?? 89 9D ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 + ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8A 11 80 FA + ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 53 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 DB + 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8A C3 80 FA ?? 75 ?? B0 ?? 0F B6 C0 2B CF 41 F7 D8 56 + 1B C0 23 C1 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? + 83 C4 ?? 8D 85 ?? ?? ?? ?? 53 53 53 50 53 57 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? + ?? 83 FE ?? 75 ?? 50 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 83 FE ?? 74 ?? 56 FF 15 + ?? ?? ?? ?? 8B C3 5E 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 + C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? + 80 F9 ?? 75 ?? 38 9D ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 + 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 + } + $encrypt_files = { + 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? + ?? ?? 53 56 57 8B D9 89 54 24 ?? B9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? BE ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? 8D 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? F3 A5 6A ?? 6A ?? 8D + 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 66 A5 50 6A ?? 6A ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? + ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 + E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B + E5 5D C3 8D 44 24 ?? 50 8D 44 24 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 74 24 ?? 8D 84 24 ?? + ?? ?? ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? + ?? ?? EB ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? + ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5F + 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 8D 44 24 ?? 50 FF 74 24 + ?? 6A ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? + ?? E9 ?? ?? ?? ?? 8B 43 ?? 8B 3D ?? ?? ?? ?? 50 89 44 24 ?? 89 44 24 ?? 8D 44 24 ?? + 50 6A ?? 6A ?? 6A ?? 6A ?? FF 74 24 ?? FF D7 85 C0 75 ?? FF 15 ?? ?? ?? ?? 50 51 BA + ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B C8 E8 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 33 C0 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + FF 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 FF 74 24 ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 + ?? 83 7B ?? ?? 72 ?? 8B 1B FF 74 24 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? FF + 74 24 ?? 50 56 6A ?? 6A ?? 6A ?? FF 74 24 ?? FF D7 85 C0 0F 84 ?? ?? ?? ?? 8B 4C 24 + ?? 8B 44 24 ?? 5F 89 01 8B C6 8B 8C 24 ?? ?? ?? ?? 5E 5B 33 CC E8 ?? ?? ?? ?? 8B E5 + 5D C3 + } + $enum_shares = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 + 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 89 75 ?? 8B 45 ?? 8D 4D ?? 51 50 + 6A ?? 6A ?? 6A ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 89 7D ?? 85 FF 0F 84 ?? ?? + ?? ?? 8D 45 ?? 50 57 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 0F 1F 40 ?? 33 DB 39 5D ?? 0F 8E ?? ?? ?? ?? 83 C7 ?? 66 90 F7 47 ?? ?? ?? ?? ?? 74 + ?? 8D 47 ?? 89 45 ?? 8B 06 8B 48 ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 01 8D 55 ?? 52 FF 50 + ?? E9 ?? ?? ?? ?? 8B 17 33 C0 66 89 45 ?? 8B C2 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? 8D 70 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C6 D1 F8 83 F8 ?? 77 ?? 8D 34 00 + 89 45 ?? 56 52 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 44 35 ?? EB ?? 52 C6 + 45 ?? ?? 8D 4D ?? FF 75 ?? 50 E8 ?? ?? ?? ?? 8B 75 ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? + 50 8B 4E ?? E8 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 43 83 C7 ?? + 3B 5D ?? 0F 8C ?? ?? ?? ?? 8B 7D ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 57 8D 45 ?? C7 + 45 ?? ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 57 FF 15 ?? + ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D + ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 + } + + condition: + uint16(0)==0x5A4D and ($find_files and $encrypt_files and $enum_shares) +} +rule REVERSINGLABS_Win32_Ransomware_Koxic : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Koxic ransomware." + author = "ReversingLabs" + id = "73c4afb0-cfa8-5bc5-bca3-49a7710f4ab9" + date = "2022-04-21" + modified = "2022-04-21" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Koxic.yara#L1-L87" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "739faf047b95fd538422a42943fcaad6538549bf4cf33ed91385c61365af4f09" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Koxic" + tc_detection_factor = 5 + importance = 25 + + strings: + $enum_shares_p1 = { + 8B 45 ?? 50 6A ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 55 ?? 52 8B 45 ?? 50 8D 4D + ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 3B 4D ?? 0F 83 ?? ?? ?? ?? 8B + 55 ?? C1 E2 ?? 8B 45 ?? 83 7C 10 ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 4D ?? C1 + E1 ?? 8B 55 ?? 8B 44 0A ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8B 4D ?? C1 E1 ?? 8B 55 ?? 8B 44 0A ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? 8B 4D ?? C1 E1 ?? 8B 55 ?? 8B 44 0A ?? 50 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? C1 E0 ?? 8B 4D ?? 8B + } + $enum_shares_p2 = { + 54 01 ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? C7 45 ?? ?? ?? ?? ?? + 0F B6 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + 51 FF 15 ?? ?? ?? ?? 83 E8 ?? 89 45 ?? EB ?? 8B 55 ?? 83 EA ?? 89 55 ?? 83 7D ?? ?? + 0F 8C ?? ?? ?? ?? 8B 45 ?? 0F B7 8C 45 ?? ?? ?? ?? 83 F9 ?? 0F 85 ?? ?? ?? ?? 8B 55 + ?? 0F B7 84 55 ?? ?? ?? ?? 83 F8 ?? 75 ?? C6 45 ?? ?? EB ?? 8B 4D ?? 8D 94 4D ?? ?? + ?? ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 C9 8B 55 ?? 66 89 8C 55 ?? ?? FF + FF 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 + ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 8B 4D ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 + ?? ?? ?? ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? EB ?? E9 ?? ?? ?? ?? 8B 55 ?? 83 EA ?? 89 + 55 ?? E9 ?? ?? ?? ?? EB ?? 8B 45 ?? C1 E0 ?? 8B 4D ?? 8B 54 01 ?? 83 E2 ?? 74 ?? 8B + 45 ?? C1 E0 ?? 8B 4D ?? 8B 54 01 ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 + ?? C1 E0 ?? 03 45 ?? B9 ?? ?? ?? ?? 6B D1 ?? 89 44 15 ?? B8 ?? ?? ?? ?? C1 E0 ?? 8B + 4D ?? 89 4C 05 ?? BA ?? ?? ?? ?? D1 E2 8B 45 ?? 89 44 15 ?? 8D 4D ?? 51 E8 ?? ?? ?? + ?? 83 C4 ?? E9 ?? ?? ?? ?? EB ?? 81 7D ?? ?? ?? ?? ?? 74 ?? EB ?? 81 7D ?? ?? ?? ?? + ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 + C0 75 ?? B8 ?? ?? ?? ?? EB ?? 33 C0 + } + $find_files = { + 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 33 D2 8B 45 ?? 66 89 10 + 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 33 C0 E9 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 0F B6 C0 83 F8 ?? 75 ?? E9 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 8D 44 02 ?? 3D ?? ?? ?? ?? + 72 ?? E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 8B + 48 ?? 81 79 ?? ?? ?? ?? ?? 76 ?? 6A ?? FF 15 ?? ?? ?? ?? EB ?? 8B 95 ?? ?? ?? ?? 83 + E2 ?? 74 ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8B 0D ?? ?? ?? ?? 51 + FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 0D + ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? C1 E2 ?? 8B 45 ?? 89 44 15 ?? 8D 4D + ?? 51 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 + C0 75 ?? 6A ?? A1 + } + $encrypt_files = { + 8D 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 7F ?? 7C ?? 83 7D ?? ?? 73 ?? + E9 ?? ?? ?? ?? 6A ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 4D ?? 2B C8 8B + 45 ?? 1B C2 89 4D ?? 89 45 ?? 6A ?? 8B 4D ?? 51 8B 55 ?? 52 6A ?? 6A ?? 8B 45 ?? 50 + FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 72 ?? + 81 7D ?? ?? ?? ?? ?? 73 ?? 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 6A ?? 8B 4D ?? 51 FF + 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? + ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? EB ?? E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? + EB ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 8B 4D ?? 51 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 + 45 + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ( all of ($enum_shares_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Bam2021 : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Bam2021 ransomware." + author = "ReversingLabs" + id = "31ae99e3-223c-51fb-97c1-353ff063057f" + date = "2021-09-17" + modified = "2021-09-17" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Bam2021.yara#L1-L167" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "5b717510991b78f07806e88f3dfe1c27d6ec1ec21af61a7c4f1edf7c915785d5" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Bam2021" + tc_detection_factor = 5 + importance = 25 + + strings: + $enum_shares = { + 83 EC ?? 53 55 8B 2D ?? ?? ?? ?? 56 57 68 ?? ?? ?? ?? FF D5 8B 74 24 ?? 6A ?? 56 C7 + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4C 24 + ?? 8D 44 24 ?? 50 51 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 89 06 33 C0 5F 5E + 5D 5B 83 C4 ?? C2 ?? ?? 8B 54 24 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 8B F8 89 7C 24 ?? 85 + FF 75 ?? 89 06 8B 44 24 ?? 50 6A ?? 57 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 8D 4C 24 + ?? 51 57 8D 54 24 ?? 52 50 E8 ?? ?? ?? ?? 8B F0 85 F6 0F 85 ?? ?? ?? ?? 33 DB 39 5C + 24 ?? 76 ?? 8D 77 ?? 90 33 C0 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 + 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 8B 06 50 C7 44 24 ?? ?? ?? ?? ?? 89 44 24 + ?? FF D5 6A ?? 6A ?? 6A ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 3E E8 ?? ?? + ?? ?? 8B 7C 24 ?? 8B 54 24 ?? 6A ?? 6A ?? 52 E8 ?? ?? ?? ?? 8B 46 ?? 83 E0 ?? 3C ?? + 75 ?? 8B 4C 24 ?? 8B 44 24 ?? 51 8D 56 ?? 52 50 E8 ?? ?? ?? ?? 43 83 C6 ?? 3B 5C 24 + ?? 0F 82 ?? ?? ?? ?? E9 ?? ?? ?? ?? 81 FE ?? ?? ?? ?? 74 ?? 56 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 89 31 57 FF 15 ?? ?? ?? ?? 8B 54 24 ?? 52 E8 ?? ?? ?? + ?? 8B F0 85 F6 74 ?? 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 89 30 33 + C0 5F 5E 5D 5B 83 C4 ?? C2 + } + $find_files_p1 = { + 8D 94 24 ?? ?? ?? ?? 52 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 + ?? 0F 84 ?? ?? ?? ?? 8B 7C 24 ?? EB ?? 8D A4 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 84 24 + ?? ?? ?? ?? 8D 64 24 ?? 66 8B 10 66 3B 11 75 ?? 66 3B D5 74 ?? 66 8B 50 ?? 66 3B 51 + ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D5 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 3B C5 0F 84 ?? + ?? ?? ?? B9 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 90 66 8B 10 66 3B 11 75 ?? 66 3B D5 74 + ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 3B D5 75 ?? 33 C0 EB ?? 1B C0 + 83 D8 ?? 3B C5 0F 84 ?? ?? ?? ?? F6 84 24 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 8C 24 + ?? ?? ?? ?? 51 BB ?? ?? ?? ?? 8D 74 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 9C 24 ?? ?? + ?? ?? 8D 74 24 ?? C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 55 8D 8C 24 + ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7C 24 ?? ?? 72 ?? 8B 54 24 ?? + 52 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C6 84 24 ?? ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 89 6C 24 ?? 66 89 44 24 ?? 72 ?? 8B 4C 24 ?? 51 E8 ?? ?? ?? ?? + 83 C4 ?? 8B 54 24 ?? 8B 44 24 ?? 42 3B C2 77 ?? 8D 5C 24 ?? E8 ?? ?? ?? ?? 8B 44 24 + ?? 8B 4C 24 ?? 8B 54 24 ?? 8D 34 0A 3B C6 77 ?? 2B F0 8B 44 24 ?? 39 2C B0 75 ?? 6A + ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 89 04 B1 8B 54 24 ?? 8B 0C B2 89 4C 24 ?? 89 + } + $find_files_p2 = { + 4C 24 ?? C6 84 24 ?? ?? ?? ?? ?? 3B CD 74 ?? 33 C0 C7 41 ?? ?? ?? ?? ?? 89 69 ?? 6A + ?? 66 89 41 ?? 55 8D 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? FF 44 + 24 ?? E9 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 73 ?? 8D 84 24 ?? + ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 51 50 68 ?? ?? ?? ?? 6A ?? 8D 94 24 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 47 ?? 50 8D 8C 24 ?? ?? ?? ?? 51 FF 15 ?? ?? + ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? BE ?? ?? ?? ?? 8B 16 52 8D 84 24 ?? + ?? ?? ?? 50 FF D3 85 C0 75 ?? 83 C6 ?? 81 FE ?? ?? ?? ?? 7C ?? E9 ?? ?? ?? ?? 57 8D + 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C0 ?? 8D 94 24 ?? ?? ?? ?? 2B D0 0F + B7 08 66 89 0C 02 83 C0 ?? 66 3B CD 75 ?? 33 C0 EB ?? 8D A4 24 ?? ?? ?? ?? 8D 49 ?? + 0F B7 8C 04 ?? ?? ?? ?? 66 89 8C 04 ?? ?? ?? ?? 83 C0 ?? 66 3B CD 75 ?? 33 C0 8D 9B + ?? ?? ?? ?? 0F B7 88 ?? ?? ?? ?? 66 89 8C 04 ?? ?? ?? ?? 83 C0 ?? 66 3B CD 75 ?? 8B + 5C 24 ?? 6A ?? B9 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 54 24 ?? 8D 8C + 24 ?? ?? ?? ?? 51 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 ?? 50 FF 15 + } + $encrypt_files_p1 = { + 55 8B EC 83 E4 ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? + ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 56 57 A1 ?? ?? ?? ?? 33 C4 50 8D 84 24 ?? ?? + ?? ?? 64 A3 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 DB 3B C3 75 ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 + 83 C4 ?? 3B F3 74 ?? 68 ?? ?? ?? ?? 8D 46 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 + EB ?? 33 C0 A3 ?? ?? ?? ?? 8D 4C 24 ?? 51 8B F8 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 + 24 ?? ?? ?? ?? 33 D2 53 89 9C 24 ?? ?? ?? ?? 50 66 89 94 24 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 33 C9 53 52 66 89 8C 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 33 C0 53 51 66 89 84 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 33 D2 53 50 66 89 54 + 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 33 C9 53 52 66 89 + 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 47 ?? 83 C4 ?? 50 89 5C 24 ?? 89 44 24 ?? E8 ?? + ?? ?? ?? 53 53 8D 84 24 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 83 EC ?? 8B + } + $encrypt_files_p2 = { + F4 33 C9 8D 84 24 ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? 89 5E ?? 89 64 24 ?? 66 89 4E ?? + 8D 50 ?? 90 66 8B 08 83 C0 ?? 66 3B CB 75 ?? 2B C2 D1 F8 50 8D 84 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 53 6A ?? 8D 94 24 ?? ?? ?? ?? 52 53 FF 15 ?? ?? ?? ?? + 85 C0 74 ?? 83 EC ?? 8B F4 33 C0 C7 46 ?? ?? ?? ?? ?? 89 5E ?? 66 89 46 ?? 8D 84 24 + ?? ?? ?? ?? 89 64 24 ?? 8D 50 ?? EB ?? 8D 49 ?? 66 8B 08 83 C0 ?? 66 3B CB 75 ?? 2B + C2 D1 F8 50 8D 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 53 6A ?? 8D 8C 24 + ?? ?? ?? ?? 51 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 83 EC ?? 8B F4 33 D2 C7 46 ?? ?? ?? + ?? ?? 89 5E ?? 8D 84 24 ?? ?? ?? ?? 66 89 56 ?? 89 64 24 ?? 8D 50 ?? EB ?? 8D 49 ?? + 66 8B 08 83 C0 ?? 66 3B CB 75 ?? 2B C2 D1 F8 50 8D 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 57 E8 ?? ?? ?? ?? 53 6A ?? 8D 44 24 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? + ?? ?? 8D 4C 24 ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 EC ?? 8B F4 33 D2 C7 46 ?? ?? + ?? ?? ?? 89 5E ?? 8D 44 24 ?? 66 89 56 ?? 89 64 24 ?? 8D 50 ?? 8D A4 24 ?? ?? ?? ?? + 66 8B 08 83 C0 ?? 66 3B CB 75 ?? 2B C2 D1 F8 50 8D 44 24 ?? E8 ?? ?? ?? ?? 57 E8 ?? + ?? ?? ?? 53 6A ?? 8D 84 24 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? + ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 EC ?? 8B F4 33 D2 C7 + } + $encrypt_files_p3 = { + 46 ?? ?? ?? ?? ?? 89 5E ?? 8D 84 24 ?? ?? ?? ?? 66 89 56 ?? 89 64 24 ?? 8D 50 ?? 90 + 66 8B 08 83 C0 ?? 66 3B CB 75 ?? 2B C2 D1 F8 50 8D 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 57 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 8D 44 24 ?? 50 53 6A ?? 53 53 53 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 89 5C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4C 24 ?? 51 FF 15 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B F8 53 + 57 E8 ?? ?? ?? ?? 8B 74 24 ?? 83 C4 ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8D 54 + 24 ?? 52 57 8B CE E8 ?? ?? ?? ?? 8B 74 24 ?? E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 74 24 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 8B 8C 24 ?? ?? ?? ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 8C 24 ?? + ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $generate_key = { + 50 C7 44 24 ?? ?? ?? ?? ?? F3 A5 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5D B8 ?? ?? ?? + ?? 5B 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C2 ?? ?? 8B 44 24 ?? 8D 4C 24 ?? 51 + 6A ?? 6A ?? 6A ?? 8D 54 24 ?? 52 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5D B8 ?? ?? + ?? ?? 5B 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C2 ?? ?? 8B 54 24 ?? 6A ?? 8D 4C + 24 ?? 51 6A ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5D B8 ?? ?? ?? ?? 5B 8B 4C 24 + ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C2 ?? ?? 8B 54 24 ?? 6A ?? 8D 44 24 ?? 50 8D 4C 24 + ?? 51 6A ?? 52 C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5D B8 ?? + ?? ?? ?? 5B 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C2 ?? ?? 8B 44 24 ?? C1 E8 ?? + 89 44 24 ?? 03 C3 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 5F 5E 5D B8 ?? ?? ?? + ?? 5B 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C2 ?? ?? 53 55 56 E8 ?? ?? ?? ?? 8B + 4C 24 ?? 83 C4 ?? 89 5C 24 ?? 83 C3 ?? 53 8D 44 24 ?? 50 56 6A ?? 6A ?? 6A ?? 51 FF + 15 ?? ?? ?? ?? 85 C0 75 ?? 5F 5E 5D B8 ?? ?? ?? ?? 5B 8B 4C 24 ?? 33 CC E8 ?? ?? ?? + ?? 83 C4 ?? C2 ?? ?? 8B 7C 24 ?? 8B 54 24 ?? 57 56 52 E8 ?? ?? ?? ?? 8B 44 24 ?? 56 + 89 38 E8 ?? ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 5F 5E 5D 5B 33 CC 33 C0 E8 ?? ?? ?? ?? 83 + C4 ?? C2 + } + $remote_connection = { + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 57 8D 44 24 ?? 50 68 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 50 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 89 46 ?? 83 + F8 ?? 74 ?? 8B 46 ?? 8D 7E ?? 83 E8 ?? 83 78 ?? ?? 7E ?? 8B 48 ?? 51 8B CF E8 ?? ?? + ?? ?? 8B 3F 57 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 54 24 ?? 52 89 44 24 ?? FF 15 ?? ?? + ?? ?? 85 C0 75 ?? 8B 46 ?? 50 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 C0 5F 8B 8C 24 + ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 8B 48 ?? 8B 11 8B 02 0F B7 56 + ?? B9 ?? ?? ?? ?? 52 89 44 24 ?? 66 89 4C 24 ?? FF 15 ?? ?? ?? ?? 8B 4E ?? 66 89 44 + 24 ?? 6A ?? 8D 44 24 ?? 50 51 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? FF 15 ?? ?? ?? ?? 8B + 56 ?? 52 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 C0 5F 8B 8C 24 ?? ?? ?? ?? 33 CC E8 + ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 8B 8C 24 ?? ?? ?? ?? 5F 33 CC B8 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 + } + + condition: + uint16(0)==0x5A4D and ($enum_shares) and ( all of ($find_files_p*)) and ($generate_key) and ( all of ($encrypt_files_p*)) and ($remote_connection) +} +rule REVERSINGLABS_Win64_Ransomware_Antiwar : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects AntiWar ransomware." + author = "ReversingLabs" + id = "3113ec26-e149-527b-9478-4dd86c7fa464" + date = "2022-04-21" + modified = "2022-04-21" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.AntiWar.yara#L1-L146" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "2d885f35454aaf7cb33f03c30b6681aa16cbe8353003bbae0b1e9fdecb2ff8a7" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "AntiWar" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files_p1 = { + 49 8B D7 49 8B CD FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? + 48 8D 95 ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? 4C 8B F0 48 89 44 24 ?? 48 83 F8 ?? + 0F 84 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? ?? 41 8B DC 48 8D 3D ?? ?? ?? ?? 66 90 48 8B 0F + E8 ?? ?? ?? ?? 48 8B D0 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? FF C3 48 83 C7 ?? 83 FB ?? 72 ?? 49 8B D7 49 8B CD FF 15 ?? ?? ?? ?? 48 8D 15 ?? + ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? + F6 85 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 66 0F 6F 35 ?? ?? 03 00 66 0F 6F 3D ?? ?? 03 + 00 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 C7 85 ?? ?? 00 00 ?? ?? 8B 05 ?? ?? ?? ?? 4C 8D + 3C C5 ?? ?? ?? ?? 41 BC ?? ?? ?? ?? 65 48 8B 04 25 ?? ?? ?? ?? 4A 8B 0C 38 41 8B 04 + 0C 39 05 ?? ?? ?? ?? 7E ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? + 75 ?? C6 05 ?? ?? ?? ?? ?? 0F 11 35 ?? ?? ?? ?? 0F 11 3D ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 89 05 ?? ?? ?? ?? 0F B7 85 ?? ?? ?? ?? 66 89 05 ?? ?? 04 00 48 8D 0D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 74 ?? 45 33 + C9 41 BA ?? ?? ?? ?? 4C 8D 35 ?? ?? ?? ?? 4D 2B D6 49 BB ?? ?? ?? ?? ?? ?? ?? ?? 66 + 66 0F 1F 84 00 ?? ?? 00 00 4B 8D 14 31 41 0F B6 C9 80 E1 ?? C0 E1 ?? 49 8B C3 48 D3 + } + $find_files_p2 = { + E8 30 02 4C 8D 42 ?? 41 8D 0C 12 80 E1 ?? C0 E1 ?? 49 8B D3 48 D3 EA 41 30 10 49 83 + C1 ?? 49 83 F9 ?? 72 ?? 4C 8B 74 24 ?? C6 05 ?? ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 48 8B D0 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 E8 ?? 48 63 C8 78 ?? 0F 1F 40 ?? 66 83 BC + 4D ?? ?? 00 00 ?? 74 ?? FF C8 48 83 E9 ?? 79 ?? EB ?? B3 ?? 48 98 4C 8D B5 ?? ?? ?? + ?? 4D 8D 34 46 48 8D 3D ?? ?? ?? ?? BE ?? ?? ?? ?? 45 33 ED 48 8B 0F E8 ?? ?? ?? ?? + 48 8B D0 49 8B CE FF 15 ?? ?? ?? ?? 0F B6 DB 85 C0 41 0F 44 DD 48 8D 7F ?? 48 83 EE + ?? 75 ?? 4C 8B 6C 24 ?? 4C 8B 74 24 ?? 84 DB 0F 84 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? ?? + 45 33 C0 49 8B D5 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 FF + 90 89 BD ?? ?? ?? ?? 4C 8D 85 ?? ?? ?? ?? 33 D2 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 48 8B D8 48 85 C0 0F 84 ?? ?? ?? ?? 66 0F 1F 84 00 ?? ?? 00 00 83 3D ?? ?? ?? ?? ?? + 0F 84 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 85 C9 0F 84 ?? ?? ?? ?? 83 79 ?? ?? 0F 8C + ?? ?? ?? ?? 66 0F 6F 35 ?? ?? 03 00 66 0F 6F 3D ?? ?? 03 00 66 C7 85 ?? ?? 00 00 ?? + ?? 65 48 8B 04 25 ?? ?? ?? ?? 4A 8B 0C 38 41 8B 04 0C 39 05 ?? ?? ?? ?? 7E ?? 48 8D + 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? C6 05 ?? ?? ?? ?? ?? 0F 11 + 35 ?? ?? ?? ?? 0F 11 3D ?? ?? ?? ?? 0F B7 85 ?? ?? ?? ?? 66 89 05 ?? ?? 04 00 48 8D + } + $find_files_p3 = { + 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? + ?? 74 ?? 48 8B C7 41 BA ?? ?? ?? ?? 4C 8D 35 ?? ?? ?? ?? 4D 2B D6 49 BB ?? ?? ?? ?? + ?? ?? ?? ?? 90 4E 8D 0C 30 0F B6 C8 80 E1 ?? C0 E1 ?? 4D 8B C3 49 D3 E8 45 30 01 43 + 8D 0C 11 80 E1 ?? C0 E1 ?? 49 8B D3 48 D3 EA 41 30 51 ?? 48 83 C0 ?? 48 83 F8 ?? 72 + ?? 4C 8B 74 24 ?? C6 05 ?? ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? C7 44 24 + ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 44 24 ?? 48 89 7D ?? 48 C7 45 ?? ?? ?? ?? ?? BA + ?? ?? ?? ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? + ?? ?? ?? 48 89 85 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 48 C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? 66 89 BD ?? ?? 00 00 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8D 15 ?? ?? ?? ?? + 48 8D 4D ?? E8 ?? ?? ?? ?? 48 8B D6 48 85 DB 48 0F 45 D3 48 8D 4D ?? E8 ?? ?? ?? ?? + 48 8B 3D ?? ?? ?? ?? 48 8B 5F ?? 48 3B 5F ?? 74 ?? 0F 1F 84 00 ?? ?? ?? ?? 48 8B 0B + } + $find_files_p4 = { + 48 8B 01 48 8D 54 24 ?? FF 50 ?? 48 83 C3 ?? 48 3B 5F ?? 75 ?? 48 8D 05 ?? ?? ?? ?? + 48 89 44 24 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 83 FA ?? + 72 ?? 48 FF C2 48 8B 8D ?? ?? ?? ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? + 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 FF + 48 89 BD ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 40 88 BD ?? ?? ?? ?? 48 8D 4D + ?? E8 ?? ?? ?? ?? EB ?? 48 8B CB E8 ?? ?? ?? ?? 48 8B CB E8 ?? ?? ?? ?? 4C 8D 85 ?? + ?? ?? ?? 33 D2 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B D8 48 85 C0 0F 85 ?? ?? ?? + ?? 45 33 C0 49 8B D5 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 45 + 33 E4 4C 8B 7C 24 ?? 48 8D 95 ?? ?? ?? ?? 49 8B CE FF 15 ?? ?? ?? ?? 85 C0 + } + $enum_shares = { + 48 83 EC ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 44 24 ?? 33 D2 C7 44 24 ?? ?? ?? ?? + ?? 48 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 4C 8B C9 48 89 44 24 ?? 8D 4A ?? 44 8D 42 + ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 4C 24 ?? 48 89 7C 24 ?? E8 ?? ?? ?? ?? + 48 8B F8 48 85 C0 0F 84 ?? ?? ?? ?? 48 8B 4C 24 ?? 4C 8D 4C 24 ?? 4C 8B C0 48 8D 54 + 24 ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 48 89 5C 24 ?? 33 DB 39 5C 24 ?? 76 ?? 0F 1F 84 00 + ?? ?? ?? ?? 48 8D 0C 5B 48 C1 E1 ?? 48 03 CF F6 41 ?? ?? 74 ?? E8 ?? ?? ?? ?? EB ?? + 48 8B 49 ?? E8 ?? ?? ?? ?? FF C3 3B 5C 24 ?? 72 ?? 48 8B 4C 24 ?? 4C 8D 4C 24 ?? 4C + 8B C7 48 8D 54 24 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 5C 24 ?? 48 8B CF E8 ?? ?? ?? + ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 48 8B 4C 24 ?? 48 33 CC E8 ?? ?? ?? + ?? 48 83 C4 ?? C3 + } + $encrypt_files_p1 = { + 48 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 45 33 C9 45 33 C0 BA + ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 4C 8B F0 48 8B 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 49 83 FE ?? 0F 84 ?? ?? ?? ?? 41 BD ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 49 + 8B CE FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8B F8 48 85 C0 0F 84 ?? ?? + ?? ?? 4C 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 80 + A5 ?? ?? ?? ?? ?? 0F B6 8D ?? ?? ?? ?? 80 E1 ?? 80 C9 ?? 88 8D ?? ?? ?? ?? 4C 8D 85 + ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? ?? + ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 85 ?? ?? ?? ?? + BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? 45 8B C1 48 8D + 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? + ?? ?? ?? 33 D2 44 8D 42 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 44 8D 42 ?? 48 + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 44 8D 42 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 48 8B DE 45 33 C9 45 33 C0 48 8B D6 49 8B CE FF 15 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? + ?? 48 81 F9 ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 F7 E9 48 + } + $encrypt_files_p2 = { + 8B FA 48 C1 FF ?? 48 8B C7 48 C1 E8 ?? 48 03 F8 48 85 FF 0F 8E ?? ?? ?? ?? 48 89 74 + 24 ?? 4C 8D 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 49 8B D7 49 8B CE FF 15 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 89 44 24 ?? 4D 8B CF 4D 8B C7 48 8D 95 ?? ?? ?? ?? 33 C9 E8 ?? ?? ?? + ?? 45 33 C9 45 33 C0 48 8B D3 49 8B CE FF 15 ?? ?? ?? ?? 48 89 74 24 ?? 4C 8D 8D ?? + ?? ?? ?? 41 B8 ?? ?? ?? ?? 49 8B D7 49 8B CE FF 15 ?? ?? ?? ?? 48 81 C3 ?? ?? ?? ?? + 45 33 C9 45 33 C0 48 8B D3 49 8B CE FF 15 ?? ?? ?? ?? 48 83 EF ?? 0F 85 ?? ?? ?? ?? + E9 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 83 78 ?? ?? 0F 8C ?? + ?? ?? ?? 41 8B C6 48 8D 1C C5 ?? ?? ?? ?? 65 48 8B 04 25 ?? ?? ?? ?? 48 8B 0C 18 8B + 04 0F 39 05 ?? ?? ?? ?? 7E ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? + ?? 75 ?? 66 C7 05 ?? ?? 05 00 ?? ?? C6 05 ?? ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 74 ?? 80 35 ?? ?? + ?? ?? ?? 80 35 ?? ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 65 48 8B 04 25 ?? ?? ?? ?? 48 8B + 0C 18 8B 04 0F 39 05 ?? ?? ?? ?? 7E ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 3D ?? + ?? ?? ?? ?? 75 ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D + } + + condition: + uint16(0)==0x5A4D and (( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($enum_shares)) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Povlsomware : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Povlsomware ransomware." + author = "ReversingLabs" + id = "317d7cca-4fe8-55ab-8f5f-e42be727ec26" + date = "2021-08-12" + modified = "2021-08-12" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Povlsomware.yara#L1-L64" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "465dc1b1d7e9eb3091f36efb51029cd3383d05ece054e814b18f379e58c7e457" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Povlsomware" + tc_detection_factor = 5 + importance = 25 + + strings: + $setup_attack = { + 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? + ?? ?? 73 ?? ?? ?? ?? 0A 06 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 2C ?? + 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 8E 69 80 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? + 0C 16 0D 2B ?? 08 09 9A 13 ?? 00 7E ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 00 00 09 17 58 0D + 09 08 8E 69 32 ?? 00 38 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 + ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 1A 6F ?? ?? ?? + ?? 00 11 ?? 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? + 13 ?? 2B ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 00 00 11 ?? 28 ?? ?? ?? ?? 00 00 DE ?? 26 00 00 + DE ?? 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC + 28 ?? ?? ?? ?? 00 00 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 00 2A + } + $find_files = { + 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? + ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 00 06 6F ?? ?? ?? ?? 0C 2B ?? + 08 6F ?? ?? ?? ?? 0D 00 7E ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 00 00 08 6F ?? ?? ?? ?? 2D ?? + DE ?? 08 2C ?? 08 6F ?? ?? ?? ?? 00 DC 02 28 ?? ?? ?? ?? 0B 00 07 13 ?? 16 13 ?? 38 ?? + ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 00 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 16 FE 01 2B ?? 16 13 ?? 11 ?? 2C ?? 00 11 ?? 03 28 ?? ?? ?? ?? 00 00 00 + DE ?? 26 00 00 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 2A + } + $encrypt_files = { + 00 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 06 2C ?? 2B ?? 02 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 6F ?? ?? ?? ?? 0B 07 2C ?? 2B ?? 02 28 ?? ?? ?? ?? 00 02 02 72 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 17 58 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 02 6F ?? ?? ?? + ?? 00 7E ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 2A + } + + condition: + uint16(0)==0x5A4D and ($setup_attack) and ($find_files) and ($encrypt_files) +} +import "pe" + +rule REVERSINGLABS_Win32_Ransomware_Cryptowall : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects CryptoWall ransomware." + author = "ReversingLabs" + id = "06d8b106-d69a-526a-8e16-c95d39eb2993" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.CryptoWall.yara#L3-L312" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "74baa04ee506732e0bb64a77cfd2d2216fcc978f13447ef07862e0116c093c14" + score = 75 + quality = 88 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "CryptoWall" + tc_detection_factor = 5 + importance = 25 + + strings: + $v30_entrypoint = { + 55 8B EC 83 EC ?? E8 ?? ?? ?? ?? 85 C0 0F 84 9A 00 00 00 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 7E C7 45 ?? ?? ?? ?? ?? + 8D 45 ?? 50 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 65 8B 4D ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 + E8 ?? ?? ?? ?? 8B 40 ?? A3 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 + 75 19 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A + ?? 6A ?? E8 ?? ?? ?? ?? 8B 50 ?? FF D2 33 C0 8B E5 5D C2 + } + $v20_entrypoint = { + 55 8B EC 83 EC ?? E8 ?? ?? ?? ?? 85 C0 0F 84 A3 00 00 00 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 85 83 00 00 00 C7 45 ?? + ?? ?? ?? ?? 8D 45 ?? 50 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 6A 8B 4D ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 90 ?? ?? + ?? ?? FF D2 E8 ?? ?? ?? ?? 8B 40 ?? A3 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 75 19 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 + E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B 50 ?? FF D2 33 C0 8B E5 5D C2 + } + $v30_api_load = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 50 01 00 00 8B 45 ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 34 01 00 00 B9 ?? ?? ?? ?? 6B D1 ?? 8B 45 ?? 8B 4D ?? 03 4C 10 ?? 89 4D ?? 8B + 55 ?? 8B 45 ?? 03 42 ?? 89 45 ?? 8B 4D ?? 8B 55 ?? 03 51 ?? 89 55 ?? 8B 45 ?? 8B 4D ?? 03 48 ?? 89 4D ?? C7 45 ?? ?? ?? + ?? ?? EB 09 8B 55 ?? 83 C2 ?? 89 55 ?? 8B 45 ?? 8B 4D ?? 3B 48 ?? 0F 83 DA 00 00 00 8B 55 ?? 8B 45 ?? 8B 4D ?? 03 0C 90 + 51 E8 ?? ?? ?? ?? 83 C4 ?? 3B 45 ?? 0F 85 B7 00 00 00 BA ?? ?? ?? ?? 6B C2 ?? 8B 4D ?? 8B 54 01 ?? 8B 44 01 ?? 89 55 ?? + 89 45 ?? 8B 4D ?? 8B 55 ?? 0F B7 04 4A 8B 4D ?? 8B 14 81 3B 55 ?? 76 71 8B 45 ?? 8B 4D ?? 0F B7 14 41 8B 45 ?? 03 45 ?? + 8B 4D ?? 39 04 91 73 59 8B 55 ?? 8B 45 ?? 0F B7 0C 50 8B 55 ?? 8B 45 ?? 03 04 8A 89 45 ?? 74 3F 6A ?? 8B 4D ?? 51 E8 ?? + ?? ?? ?? 83 C4 ?? 8B 55 ?? 8D 44 02 ?? 50 8D 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8D 45 ?? 50 6A ?? 8D 4D ?? + 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 40 ?? FF D0 EB 16 8B 4D ?? 8B 55 ?? 0F B7 04 4A 8B 4D ?? 8B 55 ?? 03 14 81 89 55 ?? EB + 05 E9 0E FF FF FF 8B 45 ?? 8B E5 5D C3 + } + $v30_dll_load = { + 55 8B EC 83 EC ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 58 8B 45 ?? 8B 48 ?? 89 4D ?? 8B 55 ?? 83 C2 ?? 89 55 ?? 8B 45 + ?? 8B 08 89 4D ?? 8B 55 ?? 3B 55 ?? 74 36 8B 45 ?? 89 45 ?? 8B 4D ?? 0F B7 51 ?? D1 EA 52 8B 45 ?? 8B 48 ?? 51 E8 ?? ?? + ?? ?? 83 C4 ?? 3B 45 ?? 75 08 8B 55 ?? 8B 42 ?? EB 0C 8B 45 ?? 8B 08 89 4D ?? EB C2 33 C0 8B E5 5D C3 + } + $v30_calculate_hash = { + 55 8B EC 83 EC ?? 56 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 5E 83 7D ?? ?? 74 58 8B 45 ?? 89 45 ?? 8B 4D ?? 89 4D ?? 8B 55 + ?? 83 EA ?? 89 55 ?? 83 7D ?? ?? 74 3D 8B 45 ?? 66 8B 08 66 89 4D ?? 8B 75 ?? C1 EE ?? 0F B7 55 ?? 52 E8 ?? ?? ?? ?? 83 + C4 ?? 0F B7 C0 33 45 ?? 25 ?? ?? ?? ?? 33 34 85 ?? ?? ?? ?? 89 75 ?? 8B 4D ?? 83 C1 ?? 89 4D ?? EB AE 8B 45 ?? 83 F0 ?? + 5E 8B E5 5D C3 + } + $v30_1_find_file_1 = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 47 02 00 00 E8 ?? ?? ?? ?? 89 45 + ?? 83 7D ?? ?? 0F 84 32 02 00 00 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 8B 4D ?? 0F B7 54 41 ?? 83 FA ?? 74 16 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 68 + ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? + ?? 0F 84 B2 01 00 00 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 84 01 00 + 00 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 8B 11 83 E2 ?? 0F 85 A0 00 00 00 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 85 C0 0F 85 80 00 00 00 8D 4D ?? 51 8B 55 ?? 83 C2 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 69 C7 45 ?? ?? ?? + ?? ?? 8D 45 ?? 50 8B 4D ?? 83 C1 ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 47 8B 45 ?? 50 8B 4D ?? 8B 11 52 8B + 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 75 1C 8B 4D ?? 83 C1 ?? 89 4D ?? 8B 55 ?? 8B 42 ?? 50 8B 4D ?? 51 + } + $v30_1_find_file_2 = { + E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? EB 67 8B 45 ?? 83 C0 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 + 54 C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 51 8B 55 ?? 83 C2 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 32 8B 4D ?? 51 E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 75 16 8B 55 ?? 52 8B 45 ?? 50 E8 30 FE FF FF 83 C4 ?? 03 45 ?? 89 45 ?? 8B 4D ?? 51 E8 ?? ?? + ?? ?? 83 C4 ?? 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 0F 85 CE FE FF FF 8B 55 ?? 52 E8 ?? + ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 7D ?? ?? 74 2E 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 + C4 ?? 3D ?? ?? ?? ?? 74 0E 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 89 4D ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 + ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 8B E5 5D C3 + } + $v30_2_find_file_1 = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 ( 3B | 3D ) 02 00 00 E8 ?? ?? ?? + ?? 89 45 ?? 83 7D ?? ?? 0F 84 ( 26 | 28 ) 02 00 00 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 0F B7 54 41 ?? 83 FA ?? 74 16 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? + ?? ?? ?? FF D1 68 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 89 45 ?? 83 7D ?? ?? 0F 84 ( A6 | A8 ) 01 00 00 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 89 45 ?? + 83 7D ?? ?? 0F 84 ( 78 | 7A ) 01 00 00 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 8B 11 83 E2 ?? 0F 85 94 00 00 00 C7 45 ?? ?? ?? ?? + ?? 8B 45 ?? 83 C0 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 78 8B 4D ?? 83 C1 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 65 C7 + 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 83 C0 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 43 8B 55 ?? 8B 02 50 8B + } + $v30_2_find_file_2 = { + 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 75 1C 8B 55 ?? 83 C2 ?? 89 55 ?? 8B 45 ?? 8B 48 ?? 51 8B 55 ?? 52 + E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB 67 8B 4D ?? 83 C1 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 + 54 C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 83 C0 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 32 8B 55 ?? 52 E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 75 16 8B 45 ?? 50 8B 4D ?? 51 E8 3C FE FF FF 83 C4 ?? 03 45 ?? 89 45 ?? 8B 55 ?? 52 E8 ?? ?? + ?? ?? 83 C4 ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 0F 85 DA FE FF FF 8B 45 ?? 50 E8 ?? + ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 83 7D ?? ?? 74 ( 2E | 30 ) 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 50 8B 45 ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 3D ?? ?? ?? ?? 74 ( 0E | 10 ) 6A ?? [0-2] 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 89 55 ?? 8B 45 ?? + 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 8B E5 5D C3 + } + $v30_3_find_file_1 = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 7C 02 00 00 E8 ?? ?? ?? ?? 89 45 + ?? 83 7D ?? ?? 0F 84 67 02 00 00 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 8B 4D ?? 0F B7 54 41 ?? 83 FA ?? 74 16 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 68 + ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? + ?? 0F 84 E7 01 00 00 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 B9 01 00 + 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 83 C1 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 91 00 00 00 8D 55 + ?? 52 8B 45 ?? 83 C0 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 7A 8B 4D ?? 8B 11 83 E2 ?? 75 70 C7 45 ?? ?? ?? ?? ?? 8D 45 + ?? 50 8B 4D ?? 83 C1 ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 49 8B 45 ?? 8B 48 ?? 51 8B 55 ?? 52 8B 45 ?? 8B + } + $v30_3_find_file_2 = { + 08 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 1C 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 8B 51 ?? 52 8B 45 ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? E9 88 00 00 00 8B 55 ?? 8B 02 83 E0 ?? 74 7E 8B 4D ?? 83 79 ?? ?? + 74 75 8B 55 ?? 83 C2 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 62 C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 8B 4D ?? 83 C1 ?? 51 8B + 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 40 8B 45 ?? 50 8B 4D ?? 8B 51 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 1D 8B 45 + ?? 50 8B 4D ?? 51 E8 15 FE FF FF 83 C4 ?? 85 C0 74 09 8B 55 ?? 83 C2 ?? 89 55 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B + 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 85 C0 0F 85 AC FE FF FF 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? + ?? ?? ?? FF D2 8B 45 ?? 50 8B 4D ?? 8B 51 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 74 2E 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 3D ?? ?? ?? ?? 74 0E 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 89 + 45 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 8B E5 5D C3 + } + $v20_1_encrypt_file_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 56 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 99 05 00 00 8B 45 ?? + 83 38 ?? 74 1B 8B 4D ?? 83 79 ?? ?? 74 12 8B 55 ?? 83 7A ?? ?? 74 09 8B 45 ?? 83 78 ?? ?? 75 08 8B 45 ?? E9 6E 05 00 00 + 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 89 45 ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? + ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 F4 04 00 00 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8B + 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 74 07 C7 45 ?? ?? ?? ?? ?? 66 0F 57 C0 66 0F 13 45 ?? 8D 45 ?? 50 + 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 E7 03 00 00 66 0F 57 C0 66 0F 13 85 ?? ?? ?? ?? 6A ?? 6A ?? + 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 F8 ?? 0F 84 AF 03 00 00 + 8D 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 97 03 00 00 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B + 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 0F 84 6A 03 00 00 C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 2C 03 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? 8D 45 ?? 50 8D 4D ?? 51 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 D9 02 00 00 + } + $v20_1_encrypt_file_2 = { + C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 8B 48 ?? 51 8B 55 ?? + 8B 02 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 81 02 00 00 C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 8B 42 ?? 50 8B + 4D ?? 8B 51 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 0F 84 41 02 00 00 8B 55 ?? 8B 45 ?? 3B 42 ?? + 0F 85 32 02 00 00 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 0F + 84 0B 02 00 00 8B 45 ?? 3B 45 ?? 0F 85 FF 01 00 00 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 C7 45 ?? ?? ?? ?? + ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 CE 01 00 00 66 0F 57 C0 66 0F 13 45 ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 3B 4D ?? 75 0C 8B 55 ?? 3B 55 ?? 0F 84 73 01 00 00 C7 45 ?? ?? + ?? ?? ?? 8B 45 ?? 33 C9 8B 55 ?? 2B 55 ?? 8B 75 ?? 1B 75 ?? 89 85 ?? ?? ?? ?? 89 4D ?? 89 55 ?? 89 75 ?? 8B 45 ?? 3B 45 + ?? 77 1A 72 0B 8B 8D ?? ?? ?? ?? 3B 4D ?? 73 0D 8B 55 ?? 33 C0 89 55 ?? 89 45 ?? EB 12 8B 4D ?? 2B 4D ?? 8B 55 ?? 1B 55 + ?? 89 4D ?? 89 55 ?? 8B 45 ?? 89 45 ?? 8B 4D ?? 33 D2 03 4D ?? 13 55 ?? 89 8D ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 3B 45 ?? 75 12 8B 8D ?? ?? ?? ?? 3B 4D ?? 75 07 C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B + } + $v20_1_encrypt_file_3 = { + 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 85 C0 0F 84 A2 00 00 00 8B 4D ?? 3B 4D ?? 0F 85 96 00 00 00 C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 74 60 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF + D1 85 C0 74 31 8B 55 ?? 3B 55 ?? 75 29 8B 45 ?? 33 C9 03 45 ?? 13 4D ?? 89 45 ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? + 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 75 02 EB 0D 83 7D ?? ?? 74 02 + EB 05 E9 79 FE FF FF 83 7D ?? ?? 74 17 8B 55 ?? 3B 55 ?? 75 0F 8B 45 ?? 3B 45 ?? 75 07 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 51 + E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? + ?? 8B 90 ?? ?? ?? ?? FF D2 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? + ?? ?? ?? FF D0 83 7D ?? ?? 74 0C 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 + 83 7D ?? ?? 75 22 6A ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 85 C0 75 07 C7 45 ?? ?? ?? ?? ?? + 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 74 60 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? + 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 74 37 8D 95 ?? ?? ?? ?? 52 8D 85 + ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 + ?? ?? ?? ?? FF D2 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 ?? 5E 8B E5 5D C3 + } + $v30_1_encrypt_file_1 = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 02 05 00 00 8B 45 ?? 83 38 ?? 74 + 09 8B 4D ?? 83 79 ?? ?? 75 08 8B 45 ?? E9 E9 04 00 00 C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? + FF D0 89 45 ?? 6A ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B + 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 0F 84 6F 04 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 0F 85 90 03 00 00 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 83 F8 ?? 0F 84 70 03 + 00 00 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 0F 84 50 03 00 00 8D 55 ?? 52 8B 45 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 38 03 00 00 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? + ?? ?? 8B 90 ?? ?? ?? ?? FF D2 89 45 ?? 83 7D ?? ?? 0F 84 04 03 00 00 6A ?? 6A ?? 8B 45 ?? 8B 48 ?? 51 8B 55 ?? 52 E8 ?? + ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 F8 ?? 0F 84 CC 02 00 00 8B 4D ?? 3B 4D ?? 73 08 8B 55 ?? 89 55 ?? EB 06 8B 45 ?? 89 + 45 ?? 8B 4D ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 6A ?? 6A ?? 8B 45 ?? 8B 08 51 E8 ?? ?? ?? + ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 0F 84 73 01 00 00 8B 45 ?? 8B 48 ?? 83 E9 ?? 89 4D ?? 8B 55 ?? D1 E2 89 55 ?? 8B 45 ?? + } + $v30_1_encrypt_file_2 = { + 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 35 01 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 2B 4D ?? 39 4D ?? 73 08 8B 55 ?? 89 55 ?? EB 09 8B 45 ?? 2B 45 ?? 89 45 ?? 8B 4D + ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? + FF D0 85 C0 0F 84 94 00 00 00 8B 4D ?? 3B 4D ?? 0F 85 88 00 00 00 8B 55 ?? 3B 55 ?? 73 07 C7 45 ?? ?? ?? ?? ?? 83 7D ?? + ?? 74 73 8B 45 ?? 89 45 ?? 8B 4D ?? 51 8D 55 ?? 52 8B 45 ?? 50 6A ?? 8B 4D ?? 51 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 + ?? ?? ?? ?? FF D0 85 C0 74 44 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF + D2 85 C0 74 21 8B 45 ?? 3B 45 ?? 75 19 8B 4D ?? 03 4D ?? 89 4D ?? 8B 55 ?? 03 55 ?? 89 55 ?? C7 45 ?? ?? ?? ?? ?? 83 7D + ?? ?? 74 06 83 7D ?? ?? 74 02 EB 0C 8B 45 ?? 3B 45 ?? 0F 85 FB FE FF FF 8B 4D ?? 3B 4D ?? 75 07 C7 45 ?? ?? ?? ?? ?? 8B + 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 83 7D ?? ?? 0F 85 02 01 00 00 C7 45 + ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 F8 ?? 0F 84 DB 00 00 00 6A ?? 8D + 4D ?? 51 8B 55 ?? 8B 42 ?? 50 8B 4D ?? 8B 51 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 0F 84 AE 00 + } + $v30_1_encrypt_file_3 = { + 00 00 8B 55 ?? 8B 45 ?? 3B 42 ?? 0F 85 9F 00 00 00 6A ?? 8D 4D ?? 51 6A ?? 8D 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 + ?? ?? ?? ?? FF D1 85 C0 74 7E 83 7D ?? ?? 75 78 8B 55 ?? 3B 55 ?? 74 1B 8B 45 ?? 8B 4D ?? 03 48 ?? 89 4D ?? 8B 55 ?? 2B + 55 ?? 89 55 ?? 8B 45 ?? 89 45 ?? 6A ?? 8D 4D ?? 51 6A ?? 8D 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 + 85 C0 74 34 83 7D ?? ?? 75 2E 6A ?? 8D 55 ?? 52 6A ?? 8D 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 + C0 74 0D 83 7D ?? ?? 75 07 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 EB 07 C7 45 ?? ?? ?? + ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 7D ?? ?? 75 71 83 7D ?? ?? 75 28 83 7D ?? ?? 75 22 68 ?? ?? + ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 07 C7 45 ?? ?? ?? ?? ?? EB 43 83 7D ?? ?? 74 36 83 7D ?? + ?? 74 30 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 + 74 07 C7 45 ?? ?? ?? ?? ?? EB 07 C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? EB 07 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 8B 45 ?? 8B E5 5D C3 + } + $v30_2_encrypt_file_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 56 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 BF 05 00 00 8B 45 ?? + 83 38 ?? 74 1B 8B 4D ?? 83 79 ?? ?? 74 12 8B 55 ?? 83 7A ?? ?? 74 09 8B 45 ?? 83 78 ?? ?? 75 08 8B 45 ?? E9 94 05 00 00 + 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 89 45 ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? + ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 1A 05 00 00 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8B + 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 74 07 C7 45 ?? ?? ?? ?? ?? 66 0F 57 C0 66 0F 13 45 ?? 8D 45 ?? 50 + 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 0D 04 00 00 66 0F 57 C0 66 0F 13 85 ?? ?? ?? ?? 6A ?? 6A ?? + 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 F8 ?? 0F 84 D5 03 00 00 + 8D 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 BD 03 00 00 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B + 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 0F 84 90 03 00 00 C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 52 03 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? 8D 45 ?? 50 8D 4D ?? 51 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 FF 02 00 00 + } + $v30_2_encrypt_file_2 = { + C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 8B 48 ?? 51 8B 55 ?? + 8B 02 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 A7 02 00 00 C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 8B 42 ?? 50 8B + 4D ?? 8B 51 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 0F 84 67 02 00 00 8B 55 ?? 8B 45 ?? 3B 42 ?? + 0F 85 58 02 00 00 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 0F + 84 31 02 00 00 8B 45 ?? 3B 45 ?? 0F 85 25 02 00 00 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 C7 45 ?? ?? ?? ?? + ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 F4 01 00 00 66 0F 57 C0 66 0F 13 45 ?? C7 45 ?? ?? ?? + ?? ?? 66 0F 57 C0 66 0F 13 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 3B 4D ?? 75 0C 8B 55 ?? 3B 55 ?? 0F + 84 90 01 00 00 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 33 C9 8B 55 ?? 2B 55 ?? 8B 75 ?? 1B 75 ?? 89 85 ?? ?? ?? ?? 89 8D ?? ?? ?? + ?? 89 95 ?? ?? ?? ?? 89 75 ?? 8B 85 ?? ?? ?? ?? 3B 45 ?? 77 1D 72 0E 8B 8D ?? ?? ?? ?? 3B 8D ?? ?? ?? ?? 73 0D 8B 55 ?? + 33 C0 89 55 ?? 89 45 ?? EB 12 8B 4D ?? 2B 4D ?? 8B 55 ?? 1B 55 ?? 89 4D ?? 89 55 ?? 8B 45 ?? 89 45 ?? 8B 4D ?? 33 D2 03 + 4D ?? 13 55 ?? 89 8D ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B 45 ?? 75 12 8B 8D ?? ?? ?? ?? 3B 4D ?? 75 07 C7 + 45 ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 85 C0 0F + 84 B3 00 00 00 8B 4D ?? 3B 4D ?? 0F 85 A7 00 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 8B + } + $v30_2_encrypt_file_3 = { + 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 71 6A ?? 8D 45 ?? 50 8B 4D ?? + 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 74 42 8B 55 ?? 3B 55 ?? 75 3A 8B 45 ?? 33 C9 03 + 45 ?? 13 4D ?? 89 45 ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 33 C0 03 55 ?? 13 45 ?? 89 55 ?? 89 45 ?? 8B 4D ?? 51 E8 + ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 75 02 EB 0D 83 7D ?? ?? 74 02 EB 05 + E9 5C FE FF FF 83 7D ?? ?? 74 17 8B 4D ?? 3B 4D ?? 75 0F 8B 55 ?? 3B 55 ?? 75 07 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B + 88 ?? ?? ?? ?? FF D1 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? + ?? FF D2 83 7D ?? ?? 74 0C 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 83 7D + ?? ?? 75 22 6A ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 75 07 C7 45 ?? ?? ?? ?? ?? 8B 45 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 74 60 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? + ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 74 37 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? + ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? + ?? ?? FF D1 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 8B 45 ?? 5E 8B E5 5D C3 + } + $v30_3_encrypt_file_1 = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 75 08 8B 45 ?? E9 48 04 00 00 83 7D ?? ?? 75 08 8B 45 ?? E9 3A 04 00 + 00 8B 45 ?? 83 78 ?? ?? 74 11 8B 4D ?? 83 39 ?? 74 09 8B 55 ?? 83 7A ?? ?? 75 08 8B 45 ?? E9 18 04 00 00 C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 6A ?? 8B 55 + ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B + 90 ?? ?? ?? ?? FF D2 89 45 ?? 83 7D ?? ?? 0F 84 90 03 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 + 83 00 00 00 8B 45 ?? 8B 48 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 74 6B 6A ?? 8D 55 ?? 52 8B 45 ?? 8B 48 ?? + 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 74 39 8B 55 ?? 3B 15 ?? ?? ?? ?? 75 2E 8B 45 ?? + 8B 48 ?? 51 8B 55 ?? 8B 42 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 50 ?? FF D2 85 C0 75 0E C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 0F 84 9A 02 00 00 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? + 8B 90 ?? ?? ?? ?? FF D2 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 0F 84 63 02 00 00 + 8B 55 ?? 3B 55 ?? 0F 87 57 02 00 00 8D 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 3F 02 00 00 6A ?? 6A + } + $v30_3_encrypt_file_2 = { + 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 0B 02 00 + 00 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 81 E1 ?? ?? ?? ?? 74 1C 6A ?? 6A ?? 8B 15 ?? ?? ?? ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B + 88 ?? ?? ?? ?? FF D1 C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? + FF D0 85 C0 0F 84 52 01 00 00 C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 51 6A ?? 6A ?? 8B 55 ?? 8B 02 50 8B 4D ?? 8B 51 ?? 52 8B 45 + ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 0F 84 0A 01 00 00 8B 55 ?? 8B 42 ?? 83 E8 ?? 89 45 ?? 8B 4D ?? D1 E1 + 89 4D ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 CC 00 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? + ?? ?? 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 74 76 8B 55 ?? + 3B 55 ?? 73 07 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 5F 8B 45 ?? 50 8D 4D ?? 51 8B 55 ?? 52 6A ?? 8B 45 ?? 50 6A ?? 8B 4D + ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 74 21 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? + ?? ?? 8B 88 ?? ?? ?? ?? FF D1 EB 15 83 7D ?? ?? 74 0D 83 7D ?? ?? 74 07 C7 45 ?? ?? ?? ?? ?? EB 0E EB 02 EB 0A 83 7D ?? + ?? 0F 84 54 FF FF FF 83 7D ?? ?? 74 07 C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? + } + $v30_3_encrypt_file_3 = { + ?? 8B 88 ?? ?? ?? ?? FF D1 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 7D ?? ?? 75 47 8B 4D ?? 81 E1 ?? + ?? ?? ?? 74 3C 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 6A ?? 8D 4D ?? 51 8B 55 ?? 8B 42 ?? + 50 8B 4D ?? 8B 51 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? + FF D0 EB 07 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 83 7D ?? ?? 75 20 68 ?? ?? ?? ?? 8B + 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 07 C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB 07 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 + 8B 45 ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and ((($v30_entrypoint at pe.entry_point) and $v30_api_load and $v30_calculate_hash and $v30_dll_load and $v30_1_find_file_1 and $v30_1_find_file_2 and $v30_1_encrypt_file_1 and $v30_1_encrypt_file_2 and $v30_1_encrypt_file_3) or (($v30_entrypoint at pe.entry_point) and $v30_api_load and $v30_calculate_hash and $v30_dll_load and $v30_2_find_file_1 and $v30_2_find_file_2 and $v30_2_encrypt_file_1 and $v30_2_encrypt_file_2 and $v30_2_encrypt_file_3) or (($v20_entrypoint at pe.entry_point) and $v30_api_load and $v30_calculate_hash and $v30_dll_load and $v30_2_find_file_1 and $v30_2_find_file_2 and $v20_1_encrypt_file_1 and $v20_1_encrypt_file_2 and $v20_1_encrypt_file_3) or (($v30_entrypoint at pe.entry_point) and $v30_api_load and $v30_calculate_hash and $v30_dll_load and $v30_3_find_file_1 and $v30_3_find_file_2 and $v30_3_encrypt_file_1 and $v30_3_encrypt_file_2 and $v30_3_encrypt_file_3)) +} +rule REVERSINGLABS_Win32_Ransomware_Torrentlocker : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects TorrentLocker ransomware." + author = "ReversingLabs" + id = "64bdb0db-ea0c-5a0d-9d3e-db1df86c132b" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.TorrentLocker.yara#L1-L98" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "f1aa523fa95e142b7e421286d26918e3da4bd3e268fef3f98f00820296291bfc" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "TorrentLocker" + tc_detection_factor = 5 + importance = 25 + + strings: + $tlocker_ep = { + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 05 E8 ?? ?? ?? ?? 33 C0 C3 + } + $tlocker_contact_server_1 = { + 55 8B EC 83 EC ?? 8D 45 ?? 50 8D 4D ?? 51 B8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 21 83 7D + ?? ?? 8B 45 ?? 75 05 8B 10 89 55 ?? 85 C0 74 0F 50 A1 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 53 56 57 8D 9B ?? ?? ?? ?? + 8B 4D ?? 8D 55 ?? 52 6A ?? BB ?? ?? ?? ?? 89 4D ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 89 75 ?? 85 F6 0F 84 2C 01 00 00 8B BE + ?? ?? ?? ?? 81 C7 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 85 DB 0F 84 EB 00 00 00 6A ?? 68 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 89 00 00 00 8D 45 ?? 50 8D + 4D ?? 51 6A ?? 56 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 16 81 4D ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 6A ?? 56 FF + 15 ?? ?? ?? ?? 8B 45 ?? 57 50 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 38 6A ?? 8D 4D ?? 51 8D 55 ?? 52 68 ?? ?? ?? ?? + 56 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 10 81 7D ?? ?? ?? ?? ?? 75 07 C7 45 ?? ?? ?? ?? + ?? 8B 3D ?? ?? ?? ?? 56 FF D7 EB 06 8B 3D ?? ?? ?? ?? 8D 45 ?? 50 8D 4D ?? 51 6A ?? 53 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 53 8B F0 FF D7 85 F6 74 06 8B 55 ?? 52 FF D7 8B 75 ?? 8B 0D ?? ?? ?? ?? 33 C0 83 7D ?? ?? 56 + 0F 94 C0 6A ?? 51 8B F8 FF 15 ?? ?? ?? ?? 85 FF 75 10 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E9 9E FE FF FF 5F 5E 5B 8B E5 5D + C3 + } + $tlocker_contact_server_2_1 = { + 55 8B EC 83 EC ?? 8D 45 ?? 50 8D 4D ?? 51 B8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 21 83 7D + ?? ?? 8B 45 ?? 75 05 8B 10 89 55 ?? 85 C0 74 0F 50 A1 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 53 56 57 8D 9B ?? ?? ?? ?? + 8B 4D ?? 8D 55 ?? 52 6A ?? BF ?? ?? ?? ?? 89 4D ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 89 75 ?? 85 F6 0F 84 E5 01 00 00 BF ?? + ?? ?? ?? 39 3D ?? ?? ?? ?? 74 11 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B + 9E ?? ?? ?? ?? 81 C3 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 85 FF 0F 84 EB 00 00 00 6A ?? 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 89 00 00 00 8D 45 ?? 50 + 8D 4D ?? 51 6A ?? 56 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 16 81 4D ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 6A ?? 56 + FF 15 ?? ?? ?? ?? 8B 45 ?? 53 50 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 38 6A ?? 8D 4D ?? 51 8D 55 ?? 52 68 ?? ?? ?? + ?? 56 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 10 81 7D ?? ?? ?? ?? ?? 75 07 C7 45 ?? ?? ?? + ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 EB 06 8B 35 ?? ?? ?? ?? 8D 45 ?? 50 8D 4D ?? 51 6A ?? 57 C7 45 ?? ?? ?? ?? ?? C7 45 ?? + } + $tlocker_contact_server_2_2 = { + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 57 8B D8 FF D6 85 DB 74 06 8B 55 ?? 52 FF D6 8B 75 ?? 33 C0 83 7D ?? ?? 0F 94 C0 8B F8 85 + FF 74 18 8B 0D ?? ?? ?? ?? 89 0D ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? EB 5E 8B 15 ?? ?? ?? ?? 3B 15 ?? ?? ?? ?? 75 + 34 FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B D1 41 89 0D ?? ?? ?? ?? 85 D2 7E 71 8B 0D ?? ?? ?? ?? 3B C1 73 08 8B C8 89 0D + ?? ?? ?? ?? 2B C1 3D ?? ?? ?? ?? 72 1C A1 ?? ?? ?? ?? 40 83 F8 ?? 7E 05 A1 ?? ?? ?? ?? 8B C8 A3 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 81 3D ?? ?? ?? ?? ?? ?? ?? ?? 75 0B 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 56 6A ?? 50 FF 15 ?? ?? ?? ?? 85 + FF 75 17 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E9 E5 FD FF FF A3 ?? ?? ?? ?? EB BF 5F 5E 5B 8B E5 5D C3 + } + $tlocker_get_server_data = { + 55 8B EC 83 EC ?? 56 57 33 FF 57 57 8D 45 ?? 50 53 33 F6 FF 15 ?? ?? ?? ?? 85 C0 74 77 8D 49 ?? 8B 4D ?? 03 CF 85 F6 75 + 73 33 C0 85 C9 74 0F 8B 15 ?? ?? ?? ?? 51 50 52 FF 15 ?? ?? ?? ?? 33 C9 85 C0 0F 95 C1 8B F0 8B C1 85 C0 74 33 8B 55 ?? + 8D 4D ?? 51 52 8D 04 37 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 1C 8B 45 ?? 85 C0 74 ?? 6A ?? 6A ?? 8D 4D ?? 51 53 03 F8 FF 15 + ?? ?? ?? ?? 85 C0 75 A0 85 F6 74 10 8B 0D ?? ?? ?? ?? 56 6A ?? 51 FF 15 ?? ?? ?? ?? 5F 33 C0 5E 8B E5 5D C3 + } + $tlocker_remove_shadow_copies = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? A1 ?? ?? ?? ?? 53 57 6A ?? 33 FF 57 50 FF 15 ?? ?? ?? ?? 8B D8 + 3B DF 0F 84 DC 00 00 00 56 8D B5 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 0A C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 73 5E B8 ?? ?? ?? ?? 8B D3 2B D0 0F B7 08 66 89 0C + 02 83 C0 ?? 66 3B CF 75 F1 6A ?? 8D 95 ?? ?? ?? ?? 57 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? + 51 8D 95 ?? ?? ?? ?? 52 57 68 ?? ?? ?? ?? 57 57 57 53 57 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 0F FF + 15 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 8B F8 83 BD ?? ?? ?? ?? ?? 74 0B 8B B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 53 + 6A ?? 50 FF 15 ?? ?? ?? ?? 5E 8B C7 5F 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 4D ?? 5F 33 CD B8 ?? ?? ?? ?? 5B + E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $tlocker_find_files = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 0D ?? ?? ?? ?? 8B 45 ?? 53 56 57 68 ?? ?? ?? ?? 33 F6 56 51 + 89 85 ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 85 DB 0F 84 AD 01 00 00 53 56 56 6A ?? 56 FF 15 ?? ?? ?? ?? + 85 C0 0F 88 89 01 00 00 68 ?? ?? ?? ?? 53 53 FF 15 ?? ?? ?? ?? 8B C3 8D 50 ?? 8D 9B ?? ?? ?? ?? 66 8B 08 83 C0 ?? 66 85 + C9 75 F5 2B C2 D1 F8 8B F8 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 85 C0 0F 84 4D 01 00 00 8D 95 ?? ?? ?? ?? 52 50 FF 15 ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? 85 C0 0F 84 15 01 00 00 F6 85 ?? ?? ?? ?? ?? 0F 84 EC 00 00 00 B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? + 66 8B 10 66 3B 11 75 1E 66 85 D2 74 15 66 8B 50 ?? 66 3B 51 ?? 75 0F 83 C0 ?? 83 C1 ?? 66 85 D2 75 DE 33 C0 EB 05 1B C0 + 83 D8 ?? 85 C0 0F 84 AE 00 00 00 B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 1E 66 85 D2 74 15 66 8B 50 ?? 66 + 3B 51 ?? 75 0F 83 C0 ?? 83 C1 ?? 66 85 D2 75 DE 33 C0 EB 05 1B C0 83 D8 ?? 85 C0 74 74 8D 85 ?? ?? ?? ?? 8D 50 ?? 8B FF + 66 8B 08 83 C0 ?? 66 85 C9 75 F5 2B C2 D1 F8 03 C7 8D 44 00 ?? 85 C0 74 6C 50 A1 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? + 8B F0 85 F6 74 57 53 8D 4F ?? 51 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 56 56 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 0A C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 52 FF + 15 ?? ?? ?? ?? 85 C0 0F 85 EB FE FF FF 8B 85 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 50 6A ?? 51 FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? + ?? 8B 15 ?? ?? ?? ?? 53 6A ?? 52 FF 15 ?? ?? ?? ?? 8B 4D ?? 5F 8B C6 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and (($tlocker_ep and $tlocker_get_server_data and $tlocker_remove_shadow_copies and $tlocker_find_files) and ($tlocker_contact_server_1 or ($tlocker_contact_server_2_1 and $tlocker_contact_server_2_2))) +} +rule REVERSINGLABS_Win64_Ransomware_Seedlocker : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects SeedLocker ransomware." + author = "ReversingLabs" + id = "efa3dd2e-faf4-5882-aef8-85189e65f0f9" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.SeedLocker.yara#L1-L91" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "a478efcfb03e3eeebe72d9a71629456cf061c3c779fbdde99539854caf8c7c33" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "SeedLocker" + tc_detection_factor = 5 + importance = 25 + + strings: + $search_files = { + 48 89 5C 24 ?? 48 89 7C 24 ?? 55 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 8B + 05 ?? ?? ?? ?? 48 33 C4 48 89 85 ?? ?? ?? ?? 48 8B F9 4C 8D 05 ?? ?? ?? ?? 4C 8B C9 + BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8D 8D ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 0F 84 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? + 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF + 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 44 24 ?? 4C 8B CF 4C 8D 05 ?? ?? ?? ?? 48 89 44 24 + ?? BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? F6 44 24 ?? ?? 48 8D 8D ?? + ?? ?? ?? 74 ?? 48 8D 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? EB ?? FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 0F 85 + ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? + ?? 48 33 CC E8 ?? ?? ?? ?? 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? 49 8B 7B ?? 49 8B E3 + 5D C3 + } + $encrypt_files_p1 = { + FF 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 63 C8 48 8D 85 ?? ?? ?? + ?? 48 8D 04 48 48 83 C0 ?? 66 83 38 ?? 75 ?? 45 33 FF 4C 8D 05 ?? ?? ?? ?? 66 44 89 + 38 45 33 C9 48 83 C0 ?? 4C 89 7C 24 ?? 48 89 05 ?? ?? ?? ?? 33 D2 48 8D 05 ?? ?? ?? + ?? 44 89 7C 24 ?? 33 C9 48 89 05 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 D2 45 8D 47 ?? 33 + C9 FF 15 ?? ?? ?? ?? 48 8B F0 48 85 C0 74 ?? 48 8B 1D ?? ?? ?? ?? 48 81 C3 ?? ?? ?? + ?? EB ?? 48 8B CB FF 15 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8B D3 48 8B CE 44 8B F0 FF + 15 ?? ?? ?? ?? 48 8B F8 48 85 C0 74 ?? 4C 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8B C8 + FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 41 8D 46 ?? 48 63 C8 48 8D 1C 4B 66 44 + 39 3B 75 ?? 48 8B CE FF 15 ?? ?? ?? ?? 33 D2 8D 4A ?? FF 15 ?? ?? ?? ?? 48 8B F8 48 + 83 F8 ?? 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 48 8B 1D ?? ?? ?? ?? 48 81 + C3 ?? ?? ?? ?? EB ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B D3 48 8D 4C 24 ?? 44 8B F0 FF + 15 ?? ?? ?? ?? 85 C0 75 ?? 44 8B 44 24 ?? 8D 48 ?? 33 D2 FF 15 ?? ?? ?? ?? 48 8B F0 + 48 83 F8 ?? 74 ?? 33 D2 48 8B C8 FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 41 8D + 46 ?? 48 63 C8 48 8D 1C 4B 66 44 39 3B 75 ?? 48 8D 54 24 ?? 48 8B CF FF 15 ?? ?? ?? + ?? 85 C0 75 ?? 48 8B CF FF 15 ?? ?? ?? ?? 33 D2 48 8D 8D ?? ?? ?? ?? 41 B8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 48 8D 35 ?? ?? ?? ?? 48 + } + $encrypt_files_p2 = { + 8D 8D ?? ?? ?? ?? 48 89 B5 ?? ?? ?? ?? 44 8D 42 ?? E8 ?? ?? ?? ?? 4C 8B 05 ?? ?? ?? + ?? 48 8D 8D ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? BB ?? ?? ?? ?? 4C 89 BD + ?? ?? ?? ?? 44 8B CB C7 44 24 ?? ?? ?? ?? ?? 45 33 C0 48 8D 8D ?? ?? ?? ?? 33 D2 FF + 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? 48 8D 44 24 ?? 45 + 33 C9 45 33 C0 48 89 44 24 ?? 8D 53 ?? 33 C9 FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? + 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? + ?? 3D ?? ?? ?? ?? 75 ?? 44 8B CB C7 44 24 ?? ?? ?? ?? ?? 45 33 C0 48 8D 8D ?? ?? ?? + ?? 33 D2 FF 15 ?? ?? ?? ?? 48 8B BD ?? ?? ?? ?? 48 85 FF 0F 84 ?? ?? ?? ?? 48 8B 0D + ?? ?? ?? ?? 41 8B DF 48 81 C1 ?? ?? ?? ?? 45 8B F7 FF 15 ?? ?? ?? ?? 85 C0 7E ?? 49 + 8B F7 48 8B 05 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? BA ?? ?? ?? ?? 0F BE 8C 06 ?? ?? ?? + ?? 44 0F BE 8C 06 ?? ?? ?? ?? 89 4C 24 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 + 48 8D 8D ?? ?? ?? ?? 44 8D 42 ?? E8 ?? ?? ?? ?? 8B CB 48 8D 76 ?? FF C3 41 83 C6 ?? + 88 84 0D ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 81 C1 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 44 + } + $encrypt_files_p3 = { + 3B F0 7C ?? 48 8D 35 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 45 33 C9 48 89 44 24 ?? 48 8D + 95 ?? ?? ?? ?? 44 8B C3 44 89 7C 24 ?? 48 8B CF FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? + ?? ?? 48 8B 1D ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 4C 8B C3 E8 ?? + ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 45 33 C9 C7 44 24 ?? ?? ?? ?? ?? + 48 89 44 24 ?? 33 D2 48 8D 85 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 48 89 44 24 ?? 45 8D 41 + ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 41 8B DF 44 39 BD ?? ?? ?? ?? 76 ?? 8B C3 4C 8D 05 + ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 44 0F B6 8C 05 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF C3 3B 9D ?? ?? + ?? ?? 72 ?? 48 8B 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 D2 48 8B CF FF 15 ?? ?? ?? ?? + 48 8B 05 ?? ?? ?? ?? 4C 8D 8D ?? ?? ?? ?? 48 83 C0 ?? 4C 8D 05 ?? ?? ?? ?? BA ?? ?? + ?? ?? 48 89 44 24 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 06 00 48 + 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 66 44 89 BD ?? ?? 00 00 F3 0F 7F 85 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 48 8D 8D ?? ?? ?? ?? 48 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 48 8B 8D ?? ?? ?? ?? + 48 33 CC E8 ?? ?? ?? ?? 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? 49 8B 73 ?? 49 8B 7B ?? + 49 8B E3 41 5F 41 5E 5D C3 + } + + condition: + uint16(0)==0x5A4D and $search_files and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_MZP : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects MZP ransomware." + author = "ReversingLabs" + id = "c08a4080-fa26-5b7b-869d-5f59096b1a12" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.MZP.yara#L1-L147" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "724ae1033bfb8ff494b30e6b3333e6c848375f1b001b75e71c9444c9f9f31251" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "MZP" + tc_detection_factor = 5 + importance = 25 + + strings: + $show_ransom_note_p1 = { + 55 8B EC B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 ?? 53 56 84 D2 74 ?? 83 C4 ?? E8 ?? ?? ?? + ?? 88 55 ?? 8B D8 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 D2 8B C3 E8 ?? ?? ?? + ?? 89 1D ?? ?? ?? ?? 33 C9 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 89 73 ?? 33 C0 + 89 46 ?? 33 C0 89 86 ?? ?? ?? ?? 33 C0 89 86 ?? ?? ?? ?? C7 86 ?? ?? ?? ?? ?? ?? ?? + ?? C7 86 ?? ?? ?? ?? ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? C7 86 ?? ?? ?? ?? ?? ?? ?? ?? + 6A ?? 6A ?? 8D 45 ?? 50 33 C9 B2 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 8D 86 ?? + ?? ?? ?? 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? + C6 86 ?? ?? ?? ?? ?? 33 C0 89 86 ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? 33 C0 89 86 ?? ?? + ?? ?? C6 86 ?? ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? 8D 86 ?? ?? ?? ?? 33 D2 E8 ?? ?? ?? + ?? 8D 86 ?? ?? ?? ?? 33 D2 E8 ?? ?? ?? ?? 33 C0 89 86 ?? ?? ?? ?? 33 C0 89 86 ?? ?? + ?? ?? C6 86 ?? ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 + ?? ?? ?? ?? B2 ?? 8B C6 E8 ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? A1 ?? ?? + ?? ?? 8B 00 50 E8 ?? ?? ?? ?? 8B D0 8B C6 E8 ?? ?? ?? ?? 33 D2 8B C6 E8 + } + $show_ransom_note_p2 = { + C6 86 ?? ?? ?? ?? ?? C7 86 ?? ?? ?? ?? ?? ?? ?? ?? 8D 86 ?? ?? ?? ?? 33 D2 E8 ?? ?? + ?? ?? C6 86 ?? ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? 89 B6 ?? ?? ?? ?? C7 86 ?? ?? ?? ?? + ?? ?? ?? ?? 33 C0 89 86 ?? ?? ?? ?? 33 C0 89 86 ?? ?? ?? ?? 8B C6 8B 10 FF 52 ?? B2 + ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 89 73 ?? 8D 46 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? C6 46 ?? ?? C6 46 ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 89 73 ?? C6 46 + ?? ?? 8D 46 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + F0 89 73 ?? BA ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 + 8D 46 ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 89 73 ?? 8B C6 C6 + 40 ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 89 73 + ?? 8B C6 C6 40 ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 89 43 ?? 8B 73 ?? 8D 46 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 46 ?? 33 D2 E8 ?? ?? ?? + ?? C6 46 ?? ?? C6 46 ?? ?? C6 46 ?? ?? C6 46 ?? ?? C6 46 ?? ?? 8D 46 ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 43 ?? B2 ?? A1 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 89 43 ?? 8B 73 ?? 8D 46 ?? 33 D2 E8 ?? ?? ?? ?? 8D 46 ?? BA ?? ?? ?? + ?? E8 + } + $search_config_file = { + 8B C0 53 56 8B F0 8A 9E ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? 80 BE ?? ?? ?? ?? ?? 75 ?? + 8B 46 ?? 8B 48 ?? A1 ?? ?? ?? ?? 33 D2 E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 33 D2 8B + 86 ?? ?? ?? ?? FF 96 ?? ?? ?? ?? 83 BE ?? ?? ?? ?? ?? 74 ?? 8B 96 ?? ?? ?? ?? B8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 89 B6 ?? ?? ?? ?? C7 86 ?? ?? ?? ?? ?? ?? ?? ?? + EB ?? 89 B6 ?? ?? ?? ?? C7 86 ?? ?? ?? ?? ?? ?? ?? ?? 88 9E ?? ?? ?? ?? 8A 96 ?? ?? + ?? ?? 8B C6 E8 ?? ?? ?? ?? 80 BE ?? ?? ?? ?? ?? 74 ?? 8B 46 ?? 8B 8E ?? ?? ?? ?? 8B + 96 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 8B 46 ?? E8 ?? ?? ?? ?? 8B 46 ?? 89 + 70 ?? 5E 5B C3 + } + $track_mouse_event_for_entropy = { + 53 56 83 C4 ?? 8B F0 8B 42 ?? 05 ?? ?? ?? ?? 83 E8 ?? 72 ?? 2D ?? ?? ?? ?? 0F 84 ?? + ?? ?? ?? E9 ?? ?? ?? ?? 8A 86 ?? ?? ?? ?? 88 44 24 ?? 66 83 BE ?? ?? ?? ?? ?? 74 ?? + 8B D6 8B 86 ?? ?? ?? ?? FF 96 ?? ?? ?? ?? 8B D8 EB ?? 54 E8 ?? ?? ?? ?? 8D 4C 24 ?? + 8B D4 8B C6 E8 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 8B 44 24 ?? 89 44 24 ?? 8D 54 24 ?? + 8B C6 E8 ?? ?? ?? ?? 8D 54 24 ?? 8B C4 E8 ?? ?? ?? ?? 8B D8 3A 5C 24 ?? 0F 84 ?? ?? + ?? ?? 8B C6 E8 ?? ?? ?? ?? 84 DB 74 ?? C6 86 ?? ?? ?? ?? ?? 66 83 BE ?? ?? ?? ?? ?? + 74 ?? 8B D6 8B 86 ?? ?? ?? ?? FF 96 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? 8B 46 ?? 89 44 24 ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? EB + ?? C6 86 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 46 ?? 89 + 44 24 ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 66 83 BE ?? ?? ?? ?? ?? 74 ?? 8B D6 8B 86 ?? ?? + ?? ?? FF 96 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? EB ?? 80 BE ?? ?? ?? ?? ?? 74 ?? C6 86 + ?? ?? ?? ?? ?? 66 83 BE ?? ?? ?? ?? ?? 74 ?? 8B D6 8B 86 ?? ?? ?? ?? FF 96 ?? ?? ?? + ?? 8B C6 E8 ?? ?? ?? ?? 33 C0 83 C4 ?? 5E 5B C3 + } + $find_files_p1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 8B FA + 8B D8 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? + ?? B9 ?? ?? ?? ?? 8B D7 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 43 ?? 8D 85 ?? ?? ?? ?? + 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 33 C9 8A 08 41 E8 + ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? + 0F 84 ?? ?? ?? ?? 80 7B ?? ?? 76 ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B D7 8B C3 E8 ?? ?? ?? ?? 80 7B ?? ?? 0F 85 ?? + ?? ?? ?? 57 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? + ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 43 ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 53 ?? E8 ?? ?? ?? ?? 84 C0 74 ?? FF 43 + } + $find_files_p2 = { + 80 7B ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B D7 8B C3 E8 ?? ?? ?? ?? EB ?? 80 7B ?? ?? 74 ?? 8D + 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 8B D7 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 43 ?? E8 ?? ?? ?? ?? EB ?? + 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? + 8D 43 ?? E8 ?? ?? ?? ?? 80 7B ?? ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 85 + C0 0F 85 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + } + $encrypt_files = { + 8B C0 33 D2 89 50 ?? 89 50 ?? 52 8D 50 ?? 52 FF 70 ?? FF 70 ?? FF 30 E8 ?? ?? ?? ?? + 85 C0 74 ?? 33 C0 C3 E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? C3 33 C0 C3 51 8B 50 ?? 85 D2 7E + ?? 33 C9 89 48 ?? 51 8D 4C 24 ?? 51 52 FF 70 ?? FF 30 E8 ?? ?? ?? ?? 85 C0 74 ?? 33 + C0 59 C3 E8 ?? ?? ?? ?? EB ?? FF 30 C7 40 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 75 ?? C3 + E8 ?? ?? ?? ?? C3 56 8B F0 33 C0 89 46 ?? 89 46 ?? 8B 46 ?? 2D ?? ?? ?? ?? 74 ?? 48 + 74 ?? 48 74 ?? E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? C7 46 ?? + ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? + BA ?? ?? ?? ?? B9 ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? + ?? ?? ?? 80 7E ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 51 6A ?? 52 50 8D 46 ?? + 50 E8 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 89 06 81 7E ?? ?? ?? ?? ?? 0F 85 ?? ?? + ?? ?? FF 4E ?? 6A ?? FF 36 E8 ?? ?? ?? ?? 40 0F 84 ?? ?? ?? ?? 2D ?? ?? ?? ?? 73 ?? + 33 C0 6A ?? 6A ?? 50 FF 36 E8 ?? ?? ?? ?? 40 0F 84 ?? ?? ?? ?? 6A ?? 8B D4 6A ?? 52 + 68 ?? ?? ?? ?? 8D 96 ?? ?? ?? ?? 52 FF 36 E8 ?? ?? ?? ?? 5A 48 0F 85 ?? ?? ?? ?? 33 + C0 3B C2 73 ?? 80 BC 06 ?? ?? ?? ?? ?? 74 ?? 40 EB ?? 6A ?? 6A ?? 2B C2 50 FF 36 E8 + ?? ?? ?? ?? 40 74 ?? FF 36 E8 ?? ?? ?? ?? 48 75 ?? EB ?? C7 46 ?? ?? ?? ?? ?? 81 7E + ?? ?? ?? ?? ?? 74 ?? 6A ?? EB ?? 6A ?? E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? 89 06 81 7E ?? + ?? ?? ?? ?? 74 ?? FF 36 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 F8 ?? 75 ?? C7 46 ?? ?? ?? ?? + ?? 33 C0 5E C3 + } + + condition: + uint16(0)==0x5A4D and ($search_config_file) and ( all of ($find_files_p*)) and ($track_mouse_event_for_entropy) and ($encrypt_files) and ( all of ($show_ransom_note_p*)) +} +rule REVERSINGLABS_Win64_Ransomware_Hermeticransom : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects HermeticRansom ransomware." + author = "ReversingLabs" + id = "6aaf89f4-0cf8-5f0e-b89d-01ac7edd06c0" + date = "2022-05-13" + modified = "2022-05-13" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.HermeticRansom.yara#L1-L105" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "123d569a9d9b9d855b3baafd6194f102d82a594fd7a2bba073843a8654a317cb" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "HermeticRansom" + tc_detection_factor = 5 + importance = 25 + + strings: + $drop_ransom_note = { + 65 48 8B 0C 25 ?? ?? ?? ?? 48 8B 89 ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 48 3B 41 ?? + 0F 86 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 89 AC 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 0F 10 04 24 0F 11 44 24 ?? 0F 10 44 24 ?? 0F 11 44 24 ?? 0F 10 44 + 24 ?? 0F 11 04 24 E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 8D BC 24 ?? ?? ?? + ?? 48 8D 35 ?? ?? ?? ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? E8 ?? ?? ?? ?? 48 8B 6D ?? 48 + 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? + ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 8B 0D ?? + ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 C7 04 24 ?? ?? ?? ?? 48 + 8D 84 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? + ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 44 24 ?? 48 8B 4C 24 ?? 48 89 8C 24 ?? ?? + ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 14 24 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 + 8B 44 24 ?? 48 8B 4C 24 ?? 48 8D 94 24 ?? ?? ?? ?? 48 89 14 24 48 89 4C 24 ?? 48 89 + 44 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 C7 04 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 4C 24 + ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 + 8B 44 24 ?? 48 8B 4C 24 ?? 48 89 0C 24 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 4C + 24 ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 44 24 ?? C7 04 24 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? + ?? 48 89 54 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 + } + $encrypt_files_p1 = { + E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 89 8C 24 ?? + ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 1D ?? ?? ?? ?? 48 8B 35 ?? ?? ?? ?? 48 89 14 24 + 48 89 74 24 ?? 48 89 5C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 89 54 24 ?? 48 C7 44 24 ?? ?? + ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 1D ?? ?? ?? ?? 48 89 5C 24 ?? 48 89 54 24 ?? E8 + ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 8B 54 24 ?? 48 8B 9C 24 ?? ?? ?? ?? 48 + 85 DB 0F 85 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 4C 24 ?? 48 89 94 24 ?? ?? ?? ?? 48 8D + 05 ?? ?? ?? ?? 48 89 04 24 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 04 24 48 8B 44 24 ?? 48 89 C1 48 C1 F8 ?? 48 + C1 E8 ?? 48 01 C8 48 C1 F8 ?? 48 89 84 24 ?? ?? ?? ?? 48 C1 E0 ?? 48 29 C1 48 89 4C + 24 ?? 48 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 89 04 24 0F 57 C0 0F + 11 44 24 ?? E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 83 F8 ?? 7E ?? B8 ?? ?? ?? ?? + 48 89 84 24 ?? ?? ?? ?? 31 C9 EB ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? + 48 39 C1 0F 8D ?? ?? ?? ?? 48 89 CA 48 C1 E1 ?? 48 FF C2 48 89 D3 48 C1 E2 ?? 48 39 + D1 0F 87 ?? ?? ?? ?? 48 8B 74 24 ?? 48 39 F2 0F 87 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? + ?? 48 8B 05 ?? ?? ?? ?? 48 8B 1D ?? ?? ?? ?? 48 8B 3D ?? ?? ?? ?? 48 89 3C 24 48 89 + } + $encrypt_files_p2 = { + 5C 24 ?? 48 89 44 24 ?? 48 29 CE 48 89 F3 48 F7 DE 48 C1 FE ?? 48 21 CE 48 8B BC 24 + ?? ?? ?? ?? 48 01 FE 48 89 74 24 ?? 48 29 CA 48 89 54 24 ?? 48 89 5C 24 ?? E8 ?? ?? + ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 8B 54 24 ?? 48 8B 5C 24 ?? 48 85 DB 0F 85 ?? + ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 89 1C 24 48 89 44 24 ?? 48 89 4C 24 ?? 48 89 54 + 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 83 F8 ?? 0F 8D ?? ?? ?? ?? 48 C1 E0 ?? 48 8B + 4C 24 ?? 48 39 C8 0F 87 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 1D ?? ?? ?? ?? 48 8B + 35 ?? ?? ?? ?? 48 89 14 24 48 89 5C 24 ?? 48 89 74 24 ?? 48 8B 54 24 ?? 48 29 C2 48 + 89 D3 48 F7 DA 48 C1 FA ?? 48 21 C2 48 8B B4 24 ?? ?? ?? ?? 48 01 F2 48 89 54 24 ?? + 48 29 C1 48 89 4C 24 ?? 48 89 5C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? + 48 8B 54 24 ?? 48 8B 5C 24 ?? 48 85 DB 74 ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 8C 24 ?? + ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 + 81 C4 ?? ?? ?? ?? C3 48 8B 9C 24 ?? ?? ?? ?? 48 89 1C 24 48 89 44 24 ?? 48 89 4C 24 + ?? 48 89 54 24 ?? E8 ?? ?? ?? ?? 48 8B 84 24 + } + $find_files = { + 65 48 8B 0C 25 ?? ?? ?? ?? 48 8B 89 ?? ?? ?? ?? 48 3B 61 ?? 0F 86 ?? ?? ?? ?? 48 83 + EC ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? 48 C7 04 24 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? + 48 89 44 24 ?? 48 8B 8C 24 ?? ?? ?? ?? 48 89 4C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 89 54 + 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 1D ?? ?? ?? ?? 48 89 54 + 24 ?? 48 89 5C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 89 54 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? + E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 89 44 24 ?? 48 8B 4C 24 ?? 48 89 4C 24 ?? 48 8B 94 + 24 ?? ?? ?? ?? 48 89 14 24 48 8B 9C 24 ?? ?? ?? ?? 48 89 5C 24 ?? 48 89 44 24 ?? 48 + 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 8B 84 24 ?? + ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 48 89 04 24 48 89 4C 24 ?? 48 C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 8B 4C 24 ?? 48 85 C9 75 + ?? 48 89 44 24 ?? 48 89 04 24 E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 85 C0 74 ?? 48 8B 44 + 24 ?? 48 89 04 24 E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 48 8B 6C 24 ?? 48 83 C4 ?? + C3 48 8B 44 24 ?? 48 89 04 24 E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 48 8B 6C 24 ?? + 48 83 C4 ?? C3 48 89 04 24 E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 48 8B 6C 24 ?? 48 + 83 C4 ?? C3 48 8B 44 24 + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($drop_ransom_note) +} +rule REVERSINGLABS_Win32_Ransomware_Wsir : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects WsIR ransomware." + author = "ReversingLabs" + id = "cb4ab736-9421-5b92-b4a5-c5db0b61725a" + date = "2022-08-02" + modified = "2022-08-02" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.WsIR.yara#L1-L73" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "c22c01f93945c7721ebfe5e7a09c3bf2b9d0ad95740bc0a76b4e61741f61d82c" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "WsIR" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files = { + 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 53 + 55 8B E9 8D 4C 24 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B 4C 24 ?? C7 84 24 ?? ?? ?? ?? ?? + ?? ?? ?? 8B 41 ?? 85 C0 74 ?? 8D 54 24 ?? 6A ?? 52 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B 00 + 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4C 24 ?? 85 C0 0F 95 C3 E8 ?? ?? ?? ?? + 84 DB 74 ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? E8 + ?? ?? ?? ?? 8B 4C 24 ?? 8D 44 24 ?? 50 51 FF 15 ?? ?? ?? ?? 83 F8 ?? 89 44 24 ?? 75 + ?? 8D 4C 24 ?? 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 56 8B B4 24 ?? ?? + ?? ?? 57 8B 3D ?? ?? ?? ?? BB ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? 8D 54 24 ?? 68 ?? ?? + ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 45 ?? 8D 54 24 ?? 52 6A ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 50 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? 89 4C 24 ?? 89 5C 24 ?? FF D7 8B 54 24 ?? 8D 4C 24 ?? 51 52 FF 15 ?? ?? + ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 56 6A ?? 68 + ?? ?? ?? ?? 51 FF D7 8D 4C 24 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 5F + 5E 8B 8C 24 ?? ?? ?? ?? 5D 5B 64 89 0D ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C2 + } + $encrypt_files = { + FF 75 ?? 8B 5D ?? FF 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? ?? + ?? FF 75 ?? 8B 5D ?? FF 33 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 68 ?? ?? + ?? ?? 6A ?? 8B 45 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 85 + C0 75 ?? B8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B + 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? + 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 89 45 ?? 8B 45 ?? 50 8B 5D ?? 85 DB 74 ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 58 89 45 ?? + E9 + } + $exec_proc = { + 52 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 1D ?? ?? + ?? ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 FF D3 8D 4C 24 ?? 8D 54 24 ?? 51 52 68 ?? ?? ?? + ?? 8B CF E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? 8D 4C 24 ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B + F0 83 C4 ?? 85 F6 75 ?? 8D 54 24 ?? 52 FF 15 ?? ?? ?? ?? 8D 74 04 ?? EB ?? 8D 57 ?? + 8D 4C 24 ?? 52 E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 48 ?? 85 C9 0F 85 ?? ?? ?? ?? 8D 4C 24 + ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 EB ?? C6 06 ?? 68 ?? ?? ?? + ?? 56 FF D3 8B 44 24 ?? 50 56 FF D3 8D 4C 24 ?? 55 51 FF 15 ?? ?? ?? ?? 8B F0 33 D2 + 83 FE ?? 0F 9F C2 8D 4C 24 ?? 8B F2 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 5D 8B C6 5B 8B 8C 24 ?? ?? ?? ?? 5F 5E 64 89 0D ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C2 + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($exec_proc) +} +rule REVERSINGLABS_Win32_Ransomware_Sevensevenseven : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects SevenSevenSeven ransomware." + author = "ReversingLabs" + id = "049531bd-9505-5da1-9512-980383c8c5ec" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.SevenSevenSeven.yara#L1-L148" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "583a8ac746cd749bd3927f10c864a3ac84f82f8bbd8d0ebf117e22b016d7ca94" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "SevenSevenSeven" + tc_detection_factor = 5 + importance = 25 + + strings: + $file_search_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? + ?? 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 45 ?? 53 56 57 89 65 ?? BE ?? ?? ?? ?? 89 75 + ?? 33 DB 89 5D ?? 88 5D ?? 89 75 ?? 89 5D ?? 88 5D ?? 89 75 ?? 88 5D ?? 68 ?? ?? ?? + ?? 8B 45 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 53 50 8D 4D ?? E8 + ?? ?? ?? ?? BF ?? ?? ?? ?? 39 BD ?? ?? ?? ?? 72 ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? + ?? 83 C4 ?? 39 7D ?? 8B 45 ?? 73 ?? 8D 45 ?? 8D 8D ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? + ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? EB ?? BE ?? ?? ?? ?? 90 6A ?? 53 8D + 4D ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8B 45 ?? 50 8D 8D ?? ?? ?? + ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? + 53 50 8D 4D ?? E8 ?? ?? ?? ?? 39 BD ?? ?? ?? ?? 72 ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 89 B5 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? 39 BD ?? ?? ?? + ?? 72 ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 B5 ?? ?? ?? ?? 89 9D ?? ?? + ?? ?? 88 9D ?? ?? ?? ?? 39 7D ?? 8B 75 ?? 73 ?? 8D 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? + ?? ?? ?? 85 C0 74 ?? B8 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 + } + $file_search_p2 = { + 74 ?? B8 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? F7 D8 1B C0 F7 D8 3B + C3 0F 85 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 + ?? 8B 45 ?? 3A C3 0F 84 ?? ?? ?? ?? 50 8D 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 3B + F3 0F 84 ?? ?? ?? ?? 39 7D ?? 72 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 39 7D ?? 72 + ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 89 5D ?? 88 5D ?? 39 7D + ?? 0F 82 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 E9 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 38 1E 74 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? + ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF + 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 89 5D ?? + 39 7D ?? 8B 45 ?? 73 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? EB + ?? B8 ?? ?? ?? ?? C3 + } + $encrypt_file_1 = { + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 55 8B AC 24 ?? ?? ?? ?? 56 55 89 84 24 ?? ?? ?? ?? + 33 F6 FF 15 ?? ?? ?? ?? 33 C9 85 C0 76 ?? 8D 9B ?? ?? ?? ?? 80 3C 29 ?? 75 ?? 46 41 + 3B C8 72 ?? 83 FE ?? 75 ?? 5E 33 C0 5D 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? + ?? ?? ?? C3 57 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 8B + F8 83 FF ?? 75 ?? 5F 5E 33 C0 5D 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? + ?? C3 53 6A ?? 57 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 73 ?? 57 FF 15 ?? ?? ?? ?? 5B 5F + 5E 33 C0 5D 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 53 6A ?? FF 15 + ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 57 8B F0 FF 15 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 53 56 + 57 FF 15 ?? ?? ?? ?? 33 C0 85 DB 76 ?? 8D 49 ?? 80 34 30 ?? 40 3B C3 72 ?? 6A ?? 6A + ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 6A ?? 8D 4C 24 ?? 51 53 56 57 FF 15 ?? ?? ?? ?? 57 FF + 15 ?? ?? ?? ?? 8D 54 24 ?? 52 FF 15 ?? ?? ?? ?? 0F B7 44 24 ?? 0F B7 4C 24 ?? 0F B7 + 54 24 ?? 68 ?? ?? ?? ?? 50 0F B7 44 24 ?? 51 0F B7 4C 24 ?? 52 0F B7 54 24 ?? 50 51 + 52 55 8D 44 24 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? 51 68 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 83 C4 ?? 8D 54 24 ?? 52 55 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B + 8C 24 ?? ?? ?? ?? 5B 5F 5E B8 ?? ?? ?? ?? 5D E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 + } + $encrypt_file_2 = { + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 55 8B AC 24 ?? ?? ?? ?? 56 55 89 84 24 ?? ?? ?? ?? + 33 F6 FF 15 ?? ?? ?? ?? 33 C9 85 C0 76 ?? 8D 9B ?? ?? ?? ?? 80 3C 29 ?? 75 ?? 46 41 + 3B C8 72 ?? 83 FE ?? 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 55 FF 15 ?? + ?? ?? ?? 8B F0 83 FE ?? 75 ?? 5E 33 C0 5D 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 + ?? ?? ?? ?? C3 53 6A ?? 56 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 73 ?? 56 FF 15 ?? ?? ?? + ?? 5B 5E 33 C0 5D 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 57 8D 83 + ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 8B F8 FF 15 ?? ?? ?? ?? + 6A ?? 8D 4C 24 ?? 51 53 57 56 FF 15 ?? ?? ?? ?? 8B CB C1 E9 ?? 41 74 ?? 8D 47 ?? B2 + ?? 80 70 ?? ?? 80 70 ?? ?? 80 30 ?? 80 70 ?? ?? 80 70 ?? ?? 80 70 ?? ?? 80 70 ?? ?? + 30 50 ?? 83 C0 ?? 49 75 ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 8D 54 24 ?? + 52 53 57 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? + 0F B7 4C 24 ?? 0F B7 54 24 ?? 0F B7 44 24 ?? 68 ?? ?? ?? ?? 51 0F B7 4C 24 ?? 52 0F + B7 54 24 ?? 50 0F B7 44 24 ?? 51 52 50 55 8D 4C 24 ?? 68 ?? ?? ?? ?? 51 FF 15 ?? ?? + ?? ?? 8D 54 24 ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 55 FF 15 + ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5B 5E B8 ?? ?? ?? ?? 5D E8 + ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 + } + $remote_server_1 = { + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 53 55 56 57 68 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 8D 8C 24 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 33 FF 57 6A ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 89 44 24 ?? 33 DB + BD ?? ?? ?? ?? 8B 44 24 ?? BA ?? ?? ?? ?? 8B CB D3 E2 85 D0 0F 84 ?? ?? ?? ?? 8A CB + 8D 54 24 ?? 80 C1 ?? 52 88 4C 24 ?? 66 C7 44 24 ?? ?? ?? FF D6 83 F8 ?? 74 ?? 8D 44 + 24 ?? 50 FF D6 83 F8 ?? 75 ?? 8D 44 24 ?? 89 6C 24 ?? 89 7C 24 ?? C6 44 24 ?? ?? 8D + 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 50 8D 4C 24 ?? 51 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 54 + 24 ?? 6A ?? 52 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 83 F8 ?? 72 ?? 8B 44 24 ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 89 6C 24 ?? 89 7C 24 ?? C6 44 24 ?? ?? 43 83 FB ?? 0F 8C ?? ?? + ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? + ?? ?? 8B 8C 24 ?? ?? ?? ?? 5F 5E 5D 33 C0 5B E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C2 + } + $remote_server_2 = { + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 57 33 FF 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 89 84 + 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 66 83 7C 24 ?? ?? + 0F 85 ?? ?? ?? ?? 66 83 7C 24 ?? ?? 0F 87 ?? ?? ?? ?? 53 55 56 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? + 8D 94 24 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? 57 6A ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 89 44 24 ?? 33 DB BD ?? ?? + ?? ?? 8B CB B8 ?? ?? ?? ?? D3 E0 8B 4C 24 ?? 85 C1 0F 84 ?? ?? ?? ?? 8A D3 8D 44 24 + ?? 80 C2 ?? 50 88 54 24 ?? 66 C7 44 24 ?? ?? ?? FF D6 83 F8 ?? 74 ?? 8D 4C 24 ?? 51 + FF D6 83 F8 ?? 75 ?? 8D 44 24 ?? 89 6C 24 ?? 89 7C 24 ?? C6 44 24 ?? ?? 8D 50 ?? 8A + 08 40 84 C9 75 ?? 2B C2 50 8D 54 24 ?? 52 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 44 24 ?? 6A + ?? 50 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 83 F8 ?? 72 ?? 8B 4C 24 ?? 51 E8 ?? ?? ?? + ?? 83 C4 ?? 89 6C 24 ?? 89 7C 24 ?? C6 44 24 ?? ?? 43 83 FB ?? 0F 8C ?? ?? ?? ?? E8 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B + 8C 24 ?? ?? ?? ?? 5E 5D 5B 33 C0 5F E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C2 ?? ?? 57 FF + 15 + } + + condition: + uint16(0)==0x5A4D and ( all of ($file_search_p*)) and ((($encrypt_file_1) and ($remote_server_1)) or (($encrypt_file_2) and ($remote_server_2))) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Namaste : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Namaste ransomware." + author = "ReversingLabs" + id = "e85d7ec3-367b-5bde-a570-8caa1f6cd61b" + date = "2021-08-12" + modified = "2021-08-12" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Namaste.yara#L1-L81" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "5a952276f41b5524bcb82a9ceb076983d2faf2864b3bbd0a06d49bbd5edc1e0e" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Namaste" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files_p1 = { + 03 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 02 06 07 9A 28 ?? ?? ?? ?? 07 17 58 0B 07 06 8E 69 32 + ?? DE ?? 26 DE ?? 00 03 28 ?? ?? ?? ?? 0C 16 0D 2B ?? 08 09 9A 13 ?? 02 11 ?? 28 ?? ?? + ?? ?? 17 28 ?? ?? ?? ?? 09 17 58 0D 09 08 8E 69 32 ?? DE ?? 26 DE ?? 2A + } + $find_files_p2 = { + 02 7B ?? ?? ?? ?? 2D ?? 03 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 17 2A 03 6F ?? ?? ?? ?? + 0A 06 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 72 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 + 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? + ?? ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 + 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? + ?? 2D ?? 06 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 16 2A 02 7B ?? ?? ?? ?? 2C ?? 03 72 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 16 2A 02 7B ?? ?? ?? ?? 2D ?? 03 72 ?? ?? ?? ?? 6F ?? ?? + ?? ?? 2D ?? 16 2A 03 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 03 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 20 ?? ?? ?? ?? 6A 31 ?? 16 0C DE ?? DE ?? 26 DE ?? 02 28 ?? ?? ?? ?? 07 28 ?? ?? ?? ?? + 2A 08 2A + } + $encrypt_files_p1 = { + 02 03 28 ?? ?? ?? ?? 2C ?? 02 7B ?? ?? ?? ?? 2C ?? 02 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 02 7B ?? ?? ?? ?? 03 6F ?? ?? ?? ?? 02 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 2B ?? 02 03 72 + ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 02 7B ?? ?? ?? ?? 2C ?? 03 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 2C ?? 02 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 2A + } + $encrypt_files_p2 = { + 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 02 20 ?? ?? ?? + ?? 7D ?? ?? ?? ?? 02 17 7D ?? ?? ?? ?? 02 17 7D ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? + ?? 25 2D ?? 26 7E ?? ?? ?? ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 02 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 1B 28 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 02 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 02 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 1F + ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 2B ?? 12 ?? 28 ?? ?? ?? ?? 0B 02 07 + 28 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? + DC 02 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2A + } + $encrypt_files_p3 = { + 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? 26 73 ?? ?? ?? ?? 0A 06 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 06 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 18 6F ?? ?? ?? ?? 04 14 73 ?? ?? ?? ?? 0B 06 07 06 + 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 07 06 6F ?? ?? ?? ?? 1E 5B 6F ?? + ?? ?? ?? 6F ?? ?? ?? ?? 06 1A 6F ?? ?? ?? ?? 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 18 73 ?? + ?? ?? ?? 0C 08 06 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 0D 03 19 73 ?? ?? ?? ?? 13 ?? 20 ?? + ?? ?? ?? 8D ?? ?? ?? ?? 13 ?? 2B ?? 09 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 11 ?? 11 ?? 16 11 + ?? 8E 69 6F ?? ?? ?? ?? 25 13 ?? 16 30 ?? DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? DC 09 + 2C ?? 09 6F ?? ?? ?? ?? DC 08 2C ?? 08 6F ?? ?? ?? ?? DC 03 28 ?? ?? ?? ?? 2A + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Linux_Ransomware_Redalert : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects RedAlert ransomware." + author = "ReversingLabs" + id = "ec7567bf-2c39-529f-ae93-74270a161827" + date = "2022-09-01" + modified = "2022-09-01" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Linux.Ransomware.RedAlert.yara#L1-L146" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "fe0d10c2ef1dacdb5374f319e470274b91f4f171db49de8c89e8aaa9aa75a45c" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "RedAlert" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 41 57 41 56 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 89 74 24 ?? BE ?? ?? ?? ?? 48 + 89 54 24 ?? 48 89 4C 24 ?? 4C 89 44 24 ?? E8 ?? ?? ?? ?? 48 85 C0 48 89 C5 75 ?? BF + ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 48 89 C7 E8 ?? ?? ?? ?? 83 F8 ?? 89 C3 75 ?? BF ?? + ?? ?? ?? E8 ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 31 C0 E9 ?? ?? ?? ?? 48 8D 54 24 ?? + 89 C6 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? FF C0 75 ?? BF ?? ?? ?? ?? EB ?? 4C 8B B4 24 ?? + ?? ?? ?? 4D 85 F6 7F ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 DF E8 ?? ?? ?? ?? EB ?? 49 + 81 FE ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 0F 97 44 24 ?? 49 81 FE ?? ?? ?? ?? 0F 97 + 44 24 ?? 80 7C 24 ?? ?? 74 ?? BA ?? ?? ?? ?? 4C 89 F0 C7 44 24 ?? ?? ?? ?? ?? 48 89 + D3 31 D2 48 F7 F3 48 6B C8 ?? 48 89 4C 24 ?? 49 81 FE ?? ?? ?? ?? 77 ?? 4D 89 F4 41 + BD ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 41 BC ?? ?? ?? ?? 45 31 ED C7 44 24 ?? + ?? ?? ?? ?? 4D 63 FD C7 44 24 ?? ?? ?? ?? ?? 4C 0F AF 7C 24 ?? E9 ?? ?? ?? ?? 80 7C + 24 ?? ?? 74 ?? 45 85 ED 74 ?? 80 7C 24 ?? ?? 74 ?? 41 8D 45 ?? 3B 44 24 ?? 4C 89 FE + 75 ?? 49 8D B6 ?? ?? ?? ?? EB ?? 31 F6 31 D2 48 89 EF E8 ?? ?? ?? ?? 48 63 7C 24 ?? + 48 89 E9 4C 89 E2 48 03 7C 24 ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 39 E0 74 ?? BF ?? + ?? ?? ?? EB ?? 44 01 64 24 ?? 41 FF C5 44 3B 6C 24 ?? 0F 85 ?? ?? ?? ?? 48 8D 9C 24 + ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 84 C0 74 ?? BF ?? + ?? ?? ?? EB ?? 48 8D BC 24 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 DE E8 ?? ?? ?? ?? 85 C0 + 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 63 6C 24 ?? 45 89 E7 44 89 64 24 ?? 4C 0F AF + 6C 24 ?? C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 8B 4C 24 ?? 41 B8 + ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 84 + } + $encrypt_files_p2 = { + C0 75 ?? 48 8B 54 24 ?? 48 8B 7C 24 ?? 48 89 E9 BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F B7 + 15 ?? ?? ?? ?? 48 39 D0 75 ?? 48 8B 44 24 ?? 48 89 E9 BE ?? ?? ?? ?? 0F B7 50 ?? 48 + 8B 38 E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 0F B7 51 ?? 48 39 D0 74 ?? BF ?? ?? ?? ?? E9 ?? + ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 4C 03 7C 24 ?? 44 3B 6C 24 ?? 0F 8C ?? ?? ?? ?? E9 + ?? ?? ?? ?? BF ?? ?? ?? ?? EB ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 80 7C + 24 ?? ?? 74 ?? 83 7C 24 ?? ?? 74 ?? 80 7C 24 ?? ?? 74 ?? 8B 44 24 ?? 4C 89 EE FF C0 + 3B 44 24 ?? 75 ?? 49 8D B6 ?? ?? ?? ?? EB ?? 31 F6 31 D2 48 89 EF E8 ?? ?? ?? ?? 48 + 63 44 24 ?? 48 8B 5C 24 ?? 48 8D B4 24 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? 31 C9 31 + D2 45 89 E1 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 01 C3 48 8D 84 24 ?? + ?? ?? ?? 49 89 D8 48 89 1C 24 48 89 44 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? + 48 89 E9 4C 89 E2 BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 39 E0 0F 85 ?? ?? ?? ?? + FF 44 24 ?? 8B 54 24 ?? 8B 4C 24 ?? 01 54 24 ?? 39 4C 24 ?? 75 ?? 31 F6 BA ?? ?? ?? + ?? 48 89 EF E8 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? 48 89 E9 BA ?? ?? ?? ?? BE ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8A 5C 24 ?? 48 83 F8 ?? B0 ?? 0F 44 D8 44 3B 7C 24 ?? 88 5C 24 + ?? 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 44 03 7C 24 ?? 4C 03 6C 24 ?? 8B 44 24 ?? 39 + 44 24 ?? 0F 8C ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 0F B6 44 24 ?? 48 81 C4 ?? ?? ?? + ?? 5B 5D 41 5C 41 5D 41 5E 41 5F C3 + } + $find_files_p1 = { + 41 57 FC 41 56 41 55 41 54 49 89 FC 55 53 48 83 EC ?? 48 8B 84 24 ?? ?? ?? ?? 48 89 + 4C 24 ?? 48 83 C9 ?? 48 89 74 24 ?? 4C 89 44 24 ?? 4C 89 4C 24 ?? 88 54 24 ?? 48 89 + 44 24 ?? 48 8B 84 24 ?? ?? ?? ?? 44 8A BC 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 8B 84 24 + ?? ?? ?? ?? 48 89 44 24 ?? 48 8B 84 24 ?? ?? ?? ?? 48 89 44 24 ?? 31 C0 F2 AE 4C 89 + E7 48 F7 D1 4C 8D 71 ?? E8 ?? ?? ?? ?? 48 85 C0 48 89 44 24 ?? 0F 85 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 38 E8 ?? ?? ?? ?? 48 83 C4 ?? 4C 89 E6 48 89 C2 5B 5D 41 5C 41 5D 41 + 5E 41 5F BF ?? ?? ?? ?? 31 C0 E9 ?? ?? ?? ?? 45 84 FF 48 8D 6B ?? 74 ?? 0F B6 4B ?? + 48 89 EA 4C 89 E6 BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 80 7B ?? ?? 0F 85 ?? ?? ?? ?? + 80 7C 24 ?? ?? 0F 84 ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 85 C0 0F 84 + ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? BE ?? ?? + ?? ?? 48 89 EF E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FC 31 C0 48 83 C9 ?? 48 89 EF + F2 AE 4C 89 F0 48 29 C8 48 3B 44 24 ?? 76 ?? 48 8B 3D ?? ?? ?? ?? 48 89 E9 4C 89 E2 + BE ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4B 8D 1C 34 48 89 EE 48 8D 7B ?? + C6 03 ?? E8 ?? ?? ?? ?? 41 0F B6 C7 4C 8B 4C 24 ?? 4C 8B 44 24 ?? 89 44 24 ?? 48 8B + 44 24 ?? BA ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B 74 24 ?? 4C 89 E7 48 89 44 24 ?? 48 8B + } + $find_files_p2 = { + 44 24 ?? 48 89 44 24 ?? 48 8B 44 24 ?? 48 89 44 24 ?? 48 8B 44 24 ?? 48 89 04 24 E8 + ?? ?? ?? ?? E9 ?? ?? ?? ?? 45 84 FF 0F 85 ?? ?? ?? ?? FC 48 83 C9 ?? 48 89 EF 44 88 + F8 F2 AE 48 8B 54 24 ?? 48 89 EF 48 89 CB 48 8B 4C 24 ?? 48 F7 D3 48 89 DE 4C 8D 6B + ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 48 89 EA 4C 89 E6 BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? + E9 ?? ?? ?? ?? 4C 89 EA BE ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? + ?? 48 89 DE 48 89 EF E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 4B 8D 1C 34 48 89 EA 4C + 89 E6 BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 48 8D 7B ?? 48 89 EE C6 03 ?? E8 ?? ?? ?? + ?? 0F B7 0D ?? ?? ?? ?? 4C 89 E7 4C 8B 44 24 ?? 48 8B 54 24 ?? 48 8B 74 24 ?? FF 15 + ?? ?? ?? ?? 84 C0 BF ?? ?? ?? ?? 74 ?? 48 8B 7C 24 ?? B9 ?? ?? ?? ?? 4C 89 E2 BE ?? + ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 48 8B 74 24 ?? 4C 89 E7 E8 ?? ?? ?? ?? 85 C0 74 ?? BF + ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 41 8D 56 ?? + 4C 89 E6 E8 ?? ?? ?? ?? C6 03 ?? 48 8B 7C 24 ?? E8 ?? ?? ?? ?? 48 85 C0 48 89 C3 0F + 85 ?? ?? ?? ?? 48 8B 7C 24 ?? 48 83 C4 ?? 5B 5D 41 5C 41 5D 41 5E 41 5F E9 + } + $setup_environment = { + 55 48 89 E5 41 56 49 89 F6 BE ?? ?? ?? ?? 41 55 41 54 53 48 89 FB 48 83 EC ?? E8 ?? + ?? ?? ?? 48 85 C0 49 89 C4 75 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 7D ?? E8 ?? ?? + ?? ?? 84 C0 BF ?? ?? ?? ?? 74 ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 85 C0 49 + 89 C4 74 ?? 0F B7 55 ?? 48 8B 7D ?? 48 89 C1 BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F B7 55 + ?? 48 8B 7D ?? 4C 89 E1 BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F B7 55 ?? 31 C9 39 C2 0F 85 + ?? ?? ?? ?? E9 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? BF ?? ?? ?? + ?? 49 89 E5 E8 ?? ?? ?? ?? 66 8B 3D ?? ?? 22 00 66 03 3D ?? ?? 22 00 66 8B 05 ?? ?? + 22 00 66 89 7D ?? 0F B7 FF 66 89 45 ?? E8 ?? ?? ?? ?? 0F B7 7D ?? 48 89 45 ?? E8 ?? + ?? ?? ?? 0F B7 55 ?? 48 8B 7D ?? 4C 89 E1 BE ?? ?? ?? ?? 48 89 45 ?? E8 ?? ?? ?? ?? + 0F B7 55 ?? 48 8B 7D ?? 4C 89 E1 BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 75 ?? BF ?? ?? + ?? ?? 31 C0 E8 ?? ?? ?? ?? 0F B7 45 ?? 0F B7 35 ?? ?? ?? ?? 31 C9 48 8B 7D ?? 48 83 + C0 ?? 25 ?? ?? ?? ?? 48 29 C4 48 8D 5C 24 ?? 48 83 E3 ?? 48 89 DA E8 ?? ?? ?? ?? 48 + 89 DE BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 0F B7 3D ?? ?? ?? ?? BE ?? ?? ?? ?? 48 03 + 7D ?? E8 ?? ?? ?? ?? 66 39 05 ?? ?? 22 00 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 + EC 31 C9 EB ?? 4C 89 E7 E8 ?? ?? ?? ?? 48 8D 75 ?? B9 ?? ?? ?? ?? 4C 89 F7 FC F3 A5 + B1 ?? EB ?? 4C 89 EC EB ?? 48 8D 65 ?? 89 C8 5B 41 5C 41 5D 41 5E C9 C3 + } + $make_configuration = { + 41 56 BE ?? ?? ?? ?? 49 89 FE BF ?? ?? ?? ?? 41 55 41 54 55 53 48 83 EC ?? E8 ?? ?? + ?? ?? 84 C0 88 C3 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 31 FF EB ?? BF ?? ?? ?? ?? E8 + ?? ?? ?? ?? BA ?? ?? ?? ?? 0F B7 F0 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 + ?? ?? ?? ?? B9 ?? ?? ?? ?? 49 89 C4 48 89 C2 BE ?? ?? ?? ?? BF ?? ?? ?? ?? 66 C7 00 + ?? ?? C6 40 ?? ?? E8 ?? ?? ?? ?? 4C 89 E6 BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 48 89 + E6 4C 89 E7 E8 ?? ?? ?? ?? 84 C0 75 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? + E8 ?? ?? ?? ?? FC 88 D8 BF ?? ?? ?? ?? 48 83 C9 ?? F2 AE 48 F7 D1 48 FF C9 8D 59 ?? + 83 C1 ?? 48 63 F9 E8 ?? ?? ?? ?? 48 85 C0 48 89 C5 0F 84 ?? ?? ?? ?? 48 8D 78 ?? 48 + 63 D3 BE ?? ?? ?? ?? C6 00 ?? E8 ?? ?? ?? ?? 48 89 EF BE ?? ?? ?? ?? E8 ?? ?? ?? ?? + 48 85 C0 48 89 C3 BF ?? ?? ?? ?? 74 ?? 0F B7 54 24 ?? 48 8B 7C 24 ?? 48 89 C1 BE ?? + ?? ?? ?? E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? BF ?? ?? ?? + ?? E8 ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? 4C 89 F7 48 89 E6 B9 ?? ?? ?? ?? FC F3 A5 + 48 83 C4 ?? 5B 5D 41 5C 41 5D 41 5E C3 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 + } + + condition: + uint32(0)==0x464C457F and ($setup_environment) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($make_configuration) +} +rule REVERSINGLABS_Win32_Ransomware_Montserrat : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Montserrat ransomware." + author = "ReversingLabs" + id = "deeb5f1a-1329-5964-93e1-8ca6a20fcd89" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Montserrat.yara#L1-L118" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "c8782a8cb2b87e76ff1f804ee8affd01405827d0914ea725bb0e9ddace7dde10" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Montserrat" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files_p1 = { + 8B FF 55 8B EC 51 8B 4D ?? 53 57 33 DB 8D 51 ?? 66 8B 01 83 C1 ?? 66 3B C3 75 ?? 8B + 7D ?? 2B CA D1 F9 83 C8 ?? 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 56 8D 5F ?? + 03 D9 6A ?? 53 E8 ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? + ?? 83 C4 ?? 85 C0 75 ?? FF 75 ?? 2B DF 8D 04 7E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 75 ?? 8B 4D ?? 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5F + 5B 8B E5 5D C3 33 C0 50 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? + ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 55 ?? 8B 4D ?? 53 8B 5D ?? 56 57 6A ?? 5E 6A ?? + 89 95 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 5F EB ?? 0F B7 01 66 3B 85 ?? ?? ?? + ?? 74 ?? 66 3B C6 74 ?? 66 3B C7 74 ?? 83 E9 ?? 3B CB 75 ?? 0F B7 31 66 3B F7 75 ?? + 8D 43 ?? 3B C8 74 ?? 52 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 6A ?? + 8B C6 33 FF 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 6A ?? 5A 66 3B C2 74 ?? 8B C7 + } + $find_files_p2 = { + EB ?? 33 C0 40 2B CB 0F B6 C0 D1 F9 41 F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 + 57 53 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? 8B 85 ?? ?? ?? ?? 50 57 57 53 E8 ?? ?? + ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD + 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 8D ?? ?? ?? ?? 6A ?? 8B 41 ?? 2B 01 C1 F8 ?? 89 85 + ?? ?? ?? ?? 58 66 39 85 ?? ?? ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 66 39 85 ?? ?? + ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 51 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 8B 8D + ?? ?? ?? ?? 85 C0 6A ?? 58 75 ?? 8B C1 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 + ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? + 83 C4 ?? E9 + } + $encrypt_files_p1 = { + 8B FF 55 8B EC 83 EC ?? 53 56 57 FF 75 ?? 8D 45 ?? FF 75 ?? FF 75 ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 8D 7D ?? 8B F0 6A ?? 59 F3 A5 83 CE ?? 39 75 ?? 75 ?? E8 ?? ?? ?? ?? 83 + 20 ?? 8B 45 ?? 89 30 E8 ?? ?? ?? ?? 8B 00 E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 5D ?? 89 + 03 3B C6 75 ?? E8 ?? ?? ?? ?? 83 20 ?? 89 33 E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? EB ?? + 8B 45 ?? 8D 75 ?? 83 65 ?? ?? 33 C9 41 C7 45 ?? ?? ?? ?? ?? 83 EC ?? 89 08 8B 45 ?? + C1 E8 ?? F7 D0 23 C1 6A ?? 59 89 45 ?? 8B FC 8D 45 ?? 50 FF 75 ?? F3 A5 E8 ?? ?? ?? + ?? 8B F8 83 C4 ?? 89 7D ?? BA ?? ?? ?? ?? 83 FF ?? 75 ?? 8B 4D ?? 8B C1 23 C2 3B C2 + 75 ?? F6 45 ?? ?? 74 ?? 83 EC ?? 8D 45 ?? 81 E1 ?? ?? ?? ?? 8D 75 ?? 89 4D ?? 6A ?? + 59 8B FC 50 FF 75 ?? F3 A5 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 89 7D ?? 83 FF ?? 75 ?? 8B + 0B 8B C1 83 E1 ?? C1 F8 ?? 6B C9 ?? 8B 04 85 ?? ?? ?? ?? 80 64 08 ?? ?? FF 15 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 59 E9 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? + ?? ?? ?? 8B F0 56 E8 ?? ?? ?? ?? 59 8B 0B 8B C1 83 E1 ?? C1 F8 ?? 6B C9 ?? 57 8B 04 + 85 ?? ?? ?? ?? 80 64 08 ?? ?? FF 15 ?? ?? ?? ?? 85 F6 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? + ?? C7 00 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 F8 ?? 75 ?? 8A 45 ?? 0C ?? EB ?? 83 F8 ?? 8A + } + $encrypt_files_p2 = { + 45 ?? 75 ?? 0C ?? 57 FF 33 88 45 ?? E8 ?? ?? ?? ?? 8A 55 ?? 59 59 8B 0B 80 CA ?? 8B + C1 88 55 ?? 83 E1 ?? C1 F8 ?? 6B C9 ?? 88 55 ?? 8B 04 85 ?? ?? ?? ?? 88 54 08 ?? 8B + 0B 8B C1 83 E1 ?? C1 F8 ?? 6B C9 ?? F6 45 ?? ?? 8B 04 85 ?? ?? ?? ?? C6 44 08 ?? ?? + 74 ?? FF 33 E8 ?? ?? ?? ?? 8B F0 59 85 F6 75 ?? 8D 45 ?? C6 45 ?? ?? 50 FF 75 ?? 8D + 75 ?? 83 EC ?? 6A ?? 59 8B FC FF 33 F3 A5 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B F0 + FF 33 E8 ?? ?? ?? ?? 59 8B C6 E9 ?? ?? ?? ?? 8B 03 8B C8 83 E0 ?? C1 F9 ?? 6B D0 ?? + 8A 45 ?? 8B 0C 8D ?? ?? ?? ?? 88 44 11 ?? 8B 0B 8B C1 C1 F8 ?? 83 E1 ?? 6B D1 ?? 8B + 0C 85 ?? ?? ?? ?? 8B 45 ?? C1 E8 ?? 32 44 11 ?? 24 ?? 30 44 11 ?? F6 45 ?? ?? 75 ?? + F6 45 ?? ?? 74 ?? 8B 0B 8B C1 83 E1 ?? C1 F8 ?? 6B C9 ?? 8B 04 85 ?? ?? ?? ?? 80 4C + 08 ?? ?? 8B 75 ?? B9 ?? ?? ?? ?? 8B C6 23 C1 3B C1 0F 85 ?? ?? ?? ?? F6 45 ?? ?? 74 + ?? FF 75 ?? FF 15 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 81 E6 ?? ?? ?? ?? 89 75 ?? 8D 75 ?? + 6A ?? 59 8B FC 50 FF 75 ?? F3 A5 E8 ?? ?? ?? ?? 8B D0 83 C4 ?? 83 FA ?? 75 ?? FF 15 + ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 0B 8B C1 83 E1 ?? C1 F8 ?? 6B C9 ?? 8B 04 85 ?? ?? + ?? ?? 80 64 08 ?? ?? FF 33 E8 ?? ?? ?? ?? 59 E9 ?? ?? ?? ?? 8B 0B 8B C1 C1 F8 ?? 83 + E1 ?? 6B C9 ?? 8B 04 85 ?? ?? ?? ?? 89 54 08 ?? 33 C0 5F 5E 5B 8B E5 5D C3 + } + $shutdown_services_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 65 ?? 8B F9 8B 75 ?? 8B 1D + ?? ?? ?? ?? FF D3 83 7E ?? ?? 89 45 ?? 72 ?? 8B 36 6A ?? 56 FF 37 FF 15 ?? ?? ?? ?? + 8B F0 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 8D 45 ?? 50 6A ?? 56 FF 15 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 75 ?? 56 FF 15 ?? ?? ?? ?? 8B + 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 ?? + ?? 83 F8 ?? 75 ?? 66 90 FF 77 ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 8D 45 ?? 50 6A + ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF D3 2B 45 ?? 3B + 47 ?? 0F 87 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8B CF E8 + ?? ?? ?? ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 75 ?? 50 6A ?? 56 FF 15 ?? ?? ?? ?? 85 + C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 + } + $shutdown_services_p2 = { + FF 77 ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 8D 45 ?? 50 6A ?? 56 FF 15 ?? ?? ?? ?? + 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? FF D3 2B 45 ?? 3B 47 ?? 0F 87 + ?? ?? ?? ?? 83 7D ?? ?? 75 ?? E9 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 + ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($shutdown_services_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Hddcryptor : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects HDDCryptor ransomware." + author = "ReversingLabs" + id = "2c6a8ca3-0f7a-52b7-af6d-74fa9407feca" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.HDDCryptor.yara#L1-L157" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "47915f315bb4956507362f56024f5632cb1bcec569ceaf77fe9d7cb9c25d1d8a" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "HDDCryptor" + tc_detection_factor = 5 + importance = 25 + + strings: + $deploy_components = { + B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 66 83 BD ?? ?? ?? ?? ?? 6A ?? 53 0F 85 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 6A ?? 68 ?? + ?? ?? ?? BA ?? ?? ?? ?? 8B CB 8B F0 E8 ?? ?? ?? ?? 8B F8 6A ?? 0F AF FE 68 ?? ?? ?? + ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 8B F0 6A ?? 0F AF F7 68 ?? ?? ?? ?? BA ?? ?? + ?? ?? 8B CB E8 ?? ?? ?? ?? 8B F8 6A ?? 0F AF FE 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB + E8 ?? ?? ?? ?? 8B F0 6A ?? 0F AF F7 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? + ?? 6A ?? 68 ?? ?? ?? ?? E9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BA ?? + ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB 8B F0 E8 ?? + ?? ?? ?? 8B F8 6A ?? 0F AF FE 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 8B + F0 6A ?? 0F AF F7 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 8B F8 6A ?? 0F + AF FE 68 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 8B F0 6A ?? 0F AF F7 68 ?? + ?? ?? ?? BA ?? ?? ?? ?? 8B CB E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B F8 BA ?? ?? ?? + ?? 0F AF FE 8B CB E8 + } + $get_shares_info = { + E8 ?? ?? ?? ?? 83 C4 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 85 C0 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? EB ?? FF 15 ?? ?? + ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF D6 8D 44 24 ?? 50 C7 44 24 ?? + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + FF 15 + } + $encrypt_discs = { + 68 ?? ?? ?? ?? FF 74 24 ?? 0F 57 C0 66 0F 7F 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 33 C9 EB ?? 8D 49 ?? 0F B7 81 ?? ?? ?? ?? 66 89 84 0C ?? ?? ?? ?? 8D 49 ?? 66 + 85 C0 75 ?? 8D 8C 24 ?? ?? ?? ?? 83 C1 ?? 66 8B 41 ?? 8D 49 ?? 66 85 C0 75 ?? A1 ?? + ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 + ?? A1 ?? ?? ?? ?? 89 41 ?? 0F B7 05 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 66 89 41 + ?? 8D 84 24 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF + D7 B9 ?? ?? ?? ?? E8 + } + $create_diskcryptor_service = { + 83 EC ?? 53 55 56 57 68 ?? ?? ?? ?? 33 ED 8B F2 55 55 8B F9 FF 15 ?? ?? ?? ?? 85 C0 + 74 ?? 55 55 55 55 55 FF 74 24 ?? 55 6A ?? 5B 53 6A ?? 68 ?? ?? ?? ?? 56 57 50 FF 15 + ?? ?? ?? ?? 8B F0 89 5C 24 ?? B8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 33 + C9 89 44 24 ?? 41 8D 44 24 ?? 89 4C 24 ?? 89 44 24 ?? 8D 44 24 ?? 50 53 56 89 4C 24 + ?? C7 44 24 ?? ?? ?? ?? ?? 89 6C 24 ?? FF 15 ?? ?? ?? ?? 8B C6 5F 5E 5D 5B 83 C4 ?? + C3 + } + $extract_diskcryptor_from_resources = { + 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 55 56 8B B4 24 ?? ?? + ?? ?? 33 C0 57 50 89 54 24 ?? 8B E9 FF 15 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 8B D8 56 + 0F B7 C9 51 53 FF 15 ?? ?? ?? ?? 8B F0 56 53 FF 15 ?? ?? ?? ?? 56 53 8B F8 FF 15 ?? + ?? ?? ?? 57 89 44 24 ?? FF 15 ?? ?? ?? ?? FF 74 24 ?? 8B F0 E8 ?? ?? ?? ?? 59 FF 74 + 24 ?? 8B D8 56 53 E8 ?? ?? ?? ?? 8B 54 24 ?? 33 FF 83 C4 ?? 8B CF 85 D2 7E ?? 8A 04 + 19 3C ?? 7C ?? 3C ?? 7F ?? 04 ?? 3C ?? 76 ?? 2C ?? 88 04 19 41 3B CA 7C ?? 33 C0 68 + ?? ?? ?? ?? 66 89 44 24 ?? 8D 44 24 ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F5 66 8B 45 + ?? 83 C5 ?? 66 3B C7 75 ?? 8D 7C 24 ?? 2B EE 83 EF ?? 33 C9 66 8B 47 ?? 83 C7 ?? 66 + 3B C1 75 ?? 8B CD C1 E9 ?? F3 A5 8B CD 83 E1 ?? F3 A4 8D 7C 24 ?? 83 EF ?? 33 ED 66 + 8B 47 ?? 8D 7F ?? 66 3B C5 75 ?? A1 ?? ?? ?? ?? 8B 54 24 ?? 8B F2 89 07 66 8B 02 83 + C2 ?? 66 3B C5 75 ?? 8D 7C 24 ?? 2B D6 83 EF ?? 66 8B 47 ?? 83 C7 ?? 66 3B C5 75 ?? + 8B CA 8D 44 24 ?? C1 E9 ?? F3 A5 55 55 6A ?? 55 55 8B CA 83 E1 ?? 68 ?? ?? ?? ?? F3 + A4 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 74 ?? 55 8D 44 24 ?? 50 FF 74 24 ?? 53 56 FF + 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 33 C0 40 EB ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 + C0 8B 8C 24 ?? ?? ?? ?? 5F 5E 5D 5B 33 CC E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? C3 + } + $encrypt_files_using_diskcryptor_p1 = { + 55 8B EC 83 E4 ?? 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? + ?? ?? ?? 33 C4 89 84 24 ?? ?? ?? ?? 53 56 57 A1 ?? ?? ?? ?? 33 C4 50 8D 84 24 ?? ?? + ?? ?? 64 A3 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D3 83 7D ?? ?? 73 ?? B9 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 8B 75 ?? BA ?? ?? ?? ?? 8B 4E ?? 8A 01 41 88 02 42 84 C0 75 ?? 8B 4E ?? BA + ?? ?? ?? ?? 8A 01 41 88 02 42 84 C0 75 ?? 6A ?? 59 BE ?? ?? ?? ?? C7 05 ?? ?? ?? ?? + ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? F3 A5 68 ?? ?? ?? ?? + 33 F6 8D 84 24 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 54 24 ?? 89 B4 24 ?? ?? ?? ?? + 8D 4C 24 ?? E8 ?? ?? ?? ?? 56 6A ?? 8D 4C 24 ?? C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 7C 24 ?? ?? 8D 44 24 ?? 56 0F 43 44 24 ?? 56 6A ?? 56 56 68 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D3 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 33 DB C7 44 + } + $encrypt_files_using_diskcryptor_p2 = { + 24 ?? ?? ?? ?? ?? 50 89 5C 24 ?? 89 5C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 53 FF 15 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B D0 59 59 85 D2 + 75 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 59 8B D0 8D BC 24 ?? ?? ?? ?? 83 EF ?? 66 + 8B 47 ?? 8D 7F ?? 66 3B C3 75 ?? A1 ?? ?? ?? ?? 83 C2 ?? 89 07 8B F2 66 8B 02 83 C2 + ?? 66 3B C3 75 ?? 8D BC 24 ?? ?? ?? ?? 2B D6 83 EF ?? 66 8B 47 ?? 83 C7 ?? 66 3B C3 + 75 ?? 8B CA 8D 84 24 ?? ?? ?? ?? C1 E9 ?? F3 A5 8B CA 83 E1 ?? F3 A4 51 50 83 EC ?? + 8B CC 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 C6 84 + 24 ?? ?? ?? ?? ?? 83 7E ?? ?? 72 ?? 8B 36 83 EC ?? 8B CC 68 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 72 ?? 8B 00 8B D6 8B C8 + E8 ?? ?? ?? ?? 59 59 53 6A ?? 8D 4C 24 ?? 8B F0 E8 ?? ?? ?? ?? 53 6A ?? 8D 4C 24 ?? + C6 84 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 F6 74 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B F3 EB ?? FF 15 ?? ?? ?? ?? 8B F0 53 6A ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? + 8B C6 EB ?? 53 6A ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 33 C0 8B 8C 24 ?? ?? ?? ?? 64 89 0D + ?? ?? ?? ?? 59 5F 5E 5B 8B 8C 24 ?? ?? ?? ?? 33 CC E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $reboot = { + 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 8D 45 ?? 50 6A ?? FF 15 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 33 C0 EB ?? 8D 45 ?? 33 F6 50 68 ?? ?? ?? ?? 56 + FF 15 ?? ?? ?? ?? 56 56 56 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 56 FF 75 ?? C7 45 ?? ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 6A ?? FF 15 + ?? ?? ?? ?? F7 D8 1B C0 F7 D8 8B 4D ?? 33 CD 5E E8 ?? ?? ?? ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and ((($deploy_components) and ($get_shares_info) and ($encrypt_discs)) or (($extract_diskcryptor_from_resources) and ($create_diskcryptor_service) and ( all of ($encrypt_files_using_diskcryptor_p*)) and ($reboot))) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Janelle : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Janelle ransomware." + author = "ReversingLabs" + id = "4fef3be5-8332-5ce2-b1e9-3993e6963331" + date = "2021-12-16" + modified = "2021-12-16" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Janelle.yara#L1-L96" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "49f1eac82930606183ab9cf1d5c6c42534d58735876134793e9712e78eb5a4c7" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Janelle" + tc_detection_factor = 5 + importance = 25 + + strings: + $setup_env_p1 = { + 00 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 73 ?? ?? ?? ?? 0A 06 02 7D ?? ?? + ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 2B ?? 08 6F + ?? ?? ?? ?? 74 ?? ?? ?? ?? 0D 00 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 6F ?? ?? ?? ?? 6F + ?? ?? ?? ?? 6F ?? ?? ?? ?? 26 00 08 6F ?? ?? ?? ?? 2D ?? DE ?? 08 75 ?? ?? ?? ?? 13 ?? + 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? 00 DC 02 7B ?? ?? ?? ?? 16 6F ?? ?? ?? ?? 00 16 28 ?? + ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 FE 01 13 ?? 11 ?? 2C ?? 00 16 + 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 16 28 ?? + ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 28 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 02 16 28 ?? ?? ?? ?? 00 00 28 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 6F ?? ?? ?? ?? 16 FE 02 16 FE 01 13 ?? 11 ?? 2C ?? 00 28 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? + 12 ?? 23 ?? ?? ?? ?? ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? + ?? 00 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 23 ?? ?? ?? ?? ?? ?? ?? ?? 28 ?? ?? ?? + ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 02 + } + $setup_env_p2 = { + 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 7B ?? ?? ?? ?? 28 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 2B ?? 00 16 28 ?? ?? ?? ?? 72 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 72 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 + 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 28 ?? ?? ?? ?? 16 28 + ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 28 ?? ?? ?? ?? 02 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 00 06 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 7D ?? ?? ?? ?? 16 28 ?? ?? ?? ?? + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 28 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 + ?? 11 ?? 2C ?? 00 02 17 7D ?? ?? ?? ?? 06 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? + ?? 25 17 6F ?? ?? ?? ?? 00 6F ?? ?? ?? ?? 00 06 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 02 + 7B ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? + ?? ?? 00 00 2A + } + $find_files = { + 73 ?? ?? ?? ?? 0A 06 02 7D ?? ?? ?? ?? 06 04 7D ?? ?? ?? ?? 06 05 7D ?? ?? ?? ?? 00 00 + 03 28 ?? ?? ?? ?? 0B 00 07 0C 16 0D 2B ?? 08 09 9A 13 ?? 00 02 11 ?? 06 7B ?? ?? ?? ?? + 28 ?? ?? ?? ?? 00 00 09 17 58 0D 09 08 8E 69 32 ?? 06 7B ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? + 00 00 00 03 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 06 7D ?? ?? + ?? ?? 11 ?? 11 ?? 11 ?? 9A 7D ?? ?? ?? ?? 00 11 ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 + ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 00 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? + 8E 69 32 ?? 00 DE ?? 13 ?? 00 72 ?? ?? ?? ?? 03 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 DE + ?? 00 00 DE ?? 26 00 72 ?? ?? ?? ?? 03 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 DE ?? 2A + } + $encrypt_files = { + 00 28 ?? ?? ?? ?? 0A 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 18 73 ?? ?? ?? ?? 0B 28 ?? ?? ?? + ?? 04 6F ?? ?? ?? ?? 0C 73 ?? ?? ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 20 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 00 09 18 6F ?? ?? ?? ?? 00 08 06 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? + 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 11 ?? 09 6F + ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 1A 6F ?? ?? ?? ?? 00 07 06 16 06 + 8E 69 6F ?? ?? ?? ?? 00 07 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 03 19 73 ?? ?? ?? + ?? 13 ?? 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? 13 ?? 00 2B ?? 00 28 ?? ?? ?? ?? 00 11 ?? 11 ?? + 16 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 25 13 ?? 16 FE + 02 13 ?? 11 ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 13 ?? 00 72 ?? ?? ?? ?? 11 ?? 6F + ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 DE ?? DE ?? 00 11 ?? 6F ?? ?? ?? ?? 00 + 07 6F ?? ?? ?? ?? 00 00 DC 2A + } + + condition: + uint16(0)==0x5A4D and ( all of ($setup_env_p*)) and ($find_files) and ($encrypt_files) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Apis : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Apis ransomware." + author = "ReversingLabs" + id = "63791250-e21e-53d1-932c-9b5d16a7cad9" + date = "2021-11-25" + modified = "2021-11-25" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Apis.yara#L1-L75" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0915469884a268f124da348d6a182eb4a0f69063d4041b46628794ab011227ef" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Apis" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files = { + 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 0A 06 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 2C ?? 06 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E + 69 32 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 7E ?? ?? ?? ?? + 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 0D 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 + ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 7E + ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? + 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 13 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 07 28 ?? ?? + ?? ?? 08 28 ?? ?? ?? ?? 09 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 + ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? + 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 2A + } + $encrypt_files = { + 02 28 ?? ?? ?? ?? 0A 17 0B 16 0C 38 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 06 08 9A 28 + ?? ?? ?? ?? 7D ?? ?? ?? ?? 06 08 9A 28 ?? ?? ?? ?? 0D 7E ?? ?? ?? ?? 11 ?? FE 06 ?? ?? + ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 09 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 + ?? ?? ?? ?? 06 08 9A 73 ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 11 ?? 6F + ?? ?? ?? ?? 20 ?? ?? ?? ?? 6A 2F ?? 28 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? + 18 5B 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 06 08 9A 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 06 08 9A 06 08 9A 72 ?? ?? ?? ?? 1A 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2B ?? + 28 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 1A 5B 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 13 ?? 06 08 9A 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 06 08 9A 06 08 9A 72 ?? ?? ?? ?? 1A + 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 07 2C ?? 16 0B 02 72 ?? ?? ?? ?? 7E ?? ?? + ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 08 17 58 0C 08 06 8E + 69 3F ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 28 ?? ?? ?? ?? + 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? DE ?? 26 DE ?? 2A + } + $setup_env = { + 28 ?? ?? ?? ?? 2C ?? 17 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? + ?? 2C ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? + ?? 2C ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 2B ?? 7E ?? ?? ?? ?? 2C ?? + 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? + 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2D ?? 14 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? + 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 7E ?? + ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2A + } + + condition: + uint16(0)==0x5A4D and ($setup_env) and ($find_files) and ($encrypt_files) +} +rule REVERSINGLABS_Win64_Ransomware_Curator : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Curator ransomware." + author = "ReversingLabs" + id = "401f1d64-afd9-55b1-8e87-b808d4679e9a" + date = "2021-04-22" + modified = "2021-04-22" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Curator.yara#L1-L94" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "8bd29195cea0f1194e27c48ed07c52100abb7dd3de2ef7f51a645d32c3527eb3" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Curator" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 44 8B CB C7 44 24 ?? ?? ?? ?? ?? 45 33 C0 48 8D 8D ?? ?? ?? ?? 33 D2 FF 15 ?? ?? ?? + ?? 48 8B BD ?? ?? ?? ?? 4C 8D 35 ?? ?? ?? ?? 48 85 FF 0F 84 ?? ?? ?? ?? 48 8B 0D ?? + ?? ?? ?? 41 8B DC 48 81 C1 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 7E ?? 45 33 F6 48 8B + 05 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? BA ?? ?? ?? ?? 41 0F BE 8C 06 ?? ?? ?? ?? 45 0F + BE 8C 06 ?? ?? ?? ?? 89 4C 24 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 D2 48 8D 8D + ?? ?? ?? ?? 44 8D 42 ?? E8 ?? ?? ?? ?? 8B CB 4D 8D 76 ?? FF C3 41 83 C4 ?? 88 84 0D + ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 81 C1 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 44 3B E0 7C + ?? 4C 8D 35 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 45 33 E4 48 89 44 24 ?? 48 8D 95 ?? ?? + ?? ?? 45 33 C9 44 89 64 24 ?? 44 8B C3 48 8B CF FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? + ?? ?? 48 8B 1D ?? ?? ?? ?? 48 8D 4C 24 ?? 48 8B 15 ?? ?? ?? ?? 4C 8B C3 E8 ?? ?? ?? + ?? 48 8B 8D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 45 8D 44 24 ?? + 48 89 44 24 ?? 45 33 C9 48 8D 44 24 ?? 89 9D ?? ?? ?? ?? 33 D2 48 89 44 24 ?? FF 15 + ?? ?? ?? ?? 85 C0 74 ?? 41 8B DC 44 39 A5 ?? ?? ?? ?? 76 ?? 8B C3 4C 8D 05 ?? ?? ?? + ?? BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 44 0F B6 4C 04 ?? E8 ?? ?? ?? ?? 48 8D 95 ?? + ?? ?? ?? 49 8B CE FF 15 ?? ?? ?? ?? FF C3 3B 9D ?? ?? ?? ?? 72 ?? 48 8B 8D ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 33 D2 48 8B CF FF 15 ?? ?? ?? ?? B9 + } + $encrypt_files_p2 = { + 48 8B C4 48 89 58 ?? 48 89 70 ?? 48 89 78 ?? 55 41 54 41 55 41 56 41 57 48 8D A8 ?? + ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 2B E0 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 + 85 ?? ?? ?? ?? 45 33 E4 C7 44 24 ?? ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 44 89 25 ?? ?? ?? + ?? 48 8D 95 ?? ?? ?? ?? 44 89 25 ?? ?? ?? ?? 33 C9 44 89 25 ?? ?? ?? ?? 45 8B FC 4C + 89 25 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 63 C8 + 48 8D 85 ?? ?? ?? ?? 48 8D 04 48 48 83 C0 ?? 66 83 38 ?? 75 ?? 66 44 89 20 4C 8D 05 + ?? ?? ?? ?? 48 83 C0 ?? 4C 89 64 24 ?? 48 89 05 ?? ?? ?? ?? 45 33 C9 48 8D 05 ?? ?? + ?? ?? 44 89 64 24 ?? 33 D2 48 89 05 ?? ?? ?? ?? 33 C9 FF 15 ?? ?? ?? ?? 33 D2 33 C9 + 44 8D 42 ?? FF 15 ?? ?? ?? ?? 48 8B F0 48 85 C0 74 ?? 48 8B 1D ?? ?? ?? ?? 48 81 C3 + ?? ?? ?? ?? EB ?? 48 8B CB FF 15 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8B D3 48 8B CE 44 + 8B F0 FF 15 ?? ?? ?? ?? 48 8B F8 48 85 C0 74 ?? 4C 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? + 48 8B C8 FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 41 8D 46 + } + $find_files = { + 48 89 5C 24 ?? 48 89 7C 24 ?? 55 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 8B + 05 ?? ?? ?? ?? 48 33 C4 48 89 85 ?? ?? ?? ?? 48 8B F9 4C 8D 05 ?? ?? ?? ?? 4C 8B C9 + BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8D 8D ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 0F 84 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? + 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF + 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 44 24 ?? 4C 8B CF 4C 8D 05 ?? ?? ?? ?? 48 89 44 24 + ?? BA ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? F6 44 24 ?? ?? 48 8D 8D ?? + ?? ?? ?? 74 ?? 48 8D 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? EB ?? FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 0F 85 + ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? + ?? 48 33 CC E8 ?? ?? ?? ?? 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? 49 8B 7B ?? 49 8B E3 + 5D C3 + } + $remote_connection = { + 44 0F B7 45 ?? 33 DB 48 8B 55 ?? 45 33 C9 48 89 5C 24 ?? 48 8B CE 89 5C 24 ?? C7 44 + 24 ?? ?? ?? ?? ?? 48 89 5C 24 ?? FF 15 ?? ?? ?? ?? 4C 8B F0 48 85 C0 0F 84 ?? ?? ?? + ?? 80 7D ?? ?? B9 ?? ?? ?? ?? 4C 8B 45 ?? B8 ?? ?? ?? ?? 48 8B 55 ?? 0F 44 C8 48 89 + 5C 24 ?? 45 33 C9 89 4C 24 ?? 89 4D ?? 49 8B CE 48 89 5C 24 ?? 48 89 5C 24 ?? FF 15 + ?? ?? ?? ?? 48 8B D8 48 85 C0 0F 84 ?? ?? ?? ?? 83 65 ?? ?? 4C 8D 4D ?? 4C 8D 45 ?? + C7 45 ?? ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8B C8 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 81 4D ?? + ?? ?? ?? ?? 4C 8D 45 ?? 41 B9 ?? ?? ?? ?? 48 8B CB 41 8D 51 ?? FF 15 ?? ?? ?? ?? 4C + 8B 4D ?? 48 8B C7 48 F7 D8 48 8B D7 8B 45 ?? 48 8B CB 45 1B C0 89 44 24 ?? FF 15 ?? + ?? ?? ?? 85 C0 74 ?? 33 FF 83 65 ?? ?? 48 8D 55 ?? 45 33 C9 45 33 C0 48 8B CB FF 15 + ?? ?? ?? ?? 85 C0 74 ?? 8B 55 ?? 49 8B CF 03 D7 E8 ?? ?? ?? ?? 44 8B 45 ?? 4C 8D 4D + ?? 8B D7 48 8B CB 48 03 D0 4C 8B F8 FF 15 ?? ?? ?? ?? 8B 45 ?? 03 F8 EB ?? 8B 45 + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($remote_connection) +} +rule REVERSINGLABS_Win32_Ransomware_Kangaroo : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Kangaroo ransomware." + author = "ReversingLabs" + id = "ec4342c1-adc9-5ddb-b403-83c2b1ce5899" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Kangaroo.yara#L1-L91" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "1078fb3d47ad737548419e5ee66e686f705c02fea27a58c0097446547325772c" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Kangaroo" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 83 EC ?? 53 55 8B 6C 24 ?? 56 57 33 FF 57 57 6A ?? 57 6A ?? 68 ?? ?? ?? ?? 33 DB 55 + 89 5C 24 ?? 89 7C 24 ?? 89 7C 24 ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 0F 84 ?? ?? ?? + ?? 8D 44 24 ?? 50 8D 4C 24 ?? 51 8D 54 24 ?? 52 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 57 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? + 8B 54 24 ?? 8D 4C 24 ?? 51 57 57 68 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 + ?? ?? ?? ?? 57 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 03 C0 50 8B 44 24 ?? 68 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 54 24 ?? 8B 44 24 ?? 8D 4C 24 ?? + 51 6A ?? 52 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 57 56 FF + 15 ?? ?? ?? ?? 8B 54 24 ?? 57 8D 4C 24 ?? 51 57 57 6A ?? 57 52 89 44 24 ?? FF 15 ?? + ?? ?? ?? 8B 44 24 ?? 6A ?? 68 ?? ?? ?? ?? 50 57 8B 3D ?? ?? ?? ?? FF D7 8B 54 24 + } + $encrypt_files_p2 = { + 6A ?? 8D 4C 24 ?? 51 52 8B D8 53 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B + 44 24 ?? 8B 54 24 ?? 50 8D 4C 24 ?? 51 53 6A ?? 6A ?? 6A ?? 52 FF 15 ?? ?? ?? ?? 83 + F8 ?? 0F 85 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? + 8B 4C 24 ?? 6A ?? 8D 44 24 ?? 50 51 53 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 8D 54 24 + ?? 52 8D 44 24 ?? 50 8D 4C 24 ?? 51 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF D7 68 ?? ?? ?? ?? 55 8B F8 68 ?? ?? ?? ?? 57 + FF 15 ?? ?? ?? ?? 83 C4 ?? 57 55 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? + ?? ?? ?? 8B C5 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 53 FF 15 + ?? ?? ?? ?? 8B 54 24 ?? 52 FF 15 ?? ?? ?? ?? 8B 5C 24 ?? 33 FF 8B 44 24 ?? 50 FF 15 + ?? ?? ?? ?? 89 7C 24 ?? 8B 4C 24 ?? 57 51 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 5F + 5E 5D 8B C3 5B 83 C4 ?? C3 + } + $find_files = { + 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 8B 75 ?? 57 56 FF 15 ?? ?? ?? ?? 8B 3D ?? + ?? ?? ?? 33 C9 83 F8 ?? 0F 94 C1 56 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 89 4C 24 + ?? FF D7 83 C4 ?? 8D 44 24 ?? 50 8D 8C 24 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 44 24 + ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? EB ?? EB ?? 8D A4 24 ?? ?? ?? ?? 90 + 8B 3D ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 8D 54 24 ?? 52 56 68 ?? ?? ?? ?? 8D 84 24 ?? + ?? ?? ?? 50 EB ?? 8D 4C 24 ?? 51 56 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 FF D7 83 + C4 ?? F6 44 24 ?? ?? 74 ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D7 85 + C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? 51 FF D7 85 C0 0F 84 ?? ?? ?? ?? 8D + 94 24 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 33 FF 33 F6 EB ?? 8D 9B + ?? ?? ?? ?? 8B 86 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? 51 FF D3 85 C0 74 ?? BF ?? ?? + ?? ?? 83 C6 ?? 83 FE ?? 72 ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 FF D3 85 C0 75 + ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D3 85 C0 74 ?? BF ?? ?? ?? ?? 8B 44 24 + ?? A8 ?? 75 ?? A9 ?? ?? ?? ?? 75 ?? 85 FF 75 ?? 3D ?? ?? ?? ?? 74 ?? 68 ?? ?? ?? ?? + 8D 8C 24 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 75 ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 8C + 24 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B 75 ?? 8B 44 24 ?? 8D 54 24 ?? 52 50 FF 15 ?? + ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 4C 24 ?? 51 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D + C3 + } + $enum_resources = { + 55 8B EC 83 E4 ?? 83 EC ?? 8B 4D ?? 53 56 57 8D 44 24 ?? 50 51 6A ?? 6A ?? 6A ?? C7 + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5F 5E + 5B 8B E5 5D C2 ?? ?? 8B 54 24 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 8B D8 85 DB 74 ?? 8B 4C + 24 ?? 8B C3 85 C9 74 ?? 8D 64 24 ?? C6 00 ?? 40 83 E9 ?? 75 ?? 8B 54 24 ?? 8D 44 24 + ?? 50 53 8D 4C 24 ?? 51 52 E8 ?? ?? ?? ?? 85 C0 75 ?? 33 FF 39 7C 24 ?? 76 ?? 8D 73 + ?? 8D 49 ?? 83 7E ?? ?? 75 ?? 8B 06 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4E ?? 83 E1 ?? 80 + F9 ?? 75 ?? 8D 56 ?? 52 E8 ?? ?? ?? ?? 47 83 C6 ?? 3B 7C 24 ?? 72 ?? EB ?? 3D ?? ?? + ?? ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 50 E8 ?? ?? ?? ?? 5F 5E B8 ?? ?? ?? ?? + 5B 8B E5 5D C2 + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($enum_resources) +} +rule REVERSINGLABS_Win32_Ransomware_Knot : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Knot ransomware." + author = "ReversingLabs" + id = "4dfe9da5-7ab1-57dc-95fc-b05777f235b8" + date = "2021-03-19" + modified = "2021-03-19" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Knot.yara#L1-L118" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "a7a3e13139d68314e583ec225a5d56373a551e67d46984dcf9a228a1f7275f14" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Knot" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 + FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 32 C0 E9 ?? ?? ?? ?? 6A ?? 8B 4D ?? 51 + FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 32 C0 E9 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? + 6A ?? 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 32 C0 E9 ?? ?? + ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 + ?? 32 C0 E9 ?? ?? ?? ?? 8D 4D ?? 51 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 52 + FF 15 ?? ?? ?? ?? 85 C0 75 ?? 32 C0 E9 ?? ?? ?? ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 8B + 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 32 C0 E9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 + C0 75 ?? 32 C0 E9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 32 C0 E9 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 FF 15 + } + $encrypt_files_p2 = { + 85 C0 75 ?? 32 C0 E9 ?? ?? ?? ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF + 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 95 + ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 6A + ?? 8D 95 ?? ?? ?? ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 8B + 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 6A + ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 + ?? 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 8B 45 ?? 50 8B 4D + ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 8B 45 ?? 50 8B 8D ?? ?? ?? + ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 + ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 + FF 15 ?? ?? ?? ?? B0 ?? 8B E5 5D C3 + } + $find_files_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 85 + ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 0F B7 8D ?? ?? ?? ?? 83 F9 ?? 0F 84 ?? ?? + ?? ?? 8B 95 ?? ?? ?? ?? 83 E2 ?? 89 95 ?? ?? ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 + ?? ?? ?? ?? 83 F8 ?? 75 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF 15 + ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 + ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? EB ?? 8B 8D ?? ?? ?? ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? + 73 ?? 8B 95 ?? ?? ?? ?? 8B 04 95 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? + 83 C4 ?? 85 C0 74 ?? C6 85 ?? ?? ?? ?? ?? EB ?? 0F B6 95 ?? ?? ?? ?? 83 FA ?? 75 + } + $find_files_p2 = { + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? 83 C0 ?? 89 85 ?? ?? ?? ?? 83 + BD ?? ?? ?? ?? ?? 73 ?? 8B 8D ?? ?? ?? ?? 8B 14 8D ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? C6 85 ?? ?? ?? ?? ?? EB ?? 0F B6 8D ?? ?? ?? + ?? 83 F9 ?? 0F 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? + ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? + ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? + ?? ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 95 ?? + ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? + ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? + 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? + 51 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? + 8B E5 5D C3 + } + $remote_connection = { + 55 8B EC 81 EC ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A + ?? FF 15 ?? ?? ?? ?? 89 45 ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? 6A ?? FF 15 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 0F B6 C0 83 F8 ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 0F B6 C8 83 F9 ?? 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 99 B9 ?? ?? ?? ?? F7 F9 81 C2 ?? ?? ?? ?? 52 8D 95 ?? ?? ?? ?? + 52 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 8D 8D + ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 E8 ?? + ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 + FF 15 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 6A ?? + 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 95 ?? ?? + ?? ?? 83 C2 ?? 89 95 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7F ?? 8D 85 ?? ?? ?? ?? 50 8B + 8D ?? ?? ?? ?? 51 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 83 BD ?? ?? ?? ?? ?? 74 + ?? EB ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 8D 95 ?? ?? ?? ?? 52 + E8 ?? ?? ?? ?? 83 C4 ?? EB ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF + 15 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 6A ?? FF 15 ?? ?? ?? ?? 33 C0 8B E5 5D C2 + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($remote_connection) +} +rule REVERSINGLABS_Win32_Ransomware_Dogecrypt : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects DogeCrypt ransomware." + author = "ReversingLabs" + id = "e0ca22a5-70bb-5d2c-bce4-bac49c2a81d2" + date = "2021-04-28" + modified = "2021-04-28" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.DogeCrypt.yara#L1-L114" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "1c19862884cf1e59d12c84f5ff6f799a4087ddc8bd887e0d2ce7da053642b851" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "DogeCrypt" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_DogeCrypt_p1 = { + 50 E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? + ?? BA ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 2B C6 89 B5 ?? ?? ?? ?? 3B C8 77 ?? 83 BD ?? ?? ?? ?? + ?? 8D 3C 31 8D 04 09 89 BD ?? ?? ?? ?? 50 8B 85 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 0F 43 + B5 ?? ?? ?? ?? 52 8D 04 46 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 04 7E EB ?? 51 52 + C6 85 ?? ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? + ?? 8D 45 ?? 8B 35 ?? ?? ?? ?? 0F 43 45 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 + ?? ?? ?? ?? 50 FF D6 8B F8 83 FF ?? 74 ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A + ?? 0F 43 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF D6 8B + F0 83 FE ?? 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B + 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? + 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? + ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? + ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? + ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? + ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? + ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? + ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? + ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 + } + $encrypt_files_DogeCrypt_p2 = { + C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 83 + FA ?? 0F 82 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? + ?? 0F 82 ?? ?? ?? ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? E9 + ?? ?? ?? ?? 90 6A ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF + 15 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? BA ?? ?? ?? ?? 81 F9 ?? ?? ?? ?? 0F 42 DA 85 C0 74 + ?? 85 C9 74 ?? 51 8D 85 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? + 53 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? EB ?? 56 8B 35 ?? ?? ?? ?? FF D6 57 + FF D6 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 52 51 E8 + ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 33 C0 66 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? + ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 + C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 + 5D C3 + } + $find_files_DogeCrypt = { + 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 + F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? ?? + ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? FF + 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 5D ?? 8B + CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 EB ?? 8B + 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 FF + 57 57 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 + C5 89 45 ?? 8B 4D ?? 53 8B 5D ?? 57 8B 7D ?? 89 9D ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 + ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8A 11 80 FA + ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 53 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 DB + 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8A C3 80 FA ?? 75 ?? B0 ?? 0F B6 C0 2B CF 41 F7 D8 56 + 1B C0 23 C1 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? + 83 C4 ?? 8D 85 ?? ?? ?? ?? 53 53 53 50 53 57 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? + ?? 83 FE ?? 75 ?? 50 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 83 FE ?? 74 ?? 56 FF 15 + ?? ?? ?? ?? 8B C3 5E 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 + C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? + 80 F9 ?? 75 ?? 38 9D ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 + 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 + } + $decrypt_DesucryptKeyContainer_DogeCrypt = { + 68 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? 66 89 45 ?? E8 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 8D 55 ?? 83 7D ?? ?? 8B 5D ?? 8B 35 ?? ?? ?? ?? 0F 43 D3 A1 ?? ?? ?? ?? 8B + 4D ?? 2B C6 89 75 ?? 3B C8 77 ?? 83 3D ?? ?? ?? ?? ?? 8D 3C 31 8D 04 09 89 3D ?? ?? + ?? ?? 50 8B 45 ?? BE ?? ?? ?? ?? 0F 43 35 ?? ?? ?? ?? 52 8D 04 46 50 E8 ?? ?? ?? ?? + 83 C4 ?? 33 C0 66 89 04 7E EB ?? 51 52 C6 45 ?? ?? FF 75 ?? 51 B9 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 5D ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8D 0C 45 ?? ?? ?? ?? + 8B C3 81 F9 ?? ?? ?? ?? 72 ?? 8B 5B ?? 83 C1 ?? 2B C3 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? + ?? ?? 51 53 E8 ?? ?? ?? ?? 83 C4 ?? 83 3D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 6A ?? 0F 43 + 05 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 6A ?? 68 ?? ?? + ?? ?? 56 FF D3 83 F8 ?? 0F 85 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 50 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 8D 45 ?? 6A ?? + 50 C6 07 ?? FF 35 ?? ?? ?? ?? 57 56 FF D3 83 F8 ?? 75 ?? BA ?? ?? ?? ?? B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? + ?? ?? 57 FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? BA ?? ?? ?? ?? B9 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? + ?? ?? EB ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? + ?? ?? 8B E5 5D C3 E8 ?? ?? ?? ?? E8 + } + + condition: + uint16(0)==0x5A4D and ($decrypt_DesucryptKeyContainer_DogeCrypt) and ($find_files_DogeCrypt) and ( all of ($encrypt_files_DogeCrypt_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Magniber : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Magniber ransomware." + author = "ReversingLabs" + id = "07b6c938-aa25-5ff6-95d2-9e0f84c41b41" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Magniber.yara#L1-L114" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "05b516f9b466489ea3a30e2fe5eb08290e85ece7a63e29e8bbbeb81c87d0a6f1" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Magniber" + tc_detection_factor = 5 + importance = 25 + + strings: + $remote_connection = { + E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B 55 + ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF + 15 ?? ?? ?? ?? 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 6A ?? 6A ?? 6A ?? 6A ?? + 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 6A + ?? 8D 45 ?? 50 8D 4D ?? 51 68 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 83 7D ?? ?? + 74 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? + ?? 8B 55 ?? 83 C2 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D + ?? ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 33 C0 EB ?? + C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? + ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 + } + $encrypt_files_1 = { + 55 8B EC 83 EC ?? 56 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? + ?? ?? ?? 89 45 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 8B 55 ?? 03 55 ?? 8D 44 12 + ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? EB + ?? 8B 4D ?? 83 C1 ?? 89 4D ?? 8B 55 ?? 3B 55 ?? 7D ?? 8B 45 ?? 8B 4D ?? 8B 55 ?? 8B + 75 ?? 66 8B 14 56 66 89 14 41 EB ?? B8 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 66 89 04 4A C7 + 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 3B 4D ?? 7D ?? 8B 55 ?? + 03 55 ?? 8B 45 ?? 8B 4D ?? 8B 75 ?? 66 8B 0C 4E 66 89 4C 50 ?? EB ?? 8B 55 ?? 03 55 + ?? 33 C0 8B 4D ?? 66 89 44 51 ?? 8D 55 ?? 52 8D 45 ?? 50 8D 4D ?? 51 8B 55 ?? 52 8B + } + $encrypt_files_2 = { + 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? + ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 89 45 ?? 83 + 7D ?? ?? 75 ?? 33 C0 E9 ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 + 75 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? + 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 + ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 45 + ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 66 0F 57 C0 66 0F 13 45 ?? 6A ?? 8D 4D ?? 51 6A ?? + 8B 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 99 8B 4D ?? + 2B 4D ?? 8B 75 ?? 1B 75 ?? 89 45 ?? 89 55 ?? 89 4D ?? 89 75 ?? 8B 55 ?? 3B 55 ?? 7C + ?? 7F ?? 8B 45 ?? 3B 45 ?? 76 ?? 8B 4D ?? 2B 4D ?? 8B 55 ?? 1B 55 ?? 89 4D ?? 89 55 + ?? EB ?? 8B 45 ?? 99 89 45 ?? 89 55 ?? 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B + } + $encrypt_files_3 = { + 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 ?? 33 C0 E9 ?? ?? ?? ?? 83 7D ?? + ?? 75 ?? E9 ?? ?? ?? ?? 8B 4D ?? 3B 4D ?? 73 ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 89 55 + ?? 8B 45 ?? 50 8D 4D ?? 51 6A ?? 6A ?? 8B 55 ?? 52 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? + ?? 89 45 ?? 83 7D ?? ?? 74 ?? 8B 4D ?? 51 8D 55 ?? 52 8B 45 ?? 50 6A ?? 8B 4D ?? 51 + 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 + ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? EB ?? + E9 ?? ?? ?? ?? 8B 45 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 7D ?? ?? + 74 ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? + 83 7D ?? ?? 74 ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 4D ?? 51 8B 55 ?? 52 FF 15 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 3B 45 ?? 7C ?? 7F ?? 8B 4D ?? 3B 4D ?? + 76 ?? 83 7D ?? ?? 74 ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? + 8B 4D ?? 51 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? + 83 C4 ?? B8 ?? ?? ?? ?? EB + } + $search_files = { + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 83 7D ?? ?? 7D ?? 8B 4D ?? 8B 94 + 8D ?? ?? ?? ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 33 C0 E9 ?? ?? ?? + ?? EB ?? 8B 4D ?? 8B 55 ?? 8B 81 ?? ?? ?? ?? 3B 82 ?? ?? ?? ?? 76 ?? B8 ?? ?? ?? ?? + E9 ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 75 ?? B8 ?? + ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 8B 8D ?? ?? ?? ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? + 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? 50 + FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 8B 4D ?? 83 C1 ?? 51 FF 15 ?? ?? ?? ?? + 85 C0 75 ?? EB ?? 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 83 C1 + ?? 51 8D 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 74 ?? 8B 4D ?? 81 79 ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? + ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8B 4D ?? + 81 79 ?? ?? ?? ?? ?? 75 ?? 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? + ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 03 45 ?? 89 + 45 ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 6A ?? 8B 4D ?? 81 C1 ?? ?? ?? ?? 51 8B 55 ?? + 81 C2 ?? ?? ?? ?? 52 8B 45 ?? 05 ?? ?? ?? ?? 50 8B 4D ?? 81 C1 ?? ?? ?? ?? 51 8B 55 + ?? 81 C2 ?? ?? ?? ?? 52 8B 45 ?? 05 ?? ?? ?? ?? 50 8B 4D ?? 81 C1 ?? ?? ?? ?? 51 8B + 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 + } + + condition: + uint16(0)==0x5A4D and ($search_files and ( all of ($encrypt_files_*)) and $remote_connection) +} +rule REVERSINGLABS_Win64_Ransomware_Hotcoffee : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects HotCoffee ransomware." + author = "ReversingLabs" + id = "11b26b91-96ae-58d3-8a8a-02a3e7d0b82e" + date = "2021-11-25" + modified = "2021-11-25" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.HotCoffee.yara#L1-L111" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "15ae428c37fcc5a09d324fd9be5a8df3a812e6459cb1ce8eec56eabf785b4c05" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "HotCoffee" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files = { + 48 85 C9 74 ?? B8 ?? ?? ?? ?? 48 2B C1 48 85 C9 48 0F 44 C6 BA ?? ?? ?? ?? 48 2B D0 + 48 8D 8D ?? ?? ?? ?? 48 8D 0C 41 74 ?? 48 05 ?? ?? ?? ?? 48 03 C2 4C 8D 0D ?? ?? ?? + ?? 4C 2B C9 0F 1F 44 00 ?? 48 85 C0 74 ?? 45 0F B7 04 09 66 45 85 C0 74 ?? 66 44 89 + 01 48 83 C1 ?? 48 FF C8 48 83 EA ?? 75 ?? 48 8D 41 ?? 48 85 D2 48 0F 45 C1 66 89 30 + 48 8D 95 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 48 0F 43 95 ?? ?? ?? ?? 48 8D 44 24 ?? + 48 89 44 24 ?? 41 B8 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 4C 8B 44 24 ?? BA ?? + ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 44 24 ?? 48 8B 4C 24 ?? 48 3B + C8 74 ?? FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 66 39 30 74 ?? 48 83 + C0 ?? 48 83 E9 ?? 75 ?? 48 85 C9 74 ?? B8 ?? ?? ?? ?? 48 2B C1 48 85 C9 48 0F 44 C6 + BA ?? ?? ?? ?? 48 2B D0 48 8D 8D ?? ?? ?? ?? 48 8D 0C 41 74 ?? 48 05 ?? ?? ?? ?? 48 + 03 C2 4C 8D 0D ?? ?? ?? ?? 4C 2B C9 48 85 C0 74 ?? 45 0F B7 04 09 66 45 85 C0 74 ?? + 66 44 89 01 48 83 C1 ?? 48 FF C8 48 83 EA ?? 75 ?? 48 8D 41 ?? 48 85 D2 48 0F 45 C1 + 66 89 30 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 4C 8B E0 48 89 + 44 24 ?? 48 83 F8 ?? 75 ?? 48 8B 95 ?? ?? ?? ?? 48 83 FA ?? 72 ?? 48 FF C2 48 8B 8D + ?? ?? ?? ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 + 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 + } + $encrypt_files_p1 = { + B9 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 90 66 83 38 ?? 74 ?? 48 83 C0 ?? 48 83 E9 ?? 75 + ?? 48 85 C9 74 ?? 41 B8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 4C 2B C1 BA ?? ?? ?? ?? 48 + 85 C9 4C 0F 44 C3 4A 8D 04 40 49 2B D0 74 ?? 49 8D 88 ?? ?? ?? ?? 48 03 CA 4C 8D 0D + ?? ?? ?? ?? 4C 2B C8 66 90 48 85 C9 74 ?? 45 0F B7 04 01 66 45 85 C0 74 ?? 66 44 89 + 00 48 FF C9 48 83 C0 ?? 48 83 EA ?? 75 ?? 48 85 D2 48 8D 48 ?? 48 0F 45 C8 66 89 19 + 48 89 5C 24 ?? 45 33 C9 C7 44 24 ?? ?? ?? ?? ?? 44 8B C7 8B D7 C7 44 24 ?? ?? ?? ?? + ?? 49 8B CC FF 15 ?? ?? ?? ?? 45 33 C9 48 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D + 8D ?? ?? ?? ?? 44 8B C7 C7 44 24 ?? ?? ?? ?? ?? 48 8B F0 41 8D 51 ?? FF 15 ?? ?? ?? + ?? 41 B9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 33 D2 48 8D 0D ?? + ?? ?? ?? 4C 8B F0 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 75 ?? 41 B9 ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 33 D2 48 8D 0D ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 45 33 C9 48 89 44 24 ?? 45 + } + $encrypt_files_p2 = { + 33 C0 BA ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B + 15 ?? ?? ?? ?? 45 33 C9 48 8B 8D ?? ?? ?? ?? 44 8B C0 FF 15 ?? ?? ?? ?? 4C 8B 85 ?? + ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 44 8B CF BA ?? ?? ?? ?? 48 89 44 + 24 ?? FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 32 DB 41 BD ?? ?? ?? ?? 48 + 8B F8 66 66 66 0F 1F 84 00 ?? ?? 00 00 4C 8D 8D ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? + ?? 41 B8 ?? ?? ?? ?? 48 8B D7 48 8B CE FF 15 ?? ?? ?? ?? 81 BD ?? ?? ?? ?? ?? ?? ?? + ?? 48 8D 85 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 89 44 24 ?? + 0F B6 DB 41 0F 42 DD 48 89 7C 24 ?? 44 0F B6 C3 45 33 C9 33 D2 FF 15 ?? ?? ?? ?? 44 + 8B 85 ?? ?? ?? ?? 4C 8D 8D ?? ?? ?? ?? 48 8B D7 48 C7 44 24 ?? ?? ?? ?? ?? 49 8B CE + FF 15 ?? ?? ?? ?? 84 DB 0F 84 ?? ?? ?? ?? 4C 8B 6C 24 ?? 48 85 F6 74 ?? 48 8B CE FF + 15 ?? ?? ?? ?? 4D 85 F6 + } + $drop_ransom_note = { + 48 85 C9 74 ?? B8 ?? ?? ?? ?? 48 2B C1 48 85 C9 49 0F 44 C6 BA ?? ?? ?? ?? 48 2B D0 + 48 8D 8D ?? ?? ?? ?? 48 8D 0C 41 74 ?? 48 05 ?? ?? ?? ?? 48 03 C2 4C 8D 0D ?? ?? ?? + ?? 4C 2B C9 66 90 48 85 C0 74 ?? 46 0F B7 04 09 66 45 85 C0 74 ?? 66 44 89 01 48 83 + C1 ?? 48 FF C8 48 83 EA ?? 75 ?? 48 8D 41 ?? 48 85 D2 48 0F 45 C1 66 44 89 30 4C 89 + 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 45 33 C9 45 33 C0 BA ?? ?? + ?? ?? 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 49 C7 C0 ?? ?? ?? ?? 49 FF C0 + 46 38 34 06 75 ?? 4C 89 74 24 ?? 4C 8D 8D ?? ?? ?? ?? 48 8B D6 48 8B CB FF 15 ?? ?? + ?? ?? 48 85 DB 74 ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CE E8 ?? ?? ?? ?? 90 48 8B 95 + ?? ?? ?? ?? 48 83 FA ?? 72 ?? 48 FF C2 48 8B 4D ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 + ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 33 F6 48 89 B5 ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 40 88 75 ?? 48 + 8B 95 ?? ?? ?? ?? 48 83 FA ?? 0F 82 ?? ?? ?? ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 8D ?? + ?? ?? ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 48 83 C2 ?? 48 8B 49 ?? 48 + 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 86 ?? ?? ?? ?? FF 15 + } + $enum_drives = { + 48 89 5D ?? 48 C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? FF 15 ?? ?? ?? ?? 8B F8 0F A3 DF 0F + 83 ?? ?? ?? ?? 8D 4B ?? 48 C7 45 ?? ?? ?? ?? ?? 88 4D ?? 48 C7 45 ?? ?? ?? ?? ?? 66 + C7 45 ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 3B 05 ?? ?? ?? ?? 74 ?? 48 8D 55 ?? 48 8B C8 + E8 ?? ?? ?? ?? 48 83 05 ?? ?? ?? ?? ?? EB ?? 4C 8D 45 ?? 48 8B D0 48 8D 0D ?? ?? ?? + ?? E8 ?? ?? ?? ?? 90 48 8B 45 ?? 48 83 F8 ?? 72 ?? 48 8D 50 ?? 48 8B 4D ?? 48 8B C1 + 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? + 77 ?? E8 ?? ?? ?? ?? FF C3 83 FB ?? 0F 8C ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? + E8 ?? ?? ?? ?? 90 33 C0 48 8B 4D ?? 48 33 CC E8 ?? ?? ?? ?? 4C 8D 5C 24 ?? 49 8B 5B + ?? 49 8B 7B ?? 49 8B E3 5D C3 FF 15 + } + + condition: + uint16(0)==0x5A4D and ($enum_drives) and ($find_files) and ( all of ($encrypt_files_p*)) and ($drop_ransom_note) +} +rule REVERSINGLABS_Win32_Ransomware_Dharma : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Dharma ransomware." + author = "ReversingLabs" + id = "8157b20b-717c-581f-83c1-5fc8d2312238" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Dharma.yara#L1-L108" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "6f33281523b462aaff68bb04f2f6869c3e6cd60cd9306ed80bb0c3e3b699f315" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Dharma" + tc_detection_factor = 5 + importance = 25 + + strings: + $file_search = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? + 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8D 4D ?? 51 8B 55 + ?? 52 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? + 75 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? 81 7D ?? ?? ?? ?? ?? 76 ?? 8B + 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B + 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D + ?? ?? 75 ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 + 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? + 89 45 ?? 8B 45 ?? 8B E5 5D C3 + } + $file_encrypt_1 = { + 55 8B EC 81 EC ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? 8B 45 ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 C1 ?? 89 4D ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 8B 55 ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 8B 45 ?? 33 D2 B9 ?? ?? ?? ?? F7 F1 8B 45 ?? 2B C2 83 E8 ?? 89 45 ?? 8B + 4D ?? 51 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? + ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 05 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 83 ?? ?? + ?? ?? 8B 4D ?? 83 E1 ?? 74 ?? 8B 55 ?? 83 E2 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 6A ?? + 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? + ?? 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 89 55 ?? 8B 45 ?? 89 85 ?? ?? ?? + ?? 8B 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8B 85 ?? ?? ?? ?? 50 8B 8D + ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? + 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 + ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 8B 4D ?? 51 + E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? + ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 8B 45 ?? 50 8B 4D + ?? 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B + 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 83 7D + ?? ?? 75 ?? 8B 4D ?? 3B 4D ?? 73 ?? 8B 45 ?? 33 D2 B9 ?? ?? ?? ?? F7 F1 B8 ?? ?? ?? + ?? 2B C2 89 45 ?? 8B 4D ?? 03 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8D 8D ?? ?? ?? ?? 51 + E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 95 ?? ?? ?? ?? 52 8B 45 ?? 03 45 ?? 50 8B 4D ?? 51 + } + $file_encrypt_2 = { + 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 03 45 ?? 39 85 ?? ?? ?? ?? + 74 ?? E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? + 83 C4 ?? 8B 95 ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? + ?? 83 7D ?? ?? 74 ?? 8B 8D ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 8B 55 ?? 52 8B 45 ?? 50 + 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 03 55 ?? 89 55 ?? 8B 45 ?? 03 45 ?? 89 + 45 ?? 6A ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 83 C0 ?? 89 45 + ?? 6A ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 83 C0 ?? 89 45 ?? + 6A ?? 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 83 C0 ?? 89 + 45 ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 83 C0 ?? 89 45 + ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 05 ?? ?? + ?? ?? 89 45 ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 83 C0 + ?? 89 45 ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 2B 55 ?? 52 8B 45 ?? 50 8B 8D ?? ?? + ?? ?? 51 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 55 ?? 2B 55 ?? 39 95 ?? ?? ?? ?? 74 ?? EB ?? + EB ?? 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? E9 ?? + ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7E ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 8D ?? ?? + ?? ?? 51 8B 95 ?? ?? ?? ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? + 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 7E ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? + ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 8B E5 5D C3 + } + $enum_shares = { + 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 8D 45 ?? + 50 8B 4D ?? 51 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 50 8D 4D ?? 51 8B 55 ?? 52 E8 ?? + ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 83 C0 ?? 89 45 + ?? 8B 4D ?? 3B 4D ?? 0F 83 ?? ?? ?? ?? 8B 55 ?? C1 E2 ?? 8B 45 ?? 83 7C 10 ?? ?? 75 + ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 50 8B 55 ?? 52 8B 45 ?? C1 E0 ?? 8B 4D ?? 8B 54 01 ?? + 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 6A ?? 8B 45 ?? 50 8B 4D ?? C1 E1 ?? 8B 55 ?? + 8B 44 0A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8B 4D ?? 51 8B 55 ?? C1 E2 ?? 8B 45 ?? + 8B 4C 10 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C1 E2 ?? 8B 45 ?? 8B 4C 10 ?? 83 E1 + ?? 74 ?? 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? C1 E1 ?? 03 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 + ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 55 ?? + 52 E8 ?? ?? ?? ?? 8D 45 ?? 50 8B 4D ?? 51 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 0F + 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 50 8D + 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB + ?? 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 3B 4D ?? 0F 83 ?? ?? ?? ?? 8B 55 ?? C1 E2 ?? + 8B 45 ?? 83 7C 10 ?? ?? 75 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 50 8B 55 ?? 52 8B 45 ?? C1 + E0 ?? 8B 4D ?? 8B 54 01 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 6A ?? 8B 45 ?? 50 + 8B 4D ?? C1 E1 ?? 8B 55 ?? 8B 44 0A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8B 4D ?? 51 + 8B 55 ?? C1 E2 ?? 8B 45 ?? 8B 4C 10 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C1 E2 ?? + 8B 45 ?? 8B 4C 10 ?? 83 E1 ?? 74 ?? 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? C1 E1 ?? 03 4D + ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? E9 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and $file_search and $enum_shares and $file_encrypt_1 and $file_encrypt_2 +} +rule REVERSINGLABS_Win32_Ransomware_Kawaiilocker : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects KawaiiLocker ransomware." + author = "ReversingLabs" + id = "8c368e2d-3c6f-5c4b-880b-ebdb06dcf901" + date = "2020-08-17" + modified = "2020-08-17" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.KawaiiLocker.yara#L1-L135" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "d86b41ef1c43da55869ad26facd5efdf232277f0e33483690a69a04c4ba8f7da" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "KawaiiLocker" + tc_detection_factor = 5 + importance = 25 + + strings: + $search_files = { + 55 8B EC 51 B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 ?? 51 87 4D ?? 53 56 57 88 4D ?? 89 55 + ?? 89 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8B 45 ?? E8 ?? + ?? ?? ?? 8B 55 ?? 80 7C 02 ?? ?? 75 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B D0 4A 8D 45 ?? E8 + ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F + 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B D0 83 CA ?? 3B D0 75 ?? 80 7D ?? ?? 0F 85 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8A 4D + ?? 8B 55 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? BE ?? ?? ?? ?? BB ?? ?? ?? ?? FF 75 ?? 68 + ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 13 E8 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? FF 75 ?? 68 ?? + ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D + 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 75 ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? + FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 95 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 08 FF 51 ?? 83 C3 ?? 4E 0F 85 ?? ?? ?? ?? + E9 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8B C7 83 C8 ?? 3B C7 75 ?? 80 7D ?? ?? 0F 85 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8A 4D + ?? 8B 55 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? BE ?? ?? ?? ?? BB ?? ?? ?? ?? FF 75 ?? 68 + ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 13 E8 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? FF 75 ?? 68 ?? + ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D + 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 75 ?? FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? + FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 95 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 08 FF 51 ?? 83 C3 ?? 4E 0F 85 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? C3 + } + $remote_connection = { + 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? B2 + ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 45 ?? 50 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 59 E8 ?? ?? ?? ?? + 8D 4D ?? BA ?? ?? ?? ?? 33 C0 E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? E8 ?? ?? ?? ?? FF 75 + ?? 8D 4D ?? BA ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? FF 75 ?? 8D 45 ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 + ?? 8B 50 ?? 8B 45 ?? 8B 08 FF 51 ?? 8D 55 ?? 8B 45 ?? 8B 08 FF 51 ?? 8B 45 ?? 8D 55 + ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? E8 ?? ?? + ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B C3 8B 55 ?? E8 ?? ?? ?? ?? + 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + } + $encrypt_files = { + 55 8B EC 6A ?? 6A ?? 6A ?? 53 56 57 BB ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 + 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 + ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 10 FF 52 + ?? 8B F0 8B C3 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 + ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 43 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B DE 4B 85 DB 7C ?? 43 33 F6 8D 55 ?? 33 C0 E8 ?? ?? ?? ?? 8B 45 + ?? 8D 55 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? + ?? ?? 8B 08 FF 51 ?? 8D 4D ?? 8B D6 A1 ?? ?? ?? ?? 8B 38 FF 57 ?? 8B 45 ?? B1 ?? BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 46 4B 75 ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 6A ?? E8 ?? ?? ?? ?? 6A ?? E8 + } + + condition: + uint16(0)==0x5A4D and $search_files and $encrypt_files and $remote_connection +} +rule REVERSINGLABS_Win32_Ransomware_Cryptobit : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects CryptoBit ransomware." + author = "ReversingLabs" + id = "8566e516-9884-5b20-90c4-7ed38fa96999" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.CryptoBit.yara#L1-L113" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ccc8a0f1c5e11211649992d0f2b309968c97b49f1c7359e62d622f364e117429" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "CryptoBit" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 55 8B EC 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 + 7D ?? ?? 75 ?? FF 75 ?? EB ?? 6A ?? 59 83 C9 ?? 83 F1 ?? 89 4D ?? 6A ?? 6A ?? 6A ?? + 6A ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 0B C0 0F 84 ?? ?? ?? ?? 89 45 ?? 60 BE ?? ?? ?? + ?? 56 64 FF 35 ?? ?? ?? ?? 64 89 25 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 33 D2 + 8B 0D ?? ?? ?? ?? F7 F1 0B C0 74 ?? FF 35 ?? ?? ?? ?? EB ?? 52 8B 0C 24 29 4D ?? 51 + FF 75 ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 59 0B C0 74 ?? 89 45 ?? 51 FF + 75 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? 83 7D ?? ?? 75 ?? 89 45 ?? 89 4D ?? FF 75 ?? + E8 ?? ?? ?? ?? EB ?? EB ?? 83 7D ?? ?? 75 ?? C7 45 ?? ?? ?? ?? ?? EB ?? A1 ?? ?? ?? + ?? 01 45 ?? EB ?? EB ?? 8B 64 24 ?? 64 8F 05 ?? ?? ?? ?? 83 C4 ?? 61 EB ?? EB ?? 64 + 8F 05 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 8B 4D + ?? EB ?? 8B 45 ?? C9 C2 + } + $encrypt_files_p2 = { + 55 8B EC 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A + ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? + ?? ?? ?? 89 45 ?? 8D 45 ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? + 0B C0 74 ?? E9 ?? ?? ?? ?? 89 45 ?? 8B 15 ?? ?? ?? ?? 8B 4D ?? 0B C9 75 ?? 83 F8 ?? + 73 ?? E9 ?? ?? ?? ?? EB ?? 0B C9 75 ?? 3B C2 73 ?? 50 EB ?? 52 8F 45 ?? 83 7D ?? ?? + 75 ?? A1 ?? ?? ?? ?? 39 45 ?? 72 ?? FF 75 ?? FF 75 ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? + ?? 89 45 ?? 0B C0 74 ?? 6A ?? 50 51 FF 75 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A + ?? 6A ?? 6A ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 0B C0 74 ?? 89 45 ?? 60 BE ?? ?? ?? ?? + 56 64 FF 35 ?? ?? ?? ?? 64 89 25 ?? ?? ?? ?? FF 75 ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF + 75 ?? E8 ?? ?? ?? ?? 0B C0 74 ?? 50 8B 4D ?? 8B 04 24 83 C9 ?? 83 F1 ?? 51 50 E8 ?? + ?? ?? ?? 89 45 ?? 0B C0 74 ?? 6A ?? 50 51 FF 75 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB + ?? 8B 64 24 ?? 64 8F 05 ?? ?? ?? ?? 83 C4 ?? 61 EB ?? EB ?? 64 8F 05 ?? ?? ?? ?? 83 + C4 ?? 83 7D ?? ?? 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? E8 ?? ?? + ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 8B 4D ?? EB ?? 33 C0 33 C9 C9 C2 + } + $find_files_p1 = { + 55 8B EC 83 C4 ?? 57 56 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 8B 75 ?? 83 7E ?? ?? 75 ?? E8 ?? ?? ?? ?? 50 8D 46 ?? 50 E8 + ?? ?? ?? ?? 23 C0 0F 84 ?? ?? ?? ?? EB ?? 83 7E ?? ?? 75 ?? FF 35 ?? ?? ?? ?? 8D 46 + ?? 50 E8 ?? ?? ?? ?? 23 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 23 C0 0F + 84 ?? ?? ?? ?? 89 45 ?? B9 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 23 C0 0F 84 ?? + ?? ?? ?? 89 45 ?? 8B 75 ?? 8B 7D ?? 68 ?? ?? ?? ?? 57 56 E8 ?? ?? ?? ?? 8D 57 ?? 8B + 47 ?? D1 E0 C7 04 10 ?? ?? ?? ?? C6 44 10 ?? ?? FF 75 ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? + 83 F8 ?? 0F 84 ?? ?? ?? ?? 89 45 ?? 8B 55 ?? 8B 75 ?? 8B 7D ?? 8B 02 25 ?? ?? ?? ?? + 0F 85 ?? ?? ?? ?? 8B 02 83 E0 ?? 0F 85 ?? ?? ?? ?? 8B 02 83 E0 ?? F7 02 ?? ?? ?? ?? + 0F 85 ?? ?? ?? ?? 8D 47 ?? 50 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 8D 42 ?? 50 8D 47 + ?? 50 E8 ?? ?? ?? ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 89 47 ?? F7 02 ?? ?? ?? ?? + 74 ?? 68 ?? ?? ?? ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? FF 77 ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? + 83 F8 ?? 74 ?? 83 F8 ?? 75 ?? 48 50 FF 76 ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? 0B C0 75 + } + $find_files_p2 = { + 0B C9 74 ?? FF 45 ?? E9 ?? ?? ?? ?? 83 7A ?? ?? 0F 84 ?? ?? ?? ?? 81 7A ?? ?? ?? ?? + ?? 0F 84 ?? ?? ?? ?? F7 02 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? F7 02 ?? ?? ?? ?? 0F 85 ?? + ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 74 ?? 8B F8 FF 76 ?? 8F 47 ?? FF 76 ?? + 8F 47 ?? FF 36 8F 07 8D 47 ?? 50 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 8D 42 ?? 50 8D + 47 ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? 8D 47 ?? 50 E8 ?? + ?? ?? ?? 89 47 ?? 83 3F ?? 75 ?? 57 68 ?? ?? ?? ?? FF 76 ?? E8 ?? ?? ?? ?? 0B C0 75 + ?? 57 E8 ?? ?? ?? ?? EB ?? 57 E8 ?? ?? ?? ?? EB ?? E9 ?? ?? ?? ?? FF 75 ?? FF 75 ?? + E8 ?? ?? ?? ?? 0B C0 0F 85 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + 8B 75 ?? 83 7D ?? ?? 74 ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B + 14 24 51 50 52 8D 46 ?? 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 D1 E1 8B 5C 24 ?? 51 50 53 8D 46 + ?? 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? E8 ?? + ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? E8 ?? + ?? ?? ?? 8B 45 ?? 5E 5F C9 C2 + } + $remote_connection = { + 55 8B EC 81 C4 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? 6A ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? + 6A ?? E8 ?? ?? ?? ?? 23 C0 89 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A + ?? 6A ?? 6A ?? FF 75 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 89 85 ?? ?? ?? ?? 0F + 84 ?? ?? ?? ?? 8D 5D ?? C7 03 ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? + ?? ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 45 ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? FF B5 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 23 C0 74 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 23 C0 89 85 ?? ?? ?? ?? 74 ?? + 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? + ?? FF B5 ?? ?? ?? ?? 0B C0 74 ?? 83 BD ?? ?? ?? ?? ?? 74 ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? + FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? C9 C2 + } + + condition: + uint16(0)==0x5A4D and ($remote_connection and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*))) +} +rule REVERSINGLABS_Win32_Ransomware_IFN643 : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects IFN643 ransomware." + author = "ReversingLabs" + id = "a4d211a7-6735-541e-885d-555bbc11e2cf" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.IFN643.yara#L1-L90" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "ced234018f1f05601dd3be55eaecd2a1e116ad0b7bb9e0292434f11f19916ebe" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "IFN643" + tc_detection_factor = 5 + importance = 25 + + strings: + $search_files_1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 89 B5 ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8B D6 C7 45 ?? ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 + ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? + 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 8D 8D ?? + ?? ?? ?? 8D 45 ?? 0F 43 45 ?? 51 50 FF 15 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB + ?? 0F 84 + } + $search_files_2 = { + 80 BD ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 75 ?? 33 + C0 EB ?? 8D 85 ?? ?? ?? ?? 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 50 8D 85 ?? ?? ?? ?? + 50 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D6 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B D0 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 + ?? 8B C8 C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B 0D ?? ?? ?? ?? F7 + E9 C1 FA ?? 8B C2 C1 E8 ?? 03 C2 83 F8 ?? 0F 83 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 85 C0 0F 8E ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D6 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 4D ?? C6 45 ?? ?? 51 8B D0 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8B 85 ?? + ?? ?? ?? 83 F8 ?? 72 ?? 8B 8D ?? ?? ?? ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? + ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? + 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? + 8B 35 ?? ?? ?? ?? 33 DB 2B CE C7 85 ?? ?? ?? ?? ?? ?? ?? ?? F7 E9 C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? C1 FA ?? 8B C2 C6 85 ?? ?? ?? ?? ?? C1 E8 ?? 03 C2 74 ?? 33 FF ?? ?? ?? + 8D 45 ?? 8D 0C 37 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 83 7D ?? ?? 89 45 ?? 8D 45 ?? 0F 43 + 45 ?? C6 00 ?? 8B 35 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B CE 43 F7 E9 83 + C7 ?? C1 FA ?? 8B C2 C1 E8 ?? 03 C2 3B D8 72 ?? 83 7D ?? ?? 76 ?? 8D 45 ?? B9 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B 0D ?? ?? ?? ?? F7 E9 C1 + FA ?? 8B C2 C1 E8 ?? 03 C2 83 F8 ?? 0F 83 ?? ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? + 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F + 83 ?? ?? ?? ?? 2B C8 83 F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 + E8 ?? ?? ?? ?? 83 C4 ?? 8B 9D ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? + ?? ?? ?? 72 ?? F6 C1 ?? 0F 85 ?? ?? ?? ?? 8B 41 ?? 3B C1 0F 83 ?? ?? ?? ?? 2B C8 83 + F9 ?? 0F 82 ?? ?? ?? ?? 83 F9 ?? 0F 87 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? + 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B + 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? + 8B 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 + ?? E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? C6 45 ?? ?? 8B 45 ?? 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 + ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 + ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? + 83 F8 ?? 72 ?? 8B 4D ?? 40 3D ?? ?? ?? ?? 72 ?? F6 C1 ?? 74 ?? E8 ?? ?? ?? ?? 8B 41 + ?? 3B C1 72 ?? E8 ?? ?? ?? ?? 2B C8 83 F9 ?? 73 ?? E8 ?? ?? ?? ?? 83 F9 ?? 76 ?? E8 + ?? ?? ?? ?? 8B C8 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E + 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $encrypt_files = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? + 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 65 ?? 8B C2 89 45 ?? 8B F9 8B 75 ?? 89 75 ?? + C7 45 ?? ?? ?? ?? ?? 90 3B F8 0F 84 ?? ?? ?? ?? 89 75 ?? C6 45 ?? ?? 85 F6 74 ?? 8B + 17 C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? 83 7E ?? ?? C7 46 + ?? ?? ?? ?? ?? 72 ?? 8B 06 EB ?? 8B C6 C6 00 ?? 80 3A ?? 75 ?? 33 C0 EB ?? 8B C2 8D + 58 ?? 66 90 8A 08 40 84 C9 75 ?? 2B C3 50 52 8B CE E8 ?? ?? ?? ?? 8B 45 ?? 83 C6 ?? + C6 45 ?? ?? 89 75 ?? 83 C7 ?? EB ?? 8B 55 ?? 51 8B 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A + ?? 6A ?? E8 ?? ?? ?? ?? 8B C6 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C3 + 2B 49 ?? E9 ?? ?? ?? ?? 2B 49 ?? E9 ?? ?? ?? ?? 2B 49 ?? E9 ?? ?? ?? ?? 2B 49 ?? E9 + ?? ?? ?? ?? 33 C0 57 8B F9 40 F0 0F C1 05 ?? ?? ?? ?? 75 ?? 56 BE ?? ?? ?? ?? 56 E8 + ?? ?? ?? ?? 83 C6 ?? 59 81 FE ?? ?? ?? ?? 7C ?? 5E 8B C7 5F C3 + } + + condition: + uint16(0)==0x5A4D and $search_files_1 and $search_files_2 and $encrypt_files +} +rule REVERSINGLABS_Win32_Ransomware_Armage : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Armage ransomware." + author = "ReversingLabs" + id = "94cf639b-7d9e-51ca-b547-e0d591581df2" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Armage.yara#L1-L128" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "aa8ddcbb0fdcad15e603e000db1d4f86eae7d42efce1c1d21dc3dd57ee9f4319" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Armage" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 55 89 E5 53 8D 5D ?? 81 EC ?? ?? ?? ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 89 5D ?? 8D 5D + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 65 ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 45 + ?? 8D 50 ?? 8D 48 ?? C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C6 40 ?? ?? 89 50 ?? 89 + 95 ?? ?? ?? ?? 8D 50 ?? 89 50 ?? 89 95 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 5D ?? 83 EC ?? 89 5D ?? + 8B 41 ?? 8B 51 ?? 8D 4D ?? 01 C2 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 45 ?? 8D 5D ?? 83 EC ?? 89 5C 24 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 45 ?? 8D 5D ?? 39 D8 74 ?? 89 04 24 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? 89 42 ?? 8B 55 ?? 89 4C 24 ?? 89 04 24 29 CA 89 54 24 + ?? E8 ?? ?? ?? ?? 8B 55 ?? 89 42 ?? 8B 42 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 55 ?? 89 42 + ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 55 ?? + 8B 42 ?? 89 04 24 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 8D ?? + ?? ?? ?? 89 4C 24 ?? 89 85 ?? ?? ?? ?? 89 44 24 ?? 8B 55 ?? 8B 42 ?? 89 04 24 E8 ?? + ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 4C 24 ?? 89 8D ?? ?? ?? ?? 89 4C 24 ?? 8B 85 ?? ?? ?? + ?? 89 44 24 ?? 8B 55 ?? 8B 42 ?? 89 04 24 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 44 24 + ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 89 5C 24 ?? 8B 8D ?? + ?? ?? ?? 89 4C 24 ?? 89 85 ?? ?? ?? ?? 89 44 24 ?? 8B 55 ?? 8B 42 ?? 89 04 24 E8 ?? + ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? 8D 45 ?? 89 04 24 E8 + } + $encrypt_files_p2 = { + 8B 55 ?? 8D 45 ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? 8D 4A ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D + 55 ?? 83 EC ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? + ?? 8B 40 ?? 8B 80 ?? ?? ?? ?? 85 C0 89 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 80 78 ?? ?? 74 ?? 0F BE 40 ?? 89 04 24 B9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 EC ?? 89 C1 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? + 8B 45 ?? 85 C0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 5D + ?? C9 C3 90 8B 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 8B 00 8B 50 ?? B8 ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 74 ?? C7 04 24 ?? ?? ?? ?? 8B 8D ?? + ?? ?? ?? FF D2 83 EC ?? 0F BE C0 E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C5 ?? 8B 45 ?? 89 + 85 ?? ?? ?? ?? 8B 45 ?? 85 C0 74 ?? 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 83 + E8 ?? 74 ?? 0F 0B 8B 45 ?? 8D 55 ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 + C0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? 3B 85 ?? ?? ?? ?? 74 ?? 89 04 24 + E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? 39 85 ?? ?? ?? ?? 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 39 D0 + 75 ?? EB + } + $find_files_p1 = { + 55 89 E5 81 EC ?? ?? ?? ?? 8D 55 ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 89 55 ?? 8D 55 ?? 89 65 ?? 89 14 24 E8 ?? ?? ?? ?? 8B 45 ?? + 8B 4D ?? 83 C0 ?? 8B 51 ?? 89 45 ?? 8D 45 ?? 89 45 ?? 8B 45 ?? 89 55 ?? 8B 00 89 C1 + 89 45 ?? 01 D1 74 ?? 85 C0 75 ?? C7 04 24 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 45 ?? 83 F8 ?? 89 45 ?? 0F 87 ?? ?? ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 8B + 45 ?? 8D 55 ?? 0F B6 00 88 45 ?? B8 ?? ?? ?? ?? 89 45 ?? C6 04 02 ?? B8 ?? ?? ?? ?? + 2B 45 ?? 83 F8 ?? 0F 86 ?? ?? ?? ?? 8D 4D ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 83 EC ?? 89 44 24 ?? 8B 45 ?? 89 + 04 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 83 EC ?? 89 81 ?? ?? ?? + ?? 8D 4D ?? 39 CA 74 ?? 89 14 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 80 ?? ?? ?? ?? 83 F8 + } + $find_files_p2 = { + 8B 45 ?? 0F 95 00 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? C9 C2 ?? ?? 8D 76 ?? 8D 45 ?? 8B + 4D ?? 89 4C 24 ?? 8B 4D ?? 89 04 24 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? E9 + ?? ?? ?? ?? 8D 45 ?? 8D 4D ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 C7 45 ?? ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8B 55 ?? 83 EC ?? 89 45 ?? 89 55 ?? EB ?? C7 04 24 ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C5 ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 85 C0 74 ?? 83 E8 + ?? 74 ?? 0F 0B 8B 45 ?? 8D 55 ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 + 24 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 66 90 55 89 E5 57 56 8D 45 ?? 53 83 EC ?? + 89 45 ?? 8D 45 ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? 89 65 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 5D ?? C6 45 ?? ?? 8B 83 ?? ?? ?? + ?? 83 F8 ?? 74 ?? 8D 53 ?? 89 04 24 89 54 24 ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 EC ?? 85 C0 0F 95 45 ?? 0F B6 45 ?? 8B 75 ?? 88 06 8B 45 ?? 89 04 24 E8 ?? ?? ?? + ?? 0F B6 45 ?? 8D 65 ?? 5B 5E 5F 5D C3 + } + $enum_resources_p1 = { + 55 B8 ?? ?? ?? ?? 89 E5 E8 ?? ?? ?? ?? 29 C4 8D 45 ?? 89 8D ?? ?? ?? ?? 89 A5 ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 44 24 ?? 8B 45 + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? C7 85 ?? ?? ?? ?? + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C9 C2 ?? ?? + 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 44 + 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 85 C0 75 ?? 8D 85 ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 85 C0 75 ?? EB + ?? 8D B4 26 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? F6 40 ?? ?? 0F 85 ?? ?? ?? ?? 83 85 ?? ?? + ?? ?? ?? 83 85 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B 85 ?? ?? ?? ?? 0F 83 + } + $enum_resources_p2 = { + 8B 85 ?? ?? ?? ?? F6 40 ?? ?? 74 ?? 8B 40 ?? 89 C2 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 85 D2 89 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? 74 ?? 89 14 24 E8 ?? ?? ?? ?? 03 85 ?? ?? + ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 04 24 C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 8B 48 ?? 3B 48 ?? 0F 84 ?? ?? ?? + ?? 85 C9 74 ?? 8D 41 ?? 8B 95 ?? ?? ?? ?? 89 01 8B 85 ?? ?? ?? ?? 01 C2 89 04 24 89 + 54 24 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 8B + 48 ?? 8B 85 ?? ?? ?? ?? 83 C1 ?? 89 48 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 39 C8 + 0F 84 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? F6 40 ?? ?? 0F 84 ?? ?? + ?? ?? 89 04 24 8B 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC + ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 0C 24 89 44 24 ?? 8B 8D ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? EB + } + + condition: + uint16(0)==0x5A4D and ( all of ($enum_resources_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) +} +import "pe" + +rule REVERSINGLABS_Win32_Ransomware_Wannacry : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects WannaCry ransomware." + author = "ReversingLabs" + id = "61734d47-2525-5e3a-94b4-60493dfe2b93" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.WannaCry.yara#L3-L135" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "fed58b533a9f7c3eb1b3e4f8fbe1f519aab94d1c066ae6937c21876693be0eac" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "WannaCry" + tc_detection_factor = 5 + importance = 25 + + strings: + $main_1 = { + A0 ?? ?? ?? ?? 56 57 6A ?? 88 85 ?? ?? ?? ?? 59 33 C0 8D BD ?? ?? ?? ?? F3 AB 66 AB + AA 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 6A ?? 50 FF D6 59 85 C0 59 74 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF D6 59 88 + 18 59 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 59 + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 53 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5F 5E 85 + C0 74 ?? 8D 45 ?? 8D 8D ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 89 5D + } + $main_2 = { + 68 ?? ?? ?? ?? 33 DB 50 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 FF 15 + ?? ?? ?? ?? 83 38 ?? 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 00 FF 70 ?? E8 ?? ?? + ?? ?? 59 85 C0 59 75 ?? 53 E8 ?? ?? ?? ?? 85 C0 59 74 ?? BE ?? ?? ?? ?? 53 8D 85 ?? + ?? ?? ?? 56 50 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? E8 ?? ?? ?? ?? + 85 C0 0F 85 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF D6 59 85 C0 + 59 74 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF D6 59 88 18 59 8D 85 ?? ?? ?? ?? 50 FF 15 ?? + ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 53 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 53 53 68 ?? ?? ?? ?? E8 + } + $main_3 = { + 83 EC ?? 56 57 B9 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 7C 24 ?? 33 C0 F3 A5 A4 89 44 24 ?? + 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 89 44 24 ?? 66 89 44 24 ?? 50 50 50 6A ?? 50 88 + 44 24 ?? FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8D 4C 24 ?? 8B F0 6A ?? 51 56 + FF 15 ?? ?? ?? ?? 8B F8 56 8B 35 ?? ?? ?? ?? 85 FF 75 ?? FF D6 6A ?? FF D6 E8 + } + $start_service_3 = { + 83 EC ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 + 38 ?? 7D ?? E8 ?? ?? ?? ?? 83 C4 ?? C3 57 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? + ?? 8B F8 85 FF 74 ?? 53 56 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B 1D + ?? ?? ?? ?? 8B F0 85 F6 74 ?? 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 56 FF D3 57 FF D3 5E + 5B 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 5F 83 C4 ?? C3 + } + $main_4 = { + 83 EC ?? 57 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 85 FF 74 ?? 53 56 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 8B F0 85 F6 74 ?? + 6A ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 56 FF D3 57 FF D3 5E 5B 8D 44 24 ?? C7 44 24 ?? ?? + ?? ?? ?? 50 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 33 C0 5F 83 C4 ?? C2 + } + $main_5 = { + 68 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 + FF D6 59 85 C0 59 74 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF D6 59 88 18 59 8D 85 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 53 53 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5F 5E 85 C0 74 ?? 8D 45 ?? 8D + 8D ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 89 5D ?? E8 ?? ?? ?? ?? 3B C3 74 ?? FF 75 ?? 50 E8 + ?? ?? ?? ?? 59 3B C3 59 74 ?? 68 ?? ?? ?? ?? 50 E8 + } + $main_6 = { + FF 74 24 ?? FF 74 24 ?? FF 74 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? C2 + } + $set_reg_key_6 = { + 68 ?? ?? ?? ?? F3 AB 66 AB AA 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 50 FF 15 ?? ?? ?? + ?? 8B 2D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 83 C4 ?? 33 FF 89 7C 24 ?? 85 FF 75 ?? 8D 4C + 24 ?? 8D 54 24 ?? 51 52 68 ?? ?? ?? ?? EB ?? 8D 44 24 ?? 8D 4C 24 ?? 50 51 68 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 85 + C9 74 ?? 8D 94 24 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? FF D5 8D BC 24 ?? ?? ?? ?? 83 C9 ?? + 33 C0 F2 AE F7 D1 8D 84 24 ?? ?? ?? ?? 51 8B 4C 24 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? + 51 FF D3 8B 7C 24 ?? 8B F0 F7 DE 1B F6 46 EB ?? 8D 54 24 ?? 8D 8C 24 ?? ?? ?? ?? 52 + 51 6A ?? 6A ?? 68 ?? ?? ?? ?? 50 C7 44 24 ?? ?? ?? ?? ?? FF 15 + } + $download_tor_6 = { + 81 EC ?? ?? ?? ?? 53 55 56 57 E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? A0 ?? ?? ?? ?? + B9 ?? ?? ?? ?? 88 44 24 ?? 33 C0 8D 7C 24 ?? 8B 35 ?? ?? ?? ?? F3 AB 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 66 AB 68 ?? ?? ?? ?? 8D 4C 24 ?? 33 ED 68 ?? ?? ?? ?? 51 89 2D ?? ?? + ?? ?? 89 2D ?? ?? ?? ?? AA FF D6 8B 1D ?? ?? ?? ?? 83 C4 ?? 8D 54 24 ?? 52 FF D3 83 + F8 ?? 0F 85 ?? ?? ?? ?? 55 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 + C0 75 ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 A0 ?? ?? ?? ?? B9 ?? ?? ?? ?? 88 84 24 ?? + ?? ?? ?? 33 C0 8D BC 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? F3 AB 66 AB 68 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 AA FF D6 83 C4 ?? 8D 94 24 ?? ?? ?? + ?? 52 FF D3 83 F8 ?? 75 ?? 5F 5E 5D 32 C0 5B 81 C4 ?? ?? ?? ?? C3 + } + $main_7 = { + 68 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 + FF D6 59 85 C0 59 74 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 FF D6 59 88 18 59 8D 85 ?? ?? ?? + ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 53 53 53 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 5F 5E 85 C0 74 ?? 8D 45 ?? 8D + 8D ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 53 8F 45 ?? E8 ?? ?? ?? ?? 39 44 24 ?? 74 ?? 89 44 + 24 ?? 83 EC ?? 2B C3 58 74 ?? FF 75 ?? 50 E8 ?? ?? ?? ?? 59 89 44 24 ?? 83 EC ?? 2B + C3 58 59 74 ?? 68 ?? ?? ?? ?? 50 E8 + } + $main_8 = { + 68 ?? ?? ?? ?? F3 AB 66 AB AA 8D 44 24 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? + ?? 8D 4C 24 ?? 6A ?? 51 FF D6 83 C4 ?? 85 C0 74 ?? 8D 54 24 ?? 6A ?? 52 FF D6 83 C4 + ?? C6 00 ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 5F + 5E 85 C0 74 ?? 8D 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 54 24 ?? 52 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 + ?? 68 ?? ?? ?? ?? 50 E8 + } + $entrypoint_all = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 64 89 25 ?? ?? ?? + ?? 83 EC ?? 53 56 57 89 65 ?? 33 DB 89 5D ?? 6A ?? FF 15 ?? ?? ?? ?? 59 83 0D ?? ?? + ?? ?? ?? 83 0D ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 08 FF 15 ?? ?? + ?? ?? 8B 0D ?? ?? ?? ?? 89 08 A1 ?? ?? ?? ?? 8B 00 A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 39 + 1D ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 59 E8 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 FF 35 ?? ?? ?? + ?? 8D 45 ?? 50 8D 45 ?? 50 8D 45 ?? 50 FF 15 + } + + condition: + uint16(0)==0x5A4D and ($entrypoint_all at pe.entry_point) and ($main_1 or $main_2 or ($main_3 and $start_service_3) or $main_4 or $main_5 or ($main_6 and ($set_reg_key_6 or $download_tor_6)) or $main_7 or $main_8) +} +rule REVERSINGLABS_Win32_Ransomware_Xorist : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Xorist ransomware." + author = "ReversingLabs" + id = "804ae039-fc3b-5f19-860e-df9efe87ee4d" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Xorist.yara#L1-L150" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "c428838cdd103f62508a23c9333b08567625291e110aa437324ecf37c62dca36" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Xorist" + tc_detection_factor = 5 + importance = 25 + + strings: + $search_and_encrypt_v1_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 0F + 84 ?? ?? ?? ?? 48 89 45 ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 2D ?? ?? ?? ?? 50 C6 80 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 80 ?? ?? ?? ?? ?? ?? ?? ?? C6 80 ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? 58 C7 80 ?? ?? ?? ?? ?? ?? ?? ?? C6 80 ?? ?? ?? ?? ?? E9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 2D ?? ?? ?? ?? C6 80 ?? ?? ?? ?? ?? A0 ?? ?? ?? ?? 3C ?? 75 ?? + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 + } + $search_and_encrypt_v1_p2 = { + 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? + E9 ?? ?? ?? ?? EB ?? 8B 3D ?? ?? ?? ?? 8B 0F 83 C7 ?? 51 57 68 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B D8 57 E8 ?? ?? ?? ?? 03 F8 47 59 83 FB ?? 74 ?? 49 75 ?? E9 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? + ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 00 ?? EB ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 85 C0 0F 84 ?? ?? ?? ?? 48 A3 ?? ?? ?? ?? 6A ?? FF + } + $search_and_encrypt_v1_p3 = { + 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 F8 ?? 7D ?? FF 35 ?? ?? ?? ?? E8 ?? + ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A + ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 3D ?? ?? ?? ?? ?? 75 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8A 10 B9 + ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? AC 32 C2 D0 C2 AA E2 ?? A1 ?? ?? ?? ?? 80 + 3D ?? ?? ?? ?? ?? 75 ?? E8 ?? ?? ?? ?? EB ?? 80 3D ?? ?? ?? ?? ?? 75 ?? E8 ?? ?? ?? + ?? EB ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? + ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? + ?? ?? C9 C3 + } + $extract_rsrc_v1 = { + 55 8B EC 83 C4 ?? B9 ?? ?? ?? ?? BF ?? ?? ?? ?? 51 57 0F 31 5F 59 25 ?? ?? ?? ?? C1 + E8 ?? 83 C0 ?? AA E2 ?? 33 C0 AA 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 0B C0 75 ?? C9 C3 89 45 ?? 50 6A ?? E8 ?? + ?? ?? ?? 0B C0 75 ?? C9 C3 89 45 ?? FF 75 ?? 6A ?? E8 ?? ?? ?? ?? 0B C0 75 ?? C9 C3 + 89 45 ?? 50 E8 ?? ?? ?? ?? 0B C0 75 ?? C9 C3 89 45 ?? 8B D8 6A ?? 6A ?? 6A ?? 6A ?? + 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? 89 45 ?? 6A ?? 6A + ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 53 FF 75 ?? E8 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? FF 75 ?? E8 + ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? + C9 C3 + } + $search_and_encrypt_v2_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 0F + 84 ?? ?? ?? ?? 48 89 45 ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 2D ?? ?? ?? ?? 50 C6 80 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 80 ?? ?? ?? ?? ?? ?? ?? ?? C6 80 ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? 58 C7 80 ?? ?? ?? ?? ?? ?? ?? ?? C6 80 ?? ?? ?? ?? ?? E9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 2D ?? ?? ?? ?? C6 80 ?? ?? ?? ?? ?? A0 ?? ?? ?? ?? 3C + ?? 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 53 68 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 + ?? 74 ?? E9 ?? ?? ?? ?? EB ?? 8B 3D ?? ?? ?? ?? 8B 0F 83 C7 ?? 51 57 68 + } + $search_and_encrypt_v2_p2 = { + E8 ?? ?? ?? ?? 8B D8 57 E8 ?? ?? ?? ?? 03 F8 47 59 83 FB ?? 74 ?? 49 75 ?? E9 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? + FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 00 ?? 6A + ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 85 C0 0F + 84 ?? ?? ?? ?? 48 A3 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? + ?? 83 F8 ?? 7D ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? + ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? EB ?? 68 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8A 10 B9 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? AC 32 C2 + D0 C2 AA E2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 35 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF + 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? + ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? FF 75 ?? E8 ?? ?? ?? ?? C9 C3 + } + $extract_rsrc_v2 = { + 55 8B EC 83 C4 ?? 53 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? 89 + 45 ?? 50 6A ?? E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? 89 45 ?? FF 75 ?? 6A ?? E8 + ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? 89 45 ?? 50 E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? + ?? ?? ?? 89 45 ?? 8B F8 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 ?? 8B 45 ?? 83 + E8 ?? 50 57 E8 ?? ?? ?? ?? 8B 1F 83 C7 ?? 53 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 0B C0 75 ?? E9 ?? ?? ?? ?? A3 ?? ?? ?? ?? 53 57 FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 03 + FB 8B 1F 83 C7 ?? 53 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? + ?? A3 ?? ?? ?? ?? 53 57 FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 03 FB 8B 1F 83 C7 ?? 53 6A + ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? A3 ?? ?? ?? ?? 53 57 + FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 03 FB 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 + ?? 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 ?? 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 83 C7 ?? 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 ?? 6A ?? 57 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 83 C7 ?? 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 ?? 6A ?? 57 + 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 ?? 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 + ?? FF 75 ?? E8 ?? ?? ?? ?? 5B C9 C3 + } + + condition: + uint16(0)==0x5A4D and (($extract_rsrc_v1) and ( all of ($search_and_encrypt_v1_p*))) or (($extract_rsrc_v2) and ( all of ($search_and_encrypt_v2_p*))) +} +rule REVERSINGLABS_Win32_Ransomware_Techandstrat : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects TechandStrat ransomware." + author = "ReversingLabs" + id = "525d0b48-2018-5848-b9e7-def8395254eb" + date = "2021-05-17" + modified = "2021-05-17" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.TechandStrat.yara#L1-L106" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "80e201cf91adeee100e05af3ba5227fc61968bb6e0ce602107ba1217a7a62856" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "TechandStrat" + tc_detection_factor = 5 + importance = 25 + + strings: + $enum_shares_p1 = { + 55 8B EC 83 EC ?? 53 56 57 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF 75 ?? C7 45 ?? ?? ?? + ?? ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? 6A ?? FF + 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 85 DB 74 ?? 8D 45 ?? 50 53 8D 45 ?? 50 FF + 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 + } + $enum_shares_p2 = { + 8D 46 ?? B9 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? EB ?? FF 36 E8 ?? ?? ?? ?? 47 83 C6 ?? 3B + 7D ?? 72 ?? 8D 45 ?? 50 53 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 53 6A + ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 + 5D C2 + } + $find_files = { + 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 4D ?? 53 8B 5D ?? + 56 8B 75 ?? 57 89 B5 ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 + 53 E8 ?? ?? ?? ?? 59 59 8B C8 3B CB 75 ?? 8A 11 80 FA ?? 75 ?? 8D 43 ?? 3B C8 74 ?? + 56 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 FF 80 FA ?? 74 ?? 80 FA ?? 74 ?? + 80 FA ?? 74 ?? 8B C7 EB ?? 33 C0 40 0F B6 C0 2B CB 41 F7 D8 68 ?? ?? ?? ?? 1B C0 23 + C1 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? + ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? ?? 83 FE ?? 75 ?? 50 57 + 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D + ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? + ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 80 BD ?? + ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 8B 85 ?? ?? ?? ?? 75 + ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B FF 56 57 + 8B F9 8B 37 EB ?? FF 36 E8 ?? ?? ?? ?? 59 83 C6 ?? 3B 77 ?? 75 ?? FF 37 E8 ?? ?? ?? + ?? 59 5F 5E C3 + } + $encrypt_files_p1 = { + 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 8B 75 ?? 8D 44 24 ?? 57 50 C6 44 + 24 ?? ?? FF 36 FF 15 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 8B + 44 24 ?? 81 E9 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 D8 ?? 6A ?? 6A ?? 50 51 FF 36 FF D7 + 6A ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 36 FF 15 ?? ?? ?? ?? + 81 BC 24 ?? ?? ?? ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 + D2 69 C0 ?? ?? ?? ?? 89 4C 24 ?? 8B 4C 24 ?? 89 8C 24 ?? ?? ?? ?? 83 C9 ?? 51 40 C7 + 44 24 ?? ?? ?? ?? ?? F7 F1 8D 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 50 + C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 89 54 24 ?? 89 94 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 94 24 ?? + ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 10 84 24 ?? ?? ?? ?? 6A ?? 6A ?? 0F + 11 84 24 ?? ?? ?? ?? 0F 57 C0 66 0F 13 44 24 ?? 8B 44 24 ?? 50 89 44 24 ?? 8B 44 24 + ?? 50 FF 36 89 44 24 ?? FF D7 6A ?? 8D 44 24 ?? 0F 57 C0 50 68 ?? ?? ?? ?? 8D 84 24 + ?? ?? ?? ?? 66 0F 13 44 24 ?? 50 FF 36 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 85 + C0 0F 84 + } + $encrypt_files_p2 = { + 6A ?? 6A ?? FF 74 24 ?? 0F 11 84 24 ?? ?? ?? ?? FF 74 24 ?? FF 36 FF 15 ?? ?? ?? ?? + 6A ?? 8D 44 24 ?? 50 FF 74 24 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 36 FF 15 ?? ?? ?? ?? 8B + 84 24 ?? ?? ?? ?? 8B C8 85 C0 B8 ?? ?? ?? ?? 6A ?? 0F 44 C8 69 44 24 ?? ?? ?? ?? ?? + 33 D2 6A ?? 40 89 44 24 ?? F7 F1 8B 4C 24 ?? 33 C0 83 C2 ?? 13 C0 01 54 24 ?? 13 C8 + 8B 44 24 ?? 89 4C 24 ?? 0F A4 C1 ?? C1 E0 ?? 51 50 FF 36 89 4C 24 ?? 89 44 24 ?? FF + 15 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 36 FF + 15 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 + 24 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 C4 ?? C7 84 24 ?? ?? ?? + ?? ?? ?? ?? ?? 6A ?? 6A ?? FF D7 8B 35 ?? ?? ?? ?? 50 FF D6 6A ?? 6A ?? 89 44 24 ?? + FF D7 50 FF D6 6A ?? 6A ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? FF D7 50 FF D6 6A ?? 6A ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? FF D7 50 FF D6 + } + $encrypt_files_p3 = { + 6A ?? 6A ?? 66 0F 13 44 24 ?? FF 74 24 ?? FF 74 24 ?? FF 36 FF 15 ?? ?? ?? ?? 6A ?? + 8D 44 24 ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 36 FF 15 ?? ?? ?? ?? C6 44 + 24 ?? ?? FF 36 FF 15 ?? ?? ?? ?? 80 7C 24 ?? ?? 74 ?? 68 ?? ?? ?? ?? 6A ?? 83 C6 ?? + 56 FF 15 ?? ?? ?? ?? 56 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D + 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? + 8B 75 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? FF 15 + } + + condition: + uint16(0)==0x5A4D and ( all of ($enum_shares_p*)) and ($find_files) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Bkransomware : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects BKRansomware ransomware." + author = "ReversingLabs" + id = "88dc5c4a-046a-52e2-b108-0a90b91d4fb6" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.BKRansomware.yara#L1-L79" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3118098f05a13bd161af0cb1ec322878b371ff70b9f3815a04115a214c0965a2" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "BKRansomware" + tc_detection_factor = 5 + importance = 25 + + strings: + $search_files = { + 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B F9 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? + 57 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? EB ?? 8D A4 24 ?? ?? ?? ?? 90 + 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? + 8B B5 ?? ?? ?? ?? 83 FE ?? 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B + 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 + 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 74 ?? B8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + 66 8B 11 66 3B 10 75 ?? 66 85 D2 74 ?? 66 8B 51 ?? 66 3B 50 ?? 75 ?? 83 C1 ?? 83 C0 + ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 57 8D + 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 83 FE ?? 74 ?? + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? + 50 57 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 + FF 15 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $encrypt_files_p1 = { + 55 8B EC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 57 6A ?? 68 + ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B F9 68 ?? ?? ?? ?? 57 89 BD ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 8B D8 89 9D ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? 56 6A ?? 53 FF 15 ?? ?? ?? + ?? 8B F0 68 ?? ?? ?? ?? 57 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? + ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? + ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 + C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? + ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 + ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? + 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 + C0 75 ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 F6 0F 8E ?? ?? ?? ?? 33 + } + $encrypt_files_p2 = { + FF 8D 49 ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 68 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? 33 F6 8D 51 ?? EB ?? 8D 49 ?? 8A 01 41 84 C0 75 ?? 2B CA 74 ?? BB ?? ?? ?? ?? + 8A 84 35 ?? ?? ?? ?? 3C ?? 7C ?? 3C ?? 7F ?? 0F BE C0 83 E8 ?? 99 F7 FB 80 C2 ?? EB + ?? 3C ?? 7C ?? 3C ?? 7F ?? 0F BE C0 83 E8 ?? 99 F7 FB 80 C2 ?? 88 94 35 ?? ?? ?? ?? + 8D 85 ?? ?? ?? ?? 46 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 3B F0 72 ?? 8B 9D ?? ?? ?? + ?? 6A ?? 6A ?? 57 53 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 51 ?? 8D 9B ?? ?? ?? ?? + 8A 01 41 84 C0 75 ?? 6A ?? 8D 85 ?? ?? ?? ?? 2B CA 50 51 8D 85 ?? ?? ?? ?? 50 53 FF + 15 ?? ?? ?? ?? 03 BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 3B BD ?? ?? ?? ?? 0F 8C ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 53 FF 15 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 57 8D 85 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? + 5E 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and ($search_files) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Hakunamatata : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects HakunaMatata ransomware." + author = "ReversingLabs" + id = "17438fcd-7a51-5fb6-96ac-38523bc1744f" + date = "2020-11-11" + modified = "2020-11-11" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.HakunaMatata.yara#L1-L373" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "e363ff93fce286d60a3f5ea20ba3ec03564b7a5321c3f6448cc82187f23e8a9f" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "HakunaMatata" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files = { + 55 89 E5 57 56 53 81 EC ?? ?? ?? ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? + 85 C0 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? 89 14 24 89 C1 E8 ?? + ?? ?? ?? 83 EC ?? 84 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? 83 7D ?? + ?? 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B + 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 + EC ?? 85 C0 0F 95 C0 84 C0 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 89 45 ?? 89 55 ?? 8B + 45 ?? 8B 40 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 50 ?? 8B 45 ?? 89 54 24 + ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 50 ?? 89 D0 C1 E0 ?? + 01 D0 01 C0 89 45 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? C7 44 24 ?? ?? ?? ?? + ?? 8D 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 + A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 0F 94 C0 84 C0 74 ?? C7 45 ?? ?? ?? ?? ?? E9 ?? + ?? ?? ?? 8B 45 ?? 8B 40 ?? BA ?? ?? ?? ?? 8B 4D ?? 8B 5D ?? 39 DA 72 ?? 39 DA 77 ?? + 39 C8 76 ?? 89 C8 89 DA 89 45 ?? 8B 55 ?? 8B 45 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 4D ?? + 89 4C 24 ?? 89 54 24 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? + 83 F8 ?? 0F 94 C0 84 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B 45 ?? 89 4C 24 ?? 89 + 54 24 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 C6 8B 45 ?? 89 C1 BB + ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 89 CF 31 C7 89 7D ?? 89 DF 31 D7 89 7D ?? 8B 45 ?? 0B + 45 ?? 85 C0 0F 94 C0 0F B6 C8 8B 55 ?? 8B 45 ?? 89 44 24 ?? 8D 45 ?? 89 44 24 ?? 89 + F0 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 14 24 + A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? A1 ?? ?? ?? ?? FF D0 89 45 ?? 8B 45 ?? 85 C0 + 79 ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? C7 44 24 ?? ?? ?? ?? ?? + 8D 4D ?? 89 4C 24 ?? 89 54 24 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 + 83 EC ?? 85 C0 0F 94 C0 84 C0 74 ?? C7 45 ?? ?? ?? ?? ?? 90 EB ?? 8B 4D ?? 8B 5D ?? + 8B 45 ?? BA ?? ?? ?? ?? 29 C1 19 D3 89 C8 89 DA 89 45 ?? 89 55 ?? 8B 45 ?? BA ?? ?? + ?? ?? 01 45 ?? 11 55 ?? 8B 45 ?? 8B 55 ?? 89 C6 83 F6 ?? 89 75 ?? 89 D0 80 F4 ?? 89 + 45 ?? 8B 55 ?? 8B 4D ?? 89 C8 09 D0 85 C0 74 ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + 8B 45 ?? 85 C0 74 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 74 ?? 8B 45 ?? + 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B 45 ?? 89 + 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? + ?? EB ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 + EC ?? 8B 45 ?? 8D 65 ?? 5B 5E 5F 5D C2 + } + $encrypt_files_2 = { + 55 89 E5 56 53 81 EC ?? ?? ?? ?? 89 4D ?? 8B 45 ?? 89 85 ?? ?? ?? ?? 8B 45 ?? 89 85 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? 85 C0 0F 84 ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? 89 04 24 89 D1 E8 ?? ?? ?? ?? 83 EC ?? 84 C0 0F 84 ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 + 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF + D0 83 EC ?? 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 89 + 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 0F 95 C0 84 C0 0F 84 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? + ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 89 45 ?? 89 55 ?? 8B 45 ?? 8B 55 ?? 89 45 ?? 89 55 ?? + 8B 85 ?? ?? ?? ?? 80 F4 ?? 89 C3 8B 85 ?? ?? ?? ?? 80 F4 ?? 89 C6 89 F0 09 D8 85 C0 + 74 ?? 8B 45 ?? 8B 55 ?? 3B 95 ?? ?? ?? ?? 72 ?? 3B 95 ?? ?? ?? ?? 77 ?? 3B 85 ?? ?? + ?? ?? 76 ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 45 ?? 89 55 ?? 8B 45 ?? 8B 40 ?? + 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 40 ?? 8B 55 ?? 89 44 24 ?? C7 44 24 ?? + ?? ?? ?? ?? 89 14 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 50 ?? 89 D0 C1 E0 ?? 01 D0 01 C0 89 + 45 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 + 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? + FF D0 83 EC ?? 85 C0 0F 94 C0 84 C0 74 ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 + ?? 8B 40 ?? BA ?? ?? ?? ?? 8B 4D ?? 8B 5D ?? 39 DA 72 ?? 39 DA 77 ?? 39 C8 76 ?? 89 + C8 89 DA 89 45 ?? 8B 4D ?? 8B 55 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 89 + 4C 24 ?? 89 54 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 83 F8 ?? 0F 94 + C0 84 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? 8B 45 ?? 89 4C 24 ?? 89 54 24 ?? 89 04 + 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 C1 BB ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? + 89 CE 31 C6 89 B5 ?? ?? ?? ?? 89 DE 31 D6 89 B5 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B B5 + ?? ?? ?? ?? 89 D8 09 F0 85 C0 0F 94 C0 88 45 ?? 8B 55 ?? 0F B6 4D ?? 8B 5D ?? 8B 45 + ?? 89 44 24 ?? 8D 45 ?? 89 44 24 ?? 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? + C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 89 45 ?? A1 ?? ?? ?? + ?? FF D0 89 45 ?? 8B 45 ?? 85 C0 79 ?? C7 45 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 4D ?? + 8B 55 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 89 4C 24 ?? 89 54 24 ?? 8B 45 + ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 0F 94 C0 84 C0 74 ?? C7 45 ?? ?? ?? + ?? ?? 90 EB ?? 8B 4D ?? 8B 5D ?? 8B 45 ?? BA ?? ?? ?? ?? 29 C1 19 D3 89 C8 89 DA 89 + 45 ?? 89 55 ?? 8B 45 ?? BA ?? ?? ?? ?? 01 45 ?? 11 55 ?? 8B 45 ?? 8B 55 ?? 89 C6 83 + F6 ?? 89 B5 ?? ?? ?? ?? 89 D0 80 F4 ?? 89 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B B5 ?? + ?? ?? ?? 89 F0 09 D8 85 C0 74 ?? E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 80 F4 ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 80 F4 ?? 89 85 ?? ?? ?? ?? 8B 9D ?? + ?? ?? ?? 8B B5 ?? ?? ?? ?? 89 F0 09 D8 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 55 ?? 2B + 45 ?? 1B 55 ?? 89 45 ?? 89 55 ?? 8B 45 ?? 8B 40 ?? 89 C1 BB ?? ?? ?? ?? 8B 45 ?? 8B + 55 ?? 39 D3 72 ?? 39 D3 77 ?? 39 C1 76 ?? 89 C1 89 D3 89 4D ?? 8B 45 ?? C7 44 24 ?? + ?? ?? ?? ?? 8D 55 ?? 89 54 24 ?? 8B 55 ?? 89 54 24 ?? 89 44 24 ?? 8B 45 ?? 89 04 24 + A1 ?? ?? ?? ?? FF D0 83 EC ?? 83 F8 ?? 0F 94 C0 84 C0 0F 84 ?? ?? ?? ?? 8B 55 ?? 8B + 45 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 4D ?? 89 4C 24 ?? 89 54 24 ?? 89 44 24 ?? 8B 45 ?? + 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 0F 94 C0 84 C0 74 ?? C7 45 ?? ?? ?? ?? + ?? EB ?? 8B 45 ?? 8B 55 ?? 8B 4D ?? BB ?? ?? ?? ?? 29 C8 19 DA 89 45 ?? 89 55 ?? 8B + 45 ?? 8B 55 ?? 89 C3 80 F7 ?? 89 9D ?? ?? ?? ?? 89 D0 80 F4 ?? 89 85 ?? ?? ?? ?? 8B + 9D ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 89 F0 09 D8 85 C0 74 ?? E9 ?? ?? ?? ?? C7 45 ?? ?? + ?? ?? ?? 8B 45 ?? 85 C0 74 ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 85 C0 74 ?? + 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 8B + 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 89 04 24 E8 + ?? ?? ?? ?? EB ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? + FF D0 83 EC ?? 8B 45 ?? 8D 65 ?? 5B 5E 5D C2 + } + $search_files = { + E8 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 95 C0 88 45 ?? 80 7D ?? ?? 74 ?? C7 44 24 ?? ?? ?? + ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? + 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? 83 45 ?? ?? EB ?? A1 ?? + ?? ?? ?? FF D0 89 C3 C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 + 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? 89 1C 24 89 C1 E8 ?? ?? ?? ?? 83 EC + ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 + ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? 8B 45 ?? 89 + C1 E8 ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 89 D9 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + 89 1C 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 85 C0 74 ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 + ?? ?? ?? ?? 90 8D 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? 89 C1 + E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? EB ?? 90 8D 85 + ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 85 C0 0F 95 + C0 84 C0 74 ?? E9 ?? ?? ?? ?? A1 ?? ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 ?? ?? + ?? ?? A1 ?? ?? ?? ?? FF D0 89 C3 C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? 89 1C 24 89 C1 E8 ?? ?? + ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? + ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? C7 + 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? BB ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 + ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC ?? 83 7D ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 05 ?? + ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 85 C0 74 ?? B8 ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? 84 C0 + 74 ?? 8D 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 89 C2 8B 85 ?? ?? ?? ?? 89 14 24 89 C1 + E8 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 89 C2 8B 45 ?? 89 04 24 89 D1 E8 ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 + ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? + ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 + } + $search_files_2 = { + FF 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 89 C3 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 50 ?? 81 C2 ?? ?? ?? ?? 8B 42 ?? + 83 E0 ?? 83 C8 ?? 89 42 ?? 89 1C 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 89 C3 8B + 00 89 DA 03 50 ?? 8B 42 ?? 83 E0 ?? 83 C8 ?? 89 42 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? + ?? ?? 89 C1 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 FF 15 ?? ?? ?? + ?? 83 EC ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 83 BB ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? + 89 04 24 89 D9 E8 ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 + ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 + 04 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 89 04 24 E8 ?? ?? ?? ?? 89 C1 E8 ?? ?? + ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 EC ?? 89 04 24 E8 ?? ?? ?? ?? 89 C1 E8 + } + $remote_connection = { + 55 89 E5 53 81 EC ?? ?? ?? ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 + 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 89 44 24 ?? C7 + 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F0 ?? 84 C0 0F 85 ?? ?? ?? ?? 8D 45 ?? 89 C1 E8 + ?? ?? ?? ?? 8B 45 ?? 8B 00 89 45 ?? 8D 45 ?? 89 44 24 ?? 8D 45 ?? 89 44 24 ?? 8D 45 + ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? + 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 89 45 ?? 83 7D ?? ?? 74 ?? 81 7D ?? ?? ?? + ?? ?? 75 ?? 8B 45 ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 39 45 ?? 77 ?? 8D 45 ?? + 89 C1 E8 ?? ?? ?? ?? 8B 45 ?? 8B 10 8D 45 ?? 8D 4D ?? 89 4C 24 ?? 89 14 24 89 C1 E8 + ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8D 50 ?? 8D 45 ?? 89 04 24 89 D1 E8 ?? ?? ?? ?? 83 EC + ?? 8D 45 ?? 89 C1 E8 ?? ?? ?? ?? 8D 45 ?? 89 C1 E8 ?? ?? ?? ?? 83 45 ?? ?? 83 45 ?? + ?? EB ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 81 7D ?? ?? ?? ?? ?? 75 ?? E9 ?? + ?? ?? ?? 8D 45 ?? 83 C0 ?? 89 C1 E8 ?? ?? ?? ?? 85 C0 0F 95 C0 84 C0 74 ?? 8B 45 ?? + 05 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8D 50 ?? 8D 45 ?? 89 04 24 89 D1 E8 + ?? ?? ?? ?? 83 EC ?? 8B 45 ?? 05 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 90 8D 45 ?? 89 + C1 E8 ?? ?? ?? ?? EB ?? 89 C3 8D 45 ?? 89 C1 E8 ?? ?? ?? ?? EB ?? 89 C3 8D 45 ?? 89 + C1 E8 ?? ?? ?? ?? EB ?? 89 C3 8D 45 ?? 89 C1 E8 ?? ?? ?? ?? 89 D8 89 04 24 E8 ?? ?? + ?? ?? 90 8B 5D ?? C9 C2 + } + $remote_connection_2 = { + 55 89 E5 57 56 53 83 EC ?? 89 4D ?? 8B 5D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 45 ?? 89 44 24 ?? C7 04 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 8B 03 89 45 ?? EB ?? 83 EC ?? 89 45 ?? 85 C0 74 ?? 3D ?? ?? + ?? ?? 74 ?? 81 7D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 8D 45 ?? 89 + 44 24 ?? 8D 45 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? C7 44 24 + ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? EB ?? 8B 45 ?? 89 45 ?? 83 7D ?? ?? + 74 ?? BE ?? ?? ?? ?? 8D 7D ?? EB ?? 83 EC ?? 8D 45 ?? 89 04 24 8D 4D ?? E8 ?? ?? ?? + ?? 83 EC ?? 8B 45 ?? 39 F8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 83 C6 ?? 39 75 ?? 72 ?? 8B + 45 ?? 8B 5C B0 ?? 89 7D ?? B8 ?? ?? ?? ?? 85 DB 74 ?? 89 1C 24 E8 ?? ?? ?? ?? 8D 04 + 43 C6 44 24 ?? ?? 89 44 24 ?? 89 1C 24 8D 4D ?? E8 ?? ?? ?? ?? EB ?? 8B 45 ?? 89 04 + 24 E8 ?? ?? ?? ?? 83 EC ?? E9 ?? ?? ?? ?? 8B 45 ?? 2B 45 ?? C1 F8 ?? 69 C0 ?? ?? ?? + ?? 85 C0 74 ?? 8B 7D ?? 8D 9F ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 47 ?? 3B 47 ?? + 74 ?? 85 C0 74 ?? 8B 55 ?? 89 10 8D 48 ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? + 8B 45 ?? 83 40 ?? ?? 89 1C 24 E8 ?? ?? ?? ?? EB ?? 8B 4D ?? 83 C1 ?? 8D 45 ?? 89 04 + 24 E8 ?? ?? ?? ?? 83 EC ?? EB ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 65 ?? 5B 5E 5F 5D C2 + } + $encrypt_files_3 = { + 55 57 56 53 83 EC ?? 8B 41 ?? 85 C0 75 ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? + ?? BE ?? ?? ?? ?? 89 F0 83 C4 ?? 5B 5E 5F 5D C2 ?? ?? 89 CB C7 44 24 ?? ?? ?? ?? ?? + 8D 54 24 ?? 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 FF + 15 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? + ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C7 BE ?? ?? + ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? + ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C2 89 44 24 ?? + 83 F8 ?? 74 ?? 8D 44 24 ?? 89 44 24 ?? 89 14 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C6 85 + C0 75 ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 3C 24 FF 15 ?? ?? ?? ?? + 83 EC ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 85 F6 0F 84 ?? ?? ?? ?? 8B + 84 24 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 8B 54 24 ?? 89 44 24 ?? 89 54 24 ?? 8B 43 ?? 89 04 + 24 E8 ?? ?? ?? ?? 89 44 24 ?? 8B 73 ?? 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 + E8 ?? ?? ?? ?? 8D 04 B6 01 C0 89 44 24 ?? 89 04 24 E8 ?? ?? ?? ?? 89 C5 C7 44 24 ?? + ?? ?? ?? ?? 8D 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 + 44 24 ?? 89 3C 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 + ?? 8B 54 24 ?? 8B 0D ?? ?? ?? ?? 89 4C 24 ?? 89 7C 24 ?? 89 C6 89 D7 89 5C 24 ?? E9 + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 89 44 24 ?? 89 5C 24 ?? 8B 44 24 ?? + 89 44 24 ?? 8B 4C 24 ?? 89 0C 24 FF 54 24 ?? 83 EC ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 89 + 5C 24 ?? 8B 44 24 ?? 89 44 24 ?? 89 2C 24 E8 ?? ?? ?? ?? 89 5C 24 ?? 89 5C 24 ?? C7 + 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 8D 44 24 ?? 89 44 24 ?? 89 6C 24 ?? C7 + 44 24 ?? ?? ?? ?? ?? 89 DA 31 F2 09 FA 0F 94 C0 0F B6 C0 89 44 24 ?? C7 44 24 ?? ?? + ?? ?? ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C3 FF 15 ?? ?? ?? ?? 85 + C0 78 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? 89 + 6C 24 ?? 8B 4C 24 ?? 89 0C 24 FF 15 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? 2B 74 24 ?? 1B + 7C 24 ?? 89 FA 09 F2 74 ?? 8B 44 24 ?? 8B 58 ?? B8 ?? ?? ?? ?? 39 F8 0F 82 ?? ?? ?? + ?? 39 F3 0F 47 DE E9 ?? ?? ?? ?? 8B 7C 24 ?? 89 DE EB ?? 8B 7C 24 ?? BE ?? ?? ?? ?? + 85 ED 74 ?? 89 2C 24 E8 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 0F 84 ?? ?? ?? ?? 89 04 24 E8 + ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 7C 24 ?? BE ?? ?? ?? ?? EB + } + $encrypt_files_4 = { + FF 15 ?? ?? ?? ?? 83 EC ?? 89 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 88 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 + 34 24 89 54 24 ?? 89 44 24 ?? 89 4C 24 ?? FF 95 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 84 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 29 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 19 95 ?? ?? ?? ?? 8B + 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 D0 89 CA 09 C2 0F 84 ?? ?? ?? ?? 31 D2 3B 95 ?? + ?? ?? ?? 8B 43 ?? 89 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 72 ?? 77 ?? 8B 8D ?? ?? ?? ?? + 39 C8 76 ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 89 44 24 ?? 8D 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? 89 54 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? + 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? 89 04 24 E8 ?? ?? ?? ?? 89 34 24 8B 35 ?? ?? ?? ?? FF D6 8B 85 ?? ?? ?? ?? 83 EC + ?? 89 04 24 FF D6 8B 85 ?? ?? ?? ?? 83 EC ?? 89 04 24 FF 15 ?? ?? ?? ?? 8B 8D ?? ?? + ?? ?? 83 EC ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 + 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? C7 04 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 40 ?? 8B 88 ?? ?? ?? ?? 85 C9 74 ?? 8B 01 C7 + 04 24 ?? ?? ?? ?? FF 50 ?? 83 EC ?? 0F B7 C0 B9 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? + 83 EC ?? 89 C1 E8 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 89 04 24 FF 15 + } + $search_files_3 = { + FF 15 ?? ?? ?? ?? 83 EC ?? 85 C0 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 75 ?? 8B 85 + ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 FF D7 83 + EC ?? 85 C0 0F 84 ?? ?? ?? ?? 83 85 ?? ?? ?? ?? ?? EB ?? 90 8D B4 26 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 83 C3 ?? 8B 50 ?? 8B 40 ?? 89 85 ?? ?? ?? ?? 29 D0 C1 F8 ?? 69 C0 ?? + ?? ?? ?? 39 C3 0F 83 ?? ?? ?? ?? 8D 04 5B 8D 34 C5 ?? ?? ?? ?? 8B 04 C2 89 44 24 ?? + 8B 85 ?? ?? ?? ?? 89 04 24 FF D7 83 EC ?? 85 C0 74 ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? 8B + 1C 30 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? C7 04 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 5C + 24 ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 40 ?? 8B 88 + ?? ?? ?? ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 01 C7 04 24 ?? ?? ?? ?? FF 50 ?? 83 EC ?? 0F + B7 C0 B9 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 89 C1 E8 ?? ?? ?? ?? 31 F6 E9 + ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 + ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 89 5C 24 + ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? + ?? E9 ?? ?? ?? ?? 90 8D 74 26 ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 + E8 + } + $install_service = { + FF 15 ?? ?? ?? ?? 83 EC ?? 85 C0 89 C1 89 44 24 ?? 0F 84 ?? ?? ?? ?? 8B 84 24 ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 0C 24 89 44 24 ?? FF 15 ?? ?? ?? ?? 83 EC ?? 85 C0 + 89 C3 0F 84 ?? ?? ?? ?? 89 04 24 A1 ?? ?? ?? ?? 8D 6C 24 ?? 8D 7C 24 ?? C7 44 24 ?? + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 6C 24 ?? 89 7C 24 ?? 89 44 24 ?? FF D0 83 EC + ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 83 E0 ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? A1 ?? ?? + ?? ?? 89 44 24 ?? FF D0 8B 74 24 ?? 89 44 24 ?? 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? B8 + ?? ?? ?? ?? F7 64 24 ?? B8 ?? ?? ?? ?? C1 EA ?? 81 FA ?? ?? ?? ?? 0F 47 D0 B8 ?? ?? + ?? ?? 81 FA ?? ?? ?? ?? 0F 42 D0 89 14 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 6C 24 ?? C7 + 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 FF 54 24 ?? 83 EC + ?? 85 C0 74 ?? 3B 74 24 ?? 8B 44 24 ?? 72 ?? FF D0 2B 44 24 ?? 3B 44 24 ?? 76 ?? 89 + 1C 24 8B 1D ?? ?? ?? ?? FF D3 83 EC ?? 8B 44 24 ?? 89 04 24 FF D3 83 EC ?? 83 C4 ?? + 5B 5E 5F 5D C2 ?? ?? 8D B4 26 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 + EC ?? 83 C4 ?? 5B 5E 5F 5D C2 ?? ?? 8D B6 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? 89 1C 24 FF 15 ?? ?? ?? ?? 83 EC ?? 85 C0 74 ?? 89 6C 24 ?? C7 44 + 24 ?? ?? ?? ?? ?? 89 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 FF 54 24 ?? 83 EC ?? + 85 C0 0F 84 ?? ?? ?? ?? 8D B6 ?? ?? ?? ?? 8B 44 24 ?? FF D0 8B 74 24 ?? 89 44 24 ?? + 83 7C 24 ?? ?? 0F 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? F7 64 24 ?? B8 ?? ?? ?? ?? C1 EA ?? + 81 FA ?? ?? ?? ?? 0F 47 D0 B8 ?? ?? ?? ?? 81 FA ?? ?? ?? ?? 0F 42 D0 89 14 24 FF 15 + ?? ?? ?? ?? 83 EC ?? 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? C7 44 24 ?? ?? + ?? ?? ?? 89 1C 24 FF 54 24 ?? 83 EC ?? 85 C0 0F 84 ?? ?? ?? ?? 3B 74 24 ?? 72 ?? 8B + 44 24 ?? FF D0 2B 44 24 ?? 3B 44 24 ?? 76 ?? E9 + } + $encrypt_files_5 = { + FF 15 ?? ?? ?? ?? 83 EC ?? 89 C7 BE ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 FF + 15 ?? ?? ?? ?? 83 EC ?? 89 C2 89 44 24 ?? 83 F8 ?? 74 ?? 8D 44 24 ?? 89 44 24 ?? 89 + 14 24 FF 15 ?? ?? ?? ?? 83 EC ?? 89 C6 85 C0 75 ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? + ?? ?? 83 EC ?? 89 3C 24 FF 15 ?? ?? ?? ?? 83 EC ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? + ?? ?? 83 EC ?? 85 F6 0F 84 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? + E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 8B 54 24 + ?? 89 44 24 ?? 89 54 24 ?? 8B 43 ?? 89 04 24 E8 ?? ?? ?? ?? 89 44 24 ?? 8B 73 ?? 89 + 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8D 04 B6 01 C0 89 44 24 ?? + 89 04 24 E8 ?? ?? ?? ?? 89 C5 C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? 89 44 24 ?? C7 44 + 24 ?? ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 89 44 24 ?? 89 3C 24 FF 15 ?? ?? ?? ?? 83 EC + ?? 89 C6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 8B 54 24 ?? 8B 0D ?? ?? ?? ?? 89 4C 24 + ?? 89 7C 24 ?? 89 C6 89 D7 89 5C 24 ?? E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 + 24 ?? 89 44 24 ?? 89 5C 24 ?? 8B 44 24 ?? 89 44 24 ?? 8B 4C 24 ?? 89 0C 24 FF 54 24 + ?? 83 EC ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 89 5C 24 ?? 8B 44 24 ?? 89 44 24 ?? 89 2C 24 + E8 ?? ?? ?? ?? 89 5C 24 ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 + ?? 8D 44 24 ?? 89 44 24 ?? 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 DA 31 F2 09 FA 0F + 94 C0 0F B6 C0 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 FF 15 ?? ?? + ?? ?? 83 EC ?? 89 C3 FF 15 ?? ?? ?? ?? 85 C0 78 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 + ?? 89 44 24 ?? 8B 44 24 ?? 89 44 24 ?? 89 6C 24 ?? 8B 4C 24 ?? 89 0C 24 FF 15 + } + $search_files_4 = { + FF 15 ?? ?? ?? ?? EB ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 89 C3 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 50 ?? 81 C2 ?? ?? ?? ?? 8B 42 ?? + 83 E0 ?? 83 C8 ?? 89 42 ?? 89 1C 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 89 C3 8B + 00 89 DA 03 50 ?? 8B 42 ?? 83 E0 ?? 83 C8 ?? 89 42 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? + ?? ?? 89 C1 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 FF 15 ?? ?? ?? + ?? 83 EC ?? 83 BD ?? ?? ?? ?? ?? 74 ?? 83 BB ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? + 89 04 24 89 D9 E8 ?? ?? ?? ?? 83 EC ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 + ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 + 04 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 89 04 24 E8 ?? ?? ?? ?? 89 C1 E8 ?? ?? + ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 B9 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 EC ?? 89 04 24 E8 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 3B BD ?? + ?? ?? ?? 75 ?? EB ?? 83 EC ?? 83 C7 ?? 39 BD ?? ?? ?? ?? 74 ?? 8B 45 ?? 89 44 24 ?? + 89 3C 24 89 D9 E8 ?? ?? ?? ?? EB ?? BE ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? + ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? + ?? ?? 8D 95 ?? ?? ?? ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 + ?? ?? ?? ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 89 F0 8D 65 ?? 5B 5E 5F 5D C2 + } + $remote_connection_3 = { + 55 89 E5 57 56 53 83 EC ?? 89 4D ?? 8B 5D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 45 ?? 89 44 24 ?? C7 04 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? 8B 03 89 45 ?? EB ?? 83 EC ?? 89 45 ?? 85 C0 74 ?? 3D ?? ?? + ?? ?? 74 ?? 81 7D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? 8D 45 ?? 89 + 44 24 ?? 8D 45 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 45 ?? 89 44 24 ?? C7 44 24 + ?? ?? ?? ?? ?? 8B 45 ?? 89 04 24 E8 ?? ?? ?? ?? EB ?? 8B 45 ?? 89 45 ?? 83 7D ?? ?? + 74 ?? BE ?? ?? ?? ?? 8D 7D ?? EB ?? 83 EC ?? 8D 45 ?? 89 04 24 8D 4D ?? E8 ?? ?? ?? + ?? 83 EC ?? 8B 45 ?? 39 F8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 83 C6 ?? 39 75 ?? 72 ?? 8B + 45 ?? 8B 5C B0 ?? 89 7D ?? B8 ?? ?? ?? ?? 85 DB 74 ?? 89 1C 24 E8 ?? ?? ?? ?? 8D 04 + 43 C6 44 24 ?? ?? 89 44 24 ?? 89 1C 24 8D 4D ?? E8 ?? ?? ?? ?? EB ?? 8B 45 ?? 89 04 + 24 E8 ?? ?? ?? ?? 83 EC ?? E9 ?? ?? ?? ?? 8B 45 ?? 2B 45 ?? C1 F8 ?? 69 C0 ?? ?? ?? + ?? 85 C0 74 ?? 8B 7D ?? 8D 9F ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 8B 47 ?? 3B 47 ?? + 74 ?? 85 C0 74 ?? 8B 55 ?? 89 10 8D 48 ?? 8D 45 ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? + 8B 45 ?? 83 40 ?? ?? 89 1C 24 E8 ?? ?? ?? ?? EB ?? 8B 4D ?? 83 C1 ?? 8D 45 ?? 89 04 + 24 E8 ?? ?? ?? ?? 83 EC ?? EB ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 65 ?? 5B 5E 5F 5D C2 ?? + ?? 89 C3 8B 45 ?? 8D 55 ?? 39 D0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? 89 1C 24 E8 ?? ?? ?? ?? 89 C3 EB ?? 53 83 EC ?? 8B 5C 24 ?? 8D 43 ?? 89 04 24 8B + 0B E8 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? C7 04 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 83 C4 ?? 5B C3 + } + + condition: + uint16(0)==0x5A4D and (($search_files and $encrypt_files and $remote_connection) or ($encrypt_files_2 and $remote_connection and $search_files) or ($search_files_2 and $encrypt_files_3 and $remote_connection_2) or ($install_service and $search_files_3 and $encrypt_files_4) or ($search_files_4 and $encrypt_files_5 and $remote_connection_3)) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Pacman : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Pacman ransomware." + author = "ReversingLabs" + id = "a440769b-030b-5b72-a6f2-cf478dd7acd2" + date = "2021-08-12" + modified = "2021-08-12" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Pacman.yara#L1-L68" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "0634303a4db2631edb40a9435444f3bdc4bc6eb745c7e43a54478e54e7507403" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Pacman" + tc_detection_factor = 5 + importance = 25 + + strings: + $pacman_find_encrypted_1 = { + 28 0A 00 00 06 [0-2] 6F 0D 00 00 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] 28 + 29 02 00 06 1F 1C 28 0E 04 00 06 [0-2] 7E 13 00 00 04 20 0F 03 00 00 28 2F 00 00 06 25 + 26 28 5D 02 00 06 [0-2] 28 6D 01 00 06 [0-2] 0B 07 13 06 16 13 05 2B 31 11 06 11 05 9A + 0C 28 0A 00 00 06 [0-2] 6F 0D 00 00 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] + 08 28 55 02 00 06 [0-2] 26 11 05 17 D6 13 05 11 05 11 06 8E B7 32 C7 1D 45 01 00 00 00 + F6 FF FF FF 17 2D 06 D0 1E 01 00 06 26 16 0A 38 BC 01 00 00 28 0A 00 00 06 [0-2] 6F 0D + 00 00 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] 06 28 AA 04 00 06 [0-2] 14 20 + B0 0F 00 00 28 2F 00 00 06 [0-2] 1F 0A 8D 76 00 00 01 13 07 11 07 16 20 BF 0F 00 00 28 + 2F 00 00 06 [0-2] A2 11 07 17 20 C2 0F 00 00 28 2F 00 00 06 [0-2] A2 11 07 18 20 C5 0F + 00 00 28 2F 00 00 06 [0-2] A2 11 07 19 20 C8 0F 00 00 28 2F 00 00 06 [0-2] A2 11 07 1A + 20 CB 0F 00 00 28 2F 00 00 06 [0-2] A2 11 07 1B 20 CE 0F 00 00 28 2F 00 00 06 [0-2] A2 + } + $pacman_find_encrypted_2 = { + 11 07 1C 20 D1 0F 00 00 28 2F 00 00 06 [0-2] A2 11 07 1D 20 D4 0F 00 00 28 2F 00 00 06 + [0-2] A2 11 07 1E 20 C2 0F 00 00 28 2F 00 00 06 [0-2] A2 11 07 1F 09 20 D7 0F 00 00 28 + 2F 00 00 06 [0-2] A2 11 07 14 14 14 28 7A 04 00 06 [0-2] 28 E2 05 00 06 [0-2] 0D 28 07 + 00 00 06 28 1A 04 00 06 [0-2] 28 0A 00 00 06 [0-2] 6F 0D 00 00 06 [0-2] 6F 33 00 00 06 + [0-2] 28 FD 01 00 06 [0-2] 06 28 AA 04 00 06 [0-2] 28 E2 05 00 06 [0-2] 28 36 05 00 06 + [0-2] 2C 78 1A 45 01 00 00 00 F6 FF FF FF 7E 16 00 00 04 28 9D 02 00 06 [0-2] 28 0A 00 + 00 06 [0-2] 6F 0D 00 00 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] 06 28 AA 04 + 00 06 [0-2] 28 E2 05 00 06 [0-2] 09 16 28 23 01 00 06 28 0A 00 00 06 [0-2] 6F 0D 00 00 + 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] 06 28 AA 04 00 06 [0-2] 28 E2 05 00 + 06 [0-2] 28 66 04 00 06 DE 0F 25 28 4E 04 00 06 13 04 28 02 03 00 06 DE 00 06 17 D6 0A + 06 28 0A 00 00 06 [0-2] 6F 0D 00 00 06 [0-2] 6F 33 00 00 06 [0-2] 28 FD 01 00 06 [0-2] + 28 E2 04 00 06 [0-2] 3F 1B FE FF FF 1B 45 01 00 00 00 F6 FF FF FF 28 28 00 00 06 2A + } + $pacman_encrypt = { + 28 65 02 00 06 [0-2] 0A 16 13 05 20 00 04 00 00 13 07 06 11 07 28 2A 05 00 06 [0-2] 2C + 19 1C 45 01 00 00 00 F6 FF FF FF 17 2D 06 D0 20 01 00 06 26 11 07 13 05 2B 15 11 07 15 + D6 13 07 11 07 17 2F D0 17 45 01 00 00 00 F6 FF FF FF 20 DA 0F 00 00 28 2F 00 00 06 [0-2] + 11 05 28 9D 02 00 06 [0-2] 28 E2 02 00 06 [0-2] 28 6E 03 00 06 06 28 0A 03 00 06 [0-2] + 0B 14 13 04 14 0D 1F 0E 8D 25 00 00 01 13 0B 11 0B 16 ?? 9C 11 0B 17 ?? 9C 11 0B 18 + ?? 9C 11 0B 19 ?? 9C 11 0B 1A ?? 9C 11 0B 1B ?? 9C 11 0B 1C ?? 9C 11 0B 1D ?? 9C 11 0B + 1E 20 ?? ?? ?? ?? 9C 11 0B 1F 09 20 ?? ?? ?? ?? 9C 11 0B 1F 0A 20 ?? ?? ?? ?? 9C 11 0B + 1F 0B 1F ?? 9C 11 0B 1F 0C 1F ?? 9C 11 0B 1F 0D 1F ?? 9C 11 0B 13 06 02 11 06 11 05 07 + 12 04 12 03 28 1F 01 00 06 05 2C 18 18 45 01 00 00 00 F6 FF FF FF 06 11 04 09 28 96 03 + 00 06 [0-2] 0C 2B 0C 06 11 04 09 28 7E 05 00 06 [0-2] 0C 04 08 17 28 45 01 00 06 [0-2] + 13 08 20 01 04 00 00 8D 25 00 00 01 13 09 03 11 09 16 20 00 04 00 00 28 3A 03 00 06 [0-2] + 13 0A 11 0A 16 33 0C 1D 45 01 00 00 00 F6 FF FF FF DE 24 11 08 11 09 16 11 0A 28 F6 04 + 00 06 2B CF 11 08 2C 11 18 45 01 00 00 00 F6 FF FF FF 11 08 28 1E 03 00 06 DC DE 0C 28 + 4E 04 00 06 28 02 03 00 06 DE 00 08 28 1E 03 00 06 2A + } + + condition: + uint16(0)==0x5A4D and ($pacman_find_encrypted_1 and $pacman_find_encrypted_2 and $pacman_encrypt) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_EAF : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects EAF ransomware." + author = "ReversingLabs" + id = "6903030e-b1a1-5238-b377-ce8e4b18d3f3" + date = "2022-07-22" + modified = "2022-07-22" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.EAF.yara#L1-L89" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3d10c852f95e8aa9bcd3543b96650b98ac57bcd2aa2b374e0badb63b5a4c0396" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "EAF" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 00 03 28 ?? ?? ?? ?? 0A 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 39 ?? ?? ?? ?? 00 7E ?? + ?? ?? ?? 0C 03 28 ?? ?? ?? ?? 0D 03 28 ?? ?? ?? ?? 13 ?? 1E 8D ?? ?? ?? ?? 25 16 11 ?? + A2 25 17 72 ?? ?? ?? ?? A2 25 18 7E ?? ?? ?? ?? A2 25 19 72 ?? ?? ?? ?? A2 25 1A 28 ?? + ?? ?? ?? A2 25 1B 72 ?? ?? ?? ?? A2 25 1C 09 A2 25 1D 72 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? + 13 ?? 02 03 11 ?? 08 28 ?? ?? ?? ?? 13 ?? 11 ?? 2D ?? 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 2B ?? 16 13 ?? 11 ?? 2C ?? 00 00 03 11 ?? 28 ?? ?? ?? ?? 00 00 DE ?? 26 00 00 DE ?? 00 + 00 00 DE ?? 26 00 00 DE ?? 2A + } + $encrypt_files_p2 = { + 00 03 19 73 ?? ?? ?? ?? 0A 00 04 18 73 ?? ?? ?? ?? 0B 00 06 16 6A 6F ?? ?? ?? ?? 00 28 + ?? ?? ?? ?? 0C 00 1F ?? 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 05 09 73 ?? + ?? ?? ?? 13 ?? 00 08 17 6F ?? ?? ?? ?? 00 08 18 6F ?? ?? ?? ?? 00 08 11 ?? 1F ?? 6F ?? + ?? ?? ?? 6F ?? ?? ?? ?? 00 08 11 ?? 1F ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 08 6F ?? + ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 00 20 ?? ?? ?? ?? 13 ?? 11 ?? 8D ?? ?? ?? ?? 13 ?? 16 + 13 ?? 00 06 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? FE 02 16 FE 01 13 + ?? 11 ?? 2C ?? 00 11 ?? 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 00 00 2B ?? 11 ?? 20 ?? ?? ?? ?? + 32 ?? 11 ?? 20 ?? ?? ?? ?? FE 02 16 FE 01 2B ?? 16 13 ?? 11 ?? 2C ?? 00 11 ?? 11 ?? 16 + 11 ?? 6F ?? ?? ?? ?? 00 00 2B ?? 11 ?? 20 ?? ?? ?? ?? 32 ?? 11 ?? 20 ?? ?? ?? ?? FE 02 + 16 FE 01 2B ?? 16 13 ?? 11 ?? 2C ?? 00 11 ?? 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 00 00 2B ?? + 00 07 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 11 ?? 58 13 ?? 00 11 ?? 16 FE 03 13 ?? + 11 ?? 3A ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? + 00 DC 00 DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? 00 DC 00 DE ?? 08 2C ?? 08 6F ?? ?? ?? + ?? 00 DC 07 6F ?? ?? ?? ?? 00 00 DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? 00 DC 06 6F ?? ?? ?? + ?? 00 00 DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? 00 DC 03 28 ?? ?? ?? ?? 00 17 13 ?? DE ?? 26 + 00 16 13 ?? DE ?? 11 ?? 2A + } + $find_files_p1 = { + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 16 0C 38 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0D 00 09 06 08 9A + 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 06 08 9A 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 09 FE 06 ?? + ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 09 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 2C ?? 11 ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 11 ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? + ?? 2B ?? 16 13 ?? 11 ?? 2C ?? 00 7E ?? ?? ?? ?? 06 08 9A 6F ?? ?? ?? ?? 00 00 00 08 17 + 58 0C 08 06 8E 69 FE 04 13 ?? 11 ?? 3A ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 16 + 13 ?? 2B ?? 00 07 11 ?? 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 07 11 ?? 9A 72 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 2C ?? 07 11 ?? 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 07 11 ?? 9A 72 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 2B ?? 16 13 ?? 11 ?? 2C ?? 00 07 11 ?? 9A 28 ?? ?? ?? ?? 00 + 00 00 11 ?? 17 58 13 ?? 11 ?? 07 8E 69 FE 04 13 ?? 11 ?? 2D ?? 00 DE ?? 26 00 00 DE ?? + 2A + } + $find_files_p2 = { + 00 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 73 ?? ?? ?? ?? 0C 08 06 07 9A 7D ?? ?? ?? ?? 00 08 7B + ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 08 7B ?? ?? ?? ?? 6F ?? + ?? ?? ?? 2B ?? 16 0D 09 2C ?? 00 08 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 00 00 00 07 17 58 0B 07 06 8E 69 32 ?? 00 DE ?? 26 00 00 DE ?? 2A + } + $destroy_exe_file = { + 00 1F ?? 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? ?? 0B 7E ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 0C 7E ?? + ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 08 72 ?? ?? ?? ?? 1B 8D ?? + ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 06 A2 25 18 72 ?? ?? ?? ?? A2 25 19 28 ?? ?? ?? + ?? A2 25 1A 72 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? 00 00 + DE ?? 26 00 00 DE ?? 2A + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($destroy_exe_file) +} +rule REVERSINGLABS_Win32_Ransomware_Spora : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Spora ransomware." + author = "ReversingLabs" + id = "f07ee1d4-d99b-5cbf-a1f0-a3802d9e3b47" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Spora.yara#L1-L124" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "4e18bb42277ce9194bf75fa45d95ea7e2bd51c5d7791d3d6e013fc07626e65b0" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Spora" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files = { + 55 8D 6C 24 ?? 81 EC ?? ?? ?? ?? 57 FF 75 ?? 33 FF 89 7D ?? FF 15 ?? ?? ?? ?? 83 F8 + ?? 0F 84 ?? ?? ?? ?? A8 ?? 74 ?? 83 E0 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 53 56 57 BE + ?? ?? ?? ?? 56 6A ?? 57 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB + ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 53 89 7D ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 0F + 82 ?? ?? ?? ?? 6A ?? 57 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? + ?? 57 8D 45 ?? 50 56 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 39 75 + ?? 0F 85 ?? ?? ?? ?? 57 8D 45 ?? 50 6A ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F + 84 ?? ?? ?? ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 56 8D 45 ?? 50 57 FF 15 ?? ?? ?? ?? 3B + 45 ?? 0F 84 ?? ?? ?? ?? 39 7D ?? 74 ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? B9 ?? ?? + ?? ?? 3B C1 72 ?? 89 4D ?? EB ?? 83 E0 ?? 89 45 ?? 57 FF 75 ?? 57 6A ?? 57 53 FF 15 + ?? ?? ?? ?? 89 45 ?? 3B C7 0F 84 ?? ?? ?? ?? FF 75 ?? 57 57 6A ?? 50 FF 15 ?? ?? ?? + ?? 89 45 ?? 3B C7 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? + ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 57 6A ?? 57 FF + 75 ?? 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 8D 45 ?? 50 8D 45 ?? 50 57 6A ?? 57 + FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? FF 75 ?? 8D 45 ?? 50 FF 75 ?? 57 57 + 57 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 8D 45 ?? 50 57 FF 15 ?? ?? ?? ?? 6A ?? + 57 57 53 89 45 ?? FF 15 ?? ?? ?? ?? 57 8D 45 ?? 50 56 8B 35 ?? ?? ?? ?? 8D 45 ?? 50 + 53 FF D6 57 8D 45 ?? 50 6A ?? 8D 45 ?? 50 53 FF D6 C7 45 ?? ?? ?? ?? ?? FF 75 ?? FF + 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? EB ?? C7 45 ?? + ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 5E 5B 8B 45 ?? 5F 83 C5 ?? C9 C2 + } + $create_key_file = { + 55 8D 6C 24 ?? 81 EC ?? ?? ?? ?? 56 8D 45 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? 33 F6 89 75 ?? C7 45 ?? ?? ?? ?? ?? 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F + 84 ?? ?? ?? ?? 57 8D 45 ?? 50 8D 45 ?? 50 56 6A ?? 56 FF 75 ?? BF ?? ?? ?? ?? 89 7D + ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 57 8B 3D ?? ?? ?? ?? 8D 45 ?? 50 8D 45 + ?? 50 56 6A ?? 56 FF 35 ?? ?? ?? ?? FF D7 FF 75 ?? FF 15 ?? ?? ?? ?? 83 E0 ?? 83 C0 + ?? 50 89 45 ?? 8D 45 ?? 50 FF 75 ?? 56 56 56 FF 75 ?? FF D7 85 C0 0F 84 ?? ?? ?? ?? + 53 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF D3 8B F8 3B FE 0F 84 ?? ?? ?? ?? 56 6A + ?? 57 56 FF 15 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8D 04 47 50 + FF 15 ?? ?? ?? ?? 83 C4 ?? 56 6A ?? 6A ?? 56 56 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? + 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 56 8D 4D ?? 51 FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? + ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 3B 45 ?? 0F 85 ?? ?? ?? ?? 56 8D 45 ?? 50 68 + ?? ?? ?? ?? 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 81 7D ?? + ?? ?? ?? ?? 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? C7 45 ?? ?? ?? ?? ?? 57 68 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF D3 8B D8 3B DE 74 ?? 89 75 ?? 8B 45 + ?? 56 FF 74 85 ?? 53 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? FF 75 ?? 68 ?? ?? ?? ?? 53 FF + 15 ?? ?? ?? ?? 8D 04 43 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 56 53 57 FF 15 ?? ?? ?? ?? FF + 45 ?? 83 7D ?? ?? 72 ?? 53 FF 15 ?? ?? ?? ?? EB ?? FF 75 ?? FF 15 ?? ?? ?? ?? 57 FF + 15 ?? ?? ?? ?? 5B FF 75 ?? FF 15 ?? ?? ?? ?? 5F 8B 45 ?? 5E 83 C5 ?? C9 C2 + } + $create_key = { + 55 8D 6C 24 ?? 81 EC ?? ?? ?? ?? 56 8D 45 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 53 57 8D 45 ?? 50 8D 45 ?? 50 + 33 DB 53 6A ?? 53 FF 75 ?? BE ?? ?? ?? ?? 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 56 8B 35 ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 53 6A ?? 53 FF 35 ?? ?? ?? ?? + FF D6 FF 75 ?? FF 15 ?? ?? ?? ?? 83 E0 ?? 83 C0 ?? 50 89 45 ?? 8D 45 ?? 50 FF 75 ?? + 53 53 53 FF 75 ?? FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 4D ?? 8B 35 ?? ?? ?? ?? + 03 C8 51 6A ?? FF D6 8B F8 89 7D ?? 3B FB 0F 84 ?? ?? ?? ?? FF 75 ?? FF 75 ?? 57 FF + 15 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? 50 8B 45 ?? 03 C7 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 83 + C4 ?? 8D 45 ?? 50 8B 45 ?? 53 6A ?? 03 C8 51 57 8B 3D ?? ?? ?? ?? FF D7 85 C0 74 ?? + FF 75 ?? 6A ?? FF D6 8B F0 3B F3 74 ?? 8B 4D ?? 8D 45 ?? 50 8B 45 ?? 56 6A ?? 03 C8 + 51 FF 75 ?? FF D7 33 FF 38 1E 74 ?? 8B C6 80 38 ?? 75 ?? 40 40 8A 08 88 0C 37 47 40 + 38 18 75 ?? 88 1C 37 EB ?? 8B 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? EB ?? 8B 75 ?? FF 75 + ?? FF 15 ?? ?? ?? ?? 5F 5B EB ?? 8B 75 ?? 8B C6 5E 83 C5 ?? C9 C2 + } + $create_lst_file = { + 55 8D 6C 24 ?? 81 EC ?? ?? ?? ?? 53 56 68 ?? ?? ?? ?? 33 F6 6A ?? 89 75 ?? FF 15 ?? + ?? ?? ?? 8B D8 3B DE 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 57 8B 45 ?? 8B 38 8D 45 + ?? 50 53 83 C7 ?? FF 15 ?? ?? ?? ?? 03 C0 50 53 FF 75 ?? FF 17 8B 45 ?? 8B 08 8D 55 + ?? 52 6A ?? 68 ?? ?? ?? ?? 50 FF 51 ?? 53 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 45 ?? 8B 08 + 8D 55 ?? 52 6A ?? 68 ?? ?? ?? ?? 50 FF 51 ?? 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? + 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 89 45 ?? 3B C6 0F 84 ?? ?? ?? ?? + 8B 3D ?? ?? ?? ?? 56 56 56 56 6A ?? 50 56 68 ?? ?? ?? ?? FF D7 89 45 ?? 3B C6 0F 84 + ?? ?? ?? ?? 83 C0 ?? 50 6A ?? FF 15 ?? ?? ?? ?? 89 45 ?? 3B C6 0F 84 ?? ?? ?? ?? 56 + 56 FF 75 ?? 50 6A ?? FF 75 ?? 56 68 ?? ?? ?? ?? FF D7 8D 45 ?? 50 6A ?? 68 ?? ?? ?? + ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 83 E0 ?? 83 + C0 ?? 89 45 ?? 8D 45 ?? 50 8D 45 ?? 50 56 6A ?? 56 FF 75 ?? BF ?? ?? ?? ?? 89 7D ?? + FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 57 8D 45 ?? 50 8D 45 ?? 50 56 6A ?? 56 FF + 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? 50 FF 75 ?? 56 56 + 56 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 56 6A ?? 53 56 FF 15 ?? ?? ?? + ?? FF 75 ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8D 04 43 50 FF 15 ?? ?? ?? ?? 83 C4 + ?? 57 53 FF 15 ?? ?? ?? ?? 56 6A ?? 6A ?? 56 56 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? + 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 56 8D 4D ?? 51 FF 75 ?? FF 75 ?? 50 FF 15 ?? ?? + ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 45 ?? 3B 45 ?? 0F 85 ?? ?? ?? ?? 56 8D 45 ?? 50 57 + 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 39 7D ?? 75 ?? FF 75 ?? C7 45 ?? + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 75 ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 3B FE 74 ?? 56 6A ?? 57 56 FF 15 ?? ?? ?? ?? 85 C0 + 74 ?? FF 75 ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8D 04 47 50 FF 15 ?? ?? ?? ?? 83 + C4 ?? 56 57 53 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? EB ?? FF 75 ?? FF 15 ?? ?? ?? + ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? + 5F 8B 45 ?? 8B 08 50 FF 51 ?? 53 FF 15 ?? ?? ?? ?? 8B 45 ?? 5E 5B 83 C5 ?? C9 C2 + } + $enumerate_resources = { + 55 8B EC 83 EC ?? 8D 45 ?? 50 FF 75 ?? 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 85 C0 0F 85 + ?? ?? ?? ?? 53 8B 1D ?? ?? ?? ?? 56 57 BE ?? ?? ?? ?? 56 6A ?? FF D3 8B F8 89 7D ?? + 85 FF [2-8] 83 4D ?? ?? 8D 45 ?? 50 57 8D 45 ?? 50 FF 75 ?? 89 75 ?? E8 + ?? ?? ?? ?? 85 C0 75 ?? 39 45 ?? 74 ?? 8D 77 ?? F6 46 ?? ?? 74 ?? 8D 46 ?? 50 [0-3] + E8 ?? ?? ?? ?? EB ?? 83 7E ?? ?? 75 ?? FF 36 FF 15 ?? ?? ?? ?? 8D 44 00 ?? 50 6A + ?? FF D3 8B F8 85 FF 74 ?? FF 36 57 FF 15 ?? ?? ?? ?? [0-5] 57 E8 ?? ?? ?? + ?? 57 FF 15 ?? ?? ?? ?? 83 C6 ?? FF 4D ?? 75 ?? 8B 7D ?? 57 FF 15 ?? ?? ?? ?? FF 75 + ?? E8 ?? ?? ?? ?? 5F 5E 5B C9 C2 + } + + condition: + uint16(0)==0x5A4D and (($create_key_file and $create_lst_file and $enumerate_resources and $encrypt_files) or ($create_key and $enumerate_resources and $encrypt_files)) +} +rule REVERSINGLABS_Win32_Ransomware_Loocipher : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects LooCipher ransomware." + author = "ReversingLabs" + id = "b5aa2bd0-72b0-5013-a60e-9b4f1ee1de1f" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.LooCipher.yara#L1-L87" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "aa0598d63b5fad6aea0945a0aa2030d3d6e2cd9f1fea16f3dd17cdceb68323e3" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "LooCipher" + tc_detection_factor = 5 + importance = 25 + + strings: + $remote_connection = { + 6A ?? 83 EC ?? 8B CC 89 A5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? + ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 B9 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? + 50 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 68 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 + 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? + 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? + ?? E8 + } + $encrypt_files = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? 53 56 57 8D BD + ?? ?? ?? ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? F3 AB A1 ?? ?? ?? ?? 33 C5 89 45 ?? 50 8D + 45 ?? 64 A3 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? + 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 0F B7 4D ?? 3B C1 74 + ?? E8 ?? ?? ?? ?? 8B F0 8D 4D ?? E8 ?? ?? ?? ?? 8B C8 83 E9 ?? 8B C6 33 D2 F7 F1 89 + 55 ?? 6A ?? 8B 45 ?? 50 8D 8D ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? 8B 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? C6 45 ?? ?? 8B 85 ?? ?? ?? ?? 50 8D 4D ?? E8 + ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 8D 45 ?? 50 8B 4D ?? + E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 C9 ?? 89 8D ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 52 8B CD 50 8D 15 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 58 5A 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B 4D ?? + 33 CD E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 3B EC E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $find_files = { + 52 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 0F B6 85 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? B9 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 0F B6 C0 85 C0 0F 84 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8B F4 89 + A5 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 50 ?? 52 8B 00 50 8B CE E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C6 45 ?? ?? B9 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 6A ?? 8D 8D ?? ?? ?? ?? 51 C6 45 ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 89 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 + B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + 68 ?? ?? ?? ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? EB ?? 83 EC ?? 8B CC + 89 A5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? + 83 C4 ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 + B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 8D + ?? ?? ?? ?? 89 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 B9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? EB + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($remote_connection) +} +rule REVERSINGLABS_Win32_Ransomware_Vegalocker : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects VegaLocker ransomware." + author = "ReversingLabs" + id = "53eec8d1-bab0-5556-92c0-1b70eb763fa5" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.VegaLocker.yara#L1-L100" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "8616e72fc435676179e83a304d4111c8f29ebf3cd79ff5b2d229cca8fc97c2a3" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "VegaLocker" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 89 55 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? + ?? 89 C3 85 DB 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 FF D3 85 C0 74 + ?? 8B 45 ?? 50 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 + ?? 80 38 ?? 75 ?? 8B 45 ?? 80 78 ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? E8 ?? ?? + ?? ?? 8B F0 80 3E ?? 0F 84 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F0 80 3E ?? 0F 84 + ?? ?? ?? ?? EB ?? 8B 75 ?? 83 C6 ?? 8B DE 2B 5D ?? 8D 43 ?? 50 8B 45 ?? 50 8D 85 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F8 8B C7 2B C6 + 03 C3 40 3D ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 8B C7 2B C6 40 50 56 8D 85 ?? ?? ?? ?? 03 + C3 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 89 45 + ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? + 8D 53 ?? 03 C2 40 3D ?? ?? ?? ?? 7F ?? C6 84 1D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B C3 + 48 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 03 C3 40 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 40 03 D8 8B F7 80 3E ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 8D 85 + ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 5F 5E 5B 8B E5 5D C3 + } + $encrypt_files_p1 = { + 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D + ?? ?? ?? ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 55 ?? 89 45 ?? 8D 45 ?? E8 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 + FF 30 64 89 20 C6 85 ?? ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 85 + ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 89 85 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 E9 ?? ?? ?? ?? 8D 85 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 55 68 + ?? ?? ?? ?? 64 FF 30 64 89 20 6A ?? 8B 4D ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 + 45 ?? 8B 45 ?? 8B 10 FF 12 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? + ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? + 33 D2 8B 45 ?? 8B 08 FF 51 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B + 45 ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C6 + 85 ?? ?? ?? ?? ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 + 64 89 10 EB ?? E9 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 + } + $encrypt_files_p2 = { + 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 8B 4D ?? B2 ?? + A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 10 FF 12 89 85 ?? ?? ?? ?? 89 95 + ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 83 BD ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? EB ?? + 0F 8E ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 76 ?? EB + ?? 7E ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 85 ?? + ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? + ?? 8D 45 ?? E8 ?? ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 85 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 83 FB ?? 7F ?? + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? + ?? 8D 45 ?? E8 ?? ?? ?? ?? 43 83 FB ?? 75 ?? 8B 85 ?? ?? ?? ?? 8B D0 8D 45 ?? E8 ?? + ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B D0 8B 8D ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 83 + BD ?? ?? ?? ?? ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 8D 45 ?? BA + } + $encrypt_files_p3 = { + E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? + EB ?? 8D 45 ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 33 D2 8B 45 ?? 8B + 08 FF 51 ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 8D 45 ?? + E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 55 E8 ?? ?? ?? ?? 59 55 E8 ?? ?? + ?? ?? 59 EB ?? 55 E8 ?? ?? ?? ?? 59 A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? + ?? 8B 45 ?? E8 ?? ?? ?? ?? 55 E8 ?? ?? ?? ?? 59 C6 85 ?? ?? ?? ?? ?? 8B 45 ?? E8 ?? + ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 + E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? + 64 FF 30 64 89 20 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? + ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? + BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win64_Ransomware_Albabat : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Albabat ransomware." + author = "ReversingLabs" + id = "11941c0d-45fb-5746-bbad-f43f336d4b1d" + date = "2024-03-18" + modified = "2024-03-18" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Albabat.yara#L1-L139" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "38ec8388b9006f6ab9a397858b89f4bfd7def2ffcf525cfc736abae49bc6034a" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Albabat" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_p1 = { + 48 8D 05 ?? ?? ?? ?? 48 89 83 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? C7 83 ?? + ?? ?? ?? ?? ?? ?? ?? 66 C7 83 ?? ?? 00 00 ?? ?? C7 83 ?? ?? ?? ?? ?? ?? ?? ?? 0F 57 + F6 0F 11 B3 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? C6 83 ?? ?? ?? ?? ?? 4C 8D + 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 D7 48 85 C0 74 ?? 0F B6 05 ?? ?? ?? ?? 48 8B 0D + ?? ?? ?? ?? 48 85 C9 75 ?? FF 15 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 C1 48 + 89 05 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 31 D2 FF 15 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? + ?? 48 89 C6 48 89 38 4C 8D 35 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 89 BB ?? ?? ?? ?? 48 C7 + 83 ?? ?? ?? ?? ?? ?? ?? ?? 0F 11 B3 ?? ?? ?? ?? 48 89 F9 E8 ?? ?? ?? ?? 48 89 C6 48 + 89 D7 48 85 C0 74 ?? 48 85 FF 0F 85 ?? ?? ?? ?? 48 89 7C 24 ?? 48 8D 8B ?? ?? ?? ?? + 48 8D 93 ?? ?? ?? ?? 4C 8D 83 ?? ?? ?? ?? 49 89 F1 E8 ?? ?? ?? ?? 48 83 BB ?? ?? ?? + ?? ?? 0F 84 ?? ?? ?? ?? 48 8B BB ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? + ?? 48 85 C9 75 ?? FF 15 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 C1 48 89 05 ?? + ?? ?? ?? 41 B8 ?? ?? ?? ?? 31 D2 FF 15 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 + } + $encrypt_files_p2 = { + C6 48 89 38 4C 8D 35 ?? ?? ?? ?? 48 83 BB ?? ?? ?? ?? ?? 74 ?? 4C 8B 83 ?? ?? ?? ?? + 48 8B 0D ?? ?? ?? ?? 31 D2 FF 15 ?? ?? ?? ?? 48 8B 8B ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 48 85 F6 0F 84 ?? ?? ?? ?? 48 89 B3 ?? ?? ?? ?? 4C 89 B3 ?? ?? ?? ?? 4C 8D B3 ?? ?? + ?? ?? 4C 89 B3 ?? ?? ?? ?? 4C 8D 3D ?? ?? ?? ?? 4C 89 BB ?? ?? ?? ?? 48 8D 05 ?? ?? + ?? ?? 48 89 83 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? + ?? ?? ?? 48 8D BB ?? ?? ?? ?? 48 89 BB ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? + 48 8D 8B ?? ?? ?? ?? 48 8D 93 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B B3 ?? ?? ?? ?? 48 8B + 93 ?? ?? ?? ?? 4C 8B A3 ?? ?? ?? ?? 48 89 F1 E8 ?? ?? ?? ?? 4D 85 E4 74 ?? 48 8B 0D + ?? ?? ?? ?? 31 D2 49 89 F0 FF 15 ?? ?? ?? ?? 4C 89 B3 ?? ?? ?? ?? 4C 89 BB ?? ?? ?? + ?? 48 8D 05 ?? ?? ?? ?? 48 89 83 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D + 35 ?? ?? ?? ?? 48 89 B3 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? 4C 8D B3 ?? ?? + ?? ?? 4C 89 B3 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? + ?? ?? ?? 48 8D 8B ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 48 8B 05 ?? ?? + ?? ?? 48 83 F8 ?? 0F 85 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 65 48 8B + 14 25 ?? ?? ?? ?? 48 8B 0C CA 48 8D 89 ?? ?? ?? ?? 48 39 C8 75 ?? 8B 05 ?? ?? ?? ?? + FF C0 75 ?? 48 8D 0D ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 + } + $drop_ransom_note = { + 48 8D 05 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 + 89 B4 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 4C 89 B4 24 ?? ?? ?? ?? 48 + C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 48 83 BC 24 ?? ?? ?? ?? ?? 74 ?? 4C 8B 84 24 ?? ?? ?? ?? 48 8B 0D ?? ?? + ?? ?? 31 D2 FF 15 ?? ?? ?? ?? 48 8D B4 24 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 89 + F1 E8 ?? ?? ?? ?? 48 85 C0 4C 8B 74 24 ?? 74 ?? 48 89 C5 4C 8B 6C 24 ?? E9 ?? ?? ?? + ?? 4D 8D 0C D1 49 83 C1 ?? 48 C1 E2 ?? 48 F7 DA 4F 8D 14 C2 49 83 C2 ?? 49 C1 E0 ?? + 49 F7 D8 45 31 DB 4C 39 DA 0F 84 ?? ?? ?? ?? 4D 39 D8 0F 84 ?? ?? ?? ?? 4B 8B 34 19 + 4F 8B 34 1A 4C 39 F6 0F 82 ?? ?? ?? ?? 49 83 C3 ?? 4C 39 F6 76 ?? E9 ?? ?? ?? ?? 48 + 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 BC 24 + ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 4C + 8B 84 24 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? ?? 48 8D 8C 24 ?? + ?? ?? ?? 48 89 DA E8 ?? ?? ?? ?? 4C 8B B4 24 ?? ?? ?? ?? 4C 8B 84 24 ?? ?? ?? ?? 48 + C7 44 24 ?? ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 4C 89 F2 E8 ?? + ?? ?? ?? 48 83 BC 24 ?? ?? ?? ?? ?? 74 ?? 48 8B 0D ?? ?? ?? ?? 31 D2 4D 89 F0 FF 15 + ?? ?? ?? ?? 48 85 ED 74 ?? 48 8B 0D ?? ?? ?? ?? 31 D2 49 89 D8 FF 15 ?? ?? ?? ?? 48 + 8D 9C 24 ?? ?? ?? ?? 48 89 D9 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? + ?? 41 B8 ?? ?? ?? ?? 48 89 D9 E8 ?? ?? ?? ?? 0F 10 00 0F 11 84 24 ?? ?? ?? ?? 48 8B + 8C 24 ?? ?? ?? ?? 48 85 C9 74 + } + $change_desktop_wallpaper = { + 4C 8D 0D ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 DA E8 ?? ?? ?? ?? 48 83 BC 24 ?? + ?? ?? ?? ?? 74 ?? 48 8B 0D ?? ?? ?? ?? 31 D2 49 89 D8 FF 15 ?? ?? ?? ?? 4D 85 F6 74 + ?? 48 8B 0D ?? ?? ?? ?? 31 D2 49 89 F0 FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D + 8C 24 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 25 ?? ?? ?? ?? 48 85 C0 4C + 8B 74 24 ?? 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 41 B8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 80 BC 24 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8B B4 24 ?? ?? + ?? ?? 4C 8B AC 24 ?? ?? ?? ?? 4C 8B 84 24 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 4C + 8D 0D ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 F2 E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? + ?? ?? 4C 8B 84 24 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? ?? 48 8D + 8C 24 ?? ?? ?? ?? 48 89 DA E8 ?? ?? ?? ?? 48 83 BC 24 ?? ?? ?? ?? ?? 74 ?? 48 8B 0D + ?? ?? ?? ?? 31 D2 49 89 D8 FF 15 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 4C 8B B4 24 ?? + ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 DA 4D 89 F0 E8 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? + ?? ?? 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 89 C1 83 E1 ?? 83 F9 ?? 0F 85 ?? ?? + ?? ?? 48 8D 58 ?? 4C 8B 70 ?? 48 8B 68 ?? 4C 89 F1 FF 55 + } + $find_files_p1 = { + 4C 8D 0D ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 DA E8 ?? ?? ?? ?? 48 83 BC 24 ?? + ?? ?? ?? ?? 74 ?? 48 8B 0D ?? ?? ?? ?? 31 D2 49 89 D8 FF 15 ?? ?? ?? ?? 4D 85 FF 74 + ?? 48 8B 0D ?? ?? ?? ?? 31 D2 49 89 F0 FF 15 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? + ?? ?? ?? 66 0F EF C0 F3 0F 7F 84 24 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 8D 94 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 C5 4C 8B 6C 24 ?? 4C 8B + 74 24 ?? E9 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 31 D2 49 89 F0 E8 ?? ?? ?? ?? 48 8B + 84 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 29 E8 48 39 F0 72 ?? 48 8B 8C 24 ?? ?? + ?? ?? 48 01 E9 31 D2 49 89 F0 E8 ?? ?? ?? ?? 48 01 F5 48 89 AC 24 ?? ?? ?? ?? E9 ?? + ?? ?? ?? 48 C1 ED ?? 74 ?? 41 BD ?? ?? ?? ?? E9 ?? ?? ?? ?? 49 83 FF ?? 72 ?? 48 85 + DB 74 ?? 48 8B 84 24 ?? ?? ?? ?? EB ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 EA 49 89 F0 E8 + ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? EB ?? 4C 89 FB 4C 89 F0 4D 85 FF 74 ?? 49 89 DC + 48 8B 44 D8 ?? 48 85 C0 74 ?? 48 0F BD C0 48 83 F0 ?? EB ?? 45 31 E4 EB ?? B8 ?? ?? + ?? ?? 49 C1 E4 ?? 49 83 CC ?? 49 29 C4 49 C1 EC ?? 48 8B B4 24 ?? ?? ?? ?? BA ?? ?? + ?? ?? 48 89 F1 45 31 C0 E8 ?? ?? ?? ?? 48 89 F1 E8 ?? ?? ?? ?? 49 89 C7 49 83 FC + } + $find_files_p2 = { + 73 ?? 48 8B 0D ?? ?? ?? ?? 31 D2 4D 89 F8 FF 15 ?? ?? ?? ?? 41 BD ?? ?? ?? ?? E9 ?? + ?? ?? ?? BA ?? ?? ?? ?? 4C 89 E1 E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 8D 68 + ?? 49 8D 5C 24 ?? 48 8B 8C 24 ?? ?? ?? ?? 48 89 EA 48 89 44 24 ?? E8 ?? ?? ?? ?? 48 + 8B 44 24 ?? F3 41 0F 6F 07 41 0F 10 4F ?? 0F 11 48 ?? F3 0F 7F 40 ?? 49 8D 4C 24 ?? + 48 39 D9 0F 83 ?? ?? ?? ?? 4D 89 E5 4C 8D 60 ?? 49 8D 4D ?? 43 C6 44 2C ?? ?? 48 39 + CB 0F 82 ?? ?? ?? ?? 43 0F 11 74 2C ?? 43 0F 11 7C 2C ?? 48 C7 44 24 ?? ?? ?? ?? ?? + 4C 89 E1 48 89 DA 48 8B B4 24 ?? ?? ?? ?? 49 89 F0 49 89 E9 E8 ?? ?? ?? ?? 48 89 5C + 24 ?? BA ?? ?? ?? ?? 48 89 E9 49 89 F0 4D 89 E1 E8 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? + 31 D2 4D 89 F8 FF 15 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? BA ?? ?? ?? ?? 4C 89 E9 E8 ?? + ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 C3 48 8D B4 24 ?? ?? ?? ?? 48 89 C1 48 8B + 54 24 ?? 4D 89 E8 E8 + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($drop_ransom_note) and ($change_desktop_wallpaper) +} +rule REVERSINGLABS_Win32_Ransomware_Ferrlock : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Ferrlock ransomware." + author = "ReversingLabs" + id = "745ce529-46d0-56ed-a8fa-b41b26b068f4" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Ferrlock.yara#L1-L131" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "b94bc77489dbb74573813631009e605bc848e17995a0a512d08b194ee3020b75" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Ferrlock" + tc_detection_factor = 5 + importance = 25 + + strings: + $search_files_p1 = { + 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 + F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? ?? + ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? FF + 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 5D ?? 8B + CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 EB ?? 8B + 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 FF + 57 57 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 + C5 89 45 ?? 8B 4D ?? 53 8B 5D ?? 57 8B 7D ?? 89 9D ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 + ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8A 11 80 FA + ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 53 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 DB + } + $search_files_p2 = { + 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8A C3 80 FA ?? 75 ?? B0 ?? 0F B6 C0 2B CF 41 F7 D8 56 + 1B C0 23 C1 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? + 83 C4 ?? 8D 85 ?? ?? ?? ?? 53 53 53 50 53 57 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? + ?? 83 FE ?? 75 ?? 50 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 83 FE ?? 74 ?? 56 FF 15 + ?? ?? ?? ?? 8B C3 5E 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 + C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? + 80 F9 ?? 75 ?? 38 9D ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 + 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 + } + $enum_rsrc = { + 6A ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 4D ?? 8B 45 ?? 8D 4D ?? 83 4D ?? ?? 51 50 6A + ?? 6A ?? 6A ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 + ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? EB ?? 33 DB 39 5D ?? 7E ?? + 8D 7E ?? F7 47 ?? ?? ?? ?? ?? 74 ?? 8D 47 ?? 89 45 ?? 8B 45 ?? 8B 00 8B 48 ?? 85 C9 + 74 ?? 8B 01 8D 55 ?? 52 FF 50 ?? EB ?? FF 37 8D 4D ?? E8 ?? ?? ?? ?? 83 65 ?? ?? 8D + 45 ?? 50 8B 45 ?? 8B 48 ?? E8 ?? ?? ?? ?? 83 4D ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 43 83 + C7 ?? 3B 5D ?? 7C ?? 83 4D ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 56 8D 45 ?? 50 FF + 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 + ?? ?? ?? ?? E8 ?? ?? ?? ?? C2 ?? ?? E8 ?? ?? ?? ?? CC 55 8B EC 6A ?? 68 ?? ?? ?? ?? + 64 A1 ?? ?? ?? ?? 50 56 A1 ?? ?? ?? ?? 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 83 + 65 ?? ?? 8B 4E ?? 85 C9 74 ?? 8B 11 3B CE 0F 95 C0 0F B6 C0 50 FF 52 ?? 83 66 ?? ?? + 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 8B E5 5D C3 + } + $create_test_file_p1 = { + 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 33 DB 8D 55 + ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 5D ?? E8 ?? ?? ?? ?? 59 8D 45 ?? C6 45 ?? ?? + 50 8D 4D ?? 89 5D ?? 89 5D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 + ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 83 CB ?? 8B 3D ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 65 ?? ?? + 8D 4D ?? 83 65 ?? ?? 56 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? FF 75 ?? 8B 45 ?? 2B 45 + ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 8B 55 ?? 8D 4D ?? 0F 43 45 ?? + 83 7D ?? ?? 0F 43 4D ?? 3B 55 ?? 75 ?? 52 50 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 85 ?? ?? + ?? ?? ?? 85 C0 74 ?? C6 85 ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? + ?? 8D 4D ?? 0F 85 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 C6 ?? 3B F7 0F 85 ?? ?? + ?? ?? 83 7D ?? ?? 8D 45 ?? 8B 35 ?? ?? ?? ?? BF ?? ?? ?? ?? 0F 43 45 ?? 33 C9 51 57 + } + $create_test_file_p2 = { + 6A ?? 51 51 68 ?? ?? ?? ?? 50 FF D6 3B C3 0F 84 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 + 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? + 33 C9 51 57 6A ?? 51 51 68 ?? ?? ?? ?? 50 FF D6 8B F8 3B FB 0F 84 ?? ?? ?? ?? 6A ?? + 57 FF 15 ?? ?? ?? ?? 8B F0 85 F6 75 ?? 57 FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? + ?? ?? E9 ?? ?? ?? ?? 6A ?? 58 3B F0 0F 42 F0 03 F0 56 E8 ?? ?? ?? ?? 59 6A ?? 89 85 + ?? ?? ?? ?? 8D 45 ?? 50 56 8B B5 ?? ?? ?? ?? 56 57 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 75 + ?? 57 FF 15 ?? ?? ?? ?? EB ?? 83 7D ?? ?? 8D 45 ?? FF 75 ?? 0F 43 45 ?? 8D 55 ?? 50 + 8B CE E8 ?? ?? ?? ?? 59 59 33 DB 53 53 53 57 FF 15 ?? ?? ?? ?? 53 8D 45 ?? 50 FF 75 + ?? 56 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 8D 4D ?? 8D 45 ?? 0F 43 + 4D ?? 83 7D ?? ?? 51 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 8D 4D ?? + E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C3 E8 ?? + ?? ?? ?? C3 + } + $encrypt_files_p1 = { + 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 33 F6 8D 4D ?? 89 B5 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 75 ?? 8D 4D ?? 68 ?? ?? ?? ?? 89 75 ?? 89 75 ?? E8 ?? + ?? ?? ?? 68 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 7D ?? 8B D8 8B 45 + ?? 0F 43 7D ?? 59 3B D8 77 ?? 85 DB 74 ?? 2B C3 40 03 C7 89 85 ?? ?? ?? ?? 2B C7 50 + 6A ?? 57 EB ?? 53 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 85 ?? ?? + ?? ?? 46 2B C6 50 6A ?? 56 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 75 ?? EB ?? 2B F7 EB + ?? 83 CE ?? 83 FE ?? 74 ?? 83 7D ?? ?? 8D 45 ?? FF 75 ?? 0F 43 45 ?? 50 51 56 8D 4D + ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 33 F6 8D 85 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 + } + $encrypt_files_p2 = { + 50 E8 ?? ?? ?? ?? 6A ?? 5F 89 7D ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? + ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 51 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? C6 45 ?? ?? 8B C8 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 51 0F 43 85 + ?? ?? ?? ?? 51 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 39 B5 ?? ?? ?? ?? 74 ?? 83 7D ?? ?? 8D + 55 ?? FF 75 ?? 0F 43 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 56 8B 40 ?? 03 C8 8B 51 + ?? 83 CA ?? 8B C2 0B C7 39 71 ?? 0F 44 D0 52 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 59 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + } + + condition: + uint16(0)==0x5A4D and ($enum_rsrc) and ( all of ($search_files_p*)) and ( all of ($create_test_file_p*)) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_5Ss5C : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects 5ss5c ransomware." + author = "ReversingLabs" + id = "c69f44de-8e48-518d-87bf-d21d11223a2f" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.5ss5c.yara#L1-L267" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "74fcec568906a01dade7091c63cffbe4afa49c4705d9c1f21d10b4eee655a805" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "5ss5c" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B FA 89 BD ?? ?? ?? ?? 8B F1 + 8B 5D ?? 33 C0 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 45 ?? 89 45 ?? 6A ?? 89 45 ?? + 89 45 ?? 89 45 ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 4D ?? 83 C4 ?? C7 00 ?? ?? ?? ?? C7 40 + ?? ?? ?? ?? ?? 8B 45 ?? 89 08 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? + 57 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 4D + ?? C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8B 45 ?? 89 08 C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? C6 45 ?? ?? C6 45 ?? ?? 6A ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 4D ?? C7 00 ?? ?? ?? ?? C7 40 ?? + ?? ?? ?? ?? 8B 45 ?? 89 08 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? C6 + 45 ?? ?? 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 83 C4 ?? C7 + 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 08 C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 0F 57 C0 8B 43 ?? 66 0F D6 + } + $find_files_p2 = { + 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 89 45 ?? C6 45 + ?? ?? 8B 3B 85 FF 74 ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? 8B 47 ?? 8D 8D ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 89 47 ?? 89 7D ?? E8 ?? ?? ?? ?? 6A + ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 3B + C8 74 ?? 83 78 ?? ?? 8D 48 ?? 72 ?? 8B 09 FF 70 ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 51 + 50 FF 15 ?? ?? ?? ?? 8B C8 89 8D ?? ?? ?? ?? 83 F9 ?? 0F 84 ?? ?? ?? ?? 8B D8 66 66 + 0F 1F 84 00 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? + 8B 8D ?? ?? ?? ?? 0F 43 45 ?? C7 45 ?? ?? ?? ?? ?? C6 00 ?? 8D 41 ?? 83 79 ?? ?? 72 + ?? 8B 00 FF 71 ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? + ?? 8D 8D ?? ?? ?? ?? 8B D0 8D 79 ?? 8A 01 41 84 C0 75 ?? 2B CF 8D 85 ?? ?? ?? ?? 51 + 50 8B CA E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 F6 85 ?? + ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 33 FF FF B7 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 + C0 0F 85 ?? ?? ?? ?? 83 C7 ?? 81 FF ?? ?? ?? ?? 72 ?? 68 ?? ?? ?? ?? 50 8D 85 ?? ?? + ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? + ?? ?? ?? 8B 9D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 83 CB ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 50 89 9D ?? ?? ?? ?? 89 5D ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 + } + $find_files_p3 = { + 45 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 6A ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? + 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? + ?? ?? 51 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 85 C0 75 + ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 8B 40 ?? 03 C8 33 C0 39 41 ?? 0F 94 C0 + 8D 04 85 ?? ?? ?? ?? 0B 41 ?? 50 E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 55 ?? 83 7D ?? ?? 8D + 8D ?? ?? ?? ?? FF 75 ?? 0F 43 55 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 8B + 40 ?? 03 C8 33 C0 39 41 ?? 0F 94 C0 8D 04 85 ?? ?? ?? ?? 0B 41 ?? 50 E8 ?? ?? ?? ?? + 8B 5D ?? 8D 55 ?? 53 FF B5 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 8B 85 ?? + ?? ?? ?? 8B 40 ?? 85 FF 0F 85 ?? ?? ?? ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? + 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 51 + ?? 0F 1F 80 ?? ?? ?? ?? 8A 01 41 84 C0 75 ?? 2B CA 8D 85 ?? ?? ?? ?? 51 50 8D 4D + } + $find_files_p4 = { + E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 8D 85 ?? ?? ?? + ?? 51 50 8D 4D ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 83 7D ?? ?? 8B FC 0F 43 45 ?? C7 + 07 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D ?? 85 DB 74 ?? 6A ?? + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? 8D 8D ?? ?? ?? ?? 89 + 47 ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 83 EC ?? 83 7D ?? ?? 8B FC 0F + 43 4D ?? 03 C1 C7 07 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D ?? + 85 DB 74 ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? 8D + 8D ?? ?? ?? ?? 89 47 ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 83 7D ?? ?? + 8B FC 0F 43 45 ?? C7 07 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D + ?? 85 DB 74 ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? + 8D 8D ?? ?? ?? ?? 89 47 ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? BA ?? ?? ?? ?? C6 45 + } + $find_files_p5 = { + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? + ?? 8D 55 ?? 83 7D ?? ?? 8B 4D ?? 0F 43 55 ?? C7 45 ?? ?? ?? ?? ?? 89 4D ?? 83 F9 ?? + 72 ?? 49 83 C8 ?? 3B C8 89 4D ?? 0F 42 C1 03 C2 0F 1F 40 ?? 80 38 ?? 75 ?? 0F B6 08 + 80 F9 ?? 75 ?? 33 C9 EB ?? 1B C9 83 C9 ?? 85 C9 74 ?? 3B C2 74 ?? 48 EB ?? 2B C2 EB + ?? 83 C8 ?? 6A ?? 8D 78 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? + ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + 83 C4 ?? C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 08 C6 45 ?? ?? + 8B 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? + ?? ?? 3B C7 0F 82 ?? ?? ?? ?? 2B C7 C7 45 ?? ?? ?? ?? ?? 83 C9 ?? 89 45 ?? 83 F8 ?? + 0F 42 C8 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 51 03 C7 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 83 8D ?? ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? FF B5 ?? ?? ?? ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + } + $find_files_p6 = { + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 83 7D ?? ?? 8B FC 0F 43 45 ?? C7 07 + ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D ?? 85 DB 74 ?? 6A ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? 8D 8D ?? ?? ?? ?? 89 47 + ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? 8B 45 ?? 8D 4D ?? 83 EC ?? 83 7D ?? ?? 8B FC 0F 43 + 4D ?? 03 C1 C7 07 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D ?? 85 + DB 74 ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? 8D 8D + ?? ?? ?? ?? 89 47 ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 83 7D ?? ?? 8B + FC 0F 43 45 ?? C7 07 ?? ?? ?? ?? C7 47 ?? ?? ?? ?? ?? 89 47 ?? C6 45 ?? ?? 8B 5D ?? + 85 DB 74 ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B CF E8 ?? ?? ?? ?? 8B 43 ?? 8D + 8D ?? ?? ?? ?? 89 47 ?? 89 7B ?? 89 1F E8 ?? ?? ?? ?? BA ?? ?? ?? ?? C6 45 ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? + 33 FF 66 66 0F 1F 84 00 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? FF B7 ?? ?? ?? ?? 0F 43 45 + ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? + ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 83 C7 ?? 83 FF + ?? 72 ?? 8B 5D ?? 85 DB 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? + ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 46 ?? 8D 4D ?? 51 39 46 ?? 74 ?? 8B C8 E8 ?? ?? ?? + ?? 8B 7E ?? 8D 8D ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B 0E 8D 41 ?? F7 D9 1B C9 23 C8 + } + $find_files_p7 = { + 74 ?? 8B 01 85 C0 74 ?? 39 78 ?? 72 ?? 77 ?? C7 00 ?? ?? ?? ?? 8B 01 8B 40 ?? 89 01 + EB ?? 8D 48 ?? 8B 01 85 C0 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 46 ?? ?? EB ?? + 50 8B CE E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + 85 C0 75 ?? 8B 46 ?? 8D 4D ?? 51 39 46 ?? 74 ?? 8B C8 E8 ?? ?? ?? ?? 8B 7E ?? 8D 8D + ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B 0E 8D 41 ?? F7 D9 1B C9 23 C8 74 ?? 8B 01 85 C0 + 74 ?? 66 0F 1F 44 00 ?? 39 78 ?? 72 ?? 77 ?? C7 00 ?? ?? ?? ?? 8B 01 8B 40 ?? 89 01 + EB ?? 8D 48 ?? 8B 01 85 C0 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 46 ?? ?? EB ?? + 50 8B CE E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? 83 8D ?? ?? ?? ?? ?? 8B D8 8B 7D ?? 85 FF 74 ?? 8B 3F 8B CB E8 ?? ?? ?? ?? 3B + } + $find_files_p8 = { + C7 74 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? E8 + ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? CC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 43 ?? 3B 45 ?? 74 ?? 8D 85 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B3 ?? EB ?? 32 DB 8B 85 ?? + ?? ?? ?? A8 ?? 74 ?? 83 E0 ?? 89 85 ?? ?? ?? ?? 6A ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? + ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 84 DB 0F + 84 ?? ?? ?? ?? 8B 46 ?? 8D 4D ?? 51 39 46 ?? 0F 84 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? + 8B 7E ?? 8D 8D ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B 0E 8D 41 ?? F7 D9 1B C9 23 C8 74 + ?? 8B 01 85 C0 74 ?? 90 39 78 ?? 72 ?? 77 ?? C7 00 ?? ?? ?? ?? 8B 01 8B 40 ?? 89 01 + EB ?? 8D 48 ?? 8B 01 85 C0 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 46 ?? ?? E9 ?? + ?? ?? ?? 83 FB ?? 0F 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 83 8D ?? ?? ?? ?? ?? 8B D8 8B 7D ?? 85 FF 74 ?? 8B 3F 8B CB E8 ?? + ?? ?? ?? 3B C7 74 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? CC 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 43 ?? 3B 45 ?? 75 ?? 8D + } + $find_files_p9 = { + 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B3 ?? EB ?? 32 + DB 8B 85 ?? ?? ?? ?? A8 ?? 74 ?? 83 E0 ?? 89 85 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? + C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? C6 45 ?? ?? 84 DB 0F 84 ?? ?? ?? ?? 8B 46 ?? 8D 4D ?? 51 39 46 ?? 0F 84 ?? + ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 8B 7E ?? 8D 4D ?? 6A ?? E8 ?? ?? ?? ?? 8B 0E 8D 41 ?? + F7 D9 1B C9 23 C8 74 ?? 8B 01 85 C0 74 ?? 39 78 ?? 72 ?? 77 ?? C7 00 ?? ?? ?? ?? 8B + 01 8B 40 ?? 89 01 EB ?? 8D 48 ?? 8B 01 85 C0 75 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 46 ?? + ?? E9 ?? ?? ?? ?? 83 FB ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 46 ?? 8D 4D ?? 51 39 46 ?? 74 ?? 8B C8 E8 ?? ?? + ?? ?? 8B 7E ?? 8D 4D ?? 6A ?? E8 ?? ?? ?? ?? 8B 0E 8D 41 ?? F7 D9 1B C9 23 C8 74 ?? + 8B 01 85 C0 74 ?? 66 0F 1F 44 00 ?? 39 78 ?? 72 ?? 77 ?? C7 00 ?? ?? ?? ?? 8B 01 8B + } + $find_files_p10 = { + 40 ?? 89 01 EB ?? 8D 48 ?? 8B 01 85 C0 75 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 46 ?? ?? EB + ?? 50 8B CE E8 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? + ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? + 75 ?? 33 FF 6A ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F + 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B + 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? E8 + } + $encrypt_files_p1 = { + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C4 89 44 24 ?? 55 8B 6C 24 ?? 56 8B + 74 24 ?? 57 8B 7C 24 ?? 85 F6 0F 8E ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? + 83 C4 ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 57 E8 + ?? ?? ?? ?? 83 C4 ?? 89 44 24 ?? 85 C0 75 ?? A1 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? ?? + ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 83 C8 ?? 5F 5E 5D 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C3 8B 4C 24 ?? 8B C1 + 83 E8 ?? 74 ?? 51 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? + 83 C4 ?? 85 C0 75 ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A + ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 + ?? 83 C8 ?? 5F 5E 5D 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C3 68 ?? ?? ?? ?? 68 + ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? A1 ?? ?? ?? ?? 85 C0 75 + } + $encrypt_files_p2 = { + E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 50 E8 ?? ?? + ?? ?? 83 C4 ?? 83 C8 ?? 5F 5E 5D 8B 4C 24 ?? 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C3 33 C9 + 85 F6 7E ?? 8D 56 ?? 53 8B 5C 24 ?? 03 D7 66 0F 1F 44 00 ?? 8A 04 19 8D 52 ?? 41 88 + 42 ?? 3B CE 7C ?? 5B 8D 44 24 ?? 89 74 24 ?? 50 8B 44 24 ?? 57 6A ?? 6A ?? 6A ?? FF + 70 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? + ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 + C4 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 44 + 24 ?? 50 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? FF 74 24 ?? 57 E8 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 83 C8 ?? 5F 5E 5D 8B 4C 24 ?? 33 CC + E8 ?? ?? ?? ?? 83 C4 ?? C3 8B 74 24 ?? 56 57 55 E8 ?? ?? ?? ?? 56 57 E8 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4C 24 ?? 8B C6 5F 5E 5D + 33 CC E8 ?? ?? ?? ?? 83 C4 ?? C3 + } + $remote_connection_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 6A ?? E8 ?? + ?? ?? ?? FF 35 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? + E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8B D8 FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 83 + C4 ?? 49 90 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? BA ?? ?? ?? ?? 83 3D ?? ?? + ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 0F 43 15 ?? ?? ?? ?? 89 41 ?? 8B F2 A1 ?? ?? ?? ?? 89 + 41 ?? A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 ?? 8A 02 42 84 C0 75 ?? 8D BD ?? + ?? ?? ?? 2B D6 4F 8A 47 ?? 47 84 C0 75 ?? 8B CA C1 E9 ?? F3 A5 8B CA 83 E1 ?? F3 A4 + 8D 8D ?? ?? ?? ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? + 8B F2 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? 66 90 8A 02 42 84 + C0 75 ?? 8D BD ?? ?? ?? ?? 2B D6 4F 8A 47 ?? 47 84 C0 75 ?? 8B CA C1 E9 ?? F3 A5 8B + CA 83 E1 ?? F3 A4 8D 8D ?? ?? ?? ?? 49 0F 1F 00 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? + ?? ?? ?? 8B F3 89 01 66 A1 ?? ?? ?? ?? 66 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? 8A 03 43 + 84 C0 75 ?? 8D BD ?? ?? ?? ?? 2B DE 4F 8A 47 ?? 47 84 C0 75 ?? 8B CB C1 E9 ?? F3 A5 + 8B CB 83 E1 ?? F3 A4 8D 8D ?? ?? ?? ?? 49 8A 41 ?? 8D 49 ?? 84 C0 75 ?? A1 ?? ?? ?? + ?? 8B 95 ?? ?? ?? ?? 8B F2 89 01 A1 ?? ?? ?? ?? 89 41 ?? A0 ?? ?? ?? ?? 88 41 ?? 0F + } + $remote_connection_p2 = { + 1F 44 00 ?? 8A 02 42 84 C0 75 ?? 8D BD ?? ?? ?? ?? 2B D6 4F 8A 47 ?? 47 84 C0 75 ?? + 8B CA C1 E9 ?? F3 A5 8B CA 83 E1 ?? F3 A4 8D 8D ?? ?? ?? ?? 49 0F 1F 00 8A 41 ?? 8D + 49 ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 89 01 A1 ?? ?? ?? ?? 89 41 ?? A1 ?? ?? ?? ?? 89 41 + ?? A0 ?? ?? ?? ?? 6A ?? 88 41 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? 83 C4 ?? C7 00 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 08 C7 45 + ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 51 ?? C7 85 ?? ?? + ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 0F 1F 00 8A 01 41 84 C0 75 ?? 2B CA 8D 85 ?? + ?? ?? ?? 51 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? + ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? + 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8B D8 85 + DB 74 ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B F0 85 F6 + 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 56 + FF 15 ?? ?? ?? ?? 56 FF D7 53 FF D7 FF B5 ?? ?? ?? ?? FF D7 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B + 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Ouroboros : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Ouroboros ransomware." + author = "ReversingLabs" + id = "af0b9311-a7dd-56e8-a004-0828af5af5ef" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Ouroboros.yara#L1-L175" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "b573f303318452010ff46f21a02b6290820f9a27bf4c51b72f6ed15263b5f433" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Ouroboros" + tc_detection_factor = 5 + importance = 25 + + strings: + $remote_connection_p1 = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? + 33 C5 89 45 ?? 56 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B 75 ?? 8D 8D ?? ?? ?? ?? 6A ?? 68 + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? + ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 8D 8D ?? ?? + ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? + 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? + ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 + } + $remote_connection_p2 = { + C6 45 ?? ?? 50 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? + C6 45 ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 + ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8B + 95 ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? + ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? + ?? ?? 83 C4 ?? FF 75 ?? 8D 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 75 ?? 8D 8D ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 8D 45 ?? C6 85 ?? ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? 50 8B CE C7 06 ?? ?? ?? ?? C6 46 ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 83 FA ?? + 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 + } + $remote_connection_p3 = { + F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? + C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? FF 70 ?? 8D 45 ?? 50 8B C8 E8 ?? ?? ?? ?? 6A ?? FF + 75 ?? E8 ?? ?? ?? ?? 8B 55 ?? 83 C4 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? + ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? + ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 + FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 + ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? + ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? FF 70 ?? 8D 45 ?? 50 8B C8 E8 ?? ?? ?? ?? 6A + ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 C4 ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? + ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 + ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 85 C9 74 ?? 8B 95 ?? ?? ?? + ?? 8B C1 2B D1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F + 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 C4 ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B C6 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $remote_connection_p4 = { + 8B 55 ?? C7 06 ?? ?? ?? ?? C6 46 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? + ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? + ?? ?? ?? 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? FF + 70 ?? 8D 45 ?? 50 8B C8 E8 ?? ?? ?? ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 55 ?? 83 C4 + ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 + 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? + ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA + ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 + E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? + ?? FF 70 ?? 8D 45 ?? 50 8B C8 E8 ?? ?? ?? ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 95 ?? + ?? ?? ?? 83 C4 ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? + 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 8D + ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? + ?? ?? ?? 85 C9 0F 84 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C1 2B D1 81 FA ?? ?? ?? ?? 0F + 82 ?? ?? ?? ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 86 ?? ?? ?? ?? E8 ?? ?? + ?? ?? E8 ?? ?? ?? ?? E8 + } + $find_files = { + 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 83 C8 ?? 57 8B 7D ?? + 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? + ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? + FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 4D ?? + 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 C0 50 + 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 + 89 45 ?? 8B 4D ?? 53 8B 5D ?? 56 8B 75 ?? 57 89 B5 ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 + ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 53 E8 ?? ?? ?? ?? 59 59 8B C8 3B CB 75 ?? 8A 11 80 FA + ?? 75 ?? 8D 43 ?? 3B C8 74 ?? 56 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 FF + 80 FA ?? 74 ?? 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8B C7 EB ?? 33 C0 40 0F B6 C0 2B CB 41 + F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? + ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 + FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? + 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 + 74 ?? 80 F9 ?? 75 ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? + ?? 85 C0 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B + C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 + ?? E9 + } + $encrypt_files_p1 = { + 83 EC ?? 8B 44 24 ?? 53 55 56 8B F1 89 44 24 ?? 57 8B 7C 24 ?? 8B 6E ?? 3B FD 77 ?? + 8B DE 83 FD ?? 72 ?? 8B 1E 57 50 53 89 7E ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 04 1F ?? 8B + C6 5F 5E 5D 5B 83 C4 ?? C2 ?? ?? 81 FF ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 8B DF 83 CB ?? + 81 FB ?? ?? ?? ?? 76 ?? BB ?? ?? ?? ?? EB ?? 8B CD B8 ?? ?? ?? ?? D1 E9 2B C1 3B E8 + 76 ?? BB ?? ?? ?? ?? EB ?? 8D 04 29 3B D8 0F 42 D8 33 C9 8B C3 83 C0 ?? 0F 92 C1 F7 + D9 0B C8 51 8B CE E8 ?? ?? ?? ?? 57 FF 74 24 ?? 89 44 24 ?? 50 89 7E ?? 89 5E ?? E8 + ?? ?? ?? ?? 8B 5C 24 ?? 83 C4 ?? C6 04 1F ?? 83 FD ?? 72 ?? 8B 06 45 81 FD ?? ?? ?? + ?? 72 ?? 8B 48 ?? 83 C5 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 8B C1 55 50 E8 ?? ?? ?? ?? + 83 C4 ?? 5F 89 1E 8B C6 5E 5D 5B 83 C4 ?? C2 ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? CC + CC CC CC CC 83 EC ?? 53 55 8B 6C 24 ?? 56 57 8B F9 8B 4C 24 ?? 89 4C 24 ?? 8B 5F ?? + 3B EB 77 ?? 89 7C 24 ?? 8B C7 83 FB ?? 72 ?? 8B 07 89 44 24 ?? 8D 34 6D + } + $encrypt_files_p2 = { + 89 6F ?? 56 51 50 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 33 C9 66 89 0C 06 8B C7 5F 5E + 5D 5B 83 C4 ?? C2 ?? ?? 81 FD ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 8B F5 83 CE ?? 81 FE ?? + ?? ?? ?? 76 ?? BE ?? ?? ?? ?? EB ?? 8B CB B8 ?? ?? ?? ?? D1 E9 2B C1 3B D8 76 ?? BE + ?? ?? ?? ?? EB ?? 8D 04 19 3B F0 0F 42 F0 33 C9 8B C6 83 C0 ?? 0F 92 C1 F7 D9 0B C8 + 51 8B CF E8 ?? ?? ?? ?? 89 77 ?? 8D 34 6D ?? ?? ?? ?? 56 FF 74 24 ?? 89 44 24 ?? 50 + 89 6F ?? E8 ?? ?? ?? ?? 8B 6C 24 ?? 33 C0 83 C4 ?? 66 89 04 2E 83 FB ?? 72 ?? 8B 07 + 8D 1C 5D ?? ?? ?? ?? 81 FB ?? ?? ?? ?? 72 ?? 8B 48 ?? 83 C3 ?? 2B C1 83 C0 ?? 83 F8 + ?? 77 ?? 8B C1 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 2F 8B C7 5F 5E 5D 5B 83 C4 ?? C2 ?? + ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? CC 8B 44 24 ?? 83 EC ?? 83 E0 ?? 89 41 ?? 8B 49 ?? + 23 C8 75 ?? 83 C4 ?? C2 ?? ?? 56 F6 C1 ?? 74 ?? BE ?? ?? ?? ?? EB ?? F6 C1 ?? BE ?? + ?? ?? ?? B8 ?? ?? ?? ?? 0F 44 F0 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4C + 24 ?? 50 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 E8 ?? ?? ?? ?? 5E + } + $encrypt_files_angus_version = { + 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 85 + ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 03 C1 83 BD ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 0F 43 + 8D ?? ?? ?? ?? 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? + ?? ?? ?? B9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 39 8D ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? C6 85 ?? ?? ?? ?? ?? 0F 42 8D ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 51 0F 43 85 ?? + ?? ?? ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? + ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? + ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 + ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? + ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? E8 + } + + condition: + uint16(0)==0x5A4D and ($find_files) and (( all of ($encrypt_files_p*)) or ($encrypt_files_angus_version)) and ( all of ($remote_connection_p*)) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Wormlocker : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects WormLocker ransomware." + author = "ReversingLabs" + id = "6d7b55b7-2e1b-56e0-950f-07a2d3fa17ae" + date = "2021-08-12" + modified = "2021-08-12" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.WormLocker.yara#L1-L69" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "87a4f805de78d7e7dffb176302407453108ca01552c682aeee38f8d0201263c9" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "WormLocker" + tc_detection_factor = 5 + importance = 25 + + strings: + $set_environment = { + 73 ?? ?? ?? ?? 0A 06 02 7D ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 0B 72 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 0C 08 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 02 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 73 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? + ?? ?? ?? 72 ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 00 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 00 09 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 00 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 7B ?? ?? + ?? ?? 6F ?? ?? ?? ?? 00 06 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 20 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 00 13 ?? 11 ?? 06 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 + 11 ?? 17 6F ?? ?? ?? ?? 00 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 2A + } + $find_files = { + 00 28 ?? ?? ?? ?? 00 16 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 0C 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 28 ?? ?? ?? + ?? 0D 08 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 13 ?? 73 ?? ?? + ?? ?? 13 ?? 72 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 00 11 ?? 09 11 ?? 9A 11 ?? 6F ?? ?? ?? + ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 09 8E 69 FE 04 13 ?? 11 ?? 2D ?? 16 13 ?? 2B ?? 00 11 + ?? 11 ?? 11 ?? 9A 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 FE 04 + 13 ?? 11 ?? 2D ?? 2A + } + $encrypt_files_p1 = { + 00 14 0A 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? 0C 00 73 + ?? ?? ?? ?? 0D 00 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 00 03 07 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? + ?? ?? 6F ?? ?? ?? ?? 00 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? + 00 09 17 6F ?? ?? ?? ?? 00 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 00 11 ?? 02 16 + 02 8E 69 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? + ?? ?? 00 DC 08 6F ?? ?? ?? ?? 0A 00 DE ?? 09 2C ?? 09 6F ?? ?? ?? ?? 00 DC 00 DE ?? 08 + 2C ?? 08 6F ?? ?? ?? ?? 00 DC 06 13 ?? 2B ?? 11 ?? 2A + } + $encrypt_files_p2 = { + 00 03 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? 0B 28 ?? ?? ?? ?? 07 6F ?? ?? + ?? ?? 0B 06 07 28 ?? ?? ?? ?? 0C 03 0D 09 08 28 ?? ?? ?? ?? 00 2A + } + + condition: + uint16(0)==0x5A4D and ($set_environment) and ($find_files) and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Fantom : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Fantom ransomware." + author = "ReversingLabs" + id = "cd32de8b-2c14-5fb4-be79-365d9848f341" + date = "2021-08-12" + modified = "2021-08-12" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Fantom.yara#L1-L97" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "f2aaa9776b7ca302052b3303d45df24cc151a4efc7ea9f4bb3c1f53d10ded03a" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Fantom" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_1 = { + 00 72 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? + 26 DE ?? 26 DE ?? 02 28 ?? ?? ?? ?? 13 ?? 02 28 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 02 28 + ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? [1-2] 02 72 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 [1-2] 20 + ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 6F + ?? ?? ?? ?? 13 ?? 02 11 ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 02 7B ?? ?? ?? ?? 02 7B + ?? ?? ?? ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 8D ?? ?? + ?? ?? 13 ?? 11 ?? 16 + } + $encrypt_files_2 = { + 72 ?? ?? ?? ?? A2 11 ?? 17 72 ?? ?? ?? ?? A2 11 ?? 18 72 ?? ?? ?? ?? A2 11 ?? + 19 72 ?? ?? ?? ?? A2 11 ?? 1A 72 ?? ?? ?? ?? A2 11 ?? 1B 72 ?? ?? ?? ?? A2 11 + ?? 1C 72 ?? ?? ?? ?? A2 11 ?? 1D 72 ?? ?? ?? ?? A2 11 ?? 1E 72 ?? ?? ?? ?? A2 + 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? + ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? + 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? + ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? + 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 + 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? + ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? + 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? + ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? + 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 + 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? + ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? + 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? + ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? + 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 + 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? + ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? + 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? + ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? + 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 + 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? + ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 11 + } + $lockfile = { + 02 7B ?? ?? ?? ?? 16 FE ?? 3A ?? ?? ?? ?? 21 EA 17 ?? ?? ?? ?? ?? ?? ?? + 03 73 ?? ?? ?? ?? [2-4] 6F ?? ?? ?? ?? [2-4] 21 00 65 CD 1D + 00 00 00 00 FE ?? 16 FE ?? 2D ?? [2-4] FE ?? 16 FE ?? 2D ?? 03 28 + ?? ?? ?? ?? ?? 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? [1-2] 28 ?? ?? ?? ?? [1-2] + 6F ?? ?? ?? ?? [1-2] 02 ?? [1-2] 28 ?? ?? ?? ?? [1-2] 03 [1-2] 28 ?? ?? + ?? ?? 03 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? [1-2] ?? FE ?? + 16 FE ?? 2D ?? 2B ?? 03 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 2B ?? 03 28 ?? ?? ?? ?? ?? 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? [1-2] 28 ?? + ?? ?? ?? [1-2] 6F ?? ?? ?? ?? [1-2] 02 ?? [1-2] 28 ?? ?? ?? ?? [1-2] 03 + [1-2] 28 ?? ?? ?? ?? 03 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 2A + } + $lockdir = { + 03 28 ?? ?? ?? ?? 0A 03 28 ?? ?? ?? ?? 0B 16 0C 08 06 8E 69 FE ?? 2C ?? + 00 06 08 9A 28 ?? ?? ?? ?? 0D 05 09 28 ?? ?? ?? ?? 16 FE ?? 2D ?? 02 25 + 7B ?? ?? ?? ?? 17 58 7D ?? ?? ?? ?? 02 06 08 9A 04 28 ?? ?? ?? ?? DE ?? + 26 DE ?? 26 DE ?? 08 17 58 0C 2B ?? 16 0C 08 07 8E 69 FE ?? 2C ?? 00 02 + 07 08 9A 04 05 28 ?? ?? ?? ?? 02 07 08 9A 04 28 ?? ?? ?? ?? DE ?? 26 DE + ?? 26 DE ?? 08 17 58 0C 2B ?? 2A + } + $sendkey = { + 00 02 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 73 ?? ?? ?? ?? + 0C 08 72 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 08 72 ?? ?? ?? ?? + 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 08 72 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F + ?? ?? ?? ?? 08 72 ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 07 03 72 ?? ?? ?? ?? 08 + 6F ?? ?? ?? ?? 26 07 6F ?? ?? ?? ?? DE ?? 26 DE ?? 2A + } + + condition: + uint16(0)==0x5A4D and (( all of ($encrypt_files_*)) and $lockfile and $lockdir and $sendkey) +} +rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Venom : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Venom ransomware." + author = "ReversingLabs" + id = "72149ec2-888e-5bed-baf1-0ec44e48328e" + date = "2022-06-06" + modified = "2022-06-06" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/ByteCode.MSIL.Ransomware.Venom.yara#L1-L68" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "5817ece6a1cc304835f7fc243c4cfdc3c7cacd2251a9ac294a6662b58d2552e8" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Venom" + tc_detection_factor = 5 + importance = 25 + + strings: + $setup_env = { + 00 28 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 07 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 1B + 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 1F ?? 28 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 07 6F ?? ?? + ?? ?? 13 ?? 2B ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 00 06 11 ?? 28 ?? ?? ?? ?? 00 00 12 ?? 28 + ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 72 ?? ?? ?? ?? 1F + ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 1F ?? + 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 1F ?? 28 ?? ?? ?? ?? 72 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 72 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 0C 72 ?? ?? ?? ?? 20 ?? ?? ?? ?? 19 7E ?? ?? ?? ?? 19 16 7E ?? ?? ?? + ?? 28 ?? ?? ?? ?? 0D 09 08 20 ?? ?? ?? ?? 12 ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 17 28 + ?? ?? ?? ?? 00 2A + } + $find_files = { + 00 00 00 03 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 06 07 9A 0C 00 00 08 72 ?? ?? ?? ?? 6F ?? ?? + ?? ?? 16 FE 01 0D 09 2C ?? 00 08 02 28 ?? ?? ?? ?? 00 00 00 DE ?? 26 00 00 DE ?? 00 07 + 17 58 0B 07 06 8E 69 32 ?? 00 03 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 13 + ?? 00 11 ?? 02 28 ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? 00 DE ?? + 26 00 00 DE ?? 2A + } + $encrypt_files = { + 00 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 03 6F ?? ?? ?? ?? 0B 02 72 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 18 73 ?? ?? ?? ?? 0C 73 ?? ?? ?? ?? 0D 09 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 20 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 00 09 18 6F ?? ?? ?? ?? 00 07 06 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? + 13 ?? 09 11 ?? 09 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 11 ?? 09 6F + ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 09 17 6F ?? ?? ?? ?? 00 08 06 16 06 + 8E 69 6F ?? ?? ?? ?? 00 08 09 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 02 19 73 ?? ?? ?? + ?? 13 ?? 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? 13 ?? 00 2B ?? 00 11 ?? 11 ?? 16 11 ?? 6F ?? ?? + ?? ?? 00 00 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 25 13 ?? 16 FE 02 13 ?? 11 ?? 2D + ?? 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 + DE ?? DE ?? 00 11 ?? 6F ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? 00 00 02 28 ?? ?? ?? ?? 00 00 + DE ?? 26 00 00 DE ?? 00 DC 2A + } + + condition: + uint16(0)==0x5A4D and ($setup_env) and ($find_files) and ($encrypt_files) +} +rule REVERSINGLABS_Win64_Ransomware_Ako : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Ako ransomware." + author = "ReversingLabs" + id = "fce98a6a-f7bd-52ee-a2b8-31b48f6134ca" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win64.Ransomware.Ako.yara#L1-L173" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "8321a4ace66ae48e3a6896daf02c184fa7767fa6bd10cd83b322ad01698008cf" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Ako" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_win64_p1 = { + 44 89 4C 24 ?? 4C 89 44 24 ?? 48 89 54 24 ?? 48 89 4C 24 ?? 56 57 48 81 EC ?? ?? ?? + ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 84 24 ?? ?? ?? ?? + 48 83 BC 24 ?? ?? ?? ?? ?? 74 ?? 48 83 BC 24 ?? ?? ?? ?? ?? 75 ?? 32 C0 E9 ?? ?? ?? + ?? 41 B9 ?? ?? ?? ?? 45 33 C0 48 8B 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 90 89 44 24 ?? 81 7C 24 ?? ?? ?? ?? ?? 73 ?? 32 C0 E9 ?? ?? ?? ?? C7 84 24 + ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 48 8B F8 33 C0 B9 ?? ?? ?? ?? F3 AA + 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 85 C0 75 ?? 32 + C0 E9 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 + ?? 45 33 C0 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 45 33 C0 BA ?? ?? ?? ?? + 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 84 + 24 ?? ?? ?? ?? 48 8B F8 33 C0 B9 ?? ?? ?? ?? F3 AA C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? + 48 8D 84 24 ?? ?? ?? ?? 48 8B F8 33 C0 B9 ?? ?? ?? ?? F3 AA 48 C7 44 24 ?? ?? ?? ?? + ?? EB ?? 48 8B 44 24 ?? 48 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 8B 84 24 ?? ?? ?? ?? 48 + 39 44 24 ?? 0F 8D ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? + 4C 8D 84 24 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 90 85 C0 75 ?? C6 44 24 ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D + 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 0F B6 44 24 ?? E9 ?? ?? ?? ?? 33 D2 48 8D 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 8C 24 ?? ?? ?? ?? 41 + B8 ?? ?? ?? ?? 48 8B D0 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 85 C0 75 ?? C6 + } + $encrypt_files_win64_p2 = { + 44 24 ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 90 0F B6 44 24 ?? E9 ?? ?? ?? ?? 45 33 C9 4C 8D 84 24 ?? ?? ?? ?? 48 8B 94 + 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 85 C0 75 ?? C6 44 24 ?? + ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 90 0F B6 44 24 ?? E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 8B 44 24 ?? 05 ?? ?? + ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? 39 44 24 ?? 0F 83 ?? ?? ?? ?? 48 8D 8C 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 90 8B 4C 24 ?? 48 03 C1 48 89 44 24 ?? 33 D2 48 8D 8C 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B F8 48 8B 44 24 ?? 48 8B F0 B9 ?? ?? ?? ?? F3 A4 48 + 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 8B 4C 24 ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? + ?? 4C 8B C8 45 33 C0 48 8B 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 90 0F B6 C0 85 C0 75 ?? C6 44 24 ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 + 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 0F B6 44 24 ?? E9 ?? ?? ?? ?? 48 8D 8C 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 90 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 4C 24 ?? 44 8B 44 24 ?? + 48 8B D0 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 85 C0 75 ?? C6 44 24 ?? ?? 48 + 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 0F + B6 44 24 ?? E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 75 ?? EB ?? E9 ?? + ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 44 24 ?? 48 8B F8 33 C0 B9 ?? ?? ?? ?? F3 AA + } + $encrypt_files_win64_p3 = { + 48 8B 44 24 ?? 48 89 84 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 44 24 ?? 48 8B + F8 33 C0 B9 ?? ?? ?? ?? F3 AA 48 8B 44 24 ?? 48 89 84 24 ?? ?? ?? ?? 41 B9 ?? ?? ?? + ?? 4C 8D 84 24 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 90 85 C0 0F 84 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 83 C0 ?? 48 8B C8 E8 + ?? ?? ?? ?? 90 48 89 44 24 ?? 48 8B 8C 24 ?? ?? ?? ?? 48 83 C1 ?? E8 ?? ?? ?? ?? 90 + 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 4C 24 ?? 48 8B 4C 24 ?? 44 8B C1 48 8B D0 48 8B 8C + 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 48 89 44 24 + ?? 48 8B 8C 24 ?? ?? ?? ?? 48 83 C1 ?? E8 ?? ?? ?? ?? 90 48 8B 4C 24 ?? 48 3B C8 0F + 85 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? + C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 8B + 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 4C 24 ?? 41 + B8 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 + 85 C0 74 ?? 8B 44 24 ?? 48 83 F8 ?? 75 ?? C6 44 24 ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 0F B6 44 24 ?? EB ?? C6 44 + 24 ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 90 0F B6 44 24 ?? 48 8B 8C 24 ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 90 48 81 C4 + ?? ?? ?? ?? 5F 5E C3 + } + $encrypt_network_shares_win64_p1 = { + 48 89 54 24 ?? 48 89 4C 24 ?? 48 81 EC ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 8B + 05 ?? ?? ?? ?? 48 33 C4 48 89 84 24 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8D 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B 84 24 ?? ?? ?? ?? 48 05 ?? ?? ?? ?? 48 8B C8 E8 + ?? ?? ?? ?? 90 0F B6 C0 85 C0 0F 85 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 90 0F B6 C0 85 C0 0F 85 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 + 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 90 0F B6 C0 85 C0 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 83 + C0 ?? 48 8D 94 24 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 90 48 8D 15 ?? ?? ?? ?? 48 8D + 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 90 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C + 8D 05 ?? ?? ?? ?? 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B D0 48 8D + 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D + 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D + 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8D 84 24 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 + 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8D 05 ?? ?? ?? ?? 48 8B D0 48 8D 8C 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D + 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B + } + $encrypt_network_shares_win64_p2 = { + 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 90 4C 8D 05 ?? ?? ?? ?? 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 90 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 90 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 94 24 ?? ?? ?? + ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D 8C + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8D 05 ?? ?? ?? ?? 48 8B D0 48 8D 8C 24 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 90 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 90 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 94 24 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 0F B6 C0 85 C0 0F 85 ?? ?? ?? + ?? 48 C7 44 24 ?? ?? ?? ?? ?? EB ?? 48 8B 44 24 ?? 48 FF C0 48 89 44 24 ?? 48 8D 8C + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 39 44 24 ?? 73 ?? 48 83 7C 24 ?? ?? 76 ?? 33 D2 + 48 8B 44 24 ?? B9 ?? ?? ?? ?? 48 F7 F1 48 8B C2 48 85 C0 75 ?? 41 B9 ?? ?? ?? ?? 4C + } + $encrypt_network_shares_win64_p3 = { + 8D 05 ?? ?? ?? ?? 48 8B 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B 44 + 24 ?? 48 FF C0 48 89 44 24 ?? EB ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? + ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 54 24 ?? 48 8D 8C 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8D 15 ?? ?? ?? ?? + 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 90 4C 8B C0 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 90 48 8B C8 E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 90 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? + E8 ?? ?? ?? ?? 90 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 94 24 ?? + ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B C8 E8 ?? ?? ?? ?? 90 4C 8B + C0 48 8D 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 90 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 C6 44 24 ?? ?? 48 8D 8C 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 90 0F B6 44 24 ?? EB ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 90 32 C0 48 8B 8C 24 ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 90 48 81 C4 ?? ?? ?? ?? C3 + } + $find_files_win64 = { + 48 89 5C 24 ?? 55 56 57 41 56 41 57 48 81 EC ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 + C4 48 89 84 24 ?? ?? ?? ?? 4D 8B F0 49 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 8B E9 48 3B D1 + 74 ?? 0F B7 02 66 83 E8 ?? 66 83 F8 ?? 77 ?? 0F B7 C0 49 0F A3 C0 72 ?? 48 83 EA ?? + 48 3B D5 75 ?? 0F B7 0A 66 83 F9 ?? 75 ?? 48 8D 45 ?? 48 3B D0 74 ?? 4D 8B CE 45 33 + C0 33 D2 48 8B CD E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 66 83 E9 ?? 33 FF 66 83 F9 ?? 77 ?? + 0F B7 C1 49 0F A3 C0 B0 ?? 72 ?? 40 8A C7 48 2B D5 48 8D 4C 24 ?? 48 D1 FA 41 B8 ?? + ?? ?? ?? 48 FF C2 F6 D8 4D 1B FF 4C 23 FA 33 D2 E8 ?? ?? ?? ?? 45 33 C9 89 7C 24 ?? + 4C 8D 44 24 ?? 48 89 7C 24 ?? 33 D2 48 8B CD FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? + 75 ?? 4D 8B CE 45 33 C0 33 D2 48 8B CD E8 ?? ?? ?? ?? 8B F8 48 83 FB ?? 74 ?? 48 8B + CB FF 15 ?? ?? ?? ?? 8B C7 48 8B 8C 24 ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 48 8B 9C + 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5E 5F 5E 5D C3 49 8B 76 ?? 49 2B 36 48 + C1 FE ?? 66 83 7C 24 ?? ?? 75 ?? 66 39 7C 24 ?? 74 ?? 66 83 7C 24 ?? ?? 75 ?? 66 39 + 7C 24 ?? 74 ?? 4D 8B CE 48 8D 4C 24 ?? 4D 8B C7 48 8B D5 E8 ?? ?? ?? ?? 85 C0 75 ?? + 48 8D 54 24 ?? 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 75 ?? 49 8B 06 49 8B 56 ?? 48 2B D0 + 48 C1 FA ?? 48 3B F2 0F 84 ?? ?? ?? ?? 48 2B D6 48 8D 0C F0 4C 8D 0D ?? ?? ?? ?? 41 + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 + } + + condition: + uint16(0)==0x5A4D and ($find_files_win64) and ( all of ($encrypt_files_win64_p*)) and ( all of ($encrypt_network_shares_win64_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Telecrypt : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects TeleCrypt ransomware." + author = "ReversingLabs" + id = "c4eada2d-72c0-5efe-bf2b-8f053348d89d" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.TeleCrypt.yara#L1-L109" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "9d856eae4369cd7ba1d88bd6ef37931e069127e2c05a84a44f5274f681e83fc0" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "TeleCrypt" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_file = { + 57 E8 ?? ?? ?? ?? 89 03 EB ?? 6A ?? E8 ?? ?? ?? ?? 89 03 66 83 BB ?? ?? ?? ?? ?? 0F + 85 ?? ?? ?? ?? 8B 03 50 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 66 81 7B ?? ?? ?? 75 ?? E8 ?? + ?? ?? ?? 66 89 83 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 89 83 ?? ?? ?? ?? E9 + ?? ?? ?? ?? 0F B7 05 ?? ?? ?? ?? 66 89 83 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 43 ?? ?? ?? + ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 6A ?? 6A ?? 50 8D 43 ?? 50 E8 ?? ?? ?? ?? 83 F8 ?? 75 + ?? 66 C7 43 ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 E9 ?? ?? ?? ?? 89 03 66 81 7B ?? ?? ?? 0F + 85 ?? ?? ?? ?? 66 C7 43 ?? ?? ?? 6A ?? 8B 03 50 E8 ?? ?? ?? ?? 8B F8 83 FF ?? 75 ?? + 8B C3 E8 ?? ?? ?? ?? 8B F0 E9 ?? ?? ?? ?? 81 EF ?? ?? ?? ?? 85 FF 7D ?? 33 FF 6A ?? + 6A ?? 57 8B 03 50 E8 ?? ?? ?? ?? 40 74 ?? 6A ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? 8D 83 + ?? ?? ?? ?? 50 8B 03 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B C3 E8 ?? ?? ?? ?? 8B F0 E9 ?? + ?? ?? ?? F6 43 ?? ?? 74 ?? 83 3C 24 ?? 76 ?? 8B 14 24 4A 85 D2 72 ?? 42 33 FF 8D 83 + ?? ?? ?? ?? 80 38 ?? 75 ?? 6A ?? 6A ?? 8B C7 2B 44 24 ?? 50 8B 03 50 E8 ?? ?? ?? ?? + 40 74 ?? 8B 03 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B C3 E8 ?? ?? ?? ?? 8B F0 EB ?? 47 40 + 4A 75 ?? 66 83 BB ?? ?? ?? ?? ?? 75 ?? 0F B7 05 ?? ?? ?? ?? 66 89 83 ?? ?? ?? ?? 66 + 81 7B ?? ?? ?? 74 ?? 8B 03 50 E8 + } + $server_communication = { + 6A ?? 8D 45 ?? 50 8B 45 ?? 8B 80 ?? ?? ?? ?? 33 C9 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A + ?? 8D 45 ?? 50 FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? + ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? + 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8B 80 ?? ?? ?? ?? + 33 C9 E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? B2 ?? A1 ?? + ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 33 DB 8B CB B8 ?? ?? ?? + ?? D3 E0 85 F0 74 ?? 8D 45 ?? 8B D3 66 83 C2 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? ?? ?? 8B 08 FF 51 ?? 43 83 FB ?? 75 ?? A1 ?? ?? + ?? ?? 8B 10 FF 52 ?? 8B F0 4E 85 F6 7C ?? 46 33 DB 8D 4D ?? 8B D3 A1 ?? ?? ?? ?? 8B + 38 FF 57 ?? 8B 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 43 4E 75 ?? A1 ?? ?? ?? ?? 8B 10 + FF 52 ?? 8B F0 4E 85 F6 7C ?? 46 33 DB 6A ?? 6A ?? 8D 4D ?? 8B D3 A1 ?? ?? ?? ?? 8B + 38 FF 57 ?? 8B 45 ?? 8B 0D ?? ?? ?? ?? 33 D2 E8 ?? ?? ?? ?? 43 4E 75 ?? 8D 55 ?? B8 + ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? + ?? ?? 8B 08 FF 91 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 45 ?? 8B 80 ?? ?? ?? ?? 33 C9 BA + ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 + ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 + ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 + } + $server_communication_1 = { + 55 8B EC 33 C9 51 51 51 51 51 53 8B D8 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 6A + ?? 8D 45 ?? 50 33 C9 BA ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 45 ?? + 50 8D 55 ?? 8B 83 ?? ?? ?? ?? 8B 08 FF 91 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? + ?? 8B 4D ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 33 C9 8B 83 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 33 D2 8B 83 ?? ?? ?? ?? 8B 08 FF 91 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? + ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + } + $exec_payload = { + 55 68 ?? ?? ?? ?? 64 FF 32 64 89 22 8B 4D ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? + E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? + ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 6A ?? 6A ?? 8D 55 ?? 33 C0 E8 ?? ?? ?? ?? + 8B 45 ?? E8 ?? ?? ?? ?? 50 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? + ?? ?? C3 + } + $copy_payload = { + 55 8B EC 6A ?? 6A ?? 6A ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? B8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? B2 ?? E8 ?? + ?? ?? ?? 84 C0 75 ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? 6A ?? 8D 55 ?? B8 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 + 8D 55 ?? 33 C0 E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 5A 59 + 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 + } + $generate_strings_to_encrypt = { + 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? + E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D + 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? + ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? + ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? + ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 + ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 + 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? + ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? + ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? + ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B + 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? + 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 + ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 + ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? + ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? + 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 + } + + condition: + uint16(0)==0x5A4D and (($generate_strings_to_encrypt and $encrypt_file and $server_communication and $exec_payload) or ($encrypt_file and $server_communication_1 and $copy_payload)) +} +rule REVERSINGLABS_Win32_Ransomware_Fuxsocy : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects FuxSocy ransomware." + author = "ReversingLabs" + id = "f4a45469-9d51-523f-8238-c7044f353cf6" + date = "2021-03-01" + modified = "2021-03-01" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.FuxSocy.yara#L1-L114" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "8b3c04eb5d60fcc82e47cb8e78da0a98642666546d6799baef24b56926e3aceb" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "FuxSocy" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files_1 = { + 83 EC ?? 53 55 57 89 54 24 ?? 8B 54 24 ?? 51 33 DB E8 ?? ?? ?? ?? 8B E8 59 85 ED 0F + 84 ?? ?? ?? ?? 8B 44 24 ?? 89 5C 24 ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8B CB E9 + ?? ?? ?? ?? 53 53 FF 74 24 ?? 41 FF 74 24 ?? BF ?? ?? ?? ?? FF 74 24 ?? 3B C7 0F 42 + F8 2B C7 89 4C 24 ?? 89 44 24 ?? FF 15 ?? ?? ?? ?? 53 8D 44 24 ?? 50 57 FF 74 24 ?? + FF 74 24 ?? FF 15 ?? ?? ?? ?? 57 FF 74 24 ?? 8D 54 24 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? + 59 59 57 8D 44 24 ?? 50 FF 74 24 ?? 33 C0 39 44 24 ?? 53 0F 94 C0 89 7C 24 ?? 50 53 + 55 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 53 53 FF 74 24 ?? FF 74 24 ?? FF 74 24 ?? FF 15 ?? + ?? ?? ?? 53 8D 44 24 ?? 50 57 FF 74 24 ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 01 7C 24 ?? + 8B 4C 24 ?? 11 5C 24 ?? F6 C1 ?? 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 8B 44 24 + ?? 85 C0 0F 85 ?? ?? ?? ?? EB ?? 88 5C 24 ?? FF 74 24 ?? 8B 54 24 ?? 8B 4C 24 ?? E8 + ?? ?? ?? ?? 59 8B 4C 24 ?? 55 89 41 ?? FF 15 ?? ?? ?? ?? 8A 5C 24 ?? 5F 5D 8A C3 5B + 83 C4 ?? C3 + } + $encrypt_files_2 = { + 83 EC ?? 53 55 56 8B 74 24 ?? 8B C1 8B 36 57 89 54 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? + 8B F8 33 D2 8D 5F ?? 8B C6 F7 F3 33 C9 85 D2 0F 95 C1 89 54 24 ?? 33 D2 03 C8 89 4C + 24 ?? 0F AF CF 89 4C 24 ?? E8 ?? ?? ?? ?? 8B E8 89 6C 24 ?? 85 ED 0F 84 ?? ?? ?? ?? + 33 D2 8B CF E8 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 83 64 24 ?? ?? + 48 89 6C 24 ?? 89 44 24 ?? 74 ?? 53 FF 74 24 ?? 89 5C 24 ?? 56 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 44 24 ?? 57 50 56 33 C0 50 50 50 FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? + ?? ?? ?? 33 C9 85 FF 74 ?? 8B 54 24 ?? 8D 6E ?? 03 EF 8A 45 ?? 4D 88 04 11 41 3B CF + 72 ?? 8B 6C 24 ?? 8B 44 24 ?? 03 44 24 ?? 01 5C 24 ?? 89 44 24 ?? 8B 44 24 ?? 40 89 + 44 24 ?? 3B 44 24 ?? 72 ?? 8B 44 24 ?? 85 C0 0F 45 D8 53 FF 74 24 ?? 89 5C 24 ?? 56 + E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 57 50 56 6A ?? 6A ?? 6A ?? FF 74 24 ?? FF 15 ?? + ?? ?? ?? 8B D8 F7 DB 1A DB 80 E3 ?? 33 C9 85 FF 74 ?? 8B 6C 24 ?? 8D 56 ?? 03 D7 8A + 02 4A 88 04 29 41 3B CF 72 ?? 8B 6C 24 ?? 8B CE E8 ?? ?? ?? ?? 84 DB 75 ?? 8B CD E8 + ?? ?? ?? ?? 33 ED EB ?? 32 DB EB ?? 8B 4C 24 ?? 8B 44 24 ?? 89 01 5F 5E 8B C5 5D 5B + 83 C4 ?? C3 + } + $find_files_1 = { + 81 EC ?? ?? ?? ?? 53 56 57 8B BC 24 ?? ?? ?? ?? 8B F2 89 74 24 ?? 8B D9 85 FF 0F 84 + ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 8B D7 C1 E2 ?? 8B + CE E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 + 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D3 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 84 C0 + 0F 84 ?? ?? ?? ?? 55 68 ?? ?? ?? ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D + 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B E8 + 83 FD ?? 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8B 44 + 24 ?? 83 E0 ?? 74 ?? F6 84 24 ?? ?? ?? ?? ?? 75 ?? 85 C0 75 ?? F6 84 24 ?? ?? ?? ?? + ?? 74 ?? 33 F6 85 FF 74 ?? 8B 44 24 ?? FF 34 B0 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 + C0 75 ?? 46 3B F7 72 ?? EB ?? FF B4 24 ?? ?? ?? ?? 8D 44 24 ?? 50 53 FF 94 24 ?? ?? + ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 74 ?? FF B4 24 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 8B 74 24 ?? F6 44 24 ?? ?? 74 ?? F6 84 24 ?? ?? ?? ?? ?? 74 + ?? 8D 44 24 ?? 50 8B D3 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 84 C0 74 ?? 83 BC 24 + ?? ?? ?? ?? ?? 74 ?? FF B4 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B + D6 FF B4 24 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? FF B4 24 ?? ?? ?? + ?? FF B4 24 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 50 55 FF 15 ?? ?? ?? + ?? 85 C0 0F 85 ?? ?? ?? ?? EB ?? 83 64 24 ?? ?? 55 FF 15 ?? ?? ?? ?? 5D 5F 5E 5B 81 + C4 ?? ?? ?? ?? C3 + } + $find_files_2 = { + 81 EC ?? ?? ?? ?? 8D 44 24 ?? 53 55 56 68 ?? ?? ?? ?? 50 8B D9 FF 15 ?? ?? ?? ?? 8B + F0 85 F6 0F 84 ?? ?? ?? ?? 8D 6C 24 ?? 8D 6C 75 ?? 33 C0 66 89 44 74 ?? 68 ?? ?? ?? + ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 59 E8 ?? ?? ?? ?? 83 C0 ?? 6A ?? 59 66 89 + 45 ?? E8 ?? ?? ?? ?? 83 C0 ?? 66 89 44 74 ?? 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? 50 + FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 50 FF 15 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 84 C0 74 ?? 8D 84 24 ?? ?? ?? ?? 50 55 FF 15 ?? ?? ?? ?? 83 64 24 ?? ?? 8D 44 + 24 ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 44 24 ?? 50 53 + FF 15 ?? ?? ?? ?? 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 + } + $find_files_3 = { + 81 EC ?? ?? ?? ?? 53 55 56 8B D9 57 8B FA 85 DB 74 ?? 33 D2 E8 ?? ?? ?? ?? 8B F0 85 + F6 0F 84 ?? ?? ?? ?? 57 56 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? + 83 C4 ?? 8B CE E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 C6 43 ?? ?? FF 15 ?? ?? ?? ?? + 0D ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 + ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? EB ?? 57 FF 15 ?? ?? ?? ?? 0D ?? ?? ?? ?? 50 57 FF + 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D7 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 84 C0 0F + 84 ?? ?? ?? ?? 8B B4 24 ?? ?? ?? ?? 80 7E ?? ?? 75 ?? 8B 15 ?? ?? ?? ?? 8D 8C 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? + 50 FF 15 ?? ?? ?? ?? 8B E8 83 FD ?? 0F 84 ?? ?? ?? ?? 83 64 24 ?? ?? 6A ?? FF 35 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 84 C0 + 0F 85 ?? ?? ?? ?? F7 44 24 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 56 + 57 FF 15 ?? ?? ?? ?? 50 8B D7 8B CB E8 ?? ?? ?? ?? 59 59 89 44 24 ?? 85 C0 0F 84 ?? + ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 50 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? F6 44 + 24 ?? ?? 74 ?? 80 7E ?? ?? 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 56 FF B4 24 ?? + ?? ?? ?? 8D 54 24 ?? E8 ?? ?? ?? ?? 59 59 EB ?? 80 7E ?? ?? 74 ?? 85 DB 74 ?? 83 7C + 24 ?? ?? 7C ?? 7F ?? 81 7C 24 ?? ?? ?? ?? ?? 72 ?? 80 3E ?? 74 ?? 6A ?? 8D 44 24 ?? + 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 8D 44 24 ?? 50 FF 74 24 ?? FF 94 24 ?? ?? ?? ?? + 83 C4 ?? 85 C0 74 ?? 8D 44 24 ?? 50 55 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 55 + FF 15 ?? ?? ?? ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_*)) and ( all of ($encrypt_files_*)) +} +rule REVERSINGLABS_Win32_Ransomware_Regretlocker : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects RegretLocker ransomware." + author = "ReversingLabs" + id = "c4e515cc-b0c2-57b2-a230-619ec01ac8d4" + date = "2021-04-02" + modified = "2021-04-02" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.RegretLocker.yara#L1-L206" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3927dfecacd74f60a169f82b68df5747daa90eaba77f24c5e730ce4c48d426a3" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "RegretLocker" + tc_detection_factor = 5 + importance = 25 + + strings: + $remote_connection_p1 = { + 55 8B EC 8B 41 ?? 8B 55 ?? 3B C2 72 ?? 2B C2 56 8B 75 ?? 3B C6 0F 42 F0 83 79 ?? ?? + 72 ?? 8B 09 56 03 CA 51 FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B C6 5E 5D C2 ?? ?? E8 ?? + ?? ?? ?? CC B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 83 65 ?? ?? 8D 45 ?? 53 + 56 57 50 E8 ?? ?? ?? ?? 83 65 ?? ?? 50 E8 ?? ?? ?? ?? 83 4D ?? ?? 8A D8 59 59 8D 4D + ?? E8 ?? ?? ?? ?? 84 DB 0F 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? + C7 45 ?? ?? ?? ?? ?? 8B CC 6A ?? 83 61 ?? ?? C7 41 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 88 + 19 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 + E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 59 59 8B 8D ?? ?? ?? + ?? 8D 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 6A ?? 5B 3B CB C6 45 ?? ?? 0F 43 C2 80 78 ?? + ?? 75 ?? 3B CB 8D 85 ?? ?? ?? ?? 0F 43 C2 80 78 ?? ?? 75 ?? 3B CB 8D 85 ?? ?? ?? ?? + 0F 43 C2 80 78 ?? ?? 75 ?? 3B CB 8D 85 ?? ?? ?? ?? 0F 43 C2 80 78 ?? ?? 75 ?? 3B CB + 8D 85 ?? ?? ?? ?? 0F 43 C2 80 78 ?? ?? 75 ?? 83 BD ?? ?? ?? ?? ?? 0F 84 + } + $remote_connection_p2 = { + 8D 45 ?? 50 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B C8 C7 04 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 84 C0 75 ?? 8B BD ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 3B FB 8D B5 ?? ?? ?? ?? 8B 9D + ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 0F 43 C3 83 FF ?? 0F 43 F3 0F 43 D3 33 C9 8A 40 ?? 3A + 46 ?? 0F BE 42 ?? 0F 94 C1 3B C8 75 ?? 83 FF ?? 8D 85 ?? ?? ?? ?? 0F 43 C3 80 78 ?? + ?? 75 ?? 83 FF ?? 8D 85 ?? ?? ?? ?? 0F 43 C3 80 78 ?? ?? 74 ?? 32 DB EB ?? B3 ?? F6 + 45 ?? ?? 74 ?? 8D 4D ?? E8 ?? ?? ?? ?? 84 DB 74 ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 6A ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 5F 6A ?? 33 DB 89 BD + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 89 65 ?? 53 89 59 ?? 89 79 ?? 68 ?? ?? ?? ?? + 88 19 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 8D 85 ?? ?? ?? ?? 50 89 59 ?? 89 59 + ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? + 8B B5 ?? ?? ?? ?? C6 45 ?? ?? 83 FE ?? 77 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 84 C0 74 ?? 6A ?? 5E 83 EC ?? 8B CC 89 65 ?? 53 89 59 ?? 89 79 ?? 68 ?? ?? + ?? ?? 88 19 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 8D 85 ?? ?? ?? ?? 50 89 59 ?? + 89 59 ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 + } + $remote_connection_p3 = { + 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 83 EE ?? 75 ?? 8B B5 ?? ?? ?? ?? 8D 46 ?? 83 F8 ?? 77 ?? 68 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? + ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 50 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 59 59 89 5D ?? 89 7D ?? 88 9D ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 89 + 5D ?? 89 5D ?? E8 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 59 8B + F0 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 89 5D ?? 89 7D ?? 88 5D ?? E8 ?? ?? ?? + ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 56 83 C1 ?? + E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? FF 35 ?? + ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 59 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 + } + $remote_connection_p4 = { + 89 5D ?? 89 7D ?? 88 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D + ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? 50 83 C1 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? + ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 51 51 8B CC 89 65 ?? 8D 45 ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? 50 8D 45 ?? 89 4D ?? 50 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8B CC 6A + ?? 89 59 ?? C7 41 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 88 19 E8 ?? ?? ?? ?? 8D 45 ?? C6 45 + ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D + ?? E8 ?? ?? ?? ?? 8B 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 0F 43 85 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 74 ?? 50 53 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 85 ?? ?? ?? ?? 8B 75 ?? 0F 43 85 ?? ?? + ?? ?? 6A ?? 6A ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 74 ?? 40 8D 8D ?? ?? ?? ?? + 50 E8 ?? ?? ?? ?? 8B 75 ?? 56 E8 ?? ?? ?? ?? 59 53 FF 75 ?? 8D 8D ?? ?? ?? ?? A3 ?? + ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 4D ?? A1 ?? ?? ?? ?? 68 ?? ?? ?? ?? 88 1C 01 E8 ?? ?? + ?? ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? A3 ?? ?? ?? ?? 59 8B 75 ?? + 8D 4D ?? C6 45 ?? ?? FF 76 ?? E8 ?? ?? ?? ?? 8B 45 ?? C6 45 ?? ?? 89 70 ?? 8B 45 ?? + 89 30 8B 45 ?? 89 70 ?? 8D 85 ?? ?? ?? ?? 50 6A ?? 58 50 68 ?? ?? ?? ?? 83 EC ?? 89 + } + $remote_connection_p5 = { + 5D ?? 8B CC FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B F8 6A ?? 58 + FF 35 ?? ?? ?? ?? 85 FF 0F 44 F8 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 59 6A ?? 5E 6A ?? 68 + ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 89 5D ?? 89 75 ?? 88 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? + C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? 50 83 C1 ?? E8 + ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? + ?? ?? ?? 8D 4D ?? 89 5D ?? 89 75 ?? 88 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 + 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 85 ?? ?? ?? ?? 50 83 C1 ?? E8 ?? ?? + ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 8B F0 6A ?? + 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 89 5D ?? C7 45 ?? ?? ?? ?? ?? 88 5D ?? E8 ?? ?? + ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 56 83 C1 + ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 8D 45 + ?? 50 E8 ?? ?? ?? ?? 59 8B F0 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? 89 5D ?? C7 + 45 ?? ?? ?? ?? ?? 88 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D + ?? E8 ?? ?? ?? ?? 8B 4D ?? 56 83 C1 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D + ?? C6 45 ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 45 ?? 57 50 E8 ?? ?? ?? ?? 83 C4 + ?? 8B F0 6A ?? 58 6A ?? 5F 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? 88 45 ?? 89 5D ?? 89 7D ?? + 88 5D ?? E8 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 8D 45 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? + 8B 4D ?? 56 83 C1 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 + ?? ?? ?? ?? 51 51 8B CC 89 65 ?? 8D 45 ?? 89 4D ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 + EC ?? C6 45 ?? ?? 8B CC 6A ?? 89 59 ?? 89 79 ?? 68 ?? ?? ?? ?? 88 19 E8 + } + $encrypt_files_p1 = { + 8B FB 89 5D ?? 89 7D ?? 89 5D ?? 8B 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? C6 45 ?? ?? 89 + 45 ?? 3B F0 74 ?? 56 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 3B DF 74 ?? + 8B 08 89 0F 8B 48 ?? 89 4F ?? 83 20 ?? 83 60 ?? ?? 83 C7 ?? 89 7D ?? EB ?? 50 57 8D + 4D ?? E8 ?? ?? ?? ?? 8B 5D ?? 8B 7D ?? 83 7D ?? ?? C6 45 ?? ?? 0F 85 ?? ?? ?? ?? 6A + ?? 58 03 F0 3B 75 ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 8B B5 ?? ?? ?? ?? + C6 45 ?? ?? 8B 06 89 45 ?? EB ?? 8D 48 ?? 8D 41 ?? 50 51 68 ?? ?? ?? ?? 8D 4D ?? E8 + ?? ?? ?? ?? C6 45 ?? ?? 3B DF 74 ?? 8B 08 89 0F 8B 48 ?? 89 4F ?? 83 20 ?? 83 60 ?? + ?? 83 C7 ?? 89 7D ?? EB ?? 50 57 8D 4D ?? E8 ?? ?? ?? ?? 8B 5D ?? 8B 7D ?? 83 7D ?? + ?? C6 45 ?? ?? 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 3B C6 75 ?? 8B 75 + ?? EB ?? 83 7E ?? ?? 74 ?? 8B CE E8 ?? ?? ?? ?? 83 C6 ?? 3B F7 75 ?? 0F 57 C0 68 ?? + ?? ?? ?? 66 0F 13 45 ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 2B 05 ?? ?? ?? ?? 6A ?? 59 99 + F7 F9 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 83 C4 ?? 8B 1D ?? ?? ?? ?? 8B + 75 ?? 8B 7D ?? 89 45 ?? 3B D8 74 ?? 83 EC ?? 8B CC 53 83 61 ?? ?? 83 61 ?? ?? E8 ?? + ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 03 F8 83 D6 ?? 6A ?? 58 03 D8 3B 5D ?? 75 ?? 0F AC + F7 ?? C1 EE ?? 56 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 C4 ?? 8B 35 + ?? ?? ?? ?? EB ?? 83 7E ?? ?? 8B C6 72 ?? 8B 06 6A ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? + ?? 83 C4 ?? 6A ?? 58 03 F0 3B F7 75 ?? 68 ?? ?? ?? ?? E8 + } + $encrypt_files_p2 = { + B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 EC ?? ?? ?? ?? 53 56 8B 75 ?? 8D 8D ?? ?? ?? ?? 57 + 56 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 33 DB 50 8D 45 ?? 89 5D ?? 50 E8 ?? ?? ?? ?? 59 + 59 8D 8D ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8B CC 6A ?? 89 59 ?? C7 41 + ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 88 19 E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 + ?? 8D 4D ?? 50 E8 ?? ?? ?? ?? 8D 4D ?? 8A D8 E8 ?? ?? ?? ?? 84 DB 74 ?? 33 DB E9 ?? + ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 59 59 85 + C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? + ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? 83 EC ?? 33 DB 8B CC 89 5D ?? 56 E8 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 89 45 ?? B9 ?? ?? ?? ?? BF ?? ?? ?? ?? 3B C1 0F 42 C8 3B C7 89 + 4D ?? 0F 42 F8 89 7D ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 8D 8D ?? ?? ?? + ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 39 9D ?? ?? ?? ?? 75 ?? 83 EC ?? 8B CC 56 E8 ?? ?? ?? + ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 83 7E ?? ?? C6 45 ?? ?? 72 ?? 8B 36 E8 + ?? ?? ?? ?? FF 30 E8 ?? ?? ?? ?? 56 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D + ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 77 ?? 56 E8 ?? ?? ?? ?? 56 89 45 ?? E8 ?? ?? ?? + ?? 8B 4D ?? 56 53 51 89 45 ?? E8 ?? ?? ?? ?? 56 53 FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? + 83 C4 ?? 89 5D ?? 8B D3 85 C0 0F 84 ?? ?? ?? ?? 8B C8 2B CA 39 4D ?? 8B C1 8B F1 0F + 46 45 ?? 3B F9 89 45 ?? 0F 46 F7 8B 7D ?? 2B CE 89 75 ?? 39 4D ?? 0F 46 4D ?? 89 4D + ?? 85 FF 75 ?? 53 56 FF 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 0C 3E 8B + } + $encrypt_files_p3 = { + C4 89 4D ?? 89 08 8D 8D ?? ?? ?? ?? 89 58 ?? 89 58 ?? 89 58 ?? 89 58 ?? 89 58 ?? E8 + ?? ?? ?? ?? 53 FF 75 ?? 8D 8D ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 FF 75 + ?? 8D 8D ?? ?? ?? ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 EC ?? 8B D4 8B D8 + 33 C0 03 CF 89 0A 8D 8D ?? ?? ?? ?? 89 42 ?? 89 42 ?? 89 42 ?? 89 42 ?? 89 42 ?? E8 + ?? ?? ?? ?? 6A ?? FF 75 ?? 8D 8D ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8B 7D ?? 2B 75 ?? 03 + 7D ?? 56 57 E8 ?? ?? ?? ?? 59 59 6A ?? 56 57 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 + ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 8B 45 ?? 2B 45 ?? 01 45 ?? 53 E8 ?? ?? ?? ?? 8B + 85 ?? ?? ?? ?? 83 C4 ?? 8B 40 ?? 8B 84 05 ?? ?? ?? ?? C1 E8 ?? A8 ?? 74 ?? 83 EC ?? + 8B CC FF 75 ?? E8 ?? ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 83 7E ?? ?? + C6 45 ?? ?? 72 ?? 8B 36 E8 ?? ?? ?? ?? FF 30 E8 ?? ?? ?? ?? 56 50 68 ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8B 7D ?? + 89 55 ?? 6A ?? 5B 3B D0 0F 82 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? + E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 59 59 FF 75 ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 EC + ?? C6 45 ?? ?? 8B CC 6A ?? 89 59 ?? C7 41 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 88 19 E8 ?? + ?? ?? ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 8B 48 ?? C6 45 ?? ?? 72 ?? + 8B 00 51 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? + 8D 45 ?? 0F 43 45 ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 EC ?? 8D 45 ?? 8B CC 50 89 59 ?? + 89 59 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? B3 ?? E8 ?? ?? ?? ?? 8D 8D + ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? FF 75 ?? 56 E8 ?? ?? ?? ?? 59 59 8A D8 8D 4D ?? E8 + ?? ?? ?? ?? 8B 4D ?? 8A C3 5F 5E 64 89 0D ?? ?? ?? ?? 5B C9 C3 + } + $find_files = { + 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 83 C8 ?? 57 8B 7D ?? + 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? + ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? + FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 4D ?? + 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 C0 50 + 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 + 89 45 ?? 8B 4D ?? 53 8B 5D ?? 56 8B 75 ?? 57 89 B5 ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 + ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 53 E8 ?? ?? ?? ?? 59 59 8B C8 3B CB 75 ?? 8A 11 80 FA + ?? 75 ?? 8D 43 ?? 3B C8 74 ?? 56 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 FF + 80 FA ?? 74 ?? 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8B C7 EB ?? 33 C0 40 0F B6 C0 2B CB 41 + F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? + ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 + FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? + 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 + 74 ?? 80 F9 ?? 75 ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? + ?? 85 C0 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B + C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 + ?? E9 + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Pay2Key : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Pay2Key ransomware." + author = "ReversingLabs" + id = "2e482222-0483-5fe3-bb87-cfadda8e7e7a" + date = "2021-04-14" + modified = "2021-04-14" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Pay2Key.yara#L1-L99" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "2497504f3afc99523cb29e51652a24f4374316d57d4baf5cde8d22e75a425585" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Pay2Key" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files = { + 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 2B CA 83 C8 ?? 57 8B 7D ?? + 41 2B C7 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? + ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? + FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 4D ?? + 56 E8 ?? ?? ?? ?? 6A ?? 8B F0 E8 ?? ?? ?? ?? 59 8B C6 5E 5B 5F 8B E5 5D C3 33 C0 50 + 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 + 89 45 ?? 8B 4D ?? 53 8B 5D ?? 56 8B 75 ?? 57 89 B5 ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 + ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 53 E8 ?? ?? ?? ?? 59 59 8B C8 3B CB 75 ?? 8A 11 80 FA + ?? 75 ?? 8D 43 ?? 3B C8 74 ?? 56 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 FF + 80 FA ?? 74 ?? 80 FA ?? 74 ?? 80 FA ?? 74 ?? 8B C7 EB ?? 33 C0 40 0F B6 C0 2B CB 41 + F7 D8 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? + ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? + ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 + FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? + 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 + 74 ?? 80 F9 ?? 75 ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? + ?? 85 C0 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B + C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 + ?? E9 + } + $encrypt_files = { + 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? 53 56 57 A1 ?? ?? ?? ?? + 33 C5 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B D9 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? + 8B 43 ?? 2B 43 ?? 75 ?? 8B 75 ?? 8B 45 ?? 8B 4D ?? C7 45 ?? ?? ?? ?? ?? 89 06 89 4E + ?? 8B 4D ?? 89 4E ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? + ?? 8B C6 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C2 ?? ?? 83 7B ?? ?? 74 + ?? 8B 45 ?? 2B 45 ?? 50 E8 ?? ?? ?? ?? 8B 75 ?? 8B F8 8B 55 ?? 2B F2 56 52 57 E8 ?? + ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? + 56 89 75 ?? E8 ?? ?? ?? ?? 56 57 50 89 45 ?? E8 ?? ?? ?? ?? 8B 75 ?? 8D 45 ?? 83 C4 + ?? 50 56 6A ?? 6A ?? 6A ?? FF 73 ?? FF 15 ?? ?? ?? ?? 8D 4D ?? 85 C0 75 ?? 8B 75 ?? + 89 45 ?? 89 45 ?? 89 45 ?? 89 06 89 46 ?? 89 46 ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? + ?? ?? 8B C6 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 5B 8B E5 5D C2 ?? ?? FF 75 ?? E8 + ?? ?? ?? ?? FF 75 ?? 56 8B 75 ?? 56 E8 ?? ?? ?? ?? 8B 7D ?? 83 C4 ?? 8B 4D ?? 8B 45 + ?? C7 45 ?? ?? ?? ?? ?? 89 4F ?? 8D 4D ?? 89 37 89 47 ?? C7 45 ?? ?? ?? ?? ?? C7 45 + ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B C7 8B 4D ?? 64 89 0D ?? ?? + ?? ?? 59 5F 5E 5B 8B E5 5D C2 + } + $remote_connection_p1 = { + 55 8B EC 83 EC ?? 56 57 6A ?? 8B F2 8B F9 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 45 ?? C7 + 45 ?? ?? ?? ?? ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 6A ?? 56 57 FF 15 ?? ?? ?? ?? + 8B 75 ?? 8B C8 8B D6 E8 ?? ?? ?? ?? 8B 0E 8B F8 83 F9 ?? 75 ?? 68 ?? ?? ?? ?? 8B CE + E8 ?? ?? ?? ?? EB ?? 81 F9 ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? EB + ?? 81 F9 ?? ?? ?? ?? 74 ?? 81 F9 ?? ?? ?? ?? 74 ?? 85 FF 74 ?? 5F 83 C8 ?? 5E 8B E5 + 5D C3 + } + $remote_connection_p2 = { + 55 8B EC 51 53 56 8B F1 57 8B 46 ?? 83 C0 ?? 50 FF 15 ?? ?? ?? ?? 80 7D ?? ?? 6A ?? + 74 ?? 8B 4E ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 5F 5E 5B 59 5D C2 ?? ?? 8B 45 ?? 8B 08 + 83 F9 ?? 75 ?? 8B 4E ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 5F 5E 5B 59 5D C2 ?? + ?? 8B 45 ?? 8B 7D ?? 57 89 45 ?? 8D 45 ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF 75 + ?? FF 75 ?? 51 FF 15 ?? ?? ?? ?? 8B D8 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? B8 ?? ?? ?? + ?? EB ?? 3D ?? ?? ?? ?? B9 ?? ?? ?? ?? 0F 44 C1 85 DB 74 ?? 3D ?? ?? ?? ?? 74 ?? FF + 75 ?? 8B 4E ?? 50 57 E8 ?? ?? ?? ?? 5F 5E 5B 59 5D C2 ?? ?? 8B 4E ?? 57 E8 ?? ?? ?? + ?? 5F 5E 5B 59 5D C2 + } + $remote_connection_p3 = { + 55 8B EC 83 EC ?? 56 57 6A ?? 8B F2 8B F9 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 45 + ?? C7 45 ?? ?? ?? ?? ?? 50 FF 75 ?? 56 57 FF 15 ?? ?? ?? ?? 8B 75 ?? 8B C8 8B D6 E8 + ?? ?? ?? ?? 8B 0E 8B F8 83 F9 ?? 75 ?? 68 ?? ?? ?? ?? EB ?? 81 F9 ?? ?? ?? ?? 75 ?? + 68 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 85 FF 74 ?? 5F 83 C8 ?? 5E 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ( all of ($remote_connection_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Atlas : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Atlas ransomware." + author = "ReversingLabs" + id = "2c702b24-4b7e-505c-a694-0d915cc47315" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Atlas.yara#L1-L99" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "1486f931ec096a00d913de0568ddd8aa5a091256445bc28aba90e3e194ebd045" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Atlas" + tc_detection_factor = 5 + importance = 25 + + strings: + $encrypt_files = { + 8B 74 24 ?? 8B 3D ?? ?? ?? ?? 8D 4C 24 ?? 6A ?? 51 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 52 56 FF D7 8B 94 24 ?? ?? ?? ?? 8D 44 24 ?? 8D 8C 24 ?? ?? ?? ?? 50 8B 84 24 ?? + ?? ?? ?? 51 52 50 E8 ?? ?? ?? ?? 8B 54 24 ?? 83 C4 ?? 8D 4C 24 ?? 8D 84 24 ?? ?? ?? + ?? 6A ?? 51 8B 4C 24 ?? 52 50 51 FF 15 ?? ?? ?? ?? 8D 54 24 ?? 6A ?? 52 55 53 56 FF + D7 8B 7C 24 ?? 33 C9 3B FD 89 4C 24 ?? 0F 85 ?? ?? ?? ?? EB ?? 8B 4C 24 ?? 33 F6 8A + 84 34 ?? ?? ?? ?? 02 C1 F6 E9 88 44 34 ?? 8A 84 34 ?? ?? ?? ?? 02 C1 F6 E9 88 44 34 + ?? 46 83 FE ?? 7C ?? 8B 74 24 ?? 57 56 8D 44 24 ?? 53 8D 8C 24 ?? ?? ?? ?? 50 51 E8 + ?? ?? ?? ?? 8B 54 24 ?? 8D 84 24 ?? ?? ?? ?? 52 53 56 8D 8C 24 ?? ?? ?? ?? 50 51 E8 + ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 83 C4 ?? 8D 54 24 ?? 6A ?? 52 50 53 51 FF 15 ?? + ?? ?? ?? 8B 44 24 ?? 8D 54 24 ?? 6A ?? 52 55 53 50 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 8B + 7C 24 ?? 41 3B FD 89 4C 24 ?? 0F 84 ?? ?? ?? ?? 8B 74 24 ?? 85 FF 74 ?? 8B 54 24 ?? + 8D 4C 24 ?? 6A ?? 51 57 53 52 FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 8B 44 24 + ?? 50 FF D6 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 53 FF D6 8B 4C 24 ?? 68 ?? ?? ?? + ?? 6A ?? 51 FF D6 5F 5E 5D 33 C0 5B 81 C4 ?? ?? ?? ?? C3 + } + $remote_server_1 = { + 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 33 C9 8D 94 24 ?? ?? ?? ?? 8A 0C 2E + 8D 84 24 ?? ?? ?? ?? 51 52 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 46 81 FE ?? ?? + ?? ?? 7C ?? 8D 8C 24 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 52 E8 ?? ?? + ?? ?? 83 C4 ?? 33 F6 33 C0 8D 8C 24 ?? ?? ?? ?? 8A 04 1E 8D 94 24 ?? ?? ?? ?? 50 51 + 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 46 81 FE ?? ?? ?? ?? 7C ?? 8D 84 24 ?? ?? + ?? ?? 8D BC 24 ?? ?? ?? ?? 50 83 C9 ?? 33 C0 33 F6 F2 AE F7 D1 49 51 8D 8C 24 ?? ?? + ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 83 FE ?? + 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 46 FF 15 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? 83 C9 ?? + 33 C0 8D 94 24 ?? ?? ?? ?? F2 AE F7 D1 49 52 8D 84 24 ?? ?? ?? ?? 51 50 68 ?? ?? ?? + ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? BE ?? ?? ?? ?? 8D 84 24 ?? ?? + ?? ?? 8A 10 8A 1E 8A CA 3A D3 75 ?? 84 C9 74 ?? 8A 50 ?? 8A 5E ?? 8A CA 3A D3 75 ?? + 83 C0 ?? 83 C6 ?? 84 C9 75 ?? 33 C0 EB + } + $remote_server_2 = { + 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 + ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? BB ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? 51 2B D8 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 52 03 D8 E8 ?? ?? ?? ?? 8B CB 8B F0 8B C1 83 C6 ?? 8D BC 24 ?? ?? ?? ?? 83 C4 + ?? C1 E9 ?? F3 A5 8B C8 68 ?? ?? ?? ?? 83 E1 ?? 68 ?? ?? ?? ?? F3 A4 8D 8C 24 ?? ?? + ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 94 24 ?? ?? ?? ?? BB + ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 2B D8 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? + ?? ?? ?? 03 D8 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B CB 8B F0 8B + D1 BF ?? ?? ?? ?? C1 E9 ?? F3 A5 83 C4 ?? 8B CA 83 E1 ?? 8D 84 24 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? F3 A4 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? + BB ?? ?? ?? ?? 2B D8 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? + ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 03 D8 E8 ?? + ?? ?? ?? 8B CB 8B F0 8B C1 83 C6 ?? BF ?? ?? ?? ?? 68 ?? ?? ?? ?? C1 E9 ?? F3 A5 8B + C8 68 ?? ?? ?? ?? 83 E1 ?? F3 A4 E8 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? 83 C9 ?? 33 C0 + 83 C4 ?? F2 AE F7 D1 49 83 F9 ?? 0F 82 ?? ?? ?? ?? 33 F6 8D BC 24 ?? ?? ?? ?? 8D 8C + 34 ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 46 83 C7 ?? 81 FE ?? ?? + ?? ?? 72 ?? 8B 3D ?? ?? ?? ?? FF D7 8D 94 24 ?? ?? ?? ?? 56 52 8B E8 E8 ?? ?? ?? ?? + 83 C4 ?? FF D7 8B F0 8D 44 24 ?? 50 2B F5 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B + 4C 24 ?? 8D 94 24 ?? ?? ?? ?? 51 56 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? + 8D 84 24 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? 50 83 C9 ?? 33 C0 F2 AE F7 D1 49 51 8D 8C + 24 ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 + } + $send_post_packet = { + 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 83 + FE ?? 89 75 ?? 75 ?? 50 E8 ?? ?? ?? ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 5F 5E 5B + 8B E5 5D C3 6A ?? 66 C7 45 ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 66 89 45 ?? 52 E8 ?? ?? + ?? ?? 89 45 ?? 8D 45 ?? 6A ?? 50 56 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 56 E8 ?? ?? ?? ?? + 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 8D BD ?? ?? ?? ?? 83 C9 ?? + 33 C0 6A ?? F2 AE F7 D1 49 51 8D 8D ?? ?? ?? ?? 51 56 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? + 56 E8 ?? ?? ?? ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 + } + $send_get_request = { + 68 ?? ?? ?? ?? 55 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 83 + FB ?? 75 ?? 68 ?? ?? ?? ?? 6A ?? 55 FF 15 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 5F 5E 5D 33 + C0 5B 81 C4 ?? ?? ?? ?? C3 6A ?? 66 C7 44 24 ?? ?? ?? E8 ?? ?? ?? ?? 8D 54 24 ?? 66 + 89 44 24 ?? 52 E8 ?? ?? ?? ?? 89 44 24 ?? 8D 44 24 ?? 6A ?? 50 53 E8 ?? ?? ?? ?? 83 + F8 ?? 75 ?? 68 ?? ?? ?? ?? 6A ?? 55 FF 15 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 5F 5E 5D 33 + C0 5B 81 C4 ?? ?? ?? ?? C3 8B FD 83 C9 ?? 33 C0 6A ?? F2 AE F7 D1 49 51 55 53 E8 ?? + ?? ?? ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? 6A ?? 55 FF 15 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? + 5F 5E 5D 33 C0 5B 81 C4 ?? ?? ?? ?? C3 + } + + condition: + uint16(0)==0x5A4D and $encrypt_files and $remote_server_1 and $remote_server_2 and $send_post_packet and $send_get_request +} +rule REVERSINGLABS_Win32_Ransomware_Jsworm : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects JSWorm ransomware." + author = "ReversingLabs" + id = "a4702cc3-1e08-5631-b832-5d28cb92a819" + date = "2020-07-15" + modified = "2020-07-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.JSWorm.yara#L1-L93" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "8ba5e2f29f5f06e6e6714bbba1129862da8c3a83bf7f296818eddee2593cae38" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "JSWorm" + tc_detection_factor = 5 + importance = 25 + + strings: + $find_files = { + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? + 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 + FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? + ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? A8 ?? + 0F 85 ?? ?? ?? ?? A8 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? 8D + 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 C6 45 ?? ?? 8B 4E ?? 8B 56 ?? 3B CA 73 + ?? 8D 41 ?? 89 46 ?? 8B C6 83 FA ?? 72 ?? 8B 06 C7 04 48 ?? ?? ?? ?? EB ?? 6A ?? C6 + 85 ?? ?? ?? ?? ?? 8B CE FF B5 ?? ?? ?? ?? 6A ?? E8 + } + $find_drives = { + 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? BE ?? ?? ?? ?? 0F 84 ?? + ?? ?? ?? 8B CE C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 51 ?? 8A 01 + 41 84 C0 75 ?? 2B CA 51 56 8D 4D ?? E8 ?? ?? ?? ?? 83 EC ?? C7 45 ?? ?? ?? ?? ?? 8B + CC 89 65 ?? 33 C0 6A ?? 68 ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 66 + 89 01 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 55 ?? 8B CC E8 ?? ?? ?? ?? C6 45 ?? ?? + E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B + C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 + ?? ?? ?? ?? 83 C4 ?? 8B C6 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 46 03 F0 38 0E 0F 85 + ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 + 5D C3 E8 ?? ?? ?? ?? E8 + } + $encrypt_files_p1 = { + 8B 00 50 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B F0 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? + 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? + ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? C7 85 + ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 83 FA ?? + 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? + 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B + CB C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 E6 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 66 89 + 85 ?? ?? ?? ?? 8D 51 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 51 53 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 78 ?? ?? 72 ?? 8B 00 56 50 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 FA + ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 + 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? + ?? 8B 95 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 + 85 ?? ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA + ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 + E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF + 15 ?? ?? ?? ?? 8B D8 8D 45 ?? 50 53 89 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 7D ?? ?? + 0F 8C ?? ?? ?? ?? 7F ?? 81 7D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 53 + FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 8B F8 89 BD ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? + B9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? BE ?? ?? ?? ?? 83 C4 ?? F3 A5 8D 8D ?? + ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 + } + $encrypt_files_p2 = { + 8B 86 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 86 ?? ?? ?? ?? 89 85 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 + 86 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 86 ?? ?? ?? ?? 83 C6 ?? 81 FE ?? ?? ?? ?? 7C ?? + 6A ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? 53 + FF 15 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 8B F4 8B CA 33 C0 + C7 46 ?? ?? ?? ?? ?? 8D 79 ?? C7 46 ?? ?? ?? ?? ?? 66 89 06 66 8B 01 83 C1 ?? 66 85 + C0 75 ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 53 8B 1D ?? ?? ?? ?? FF D3 6A ?? 8D 45 ?? + 50 FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 + ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? + ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B + F8 89 BD ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? + ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? BE ?? ?? ?? ?? F3 A5 8B 45 ?? 8D 8D ?? ?? ?? ?? 50 68 + ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 + FF D3 6A ?? 8D 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 56 FF 15 + } + + condition: + uint16(0)==0x5A4D and $find_drives and $find_files and ( all of ($encrypt_files_p*)) +} +rule REVERSINGLABS_Win32_Ransomware_Dualshot : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Dualshot ransomware." + author = "ReversingLabs" + id = "17828c85-0f1b-581b-842a-24e6f26e0b4d" + date = "2020-11-20" + modified = "2020-11-20" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/ransomware/Win32.Ransomware.Dualshot.yara#L1-L112" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "a401369357901f42ad83227b025d3b14b3acd1f50705da82afbe8e4f85501919" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Ransomware" + tc_detection_name = "Dualshot" + tc_detection_factor = 5 + importance = 25 + + strings: + $internal_encrypt_file = { + 02 28 ?? ?? ?? ?? 0A 02 28 ?? ?? ?? ?? 0B 02 28 ?? ?? ?? ?? 0C 02 28 ?? ?? ?? ?? 03 28 + ?? ?? ?? ?? 0D 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 25 09 16 09 8E 69 6F ?? + ?? ?? ?? 6F ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 06 28 ?? ?? ?? ?? 02 72 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 07 28 ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 28 ?? ?? ?? + ?? 02 1B 19 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 00 02 28 ?? ?? ?? ?? DE ?? 26 + DE ?? 2A + } + $encrypt_files_p1 = { + 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? + 8E 69 32 ?? DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 11 ?? 13 + ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 11 ?? 28 ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? + 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? 72 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? + ?? ?? 72 ?? ?? ?? ?? 08 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? + ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 25 28 ?? ?? ?? ?? 11 + ?? 6F ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 8E 69 6F ?? ?? ?? ?? 6F ?? ?? + ?? ?? 06 72 ?? ?? ?? ?? 12 ?? 6F ?? ?? ?? ?? 26 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 08 1F ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 + ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 72 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 16 6F ?? + ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 11 ?? + 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 DE ?? + 26 DE ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 08 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 13 ?? 12 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 1B 8D ?? ?? ?? ?? 25 16 28 ?? ?? ?? ?? 6F ?? + ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 11 ?? A2 25 19 72 ?? ?? ?? ?? A2 25 1A 11 ?? + A2 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 09 2C ?? 73 ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 16 6F + ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 2B ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 11 ?? + 72 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2A + } + $encrypt_files_p2 = { + 02 16 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 02 17 9A 28 ?? ?? ?? ?? 13 ?? 02 + 18 9A 28 ?? ?? ?? ?? 2C ?? 02 18 9A 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 02 18 9A 1B 19 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 02 18 + 9A 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 2A 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 08 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 12 ?? 6F ?? ?? ?? ?? 26 07 72 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 18 8D ?? ?? + ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 00 + 1B 8D ?? ?? ?? ?? 25 16 28 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 08 20 ?? ?? ?? + ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 72 ?? ?? ?? ?? A2 + 25 1A 11 ?? 08 11 ?? 8E 69 6F ?? ?? ?? ?? 9A A2 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 11 ?? 6F ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 16 6F + ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 DE ?? 26 DE ?? 11 ?? 17 58 13 ?? 11 + ?? 1F ?? 3F ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 16 6F ?? ?? ?? ?? 25 17 + 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? + 6F ?? ?? ?? ?? 2A + } + $find_files_p1 = { + 73 ?? ?? ?? ?? 0A 06 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 72 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2D ?? 72 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 2C ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 0C 28 ?? ?? ?? ?? 16 28 ?? ?? + ?? ?? 02 8E 39 ?? ?? ?? ?? 02 16 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 16 0D + 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 17 0D 20 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 1F ?? 1B 28 ?? ?? ?? ?? 25 6F ?? ?? ?? ?? 13 ?? 6F ?? ?? ?? ?? 13 ?? 28 + ?? ?? ?? ?? 72 ?? ?? ?? ?? 08 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? + 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 25 11 ?? 16 11 + ?? 8E 69 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 8D ?? ?? ?? ?? 13 ?? 1C 8D ?? ?? ?? ?? 25 16 + 72 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 72 ?? ?? ?? ?? + A2 25 1A 72 ?? ?? ?? ?? A2 25 1B 72 ?? ?? ?? ?? A2 13 ?? 1F ?? 8D ?? ?? ?? ?? 25 16 72 + ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 72 ?? ?? ?? ?? A2 + 25 1A 72 ?? ?? ?? ?? A2 25 1B 72 ?? ?? ?? ?? A2 25 1C 72 ?? ?? ?? ?? A2 25 1D 72 ?? ?? + ?? ?? A2 25 1E 72 ?? ?? ?? ?? A2 25 1F ?? 72 ?? ?? ?? ?? A2 25 1F ?? 72 + } + $find_files_p2 = { + A2 13 ?? 1F ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 6F ?? ?? ?? ?? 1C 32 ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? + 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 72 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? + 72 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 13 ?? + 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 72 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? + ?? ?? 2C ?? 12 ?? 11 ?? 8E 69 17 58 28 ?? ?? ?? ?? 11 ?? 11 ?? 16 6F ?? ?? ?? ?? 11 ?? + A2 2B + } + + condition: + uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($internal_encrypt_file) +} +rule REVERSINGLABS_Linux_Backdoor_Krasue : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Krasue backdoor." + author = "ReversingLabs" + id = "3187eebf-ef70-585f-85cf-5813025c785e" + date = "2024-03-04" + modified = "2024-03-04" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/Linux.Backdoor.Krasue.yara#L1-L127" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "e2daa35ef9e0793062c9fb3bd8e4838e1e81ee3d228d8117b1c3b0e72eb8e151" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "Krasue" + tc_detection_factor = 5 + importance = 25 + + strings: + $switch_server = { + 8B 05 ?? ?? ?? ?? FF C0 3B 05 ?? ?? ?? ?? 89 05 ?? ?? ?? ?? 7C ?? C7 05 ?? ?? ?? ?? + ?? ?? ?? ?? 48 63 05 ?? ?? ?? ?? 85 C0 75 ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B + 15 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? C6 05 ?? ?? ?? ?? + ?? 89 15 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 66 89 15 ?? ?? 23 00 48 8B 04 C5 ?? ?? ?? ?? + 66 C7 05 ?? ?? 23 00 ?? ?? 8B 10 89 15 ?? ?? ?? ?? 66 8B 40 ?? 66 89 05 ?? ?? 23 00 + C3 + } + $get_hostname = { + 41 55 41 54 31 F6 55 53 31 C0 BF ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 + C0 0F 88 ?? ?? ?? ?? 48 89 E6 89 C7 89 C3 E8 ?? ?? ?? ?? 48 8B 6C 24 ?? 45 31 C9 31 + FF 41 89 D8 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 41 89 EC 48 63 ED 48 89 EE E8 ?? ?? ?? ?? + BE ?? ?? ?? ?? 48 89 C7 49 89 C5 E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? 48 63 D0 49 8D 74 15 + ?? 8D 50 ?? 48 63 D2 44 39 E2 41 89 D0 7D ?? 48 FF C2 41 80 7C 15 ?? ?? 75 ?? 44 89 + C1 41 FF C8 BA ?? ?? ?? ?? 29 C1 4D 63 C0 48 89 D7 83 E9 ?? 48 63 C9 F3 A4 41 C6 80 + ?? ?? ?? ?? ?? 4C 89 EF 48 89 EE E8 ?? ?? ?? ?? 89 DF E8 ?? ?? ?? ?? 48 81 C4 ?? ?? + ?? ?? 5B 5D 41 5C 41 5D C3 + } + $start_server_p1 = { + 41 57 41 56 31 D2 41 55 41 54 BE ?? ?? ?? ?? 55 53 89 FB BF ?? ?? ?? ?? 48 81 EC ?? + ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 89 05 ?? ?? ?? ?? 79 ?? 83 CF ?? E9 ?? ?? ?? ?? 48 8D + 4C 24 ?? 41 B8 ?? ?? ?? ?? BE ?? ?? ?? ?? BA ?? ?? ?? ?? 89 C7 C7 44 24 ?? ?? ?? ?? + ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? 48 89 D7 F3 AB 31 FF 66 C7 05 + ?? ?? 23 00 ?? ?? E8 ?? ?? ?? ?? 0F B7 FB 89 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 3D ?? + ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 66 89 05 ?? ?? 23 00 E8 ?? ?? ?? ?? 85 C0 78 + ?? 4C 8D A4 24 ?? ?? ?? ?? 4C 8D AC 24 ?? ?? ?? ?? 4C 8D 74 24 ?? C7 05 ?? ?? ?? ?? + ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 31 C9 41 B9 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? BA ?? ?? ?? + ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 48 89 C3 0F 88 ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? + ?? 4C 89 E7 83 FB ?? F3 AB 7E ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? + ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 44 8D 08 31 C9 BA + ?? ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 83 FB ?? 75 ?? BE ?? ?? ?? ?? 4C 89 + E7 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 05 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 89 05 + ?? ?? ?? ?? E9 ?? ?? ?? ?? 89 DA BE ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? 4C 89 E6 89 + C2 8A 06 89 F5 44 29 E5 3C ?? 75 ?? 80 7E ?? ?? 75 ?? 48 83 C6 ?? EB ?? 3C ?? 75 ?? + 80 7E ?? ?? 75 ?? 41 B8 ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? 4C 89 C7 4C 8B 05 ?? ?? ?? + ?? F3 AB 8B 7E ?? 66 8B 4E ?? 4C 89 06 C6 06 ?? 45 31 C0 C6 46 ?? ?? BE + } + $start_server_p2 = { + 66 C7 05 ?? ?? 23 00 ?? ?? 89 3D ?? ?? ?? ?? 66 89 0D ?? ?? 23 00 89 3D ?? ?? ?? ?? + 66 89 0D ?? ?? 23 00 48 89 F7 B9 ?? ?? ?? ?? 4C 89 E6 F3 AB E9 ?? ?? ?? ?? 85 ED 75 + ?? 48 63 DD BA ?? ?? ?? ?? BE ?? ?? ?? ?? 4C 01 E3 48 89 DF E8 ?? ?? ?? ?? 85 C0 75 + ?? 48 8D 7B ?? E8 ?? ?? ?? ?? 6B C0 ?? B9 ?? ?? ?? ?? BE ?? ?? ?? ?? 4C 89 EF 99 F7 + F9 31 C0 E8 ?? ?? ?? ?? EB ?? 8D 45 ?? 48 8D 54 24 ?? 48 98 85 C0 78 ?? 49 8B 0C 04 + 48 83 C2 ?? 48 83 E8 ?? 48 89 4A ?? C6 42 ?? ?? C6 42 ?? ?? EB ?? BA ?? ?? ?? ?? BE + ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 05 ?? ?? ?? ?? 89 E9 4C 89 F6 + 89 2D ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 05 ?? ?? ?? ?? B8 ?? ?? ?? ?? + 48 89 C7 F3 A4 BE ?? ?? ?? ?? 4C 89 EF E8 ?? ?? ?? ?? 31 C0 48 83 C9 ?? 4C 89 EF F2 + AE 48 89 C8 48 F7 D0 48 8D 50 ?? E9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 + DF E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 44 8B 0D ?? ?? ?? ?? 44 + 8B 3D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 89 4C 24 ?? 44 89 4C 24 ?? E8 ?? ?? ?? ?? 48 83 + EC ?? 41 89 C0 BA ?? ?? ?? ?? 8B 4C 24 ?? 4C 89 EF BE ?? ?? ?? ?? 31 C0 51 8B 0D ?? + ?? ?? ?? 41 57 53 44 8B 4C 24 ?? E8 ?? ?? ?? ?? 31 C0 48 83 C9 ?? 4C 89 EF F2 AE 48 + 83 C4 ?? 48 89 C8 48 F7 D0 48 8D 50 ?? 41 89 E8 4C 89 F1 4C 89 EE 8B 3D ?? ?? ?? ?? + E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 + } + $start_server_p3 = { + 85 C0 75 ?? 31 FF E8 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? + ?? 85 C0 75 ?? BF ?? ?? ?? ?? EB ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? + ?? ?? 85 C0 75 ?? BF ?? ?? ?? ?? EB ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? + ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 89 C7 E8 ?? ?? ?? ?? 45 85 FF 0F + 85 ?? ?? ?? ?? 48 8D 7C 24 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 41 89 C4 75 ?? 8B + 7C 24 ?? E8 ?? ?? ?? ?? 8B 7C 24 ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 7C 24 ?? BE ?? + ?? ?? ?? E8 ?? ?? ?? ?? 8B 7C 24 ?? E8 ?? ?? ?? ?? 48 8D 4B ?? 45 31 C0 BA ?? ?? ?? + ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 7C 24 ?? E8 + ?? ?? ?? ?? 8B 7C 24 ?? 48 8D B4 24 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 + 89 C3 7E ?? 4C 8D AC 24 ?? ?? ?? ?? 8D 04 2B 3D ?? ?? ?? ?? 7E ?? 8B 3D ?? ?? ?? ?? + BA ?? ?? ?? ?? 48 8D 4C 24 ?? 4C 89 EE 29 EA 41 89 E8 49 81 C5 ?? ?? ?? ?? 81 EB ?? + ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 8B 3D ?? ?? ?? ?? 48 8D 4C 24 ?? 41 89 E8 89 DA 4C 89 + EE E8 ?? ?? ?? ?? EB ?? 31 F6 BA ?? ?? ?? ?? 44 89 E7 E8 ?? ?? ?? ?? 85 C0 0F 85 + } + $send_encrypt = { + E8 ?? ?? ?? ?? 41 8D 7E ?? 49 89 C5 48 63 FF E8 ?? ?? ?? ?? 48 63 54 24 ?? 48 89 C7 + 4C 89 FE 48 8D 0C 13 C6 04 08 ?? 89 D1 48 01 C2 F3 A4 48 89 D7 48 89 EE 48 89 D9 44 + 89 F2 F3 A4 48 89 C6 EB ?? 8D 7B ?? 48 63 FF E8 ?? ?? ?? ?? 89 DA 49 89 C5 48 89 EE + 4C 89 EF E8 ?? ?? ?? ?? 44 8B 0D ?? ?? ?? ?? 4C 89 EE 44 89 E7 48 63 D0 41 B8 ?? ?? + ?? ?? 31 C9 E8 ?? ?? ?? ?? 48 83 C4 ?? 5B 5D 41 5C 41 5D 41 5E 41 5F C3 + } + $notify_server = { + 48 81 EC ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 48 89 E0 85 D2 7E ?? BE ?? ?? ?? ?? 89 D1 48 + 89 E7 F3 A4 48 63 D2 BE ?? ?? ?? ?? B9 ?? ?? ?? ?? 4C 8D 04 10 41 B9 ?? ?? ?? ?? 48 + 83 C2 ?? 4C 89 C7 41 B8 ?? ?? ?? ?? F3 A4 8B 3D ?? ?? ?? ?? 48 89 C6 E8 ?? ?? ?? ?? + 8B 05 ?? ?? ?? ?? 89 05 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 + } + + condition: + uint32(0)==0x464C457F and ($switch_server) and ($get_hostname) and ( all of ($start_server_p*)) and ($send_encrypt) and ($notify_server) +} +rule REVERSINGLABS_Bytecode_MSIL_Backdoor_Limerat : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects LimeRAT backdoor." + author = "ReversingLabs" + id = "c2ef6f27-3fb8-55f4-97a6-9e25a3d1ce49" + date = "2024-03-04" + modified = "2024-03-04" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/ByteCode.MSIL.Backdoor.LimeRAT.yara#L1-L91" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "03eaa2ac41950f036601222b32a28c03aae3b3445501e988e2f87e231a1a1522" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "LimeRAT" + tc_detection_factor = 5 + importance = 25 + + strings: + $persistence_mechanism = { + 02 2C ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 16 16 15 28 ?? ?? ?? ?? 26 2B ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 28 ?? ?? + ?? ?? 28 ?? ?? ?? ?? DE + } + $crypto_miner = { + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 8E 69 16 31 ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 0B 07 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 08 6F ?? ?? ?? ?? 0D 2B ?? 09 6F ?? ?? + ?? ?? 74 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 0A DE ?? 09 6F ?? ?? ?? ?? 2D ?? DE ?? 09 2C ?? 09 + 6F ?? ?? ?? ?? DC DE ?? 25 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? DE ?? 28 ?? ?? ?? ?? + 0A DE ?? 25 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? DE ?? 06 + } + $downloader = { + 73 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 7E + ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 2C ?? 06 7E ?? ?? ?? ?? 07 6F ?? + ?? ?? ?? 07 28 ?? ?? ?? ?? 26 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 2B ?? + 06 7E ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 07 28 ?? ?? ?? ?? 26 00 06 6F ?? ?? ?? ?? 14 0A + DE ?? 25 28 ?? ?? ?? ?? 0C 28 ?? ?? ?? ?? DE ?? DE ?? 25 28 ?? ?? ?? ?? 0D 28 ?? ?? + ?? ?? DE + } + $network_communication_p1 = { + 16 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 0B 28 ?? ?? + ?? ?? DE ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 0C 28 ?? ?? ?? + ?? DE ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 0D 28 ?? ?? ?? ?? + DE ?? 00 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 7E ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 15 6F ?? ?? ?? ?? 7E ?? + ?? ?? ?? 15 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 73 ?? + ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 11 ?? 14 72 ?? ?? ?? ?? 17 8D ?? ?? ?? ?? + 25 16 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 14 14 14 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? + ?? ?? ?? 15 16 28 ?? ?? ?? ?? 13 ?? 11 ?? 16 9A 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 26 11 + ?? 73 ?? ?? ?? ?? 17 11 ?? 8E 69 6F ?? ?? ?? ?? 9A 28 ?? ?? ?? ?? 80 ?? ?? ?? ?? 11 + ?? 6F ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? DE ?? DE ?? 11 ?? 2C + ?? 11 ?? 6F ?? ?? ?? ?? DC 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? + ?? 17 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 1F ?? 8D ?? ?? ?? ?? 25 16 72 ?? + ?? ?? ?? A2 25 17 7E ?? ?? ?? ?? A2 25 18 28 ?? ?? ?? ?? A2 25 19 7E ?? ?? ?? ?? A2 + } + $network_communication_p2 = { + 25 1A 28 ?? ?? ?? ?? A2 25 1B 7E ?? ?? ?? ?? A2 25 1C 72 ?? ?? ?? ?? A2 25 1D 7E ?? + ?? ?? ?? A2 25 1E 28 ?? ?? ?? ?? A2 25 1F ?? 72 ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? + ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? + A2 25 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? ?? A2 + 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 + 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? 8C ?? ?? + ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? + ?? A2 25 1F ?? 72 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 72 ?? ?? ?? ?? + A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 + 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 7E ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 2B ?? 7E + } + + condition: + uint16(0)==0x5A4D and ($persistence_mechanism) and ($crypto_miner) and ($downloader) and ( all of ($network_communication_p*)) +} +rule REVERSINGLABS_Bytecode_MSIL_Backdoor_Agentracoon : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects AgentRacoon backdoor." + author = "ReversingLabs" + id = "ad74d530-ffbd-589f-b941-3a5d9ec737b6" + date = "2023-12-15" + modified = "2023-12-15" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/ByteCode.MSIL.Backdoor.AgentRacoon.yara#L1-L128" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "3ba73f19f59c2e5880df820c52f16997047d7299eb14d421ae2ed8f3790bcfe9" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "AgentRacoon" + tc_detection_factor = 5 + importance = 25 + + strings: + $unpack_response_p1 = { + 17 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 03 18 91 9C 11 ?? 73 ?? ?? ?? ?? 0A 06 16 6F ?? ?? + ?? ?? 2D ?? 73 ?? ?? ?? ?? 7A 17 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 03 19 91 9C 11 ?? 73 + ?? ?? ?? ?? 0A 06 1A 6F ?? ?? ?? ?? 2C ?? 06 1B 6F ?? ?? ?? ?? 2C ?? 06 1C 6F ?? ?? + ?? ?? 2C ?? 06 1D 6F ?? ?? ?? ?? 2C ?? 73 ?? ?? ?? ?? 7A 1F ?? 0B 2B ?? 07 17 58 0B + 03 07 91 2D ?? 07 17 58 0B 03 8E 69 07 59 0C 08 8D ?? ?? ?? ?? 0D 03 07 09 16 08 28 + ?? ?? ?? ?? 1A 13 ?? 2B ?? 11 ?? 17 58 13 ?? 09 11 ?? 91 2D ?? 11 ?? 17 58 13 ?? 09 + 8E 69 11 ?? 59 0C 08 8D ?? ?? ?? ?? 13 ?? 09 11 ?? 11 ?? 16 08 28 ?? ?? ?? ?? 02 12 + ?? FE 15 ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? + 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? + ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? + ?? 12 ?? 07 1F ?? 59 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? + ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 11 ?? 1A 59 8D ?? ?? ?? ?? 7D ?? + ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? + ?? 12 ?? 1A 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 11 + ?? 7D ?? ?? ?? ?? 03 16 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 03 18 + } + $unpack_response_p2 = { + 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 03 1A 02 7C ?? ?? ?? ?? 7B ?? + ?? ?? ?? 16 18 28 ?? ?? ?? ?? 03 1C 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? + ?? ?? 03 1E 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 03 1F ?? 02 7C ?? + ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 03 1F ?? 02 7C ?? ?? ?? ?? 7B ?? ?? ?? + ?? 16 07 1F ?? 59 28 ?? ?? ?? ?? 09 16 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? + ?? ?? ?? 09 18 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 09 1A 02 7C ?? + ?? ?? ?? 7B ?? ?? ?? ?? 16 11 ?? 1A 59 28 ?? ?? ?? ?? 11 ?? 16 02 7C ?? ?? ?? ?? 7B + ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 11 ?? 18 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 + ?? ?? ?? ?? 11 ?? 1A 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 1A 28 ?? ?? ?? ?? 11 ?? 1E + 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 02 7C ?? + ?? ?? ?? 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 1F ?? 91 13 ?? 02 7C ?? ?? ?? ?? 11 ?? + 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 11 ?? 1F ?? 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 11 ?? + 28 ?? ?? ?? ?? 2A + } + $upload = { + 28 ?? ?? ?? ?? 0A 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 2D ?? DD ?? ?? ?? ?? 16 0B 38 ?? + ?? ?? ?? 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 0C 06 02 7C ?? ?? ?? ?? + 7B ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 28 ?? ?? ?? ?? 02 7C ?? ?? ?? ?? + 7B ?? ?? ?? ?? 1B 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 72 ?? ?? ?? ?? A2 11 ?? 17 02 7C ?? + ?? ?? ?? 7B ?? ?? ?? ?? 07 6F ?? ?? ?? ?? A2 11 ?? 18 72 ?? ?? ?? ?? A2 11 ?? ?? 06 + A2 11 ?? 1A 72 ?? ?? ?? ?? A2 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7C ?? ?? ?? ?? + 7B ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 07 + 14 6F ?? ?? ?? ?? 07 17 58 0B 07 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 3F + ?? ?? ?? ?? 02 7C ?? ?? ?? ?? 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 7C ?? ?? ?? ?? 73 ?? + ?? ?? ?? 7D ?? ?? ?? ?? DE 23 0D 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 09 + 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 2A + } + $perform_request = { + 05 6F ?? ?? ?? ?? 0A 06 04 3D ?? ?? ?? ?? 06 04 19 5B 18 5A 3F ?? ?? ?? ?? 05 16 06 + 19 5B 6F ?? ?? ?? ?? 0B 05 06 19 5B 06 19 5B 6F ?? ?? ?? ?? 0C 05 06 19 5B 18 5A 6F + ?? ?? ?? ?? 0D 02 07 28 ?? ?? ?? ?? 0B 02 08 28 ?? ?? ?? ?? 0C 02 09 28 ?? ?? ?? ?? + 0D 1F ?? 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 03 A2 11 ?? 17 72 ?? ?? ?? ?? A2 11 ?? 18 07 + A2 11 ?? 19 72 ?? ?? ?? ?? A2 11 ?? 1A 08 A2 11 ?? 1B 72 ?? ?? ?? ?? A2 11 ?? 1C 09 + A2 11 ?? 1D 72 ?? ?? ?? ?? A2 11 ?? 1E 02 28 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? + ?? A2 11 ?? 1F ?? 02 7B ?? ?? ?? ?? A2 11 ?? 28 ?? ?? ?? ?? 10 ?? 38 ?? ?? ?? ?? 06 + 04 19 5B 18 5A 3D ?? ?? ?? ?? 06 04 19 5B 3F ?? ?? ?? ?? 05 16 06 18 5B 6F ?? ?? ?? + ?? 13 ?? 05 06 18 5B 6F ?? ?? ?? ?? 13 ?? 02 11 ?? 28 ?? ?? ?? ?? 13 ?? 02 11 ?? 28 + ?? ?? ?? ?? 13 ?? 1F ?? 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 03 A2 11 ?? 17 72 ?? ?? ?? ?? + A2 11 ?? 18 11 ?? A2 11 ?? 19 72 ?? ?? ?? ?? A2 11 ?? 1A 11 ?? A2 11 ?? 1B 72 ?? ?? + ?? ?? A2 11 ?? 1C 02 28 ?? ?? ?? ?? A2 11 ?? 1D 72 ?? ?? ?? ?? A2 11 ?? 1E 02 7B ?? + ?? ?? ?? A2 11 ?? 28 ?? ?? ?? ?? 10 ?? 2B ?? 02 05 28 ?? ?? ?? ?? 13 ?? 1D 8D ?? ?? + ?? ?? 13 ?? 11 ?? 16 03 A2 11 ?? 17 72 ?? ?? ?? ?? A2 11 ?? 18 11 ?? A2 11 ?? 19 72 + ?? ?? ?? ?? A2 11 ?? 1A 02 28 ?? ?? ?? ?? A2 11 ?? 1B 72 ?? ?? ?? ?? A2 11 ?? 1C 02 + 7B ?? ?? ?? ?? A2 11 ?? 28 ?? ?? ?? ?? 10 ?? 05 2A + } + $get_txt_record = { + 14 0A 03 73 ?? ?? ?? ?? 0B 07 6F ?? ?? ?? ?? 0C 7E ?? ?? ?? ?? 1F ?? 73 ?? ?? ?? ?? + 0D 09 08 08 8E 69 6F ?? ?? ?? ?? 26 09 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 09 12 ?? 6F ?? ?? ?? ?? 13 ?? 09 6F ?? ?? ?? ?? 07 11 ?? 6F ?? ?? ?? ?? 07 6F ?? ?? + ?? ?? 13 ?? 28 ?? ?? ?? ?? 12 ?? 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? DE ?? 26 72 ?? + ?? ?? ?? 13 ?? DE ?? 11 ?? 2A + } + $main_loop = { + 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? + ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 18 16 16 6F ?? ?? ?? ?? 0A 06 28 + ?? ?? ?? ?? 2D ?? 2A 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 2A 7E ?? ?? + ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 07 6F ?? ?? ?? + ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 12 ?? 7B ?? ?? ?? ?? 0D 12 ?? 7B + ?? ?? ?? ?? 13 ?? 72 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 7E ?? ?? ?? ?? 19 11 ?? 11 ?? + 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 2D ?? 14 80 ?? ?? ?? ?? 2A 11 ?? 7E ?? ?? ?? ?? 28 ?? + ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? + ?? ?? 11 ?? 17 58 13 ?? 11 ?? 09 32 ?? 7E ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 0B 73 ?? + ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 6F ?? ?? ?? + ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 7E ?? ?? ?? ?? 07 + 17 6F ?? ?? ?? ?? 13 ?? 11 ?? 7E ?? ?? ?? ?? 1A 16 16 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? + 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 DD ?? ?? ?? ?? 26 DE ?? 2A + } + + condition: + uint16(0)==0x5A4D and ( all of ($unpack_response_p*)) and ($upload) and ($perform_request) and ($get_txt_record) and ($main_loop) +} +rule REVERSINGLABS_Linux_Trojan_Chinaz : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects ChinaZ trojan." + author = "ReversingLabs" + id = "f99c224b-db54-5cae-b5fb-8939ebee3250" + date = "2024-07-31" + modified = "2024-07-31" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/Linux.Trojan.ChinaZ.yara#L1-L246" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "d8d08f4f3f36ecc7b219b6b1aae3c76d26e8fb3a44444763929190c6124532ff" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Trojan" + tc_detection_name = "ChinaZ" + tc_detection_factor = 5 + importance = 25 + + strings: + $collect_system_information_32_p1 = { + 55 57 56 53 81 EC ?? ?? ?? ?? 8D 5C 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? + ?? 89 44 24 ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 + ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 + ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 31 31 C9 89 C6 8D 44 24 ?? 31 + FF C7 44 24 ?? ?? ?? ?? ?? 01 CE 89 04 24 11 D7 E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? + E8 ?? ?? ?? ?? 0F 31 89 C1 31 C0 31 DB 01 C1 8D 44 24 ?? 11 D3 C7 44 24 ?? ?? ?? ?? + ?? 89 04 24 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 8B 44 24 ?? C7 04 24 ?? ?? ?? ?? + 29 F1 19 FB 31 ED 2B 44 24 ?? 89 4C 24 ?? 8D B4 24 ?? ?? ?? ?? 89 5C 24 ?? 89 F7 69 + C0 ?? ?? ?? ?? DF 6C 24 ?? 03 44 24 ?? 2B 44 24 ?? D9 7C 24 ?? 89 44 24 ?? DB 44 24 + ?? DE F9 0F B7 44 24 ?? B4 ?? 66 89 44 24 ?? D9 6C 24 ?? DB 5C 24 ?? D9 6C 24 ?? 8B + 5C 24 ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? + 8D 9C 24 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? A1 + } + $collect_system_information_32_p2 = { + C7 04 24 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 89 E8 B9 ?? ?? ?? ?? F3 AB 89 + DF B1 ?? F3 AB 89 DF 89 5C 24 ?? 89 74 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 C7 44 24 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 8B 54 24 ?? 89 E8 B9 ?? ?? ?? ?? F3 AB 89 F7 C7 44 24 ?? ?? ?? ?? ?? 89 D0 + C1 F8 ?? C1 E8 ?? 01 D0 C1 F8 ?? 89 44 24 ?? 89 1C 24 89 44 24 ?? E8 ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 C2 A1 ?? ?? ?? + ?? 89 54 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 89 E8 B9 ?? ?? ?? ?? F3 AB 89 DF B1 ?? F3 + AB 89 5C 24 ?? 89 74 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 54 24 ?? 85 D2 0F + 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? + ?? A1 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? + ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 + 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 5B 5E 5F 5D + C3 + } + $send_system_info_32 = { + 57 56 53 81 EC ?? ?? ?? ?? 8D 5C 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? + 89 44 24 ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? + ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? + 0F 31 31 C9 89 C6 8D 44 24 ?? 31 FF C7 44 24 ?? ?? ?? ?? ?? 01 CE 89 04 24 11 D7 E8 + ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 31 89 C1 31 C0 31 DB 01 C1 8D 44 + 24 ?? 11 D3 C7 44 24 ?? ?? ?? ?? ?? 89 04 24 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? + 8B 44 24 ?? C7 04 24 ?? ?? ?? ?? 29 F1 19 FB 2B 44 24 ?? 89 4C 24 ?? 89 5C 24 ?? 69 + C0 ?? ?? ?? ?? DF 6C 24 ?? 03 44 24 ?? 2B 44 24 ?? D9 7C 24 ?? 89 44 24 ?? DB 44 24 + ?? DE F9 0F B7 44 24 ?? B4 ?? 66 89 44 24 ?? D9 6C 24 ?? DB 5C 24 ?? D9 6C 24 ?? 8B + 5C 24 ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? + C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? C7 04 24 ?? ?? + ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + 89 04 24 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5B 5E 5F C3 + } + $parse_c2_commands_32 = { + 55 31 C0 57 B9 ?? ?? ?? ?? 56 53 81 EC ?? ?? ?? ?? 8D 9C 24 ?? ?? ?? ?? 0F B6 94 24 + ?? ?? ?? ?? 89 DF F3 AB C7 04 24 ?? ?? ?? ?? 88 94 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D + 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 83 E0 ?? 89 84 24 ?? ?? ?? ?? 90 A1 ?? ?? ?? + ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? 89 04 24 E8 ?? ?? ?? + ?? 85 C0 0F 84 ?? ?? ?? ?? 8B B4 24 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? 89 74 24 ?? + C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 83 F8 ?? 74 ?? 83 F8 ?? 0F + 84 ?? ?? ?? ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 + ?? ?? ?? ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 83 FE ?? 0F 84 ?? + ?? ?? ?? 83 FE ?? 0F 85 ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? F3 AB + 8D B4 24 ?? ?? ?? ?? B0 ?? 8D BC 24 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? B1 ?? F3 A5 89 + D6 8B BC 24 ?? ?? ?? ?? F7 C7 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? F7 C7 ?? ?? ?? ?? 0F 85 + ?? ?? ?? ?? 89 C1 C1 E9 ?? A8 ?? F3 A5 0F 85 ?? ?? ?? ?? A8 ?? 0F 85 ?? ?? ?? ?? 89 + 54 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? + 81 C4 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5B 5E 5F 5D C3 + } + $dns_flood_32_p1 = { + 55 57 56 53 81 EC ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 5C 24 ?? 8B + B4 24 ?? ?? ?? ?? B8 ?? ?? ?? ?? F6 C3 ?? 89 DF 0F 85 ?? ?? ?? ?? 89 C1 C1 E9 ?? A8 + ?? F3 A5 0F 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? + 89 F7 89 44 24 ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 66 C7 44 24 ?? ?? ?? 66 C7 44 24 ?? ?? ?? E8 ?? ?? ?? ?? 31 D2 + C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? F7 35 ?? ?? ?? + ?? 8B 04 95 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 C5 8D + 44 24 ?? 89 44 24 ?? 89 2C 24 E8 ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? F3 AB 8D 54 24 ?? + 89 14 24 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 5C 24 ?? 89 84 24 ?? + ?? ?? ?? 0F B7 44 24 ?? 66 89 84 24 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 89 04 24 E8 ?? + ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 89 14 24 89 74 24 ?? 89 54 24 ?? C6 84 24 ?? ?? ?? ?? + ?? C6 84 24 ?? ?? ?? ?? ?? 66 C7 84 24 ?? ?? ?? ?? ?? ?? 66 C7 84 24 ?? ?? ?? ?? ?? + ?? 66 C7 84 24 ?? ?? ?? ?? ?? ?? 66 C7 84 24 ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 54 + } + $dns_flood_32_p2 = { + 24 ?? 89 D1 8B 39 83 C1 ?? 8D 87 ?? ?? ?? ?? F7 D7 21 F8 25 ?? ?? ?? ?? 74 ?? A9 ?? + ?? ?? ?? 0F 84 ?? ?? ?? ?? 00 C0 89 D7 83 D9 ?? 29 D1 8D 84 0C ?? ?? ?? ?? 66 C7 00 + ?? ?? 66 C7 40 ?? ?? ?? 8B 0F 83 C7 ?? 8D 81 ?? ?? ?? ?? F7 D1 21 C8 25 ?? ?? ?? ?? + 74 ?? A9 ?? ?? ?? ?? 75 ?? C1 E8 ?? 83 C7 ?? 00 C0 8D 44 24 ?? 83 DF ?? C7 44 24 ?? + ?? ?? ?? ?? 29 D7 89 04 24 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 54 24 ?? 89 74 + 24 ?? 89 84 24 ?? ?? ?? ?? 0F B7 44 24 ?? 89 14 24 66 89 84 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 8D 94 24 ?? ?? ?? ?? 89 5C 24 ?? 89 14 24 E8 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? + 83 B8 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 83 C7 ?? 89 C2 + C1 FA ?? F7 F9 8D 42 ?? 66 C1 C8 ?? 66 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 31 D2 C7 + 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? 89 2C 24 F7 35 ?? ?? ?? ?? + 8B 04 95 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? 8D 44 24 ?? 89 44 + 24 ?? E8 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 83 80 ?? ?? ?? ?? ?? 83 90 ?? ?? ?? ?? ?? + 83 3D ?? ?? ?? ?? ?? 74 ?? C7 04 24 ?? ?? ?? ?? E8 + } + $collect_system_information_64_p1 = { + 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 8D 7C 24 ?? E8 ?? ?? ?? ?? 4C 8D 84 24 ?? + ?? ?? ?? 48 8D 4C 24 ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? + ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? + ?? 0F 31 48 89 D3 48 8D 7C 24 ?? 31 F6 48 C1 E3 ?? 89 C0 48 01 C3 E8 ?? ?? ?? ?? BF + ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 31 48 89 D5 48 8D 7C 24 ?? 31 F6 48 C1 E5 ?? 89 C0 45 + 31 E4 48 01 C5 E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 2B 44 24 ?? 48 29 DD 48 8B 54 24 ?? + 2B 54 24 ?? BF ?? ?? ?? ?? F2 48 0F 2A C5 48 8D AC 24 ?? ?? ?? ?? 69 C0 ?? ?? ?? ?? + 01 D0 F2 0F 2A C8 F2 0F 5E C1 F2 0F 2C D8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 C1 BE ?? + ?? ?? ?? BF ?? ?? ?? ?? 31 C0 41 89 D8 48 8D 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 05 + ?? ?? ?? ?? BF ?? ?? ?? ?? 89 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? BE + ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 E0 B9 ?? ?? ?? ?? 48 89 EF F3 48 AB + } + $collect_system_information_64_p2 = { + 48 89 DF 48 89 DA 48 89 EE B1 ?? F3 48 AB BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 54 24 + ?? BE ?? ?? ?? ?? 48 89 DF 31 C0 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 E0 B9 + ?? ?? ?? ?? 48 89 DF F3 48 AB 8B 44 24 ?? BE ?? ?? ?? ?? 48 89 DF 8D 90 ?? ?? ?? ?? + 85 C0 0F 49 D0 31 C0 C1 FA ?? 89 54 24 ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 DE BF + ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? BE ?? + ?? ?? ?? BF ?? ?? ?? ?? 41 89 C5 E8 ?? ?? ?? ?? 4C 89 E0 B9 ?? ?? ?? ?? 48 89 EF F3 + 48 AB 48 89 DF 48 89 DA 48 89 EE B1 ?? F3 48 AB BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 45 85 + ED 75 ?? BA ?? ?? ?? ?? 48 89 DE BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 3D ?? ?? ?? ?? + E8 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? BE ?? ?? ?? ?? BF + ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 7C 24 ?? 31 C9 + BA ?? ?? ?? ?? 31 F6 E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5D 41 5C 41 5D C3 + } + $send_system_info_64 = { + 55 53 48 81 EC ?? ?? ?? ?? 48 8D 7C 24 ?? E8 ?? ?? ?? ?? 4C 8D 84 24 ?? ?? ?? ?? 48 + 8D 4C 24 ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? BE ?? + ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 31 48 89 D3 31 F6 48 89 E7 48 C1 E3 ?? 89 + C0 48 01 C3 E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 31 48 89 D5 48 8D 7C 24 + ?? 31 F6 89 C0 48 C1 E5 ?? 48 01 C5 E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 2B 04 24 48 29 + DD 48 8B 54 24 ?? 2B 54 24 ?? BF ?? ?? ?? ?? F2 48 0F 2A C5 69 C0 ?? ?? ?? ?? 01 D0 + F2 0F 2A C8 F2 0F 5E C1 F2 0F 2C D8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 C1 BE ?? ?? ?? + ?? BF ?? ?? ?? ?? 31 C0 41 89 D8 E8 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? BA ?? ?? ?? ?? + BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? BA ?? ?? ?? ?? + BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5B 5D C3 + } + $parse_c2_commands_64 = { + 41 57 31 C0 49 89 FF B9 ?? ?? ?? ?? 41 56 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 + 8D 9C 24 ?? ?? ?? ?? 40 88 B4 24 ?? ?? ?? ?? 4C 8D AC 24 ?? ?? ?? ?? 4C 8D A4 24 ?? + ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 DF F3 48 AB C7 07 ?? ?? ?? ?? BF ?? ?? ?? ?? + E8 ?? ?? ?? ?? 48 8D 43 ?? 48 89 84 24 ?? ?? ?? ?? 0F 1F 00 8B 3D ?? ?? ?? ?? 31 C9 + BA ?? ?? ?? ?? 48 89 DE E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 44 8B B4 24 ?? ?? + ?? ?? 45 85 F6 0F 84 ?? ?? ?? ?? 31 C0 44 89 F6 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 84 + 24 ?? ?? ?? ?? 83 F8 ?? 74 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 41 83 FE ?? 0F 84 ?? ?? ?? + ?? 41 83 FE ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 41 83 FE ?? 0F 84 ?? ?? + ?? ?? 41 83 FE ?? 0F 84 ?? ?? ?? ?? 41 83 FE ?? 0F 84 ?? ?? ?? ?? 41 83 FE ?? 0F 85 + ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? F3 48 AB 48 8B 84 24 ?? ?? + ?? ?? 4C 8B 9C 24 ?? ?? ?? ?? 4C 8B 94 24 ?? ?? ?? ?? 4C 8B 8C 24 ?? ?? ?? ?? 4C 8B + 84 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? C7 07 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? + 48 8B 84 24 ?? ?? ?? ?? 48 8B BC 24 ?? ?? ?? ?? 48 8B B4 24 ?? ?? ?? ?? 48 8B 94 24 + ?? ?? ?? ?? 4C 8B B4 24 ?? ?? ?? ?? 4C 8B AC 24 ?? ?? ?? ?? 4C 8B A4 24 ?? ?? ?? ?? + 48 8B AC 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 84 24 + ?? ?? ?? ?? 4C 89 9C 24 ?? ?? ?? ?? 4C 89 94 24 ?? ?? ?? ?? 4C 89 8C 24 ?? ?? ?? ?? + 4C 89 84 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? 48 89 B4 24 + ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? 4C 89 B4 24 ?? ?? ?? ?? 4C 89 AC 24 ?? ?? ?? ?? + 4C 89 A4 24 ?? ?? ?? ?? 48 89 AC 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 84 24 + ?? ?? ?? ?? 49 89 57 ?? 48 8B 94 24 ?? ?? ?? ?? 49 89 77 ?? 48 8D B4 24 + } + $dns_flood_64_p1 = { + 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 49 89 + FC BB ?? ?? ?? ?? 48 8D 7C 24 ?? 48 89 D9 4C 89 E6 48 8D AC 24 ?? ?? ?? ?? F3 48 A5 + 8B 06 48 89 CB 89 07 0F B7 46 ?? 8B 35 ?? ?? ?? ?? 66 89 47 ?? BF ?? ?? ?? ?? 31 C0 + E8 ?? ?? ?? ?? 48 C7 04 24 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 66 C7 04 24 ?? ?? + 66 C7 44 24 ?? ?? ?? E8 ?? ?? ?? ?? 31 D2 BE ?? ?? ?? ?? BF ?? ?? ?? ?? F7 35 ?? ?? + ?? ?? 89 D2 8B 04 95 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? BA ?? ?? + ?? ?? 48 89 E6 89 C7 41 89 C5 E8 ?? ?? ?? ?? 48 89 D8 B9 ?? ?? ?? ?? 48 89 EF F3 48 + AB 48 8D 7C 24 ?? BE ?? ?? ?? ?? 48 8D 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? + 48 8D 7D ?? 48 8D 74 24 ?? 89 84 24 ?? ?? ?? ?? 0F B7 44 24 ?? 66 89 84 24 ?? ?? 00 + 00 E8 ?? ?? ?? ?? 48 89 EE 48 89 DF C6 84 24 ?? ?? ?? ?? ?? C6 84 24 + } + $dns_flood_64_p2 = { + 66 C7 84 24 ?? ?? 00 00 ?? ?? 66 C7 84 24 ?? ?? 00 00 ?? ?? 66 C7 84 24 ?? ?? 00 00 + ?? ?? 66 C7 84 24 ?? ?? 00 00 ?? ?? E8 ?? ?? ?? ?? 48 89 D9 8B 01 48 83 C1 ?? 8D 90 + ?? ?? ?? ?? F7 D0 21 C2 81 E2 ?? ?? ?? ?? 74 ?? 89 D0 C1 E8 ?? F7 C2 ?? ?? ?? ?? 0F + 44 D0 48 8D 41 ?? 48 0F 44 C8 00 D2 48 83 D9 ?? 48 29 D9 48 8D 84 0C ?? ?? ?? ?? 48 + 8D 8C 24 ?? ?? ?? ?? 66 C7 00 ?? ?? 66 C7 40 ?? ?? ?? 48 89 CB 8B 13 48 83 C3 ?? 8D + 82 ?? ?? ?? ?? F7 D2 21 D0 25 ?? ?? ?? ?? 74 ?? 89 C2 48 8D 7C 24 ?? BE ?? ?? ?? ?? + C1 EA ?? A9 ?? ?? ?? ?? 0F 44 C2 48 8D 53 ?? 48 0F 44 DA 00 C0 48 83 DB ?? 48 29 CB + E8 ?? ?? ?? ?? 8B 44 24 ?? 48 8D BC 24 ?? ?? ?? ?? 48 89 EE 89 84 24 ?? ?? ?? ?? 0F + B7 44 24 ?? 66 89 84 24 ?? ?? 00 00 E8 ?? ?? ?? ?? 48 8D 7D ?? 48 8D 74 24 ?? E8 ?? + ?? ?? ?? 41 83 BC 24 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 C2 B9 ?? ?? + ?? ?? 83 C3 ?? C1 FA ?? F7 F9 8D 42 ?? 66 C1 C8 ?? 66 89 84 24 ?? ?? 00 00 E8 ?? ?? + ?? ?? 31 D2 48 8D B4 24 ?? ?? ?? ?? 31 C9 F7 35 ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? 49 89 + E0 44 89 EF 89 D2 8B 04 95 ?? ?? ?? ?? 48 63 D3 89 44 24 ?? E8 ?? ?? ?? ?? 49 83 84 + 24 ?? ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 74 ?? BF ?? ?? ?? ?? E8 + } + + condition: + uint32(0)==0x464C457F and ((( all of ($collect_system_information_32_p*)) and ($send_system_info_32) and ($parse_c2_commands_32) and ( all of ($dns_flood_32_p*))) or (( all of ($collect_system_information_64_p*)) and ($send_system_info_64) and ($parse_c2_commands_64) and ( all of ($dns_flood_64_p*)))) +} +rule REVERSINGLABS_Win64_Backdoor_Konni : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Konni backdoor." + author = "ReversingLabs" + id = "c45c23c6-be15-58cc-ae4d-631bed4a3bb2" + date = "2023-12-07" + modified = "2023-12-07" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/Win64.Backdoor.Konni.yara#L1-L205" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "37c45e3ed23ca9f4de876f666c9f6d9bf7eee5cb1650b02cdd9f58e2ccc4b5cb" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "Konni" + tc_detection_factor = 5 + importance = 25 + + strings: + $network_communication_p1 = { + 48 8B C4 53 55 57 41 54 41 55 41 56 41 57 48 83 EC ?? 48 8B 3D ?? ?? ?? ?? 45 33 FF + 48 8B D9 4C 8D A7 ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? 49 8B CC 44 89 78 ?? 44 89 78 + ?? 45 8B F7 44 89 78 ?? 41 8B EF E8 ?? ?? ?? ?? 4C 8D 8F ?? ?? ?? ?? 4C 8D 05 ?? ?? + ?? ?? BA ?? ?? ?? ?? 49 8B CC 48 89 5C 24 ?? 48 89 7C 24 ?? E8 ?? ?? ?? ?? 48 8D 9F + ?? ?? ?? ?? 48 8B CB E8 ?? ?? ?? ?? 41 BD ?? ?? ?? ?? 45 33 C9 45 33 C0 33 C9 41 8B + D5 44 89 7C 24 ?? FF 15 ?? ?? ?? ?? 48 8B F8 48 89 44 24 ?? 48 85 C0 75 ?? 83 C8 ?? + 48 83 C4 ?? 41 5F 41 5E 41 5D 41 5C 5F 5D 5B C3 4C 89 7C 24 ?? 44 89 7C 24 ?? 41 B8 + ?? ?? ?? ?? 45 33 C9 48 8B D3 48 8B C8 C7 44 24 ?? ?? ?? ?? ?? 48 89 B4 24 ?? ?? ?? + ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 4C 89 7C 24 ?? FF 15 ?? ?? ?? ?? 48 8B F0 48 85 + C0 0F 84 ?? ?? ?? ?? 4C 89 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 45 + 33 C9 4D 8B C4 48 8B C8 4C 89 7C 24 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 4C 89 7C 24 + ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 85 C0 74 ?? 45 33 C9 45 33 C0 33 D2 48 8B C8 44 89 + 7C 24 ?? FF 15 ?? ?? ?? ?? 45 33 C9 45 33 C0 48 8B CB 85 C0 74 ?? 48 8D 94 24 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 45 33 C9 48 8B CB 45 33 C0 33 D2 FF 15 ?? ?? ?? + ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? + 41 8B C5 E9 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 85 C0 75 ?? 48 8B CB EB ?? FF C0 B9 ?? + ?? ?? ?? 8B D0 89 84 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 4C 8B E0 48 85 C0 74 ?? 44 8B + } + $network_communication_p2 = { + 84 24 ?? ?? ?? ?? 33 D2 48 8B C8 E8 ?? ?? ?? ?? 45 33 C9 4C 89 7C 24 ?? 48 8D 0D ?? + ?? ?? ?? 45 8D 41 ?? BA ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 4C 8B E8 48 8B CB 48 83 F8 ?? 75 ?? 45 33 C9 45 33 C0 33 D2 FF 15 + ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? + ?? ?? ?? 83 C8 ?? E9 ?? ?? ?? ?? 44 8B 84 24 ?? ?? ?? ?? 4C 8D 8C 24 ?? ?? ?? ?? 49 + 8B D4 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? BF ?? ?? ?? ?? 0F 1F 00 44 39 BC 24 + ?? ?? ?? ?? 74 ?? 48 8D 15 ?? ?? ?? ?? 49 8B CC 41 8B EF E8 ?? ?? ?? ?? 48 85 C0 0F + 45 EF 3B EF 74 ?? 44 8B 84 24 ?? ?? ?? ?? 4C 8D 8C 24 ?? ?? ?? ?? 49 8B D4 49 8B CD + 4C 89 7C 24 ?? FF 15 ?? ?? ?? ?? 44 8B 84 24 ?? ?? ?? ?? 44 03 B4 24 ?? ?? ?? ?? 33 + D2 49 8B CC E8 ?? ?? ?? ?? 44 8B 84 24 ?? ?? ?? ?? 4C 8D 8C 24 ?? ?? ?? ?? 49 8B D4 + 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8B 7C 24 ?? 49 8B CD FF 15 ?? + ?? ?? ?? 49 8B CC FF 15 ?? ?? ?? ?? 45 33 C9 45 33 C0 33 D2 48 8B CB FF 15 ?? ?? ?? + ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? + 83 C8 ?? 45 85 F6 0F 44 E8 8B C5 48 8B B4 24 ?? ?? ?? ?? 48 83 C4 ?? 41 5F 41 5E 41 + 5D 41 5C 5F 5D 5B C3 + } + $handle_c2_commands_p1 = { + 48 89 5C 24 ?? 48 89 74 24 ?? 57 48 81 EC ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 + 48 89 84 24 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? ?? 48 8D 54 24 ?? 33 FF 48 8B CE 89 7C 24 + ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 85 C0 75 ?? 83 C8 ?? E9 ?? ?? ?? ?? 48 8B 15 ?? ?? + ?? ?? 48 8B 08 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 4B + ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 4B ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 + 75 ?? 48 8B 4B ?? 8D 50 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 4C 24 ?? 33 D2 41 B8 + ?? ?? ?? ?? 66 89 7C 24 ?? E8 ?? ?? ?? ?? 48 8B 4B ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? + 48 8B 15 ?? ?? ?? ?? 48 8B 4B ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 53 ?? 48 8D 0D ?? + ?? ?? ?? 45 33 C0 FF 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E9 ?? ?? + ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 4B ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 4B ?? E8 ?? + ?? ?? ?? 69 C0 ?? ?? ?? ?? 89 05 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 + 8B 4B ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 4B ?? E8 ?? ?? ?? ?? 69 C0 ?? ?? ?? ?? 89 + } + $handle_c2_commands_p2 = { + 05 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 63 4C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 8B 4C CB ?? E8 + ?? ?? ?? ?? 48 8B CE 85 C0 75 ?? 8D 50 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 D2 E8 ?? + ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 0B E8 ?? ?? ?? ?? 48 63 4C 24 ?? + 48 8B 15 ?? ?? ?? ?? 48 8B 4C CB ?? 85 C0 75 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 48 63 4C + 24 ?? 48 8D 15 ?? ?? ?? ?? 48 8B 4C CB ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 3B 48 83 + C9 ?? 33 C0 66 F2 AF 33 D2 48 F7 D1 48 8D 0C 4E E8 ?? ?? ?? ?? EB ?? 48 8B 3B 48 83 + C9 ?? 33 C0 66 F2 AF 8D 50 ?? 48 F7 D1 48 8D 0C 4E E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? + ?? 85 C0 75 ?? 8D 48 ?? EB ?? 33 C9 E8 ?? ?? ?? ?? 8B F8 48 8B CB FF 15 ?? ?? ?? ?? + 8B C7 48 8B 8C 24 ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 4C 8D 9C 24 ?? ?? ?? ?? 49 8B + 5B ?? 49 8B 73 ?? 49 8B E3 5F C3 + } + $create_cab_file_and_upload_p1 = { + 48 89 5C 24 ?? 55 56 57 41 54 41 57 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 + 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 85 ?? ?? ?? ?? 4C 8B 3D ?? ?? ?? ?? 33 DB 48 8B F1 + 48 8D 4D ?? 33 D2 41 B8 ?? ?? ?? ?? 44 8B E3 89 5C 24 ?? 89 5C 24 ?? 66 89 5D ?? E8 + ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? 66 89 9D ?? ?? 00 00 E8 ?? + ?? ?? ?? 33 C0 48 8D 4C 24 ?? 66 89 5C 24 ?? 48 89 44 24 ?? 89 44 24 ?? 66 89 44 24 + ?? FF 15 ?? ?? ?? ?? 0F B7 54 24 ?? 0F B7 4C 24 ?? 44 0F B7 44 24 ?? 0F B7 44 24 ?? + 0F B7 7C 24 ?? 89 54 24 ?? 89 44 24 ?? 89 4C 24 ?? 89 7C 24 ?? 44 89 44 24 ?? 4C 8D + 05 ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? + ?? 48 8D 4D ?? 33 D2 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 55 ?? B9 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 4C 8D 4D ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4D ?? 45 33 C0 FF 15 ?? ?? ?? + ?? 48 8D 4D ?? FF 15 ?? ?? ?? ?? 8D 53 ?? 48 8B CE E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? + ?? 48 8B C8 48 8B F8 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8B CF E8 ?? + ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D + 15 ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8B CF E8 + ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? 85 C0 74 ?? 48 + } + $create_cab_file_and_upload_p2 = { + 8D 4D ?? 48 8B D6 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 0B C0 E9 ?? ?? ?? ?? 48 8D 55 ?? 45 + 33 C0 48 8B CE FF 15 ?? ?? ?? ?? 45 33 C9 48 89 5C 24 ?? 48 8D 4D ?? 45 8D 41 ?? BA + ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 4C 89 AC 24 ?? ?? ?? ?? 89 5C 24 ?? C7 44 24 ?? + ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B F8 48 83 F8 ?? 75 ?? 8B C3 EB ?? 33 D2 48 8B C8 + FF 15 ?? ?? ?? ?? 8B F0 85 C0 75 ?? 48 8B CF FF 15 ?? ?? ?? ?? 8B C3 EB ?? FF C6 B9 + ?? ?? ?? ?? 8B D6 44 8B EE FF 15 ?? ?? ?? ?? 4C 8B E0 48 85 C0 75 ?? 48 8B CF FF 15 + ?? ?? ?? ?? 8B C3 EB ?? 4D 8B C5 33 D2 48 8B C8 E8 ?? ?? ?? ?? 4C 8D 4C 24 ?? 44 8B + C6 49 8B D4 48 8B CF 48 89 5C 24 ?? FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 8B + 44 24 ?? 89 44 24 ?? 85 C0 75 ?? 83 C8 ?? E9 ?? ?? ?? ?? 48 8D 4D ?? 4C 89 B4 24 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 44 8B 6C 24 ?? B9 ?? ?? ?? ?? 41 83 C5 ?? 41 8B FD 41 8B + D5 48 89 7C 24 ?? FF 15 ?? ?? ?? ?? 4C 8B F0 48 85 C0 0F 84 ?? ?? ?? ?? 44 8B C7 33 + D2 48 8B C8 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B F0 48 85 C0 74 ?? 33 + C0 48 83 C9 ?? 4C 8D 86 ?? ?? ?? ?? 48 8D BD ?? ?? ?? ?? 66 F2 AF 49 89 00 49 89 40 + ?? 48 F7 D1 49 89 40 ?? 49 89 40 ?? 48 FF C9 03 C9 74 ?? 8B D1 48 8D 8D ?? ?? ?? ?? + E8 ?? ?? ?? ?? EB ?? 48 8B F3 49 89 B7 ?? ?? ?? ?? 48 85 F6 0F 84 ?? ?? ?? ?? 44 8B + } + $create_cab_file_and_upload_p3 = { + 44 24 ?? 4D 8B CE 49 8B D4 48 8B CE 44 89 6C 24 ?? E8 ?? ?? ?? ?? 49 8B 8F ?? ?? ?? + ?? 48 85 C9 74 ?? E8 ?? ?? ?? ?? 49 8B CC 49 89 9F ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 + 83 C9 ?? 33 C0 48 8D BD ?? ?? ?? ?? 66 F2 AF 48 F7 D1 41 8D 84 4D ?? ?? ?? ?? B9 ?? + ?? ?? ?? 8B D0 89 44 24 ?? FF 15 ?? ?? ?? ?? 4C 8B E8 48 85 C0 0F 84 ?? ?? ?? ?? 44 + 8B 44 24 ?? 33 D2 48 8B C8 E8 ?? ?? ?? ?? 8B 54 24 ?? 4C 8D 8D ?? ?? ?? ?? 4C 8D 05 + ?? ?? ?? ?? 49 8B CD E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 49 8B D6 8B C8 4C 8B C7 89 44 24 + ?? 49 03 CD E8 ?? ?? ?? ?? 8B 4C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 03 CF 41 B8 ?? ?? ?? + ?? 49 03 CD E8 ?? ?? ?? ?? 49 8B CE FF 15 ?? ?? ?? ?? 49 8D 8F ?? ?? ?? ?? E8 ?? ?? + ?? ?? 45 33 C9 45 33 C0 41 8D 51 ?? 33 C9 89 5C 24 ?? FF 15 ?? ?? ?? ?? 48 8B F0 48 + 85 C0 0F 84 ?? ?? ?? ?? 48 89 5C 24 ?? 89 5C 24 ?? 49 8D 97 ?? ?? ?? ?? 41 B8 ?? ?? + ?? ?? 45 33 C9 48 8B C8 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 89 5C 24 + ?? FF 15 ?? ?? ?? ?? 4C 8B E0 48 85 C0 0F 84 ?? ?? ?? ?? 49 8D 8F ?? ?? ?? ?? 33 D2 + 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4D 8D 8F ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 49 8D 8F + ?? ?? ?? ?? BA ?? ?? ?? ?? 4C 89 7C 24 ?? E8 ?? ?? ?? ?? 48 89 5C 24 ?? C7 44 24 ?? + ?? ?? ?? ?? 4D 8D 87 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 45 33 C9 49 8B CC 48 89 5C 24 + ?? C7 44 24 ?? ?? ?? ?? ?? 48 89 5C 24 ?? FF 15 ?? ?? ?? ?? 48 8B F8 48 85 C0 74 + } + $create_cab_file_and_upload_p4 = { + 8B 44 24 ?? 48 8D 15 ?? ?? ?? ?? 4D 8B CD 41 B8 ?? ?? ?? ?? 48 8B CF 89 44 24 ?? FF + 15 ?? ?? ?? ?? 85 C0 74 ?? 49 8B CD FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 45 33 C9 45 33 + C0 48 8B CF FF 15 ?? ?? ?? ?? 85 C0 75 ?? 45 33 C9 45 33 C0 33 D2 48 8B CF FF 15 ?? + ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 49 8B CC FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? + ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 74 ?? FF C0 B9 ?? ?? ?? ?? 8B + D0 89 44 24 ?? FF 15 ?? ?? ?? ?? 4C 8B E8 48 85 C0 75 ?? 45 33 C9 45 33 C0 33 D2 48 + 8B CF FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 49 8B CC FF 15 ?? ?? ?? ?? 48 8B + CE FF 15 ?? ?? ?? ?? 83 C8 ?? EB ?? 44 8B 44 24 ?? 33 D2 48 8B C8 E8 ?? ?? ?? ?? 44 + 8B 44 24 ?? 4C 8D 4C 24 ?? 49 8B D5 48 8B CF FF 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 + ?? ?? ?? ?? 49 8B CD E8 ?? ?? ?? ?? EB ?? BB ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? + 45 33 C9 45 33 C0 33 D2 48 8B CF FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 49 8B + CC FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 8B C3 4C 8B B4 24 ?? ?? ?? ?? 4C 8B + AC 24 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? + ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5C 5F 5E 5D C3 + } + $cmd_expand_payload_p1 = { + 40 53 55 41 55 48 81 EC ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 84 24 ?? ?? + ?? ?? 48 8B E9 48 8D 8C 24 ?? ?? ?? ?? 45 33 ED 33 D2 41 B8 ?? ?? ?? ?? 66 44 89 AC + 24 ?? ?? 00 00 E8 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? 66 44 + 89 AC 24 ?? ?? 00 00 E8 ?? ?? ?? ?? 45 8D 45 ?? 48 8D 4C 24 ?? 33 D2 44 89 6C 24 ?? + E8 ?? ?? ?? ?? 33 C0 4C 89 6C 24 ?? 45 8D 45 ?? 45 33 C9 BA ?? ?? ?? ?? 48 8B CD C7 + 44 24 ?? ?? ?? ?? ?? 4C 89 6C 24 ?? 48 89 44 24 ?? 48 89 44 24 ?? C7 44 24 ?? ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 75 ?? 0B C0 E9 ?? ?? ?? ?? 45 33 C9 33 + D2 48 8B C8 45 8D 41 ?? 4C 89 6C 24 ?? 48 89 BC 24 ?? ?? ?? ?? 44 89 6C 24 ?? FF 15 + ?? ?? ?? ?? 48 8B F8 48 85 C0 75 ?? 48 8B CB FF 15 ?? ?? ?? ?? 83 C8 ?? E9 ?? ?? ?? + ?? 45 33 C9 45 33 C0 48 8B C8 41 8D 51 ?? 48 89 B4 24 ?? ?? ?? ?? 4C 89 6C 24 ?? FF + 15 ?? ?? ?? ?? 48 8B F0 48 85 C0 75 ?? 48 8B CB FF 15 ?? ?? ?? ?? 83 C8 ?? E9 ?? ?? + ?? ?? 4C 8D 40 ?? 48 8D 84 24 ?? ?? ?? ?? 41 83 C9 ?? 33 D2 33 C9 C7 44 24 ?? ?? ?? + ?? ?? 48 89 44 24 ?? 4C 89 A4 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? + 33 D2 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? FF 15 ?? + ?? ?? ?? 4C 8D 84 24 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 + } + $cmd_expand_payload_p2 = { + 44 8B 66 ?? 48 8B CE FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 48 8B CB FF 15 ?? + ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? + ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 4C 8B CD BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 44 24 + ?? 48 8D 94 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 44 24 ?? 45 33 C9 48 89 44 24 ?? 4C + 89 6C 24 ?? 4C 89 6C 24 ?? 45 33 C0 33 C9 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? + ?? ?? 66 44 89 AC 24 ?? ?? 00 00 44 89 6C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 83 C8 + ?? EB ?? 90 B9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 45 33 C9 4C 89 6C 24 ?? 48 8D 0D ?? ?? + ?? ?? 45 8D 41 ?? BA ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 75 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 48 8B CB + FF 15 ?? ?? ?? ?? 41 8B C4 4C 8B A4 24 ?? ?? ?? ?? 48 8B B4 24 ?? ?? ?? ?? 48 8B BC + 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? + 41 5D 5D 5B C3 + } + + condition: + uint16(0)==0x5A4D and ( all of ($network_communication_p*)) and ( all of ($handle_c2_commands_p*)) and ( all of ($create_cab_file_and_upload_p*)) and ( all of ($cmd_expand_payload_p*)) +} +rule REVERSINGLABS_Bytecode_MSIL_Backdoor_Asyncrat : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects AsyncRAT backdoor." + author = "ReversingLabs" + id = "78ff36e1-1620-50f4-8abd-adcf8b1242da" + date = "2024-05-22" + modified = "2024-05-22" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/ByteCode.MSIL.Backdoor.AsyncRAT.yara#L1-L149" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "53a13975cd53b571910f951adc44707c11b86c003eeb7b88dbe701253645ac89" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "AsyncRAT" + tc_detection_factor = 5 + importance = 25 + + strings: + $read_server_data_v1 = { + 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 39 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 16 28 ?? + ?? ?? ?? DD ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 6F ?? ?? ?? ?? 0A 06 16 3E ?? ?? ?? ?? 28 + ?? ?? ?? ?? 06 6A 58 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 06 6A 59 28 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 3A ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 6A 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 16 6A 3E ?? ?? ?? ?? 16 6A 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? D4 8D ?? ?? ?? ?? 28 ?? + ?? ?? ?? 38 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 69 28 ?? ?? ?? + ?? 69 6F ?? ?? ?? ?? 0B 07 16 3D ?? ?? ?? ?? 16 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 28 ?? + ?? ?? ?? 07 6A 58 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 07 6A 59 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 16 6A 3C ?? ?? ?? ?? 16 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 6A 30 ?? + 14 (FE | 06) ?? ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? + ?? 16 6A 28 ?? ?? ?? ?? 1A 6A 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? D4 8D ?? ?? ?? ?? 28 ?? + ?? ?? ?? 38 ?? ?? ?? ?? 1A 6A 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? D4 8D ?? ?? ?? ?? 28 ?? + ?? ?? ?? 16 6A 28 ?? ?? ?? ?? 38 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 6A 3C ?? ?? ?? ?? 16 + 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 69 28 ?? + ?? ?? ?? 69 14 (FE | 06) ?? ?? ?? ?? ?? 73 ?? ?? ?? ?? 14 6F ?? ?? ?? ?? 26 38 ?? ?? + ?? ?? 16 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 26 16 28 ?? ?? ?? ?? DD + } + $send_v1 = { + 28 ?? ?? ?? ?? 0A 16 0B 06 12 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DD ?? + ?? ?? ?? 02 8E 69 28 ?? ?? ?? ?? 0C 28 ?? ?? ?? ?? 15 17 6F ?? ?? ?? ?? 26 28 ?? ?? + ?? ?? 08 16 08 8E 69 6F ?? ?? ?? ?? 02 8E 69 20 ?? ?? ?? ?? 3E ?? ?? ?? ?? 02 73 ?? + ?? ?? ?? 0D 16 13 ?? 09 16 6A 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? 13 ?? 38 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 15 17 6F ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 11 ?? 16 11 ?? 6F + ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 25 + 13 ?? 16 30 ?? DD ?? ?? ?? ?? 09 39 ?? ?? ?? ?? 09 6F ?? ?? ?? ?? DC 28 ?? ?? ?? ?? + 15 17 6F ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 02 16 02 8E 69 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? + 6F ?? ?? ?? ?? DD ?? ?? ?? ?? 26 16 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 07 39 ?? ?? ?? ?? + 06 28 ?? ?? ?? ?? DC + } + $read_packet_v1_p1 = { + 73 ?? ?? ?? ?? 0A 06 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 02 74 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B + 07 28 ?? ?? ?? ?? 0C 08 20 4F 01 89 64 42 ?? ?? ?? ?? 08 20 7A 39 BA 13 42 ?? ?? ?? + ?? 08 20 D4 CA CD 0C 3B ?? ?? ?? ?? 08 20 7A 39 BA 13 3B ?? ?? ?? ?? 38 ?? ?? ?? ?? + 08 20 2B C2 32 1B 3B ?? ?? ?? ?? 08 20 E2 A2 F4 57 3B ?? ?? ?? ?? 08 20 4F 01 89 64 + 3B ?? ?? ?? ?? 38 ?? ?? ?? ?? 08 20 5A 15 79 D9 42 ?? ?? ?? ?? 08 20 B7 16 DB 7A 3B + ?? ?? ?? ?? 08 20 39 20 3F B2 3B ?? ?? ?? ?? 08 20 5A 15 79 D9 3B ?? ?? ?? ?? 38 ?? + ?? ?? ?? 08 20 1E CA D2 DC 3B ?? ?? ?? ?? 08 20 45 FD B6 E0 3B ?? ?? ?? ?? 08 20 D0 + 5E 9B FA 3B ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? + ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? + ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? + ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 + } + $read_packet_v1_p2 = { + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 73 ?? + ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6A 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? + 16 28 ?? ?? ?? ?? 38 ?? ?? ?? ?? 00 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 7E ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 6F ?? + ?? ?? ?? 73 ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? + ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? + 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 38 ?? ?? ?? ?? 06 7B ?? + ?? ?? ?? 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? DD ?? ?? ?? ?? + 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 72 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 28 ?? ?? + ?? ?? 6F ?? ?? ?? ?? 0D 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? + ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F + ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 11 ?? + 6F ?? ?? ?? ?? 26 12 ?? 28 ?? ?? ?? ?? 2D ?? DD ?? ?? ?? ?? 12 ?? (FE | 16) ?? ?? ?? + ?? ?? 6F ?? ?? ?? ?? DC 73 ?? ?? ?? ?? 26 06 (FE | 06) ?? ?? ?? ?? ?? 73 ?? ?? ?? ?? + 73 ?? ?? ?? ?? 25 16 6F ?? ?? ?? ?? 25 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 38 ?? ?? ?? ?? + 7E ?? ?? ?? ?? 25 3A ?? ?? ?? ?? 26 7E ?? ?? ?? ?? (FE | 06) ?? ?? ?? ?? ?? 73 + } + $send_v2 = { + 7E ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 16 13 ?? 11 ?? 12 ?? 28 ?? ?? ?? ?? 7E ?? + ?? ?? ?? 39 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0A 02 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 8E + B7 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 06 08 16 08 8E B7 + 6F ?? ?? ?? ?? 06 07 16 07 8E B7 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 15 17 6F ?? ?? ?? ?? + 26 7E ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 16 06 6F ?? ?? ?? ?? B7 16 14 (FE | 06) ?? ?? ?? + ?? ?? 73 ?? ?? ?? ?? 14 6F ?? ?? ?? ?? 26 DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? DC DE ?? + 25 28 ?? ?? ?? ?? 0D 16 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? DE ?? 11 ?? 2C ?? 11 ?? + 28 ?? ?? ?? ?? DC + } + $open_url_v2 = { + 03 39 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 20 00 0C 00 00 28 ?? ?? ?? ?? 20 0F 27 00 00 28 + ?? ?? ?? ?? DE ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 02 28 ?? ?? ?? ?? 74 ?? ?? ?? + ?? 0A 06 7E ?? ?? ?? ?? 73 ?? ?? ?? ?? 7E ?? ?? ?? ?? 8E B7 6F ?? ?? ?? ?? 9A 6F ?? + ?? ?? ?? 06 17 6F ?? ?? ?? ?? 06 20 10 27 00 00 6F ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 74 ?? ?? ?? ?? 0B DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC + 2B ?? 02 28 ?? ?? ?? ?? 26 + } + $monitoring_v2 = { + 73 ?? ?? ?? ?? 0C 02 72 ?? ?? ?? ?? 15 16 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? + 11 ?? 9A 0B 08 07 14 72 ?? ?? ?? ?? 16 8D ?? ?? ?? ?? 14 14 14 28 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 6F ?? ?? ?? ?? 11 ?? 17 D6 13 ?? 11 ?? 11 ?? 8E B7 32 ?? 1F ?? 0A 38 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 0D 09 6F ?? ?? ?? ?? 28 ?? + ?? ?? ?? 2C ?? 2B ?? 08 09 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 (FE | 07) ?? ?? ?? ?? ?? + 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 06 1F ?? 31 ?? 16 0A 72 ?? ?? ?? ?? 09 6F ?? ?? + ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 17 D6 13 ?? + 11 ?? 11 ?? 8E B7 32 ?? 06 17 D6 0A 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 3A + } + + condition: + uint16(0)==0x5A4D and ((($read_server_data_v1) and ($send_v1) and ( all of ($read_packet_v1_p*))) or (($send_v2) and ($open_url_v2) and ($monitoring_v2))) +} +rule REVERSINGLABS_Linux_Backdoor_Linodas : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Linodas backdoor." + author = "ReversingLabs" + id = "2b197346-abce-5cff-938f-bb8742e03168" + date = "2024-05-22" + modified = "2024-05-22" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/Linux.Backdoor.Linodas.yara#L1-L216" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "12445771106e36b74b1ea292a8a25cab66bcaf0a08cf88d39a9f1bb13c6f525b" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "Linodas" + tc_detection_factor = 5 + importance = 25 + + strings: + $persistence_mechanism_ubuntu = { + 41 54 BE ?? ?? ?? ?? 55 53 48 81 EC ?? ?? ?? ?? 48 8D 6C 24 ?? 48 8D 54 24 ?? 48 89 + EF E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 5C 24 ?? 48 + 89 EE 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 48 + 81 FB ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8D 6C 24 ?? 48 8D 54 24 ?? BE ?? ?? ?? ?? 48 + 89 EF E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 5C 24 ?? + 48 89 EE 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? + 48 81 FB ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8D 5C 24 ?? 48 89 EE 48 89 DF E8 ?? ?? ?? + ?? 48 89 DF E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 41 BC ?? ?? ?? ?? 48 83 EB ?? 4C 39 E3 0F + 85 ?? ?? ?? ?? 4C 8B 44 24 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 E7 + E8 ?? ?? ?? ?? 48 89 E7 E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 E7 E8 ?? ?? ?? ?? 85 C0 + 74 ?? 48 8B 4C 24 ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 + 8D 5C 24 ?? 4C 8B 44 24 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 + ?? ?? ?? ?? 48 89 DE 48 89 E7 E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DC 0F + 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 E7 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 4C 24 ?? BA + ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 5C 24 ?? 4C 8B 44 24 + ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 89 DE 48 + 89 E7 E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DC 0F 85 ?? ?? ?? ?? BE ?? ?? + ?? ?? 48 89 E7 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 4C 24 ?? BA ?? ?? ?? ?? BE ?? ?? ?? + ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 1C 24 48 83 EB ?? 49 39 DC 0F 85 ?? ?? ?? ?? + 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DC 0F 85 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 + 39 DC 0F 85 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5D 41 5C C3 + } + $network_communication_1 = { + 48 89 5C 24 ?? 48 89 6C 24 ?? 48 89 F3 4C 89 64 24 ?? 4C 89 6C 24 ?? 48 81 EC ?? ?? + ?? ?? 48 8B 06 48 89 FD 89 54 24 ?? 45 89 C4 48 83 78 ?? ?? 0F 84 ?? ?? ?? ?? 4C 8D + 6C 24 ?? 48 8B 33 4C 89 EF E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 83 78 ?? ?? 0F 84 ?? ?? + ?? ?? 45 84 E4 0F 85 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 88 45 + ?? 80 7D ?? ?? 0F 84 ?? ?? ?? ?? C6 45 ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 89 C5 0F 84 ?? ?? ?? ?? 48 8D 4C 24 ?? 41 B8 ?? ?? ?? + ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 89 C7 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? + ?? ?? ?? 48 8D 5C 24 ?? E8 ?? ?? ?? ?? 48 8D 4C 24 ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? + 41 B8 ?? ?? ?? ?? 89 EF 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? + ?? ?? ?? 48 8B 7C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 48 C7 44 24 ?? ?? ?? + ?? ?? 66 C1 C8 ?? 66 C7 44 24 ?? ?? ?? 66 89 44 24 ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? + 89 44 24 ?? 48 89 DE 89 EF E8 ?? ?? ?? ?? 83 C0 ?? 0F 84 ?? ?? ?? ?? 0F 1F 44 00 ?? + 48 8B 5C 24 ?? 48 83 EB ?? 48 81 FB ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 89 E8 48 8B 5C 24 + ?? 48 8B 6C 24 ?? 4C 8B 64 24 ?? 4C 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 + } + $network_communication_2 = { + 48 89 5C 24 ?? 48 89 6C 24 ?? 48 89 FB 4C 89 64 24 ?? BE ?? ?? ?? ?? 48 83 EC ?? BF + ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? + ?? ?? ?? 48 8D 73 ?? 48 8D 53 ?? BF ?? ?? ?? ?? 48 8D 6C 24 ?? 45 31 E4 E8 ?? ?? ?? + ?? 48 89 DF E8 ?? ?? ?? ?? 48 8B 73 ?? 48 89 EF E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 83 + 78 ?? ?? 74 ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? + 4C 8D 64 24 ?? 48 89 EE 4C 89 E7 E8 ?? ?? ?? ?? 4C 89 E6 48 89 DF E8 ?? ?? ?? ?? 48 + 8B 6C 24 ?? 41 89 C4 48 83 ED ?? 48 81 FD ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 45 84 E4 74 + ?? 80 7B ?? ?? 0F 84 ?? ?? ?? ?? 90 48 89 DF E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 41 0F B6 + EC 48 83 EB ?? 48 81 FB ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 89 E8 48 8B 5C 24 ?? 48 8B 6C + 24 ?? 4C 8B 64 24 ?? 48 83 C4 ?? C3 + } + $persistence_mechanism_redhat_v11 = { + 41 57 41 56 41 55 41 54 55 53 48 83 EC ?? 48 8D 7C 24 ?? E8 ?? ?? ?? ?? 48 8B 6C 24 + ?? 8B 7D ?? 4C 8D 7D ?? 81 C7 ?? ?? ?? ?? 48 63 FF E8 ?? ?? ?? ?? 48 89 C3 48 8D 7C + 24 ?? 48 89 EE E8 ?? ?? ?? ?? 4C 8B 6C 24 ?? BE ?? ?? ?? ?? 48 89 DF 31 C0 4C 8D 74 + 24 ?? 4C 89 EA E8 ?? ?? ?? ?? 48 98 48 8D 54 24 ?? 48 89 DE C6 04 18 ?? 4C 89 F7 E8 + ?? ?? ?? ?? 48 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 74 ?? 4C 89 E9 4C 89 EA BE ?? + ?? ?? ?? 48 89 DF 49 89 E9 4D 89 E8 31 C0 E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 41 89 C4 B9 + ?? ?? ?? ?? 89 C2 48 89 DE E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 + 0F 85 ?? ?? ?? ?? 48 8B 54 24 ?? 48 89 DF BE ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 48 89 + DF E8 ?? ?? ?? ?? 4C 89 EA BE ?? ?? ?? ?? 48 89 DF 31 C0 48 8D 6C 24 ?? E8 ?? ?? ?? + ?? 48 98 48 8D 54 24 ?? 48 89 DE C6 04 18 ?? 48 89 EF E8 ?? ?? ?? ?? 48 89 E7 31 C9 + BA ?? ?? ?? ?? 48 89 EE E8 ?? ?? ?? ?? 48 8B 6C 24 ?? 41 BE ?? ?? ?? ?? 4C 8B 24 24 + 48 83 ED ?? 4C 39 F5 0F 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? 48 85 + C0 0F 84 ?? ?? ?? ?? 48 89 DF 49 8D 5C 24 ?? E8 ?? ?? ?? ?? 49 39 DE 0F 85 ?? ?? ?? + ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DE 0F 85 ?? ?? ?? ?? 49 8D 5D ?? 49 39 DE 0F 85 + ?? ?? ?? ?? 49 81 FF ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 83 C4 ?? 5B 5D 41 5C 41 5D 41 + 5E 41 5F C3 + } + $change_timestamp_and_read_config_v11 = { + 55 53 48 83 EC ?? 48 8D 5C 24 ?? 48 89 E7 E8 ?? ?? ?? ?? 48 89 E6 48 89 DF E8 ?? ?? + ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 48 81 FB ?? ?? ?? ?? 0F 85 + ?? ?? ?? ?? 48 89 E6 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 1C 24 BE ?? ?? ?? ?? 48 89 + DF E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 83 C0 ?? 89 C5 29 DD 8D 7D ?? 48 63 FF E8 ?? ?? + ?? ?? 48 63 D5 48 89 C3 48 89 C7 C6 04 02 ?? 48 8B 34 24 E8 ?? ?? ?? ?? 48 89 DF E8 + ?? ?? ?? ?? 48 89 DE 48 89 C2 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? + BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 1C 24 B8 ?? ?? ?? + ?? 48 83 EB ?? 48 39 D8 75 ?? 48 83 C4 ?? 5B 5D C3 + } + $generate_machine_id_v11 = { + 41 57 BE ?? ?? ?? ?? 49 89 FF 41 56 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 8D 9C + 24 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 8D AC 24 ?? ?? ?? + ?? 31 C9 BA ?? ?? ?? ?? 48 89 DE 4C 89 EF E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 41 + BE ?? ?? ?? ?? 48 83 EB ?? 4C 39 F3 0F 85 ?? ?? ?? ?? 4C 8D A4 24 ?? ?? ?? ?? 48 8B + B4 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? 48 8B 84 24 + ?? ?? ?? ?? 48 83 78 ?? ?? 0F 84 ?? ?? ?? ?? 48 8D 9C 24 ?? ?? ?? ?? 48 8D 94 24 ?? + ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 31 C9 BA ?? + ?? ?? ?? 48 89 DE 48 89 EF E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 + DE 0F 85 ?? ?? ?? ?? 48 89 EE 4C 89 E7 E8 ?? ?? ?? ?? 48 8B B4 24 ?? ?? ?? ?? 48 8D + BC 24 ?? ?? ?? ?? 48 8B 56 ?? E8 ?? ?? ?? ?? 31 FF 4C 8B AC 24 ?? ?? ?? ?? E8 ?? ?? + ?? ?? 89 C7 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 C6 48 8D BC 24 ?? ?? ?? + ?? F7 EA 89 F1 89 F5 C1 F9 ?? C1 FA ?? 29 CA 69 D2 ?? ?? ?? ?? 29 D5 E8 ?? ?? ?? ?? + 48 8B 9C 24 ?? ?? ?? ?? 41 89 E8 31 C0 4C 89 E9 BE ?? ?? ?? ?? 48 89 E7 48 89 DA 48 + 83 EB ?? E8 ?? ?? ?? ?? 49 39 DE 89 C5 0F 85 ?? ?? ?? ?? 48 63 C5 48 8D 94 24 ?? ?? + ?? ?? 48 8D BC 24 ?? ?? ?? ?? C6 04 04 ?? 48 89 E6 E8 ?? ?? ?? ?? 48 8D 94 24 ?? ?? + ?? ?? 48 89 E6 4C 89 FF E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DE + 0F 85 ?? ?? ?? ?? 49 8D 5D ?? 49 39 DE 0F 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 + 83 EB ?? 49 39 DE 0F 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DE 0F + 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DE 0F 85 ?? ?? ?? ?? 48 81 + C4 ?? ?? ?? ?? 4C 89 F8 5B 5D 41 5C 41 5D 41 5E 41 5F C3 + } + $persistence_mechanism_redhat_v7 = { + 48 89 6C 24 ?? 4C 89 7C 24 ?? 48 89 5C 24 ?? 4C 89 64 24 ?? 4C 89 6C 24 ?? 4C 89 74 + 24 ?? 48 81 EC ?? ?? ?? ?? 48 8D 7C 24 ?? E8 ?? ?? ?? ?? 48 8B 6C 24 ?? 8B 7D ?? 4C + 8D 7D ?? 81 C7 ?? ?? ?? ?? 48 63 FF E8 ?? ?? ?? ?? 48 89 C3 48 8D 7C 24 ?? 48 89 EE + E8 ?? ?? ?? ?? 4C 8B 64 24 ?? BE ?? ?? ?? ?? 48 89 DF 31 C0 4C 8D 74 24 ?? 4C 89 E2 + E8 ?? ?? ?? ?? 48 98 48 8D 54 24 ?? 48 89 DE C6 04 18 ?? 4C 89 F7 E8 ?? ?? ?? ?? 48 + 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 74 ?? 4C 89 E1 4C 89 E2 BE ?? ?? ?? ?? 48 89 + DF 49 89 E9 4D 89 E0 31 C0 E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 41 89 C5 B9 ?? ?? ?? ?? 89 + C2 48 89 DE E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? + ?? 48 8B 54 24 ?? 48 89 DF BE ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? + ?? 4C 89 E2 BE ?? ?? ?? ?? 48 89 DF 31 C0 E8 ?? ?? ?? ?? 48 98 48 89 E7 31 C9 C6 04 + 18 ?? BA ?? ?? ?? ?? 48 89 DE E8 ?? ?? ?? ?? 48 8B 2C 24 BE ?? ?? ?? ?? 48 89 EF E8 + ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 DF 48 8D 5D ?? BD ?? ?? ?? ?? E8 ?? ?? + ?? ?? 48 39 EB 0F 85 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 48 39 DD 0F 85 ?? ?? ?? + ?? 49 8D 5C 24 ?? 48 39 DD 0F 85 ?? ?? ?? ?? 49 81 FF ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? + 48 8B 5C 24 ?? 48 8B 6C 24 ?? 4C 8B 64 24 ?? 4C 8B AC 24 ?? ?? ?? ?? 4C 8B B4 24 ?? + ?? ?? ?? 4C 8B BC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 + } + $get_device_name_v7 = { + 48 89 5C 24 ?? 48 89 6C 24 ?? BE ?? ?? ?? ?? 4C 89 64 24 ?? 4C 89 6C 24 ?? B9 ?? ?? + ?? ?? 4C 89 74 24 ?? 48 81 EC ?? ?? ?? ?? 4C 8B 05 ?? ?? ?? ?? 48 8D 5C 24 ?? BA ?? + ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 89 DE BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 5C 24 + ?? 41 BD ?? ?? ?? ?? 48 83 EB ?? 4C 39 EB 0F 85 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 + 83 78 ?? ?? 75 ?? 48 8D 5C 24 ?? 48 89 DF E8 ?? ?? ?? ?? 48 89 DE BF ?? ?? ?? ?? E8 + ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? + ?? 48 8B 15 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 7C 24 ?? + E8 ?? ?? ?? ?? 4C 8B 64 24 ?? 48 89 E7 E8 ?? ?? ?? ?? 48 8B 2C 24 48 8D 5C 24 ?? 41 + B8 ?? ?? ?? ?? 4C 89 E2 BE ?? ?? ?? ?? 31 C0 48 89 DF 48 89 E9 E8 ?? ?? ?? ?? 48 89 + DE BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 48 8D 5D ?? 49 39 DD 0F 85 ?? ?? ?? ?? 49 8D 5C 24 ?? 49 39 DD 0F + 85 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 8B 6C 24 ?? 4C 8B 64 24 ?? 4C 8B 6C 24 ?? 4C 8B B4 + 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 + } + $generate_machine_id_v7 = { + 41 57 31 C9 BA ?? ?? ?? ?? BE ?? ?? ?? ?? 49 89 FF 41 56 41 55 41 54 55 53 48 81 EC + ?? ?? ?? ?? 4C 8D A4 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? + 48 8B B4 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 48 8B + 84 24 ?? ?? ?? ?? 48 83 78 ?? ?? 0F 84 ?? ?? ?? ?? 48 8D 9C 24 ?? ?? ?? ?? 31 C9 BA + ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 89 DE 48 89 EF E8 ?? ?? ?? ?? + 48 8B B4 24 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? 48 8B 56 ?? E8 ?? ?? ?? ?? 31 FF 4C + 8B B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 C7 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? + ?? 89 C6 48 8D BC 24 ?? ?? ?? ?? F7 EA 89 F1 89 F5 C1 F9 ?? C1 FA ?? 29 CA 69 D2 ?? + ?? ?? ?? 29 D5 E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 41 89 E8 31 C0 4C 89 F1 BE ?? + ?? ?? ?? 48 89 E7 41 BD ?? ?? ?? ?? 48 89 DA 48 83 EB ?? E8 ?? ?? ?? ?? 4C 39 EB 89 + C5 0F 85 ?? ?? ?? ?? 48 63 C5 48 8D 94 24 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? C6 04 + 04 ?? 48 89 E6 E8 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 89 E6 4C 89 FF E8 ?? ?? ?? + ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? ?? 49 8D 5E ?? 49 39 + DD 0F 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? ?? + 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? + ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 4C 89 F8 5B 5D 41 5C + 41 5D 41 5E 41 5F C3 + } + + condition: + uint32(0)==0x464C457F and (($persistence_mechanism_ubuntu) and ( all of ($network_communication_*)) and ((($change_timestamp_and_read_config_v11) and ($persistence_mechanism_redhat_v11) and ($generate_machine_id_v11)) or (($persistence_mechanism_redhat_v7) and ($get_device_name_v7) and ($generate_machine_id_v7)))) +} +rule REVERSINGLABS_Win32_Backdoor_Minodo : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Minodo backdoor." + author = "ReversingLabs" + id = "0eeff863-1a46-5b25-8780-5cd887e3b1e2" + date = "2023-06-07" + modified = "2023-06-07" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/Win64.Backdoor.Minodo.yara#L1-L110" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "807408699fe00c8d1170598050e533dd0d79bb170f2538b6b6227cda7410060b" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "Minodo" + tc_detection_factor = 5 + importance = 25 + + strings: + $generate_system_id = { + 40 55 53 56 57 41 56 48 8D 6C 24 ?? 48 81 EC ?? ?? ?? ?? 4C 8B F1 48 8D 55 ?? 48 8D + 4D ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 DB 85 C0 75 ?? 66 C7 45 ?? ?? ?? 4C + 8D 45 ?? 48 8D 55 ?? B9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 + ?? 66 C7 45 ?? ?? ?? 48 83 4D ?? ?? 4C 8D 4D ?? 4C 8D 45 ?? 8B CB 48 8B D3 BE ?? ?? + ?? ?? 48 85 D2 7E ?? 44 8A 54 15 ?? EB ?? 44 8A 95 ?? ?? ?? ?? 41 8A 01 49 FF C1 48 + FF C2 32 44 15 ?? 41 32 C2 41 32 00 49 FF C0 88 44 15 ?? 41 38 19 75 ?? 83 C9 ?? 4C + 8D 4D ?? 41 38 18 75 ?? 83 C9 ?? 4C 8D 45 ?? 48 3B D6 75 ?? 83 C9 ?? 48 8B D3 83 F9 + ?? 75 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4D ?? FF 15 ?? ?? ?? ?? 48 8D 5D ?? 49 8B FE 44 + 0F B6 03 48 8D 55 ?? 48 8B CF FF 15 ?? ?? ?? ?? 48 83 C7 ?? 48 FF C3 48 FF CE 75 ?? + FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4D ?? 8B D8 FF 15 ?? ?? ?? ?? 48 8D 55 + ?? 44 8B CB 4D 8B C6 49 8B CE FF 15 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5E 5F 5E 5B + 5D C3 + } + $generate_encrypt_and_send_key = { + 48 8B C4 48 89 58 ?? 48 89 68 ?? 48 89 70 ?? 48 89 78 ?? 41 56 48 81 EC ?? ?? ?? ?? + 8B F2 E8 ?? ?? ?? ?? 48 85 C0 75 ?? 33 C0 E9 ?? ?? ?? ?? 48 8B 40 ?? 48 8B 08 8B 09 + E8 ?? ?? ?? ?? 48 8B F8 48 85 C0 74 ?? 45 33 C0 45 8D 70 ?? 41 8D 50 ?? 41 8B CE E8 + ?? ?? ?? ?? 48 8B D8 83 F8 ?? 74 ?? 41 8D 6E ?? 48 8D 44 24 ?? 8B CD C6 00 ?? 48 FF + C0 48 FF C9 75 ?? 0F B7 CE 66 44 89 74 24 ?? E8 ?? ?? ?? ?? 48 8B CF 66 89 44 24 ?? + E8 ?? ?? ?? ?? 48 63 FB 48 8D 54 24 ?? 48 8B CF 44 8B C5 89 44 24 ?? E8 ?? ?? ?? ?? + 85 C0 74 ?? 48 8B CF E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 2D ?? ?? ?? ?? BE ?? ?? ?? + ?? 48 8B CD 8B D6 E8 ?? ?? ?? ?? 66 C7 44 24 ?? ?? ?? 33 C9 8A 44 29 ?? 48 FF C9 88 + 44 0C ?? 48 FF CE 75 ?? 8D 56 ?? 44 8D 46 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B CF + 8B F0 85 C0 74 ?? 48 8D 54 24 ?? 45 33 C9 44 8B C0 E8 ?? ?? ?? ?? 3B C6 74 ?? 48 8B + CF E8 ?? ?? ?? ?? 33 DB 8B C3 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? 49 8B 6B ?? 49 8B + 73 ?? 49 8B 7B ?? 49 8B E3 41 5E C3 + } + $get_encrypt_and_send_system_info = { + 48 89 5C 24 ?? 48 89 74 24 ?? 48 89 7C 24 ?? 55 48 8D 6C 24 ?? 48 81 EC ?? ?? ?? ?? + 8B F1 48 8B CA 48 8B DA FF 15 ?? ?? ?? ?? C6 44 24 ?? ?? 48 63 F8 40 88 7C 24 ?? 4C + 8B C7 85 C0 74 ?? 48 8D 44 24 ?? 48 2B D8 48 8D 4C 24 ?? 49 FF C8 4A 8D 0C 01 8A 04 + 0B 88 01 75 ?? 83 C7 ?? 48 63 DF E8 ?? ?? ?? ?? BA ?? ?? ?? ?? F6 D8 48 8D 45 ?? 1A + C9 80 E1 ?? 80 C9 ?? FF C7 88 4C 1C ?? 8B CA C6 00 ?? 48 FF C0 48 FF C9 75 ?? 48 8D + 4D ?? 89 55 ?? FF 15 ?? ?? ?? ?? 8A 45 ?? 48 63 CF 88 44 0C ?? 8A 45 ?? FF C7 48 63 + CF FF C7 BB ?? ?? ?? ?? 88 44 0C ?? 8A 45 ?? 48 63 CF 88 44 0C ?? 8A 45 ?? FF C7 48 + 63 CF FF C7 4C 8D 85 ?? ?? ?? ?? 88 44 0C ?? 8A 45 ?? 48 63 D7 88 44 14 ?? 8B 45 ?? + FF C7 48 63 D7 8D 4B ?? C6 44 24 ?? ?? 89 44 14 ?? 48 8D 54 24 ?? 83 C7 ?? 89 9D ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 44 8B C0 8D 48 ?? 03 CF + 48 63 D1 48 83 FA ?? 76 ?? 44 8D 43 ?? 44 2B C7 48 63 C7 FF C7 4C 8D 54 24 ?? 44 88 + 44 04 ?? 48 63 C7 49 63 D0 4C 03 D0 45 85 C0 74 ?? 4C 8D 4C 24 ?? 4A 8D 0C 12 4D 2B + CA 48 FF C9 41 8A 04 09 88 01 48 FF CA 75 ?? 48 8D 95 ?? ?? ?? ?? 48 8D 4C 24 ?? 41 + 03 F8 C6 44 24 ?? ?? 89 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? + ?? ?? 44 8B C0 8D 48 ?? 03 CF 48 63 D1 48 83 FA ?? 76 ?? 41 B8 ?? ?? ?? ?? 44 2B C7 + 48 63 C7 FF C7 4C 8D 54 24 ?? 44 88 44 04 ?? 48 63 C7 49 63 D0 4C 03 D0 45 85 C0 74 + ?? 4C 8D 4C 24 ?? 4A 8D 0C 12 4D 2B CA 48 FF C9 42 8A 04 09 88 01 48 FF CA 75 ?? 4C + 8D 4C 24 ?? 48 8D 54 24 ?? 44 03 C7 8B CE E8 ?? ?? ?? ?? 4C 8D 9C 24 ?? ?? ?? ?? 49 + 8B 5B ?? 49 8B 73 ?? 49 8B 7B ?? 49 8B E3 5D C3 + } + $copy_payload_into_allocated_memory = { + 48 89 5C 24 ?? 48 89 6C 24 ?? 56 57 41 56 48 83 EC ?? 49 8B D8 48 63 F2 48 8B F9 41 + C6 00 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 66 C7 03 ?? ?? B8 ?? ?? + ?? ?? E9 ?? ?? ?? ?? 4C 8D 4C 24 ?? 4C 8D 44 24 ?? 48 8B D3 48 8B CF E8 ?? ?? ?? ?? + 8B E8 85 C0 74 ?? 41 B9 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8B D6 33 C9 4C 8B F6 FF 15 + ?? ?? ?? ?? 48 8B F0 48 85 C0 75 ?? 66 C7 03 ?? ?? FF 15 ?? ?? ?? ?? 89 43 ?? 8D 46 + ?? EB ?? 4D 8B C6 48 8B D7 48 8B C8 E8 ?? ?? ?? ?? 48 83 64 24 ?? ?? 83 64 24 ?? ?? + 4C 8D 04 2E 45 33 C9 33 D2 33 C9 FF 15 ?? ?? ?? ?? 48 8B C8 FF 15 ?? ?? ?? ?? 8B 44 + 24 ?? 48 8B 5C 24 ?? 48 8B 6C 24 ?? 48 83 C4 ?? 41 5E 5F 5E C3 + } + $execute_payload_from_temp = { + 40 53 48 81 EC ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 4C 8B D1 48 8D 44 24 ?? 41 8B D0 33 DB + 88 18 48 FF C0 48 FF CA 75 ?? 48 8D 44 24 ?? 8D 4A ?? 88 18 48 FF C0 48 FF C9 75 ?? + 48 8D 44 24 ?? 44 89 44 24 ?? 45 33 C9 48 89 44 24 ?? 48 8D 44 24 ?? 45 33 C0 48 89 + 44 24 ?? 48 89 5C 24 ?? 48 89 5C 24 ?? 49 8B D2 89 5C 24 ?? C7 84 24 ?? ?? ?? ?? ?? + ?? ?? ?? 89 5C 24 ?? 66 89 9C 24 ?? ?? 00 00 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 4C + 24 ?? FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? FF 15 ?? ?? ?? ?? B0 ?? EB ?? 32 C0 48 81 C4 + ?? ?? ?? ?? 5B C3 + } + + condition: + uint16(0)==0x5A4D and ($generate_system_id) and ($generate_encrypt_and_send_key) and ($get_encrypt_and_send_system_info) and ($copy_payload_into_allocated_memory) and ($execute_payload_from_temp) +} +rule REVERSINGLABS_Bytecode_MSIL_Backdoor_Menorah : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Menorah backdoor." + author = "ReversingLabs" + id = "4f13a6c6-bd97-58aa-ac3b-399866b5c63b" + date = "2024-05-10" + modified = "2024-05-10" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/ByteCode.MSIL.Backdoor.Menorah.yara#L1-L169" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "770aefca192ceb3a778c0b1259105ace8e64cb35d0c34acb15c45fb6f22ad94b" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "Menorah" + tc_detection_factor = 5 + importance = 25 + + strings: + $send_fingerprint_to_c2_p1 = { + 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A + 73 ?? ?? ?? ?? 19 1F 0E 6F ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 1F 5B 13 ?? 12 ?? 28 ?? ?? + ?? ?? 1F 40 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F 40 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F 5D 13 ?? + 12 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 1B 8D ?? ?? ?? ?? 25 16 1F 5B 13 ?? 12 ?? 28 ?? + ?? ?? ?? A2 25 17 1F 40 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 06 A2 25 19 1F 40 13 ?? + 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 5D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 6F + ?? ?? ?? ?? 0B 28 ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 0C 72 ?? ?? ?? ?? 0D 1F 3F 13 ?? 12 + ?? 28 ?? ?? ?? ?? 17 16 28 ?? ?? ?? ?? 1F 3D 13 ?? 12 ?? 28 ?? ?? ?? ?? 17 16 28 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 03 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 74 ?? ?? ?? ?? + 13 ?? 11 ?? 1F 50 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F 4F 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F 53 + 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F 54 13 ?? 12 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? + ?? ?? 11 ?? 1F 21 8D ?? ?? ?? ?? 25 16 1F 61 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F + 70 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 1F 70 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F + 6C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F + 63 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F 61 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1D 1F + 74 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 09 + } + $send_fingerprint_to_c2_p2 = { + 1F 6F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0A 1F 6E 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 + 1F 0B 1F 2F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0C 1F 78 13 ?? 12 ?? 28 ?? ?? ?? ?? + A2 25 1F 0D 1F 2D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0E 1F 77 13 ?? 12 ?? 28 ?? ?? + ?? ?? A2 25 1F 0F 1F 77 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 10 1F 77 13 ?? 12 ?? 28 + ?? ?? ?? ?? A2 25 1F 11 1F 2D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 12 1F 66 13 ?? 12 + ?? 28 ?? ?? ?? ?? A2 25 1F 13 1F 6F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 14 1F 72 13 + ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 15 1F 6D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 16 1F + 2D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 17 1F 75 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F + 18 1F 72 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 19 1F 6C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 + 25 1F 1A 1F 65 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 1B 1F 6E 13 ?? 12 ?? 28 ?? ?? ?? + ?? A2 25 1F 1C 1F 63 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 1D 1F 6F 13 ?? 12 ?? 28 ?? + ?? ?? ?? A2 25 1F 1E 1F 64 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 1F 1F 65 13 ?? 12 ?? + 28 ?? ?? ?? ?? A2 25 1F 20 1F 64 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 6F ?? + ?? ?? ?? 11 ?? 08 8E 69 6A 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 25 08 16 08 8E 69 6F + ?? ?? ?? ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 25 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 + 6F ?? ?? ?? ?? 0D 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 13 ?? DE ?? 26 7E ?? ?? ?? ?? 13 + ?? DE ?? 11 + } + $get_files_and_directories_p1 = { + 11 ?? 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 8E 69 17 31 ?? + 11 ?? 17 9A 13 ?? 11 ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 1F 0F 8D + ?? ?? ?? ?? 25 16 1F 44 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F 69 13 ?? 12 ?? 28 ?? + ?? ?? ?? A2 25 18 1F 72 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F 65 13 ?? 12 ?? 28 ?? + ?? ?? ?? A2 25 1A 1F 63 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F 74 13 ?? 12 ?? 28 ?? + ?? ?? ?? A2 25 1C 1F 6F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1D 1F 72 13 ?? 12 ?? 28 ?? + ?? ?? ?? A2 25 1E 1F 79 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 09 1F 20 13 ?? 12 ?? 28 + ?? ?? ?? ?? A2 25 1F 0A 1F 6F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0B 1F 66 13 ?? 12 + ?? 28 ?? ?? ?? ?? A2 25 1F 0C 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0D 11 ?? A2 + 25 1F 0E 72 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 + ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 73 ?? ?? ?? ?? + 13 ?? 1F 0B 8D ?? ?? ?? ?? 25 16 11 ?? A2 25 17 11 ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 1F + 16 8D ?? ?? ?? ?? 25 16 1F 4D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F 4D 13 ?? 12 ?? + 28 ?? ?? ?? ?? A2 25 18 1F 2F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F 64 13 ?? 12 ?? + 28 ?? ?? ?? ?? A2 25 1A 1F 64 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F 2F 13 ?? 12 ?? + 28 ?? ?? ?? ?? A2 25 1C 1F 79 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1D 1F 79 13 ?? 12 + } + $get_files_and_directories_p2 = { + 28 ?? ?? ?? ?? A2 25 1E 1F 79 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F 79 13 ?? 12 + ?? 28 ?? ?? ?? ?? A2 25 1F 0A 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0B 1F 68 13 + ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0C 1F 68 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0D 1F + 3A 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0E 1F 6D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F + 0F 1F 6D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 10 1F 3A 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 + 25 1F 11 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 12 1F 73 13 ?? 12 ?? 28 ?? ?? ?? + ?? A2 25 1F 13 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 14 1F 74 13 ?? 12 ?? 28 ?? + ?? ?? ?? A2 25 1F 15 1F 74 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 28 ?? ?? ?? + ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 1F 3C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 44 + 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F 49 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F 52 + 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1D 1F 3E 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 72 ?? + ?? ?? ?? A2 25 1F 09 11 ?? 6F ?? ?? ?? ?? A2 25 1F 0A 72 ?? ?? ?? ?? A2 28 ?? ?? ?? + ?? 13 ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 11 ?? 13 ?? 16 13 ?? 38 + ?? ?? ?? ?? 11 ?? 11 ?? 9A 73 ?? ?? ?? ?? 13 ?? 1F 0C 8D ?? ?? ?? ?? 25 16 11 ?? A2 + 25 17 11 ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 1F 16 8D ?? ?? ?? ?? 25 16 1F 4D 13 ?? 12 ?? + 28 ?? ?? ?? ?? A2 25 17 1F 4D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 1F 2F 13 ?? 12 ?? + 28 ?? ?? ?? ?? A2 25 19 1F 64 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 64 13 ?? 12 ?? + 28 ?? ?? ?? ?? A2 25 1B 1F 2F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F 79 13 ?? 12 ?? + 28 ?? ?? ?? ?? A2 25 1D 1F 79 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 1F 79 13 ?? 12 ?? + 28 ?? ?? ?? ?? A2 25 1F 09 1F 79 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0A 1F 20 13 + } + $get_files_and_directories_p3 = { + 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0B 1F 68 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0C 1F 68 + 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0D 1F 3A 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0E + 1F 6D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0F 1F 6D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 + 1F 10 1F 3A 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 11 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? + A2 25 1F 12 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 13 1F 20 13 ?? 12 ?? 28 ?? ?? + ?? ?? A2 25 1F 14 1F 74 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 15 1F 74 13 ?? 12 ?? 28 + ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 1F 46 + 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 49 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F 4C + 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F 45 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1D 72 ?? + ?? ?? ?? A2 25 1E 11 ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 09 72 ?? + ?? ?? ?? A2 25 1F 0A 11 ?? 6F ?? ?? ?? ?? A2 25 1F 0B 72 ?? ?? ?? ?? A2 28 ?? ?? ?? + ?? 13 ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 1F 0B 8D ?? ?? ?? ?? 25 + 16 11 ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 11 ?? 8E 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 + 25 19 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 44 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 + 25 1B 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F 72 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 + 25 1D 1F 28 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 + 25 1F 09 1F 29 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0A 72 ?? ?? ?? ?? A2 28 ?? ?? ?? + ?? 13 ?? 1F 0B 8D ?? ?? ?? ?? 25 16 11 ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 11 ?? 8E + 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F + } + $upload_file_to_c2_p1 = { + 11 ?? 28 ?? ?? ?? ?? 13 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 8E 69 17 3E ?? ?? ?? ?? 11 ?? + 17 9A 17 8D ?? ?? ?? ?? 25 16 1F 22 9D 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 39 + ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 02 28 ?? ?? ?? ?? + 13 ?? 1F 0D 8D ?? ?? ?? ?? 25 16 1F 75 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F 40 13 + ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 11 ?? A2 25 19 1F 40 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 + 25 1A 28 ?? ?? ?? ?? A2 25 1B 1F 7C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 28 ?? ?? ?? + ?? A2 25 1D 1F 40 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 11 ?? A2 25 1F 09 1F 40 13 ?? + 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0A 1F 32 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0B 1F 40 + 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0C 11 ?? 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 13 ?? + 02 02 7B ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 26 1F 1E 8D ?? ?? ?? ?? 25 16 1F 66 13 ?? + 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 1F 6C 13 ?? + 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F 65 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 5B 13 ?? + 12 ?? 28 ?? ?? ?? ?? A2 25 1B 11 ?? A2 25 1C 1F 5D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 + 1D 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 + 1F 09 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0A 1F 20 13 ?? 12 ?? 28 + } + $upload_file_to_c2_p2 = { + A2 25 1F 0B 1F 75 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0C 1F 70 13 ?? 12 ?? 28 ?? ?? + ?? ?? A2 25 1F 0D 1F 6C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0E 1F 6F 13 ?? 12 ?? 28 + ?? ?? ?? ?? A2 25 1F 0F 1F 61 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 10 1F 64 13 ?? 12 + ?? 28 ?? ?? ?? ?? A2 25 1F 11 1F 65 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 12 1F 64 13 + ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 13 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 14 1F + 74 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 15 1F 6F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F + 16 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 17 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 + 25 1F 18 1F 65 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 19 1F 72 13 ?? 12 ?? 28 ?? ?? ?? + ?? A2 25 1F 1A 1F 76 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 1B 1F 65 13 ?? 12 ?? 28 ?? + ?? ?? ?? A2 25 1F 1C 1F 72 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 1D 1F 2E 13 ?? 12 ?? + 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 1F 0F 8D ?? ?? ?? ?? 25 16 1F + 66 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 1F + 6C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F 65 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F + 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F 6E 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F + } + + condition: + uint16(0)==0x5A4D and ( all of ($send_fingerprint_to_c2_p*)) and ( all of ($get_files_and_directories_p*)) and ( all of ($upload_file_to_c2_p*)) +} +rule REVERSINGLABS_Win32_Backdoor_Konni : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects Konni backdoor." + author = "ReversingLabs" + id = "6fe230b1-357a-54f7-a9a8-15d0369fec71" + date = "2023-12-07" + modified = "2023-12-07" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/Win32.Backdoor.Konni.yara#L1-L190" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "7907a657d804d485718ba13bb23513de0b909e7d455c2b3ee193b5329edd3ac6" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "Konni" + tc_detection_factor = 5 + importance = 25 + + strings: + $network_communication_p1 = { + 55 8B EC 83 EC ?? 53 56 8B 35 ?? ?? ?? ?? 57 33 FF 68 ?? ?? ?? ?? 8D 9E ?? ?? ?? ?? + 57 53 89 7D ?? 89 7D ?? 89 7D ?? 89 7D ?? 89 7D ?? 89 5D ?? E8 ?? ?? ?? ?? 8B 45 ?? + 50 56 8D 8E ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? + 81 C6 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 57 57 57 6A ?? 57 FF 15 ?? ?? ?? ?? 8B D8 3B DF + 0F 84 ?? ?? ?? ?? 57 57 6A ?? 57 57 6A ?? 56 53 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 8B F8 89 7D ?? 85 FF 75 ?? 53 FF 15 ?? ?? ?? ?? 8D 47 ?? 5F 5E 5B 8B E5 5D C2 ?? + ?? 8B 55 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 52 68 ?? ?? ?? ?? 57 C7 45 ?? ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 75 ?? 8B 35 ?? ?? ?? ?? 57 FF D6 53 FF D6 5F + 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C2 ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? + 6A ?? 6A ?? 85 C0 74 ?? 8D 45 ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 50 50 6A ?? 56 + FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 57 FF D6 53 FF D6 5F 5E B8 ?? ?? ?? ?? + 5B 8B E5 5D C2 ?? ?? 8B 45 ?? 85 C0 75 ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 56 8B 35 ?? + ?? ?? ?? FF D6 57 FF D6 53 FF D6 5F 5E 83 C8 ?? 5B 8B E5 5D C2 ?? ?? 40 50 6A ?? 89 + } + $network_communication_p2 = { + 45 ?? FF 15 ?? ?? ?? ?? 8B F8 85 FF 75 ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 56 8B 35 ?? + ?? ?? ?? FF D6 8B 4D ?? 51 FF D6 53 FF D6 5F 5E 83 C8 ?? 5B 8B E5 5D C2 ?? ?? 8B 55 + ?? 52 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? + ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 6A ?? 6A ?? 6A ?? + 56 FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 8B 45 ?? 50 FF D6 53 FF D6 5F 5E 83 + C8 ?? 5B 8B E5 5D C2 ?? ?? 8B 55 ?? 8D 4D ?? 51 52 57 56 FF 15 ?? ?? ?? ?? 85 C0 74 + ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 57 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? + 85 C0 B8 ?? ?? ?? ?? 75 ?? 8B 45 ?? 89 45 ?? 83 F8 ?? 74 ?? 8B 4D ?? 8B 55 ?? 6A ?? + 8D 45 ?? 50 51 57 52 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B 45 ?? 01 45 ?? 51 6A ?? 57 E8 ?? + ?? ?? ?? 8B 45 ?? 83 C4 ?? 8D 55 ?? 52 50 57 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4D + ?? 51 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? + 56 8B 35 ?? ?? ?? ?? FF D6 8B 55 ?? 52 FF D6 53 FF D6 83 7D ?? ?? 0F 84 ?? ?? ?? ?? + 8B 45 ?? 5F 5E 5B 8B E5 5D C2 + } + $handle_c2_commands_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 8D 85 ?? ?? ?? ?? + 50 33 FF 68 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 89 B5 ?? ?? ?? ?? + 3B F7 75 ?? 83 C8 ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 0D ?? ?? + ?? ?? 8B 16 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B + 4E ?? 50 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 56 ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? + ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 4E ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B + 5E ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 33 C0 57 51 66 89 85 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 46 ?? 52 50 E8 ?? ?? + ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 4E ?? 57 51 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? + ?? ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 46 ?? 52 50 E8 ?? ?? ?? + ?? 83 C4 ?? 85 C0 75 ?? 8B 46 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 69 C0 ?? ?? ?? ?? A3 ?? + ?? ?? ?? E9 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B 56 ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 + } + $handle_c2_commands_p2 = { + C0 75 ?? 8B 46 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 69 C0 ?? ?? ?? ?? A3 ?? ?? ?? ?? E9 ?? + ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4C 86 ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? BE + ?? ?? ?? ?? 85 C0 75 ?? 8D 78 ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 + FF E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 06 52 50 E8 + ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B + 44 96 ?? 51 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 8D ?? ?? ?? ?? 8B 54 8E ?? 68 + ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 06 8D 50 ?? 8B FF 66 8B 08 83 + C0 ?? 66 3B CF 75 ?? 2B C2 D1 F8 57 8D 3C 45 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB + ?? 8B 06 8D 50 ?? 66 8B 08 83 C0 ?? 66 3B CF 75 ?? 2B C2 D1 F8 6A ?? 8D 3C 45 ?? ?? + ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? A1 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 54 8E ?? 50 + 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 48 ?? EB ?? 33 C9 E8 ?? ?? ?? ?? 8B F8 56 + FF 15 ?? ?? ?? ?? 8B 4D ?? 8B C7 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $create_cab_file_and_upload_p1 = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? A1 ?? ?? ?? ?? 53 56 57 33 + FF 68 ?? ?? ?? ?? 8B F1 8D 95 ?? ?? ?? ?? 33 C9 57 52 89 85 ?? ?? ?? ?? 89 BD ?? ?? + ?? ?? 89 BD ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 66 89 8D ?? ?? ?? ?? E8 + ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 33 C0 57 51 66 89 85 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 33 C0 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 66 89 + 85 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 33 D2 50 66 89 95 ?? ?? ?? ?? FF 15 ?? ?? + ?? ?? 0F B7 8D ?? ?? ?? ?? 0F B7 95 ?? ?? ?? ?? 0F B7 85 ?? ?? ?? ?? 51 0F B7 8D ?? + ?? ?? ?? 52 0F B7 95 ?? ?? ?? ?? 50 51 52 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? + ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 57 + 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D + 85 ?? ?? ?? ?? 50 57 68 ?? ?? ?? ?? 8B C8 51 FF 15 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 + FF 15 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B D8 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 + C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? + 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? + ?? 83 C4 ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 68 ?? + ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B CE 8D BD ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 F8 ?? 75 ?? 83 C8 ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 57 8D + } + $create_cab_file_and_upload_p2 = { + 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? EB ?? 33 FF 8D 9D ?? ?? ?? ?? 8D 85 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 3B C7 74 ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? + ?? 8B B5 ?? ?? ?? ?? 83 C6 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 3B C7 74 + ?? 56 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 3B + DF 74 ?? 8D 85 ?? ?? ?? ?? 8D 50 ?? EB ?? 8D 9B ?? ?? ?? ?? 66 8B 08 83 C0 ?? 66 3B + CF 75 ?? 2B C2 8D 93 ?? ?? ?? ?? D1 F8 8D 0C 00 33 C0 89 02 89 42 ?? 89 42 ?? 89 42 + ?? 89 42 ?? 89 42 ?? 89 42 ?? 89 42 ?? 3B CF 74 ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? + ?? 83 C4 ?? 8B CB EB ?? 33 C9 8B 95 ?? ?? ?? ?? 89 8A ?? ?? ?? ?? 3B CF 0F 84 ?? ?? + ?? ?? 8B 85 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 8B + BD ?? ?? ?? ?? 8B 87 ?? ?? ?? ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 53 C7 87 ?? + ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 50 ?? 8D 9B ?? ?? ?? ?? + 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 8D 84 46 ?? ?? ?? ?? 50 6A ?? 89 85 ?? + ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 6A ?? + 53 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 50 + 53 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 56 89 85 ?? ?? ?? ?? 51 03 C3 50 E8 ?? ?? ?? ?? + 8B BD ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 03 FB 83 C4 ?? 03 FE B9 ?? ?? ?? ?? BE ?? ?? ?? + ?? 50 F3 A5 FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? 56 E8 + } + $create_cab_file_and_upload_p3 = { + 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 85 FF 0F 84 ?? ?? ?? ?? 6A ?? + 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 57 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 89 85 ?? ?? ?? ?? 85 C0 75 ?? 57 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5F 5E 5B 8B 4D ?? + 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? + 6A ?? 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? 50 05 ?? ?? ?? ?? 50 68 ?? ?? ?? + ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? + 6A ?? 6A ?? 6A ?? 56 68 ?? ?? ?? ?? 51 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? + ?? 8B F0 85 F6 75 ?? 8B 95 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 52 FF D6 57 FF D6 B8 ?? ?? + ?? ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 85 ?? ?? ?? ?? 50 53 6A + ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 56 + 8B 35 ?? ?? ?? ?? FF D6 8B 8D ?? ?? ?? ?? 51 FF D6 57 FF D6 B8 ?? ?? ?? ?? 5F 5E 5B + 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 53 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 95 ?? + ?? ?? ?? 52 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 56 8B 35 + ?? ?? ?? ?? FF D6 8B 85 ?? ?? ?? ?? 50 FF D6 57 FF D6 B8 ?? ?? ?? ?? 5F 5E 5B 8B 4D + ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 85 ?? ?? ?? ?? 85 C0 75 ?? 50 50 50 56 FF 15 + ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 8B 8D ?? ?? ?? ?? 51 FF D6 57 FF D6 83 C8 + } + $create_cab_file_and_upload_p4 = { + 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 40 50 6A ?? 89 85 ?? ?? ?? ?? FF + 15 ?? ?? ?? ?? 8B D8 85 DB 75 ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? + FF D6 8B 95 ?? ?? ?? ?? 52 FF D6 57 FF D6 83 C8 ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? + ?? ?? 8B E5 5D C3 8B 85 ?? ?? ?? ?? 50 6A ?? 53 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 + C4 ?? 8D 8D ?? ?? ?? ?? 51 52 53 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 53 + E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? + ?? ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? + ?? FF D6 8B 85 ?? ?? ?? ?? 50 FF D6 57 FF D6 8B 4D ?? 8B 85 ?? ?? ?? ?? 5F 5E 33 CD + 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + } + $cmd_expand_payload = { + 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 68 ?? ?? ?? ?? 8B + D9 33 FF 8D 8D ?? ?? ?? ?? 33 C0 57 51 66 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? + ?? ?? 8D 85 ?? ?? ?? ?? 33 D2 57 50 66 89 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 8D + ?? ?? ?? ?? 57 51 89 BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 68 ?? ?? ?? ?? 6A ?? + 57 6A ?? 33 C0 68 ?? ?? ?? ?? 53 89 BD ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? + ?? 89 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 74 ?? 57 57 57 6A ?? 57 56 FF + 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 3B C7 75 ?? 56 FF 15 ?? ?? ?? ?? 83 C8 ?? 5F 5E 5B + 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 57 57 57 6A ?? 50 FF 15 ?? ?? ?? ?? 8B F8 + 85 FF 74 ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 6A ?? 8D 47 ?? 50 6A ?? 6A ?? FF 15 + ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? + ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? + ?? E8 ?? ?? ?? ?? 8B 57 ?? 83 C4 ?? 57 89 95 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 85 ?? + ?? ?? ?? 8B 3D ?? ?? ?? ?? 50 FF D7 56 FF D7 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? + 51 E8 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? + ?? 83 C4 ?? 33 C0 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 50 50 68 ?? ?? ?? ?? 50 + 50 50 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? + FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D3 6A + ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? + 8B F0 83 FE ?? 75 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 56 FF D7 8B 4D ?? 8B 85 ?? ?? + ?? ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 + } + + condition: + uint16(0)==0x5A4D and ( all of ($network_communication_p*)) and ( all of ($handle_c2_commands_p*)) and ( all of ($create_cab_file_and_upload_p*)) and ($cmd_expand_payload) +} +rule REVERSINGLABS_Linux_Backdoor_Noodrat : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects NoodRAT backdoor." + author = "ReversingLabs" + id = "ac5eae27-dc42-5060-b639-c23c0bbabb50" + date = "2024-08-26" + modified = "2024-08-26" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/Linux.Backdoor.NoodRAT.yara#L1-L162" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "2ec4a8ba7428054edb4dcdb6a00015b9758badf515f2c210bb946ba5402674d2" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "NoodRAT" + tc_detection_factor = 5 + importance = 25 + + strings: + $change_name_on_system_p1 = { + 41 56 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 89 FB 48 8D BC 24 ?? ?? ?? ?? B8 ?? + ?? ?? ?? B9 ?? ?? ?? ?? F3 48 AB 48 8D BC 24 ?? ?? ?? ?? B1 ?? F3 48 AB C6 84 24 ?? + ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? + C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? + ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 0F B7 15 + ?? ?? ?? ?? 66 89 55 ?? 4C 8D 65 ?? 0F B7 D2 BE ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? + 48 8D 94 24 ?? ?? ?? ?? 0F B7 75 ?? 4C 89 E7 E8 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? + 4C 89 E6 48 89 EF E8 ?? ?? ?? ?? 4C 8B 03 48 C7 C6 ?? ?? ?? ?? 4C 89 C7 B8 ?? ?? ?? + ?? 48 89 F1 F2 AE 48 F7 D1 48 8D 14 31 48 89 EF 48 89 F1 F2 AE 48 89 CE 48 F7 D6 48 + 83 EE ?? 48 39 F2 72 ?? BE ?? ?? ?? ?? 4C 89 C7 E8 ?? ?? ?? ?? 48 89 EE 48 8B 3B E8 + ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? B8 ?? ?? ?? ?? B9 + ?? ?? ?? ?? F3 48 AB 48 8D BC 24 ?? ?? ?? ?? B1 ?? F3 48 AB C6 84 24 ?? ?? ?? ?? ?? + C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? + ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? + C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? + ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? + C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? + ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? 48 8D B4 24 ?? ?? ?? ?? + 48 8D BC 24 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C2 B8 ?? ?? ?? ?? 48 85 + D2 0F 8E ?? ?? ?? ?? 48 C7 C2 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? 48 89 D1 F2 AE 48 + } + $change_name_on_system_p2 = { + 89 CB 48 8D BC 24 ?? ?? ?? ?? 48 89 D1 F2 AE F7 D3 8D 5C 0B ?? 85 DB B8 ?? ?? ?? ?? + 0F 4E D8 48 8D B4 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 48 + 89 EF B8 ?? ?? ?? ?? 48 C7 C1 ?? ?? ?? ?? F2 AE 48 F7 D1 48 8D 79 ?? 48 63 D3 48 63 + FF 48 8D 7C 3D ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? + ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? C6 84 24 ?? ?? ?? ?? ?? + C6 84 24 ?? ?? ?? ?? ?? 48 8D B4 24 ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 49 89 C6 48 + 8D B4 24 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C3 48 89 E7 B9 ?? + ?? ?? ?? B8 ?? ?? ?? ?? F3 48 AB C6 07 ?? 48 89 E5 41 BC ?? ?? ?? ?? 41 BD ?? ?? ?? + ?? EB ?? 48 89 EF 4C 89 E9 4C 89 E0 F3 48 AB C6 07 ?? 48 89 D9 BA ?? ?? ?? ?? BE ?? + ?? ?? ?? 48 89 E7 E8 ?? ?? ?? ?? 85 C0 7E ?? 48 63 D0 4C 89 F1 BE ?? ?? ?? ?? 48 89 + E7 E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 85 C0 74 ?? 48 89 DF E8 ?? ?? ?? ?? 4C 89 + F7 E8 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? + ?? 85 C0 75 ?? 48 8D BC 24 ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? + ?? ?? ?? ?? ?? 48 8D B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? EB ?? 85 C0 7E + ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? + ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5D 41 5C 41 5D 41 5E C3 + } + $decrypt_configuration_p1 = { + 41 57 41 56 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 89 7C 24 ?? 48 8D 9C 24 ?? ?? + ?? ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 89 DF F3 48 AB C6 07 ?? 48 8D 54 24 ?? B1 ?? + 48 89 D7 F3 48 AB C6 44 24 ?? ?? C6 44 24 ?? ?? C6 44 24 ?? ?? C6 44 24 ?? ?? C6 44 + 24 ?? ?? C6 44 24 ?? ?? C6 44 24 ?? ?? C6 44 24 ?? ?? 48 8D 54 24 ?? 0F B7 35 ?? ?? + ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 C7 C1 ?? ?? ?? + ?? F2 AE 48 F7 D1 48 83 E9 ?? 48 81 F9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 0F 46 D1 BE ?? + ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? C6 44 24 ?? ?? C6 44 24 ?? ?? 48 8D 74 24 ?? 48 89 + DF E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 8D 50 ?? 48 89 54 24 ?? C6 00 ?? 48 + 8D 74 24 ?? 48 89 D7 E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 8D 48 ?? 48 89 4C + 24 ?? C6 00 ?? 48 8D 74 24 ?? 48 89 CF E8 ?? ?? ?? ?? 48 89 44 24 ?? 48 85 C0 0F 84 + ?? ?? ?? ?? C6 00 ?? 48 8D B4 24 ?? ?? ?? ?? 48 C7 C5 ?? ?? ?? ?? 48 89 F7 41 BC ?? + ?? ?? ?? 48 89 E9 44 89 E0 F2 AE 48 F7 D1 48 01 E9 48 8D 5C 24 ?? 48 81 F9 ?? ?? ?? + ?? BA ?? ?? ?? ?? 48 0F 46 D1 48 89 DF E8 ?? ?? ?? ?? 48 89 DF 48 89 E9 44 89 E0 F2 + AE 48 89 CD 48 F7 D5 83 ED ?? 8D 45 ?? 48 98 80 7C 04 ?? ?? 74 ?? 48 63 C5 C6 44 04 + ?? ?? 83 C5 ?? 48 63 ED C6 44 2C ?? ?? 4C 8D 6C 24 ?? 4C 89 EB BD ?? ?? ?? ?? C7 44 + 24 ?? ?? ?? ?? ?? 66 C7 44 24 ?? ?? ?? 41 BC ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 + 44 24 ?? ?? ?? ?? ?? 49 C7 C6 ?? ?? ?? ?? 4D 89 EF E9 ?? ?? ?? ?? 0F B6 03 3C ?? 75 + ?? 44 8B 64 24 ?? 4D 6B E4 ?? 4C 03 64 24 ?? 49 8D 7C 24 ?? 83 7C 24 ?? ?? BA ?? ?? + ?? ?? 0F 4E 54 24 ?? 48 63 D2 8B 74 24 ?? 48 8D 44 24 ?? 48 8D 34 30 E8 + } + $decrypt_configuration_p2 = { + 0F B7 54 24 ?? 66 41 89 54 24 ?? 83 44 24 ?? ?? 83 7C 24 ?? ?? 77 ?? 89 6C 24 ?? 41 + BC ?? ?? ?? ?? EB ?? 3C ?? 75 ?? 48 8D 7B ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? + ?? ?? 66 89 44 24 ?? 44 89 64 24 ?? EB ?? 41 83 C4 ?? 83 C5 ?? 48 83 C3 ?? 4C 89 F1 + 4C 89 FF B8 ?? ?? ?? ?? F2 AE 48 F7 D1 48 83 E9 ?? 48 89 D8 4C 29 E8 48 39 C8 0F 82 + ?? ?? ?? ?? 8B 4C 24 ?? 48 8B 54 24 ?? 89 8A ?? ?? ?? ?? 48 8D 5C 24 ?? B9 ?? ?? ?? + ?? B8 ?? ?? ?? ?? 48 89 DF F3 48 AB 48 8B 7C 24 ?? 48 C7 C1 ?? ?? ?? ?? F2 AE 48 F7 + D1 48 8D 51 ?? 48 8B 74 24 ?? 48 89 DF E8 ?? ?? ?? ?? 80 7C 24 ?? ?? 75 ?? 48 8B 44 + 24 ?? C6 80 ?? ?? ?? ?? ?? 80 7C 24 ?? ?? 75 ?? 48 8B 54 24 ?? C6 82 ?? ?? ?? ?? ?? + 80 7C 24 ?? ?? 75 ?? 48 8B 4C 24 ?? C6 81 ?? ?? ?? ?? ?? 80 7C 24 ?? ?? 75 ?? 48 8B + 44 24 ?? C6 80 ?? ?? ?? ?? ?? 80 7C 24 ?? ?? 75 ?? 48 8B 54 24 ?? C6 82 ?? ?? ?? ?? + ?? 80 7C 24 ?? ?? 75 ?? 48 8B 4C 24 ?? C6 81 ?? ?? ?? ?? ?? 80 7C 24 ?? ?? 75 ?? 48 + 8B 44 24 ?? C6 80 ?? ?? ?? ?? ?? 48 8D 5C 24 ?? B9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 48 89 + DF F3 48 AB 48 8B 7C 24 ?? 48 C7 C1 ?? ?? ?? ?? F2 AE 48 F7 D1 48 83 E9 ?? 48 81 F9 + ?? ?? ?? ?? BA ?? ?? ?? ?? 48 0F 46 D1 48 8B 74 24 ?? 48 89 DF E8 ?? ?? ?? ?? C6 44 + 24 ?? ?? C6 44 24 ?? ?? 48 8D 74 24 ?? 48 89 DF E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? + ?? ?? 48 8D 7C 24 ?? B8 ?? ?? ?? ?? 48 C7 C1 ?? ?? ?? ?? F2 AE 48 F7 D1 83 E9 ?? 8D + } + $decrypt_configuration_p3 = { + 41 ?? 48 98 80 7C 04 ?? ?? 74 ?? 48 63 C1 C6 44 04 ?? ?? 83 C1 ?? 48 63 C9 C6 44 0C + ?? ?? 4C 89 EB BD ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 49 C7 + C4 ?? ?? ?? ?? 4C 8D 74 24 ?? 41 BF ?? ?? ?? ?? EB ?? 0F B6 03 3C ?? 75 ?? 8B 7C 24 + ?? 48 8D 54 24 ?? 48 8D 3C 3A BA ?? ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 54 24 + ?? 48 81 C2 ?? ?? ?? ?? 48 8B 4C 24 ?? 66 89 44 91 ?? 0F B7 44 24 ?? 66 89 44 91 ?? + 83 44 24 ?? ?? 83 7C 24 ?? ?? 77 ?? 89 6C 24 ?? EB ?? 3C ?? 75 ?? 48 8D 7B ?? BA ?? + ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 89 44 24 ?? 83 C5 ?? 48 83 C3 ?? 4C 89 E1 + 4C 89 F7 44 89 F8 F2 AE 48 F7 D1 48 83 E9 ?? 48 89 D8 4C 29 E8 48 39 C8 0F 82 ?? ?? + ?? ?? 8B 4C 24 ?? 48 8B 54 24 ?? 89 8A ?? ?? ?? ?? EB ?? 48 8B 44 24 ?? C7 80 ?? ?? + ?? ?? ?? ?? ?? ?? 48 8B 7C 24 ?? 48 83 C7 ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? + ?? ?? 85 C0 BA ?? ?? ?? ?? 0F 4E C2 48 8B 54 24 ?? 89 82 ?? ?? ?? ?? B8 ?? ?? ?? ?? + EB ?? B8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5D 41 5C 41 5D 41 5E 41 5F C3 + } + $encrypt_and_send_data = { + 48 89 5C 24 ?? 48 89 6C 24 ?? 4C 89 64 24 ?? 4C 89 6C 24 ?? 4C 89 74 24 ?? 4C 89 7C + 24 ?? 48 83 EC ?? 41 89 FC 48 89 F5 49 89 D6 41 89 CD 48 85 F6 0F 84 ?? ?? ?? ?? BF + ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C3 48 85 C0 0F 84 ?? ?? ?? ?? 48 8B 45 ?? 48 89 03 + 0F B6 45 ?? 88 43 ?? 8B 6B ?? 48 8B 3D ?? ?? ?? ?? 48 83 C7 ?? E8 ?? ?? ?? ?? BA ?? + ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 44 89 E9 BA ?? ?? ?? ?? 48 89 DE 44 + 89 E7 E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 3D ?? ?? ?? ?? 48 83 C7 ?? E8 ?? ?? ?? ?? 48 + 89 DF E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 85 ED 74 + ?? 4D 85 F6 75 ?? 48 8B 3D ?? ?? ?? ?? 48 83 C7 ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 + ?? ?? ?? ?? 4C 63 FD 4C 89 FF E8 ?? ?? ?? ?? 48 89 C3 48 85 C0 74 ?? 4C 89 FA 4C 89 + F6 48 89 C7 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 EE 48 89 DF E8 ?? ?? ?? ?? 44 89 E9 89 + EA 48 89 DE 44 89 E7 E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 3D ?? ?? ?? ?? 48 83 C7 ?? E8 + ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? EB ?? 48 8B 3D ?? ?? ?? ?? 48 83 + C7 ?? E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? 48 + 8B 5C 24 ?? 48 8B 6C 24 ?? 4C 8B 64 24 ?? 4C 8B 6C 24 ?? 4C 8B 74 24 ?? 4C 8B 7C 24 + ?? 48 83 C4 ?? C3 + } + $receive_and_decrypt_data = { + 48 89 5C 24 ?? 48 89 6C 24 ?? 4C 89 64 24 ?? 4C 89 6C 24 ?? 48 83 EC ?? 41 89 FC 48 + 89 F3 49 89 D5 89 CD 48 85 F6 74 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? BA ?? + ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 8B 53 ?? 85 D2 74 ?? 4D 85 ED 75 ?? + B8 ?? ?? ?? ?? EB ?? 81 FA ?? ?? ?? ?? 77 ?? 89 E9 4C 89 EE 44 89 E7 E8 ?? ?? ?? ?? + 85 C0 74 ?? 8B 73 ?? BA ?? ?? ?? ?? 4C 89 EF E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? EB ?? B8 + ?? ?? ?? ?? 48 8B 5C 24 ?? 48 8B 6C 24 ?? 4C 8B 64 24 ?? 4C 8B 6C 24 ?? 48 83 C4 ?? + C3 + } + + condition: + uint32(0)==0x464C457F and (( all of ($change_name_on_system_p*)) and ( all of ($decrypt_configuration_p*)) and ($encrypt_and_send_data) and ($receive_and_decrypt_data)) +} +rule REVERSINGLABS_Win64_Backdoor_Sidetwist : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects SideTwist backdoor." + author = "ReversingLabs" + id = "979b442e-8739-54a8-b486-39fc5673791e" + date = "2024-03-18" + modified = "2024-03-18" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/Win64.Backdoor.SideTwist.yara#L1-L154" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "811fa73ede59493c71435743848a3fce3a1604ec4065ffcb0b43e9715dfa5c31" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "SideTwist" + tc_detection_factor = 5 + importance = 25 + + strings: + $anti_sandbox_detect_environment = { + 55 57 56 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 89 4D ?? 48 89 55 ?? E8 ?? + ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? 48 8D 55 ?? 48 8D 45 ?? 4C + 8D 05 ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 85 C0 75 ?? 48 8B 45 ?? 48 85 + C0 74 ?? B8 ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 48 8D 45 ?? 48 + 89 C1 E8 ?? ?? ?? ?? 48 8B 55 ?? 48 8D 4D ?? 48 8D 45 ?? 49 89 C8 48 89 C1 E8 ?? ?? + ?? ?? 48 8D 45 ?? 48 8D 55 ?? 4C 8D 05 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 + ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C1 + E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF + D0 85 C0 0F 94 C0 84 C0 74 ?? 48 8D 05 ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF + D0 BB ?? ?? ?? ?? BE ?? ?? ?? ?? EB + } + $collect_host_information = { + 55 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 4D ?? 48 89 55 ?? C7 45 ?? + ?? ?? ?? ?? 8B 45 ?? 89 C0 48 BA ?? ?? ?? ?? ?? ?? ?? ?? 48 39 C2 72 ?? 48 01 C0 48 + 89 C1 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 + 8B 45 ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? + 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8B 45 ?? 49 89 D0 48 89 C2 B9 ?? + ?? ?? ?? 48 8B 05 ?? ?? ?? ?? FF D0 85 C0 0F 95 C0 84 C0 0F 84 ?? ?? ?? ?? 48 8D 45 + ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 4D ?? 48 8B 55 ?? 48 8D 45 ?? 49 89 C8 48 89 C1 E8 + ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? + 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 + 89 C2 48 8D 4D ?? 48 8D 45 ?? 49 89 C9 49 89 D8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? + 48 8D 55 ?? 41 B9 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? + 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? + 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 + ?? ?? ?? ?? 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 84 C0 74 ?? 48 8B 45 ?? 48 8D 15 ?? + ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 48 8B 45 ?? 48 89 + C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 89 + C1 E8 ?? ?? ?? ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D + 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 + 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? + 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 90 48 8B 45 ?? 48 81 C4 ?? ?? ?? ?? 5B 5D C3 + } + $contact_c2_server = { + 55 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 4D ?? 48 89 55 ?? 48 8D 45 + ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8D 85 ?? ?? ?? ?? 49 89 D0 48 8D 15 ?? ?? + ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 8D 50 ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? + ?? ?? 48 8B 55 ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 4C 8D 45 + ?? 48 8B 55 ?? 48 8D 8D ?? ?? ?? ?? 48 89 4C 24 ?? 48 8D 4D ?? 48 89 4C 24 ?? 4D 89 + C1 4C 8D 05 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? + 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 + 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 C1 + E8 ?? ?? ?? ?? 85 C0 0F 95 C0 84 C0 74 ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? + ?? 48 8D 95 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 4D ?? 48 8D 55 ?? + 48 8B 45 ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? BB + ?? ?? ?? ?? EB ?? BB ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 89 D8 + EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 + C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? + 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 48 89 + C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 + E8 ?? ?? ?? ?? 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5D C3 + } + $parse_c2_response = { + 55 53 48 83 EC ?? 48 8D 6C 24 ?? 48 89 4D ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 + 8D 55 ?? 48 8D 45 ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 + ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8B 45 ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? + ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 41 B8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 + ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 C1 48 8B 55 ?? 48 + 8B 45 ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B + 55 ?? 48 01 C2 48 8B 45 ?? 49 89 D0 BA ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 + ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 + D8 48 89 C1 E8 ?? ?? ?? ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 + 89 C1 E8 ?? ?? ?? ?? 90 48 83 C4 ?? 5B 5D C3 + } + $download_file_from_c2_p1 = { + 55 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 4D ?? 48 89 55 ?? 4C 89 45 + ?? 4C 89 4D ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 5D ?? 48 8B 55 ?? + 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? + ?? 49 89 D0 48 89 C2 48 89 D9 E8 ?? ?? ?? ?? 85 C0 0F 95 C0 88 45 ?? 48 8D 85 ?? ?? + ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 0F B6 45 ?? 83 F0 ?? 84 C0 0F 84 ?? ?? ?? ?? 48 8D 85 + ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? + 48 89 C2 48 8D 85 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF + D0 89 45 ?? 83 7D ?? ?? 0F 95 C0 84 C0 74 ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 + 8D 55 ?? 48 8B 45 ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 + ?? 48 89 C1 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 9D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? + 48 89 C1 E8 ?? ?? ?? ?? 48 89 C2 48 8B 45 ?? 49 89 D9 49 89 D0 BA ?? ?? ?? ?? 48 89 + C1 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 8D 45 ?? 48 + } + $download_file_from_c2_p2 = { + 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8B 45 ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 + E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 8D 45 ?? 48 8B 55 ?? 49 + 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 8D 55 ?? 4C 8D 05 + ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 8B 4D ?? 48 8D 55 ?? 49 89 C8 48 + 89 C1 E8 ?? ?? ?? ?? 90 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 + ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? + ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? + EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 + C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 + 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 48 8B + 45 ?? 48 81 C4 ?? ?? ?? ?? 5B 5D C3 + } + $reply_to_c2_server = { + 55 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 4D ?? 48 89 55 ?? 4C 89 45 + ?? 4C 89 4D ?? 48 8B 55 ?? 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? + 48 8B 55 ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 8B 55 ?? 49 89 + D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 8D 55 ?? 4C 8D 05 ?? + ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 8D 8D ?? ?? ?? ?? 48 8D 55 ?? 49 89 + C8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 8D 55 ?? 4C 8D 05 ?? ?? ?? ?? 48 89 C1 E8 + ?? ?? ?? ?? 48 8D 55 ?? 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 + ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? + 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB + ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 + E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 + 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 90 48 81 + C4 ?? ?? ?? ?? 5B 5D C3 + } + + condition: + uint16(0)==0x5A4D and ($anti_sandbox_detect_environment) and ($collect_host_information) and ($contact_c2_server) and ($parse_c2_response) and ( all of ($download_file_from_c2_p*)) and ($reply_to_c2_server) +} +rule REVERSINGLABS_Bytecode_MSIL_Backdoor_Njrat : TC_DETECTION MALICIOUS MALWARE FILE +{ + meta: + description = "Yara rule that detects NjRAT backdoor." + author = "ReversingLabs" + id = "578c813f-4bba-52cd-bcc7-4de2c3943cf7" + date = "2024-07-31" + modified = "2024-07-31" + reference = "ReversingLabs" + source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/yara/backdoor/ByteCode.MSIL.Backdoor.NjRAT.yara#L1-L266" + license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/5cd6c7eb3df8e809418e3d5b6d2c9f09a7c2dfd0/LICENSE" + logic_hash = "eeecf90965e6952d8b9efc9d1e96eaa47709b1d69fc7d435f4aebaaf0191f317" + score = 75 + quality = 90 + tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" + status = "RELEASED" + sharing = "TLP:WHITE" + category = "MALWARE" + tc_detection_type = "Backdoor" + tc_detection_name = "NjRAT" + tc_detection_factor = 5 + importance = 25 + + strings: + $persistence_mechanism_v1_p1 = { + 00 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? + ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? + ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 16 2B ?? 17 13 ?? 11 ?? 39 ?? ?? ?? ?? + 00 28 ?? ?? ?? ?? 18 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? + 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 7E ?? ?? ?? ?? 28 ?? + ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 7E ?? ?? ?? + ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? + ?? ?? ?? 17 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? + ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 0A + 00 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? DE ?? 00 00 00 1B 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 + 72 ?? ?? ?? ?? A2 00 11 ?? 17 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? A2 00 11 ?? 18 72 ?? ?? + ?? ?? A2 00 11 ?? 19 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? A2 00 11 ?? 1A 72 ?? ?? ?? ?? A2 + 00 11 ?? 28 ?? ?? ?? ?? 16 16 15 28 ?? ?? ?? ?? 26 DE ?? 25 28 ?? ?? ?? ?? 0B 00 28 + ?? ?? ?? ?? DE ?? 00 7E ?? ?? ?? ?? 13 ?? 11 ?? 39 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 6F + ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? + ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 + DE ?? 25 28 ?? ?? ?? ?? 0C 00 28 ?? ?? ?? ?? DE ?? 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? + ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E + ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DE ?? 25 + } + $persistence_mechanism_v1_p2 = { + 28 ?? ?? ?? ?? 0D 00 28 ?? ?? ?? ?? DE ?? 00 00 7E ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 + 28 ?? ?? ?? ?? 18 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 1D 28 ?? ?? ?? ?? + 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 00 1D + 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 19 73 ?? + ?? ?? ?? 80 ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 00 + 7E ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 16 + 15 28 ?? ?? ?? ?? 26 00 7E ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 28 ?? ?? ?? ?? 18 28 ?? + ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 00 7E ?? ?? ?? + ?? 13 ?? 11 ?? 39 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 13 ?? 18 13 ?? 28 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 13 ?? + 11 ?? 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 00 28 ?? ?? ?? ?? 11 ?? 11 + ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 11 ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? + 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 00 11 ?? 72 ?? ?? ?? ?? + 11 ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 11 + ?? 72 ?? ?? ?? ?? 11 ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 11 ?? 72 ?? ?? ?? ?? + 11 ?? 28 ?? ?? ?? ?? 17 8C ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 11 + ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 + } + $connect_v1_p1 = { + 00 16 80 ?? ?? ?? ?? 20 D0 07 00 00 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 0B 00 07 13 ?? + 11 ?? 28 ?? ?? ?? ?? 00 00 00 7E ?? ?? ?? ?? 14 (FE | 01) ?? 16 (FE | 01) ?? 13 ?? 11 + ?? 2C ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 14 80 ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? + ?? 0C 00 28 ?? ?? ?? ?? DE ?? 00 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DE ?? 25 28 + ?? ?? ?? ?? 0D 00 28 ?? ?? ?? ?? DE ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? + ?? ?? DE ?? 00 00 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? + ?? ?? ?? 20 00 20 03 00 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 20 00 20 03 00 6F ?? ?? ?? + ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 20 10 27 00 00 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? + 6F ?? ?? ?? ?? 20 10 27 00 00 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 14 72 ?? ?? ?? ?? 18 + 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 17 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 8C ?? ?? ?? ?? A2 + 00 11 ?? 14 14 14 17 28 ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? + 28 ?? ?? ?? ?? 80 ?? ?? ?? ?? 17 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 00 + 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? + ?? ?? ?? 13 ?? 11 ?? 2C ?? 11 ?? 7F ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 13 ?? 2B ?? 00 11 ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 + } + $connect_v1_p2 = { + 00 1F ?? 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 1B 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 11 ?? A2 00 + 11 ?? 17 7E ?? ?? ?? ?? A2 00 11 ?? 18 72 ?? ?? ?? ?? A2 00 11 ?? 19 7E ?? ?? ?? ?? + A2 00 11 ?? 1A 72 ?? ?? ?? ?? A2 00 11 ?? 28 ?? ?? ?? ?? A2 00 11 ?? 17 7E ?? ?? ?? + ?? A2 00 11 ?? 18 72 ?? ?? ?? ?? A2 00 11 ?? 19 7E ?? ?? ?? ?? A2 00 11 ?? 1A 72 ?? + ?? ?? ?? A2 00 11 ?? 1B 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1C 72 ?? ?? ?? ?? + A2 00 11 ?? 1D 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1E 72 ?? ?? ?? ?? A2 00 11 + ?? 1F ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 00 11 ?? + 1F ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 00 11 ?? 1F + ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 00 11 ?? 1F ?? + 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 7E + ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 7E ?? + ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 28 ?? ?? ?? ?? 13 ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? + ?? 12 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 DE ?? 25 28 ?? ?? ?? ?? 13 + ?? 00 28 ?? ?? ?? ?? DE ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 16 80 ?? ?? ?? ?? 28 + ?? ?? ?? ?? DE ?? 00 00 DE ?? 11 ?? 28 ?? ?? ?? ?? 00 DC 7E ?? ?? ?? ?? 0A 2B ?? 06 + } + $send_v1 = { + 00 7E ?? ?? ?? ?? 16 (FE | 01) ?? 13 ?? 11 ?? 2C ?? 16 0A 38 ?? ?? ?? ?? 00 00 7E ?? + ?? ?? ?? 0B 00 07 13 ?? 11 ?? 28 ?? ?? ?? ?? 00 00 7E ?? ?? ?? ?? 16 (FE | 01) ?? 13 + ?? 11 ?? 2C ?? 16 0A DD ?? ?? ?? ?? 00 73 ?? ?? ?? ?? 13 ?? 02 8E B7 0D 12 ?? 28 ?? + ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 0C 11 ?? 08 16 08 + 8E B7 6F ?? ?? ?? ?? 00 11 ?? 02 16 02 8E B7 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 6F ?? + ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 16 11 ?? 6F ?? ?? ?? ?? B7 16 6F ?? ?? ?? ?? 26 00 DE + ?? 11 ?? 28 ?? ?? ?? ?? 00 DC DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 11 ?? 28 ?? ?? ?? ?? + 00 11 ?? 13 ?? 00 7E ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 16 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? + 6F ?? ?? ?? ?? 00 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 28 ?? + ?? ?? ?? DE ?? 00 7E ?? ?? ?? ?? 0A 2B ?? 06 + } + $receive_v1_p1 = { + 00 00 00 72 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 14 (FE | 01) ?? 16 (FE | 01) ?? + 13 ?? 11 ?? 39 ?? ?? ?? ?? 15 6A 0A 16 0B 00 00 00 07 17 D6 0B 07 1F ?? (FE | 01) ?? + 13 ?? 11 ?? 2C ?? 16 0B 17 28 ?? ?? ?? ?? 00 00 7E ?? ?? ?? ?? 16 (FE | 01) ?? 13 ?? + 11 ?? 2C ?? 00 DD ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 (FE | 04) ?? 13 ?? + 11 ?? 2C ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 15 16 6F ?? ?? ?? ?? 26 00 00 00 7E ?? ?? + ?? ?? 6F ?? ?? ?? ?? 16 (FE | 02) ?? 13 ?? 11 ?? 39 ?? ?? ?? ?? 06 15 6A (FE | 01) ?? + 13 ?? 11 ?? 39 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? + ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 00 11 ?? 15 59 13 ?? 11 ?? 45 ?? ?? ?? ?? ?? ?? ?? ?? + ?? ?? ?? ?? 2B ?? 00 00 DD ?? ?? ?? ?? 2B ?? 00 11 ?? 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? + ?? 13 ?? 06 16 6A (FE | 01) ?? 13 ?? 11 ?? 2C ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 15 + 6A 0A 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 (FE | 02) ?? 16 (FE | 01) ?? 13 ?? 11 ?? 2C + ?? 38 ?? ?? ?? ?? 00 38 ?? ?? ?? ?? 00 11 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 00 17 13 ?? 11 ?? 3A ?? + ?? ?? ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 D6 17 DA 17 D6 8D ?? ?? ?? ?? 80 ?? ?? + ?? ?? 06 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DA 0D 7E ?? ?? ?? ?? 8E B7 6A 09 (FE | 02) + } + $receive_v1_p2 = { + 13 ?? 11 ?? 2C ?? 09 17 6A DA B7 17 D6 17 DA 17 D6 8D ?? ?? ?? ?? 80 ?? ?? ?? ?? 00 + 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 16 7E ?? ?? ?? ?? 8E B7 16 6F ?? ?? ?? + ?? 0C 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 16 08 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 6F ?? ?? + ?? ?? 06 (FE | 01) ?? 13 ?? 11 ?? 2C ?? 15 6A 0A 14 (FE | 06) ?? ?? ?? ?? ?? 73 ?? ?? + ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 11 ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 + 11 ?? 1F ?? 6F ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 73 ?? ?? ?? ?? 80 ?? + ?? ?? ?? 00 38 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? + 00 00 00 00 00 7E ?? ?? ?? ?? 14 (FE | 01) ?? 16 (FE | 01) ?? 13 ?? 11 ?? 2C ?? 7E ?? + ?? ?? ?? 28 ?? ?? ?? ?? 14 72 ?? ?? ?? ?? 16 8D ?? ?? ?? ?? 14 14 14 17 28 ?? ?? ?? + ?? 26 14 80 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 + 16 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 (FE | 01) ?? 13 ?? 11 ?? 2C ?? 2B ?? 00 17 80 ?? + ?? ?? ?? 38 ?? ?? ?? ?? 00 + } + $connect_v2 = { + 16 80 ?? ?? ?? ?? 20 D0 07 00 00 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 0A 06 25 13 ?? 28 ?? + ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 14 80 ?? ?? ?? ?? DE ?? + 26 DE ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? DE ?? 26 DE ?? 73 ?? ?? ?? ?? + 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 20 00 20 03 00 6F ?? ?? + ?? ?? 7E ?? ?? ?? ?? 20 00 20 03 00 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 20 + 10 27 00 00 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 20 10 27 00 00 6F ?? ?? ?? + ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 80 + ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 0B 72 ?? ?? ?? ?? 72 ?? + ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 2C ?? 07 7F ?? ?? ?? ?? 28 + ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 2B ?? 07 0C 72 ?? ?? ?? ?? 72 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 08 12 ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 0B 1B 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 07 A2 11 ?? 17 7E ?? ?? ?? ?? A2 11 ?? 18 + 72 ?? ?? ?? ?? A2 11 ?? 19 7E ?? ?? ?? ?? A2 11 ?? 1A 72 ?? ?? ?? ?? A2 11 ?? 28 ?? + ?? ?? ?? 0B 07 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 7E + ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B + 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? + ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 DE ?? 26 DE ?? DE ?? 26 16 80 ?? ?? ?? ?? DE ?? + DE ?? 11 ?? 28 ?? ?? ?? ?? DC 7E + } + $receive_v2 = { + 72 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 39 ?? ?? ?? ?? 15 6A 0A 16 0B 07 17 D6 + 0B 07 1F ?? 33 ?? 16 0B 17 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 39 ?? ?? ?? ?? 7E ?? ?? ?? + ?? 6F ?? ?? ?? ?? 17 3C ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 15 16 6F ?? ?? ?? + ?? 26 38 ?? ?? ?? ?? 06 15 6A 3B ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 D6 8D + ?? ?? ?? ?? 80 ?? ?? ?? ?? 06 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DA 0C 7E ?? ?? ?? ?? 8E + 69 6A 08 31 ?? 08 17 6A DA B7 17 D6 8D ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F + ?? ?? ?? ?? 7E ?? ?? ?? ?? 16 7E ?? ?? ?? ?? 8E 69 16 6F ?? ?? ?? ?? 0D 7E ?? ?? ?? + ?? 7E ?? ?? ?? ?? 16 09 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 40 ?? ?? ?? + ?? 15 6A 0A 7E ?? ?? ?? ?? 2D ?? 14 (FE | 06) ?? ?? ?? ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? + ?? ?? 7E ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 11 ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F + ?? ?? ?? ?? 11 ?? 1F ?? 6F ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 73 ?? ?? ?? + ?? 80 ?? ?? ?? ?? 38 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? + 6F ?? ?? ?? ?? 13 ?? 11 ?? 15 2E ?? 11 ?? 2C ?? 11 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 12 + ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 28 + ?? ?? ?? ?? 0A 06 16 6A 33 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 15 6A 0A 7E ?? ?? ?? + ?? 6F ?? ?? ?? ?? 16 3E ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? DE + ?? 26 DE ?? 7E ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 14 72 ?? ?? ?? ?? 16 8D ?? ?? ?? ?? + 14 14 14 17 28 ?? ?? ?? ?? 26 14 80 ?? ?? ?? ?? DE ?? 26 DE ?? 16 80 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 2C ?? 17 80 + } + $get_system_information_v2_p1 = { + 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 2C ?? 06 0B 7F ?? ?? ?? ?? 28 ?? ?? ?? ?? + 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 07 12 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? + ?? 28 ?? ?? ?? ?? 0A 2B ?? 06 0D 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? + ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 + ?? 09 12 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 26 06 13 ?? 28 ?? + ?? ?? ?? 13 ?? 11 ?? 12 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 06 + 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 26 06 72 ?? ?? ?? ?? 7E ?? ?? + ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 06 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE + ?? 26 06 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 06 7E ?? ?? ?? ?? 6F + ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E + ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 26 06 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? + ?? 0A DE ?? 06 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 06 73 ?? ?? ?? ?? 28 + ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 26 06 72 ?? ?? ?? ?? 28 ?? ?? ?? + ?? 0A DE ?? 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? + ?? ?? ?? 15 16 28 ?? ?? ?? ?? 13 ?? 11 ?? 8E 69 17 33 ?? 06 72 ?? ?? ?? ?? 28 ?? ?? + ?? ?? 0A 06 11 ?? 11 ?? 8E 69 17 DA 9A 28 ?? ?? ?? ?? 0A DE ?? 26 06 72 + } + $get_system_information_v2_p2 = { + 28 ?? ?? ?? ?? 0A DE ?? 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 06 + 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 2B ?? 06 72 ?? ?? ?? ?? 7E ?? ?? ?? + ?? 28 ?? ?? ?? ?? 0A DE ?? 26 06 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 28 ?? ?? ?? + ?? 2C ?? 06 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 2B ?? 06 72 ?? ?? ?? ?? + 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 06 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A + 06 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 06 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? + 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? + 28 ?? ?? ?? ?? 16 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A + 13 ?? 11 ?? 6F ?? ?? ?? ?? 1F ?? 33 ?? 11 ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 + ?? 11 ?? 17 D6 13 ?? 11 ?? 11 ?? 8E 69 32 ?? DE ?? 26 DE ?? 06 11 ?? 28 + } + $send_v2 = { + 7E ?? ?? ?? ?? 2D ?? 16 2A 7E ?? ?? ?? ?? 0A 06 25 13 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? + ?? 2D ?? 16 13 ?? DD ?? ?? ?? ?? 73 ?? ?? ?? ?? 0B 02 8E 69 13 ?? 12 ?? 28 ?? ?? ?? + ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 12 ?? 28 ?? ?? ?? ?? 0D 07 09 16 09 8E 69 6F ?? + ?? ?? ?? 07 02 16 02 8E 69 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 07 6F ?? ?? + ?? ?? 16 07 6F ?? ?? ?? ?? B7 16 6F ?? ?? ?? ?? 26 07 6F ?? ?? ?? ?? DE ?? 11 ?? 28 + ?? ?? ?? ?? DC DE ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 16 80 ?? ?? ?? + ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 28 ?? ?? ?? ?? DE ?? 7E ?? ?? ?? ?? + 2A 11 + } + + condition: + uint16(0)==0x5A4D and ((( all of ($persistence_mechanism_v1_p*)) and ( all of ($connect_v1_p*)) and ($send_v1) and ( all of ($receive_v1_p*))) or (($connect_v2) and ($receive_v2) and ( all of ($get_system_information_v2_p*)) and ($send_v2))) +} +/* + * YARA Rule Set + * Repository Name: Elastic + * Repository: https://github.com/elastic/protections-artifacts/ + * Retrieval Date: 2024-09-01 + * Git Commit: 9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd + * Number of Rules: 1781 + * Skipped: 0 (age), 6 (quality), 0 (score), 0 (importance) + * + * + * LICENSE + * + * Elastic License 2.0 + +URL: https://www.elastic.co/licensing/elastic-license + +## Acceptance + +By using the software, you agree to all of the terms and conditions below. + +## Copyright License + +The licensor grants you a non-exclusive, royalty-free, worldwide, +non-sublicensable, non-transferable license to use, copy, distribute, make +available, and prepare derivative works of the software, in each case subject to +the limitations and conditions below. + +## Limitations + +You may not provide the software to third parties as a hosted or managed +service, where the service provides users with access to any substantial set of +the features or functionality of the software. + +You may not move, change, disable, or circumvent the license key functionality +in the software, and you may not remove or obscure any functionality in the +software that is protected by the license key. + +You may not alter, remove, or obscure any licensing, copyright, or other notices +of the licensor in the software. Any use of the licensor’s trademarks is subject +to applicable law. + +## Patents + +The licensor grants you a license, under any patent claims the licensor can +license, or becomes able to license, to make, have made, use, sell, offer for +sale, import and have imported the software, in each case subject to the +limitations and conditions in this license. This license does not cover any +patent claims that you cause to be infringed by modifications or additions to +the software. If you or your company make any written claim that the software +infringes or contributes to infringement of any patent, your patent license for +the software granted under these terms ends immediately. If your company makes +such a claim, your patent license ends immediately for work on behalf of your +company. + +## Notices + +You must ensure that anyone who gets a copy of any part of the software from you +also gets a copy of these terms. + +If you modify the software, you must include in any modified copies of the +software prominent notices stating that you have modified the software. + +## No Other Rights + +These terms do not imply any licenses other than those expressly granted in +these terms. + +## Termination + +If you use the software in violation of these terms, such use is not licensed, +and your licenses will automatically terminate. If the licensor provides you +with a notice of your violation, and you cease all violation of this license no +later than 30 days after you receive that notice, your licenses will be +reinstated retroactively. However, if you violate these terms after such +reinstatement, any additional violation of these terms will cause your licenses +to terminate automatically and permanently. + +## No Liability + +*As far as the law allows, the software comes as is, without any warranty or +condition, and the licensor will not be liable to you for any damages arising +out of these terms or the use or nature of the software, under any kind of +legal claim.* + +## Definitions + +The **licensor** is the entity offering these terms, and the **software** is the +software the licensor makes available under these terms, including any portion +of it. + +**you** refers to the individual or entity agreeing to these terms. + +**your company** is any legal entity, sole proprietorship, or other kind of +organization that you work for, plus all organizations that have control over, +are under the control of, or are under common control with that +organization. **control** means ownership of substantially all the assets of an +entity, or the power to direct its management and policies by vote, contract, or +otherwise. Control can be direct or indirect. + +**your licenses** are all the licenses granted to you for the software under +these terms. + +**use** means anything you do with the software requiring one of your licenses. + +**trademark** means trademarks, service marks, and similar rights. + + */ +rule ELASTIC_Linux_Rootkit_Dakkatoni_010D3Ac2 : FILE MEMORY +{ + meta: + description = "Detects Linux Rootkit Dakkatoni (Linux.Rootkit.Dakkatoni)" + author = "Elastic Security" + id = "010d3ac2-0bb2-4966-bf5f-fd040ba07311" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Rootkit_Dakkatoni.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "38b2d033eb5ce87faa4faa7fcac943d9373e432e0d45e741a0c01d714ee9d4d3" + logic_hash = "51119321f29aed695e09da22d3234eae96db93e8029d4525d018e56c7131f7b8" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "2c7935079dc971d2b8a64c512ad677e946ff45f7f1d1b62c3ca011ebde82f13b" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 89 C8 C1 E0 0D 31 C1 89 CE 83 E6 03 83 C6 05 89 C8 31 D2 C1 } + + condition: + all of them +} +rule ELASTIC_Windows_Trojan_Latrodectus_841Ff697 : FILE MEMORY +{ + meta: + description = "Detects Windows Trojan Latrodectus (Windows.Trojan.Latrodectus)" + author = "Elastic Security" + id = "841ff697-f389-497a-b813-3b9e19cba26e" + date = "2024-03-13" + modified = "2024-05-08" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Latrodectus.yar#L1-L26" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "aee22a35cbdac3f16c3ed742c0b1bfe9739a13469cf43b36fb2c63565111028c" + logic_hash = "aa1a4813a18b4eb4f07e805ff9c87523ad74f59c0ed538212918335eaeee29d7" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "8f095e7909860471e2702b247f4cefa694b698c236e67844ef0b0b7714518a18" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "windows" + + strings: + $Str1 = { 48 83 EC 38 C6 44 24 20 73 C6 44 24 21 63 C6 44 24 22 75 C6 44 24 23 62 C6 44 24 24 } + $crc32_loadlibrary = { 48 89 44 24 40 EB 02 EB 90 48 8B 4C 24 20 E8 ?? ?? FF FF 48 8B 44 24 40 48 81 C4 E8 02 00 00 C3 } + $delete_self = { 44 24 68 BA 03 00 00 00 48 8B 4C 24 48 FF 15 ED D1 00 00 85 C0 75 14 48 8B 4C 24 50 E8 ?? ?? 00 00 B8 FF FF FF FF E9 A6 00 } + $Str4 = { 89 44 24 44 EB 1F C7 44 24 20 00 00 00 00 45 33 C9 45 33 C0 33 D2 48 8B 4C 24 48 FF 15 7E BB 00 00 89 44 24 44 83 7C 24 44 00 75 02 EB 11 48 8B 44 24 48 EB 0C 33 C0 85 C0 0F 85 10 FE FF FF 33 } + $handler_check = { 83 BC 24 D8 01 00 00 12 74 36 83 BC 24 D8 01 00 00 0E 74 2C 83 BC 24 D8 01 00 00 0C 74 22 83 BC 24 D8 01 00 00 0D 74 18 83 BC 24 D8 01 00 00 0F 74 0E 83 BC 24 D8 01 00 00 04 0F 85 44 02 00 00 } + $hwid_calc = { 48 89 4C 24 08 48 8B 44 24 08 69 00 0D 66 19 00 48 8B 4C 24 08 89 01 48 8B 44 24 08 8B 00 C3 } + $string_decrypt = { 89 44 24 ?? 48 8B 44 24 ?? 0F B7 40 ?? 8B 4C 24 ?? 33 C8 8B C1 66 89 44 24 ?? 48 8B 44 24 ?? 48 83 C0 ?? 48 89 44 24 ?? 33 C0 66 89 44 24 ?? EB ?? } + $campaign_fnv = { 48 03 C8 48 8B C1 48 39 44 24 08 73 1E 48 8B 44 24 08 0F BE 00 8B 0C 24 33 C8 8B C1 89 04 24 69 04 24 93 01 00 01 89 04 24 EB BE } + + condition: + 2 of them +} +rule ELASTIC_Linux_Exploit_Wuftpd_0991E62F : FILE MEMORY +{ + meta: + description = "Detects Linux Exploit Wuftpd (Linux.Exploit.Wuftpd)" + author = "Elastic Security" + id = "0991e62f-af72-416a-b88b-6bc8a501b8bb" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Wuftpd.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c0b6303300f38013840abe17abe192db6a99ace78c83bc7ef705f5c568bc98fd" + logic_hash = "71ad26a182c7f16e7e0ad7f7afe0dcf1d38fe953dc0806341d7e21ee4acea87d" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "642c7b059fa604a0a5110372e2247da9625b07008b012fd498670a6dd1b29974" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { F3 8D 4E 08 8D 56 0C B0 0B CD 80 31 C0 31 DB } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Winnti_61215D98 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Winnti (Linux.Trojan.Winnti)" + author = "Elastic Security" + id = "61215d98-f52d-45d3-afa2-4bd25270aa99" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Winnti.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "cc1455e3a479602581c1c7dc86a0e02605a3c14916b86817960397d5a2f41c31" + logic_hash = "051cc157f189094d25d45e66e410bdfd61ed7649a4c935d076cec1597c5debf5" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "20ee92147edbf91447cca2ee0c47768a50ec9c7aa7d081698953d3bdc2a25320" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { FF FF FF C9 C3 55 48 89 E5 48 83 EC 30 89 F8 66 89 45 DC C7 45 FC FF FF } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Winnti_4C5A1865 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Winnti (Linux.Trojan.Winnti)" + author = "Elastic Security" + id = "4c5a1865-ff41-445b-8616-c83b87498c2b" + date = "2021-06-28" + modified = "2021-09-16" + reference = "0d963a713093fc8e5928141f5747640c9b43f3aadc8a5478c949f7ec364b28ad" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Winnti.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "69f6dcba59ec8cd7f4dfe853495a35601e35d74476fad9e18bef7685a68ece51" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "685fe603e04ff123b3472293d3d83e2dc833effd1a7e6c616ff17ed61df0004c" + severity = "100" + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { C1 E8 1F 84 C0 75 7B 85 D2 89 D5 7E 75 8B 47 0C 39 C6 7D 6E 44 8D } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Winnti_6F4Ca425 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Winnti (Linux.Trojan.Winnti)" + author = "Elastic Security" + id = "6f4ca425-5cd2-4c22-b017-b5fc02b3abc2" + date = "2022-01-05" + modified = "2022-01-26" + reference = "161af780209aa24845863f7a8120aa982aa811f16ec04bcd797ed165955a09c1" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Winnti.yar#L41-L59" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "a1ffc0e3d27c4bb9fd10f14d45b649b4f059c654b31449013ac06d0981ed25ed" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "dec25af33fc004de3a1f53e0c3006ff052f7c51c95f90be323b281590da7d924" + severity = "100" + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 89 E5 48 89 7D D8 48 8B 45 D8 0F B6 40 27 0F BE C0 89 45 F8 48 8B } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Winnti_De4B0F6E : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Winnti (Linux.Trojan.Winnti)" + author = "Elastic Security" + id = "de4b0f6e-0183-4ea8-9c03-f716a25f1884" + date = "2022-01-05" + modified = "2022-01-26" + reference = "a6b9b3ea19eaddd4d90e58c372c10bbe37dbfced638d167182be2c940e615710" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Winnti.yar#L61-L79" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "fb7b0ff4757dfc1ba2ca8585d5ddf14aae03063e10bdc2565443362c6ba37c30" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "c72eddc2d72ea979ad4f680d060aac129f1cd61dbdf3b0b5a74f5d35a9fe69d7" + severity = "100" + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 85 30 FF FF FF 02 00 48 8D 85 30 FF FF FF 48 8D 50 02 0F B7 85 28 FF } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_268Aac0B : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "268aac0b-c5c7-4035-8381-4e182de91e32" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "49c94d184d7e387c3efe34ae6f021e011c3046ae631c9733ab0a230d5fe28ead" + logic_hash = "6eae3aba35d3379fa194b66a1b4e0d78d0d0b88386cd4ea5dfeb3c072642c7ba" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "9c581721bf82af7dc6482a2c41af5fb3404e01c82545c7b2b29230f707014781" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 24 18 0F B7 44 24 20 8B 54 24 1C 83 F9 01 8B 7E 0C 89 04 24 8B } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_D5F2Abe2 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "d5f2abe2-511f-474d-9292-39060bbf6feb" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c490586fbf90d360cf3b2f9e2dc943809441df3dfd64dadad27fc9f5ee96ec74" + logic_hash = "169e7e5d1a7ea8c219464e22df9be8bc8caa2e78e1bc725674c8e0b14f6b9fc5" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "475a1c92c0a938196a5a4bca708b338a62119a2adf36cabf7bc99893fee49f2a" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 41 56 41 89 FE 40 0F B6 FF 41 55 49 89 F5 BE 08 00 00 00 41 54 41 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_1Cb033F3 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "1cb033f3-68c1-4fe5-9cd1-b5d066c1d86e" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L41-L58" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "ebaf45ce58124aa91b07ebb48779e6da73baa0b80b13e663c13d8fb2bb47ad0d" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "49201ab37ff0b5cdfa9b0b34b6faa170bd25f04df51c24b0b558b7534fecc358" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { C3 EB 06 8A 46 FF 88 47 FF FF CA 48 FF C7 48 FF C6 83 FA FF } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_Fa3Ad9D0 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "fa3ad9d0-7c55-4621-90fc-6b154c44a67b" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L60-L78" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6" + logic_hash = "5890c85872ea4508e673235b20b481972f613f6e5f9564c0237c458995532347" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_0Cb1699C : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "0cb1699c-9a08-4885-aa7f-0f1ee2543cac" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L80-L98" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb" + logic_hash = "97307f583240290de2bfc663b99f8dcdedace92885bd3e0c0340709b94c0bc2a" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "6e44c68bba8c9fb53ac85080b9ad765579f027cabfea5055a0bb3a85b8671089" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 10 0F B7 02 83 E9 02 83 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_6F021787 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "6f021787-9c2d-4536-bd90-5230c85a8718" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L100-L118" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "88183d71359c16d91a3252085ad5a270ad3e196fe431e3019b0810ecfd85ae10" + logic_hash = "7e8062682a0babbaa3c00975807ba9fc34c465afde55e4144944e7598f0ea1fd" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "33ba39b77e55b1a2624e7846e06b2a820de9a8a581a7eec57e35b3a1636b8b0d" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 55 D4 66 89 14 01 0F B6 45 D0 48 63 D0 48 89 D0 48 01 C0 48 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_1E0C5Ce0 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "1e0c5ce0-3b76-4da4-8bed-2e5036b6ce79" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L120-L138" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "5b1f95840caebf9721bf318126be27085ec08cf7881ec64a884211a934351c2d" + logic_hash = "591cc3ef6932bf990f56c932866b34778e8eccd0e343f9bd6126eb8205a12ecc" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "8e45538b59f9c9b8bc49661069044900c8199e487714c715c1b1f970fd528e3b" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 4C 24 54 31 F6 41 B8 04 00 00 00 BA 03 00 00 00 C7 44 24 54 01 00 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_22965A6D : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "22965a6d-85d3-4f7c-be4a-581044581b77" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L140-L158" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "09c821aa8977f67878f8769f717c792d69436a951bb5ac06ce5052f46da80a48" + logic_hash = "6b2a46694edf709d28267268252cfe95d88049b7dca854059cfe44479ada7423" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "a34bcba23cde4a2a49ef8192fa2283ce03c75b2d1d08f1fea477932d4b9f5135" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { E6 4A 64 2B E4 82 D1 E3 F6 5E 88 34 DA 36 30 CE 4E 83 EC F1 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_4032Ade1 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "4032ade1-4864-4637-ae73-867cd5fb7378" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L160-L178" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "6150fbbefb916583a0e888dee8ed3df8ec197ba7c04f89fb24f31de50226e688" + logic_hash = "9c5e24c4efd4035408897f638d3579c3798139fd18178cee4a944b49c13e1532" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "2b150a6571f5a2475d0b4a2ddb75623d6fa1c861f5385a5c42af24db77573480" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { F8 0C 67 56 55 4C 06 87 DE B2 C0 79 AE 88 73 79 0C 7E F8 87 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_B14F4C5D : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "b14f4c5d-054f-46e6-9fa8-3588f1ef68b7" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L180-L197" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "1a2114a7b397c850d732940a0e154bc04fbee1fdc12d343947b343b9b27a8af1" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_C8385B81 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "c8385b81-0f5b-41c3-94bb-265ede946a84" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L199-L217" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "3d27736caccdd3199a14ce29d91b1812d1d597a4fa8472698e6df6ef716f5ce9" + logic_hash = "4ff1f0912fb92e7ac5af49e1738dac897ff1f0a118d8ff905da45b0a91b3f4a7" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "dfdbd4dbfe16bcf779adb16352d5e57e3950e449e96c10bf33a91efee7c085e5" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 8D 74 26 00 89 C2 83 ED 04 C1 E2 0B 31 C2 89 F0 C1 E8 13 89 D1 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_122Ff2E6 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L219-L237" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4" + logic_hash = "62884309b9095cdd6219c9ef6cd77a0f712640d8a1db4afe5b1d01f4bbe5acc2" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 24 EB 15 89 F0 83 C8 01 EB 03 8B 5B 08 3B 43 04 72 F8 8B 4B 0C 89 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_26Cba88C : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "26cba88c-7bd4-4fac-b395-04c4745fee43" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L239-L257" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "4b4758bff3dcaa5640e340d27abba5c2e2b02c3c4a582374e183986375e49be8" + logic_hash = "bb5a0f9e68655556ab9fccc27d11bf7828c299720bb67948455579d6a7eb2a9f" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "358dd5d916fec3e1407c490ce0289886985be8fabee49581afbc01dcf941733e" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { F6 41 00 42 00 43 00 44 00 45 00 46 00 47 00 48 00 49 00 4A 00 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_93Fc3657 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "93fc3657-fd21-4e93-a728-c084fc0a6a4a" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L259-L277" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6" + logic_hash = "0b5278feddd00b0b24ca735bf7cd1440379c6ce5aca6d2a6f38c9fdcedcb3c0d" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 00 00 00 89 44 24 60 89 D1 31 C0 8B 7C 24 28 FC F3 AB 89 D1 8B 7C } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_7C88Acbc : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "7c88acbc-8b98-4508-ac53-ab8af858660d" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L279-L296" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "76373f8e09b7467ac5d36e8baad3025a57568e891434297e53f2629a72cf8929" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "e2ef1c60e21f18e54694bcfc874094a941e5f61fa6144c5a0e44548dafa315be" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = "[Cobalt][%s][%s][%s][%s]" + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_804F8E7C : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "804f8e7c-4786-42bc-92e4-c68c24ca530e" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L298-L316" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6" + logic_hash = "711d74406d9b0d658b3b29f647bd659699ac0af9cd482403122124ec6054f1ec" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 31 ED 81 E1 FF 00 00 00 89 4C 24 58 89 EA C6 46 04 00 C1 FA 1F } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_A2D2E15A : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "a2d2e15a-a2eb-43c6-a43d-094ee9739749" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L318-L336" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "567c3ce9bbbda760be81c286bfb2252418f551a64ba1189f6c0ec8ec059cee49" + logic_hash = "c76fe953c4a70110346a020f2b27c7e79f4ad8a24fd92ac26e5ddd1fed068f65" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "0e57d17f5c0cd876248a32d4c9cbe69b5103899af36e72e4ec3119fa48e68de2" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 42 F0 41 83 F8 01 76 5F 44 0F B7 41 10 4C 01 C0 44 8D 42 EE 41 83 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_5946F41B : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "5946f41b-594c-4fde-827c-616a99f6fc1b" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L338-L356" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "f0b6bf8a683f8692973ea8291129c9764269a6739650ec3f9ee50d222df0a38a" + logic_hash = "43691675db419426413ccc24aa9dfe94456fa1007630652b08a625eafd1f17b8" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "f28b9b311296fc587eced94ca0d80fc60ee22344e5c38520ab161d9f1273e328" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 59 08 AA 3A 4C D3 6C 2E 6E F7 24 54 32 7C 61 39 65 21 66 74 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_Da4Aa3B3 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "da4aa3b3-521d-4fde-b1be-c381d28c701c" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L358-L376" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "dbc246032d432318f23a4c1e5b6fcd787df29da3bf418613f588f758dcd80617" + logic_hash = "84ddc505d2e2be955b88a0fe3b78d435f73c0a315b513e105933e84be78ba2ad" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "8b004abc37f47de6e4ed35284c23db0f6617eec037a71ce92c10aa8efc3bdca5" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 01 D0 C1 E0 03 89 C2 8B 45 A0 01 D0 0F B6 40 14 3C 1F 77 65 8B } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_70Ef58F1 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "70ef58f1-ac74-4e33-ae03-e68d1d5a4379" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L378-L396" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb" + logic_hash = "3ad201d643e8f93a6f9075c03a76020d78186702a19bf9174b08688a2e94ef5c" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "c46eac9185e5f396456004d1e0c42b54a9318e0450f797c55703122cfb8fea89" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 89 D0 8B 19 01 D8 0F B6 5C 24 10 30 18 89 D0 8B 19 01 D8 0F B6 5C } condition: - uint16(0)==0x5A4D and ($decrypt_DesucryptKeyContainer_DogeCrypt) and ($find_files_DogeCrypt) and ( all of ($encrypt_files_DogeCrypt_p*)) + all of them } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Timetime : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Ea584243 : FILE MEMORY { meta: - description = "Yara rule that detects TimeTime ransomware." - author = "ReversingLabs" - id = "27bff941-01ce-5bf7-a9d8-d01d2db3bfd3" - date = "2022-02-21" - modified = "2022-02-21" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.TimeTime.yara#L1-L75" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "43867dd793bc84e6f39ca2de1aff4047a742b295dc4df94cd337bd2ef89e4a62" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "ea584243-6ead-4b96-9a5c-5b5dee12fd57" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L398-L416" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "f363d9bd2132d969cd41e79f29c53ef403da64ca8afc4643084cc50076ddfb47" + logic_hash = "34c6f800c849c295797cdd971fb4f3d16d680530f9a98c291388345569708208" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "TimeTime" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "cbcabf4cba48152b3599570ef84503bfb8486db022a2b10df7544d4384023355" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $rename_files = { - 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 2B ?? 12 ?? 28 ?? ?? ?? ?? 0B 00 07 28 ?? ?? ?? - ?? 16 FE 01 0C 08 2C ?? 2B ?? 00 00 07 07 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 00 00 DE ?? 26 00 00 DE ?? 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 00 DC 2A - } - $find_files = { - 00 73 ?? ?? ?? ?? 0A 00 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 07 2C ?? 06 0C DD ?? ?? ?? - ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0D 09 2C ?? 06 0C DD ?? ?? ?? ?? 02 72 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 06 0C DD ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 13 ?? 11 ?? 2C ?? 06 0C DD ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C - ?? 06 0C DD ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 06 0C DD ?? - ?? ?? ?? 02 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 06 0C DD ?? ?? ?? ?? 02 72 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 06 0C DD ?? ?? ?? ?? 02 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 06 0C DE ?? 00 02 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 - ?? 11 ?? 9A 13 ?? 00 06 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 - 32 ?? 00 02 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 13 ?? 00 06 11 ?? 28 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 ?? 00 DE ?? 13 ?? - 00 00 DE ?? 06 0C 2B ?? 08 2A - } - $encrypt_folder = { - 00 02 28 ?? ?? ?? ?? 0A 00 06 6F ?? ?? ?? ?? 0B 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 0C - 00 00 08 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 FE 01 0D 09 2C ?? 00 16 13 ?? 16 13 ?? 08 73 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 8C ?? ?? ?? ?? 17 8C ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 08 19 - 73 ?? ?? ?? ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 00 DE ?? - 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? 00 DC 11 ?? 16 FE 01 11 ?? 5F 11 ?? 5F 13 ?? 11 ?? 2C - ?? 00 08 28 ?? ?? ?? ?? 00 00 00 00 DE ?? 26 00 00 DE ?? 00 12 ?? 28 ?? ?? ?? ?? 3A ?? - ?? ?? ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 2A - } - $encrypt_files = { - 00 02 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 08 2C ?? 38 ?? ?? ?? ?? 02 7E ?? ?? ?? ?? 6F ?? - ?? ?? ?? 0D 09 2C ?? 2B ?? 02 28 ?? ?? ?? ?? 0A 06 8E 69 8D ?? ?? ?? ?? 0B 16 13 ?? 2B - ?? 00 06 11 ?? 91 13 ?? 11 ?? 17 58 D1 13 ?? 11 ?? D2 13 ?? 07 11 ?? 11 ?? 9C 00 11 ?? - 17 58 13 ?? 11 ?? 07 8E 69 FE 04 13 ?? 11 ?? 2D ?? 02 07 28 ?? ?? ?? ?? 00 02 02 7E ?? - ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 02 28 ?? ?? ?? ?? 00 02 28 ?? ?? ?? ?? 00 7E - ?? ?? ?? ?? 02 6F ?? ?? ?? ?? 00 2A - } + $a = { 01 00 00 0E 00 00 00 18 03 00 7F E9 38 32 C9 4D 04 9A 3C 81 FA } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($encrypt_folder) and ($rename_files) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Bluelocker : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_564B8Eda : FILE MEMORY { meta: - description = "Yara rule that detects BlueLocker ransomware." - author = "ReversingLabs" - id = "145ff05e-c90d-598a-a3d5-220bd6df718a" - date = "2022-08-04" - modified = "2022-08-04" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.BlueLocker.yara#L1-L130" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "fbe5f246f4554e63b5da6a0aca169e8221a84fce18fd437ae7ad9b068e9ca576" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "564b8eda-6f0e-45b8-bef6-d61b0f090a36" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L418-L436" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee" + logic_hash = "4bf11492f480911629623250146554f2456f3a527f5f80402ef74b22c1460462" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "BlueLocker" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 8B 75 ?? 57 - 8B 7D ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 56 89 55 ?? 89 75 ?? - 89 45 ?? 89 7D ?? FF 15 ?? ?? ?? ?? 8B D8 C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 53 FF 15 - ?? ?? ?? ?? 8B 55 ?? 33 C9 0B C8 89 55 ?? 89 4D ?? 83 FB ?? 75 ?? 0B C3 5F 5E 5B 8B - 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 6A ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B - F0 FF 15 ?? ?? ?? ?? 33 C9 03 F0 83 C6 ?? 0F 92 C1 F7 D9 0B CE 51 E8 ?? ?? ?? ?? 8B - F0 83 C4 ?? 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 50 FF 75 ?? - 56 E8 ?? ?? ?? ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 E8 - ?? ?? ?? ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 85 C9 0F 8C ?? ?? - ?? ?? 8B 45 ?? 0F 8F ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 85 C9 0F 8F ?? ?? - ?? ?? 7C ?? 3D ?? ?? ?? ?? 0F 83 ?? ?? ?? ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 8B 55 ?? 8D - 4D ?? D1 E8 89 45 ?? E8 ?? ?? ?? ?? 0F B6 4F ?? 0F 57 C0 0F B6 47 ?? C1 E1 ?? 0B C8 - } - $encrypt_files_p2 = { - 66 0F 13 45 ?? 0F B6 47 ?? C1 E1 ?? 0B C8 C7 45 ?? ?? ?? ?? ?? 0F B6 07 C1 E1 ?? 0B - C8 C7 45 ?? ?? ?? ?? ?? 0F B6 47 ?? 89 4D ?? 0F B6 4F ?? C1 E1 ?? 0B C8 0F B6 47 ?? - 6A ?? 6A ?? FF 75 ?? C1 E1 ?? FF 75 ?? 0B C8 0F B6 47 ?? 8B 3D ?? ?? ?? ?? C1 E1 ?? - 0B C8 53 89 4D ?? FF D7 33 F6 8D 45 ?? 56 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 0F 1F 40 ?? FF 75 ?? BA ?? ?? ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 33 C0 F7 D9 13 C0 6A ?? 6A ?? F7 D8 50 51 53 FF D7 6A - ?? 8D 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 8B 45 ?? 03 F0 3B 75 ?? 0F 87 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 6A ?? 8D - 45 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? E9 ?? ?? ?? - ?? 85 C9 7F ?? 7C ?? 3D ?? ?? ?? ?? 73 ?? 8B 75 ?? 8B CB 57 8B D6 E8 ?? ?? ?? ?? 8B - 3D ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B 75 ?? 8B CB 57 8B D6 E8 ?? ?? ?? ?? 8B 3D - ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 0F B6 4F ?? 0F - } - $encrypt_files_p3 = { - 57 C0 0F B6 47 ?? C1 E1 ?? 0B C8 66 0F 13 45 ?? 0F B6 47 ?? C1 E1 ?? 0B C8 C7 45 ?? - ?? ?? ?? ?? 0F B6 07 C1 E1 ?? 0B C8 C7 45 ?? ?? ?? ?? ?? 0F B6 47 ?? 89 4D ?? 0F B6 - 4F ?? C1 E1 ?? 0B C8 0F B6 47 ?? 6A ?? 6A ?? FF 75 ?? C1 E1 ?? FF 75 ?? 0B C8 0F B6 - 47 ?? 8B 3D ?? ?? ?? ?? C1 E1 ?? 0B C8 53 89 4D ?? FF D7 8B 35 ?? ?? ?? ?? 8D 45 ?? - 6A ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF D6 85 C0 74 ?? FF 75 ?? BA ?? ?? ?? ?? - 8D 4D ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 33 C0 F7 D9 13 C0 6A ?? 6A ?? F7 D8 50 51 - 53 FF D7 6A ?? 8D 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? - 81 7D ?? ?? ?? ?? ?? 72 ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF D6 - 85 C0 75 ?? 8B 75 ?? 6A ?? 0F 57 C0 6A ?? 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 53 FF D7 - 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 C7 45 ?? ?? ?? ?? ?? 83 C4 ?? 89 55 ?? C7 - 45 ?? ?? ?? ?? ?? 85 D2 74 ?? 8B FA B9 ?? ?? ?? ?? F3 A5 8B 4D ?? 68 ?? ?? ?? ?? 8B - 01 8B 49 ?? 89 82 ?? ?? ?? ?? 8D 45 ?? 50 52 6A ?? 6A ?? 6A ?? FF 75 ?? 89 8A ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 8B 75 ?? 85 C0 74 ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 56 53 FF 15 - ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 EB ?? 83 CE ?? 85 DB 74 ?? 53 FF 15 ?? - ?? ?? ?? 8B 7D ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? EB ?? 8B 7D ?? 57 E8 ?? ?? ?? ?? 8B - 4D ?? 83 C4 ?? 8B C6 33 CD 5F 5E 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $find_files_p1 = { - FF 74 B4 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 46 83 - FE ?? 7C ?? FF 74 24 ?? FF D7 68 ?? ?? ?? ?? 8B F0 FF D7 03 F0 8D 84 24 ?? ?? ?? ?? - 6A ?? 50 FF D7 8D 0C 06 33 C0 83 C1 ?? 0F 92 C0 F7 D8 0B C1 50 E8 ?? ?? ?? ?? 8B F0 - 83 C4 ?? 85 F6 0F 84 ?? ?? ?? ?? FF 74 24 ?? FF D7 48 50 FF 74 24 ?? 56 E8 ?? ?? ?? - ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 56 E8 ?? ?? - ?? ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? - 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 8B 7C 24 ?? 83 C4 ?? 83 C7 ?? 57 FF 15 ?? ?? ?? - ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B C8 83 C4 ?? 85 C9 74 ?? 8B 54 24 ?? C7 01 ?? ?? ?? - ?? C7 41 ?? ?? ?? ?? ?? 83 7A ?? ?? 75 ?? 89 4A ?? 89 4A ?? 57 89 31 FF 15 ?? ?? ?? - ?? E9 ?? ?? ?? ?? 8B 42 ?? 89 48 ?? 8B 42 ?? 8B 40 ?? 89 42 ?? 89 30 57 FF 15 ?? ?? - ?? ?? E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 33 F6 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 74 B4 ?? 8D 84 24 - } - $find_files_p2 = { - 50 FF D3 85 C0 0F 85 ?? ?? ?? ?? 46 83 FE ?? 7C ?? 6A ?? FF 74 24 ?? FF D7 8B F0 8D - 84 24 ?? ?? ?? ?? 50 FF D7 03 F0 33 C0 83 C6 ?? 0F 92 C0 F7 D8 0B C6 50 E8 ?? ?? ?? - ?? 8B F0 83 C4 ?? 85 F6 0F 84 ?? ?? ?? ?? FF 74 24 ?? FF D7 48 50 FF 74 24 ?? 56 E8 - ?? ?? ?? ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 84 24 ?? ?? ?? ?? 50 56 - E8 ?? ?? ?? ?? 83 C4 ?? D1 E8 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 75 ?? 56 E8 ?? ?? ?? ?? EB ?? 6A ?? 6A ?? E8 ?? ?? - ?? ?? 8B D8 83 C4 ?? 85 DB 75 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 57 EB ?? 57 68 ?? ?? ?? - ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 53 6A ?? FF 74 24 ?? FF 15 ?? ?? ?? ?? - 85 C0 74 ?? 8B 54 24 ?? 53 57 56 E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? - 57 E8 ?? ?? ?? ?? 83 C4 ?? 53 E8 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 83 C4 ?? 8B 35 ?? ?? - ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 74 24 ?? FF 15 - } - $create_crypt_context = { - 55 8B EC 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? - ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 83 C8 ?? 8B 4D ?? 33 CD E8 ?? ?? ?? - ?? 8B E5 5D C2 ?? ?? 56 8B 35 ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? - ?? 6A ?? 50 FF D6 85 C0 75 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 8D 45 ?? 50 FF - D6 85 C0 75 ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 8D 45 ?? 50 FF D6 85 C0 75 ?? - 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 50 8D 45 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 6A - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 74 ?? 68 ?? ?? ?? ?? 56 6A ?? - FF 15 ?? ?? ?? ?? 8D 45 ?? 89 35 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D - 04 45 ?? ?? ?? ?? 50 FF 35 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? - ?? ?? ?? 85 C0 75 ?? 50 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 8B 45 ?? 5E 85 C0 74 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? - 33 C0 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 - } + $a = { 83 FE 01 76 12 0F B7 07 83 EE 02 48 83 C7 02 48 01 C1 83 FE 01 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($create_crypt_context) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Xorist : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_7E9F85Fb : FILE MEMORY { meta: - description = "Yara rule that detects Xorist ransomware." - author = "ReversingLabs" - id = "804ae039-fc3b-5f19-860e-df9efe87ee4d" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Xorist.yara#L1-L150" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "c428838cdd103f62508a23c9333b08567625291e110aa437324ecf37c62dca36" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "7e9f85fb-bfc4-4af6-9315-f6e43fefc4ff" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L438-L456" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "4333e80fd311b28c948bab7fb3f5efb40adda766f1ea4bed96a8db5fe0d80ea1" + logic_hash = "f4ce912e190bc5dcb56541f54ba8e47b6103c482bdc7e83b44693d2c066c0170" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Xorist" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "ef420ec934e3fd07d5c154a727ed5c4689648eb9ccef494056fed1dea7aa5f9c" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $search_and_encrypt_v1_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 0F - 84 ?? ?? ?? ?? 48 89 45 ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 2D ?? ?? ?? ?? 50 C6 80 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 80 ?? ?? ?? ?? ?? ?? ?? ?? C6 80 ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? 58 C7 80 ?? ?? ?? ?? ?? ?? ?? ?? C6 80 ?? ?? ?? ?? ?? E9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 2D ?? ?? ?? ?? C6 80 ?? ?? ?? ?? ?? A0 ?? ?? ?? ?? 3C ?? 75 ?? - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 - } - $search_and_encrypt_v1_p2 = { - 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? - E9 ?? ?? ?? ?? EB ?? 8B 3D ?? ?? ?? ?? 8B 0F 83 C7 ?? 51 57 68 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B D8 57 E8 ?? ?? ?? ?? 03 F8 47 59 83 FB ?? 74 ?? 49 75 ?? E9 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? - ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 00 ?? EB ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 85 C0 0F 84 ?? ?? ?? ?? 48 A3 ?? ?? ?? ?? 6A ?? FF - } - $search_and_encrypt_v1_p3 = { - 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? ?? 83 F8 ?? 7D ?? FF 35 ?? ?? ?? ?? E8 ?? - ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A - ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 3D ?? ?? ?? ?? ?? 75 ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8A 10 B9 - ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? AC 32 C2 D0 C2 AA E2 ?? A1 ?? ?? ?? ?? 80 - 3D ?? ?? ?? ?? ?? 75 ?? E8 ?? ?? ?? ?? EB ?? 80 3D ?? ?? ?? ?? ?? 75 ?? E8 ?? ?? ?? - ?? EB ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? - ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? - ?? ?? C9 C3 - } - $extract_rsrc_v1 = { - 55 8B EC 83 C4 ?? B9 ?? ?? ?? ?? BF ?? ?? ?? ?? 51 57 0F 31 5F 59 25 ?? ?? ?? ?? C1 - E8 ?? 83 C0 ?? AA E2 ?? 33 C0 AA 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 0B C0 75 ?? C9 C3 89 45 ?? 50 6A ?? E8 ?? - ?? ?? ?? 0B C0 75 ?? C9 C3 89 45 ?? FF 75 ?? 6A ?? E8 ?? ?? ?? ?? 0B C0 75 ?? C9 C3 - 89 45 ?? 50 E8 ?? ?? ?? ?? 0B C0 75 ?? C9 C3 89 45 ?? 8B D8 6A ?? 6A ?? 6A ?? 6A ?? - 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? 89 45 ?? 6A ?? 6A - ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 53 FF 75 ?? E8 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? FF 75 ?? E8 - ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? - C9 C3 - } - $search_and_encrypt_v2_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 0F - 84 ?? ?? ?? ?? 48 89 45 ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 2D ?? ?? ?? ?? 50 C6 80 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 80 ?? ?? ?? ?? ?? ?? ?? ?? C6 80 ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? 58 C7 80 ?? ?? ?? ?? ?? ?? ?? ?? C6 80 ?? ?? ?? ?? ?? E9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 2D ?? ?? ?? ?? C6 80 ?? ?? ?? ?? ?? A0 ?? ?? ?? ?? 3C - ?? 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 53 68 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 - ?? 74 ?? E9 ?? ?? ?? ?? EB ?? 8B 3D ?? ?? ?? ?? 8B 0F 83 C7 ?? 51 57 68 - } - $search_and_encrypt_v2_p2 = { - E8 ?? ?? ?? ?? 8B D8 57 E8 ?? ?? ?? ?? 03 F8 47 59 83 FB ?? 74 ?? 49 75 ?? E9 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 80 3D ?? ?? ?? ?? ?? 75 ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 00 ?? 6A - ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 40 85 C0 0F - 84 ?? ?? ?? ?? 48 A3 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? A3 ?? ?? ?? - ?? 83 F8 ?? 7D ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? - ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? EB ?? 68 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8A 10 B9 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? AC 32 C2 - D0 C2 AA E2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 35 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF - 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? - ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? FF 75 ?? E8 ?? ?? ?? ?? C9 C3 - } - $extract_rsrc_v2 = { - 55 8B EC 83 C4 ?? 53 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? 89 - 45 ?? 50 6A ?? E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? 89 45 ?? FF 75 ?? 6A ?? E8 - ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? 89 45 ?? 50 E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? - ?? ?? ?? 89 45 ?? 8B F8 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 ?? 8B 45 ?? 83 - E8 ?? 50 57 E8 ?? ?? ?? ?? 8B 1F 83 C7 ?? 53 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 0B C0 75 ?? E9 ?? ?? ?? ?? A3 ?? ?? ?? ?? 53 57 FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 03 - FB 8B 1F 83 C7 ?? 53 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? - ?? A3 ?? ?? ?? ?? 53 57 FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 03 FB 8B 1F 83 C7 ?? 53 6A - ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? A3 ?? ?? ?? ?? 53 57 - FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 03 FB 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 - ?? 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 ?? 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C7 ?? 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 ?? 6A ?? 57 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C7 ?? 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 ?? 6A ?? 57 - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 ?? 6A ?? 57 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C7 - ?? FF 75 ?? E8 ?? ?? ?? ?? 5B C9 C3 - } + $a = { 85 50 FF FF FF 0F B6 40 04 3C 07 75 79 48 8B 85 50 FF FF FF } condition: - uint16(0)==0x5A4D and (($extract_rsrc_v1) and ( all of ($search_and_encrypt_v1_p*))) or (($extract_rsrc_v2) and ( all of ($search_and_encrypt_v2_p*))) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Badblock : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_3A85A418 : FILE MEMORY { meta: - description = "Yara rule that detects BadBlock ransomware." - author = "ReversingLabs" - id = "a5afb7d6-4bc1-5465-a35d-fe40e7f11c3e" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.BadBlock.yara#L1-L100" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "421e6a3772eeec6ef0cbb2427b7e044b450a2b2146cee2ca7d8c3a3a92918557" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "3a85a418-2bd9-445a-86cb-657ca7edf566" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L458-L476" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "86a43b39b157f47ab12e9dc1013b4eec0e1792092d4cef2772a21a9bf4fc518a" + logic_hash = "bd7fe497fb2557c9e9c26ec90e783f03cbbc9bdaa8d20b364ce65edf6c1e5fa3" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "BadBlock" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "554aff5770bfe8fdeae94f5f5a0fd7f7786340a95633433d8e686af1c25b8cec" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files = { - 55 8B EC 83 C4 ?? 53 56 57 33 DB 89 5D ?? 89 5D ?? 89 5D ?? 89 4D ?? 89 55 ?? 8B D8 - 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? 8B 45 ?? - 8B 40 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C3 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 55 - ?? 8B 45 ?? 8B 40 ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 - ?? B2 ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D - 45 ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? - ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B D0 8B 45 ?? 85 C0 74 ?? 83 E8 ?? 8B 00 6A ?? 50 52 - 8B 45 ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 8B 45 ?? 50 - E8 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 - 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 10 FF 12 89 45 ?? 89 55 ?? E9 ?? ?? - ?? ?? 83 7D ?? ?? 75 ?? 81 7D ?? ?? ?? ?? ?? 73 ?? EB ?? 7D ?? 8B 45 ?? 89 45 ?? 8B - 45 ?? 89 45 ?? EB ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 8B D8 8B C3 - E8 ?? ?? ?? ?? 8B F0 8B D6 8B CB 8B 45 ?? 8B 38 FF 57 ?? 89 45 ?? 8B 45 ?? 8B 10 FF - 12 52 50 8B 45 ?? E8 ?? ?? ?? ?? 3B 54 24 ?? 75 ?? 3B 04 24 5A 58 72 ?? EB ?? 5A 58 - 7C ?? 8B 45 ?? 50 8D 45 ?? 50 56 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? EB ?? - 8B 45 ?? 50 8D 45 ?? 50 56 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? E8 - ?? ?? ?? ?? 52 50 8B C3 99 29 04 24 19 54 24 ?? 58 5A 52 50 8B 45 ?? E8 ?? ?? ?? ?? - 8B D6 8B 4D ?? 8B 45 ?? 8B 38 FF 57 ?? 8B C3 99 29 45 ?? 19 55 ?? 8B D3 8B C6 E8 ?? - ?? ?? ?? 83 7D ?? ?? 75 ?? 83 7D ?? ?? 0F 87 ?? ?? ?? ?? EB ?? 0F 8F ?? ?? ?? ?? A1 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B - 48 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? A1 ?? ?? ?? ?? 8B 00 8B 80 ?? - ?? ?? ?? 8B 80 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 18 FF 53 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 - C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB - ?? E8 ?? ?? ?? ?? EB ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? - ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? - EB ?? 5F 5E 5B 8B E5 5D C3 - } - $search_files = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D - ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 55 ?? 89 85 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 - 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B - 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 85 C0 0F 94 C3 E9 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 66 83 38 ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? A1 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? A1 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 85 C0 75 ?? B9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 85 C0 75 ?? 8B 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8D 85 ?? - ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 0D ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? 66 - 83 38 ?? 74 ?? B9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 - 75 ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? - 8B C6 8B 08 FF 51 ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 94 C3 84 DB 0F 85 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C6 8B 10 FF 52 ?? 8B D8 4B 85 DB 7C ?? - 43 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C6 8B 38 FF - 57 ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? E8 ?? ?? ?? ?? FF 85 ?? ?? ?? ?? 4B 75 ?? 8B C6 E8 ?? ?? ?? ?? 33 C0 5A 59 59 - 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 - } - $remote_connection = { - A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? - 8D 4D ?? 8B 45 ?? 8B 90 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 4D ?? 8D 45 ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? 8B 08 FF - 51 ?? 8B 45 ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? - 05 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 - 89 20 6A ?? 8D 45 ?? 50 8D 4D ?? 8B 15 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? - 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? - 8B 45 ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 - 74 ?? C7 45 ?? ?? ?? ?? ?? 8B 5D ?? 85 DB 74 ?? 83 EB ?? 8B 1B 68 ?? ?? ?? ?? 8B CB - BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? B9 ?? ?? ?? ?? - 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 8B 90 ?? ?? ?? ?? 8D 45 - ?? 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? B2 ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 8B 45 - ?? 8B 90 ?? ?? ?? ?? 8D 45 ?? 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 8B 75 ?? 85 F6 74 ?? 83 EE ?? 8B 36 68 ?? ?? ?? ?? 8B CE BA ?? ?? ?? ?? 8B 45 ?? - E8 ?? ?? ?? ?? 33 C0 A3 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 - 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C3 - } + $a = { 01 D8 66 C1 C8 08 C1 C8 10 66 C1 C8 08 66 83 7C 24 2C FF 89 } condition: - uint16(0)==0x5A4D and ($search_files and $encrypt_files and $remote_connection) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Wastedlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_24C5B7D6 : FILE MEMORY { meta: - description = "Yara rule that detects WastedLocker ransomware." - author = "ReversingLabs" - id = "68090960-9878-5836-8caa-bf8f408a474e" - date = "2020-12-07" - modified = "2020-12-07" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Wastedlocker.yara#L1-L86" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0899d3cc3bcea8eae60689a54f34e57bdc52088c879c8420b8e6d0b1969cb186" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "24c5b7d6-1aa8-4d8e-9983-c7234f57c3de" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L478-L496" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "7c2f8ba2d6f1e67d1b4a3a737a449429c322d945d49dafb9e8c66608ab2154c4" + logic_hash = "f790f6b8fcf932773054525ed74a3f15998d91a2626ae9c56486de8dabc2035c" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "WastedLocker" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "3411b624f02dd1c7a0e663f1f119c8d5e47a81892bb7c445b7695c605b0b8ee2" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files_p1 = { - 55 8B EC 83 EC ?? 83 65 ?? ?? 57 68 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 8B F8 85 FF 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 45 ?? 53 8B 5D ?? 8D 04 41 89 45 ?? - C7 00 ?? ?? ?? ?? 8B 43 ?? 57 51 89 45 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 89 45 ?? 0F 84 - ?? ?? ?? ?? 56 8D 47 ?? 66 83 38 ?? 75 ?? 0F B7 4F ?? 66 85 C9 0F 84 ?? ?? ?? ?? 66 - 83 F9 ?? 75 ?? 66 83 7F ?? ?? 0F 84 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B F0 - 8D 14 0E B8 ?? ?? ?? ?? 3B D0 89 55 ?? 0F 83 ?? ?? ?? ?? F6 07 ?? 0F 85 ?? ?? ?? ?? - 8B 45 ?? 85 C0 74 ?? 83 7F ?? ?? 75 ?? 39 47 ?? 0F 82 ?? ?? ?? ?? 8D 44 36 ?? 50 8D - 47 ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 85 C9 74 ?? 8B 45 ?? 83 C0 ?? 50 - E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? 85 C9 74 ?? 8B 45 ?? 83 C0 ?? 50 E8 - ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 03 C6 8D 44 00 ?? 83 C0 ?? 50 6A ?? FF - 35 ?? ?? ?? ?? 89 45 ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? FF 75 ?? 6A - ?? 56 E8 ?? ?? ?? ?? 8B 45 ?? 8D 44 00 ?? 50 FF 75 ?? 8D 46 ?? 50 89 76 ?? 89 36 E8 - ?? ?? ?? ?? 8B 45 ?? 89 46 ?? 8B 45 ?? 89 46 ?? 8B 07 89 46 ?? 8B 47 ?? 89 46 ?? 8B - } - $find_files_p2 = { - 47 ?? 89 46 ?? 8B 47 ?? 89 46 ?? 8B 47 ?? 83 C4 ?? 89 46 ?? 83 3B ?? 74 ?? 53 FF 15 - ?? ?? ?? ?? 8D 43 ?? 8B 48 ?? 89 06 89 4E ?? 89 31 89 70 ?? FF 43 ?? 83 7B ?? ?? 74 - ?? 8B 43 ?? 83 F8 ?? 75 ?? FF 73 ?? FF 15 ?? ?? ?? ?? 83 3B ?? 0F 84 ?? ?? ?? ?? 53 - FF 15 ?? ?? ?? ?? EB ?? C7 45 ?? ?? ?? ?? ?? EB ?? F6 45 ?? ?? 74 ?? 8D 4C 0E ?? 3B - C8 73 ?? 8D 04 36 50 8D 47 ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 8B 4D ?? 8B 45 ?? 8D 04 41 - 66 83 60 ?? ?? 83 C4 ?? 83 7D ?? ?? 66 C7 00 ?? ?? 74 ?? 83 C1 ?? 51 8B 4D ?? E8 ?? - ?? ?? ?? 85 C0 75 ?? 8B 4D ?? FF 75 ?? 8B 45 ?? 53 FF 75 ?? 8D 44 06 ?? FF 75 ?? 50 - 51 E8 ?? ?? ?? ?? 89 45 ?? EB ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 ?? F6 45 ?? ?? - 74 ?? 83 65 ?? ?? 83 7D ?? ?? 75 ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 43 - ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5E 57 6A ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 5B EB - ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 5F C9 C2 - } - $encrypt_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 FF 75 ?? 8B 3D ?? ?? ?? ?? FF 75 ?? FF D7 85 C0 - 0F 84 ?? ?? ?? ?? FF 75 ?? 8D 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 89 45 ?? 75 ?? FF 75 ?? - FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 74 ?? F6 C3 ?? 74 ?? 83 E0 ?? 50 FF 75 ?? FF 15 ?? - ?? ?? ?? 85 C0 75 ?? 33 DB 85 DB 89 5D ?? 0F 84 ?? ?? ?? ?? FF 75 ?? 8D 75 ?? E8 ?? - ?? ?? ?? 89 45 ?? EB ?? 83 65 ?? ?? 33 C9 39 4D ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 39 4D ?? 74 ?? 8B 45 ?? 8B 10 8B 40 ?? C1 65 ?? ?? 89 55 ?? 89 45 - ?? EB ?? C7 45 ?? ?? ?? ?? ?? 89 4D ?? 89 4D ?? 8B 45 ?? 89 45 ?? 89 4D ?? 89 4D ?? - 8B 5D ?? 33 F6 8B 45 ?? 85 C0 89 45 ?? 74 ?? 3B D8 73 ?? 89 5D ?? 2B 45 ?? 89 45 ?? - 75 ?? 8B 45 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 8B 7D ?? 8D 45 ?? 50 57 8D 47 ?? 50 FF 75 - ?? 8B 45 ?? 03 C6 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 03 75 ?? 85 C0 89 45 ?? 0F - } - $encrypt_files_p2 = { - 85 ?? ?? ?? ?? 2B 5D ?? 75 ?? EB ?? 8B 7D ?? 8B 45 ?? 0B 45 ?? 0F 84 ?? ?? ?? ?? 33 - C0 3B 45 ?? 77 ?? 72 ?? 3B 5D ?? 73 ?? 8B C3 EB ?? 8B 45 ?? 29 45 ?? 8B 4D ?? 83 5D - ?? ?? 0B 4D ?? 75 ?? 8B 4D ?? 89 4D ?? 03 F0 2B D8 0F 85 ?? ?? ?? ?? 8B 45 ?? 8B 4D - ?? 0F AC C8 ?? C1 E9 ?? 85 C0 74 ?? B9 ?? ?? ?? ?? F7 E1 29 45 ?? 19 55 ?? 01 45 ?? - 11 55 ?? 83 7D ?? ?? 75 ?? 8D 75 ?? E8 ?? ?? ?? ?? 85 C0 89 45 ?? 0F 84 ?? ?? ?? ?? - 8B 7D ?? 8D 47 ?? 50 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 39 75 ?? 74 ?? 83 7D ?? - ?? 74 ?? 8B 4D ?? 8B 45 ?? 8B D1 0B D0 74 ?? 0F AC C1 ?? C1 E8 ?? 83 4F ?? ?? 89 4F - ?? 89 75 ?? 39 75 ?? 74 ?? FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 39 - 75 ?? 74 ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? EB ?? 8B 45 ?? 89 45 ?? 85 DB 0F 85 - ?? ?? ?? ?? E9 ?? ?? ?? ?? 01 75 ?? 83 55 ?? ?? E9 ?? ?? ?? ?? FF 75 ?? FF 75 ?? FF - D7 EB ?? FF 15 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 5F 5E 5B C9 C2 - } + $a = { 54 38 1C 80 FA 3E 74 25 80 FA 3A 74 20 80 FA 24 74 1B 80 FA 23 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Bandarchor : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_99D78950 : FILE MEMORY { meta: - description = "Yara rule that detects BandarChor ransomware." - author = "ReversingLabs" - id = "c645a081-7ff6-58fc-af8e-55f43f56d0ea" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.BandarChor.yara#L1-L97" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "1c0c33ef7de089fc7ed6b364c7693499d1a93f79a48d6f2a5c375e47aea176bc" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "99d78950-ea23-4166-a85a-7a029209f5b1" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L498-L516" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6" + logic_hash = "bfd628a9973f85ed0a8be2723c7ff4bd028af00ea98c9cbcde9df6aabcf394b2" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "BandarChor" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $file_extensions_1 = { - 55 8B EC B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 F9 51 53 89 55 ?? 8B D8 8B 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 4D ?? 8B 95 ?? - ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 83 F8 ?? 0F 85 F9 00 00 00 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B 55 ?? 8B C3 E8 4F FE FF FF E9 ?? ?? ?? ?? 8D 95 - } - $file_extensions_2 = { - ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? - E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? - ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 - ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? - ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? - ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 - } - $file_extensions_3 = { - 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? - ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? - 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B - 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 - } - $file_extensions_4 = { - 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D - 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 - ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F - 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? - E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 - } - $file_extensions_5 = { - ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? - ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 - } - $parse_server_commands = { - 83 F9 ?? 0F 84 E0 00 00 00 50 53 56 57 89 C3 89 D6 89 CF 31 D2 8A 06 8A 56 ?? 3C ?? 74 25 3C ?? 74 3E 3C ?? 74 51 3C ?? - 74 5C 3C ?? 74 76 3C ?? 0F 84 84 00 00 00 3C ?? 0F 84 8B 00 00 00 E9 97 00 00 00 83 F9 ?? 89 D8 7F 0A E8 ?? ?? ?? ?? E9 - 91 00 00 00 89 CA E8 ?? ?? ?? ?? E9 85 00 00 00 83 F9 ?? 89 D8 7F 07 E8 ?? ?? ?? ?? EB 77 89 CA E8 ?? ?? ?? ?? EB 6E 89 - D8 83 C3 ?? E8 ?? ?? ?? ?? 4F 7F F3 EB 5F 55 89 D5 8B 54 2E ?? 89 D8 03 5C 2E ?? 8B 4C 2E ?? 8B 12 E8 62 FF FF FF 4F 7F - E8 5D EB 41 55 89 D5 89 D8 03 5C 2E ?? 89 F2 E8 ?? ?? ?? ?? 4F 7F F0 5D EB 2B 89 D8 83 C3 ?? E8 ?? ?? ?? ?? 4F 7F F3 EB - 1C 89 D8 89 F2 83 C3 ?? E8 ?? ?? ?? ?? 4F 7F F1 EB 0B 5F 5E 5B 58 B0 ?? E9 ?? ?? ?? ?? 5F 5E 5B 58 C3 8B C0 B9 ?? ?? ?? - ?? E9 0A FF FF FF C3 - } + $a = { 10 89 C3 80 BC 04 83 00 00 00 20 0F 94 C0 8D B4 24 83 00 00 00 25 FF 00 } condition: - uint16(0)==0x5A4D and (($file_extensions_1 and $file_extensions_2 and $file_extensions_3 and $file_extensions_4 and $file_extensions_5) and $parse_server_commands) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Jamper : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_3Fe3C668 : FILE MEMORY { meta: - description = "Yara rule that detects Jamper ransomware." - author = "ReversingLabs" - id = "9ba9358e-8f67-5d0e-a9bc-b3b10cd3a8b2" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Jamper.yara#L1-L110" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "826f8fa7cc92b279c609a9ab6a87c32940e37b4c2476854af75bbed29cb3eaf2" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "3fe3c668-89f4-4601-a167-f41bbd984ae5" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L518-L535" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "e75b2dca7de7d9f31a0ae5940dc45d0e6d0f1ca110b5458fc99912400da97bde" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Jamper" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "2a79caea707eb0ecd740106ea4bed2918e7592c1e5ad6050f6f0992cf31ba5ec" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D - ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 4D ?? 89 55 ?? - 89 45 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 DB 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? 8B - 45 ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 - 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? - 8B 45 ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 6A ?? 8B 4D ?? B2 ?? A1 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 10 FF 12 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 83 - BD ?? ?? ?? ?? ?? 75 ?? 83 BD ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? EB ?? 0F 8E ?? ?? ?? - ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 76 ?? EB ?? 7E ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B 85 ?? ?? ?? ?? 89 85 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 - ?? ?? ?? ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 85 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 83 FB ?? 7F ?? B8 - } - $encrypt_files_p2 = { - E8 ?? ?? ?? ?? 8B D0 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 45 ?? E8 - ?? ?? ?? ?? 43 83 FB ?? 75 ?? 8B 85 ?? ?? ?? ?? 8B D0 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 - ?? E8 ?? ?? ?? ?? 8B D0 8B 8D ?? ?? ?? ?? 8B 45 ?? 8B 18 FF 53 ?? 83 BD ?? ?? ?? ?? - ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 45 ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? 8B 18 FF 53 ?? EB ?? 8D 45 ?? - E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 33 D2 8B 45 ?? 8B 08 FF 51 ?? 83 - BD ?? ?? ?? ?? ?? 75 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? 8D 45 ?? E8 ?? ?? ?? ?? - 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? 8B 18 FF 53 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 B9 - ?? ?? ?? ?? 8B 45 ?? 8B 18 FF 53 ?? 55 E8 ?? ?? ?? ?? 59 55 E8 ?? ?? ?? ?? 59 EB ?? - 55 E8 ?? ?? ?? ?? 59 A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 B9 ?? ?? ?? ?? 8B 45 ?? 8B - 18 FF 53 ?? 55 E8 ?? ?? ?? ?? 59 B3 ?? 8D 45 ?? E8 ?? ?? ?? ?? 84 DB 74 ?? 8D 95 ?? - ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 8D ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B - F8 57 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 56 57 E8 ?? ?? ?? ?? 33 C0 5A 59 59 - 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 - } - $find_files = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 89 55 ?? 89 45 ?? 8B 45 ?? 89 45 ?? 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? - ?? 89 C3 85 DB 74 ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 FF D3 85 C0 74 - ?? 8B 45 ?? 50 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 45 - ?? 80 38 ?? 75 ?? 8B 45 ?? 80 78 ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? E8 ?? ?? - ?? ?? 8B F0 80 3E ?? 0F 84 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F0 80 3E ?? 0F 84 - ?? ?? ?? ?? EB ?? 8B 75 ?? 83 C6 ?? 8B DE 2B 5D ?? 8D 43 ?? 50 8B 45 ?? 50 8D 85 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 46 ?? E8 ?? ?? ?? ?? 8B F8 8B C7 2B C6 - 03 C3 40 3D ?? ?? ?? ?? 0F 8F ?? ?? ?? ?? 8B C7 2B C6 40 50 56 8D 85 ?? ?? ?? ?? 03 - C3 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 89 45 - ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? - 8D 53 ?? 03 C2 40 3D ?? ?? ?? ?? 7F ?? C6 84 1D ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 2B C3 - 48 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 03 C3 40 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 40 03 D8 8B F7 80 3E ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 8D 85 - ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 5F 5E 5B 8B E5 5D C3 - } - $enum_resources = { - 55 8B EC 83 C4 ?? 53 56 57 33 D2 89 55 ?? 89 55 ?? 89 55 ?? 33 D2 55 68 ?? ?? ?? ?? - 64 FF 32 64 89 22 33 D2 55 68 ?? ?? ?? ?? 64 FF 32 64 89 22 8D 55 ?? 52 50 6A ?? 6A - ?? 6A ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 ?? 33 C0 5A 59 59 64 89 10 E9 ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 6A ?? E8 ?? ?? ?? ?? 89 - 45 ?? 8D 45 ?? 50 8B 45 ?? 50 8D 45 ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 83 7D - ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 48 85 C0 0F 82 ?? ?? ?? ?? 40 89 45 ?? 8B 45 ?? 8B - 58 ?? 85 DB 0F 84 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? 8B - D3 E8 ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? 0F B6 12 88 50 ?? C6 00 ?? 8D 55 ?? 8D 45 ?? E8 - ?? ?? ?? ?? 8D 45 ?? 8B 55 ?? 0F B6 52 ?? 88 50 ?? C6 00 ?? 8D 55 ?? 8D 45 ?? B1 ?? - E8 ?? ?? ?? ?? 8D 55 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 50 8D 55 ?? B8 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B 55 ?? 58 E8 ?? ?? ?? ?? 75 ?? A1 ?? ?? ?? ?? 8B 40 ?? 8B 55 ?? 8B - 08 FF 51 ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? F7 - 40 ?? ?? ?? ?? ?? 76 ?? 8B 45 ?? E8 ?? ?? ?? ?? 83 45 ?? ?? FF 4D ?? 0F 85 ?? ?? ?? - ?? EB ?? 81 7D ?? ?? ?? ?? ?? 74 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? EB ?? 8B 45 ?? 50 E8 - ?? ?? ?? ?? 81 7D ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 33 C0 - 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? - ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? C3 - } + $a = { 00 84 C0 0F 95 C0 48 FF 45 E8 84 C0 75 E9 8B 45 FC C9 C3 55 48 } condition: - uint16(0)==0x5A4D and ($enum_resources) and ($find_files) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Denizkizi : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Eedfbfc6 : FILE MEMORY { meta: - description = "Yara rule that detects DenizKizi ransomware." - author = "ReversingLabs" - id = "e16a00d6-d5b8-5702-9cd7-d037b0ff46a3" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.DenizKizi.yara#L1-L88" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "fbeb01263d6f68141e094ba8fb1c1a54c601ab24292f5c6b0eb8cb0c49f46afc" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "eedfbfc6-98a4-4817-a0d6-dcb065307f5c" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L537-L555" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b7342f7437a3a16805a7a8d4a667e0e018584f9a99591413650e05d21d3e6da6" + logic_hash = "949b32db1a00570fc84fbbe510f57f6e898d089efd3fedbd7719f8059021b6bc" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "DenizKizi" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "c79058b4a40630cb4142493062318cdfda881259ac95b70d977816f85b82bb36" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files = { - 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? - ?? 64 FF 30 64 89 20 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 7E ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? - 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B - 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 F6 85 ?? ?? ?? - ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 - ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 8B E5 5D C3 - } - $encrypt_files = { - 55 8B EC 83 C4 ?? 53 56 57 33 DB 89 5D ?? 89 4D ?? 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? - ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 - FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 89 45 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? - ?? 64 FF 30 64 89 20 33 C9 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 0D ?? ?? - ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C9 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 - 45 ?? 8B 0D ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? - ?? ?? 8B 45 ?? 8B 10 FF 12 52 50 8B 45 ?? 8B 10 FF 52 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 10 FF 12 50 8B 4D ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? - 8B 45 ?? 8B 10 FF 52 ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 10 FF 12 50 - 8B 4D ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 10 FF 52 ?? 8B 55 ?? 8B 45 ?? - E8 ?? ?? ?? ?? 8D 45 ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 50 8B 45 ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? - ?? 8B 45 ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C3 - } - $delete_shadow_copies = { - 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 - 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B - 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? - ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? - ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B - 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? - ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? - ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B - 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? - ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? - ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B - 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 E8 ?? ?? - ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 8B - E5 5D C3 - } + $a = { 7C 39 57 52 AC 57 A8 CE A8 8C FC 53 A8 A8 0E 33 C2 AA 38 14 FB 29 } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($delete_shadow_copies) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Revil : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_6D96Ae91 : FILE MEMORY { meta: - description = "Yara rule that detects Revil ransomware." - author = "ReversingLabs" - id = "67c2f49e-b9dc-5900-a89d-49ba41088ac3" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Revil.yara#L1-L101" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "24a79477eb797d7a7121d1248ebbece833ccd256de55729ff96084135ce8d426" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "6d96ae91-9d5c-48f1-928b-1562b120a74d" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L557-L575" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "e3a1d92df6fb566e09c389cfb085126d2ea0f51a776ec099afb8913ef5e96f9b" + logic_hash = "43b0ac7090620eb6c892f1105778c395bf18f5ac309ce1b2d9015b5abccbfc2a" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Revil" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "fdbeaae0a96f3950d19aed497fae3e7a5517db141f53a1a6315b38b1d53d678b" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $search_files = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 8B 75 ?? 33 C0 57 8B 7D ?? 8B D8 50 56 89 45 ?? 89 - 5D ?? 89 45 ?? 89 45 ?? FF 57 ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 56 50 E8 ?? - ?? ?? ?? 53 56 FF 77 ?? FF 57 ?? 83 C4 ?? 01 47 ?? 11 57 ?? E9 ?? ?? ?? ?? 8B 45 ?? - 0B 45 ?? 74 ?? FF 33 56 E8 ?? ?? ?? ?? 8B F3 8B 5B ?? 89 5D ?? FF 36 E8 ?? ?? ?? ?? - 56 E8 ?? ?? ?? ?? 8B 45 ?? 83 C4 ?? 8B 4D ?? 83 C0 ?? 89 45 ?? 83 D1 ?? 0B C1 89 4D - ?? 75 ?? 21 45 ?? 8B 75 ?? 33 C0 40 85 C0 0F 84 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? C7 04 - 24 ?? ?? ?? ?? 56 89 45 ?? E8 ?? ?? ?? ?? 59 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? - ?? ?? 89 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 59 59 85 C0 0F 84 ?? ?? ?? ?? F7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 8D 04 46 50 E8 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 59 59 - 74 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 57 ?? 83 C4 ?? 85 - C0 74 ?? 8D 45 ?? 56 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 77 ?? FF 57 ?? 83 - C4 ?? 01 47 ?? 11 57 ?? EB ?? 8B 85 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 50 89 45 ?? 8D 85 - ?? ?? ?? ?? 53 50 56 FF 57 ?? 83 C4 ?? 85 C0 74 ?? FF 75 ?? 8D 85 ?? ?? ?? ?? 53 50 - 56 FF 77 ?? FF 57 ?? 83 C4 ?? 01 47 ?? 11 57 ?? 83 3F ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 - FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 5D - ?? 83 3F ?? 0F 84 ?? ?? ?? ?? EB ?? 8B F3 8B 5B ?? FF 36 E8 ?? ?? ?? ?? 56 E8 ?? ?? - ?? ?? 59 59 85 DB 75 ?? 5F 5E 5B 8B E5 5D C3 - } - $remote_connection = { - 55 8B EC 81 EC ?? ?? ?? ?? 56 57 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? - ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 33 C0 66 89 85 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 56 56 56 56 50 FF 15 ?? ?? ?? ?? 8B F8 33 C0 89 7D ?? 85 FF 0F 84 ?? ?? - ?? ?? 66 89 45 ?? 33 C9 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 56 56 FF 75 ?? 41 89 75 ?? - 89 75 ?? 89 75 ?? 89 75 ?? 89 4D ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 75 ?? 89 - 4D ?? 89 75 ?? 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 57 FF 15 ?? ?? ?? ?? 33 C0 E9 - ?? ?? ?? ?? 8B 4D ?? 33 D2 8B 45 ?? 53 56 66 89 14 41 FF 75 ?? FF 75 ?? 57 FF 15 ?? - ?? ?? ?? 8B D8 89 5D ?? 85 DB 75 ?? 57 EB ?? 8B 45 ?? 66 39 30 75 ?? 6A ?? 59 66 89 - 08 8D 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 - C0 83 7D ?? ?? B9 ?? ?? ?? ?? 66 89 45 ?? 0F 44 C1 0D ?? ?? ?? ?? 50 56 56 56 FF 75 - ?? 8D 45 ?? 50 53 FF 15 ?? ?? ?? ?? 8B D8 85 DB 75 ?? 57 FF 15 ?? ?? ?? ?? FF 75 ?? - FF 15 ?? ?? ?? ?? 33 C0 E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B FE 50 6A ?? 6A ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 66 89 45 ?? 56 FF 75 ?? 8D 85 - ?? ?? ?? ?? FF 75 ?? FF 75 ?? 6A ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? E8 ?? ?? ?? - ?? 3D ?? ?? ?? ?? 75 ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 6A ?? 53 FF 15 ?? ?? - ?? ?? 85 C0 6A ?? 58 0F 45 F8 85 FF 75 ?? 8B 45 ?? 56 53 89 30 FF 15 ?? ?? ?? ?? 8B - 7D ?? 85 C0 74 ?? 56 8D 45 ?? 89 75 ?? 50 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 56 68 ?? - ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 4D ?? F7 D8 1B C0 23 45 ?? 89 01 3D ?? ?? ?? ?? 75 - ?? FF 75 ?? 53 E8 ?? ?? ?? ?? 59 59 8B F0 57 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? - ?? ?? 53 FF 15 ?? ?? ?? ?? 8B C6 5B 5F 5E 8B E5 5D C3 - } - $encrypt_files = { - 55 8B EC 51 83 7D ?? ?? 53 56 57 BB ?? ?? ?? ?? 7F ?? 7C ?? 39 5D ?? 73 ?? 8B 5D ?? - 8B 7D ?? 8D 83 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 59 59 EB ?? E8 ?? ?? ?? ?? 83 F8 ?? - 75 ?? 6A ?? E8 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 85 - F6 74 ?? 89 9E ?? ?? ?? ?? 8B 5D ?? C7 45 ?? ?? ?? ?? ?? EB ?? 33 C0 EB ?? E8 ?? ?? - ?? ?? 8B 55 ?? 8B CA 4A 89 55 ?? 85 C9 74 ?? 83 F8 ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 83 - F8 ?? 74 ?? A8 ?? 74 ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? FF 75 ?? FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 56 E8 ?? - ?? ?? ?? 8B C6 59 5F 5E 5B 8B E5 5D C3 56 57 E8 ?? ?? ?? ?? 59 33 C0 EB - } - $enum_resources = { - 55 8B EC 83 EC ?? 8D 45 ?? 50 FF 75 ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 - ?? 33 C0 E9 ?? ?? ?? ?? 83 4D ?? ?? B8 ?? ?? ?? ?? 57 50 89 45 ?? E8 ?? ?? ?? ?? 8B - F8 59 85 FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 33 C0 EB ?? 53 56 8D 45 ?? 50 57 8D 45 - ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 75 ?? 33 DB 39 5D ?? 76 ?? 8D 77 ?? - 83 7E ?? ?? 75 ?? FF 75 ?? FF 36 E8 ?? ?? ?? ?? 59 59 F6 46 ?? ?? 74 ?? 8D 46 ?? 50 - FF 75 ?? E8 ?? ?? ?? ?? 59 59 43 83 C6 ?? 3B 5D ?? 72 ?? 8B 45 ?? 3D ?? ?? ?? ?? 75 - ?? 57 E8 ?? ?? ?? ?? 59 FF 75 ?? FF 15 ?? ?? ?? ?? F7 D8 5E 1B C0 40 5B 5F 8B E5 5D - C3 - } + $a = { 01 00 00 C1 00 00 00 0E 00 00 00 18 03 00 7F E9 38 32 C9 4D } condition: - uint16(0)==0x5A4D and ($enum_resources) and ($search_files) and ($encrypt_files) and ($remote_connection) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Flamingo : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_D8779A57 : FILE MEMORY { meta: - description = "Yara rule that detects Flamingo ransomware." - author = "ReversingLabs" - id = "333ef1f9-ac54-5a3d-9b2b-50483eeb93e1" - date = "2021-04-14" - modified = "2021-04-14" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Flamingo.yara#L1-L54" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "446c0d332af01c0fceb0356d5ab273eb55764869cc8343468b75625e5d4d1036" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "d8779a57-c6ee-4627-9eb0-ab9305bd2454" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L577-L595" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c490586fbf90d360cf3b2f9e2dc943809441df3dfd64dadad27fc9f5ee96ec74" + logic_hash = "2154786bbb6dbcc280aaa9e2b75106b585d04c7c85f6162f441c81dc54663cb3" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Flamingo" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "6c7a18cc03cacef5186d4c1f6ce05203cf8914c09798e345b41ce0dcee1ca9a6" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files = { - 68 ?? ?? ?? ?? 1B C0 23 C1 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? - 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? - ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 - ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 - C1 F9 ?? 89 8D ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? - 80 F9 ?? 75 ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 - 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 - C0 8B 85 ?? ?? ?? ?? 75 ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F - 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 - } - $encrypt_files = { - 68 ?? ?? ?? ?? 83 EC ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B CC C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C6 85 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? - ?? ?? 83 79 ?? ?? C7 41 ?? ?? ?? ?? ?? 72 ?? 8B 01 EB ?? 8B C1 6A ?? C6 00 ?? 8D 85 - ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 50 68 ?? ?? - ?? ?? 51 6A ?? 83 EC ?? C6 45 ?? ?? 8B CC C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? - C7 41 ?? ?? ?? ?? ?? 83 79 ?? ?? C7 41 ?? ?? ?? ?? ?? 72 ?? 8B 01 EB ?? 8B C1 6A ?? - C6 00 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 8B BD ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 45 ?? C6 45 ?? ?? 50 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 47 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 83 EC ?? 8B CC C7 41 ?? ?? ?? ?? - ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 83 79 ?? ?? C7 41 ?? ?? ?? ?? ?? 72 ?? - 8B 01 EB ?? 8B C1 6A ?? C6 00 ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 - } + $a = { B6 FF 41 89 D0 85 FF 74 29 38 56 08 74 28 48 83 C6 10 31 D2 } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) + all of them } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Retis : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_3E72E107 : FILE MEMORY { meta: - description = "Yara rule that detects Retis ransomware." - author = "ReversingLabs" - id = "3d1de7c2-abb7-5411-a598-6bc68229a22a" - date = "2021-08-12" - modified = "2021-08-12" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Retis.yara#L1-L74" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3e3429041acc5730b009916efbcd35c7cfd2b2877dc1d2cf980f7fb7d399d532" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "3e72e107-3647-4afd-a556-3c49dae7eb0c" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L597-L615" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "57d04035b68950246dd152054e949008dafb810f3705710d09911876cd44aec7" + logic_hash = "ba0ba56ded8977502ad9f8a1ceebd30efbff964d576bbfeedff5761f0538d8f0" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Retis" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "3bca41fd44e5e9d8cdfb806fbfcaab3cc18baa268985b95e2f6d06ecdb58741a" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $search_files = { - 00 00 04 6F ?? ?? ?? ?? 0B 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 0C 00 08 28 ?? ?? ?? ?? - 0A 72 ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 03 6F ?? ?? ?? - ?? 0D 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 00 00 72 ?? ?? ?? ?? 11 ?? 72 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 06 72 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? - ?? 17 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? - 12 ?? 28 ?? ?? ?? ?? 13 07 00 11 ?? 73 ?? ?? ?? ?? 13 ?? 02 11 ?? 28 ?? ?? ?? ?? 16 FE - ?? 13 ?? 11 ?? 2C ?? 00 02 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 1F ?? 28 ?? ?? ?? ?? - 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? - ?? 00 00 2B ?? 00 1F ?? 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 28 ?? ?? ?? - ?? 00 72 ?? ?? ?? ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 00 12 ?? - 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE ?? ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 00 DE - ?? 26 00 00 DE ?? 00 12 ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE ?? ?? ?? ?? ?? - 6F ?? ?? ?? ?? 00 DC 00 12 ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE ?? ?? ?? ?? - ?? 6F ?? ?? ?? ?? 00 DC 2A - } - $search_drives = { - 00 28 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 00 06 0C 16 0D 2B ?? 08 09 9A 13 ?? 00 - 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 07 11 ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? - ?? 6F ?? ?? ?? ?? 00 00 00 09 17 58 0D 09 08 8E 69 32 ?? 07 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 26 00 07 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? - 13 ?? 00 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 00 00 03 6F ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? - 12 ?? 28 ?? ?? ?? ?? 13 ?? 00 00 72 ?? ?? ?? ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 00 11 ?? 72 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? - ?? 17 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 00 11 ?? 6F ?? ?? ?? ?? 13 ?? 2B ?? - 12 ?? 28 ?? ?? ?? ?? 13 ?? 00 02 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 1F ?? - 28 ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 00 11 ?? 6F - ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE ?? - ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 00 DE ?? 26 00 00 DE ?? 00 12 ?? 28 ?? ?? ?? - ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE ?? ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 00 12 ?? - 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DE ?? 12 ?? FE ?? ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 - DC 2A - } - $encrypt_files = { - 00 03 19 17 73 ?? ?? ?? ?? 0A 06 6F ?? ?? ?? ?? D4 8D ?? ?? ?? ?? 0B 06 07 - 16 07 8E 69 6F ?? ?? ?? ?? 26 06 6F ?? ?? ?? ?? 00 03 18 18 73 ?? ?? ?? ?? - 0C 73 ?? ?? ?? ?? 0D 09 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F - ?? ?? ?? ?? 00 09 28 ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? - ?? ?? 00 09 6F ?? ?? ?? ?? 13 ?? 08 11 ?? 17 73 ?? ?? ?? ?? 13 ?? 11 ?? 07 - 16 07 8E 69 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? 00 - 03 03 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 2A - } + $a = { 10 85 C0 BA FF FF FF FF 74 14 8D 65 F4 5B 5E 5F 89 D0 5D C3 8D } condition: - uint16(0)==0x5A4D and ($search_files and $search_drives and $encrypt_files) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Acepy : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_5C62E6B2 : FILE MEMORY { meta: - description = "Yara rule that detects Acepy ransomware." - author = "ReversingLabs" - id = "3ffb45b1-6bde-5bf8-957e-433b9488ba91" - date = "2022-08-04" - modified = "2022-08-04" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Acepy.yara#L1-L69" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "92c543a0b8c3c884f83647119d32c7b46f5fe839694bb8a8de0146c5c77bc587" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "5c62e6b2-9f6a-4c6d-b3fc-c6cbc8cf0b4b" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L617-L635" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "91642663793bdda93928597ff1ac6087e4c1e5d020a8f40f2140e9471ab730f9" + logic_hash = "6505c4272f0f7c8c5f2d3f7cefdc3947c4015b0dfd94efde4357a506af93a99d" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Acepy" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "39501003c45c89d6a08f71fbf9c442bcc952afc5f1a1eb7b5af2d4b7633698a8" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files = { - E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? - 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? B9 ?? ?? ?? ?? 51 50 E8 ?? ?? ?? ?? - 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B 45 ?? 8B 08 51 E8 ?? ?? ?? ?? - 83 C4 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? - E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? - B8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 - 8B 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? - ?? ?? B8 ?? ?? ?? ?? C9 C3 - } - $encrypt_files = { - 55 89 E5 81 EC ?? ?? ?? ?? 90 B8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 89 45 ?? 8B 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? - ?? ?? B8 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? B8 ?? ?? ?? ?? 50 B8 ?? ?? ?? ?? 50 8B 45 ?? - 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 40 50 B8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 89 45 ?? 8B 45 ?? 50 B8 ?? ?? ?? ?? 50 8B 45 ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? B8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 4D ?? 39 C8 0F 83 ?? ?? ?? ?? E9 ?? ?? ?? ?? - 8B 45 ?? 89 C1 40 89 45 ?? EB ?? 8B 45 ?? 8B 4D ?? 01 C1 8B 45 ?? 8B 55 ?? 01 C2 8B - 45 ?? 50 89 4D ?? 89 55 ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 8B 45 ?? 8B 4D ?? 31 D2 - F7 F1 8B 45 ?? 01 D0 8B 4D ?? 0F BE 09 0F BE 10 31 D1 8B 45 ?? 88 08 EB ?? B8 ?? ?? - ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 B9 ?? ?? ?? ?? 51 50 E8 ?? - ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 B8 ?? ?? ?? ?? 50 8B 45 ?? 50 8B 45 ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? C9 C3 - } - $drop_ransom_note = { - 55 89 E5 81 EC ?? ?? ?? ?? 90 B8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 89 45 ?? 8B 45 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? - ?? ?? B8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 50 B8 ?? ?? ?? ?? 50 B8 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? B8 ?? ?? - ?? ?? C9 C3 - } + $a = { FF C1 83 F9 05 7F 14 48 63 C1 48 89 94 C4 00 01 00 00 FF C6 48 } condition: - uint16(0)==0x5A4D and (($find_files) and ($encrypt_files) and ($drop_ransom_note)) + all of them } -import "pe" - -rule REVERSINGLABS_Win32_Ransomware_Dirtydecrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_C5430Ff9 : FILE MEMORY { meta: - description = "Yara rule that detects DirtyDecrypt ransomware." - author = "ReversingLabs" - id = "f4d69c3e-a082-5bc9-bf72-4cc330d3de74" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.DirtyDecrypt.yara#L3-L112" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "eb6a1c376b0739848b523e741d0d1ebdbc87056d51931fb94c744aa094d6479f" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "c5430ff9-af40-4653-94c3-4651a5e9331e" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L637-L655" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "5676773882a84d0efc220dd7595c4594bc824cbe3eeddfadc00ac3c8e899aa77" + logic_hash = "8c385980560cd4b24e703744b57a9d5ea1bca8fbeea066e98dd4b40009e56104" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "DirtyDecrypt" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "a19dcb00fc5553d41978184cc53ef93c36eb9541ea19c6c50496b4e346aaf240" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $dd_ep = { - 55 8B EC 83 EC ?? E8 ?? ?? ?? ?? 85 C0 0F 84 BF 00 00 00 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 - 1F 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 74 07 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB - 09 8B 4D ?? 83 C1 ?? 89 4D ?? 83 7D ?? ?? 73 15 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 89 44 95 ?? EB DC 6A ?? 68 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? - 8B 15 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A - ?? 8D 55 ?? 52 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 33 C0 8B E5 5D C2 ?? ?? - } - $dd_hash = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 D5 00 00 00 83 7D ?? ?? 0F 84 CB 00 00 00 83 7D ?? ?? 0F 84 C1 - 00 00 00 83 7D ?? ?? 0F 84 B7 00 00 00 83 7D ?? ?? 0F 84 AD 00 00 00 83 7D ?? ?? 0F 84 A3 00 00 00 C7 45 ?? ?? ?? ?? ?? - 8D 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 C0 75 02 EB 6F 83 7D ?? ?? 76 2A 6A ?? 6A ?? 8B - 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 02 EB 51 8B 4D ?? 83 E9 ?? 89 4D ?? 8B 55 ?? 83 C2 ?? 89 55 ?? 6A ?? 8B - 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 02 EB 25 6A ?? 6A ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B - 45 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 33 C9 0F 85 74 FF FF FF 83 7D ?? ?? 74 0A 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 8B 45 ?? 8B - E5 5D C2 ?? ?? - } - $dd_getkey = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 31 C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8D 4D ?? 51 6A ?? 8B 55 - ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 07 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? C1 E8 ?? 89 45 ?? 8B 45 ?? 8B E5 5D C2 ?? ?? - } - $dd_destroykey = { - 55 8B EC 83 7D ?? ?? 74 0A 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 5D C2 - } - $dd_importkey = { - 55 8B EC 51 C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? 8B 4D ?? 8B 51 ?? 52 8B 45 ?? 8B 08 51 8B 55 ?? 52 FF 15 ?? ?? - ?? ?? 8B 45 ?? 8B E5 5D C2 ?? ?? - } - $dd_decrypt = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 22 01 00 00 83 7D ?? ?? 0F 84 18 01 00 00 83 7D ?? ?? 0F 84 0E - 01 00 00 83 7D ?? ?? 0F 84 04 01 00 00 83 7D ?? ?? 0F 84 FA 00 00 00 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 33 D2 - F7 75 ?? 0F AF 45 ?? 89 45 ?? 8B 4D ?? 89 4D ?? 8B 55 ?? 8B 02 03 45 ?? 89 45 ?? 8B 4D ?? 8B 11 03 55 ?? 52 8B 45 ?? 8B - 08 51 6A ?? E8 ?? ?? ?? ?? 8B 55 ?? 89 02 8B 45 ?? 83 38 ?? 0F 84 A7 00 00 00 8B 4D ?? 8B 11 8B 45 ?? 03 10 89 55 ?? 83 - 7D ?? ?? 74 61 6A ?? 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 45 ?? - 89 45 ?? 8D 4D ?? 51 8B 55 ?? 52 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 02 EB 1D 8B 4D ?? 03 4D ?? 89 - 4D ?? 8B 55 ?? 2B 55 ?? 89 55 ?? 8B 45 ?? 03 45 ?? 89 45 ?? EB 99 83 7D ?? ?? 75 15 8B 4D ?? 89 4D ?? 8B 55 ?? 8B 45 ?? - 2B 02 8B 4D ?? 89 01 EB 18 8B 55 ?? 8B 02 50 8B 4D ?? 8B 11 52 6A ?? E8 ?? ?? ?? ?? 8B 4D ?? 89 01 8B 45 ?? 8B E5 5D C2 - ?? ?? - } - $dd_encrypt = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 89 01 00 00 83 7D ?? ?? 0F 84 7F 01 00 00 83 7D ?? ?? 0F 84 75 - 01 00 00 83 7D ?? ?? 0F 84 6B 01 00 00 83 7D ?? ?? 0F 84 61 01 00 00 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 8B 4D ?? 83 E9 - ?? 89 4D ?? 8B 55 ?? 89 55 ?? 6A ?? 8D 45 ?? 50 6A ?? 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 C0 0F 84 26 01 - 00 00 8B 55 ?? 3B 55 ?? 76 08 8B 45 ?? 89 45 ?? EB 06 8B 4D ?? 89 4D ?? 8B 55 ?? 89 55 ?? 8B 45 ?? 33 D2 F7 75 ?? 0F AF - 45 ?? 8B 4D ?? 8B 11 03 D0 03 55 ?? 89 55 ?? 8B 45 ?? 50 8B 4D ?? 8B 11 52 6A ?? E8 ?? ?? ?? ?? 8B 4D ?? 89 01 8B 55 ?? - 83 3A ?? 0F 84 CF 00 00 00 8B 45 ?? 8B 08 8B 55 ?? 03 0A 89 4D ?? 83 7D ?? ?? 0F 84 84 00 00 00 8B 45 ?? 3B 45 ?? 73 08 - 8B 4D ?? 89 4D ?? EB 06 8B 55 ?? 89 55 ?? 8B 45 ?? 89 45 ?? 6A ?? 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B - 4D ?? 89 4D ?? 8B 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 02 EB 2D 8B - 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 55 ?? 03 55 ?? 89 55 ?? 8B 45 ?? 2B 45 ?? 89 45 ?? 8B 4D ?? 03 4D ?? 89 4D ?? E9 - 72 FF FF FF 83 7D ?? ?? 75 16 8B 55 ?? 8B 45 ?? 2B 02 8B 4D ?? 89 01 C7 45 ?? ?? ?? ?? ?? EB 18 8B 55 ?? 8B 02 50 8B 4D - ?? 8B 11 52 6A ?? E8 ?? ?? ?? ?? 8B 4D ?? 89 01 8B 45 ?? 8B E5 5D C2 ?? ?? - } - $dd_provparam = { - 55 8B EC 83 EC ?? 83 7D ?? ?? 0F 84 94 00 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A ?? 6A ?? - 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 C0 74 3F 8B 55 ?? 83 C2 ?? 52 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 2A 6A ?? 8D 45 ?? - 50 8B 4D ?? 51 6A ?? 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 10 8B 45 ?? 50 E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8B - 4D ?? 51 FF 15 ?? ?? ?? ?? 83 7D ?? ?? 74 1D 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? 51 E8 - ?? ?? ?? ?? 8B E5 5D C2 ?? ?? - } - $dd_acquirecontext = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 0B 8B 45 ?? 0D ?? ?? ?? ?? 89 45 ?? C7 45 ?? - ?? ?? ?? ?? 83 7D ?? ?? 75 07 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 03 45 ?? 50 6A ?? 6A ?? 6A ?? 8D 4D ?? 51 E8 ?? ?? ?? - ?? 8B 55 ?? 52 6A ?? 8B 45 ?? 50 8D 4D ?? 51 8D 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 39 8B 45 ?? 83 C8 ?? 50 6A ?? 8B 4D - ?? 51 8D 55 ?? 52 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 1A 6A ?? 6A ?? 6A ?? 8D 4D ?? 51 8D 55 ?? 52 FF 15 ?? ?? ?? ?? - 85 C0 75 02 EB 0E 6A ?? FF 15 ?? ?? ?? ?? 83 7D ?? ?? 74 9D 8B 45 ?? 8B E5 5D C2 ?? ?? - } - $dd_mrwhite = { - 55 8B EC 81 EC ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 64 01 00 00 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8D - 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 12 83 3D ?? ?? ?? ?? ?? 74 09 83 3D ?? ?? ?? ?? ?? 75 05 E9 13 - 01 00 00 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 85 C0 75 05 E9 F0 00 00 00 8B 95 - ?? ?? ?? ?? 52 6A ?? 6A ?? 6A ?? 8B 45 ?? 50 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 - 05 E9 C0 00 00 00 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 85 C0 74 09 83 BD ?? ?? ?? ?? ?? 73 05 E9 9B - 00 00 00 8B 95 ?? ?? ?? ?? 52 8B 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 - 75 02 EB 72 8B 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 02 83 C0 ?? 3B 85 ?? ?? ?? ?? 76 02 EB 51 8B 8D ?? - ?? ?? ?? 83 39 ?? 74 3E 0F B7 95 ?? ?? ?? ?? 83 FA ?? 75 32 8B 85 ?? ?? ?? ?? 8B 08 51 8B 95 ?? ?? ?? ?? 83 C2 ?? 52 6A - ?? 8D 85 ?? ?? ?? ?? 50 8B 0D ?? ?? ?? ?? 51 8B 15 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 89 45 ?? 33 C0 0F 85 CD FE FF FF 8D 8D - ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 8B 45 ?? 8B E5 5D C2 ?? ?? - } + $a = { 00 00 00 FC F3 A6 0F 97 C2 0F 92 C0 38 C2 75 29 83 EC 08 8B } condition: - uint16(0)==0x5A4D and ($dd_ep at pe.entry_point) and $dd_hash and $dd_getkey and $dd_destroykey and $dd_importkey and $dd_decrypt and $dd_encrypt and $dd_provparam and $dd_acquirecontext and $dd_mrwhite + all of them } -rule REVERSINGLABS_Win32_Ransomware_Cryptojoker : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_402Adc45 : FILE MEMORY { meta: - description = "Yara rule that detects CryptoJoker ransomware." - author = "ReversingLabs" - id = "50a9280b-a352-5a2b-acee-5690e509dfd7" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.CryptoJoker.yara#L1-L140" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "42ee1e63ada1ae986f43a1300eda0b1fa7b54c26be31ef5637bb321defffbe40" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "402adc45-6279-44a6-b766-24706b0328fe" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L657-L675" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "1ae0cd7e5bac967e31771873b4b41a1887abddfcdfcc76fa9149bb2054b03ca4" + logic_hash = "dab879d57507d5e119ddf4ce6ed33570c74f185a2260e97a7ec1d6c844943e5d" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "CryptoJoker" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "01b88411c40abc65c24d7a335027888c0cf48ad190dd3fa1b8e17d086a9b80a0" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $call_encrypt = { - 2B 02 26 16 FE 09 00 00 FE 09 01 00 FE 09 02 00 6F ?? ?? ?? ?? 2A - } - $encrypt_files = { - 2B 02 26 16 20 04 ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 26 20 00 04 ?? ?? 73 ?? ?? ?? ?? 0C 20 05 ?? ?? ?? - 16 39 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 0B 38 ?? ?? ?? ?? 20 04 ?? ?? ?? FE ?? ?? ?? FE ?? ?? - ?? 45 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 38 ?? ?? ?? ?? 26 - 20 03 ?? ?? ?? 16 39 ?? ?? ?? ?? 26 00 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? - ?? ?? ?? 26 20 00 ?? ?? ?? 38 ?? ?? ?? ?? 00 00 08 06 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? - ?? ?? 26 20 03 ?? ?? ?? 38 ?? ?? ?? ?? 09 28 ?? ?? ?? ?? 13 04 20 04 ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? - 26 00 08 07 17 28 ?? ?? ?? ?? 0D 38 ?? ?? ?? ?? 20 03 ?? ?? ?? FE ?? ?? ?? FE ?? ?? ?? 45 ?? ?? ?? ?? ?? ?? - ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 38 ?? ?? ?? ?? 26 20 02 ?? ?? ?? 38 ?? ?? ?? ?? 11 04 - 13 05 DD ?? ?? ?? ?? 00 08 16 28 ?? ?? ?? ?? 00 00 DC 08 14 FE 01 13 06 11 06 3A ?? ?? ?? ?? 08 28 ?? ?? ?? - ?? 00 DC 00 11 05 2A - } - $start_process = { - 2B ?? 26 16 20 10 ?? ?? ?? 38 ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 20 ?? ?? ?? ?? - 38 ?? ?? ?? ?? 00 11 05 17 28 ?? ?? ?? ?? 20 06 ?? ?? ?? 38 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? - 0A 20 09 ?? ?? ?? 38 ?? ?? ?? ?? 00 11 05 08 28 ?? ?? ?? ?? 20 12 ?? ?? ?? 38 ?? ?? ?? ?? - 11 06 17 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 - ?? ?? ?? ?? 11 05 17 28 ?? ?? ?? ?? 20 ?? ?? ?? ?? 38 ?? ?? ?? ?? 11 06 19 20 ?? ?? ?? ?? - 28 ?? ?? ?? ?? A2 20 0F ?? ?? ?? 38 ?? ?? ?? ?? 1A 8D ?? ?? ?? ?? 13 06 20 02 ?? ?? ?? 38 - ?? ?? ?? ?? 00 11 04 28 ?? ?? ?? ?? 26 20 13 ?? ?? ?? 38 ?? ?? ?? ?? 08 09 28 ?? ?? ?? ?? - 20 07 ?? ?? ?? 38 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 05 38 ?? ?? ?? ?? 26 20 0D ?? ?? ?? 38 ?? - ?? ?? ?? 11 06 0D 38 ?? ?? ?? ?? 20 10 ?? ?? ?? FE ?? ?? ?? FE ?? ?? ?? 45 ?? ?? ?? ?? ?? - ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? - ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? - ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 20 08 ?? ?? ?? 17 3A ?? ?? ?? ?? - 26 11 06 18 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 20 00 ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? - 26 06 07 28 ?? ?? ?? ?? 0C 20 0B ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 26 11 06 16 20 ?? - ?? ?? ?? 28 ?? ?? ?? ?? A2 17 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 26 20 03 ?? ?? ?? 16 39 ?? ?? - ?? ?? 26 00 11 04 11 05 28 ?? ?? ?? ?? 20 0A ?? ?? ?? 17 3A ?? ?? ?? ?? 26 00 73 ?? ?? ?? - ?? 13 04 20 04 ?? ?? ?? 38 ?? ?? ?? ?? 2A - } - $msgbox_timer = { - 00 28 ?? ?? ?? ?? 0A 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 28 ?? ?? ?? ?? 0C - 00 02 7B ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 DE 12 08 14 FE 01 - 13 04 11 04 2D ?? 08 6F ?? ?? ?? ?? 00 DC 00 02 7B ?? ?? ?? ?? 16 32 0E 02 7B - ?? ?? ?? ?? 16 FE 04 16 FE 01 2B ?? 16 00 13 04 11 04 2D ?? 00 02 7B ?? ?? ?? - ?? 6F ?? ?? ?? ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 38 ?? ?? ?? ?? 02 7B ?? - ?? ?? ?? 2D ?? 02 7B ?? ?? ?? ?? 2D ?? 02 7B ?? ?? ?? ?? 16 FE 01 16 FE 01 2B - ?? 17 00 13 04 11 04 2D ?? 00 02 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 73 ?? ?? ?? - ?? 0D 09 17 6F ?? ?? ?? ?? 00 09 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 1F 40 28 ?? - ?? ?? ?? 26 00 38 ?? ?? ?? ?? 00 02 7B ?? ?? ?? ?? 17 FE 04 16 FE 01 13 04 11 - 04 2D ?? 00 02 1F 3B 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 17 FE 04 16 FE 01 13 04 - 11 04 2D ?? 00 02 1F 3B 7D ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 16 FE 01 13 04 11 04 - 2D ?? 02 25 7B ?? ?? ?? ?? 17 59 7D ?? ?? ?? ?? 00 2B ?? 02 25 7B ?? ?? ?? ?? - 17 59 7D ?? ?? ?? ?? 00 2B ?? 02 25 7B ?? ?? ?? ?? 17 59 7D ?? ?? ?? ?? 02 7B - ?? ?? ?? ?? 1F 09 FE 02 16 FE 01 13 04 11 04 2D ?? 02 7B ?? ?? ?? ?? 02 7C ?? - ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 2B ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? - ?? 02 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 7B ?? - ?? ?? ?? 1F 09 FE 02 16 FE 01 13 04 11 04 2D ?? 02 7B ?? ?? ?? ?? 02 7C ?? ?? - ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 2B ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? - 02 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 02 7B ?? ?? - ?? ?? 1F 09 FE 02 16 FE 01 13 04 11 04 2D ?? 02 7B ?? ?? ?? ?? 02 7C ?? ?? ?? - ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 2B ?? 02 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 02 - 7C ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 00 2A - } - $unzip_packed_file = { - 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 0B 06 07 2E ?? 07 06 28 ?? ?? ?? ?? 2D ?? 14 - 2A 02 73 ?? ?? ?? ?? 0C 16 8D ?? ?? ?? ?? 0D 08 6F ?? ?? ?? ?? 13 04 11 04 20 - ?? ?? ?? ?? 40 ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 68 13 05 08 6F ?? ?? ?? ?? 13 06 - 08 6F ?? ?? ?? ?? 13 07 11 04 20 ?? ?? ?? ?? 33 ?? 11 05 1F 14 33 ?? 11 06 2D - ?? 11 07 1E 2E ?? 72 ?? ?? ?? ?? 73 ?? ?? ?? ?? 7A 08 6F ?? ?? ?? ?? 26 08 6F - ?? ?? ?? ?? 26 08 6F ?? ?? ?? ?? 26 08 6F ?? ?? ?? ?? 13 08 08 6F ?? ?? ?? ?? - 13 09 08 6F ?? ?? ?? ?? 13 0A 11 09 16 31 ?? 11 09 8D ?? ?? ?? ?? 13 0B 08 11 - 0B 16 11 09 6F ?? ?? ?? ?? 26 11 0A 16 31 ?? 11 0A 8D ?? ?? ?? ?? 13 0C 08 11 - 0C 16 11 0A 6F ?? ?? ?? ?? 26 08 6F ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 59 D4 8D ?? - ?? ?? ?? 13 0D 08 11 0D 16 11 0D 8E 69 6F ?? ?? ?? ?? 26 11 0D 73 ?? ?? ?? ?? - 13 0E 11 08 8D ?? ?? ?? ?? 0D 11 0E 09 16 09 8E 69 6F ?? ?? ?? ?? 26 14 13 0D - 38 ?? ?? ?? ?? 11 04 1F 18 63 13 0F 11 04 11 0F 1F 18 62 59 13 04 11 04 20 ?? - ?? ?? ?? 40 ?? ?? ?? ?? 11 0F 17 33 ?? 08 6F ?? ?? ?? ?? 13 10 11 10 8D ?? ?? - ?? ?? 0D 16 13 11 2B ?? 08 6F ?? ?? ?? ?? 13 12 08 6F ?? ?? ?? ?? 13 13 11 12 - 8D ?? ?? ?? ?? 13 15 08 11 15 16 11 15 8E 69 6F ?? ?? ?? ?? 26 11 15 73 ?? ?? - ?? ?? 13 14 11 14 09 11 11 11 13 6F ?? ?? ?? ?? 26 11 11 11 13 58 13 11 11 11 - 11 10 32 ?? 11 0F 18 33 ?? 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 13 16 1E 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 17 11 16 11 17 17 - 28 ?? ?? ?? ?? 13 18 11 18 02 1A 02 8E 69 1A 59 6F ?? ?? ?? ?? 13 19 11 19 28 - ?? ?? ?? ?? 0D DE ?? 11 18 2C ?? 11 18 6F ?? ?? ?? ?? DC 11 0F 19 33 ?? 1F 10 - 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 1A 1F 10 8D ?? ?? ?? ?? 25 - D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 1B 11 1A 11 1B 17 28 ?? ?? ?? ?? 13 1C 11 1C - 02 1A 02 8E 69 1A 59 6F ?? ?? ?? ?? 13 1D 11 1D 28 ?? ?? ?? ?? 0D DE 17 11 1C - 2C ?? 11 1C 6F ?? ?? ?? ?? DC 72 B5 0E 00 70 73 ?? ?? ?? ?? 7A 08 6F ?? ?? ?? - ?? 14 0C 09 2A - } - $resolve_assembly = { - 12 00 03 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 12 00 16 28 ?? ?? ?? ?? 0B 28 ?? ?? ?? ?? 07 - 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 72 ?? ?? ?? ?? 17 8D ?? ?? ?? ?? 13 13 11 13 16 1F - 2C 9D 11 13 6F ?? ?? ?? ?? 0D 7E ?? ?? ?? ?? 13 04 16 13 05 16 13 06 16 13 07 2B ?? - 09 11 07 9A 08 28 ?? ?? ?? ?? 2C 0A 09 11 07 17 58 9A 13 04 2B ?? 11 07 18 58 13 07 - 11 07 09 8E 69 17 59 32 ?? 11 04 6F ?? ?? ?? ?? 2D ?? 12 00 7B ?? ?? ?? ?? 6F ?? ?? - ?? ?? 2D ?? 28 ?? ?? ?? ?? 12 00 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 16 - 13 08 2B ?? 09 11 08 9A 08 28 ?? ?? ?? ?? 2C ?? 09 11 08 17 58 9A 13 04 2B ?? 11 08 - 18 58 13 08 11 08 09 8E 69 17 59 32 ?? 11 04 6F ?? ?? ?? ?? 16 3E ?? ?? ?? ?? 11 04 - 16 6F ?? ?? ?? ?? 1F 5B 33 ?? 11 04 1F 5D 6F ?? ?? ?? ?? 13 09 11 04 17 11 09 17 59 - 6F ?? ?? ?? ?? 13 0A 11 0A 1F 7A 6F ?? ?? ?? ?? 16 FE 04 16 FE 01 13 05 11 0A 1F 74 - 6F ?? ?? ?? ?? 16 FE 04 16 FE 01 13 06 11 04 11 09 17 58 6F ?? ?? ?? ?? 13 04 7E ?? - ?? ?? ?? 25 13 14 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 11 04 6F ?? ?? ?? ?? 2C ?? 7E ?? ?? - ?? ?? 11 04 6F ?? ?? ?? ?? 13 12 DD ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 04 6F ?? ?? ?? ?? - 13 0B 11 0B 39 ?? ?? ?? ?? 11 0B 6F ?? ?? ?? ?? 69 13 0C 11 0C 8D ?? ?? ?? ?? 13 0D - 11 0B 11 0D 16 11 0C 6F ?? ?? ?? ?? 26 11 05 2C ?? 11 0D 28 ?? ?? ?? ?? 13 0D 14 13 - 0E 11 06 2D ?? 11 0D 28 ?? ?? ?? ?? 13 0E DE 0C 26 17 13 06 DE ?? 26 17 13 06 DE ?? - 11 06 2C ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 04 28 ?? ?? ?? ?? 13 0F 11 0F 28 ?? ?? - ?? ?? 26 11 0F 12 00 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 10 11 10 28 ?? - ?? ?? ?? 2D ?? 11 10 28 ?? ?? ?? ?? 13 11 11 11 11 0D 16 11 0D 8E 69 6F ?? ?? ?? ?? - 11 11 6F ?? ?? ?? ?? 11 10 14 1A 28 ?? ?? ?? ?? 26 11 0F 14 1A 28 ?? ?? ?? ?? 26 11 - 10 28 ?? ?? ?? ?? 13 0E DE ?? 26 DE ?? 7E ?? ?? ?? ?? 11 04 11 0E 6F ?? ?? ?? ?? 11 - 0E 13 12 DE ?? DE ?? 11 14 28 ?? ?? ?? ?? DC 14 2A 11 12 2A - } + $a = { C3 EB DF 5A 5B 5D 41 5C 41 5D C3 41 57 41 56 41 55 41 54 55 53 48 } condition: - uint16(0)==0x5A4D and (($call_encrypt and $encrypt_files and $start_process) or ($msgbox_timer) or ($unzip_packed_file and $resolve_assembly)) + all of them } -import "pe" - -rule REVERSINGLABS_Win32_Ransomware_Cryptowall : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_A39Dfaa7 : FILE MEMORY { meta: - description = "Yara rule that detects CryptoWall ransomware." - author = "ReversingLabs" - id = "06d8b106-d69a-526a-8e16-c95d39eb2993" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.CryptoWall.yara#L3-L312" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "74baa04ee506732e0bb64a77cfd2d2216fcc978f13447ef07862e0116c093c14" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "a39dfaa7-7d2c-4d40-bea5-bbebad522fa4" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L677-L694" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "98fde36fc412b6aa50c80c12118975a6bf754a9fba94f1cc3cdeed22565d6b0d" score = 75 - quality = 88 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "CryptoWall" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "95d12cb127c088d55fb0090a1cb0af8e0a02944ff56fd18bcb0834b148c17ad7" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $v30_entrypoint = { - 55 8B EC 83 EC ?? E8 ?? ?? ?? ?? 85 C0 0F 84 9A 00 00 00 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 75 7E C7 45 ?? ?? ?? ?? ?? - 8D 45 ?? 50 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 65 8B 4D ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 - E8 ?? ?? ?? ?? 8B 40 ?? A3 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 - 75 19 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A - ?? 6A ?? E8 ?? ?? ?? ?? 8B 50 ?? FF D2 33 C0 8B E5 5D C2 - } - $v20_entrypoint = { - 55 8B EC 83 EC ?? E8 ?? ?? ?? ?? 85 C0 0F 84 A3 00 00 00 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 85 83 00 00 00 C7 45 ?? - ?? ?? ?? ?? 8D 45 ?? 50 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 6A 8B 4D ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 90 ?? ?? - ?? ?? FF D2 E8 ?? ?? ?? ?? 8B 40 ?? A3 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 75 19 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 - E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B 50 ?? FF D2 33 C0 8B E5 5D C2 - } - $v30_api_load = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 50 01 00 00 8B 45 ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 34 01 00 00 B9 ?? ?? ?? ?? 6B D1 ?? 8B 45 ?? 8B 4D ?? 03 4C 10 ?? 89 4D ?? 8B - 55 ?? 8B 45 ?? 03 42 ?? 89 45 ?? 8B 4D ?? 8B 55 ?? 03 51 ?? 89 55 ?? 8B 45 ?? 8B 4D ?? 03 48 ?? 89 4D ?? C7 45 ?? ?? ?? - ?? ?? EB 09 8B 55 ?? 83 C2 ?? 89 55 ?? 8B 45 ?? 8B 4D ?? 3B 48 ?? 0F 83 DA 00 00 00 8B 55 ?? 8B 45 ?? 8B 4D ?? 03 0C 90 - 51 E8 ?? ?? ?? ?? 83 C4 ?? 3B 45 ?? 0F 85 B7 00 00 00 BA ?? ?? ?? ?? 6B C2 ?? 8B 4D ?? 8B 54 01 ?? 8B 44 01 ?? 89 55 ?? - 89 45 ?? 8B 4D ?? 8B 55 ?? 0F B7 04 4A 8B 4D ?? 8B 14 81 3B 55 ?? 76 71 8B 45 ?? 8B 4D ?? 0F B7 14 41 8B 45 ?? 03 45 ?? - 8B 4D ?? 39 04 91 73 59 8B 55 ?? 8B 45 ?? 0F B7 0C 50 8B 55 ?? 8B 45 ?? 03 04 8A 89 45 ?? 74 3F 6A ?? 8B 4D ?? 51 E8 ?? - ?? ?? ?? 83 C4 ?? 8B 55 ?? 8D 44 02 ?? 50 8D 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8D 45 ?? 50 6A ?? 8D 4D ?? - 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 40 ?? FF D0 EB 16 8B 4D ?? 8B 55 ?? 0F B7 04 4A 8B 4D ?? 8B 55 ?? 03 14 81 89 55 ?? EB - 05 E9 0E FF FF FF 8B 45 ?? 8B E5 5D C3 - } - $v30_dll_load = { - 55 8B EC 83 EC ?? E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 74 58 8B 45 ?? 8B 48 ?? 89 4D ?? 8B 55 ?? 83 C2 ?? 89 55 ?? 8B 45 - ?? 8B 08 89 4D ?? 8B 55 ?? 3B 55 ?? 74 36 8B 45 ?? 89 45 ?? 8B 4D ?? 0F B7 51 ?? D1 EA 52 8B 45 ?? 8B 48 ?? 51 E8 ?? ?? - ?? ?? 83 C4 ?? 3B 45 ?? 75 08 8B 55 ?? 8B 42 ?? EB 0C 8B 45 ?? 8B 08 89 4D ?? EB C2 33 C0 8B E5 5D C3 - } - $v30_calculate_hash = { - 55 8B EC 83 EC ?? 56 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 5E 83 7D ?? ?? 74 58 8B 45 ?? 89 45 ?? 8B 4D ?? 89 4D ?? 8B 55 - ?? 83 EA ?? 89 55 ?? 83 7D ?? ?? 74 3D 8B 45 ?? 66 8B 08 66 89 4D ?? 8B 75 ?? C1 EE ?? 0F B7 55 ?? 52 E8 ?? ?? ?? ?? 83 - C4 ?? 0F B7 C0 33 45 ?? 25 ?? ?? ?? ?? 33 34 85 ?? ?? ?? ?? 89 75 ?? 8B 4D ?? 83 C1 ?? 89 4D ?? EB AE 8B 45 ?? 83 F0 ?? - 5E 8B E5 5D C3 - } - $v30_1_find_file_1 = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 47 02 00 00 E8 ?? ?? ?? ?? 89 45 - ?? 83 7D ?? ?? 0F 84 32 02 00 00 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 8B 4D ?? 0F B7 54 41 ?? 83 FA ?? 74 16 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 68 - ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? - ?? 0F 84 B2 01 00 00 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 84 01 00 - 00 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 8B 11 83 E2 ?? 0F 85 A0 00 00 00 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 85 C0 0F 85 80 00 00 00 8D 4D ?? 51 8B 55 ?? 83 C2 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 69 C7 45 ?? ?? ?? - ?? ?? 8D 45 ?? 50 8B 4D ?? 83 C1 ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 47 8B 45 ?? 50 8B 4D ?? 8B 11 52 8B - 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 75 1C 8B 4D ?? 83 C1 ?? 89 4D ?? 8B 55 ?? 8B 42 ?? 50 8B 4D ?? 51 - } - $v30_1_find_file_2 = { - E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? EB 67 8B 45 ?? 83 C0 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 - 54 C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 51 8B 55 ?? 83 C2 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 32 8B 4D ?? 51 E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 75 16 8B 55 ?? 52 8B 45 ?? 50 E8 30 FE FF FF 83 C4 ?? 03 45 ?? 89 45 ?? 8B 4D ?? 51 E8 ?? ?? - ?? ?? 83 C4 ?? 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 0F 85 CE FE FF FF 8B 55 ?? 52 E8 ?? - ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 7D ?? ?? 74 2E 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 - C4 ?? 3D ?? ?? ?? ?? 74 0E 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 89 4D ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 - ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 8B E5 5D C3 - } - $v30_2_find_file_1 = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 ( 3B | 3D ) 02 00 00 E8 ?? ?? ?? - ?? 89 45 ?? 83 7D ?? ?? 0F 84 ( 26 | 28 ) 02 00 00 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 0F B7 54 41 ?? 83 FA ?? 74 16 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? - ?? ?? ?? FF D1 68 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 89 45 ?? 83 7D ?? ?? 0F 84 ( A6 | A8 ) 01 00 00 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 89 45 ?? - 83 7D ?? ?? 0F 84 ( 78 | 7A ) 01 00 00 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 8B 11 83 E2 ?? 0F 85 94 00 00 00 C7 45 ?? ?? ?? ?? - ?? 8B 45 ?? 83 C0 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 78 8B 4D ?? 83 C1 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 65 C7 - 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 83 C0 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 43 8B 55 ?? 8B 02 50 8B - } - $v30_2_find_file_2 = { - 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 75 1C 8B 55 ?? 83 C2 ?? 89 55 ?? 8B 45 ?? 8B 48 ?? 51 8B 55 ?? 52 - E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB 67 8B 4D ?? 83 C1 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 - 54 C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8B 45 ?? 83 C0 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 32 8B 55 ?? 52 E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 75 16 8B 45 ?? 50 8B 4D ?? 51 E8 3C FE FF FF 83 C4 ?? 03 45 ?? 89 45 ?? 8B 55 ?? 52 E8 ?? ?? - ?? ?? 83 C4 ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 0F 85 DA FE FF FF 8B 45 ?? 50 E8 ?? - ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 83 7D ?? ?? 74 ( 2E | 30 ) 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 50 8B 45 ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 3D ?? ?? ?? ?? 74 ( 0E | 10 ) 6A ?? [0-2] 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 89 55 ?? 8B 45 ?? - 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 8B E5 5D C3 - } - $v30_3_find_file_1 = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 7C 02 00 00 E8 ?? ?? ?? ?? 89 45 - ?? 83 7D ?? ?? 0F 84 67 02 00 00 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 8B 4D ?? 0F B7 54 41 ?? 83 FA ?? 74 16 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 68 - ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? - ?? 0F 84 E7 01 00 00 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 B9 01 00 - 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 83 C1 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 91 00 00 00 8D 55 - ?? 52 8B 45 ?? 83 C0 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 7A 8B 4D ?? 8B 11 83 E2 ?? 75 70 C7 45 ?? ?? ?? ?? ?? 8D 45 - ?? 50 8B 4D ?? 83 C1 ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 49 8B 45 ?? 8B 48 ?? 51 8B 55 ?? 52 8B 45 ?? 8B - } - $v30_3_find_file_2 = { - 08 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 1C 8B 45 ?? 83 C0 ?? 89 45 ?? 8B 4D ?? 8B 51 ?? 52 8B 45 ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? E9 88 00 00 00 8B 55 ?? 8B 02 83 E0 ?? 74 7E 8B 4D ?? 83 79 ?? ?? - 74 75 8B 55 ?? 83 C2 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 62 C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 8B 4D ?? 83 C1 ?? 51 8B - 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 40 8B 45 ?? 50 8B 4D ?? 8B 51 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 1D 8B 45 - ?? 50 8B 4D ?? 51 E8 15 FE FF FF 83 C4 ?? 85 C0 74 09 8B 55 ?? 83 C2 ?? 89 55 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B - 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 85 C0 0F 85 AC FE FF FF 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? - ?? ?? ?? FF D2 8B 45 ?? 50 8B 4D ?? 8B 51 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 74 2E 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 3D ?? ?? ?? ?? 74 0E 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 89 - 45 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 8B E5 5D C3 - } - $v20_1_encrypt_file_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 56 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 99 05 00 00 8B 45 ?? - 83 38 ?? 74 1B 8B 4D ?? 83 79 ?? ?? 74 12 8B 55 ?? 83 7A ?? ?? 74 09 8B 45 ?? 83 78 ?? ?? 75 08 8B 45 ?? E9 6E 05 00 00 - 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 89 45 ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? - ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 F4 04 00 00 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8B - 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 74 07 C7 45 ?? ?? ?? ?? ?? 66 0F 57 C0 66 0F 13 45 ?? 8D 45 ?? 50 - 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 E7 03 00 00 66 0F 57 C0 66 0F 13 85 ?? ?? ?? ?? 6A ?? 6A ?? - 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 F8 ?? 0F 84 AF 03 00 00 - 8D 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 97 03 00 00 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B - 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 0F 84 6A 03 00 00 C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 2C 03 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? 8D 45 ?? 50 8D 4D ?? 51 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 D9 02 00 00 - } - $v20_1_encrypt_file_2 = { - C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 8B 48 ?? 51 8B 55 ?? - 8B 02 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 81 02 00 00 C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 8B 42 ?? 50 8B - 4D ?? 8B 51 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 0F 84 41 02 00 00 8B 55 ?? 8B 45 ?? 3B 42 ?? - 0F 85 32 02 00 00 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 0F - 84 0B 02 00 00 8B 45 ?? 3B 45 ?? 0F 85 FF 01 00 00 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 C7 45 ?? ?? ?? ?? - ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 CE 01 00 00 66 0F 57 C0 66 0F 13 45 ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 3B 4D ?? 75 0C 8B 55 ?? 3B 55 ?? 0F 84 73 01 00 00 C7 45 ?? ?? - ?? ?? ?? 8B 45 ?? 33 C9 8B 55 ?? 2B 55 ?? 8B 75 ?? 1B 75 ?? 89 85 ?? ?? ?? ?? 89 4D ?? 89 55 ?? 89 75 ?? 8B 45 ?? 3B 45 - ?? 77 1A 72 0B 8B 8D ?? ?? ?? ?? 3B 4D ?? 73 0D 8B 55 ?? 33 C0 89 55 ?? 89 45 ?? EB 12 8B 4D ?? 2B 4D ?? 8B 55 ?? 1B 55 - ?? 89 4D ?? 89 55 ?? 8B 45 ?? 89 45 ?? 8B 4D ?? 33 D2 03 4D ?? 13 55 ?? 89 8D ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 3B 45 ?? 75 12 8B 8D ?? ?? ?? ?? 3B 4D ?? 75 07 C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B - } - $v20_1_encrypt_file_3 = { - 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 85 C0 0F 84 A2 00 00 00 8B 4D ?? 3B 4D ?? 0F 85 96 00 00 00 C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 74 60 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF - D1 85 C0 74 31 8B 55 ?? 3B 55 ?? 75 29 8B 45 ?? 33 C9 03 45 ?? 13 4D ?? 89 45 ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? - 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 75 02 EB 0D 83 7D ?? ?? 74 02 - EB 05 E9 79 FE FF FF 83 7D ?? ?? 74 17 8B 55 ?? 3B 55 ?? 75 0F 8B 45 ?? 3B 45 ?? 75 07 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 51 - E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? - ?? 8B 90 ?? ?? ?? ?? FF D2 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? - ?? ?? ?? FF D0 83 7D ?? ?? 74 0C 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 - 83 7D ?? ?? 75 22 6A ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 85 C0 75 07 C7 45 ?? ?? ?? ?? ?? - 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 74 60 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 74 37 8D 95 ?? ?? ?? ?? 52 8D 85 - ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 - ?? ?? ?? ?? FF D2 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 ?? 5E 8B E5 5D C3 - } - $v30_1_encrypt_file_1 = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 02 05 00 00 8B 45 ?? 83 38 ?? 74 - 09 8B 4D ?? 83 79 ?? ?? 75 08 8B 45 ?? E9 E9 04 00 00 C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? - FF D0 89 45 ?? 6A ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B - 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 0F 84 6F 04 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 0F 85 90 03 00 00 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 83 F8 ?? 0F 84 70 03 - 00 00 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 0F 84 50 03 00 00 8D 55 ?? 52 8B 45 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 38 03 00 00 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? - ?? ?? 8B 90 ?? ?? ?? ?? FF D2 89 45 ?? 83 7D ?? ?? 0F 84 04 03 00 00 6A ?? 6A ?? 8B 45 ?? 8B 48 ?? 51 8B 55 ?? 52 E8 ?? - ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 F8 ?? 0F 84 CC 02 00 00 8B 4D ?? 3B 4D ?? 73 08 8B 55 ?? 89 55 ?? EB 06 8B 45 ?? 89 - 45 ?? 8B 4D ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 6A ?? 6A ?? 8B 45 ?? 8B 08 51 E8 ?? ?? ?? - ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 0F 84 73 01 00 00 8B 45 ?? 8B 48 ?? 83 E9 ?? 89 4D ?? 8B 55 ?? D1 E2 89 55 ?? 8B 45 ?? - } - $v30_1_encrypt_file_2 = { - 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 35 01 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 2B 4D ?? 39 4D ?? 73 08 8B 55 ?? 89 55 ?? EB 09 8B 45 ?? 2B 45 ?? 89 45 ?? 8B 4D - ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? - FF D0 85 C0 0F 84 94 00 00 00 8B 4D ?? 3B 4D ?? 0F 85 88 00 00 00 8B 55 ?? 3B 55 ?? 73 07 C7 45 ?? ?? ?? ?? ?? 83 7D ?? - ?? 74 73 8B 45 ?? 89 45 ?? 8B 4D ?? 51 8D 55 ?? 52 8B 45 ?? 50 6A ?? 8B 4D ?? 51 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 - ?? ?? ?? ?? FF D0 85 C0 74 44 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF - D2 85 C0 74 21 8B 45 ?? 3B 45 ?? 75 19 8B 4D ?? 03 4D ?? 89 4D ?? 8B 55 ?? 03 55 ?? 89 55 ?? C7 45 ?? ?? ?? ?? ?? 83 7D - ?? ?? 74 06 83 7D ?? ?? 74 02 EB 0C 8B 45 ?? 3B 45 ?? 0F 85 FB FE FF FF 8B 4D ?? 3B 4D ?? 75 07 C7 45 ?? ?? ?? ?? ?? 8B - 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 83 7D ?? ?? 0F 85 02 01 00 00 C7 45 - ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 F8 ?? 0F 84 DB 00 00 00 6A ?? 8D - 4D ?? 51 8B 55 ?? 8B 42 ?? 50 8B 4D ?? 8B 51 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 0F 84 AE 00 - } - $v30_1_encrypt_file_3 = { - 00 00 8B 55 ?? 8B 45 ?? 3B 42 ?? 0F 85 9F 00 00 00 6A ?? 8D 4D ?? 51 6A ?? 8D 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 - ?? ?? ?? ?? FF D1 85 C0 74 7E 83 7D ?? ?? 75 78 8B 55 ?? 3B 55 ?? 74 1B 8B 45 ?? 8B 4D ?? 03 48 ?? 89 4D ?? 8B 55 ?? 2B - 55 ?? 89 55 ?? 8B 45 ?? 89 45 ?? 6A ?? 8D 4D ?? 51 6A ?? 8D 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 - 85 C0 74 34 83 7D ?? ?? 75 2E 6A ?? 8D 55 ?? 52 6A ?? 8D 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 - C0 74 0D 83 7D ?? ?? 75 07 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 EB 07 C7 45 ?? ?? ?? - ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 7D ?? ?? 75 71 83 7D ?? ?? 75 28 83 7D ?? ?? 75 22 68 ?? ?? - ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 07 C7 45 ?? ?? ?? ?? ?? EB 43 83 7D ?? ?? 74 36 83 7D ?? - ?? 74 30 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 - 74 07 C7 45 ?? ?? ?? ?? ?? EB 07 C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? EB 07 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 8B 45 ?? 8B E5 5D C3 - } - $v30_2_encrypt_file_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 56 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 06 83 7D ?? ?? 75 08 8B 45 ?? E9 BF 05 00 00 8B 45 ?? - 83 38 ?? 74 1B 8B 4D ?? 83 79 ?? ?? 74 12 8B 55 ?? 83 7A ?? ?? 74 09 8B 45 ?? 83 78 ?? ?? 75 08 8B 45 ?? E9 94 05 00 00 - 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 89 45 ?? 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 C7 - 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? - ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 1A 05 00 00 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8B - 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 74 07 C7 45 ?? ?? ?? ?? ?? 66 0F 57 C0 66 0F 13 45 ?? 8D 45 ?? 50 - 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 0D 04 00 00 66 0F 57 C0 66 0F 13 85 ?? ?? ?? ?? 6A ?? 6A ?? - 8B 85 ?? ?? ?? ?? 50 8B 8D ?? ?? ?? ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 F8 ?? 0F 84 D5 03 00 00 - 8D 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 BD 03 00 00 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B - 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 0F 84 90 03 00 00 C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 52 03 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? 8D 45 ?? 50 8D 4D ?? 51 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 FF 02 00 00 - } - $v30_2_encrypt_file_2 = { - C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 8B 48 ?? 51 8B 55 ?? - 8B 02 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 A7 02 00 00 C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 8B 55 ?? 8B 42 ?? 50 8B - 4D ?? 8B 51 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 0F 84 67 02 00 00 8B 55 ?? 8B 45 ?? 3B 42 ?? - 0F 85 58 02 00 00 6A ?? 8D 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 0F - 84 31 02 00 00 8B 45 ?? 3B 45 ?? 0F 85 25 02 00 00 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 C7 45 ?? ?? ?? ?? - ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 F4 01 00 00 66 0F 57 C0 66 0F 13 45 ?? C7 45 ?? ?? ?? - ?? ?? 66 0F 57 C0 66 0F 13 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 3B 4D ?? 75 0C 8B 55 ?? 3B 55 ?? 0F - 84 90 01 00 00 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 33 C9 8B 55 ?? 2B 55 ?? 8B 75 ?? 1B 75 ?? 89 85 ?? ?? ?? ?? 89 8D ?? ?? ?? - ?? 89 95 ?? ?? ?? ?? 89 75 ?? 8B 85 ?? ?? ?? ?? 3B 45 ?? 77 1D 72 0E 8B 8D ?? ?? ?? ?? 3B 8D ?? ?? ?? ?? 73 0D 8B 55 ?? - 33 C0 89 55 ?? 89 45 ?? EB 12 8B 4D ?? 2B 4D ?? 8B 55 ?? 1B 55 ?? 89 4D ?? 89 55 ?? 8B 45 ?? 89 45 ?? 8B 4D ?? 33 D2 03 - 4D ?? 13 55 ?? 89 8D ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B 45 ?? 75 12 8B 8D ?? ?? ?? ?? 3B 4D ?? 75 07 C7 - 45 ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 85 C0 0F - 84 B3 00 00 00 8B 4D ?? 3B 4D ?? 0F 85 A7 00 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 8B - } - $v30_2_encrypt_file_3 = { - 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 71 6A ?? 8D 45 ?? 50 8B 4D ?? - 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 74 42 8B 55 ?? 3B 55 ?? 75 3A 8B 45 ?? 33 C9 03 - 45 ?? 13 4D ?? 89 45 ?? 89 4D ?? C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 33 C0 03 55 ?? 13 45 ?? 89 55 ?? 89 45 ?? 8B 4D ?? 51 E8 - ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 75 02 EB 0D 83 7D ?? ?? 74 02 EB 05 - E9 5C FE FF FF 83 7D ?? ?? 74 17 8B 4D ?? 3B 4D ?? 75 0F 8B 55 ?? 3B 55 ?? 75 07 C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B - 88 ?? ?? ?? ?? FF D1 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? - ?? FF D2 83 7D ?? ?? 74 0C 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 83 7D - ?? ?? 75 22 6A ?? 8B 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 75 07 C7 45 ?? ?? ?? ?? ?? 8B 45 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 74 60 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? - ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 74 37 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? - ?? ?? 52 8D 85 ?? ?? ?? ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? - ?? ?? FF D1 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 8B 45 ?? 5E 8B E5 5D C3 - } - $v30_3_encrypt_file_1 = { - 55 8B EC 83 EC ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 75 08 8B 45 ?? E9 48 04 00 00 83 7D ?? ?? 75 08 8B 45 ?? E9 3A 04 00 - 00 8B 45 ?? 83 78 ?? ?? 74 11 8B 4D ?? 83 39 ?? 74 09 8B 55 ?? 83 7A ?? ?? 75 08 8B 45 ?? E9 18 04 00 00 C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 6A ?? 8B 55 - ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B - 90 ?? ?? ?? ?? FF D2 89 45 ?? 83 7D ?? ?? 0F 84 90 03 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 0F 84 - 83 00 00 00 8B 45 ?? 8B 48 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 74 6B 6A ?? 8D 55 ?? 52 8B 45 ?? 8B 48 ?? - 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 74 39 8B 55 ?? 3B 15 ?? ?? ?? ?? 75 2E 8B 45 ?? - 8B 48 ?? 51 8B 55 ?? 8B 42 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 50 ?? FF D2 85 C0 75 0E C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 7D ?? ?? 0F 84 9A 02 00 00 6A ?? 6A ?? 6A ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? - 8B 90 ?? ?? ?? ?? FF D2 6A ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 89 45 ?? 83 7D ?? ?? 0F 84 63 02 00 00 - 8B 55 ?? 3B 55 ?? 0F 87 57 02 00 00 8D 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 3F 02 00 00 6A ?? 6A - } - $v30_3_encrypt_file_2 = { - 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 89 45 ?? 83 7D ?? ?? 0F 84 0B 02 00 - 00 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 81 E1 ?? ?? ?? ?? 74 1C 6A ?? 6A ?? 8B 15 ?? ?? ?? ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B - 88 ?? ?? ?? ?? FF D1 C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? - FF D0 85 C0 0F 84 52 01 00 00 C7 45 ?? ?? ?? ?? ?? 8D 4D ?? 51 6A ?? 6A ?? 8B 55 ?? 8B 02 50 8B 4D ?? 8B 51 ?? 52 8B 45 - ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 0F 84 0A 01 00 00 8B 55 ?? 8B 42 ?? 83 E8 ?? 89 45 ?? 8B 4D ?? D1 E1 - 89 4D ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? 83 7D ?? ?? 0F 84 CC 00 00 00 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 85 C0 74 76 8B 55 ?? - 3B 55 ?? 73 07 C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 74 5F 8B 45 ?? 50 8D 4D ?? 51 8B 55 ?? 52 6A ?? 8B 45 ?? 50 6A ?? 8B 4D - ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 85 C0 74 21 6A ?? 8D 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 8B 45 ?? 50 E8 ?? ?? - ?? ?? 8B 88 ?? ?? ?? ?? FF D1 EB 15 83 7D ?? ?? 74 0D 83 7D ?? ?? 74 07 C7 45 ?? ?? ?? ?? ?? EB 0E EB 02 EB 0A 83 7D ?? - ?? 0F 84 54 FF FF FF 83 7D ?? ?? 74 07 C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 50 E8 ?? ?? ?? - } - $v30_3_encrypt_file_3 = { - ?? 8B 88 ?? ?? ?? ?? FF D1 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 83 7D ?? ?? 75 47 8B 4D ?? 81 E1 ?? - ?? ?? ?? 74 3C 6A ?? 6A ?? 6A ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 6A ?? 8D 4D ?? 51 8B 55 ?? 8B 42 ?? - 50 8B 4D ?? 8B 51 ?? 52 8B 45 ?? 50 E8 ?? ?? ?? ?? 8B 88 ?? ?? ?? ?? FF D1 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? - FF D0 EB 07 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 51 E8 ?? ?? ?? ?? 8B 90 ?? ?? ?? ?? FF D2 83 7D ?? ?? 75 20 68 ?? ?? ?? ?? 8B - 45 ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 07 C7 45 ?? ?? ?? ?? ?? 8B 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? EB 07 C7 45 ?? ?? ?? ?? ?? 8B 4D ?? 51 8B 55 ?? 52 E8 ?? ?? ?? ?? 8B 80 ?? ?? ?? ?? FF D0 - 8B 45 ?? 8B E5 5D C3 - } + $a = { 00 6C 72 00 00 50 E8 4E 0C 00 00 EB 0E 5A 58 59 97 60 8A 54 } condition: - uint16(0)==0x5A4D and ((($v30_entrypoint at pe.entry_point) and $v30_api_load and $v30_calculate_hash and $v30_dll_load and $v30_1_find_file_1 and $v30_1_find_file_2 and $v30_1_encrypt_file_1 and $v30_1_encrypt_file_2 and $v30_1_encrypt_file_3) or (($v30_entrypoint at pe.entry_point) and $v30_api_load and $v30_calculate_hash and $v30_dll_load and $v30_2_find_file_1 and $v30_2_find_file_2 and $v30_2_encrypt_file_1 and $v30_2_encrypt_file_2 and $v30_2_encrypt_file_3) or (($v20_entrypoint at pe.entry_point) and $v30_api_load and $v30_calculate_hash and $v30_dll_load and $v30_2_find_file_1 and $v30_2_find_file_2 and $v20_1_encrypt_file_1 and $v20_1_encrypt_file_2 and $v20_1_encrypt_file_3) or (($v30_entrypoint at pe.entry_point) and $v30_api_load and $v30_calculate_hash and $v30_dll_load and $v30_3_find_file_1 and $v30_3_find_file_2 and $v30_3_encrypt_file_1 and $v30_3_encrypt_file_2 and $v30_3_encrypt_file_3)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Makop : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_E3E6D768 : FILE MEMORY { meta: - description = "Yara rule that detects Makop ransomware." - author = "ReversingLabs" - id = "9b7d42f3-0417-5228-8b25-244224cbc414" - date = "2020-10-30" - modified = "2020-10-30" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Makop.yara#L1-L99" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0ff4739d32b4a775d07a5f22d551ed67025681d4986e4404c9a01ad4078468f3" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "e3e6d768-6510-4eb2-a5ec-8cb8eead13f2" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L696-L714" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b505cb26d3ead5a0ef82d2c87a9b352cc0268ef0571f5e28defca7131065545e" + logic_hash = "b848c7200f405d77553d661a6c49fb958df225875957ead35b35091995f307d1" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Makop" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "ce11f9c038c31440bcdf7f9d194d1a82be5d283b875cc6170a140c398747ff8c" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files_p1 = { - 8D 54 24 ?? 52 56 FF 15 ?? ?? ?? ?? 56 8B F8 6A ?? 89 7C 24 ?? FF 15 ?? ?? ?? ?? 50 - FF 15 ?? ?? ?? ?? 83 FF ?? 75 ?? 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 5F 5E 5B 8B E5 5D C3 33 F6 89 74 24 ?? EB ?? 8D A4 24 ?? ?? ?? ?? 8D 64 24 ?? - 66 8B 44 24 ?? 66 85 C0 0F 84 ?? ?? ?? ?? 66 3D ?? ?? 75 ?? 66 8B 44 24 ?? 66 85 C0 - 0F 84 ?? ?? ?? ?? 66 3D ?? ?? 75 ?? 66 83 7C 24 ?? ?? 0F 84 ?? ?? ?? ?? 8D 44 24 ?? - EB ?? 8D 9B ?? ?? ?? ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 8D 54 24 ?? 2B C2 D1 F8 83 - E8 ?? 85 F6 8B F8 89 7C 24 ?? 75 ?? 8B 45 ?? 05 ?? ?? ?? ?? 03 C0 0F 84 ?? ?? ?? ?? - 50 56 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 89 44 24 ?? 8B F0 0F 84 ?? ?? ?? - ?? F6 44 24 ?? ?? 0F 84 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 38 85 FF 74 ?? 8B 1F 8D 54 24 - ?? 8B CA 2B D9 8D 49 ?? 0F B7 04 13 66 3D ?? ?? 72 ?? 66 3D ?? ?? 77 ?? 83 C0 ?? 0F - B7 C8 0F B7 02 66 3D ?? ?? 72 ?? 66 3D ?? ?? 77 ?? 83 C0 ?? 83 C2 ?? 66 85 C9 0F B7 - C0 74 ?? 66 3B C8 74 ?? 0F B7 D0 0F B7 C1 2B C2 0F 84 ?? ?? ?? ?? 8B 7F ?? 85 FF 75 - ?? 8B 7D ?? 8B 55 ?? 81 C7 ?? ?? ?? ?? 8B DE E8 ?? ?? ?? ?? 8B 4D ?? 8D 5C 4E ?? BA - ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 1C 56 8D 54 24 ?? BF ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4D ?? 8D 54 08 ?? 8B 45 ?? 52 56 50 E8 - } - $find_files_p2 = { - 83 C4 ?? E9 ?? ?? ?? ?? 8D 5C 24 ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 8B 4D ?? - 80 79 ?? ?? 0F 85 ?? ?? ?? ?? 8B 55 ?? 03 FA 81 FF ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? 8B - 15 ?? ?? ?? ?? C6 44 24 ?? ?? 8B 7D ?? 81 C7 ?? ?? ?? ?? 8B DE E8 ?? ?? ?? ?? 8A 44 - 24 ?? 84 C0 75 ?? 8B 55 ?? 83 C7 ?? 8D 5E ?? E8 ?? ?? ?? ?? 8A 44 24 ?? 8A C8 8B 54 - 24 ?? F6 D9 1B C9 83 E1 ?? F6 D8 8B F1 8D BE ?? ?? ?? ?? 1B C0 83 E0 ?? 83 C0 ?? 03 - 45 ?? 8D 04 42 89 44 24 ?? 8D 58 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 5C 24 ?? 8D BE - ?? ?? ?? ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 8B 54 24 ?? 85 D2 8B 74 24 ?? 8B 45 ?? 77 ?? - 3B 70 ?? 77 ?? B1 ?? EB ?? 8B 55 ?? C6 44 24 ?? ?? E9 ?? ?? ?? ?? 32 C9 88 48 ?? 8B - 4C 24 ?? F6 C1 ?? 74 ?? C6 40 ?? ?? 89 48 ?? EB ?? C6 40 ?? ?? 50 89 50 ?? 89 70 ?? - 8B 44 24 ?? 50 E8 ?? ?? ?? ?? 8B 74 24 ?? 83 C4 ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? - 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 54 24 ?? 8D 4C 24 ?? 51 52 FF 15 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? EB ?? C7 44 24 ?? ?? ?? ?? ?? 8B 74 24 ?? EB ?? 56 6A ?? FF 15 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 50 FF 15 ?? ?? ?? ?? 56 6A ?? FF 15 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 - } - $encrypt_files = { - 8B 50 ?? 8B 00 83 EC ?? 55 8B 2D ?? ?? ?? ?? 56 57 6A ?? 8B F9 8D 4C 24 ?? 51 52 50 - 53 FF D5 85 C0 0F 84 ?? ?? ?? ?? 8B 57 ?? 8B 47 ?? 33 F6 56 8D 4C 24 ?? 51 52 50 53 - FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 75 ?? B0 ?? 5F 5E 5D 83 - C4 ?? C3 3B 47 ?? 73 ?? 8B C8 83 E1 ?? 74 ?? BE ?? ?? ?? ?? 2B F1 8B 4F ?? 56 03 C8 - 6A ?? 51 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 8B 4F ?? 03 C6 50 8D 54 24 ?? 52 51 6A - ?? 6A ?? 89 44 24 ?? 8B 44 24 ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 8B 4C 24 ?? 8B 54 24 ?? 6A ?? 6A ?? 51 52 53 FF D5 85 C0 74 ?? 8B 4C 24 ?? 8B 57 ?? - 8B 3D ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 03 CE 51 52 53 FF D7 85 C0 74 ?? 8B 44 24 ?? - 8D 0C 30 8B 44 24 ?? 3B C1 72 ?? 01 44 24 ?? 8B 44 24 ?? 8B 50 ?? 8B 00 83 54 24 ?? - ?? 6A ?? 6A ?? 52 50 53 FF D5 85 C0 74 ?? 6A ?? 8D 4C 24 ?? 51 6A ?? 8D 54 24 ?? 52 - 53 FF D7 85 C0 74 ?? 83 7C 24 ?? ?? 0F 83 ?? ?? ?? ?? 5F 5E 32 C0 5D 83 C4 ?? C3 - } - $enum_network_resources = { - 55 8B EC 83 E4 ?? 83 EC ?? 53 56 57 68 ?? ?? ?? ?? 6A ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 8B F0 85 F6 89 74 24 ?? 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 7D ?? 8D 44 24 ?? 50 51 6A ?? - 6A ?? 57 E8 ?? ?? ?? ?? 85 C0 74 ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B - 7D ?? 68 ?? ?? ?? ?? 6A ?? 56 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 8D 54 24 ?? 52 56 8D 44 24 ?? 50 51 E8 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 85 C0 75 ?? 8B 54 24 ?? 8B 45 ?? 52 50 EB ?? 8B 4C 24 - ?? 8B 50 ?? 51 52 E8 ?? ?? ?? ?? 33 DB 83 C4 ?? 39 5C 24 ?? 76 ?? 83 C6 ?? 8D 49 ?? - 8B 46 ?? 85 C0 8B C8 75 ?? B9 ?? ?? ?? ?? 8B 46 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 51 8B - 0E 51 50 E8 ?? ?? ?? ?? 8B 46 ?? 83 C4 ?? A8 ?? 74 ?? 8B 56 ?? 85 D2 74 ?? 85 FF 7E - ?? 8B 45 ?? 85 C0 74 ?? 8B 40 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 55 ?? 8B 4D ?? 52 83 - EF ?? 57 8D 46 ?? 50 51 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? F6 06 ?? 74 ?? 50 E8 ?? ?? ?? - ?? 8B 56 ?? 8B 45 ?? 83 C4 ?? 52 50 E8 ?? ?? ?? ?? 83 C3 ?? 83 C6 ?? 3B 5C 24 ?? 0F - 82 ?? ?? ?? ?? 8B 74 24 ?? E9 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 8B 44 24 ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 56 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 - } + $a = { 7E 14 48 89 DF 48 63 C8 4C 89 E6 FC F3 A4 41 01 C5 48 89 FB } condition: - uint16(0)==0x5A4D and ($enum_network_resources) and ( all of ($find_files_p*)) and ($encrypt_files) + all of them } -rule REVERSINGLABS_Win64_Ransomware_Redroman : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_520Deeb8 : FILE MEMORY { meta: - description = "Yara rule that detects RedRoman ransomware." - author = "ReversingLabs" - id = "c860586a-fa50-5bb4-a3b4-13506f9d6030" - date = "2021-05-10" - modified = "2021-05-10" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.RedRoman.yara#L1-L82" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6fb2ac0e7f7ac095766e27c057e5124406dc493c08d01a7e5381403d794c7240" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "520deeb8-cbc0-4225-8d23-adba5e040471" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L716-L733" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "671c17835f30cce1e5d68dbf3a73d340069b1b55a2ac42fc132c008cb2da622e" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "RedRoman" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? - ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? - ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 48 89 44 24 ?? 4C 8D 8C 24 ?? ?? ?? ?? 41 B8 ?? ?? - ?? ?? BA ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 48 C7 84 - 24 ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 85 C0 75 ?? 33 D2 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 8D 84 24 ?? ?? - ?? ?? 48 89 44 24 ?? 41 B9 ?? ?? ?? ?? 45 33 C0 BA ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 6B C9 ?? 48 89 84 0C ?? ?? ?? ?? 48 C7 84 24 - ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 85 C0 75 ?? B8 ?? ?? ?? ?? 48 6B C0 ?? 48 83 BC 04 ?? - ?? ?? ?? ?? 74 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 48 89 84 - 24 ?? ?? ?? ?? EB ?? 33 D2 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? - E9 ?? ?? ?? ?? 33 D2 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B 49 ?? 48 89 01 48 8B 44 24 ?? 48 8B - 40 ?? 48 83 38 ?? 75 ?? 48 8D 15 ?? ?? ?? ?? 48 8B 4C 24 ?? E8 ?? ?? ?? ?? B8 ?? ?? - ?? ?? 48 6B C0 ?? 48 83 BC 04 ?? ?? ?? ?? ?? 74 ?? B8 ?? ?? ?? ?? 48 6B C0 ?? 48 8B - 8C 04 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? B8 - } - $encrypt_files_p2 = { - 4C 8D 05 ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? 48 8B 4D ?? 48 8B 55 ?? E8 ?? ?? ?? ?? 48 89 - 55 ?? 48 89 45 ?? EB ?? 31 C0 41 89 C0 48 8B 4D ?? 48 8B 55 ?? E8 ?? ?? ?? ?? 48 89 - 45 ?? EB ?? 48 8B 45 ?? 48 83 F8 ?? 74 ?? 48 8B 55 ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? EB ?? EB ?? 48 81 C4 ?? ?? ?? ?? 5D C3 48 8D 4D ?? E8 ?? ?? ?? ?? EB ?? 48 8B - 85 ?? ?? ?? ?? 48 85 C0 74 ?? EB ?? EB ?? 0F 0B 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? - ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? - ?? ?? C6 85 ?? ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? - ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? - ?? ?? ?? 0F 84 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? - 48 89 85 ?? ?? ?? ?? 48 89 8D ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? - 48 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 85 - C0 74 ?? EB ?? EB ?? 0F 0B 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? - ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? - ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? - ?? ?? 48 89 85 ?? ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E9 ?? ?? ?? ?? - 48 8B 85 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 89 8D - } - $find_files = { - 48 8D 9C 24 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 D9 31 D2 E8 ?? ?? ?? ?? 48 8B 0F 48 - 89 DA E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 4C 8D B4 24 ?? ?? ?? ?? 48 8D 9C 24 ?? - ?? ?? ?? 66 83 BC 24 ?? ?? 00 00 ?? 74 ?? EB ?? 0F 1F 84 00 ?? ?? ?? ?? 48 8B 0F 48 - 89 DA E8 ?? ?? ?? ?? 85 C0 74 ?? 66 83 BC 24 ?? ?? 00 00 ?? 75 ?? 0F B7 84 24 ?? ?? - ?? ?? 66 85 C0 74 ?? 66 83 F8 ?? 75 ?? 66 83 BC 24 ?? ?? 00 00 ?? 74 ?? 48 8B 47 ?? - F0 48 83 00 ?? 0F 8E ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 41 - B8 ?? ?? ?? ?? 4C 89 F1 E8 ?? ?? ?? ?? 48 C7 06 ?? ?? ?? ?? 48 8D 4E ?? 48 8D 94 24 - ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 48 - C7 06 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? 48 C7 06 ?? ?? ?? ?? C6 46 ?? ?? 89 46 ?? 48 - 89 F0 0F 28 B5 ?? ?? ?? ?? 0F 28 BD ?? ?? ?? ?? 44 0F 28 85 ?? ?? ?? ?? 44 0F 28 8D - ?? ?? ?? ?? 44 0F 28 95 ?? ?? ?? ?? 44 0F 28 9D ?? ?? ?? ?? 44 0F 28 A5 ?? ?? ?? ?? - 44 0F 28 AD ?? ?? ?? ?? 44 0F 28 B5 ?? ?? ?? ?? 44 0F 28 BD ?? ?? ?? ?? 48 8D A5 ?? - ?? ?? ?? 5B 5F 5E 41 5E 5D C3 0F 0B - } + $a = { ED 48 89 44 24 30 44 89 6C 24 10 7E 47 48 89 C1 44 89 E8 44 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Torrentlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_77137320 : FILE MEMORY { meta: - description = "Yara rule that detects TorrentLocker ransomware." - author = "ReversingLabs" - id = "64bdb0db-ea0c-5a0d-9d3e-db1df86c132b" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.TorrentLocker.yara#L1-L98" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "f1aa523fa95e142b7e421286d26918e3da4bd3e268fef3f98f00820296291bfc" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "77137320-6c7e-4bb8-81a4-bd422049c309" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L735-L753" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "91642663793bdda93928597ff1ac6087e4c1e5d020a8f40f2140e9471ab730f9" + logic_hash = "ee48e0478845a61dbbdb5cc3ee5194eb272fcf6dcf139381f068c9af1557d0d4" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "TorrentLocker" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "afeedf7fb287320c70a2889f43bc36a3047528204e1de45c4ac07898187d136b" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $tlocker_ep = { - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 05 E8 ?? ?? ?? ?? 33 C0 C3 - } - $tlocker_contact_server_1 = { - 55 8B EC 83 EC ?? 8D 45 ?? 50 8D 4D ?? 51 B8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 21 83 7D - ?? ?? 8B 45 ?? 75 05 8B 10 89 55 ?? 85 C0 74 0F 50 A1 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 53 56 57 8D 9B ?? ?? ?? ?? - 8B 4D ?? 8D 55 ?? 52 6A ?? BB ?? ?? ?? ?? 89 4D ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 89 75 ?? 85 F6 0F 84 2C 01 00 00 8B BE - ?? ?? ?? ?? 81 C7 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 85 DB 0F 84 EB 00 00 00 6A ?? 68 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 89 00 00 00 8D 45 ?? 50 8D - 4D ?? 51 6A ?? 56 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 16 81 4D ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 6A ?? 56 FF - 15 ?? ?? ?? ?? 8B 45 ?? 57 50 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 38 6A ?? 8D 4D ?? 51 8D 55 ?? 52 68 ?? ?? ?? ?? - 56 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 10 81 7D ?? ?? ?? ?? ?? 75 07 C7 45 ?? ?? ?? ?? - ?? 8B 3D ?? ?? ?? ?? 56 FF D7 EB 06 8B 3D ?? ?? ?? ?? 8D 45 ?? 50 8D 4D ?? 51 6A ?? 53 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 53 8B F0 FF D7 85 F6 74 06 8B 55 ?? 52 FF D7 8B 75 ?? 8B 0D ?? ?? ?? ?? 33 C0 83 7D ?? ?? 56 - 0F 94 C0 6A ?? 51 8B F8 FF 15 ?? ?? ?? ?? 85 FF 75 10 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E9 9E FE FF FF 5F 5E 5B 8B E5 5D - C3 - } - $tlocker_contact_server_2_1 = { - 55 8B EC 83 EC ?? 8D 45 ?? 50 8D 4D ?? 51 B8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 21 83 7D - ?? ?? 8B 45 ?? 75 05 8B 10 89 55 ?? 85 C0 74 0F 50 A1 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? 53 56 57 8D 9B ?? ?? ?? ?? - 8B 4D ?? 8D 55 ?? 52 6A ?? BF ?? ?? ?? ?? 89 4D ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 89 75 ?? 85 F6 0F 84 E5 01 00 00 BF ?? - ?? ?? ?? 39 3D ?? ?? ?? ?? 74 11 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B - 9E ?? ?? ?? ?? 81 C3 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 85 FF 0F 84 EB 00 00 00 6A ?? 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 89 00 00 00 8D 45 ?? 50 - 8D 4D ?? 51 6A ?? 56 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 16 81 4D ?? ?? ?? ?? ?? 6A ?? 8D 55 ?? 52 6A ?? 56 - FF 15 ?? ?? ?? ?? 8B 45 ?? 53 50 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 38 6A ?? 8D 4D ?? 51 8D 55 ?? 52 68 ?? ?? ?? - ?? 56 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 10 81 7D ?? ?? ?? ?? ?? 75 07 C7 45 ?? ?? ?? - ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 EB 06 8B 35 ?? ?? ?? ?? 8D 45 ?? 50 8D 4D ?? 51 6A ?? 57 C7 45 ?? ?? ?? ?? ?? C7 45 ?? - } - $tlocker_contact_server_2_2 = { - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 57 8B D8 FF D6 85 DB 74 06 8B 55 ?? 52 FF D6 8B 75 ?? 33 C0 83 7D ?? ?? 0F 94 C0 8B F8 85 - FF 74 18 8B 0D ?? ?? ?? ?? 89 0D ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? EB 5E 8B 15 ?? ?? ?? ?? 3B 15 ?? ?? ?? ?? 75 - 34 FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B D1 41 89 0D ?? ?? ?? ?? 85 D2 7E 71 8B 0D ?? ?? ?? ?? 3B C1 73 08 8B C8 89 0D - ?? ?? ?? ?? 2B C1 3D ?? ?? ?? ?? 72 1C A1 ?? ?? ?? ?? 40 83 F8 ?? 7E 05 A1 ?? ?? ?? ?? 8B C8 A3 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 81 3D ?? ?? ?? ?? ?? ?? ?? ?? 75 0B 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 56 6A ?? 50 FF 15 ?? ?? ?? ?? 85 - FF 75 17 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E9 E5 FD FF FF A3 ?? ?? ?? ?? EB BF 5F 5E 5B 8B E5 5D C3 - } - $tlocker_get_server_data = { - 55 8B EC 83 EC ?? 56 57 33 FF 57 57 8D 45 ?? 50 53 33 F6 FF 15 ?? ?? ?? ?? 85 C0 74 77 8D 49 ?? 8B 4D ?? 03 CF 85 F6 75 - 73 33 C0 85 C9 74 0F 8B 15 ?? ?? ?? ?? 51 50 52 FF 15 ?? ?? ?? ?? 33 C9 85 C0 0F 95 C1 8B F0 8B C1 85 C0 74 33 8B 55 ?? - 8D 4D ?? 51 52 8D 04 37 50 53 FF 15 ?? ?? ?? ?? 85 C0 74 1C 8B 45 ?? 85 C0 74 ?? 6A ?? 6A ?? 8D 4D ?? 51 53 03 F8 FF 15 - ?? ?? ?? ?? 85 C0 75 A0 85 F6 74 10 8B 0D ?? ?? ?? ?? 56 6A ?? 51 FF 15 ?? ?? ?? ?? 5F 33 C0 5E 8B E5 5D C3 - } - $tlocker_remove_shadow_copies = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? A1 ?? ?? ?? ?? 53 57 6A ?? 33 FF 57 50 FF 15 ?? ?? ?? ?? 8B D8 - 3B DF 0F 84 DC 00 00 00 56 8D B5 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 0A C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 3D ?? ?? ?? ?? 73 5E B8 ?? ?? ?? ?? 8B D3 2B D0 0F B7 08 66 89 0C - 02 83 C0 ?? 66 3B CF 75 F1 6A ?? 8D 95 ?? ?? ?? ?? 57 52 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? - 51 8D 95 ?? ?? ?? ?? 52 57 68 ?? ?? ?? ?? 57 57 57 53 57 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 0F FF - 15 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 8B F8 83 BD ?? ?? ?? ?? ?? 74 0B 8B B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 53 - 6A ?? 50 FF 15 ?? ?? ?? ?? 5E 8B C7 5F 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 4D ?? 5F 33 CD B8 ?? ?? ?? ?? 5B - E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $tlocker_find_files = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 0D ?? ?? ?? ?? 8B 45 ?? 53 56 57 68 ?? ?? ?? ?? 33 F6 56 51 - 89 85 ?? ?? ?? ?? 89 B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 85 DB 0F 84 AD 01 00 00 53 56 56 6A ?? 56 FF 15 ?? ?? ?? ?? - 85 C0 0F 88 89 01 00 00 68 ?? ?? ?? ?? 53 53 FF 15 ?? ?? ?? ?? 8B C3 8D 50 ?? 8D 9B ?? ?? ?? ?? 66 8B 08 83 C0 ?? 66 85 - C9 75 F5 2B C2 D1 F8 8B F8 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 85 C0 0F 84 4D 01 00 00 8D 95 ?? ?? ?? ?? 52 50 FF 15 ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? 85 C0 0F 84 15 01 00 00 F6 85 ?? ?? ?? ?? ?? 0F 84 EC 00 00 00 B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 66 8B 10 66 3B 11 75 1E 66 85 D2 74 15 66 8B 50 ?? 66 3B 51 ?? 75 0F 83 C0 ?? 83 C1 ?? 66 85 D2 75 DE 33 C0 EB 05 1B C0 - 83 D8 ?? 85 C0 0F 84 AE 00 00 00 B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 1E 66 85 D2 74 15 66 8B 50 ?? 66 - 3B 51 ?? 75 0F 83 C0 ?? 83 C1 ?? 66 85 D2 75 DE 33 C0 EB 05 1B C0 83 D8 ?? 85 C0 74 74 8D 85 ?? ?? ?? ?? 8D 50 ?? 8B FF - 66 8B 08 83 C0 ?? 66 85 C9 75 F5 2B C2 D1 F8 03 C7 8D 44 00 ?? 85 C0 74 6C 50 A1 ?? ?? ?? ?? 6A ?? 50 FF 15 ?? ?? ?? ?? - 8B F0 85 F6 74 57 53 8D 4F ?? 51 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 56 56 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 0A C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 52 FF - 15 ?? ?? ?? ?? 85 C0 0F 85 EB FE FF FF 8B 85 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 50 6A ?? 51 FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? - ?? 8B 15 ?? ?? ?? ?? 53 6A ?? 52 FF 15 ?? ?? ?? ?? 8B 4D ?? 5F 8B C6 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } + $a = { 54 24 01 89 C7 31 F6 31 C9 48 89 A4 24 00 01 00 00 EB 1D 80 7A } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_A6A81F9C : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "a6a81f9c-b43b-4ec3-8b0b-94c1cfee4f08" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L755-L772" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "0d31cc1f4a673c13e6c81c492acbe16e1e0dfb0b15913fb276ea4abff18b32af" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "e1ec5725b75e4bb3eefe34a17ced900a16af9329a07a99f18f88aaef2678bfc1" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 41 57 00 54 43 50 00 47 52 45 00 4B 54 00 73 68 65 6C 6C 00 } condition: - uint16(0)==0x5A4D and (($tlocker_ep and $tlocker_get_server_data and $tlocker_remove_shadow_copies and $tlocker_find_files) and ($tlocker_contact_server_1 or ($tlocker_contact_server_2_1 and $tlocker_contact_server_2_2))) + all of them } -rule REVERSINGLABS_Linux_Ransomware_Luckyjoe : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_485C4B13 : FILE MEMORY { meta: - description = "Yara rule that detects LuckyJoe ransomware." - author = "ReversingLabs" - id = "8dc98d71-b79d-5b09-9383-11f2b57baeb5" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Linux.Ransomware.LuckyJoe.yara#L1-L146" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "1e7df2c45bee072af233cf8f355a84ec931fe96afa3fbdcd225dded1b75ea961" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "485c4b13-3c7c-47a7-b926-8237cb759ad7" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L774-L792" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "49c94d184d7e387c3efe34ae6f021e011c3046ae631c9733ab0a230d5fe28ead" + logic_hash = "9625e4190559cc77f41ebef24f9bfa5e3d2e2259c12b301148c614b0f98b5835" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "LuckyJoe" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "28f3e8982cee2836a59721c88ee0a9159ad6fdfc27c0091927f5286f3a731e9a" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $main_call_p1 = { - 55 48 89 E5 48 81 EC ?? ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? 48 - C7 45 ?? ?? ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? - 48 89 45 ?? 48 8B 55 ?? 48 8B 45 ?? 48 89 D6 48 89 C7 E8 ?? ?? ?? ?? 48 8D 75 ?? 48 - 8B 45 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? BE ?? ?? - ?? ?? BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 89 C7 E8 - ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? - ?? 48 89 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? E8 ?? ?? - ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 35 ?? ?? ?? ?? 48 83 EC ?? 48 8B 45 - ?? 6A ?? 41 B9 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 C7 - E8 ?? ?? ?? ?? 48 83 C4 ?? 48 8B 15 ?? ?? ?? ?? 48 8B 45 ?? 48 89 D6 48 89 C7 E8 ?? - ?? ?? ?? 48 8B 45 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? - ?? ?? 48 98 48 89 45 ?? 48 8B 45 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 - } - $main_call_p2 = { - 89 C7 E8 ?? ?? ?? ?? 48 98 48 89 45 ?? 48 8B 45 ?? 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? - ?? 48 89 45 ?? 48 8B 45 ?? 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 - ?? 89 C2 48 8B 4D ?? 48 8B 45 ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 89 C2 - 48 8B 4D ?? 48 8B 45 ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? ?? 48 8B 55 ?? 48 8B 45 ?? 48 - 01 D0 C6 00 ?? 48 8B 55 ?? 48 8B 45 ?? 48 01 D0 C6 00 ?? 48 8B 45 ?? 48 8B 55 ?? 48 - 89 D6 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 83 7D ?? ?? 75 ?? BF ?? ?? ?? ?? E8 ?? - ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C6 BF ?? ?? ?? ?? B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? B8 - ?? ?? ?? ?? E9 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 45 ?? - 48 83 7D ?? ?? 74 ?? 48 8B 55 ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 B8 - } - $main_call_p3 = { - E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 79 ?? 48 8B 45 ?? 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? - ?? ?? E9 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 89 C7 E8 ?? ?? - ?? ?? 48 C7 45 ?? ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 45 - ?? 48 83 7D ?? ?? 74 ?? EB ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? - ?? ?? 48 8B 55 ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 89 45 ?? 83 7D ?? ?? 79 ?? 48 8B 45 ?? 89 C7 E8 ?? ?? ?? ?? EB ?? 48 8B 45 ?? 48 89 - C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 89 C7 E8 ?? ?? ?? ?? EB ?? BF ?? ?? ?? ?? E8 ?? ?? ?? - ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? - ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 48 98 48 8B 84 - C5 ?? ?? ?? ?? 48 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 48 98 - 48 8B 84 C5 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 83 45 ?? ?? 83 7D ?? ?? 74 ?? BF ?? - ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 - ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? C9 C3 - } - $encrypt_files_p1 = { - 55 48 89 E5 53 48 81 EC ?? ?? ?? ?? 48 89 BD ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? BA ?? - ?? ?? ?? B9 ?? ?? ?? ?? 48 89 C7 48 89 D6 F3 48 A5 48 89 F2 48 89 F8 0F B7 0A 66 89 - 08 48 8D 40 ?? 48 8D 52 ?? 48 C7 45 ?? ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - 48 C7 45 ?? ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 89 D7 - F3 48 AB 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 83 7D ?? ?? 75 - ?? 48 8B 85 ?? ?? ?? ?? 48 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? - ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 D6 48 89 C7 - E8 ?? ?? ?? ?? 48 8B 45 ?? 0F B6 40 ?? 3C ?? 0F 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? - 48 89 C7 E8 ?? ?? ?? ?? 48 89 C3 48 8B 45 ?? 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 - 01 D8 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 85 ?? ?? ?? ?? BE ?? ?? - ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 84 C0 74 ?? 48 8B 45 ?? 48 8D 48 ?? 48 8B 95 ?? ?? ?? - ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 48 8B 45 - ?? 48 8D 48 ?? 48 8B 95 ?? ?? ?? ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8B 4D ?? 48 8D 85 ?? ?? ?? ?? 48 89 CE 48 - 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? EB ?? 48 8B 45 ?? 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? - ?? 48 89 C2 48 8B 45 ?? 48 89 C6 48 89 D7 E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 45 ?? 48 - } - $encrypt_files_p2 = { - 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? - ?? EB ?? 48 8D 95 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C6 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 - 89 45 ?? 48 83 7D ?? ?? 75 ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 - 8B 45 ?? 0F B6 40 ?? 3C ?? 0F 85 ?? ?? ?? ?? 48 8B 45 ?? 48 83 C0 ?? BE ?? ?? ?? ?? - 48 89 C7 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 8B 45 ?? 48 83 C0 ?? BE ?? ?? ?? - ?? 48 89 C7 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 8B 45 ?? 48 83 C0 ?? 48 89 45 - ?? 48 8B 85 ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 C3 48 8B 45 ?? 48 89 C7 E8 ?? - ?? ?? ?? 48 01 D8 48 83 C0 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 85 ?? ?? ?? - ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 84 C0 74 ?? 48 8B 45 ?? 48 8D 48 ?? 48 8B - 95 ?? ?? ?? ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB - ?? 48 8B 45 ?? 48 8D 48 ?? 48 8B 95 ?? ?? ?? ?? 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 - C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 83 7D ?? ?? 0F - 85 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5D C3 - } - $encrypt_internal_message_p1 = { - 55 48 89 E5 53 48 83 EC ?? 48 89 7D ?? 48 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? BF ?? ?? - ?? ?? E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 89 45 ?? 48 8B - 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 83 C0 ?? 48 98 48 89 C7 E8 ?? ?? ?? - ?? 48 89 45 ?? 8B 45 ?? 83 C0 ?? 48 63 D0 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? - ?? ?? ?? 8B 45 ?? 48 63 D0 48 8B 4D ?? 48 8B 45 ?? 48 89 CE 48 89 C7 E8 ?? ?? ?? ?? - 8B 45 ?? 48 98 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 8B 45 ?? 83 E8 ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 66 0F EF C0 F2 0F 2A 45 ?? - 66 0F EF C9 F2 0F 2A 4D ?? F2 0F 5E C1 E8 ?? ?? ?? ?? F2 0F 2C C0 89 45 ?? 8B 45 ?? - 0F AF 45 ?? 48 98 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 8B 45 ?? 0F AF 45 ?? 48 63 D0 - 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 8B 45 ?? 0F AF 45 ?? 89 C3 48 8B - 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 C6 8B 45 ?? 89 C1 89 DA BF ?? ?? ?? ?? B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? E9 ?? ?? ?? ?? 8B 45 ?? 2B 45 ?? 3B 45 ?? 7D ?? 8B 45 ?? 2B 45 ?? 89 45 ?? 8B 45 - ?? 48 63 D0 48 8B 45 ?? BE ?? ?? ?? ?? 48 89 C7 E8 ?? ?? ?? ?? 8B 45 ?? 2B 45 ?? 89 - } - $encrypt_internal_message_p2 = { - C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 48 63 D0 48 8B 45 ?? 48 8D - 34 02 48 8B 4D ?? 48 8B 55 ?? 8B 45 ?? 41 B8 ?? ?? ?? ?? 89 C7 E8 ?? ?? ?? ?? 89 45 - ?? 8B 45 ?? 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? E8 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C2 48 8B 45 ?? 48 89 C6 48 89 D7 E8 ?? ?? ?? ?? 48 - 8B 05 ?? ?? ?? ?? 48 8B 55 ?? BE ?? ?? ?? ?? 48 89 C7 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? - 48 89 C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? - ?? ?? 8B 45 ?? 48 63 D0 8B 45 ?? 48 63 C8 48 8B 45 ?? 48 01 C1 48 8B 45 ?? 48 89 C6 - 48 89 CF E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 48 89 C6 BF ?? ?? ?? ?? - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 01 45 ?? 8B 45 ?? 01 45 ?? 48 8B 45 ?? 48 89 - C7 E8 ?? ?? ?? ?? 83 45 ?? ?? 8B 45 ?? 3B 45 ?? 0F 8E ?? ?? ?? ?? 48 8B 45 ?? 48 89 - C7 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? 8B 4D ?? 48 8B 45 ?? BA ?? ?? - ?? ?? 89 CE 48 89 C7 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 48 89 C7 E8 ?? ?? ?? ?? - 48 89 C6 BF ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 45 ?? 48 83 C4 ?? 5B 5D - C3 - } + $a = { 7E 1F 8B 4C 24 4C 01 D1 0F B6 11 88 D0 2C 61 3C 19 77 05 80 } condition: - uint32(0)==0x464C457F and ( all of ($main_call_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($encrypt_internal_message_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Plague17 : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_7146E518 : FILE MEMORY { meta: - description = "Yara rule that detects Plague17 ransomware." - author = "ReversingLabs" - id = "065c47b5-f459-529e-8046-7394a742b50a" - date = "2021-02-19" - modified = "2021-02-19" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Plague17.yara#L1-L263" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "e0e518fc83a62d70b83df273c6ba469e6f0fdf9c035126428ec7561e04437b6f" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "7146e518-f6f4-425d-bac8-b31edc0ac559" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L794-L811" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "374602254be1f5c1dbb00ad25d870722e03d674033dfcf953a2895e1f50c637d" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Plague17" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "334ef623a8dadd33594e86caca1c95db060361c65bf366bacb9bc3d93ba90c4f" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files_p1 = { - 55 89 E5 57 56 8D 85 ?? ?? ?? ?? 53 81 EC ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 31 C0 66 89 - 85 ?? ?? ?? ?? 8B 45 ?? 89 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 50 ?? 8B - 00 66 83 7C 50 ?? ?? 74 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? BA ?? ?? ?? - ?? 2B 51 ?? 39 D0 0F 87 ?? ?? ?? ?? 8B 4D ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 45 ?? 8B 7D ?? 83 EC ?? 8B 00 8B 57 ?? 8D 8D ?? ?? ?? ?? 8D 14 50 C6 44 - 24 ?? ?? 89 04 24 89 8D ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 54 24 ?? E8 ?? ?? ?? ?? 83 - EC ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 2B 95 ?? ?? ?? ?? 39 D0 0F - 87 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 44 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 83 EC ?? 8D 8D ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 83 EC ?? 39 F8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 45 ?? 8B 7D ?? 8D - } - $find_files_p2 = { - 9D ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 89 D9 8B 00 C6 44 24 ?? ?? 8B 57 ?? 89 B5 ?? ?? ?? - ?? 89 04 24 8D 14 50 89 54 24 ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 EC ?? 89 1C 24 - E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 39 F0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 89 5C 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 83 F8 ?? 89 C6 0F 84 ?? - ?? ?? ?? 8D BD ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 85 C0 74 - ?? C7 44 24 ?? ?? ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? F6 85 ?? ?? - ?? ?? ?? 89 7C 24 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 0F 85 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? 83 EC ?? 39 C8 74 ?? 89 04 24 E8 ?? ?? ?? ?? EB ?? C7 44 24 ?? - ?? ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 85 C0 75 ?? 89 5C 24 ?? 89 34 24 FF 15 ?? ?? ?? - ?? 83 EC ?? 85 C0 75 ?? 89 34 24 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 9D ?? ?? ?? - ?? 83 EC ?? 39 D8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8D 65 ?? 5B 5E 5F 5D C2 ?? ?? 8D 76 - ?? 8D BC 27 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 85 C0 74 - } - $find_files_p3 = { - 8B 45 ?? F6 85 ?? ?? ?? ?? ?? 89 7C 24 ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 75 - ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 83 EC ?? 39 D0 0F 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? EB ?? 89 - C3 8B 85 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? 39 F0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8D B5 ?? ?? ?? ?? 39 F0 74 ?? 89 04 24 E8 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? - ?? EB ?? 89 C3 8B 85 ?? ?? ?? ?? 39 F0 75 ?? EB ?? EB ?? EB ?? 89 C3 EB ?? C7 04 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB - } - $encrypt_files_p1 = { - 55 89 E5 57 56 53 81 EC ?? ?? ?? ?? 8B 45 ?? 89 8D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 00 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 83 - F8 ?? 89 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 89 C6 8D 85 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? - 89 34 24 89 44 24 ?? FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 8B 95 ?? ?? ?? ?? - 89 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 89 34 24 05 ?? ?? ?? ?? 89 85 - ?? ?? ?? ?? 89 44 24 ?? 83 D2 ?? A1 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 89 54 24 ?? 89 85 - ?? ?? ?? ?? FF D0 31 C0 83 EC ?? 83 BD ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 AB 7C ?? 0F - 8E ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 74 24 ?? 89 04 24 FF 15 ?? ?? ?? ?? - 83 EC ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 83 EC ?? 85 C0 0F - 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 35 ?? ?? ?? ?? 0B 85 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? - 80 7D ?? ?? 0F 85 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 C3 8D 85 ?? ?? - ?? ?? 89 D9 89 04 24 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? - ?? ?? 83 EC ?? 8B B5 ?? ?? ?? ?? 89 D9 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 1E 0F A4 C2 ?? C1 E0 ?? 89 95 ?? ?? ?? ?? 89 85 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D - } - $encrypt_files_p2 = { - 85 ?? ?? ?? ?? 89 04 24 8B 0E E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 89 04 24 8B - 85 ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 - ?? 8B 0E E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 89 04 24 89 54 - 24 ?? 8B 0E 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 83 EC ?? 8B 85 ?? ?? - ?? ?? 85 FF 0F 84 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 95 - ?? ?? ?? ?? 8D BD ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? 89 44 24 ?? 8B 85 - ?? ?? ?? ?? 89 54 24 ?? 89 04 24 FF 95 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? C7 04 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 89 - 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 2B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? - 1B 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 0F AC D0 ?? C1 EA ?? 89 D3 09 - C3 0F 84 ?? ?? ?? ?? 83 C0 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? 83 D2 ?? 89 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? - 90 8D B4 26 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 74 24 ?? C7 44 - 24 ?? ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 04 24 FF 95 ?? ?? ?? ?? 8B 8D ?? - ?? ?? ?? 8B 9D ?? ?? ?? ?? 83 EC ?? 8B 95 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C - } - $encrypt_files_p3 = { - 24 ?? 89 0C 24 8B 0A E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 8B - 9D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? 89 44 24 ?? 89 54 24 ?? 89 1C 24 - FF 95 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 EC ?? 89 9D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 89 4C 24 ?? FF 15 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 83 EC ?? 8B 95 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 81 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? 83 95 ?? ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 5C - 24 ?? 89 54 24 ?? 89 04 24 FF 95 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 83 - EC ?? 81 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 D9 83 95 ?? ?? ?? ?? ?? 8B 02 89 04 24 E8 ?? - ?? ?? ?? 8B 9D ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 EC ?? 8B 95 ?? ?? ?? ?? 8B 85 ?? ?? - ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D - ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 0B 89 85 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 04 24 8B 0B E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 83 EC ?? 89 04 24 8B 85 ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? 8B - 85 ?? ?? ?? ?? 89 44 24 ?? 8B 0B E8 ?? ?? ?? ?? 8B 0B 83 EC ?? E8 ?? ?? ?? ?? 8B 9D - ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 89 1C 24 FF 15 ?? ?? ?? ?? 8B - } - $encrypt_files_p4 = { - 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? 89 1C - 24 89 44 24 ?? 89 54 24 ?? FF 95 ?? ?? ?? ?? 83 EC ?? 83 85 ?? ?? ?? ?? ?? 8B 9D ?? - ?? ?? ?? 83 95 ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 31 CB 31 D0 89 DA 09 C2 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 2B 85 ?? ?? ?? ?? 8B 95 - ?? ?? ?? ?? 1B 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 74 24 ?? 89 4C 24 ?? 8B 8D ?? ?? ?? ?? - 89 C3 89 44 24 ?? 89 0C 24 FF 95 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 8B 85 ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 8B 95 ?? ?? ?? ?? 89 14 24 8B 08 E8 ?? ?? - ?? ?? 83 EC ?? 8B 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 7C 24 ?? 8B BD ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 89 54 24 ?? 89 3C 24 FF 95 ?? ?? ?? ?? 83 EC ?? 8B - 95 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 89 5C 24 ?? 8B 1D ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? 89 74 24 ?? 89 54 24 ?? 89 3C 24 89 9D ?? ?? ?? ?? FF D3 8B 95 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 83 EC ?? B9 ?? ?? ?? ?? C7 85 - } - $encrypt_files_p5 = { - 89 DF C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F AC D0 ?? C1 EA - ?? 01 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 11 95 ?? ?? ?? ?? 31 C0 C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? F3 AB C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 45 - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? C7 44 24 ?? ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 89 54 24 ?? E8 ?? ?? ?? ?? 8B BD ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 89 5C 24 ?? C7 04 24 ?? ?? ?? ?? 89 85 ?? ?? - ?? ?? 89 7C 24 ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 31 C0 F3 AB 8B BD ?? ?? ?? ?? 89 74 - 24 ?? 8D B5 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 74 24 ?? - 89 3C 24 FF 95 ?? ?? ?? ?? 83 EC ?? 89 3C 24 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 - EC ?? 8B 18 85 DB 74 ?? 89 D9 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? - ?? 8D 65 ?? 31 C0 5B 5E 5F 5D C2 ?? ?? 8D BD ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? 8B B5 - ?? ?? ?? ?? 31 D2 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? F3 AB 8B BD ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? 89 F9 C1 F9 ?? 83 E1 ?? 89 C8 01 F0 11 FA 0F AC D0 ?? C1 FA ?? 83 - } - $encrypt_files_p6 = { - C0 ?? 83 D2 ?? 0F A4 C2 ?? C1 E0 ?? 89 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 89 FA 09 F2 - 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 8D 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 F7 C6 00 ?? 83 C0 ?? 39 C2 75 ?? 89 BD - ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 C3 8B 85 ?? ?? ?? ?? 89 D9 89 04 - 24 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 89 18 A1 ?? ?? ?? ?? 89 44 24 ?? 8D 85 - ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 89 - 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 75 ?? 83 C0 - ?? 83 EC ?? 8B 56 ?? 39 D0 0F 87 ?? ?? ?? ?? 8B 7D ?? 29 C2 8D B5 ?? ?? ?? ?? 8D 9D - ?? ?? ?? ?? 8B 0F C6 44 24 ?? ?? 89 9D ?? ?? ?? ?? 8D 0C 41 8D 04 51 89 0C 24 89 F1 - 89 44 24 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 89 34 24 8D 48 ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 39 D8 74 ?? 89 04 24 E8 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? - 8D B5 ?? ?? ?? ?? 8D 9D ?? ?? ?? ?? 8B 47 ?? 89 34 24 89 44 24 ?? E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 0F C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 90 89 34 24 8B - 0F 83 C6 ?? E8 ?? ?? ?? ?? 83 EC ?? 39 DE 75 ?? 8B BD ?? ?? ?? ?? 8B B5 - } - $encrypt_files_p7 = { - 8B 0F E8 ?? ?? ?? ?? 8B 07 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 - 04 24 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 8B 85 ?? ?? ?? ?? - 8B 9D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 8B 0F 89 95 ?? ?? ?? ?? 89 95 - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 04 24 8B 0F E8 ?? ?? ?? ?? 8B 0F 83 EC ?? E8 ?? - ?? ?? ?? 8B 0F 89 F7 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 95 ?? ?? - ?? ?? 8B 95 ?? ?? ?? ?? 89 34 24 8D B5 ?? ?? ?? ?? 89 44 24 ?? 8B 85 ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? FF 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 - EC ?? 89 3C 24 C7 44 24 ?? ?? ?? ?? ?? 89 74 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 - ?? FF 15 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 83 EC ?? 8B 85 ?? ?? ?? ?? 85 FF 0F 85 ?? ?? - ?? ?? 3D ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 3D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - 0F 87 ?? ?? ?? ?? 3D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 87 ?? ?? ?? ?? 3D - ?? ?? ?? ?? 0F 97 C0 0F B6 C0 89 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 65 ?? B8 ?? ?? ?? - ?? 5B 5E 5F 5D C2 ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 FF 15 ?? ?? ?? ?? 83 EC ?? 8D 65 - ?? B8 ?? ?? ?? ?? 5B 5E 5F 5D C2 ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 FF 15 - } - $encrypt_files_p8 = { - 83 EC ?? 8D 65 ?? 31 C0 5B 5E 5F 5D C2 ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 - 04 24 ?? ?? ?? ?? 89 C6 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 04 24 C1 F8 ?? 89 F1 89 - 44 24 ?? 8D B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 EC ?? 89 B5 ?? ?? ?? - ?? 89 85 ?? ?? ?? ?? 89 C3 A1 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 - ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 89 - 04 24 89 54 24 ?? 89 74 24 ?? 89 7C 24 ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8B BD ?? - ?? ?? ?? 89 95 ?? ?? ?? ?? 89 54 24 ?? 89 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 - 7C 24 ?? 89 44 24 ?? 89 34 24 FF 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 EC ?? 89 5C 24 - ?? C7 44 24 ?? ?? ?? ?? ?? 83 C3 ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 89 44 24 ?? FF - 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 83 EC ?? 39 C3 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 76 ?? 81 BD ?? ?? - ?? ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? E9 ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? - E9 ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 89 C6 C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 34 24 E8 ?? - ?? ?? ?? 89 C3 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? EB - } - $remote_connection_p1 = { - 55 57 56 53 81 EC ?? ?? ?? ?? 8B 1A 39 18 0F 84 ?? ?? ?? ?? 89 54 24 ?? 89 C6 8D 5C - 24 ?? F6 05 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? 89 DF 8B 56 ?? 89 54 24 - ?? 8B 56 ?? 89 54 24 ?? 8B 56 ?? 89 54 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 89 - 3C 24 E8 ?? ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 01 C7 89 F8 29 D8 BA ?? ?? ?? ?? 89 D5 - 29 C5 F6 05 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 06 89 44 24 ?? 8B 46 ?? 89 44 24 ?? - C7 44 24 ?? ?? ?? ?? ?? 89 6C 24 ?? 89 3C 24 E8 ?? ?? ?? ?? 89 5C 24 ?? 8B 7C 24 ?? - 8B 07 89 04 24 E8 ?? ?? ?? ?? FF 47 ?? 8B 46 ?? 01 47 ?? 8B 6E ?? 85 ED 0F 84 ?? ?? - ?? ?? 89 6C 24 ?? 8D 44 24 ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E9 ?? - ?? ?? ?? 8D B6 ?? ?? ?? ?? 8D BC 27 ?? ?? ?? ?? 85 C0 74 ?? C6 03 ?? A8 ?? 0F 85 ?? - ?? ?? ?? 8B 7D ?? 8B 75 ?? 89 2C 24 E8 ?? ?? ?? ?? 89 7C 24 ?? 89 74 24 ?? 89 44 24 - ?? C7 44 24 ?? ?? ?? ?? ?? B8 ?? ?? ?? ?? 8B 74 24 ?? 29 F0 89 44 24 ?? 8D 04 33 89 - 04 24 E8 ?? ?? ?? ?? 89 DF 8B 17 83 C7 ?? 8D 82 ?? ?? ?? ?? F7 D2 21 D0 25 ?? ?? ?? - ?? 74 ?? A9 ?? ?? ?? ?? 75 ?? C1 E8 ?? 83 C7 ?? 88 C1 00 C1 83 DF ?? 29 DF 8B 75 - } - $remote_connection_p2 = { - 89 34 24 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 29 F9 39 C1 0F 8D ?? ?? ?? ?? 8D 04 3B 83 F9 - ?? 0F 83 ?? ?? ?? ?? 85 C9 74 ?? 8A 16 88 10 F6 C1 ?? 0F 85 ?? ?? ?? ?? BA ?? ?? ?? - ?? B8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 01 D8 89 04 24 E8 ?? ?? ?? ?? - 89 5C 24 ?? 8B 44 24 ?? 8B 00 89 04 24 E8 ?? ?? ?? ?? 8B 6D ?? 85 ED 74 ?? 8D 44 24 - ?? 89 44 24 ?? 89 2C 24 E8 ?? ?? ?? ?? 85 C0 75 ?? FF 44 24 ?? 8B 44 24 ?? 83 F8 ?? - 0F 82 ?? ?? ?? ?? C7 44 03 ?? ?? ?? ?? ?? 8D 48 ?? C1 E9 ?? 89 DF B8 ?? ?? ?? ?? F3 - AB E9 ?? ?? ?? ?? 8D B6 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 5B 5E 5F 5D C3 90 8D 74 26 ?? - 8D 40 ?? 89 04 24 E8 ?? ?? ?? ?? 8B 10 89 54 24 ?? 8B 50 ?? 89 54 24 ?? 8B 40 ?? 89 - 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 89 - DA 8B 0A 83 C2 ?? 8D 81 ?? ?? ?? ?? F7 D1 21 C8 25 ?? ?? ?? ?? 74 ?? A9 - } - $remote_connection_p3 = { - 75 ?? C1 E8 ?? 83 C2 ?? 88 C1 00 C1 83 DA ?? 29 DA 8D 3C 13 B8 ?? ?? ?? ?? 29 D0 E9 - ?? ?? ?? ?? 8D B6 ?? ?? ?? ?? 8D BF ?? ?? ?? ?? B8 ?? ?? ?? ?? 29 F8 89 44 24 ?? 89 - 74 24 ?? 01 DF 89 3C 24 E8 ?? ?? ?? ?? 89 D8 8B 08 83 C0 ?? 8D 91 ?? ?? ?? ?? F7 D1 - 21 CA 81 E2 ?? ?? ?? ?? 74 ?? F7 C2 ?? ?? ?? ?? 75 ?? C1 EA ?? 83 C0 ?? 88 D1 00 D1 - 83 D8 ?? 29 D8 BA ?? ?? ?? ?? 29 C2 E9 ?? ?? ?? ?? 8D 74 26 ?? 8D BC 27 ?? ?? ?? ?? - 8B 16 89 10 8B 54 0E ?? 89 54 08 ?? 8D 78 ?? 83 E7 ?? 29 F8 29 C6 01 C1 C1 E9 ?? F3 - A5 E9 ?? ?? ?? ?? 8D B4 26 ?? ?? ?? ?? 8D BC 27 ?? ?? ?? ?? 89 54 24 ?? 8D 46 ?? 89 - 04 24 E8 ?? ?? ?? ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 6C 24 ?? 89 3C 24 E8 ?? - ?? ?? ?? 89 3C 24 E8 ?? ?? ?? ?? 01 C7 89 F8 29 D8 8B 54 24 ?? 29 C2 89 D5 E9 ?? ?? - ?? ?? 8D B4 26 ?? ?? ?? ?? 8D BC 27 ?? ?? ?? ?? 8B 44 24 ?? 66 C7 44 03 ?? ?? ?? E9 - ?? ?? ?? ?? 66 8B 54 0E ?? 66 89 54 08 ?? E9 ?? ?? ?? ?? 90 8B 54 24 ?? 8B 44 24 ?? - E9 - } + $a = { 85 82 11 79 AF 20 C2 7A 9E 18 6C A9 00 21 E2 6A C6 D5 59 B4 E8 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($remote_connection_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Techandstrat : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_6A77Af0F : FILE MEMORY { meta: - description = "Yara rule that detects TechandStrat ransomware." - author = "ReversingLabs" - id = "525d0b48-2018-5848-b9e7-def8395254eb" - date = "2021-05-17" - modified = "2021-05-17" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.TechandStrat.yara#L1-L106" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "80e201cf91adeee100e05af3ba5227fc61968bb6e0ce602107ba1217a7a62856" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "6a77af0f-31fa-4793-82aa-10b065ba1ec0" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L813-L830" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "7d7623dfc1e16c7c02294607ddf46edd12cdc7d39a2b920d8711dc47c383731b" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "TechandStrat" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $enum_shares_p1 = { - 55 8B EC 83 EC ?? 53 56 57 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF 75 ?? C7 45 ?? ?? ?? - ?? ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? 6A ?? FF - 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 85 DB 74 ?? 8D 45 ?? 50 53 8D 45 ?? 50 FF - 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 - } - $enum_shares_p2 = { - 8D 46 ?? B9 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? EB ?? FF 36 E8 ?? ?? ?? ?? 47 83 C6 ?? 3B - 7D ?? 72 ?? 8D 45 ?? 50 53 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 53 6A - ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 - 5D C2 - } - $find_files = { - 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 4D ?? 53 8B 5D ?? - 56 8B 75 ?? 57 89 B5 ?? ?? ?? ?? EB ?? 8A 01 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 - 53 E8 ?? ?? ?? ?? 59 59 8B C8 3B CB 75 ?? 8A 11 80 FA ?? 75 ?? 8D 43 ?? 3B C8 74 ?? - 56 33 FF 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 33 FF 80 FA ?? 74 ?? 80 FA ?? 74 ?? - 80 FA ?? 74 ?? 8B C7 EB ?? 33 C0 40 0F B6 C0 2B CB 41 F7 D8 68 ?? ?? ?? ?? 1B C0 23 - C1 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? - ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B 85 ?? ?? ?? ?? 83 FE ?? 75 ?? 50 57 - 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D - ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? - ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 8A 8D ?? ?? ?? ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 80 BD ?? - ?? ?? ?? ?? 74 ?? 50 FF B5 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 8B 85 ?? ?? ?? ?? 75 - ?? 8B 10 8B 40 ?? 8B 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B FF 56 57 - 8B F9 8B 37 EB ?? FF 36 E8 ?? ?? ?? ?? 59 83 C6 ?? 3B 77 ?? 75 ?? FF 37 E8 ?? ?? ?? - ?? 59 5F 5E C3 - } - $encrypt_files_p1 = { - 55 8B EC 83 E4 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 8B 75 ?? 8D 44 24 ?? 57 50 C6 44 - 24 ?? ?? FF 36 FF 15 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 4C 24 ?? 83 C4 ?? 8B - 44 24 ?? 81 E9 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 D8 ?? 6A ?? 6A ?? 50 51 FF 36 FF D7 - 6A ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 36 FF 15 ?? ?? ?? ?? - 81 BC 24 ?? ?? ?? ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 - D2 69 C0 ?? ?? ?? ?? 89 4C 24 ?? 8B 4C 24 ?? 89 8C 24 ?? ?? ?? ?? 83 C9 ?? 51 40 C7 - 44 24 ?? ?? ?? ?? ?? F7 F1 8D 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 50 - C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 89 54 24 ?? 89 94 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 51 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 94 24 ?? - ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 10 84 24 ?? ?? ?? ?? 6A ?? 6A ?? 0F - 11 84 24 ?? ?? ?? ?? 0F 57 C0 66 0F 13 44 24 ?? 8B 44 24 ?? 50 89 44 24 ?? 8B 44 24 - ?? 50 FF 36 89 44 24 ?? FF D7 6A ?? 8D 44 24 ?? 0F 57 C0 50 68 ?? ?? ?? ?? 8D 84 24 - ?? ?? ?? ?? 66 0F 13 44 24 ?? 50 FF 36 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 85 - C0 0F 84 - } - $encrypt_files_p2 = { - 6A ?? 6A ?? FF 74 24 ?? 0F 11 84 24 ?? ?? ?? ?? FF 74 24 ?? FF 36 FF 15 ?? ?? ?? ?? - 6A ?? 8D 44 24 ?? 50 FF 74 24 ?? 8D 84 24 ?? ?? ?? ?? 50 FF 36 FF 15 ?? ?? ?? ?? 8B - 84 24 ?? ?? ?? ?? 8B C8 85 C0 B8 ?? ?? ?? ?? 6A ?? 0F 44 C8 69 44 24 ?? ?? ?? ?? ?? - 33 D2 6A ?? 40 89 44 24 ?? F7 F1 8B 4C 24 ?? 33 C0 83 C2 ?? 13 C0 01 54 24 ?? 13 C8 - 8B 44 24 ?? 89 4C 24 ?? 0F A4 C1 ?? C1 E0 ?? 51 50 FF 36 89 4C 24 ?? 89 44 24 ?? FF - 15 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 36 FF - 15 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 - 24 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 83 C4 ?? C7 84 24 ?? ?? ?? - ?? ?? ?? ?? ?? 6A ?? 6A ?? FF D7 8B 35 ?? ?? ?? ?? 50 FF D6 6A ?? 6A ?? 89 44 24 ?? - FF D7 50 FF D6 6A ?? 6A ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? FF D7 50 FF D6 6A ?? 6A ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? FF D7 50 FF D6 - } - $encrypt_files_p3 = { - 6A ?? 6A ?? 66 0F 13 44 24 ?? FF 74 24 ?? FF 74 24 ?? FF 36 FF 15 ?? ?? ?? ?? 6A ?? - 8D 44 24 ?? 50 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 36 FF 15 ?? ?? ?? ?? C6 44 - 24 ?? ?? FF 36 FF 15 ?? ?? ?? ?? 80 7C 24 ?? ?? 74 ?? 68 ?? ?? ?? ?? 6A ?? 83 C6 ?? - 56 FF 15 ?? ?? ?? ?? 56 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D - 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? - 8B 75 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? FF 15 - } + $a = { 31 D1 89 0F 48 83 C7 04 85 F6 7E 3B 44 89 C8 45 89 D1 45 89 C2 41 } condition: - uint16(0)==0x5A4D and ( all of ($enum_shares_p*)) and ($find_files) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Lechiffre : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_5F7B67B8 : FILE MEMORY { meta: - description = "Yara rule that detects LeChiffre ransomware." - author = "ReversingLabs" - id = "5d2698fe-9a0b-549d-9a83-72e2ccfc1966" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.LeChiffre.yara#L1-L123" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "0b96f5f48700f2cba22da91187b3111946074e9cc58a502f25d7b96059a043cb" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L832-L849" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "b2aedc0361c1093d7a996f26d907da3e4654c32a6dbcdbab441c19d4207f2e2a" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "LeChiffre" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $remote_connection_1 = { - 55 8B EC 33 C9 51 51 51 51 51 51 51 53 56 57 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF - 30 64 89 20 8B 45 ?? 33 D2 E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 - ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 8B 45 ?? - E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 8B 50 ?? 8B 45 - ?? 8B 08 FF 51 ?? 8B 45 ?? 8B 10 FF 52 ?? 8B F0 4E 85 F6 7C ?? 46 33 DB 8D 4D ?? 8B - D3 8B 45 ?? 8B 38 FF 57 ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 7E ?? 8D 45 - ?? 50 8D 4D ?? 8B D3 8B 45 ?? 8B 38 FF 57 ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 E8 ?? 50 8D 4D ?? 8B D3 8B 45 ?? 8B 38 FF 57 ?? 8B 45 ?? BA ?? ?? ?? ?? 59 E8 ?? - ?? ?? ?? 43 4E 75 ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? - 8B 45 ?? E8 ?? ?? ?? ?? C3 - } - $remote_connection_2 = { - 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 - C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8B 45 ?? 8B 80 ?? ?? ?? ?? 66 BE ?? ?? E8 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 - ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 55 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 4D ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C3 - } - $remote_connection_3 = { - E8 ?? ?? ?? ?? 8B 45 ?? 8B 80 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 E8 ?? ?? - ?? ?? DD 5D ?? 9B FF 75 ?? FF 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 ?? ?? - ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? ?? ?? ?? 8D 45 ?? - 8B 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8D 55 ?? E8 ?? ?? ?? ?? FF - 75 ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8D 45 ?? E8 ?? ?? ?? ?? 8B 4D - ?? BA ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B - 45 ?? E8 ?? ?? ?? ?? C3 - } - $encrypt_files_1 = { - E8 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? - 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 55 ?? 8B 45 ?? E8 - ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 55 ?? - 8B 45 ?? E8 ?? ?? ?? ?? 8B 55 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? 83 7B ?? ?? 0F 84 ?? ?? ?? ?? 8B 13 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B - 03 E8 ?? ?? ?? ?? 84 C0 75 ?? 8B 03 BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? FF 86 ?? ?? - ?? ?? B2 ?? 8B 86 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 8B 03 E8 ?? ?? ?? ?? FF 75 ?? - 68 ?? ?? ?? ?? 8B 43 ?? C1 E8 ?? 33 D2 52 50 8D 45 ?? E8 ?? ?? ?? ?? FF 75 ?? 68 ?? - ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B 86 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8B 03 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? C3 - } - $encrypt_files_2 = { - E8 ?? ?? ?? ?? 8D 45 ?? 8B 15 ?? ?? ?? ?? 8B 12 8B 92 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 45 ?? 8B 40 ?? 8B 55 ?? E8 ?? ?? ?? ?? 3D ?? - ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? FF 70 ?? 68 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? - ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 8B 40 - ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? - ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 - FF 30 64 89 20 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 00 - 8B 90 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 - C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? - ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 - 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - A1 ?? ?? ?? ?? 8B 00 8B 90 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 8B 45 ?? E8 - ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? 50 68 ?? ?? ?? ?? 8B 45 - ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? - C3 E9 ?? ?? ?? ?? EB ?? 8B E5 5D C3 - } - $find_files = { - E8 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B 55 ?? 8B C3 E8 ?? ?? ?? ?? - 84 C0 0F 85 ?? ?? ?? ?? 33 C0 89 43 ?? 8B 43 ?? E8 ?? ?? ?? ?? 8B F0 85 F6 7C ?? 46 - 33 FF 8B 43 ?? C7 04 B8 ?? ?? ?? ?? 47 4E 75 ?? 8B 43 ?? 8B 40 ?? E8 ?? ?? ?? ?? 8B - F0 85 F6 7C ?? 46 33 FF 8B 43 ?? 8B 40 ?? 8B 14 B8 8D 8D ?? ?? ?? ?? 8B 45 ?? E8 ?? - ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B 43 ?? 8B 53 ?? 89 14 B8 47 4E 75 - ?? 8B 73 ?? 4E 85 F6 7C ?? 46 33 FF 80 7B ?? ?? 0F 85 ?? ?? ?? ?? 8D 04 BF 8B 53 ?? - 8D 04 C2 89 43 ?? 89 45 ?? 8D 8D ?? ?? ?? ?? 8B 45 ?? 8B 10 8B 45 ?? E8 ?? ?? ?? ?? - 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B - 45 ?? 33 D2 E8 ?? ?? ?? ?? 47 4E 75 ?? 8B 43 ?? 8B 40 ?? 80 78 ?? ?? 0F 84 ?? ?? ?? - ?? 80 7B ?? ?? 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? BA ?? ?? ?? - ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 89 45 - ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 F6 85 ?? - ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 - ?? ?? ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B C3 - E8 ?? ?? ?? ?? 80 7B ?? ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? - ?? C3 E9 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 8B E5 5D C3 - } + $a = { 89 38 83 CF FF 89 F8 5A 59 5F C3 57 56 83 EC 04 8B 7C 24 10 8B 4C } condition: - uint16(0)==0x5A4D and $find_files and $encrypt_files_1 and $encrypt_files_2 and $remote_connection_1 and $remote_connection_2 and $remote_connection_3 + all of them } -rule REVERSINGLABS_Win64_Ransomware_Cactus : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_A3Cedc45 : FILE MEMORY { meta: - description = "Yara rule that detects Cactus ransomware." - author = "ReversingLabs" - id = "f391919a-b433-5f8d-8051-f0467118fa1b" - date = "2023-12-15" - modified = "2023-12-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Cactus.yara#L1-L190" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "2953b67e926cb653df0de208b098da3d5c16e6690842ab28fbf8c37cd16f54d7" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "a3cedc45-962d-44b5-bf0e-67166fa6c1a4" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L851-L869" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "1ae0cd7e5bac967e31771873b4b41a1887abddfcdfcc76fa9149bb2054b03ca4" + logic_hash = "9233e6faa43d8ea43ff3c71ecb5248d5d311b2a593825c299cac4466278cd020" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Cactus" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "8335e540adfeacdf8f45c9cb36b08fea7a06017bb69aa264dc29647e7ca4a541" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 55 41 57 41 56 41 55 41 54 56 53 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 29 C4 48 8D AC 24 - ?? ?? ?? ?? 48 89 8D ?? ?? ?? ?? 48 89 95 ?? ?? ?? ?? 4C 89 85 ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C1 E8 ?? - ?? ?? ?? 48 98 48 89 C1 E8 ?? ?? ?? ?? 48 89 45 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 - 89 85 ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 C1 4C 8D 4D - ?? 4C 8D 45 ?? 48 8B 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 - 89 54 24 ?? 48 8B 95 ?? ?? ?? ?? 48 89 54 24 ?? 48 89 CA 48 89 C1 E8 ?? ?? ?? ?? 48 - 8D 45 ?? 48 8B 95 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 - ?? 48 8B 95 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 - 89 C1 E8 ?? ?? ?? ?? 48 89 C3 48 8B 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DA - 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA - ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 C2 - 48 8D 85 ?? ?? ?? ?? 41 89 D8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 41 B8 ?? - ?? ?? ?? BA ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 8B 45 ?? 4C 63 C0 48 8B 45 ?? 48 8D - } - $encrypt_files_p2 = { - 95 ?? ?? ?? ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 4C 8B 85 ?? ?? ?? ?? 48 8B 85 ?? - ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? - ?? 48 83 C0 ?? BA ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 8D 95 - ?? ?? ?? ?? 48 8D 4A ?? 41 B8 ?? ?? ?? ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? - ?? 41 B8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 29 - C2 48 89 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 48 98 48 39 85 ?? ?? ?? ?? 0F 8D ?? ?? ?? - ?? 48 89 E0 48 89 C6 48 8B 85 ?? ?? ?? ?? 48 8D 50 ?? 48 85 C0 48 0F 48 C2 48 C1 F8 - ?? 48 C1 E0 ?? 48 89 85 ?? ?? ?? ?? 48 8B 9D ?? ?? ?? ?? 48 8D 43 ?? 48 89 85 ?? ?? - ?? ?? 48 89 D8 49 89 C4 41 BD ?? ?? ?? ?? 48 89 D8 49 89 C6 41 BF ?? ?? ?? ?? 48 89 - D8 48 83 C0 ?? 48 C1 E8 ?? 48 C1 E0 ?? E8 ?? ?? ?? ?? 48 29 C4 48 8D 44 24 ?? 48 83 - C0 ?? 48 89 85 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 8B 95 ?? ?? ?? ?? 48 8D 85 ?? ?? - ?? ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 41 89 D9 4C 8B 85 ?? ?? ?? ?? 48 89 E9 48 8D - 55 ?? 48 8B 85 ?? ?? ?? ?? 44 89 4C 24 ?? 4D 89 C1 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? - 48 8B 85 ?? ?? ?? ?? F7 D8 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 48 63 D0 48 8D 85 ?? - ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 8B 45 ?? 4C 63 C0 48 8D 45 ?? 48 - 8D 95 ?? ?? ?? ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 2B 85 - ?? ?? ?? ?? 48 89 C2 48 8D 85 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 - } - $encrypt_files_p3 = { - 48 89 DA 48 8B 85 ?? ?? ?? ?? 48 01 D0 48 89 85 ?? ?? ?? ?? 90 48 89 F4 E9 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 48 63 C8 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 49 89 C8 48 - 89 C1 E8 ?? ?? ?? ?? 4C 8D 85 ?? ?? ?? ?? 48 89 E9 48 8D 55 ?? 48 8B 85 ?? ?? ?? ?? - C7 44 24 ?? ?? ?? ?? ?? 4D 89 C1 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - F7 D8 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 48 63 D0 48 8D 85 ?? ?? ?? ?? 41 B8 ?? ?? - ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 8B 45 ?? 4C 63 C0 48 8D 45 ?? 48 8D 95 ?? ?? ?? ?? 48 - 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 05 ?? ?? ?? ?? 48 89 85 ?? - ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 05 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 83 F0 ?? 84 - C0 0F 85 ?? ?? ?? ?? 8B 45 ?? 48 98 48 8D 55 ?? 48 01 C2 48 89 E9 48 8B 85 ?? ?? ?? - ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 8B 45 ?? 4C 63 C0 48 8D 45 ?? 48 8D 95 ?? ?? ?? - ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 8B 45 ?? 4C 63 C0 48 8B 45 ?? 48 8D 95 ?? ?? - ?? ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 4C 8B 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? - 48 8D 95 ?? ?? ?? ?? 48 8D 4A ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 83 - C0 ?? BA ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? - ?? 48 8D 4A ?? 41 B8 ?? ?? ?? ?? 48 89 C2 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 - } - $encrypt_files_p4 = { - C1 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 - E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 41 B8 - ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 89 - C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 84 DB 74 ?? 48 8D 45 ?? 48 89 C1 E8 - ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? - 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DA 48 89 C1 48 8B 05 ?? ?? ?? ?? - FF D0 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D - 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 F4 48 89 C3 EB ?? 48 89 C3 48 8D - 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? - ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? - ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 90 48 8D A5 ?? ?? - ?? ?? 5B 5E 41 5C 41 5D 41 5E 41 5F 5D C3 - } - $find_files_p1 = { - 55 56 53 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 29 C4 48 8D AC 24 ?? ?? ?? ?? 48 89 8D ?? - ?? ?? ?? 48 8D 45 ?? BB ?? ?? ?? ?? 48 89 C6 EB ?? 48 89 F1 E8 ?? ?? ?? ?? 48 83 EB - ?? 48 83 C6 ?? 48 85 DB 79 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 85 C0 - 0F 95 C0 84 C0 74 ?? 48 8B 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? - ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? - ?? ?? ?? E9 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? - 84 C0 74 ?? 48 8D 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 - ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? - ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? - ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - E9 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 84 C0 74 ?? 48 8D 45 ?? 8B 95 ?? ?? ?? ?? 48 63 - D2 48 C1 E2 ?? 48 01 C2 48 8D 85 ?? ?? ?? ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 - E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 - } - $find_files_p2 = { - 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 8B 95 ?? ?? ?? ?? 48 63 D2 48 C1 E2 ?? 48 01 C2 48 - 8D 85 ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D - 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? - 83 85 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B 85 ?? ?? ?? ?? 0F 8C ?? ?? ?? ?? C6 05 ?? - ?? ?? ?? ?? 48 8D 5D ?? 48 81 C3 ?? ?? ?? ?? 48 8D 45 ?? 48 39 C3 74 ?? 48 83 EB ?? - 48 89 D9 E8 ?? ?? ?? ?? EB ?? 90 E9 ?? ?? ?? ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 - C1 E8 ?? ?? ?? ?? 48 89 DE EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? - ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DE EB ?? 48 89 - C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DE EB ?? 48 89 C3 48 8D 85 ?? - ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DE EB ?? 48 89 C6 48 8D 5D ?? 48 81 C3 ?? ?? - ?? ?? 48 8D 45 ?? 48 39 C3 74 ?? 48 83 EB ?? 48 89 D9 E8 ?? ?? ?? ?? EB ?? 90 48 89 - F0 48 89 C1 E8 ?? ?? ?? ?? 90 48 81 C4 ?? ?? ?? ?? 5B 5E 5D C3 - } - $check_processes = { - 55 53 48 83 EC ?? 48 8D 6C 24 ?? 48 89 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? EB ?? 8B 45 ?? 48 98 48 8D 14 C5 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 8B 1C 02 48 - 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 DA 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 48 85 - C0 0F 95 C0 84 C0 74 ?? B8 ?? ?? ?? ?? EB ?? 83 45 ?? ?? 8B 45 ?? 3B 45 ?? 7C ?? B8 - ?? ?? ?? ?? 48 83 C4 ?? 5B 5D C3 - } - $kill_file_processes_p1 = { - 55 56 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 8D ?? ?? ?? ?? C6 85 ?? - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF C0 - 0F 11 45 ?? F3 0F 6F 4D ?? 0F 11 8D ?? ?? ?? ?? F3 0F 6F 55 ?? 0F 11 95 ?? ?? ?? ?? - F3 0F 6F 5D ?? 0F 11 9D ?? ?? ?? ?? F3 0F 6F 65 ?? 0F 11 A5 ?? ?? ?? ?? 0F B7 45 ?? - 66 89 85 ?? ?? 00 00 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 49 89 D0 BA ?? ?? ?? - ?? 48 89 C1 E8 ?? ?? ?? ?? 85 C0 0F 94 C0 84 C0 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 48 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 41 B9 - ?? ?? ?? ?? 4C 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 85 C0 0F 94 C0 - 84 C0 0F 84 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 4C - 8D 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 89 4C 24 ?? 41 B9 ?? - ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 75 ?? - 8B 85 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? BB ?? ?? ?? ?? - E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 C0 48 69 F0 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? FF - D0 49 89 F0 BA ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 48 89 85 ?? ?? ?? ?? - 48 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? BB ?? ?? ?? ?? - E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 4C 8B 8D ?? ?? - ?? ?? 4C 8D 85 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 89 4C 24 - } - $kill_file_processes_p2 = { - 89 C1 E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 75 ?? 8B 85 ?? ?? ?? ?? - 85 C0 75 ?? 48 8B 05 ?? ?? ?? ?? FF D0 48 8B 95 ?? ?? ?? ?? 49 89 D0 BA ?? ?? ?? ?? - 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 8B 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? BB ?? ?? - ?? ?? E9 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? FF D0 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 - 89 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 48 - 98 48 69 D0 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 01 D0 8B 00 39 85 ?? ?? ?? ?? 75 ?? - 48 8B 05 ?? ?? ?? ?? FF D0 48 8B 95 ?? ?? ?? ?? 49 89 D0 BA ?? ?? ?? ?? 48 89 C1 48 - 8B 05 ?? ?? ?? ?? FF D0 8B 85 ?? ?? ?? ?? 89 C1 E8 ?? ?? ?? ?? BB ?? ?? ?? ?? E9 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 48 98 48 69 D0 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 01 D0 - 8B 00 41 89 C0 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? FF D0 48 89 85 ?? - ?? ?? ?? 48 83 BD ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 48 8D 55 ?? 48 8B 85 ?? ?? ?? ?? - 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? - ?? ?? ?? FF D0 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 48 - 8D 55 ?? 48 8D 45 ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 - E8 ?? ?? ?? ?? 48 8D 45 ?? 49 C7 C0 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? - ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C0 ?? 48 63 C8 48 8D 45 ?? 48 8D 55 - ?? 49 C7 C1 ?? ?? ?? ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8D 85 ?? ?? - ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 - } + $a = { 74 2C 48 8B 03 48 83 E0 FE 48 29 C3 48 8B 43 08 48 83 E0 FE 4A 8D } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($check_processes) and ( all of ($kill_file_processes_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Ako : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_7D05725E : FILE MEMORY { meta: - description = "Yara rule that detects Ako ransomware." - author = "ReversingLabs" - id = "00d67696-998c-5bc3-95e7-0320ca558cdb" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Ako.yara#L1-L152" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "488e9b528f75fcfaa8dd19859801e6e5a73575c33cd70c98ebaa9ae93025018b" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "7d05725e-db59-42a7-99aa-99de79728126" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L871-L889" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb" + logic_hash = "ac2d0b81325ce7984bc09f93e61b42c8e312a31c75f09d37313d70cd40d3cf8b" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Ako" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "7fcd34cb7c37836a1fa8eb9375a80da01bda0e98c568422255d83c840acc0714" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_network_shares_win32_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 4D ?? 8B 45 ?? 50 8D 4D ?? E8 ?? ?? - ?? ?? 8B 4D ?? 81 C1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F B6 C8 85 C9 0F 85 ?? ?? ?? ?? 8B - 4D ?? E8 ?? ?? ?? ?? 0F B6 D0 85 D2 0F 85 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 45 - ?? 50 8B 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? E8 ?? ?? ?? ?? 0F B6 D0 85 D2 0F - 85 ?? ?? ?? ?? 8D 45 ?? 50 8B 4D ?? 83 C1 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B 4D ?? E8 ?? ?? ?? ?? 50 8D 95 - ?? ?? ?? ?? 52 8B 4D ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? E8 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 55 ?? 52 - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 - E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 - } - $encrypt_network_shares_win32_p2 = { - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 50 8D 95 ?? - ?? ?? ?? 52 8B 4D ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? E8 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? 52 - 8B 4D ?? E8 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 55 ?? 52 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? - E8 ?? ?? ?? ?? 0F B6 C8 85 C9 0F 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 55 ?? - 83 C2 ?? 89 55 ?? 8D 4D ?? E8 ?? ?? ?? ?? 39 45 ?? 73 ?? 83 7D ?? ?? 76 ?? 8B 45 - } - $encrypt_network_shares_win32_p3 = { - 33 D2 B9 ?? ?? ?? ?? F7 F1 85 D2 75 ?? 6A ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 8D 4D ?? E8 - ?? ?? ?? ?? 8B 45 ?? 83 C0 ?? 89 45 ?? EB ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? - 8D 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 55 ?? 52 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - 8B 4D ?? E8 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 8B 4D ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 83 C4 ?? 50 8D 95 ?? ?? ?? ?? 52 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? - ?? 50 8B 4D ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 8D ?? ?? ?? ?? 51 8D - 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? 8A 45 ?? EB ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? 32 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D - C2 - } - $find_files_win32_p1 = { - 8B FF 55 8B EC 51 8B 4D ?? 53 57 33 DB 8D 51 ?? 66 8B 01 83 C1 ?? 66 3B C3 75 ?? 8B - 7D ?? 2B CA D1 F9 8B C7 41 F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 EB ?? 56 8D 5F ?? 03 - D9 6A ?? 53 E8 ?? ?? ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? - 83 C4 ?? 85 C0 75 ?? FF 75 ?? 2B DF 8D 04 7E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? - 85 C0 75 ?? 8B 7D ?? 8B CF E8 ?? ?? ?? ?? 8B D8 85 DB 74 ?? 56 E8 ?? ?? ?? ?? 59 EB - ?? 8B 47 ?? 89 30 83 47 ?? ?? 33 DB 6A ?? E8 ?? ?? ?? ?? 59 8B C3 5E 5F 5B 8B E5 5D - C3 33 C0 50 50 50 50 50 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? - ?? ?? 33 C5 89 45 ?? 8B 55 ?? 8B 4D ?? 53 8B 5D ?? 89 8D ?? ?? ?? ?? 56 57 3B D3 74 - ?? 0F B7 02 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 84 C0 75 ?? 83 EA ?? 3B D3 75 ?? 8B - } - $find_files_win32_p2 = { - 8D ?? ?? ?? ?? 0F B7 32 83 FE ?? 75 ?? 8D 43 ?? 3B D0 74 ?? 51 33 FF 57 57 53 E8 ?? - ?? ?? ?? 83 C4 ?? EB ?? 56 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 2B D3 0F B6 C0 D1 FA 42 - F7 D8 68 ?? ?? ?? ?? 1B C0 33 FF 23 C2 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 - ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 57 57 57 50 57 53 FF 15 ?? ?? ?? ?? 8B F0 8B - 85 ?? ?? ?? ?? 83 FE ?? 75 ?? 50 57 57 53 E8 ?? ?? ?? ?? 83 C4 ?? 8B F8 83 FE ?? 74 - ?? 56 FF 15 ?? ?? ?? ?? 8B C7 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 8B - 48 ?? 2B 08 C1 F9 ?? 6A ?? 89 8D ?? ?? ?? ?? 59 66 39 8D ?? ?? ?? ?? 75 ?? 66 39 BD - ?? ?? ?? ?? 74 ?? 66 39 8D ?? ?? ?? ?? 75 ?? 66 39 BD ?? ?? ?? ?? 74 ?? 50 FF B5 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 85 ?? ?? ?? - ?? 50 56 FF 15 ?? ?? ?? ?? 6A ?? 85 C0 8B 85 ?? ?? ?? ?? 59 75 ?? 8B 10 8B 40 ?? 8B - 8D ?? ?? ?? ?? 2B C2 C1 F8 ?? 3B C8 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 - 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? E9 - } - $encrypt_files_win32_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 4D ?? 83 7D ?? ?? 74 ?? 83 7D ?? ?? - 75 ?? 32 C0 E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8B 45 ?? 50 8B 4D ?? E8 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 73 ?? 32 C0 E9 ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? 33 C9 89 4D ?? 8D 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 32 - C0 E9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 8B 8D ?? ?? ?? ?? - 51 8D 4D ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 33 D2 89 55 ?? C7 45 ?? ?? ?? ?? ?? 33 C0 89 45 ?? 0F 57 C0 66 0F 13 85 ?? - ?? ?? ?? EB ?? 8B 8D ?? ?? ?? ?? 81 C1 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 D2 ?? 89 8D - ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 3B 45 ?? 0F 8F ?? ?? ?? ?? 7C ?? 8B - 8D ?? ?? ?? ?? 3B 4D ?? 0F 83 ?? ?? ?? ?? 0F 57 C0 66 0F 13 45 ?? 6A ?? 8D 55 ?? 52 - } - $encrypt_files_win32_p2 = { - 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? C6 45 ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8A 45 ?? E9 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 - 68 ?? ?? ?? ?? 6A ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 8B 4D ?? 51 FF 15 ?? ?? ?? ?? 85 C0 - 75 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8A 45 ?? E9 ?? ?? - ?? ?? 6A ?? 8D 55 ?? 52 8B 45 ?? 50 8B 4D ?? 51 8B 55 ?? 52 FF 15 ?? ?? ?? ?? 85 C0 - 75 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8A 45 ?? E9 ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? EB ?? 8B 45 ?? 05 ?? ?? ?? ?? 89 45 ?? 8B 4D ?? 3B 4D ?? - 0F 83 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 03 45 ?? 50 6A ?? 8D 4D ?? - E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 8D 45 - ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 6A ?? 8B 4D ?? 51 8B 4D ?? E8 ?? ?? ?? ?? 0F B6 D0 - 85 D2 75 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8A 45 ?? E9 - ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8B 8D ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 50 8B 55 - ?? 52 FF 15 ?? ?? ?? ?? 85 C0 75 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? 8A 45 ?? E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? EB ?? E9 ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 89 4D - ?? 8B 95 ?? ?? ?? ?? 89 55 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 89 85 - } - $encrypt_files_win32_p3 = { - 8B 8D ?? ?? ?? ?? 89 4D ?? 8B 95 ?? ?? ?? ?? 89 55 ?? 6A ?? 8D 45 ?? 50 8B 4D ?? 51 - 8B 55 ?? 52 8B 45 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 - 8B 4D ?? 83 C1 ?? E8 ?? ?? ?? ?? 50 8B 4D ?? 83 C1 ?? E8 ?? ?? ?? ?? 50 8B 55 ?? 52 - FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 4D ?? 83 C1 ?? E8 ?? ?? ?? ?? 39 45 ?? 75 ?? 0F 57 - C0 66 0F 13 45 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 89 45 ?? 8B 4D - ?? 89 4D ?? 8B 55 ?? 89 55 ?? 6A ?? 8D 45 ?? 50 6A ?? 8D 4D ?? 51 8B 55 ?? 52 FF 15 - ?? ?? ?? ?? 85 C0 74 ?? 83 7D ?? ?? 75 ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D - ?? E8 ?? ?? ?? ?? 8A 45 ?? EB ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? - ?? ?? ?? 8A 45 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B - E5 5D C2 - } + $a = { 24 97 00 00 00 89 6C 24 08 89 74 24 04 89 14 24 0F B7 C0 89 44 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_win32_p*)) and ( all of ($encrypt_files_win32_p*)) and ( all of ($encrypt_network_shares_win32_p*)) + all of them } -rule REVERSINGLABS_Win64_Ransomware_DST : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Fa48B592 : FILE MEMORY { meta: - description = "Yara rule that detects DST ransomware." - author = "ReversingLabs" - id = "bcc9933d-14eb-5f83-a136-5f009c7a3282" - date = "2021-12-06" - modified = "2021-12-06" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.DST.yara#L1-L170" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "b658093232a2265d425e3b38758268c116bbac51fa5eed372b5b4f00de4c6880" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "fa48b592-8d80-45af-a3e4-232695b8f5dd" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L891-L909" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee" + logic_hash = "5648bcc96b1fdd1529b4b8765b1738594d0d61f7880b763e803cd89bd117e96b" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "DST" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 31 C0 BA 01 00 00 00 B9 01 00 00 00 03 04 24 89 D7 31 D2 F7 F7 0F } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_B9A9D04B : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "b9a9d04b-a997-46c4-b893-e89a3813efd3" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L911-L928" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "61575576be4c1991bc381965a40e5d9d751bba2680a42907b0148651716419fc" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "874249d8ad391be97466c0259ae020cc0564788a6770bb0f07dd0653721f48b1" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 4C 8D A4 24 ?? ?? ?? ?? 4D 3B 66 ?? 0F 86 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 89 AC - 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? - ?? 48 89 BC 24 ?? ?? ?? ?? 44 0F 11 BC 24 ?? ?? ?? ?? 48 85 DB 0F 84 ?? ?? ?? ?? 48 - 89 9C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? 48 89 4C 24 ?? - 31 C9 31 FF E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 85 DB - 0F 85 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 44 0F 11 BC 24 ?? ?? ?? ?? 48 8D 0D ?? ?? - ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? - ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 0F 1F 00 - E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 31 C0 48 8B 9C 24 ?? ?? ?? ?? 48 8B 8C 24 ?? - ?? ?? ?? 48 8D 3D ?? ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? BF ?? ?? - ?? ?? E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 85 DB 0F 85 - ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 44 0F 11 BC 24 ?? ?? ?? ?? 48 8D 0D - } - $encrypt_files_p2 = { - 48 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 8C 24 - ?? ?? ?? ?? 48 89 4C 24 ?? 48 8D 44 24 ?? E8 ?? ?? ?? ?? 90 85 C0 0F 85 ?? ?? ?? ?? - 48 8D 05 ?? ?? ?? ?? BB ?? ?? ?? ?? 48 89 D9 E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? - BB ?? ?? ?? ?? 48 89 D9 E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? - ?? 48 85 DB 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? BB ?? ?? ?? ?? 48 89 D9 E8 ?? - ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? 48 85 C9 0F 85 ?? ?? ?? ?? - 48 89 5C 24 ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B 51 ?? 48 8B 84 24 ?? ?? - ?? ?? FF D2 48 8B 0D ?? ?? ?? ?? 83 B9 ?? ?? ?? ?? ?? 75 ?? 48 89 C2 48 C1 E0 ?? 48 - 8D 70 ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 D1 48 F7 EE 48 8D 14 CA 48 8D 52 ?? 48 - } - $encrypt_files_p3 = { - C1 FA ?? 48 C1 FE ?? 48 29 F2 EB ?? 48 8D 70 ?? 48 89 C1 48 B8 ?? ?? ?? ?? ?? ?? ?? - ?? 48 F7 EE 48 8D 14 0A 48 8D 52 ?? 48 D1 FA 48 C1 FE ?? 48 29 F2 48 C1 E2 ?? 48 8D - 4A ?? 48 89 4C 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 CB E8 ?? ?? ?? ?? 48 89 C3 48 8B 4C - 24 ?? 48 89 CF 48 8B 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 - 8C 24 ?? ?? ?? ?? 48 85 DB 0F 85 ?? ?? ?? ?? 31 C0 48 8B 9C 24 ?? ?? ?? ?? 48 8B 4C - 24 ?? 48 8D 3D ?? ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 D9 48 89 C3 48 8B 84 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 85 - DB 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? BB ?? ?? ?? ?? 48 89 D9 31 FF 48 8B 74 - 24 ?? 4C 8B 84 24 ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? ?? 4C 8B 94 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 66 0F 1F 44 00 ?? 48 85 DB 0F - 85 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 C3 48 8D 0D ?? ?? ?? ?? 48 8B BC 24 ?? - ?? ?? ?? 31 F6 45 31 C0 4D 89 C1 48 8D 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 9C 24 ?? - ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 84 24 - ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 85 C0 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? - ?? 31 DB 31 C9 E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 85 - DB 74 ?? 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC - 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 48 8B 94 24 ?? ?? ?? ?? 48 8B 72 ?? 48 8B 42 - ?? 48 8B 56 ?? 31 DB 31 C9 48 89 CF FF D2 48 8B 15 ?? ?? ?? ?? 48 89 CF 48 89 D9 48 - } - $encrypt_files_p4 = { - 89 C3 48 89 D0 E8 ?? ?? ?? ?? 48 89 D9 48 89 C3 48 8B 84 24 ?? ?? ?? ?? 0F 1F 40 ?? - E8 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 90 E8 ?? ?? ?? ?? 48 - 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? - ?? ?? C3 90 0F 1F 40 ?? E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? - ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? - ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 - E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? - ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? - ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 - 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? - C3 90 66 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC - 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 - 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? - ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 - ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 - 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? - ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 90 66 90 - E8 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? - ?? 48 81 C4 ?? ?? ?? ?? C3 48 89 44 24 ?? 48 89 5C 24 ?? 48 89 4C 24 ?? 48 89 7C 24 - ?? E8 - } - $find_files_p1 = { - 4C 8D A4 24 ?? ?? ?? ?? 4D 3B 66 ?? 0F 86 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 89 AC - 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? - ?? 48 89 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 85 DB 7E ?? 48 89 5C 24 ?? 31 C9 EB ?? - 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 48 8B 9C 24 ?? ?? ?? ?? 48 8D 43 ?? - 48 89 4C 24 ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 10 48 89 54 24 ?? 48 8B 58 ?? 48 89 5C - 24 ?? 48 8B 72 ?? 48 89 D8 FF D6 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 - 8B 8C 24 ?? ?? ?? ?? 48 8D 3D ?? ?? ?? ?? BE ?? ?? ?? ?? 49 89 C0 49 89 D9 31 C0 48 - 8B 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 5C 24 ?? 48 8B 4C 24 ?? 48 - 8B 51 ?? 48 8B 44 24 ?? FF D2 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 8D - 4B ?? 66 90 E9 ?? ?? ?? ?? 48 29 CB 48 89 DA 48 F7 DB 48 C1 FB ?? 48 21 D9 48 01 C1 - 48 89 8C 24 ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? EB ?? 31 D2 31 C9 48 89 C8 48 89 D3 - E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? - 48 8B 3D ?? ?? ?? ?? 48 8B 35 ?? ?? ?? ?? 66 90 E8 ?? ?? ?? ?? 84 C0 74 ?? 48 8D BC - 24 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? ?? 0F 1F 84 00 ?? ?? ?? ?? 48 89 6C 24 ?? 48 8D 6C - } - $find_files_p2 = { - 24 ?? E8 ?? ?? ?? ?? 48 8B 6D ?? 48 8D 84 24 ?? ?? ?? ?? 31 C9 0F 1F 00 E9 ?? ?? ?? - ?? 48 8B 4C 24 ?? 48 8B 49 ?? 48 8B 44 24 ?? FF D1 84 C0 74 ?? 48 8B 44 24 ?? 48 8B - 5C 24 ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 FF C1 48 8B 54 24 - ?? 0F 1F 00 48 39 CA 0F 8F ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 FF C9 48 85 C9 0F 8C ?? ?? - ?? ?? 0F B6 14 08 66 90 80 FA ?? 0F 84 ?? ?? ?? ?? 80 FA ?? 0F 84 ?? ?? ?? ?? 80 FA - ?? 75 ?? E9 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8D 42 ?? 48 89 4C 24 ?? 48 89 84 - 24 ?? ?? ?? ?? 48 8B 10 48 89 54 24 ?? 48 8B 70 ?? 48 89 74 24 ?? 48 8B 5C 24 ?? 48 - 8B 44 24 ?? E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 8B 44 - 24 ?? 48 8B 5C 24 ?? E8 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? - 48 89 DF 48 89 D3 48 89 C2 48 89 C8 48 89 D1 E8 ?? ?? ?? ?? 0F 1F 84 00 ?? ?? ?? ?? - 48 85 C0 0F 8D ?? ?? ?? ?? 48 8B 4C 24 ?? 48 FF C1 48 83 F9 ?? 0F 8C ?? ?? ?? ?? 48 - 8B 4C 24 ?? 48 89 8C 24 ?? ?? ?? ?? 48 8B 54 24 ?? 48 89 94 24 ?? ?? ?? ?? 48 8B 84 - 24 ?? ?? ?? ?? 48 8D 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 89 44 24 ?? - 48 89 5C 24 ?? 48 89 4C 24 ?? 66 90 E8 - } - $kill_procs_p1 = { - 4C 8D A4 24 ?? ?? ?? ?? 4D 3B 66 ?? 0F 86 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 89 AC - 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 90 E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 - 89 5C 24 ?? 31 C9 66 90 EB ?? 48 8B 54 24 ?? 48 8D 4A ?? 48 8B 84 24 ?? ?? ?? ?? 48 - 8B 5C 24 ?? 0F 1F 84 00 ?? ?? ?? ?? 48 39 CB 0F 8E ?? ?? ?? ?? 48 89 4C 24 ?? 48 C1 - E1 ?? 48 8B 1C 08 48 89 5C 24 ?? 48 8B 4C 08 ?? 48 89 4C 24 ?? 48 8B 73 ?? 48 89 C8 - FF D6 48 89 1D ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 75 ?? 48 89 05 ?? ?? ?? ?? EB ?? 48 - 8D 3D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B 49 ?? 48 8B 44 24 ?? FF D1 48 - 89 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 8B - 3D ?? ?? ?? ?? 48 89 C3 48 8D 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 - 89 08 48 8D BC 24 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 48 A5 48 8D BC - 24 ?? ?? ?? ?? 48 8D 7F ?? 48 89 6C 24 ?? 48 8D 6C 24 ?? E8 ?? ?? ?? ?? 48 8B 6D ?? - 48 8D 05 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - EB ?? 48 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 48 8D 84 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 66 0F 1F 84 00 ?? ?? 00 00 48 85 C9 0F 84 ?? ?? ?? - ?? 48 8B 94 24 ?? ?? ?? ?? 48 8B 12 48 89 54 24 ?? 48 8B 01 48 89 44 24 ?? 48 8B 59 - ?? 48 89 5C 24 ?? 48 8D 8C 24 ?? ?? ?? ?? 31 F6 EB ?? 48 8B 94 24 ?? ?? ?? ?? 48 83 - } - $kill_procs_p2 = { - C2 ?? 48 8B 44 24 ?? 48 8B 5C 24 ?? 48 89 CE 48 89 D1 48 89 74 24 ?? 48 89 8C 24 ?? - ?? ?? ?? 48 8B 11 48 89 54 24 ?? 48 8B 79 ?? 48 89 7C 24 ?? E8 ?? ?? ?? ?? 48 8B 4C - 24 ?? 48 8B 7C 24 ?? 90 E8 ?? ?? ?? ?? 48 85 C0 0F 8C ?? ?? ?? ?? 48 8B 44 24 ?? BB - ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 48 89 C7 48 89 DE 31 C0 48 8D 1D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 44 0F 11 39 48 8D 94 24 ?? ?? ?? ?? 44 0F - 11 3A 48 8D 15 ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? - ?? 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? BB ?? ?? ?? - ?? BF ?? ?? ?? ?? 48 89 FE E8 ?? ?? ?? ?? 48 89 44 24 ?? 44 0F 11 BC 24 ?? ?? ?? ?? - 48 8D 0D ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 1D ?? ?? - ?? ?? BF ?? ?? ?? ?? 48 89 FE 48 8D 05 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 48 8B 44 24 ?? 90 E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 FF C1 48 83 F9 ?? 0F 8C ?? - ?? ?? ?? E9 ?? ?? ?? ?? 0F 1F 40 ?? E8 - } + $a = "nexuszetaisacrackaddict" condition: - uint16(0)==0x5A4D and ( all of ($kill_procs_p*)) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Atlas : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_D2205527 : FILE MEMORY { meta: - description = "Yara rule that detects Atlas ransomware." - author = "ReversingLabs" - id = "2c702b24-4b7e-505c-a694-0d915cc47315" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Atlas.yara#L1-L99" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "1486f931ec096a00d913de0568ddd8aa5a091256445bc28aba90e3e194ebd045" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "d2205527-0545-462b-b3c9-3bf2bdc44c6c" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L930-L948" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "e4f584d1f75f0d7c98b325adc55025304d55907e8eb77b328c007600180d6f06" + logic_hash = "172ba256873cce61047a5198733cacaff4ef343c9cbd76f2fbbf0e1ed8003236" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Atlas" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "01d937fe8823e5f4764dea9dfe2d8d789187dcd6592413ea48e13f41943d67fd" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files = { - 8B 74 24 ?? 8B 3D ?? ?? ?? ?? 8D 4C 24 ?? 6A ?? 51 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 52 56 FF D7 8B 94 24 ?? ?? ?? ?? 8D 44 24 ?? 8D 8C 24 ?? ?? ?? ?? 50 8B 84 24 ?? - ?? ?? ?? 51 52 50 E8 ?? ?? ?? ?? 8B 54 24 ?? 83 C4 ?? 8D 4C 24 ?? 8D 84 24 ?? ?? ?? - ?? 6A ?? 51 8B 4C 24 ?? 52 50 51 FF 15 ?? ?? ?? ?? 8D 54 24 ?? 6A ?? 52 55 53 56 FF - D7 8B 7C 24 ?? 33 C9 3B FD 89 4C 24 ?? 0F 85 ?? ?? ?? ?? EB ?? 8B 4C 24 ?? 33 F6 8A - 84 34 ?? ?? ?? ?? 02 C1 F6 E9 88 44 34 ?? 8A 84 34 ?? ?? ?? ?? 02 C1 F6 E9 88 44 34 - ?? 46 83 FE ?? 7C ?? 8B 74 24 ?? 57 56 8D 44 24 ?? 53 8D 8C 24 ?? ?? ?? ?? 50 51 E8 - ?? ?? ?? ?? 8B 54 24 ?? 8D 84 24 ?? ?? ?? ?? 52 53 56 8D 8C 24 ?? ?? ?? ?? 50 51 E8 - ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 83 C4 ?? 8D 54 24 ?? 6A ?? 52 50 53 51 FF 15 ?? - ?? ?? ?? 8B 44 24 ?? 8D 54 24 ?? 6A ?? 52 55 53 50 FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 8B - 7C 24 ?? 41 3B FD 89 4C 24 ?? 0F 84 ?? ?? ?? ?? 8B 74 24 ?? 85 FF 74 ?? 8B 54 24 ?? - 8D 4C 24 ?? 6A ?? 51 57 53 52 FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 8B 44 24 - ?? 50 FF D6 8B 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 53 FF D6 8B 4C 24 ?? 68 ?? ?? ?? - ?? 6A ?? 51 FF D6 5F 5E 5D 33 C0 5B 81 C4 ?? ?? ?? ?? C3 - } - $remote_server_1 = { - 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 F6 33 C9 8D 94 24 ?? ?? ?? ?? 8A 0C 2E - 8D 84 24 ?? ?? ?? ?? 51 52 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 46 81 FE ?? ?? - ?? ?? 7C ?? 8D 8C 24 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 52 E8 ?? ?? - ?? ?? 83 C4 ?? 33 F6 33 C0 8D 8C 24 ?? ?? ?? ?? 8A 04 1E 8D 94 24 ?? ?? ?? ?? 50 51 - 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 46 81 FE ?? ?? ?? ?? 7C ?? 8D 84 24 ?? ?? - ?? ?? 8D BC 24 ?? ?? ?? ?? 50 83 C9 ?? 33 C0 33 F6 F2 AE F7 D1 49 51 8D 8C 24 ?? ?? - ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 83 FE ?? - 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 46 FF 15 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? 83 C9 ?? - 33 C0 8D 94 24 ?? ?? ?? ?? F2 AE F7 D1 49 52 8D 84 24 ?? ?? ?? ?? 51 50 68 ?? ?? ?? - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? BE ?? ?? ?? ?? 8D 84 24 ?? ?? - ?? ?? 8A 10 8A 1E 8A CA 3A D3 75 ?? 84 C9 74 ?? 8A 50 ?? 8A 5E ?? 8A CA 3A D3 75 ?? - 83 C0 ?? 83 C6 ?? 84 C9 75 ?? 33 C0 EB - } - $remote_server_2 = { - 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? BB ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 51 2B D8 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 52 03 D8 E8 ?? ?? ?? ?? 8B CB 8B F0 8B C1 83 C6 ?? 8D BC 24 ?? ?? ?? ?? 83 C4 - ?? C1 E9 ?? F3 A5 8B C8 68 ?? ?? ?? ?? 83 E1 ?? 68 ?? ?? ?? ?? F3 A4 8D 8C 24 ?? ?? - ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 94 24 ?? ?? ?? ?? BB - ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 2B D8 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? - ?? ?? ?? 03 D8 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B CB 8B F0 8B - D1 BF ?? ?? ?? ?? C1 E9 ?? F3 A5 83 C4 ?? 8B CA 83 E1 ?? 8D 84 24 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? F3 A4 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - BB ?? ?? ?? ?? 2B D8 68 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? - ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 03 D8 E8 ?? - ?? ?? ?? 8B CB 8B F0 8B C1 83 C6 ?? BF ?? ?? ?? ?? 68 ?? ?? ?? ?? C1 E9 ?? F3 A5 8B - C8 68 ?? ?? ?? ?? 83 E1 ?? F3 A4 E8 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? 83 C9 ?? 33 C0 - 83 C4 ?? F2 AE F7 D1 49 83 F9 ?? 0F 82 ?? ?? ?? ?? 33 F6 8D BC 24 ?? ?? ?? ?? 8D 8C - 34 ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 46 83 C7 ?? 81 FE ?? ?? - ?? ?? 72 ?? 8B 3D ?? ?? ?? ?? FF D7 8D 94 24 ?? ?? ?? ?? 56 52 8B E8 E8 ?? ?? ?? ?? - 83 C4 ?? FF D7 8B F0 8D 44 24 ?? 50 2B F5 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 4C 24 ?? 8D 94 24 ?? ?? ?? ?? 51 56 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? - 8D 84 24 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? 50 83 C9 ?? 33 C0 F2 AE F7 D1 49 51 8D 8C - 24 ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 - } - $send_post_packet = { - 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 83 - FE ?? 89 75 ?? 75 ?? 50 E8 ?? ?? ?? ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 5F 5E 5B - 8B E5 5D C3 6A ?? 66 C7 45 ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 66 89 45 ?? 52 E8 ?? ?? - ?? ?? 89 45 ?? 8D 45 ?? 6A ?? 50 56 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 56 E8 ?? ?? ?? ?? - 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 8D BD ?? ?? ?? ?? 83 C9 ?? - 33 C0 6A ?? F2 AE F7 D1 49 51 8D 8D ?? ?? ?? ?? 51 56 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? - 56 E8 ?? ?? ?? ?? 33 C0 8B 4D ?? 64 89 0D ?? ?? ?? ?? 5F 5E 5B 8B E5 5D C3 - } - $send_get_request = { - 68 ?? ?? ?? ?? 55 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 8B D8 83 - FB ?? 75 ?? 68 ?? ?? ?? ?? 6A ?? 55 FF 15 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 5F 5E 5D 33 - C0 5B 81 C4 ?? ?? ?? ?? C3 6A ?? 66 C7 44 24 ?? ?? ?? E8 ?? ?? ?? ?? 8D 54 24 ?? 66 - 89 44 24 ?? 52 E8 ?? ?? ?? ?? 89 44 24 ?? 8D 44 24 ?? 6A ?? 50 53 E8 ?? ?? ?? ?? 83 - F8 ?? 75 ?? 68 ?? ?? ?? ?? 6A ?? 55 FF 15 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 5F 5E 5D 33 - C0 5B 81 C4 ?? ?? ?? ?? C3 8B FD 83 C9 ?? 33 C0 6A ?? F2 AE F7 D1 49 51 55 53 E8 ?? - ?? ?? ?? 83 F8 ?? 75 ?? 68 ?? ?? ?? ?? 6A ?? 55 FF 15 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? - 5F 5E 5D 33 C0 5B 81 C4 ?? ?? ?? ?? C3 - } + $a = { CA B8 37 00 00 00 0F 05 48 3D 01 F0 FF FF 73 01 C3 48 C7 C1 C0 FF } condition: - uint16(0)==0x5A4D and $encrypt_files and $remote_server_1 and $remote_server_2 and $send_post_packet and $send_get_request + all of them } -rule REVERSINGLABS_Win32_Ransomware_Kangaroo : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Ab073861 : FILE MEMORY { meta: - description = "Yara rule that detects Kangaroo ransomware." - author = "ReversingLabs" - id = "ec4342c1-adc9-5ddb-b403-83c2b1ce5899" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Kangaroo.yara#L1-L91" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "1078fb3d47ad737548419e5ee66e686f705c02fea27a58c0097446547325772c" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "ab073861-38df-4a39-ab81-8451b6fab30c" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L950-L968" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "175444a9c9ca78565de4b2eabe341f51b55e59dec00090574ee0f1875422cbac" + logic_hash = "251b92c4fec9d113025c6869c279247a3dd16ee094c8861fe43a33f87132bf75" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Kangaroo" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "37ab5e3ccc9a91c885bff2b1b612efbde06999e83ff5c5cd330bd3a709a831f5" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 83 EC ?? 53 55 8B 6C 24 ?? 56 57 33 FF 57 57 6A ?? 57 6A ?? 68 ?? ?? ?? ?? 33 DB 55 - 89 5C 24 ?? 89 7C 24 ?? 89 7C 24 ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 0F 84 ?? ?? ?? - ?? 8D 44 24 ?? 50 8D 4C 24 ?? 51 8D 54 24 ?? 52 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 6A ?? 68 ?? ?? ?? ?? 57 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? - 8B 54 24 ?? 8D 4C 24 ?? 51 57 57 68 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 - ?? ?? ?? ?? 57 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 03 C0 50 8B 44 24 ?? 68 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B 54 24 ?? 8B 44 24 ?? 8D 4C 24 ?? - 51 6A ?? 52 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 57 56 FF - 15 ?? ?? ?? ?? 8B 54 24 ?? 57 8D 4C 24 ?? 51 57 57 6A ?? 57 52 89 44 24 ?? FF 15 ?? - ?? ?? ?? 8B 44 24 ?? 6A ?? 68 ?? ?? ?? ?? 50 57 8B 3D ?? ?? ?? ?? FF D7 8B 54 24 - } - $encrypt_files_p2 = { - 6A ?? 8D 4C 24 ?? 51 52 8B D8 53 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 8B - 44 24 ?? 8B 54 24 ?? 50 8D 4C 24 ?? 51 53 6A ?? 6A ?? 6A ?? 52 FF 15 ?? ?? ?? ?? 83 - F8 ?? 0F 85 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? - 8B 4C 24 ?? 6A ?? 8D 44 24 ?? 50 51 53 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 8D 54 24 - ?? 52 8D 44 24 ?? 50 8D 4C 24 ?? 51 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF D7 68 ?? ?? ?? ?? 55 8B F8 68 ?? ?? ?? ?? 57 - FF 15 ?? ?? ?? ?? 83 C4 ?? 57 55 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 FF 15 ?? - ?? ?? ?? 8B C5 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 53 FF 15 - ?? ?? ?? ?? 8B 54 24 ?? 52 FF 15 ?? ?? ?? ?? 8B 5C 24 ?? 33 FF 8B 44 24 ?? 50 FF 15 - ?? ?? ?? ?? 89 7C 24 ?? 8B 4C 24 ?? 57 51 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 5F - 5E 5D 8B C3 5B 83 C4 ?? C3 - } - $find_files = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 8B 75 ?? 57 56 FF 15 ?? ?? ?? ?? 8B 3D ?? - ?? ?? ?? 33 C9 83 F8 ?? 0F 94 C1 56 8D 94 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 89 4C 24 - ?? FF D7 83 C4 ?? 8D 44 24 ?? 50 8D 8C 24 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 89 44 24 - ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? EB ?? EB ?? 8D A4 24 ?? ?? ?? ?? 90 - 8B 3D ?? ?? ?? ?? 83 7C 24 ?? ?? 75 ?? 8D 54 24 ?? 52 56 68 ?? ?? ?? ?? 8D 84 24 ?? - ?? ?? ?? 50 EB ?? 8D 4C 24 ?? 51 56 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 FF D7 83 - C4 ?? F6 44 24 ?? ?? 74 ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D7 85 - C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4C 24 ?? 51 FF D7 85 C0 0F 84 ?? ?? ?? ?? 8D - 94 24 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 33 FF 33 F6 EB ?? 8D 9B - ?? ?? ?? ?? 8B 86 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? 51 FF D3 85 C0 74 ?? BF ?? ?? - ?? ?? 83 C6 ?? 83 FE ?? 72 ?? 68 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 FF D3 85 C0 75 - ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D3 85 C0 74 ?? BF ?? ?? ?? ?? 8B 44 24 - ?? A8 ?? 75 ?? A9 ?? ?? ?? ?? 75 ?? 85 FF 75 ?? 3D ?? ?? ?? ?? 74 ?? 68 ?? ?? ?? ?? - 8D 8C 24 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 75 ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 8C - 24 ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B 75 ?? 8B 44 24 ?? 8D 54 24 ?? 52 50 FF 15 ?? - ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 4C 24 ?? 51 FF 15 ?? ?? ?? ?? 5F 5E 5B 8B E5 5D - C3 - } - $enum_resources = { - 55 8B EC 83 E4 ?? 83 EC ?? 8B 4D ?? 53 56 57 8D 44 24 ?? 50 51 6A ?? 6A ?? 6A ?? C7 - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5F 5E - 5B 8B E5 5D C2 ?? ?? 8B 54 24 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 8B D8 85 DB 74 ?? 8B 4C - 24 ?? 8B C3 85 C9 74 ?? 8D 64 24 ?? C6 00 ?? 40 83 E9 ?? 75 ?? 8B 54 24 ?? 8D 44 24 - ?? 50 53 8D 4C 24 ?? 51 52 E8 ?? ?? ?? ?? 85 C0 75 ?? 33 FF 39 7C 24 ?? 76 ?? 8D 73 - ?? 8D 49 ?? 83 7E ?? ?? 75 ?? 8B 06 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4E ?? 83 E1 ?? 80 - F9 ?? 75 ?? 8D 56 ?? 52 E8 ?? ?? ?? ?? 47 83 C6 ?? 3B 7C 24 ?? 72 ?? EB ?? 3D ?? ?? - ?? ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 8B 44 24 ?? 50 E8 ?? ?? ?? ?? 5F 5E B8 ?? ?? ?? ?? - 5B 8B E5 5D C2 - } + $a = { AC 00 00 00 54 60 00 00 50 E8 4E 0C 00 00 EB 0E 5A 58 59 97 60 8A 54 } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($enum_resources) + all of them } -rule REVERSINGLABS_Win64_Ransomware_Blackbasta : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_637F2C04 : FILE MEMORY { meta: - description = "Yara rule that detects BlackBasta ransomware." - author = "ReversingLabs" - id = "7a4ad567-0612-5a9c-8a06-4d615bc7e24a" - date = "2022-12-13" - modified = "2022-12-13" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.BlackBasta.yara#L1-L293" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "79c81a4470e9eabbd714b1a91621c7b2bbe42d5371ba2c799529662d5f5c479a" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "637f2c04-98e4-45aa-b60a-14a96c6cebb7" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L970-L987" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "cff4aa6c613ccc64f64441f7e40f79d3a22b5c12856c32814545bd41d5f112bd" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "BlackBasta" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "7af3d573af8b7f8252590a53adda52ecf53bdaf9a86b52ef50702f048e08ba8c" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files = { - 48 8B 44 24 ?? 83 A0 ?? ?? ?? ?? ?? 44 8B C9 EB ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 44 38 - 75 ?? 74 ?? 48 8B 44 24 ?? 83 A0 ?? ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? EB ?? 44 38 75 ?? - 74 ?? 48 8B 44 24 ?? 83 A0 ?? ?? ?? ?? ?? 45 8B CE 4C 8D 44 24 ?? 48 8B CF 48 8D 54 - 24 ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 4C 8D 45 ?? 85 C0 44 89 74 24 ?? 4C 89 74 24 ?? - 49 0F 45 CE 45 33 C9 33 D2 FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 75 ?? 4D 8B CC 45 - 33 C0 33 D2 48 8B CF E8 ?? ?? ?? ?? 8B D8 44 38 74 24 ?? 74 ?? 48 8B 4C 24 ?? E8 ?? - ?? ?? ?? 8B C3 E9 ?? ?? ?? ?? 49 8B 74 24 ?? 49 2B 34 24 48 C1 FE ?? 33 D2 4C 89 75 - ?? 48 8D 4D ?? 4C 89 75 ?? 4C 89 75 ?? 4C 89 75 ?? 4C 89 75 ?? 44 88 75 ?? E8 ?? ?? - ?? ?? 48 8B 45 ?? B9 ?? ?? ?? ?? 39 48 ?? 75 ?? 44 38 75 ?? 74 ?? 48 8B 45 ?? 83 A0 - ?? ?? ?? ?? ?? 44 8B C9 EB ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 44 38 75 ?? 74 ?? 48 8B 45 - ?? 83 A0 ?? ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? EB ?? 44 38 75 ?? 74 ?? 48 8B 45 ?? 83 A0 - ?? ?? ?? ?? ?? 45 8B CE 4C 8D 44 24 ?? 48 8D 55 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 4C 8B - 75 ?? 33 D2 85 C0 49 8B CE 48 0F 45 CA 80 39 ?? 75 ?? 8A 41 ?? 84 C0 75 ?? 38 55 ?? - 74 ?? 49 8B CE E8 ?? ?? ?? ?? EB ?? 3C ?? 75 ?? 38 51 ?? 74 ?? 4D 8B CC 4D 8B C5 48 - 8B D7 E8 ?? ?? ?? ?? 44 8B E8 85 C0 75 ?? 38 45 ?? 74 ?? 49 8B CE E8 ?? ?? ?? ?? 4C - 8B 6C 24 ?? 48 8D 55 ?? 48 8B CB FF 15 ?? ?? ?? ?? 45 33 F6 85 C0 0F 85 ?? ?? ?? ?? - 49 8B 04 24 49 8B 54 24 ?? 48 2B D0 48 C1 FA ?? 48 3B F2 74 ?? 48 2B D6 48 8D 0C F0 - 4C 8D 0D ?? ?? ?? ?? 45 8D 46 ?? E8 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 44 38 74 - 24 ?? 74 ?? 48 8B 4C 24 - } - $find_system_volumes_v1_p1 = { - 48 89 4C 24 ?? 55 53 56 57 41 56 41 57 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? - 48 8B F1 45 33 FF 44 89 7C 24 ?? 4C 89 39 4C 89 79 ?? 4C 89 79 ?? C7 44 24 ?? ?? ?? - ?? ?? BA ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 4C 8B F0 0F 1F 00 4C 8D 8D ?? - ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 44 89 7C 24 ?? 4C 89 7C 24 ?? 48 8D 85 ?? ?? ?? ?? 48 89 44 24 - ?? 4C 89 7C 24 ?? 45 33 C9 45 33 C0 33 D2 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? F7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 48 8D 14 00 48 8D BD ?? ?? ?? ?? 48 03 FA 4C 89 7C 24 ?? 4C 89 - 7C 24 ?? 4C 89 7C 24 ?? 4C 89 7C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? 48 - 8D 9D ?? ?? ?? ?? 48 D1 FA 48 83 FA ?? 72 ?? 45 33 C0 48 8D 4C 24 ?? E8 - } - $find_system_volumes_v1_p2 = { - 4C 89 7C 24 ?? 48 8D 44 24 ?? 48 89 85 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 3B C7 74 - ?? 66 66 66 0F 1F 84 00 ?? ?? 00 00 44 0F B6 0B 48 8B 4C 24 ?? 48 8B 54 24 ?? 48 3B - CA 73 ?? 48 8D 41 ?? 48 89 44 24 ?? 48 8D 44 24 ?? 48 83 FA ?? 48 0F 43 44 24 ?? 44 - 88 0C 08 C6 44 08 ?? ?? EB ?? 45 33 C0 41 8D 50 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 - 83 C3 ?? 48 3B DF 75 ?? 4C 89 BD ?? ?? ?? ?? 48 8B 46 ?? 48 3B 46 ?? 74 ?? 4C 89 38 - 4C 89 78 ?? 4C 89 78 ?? 41 B8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B C8 E8 ?? ?? ?? ?? 4C - 89 7C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? C6 44 24 ?? ?? 48 83 46 ?? ?? EB ?? 4C 8D 44 - 24 ?? 48 8B D0 48 8B CE E8 ?? ?? ?? ?? 90 48 8B 54 24 ?? 48 83 FA ?? 72 ?? 48 FF C2 - 48 8B 4C 24 ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 - 48 83 C0 ?? 48 83 F8 ?? 77 ?? E8 ?? ?? ?? ?? 4C 89 7C 24 ?? 48 C7 44 24 ?? ?? ?? ?? - ?? C6 44 24 ?? ?? 41 B8 ?? ?? ?? ?? 48 8D 54 24 ?? 49 8B CE FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? 49 8B CE FF 15 ?? ?? ?? ?? 48 8B C6 48 81 C4 - } - $set_default_icon_p1 = { - 48 89 5C 24 ?? 48 89 4C 24 ?? 55 56 57 41 54 41 55 41 56 41 57 48 81 EC ?? ?? ?? ?? - 48 8B F1 45 33 ED 44 89 6C 24 ?? 4C 8B 35 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 4C 8B F8 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 8B C8 49 2B CE 49 3B CF 0F 82 ?? ?? - ?? ?? 4C 8D 25 ?? ?? ?? ?? 48 83 3D ?? ?? ?? ?? ?? 4C 0F 43 25 ?? ?? ?? ?? 4C 89 6C - 24 ?? 4C 89 6C 24 ?? 4C 89 6C 24 ?? 4B 8D 2C 37 BB ?? ?? ?? ?? 48 8D 7C 24 ?? 48 3B - EB 0F 86 ?? ?? ?? ?? 48 8B DD 48 83 CB ?? 48 3B D8 76 ?? 48 8B D8 48 B8 ?? ?? ?? ?? - ?? ?? ?? ?? 48 8D 0C 00 EB ?? B8 ?? ?? ?? ?? 48 3B D8 48 0F 42 D8 48 8D 4B ?? 48 B8 - ?? ?? ?? ?? ?? ?? ?? ?? 48 3B C8 0F 87 ?? ?? ?? ?? 48 03 C9 48 81 F9 ?? ?? ?? ?? 72 - ?? 48 8D 41 ?? 48 3B C1 0F 86 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? - ?? ?? ?? 48 8D 78 ?? 48 83 E7 ?? 48 89 47 ?? EB ?? 48 85 C9 74 ?? E8 ?? ?? ?? ?? 48 - 8B F8 EB ?? 49 8B FD 48 89 7C 24 ?? 48 89 6C 24 ?? 48 89 5C 24 ?? 4B 8D 1C 36 4C 8B - } - $set_default_icon_p2 = { - C3 49 8B D4 48 8B CF E8 ?? ?? ?? ?? 48 8D 0C 3B 4F 8D 04 3F 48 8D 15 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 66 44 89 2C 6F BB ?? ?? ?? ?? 89 5C 24 ?? 48 8D 54 24 ?? 48 83 7C 24 ?? - ?? 48 0F 43 54 24 ?? 48 8D 84 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 84 24 ?? ?? ?? ?? - 48 89 44 24 ?? 4C 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 44 89 6C 24 ?? 45 33 C9 45 33 - C0 48 C7 C1 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 48 8B CE 48 83 7E ?? ?? 72 ?? - 48 8B 0E 8B 46 ?? 03 C0 89 44 24 ?? 48 89 4C 24 ?? 44 8B CB 45 33 C0 48 8D 15 ?? ?? - ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 45 33 C9 45 33 C0 33 D2 B9 ?? ?? ?? - ?? FF 15 ?? ?? ?? ?? 45 33 C9 45 33 C0 BA ?? ?? ?? ?? B9 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? EB ?? 4C 89 6C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 4C 24 - ?? 45 33 C9 44 8B C0 33 D2 B9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 E3 ?? 89 5C 24 ?? 48 - 8B 54 24 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B C1 48 81 - FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 77 ?? - E8 ?? ?? ?? ?? 4C 89 6C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 66 44 89 6C 24 ?? 48 8B CE - E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5E 41 5D 41 5C - 5F 5E 5D C3 - } - $cmd_prompt = { - 48 89 5C 24 ?? 48 89 7C 24 ?? 55 48 8B EC 48 83 EC ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 - 48 89 45 ?? 48 8B D9 4C 8D 05 ?? ?? ?? ?? 33 FF 48 8D 4D ?? 33 D2 48 89 7D ?? E8 ?? - ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 48 85 DB 75 ?? 48 8B 4D ?? 48 85 C9 0F 84 ?? ?? - ?? ?? 33 D2 E8 ?? ?? ?? ?? 48 8B 4D ?? 8B D8 E8 ?? ?? ?? ?? 85 DB 40 0F 94 C7 E9 ?? - ?? ?? ?? 48 8B 45 ?? 48 8D 0D ?? ?? ?? ?? 48 89 45 ?? 48 89 4D ?? 48 89 5D ?? 48 89 - 7D ?? 48 85 C0 74 ?? E8 ?? ?? ?? ?? 8B 18 E8 ?? ?? ?? ?? 45 33 C9 4C 8D 45 ?? 33 C9 - 89 38 48 8B 55 ?? E8 ?? ?? ?? ?? 48 8B F8 83 F8 ?? 74 ?? E8 ?? ?? ?? ?? 89 18 EB ?? - E8 ?? ?? ?? ?? 83 38 ?? 74 ?? E8 ?? ?? ?? ?? 83 38 ?? 74 ?? 48 8B 4D ?? E8 ?? ?? ?? - ?? 83 CF ?? EB ?? E8 ?? ?? ?? ?? 89 18 48 8D 15 ?? ?? ?? ?? 45 33 C9 4C 8D 45 ?? 48 - 89 55 ?? 33 C9 E8 ?? ?? ?? ?? 48 8B F8 48 8B 4D ?? E8 ?? ?? ?? ?? 8B C7 48 8B 4D ?? - 48 33 CC E8 ?? ?? ?? ?? 4C 8D 5C 24 ?? 49 8B 5B ?? 49 8B 7B ?? 49 8B E3 5D C3 - } - $exclude_from_encryption = { - 66 89 75 ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D - 4D ?? E8 ?? ?? ?? ?? 90 45 33 C0 48 8D 55 ?? 48 8B CB E8 ?? ?? ?? ?? 48 8B F8 48 8B - 55 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4D ?? 48 8B C1 48 81 FA ?? ?? - ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 48 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? 66 89 75 ?? 48 83 FF ?? 0F 85 - ?? ?? ?? ?? 48 89 75 ?? 48 89 75 ?? 48 89 75 ?? 48 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? - 66 89 75 ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D - 4D ?? E8 ?? ?? ?? ?? 90 45 33 C0 48 8D 55 ?? 48 8B CB E8 ?? ?? ?? ?? 48 8B F8 48 8B - 55 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4D ?? 48 8B C1 48 81 FA ?? ?? - ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 48 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? 66 89 75 ?? 48 83 FF ?? 0F 85 - ?? ?? ?? ?? 48 89 75 ?? 48 89 75 ?? 48 89 75 ?? 48 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? - 66 89 75 ?? 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D - 4D ?? E8 ?? ?? ?? ?? 90 45 33 C0 48 8D 55 ?? 48 8B CB E8 ?? ?? ?? ?? 48 8B F8 48 8B - 55 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4D ?? 48 8B C1 48 81 FA ?? ?? - ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 - } - $encrypt_files_v1 = { - 41 83 CC ?? 44 89 64 24 ?? 48 8D 8C 24 ?? ?? ?? ?? 48 83 FF ?? 48 0F 43 8C 24 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 8B F8 41 83 E4 ?? 44 89 64 24 ?? 48 8B 94 24 ?? ?? ?? ?? 48 - 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? - ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 89 94 24 ?? ?? ?? ?? 48 8B 49 - ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 9C 24 ?? - ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 9C 24 ?? ?? 00 00 40 F6 C7 ?? 74 - ?? 49 8B CF E8 ?? ?? ?? ?? 90 48 BE ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 3D ?? ?? ?? ?? 4C - 8D 35 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? E9 ?? ?? ?? ?? 49 8B CF E8 ?? ?? ?? ?? C6 84 - 24 ?? ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B F0 48 - 89 9C 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 4C 8B 70 ?? 48 - 83 78 ?? ?? 72 ?? 48 8B 30 48 8D 8C 24 ?? ?? ?? ?? 49 83 FE ?? 73 ?? 41 B8 ?? ?? ?? - ?? 48 8B D6 E8 ?? ?? ?? ?? 4C 89 B4 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? - ?? EB ?? 4C 89 AC 24 ?? ?? ?? ?? 49 8B FE 48 83 CF ?? 48 89 BC 24 ?? ?? ?? ?? 49 3B - FD 49 0F 47 FD 48 8D 57 ?? E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 4E 8D 04 75 ?? ?? - ?? ?? 48 8B D6 48 8B C8 E8 ?? ?? ?? ?? 4C 89 B4 24 ?? ?? ?? ?? 48 89 BC 24 - } - $find_system_volumes_v2 = { - BA ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 48 8B F8 0F 1F 44 00 ?? 4C 8D 8D ?? - ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? 89 74 24 ?? 48 89 74 24 ?? 48 8D 85 ?? ?? ?? ?? 48 89 44 24 ?? - 48 89 74 24 ?? 45 33 C9 45 33 C0 33 D2 48 8D 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 - 0F 84 ?? ?? ?? ?? F7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 4C 8D 04 00 48 8D 85 ?? ?? ?? ?? 49 03 C0 48 89 74 24 ?? 48 89 74 - 24 ?? 48 89 74 24 ?? 48 89 74 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 66 89 74 24 ?? 48 8D - 8D ?? ?? ?? ?? 48 3B C8 74 ?? 49 D1 F8 48 8D 95 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? - ?? ?? 90 48 8B 43 ?? 48 3B 43 ?? 74 ?? 48 89 30 48 89 70 ?? 48 89 70 ?? 41 B8 ?? ?? - ?? ?? 48 8D 54 24 ?? 48 8B C8 E8 ?? ?? ?? ?? 48 89 74 24 ?? 48 C7 44 24 ?? ?? ?? ?? - ?? 66 89 74 24 ?? 48 83 43 ?? ?? EB ?? 4C 8D 44 24 ?? 48 8B D0 48 8B CB E8 ?? ?? ?? - ?? 90 48 8B 54 24 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 8B - C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 - ?? 77 ?? E8 ?? ?? ?? ?? 48 89 74 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 66 89 74 24 ?? 41 - B8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 8B CF FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 - 8B CF FF 15 ?? ?? ?? ?? 48 8B C3 48 8B 9C 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5F 5E - 5D C3 - } - $drop_ransom_note = { - 48 83 3D ?? ?? ?? ?? ?? 48 0F 43 15 ?? ?? ?? ?? 4C 8B 05 ?? ?? ?? ?? 48 8D 4D ?? E8 - ?? ?? ?? ?? 48 8B D8 4C 89 75 ?? 4C 89 75 ?? 4C 89 75 ?? 45 8D 46 ?? 48 8B D0 48 8D - 4D ?? E8 ?? ?? ?? ?? 4C 89 73 ?? 48 C7 43 ?? ?? ?? ?? ?? 66 44 89 33 BE ?? ?? ?? ?? - 89 75 ?? 83 E6 ?? 89 75 ?? 48 8B 55 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 - 8B 4D ?? 48 8B C1 48 81 FA ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 - C0 ?? 48 83 F8 ?? 0F 87 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 75 ?? 48 C7 45 ?? ?? ?? ?? - ?? 66 44 89 75 ?? 48 8D 4D ?? 48 83 7D ?? ?? 48 0F 43 4D ?? 4C 89 74 24 ?? C7 44 24 - ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 45 33 C9 45 33 C0 BA ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 48 8B D8 48 83 F8 ?? 74 ?? 4C 89 74 24 ?? 45 33 C9 41 B8 ?? ?? ?? ?? 48 8D 15 - ?? ?? ?? ?? 48 8B C8 FF 15 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 83 E6 ?? 89 75 ?? - 48 8B 55 ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 4D ?? 48 8B C1 48 81 FA - ?? ?? ?? ?? 72 ?? 48 83 C2 ?? 48 8B 49 ?? 48 2B C1 48 83 C0 ?? 48 83 F8 ?? 0F 87 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 75 ?? 48 C7 45 ?? ?? ?? ?? ?? 66 44 89 75 ?? 48 8B 57 - ?? 48 83 FA ?? 72 ?? 48 8D 14 55 ?? ?? ?? ?? 48 8B 0F 48 81 FA ?? ?? ?? ?? 72 ?? 48 - 83 C2 ?? 4C 8B 41 ?? 49 2B C8 48 8D 41 ?? 48 83 F8 ?? 77 ?? 49 8B C8 E8 ?? ?? ?? ?? - 4C 89 77 ?? 48 C7 47 ?? ?? ?? ?? ?? 66 44 89 37 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? - 49 8B 73 ?? 49 8B 7B - } - $encrypt_files_v2_p1 = { - BA ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 75 ?? 48 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 90 48 8D 05 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? 48 89 - 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 85 C9 0F 84 ?? ?? ?? ?? 49 8B FA 49 8B D1 4D 85 D2 - 74 ?? 4C 8B C1 4D 2B C1 0F B7 02 66 41 39 04 10 75 ?? 48 83 C2 ?? 48 83 EF ?? 75 ?? - 49 2B CB 48 D1 F9 E9 ?? ?? ?? ?? 48 83 C1 ?? E9 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 - 8B CB FF 15 ?? ?? ?? ?? 85 C0 75 ?? 48 8B CB FF 15 ?? ?? ?? ?? 90 48 8D 8D ?? ?? ?? - ?? E8 ?? ?? ?? ?? 90 48 8D 05 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? - 48 89 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 8B BD ?? ?? ?? ?? B2 ?? 48 8D 4C 24 ?? E8 ?? - ?? ?? ?? B2 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 66 0F 6F 05 ?? ?? 0B 00 F3 0F 7F 45 ?? - 48 89 75 ?? 48 89 75 ?? 48 8D 45 ?? 48 89 85 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 ?? - C6 45 ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 45 ?? 48 C7 45 ?? ?? ?? ?? ?? C6 45 - ?? ?? 48 8D 45 ?? 83 E0 ?? 48 8D 44 05 ?? 48 89 45 ?? 89 75 ?? C7 45 ?? ?? ?? ?? ?? - 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 05 ?? - ?? ?? ?? 48 89 44 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 - 44 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 - 8D 05 ?? ?? ?? ?? 48 89 45 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 - C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C - 8B E8 48 89 44 24 ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B F8 48 89 85 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 49 - } - $encrypt_files_v2_p2 = { - 8B D5 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8B D7 48 8D 0D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8B CF 41 B8 ?? ?? ?? ?? 49 8B D5 - 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 49 8B D5 48 8B 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 83 C1 ?? 41 B8 ?? ?? ?? ?? 48 8B D7 E8 ?? ?? ?? ?? - BF ?? ?? ?? ?? 4C 3B FF 0F 8D ?? ?? ?? ?? F2 0F 10 35 ?? ?? ?? ?? 48 8B FE 49 8B C7 - 48 2B C7 48 99 83 E2 ?? 48 03 C2 48 C1 F8 ?? 4C 8B F0 F2 0F 59 35 ?? ?? ?? ?? 0F 57 - C0 F2 48 0F 2A C0 F2 0F 59 F0 F2 48 0F 2C CE 48 85 C9 0F 85 ?? ?? ?? ?? 4D 85 FF 0F - 8E ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 ?? 48 8D 54 24 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? - 90 48 8D 35 ?? ?? ?? ?? 48 89 75 ?? 4C 8D 35 ?? ?? ?? ?? 4C 89 75 ?? 48 8D 05 ?? ?? - ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 - ?? 4D 8B CF 45 33 C0 48 8B D3 48 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 49 - 81 FF ?? ?? ?? ?? 0F 8E ?? ?? ?? ?? F2 0F 10 35 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 - ?? 48 8D 54 24 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 - 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? - 48 89 85 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 ?? 4C 8B CF 45 33 C0 48 8B D3 49 8B CE - E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 99 48 F7 F9 4C 8B E8 48 85 C0 75 ?? 48 8D 45 ?? 48 - } - $encrypt_files_v2_p3 = { - 89 44 24 ?? 48 8D 54 24 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 35 ?? ?? ?? ?? 48 89 - 75 ?? 4C 8D 35 ?? ?? ?? ?? 4C 89 75 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? - ?? ?? ?? 48 89 85 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 ?? 4D 8B CF 45 33 C0 48 8B D3 - 48 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8B 6C 24 ?? E9 ?? ?? ?? ?? 4D 85 F6 0F 8E ?? - ?? ?? ?? 4D 8B FD 49 C1 E7 ?? 4C 8B A5 ?? ?? ?? ?? 90 48 8D 45 ?? 48 89 44 24 ?? 48 - 8D 54 24 ?? 48 8D 4D ?? E8 ?? ?? ?? ?? 90 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 - ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 45 ?? 48 8D 05 ?? ?? ?? ?? 48 89 - 85 ?? ?? ?? ?? 48 8D 45 ?? 48 89 44 24 ?? 41 B9 ?? ?? ?? ?? 4C 8B C7 48 8B D3 49 8B - CC E8 ?? ?? ?? ?? 49 03 F5 49 03 FF 49 3B F6 7C ?? 4C 8B A5 ?? ?? ?? ?? 4C 8B 6C 24 - ?? 48 8D 35 ?? ?? ?? ?? 4C 8D 35 ?? ?? ?? ?? 4C 8D 8D ?? ?? ?? ?? 4C 8B C3 48 8B 95 - ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 4D 8B C4 - 48 8D 95 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B 95 ?? ?? ?? ?? 48 - 85 D2 74 ?? 48 8B FA 33 C0 B9 ?? ?? ?? ?? F3 AA 48 8B CA E8 ?? ?? ?? ?? 90 4D 85 ED - 74 ?? 49 8B FD 33 C0 B9 ?? ?? ?? ?? F3 AA 49 8B CD E8 ?? ?? ?? ?? 90 48 89 74 24 ?? - 4C 89 74 24 - } + $a = { 10 48 8B 45 E0 0F B6 00 38 C2 0F 95 C0 48 FF 45 E8 48 FF 45 E0 } condition: - uint16(0)==0x5A4D and ((($find_files) and ( all of ($find_system_volumes_v1_p*)) and ( all of ($set_default_icon_p*)) and ($cmd_prompt) and ($exclude_from_encryption) and ($encrypt_files_v1)) or (($find_files) and ($cmd_prompt) and ($find_system_volumes_v2) and ($drop_ransom_note) and ( all of ($encrypt_files_v2_p*)))) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Bananacrypt : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Aa39Fb02 : FILE MEMORY { meta: - description = "Yara rule that detects BananaCrypt ransomware." - author = "ReversingLabs" - id = "9e47d094-d7fc-57dd-826c-5321d0219273" - date = "2020-09-14" - modified = "2020-09-14" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.BananaCrypt.yara#L1-L103" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6bde4430e438947b0d7f10c4de11216929ec03af81b3d74f8b7bb8ed134d08d2" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "aa39fb02-ca7e-4809-ab5d-00e92763f7ec" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L989-L1006" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "ffa95d92a2b619008bd5918cd34a17cd034b2830dc09d495db4b0c397b1cb53a" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "BananaCrypt" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "b136ba6496816ba9737a3eb0e633c28a337511a97505f06e52f37b38599587cb" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 55 89 E5 57 56 53 89 C3 81 EC ?? ?? ?? ?? 89 95 ?? ?? ?? ?? 8B 55 ?? 89 8D ?? ?? ?? - ?? 85 D2 74 ?? 8B 45 ?? 85 C0 0F 85 ?? ?? ?? ?? 31 F6 0F B6 13 84 D2 0F 84 ?? ?? ?? - ?? 8D 43 ?? 88 95 ?? ?? ?? ?? 8D 8B ?? ?? ?? ?? 8D BD ?? ?? ?? ?? EB ?? 83 C0 ?? 83 - C7 ?? 88 57 ?? 39 C1 74 ?? 0F B6 10 84 D2 75 ?? 89 BD ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - C6 00 ?? 89 1C 24 E8 ?? ?? ?? ?? 85 C0 89 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 89 F0 84 - C0 0F 85 ?? ?? ?? ?? 8D 5D ?? 8D 76 ?? 8D BC 27 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 - 24 E8 ?? ?? ?? ?? 85 C0 89 C6 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D BD ?? ?? ?? ?? - 39 F9 89 C8 76 ?? 0F B6 41 ?? 89 CF 3C ?? 0F 95 C1 3C ?? 0F 95 C2 84 D1 0F 84 ?? ?? - ?? ?? 3C ?? 0F 84 ?? ?? ?? ?? 8D 47 ?? C6 07 ?? 8D 7E ?? 39 D8 89 BD ?? ?? ?? ?? 73 - ?? 0F B6 56 ?? 84 D2 74 ?? 89 F9 8B BD ?? ?? ?? ?? EB ?? 90 0F B6 11 84 D2 74 ?? 83 - C0 ?? 83 C1 ?? 88 50 ?? 39 D8 75 ?? 89 BD ?? ?? ?? ?? C6 00 ?? 8D 85 ?? ?? ?? ?? 31 - FF 89 04 24 E8 ?? ?? ?? ?? 85 C0 89 C2 74 ?? 80 38 ?? 74 ?? 8B 85 ?? ?? ?? ?? 66 90 - 83 C7 ?? 80 3C 3A ?? 75 ?? 89 85 ?? ?? ?? ?? 89 54 24 ?? C7 04 24 ?? ?? ?? ?? 89 95 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 46 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 3D ?? ?? ?? ?? 8B 95 - ?? ?? ?? ?? 74 ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 7C 24 ?? 89 14 24 89 - } - $encrypt_files_p2 = { - 44 24 ?? 8B 85 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? C7 04 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 C6 8D 85 ?? ?? ?? ?? 89 F1 89 04 24 E8 ?? ?? ?? ?? - 83 EC ?? 89 F1 E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? 89 C7 8D - 40 ?? 83 F8 ?? 76 ?? 89 F1 83 05 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 3C 24 89 44 24 ?? E8 ?? ?? ?? ?? 89 F1 E8 ?? - ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 - ?? ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 89 - F1 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B - B5 ?? ?? ?? ?? BF ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 A6 0F 84 ?? ?? ?? ?? 8B B5 ?? ?? ?? - ?? BF ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 A6 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 8D ?? ?? ?? ?? - 8B 95 ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 04 24 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 - ?? ?? ?? ?? 8D 74 26 ?? 8B 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 04 24 - E8 ?? ?? ?? ?? 8D 65 ?? B8 ?? ?? ?? ?? 5B 5E 5F 5D C3 8B 45 ?? 89 1C 24 89 44 24 ?? - 8B 45 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 89 C6 E9 ?? ?? ?? ?? 8D 65 ?? 31 C0 5B 5E 5F 5D - C3 8D 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E9 - } - $find_files_p1 = { - 8D 4C 24 ?? 83 E4 ?? FF 71 ?? 55 89 E5 57 56 53 51 81 EC ?? ?? ?? ?? 8B 31 8B 79 ?? - E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 FE ?? 7E ?? 89 74 24 ?? C7 04 - 24 ?? ?? ?? ?? 31 DB E8 ?? ?? ?? ?? 8B 04 9F 89 5C 24 ?? 83 C3 ?? C7 04 24 ?? ?? ?? - ?? 89 44 24 ?? E8 ?? ?? ?? ?? 39 DE 75 ?? C7 44 24 ?? ?? ?? ?? ?? 8B 47 ?? 89 04 24 - E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 89 - 44 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D BD ?? - ?? ?? ?? F3 A5 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 04 24 C7 85 - } - $find_files_p2 = { - 8B 85 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 C3 E8 ?? ?? ?? ?? - 8D 44 03 ?? 89 04 24 E8 ?? ?? ?? ?? 89 C3 8B 85 ?? ?? ?? ?? 89 1C 24 89 44 24 ?? E8 - ?? ?? ?? ?? 89 DA 8B 0A 83 C2 ?? 8D 81 ?? ?? ?? ?? F7 D1 21 C8 25 ?? ?? ?? ?? 74 ?? - A9 ?? ?? ?? ?? 74 ?? 89 C1 00 C1 83 DA ?? C7 02 ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C7 - 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C7 42 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 84 C0 74 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 65 ?? 31 C0 59 5B 5E - 5F 5D 8D 61 ?? C3 C1 E8 ?? 83 C2 ?? EB ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8D BD ?? ?? ?? ?? BE ?? ?? ?? ?? 89 04 24 B8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 29 - F9 89 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? 29 CE 81 C1 ?? ?? ?? ?? C1 E9 ?? 89 45 ?? F3 - } - $find_files_p3 = { - A5 89 1C 24 E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? - ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 89 C6 74 ?? 89 44 24 ?? C7 44 24 ?? ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 34 24 E8 ?? - ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 - ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 04 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? 89 1C 24 E8 ?? ?? ?? ?? 85 C0 89 C6 0F 84 ?? ?? ?? ?? 89 44 24 - ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? - ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? E9 - } + $a = { 74 DE 8D 40 F1 3C 01 76 D7 80 FA 38 74 D2 80 FA 0A 74 CD 80 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Buran : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_0Bce98A2 : FILE MEMORY { meta: - description = "Yara rule that detects Buran ransomware." - author = "ReversingLabs" - id = "c2a36a8b-5c21-5c31-994d-b424c038dd21" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Buran.yara#L1-L91" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "5606e0acecd99ccf2feaa995353211302903a09bb2c4ec65903566215e2d5ca4" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "0bce98a2-113e-41e1-95c9-9e1852b26142" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1008-L1026" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80" + logic_hash = "04d10ef03c178fb101d3c6b6d3b36f0aa04149b9b35a33c3d10d17af1fc07625" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Buran" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D - ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? - 89 5D ?? 89 5D ?? 88 8D ?? ?? ?? ?? 88 95 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? E8 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF - 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? 8B 45 ?? E8 ?? ?? ?? - ?? 8B 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 80 BD ?? ?? ?? ?? ?? 75 ?? 33 - C0 5A 59 59 64 89 10 E9 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8B 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? - ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 45 ?? - 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 - C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 - 74 ?? 80 BD ?? ?? ?? ?? ?? 74 ?? 33 C9 8B 55 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5A 59 59 - 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 - } - $encrypt_files = { - 53 56 57 55 BB ?? ?? ?? ?? BF ?? ?? ?? ?? 80 7B ?? ?? 75 ?? 83 3F ?? 74 ?? 8B 07 89 - C6 33 C0 89 07 FF D6 83 3F ?? 75 ?? 83 3D ?? ?? ?? ?? ?? 74 ?? E8 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 33 C0 A3 ?? ?? ?? ?? 80 7B ?? ?? 75 ?? 83 3D ?? ?? ?? ?? ?? 75 ?? 33 C0 89 - 43 ?? E8 ?? ?? ?? ?? 80 7B ?? ?? 76 ?? 83 3D ?? ?? ?? ?? ?? 74 ?? 8B 7B ?? 85 FF 74 - ?? 8B C7 E8 ?? ?? ?? ?? 8B 6B ?? 8B 75 ?? 3B 75 ?? 74 ?? 85 F6 74 ?? 56 E8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 80 7B ?? ?? 75 ?? FF 53 ?? 80 7B ?? ?? 74 ?? E8 ?? ?? ?? ?? 83 3B - ?? 75 ?? 83 3D ?? ?? ?? ?? ?? 74 ?? FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 8B 03 8B F0 8B FB B9 ?? ?? ?? ?? F3 A5 E9 ?? ?? ?? ?? 5D 5F 5E 5B C3 A3 - } - $remote_connection_p1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 50 83 C4 ?? 53 56 33 DB 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? - ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 5D ?? 8B D9 89 55 ?? 89 - 45 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF - 30 64 89 20 8B C3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? E8 ?? ?? ?? ?? 89 45 - ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 BE ?? ?? - ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? - ?? 0F 84 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 55 ?? B8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 6A ?? 56 6A ?? 6A ?? 6A ?? 8B 45 ?? E8 - } - $remote_connection_p2 = { - 50 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 89 45 ?? 83 7D ?? ?? 0F 84 - ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 C9 B2 ?? A1 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 95 ?? ?? ?? ?? B8 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? - ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? - ?? 8D 95 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 75 ?? 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B 45 ?? - E8 ?? ?? ?? ?? 8B 45 ?? 8B 70 ?? 85 F6 74 ?? 83 EE ?? 8B 36 68 ?? ?? ?? ?? 56 8B 45 - ?? 8B 40 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 8B - 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 89 45 ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 EB ?? 83 7D ?? ?? 74 ?? 8D 95 ?? - ?? ?? ?? 8B 4D ?? 8B 45 ?? 8B 30 FF 56 ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 85 C0 75 ?? C6 85 ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? - B9 ?? ?? ?? ?? 8B 45 ?? 8B 30 FF 56 ?? 8B C3 8B 55 ?? 8B 52 ?? E8 ?? ?? ?? ?? 33 C0 - 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? C3 E9 - } + $a = { 4B 52 41 00 46 47 44 43 57 4E 56 00 48 57 43 4C 56 47 41 4A } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ( all of ($remote_connection_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Cryptobit : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_3A56423B : FILE MEMORY { meta: - description = "Yara rule that detects CryptoBit ransomware." - author = "ReversingLabs" - id = "8566e516-9884-5b20-90c4-7ed38fa96999" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.CryptoBit.yara#L1-L113" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ccc8a0f1c5e11211649992d0f2b309968c97b49f1c7359e62d622f364e117429" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "3a56423b-c0cf-4483-87e3-552beb40563a" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1028-L1045" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "0c2765a5c1b331eb9ff5e542bc72eff7be3506e6caef94128413d500086715c6" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "CryptoBit" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 55 8B EC 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 - 7D ?? ?? 75 ?? FF 75 ?? EB ?? 6A ?? 59 83 C9 ?? 83 F1 ?? 89 4D ?? 6A ?? 6A ?? 6A ?? - 6A ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 0B C0 0F 84 ?? ?? ?? ?? 89 45 ?? 60 BE ?? ?? ?? - ?? 56 64 FF 35 ?? ?? ?? ?? 64 89 25 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 45 ?? 33 D2 - 8B 0D ?? ?? ?? ?? F7 F1 0B C0 74 ?? FF 35 ?? ?? ?? ?? EB ?? 52 8B 0C 24 29 4D ?? 51 - FF 75 ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 59 0B C0 74 ?? 89 45 ?? 51 FF - 75 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? 83 7D ?? ?? 75 ?? 89 45 ?? 89 4D ?? FF 75 ?? - E8 ?? ?? ?? ?? EB ?? EB ?? 83 7D ?? ?? 75 ?? C7 45 ?? ?? ?? ?? ?? EB ?? A1 ?? ?? ?? - ?? 01 45 ?? EB ?? EB ?? 8B 64 24 ?? 64 8F 05 ?? ?? ?? ?? 83 C4 ?? 61 EB ?? EB ?? 64 - 8F 05 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 8B 4D - ?? EB ?? 8B 45 ?? C9 C2 - } - $encrypt_files_p2 = { - 55 8B EC 83 C4 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 6A - ?? 6A ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? - ?? ?? ?? 89 45 ?? 8D 45 ?? 50 FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? - 0B C0 74 ?? E9 ?? ?? ?? ?? 89 45 ?? 8B 15 ?? ?? ?? ?? 8B 4D ?? 0B C9 75 ?? 83 F8 ?? - 73 ?? E9 ?? ?? ?? ?? EB ?? 0B C9 75 ?? 3B C2 73 ?? 50 EB ?? 52 8F 45 ?? 83 7D ?? ?? - 75 ?? A1 ?? ?? ?? ?? 39 45 ?? 72 ?? FF 75 ?? FF 75 ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? - ?? 89 45 ?? 0B C0 74 ?? 6A ?? 50 51 FF 75 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 6A - ?? 6A ?? 6A ?? 6A ?? FF 75 ?? E8 ?? ?? ?? ?? 0B C0 74 ?? 89 45 ?? 60 BE ?? ?? ?? ?? - 56 64 FF 35 ?? ?? ?? ?? 64 89 25 ?? ?? ?? ?? FF 75 ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? FF - 75 ?? E8 ?? ?? ?? ?? 0B C0 74 ?? 50 8B 4D ?? 8B 04 24 83 C9 ?? 83 F1 ?? 51 50 E8 ?? - ?? ?? ?? 89 45 ?? 0B C0 74 ?? 6A ?? 50 51 FF 75 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? EB - ?? 8B 64 24 ?? 64 8F 05 ?? ?? ?? ?? 83 C4 ?? 61 EB ?? EB ?? 64 8F 05 ?? ?? ?? ?? 83 - C4 ?? 83 7D ?? ?? 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? E8 ?? ?? - ?? ?? 83 7D ?? ?? 74 ?? 8B 45 ?? 8B 4D ?? EB ?? 33 C0 33 C9 C9 C2 - } - $find_files_p1 = { - 55 8B EC 83 C4 ?? 57 56 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? 8B 75 ?? 83 7E ?? ?? 75 ?? E8 ?? ?? ?? ?? 50 8D 46 ?? 50 E8 - ?? ?? ?? ?? 23 C0 0F 84 ?? ?? ?? ?? EB ?? 83 7E ?? ?? 75 ?? FF 35 ?? ?? ?? ?? 8D 46 - ?? 50 E8 ?? ?? ?? ?? 23 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 23 C0 0F - 84 ?? ?? ?? ?? 89 45 ?? B9 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 23 C0 0F 84 ?? - ?? ?? ?? 89 45 ?? 8B 75 ?? 8B 7D ?? 68 ?? ?? ?? ?? 57 56 E8 ?? ?? ?? ?? 8D 57 ?? 8B - 47 ?? D1 E0 C7 04 10 ?? ?? ?? ?? C6 44 10 ?? ?? FF 75 ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? - 83 F8 ?? 0F 84 ?? ?? ?? ?? 89 45 ?? 8B 55 ?? 8B 75 ?? 8B 7D ?? 8B 02 25 ?? ?? ?? ?? - 0F 85 ?? ?? ?? ?? 8B 02 83 E0 ?? 0F 85 ?? ?? ?? ?? 8B 02 83 E0 ?? F7 02 ?? ?? ?? ?? - 0F 85 ?? ?? ?? ?? 8D 47 ?? 50 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 8D 42 ?? 50 8D 47 - ?? 50 E8 ?? ?? ?? ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 89 47 ?? F7 02 ?? ?? ?? ?? - 74 ?? 68 ?? ?? ?? ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? FF 77 ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? - 83 F8 ?? 74 ?? 83 F8 ?? 75 ?? 48 50 FF 76 ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? 0B C0 75 - } - $find_files_p2 = { - 0B C9 74 ?? FF 45 ?? E9 ?? ?? ?? ?? 83 7A ?? ?? 0F 84 ?? ?? ?? ?? 81 7A ?? ?? ?? ?? - ?? 0F 84 ?? ?? ?? ?? F7 02 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? F7 02 ?? ?? ?? ?? 0F 85 ?? - ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 74 ?? 8B F8 FF 76 ?? 8F 47 ?? FF 76 ?? - 8F 47 ?? FF 36 8F 07 8D 47 ?? 50 8D 46 ?? 50 E8 ?? ?? ?? ?? 8B 55 ?? 8D 42 ?? 50 8D - 47 ?? 50 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 47 ?? 50 E8 ?? ?? ?? ?? 8D 47 ?? 50 E8 ?? - ?? ?? ?? 89 47 ?? 83 3F ?? 75 ?? 57 68 ?? ?? ?? ?? FF 76 ?? E8 ?? ?? ?? ?? 0B C0 75 - ?? 57 E8 ?? ?? ?? ?? EB ?? 57 E8 ?? ?? ?? ?? EB ?? E9 ?? ?? ?? ?? FF 75 ?? FF 75 ?? - E8 ?? ?? ?? ?? 0B C0 0F 85 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - 8B 75 ?? 83 7D ?? ?? 74 ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B - 14 24 51 50 52 8D 46 ?? 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 D1 E1 8B 5C 24 ?? 51 50 53 8D 46 - ?? 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? E8 ?? - ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 7D ?? ?? 74 ?? FF 75 ?? E8 ?? - ?? ?? ?? 8B 45 ?? 5E 5F C9 C2 - } - $remote_connection = { - 55 8B EC 81 C4 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? 6A ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? - 6A ?? E8 ?? ?? ?? ?? 23 C0 89 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A - ?? 6A ?? 6A ?? FF 75 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 89 85 ?? ?? ?? ?? 0F - 84 ?? ?? ?? ?? 8D 5D ?? C7 03 ?? ?? ?? ?? C7 43 ?? ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? - ?? ?? 6A ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 45 ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 74 ?? 6A ?? 6A ?? 6A ?? 6A ?? FF B5 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 23 C0 74 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 23 C0 89 85 ?? ?? ?? ?? 74 ?? - 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? - ?? FF B5 ?? ?? ?? ?? 0B C0 74 ?? 83 BD ?? ?? ?? ?? ?? 74 ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? - FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? C9 C2 - } + $a = { 24 1C 8B 44 24 20 0F B6 D0 C1 E8 08 89 54 24 24 89 44 24 20 BA 01 00 } condition: - uint16(0)==0x5A4D and ($remote_connection and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*))) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Jsworm : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_D18B3463 : FILE MEMORY { meta: - description = "Yara rule that detects JSWorm ransomware." - author = "ReversingLabs" - id = "a4702cc3-1e08-5631-b832-5d28cb92a819" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.JSWorm.yara#L1-L93" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "8ba5e2f29f5f06e6e6714bbba1129862da8c3a83bf7f296818eddee2593cae38" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "d18b3463-1b5e-49e1-9ae8-1d63a10a1ccc" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1047-L1065" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "cd86534d709877ec737ceb016b2a5889d2e3562ffa45a278bc615838c2e9ebc3" + logic_hash = "f906c6f9baae6d6fa3f42e84607549bae44ed9ca847fd916d04f2671eef1caa1" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "JSWorm" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "4b3d3bb65db2cdb768d91c50928081780f206208e952c74f191d8bc481ce19c6" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files = { - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? A8 ?? - 0F 85 ?? ?? ?? ?? A8 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 C6 45 ?? ?? 8B 4E ?? 8B 56 ?? 3B CA 73 - ?? 8D 41 ?? 89 46 ?? 8B C6 83 FA ?? 72 ?? 8B 06 C7 04 48 ?? ?? ?? ?? EB ?? 6A ?? C6 - 85 ?? ?? ?? ?? ?? 8B CE FF B5 ?? ?? ?? ?? 6A ?? E8 - } - $find_drives = { - 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 80 3D ?? ?? ?? ?? ?? BE ?? ?? ?? ?? 0F 84 ?? - ?? ?? ?? 8B CE C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? 8D 51 ?? 8A 01 - 41 84 C0 75 ?? 2B CA 51 56 8D 4D ?? E8 ?? ?? ?? ?? 83 EC ?? C7 45 ?? ?? ?? ?? ?? 8B - CC 89 65 ?? 33 C0 6A ?? 68 ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 66 - 89 01 E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 55 ?? 8B CC E8 ?? ?? ?? ?? C6 45 ?? ?? - E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B - C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 - ?? ?? ?? ?? 83 C4 ?? 8B C6 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 46 03 F0 38 0E 0F 85 - ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 - 5D C3 E8 ?? ?? ?? ?? E8 - } - $encrypt_files_p1 = { - 8B 00 50 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B F0 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? - 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? - ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 83 FA ?? - 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? - 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B - CB C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 E6 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 C0 66 89 - 85 ?? ?? ?? ?? 8D 51 ?? 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 51 53 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 78 ?? ?? 72 ?? 8B 00 56 50 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 FA - ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 - 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? - ?? 8B 95 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 - 85 ?? ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA - ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 - E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 53 FF - 15 ?? ?? ?? ?? 8B D8 8D 45 ?? 50 53 89 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 7D ?? ?? - 0F 8C ?? ?? ?? ?? 7F ?? 81 7D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 53 - FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 8B F8 89 BD ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? - B9 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? BE ?? ?? ?? ?? 83 C4 ?? F3 A5 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 33 F6 - } - $encrypt_files_p2 = { - 8B 86 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 86 ?? ?? ?? ?? 89 85 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 - 86 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 89 86 ?? ?? ?? ?? 83 C6 ?? 81 FE ?? ?? ?? ?? 7C ?? - 6A ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? 53 - FF 15 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 EC ?? 8B F4 8B CA 33 C0 - C7 46 ?? ?? ?? ?? ?? 8D 79 ?? C7 46 ?? ?? ?? ?? ?? 66 89 06 66 8B 01 83 C1 ?? 66 85 - C0 75 ?? E9 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 53 8B 1D ?? ?? ?? ?? FF D3 6A ?? 8D 45 ?? - 50 FF 75 ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? - ?? ?? ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B - F8 89 BD ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? BE ?? ?? ?? ?? F3 A5 8B 45 ?? 8D 8D ?? ?? ?? ?? 50 68 - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 - FF D3 6A ?? 8D 45 ?? 50 FF 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 56 FF 15 - } + $a = { DF 77 95 8D 42 FA 3C 01 76 8E 80 FA 0B 74 89 80 FA 15 74 84 80 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_Fe721Dc5 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "fe721dc5-c2bc-4fa6-bdbc-589c6e033e6b" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1067-L1084" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "e9312eefb5f14a27d96e973139e45098c2f62a24d5254ca24dea64b9888a4448" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "ab7f571a3a3f6b50b9e120612b3cc34d654fc824429a2971054ca0d078ecb983" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 89 18 EB E1 57 83 EC 08 8B 7C 24 10 8B 4C 24 14 8B 54 24 18 53 } condition: - uint16(0)==0x5A4D and $find_drives and $find_files and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Defray : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_575F5Bc8 : FILE MEMORY { meta: - description = "Yara rule that detects Defray ransomware." - author = "ReversingLabs" - id = "bc9e2dfe-168b-5b99-8523-07bfdcba44f2" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Defray.yara#L1-L157" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "82d883c77f49e50edbc7af05a108d4d54a46dca7661e4d0cd8aeffa19cb8df98" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "575f5bc8-b848-4db4-a99c-132d4d2bc8a4" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1086-L1103" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "dec143d096f5774f297ce90ef664ae50c40ae4f87843bbb34e496565c0faf3b2" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Defray" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "58e22a2acd002b07e1b1c546e8dfe9885d5dfd2092d4044630064078038e314f" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 68 ?? ?? ?? ?? 33 - F6 89 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B D9 56 50 89 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 83 - C4 ?? 2B D3 8B CB 89 95 ?? ?? ?? ?? 0F B7 01 66 89 04 0A 8D 49 ?? 66 85 C0 75 ?? 8D - BD ?? ?? ?? ?? 83 EF ?? 66 8B 47 ?? 83 C7 ?? 66 3B C6 75 ?? BE ?? ?? ?? ?? 68 ?? ?? - ?? ?? 53 A5 A5 66 A5 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 33 F6 8B 1D ?? ?? ?? ?? - 83 FB ?? 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B 10 66 3B 11 75 ?? - 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 85 D2 75 ?? 8B C6 - EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 66 8B - 10 66 3B 11 75 ?? 66 85 D2 74 ?? 66 8B 50 ?? 66 3B 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 66 - 85 D2 75 ?? 8B C6 EB ?? 1B C0 83 C8 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B - 95 ?? ?? ?? ?? 0F B7 01 66 89 04 0A 8D 49 ?? 66 85 C0 75 ?? 8D BD ?? ?? ?? ?? 83 EF - ?? 33 C9 66 8B 47 ?? 8D 7F ?? 66 3B C1 75 ?? A1 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 89 07 - 8B F2 66 8B 02 83 C2 ?? 66 3B C1 75 ?? 8D BD ?? ?? ?? ?? 2B D6 83 EF ?? 66 8B 47 ?? - 83 C7 ?? 66 3B C1 75 ?? 8B CA C1 E9 ?? F3 A5 8B CA 83 E1 ?? F6 85 ?? ?? ?? ?? ?? F3 - A4 74 ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? F7 85 ?? ?? ?? ?? - ?? ?? ?? ?? 75 ?? 8B 8D ?? ?? ?? ?? 66 8B 85 ?? ?? ?? ?? 66 89 04 59 43 89 1D ?? ?? - ?? ?? 33 F6 8B 9D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? ?? 85 C0 0F 85 - ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $find_special_folders = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 BE ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 56 33 DB 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 56 53 50 E8 - ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 56 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? - ?? ?? BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 6A ?? 59 68 ?? ?? ?? ?? 53 F3 A5 50 E8 ?? ?? - ?? ?? 83 C4 ?? 8D BD ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 6A ?? 59 F3 A5 68 - ?? ?? ?? ?? 53 50 66 A5 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D - BD ?? ?? ?? ?? 6A ?? 59 68 ?? ?? ?? ?? 53 F3 A5 50 E8 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 83 C4 ?? 53 6A ?? 50 53 FF D6 53 6A ?? 8D 85 ?? ?? ?? ?? 50 53 FF - D6 53 6A ?? 8D 85 ?? ?? ?? ?? 50 53 FF D6 8D BD ?? ?? ?? ?? 83 EF ?? 66 8B 47 ?? 83 - C7 ?? 66 3B C3 75 ?? 6A ?? 59 BE ?? ?? ?? ?? F3 A5 8D BD ?? ?? ?? ?? 83 EF ?? 66 8B - 47 ?? 83 C7 ?? 66 3B C3 75 ?? 6A ?? 59 BE ?? ?? ?? ?? F3 A5 8D BD ?? ?? ?? ?? 83 EF - ?? 66 8B 47 ?? 83 C7 ?? 66 3B C3 75 ?? BE ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? A5 A5 A5 A5 - 66 A5 E8 ?? ?? ?? ?? 84 C0 74 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $remote_connection = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 57 89 85 ?? - ?? ?? ?? 33 DB 8B 45 ?? 8B FA 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 - 50 E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 83 C4 ?? 89 45 ?? A0 ?? ?? ?? ?? 88 45 ?? 8D 85 ?? - ?? ?? ?? 53 53 53 53 50 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8B D8 89 9D ?? ?? ?? ?? - 85 DB 74 ?? 33 C0 50 50 6A ?? 50 50 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? ?? 8B F8 85 - FF 74 ?? 33 C0 50 68 ?? ?? ?? ?? 50 50 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 45 ?? 50 - 57 FF 15 ?? ?? ?? ?? 8B D8 85 DB 74 ?? 8B 95 ?? ?? ?? ?? 33 C9 85 D2 74 ?? 8B CA 8D - 41 ?? 89 85 ?? ?? ?? ?? 8A 01 41 84 C0 75 ?? 2B 8D ?? ?? ?? ?? 51 52 6A ?? 6A ?? 53 - FF 15 ?? ?? ?? ?? 53 FF D6 8B 9D ?? ?? ?? ?? 57 FF D6 53 FF D6 8B 4D ?? 5F 5E 33 CD - 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $encrypt_files_1 = { - 55 8B EC 51 51 83 4D ?? ?? 83 4D ?? ?? 57 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 - ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 75 ?? 6A ?? 58 EB ?? 56 8D 45 ?? 50 - 57 FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 75 ?? 6A ?? EB ?? 8B 75 ?? 3B C6 0F 42 F0 83 7D - ?? ?? 74 ?? 6A ?? 8D 45 ?? 50 56 FF 75 ?? 57 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? 5E - 57 FF 15 ?? ?? ?? ?? EB ?? 57 FF 15 ?? ?? ?? ?? 3B 75 ?? 6A ?? 58 0F 45 F0 8B C6 EB - ?? 57 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5E 5F 8B E5 5D C2 - } - $encrypt_files_2_p1 = { - 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 33 C0 89 85 ?? ?? ?? - ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 45 ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? C6 45 ?? ?? 50 89 85 ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 6A ?? 59 33 C0 8D 7D ?? - F3 AB 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 85 C0 74 ?? FF 15 ?? ?? ?? ?? 50 - 68 ?? ?? ?? ?? 83 CE ?? EB ?? 6A ?? 8D 55 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 85 - C0 74 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 5E 6A ?? 8B D6 59 E8 ?? ?? ?? ?? - 59 59 E9 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 85 F6 75 ?? 6A ?? 5E E9 ?? ?? ?? ?? 80 BD ?? - ?? ?? ?? ?? B8 ?? ?? ?? ?? 75 ?? B8 ?? ?? ?? ?? 3B F0 0F 47 F0 8D 85 ?? ?? ?? ?? 50 - 56 8B C8 89 B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 FF B5 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? - ?? 8B F8 85 FF 79 ?? FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 6A ?? 5A 6A ?? 59 E8 ?? ?? ?? - ?? 59 59 BE ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? - FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? 5A 6A ?? 59 E8 ?? ?? ?? ?? 59 59 6A ?? E9 - ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 8D 55 ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C7 8B DF 25 ?? ?? ?? ?? 79 ?? 48 83 C8 ?? 40 74 ?? 8B - } - $encrypt_files_2_p2 = { - B5 ?? ?? ?? ?? 43 46 8B C3 25 ?? ?? ?? ?? 79 ?? 48 83 C8 ?? 40 75 ?? 89 B5 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 53 8B C8 E8 ?? ?? ?? ?? 33 D2 85 FF 7E ?? 8B 85 ?? ?? ?? ?? - 8A 0C 10 8B 85 ?? ?? ?? ?? 88 0C 10 42 3B D7 7C ?? 3B FB 7D ?? 8B C3 2B C7 50 8B 85 - ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 03 C7 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 - 53 8B C8 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 8B C8 E8 ?? ?? ?? ?? 8B - 95 ?? ?? ?? ?? 8D 45 ?? 51 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 - ?? 6A ?? E9 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 53 FF B5 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 59 59 85 C0 75 ?? 6A ?? 33 FF 5A 8B 85 ?? ?? ?? ?? 8A 4C 3D ?? 88 0C 38 - 47 3B FA 7C ?? 8D 75 ?? 6A ?? 2B F2 5F 8B 85 ?? ?? ?? ?? 8A 0C 32 88 0C 10 42 3B D7 - 7C ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 95 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 59 59 85 C0 74 ?? 6A ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 83 EC ?? 8D - 85 ?? ?? ?? ?? 50 51 8B 8D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - } - $encrypt_files_2_p3 = { - 85 C0 79 ?? 6A ?? E9 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? BA ?? ?? ?? ?? 2B F7 8B 85 ?? ?? - ?? ?? 8A 0C 37 88 0C 38 47 3B FA 7C ?? 8B B5 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8A 8C 02 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 88 0C 10 42 81 FA ?? ?? ?? ?? 7C ?? 83 BD ?? ?? ?? ?? ?? - 74 ?? 8D 4D ?? E8 ?? ?? ?? ?? 84 C0 75 ?? BE ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B C6 E9 ?? ?? ?? ?? 51 6A ?? 53 FF B5 ?? ?? ?? ?? 8D 4D ?? E8 - ?? ?? ?? ?? 8B F8 85 FF 79 ?? FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 6A ?? 5A 6A ?? 59 E8 - ?? ?? ?? ?? 59 59 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 87 ?? ?? ?? ?? - E9 ?? ?? ?? ?? 51 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B - F8 85 FF 79 ?? FF 15 ?? ?? ?? ?? 50 8D 45 ?? 50 6A ?? 5A 6A ?? 59 E8 ?? ?? ?? ?? 59 - 59 EB ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 01 34 85 - ?? ?? ?? ?? FF 04 85 ?? ?? ?? ?? 33 FF 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B C7 E8 ?? ?? ?? ?? C3 - } + $a = { 5A 56 5B 5B 55 42 44 5E 59 52 44 44 00 5E 73 5E 45 52 54 43 00 } condition: - uint16(0)==0x5A4D and ($find_files) and ($find_special_folders) and ($encrypt_files_1) and ( all of ($encrypt_files_2_p*)) and ($remote_connection) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Globeimposter : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_449937Aa : FILE MEMORY { meta: - description = "Yara rule that detects GlobeImposter ransomware." - author = "ReversingLabs" - id = "6634a554-b4bb-503d-a4f1-9997b4caa1f0" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.GlobeImposter.yara#L1-L171" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "4345a767f270428f3b509fdad5a96bf9b494b190d3a836c4bf53dfd75da5bacb" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "449937aa-682a-4906-89ab-80d7127e461e" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1105-L1123" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "6f27766534445cffb097c7c52db1fca53b2210c1b10b75594f77c34dc8b994fe" + logic_hash = "d459e46893115dbdef46bcaceb6a66255ef3a389f1bf7173b0e0bd0d8ce024fb" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "GlobeImposter" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "cf2c6b86830099f039b41aeaafbffedfb8294a1124c499e99a11f48a06cd1dfd" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_1 = { - 81 EC ?? ?? ?? ?? 83 24 24 ?? 6A ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 44 24 - ?? 50 E8 ?? ?? ?? ?? 8D 04 24 50 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 53 8B 1D ?? - ?? ?? ?? 55 56 57 8B 3D ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? 50 E8 ?? ?? - ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F0 8D 84 24 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 50 89 74 24 ?? FF D3 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 8B E8 83 FD ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D7 85 C0 0F 84 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 33 C0 66 89 84 - 74 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF D3 6A ?? 8D 44 24 ?? 50 E8 - ?? ?? ?? ?? F6 44 24 ?? ?? 8B F0 74 ?? 6A ?? 56 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D3 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? - 50 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 8D 44 24 ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? - 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 8D 44 24 ?? - 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? A8 ?? 74 ?? 83 E0 ?? 50 8D 84 24 ?? ?? - ?? ?? 50 FF 15 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 50 FF B4 24 - ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 8D 84 24 ?? ?? ?? ?? - 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? - 50 FF D3 6A ?? 8D 84 24 ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D - 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 74 24 ?? 59 8D 44 24 ?? 50 - 55 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 E8 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C2 - } - $search_files_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 8B F8 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D8 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 33 F6 - 8D 85 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 DB 74 ?? F6 C3 ?? 74 ?? 8D 85 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 75 ?? 6A ?? 6A - ?? C6 85 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 89 - 04 B7 51 50 FF 15 ?? ?? ?? ?? 46 FE 85 ?? ?? ?? ?? D1 EB 75 ?? EB ?? 68 ?? ?? ?? ?? - FF 34 B7 FF 15 ?? ?? ?? ?? 85 C0 74 - } - $encrypt_files_2 = { - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 24 24 ?? 53 55 56 57 E8 ?? ?? ?? ?? 8B D0 8D 4C 24 - ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 1D ?? ?? ?? - ?? 8B 35 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8D 84 24 ?? ?? - ?? ?? 50 FF 15 ?? ?? ?? ?? 8B F8 8D 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 89 7C 24 ?? - FF D3 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B E8 83 FD ?? 0F 84 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 33 C0 66 89 84 7C ?? ?? ?? ?? 8D 44 - 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF D3 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B F8 33 D2 F6 44 - 24 ?? ?? 8B CF 74 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 - ?? ?? ?? ?? 50 FF D3 8D 94 24 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? - 42 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 - 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 68 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 50 8D 44 24 ?? 50 FF D6 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 - ?? A8 ?? 74 ?? 83 E0 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 51 6A ?? 5A 8B - CF E8 ?? ?? ?? ?? 50 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8D 84 24 ?? ?? - ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 84 24 ?? ?? - ?? ?? 50 FF D3 6A ?? 8D 84 24 ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 8B 7C 24 ?? 59 8D 44 24 ?? - 50 55 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? E8 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C2 - } - $kill_specific_processes_2 = { - 81 EC ?? ?? ?? ?? 56 57 6A ?? 5E 56 8D 44 24 ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 - 74 24 ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 83 FF ?? 0F 84 ?? ?? ?? ?? 8D 84 24 ?? - ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 53 55 BE ?? ?? ?? - ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 8B E8 33 D2 85 ED 7E ?? 0F BE 0C 1A E8 ?? ?? ?? ?? 88 04 1A 42 3B D5 7C ?? FF 36 - 53 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 83 C6 ?? 81 FE ?? ?? ?? ?? 7C ?? 85 C0 74 ?? 33 DB - 53 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? FF B4 - 24 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 68 ?? - ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 56 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 8D - 44 24 ?? 50 53 53 68 ?? ?? ?? ?? 53 53 53 8D 84 24 ?? ?? ?? ?? 50 53 FF 15 ?? ?? ?? - ?? 8D 84 24 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? - ?? ?? ?? 5D 5B 5F 5E 81 C4 ?? ?? ?? ?? C2 - } - $kill_specific_processes_1 = { - 81 EC ?? ?? ?? ?? 55 56 57 6A ?? 5E 56 33 ED 8D 44 24 ?? 55 50 E8 ?? ?? ?? ?? 83 C4 - ?? 89 74 24 ?? 55 6A ?? E8 ?? ?? ?? ?? 8B F8 89 7C 24 ?? 83 FF ?? 0F 84 ?? ?? ?? ?? - 53 8D 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 8B 5C - 24 ?? 83 BC 24 ?? ?? ?? ?? ?? 8B F5 7E ?? 55 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? - 8B E8 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 DB 89 44 24 ?? 85 C0 7E ?? 8B F8 - 0F BE 0C 2B 51 E8 ?? ?? ?? ?? 88 04 2B 43 3B DF 7C ?? 8B 84 24 ?? ?? ?? ?? FF 34 B0 - 55 FF 15 ?? ?? ?? ?? 8B D8 85 DB 75 ?? 46 50 5D 3B B4 24 ?? ?? ?? ?? 7C ?? 8B 7C 24 - ?? 33 ED 85 DB 74 ?? 55 68 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 55 50 FF - 15 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 83 C4 - ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 56 8D 44 24 ?? 50 FF 15 ?? ?? ?? - ?? 8D 44 24 ?? 50 8D 44 24 ?? 50 55 55 68 ?? ?? ?? ?? 55 55 55 8D 84 24 ?? ?? ?? ?? - 50 55 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? - ?? ?? 57 FF 15 ?? ?? ?? ?? 5B 5F 5E 5D 81 C4 ?? ?? ?? ?? C2 - } - $encrypt_files_3 = { - 68 ?? ?? ?? ?? 8D 44 24 ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 33 C0 66 89 84 74 ?? ?? - ?? ?? 8D 44 24 ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF D3 6A ?? 8D 44 24 ?? 50 E8 ?? ?? ?? - ?? F6 44 24 ?? ?? 8B F0 74 ?? 6A ?? 56 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D3 8D 84 24 ?? ?? ?? ?? 50 8D 44 24 ?? 50 E8 ?? - ?? ?? ?? E9 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 44 24 ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 44 24 ?? 50 FF - D7 85 C0 0F 84 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 8D 44 24 ?? 50 FF - D7 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? A8 ?? 74 ?? 83 E0 ?? 50 8D 84 24 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? FF 74 24 ?? 6A ?? 56 E8 ?? ?? ?? ?? 50 FF 74 24 ?? 8D 84 24 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 8D 84 24 ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 FF D3 6A ?? 8D 84 24 - ?? ?? ?? ?? 50 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 74 24 ?? 59 8D 44 24 ?? 50 55 FF 15 - } - $search_files_2 = { - 53 55 56 57 8B 3D ?? ?? ?? ?? 6A ?? 6A ?? FF D7 50 FF 15 ?? ?? ?? ?? 8B E8 FF 15 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8B D8 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 33 F6 8D 84 24 ?? ?? - ?? ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 DB 74 ?? F6 C3 ?? 74 ?? 8D 84 24 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? 83 F8 ?? 74 ?? 83 F8 ?? 75 ?? 6A ?? 6A ?? C6 84 - 24 ?? ?? ?? ?? ?? FF D7 50 FF 15 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 89 44 B5 ?? 51 50 - FF 15 ?? ?? ?? ?? 46 FE 84 24 ?? ?? ?? ?? D1 EB 75 ?? 33 FF 85 F6 7E ?? 8B 9C 24 ?? - ?? ?? ?? 8D 44 24 ?? 2B E8 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 8C - 24 ?? ?? ?? ?? 89 48 ?? 8D 0C BD ?? ?? ?? ?? 03 CD 89 58 ?? 8B 4C 0C ?? 89 08 33 C9 - 51 51 50 68 ?? ?? ?? ?? 51 51 FF 15 ?? ?? ?? ?? 89 44 BC ?? 47 3B FE 7C ?? 6A ?? 6A - ?? 8D 44 24 ?? 50 56 FF 15 - } - $kill_specific_processes_3 = { - E8 ?? ?? ?? ?? 83 C4 ?? 89 74 24 ?? 55 6A ?? E8 ?? ?? ?? ?? 8B F8 89 7C 24 ?? 83 FF - ?? 0F 84 ?? ?? ?? ?? 53 8D 84 24 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 50 57 - E8 ?? ?? ?? ?? 8B 5C 24 ?? 83 BC 24 ?? ?? ?? ?? ?? 8B F5 7E ?? 55 8D 84 24 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? 8B E8 8D 84 24 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 33 DB 89 44 24 - ?? 85 C0 7E ?? 8B F8 0F BE 0C 2B 51 E8 ?? ?? ?? ?? 88 04 2B 43 3B DF 7C ?? 8B 84 24 - ?? ?? ?? ?? FF 34 B0 55 FF 15 ?? ?? ?? ?? 8B D8 85 DB 75 ?? 46 50 5D 3B B4 24 ?? ?? - ?? ?? 7C ?? 8B 7C 24 ?? 33 ED 85 DB 74 ?? 55 68 ?? ?? ?? ?? 55 FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 55 50 FF 15 ?? ?? ?? ?? FF B4 24 ?? ?? ?? ?? 8B F0 68 ?? ?? ?? ?? 56 FF - 15 ?? ?? ?? ?? 83 C4 ?? 8D 44 24 ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 56 8D 44 24 - ?? 50 FF 15 ?? ?? ?? ?? 8D 44 24 ?? 50 8D 44 24 ?? 50 55 55 68 ?? ?? ?? ?? 55 55 55 - 8D 84 24 ?? ?? ?? ?? 50 55 FF 15 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? - ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 - } + $a = { 00 00 5B 72 65 73 6F 6C 76 5D 20 46 6F 75 6E 64 20 49 50 20 } condition: - uint16(0)==0x5A4D and (($search_files_1 and $encrypt_files_1 and $kill_specific_processes_1) or ($search_files_1 and $encrypt_files_2 and $kill_specific_processes_2) or ($search_files_2 and $encrypt_files_3 and $kill_specific_processes_3)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_MZP : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_2E3F67A9 : FILE MEMORY { meta: - description = "Yara rule that detects MZP ransomware." - author = "ReversingLabs" - id = "c08a4080-fa26-5b7b-869d-5f59096b1a12" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.MZP.yara#L1-L147" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "724ae1033bfb8ff494b30e6b3333e6c848375f1b001b75e71c9444c9f9f31251" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "2e3f67a9-6fd5-4457-a626-3a9015bdb401" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1125-L1143" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb" + logic_hash = "8c83c5d32c58041444f33264f692a7580c76324d2cbad736fdd737bdfcd63595" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "MZP" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "6a06815f3d2e5f1a7a67f4264953dbb2e9d14e5f3486b178da845eab5b922d4f" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $show_ransom_note_p1 = { - 55 8B EC B9 ?? ?? ?? ?? 6A ?? 6A ?? 49 75 ?? 53 56 84 D2 74 ?? 83 C4 ?? E8 ?? ?? ?? - ?? 88 55 ?? 8B D8 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 33 D2 8B C3 E8 ?? ?? ?? - ?? 89 1D ?? ?? ?? ?? 33 C9 B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 89 73 ?? 33 C0 - 89 46 ?? 33 C0 89 86 ?? ?? ?? ?? 33 C0 89 86 ?? ?? ?? ?? C7 86 ?? ?? ?? ?? ?? ?? ?? - ?? C7 86 ?? ?? ?? ?? ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? C7 86 ?? ?? ?? ?? ?? ?? ?? ?? - 6A ?? 6A ?? 8D 45 ?? 50 33 C9 B2 ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 55 ?? 8D 86 ?? - ?? ?? ?? 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? - C6 86 ?? ?? ?? ?? ?? 33 C0 89 86 ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? 33 C0 89 86 ?? ?? - ?? ?? C6 86 ?? ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? 8D 86 ?? ?? ?? ?? 33 D2 E8 ?? ?? ?? - ?? 8D 86 ?? ?? ?? ?? 33 D2 E8 ?? ?? ?? ?? 33 C0 89 86 ?? ?? ?? ?? 33 C0 89 86 ?? ?? - ?? ?? C6 86 ?? ?? ?? ?? ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 - ?? ?? ?? ?? B2 ?? 8B C6 E8 ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? A1 ?? ?? - ?? ?? 8B 00 50 E8 ?? ?? ?? ?? 8B D0 8B C6 E8 ?? ?? ?? ?? 33 D2 8B C6 E8 - } - $show_ransom_note_p2 = { - C6 86 ?? ?? ?? ?? ?? C7 86 ?? ?? ?? ?? ?? ?? ?? ?? 8D 86 ?? ?? ?? ?? 33 D2 E8 ?? ?? - ?? ?? C6 86 ?? ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? 89 B6 ?? ?? ?? ?? C7 86 ?? ?? ?? ?? - ?? ?? ?? ?? 33 C0 89 86 ?? ?? ?? ?? 33 C0 89 86 ?? ?? ?? ?? 8B C6 8B 10 FF 52 ?? B2 - ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 89 73 ?? 8D 46 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? C6 46 ?? ?? C6 46 ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 89 73 ?? C6 46 - ?? ?? 8D 46 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - F0 89 73 ?? BA ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 - 8D 46 ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 89 73 ?? 8B C6 C6 - 40 ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 89 73 - ?? 8B C6 C6 40 ?? ?? 66 BA ?? ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 89 43 ?? 8B 73 ?? 8D 46 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 46 ?? 33 D2 E8 ?? ?? ?? - ?? C6 46 ?? ?? C6 46 ?? ?? C6 46 ?? ?? C6 46 ?? ?? C6 46 ?? ?? 8D 46 ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 43 ?? B2 ?? A1 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 89 43 ?? 8B 73 ?? 8D 46 ?? 33 D2 E8 ?? ?? ?? ?? 8D 46 ?? BA ?? ?? ?? - ?? E8 - } - $search_config_file = { - 8B C0 53 56 8B F0 8A 9E ?? ?? ?? ?? C6 86 ?? ?? ?? ?? ?? 80 BE ?? ?? ?? ?? ?? 75 ?? - 8B 46 ?? 8B 48 ?? A1 ?? ?? ?? ?? 33 D2 E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 33 D2 8B - 86 ?? ?? ?? ?? FF 96 ?? ?? ?? ?? 83 BE ?? ?? ?? ?? ?? 74 ?? 8B 96 ?? ?? ?? ?? B8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 89 B6 ?? ?? ?? ?? C7 86 ?? ?? ?? ?? ?? ?? ?? ?? - EB ?? 89 B6 ?? ?? ?? ?? C7 86 ?? ?? ?? ?? ?? ?? ?? ?? 88 9E ?? ?? ?? ?? 8A 96 ?? ?? - ?? ?? 8B C6 E8 ?? ?? ?? ?? 80 BE ?? ?? ?? ?? ?? 74 ?? 8B 46 ?? 8B 8E ?? ?? ?? ?? 8B - 96 ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 8B 46 ?? E8 ?? ?? ?? ?? 8B 46 ?? 89 - 70 ?? 5E 5B C3 - } - $track_mouse_event_for_entropy = { - 53 56 83 C4 ?? 8B F0 8B 42 ?? 05 ?? ?? ?? ?? 83 E8 ?? 72 ?? 2D ?? ?? ?? ?? 0F 84 ?? - ?? ?? ?? E9 ?? ?? ?? ?? 8A 86 ?? ?? ?? ?? 88 44 24 ?? 66 83 BE ?? ?? ?? ?? ?? 74 ?? - 8B D6 8B 86 ?? ?? ?? ?? FF 96 ?? ?? ?? ?? 8B D8 EB ?? 54 E8 ?? ?? ?? ?? 8D 4C 24 ?? - 8B D4 8B C6 E8 ?? ?? ?? ?? 8B 44 24 ?? 89 04 24 8B 44 24 ?? 89 44 24 ?? 8D 54 24 ?? - 8B C6 E8 ?? ?? ?? ?? 8D 54 24 ?? 8B C4 E8 ?? ?? ?? ?? 8B D8 3A 5C 24 ?? 0F 84 ?? ?? - ?? ?? 8B C6 E8 ?? ?? ?? ?? 84 DB 74 ?? C6 86 ?? ?? ?? ?? ?? 66 83 BE ?? ?? ?? ?? ?? - 74 ?? 8B D6 8B 86 ?? ?? ?? ?? FF 96 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? 8B 46 ?? 89 44 24 ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? EB - ?? C6 86 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 46 ?? 89 - 44 24 ?? 8D 44 24 ?? E8 ?? ?? ?? ?? 66 83 BE ?? ?? ?? ?? ?? 74 ?? 8B D6 8B 86 ?? ?? - ?? ?? FF 96 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? EB ?? 80 BE ?? ?? ?? ?? ?? 74 ?? C6 86 - ?? ?? ?? ?? ?? 66 83 BE ?? ?? ?? ?? ?? 74 ?? 8B D6 8B 86 ?? ?? ?? ?? FF 96 ?? ?? ?? - ?? 8B C6 E8 ?? ?? ?? ?? 33 C0 83 C4 ?? 5E 5B C3 - } - $find_files_p1 = { - 55 8B EC 81 C4 ?? ?? ?? ?? 53 56 57 33 C9 89 8D ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 8B FA - 8B D8 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? - ?? B9 ?? ?? ?? ?? 8B D7 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? 8B F0 83 FE ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 43 ?? 8D 85 ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? 33 C9 8A 08 41 E8 - ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? - 0F 84 ?? ?? ?? ?? 80 7B ?? ?? 76 ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B D7 8B C3 E8 ?? ?? ?? ?? 80 7B ?? ?? 0F 85 ?? - ?? ?? ?? 57 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? - ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 43 ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 95 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 53 ?? E8 ?? ?? ?? ?? 84 C0 74 ?? FF 43 - } - $find_files_p2 = { - 80 7B ?? ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B D7 8B C3 E8 ?? ?? ?? ?? EB ?? 80 7B ?? ?? 74 ?? 8D - 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 8B D7 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8D 43 ?? E8 ?? ?? ?? ?? EB ?? - 8D 85 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? - 8D 43 ?? E8 ?? ?? ?? ?? 80 7B ?? ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 85 - C0 0F 85 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 - } - $encrypt_files = { - 8B C0 33 D2 89 50 ?? 89 50 ?? 52 8D 50 ?? 52 FF 70 ?? FF 70 ?? FF 30 E8 ?? ?? ?? ?? - 85 C0 74 ?? 33 C0 C3 E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? C3 33 C0 C3 51 8B 50 ?? 85 D2 7E - ?? 33 C9 89 48 ?? 51 8D 4C 24 ?? 51 52 FF 70 ?? FF 30 E8 ?? ?? ?? ?? 85 C0 74 ?? 33 - C0 59 C3 E8 ?? ?? ?? ?? EB ?? FF 30 C7 40 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 75 ?? C3 - E8 ?? ?? ?? ?? C3 56 8B F0 33 C0 89 46 ?? 89 46 ?? 8B 46 ?? 2D ?? ?? ?? ?? 74 ?? 48 - 74 ?? 48 74 ?? E9 ?? ?? ?? ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? C7 46 ?? - ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? BA ?? ?? ?? ?? B9 ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? - BA ?? ?? ?? ?? B9 ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? ?? ?? ?? C7 46 ?? ?? - ?? ?? ?? 80 7E ?? ?? 0F 84 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 51 6A ?? 52 50 8D 46 ?? - 50 E8 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 89 06 81 7E ?? ?? ?? ?? ?? 0F 85 ?? ?? - ?? ?? FF 4E ?? 6A ?? FF 36 E8 ?? ?? ?? ?? 40 0F 84 ?? ?? ?? ?? 2D ?? ?? ?? ?? 73 ?? - 33 C0 6A ?? 6A ?? 50 FF 36 E8 ?? ?? ?? ?? 40 0F 84 ?? ?? ?? ?? 6A ?? 8B D4 6A ?? 52 - 68 ?? ?? ?? ?? 8D 96 ?? ?? ?? ?? 52 FF 36 E8 ?? ?? ?? ?? 5A 48 0F 85 ?? ?? ?? ?? 33 - C0 3B C2 73 ?? 80 BC 06 ?? ?? ?? ?? ?? 74 ?? 40 EB ?? 6A ?? 6A ?? 2B C2 50 FF 36 E8 - ?? ?? ?? ?? 40 74 ?? FF 36 E8 ?? ?? ?? ?? 48 75 ?? EB ?? C7 46 ?? ?? ?? ?? ?? 81 7E - ?? ?? ?? ?? ?? 74 ?? 6A ?? EB ?? 6A ?? E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? 89 06 81 7E ?? - ?? ?? ?? ?? 74 ?? FF 36 E8 ?? ?? ?? ?? 85 C0 74 ?? 83 F8 ?? 75 ?? C7 46 ?? ?? ?? ?? - ?? 33 C0 5E C3 - } + $a = { 53 83 EC 04 0F B6 74 24 14 8B 5C 24 18 8B 7C 24 20 0F B6 44 } condition: - uint16(0)==0x5A4D and ($search_config_file) and ( all of ($find_files_p*)) and ($track_mouse_event_for_entropy) and ($encrypt_files) and ( all of ($show_ransom_note_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Mountlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_01E4A728 : FILE MEMORY { meta: - description = "Yara rule that detects MountLocker ransomware." - author = "ReversingLabs" - id = "8ce7e5c4-9eca-5dd2-ab92-39b915900d72" - date = "2021-03-25" - modified = "2021-03-25" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.MountLocker.yara#L1-L86" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "d203217c229d54802e96e19dc66d38ecb0443d19e0492efe337df471a99559dc" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "01e4a728-7c1c-479b-aed0-cb76d64dbb02" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1145-L1162" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "753936b97a36c774975a1d0988f6f908d4b5e5906498aa34c606d4cd971f1ba5" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "MountLocker" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 55 8B EC 83 E4 ?? 83 EC ?? 53 56 57 8B 3D ?? ?? ?? ?? 8B DA 8B F1 FF D7 89 44 24 ?? - 33 C0 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? 56 89 54 24 ?? 89 44 24 ?? FF 15 - ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8D 4C 24 ?? 51 50 FF 15 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? FF 74 24 ?? FF 74 24 ?? 6A ?? 6A ?? FF 74 24 ?? FF - 15 ?? ?? ?? ?? 89 44 24 ?? 85 C0 0F 84 ?? ?? ?? ?? 33 C9 0F 31 89 44 8C ?? 41 83 F9 - ?? 72 ?? FF 75 ?? 8B D3 8D 4C 24 ?? E8 ?? ?? ?? ?? 89 44 24 ?? 59 85 C0 74 ?? 8D 4C - 24 ?? E8 ?? ?? ?? ?? 89 44 24 ?? 8B 7C 24 ?? 8B 44 24 ?? 89 7C 24 ?? 89 44 24 ?? 8B - 35 ?? ?? ?? ?? 8B DE 8B 15 ?? ?? ?? ?? 03 DF 8B CA 89 54 24 ?? 13 C8 BF ?? ?? ?? ?? - 8B C6 F0 0F C7 0F 8B 7C 24 ?? 3B C6 8B 44 24 ?? 75 ?? 3B 54 24 ?? 75 ?? FF 74 24 ?? - 8B 35 ?? ?? ?? ?? FF D6 FF 74 24 ?? FF D6 8B 3D ?? ?? ?? ?? FF D7 8B F8 8B C2 2B 7C - 24 ?? 89 7C 24 ?? 1B 44 24 ?? 89 44 24 ?? 75 ?? 85 FF 0F 84 ?? ?? ?? ?? 8B 35 ?? ?? - ?? ?? 8B DE 8B 15 ?? ?? ?? ?? 03 DF 8B CA 89 54 24 ?? 13 C8 BF ?? ?? ?? ?? 8B C6 F0 - 0F C7 0F 8B 7C 24 ?? 3B C6 8B 44 24 ?? 75 ?? 3B 54 24 ?? 75 ?? 50 57 FF 74 24 ?? FF - 74 24 ?? E8 ?? ?? ?? ?? 89 44 24 ?? 8B C2 81 E2 ?? ?? ?? ?? 25 ?? ?? ?? ?? 89 54 24 - ?? DF 6C 24 ?? 83 64 24 ?? ?? 89 44 24 ?? DF 6C 24 ?? D9 E0 DE C1 D9 5C 24 ?? D9 44 - 24 ?? D9 05 ?? ?? ?? ?? D8 D9 DF E0 F6 C4 ?? 7A ?? D9 1D ?? ?? ?? ?? EB ?? DD D8 8B - 44 24 ?? EB ?? 8B 44 24 ?? 85 C0 8B 35 ?? ?? ?? ?? 74 ?? 50 FF D6 FF 74 24 ?? FF D6 - 33 C0 5F 5E 5B 8B E5 5D C3 - } - $encrypt_files_p2 = { - 55 8B EC 83 EC ?? 53 56 57 33 FF 6A ?? 8B F7 5B 0F 31 6A ?? 89 86 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 83 C6 ?? 3B F3 72 ?? 8B D3 B9 ?? ?? ?? ?? 8A 01 88 41 ?? 41 83 EA ?? 75 - ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 57 8D 45 ?? 89 5D ?? 50 89 7D ?? 89 7D ?? FF - 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 57 57 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 68 ?? ?? - ?? ?? 57 6A ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? 8B F0 FF 15 ?? ?? ?? ?? 57 FF - 75 ?? FF 15 ?? ?? ?? ?? 85 F6 74 ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? ?? ?? 33 C0 40 - EB ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5F 5E - 5B 8B E5 5D C3 - } - $find_files_p1 = { - 53 55 56 8B 74 24 ?? 8B EA 57 8B F9 6A ?? 83 26 ?? 58 66 89 44 6F ?? 8D 5F ?? 33 C0 - 66 89 44 6F ?? 8D 87 ?? ?? ?? ?? 50 A1 ?? ?? ?? ?? 53 89 44 24 ?? FF D0 33 C9 66 89 - 4C 6F ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 39 4F ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 - F8 ?? 0F 85 ?? ?? ?? ?? 8D 46 ?? 50 6A ?? 8D 4E ?? 51 8D 56 ?? 52 8D 46 ?? 50 6A ?? - 6A ?? 8D 5F ?? 53 FF 15 ?? ?? ?? ?? F7 D8 1B C0 83 C0 ?? 89 06 74 ?? 8B CB E8 ?? ?? - ?? ?? 85 C0 74 ?? 6A ?? 58 66 89 44 6F ?? 33 C0 66 89 44 6F ?? 8D 87 ?? ?? ?? ?? 50 - 53 FF 54 24 ?? 33 C9 66 89 4C 6F ?? 83 F8 ?? 75 ?? 39 0E 74 ?? 51 FF 76 ?? FF 76 ?? - FF 76 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 83 3E ?? 74 ?? FF 76 ?? FF 15 ?? ?? ?? ?? - 83 26 ?? 83 C8 ?? 5F 5E 5D 5B C3 - } - $find_files_p2 = { - 55 8B EC 83 E4 ?? 83 EC ?? 53 55 56 8B F1 57 FF 46 ?? 8D 7E ?? 8B 07 8D 5E ?? 89 44 - 24 ?? 8B 46 ?? 53 89 07 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? 89 44 24 ?? 51 8B D0 8B CE E8 - ?? ?? ?? ?? 8B E8 59 83 FD ?? 75 ?? 33 C0 E9 ?? ?? ?? ?? 53 8D 86 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 8D 9E ?? ?? ?? ?? F6 03 ?? 74 ?? 8B 54 24 ?? 8B CE E8 ?? ?? ?? ?? EB - ?? 8D 86 ?? ?? ?? ?? 50 8B 44 24 ?? 05 ?? ?? ?? ?? 8D 04 46 50 FF 15 ?? ?? ?? ?? FF - 76 ?? 57 6A ?? FF 16 83 C4 ?? 85 C0 74 ?? 53 55 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 55 FF - 15 ?? ?? ?? ?? 83 7E ?? ?? 8D 5E ?? 74 ?? 83 7C 24 ?? ?? 74 ?? 6A ?? FF 74 24 ?? FF - 74 24 ?? FF 74 24 ?? 6A ?? 6A ?? 53 FF 15 ?? ?? ?? ?? 83 7C 24 ?? ?? 74 ?? FF 74 24 - ?? FF 15 ?? ?? ?? ?? 8B 4C 24 ?? 33 C0 89 0F 40 5F 5E 5D 5B 8B E5 5D C3 - } + $a = { 44 24 23 48 8B 6C 24 28 83 F9 01 4A 8D 14 20 0F B6 02 88 45 08 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Ransoc : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_64D5Cde2 : FILE MEMORY { meta: - description = "Yara rule that detects Ransoc ransomware." - author = "ReversingLabs" - id = "a990754e-eafa-5501-a123-bcbd5aa26ca6" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Ransoc.yara#L1-L114" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "1f48f1b713c18b099e863d8a11e872ae84df0ea355f01cba765e8333d8d98575" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "64d5cde2-e4b1-425b-8af3-314a5bf519a9" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1164-L1182" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "caf2a8c199156db2f39dbb0a303db56040f615c4410e074ef56be2662752ca9d" + logic_hash = "08f3635e5517185cae936b39f503bbeba5aed2e36abdd805170a259bc5e3644f" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Ransoc" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "1a69f91b096816973ce0c2e775bcf2a54734fa8fbbe6ea1ffcf634ce2be41767" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $scan_for_services = { - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 66 A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 66 39 2D ?? ?? ?? ?? 73 ?? 66 01 1D ?? ?? ?? ?? 03 F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B9 ?? ?? ?? ?? 66 89 - 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 39 2D ?? ?? ?? ?? 73 ?? 66 01 1D ?? ?? ?? ?? 03 F3 - E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 - C0 75 ?? BA ?? ?? ?? ?? 66 89 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 39 2D ?? ?? ?? ?? 73 - ?? 66 01 1D ?? ?? ?? ?? 03 F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 66 A3 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 66 39 2D ?? ?? ?? ?? 73 ?? 66 01 1D ?? ?? ?? ?? 03 F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B9 ?? ?? ?? ?? 66 - 89 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 39 2D ?? ?? ?? ?? 73 ?? 66 01 1D ?? ?? ?? ?? 03 - F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 85 C0 75 ?? BA ?? ?? ?? ?? 66 89 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 FF 66 39 2D ?? ?? - ?? ?? 73 ?? A1 ?? ?? ?? ?? 50 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 66 01 1D ?? ?? ?? ?? 8B - FB 03 F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 75 ?? BA ?? ?? ?? ?? 66 89 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 66 39 2D ?? ?? - ?? ?? 73 ?? 85 FF 75 ?? A1 ?? ?? ?? ?? 50 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 66 - 01 1D ?? ?? ?? ?? 03 F3 E8 ?? ?? ?? ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? BA ?? ?? ?? ?? 66 89 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? - EB ?? 85 FF 74 ?? 8D 44 24 ?? 50 E8 - } - $remote_connection = { - 8B 44 24 ?? 83 EC ?? 53 8B 5C 24 ?? 56 8B 74 24 ?? 50 56 E8 ?? ?? ?? ?? 8B D8 83 C4 - ?? 83 FB ?? 75 ?? 5E B8 ?? ?? ?? ?? 5B 83 C4 ?? C3 8B 4C 24 ?? 55 8B 6C 24 ?? 57 55 - 56 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 56 FF 15 ?? ?? ?? ?? 50 56 53 E8 - ?? ?? ?? ?? 56 8B F8 E8 ?? ?? ?? ?? 83 C4 ?? 83 FF ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 8D - 47 ?? 5F 5D 5E 5B 83 C4 ?? C3 8B 44 24 ?? 85 C0 74 ?? 85 ED 74 ?? 55 50 53 E8 ?? ?? - ?? ?? 83 C4 ?? 83 F8 ?? 75 ?? 53 FF 15 ?? ?? ?? ?? 5F 5D 5E B8 ?? ?? ?? ?? 5B 83 C4 - ?? C3 8D 54 24 ?? 52 E8 ?? ?? ?? ?? 8B 2D ?? ?? ?? ?? 83 C4 ?? 8D 49 ?? 8B 74 24 ?? - 8B C6 2B 44 24 ?? 75 ?? 8D 4C 24 ?? 6A ?? 51 E8 ?? ?? ?? ?? 8B 74 24 ?? 83 C4 ?? 2B - 74 24 ?? 6A ?? 56 8D 54 24 ?? 56 52 E8 ?? ?? ?? ?? 83 C4 ?? 50 53 FF D5 8B F8 85 FF - 78 ?? 2B C6 01 44 24 ?? EB ?? 29 74 24 ?? 83 FF ?? 74 ?? 85 FF 75 ?? 53 FF 15 ?? ?? - ?? ?? 85 FF 79 ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 5F 5D 5E B8 ?? ?? ?? ?? 5B - 83 C4 ?? C3 8D 54 24 ?? 6A ?? 52 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? 68 ?? ?? ?? ?? - 50 FF 15 ?? ?? ?? ?? 8B F0 85 F6 75 ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 5F 5D - 8D 46 ?? 5E 5B 83 C4 ?? C3 8B 54 24 ?? 83 C2 ?? 6A ?? 52 E8 ?? ?? ?? ?? 8B 4C 24 ?? - 8B 54 24 ?? 8B F8 8B 44 24 ?? 2B F0 83 C6 ?? 2B CE 51 03 F0 56 52 E8 ?? ?? ?? ?? 8D - 44 24 ?? 50 E8 - } - $encrypt_files = { - 81 EC ?? ?? ?? ?? 53 55 56 8B 35 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? - 8B F8 FF D6 8B 8C 24 ?? ?? ?? ?? 8B E8 8B 84 24 ?? ?? ?? ?? 50 51 57 8D 94 24 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 6A ?? 50 - E8 ?? ?? ?? ?? 8B BC 24 ?? ?? ?? ?? 8B 8C 24 ?? ?? ?? ?? 83 C4 ?? 89 4C 24 ?? BB ?? - ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? EB ?? 8D 49 ?? 55 68 ?? ?? ?? ?? 83 FB ?? 7E ?? 8D - 94 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8D 74 24 ?? 8D BC 24 ?? ?? ?? ?? 52 F3 A5 E8 ?? ?? - ?? ?? 8B BC 24 ?? ?? ?? ?? 88 9C 2C ?? ?? ?? ?? 8D 75 ?? EB ?? 8D 84 24 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 88 9C 2C ?? ?? ?? ?? 8D 75 ?? 83 C4 ?? 6A ?? 8D 4C 24 ?? 6A ?? 51 - E8 ?? ?? ?? ?? 6A ?? 8D 94 24 ?? ?? ?? ?? 52 8D 44 24 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 8D 44 24 ?? B9 ?? ?? ?? ?? 80 30 ?? 40 49 75 ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 6A ?? - 8D 54 24 ?? 52 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 56 8D 8C 24 ?? ?? ?? ?? 51 8D - 94 24 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 50 8D 4C 24 ?? 51 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 44 24 ?? B9 ?? ?? ?? ?? 8B FF 80 30 ?? 40 49 75 ?? 8D 54 24 ?? 52 - E8 ?? ?? ?? ?? 6A ?? 8D 44 24 ?? 50 8D 8C 24 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 6A ?? 8D - 54 24 ?? 52 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8D 8C 24 ?? ?? ?? ?? 51 8D 54 24 - ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B F7 83 FF ?? 72 ?? BE ?? ?? ?? ?? 8B 4C 24 ?? 56 8D - 44 24 ?? 50 51 E8 ?? ?? ?? ?? 01 74 24 ?? 2B FE 83 C4 ?? 43 89 BC 24 ?? ?? ?? ?? 85 - FF 0F 85 ?? ?? ?? ?? 5F 5E 5D 5B 81 C4 ?? ?? ?? ?? C3 - } - $find_files = { - 83 EC ?? 53 55 56 57 33 DB 68 ?? ?? ?? ?? 6A ?? 89 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? - ?? 8B E8 8D 44 24 ?? 50 89 6C 24 ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? 55 51 E8 ?? ?? ?? ?? - 8B 74 24 ?? 6A ?? 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 55 68 ?? ?? ?? - ?? 89 5C 24 ?? 89 5C 24 ?? E8 ?? ?? ?? ?? 8B F8 57 8D 54 24 ?? 52 8D 44 24 ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 89 44 24 ?? 3B C3 75 ?? 8B 4C 24 ?? 51 8D 54 24 ?? 52 E8 ?? ?? - ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? - ?? ?? 8B 44 24 ?? 50 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 4C 24 ?? - 51 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 54 24 ?? 52 56 E8 ?? ?? ?? - ?? 83 C4 ?? 33 FF 39 5C 24 ?? 76 ?? 8D 64 24 ?? 8B 44 24 ?? 8B 0C B8 51 56 E8 ?? ?? - ?? ?? 47 83 C4 ?? 3B 7C 24 ?? 72 ?? 39 5C 24 ?? 75 ?? 8B 44 24 ?? 3B C3 74 ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 54 24 ?? 52 56 E8 ?? ?? ?? - ?? 8B 44 24 ?? 83 C4 ?? 89 5C 24 ?? 3B C3 0F 86 ?? ?? ?? ?? EB ?? 8D 9B ?? ?? ?? ?? - 8B 44 24 ?? 8B 4C 24 ?? 8B 1C 88 53 55 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 57 68 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 57 68 ?? ?? ?? ?? 8B E8 E8 ?? ?? ?? ?? 6A ?? 56 89 44 24 ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 53 56 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? - 56 E8 ?? ?? ?? ?? 33 C0 8D 54 24 ?? 55 52 C7 44 24 ?? ?? ?? ?? ?? 89 44 24 ?? 89 84 - 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 - 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 50 56 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8D 44 24 ?? 50 56 - E8 ?? ?? ?? ?? 8D 4C 24 ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? - ?? 8B 5C 24 ?? E8 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 55 E8 ?? ?? ?? ?? 8B D3 52 E8 ?? ?? - ?? ?? 8B 4C 24 ?? 8B 44 24 ?? 8B 6C 24 ?? 41 83 C4 ?? 89 4C 24 ?? 3B C8 0F 82 ?? ?? - ?? ?? 33 DB 33 F6 3B C3 76 ?? 8B 44 24 ?? 8B 0C B0 51 E8 ?? ?? ?? ?? 46 83 C4 ?? 3B - 74 24 ?? 72 ?? 8D 54 24 ?? 52 E8 ?? ?? ?? ?? 55 E8 ?? ?? ?? ?? 8B 44 24 ?? 83 C4 ?? - 3B C3 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 44 24 ?? 5F 5E 5D 3B C3 5B 74 ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 83 C4 ?? C3 - } + $a = { 0F 35 7E B3 02 00 D0 02 00 00 07 01 00 00 0E 00 00 00 18 03 00 } condition: - uint16(0)==0x5A4D and $scan_for_services and $find_files and $encrypt_files and $remote_connection + all of them } -rule REVERSINGLABS_Win32_Ransomware_Afrodita : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_0D73971C : FILE MEMORY { meta: - description = "Yara rule that detects Afrodita ransomware." - author = "ReversingLabs" - id = "513963fd-5f3d-5d31-a65a-37f6f5c72260" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Afrodita.yara#L1-L119" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ce7cc445d4c1f59c25b9505fc1f7f9dd0d286ab80510e2977b50ff15433aea60" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "0d73971c-4253-4e7d-b1e1-20b031197f9e" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1184-L1202" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "49c94d184d7e387c3efe34ae6f021e011c3046ae631c9733ab0a230d5fe28ead" + logic_hash = "56f3bac05fce0a0458e5b80197335e7bef6dcd50b9feb6f1008b8679f29cf37a" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Afrodita" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "95279bc45936ca867efb30040354c8ff81de31dccda051cfd40b4fb268c228c5" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $exclude_directories_and_drop_ransom_note = { - 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8D 8D ?? ?? - ?? ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? ?? ?? 8D 95 ?? - ?? ?? ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? ?? ?? 8D - 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 ?? - ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? E9 - ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 E0 ?? 75 ?? E9 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B - 55 ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? - ?? ?? 89 8D ?? ?? ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 8D 4D ?? E8 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? - ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8B 55 ?? 52 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 6A - ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A ?? 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D - 4D ?? E8 ?? ?? ?? ?? EB ?? B8 - } - $drop_ransom_note_no_dir_exclusion = { - 8D 95 ?? ?? ?? ?? 52 8B 43 ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 - ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 89 95 ?? ?? ?? ?? C6 45 ?? ?? 68 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 8B 95 ?? - ?? ?? ?? 52 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D - 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 33 C0 88 85 ?? ?? ?? ?? 33 C9 88 8D ?? ?? - ?? ?? 33 D2 88 95 ?? ?? ?? ?? 0F B6 85 ?? ?? ?? ?? 50 0F B6 8D ?? ?? ?? ?? 51 0F B6 - 95 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B C8 E8 ?? ?? ?? ?? - 50 8B 4B ?? 51 8D 55 ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? - 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? - 6A ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 FF 15 - ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 FF 15 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? EB ?? 8B - 5D ?? B8 ?? ?? ?? ?? C3 C7 45 - } - $find_files_p1 = { - 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 4D ?? 8B 55 ?? 53 - 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 74 ?? - 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 ?? ?? ?? ?? 8A 01 88 85 ?? ?? ?? - ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? - ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 8A C3 75 ?? B0 ?? 2B - CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D ?? ?? ?? ?? 56 1B C0 89 9D ?? ?? ?? ?? - 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? F7 D8 - } - $find_files_p2 = { - 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 - ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? - ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 ?? 8A 48 ?? 84 C9 74 ?? - 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? - ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? - ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? - 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 8B D8 56 FF 15 ?? ?? ?? - ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B C3 8B 4D ?? - 5F 33 CD 5B E8 ?? ?? ?? ?? C9 C3 - } - $encrypt_files = { - 53 8B DC 83 EC ?? 83 E4 ?? 83 C4 ?? 55 8B 6B ?? 89 6C 24 ?? 8B EC 6A ?? 68 ?? ?? ?? - ?? 64 A1 ?? ?? ?? ?? 50 53 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 50 8D 45 - ?? 64 A3 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? 6A ?? 6A ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4B ?? 51 - FF 15 ?? ?? ?? ?? 83 E0 ?? 74 ?? 8B 53 ?? 52 FF 15 ?? ?? ?? ?? 83 E0 ?? 50 8B 43 ?? - 50 FF 15 ?? ?? ?? ?? 8B 4B ?? 51 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 8B 53 - ?? 52 8D 45 ?? 50 83 EC ?? 8B CC 89 A5 ?? ?? ?? ?? 51 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? - ?? ?? C6 45 ?? ?? 8D 55 ?? 52 8B 43 ?? 50 8D 4D ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 - ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 8B 43 ?? 50 8D - 4D ?? 51 83 EC ?? 8B D4 89 A5 ?? ?? ?? ?? 52 8B 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8B 43 ?? 50 8B 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? ?? - C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 8B 4D ?? - 33 CD E8 ?? ?? ?? ?? 8B E5 5D 8B E3 5B C2 - } + $a = { 89 C2 83 EB 04 C1 E2 0B 31 C2 89 F0 C1 E8 13 89 D1 31 F0 C1 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ($encrypt_files) and (($exclude_directories_and_drop_ransom_note) or ($drop_ransom_note_no_dir_exclusion)) + all of them } -rule REVERSINGLABS_Win64_Ransomware_Rook : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_82C361D4 : FILE MEMORY { meta: - description = "Yara rule that detects Rook ransomware." - author = "ReversingLabs" - id = "60bbfd57-18bb-58b3-9abc-ab30943bbddd" - date = "2022-01-17" - modified = "2022-01-17" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Rook.yara#L1-L122" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "dc8b37e55b634de52855dd851dbaaf3e690adfb2e875d0e0c9ef5f4846c6ff30" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "82c361d4-2adf-48f2-a9be-677676d7451f" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1204-L1222" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "f8dbcf0fc52f0c717c8680cb5171a8c6c395f14fd40a2af75efc9ba5684a5b49" + logic_hash = "766a964d7d35525fbc88adcf86fb69d11f9c63c0d28ceefb3ae79797a7161193" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Rook" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "a8a4252c6f7006181bdb328d496e0e29522f87e55229147bc6cf4d496f5828fb" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files = { - 48 2B D6 48 8D 4C 24 ?? 48 FF C2 41 B8 ?? ?? ?? ?? F6 D8 4D 1B FF 4C 23 FA 33 D2 E8 - ?? ?? ?? ?? 45 33 C9 89 7C 24 ?? 4C 8D 44 24 ?? 48 89 7C 24 ?? 33 D2 48 8B CE FF 15 - ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 75 ?? 4D 8B CE 45 33 C0 33 D2 48 8B CE E8 ?? ?? ?? - ?? 8B F8 48 83 FB ?? 74 ?? 48 8B CB FF 15 ?? ?? ?? ?? 8B C7 48 8B 8C 24 ?? ?? ?? ?? - 48 33 CC E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5E 5F - 5E 5D C3 49 8B 6E ?? 49 2B 2E 48 C1 FD ?? 80 7C 24 ?? ?? 75 ?? 8A 44 24 ?? 84 C0 74 - ?? 3C ?? 75 ?? 40 38 7C 24 ?? 74 ?? 4D 8B CE 48 8D 4C 24 ?? 4D 8B C7 48 8B D6 E8 ?? - ?? ?? ?? 85 C0 75 ?? 48 8D 54 24 ?? 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 75 ?? 49 8B 06 - 49 8B 56 ?? 48 2B D0 48 C1 FA ?? 48 3B EA 0F 84 ?? ?? ?? ?? 48 2B D5 48 8D 0C E8 4C - 8D 0D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 - } - $encrypt_files_p1 = { - 40 55 53 56 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? F2 0F 10 05 ?? ?? ?? ?? 0F - B6 05 ?? ?? ?? ?? F2 0F 11 44 24 ?? 88 44 24 ?? E8 ?? ?? ?? ?? 33 D2 48 8D 0D ?? ?? - ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 83 CE ?? 48 8D 4C 24 ?? 89 35 ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 48 63 C8 4C 8D 4C 24 ?? 48 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8D 4C 24 - ?? FF 15 ?? ?? ?? ?? 48 63 C8 4C 8D 4C 24 ?? 48 89 4C 24 ?? E8 ?? ?? ?? ?? 0F 57 C0 - 0F 57 C9 F3 0F 7F 05 ?? ?? ?? ?? F3 0F 7F 0D ?? ?? ?? ?? F3 0F 7F 05 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 48 85 C0 48 89 05 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? 48 0F 44 0D ?? ?? ?? - ?? 48 89 0D ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF C0 48 8D 15 ?? ?? - ?? ?? 4C 63 C0 48 8D 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 8D 15 ?? - ?? ?? ?? 48 89 05 ?? ?? ?? ?? 33 DB 48 8B 05 ?? ?? ?? ?? 45 33 C9 48 89 05 ?? ?? ?? - ?? 45 33 C0 48 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 44 24 ?? 48 C7 - } - $encrypt_files_p2 = { - C1 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 5C 24 ?? C7 44 24 ?? ?? ?? - ?? ?? 89 5C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 - 8D 85 ?? ?? ?? ?? 4C 89 A4 24 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 44 24 ?? 4C 8D - 25 ?? ?? ?? ?? 4C 89 AC 24 ?? ?? ?? ?? 45 33 C9 45 33 C0 4C 89 64 24 ?? 4C 89 BC 24 - ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 4C 8D 2D ?? ?? ?? ?? 83 - F8 ?? 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 54 24 ?? 48 89 5C 24 ?? - E8 ?? ?? ?? ?? 85 C0 78 ?? 4C 63 C8 4C 8D 85 ?? ?? ?? ?? 48 8D 44 24 ?? 4D 2B C1 48 - 89 44 24 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? 4C 89 64 24 ?? E8 ?? ?? ?? ?? - 49 8B CD FF 15 ?? ?? ?? ?? 44 8B C0 89 05 ?? ?? ?? ?? B8 ?? ?? ?? ?? 41 F7 E8 C1 FA - ?? 8B CA C1 E9 ?? 03 D1 69 CA ?? ?? ?? ?? 44 3B C1 74 ?? FF C2 4C 8D 3D ?? ?? ?? ?? - 85 D2 0F 8E ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? 49 8B DD 4C 89 B4 24 ?? ?? ?? ?? 49 - } - $encrypt_files_p3 = { - 8B FF 44 8B F2 0F 1F 00 48 8B 0D ?? ?? ?? ?? 8B 91 ?? ?? ?? ?? 85 D2 74 ?? 83 FA ?? - 75 ?? 48 89 7C 24 ?? 4C 8D 05 ?? ?? ?? ?? 48 89 5C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 C7 - 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 48 89 7C 24 ?? 4C 8D 05 ?? ?? ?? ?? 48 89 - 5C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 81 C7 ?? - ?? ?? ?? 48 81 C3 ?? ?? ?? ?? 49 83 EE ?? 75 ?? 4C 8B B4 24 ?? ?? ?? ?? 33 DB 48 8B - BC 24 ?? ?? ?? ?? 66 0F 1F 44 00 ?? 48 FF C6 41 80 3C 34 ?? 75 ?? 48 8B 8D ?? ?? ?? - ?? 48 8D 15 ?? ?? ?? ?? 89 74 24 ?? 41 B9 ?? ?? ?? ?? 45 33 C0 4C 89 64 24 ?? FF 15 - ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? C7 44 24 ?? - ?? ?? ?? ?? 45 33 C0 4C 89 7C 24 ?? FF 15 ?? ?? ?? ?? EB ?? 48 8B 8D ?? ?? ?? ?? 48 - 8D 85 ?? ?? ?? ?? 48 89 44 24 ?? 4C 8D 3D ?? ?? ?? ?? 45 33 C9 4C 89 7C 24 ?? 45 33 - C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 49 8B CC FF - 15 ?? ?? ?? ?? 49 8B D4 48 8D 0D ?? ?? ?? ?? FF C0 4C 63 C0 E8 ?? ?? ?? ?? 48 8B 05 - ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? 48 89 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 05 ?? ?? - ?? ?? 4C 8B BC 24 ?? ?? ?? ?? 4C 8B A4 24 ?? ?? ?? ?? 48 85 C0 74 ?? 48 8B 0D ?? ?? - ?? ?? FF 50 ?? 48 8B 05 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? 33 D2 44 8D 42 ?? FF D0 48 - 8B 8D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 48 63 85 ?? ?? ?? ?? 48 3D ?? - ?? ?? ?? 73 ?? 0F 1F 00 48 63 85 ?? ?? ?? ?? 42 C6 04 28 ?? FF 85 ?? ?? ?? ?? 48 63 - 85 ?? ?? ?? ?? 48 3D ?? ?? ?? ?? 72 ?? 4C 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? - 5E 5B 5D C3 - } - $enum_procs = { - 40 56 48 81 EC ?? ?? ?? ?? 33 D2 8D 4A ?? FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? C7 44 24 - ?? ?? ?? ?? ?? 48 8B C8 48 8B F0 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 48 89 9C - 24 ?? ?? ?? ?? 48 89 AC 24 ?? ?? ?? ?? 48 8D 2D ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? - 0F 1F 40 ?? 0F 1F 84 00 ?? ?? ?? ?? 33 DB 48 8B FD 66 66 66 0F 1F 84 00 ?? ?? 00 00 - 48 8B 0F 48 8D 54 24 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? FF C3 48 83 C7 ?? 83 FB ?? 72 - ?? EB ?? 44 8B 44 24 ?? 33 D2 8D 4A ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 85 C0 74 ?? BA - ?? ?? ?? ?? 48 8B C8 FF 15 ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 48 - 8B CE FF 15 ?? ?? ?? ?? 85 C0 75 ?? 48 8B BC 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? - 48 8B 9C 24 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5E C3 - } - $enum_shares = { - 48 83 EC ?? 33 D2 C7 44 24 ?? ?? ?? ?? ?? 48 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 4C - 8B C9 48 89 44 24 ?? 8D 4A ?? 44 8D 42 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 48 89 5C 24 ?? 8B 5C 24 ?? 48 89 7C 24 ?? 66 66 0F 1F 84 00 ?? ?? 00 00 48 8B 0D ?? - ?? ?? ?? 4C 8D 43 ?? BA ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B F8 48 85 C0 74 ?? 48 8B - 4C 24 ?? 4C 8D 4C 24 ?? 4C 8B C0 48 8D 54 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 66 0F - 1F 44 00 ?? 33 DB 39 5C 24 ?? 76 ?? 0F 1F 84 00 ?? ?? ?? ?? 48 8D 0C 5B 48 C1 E1 ?? - 48 03 CF F6 41 ?? ?? 74 ?? E8 ?? ?? ?? ?? EB ?? 48 8B 49 ?? E8 ?? ?? ?? ?? FF C3 3B - 5C 24 ?? 72 ?? 48 8B 4C 24 ?? 4C 8D 4C 24 ?? 4C 8B C7 48 8D 54 24 ?? FF 15 ?? ?? ?? - ?? 85 C0 74 ?? 48 8B 0D ?? ?? ?? ?? 4C 8B C7 33 D2 FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? - FF 15 ?? ?? ?? ?? 48 8B 7C 24 ?? 48 8B 5C 24 ?? 48 83 C4 ?? C3 - } + $a = { 23 CB 67 4C 94 11 6E 75 EC A6 76 98 23 CC 80 CF AE 3E A6 0C } condition: - uint16(0)==0x5A4D and ($enum_shares) and ($enum_procs) and ($find_files) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Ghostencryptor : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Ec591E81 : FILE MEMORY { meta: - description = "Yara rule that detects GhosTEncryptor ransomware." - author = "ReversingLabs" - id = "9f035e39-e0fe-54f3-8206-08fbbd9206b4" - date = "2021-08-12" - modified = "2021-08-12" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.GhosTEncryptor.yara#L1-L69" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "85c1f6e5acf746388b0a9ddeb1f0ad1d2219fff7358c9a981849863155c13e3c" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "ec591e81-8594-4317-89b0-0fb4d43e14c1" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1224-L1242" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "7d45a4a128c25f317020b5d042ab893e9875b6ff0ef17482b984f5b3fe87e451" + logic_hash = "f2a147fe7f98d2b3141a1fda118ee803c81d9bc6f498bfaf3557665397eb44da" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "GhosTEncryptor" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "fe3d305202ca5376be7103d0b40f746fc26f8e442f8337a1e7c6d658b00fc4aa" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $enum_folders = { - 17 8D ?? ?? ?? ?? 0A 06 16 72 ?? ?? ?? ?? A2 03 28 ?? ?? ?? ?? 0B 16 0C 38 ?? ?? ?? ?? - 07 08 9A 0D 02 09 28 ?? ?? ?? ?? 2C ?? 09 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 09 72 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 09 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 09 72 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 2D ?? 09 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 09 72 ?? ?? ?? ?? 6F ?? ?? - ?? ?? 2D ?? 09 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 02 02 7B ?? ?? ?? ?? 09 72 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 09 28 ?? ?? ?? ?? 26 08 17 58 0C 08 07 8E 69 3F ?? - ?? ?? ?? 02 7B ?? ?? ?? ?? 06 17 6F ?? ?? ?? ?? 2A - } - $encrypt_folder_p1 = { - 1F ?? 8D ?? ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? - ?? A2 25 19 72 ?? ?? ?? ?? A2 25 1A 72 ?? ?? ?? ?? A2 25 1B 72 ?? ?? ?? ?? A2 25 1C 72 - ?? ?? ?? ?? A2 25 1D 72 ?? ?? ?? ?? A2 25 1E 72 ?? ?? ?? ?? A2 25 1F ?? 72 ?? ?? ?? ?? - A2 25 1F ?? 72 ?? ?? ?? ?? A2 25 1F ?? 72 - } - $encrypt_folder_p2 = { - A2 0A 03 28 ?? ?? ?? ?? 0B 03 28 ?? ?? ?? ?? 0C 16 0D 2B ?? 07 09 9A 28 ?? ?? ?? ?? 13 - ?? 06 11 ?? 28 ?? ?? ?? ?? 2C ?? 02 07 09 9A 04 28 ?? ?? ?? ?? 09 17 58 0D 09 07 8E 69 - 32 ?? 16 13 ?? 2B ?? 02 08 11 ?? 9A 04 28 ?? ?? ?? ?? 11 ?? 17 58 13 ?? 11 ?? 08 8E 69 - 32 ?? 2A - } - $deep_search_p1 = { - 17 8D ?? ?? ?? ?? 0A 06 16 72 ?? ?? ?? ?? A2 7E ?? ?? ?? ?? 0B 02 0C 16 0D 38 ?? ?? ?? - ?? 08 09 9A 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 11 ?? 72 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? - ?? ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 11 ?? 72 - } - $deep_search_p2 = { - 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 2D ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 07 11 ?? 72 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 0B 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 09 17 58 0D 09 08 8E - 69 3F ?? ?? ?? ?? 07 06 17 6F ?? ?? ?? ?? 2A - } + $a = { 22 01 00 00 0E 00 00 00 18 03 00 7F E9 38 32 C9 4D 04 9A 3C } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_0Eba3F5A : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "0eba3f5a-1aa8-4dc8-9f63-01bc4959792a" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1244-L1262" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "2e4f89c76dfefd4b2bfd1cf0467ac0324026355723950d12d7ed51195fd998cf" + logic_hash = "bcb2f1e1659102f39977fac43b119c58d6c72f828c3065e2318f671146e911da" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "c0f4f9a93672bce63c9e3cfc389c73922c1c24a2db7728ad7ebc1d69b4db150f" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { C3 55 48 89 E5 48 83 EC 40 48 89 7D C8 89 F0 66 89 45 C4 C7 45 DC 01 00 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_E43A8744 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "e43a8744-1c52-4f95-bd16-be6722bc4d1a" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1264-L1282" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "f363d9bd2132d969cd41e79f29c53ef403da64ca8afc4643084cc50076ddfb47" + logic_hash = "17c52d2b720fa2e98c3e9bb077525a695a6e547a66e8c44fcc1e26e48df81adf" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "e7ead3d1a51f0d7435a6964293a45cb8fadd739afb23dc48c1d81fbc593b23ef" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 23 01 00 00 0E 00 00 00 18 03 00 7F E9 38 32 C9 4D 04 9A 3C } condition: - uint16(0)==0x5A4D and ($enum_folders) and ( all of ($deep_search_p*)) and ( all of ($encrypt_folder_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Princesslocker : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_6E8E9257 : FILE MEMORY { meta: - description = "Yara rule that detects PrincessLocker ransomware." - author = "ReversingLabs" - id = "b76ef137-aa0b-5fd3-9876-2459cb6535ff" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.PrincessLocker.yara#L1-L92" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "5be4ca3bd0b0afed1d2f3a59e2951d74a8de94c5a4d5a2c6cc29add49eab9ec0" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "6e8e9257-a6d5-407a-a584-4656816a3ddc" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1284-L1301" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "67973257e578783838f18dc8ae994f221ad1c1b3f4a04a2b6b523da5ebd8c95b" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "PrincessLocker" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "4bad14aebb0b8c7aa414f38866baaf1f4b350b2026735de24bcf2014ff4b0a6a" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files = { - 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - 6A ?? 6A ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? - ?? BA ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 45 ?? 83 7D ?? ?? 0F 43 45 - ?? 50 53 FF D7 6A ?? FF B5 ?? ?? ?? ?? 8B F0 FF 15 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? - FF B5 ?? ?? ?? ?? FF D6 85 C0 75 ?? 83 7D ?? ?? 72 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 6A ?? FF B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 85 C0 0F 84 ?? ?? ?? ?? BA ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? - 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 50 53 FF D7 68 ?? ?? ?? - ?? 8D 4D ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 68 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 89 9D ?? ?? ?? ?? 85 DB 75 ?? 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 8D - 4D ?? E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? A1 ?? ?? - ?? ?? 8B 30 89 B5 ?? ?? ?? ?? 3B F0 0F 84 ?? ?? ?? ?? 33 C9 C6 45 ?? ?? 6A ?? 51 8D - 46 ?? 66 89 8D ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 EC ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? C7 85 - ?? ?? ?? ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 50 6A ?? 8D 85 ?? ?? ?? - ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 83 BD ?? ?? ?? ?? ?? 72 ?? FF B5 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? FF 75 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 7D ?? ?? - 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 50 FF 75 ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? 51 8D 4D ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 83 EC ?? C6 45 ?? ?? 8B CC - 33 C0 6A ?? C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? 50 66 89 01 8D 85 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C7 45 ?? ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? - C3 C7 45 ?? ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? - E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 68 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 - 45 ?? ?? 83 BD ?? ?? ?? ?? ?? 72 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? - 68 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D BD ?? ?? - ?? ?? 6A ?? 6A ?? 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? 83 BD - ?? ?? ?? ?? ?? 6A ?? 0F 43 BD ?? ?? ?? ?? 6A ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 89 - 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 83 FB ?? 0F 84 ?? ?? ?? ?? 85 DB 0F 84 ?? ?? - ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 8B F8 83 FF - ?? 0F 84 ?? ?? ?? ?? 85 FF 0F 84 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? - ?? ?? 50 FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 85 - ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 48 39 85 ?? ?? ?? ?? B8 ?? ?? ?? ?? - 0F B6 C9 0F 46 C8 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? 0F B6 C1 6A ?? 50 6A ?? FF - B5 ?? ?? ?? ?? 89 8D ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 FF B5 - ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 FF 15 - } - $remote_connection_1 = { - 6A ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 84 DB 0F 85 ?? ?? ?? - ?? 6A ?? 6A ?? 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? 88 5D ?? C7 45 ?? ?? - ?? ?? ?? 66 C7 45 ?? ?? ?? 88 5D ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? BA ?? ?? ?? ?? 89 45 ?? E8 ?? ?? ?? ?? 8B F0 8D 55 ?? C6 45 ?? ?? 8D 8D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B D0 8D 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 56 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 - } - $remote_connection_2 = { - BA ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 66 C7 45 ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 66 C7 45 ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 8D 55 ?? C6 45 - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F8 BA ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B F0 8D 55 ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 56 - 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 57 8B D0 C6 45 ?? ?? 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 53 8B D0 C6 45 ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? - ?? 51 8B D0 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D0 C6 45 ?? ?? 8D 8D - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 50 E8 - } + $a = { 53 83 EC 04 8B 5C 24 18 8B 7C 24 20 8A 44 24 14 8A 54 24 1C 88 54 } condition: - uint16(0)==0x5A4D and $encrypt_files and $remote_connection_1 and $remote_connection_2 + all of them } -rule REVERSINGLABS_Win32_Ransomware_Ransomexx : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Ac253E4F : FILE MEMORY { meta: - description = "Yara rule that detects Ransomexx ransomware." - author = "ReversingLabs" - id = "5e62660d-2696-56c7-9322-fed6ce9d36ff" - date = "2020-11-26" - modified = "2020-11-26" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Ransomexx.yara#L1-L147" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "27b4132b7f16cafc40687e96a552ce59cc24ebf7679575680f170e3beee8a0a9" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "ac253e4f-b628-4dd0-91f1-f19099286992" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1303-L1321" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "91642663793bdda93928597ff1ac6087e4c1e5d020a8f40f2140e9471ab730f9" + logic_hash = "1ab463fce01148c2cc95659fdf8b05e597d9b4eeabe81a9cdfa1da3632d72291" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Ransomexx" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "e2eee1f72b8c2dbf68e57b721c481a5cd85296e844059decc3548e7a6dc28fea" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 8B 7D ?? 85 FF 0F 84 ?? ?? ?? ?? B8 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B F4 B3 ?? 85 F6 74 ?? C6 46 ?? ?? B0 ?? 66 C7 06 ?? ?? 88 5E ?? 88 - 46 ?? 8B C7 8D 50 ?? 90 8A 08 40 84 C9 75 ?? 2B C2 8B D0 8B C6 8D 78 ?? 8A 08 40 84 - C9 75 ?? 2B C7 8D 84 10 ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? - 89 45 ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 7D ?? 68 ?? ?? ?? ?? 57 50 FF 15 ?? ?? ?? ?? 68 - ?? ?? ?? ?? 56 8B 75 ?? 56 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 56 FF 15 ?? ?? ?? - ?? 8B F0 89 75 ?? 83 FE ?? 75 ?? FF 15 ?? ?? ?? ?? 8D A5 ?? ?? ?? ?? 5F 5E 5B 8B E5 - 5D C3 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B C4 89 45 ?? 85 C0 74 ?? C6 40 ?? ?? 88 18 88 - 58 ?? B9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 49 ?? 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 - ?? 3A 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F - 84 ?? ?? ?? ?? 8B 4D ?? 8D 85 ?? ?? ?? ?? 8A 10 3A 11 75 ?? 84 D2 74 ?? 8A 50 ?? 3A - } - $find_files_p2 = { - 51 ?? 75 ?? 83 C0 ?? 83 C1 ?? 84 D2 75 ?? 33 C0 EB ?? 1B C0 83 D8 ?? 85 C0 0F 84 ?? - ?? ?? ?? 8B C7 8D 50 ?? 8A 08 40 84 C9 75 ?? 2B C2 8B D0 8D 85 ?? ?? ?? ?? 8D 70 ?? - 8D 64 24 ?? 8A 08 40 84 C9 75 ?? 8B 1D ?? ?? ?? ?? 2B C6 8D 94 10 ?? ?? ?? ?? 52 6A - ?? FF D3 50 FF 15 ?? ?? ?? ?? 8B F0 85 F6 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 56 FF - 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? - ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 74 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 6A ?? 56 FF 15 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 FF 15 ?? ?? ?? ?? 85 - C0 75 ?? 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 56 6A ?? - FF D3 50 FF 15 ?? ?? ?? ?? 8B 75 ?? 8D 8D ?? ?? ?? ?? 51 56 FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B 55 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 - ?? ?? ?? ?? 6A ?? 57 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8D A5 ?? ?? ?? ?? 5F 5E - 5B 8B E5 5D C3 - } - $find_files_p3 = { - 55 8B EC 83 E4 ?? 81 EC ?? ?? ?? ?? 53 56 57 8B 7D ?? 85 FF 0F 84 ?? ?? ?? ?? 8B C7 - 8D 50 ?? 90 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 8D B4 00 ?? ?? ?? ?? 8D 86 - ?? ?? ?? ?? 50 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? - ?? ?? 56 57 53 FF 15 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8D 4C 24 ?? - 51 53 FF 15 ?? ?? ?? ?? 89 44 24 ?? 83 F8 ?? 75 ?? 8B 3D ?? ?? ?? ?? FF D7 83 F8 ?? - 0F 84 ?? ?? ?? ?? FF D7 E9 ?? ?? ?? ?? 8D A4 24 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 68 ?? - ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 52 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 84 - 24 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? F6 44 24 ?? ?? 0F 85 ?? ?? ?? ?? 8B - 4D ?? 56 51 53 FF 15 ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 56 8D 94 24 - ?? ?? ?? ?? 52 53 FF 15 ?? ?? ?? ?? F6 44 24 ?? ?? 74 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 - ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 44 24 ?? 50 FF 15 ?? ?? ?? ?? 85 C0 - 74 ?? 66 83 38 ?? 74 ?? 68 ?? ?? ?? ?? 50 FF D7 85 C0 75 ?? FF 05 ?? ?? ?? ?? E9 ?? - ?? ?? ?? 8D 7C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 39 05 ?? ?? ?? ?? 0F 84 - ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8D 4C 24 ?? 51 8D 54 24 ?? 52 FF D7 85 C0 74 ?? 8D 44 - } - $find_files_p4 = { - 24 ?? 50 8D 4C 24 ?? 51 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 0F B7 44 24 ?? 8B 0D ?? - ?? ?? ?? 3B C1 74 ?? 49 3B C1 74 ?? 8D 54 24 ?? 52 8D 44 24 ?? 50 FF D7 85 C0 74 ?? - 8D 4C 24 ?? 51 8D 54 24 ?? 52 6A ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 0F B7 44 24 ?? 8B - 0D ?? ?? ?? ?? 3B C1 74 ?? 49 3B C1 74 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? - ?? ?? ?? 8B 44 24 ?? 0B 44 24 ?? 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 6A ?? 6A ?? 50 51 FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? - 80 3B ?? 75 ?? 80 7B ?? ?? 75 ?? 8B 15 ?? ?? ?? ?? 8D 3C 85 ?? ?? ?? ?? 8B 04 17 53 - 50 FF 15 ?? ?? ?? ?? EB ?? 8B 0D ?? ?? ?? ?? 8D 3C 85 ?? ?? ?? ?? 8B 14 0F 68 ?? ?? - ?? ?? 52 FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 0C 07 68 ?? ?? ?? ?? 53 51 FF 15 ?? ?? - ?? ?? 8B 15 ?? ?? ?? ?? 8B 04 17 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 8B 54 24 ?? 8D 4C 24 ?? 51 52 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 44 24 - ?? 50 FF 15 ?? ?? ?? ?? 53 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 5F 5E 33 C0 - 5B 8B E5 5D C2 - } - $enum_network_resources = { - 55 8B EC 8B 4D ?? 83 EC ?? 8D 45 ?? 50 51 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? 53 8B 1D ?? ?? ?? ?? 56 68 ?? ?? ?? ?? 6A ?? C7 45 ?? ?? ?? ?? ?? - FF D3 50 FF 15 ?? ?? ?? ?? 8B F0 89 75 ?? 85 F6 0F 84 ?? ?? ?? ?? 57 90 8B 4D ?? 8D - 55 ?? 52 56 8D 45 ?? 50 51 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? - ?? ?? 33 FF 39 7D ?? 76 ?? 83 C6 ?? 8D 64 24 ?? F6 46 ?? ?? 74 ?? F6 46 ?? ?? 74 ?? - 8B 06 8D 50 ?? 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 8D 94 00 ?? ?? ?? ?? 52 - 6A ?? FF D3 50 FF 15 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 89 04 8D ?? ?? ?? ?? 85 C0 74 ?? - 8B 16 0F B7 0A 66 89 08 83 C2 ?? 83 C0 ?? 66 85 C9 75 ?? FF 05 ?? ?? ?? ?? 8B 56 ?? - 83 E2 ?? 80 FA ?? 75 ?? 8D 46 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 47 83 C6 ?? 3B 7D ?? 72 - ?? 8B 75 ?? E9 ?? ?? ?? ?? 56 6A ?? FF D3 50 FF 15 ?? ?? ?? ?? 5F 8B 4D ?? 51 FF 15 - ?? ?? ?? ?? 5E 5B 8B E5 5D C3 - } - $encrypt_files_p1 = { - 55 8B EC 83 EC ?? 53 56 57 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 89 45 ?? 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8B 4D ?? B8 ?? ?? ?? ?? 89 4D ?? E8 ?? ?? ?? - ?? 8B F4 85 F6 0F 84 ?? ?? ?? ?? 8B D6 81 EA ?? ?? ?? ?? 83 C2 ?? 89 55 ?? 8B D6 81 - EA ?? ?? ?? ?? 83 C2 ?? 89 55 ?? 8B D6 8B CE 8B FE 81 EA ?? ?? ?? ?? 33 C0 81 E9 ?? - ?? ?? ?? 81 EF ?? ?? ?? ?? 83 C2 ?? C6 46 ?? ?? 89 55 ?? 8B 5D ?? 8A D0 80 E2 ?? 02 - 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 01 ?? ?? ?? ?? 8D 50 ?? 80 E2 ?? 02 90 ?? ?? - ?? ?? 32 90 ?? ?? ?? ?? 88 94 07 ?? ?? ?? ?? 8D 50 ?? 80 E2 ?? 02 90 ?? ?? ?? ?? 32 - 90 ?? ?? ?? ?? 88 94 03 ?? ?? ?? ?? 8B 5D ?? 8D 50 ?? 80 E2 ?? 02 90 ?? ?? ?? ?? 32 - 90 ?? ?? ?? ?? 88 94 03 ?? ?? ?? ?? 8B 5D ?? 8D 50 ?? 80 E2 ?? 02 90 ?? ?? ?? ?? 32 - 90 ?? ?? ?? ?? 88 94 03 ?? ?? ?? ?? 8D 50 ?? 80 E2 ?? 02 90 ?? ?? ?? ?? 83 C0 ?? 32 - 90 ?? ?? ?? ?? 88 54 06 ?? 83 F8 ?? 0F 8C ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 4D ?? 50 51 - FF 15 ?? ?? ?? ?? 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? - ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 55 ?? 52 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? C7 45 - ?? ?? ?? ?? ?? FF D6 85 C0 75 ?? 8B 3D ?? ?? ?? ?? 8D 49 ?? 68 ?? ?? ?? ?? FF D7 8D - 45 ?? 50 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? FF D6 85 C0 74 ?? 50 FF 15 ?? ?? ?? - ?? B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B FC 85 FF 0F 84 ?? ?? ?? ?? 8B D7 81 EA ?? ?? ?? - ?? 83 C2 ?? 89 55 ?? 8B D7 81 EA ?? ?? ?? ?? 83 C2 ?? 89 55 ?? 8B D7 8B CF 8B F7 81 - } - $encrypt_files_p2 = { - EA ?? ?? ?? ?? 33 C0 81 E9 ?? ?? ?? ?? 81 EE ?? ?? ?? ?? 83 C2 ?? C6 47 ?? ?? 89 55 - ?? 8B 5D ?? 8A D0 80 E2 ?? 02 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 08 ?? ?? ?? ?? - 8D 50 ?? 80 E2 ?? 02 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 30 ?? ?? ?? ?? 8D 50 ?? - 80 E2 ?? 02 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 18 ?? ?? ?? ?? 8B 5D ?? 8D 50 ?? - 80 E2 ?? 02 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 18 ?? ?? ?? ?? 8B 5D ?? 8D 50 ?? - 80 E2 ?? 02 90 ?? ?? ?? ?? 32 90 ?? ?? ?? ?? 88 94 18 ?? ?? ?? ?? 8D 50 ?? 80 E2 ?? - 02 90 ?? ?? ?? ?? 83 C0 ?? 32 90 ?? ?? ?? ?? 88 54 07 ?? 83 F8 ?? 0F 8C ?? ?? ?? ?? - E8 ?? ?? ?? ?? 8B D8 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B C8 2B 4D ?? - B8 ?? ?? ?? ?? F7 E1 8B CA C1 E9 ?? B8 ?? ?? ?? ?? F7 E1 C1 EA ?? 8B C2 C1 E0 ?? 2B - C2 03 C0 03 C0 2B C8 8B F2 B8 ?? ?? ?? ?? F7 E6 A1 ?? ?? ?? ?? 51 C1 EA ?? 8B CA C1 - E1 ?? 2B CA 03 C9 03 C9 2B F1 56 52 8B 15 ?? ?? ?? ?? 52 50 53 57 E8 ?? ?? ?? ?? 83 - C4 ?? 85 DB 0F 84 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B D8 C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B C8 2B - 4D ?? B8 ?? ?? ?? ?? F7 E1 8B CA C1 E9 ?? B8 ?? ?? ?? ?? F7 E1 C1 EA ?? 8B C2 C1 E0 - ?? 2B C2 03 C0 03 C0 2B C8 8B F2 B8 ?? ?? ?? ?? F7 E6 A1 ?? ?? ?? ?? 51 C1 EA ?? 8B - CA C1 E1 ?? 2B CA 03 C9 03 C9 2B F1 56 52 8B 15 ?? ?? ?? ?? 52 50 53 57 E8 ?? ?? ?? - ?? 83 C4 ?? 85 DB 0F 85 ?? ?? ?? ?? 8D 65 ?? 5F 5E 5B 8B E5 5D C3 - } + $a = { 00 31 C9 EB 0A 6B C1 0A 0F BE D2 8D 4C 02 D0 8A 17 48 FF C7 8D } condition: - uint16(0)==0x5A4D and ($enum_network_resources) and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win64_Ransomware_Albabat : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_994535C4 : FILE MEMORY { meta: - description = "Yara rule that detects Albabat ransomware." - author = "ReversingLabs" - id = "11941c0d-45fb-5746-bbad-f43f336d4b1d" - date = "2024-03-18" - modified = "2024-03-18" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Albabat.yara#L1-L139" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "38ec8388b9006f6ab9a397858b89f4bfd7def2ffcf525cfc736abae49bc6034a" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "994535c4-77a6-4cc6-b673-ce120be8d0f4" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1323-L1341" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "376a2771a2a973628e22379b3dbb9a8015c828505bbe18a0c027b5d513c9e90d" + logic_hash = "c83c8c9cdfea1bf322115e5b23d751b226a5dbf42fc41faac172d36192ccf31f" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Albabat" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "a3753e29ecf64bef21e062b8dec96ba9066f665919d60976657b0991c55b827b" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 48 8D 05 ?? ?? ?? ?? 48 89 83 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? C7 83 ?? - ?? ?? ?? ?? ?? ?? ?? 66 C7 83 ?? ?? 00 00 ?? ?? C7 83 ?? ?? ?? ?? ?? ?? ?? ?? 0F 57 - F6 0F 11 B3 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? C6 83 ?? ?? ?? ?? ?? 4C 8D - 83 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 D7 48 85 C0 74 ?? 0F B6 05 ?? ?? ?? ?? 48 8B 0D - ?? ?? ?? ?? 48 85 C9 75 ?? FF 15 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 C1 48 - 89 05 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 31 D2 FF 15 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? - ?? 48 89 C6 48 89 38 4C 8D 35 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 89 BB ?? ?? ?? ?? 48 C7 - 83 ?? ?? ?? ?? ?? ?? ?? ?? 0F 11 B3 ?? ?? ?? ?? 48 89 F9 E8 ?? ?? ?? ?? 48 89 C6 48 - 89 D7 48 85 C0 74 ?? 48 85 FF 0F 85 ?? ?? ?? ?? 48 89 7C 24 ?? 48 8D 8B ?? ?? ?? ?? - 48 8D 93 ?? ?? ?? ?? 4C 8D 83 ?? ?? ?? ?? 49 89 F1 E8 ?? ?? ?? ?? 48 83 BB ?? ?? ?? - ?? ?? 0F 84 ?? ?? ?? ?? 48 8B BB ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? - ?? 48 85 C9 75 ?? FF 15 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 C1 48 89 05 ?? - ?? ?? ?? 41 B8 ?? ?? ?? ?? 31 D2 FF 15 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 - } - $encrypt_files_p2 = { - C6 48 89 38 4C 8D 35 ?? ?? ?? ?? 48 83 BB ?? ?? ?? ?? ?? 74 ?? 4C 8B 83 ?? ?? ?? ?? - 48 8B 0D ?? ?? ?? ?? 31 D2 FF 15 ?? ?? ?? ?? 48 8B 8B ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 48 85 F6 0F 84 ?? ?? ?? ?? 48 89 B3 ?? ?? ?? ?? 4C 89 B3 ?? ?? ?? ?? 4C 8D B3 ?? ?? - ?? ?? 4C 89 B3 ?? ?? ?? ?? 4C 8D 3D ?? ?? ?? ?? 4C 89 BB ?? ?? ?? ?? 48 8D 05 ?? ?? - ?? ?? 48 89 83 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? - ?? ?? ?? 48 8D BB ?? ?? ?? ?? 48 89 BB ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? - 48 8D 8B ?? ?? ?? ?? 48 8D 93 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B B3 ?? ?? ?? ?? 48 8B - 93 ?? ?? ?? ?? 4C 8B A3 ?? ?? ?? ?? 48 89 F1 E8 ?? ?? ?? ?? 4D 85 E4 74 ?? 48 8B 0D - ?? ?? ?? ?? 31 D2 49 89 F0 FF 15 ?? ?? ?? ?? 4C 89 B3 ?? ?? ?? ?? 4C 89 BB ?? ?? ?? - ?? 48 8D 05 ?? ?? ?? ?? 48 89 83 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D - 35 ?? ?? ?? ?? 48 89 B3 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? 4C 8D B3 ?? ?? - ?? ?? 4C 89 B3 ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? ?? ?? ?? 48 C7 83 ?? ?? ?? ?? ?? - ?? ?? ?? 48 8D 8B ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 85 ?? ?? ?? ?? 48 8B 05 ?? ?? - ?? ?? 48 83 F8 ?? 0F 85 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 65 48 8B - 14 25 ?? ?? ?? ?? 48 8B 0C CA 48 8D 89 ?? ?? ?? ?? 48 39 C8 75 ?? 8B 05 ?? ?? ?? ?? - FF C0 75 ?? 48 8D 0D ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 - } - $drop_ransom_note = { - 48 8D 05 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 - 89 B4 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 4C 89 B4 24 ?? ?? ?? ?? 48 - C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 48 83 BC 24 ?? ?? ?? ?? ?? 74 ?? 4C 8B 84 24 ?? ?? ?? ?? 48 8B 0D ?? ?? - ?? ?? 31 D2 FF 15 ?? ?? ?? ?? 48 8D B4 24 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 89 - F1 E8 ?? ?? ?? ?? 48 85 C0 4C 8B 74 24 ?? 74 ?? 48 89 C5 4C 8B 6C 24 ?? E9 ?? ?? ?? - ?? 4D 8D 0C D1 49 83 C1 ?? 48 C1 E2 ?? 48 F7 DA 4F 8D 14 C2 49 83 C2 ?? 49 C1 E0 ?? - 49 F7 D8 45 31 DB 4C 39 DA 0F 84 ?? ?? ?? ?? 4D 39 D8 0F 84 ?? ?? ?? ?? 4B 8B 34 19 - 4F 8B 34 1A 4C 39 F6 0F 82 ?? ?? ?? ?? 49 83 C3 ?? 4C 39 F6 76 ?? E9 ?? ?? ?? ?? 48 - 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 80 BC 24 - ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 4C - 8B 84 24 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? ?? 48 8D 8C 24 ?? - ?? ?? ?? 48 89 DA E8 ?? ?? ?? ?? 4C 8B B4 24 ?? ?? ?? ?? 4C 8B 84 24 ?? ?? ?? ?? 48 - C7 44 24 ?? ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 4C 89 F2 E8 ?? - ?? ?? ?? 48 83 BC 24 ?? ?? ?? ?? ?? 74 ?? 48 8B 0D ?? ?? ?? ?? 31 D2 4D 89 F0 FF 15 - ?? ?? ?? ?? 48 85 ED 74 ?? 48 8B 0D ?? ?? ?? ?? 31 D2 49 89 D8 FF 15 ?? ?? ?? ?? 48 - 8D 9C 24 ?? ?? ?? ?? 48 89 D9 E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? - ?? 41 B8 ?? ?? ?? ?? 48 89 D9 E8 ?? ?? ?? ?? 0F 10 00 0F 11 84 24 ?? ?? ?? ?? 48 8B - 8C 24 ?? ?? ?? ?? 48 85 C9 74 - } - $change_desktop_wallpaper = { - 4C 8D 0D ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 DA E8 ?? ?? ?? ?? 48 83 BC 24 ?? - ?? ?? ?? ?? 74 ?? 48 8B 0D ?? ?? ?? ?? 31 D2 49 89 D8 FF 15 ?? ?? ?? ?? 4D 85 F6 74 - ?? 48 8B 0D ?? ?? ?? ?? 31 D2 49 89 F0 FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D - 8C 24 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 25 ?? ?? ?? ?? 48 85 C0 4C - 8B 74 24 ?? 0F 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 41 B8 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 80 BC 24 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8B B4 24 ?? ?? - ?? ?? 4C 8B AC 24 ?? ?? ?? ?? 4C 8B 84 24 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 4C - 8D 0D ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 F2 E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? - ?? ?? 4C 8B 84 24 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? ?? 48 8D - 8C 24 ?? ?? ?? ?? 48 89 DA E8 ?? ?? ?? ?? 48 83 BC 24 ?? ?? ?? ?? ?? 74 ?? 48 8B 0D - ?? ?? ?? ?? 31 D2 49 89 D8 FF 15 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 4C 8B B4 24 ?? - ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 DA 4D 89 F0 E8 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? - ?? ?? 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 89 C1 83 E1 ?? 83 F9 ?? 0F 85 ?? ?? - ?? ?? 48 8D 58 ?? 4C 8B 70 ?? 48 8B 68 ?? 4C 89 F1 FF 55 - } - $find_files_p1 = { - 4C 8D 0D ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 DA E8 ?? ?? ?? ?? 48 83 BC 24 ?? - ?? ?? ?? ?? 74 ?? 48 8B 0D ?? ?? ?? ?? 31 D2 49 89 D8 FF 15 ?? ?? ?? ?? 4D 85 FF 74 - ?? 48 8B 0D ?? ?? ?? ?? 31 D2 49 89 F0 FF 15 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? - ?? ?? ?? 66 0F EF C0 F3 0F 7F 84 24 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 48 8D 94 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 C5 4C 8B 6C 24 ?? 4C 8B - 74 24 ?? E9 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 31 D2 49 89 F0 E8 ?? ?? ?? ?? 48 8B - 84 24 ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? 48 29 E8 48 39 F0 72 ?? 48 8B 8C 24 ?? ?? - ?? ?? 48 01 E9 31 D2 49 89 F0 E8 ?? ?? ?? ?? 48 01 F5 48 89 AC 24 ?? ?? ?? ?? E9 ?? - ?? ?? ?? 48 C1 ED ?? 74 ?? 41 BD ?? ?? ?? ?? E9 ?? ?? ?? ?? 49 83 FF ?? 72 ?? 48 85 - DB 74 ?? 48 8B 84 24 ?? ?? ?? ?? EB ?? 48 8D 8C 24 ?? ?? ?? ?? 48 89 EA 49 89 F0 E8 - ?? ?? ?? ?? 48 8B AC 24 ?? ?? ?? ?? EB ?? 4C 89 FB 4C 89 F0 4D 85 FF 74 ?? 49 89 DC - 48 8B 44 D8 ?? 48 85 C0 74 ?? 48 0F BD C0 48 83 F0 ?? EB ?? 45 31 E4 EB ?? B8 ?? ?? - ?? ?? 49 C1 E4 ?? 49 83 CC ?? 49 29 C4 49 C1 EC ?? 48 8B B4 24 ?? ?? ?? ?? BA ?? ?? - ?? ?? 48 89 F1 45 31 C0 E8 ?? ?? ?? ?? 48 89 F1 E8 ?? ?? ?? ?? 49 89 C7 49 83 FC - } - $find_files_p2 = { - 73 ?? 48 8B 0D ?? ?? ?? ?? 31 D2 4D 89 F8 FF 15 ?? ?? ?? ?? 41 BD ?? ?? ?? ?? E9 ?? - ?? ?? ?? BA ?? ?? ?? ?? 4C 89 E1 E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 8D 68 - ?? 49 8D 5C 24 ?? 48 8B 8C 24 ?? ?? ?? ?? 48 89 EA 48 89 44 24 ?? E8 ?? ?? ?? ?? 48 - 8B 44 24 ?? F3 41 0F 6F 07 41 0F 10 4F ?? 0F 11 48 ?? F3 0F 7F 40 ?? 49 8D 4C 24 ?? - 48 39 D9 0F 83 ?? ?? ?? ?? 4D 89 E5 4C 8D 60 ?? 49 8D 4D ?? 43 C6 44 2C ?? ?? 48 39 - CB 0F 82 ?? ?? ?? ?? 43 0F 11 74 2C ?? 43 0F 11 7C 2C ?? 48 C7 44 24 ?? ?? ?? ?? ?? - 4C 89 E1 48 89 DA 48 8B B4 24 ?? ?? ?? ?? 49 89 F0 49 89 E9 E8 ?? ?? ?? ?? 48 89 5C - 24 ?? BA ?? ?? ?? ?? 48 89 E9 49 89 F0 4D 89 E1 E8 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? - 31 D2 4D 89 F8 FF 15 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? BA ?? ?? ?? ?? 4C 89 E9 E8 ?? - ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 C3 48 8D B4 24 ?? ?? ?? ?? 48 89 C1 48 8B - 54 24 ?? 4D 89 E8 E8 - } + $a = { 20 74 07 31 C0 48 FF C3 EB EA FF C0 83 F8 08 75 F4 48 8D 73 03 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($drop_ransom_note) and ($change_desktop_wallpaper) + all of them } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_EAF : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_A68E498C : FILE MEMORY { meta: - description = "Yara rule that detects EAF ransomware." - author = "ReversingLabs" - id = "6903030e-b1a1-5238-b377-ce8e4b18d3f3" - date = "2022-07-22" - modified = "2022-07-22" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.EAF.yara#L1-L89" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3d10c852f95e8aa9bcd3543b96650b98ac57bcd2aa2b374e0badb63b5a4c0396" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "a68e498c-0768-4321-ab65-42dd6ef85323" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1343-L1361" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6" + logic_hash = "e4552813dc92b397c5ba78f32ee6507520f337b55779a3fc705de7e961f8eb8f" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "EAF" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 00 03 28 ?? ?? ?? ?? 0A 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 39 ?? ?? ?? ?? 00 7E ?? - ?? ?? ?? 0C 03 28 ?? ?? ?? ?? 0D 03 28 ?? ?? ?? ?? 13 ?? 1E 8D ?? ?? ?? ?? 25 16 11 ?? - A2 25 17 72 ?? ?? ?? ?? A2 25 18 7E ?? ?? ?? ?? A2 25 19 72 ?? ?? ?? ?? A2 25 1A 28 ?? - ?? ?? ?? A2 25 1B 72 ?? ?? ?? ?? A2 25 1C 09 A2 25 1D 72 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? - 13 ?? 02 03 11 ?? 08 28 ?? ?? ?? ?? 13 ?? 11 ?? 2D ?? 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 2B ?? 16 13 ?? 11 ?? 2C ?? 00 00 03 11 ?? 28 ?? ?? ?? ?? 00 00 DE ?? 26 00 00 DE ?? 00 - 00 00 DE ?? 26 00 00 DE ?? 2A - } - $encrypt_files_p2 = { - 00 03 19 73 ?? ?? ?? ?? 0A 00 04 18 73 ?? ?? ?? ?? 0B 00 06 16 6A 6F ?? ?? ?? ?? 00 28 - ?? ?? ?? ?? 0C 00 1F ?? 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 05 09 73 ?? - ?? ?? ?? 13 ?? 00 08 17 6F ?? ?? ?? ?? 00 08 18 6F ?? ?? ?? ?? 00 08 11 ?? 1F ?? 6F ?? - ?? ?? ?? 6F ?? ?? ?? ?? 00 08 11 ?? 1F ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 07 08 6F ?? - ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 00 20 ?? ?? ?? ?? 13 ?? 11 ?? 8D ?? ?? ?? ?? 13 ?? 16 - 13 ?? 00 06 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? FE 02 16 FE 01 13 - ?? 11 ?? 2C ?? 00 11 ?? 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 00 00 2B ?? 11 ?? 20 ?? ?? ?? ?? - 32 ?? 11 ?? 20 ?? ?? ?? ?? FE 02 16 FE 01 2B ?? 16 13 ?? 11 ?? 2C ?? 00 11 ?? 11 ?? 16 - 11 ?? 6F ?? ?? ?? ?? 00 00 2B ?? 11 ?? 20 ?? ?? ?? ?? 32 ?? 11 ?? 20 ?? ?? ?? ?? FE 02 - 16 FE 01 2B ?? 16 13 ?? 11 ?? 2C ?? 00 11 ?? 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 00 00 2B ?? - 00 07 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 11 ?? 58 13 ?? 00 11 ?? 16 FE 03 13 ?? - 11 ?? 3A ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? - 00 DC 00 DE ?? 11 ?? 2C ?? 11 ?? 6F ?? ?? ?? ?? 00 DC 00 DE ?? 08 2C ?? 08 6F ?? ?? ?? - ?? 00 DC 07 6F ?? ?? ?? ?? 00 00 DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? 00 DC 06 6F ?? ?? ?? - ?? 00 00 DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? 00 DC 03 28 ?? ?? ?? ?? 00 17 13 ?? DE ?? 26 - 00 16 13 ?? DE ?? 11 ?? 2A - } - $find_files_p1 = { - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 16 0C 38 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0D 00 09 06 08 9A - 28 ?? ?? ?? ?? 7D ?? ?? ?? ?? 06 08 9A 28 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 09 FE 06 ?? - ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 09 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 2C ?? 11 ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 11 ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? - ?? 2B ?? 16 13 ?? 11 ?? 2C ?? 00 7E ?? ?? ?? ?? 06 08 9A 6F ?? ?? ?? ?? 00 00 00 08 17 - 58 0C 08 06 8E 69 FE 04 13 ?? 11 ?? 3A ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 16 - 13 ?? 2B ?? 00 07 11 ?? 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 07 11 ?? 9A 72 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 2C ?? 07 11 ?? 9A 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 07 11 ?? 9A 72 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 2B ?? 16 13 ?? 11 ?? 2C ?? 00 07 11 ?? 9A 28 ?? ?? ?? ?? 00 - 00 00 11 ?? 17 58 13 ?? 11 ?? 07 8E 69 FE 04 13 ?? 11 ?? 2D ?? 00 DE ?? 26 00 00 DE ?? - 2A - } - $find_files_p2 = { - 00 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 73 ?? ?? ?? ?? 0C 08 06 07 9A 7D ?? ?? ?? ?? 00 08 7B - ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 08 7B ?? ?? ?? ?? 6F ?? - ?? ?? ?? 2B ?? 16 0D 09 2C ?? 00 08 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 00 00 00 07 17 58 0B 07 06 8E 69 32 ?? 00 DE ?? 26 00 00 DE ?? 2A - } - $destroy_exe_file = { - 00 1F ?? 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? ?? 0B 7E ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 0C 7E ?? - ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 08 72 ?? ?? ?? ?? 1B 8D ?? - ?? ?? ?? 25 16 72 ?? ?? ?? ?? A2 25 17 06 A2 25 18 72 ?? ?? ?? ?? A2 25 19 28 ?? ?? ?? - ?? A2 25 1A 72 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 08 6F ?? ?? ?? ?? 00 00 - DE ?? 26 00 00 DE ?? 2A - } + $a = { 10 39 D0 7E 25 8B 4C 24 38 01 D1 8A 11 8D 42 9F 3C 19 77 05 8D } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ($destroy_exe_file) + all of them } -rule REVERSINGLABS_Win32_Ransomware_MRAC : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_88De437F : FILE MEMORY { meta: - description = "Yara rule that detects MRAC ransomware." - author = "ReversingLabs" - id = "135c3dc9-bf08-5f00-bade-7054d9f33830" - date = "2022-02-21" - modified = "2022-02-21" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.MRAC.yara#L1-L69" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "04e8364dc9c726f4bb2d3035e5b7e8dab4cae124b2f047be6f11b865fab557a7" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "88de437f-9c98-4e1d-96c0-7b433c99886a" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1363-L1381" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6" + logic_hash = "233dbf3d13c35f4c9c7078d67ea60086355c801ce6515f9d3c518e95afd39d85" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "MRAC" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files = { - B8 ?? ?? ?? ?? 66 8B 11 66 3B 10 75 ?? 66 85 D2 74 ?? 66 8B 51 ?? 66 3B 50 ?? 75 ?? - 83 C1 ?? 83 C0 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 8B 75 ?? 85 C0 75 ?? B1 - ?? EB ?? 32 C9 8B 45 ?? 88 4D ?? 83 F8 ?? 72 ?? 8D 0C 45 ?? ?? ?? ?? 8B C6 81 F9 ?? - ?? ?? ?? 72 ?? 8B 76 ?? 83 C1 ?? 2B C6 83 C0 ?? 83 F8 ?? 77 ?? 51 56 E8 ?? ?? ?? ?? - 8A 4D ?? 83 C4 ?? 8A C1 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? - ?? ?? ?? 8B E5 5D C2 ?? ?? E8 ?? ?? ?? ?? E8 - } - $import_key = { - 8D 45 ?? 50 6A ?? 6A ?? 6A ?? FF 75 ?? 56 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 - C0 0F 84 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 - ?? 89 45 ?? 8D 4D ?? 51 50 6A ?? 6A ?? FF 75 ?? 56 6A ?? 68 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? FF 75 ?? FF 75 ?? FF 75 ?? FF - 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF - 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 45 ?? 6A ?? 50 6A ?? FF - 75 ?? FF D6 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A ?? FF 75 ?? FF D6 85 C0 0F - 84 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 6A ?? 8D 45 ?? 50 6A ?? FF 75 ?? FF D6 85 C0 0F 84 ?? ?? ?? ?? 6A ?? FF 75 ?? FF 15 - ?? ?? ?? ?? 8B C8 F6 C1 ?? 75 ?? B8 ?? ?? ?? ?? EB ?? 8B C1 C1 E8 ?? 40 C1 E0 ?? 2B - C1 68 ?? ?? ?? ?? 89 45 ?? E8 ?? ?? ?? ?? 8B F8 83 C4 ?? 85 FF 0F 84 ?? ?? ?? ?? 6A - ?? 8D 45 ?? 50 68 ?? ?? ?? ?? 57 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? - 8B 45 ?? 3D ?? ?? ?? ?? 0F 92 C3 85 C0 74 ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 57 6A ?? 0F - B6 C3 50 6A ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 75 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 8D - 45 ?? 50 FF 75 ?? 57 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? EB ?? 8B 75 ?? 84 - DB 74 - } - $find_files = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 83 EC ?? A1 ?? ?? ?? ?? 33 C5 89 - 45 ?? 53 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 89 4D ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 74 ?? 32 C0 E9 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 68 ?? ?? - ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 89 06 FF - D7 85 C0 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 90 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D3 - F6 05 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 8B - 4D ?? 6A ?? 68 ?? ?? ?? ?? E8 - } + $a = { 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0 } condition: - uint16(0)==0x5A4D and ($find_files) and ($import_key) and ($encrypt_files) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Dmalocker : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_95E0056C : FILE MEMORY { meta: - description = "Yara rule that detects DMALocker ransomware." - author = "ReversingLabs" - id = "3ddef0f1-61c9-59f6-a02c-35768c2cd4d6" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.DMALocker.yara#L1-L149" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "107dbc4cacd9d451e9c6fe8aa91cd612f70ac767ee70f74f3a77d1e5548b054f" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "95e0056c-bc07-42cf-89ab-6c0cde3ccc8a" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1383-L1401" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380" + logic_hash = "9e34891d28034d1f4fc3da5cb99df8fc74f0b876903088f5eab5fe36e0e0e603" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "DMALocker" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $dmalock_v1_encrypt_files_1 = { - 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? - ?? ?? A3 ?? ?? ?? ?? 52 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 - F8 ?? 75 ?? 32 C0 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8A 9D ?? ?? ?? - ?? 33 C0 84 DB 74 ?? EB ?? 8D [2-5] 8A 90 ?? ?? ?? ?? 84 D2 74 ?? 8A 8C 05 - ?? ?? ?? ?? 3A CA 74 ?? 80 F1 ?? 3A CA 75 ?? 40 80 BC 05 ?? ?? ?? ?? ?? 75 ?? 8A 8C - 05 ?? ?? ?? ?? 3A 88 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 33 C0 84 DB 74 ?? 8A 90 ?? ?? ?? - ?? 84 D2 74 ?? 8A 8C 05 ?? ?? ?? ?? 3A CA - } - $dmalock_v1_encrypt_files_2 = { - EB ?? 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B BD ?? ?? ?? ?? - 8D 95 ?? ?? ?? ?? 52 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? - ?? 8B 4D ?? 5F 5E 33 CD B0 ?? 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $dmalock_v1_encrypt_files_3 = { - 74 ?? 80 F1 ?? 3A CA 75 ?? 40 80 BC 05 ?? ?? ?? ?? ?? 75 ?? 8A 8C 05 ?? ?? ?? ?? 3A - 88 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 56 8D 95 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 52 E8 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 83 C4 ?? A8 ?? 74 ?? A8 ?? 0F 85 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? 50 56 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 8B 55 - ?? 8B 85 ?? ?? ?? ?? 52 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 - } - $dmalock_v1_enum_shares_and_discs_type_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 57 68 ?? ?? - ?? ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B ?? 83 C4 ?? 89 ?? ?? ?? ?? ?? C6 85 ?? - ?? ?? ?? ?? 85 ?? 0F 84 ?? ?? ?? ?? ?? 32 DB E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? ?? - 8B F8 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 ?? 6A ?? 89 45 ?? 66 89 45 ?? 88 45 ?? 8D 45 ?? - 6A ?? 50 88 5D ?? E8 ?? ?? ?? ?? 6A ?? 8D 4D ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 75 ?? B3 ?? 6A ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 84 DB 74 ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 32 C0 5F 5E 5B 8B 4D ?? 33 CD - E8 ?? ?? ?? ?? 8B E5 5D C3 8D 95 ?? ?? ?? ?? 52 ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 83 BD ?? ?? ?? ?? ?? 77 ?? 81 BD ?? ?? ?? ?? ?? ?? ?? ?? 72 ?? C6 - 85 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 ?? E8 ?? ?? ?? ?? 83 C4 ?? 50 E8 ?? ?? ?? ?? - 8B 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 51 52 68 - } - $dmalock_v1_enum_shares_and_discs_type_2 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 8B 5D ?? 56 57 - 8D 8D ?? ?? ?? ?? 51 50 6A ?? 6A ?? 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? 33 C0 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 ?? ?? 8B 95 ?? ?? ?? - ?? 52 6A ?? FF 15 ?? ?? ?? ?? 8B F8 89 BD ?? ?? ?? ?? 85 FF 75 ?? 50 68 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 ?? - ?? 8D A4 24 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 6A ?? 57 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 51 57 8D 95 ?? ?? ?? ?? 52 50 FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 39 85 ?? ?? ?? ?? 76 ?? 8D 77 ?? EB ?? 8D A4 24 - ?? ?? ?? ?? 83 7E ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 51 - C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 0E 8B C1 83 C4 ?? 8D 78 ?? 8B FF 8A 10 40 84 - D2 75 ?? 2B C7 50 51 8D 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 8B 06 83 C4 ?? 8D 50 ?? 90 - 8A 08 40 84 C9 75 ?? 2B C2 6A ?? 8D 84 05 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 8B 4D ?? 83 C4 ?? 51 8D 95 ?? ?? ?? ?? 53 52 E8 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 83 - C4 ?? 8B 46 ?? 83 E0 ?? 3C ?? 75 ?? 8B 4D ?? 51 53 8D 56 ?? 52 E8 ?? ?? ?? ?? 85 C0 - 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B 85 ?? ?? ?? ?? 40 83 C6 ?? 89 85 ?? - ?? ?? ?? 3B 85 ?? ?? ?? ?? 0F 82 ?? ?? ?? ?? E9 ?? ?? ?? ?? 3D ?? ?? ?? ?? 74 ?? 50 - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 FF 15 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 8B 4D ?? F7 D8 5F 1B C0 5E 33 CD 40 5B E8 ?? ?? ?? ?? 8B E5 5D C2 - } - $dmalock_v1_enum_shares_and_discs_type_3 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 57 68 ?? ?? - ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? A3 ?? ?? ?? ?? FF D0 68 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? 6A ?? 51 8B D8 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? A3 ?? ?? ?? ?? BF ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? F7 C3 ?? ?? ?? ?? 76 ?? 57 8D 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? - ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8B F0 56 68 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 FE ?? 74 ?? 83 FE ?? 74 ?? 83 FE ?? 75 ?? 8B - 55 ?? 8B 85 ?? ?? ?? ?? 52 50 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 47 D1 EB - FF 8D ?? ?? ?? ?? 75 ?? 8B 4D ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $dmalock_v2_enum_logical_disks = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 33 DB 68 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 53 50 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F BE 4D ?? 51 8D 95 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 53 50 88 9D ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? - ?? 52 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 85 C0 75 ?? 8D 8D ?? ?? ?? ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? - B0 ?? 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 4D ?? 8A C3 33 CD 5B E8 ?? ?? - ?? ?? 8B E5 5D C3 - } - $dmalock_v4_remote_server_communication = { - 85 FF 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 83 FB ?? 0F - 87 ?? ?? ?? ?? FF 24 9D ?? ?? ?? ?? 8B 46 ?? 50 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 - C4 ?? B0 ?? C3 8B 4E ?? 8B 56 ?? 51 52 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 - ?? C3 8B 46 ?? 8B 4E ?? 50 51 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? C3 8B - 56 ?? 8B 46 ?? 52 50 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? C3 8B 4E ?? 8B - 56 ?? 51 52 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? C3 8B 46 ?? 8B 4E ?? 8B - 56 ?? 50 51 52 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? C3 8B 46 ?? 8B 4E ?? - 50 51 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? B0 ?? C3 32 C0 C3 - } - $dmalock_v4_encrypt_file_1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 45 ?? 53 56 57 68 ?? ?? - ?? ?? 50 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 85 F6 0F 84 ?? ?? ?? ?? 56 - 32 DB E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 56 8B F8 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 56 - 6A ?? 89 45 ?? 89 45 ?? 66 89 45 ?? 8D 45 ?? 6A ?? 50 88 5D ?? E8 ?? ?? ?? ?? 6A ?? - 8D 4D ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? B3 ?? 6A ?? 57 56 E8 - ?? ?? ?? ?? 83 C4 ?? 84 DB 74 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 5F 5E 5B 8B 4D ?? - 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $dmalock_v4_encrypt_file_2 = { - 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 6A ?? 52 C6 85 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 89 B5 ?? ?? ?? - ?? 85 F6 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8B - D8 6A ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 83 3D ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? 0F 85 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B F0 83 C4 ?? 89 B5 ?? ?? ?? ?? 85 F6 74 - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 46 ?? 85 C0 74 ?? 8B 75 ?? B9 ?? ?? ?? - ?? 8B F8 F3 A5 66 A5 8B B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 89 46 - ?? EB ?? 33 F6 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 8D 7E ?? 57 89 35 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 8B C6 E8 ?? ?? ?? ?? 84 C0 74 ?? 8B 4E ?? 8B 17 56 6A - ?? 6A ?? 68 ?? ?? ?? ?? 51 52 FF 15 ?? ?? ?? ?? 85 C0 74 ?? C6 46 ?? ?? 8B B5 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 50 53 8D 8D ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 56 6A ?? 6A ?? 68 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 56 52 6A ?? 53 E8 ?? ?? ?? ?? 8B 45 ?? - 8B 8D ?? ?? ?? ?? 56 50 6A ?? 51 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? E8 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 5F 5E 33 - CD B8 ?? ?? ?? ?? 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } + $a = { 50 46 00 13 10 11 16 17 00 57 51 47 50 00 52 43 51 51 00 43 } condition: - uint16(0)==0x5A4D and ($dmalock_v1_encrypt_files_1 and $dmalock_v1_encrypt_files_2 and $dmalock_v1_encrypt_files_3 and $dmalock_v1_enum_shares_and_discs_type_1) or ($dmalock_v1_encrypt_files_1 and $dmalock_v1_encrypt_files_2 and $dmalock_v1_encrypt_files_3 and $dmalock_v1_enum_shares_and_discs_type_2) or ($dmalock_v1_encrypt_files_1 and $dmalock_v1_encrypt_files_2 and $dmalock_v1_encrypt_files_3 and $dmalock_v1_enum_shares_and_discs_type_3) or ($dmalock_v1_encrypt_files_1 and $dmalock_v1_encrypt_files_3 and $dmalock_v1_enum_shares_and_discs_type_1 and $dmalock_v2_enum_logical_disks) or ($dmalock_v4_encrypt_file_1 and $dmalock_v4_encrypt_file_2 and $dmalock_v4_remote_server_communication and $dmalock_v2_enum_logical_disks) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Hentaioniichan : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_B548632D : FILE MEMORY { meta: - description = "Yara rule that detects Hentai Oniichan ransomware." - author = "ReversingLabs" - id = "cd5e916f-7195-5bb6-abff-b08231053f9a" - date = "2021-03-05" - modified = "2021-03-05" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.HentaiOniichan.yara#L1-L140" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "153526e5a2f05bc8e3f77d83eefce6b4cd962ea093b6f1c0ab8fcabe8d8a7ad9" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "b548632d-7916-444a-aa68-4b3e38251905" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1403-L1421" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "639d9d6da22e84fb6b6fc676a1c4cfd74a8ed546ce8661500ab2ef971242df07" + logic_hash = "bfb46457f8b79548726e3988d649f94e04f26f9e546aae70ece94defae6bab8a" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "HentaiOniichan" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "8b355e9c1150d43f52e6e9e052eda87ba158041f7b645f4f67c32dd549c09f28" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files_p1 = { - 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 4D ?? 8B 55 ?? 53 - 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 74 ?? - 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 ?? ?? ?? ?? 8A 01 88 85 ?? ?? ?? - ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? - ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 8A C3 75 ?? B0 ?? 2B - CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D ?? ?? ?? ?? 56 1B C0 89 9D ?? ?? ?? ?? - 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? F7 D8 - } - $find_files_p2 = { - 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 - ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? - ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 ?? 8A 48 ?? 84 C9 74 ?? - 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? - ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? - ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? - 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 8B D8 56 FF 15 ?? ?? ?? - ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B C3 8B 4D ?? - 5F 33 CD 5B E8 ?? ?? ?? ?? C9 C3 - } - $inject_code_into_process = { - 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F8 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 0F 1F 84 00 ?? ?? ?? ?? 8B C6 8D 8D - ?? ?? ?? ?? 66 8B 11 66 3B 10 75 ?? 66 85 D2 74 ?? 66 8B 51 ?? 66 3B 50 ?? 75 ?? 83 - C1 ?? 83 C0 ?? 66 85 D2 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 75 ?? FF B5 ?? ?? ?? - ?? 50 6A ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? FF 15 ?? ?? ?? ?? 39 85 ?? ?? ?? ?? - 74 ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? C6 45 ?? - ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 - ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? - ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 - ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 8D ?? - ?? ?? ?? 83 C1 ?? 89 8D ?? ?? ?? ?? 3B 8D ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8B 45 ?? 8B - 4D ?? 85 C9 74 ?? 51 8B D0 E8 ?? ?? ?? ?? 8B 4D ?? B8 ?? ?? ?? ?? 8B 75 ?? 83 C4 ?? - 2B CE F7 E9 C1 FA ?? 8B C2 C1 E8 ?? 03 C2 8D 0C 40 8B C6 C1 E1 ?? 81 F9 ?? ?? ?? ?? - 72 ?? 8B 76 ?? 83 C1 ?? 2B C6 83 C0 ?? 83 F8 ?? 77 ?? 51 56 E8 ?? ?? ?? ?? 83 C4 ?? - 8B 4D ?? 64 89 0D ?? ?? ?? ?? 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D 8B E3 - 5B C3 E8 - } - $remote_connection_p1 = { - 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? C7 45 - ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 28 45 - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 29 45 ?? 0F 28 45 - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF 85 ?? ?? ?? ?? 50 0F 29 45 ?? E8 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8D 45 - ?? C7 45 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - 0F 28 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF 85 ?? ?? ?? ?? 0F 29 45 ?? - C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? - 0F 28 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF 85 ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 0F 29 45 - } - $remote_connection_p2 = { - 0F 28 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 0F EF 85 ?? ?? ?? ?? 50 0F 29 45 - ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 0F 43 95 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? 8B 40 ?? 03 C8 33 C0 39 41 - ?? 0F 94 C0 8D 04 85 ?? ?? ?? ?? 0B 41 ?? 50 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? B8 ?? - ?? ?? ?? 2B C1 83 F8 ?? 0F 82 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 51 - 0F 43 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 50 6A ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? - 0F 43 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 6A ?? 6A ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? 8D 4D ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 8D ?? ?? ?? ?? 83 BD ?? ?? ?? ?? - ?? 8B 85 ?? ?? ?? ?? 0F 43 8D ?? ?? ?? ?? 03 C1 50 51 8D 85 ?? ?? ?? ?? 50 8D 4D ?? - E8 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 - 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 C4 ?? 8B F0 83 FA ?? 72 ?? 8B - 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? - 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 - } - $encrypt_files = { - 8B FF 55 8B EC 83 EC ?? 8B 4D ?? 89 4D ?? 53 56 8B 75 ?? 57 8B 7D ?? 89 7D ?? 85 C9 - 0F 84 ?? ?? ?? ?? 85 FF 75 ?? E8 ?? ?? ?? ?? 83 20 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C8 ?? E9 ?? ?? ?? ?? 8B C6 8B D6 C1 FA ?? 83 E0 ?? 6B C0 ?? 89 - 55 ?? 8B 14 95 ?? ?? ?? ?? 89 45 ?? 8A 5C 02 ?? 80 FB ?? 74 ?? 80 FB ?? 75 ?? 8B C1 - F7 D0 A8 ?? 74 ?? 8B 45 ?? F6 44 02 ?? ?? 74 ?? 6A ?? 6A ?? 6A ?? 56 E8 ?? ?? ?? ?? - 83 C4 ?? 56 E8 ?? ?? ?? ?? 59 84 C0 74 ?? 84 DB 74 ?? FE CB 80 FB ?? 0F 87 ?? ?? ?? - ?? FF 75 ?? 8D 45 ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 E9 ?? ?? ?? ?? FF 75 ?? 8D - 45 ?? 57 56 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 8B 45 ?? 8B 0C 85 ?? ?? ?? ?? 8B 45 ?? - 80 7C 01 ?? ?? 7D ?? 0F BE C3 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 83 E8 ?? 0F 85 ?? ?? ?? - ?? FF 75 ?? 8D 45 ?? 57 56 50 E8 ?? ?? ?? ?? EB ?? FF 75 ?? 8D 45 ?? 57 56 50 E8 ?? - ?? ?? ?? EB ?? FF 75 ?? 8D 45 ?? 57 56 50 E8 ?? ?? ?? ?? EB ?? 8B 4C 01 ?? 8D 7D ?? - 33 C0 AB 6A ?? AB AB 8D 45 ?? 50 FF 75 ?? FF 75 ?? 51 FF 15 ?? ?? ?? ?? 85 C0 75 ?? - FF 15 ?? ?? ?? ?? 89 45 ?? 8D 75 ?? 8D 7D ?? A5 A5 A5 8B 45 ?? 85 C0 75 ?? 8B 45 ?? - 85 C0 74 ?? 6A ?? 5E 3B C6 75 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 - 30 E9 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 E9 ?? ?? ?? ?? 8B 7D ?? 8B 45 ?? 8B 4D ?? 8B - 04 85 ?? ?? ?? ?? F6 44 08 ?? ?? 74 ?? 80 3F ?? 74 ?? E8 ?? ?? ?? ?? C7 00 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 20 ?? E9 ?? ?? ?? ?? 2B 45 ?? EB ?? 33 C0 5F 5E 5B C9 C3 - } + $a = { 00 0B 01 00 00 0E 00 00 00 18 03 00 7F E9 38 32 C9 4D 04 9A } condition: - uint16(0)==0x5A4D and ($inject_code_into_process) and ( all of ($find_files_p*)) and ($encrypt_files) and ( all of ($remote_connection_p*)) + all of them } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Hog : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_E0Cf29E2 : FILE MEMORY { meta: - description = "Yara rule that detects Hog ransomware." - author = "ReversingLabs" - id = "b4f26acf-5ff1-5c49-8cfa-8f619af84efd" - date = "2021-10-12" - modified = "2021-10-12" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Hog.yara#L1-L70" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "c5cbc79fee9083ed3befa6b0d348f2d38064bb9012b8f0ca11afd7137243866d" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "e0cf29e2-88d7-4aa4-b60a-c24626f2b246" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1423-L1440" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "693e27da8cbab32954cc2c9ba648151ad9fc21fe53251628145d7b436ec5e976" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Hog" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $generate_key = { - 73 ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 1A 8D ?? ?? ?? ?? 0C 2B ?? 07 08 6F ?? ?? ?? ?? 08 - 16 28 ?? ?? ?? ?? 0D 06 72 ?? ?? ?? ?? 09 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 5E 28 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 26 02 25 17 59 10 ?? 16 30 ?? 06 6F ?? ?? ?? ?? 13 ?? DE ?? 07 2C ?? - 07 6F ?? ?? ?? ?? DC 11 ?? 2A - } - $find_files = { - 16 7E ?? ?? ?? ?? 73 ?? ?? ?? ?? 0A 06 16 16 6F ?? ?? ?? ?? 2D ?? DD ?? ?? ?? ?? 00 1F - ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? - ?? ?? 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? - 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 7E ?? - ?? ?? ?? 6F ?? ?? ?? ?? 17 31 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 25 2D ?? 26 7E ?? ?? ?? - ?? FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C - 2B ?? 08 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 6F ?? ?? ?? ?? 2D ?? DE ?? 08 2C ?? 08 6F ?? - ?? ?? ?? DC 28 ?? ?? ?? ?? DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC DE ?? 26 28 ?? ?? ?? ?? - DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? DC 2A - } - $encrypt_files_p1 = { - 02 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? 02 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? - ?? ?? ?? 31 ?? DD ?? ?? ?? ?? 73 ?? ?? ?? ?? 0A 06 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 06 1F ?? 8D ?? ?? ?? ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 19 - 73 ?? ?? ?? ?? 0B 02 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 08 06 6F ?? ?? ?? - ?? 17 73 ?? ?? ?? ?? 0D 08 06 6F ?? ?? ?? ?? 16 06 6F ?? ?? ?? ?? 8E 69 6F ?? ?? ?? ?? - 07 09 6F ?? ?? ?? ?? DE ?? 09 2C ?? 09 6F ?? ?? ?? ?? DC DE ?? 08 2C ?? 08 6F ?? ?? ?? - ?? DC DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? DC 02 28 ?? - ?? ?? ?? DE ?? 26 DE ?? 2A - } - $encrypt_files_p2 = { - 73 ?? ?? ?? ?? 0A 06 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 1F ?? 8D ?? ?? ?? - ?? 25 D0 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 6F ?? ?? ?? ?? 0B - 73 ?? ?? ?? ?? 0C 08 06 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 0D 09 07 16 07 8E 69 6F ?? ?? - ?? ?? 09 6F ?? ?? ?? ?? DE ?? 09 2C ?? 09 6F ?? ?? ?? ?? DC 08 6F ?? ?? ?? ?? 28 ?? ?? - ?? ?? 10 ?? DE ?? 08 2C ?? 08 6F ?? ?? ?? ?? DC 02 13 ?? DE ?? 06 2C ?? 06 6F ?? ?? ?? - ?? DC 26 DE ?? 02 2A 11 ?? 2A - } + $a = { 83 FE 01 76 12 0F B7 07 83 EE 02 48 83 C7 02 48 01 C2 83 FE 01 } condition: - uint16(0)==0x5A4D and ($find_files) and ($generate_key) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Ragnarlocker : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_1754B331 : FILE MEMORY { meta: - description = "Yara rule that detects RagnarLocker ransomware." - author = "ReversingLabs" - id = "3bc3765a-f1f8-59bc-bbe8-6821654b334f" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.RagnarLocker.yara#L1-L108" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "398f0e5e003f87edf90cdea718be6b10470df317214d00db4dc6c4cccc5b6748" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "1754b331-5704-43c1-91be-89c7a0dd29a4" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1442-L1460" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0d89fc59d0de2584af0e4614a1561d1d343faa766edfef27d1ea96790ac7014b" + logic_hash = "fde04b0e31a00326f9d011198995999ff9b15628f5ff4139ec7dec19ac0c59c9" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "RagnarLocker" - tc_detection_factor = 5 - importance = 25 - - strings: - $find_files_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 33 C0 B9 ?? ?? ?? ?? 53 8B 1D ?? ?? ?? ?? 56 8B 75 ?? 57 - 8D BD ?? ?? ?? ?? F3 AB 8B 3D ?? ?? ?? ?? 39 45 ?? 0F 84 ?? ?? ?? ?? 8D 45 ?? 50 8D - 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF 75 - ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF D3 - } - $find_files_p2 = { - 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? - ?? 83 FB ?? 75 ?? C7 45 ?? ?? ?? ?? ?? 33 F6 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? FF 74 B5 ?? 8D 85 ?? ?? ?? ?? 50 FF D7 85 C0 0F 84 ?? ?? ?? - ?? 46 83 FE ?? 7C ?? 33 C0 85 C0 0F 85 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 - 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 FF 75 ?? FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 - FF D6 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 FF D6 6A ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF D6 6A ?? 8D 85 ?? ?? ?? ?? 53 50 E8 ?? - ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? - ?? ?? 8B 45 ?? 8B 1D ?? ?? ?? ?? 8B 75 ?? 50 FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - 56 FF D3 - } - $find_files_p3 = { - 33 F6 C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? - ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 90 FF 74 B5 ?? - 53 FF D7 85 C0 74 ?? 46 83 FE ?? 72 ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 8B 45 ?? 8B 75 ?? 8D 8D ?? ?? ?? ?? 51 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? E9 - ?? ?? ?? ?? 5F 5E 32 C0 5B 8B E5 5D C3 FF 75 ?? FF 15 ?? ?? ?? ?? 5F 5E B0 ?? 5B 8B - E5 5D C3 - } - $encrypt_files_p1 = { - 56 8B 75 ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 83 C4 ?? 68 ?? ?? ?? ?? 50 FF D7 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D7 56 8B 35 ?? ?? - ?? ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D6 68 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 FF D6 6A ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 68 ?? ?? ?? ?? FF D6 FF 75 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8B F0 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? - ?? ?? 8B F8 C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? 56 8D 85 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 85 C0 74 ?? FF 75 ?? 6A ?? FF 15 ?? ?? ?? ?? 50 FF 15 - } - $encrypt_files_p2 = { - 8D 45 ?? 50 57 68 ?? ?? ?? ?? 56 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 75 ?? - 57 50 FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? - 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 85 C0 74 ?? 8B 35 ?? ?? ?? - ?? 8D 4D ?? 6A ?? 51 FF 75 ?? FF 75 ?? 50 FF D6 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 68 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 - C4 ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8D 4D ?? 51 50 8D 85 ?? ?? ?? ?? - 50 FF 75 ?? FF D6 8B 45 ?? 50 FF 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? - ?? ?? ?? FF D0 FF 75 ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? BF ?? ?? - ?? ?? 89 45 ?? 8D 57 ?? 8B CF D3 E8 A8 ?? 0F 84 ?? ?? ?? ?? 8D 47 ?? C7 45 ?? ?? ?? - ?? ?? 66 89 45 ?? 33 F6 33 C0 50 50 50 50 50 68 ?? ?? ?? ?? 50 66 89 45 ?? 8D 45 ?? - 50 FF 15 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? - ?? 83 7D ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 66 8B 85 ?? ?? ?? ?? 66 3B 45 ?? 75 ?? 66 8B 85 ?? ?? ?? ?? 66 3B 45 ?? B8 ?? ?? - ?? ?? 0F 44 F0 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 50 FF 15 ?? ?? ?? ?? 6A ?? 8D 85 ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 83 C4 ?? BA ?? - ?? ?? ?? 83 EF ?? 8B 45 ?? 0F 89 ?? ?? ?? ?? 0F 57 C0 C7 85 - } - $encrypt_files_p3 = { - 0F 29 85 ?? ?? ?? ?? 0F 29 85 ?? ?? ?? ?? 0F 29 85 ?? ?? ?? ?? 0F 29 85 ?? ?? ?? ?? - 0F 29 45 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 68 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8D 45 ?? 50 6A ?? 6A ?? 6A ?? 68 - ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 6A ?? FF 75 ?? FF 15 ?? ?? - ?? ?? B8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 6A ?? 50 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 - FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 6A ?? 6A ?? 6A ?? 6A ?? - 6A ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 - C0 74 ?? FF 75 ?? 8B 35 ?? ?? ?? ?? FF D6 FF 75 ?? FF D6 6A ?? FF 15 - } + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "35db945d116a4c9264af44a9947a5e831ea655044728dc78770085c7959a678e" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { CF 07 66 5F 10 F0 EB 0C 42 0B 2F 0B 0B 43 C1 42 E4 C2 7C 85 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Hermes : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_3278F1B8 : FILE MEMORY { meta: - description = "Yara rule that detects Hermes ransomware." - author = "ReversingLabs" - id = "1f1f363a-5be0-59e5-b1c1-5e277922790c" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Hermes.yara#L1-L284" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6db95c422ee2f9dd8a1795031ee8d7d5ed84e16cde47512becc006b6a849e890" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "3278f1b8-f208-42c8-a851-d22413f74dea" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1462-L1480" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb" + logic_hash = "4d709e8e2062099ac06b241408e52bcb86bbf8163faaffbcff68a05f864e1b3f" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Hermes" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "7e9fc284c9c920ac2752911d6aacbc3c2bf1b053aa35c22d83bab0089290778d" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $hermes_find_files_v1_p1 = { - A5 A5 A5 8D BD ?? ?? ?? ?? 66 AB BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? A5 A5 66 A5 68 ?? - ?? ?? ?? 8D BD ?? ?? ?? ?? 50 AB 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 83 65 - ?? ?? 8B 5D ?? 8B FB 4F 4F 8D 47 ?? 66 8B 4F ?? 47 47 66 85 C9 75 ?? BE ?? ?? ?? ?? - A5 A5 8D 8D ?? ?? ?? ?? 51 50 66 A5 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 89 45 ?? E8 - ?? ?? ?? ?? 59 59 8B C8 E8 ?? ?? ?? ?? 8B CB 8B D0 E8 ?? ?? ?? ?? 2B C2 33 C9 83 7D - ?? ?? 66 89 0C 43 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? - 8B C1 6A ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 ?? FF 15 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? - 8B C1 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 FF 75 - ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? BE ?? ?? ?? ?? 8D 7D ?? A5 A5 A5 A5 33 - } - $hermes_find_files_v1_p2 = { - C0 6A ?? 59 6A ?? 8D 7D ?? 66 AB BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 A5 59 BE ?? ?? - ?? ?? 8D BD ?? ?? ?? ?? F3 A5 BE ?? ?? ?? ?? 8D 7D ?? A5 A5 A5 A5 6A ?? 59 8D 7D ?? - AB BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? F3 A5 8D BD ?? ?? ?? ?? AB AB 66 AB BE ?? ?? ?? - ?? 8D 7D ?? A5 A5 A5 A5 33 C0 6A ?? 8D 7D ?? AB 59 BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? - F3 A5 66 A5 8D BD ?? ?? ?? ?? AB BE ?? ?? ?? ?? 8D BD ?? ?? ?? ?? A5 A5 A5 A5 8D BD - ?? ?? ?? ?? AB AB AB 66 AB 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 - C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 - 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 - 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D - 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 - 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 0F - } - $hermes_find_files_v1_p3 = { - 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? - ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 - 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F - 85 ?? ?? ?? ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? - ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F - 85 ?? ?? ?? ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D - } - $hermes_find_files_v1_p4 = { - 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 45 - ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? - ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? F6 85 - ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? F6 85 ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 53 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8B C8 E8 ?? ?? ?? ?? 83 F8 ?? 7E ?? 53 FF 75 - ?? FF 75 ?? E8 - } - $hermes_encrypt_files_v1_p1 = { - 55 8B EC 83 EC ?? 53 56 57 FF 75 ?? FF 15 ?? ?? ?? ?? BB ?? ?? ?? ?? 3B C3 74 ?? 53 - FF 75 ?? FF 15 ?? ?? ?? ?? 33 F6 56 53 6A ?? 56 56 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? - ?? ?? ?? 89 45 ?? 3B C6 0F 84 ?? ?? ?? ?? 8D 4D ?? 51 50 FF 15 ?? ?? ?? ?? 89 45 ?? - 83 F8 ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 82 ?? ?? ?? ?? 56 89 45 ?? 8D 45 ?? 50 56 56 - 6A ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? BF ?? ?? ?? ?? 57 FF 75 ?? 56 - FF 15 ?? ?? ?? ?? 89 45 ?? 3B C6 74 ?? 56 8D 4D ?? 51 FF 75 ?? 89 75 ?? 50 FF 75 ?? - FF 15 ?? ?? ?? ?? 85 C0 74 ?? 8B 45 ?? 8B 4D ?? 8D 44 08 ?? 80 38 ?? 75 ?? 80 78 ?? - ?? 75 ?? 80 78 ?? ?? 75 ?? 80 78 ?? ?? 75 ?? 80 78 ?? ?? 75 ?? 80 78 ?? ?? 75 ?? FF - 75 ?? FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 33 C0 5F 5E 5B - } - $hermes_encrypt_files_v1_p2 = { - C9 C3 FF 75 ?? 8D 45 ?? 50 51 56 6A ?? 56 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 74 ?? 56 - 56 56 FF 75 ?? FF 15 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 E8 ?? ?? ?? - ?? 6A ?? 57 FF 75 ?? 88 45 ?? 56 FF 15 ?? ?? ?? ?? 8B F8 89 7D ?? 3B FE 74 ?? FF 75 - ?? 0F BE 45 ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 56 8D 45 ?? 50 FF 75 ?? 89 75 ?? 57 FF - 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? BF ?? ?? ?? ?? 57 56 FF 75 ?? FF 15 - ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 56 53 6A ?? 56 56 68 ?? ?? ?? ?? FF 75 ?? FF - 15 ?? ?? ?? ?? 8B D8 3B DE 0F 84 ?? ?? ?? ?? 56 8D 45 ?? 50 FF 75 ?? 89 75 ?? FF 75 - ?? 53 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 56 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? - 53 89 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 57 56 FF - 75 ?? FF 15 ?? ?? ?? ?? 33 C0 40 E9 - } - $hermes_enum_resources_v1 = { - 55 8B EC 83 EC ?? 53 56 57 8D 45 ?? 50 FF 75 ?? C7 45 ?? ?? ?? ?? ?? 6A ?? 6A ?? 6A - ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? 6A ?? FF - 15 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? FF 75 ?? 6A ?? 53 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 45 ?? 50 53 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B - 43 ?? 66 83 38 ?? 8D 48 ?? 75 ?? 66 83 78 ?? ?? 75 ?? 6A ?? 51 E8 ?? ?? ?? ?? 59 59 - 85 C0 74 ?? 8B 43 ?? 8B D0 66 8B 08 40 40 66 85 C9 75 ?? 8B 7D ?? 2B C2 4F 4F 66 8B - 4F ?? 47 47 66 85 C9 75 ?? 8B C8 C1 E9 ?? 8B F2 F3 A5 8B C8 83 E1 ?? F3 A4 8B 7D ?? - 4F 4F 66 8B 47 ?? 47 47 66 85 C0 75 ?? BE ?? ?? ?? ?? A5 8B 43 ?? 83 E0 ?? 3C ?? 0F - 85 ?? ?? ?? ?? FF 75 ?? 53 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 33 C0 5F 5E - 5B C9 C3 33 C0 40 EB - } - $hermes_encrypt_files_v2_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 56 57 33 C0 8D BD ?? ?? ?? ?? AB 33 DB 89 5D ?? AB AB - AB 8B 7D ?? 57 FF 15 ?? ?? ?? ?? BE ?? ?? ?? ?? 56 57 FF 15 ?? ?? ?? ?? 53 56 6A ?? - 53 53 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B F0 85 F6 75 ?? 53 FF 15 ?? ?? ?? ?? 33 - C0 E9 ?? ?? ?? ?? 33 DB 33 C0 89 5D ?? 0F 57 C0 89 45 ?? 66 0F 13 45 ?? 83 FE ?? 74 - ?? 8D 45 ?? 50 56 FF 15 ?? ?? ?? ?? 8D 45 ?? 50 56 FF 15 ?? ?? ?? ?? 8B 5D ?? 8B 45 - ?? 83 FB ?? 75 ?? 85 C0 75 ?? 33 FF 47 E9 ?? ?? ?? ?? 83 65 ?? ?? 83 7D ?? ?? 77 ?? - 81 7D ?? ?? ?? ?? ?? 0F 86 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? - 6A ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 8B 4D ?? - 89 45 ?? 83 F9 ?? 72 ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 76 ?? 6A ?? 6A ?? 51 FF 75 ?? E8 - ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 45 ?? 3D ?? ?? ?? ?? 76 ?? - C7 45 ?? ?? ?? ?? ?? EB ?? 8B 55 ?? 8B C1 81 C2 ?? ?? ?? ?? 83 D0 ?? 83 F8 ?? 77 ?? - 72 ?? 81 FA ?? ?? ?? ?? 77 ?? 6A ?? 6A ?? 51 FF 75 ?? E8 ?? ?? ?? ?? 6A ?? 6A ?? 52 - 50 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 45 ?? EB ?? 83 F9 - } - $hermes_encrypt_files_v2_p2 = { - 77 ?? 72 ?? 81 7D ?? ?? ?? ?? ?? 73 ?? 8B 45 ?? EB ?? 8B 45 ?? 3D ?? ?? ?? ?? 0F 87 - ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 0F 82 ?? ?? ?? ?? 83 7D ?? ?? - 0F 82 ?? ?? ?? ?? 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 83 7D ?? ?? B8 ?? ?? ?? ?? 77 ?? 39 - 45 ?? 0F 86 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? 2B D8 53 56 89 5D ?? FF 15 ?? ?? ?? ?? - 83 F8 ?? 75 ?? 6A ?? 58 E9 ?? ?? ?? ?? 33 DB 8D 45 ?? 53 50 6A ?? 8D 85 ?? ?? ?? ?? - 89 5D ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? EB ?? 8B C3 80 BC 05 ?? ?? ?? ?? - ?? 75 ?? 80 BC 05 ?? ?? ?? ?? ?? 75 ?? 80 BC 05 ?? ?? ?? ?? ?? 75 ?? 80 BC 05 ?? ?? - ?? ?? ?? 75 ?? 80 BC 05 ?? ?? ?? ?? ?? 75 ?? 80 BC 05 ?? ?? ?? ?? ?? 74 ?? 40 83 F8 - ?? 72 ?? 53 53 53 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 85 ?? ?? ?? ?? 6A ?? E9 ?? ?? ?? - ?? 56 FF 15 ?? ?? ?? ?? 6A ?? 58 6A ?? 66 89 45 ?? 58 66 89 45 ?? 6A ?? 58 66 89 45 - ?? 33 C0 66 89 45 ?? 8D 45 ?? 50 57 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 6A ?? 68 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? 57 56 89 1E E8 ?? ?? ?? - ?? 57 56 E8 ?? ?? ?? ?? 8D 45 ?? 50 56 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 56 57 FF 15 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 53 56 FF 15 ?? ?? ?? ?? 6A ?? E9 ?? ?? ?? ?? 33 DB 8D 45 - } - $hermes_encrypt_files_v2_p3 = { - 50 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 6A ?? E9 ?? ?? ?? ?? - 39 5D ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? 53 53 68 ?? ?? ?? ?? FF 75 ?? FF 75 ?? E8 - ?? ?? ?? ?? 89 5D ?? 5B 6A ?? 89 4D ?? 33 DB 89 45 ?? 89 55 ?? 5F EB ?? 8B 45 ?? 89 - 45 ?? 53 69 C0 ?? ?? ?? ?? 53 50 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 6A ?? E9 ?? ?? - ?? ?? 53 8D 45 ?? 89 5D ?? 50 6A ?? 5F 57 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? - 85 C0 75 ?? 6A ?? E9 ?? ?? ?? ?? 53 53 53 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 6A ?? - E9 ?? ?? ?? ?? 89 5D ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? 8B - D8 85 DB 75 ?? 6A ?? E9 ?? ?? ?? ?? 8B 55 ?? 33 C9 33 C0 C7 45 ?? ?? ?? ?? ?? 89 4D - ?? 89 45 ?? 83 65 ?? ?? C7 45 ?? ?? ?? ?? ?? 3B CA 75 ?? 8B 4D ?? 89 4D ?? C7 45 ?? - ?? ?? ?? ?? 33 C9 51 51 50 56 89 4D ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? - 6A ?? 8D 45 ?? 50 FF 75 ?? 53 56 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 33 C9 C7 - } - $hermes_encrypt_files_v2_p4 = { - 45 ?? ?? ?? ?? ?? 51 8D 45 ?? 50 51 51 FF 75 ?? 51 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 - 0F 84 ?? ?? ?? ?? FF 75 ?? 8D 45 ?? 50 53 6A ?? FF 75 ?? 6A ?? FF 75 ?? FF 15 ?? ?? - ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 6A ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 83 F8 ?? 0F - 84 ?? ?? ?? ?? 83 65 ?? ?? 8D 45 ?? 6A ?? 50 FF 75 ?? 53 56 FF 15 ?? ?? ?? ?? 85 C0 - 0F 84 ?? ?? ?? ?? 8B 4D ?? 8B 45 ?? 41 8B 55 ?? 05 ?? ?? ?? ?? 89 4D ?? 89 45 ?? 3B - CA 0F 86 ?? ?? ?? ?? 33 C0 C7 45 ?? ?? ?? ?? ?? 8D 7D ?? 66 C7 45 ?? ?? ?? AB AB AB - AB 66 AB 33 C0 88 45 ?? 39 45 ?? 77 ?? 81 7D ?? ?? ?? ?? ?? 77 ?? 8D 45 ?? 50 8D 45 - ?? 50 E8 ?? ?? ?? ?? 59 59 EB ?? 6A ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 33 C0 8D 7D ?? - AB 6A ?? AB 66 AB 8D 45 ?? 50 8B 45 ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 8D 45 ?? 50 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 33 FF 8D 45 ?? 57 50 8D - 45 ?? 89 7D ?? 50 E8 ?? ?? ?? ?? 59 50 8D 45 ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? - 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? ?? 6A ?? E9 ?? ?? ?? ?? 8D 45 ?? 50 57 57 6A - } - $hermes_encrypt_files_v2_p5 = { - FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? - ?? 6A ?? E9 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 57 6A ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 85 - C0 75 ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? ?? 6A ?? E9 ?? ?? ?? ?? 57 8D 45 ?? 89 - 7D ?? 50 FF 75 ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? - ?? 57 53 FF 15 ?? ?? ?? ?? 6A ?? E9 ?? ?? ?? ?? 39 7D ?? 77 ?? 81 7D ?? ?? ?? ?? ?? - 76 ?? 6A ?? 57 0F 57 C0 66 0F 13 45 ?? FF 75 ?? FF 75 ?? 56 FF 15 ?? ?? ?? ?? 83 F8 - ?? 75 ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? ?? 6A ?? EB ?? 57 8D 45 ?? 89 7D ?? 50 - 6A ?? 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? 57 53 FF - 15 ?? ?? ?? ?? 6A ?? EB ?? 56 FF 15 ?? ?? ?? ?? 68 ?? ?? ?? ?? 57 53 E8 ?? ?? ?? ?? - 83 C4 ?? 68 ?? ?? ?? ?? 57 53 FF 15 ?? ?? ?? ?? 6A ?? 5B EB ?? 68 ?? ?? ?? ?? 6A ?? - 53 FF 15 ?? ?? ?? ?? 6A ?? 5B 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B C3 - EB ?? FF 75 ?? FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? EB ?? FF 75 ?? FF 15 ?? - ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 6A ?? EB ?? FF 75 ?? FF 15 ?? ?? ?? ?? 56 FF 15 ?? ?? - ?? ?? 6A ?? 5F EB ?? 6A ?? 5F 56 FF 15 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 6A ?? 53 FF 15 ?? ?? ?? ?? EB ?? 6A ?? E9 ?? ?? ?? ?? 6A ?? 5F 56 FF 15 ?? - ?? ?? ?? 8B C7 5F 5E 5B 8B E5 5D C3 - } - $hermes_find_files_v2_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? 53 8B 5D ?? 8D 85 ?? ?? ?? ?? 56 57 50 68 ?? ?? ?? ?? 53 - E8 ?? ?? ?? ?? 59 59 50 FF 15 ?? ?? ?? ?? 8B F8 68 ?? ?? ?? ?? 53 89 7D ?? E8 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 53 8B F0 E8 ?? ?? ?? ?? 2B C6 33 C9 83 C4 ?? 66 89 0C 43 83 - FF ?? 0F 84 ?? ?? ?? ?? 33 F6 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 83 F8 ?? 75 ?? - 8D 85 ?? ?? ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8D 85 ?? ?? ?? ?? 50 57 - FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 83 - F8 ?? 75 ?? 8D 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 8D - 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 58 6A ?? 5F 6A - ?? 5A 6A ?? 66 89 45 ?? 58 6A ?? 59 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? - 66 89 45 ?? 33 C0 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 - } - $hermes_find_files_v2_p2 = { - 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 33 C0 66 89 45 ?? 58 6A ?? 66 89 45 - ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 33 C0 66 89 55 ?? - 66 89 55 ?? 5A 6A ?? 66 89 45 ?? 58 6A ?? 66 89 85 ?? ?? ?? ?? 58 6A ?? 66 89 4D ?? - 66 89 4D ?? 66 89 8D ?? ?? ?? ?? 59 66 89 85 ?? ?? ?? ?? 6A ?? 58 66 89 85 ?? ?? ?? - ?? 33 C0 66 89 7D ?? 66 89 BD ?? ?? ?? ?? 8D 7D ?? 89 75 ?? 66 89 75 ?? 66 89 55 ?? - 89 75 ?? 66 89 75 ?? 66 89 8D ?? ?? ?? ?? 66 89 8D ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? - AB 6A ?? 66 89 4D ?? 66 89 55 ?? AB 66 89 55 ?? 89 75 ?? AB 66 AB 58 6A ?? 66 89 45 - ?? 58 6A ?? 5F 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? - 66 89 45 ?? 58 6A ?? 66 89 45 ?? 58 6A ?? 59 66 89 45 ?? 33 C0 66 89 45 ?? 6A ?? 58 - 66 89 85 ?? ?? ?? ?? 6A ?? 58 66 89 85 ?? ?? ?? ?? 6A ?? 58 66 89 85 ?? ?? ?? ?? 6A - ?? 58 66 89 85 ?? ?? ?? ?? 6A ?? 58 66 89 85 ?? ?? ?? ?? 33 C0 66 89 7D ?? 66 89 7D - ?? 8D BD ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 66 89 8D ?? ?? ?? ?? 66 89 8D - } - $hermes_find_files_v2_p3 = { - AB AB AB 66 AB 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D - 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? - 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? - 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 - C0 0F 84 ?? ?? ?? ?? 8B 7D ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 - ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? ?? - ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 - E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 - 59 85 C0 75 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 - } - $hermes_find_files_v2_p4 = { - 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 8D 45 ?? 50 8D 85 - ?? ?? ?? ?? 50 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 45 - ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 45 ?? 50 - 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? - 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 45 ?? 50 8D - 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 0F 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 - 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? EB ?? 8B 7D ?? F6 85 ?? ?? ?? - ?? ?? 74 ?? 53 E8 ?? ?? ?? ?? 59 FF 75 ?? 8D 85 ?? ?? ?? ?? FF 75 ?? FF 75 ?? 50 53 - E8 ?? ?? ?? ?? 59 59 50 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 8B F0 8D - 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 2B F0 83 C4 ?? 33 C0 66 89 44 73 ?? 33 F6 8D 85 ?? - ?? ?? ?? 50 57 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 5F 5E - 5B 8B E5 5D C3 - } - $hermes_enum_resources_v2 = { - 55 8B EC 83 EC ?? 53 56 57 8D 45 ?? C7 45 ?? ?? ?? ?? ?? 50 FF 75 ?? 33 DB C7 45 ?? - ?? ?? ?? ?? 53 53 6A ?? 89 5D ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF 75 ?? - 6A ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 74 ?? FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 8D - 45 ?? 50 56 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 7E ?? 6A ?? 58 66 - 39 07 75 ?? 66 39 47 ?? 75 ?? 50 8D 47 ?? 50 E8 ?? ?? ?? ?? 59 59 85 C0 74 ?? 57 FF - 75 ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? 83 C4 ?? F7 46 ?? ?? ?? - ?? ?? 74 ?? FF 75 ?? 56 E8 ?? ?? ?? ?? 59 59 85 C0 75 ?? 33 C0 5F 5E 5B 8B E5 5D C3 - 33 C0 40 EB - } + $a = { D2 0F B6 C3 C1 E0 10 0F B6 C9 C1 E2 18 09 C2 0F B6 44 24 40 C1 } condition: - uint16(0)==0x5A4D and ((( all of ($hermes_find_files_v1_p*)) and ( all of ($hermes_encrypt_files_v1_p*))) or (( all of ($hermes_find_files_v2_p*)) and ( all of ($hermes_encrypt_files_v2_p*)))) and ( any of ($hermes_enum_resources_v*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Cryptofortress : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Ab804Bb7 : FILE MEMORY { meta: - description = "Yara rule that detects CryptoFortress ransomware." - author = "ReversingLabs" - id = "460289b1-f775-5e0b-8c44-4f6e5c92da60" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.CryptoFortress.yara#L1-L162" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "474893b63523de5ff9eb8a0c91b0677b99ce65056af7f5d02a73e43fa65453c9" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "ab804bb7-57ab-48db-85cc-a6d88de0c84a" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1482-L1500" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "8f0cc764729498b4cb9c5446f1a84cde54e828e913dc78faf537004a7df21b20" + logic_hash = "cef2ffafe152332502fb0d72d014c81b90dc9ad4f4491f1b2f2f9c1f73cc7958" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "CryptoFortress" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "b9716aa7be1b0e4c966a25a40521114e33c21c7ec3c4468afc1bf8378dd11932" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $enum_drives = { - 55 8B EC 83 C4 ?? 56 57 C7 45 ?? ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 8D 7D ?? B2 ?? B9 ?? ?? ?? ?? A9 ?? ?? ?? ?? 74 ?? 88 17 47 D1 E8 FE C2 49 - 75 ?? C6 07 ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 8B F8 8D 75 ?? 8A 16 88 55 ?? 8D 45 ?? 50 - FF 15 ?? ?? ?? ?? 8D 55 ?? C6 42 ?? ?? 83 F8 ?? 75 ?? 60 8D 45 ?? 50 8D 45 ?? 50 6A - ?? 8D 45 ?? 50 FF 15 ?? ?? ?? ?? 8D 45 ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 45 ?? - 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 05 ?? ?? ?? ?? 61 46 4F 75 ?? A1 ?? ?? ?? ?? A3 - ?? ?? ?? ?? A1 ?? ?? ?? ?? A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 5F 5E C9 C3 - } - $enum_shared_resources = { - 55 8B EC 83 C4 ?? 8D 45 ?? 50 FF 75 ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 0B C0 0F - 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 89 45 ?? C7 45 ?? ?? ?? ?? ?? 8D 45 ?? 50 FF 75 ?? 8D 45 ?? 50 FF 75 ?? FF 15 - ?? ?? ?? ?? 83 7D ?? ?? 74 ?? 3D ?? ?? ?? ?? 74 ?? 8B 4D ?? 51 8D 49 ?? 6B C9 ?? 8B - 45 ?? 8D 0C 01 6A ?? 51 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 75 ?? FF 75 ?? E8 ?? - ?? ?? ?? 83 F8 ?? 76 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 0B C0 74 ?? FF 75 ?? E8 ?? ?? ?? ?? EB ?? 8D 45 ?? 50 E8 ?? ?? ?? ?? 59 49 75 ?? EB - ?? EB ?? E9 ?? ?? ?? ?? FF 75 ?? 6A ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 75 ?? FF - 15 ?? ?? ?? ?? C9 C2 - } - $find_files = { - 55 8B EC 81 C4 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? FF 35 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 - ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 40 0F 84 ?? ?? ?? ?? 48 89 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 83 E0 ?? 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 - 0F 84 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? - ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? C6 00 ?? 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? C6 00 ?? 2B 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? - E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B - 8D ?? ?? ?? ?? C7 04 08 ?? ?? ?? ?? E8 ?? ?? ?? ?? 58 8B 8D ?? ?? ?? ?? C7 44 08 ?? - ?? ?? ?? ?? E9 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 - 0F 84 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF B5 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 85 C0 0F - 85 ?? ?? ?? ?? 8B 4D ?? 0B C9 75 ?? 6A ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 45 ?? - 8D 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF - 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 49 8B 1D ?? ?? ?? ?? 51 53 - FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 59 EB ?? 53 E8 ?? ?? ?? ?? 03 D8 - 83 C3 ?? 59 E2 ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 8B 8D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 0B - C9 75 ?? 3B D0 72 ?? EB ?? EB ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? - FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B C0 75 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF B5 - ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? FF B5 - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? C9 C3 - } - $encrypt_files = { - 55 8B EC 83 C4 ?? 53 33 C0 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 - 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? 89 45 ?? FF 35 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 89 45 ?? FF 75 ?? E8 ?? ?? ?? ?? 33 C0 50 50 6A ?? 50 6A ?? 68 ?? ?? ?? ?? - FF 75 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? E9 ?? ?? ?? ?? 89 45 ?? 8D 45 ?? 50 8D 45 - ?? 50 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? ?? - 83 7D ?? ?? 75 ?? 83 7D ?? ?? 73 ?? E9 ?? ?? ?? ?? 8B 55 ?? 8B 4D ?? BB ?? ?? ?? ?? - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F B6 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? BB ?? ?? ?? ?? B8 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 0B D2 75 ?? 0B C9 75 ?? B9 ?? ?? ?? ?? 89 4D ?? 89 55 ?? - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 4D ?? 89 55 ?? BB ?? ?? ?? ?? B8 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 89 4D ?? 89 55 ?? 0B DB 75 ?? 0B C0 74 ?? 83 45 ?? ?? 83 55 ?? ?? FF 75 ?? - FF 75 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 83 7D ?? ?? 77 ?? 81 7D ?? ?? ?? - ?? ?? 76 ?? B8 ?? ?? ?? ?? EB ?? 8B 45 ?? 6B C0 ?? 89 45 ?? 6A ?? 8D 45 ?? 50 FF 75 - ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? 0B C0 74 ?? E9 ?? ?? ?? ?? - 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 8D 45 ?? 50 FF 75 ?? 6A ?? 6A ?? 6A ?? FF 35 ?? ?? ?? ?? FF 15 - ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? E8 ?? ?? - ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? ?? ?? 0B C0 74 ?? E9 ?? ?? ?? ?? 6A ?? 8D 45 ?? 50 FF - 75 ?? FF 75 ?? FF 75 ?? FF 15 ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? DF 6D ?? DA 45 - ?? DF 7D ?? C7 45 ?? ?? ?? ?? ?? DF 6D ?? DA 65 ?? DF 7D ?? C7 45 ?? ?? ?? ?? ?? DF - 6D ?? DA 65 ?? DF 7D ?? 83 7D ?? ?? 75 ?? 83 7D ?? ?? 74 ?? E9 ?? ?? ?? ?? 8F 45 ?? - 8F 45 ?? 6A ?? 8D 45 ?? 50 FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? E8 ?? ?? - ?? ?? 0B C0 74 ?? EB ?? 6A ?? 8D 45 ?? 50 6A ?? 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? ?? - ?? 0B C0 75 ?? EB ?? 6A ?? 8D 45 ?? 50 6A ?? 68 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? - ?? 0B C0 75 ?? EB ?? EB ?? 8D 45 ?? 50 8D 45 ?? 50 8D 45 ?? 50 FF 75 ?? FF 15 ?? ?? - ?? ?? FF 75 ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? EB ?? 8D 45 ?? 50 8D 45 ?? 50 8D 45 ?? - 50 FF 75 ?? FF 15 ?? ?? ?? ?? FF 75 ?? E8 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5B C9 C2 - } - $read_config_file = { - 55 8B EC 83 C4 ?? [0-20] 6A ?? 68 ?? ?? ?? ?? 6A - ?? (E8 | FF 15) ?? ?? ?? ?? 0B C0 75 ?? 33 C0 C9 - C3 89 45 ?? 50 6A ?? (E8 | FF 15) ?? ?? ?? ?? 0B - C0 75 04 33 C0 C9 C3 89 45 ?? FF 75 ?? 6A ?? - (E8 | FF 15) ?? ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 - 89 45 ?? 50 (E8 | FF 15) ?? ?? ?? ?? 0B C0 75 04 - 33 C0 C9 C3 89 45 ?? FF 75 ?? 6A ?? (E8 | FF 15) - ?? ?? ?? ?? 0B C0 75 04 33 C0 C9 C3 89 45 ?? 8B - D8 FF 75 ?? FF 75 ?? FF 75 ?? (E8 | FF 15) ?? ?? - ?? ?? FF 75 ?? (E8 | FF 15) ?? ?? ?? ?? 8B 5D ?? - 6A ?? 53 68 ?? ?? ?? ?? (E8 | FF 15) ?? ?? ?? ?? - 83 C3 ?? 8B 45 ?? 83 (E8 | FF 15) ?? 50 53 - (E8 | FF 15) ?? ?? ?? ?? 8A 03 A2 ?? ?? ?? ?? 83 - C3 ?? 8A 03 A2 ?? ?? ?? ?? 83 C3 - } - $file_type_loop = { - 51 53 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 - ?? 75 03 59 EB ?? 53 E8 ?? ?? ?? ?? 03 D8 83 C3 - ?? 59 E2 DC [20-40] FF B5 ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 0B C0 75 44 FF B5 ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? E8 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? FF B5 - ?? ?? ?? ?? E8 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF - B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? 50 FF B5 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 - 0F 85 - } - $encrypt_routine = { - FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? - [0-10] E9 ?? ?? ?? ?? 6A ?? [1-10] FF 75 ?? - FF (35 | 75) [1-4] FF 75 ?? (E8 | FF 15) - ?? ?? ?? ?? 0B C0 75 ?? E9 ?? ?? ?? ?? 68 ?? - ?? ?? ?? [1-10] FF (35 | 75) [1-4] 6A ?? - 6A ?? 6A ?? FF 35 ?? ?? ?? ?? (E8 | FF 15) ?? - ?? ?? ?? 0B C0 75 ?? (EB | E9) [1-4] 6A ?? - [2-10] FF 75 ?? FF 75 ?? E8 ?? ?? ?? ?? 83 F8 - ?? 75 ?? [10-40] FF (35 | 75) [1-4] FF 75 ?? - (E8 |FF 15) - } + $a = { 4A 75 05 0F BE 11 01 D0 89 C2 0F B7 C0 C1 FA 10 01 C2 89 D0 C1 } condition: - uint16(0)==0x5A4D and (($read_config_file and $file_type_loop and $encrypt_routine) or ($enum_drives and $enum_shared_resources and $find_files and $encrypt_files)) + all of them } -rule REVERSINGLABS_Win64_Ransomware_Ako : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Dca3B9B4 : FILE MEMORY { meta: - description = "Yara rule that detects Ako ransomware." - author = "ReversingLabs" - id = "fce98a6a-f7bd-52ee-a2b8-31b48f6134ca" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win64.Ransomware.Ako.yara#L1-L173" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "8321a4ace66ae48e3a6896daf02c184fa7767fa6bd10cd83b322ad01698008cf" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "dca3b9b4-62f3-41ed-a3b3-80dd0990f8c5" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1502-L1520" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "a839437deba6d30e7a22104561e38f60776729199a96a71da3a88a7c7990246a" + logic_hash = "f85dfc1c00706d7ac11ef35c41c471383ef8b019a5c2566b27072a5ef5ad5c93" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Ako" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "b0471831229be1bcbcf6834e2d1a5b85ed66fb612868c2c207fe009ae2a0e799" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_win64_p1 = { - 44 89 4C 24 ?? 4C 89 44 24 ?? 48 89 54 24 ?? 48 89 4C 24 ?? 56 57 48 81 EC ?? ?? ?? - ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 84 24 ?? ?? ?? ?? - 48 83 BC 24 ?? ?? ?? ?? ?? 74 ?? 48 83 BC 24 ?? ?? ?? ?? ?? 75 ?? 32 C0 E9 ?? ?? ?? - ?? 41 B9 ?? ?? ?? ?? 45 33 C0 48 8B 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 90 89 44 24 ?? 81 7C 24 ?? ?? ?? ?? ?? 73 ?? 32 C0 E9 ?? ?? ?? ?? C7 84 24 - ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? 48 8B F8 33 C0 B9 ?? ?? ?? ?? F3 AA - 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 85 C0 75 ?? 32 - C0 E9 ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 - ?? 45 33 C0 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 45 33 C0 BA ?? ?? ?? ?? - 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 84 - 24 ?? ?? ?? ?? 48 8B F8 33 C0 B9 ?? ?? ?? ?? F3 AA C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? - 48 8D 84 24 ?? ?? ?? ?? 48 8B F8 33 C0 B9 ?? ?? ?? ?? F3 AA 48 C7 44 24 ?? ?? ?? ?? - ?? EB ?? 48 8B 44 24 ?? 48 05 ?? ?? ?? ?? 48 89 44 24 ?? 48 8B 84 24 ?? ?? ?? ?? 48 - 39 44 24 ?? 0F 8D ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? - 4C 8D 84 24 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 90 85 C0 75 ?? C6 44 24 ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D - 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 0F B6 44 24 ?? E9 ?? ?? ?? ?? 33 D2 48 8D 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 8C 24 ?? ?? ?? ?? 41 - B8 ?? ?? ?? ?? 48 8B D0 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 85 C0 75 ?? C6 - } - $encrypt_files_win64_p2 = { - 44 24 ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 90 0F B6 44 24 ?? E9 ?? ?? ?? ?? 45 33 C9 4C 8D 84 24 ?? ?? ?? ?? 48 8B 94 - 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 85 C0 75 ?? C6 44 24 ?? - ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 90 0F B6 44 24 ?? E9 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? EB ?? 8B 44 24 ?? 05 ?? ?? - ?? ?? 89 44 24 ?? 8B 84 24 ?? ?? ?? ?? 39 44 24 ?? 0F 83 ?? ?? ?? ?? 48 8D 8C 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 90 8B 4C 24 ?? 48 03 C1 48 89 44 24 ?? 33 D2 48 8D 8C 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B F8 48 8B 44 24 ?? 48 8B F0 B9 ?? ?? ?? ?? F3 A4 48 - 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 8B 4C 24 ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? - ?? 4C 8B C8 45 33 C0 48 8B 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 90 0F B6 C0 85 C0 75 ?? C6 44 24 ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 - 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 0F B6 44 24 ?? E9 ?? ?? ?? ?? 48 8D 8C 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 90 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 4C 24 ?? 44 8B 44 24 ?? - 48 8B D0 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 85 C0 75 ?? C6 44 24 ?? ?? 48 - 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 0F - B6 44 24 ?? E9 ?? ?? ?? ?? E9 ?? ?? ?? ?? 83 BC 24 ?? ?? ?? ?? ?? 75 ?? EB ?? E9 ?? - ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 44 24 ?? 48 8B F8 33 C0 B9 ?? ?? ?? ?? F3 AA - } - $encrypt_files_win64_p3 = { - 48 8B 44 24 ?? 48 89 84 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 44 24 ?? 48 8B - F8 33 C0 B9 ?? ?? ?? ?? F3 AA 48 8B 44 24 ?? 48 89 84 24 ?? ?? ?? ?? 41 B9 ?? ?? ?? - ?? 4C 8D 84 24 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 90 85 C0 0F 84 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 83 C0 ?? 48 8B C8 E8 - ?? ?? ?? ?? 90 48 89 44 24 ?? 48 8B 8C 24 ?? ?? ?? ?? 48 83 C1 ?? E8 ?? ?? ?? ?? 90 - 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 4C 24 ?? 48 8B 4C 24 ?? 44 8B C1 48 8B D0 48 8B 8C - 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 85 C0 0F 84 ?? ?? ?? ?? 8B 44 24 ?? 48 89 44 24 - ?? 48 8B 8C 24 ?? ?? ?? ?? 48 83 C1 ?? E8 ?? ?? ?? ?? 90 48 8B 4C 24 ?? 48 3B C8 0F - 85 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? - C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 8B - 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 4C 8D 4C 24 ?? 41 - B8 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 90 - 85 C0 74 ?? 8B 44 24 ?? 48 83 F8 ?? 75 ?? C6 44 24 ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 0F B6 44 24 ?? EB ?? C6 44 - 24 ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 90 0F B6 44 24 ?? 48 8B 8C 24 ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 90 48 81 C4 - ?? ?? ?? ?? 5F 5E C3 - } - $encrypt_network_shares_win64_p1 = { - 48 89 54 24 ?? 48 89 4C 24 ?? 48 81 EC ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 48 8B - 05 ?? ?? ?? ?? 48 33 C4 48 89 84 24 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8D 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B 84 24 ?? ?? ?? ?? 48 05 ?? ?? ?? ?? 48 8B C8 E8 - ?? ?? ?? ?? 90 0F B6 C0 85 C0 0F 85 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 90 0F B6 C0 85 C0 0F 85 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 - 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 90 0F B6 C0 85 C0 0F 85 ?? ?? ?? ?? 48 8B 84 24 ?? ?? ?? ?? 48 83 - C0 ?? 48 8D 94 24 ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 90 48 8D 15 ?? ?? ?? ?? 48 8D - 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 90 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C - 8D 05 ?? ?? ?? ?? 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B D0 48 8D - 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D - 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D - 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8D 84 24 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 - 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8D 05 ?? ?? ?? ?? 48 8B D0 48 8D 8C 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D - 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B - } - $encrypt_network_shares_win64_p2 = { - 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 90 4C 8D 05 ?? ?? ?? ?? 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 90 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 90 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 94 24 ?? ?? ?? - ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 15 ?? ?? ?? ?? 48 8D 8C - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8D 05 ?? ?? ?? ?? 48 8B D0 48 8D 8C 24 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 90 48 8B D0 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 90 48 8D 15 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 94 24 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 0F B6 C0 85 C0 0F 85 ?? ?? ?? - ?? 48 C7 44 24 ?? ?? ?? ?? ?? EB ?? 48 8B 44 24 ?? 48 FF C0 48 89 44 24 ?? 48 8D 8C - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 39 44 24 ?? 73 ?? 48 83 7C 24 ?? ?? 76 ?? 33 D2 - 48 8B 44 24 ?? B9 ?? ?? ?? ?? 48 F7 F1 48 8B C2 48 85 C0 75 ?? 41 B9 ?? ?? ?? ?? 4C - } - $encrypt_network_shares_win64_p3 = { - 8D 05 ?? ?? ?? ?? 48 8B 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B 44 - 24 ?? 48 FF C0 48 89 44 24 ?? EB ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? E8 ?? ?? ?? - ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 54 24 ?? 48 8D 8C 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8D 15 ?? ?? ?? ?? - 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 90 4C 8B C0 48 8D 94 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 90 48 8B C8 E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 - ?? ?? ?? ?? 90 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 48 8D 15 ?? ?? ?? ?? 48 8D 4C 24 ?? - E8 ?? ?? ?? ?? 90 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 4C 8B C0 48 8D 94 24 ?? - ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8B C8 E8 ?? ?? ?? ?? 90 4C 8B - C0 48 8D 54 24 ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 90 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 90 C6 44 24 ?? ?? 48 8D 8C 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 90 0F B6 44 24 ?? EB ?? 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 90 48 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 90 32 C0 48 8B 8C 24 ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 90 48 81 C4 ?? ?? ?? ?? C3 - } - $find_files_win64 = { - 48 89 5C 24 ?? 55 56 57 41 56 41 57 48 81 EC ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 - C4 48 89 84 24 ?? ?? ?? ?? 4D 8B F0 49 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 8B E9 48 3B D1 - 74 ?? 0F B7 02 66 83 E8 ?? 66 83 F8 ?? 77 ?? 0F B7 C0 49 0F A3 C0 72 ?? 48 83 EA ?? - 48 3B D5 75 ?? 0F B7 0A 66 83 F9 ?? 75 ?? 48 8D 45 ?? 48 3B D0 74 ?? 4D 8B CE 45 33 - C0 33 D2 48 8B CD E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 66 83 E9 ?? 33 FF 66 83 F9 ?? 77 ?? - 0F B7 C1 49 0F A3 C0 B0 ?? 72 ?? 40 8A C7 48 2B D5 48 8D 4C 24 ?? 48 D1 FA 41 B8 ?? - ?? ?? ?? 48 FF C2 F6 D8 4D 1B FF 4C 23 FA 33 D2 E8 ?? ?? ?? ?? 45 33 C9 89 7C 24 ?? - 4C 8D 44 24 ?? 48 89 7C 24 ?? 33 D2 48 8B CD FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? - 75 ?? 4D 8B CE 45 33 C0 33 D2 48 8B CD E8 ?? ?? ?? ?? 8B F8 48 83 FB ?? 74 ?? 48 8B - CB FF 15 ?? ?? ?? ?? 8B C7 48 8B 8C 24 ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 48 8B 9C - 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5E 5F 5E 5D C3 49 8B 76 ?? 49 2B 36 48 - C1 FE ?? 66 83 7C 24 ?? ?? 75 ?? 66 39 7C 24 ?? 74 ?? 66 83 7C 24 ?? ?? 75 ?? 66 39 - 7C 24 ?? 74 ?? 4D 8B CE 48 8D 4C 24 ?? 4D 8B C7 48 8B D5 E8 ?? ?? ?? ?? 85 C0 75 ?? - 48 8D 54 24 ?? 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 75 ?? 49 8B 06 49 8B 56 ?? 48 2B D0 - 48 C1 FA ?? 48 3B F2 0F 84 ?? ?? ?? ?? 48 2B D6 48 8D 0C F0 4C 8D 0D ?? ?? ?? ?? 41 - B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E9 - } + $a = { 83 45 F4 01 8B 45 F4 3B 45 F0 75 11 48 8B 45 F8 48 2B 45 D8 } condition: - uint16(0)==0x5A4D and ($find_files_win64) and ( all of ($encrypt_files_win64_p*)) and ( all of ($encrypt_network_shares_win64_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Badbeeteam : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Ae9D0Fa6 : FILE MEMORY { meta: - description = "Yara rule that detects Badbeeteam ransomware." - author = "ReversingLabs" - id = "39490b21-34b9-51cb-a3ed-672b3186a233" - date = "2020-11-13" - modified = "2020-11-13" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Badbeeteam.yara#L1-L137" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "9b5367655c7c70958332d31524833d96d03027aab693393b19f478a80482abd0" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "ae9d0fa6-be06-4656-9b13-8edfc0ee9e71" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1522-L1539" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "8da5b14b95d96de5ced8bcab98e23973e449c1b5ca101f39a2114bb8e74fd9a5" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Badbeeteam" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files_p1 = { - 8B FF 55 8B EC 51 8B 4D ?? 8D 51 ?? 8A 01 41 84 C0 75 ?? 57 8B 7D ?? 2B CA 8B C7 41 - F7 D0 89 4D ?? 3B C8 76 ?? 6A ?? 58 5F C9 C3 53 56 8D 5F ?? 03 D9 6A ?? 53 E8 ?? ?? - ?? ?? 8B F0 59 59 85 FF 74 ?? 57 FF 75 ?? 53 56 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? - FF 75 ?? 2B DF 8D 04 3E FF 75 ?? 53 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 5D ?? - 8B CB E8 ?? ?? ?? ?? 33 FF 89 45 ?? 85 C0 74 ?? 56 E8 ?? ?? ?? ?? 8B 75 ?? 59 EB ?? - 8B 43 ?? 89 30 8B F7 83 43 ?? ?? 57 E8 ?? ?? ?? ?? 59 8B C6 5E 5B EB ?? 33 FF 57 57 - 57 57 57 E8 ?? ?? ?? ?? CC 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 - 45 ?? 8B 4D ?? 8B 55 ?? 53 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C ?? 74 - ?? 3C ?? 74 ?? 3C ?? 74 ?? 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 ?? ?? - ?? ?? 8A 01 88 85 ?? ?? ?? ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 57 E8 - ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? 74 ?? - 3C ?? 8A C3 75 ?? B0 ?? 2B CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D - } - $find_files_p2 = { - 56 1B C0 89 9D ?? ?? ?? ?? 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? - ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 8D ?? ?? ?? ?? F7 D8 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? - ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B - D8 E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D - ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? - 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 - ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? - 75 ?? 8A 48 ?? 84 C9 74 ?? 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? - ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? - ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 - C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 - ?? EB ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? - 59 8B D8 56 FF 15 ?? ?? ?? ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 59 8B C3 8B 4D ?? 5F 33 CD 5B E8 ?? ?? ?? ?? C9 C3 - } - $encrypt_files_p1 = { - 59 6A ?? 68 ?? ?? ?? ?? 52 50 E8 ?? ?? ?? ?? 89 F1 83 C4 ?? 84 C0 0F 85 ?? ?? ?? ?? - 51 E8 ?? ?? ?? ?? 59 B9 ?? ?? ?? ?? 89 D6 6A ?? 5A 56 50 E8 ?? ?? ?? ?? 8D 8C 24 ?? - ?? ?? ?? 83 C4 ?? 84 C0 0F 85 ?? ?? ?? ?? FF 04 24 51 57 E8 ?? ?? ?? ?? 58 59 8D 8C - 24 ?? ?? ?? ?? 8D 54 24 ?? 57 E8 ?? ?? ?? ?? 58 83 BC 24 ?? ?? ?? ?? ?? 0F 84 ?? ?? - ?? ?? 8B 84 24 ?? ?? ?? ?? F2 0F 10 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? A1 ?? ?? - ?? ?? F2 0F 11 84 24 ?? ?? ?? ?? 8B 00 83 F8 ?? 72 ?? 8D 84 24 ?? ?? ?? ?? C7 84 24 - ?? ?? ?? ?? ?? ?? ?? ?? 8D 4C 24 ?? 89 44 24 ?? 31 C0 C7 44 24 ?? ?? ?? ?? ?? 40 89 - 84 24 ?? ?? ?? ?? 83 A4 24 ?? ?? ?? ?? ?? 89 8C 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 57 E8 - ?? ?? ?? ?? 59 89 D6 B9 ?? ?? ?? ?? 6A ?? 5A 56 50 E8 ?? ?? ?? ?? 59 5A 89 F9 89 C3 - E8 ?? ?? ?? ?? 84 DB 0F 85 ?? ?? ?? ?? 6A ?? 59 8D 7C 24 ?? 8D B4 24 ?? ?? ?? ?? F3 - A5 6A ?? 59 8D BC 24 ?? ?? ?? ?? 8D 74 24 ?? 31 C0 F3 A5 E9 ?? ?? ?? ?? 8B 84 24 ?? - ?? ?? ?? 85 C0 74 ?? 8B 8C 24 ?? ?? ?? ?? 50 FF 11 83 C4 ?? 8B 84 24 ?? ?? ?? ?? 8B - 70 ?? 8B 78 ?? FF B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 89 C1 89 F2 57 E8 ?? ?? ?? ?? - 58 8D 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 9C 24 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 69 - } - $encrypt_files_p2 = { - 7B ?? ?? ?? ?? ?? 89 C6 83 C6 ?? 85 FF 74 ?? 83 7E ?? ?? 74 ?? 8D 46 ?? 50 E8 ?? ?? - ?? ?? 58 81 C6 ?? ?? ?? ?? 81 C7 ?? ?? ?? ?? EB ?? 83 7E ?? ?? 74 ?? 83 3E ?? 74 ?? - 8D 4E ?? E8 ?? ?? ?? ?? EB ?? 8D 46 ?? 50 E8 ?? ?? ?? ?? 58 8B 06 F0 FF 08 75 ?? 56 - E8 ?? ?? ?? ?? EB ?? 53 8D 44 24 ?? 50 E8 ?? ?? ?? ?? 58 59 8B 4C 24 ?? 85 C9 74 ?? - 8B 54 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 58 8D 9C 24 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 59 - 6B 5B ?? ?? 89 C7 89 C6 83 C7 ?? 85 DB 74 ?? 8D 4E ?? E8 ?? ?? ?? ?? 83 7E ?? ?? 74 - ?? 57 E8 ?? ?? ?? ?? 58 83 3F ?? 74 ?? 8D 47 ?? EB ?? 8D 46 ?? 50 E8 ?? ?? ?? ?? 58 - 83 C6 ?? 83 C7 ?? 83 C3 ?? EB ?? 8D 84 24 ?? ?? ?? ?? 50 8D 5C 24 ?? 53 E8 ?? ?? ?? - ?? 58 59 8B 4C 24 ?? 85 C9 74 ?? 8B 54 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 58 8D B4 24 - ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 6B 7E ?? ?? 89 C1 85 FF 74 ?? 8D 59 ?? 83 C1 ?? E8 - ?? ?? ?? ?? 89 D9 83 C7 ?? 8D 5C 24 ?? EB ?? 56 53 E8 ?? ?? ?? ?? 58 59 8B 4C 24 ?? - 85 C9 74 ?? 8B 54 24 ?? FF 74 24 ?? E8 ?? ?? ?? ?? 58 A1 ?? ?? ?? ?? 8B 00 83 F8 ?? - 72 ?? 89 E0 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 89 C6 89 D7 68 ?? ?? ?? ?? 8D 44 - 24 ?? 50 E8 ?? ?? ?? ?? 59 59 89 B4 24 ?? ?? ?? ?? 89 BC 24 ?? ?? ?? ?? 89 84 24 ?? - ?? ?? ?? 89 94 24 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 6A ?? 58 89 44 24 ?? 83 64 24 - ?? ?? 8D 8C 24 ?? ?? ?? ?? 89 4C 24 ?? 89 44 24 ?? 68 ?? ?? ?? ?? 6A ?? 53 E8 ?? ?? - ?? ?? 83 C4 ?? 8D 4C 24 ?? E8 ?? ?? ?? ?? 8B 7D ?? 8B 77 ?? 83 C7 ?? 8D 4E ?? E8 ?? - ?? ?? ?? C7 46 ?? ?? ?? ?? ?? 83 66 ?? ?? 89 F9 E8 ?? ?? ?? ?? 8D 65 ?? 5E 5F 5B 5D - C3 - } - $drop_hta_file_p1 = { - 6A ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? ?? ?? ?? 59 89 D3 89 F9 89 - C2 53 E8 ?? ?? ?? ?? 58 8D B4 24 ?? ?? ?? ?? 89 F1 E8 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? - ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 57 E8 ?? ?? ?? ?? 58 31 DB 43 53 57 E8 ?? ?? ?? ?? 59 - 5A 53 89 DF 50 E8 ?? ?? ?? ?? 59 5A 8D 5C 24 ?? 89 C2 89 D9 56 E8 ?? ?? ?? ?? 58 39 - 3B 0F 85 ?? ?? ?? ?? F2 0F 10 44 24 ?? A1 ?? ?? ?? ?? 8D 74 24 ?? 8D BC 24 ?? ?? ?? - ?? F2 0F 11 44 24 ?? 8B 00 83 F8 ?? 72 ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 59 59 89 - 84 24 ?? ?? ?? ?? 31 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 89 94 24 ?? ?? ?? ?? 40 89 - 84 24 ?? ?? ?? ?? 83 A4 24 ?? ?? ?? ?? ?? 89 BC 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? - 68 ?? ?? ?? ?? 6A ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 56 E8 ?? ?? ?? - ?? EB ?? 8B 44 24 ?? 89 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? - 8D BC 24 ?? ?? ?? ?? 57 8D B4 24 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? 89 F1 E8 ?? - ?? ?? ?? 57 E8 ?? ?? ?? ?? 58 6A ?? 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 6A - } - $drop_hta_file_p2 = { - 68 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D B4 24 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 58 - 31 DB 43 53 56 E8 ?? ?? ?? ?? 59 5A 53 50 E8 ?? ?? ?? ?? 59 5A 8D 74 24 ?? 89 C2 89 - F1 57 E8 ?? ?? ?? ?? 58 39 1E 0F 85 ?? ?? ?? ?? F2 0F 10 44 24 ?? A1 ?? ?? ?? ?? 8D - 74 24 ?? F2 0F 11 84 24 ?? ?? ?? ?? 8B 00 83 F8 ?? 72 ?? 68 ?? ?? ?? ?? 8D 84 24 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 59 59 89 44 24 ?? 31 C0 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? - 89 54 24 ?? 40 89 84 24 ?? ?? ?? ?? 83 A4 24 ?? ?? ?? ?? ?? 89 B4 24 ?? ?? ?? ?? 89 - 84 24 ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 8D 84 24 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? EB ?? 8B 44 24 ?? 89 44 24 ?? 68 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 8D 74 24 ?? 56 8D 9C 24 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? - 83 C4 ?? 89 D9 E8 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 58 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 - 8D BC 24 ?? ?? ?? ?? 89 C3 89 84 24 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 F9 6A ?? E8 ?? ?? - ?? ?? 58 83 64 24 ?? ?? 83 64 24 ?? ?? 57 E8 ?? ?? ?? ?? 59 8D 4C 24 ?? 51 56 6A ?? - 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 50 53 E8 - } + $a = { 83 EC 04 8A 44 24 18 8B 5C 24 14 88 44 24 03 8A 44 24 10 25 FF 00 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) and ( all of ($drop_hta_file_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Sifrelendi : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_612B407C : FILE MEMORY { meta: - description = "Yara rule that detects Sifrelendi ransomware." - author = "ReversingLabs" - id = "b9083b7c-eb09-52da-a240-39b51df892f9" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Sifrelendi.yara#L1-L67" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "430d3877c10c86fcb19b5624dd8886d61e54ccd0453678329309b49712c6d5c6" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "612b407c-fceb-4a19-8905-2f5b822f62cc" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1541-L1559" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "7833bc89778461a9f46cc47a78c67dda48b498ee40b09a80a21e67cb70c6add1" + logic_hash = "6514725a32f7c28be7de5ff6fe1363df7c50e2cd6c8c79824ec4cbeadda2ca31" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Sifrelendi" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "c48c26b1052ef832d4d6a106db186bf20c503bdf38392a1661eb2d3c3ec010cd" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $search_files = { - E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 8D 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 7E ?? 8D 85 ?? ?? ?? - ?? 8B 8D ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5A 59 59 64 89 10 68 - ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 8D 85 ?? ?? ?? - ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? BA ?? - ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 - 89 20 F6 85 ?? ?? ?? ?? ?? 74 ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 - ?? 8B 85 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 74 ?? 8D 85 ?? ?? ?? ?? 8B 8D ?? - ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4D ?? 8B 55 ?? E8 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? - 8D 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 33 C0 5A 59 59 64 89 10 EB - ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8D 45 ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 8B E5 5D - C3 - } - $encrypt_files = { - 55 8B EC 83 C4 ?? 53 56 57 33 DB 89 5D ?? 89 4D ?? 89 55 ?? 89 45 ?? 8B 45 ?? E8 ?? - ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 33 C0 55 68 ?? ?? ?? ?? 64 - FF 30 64 89 20 33 C0 55 68 ?? ?? ?? ?? 64 FF 30 64 89 20 B2 ?? A1 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 89 45 ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 45 ?? 33 C9 B2 ?? A1 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B F8 8B 0D ?? ?? ?? ?? 8B 55 ?? 8B C7 E8 ?? ?? ?? ?? 33 C9 B2 - ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B F0 8B 0D ?? ?? ?? ?? 8B 55 ?? 8B C6 E8 ?? ?? ?? - ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? B2 ?? A1 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 8B 45 - ?? 8B 10 FF 12 50 8B CB 8B 55 ?? 8B C6 E8 ?? ?? ?? ?? 8B C6 8B 10 FF 52 ?? 6A ?? 6A - ?? 8B C3 E8 ?? ?? ?? ?? 8B C3 8B 10 FF 12 50 8B 4D ?? 8B D3 8B C7 E8 ?? ?? ?? ?? 8B - C7 8B 10 FF 52 ?? 8B 55 ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 8B 45 ?? - E8 ?? ?? ?? ?? 8B C3 E8 ?? ?? ?? ?? 8B C6 E8 ?? ?? ?? ?? 8B C7 E8 ?? ?? ?? ?? 8D 45 - ?? B9 ?? ?? ?? ?? 8B 55 ?? E8 ?? ?? ?? ?? 8B 45 ?? E8 ?? ?? ?? ?? 50 8B 45 ?? E8 ?? - ?? ?? ?? 50 E8 ?? ?? ?? ?? 33 C0 5A 59 59 64 89 10 EB ?? E9 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 33 C0 5A 59 59 64 89 10 68 ?? ?? ?? ?? 8D 45 ?? E8 ?? ?? ?? ?? 8D 45 ?? BA ?? ?? - ?? ?? E8 ?? ?? ?? ?? C3 E9 ?? ?? ?? ?? EB ?? 5F 5E 5B 8B E5 5D C3 - } + $a = { 11 B2 73 45 2B 7A 57 E2 F9 77 A2 23 EC 7C 0C 29 FE 3F B2 DE 28 6C } condition: - uint16(0)==0x5A4D and ($search_files) and ($encrypt_files) + all of them } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Mcburglar : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_D5Da717F : FILE MEMORY { meta: - description = "Yara rule that detects McBurglar ransomware." - author = "ReversingLabs" - id = "11816401-87c3-5aff-b161-da0fa4eb4bca" - date = "2021-09-27" - modified = "2021-09-27" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.McBurglar.yara#L1-L75" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "57fefcdc1528fc1c8da36a431cd09774e33ea08a394ac4f8d19a27504e72676d" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "d5da717f-3344-41a8-884e-8944172ea370" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1561-L1579" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "1f6bcdfc7d1c56228897cd7548266bb0b9a41b913be354036816643ac21b6f66" + logic_hash = "034dae5bea7536e8c8aa22b8b891b9c991b94f04be12c9fe6d78ddf07a2365d9" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "McBurglar" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "c3674075a435ef1cd9e568486daa2960450aa7ffa8e5dbf440a50e01803ea2f3" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $setup_env = { - 00 7E ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 7E ?? ?? ?? - ?? 1B 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? - ?? 00 7E ?? ?? ?? ?? 1F ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 28 ?? ?? ?? ?? 00 28 ?? ?? - ?? ?? 00 2A - } - $encrypt_files_p1 = { - 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0A 2B ?? 73 ?? ?? ?? ?? 0B 07 12 ?? 28 ?? ?? ?? ?? - 7D ?? ?? ?? ?? 00 07 FE 06 ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 - 00 12 ?? 28 ?? ?? ?? ?? 2D ?? DE ?? 12 ?? FE 16 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DC 2A - } - $encrypt_files_p2 = { - 00 28 ?? ?? ?? ?? 0A 02 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 18 73 ?? ?? ?? ?? 0B 73 ?? ?? ?? - ?? 0C 28 ?? ?? ?? ?? 03 6F ?? ?? ?? ?? 0D 73 ?? ?? ?? ?? 13 ?? 11 ?? 20 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 00 11 ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 11 ?? 18 6F ?? ?? ?? ?? 00 09 06 - 20 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? - ?? 6F ?? ?? ?? ?? 00 11 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 1E 5B 6F ?? ?? ?? ?? 6F ?? ?? ?? - ?? 00 11 ?? 1A 6F ?? ?? ?? ?? 00 07 06 16 06 8E 69 6F ?? ?? ?? ?? 00 07 11 ?? 6F ?? ?? - ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 02 19 73 ?? ?? ?? ?? 13 ?? 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? - 13 ?? 00 2B ?? 00 11 ?? 11 ?? 16 11 ?? 6F ?? ?? ?? ?? 00 00 11 ?? 11 ?? 16 11 ?? 8E 69 - 6F ?? ?? ?? ?? 25 13 ?? 16 FE 02 13 ?? 11 ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 00 00 DE ?? 13 - ?? 00 72 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 00 DE ?? DE - ?? 00 11 ?? 6F ?? ?? ?? ?? 00 07 6F ?? ?? ?? ?? 00 00 DC 2A - } - $find_files = { - 00 00 02 28 ?? ?? ?? ?? 0A 00 06 0C 16 0D 2B ?? 08 09 9A 13 ?? 00 11 ?? 28 ?? ?? ?? ?? - 00 00 09 17 58 0D 09 08 8E 69 32 ?? 02 28 ?? ?? ?? ?? 0B 00 07 13 ?? 16 13 ?? 2B ?? 11 - ?? 11 ?? 9A 13 ?? 00 11 ?? 28 ?? ?? ?? ?? 00 00 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 32 - ?? 00 DE ?? 26 00 00 DE ?? 2A - } - $generate_salt = { - 00 1F ?? 8D ?? ?? ?? ?? 0A 73 ?? ?? ?? ?? 0B 00 16 0C 2B ?? 00 07 06 6F ?? ?? ?? ?? 00 - 00 08 17 58 0C 08 1F ?? FE 04 0D 09 2D ?? 00 DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? 00 DC 06 - 13 ?? 2B ?? 11 ?? 2A - } + $a = { 00 00 66 83 7C 24 34 FF 66 89 46 2C 0F 85 C2 } condition: - uint16(0)==0x5A4D and ($setup_env) and ($find_files) and ($generate_salt) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Meow : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_D33095D4 : FILE MEMORY { meta: - description = "Yara rule that detects Meow ransomware." - author = "ReversingLabs" - id = "7cebb04d-1cda-5ad1-b412-8b38df7b2550" - date = "2022-10-24" - modified = "2022-10-24" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Meow.yara#L1-L84" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "b00753d2b150a815279297ddf40d70051d25de1c32bb90f5b706ea7fd36bb871" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "d33095d4-ea02-4588-9852-7493f6781bb4" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1581-L1599" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "72326a3a9160e9481dd6fc87159f7ebf8a358f52bf0c17fbc3df80217d032635" + logic_hash = "b7feaec65d72907d08c98b09fb4ac494ceee7d7bd51c09063363c617e3f057a4" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Meow" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "20c0faab6aef6e0f15fd34f9bd173547f3195c096eb34c4316144b19d2ab1dc4" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files_p1 = { - 72 ?? 8D 45 ?? BA ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 68 ?? ?? ?? ?? 57 FF D0 85 C0 75 ?? 33 F6 6A ?? 68 ?? ?? ?? ?? BA ?? ?? ?? - ?? E8 ?? ?? ?? ?? 83 C4 ?? FF B4 B5 ?? ?? ?? ?? 57 FF D0 85 C0 75 ?? 46 83 FE ?? 7C - ?? 5F 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C3 5F 5E 33 C0 5B 8B E5 5D C3 CC 55 8B EC 83 EC - ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 56 57 C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? - ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? - ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? - ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? C6 45 ?? ?? 8A 45 ?? 80 7D ?? ?? - 75 - } - $encrypt_files_p2 = { - 8B 45 ?? 40 89 45 ?? 8B 45 ?? 99 F7 F9 85 D2 74 ?? E9 ?? ?? ?? ?? 8B 45 ?? 25 ?? ?? - ?? ?? 79 ?? 48 83 C8 ?? 83 C0 ?? 74 ?? 8B 4D ?? 8D 46 ?? 03 CF 0F AF C8 89 4D ?? 8B - 45 ?? 25 ?? ?? ?? ?? 79 ?? 48 83 C8 ?? 83 C0 ?? 75 ?? B9 ?? ?? ?? ?? 90 8B 45 ?? 99 - F7 F9 8B 45 ?? 85 D2 74 ?? 48 EB ?? 40 89 45 ?? 8B 45 ?? 25 ?? ?? ?? ?? 79 ?? 48 83 - C8 ?? 83 C0 ?? 74 ?? EB ?? 8B 45 ?? B9 ?? ?? ?? ?? 99 F7 F9 85 D2 74 ?? 8B 45 ?? 8D - 4E ?? 83 C0 ?? 99 F7 F9 B9 ?? ?? ?? ?? 89 45 ?? 8B 45 ?? 99 F7 F9 85 D2 75 ?? 8B 45 - ?? 99 F7 7D ?? 8B 45 ?? 85 D2 74 ?? 40 EB ?? 48 89 45 ?? 8B 45 ?? 99 F7 F9 85 D2 74 - ?? 6A ?? 68 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 56 FF - D0 C7 45 ?? ?? ?? ?? ?? B9 ?? ?? ?? ?? 8B 45 ?? 99 F7 F9 8B 45 ?? 85 D2 74 ?? 83 C0 - ?? 03 C3 89 45 ?? 8B 45 ?? 25 ?? ?? ?? ?? 79 ?? 48 83 C8 ?? 83 C0 ?? 0F 85 - } - $drop_ransom_note = { - 66 8B 01 83 C1 ?? 66 85 C0 75 ?? 2B CA D1 F9 51 53 B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 - FF 74 ?? 8B CF E8 ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 85 F6 74 ?? 6A - ?? 68 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? FF D0 6A ?? - 68 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A - ?? 6A ?? 68 ?? ?? ?? ?? 56 FF D0 8B F0 BA ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 89 35 ?? - ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 6A ?? 6A ?? 56 FF D0 B9 ?? ?? ?? ?? 8D BD ?? - ?? ?? ?? BE ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? F3 A5 68 ?? ?? ?? ?? 6A ?? 50 66 A5 A4 E8 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 ?? 33 CD B8 ?? - ?? ?? ?? 5F 5B 5E E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $find_files = { - 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 ?? FF - B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? ?? ?? - ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 - 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? ?? ?? - 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 - C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 ?? 8A 48 ?? 84 C9 74 ?? 80 F9 - ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? ?? 83 - C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? E8 ?? - ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 85 - ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? ?? ?? - ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? 74 ?? - FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 8B D8 56 FF 15 - } + $a = { 00 00 66 83 7C 24 54 FF 66 89 46 04 0F 85 CB } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_4E2246Fb : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "4e2246fb-5f9a-4dea-8041-51758920d0b9" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1601-L1619" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "1f6bcdfc7d1c56228897cd7548266bb0b9a41b913be354036816643ac21b6f66" + logic_hash = "6d2e1300286751a5e1ae683e9aab2f59bfbb20d1cc18dcce89c06ecadf25a3e6" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "23b0cfabc2db26153c02a7dc81e2006b28bfc9667526185b2071b34d2fb073c4" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 00 00 B8 01 00 00 00 31 DB CD 80 EB FA 8D 8B 10 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_D5981806 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "d5981806-0db8-4422-ad57-5d1c0f7464c3" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1621-L1639" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "784f2005853b5375efaf3995208e4611b81b8c52f67b6dc139fd9fec7b49d9dc" + logic_hash = "e625323543aa5c8374a179dfa51c3f5be1446459c45fa7c7a27ae383cf0f551b" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "b0fd8632505252315ba551bb3680fa8dc51038be17609018bf9d92c3e1c43ede" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { 3F 00 00 66 83 7C 24 38 FF 66 89 46 04 0F 85 EA } condition: - uint16(0)==0x5A4D and ($find_files) and ( all of ($encrypt_files_p*)) and ($drop_ransom_note) + all of them } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Ghostbin : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_C6055Dc9 : FILE MEMORY { meta: - description = "Yara rule that detects Ghostbin ransomware." - author = "ReversingLabs" - id = "4d576854-7a30-527d-9a7a-f22018183540" - date = "2021-09-06" - modified = "2021-09-06" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.Ghostbin.yara#L1-L61" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3881e1c83ac2a31fdd8a081d3e6e6ea759771dbc183c3af9528930619bcddf9e" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "c6055dc9-316b-478d-9997-1dbf455cafcc" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1641-L1659" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c1718d7fdeef886caa33951e75cbd9139467fa1724605fdf76c8cdb1ec20e024" + logic_hash = "4d9d7c44f0d3ae60275720ae5faf3c25c368aa6e7d9ab5ed706a30f9a7ffd3b8" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Ghostbin" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "b95f582edf2504089ddd29ef1a0daf30644b364f3d90ede413a2aa777c205070" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $setup_env = { - 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 16 0B 2B ?? 06 07 9A 0C - 08 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 18 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 - 28 ?? ?? ?? ?? 2C ?? 08 6F ?? ?? ?? ?? 19 FE 01 08 6F ?? ?? ?? ?? 18 FE 01 60 2C ?? 08 - 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 07 17 D6 0B 07 06 8E 69 32 ?? 00 72 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 2C ?? 16 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? - ?? DE ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 00 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 72 - ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 1F ?? 16 28 ?? ?? ?? ?? 26 DE ?? 28 ?? ?? ?? ?? 28 ?? ?? - ?? ?? DE ?? 2A - } - $encrypt_files = { - 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0A 25 6F ?? ?? ?? ?? 25 06 28 ?? ?? ?? ?? 03 6F ?? ?? ?? - ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 17 6F ?? ?? ?? ?? 25 6F ?? ?? ?? ?? 0C 6F ?? ?? ?? - ?? 02 16 02 8E 69 6F ?? ?? ?? ?? 0B 07 8E 69 17 59 1F ?? 58 17 58 8D ?? ?? ?? ?? 0D 08 - 09 1F ?? 28 ?? ?? ?? ?? 07 16 09 1F ?? 07 8E 69 28 ?? ?? ?? ?? 09 2A - } - $find_files = { - 02 17 8D ?? ?? ?? ?? 25 16 1F ?? 9D 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 6F ?? ?? ?? ?? 28 - ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? 0A 16 0B - 2B ?? 06 07 9A 0C 7E ?? ?? ?? ?? 08 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 08 28 ?? ?? ?? - ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2D ?? 08 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 08 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 28 ?? - ?? ?? ?? 08 28 ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 0D 28 ?? ?? ?? ?? DE ?? 07 17 D6 0B - 07 06 8E 69 32 ?? 02 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 28 ?? ?? ?? ?? - 11 ?? 17 D6 13 ?? 11 ?? 11 ?? 8E 69 32 ?? DE ?? 25 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? - DE ?? 2A - } + $a = { 83 7F 43 80 77 39 CF 7E 09 83 C8 FF 5A 5D 8A 0E } condition: - uint16(0)==0x5A4D and ($setup_env) and ($find_files) and ($encrypt_files) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Farattack : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_3B9675Fd : FILE MEMORY { meta: - description = "Yara rule that detects FarAttack ransomware." - author = "ReversingLabs" - id = "7ee7121a-4ca2-513c-96dc-53b5c48d719f" - date = "2022-06-21" - modified = "2022-06-21" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.FarAttack.yara#L1-L93" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "af22b8110c2b545f083b443c7a1fa7e7639324e9188eefadfe1fe70ebb1bb7fb" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "3b9675fd-1fa1-4e15-9472-64cb93315d63" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1661-L1679" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "4ec4bc88156bd51451fdaf0550c21c799c6adacbfc654c8ec634ebca3383bd66" + logic_hash = "61ff7cb8d664291de5cf0c82b80cf0f4001c41d3f02b7f4762f67eb8128df15d" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "FarAttack" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "40a154bafa72c5aa0c085ac2b92b5777d1acecfd28d28b15c7229ba5c59435f2" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files = { - 56 FF 73 ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 50 FF 15 ?? ?? ?? ?? 56 E8 ?? - ?? ?? ?? 59 6A ?? 58 E9 ?? ?? ?? ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 89 45 ?? 03 C7 89 - 45 ?? 3D ?? ?? ?? ?? 0F 8D ?? ?? ?? ?? F7 06 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 8D 4E ?? - 51 68 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 83 F8 ?? 0F 84 ?? ?? ?? ?? F6 06 ?? 74 ?? 8B 45 ?? 8D 04 45 ?? ?? ?? ?? 50 8D 46 ?? - 50 8B 43 ?? 8D 04 78 83 C0 ?? 50 E8 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 83 C4 ?? 8B 53 ?? - 8B 75 ?? 8B 01 53 89 44 72 ?? 66 8B 41 ?? 8B CE 66 89 44 4A ?? FF 43 ?? 83 63 ?? ?? - E8 ?? ?? ?? ?? FF 4B ?? 83 63 ?? ?? 8B 75 ?? E9 ?? ?? ?? ?? 83 7B ?? ?? 75 ?? FF 73 - ?? FF 73 ?? FF 73 ?? FF 73 ?? 57 FF 73 ?? E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? C7 43 - ?? ?? ?? ?? ?? 8D 46 ?? 50 FF 15 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A ?? FF 35 ?? ?? ?? - ?? FF 35 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 8D - 04 45 ?? ?? ?? ?? 50 8D 46 ?? 50 8B 43 ?? 8D 04 78 83 C0 ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 83 7E ?? ?? 75 ?? 83 7E ?? ?? 74 ?? 6A ?? E8 ?? ?? ?? ?? 8B F8 8B 45 ?? 8D 34 00 - 8D 4E ?? 51 E8 ?? ?? ?? ?? 56 89 07 FF 73 ?? 50 E8 ?? ?? ?? ?? 8B 07 33 C9 83 C4 ?? - 66 89 0C 06 8B 75 ?? 51 57 51 8B 46 ?? 89 47 ?? 8B 46 ?? 89 47 ?? 8B 45 ?? 89 47 ?? - FF 73 ?? FF 15 ?? ?? ?? ?? 8B 7D ?? 8B 4B ?? A1 ?? ?? ?? ?? 89 44 79 ?? 66 A1 ?? ?? - ?? ?? 66 89 44 79 ?? 56 FF 75 ?? FF 15 - } - $create_key = { - 55 8B EC 56 6A ?? E8 ?? ?? ?? ?? 8B F0 59 85 F6 75 ?? 32 C0 EB ?? A1 ?? ?? ?? ?? 53 - 33 DB 85 C0 74 ?? 53 6A ?? 53 53 56 FF D0 EB ?? 8A C3 84 C0 75 ?? FF 15 ?? ?? ?? ?? - 3D ?? ?? ?? ?? 75 ?? A1 ?? ?? ?? ?? 85 C0 74 ?? 6A ?? 6A ?? 53 53 56 FF D0 8A D8 84 - DB 75 ?? 56 E8 ?? ?? ?? ?? 59 32 C0 EB ?? 8B 4D ?? B0 ?? 89 71 ?? 5B 5E 5D C3 - } - $encrypt_files_p1 = { - 50 68 ?? ?? ?? ?? 6A ?? 50 50 68 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 8B F8 89 7D ?? 83 - FF ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 0B 45 ?? 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 48 ?? 8B 40 - ?? 83 C1 ?? 03 C1 8B 5D ?? 89 5D ?? 8B 4D ?? 89 4D ?? 99 03 D8 89 5D ?? 13 CA 89 4D - ?? 8B 55 ?? 8B 45 ?? 85 D2 7C ?? 7F ?? 3D ?? ?? ?? ?? 76 ?? 89 75 ?? EB ?? 83 65 ?? - ?? 85 D2 7C ?? 7F ?? 3D ?? ?? ?? ?? 76 ?? 89 75 ?? EB ?? 83 65 ?? ?? C7 45 ?? ?? ?? - ?? ?? 83 7D ?? ?? 74 ?? 6A ?? 6A ?? 52 50 E8 ?? ?? ?? ?? 6A ?? 6A ?? 59 89 4D ?? 51 - 52 50 E8 ?? ?? ?? ?? 89 45 ?? 89 55 ?? 8B 4D ?? 6A ?? 53 51 6A ?? 6A ?? 57 FF 15 ?? - ?? ?? ?? 8B D8 89 5D ?? 85 DB 0F 84 ?? ?? ?? ?? 83 FB ?? 0F 84 ?? ?? ?? ?? B8 ?? ?? - ?? ?? 89 45 ?? 89 45 ?? 33 C9 8B C1 89 45 ?? 89 45 ?? 89 4D ?? 89 4D ?? 89 45 ?? 89 - 45 ?? 89 4D ?? 8B 4D ?? FF 71 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? - 84 C0 0F 85 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 4D ?? FF 71 ?? FF 71 ?? 8D 41 ?? 50 - FF 71 ?? 6A ?? 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8B 45 ?? 8B 55 ?? 85 C0 - } - $encrypt_files_p2 = { - 75 ?? 89 55 ?? 21 45 ?? 8B CE 89 4D ?? 89 4D ?? EB ?? 8B 4D ?? 3B 4D ?? 0F 8D ?? ?? - ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 85 C9 74 ?? 83 7D ?? ?? 74 ?? 8D 41 ?? 3B 45 ?? 74 ?? - 8B C1 99 FF 75 ?? FF 75 ?? 52 50 E8 ?? ?? ?? ?? 8B C8 89 45 ?? C7 45 ?? ?? ?? ?? ?? - EB ?? 8B CA 81 E9 ?? ?? ?? ?? 89 4D ?? 8B 55 ?? 83 DA ?? 83 65 ?? ?? 89 55 ?? 6A ?? - 8B 45 ?? FF 70 ?? 52 51 E8 ?? ?? ?? ?? 6A ?? 8B 4D ?? FF 71 ?? 52 50 E8 ?? ?? ?? ?? - 8B C8 89 4D ?? 89 55 ?? 8B 45 ?? 2B C1 89 45 ?? 8B 4D ?? 1B CA 89 45 ?? 89 4D ?? EB - ?? 8B 55 ?? 8B C2 C1 F8 ?? FF 75 ?? FF 75 ?? 52 68 ?? ?? ?? ?? 53 FF 15 ?? ?? ?? ?? - 89 45 ?? 85 C0 75 ?? 50 FF 75 ?? FF 75 ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 57 FF 15 ?? ?? - ?? ?? 8B 75 ?? 8B 7D ?? 83 4D ?? ?? E8 ?? ?? ?? ?? FF 75 ?? FF 15 ?? ?? ?? ?? 8B 45 - ?? E8 ?? ?? ?? ?? C3 03 45 ?? 56 6A ?? 8D 4D ?? 51 50 FF 75 ?? 50 6A ?? 6A ?? 8D 85 - ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 45 ?? 40 - 89 45 ?? 3B 45 ?? 75 ?? 8B 75 ?? FF 76 ?? FF 76 ?? 8B 45 ?? 03 45 ?? 03 45 ?? 50 E8 - ?? ?? ?? ?? FF 76 ?? FF 76 ?? 8B 46 ?? 03 45 ?? 03 45 ?? 03 45 ?? 50 E8 ?? ?? ?? ?? - 83 C4 ?? 8B 7E ?? 03 7E ?? 03 7D ?? 03 7D ?? 8B 45 ?? 03 F8 8D 75 ?? A5 A5 A5 A5 6A - ?? 50 FF 15 ?? ?? ?? ?? 8B 7D ?? 33 F6 46 FF 75 ?? FF 15 ?? ?? ?? ?? 8B 4D ?? 89 4D - ?? 8B 55 ?? 8B 45 ?? E9 ?? ?? ?? ?? 53 8B 35 ?? ?? ?? ?? FF D6 - } + $a = { 78 10 85 C9 75 65 48 8B 8C 24 A0 00 00 00 48 89 48 10 0F B6 4C } condition: - uint16(0)==0x5A4D and ($find_files) and ($create_key) and ( all of ($encrypt_files_p*)) + all of them } -rule REVERSINGLABS_Win32_Ransomware_Good : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_1C0D246D : FILE MEMORY { meta: - description = "Yara rule that detects Good ransomware." - author = "ReversingLabs" - id = "e0f97200-7fe9-5811-b6cd-708ecc3a2fbc" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.Good.yara#L1-L82" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6737853a77a6008f9fd2141bb6b13d595f1cb7e832be944596f709e1fcdf8003" + description = "Based off community provided sample" + author = "Elastic Security" + id = "1c0d246d-dc23-48d6-accb-1e1db1eba49b" + date = "2021-04-13" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1681-L1700" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "211cfe9d158c8a6840a53f2d1db2bf94ae689946fffb791eed3acceef7f0e3dd" + logic_hash = "7a101e6d2265e09eb6c8d0f1a2fe54c9aa353dfd8bd156926937f4aec86c3ef1" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "Good" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "b6b6991e016419b1ddf22822ce76401370471f852866f0da25c7b0f4bec530ee" + threat_name = "Linux.Trojan.Mirai" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files = { - FF D7 53 85 C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C3 8D - 85 ?? ?? ?? ?? 50 FF D7 53 85 C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E - 5B 8B E5 5D C3 8D 85 ?? ?? ?? ?? 50 FF D7 53 85 C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C3 8D 85 ?? ?? ?? ?? 50 FF D7 53 85 C0 75 ?? 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C3 8D 85 ?? ?? ?? ?? 50 FF D7 53 85 - C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C3 8B 3D ?? ?? ?? - ?? 33 C0 66 89 45 ?? 8D 45 ?? 50 8D 85 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? 50 C7 45 ?? - ?? ?? ?? ?? FF D7 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? - ?? 8B D8 83 FB ?? 75 ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 5F 5E 5B 8B E5 5D C3 - } - $remote_connection = { - 55 8B EC 53 8B 5D ?? 57 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 7D ?? 83 C4 ?? 8B 0F 8B - C1 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 83 E8 ?? 74 ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 - C4 ?? EB ?? 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 83 C4 ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 4F ?? 83 C4 ?? 8B C1 83 E8 ?? 74 ?? 83 - E8 ?? 74 ?? 83 E8 ?? 74 ?? 51 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? - ?? ?? EB ?? 68 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 53 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 47 ?? 83 C4 ?? 83 F8 ?? 77 ?? FF 24 85 ?? ?? ?? ?? 68 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 - ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB - ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 - ?? EB ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? FF 77 ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 47 ?? 83 C4 ?? A8 ?? 74 ?? - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 47 ?? 83 C4 ?? A8 ?? 74 ?? 68 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 83 C4 ?? 83 7F ?? ?? 75 ?? 56 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 FF - 77 ?? FF 15 ?? ?? ?? ?? 8D 04 45 ?? ?? ?? ?? 50 FF 77 ?? 56 E8 ?? ?? ?? ?? 83 C4 ?? - 8D 45 ?? 50 6A ?? 56 68 ?? ?? ?? ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 5E FF 77 ?? 53 68 - ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 77 ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 77 ?? 53 68 - ?? ?? ?? ?? E8 ?? ?? ?? ?? FF 77 ?? 53 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5B - 5D C3 - } - $encrypt_files = { - 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 8B C8 8B F2 83 C4 ?? 2B CE 8D 71 ?? - 66 90 0F B7 0A 8D 52 ?? 66 89 4C 32 ?? 66 85 C9 75 ?? 50 FF 35 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 8B 35 ?? ?? ?? ?? 47 89 7D ?? E9 ?? ?? ?? ?? FF 75 ?? 8D 85 ?? ?? ?? ?? C7 - 45 ?? ?? ?? ?? ?? FF 75 ?? 50 E8 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 8B 35 ?? ?? ?? ?? 83 C4 ?? EB ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 8D 85 ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 - 8D 85 ?? ?? ?? ?? 50 FF 15 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? EB ?? 68 ?? ?? ?? ?? EB ?? - 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 50 53 - FF D6 8B 3D ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 74 ?? - 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 5D C3 53 - FF 15 ?? ?? ?? ?? 85 C0 75 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 5F 5E 5B 8B E5 - 5D C3 - } + $a = { E7 C0 00 51 78 0F 1B FF 8A 7C 18 27 83 2F 85 2E CB 14 50 2E } condition: - uint16(0)==0x5A4D and ($find_files) and ($encrypt_files) and ($remote_connection) + all of them } -rule REVERSINGLABS_Bytecode_MSIL_Ransomware_Wildfire : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Ad337D2F : FILE MEMORY { meta: - description = "Yara rule that detects WildFire ransomware." - author = "ReversingLabs" - id = "0c44f017-703c-5db7-b777-62fcd181af9a" - date = "2021-08-12" - modified = "2021-08-12" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/ByteCode.MSIL.Ransomware.WildFire.yara#L1-L77" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "d3be2eac7967853aae6e1317d9c22d95a3dc4b3e5bf8acbe97a7bbeabc9eab38" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "ad337d2f-d4ac-42a7-9d2e-576fe633fa16" + date = "2021-06-28" + modified = "2021-09-16" + reference = "012b717909a8b251ec1e0c284b3c795865a32a1f4b79706d2254a4eb289c30a7" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1702-L1720" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "dba630c1deb00b0dbd9f895a9b93393bc634150c8f32527b02d8dd71dc806e7d" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "WildFire" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "67cbcb8288fe319c3b8f961210748f7cea49c2f64fc2f1f55614d7ed97a86238" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $encrypt_files = { - 00 02 19 17 73 ?? ?? ?? ?? 0A 1B 8D ?? ?? ?? ?? 25 16 02 16 02 [5-10] 6F ?? ?? ?? ?? - 6F ?? ?? ?? ?? A2 25 17 [5-10] A2 25 18 7E ?? ?? ?? ?? A2 25 19 [5-10] A2 25 1A 02 02 - [5-10] 6F ?? ?? ?? ?? 17 D6 6F ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 0B 07 [5-10] 28 ?? ?? ?? - ?? 1A 18 73 ?? ?? ?? ?? 0C 08 21 00 00 00 00 00 00 00 00 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? - 8D ?? ?? ?? ?? 0D 21 00 00 00 00 00 00 00 00 13 ?? 06 6F ?? ?? ?? ?? 13 ?? 73 ?? ?? ?? - ?? 13 ?? 08 11 ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? - 2B ?? 06 09 16 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 09 16 11 ?? 6F ?? ?? ?? ?? 11 - ?? 11 ?? 6A D6 13 ?? 11 ?? 11 ?? FE ?? 2D ?? 11 ?? 6F ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 08 - 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 17 D6 80 ?? ?? ?? ?? 02 28 ?? ?? ?? ?? DE ?? 28 ?? ?? ?? - ?? 28 ?? ?? ?? ?? DE ?? 2A - } - $enum_drives = { - 00 00 28 ?? ?? ?? ?? 1F ?? 0A 18 0C 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F - ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 19 0C 28 ?? ?? ?? ?? 0D 1A - 0C 09 13 ?? 16 13 ?? 11 ?? 11 ?? 8E 69 FE ?? 2C ?? 11 ?? 11 ?? 9A 13 ?? 1B 0C 11 ?? - 6F ?? ?? ?? ?? 2C ?? 1C 0C 11 ?? 6F ?? ?? ?? ?? 19 FE ?? 16 FE ?? 65 18 60 1A 60 11 - ?? 6F ?? ?? ?? ?? 21 ?? ?? ?? ?? ?? ?? ?? ?? FE ?? 16 FE ?? 65 5F 16 FE ?? 2C ?? 1D - 0C 11 ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 1E 0C 11 ?? 6F ?? ?? ?? ?? - 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 1F ?? 0C 11 ?? 17 D6 13 ?? 2B - } - $file_search = { - A2 25 20 ?? ?? ?? ?? [5-10] A2 25 20 ?? ?? ?? ?? [5-10] A2 25 20 ?? ?? ?? ?? [5-10] - A2 25 20 ?? ?? ?? ?? [5-10] A2 25 20 ?? ?? ?? ?? [5-10] A2 0D 19 0C 19 8D ?? ?? ?? ?? - 25 16 [5-10] A2 25 17 [5-10] A2 25 18 [5-10] A2 13 04 1A 0C 02 28 ?? ?? ?? ?? 13 ?? 1B - 0C 11 ?? 8E 69 17 DA 13 ?? 16 13 ?? 11 ?? 11 ?? (30 | 3D) [1-4] 1C 0C 11 ?? 11 ?? 9A 28 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 1D 0C 09 11 ?? 6F ?? ?? ?? ?? 11 ?? 11 ?? 9A [5-10] 6F - ?? ?? ?? ?? 16 FE ?? 5F 11 ?? 11 ?? 9A 1F ?? 28 ?? ?? ?? ?? [5-10] 28 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 16 FE ?? 5F 11 ?? [5-10] 16 28 ?? ?? ?? ?? 16 FE ?? 5F 2C ?? 1E 0C 11 ?? 11 ?? - 9A 28 ?? ?? ?? ?? 1F ?? 0C 11 ?? 17 D6 13 ?? (38 | 2B) [1-4] 1F ?? 0C 02 28 ?? ?? ?? ?? - 13 ?? 1F ?? 0C 11 ?? 8E 69 17 DA 13 ?? 16 13 ?? 11 ?? 11 ?? 30 ?? 1F ?? 0C 11 ?? 11 ?? - 11 ?? 9A 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 FE ?? 2C ?? 1F ?? 0C 11 ?? 11 ?? 9A 28 ?? ?? - ?? ?? 1F ?? 0C 11 ?? 17 D6 13 ?? 2B ?? 1F ?? 0C 02 17 8D ?? ?? ?? ?? 25 16 1F ?? 9D 6F - ?? ?? ?? ?? 8E 69 17 DA 18 FE ?? 16 FE ?? 2C ?? 1F ?? 0C 02 16 28 ?? ?? ?? ?? DD ?? ?? - ?? ?? 07 17 58 16 0B 45 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? - ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? - ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? - ?? ?? ?? ?? ?? ?? ?? ?? ?? DE - } - $remote_server_communication_1 = { - 00 7E ?? ?? ?? ?? 73 ?? ?? ?? ?? 16 7E ?? ?? ?? ?? 8E 69 6F ?? ?? ?? ?? 9A [5-10] 28 ?? - ?? ?? ?? 0B 02 [5-10] 16 28 ?? ?? ?? ?? 16 FE ?? 3A ?? ?? ?? ?? 02 [5-10] 16 28 ?? ?? ?? - ?? 16 FE ?? 39 ?? ?? ?? ?? 1D 8D ?? ?? ?? ?? 25 16 [5-10] A2 25 17 02 A2 25 18 [5-10] A2 - 25 19 7E ?? ?? ?? ?? A2 25 1A [5-10] A2 25 1B 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 25 1C [5-10] - A2 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? - [5-10] 11 ?? 28 ?? ?? ?? ?? 13 ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 07 - 28 ?? ?? ?? ?? 74 ?? ?? ?? ?? 13 ?? 11 ?? [5-10] 6F ?? ?? ?? ?? 11 ?? [5-10] 6F ?? ?? ?? ?? - 11 ?? 11 ?? 8E 69 6A 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 16 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? - ?? 13 ?? 11 ?? 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? - 74 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 6F ?? ?? ?? ?? 13 ?? 11 - } + $a = { 01 75 14 80 78 FF 2F 48 8D 40 FF 0F 94 C2 48 39 D8 77 EB 84 D2 } condition: - uint16(0)==0x5A4D and $enum_drives and $file_search and $encrypt_files and $remote_server_communication_1 + all of them } -rule REVERSINGLABS_Win32_Ransomware_DMR : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_88A1B067 : FILE MEMORY { meta: - description = "Yara rule that detects DMR ransomware." - author = "ReversingLabs" - id = "45d8f91f-d2d0-5c6e-a29e-b8c9c29dc296" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/ransomware/Win32.Ransomware.DMR.yara#L1-L214" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "55e19f3017c2cc8355c27f9a516e611b58b108f15bfed41b88d5662b55677a59" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "88a1b067-11d5-4128-b763-2d1747c95eef" + date = "2021-06-28" + modified = "2021-09-16" + reference = "1a62db02343edda916cbbf463d8e07ec2ad4509fd0f15a5f6946d0ec6c332dd9" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1722-L1740" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "0755f1f974734ccd4ecc444217bf52ed306d1dc32c05841ba9ca6d259e1a147e" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Ransomware" - tc_detection_name = "DMR" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "b32b42975297aed7cef72668ee272a5cfb753dce7813583f0c3ec91e52f8601f" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $find_files_p1 = { - 8B FF 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 8B 4D ?? 8B 55 ?? 53 - 57 8B 7D ?? 89 95 ?? ?? ?? ?? 3B CF 74 ?? 8A 01 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 74 ?? - 51 57 E8 ?? ?? ?? ?? 59 59 8B C8 3B CF 75 ?? 8B 95 ?? ?? ?? ?? 8A 01 88 85 ?? ?? ?? - ?? 3C ?? 75 ?? 8D 47 ?? 3B C8 74 ?? 52 33 DB 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? - ?? ?? ?? 8A 85 ?? ?? ?? ?? 33 DB 3C ?? 74 ?? 3C ?? 74 ?? 3C ?? 8A C3 75 ?? B0 ?? 2B - CF 0F B6 C0 41 89 9D ?? ?? ?? ?? F7 D8 89 9D ?? ?? ?? ?? 56 1B C0 89 9D ?? ?? ?? ?? - 23 C1 89 9D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? - ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 57 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? F7 D8 - 1B C0 53 53 53 51 F7 D0 23 85 ?? ?? ?? ?? 53 50 FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 75 - ?? FF B5 ?? ?? ?? ?? 53 53 57 E8 ?? ?? ?? ?? 83 C4 ?? 8B D8 E9 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8B 48 ?? 2B 08 C1 F9 ?? 89 8D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? - ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 89 9D ?? ?? ?? ?? 88 9D ?? ?? ?? ?? E8 ?? ?? - ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 8D 85 ?? ?? ?? ?? 50 E8 ?? ?? ?? - ?? 83 C4 ?? F7 D8 1B C0 F7 D0 23 85 ?? ?? ?? ?? 80 38 ?? 75 ?? 8A 48 ?? 84 C9 74 - } - $find_files_p2 = { - 80 F9 ?? 75 ?? 38 58 ?? 74 ?? FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 57 50 E8 ?? ?? ?? - ?? 83 C4 ?? 89 85 ?? ?? ?? ?? 85 C0 75 ?? 38 9D ?? ?? ?? ?? 74 ?? FF B5 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 59 8D 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? - 8B 85 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 10 8B 40 ?? 2B C2 C1 F8 ?? 3B C8 74 ?? 68 ?? - ?? ?? ?? 2B C1 6A ?? 50 8D 04 8A 50 E8 ?? ?? ?? ?? 83 C4 ?? EB ?? 38 9D ?? ?? ?? ?? - 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 59 8B D8 56 FF 15 ?? ?? ?? - ?? 80 BD ?? ?? ?? ?? ?? 5E 74 ?? FF B5 ?? ?? ?? ?? E8 ?? ?? ?? ?? 59 8B C3 8B 4D ?? - 5F 33 CD 5B E8 ?? ?? ?? ?? C9 C3 - } - $encrypt_files_p1 = { - 55 8B EC 6A ?? 68 ?? ?? ?? ?? 64 A1 ?? ?? ?? ?? 50 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? - 33 C5 89 45 ?? 56 57 50 8D 45 ?? 64 A3 ?? ?? ?? ?? 8B F1 89 B5 ?? ?? ?? ?? C7 45 ?? - ?? ?? ?? ?? 8D 45 ?? 83 7D ?? ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 - ?? 85 C0 0F 85 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 68 ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? - ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 88 85 ?? ?? ?? ?? 8D 55 ?? FF B5 ?? ?? ?? - ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? 8D 4D ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? - 8B 55 ?? 88 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA - ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 - E8 ?? ?? ?? ?? 8A 85 ?? ?? ?? ?? 83 C4 ?? 84 C0 0F 84 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? - ?? 8D 55 ?? FF B5 ?? ?? ?? ?? 8D 4D ?? E8 ?? ?? ?? ?? 83 C4 ?? C6 45 ?? ?? 8D 45 ?? - 83 7D ?? ?? 0F 43 45 ?? 50 FF 15 ?? ?? ?? ?? 83 E0 ?? 8D 4D ?? 83 7D ?? ?? 50 0F 43 - } - $encrypt_files_p2 = { - 4D ?? 51 FF 15 ?? ?? ?? ?? 8D 45 ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? - ?? 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 8D 8D - ?? ?? ?? ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 40 ?? C7 84 05 ?? ?? - ?? ?? ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 8D 41 ?? 89 84 0D ?? ?? ?? ?? 8D BE ?? - ?? ?? ?? C6 45 ?? ?? 83 7F ?? ?? 8B C7 89 BD ?? ?? ?? ?? 72 ?? 8B 07 83 7F ?? ?? 75 - ?? 0F B6 00 3C ?? 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 85 C0 75 ?? C7 86 ?? ?? ?? ?? ?? - ?? ?? ?? B8 ?? ?? ?? ?? EB ?? 8B 86 ?? ?? ?? ?? 6A ?? 50 8D 4D ?? C7 45 ?? ?? ?? ?? - ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 8D 4D ?? 8B 86 ?? ?? - ?? ?? 83 7D ?? ?? 99 0F 43 4D ?? 52 50 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 8D ?? - ?? ?? ?? 8B 55 ?? 3B CA 77 ?? 83 7D ?? ?? 8D 45 ?? 89 4D ?? 0F 43 45 ?? C6 04 01 ?? - EB ?? 8B 45 ?? 8B F9 2B FA 2B C2 3B F8 77 ?? 83 7D ?? ?? 8D 75 ?? 57 0F 43 75 ?? 03 - } - $encrypt_files_p3 = { - F2 89 4D ?? 6A ?? 56 E8 ?? ?? ?? ?? C6 04 3E ?? 83 C4 ?? 8B B5 ?? ?? ?? ?? EB ?? 6A - ?? 57 C6 85 ?? ?? ?? ?? ?? 8D 4D ?? FF B5 ?? ?? ?? ?? 57 E8 ?? ?? ?? ?? 8B BD ?? ?? - ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? - ?? 6A ?? 8B 40 ?? 03 C8 33 C0 39 41 ?? 0F 94 C0 8D 04 85 ?? ?? ?? ?? 0B 41 ?? 50 E8 - ?? ?? ?? ?? 83 7D ?? ?? 8D 45 ?? 0F 43 45 ?? 83 BD ?? ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? - 6A ?? 6A ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 6A ?? 50 8D 8D ?? ?? - ?? ?? E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 48 ?? 89 8D ?? ?? ?? ?? 8B 01 FF 50 ?? 8D - 85 ?? ?? ?? ?? C6 45 ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? 50 E8 ?? ?? - ?? ?? C6 45 ?? ?? 8B 8D ?? ?? ?? ?? 85 C9 74 ?? 8B 01 8B 40 ?? FF D0 85 C0 74 ?? 8B - 08 6A ?? 8B 11 8B C8 FF D2 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 33 D2 8B 40 ?? 03 C8 - B8 ?? ?? ?? ?? 39 51 ?? 0F 45 C2 EB ?? 8B 85 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 8B 40 ?? - 03 C8 33 C0 39 41 ?? 0F 94 C0 8D 04 85 ?? ?? ?? ?? 0B 41 ?? 6A ?? 50 E8 ?? ?? ?? ?? - 81 C6 ?? ?? ?? ?? 8D 45 ?? 3B F0 74 ?? 83 7D ?? ?? 8B CE FF 75 ?? 0F 43 45 ?? 50 E8 - ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? 8D 4D ?? C7 45 ?? ?? ?? ?? ?? C7 45 - } - $encrypt_files_p4 = { - C6 45 ?? ?? E8 ?? ?? ?? ?? C6 45 ?? ?? 83 7F ?? ?? 8B 47 ?? 72 ?? 8B 3F 83 F8 ?? 75 - ?? 0F B6 07 3C ?? 75 ?? 33 C0 EB ?? 1B C0 83 C8 ?? 8B BD ?? ?? ?? ?? 85 C0 75 ?? 8D - 45 ?? 50 83 EC ?? 8D 87 ?? ?? ?? ?? 8B CC 89 A5 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 EC - ?? C6 45 ?? ?? 8B CC 56 E8 ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? ?? EB ?? 8B BD ?? ?? - ?? ?? 8D 45 ?? 3B F0 74 ?? 83 7D ?? ?? 8B CE FF 75 ?? 0F 43 45 ?? 50 E8 ?? ?? ?? ?? - 8D 45 ?? 3B C6 74 ?? 83 7E ?? ?? 8B C6 72 ?? 8B 06 FF 76 ?? 8D 4D ?? 50 E8 ?? ?? ?? - ?? 6A ?? 68 ?? ?? ?? ?? 8B CE E8 ?? ?? ?? ?? 83 7E ?? ?? 8B C6 72 ?? 8B 06 C7 46 ?? - ?? ?? ?? ?? 8D 55 ?? C6 00 ?? 8D 8D ?? ?? ?? ?? 83 7D ?? ?? FF 75 ?? 0F 43 55 ?? E8 - ?? ?? ?? ?? 83 C4 ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 85 ?? ?? ?? ?? - 8D 8D ?? ?? ?? ?? 6A ?? 8B 40 ?? 03 C8 33 C0 39 41 ?? 0F 94 C0 8D 04 85 ?? ?? ?? ?? - 0B 41 ?? 50 E8 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 8B F0 8D 85 ?? ?? ?? ?? C6 45 ?? ?? 50 8D - 4D ?? E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? C6 45 ?? ?? 51 8B C8 E8 ?? ?? ?? ?? 8B C8 C6 - 45 ?? ?? 8B 41 ?? 8B 51 ?? 2B C2 83 F8 ?? 72 ?? 83 79 ?? ?? 8D 42 ?? 89 41 ?? 8B C1 - 72 ?? 8B 01 66 C7 04 02 ?? ?? EB ?? 6A ?? 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? FF B5 - ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 8B C8 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? - ?? ?? ?? ?? ?? 0F 10 01 0F 11 85 ?? ?? ?? ?? F3 0F 7E 41 ?? 66 0F D6 85 ?? ?? ?? ?? - C7 41 ?? ?? ?? ?? ?? C7 41 ?? ?? ?? ?? ?? C6 01 ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 8B - } - $encrypt_files_p5 = { - C2 8B 8D ?? ?? ?? ?? 2B C1 83 F8 ?? 72 ?? 8D 41 ?? 83 FA ?? 89 85 ?? ?? ?? ?? 8D 85 - ?? ?? ?? ?? 0F 43 85 ?? ?? ?? ?? C7 04 01 ?? ?? ?? ?? C6 44 01 ?? ?? 8D 85 ?? ?? ?? - ?? EB ?? 6A ?? 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? FF B5 ?? ?? ?? - ?? 6A ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - 0F 10 00 0F 11 85 ?? ?? ?? ?? F3 0F 7E 40 ?? 66 0F D6 85 ?? ?? ?? ?? C7 40 ?? ?? ?? - ?? ?? C7 40 ?? ?? ?? ?? ?? C6 00 ?? 8D 47 ?? C6 45 ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 10 00 0F 11 - 85 ?? ?? ?? ?? F3 0F 7E 40 ?? 66 0F D6 85 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? - ?? ?? ?? ?? C6 00 ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 8B C2 8B 8D ?? ?? ?? ?? 2B C1 83 - F8 ?? 72 ?? 8D 41 ?? 83 FA ?? 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 0F 43 85 ?? ?? ?? - ?? 66 C7 04 08 ?? ?? 8D 85 ?? ?? ?? ?? EB ?? 6A ?? 68 ?? ?? ?? ?? C6 85 ?? ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? FF B5 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 10 00 0F 11 85 ?? ?? ?? ?? F3 0F 7E 40 ?? 66 - 0F D6 85 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C6 00 ?? C6 45 - } - $encrypt_files_p6 = { - 8B BD ?? ?? ?? ?? 8B C7 8B 8D ?? ?? ?? ?? 2B C1 8B 56 ?? 3B D0 76 ?? 8B 46 ?? 2B C2 - 3B C1 72 ?? 83 FF ?? 8D 85 ?? ?? ?? ?? 51 0F 43 85 ?? ?? ?? ?? 8B CE 50 6A ?? E8 ?? - ?? ?? ?? EB ?? 56 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? 0F 10 00 0F 11 85 ?? ?? ?? ?? F3 0F 7E 40 ?? 66 0F D6 85 - ?? ?? ?? ?? C6 00 ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? - ?? ?? ?? 8B C2 8B 8D ?? ?? ?? ?? 2B C1 6A ?? 68 ?? ?? ?? ?? 83 F8 ?? 72 ?? 83 FA ?? - 8D B5 ?? ?? ?? ?? 8D 41 ?? 0F 43 B5 ?? ?? ?? ?? 03 F1 89 85 ?? ?? ?? ?? 56 E8 ?? ?? - ?? ?? 83 C4 ?? C6 46 ?? ?? 8D 85 ?? ?? ?? ?? EB ?? C6 85 ?? ?? ?? ?? ?? 8D 8D ?? ?? - ?? ?? FF B5 ?? ?? ?? ?? 6A ?? E8 ?? ?? ?? ?? 0F 10 00 0F 11 45 ?? F3 0F 7E 40 ?? 66 - 0F D6 45 ?? C7 40 ?? ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? C6 00 ?? C6 45 ?? ?? 8B 95 ?? - ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? - 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 - ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? - 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? - ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? - ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 - } - $encrypt_files_p7 = { - FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 - 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? - ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 - ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? - 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? - 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? - 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? - 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B - } - $encrypt_files_p8 = { - 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? - ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 - ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? - ?? 66 89 85 ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? - ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 - ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? C7 85 ?? ?? - ?? ?? ?? ?? ?? ?? C6 85 ?? ?? ?? ?? ?? C6 45 ?? ?? 8B 95 ?? ?? ?? ?? 83 FA ?? 72 ?? - 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 - ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 33 C0 C7 - 85 ?? ?? ?? ?? ?? ?? ?? ?? 83 EC ?? 66 89 85 ?? ?? ?? ?? 8D 45 ?? C7 85 ?? ?? ?? ?? - ?? ?? ?? ?? 8B CC 50 E8 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 8B F0 - C6 45 ?? ?? 83 7E ?? ?? 72 ?? 8B 36 83 EC ?? 8D 85 ?? ?? ?? ?? 8B CC 50 E8 ?? ?? ?? - ?? 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 83 78 ?? ?? 72 ?? 8B 00 56 50 E8 ?? ?? - ?? ?? 8B 95 ?? ?? ?? ?? 83 C4 ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 8D 14 55 ?? ?? ?? - ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? - ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 95 ?? ?? ?? ?? 33 C0 C7 85 ?? ?? ?? ?? ?? - ?? ?? ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? 66 89 85 ?? ?? ?? ?? 83 FA ?? 72 ?? 8B 8D ?? - ?? ?? ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 - } - $encrypt_files_p9 = { - 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? - 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 - F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 4D - ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 - ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? - ?? ?? ?? C6 45 ?? ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 - ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? - 8D 8D ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? C6 45 ?? ?? E8 ?? ?? ?? - ?? 8B 55 ?? 83 FA ?? 72 ?? 8B 8D ?? ?? ?? ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 - ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 0F 87 ?? ?? ?? ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? - 8B 55 ?? 83 FA ?? 72 ?? 8B 4D ?? 8D 14 55 ?? ?? ?? ?? 8B C1 81 FA ?? ?? ?? ?? 72 ?? - 8B 49 ?? 83 C2 ?? 2B C1 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 55 - ?? 83 FA ?? 72 ?? 8B 4D ?? 42 8B C1 81 FA ?? ?? ?? ?? 72 ?? 8B 49 ?? 83 C2 ?? 2B C1 - 83 C0 ?? 83 F8 ?? 77 ?? 52 51 E8 ?? ?? ?? ?? 83 C4 ?? 8B 4D ?? 64 89 0D ?? ?? ?? ?? - 59 5F 5E 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C2 ?? ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? - ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? E8 - } + $a = { 00 00 00 55 89 E5 0F B6 55 08 0F B6 45 0C C1 E2 18 C1 E0 10 } condition: - uint16(0)==0x5A4D and ( all of ($find_files_p*)) and ( all of ($encrypt_files_p*)) + all of them } -import "pe" - -rule REVERSINGLABS_Win32_Virus_Cmay : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_76Bbc4Ca : FILE MEMORY { meta: - description = "Yara rule that detects Cmay virus." - author = "ReversingLabs" - id = "d61e09f1-1d3f-5e1e-9884-25f1a465e88d" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/virus/Win32.Virus.Cmay.yara#L3-L73" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "f3bdf772eb80c632a913621732d12ae4a02bc7d3ba41f51711aa329be2ca6220" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "76bbc4ca-e6da-40f7-8ba6-139ec8393f35" + date = "2021-06-28" + modified = "2021-09-16" + reference = "1a9ff86a66d417678c387102932a71fd879972173901c04f3462de0e519c3b51" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1742-L1760" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "855b7938b92b5645fcefd2ec1e2ccb71269654816f362282ccbf9aef1c01c8a0" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Virus" - tc_detection_name = "Cmay" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "4206c56b538eb1dd97e8ba58c5bab6e21ad22a0f8c11a72f82493c619d22d9b7" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $cmay_body_1 = { - 60 66 9C E8 00 00 00 00 5D 8B C5 81 ED ?? ?? ?? ?? 2D 08 00 00 00 2D - ?? ?? ?? ?? 89 85 ?? ?? ?? ?? E8 3A 02 00 00 0F 82 7C 03 00 00 8D B5 - ?? ?? ?? ?? 8D BD ?? ?? ?? ?? E8 4F 02 00 00 E8 05 00 00 00 E9 61 03 - 00 00 8D BD ?? ?? ?? ?? C6 85 ?? ?? ?? ?? 03 6A 7F 57 FF 95 ?? ?? ?? - ?? 83 C7 7F 6A 7F 57 FF 95 ?? ?? ?? ?? 83 C7 7F 57 6A 7F FF 95 ?? ?? - ?? ?? 8D BD ?? ?? ?? ?? 80 BD ?? ?? ?? ?? 00 0F 84 20 03 00 00 FE 8D - ?? ?? ?? ?? 57 FF 95 ?? ?? ?? ?? 83 C7 7F 8D 9D ?? ?? ?? ?? 53 8D 9D - ?? ?? ?? ?? 53 FF 95 ?? ?? ?? ?? 83 F8 FF 74 CA 89 85 ?? ?? ?? ?? FF - 85 ?? ?? ?? ?? E8 C0 02 00 00 83 F8 FF 74 75 E8 70 02 00 00 85 C0 74 - 6C 8B 85 ?? ?? ?? ?? 8B 50 3C 3B 95 ?? ?? ?? ?? 73 5B 03 D0 8B 02 35 - 96 23 00 00 3D C6 66 00 00 75 4B 81 7A 4C 53 54 30 00 74 42 52 FF B5 - ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 5A FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? - E8 79 00 00 00 8F 85 ?? ?? ?? ?? 8F 85 ?? ?? ?? ?? 83 BD ?? ?? ?? ?? - 05 7E 0E 80 BD ?? ?? ?? ?? 00 0F 85 40 FF FF FF C3 57 8D BD ?? ?? ?? - ?? B9 04 01 00 00 32 C0 F3 AA 5F FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? - FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? - ?? 8D 9D ?? ?? ?? ?? 53 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 85 C0 74 - 05 E9 2A FF FF FF E9 E9 FE FF FF 8B B5 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? - 8B 5A 3C E8 87 01 00 00 89 B5 ?? ?? ?? ?? E8 8B 01 00 00 33 DB 8B 95 - ?? ?? ?? ?? 8B 42 3C 03 D0 0F B7 42 06 48 6B C0 28 0F B7 5A 14 83 C3 - 18 03 DA 03 C3 8B 58 10 03 58 14 03 9D ?? ?? ?? ?? 53 8B 4A 28 89 8D - ?? ?? ?? ?? 8B 4A 34 89 8D ?? ?? ?? ?? 8B 48 0C 03 48 10 89 8D ?? ?? - ?? ?? 89 4A 28 8B 70 10 81 C6 ?? ?? ?? ?? 8B 5A 3C E8 1D 01 00 00 89 - 70 10 89 70 08 03 70 0C 89 72 50 81 48 24 20 00 00 A0 C7 42 4C 53 54 - } - $cmay_body_2 = { - 30 00 5B B9 ?? ?? ?? ?? FC 8B FB 8D B5 ?? ?? ?? ?? F3 A4 FF B5 ?? ?? - ?? ?? FF 95 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? FF B5 ?? - ?? ?? ?? FF 95 ?? ?? ?? ?? C3 50 51 B9 05 00 00 00 8B 44 24 2E 25 00 - 00 FF FF 66 81 38 4D 5A 74 09 2D 00 00 01 00 E2 F2 EB 06 89 85 ?? ?? - ?? ?? 59 58 74 01 F9 C3 56 8B 95 ?? ?? ?? ?? 8B 72 3C 03 F2 8B 76 78 - 03 F2 83 C6 1C AD 03 C2 89 85 ?? ?? ?? ?? AD 03 C2 89 85 ?? ?? ?? ?? - AD 03 C2 89 85 ?? ?? ?? ?? 5E 57 E8 16 00 00 00 5F 89 07 83 C7 04 80 - 3E 88 C7 85 ?? ?? ?? ?? 00 00 00 00 75 E5 C3 8B DE 80 3E 00 74 03 46 - EB F8 46 8B CE 2B CB 8B F3 8B BD ?? ?? ?? ?? 57 8B 3F 03 FA 51 F3 A6 - 74 0F 8B F3 59 5F 83 C7 04 FF 85 ?? ?? ?? ?? EB E7 59 5F 8B 85 ?? ?? - ?? ?? D1 E0 03 85 ?? ?? ?? ?? 33 DB 66 8B 18 C1 E3 02 03 9D ?? ?? ?? - ?? 8B 1B 03 DA 8B C3 C3 50 52 33 D2 8B C6 F7 F3 2B DA 03 F3 5A 58 C3 - 8B 85 ?? ?? ?? ?? 6A 00 50 6A 00 6A 04 6A 00 FF B5 ?? ?? ?? ?? FF 95 - ?? ?? ?? ?? 85 C0 74 1E 89 85 ?? ?? ?? ?? 6A 00 6A 00 6A 00 6A 02 FF - B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 85 C0 75 02 33 C0 89 85 ?? ?? ?? ?? - C3 33 C0 50 68 80 00 00 00 6A 03 50 40 50 68 00 00 00 C0 8D B5 ?? ?? - ?? ?? 56 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? C3 85 ED 0F 84 2A 04 00 - 00 33 C0 05 ?? ?? ?? ?? 05 ?? ?? ?? ?? FF E0 - } + $a = { 10 40 2D E9 00 40 A0 E1 28 20 84 E2 0C 00 92 E8 3B F1 FF EB } condition: - uint16(0)==0x5A4D and ($cmay_body_1 at pe.entry_point) and $cmay_body_2 + all of them } -import "pe" - -rule REVERSINGLABS_Win32_Virus_Elerad : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_0Bfc17Bd : FILE MEMORY { meta: - description = "Yara rule that detects Elerad virus." - author = "ReversingLabs" - id = "0307a136-ea2c-584c-bfda-f41e2c46fd09" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/virus/Win32.Virus.Elerad.yara#L3-L33" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "930594bf99daf55ef02542ce7b393c1c23ead75946b3da3b555102a2e7142e33" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "0bfc17bd-49bb-4721-9653-0920b631b1de" + date = "2022-01-05" + modified = "2022-01-26" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1762-L1780" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "1cdd94f2a1cb2b93134646c171d947e325a498f7a13db021e88c05a4cbb68903" + logic_hash = "ef83bc9ae3c881d09b691db42a1712b500a5bb8df34060a6786cfdc6caaf5530" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Virus" - tc_detection_name = "Elerad" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "d67e4e12e74cbd31037fae52cf7bad8d8d5b4240d79449fa1ebf9a271af008e1" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $elerad_body = { - EB 77 60 E8 09 00 00 00 8B 64 24 08 E9 DD 01 00 00 33 D2 64 FF 32 64 89 22 50 8B D8 B9 FF 00 00 00 81 38 2E 65 78 65 74 - 08 40 E2 F5 E9 BD 01 00 00 32 D2 38 50 04 0F 85 B2 01 00 00 33 D2 80 38 5C 74 07 3B C3 74 07 48 E2 F4 88 10 8B D0 58 BE - 00 00 E6 77 BF 23 C1 AB 00 EB 3E 60 E8 09 00 00 00 8B 64 24 08 E9 84 01 00 00 33 D2 64 FF 32 64 89 22 BE 00 00 E6 77 EB - 20 68 ?? ?? ?? ?? 60 8B 74 24 24 E8 09 00 00 00 8B 64 24 08 E9 5D 01 00 00 33 D2 64 FF 32 64 89 22 E8 00 00 00 00 5D 81 - ED ?? ?? ?? ?? 81 FF 23 C1 AB 00 75 0C 89 95 22 12 40 00 89 85 1E 12 40 00 BA ?? ?? ?? ?? B9 09 02 00 00 8D 85 D0 10 40 - 00 31 10 83 C0 04 E2 F9 - } + $a = { 54 24 64 0F CD 48 8D 14 52 41 0F B6 4C D7 14 D3 E8 01 C5 83 7C 24 } condition: - uint16(0)==0x5A4D and ($elerad_body at pe.entry_point) + all of them } -import "pe" - -rule REVERSINGLABS_Win32_Virus_Deadcode : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_389Ee3E9 : FILE MEMORY { meta: - description = "Yara rule that detects DeadCode virus." - author = "ReversingLabs" - id = "89ec2e39-a163-5ba6-9b19-9c94b1923d47" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/virus/Win32.Virus.DeadCode.yara#L3-L76" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "6ac2e48daaed222f0a19afd4d03a02834705e0e3762db3217f68569554171846" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "389ee3e9-70c1-4c93-a999-292cf6ff1652" + date = "2022-01-05" + modified = "2022-01-26" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1782-L1800" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f" + logic_hash = "fedeae98d468a11c3eaa561b9d5433ec206bdd4caed5aed7926434730f7f866b" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Virus" - tc_detection_name = "DeadCode" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $deadcode_ep_1 = { - 64 67 FF 36 30 00 58 8B 40 08 FF 70 48 5B FF 70 4C 5A 03 40 44 - FF E0 - } - $deadcode_marker = { - DE C0 AD DE - } - $deadcode_ep_2 = { - 2B C0 85 C0 74 0E 64 67 FF 36 00 00 64 67 89 26 00 00 89 00 E8 - ED FF FF FF 8B 74 24 0C 64 67 A1 30 00 8B 40 08 8B 58 48 8B 50 - 4C 03 40 44 89 86 B8 00 00 00 89 86 B0 00 00 00 89 9E A4 00 00 - 00 89 96 A8 00 00 00 2B C0 C3 - } - $deadcode_ep_3 = { - B8 DE C0 AD DE 50 5A 64 67 A1 30 00 8B 40 08 8B 58 48 8B 50 4C - 03 40 44 FF D0 - } - $deadcode_body_1 = { - 8B D0 8B EA 81 C5 ?? ?? ?? ?? 89 85 A4 00 00 00 89 9D C0 00 00 00 E8 56 01 00 00 89 - 45 00 8D 75 04 81 C2 ?? ?? ?? ?? 6A 19 FF 75 00 52 56 E8 CE 01 00 00 64 67 A1 30 00 - 8B 40 08 89 85 88 00 00 00 C7 85 D0 00 00 00 ?? ?? ?? ?? E8 09 00 00 00 8B 64 24 08 - E9 03 01 00 00 33 D2 64 FF 32 64 89 22 83 BD C0 00 00 00 00 75 2F 6A 04 68 00 10 00 - 00 68 40 01 00 00 6A 00 FF 55 08 50 8F 45 78 E8 2A 03 00 00 68 00 40 00 00 68 40 01 - 00 00 FF 75 78 FF 55 28 E9 C3 00 00 00 8B 85 A4 00 00 00 05 ?? ?? ?? ?? 8D B5 B4 00 - 00 00 56 6A 00 55 50 68 00 00 10 00 6A 00 FF 55 30 89 85 AC 00 00 00 6A 04 68 00 10 - 00 00 6A 54 6A 00 FF 55 08 89 85 A8 00 00 00 64 67 A1 30 00 8B 40 10 8B 40 3C 8B B5 - A8 00 00 00 8D 7E 10 56 57 6A 00 6A 00 6A 04 6A 01 6A 00 6A 00 50 6A 00 FF 55 50 85 - C0 74 5D FF 76 04 8F 85 B0 00 00 00 64 67 A1 30 00 8B 40 08 8B D8 03 5B 3C 8B 5B 28 - 03 D8 8B 8D A4 00 00 00 81 ?? ?? ?? ?? 8D 85 B4 00 00 00 50 6A ?? 51 53 FF 36 FF 55 - 4C FF 76 04 FF 55 54 8D B5 AC 00 00 00 6A FF 6A 01 56 6A 02 FF 55 34 68 00 40 00 00 - 6A 54 FF B5 A8 00 00 00 FF 55 28 33 D2 64 8F 02 5A E8 DB 01 00 00 E8 F5 00 00 00 6A - 00 FF 55 3C 64 67 8B 36 00 00 AD 83 F8 FF 74 04 8B F0 EB F6 8B 7E 04 81 E7 00 00 FF - FF 66 81 3F 4D 5A 74 08 81 EF 00 00 01 00 EB F1 8B DF 03 5B 3C 66 81 3B 50 45 74 02 - EB E3 8B C7 C3 55 8B EC 8B 75 0C AC 84 C0 75 FB 2B 75 0C 8B CE 8B 5D 08 03 5B 3C 8B - 5B 78 03 5D 08 8B 53 20 03 55 08 2B C0 8B 32 03 75 08 8B 7D 0C 51 FC F3 A6 59 74 06 - } - $deadcode_body_2 = { - 83 C2 04 40 EB EB 8B 73 24 03 75 08 2B D2 66 8B 14 46 8B 73 1C 03 75 08 8B 04 96 03 - 45 08 8B E5 5D C2 08 00 55 8B EC 8B 7D 08 8B 75 0C 8B 4D 14 51 56 57 56 FF 75 10 E8 - 91 FF FF FF 5F 5E 59 AB AC 84 C0 75 FB E2 E9 8B E5 5D C2 10 00 8B 6C 24 04 6A 04 68 - 00 10 00 00 68 40 01 00 00 6A 00 FF 55 08 85 C0 74 18 89 45 78 E8 63 01 00 00 68 00 - 40 00 00 68 40 01 00 00 FF 75 78 FF 55 28 6A 00 FF 55 40 C3 - } + $a = { 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83 } condition: - uint16(0)==0x5A4D and ((($deadcode_ep_1 at pe.entry_point) and ($deadcode_marker at 0x40)) or (($deadcode_ep_2 at pe.entry_point) and ($deadcode_marker at 0x40)) or (($deadcode_ep_3 at pe.entry_point) and ($deadcode_marker at 0x40)) or ($deadcode_body_1 and $deadcode_body_2)) + all of them } -import "elf" - -rule REVERSINGLABS_Linux_Virus_Vit : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Cc93863B : FILE MEMORY { meta: - description = "Yara rule that detects Vit virus." - author = "ReversingLabs" - id = "4515fe43-4c5a-521d-82b7-273823f0c64e" - date = "2024-08-04" - date = "2024-08-04" - modified = "2023-06-07" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/virus/Linux.Virus.Vit.yara#L3-L36" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "2fba7a081dfca85aee5c7f3b33414b799ed52ca6aa5bbf031da040aaa75acde9" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "cc93863b-1050-40ba-9d02-5ec9ce6a3a28" + date = "2022-01-05" + modified = "2022-01-26" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1802-L1820" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f" + logic_hash = "881998dee010270d7cefae5b59a888e541d4a2b93e3e52ae0abe0df41371c50d" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Virus" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $vit_entry_point = { - 55 89 E5 81 EC 40 31 00 00 57 56 50 53 51 52 C7 85 D8 CE FF FF 00 00 00 00 C7 85 D4 - CE FF FF 00 00 00 00 C7 85 FC CF FF FF CA 08 00 00 C7 85 F8 CF FF FF B8 06 00 00 C7 - 85 F4 CF FF FF AD 08 00 00 C7 85 F0 CF FF FF 50 06 00 00 6A 00 6A 00 8B 45 08 50 E8 - 18 FA FF FF 89 C6 83 C4 0C 85 F6 0F 8C E6 01 00 00 6A 00 68 ?? ?? ?? ?? 56 E8 2E FA - FF FF 83 C4 0C 85 C0 0F 8C C4 01 00 00 8B 85 FC CF FF FF 50 8D 85 00 D0 FF FF 50 56 - E8 2A FA FF FF 89 C2 8B 85 FC CF FF FF 83 C4 0C 39 C2 0F 85 9D 01 00 00 56 E8 E1 F9 - FF FF BE FF FF FF FF 6A 00 6A 00 E9 - } - $vit_str = "vi324.tmp" + $a = { C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08 } condition: - uint32(0)==0x464C457F and $vit_entry_point at elf.entry_point and $vit_str + all of them } -import "pe" - -rule REVERSINGLABS_Win32_Virus_Mocket : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_8Aa7B5D3 : FILE MEMORY { meta: - description = "Yara rule that detects Mocket virus." - author = "ReversingLabs" - id = "878c2162-9a79-52e6-af7b-95f9667f9e78" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/virus/Win32.Virus.Mocket.yara#L3-L58" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "af16974396efe7a1a46aa39b812482dcc49d0fe95db6640c1703db479e7ea9dc" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9" + date = "2022-01-05" + modified = "2022-01-26" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1822-L1840" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f" + logic_hash = "3c99b7b126184b75802c7198c81f4783af776920edc6e964dbe726d28d88f64d" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Virus" - tc_detection_name = "Mocket" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $mocket_body_1 = { - E8 00 00 00 00 5B 81 EB ?? ?? ?? ?? 8B 34 24 81 E6 00 00 FF FF E8 31 00 00 00 89 83 ?? ?? ?? ?? E8 4C 00 00 00 89 83 ?? - ?? ?? ?? E8 A2 00 00 00 E8 CD 00 00 00 E8 05 01 00 00 87 CB E3 0C B8 ?? ?? ?? ?? 05 ?? ?? ?? ?? FF E0 C3 66 81 3E 4D 5A - 75 0E 8B 7E 3C 03 FE 66 81 3F 50 45 75 02 96 C3 81 EE 00 00 01 00 81 FE 00 00 00 70 73 DD 33 C0 C3 8B 70 3C 03 F0 8B 76 - 78 03 F0 56 8B 76 20 03 F0 8B C6 33 D2 33 C9 8A 8B ?? ?? ?? ?? 8D BB ?? ?? ?? ?? 8B 34 02 03 B3 ?? ?? ?? ?? 83 C2 04 F3 - A6 75 E2 5E 8B C6 83 EA 04 D1 EA 8B 40 24 03 83 ?? ?? ?? ?? 33 C9 66 8B 0C 02 8B C6 8B 40 1C 03 83 ?? ?? ?? ?? C1 E1 02 - 8B 04 01 03 83 ?? ?? ?? ?? C3 8D BB ?? ?? ?? ?? 8D B3 ?? ?? ?? ?? 57 8B 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? FF D0 89 06 - 83 C6 04 B9 FF FF FF FF 32 C0 F2 AE 80 3F 90 75 DD C3 8D BB ?? ?? ?? ?? 57 68 80 00 00 00 8B 83 ?? ?? ?? ?? FF D0 81 C7 - 80 00 00 00 57 68 80 00 00 00 8B 83 ?? ?? ?? ?? FF D0 81 C7 80 00 00 00 57 68 80 00 00 00 8B 83 ?? ?? ?? ?? FF D0 C3 33 - C9 B1 03 8D BB ?? ?? ?? ?? 57 8B 83 ?? ?? ?? ?? FF D0 E8 01 00 00 00 C3 C7 83 ?? ?? ?? ?? 00 00 00 00 8D 83 ?? ?? ?? ?? - } - $mocket_body_2 = { - 50 8D 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? FF D0 40 0B C0 74 53 48 89 83 ?? ?? ?? ?? E8 48 00 00 00 FE 83 ?? ?? ?? ?? 80 - BB ?? ?? ?? ?? 0A 74 29 8D BB ?? ?? ?? ?? B9 ?? ?? ?? ?? 32 C0 F3 AA 8D 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? 50 8B 83 ?? - ?? ?? ?? FF D0 0B C0 75 C3 8B 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? FF D0 C3 60 8D B3 ?? ?? ?? ?? 56 8B 83 ?? ?? ?? ?? FF - D0 89 83 ?? ?? ?? ?? 68 80 00 00 00 56 8B 83 ?? ?? ?? ?? FF D0 E8 B7 01 00 00 40 0B C0 0F 84 75 01 00 00 48 89 83 ?? ?? - ?? ?? 8B 8B ?? ?? ?? ?? E8 B4 01 00 00 0B C0 0F 84 4D 01 00 00 89 83 ?? ?? ?? ?? 8B 8B ?? ?? ?? ?? E8 B4 01 00 00 0B C0 - 0F 84 26 01 00 00 89 83 ?? ?? ?? ?? 8B 70 3C 03 F0 66 81 3E 50 45 0F 85 F7 00 00 00 81 7E 4C 4B 43 4F 4D 0F 84 EA 00 00 - 00 8B 4E 3C 51 8B 46 28 89 83 ?? ?? ?? ?? 8B 46 34 89 83 ?? ?? ?? ?? FF B3 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 FF B3 ?? - ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 59 8B 83 ?? ?? ?? ?? 05 ?? ?? ?? ?? E8 5C 01 00 00 89 83 ?? ?? ?? ?? 91 E8 21 01 00 00 - 40 0B C0 0F 84 B9 00 00 00 48 89 83 ?? ?? ?? ?? 8B 8B ?? ?? ?? ?? E8 1F 01 00 00 0B C0 0F 84 91 00 00 00 89 83 ?? ?? ?? - } - $mocket_body_3 = { - ?? 8B 70 3C 03 F0 8B FE 83 C6 78 8B 57 74 C1 E2 03 03 F2 0F B7 47 06 48 6B C0 28 03 F0 8B 56 10 8B CA 03 56 14 52 8B C1 - 03 46 0C 89 47 28 8B 46 10 05 ?? ?? ?? ?? 8B 4F 3C E8 EA 00 00 00 89 46 10 89 46 08 8B 46 10 03 46 0C 89 47 50 81 4E 24 - 20 00 00 A0 C7 47 4C 4B 43 4F 4D 8D B3 ?? ?? ?? ?? 5A 87 FA 03 BB ?? ?? ?? ?? B9 ?? ?? ?? ?? F3 A4 EB 0B 8B 8B ?? ?? ?? - ?? E8 41 00 00 00 FF B3 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 FF B3 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 FF B3 ?? ?? ?? ?? - 8B 83 ?? ?? ?? ?? FF D0 FF B3 ?? ?? ?? ?? 8D 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? FF D0 61 C3 33 C0 50 50 51 FF B3 ?? ?? - ?? ?? 8B 83 ?? ?? ?? ?? FF D0 FF B3 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 C3 33 C0 50 50 6A 03 50 6A 01 68 00 00 00 C0 56 - 8B 83 ?? ?? ?? ?? FF D0 C3 6A 00 51 6A 00 6A 04 6A 00 8B 83 ?? ?? ?? ?? 50 8B 83 ?? ?? ?? ?? FF D0 C3 51 6A 00 6A 00 6A - 02 FF B3 ?? ?? ?? ?? 8B 83 ?? ?? ?? ?? FF D0 C3 33 D2 F7 F1 0B D2 74 01 40 F7 E1 C3 - } + $a = { 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88 } condition: - uint16(0)==0x5A4D and ($mocket_body_1 at pe.entry_point) and $mocket_body_2 and $mocket_body_3 + all of them } -import "pe" - -rule REVERSINGLABS_Win32_Virus_Awfull : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_76908C99 : FILE MEMORY { meta: - description = "Yara rule that detects Awfull virus." - author = "ReversingLabs" - id = "34104923-b401-5d39-883b-aa9a5a8e64f3" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/virus/Win32.Virus.Awfull.yara#L3-L33" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "84a4faee4cbbb3387ad25bd9230c6482b8db461bc008312bc782f23e3df2eae3" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "76908c99-e350-4dbb-9559-27cbe05f55f9" + date = "2022-09-12" + modified = "2022-10-18" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1842-L1860" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "533a90959bfb337fd7532fb844501fd568f5f4a49998d5d479daf5dfbd01abb2" + logic_hash = "bd8254e888b1ea93ca9aad92ea2c8ece1f2d03ae2949ca4c3743b6e339ee21e0" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Virus" - tc_detection_name = "Awfull" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "1741b0c2121e3f73bf7e4f505c4661c95753cbf7e0b7a1106dc4ea4d4dd73d6c" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $awfull_body = { - 60 E8 ?? 00 00 00 8B 64 24 08 EB ?? [0-256] - 33 D2 64 FF 32 64 89 22 33 C0 C7 00 00 00 00 00 33 D2 64 8F 02 - 5A 64 (8B 0D | 67 8B 0E ) 14 00 [0-2] E3 03 FA - EB FD 61 E8 00 00 00 00 5D 81 ED ?? ?? ?? ?? 0B ED 74 ?? - [0-128] (BE | 8B 35) ?? ?? ?? ?? 03 F5 B9 ?? ?? ?? ?? - 56 5F AC F6 D0 AA 49 E3 02 EB F7 - } + $a = { 64 24 F8 48 89 04 24 48 8B C6 48 8B 34 24 48 87 CF 48 8B 4C } condition: - uint16(0)==0x5A4D and ($awfull_body at pe.entry_point) + all of them } -import "pe" - -rule REVERSINGLABS_Win32_Virus_Negt : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_1538Ce1A : FILE MEMORY { meta: - description = "Yara rule that detects Negt virus." - author = "ReversingLabs" - id = "80e83105-dd98-5fad-9119-f851ec3199af" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/virus/Win32.Virus.Negt.yara#L3-L94" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "43057ef111fc505678606386c8d428653da391f4b65844d81479ca05e3517346" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "1538ce1a-7078-4be3-bd69-7e692a1237f5" + date = "2022-09-12" + modified = "2022-10-18" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1862-L1880" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "2382996a8fd44111376253da227120649a1a94b5c61739e87a4e8acc1130e662" + logic_hash = "cf2dd11da520640c6a64e05c4679072a714d8cf93d5f5aa3a1eca8eb3e9c8b3b" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Virus" - tc_detection_name = "Negt" - tc_detection_factor = 5 - importance = 25 - - strings: - $negt_body_and_infector_1 = { - 6A 00 E8 99 08 00 00 A3 ?? ?? ?? ?? 68 04 01 00 00 68 ?? ?? ?? ?? 6A 00 E8 7D 08 00 00 6A 00 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? E8 48 08 00 00 BB 00 00 00 00 8D 05 ?? ?? ?? ?? FE 00 68 ?? ?? ?? ?? E8 2D 00 00 00 43 83 FB 18 7C E8 E8 92 08 00 00 - 3C 9F 7F 17 6A 01 68 ?? ?? ?? ?? 6A 00 68 ?? ?? ?? ?? 6A 00 6A 00 E8 7D 08 00 00 6A 00 E8 10 08 00 00 55 8B EC 81 C4 B8 - FD FF FF FF 75 08 E8 35 08 00 00 0B C0 0F 84 C2 00 00 00 8D 85 C2 FE FF FF 50 68 ?? ?? ?? ?? E8 F2 07 00 00 89 85 BC FE - FF FF 83 BD BC FE FF FF FF 0F 84 9E 00 00 00 8D 9D EE FE FF FF 53 E8 21 08 00 00 8B F3 BB 00 00 00 00 F7 D3 68 ?? ?? ?? - ?? 56 E8 01 08 00 00 23 D8 68 ?? ?? ?? ?? 56 E8 F4 07 00 00 23 D8 68 ?? ?? ?? ?? 56 E8 E7 07 00 00 23 D8 68 ?? ?? ?? ?? - 56 E8 DA 07 00 00 23 D8 68 ?? ?? ?? ?? 56 E8 CD 07 00 00 23 D8 83 FB 00 74 28 FF 75 08 68 ?? ?? ?? ?? E8 BF 07 00 00 8D - 85 EE FE FF FF 50 68 ?? ?? ?? ?? E8 A2 07 00 00 68 ?? ?? ?? ?? E8 08 01 00 00 8D 85 C2 FE FF FF 50 FF B5 BC FE FF FF E8 - 50 07 00 00 83 F8 00 0F 85 62 FF FF FF FF B5 BC FE FF FF E8 30 07 00 00 8D 85 C2 FE FF FF 50 68 ?? ?? ?? ?? E8 25 07 00 - 00 89 85 BC FE FF FF 83 BD BC FE FF FF FF 0F 84 AF 00 00 00 8D BD C2 FE FF FF 8B 07 66 83 E0 10 0F 84 82 00 00 00 8D 9D - } - $negt_body_and_infector_2 = { - EE FE FF FF 53 E8 42 07 00 00 8B F3 BB 00 00 00 00 F7 D3 68 ?? ?? ?? ?? 56 E8 22 07 00 00 23 D8 68 ?? ?? ?? ?? 56 E8 15 - 07 00 00 23 D8 68 ?? ?? ?? ?? 56 E8 08 07 00 00 23 D8 83 FB 00 74 41 FF 75 08 8D 85 B8 FD FF FF 50 E8 F8 06 00 00 8D 85 - EE FE FF FF 50 8D 85 B8 FD FF FF 50 E8 D9 06 00 00 68 ?? ?? ?? ?? 8D 85 B8 FD FF FF 50 E8 C8 06 00 00 60 8D 85 B8 FD FF - FF 50 E8 63 FE FF FF 61 8D 85 C2 FE FF FF 50 FF B5 BC FE FF FF E8 72 06 00 00 83 F8 00 0F 85 51 FF FF FF FF B5 BC FE FF - FF E8 52 06 00 00 C9 C2 04 00 55 8B EC 81 C4 E4 E9 FF FF 51 6A 00 68 80 00 00 00 6A 03 6A 00 6A 03 68 00 00 00 C0 FF 75 - 08 E8 1E 06 00 00 83 F8 FF 75 05 E9 AE 03 00 00 89 45 FC 6A 00 6A 00 6A 3C FF 75 FC E8 45 06 00 00 6A 00 8D 45 F0 50 6A - 04 8D 45 F4 50 FF 75 FC E8 25 06 00 00 6A 00 6A 00 FF 75 F4 FF 75 FC E8 22 06 00 00 6A 00 8D 45 F0 50 68 20 01 00 00 68 - ?? ?? ?? ?? FF 75 FC E8 FE 05 00 00 8B 5D F4 83 EB 0B 6A 00 6A 00 53 FF 75 FC E8 F7 05 00 00 6A 00 8D 45 F0 50 6A 0B 68 - ?? ?? ?? ?? FF 75 FC E8 D6 05 00 00 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 E5 05 00 00 0B C0 75 05 E9 12 03 00 00 81 3D ?? ?? - ?? ?? 50 45 00 00 74 05 E9 01 03 00 00 0F B7 05 ?? ?? ?? ?? B9 28 00 00 00 F7 E1 03 45 F4 83 C0 18 0F B7 0D ?? ?? ?? ?? - 03 C1 83 C0 28 3B 05 ?? ?? ?? ?? 76 05 E9 D4 02 00 00 A1 ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? ?? ?? ?? A3 ?? ?? ?? ?? 0F B7 - } - $negt_body_and_infector_3 = { - 05 ?? ?? ?? ?? B9 28 00 00 00 F7 E1 83 C0 04 03 45 F4 83 C0 14 05 E0 00 00 00 89 45 EC C7 05 ?? ?? ?? ?? 2E 45 41 54 C7 - 05 ?? ?? ?? ?? 55 02 00 00 FF 35 ?? ?? ?? ?? 8F 05 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 99 F7 F1 40 F7 E1 A3 ?? - ?? ?? ?? 8B 45 EC 83 E8 18 6A 00 6A 00 50 FF 75 FC E8 10 05 00 00 6A 00 8D 45 F0 50 6A 04 8D 45 E8 50 FF 75 FC E8 F0 04 - 00 00 6A 00 8D 45 F0 50 6A 04 8D 45 E4 50 FF 75 FC E8 DC 04 00 00 8B 45 E8 03 45 E4 A3 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? 00 - 00 00 00 C7 05 ?? ?? ?? ?? 00 00 00 00 66 C7 05 ?? ?? ?? ?? 00 00 66 C7 05 ?? ?? ?? ?? 00 00 C7 05 ?? ?? ?? ?? 20 00 00 - E0 6A 00 6A 00 FF 75 EC FF 75 FC E8 9E 04 00 00 6A 00 8D 45 F0 50 6A 28 68 ?? ?? ?? ?? FF 75 FC E8 8F 04 00 00 68 ?? ?? - ?? ?? E8 61 04 00 00 68 ?? ?? ?? ?? E8 63 04 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 48 04 00 00 A3 ?? - ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 33 04 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 1E 04 00 00 - A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 09 04 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 F4 03 - 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 DF 03 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 - CA 03 00 00 A3 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 35 ?? ?? ?? ?? E8 B5 03 00 00 A3 ?? ?? ?? ?? 6A 02 6A 00 6A 00 FF 75 FC E8 - BA 03 00 00 6A 00 8D 45 F0 50 FF 35 ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 50 FF 75 FC E8 A5 03 00 00 66 FF 05 ?? ?? ?? ?? A1 ?? - ?? ?? ?? 8B 0D ?? ?? ?? ?? 99 F7 F1 40 F7 E1 03 05 ?? ?? ?? ?? A3 ?? ?? ?? ?? A1 ?? ?? ?? ?? A3 ?? ?? ?? ?? 6A 00 6A 00 - } - $negt_body_and_infector_4 = { - FF 75 F4 FF 75 FC E8 63 03 00 00 6A 00 8D 45 F0 50 68 F8 00 00 00 68 ?? ?? ?? ?? FF 75 FC E8 51 03 00 00 83 6D F4 0B 6A - 00 6A 00 FF 75 F4 FF 75 FC E8 38 03 00 00 6A 00 8D 45 F0 50 6A 0B 68 ?? ?? ?? ?? FF 75 FC E8 29 03 00 00 6A 00 6A 20 6A - 03 6A 00 6A 01 68 00 00 00 80 68 ?? ?? ?? ?? E8 C8 02 00 00 89 45 F8 6A 00 6A 00 6A 00 FF 75 F8 E8 F9 02 00 00 6A 00 8D - 45 F0 50 68 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 FF 75 F8 E8 D3 02 00 00 8B 75 F0 6A 02 6A 00 6A 00 FF 75 FC E8 CE 02 00 00 - 6A 00 8D 45 F0 50 56 8D 85 ?? ?? ?? ?? 50 FF 75 FC E8 BE 02 00 00 FF 75 FC E8 62 02 00 00 FF 75 F8 E8 5A 02 00 00 59 C9 - C2 04 00 E8 00 00 00 00 5D 81 ED ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 68 00 01 00 00 FF B5 ?? ?? ?? ?? 6A 00 - FF 95 ?? ?? ?? ?? 6A 00 6A 20 6A 03 6A 00 6A 01 68 00 00 00 80 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A - 00 6A 20 6A 02 6A 00 6A 03 68 00 00 00 C0 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A 00 FF B5 ?? ?? ?? - ?? FF 95 ?? ?? ?? ?? 2D ?? ?? ?? ?? 6A 00 6A 00 50 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 6A 00 8D 85 ?? ?? ?? ?? 50 68 00 - 01 00 00 FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 83 FB 00 74 1E 8D 85 ?? ?? ?? ?? 6A 00 - 50 53 FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? EB B7 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? - FF 95 ?? ?? ?? ?? 6A 00 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 03 85 ?? ?? ?? ?? 50 C3 - } - $negt_infector = { - E8 00 00 00 00 5D 81 ED ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 68 00 01 00 00 FF B5 ?? ?? ?? ?? 6A 00 FF 95 ?? - ?? ?? ?? 6A 00 6A 20 6A 03 6A 00 6A 01 68 00 00 00 80 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A 00 6A 20 - 6A 02 6A 00 6A 03 68 00 00 00 C0 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 6A 00 FF B5 ?? ?? ?? ?? FF 95 - ?? ?? ?? ?? 2D ?? ?? ?? ?? 6A 00 6A 00 50 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 6A 00 8D 85 ?? ?? ?? ?? 50 68 00 01 00 00 - FF B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 83 FB 00 74 1E 8D 85 ?? ?? ?? ?? 6A 00 50 53 FF - B5 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? EB B7 FF B5 ?? ?? ?? ?? FF 95 ?? ?? ?? ?? FF B5 ?? ?? ?? ?? FF 95 ?? - ?? ?? ?? 6A 00 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 03 85 ?? ?? ?? ?? 50 C3 - } + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "f3d82cae74db83b7a49c5ec04d1a95c3b17ab1b935de24ca5c34e9b99db36803" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" + + strings: + $a = { FD 00 00 00 FD 34 FD FD 04 40 FD 04 FD FD 7E 14 FD 78 14 1F 0F } condition: - uint16(0)==0x5A4D and (($negt_infector at pe.entry_point) or (($negt_body_and_infector_1 at pe.entry_point) and $negt_body_and_infector_2 and $negt_body_and_infector_3 and $negt_body_and_infector_4)) + all of them } -import "pe" +rule ELASTIC_Linux_Trojan_Mirai_07B1F4F6 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "07b1f4f6-9324-48ab-9086-b738fdaf47c3" + date = "2022-09-12" + modified = "2022-10-18" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1882-L1900" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "2382996a8fd44111376253da227120649a1a94b5c61739e87a4e8acc1130e662" + logic_hash = "4af1a20e29e0c9b62e1530031e49a3d7b37d4e9a547d89a270a2e59e0c7852cc" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "bebafc3c8e68b36c04dc9af630b81f9d56939818d448759fdd83067e4c97e87a" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" -rule REVERSINGLABS_Win32_Virus_Greenp : TC_DETECTION MALICIOUS MALWARE FILE + strings: + $a = { FD 08 FD 5C 24 48 66 FD 07 66 FD 44 24 2E 66 FD FD 08 66 FD 47 } + + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Mirai_Feaa98Ff : FILE MEMORY { meta: - description = "Yara rule that detects Greenp virus." - author = "ReversingLabs" - id = "5751e91c-652b-59bd-93b8-ece677ad4911" - date = "2020-07-15" - modified = "2020-07-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/virus/Win32.Virus.Greenp.yara#L3-L46" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "ca6df34ee2ad9d93e35b0d1a2d4765f681f3981ffe2786bbc822c3090212fd02" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "feaa98ff-6cd9-40bb-8c4f-ea7c79b272f3" + date = "2022-09-12" + modified = "2022-10-18" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1902-L1920" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "2382996a8fd44111376253da227120649a1a94b5c61739e87a4e8acc1130e662" + logic_hash = "06be9d8bcfcb7e6b600103cf29fa8a94a457ff56e8c7018336c270978a57ccbf" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Virus" - tc_detection_name = "Greenp" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "0bc8ba390a11e205624bc8035b1d1e22337a5179a81d354178fa2546c61cdeb0" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $greenp_body_1 = { - 68 ?? ?? ?? ?? 60 FC E8 4E 05 00 00 E8 31 04 00 00 0F 82 93 00 00 00 80 BD ?? ?? ?? ?? 01 75 63 FF 95 ?? ?? ?? ?? 6A 01 - 50 FF 95 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 68 ?? ?? ?? ?? 6A 00 6A 00 FF 95 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 83 EC 18 8B FC - 6A 00 6A 00 6A 00 57 FF 95 ?? ?? ?? ?? 85 C0 74 10 57 FF 95 ?? ?? ?? ?? 57 FF 95 ?? ?? ?? ?? EB DF 68 ?? ?? ?? ?? 6A 00 - FF 95 ?? ?? ?? ?? 83 C4 18 EB 27 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? ?? 85 C0 75 16 8D 85 ?? ?? ?? ?? 50 FF 95 ?? ?? ?? - ?? 85 C0 74 05 E8 81 00 00 00 61 58 FF E0 ?? E8 04 00 00 00 [4] 8B 3C 24 81 EC 00 01 00 00 8B F4 56 68 00 01 00 00 FF - 95 ?? ?? ?? ?? AC AA 81 C4 00 01 00 00 FF 95 ?? ?? ?? ?? 83 F8 03 75 2D 83 EC 10 8B F4 56 8D 46 04 50 8D 46 08 50 8D 46 - 0C 50 4F 57 FF 95 ?? ?? ?? ?? 8B 46 04 2B D2 F7 66 08 F7 66 0C 83 C4 10 3D 00 00 40 06 C3 [27] 81 EC ?? ?? ?? ?? 8B F4 - 68 ?? ?? ?? ?? 56 FF 95 ?? ?? ?? ?? 8D BD ?? ?? ?? ?? 8A 17 88 14 06 40 47 80 FA 00 75 F4 68 ?? ?? ?? ?? 6A 00 FF 95 ?? - ?? ?? ?? 97 56 57 B9 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? E8 3A 02 00 00 5F B8 ?? ?? ?? ?? 99 68 ?? ?? ?? ?? 59 F7 F1 40 F7 E1 - 8B 57 3C 03 D7 0F B7 5A 14 8D 5C 13 40 8B 72 28 03 72 34 89 B5 ?? ?? ?? ?? C7 42 10 80 67 D5 40 FF 73 10 01 43 10 8B 43 - 10 05 ?? ?? ?? ?? 89 43 08 58 03 43 0C 89 42 28 52 B8 ?? ?? ?? ?? 99 68 ?? ?? ?? ?? 59 F7 F1 40 F7 E1 5A 01 43 10 01 42 - 50 81 42 50 ?? ?? ?? ?? 57 C6 85 ?? ?? ?? ?? 01 81 C7 ?? ?? ?? ?? 8D B5 ?? ?? ?? ?? B9 ?? ?? ?? ?? FC F3 A4 C6 85 ?? ?? - ?? ?? 00 5F 5E 6A 00 6A 00 6A 02 6A 00 6A 00 68 00 00 00 C0 56 FF 95 ?? ?? ?? ?? 93 50 8B C4 6A 00 50 B8 ?? ?? ?? ?? 99 - } - $greenp_body_2 = { - 68 ?? ?? ?? ?? 59 F7 F1 40 F7 E1 50 57 53 FF 95 ?? ?? ?? ?? 58 57 FF 95 ?? ?? ?? ?? 53 FF 95 ?? ?? ?? ?? 6A 00 56 FF 95 - ?? ?? ?? ?? 50 50 8B FC 8D 57 04 2B C0 52 57 50 68 3F 00 0F 00 50 50 50 8D 85 ?? ?? ?? ?? 50 68 02 00 00 80 FF 95 ?? ?? - ?? ?? 85 C0 75 1E 6A 0C 56 6A 01 6A 00 8D 85 ?? ?? ?? ?? 50 FF 37 FF 95 ?? ?? ?? ?? FF 37 FF 95 ?? ?? ?? ?? 81 C4 ?? ?? - ?? ?? C3 - } + $a = { 0F FD FD FD FD FD FD 7A 03 41 74 5E 42 31 FD FD 6E FD FD FD FD } condition: - uint16(0)==0x5A4D and ($greenp_body_1 at pe.entry_point) and $greenp_body_2 + all of them } -rule REVERSINGLABS_Bytecode_MSIL_Backdoor_Menorah : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_3Acd6Ed4 : FILE MEMORY { meta: - description = "Yara rule that detects Menorah backdoor." - author = "ReversingLabs" - id = "4f13a6c6-bd97-58aa-ac3b-399866b5c63b" - date = "2024-05-10" - modified = "2024-05-10" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/ByteCode.MSIL.Backdoor.Menorah.yara#L1-L169" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "770aefca192ceb3a778c0b1259105ace8e64cb35d0c34acb15c45fb6f22ad94b" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "3acd6ed4-6d62-47af-8d80-d5465abce38a" + date = "2022-09-12" + modified = "2022-10-18" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1922-L1940" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "2644447de8befa1b4fe39b2117d49754718a2f230d6d5f977166386aa88e7b84" + logic_hash = "ab284d41af8e1920fa54ac8bfab84bac493adf816aebce60490ab22c0e502201" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "Menorah" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "e787989c37c26d4bb79c235150a08bbf3c4c963e2bc000f9a243a09bbf1f59cb" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $send_fingerprint_to_c2_p1 = { - 28 ?? ?? ?? ?? 04 6F ?? ?? ?? ?? 02 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A - 73 ?? ?? ?? ?? 19 1F 0E 6F ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 1F 5B 13 ?? 12 ?? 28 ?? ?? - ?? ?? 1F 40 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F 40 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F 5D 13 ?? - 12 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 1B 8D ?? ?? ?? ?? 25 16 1F 5B 13 ?? 12 ?? 28 ?? - ?? ?? ?? A2 25 17 1F 40 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 06 A2 25 19 1F 40 13 ?? - 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 5D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 0B 28 ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 0C 72 ?? ?? ?? ?? 0D 1F 3F 13 ?? 12 - ?? 28 ?? ?? ?? ?? 17 16 28 ?? ?? ?? ?? 1F 3D 13 ?? 12 ?? 28 ?? ?? ?? ?? 17 16 28 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 03 11 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 74 ?? ?? ?? ?? - 13 ?? 11 ?? 1F 50 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F 4F 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F 53 - 13 ?? 12 ?? 28 ?? ?? ?? ?? 1F 54 13 ?? 12 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? - ?? ?? 11 ?? 1F 21 8D ?? ?? ?? ?? 25 16 1F 61 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F - 70 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 1F 70 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F - 6C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F - 63 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F 61 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1D 1F - 74 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 09 - } - $send_fingerprint_to_c2_p2 = { - 1F 6F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0A 1F 6E 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 - 1F 0B 1F 2F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0C 1F 78 13 ?? 12 ?? 28 ?? ?? ?? ?? - A2 25 1F 0D 1F 2D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0E 1F 77 13 ?? 12 ?? 28 ?? ?? - ?? ?? A2 25 1F 0F 1F 77 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 10 1F 77 13 ?? 12 ?? 28 - ?? ?? ?? ?? A2 25 1F 11 1F 2D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 12 1F 66 13 ?? 12 - ?? 28 ?? ?? ?? ?? A2 25 1F 13 1F 6F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 14 1F 72 13 - ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 15 1F 6D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 16 1F - 2D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 17 1F 75 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F - 18 1F 72 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 19 1F 6C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 - 25 1F 1A 1F 65 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 1B 1F 6E 13 ?? 12 ?? 28 ?? ?? ?? - ?? A2 25 1F 1C 1F 63 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 1D 1F 6F 13 ?? 12 ?? 28 ?? - ?? ?? ?? A2 25 1F 1E 1F 64 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 1F 1F 65 13 ?? 12 ?? - 28 ?? ?? ?? ?? A2 25 1F 20 1F 64 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 11 ?? 08 8E 69 6A 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 25 08 16 08 8E 69 6F - ?? ?? ?? ?? 6F ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 25 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 25 - 6F ?? ?? ?? ?? 0D 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 13 ?? DE ?? 26 7E ?? ?? ?? ?? 13 - ?? DE ?? 11 - } - $get_files_and_directories_p1 = { - 11 ?? 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 11 ?? 8E 69 17 31 ?? - 11 ?? 17 9A 13 ?? 11 ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 1F 0F 8D - ?? ?? ?? ?? 25 16 1F 44 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F 69 13 ?? 12 ?? 28 ?? - ?? ?? ?? A2 25 18 1F 72 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F 65 13 ?? 12 ?? 28 ?? - ?? ?? ?? A2 25 1A 1F 63 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F 74 13 ?? 12 ?? 28 ?? - ?? ?? ?? A2 25 1C 1F 6F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1D 1F 72 13 ?? 12 ?? 28 ?? - ?? ?? ?? A2 25 1E 1F 79 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 09 1F 20 13 ?? 12 ?? 28 - ?? ?? ?? ?? A2 25 1F 0A 1F 6F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0B 1F 66 13 ?? 12 - ?? 28 ?? ?? ?? ?? A2 25 1F 0C 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0D 11 ?? A2 - 25 1F 0E 72 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 - ?? ?? ?? ?? 13 ?? 11 ?? 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 73 ?? ?? ?? ?? - 13 ?? 1F 0B 8D ?? ?? ?? ?? 25 16 11 ?? A2 25 17 11 ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 1F - 16 8D ?? ?? ?? ?? 25 16 1F 4D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F 4D 13 ?? 12 ?? - 28 ?? ?? ?? ?? A2 25 18 1F 2F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F 64 13 ?? 12 ?? - 28 ?? ?? ?? ?? A2 25 1A 1F 64 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F 2F 13 ?? 12 ?? - 28 ?? ?? ?? ?? A2 25 1C 1F 79 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1D 1F 79 13 ?? 12 - } - $get_files_and_directories_p2 = { - 28 ?? ?? ?? ?? A2 25 1E 1F 79 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F ?? 1F 79 13 ?? 12 - ?? 28 ?? ?? ?? ?? A2 25 1F 0A 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0B 1F 68 13 - ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0C 1F 68 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0D 1F - 3A 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0E 1F 6D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F - 0F 1F 6D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 10 1F 3A 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 - 25 1F 11 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 12 1F 73 13 ?? 12 ?? 28 ?? ?? ?? - ?? A2 25 1F 13 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 14 1F 74 13 ?? 12 ?? 28 ?? - ?? ?? ?? A2 25 1F 15 1F 74 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 1F 3C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 44 - 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F 49 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F 52 - 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1D 1F 3E 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 72 ?? - ?? ?? ?? A2 25 1F 09 11 ?? 6F ?? ?? ?? ?? A2 25 1F 0A 72 ?? ?? ?? ?? A2 28 ?? ?? ?? - ?? 13 ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 11 ?? 13 ?? 16 13 ?? 38 - ?? ?? ?? ?? 11 ?? 11 ?? 9A 73 ?? ?? ?? ?? 13 ?? 1F 0C 8D ?? ?? ?? ?? 25 16 11 ?? A2 - 25 17 11 ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 1F 16 8D ?? ?? ?? ?? 25 16 1F 4D 13 ?? 12 ?? - 28 ?? ?? ?? ?? A2 25 17 1F 4D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 1F 2F 13 ?? 12 ?? - 28 ?? ?? ?? ?? A2 25 19 1F 64 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 64 13 ?? 12 ?? - 28 ?? ?? ?? ?? A2 25 1B 1F 2F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F 79 13 ?? 12 ?? - 28 ?? ?? ?? ?? A2 25 1D 1F 79 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 1F 79 13 ?? 12 ?? - 28 ?? ?? ?? ?? A2 25 1F 09 1F 79 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0A 1F 20 13 - } - $get_files_and_directories_p3 = { - 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0B 1F 68 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0C 1F 68 - 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0D 1F 3A 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0E - 1F 6D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0F 1F 6D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 - 1F 10 1F 3A 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 11 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? - A2 25 1F 12 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 13 1F 20 13 ?? 12 ?? 28 ?? ?? - ?? ?? A2 25 1F 14 1F 74 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 15 1F 74 13 ?? 12 ?? 28 - ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 25 18 72 ?? ?? ?? ?? A2 25 19 1F 46 - 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 49 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F 4C - 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F 45 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1D 72 ?? - ?? ?? ?? A2 25 1E 11 ?? 6F ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 09 72 ?? - ?? ?? ?? A2 25 1F 0A 11 ?? 6F ?? ?? ?? ?? A2 25 1F 0B 72 ?? ?? ?? ?? A2 28 ?? ?? ?? - ?? 13 ?? 11 ?? 17 58 13 ?? 11 ?? 11 ?? 8E 69 3F ?? ?? ?? ?? 1F 0B 8D ?? ?? ?? ?? 25 - 16 11 ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 11 ?? 8E 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 - 25 19 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 44 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 - 25 1B 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F 72 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 - 25 1D 1F 28 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 - 25 1F 09 1F 29 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0A 72 ?? ?? ?? ?? A2 28 ?? ?? ?? - ?? 13 ?? 1F 0B 8D ?? ?? ?? ?? 25 16 11 ?? A2 25 17 72 ?? ?? ?? ?? A2 25 18 11 ?? 8E - 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F - } - $upload_file_to_c2_p1 = { - 11 ?? 28 ?? ?? ?? ?? 13 ?? 72 ?? ?? ?? ?? 13 ?? 11 ?? 8E 69 17 3E ?? ?? ?? ?? 11 ?? - 17 9A 17 8D ?? ?? ?? ?? 25 16 1F 22 9D 6F ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 39 - ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 02 28 ?? ?? ?? ?? - 13 ?? 1F 0D 8D ?? ?? ?? ?? 25 16 1F 75 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F 40 13 - ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 11 ?? A2 25 19 1F 40 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 - 25 1A 28 ?? ?? ?? ?? A2 25 1B 1F 7C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 28 ?? ?? ?? - ?? A2 25 1D 1F 40 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 11 ?? A2 25 1F 09 1F 40 13 ?? - 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0A 1F 32 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0B 1F 40 - 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0C 11 ?? 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 13 ?? - 02 02 7B ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 26 1F 1E 8D ?? ?? ?? ?? 25 16 1F 66 13 ?? - 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 1F 6C 13 ?? - 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F 65 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F 5B 13 ?? - 12 ?? 28 ?? ?? ?? ?? A2 25 1B 11 ?? A2 25 1C 1F 5D 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 - 1D 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1E 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 - 1F 09 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0A 1F 20 13 ?? 12 ?? 28 - } - $upload_file_to_c2_p2 = { - A2 25 1F 0B 1F 75 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0C 1F 70 13 ?? 12 ?? 28 ?? ?? - ?? ?? A2 25 1F 0D 1F 6C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 0E 1F 6F 13 ?? 12 ?? 28 - ?? ?? ?? ?? A2 25 1F 0F 1F 61 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 10 1F 64 13 ?? 12 - ?? 28 ?? ?? ?? ?? A2 25 1F 11 1F 65 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 12 1F 64 13 - ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 13 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 14 1F - 74 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 15 1F 6F 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F - 16 1F 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 17 1F 73 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 - 25 1F 18 1F 65 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 19 1F 72 13 ?? 12 ?? 28 ?? ?? ?? - ?? A2 25 1F 1A 1F 76 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 1B 1F 65 13 ?? 12 ?? 28 ?? - ?? ?? ?? A2 25 1F 1C 1F 72 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1F 1D 1F 2E 13 ?? 12 ?? - 28 ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 1F 0F 8D ?? ?? ?? ?? 25 16 1F - 66 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 17 1F 69 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 18 1F - 6C 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 19 1F 65 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1A 1F - 20 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1B 1F 6E 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 25 1C 1F - } + $a = { E5 7E 44 4C 89 E3 31 FF 48 C1 E3 05 48 03 5D 38 48 89 2B 44 88 } condition: - uint16(0)==0x5A4D and ( all of ($send_fingerprint_to_c2_p*)) and ( all of ($get_files_and_directories_p*)) and ( all of ($upload_file_to_c2_p*)) + all of them } -rule REVERSINGLABS_Win32_Backdoor_Minodo : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Mirai_Eb940856 : FILE MEMORY { meta: - description = "Yara rule that detects Minodo backdoor." - author = "ReversingLabs" - id = "0eeff863-1a46-5b25-8780-5cd887e3b1e2" - date = "2023-06-07" - modified = "2023-06-07" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/Win64.Backdoor.Minodo.yara#L1-L110" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "807408699fe00c8d1170598050e533dd0d79bb170f2538b6b6227cda7410060b" + description = "Detects Linux Trojan Mirai (Linux.Trojan.Mirai)" + author = "Elastic Security" + id = "eb940856-60d2-4148-9126-aac79a24828e" + date = "2022-09-12" + modified = "2022-10-18" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mirai.yar#L1942-L1960" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "fbf814c04234fc95b6a288b62fb9513d6bbad2e601b96db14bb65ab153e65fef" + logic_hash = "d7bb2373a35ea97a11513e80e9a561f53a8f0b9345f392e8e7f042d4cb2d7d20" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "Minodo" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "01532c6feda3487829ad005232d30fe7dde5e37fd7cecd2bb9586206554c90a7" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $generate_system_id = { - 40 55 53 56 57 41 56 48 8D 6C 24 ?? 48 81 EC ?? ?? ?? ?? 4C 8B F1 48 8D 55 ?? 48 8D - 4D ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 33 DB 85 C0 75 ?? 66 C7 45 ?? ?? ?? 4C - 8D 45 ?? 48 8D 55 ?? B9 ?? ?? ?? ?? C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 - ?? 66 C7 45 ?? ?? ?? 48 83 4D ?? ?? 4C 8D 4D ?? 4C 8D 45 ?? 8B CB 48 8B D3 BE ?? ?? - ?? ?? 48 85 D2 7E ?? 44 8A 54 15 ?? EB ?? 44 8A 95 ?? ?? ?? ?? 41 8A 01 49 FF C1 48 - FF C2 32 44 15 ?? 41 32 C2 41 32 00 49 FF C0 88 44 15 ?? 41 38 19 75 ?? 83 C9 ?? 4C - 8D 4D ?? 41 38 18 75 ?? 83 C9 ?? 4C 8D 45 ?? 48 3B D6 75 ?? 83 C9 ?? 48 8B D3 83 F9 - ?? 75 ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4D ?? FF 15 ?? ?? ?? ?? 48 8D 5D ?? 49 8B FE 44 - 0F B6 03 48 8D 55 ?? 48 8B CF FF 15 ?? ?? ?? ?? 48 83 C7 ?? 48 FF C3 48 FF CE 75 ?? - FF 15 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4D ?? 8B D8 FF 15 ?? ?? ?? ?? 48 8D 55 - ?? 44 8B CB 4D 8B C6 49 8B CE FF 15 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 41 5E 5F 5E 5B - 5D C3 - } - $generate_encrypt_and_send_key = { - 48 8B C4 48 89 58 ?? 48 89 68 ?? 48 89 70 ?? 48 89 78 ?? 41 56 48 81 EC ?? ?? ?? ?? - 8B F2 E8 ?? ?? ?? ?? 48 85 C0 75 ?? 33 C0 E9 ?? ?? ?? ?? 48 8B 40 ?? 48 8B 08 8B 09 - E8 ?? ?? ?? ?? 48 8B F8 48 85 C0 74 ?? 45 33 C0 45 8D 70 ?? 41 8D 50 ?? 41 8B CE E8 - ?? ?? ?? ?? 48 8B D8 83 F8 ?? 74 ?? 41 8D 6E ?? 48 8D 44 24 ?? 8B CD C6 00 ?? 48 FF - C0 48 FF C9 75 ?? 0F B7 CE 66 44 89 74 24 ?? E8 ?? ?? ?? ?? 48 8B CF 66 89 44 24 ?? - E8 ?? ?? ?? ?? 48 63 FB 48 8D 54 24 ?? 48 8B CF 44 8B C5 89 44 24 ?? E8 ?? ?? ?? ?? - 85 C0 74 ?? 48 8B CF E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 2D ?? ?? ?? ?? BE ?? ?? ?? - ?? 48 8B CD 8B D6 E8 ?? ?? ?? ?? 66 C7 44 24 ?? ?? ?? 33 C9 8A 44 29 ?? 48 FF C9 88 - 44 0C ?? 48 FF CE 75 ?? 8D 56 ?? 44 8D 46 ?? 48 8D 4C 24 ?? E8 ?? ?? ?? ?? 48 8B CF - 8B F0 85 C0 74 ?? 48 8D 54 24 ?? 45 33 C9 44 8B C0 E8 ?? ?? ?? ?? 3B C6 74 ?? 48 8B - CF E8 ?? ?? ?? ?? 33 DB 8B C3 4C 8D 9C 24 ?? ?? ?? ?? 49 8B 5B ?? 49 8B 6B ?? 49 8B - 73 ?? 49 8B 7B ?? 49 8B E3 41 5E C3 - } - $get_encrypt_and_send_system_info = { - 48 89 5C 24 ?? 48 89 74 24 ?? 48 89 7C 24 ?? 55 48 8D 6C 24 ?? 48 81 EC ?? ?? ?? ?? - 8B F1 48 8B CA 48 8B DA FF 15 ?? ?? ?? ?? C6 44 24 ?? ?? 48 63 F8 40 88 7C 24 ?? 4C - 8B C7 85 C0 74 ?? 48 8D 44 24 ?? 48 2B D8 48 8D 4C 24 ?? 49 FF C8 4A 8D 0C 01 8A 04 - 0B 88 01 75 ?? 83 C7 ?? 48 63 DF E8 ?? ?? ?? ?? BA ?? ?? ?? ?? F6 D8 48 8D 45 ?? 1A - C9 80 E1 ?? 80 C9 ?? FF C7 88 4C 1C ?? 8B CA C6 00 ?? 48 FF C0 48 FF C9 75 ?? 48 8D - 4D ?? 89 55 ?? FF 15 ?? ?? ?? ?? 8A 45 ?? 48 63 CF 88 44 0C ?? 8A 45 ?? FF C7 48 63 - CF FF C7 BB ?? ?? ?? ?? 88 44 0C ?? 8A 45 ?? 48 63 CF 88 44 0C ?? 8A 45 ?? FF C7 48 - 63 CF FF C7 4C 8D 85 ?? ?? ?? ?? 88 44 0C ?? 8A 45 ?? 48 63 D7 88 44 14 ?? 8B 45 ?? - FF C7 48 63 D7 8D 4B ?? C6 44 24 ?? ?? 89 44 14 ?? 48 8D 54 24 ?? 83 C7 ?? 89 9D ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? ?? ?? 44 8B C0 8D 48 ?? 03 CF - 48 63 D1 48 83 FA ?? 76 ?? 44 8D 43 ?? 44 2B C7 48 63 C7 FF C7 4C 8D 54 24 ?? 44 88 - 44 04 ?? 48 63 C7 49 63 D0 4C 03 D0 45 85 C0 74 ?? 4C 8D 4C 24 ?? 4A 8D 0C 12 4D 2B - CA 48 FF C9 41 8A 04 09 88 01 48 FF CA 75 ?? 48 8D 95 ?? ?? ?? ?? 48 8D 4C 24 ?? 41 - 03 F8 C6 44 24 ?? ?? 89 9D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 4C 24 ?? FF 15 ?? ?? - ?? ?? 44 8B C0 8D 48 ?? 03 CF 48 63 D1 48 83 FA ?? 76 ?? 41 B8 ?? ?? ?? ?? 44 2B C7 - 48 63 C7 FF C7 4C 8D 54 24 ?? 44 88 44 04 ?? 48 63 C7 49 63 D0 4C 03 D0 45 85 C0 74 - ?? 4C 8D 4C 24 ?? 4A 8D 0C 12 4D 2B CA 48 FF C9 42 8A 04 09 88 01 48 FF CA 75 ?? 4C - 8D 4C 24 ?? 48 8D 54 24 ?? 44 03 C7 8B CE E8 ?? ?? ?? ?? 4C 8D 9C 24 ?? ?? ?? ?? 49 - 8B 5B ?? 49 8B 73 ?? 49 8B 7B ?? 49 8B E3 5D C3 - } - $copy_payload_into_allocated_memory = { - 48 89 5C 24 ?? 48 89 6C 24 ?? 56 57 41 56 48 83 EC ?? 49 8B D8 48 63 F2 48 8B F9 41 - C6 00 ?? C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 75 ?? 66 C7 03 ?? ?? B8 ?? ?? - ?? ?? E9 ?? ?? ?? ?? 4C 8D 4C 24 ?? 4C 8D 44 24 ?? 48 8B D3 48 8B CF E8 ?? ?? ?? ?? - 8B E8 85 C0 74 ?? 41 B9 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 8B D6 33 C9 4C 8B F6 FF 15 - ?? ?? ?? ?? 48 8B F0 48 85 C0 75 ?? 66 C7 03 ?? ?? FF 15 ?? ?? ?? ?? 89 43 ?? 8D 46 - ?? EB ?? 4D 8B C6 48 8B D7 48 8B C8 E8 ?? ?? ?? ?? 48 83 64 24 ?? ?? 83 64 24 ?? ?? - 4C 8D 04 2E 45 33 C9 33 D2 33 C9 FF 15 ?? ?? ?? ?? 48 8B C8 FF 15 ?? ?? ?? ?? 8B 44 - 24 ?? 48 8B 5C 24 ?? 48 8B 6C 24 ?? 48 83 C4 ?? 41 5E 5F 5E C3 - } - $execute_payload_from_temp = { - 40 53 48 81 EC ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 4C 8B D1 48 8D 44 24 ?? 41 8B D0 33 DB - 88 18 48 FF C0 48 FF CA 75 ?? 48 8D 44 24 ?? 8D 4A ?? 88 18 48 FF C0 48 FF C9 75 ?? - 48 8D 44 24 ?? 44 89 44 24 ?? 45 33 C9 48 89 44 24 ?? 48 8D 44 24 ?? 45 33 C0 48 89 - 44 24 ?? 48 89 5C 24 ?? 48 89 5C 24 ?? 49 8B D2 89 5C 24 ?? C7 84 24 ?? ?? ?? ?? ?? - ?? ?? ?? 89 5C 24 ?? 66 89 9C 24 ?? ?? 00 00 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 4C - 24 ?? FF 15 ?? ?? ?? ?? 48 8B 4C 24 ?? FF 15 ?? ?? ?? ?? B0 ?? EB ?? 32 C0 48 81 C4 - ?? ?? ?? ?? 5B C3 - } + $a = { 84 24 80 00 00 00 31 C9 EB 23 48 89 4C 24 38 48 8D 84 24 C8 00 } condition: - uint16(0)==0x5A4D and ($generate_system_id) and ($generate_encrypt_and_send_key) and ($get_encrypt_and_send_system_info) and ($copy_payload_into_allocated_memory) and ($execute_payload_from_temp) + all of them } -rule REVERSINGLABS_Linux_Backdoor_Linodas : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Windows_Hacktool_Sleepobfloader_460A1A75 : FILE MEMORY { meta: - description = "Yara rule that detects Linodas backdoor." - author = "ReversingLabs" - id = "2b197346-abce-5cff-938f-bb8742e03168" - date = "2024-05-22" - modified = "2024-05-22" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/Linux.Backdoor.Linodas.yara#L1-L216" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "12445771106e36b74b1ea292a8a25cab66bcaf0a08cf88d39a9f1bb13c6f525b" + description = "Detects Windows Hacktool Sleepobfloader (Windows.Hacktool.SleepObfLoader)" + author = "Elastic Security" + id = "460a1a75-7242-41d6-8b39-51f2f0276a33" + date = "2024-01-24" + modified = "2024-01-29" + reference = "https://www.elastic.co/security-labs/unmasking-financial-services-intrusion-ref0657" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_SleepObfLoader.yar#L1-L22" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "84b3bc58ec04ab272544d31f5e573c0dd7812b56df4fa445194e7466f280e16d" + logic_hash = "c0bc1b7ef71c1a91fc487f904315c6f187530ab39825f90f55ac36625d5b93cf" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "Linodas" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "8dbba5af9f379ac16a79b4989067b8715e084490ae2f048eb3a28d8d33c716e9" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "windows" strings: - $persistence_mechanism_ubuntu = { - 41 54 BE ?? ?? ?? ?? 55 53 48 81 EC ?? ?? ?? ?? 48 8D 6C 24 ?? 48 8D 54 24 ?? 48 89 - EF E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 5C 24 ?? 48 - 89 EE 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 48 - 81 FB ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8D 6C 24 ?? 48 8D 54 24 ?? BE ?? ?? ?? ?? 48 - 89 EF E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 5C 24 ?? - 48 89 EE 48 89 DF E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? - 48 81 FB ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 8D 5C 24 ?? 48 89 EE 48 89 DF E8 ?? ?? ?? - ?? 48 89 DF E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 41 BC ?? ?? ?? ?? 48 83 EB ?? 4C 39 E3 0F - 85 ?? ?? ?? ?? 4C 8B 44 24 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 E7 - E8 ?? ?? ?? ?? 48 89 E7 E8 ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 E7 E8 ?? ?? ?? ?? 85 C0 - 74 ?? 48 8B 4C 24 ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 - 8D 5C 24 ?? 4C 8B 44 24 ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 - ?? ?? ?? ?? 48 89 DE 48 89 E7 E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DC 0F - 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 E7 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 4C 24 ?? BA - ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 5C 24 ?? 4C 8B 44 24 - ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 89 DE 48 - 89 E7 E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DC 0F 85 ?? ?? ?? ?? BE ?? ?? - ?? ?? 48 89 E7 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 4C 24 ?? BA ?? ?? ?? ?? BE ?? ?? ?? - ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 1C 24 48 83 EB ?? 49 39 DC 0F 85 ?? ?? ?? ?? - 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DC 0F 85 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 - 39 DC 0F 85 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5D 41 5C C3 - } - $network_communication_1 = { - 48 89 5C 24 ?? 48 89 6C 24 ?? 48 89 F3 4C 89 64 24 ?? 4C 89 6C 24 ?? 48 81 EC ?? ?? - ?? ?? 48 8B 06 48 89 FD 89 54 24 ?? 45 89 C4 48 83 78 ?? ?? 0F 84 ?? ?? ?? ?? 4C 8D - 6C 24 ?? 48 8B 33 4C 89 EF E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 83 78 ?? ?? 0F 84 ?? ?? - ?? ?? 45 84 E4 0F 85 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 88 45 - ?? 80 7D ?? ?? 0F 84 ?? ?? ?? ?? C6 45 ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 F8 ?? 89 C5 0F 84 ?? ?? ?? ?? 48 8D 4C 24 ?? 41 B8 ?? ?? ?? - ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 89 C7 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? - ?? ?? ?? 48 8D 5C 24 ?? E8 ?? ?? ?? ?? 48 8D 4C 24 ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? - 41 B8 ?? ?? ?? ?? 89 EF 48 C7 44 24 ?? ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 48 8B 7C 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 48 C7 44 24 ?? ?? ?? - ?? ?? 66 C1 C8 ?? 66 C7 44 24 ?? ?? ?? 66 89 44 24 ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? - 89 44 24 ?? 48 89 DE 89 EF E8 ?? ?? ?? ?? 83 C0 ?? 0F 84 ?? ?? ?? ?? 0F 1F 44 00 ?? - 48 8B 5C 24 ?? 48 83 EB ?? 48 81 FB ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 89 E8 48 8B 5C 24 - ?? 48 8B 6C 24 ?? 4C 8B 64 24 ?? 4C 8B AC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 - } - $network_communication_2 = { - 48 89 5C 24 ?? 48 89 6C 24 ?? 48 89 FB 4C 89 64 24 ?? BE ?? ?? ?? ?? 48 83 EC ?? BF - ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 74 ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? - ?? ?? ?? 48 8D 73 ?? 48 8D 53 ?? BF ?? ?? ?? ?? 48 8D 6C 24 ?? 45 31 E4 E8 ?? ?? ?? - ?? 48 89 DF E8 ?? ?? ?? ?? 48 8B 73 ?? 48 89 EF E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 83 - 78 ?? ?? 74 ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? - 4C 8D 64 24 ?? 48 89 EE 4C 89 E7 E8 ?? ?? ?? ?? 4C 89 E6 48 89 DF E8 ?? ?? ?? ?? 48 - 8B 6C 24 ?? 41 89 C4 48 83 ED ?? 48 81 FD ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 45 84 E4 74 - ?? 80 7B ?? ?? 0F 84 ?? ?? ?? ?? 90 48 89 DF E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 41 0F B6 - EC 48 83 EB ?? 48 81 FB ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 89 E8 48 8B 5C 24 ?? 48 8B 6C - 24 ?? 4C 8B 64 24 ?? 48 83 C4 ?? C3 - } - $persistence_mechanism_redhat_v11 = { - 41 57 41 56 41 55 41 54 55 53 48 83 EC ?? 48 8D 7C 24 ?? E8 ?? ?? ?? ?? 48 8B 6C 24 - ?? 8B 7D ?? 4C 8D 7D ?? 81 C7 ?? ?? ?? ?? 48 63 FF E8 ?? ?? ?? ?? 48 89 C3 48 8D 7C - 24 ?? 48 89 EE E8 ?? ?? ?? ?? 4C 8B 6C 24 ?? BE ?? ?? ?? ?? 48 89 DF 31 C0 4C 8D 74 - 24 ?? 4C 89 EA E8 ?? ?? ?? ?? 48 98 48 8D 54 24 ?? 48 89 DE C6 04 18 ?? 4C 89 F7 E8 - ?? ?? ?? ?? 48 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 74 ?? 4C 89 E9 4C 89 EA BE ?? - ?? ?? ?? 48 89 DF 49 89 E9 4D 89 E8 31 C0 E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 41 89 C4 B9 - ?? ?? ?? ?? 89 C2 48 89 DE E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 - 0F 85 ?? ?? ?? ?? 48 8B 54 24 ?? 48 89 DF BE ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 48 89 - DF E8 ?? ?? ?? ?? 4C 89 EA BE ?? ?? ?? ?? 48 89 DF 31 C0 48 8D 6C 24 ?? E8 ?? ?? ?? - ?? 48 98 48 8D 54 24 ?? 48 89 DE C6 04 18 ?? 48 89 EF E8 ?? ?? ?? ?? 48 89 E7 31 C9 - BA ?? ?? ?? ?? 48 89 EE E8 ?? ?? ?? ?? 48 8B 6C 24 ?? 41 BE ?? ?? ?? ?? 4C 8B 24 24 - 48 83 ED ?? 4C 39 F5 0F 85 ?? ?? ?? ?? BE ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? 48 85 - C0 0F 84 ?? ?? ?? ?? 48 89 DF 49 8D 5C 24 ?? E8 ?? ?? ?? ?? 49 39 DE 0F 85 ?? ?? ?? - ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DE 0F 85 ?? ?? ?? ?? 49 8D 5D ?? 49 39 DE 0F 85 - ?? ?? ?? ?? 49 81 FF ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? 48 83 C4 ?? 5B 5D 41 5C 41 5D 41 - 5E 41 5F C3 - } - $change_timestamp_and_read_config_v11 = { - 55 53 48 83 EC ?? 48 8D 5C 24 ?? 48 89 E7 E8 ?? ?? ?? ?? 48 89 E6 48 89 DF E8 ?? ?? - ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 48 81 FB ?? ?? ?? ?? 0F 85 - ?? ?? ?? ?? 48 89 E6 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 1C 24 BE ?? ?? ?? ?? 48 89 - DF E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 83 C0 ?? 89 C5 29 DD 8D 7D ?? 48 63 FF E8 ?? ?? - ?? ?? 48 63 D5 48 89 C3 48 89 C7 C6 04 02 ?? 48 8B 34 24 E8 ?? ?? ?? ?? 48 89 DF E8 - ?? ?? ?? ?? 48 89 DE 48 89 C2 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? - BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 1C 24 B8 ?? ?? ?? - ?? 48 83 EB ?? 48 39 D8 75 ?? 48 83 C4 ?? 5B 5D C3 - } - $generate_machine_id_v11 = { - 41 57 BE ?? ?? ?? ?? 49 89 FF 41 56 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 8D 9C - 24 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 4C 8D AC 24 ?? ?? ?? - ?? 31 C9 BA ?? ?? ?? ?? 48 89 DE 4C 89 EF E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 41 - BE ?? ?? ?? ?? 48 83 EB ?? 4C 39 F3 0F 85 ?? ?? ?? ?? 4C 8D A4 24 ?? ?? ?? ?? 48 8B - B4 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? 48 8B 84 24 - ?? ?? ?? ?? 48 83 78 ?? ?? 0F 84 ?? ?? ?? ?? 48 8D 9C 24 ?? ?? ?? ?? 48 8D 94 24 ?? - ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 31 C9 BA ?? - ?? ?? ?? 48 89 DE 48 89 EF E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 - DE 0F 85 ?? ?? ?? ?? 48 89 EE 4C 89 E7 E8 ?? ?? ?? ?? 48 8B B4 24 ?? ?? ?? ?? 48 8D - BC 24 ?? ?? ?? ?? 48 8B 56 ?? E8 ?? ?? ?? ?? 31 FF 4C 8B AC 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 89 C7 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 C6 48 8D BC 24 ?? ?? ?? - ?? F7 EA 89 F1 89 F5 C1 F9 ?? C1 FA ?? 29 CA 69 D2 ?? ?? ?? ?? 29 D5 E8 ?? ?? ?? ?? - 48 8B 9C 24 ?? ?? ?? ?? 41 89 E8 31 C0 4C 89 E9 BE ?? ?? ?? ?? 48 89 E7 48 89 DA 48 - 83 EB ?? E8 ?? ?? ?? ?? 49 39 DE 89 C5 0F 85 ?? ?? ?? ?? 48 63 C5 48 8D 94 24 ?? ?? - ?? ?? 48 8D BC 24 ?? ?? ?? ?? C6 04 04 ?? 48 89 E6 E8 ?? ?? ?? ?? 48 8D 94 24 ?? ?? - ?? ?? 48 89 E6 4C 89 FF E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DE - 0F 85 ?? ?? ?? ?? 49 8D 5D ?? 49 39 DE 0F 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 - 83 EB ?? 49 39 DE 0F 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DE 0F - 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DE 0F 85 ?? ?? ?? ?? 48 81 - C4 ?? ?? ?? ?? 4C 89 F8 5B 5D 41 5C 41 5D 41 5E 41 5F C3 - } - $persistence_mechanism_redhat_v7 = { - 48 89 6C 24 ?? 4C 89 7C 24 ?? 48 89 5C 24 ?? 4C 89 64 24 ?? 4C 89 6C 24 ?? 4C 89 74 - 24 ?? 48 81 EC ?? ?? ?? ?? 48 8D 7C 24 ?? E8 ?? ?? ?? ?? 48 8B 6C 24 ?? 8B 7D ?? 4C - 8D 7D ?? 81 C7 ?? ?? ?? ?? 48 63 FF E8 ?? ?? ?? ?? 48 89 C3 48 8D 7C 24 ?? 48 89 EE - E8 ?? ?? ?? ?? 4C 8B 64 24 ?? BE ?? ?? ?? ?? 48 89 DF 31 C0 4C 8D 74 24 ?? 4C 89 E2 - E8 ?? ?? ?? ?? 48 98 48 8D 54 24 ?? 48 89 DE C6 04 18 ?? 4C 89 F7 E8 ?? ?? ?? ?? 48 - 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 74 ?? 4C 89 E1 4C 89 E2 BE ?? ?? ?? ?? 48 89 - DF 49 89 E9 4D 89 E0 31 C0 E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 41 89 C5 B9 ?? ?? ?? ?? 89 - C2 48 89 DE E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 31 F6 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? - ?? 48 8B 54 24 ?? 48 89 DF BE ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? - ?? 4C 89 E2 BE ?? ?? ?? ?? 48 89 DF 31 C0 E8 ?? ?? ?? ?? 48 98 48 89 E7 31 C9 C6 04 - 18 ?? BA ?? ?? ?? ?? 48 89 DE E8 ?? ?? ?? ?? 48 8B 2C 24 BE ?? ?? ?? ?? 48 89 EF E8 - ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 48 89 DF 48 8D 5D ?? BD ?? ?? ?? ?? E8 ?? ?? - ?? ?? 48 39 EB 0F 85 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 48 39 DD 0F 85 ?? ?? ?? - ?? 49 8D 5C 24 ?? 48 39 DD 0F 85 ?? ?? ?? ?? 49 81 FF ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? - 48 8B 5C 24 ?? 48 8B 6C 24 ?? 4C 8B 64 24 ?? 4C 8B AC 24 ?? ?? ?? ?? 4C 8B B4 24 ?? - ?? ?? ?? 4C 8B BC 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 - } - $get_device_name_v7 = { - 48 89 5C 24 ?? 48 89 6C 24 ?? BE ?? ?? ?? ?? 4C 89 64 24 ?? 4C 89 6C 24 ?? B9 ?? ?? - ?? ?? 4C 89 74 24 ?? 48 81 EC ?? ?? ?? ?? 4C 8B 05 ?? ?? ?? ?? 48 8D 5C 24 ?? BA ?? - ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 89 DE BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 5C 24 - ?? 41 BD ?? ?? ?? ?? 48 83 EB ?? 4C 39 EB 0F 85 ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 - 83 78 ?? ?? 75 ?? 48 8D 5C 24 ?? 48 89 DF E8 ?? ?? ?? ?? 48 89 DE BF ?? ?? ?? ?? E8 - ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? - ?? 48 8B 15 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 7C 24 ?? - E8 ?? ?? ?? ?? 4C 8B 64 24 ?? 48 89 E7 E8 ?? ?? ?? ?? 48 8B 2C 24 48 8D 5C 24 ?? 41 - B8 ?? ?? ?? ?? 4C 89 E2 BE ?? ?? ?? ?? 31 C0 48 89 DF 48 89 E9 E8 ?? ?? ?? ?? 48 89 - DE BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 48 8D 5D ?? 49 39 DD 0F 85 ?? ?? ?? ?? 49 8D 5C 24 ?? 49 39 DD 0F - 85 ?? ?? ?? ?? 48 8B 5C 24 ?? 48 8B 6C 24 ?? 4C 8B 64 24 ?? 4C 8B 6C 24 ?? 4C 8B B4 - 24 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 - } - $generate_machine_id_v7 = { - 41 57 31 C9 BA ?? ?? ?? ?? BE ?? ?? ?? ?? 49 89 FF 41 56 41 55 41 54 55 53 48 81 EC - ?? ?? ?? ?? 4C 8D A4 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? - 48 8B B4 24 ?? ?? ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 EF E8 ?? ?? ?? ?? 48 8B - 84 24 ?? ?? ?? ?? 48 83 78 ?? ?? 0F 84 ?? ?? ?? ?? 48 8D 9C 24 ?? ?? ?? ?? 31 C9 BA - ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 48 89 DE 48 89 EF E8 ?? ?? ?? ?? - 48 8B B4 24 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? 48 8B 56 ?? E8 ?? ?? ?? ?? 31 FF 4C - 8B B4 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 C7 E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? - ?? 89 C6 48 8D BC 24 ?? ?? ?? ?? F7 EA 89 F1 89 F5 C1 F9 ?? C1 FA ?? 29 CA 69 D2 ?? - ?? ?? ?? 29 D5 E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 41 89 E8 31 C0 4C 89 F1 BE ?? - ?? ?? ?? 48 89 E7 41 BD ?? ?? ?? ?? 48 89 DA 48 83 EB ?? E8 ?? ?? ?? ?? 4C 39 EB 89 - C5 0F 85 ?? ?? ?? ?? 48 63 C5 48 8D 94 24 ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? C6 04 - 04 ?? 48 89 E6 E8 ?? ?? ?? ?? 48 8D 94 24 ?? ?? ?? ?? 48 89 E6 4C 89 FF E8 ?? ?? ?? - ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? ?? 49 8D 5E ?? 49 39 - DD 0F 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? ?? - 48 8B 9C 24 ?? ?? ?? ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? - ?? 48 83 EB ?? 49 39 DD 0F 85 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 4C 89 F8 5B 5D 41 5C - 41 5D 41 5E 41 5F C3 - } + $a = { BA 01 00 00 00 41 B8 20 01 00 00 8B 48 3C 8B 4C 01 28 48 03 C8 48 89 0D ?? ?? ?? ?? FF ?? ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? B9 01 00 00 00 } + $b = { 8A 50 20 83 60 24 F0 80 E2 F8 48 8B ?? ?? ?? 4C 8B ?? ?? ?? 48 89 08 48 8B ?? ?? ?? 48 89 48 08 } + $c = { 8B 46 FB 41 89 40 18 0F B7 46 FF 66 41 89 40 1C 8A 46 01 41 88 40 1E } condition: - uint32(0)==0x464C457F and (($persistence_mechanism_ubuntu) and ( all of ($network_communication_*)) and ((($change_timestamp_and_read_config_v11) and ($persistence_mechanism_redhat_v11) and ($generate_machine_id_v11)) or (($persistence_mechanism_redhat_v7) and ($get_device_name_v7) and ($generate_machine_id_v7)))) + all of them } -rule REVERSINGLABS_Win64_Backdoor_Sidetwist : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Windows_Trojan_Systembc_5E883723 : FILE MEMORY { meta: - description = "Yara rule that detects SideTwist backdoor." - author = "ReversingLabs" - id = "979b442e-8739-54a8-b486-39fc5673791e" - date = "2024-03-18" - modified = "2024-03-18" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/Win64.Backdoor.SideTwist.yara#L1-L154" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "811fa73ede59493c71435743848a3fce3a1604ec4065ffcb0b43e9715dfa5c31" + description = "Detects Windows Trojan Systembc (Windows.Trojan.SystemBC)" + author = "Elastic Security" + id = "5e883723-7eaa-4992-91de-abb0ffbba54e" + date = "2022-03-22" + modified = "2022-04-12" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_SystemBC.yar#L1-L24" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b432805eb6b2b58dd957481aa8a973be58915c26c04630ce395753c6a5196b14" + logic_hash = "fde2e0b5debd4d26838fb245fdf8e5103ab5aab9feff900cbba00c1950adc61a" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "SideTwist" - tc_detection_factor = 5 - importance = 25 + quality = 50 + tags = "FILE, MEMORY" + fingerprint = "add95c1f4bb279c8b189c3d64a0c2602c73363ebfad56a4077119af148dd2d87" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "windows" strings: - $anti_sandbox_detect_environment = { - 55 57 56 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 89 4D ?? 48 89 55 ?? E8 ?? - ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? 48 C7 45 ?? ?? ?? ?? ?? 48 8D 55 ?? 48 8D 45 ?? 4C - 8D 05 ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF D0 85 C0 75 ?? 48 8B 45 ?? 48 85 - C0 74 ?? B8 ?? ?? ?? ?? EB ?? B8 ?? ?? ?? ?? 84 C0 0F 84 ?? ?? ?? ?? 48 8D 45 ?? 48 - 89 C1 E8 ?? ?? ?? ?? 48 8B 55 ?? 48 8D 4D ?? 48 8D 45 ?? 49 89 C8 48 89 C1 E8 ?? ?? - ?? ?? 48 8D 45 ?? 48 8D 55 ?? 4C 8D 05 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 - ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 89 C1 - E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF - D0 85 C0 0F 94 C0 84 C0 74 ?? 48 8D 05 ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF - D0 BB ?? ?? ?? ?? BE ?? ?? ?? ?? EB - } - $collect_host_information = { - 55 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 4D ?? 48 89 55 ?? C7 45 ?? - ?? ?? ?? ?? 8B 45 ?? 89 C0 48 BA ?? ?? ?? ?? ?? ?? ?? ?? 48 39 C2 72 ?? 48 01 C0 48 - 89 C1 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 - 8B 45 ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? - 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8B 45 ?? 49 89 D0 48 89 C2 B9 ?? - ?? ?? ?? 48 8B 05 ?? ?? ?? ?? FF D0 85 C0 0F 95 C0 84 C0 0F 84 ?? ?? ?? ?? 48 8D 45 - ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 4D ?? 48 8B 55 ?? 48 8D 45 ?? 49 89 C8 48 89 C1 E8 - ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? - 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 - 89 C2 48 8D 4D ?? 48 8D 45 ?? 49 89 C9 49 89 D8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? - 48 8D 55 ?? 41 B9 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? - 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? - 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 - ?? ?? ?? ?? 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 84 C0 74 ?? 48 8B 45 ?? 48 8D 15 ?? - ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 83 7D ?? ?? 0F 84 ?? ?? ?? ?? 48 8B 45 ?? 48 89 - C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 89 - C1 E8 ?? ?? ?? ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D - 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 - 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? - 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 90 48 8B 45 ?? 48 81 C4 ?? ?? ?? ?? 5B 5D C3 - } - $contact_c2_server = { - 55 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 4D ?? 48 89 55 ?? 48 8D 45 - ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8D 85 ?? ?? ?? ?? 49 89 D0 48 8D 15 ?? ?? - ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 8D 50 ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? - ?? ?? 48 8B 55 ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 4C 8D 45 - ?? 48 8B 55 ?? 48 8D 8D ?? ?? ?? ?? 48 89 4C 24 ?? 48 8D 4D ?? 48 89 4C 24 ?? 4D 89 - C1 4C 8D 05 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? - 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 - 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 C1 - E8 ?? ?? ?? ?? 85 C0 0F 95 C0 84 C0 74 ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? - ?? 48 8D 95 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 4D ?? 48 8D 55 ?? - 48 8B 45 ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? BB - ?? ?? ?? ?? EB ?? BB ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 89 D8 - EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 - C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? - 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 48 89 - C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? ?? ?? ?? 48 89 C1 - E8 ?? ?? ?? ?? 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5D C3 - } - $parse_c2_response = { - 55 53 48 83 EC ?? 48 8D 6C 24 ?? 48 89 4D ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 - 8D 55 ?? 48 8D 45 ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 - ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8B 45 ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? - ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 41 B8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 - ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 C1 48 8B 55 ?? 48 - 8B 45 ?? 49 89 C8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B - 55 ?? 48 01 C2 48 8B 45 ?? 49 89 D0 BA ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 - ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 - D8 48 89 C1 E8 ?? ?? ?? ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 - 89 C1 E8 ?? ?? ?? ?? 90 48 83 C4 ?? 5B 5D C3 - } - $download_file_from_c2_p1 = { - 55 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 4D ?? 48 89 55 ?? 4C 89 45 - ?? 4C 89 4D ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 5D ?? 48 8B 55 ?? - 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 95 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? - ?? 49 89 D0 48 89 C2 48 89 D9 E8 ?? ?? ?? ?? 85 C0 0F 95 C0 88 45 ?? 48 8D 85 ?? ?? - ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 0F B6 45 ?? 83 F0 ?? 84 C0 0F 84 ?? ?? ?? ?? 48 8D 85 - ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 45 ?? 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? - 48 89 C2 48 8D 85 ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 48 89 C1 48 8B 05 ?? ?? ?? ?? FF - D0 89 45 ?? 83 7D ?? ?? 0F 95 C0 84 C0 74 ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 - 8D 55 ?? 48 8B 45 ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 - ?? 48 89 C1 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 9D ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? - 48 89 C1 E8 ?? ?? ?? ?? 48 89 C2 48 8B 45 ?? 49 89 D9 49 89 D0 BA ?? ?? ?? ?? 48 89 - C1 E8 ?? ?? ?? ?? 48 8B 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 8D 45 ?? 48 - } - $download_file_from_c2_p2 = { - 89 C1 E8 ?? ?? ?? ?? 48 8D 55 ?? 48 8B 45 ?? 49 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 - E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 8D 45 ?? 48 8B 55 ?? 49 - 89 D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 8D 55 ?? 4C 8D 05 - ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8B 45 ?? 48 8B 4D ?? 48 8D 55 ?? 49 89 C8 48 - 89 C1 E8 ?? ?? ?? ?? 90 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 - ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 85 ?? - ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? - EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 - C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 - 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 48 8B - 45 ?? 48 81 C4 ?? ?? ?? ?? 5B 5D C3 - } - $reply_to_c2_server = { - 55 53 48 81 EC ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 4D ?? 48 89 55 ?? 4C 89 45 - ?? 4C 89 4D ?? 48 8B 55 ?? 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? - 48 8B 55 ?? 41 B8 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 8B 55 ?? 49 89 - D0 48 8D 15 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 8D 55 ?? 4C 8D 05 ?? - ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 8D 8D ?? ?? ?? ?? 48 8D 55 ?? 49 89 - C8 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 8D 55 ?? 4C 8D 05 ?? ?? ?? ?? 48 89 C1 E8 - ?? ?? ?? ?? 48 8D 55 ?? 48 8B 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 - ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? - 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? 48 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? EB - ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 - E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 8D 45 ?? 48 89 C1 E8 ?? ?? ?? ?? EB ?? 48 89 C3 48 - 8D 85 ?? ?? ?? ?? 48 89 C1 E8 ?? ?? ?? ?? 48 89 D8 48 89 C1 E8 ?? ?? ?? ?? 90 48 81 - C4 ?? ?? ?? ?? 5B 5D C3 - } + $a1 = "GET /tor/rendezvous2/%s HTTP/1.0" ascii fullword + $a2 = "https://api.ipify.org/" ascii fullword + $a3 = "KEY-----" ascii fullword + $a4 = "Host: %s" ascii fullword + $a5 = "BEGINDATA" ascii fullword + $a6 = "-WindowStyle Hidden -ep bypass -file \"" ascii fullword condition: - uint16(0)==0x5A4D and ($anti_sandbox_detect_environment) and ($collect_host_information) and ($contact_c2_server) and ($parse_c2_response) and ( all of ($download_file_from_c2_p*)) and ($reply_to_c2_server) + all of them } -rule REVERSINGLABS_Win64_Backdoor_Konni : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Windows_Trojan_Systembc_C1B58C2F : FILE MEMORY { meta: - description = "Yara rule that detects Konni backdoor." - author = "ReversingLabs" - id = "c45c23c6-be15-58cc-ae4d-631bed4a3bb2" - date = "2023-12-07" - modified = "2023-12-07" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/Win64.Backdoor.Konni.yara#L1-L205" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "37c45e3ed23ca9f4de876f666c9f6d9bf7eee5cb1650b02cdd9f58e2ccc4b5cb" + description = "Detects Windows Trojan Systembc (Windows.Trojan.SystemBC)" + author = "Elastic Security" + id = "c1b58c2f-8bbf-4c03-9f53-13ab2fb081cc" + date = "2024-05-02" + modified = "2024-05-08" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_SystemBC.yar#L26-L49" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "016fc1db90d9d18fe25ed380606346ef12b886e1db0d80fe58c22da23f6d677d" + logic_hash = "16ed14dac0c30500c5e91759b0a1b321f3bd53ae6aab1389a685582eba72c222" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "Konni" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "dfbf98554e7fb8660e4eebd6ad2fadc394fc2a4168050390370ec358f6af1c1d" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "windows" strings: - $network_communication_p1 = { - 48 8B C4 53 55 57 41 54 41 55 41 56 41 57 48 83 EC ?? 48 8B 3D ?? ?? ?? ?? 45 33 FF - 48 8B D9 4C 8D A7 ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? 49 8B CC 44 89 78 ?? 44 89 78 - ?? 45 8B F7 44 89 78 ?? 41 8B EF E8 ?? ?? ?? ?? 4C 8D 8F ?? ?? ?? ?? 4C 8D 05 ?? ?? - ?? ?? BA ?? ?? ?? ?? 49 8B CC 48 89 5C 24 ?? 48 89 7C 24 ?? E8 ?? ?? ?? ?? 48 8D 9F - ?? ?? ?? ?? 48 8B CB E8 ?? ?? ?? ?? 41 BD ?? ?? ?? ?? 45 33 C9 45 33 C0 33 C9 41 8B - D5 44 89 7C 24 ?? FF 15 ?? ?? ?? ?? 48 8B F8 48 89 44 24 ?? 48 85 C0 75 ?? 83 C8 ?? - 48 83 C4 ?? 41 5F 41 5E 41 5D 41 5C 5F 5D 5B C3 4C 89 7C 24 ?? 44 89 7C 24 ?? 41 B8 - ?? ?? ?? ?? 45 33 C9 48 8B D3 48 8B C8 C7 44 24 ?? ?? ?? ?? ?? 48 89 B4 24 ?? ?? ?? - ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 4C 89 7C 24 ?? FF 15 ?? ?? ?? ?? 48 8B F0 48 85 - C0 0F 84 ?? ?? ?? ?? 4C 89 7C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 45 - 33 C9 4D 8B C4 48 8B C8 4C 89 7C 24 ?? C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 4C 89 7C 24 - ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 85 C0 74 ?? 45 33 C9 45 33 C0 33 D2 48 8B C8 44 89 - 7C 24 ?? FF 15 ?? ?? ?? ?? 45 33 C9 45 33 C0 48 8B CB 85 C0 74 ?? 48 8D 94 24 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 45 33 C9 48 8B CB 45 33 C0 33 D2 FF 15 ?? ?? ?? - ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? - 41 8B C5 E9 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 85 C0 75 ?? 48 8B CB EB ?? FF C0 B9 ?? - ?? ?? ?? 8B D0 89 84 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 4C 8B E0 48 85 C0 74 ?? 44 8B - } - $network_communication_p2 = { - 84 24 ?? ?? ?? ?? 33 D2 48 8B C8 E8 ?? ?? ?? ?? 45 33 C9 4C 89 7C 24 ?? 48 8D 0D ?? - ?? ?? ?? 45 8D 41 ?? BA ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 4C 8B E8 48 8B CB 48 83 F8 ?? 75 ?? 45 33 C9 45 33 C0 33 D2 FF 15 - ?? ?? ?? ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? - ?? ?? ?? 83 C8 ?? E9 ?? ?? ?? ?? 44 8B 84 24 ?? ?? ?? ?? 4C 8D 8C 24 ?? ?? ?? ?? 49 - 8B D4 FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? BF ?? ?? ?? ?? 0F 1F 00 44 39 BC 24 - ?? ?? ?? ?? 74 ?? 48 8D 15 ?? ?? ?? ?? 49 8B CC 41 8B EF E8 ?? ?? ?? ?? 48 85 C0 0F - 45 EF 3B EF 74 ?? 44 8B 84 24 ?? ?? ?? ?? 4C 8D 8C 24 ?? ?? ?? ?? 49 8B D4 49 8B CD - 4C 89 7C 24 ?? FF 15 ?? ?? ?? ?? 44 8B 84 24 ?? ?? ?? ?? 44 03 B4 24 ?? ?? ?? ?? 33 - D2 49 8B CC E8 ?? ?? ?? ?? 44 8B 84 24 ?? ?? ?? ?? 4C 8D 8C 24 ?? ?? ?? ?? 49 8B D4 - 48 8B CB FF 15 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8B 7C 24 ?? 49 8B CD FF 15 ?? - ?? ?? ?? 49 8B CC FF 15 ?? ?? ?? ?? 45 33 C9 45 33 C0 33 D2 48 8B CB FF 15 ?? ?? ?? - ?? 48 8B CB FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? - 83 C8 ?? 45 85 F6 0F 44 E8 8B C5 48 8B B4 24 ?? ?? ?? ?? 48 83 C4 ?? 41 5F 41 5E 41 - 5D 41 5C 5F 5D 5B C3 - } - $handle_c2_commands_p1 = { - 48 89 5C 24 ?? 48 89 74 24 ?? 57 48 81 EC ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 - 48 89 84 24 ?? ?? ?? ?? 48 8D 35 ?? ?? ?? ?? 48 8D 54 24 ?? 33 FF 48 8B CE 89 7C 24 - ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 85 C0 75 ?? 83 C8 ?? E9 ?? ?? ?? ?? 48 8B 15 ?? ?? - ?? ?? 48 8B 08 E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 4B - ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 4B ?? 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 - 75 ?? 48 8B 4B ?? 8D 50 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8D 4C 24 ?? 33 D2 41 B8 - ?? ?? ?? ?? 66 89 7C 24 ?? E8 ?? ?? ?? ?? 48 8B 4B ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? - 48 8B 15 ?? ?? ?? ?? 48 8B 4B ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 53 ?? 48 8D 0D ?? - ?? ?? ?? 45 33 C0 FF 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? FF 15 ?? ?? ?? ?? E9 ?? ?? - ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 4B ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 4B ?? E8 ?? - ?? ?? ?? 69 C0 ?? ?? ?? ?? 89 05 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 - 8B 4B ?? E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 4B ?? E8 ?? ?? ?? ?? 69 C0 ?? ?? ?? ?? 89 - } - $handle_c2_commands_p2 = { - 05 ?? ?? ?? ?? E9 ?? ?? ?? ?? 48 63 4C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 8B 4C CB ?? E8 - ?? ?? ?? ?? 48 8B CE 85 C0 75 ?? 8D 50 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 D2 E8 ?? - ?? ?? ?? E9 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? 48 8B 0B E8 ?? ?? ?? ?? 48 63 4C 24 ?? - 48 8B 15 ?? ?? ?? ?? 48 8B 4C CB ?? 85 C0 75 ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 48 63 4C - 24 ?? 48 8D 15 ?? ?? ?? ?? 48 8B 4C CB ?? E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8B 3B 48 83 - C9 ?? 33 C0 66 F2 AF 33 D2 48 F7 D1 48 8D 0C 4E E8 ?? ?? ?? ?? EB ?? 48 8B 3B 48 83 - C9 ?? 33 C0 66 F2 AF 8D 50 ?? 48 F7 D1 48 8D 0C 4E E8 ?? ?? ?? ?? EB ?? E8 ?? ?? ?? - ?? 85 C0 75 ?? 8D 48 ?? EB ?? 33 C9 E8 ?? ?? ?? ?? 8B F8 48 8B CB FF 15 ?? ?? ?? ?? - 8B C7 48 8B 8C 24 ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 4C 8D 9C 24 ?? ?? ?? ?? 49 8B - 5B ?? 49 8B 73 ?? 49 8B E3 5F C3 - } - $create_cab_file_and_upload_p1 = { - 48 89 5C 24 ?? 55 56 57 41 54 41 57 48 8D AC 24 ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? 48 - 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 85 ?? ?? ?? ?? 4C 8B 3D ?? ?? ?? ?? 33 DB 48 8B F1 - 48 8D 4D ?? 33 D2 41 B8 ?? ?? ?? ?? 44 8B E3 89 5C 24 ?? 89 5C 24 ?? 66 89 5D ?? E8 - ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? 66 89 9D ?? ?? 00 00 E8 ?? - ?? ?? ?? 33 C0 48 8D 4C 24 ?? 66 89 5C 24 ?? 48 89 44 24 ?? 89 44 24 ?? 66 89 44 24 - ?? FF 15 ?? ?? ?? ?? 0F B7 54 24 ?? 0F B7 4C 24 ?? 44 0F B7 44 24 ?? 0F B7 44 24 ?? - 0F B7 7C 24 ?? 89 54 24 ?? 89 44 24 ?? 89 4C 24 ?? 89 7C 24 ?? 44 89 44 24 ?? 4C 8D - 05 ?? ?? ?? ?? 4C 8D 0D ?? ?? ?? ?? 48 8D 8D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? - ?? 48 8D 4D ?? 33 D2 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 55 ?? B9 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 4C 8D 4D ?? 48 8D 15 ?? ?? ?? ?? 48 8D 4D ?? 45 33 C0 FF 15 ?? ?? ?? - ?? 48 8D 4D ?? FF 15 ?? ?? ?? ?? 8D 53 ?? 48 8B CE E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? - ?? 48 8B C8 48 8B F8 E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8B CF E8 ?? - ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D - 15 ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8B CF E8 - ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 ?? ?? ?? ?? 48 8B CF E8 ?? ?? ?? ?? 85 C0 74 ?? 48 - } - $create_cab_file_and_upload_p2 = { - 8D 4D ?? 48 8B D6 E8 ?? ?? ?? ?? 83 F8 ?? 75 ?? 0B C0 E9 ?? ?? ?? ?? 48 8D 55 ?? 45 - 33 C0 48 8B CE FF 15 ?? ?? ?? ?? 45 33 C9 48 89 5C 24 ?? 48 8D 4D ?? 45 8D 41 ?? BA - ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 4C 89 AC 24 ?? ?? ?? ?? 89 5C 24 ?? C7 44 24 ?? - ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8B F8 48 83 F8 ?? 75 ?? 8B C3 EB ?? 33 D2 48 8B C8 - FF 15 ?? ?? ?? ?? 8B F0 85 C0 75 ?? 48 8B CF FF 15 ?? ?? ?? ?? 8B C3 EB ?? FF C6 B9 - ?? ?? ?? ?? 8B D6 44 8B EE FF 15 ?? ?? ?? ?? 4C 8B E0 48 85 C0 75 ?? 48 8B CF FF 15 - ?? ?? ?? ?? 8B C3 EB ?? 4D 8B C5 33 D2 48 8B C8 E8 ?? ?? ?? ?? 4C 8D 4C 24 ?? 44 8B - C6 49 8B D4 48 8B CF 48 89 5C 24 ?? FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 8B - 44 24 ?? 89 44 24 ?? 85 C0 75 ?? 83 C8 ?? E9 ?? ?? ?? ?? 48 8D 4D ?? 4C 89 B4 24 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 44 8B 6C 24 ?? B9 ?? ?? ?? ?? 41 83 C5 ?? 41 8B FD 41 8B - D5 48 89 7C 24 ?? FF 15 ?? ?? ?? ?? 4C 8B F0 48 85 C0 0F 84 ?? ?? ?? ?? 44 8B C7 33 - D2 48 8B C8 E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B F0 48 85 C0 74 ?? 33 - C0 48 83 C9 ?? 4C 8D 86 ?? ?? ?? ?? 48 8D BD ?? ?? ?? ?? 66 F2 AF 49 89 00 49 89 40 - ?? 48 F7 D1 49 89 40 ?? 49 89 40 ?? 48 FF C9 03 C9 74 ?? 8B D1 48 8D 8D ?? ?? ?? ?? - E8 ?? ?? ?? ?? EB ?? 48 8B F3 49 89 B7 ?? ?? ?? ?? 48 85 F6 0F 84 ?? ?? ?? ?? 44 8B - } - $create_cab_file_and_upload_p3 = { - 44 24 ?? 4D 8B CE 49 8B D4 48 8B CE 44 89 6C 24 ?? E8 ?? ?? ?? ?? 49 8B 8F ?? ?? ?? - ?? 48 85 C9 74 ?? E8 ?? ?? ?? ?? 49 8B CC 49 89 9F ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 - 83 C9 ?? 33 C0 48 8D BD ?? ?? ?? ?? 66 F2 AF 48 F7 D1 41 8D 84 4D ?? ?? ?? ?? B9 ?? - ?? ?? ?? 8B D0 89 44 24 ?? FF 15 ?? ?? ?? ?? 4C 8B E8 48 85 C0 0F 84 ?? ?? ?? ?? 44 - 8B 44 24 ?? 33 D2 48 8B C8 E8 ?? ?? ?? ?? 8B 54 24 ?? 4C 8D 8D ?? ?? ?? ?? 4C 8D 05 - ?? ?? ?? ?? 49 8B CD E8 ?? ?? ?? ?? 48 8B 7C 24 ?? 49 8B D6 8B C8 4C 8B C7 89 44 24 - ?? 49 03 CD E8 ?? ?? ?? ?? 8B 4C 24 ?? 48 8D 15 ?? ?? ?? ?? 48 03 CF 41 B8 ?? ?? ?? - ?? 49 03 CD E8 ?? ?? ?? ?? 49 8B CE FF 15 ?? ?? ?? ?? 49 8D 8F ?? ?? ?? ?? E8 ?? ?? - ?? ?? 45 33 C9 45 33 C0 41 8D 51 ?? 33 C9 89 5C 24 ?? FF 15 ?? ?? ?? ?? 48 8B F0 48 - 85 C0 0F 84 ?? ?? ?? ?? 48 89 5C 24 ?? 89 5C 24 ?? 49 8D 97 ?? ?? ?? ?? 41 B8 ?? ?? - ?? ?? 45 33 C9 48 8B C8 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 48 89 5C 24 - ?? FF 15 ?? ?? ?? ?? 4C 8B E0 48 85 C0 0F 84 ?? ?? ?? ?? 49 8D 8F ?? ?? ?? ?? 33 D2 - 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4D 8D 8F ?? ?? ?? ?? 4C 8D 05 ?? ?? ?? ?? 49 8D 8F - ?? ?? ?? ?? BA ?? ?? ?? ?? 4C 89 7C 24 ?? E8 ?? ?? ?? ?? 48 89 5C 24 ?? C7 44 24 ?? - ?? ?? ?? ?? 4D 8D 87 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? 45 33 C9 49 8B CC 48 89 5C 24 - ?? C7 44 24 ?? ?? ?? ?? ?? 48 89 5C 24 ?? FF 15 ?? ?? ?? ?? 48 8B F8 48 85 C0 74 - } - $create_cab_file_and_upload_p4 = { - 8B 44 24 ?? 48 8D 15 ?? ?? ?? ?? 4D 8B CD 41 B8 ?? ?? ?? ?? 48 8B CF 89 44 24 ?? FF - 15 ?? ?? ?? ?? 85 C0 74 ?? 49 8B CD FF 15 ?? ?? ?? ?? 48 8D 54 24 ?? 45 33 C9 45 33 - C0 48 8B CF FF 15 ?? ?? ?? ?? 85 C0 75 ?? 45 33 C9 45 33 C0 33 D2 48 8B CF FF 15 ?? - ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 49 8B CC FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? - ?? ?? B8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 74 ?? FF C0 B9 ?? ?? ?? ?? 8B - D0 89 44 24 ?? FF 15 ?? ?? ?? ?? 4C 8B E8 48 85 C0 75 ?? 45 33 C9 45 33 C0 33 D2 48 - 8B CF FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 49 8B CC FF 15 ?? ?? ?? ?? 48 8B - CE FF 15 ?? ?? ?? ?? 83 C8 ?? EB ?? 44 8B 44 24 ?? 33 D2 48 8B C8 E8 ?? ?? ?? ?? 44 - 8B 44 24 ?? 4C 8D 4C 24 ?? 49 8B D5 48 8B CF FF 15 ?? ?? ?? ?? 85 C0 74 ?? 48 8D 15 - ?? ?? ?? ?? 49 8B CD E8 ?? ?? ?? ?? EB ?? BB ?? ?? ?? ?? 49 8B CD FF 15 ?? ?? ?? ?? - 45 33 C9 45 33 C0 33 D2 48 8B CF FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 49 8B - CC FF 15 ?? ?? ?? ?? 48 8B CE FF 15 ?? ?? ?? ?? 8B C3 4C 8B B4 24 ?? ?? ?? ?? 4C 8B - AC 24 ?? ?? ?? ?? 48 8B 8D ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? - ?? 48 81 C4 ?? ?? ?? ?? 41 5F 41 5C 5F 5E 5D C3 - } - $cmd_expand_payload_p1 = { - 40 53 55 41 55 48 81 EC ?? ?? ?? ?? 48 8B 05 ?? ?? ?? ?? 48 33 C4 48 89 84 24 ?? ?? - ?? ?? 48 8B E9 48 8D 8C 24 ?? ?? ?? ?? 45 33 ED 33 D2 41 B8 ?? ?? ?? ?? 66 44 89 AC - 24 ?? ?? 00 00 E8 ?? ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? 66 44 - 89 AC 24 ?? ?? 00 00 E8 ?? ?? ?? ?? 45 8D 45 ?? 48 8D 4C 24 ?? 33 D2 44 89 6C 24 ?? - E8 ?? ?? ?? ?? 33 C0 4C 89 6C 24 ?? 45 8D 45 ?? 45 33 C9 BA ?? ?? ?? ?? 48 8B CD C7 - 44 24 ?? ?? ?? ?? ?? 4C 89 6C 24 ?? 48 89 44 24 ?? 48 89 44 24 ?? C7 44 24 ?? ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 75 ?? 0B C0 E9 ?? ?? ?? ?? 45 33 C9 33 - D2 48 8B C8 45 8D 41 ?? 4C 89 6C 24 ?? 48 89 BC 24 ?? ?? ?? ?? 44 89 6C 24 ?? FF 15 - ?? ?? ?? ?? 48 8B F8 48 85 C0 75 ?? 48 8B CB FF 15 ?? ?? ?? ?? 83 C8 ?? E9 ?? ?? ?? - ?? 45 33 C9 45 33 C0 48 8B C8 41 8D 51 ?? 48 89 B4 24 ?? ?? ?? ?? 4C 89 6C 24 ?? FF - 15 ?? ?? ?? ?? 48 8B F0 48 85 C0 75 ?? 48 8B CB FF 15 ?? ?? ?? ?? 83 C8 ?? E9 ?? ?? - ?? ?? 4C 8D 40 ?? 48 8D 84 24 ?? ?? ?? ?? 41 83 C9 ?? 33 D2 33 C9 C7 44 24 ?? ?? ?? - ?? ?? 48 89 44 24 ?? 4C 89 A4 24 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? - 33 D2 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 15 ?? ?? ?? ?? B9 ?? ?? ?? ?? FF 15 ?? - ?? ?? ?? 4C 8D 84 24 ?? ?? ?? ?? 48 8D 0D ?? ?? ?? ?? BA ?? ?? ?? ?? E8 - } - $cmd_expand_payload_p2 = { - 44 8B 66 ?? 48 8B CE FF 15 ?? ?? ?? ?? 48 8B CF FF 15 ?? ?? ?? ?? 48 8B CB FF 15 ?? - ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 33 D2 41 B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 8D 05 ?? - ?? ?? ?? 48 8D 8C 24 ?? ?? ?? ?? 4C 8B CD BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 44 24 - ?? 48 8D 94 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 8D 44 24 ?? 45 33 C9 48 89 44 24 ?? 4C - 89 6C 24 ?? 4C 89 6C 24 ?? 45 33 C0 33 C9 C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? 66 44 89 AC 24 ?? ?? 00 00 44 89 6C 24 ?? FF 15 ?? ?? ?? ?? 85 C0 75 ?? 83 C8 - ?? EB ?? 90 B9 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 45 33 C9 4C 89 6C 24 ?? 48 8D 0D ?? ?? - ?? ?? 45 8D 41 ?? BA ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 48 8B D8 48 83 F8 ?? 75 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 48 8B CB - FF 15 ?? ?? ?? ?? 41 8B C4 4C 8B A4 24 ?? ?? ?? ?? 48 8B B4 24 ?? ?? ?? ?? 48 8B BC - 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 48 33 CC E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? - 41 5D 5D 5B C3 - } + $a1 = "GET %s HTTP/1.0" ascii fullword + $a2 = "HOST1:" + $a3 = "PORT1:" + $a4 = "-WindowStyle Hidden -ep bypass -file \"" ascii fullword + $a5 = "BEGINDATA" ascii fullword + $a6 = "socks32.dll" ascii fullword condition: - uint16(0)==0x5A4D and ( all of ($network_communication_p*)) and ( all of ($handle_c2_commands_p*)) and ( all of ($create_cab_file_and_upload_p*)) and ( all of ($cmd_expand_payload_p*)) + 5 of them } -rule REVERSINGLABS_Bytecode_MSIL_Backdoor_Limerat : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Macos_Trojan_Fplayer_1C1Fae37 : FILE MEMORY { meta: - description = "Yara rule that detects LimeRAT backdoor." - author = "ReversingLabs" - id = "c2ef6f27-3fb8-55f4-97a6-9e25a3d1ce49" - date = "2024-03-04" - modified = "2024-03-04" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/ByteCode.MSIL.Backdoor.LimeRAT.yara#L1-L91" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "03eaa2ac41950f036601222b32a28c03aae3b3445501e988e2f87e231a1a1522" + description = "Detects Macos Trojan Fplayer (MacOS.Trojan.Fplayer)" + author = "Elastic Security" + id = "1c1fae37-8d19-4129-a715-b78163f93fd2" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Fplayer.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "f57e651088dee2236328d09705cef5e98461e97d1eb2150c372d00ca7c685725" + logic_hash = "0d65717bdbac694ffb2535a1ff584f7ec2aa7b553a08d29113c6e2bd7b2ff1aa" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "LimeRAT" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "abeb3cd51c0ff2e3173739c423778defb9a77bc49b30ea8442e6ec93a2d2d8d2" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "macos" strings: - $persistence_mechanism = { - 02 2C ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 16 16 15 28 ?? ?? ?? ?? 26 2B ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? - ?? ?? ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 28 ?? ?? - ?? ?? 28 ?? ?? ?? ?? DE - } - $crypto_miner = { - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 8E 69 16 31 ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 0B 07 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 08 6F ?? ?? ?? ?? 0D 2B ?? 09 6F ?? ?? - ?? ?? 74 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? ?? 0A DE ?? 09 6F ?? ?? ?? ?? 2D ?? DE ?? 09 2C ?? 09 - 6F ?? ?? ?? ?? DC DE ?? 25 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? DE ?? 28 ?? ?? ?? ?? - 0A DE ?? 25 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? DE ?? 06 - } - $downloader = { - 73 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 7E - ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 2C ?? 72 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 2C ?? 06 7E ?? ?? ?? ?? 07 6F ?? - ?? ?? ?? 07 28 ?? ?? ?? ?? 26 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 2B ?? - 06 7E ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 07 28 ?? ?? ?? ?? 26 00 06 6F ?? ?? ?? ?? 14 0A - DE ?? 25 28 ?? ?? ?? ?? 0C 28 ?? ?? ?? ?? DE ?? DE ?? 25 28 ?? ?? ?? ?? 0D 28 ?? ?? - ?? ?? DE - } - $network_communication_p1 = { - 16 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 0B 28 ?? ?? - ?? ?? DE ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 0C 28 ?? ?? ?? - ?? DE ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 0D 28 ?? ?? ?? ?? - DE ?? 00 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 7E ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 15 6F ?? ?? ?? ?? 7E ?? - ?? ?? ?? 15 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 73 ?? - ?? ?? ?? 13 ?? 11 ?? 11 ?? 6F ?? ?? ?? ?? 11 ?? 14 72 ?? ?? ?? ?? 17 8D ?? ?? ?? ?? - 25 16 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 14 14 14 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? - ?? ?? ?? 15 16 28 ?? ?? ?? ?? 13 ?? 11 ?? 16 9A 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 26 11 - ?? 73 ?? ?? ?? ?? 17 11 ?? 8E 69 6F ?? ?? ?? ?? 9A 28 ?? ?? ?? ?? 80 ?? ?? ?? ?? 11 - ?? 6F ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? DE ?? DE ?? 11 ?? 2C - ?? 11 ?? 6F ?? ?? ?? ?? DC 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? - ?? 17 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 1F ?? 8D ?? ?? ?? ?? 25 16 72 ?? - ?? ?? ?? A2 25 17 7E ?? ?? ?? ?? A2 25 18 28 ?? ?? ?? ?? A2 25 19 7E ?? ?? ?? ?? A2 - } - $network_communication_p2 = { - 25 1A 28 ?? ?? ?? ?? A2 25 1B 7E ?? ?? ?? ?? A2 25 1C 72 ?? ?? ?? ?? A2 25 1D 7E ?? - ?? ?? ?? A2 25 1E 28 ?? ?? ?? ?? A2 25 1F ?? 72 ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? - ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? - A2 25 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? ?? A2 - 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 - 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? 8C ?? ?? - ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? - ?? A2 25 1F ?? 72 ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 72 ?? ?? ?? ?? - A2 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? A2 - 25 1F ?? 7E ?? ?? ?? ?? A2 25 1F ?? 7E ?? ?? ?? ?? A2 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 7E ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 2B ?? 7E - } + $a = { 56 41 55 41 54 53 48 83 EC 48 4D 89 C4 48 89 C8 48 89 D1 49 89 F6 49 89 FD 49 } condition: - uint16(0)==0x5A4D and ($persistence_mechanism) and ($crypto_miner) and ($downloader) and ( all of ($network_communication_p*)) + all of them } -rule REVERSINGLABS_Win32_Backdoor_Konni : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Windows_Vulndriver_Mtcbsv_7F6D642E : FILE { meta: - description = "Yara rule that detects Konni backdoor." - author = "ReversingLabs" - id = "6fe230b1-357a-54f7-a9a8-15d0369fec71" - date = "2023-12-07" - modified = "2023-12-07" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/Win32.Backdoor.Konni.yara#L1-L190" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "7907a657d804d485718ba13bb23513de0b909e7d455c2b3ee193b5329edd3ac6" + description = "Name: mtcBSv64.sys, Version: 21.2.0.0" + author = "Elastic Security" + id = "7f6d642e-bf8c-44e7-939f-08513523ee2e" + date = "2022-04-07" + modified = "2022-04-07" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_MtcBsv.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "ff803017d1acafde6149fe7d463aee23b1c4f6f3b97c698c05f3ca6f07e4df6c" + logic_hash = "dfd53a2b97ad722307561fc5f109dcba372bf600113786bb351ed1262fdc8556" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "Konni" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE" + fingerprint = "f59ad8d5f19584e76e67689aba1e0d305d451ed6a030c6e2bccd048e0aeb0b0a" + threat_name = "Windows.VulnDriver.MtcBsv" + severity = 50 + arch_context = "x86" + scan_context = "file" + license = "Elastic License v2" + os = "windows" strings: - $network_communication_p1 = { - 55 8B EC 83 EC ?? 53 56 8B 35 ?? ?? ?? ?? 57 33 FF 68 ?? ?? ?? ?? 8D 9E ?? ?? ?? ?? - 57 53 89 7D ?? 89 7D ?? 89 7D ?? 89 7D ?? 89 7D ?? 89 5D ?? E8 ?? ?? ?? ?? 8B 45 ?? - 50 56 8D 8E ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? - 81 C6 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 57 57 57 6A ?? 57 FF 15 ?? ?? ?? ?? 8B D8 3B DF - 0F 84 ?? ?? ?? ?? 57 57 6A ?? 57 57 6A ?? 56 53 C7 45 ?? ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 8B F8 89 7D ?? 85 FF 75 ?? 53 FF 15 ?? ?? ?? ?? 8D 47 ?? 5F 5E 5B 8B E5 5D C2 ?? - ?? 8B 55 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 52 68 ?? ?? ?? ?? 57 C7 45 ?? ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 85 F6 75 ?? 8B 35 ?? ?? ?? ?? 57 FF D6 53 FF D6 5F - 5E B8 ?? ?? ?? ?? 5B 8B E5 5D C2 ?? ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? - 6A ?? 6A ?? 85 C0 74 ?? 8D 45 ?? 50 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 50 50 6A ?? 56 - FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 57 FF D6 53 FF D6 5F 5E B8 ?? ?? ?? ?? - 5B 8B E5 5D C2 ?? ?? 8B 45 ?? 85 C0 75 ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 56 8B 35 ?? - ?? ?? ?? FF D6 57 FF D6 53 FF D6 5F 5E 83 C8 ?? 5B 8B E5 5D C2 ?? ?? 40 50 6A ?? 89 - } - $network_communication_p2 = { - 45 ?? FF 15 ?? ?? ?? ?? 8B F8 85 FF 75 ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 56 8B 35 ?? - ?? ?? ?? FF D6 8B 4D ?? 51 FF D6 53 FF D6 5F 5E 83 C8 ?? 5B 8B E5 5D C2 ?? ?? 8B 55 - ?? 52 6A ?? 57 E8 ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? - ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 45 ?? 83 F8 ?? 75 ?? 6A ?? 6A ?? 6A ?? - 56 FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 8B 45 ?? 50 FF D6 53 FF D6 5F 5E 83 - C8 ?? 5B 8B E5 5D C2 ?? ?? 8B 55 ?? 8D 4D ?? 51 52 57 56 FF 15 ?? ?? ?? ?? 85 C0 74 - ?? 83 7D ?? ?? 74 ?? 68 ?? ?? ?? ?? 57 C7 45 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? - 85 C0 B8 ?? ?? ?? ?? 75 ?? 8B 45 ?? 89 45 ?? 83 F8 ?? 74 ?? 8B 4D ?? 8B 55 ?? 6A ?? - 8D 45 ?? 50 51 57 52 FF 15 ?? ?? ?? ?? 8B 4D ?? 8B 45 ?? 01 45 ?? 51 6A ?? 57 E8 ?? - ?? ?? ?? 8B 45 ?? 83 C4 ?? 8D 55 ?? 52 50 57 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 8B 4D - ?? 51 FF 15 ?? ?? ?? ?? 57 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? - 56 8B 35 ?? ?? ?? ?? FF D6 8B 55 ?? 52 FF D6 53 FF D6 83 7D ?? ?? 0F 84 ?? ?? ?? ?? - 8B 45 ?? 5F 5E 5B 8B E5 5D C2 - } - $handle_c2_commands_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 8D 85 ?? ?? ?? ?? - 50 33 FF 68 ?? ?? ?? ?? 89 BD ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 89 B5 ?? ?? ?? ?? - 3B F7 75 ?? 83 C8 ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 0D ?? ?? - ?? ?? 8B 16 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8B - 4E ?? 50 51 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 56 ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? - ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 4E ?? 6A ?? E8 ?? ?? ?? ?? 83 C4 ?? E9 ?? ?? ?? ?? 8B - 5E ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 33 C0 57 51 66 89 85 ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 46 ?? 52 50 E8 ?? ?? - ?? ?? 83 C4 ?? 85 C0 75 ?? 8B 4E ?? 57 51 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 68 ?? ?? - ?? ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 46 ?? 52 50 E8 ?? ?? ?? - ?? 83 C4 ?? 85 C0 75 ?? 8B 46 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 69 C0 ?? ?? ?? ?? A3 ?? - ?? ?? ?? E9 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B 56 ?? 51 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 - } - $handle_c2_commands_p2 = { - C0 75 ?? 8B 46 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 69 C0 ?? ?? ?? ?? A3 ?? ?? ?? ?? E9 ?? - ?? ?? ?? 8B 85 ?? ?? ?? ?? 8B 4C 86 ?? 68 ?? ?? ?? ?? 51 E8 ?? ?? ?? ?? 83 C4 ?? BE - ?? ?? ?? ?? 85 C0 75 ?? 8D 78 ?? E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? E9 ?? ?? ?? ?? 33 - FF E8 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 8B 06 52 50 E8 - ?? ?? ?? ?? 83 C4 ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 8B - 44 96 ?? 51 50 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 8D ?? ?? ?? ?? 8B 54 8E ?? 68 - ?? ?? ?? ?? 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B 06 8D 50 ?? 8B FF 66 8B 08 83 - C0 ?? 66 3B CF 75 ?? 2B C2 D1 F8 57 8D 3C 45 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB - ?? 8B 06 8D 50 ?? 66 8B 08 83 C0 ?? 66 3B CF 75 ?? 2B C2 D1 F8 6A ?? 8D 3C 45 ?? ?? - ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? EB ?? A1 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 8B 54 8E ?? 50 - 52 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 8D 48 ?? EB ?? 33 C9 E8 ?? ?? ?? ?? 8B F8 56 - FF 15 ?? ?? ?? ?? 8B 4D ?? 8B C7 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $create_cab_file_and_upload_p1 = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? A1 ?? ?? ?? ?? 53 56 57 33 - FF 68 ?? ?? ?? ?? 8B F1 8D 95 ?? ?? ?? ?? 33 C9 57 52 89 85 ?? ?? ?? ?? 89 BD ?? ?? - ?? ?? 89 BD ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 89 BD ?? ?? ?? ?? 66 89 8D ?? ?? ?? ?? E8 - ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 33 C0 57 51 66 89 85 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 33 C0 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 66 89 - 85 ?? ?? ?? ?? 83 C4 ?? 8D 85 ?? ?? ?? ?? 33 D2 50 66 89 95 ?? ?? ?? ?? FF 15 ?? ?? - ?? ?? 0F B7 8D ?? ?? ?? ?? 0F B7 95 ?? ?? ?? ?? 0F B7 85 ?? ?? ?? ?? 51 0F B7 8D ?? - ?? ?? ?? 52 0F B7 95 ?? ?? ?? ?? 50 51 52 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8D 85 ?? ?? - ?? ?? 68 ?? ?? ?? ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 57 - 51 E8 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D - 85 ?? ?? ?? ?? 50 57 68 ?? ?? ?? ?? 8B C8 51 FF 15 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 - FF 15 ?? ?? ?? ?? 6A ?? 56 E8 ?? ?? ?? ?? 8B D8 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 - C4 ?? 85 C0 0F 84 ?? ?? ?? ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? - 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? - ?? 83 C4 ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 68 ?? - ?? ?? ?? 53 E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 74 ?? 8B CE 8D BD ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 F8 ?? 75 ?? 83 C8 ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 57 8D - } - $create_cab_file_and_upload_p2 = { - 85 ?? ?? ?? ?? 50 56 FF 15 ?? ?? ?? ?? EB ?? 33 FF 8D 9D ?? ?? ?? ?? 8D 85 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 3B C7 74 ?? 8D 8D ?? ?? ?? ?? 51 FF 15 ?? ?? ?? - ?? 8B B5 ?? ?? ?? ?? 83 C6 ?? 56 6A ?? FF 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 3B C7 74 - ?? 56 57 50 E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D8 83 C4 ?? 3B - DF 74 ?? 8D 85 ?? ?? ?? ?? 8D 50 ?? EB ?? 8D 9B ?? ?? ?? ?? 66 8B 08 83 C0 ?? 66 3B - CF 75 ?? 2B C2 8D 93 ?? ?? ?? ?? D1 F8 8D 0C 00 33 C0 89 02 89 42 ?? 89 42 ?? 89 42 - ?? 89 42 ?? 89 42 ?? 89 42 ?? 89 42 ?? 3B CF 74 ?? 51 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? - ?? 83 C4 ?? 8B CB EB ?? 33 C9 8B 95 ?? ?? ?? ?? 89 8A ?? ?? ?? ?? 3B CF 0F 84 ?? ?? - ?? ?? 8B 85 ?? ?? ?? ?? 8B BD ?? ?? ?? ?? 8B 9D ?? ?? ?? ?? 56 50 E8 ?? ?? ?? ?? 8B - BD ?? ?? ?? ?? 8B 87 ?? ?? ?? ?? 85 C0 74 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 53 C7 87 ?? - ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 8D 50 ?? 8D 9B ?? ?? ?? ?? - 66 8B 08 83 C0 ?? 66 85 C9 75 ?? 2B C2 D1 F8 8D 84 46 ?? ?? ?? ?? 50 6A ?? 89 85 ?? - ?? ?? ?? FF 15 ?? ?? ?? ?? 8B D8 85 DB 0F 84 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 51 6A ?? - 53 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? 8D 95 ?? ?? ?? ?? 52 68 ?? ?? ?? ?? 50 - 53 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 56 89 85 ?? ?? ?? ?? 51 03 C3 50 E8 ?? ?? ?? ?? - 8B BD ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 03 FB 83 C4 ?? 03 FE B9 ?? ?? ?? ?? BE ?? ?? ?? - ?? 50 F3 A5 FF 15 ?? ?? ?? ?? 8B B5 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? 56 E8 - } - $create_cab_file_and_upload_p3 = { - 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? FF 15 ?? ?? ?? ?? 8B F8 85 FF 0F 84 ?? ?? ?? ?? 6A ?? - 6A ?? 6A ?? 6A ?? 6A ?? 6A ?? 56 57 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 89 85 ?? ?? ?? ?? 85 C0 75 ?? 57 FF 15 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5F 5E 5B 8B 4D ?? - 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B B5 ?? ?? ?? ?? 68 ?? ?? ?? ?? 81 C6 ?? ?? ?? ?? - 6A ?? 56 E8 ?? ?? ?? ?? 8B 85 ?? ?? ?? ?? 83 C4 ?? 50 05 ?? ?? ?? ?? 50 68 ?? ?? ?? - ?? 68 ?? ?? ?? ?? 56 E8 ?? ?? ?? ?? 8B 8D ?? ?? ?? ?? 83 C4 ?? 6A ?? 68 ?? ?? ?? ?? - 6A ?? 6A ?? 6A ?? 56 68 ?? ?? ?? ?? 51 C7 85 ?? ?? ?? ?? ?? ?? ?? ?? FF 15 ?? ?? ?? - ?? 8B F0 85 F6 75 ?? 8B 95 ?? ?? ?? ?? 8B 35 ?? ?? ?? ?? 52 FF D6 57 FF D6 B8 ?? ?? - ?? ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 85 ?? ?? ?? ?? 50 53 6A - ?? 68 ?? ?? ?? ?? 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 56 - 8B 35 ?? ?? ?? ?? FF D6 8B 8D ?? ?? ?? ?? 51 FF D6 57 FF D6 B8 ?? ?? ?? ?? 5F 5E 5B - 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 53 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 8D 95 ?? - ?? ?? ?? 52 56 FF 15 ?? ?? ?? ?? 85 C0 75 ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 56 8B 35 - ?? ?? ?? ?? FF D6 8B 85 ?? ?? ?? ?? 50 FF D6 57 FF D6 B8 ?? ?? ?? ?? 5F 5E 5B 8B 4D - ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 8B 85 ?? ?? ?? ?? 85 C0 75 ?? 50 50 50 56 FF 15 - ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? FF D6 8B 8D ?? ?? ?? ?? 51 FF D6 57 FF D6 83 C8 - } - $create_cab_file_and_upload_p4 = { - 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 40 50 6A ?? 89 85 ?? ?? ?? ?? FF - 15 ?? ?? ?? ?? 8B D8 85 DB 75 ?? 50 50 50 56 FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? ?? - FF D6 8B 95 ?? ?? ?? ?? 52 FF D6 57 FF D6 83 C8 ?? 5F 5E 5B 8B 4D ?? 33 CD E8 ?? ?? - ?? ?? 8B E5 5D C3 8B 85 ?? ?? ?? ?? 50 6A ?? 53 E8 ?? ?? ?? ?? 8B 95 ?? ?? ?? ?? 83 - C4 ?? 8D 8D ?? ?? ?? ?? 51 52 53 56 FF 15 ?? ?? ?? ?? 85 C0 74 ?? 68 ?? ?? ?? ?? 53 - E8 ?? ?? ?? ?? 83 C4 ?? 85 C0 75 ?? 89 85 ?? ?? ?? ?? EB ?? C7 85 ?? ?? ?? ?? ?? ?? - ?? ?? 53 FF 15 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 56 FF 15 ?? ?? ?? ?? 56 8B 35 ?? ?? ?? - ?? FF D6 8B 85 ?? ?? ?? ?? 50 FF D6 57 FF D6 8B 4D ?? 8B 85 ?? ?? ?? ?? 5F 5E 33 CD - 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } - $cmd_expand_payload = { - 55 8B EC 81 EC ?? ?? ?? ?? A1 ?? ?? ?? ?? 33 C5 89 45 ?? 53 56 57 68 ?? ?? ?? ?? 8B - D9 33 FF 8D 8D ?? ?? ?? ?? 33 C0 57 51 66 89 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? - ?? ?? 8D 85 ?? ?? ?? ?? 33 D2 57 50 66 89 95 ?? ?? ?? ?? E8 ?? ?? ?? ?? 6A ?? 8D 8D - ?? ?? ?? ?? 57 51 89 BD ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 57 68 ?? ?? ?? ?? 6A ?? - 57 6A ?? 33 C0 68 ?? ?? ?? ?? 53 89 BD ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 89 85 ?? ?? ?? - ?? 89 85 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B F0 83 FE ?? 74 ?? 57 57 57 6A ?? 57 56 FF - 15 ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 3B C7 75 ?? 56 FF 15 ?? ?? ?? ?? 83 C8 ?? 5F 5E 5B - 8B 4D ?? 33 CD E8 ?? ?? ?? ?? 8B E5 5D C3 57 57 57 6A ?? 50 FF 15 ?? ?? ?? ?? 8B F8 - 85 FF 74 ?? 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 52 6A ?? 8D 47 ?? 50 6A ?? 6A ?? FF 15 - ?? ?? ?? ?? 68 ?? ?? ?? ?? 6A ?? 68 ?? ?? ?? ?? E8 ?? ?? ?? ?? 83 C4 ?? 68 ?? ?? ?? - ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 51 68 ?? ?? ?? ?? 68 ?? ?? ?? - ?? E8 ?? ?? ?? ?? 8B 57 ?? 83 C4 ?? 57 89 95 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 8B 85 ?? - ?? ?? ?? 8B 3D ?? ?? ?? ?? 50 FF D7 56 FF D7 68 ?? ?? ?? ?? 8D 8D ?? ?? ?? ?? 6A ?? - 51 E8 ?? ?? ?? ?? 53 68 ?? ?? ?? ?? 8D 95 ?? ?? ?? ?? 68 ?? ?? ?? ?? 52 E8 ?? ?? ?? - ?? 83 C4 ?? 33 C0 8D 8D ?? ?? ?? ?? 51 8D 95 ?? ?? ?? ?? 52 50 50 68 ?? ?? ?? ?? 50 - 50 50 66 89 85 ?? ?? ?? ?? 8D 85 ?? ?? ?? ?? 50 6A ?? C7 85 ?? ?? ?? ?? ?? ?? ?? ?? - FF 15 ?? ?? ?? ?? 85 C0 0F 84 ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 68 ?? ?? ?? ?? FF D3 6A - ?? 68 ?? ?? ?? ?? 6A ?? 6A ?? 6A ?? 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? - 8B F0 83 FE ?? 75 ?? FF 15 ?? ?? ?? ?? 83 F8 ?? 75 ?? 56 FF D7 8B 4D ?? 8B 85 ?? ?? - ?? ?? 5F 5E 33 CD 5B E8 ?? ?? ?? ?? 8B E5 5D C3 - } + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 6D 00 74 00 63 00 42 00 53 00 76 00 36 00 34 00 2E 00 73 00 79 00 73 00 00 00 } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x02][\x00-\x00])([\x00-\x15][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x14][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x01][\x00-\x00])([\x00-\x15][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ condition: - uint16(0)==0x5A4D and ( all of ($network_communication_p*)) and ( all of ($handle_c2_commands_p*)) and ( all of ($create_cab_file_and_upload_p*)) and ($cmd_expand_payload) + int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version } -rule REVERSINGLABS_Bytecode_MSIL_Backdoor_Njrat : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Exploit_Moogrey_81131B66 : FILE MEMORY { meta: - description = "Yara rule that detects NjRAT backdoor." - author = "ReversingLabs" - id = "578c813f-4bba-52cd-bcc7-4de2c3943cf7" - date = "2024-07-31" - modified = "2024-07-31" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/ByteCode.MSIL.Backdoor.NjRAT.yara#L1-L266" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "eeecf90965e6952d8b9efc9d1e96eaa47709b1d69fc7d435f4aebaaf0191f317" + description = "Detects Linux Exploit Moogrey (Linux.Exploit.Moogrey)" + author = "Elastic Security" + id = "81131b66-788e-4456-9cb4-ffade713e8d4" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Moogrey.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "cc27b9755bd9feb1fb2c510f66e36c20a1503e6769cdaeee2bea7fe962d22ccc" + logic_hash = "dc2fe7caa38f665d24bbc673ff63491ebdeec8d56a420092243ce241238846cf" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "NjRAT" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "d21e48c7afe580a764153ca489c24a7039ae663ebb281a4605f3a230a963e33e" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $persistence_mechanism_v1_p1 = { - 00 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? - ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? - ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 16 2B ?? 17 13 ?? 11 ?? 39 ?? ?? ?? ?? - 00 28 ?? ?? ?? ?? 18 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? - 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 7E ?? ?? ?? ?? 28 ?? - ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 7E ?? ?? ?? - ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? - ?? ?? ?? 17 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? - ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 0A - 00 28 ?? ?? ?? ?? 00 28 ?? ?? ?? ?? DE ?? 00 00 00 1B 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 - 72 ?? ?? ?? ?? A2 00 11 ?? 17 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? A2 00 11 ?? 18 72 ?? ?? - ?? ?? A2 00 11 ?? 19 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? A2 00 11 ?? 1A 72 ?? ?? ?? ?? A2 - 00 11 ?? 28 ?? ?? ?? ?? 16 16 15 28 ?? ?? ?? ?? 26 DE ?? 25 28 ?? ?? ?? ?? 0B 00 28 - ?? ?? ?? ?? DE ?? 00 7E ?? ?? ?? ?? 13 ?? 11 ?? 39 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 6F - ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? - ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 - DE ?? 25 28 ?? ?? ?? ?? 0C 00 28 ?? ?? ?? ?? DE ?? 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? - ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 17 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E - ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DE ?? 25 - } - $persistence_mechanism_v1_p2 = { - 28 ?? ?? ?? ?? 0D 00 28 ?? ?? ?? ?? DE ?? 00 00 7E ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 - 28 ?? ?? ?? ?? 18 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 1D 28 ?? ?? ?? ?? - 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 00 1D - 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 19 73 ?? - ?? ?? ?? 80 ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 00 - 7E ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 16 - 15 28 ?? ?? ?? ?? 26 00 7E ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 00 28 ?? ?? ?? ?? 18 28 ?? - ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 00 7E ?? ?? ?? - ?? 13 ?? 11 ?? 39 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 13 ?? 18 13 ?? 28 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 28 ?? ?? ?? ?? 13 ?? - 11 ?? 13 ?? 16 13 ?? 38 ?? ?? ?? ?? 11 ?? 11 ?? 9A 13 ?? 00 28 ?? ?? ?? ?? 11 ?? 11 - ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 00 11 ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? - 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 00 11 ?? 72 ?? ?? ?? ?? - 11 ?? 28 ?? ?? ?? ?? 73 ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 11 - ?? 72 ?? ?? ?? ?? 11 ?? 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 11 ?? 72 ?? ?? ?? ?? - 11 ?? 28 ?? ?? ?? ?? 17 8C ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 11 ?? 6F ?? ?? ?? ?? 00 11 - ?? 11 ?? 28 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 - } - $connect_v1_p1 = { - 00 16 80 ?? ?? ?? ?? 20 D0 07 00 00 28 ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 0B 00 07 13 ?? - 11 ?? 28 ?? ?? ?? ?? 00 00 00 7E ?? ?? ?? ?? 14 (FE | 01) ?? 16 (FE | 01) ?? 13 ?? 11 - ?? 2C ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 14 80 ?? ?? ?? ?? DE ?? 25 28 ?? ?? ?? - ?? 0C 00 28 ?? ?? ?? ?? DE ?? 00 00 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 DE ?? 25 28 - ?? ?? ?? ?? 0D 00 28 ?? ?? ?? ?? DE ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? - ?? ?? DE ?? 00 00 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? - ?? ?? ?? 20 00 20 03 00 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 20 00 20 03 00 6F ?? ?? ?? - ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 20 10 27 00 00 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? - 6F ?? ?? ?? ?? 20 10 27 00 00 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 14 72 ?? ?? ?? ?? 18 - 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 17 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 8C ?? ?? ?? ?? A2 - 00 11 ?? 14 14 14 17 28 ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? - 28 ?? ?? ?? ?? 80 ?? ?? ?? ?? 17 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 00 - 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? - ?? ?? ?? 13 ?? 11 ?? 2C ?? 11 ?? 7F ?? ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 13 ?? 2B ?? 00 11 ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 - } - $connect_v1_p2 = { - 00 1F ?? 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 1B 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 11 ?? A2 00 - 11 ?? 17 7E ?? ?? ?? ?? A2 00 11 ?? 18 72 ?? ?? ?? ?? A2 00 11 ?? 19 7E ?? ?? ?? ?? - A2 00 11 ?? 1A 72 ?? ?? ?? ?? A2 00 11 ?? 28 ?? ?? ?? ?? A2 00 11 ?? 17 7E ?? ?? ?? - ?? A2 00 11 ?? 18 72 ?? ?? ?? ?? A2 00 11 ?? 19 7E ?? ?? ?? ?? A2 00 11 ?? 1A 72 ?? - ?? ?? ?? A2 00 11 ?? 1B 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1C 72 ?? ?? ?? ?? - A2 00 11 ?? 1D 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1E 72 ?? ?? ?? ?? A2 00 11 - ?? 1F ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 00 11 ?? - 1F ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 00 11 ?? 1F - ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 00 11 ?? 1F ?? - 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 7E - ?? ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 72 ?? ?? ?? ?? A2 00 11 ?? 1F ?? 7E ?? - ?? ?? ?? 28 ?? ?? ?? ?? A2 00 11 ?? 28 ?? ?? ?? ?? 13 ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? - ?? 12 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 DE ?? 25 28 ?? ?? ?? ?? 13 - ?? 00 28 ?? ?? ?? ?? DE ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 16 80 ?? ?? ?? ?? 28 - ?? ?? ?? ?? DE ?? 00 00 DE ?? 11 ?? 28 ?? ?? ?? ?? 00 DC 7E ?? ?? ?? ?? 0A 2B ?? 06 - } - $send_v1 = { - 00 7E ?? ?? ?? ?? 16 (FE | 01) ?? 13 ?? 11 ?? 2C ?? 16 0A 38 ?? ?? ?? ?? 00 00 7E ?? - ?? ?? ?? 0B 00 07 13 ?? 11 ?? 28 ?? ?? ?? ?? 00 00 7E ?? ?? ?? ?? 16 (FE | 01) ?? 13 - ?? 11 ?? 2C ?? 16 0A DD ?? ?? ?? ?? 00 73 ?? ?? ?? ?? 13 ?? 02 8E B7 0D 12 ?? 28 ?? - ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 0C 11 ?? 08 16 08 - 8E B7 6F ?? ?? ?? ?? 00 11 ?? 02 16 02 8E B7 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 6F ?? - ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 16 11 ?? 6F ?? ?? ?? ?? B7 16 6F ?? ?? ?? ?? 26 00 DE - ?? 11 ?? 28 ?? ?? ?? ?? 00 DC DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 11 ?? 28 ?? ?? ?? ?? - 00 11 ?? 13 ?? 00 7E ?? ?? ?? ?? 13 ?? 11 ?? 2C ?? 16 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? - 6F ?? ?? ?? ?? 00 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 28 ?? - ?? ?? ?? DE ?? 00 7E ?? ?? ?? ?? 0A 2B ?? 06 - } - $receive_v1_p1 = { - 00 00 00 72 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 14 (FE | 01) ?? 16 (FE | 01) ?? - 13 ?? 11 ?? 39 ?? ?? ?? ?? 15 6A 0A 16 0B 00 00 00 07 17 D6 0B 07 1F ?? (FE | 01) ?? - 13 ?? 11 ?? 2C ?? 16 0B 17 28 ?? ?? ?? ?? 00 00 7E ?? ?? ?? ?? 16 (FE | 01) ?? 13 ?? - 11 ?? 2C ?? 00 DD ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 (FE | 04) ?? 13 ?? - 11 ?? 2C ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 15 16 6F ?? ?? ?? ?? 26 00 00 00 7E ?? ?? - ?? ?? 6F ?? ?? ?? ?? 16 (FE | 02) ?? 13 ?? 11 ?? 39 ?? ?? ?? ?? 06 15 6A (FE | 01) ?? - 13 ?? 11 ?? 39 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 38 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? - ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 00 11 ?? 15 59 13 ?? 11 ?? 45 ?? ?? ?? ?? ?? ?? ?? ?? - ?? ?? ?? ?? 2B ?? 00 00 DD ?? ?? ?? ?? 2B ?? 00 11 ?? 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? - ?? 13 ?? 06 16 6A (FE | 01) ?? 13 ?? 11 ?? 2C ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 15 - 6A 0A 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 16 (FE | 02) ?? 16 (FE | 01) ?? 13 ?? 11 ?? 2C - ?? 38 ?? ?? ?? ?? 00 38 ?? ?? ?? ?? 00 11 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 00 17 13 ?? 11 ?? 3A ?? - ?? ?? ?? 00 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 D6 17 DA 17 D6 8D ?? ?? ?? ?? 80 ?? ?? - ?? ?? 06 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DA 0D 7E ?? ?? ?? ?? 8E B7 6A 09 (FE | 02) - } - $receive_v1_p2 = { - 13 ?? 11 ?? 2C ?? 09 17 6A DA B7 17 D6 17 DA 17 D6 8D ?? ?? ?? ?? 80 ?? ?? ?? ?? 00 - 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 16 7E ?? ?? ?? ?? 8E B7 16 6F ?? ?? ?? - ?? 0C 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 16 08 6F ?? ?? ?? ?? 00 7E ?? ?? ?? ?? 6F ?? ?? - ?? ?? 06 (FE | 01) ?? 13 ?? 11 ?? 2C ?? 15 6A 0A 14 (FE | 06) ?? ?? ?? ?? ?? 73 ?? ?? - ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 11 ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 - 11 ?? 1F ?? 6F ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 00 73 ?? ?? ?? ?? 80 ?? - ?? ?? ?? 00 38 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? - 00 00 00 00 00 7E ?? ?? ?? ?? 14 (FE | 01) ?? 16 (FE | 01) ?? 13 ?? 11 ?? 2C ?? 7E ?? - ?? ?? ?? 28 ?? ?? ?? ?? 14 72 ?? ?? ?? ?? 16 8D ?? ?? ?? ?? 14 14 14 17 28 ?? ?? ?? - ?? 26 14 80 ?? ?? ?? ?? 00 DE ?? 25 28 ?? ?? ?? ?? 13 ?? 00 28 ?? ?? ?? ?? DE ?? 00 - 16 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 (FE | 01) ?? 13 ?? 11 ?? 2C ?? 2B ?? 00 17 80 ?? - ?? ?? ?? 38 ?? ?? ?? ?? 00 - } - $connect_v2 = { - 16 80 ?? ?? ?? ?? 20 D0 07 00 00 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 0A 06 25 13 ?? 28 ?? - ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 14 80 ?? ?? ?? ?? DE ?? - 26 DE ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? DE ?? 26 DE ?? 73 ?? ?? ?? ?? - 80 ?? ?? ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 20 00 20 03 00 6F ?? ?? - ?? ?? 7E ?? ?? ?? ?? 20 00 20 03 00 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 20 - 10 27 00 00 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 20 10 27 00 00 6F ?? ?? ?? - ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 80 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 0B 72 ?? ?? ?? ?? 72 ?? - ?? ?? ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 2C ?? 07 7F ?? ?? ?? ?? 28 - ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 2B ?? 07 0C 72 ?? ?? ?? ?? 72 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0D 08 12 ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 0B 1B 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 07 A2 11 ?? 17 7E ?? ?? ?? ?? A2 11 ?? 18 - 72 ?? ?? ?? ?? A2 11 ?? 19 7E ?? ?? ?? ?? A2 11 ?? 1A 72 ?? ?? ?? ?? A2 11 ?? 28 ?? - ?? ?? ?? 0B 07 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 7E - ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B - 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? - ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 DE ?? 26 DE ?? DE ?? 26 16 80 ?? ?? ?? ?? DE ?? - DE ?? 11 ?? 28 ?? ?? ?? ?? DC 7E - } - $receive_v2 = { - 72 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 39 ?? ?? ?? ?? 15 6A 0A 16 0B 07 17 D6 - 0B 07 1F ?? 33 ?? 16 0B 17 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 39 ?? ?? ?? ?? 7E ?? ?? ?? - ?? 6F ?? ?? ?? ?? 17 3C ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 15 16 6F ?? ?? ?? - ?? 26 38 ?? ?? ?? ?? 06 15 6A 3B ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 17 D6 8D - ?? ?? ?? ?? 80 ?? ?? ?? ?? 06 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DA 0C 7E ?? ?? ?? ?? 8E - 69 6A 08 31 ?? 08 17 6A DA B7 17 D6 8D ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F - ?? ?? ?? ?? 7E ?? ?? ?? ?? 16 7E ?? ?? ?? ?? 8E 69 16 6F ?? ?? ?? ?? 0D 7E ?? ?? ?? - ?? 7E ?? ?? ?? ?? 16 09 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 40 ?? ?? ?? - ?? 15 6A 0A 7E ?? ?? ?? ?? 2D ?? 14 (FE | 06) ?? ?? ?? ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? - ?? ?? 7E ?? ?? ?? ?? 17 73 ?? ?? ?? ?? 13 ?? 11 ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F - ?? ?? ?? ?? 11 ?? 1F ?? 6F ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 73 ?? ?? ?? - ?? 80 ?? ?? ?? ?? 38 ?? ?? ?? ?? 72 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? - 6F ?? ?? ?? ?? 13 ?? 11 ?? 15 2E ?? 11 ?? 2C ?? 11 ?? 11 ?? 28 ?? ?? ?? ?? 13 ?? 12 - ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 ?? 2B ?? 11 ?? 28 - ?? ?? ?? ?? 0A 06 16 6A 33 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 15 6A 0A 7E ?? ?? ?? - ?? 6F ?? ?? ?? ?? 16 3E ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 3A ?? ?? ?? ?? DE - ?? 26 DE ?? 7E ?? ?? ?? ?? 2C ?? 7E ?? ?? ?? ?? 14 72 ?? ?? ?? ?? 16 8D ?? ?? ?? ?? - 14 14 14 17 28 ?? ?? ?? ?? 26 14 80 ?? ?? ?? ?? DE ?? 26 DE ?? 16 80 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 2C ?? 17 80 - } - $get_system_information_v2_p1 = { - 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 72 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 2C ?? 06 0B 7F ?? ?? ?? ?? 28 ?? ?? ?? ?? - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 07 12 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? - ?? 28 ?? ?? ?? ?? 0A 2B ?? 06 0D 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 - ?? 09 12 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 26 06 13 ?? 28 ?? - ?? ?? ?? 13 ?? 11 ?? 12 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 06 - 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 26 06 72 ?? ?? ?? ?? 7E ?? ?? - ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 06 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE - ?? 26 06 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 06 7E ?? ?? ?? ?? 6F - ?? ?? ?? ?? 13 ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 12 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E - ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 26 06 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? - ?? 0A DE ?? 06 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 06 73 ?? ?? ?? ?? 28 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 26 06 72 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 0A DE ?? 06 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? - ?? ?? ?? 15 16 28 ?? ?? ?? ?? 13 ?? 11 ?? 8E 69 17 33 ?? 06 72 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 0A 06 11 ?? 11 ?? 8E 69 17 DA 9A 28 ?? ?? ?? ?? 0A DE ?? 26 06 72 - } - $get_system_information_v2_p2 = { - 28 ?? ?? ?? ?? 0A DE ?? 1F ?? 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 2C ?? 06 - 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 2B ?? 06 72 ?? ?? ?? ?? 7E ?? ?? ?? - ?? 28 ?? ?? ?? ?? 0A DE ?? 26 06 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A DE ?? 28 ?? ?? ?? - ?? 2C ?? 06 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 2B ?? 06 72 ?? ?? ?? ?? - 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 06 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A - 06 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 0A 06 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? - 28 ?? ?? ?? ?? 0A 72 ?? ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? - 28 ?? ?? ?? ?? 16 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A - 13 ?? 11 ?? 6F ?? ?? ?? ?? 1F ?? 33 ?? 11 ?? 11 ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 13 - ?? 11 ?? 17 D6 13 ?? 11 ?? 11 ?? 8E 69 32 ?? DE ?? 26 DE ?? 06 11 ?? 28 - } - $send_v2 = { - 7E ?? ?? ?? ?? 2D ?? 16 2A 7E ?? ?? ?? ?? 0A 06 25 13 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? - ?? 2D ?? 16 13 ?? DD ?? ?? ?? ?? 73 ?? ?? ?? ?? 0B 02 8E 69 13 ?? 12 ?? 28 ?? ?? ?? - ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 12 ?? 28 ?? ?? ?? ?? 0D 07 09 16 09 8E 69 6F ?? - ?? ?? ?? 07 02 16 02 8E 69 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 07 6F ?? ?? - ?? ?? 16 07 6F ?? ?? ?? ?? B7 16 6F ?? ?? ?? ?? 26 07 6F ?? ?? ?? ?? DE ?? 11 ?? 28 - ?? ?? ?? ?? DC DE ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 16 80 ?? ?? ?? - ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 26 DE ?? 28 ?? ?? ?? ?? DE ?? 7E ?? ?? ?? ?? - 2A 11 - } + $a = { 89 C0 89 45 D4 83 7D D4 00 79 1A 83 EC 0C 68 50 } condition: - uint16(0)==0x5A4D and ((( all of ($persistence_mechanism_v1_p*)) and ( all of ($connect_v1_p*)) and ($send_v1) and ( all of ($receive_v1_p*))) or (($connect_v2) and ($receive_v2) and ( all of ($get_system_information_v2_p*)) and ($send_v2))) + all of them } -rule REVERSINGLABS_Linux_Backdoor_Krasue : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Windows_Vulndriver_Ryzen_7Df5A747 : FILE { meta: - description = "Yara rule that detects Krasue backdoor." - author = "ReversingLabs" - id = "3187eebf-ef70-585f-85cf-5813025c785e" - date = "2024-03-04" - modified = "2024-03-04" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/Linux.Backdoor.Krasue.yara#L1-L127" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "e2daa35ef9e0793062c9fb3bd8e4838e1e81ee3d228d8117b1c3b0e72eb8e151" + description = "Name: AMDRyzenMasterDriver.sys, Version: 1.5.0.0" + author = "Elastic Security" + id = "7df5a747-d924-459d-8363-9c12841ef37f" + date = "2022-04-07" + modified = "2022-04-07" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Ryzen.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "a13054f349b7baa8c8a3fcbd31789807a493cc52224bbff5e412eb2bd52a6433" + logic_hash = "192b51f0bbd2cab4c1d3da6f82fbee7129a53abaa6e8769d3681821112017824" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "Krasue" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE" + fingerprint = "1bf5d6b2739ce4fe5137cff84e7bfb9389e8d175480094fe831f8f68d84abb16" + threat_name = "Windows.VulnDriver.Ryzen" + severity = 50 + arch_context = "x86" + scan_context = "file" + license = "Elastic License v2" + os = "windows" strings: - $switch_server = { - 8B 05 ?? ?? ?? ?? FF C0 3B 05 ?? ?? ?? ?? 89 05 ?? ?? ?? ?? 7C ?? C7 05 ?? ?? ?? ?? - ?? ?? ?? ?? 48 63 05 ?? ?? ?? ?? 85 C0 75 ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? EB ?? 8B - 15 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? C6 05 ?? ?? ?? ?? ?? C6 05 ?? ?? ?? ?? - ?? 89 15 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 66 89 15 ?? ?? 23 00 48 8B 04 C5 ?? ?? ?? ?? - 66 C7 05 ?? ?? 23 00 ?? ?? 8B 10 89 15 ?? ?? ?? ?? 66 8B 40 ?? 66 89 05 ?? ?? 23 00 - C3 - } - $get_hostname = { - 41 55 41 54 31 F6 55 53 31 C0 BF ?? ?? ?? ?? 48 81 EC ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 - C0 0F 88 ?? ?? ?? ?? 48 89 E6 89 C7 89 C3 E8 ?? ?? ?? ?? 48 8B 6C 24 ?? 45 31 C9 31 - FF 41 89 D8 B9 ?? ?? ?? ?? BA ?? ?? ?? ?? 41 89 EC 48 63 ED 48 89 EE E8 ?? ?? ?? ?? - BE ?? ?? ?? ?? 48 89 C7 49 89 C5 E8 ?? ?? ?? ?? 83 F8 ?? 74 ?? 48 63 D0 49 8D 74 15 - ?? 8D 50 ?? 48 63 D2 44 39 E2 41 89 D0 7D ?? 48 FF C2 41 80 7C 15 ?? ?? 75 ?? 44 89 - C1 41 FF C8 BA ?? ?? ?? ?? 29 C1 4D 63 C0 48 89 D7 83 E9 ?? 48 63 C9 F3 A4 41 C6 80 - ?? ?? ?? ?? ?? 4C 89 EF 48 89 EE E8 ?? ?? ?? ?? 89 DF E8 ?? ?? ?? ?? 48 81 C4 ?? ?? - ?? ?? 5B 5D 41 5C 41 5D C3 - } - $start_server_p1 = { - 41 57 41 56 31 D2 41 55 41 54 BE ?? ?? ?? ?? 55 53 89 FB BF ?? ?? ?? ?? 48 81 EC ?? - ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 89 05 ?? ?? ?? ?? 79 ?? 83 CF ?? E9 ?? ?? ?? ?? 48 8D - 4C 24 ?? 41 B8 ?? ?? ?? ?? BE ?? ?? ?? ?? BA ?? ?? ?? ?? 89 C7 C7 44 24 ?? ?? ?? ?? - ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? 48 89 D7 F3 AB 31 FF 66 C7 05 - ?? ?? 23 00 ?? ?? E8 ?? ?? ?? ?? 0F B7 FB 89 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 3D ?? - ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 66 89 05 ?? ?? 23 00 E8 ?? ?? ?? ?? 85 C0 78 - ?? 4C 8D A4 24 ?? ?? ?? ?? 4C 8D AC 24 ?? ?? ?? ?? 4C 8D 74 24 ?? C7 05 ?? ?? ?? ?? - ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 31 C9 41 B9 ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? BA ?? ?? ?? - ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 48 89 C3 0F 88 ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? - ?? 4C 89 E7 83 FB ?? F3 AB 7E ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? - ?? 85 C0 75 ?? B8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? 41 B8 ?? ?? ?? ?? 44 8D 08 31 C9 BA - ?? ?? ?? ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 83 FB ?? 75 ?? BE ?? ?? ?? ?? 4C 89 - E7 E8 ?? ?? ?? ?? 85 C0 75 ?? 8B 05 ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 89 05 - ?? ?? ?? ?? E9 ?? ?? ?? ?? 89 DA BE ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? 4C 89 E6 89 - C2 8A 06 89 F5 44 29 E5 3C ?? 75 ?? 80 7E ?? ?? 75 ?? 48 83 C6 ?? EB ?? 3C ?? 75 ?? - 80 7E ?? ?? 75 ?? 41 B8 ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? 4C 89 C7 4C 8B 05 ?? ?? ?? - ?? F3 AB 8B 7E ?? 66 8B 4E ?? 4C 89 06 C6 06 ?? 45 31 C0 C6 46 ?? ?? BE - } - $start_server_p2 = { - 66 C7 05 ?? ?? 23 00 ?? ?? 89 3D ?? ?? ?? ?? 66 89 0D ?? ?? 23 00 89 3D ?? ?? ?? ?? - 66 89 0D ?? ?? 23 00 48 89 F7 B9 ?? ?? ?? ?? 4C 89 E6 F3 AB E9 ?? ?? ?? ?? 85 ED 75 - ?? 48 63 DD BA ?? ?? ?? ?? BE ?? ?? ?? ?? 4C 01 E3 48 89 DF E8 ?? ?? ?? ?? 85 C0 75 - ?? 48 8D 7B ?? E8 ?? ?? ?? ?? 6B C0 ?? B9 ?? ?? ?? ?? BE ?? ?? ?? ?? 4C 89 EF 99 F7 - F9 31 C0 E8 ?? ?? ?? ?? EB ?? 8D 45 ?? 48 8D 54 24 ?? 48 98 85 C0 78 ?? 49 8B 0C 04 - 48 83 C2 ?? 48 83 E8 ?? 48 89 4A ?? C6 42 ?? ?? C6 42 ?? ?? EB ?? BA ?? ?? ?? ?? BE - ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? ?? 85 C0 75 ?? 48 8B 05 ?? ?? ?? ?? 89 E9 4C 89 F6 - 89 2D ?? ?? ?? ?? C7 05 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 05 ?? ?? ?? ?? B8 ?? ?? ?? ?? - 48 89 C7 F3 A4 BE ?? ?? ?? ?? 4C 89 EF E8 ?? ?? ?? ?? 31 C0 48 83 C9 ?? 4C 89 EF F2 - AE 48 89 C8 48 F7 D0 48 8D 50 ?? E9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 - DF E8 ?? ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? 8B 0D ?? ?? ?? ?? 44 8B 0D ?? ?? ?? ?? 44 - 8B 3D ?? ?? ?? ?? 8B 1D ?? ?? ?? ?? 89 4C 24 ?? 44 89 4C 24 ?? E8 ?? ?? ?? ?? 48 83 - EC ?? 41 89 C0 BA ?? ?? ?? ?? 8B 4C 24 ?? 4C 89 EF BE ?? ?? ?? ?? 31 C0 51 8B 0D ?? - ?? ?? ?? 41 57 53 44 8B 4C 24 ?? E8 ?? ?? ?? ?? 31 C0 48 83 C9 ?? 4C 89 EF F2 AE 48 - 83 C4 ?? 48 89 C8 48 F7 D0 48 8D 50 ?? 41 89 E8 4C 89 F1 4C 89 EE 8B 3D ?? ?? ?? ?? - E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 - } - $start_server_p3 = { - 85 C0 75 ?? 31 FF E8 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? ?? - ?? 85 C0 75 ?? BF ?? ?? ?? ?? EB ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? ?? - ?? ?? 85 C0 75 ?? BF ?? ?? ?? ?? EB ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? 48 89 DF E8 ?? - ?? ?? ?? 85 C0 0F 85 ?? ?? ?? ?? E8 ?? ?? ?? ?? 41 89 C7 E8 ?? ?? ?? ?? 45 85 FF 0F - 85 ?? ?? ?? ?? 48 8D 7C 24 ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 41 89 C4 75 ?? 8B - 7C 24 ?? E8 ?? ?? ?? ?? 8B 7C 24 ?? BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 7C 24 ?? BE ?? - ?? ?? ?? E8 ?? ?? ?? ?? 8B 7C 24 ?? E8 ?? ?? ?? ?? 48 8D 4B ?? 45 31 C0 BA ?? ?? ?? - ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? E9 ?? ?? ?? ?? 8B 7C 24 ?? E8 - ?? ?? ?? ?? 8B 7C 24 ?? 48 8D B4 24 ?? ?? ?? ?? BA ?? ?? ?? ?? E8 ?? ?? ?? ?? 85 C0 - 89 C3 7E ?? 4C 8D AC 24 ?? ?? ?? ?? 8D 04 2B 3D ?? ?? ?? ?? 7E ?? 8B 3D ?? ?? ?? ?? - BA ?? ?? ?? ?? 48 8D 4C 24 ?? 4C 89 EE 29 EA 41 89 E8 49 81 C5 ?? ?? ?? ?? 81 EB ?? - ?? ?? ?? E8 ?? ?? ?? ?? EB ?? 8B 3D ?? ?? ?? ?? 48 8D 4C 24 ?? 41 89 E8 89 DA 4C 89 - EE E8 ?? ?? ?? ?? EB ?? 31 F6 BA ?? ?? ?? ?? 44 89 E7 E8 ?? ?? ?? ?? 85 C0 0F 85 - } - $send_encrypt = { - E8 ?? ?? ?? ?? 41 8D 7E ?? 49 89 C5 48 63 FF E8 ?? ?? ?? ?? 48 63 54 24 ?? 48 89 C7 - 4C 89 FE 48 8D 0C 13 C6 04 08 ?? 89 D1 48 01 C2 F3 A4 48 89 D7 48 89 EE 48 89 D9 44 - 89 F2 F3 A4 48 89 C6 EB ?? 8D 7B ?? 48 63 FF E8 ?? ?? ?? ?? 89 DA 49 89 C5 48 89 EE - 4C 89 EF E8 ?? ?? ?? ?? 44 8B 0D ?? ?? ?? ?? 4C 89 EE 44 89 E7 48 63 D0 41 B8 ?? ?? - ?? ?? 31 C9 E8 ?? ?? ?? ?? 48 83 C4 ?? 5B 5D 41 5C 41 5D 41 5E 41 5F C3 - } - $notify_server = { - 48 81 EC ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? 48 89 E0 85 D2 7E ?? BE ?? ?? ?? ?? 89 D1 48 - 89 E7 F3 A4 48 63 D2 BE ?? ?? ?? ?? B9 ?? ?? ?? ?? 4C 8D 04 10 41 B9 ?? ?? ?? ?? 48 - 83 C2 ?? 4C 89 C7 41 B8 ?? ?? ?? ?? F3 A4 8B 3D ?? ?? ?? ?? 48 89 C6 E8 ?? ?? ?? ?? - 8B 05 ?? ?? ?? ?? 89 05 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? C3 - } + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 41 00 4D 00 44 00 52 00 79 00 7A 00 65 00 6E 00 4D 00 61 00 73 00 74 00 65 00 72 00 44 00 72 00 69 00 76 00 65 00 72 00 2E 00 73 00 79 00 73 00 00 00 } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x05][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x04][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ condition: - uint32(0)==0x464C457F and ($switch_server) and ($get_hostname) and ( all of ($start_server_p*)) and ($send_encrypt) and ($notify_server) + int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version } -rule REVERSINGLABS_Bytecode_MSIL_Backdoor_Asyncrat : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Windows_Vulndriver_Ryzen_9B01C718 : FILE { meta: - description = "Yara rule that detects AsyncRAT backdoor." - author = "ReversingLabs" - id = "78ff36e1-1620-50f4-8abd-adcf8b1242da" - date = "2024-05-22" - modified = "2024-05-22" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/ByteCode.MSIL.Backdoor.AsyncRAT.yara#L1-L149" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "53a13975cd53b571910f951adc44707c11b86c003eeb7b88dbe701253645ac89" + description = "Name: AMDRyzenMasterDriver.sys, Version: <= 1.7.0.0" + author = "Elastic Security" + id = "9b01c718-ba36-4642-b27d-e9310d05d8a5" + date = "2023-01-22" + modified = "2023-06-13" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Ryzen.yar#L23-L43" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "bb82d8c29127955d58dff58978605a9daa718425c74c4bce5ae3e53712909148" + logic_hash = "5734f6a249656f22a2a363b42ae77b5e6b7673bc96bad34b04b1be7f2b584b08" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "AsyncRAT" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE" + fingerprint = "18ad3df5ae549dddbe1f6f33db534b4fcfc603e0863f8262a8cb9c166a16af67" + threat_name = "Windows.VulnDriver.Ryzen" + severity = 49 + arch_context = "x86" + scan_context = "file" + license = "Elastic License v2" + os = "windows" strings: - $read_server_data_v1 = { - 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 39 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 16 28 ?? - ?? ?? ?? DD ?? ?? ?? ?? 28 ?? ?? ?? ?? 02 6F ?? ?? ?? ?? 0A 06 16 3E ?? ?? ?? ?? 28 - ?? ?? ?? ?? 06 6A 58 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 06 6A 59 28 ?? ?? ?? ?? 28 ?? ?? - ?? ?? 3A ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 6A 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 16 6A 3E ?? ?? ?? ?? 16 6A 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? D4 8D ?? ?? ?? ?? 28 ?? - ?? ?? ?? 38 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 69 28 ?? ?? ?? - ?? 69 6F ?? ?? ?? ?? 0B 07 16 3D ?? ?? ?? ?? 16 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 28 ?? - ?? ?? ?? 07 6A 58 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 07 6A 59 28 ?? ?? ?? ?? 28 ?? ?? ?? - ?? 16 6A 3C ?? ?? ?? ?? 16 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 6A 30 ?? - 14 (FE | 06) ?? ?? ?? ?? ?? 73 ?? ?? ?? ?? 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? - ?? 16 6A 28 ?? ?? ?? ?? 1A 6A 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? D4 8D ?? ?? ?? ?? 28 ?? - ?? ?? ?? 38 ?? ?? ?? ?? 1A 6A 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? D4 8D ?? ?? ?? ?? 28 ?? - ?? ?? ?? 16 6A 28 ?? ?? ?? ?? 38 ?? ?? ?? ?? 28 ?? ?? ?? ?? 16 6A 3C ?? ?? ?? ?? 16 - 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 69 28 ?? - ?? ?? ?? 69 14 (FE | 06) ?? ?? ?? ?? ?? 73 ?? ?? ?? ?? 14 6F ?? ?? ?? ?? 26 38 ?? ?? - ?? ?? 16 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 26 16 28 ?? ?? ?? ?? DD - } - $send_v1 = { - 28 ?? ?? ?? ?? 0A 16 0B 06 12 ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? DD ?? - ?? ?? ?? 02 8E 69 28 ?? ?? ?? ?? 0C 28 ?? ?? ?? ?? 15 17 6F ?? ?? ?? ?? 26 28 ?? ?? - ?? ?? 08 16 08 8E 69 6F ?? ?? ?? ?? 02 8E 69 20 ?? ?? ?? ?? 3E ?? ?? ?? ?? 02 73 ?? - ?? ?? ?? 0D 16 13 ?? 09 16 6A 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? 8D ?? ?? ?? ?? 13 ?? 38 - ?? ?? ?? ?? 28 ?? ?? ?? ?? 15 17 6F ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 11 ?? 16 11 ?? 6F - ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 09 11 ?? 16 11 ?? 8E 69 6F ?? ?? ?? ?? 25 - 13 ?? 16 30 ?? DD ?? ?? ?? ?? 09 39 ?? ?? ?? ?? 09 6F ?? ?? ?? ?? DC 28 ?? ?? ?? ?? - 15 17 6F ?? ?? ?? ?? 26 28 ?? ?? ?? ?? 02 16 02 8E 69 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? - 6F ?? ?? ?? ?? DD ?? ?? ?? ?? 26 16 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 07 39 ?? ?? ?? ?? - 06 28 ?? ?? ?? ?? DC - } - $read_packet_v1_p1 = { - 73 ?? ?? ?? ?? 0A 06 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 02 74 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B - 07 28 ?? ?? ?? ?? 0C 08 20 4F 01 89 64 42 ?? ?? ?? ?? 08 20 7A 39 BA 13 42 ?? ?? ?? - ?? 08 20 D4 CA CD 0C 3B ?? ?? ?? ?? 08 20 7A 39 BA 13 3B ?? ?? ?? ?? 38 ?? ?? ?? ?? - 08 20 2B C2 32 1B 3B ?? ?? ?? ?? 08 20 E2 A2 F4 57 3B ?? ?? ?? ?? 08 20 4F 01 89 64 - 3B ?? ?? ?? ?? 38 ?? ?? ?? ?? 08 20 5A 15 79 D9 42 ?? ?? ?? ?? 08 20 B7 16 DB 7A 3B - ?? ?? ?? ?? 08 20 39 20 3F B2 3B ?? ?? ?? ?? 08 20 5A 15 79 D9 3B ?? ?? ?? ?? 38 ?? - ?? ?? ?? 08 20 1E CA D2 DC 3B ?? ?? ?? ?? 08 20 45 FD B6 E0 3B ?? ?? ?? ?? 08 20 D0 - 5E 9B FA 3B ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? - ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? - ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? - ?? 38 ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 07 - } - $read_packet_v1_p2 = { - 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 38 ?? ?? ?? ?? 16 28 ?? ?? ?? ?? 73 ?? - ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6A 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? - 16 28 ?? ?? ?? ?? 38 ?? ?? ?? ?? 00 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 3A ?? ?? ?? ?? 7E ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 6F ?? - ?? ?? ?? 73 ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? - ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 38 ?? ?? ?? ?? 06 7B ?? - ?? ?? ?? 28 ?? ?? ?? ?? DD ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? DD ?? ?? ?? ?? - 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 72 - ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 7E ?? ?? ?? ?? 28 ?? ?? - ?? ?? 6F ?? ?? ?? ?? 0D 38 ?? ?? ?? ?? 12 ?? 28 ?? ?? ?? ?? 13 ?? 11 ?? 72 ?? ?? ?? - ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 06 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F - ?? ?? ?? ?? 28 ?? ?? ?? ?? 39 ?? ?? ?? ?? 11 ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 11 ?? - 6F ?? ?? ?? ?? 26 12 ?? 28 ?? ?? ?? ?? 2D ?? DD ?? ?? ?? ?? 12 ?? (FE | 16) ?? ?? ?? - ?? ?? 6F ?? ?? ?? ?? DC 73 ?? ?? ?? ?? 26 06 (FE | 06) ?? ?? ?? ?? ?? 73 ?? ?? ?? ?? - 73 ?? ?? ?? ?? 25 16 6F ?? ?? ?? ?? 25 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 38 ?? ?? ?? ?? - 7E ?? ?? ?? ?? 25 3A ?? ?? ?? ?? 26 7E ?? ?? ?? ?? (FE | 06) ?? ?? ?? ?? ?? 73 - } - $send_v2 = { - 7E ?? ?? ?? ?? 13 ?? 11 ?? 28 ?? ?? ?? ?? 16 13 ?? 11 ?? 12 ?? 28 ?? ?? ?? ?? 7E ?? - ?? ?? ?? 39 ?? ?? ?? ?? 73 ?? ?? ?? ?? 0A 02 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0B 07 8E - B7 28 ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 0C 06 08 16 08 8E B7 - 6F ?? ?? ?? ?? 06 07 16 07 8E B7 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 15 17 6F ?? ?? ?? ?? - 26 7E ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 16 06 6F ?? ?? ?? ?? B7 16 14 (FE | 06) ?? ?? ?? - ?? ?? 73 ?? ?? ?? ?? 14 6F ?? ?? ?? ?? 26 DE ?? 06 2C ?? 06 6F ?? ?? ?? ?? DC DE ?? - 25 28 ?? ?? ?? ?? 0D 16 80 ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? DE ?? 11 ?? 2C ?? 11 ?? - 28 ?? ?? ?? ?? DC - } - $open_url_v2 = { - 03 39 ?? ?? ?? ?? 17 28 ?? ?? ?? ?? 20 00 0C 00 00 28 ?? ?? ?? ?? 20 0F 27 00 00 28 - ?? ?? ?? ?? DE ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? DE ?? 02 28 ?? ?? ?? ?? 74 ?? ?? ?? - ?? 0A 06 7E ?? ?? ?? ?? 73 ?? ?? ?? ?? 7E ?? ?? ?? ?? 8E B7 6F ?? ?? ?? ?? 9A 6F ?? - ?? ?? ?? 06 17 6F ?? ?? ?? ?? 06 20 10 27 00 00 6F ?? ?? ?? ?? 06 72 ?? ?? ?? ?? 6F - ?? ?? ?? ?? 06 6F ?? ?? ?? ?? 74 ?? ?? ?? ?? 0B DE ?? 07 2C ?? 07 6F ?? ?? ?? ?? DC - 2B ?? 02 28 ?? ?? ?? ?? 26 - } - $monitoring_v2 = { - 73 ?? ?? ?? ?? 0C 02 72 ?? ?? ?? ?? 15 16 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? - 11 ?? 9A 0B 08 07 14 72 ?? ?? ?? ?? 16 8D ?? ?? ?? ?? 14 14 14 28 ?? ?? ?? ?? 28 ?? - ?? ?? ?? 6F ?? ?? ?? ?? 11 ?? 17 D6 13 ?? 11 ?? 11 ?? 8E B7 32 ?? 1F ?? 0A 38 ?? ?? - ?? ?? 28 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 11 ?? 11 ?? 9A 0D 09 6F ?? ?? ?? ?? 28 ?? - ?? ?? ?? 2C ?? 2B ?? 08 09 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 (FE | 07) ?? ?? ?? ?? ?? - 73 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 06 1F ?? 31 ?? 16 0A 72 ?? ?? ?? ?? 09 6F ?? ?? - ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 17 D6 13 ?? - 11 ?? 11 ?? 8E B7 32 ?? 06 17 D6 0A 20 ?? ?? ?? ?? 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 3A - } + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 41 00 4D 00 44 00 52 00 79 00 7A 00 65 00 6E 00 4D 00 61 00 73 00 74 00 65 00 72 00 44 00 72 00 69 00 76 00 65 00 72 00 2E 00 73 00 79 00 73 00 00 00 } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x07][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x06][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ condition: - uint16(0)==0x5A4D and ((($read_server_data_v1) and ($send_v1) and ( all of ($read_packet_v1_p*))) or (($send_v2) and ($open_url_v2) and ($monitoring_v2))) + int16 ( uint32(0x3C)+0x5c)==0x0001 and int16 ( uint32(0x3C)+0x18)==0x020b and $original_file_name and $version } -rule REVERSINGLABS_Linux_Trojan_Chinaz : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Linux_Trojan_Godropper_Bae099Bd : FILE MEMORY { meta: - description = "Yara rule that detects ChinaZ trojan." - author = "ReversingLabs" - id = "f99c224b-db54-5cae-b5fb-8939ebee3250" - date = "2024-07-31" - modified = "2024-07-31" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/Linux.Trojan.ChinaZ.yara#L1-L246" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "d8d08f4f3f36ecc7b219b6b1aae3c76d26e8fb3a44444763929190c6124532ff" + description = "Detects Linux Trojan Godropper (Linux.Trojan.Godropper)" + author = "Elastic Security" + id = "bae099bd-c19a-4893-96e8-63132dabce39" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Godropper.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "704643f3fd11cda1d52260285bf2a03bccafe59cfba4466427646c1baf93881e" + logic_hash = "ef6274928f7cfc0312122ac3e4153fb0a78dc7d5fb2d68db6cbe4974f5497210" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Trojan" - tc_detection_name = "ChinaZ" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "5a7b0906ebc47130aefa868643e1e0a40508fe7a25bc55e5c41ff284ca2751e5" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" strings: - $collect_system_information_32_p1 = { - 55 57 56 53 81 EC ?? ?? ?? ?? 8D 5C 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? - ?? 89 44 24 ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 - ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 - ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 31 31 C9 89 C6 8D 44 24 ?? 31 - FF C7 44 24 ?? ?? ?? ?? ?? 01 CE 89 04 24 11 D7 E8 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? - E8 ?? ?? ?? ?? 0F 31 89 C1 31 C0 31 DB 01 C1 8D 44 24 ?? 11 D3 C7 44 24 ?? ?? ?? ?? - ?? 89 04 24 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? 8B 44 24 ?? C7 04 24 ?? ?? ?? ?? - 29 F1 19 FB 31 ED 2B 44 24 ?? 89 4C 24 ?? 8D B4 24 ?? ?? ?? ?? 89 5C 24 ?? 89 F7 69 - C0 ?? ?? ?? ?? DF 6C 24 ?? 03 44 24 ?? 2B 44 24 ?? D9 7C 24 ?? 89 44 24 ?? DB 44 24 - ?? DE F9 0F B7 44 24 ?? B4 ?? 66 89 44 24 ?? D9 6C 24 ?? DB 5C 24 ?? D9 6C 24 ?? 8B - 5C 24 ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? - 8D 9C 24 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? A1 - } - $collect_system_information_32_p2 = { - C7 04 24 ?? ?? ?? ?? A3 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 89 E8 B9 ?? ?? ?? ?? F3 AB 89 - DF B1 ?? F3 AB 89 DF 89 5C 24 ?? 89 74 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 1C 24 C7 44 24 ?? ?? ?? ?? ?? E8 ?? - ?? ?? ?? 8B 54 24 ?? 89 E8 B9 ?? ?? ?? ?? F3 AB 89 F7 C7 44 24 ?? ?? ?? ?? ?? 89 D0 - C1 F8 ?? C1 E8 ?? 01 D0 C1 F8 ?? 89 44 24 ?? 89 1C 24 89 44 24 ?? E8 ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 C2 A1 ?? ?? ?? - ?? 89 54 24 ?? 89 44 24 ?? E8 ?? ?? ?? ?? 89 E8 B9 ?? ?? ?? ?? F3 AB 89 DF B1 ?? F3 - AB 89 5C 24 ?? 89 74 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 54 24 ?? 85 D2 0F - 85 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? - ?? A1 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? - ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 04 - 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? - ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? 5B 5E 5F 5D - C3 - } - $send_system_info_32 = { - 57 56 53 81 EC ?? ?? ?? ?? 8D 5C 24 ?? 89 1C 24 E8 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? - 89 44 24 ?? 89 5C 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? - ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? - 0F 31 31 C9 89 C6 8D 44 24 ?? 31 FF C7 44 24 ?? ?? ?? ?? ?? 01 CE 89 04 24 11 D7 E8 - ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 31 89 C1 31 C0 31 DB 01 C1 8D 44 - 24 ?? 11 D3 C7 44 24 ?? ?? ?? ?? ?? 89 04 24 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 4C 24 ?? - 8B 44 24 ?? C7 04 24 ?? ?? ?? ?? 29 F1 19 FB 2B 44 24 ?? 89 4C 24 ?? 89 5C 24 ?? 69 - C0 ?? ?? ?? ?? DF 6C 24 ?? 03 44 24 ?? 2B 44 24 ?? D9 7C 24 ?? 89 44 24 ?? DB 44 24 - ?? DE F9 0F B7 44 24 ?? B4 ?? 66 89 44 24 ?? D9 6C 24 ?? DB 5C 24 ?? D9 6C 24 ?? 8B - 5C 24 ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? - C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 8B 15 ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? C7 04 24 ?? ?? - ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? - 89 04 24 E8 ?? ?? ?? ?? 81 C4 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5B 5E 5F C3 - } - $parse_c2_commands_32 = { - 55 31 C0 57 B9 ?? ?? ?? ?? 56 53 81 EC ?? ?? ?? ?? 8D 9C 24 ?? ?? ?? ?? 0F B6 94 24 - ?? ?? ?? ?? 89 DF F3 AB C7 04 24 ?? ?? ?? ?? 88 94 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8D - 84 24 ?? ?? ?? ?? 89 84 24 ?? ?? ?? ?? 83 E0 ?? 89 84 24 ?? ?? ?? ?? 90 A1 ?? ?? ?? - ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 5C 24 ?? 89 04 24 E8 ?? ?? ?? - ?? 85 C0 0F 84 ?? ?? ?? ?? 8B B4 24 ?? ?? ?? ?? 85 F6 0F 84 ?? ?? ?? ?? 89 74 24 ?? - C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 83 F8 ?? 74 ?? 83 F8 ?? 0F - 84 ?? ?? ?? ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 - ?? ?? ?? ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 83 FE ?? 0F 84 ?? ?? ?? ?? 83 FE ?? 0F 84 ?? - ?? ?? ?? 83 FE ?? 0F 85 ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? 8D BC 24 ?? ?? ?? ?? F3 AB - 8D B4 24 ?? ?? ?? ?? B0 ?? 8D BC 24 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? B1 ?? F3 A5 89 - D6 8B BC 24 ?? ?? ?? ?? F7 C7 ?? ?? ?? ?? 0F 85 ?? ?? ?? ?? F7 C7 ?? ?? ?? ?? 0F 85 - ?? ?? ?? ?? 89 C1 C1 E9 ?? A8 ?? F3 A5 0F 85 ?? ?? ?? ?? A8 ?? 0F 85 ?? ?? ?? ?? 89 - 54 24 ?? C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? A1 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? - 81 C4 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5B 5E 5F 5D C3 - } - $dns_flood_32_p1 = { - 55 57 56 53 81 EC ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8D 5C 24 ?? 8B - B4 24 ?? ?? ?? ?? B8 ?? ?? ?? ?? F6 C3 ?? 89 DF 0F 85 ?? ?? ?? ?? 89 C1 C1 E9 ?? A8 - ?? F3 A5 0F 85 ?? ?? ?? ?? A1 ?? ?? ?? ?? 8D B4 24 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? - 89 F7 89 44 24 ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 - 44 24 ?? ?? ?? ?? ?? 66 C7 44 24 ?? ?? ?? 66 C7 44 24 ?? ?? ?? E8 ?? ?? ?? ?? 31 D2 - C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? F7 35 ?? ?? ?? - ?? 8B 04 95 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 C5 8D - 44 24 ?? 89 44 24 ?? 89 2C 24 E8 ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? F3 AB 8D 54 24 ?? - 89 14 24 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 89 5C 24 ?? 89 84 24 ?? - ?? ?? ?? 0F B7 44 24 ?? 66 89 84 24 ?? ?? ?? ?? 8D 84 24 ?? ?? ?? ?? 89 04 24 E8 ?? - ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 89 14 24 89 74 24 ?? 89 54 24 ?? C6 84 24 ?? ?? ?? ?? - ?? C6 84 24 ?? ?? ?? ?? ?? 66 C7 84 24 ?? ?? ?? ?? ?? ?? 66 C7 84 24 ?? ?? ?? ?? ?? - ?? 66 C7 84 24 ?? ?? ?? ?? ?? ?? 66 C7 84 24 ?? ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 54 - } - $dns_flood_32_p2 = { - 24 ?? 89 D1 8B 39 83 C1 ?? 8D 87 ?? ?? ?? ?? F7 D7 21 F8 25 ?? ?? ?? ?? 74 ?? A9 ?? - ?? ?? ?? 0F 84 ?? ?? ?? ?? 00 C0 89 D7 83 D9 ?? 29 D1 8D 84 0C ?? ?? ?? ?? 66 C7 00 - ?? ?? 66 C7 40 ?? ?? ?? 8B 0F 83 C7 ?? 8D 81 ?? ?? ?? ?? F7 D1 21 C8 25 ?? ?? ?? ?? - 74 ?? A9 ?? ?? ?? ?? 75 ?? C1 E8 ?? 83 C7 ?? 00 C0 8D 44 24 ?? 83 DF ?? C7 44 24 ?? - ?? ?? ?? ?? 29 D7 89 04 24 89 54 24 ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 54 24 ?? 89 74 - 24 ?? 89 84 24 ?? ?? ?? ?? 0F B7 44 24 ?? 89 14 24 66 89 84 24 ?? ?? ?? ?? E8 ?? ?? - ?? ?? 8D 94 24 ?? ?? ?? ?? 89 5C 24 ?? 89 14 24 E8 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? - 83 B8 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? B9 ?? ?? ?? ?? 83 C7 ?? 89 C2 - C1 FA ?? F7 F9 8D 42 ?? 66 C1 C8 ?? 66 89 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 31 D2 C7 - 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? ?? ?? ?? ?? 89 7C 24 ?? 89 2C 24 F7 35 ?? ?? ?? ?? - 8B 04 95 ?? ?? ?? ?? 8D 94 24 ?? ?? ?? ?? 89 54 24 ?? 89 44 24 ?? 8D 44 24 ?? 89 44 - 24 ?? E8 ?? ?? ?? ?? 8B 84 24 ?? ?? ?? ?? 83 80 ?? ?? ?? ?? ?? 83 90 ?? ?? ?? ?? ?? - 83 3D ?? ?? ?? ?? ?? 74 ?? C7 04 24 ?? ?? ?? ?? E8 - } - $collect_system_information_64_p1 = { - 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 8D 7C 24 ?? E8 ?? ?? ?? ?? 4C 8D 84 24 ?? - ?? ?? ?? 48 8D 4C 24 ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? - ?? ?? B9 ?? ?? ?? ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? - ?? 0F 31 48 89 D3 48 8D 7C 24 ?? 31 F6 48 C1 E3 ?? 89 C0 48 01 C3 E8 ?? ?? ?? ?? BF - ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 31 48 89 D5 48 8D 7C 24 ?? 31 F6 48 C1 E5 ?? 89 C0 45 - 31 E4 48 01 C5 E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 2B 44 24 ?? 48 29 DD 48 8B 54 24 ?? - 2B 54 24 ?? BF ?? ?? ?? ?? F2 48 0F 2A C5 48 8D AC 24 ?? ?? ?? ?? 69 C0 ?? ?? ?? ?? - 01 D0 F2 0F 2A C8 F2 0F 5E C1 F2 0F 2C D8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 C1 BE ?? - ?? ?? ?? BF ?? ?? ?? ?? 31 C0 41 89 D8 48 8D 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 05 - ?? ?? ?? ?? BF ?? ?? ?? ?? 89 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? BE - ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 E0 B9 ?? ?? ?? ?? 48 89 EF F3 48 AB - } - $collect_system_information_64_p2 = { - 48 89 DF 48 89 DA 48 89 EE B1 ?? F3 48 AB BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 54 24 - ?? BE ?? ?? ?? ?? 48 89 DF 31 C0 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 4C 89 E0 B9 - ?? ?? ?? ?? 48 89 DF F3 48 AB 8B 44 24 ?? BE ?? ?? ?? ?? 48 89 DF 8D 90 ?? ?? ?? ?? - 85 C0 0F 49 D0 31 C0 C1 FA ?? 89 54 24 ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 89 DE BF - ?? ?? ?? ?? E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 15 ?? ?? ?? ?? BE ?? - ?? ?? ?? BF ?? ?? ?? ?? 41 89 C5 E8 ?? ?? ?? ?? 4C 89 E0 B9 ?? ?? ?? ?? 48 89 EF F3 - 48 AB 48 89 DF 48 89 DA 48 89 EE B1 ?? F3 48 AB BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 45 85 - ED 75 ?? BA ?? ?? ?? ?? 48 89 DE BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 3D ?? ?? ?? ?? - E8 ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? BE ?? ?? ?? ?? BF - ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8D 7C 24 ?? 31 C9 - BA ?? ?? ?? ?? 31 F6 E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? 5B 5D 41 5C 41 5D C3 - } - $send_system_info_64 = { - 55 53 48 81 EC ?? ?? ?? ?? 48 8D 7C 24 ?? E8 ?? ?? ?? ?? 4C 8D 84 24 ?? ?? ?? ?? 48 - 8D 4C 24 ?? BA ?? ?? ?? ?? BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? BE ?? - ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 31 48 89 D3 31 F6 48 89 E7 48 C1 E3 ?? 89 - C0 48 01 C3 E8 ?? ?? ?? ?? BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 0F 31 48 89 D5 48 8D 7C 24 - ?? 31 F6 89 C0 48 C1 E5 ?? 48 01 C5 E8 ?? ?? ?? ?? 48 8B 44 24 ?? 48 2B 04 24 48 29 - DD 48 8B 54 24 ?? 2B 54 24 ?? BF ?? ?? ?? ?? F2 48 0F 2A C5 69 C0 ?? ?? ?? ?? 01 D0 - F2 0F 2A C8 F2 0F 5E C1 F2 0F 2C D8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 C1 BE ?? ?? ?? - ?? BF ?? ?? ?? ?? 31 C0 41 89 D8 E8 ?? ?? ?? ?? 48 8B 0D ?? ?? ?? ?? BA ?? ?? ?? ?? - BE ?? ?? ?? ?? BF ?? ?? ?? ?? 31 C0 E8 ?? ?? ?? ?? 8B 3D ?? ?? ?? ?? BA ?? ?? ?? ?? - BE ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 81 C4 ?? ?? ?? ?? B8 ?? ?? ?? ?? 5B 5D C3 - } - $parse_c2_commands_64 = { - 41 57 31 C0 49 89 FF B9 ?? ?? ?? ?? 41 56 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 48 - 8D 9C 24 ?? ?? ?? ?? 40 88 B4 24 ?? ?? ?? ?? 4C 8D AC 24 ?? ?? ?? ?? 4C 8D A4 24 ?? - ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 48 89 DF F3 48 AB C7 07 ?? ?? ?? ?? BF ?? ?? ?? ?? - E8 ?? ?? ?? ?? 48 8D 43 ?? 48 89 84 24 ?? ?? ?? ?? 0F 1F 00 8B 3D ?? ?? ?? ?? 31 C9 - BA ?? ?? ?? ?? 48 89 DE E8 ?? ?? ?? ?? 48 85 C0 0F 84 ?? ?? ?? ?? 44 8B B4 24 ?? ?? - ?? ?? 45 85 F6 0F 84 ?? ?? ?? ?? 31 C0 44 89 F6 BF ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 84 - 24 ?? ?? ?? ?? 83 F8 ?? 74 ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 41 83 FE ?? 0F 84 ?? ?? ?? - ?? 41 83 FE ?? 0F 84 ?? ?? ?? ?? 83 F8 ?? 0F 84 ?? ?? ?? ?? 41 83 FE ?? 0F 84 ?? ?? - ?? ?? 41 83 FE ?? 0F 84 ?? ?? ?? ?? 41 83 FE ?? 0F 84 ?? ?? ?? ?? 41 83 FE ?? 0F 85 - ?? ?? ?? ?? 48 8D BC 24 ?? ?? ?? ?? 31 C0 B9 ?? ?? ?? ?? F3 48 AB 48 8B 84 24 ?? ?? - ?? ?? 4C 8B 9C 24 ?? ?? ?? ?? 4C 8B 94 24 ?? ?? ?? ?? 4C 8B 8C 24 ?? ?? ?? ?? 4C 8B - 84 24 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? C7 07 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? - 48 8B 84 24 ?? ?? ?? ?? 48 8B BC 24 ?? ?? ?? ?? 48 8B B4 24 ?? ?? ?? ?? 48 8B 94 24 - ?? ?? ?? ?? 4C 8B B4 24 ?? ?? ?? ?? 4C 8B AC 24 ?? ?? ?? ?? 4C 8B A4 24 ?? ?? ?? ?? - 48 8B AC 24 ?? ?? ?? ?? 48 8B 9C 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 8B 84 24 - ?? ?? ?? ?? 4C 89 9C 24 ?? ?? ?? ?? 4C 89 94 24 ?? ?? ?? ?? 4C 89 8C 24 ?? ?? ?? ?? - 4C 89 84 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? 48 89 BC 24 ?? ?? ?? ?? 48 89 B4 24 - ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? 4C 89 B4 24 ?? ?? ?? ?? 4C 89 AC 24 ?? ?? ?? ?? - 4C 89 A4 24 ?? ?? ?? ?? 48 89 AC 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 84 24 - ?? ?? ?? ?? 49 89 57 ?? 48 8B 94 24 ?? ?? ?? ?? 49 89 77 ?? 48 8D B4 24 - } - $dns_flood_64_p1 = { - 41 55 41 54 55 53 48 81 EC ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 49 89 - FC BB ?? ?? ?? ?? 48 8D 7C 24 ?? 48 89 D9 4C 89 E6 48 8D AC 24 ?? ?? ?? ?? F3 48 A5 - 8B 06 48 89 CB 89 07 0F B7 46 ?? 8B 35 ?? ?? ?? ?? 66 89 47 ?? BF ?? ?? ?? ?? 31 C0 - E8 ?? ?? ?? ?? 48 C7 04 24 ?? ?? ?? ?? 48 C7 44 24 ?? ?? ?? ?? ?? 66 C7 04 24 ?? ?? - 66 C7 44 24 ?? ?? ?? E8 ?? ?? ?? ?? 31 D2 BE ?? ?? ?? ?? BF ?? ?? ?? ?? F7 35 ?? ?? - ?? ?? 89 D2 8B 04 95 ?? ?? ?? ?? BA ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? BA ?? ?? - ?? ?? 48 89 E6 89 C7 41 89 C5 E8 ?? ?? ?? ?? 48 89 D8 B9 ?? ?? ?? ?? 48 89 EF F3 48 - AB 48 8D 7C 24 ?? BE ?? ?? ?? ?? 48 8D 9C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? - 48 8D 7D ?? 48 8D 74 24 ?? 89 84 24 ?? ?? ?? ?? 0F B7 44 24 ?? 66 89 84 24 ?? ?? 00 - 00 E8 ?? ?? ?? ?? 48 89 EE 48 89 DF C6 84 24 ?? ?? ?? ?? ?? C6 84 24 - } - $dns_flood_64_p2 = { - 66 C7 84 24 ?? ?? 00 00 ?? ?? 66 C7 84 24 ?? ?? 00 00 ?? ?? 66 C7 84 24 ?? ?? 00 00 - ?? ?? 66 C7 84 24 ?? ?? 00 00 ?? ?? E8 ?? ?? ?? ?? 48 89 D9 8B 01 48 83 C1 ?? 8D 90 - ?? ?? ?? ?? F7 D0 21 C2 81 E2 ?? ?? ?? ?? 74 ?? 89 D0 C1 E8 ?? F7 C2 ?? ?? ?? ?? 0F - 44 D0 48 8D 41 ?? 48 0F 44 C8 00 D2 48 83 D9 ?? 48 29 D9 48 8D 84 0C ?? ?? ?? ?? 48 - 8D 8C 24 ?? ?? ?? ?? 66 C7 00 ?? ?? 66 C7 40 ?? ?? ?? 48 89 CB 8B 13 48 83 C3 ?? 8D - 82 ?? ?? ?? ?? F7 D2 21 D0 25 ?? ?? ?? ?? 74 ?? 89 C2 48 8D 7C 24 ?? BE ?? ?? ?? ?? - C1 EA ?? A9 ?? ?? ?? ?? 0F 44 C2 48 8D 53 ?? 48 0F 44 DA 00 C0 48 83 DB ?? 48 29 CB - E8 ?? ?? ?? ?? 8B 44 24 ?? 48 8D BC 24 ?? ?? ?? ?? 48 89 EE 89 84 24 ?? ?? ?? ?? 0F - B7 44 24 ?? 66 89 84 24 ?? ?? 00 00 E8 ?? ?? ?? ?? 48 8D 7D ?? 48 8D 74 24 ?? E8 ?? - ?? ?? ?? 41 83 BC 24 ?? ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E8 ?? ?? ?? ?? 89 C2 B9 ?? ?? - ?? ?? 83 C3 ?? C1 FA ?? F7 F9 8D 42 ?? 66 C1 C8 ?? 66 89 84 24 ?? ?? 00 00 E8 ?? ?? - ?? ?? 31 D2 48 8D B4 24 ?? ?? ?? ?? 31 C9 F7 35 ?? ?? ?? ?? 41 B9 ?? ?? ?? ?? 49 89 - E0 44 89 EF 89 D2 8B 04 95 ?? ?? ?? ?? 48 63 D3 89 44 24 ?? E8 ?? ?? ?? ?? 49 83 84 - 24 ?? ?? ?? ?? ?? 83 3D ?? ?? ?? ?? ?? 74 ?? BF ?? ?? ?? ?? E8 - } + $a = { FF FF FF FF 88 DB A2 31 03 A3 5A 5C 9A 19 0E DB } condition: - uint32(0)==0x464C457F and ((( all of ($collect_system_information_32_p*)) and ($send_system_info_32) and ($parse_c2_commands_32) and ( all of ($dns_flood_32_p*))) or (( all of ($collect_system_information_64_p*)) and ($send_system_info_64) and ($parse_c2_commands_64) and ( all of ($dns_flood_64_p*)))) + all of them } -rule REVERSINGLABS_Bytecode_MSIL_Backdoor_Agentracoon : TC_DETECTION MALICIOUS MALWARE FILE +rule ELASTIC_Macos_Trojan_Genieo_5E0F8980 : FILE MEMORY { meta: - description = "Yara rule that detects AgentRacoon backdoor." - author = "ReversingLabs" - id = "ad74d530-ffbd-589f-b941-3a5d9ec737b6" - date = "2023-12-15" - modified = "2023-12-15" - reference = "ReversingLabs" - source_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/yara/backdoor/ByteCode.MSIL.Backdoor.AgentRacoon.yara#L1-L128" - license_url = "https://github.com/reversinglabs/reversinglabs-yara-rules//blob/fb48728b76c37152bb200afb51847f82f75c50c7/LICENSE" - logic_hash = "3ba73f19f59c2e5880df820c52f16997047d7299eb14d421ae2ed8f3790bcfe9" + description = "Detects Macos Trojan Genieo (MacOS.Trojan.Genieo)" + author = "Elastic Security" + id = "5e0f8980-1789-4763-9e41-a521bdb3ff34" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Genieo.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "6c698bac178892dfe03624905256a7d9abe468121163d7507cade48cf2131170" + logic_hash = "76b725f6ae5755bb00d384ef2ae1511789487257d8bb7cb61b893226f03a803e" score = 75 - quality = 90 - tags = "TC_DETECTION, MALICIOUS, MALWARE, FILE" - status = "RELEASED" - sharing = "TLP:WHITE" - category = "MALWARE" - tc_detection_type = "Backdoor" - tc_detection_name = "AgentRacoon" - tc_detection_factor = 5 - importance = 25 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "f0b5198ce85d19889052a7e33fb7cf32a7725c4fdb384ffa7d60d209a7157092" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "macos" strings: - $unpack_response_p1 = { - 17 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 03 18 91 9C 11 ?? 73 ?? ?? ?? ?? 0A 06 16 6F ?? ?? - ?? ?? 2D ?? 73 ?? ?? ?? ?? 7A 17 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 03 19 91 9C 11 ?? 73 - ?? ?? ?? ?? 0A 06 1A 6F ?? ?? ?? ?? 2C ?? 06 1B 6F ?? ?? ?? ?? 2C ?? 06 1C 6F ?? ?? - ?? ?? 2C ?? 06 1D 6F ?? ?? ?? ?? 2C ?? 73 ?? ?? ?? ?? 7A 1F ?? 0B 2B ?? 07 17 58 0B - 03 07 91 2D ?? 07 17 58 0B 03 8E 69 07 59 0C 08 8D ?? ?? ?? ?? 0D 03 07 09 16 08 28 - ?? ?? ?? ?? 1A 13 ?? 2B ?? 11 ?? 17 58 13 ?? 09 11 ?? 91 2D ?? 11 ?? 17 58 13 ?? 09 - 8E 69 11 ?? 59 0C 08 8D ?? ?? ?? ?? 13 ?? 09 11 ?? 11 ?? 16 08 28 ?? ?? ?? ?? 02 12 - ?? FE 15 ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? - 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? - ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? - ?? 12 ?? 07 1F ?? 59 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? - ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 11 ?? 1A 59 8D ?? ?? ?? ?? 7D ?? - ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? - ?? 12 ?? 1A 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 12 ?? 18 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 11 - ?? 7D ?? ?? ?? ?? 03 16 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 03 18 - } - $unpack_response_p2 = { - 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 03 1A 02 7C ?? ?? ?? ?? 7B ?? - ?? ?? ?? 16 18 28 ?? ?? ?? ?? 03 1C 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? - ?? ?? 03 1E 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 03 1F ?? 02 7C ?? - ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 03 1F ?? 02 7C ?? ?? ?? ?? 7B ?? ?? ?? - ?? 16 07 1F ?? 59 28 ?? ?? ?? ?? 09 16 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? - ?? ?? ?? 09 18 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 09 1A 02 7C ?? - ?? ?? ?? 7B ?? ?? ?? ?? 16 11 ?? 1A 59 28 ?? ?? ?? ?? 11 ?? 16 02 7C ?? ?? ?? ?? 7B - ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 11 ?? 18 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 - ?? ?? ?? ?? 11 ?? 1A 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 1A 28 ?? ?? ?? ?? 11 ?? 1E - 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 18 28 ?? ?? ?? ?? 7E ?? ?? ?? ?? 2C ?? 02 7C ?? - ?? ?? ?? 7B ?? ?? ?? ?? 28 ?? ?? ?? ?? 11 ?? 1F ?? 91 13 ?? 02 7C ?? ?? ?? ?? 11 ?? - 8D ?? ?? ?? ?? 7D ?? ?? ?? ?? 11 ?? 1F ?? 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 16 11 ?? - 28 ?? ?? ?? ?? 2A - } - $upload = { - 28 ?? ?? ?? ?? 0A 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 2D ?? DD ?? ?? ?? ?? 16 0B 38 ?? - ?? ?? ?? 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 0C 06 02 7C ?? ?? ?? ?? - 7B ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 08 28 ?? ?? ?? ?? 02 7C ?? ?? ?? ?? - 7B ?? ?? ?? ?? 1B 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 72 ?? ?? ?? ?? A2 11 ?? 17 02 7C ?? - ?? ?? ?? 7B ?? ?? ?? ?? 07 6F ?? ?? ?? ?? A2 11 ?? 18 72 ?? ?? ?? ?? A2 11 ?? ?? 06 - A2 11 ?? 1A 72 ?? ?? ?? ?? A2 11 ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7C ?? ?? ?? ?? - 7B ?? ?? ?? ?? 07 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 07 - 14 6F ?? ?? ?? ?? 07 17 58 0B 07 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 3F - ?? ?? ?? ?? 02 7C ?? ?? ?? ?? 73 ?? ?? ?? ?? 7D ?? ?? ?? ?? 02 7C ?? ?? ?? ?? 73 ?? - ?? ?? ?? 7D ?? ?? ?? ?? DE 23 0D 02 7C ?? ?? ?? ?? 7B ?? ?? ?? ?? 72 ?? ?? ?? ?? 09 - 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? DE ?? 2A - } - $perform_request = { - 05 6F ?? ?? ?? ?? 0A 06 04 3D ?? ?? ?? ?? 06 04 19 5B 18 5A 3F ?? ?? ?? ?? 05 16 06 - 19 5B 6F ?? ?? ?? ?? 0B 05 06 19 5B 06 19 5B 6F ?? ?? ?? ?? 0C 05 06 19 5B 18 5A 6F - ?? ?? ?? ?? 0D 02 07 28 ?? ?? ?? ?? 0B 02 08 28 ?? ?? ?? ?? 0C 02 09 28 ?? ?? ?? ?? - 0D 1F ?? 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 03 A2 11 ?? 17 72 ?? ?? ?? ?? A2 11 ?? 18 07 - A2 11 ?? 19 72 ?? ?? ?? ?? A2 11 ?? 1A 08 A2 11 ?? 1B 72 ?? ?? ?? ?? A2 11 ?? 1C 09 - A2 11 ?? 1D 72 ?? ?? ?? ?? A2 11 ?? 1E 02 28 ?? ?? ?? ?? A2 11 ?? 1F ?? 72 ?? ?? ?? - ?? A2 11 ?? 1F ?? 02 7B ?? ?? ?? ?? A2 11 ?? 28 ?? ?? ?? ?? 10 ?? 38 ?? ?? ?? ?? 06 - 04 19 5B 18 5A 3D ?? ?? ?? ?? 06 04 19 5B 3F ?? ?? ?? ?? 05 16 06 18 5B 6F ?? ?? ?? - ?? 13 ?? 05 06 18 5B 6F ?? ?? ?? ?? 13 ?? 02 11 ?? 28 ?? ?? ?? ?? 13 ?? 02 11 ?? 28 - ?? ?? ?? ?? 13 ?? 1F ?? 8D ?? ?? ?? ?? 13 ?? 11 ?? 16 03 A2 11 ?? 17 72 ?? ?? ?? ?? - A2 11 ?? 18 11 ?? A2 11 ?? 19 72 ?? ?? ?? ?? A2 11 ?? 1A 11 ?? A2 11 ?? 1B 72 ?? ?? - ?? ?? A2 11 ?? 1C 02 28 ?? ?? ?? ?? A2 11 ?? 1D 72 ?? ?? ?? ?? A2 11 ?? 1E 02 7B ?? - ?? ?? ?? A2 11 ?? 28 ?? ?? ?? ?? 10 ?? 2B ?? 02 05 28 ?? ?? ?? ?? 13 ?? 1D 8D ?? ?? - ?? ?? 13 ?? 11 ?? 16 03 A2 11 ?? 17 72 ?? ?? ?? ?? A2 11 ?? 18 11 ?? A2 11 ?? 19 72 - ?? ?? ?? ?? A2 11 ?? 1A 02 28 ?? ?? ?? ?? A2 11 ?? 1B 72 ?? ?? ?? ?? A2 11 ?? 1C 02 - 7B ?? ?? ?? ?? A2 11 ?? 28 ?? ?? ?? ?? 10 ?? 05 2A - } - $get_txt_record = { - 14 0A 03 73 ?? ?? ?? ?? 0B 07 6F ?? ?? ?? ?? 0C 7E ?? ?? ?? ?? 1F ?? 73 ?? ?? ?? ?? - 0D 09 08 08 8E 69 6F ?? ?? ?? ?? 26 09 6F ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? - 09 12 ?? 6F ?? ?? ?? ?? 13 ?? 09 6F ?? ?? ?? ?? 07 11 ?? 6F ?? ?? ?? ?? 07 6F ?? ?? - ?? ?? 13 ?? 28 ?? ?? ?? ?? 12 ?? 7B ?? ?? ?? ?? 6F ?? ?? ?? ?? 13 ?? DE ?? 26 72 ?? - ?? ?? ?? 13 ?? DE ?? 11 ?? 2A - } - $main_loop = { - 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? - ?? ?? 73 ?? ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 18 16 16 6F ?? ?? ?? ?? 0A 06 28 - ?? ?? ?? ?? 2D ?? 2A 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 2C ?? 2A 7E ?? ?? - ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 07 6F ?? ?? ?? - ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0C 12 ?? 7B ?? ?? ?? ?? 0D 12 ?? 7B - ?? ?? ?? ?? 13 ?? 72 ?? ?? ?? ?? 13 ?? 16 13 ?? 2B ?? 7E ?? ?? ?? ?? 19 11 ?? 11 ?? - 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 2D ?? 14 80 ?? ?? ?? ?? 2A 11 ?? 7E ?? ?? ?? ?? 28 ?? - ?? ?? ?? 13 ?? 7E ?? ?? ?? ?? 20 ?? ?? ?? ?? 20 ?? ?? ?? ?? 6F ?? ?? ?? ?? 28 ?? ?? - ?? ?? 11 ?? 17 58 13 ?? 11 ?? 09 32 ?? 7E ?? ?? ?? ?? 11 ?? 6F ?? ?? ?? ?? 0B 73 ?? - ?? ?? ?? 80 ?? ?? ?? ?? 7E ?? ?? ?? ?? 7E ?? ?? ?? ?? 07 6F ?? ?? ?? ?? 6F ?? ?? ?? - ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? 6F ?? ?? ?? ?? 0B 7E ?? ?? ?? ?? 07 - 17 6F ?? ?? ?? ?? 13 ?? 11 ?? 7E ?? ?? ?? ?? 1A 16 16 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? - 11 ?? 6F ?? ?? ?? ?? 28 ?? ?? ?? ?? 26 DD ?? ?? ?? ?? 26 DE ?? 2A - } + $a = { 00 CD 01 1E 68 57 58 D7 56 7C 62 C9 27 3C C6 15 A9 3D 01 02 2F E1 69 B5 4A 11 } condition: - uint16(0)==0x5A4D and ( all of ($unpack_response_p*)) and ($upload) and ($perform_request) and ($get_txt_record) and ($main_loop) + all of them } -/* - * YARA Rule Set - * Repository Name: Elastic - * Repository: https://github.com/elastic/protections-artifacts/ - * Retrieval Date: 2024-08-04 - * Git Commit: 9038ed0994941166ede4355ee47e1ae8467ce23e - * Number of Rules: 1773 - * Skipped: 0 (age), 5 (quality), 0 (score), 0 (importance) - * - * - * LICENSE - * - * Elastic License 2.0 +rule ELASTIC_Macos_Trojan_Genieo_37878473 : FILE MEMORY +{ + meta: + description = "Detects Macos Trojan Genieo (MacOS.Trojan.Genieo)" + author = "Elastic Security" + id = "37878473-b6f8-4cbe-ba70-31ecddf41c82" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Genieo.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0fadd926f8d763f7f15e64f857e77f44a492dcf5dc82ae965d3ddf80cd9c7a0d" + logic_hash = "bb04ae4e0a98e0dbd0c0708d5e767306e38edf76de2671523f4bd43cbcbfefc2" + score = 75 + quality = 73 + tags = "FILE, MEMORY" + fingerprint = "e9760bda6da453f75e543c919c260a4560989f62f3332f28296283d4c01b62a2" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "macos" -URL: https://www.elastic.co/licensing/elastic-license + strings: + $a = { 65 72 6E 61 6C 44 6F 77 6E 4C 6F 61 64 55 72 6C 46 6F 72 42 72 61 6E 64 3A 5D } -## Acceptance + condition: + all of them +} +rule ELASTIC_Macos_Trojan_Genieo_0D003634 : FILE MEMORY +{ + meta: + description = "Detects Macos Trojan Genieo (MacOS.Trojan.Genieo)" + author = "Elastic Security" + id = "0d003634-8b17-4e26-b4a2-4bfce2e64dde" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Genieo.yar#L41-L59" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "bcd391b58338efec4769e876bd510d0c4b156a7830bab56c3b56585974435d70" + logic_hash = "0412f88408fb14d1126ef091d0a5cc0ee2b2e39aeb241bef55208b59830ca993" + score = 75 + quality = 73 + tags = "FILE, MEMORY" + fingerprint = "6f38b7fc403184482449957aff51d54ac9ea431190c6f42c7a5420efbfdb8f7d" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "macos" -By using the software, you agree to all of the terms and conditions below. + strings: + $a = { 75 69 6C 64 2F 41 6E 61 62 65 6C 50 61 63 6B 61 67 65 2F 62 75 69 6C 64 2F 73 } -## Copyright License + condition: + all of them +} +rule ELASTIC_Macos_Trojan_Genieo_9E178C0B : FILE MEMORY +{ + meta: + description = "Detects Macos Trojan Genieo (MacOS.Trojan.Genieo)" + author = "Elastic Security" + id = "9e178c0b-02ca-499b-93d1-2b6951d41435" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Genieo.yar#L61-L79" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b7760e73195c3ea8566f3ff0427d85d6f35c6eec7ee9184f3aceab06da8845d8" + logic_hash = "212f96ca964aceeb80c6d3282d488cfbb74aeffb9c0c9dd840a3a28f9bbdcbea" + score = 75 + quality = 73 + tags = "FILE, MEMORY" + fingerprint = "b00bffbdac79c5022648bf8ca5a238db7e71f3865a309f07d068ee80ba283b82" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "macos" -The licensor grants you a non-exclusive, royalty-free, worldwide, -non-sublicensable, non-transferable license to use, copy, distribute, make -available, and prepare derivative works of the software, in each case subject to -the limitations and conditions below. + strings: + $a = { 4D 49 70 67 41 59 4B 6B 42 5A 59 53 65 4D 6B 61 70 41 42 48 4D 5A 43 63 44 44 } -## Limitations + condition: + all of them +} +rule ELASTIC_Windows_Ransomware_Helloxd_0C50F01B : FILE MEMORY +{ + meta: + description = "Detects Windows Ransomware Helloxd (Windows.Ransomware.Helloxd)" + author = "Elastic Security" + id = "0c50f01b-5f3d-4112-9930-ca1150fc12fa" + date = "2022-06-14" + modified = "2022-07-18" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Helloxd.yar#L1-L26" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "435781ab608ff908123d9f4758132fa45d459956755d27027a52b8c9e61f9589" + logic_hash = "71e09fa1a00fa6f3688129ee2b2a8957b84f64ef51fcba5123a6a9df80a9c7e1" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "462d8c231d608e28e66d810b811f9fdf82d0b3770d21267a4375669a26bbaafd" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "windows" -You may not provide the software to third parties as a hosted or managed -service, where the service provides users with access to any substantial set of -the features or functionality of the software. + strings: + $mutex = "With best wishes And good intentions..." + $ransomnote0 = ":: our TOX below >:)" + $ransomnote1 = "You can download TOX here" + $ransomnote2 = "...!XD ::" + $productname = "HelloXD" ascii wide + $legalcopyright = "uKn0w" ascii wide + $description = "VhlamAV" ascii wide + $companyname = "MicloZ0ft" ascii wide -You may not move, change, disable, or circumvent the license key functionality -in the software, and you may not remove or obscure any functionality in the -software that is protected by the license key. + condition: + ($mutex and all of ($ransomnote*)) or (3 of ($productname,$legalcopyright,$description,$companyname)) +} +rule ELASTIC_Windows_Trojan_Rudebird_3Cbf7Bc6 : FILE MEMORY +{ + meta: + description = "Detects Windows Trojan Rudebird (Windows.Trojan.RudeBird)" + author = "Elastic Security" + id = "3cbf7bc6-71c5-4c7c-a846-7a95c3d28917" + date = "2023-05-09" + modified = "2023-06-13" + reference = "https://www.elastic.co/security-labs/introducing-the-ref5961-intrusion-set" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_RudeBird.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "2095c3b6bde779b5661c7796b5e33bb0c43facf791b272a603b786f889a06a95" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "f70bd86d877d9371601c7f65cf50a5bb9b76ba45acbf591bd8e4c1117a0cac1d" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "windows" -You may not alter, remove, or obscure any licensing, copyright, or other notices -of the licensor in the software. Any use of the licensor’s trademarks is subject -to applicable law. + strings: + $a1 = { 40 53 48 83 EC 20 48 8B D9 B9 D8 00 00 00 E8 FD C1 FF FF 48 8B C8 33 C0 48 85 C9 74 05 E8 3A F2 } -## Patents + condition: + all of them +} +rule ELASTIC_Linux_Exploit_Vmsplice_Cfa94001 : FILE MEMORY +{ + meta: + description = "Detects Linux Exploit Vmsplice (Linux.Exploit.Vmsplice)" + author = "Elastic Security" + id = "cfa94001-6000-4633-9af2-efabfaa96f94" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Vmsplice.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0a26e67692605253819c489cd4793a57e86089d50150124394c30a8801bf33e6" + logic_hash = "b5a86a79384997f977d353371ccaa8c736f5c24af40b85a24076d4c4fb79a237" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "3fb484112484e2afc04a88d50326312af950605c61f258651479427b7bae300a" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" -The licensor grants you a license, under any patent claims the licensor can -license, or becomes able to license, to make, have made, use, sell, offer for -sale, import and have imported the software, in each case subject to the -limitations and conditions in this license. This license does not cover any -patent claims that you cause to be infringed by modifications or additions to -the software. If you or your company make any written claim that the software -infringes or contributes to infringement of any patent, your patent license for -the software granted under these terms ends immediately. If your company makes -such a claim, your patent license ends immediately for work on behalf of your -company. + strings: + $a = { 7A 00 21 40 23 24 00 6D 6D 61 70 00 5B 2B 5D 20 6D 6D 61 70 3A } -## Notices + condition: + all of them +} +rule ELASTIC_Linux_Exploit_Vmsplice_A000F267 : FILE MEMORY +{ + meta: + description = "Detects Linux Exploit Vmsplice (Linux.Exploit.Vmsplice)" + author = "Elastic Security" + id = "a000f267-b4d7-46e9-ab61-818633083ba2" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Vmsplice.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c85cc6768a28fb7de16f1cad8d3c69d8f0b4aa01e00c8e48759d27092747ca6f" + logic_hash = "2a8cb11bb21f2ce620a6fa1f0fb932bef60a479fac836058ec4e8c760b5d60f9" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "0753ef1bc3e151fd6d4773967b5cde6ad789df593e7d8b9ed08052151a1a1849" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" -You must ensure that anyone who gets a copy of any part of the software from you -also gets a copy of these terms. + strings: + $a = { 24 04 73 00 00 00 89 44 24 00 CF 83 C4 10 5B C9 C3 55 89 E5 83 } -If you modify the software, you must include in any modified copies of the -software prominent notices stating that you have modified the software. + condition: + all of them +} +rule ELASTIC_Linux_Exploit_Vmsplice_8B9E4F9F : FILE MEMORY +{ + meta: + description = "Detects Linux Exploit Vmsplice (Linux.Exploit.Vmsplice)" + author = "Elastic Security" + id = "8b9e4f9f-7903-4aa5-9098-766f4311a22b" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Vmsplice.yar#L41-L59" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0230c81ba747e588cd9b6113df6e1867dcabf9d8ada0c1921d1bffa9c1b9c75d" + logic_hash = "6979a900a2532a8da36711f3ffe13f71ec4efa7771aa2feec9391bd031aaa023" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "585b16ad3e4489a17610f0a226be428def33e411886f273d0c1db45b3819ba3f" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" -## No Other Rights + strings: + $a = { 00 00 00 00 20 4C 69 6E 75 78 20 76 6D 73 70 6C } -These terms do not imply any licenses other than those expressly granted in -these terms. + condition: + all of them +} +rule ELASTIC_Linux_Exploit_Vmsplice_055F88B8 : FILE MEMORY +{ + meta: + description = "Detects Linux Exploit Vmsplice (Linux.Exploit.Vmsplice)" + author = "Elastic Security" + id = "055f88b8-b1b0-4b02-8fc5-97804b564d27" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Vmsplice.yar#L61-L79" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "607c8c5edc8cbbd79a40ce4a0eccf46e01447985d9415d1eff6a91bf64074507" + logic_hash = "29e59bb372f0b37b507c72e5b5bcb27ba0fa2aaac71ea77f0cab85af31708c8a" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "38f7d6c56ee1cd465062b5c82320710c4d0393a3b33f5586b6c0c0c778e5d3b2" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" -## Termination + strings: + $a = { 2D 2D 2D 00 20 4C 69 6E 75 78 20 76 6D 73 70 6C } -If you use the software in violation of these terms, such use is not licensed, -and your licenses will automatically terminate. If the licensor provides you -with a notice of your violation, and you cease all violation of this license no -later than 30 days after you receive that notice, your licenses will be -reinstated retroactively. However, if you violate these terms after such -reinstatement, any additional violation of these terms will cause your licenses -to terminate automatically and permanently. + condition: + all of them +} +rule ELASTIC_Linux_Exploit_Vmsplice_431E689D : FILE MEMORY +{ + meta: + description = "Detects Linux Exploit Vmsplice (Linux.Exploit.Vmsplice)" + author = "Elastic Security" + id = "431e689d-0c41-4c92-98b0-0dac529d8328" + date = "2021-06-28" + modified = "2021-09-16" + reference = "1cbb09223f16af4cd13545d72dbeeb996900535b1e279e4bcf447670728de1e1" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Vmsplice.yar#L81-L99" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "5b9a7ffcd6fc6893a8224fd2b9ca59f4cff6086669a73190114db510a1ad9ff2" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "1e8aee445a3adef6ccbd2d25f7b38202bef98a99b828eda56fb8b9269b6316b4" + severity = "100" + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" -## No Liability + strings: + $a = { 69 6F 6E 00 70 75 74 65 6E 76 00 73 74 64 6F 75 74 00 73 65 } -*As far as the law allows, the software comes as is, without any warranty or -condition, and the licensor will not be liable to you for any damages arising -out of these terms or the use or nature of the software, under any kind of -legal claim.* + condition: + all of them +} +rule ELASTIC_Linux_Virus_Thebe_1Eb5985A : FILE MEMORY +{ + meta: + description = "Detects Linux Virus Thebe (Linux.Virus.Thebe)" + author = "Elastic Security" + id = "1eb5985a-2b35-434f-81d9-f502dff25397" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Virus_Thebe.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "30af289be070f4e0f8761f04fb44193a037ec1aab9cc029343a1a1f2a8d67670" + logic_hash = "7d4bc4b1615048dec1f1fac599afa667e06ccb369bb1242b25887e0ce2a5066a" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "5cf9aa9a31c36028025d5038c98d56aef32c9e8952aa5cd4152fbd811231769e" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" -## Definitions + strings: + $a = { 42 31 C9 31 DB 31 F6 B0 1A CD 80 85 C0 0F 85 83 } -The **licensor** is the entity offering these terms, and the **software** is the -software the licensor makes available under these terms, including any portion -of it. + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Getshell_98D002Bf : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Getshell (Linux.Trojan.Getshell)" + author = "Elastic Security" + id = "98d002bf-63b7-4d11-98ef-c3127e68d59c" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Getshell.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "97b7650ab083f7ba23417e6d5d9c1d133b9158e2c10427d1f1e50dfe6c0e7541" + logic_hash = "358575f55910b060bde94bbc55daa9650a43cf1470b77d1842ddcaa8b299700a" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "b7bfec0a3cfc05b87fefac6b10673491b611400edacf9519cbcc1a71842e9fa3" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" -**you** refers to the individual or entity agreeing to these terms. + strings: + $a = { B2 6A B0 03 CD 80 85 C0 78 02 FF E1 B8 01 00 00 00 BB 01 00 } -**your company** is any legal entity, sole proprietorship, or other kind of -organization that you work for, plus all organizations that have control over, -are under the control of, or are under common control with that -organization. **control** means ownership of substantially all the assets of an -entity, or the power to direct its management and policies by vote, contract, or -otherwise. Control can be direct or indirect. + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Getshell_213D4D69 : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Getshell (Linux.Trojan.Getshell)" + author = "Elastic Security" + id = "213d4d69-5660-468d-a98c-ff3eef604b1e" + date = "2021-06-28" + modified = "2021-09-16" + reference = "05fc4dcce9e9e1e627ebf051a190bd1f73bc83d876c78c6b3d86fc97b0dfd8e8" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Getshell.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "2075def88b31ac32e44c270ab20273c8b91f37e25a837c0353f76bcf431cdcb3" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "60e385e4c5eb189785bc14d39bf8a22c179e4be861ce3453fbcf4d367fc87c90" + severity = "100" + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" -**your licenses** are all the licenses granted to you for the software under -these terms. + strings: + $a = { EC 01 00 00 00 EB 3C 8B 45 EC 48 98 48 C1 E0 03 48 03 45 D0 48 } -**use** means anything you do with the software requiring one of your licenses. + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Getshell_3Cf5480B : FILE MEMORY +{ + meta: + description = "Detects Linux Trojan Getshell (Linux.Trojan.Getshell)" + author = "Elastic Security" + id = "3cf5480b-bb21-4a6e-a078-4b145d22c79f" + date = "2021-06-28" + modified = "2021-09-16" + reference = "0e41c0d6286fb7cd3288892286548eaebf67c16f1a50a69924f39127eb73ff38" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Getshell.yar#L41-L59" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "87b0db74e81d4f236b11f51a72fba2e4263c988402292b2182d19293858c6126" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "3ef0817445c54994d5a6792ec0e6c93f8a51689030b368eb482f5ffab4761dd2" + severity = "100" + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "linux" -**trademark** means trademarks, service marks, and similar rights. + strings: + $a = { B2 24 B0 03 CD 80 85 C0 78 02 FF E1 B8 01 00 00 00 BB 01 00 } - */ -rule ELASTIC_Linux_Ransomware_Lockbit_D248E80E : FILE MEMORY + condition: + all of them +} +rule ELASTIC_Linux_Trojan_Getshell_8A79B859 : FILE MEMORY { meta: - description = "Detects Linux Ransomware Lockbit (Linux.Ransomware.Lockbit)" + description = "Detects Linux Trojan Getshell (Linux.Trojan.Getshell)" author = "Elastic Security" - id = "d248e80e-3e2f-4957-adc3-0c912b0cd386" - date = "2023-07-27" - modified = "2024-02-13" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Ransomware_Lockbit.yar#L1-L24" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "4800a67ceff340d2ab4f79406a01f58e5a97d589b29b35394b2a82a299b19745" - logic_hash = "5d33d243cd7f9d9189139eb34a4dd8d81882be200223d5c8e60dfd07ca98f94b" + id = "8a79b859-654c-4082-8cfc-61a143671457" + date = "2021-06-28" + modified = "2021-09-16" + reference = "1154ba394176730e51c7c7094ff3274e9f68aaa2ed323040a94e1c6f7fb976a2" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Getshell.yar#L61-L79" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "2aa3914ec4cc04e5daa2da1460410b4f0e5e7a37c5a2eae5a02ff5f55382f1fe" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "417ecf5a0b6030ed5b973186efa1e72dfa56886ba6cfc5fbf615e0814c24992f" - severity = 100 + fingerprint = "5a95d1df94791c8484d783da975bec984fb11653d1f81f6397efd734a042272b" + severity = "100" arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" os = "linux" strings: - $a1 = "restore-my-files.txt" fullword - $b1 = "xkeyboard-config" fullword - $b2 = "bootsect.bak" fullword - $b3 = "lockbit" fullword - $b4 = "Error: %s" fullword - $b5 = "crypto_generichash_blake2b_final" fullword + $a = { 0A 00 89 E1 6A 1C 51 56 89 E1 43 6A 66 58 CD 80 B0 66 B3 04 } condition: - $a1 and 2 of ($b*) + all of them } -rule ELASTIC_Linux_Ransomware_Lockbit_5B30A04B : FILE MEMORY +rule ELASTIC_Windows_Trojan_Falsefont_D1F0D357 : FILE MEMORY { meta: - description = "Detects Linux Ransomware Lockbit (Linux.Ransomware.Lockbit)" + description = "Detects Windows Trojan Falsefont (Windows.Trojan.FalseFont)" author = "Elastic Security" - id = "5b30a04b-d618-4698-a797-30bf6d4a001c" - date = "2023-07-29" - modified = "2024-02-13" + id = "d1f0d357-26cb-4dab-8ca6-65f17109982b" + date = "2024-03-26" + modified = "2024-05-08" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Ransomware_Lockbit.yar#L26-L46" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "41cbb7d79388eaa4d6e704bd4a8bf8f34d486d27277001c343ea3ce112f4fb0d" - logic_hash = "b89d0f25f08ffa35e075def6a29cf52a80500c6499732146426a71c741059a3b" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_FalseFont.yar#L1-L26" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "364275326bbfc4a3b89233dabdaf3230a3d149ab774678342a40644ad9f8d614" + logic_hash = "af356dec77f773cec01626a3823dbea7e9d3719b9d152ec4057c0b97efabf0df" score = 75 - quality = 69 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "99bf6afb1554ec3b3b82389c93ca87018c51f7a80270d64007a5f5fc59715c45" + fingerprint = "ad63447832e9a160d479fccd780de89b9c29b9697f69ac3553e39bc388d49b83" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a1 = { 5D 50 4A 49 55 58 40 77 58 54 5C } - $a2 = { 33 6B 5C 5A 4C 4B 4A 50 4F 5C 55 40 } - $a3 = { 5E 4C 58 4B 58 57 4D 5C 5C 5D } + $s1 = "KillById" + $s2 = "KillByName" + $s3 = "SignalRHub" + $s4 = "ExecUseShell" + $s5 = "ExecAndKeepAlive" + $s6 = "SendAllDirectoryWithStartPath" + $s7 = "AppLiveDirectorySendHard" + $s8 = "AppLiveDirectorySendScreen" condition: - all of them + 4 of them } -rule ELASTIC_Windows_Ransomware_Nightsky_A7F19411 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Bitsloth_05Fc3A0A : FILE MEMORY { meta: - description = "Detects Windows Ransomware Nightsky (Windows.Ransomware.Nightsky)" + description = "Detects Windows Trojan Bitsloth (Windows.Trojan.BITSloth)" author = "Elastic Security" - id = "a7f19411-4c28-4cc7-b60c-ef51cb10b905" - date = "2022-01-11" - modified = "2022-04-12" + id = "05fc3a0a-ce19-4042-90f8-32a43f40616e" + date = "2024-07-16" + modified = "2024-07-26" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Nightsky.yar#L1-L22" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "1fca1cd04992e0fcaa714d9dfa97323d81d7e3d43a024ec37d1c7a2767a17577" - logic_hash = "defc7ab43035c663302edfda60a4b57cb301b3d61662afe3ce1de2ac93cfc3e2" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_BITSloth.yar#L1-L27" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0944b17a4330e1c97600f62717d6bae7e4a4260604043f2390a14c8d76ef1507" + logic_hash = "8210dc28cf408f7f836aad3c32868ea21dd0862070c2c37d98b089a80be9285e" score = 75 - quality = 48 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "0f2aac3a538a921b78f7c2521adf65678830abab8ec8b360ac3dddae5fbc4756" - severity = 90 + fingerprint = "520722d4502230eed76b0c53fffb90bd2b818256363bc1393f51c378ff6cdd9b" + severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" os = "windows" strings: - $a1 = "\\NightSkyReadMe.hta" wide fullword - $a2 = ".nightsky" wide fullword - $a3 = "
Do not try to decrypt then by yourself - it's impossible" ascii fullword + $a = { FE 8A 14 06 88 50 FF 8A 54 BC 11 88 10 8A 54 BC 10 88 50 01 47 83 } condition: all of them } -rule ELASTIC_Linux_Hacktool_Portscan_A40C7Ef0 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Qbot_7D5Dc64A : FILE MEMORY { meta: - description = "Detects Linux Hacktool Portscan (Linux.Hacktool.Portscan)" + description = "Detects Windows Trojan Qbot (Windows.Trojan.Qbot)" author = "Elastic Security" - id = "a40c7ef0-627c-4965-b4d3-b05b79586170" - date = "2021-01-12" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Hacktool_Portscan.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "c389c42bac5d4261dbca50c848f22c701df4c9a2c5877dc01e2eaa81300bdc29" - logic_hash = "6118ea86d628450e79ee658f4b95bae40080764a25240698d8ca7fcb7e6adaaf" + id = "7d5dc64a-a597-44ac-a0fd-cefffc5e9cff" + date = "2021-10-04" + modified = "2022-01-13" + reference = "https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Qbot.yar#L22-L42" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "a2bacde7210d88675564106406d9c2f3b738e2b1993737cb8bf621b78a9ebf56" + logic_hash = "5c8858502050494ab20a230f04c2c1cb4bfcd80f4a248dad82787d7ce67c741d" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "bf686c3c313936a144265cbf75850c8aee3af3ae36cb571050c7fceed385451d" + fingerprint = "ab80d96a454e0aad56621e70be4d55f099c41b538a380feb09192d252b4db5aa" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 54 50 44 00 52 65 73 70 6F 6E 73 65 20 77 61 73 20 4E 54 50 20 } + $a1 = "%u.%u.%u.%u.%u.%u.%04x" ascii fullword + $a2 = "stager_1.dll" ascii fullword condition: all of them } -rule ELASTIC_Linux_Hacktool_Portscan_6C6000C2 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Qbot_6Fd34691 : FILE MEMORY { meta: - description = "Detects Linux Hacktool Portscan (Linux.Hacktool.Portscan)" + description = "Detects Windows Trojan Qbot (Windows.Trojan.Qbot)" author = "Elastic Security" - id = "6c6000c2-7e9a-457c-a745-00a3ac83a4bc" - date = "2021-01-12" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Hacktool_Portscan.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "8877009fc8ee27ba3b35a7680b80d21c84ee7296bcabe1de51aeeafcc8978da7" - logic_hash = "0cae81cbc0fdf48b4e7ac09865f05e2ad93d79b7a6f1af76a632727127ab050f" + id = "6fd34691-10e4-4a66-85ff-1b67ed3da4dd" + date = "2022-03-07" + modified = "2022-04-12" + reference = "https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Qbot.yar#L44-L64" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0838cd11d6f504203ea98f78cac8f066eb2096a2af16d27fb9903484e7e6a689" + logic_hash = "9422d9f276f0c8c2990ece3282d918abc6fcce7eeb6809d46ae6b768a501a877" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "3c893aebe688d70aebcb15fdc0d2780d2ec0589084c915ff71519ec29e5017f1" + fingerprint = "187fc04abcba81a2cbbe839adf99b8ab823cbf65993c8780d25e7874ac185695" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 30 B9 0E 00 00 00 4C 89 D7 F3 A6 0F 97 C2 80 DA 00 84 D2 45 0F } + $a1 = { 75 C9 8B 45 1C 89 45 A4 8B 45 18 89 45 A8 8B 45 14 89 45 AC 8B } + $a2 = "\\stager_1.obf\\Benign\\mfc\\" wide condition: - all of them + any of them } -rule ELASTIC_Linux_Hacktool_Portscan_E191222D : FILE MEMORY +rule ELASTIC_Windows_Trojan_Qbot_3074A8D4 : FILE MEMORY { meta: - description = "Detects Linux Hacktool Portscan (Linux.Hacktool.Portscan)" + description = "Detects Windows Trojan Qbot (Windows.Trojan.Qbot)" author = "Elastic Security" - id = "e191222d-633a-4408-9a54-a70bb9e89cc0" - date = "2021-01-12" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Hacktool_Portscan.yar#L41-L59" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "e2f4313538c3ef23adbfc50f37451c318bfd1ffd0e5aaa346cce4cc37417f812" - logic_hash = "6ffb2add4a76214ffd555cf1fe356371acd3638216094097b355670ecfe02ecd" + id = "3074a8d4-d93c-4987-9031-9ecd3881730d" + date = "2022-06-07" + modified = "2022-07-18" + reference = "https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Qbot.yar#L66-L97" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c2ba065654f13612ae63bca7f972ea91c6fe97291caeaaa3a28a180fb1912b3a" + logic_hash = "90c06bd09fe640bb5a6be8e4f2384fb15c7501674d57db005e790ed336740c99" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "5580dd8b9180b8ff36c7d08a134b1b3782b41054d8b29b23fc5a79e7b0059fd1" + fingerprint = "c233a0c24576450ce286d96126379b6b28d537619e853d860e2812f521b810ac" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 46 4F 55 4E 44 00 56 41 4C 55 45 00 44 45 4C 45 54 45 44 00 54 } + $a1 = "qbot" wide + $a2 = "stager_1.obf\\Benign\\mfc" wide + $a3 = "common.obf\\Benign\\mfc" wide + $a4 = "%u;%u;%u;" + $a5 = "%u.%u.%u.%u.%u.%u.%04x" + $a6 = "%u&%s&%u" + $get_string1 = { 33 D2 8B ?? 6A 5A 5? F7 ?? 8B ?? 08 8A 04 ?? 8B 55 ?? 8B ?? 10 3A 04 ?? } + $get_string2 = { 33 D2 8B ?? F7 75 F4 8B 45 08 8A 04 02 32 04 ?? 88 04 ?? ?? 83 ?? 01 } + $set_key = { 8D 87 00 04 00 00 50 56 E8 ?? ?? ?? ?? 59 8B D0 8B CE E8 } + $do_computer_use_russian_like_keyboard = { B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D } + $execute_each_tasks = { 8B 44 0E ?? 85 C0 74 ?? FF D0 EB ?? 6A 00 6A 00 6A 00 FF 74 0E ?? E8 ?? ?? ?? ?? 83 C4 10 } + $generate_random_alpha_num_string = { 57 E8 ?? ?? ?? ?? 48 50 8D 85 ?? ?? ?? ?? 6A 00 50 E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C } + $load_base64_dll_from_file_and_inject_into_targets = { 10 C7 45 F0 50 00 00 00 83 65 E8 00 83 7D F0 0B 73 08 8B 45 F0 89 } condition: - all of them + 6 of them } -rule ELASTIC_Linux_Hacktool_Portscan_E57B0A0C : FILE MEMORY +rule ELASTIC_Windows_Trojan_Qbot_1Ac22A26 : FILE MEMORY { meta: - description = "Detects Linux Hacktool Portscan (Linux.Hacktool.Portscan)" + description = "Detects Windows Trojan Qbot (Windows.Trojan.Qbot)" author = "Elastic Security" - id = "e57b0a0c-66b8-488b-b19d-ae06623645fd" - date = "2021-01-12" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Hacktool_Portscan.yar#L61-L79" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "f8ee385316b60ee551565876287c06d76ac5765f005ca584d1ca6da13a6eb619" - logic_hash = "b2f67805e9381864591fdf61846284da97f8dd2f5c60484ce9c6e76d2f6f3872" + id = "1ac22a26-ec88-4e88-8fe6-a092bbb61904" + date = "2022-12-29" + modified = "2023-02-01" + reference = "https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Qbot.yar#L99-L136" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c2ba065654f13612ae63bca7f972ea91c6fe97291caeaaa3a28a180fb1912b3a" + logic_hash = "d9beaf4a8c28a0b3c38dda6bf22a96b8c96ef715bd36de880504a9f970338fe2" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "829c7d271ae475ef06d583148bbdf91af67ce4c7a831da73cc52e8406e7e8f9e" + fingerprint = "22436c48bc775284d1f682eaeb650fd998302021342efc322c4ca40dd30f1a0d" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 10 83 7D 08 03 75 2B 83 EC 0C 8B 45 0C 83 C0 08 FF 30 8B 45 0C 83 } + $a1 = "qbot" wide + $a2 = "stager_1.obf\\Benign\\mfc" wide + $a3 = "common.obf\\Benign\\mfc" wide + $a4 = "%u;%u;%u" + $a5 = "%u.%u.%u.%u.%u.%u.%04x" + $a6 = "%u&%s&%u" + $a7 = "mnjhuiv40" + $a8 = "\\u%04X" + $get_string1 = { 33 D2 8B ?? 6A ?? 5? F7 ?? 8B ?? 08 8A 04 ?? 8B 55 ?? 8B ?? 10 3A 04 } + $get_string2 = { 8B C6 83 E0 ?? 8A 04 08 3A 04 1E 74 ?? 46 3B F2 72 } + $get_string3 = { 8A 04 ?? 32 04 ?? 88 04 ?? 4? 83 ?? 01 } + $set_key_1 = { 8D 87 00 04 00 00 50 56 E8 [4] 59 8B D0 8B CE E8 } + $set_key_2 = { 59 6A 14 58 6A 0B 66 89 87 [0-1] 20 04 00 00 } + $cccp_keyboard_0 = { 6A ?? 66 89 45 E? 58 6A ?? 66 89 45 E? 58 } + $cccp_keyboard_1 = { 66 8B 84 9? ?? FE FF FF B9 FF 03 00 00 66 23 C1 33 ?? 0F B7 } + $execute_each_tasks = { 8B 0D [4] 83 7C 0E 04 00 74 ?? 83 7C 0E 1C 00 74 ?? 8B 04 0E 85 C0 7E ?? 6B C0 3C } + $generate_random_alpha_num_string = { 57 E8 [4] 48 50 8D 85 [4] 6A 00 50 E8 [4] 8B 4D ?? 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C } + $load_and_inject_b64_dll_from_file = { 6B 45 FC 18 8B 4D F8 83 7C 01 04 00 76 ?? 6A 00 6B 45 FC 18 8B 4D F8 FF 74 01 10 6B 45 FC 18 } + $decipher_rsrc_data = { F6 86 38 04 00 00 04 89 BE 2C 04 00 00 89 BE 28 04 00 00 [2-6] 8B 0B 8D 45 F? 83 65 F? 00 8B D7 50 E8 } condition: - all of them + 6 of them } -rule ELASTIC_Linux_Trojan_Ebury_7B13E9B6 : FILE MEMORY +rule ELASTIC_Windows_Vulndriver_Hpportio_B31E3473 : FILE { meta: - description = "Detects Linux Trojan Ebury (Linux.Trojan.Ebury)" + description = "Name: HpPortIox64.sys, Version: 1.2.0.9" author = "Elastic Security" - id = "7b13e9b6-ce96-4bd3-8196-83420280bd1f" - date = "2021-01-12" - modified = "2021-09-16" + id = "b31e3473-b87e-47df-b3ec-b09c69dcbb4e" + date = "2022-04-07" + modified = "2022-04-07" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Ebury.yar#L1-L18" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "30d126ffc5b782236663c23734f1eef21e1cc929d549a37bba8e1e7b41321111" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_HpPortIo.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c5050a2017490fff7aa53c73755982b339ddb0fd7cef2cde32c81bc9834331c5" + logic_hash = "e449b45f3cf2836254614bbdc957aa7093162fc1acd672edd931d5f240503963" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "a891724ce36e86637540f722bc13b44984771f709219976168f12fe782f08306" - severity = 100 + tags = "FILE" + fingerprint = "66067334492941eb2da8c72dc0d2f55ba1c2b564904f40b6e77925262501abd9" + threat_name = "Windows.VulnDriver.HpPortIo" + severity = 50 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 8B 44 24 10 4C 8B 54 24 18 4C 8B 5C 24 20 8B 5C 24 28 74 04 } + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 48 00 70 00 50 00 6F 00 72 00 74 00 49 00 6F 00 78 00 36 00 34 00 2E 00 73 00 79 00 73 00 00 00 } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x02][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x09][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x01][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ condition: - all of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version } -rule ELASTIC_Linux_Ransomware_Blackbasta_96Eb3F20 : FILE MEMORY +rule ELASTIC_Windows_Ransomware_Phobos_A5420148 : BETA FILE MEMORY { meta: - description = "Detects Linux Ransomware Blackbasta (Linux.Ransomware.BlackBasta)" + description = "Identifies Phobos ransomware" author = "Elastic Security" - id = "96eb3f20-9c40-4d40-8a6c-568a51c52d4d" - date = "2022-08-06" - modified = "2022-08-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Ransomware_BlackBasta.yar#L1-L25" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "96339a7e87ffce6ced247feb9b4cb7c05b83ca315976a9522155bad726b8e5be" - logic_hash = "a5e0b60ba51490f70af53c9fba91e3349c712bebb10574eb4bed028ab961ae74" + id = "a5420148-2f80-4a14-8a0d-98943fcbe784" + date = "2020-06-25" + modified = "2021-08-23" + reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phobos" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Phobos.yar#L1-L22" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "9fcfe41102bee4f8ecf19f30d0bbb2de50e1a1aff4e17c587b5d9adb417527c5" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "5146ad9def7ccaba4b4896f345b0950c587ad5f96a106ec461caeb028d809ead" + tags = "BETA, FILE, MEMORY" + fingerprint = "2b3937dbecb9a12e5e276c681eb40cb3884411a048175fcfe1bd4be3f7611aca" + threat_name = "Windows.Ransomware.Phobos" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a1 = "Done time: %.4f seconds, encrypted: %.4f gb" ascii fullword - $a2 = "Your data are stolen and encrypted" ascii fullword - $a3 = "fileEncryptionPercent" ascii fullword - $a4 = "fileQueueLocker" ascii fullword - $a5 = "totalBytesEncrypted" ascii fullword - $seq_encrypt_block = { 41 56 31 D2 41 55 41 54 49 89 FE 55 53 48 89 F5 49 63 D8 4C } - $seq_encrypt_thread = { 4C 8B 74 24 ?? 31 DB 45 31 FF 4D 8B 6E ?? 49 83 FD ?? 0F 87 ?? ?? ?? ?? 31 C0 4D 39 EF 0F 82 ?? ?? ?? ?? 48 01 C3 4C 39 EB 0F 83 ?? ?? ?? ?? } + $a1 = { 61 00 63 00 75 00 74 00 65 00 00 00 61 00 63 00 74 00 69 00 6E 00 00 00 61 00 63 00 74 00 6F 00 6E 00 00 00 61 00 63 00 74 00 6F 00 72 00 00 00 61 00 63 00 75 00 66 00 66 00 00 } + $a2 = { 0C 6D 00 73 00 66 00 74 00 65 00 73 00 71 00 6C 00 2E 00 65 00 78 00 65 00 00 00 73 00 71 00 6C 00 61 00 67 00 65 00 6E 00 74 00 2E 00 65 00 78 00 65 00 00 00 73 00 71 00 6C 00 62 00 72 00 6F 00 77 00 73 00 65 00 72 00 2E 00 65 00 78 00 65 00 00 00 73 00 71 00 6C 00 73 00 65 00 72 00 76 00 72 00 2E 00 65 00 78 00 65 00 00 00 73 00 71 00 6C 00 77 00 72 00 69 00 74 00 65 00 72 00 2E 00 65 00 78 00 65 00 00 00 6F 00 72 00 61 00 63 00 6C 00 65 00 2E 00 65 00 78 00 } + $a3 = { 31 00 63 00 64 00 00 00 33 00 64 00 73 00 00 00 33 00 66 00 72 00 00 00 33 00 67 00 32 00 00 00 33 00 67 00 70 00 00 00 37 00 7A 00 00 00 61 00 63 00 63 00 64 00 61 00 00 00 61 00 63 00 63 00 64 00 62 00 00 00 61 00 63 00 63 00 64 00 63 00 00 00 61 00 63 00 63 00 64 00 65 00 00 00 61 00 63 00 63 00 64 00 74 00 00 00 61 00 63 00 63 00 64 00 77 00 00 00 61 00 64 00 62 00 00 00 61 00 64 00 70 00 00 00 61 00 69 00 00 00 61 00 69 00 33 00 00 00 61 00 69 00 34 00 00 00 61 00 69 00 35 00 00 00 61 00 69 00 36 00 00 00 61 00 69 00 37 00 00 00 61 00 69 00 38 00 00 00 61 00 6E 00 69 00 6D 00 00 00 61 00 72 00 77 00 00 00 61 00 73 00 00 00 61 00 73 00 61 00 00 00 61 00 73 00 63 00 00 00 61 00 73 00 63 00 78 00 00 00 61 00 73 00 6D 00 00 00 61 00 73 00 6D 00 78 00 00 00 61 00 73 00 70 00 00 00 61 00 73 00 70 00 78 00 00 00 61 00 73 00 72 00 00 00 61 00 73 00 78 00 00 00 61 00 76 00 69 00 00 00 61 00 76 00 73 00 00 00 62 00 61 00 63 00 6B 00 75 00 70 00 00 00 62 00 61 00 6B 00 00 00 62 00 61 00 79 00 00 00 62 00 64 00 00 00 62 00 69 00 6E 00 00 00 62 00 6D 00 70 00 00 00 } condition: - 3 of ($a*) and 1 of ($seq*) + 2 of ($a*) } -rule ELASTIC_Windows_Trojan_Remcos_B296E965 : FILE MEMORY +rule ELASTIC_Windows_Ransomware_Phobos_Ff55774D : BETA FILE MEMORY { meta: - description = "Detects Windows Trojan Remcos (Windows.Trojan.Remcos)" + description = "Identifies Phobos ransomware" author = "Elastic Security" - id = "b296e965-a99e-4446-b969-ba233a2a8af4" - date = "2021-06-10" + id = "ff55774d-4425-4243-8156-ce029c1d5860" + date = "2020-06-25" modified = "2021-08-23" - reference = "https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Remcos.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed" - logic_hash = "069072abd1182eee50cb9937503d47845e7315d8e3cd6b63576adc8f21820c82" + reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phobos" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Phobos.yar#L24-L43" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "9ee41b9638a8cc1d9f9b254878c935c531b2f599be59550b3617b1de8cba2ba5" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d" - severity = 100 + tags = "BETA, FILE, MEMORY" + fingerprint = "d8016c9be4a8e5b5ac32b7108542fee8426d65b4d37e2a9c5ad57284abb3781e" + threat_name = "Windows.Ransomware.Phobos" + severity = 90 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" os = "windows" strings: - $a1 = "Remcos restarted by watchdog!" ascii fullword - $a2 = "Mutex_RemWatchdog" ascii fullword - $a3 = "%02i:%02i:%02i:%03i" - $a4 = "* Remcos v" ascii fullword + $c1 = { 24 18 83 C4 0C 8B 4F 0C 03 C6 50 8D 54 24 18 52 51 6A 00 6A 00 89 44 } condition: - 2 of them + 1 of ($c*) } -rule ELASTIC_Windows_Trojan_Remcos_7591E9F1 : FILE MEMORY +rule ELASTIC_Windows_Ransomware_Phobos_11Ea7Be5 : BETA FILE MEMORY { meta: - description = "Detects Windows Trojan Remcos (Windows.Trojan.Remcos)" + description = "Identifies Phobos ransomware" author = "Elastic Security" - id = "7591e9f1-452d-4731-9bec-545fb0272c80" - date = "2023-06-23" - modified = "2023-07-10" - reference = "https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Remcos.yar#L25-L49" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "4e6e5ecd1cf9c88d536c894d74320c77967fe08c75066098082bf237283842fa" - logic_hash = "96acf1ba7740a8d34d929ed4a4fa446c984c3a8f64a603d428e782b6997e4d20" + id = "11ea7be5-7aac-41d7-8d09-45131a9c656e" + date = "2020-06-25" + modified = "2021-08-23" + reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phobos" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Phobos.yar#L45-L64" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "1f86695f316200c92d0d02f5f3ba9f68854978f98db5d4291a81c06c9f0b8d28" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "9436c314f89a09900a9b3c2fd9bab4a0423912427cf47b71edce5eba31132449" + tags = "BETA, FILE, MEMORY" + fingerprint = "a264f93e085134e5114c5d72e1bf93e70935e33756a79f1021e9c1e71d6c8697" + threat_name = "Windows.Ransomware.Phobos" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -57676,33 +61959,28 @@ rule ELASTIC_Windows_Trojan_Remcos_7591E9F1 : FILE MEMORY os = "windows" strings: - $a1 = "ServRem" ascii fullword - $a2 = "Screenshots" ascii fullword - $a3 = "MicRecords" ascii fullword - $a4 = "remcos.exe" wide nocase fullword - $a5 = "Remcos" wide fullword - $a6 = "logs.dat" wide fullword + $b1 = { C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89 } condition: - 3 of them + 1 of ($b*) } -rule ELASTIC_Windows_Ransomware_Ryuk_25D3C5Ba : BETA FILE MEMORY +rule ELASTIC_Windows_Hacktool_Rubeus_43F18623 : FILE MEMORY { meta: - description = "Identifies RYUK ransomware" + description = "Detects Windows Hacktool Rubeus (Windows.Hacktool.Rubeus)" author = "Elastic Security" - id = "25d3c5ba-8f80-4af0-8a5d-29c974fb016a" - date = "2020-04-30" - modified = "2021-08-23" - reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ryuk.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "4d461ff9b87e3a17637cef89ff8a85ef22f69695d4664f6fe8f271a6a5f7b4bc" + id = "43f18623-6024-4608-8019-e3fecd54cf84" + date = "2022-10-20" + modified = "2022-11-24" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_Rubeus.yar#L1-L27" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b7b4691ad1cdad7663c32d07e911a03d9cc8b104f724c2825fd4957007649235" + logic_hash = "8714f30e12c0dc61c83491a71dbf9f1e9b6bc66663a8f2c069e7a7841d52cf68" score = 75 - quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "18e70599e3a187e77697844fa358dd150e7e25ac74060e8c7cf2707fb7304efd" - threat_name = "Windows.Ransomware.Ryuk" + quality = 73 + tags = "FILE, MEMORY" + fingerprint = "fbc2f67f394a4d21cac532b42c6749002cb7284b4a3912e18672881e6e74765d" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -57710,259 +61988,239 @@ rule ELASTIC_Windows_Ransomware_Ryuk_25D3C5Ba : BETA FILE MEMORY os = "windows" strings: - $g1 = { 41 8B C0 45 03 C7 99 F7 FE 48 63 C2 8A 4C 84 20 } + $guid = "658C8B7F-3664-4A95-9572-A3E5871DFC06" ascii wide nocase + $print_str0 = "[*] Printing argument list for use with Rubeus" ascii wide + $print_str1 = "[+] Ticket successfully imported!" ascii wide + $print_str2 = "[+] Tickets successfully purged!" ascii wide + $print_str3 = "[*] Searching for accounts that support AES128_CTS_HMAC_SHA1_96/AES256_CTS_HMAC_SHA1_96" ascii wide + $print_str4 = "[*] Action: TGT Harvesting (with auto-renewal)" ascii wide + $print_str5 = "[X] Unable to retrieve TGT using tgtdeleg" ascii wide + $print_str6 = "[!] Unhandled Rubeus exception:" ascii wide + $print_str7 = "[*] Using a TGT /ticket to request service tickets" ascii wide condition: - 1 of ($g*) + $guid or 4 of ($print_str*) } -rule ELASTIC_Windows_Ransomware_Ryuk_878Bae7E : BETA FILE MEMORY +rule ELASTIC_Linux_Trojan_Dropperl_B97Baf37 : FILE MEMORY { meta: - description = "Identifies RYUK ransomware" + description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" author = "Elastic Security" - id = "878bae7e-1e53-4648-93aa-b4075eef256d" - date = "2020-04-30" - modified = "2021-08-23" - reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ryuk.yar#L22-L42" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "94bed2220aeb41ae8069cee56cc5299b9fc56797d3b54085b8246a03d9e8bd93" + id = "b97baf37-48db-4eb7-85c7-08e75054bea7" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Dropperl.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "aff94f915fc81d5a2649ebd7c21ec8a4c2fc0d622ec9b790b43cc49f7feb83da" + logic_hash = "e58130c33242bc3020602c2c0254bed2bbc564c4a11806c6cfcd858fd724c362" score = 75 quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "93a501463bb2320a9ab824d70333da2b6f635eb5958d6f8de43fde3a21de2298" - threat_name = "Windows.Ransomware.Ryuk" + tags = "FILE, MEMORY" + fingerprint = "0852f1afa6162d14b076a3fc1f56e4d365b5d0e8932bae6ab055000cca7d1fba" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $b2 = "RyukReadMe.html" wide fullword - $b3 = "RyukReadMe.txt" wide fullword + $a = { 12 48 89 10 83 45 DC 01 83 45 D8 01 8B 45 D8 3B 45 BC 7C CF 8B } condition: - 1 of ($b*) + all of them } -rule ELASTIC_Windows_Ransomware_Ryuk_6C726744 : BETA FILE MEMORY +rule ELASTIC_Linux_Trojan_Dropperl_E2443Be5 : FILE MEMORY { meta: - description = "Identifies RYUK ransomware" + description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" author = "Elastic Security" - id = "6c726744-acdb-443a-b683-b11f8b657f7a" - date = "2020-04-30" - modified = "2021-08-23" - reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ryuk.yar#L44-L67" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "ee7586d5cbef23d1863a4dfcc5da9b97397c993268881922c681022bf4f293f0" + id = "e2443be5-da15-4af2-b090-bf5accf2a844" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Dropperl.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "aff94f915fc81d5a2649ebd7c21ec8a4c2fc0d622ec9b790b43cc49f7feb83da" + logic_hash = "85733ff904cfa3eddaa4c4fbfc51c00494c3a3725e2eb722bbf33c82e7135336" score = 75 quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "d0a4608907e48d02d78ff40a59d47cad1b9258df31b7312dd1a85f8fee2a28d5" - threat_name = "Windows.Ransomware.Ryuk" + tags = "FILE, MEMORY" + fingerprint = "e49acaa476bd669b40ccc82a7d3a01e9c421e6709ecbfe8d0e24219677c96339" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = "172.16." ascii fullword - $a2 = "192.168." ascii fullword - $a3 = "DEL /F" wide fullword - $a4 = "lsaas.exe" wide fullword - $a5 = "delete[]" ascii fullword + $a = { 45 F0 75 DB EB 17 48 8B 45 F8 48 83 C0 08 48 8B 10 48 8B 45 F8 48 } condition: - 4 of ($a*) + all of them } -rule ELASTIC_Windows_Ransomware_Ryuk_1A4Ad952 : BETA FILE MEMORY +rule ELASTIC_Linux_Trojan_Dropperl_683C2Ba1 : FILE MEMORY { meta: - description = "Identifies RYUK ransomware" + description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" author = "Elastic Security" - id = "1a4ad952-cc99-4653-932b-290381e7c871" - date = "2020-04-30" - modified = "2021-08-23" - reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ryuk.yar#L69-L88" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "bb854f5760f41e2c103c99d8f128a2546926a614dff8753eaa1287ac583e213a" + id = "683c2ba1-fe4a-44e4-b176-8d5d5788e1a4" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Dropperl.yar#L41-L59" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "a02e166fbf002dd4217c012f24bb3a8dbe310a9f0b0635eb20a7d315049367e1" + logic_hash = "eef2bdef7e20633f7dc92f653b43e3a217e8cbdbac63d05540bdd520e22dd1ed" score = 75 quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "d8c5162850e758e27439e808e914df63f42756c0b8f7c2b5f9346c0731d3960c" - threat_name = "Windows.Ransomware.Ryuk" + tags = "FILE, MEMORY" + fingerprint = "42dcea472417140d0f7768e8189ac3a8a46aaeff039be1efd36f8d50f81e347c" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $e1 = { 8B 0A 41 8D 45 01 45 03 C1 48 8D 52 08 41 3B C9 41 0F 45 C5 44 8B E8 49 63 C0 48 3B C3 72 E1 } + $a = { E8 95 FB FF FF 83 7D D4 00 79 0A B8 ?? ?? 60 00 } condition: - 1 of ($e*) + all of them } -rule ELASTIC_Windows_Ransomware_Ryuk_72B5Fd9D : BETA FILE MEMORY +rule ELASTIC_Linux_Trojan_Dropperl_8Bca73F6 : FILE MEMORY { meta: - description = "Identifies RYUK ransomware" + description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" author = "Elastic Security" - id = "72b5fd9d-23db-4f18-88d9-a849ec039135" - date = "2020-04-30" - modified = "2021-08-23" - reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ryuk.yar#L90-L109" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "b2abc8f70df5d730ce6a7d0bc125bb623f27b292e7d575914368a8bfc0fb5837" + id = "8bca73f6-c3ec-45a3-a5ae-67c871aaf9df" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Dropperl.yar#L61-L79" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "e7c17b7916b38494b9a07c249acb99499808959ba67125c29afec194ca4ae36c" + logic_hash = "2cfad4e436198391185fdae5c4af18ae43841db19da33473fdf18b64b0399613" score = 75 quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "7c394aa283336013b74a8aaeb56e8363033958b4a1bd8011f3b32cfe2d37e088" - threat_name = "Windows.Ransomware.Ryuk" + tags = "FILE, MEMORY" + fingerprint = "36df2fd9746da80697ef675f84f47efb3cb90e9757677e4f565a7576966eb169" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $d1 = { 48 2B C3 33 DB 66 89 1C 46 48 83 FF FF 0F } + $a = { E8 95 FB FF FF 83 7D D4 00 79 0A B8 ?? ?? 62 00 } condition: - 1 of ($d*) + all of them } -rule ELASTIC_Windows_Ransomware_Ryuk_8Ba51798 : BETA FILE MEMORY +rule ELASTIC_Linux_Trojan_Dropperl_C4018572 : FILE MEMORY { meta: - description = "Identifies RYUK ransomware" + description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" author = "Elastic Security" - id = "8ba51798-15d7-4f02-97fa-1844465ae9d8" - date = "2020-04-30" - modified = "2021-08-23" - reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ryuk.yar#L111-L137" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "0733ae6a7e38bc2a25aa76a816284482d3ee25626559ec5af554b5f5070e534a" + id = "c4018572-a8af-4204-bc19-284a2a27dfdd" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Dropperl.yar#L81-L99" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c1515b3a7a91650948af7577b613ee019166f116729b7ff6309b218047141f6d" + logic_hash = "10d70540532c5c2984dc7e492672450924cb8f34c8158638191886057596b0a1" score = 75 quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "8e284bc6015502577a6ddd140b9cd110fd44d4d2cb55d0fdec5bebf3356fd7b3" - threat_name = "Windows.Ransomware.Ryuk" + tags = "FILE, MEMORY" + fingerprint = "f2ede50ea639af593211c9ef03ee2847a32cf3eb155db4e2ca302f3508bf2a45" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $c1 = "/v \"svchos\" /f" wide fullword - $c2 = "cmd /c \"WMIC.exe shadowcopy delet\"" ascii fullword - $c3 = "lsaas.exe" wide fullword - $c4 = "FA_Scheduler" wide fullword - $c5 = "ocautoupds" wide fullword - $c6 = "CNTAoSMgr" wide fullword - $c7 = "hrmlog" wide fullword - $c8 = "UNIQUE_ID_DO_NOT_REMOVE" wide fullword + $a = { E8 97 FB FF FF 83 7D D4 00 79 0A B8 ?? ?? 60 00 } condition: - 3 of ($c*) + all of them } -rule ELASTIC_Windows_Ransomware_Ryuk_88Daaf8E : BETA FILE MEMORY +rule ELASTIC_Linux_Trojan_Dropperl_733C0330 : FILE MEMORY { meta: - description = "Identifies RYUK ransomware" + description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" author = "Elastic Security" - id = "88daaf8e-0bfe-46c4-9a75-2527d0e10538" - date = "2020-04-30" - modified = "2021-08-23" - reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ryuk.yar#L139-L158" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "6fc463976c0fb9c3e4f25d854545d07800c63730826f3974298f0077d272cff0" + id = "733c0330-3163-48f3-a780-49be80a3387f" + date = "2021-04-06" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Dropperl.yar#L101-L119" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b303f241a2687dba8d7b4987b7a46b5569bd2272e2da3e0c5e597b342d4561b6" + logic_hash = "37bf7777e26e556f09b8cb0e7e3c8425226a6412c3bed0d95fdab7229b6f4815" score = 75 quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "b1f218a9bc6bf5f3ec108a471de954988e7692de208e68d7d4ee205194cbbb40" - threat_name = "Windows.Ransomware.Ryuk" + tags = "FILE, MEMORY" + fingerprint = "ee233c875dd3879b4973953a1f2074cd77abf86382019eeb72da069e1fd03e1c" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $f1 = { 48 8B CF E8 AB 25 00 00 85 C0 74 35 } + $a = { E8 A0 FB FF FF 83 7D DC 00 79 0A B8 ?? ?? 60 00 } condition: - 1 of ($f*) + all of them } -rule ELASTIC_Windows_Trojan_Havoc_77F3D40E : FILE MEMORY +rule ELASTIC_Linux_Trojan_Dropperl_39F4Cd0D : FILE MEMORY { meta: - description = "Detects Windows Trojan Havoc (Windows.Trojan.Havoc)" + description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" author = "Elastic Security" - id = "77f3d40e-9365-4e76-a1a3-36d128e775a9" - date = "2022-10-20" - modified = "2022-11-24" + id = "39f4cd0d-4261-4d62-a527-f403edadbd0c" + date = "2021-04-06" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Havoc.yar#L1-L35" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "3427dac129b760a03f2c40590c01065c9bf2340d2dfa4a4a7cf4830a02e95879" - logic_hash = "3d2733ed24d90e9e851ec36a08c497e9c90b47c3dcbb8755e3f6b6a6bd3a8b54" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Dropperl.yar#L121-L139" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c08e1347877dc77ad73c1e017f928c69c8c78a0e3c16ac5455668d2ad22500f3" + logic_hash = "5b61f54604b110d2c8efaf1782a2e520baac96c6d3e8d1eda0877475c504bf89" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "95d35d167df7f77f23b1afb1b7655cc47830c9986c54791b562c33db8f2773ae" + fingerprint = "e1cdd678a1f46a3c6d26d53dd96ba6c6a45f97e743765c534f644af7c6450f8e" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $core = { 48 ?? ?? 2C 06 00 00 00 ?? ?? 48 ?? ?? 5C 06 00 00 00 ?? ?? ?? ?? ?? ?? 48 8B ?? 5C 06 00 00 ?? F6 99 5A 2E E8 ?? ?? ?? ?? 48 8B ?? 48 ?? ?? 4C 02 00 00 48 8B ?? 5C 06 00 00 ?? 23 DB 07 03 E8 ?? ?? ?? ?? 48 8B ?? 48 ?? ?? 44 02 00 00 48 8B ?? 5C 06 00 00 ?? DA 81 B3 C0 E8 ?? ?? ?? ?? 48 8B ?? 48 ?? ?? 54 02 00 00 48 8B ?? 5C 06 00 00 ?? D7 71 BA 70 E8 ?? ?? ?? ?? 48 8B ?? 48 ?? ?? 64 02 00 00 48 8B ?? 5C 06 00 00 ?? 88 2B 49 8E E8 ?? ?? ?? ?? 48 8B ?? 48 ?? ?? 84 02 00 00 48 8B ?? 5C 06 00 00 ?? EF F0 A1 3A E8 ?? ?? ?? ?? } - $commands_table = { 0B 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 64 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 15 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 10 10 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 0C 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? [0-12] 0F 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 14 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 01 20 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 03 20 00 00 ?? ?? ?? ?? ?? ?? ?? ?? C4 09 00 00 ?? ?? ?? ?? ?? ?? ?? ?? CE 09 00 00 ?? ?? ?? ?? ?? ?? ?? ?? D8 09 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 34 08 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 16 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 18 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 1A 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 28 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 5C 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? } - $hashes_0 = { F6 99 5A 2E } - $hashes_1 = { DA 81 B3 C0 } - $hashes_2 = { D7 71 BA 70 } - $hashes_3 = { 88 2B 49 8E } - $hashes_4 = { EF F0 A1 3A } - $hashes_5 = { F5 39 34 7C } - $hashes_6 = { 2A 92 12 D8 } - $hashes_7 = { 8D F1 4F 84 } - $hashes_8 = { 5B BC CE 73 } - $hashes_9 = { 59 24 93 B8 } - $hashes_10 = { 02 9E D0 C2 } - $hashes_11 = { E5 36 26 AE } - $hashes_12 = { 5C 3C B4 F3 } - $hashes_13 = { 2F 87 D8 1C } - $hashes_14 = { D7 53 22 AC } + $a = { E8 ?? FA FF FF 83 7D D4 00 79 0A B8 ?? ?? 60 00 } condition: - $core or ($commands_table and all of ($hashes*)) + all of them } -rule ELASTIC_Windows_Trojan_Havoc_9C7Bb863 : FILE MEMORY +rule ELASTIC_Windows_Hacktool_Sharprdp_80895Fcb : FILE MEMORY { meta: - description = "Detects Windows Trojan Havoc (Windows.Trojan.Havoc)" + description = "Detects Windows Hacktool Sharprdp (Windows.Hacktool.SharpRDP)" author = "Elastic Security" - id = "9c7bb863-b6c2-4d5f-ae50-0fd900f1d4eb" - date = "2023-04-28" - modified = "2023-06-13" + id = "80895fcb-b98e-4865-a1f6-87cbea327cea" + date = "2022-11-20" + modified = "2023-01-11" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Havoc.yar#L37-L56" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "261b92d9e8dcb9d0abf1627b791831ec89779f2b7973b1926c6ec9691288dd57" - logic_hash = "c1245c38c54b0a72fb335680d9ea191390e4e2fe7e47a3ed776878c5e01a3e16" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_SharpRDP.yar#L1-L23" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "6e909861781a8812ee01bc59435fd73fd34da23fa9ad6d699eefbf9f84629876" + logic_hash = "ef9a92f2ed29f508dca591e9c65a6ce0013ccdfd0c62770e8840be2f3ee5982e" score = 75 - quality = 75 + quality = 73 tags = "FILE, MEMORY" - fingerprint = "cda55a9e65badb984e71778b081929db2bdef223792b78bba32b2259757f1348" + fingerprint = "a7eb084004fce79efc39781044bad501a731163fa3ad6f9b8b334611d03f5379" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -57970,58 +62228,60 @@ rule ELASTIC_Windows_Trojan_Havoc_9C7Bb863 : FILE MEMORY os = "windows" strings: - $a1 = { 56 48 89 E6 48 83 E4 F0 48 83 EC 20 E8 0F 00 00 00 48 89 F4 5E C3 } - $a2 = { 65 48 8B 04 25 60 00 00 00 } + $guid = "F1DF1D0F-FF86-4106-97A8-F95AAF525C54" ascii wide nocase + $print_str0 = "[+] Another user is logged on, asking to take over session" ascii wide fullword + $print_str1 = "[+] Execution priv type : {0}" ascii wide fullword + $print_str2 = "[+] Sleeping for 30 seconds" ascii wide fullword + $print_str3 = "[X] Error: A password is required" ascii wide fullword condition: - all of them + $guid or all of ($print_str*) } -rule ELASTIC_Windows_Trojan_Havoc_88053562 : FILE MEMORY +rule ELASTIC_Windows_Vulndriver_Gvci_F5A35359 : FILE { meta: - description = "Detects Windows Trojan Havoc (Windows.Trojan.Havoc)" + description = "Detects Windows Vulndriver Gvci (Windows.VulnDriver.Gvci)" author = "Elastic Security" - id = "88053562-ae19-44fe-8aaf-d6b9687d6b80" - date = "2024-01-04" - modified = "2024-01-12" + id = "f5a35359-ee16-444a-aafd-c4ef162e46d4" + date = "2022-04-04" + modified = "2022-04-04" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Havoc.yar#L58-L76" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "2f0b59f8220edd0d34fba92905faf0b51aead95d53be8b5f022eed7e21bdb4af" - logic_hash = "f79b39cc2ca4bbf6ad4b6585a9914a75797110d6fb68bcb7141c5c3d0429c412" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Gvci.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "42f0b036687cbd7717c9efed6991c00d4e3e7b032dc965a2556c02177dfdad0f" + logic_hash = "beb0c324358a016e708dae30a222373113a7eab8e3d90dfa1bbde6c2f7874362" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "818011b7972ab71cbfe07ec2266f504ba0ec7df30136e414d15366aa68ad5b8a" - severity = 100 + tags = "FILE" + fingerprint = "590e6b10c8bd1c299eb4ecd1368ac05d8811147c7ce3976de5e86d1a6d8bc14f" + severity = 50 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" os = "windows" strings: - $a = { 48 81 EC F8 04 00 00 48 8D 7C 24 78 44 89 8C 24 58 05 00 00 48 8B AC 24 60 05 00 00 4C 8D 6C 24 78 F3 AB B9 59 00 00 00 48 C7 44 24 70 00 00 00 00 C7 44 24 78 68 00 00 00 C7 84 24 B4 00 00 00 } + $str1 = "\\GVCIDrv64.pdb" condition: - all of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1 } -rule ELASTIC_Windows_Trojan_Havoc_Ffecc8Af : FILE MEMORY +rule ELASTIC_Windows_Trojan_P8Loader_E478A831 : FILE MEMORY { meta: - description = "Detects Windows Trojan Havoc (Windows.Trojan.Havoc)" + description = "Detects Windows Trojan P8Loader (Windows.Trojan.P8Loader)" author = "Elastic Security" - id = "ffecc8af-4a64-4252-b7ca-3316d27c3942" - date = "2024-04-29" - modified = "2024-05-08" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Havoc.yar#L78-L107" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "495d323651c252e38814b77b9c6c913b9489e769252ac8bbaf8432f15e0efe44" - logic_hash = "c9da6215db1de91a6cd52dd6558dc5a60bbd69abc6fa0db8714f001cdae20ddb" + id = "e478a831-b2a1-4436-8b17-ca92b9581c39" + date = "2023-04-13" + modified = "2023-05-26" + reference = "https://www.elastic.co/security-labs/elastic-charms-spectralviper" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_P8Loader.yar#L1-L26" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "f1a7de6bb4477ea82c18aea1ddc4481de2fc362ce5321f4205bb3b74c1c45a7e" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "d09b0519d518b741cec7f6e42efaa657410edd36d027f54e515be510b33fa821" + fingerprint = "267743fc82c701d3029cde789eb471b49839001b21b90eeb20783382a56fb2c3" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58029,68 +62289,63 @@ rule ELASTIC_Windows_Trojan_Havoc_Ffecc8Af : FILE MEMORY os = "windows" strings: - $commands_table = { 0B 00 00 00 00 00 00 00 [8] 64 00 00 00 00 00 00 00 [8] 15 00 00 00 00 00 00 00 [8] 10 10 00 00 00 00 00 00 [8] 0C 00 00 00 00 00 00 00 [8] 0F 00 00 00 00 00 00 00 [8] 14 00 00 00 00 00 00 00 [8] 01 20 00 00 00 00 00 00 [8] 03 20 00 00 00 00 00 00 [8] C4 09 00 00 00 00 00 00 [8] CE 09 00 00 00 00 00 00 [8] D8 09 00 00 00 00 00 00 [8] 34 08 00 00 00 00 00 00 [8] 16 00 00 00 00 00 00 00 [8] 18 00 00 00 00 00 00 00 [8] 1A 00 00 00 00 00 00 00 [8] 28 00 00 00 00 00 00 00 [8] E2 09 00 00 00 00 00 00 [8] EC 09 00 00 00 00 00 00 [8] F6 09 00 00 00 00 00 00 [8] 00 0A 00 00 00 00 00 00 [8] 5C 00 00 00 00 00 00 00 } - $hash_ldrloaddll = { 43 6A 45 9E } - $hash_ldrgetprocedureaddress = { B6 6B CE FC } - $hash_ntaddbootentry = { 76 C7 FC 8C } - $hash_ntallocatevirtualmemory = { EC B8 83 F7 } - $hash_ntfreevirtualmemory = { 09 C6 02 28 } - $hash_ntunmapviewofsection = { CD 12 A4 6A } - $hash_ntwritevirtualmemory = { 92 01 17 C3 } - $hash_ntsetinformationvirtualmemory = { 39 C2 6A 94 } - $hash_ntqueryvirtualmemory = { 5D E8 C0 10 } - $hash_ntopenprocesstoken = { 99 CA 0D 35 } - $hash_ntopenthreadtoken = { D2 47 33 80 } + $a1 = "\t[+] Create pipe direct std success\n" fullword + $a2 = "\tPEAddress: %p\n" fullword + $a3 = "\tPESize: %ld\n" fullword + $a4 = "DynamicLoad(%s, %s) %d\n" fullword + $a5 = "LoadLibraryA(%s) FAILED in %s function, line %d" fullword + $a6 = "\t[+] No PE loaded on memory\n" wide fullword + $a7 = "\t[+] PE argument: %ws\n" wide fullword + $a8 = "LoadLibraryA(%s) FAILED in %s function, line %d" fullword condition: - $commands_table and 4 of ($hash_*) + 5 of them } -rule ELASTIC_Windows_Trojan_Arkeistealer_84C7086A : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_83715433 : FILE MEMORY { meta: - description = "Detects Windows Trojan Arkeistealer (Windows.Trojan.ArkeiStealer)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "84c7086a-abc3-4b97-b325-46a078b90a95" - date = "2022-02-17" - modified = "2022-04-12" + id = "83715433-3dff-4238-8cdb-c51279565e05" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_ArkeiStealer.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "708d9fb40f49192d4bf6eff62e0140c920a7eca01b9f78aeaf558bef0115dbe2" - logic_hash = "b7129094389f789f0b43f0da54645c24a6d1149f53d6536c14714e3ff44f935b" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "3648a407224634d76e82eceec84250a7506720a7f43a6ccf5873f478408fedba" + logic_hash = "7a7328322c2c1e128e267e92de0964e78ad9f49b7de8ec69d7f0632c69723a7d" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "f1d701463b0001de8996b30d2e36ddecb93fe4ca2a1a26fc4fcdaeb0aa3a3d6d" + fingerprint = "25ac15f4b903d9e28653dad0db399ebd20d4e9baabf5078fbc33d3cd838dd7e9" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a = { 01 89 55 F4 8B 45 F4 3B 45 10 73 31 8B 4D 08 03 4D F4 0F BE 19 8B } + $a = { 8B 45 08 88 10 FF 45 08 8B 45 08 0F B6 00 84 C0 75 DB C9 C3 55 } condition: all of them } -rule ELASTIC_Linux_Virus_Thebe_1Eb5985A : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_28A2Fe0C : FILE MEMORY { meta: - description = "Detects Linux Virus Thebe (Linux.Virus.Thebe)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "1eb5985a-2b35-434f-81d9-f502dff25397" - date = "2021-04-06" + id = "28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd" + date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Virus_Thebe.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "30af289be070f4e0f8761f04fb44193a037ec1aab9cc029343a1a1f2a8d67670" - logic_hash = "7d4bc4b1615048dec1f1fac599afa667e06ccb369bb1242b25887e0ce2a5066a" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L21-L38" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "04bbc6c40cdd71b4185222a822d18b96ec8427006221f213a1c9e4d9c689ce5c" score = 75 - quality = 75 + quality = 73 tags = "FILE, MEMORY" - fingerprint = "5cf9aa9a31c36028025d5038c98d56aef32c9e8952aa5cd4152fbd811231769e" + fingerprint = "a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58098,61 +62353,57 @@ rule ELASTIC_Linux_Virus_Thebe_1Eb5985A : FILE MEMORY os = "linux" strings: - $a = { 42 31 C9 31 DB 31 F6 B0 1A CD 80 85 C0 0F 85 83 } + $a = { 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F } condition: all of them } -rule ELASTIC_Linux_Trojan_Mettle_E8Fdbcbd : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_Eb96Cc26 : FILE MEMORY { meta: - description = "Detects Linux Trojan Mettle (Linux.Trojan.Mettle)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "e8fdbcbd-84d3-4c42-986b-c8d5d940a96a" - date = "2024-05-06" - modified = "2024-05-21" + id = "eb96cc26-e6d6-4388-a5da-2501e6e2ea32" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Mettle.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "864eae4f27648b8a9d9b0eb1894169aa739311cdd02b1435a34881acf7059d58" - logic_hash = "d13c1e7fb815ebbefa78922e9b85a1ced015c03b8f1b2cf1885a9c483b8e0ab3" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L40-L58" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "440318179ba2419cfa34ea199b49ee6bdecd076883d26329bbca6dca9d39c500" + logic_hash = "3d8740a6cca4856a73ea745877a3eb39cbf3ad4ca612daabd197f551116efa04" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "2038686308a77286ed5d13b408962075933da7ca5772d46b65e5f247193036b5" + fingerprint = "73967a3499d5dce61735aa2d352c1db48bb1d965b2934bb924209d729b5eb162" severity = 100 - arch_context = "x86, arm64" + arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" os = "linux" strings: - $mettle1 = "mettlesploit!" - $mettle2 = "/mettle/mettle/src/" - $mettle3 = "mettle_get_c2" - $mettle4 = "mettle_console_start_interactive" - $mettle5 = "mettle_get_machine_id" + $a = { 49 6E 66 6F 3A 20 0A 00 5E 6A 02 5F 6A 01 58 0F 05 6A 7F 5F } condition: - 2 of ($mettle*) + all of them } -rule ELASTIC_Linux_Trojan_Mettle_813B9B6C : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_5008Aee6 : FILE MEMORY { meta: - description = "Detects Linux Trojan Mettle (Linux.Trojan.Mettle)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "813b9b6c-946d-46f0-a255-d06ab78347d4" - date = "2024-05-06" - modified = "2024-05-21" + id = "5008aee6-3866-4f0a-89bf-bde740baee5c" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Mettle.yar#L25-L52" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "bb651d974ca3f349858db7b5a86f03a8d47d668294f27e709a823fa11e6963d7" - logic_hash = "a6a9cf424bf1ca7985e1c4b14123ed236208ffa3f7c9ffebbdd85765a90bfa54" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L60-L78" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b32cd71fcfda0a2fcddad49d8c5ba8d4d68867b2ff2cb3b49d1a0e358346620c" + logic_hash = "538bae17dcf0298e379f656e1dba794b75af6c7448a23253a51994bde9d30524" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "6b350abfda820ee4c6e7aa84f732ab4527c454b93ae13363747f024bb8c5e3b4" + fingerprint = "6876a6c1333993c4349e459d4d13c11be1b0f78311274c0f778e65d0fabeeaa7" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58160,37 +62411,28 @@ rule ELASTIC_Linux_Trojan_Mettle_813B9B6C : FILE MEMORY os = "linux" strings: - $process_set_nonblocking_stdio = { 55 89 E5 53 83 EC 08 E8 ?? ?? ?? ?? 81 C3 3D 32 0D 00 6A 00 6A 03 6A 00 E8 ?? ?? ?? ?? 83 C4 0C 80 CC 08 50 6A 04 6A 00 E8 ?? ?? ?? ?? 83 C4 0C 6A 00 6A 03 6A 01 E8 ?? ?? ?? ?? 83 C4 0C 80 CC 08 50 6A 04 6A 01 E8 } - $process_create = { 55 89 E5 57 56 53 81 EC 98 00 00 00 E8 ?? ?? ?? ?? 81 C3 A6 3B 0D 00 89 45 84 89 95 78 FF FF FF 89 4D 80 8B 7D 0C 8D 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 10 40 0F ?? ?? ?? ?? ?? 50 50 68 B4 00 00 00 6A 01 E8 ?? ?? ?? ?? 89 C6 83 C4 10 85 C0 0F ?? ?? ?? ?? ?? F6 47 14 80 74 ?? 6A 00 6A 00 6A 00 8D 45 ?? 50 E8 ?? ?? ?? ?? 89 85 7C FF FF FF } - $process_read = { 55 89 E5 57 56 53 83 EC 1C E8 ?? ?? ?? ?? 81 C3 90 30 0D 00 8B 4D 08 8B 7D 0C 8B 75 10 83 C8 FF 85 C9 74 ?? 52 56 57 FF 71 24 89 4D E4 E8 ?? ?? ?? ?? 89 C2 83 C4 10 39 C6 8B 4D E4 76 ?? 50 29 D6 56 01 D7 89 55 E4 57 FF 71 48 E8 ?? ?? ?? ?? 8B 55 E4 01 C2 83 C4 10 89 D0 8D 65 ?? 5B 5E 5F 5D C3 } - $file_new = { 83 C4 10 52 52 50 FF 76 0C E8 ?? ?? ?? ?? 89 34 24 E8 ?? ?? ?? ?? 83 C4 10 8D 65 ?? 5B 5E 5F 5D C3 } - $file_read = { 55 89 E5 53 83 EC 10 E8 ?? ?? ?? ?? 81 C3 41 A7 0D 00 FF 75 08 E8 ?? ?? ?? ?? 50 FF 75 10 6A 01 FF 75 0C E8 ?? ?? ?? ?? 8B 5D FC C9 C3 } - $file_seek = { 55 89 E5 53 83 EC 10 E8 ?? ?? ?? ?? 81 C3 C0 A6 0D 00 FF 75 08 E8 ?? ?? ?? ?? 83 C4 0C FF 75 10 FF 75 0C 50 E8 ?? ?? ?? ?? 8B 5D FC C9 C3 } - $func_write_audio_file = { 55 89 E5 57 56 53 83 EC 18 E8 ?? ?? ?? ?? 81 C3 D8 23 0D 00 FF 75 08 E8 ?? ?? ?? ?? 89 C6 8B 45 10 03 06 89 06 5A 59 50 FF 76 04 E8 ?? ?? ?? ?? 89 C7 89 46 04 83 C4 10 83 C8 FF 85 FF 74 ?? 2B 7D 10 8B 06 01 F8 89 C7 8B 75 0C 8B 4D 10 F3 ?? 8B 45 10 8D 65 ?? 5B 5E 5F 5D C3 } - $func_is_compatible_elf = { 55 89 E5 56 53 E8 ?? ?? ?? ?? 81 C3 CF AB 05 00 8B 55 08 31 C0 81 3A 7F 45 4C 46 75 ?? 80 7A 04 01 75 ?? 0F B6 72 05 83 EC 0C 6A 01 E8 ?? ?? ?? ?? 83 C4 10 48 0F 94 C0 0F B6 C0 40 39 C6 0F 94 C0 0F B6 C0 83 E0 01 8D 65 ?? 5B 5E 5D C3 } - $func_stack_setup = { 89 DA 31 C0 8B 0C 86 85 C9 8D 40 ?? 74 ?? 89 0A 83 C2 04 EB ?? C7 02 00 00 00 00 C7 04 83 00 00 00 00 EB ?? 83 EC 0C 53 E8 ?? ?? ?? ?? 83 C4 10 8B 45 DC 89 45 10 8B 45 E0 89 45 0C 89 5D 08 8D 65 ?? 5B 5E 5F 5D } - $func_c2_new_struct = { C7 46 14 00 00 00 00 C7 46 10 00 00 00 00 C7 46 18 00 00 00 00 8D 83 ?? ?? ?? ?? 89 46 20 C7 46 24 00 00 00 00 C7 46 28 00 00 00 00 C7 46 2C 00 00 00 00 C7 46 30 00 00 F0 3F 89 76 1C 83 EC 0C 56 E8 } + $a = { 50 16 B4 87 58 83 00 21 84 51 FD 13 4E 79 28 57 C3 8B 30 55 } condition: - 2 of ($process*) and 2 of ($file*) and 2 of ($func*) + all of them } -rule ELASTIC_Linux_Trojan_Mettle_78Aead1C : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_6321B565 : FILE MEMORY { meta: - description = "Detects Linux Trojan Mettle (Linux.Trojan.Mettle)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "78aead1c-7dc2-4db0-a0b8-cccf2d583c67" - date = "2024-05-06" - modified = "2024-05-21" + id = "6321b565-ed25-4bf2-be4f-3ffa0e643085" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Mettle.yar#L54-L81" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "864eae4f27648b8a9d9b0eb1894169aa739311cdd02b1435a34881acf7059d58" - logic_hash = "d68d37379b8a3a2d242030fd14884781488e9785823aa25fedfdd406748f8039" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L80-L98" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "cd48addd392e7912ab15a5464c710055f696990fab564f29f13121e7a5e93730" + logic_hash = "ad5c73ab68059101acf2fd8cfb3d676fd1ff58811e1c4b9008c291361ee951b8" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "bf2b8bd0e12905ab4bed94c70dbd854a482446909ba255fceaee309efd69b835" + fingerprint = "c1d286e82426cbf19fc52836ef9a6b88c1f6e144967f43760df93cf1ab497d07" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58198,72 +62440,57 @@ rule ELASTIC_Linux_Trojan_Mettle_78Aead1C : FILE MEMORY os = "linux" strings: - $process_set_nonblocking_stdio = { 48 83 EC 08 31 D2 BE 03 00 00 00 31 FF 31 C0 E8 ?? ?? ?? ?? 80 CC 08 BE 04 00 00 00 31 FF 89 C2 31 C0 E8 ?? ?? ?? ?? 31 D2 BE 03 00 00 00 BF 01 00 00 00 31 C0 E8 ?? ?? ?? ?? 80 CC 08 BE 04 00 00 00 BF 01 00 00 00 89 C2 31 C0 E8 } - $process_create = { 41 57 41 56 49 89 CE 41 55 41 54 4D 89 C5 55 53 48 89 FB 48 89 D5 48 81 EC 88 00 00 00 48 8D ?? ?? ?? 48 89 34 24 E8 ?? ?? ?? ?? FF C0 0F ?? ?? ?? ?? ?? BE 20 01 00 00 BF 01 00 00 00 E8 ?? ?? ?? ?? 48 85 C0 49 89 C7 0F ?? ?? ?? ?? ?? 41 F6 45 28 80 74 ?? 48 8D ?? ?? ?? 31 C9 31 D2 31 F6 E8 ?? ?? ?? ?? 85 C0 } - $process_read = { 48 85 FF 74 ?? 41 55 41 54 49 89 FD 55 53 48 89 D5 49 89 F4 48 83 EC 08 48 8B 7F 38 E8 ?? ?? ?? ?? 48 39 C5 48 89 C3 76 ?? 49 8B 7D 70 48 89 EA 49 8D ?? ?? 48 29 C2 E8 ?? ?? ?? ?? 48 01 C3 5A 48 89 D8 5B 5D 41 5C 41 5D C3 } - $file_new = { 41 54 55 48 89 F5 53 48 89 FB 48 8B 7F 10 BE B2 04 01 00 E8 ?? ?? ?? ?? 48 8B 7B 10 BE B3 04 01 00 49 89 C4 E8 ?? ?? ?? ?? 48 85 C0 75 ?? 48 8D ?? ?? ?? ?? ?? 48 89 C6 4C 89 E7 E8 ?? ?? ?? ?? 83 CA FF 48 85 C0 74 ?? 48 89 C6 48 89 EF E8 ?? ?? ?? ?? 31 D2 5B 89 D0 5D 41 5C C3 } - $file_read = { 53 48 89 F3 48 83 EC 10 48 89 54 24 08 E8 ?? ?? ?? ?? 48 8B 54 24 08 48 83 C4 10 48 89 DF 5B 48 89 C1 BE 01 00 00 00 E9 } - $file_seek = { 48 83 EC 18 48 89 74 24 08 89 54 24 04 E8 ?? ?? ?? ?? 8B 54 24 04 48 8B 74 24 08 48 89 C7 48 83 C4 18 E9 } - $func_write_audio_file = { 41 54 55 49 89 F4 53 48 89 D3 E8 ?? ?? ?? ?? 48 8B 30 48 8B 78 08 48 89 C5 48 01 DE 48 89 30 E8 ?? ?? ?? ?? 48 89 C7 48 89 45 08 48 83 C8 FF 48 85 FF 74 ?? 48 8B 45 00 48 29 DF 4C 89 E6 48 89 D9 48 01 F8 48 89 C7 48 89 D8 F3 ?? 5B 5D 41 5C C3 } - $func_is_compatible_elf = { 31 C0 81 3F 7F 45 4C 46 75 ?? 80 7F 04 02 75 ?? 53 0F B6 5F 05 BF 01 00 00 00 E8 ?? ?? ?? ?? FF C8 0F 94 C0 0F B6 C0 FF C0 39 C3 0F 94 C0 0F B6 C0 83 E0 01 5B C3 83 E0 01 C3 } - $func_stack_setup = { 48 89 EA 31 C0 49 8B 0C C0 48 FF C0 48 85 C9 74 ?? 48 89 0A 48 83 C2 08 EB ?? 48 C7 02 00 00 00 00 48 C7 44 C5 00 00 00 00 00 EB ?? 48 89 EF 4C 89 4C 24 08 E8 ?? ?? ?? ?? 4C 8B 4C 24 08 48 83 C4 10 48 89 DA 48 89 EF 5B 5D 41 5C 4C 89 CE } - $func_c2_new_struct = { 48 89 DF 48 C7 43 20 00 00 00 00 C7 43 28 00 00 00 00 48 C7 43 40 00 00 00 00 48 89 43 38 48 8B 05 D1 BE 09 00 48 89 5B 30 48 89 43 48 E8 } + $a = { D8 89 D0 01 C0 01 D0 C1 E0 03 8B 04 08 83 E0 1F 0F AB 84 9D 58 FF } condition: - 2 of ($process*) and 2 of ($file*) and 2 of ($func*) + all of them } -rule ELASTIC_Windows_Ransomware_Blackhunt_7B46Cb9C : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_A6A2Adb9 : FILE MEMORY { meta: - description = "Detects Windows Ransomware Blackhunt (Windows.Ransomware.BlackHunt)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "7b46cb9c-4601-4be0-a2de-6a4f27d1a446" - date = "2024-03-12" - modified = "2024-03-21" + id = "a6a2adb9-9d54-42d4-abed-5b30d8062e97" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_BlackHunt.yar#L1-L25" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "6c4e968c9b53906ba0e86a41eccdabe2b736238cb126852023e15850e956293d" - logic_hash = "97bb8436574fd814d8278e5a7043e011d0e4f9a7dd9df5e67605f28ac1af1e74" - score = 50 + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L100-L118" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df" + logic_hash = "8f5fc4cb1ad51178701509a44a793e119fe7e7fad97eafcac8be14fce64e3b7b" + score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "1e46e2de840bfd557147e686eb00c350d00f6d1c6b2b8d1df98165c73cbe89ba" + fingerprint = "cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = "#BlackHunt_ReadMe.txt" wide fullword - $a2 = "#BlackHunt_Private.key" wide fullword - $a3 = "#BlackHunt_ID.txt" wide fullword - $a4 = "BLACK_HUNT_MUTEX" ascii fullword - $a5 = "BlackKeys" ascii fullword - $a6 = "ENCRYPTED VOLUME : %dGB" ascii fullword - $a7 = "RUNNING TIME : %02dm:%02ds" ascii fullword + $a = { CC 01 C2 89 55 B4 8B 45 B4 C9 C3 55 48 89 E5 48 81 EC 90 00 } condition: - 4 of them + all of them } -rule ELASTIC_Linux_Trojan_Banload_D5E1C189 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_C573932B : FILE MEMORY { meta: - description = "Detects Linux Trojan Banload (Linux.Trojan.Banload)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "d5e1c189-7d19-4f03-a4f3-a0aaf6d499dc" + id = "c573932b-9b3f-4ab7-a6b6-32dcc7473790" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Banload.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "48bf0403f777db5da9c6a7eada17ad4ddf471bd73ea6cf02817dd202b49204f4" - logic_hash = "3f0bee251152a8c835a3bf71dc33c2e150705713c50ca2cfdbeb69361ed91a09" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L120-L138" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68" + logic_hash = "174a3fcebc1e17cc35ddc11fde1798164b5783fc51fdf16581a9690c3b4d6549" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "4aa04f08005b1b7ed941dbfc563737728099e35e3f0f025532921b91b79c967c" + fingerprint = "18a3025ebb8af46605970ee8d7d18214854b86200001d576553e102cb71df266" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58271,165 +62498,142 @@ rule ELASTIC_Linux_Trojan_Banload_D5E1C189 : FILE MEMORY os = "linux" strings: - $a = { E4 E4 E4 58 88 60 90 E4 E4 E4 E4 68 98 70 A0 E4 E4 E4 E4 78 } + $a = { 83 7D 18 00 74 22 8B 45 1C 83 E0 02 85 C0 74 18 83 EC 08 6A 2D FF } condition: all of them } -rule ELASTIC_Windows_Backdoor_Goldbackdoor_91902940 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_A10161Ce : FILE MEMORY { meta: - description = "Detects Windows Backdoor Goldbackdoor (Windows.Backdoor.Goldbackdoor)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "91902940-a291-4fc6-81c5-2cde2328e8d9" - date = "2022-04-29" - modified = "2022-06-09" + id = "a10161ce-62e0-4f60-9de7-bd8caf8618be" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Backdoor_Goldbackdoor.yar#L1-L26" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "485246b411ef5ea9e903397a5490d106946a8323aaf79e6041bdf94763a0c028" - logic_hash = "71e26cce6d730560e1303b2a4f49d0da6d1341263bb47ade46338f03e528cbf7" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L140-L157" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "12ba13a746300d1ab1d0386b86ec224eebf4e6d0b3688495c2fee6a7eccc361d" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "83a404a24e54bd05319d3df3a830f1ffe51d30f71ca55d63ca152d5169511df4" + fingerprint = "77e89011a67a539954358118d41ad3dabde0e69bac2bbb2b2da18eaad427d935" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $pdf = "D:\\Development\\GOLD-BACKDOOR\\" - $agent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.3112.113 Safari/537.36" - $str0 = "client_id" - $str1 = "client_secret" - $str2 = "redirect_uri" - $str3 = "refresh_token" - $a = { 56 57 8B 7D 08 8B F1 6A 00 6A 00 6A 00 6A 00 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 46 30 85 C0 75 ?? 33 C0 5F 5E } - $b = { 66 8B 02 83 C2 02 66 85 C0 75 ?? 2B D1 D1 FA 75 ?? 33 C0 E9 ?? ?? ?? ?? 6A 40 8D 45 ?? 6A 00 50 E8 } + $a = { 45 B0 8B 45 BC 48 63 D0 48 89 D0 48 C1 E0 02 48 8D 14 10 48 8B } condition: - ($pdf and $agent) or ( all of ($str*) and $a and $b) + all of them } -rule ELASTIC_Windows_Backdoor_Goldbackdoor_F11D57Df : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_Ae01D978 : FILE MEMORY { meta: - description = "Detects Windows Backdoor Goldbackdoor (Windows.Backdoor.Goldbackdoor)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "f11d57df-8dd4-481c-a557-f83ae05d53fe" - date = "2022-04-29" - modified = "2022-06-09" + id = "ae01d978-d07d-4813-a22b-5d172c477d08" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Backdoor_Goldbackdoor.yar#L28-L51" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "45ece107409194f5f1ec2fbd902d041f055a914e664f8ed2aa1f90e223339039" - logic_hash = "6401b215523289a3842dec6d3e016a2ca99512c5889e87cb5ff13023bb0b8e1e" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L159-L176" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "c6c22b11dc1f0d4996e5da92c6edf58b7d21d7be40da87ddd39ed0e2d4c84072" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "fed0317d43910d962908604812c2cd1aff6e67f7e245c82b39f2ac6dc14b6edb" + fingerprint = "2d937c6009cfd53e11af52482a7418546ae87b047deabcebf3759e257cd89ce1" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a = { C7 45 ?? 64 69 72 25 C7 45 ?? 5C 53 79 73 C7 45 ?? 74 65 6D 33 C7 45 ?? 32 5C 00 00 C7 45 ?? 2A 2E 65 78 C7 45 ?? 65 00 00 00 E8 ?? ?? ?? ?? FF D0 } - $b = { B9 18 48 24 9D E8 ?? ?? ?? ?? FF D0 } - $c = { B9 F8 92 FA 98 E8 ?? ?? ?? ?? FF D0 } - $a1 = { 64 A1 30 00 00 00 53 55 56 } - $b1 = { B9 76 DB 7A AA 6A 40 68 00 30 00 00 FF 75 ?? 50 E8 ?? ?? ?? ?? FF D0 } - $c1 = { B9 91 51 13 EE 50 68 80 00 00 00 6A 04 50 50 ?? ?? ?? ?? ?? ?? ?? 6A 04 50 E8 ?? ?? ?? ?? FF D0 } + $a = { 00 00 2C 01 00 00 0E 00 00 00 18 03 00 7F E9 38 32 C9 4D 04 9A } condition: all of them } -rule ELASTIC_Linux_Virus_Staffcounter_D2D608A8 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_9E9530A7 : FILE MEMORY { meta: - description = "Detects Linux Virus Staffcounter (Linux.Virus.Staffcounter)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "d2d608a8-2d65-4b10-be71-0a0a6a027920" - date = "2021-06-28" + id = "9e9530a7-ad4d-4a44-b764-437b7621052f" + date = "2021-01-12" modified = "2021-09-16" - reference = "06e562b54b7ee2ffee229c2410c9e2c42090e77f6211ce4b9fa26459ff310315" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Virus_Staffcounter.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "e30f1312eb1cbbc4faba3f67527a4e0e955b5684a1ba58cdd82a7a0f1ce3d2b9" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L178-L196" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961" + logic_hash = "6a5a80e58c86a80f8954e678a2cc26b258d7d7c50047a3e71f3580f1780e3454" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "a791024dc3064ed2e485e5c57d7ab77fc1ec14665c9302b8b572ac4d9d5d2f93" - severity = "100" + fingerprint = "d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50" + severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" os = "linux" strings: - $a = { 20 22 00 20 4C 69 6E 75 78 22 20 3C 00 54 6F 3A 20 22 00 20 } + $a = { F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3 } condition: all of them } -rule ELASTIC_Windows_Hacktool_Darkloadlibrary_C25Ee4Eb : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_5Bf62Ce4 : FILE MEMORY { meta: - description = "Detects Windows Hacktool Darkloadlibrary (Windows.Hacktool.DarkLoadLibrary)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "c25ee4eb-8ea6-40e2-a1a3-ec60491ced03" - date = "2022-12-02" - modified = "2023-01-11" + id = "5bf62ce4-619b-4d46-b221-c5bf552474bb" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_DarkLoadLibrary.yar#L1-L29" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "5546194a71bc449789c3697f9c106860ac0a21e1ccf2b1196120b3f92f4b5306" - logic_hash = "c585abbe72834e9ba2e5f1c8070a43b0f10c2b574c72ffe1def4bfd431096415" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L198-L216" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68" + logic_hash = "848e0c796584cfa21afc182da5f417f5467ae84c74f52cabc13e0f5de4990232" score = 75 - quality = 73 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "a73ca4c615d3567c48cc9ec3eedb0497de67960e9610fd1d0ad136075005d10b" + fingerprint = "3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $guid = "3DDD52BB-803A-40E7-90E4-A879A873DD8B" ascii wide nocase - $print_str0 = "LocalLdrGetProcedureAddress: failed to resolve address of: %s" ascii fullword - $print_str1 = "Not implemented yet, sorry" wide - $print_str2 = "Failed to link module to PEB: %s" ascii wide fullword - $print_str3 = "Failed to resolve imports: %s" ascii wide fullword - $print_str4 = "Failed to map sections: %s" ascii wide fullword - $print_str5 = "Failed to open local DLL file" wide fullword - $print_str6 = "Failed to get DLL file size" wide fullword - $print_str7 = "Failed to allocate memory for DLL data" wide fullword - $print_str8 = "Failed to read data from DLL file" wide fullword - $print_str9 = "Failed to close handle on DLL file" wide + $a = { 89 E5 56 53 31 F6 8D 45 10 83 EC 10 89 45 F4 8B 55 F4 46 8D } condition: - $guid or 4 of ($print_str*) + all of them } -rule ELASTIC_Linux_Ransomware_Babuk_Bd216Cab : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_F3D83A74 : FILE MEMORY { meta: - description = "Detects Linux Ransomware Babuk (Linux.Ransomware.Babuk)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "bd216cab-6532-4a71-9353-8ad692550b97" - date = "2024-05-09" - modified = "2024-06-12" + id = "f3d83a74-2888-435a-9a3c-b7de25084e9a" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Ransomware_Babuk.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "d305a30017baef4f08cee38a851b57869676e45c66e64bb7cc58d40bf0142fe0" - logic_hash = "b0538be9d8deccc3f77640da28e5fd38a07557e9e5e3c09b11349d7eb50a56b5" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L218-L236" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df" + logic_hash = "2db46180e66c9268a97d63cd1c4eb8439e6882b4e3277bc4848e940e4d25482f" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "c7517a40759de20edf7851d164c0e4ba71de049f8ea964f15ab5db12c35352ad" + fingerprint = "1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58437,29 +62641,27 @@ rule ELASTIC_Linux_Ransomware_Babuk_Bd216Cab : FILE MEMORY os = "linux" strings: - $a1 = "Whole files count: %d" - $a2 = "Doesn't encrypted files: %d" + $a = { DC 00 74 1B 83 7D E0 0A 75 15 83 7D E4 00 79 0F C7 45 C8 01 00 } condition: all of them } -rule ELASTIC_Linux_Trojan_Dnsamp_C31Eebd4 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_807911A2 : FILE MEMORY { meta: - description = "Detects Linux Trojan Dnsamp (Linux.Trojan.Dnsamp)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "c31eebd4-7709-440d-95d1-f9a3071cc5ca" + id = "807911a2-f6ec-4e65-924f-61cb065dafc6" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Dnsamp.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "4b86de97819a49a90961d59f9c3ab9f8e57e19add9fe1237d2a2948b4ff22de6" - logic_hash = "b998065eff9f67a1cdf19644a13edb0cef3c619d8b6e16c412d58f5d538e4617" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L238-L255" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "66b15304d5ed22daea666bd0e2b18726b8a058361ff8d69b974bfded933a4d8c" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "220b656a51b3041ede4ffe8f509657c393ff100c88b401c802079aae5804dacd" + fingerprint = "f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58467,28 +62669,27 @@ rule ELASTIC_Linux_Trojan_Dnsamp_C31Eebd4 : FILE MEMORY os = "linux" strings: - $a = { 45 F8 8B 40 14 48 63 D0 48 8D 45 E0 48 8D 70 04 48 8B 45 F8 48 8B } + $a = { FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D } condition: all of them } -rule ELASTIC_Linux_Trojan_Merlin_Bbad69B8 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_9C18716C : FILE MEMORY { meta: - description = "Detects Linux Trojan Merlin (Linux.Trojan.Merlin)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "bbad69b8-e8fc-43ce-a620-793c059536fd" - date = "2022-09-12" - modified = "2022-10-18" + id = "9c18716c-e5cd-4b4f-98e2-0daed77f34cd" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Merlin.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "d9955487f7d08f705e41a5ff848fb6f02d6c88286a52ec837b7b555fb422d1b6" - logic_hash = "e18079c9f018dc8d7f2fdf5c950b405f9f84ad2a5b18775dbef829fe1cb770c3" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L257-L274" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "0e70dc82b2049a6f5efcc501e18e6f87e04a2d50efcb5143240c68c4a924de52" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "594f385556978ef1029755cea53c3cf89ff4d6697be8769fe1977b14bbdb46d1" + fingerprint = "351772d2936ec1a14ee7e2f2b79a8fde62d02097ae6a5304c67e00ad1b11085a" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58496,28 +62697,28 @@ rule ELASTIC_Linux_Trojan_Merlin_Bbad69B8 : FILE MEMORY os = "linux" strings: - $a = { DA 31 C0 BB 1F 00 00 00 EB 12 0F B6 3C 13 40 88 3C 02 40 88 } + $a = { FC 80 F6 FE 59 21 EC 75 10 26 CF DC 7B 5A 5B 4D 24 C9 C0 F3 } condition: all of them } -rule ELASTIC_Linux_Trojan_Merlin_C6097296 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_Fbed4652 : FILE MEMORY { meta: - description = "Detects Linux Trojan Merlin (Linux.Trojan.Merlin)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "c6097296-c518-4541-99b2-e2f6d3e4610b" - date = "2022-09-12" - modified = "2022-10-18" + id = "fbed4652-2c68-45c6-8116-e3fe7d0a28b8" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Merlin.yar#L41-L59" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "d9955487f7d08f705e41a5ff848fb6f02d6c88286a52ec837b7b555fb422d1b6" - logic_hash = "f48ed7f19ab29633600fde4bfea274bf36e7f60d700c9806b334d38a51d28b92" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L276-L294" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "2ea21358205612f5dc0d5f417c498b236c070509531621650b8c215c98c49467" + logic_hash = "fc1f501123ab7421034e183186b077f65838b475f883d4ff04e8fc8a283424ef" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "8496ec66e276304108184db36add64936500f1f0dd74120e03b78c64ac7b5ba1" + fingerprint = "a08bcc7d0999562b4ef2d8e0bdcfa111fe0f76fc0d3b14d42c8e93b7b90abdca" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58525,120 +62726,115 @@ rule ELASTIC_Linux_Trojan_Merlin_C6097296 : FILE MEMORY os = "linux" strings: - $a = { 54 24 38 48 89 5C 24 48 48 85 C9 75 62 48 85 D2 75 30 48 89 9C 24 C8 00 } + $a = { 02 00 00 2B 01 00 00 0E 00 00 00 18 03 00 7F E9 38 32 C9 4D } condition: all of them } -rule ELASTIC_Windows_Ransomware_Snake_550E0265 : BETA FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_94A44Aa5 : FILE MEMORY { meta: - description = "Identifies SNAKE ransomware" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "550e0265-fca9-46df-9d5a-cf3ef7efc7ff" - date = "2020-06-30" - modified = "2021-08-23" - reference = "https://labs.sentinelone.com/new-snake-ransomware-adds-itself-to-the-increasing-collection-of-golang-crimeware/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Snake.yar#L1-L24" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "d9c2f6961a4ef560743060ed176bdc606561ca1b8270b8826cb0dbadaf4e5dbc" - score = 75 - quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "f2796560ddc85ad98a5ef4f0d7323948d57116813c8a26ab902fdfde849704e0" - threat_name = "Windows.Ransomware.Snake" + id = "94a44aa5-6c8b-40b9-8aac-d18cf4a76a19" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L296-L314" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "a7694202f9c32a9d73a571a30a9e4a431d5dfd7032a500084756ba9a48055dba" + logic_hash = "deb46c2960dc4868b7bac1255d8753895950bc066dec03674a714860ff72ef2c" + score = 60 + quality = 45 + tags = "FILE, MEMORY" + fingerprint = "daf7e0382dd4a566eb5a4aac8c5d9defd208f332d8e327637d47b50b9ef271f9" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = "Go build ID: \"X6lNEpDhc_qgQl56x4du/fgVJOqLlPCCIekQhFnHL/rkxe6tXCg56Ez88otHrz/Y-lXW-OhiIbzg3-ioGRz\"" ascii fullword - $a2 = "We breached your corporate network and encrypted the data on your computers." - $a3 = "c:\\users\\public\\desktop\\Fix-Your-Files.txt" nocase - $a4 = "%System Root%\\Fix-Your-Files.txt" nocase - $a5 = "%Desktop%\\Fix-Your-Files.txt" nocase + $a = { 00 00 00 83 F8 FF 0F 45 C2 48 8B 4C 24 08 64 48 33 0C 25 28 00 } condition: - 1 of ($a*) + all of them } -rule ELASTIC_Windows_Ransomware_Snake_119F9C83 : BETA FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_E0673A90 : FILE MEMORY { meta: - description = "Identifies SNAKE ransomware" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "119f9c83-4b55-47ce-8c0d-3799a7b46369" - date = "2020-06-30" - modified = "2021-08-23" - reference = "https://labs.sentinelone.com/new-snake-ransomware-adds-itself-to-the-increasing-collection-of-golang-crimeware/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Snake.yar#L26-L46" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "cf6c81e7332acc798409a05a548460bad0ac3621402672c242e48a1b6bccdae6" + id = "e0673a90-165e-4347-a965-e8d14fdf684b" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L316-L334" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6" + logic_hash = "149147eedd66f9ca2dad9cb69f37abc849d44331ec1b5d2917ab3867ced0b274" score = 75 quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "13ffd63c31df2cbaa6988abcaff3b0a3518437f1d37dcd872817b9cbdb61576f" - threat_name = "Windows.Ransomware.Snake" + tags = "FILE, MEMORY" + fingerprint = "6834f65d54bbfb926f986fe2dd72cd30bf9804ed65fcc71c2c848e72350f386a" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $c1 = { 00 40 83 7C 00 40 9E 7C 00 60 75 7C 00 B0 6C 7C 00 B0 74 7C 00 D0 74 7C 00 B0 59 7C 00 D0 59 7C 00 F0 59 7C 00 10 5A 7C 00 30 5A 7C 00 50 5A 7C 00 70 5A 7C 00 90 5A 7C 00 B0 5A 7C 00 D0 5A 7C 00 D0 6C 7C 00 F0 5A 7C 00 30 5B 7C 00 50 5B 7C 00 70 5B 7C 00 90 5B 7C 00 D0 5E 7C 00 B0 5B 7C 00 D0 5B 7C 00 F0 5B 7C 00 50 60 7C 00 70 61 7C 00 10 5C 7C 00 30 5C 7C 00 50 5C 7C 00 10 63 7C 00 70 5C 7C 00 90 5C 7C 00 90 64 7C 00 B0 5C 7C 00 F0 5C 7C 00 10 5D 7C 00 F0 6C 7C 00 10 6D 7C 00 30 5D 7C 00 50 5D 7C 00 30 6D 7C 00 90 71 7C 00 70 5D 7C 00 90 5D 7C 00 B0 5D 7C 00 D0 5D 7C 00 70 6D 7C 00 F0 5D 7C 00 10 5E 7C 00 30 5E 7C 00 50 5E 7C 00 70 5E 7C 00 90 5E 7C 00 B0 5E 7C 00 F0 5E 7C 00 10 5F 7C 00 30 5F 7C 00 50 5F 7C 00 70 5F 7C 00 90 6D 7C 00 90 5F 7C 00 B0 6D 7C 00 D0 6D 7C 00 F0 6D 7C 00 10 6E 7C 00 B0 5F 7C 00 D0 5F 7C 00 F0 5F 7C 00 10 60 7C 00 30 60 7C 00 30 6E 7C 00 70 60 7C } - $c2 = { 00 30 64 7C 00 50 64 7C 00 70 64 7C 00 B0 64 7C 00 D0 64 7C 00 30 73 7C 00 F0 64 7C 00 90 71 7C 00 10 65 7C 00 30 65 7C 00 50 65 7C 00 90 72 7C 00 B0 72 7C 00 70 6E 7C 00 70 65 7C 00 B0 65 7C 00 D0 65 7C 00 F0 65 7C 00 10 66 7C 00 30 66 7C 00 50 66 7C 00 70 66 7C 00 90 66 7C 00 B0 66 7C 00 D0 66 7C 00 F0 66 7C 00 30 67 7C 00 90 6E 7C 00 B0 6E 7C 00 D0 6E 7C } + $a = { 45 E8 0F B6 00 84 C0 74 17 48 8B 75 E8 48 FF C6 48 8B 7D F0 48 } condition: - 1 of ($c*) + all of them } -rule ELASTIC_Windows_Ransomware_Snake_20Bc5Abc : BETA FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_821173Df : FILE MEMORY { meta: - description = "Identifies SNAKE ransomware" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "20bc5abc-c519-47d2-a6de-5108071a9144" - date = "2020-06-30" - modified = "2021-08-23" - reference = "https://labs.sentinelone.com/new-snake-ransomware-adds-itself-to-the-increasing-collection-of-golang-crimeware/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Snake.yar#L48-L67" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "f3d8a523e04e516e8e059c9f13df355e6caf29a528cfebdf730e3a7d135e3351" + id = "821173df-6835-41e1-a662-a432abf23431" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L336-L354" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "de7d1aff222c7d474e1a42b2368885ef16317e8da1ca3a63009bf06376026163" + logic_hash = "1c6c7666983c43176aa1a9628fb4352f8f11729e02dda13669ca2e62aed5f4ee" score = 75 quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "e7f1be2bd7e1f39b79ac89cf58c90abdb537ff54cbf161192d997e054d3f0883" - threat_name = "Windows.Ransomware.Snake" + tags = "FILE, MEMORY" + fingerprint = "c311789e1370227f7be1d87da0c370a905b7f5b4c55cdee0f0474060cc0fc5e4" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $b1 = { 57 12 1A 10 1A 10 1A 10 1A 10 1A 10 1A 10 1A 10 1A 10 1A 10 1A } + $a = { D0 48 FF C8 48 03 45 F8 48 FF C8 C6 00 00 48 8B 45 F8 48 C7 C1 FF FF } condition: - 1 of ($b*) + all of them } -rule ELASTIC_Linux_Backdoor_Bash_E427876D : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_31796A40 : FILE MEMORY { meta: - description = "Detects Linux Backdoor Bash (Linux.Backdoor.Bash)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "e427876d-c7c5-447a-ad6d-5cbc12d9dacf" + id = "31796a40-1cbe-4d0c-a785-d16f40765f4a" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Backdoor_Bash.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "07db41a4ddaac802b04df5e5bbae0881fead30cb8f6fa53a8a2e1edf14f2d36b" - logic_hash = "fdd066b746416730419787d21eb53fa2ba997679a237d9db3a2e1365d43df892" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L356-L374" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "227c7f13f7bdadf6a14cc85e8d2106b9d69ab80abe6fc0056af5edef3621d4fb" + logic_hash = "0e0e901d12edd77e77a205f8547f891f483fc8676493e9b7a324e970225af3c9" score = 75 - quality = 73 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "6cc13bb2591d896affc58f4a22b3463a72f6c9d896594fe1714b825e064b0956" + fingerprint = "0a6c56eeed58a1a100c9b981157bb864904ffddb3a0c4cb61ec4cc0d770d68ae" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58646,28 +62842,28 @@ rule ELASTIC_Linux_Backdoor_Bash_E427876D : FILE MEMORY os = "linux" strings: - $a = { 67 65 44 6F 6B 4B 47 6C 6B 49 43 31 31 4B 54 6F 67 4C 32 56 } + $a = { 14 48 63 D0 48 8D 45 C0 48 8D 70 04 48 8B 45 E8 48 8B 40 18 48 } condition: all of them } -rule ELASTIC_Linux_Trojan_Backegmm_B59712E6 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_750Fe002 : FILE MEMORY { meta: - description = "Detects Linux Trojan Backegmm (Linux.Trojan.Backegmm)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "b59712e6-d14d-4a57-a3d6-2dc323bf840d" + id = "750fe002-cac1-4832-94d2-212aa5ec17e3" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Backegmm.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "d6c8e15cb65102b442b7ee42186c58fa69cd0cb68f4fd47eb5ad23763371e0be" - logic_hash = "a2e6016bfd8475880c28c89b5f5beeef1335de9529d44bbe7c5aaa352aab9a29" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L376-L394" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68" + logic_hash = "eb9907d8a63822c2e3ab57d43dca8ede7876610f029e2f9c10c9eeace9ea0078" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "61b2f0c7cb98439b05776edeaf06b114d364119ebe733d924158792110c5e21c" + fingerprint = "f51347158a6477b0da4ed4df3374fbad92b6ac137aa4775f83035d1e30cba7dc" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58675,226 +62871,200 @@ rule ELASTIC_Linux_Trojan_Backegmm_B59712E6 : FILE MEMORY os = "linux" strings: - $a = { 69 73 74 65 6E 00 66 6F 72 6B 00 73 70 72 69 6E 74 66 00 68 } + $a = { 10 8B 45 0C 40 8A 00 3C FC 75 06 C6 45 FF FE EB 50 8B 45 0C 40 } condition: all of them } -rule ELASTIC_Windows_Vulndriver_Mhyprot_26214176 : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_6122Acdf : FILE MEMORY { meta: - description = "Subject: miHoYo Co.,Ltd., Version: 1.0.0.0" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "26214176-1565-4b10-bd7a-901206ef6b29" - date = "2022-08-25" - modified = "2022-08-25" + id = "6122acdf-1eef-45ea-83ea-699d21c2dc20" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_Mhyprot.yar#L1-L22" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "509628b6d16d2428031311d7bd2add8d5f5160e9ecc0cd909f1e82bbbb3234d6" - logic_hash = "61d1713c689b9d663f2d3360d07735b07ca10365b5ce424b2df726bd6cc434d3" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L396-L413" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "140b32a8f2b7493b068e63a05b3d9baec6ec14c9f2062c7e760dde96335e29f1" score = 75 quality = 75 - tags = "FILE" - fingerprint = "368c818c0052192c73f078a0ea314e3d2f5d08bc4ef32a27d7e01a40eba68940" - threat_name = "Windows.VulnDriver.Mhyprot" + tags = "FILE, MEMORY" + fingerprint = "283275705c729be23d7dc75056388ecae00390bd25ee7b66b0cfc9b85feee212" severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $subject_name = { 06 03 55 04 03 [2] 6D 69 48 6F 59 6F 20 43 6F 2E 2C 4C 74 64 2E } - $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x00][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ - $str1 = "\\Device\\mhyprot2" wide fullword + $a = { E8 B0 00 FC 8B 7D E8 F2 AE 89 C8 F7 D0 48 48 89 45 F8 EB 03 FF } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and int16 ( uint32(0x3C)+0x18)==0x020b and $subject_name and $version and $str1 + all of them } -rule ELASTIC_Windows_Trojan_Stealc_B8Ab9Ab5 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_A0A4De11 : FILE MEMORY { meta: - description = "Detects Windows Trojan Stealc (Windows.Trojan.Stealc)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "b8ab9ab5-5731-4651-b982-03ad8fe347fb" - date = "2024-03-13" - modified = "2024-03-21" + id = "a0a4de11-fe65-449f-a990-ad5f18ac66f0" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Stealc.yar#L1-L27" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0d1c07c84c54348db1637e21260dbed09bd6b7e675ef58e003d0fe8f017fd2c8" - logic_hash = "5fc5d5cea481d1d204d1aa6c52679a23eb59438df2fe547d14c00524772867bb" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L415-L433" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417" + logic_hash = "220c6ba82b906f070123b3bae9aafa72c0fb3bc8d5858a4f4bd65567076eb73d" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "49253b1d1e39ba25b2d3b622d00633b9629715e65e1537071b0f3b0318b7db12" + fingerprint = "891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $seq_str_decrypt = { 55 8B EC 83 EC ?? 8D 4D ?? E8 ?? ?? ?? ?? 8B 45 ?? 50 E8 ?? ?? ?? ?? 83 C4 ?? 50 8D 4D ?? E8 ?? ?? ?? ?? 83 C0 ?? 50 } - $seq_lang_check = { 81 E9 19 04 00 00 89 4D ?? 83 7D ?? ?? 77 ?? 8B 55 ?? 0F B6 82 ?? ?? ?? ?? FF 24 85 ?? ?? ?? ?? } - $seq_mem_check_constant = { 72 09 81 7D F8 57 04 00 00 73 08 } - $seq_hwid_algo = { 8B 08 69 C9 0B A3 14 00 81 E9 51 75 42 69 8B 55 08 } - $str1 = "- Country: ISO?" ascii fullword - $str2 = "%d/%d/%d %d:%d:%d" ascii fullword - $str3 = "%08lX%04lX%lu" ascii fullword - $str4 = "\\Outlook\\accounts.txt" ascii fullword - $str5 = "/c timeout /t 5 & del /f /q" ascii fullword + $a = { 42 0D 83 C8 10 88 42 0D 48 8B 55 D8 0F B6 42 0D 83 C8 08 88 } condition: - (2 of ($seq*) or 4 of ($str*)) + all of them } -rule ELASTIC_Windows_Trojan_Stealc_A2B71Dc4 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_A473Dcb6 : FILE MEMORY { meta: - description = "Detects Windows Trojan Stealc (Windows.Trojan.Stealc)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "a2b71dc4-4041-4c1f-b546-a2b6947702d1" - date = "2024-03-13" - modified = "2024-03-21" + id = "a473dcb6-887e-4a9a-a1f2-df094f1575b9" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Stealc.yar#L29-L50" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0d1c07c84c54348db1637e21260dbed09bd6b7e675ef58e003d0fe8f017fd2c8" - logic_hash = "b79ac3e65cd7d2819d6a49f59ec661241c97174f66a7c4ada91932f10fc43583" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L435-L453" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "7ba74e3cb0d633de0e8dbe6cfc49d4fc77dd0c02a5f1867cc4a1f1d575def97d" + logic_hash = "106ee9cd9c368674ae08b835f54dbb6918b553e3097aae9b0de88f55420f046b" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "9eeb13fededae39b8a531fa5d07eaf839b56a1c828ecd11322c604962e8b1aec" + fingerprint = "6119a43aa5c9f61249083290293f15696b54b012cdf92553fd49736d40c433f9" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $seq_1 = { 8B C6 C1 E8 02 33 C6 D1 E8 33 C6 C1 E8 02 33 C6 83 E0 01 A3 D4 35 61 00 C1 E0 0F 66 D1 E9 66 0B C8 } - $seq_2 = { FF D3 8B 4D ?? E8 [4] 6A ?? 33 D2 5F 8B C8 F7 F7 85 D2 74 ?? } - $seq_3 = { 33 D2 8B F8 59 F7 F1 8B C7 3B D3 76 04 2B C2 03 C1 } - $seq_4 = { 6A 7C 58 66 89 45 FC 8D 45 F0 50 8D 45 FC 50 FF 75 08 C7 45 F8 01 } + $a = { 49 56 04 0B 1E 46 1E B0 EB 10 18 38 38 D7 80 4D 2D 03 29 62 } condition: - 2 of ($seq*) + all of them } -rule ELASTIC_Windows_Trojan_Stealc_5D3F297C : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_30444846 : FILE MEMORY { meta: - description = "Detects Windows Trojan Stealc (Windows.Trojan.Stealc)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "5d3f297c-b812-401a-8671-2e00369cd6f2" - date = "2024-03-05" - modified = "2024-06-13" + id = "30444846-439f-41e1-b0b4-c12da774a228" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Stealc.yar#L52-L70" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "885c8cd8f7ad93f0fd43ba4fb7f14d94dfdee3d223715da34a6e2fbb4d25b9f4" - logic_hash = "556d3bc9374a5ec23faa410900dfc94b5534434c9733165355d281976444a42b" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L455-L473" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c84b81d79d437bb9b8a6bad3646aef646f2a8e1f1554501139648d2f9de561da" + logic_hash = "26bc95efb2ea69fece52cf3ab38ce35891c77fc0dac3e26e5580ba3a88e112e9" score = 75 - quality = 75 + quality = 73 tags = "FILE, MEMORY" - fingerprint = "ff90bfcb28bb3164fb11da5f35f289af679805f7e4047e48d97ae89e5b820dcd" - severity = 50 + fingerprint = "3c74db508de7c8c1c190d5569e0a2c2b806f72045e7b74d44bfbaed20ecb956b" + severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = { 83 EC 08 C7 45 F8 00 00 00 00 83 7D 08 00 74 4A 83 7D 0C 00 74 44 8B 45 0C 83 C0 01 50 6A 40 ?? ?? ?? ?? ?? ?? 89 45 F8 83 7D F8 00 74 2C C7 45 FC 00 00 00 00 EB 09 8B 4D FC 83 C1 01 } + $a = { 64 20 2B 78 20 74 66 74 70 31 2E 73 68 3B 20 73 68 20 74 66 74 } condition: all of them } -rule ELASTIC_Windows_Hacktool_Sharpmove_05E28928 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_Ea92Cca8 : FILE MEMORY { meta: - description = "Detects Windows Hacktool Sharpmove (Windows.Hacktool.SharpMove)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "05e28928-6109-4afe-bd86-908d354ddd80" - date = "2022-11-20" - modified = "2023-01-11" + id = "ea92cca8-bba7-4a1c-9b88-a2d051ad0021" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_SharpMove.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "051f60f9f4665b96f764810defe9525ae7b4f9898249b83a23094cee63fa0c3b" - logic_hash = "021a56dd47d9929e71b82b00d24aa8969a31945681dcf414c69b8d175fb0b6eb" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L475-L492" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "5a9598b3fd37b15444063403a481df1a43894ddcbbd343961e1c770cb74180c9" score = 75 quality = 73 tags = "FILE, MEMORY" - fingerprint = "634efb2dedbb181a31ea41ff34d1d0810d1ab4823c8611737d68cb56601a052d" + fingerprint = "aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $guid = "8BF82BBE-909C-4777-A2FC-EA7C070FF43E" ascii wide nocase - $print_str0 = "[X] Failed to connecto to WMI: {0}" ascii wide fullword - $print_str1 = "[+] Executing DCOM ShellBrowserWindow : {0}" ascii wide fullword - $print_str2 = "[+] User credentials : {0}" ascii wide fullword - $print_str3 = "[+] Executing DCOM ExcelDDE : {0}" ascii wide fullword + $a = { 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64 } condition: - $guid or all of ($print_str*) + all of them } -rule ELASTIC_Windows_Trojan_Mylobot_A895174A : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_D4227Dbf : FILE MEMORY { meta: - description = "Detects Windows Trojan Mylobot (Windows.Trojan.MyloBot)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "a895174a-0395-4ccb-b681-e8111a817a5c" - date = "2024-05-15" - modified = "2024-06-12" + id = "d4227dbf-6ab4-4637-a6ba-0e604acaafb4" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_MyloBot.yar#L1-L25" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "33831d9ad64d0f52f507f08ef81607aafa6ced58a189969af6cf57c659c982d2" - logic_hash = "16f2d8eeb6c85944030a33bd250e4e8b98985a6c877a0ec3ad5a6037e7c00159" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L494-L512" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961" + logic_hash = "7953b8d08834315a6ca2c0c8ac1ec7b74a6ffcb71cec4fc053c24e1b59232c0c" score = 75 - quality = 50 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "dfa1e47260c0e07fea3b2b61157de71f412807b9eec19b14082da7d6a95d6099" + fingerprint = "58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = "%s\\%s.lnk" wide fullword - $a2 = "%s\\%s.exe" wide fullword - $a3 = "%s\\%s\\%s.exe" wide fullword - $a4 = "HTTP/1.0 502" ascii fullword - $a5 = "/c \"%ws '%ws%s'\"" ascii fullword - $a6 = ">> %ws %ws %ws" ascii fullword - $a7 = "%s\\DefaultIcon" ascii fullword + $a = { FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00 } condition: all of them } -rule ELASTIC_Linux_Trojan_Getshell_98D002Bf : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_09C3070E : FILE MEMORY { meta: - description = "Detects Linux Trojan Getshell (Linux.Trojan.Getshell)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "98d002bf-63b7-4d11-98ef-c3127e68d59c" + id = "09c3070e-4b71-45a0-aa62-0cc6e496644a" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Getshell.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "97b7650ab083f7ba23417e6d5d9c1d133b9158e2c10427d1f1e50dfe6c0e7541" - logic_hash = "358575f55910b060bde94bbc55daa9650a43cf1470b77d1842ddcaa8b299700a" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L514-L532" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df" + logic_hash = "f8f8e8883cf1e51fbaef81b8334ac5fa45a54682d285282da62c80e4aa50a48d" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "b7bfec0a3cfc05b87fefac6b10673491b611400edacf9519cbcc1a71842e9fa3" + fingerprint = "84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -58902,294 +63072,287 @@ rule ELASTIC_Linux_Trojan_Getshell_98D002Bf : FILE MEMORY os = "linux" strings: - $a = { B2 6A B0 03 CD 80 85 C0 78 02 FF E1 B8 01 00 00 00 BB 01 00 } + $a = { 48 C1 E8 06 48 89 C6 48 8B 94 C5 50 FF FF FF 8B 8D 2C FF FF FF 83 } condition: all of them } -rule ELASTIC_Linux_Trojan_Getshell_213D4D69 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_Fa19B8Fc : FILE MEMORY { meta: - description = "Detects Linux Trojan Getshell (Linux.Trojan.Getshell)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "213d4d69-5660-468d-a98c-ff3eef604b1e" - date = "2021-06-28" + id = "fa19b8fc-6035-4415-842f-4993411ab43e" + date = "2021-01-12" modified = "2021-09-16" - reference = "05fc4dcce9e9e1e627ebf051a190bd1f73bc83d876c78c6b3d86fc97b0dfd8e8" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Getshell.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "2075def88b31ac32e44c270ab20273c8b91f37e25a837c0353f76bcf431cdcb3" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L534-L552" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "a7cfc16ec33ec633cbdcbff3c4cefeed84d7cbe9ca1f4e2a3b3e43d39291cd6b" + logic_hash = "cddf3b9948b9bc685ff7d4c00377d0f80861169707777022297e549bd166dbf0" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "60e385e4c5eb189785bc14d39bf8a22c179e4be861ce3453fbcf4d367fc87c90" - severity = "100" + fingerprint = "4f213d5d1b4a0b832ed7a6fac91bef7c29117259b775b85409e9e4c8aec2ad10" + severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" os = "linux" strings: - $a = { EC 01 00 00 00 EB 3C 8B 45 EC 48 98 48 C1 E0 03 48 03 45 D0 48 } + $a = { 02 63 10 01 0F 4B 85 14 36 B0 60 53 03 4F 0D B2 05 76 02 B7 00 00 } condition: all of them } -rule ELASTIC_Linux_Trojan_Getshell_3Cf5480B : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_Eaa9A668 : FILE MEMORY { meta: - description = "Detects Linux Trojan Getshell (Linux.Trojan.Getshell)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "3cf5480b-bb21-4a6e-a078-4b145d22c79f" - date = "2021-06-28" + id = "eaa9a668-e3b9-4657-81bf-1c6456e2053a" + date = "2021-01-12" modified = "2021-09-16" - reference = "0e41c0d6286fb7cd3288892286548eaebf67c16f1a50a69924f39127eb73ff38" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Getshell.yar#L41-L59" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "87b0db74e81d4f236b11f51a72fba2e4263c988402292b2182d19293858c6126" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L554-L572" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "409c55110d392aed1a9ec98a6598fb8da86ab415534c8754aa48e3949e7c4b62" + logic_hash = "05e9047342a9d081a09f8514f0ec32d72bc43a286035014ada90b0243f92cfa8" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "3ef0817445c54994d5a6792ec0e6c93f8a51689030b368eb482f5ffab4761dd2" - severity = "100" + fingerprint = "bee2744457164e5747575a101026c7862474154d82f52151ac0d77fb278d9405" + severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" os = "linux" strings: - $a = { B2 24 B0 03 CD 80 85 C0 78 02 FF E1 B8 01 00 00 00 BB 01 00 } + $a = { 45 C0 0F B6 00 3C 2F 76 0B 48 8B 45 C0 0F B6 00 3C 39 76 C7 48 8B } condition: all of them } -rule ELASTIC_Linux_Trojan_Getshell_8A79B859 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_46Eec778 : FILE MEMORY { meta: - description = "Detects Linux Trojan Getshell (Linux.Trojan.Getshell)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "8a79b859-654c-4082-8cfc-61a143671457" - date = "2021-06-28" + id = "46eec778-7342-4ef7-adac-35bc0cdb9867" + date = "2021-01-12" modified = "2021-09-16" - reference = "1154ba394176730e51c7c7094ff3274e9f68aaa2ed323040a94e1c6f7fb976a2" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Getshell.yar#L61-L79" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "2aa3914ec4cc04e5daa2da1460410b4f0e5e7a37c5a2eae5a02ff5f55382f1fe" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L574-L592" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1" + logic_hash = "08e77a31005e14a06197857301e22d20334c1f2ef7fc06a4208643438377f4c4" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "5a95d1df94791c8484d783da975bec984fb11653d1f81f6397efd734a042272b" - severity = "100" + fingerprint = "2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518" + severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" os = "linux" strings: - $a = { 0A 00 89 E1 6A 1C 51 56 89 E1 43 6A 66 58 CD 80 B0 66 B3 04 } + $a = { C0 01 45 F8 48 83 45 E8 02 83 6D C8 02 83 7D C8 01 7F E4 83 7D } condition: all of them } -rule ELASTIC_Windows_Vulndriver_Rtkio_13B3C88B : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_F51C5Ac3 : FILE MEMORY { meta: - description = "Name: rtkio.sys" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "13b3c88b-daa7-4402-ad31-6fc7d4064087" - date = "2022-04-07" - modified = "2022-04-07" + id = "f51c5ac3-ade9-4d01-b578-3473a2b116db" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_Rtkio.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "478917514be37b32d5ccf76e4009f6f952f39f5553953544f1b0688befd95e82" - logic_hash = "1e37650292884e28dcc51c42bc1b1d1e8efc13b0727f7865ff1dc7b8e1a72380" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L594-L612" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "899c072730590003b98278bdda21c15ecaa2f49ad51e417ed59e88caf054a72d" + logic_hash = "e82b5ddb760d5bdcd146e1de12ec34c4764e668543420765146e22dee6f5732b" score = 75 quality = 75 - tags = "FILE" - fingerprint = "3788e6a7a759796a2675116e4d291324f97114773cf53345f15796566266f702" - threat_name = "Windows.VulnDriver.Rtkio" - severity = 50 + tags = "FILE, MEMORY" + fingerprint = "34f254afdf94b1eb29bae4eb8e3864ea49e918a5dbe6e4c9d06a4292c104a792" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 72 00 74 00 6B 00 69 00 6F 00 2E 00 73 00 79 00 73 00 00 00 } + $a = { 74 2A 8B 45 0C 0F B6 00 84 C0 74 17 8B 45 0C 40 89 44 24 04 8B } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name + all of them } -rule ELASTIC_Windows_Vulndriver_Rtkio_D595781E : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_71E487Ea : FILE MEMORY { meta: - description = "Name: rtkio64.sys" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "d595781e-67c1-47bf-a7ea-bb4a9ba33879" - date = "2022-04-07" - modified = "2022-04-07" + id = "71e487ea-a592-469c-a03e-0c64d2549e74" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_Rtkio.yar#L22-L41" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "4ed2d2c1b00e87b926fb58b4ea43d2db35e5912975f4400aa7bd9f8c239d08b7" - logic_hash = "289eb17025d989cc74e109b1c03378e9760817a84f1a759153ff6ff6b6401e6d" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L614-L632" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b8d044f2de21d20c7e4b43a2baf5d8cdb97fba95c3b99816848c0f214515295b" + logic_hash = "3de9e0e3334e9e6e5906886f95ff8ce3596f85772dc25021fb0ee148281cf81c" score = 75 quality = 75 - tags = "FILE" - fingerprint = "efe0871703d5c146764c4a7ac9c80ae4e635dc6dd0e718e6ddc4c39b18ca9fdd" - threat_name = "Windows.VulnDriver.Rtkio" - severity = 50 + tags = "FILE, MEMORY" + fingerprint = "8df69968ddfec5821500949015192b6cdbc188c74f785a272effd7bc9707f661" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 72 00 74 00 6B 00 69 00 6F 00 36 00 34 00 2E 00 73 00 79 00 73 00 20 00 00 00 } + $a = { E0 8B 45 D8 8B 04 D0 8D 50 01 83 EC 0C 8D 85 40 FF FF FF 50 } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name + all of them } -rule ELASTIC_Windows_Vulndriver_Rtkio_B09Af431 : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_6620Ec67 : FILE MEMORY { meta: - description = "Name: rtkiow8x64.sys" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "b09af431-307b-40e2-bac5-5865c1ad54c8" - date = "2022-04-07" - modified = "2022-04-07" + id = "6620ec67-8f12-435b-963c-b44a02f43ef1" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_Rtkio.yar#L43-L62" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "b205835b818d8a50903cf76936fcf8160060762725bd74a523320cfbd091c038" - logic_hash = "916a6e63dc4c7ee0bfdf4a455ee467a1d03c1042db60806511aa7cbf3b096190" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L634-L652" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b91eb196605c155c98f824abf8afe122f113d1fed254074117652f93d0c9d6b2" + logic_hash = "2df2c8cdc2cb545f916159d44a800708b55a2993cd54a4dcf920a6a8dc6361e7" score = 75 quality = 75 - tags = "FILE" - fingerprint = "e62a497acc1ee04510aa42ca96c5265e16b3be665f99e7dfc09ecc38055aca5b" - threat_name = "Windows.VulnDriver.Rtkio" - severity = 50 + tags = "FILE, MEMORY" + fingerprint = "9d68db5b3779bb5abe078f9e36dd9a09d4d3ad9274a3a50bdfa0e444a7e46623" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 72 00 74 00 6B 00 69 00 6F 00 77 00 38 00 78 00 36 00 34 00 2E 00 73 00 79 00 73 00 00 00 } + $a = { AF 93 64 1A D8 0B 48 93 64 0B 48 A3 64 11 D1 0B 41 05 E4 48 } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name + all of them } -rule ELASTIC_Windows_Vulndriver_Rtkio_5693E967 : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_D996D335 : FILE MEMORY { meta: - description = "Name: rtkiow10x64.sys" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "5693e967-dbe4-457c-8b0c-404774871ac0" - date = "2022-04-07" - modified = "2022-04-07" + id = "d996d335-e049-4052-bf36-6cd07c911a8b" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_Rtkio.yar#L64-L83" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "ab8f2217e59319b88080e052782e559a706fa4fb7b8b708f709ff3617124da89" - logic_hash = "4cbc7a52de7f610cdb12bf40a9099bcfae818dcb5e4119a8c34499433aeebd7e" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L654-L672" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda" + logic_hash = "212c75ab61eac8b3ed2049966628dfc81ae5a620b4a4b38aaa0696d594910dea" score = 75 quality = 75 - tags = "FILE" - fingerprint = "4de76b2d42b523c4bfefeee8905e8f431168cb59e18049563f9942e97c276e46" - threat_name = "Windows.VulnDriver.Rtkio" - severity = 50 + tags = "FILE, MEMORY" + fingerprint = "e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 72 00 74 00 6B 00 69 00 6F 00 77 00 31 00 30 00 78 00 36 00 34 00 2E 00 73 00 79 00 73 00 20 00 00 00 } + $a = { D0 EB 0F 40 38 37 75 04 48 89 F8 C3 49 FF C8 48 FF C7 4D 85 C0 } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name + all of them } -rule ELASTIC_Windows_Vulndriver_Viragt_5F92F226 : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_D0C57A2E : FILE MEMORY { meta: - description = "Name: viragt.sys, Version: 1.80.0.0" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "5f92f226-053e-4a5b-8a0c-52a578f66cb8" - date = "2022-04-07" - modified = "2022-04-07" + id = "d0c57a2e-c10c-436c-be13-50a269326cf2" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_Viragt.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "e05eeb2b8c18ad2cb2d1038c043d770a0d51b96b748bc34be3e7fc6f3790ce53" - logic_hash = "e7ade7aec563c1dc602dfd7fda8c063058f47ae2a915959468792fce389b38f1" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L674-L691" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "2ac51f0943d573fdc9a39837aeefd9158c27a4b3f35fbbb0a058a88392a53c14" score = 75 quality = 75 - tags = "FILE" - fingerprint = "544d7012478f31e9f9858ddb4463fa705bf8d50a97b5477557bd95e2d3d3b3ac" - threat_name = "Windows.VulnDriver.Viragt" - severity = 50 + tags = "FILE, MEMORY" + fingerprint = "3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 76 00 69 00 72 00 61 00 67 00 74 00 2E 00 73 00 79 00 73 00 00 00 } - $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x50][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x4f][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ + $a = { 07 0F B6 57 01 C1 E0 08 09 D0 89 06 0F BE 47 02 C1 E8 1F 89 } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version + all of them } -rule ELASTIC_Windows_Vulndriver_Viragt_84D508Ad : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_751Acb94 : FILE MEMORY { meta: - description = "Name: viragt64.sys, Version: 1.0.0.11" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "84d508ad-939d-4e3b-b9a6-204eb8bcaee5" - date = "2022-04-07" - modified = "2022-04-07" + id = "751acb94-cb23-4949-a4dd-87985c47379e" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_Viragt.yar#L23-L43" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "58a74dceb2022cd8a358b92acd1b48a5e01c524c3b0195d7033e4bd55eff4495" - logic_hash = "a3e1b41155c7dd347976a1057cb763ab60c50c34e981fef050bd54f060a412fc" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L693-L710" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "1963351d209168f4ae2268d245cfd5320e4442d00746d021088ffae98e5da454" score = 75 quality = 75 - tags = "FILE" - fingerprint = "172be67b6bb07f189fd5e535e173d245114bf4b17c3daf89924a30c7219d3e69" - threat_name = "Windows.VulnDriver.Viragt" - severity = 50 + tags = "FILE, MEMORY" + fingerprint = "dbdfdb455868332e9fbadd36c084d0927a3dd8ab844f0b1866e914914084cd4b" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 76 00 69 00 72 00 61 00 67 00 74 00 36 00 34 00 2E 00 73 00 79 00 73 00 00 00 } - $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x00][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x0b][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ + $a = { 20 54 6F 20 43 6F 6E 6E 65 63 74 21 20 00 53 75 63 63 65 73 66 } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version + all of them } -rule ELASTIC_Linux_Exploit_Iouring_D04C1C19 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_656Bf077 : FILE MEMORY { meta: - description = "Detects Linux Exploit Iouring (Linux.Exploit.IOUring)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "d04c1c19-9303-41cd-ae9c-149bb137e6cc" - date = "2024-04-07" - modified = "2024-06-12" + id = "656bf077-ca0c-4d28-9daa-eb6baafaf467" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_IOUring.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "29e6a5f7b36e271219601528f3fd70831aacb8b9f05722779faa40afc97b3b60" - logic_hash = "b1d8d6090576b4b5bcd435eb69ee1dc1f1947115d38b62364cf1730a4f08d317" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L712-L730" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6" + logic_hash = "0c9728304e720eb2cd00afad8d16f309514473dece48fa94af6a72ca41705a36" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "0e50d858b8e5428a964dc70b0132659defd61e8965331fa327b1f454bf922162" + fingerprint = "3ea8ed60190198d5887bb7093975d648a9fd78234827d648a8258008c965b1c1" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -59197,242 +63360,231 @@ rule ELASTIC_Linux_Exploit_Iouring_D04C1C19 : FILE MEMORY os = "linux" strings: - $s1 = "io_uring_" - $s2 = "kaslr_leak: 0x%llx" - $s3 = "kaslr_base: 0x%llx" + $a = { 74 28 48 8B 45 E8 0F B6 00 84 C0 74 14 48 8B 75 E8 48 FF C6 48 8B } condition: all of them } -rule ELASTIC_Windows_Exploit_Eternalblue_Ead33Bf8 : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_E6D75E6F : FILE MEMORY { meta: - description = "Detects Windows Exploit Eternalblue (Windows.Exploit.Eternalblue)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "ead33bf8-1870-4d01-a223-edcbe262542f" + id = "e6d75e6f-aa04-4767-8730-6909958044a7" date = "2021-01-12" - modified = "2021-08-23" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Exploit_Eternalblue.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "a1340e418c80be58fb6bbb48d4e363de8c6d62ea59730817d5eda6ba17b2c7a7" - logic_hash = "4d0ab8bd7ef5b20e656110ac3c78b08803539387cb4fe1425a284d39c42aa199" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L732-L750" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "48b15093f33c18778724c48c34199a420be4beb0d794e36034097806e1521eb8" + logic_hash = "339dd33a3313a4a94d2515cd4c2100ac6b9d5e0029881494c28dc3e7c8a05798" score = 75 quality = 75 - tags = "FILE" - fingerprint = "9e3b5f4f0b8ac683544886abbd9eecbf0253a7992ee5d99c453de67b9aacdccd" + tags = "FILE, MEMORY" + fingerprint = "e99805e8917d6526031270b6da5c2f3cc1c8235fed1d47134835a107d0df497c" severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a = { F8 31 C9 EB 0B 40 8A 3C 0E 40 88 3C 08 48 FF C1 48 39 D1 75 } + $a = { 00 00 00 CD 80 C3 8B 54 24 04 8B 4C 24 08 87 D3 B8 5B 00 00 00 } condition: all of them } -rule ELASTIC_Windows_Trojan_Backoff_22798F00 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_7167D08F : FILE MEMORY { meta: - description = "Detects Windows Trojan Backoff (Windows.Trojan.Backoff)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "22798f00-ff2a-4f5f-a9ef-fab6d04ca679" - date = "2022-08-10" - modified = "2022-09-29" + id = "7167d08f-bfeb-4d78-9783-3a1df2ef0ed3" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Backoff.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "65b5aff18a4e0bc29d7cc4cfbe2d5882f99a855727fe467b2ba2e2851c43d21b" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L752-L770" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68" + logic_hash = "88c07bf06801192f38ef66229a0aa5c1ef6242caeb080ce1c7cd13ad0d540c82" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "a45fc701844e6e0cfba5d8ef90d00960b5817af66e6b3d889a54d33539cd5d41" + fingerprint = "b9df4ab322a2a329168f684b07b7b05ee3d03165c5b9050a4710eae7aeca6cd9" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $str1 = "\\nsskrnl" fullword - $str2 = "Upload KeyLogs" fullword - $str3 = "&op=%d&id=%s&ui=%s&wv=%d&gr=%s&bv=%s" fullword - $str4 = "[%s] - [%.2d/%.2d/%d %.2d:%.2d:%.2d]" fullword - $str5 = "\\OracleJava\\Log.txt" fullword - $str6 = "[Ctrl+%c]" fullword + $a = { 0C 8A 00 3C 2D 75 13 FF 45 0C C7 45 E4 01 00 00 00 EB 07 FF } condition: - 3 of them + all of them } -rule ELASTIC_Windows_Trojan_Eagerbee_7029Ba21 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_27De1106 : FILE MEMORY { meta: - description = "Detects Windows Trojan Eagerbee (Windows.Trojan.EagerBee)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "7029ba21-12ea-4120-911b-a36c4002409e" - date = "2023-05-09" - modified = "2023-06-13" - reference = "https://www.elastic.co/security-labs/introducing-the-ref5961-intrusion-set" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_EagerBee.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "09005775fc587ac7bf150c05352e59dc01008b7bf8c1d870d1cea87561aa0b06" - logic_hash = "874959361b14ba74e13e6e674da75c9bdb6b9475d8b286572825c940b41f679f" + id = "27de1106-497d-40a0-8fc4-929f7a927628" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L772-L790" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "899c072730590003b98278bdda21c15ecaa2f49ad51e417ed59e88caf054a72d" + logic_hash = "4e266e1ae31d7d86866b112a04ca38c0a8185c18ebb10ac6497bbaa69f51b2fd" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "26d0d10f7c503e284e2b24a9e273f880d2e152348dfdd44fb3fc8cb10aa57e2a" + fingerprint = "9a747f0fc7ccc55f24f2654344484f643103da709270a45de4c1174d8e4101cc" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = { C2 EB D6 0F B7 C2 48 8D 0C 80 41 8B 44 CB 14 41 2B 44 CB 0C 41 } - $a2 = { C8 75 04 33 C0 EB 7C 48 63 41 3C 8B 94 08 88 00 00 00 48 03 D1 8B } + $a = { 0C 0F B6 00 84 C0 74 18 8B 45 0C 40 8B 55 08 42 89 44 24 04 89 } condition: all of them } -rule ELASTIC_Windows_Trojan_Eagerbee_A64B323B : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_148B91A2 : FILE MEMORY { meta: - description = "Detects Windows Trojan Eagerbee (Windows.Trojan.EagerBee)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "a64b323b-60b6-49b9-99d2-82a336fe304e" - date = "2023-09-04" - modified = "2023-09-20" - reference = "https://www.elastic.co/security-labs/introducing-the-ref5961-intrusion-set" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_EagerBee.yar#L23-L45" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "339e4fdbccb65b0b06a1421c719300a8da844789a2016d58e8ce4227cb5dc91b" - logic_hash = "e1c25cf8ce0ff434727c9104c6b79110ff5cfa84eb3e939119fd05cf676727c6" + id = "148b91a2-ed51-4c2d-9d15-6a48d9ea3e0a" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L792-L810" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "d5b2bde0749ff482dc2389971e2ac76c4b1e7b887208a538d5555f0fe6984825" + logic_hash = "1a974c0882c2d088c978a52e5b535807c86f117cf2f05c40c084e849b1849f5b" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "5109ec213a2ac1a1d920f3a9753bed97d038b226775996002511df5dc0b6de9c" + fingerprint = "0f75090ed840f4601df4e43a2f49f2b32585213f3d86d19fb255d79c21086ba3" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $dexor_config_file = { 48 FF C0 8D 51 FF 44 30 00 49 03 C4 49 2B D4 ?? ?? 48 8D 4F 01 48 } - $parse_config = { 80 7C 14 20 3A ?? ?? ?? ?? ?? ?? 45 03 C4 49 03 D4 49 63 C0 48 3B C1 } - $parse_proxy1 = { 44 88 7C 24 31 44 88 7C 24 32 48 F7 D1 C6 44 24 33 70 C6 44 24 34 3D 88 5C 24 35 48 83 F9 01 } - $parse_proxy2 = { 33 C0 48 8D BC 24 F0 00 00 00 49 8B CE F2 AE 8B D3 48 F7 D1 48 83 E9 01 48 8B F9 } + $a = { C6 45 DB FC EB 04 C6 45 DB FE 0F B6 45 DB 88 45 FF 48 8D 75 FF 8B } condition: - 2 of them + all of them } -rule ELASTIC_Windows_Trojan_Darkcloud_9905Abce : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_20F5E74F : FILE MEMORY { meta: - description = "Detects Windows Trojan Darkcloud (Windows.Trojan.DarkCloud)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "9905abce-cbfc-4c92-aef6-38f2099eb5da" - date = "2023-05-03" - modified = "2023-06-13" + id = "20f5e74f-9f94-431b-877c-9b0d78a1d4eb" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_DarkCloud.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "500cb8459c19acd5a1144c4b509c14dbddec74ad623896bfe946fde1cd99a571" - logic_hash = "27d3841d6acf87f5c9c03d643c7859d9eaf42e49ed0241b761f858c669c4e931" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L812-L830" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "9084b00f9bb71524987dc000fb2bc6f38e722e2be2832589ca4bb1671e852f5b" + logic_hash = "067f1c15961c1ddceecb490b338db9f5b8501d89b38e870edfa628d21527dc1c" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "5aeb210b37f4b2b4032917f53f2fb0422132aa1f8cddf0f47bccf50ff68ce00c" + fingerprint = "070fe0d678612b4ec8447a07ead0990a0abd908ce714388720e7fd7055bf1175" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = { 8D 45 DC 57 57 6A 01 6A 11 50 6A 01 68 80 00 00 00 89 7D E8 89 } - $a2 = { C8 33 FF 50 57 FF D6 8D 4D DC 51 57 FF D6 C3 8B 4D F0 8B 45 } + $a = { D8 8B 45 D0 8B 04 D0 8D 50 01 83 EC 0C 8D 85 38 FF FF FF 50 8D 85 40 FF } condition: all of them } -rule ELASTIC_Windows_Vulndriver_Dbutil_Ffe07C79 : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_1B2E2A3A : FILE MEMORY { meta: - description = "Detects Windows Vulndriver Dbutil (Windows.VulnDriver.DBUtil)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "ffe07c79-d97b-43ba-92b9-206bb4c7bdd4" - date = "2022-04-04" - modified = "2022-04-04" + id = "1b2e2a3a-1302-41c7-be99-43edb5563294" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_DBUtil.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "87e38e7aeaaaa96efe1a74f59fca8371de93544b7af22862eb0e574cec49c7c3" - logic_hash = "18b1c93c395b105f446b4c968441e0a43e42b1bd7efcf6501a89eb92cbd21824" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L832-L850" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "899c072730590003b98278bdda21c15ecaa2f49ad51e417ed59e88caf054a72d" + logic_hash = "6f40f868d20f0125721eb2a7934b356d69b695d4a558155a2ddcd0107d3f8c30" score = 75 quality = 75 - tags = "FILE" - fingerprint = "16c22aba1e8c677cc22d3925dd7416a3c55c67271940289936a2cdc199a53798" - severity = 50 + tags = "FILE, MEMORY" + fingerprint = "6f24b67d0a6a4fc4e1cfea5a5414b82af1332a3e6074eb2178aee6b27702b407" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $str1 = "\\DBUtilDrv2_32.pdb" + $a = { 83 7D 18 00 74 25 8B 45 1C 83 E0 02 85 C0 74 1B C7 44 24 04 2D 00 } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1 + all of them } -rule ELASTIC_Windows_Vulndriver_Dbutil_852Ba283 : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_620087B9 : FILE MEMORY { meta: - description = "Detects Windows Vulndriver Dbutil (Windows.VulnDriver.DBUtil)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "852ba283-6a03-44b6-b7e2-b00d1b0586e4" - date = "2022-04-04" - modified = "2022-04-04" + id = "620087b9-c87d-4752-89e8-ca1c16486b28" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_DBUtil.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5" - logic_hash = "78acd081c2517f9c53cb311481c0cc40cc3699b222afc290da1a3698e7bf75b7" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L852-L870" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961" + logic_hash = "411451ea326498a25af8be5cd43fe0b98973af354706268c89828b88ece5e497" score = 75 quality = 75 - tags = "FILE" - fingerprint = "aec919dfea62a8ed01dde4e8c63fbfa9c2a9720c144668460c00f56171c8db25" - severity = 50 + tags = "FILE, MEMORY" + fingerprint = "06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $str1 = "\\DBUtilDrv2_64.pdb" + $a = { 48 89 D8 48 83 C8 01 EB 04 48 8B 76 10 48 3B 46 08 72 F6 48 8B } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1 + all of them } -rule ELASTIC_Linux_Hacktool_Exploitscan_4327F817 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_Dd0D6173 : FILE MEMORY { meta: - description = "Detects Linux Hacktool Exploitscan (Linux.Hacktool.Exploitscan)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "4327f817-cb11-480f-aba7-4d5170c77758" + id = "dd0d6173-b863-45cf-9348-3375a4e624cf" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Hacktool_Exploitscan.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "66c6d0e58916d863a1a973b4f5cb7d691fbd01d26b408dbc8c74f0f1e4088dfb" - logic_hash = "7797d9bd75dff355e1ee84b856e77cf9e886dfe727fb8ce7a6fdbe5ed1eb0985" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L872-L890" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6" + logic_hash = "7061edef1981e2b93bcdd8be47c0f6067acc140a543eed748bf0513f182e0a59" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "3f70c8ef8f20f763dcada4353c254fe1df238829ce590fb87c279d8a892cf9c4" + fingerprint = "5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -59440,132 +63592,114 @@ rule ELASTIC_Linux_Hacktool_Exploitscan_4327F817 : FILE MEMORY os = "linux" strings: - $a = { 24 08 8B 4C 24 0C 85 C0 74 20 8B 58 20 84 03 83 C3 10 8B 68 24 89 9C 24 DC 00 } + $a = { 55 F8 8B 45 F0 89 42 0C 48 8B 55 F8 8B 45 F4 89 42 10 C9 C3 55 48 } condition: all of them } -rule ELASTIC_Windows_Hacktool_Safetykatz_072B7370 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_779E142F : FILE MEMORY { meta: - description = "Detects Windows Hacktool Safetykatz (Windows.Hacktool.SafetyKatz)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "072b7370-517b-45dc-af23-ba3adbd32fbd" - date = "2022-11-20" - modified = "2023-01-11" + id = "779e142f-b867-46e6-b1fb-9105976f42fd" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_SafetyKatz.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "89a456943cf6d2b3cd9cdc44f13a23640575435ed49fa754f7ed358c1a3b6ba9" - logic_hash = "cedd3ede487371a8e0d29804f2b81ae808c7ad01bd803fa39dc2c50e472cff43" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L892-L910" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df" + logic_hash = "80ba5a1cf333fafc6a1d7823ca4a8d5c30c1c07a01d6d681c22dd29e197089f1" score = 75 - quality = 73 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "f0d11341fc91d2c45c07c6079aad24a11da03320286216be0a68461b6bf55b02" + fingerprint = "83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $guid = "8347E81B-89FC-42A9-B22C-F59A6A572DEC" ascii wide nocase - $print_str0 = "[X] Not in high integrity, unable to grab a handle to lsass!" ascii wide fullword - $print_str1 = "[X] Dump directory \"{0}\" doesn't exist!" ascii wide fullword - $print_str2 = "[X] Process is not 64-bit, this version of Mimikatz won't work yo'!" ascii wide fullword - $print_str3 = "[+] Dump successful!" ascii wide fullword + $a = { EC 8B 45 E8 83 E0 02 85 C0 74 07 C7 45 D8 30 00 00 00 8B 45 E8 83 } condition: - $guid or all of ($print_str*) + all of them } -rule ELASTIC_Windows_PUP_Mediaarena_A9E3B4A1 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_Cf84C9F2 : FILE MEMORY { meta: - description = "Detects Windows Pup Mediaarena (Windows.PUP.MediaArena)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "a9e3b4a1-fd87-4f8f-a9d4-d93f9c018270" - date = "2023-06-02" - modified = "2023-06-13" + id = "cf84c9f2-7435-4faf-8c5f-d14945ffad7a" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_PUP_MediaArena.yar#L1-L25" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "c071e0b67e4c105c87b876183900f97a4e8bc1a7c18e61c028dee59ce690b1ac" - logic_hash = "8e52b29f2848498aae2fd7ad35494362d6c07f0e752b628840a256923aca32c7" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L912-L930" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df" + logic_hash = "9af164ece7e7e0f33dc32f18735a8f655593ae6cde34e05108f3221b71aa8676" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "0535228889b1d2a7c317a7ce939621d3d20e2a454ec6d31915c25884931d62b9" + fingerprint = "bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = "Going to change default browser to be MS Edge ..." wide - $a2 = "https://www.searcharchiver.com/eula" wide - $a3 = "Current default browser is unchanged!" wide - $a4 = "You can terminate your use of the Search Technology and Search Technology services" - $a5 = "The software may also offer to change your current web navigation access points" - $a6 = "{{BRAND_NAME}} may have various version compatible with different platform," - $a7 = "{{BRAND_NAME}} is a powerful search tool" wide + $a = { 55 48 89 E5 48 83 EC 30 48 89 7D E8 89 75 E4 89 55 E0 C7 45 F8 01 00 } condition: - 2 of them + all of them } -rule ELASTIC_Windows_Trojan_Falsefont_D1F0D357 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_0Cd591Cd : FILE MEMORY { meta: - description = "Detects Windows Trojan Falsefont (Windows.Trojan.FalseFont)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "d1f0d357-26cb-4dab-8ca6-65f17109982b" - date = "2024-03-26" - modified = "2024-05-08" + id = "0cd591cd-c348-4c3a-a895-2063cf892cda" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_FalseFont.yar#L1-L26" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "364275326bbfc4a3b89233dabdaf3230a3d149ab774678342a40644ad9f8d614" - logic_hash = "af356dec77f773cec01626a3823dbea7e9d3719b9d152ec4057c0b97efabf0df" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L932-L949" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "4300bdd173dfb33ca34c0f2fe4fa6ee071e99d5db201262e914721aad0ad433b" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "ad63447832e9a160d479fccd780de89b9c29b9697f69ac3553e39bc388d49b83" + fingerprint = "96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $s1 = "KillById" - $s2 = "KillByName" - $s3 = "SignalRHub" - $s4 = "ExecUseShell" - $s5 = "ExecAndKeepAlive" - $s6 = "SendAllDirectoryWithStartPath" - $s7 = "AppLiveDirectorySendHard" - $s8 = "AppLiveDirectorySendScreen" + $a = { 4E F8 48 8D 4E D8 49 8D 42 E0 48 83 C7 03 EB 6B 4C 8B 46 F8 48 8D } condition: - 4 of them + all of them } -rule ELASTIC_Linux_Hacktool_Fontonlake_68Ad8568 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_859042A0 : FILE MEMORY { meta: - description = "Detects Linux Hacktool Fontonlake (Linux.Hacktool.Fontonlake)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "68ad8568-2b00-4680-a83f-1689eff6099c" - date = "2021-10-12" - modified = "2022-01-26" + id = "859042a0-a424-4c83-944b-ed182b342998" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Hacktool_Fontonlake.yar#L1-L30" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "717953f52318e7687fc95626561cc607d4875d77ff7e3cf5c7b21cf91f576fa4" - logic_hash = "63dd5769305c715e27e3c62160f7b0f65b57204009ed46383b5b477c67cfac8e" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L951-L969" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0" + logic_hash = "b8daa4a136a6511472703687fe56fbca2bd005a1373802a46c8d211b6d039d75" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "81936e696a525cf02070fa7cfa27574cdad37e1b3d8f278950390a1945c21611" + fingerprint = "a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -59573,103 +63707,85 @@ rule ELASTIC_Linux_Hacktool_Fontonlake_68Ad8568 : FILE MEMORY os = "linux" strings: - $s1 = "run_in_bash" - $s2 = "run_in_ss" - $s3 = "real_bash_fork" - $s4 = "fake_bash_add_history" - $s5 = "hook_bash_add_history" - $s6 = "real_bash_add_history" - $s7 = "real_current_user.5417" - $s8 = "real_bash_execve" - $s9 = "inject_so_symbol.c" - $s10 = "/root/rmgr_ko/subhook-0.5/subhook_x86.c" - $s11 = "|1|%ld|%d|%d|%d|%d|%s|%s" - $s12 = "/proc/.dot3" + $a = { 45 A8 48 83 C0 01 48 89 45 C0 EB 05 48 83 45 C0 01 48 8B 45 C0 0F } condition: - 4 of them + all of them } -rule ELASTIC_Windows_Trojan_Dcrat_1Aeea1Ac : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_33B4111A : FILE MEMORY { meta: - description = "Detects Windows Trojan Dcrat (Windows.Trojan.DCRat)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "1aeea1ac-69b9-4cc6-91af-18b7a79f35ce" - date = "2022-01-15" - modified = "2022-04-12" + id = "33b4111a-e59e-48db-9d74-34ca44fcd9f5" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_DCRat.yar#L1-L24" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "6163e04a40ed52d5e94662131511c3ae08d473719c364e0f7de60dff7fa92cf7" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L971-L989" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961" + logic_hash = "a08c0f7be26e2e9abfaa392712895bb3ce1d12583da4060ebe41e1a9c1491b7c" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "fc67d76dc916b7736de783aa245483381a8fe071c533f3761e550af80a873fe9" + fingerprint = "9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = "havecamera" ascii fullword - $a2 = "timeout 3 > NUL" wide fullword - $a3 = "START \"\" \"" wide fullword - $a4 = "L2Mgc2NodGFza3MgL2NyZWF0ZSAvZiAvc2Mgb25sb2dvbiAvcmwgaGlnaGVzdCAvdG4g" wide fullword - $a5 = "U09GVFdBUkVcTWljcm9zb2Z0XFdpbmRvd3NcQ3VycmVudFZlcnNpb25cUnVuXA==" wide fullword - $b1 = "DcRatByqwqdanchun" ascii fullword - $b2 = "DcRat By qwqdanchun1" ascii fullword + $a = { C1 83 E1 0F 74 1A B8 10 00 00 00 48 29 C8 48 8D 0C 02 48 89 DA 48 } condition: - 5 of ($a*) or 1 of ($b*) + all of them } -rule ELASTIC_Windows_Packer_Scrubcrypt_6A75A4Bb : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_4F43B164 : FILE MEMORY { meta: - description = "Detects Windows Packer Scrubcrypt (Windows.Packer.ScrubCrypt)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "6a75a4bb-8026-4c33-af39-621d76f3baba" - date = "2023-04-18" - modified = "2023-06-13" + id = "4f43b164-686d-4b73-b532-45e2df992b33" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Packer_ScrubCrypt.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "05c1eea2ff8c31aa5baf1dfd8015988f7e737753275ed1c8c29013a3a7414b50" - logic_hash = "edcaa6f1cc85ef084ae5bf2524f39869a90b008dce85e72bca4835565f067ca7" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L991-L1009" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "f0fdb3de75f85e199766bbb39722865cac578cde754afa2d2f065ef028eec788" + logic_hash = "79a17e70e9b7af6e53f62211c33355a4c46a82e7c4e80c20ffe9684e24155808" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "263175cbdc74502a595664833c90bf0a27f2bf20c227775658d552e29d98620e" + fingerprint = "35a885850a06e7991c3a8612bbcdfc279b87e4ca549723192d3011a1e0a81640" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a = { 43 68 65 63 6B 52 65 6D 6F 74 65 44 65 62 75 67 67 65 72 50 72 65 73 65 6E 74 00 49 73 44 65 62 75 67 67 65 72 50 72 65 73 65 6E 74 } - $b = { 53 63 72 75 62 43 72 79 70 74 00 53 74 61 72 74 } + $a = { 46 00 4B 49 4C 4C 53 55 42 00 4B 49 4C 4C 53 55 42 20 3C 73 } condition: all of them } -rule ELASTIC_Linux_Trojan_Sdbot_98628Ea1 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_E4A1982B : FILE MEMORY { meta: - description = "Detects Linux Trojan Sdbot (Linux.Trojan.Sdbot)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "98628ea1-40d8-4a05-835f-a5a5f83637cb" + id = "e4a1982b-928a-4da5-b497-cedc1d26e845" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Sdbot.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "5568ae1f8a1eb879eb4705db5b3820e36c5ecea41eb54a8eef5b742f477cbdd8" - logic_hash = "55b8e3fa755965b85a043015f9303644b8e06fe8bfdc0e2062de75bdc2881541" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1011-L1028" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "4cd7aa205b3571cffca208e315d6311fa92a5993e2a8e40d342d6184811f42f0" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "15cf6b916dd87915738f3aa05a2955c78a357935a183c0f88092d808535625a5" + fingerprint = "d9f852c28433128b0fd330bee35f7bd4aada5226e9ca865fe5cd8cca52b2a622" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -59677,89 +63793,85 @@ rule ELASTIC_Linux_Trojan_Sdbot_98628Ea1 : FILE MEMORY os = "linux" strings: - $a = { 54 00 3C 08 54 00 02 00 26 00 00 40 4D 08 00 5C 00 50 00 49 00 } + $a = { 8B 45 EC F7 D0 21 D0 33 45 FC C9 C3 55 48 89 E5 48 83 EC 30 48 89 } condition: all of them } -rule ELASTIC_Windows_Ransomware_Lockfile_74185716 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_862C4E0E : FILE MEMORY { meta: - description = "Detects Windows Ransomware Lockfile (Windows.Ransomware.Lockfile)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "74185716-e79d-4d63-b6ae-9480f24dcd4f" - date = "2021-08-31" - modified = "2022-01-13" + id = "862c4e0e-83a4-458b-8c00-f2f3cf0bf9db" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Lockfile.yar#L1-L22" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "bf315c9c064b887ee3276e1342d43637d8c0e067260946db45942f39b970d7ce" - logic_hash = "e922c2fc9dd52dd0238847a9d48691bea90d028cf680fc3a1a0dbdfef1d8dce3" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1030-L1048" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1" + logic_hash = "a1dce44e76f9d2a517c4849c58dfecb07e1ef0d78fddff10af601184d636583f" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "849a0fb5a2e08b2d32db839a7fdbde03a184a48726678e65e7f8452b354a3ca8" + fingerprint = "2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = "LOCKFILE-README" - $a2 = "wmic process where \"name like '%virtualbox%'\" call terminate" - $a3 = "" - $a4 = ".lockfile" + $a = { 02 89 45 F8 8B 45 F8 C1 E8 10 85 C0 75 E6 8B 45 F8 F7 D0 0F } condition: all of them } -rule ELASTIC_Windows_Exploit_Dcom_7A1Bcec7 : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_9127F7Be : FILE MEMORY { meta: - description = "Detects Windows Exploit Dcom (Windows.Exploit.Dcom)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "7a1bcec7-e177-4adf-97a7-0d876bf65abc" + id = "9127f7be-6e82-46a1-9f11-0b3570b0cd76" date = "2021-01-12" - modified = "2021-08-23" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Exploit_Dcom.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "84073caf71d0e0523adeb96169c85b8f0bfea09e7ef3bf677bfc19d3b536d8a5" - logic_hash = "484576ab5369f99dc7086d724ead12d464f2bedaf84c93b74e137ddd98600b06" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1050-L1068" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "899c072730590003b98278bdda21c15ecaa2f49ad51e417ed59e88caf054a72d" + logic_hash = "2b1fa115598561e081dfb9b5f24f6728b0d52cb81ac7933728d81646f461bcae" score = 75 - quality = 73 - tags = "FILE" - fingerprint = "0abae84599e490056412d5a5ce1868ea118551243377d59cbb6ebd83701769b8" + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "72c742cb8b11ddf030e10f67e13c0392748dcd970394ec77ace3d2baa705a375" severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a = { 20 62 79 20 46 6C 61 73 68 53 6B 79 20 61 6E 64 20 42 65 6E } + $a = { E4 F7 E1 89 D0 C1 E8 03 89 45 E8 8B 45 E8 01 C0 03 45 E8 C1 } condition: all of them } -rule ELASTIC_Linux_Trojan_Sshdkit_18A0B82A : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_0E03B7D3 : FILE MEMORY { meta: - description = "Detects Linux Trojan Sshdkit (Linux.Trojan.Sshdkit)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "18a0b82a-94ff-4328-bfa7-25034f170522" - date = "2021-04-06" + id = "0e03b7d3-a6b0-46a0-920e-c15ee7e723f7" + date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Sshdkit.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "003245047359e17706e4504f8988905a219fcb48865afea934e6aafa7f97cef6" - logic_hash = "4b7a78ebf3c114809148cc9855379b2e63c959966272ad45759838d570b42016" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1070-L1087" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "845be03fac893f8e914aabda5206000dc07947ade0b8f46cc5d58d8458f035f6" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "9bd28a490607b75848611389b39cf77229cfdd1e885f23c5439d49773924ce16" + fingerprint = "1bf1f271005328669b3eb4940e2b75eff9fc47208d79a12196fd7ce04bc4dbe8" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -59767,61 +63879,56 @@ rule ELASTIC_Linux_Trojan_Sshdkit_18A0B82A : FILE MEMORY os = "linux" strings: - $a = { 06 2A CA 37 F2 31 18 0E 2F 47 CD 87 9D 16 3F 6D } + $a = { F5 74 84 32 63 29 5A B2 78 FF F7 FA 0E 51 B3 2F CD 7F 10 FA } condition: all of them } -rule ELASTIC_Windows_Hacktool_Sharphound_5Adf9D6D : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_32Eb0C81 : FILE MEMORY { meta: - description = "Detects Windows Hacktool Sharphound (Windows.Hacktool.SharpHound)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "5adf9d6d-b6db-43ea-95bd-e9747b82a36d" - date = "2022-10-20" - modified = "2022-11-24" + id = "32eb0c81-25af-4670-ab77-07ea7ce1874a" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_SharpHound.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "1f74ed6e61880d19e53cde5b0d67a0507bfda0be661860300dcb0f20ea9a45f4" - logic_hash = "2c9f38187866985109a42ffdf8940b5d195aadd3815b2de952b190d4b0b95c3c" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1089-L1107" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df" + logic_hash = "a06d9e1190ba79b0e19cab7468f01a49359629a6feb27b7d72f3d1d52d1483d7" score = 75 - quality = 71 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "53d295223e2330a973f9495a7ca625c1e9429bc5daf7dda1b84b2aaeca5ea898" + fingerprint = "7c50ed29e2dd75a6a85afc43f8452794cb787ecd2061f4bf415d7038c14c523f" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $guid0 = "A517A8DE-5834-411D-ABDA-2D0E1766539C" ascii wide nocase - $guid1 = "90A6822C-4336-433D-923F-F54CE66BA98F" ascii wide nocase - $print_str0 = "Initializing SharpHound at {time} on {date}" ascii wide - $print_str1 = "SharpHound completed {Number} loops! Zip file written to {Filename}" ascii wide - $print_str2 = "[-] Removed DCOM Collection" ascii wide + $a = { D4 48 FF 45 F0 48 8B 45 F0 0F B6 00 84 C0 75 DB EB 12 48 8B } condition: - $guid0 or $guid1 or all of ($print_str*) + all of them } -rule ELASTIC_Linux_Cryptominer_Bscope_348B7Fa0 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_9Abf7E0C : FILE MEMORY { meta: - description = "Detects Linux Cryptominer Bscope (Linux.Cryptominer.Bscope)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "348b7fa0-e226-4350-8697-345ae39fa0f6" + id = "9abf7e0c-5076-4881-a488-f0f62810f843" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Cryptominer_Bscope.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "a6fb80d77986e00a6b861585bd4e573a927e970fb0061bf5516f83400ad7c0db" - logic_hash = "bc6a59dcc36676273c61fa71231fd8709884beebb7ab64b58f22551393b20c71" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1109-L1126" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "00276330e388d07368577c4134343cb9fc11957dba6cff5523331199f1ed04aa" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "caae9d3938f9269f8bc30e4837021513ca6e4e2edd1117d235b0d25474df5357" + fingerprint = "7d02513aaef250091a58db58435a1381974e55c2ed695c194b6b7b83c235f848" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -59829,57 +63936,56 @@ rule ELASTIC_Linux_Cryptominer_Bscope_348B7Fa0 : FILE MEMORY os = "linux" strings: - $a = { 04 8B 00 03 45 C0 89 02 8B 45 08 8D 50 08 8B 45 08 83 C0 08 } + $a = { 55 E0 0F B6 42 0D 83 C8 01 88 42 0D 48 8B 55 E0 0F B6 42 0D 83 } condition: all of them } -rule ELASTIC_Windows_Vulndriver_Eneio_6E01882F : FILE +rule ELASTIC_Linux_Trojan_Gafgyt_33801844 : FILE MEMORY { meta: - description = "Detects Windows Vulndriver Eneio (Windows.VulnDriver.EneIo)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "6e01882f-8394-4e32-8049-fa9c4588b087" - date = "2022-04-04" - modified = "2022-04-04" + id = "33801844-50b1-4968-a1b7-d106f16519ee" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_EneIo.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "175eed7a4c6de9c3156c7ae16ae85c554959ec350f1c8aaa6dfe8c7e99de3347" - logic_hash = "144ac5375cb637b6301a2275f2412fbd0d0c5fb23105c7cce5aa7912cf68fa2c" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1128-L1146" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "2ceff60e88c30c02c1c7b12a224aba1895669aad7316a40b575579275b3edbb3" + logic_hash = "20b8ebce14776e48310be099afd0dca0f28778d0024318b339b75e2689f70128" score = 75 quality = 75 - tags = "FILE" - fingerprint = "8077212bfbadc7f47f2eb76f123a6e4bcda12009293cb975bbeaba77f8c9dcd0" - severity = 50 + tags = "FILE, MEMORY" + fingerprint = "36218345b9ce4aaf50b5df1642c00ac5caa744069e952eb6008a9a57a37dbbdc" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $str1 = "\\Release\\EneIo.pdb" + $a = { 45 F8 48 83 E8 01 0F B6 00 3C 0D 75 0B 48 8B 45 F8 0F B6 00 } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1 + all of them } -rule ELASTIC_Linux_Exploit_Vmsplice_Cfa94001 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_A33A8363 : FILE MEMORY { meta: - description = "Detects Linux Exploit Vmsplice (Linux.Exploit.Vmsplice)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "cfa94001-6000-4633-9af2-efabfaa96f94" + id = "a33a8363-5511-4fe1-a0d8-75156b9ccfc7" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Vmsplice.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0a26e67692605253819c489cd4793a57e86089d50150124394c30a8801bf33e6" - logic_hash = "b5a86a79384997f977d353371ccaa8c736f5c24af40b85a24076d4c4fb79a237" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1148-L1165" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "3fe17dc43f07dacdad6ababf141983854b977e244c0af824fea0ab953ad70fee" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "3fb484112484e2afc04a88d50326312af950605c61f258651479427b7bae300a" + fingerprint = "74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -59887,28 +63993,28 @@ rule ELASTIC_Linux_Exploit_Vmsplice_Cfa94001 : FILE MEMORY os = "linux" strings: - $a = { 7A 00 21 40 23 24 00 6D 6D 61 70 00 5B 2B 5D 20 6D 6D 61 70 3A } + $a = { 41 88 02 48 85 D2 75 ED 5A 5B 5D 41 5C 41 5D 4C 89 F0 41 5E } condition: all of them } -rule ELASTIC_Linux_Exploit_Vmsplice_A000F267 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_9A62845F : FILE MEMORY { meta: - description = "Detects Linux Exploit Vmsplice (Linux.Exploit.Vmsplice)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "a000f267-b4d7-46e9-ab61-818633083ba2" + id = "9a62845f-6311-49ae-beac-f446b2909d9c" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Vmsplice.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "c85cc6768a28fb7de16f1cad8d3c69d8f0b4aa01e00c8e48759d27092747ca6f" - logic_hash = "2a8cb11bb21f2ce620a6fa1f0fb932bef60a479fac836058ec4e8c760b5d60f9" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1167-L1185" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "f67f8566beab9d7494350923aceb0e76cd28173bdf2c4256e9d45eff7fc8cb41" + logic_hash = "b3ab125c8bfb5b7a0be0e92cf5a50057e403ab3597698ec2e7a8bafa0d3a8b80" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "0753ef1bc3e151fd6d4773967b5cde6ad789df593e7d8b9ed08052151a1a1849" + fingerprint = "2ccc813c5efed35308eb2422239b5b83d051eca64b7c785e66d602b13f8bd9b4" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -59916,28 +64022,28 @@ rule ELASTIC_Linux_Exploit_Vmsplice_A000F267 : FILE MEMORY os = "linux" strings: - $a = { 24 04 73 00 00 00 89 44 24 00 CF 83 C4 10 5B C9 C3 55 89 E5 83 } + $a = { 10 83 F8 20 7F 1E 83 7D 08 07 75 33 8B 45 0C 83 C0 18 8B 00 83 } condition: all of them } -rule ELASTIC_Linux_Exploit_Vmsplice_8B9E4F9F : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_4D81Ad42 : FILE MEMORY { meta: - description = "Detects Linux Exploit Vmsplice (Linux.Exploit.Vmsplice)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "8b9e4f9f-7903-4aa5-9098-766f4311a22b" + id = "4d81ad42-bf08-48a9-9a93-85cb491257b3" date = "2021-04-06" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Vmsplice.yar#L41-L59" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0230c81ba747e588cd9b6113df6e1867dcabf9d8ada0c1921d1bffa9c1b9c75d" - logic_hash = "6979a900a2532a8da36711f3ffe13f71ec4efa7771aa2feec9391bd031aaa023" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1187-L1205" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "3021a861e6f03df3e7e3919e6255bdae6e48163b9a8ba4f1a5c5dced3e3e368b" + logic_hash = "57b54eed37690949ba2d4eff713691f16f00207d7b374beb7dfa2e368588dbb0" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "585b16ad3e4489a17610f0a226be428def33e411886f273d0c1db45b3819ba3f" + fingerprint = "f285683c3b145990e1b6d31d3c9d09177ebf76f183d0fa336e8df3dbcba24366" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -59945,28 +64051,27 @@ rule ELASTIC_Linux_Exploit_Vmsplice_8B9E4F9F : FILE MEMORY os = "linux" strings: - $a = { 00 00 00 00 20 4C 69 6E 75 78 20 76 6D 73 70 6C } + $a = { 0F 44 C8 07 0B BF F1 1B 7E 83 CD FF 31 DB 2E 22 } condition: all of them } -rule ELASTIC_Linux_Exploit_Vmsplice_055F88B8 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_6A510422 : FILE MEMORY { meta: - description = "Detects Linux Exploit Vmsplice (Linux.Exploit.Vmsplice)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "055f88b8-b1b0-4b02-8fc5-97804b564d27" - date = "2021-04-06" + id = "6a510422-3662-4fdb-9c03-0101f16e87cd" + date = "2021-06-28" modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Vmsplice.yar#L61-L79" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "607c8c5edc8cbbd79a40ce4a0eccf46e01447985d9415d1eff6a91bf64074507" - logic_hash = "29e59bb372f0b37b507c72e5b5bcb27ba0fa2aaac71ea77f0cab85af31708c8a" + reference = "14cc92b99daa0c91aa09d9a7996ee5549a5cacd7be733960b2cf3681a7c2b628" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1207-L1225" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "4384536817bf5df223d4cf145892b7714f2dbd1748930b6cd43152d4e35c9e56" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "38f7d6c56ee1cd465062b5c82320710c4d0393a3b33f5586b6c0c0c778e5d3b2" + fingerprint = "8ee116ff41236771cdc8dc4b796c3b211502413ae631d5b5aedbbaa2eccc3b75" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -59974,89 +64079,83 @@ rule ELASTIC_Linux_Exploit_Vmsplice_055F88B8 : FILE MEMORY os = "linux" strings: - $a = { 2D 2D 2D 00 20 4C 69 6E 75 78 20 76 6D 73 70 6C } + $a = { 0B E5 24 30 1B E5 2C 30 0B E5 1C 00 00 EA 18 30 1B E5 00 30 } condition: all of them } -rule ELASTIC_Linux_Exploit_Vmsplice_431E689D : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_D2953F92 : FILE MEMORY { meta: - description = "Detects Linux Exploit Vmsplice (Linux.Exploit.Vmsplice)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "431e689d-0c41-4c92-98b0-0dac529d8328" + id = "d2953f92-62ee-428d-88c5-723914c88c6e" date = "2021-06-28" modified = "2021-09-16" - reference = "1cbb09223f16af4cd13545d72dbeeb996900535b1e279e4bcf447670728de1e1" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Vmsplice.yar#L81-L99" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "5b9a7ffcd6fc6893a8224fd2b9ca59f4cff6086669a73190114db510a1ad9ff2" + reference = "14cc92b99daa0c91aa09d9a7996ee5549a5cacd7be733960b2cf3681a7c2b628" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1227-L1245" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "d0af462d26f6ffe469c57d63f1f7d551e3fb9cc39c7e4c35b3e71f659c01c076" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "1e8aee445a3adef6ccbd2d25f7b38202bef98a99b828eda56fb8b9269b6316b4" - severity = "100" + fingerprint = "276c6d62a8a335d0e2421b6b5b90c2c0eb69eec294bc9fcdeb7743abbf08d8bc" + severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" os = "linux" strings: - $a = { 69 6F 6E 00 70 75 74 65 6E 76 00 73 74 64 6F 75 74 00 73 65 } + $a = { 1B E5 2A 00 53 E3 0A 00 00 0A 30 30 1B E5 3F 00 53 E3 23 00 } condition: all of them } -rule ELASTIC_Windows_Trojan_Whispergate_9192618B : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_6Ae4B580 : FILE MEMORY { meta: - description = "Detects Windows Trojan Whispergate (Windows.Trojan.WhisperGate)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "9192618b-4f3e-4503-a97f-3c4420fb79e0" - date = "2022-01-17" - modified = "2022-01-17" - reference = "https://www.elastic.co/security-labs/operation-bleeding-bear" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_WhisperGate.yar#L1-L24" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "dcbbae5a1c61dbbbb7dcd6dc5dd1eb1169f5329958d38b58c3fd9384081c9b78" - logic_hash = "28bb08d61d99d2bfc49ba18cdbabc34c31a715ae6439ab25bbce8cc6958ed381" + id = "6ae4b580-f7cf-4318-b584-7ea15f10f5ea" + date = "2021-06-28" + modified = "2021-09-16" + reference = "14cc92b99daa0c91aa09d9a7996ee5549a5cacd7be733960b2cf3681a7c2b628" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1247-L1265" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "eb0fe44df1c995c5d4e3a361c3e466f78cb70bffbc76d1b7b345ee651b313b9e" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "21f2a5b730a86567e68491a0d997fc52ba37f28b2164747240a74c225be3c661" + fingerprint = "279e344d6da518980631e70d7b1ded4ff1b034d24e4b4fe01b36ed62f5c1176c" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = "https://cdn.discordapp.com/attachments/" wide - $a2 = "DxownxloxadDxatxxax" wide fullword - $a3 = "powershell" wide fullword - $a4 = "-enc UwB0AGEAcgB0AC" wide fullword - $a5 = "Ylfwdwgmpilzyaph" wide fullword + $a = { 30 0B E5 3C 20 1B E5 6C 32 1B E5 03 00 52 E1 01 00 00 DA 6C } condition: all of them } -rule ELASTIC_Linux_Trojan_Dropperl_B97Baf37 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_D608Cf3B : FILE MEMORY { meta: - description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "b97baf37-48db-4eb7-85c7-08e75054bea7" - date = "2021-01-12" + id = "d608cf3b-c255-4a8d-9bf1-66f92eacd751" + date = "2021-06-28" modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Dropperl.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "aff94f915fc81d5a2649ebd7c21ec8a4c2fc0d622ec9b790b43cc49f7feb83da" - logic_hash = "e58130c33242bc3020602c2c0254bed2bbc564c4a11806c6cfcd858fd724c362" + reference = "14cc92b99daa0c91aa09d9a7996ee5549a5cacd7be733960b2cf3681a7c2b628" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1267-L1285" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "ad5b7d32c85adc7f778a8f4815e595b90a6f15dec048bcf97c6ab179582eb4f7" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "0852f1afa6162d14b076a3fc1f56e4d365b5d0e8932bae6ab055000cca7d1fba" + fingerprint = "3825aa1c9cddb46fdef6abc0503b42acbca8744dd89b981a3eea8db2f86a8a76" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60064,28 +64163,27 @@ rule ELASTIC_Linux_Trojan_Dropperl_B97Baf37 : FILE MEMORY os = "linux" strings: - $a = { 12 48 89 10 83 45 DC 01 83 45 D8 01 8B 45 D8 3B 45 BC 7C CF 8B } + $a = { FF 2F E1 7E 03 00 00 78 D8 00 00 24 00 00 00 28 00 00 00 4C } condition: all of them } -rule ELASTIC_Linux_Trojan_Dropperl_E2443Be5 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_3F8Cf56E : FILE MEMORY { meta: - description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "e2443be5-da15-4af2-b090-bf5accf2a844" - date = "2021-01-12" + id = "3f8cf56e-a8cb-4c03-8829-f1daa3dc64a8" + date = "2021-06-28" modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Dropperl.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "aff94f915fc81d5a2649ebd7c21ec8a4c2fc0d622ec9b790b43cc49f7feb83da" - logic_hash = "85733ff904cfa3eddaa4c4fbfc51c00494c3a3725e2eb722bbf33c82e7135336" + reference = "1878f0783085cc6beb2b81cfda304ec983374264ce54b6b98a51c09aea9f750d" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1287-L1305" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "b2cf8b1913a88e6a6346f0ac8cd2e7c33b41d44bf60ff7327ae40a2d54748bd9" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "e49acaa476bd669b40ccc82a7d3a01e9c421e6709ecbfe8d0e24219677c96339" + fingerprint = "77306f0610515434371f70f2b42c895cdc5bbae2ef6919cf835b3cfe2e4e4976" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60093,28 +64191,27 @@ rule ELASTIC_Linux_Trojan_Dropperl_E2443Be5 : FILE MEMORY os = "linux" strings: - $a = { 45 F0 75 DB EB 17 48 8B 45 F8 48 83 C0 08 48 8B 10 48 8B 45 F8 48 } + $a = { 45 2F DA E8 E9 CC E4 F4 39 55 E2 9E 33 0E C0 F0 FB 26 93 31 } condition: all of them } -rule ELASTIC_Linux_Trojan_Dropperl_683C2Ba1 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_Fb14E81F : FILE MEMORY { meta: - description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "683c2ba1-fe4a-44e4-b176-8d5d5788e1a4" - date = "2021-04-06" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Dropperl.yar#L41-L59" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "a02e166fbf002dd4217c012f24bb3a8dbe310a9f0b0635eb20a7d315049367e1" - logic_hash = "eef2bdef7e20633f7dc92f653b43e3a217e8cbdbac63d05540bdd520e22dd1ed" + id = "fb14e81f-be2a-4428-9877-958e394a7ae2" + date = "2022-01-05" + modified = "2022-01-26" + reference = "0fd07e6068a721774716eb4940e2c19faef02d5bdacf3b018bf5995fa98a3a27" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1307-L1325" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "2efb958c269640c374485502611372f4404cf35d7ab704d20ce37b8c1f69645d" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "42dcea472417140d0f7768e8189ac3a8a46aaeff039be1efd36f8d50f81e347c" + fingerprint = "12b430108256bd0f57f48b9dbbea12eba7405c0b3b66a1c4b882647051f1ec52" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60122,28 +64219,27 @@ rule ELASTIC_Linux_Trojan_Dropperl_683C2Ba1 : FILE MEMORY os = "linux" strings: - $a = { E8 95 FB FF FF 83 7D D4 00 79 0A B8 ?? ?? 60 00 } + $a = { 4E 45 52 00 53 43 41 4E 4E 45 52 20 4F 4E 20 7C 20 4F 46 46 00 } condition: all of them } -rule ELASTIC_Linux_Trojan_Dropperl_8Bca73F6 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_E09726Dc : FILE MEMORY { meta: - description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "8bca73f6-c3ec-45a3-a5ae-67c871aaf9df" - date = "2021-04-06" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Dropperl.yar#L61-L79" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "e7c17b7916b38494b9a07c249acb99499808959ba67125c29afec194ca4ae36c" - logic_hash = "2cfad4e436198391185fdae5c4af18ae43841db19da33473fdf18b64b0399613" + id = "e09726dc-4e6d-4115-b178-d20375c09e04" + date = "2022-01-05" + modified = "2022-01-26" + reference = "1e64187b5e3b5fe71d34ea555ff31961404adad83f8e0bd1ce0aad056a878d73" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1327-L1345" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "ebd00e593a7fcd46e36fd0ca213e1f82c0f4a94448b6fd605d35cea45a490493" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "36df2fd9746da80697ef675f84f47efb3cb90e9757677e4f565a7576966eb169" + fingerprint = "614d54b3346835cd5c2a36a54cae917299b1a1ae0d057e3fa1bb7dddefc1490f" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60151,28 +64247,27 @@ rule ELASTIC_Linux_Trojan_Dropperl_8Bca73F6 : FILE MEMORY os = "linux" strings: - $a = { E8 95 FB FF FF 83 7D D4 00 79 0A B8 ?? ?? 62 00 } + $a = { 00 00 48 83 EC 08 48 83 C4 08 C3 00 00 00 01 00 02 00 50 49 4E 47 } condition: all of them } -rule ELASTIC_Linux_Trojan_Dropperl_C4018572 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_Ad12B9B6 : FILE MEMORY { meta: - description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "c4018572-a8af-4204-bc19-284a2a27dfdd" - date = "2021-04-06" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Dropperl.yar#L81-L99" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "c1515b3a7a91650948af7577b613ee019166f116729b7ff6309b218047141f6d" - logic_hash = "10d70540532c5c2984dc7e492672450924cb8f34c8158638191886057596b0a1" + id = "ad12b9b6-2e66-4647-8bf3-0300f2124a97" + date = "2022-01-05" + modified = "2022-01-26" + reference = "f0411131acfddb40ac8069164ce2808e9c8928709898d3fb5dc88036003fe9c8" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1347-L1365" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "72a85d14eb8ab78364ea2e8b89d9409c0046b14602f4a3415d829f4985fb2de3" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "f2ede50ea639af593211c9ef03ee2847a32cf3eb155db4e2ca302f3508bf2a45" + fingerprint = "46d86406f7fb25f0e240abc13e86291c56eb7468d0128fdff181f28d4f978058" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60180,28 +64275,28 @@ rule ELASTIC_Linux_Trojan_Dropperl_C4018572 : FILE MEMORY os = "linux" strings: - $a = { E8 97 FB FF FF 83 7D D4 00 79 0A B8 ?? ?? 60 00 } + $a = { 4C 52 46 00 4B 45 46 31 4A 43 53 00 4B 45 46 31 51 45 42 00 } condition: all of them } -rule ELASTIC_Linux_Trojan_Dropperl_733C0330 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_0535Ebf7 : FILE MEMORY { meta: - description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "733c0330-3163-48f3-a780-49be80a3387f" - date = "2021-04-06" - modified = "2021-09-16" + id = "0535ebf7-844f-4207-82ef-e155ceff7a3e" + date = "2022-09-12" + modified = "2022-10-18" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Dropperl.yar#L101-L119" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "b303f241a2687dba8d7b4987b7a46b5569bd2272e2da3e0c5e597b342d4561b6" - logic_hash = "37bf7777e26e556f09b8cb0e7e3c8425226a6412c3bed0d95fdab7229b6f4815" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1367-L1385" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "77e18bb5479b644ba01d074057c9e2bd532717f6ab3bb88ad2b7497b85d2a5de" + logic_hash = "eb574468e9d371def0da74e6aba827272181399a84388a14ffb167ec6ebd40d1" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "ee233c875dd3879b4973953a1f2074cd77abf86382019eeb72da069e1fd03e1c" + fingerprint = "2b9b17dad296c0a58a7efa1fb3f71c62bf849f00deb978c1103ab8a480290024" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60209,28 +64304,28 @@ rule ELASTIC_Linux_Trojan_Dropperl_733C0330 : FILE MEMORY os = "linux" strings: - $a = { E8 A0 FB FF FF 83 7D DC 00 79 0A B8 ?? ?? 60 00 } + $a = { F8 48 8B 04 24 6A 18 48 F7 14 24 48 FF 04 24 48 03 24 24 48 8D 64 } condition: all of them } -rule ELASTIC_Linux_Trojan_Dropperl_39F4Cd0D : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_32A7Edd2 : FILE MEMORY { meta: - description = "Detects Linux Trojan Dropperl (Linux.Trojan.Dropperl)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "39f4cd0d-4261-4d62-a527-f403edadbd0c" - date = "2021-04-06" - modified = "2021-09-16" + id = "32a7edd2-175f-45b3-bf3d-8c842e4ae7e7" + date = "2022-09-12" + modified = "2022-10-18" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Dropperl.yar#L121-L139" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "c08e1347877dc77ad73c1e017f928c69c8c78a0e3c16ac5455668d2ad22500f3" - logic_hash = "5b61f54604b110d2c8efaf1782a2e520baac96c6d3e8d1eda0877475c504bf89" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1387-L1405" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "79a75c8aa5aa0d1edef5965e1bcf8ba2f2a004a77833a74870b8377d7fde89cf" + logic_hash = "af26549c1cad0975735e2c233bc71e5e1b0e283d02552fdaea02656332ecd854" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "e1cdd678a1f46a3c6d26d53dd96ba6c6a45f97e743765c534f644af7c6450f8e" + fingerprint = "d59183e8833272440a12b96de82866171f7ea0212cee0e2629c169fdde4da2a5" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60238,27 +64333,28 @@ rule ELASTIC_Linux_Trojan_Dropperl_39F4Cd0D : FILE MEMORY os = "linux" strings: - $a = { E8 ?? FA FF FF 83 7D D4 00 79 0A B8 ?? ?? 60 00 } + $a = { 75 FD 48 FD 45 FD 0F FD 00 FD FD 0F FD FD 02 00 00 48 FD 45 } condition: all of them } -rule ELASTIC_Linux_Trojan_Meterpreter_A82F5D21 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_D7F35B54 : FILE MEMORY { meta: - description = "Detects Linux Trojan Meterpreter (Linux.Trojan.Meterpreter)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "a82f5d21-3b01-4a05-a34a-6985c1f3b460" - date = "2021-01-12" - modified = "2021-09-16" + id = "d7f35b54-82a8-4ef0-8c8c-30a6734223e1" + date = "2022-09-12" + modified = "2022-10-18" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Meterpreter.yar#L1-L18" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "d76886222de7292e8a76717f6d49452f52aaffb957bb0326bcfc7a35c3fdfc6a" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1407-L1425" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "79a75c8aa5aa0d1edef5965e1bcf8ba2f2a004a77833a74870b8377d7fde89cf" + logic_hash = "d827e21c09b8dce65db293aa57b39f49f034537bb708471989ad64e653c479be" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "b0adb928731dc489a615fa86e46cc19de05e251eef2e02eb02f478ed1ca01ec5" + fingerprint = "d01db0f6a169d82d921c76801738108a2f0ef4ef65ea2e104fb80188a3bb73b8" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60266,28 +64362,28 @@ rule ELASTIC_Linux_Trojan_Meterpreter_A82F5D21 : FILE MEMORY os = "linux" strings: - $a = { F8 02 74 22 77 08 66 83 F8 01 74 20 EB 24 66 83 F8 03 74 0C 66 83 } + $a = { FD 48 FD 45 FD 48 FD FD FD FD FD FD FD FD FD 48 FD 45 FD 66 } condition: all of them } -rule ELASTIC_Linux_Trojan_Meterpreter_383C6708 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_F11E98Be : FILE MEMORY { meta: - description = "Detects Linux Trojan Meterpreter (Linux.Trojan.Meterpreter)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "383c6708-0861-4089-93c3-4320bc1e7cfc" - date = "2021-01-12" - modified = "2021-09-16" + id = "f11e98be-bf81-480e-b2d1-dcc748c6869d" + date = "2022-09-12" + modified = "2022-10-18" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Meterpreter.yar#L20-L38" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "d9d607f0bbc101f7f6dc0f16328bdd8f6ddb8ae83107b7eee34e1cc02072cb15" - logic_hash = "b0fd479722ab0808a4709cbacbb874282c48a425f4dbdaec9f74bc7f839c82e4" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1427-L1445" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "79a75c8aa5aa0d1edef5965e1bcf8ba2f2a004a77833a74870b8377d7fde89cf" + logic_hash = "9b9122f0897610dff6b37446b3cecbfcec3dce8dc7e1934e78cc32d5f6ac9648" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "6e9da04c91b5846b3b1109f9d907d9afa917fb7dfe9f77780e745d17b799b540" + fingerprint = "8cdf2acffd0cdce48ceaffa6682d2f505c557b873e4f418f4712dfa281a3095a" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60295,27 +64391,28 @@ rule ELASTIC_Linux_Trojan_Meterpreter_383C6708 : FILE MEMORY os = "linux" strings: - $a = { 99 B6 10 48 89 D6 4D 31 C9 6A 22 41 5A B2 07 0F 05 48 96 48 } + $a = { FD 40 00 09 FD 21 FD FD 08 48 FD 80 3E 00 75 FD FD 4C 24 48 0F FD } condition: all of them } -rule ELASTIC_Linux_Trojan_Meterpreter_621054Fe : FILE MEMORY +rule ELASTIC_Linux_Trojan_Gafgyt_8D4E4F4A : FILE MEMORY { meta: - description = "Detects Linux Trojan Meterpreter (Linux.Trojan.Meterpreter)" + description = "Detects Linux Trojan Gafgyt (Linux.Trojan.Gafgyt)" author = "Elastic Security" - id = "621054fe-bbdf-445c-a503-ccba82b88243" - date = "2021-01-12" - modified = "2021-09-16" + id = "8d4e4f4a-b3ea-4f93-ada2-2c88bb5d806d" + date = "2022-09-12" + modified = "2022-10-18" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Meterpreter.yar#L40-L57" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "18f22bb0aa66ec2ecdaa9ca0e0d00ee59a2c9a3f231bd71915140e4464a4ea78" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Gafgyt.yar#L1447-L1465" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "79a75c8aa5aa0d1edef5965e1bcf8ba2f2a004a77833a74870b8377d7fde89cf" + logic_hash = "11ee101a936f8e6949701e840ef48a0fe102099ea3b71c790b9a5128e5c59029" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "13cb03783b1d5f14cadfaa9b938646d5edb30ea83702991a81cc4ca82e4637dc" + fingerprint = "9601c7cf7f2b234bc30d00e1fc0217b5fa615c369e790f5ff9ca42bcd85aea12" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60323,27 +64420,28 @@ rule ELASTIC_Linux_Trojan_Meterpreter_621054Fe : FILE MEMORY os = "linux" strings: - $a = { 28 85 D2 75 0A 8B 50 2C 83 C8 FF 85 D2 74 03 8B 42 64 5D C3 55 } + $a = { 50 00 FD FD 00 00 00 31 FD 48 FD FD 01 00 00 00 49 FD FD 04 } condition: all of them } -rule ELASTIC_Linux_Trojan_Meterpreter_1Bda891E : FILE MEMORY +rule ELASTIC_Linux_Trojan_Mumblehard_523450Aa : FILE MEMORY { meta: - description = "Detects Linux Trojan Meterpreter (Linux.Trojan.Meterpreter)" + description = "Detects Linux Trojan Mumblehard (Linux.Trojan.Mumblehard)" author = "Elastic Security" - id = "1bda891e-a031-4254-9d0b-dc590023d436" - date = "2021-12-13" - modified = "2022-01-26" + id = "523450aa-6bb4-4863-9656-81a6e6cb7d88" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Meterpreter.yar#L59-L76" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "74e7547472117de20159f5b158cee0ccacc02a9aba5e5ad64a52c552c966d539" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mumblehard.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "a637ea8f070e1edf2c9c81450e83934c177696171b24b4dff32dfb23cefa56d3" + logic_hash = "60b4cc388975ce030e03c5c3a48adcfeec25299105206909163f20100fbf45d8" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "fc3f5afb9b90bbf3b61f144f90b02ff712f60fbf62fb0c79c5eaa808627aa0a1" + fingerprint = "783f07e4f4625c061309af2d89e9ece0ba4a8ce21a7d93ce19cd32bcd6ad38e9" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60351,210 +64449,318 @@ rule ELASTIC_Linux_Trojan_Meterpreter_1Bda891E : FILE MEMORY os = "linux" strings: - $a = { 11 62 08 F2 0F 5E D0 F2 0F 58 CB F2 0F 11 5A 10 F2 44 0F 5E C0 F2 0F } + $a = { 09 75 05 89 03 89 53 04 B8 02 00 00 00 50 80 F9 09 75 0B CD 80 } condition: all of them } -rule ELASTIC_Windows_Trojan_Guloader_8F10Fa66 : FILE MEMORY +rule ELASTIC_Windows_Vulndriver_Sandra_5D112Feb : FILE { meta: - description = "Detects Windows Trojan Guloader (Windows.Trojan.Guloader)" + description = "Name: SANDRA, Version: 10.12.0.0" author = "Elastic Security" - id = "8f10fa66-a24b-4cc2-b9e0-11be14aba9af" - date = "2021-08-17" - modified = "2021-10-04" - reference = "https://www.elastic.co/security-labs/getting-gooey-with-guloader-downloader" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Guloader.yar#L1-L24" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "a3e2d5013b80cd2346e37460753eca4a4fec3a7941586cc26e049a463277562e" - logic_hash = "f2cd08f6a32c075dc0294a0e26c51e686babc54ced4faa1873368c8821f0bfef" + id = "5d112feb-dc0a-464c-9753-695bb510f5a8" + date = "2022-04-07" + modified = "2022-04-07" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Sandra.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "3a364a7a3f6c0f2f925a060e84fb18b16c118125165b5ea6c94363221dc1b6de" + logic_hash = "d234a1e74234400f51c2aa7a9fb1549be1bc422bdf585db7d2ec9ad1ec75e490" + score = 75 + quality = 75 + tags = "FILE" + fingerprint = "13572e1155a5417549508952504b891f0e4f40cb6ff911bdda6f152c051c401c" + threat_name = "Windows.VulnDriver.Sandra" + severity = 50 + arch_context = "x86" + scan_context = "file" + license = "Elastic License v2" + os = "windows" + + strings: + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 53 00 41 00 4E 00 44 00 52 00 41 00 00 00 } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x0c][\x00-\x00])([\x00-\x0a][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x09][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x0b][\x00-\x00])([\x00-\x0a][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ + + condition: + int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version +} +rule ELASTIC_Windows_Vulndriver_Sandra_612A7A16 : FILE +{ + meta: + description = "Name: sandra.sys, Version: 10.12.0.0" + author = "Elastic Security" + id = "612a7a16-b616-4a70-9994-cb5aebfa0ca9" + date = "2022-04-07" + modified = "2022-04-07" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Sandra.yar#L23-L42" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "8fda0e1775d903b73836d4103f6e8b0e2f052026b3acdb07bd345b9ddb3c873a" + score = 75 + quality = 75 + tags = "FILE" + fingerprint = "ead3bd8256fbb5d26c4a177298a5cdd14e5eeb73d9336999c0a68ece9efa2d55" + threat_name = "Windows.VulnDriver.Sandra" + severity = 50 + arch_context = "x86" + scan_context = "file" + license = "Elastic License v2" + os = "windows" + + strings: + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 73 00 61 00 6E 00 64 00 72 00 61 00 2E 00 73 00 79 00 73 00 00 00 } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x0c][\x00-\x00])([\x00-\x0a][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x09][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x0b][\x00-\x00])([\x00-\x0a][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ + + condition: + int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version +} +rule ELASTIC_Windows_Vulndriver_Fiddrv_E7875A5A : FILE +{ + meta: + description = "Detects Intel's R/W MSR driver (fiddrv64.sys)" + author = "Elastic Security" + id = "e7875a5a-5a88-4bc3-9cfc-91b446dcc6aa" + date = "2023-07-25" + modified = "2023-07-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Vulndriver_FidDrv.yar#L1-L23" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "4bf4cced4209c73aa37a9e2bf9ff27d458d8d7201eefa6f6ad4849ee276ad158" + logic_hash = "aa1635c651c8364ad2ee93b369dd583fce699001d753e46de013c476d185eef1" + score = 75 + quality = 75 + tags = "FILE" + fingerprint = "ed9ef63a9e2434a30f22f679edb99b9104eb4397968d84599c7828102312025e" + threat_name = "Windows.VulnDriver.FidDrv" + severity = 50 + arch_context = "x86" + scan_context = "file" + license = "Elastic License v2" + os = "windows" + + strings: + $subject = { 06 03 55 04 03 [2] 49 6E 74 65 6C 28 52 29 20 50 72 6F 63 65 73 73 6F 72 20 49 64 65 6E 74 69 66 69 63 61 74 69 6F 6E 20 55 74 69 6C 69 74 79 } + $read_msr = { 53 55 57 56 52 41 50 0F 32 41 58 41 89 10 5A 89 02 B8 01 00 00 00 5E 5F 5D 5B C3 } + $write_msr = { 53 55 57 56 48 8B C2 49 8B D0 0F 30 B8 01 00 00 00 5E 5F 5D 5B C3 } + $ioctl_check = { 48 8B 82 B8 00 00 00 8B 48 18 81 E9 84 2A 22 00 0F 84 ?? ?? ?? ?? 83 E9 04 } + + condition: + int16 ( uint32(0x3C)+0x5c)==0x0001 and all of them +} +rule ELASTIC_Macos_Exploit_Log4J_75A13888 : FILE MEMORY +{ + meta: + description = "Detects Macos Exploit Log4J (MacOS.Exploit.Log4j)" + author = "Elastic Security" + id = "75a13888-7650-4ef3-adec-15378c8479bd" + date = "2021-12-13" + modified = "2022-07-22" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Exploit_Log4j.yar#L1-L24" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "b09d8dd9c422e7eb8aa23f8b1204d31fd290252925099300d6d19d73e562ca5e" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "5841d70a38d4620c446427c80ca12b5e918f23e90c5288854943b0240958bcfb" + fingerprint = "cd06db6f5bebf0412d056017259b5451184d5ba5b2976efd18fa8f96dba6a159" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $a1 = "msvbvm60.dll" wide fullword - $a2 = "C:\\Program Files\\qga\\qga.exe" ascii fullword - $a3 = "C:\\Program Files\\Qemu-ga\\qemu-ga.exe" ascii fullword - $a4 = "USERPROFILE=" wide fullword - $a5 = "Startup key" ascii fullword + $jndi1 = "jndi.ldap.LdapCtx.c_lookup" + $jndi2 = "logging.log4j.core.lookup.JndiLookup.lookup" + $jndi3 = "com.sun.jndi.url.ldap.ldapURLContext.lookup" + $exp1 = "Basic/Command/Base64/" + $exp2 = "java.lang.ClassCastException: Exploit" + $exp3 = "WEB-INF/classes/Exploit" + $exp4 = "Exploit.java" condition: - all of them + 2 of ($jndi*) and 1 of ($exp*) } -rule ELASTIC_Windows_Trojan_Guloader_C4D9Dd33 : FILE MEMORY +rule ELASTIC_Windows_Vulndriver_Gdrv_5368078B : FILE { meta: - description = "Detects Windows Trojan Guloader (Windows.Trojan.Guloader)" + description = "Name: gdrv.sys, Version: 5.2.3790.1830" author = "Elastic Security" - id = "c4d9dd33-b7e7-4ff4-a2f3-62316d064f5a" - date = "2021-08-17" - modified = "2021-10-04" - reference = "https://www.elastic.co/security-labs/getting-gooey-with-guloader-downloader" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Guloader.yar#L26-L45" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "a3e2d5013b80cd2346e37460753eca4a4fec3a7941586cc26e049a463277562e" - logic_hash = "623ea751fc32648720bda40598024d4d5b6a9a11b3cce3c9427310ba17745643" + id = "5368078b-5dba-42c7-a50c-ac8859d3393d" + date = "2022-04-04" + modified = "2022-04-04" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_GDrv.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "31f4cfb4c71da44120752721103a16512444c13c2ac2d857a7e6f13cb679b427" + logic_hash = "f4d43ac4a4b6d879ffb5ba637b38ec75c8b57f531db644015c1a71c2cdea45d5" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "53a2d6f895cdd1a6384a55756711d9d758b3b20dd0b87d62a89111fd1a20d1d6" - severity = 100 + tags = "FILE" + fingerprint = "ce6e81ee34ba47466684387bdb957c3018b9c06938dbb2f7eb830609bd085f66" + threat_name = "Windows.VulnDriver.GDrv" + severity = 50 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" os = "windows" strings: - $a1 = "This program cannot be run under virtual environment or debugging software !" ascii fullword + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 67 00 64 00 72 00 76 00 2E 00 73 00 79 00 73 00 00 00 } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x02][\x00-\x00])([\x00-\x05][\x00-\x00])([\x00-\x26][\x00-\x07]|[\x00-\xff][\x00-\x06])([\x00-\xce][\x00-\x0e]|[\x00-\xff][\x00-\x0d])|([\x00-\xff][\x00-\xff])([\x00-\x04][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x01][\x00-\x00])([\x00-\x05][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x02][\x00-\x00])([\x00-\x05][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xcd][\x00-\x0e]|[\x00-\xff][\x00-\x0d]))/ condition: - all of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version } -rule ELASTIC_Windows_Trojan_Guloader_2F1E44C8 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Lurker_0Ee51802 : FILE { meta: - description = "Detects Windows Trojan Guloader (Windows.Trojan.Guloader)" + description = "Detects Windows Trojan Lurker (Windows.Trojan.Lurker)" author = "Elastic Security" - id = "2f1e44c8-f269-4cd6-a516-8d9282ddcfbc" - date = "2023-10-30" - modified = "2023-11-02" - reference = "https://www.elastic.co/security-labs/getting-gooey-with-guloader-downloader" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Guloader.yar#L47-L70" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "6ae7089aa6beaa09b1c3aa3ecf28a884d8ca84f780aab39902223721493b1f99" - logic_hash = "434b33c3fdc6bf4b0f59cd4aba66327d0b7ab524be603b256494d46b609cecd5" + id = "0ee51802-4ff3-4edf-95ed-bb0338ff25d9" + date = "2022-04-04" + modified = "2022-06-09" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Lurker.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "5718fd4f807e29e48a8b6a6f4484426ba96c61ec8630dc78677686e0c9ba2b87" + logic_hash = "782926c927dce82b95e51634d5607c474937e1edc0f7f739acefa0f4c03aa753" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "b00255f8d7ce460ffc778e96f6101db753e8992d36ee75a25b48e32ac7817c58" - severity = 100 + tags = "FILE" + fingerprint = "c30bc4e25c1984268a3bb44c59081131d1e81254b94734f6af2b47969c0acd0e" + severity = 50 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" os = "windows" strings: - $djb2_str_compare = { 83 C0 08 83 3C 04 00 0F 84 [4] 39 14 04 75 } - $check_exception = { 8B 45 ?? 8B 00 38 EC 8B 58 ?? 84 FD 81 38 05 00 00 C0 } - $parse_mem = { 18 00 10 00 00 83 C0 18 50 83 E8 04 81 00 00 10 00 00 50 } - $hw_bp = { 39 48 0C 0F 85 [4] 39 48 10 0F 85 [4] 39 48 14 0F 85 [7] 39 48 18 } - $scan_protection = { 39 ?? 14 8B [5] 0F 84 } + $str1 = "\\Device\\ZHWLurker0410" wide fullword condition: - 2 of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1 } -rule ELASTIC_Linux_Exploit_Enoket_79B52A4C : FILE MEMORY +rule ELASTIC_Windows_Hacktool_Sharpwmi_A67D6Fe5 : FILE MEMORY { meta: - description = "Detects Linux Exploit Enoket (Linux.Exploit.Enoket)" + description = "Detects Windows Hacktool Sharpwmi (Windows.Hacktool.SharpWMI)" author = "Elastic Security" - id = "79b52a4c-80cd-4fe1-aa6c-463e2cdd64ac" - date = "2021-01-12" - modified = "2021-09-16" + id = "a67d6fe5-3ce5-4e63-979e-3fb799d9d173" + date = "2022-10-20" + modified = "2022-11-24" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Enoket.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "3ae8f7e7df62316400d0c5fe0139d7a48c9f184e92706b552aad3d827d3dbbbf" - logic_hash = "204082a3be602b3f6aebb013a46e6f9c98b5dad2476350afa60c1954b13598fe" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_SharpWMI.yar#L1-L27" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "2134a5e1a5eece1336f831a7686c5ea3b6ca5aaa63ab7e7820be937da0678e15" + logic_hash = "de8749951ece8d4798ade4661d531515e12edf8e8606ddc330000d847a66a26c" score = 75 quality = 73 tags = "FILE, MEMORY" - fingerprint = "84be6877d6b1eb091de9817a5cf0ecba5e0e82089a6dd1dc0af2e91b01fe4003" + fingerprint = "20719ea15d4dee90c95b474689752172a6b6fb941dced81803f9f726ddc26d29" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 66 6F 75 6E 64 20 61 74 20 30 78 25 30 34 78 20 69 6E 20 74 } + $guid = "6DD22880-DAC5-4B4D-9C91-8C35CC7B8180" ascii wide nocase + $str0 = "powershell -w hidden -nop -c \"$e=([WmiClass]'{0}:{1}').Properties['{2}'].Value;[IO.File]::WriteAllBytes('{3}',[Byte[]][Int[]]($e-split','))\"" ascii wide + $str1 = "powershell -w hidden -nop -c \"iex($env:{0})\"" ascii wide + $str2 = "SELECT * FROM Win32_Process" ascii wide + $str3 = "DOWNLOAD_URL" ascii wide + $str4 = "TARGET_FILE" ascii wide + $str5 = "SELECT Enabled,DisplayName,Action,Direction,InstanceID from MSFT_NetFirewallRule WHERE Enabled=1" ascii wide + $print_str0 = "This may indicate called SharpWMI did not invoked WMI using elevated/impersonated token." ascii wide + $print_str1 = "[+] Attempted to terminate remote process ({0}). Returned: {1}" ascii wide condition: - all of them + $guid or ( all of ($str*) and 1 of ($print_str*)) } -rule ELASTIC_Linux_Exploit_Enoket_5969A348 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Hazelcobra_6A9Fe48A : FILE MEMORY { meta: - description = "Detects Linux Exploit Enoket (Linux.Exploit.Enoket)" + description = "Detects Windows Trojan Hazelcobra (Windows.Trojan.HazelCobra)" author = "Elastic Security" - id = "5969a348-6573-4cb3-b81e-db455ff7b484" - date = "2021-01-12" - modified = "2021-09-16" + id = "6a9fe48a-6fd9-4bce-ac43-254c02d6b3a4" + date = "2023-11-01" + modified = "2023-11-01" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Enoket.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "4b4d7ca9e1ffa2c46cb097d4a014c59b1a9feb93b3adcb5936ef6a1dfef9b0ae" - logic_hash = "e47af0fba86c9152d17911b984070a8419b98da8916538ebb1065a5348da6e31" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_HazelCobra.yar#L1-L22" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b5acf14cdac40be590318dee95425d0746e85b1b7b1cbd14da66f21f2522bf4d" + logic_hash = "dc4d561497c2e3da270d305ceaf3194b48d64c0d8e212ee6f03a2d89c8e006e8" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "7e9b9ba6146754857632451be2f98a5008268091ae1cfab1a87322b6fe30097c" + fingerprint = "4dc883be5fb6aae0dac0ec5d64baf24f0f3aaded6d759ec7dccb1a2ae641ae7b" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { FC 83 7D FC FF 75 07 B8 FF FF FF FF EB 0F 8B 45 FC 01 45 F0 83 7D } + $a1 = { 83 E9 37 48 63 C2 F6 C2 01 75 0C C0 E1 04 48 D1 F8 88 4C 04 40 EB 07 } + $s1 = "Data file loaded. Running..." fullword + $s2 = "No key in args" fullword + $s3 = "Can't read data file" fullword condition: - all of them + $a1 or all of ($s*) } -rule ELASTIC_Linux_Exploit_Enoket_80Fac3E9 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Darkvnc_Bd803C2E : FILE MEMORY { meta: - description = "Detects Linux Exploit Enoket (Linux.Exploit.Enoket)" + description = "Detects Windows Trojan Darkvnc (Windows.Trojan.DarkVNC)" author = "Elastic Security" - id = "80fac3e9-bf77-46d1-8d9b-25f3cf06a3b7" - date = "2021-01-12" - modified = "2021-09-16" + id = "bd803c2e-77bd-4b8c-bdfa-11a9bd54a454" + date = "2023-01-23" + modified = "2023-02-01" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Enoket.yar#L41-L59" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "3355ad81c566914a7d7734b40c46ded0cfa53aa22c6e834d42e185bf8bbe6128" - logic_hash = "19cb7f02ca80095293c4a09f7ea616c31364af1e4189a9211aaba54aaa2db14e" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_DarkVNC.yar#L1-L23" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0fcc1b02fdaf211c772bd4fa1abcdeb5338d95911c226a9250200ff7f8e45601" + logic_hash = "d9e8a42a424d6a186939682e1cd2ed794c8a3765824188e863b1b2829650e2d5" score = 75 - quality = 73 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "627418bfe84af36e9b34d42aa42cb6d793e6bc41aa555a77e4f9389a9407d6f2" + fingerprint = "131f4b3ef5b01720a52958058ecc4c3681ed0ca975a1a06cd034d7205680e710" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 42 4C 45 20 54 4F 20 4D 41 50 20 5A 45 52 4F 20 50 41 47 45 } + $a1 = "BOT-%s(%s)_%S-%S%u%u" wide fullword + $a2 = "{%08X-%04X-%04X-%04X-%08X%04X}" wide fullword + $a3 = "monitor_off / monitor_on" ascii fullword + $a4 = "bot_shell >" ascii fullword + $a5 = "keyboard and mouse are blocked !" ascii fullword condition: all of them } -rule ELASTIC_Linux_Exploit_Enoket_7Da5F86A : FILE MEMORY +rule ELASTIC_Linux_Trojan_Badbee_231Cb054 : FILE MEMORY { meta: - description = "Detects Linux Exploit Enoket (Linux.Exploit.Enoket)" + description = "Detects Linux Trojan Badbee (Linux.Trojan.Badbee)" author = "Elastic Security" - id = "7da5f86a-c177-47c9-a82e-50648c84174a" + id = "231cb054-36a9-434f-8254-17fee38e5275" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Enoket.yar#L61-L79" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "406b003978d79d453d3e2c21b991b113bf2fc53ffbf3a1724c5b97a4903ef550" - logic_hash = "df5769a87230f5e563849302f32673b5f5de2595e12de72c27921d45edc58928" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Badbee.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "832ba859c3030e58b94398ff663ddfe27078946a83dcfc81a5ef88351d41f4e2" + logic_hash = "a1ed8f2da9b4f891a5c65d943424bb7c465f0d07e7756e292c617ce5ef14d182" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "cf9a703969e3f9a3cd20119fc0a24fa2d16bec5ea7e3b1a8df763872625c90fc" + fingerprint = "ebe789fc467daf9276f72210f94e87b7fa79fc92a72740de49e47b71f123ed5c" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60562,115 +64768,120 @@ rule ELASTIC_Linux_Exploit_Enoket_7Da5F86A : FILE MEMORY os = "linux" strings: - $a = { FF 75 F2 80 7D 94 00 74 23 0F B6 0F B8 01 00 00 00 3A 4D 94 } + $a = { 8D B4 41 31 44 97 10 83 F9 10 75 E4 89 DE C1 FE 14 F7 C6 01 00 } condition: all of them } -rule ELASTIC_Linux_Exploit_Enoket_C77C0D6D : FILE MEMORY +rule ELASTIC_Macos_Virus_Pirrit_271B8Ed0 : FILE MEMORY { meta: - description = "Detects Linux Exploit Enoket (Linux.Exploit.Enoket)" + description = "Detects Macos Virus Pirrit (MacOS.Virus.Pirrit)" author = "Elastic Security" - id = "c77c0d6d-7f5c-4618-b6f6-3c1ddc70783c" - date = "2021-01-12" - modified = "2021-09-16" + id = "271b8ed0-937a-4be6-aecb-62535b5aeda7" + date = "2021-10-05" + modified = "2021-10-25" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Enoket.yar#L81-L99" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "3ae8f7e7df62316400d0c5fe0139d7a48c9f184e92706b552aad3d827d3dbbbf" - logic_hash = "504d61715bd5dba7f777fcb2d62eb53d8d54dad2dcf93f2fc2d7dcd359c4b994" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Virus_Pirrit.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "7feda05d41b09c06a08c167c7f4dde597ac775c54bf0d74a82aa533644035177" + logic_hash = "cb77f6df1403afbc7f45d30551559b6de7eb1c3434778b46d31754da0a1b1f10" score = 75 - quality = 73 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "739e23abbd2971d6ff24c94a87d7aab082aec85f9cd7eb3a168b35fa22f32eb9" + fingerprint = "12b09b2e3a43905db2cfe96d0fd0e735cfc7784ee7b03586c5d437d7c6a1b422" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "macos" strings: - $a = { 6E 64 20 74 68 65 20 77 6F 72 6C 64 2C 20 6F 6E 65 20 68 61 } + $a = { 35 4A 6A 00 00 32 80 35 44 6A 00 00 75 80 35 3E 6A 00 00 1F 80 35 38 6A 00 00 } condition: all of them } -rule ELASTIC_Linux_Exploit_Enoket_Fbf508E1 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Hijackloader_A8444812 : FILE MEMORY { meta: - description = "Detects Linux Exploit Enoket (Linux.Exploit.Enoket)" + description = "Detects Windows Trojan Hijackloader (Windows.Trojan.HijackLoader)" author = "Elastic Security" - id = "fbf508e1-2a44-417e-a2e4-8d43c2b64017" - date = "2021-01-12" - modified = "2021-09-16" + id = "a8444812-6aef-4ed7-a44b-b147301544c8" + date = "2023-11-15" + modified = "2024-01-12" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Enoket.yar#L101-L119" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "d1fa8520d3c3811d29c3d5702e7e0e7296b3faef0553835c495223a2bc015214" - logic_hash = "21b1d69677c3fddb210dcf5947e8321abccd5a1ebbde8438a83fee5d4b29443d" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_HijackLoader.yar#L1-L24" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "065c379a33ef1539e8a68fd4b7638fe8a30ec19fc128642ed0c68539656374b9" + logic_hash = "6cd88adc7a0d35013a26d1135efb294ee6f9ddab99b4549e82d3d6f5f65509b6" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "4909d3a04b820547fbff774c64c112b8a6a5e95452992639296a220776826d98" + fingerprint = "dd9f3bca44b585e3a31626b66223288634fcb092e43ecb053806726e5f2006e9" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 45 E8 76 0F 48 8B 45 E8 48 83 E8 01 0F B6 00 3C 5F 74 DF 48 8B } + $a1 = { 8B 45 ?? 40 89 45 ?? 8B 45 ?? 3B 45 ?? 73 ?? 8B 45 ?? 03 45 ?? 66 0F BE 00 66 89 45 ?? FF 75 ?? FF 75 ?? 8D 45 ?? 50 E8 [4] 83 C4 0C EB ?? } + $a2 = { 8B 45 ?? 8B 4D ?? 8B [1-5] 0F AF [1-5] 0F B7 [2] 03 C1 8B 4D ?? 89 01 } + $a3 = { 33 C0 40 74 ?? 8B 45 ?? 8B 4D ?? 8B 55 ?? 03 14 81 89 55 ?? FF 75 ?? FF 75 ?? E8 [4] 59 59 89 45 ?? 8B 45 ?? 8B 4D ?? 0F B7 04 41 8B 4D ?? 8B 55 ?? 03 14 81 89 55 ?? 8B 45 ?? 3B 45 ?? 75 ?? 8B 45 ?? EB ?? 8B 45 ?? 40 89 45 ?? EB ?? } + $a4 = { 8B 45 ?? 8B 4D ?? 8B [1-5] 0F AF [1-5] 0F B7 4D ?? 03 C1 8B 4D ?? 89 01 } + $a5 = { 8B 45 ?? 83 C0 04 89 45 ?? 8B 45 ?? 3B 45 ?? 73 ?? 8B 45 ?? 8B 4D ?? 8B 04 81 03 45 ?? 8B 4D ?? 8B 55 ?? 89 04 8A 8B 45 ?? 40 89 45 ?? EB ?? } + $a6 = { 8B 45 ?? 83 C0 04 89 45 ?? 8B 45 ?? 3B 45 ?? 73 ?? 8B 45 ?? 03 45 ?? 89 45 ?? 8B 45 ?? 8B 00 89 45 ?? 8B 45 ?? 33 45 ?? 8B 4D ?? 89 01 EB ?? } condition: - all of them + 3 of them } -rule ELASTIC_Linux_Exploit_Race_758A0884 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Afdk_C952Fcfa : FILE MEMORY { meta: - description = "Detects Linux Exploit Race (Linux.Exploit.Race)" + description = "Detects Windows Trojan Afdk (Windows.Trojan.Afdk)" author = "Elastic Security" - id = "758a0884-0174-46c8-a57a-980fc04360d0" - date = "2021-01-12" - modified = "2021-09-16" + id = "c952fcfa-75e1-4880-a4e3-1e4cc89c160f" + date = "2023-12-01" + modified = "2024-01-12" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Race.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "a4966baaa34b05cb782071ef114a53cac164e6dece275c862fe96a2cff4a6f06" - logic_hash = "ccba0e2ddefd53939cda6b4985def2d487ac5916cbad7374ac3143f02b9f7ff5" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Afdk.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "6723a9489e7cfb5e2d37ff9160d55cda065f06907122d73764849808018eb7a0" + logic_hash = "a0589a3bf9e733e615b6e552395b3ff513e4fad7efd7d2ebea634aa91d2f60d9" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "3516086ae773ec1c1de75a54bafbb72ad49b4c7f1661961d5613462b53f26c43" + fingerprint = "577b2f82944711a51e52eb35a0eaf17379576ae151dd820d8b442e8fed8a5373" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 00 22 00 00 00 36 00 00 00 18 85 04 08 34 00 00 00 12 00 00 } + $a = { 55 8B EC 51 51 83 65 F8 00 8D 45 F8 83 65 FC 00 50 E8 80 FF FF FF 59 85 C0 75 2B 8B 4D 08 8B 55 F8 8B 45 FC 89 41 04 8D 45 F8 89 11 83 CA 1F 50 89 55 F8 E8 7B FF FF FF 59 85 C0 75 09 E8 DA 98 } condition: all of them } -rule ELASTIC_Windows_Trojan_Pandastealer_8B333E76 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Afdk_5F8Cc135 : FILE MEMORY { meta: - description = "Detects Windows Trojan Pandastealer (Windows.Trojan.Pandastealer)" + description = "Detects Windows Trojan Afdk (Windows.Trojan.Afdk)" author = "Elastic Security" - id = "8b333e76-f723-4093-ad72-2f5d42aaa9c9" - date = "2021-09-02" - modified = "2022-01-13" + id = "5f8cc135-88b1-478d-aedb-0d60cee0bbf2" + date = "2023-12-01" + modified = "2024-01-12" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Pandastealer.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "ec346bd56be375b695b4bc76720959fa07d1357ffc3783eb61de9b8d91b3d935" - logic_hash = "5878799338fc18bac0f946faeadd59c921dee32c9391fc12d22c72c0cd6733a8" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Afdk.yar#L21-L41" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "6723a9489e7cfb5e2d37ff9160d55cda065f06907122d73764849808018eb7a0" + logic_hash = "0523a0cc3a4446f2ac88c72999568313c6b40f7f8975b8e332c0c6b1e48c5d76" score = 75 - quality = 25 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "873af8643b7f08b159867c3556654a5719801aa82e1a1f6402029afad8c01487" + fingerprint = "275bfaac332f3cbc1164c35bdbc5cbe8bfd45559f6b929a0b8b64af2de241bd8" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60678,32 +64889,31 @@ rule ELASTIC_Windows_Trojan_Pandastealer_8B333E76 : FILE MEMORY os = "windows" strings: - $a1 = "] - [user: " ascii fullword - $a2 = "[-] data unpacked failed" ascii fullword - $a3 = "[+] data unpacked" ascii fullword - $a4 = "\\history\\" ascii fullword - $a5 = "PlayerName" ascii fullword + $a1 = "Cannot set the log file name" + $a2 = "Cannot install the hook procedure" + $a3 = "Keylogger is up and running..." condition: - all of them + 2 of them } -rule ELASTIC_Windows_Trojan_Blister_Cb99A1Df : FILE MEMORY +rule ELASTIC_Windows_Trojan_Solarmarker_D466E548 : FILE MEMORY { meta: - description = "Detects Windows Trojan Blister (Windows.Trojan.Blister)" + description = "Detects Windows Trojan Solarmarker (Windows.Trojan.SolarMarker)" author = "Elastic Security" - id = "cb99a1df-756b-46fe-b657-63b4be2c0664" - date = "2021-12-21" - modified = "2022-01-13" - reference = "https://www.elastic.co/security-labs/elastic-security-uncovers-blister-malware-campaign" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Blister.yar#L1-L22" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0a7778cf6f9a1bd894e89f282f2e40f9d6c9cd4b72be97328e681fe32a1b1a00" - logic_hash = "deb1be5300d8af12dda868dd5f4ccdbb3ec653bd97c33a09e567c13ecafb9e8a" + id = "d466e548-eb88-41e6-9740-ae59980db835" + date = "2023-12-12" + modified = "2024-01-12" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_SolarMarker.yar#L1-L20" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "330f5067c93041821be4e7097cf32fb569e2e1d00e952156c9aafcddb847b873" + hash = "e2a620e76352fa7ac58407a711821da52093d97d12293ae93d813163c58eb84b" + logic_hash = "c0792bc3c1a2f01ff4b8d0a12c95a74491c2805c876f95a26bbeaabecdff70e9" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "7a7e189ed42019636ffccc06d61e18f2aa17bc3d43d08d50bb77c3258bc1a9a4" + fingerprint = "0f4b0162ee8283959e10c459ddc55eb00eae30d241119aad1aa3ea6c101f9889" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60711,30 +64921,28 @@ rule ELASTIC_Windows_Trojan_Blister_Cb99A1Df : FILE MEMORY os = "windows" strings: - $a1 = { 8D 45 DC 89 5D EC 50 6A 04 8D 45 F0 50 8D 45 EC 50 6A FF FF D7 } - $a2 = { 75 F7 39 4D FC 0F 85 F3 00 00 00 64 A1 30 00 00 00 53 57 89 75 } - $b1 = { 78 03 C3 8B 48 20 8B 50 1C 03 CB 8B 78 24 03 D3 8B 40 18 03 FB 89 4D F8 89 55 E0 89 45 E4 85 C0 74 3E 8B 09 8B D6 03 CB 8A 01 84 C0 74 17 C1 C2 09 0F BE C0 03 D0 41 8A 01 84 C0 75 F1 81 FA B2 17 EB 41 74 27 8B 4D F8 83 C7 02 8B 45 F4 83 C1 04 40 89 4D F8 89 45 F4 0F B7 C0 3B 45 E4 72 C2 8B FE 8B 45 04 B9 } + $a1 = { 00 00 2B 03 00 2B 15 00 07 2D 09 08 16 FE 01 16 FE 01 2B 01 17 00 13 04 11 04 2D 8C 07 2D 06 08 } condition: - any of them + all of them } -rule ELASTIC_Windows_Trojan_Blister_9D757838 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Solarmarker_08Bfc26B : FILE MEMORY { meta: - description = "Detects Windows Trojan Blister (Windows.Trojan.Blister)" + description = "Detects Windows Trojan Solarmarker (Windows.Trojan.SolarMarker)" author = "Elastic Security" - id = "9d757838-ebaa-4ecf-b927-ac0f4848c9cb" - date = "2022-04-26" - modified = "2022-06-09" - reference = "https://www.elastic.co/security-labs/elastic-security-uncovers-blister-malware-campaign" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Blister.yar#L24-L44" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "863de84a39c9f741d8103db83b076695d0d10a7384e4e3ba319c05a6018d9737" - logic_hash = "4d9ce1622d77b2ac8b20b2dfb60ac672752dabab315221a5449ebd3c73a3edca" + id = "08bfc26b-efda-49b4-b685-57edca8b9d18" + date = "2024-05-29" + modified = "2024-06-12" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_SolarMarker.yar#L22-L42" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c1a6d2d78cc50f080f1fe4cadc6043027bf201d194f2b73625ce3664433a3966" + logic_hash = "b31b9f8460b606426c1101eba39a41a75c7ecaafc62388a6a5ac0f24057561ed" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "4ef2e22d0006b127b253d02073cde0d805d22d8696562feabc94020e287e2eb2" + fingerprint = "9c0c4a5bce63c9d99d53813f7250b3ccc395cb99eaebb8c016f8c040fbfa4ea7" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60742,29 +64950,30 @@ rule ELASTIC_Windows_Trojan_Blister_9D757838 : FILE MEMORY os = "windows" strings: - $a1 = { 65 48 8B 04 25 60 00 00 00 44 0F B7 DB 48 8B 48 ?? 48 8B 41 ?? C7 45 48 ?? ?? ?? ?? 4C 8B 40 ?? 49 63 40 ?? } - $a2 = { B9 FF FF FF 7F 89 5D 40 8B C1 44 8D 63 ?? F0 44 01 65 40 49 2B C4 75 ?? 39 4D 40 0F 85 ?? ?? ?? ?? 65 48 8B 04 25 60 00 00 00 44 0F B7 DB } + $a1 = { 07 09 91 61 D2 9C 09 20 C8 00 00 00 5D 16 FE 01 16 FE 01 13 } + $a2 = { 91 07 08 91 61 D2 9C 08 20 C8 00 00 00 5D 16 FE 01 16 FE 01 } + $a3 = { 06 08 06 08 91 07 08 91 61 D2 9C 08 20 C8 00 00 00 5D 16 FE } condition: any of them } -rule ELASTIC_Windows_Trojan_Blister_68B53E1B : FILE MEMORY +rule ELASTIC_Windows_Hacktool_Seatbelt_674Fd535 : FILE MEMORY { meta: - description = "Detects Windows Trojan Blister (Windows.Trojan.Blister)" + description = "Detects Windows Hacktool Seatbelt (Windows.Hacktool.Seatbelt)" author = "Elastic Security" - id = "68b53e1b-dbd7-4903-ac10-8336c05f42df" - date = "2023-08-02" - modified = "2023-08-08" - reference = "https://www.elastic.co/security-labs/elastic-security-uncovers-blister-malware-campaign" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Blister.yar#L46-L66" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "5fc79a4499bafa3a881778ef51ce29ef015ee58a587e3614702e69da304395db" - logic_hash = "6d935461406a6b9b39867d52aa5ecb088945ae0f8c56895a67e8565e5a2a3699" + id = "674fd535-f188-4b20-8b5e-69a111bf08e5" + date = "2022-10-20" + modified = "2022-11-24" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_Seatbelt.yar#L1-L26" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "a0e467aacd383727d46e766f1c45b424a6d46248118c155c22c538e8773b3ae7" + logic_hash = "1bff820ec5cc9e56e7be4b290a48628115cc1ace5e41278fa76898bf39ef893e" score = 75 - quality = 75 + quality = 73 tags = "FILE, MEMORY" - fingerprint = "b46d59117eda3d6a7a6397287c962106719bf338d19814e20bde9deeebfe65c1" + fingerprint = "cdbafa7507cb723f20ad0c7a288750a0d95792c8fe5ceb5e48c62fd45f2ffc0b" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60772,29 +64981,35 @@ rule ELASTIC_Windows_Trojan_Blister_68B53E1B : FILE MEMORY os = "windows" strings: - $b_loader_xor = { 48 8B C3 49 03 DC 83 E0 03 8A 44 05 48 [2-3] ?? 03 ?? 4D 2B ?? 75 } - $b_loader_virtual_protect = { 48 8D 45 50 41 ?? ?? ?? ?? 00 4C 8D ?? 04 4C 89 ?? ?? 41 B9 04 00 00 00 4C 89 ?? F0 4C 8D 45 58 48 89 44 24 20 48 8D 55 F0 } + $guid = "AEC32155-D589-4150-8FE7-2900DF4554C8" ascii wide nocase + $str0 = "LogonId=\"(\\d+)" ascii wide + $str1 = "Domain=\"(.*)\",Name=\"(.*)\"" ascii wide + $str2 = "^\\W*([a-z]:\\\\.+?(\\.exe|\\.dll|\\.sys))\\W*" ascii wide + $str3 = "KB\\d+" ascii wide + $str4 = "(^https?://.+)|(^ftp://)" ascii wide + $str5 = "[0-9A-Fa-f]{8}[-][0-9A-Fa-f]{4}[-][0-9A-Fa-f]{4}[-][0-9A-Fa-f]{4}[-][0-9A-Fa-f]{12}" ascii wide + $str6 = "(http|ftp|https|file)://([\\w_-]+(?:(?:\\.[\\w_-]+)+))([\\w.,@?^=%&:/~+#-]*[\\w@?^=%&/~+#-])?" ascii wide condition: - all of them + $guid or all of ($str*) } -rule ELASTIC_Windows_Trojan_Blister_487B0966 : FILE MEMORY +rule ELASTIC_Windows_Ransomware_Darkside_D7Fc4594 : FILE MEMORY { meta: - description = "Detects Windows Trojan Blister (Windows.Trojan.Blister)" + description = "Detects Windows Ransomware Darkside (Windows.Ransomware.Darkside)" author = "Elastic Security" - id = "487b0966-fb24-4c41-84cc-f3a389461ddc" - date = "2023-09-11" - modified = "2023-09-20" - reference = "https://www.elastic.co/security-labs/elastic-security-uncovers-blister-malware-campaign" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Blister.yar#L68-L89" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "5fc79a4499bafa3a881778ef51ce29ef015ee58a587e3614702e69da304395db" - logic_hash = "521409d03335205507cc6894e0de3ca627eb966a95a2f8e7b931e552ad78bbb7" + id = "d7fc4594-185c-4afb-986e-5718c0beabf1" + date = "2021-05-20" + modified = "2021-10-04" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Darkside.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "bfb31c96f9e6285f5bb60433f2e45898b8a7183a2591157dc1d766be16c29893" + logic_hash = "0083fb64955973e7dbbb35d08cb780fa0b4ff4d064c102dc8f86e29af8358bad" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "7111f2f9746e056f6ac5e08d904f71628a548b4ab2c1181dec0a38f0f8387878" + fingerprint = "90444cd2d3a38296b4979f91345a9999b0032f6c0abee6ff7c15d149b59e5e88" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60802,176 +65017,145 @@ rule ELASTIC_Windows_Trojan_Blister_487B0966 : FILE MEMORY os = "windows" strings: - $b_loader0 = { 65 48 8B 04 25 60 00 00 00 44 8B D3 41 BE ?? ?? ?? ?? 48 8B 50 18 48 83 C2 ?? 48 8B 0A } - $b_loader1 = { 0F B7 C0 4D 8D 49 02 41 33 C0 44 69 C0 ?? ?? ?? ?? 41 8B C0 C1 E8 0F 44 33 C0 41 0F B7 01 66 85 C0 } - $b_loader2 = { 66 45 03 DC 49 83 C2 04 41 0F B7 C3 49 83 C0 02 3B C6 } + $a1 = { 5F 30 55 56 BD 0A 00 00 00 8B 07 8B 5F 10 8B 4F 20 8B 57 30 } condition: - 2 of them + any of them } -rule ELASTIC_Macos_Hacktool_Swiftbelt_Bc62Ede6 : FILE MEMORY +rule ELASTIC_Windows_Ransomware_Darkside_Aceac5D9 : FILE MEMORY { meta: - description = "Detects Macos Hacktool Swiftbelt (MacOS.Hacktool.Swiftbelt)" + description = "Detects Windows Ransomware Darkside (Windows.Ransomware.Darkside)" author = "Elastic Security" - id = "bc62ede6-e6f1-4c9e-bff2-ef55a5d12ba1" - date = "2021-10-12" - modified = "2021-10-25" - reference = "https://www.elastic.co/security-labs/inital-research-of-jokerspy" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/MacOS_Hacktool_Swiftbelt.yar#L1-L44" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "452c832a17436f61ad5f32ee1c97db05575160105ed1dcd0d3c6db9fb5a9aea1" - logic_hash = "51481baa6ddb09cf8463d989637319cb26b23fef625cc1a44c96d438c77362ca" + id = "aceac5d9-fb38-4dca-ab1f-44ee40005d37" + date = "2021-05-20" + modified = "2021-10-04" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Darkside.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "bfb31c96f9e6285f5bb60433f2e45898b8a7183a2591157dc1d766be16c29893" + logic_hash = "888ab06b55b07879ee6b9a45c04f1a09c570aeb4be55c698300566d57fd47252" score = 75 - quality = 73 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "98d14dba562ad68c8ecc00780ab7ee2ecbe912cd00603fff0eb887df1cd12fdb" + fingerprint = "521b0f574b27151ad03fc7693fd692e1a13e81a28e39d04d3f7ea149a0da59b9" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "macos" + os = "windows" strings: - $dbg1 = "SwiftBelt/Sources/SwiftBelt" - $dbg2 = "[-] Firefox places.sqlite database not found for user" - $dbg3 = "[-] No security products found" - $dbg4 = "SSH/AWS/gcloud Credentials Search:" - $dbg5 = "[-] Could not open the Slack Cookies database" - $sec1 = "[+] Malwarebytes A/V found on this host" - $sec2 = "[+] Cisco AMP for endpoints found" - $sec3 = "[+] SentinelOne agent running" - $sec4 = "[+] Crowdstrike Falcon agent found" - $sec5 = "[+] FireEye HX agent installed" - $sec6 = "[+] Little snitch firewall found" - $sec7 = "[+] ESET A/V installed" - $sec8 = "[+] Carbon Black OSX Sensor installed" - $sec9 = "/Library/Little Snitch" - $sec10 = "/Library/FireEye/xagt" - $sec11 = "/Library/CS/falcond" - $sec12 = "/Library/Logs/PaloAltoNetworks/GlobalProtect" - $sec13 = "/Library/Application Support/Malwarebytes" - $sec14 = "/usr/local/bin/osqueryi" - $sec15 = "/Library/Sophos Anti-Virus" - $sec16 = "/Library/Objective-See/Lulu" - $sec17 = "com.eset.remoteadministrator.agent" - $sec18 = "/Applications/CarbonBlack/CbOsxSensorService" - $sec19 = "/Applications/BlockBlock Helper.app" - $sec20 = "/Applications/KextViewr.app" + $a1 = { 41 54 55 53 48 83 EC 28 48 8B 1F 4C 8B 66 08 48 8D 7C 24 10 4C } condition: - 6 of them + any of them } -rule ELASTIC_Linux_Exploit_Openssl_47C6Fad7 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Ghostpulse_A1311F49 : FILE MEMORY { meta: - description = "Detects Linux Exploit Openssl (Linux.Exploit.Openssl)" + description = "Detects Windows Trojan Ghostpulse (Windows.Trojan.GhostPulse)" author = "Elastic Security" - id = "47c6fad7-0582-4a7a-9c51-68830e6b6132" - date = "2021-04-06" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Openssl.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "8024af0931dff24b5444f0b06a27366a776014358aa0b7fc073030958f863ef8" - logic_hash = "4c60071ecd7b826e692710ae11b09be30e7df5833bcaa8642fea014e12b9abd7" + id = "a1311f49-65a7-4136-a5ab-28cf4de4d40f" + date = "2023-10-06" + modified = "2023-10-26" + reference = "https://www.elastic.co/security-labs/ghostpulse-haunts-victims-using-defense-evasion-bag-o-tricks" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_GhostPulse.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0175448655e593aa299278d5f11b81f2af76638859e104975bdb5d30af5c0c11" + logic_hash = "21838f230ac1a77f09d01d30f4ea3b66313618660e63ab7012b030e0b819547e" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "bde819830cc991269275ce5de2db50489368c821271aaa397ab914011f2fcb91" + fingerprint = "e07a8152ab75624aa8dd0a8301d690a6a4bdd3b0e069699632541fb6a32e419b" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 31 C9 F7 E1 51 5B B0 A4 CD 80 31 C0 50 68 2F } + $a1 = { 0F BE 00 48 0F BE C0 85 C0 74 0D B8 01 00 00 00 03 45 00 89 45 00 EB E1 8B 45 00 48 8D 65 10 5D C3 } + $a2 = { 88 4C 24 08 48 83 EC 18 0F B6 44 24 20 88 04 24 0F BE 44 24 20 83 F8 41 7C 13 0F BE 04 24 83 F8 5A 7F 0A 0F BE 04 24 83 C0 20 88 04 24 } condition: - all of them + any of them } -rule ELASTIC_Macos_Backdoor_Useragent_1A02Fc3A : FILE MEMORY +rule ELASTIC_Windows_Trojan_Ghostpulse_3Fe1D02D : FILE MEMORY { meta: - description = "Detects Macos Backdoor Useragent (MacOS.Backdoor.Useragent)" + description = "Detects Windows Trojan Ghostpulse (Windows.Trojan.GhostPulse)" author = "Elastic Security" - id = "1a02fc3a-a394-457b-8af5-99f7f22b0a3b" - date = "2021-11-11" - modified = "2022-07-22" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/MacOS_Backdoor_Useragent.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "623f99cbe20af8b79cbfea7f485d47d3462d927153d24cac4745d7043c15619a" - logic_hash = "90debdfc24ef100952302808a2e418bca2a46be3e505add9a0ccf4c49aff5102" + id = "3fe1d02d-5de3-42df-8389-6a55fc2b8afd" + date = "2023-10-12" + modified = "2023-10-26" + reference = "https://www.elastic.co/security-labs/ghostpulse-haunts-victims-using-defense-evasion-bag-o-tricks" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_GhostPulse.yar#L23-L41" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "4ef78d436a153ed751a8483c1e43ec2ba053dedfa0da2780fded42012d3042c1" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "22afa14a3dc6f8053b93bf3e971d57808a9cc19e676f9ed358ba5f1db9292ba4" + fingerprint = "18aed348ba64bee842fb6af3b3220e108052a67f49724cf34ba52c8ec7c15cac" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "macos" + os = "windows" strings: - $s1 = "/Library/LaunchAgents/com.UserAgent.va.plist" - $s2 = "this is not root" - $s3 = "rm -Rf " - $s4 = "/start.sh" - $s5 = ".killchecker_" + $a = { 48 89 5C 24 08 48 89 7C 24 10 8B DA 45 33 D2 48 8B F9 41 2B D9 74 50 4C 8B D9 4C 2B C1 0F 1F 00 33 C9 } condition: - 4 of them + all of them } -rule ELASTIC_Windows_Vulndriver_Mtcbsv_7F6D642E : FILE +rule ELASTIC_Windows_Trojan_Ghostpulse_3673D337 : FILE MEMORY { meta: - description = "Name: mtcBSv64.sys, Version: 21.2.0.0" + description = "Detects Windows Trojan Ghostpulse (Windows.Trojan.GhostPulse)" author = "Elastic Security" - id = "7f6d642e-bf8c-44e7-939f-08513523ee2e" - date = "2022-04-07" - modified = "2022-04-07" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_MtcBsv.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "ff803017d1acafde6149fe7d463aee23b1c4f6f3b97c698c05f3ca6f07e4df6c" - logic_hash = "dfd53a2b97ad722307561fc5f109dcba372bf600113786bb351ed1262fdc8556" + id = "3673d337-218b-4ea8-93f5-ecbc6fe51885" + date = "2023-12-11" + modified = "2024-01-12" + reference = "https://www.elastic.co/security-labs/ghostpulse-haunts-victims-using-defense-evasion-bag-o-tricks" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_GhostPulse.yar#L43-L63" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "3013ba32838f6d97d7d75e25394f9611b1c5def94d93588f0a05c90b25b7d6d5" + logic_hash = "a92815f27533338e17afd5ebdbe82e382636fb81167a82d1b613c0dccc5b7ed3" score = 75 quality = 75 - tags = "FILE" - fingerprint = "f59ad8d5f19584e76e67689aba1e0d305d451ed6a030c6e2bccd048e0aeb0b0a" - threat_name = "Windows.VulnDriver.MtcBsv" - severity = 50 + tags = "FILE, MEMORY" + fingerprint = "0b46a0e04ab2ca2760b2ace397a09b681bc6c0da5581c3f0f5cdb1a60f307a15" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" os = "windows" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 6D 00 74 00 63 00 42 00 53 00 76 00 36 00 34 00 2E 00 73 00 79 00 73 00 00 00 } - $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x02][\x00-\x00])([\x00-\x15][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x14][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x01][\x00-\x00])([\x00-\x15][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ + $IDAT_parser_x86 = { 80 F9 3F 75 ?? 38 54 1E 02 74 ?? 80 FA 3F 75 ?? 38 6C 1E 03 74 ?? 80 FD 3F 75 ?? 8A 74 24 04 38 74 1E 04 } + $IDAT_parser_x64 = { 80 FB 3F 0F 94 44 24 27 3C 3F 0F 94 44 24 30 40 80 FF 3F 0F 94 44 24 31 41 80 FD 3F 0F 94 44 24 32 41 80 FC 3F 0F 94 44 24 33 } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version + any of them } -rule ELASTIC_Windows_Trojan_Smokeloader_4E31426E : FILE MEMORY +rule ELASTIC_Windows_Trojan_Ghostpulse_8Ae8310B : FILE MEMORY { meta: - description = "Detects Windows Trojan Smokeloader (Windows.Trojan.Smokeloader)" + description = "Detects Windows Trojan Ghostpulse (Windows.Trojan.GhostPulse)" author = "Elastic Security" - id = "4e31426e-d62e-4b6d-911b-4223e1f6adef" - date = "2021-07-21" - modified = "2021-08-23" + id = "8ae8310b-4ead-4b5c-be73-7db365470891" + date = "2024-05-27" + modified = "2024-06-12" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Smokeloader.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174" - logic_hash = "44ac7659964519ae72f83076bcd1b3e5244eb9cadd9a3b123dda78b0e9e07424" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_GhostPulse.yar#L65-L84" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "5b64f91b41a7390d89cd3b1fccf02b08b18b7fed17a43b0bfac63d75dc0df083" + logic_hash = "b3873a3c728e98d65984033620c0ac8ee93be21db5b6d9bd4665b9f7d0d759fa" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277" + fingerprint = "61213fd4ce9ddebdc7de8e6b23827347af3cbddd61254f95917e9af6b8a2b7b2" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -60979,28 +65163,29 @@ rule ELASTIC_Windows_Trojan_Smokeloader_4E31426E : FILE MEMORY os = "windows" strings: - $a = { 5B 81 EB 34 10 00 00 6A 30 58 64 8B 00 8B 40 0C 8B 40 1C 8B 40 08 89 85 C0 } + $a = { 48 8B 84 24 ?? 0D 00 00 8B 40 14 0F BA E8 09 48 8B 8C 24 ?? 0D 00 00 89 41 14 48 8B 84 24 ?? 0D 00 00 48 8B 8C 24 ?? 05 00 00 48 89 88 C0 ?? 00 00 } + $b = { BA C8 90 F0 B2 48 8B ?? ?? ?? E8 ?? ?? ?? 00 48 89 ?? ?? ?? 07 00 00 BA 9C 6C DA DC 48 8B ?? ?? ?? E8 ?? ?? ?? 00 48 89 ?? ?? ?? 07 00 00 BA 8D 20 4A A1 48 8B ?? ?? ?? E8 ?? ?? ?? 00 48 89 ?? ?? ?? 07 00 00 BA D4 7C 1A A8 } condition: - all of them + any of them } -rule ELASTIC_Windows_Trojan_Smokeloader_4Ee15B92 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Ghostpulse_9E22C56D : FILE MEMORY { meta: - description = "Detects Windows Trojan Smokeloader (Windows.Trojan.Smokeloader)" + description = "Detects Windows Trojan Ghostpulse (Windows.Trojan.GhostPulse)" author = "Elastic Security" - id = "4ee15b92-c62f-42d2-bbba-1dac2fa5644f" - date = "2022-02-17" - modified = "2022-04-12" + id = "9e22c56d-91bf-4259-8b60-aa7323b5e8f9" + date = "2024-07-21" + modified = "2024-07-26" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Smokeloader.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "09b9283286463b35ea2d5abfa869110eb124eb8c1788eb2630480d058e82abf2" - logic_hash = "7d5ba6a4cc1f1b87f7ea1963b41749f5488197ea28b31f20a235091236250463" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_GhostPulse.yar#L86-L106" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "349b4dfa1e93144b010affba926663264288a5cfcb7b305320f466b2551b93df" + logic_hash = "5dbd0d6a936a73e933181017c67c36fde7576b47643ec00848f7b58170bd9c6b" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "5d2ed385c76dbb4c1c755ae88b68306086a199a25a29317ae132bc874b253580" + fingerprint = "5e9883ad58fee79960a6e5e3c266885c6dc72057a16f4ea0e371088571e9b663" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61008,28 +65193,30 @@ rule ELASTIC_Windows_Trojan_Smokeloader_4Ee15B92 : FILE MEMORY os = "windows" strings: - $a = { 24 34 30 33 33 8B 45 F4 5F 5E 5B C9 C2 10 00 55 89 E5 83 EC } + $a = { C7 44 24 28 80 3C 36 FE C7 44 24 2C FF FF FF FF 53 6A 00 } + $b = { 80 7C 24 04 3F ?? ?? 8A 74 24 08 38 74 1E 05 8A 6C 24 10 ?? ?? 80 7C 24 08 3F } + $c = { 89 41 5C 8B 44 24 ?? 8B 80 04 01 00 00 89 44 24 ?? 8B 42 3C 8B 44 02 78 8B 4C 02 20 01 D1 89 4C 24 ?? 8B 4C 02 1C 89 4C 24 ?? 8B 44 02 24 89 44 } condition: - all of them + any of them } -rule ELASTIC_Windows_Trojan_Smokeloader_Ea14B2A5 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Hotpage_414F235F : FILE MEMORY { meta: - description = "Detects Windows Trojan Smokeloader (Windows.Trojan.Smokeloader)" + description = "Detects Windows Trojan Hotpage (Windows.Trojan.HotPage)" author = "Elastic Security" - id = "ea14b2a5-ea0d-4da2-8190-dbfcda7330d9" - date = "2023-05-03" - modified = "2023-06-13" + id = "414f235f-5e16-449a-9ac5-556655c4418e" + date = "2024-07-18" + modified = "2024-07-26" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Smokeloader.yar#L41-L60" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "15fe237276b9c2c6ceae405c0739479d165b406321891c8a31883023e7b15d54" - logic_hash = "8a96985902f82979f1512d4d30cfa41fd23562b8f86bf2f722351ef2adf4365f" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_HotPage.yar#L1-L25" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b8464126b64c809b4ab47aa91c5f322ce2c0ae4fd668a43de738a5caa7567225" + logic_hash = "cfa0036b22a83a5396b3f9014511720071246a775053ad493791ebc1212400f2" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "950ce9826fdff209b6e03c70a4f78b812d211a2a9de84bec0e5efe336323001b" + fingerprint = "6f590056d3f7bb9f743861e8d317ec589d8703353428dfcea9a6d2f61f266cdf" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61037,38 +65224,44 @@ rule ELASTIC_Windows_Trojan_Smokeloader_Ea14B2A5 : FILE MEMORY os = "windows" strings: - $a1 = { AC 41 80 01 AC 41 80 00 AC 41 80 00 AC 41 C0 00 AC 41 80 01 } - $a2 = { AC 41 80 00 AC 41 80 07 AC 41 80 00 AC 41 80 00 AC 41 80 00 } + $SpcSpOpusInfo = { 30 48 A0 1A 80 18 6E 56 53 17 76 FE 7F 51 7F 51 7E DC 79 D1 62 80 67 09 96 50 51 6C 53 F8 } + $s1 = "\\Device\\KNewTableBaseIo" + $s2 = "Release\\DwAdsafeLoad.pdb" + $s3 = "RedDriver.pdb" + $s4 = "Release\\DwAdSafe.pdb" + $s5 = "[%s] Begin injecting Broser pid=[%d]" + $s6 = "[%s] ADDbrowser PID ->[%d]" condition: - all of them + $SpcSpOpusInfo or 2 of ($s*) } -rule ELASTIC_Windows_Trojan_Smokeloader_De52Ed44 : FILE MEMORY +rule ELASTIC_Multi_Trojan_Sparkrat_9A21E541 : FILE MEMORY { meta: - description = "Detects Windows Trojan Smokeloader (Windows.Trojan.Smokeloader)" + description = "Detects Multi Trojan Sparkrat (Multi.Trojan.SparkRat)" author = "Elastic Security" - id = "de52ed44-062c-4b0d-9a41-1bfc31a8daa9" - date = "2023-05-04" - modified = "2023-06-13" + id = "9a21e541-886c-4d7f-8602-832862121730" + date = "2023-11-13" + modified = "2024-06-12" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Smokeloader.yar#L62-L81" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "c689a384f626616005d37a94e6a5a713b9eead1b819a238e4e586452871f6718" - logic_hash = "95a60079a316016ca3f78f18e7920b962f5770bef4211dd70e37f45bbe069406" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Multi_Trojan_SparkRat.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "23efecc03506a9428175546a4b7d40c8a943c252110e83dec132c6a5db8c4dd6" + logic_hash = "903c5c65436bea8dd044fd5f1f6dda3d1e90ab25802d508f67ba0f7fd06e92d4" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "950db8f87a81ef05cc2ecbfa174432ab31a3060c464836f3b38448bd8e5801be" + fingerprint = "2691da3a037b651d0f7f6d7be767c34845c3b9a642f4a2fb1c54f391f08089b6" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "multi" strings: - $a1 = { 08 31 FF 89 7D CC 66 8C E8 66 85 C0 74 03 FF 45 CC FF 53 48 } - $a2 = { B0 8F 45 C8 8D 45 B8 89 38 8D 4D C8 6A 04 57 6A 01 51 57 57 } + $a1 = "Spark/client/service/file" ascii wide + $a2 = "Spark/client/service/desktop" ascii wide + $a3 = "Spark/utils.Encrypt" ascii wide condition: all of them @@ -61082,8 +65275,8 @@ rule ELASTIC_Linux_Trojan_Sambashell_F423755D : FILE MEMORY date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Sambashell.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Sambashell.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" hash = "bd8a3728a59afbf433799578ef597b9a7211c8d62e87a25209398814851a77ea" logic_hash = "b93c671fae87cd635679142d248cb2b754389ba3b416f3370ea331640eb906ab" score = 75 @@ -61102,23 +65295,23 @@ rule ELASTIC_Linux_Trojan_Sambashell_F423755D : FILE MEMORY condition: all of them } -rule ELASTIC_Windows_PUP_Veriato_Fae5978C : FILE MEMORY +rule ELASTIC_Windows_Trojan_Pipedance_01C18057 : FILE MEMORY { meta: - description = "Detects Windows Pup Veriato (Windows.PUP.Veriato)" + description = "Detects Windows Trojan Pipedance (Windows.Trojan.PipeDance)" author = "Elastic Security" - id = "fae5978c-f26c-4215-9407-d16e492ab5c1" - date = "2022-06-08" - modified = "2022-09-29" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_PUP_Veriato.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "53f09e60b188e67cdbf28bda669728a1f83d47b0279debf3d0a8d5176479d17f" - logic_hash = "8ae6f8b2b6e3849b33e6a477af52982efe137d7ebeff0c92cee5667d75f05145" + id = "01c18057-258d-4242-928c-26972a2f1e76" + date = "2023-02-02" + modified = "2023-02-22" + reference = "https://www.elastic.co/security-labs/twice-around-the-dance-floor-with-pipedance" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_PipeDance.yar#L1-L27" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "9d3f739e35182992f1e3ade48b8999fb3a5049f48c14db20e38ee63eddc5a1e7" + logic_hash = "0c03a725ae930eb829d6a6a9f681489d61aa7f69e72b6b298776f75a98115398" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "8d351cdd11d6dddc76cd89e7de9e65b28ef5c8183db804b2a450095e2f3214e5" + fingerprint = "01b8c127974ec8e3db0fc68db8d11cd4f4247c0128a8630f64c7bd20726220af" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61126,30 +65319,35 @@ rule ELASTIC_Windows_PUP_Veriato_Fae5978C : FILE MEMORY os = "windows" strings: - $s1 = "InitializeDll" fullword - $a1 = "C:\\Windows\\winipbin\\svrltmgr.dll" fullword - $a2 = "C:\\Windows\\winipbin\\svrltmgr64.dll" fullword + $str1 = "%-5d %-30s %-4s %-7d %s" wide fullword + $str2 = "PID Name Arch Session User" wide fullword + $str3 = "%s %7.2f B" wide fullword + $str4 = "\\\\.\\pipe\\%s.%d" ascii fullword + $seq_rc4 = { 8D 46 ?? 0F B6 F0 8A 14 3E 0F B6 C2 03 C1 0F B6 C8 89 4D ?? 8A 04 0F 88 04 3E 88 14 0F 0F B6 0C 3E 0F B6 C2 03 C8 0F B6 C1 8B 4D ?? 8A 04 38 30 04 0B 43 8B 4D ?? 3B 5D ?? 72 ?? } + $seq_srv_resp = { 8B CE 50 6A 04 5A E8 ?? ?? ?? ?? B8 00 04 00 00 8D 4E ?? 50 53 8B D0 E8 ?? ?? ?? ?? B8 08 02 00 00 8D 8E ?? ?? ?? ?? 50 57 8B D0 E8 ?? ?? ?? ?? } + $seq_cmd_dispatch = { 83 FE 29 0F 87 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 83 FE 06 0F 87 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? 8B C6 33 D2 2B C2 0F 84 ?? ?? ?? ?? 83 E8 01 } + $seq_icmp = { 59 6A 61 5E 89 45 ?? 8B D0 89 5D ?? 2B F0 8D 04 16 8D 4B ?? 88 0A 83 F8 77 7E ?? 80 E9 17 88 0A 43 42 83 FB 20 } condition: - $s1 and ($a1 or $a2) + 4 of ($str*) or 2 of ($seq*) } -rule ELASTIC_Linux_Cryptominer_Pgminer_Ccf88A37 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Banload_D5E1C189 : FILE MEMORY { meta: - description = "Detects Linux Cryptominer Pgminer (Linux.Cryptominer.Pgminer)" + description = "Detects Linux Trojan Banload (Linux.Trojan.Banload)" author = "Elastic Security" - id = "ccf88a37-2a58-40f9-8c13-f1ce218a2ec4" + id = "d5e1c189-7d19-4f03-a4f3-a0aaf6d499dc" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Cryptominer_Pgminer.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "3afc8d2d85aca61108d21f82355ad813eba7a189e81dde263d318988c5ea50bd" - logic_hash = "77833cdb319bc8e22db2503478677d5992774105f659fe7520177a691c83aa91" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Banload.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "48bf0403f777db5da9c6a7eada17ad4ddf471bd73ea6cf02817dd202b49204f4" + logic_hash = "3f0bee251152a8c835a3bf71dc33c2e150705713c50ca2cfdbeb69361ed91a09" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "dc82b841a7e72687921c9b14bc86218c3377f939166d11a7cccd885dad4a06e7" + fingerprint = "4aa04f08005b1b7ed941dbfc563737728099e35e3f0f025532921b91b79c967c" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61157,28 +65355,28 @@ rule ELASTIC_Linux_Cryptominer_Pgminer_Ccf88A37 : FILE MEMORY os = "linux" strings: - $a = { F6 41 83 C5 02 48 8B 5D 00 8A 0B 80 F9 2F 76 7E 41 83 FF 0A B8 0A 00 } + $a = { E4 E4 E4 58 88 60 90 E4 E4 E4 E4 68 98 70 A0 E4 E4 E4 E4 78 } condition: all of them } -rule ELASTIC_Linux_Cryptominer_Pgminer_5Fb2Efd5 : FILE MEMORY +rule ELASTIC_Linux_Exploit_Perl_4A4B8A42 : FILE MEMORY { meta: - description = "Detects Linux Cryptominer Pgminer (Linux.Cryptominer.Pgminer)" + description = "Detects Linux Exploit Perl (Linux.Exploit.Perl)" author = "Elastic Security" - id = "5fb2efd5-4adc-4285-bef1-6e4987066944" + id = "4a4b8a42-bf26-4323-a12d-06360cd88aa3" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Cryptominer_Pgminer.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "6d296648fdbc693e604f6375eaf7e28b87a73b8405dc8cd3147663b5e8b96ff0" - logic_hash = "4c247f40c9781332f04f82a244f6e8e22c9c744963f736937eddecf769b40a54" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Perl.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "d1fa8520d3c3811d29c3d5702e7e0e7296b3faef0553835c495223a2bc015214" + logic_hash = "c1f7b1c20fe6db6acbe46be38cc97a40de6ca047a4e4490e86610dbff356b395" score = 75 - quality = 75 + quality = 73 tags = "FILE, MEMORY" - fingerprint = "8ac56b60418e3f3f4d1f52c7a58d0b7c1f374611d45e560452c75a01c092a59b" + fingerprint = "70ae986009e1d375a0322bf31fbae2090b7c0b6051ddd850e103e654d7b237b2" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61186,59 +65384,57 @@ rule ELASTIC_Linux_Cryptominer_Pgminer_5Fb2Efd5 : FILE MEMORY os = "linux" strings: - $a = { 00 16 00 00 00 0E 00 00 00 18 03 00 7F EB 28 33 C5 56 5D F2 50 67 C5 6F } + $a = { 20 73 65 65 6B 69 6E 67 20 6F 75 74 20 74 68 65 20 73 6D 61 } condition: all of them } -rule ELASTIC_Windows_Trojan_Behinder_B9A49F4B : FILE MEMORY +rule ELASTIC_Linux_Exploit_Perl_982Bb709 : FILE MEMORY { meta: - description = "Webshell found in REF2924, either Behinder or Godzilla based shell in C#" + description = "Detects Linux Exploit Perl (Linux.Exploit.Perl)" author = "Elastic Security" - id = "b9a49f4b-5923-420e-a9e6-9bfa05c93bbf" - date = "2023-03-02" - modified = "2023-06-13" - reference = "https://www.elastic.co/security-labs/ref2924-howto-maintain-persistence-as-an-advanced-threat" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Behinder.yar#L1-L22" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "a50ca8df4181918fe0636272f31e19815f1b97cce6d871e15e03b0ee0e3da17b" - logic_hash = "2303ef82e4dc5e8be87ddc4563dcd06963d17e1fbf25cf246a6c81e4e74adbcb" + id = "982bb709-beec-4f7f-b249-44b1fb46c3be" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Perl.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "f3e4e2b5af9d0c72aae83cec57e5c091a95c549f826e8f13559aaf7d300f6e13" + logic_hash = "b38e6cb15034c38c31f6b267b9ecaabe8dfa950a2fc8863cfff7705182cffb3a" score = 75 quality = 73 tags = "FILE, MEMORY" - fingerprint = "cb7856a7d3e792cc60837587fe4afc04448af74cb5ce0478a09eb129e53bf7f1" - threat_name = "Windows.Trojan.Behinder" + fingerprint = "a2f68acb31b84e93f902aeb838ad550e1644c20e1c8060bb8de8ad57fa4ba4bb" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $load = { 53 79 73 74 65 6D 2E 52 65 66 6C 65 63 74 69 6F 6E 2E 41 73 73 65 6D 62 6C 79 } - $key = "e45e329feb5d925b" ascii wide + $a = { 54 75 65 20 53 65 70 20 32 31 20 31 36 3A 34 38 3A 31 32 20 } condition: all of them } -rule ELASTIC_Windows_Ransomware_Lockbit_89E64044 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Xpertrat_Ce03C41D : FILE MEMORY { meta: - description = "Detects Windows Ransomware Lockbit (Windows.Ransomware.Lockbit)" + description = "Detects Windows Trojan Xpertrat (Windows.Trojan.Xpertrat)" author = "Elastic Security" - id = "89e64044-74e4-4679-b6ad-bfb9b264330c" + id = "ce03c41d-d5c3-43f5-b3ca-f244f177d710" date = "2021-08-06" modified = "2021-10-04" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Lockbit.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0d6524b9a1d709ecd9f19f75fa78d94096e039b3d4592d13e8dbddf99867182d" - logic_hash = "bd504b078704b9f307a50c8556c143eee061015a9727670137aadc47ae93e2a6" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Xpertrat.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "d7f2fddb43eb63f9246f0a4535dfcca6da2817592455d7eceaacde666cf1aaae" + logic_hash = "f6ff0a11f261bc75c9d0015131f177d39bb9e8e30346a75209ba8fa808ac4fcb" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "ec45013d3ecbc39ffce5ac18d5bf8b0d18bcadd66659975b0a9f26bcae0a5b49" + fingerprint = "8aa4336ba6909c820f1164c78453629959e28cb619fda45dbe46291f9fbcbec4" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61246,281 +65442,236 @@ rule ELASTIC_Windows_Ransomware_Lockbit_89E64044 : FILE MEMORY os = "windows" strings: - $a1 = "\\LockBit_Ransomware.hta" wide fullword - $a2 = "\\Registry\\Machine\\Software\\Classes\\Lockbit\\shell" wide fullword - $a3 = "%s\\%02X%02X%02X%02X.lock" wide fullword + $a1 = "[XpertRAT-Mutex]" wide fullword + $a2 = "XPERTPLUGIN" wide fullword + $a3 = "keylog.tmp" wide fullword condition: all of them } -rule ELASTIC_Windows_Ransomware_Lockbit_A1C60939 : FILE MEMORY +rule ELASTIC_Windows_Hacktool_Leigod_89397Ebf : FILE { meta: - description = "Detects Windows Ransomware Lockbit (Windows.Ransomware.Lockbit)" + description = "Detects Windows Hacktool Leigod (Windows.Hacktool.LeiGod)" author = "Elastic Security" - id = "a1c60939-e257-420d-87ed-f31f30f2fc2a" - date = "2021-08-06" - modified = "2021-10-04" + id = "89397ebf-2fdb-4607-85a1-b9c378b4e256" + date = "2022-04-04" + modified = "2022-04-04" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Lockbit.yar#L23-L41" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0d6524b9a1d709ecd9f19f75fa78d94096e039b3d4592d13e8dbddf99867182d" - logic_hash = "6e6d88251e93f69788ad22fc915133f3ba0267984d6a5004d5ca44dcd9f5f052" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_LeiGod.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "ae5cc99f3c61c86c7624b064fd188262e0160645c1676d231516bf4e716a22d3" + logic_hash = "e887c34c624a182a3c57a55abe02784c4350d3956bcfd9f7918f08a464819e63" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "a41fb21e82ee893468393428d655b03ce251d23f34acb54bbf01ae0eb86817bf" - severity = 100 + tags = "FILE" + fingerprint = "04709d703cd0a062029a05baee160eb9579fe0503984f3059ce49e1bcfa6e963" + severity = 50 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" os = "windows" strings: - $a1 = { 3C 8B 4C 18 78 8D 04 19 89 45 F8 3B C3 74 70 33 C9 89 4D F4 39 } + $str1 = "\\Device\\CtrlLeiGod" wide fullword condition: - all of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1 } -rule ELASTIC_Windows_Ransomware_Lockbit_369E1E94 : FILE MEMORY +rule ELASTIC_Windows_Hacktool_Leigod_3F5C98C4 : FILE { meta: - description = "Detects Windows Ransomware Lockbit (Windows.Ransomware.Lockbit)" + description = "Detects Windows Hacktool Leigod (Windows.Hacktool.LeiGod)" author = "Elastic Security" - id = "369e1e94-3fbb-4828-bb78-89d26e008105" - date = "2022-07-05" - modified = "2022-07-18" + id = "3f5c98c4-03ba-4919-90b0-604d3cb9361e" + date = "2022-04-04" + modified = "2022-04-04" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Lockbit.yar#L43-L67" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "d61af007f6c792b8fb6c677143b7d0e2533394e28c50737588e40da475c040ee" - logic_hash = "c34dafc024d85902b85fc3424573abb8781d6fab58edd86c255266db3635ce98" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_LeiGod.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0c42fe45ffa9a9c36c87a7f01510a077da6340ffd86bf8509f02c6939da133c5" + logic_hash = "7570bf1a69df6b493bde41c1de27969e36a3fcb59be574ee2e24e3a61347a146" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "9cf4c112c0ee708ae64052926681e8351f1ccefeb558c41e875dbd9e4bdcb5f2" - severity = 100 + tags = "FILE" + fingerprint = "883dcad7097ad5713c4f45ce2fc232c3c1e61cf9dfdc81a194124d5995a64c9e" + severity = 50 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" os = "windows" strings: - $a1 = { 66 83 F8 61 72 ?? 66 83 F8 66 77 ?? 66 83 E8 57 EB ?? 66 83 F8 30 72 ?? 66 83 F8 39 77 ?? 66 83 E8 30 EB ?? } - $a2 = { 8B EC 53 56 57 33 C0 8B 5D ?? 33 C9 33 D2 8B 75 ?? 8B 7D ?? 85 F6 74 ?? 55 8B 6D ?? 8A 54 0D ?? 02 D3 8A 5C 15 ?? 8A 54 1D ?? } - $a3 = { 53 51 6A ?? 58 0F A2 F7 C1 ?? ?? ?? ?? 0F 95 C0 84 C0 74 ?? 0F C7 F0 0F C7 F2 59 5B C3 6A ?? 58 33 C9 0F A2 F7 C3 ?? ?? ?? ?? 0F 95 C0 84 C0 74 ?? 0F C7 F8 0F C7 FA 59 5B C3 0F 31 8B C8 C1 C9 ?? 0F 31 8B D0 C1 C2 ?? 8B C1 59 5B C3 } - $b1 = { 6D 00 73 00 65 00 78 00 63 00 68 00 61 00 6E 00 67 00 65 00 00 00 73 00 6F 00 70 00 68 00 6F 00 73 00 } - $b2 = "LockBit 3.0 the world's fastest and most stable ransomware from 2019" ascii fullword - $b3 = "http://lockbit" - $b4 = "Warning! Do not delete or modify encrypted files, it will lead to problems with decryption of files!" ascii fullword - - condition: - 2 of ($a*) or all of ($b*) -} -rule ELASTIC_Multi_EICAR_Ac8F42D6 : FILE MEMORY -{ - meta: - description = "Detects Multi Eicar Not A Virus (Multi.EICAR.Not-a-virus)" - author = "Elastic Security" - id = "ac8f42d6-52da-46ec-8db1-5a5f69222a38" - date = "2021-01-21" - modified = "2022-01-13" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_EICAR.yar#L1-L18" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "05c92058aab1229dfa31e006276c2c83fa484e813bdfe66edf387763797d9d57" - score = 75 - quality = 25 - tags = "FILE, MEMORY" - fingerprint = "bb0e0bdf70ec65d98f652e2428e3567013d5413f2725a2905b372fd18da8b9dd" - severity = 1 - arch_context = "x86, arm64" - scan_context = "file, memory" - license = "Elastic License v2" - os = "multi" - - strings: - $a = "X5O!P%@AP[4\\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*" ascii fullword + $str1 = "\\LgDCatcher.pdb" condition: - all of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1 } -rule ELASTIC_Multi_Ransomware_Blackcat_Aaf312C3 : FILE MEMORY +rule ELASTIC_Windows_Vulndriver_Llaccess_C57534E8 : FILE { meta: - description = "Detects Multi Ransomware Blackcat (Multi.Ransomware.BlackCat)" + description = "Name: Corsair LL Access, Version: 1.0.18.0" author = "Elastic Security" - id = "aaf312c3-47b4-4dab-b7fc-8a2ac9883772" - date = "2022-02-02" - modified = "2023-09-20" + id = "c57534e8-eb38-4714-9262-c489cc6204f1" + date = "2022-04-04" + modified = "2022-04-04" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_Ransomware_BlackCat.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0c6f444c6940a3688ffc6f8b9d5774c032e3551ebbccb64e4280ae7fc1fac479" - logic_hash = "0771ab5a795af164a568bda036cccf08afeb33458f2cd5a7240349fca9b60ead" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_LLAccess.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "000547560fea0dd4b477eb28bf781ea67bf83c748945ce8923f90fdd14eb7a4b" + logic_hash = "8bf629fd2ce0b1f15c7aacd573659b649dcf968556232683b29d68b27d12e577" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "577c7f24a7ecf89a542e9a63a1744a129c96c32e8dccfbf779dd9fc6c0194930" - severity = 100 + tags = "FILE" + fingerprint = "2eea8941c92353442f7a8986fa3abee06f83824e48bd6a3a5012f7cf76cd543e" + threat_name = "Windows.VulnDriver.LLAccess" + severity = 50 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" - os = "multi" + os = "windows" strings: - $chacha20_enc = { EF D9 F3 0F 7F 14 3B F3 0F 7F 5C 3B 10 83 C7 20 39 F8 75 D0 8B } - $crc32_imp = { F3 0F 6F 02 66 0F 6F D1 66 0F 3A 44 CD 11 83 C0 F0 83 C2 10 66 0F 3A 44 D4 00 83 F8 0F 66 0F EF C8 66 0F EF CA } + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 43 00 6F 00 72 00 73 00 61 00 69 00 72 00 20 00 4C 00 4C 00 20 00 41 00 63 00 63 00 65 00 73 00 73 00 00 00 } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x00][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x12][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x00][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\x11][\x00-\x00]))/ condition: - all of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version } -rule ELASTIC_Multi_Ransomware_Blackcat_00E525D7 : FILE MEMORY +rule ELASTIC_Linux_Webshell_Generic_E80Ff633 : FILE MEMORY { meta: - description = "Detects Multi Ransomware Blackcat (Multi.Ransomware.BlackCat)" + description = "Detects Linux Webshell Generic (Linux.Webshell.Generic)" author = "Elastic Security" - id = "00e525d7-a8a6-475f-89ad-607c452aea1e" - date = "2022-02-02" - modified = "2022-08-16" + id = "e80ff633-990e-4e2e-ac80-2e61685ab8b0" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_Ransomware_BlackCat.yar#L22-L43" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0c6f444c6940a3688ffc6f8b9d5774c032e3551ebbccb64e4280ae7fc1fac479" - logic_hash = "e44625d0fa8308b9d4d63a9e6920b4da4a2ce124437f122b2c8fe5cf0ab85a6b" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Webshell_Generic.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "7640ba6f2417931ef901044152d5bfe1b266219d13b5983d92ddbdf644de5818" + logic_hash = "d345e6ce3e51ed55064aafb1709e9bee7ef2ce87ec80165ac1b58eebd83cefee" score = 75 - quality = 50 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "631e30b8b51a5c0a0e91e8c09968663192569005b8bffff9f0474749788e9d57" + fingerprint = "dcca52dce2d50b0aa6cf0132348ce9dc234b985ae683b896d9971d409f109849" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "multi" + os = "linux" strings: - $a1 = "ata\",\"boot\",\"config.msi\",\"google\",\"perflogs\",\"appdata\",\"windows.old\"],\"exclude_file_names\":[\"desktop.ini\",\"aut" - $a2 = "locker::core::windows::processvssadmin.exe delete shadows /all /quietshadow_copy::remove_all=" ascii fullword - $a3 = "\\\\.\\pipe\\__rust_anonymous_pipe1__." ascii fullword - $a4 = "--bypass-p-p--bypass-path-path --no-prop-servers \\\\" ascii fullword + $a = { 24 A8 00 00 00 89 1C 24 83 3C 24 00 74 23 83 04 24 24 8D B4 24 AC 00 } condition: all of them } -rule ELASTIC_Multi_Ransomware_Blackcat_C4B043E6 : FILE MEMORY +rule ELASTIC_Linux_Webshell_Generic_41A5Fa40 : FILE MEMORY { meta: - description = "Detects Multi Ransomware Blackcat (Multi.Ransomware.BlackCat)" + description = "Detects Linux Webshell Generic (Linux.Webshell.Generic)" author = "Elastic Security" - id = "c4b043e6-ff5f-4492-94e3-fd688d690738" - date = "2022-09-12" - modified = "2022-09-29" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_Ransomware_BlackCat.yar#L45-L63" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "45b8678f74d29c87e2d06410245ab6c2762b76190594cafc9543fb9db90f3d4f" - logic_hash = "1262ca76581920f08a6482ead68023fdfff08a9ddd19e00230054e3167dc184c" + id = "41a5fa40-a4e7-4c97-a3b9-3700743265df" + date = "2021-06-28" + modified = "2021-09-16" + reference = "18ac7fbc3d8d3bb8581139a20a7fee8ea5b7fcfea4a9373e3d22c71bae3c9de0" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Webshell_Generic.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "574148bc58626aac00add1989c65ad56315c7e2a8d27c7b96be404d831a7a576" score = 75 - quality = 75 + quality = 73 tags = "FILE, MEMORY" - fingerprint = "3e89858e90632ad5f4831427bd630252113b735c51f7a1aa1eab8ba6e4c16f18" - severity = 100 + fingerprint = "49e0d55579453ec37c6757ddb16143d8e86ad7c7c4634487a1bd2215cd22df83" + severity = "100" arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "multi" + os = "linux" strings: - $a = { 28 4C 8B 60 08 4C 8B 68 10 0F 10 40 28 0F 29 44 24 10 0F 10 } + $a = { 5A 46 55 6C 73 6E 55 6B 56 52 56 55 56 54 56 46 39 56 55 6B 6B } condition: all of them } -rule ELASTIC_Multi_Ransomware_Blackcat_70171625 : FILE MEMORY +rule ELASTIC_Windows_Vulndriver_Cpuz_A53D1446 : FILE { meta: - description = "Detects Multi Ransomware Blackcat (Multi.Ransomware.BlackCat)" + description = "Name: cpuz.sys, Version: 1.0.4.3" author = "Elastic Security" - id = "70171625-c29b-47c1-b572-2e6dc846a907" - date = "2023-01-05" - modified = "2023-09-20" + id = "a53d1446-ebf7-44f3-843c-2ea5f043e168" + date = "2022-04-07" + modified = "2022-04-07" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_Ransomware_BlackCat.yar#L65-L91" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0c6f444c6940a3688ffc6f8b9d5774c032e3551ebbccb64e4280ae7fc1fac479" - logic_hash = "fd07acd7c8627754f000c44827848bf65bcaa96f2dfb46e41542f3c9b40eee78" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Cpuz.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "8c95d28270a4a314299cf50f05dcbe63033b2a555195d2ad2f678e09e00393e6" + logic_hash = "37da20f5fe1377fe85594055dc811424f52e53a9d77060c6784c2e4d1279e26f" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "f3f70f92fe9c044f4565fca519cb04a3a54536985c2614077ef92c3193fff9c1" - severity = 100 + tags = "FILE" + fingerprint = "1b74df56b73fa8d178a968427480332c6935e023af295e4fff5810bb66db6aab" + threat_name = "Windows.VulnDriver.Cpuz" + severity = 50 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" - os = "multi" + os = "windows" strings: - $str0 = "}RECOVER-${EXTENSION}-FILES.txt" - $str1 = "?access-key=${ACCESS_KEY}" - $str2 = "${NOTE_FILE_NAME}" - $str3 = "enable_network_discovery" - $str4 = "enable_set_wallpaper" - $str5 = "enable_esxi_vm_kill" - $str6 = "strict_include_paths" - $str7 = "exclude_file_path_wildcard" - $str8 = "${ACCESS_KEY}${EXTENSION}" + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 63 00 70 00 75 00 7A 00 2E 00 73 00 79 00 73 00 00 00 } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x00][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x03][\x00-\x00])([\x00-\x04][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x00][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\x03][\x00-\x00]))/ condition: - all of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version } -rule ELASTIC_Multi_Ransomware_Blackcat_E066D802 : FILE MEMORY +rule ELASTIC_Macos_Backdoor_Applejeus_31872Ae2 : FILE MEMORY { meta: - description = "Detects Multi Ransomware Blackcat (Multi.Ransomware.BlackCat)" + description = "Detects Macos Backdoor Applejeus (MacOS.Backdoor.Applejeus)" author = "Elastic Security" - id = "e066d802-b803-4e35-9b53-ae1823662483" - date = "2023-07-27" - modified = "2023-09-20" + id = "31872ae2-f6df-4079-89c2-866cb2e62ec8" + date = "2021-10-18" + modified = "2021-10-25" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_Ransomware_BlackCat.yar#L93-L113" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "00360830bf5886288f23784b8df82804bf6f22258e410740db481df8a7701525" - logic_hash = "00fbb8013faf26c35b6cd8a72ebc246444c37c5ec7a0df2295830e96c01c8720" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Backdoor_Applejeus.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "e352d6ea4da596abfdf51f617584611fc9321d5a6d1c22aff243aecdef8e7e55" + logic_hash = "1d6f06668a7d048a93e53b294c5ab8ffe4cd610f3bef3fd80f14425ef8a85a29" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "05037af3395b682d1831443757376064c873815ac4b6d1c09116715570f51f5d" + fingerprint = "24b78b736f691e6b84ba88b0bb47aaba84aad0c0e45cf70f2fa8c455291517df" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "multi" + os = "macos" strings: - $a1 = "esxcli vm process kill --type=force --world-id=Killing" - $a2 = "vim-cmd vmsvc/snapshot.removeall $i" - $a3 = "File already has encrypted extension" + $a = { FF CE 74 12 89 F0 31 C9 80 34 0F 63 48 FF C1 48 39 C8 75 F4 } condition: - 2 of them + all of them } -rule ELASTIC_Windows_Ransomware_Avoslocker_7Ae4D4F2 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Metastealer_F94E2464 : FILE MEMORY { meta: - description = "Detects Windows Ransomware Avoslocker (Windows.Ransomware.Avoslocker)" + description = "Detects Windows Trojan Metastealer (Windows.Trojan.MetaStealer)" author = "Elastic Security" - id = "7ae4d4f2-be5f-4aad-baaa-4182ff9cf996" - date = "2021-07-28" - modified = "2021-08-23" + id = "f94e2464-b41a-46fd-89c1-335aa8c14425" + date = "2024-03-27" + modified = "2024-05-08" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Avoslocker.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "43b7a60c0ef8b4af001f45a0c57410b7374b1d75a6811e0dfc86e4d60f503856" - logic_hash = "c87faf6f128fd6a8cabd68ec8de72fb10e6be42bdbe23ece374dd8f3cf0c1b15" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_MetaStealer.yar#L1-L34" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "14ca15c0751207103c38f1a2f8fdc73e5dd3d58772f6e5641e54e0c790ecd132" + logic_hash = "bf374bda2ca7c7bcec1ff092bbc9c3fd95c33faa78a6ea105a7b12b8e80a2e23" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "0e5ff268ed2b62f9d31df41192135145094849a4e6891407568c3ea27ebf66bb" + fingerprint = "fb35feaf8e2d0994d022da1c8e872dc8b05b04e25ab6fed2ed1997267edfccd9" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61528,119 +65679,140 @@ rule ELASTIC_Windows_Ransomware_Avoslocker_7Ae4D4F2 : FILE MEMORY os = "windows" strings: - $a1 = "drive %s took %f seconds" ascii fullword - $a2 = "client_rsa_priv: %s" ascii fullword - $a3 = "drive: %s" ascii fullword - $a4 = "Map: %s" ascii fullword - $a5 = "encrypting %ls failed" wide fullword + $string1 = "AvailableLanguages" fullword + $string2 = "GetGraphicCards" fullword + $string3 = "GetVs" fullword + $string4 = "GetSerialNumber" fullword + $string5 = "net.tcp://" wide + $string6 = "AntivirusProduct|AntiSpyWareProduct|FirewallProduct" wide + $string7 = "wallet.dat" wide + $string8 = "[A-Za-z\\d]{24}\\.[\\w-]{6}\\.[\\w-]{27}" wide + $string9 = "Software\\Valve\\Steam" wide + $string10 = "{0}\\FileZilla\\recentservers.xml" wide + $string11 = "{0}\\FileZilla\\sitemanager.xml" wide + $string12 = "([a-zA-Z0-9]{1000,1500})" wide + $string13 = "\\qemu-ga.exe" wide + $string14 = "metaData" wide + $string15 = "%DSK_23%" wide + $string16 = "CollectMemory" fullword condition: all of them } -rule ELASTIC_Linux_Exploit_Lotoor_03C81Bd9 : FILE MEMORY +rule ELASTIC_Windows_Hacktool_Capcom_7Abae448 : FILE { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Subject: CAPCOM Co.,Ltd." author = "Elastic Security" - id = "03c81bd9-c7d1-4044-9cce-951637b2b523" - date = "2021-01-12" - modified = "2021-09-16" + id = "7abae448-0ebc-433f-b368-0b8560da7197" + date = "2022-04-07" + modified = "2022-04-07" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "3fc701a2caab0297112501f55eaeb05264c5e4099c411dcadc7095627e19837a" - logic_hash = "dc2dfa128f509221cae8bae9864190e8316bb7a5ae081da1076081b5f4fdc870" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_Capcom.yar#L1-L20" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "da6ca1fb539f825ca0f012ed6976baf57ef9c70143b7a1e88b4650bf7a925e24" + logic_hash = "88f25c479cc8970e05ef9d08143afbbbfa17322f34379ba571e3a09105b33ee0" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "329dc1e21088c87095ee030c597a3340f838c338403ae64aec574e0086281461" - severity = 100 + tags = "FILE" + fingerprint = "965e85fc3b2a21aef84c7c2bd59708b121d9635ce6bab177014b28fb00102884" + threat_name = "Windows.Hacktool.Capcom" + severity = 50 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 65 00 65 78 70 5F 73 74 61 74 65 00 6D 65 6D 73 65 74 00 70 } + $subject_name = { 06 03 55 04 03 [2] 43 41 50 43 4F 4D 20 43 6F 2E 2C 4C 74 64 2E } condition: - all of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and $subject_name } -rule ELASTIC_Linux_Exploit_Lotoor_757637D9 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Nimplant_44Ff3211 : FILE MEMORY { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Detects Windows Trojan Nimplant (Windows.Trojan.Nimplant)" author = "Elastic Security" - id = "757637d9-6171-4e2a-bf7c-3ee2c71066a7" - date = "2021-01-12" - modified = "2021-09-16" + id = "44ff3211-1ba6-4c46-a990-b2419d88367e" + date = "2023-06-23" + modified = "2023-07-10" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0762fa4e0d74e3c21b2afc8e4c28e2292d1c3de3683c46b5b77f0f9fe1faeec7" - logic_hash = "b1f1784aae5958740d03ca50d0b9731e8db7d86d918d16e82cf6fc1e1bf663a9" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Nimplant.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b56e20384f98e1d2417bb7dcdbfb375987dd075911b74ea7ead082494836b8f4" + logic_hash = "ee519d8d722404ed440b385d283a41921bc34ee11f0e7273cdc074b377494c39" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "7fa3e2432ddd696b5d40aafbde1e026e74294d31c9201800ce66b343a3724c6e" + fingerprint = "cb7f823b1621e49ffac42e8a3f90ca7f8bac7ae108ca20b9a0884548681d1f87" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 64 00 73 70 72 69 6E 74 66 00 6F 70 65 6E 00 69 73 5F 6F 6C } + $a1 = "@NimPlant v" + $a2 = ".Env_NimPlant." + $a3 = "NimPlant.dll" condition: - all of them + 2 of them } -rule ELASTIC_Linux_Exploit_Lotoor_78543893 : FILE MEMORY +rule ELASTIC_Windows_Hacktool_Sharplaps_381C3F40 : FILE MEMORY { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Detects Windows Hacktool Sharplaps (Windows.Hacktool.SharpLAPS)" author = "Elastic Security" - id = "78543893-7180-4857-8951-4190ca4602f1" - date = "2021-01-12" - modified = "2021-09-16" + id = "381c3f40-b6c6-4e50-be28-3d34ba07b644" + date = "2022-12-22" + modified = "2022-12-22" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L41-L59" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "ff5b02d2b4dfa9c3d53e7218533f3c57e82315be8f62aa17e26eda55a3b53479" - logic_hash = "4bb6a6e063fd00569b04f4514ec1731357aa8e8ce4cfee354fdd86773a4358da" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_SharpLAPS.yar#L1-L26" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "ef0d508b3051fe6f99ba55202a17237f29fdbc0085e3f5c99b1aef52c8ebe425" + logic_hash = "d94f9e4200a63283346919c121873130ad90e4ad5979c017cb71dc0cc910a64a" score = 75 - quality = 75 + quality = 73 tags = "FILE, MEMORY" - fingerprint = "b581e0820d7895021841d67e4e9dc40cec8f5ae5ba4dbc0585abcb76f97c9a2f" + fingerprint = "556b9ba9c0a2f08ff0b27e38e273f5817011de335436feb2a30cac74285d7e4f" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 00 48 8B 48 08 48 8B 54 24 F0 48 63 C6 48 89 8C C2 88 00 00 00 83 44 24 } + $guid = "1e0986b4-4bf3-4cea-a885-347b6d232d46" ascii wide nocase + $str_name = "SharpLAPS.exe" ascii wide + $str0 = "Using the current session" ascii wide + $str1 = "Extracting LAPS password" ascii wide + $str2 = "(&(objectCategory=computer)(ms-MCS-AdmPwd=*)(sAMAccountName=" ascii wide + $str4 = "Machine" ascii wide + $str5 = "sAMAccountName" ascii wide + $str6 = "ms-Mcs-AdmPwd" ascii wide condition: - all of them + $guid or 6 of ($str*) } -rule ELASTIC_Linux_Exploit_Lotoor_4F8D83D2 : FILE MEMORY +rule ELASTIC_Linux_Exploit_CVE_2012_0056_06B2Dff5 : FILE MEMORY CVE_2012_0056 { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Detects Linux Exploit Cve 2012 0056 (Linux.Exploit.CVE-2012-0056)" author = "Elastic Security" - id = "4f8d83d2-4f7b-4a55-9d08-f7bc84263302" + id = "06b2dff5-250a-46e0-b763-8e6b04498fe2" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L61-L79" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "d78128eca706557eeab8a454cf875362a097459347ddc32118f71bd6c73d5bbd" - logic_hash = "6fee488d97fe1d4be558b6886c603010c6d1423a750783b38a65d2fb3eeb76f4" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_CVE_2012_0056.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "168b3fb1c675ab76224c641e228434495160502a738b64172c679e8ce791ac17" + logic_hash = "4361e6e74d6678d9e0823b23a7a2e4ae84119142cad319950154f806115845d5" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "1a4e2746eb1da2a841c08ea44c6d0476c02dae5b4fbbe17926433bdb8c4e6df5" + tags = "FILE, MEMORY, CVE-2012-0056" + fingerprint = "82b200deae93c8fa376d670f5091d9a63730a6f5b5e8a0567fe9c283075d57c0" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61648,28 +65820,28 @@ rule ELASTIC_Linux_Exploit_Lotoor_4F8D83D2 : FILE MEMORY os = "linux" strings: - $a = { 00 75 6E 61 6D 65 00 73 74 64 6F 75 74 00 66 77 72 69 74 65 00 } + $a = { 20 66 64 20 69 6E 20 70 61 72 65 6E 74 2E 00 5B 2B 5D 20 52 65 63 } condition: all of them } -rule ELASTIC_Linux_Exploit_Lotoor_F4Afd230 : FILE MEMORY +rule ELASTIC_Linux_Exploit_CVE_2012_0056_B39839F4 : FILE MEMORY CVE_2012_0056 { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Detects Linux Exploit Cve 2012 0056 (Linux.Exploit.CVE-2012-0056)" author = "Elastic Security" - id = "f4afd230-6c9f-49e8-8f13-429635b38eb5" + id = "b39839f4-e6f4-44bd-a636-ce355f3c5c6a" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L81-L99" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "805e900ffc9edb9f550dcbc938a3b06d28e9e7d3fb604ff68a311a0accbcd2b1" - logic_hash = "9aba4ebbf946f07071bfb94fa50c6981ae8c659aca9ee6e05c7ef214432d7466" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_CVE_2012_0056.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "cf569647759e011ff31d8626cea65ed506e8d0ef1d26f3bbb7c02a4060ce58dc" + logic_hash = "553111c64d8abfc3688a88dd95088de0ea7e92f68592e9a778f8041b40071e84" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "1709244fdc1e2d9d7fba01743b0cf87de7b940d2b25a0016e021b7e9696525bc" + tags = "FILE, MEMORY, CVE-2012-0056" + fingerprint = "f269c4aecbb55e24d9081d7a1e4bd6cfa9799409b3a3d7a6f9bf127f7468dedc" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61677,28 +65849,28 @@ rule ELASTIC_Linux_Exploit_Lotoor_F4Afd230 : FILE MEMORY os = "linux" strings: - $a = { 83 20 FF FF FF 85 C0 74 25 8B 83 F8 FF FF FF 85 C0 74 1B 83 } + $a = { 08 02 7E 3E 8B 45 0C 83 C0 04 8B 00 0F B6 00 3C 2D 75 2F 8B } condition: all of them } -rule ELASTIC_Linux_Exploit_Lotoor_Bb384Bc9 : FILE MEMORY +rule ELASTIC_Linux_Exploit_CVE_2012_0056_A1E53450 : FILE MEMORY CVE_2012_0056 { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Detects Linux Exploit Cve 2012 0056 (Linux.Exploit.CVE-2012-0056)" author = "Elastic Security" - id = "bb384bc9-fcda-4ad4-82ad-b95de750d31c" - date = "2021-01-12" + id = "a1e53450-036e-4ae3-bfe4-64a6c7239a04" + date = "2021-04-06" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L101-L119" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "ecc6635117b99419255af5d292a7af3887b06d5f3b0f59d158281eebfe606445" - logic_hash = "1e9faba4f245d8b0d6944430286a5fc3e11cd7e036a4151b29fc2c5f037894fb" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_CVE_2012_0056.yar#L41-L59" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "15a4d149e935758199f6df946ff889e12097f5fec4ef450e9cbd554d1efbd5e6" + logic_hash = "f2ab5de83c36a9a834e41c8f6fdccd0dffdeb384adf7b1e1098e86a2ac52df18" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "6878670c1fa154f5c4a845a824c63d0a900359b6e122b3fa759077c6a7e33e4c" + tags = "FILE, MEMORY, CVE-2012-0056" + fingerprint = "d0a0635fb356ccedb1448082cc63748d49d45f8a25e43eab7ac1d67e87062b8f" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61706,115 +65878,130 @@ rule ELASTIC_Linux_Exploit_Lotoor_Bb384Bc9 : FILE MEMORY os = "linux" strings: - $a = { C2 75 64 4C 8B 45 F0 49 83 C0 04 4C 8B 4D F0 49 83 C1 08 48 8B } + $a = { 80 31 C9 B3 ?? B1 02 B0 3F CD 80 31 C0 50 68 6E } condition: all of them } -rule ELASTIC_Linux_Exploit_Lotoor_B293F6Ec : FILE MEMORY +rule ELASTIC_Windows_Backdoor_Goldbackdoor_91902940 : FILE MEMORY { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Detects Windows Backdoor Goldbackdoor (Windows.Backdoor.Goldbackdoor)" author = "Elastic Security" - id = "b293f6ec-0342-4727-b2a1-bd60be11ef74" - date = "2021-01-12" - modified = "2021-09-16" + id = "91902940-a291-4fc6-81c5-2cde2328e8d9" + date = "2022-04-29" + modified = "2022-06-09" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L121-L139" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "d1fa8520d3c3811d29c3d5702e7e0e7296b3faef0553835c495223a2bc015214" - logic_hash = "0e310082714f5283f9b4ccde5a8e17994e3bc4acf3d744b22734c136dde7cebb" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Backdoor_Goldbackdoor.yar#L1-L26" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "485246b411ef5ea9e903397a5490d106946a8323aaf79e6041bdf94763a0c028" + logic_hash = "71e26cce6d730560e1303b2a4f49d0da6d1341263bb47ade46338f03e528cbf7" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "42c95bdd82e398bceeb985cff50f4613596b71024c052487f5b337bb35489594" + fingerprint = "83a404a24e54bd05319d3df3a830f1ffe51d30f71ca55d63ca152d5169511df4" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { B8 89 45 A8 8B 45 A8 83 C0 64 89 45 B4 EB 2A 8B 45 A8 48 98 48 C1 } + $pdf = "D:\\Development\\GOLD-BACKDOOR\\" + $agent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.3112.113 Safari/537.36" + $str0 = "client_id" + $str1 = "client_secret" + $str2 = "redirect_uri" + $str3 = "refresh_token" + $a = { 56 57 8B 7D 08 8B F1 6A 00 6A 00 6A 00 6A 00 68 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? 89 46 30 85 C0 75 ?? 33 C0 5F 5E } + $b = { 66 8B 02 83 C2 02 66 85 C0 75 ?? 2B D1 D1 FA 75 ?? 33 C0 E9 ?? ?? ?? ?? 6A 40 8D 45 ?? 6A 00 50 E8 } condition: - all of them + ($pdf and $agent) or ( all of ($str*) and $a and $b) } -rule ELASTIC_Linux_Exploit_Lotoor_C5983669 : FILE MEMORY +rule ELASTIC_Windows_Backdoor_Goldbackdoor_F11D57Df : FILE MEMORY { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Detects Windows Backdoor Goldbackdoor (Windows.Backdoor.Goldbackdoor)" author = "Elastic Security" - id = "c5983669-67d6-4a9e-945f-aae383211872" - date = "2021-01-12" - modified = "2021-09-16" + id = "f11d57df-8dd4-481c-a557-f83ae05d53fe" + date = "2022-04-29" + modified = "2022-06-09" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L141-L159" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "d08be92a484991afae3567256b6cec60a53400e0e9b6f6b4d5c416a22ccca1cf" - logic_hash = "ff673070969f1ededf8ff2c7cadfc251c7d2e52da58906b15cfc04593a755d55" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Backdoor_Goldbackdoor.yar#L28-L51" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "45ece107409194f5f1ec2fbd902d041f055a914e664f8ed2aa1f90e223339039" + logic_hash = "6401b215523289a3842dec6d3e016a2ca99512c5889e87cb5ff13023bb0b8e1e" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "1d74ddacc623a433f84b1ab6e74bcfc0e69afb29f40a8b2d660d96a88610c3b2" + fingerprint = "fed0317d43910d962908604812c2cd1aff6e67f7e245c82b39f2ac6dc14b6edb" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 48 83 C0 58 48 89 44 24 20 48 8B 44 24 18 48 89 C7 BA 60 00 } + $a = { C7 45 ?? 64 69 72 25 C7 45 ?? 5C 53 79 73 C7 45 ?? 74 65 6D 33 C7 45 ?? 32 5C 00 00 C7 45 ?? 2A 2E 65 78 C7 45 ?? 65 00 00 00 E8 ?? ?? ?? ?? FF D0 } + $b = { B9 18 48 24 9D E8 ?? ?? ?? ?? FF D0 } + $c = { B9 F8 92 FA 98 E8 ?? ?? ?? ?? FF D0 } + $a1 = { 64 A1 30 00 00 00 53 55 56 } + $b1 = { B9 76 DB 7A AA 6A 40 68 00 30 00 00 FF 75 ?? 50 E8 ?? ?? ?? ?? FF D0 } + $c1 = { B9 91 51 13 EE 50 68 80 00 00 00 6A 04 50 50 ?? ?? ?? ?? ?? ?? ?? 6A 04 50 E8 ?? ?? ?? ?? FF D0 } condition: all of them } -rule ELASTIC_Linux_Exploit_Lotoor_Fbff22Da : FILE MEMORY +rule ELASTIC_Windows_Vulndriver_Mhyprot_26214176 : FILE { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Subject: miHoYo Co.,Ltd., Version: 1.0.0.0" author = "Elastic Security" - id = "fbff22da-2f31-416c-8aa0-1003e3be8baa" - date = "2021-01-12" - modified = "2021-09-16" + id = "26214176-1565-4b10-bd7a-901206ef6b29" + date = "2022-08-25" + modified = "2022-08-25" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L161-L179" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0762fa4e0d74e3c21b2afc8e4c28e2292d1c3de3683c46b5b77f0f9fe1faeec7" - logic_hash = "d3e3037593f5714dfb49c6e19631fd46331e2702c8bf6d6099bb5b34158321a9" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Mhyprot.yar#L1-L22" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "509628b6d16d2428031311d7bd2add8d5f5160e9ecc0cd909f1e82bbbb3234d6" + logic_hash = "61d1713c689b9d663f2d3360d07735b07ca10365b5ce424b2df726bd6cc434d3" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "b649b172fad3e3b085cbf250bd17dbea4c409a7337914c63230d188f9b8135fa" + tags = "FILE" + fingerprint = "368c818c0052192c73f078a0ea314e3d2f5d08bc4ef32a27d7e01a40eba68940" + threat_name = "Windows.VulnDriver.Mhyprot" severity = 100 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 00 75 6E 61 6D 65 00 73 74 72 6C 65 6E 00 73 74 64 6F 75 74 00 } + $subject_name = { 06 03 55 04 03 [2] 6D 69 48 6F 59 6F 20 43 6F 2E 2C 4C 74 64 2E } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x00][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ + $str1 = "\\Device\\mhyprot2" wide fullword condition: - all of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and int16 ( uint32(0x3C)+0x18)==0x020b and $subject_name and $version and $str1 } -rule ELASTIC_Linux_Exploit_Lotoor_E2D5Fad8 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Sdbot_98628Ea1 : FILE MEMORY { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Detects Linux Trojan Sdbot (Linux.Trojan.Sdbot)" author = "Elastic Security" - id = "e2d5fad8-45b6-4d65-826d-b909230e2b69" + id = "98628ea1-40d8-4a05-835f-a5a5f83637cb" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L181-L199" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "7e54e57db3de32555c15e529c04b35f52d75af630e45b5f8d6c21149866b6929" - logic_hash = "b294ce1c4d928d73342bb6260456d850f9c59f3c48c7c4ffbce32ea9238f6eee" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Sdbot.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "5568ae1f8a1eb879eb4705db5b3820e36c5ecea41eb54a8eef5b742f477cbdd8" + logic_hash = "55b8e3fa755965b85a043015f9303644b8e06fe8bfdc0e2062de75bdc2881541" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "ec64f2c3ca5ec2bfc2146159dab3258e389be5962bdddf4c6db5975cc730a231" + fingerprint = "15cf6b916dd87915738f3aa05a2955c78a357935a183c0f88092d808535625a5" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -61822,264 +66009,286 @@ rule ELASTIC_Linux_Exploit_Lotoor_E2D5Fad8 : FILE MEMORY os = "linux" strings: - $a = { 8B 45 E4 8B 00 89 45 E8 8B 45 E8 8B 00 85 C0 75 08 8B 45 E8 89 } + $a = { 54 00 3C 08 54 00 02 00 26 00 00 40 4D 08 00 5C 00 50 00 49 00 } condition: all of them } -rule ELASTIC_Linux_Exploit_Lotoor_F2F8Eb6B : FILE MEMORY +rule ELASTIC_Windows_Ransomware_Conti_89F3F6Fa : FILE MEMORY { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Detects Windows Ransomware Conti (Windows.Ransomware.Conti)" author = "Elastic Security" - id = "f2f8eb6b-1fc3-4fca-b58d-d71ad932e1a7" - date = "2021-01-12" - modified = "2021-09-16" + id = "89f3f6fa-492c-40e3-a4aa-a526004197b2" + date = "2021-08-05" + modified = "2021-10-04" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L201-L219" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "01721b9c024ca943f42c402a57f45bd4c77203a604c5c2cd26e5670df76a95b2" - logic_hash = "b6555e69b663591550976fd44352ecbdf0a0aef1e07a64396a576125a4fe4ba6" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Conti.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "eae876886f19ba384f55778634a35a1d975414e83f22f6111e3e792f706301fe" + logic_hash = "4c1834e45d5e42f466249b75a89561ce1e88b9e3c07070e2833d4897fbed22ee" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "881e2cd5b644c2511306b3670320224810de369971278516f7562076226fa5b7" + fingerprint = "a82331eba3cbd52deb4bed5e11035ac1e519ec27931507f582f2985865c0fb1a" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 24 14 40 00 00 00 EB 38 8B 44 24 14 48 98 83 E0 3F 48 85 C0 } + $a = { F7 FE 88 57 FF 83 EB 01 75 DA 8B 45 FC 5F 5B 40 5E 8B E5 5D C3 8D } condition: all of them } -rule ELASTIC_Linux_Exploit_Lotoor_89671B03 : FILE MEMORY +rule ELASTIC_Windows_Ransomware_Clop_6A1670Aa : BETA FILE MEMORY { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Identifies CLOP ransomware in unpacked state" author = "Elastic Security" - id = "89671b03-5bd4-481b-9304-2655ea689c5f" - date = "2021-04-06" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L241-L259" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "001098473574cfac1edaca9f1180ab2005569e094be63186c45b48c18f880cf8" - logic_hash = "dfa7027c4fa0cbde33df87063fea4ecf51a085f3cc1805123c62747882d0a07e" + id = "6a1670aa-7f78-455b-9e28-f39ed4c6476e" + date = "2020-05-03" + modified = "2021-08-23" + reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.clop" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Clop.yar#L1-L20" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "afe28000d50495bf2f2adc6cbf0159591ce87bff207f3c6a1d38e09f9ed328d7" score = 75 - quality = 73 - tags = "FILE, MEMORY" - fingerprint = "e8b9631e5d4d8db559615504cc3f6fbd8a81bfbdb9e570113f20d006c44c8a9c" + quality = 75 + tags = "BETA, FILE, MEMORY" + fingerprint = "7c24cc6a519922635a519dad412d1a07728317b91f90a120ccc1c7e7e2c8a002" + threat_name = "Windows.Ransomware.Clop" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 62 65 6C 3A 20 4C 69 6E 75 78 20 3C 20 32 2E 36 } + $b1 = { FF 15 04 E1 40 00 83 F8 03 74 0A 83 F8 02 } condition: - all of them + 1 of ($b*) } -rule ELASTIC_Linux_Exploit_Lotoor_Dbc73Db0 : FILE MEMORY +rule ELASTIC_Windows_Ransomware_Clop_E04959B5 : BETA FILE MEMORY { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Identifies CLOP ransomware in unpacked state" author = "Elastic Security" - id = "dbc73db0-527c-436f-afdc-bc3750f10ea0" - date = "2021-04-06" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L261-L279" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "9fe78e4dd7975856a74d8dfd83e69793a769143e0fe6994cbc3ef28ea37d6cf8" - logic_hash = "4a7453342fd72dacb781919d3fac3bab02e7ef7c882d5938a2e0e1274c704705" + id = "e04959b5-f3da-428d-8b56-8a9817fdebe0" + date = "2020-05-03" + modified = "2021-08-23" + reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.clop" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Clop.yar#L22-L50" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "039fcb0e48898c7546588cd095fac16f06cf5e5568141aefb6db382a61e80a8d" score = 75 - quality = 73 - tags = "FILE, MEMORY" - fingerprint = "2f6ad833b84f00be1d385de686a979d3738147c38b4126506e56225080ee81ef" + quality = 50 + tags = "BETA, FILE, MEMORY" + fingerprint = "7367b90772ce6db0d639835a0a54a994ef8ed351b6dadff42517ed5fbc3d0d1a" + threat_name = "Windows.Ransomware.Clop" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 63 75 73 3A 20 4C 69 6E 75 78 20 32 2E 36 2E 33 } + $a1 = "-%s\\CIopReadMe.txt" wide fullword + $a2 = "CIopReadMe.txt" wide fullword + $a3 = "%s-CIop^_" wide fullword + $a4 = "%s%s.CIop" wide fullword + $a5 = "BestChangeT0p^_-666" ascii fullword + $a6 = ".CIop" wide fullword + $a7 = "A%s\\ClopReadMe.txt" wide fullword + $a8 = "%s%s.Clop" wide fullword + $a9 = "CLOP#666" wide fullword + $a10 = "MoneyP#666" wide fullword condition: - all of them + 1 of ($a*) } -rule ELASTIC_Linux_Exploit_Lotoor_Ec339160 : FILE MEMORY +rule ELASTIC_Windows_Ransomware_Clop_9Ac9Ea3E : BETA FILE MEMORY { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Identifies CLOP ransomware in unpacked state" author = "Elastic Security" - id = "ec339160-5f25-495c-8e48-4683ad2fcca0" - date = "2021-04-06" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L281-L299" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0002b469972f5c77a29e2a2719186059a3e96a6f4b1ef2d18a68fee3205ea0ba" - logic_hash = "9c1d1254093b172798024c42a6d78f5e6720d20b8c2a8ad4ca26c8e88e42f0e8" + id = "9ac9ea3e-72e1-4151-a2f8-87869f5f98e3" + date = "2020-05-03" + modified = "2021-08-23" + reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.clop" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Clop.yar#L52-L71" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "1228ee4b934faf1d5f8cf4518974cd2c80a73d84c8a354bde4813fb97ba516d7" score = 75 - quality = 73 - tags = "FILE, MEMORY" - fingerprint = "24a3630fd49860104c60c4f4d0ef03bd17c124383a0b5d027a06c7ca6cb9cbba" + quality = 75 + tags = "BETA, FILE, MEMORY" + fingerprint = "1cb0adb36e94ef8f8d74862250205436ed3694ed7719d8e639cfdd0c8632fd6c" + threat_name = "Windows.Ransomware.Clop" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 69 75 6D 3A 20 4C 69 6E 75 78 20 32 2E 58 20 73 } + $c1 = { 8B 1D D8 E0 40 00 33 F6 8B 3D BC E0 40 00 } condition: - all of them + 1 of ($c*) } -rule ELASTIC_Linux_Exploit_Lotoor_7Cd57E18 : FILE MEMORY +rule ELASTIC_Windows_Ransomware_Clop_606020E7 : BETA FILE MEMORY { meta: - description = "Detects Linux Exploit Lotoor (Linux.Exploit.Lotoor)" + description = "Identifies CLOP ransomware in unpacked state" author = "Elastic Security" - id = "7cd57e18-2315-419b-b373-ea801181232c" - date = "2021-04-06" - modified = "2021-09-16" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Lotoor.yar#L301-L319" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "1eecf16dae302ae788d1bc81278139cd9f6af52d7bed48b8677b35ba5eb14e30" - logic_hash = "97604cdc9daa9993b9a18dc5df7ab105a5e6001129bcfcfeeb86640bee26f59d" + id = "606020e7-ce1a-4a48-b801-100fd22b3791" + date = "2020-05-03" + modified = "2021-08-23" + reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.clop" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Clop.yar#L73-L92" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + logic_hash = "f5169b324bc19f6f5a04c99f1d3326c97300d038ec383c3eab94eb258963ac30" score = 75 - quality = 73 - tags = "FILE, MEMORY" - fingerprint = "a7d3183de1bccd816bcd2346e9754aaf6e7eb124d7416d79bdbe422b33035414" + quality = 75 + tags = "BETA, FILE, MEMORY" + fingerprint = "5ec4e00ddf2cb1315ec7d62dd228eee0d9c15fafe4712933d42e868f83f13569" + threat_name = "Windows.Ransomware.Clop" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 76 65 3A 20 4C 69 6E 75 78 20 32 2E 36 2E } + $d1 = { B8 E1 83 0F 3E F7 E6 8B C6 C1 EA 04 8B CA C1 E1 05 03 CA } condition: - all of them + 1 of ($d*) } -rule ELASTIC_Linux_Trojan_Xpmmap_7Dcc3534 : FILE MEMORY +rule ELASTIC_Windows_Hacktool_Sharpview_2C7603Ad : FILE MEMORY { meta: - description = "Detects Linux Trojan Xpmmap (Linux.Trojan.Xpmmap)" + description = "Detects Windows Hacktool Sharpview (Windows.Hacktool.SharpView)" author = "Elastic Security" - id = "7dcc3534-e94c-4c92-ac9b-a82b00fb045b" - date = "2021-04-06" - modified = "2021-09-16" + id = "2c7603ad-27f4-49fc-9fab-f4284620452f" + date = "2022-10-20" + modified = "2022-11-24" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Xpmmap.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "765546a981921187a4a2bed9904fbc2ccb2a5876e0d45c72e79f04a517c1bda3" - logic_hash = "f88cc0f02797651e8cdf8e25b67a92f7825ec616b79df21daae798b613baf334" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_SharpView.yar#L1-L34" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c0621954bd329b5cabe45e92b31053627c27fa40853beb2cce2734fa677ffd93" + logic_hash = "1f80b2fd6121c2b36742c819a56626af2e1450dac0f62c67d93f09e4e140b75f" score = 75 - quality = 75 + quality = 73 tags = "FILE, MEMORY" - fingerprint = "397618543390fb8fd8b198f63034fe88b640408d75b769fb337433138dafcf66" + fingerprint = "379606da5cf6adb58d6a8e693d379252f7987ff295f838df092ce2246da08354" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a = { 48 89 45 F8 48 83 7D F8 FF 75 14 BF 10 0C 40 00 } + $guid = "22A156EA-2623-45C7-8E50-E864D9FC44D3" ascii wide nocase + $print_str0 = "[Add-DomainObjectAcl] Granting principal {0} rights GUID '{1}' on {2}" ascii wide + $print_str1 = "[Get-NetRDPSession] Error opening the Remote Desktop Session Host (RD Session Host) server for: {0}" ascii wide + $print_str2 = "[Get-WMIProcess] Error enumerating remote processes on '{0}', access likely denied: {1}" ascii wide + $print_str3 = "[Get-WMIRegLastLoggedOn] Error opening remote registry on $Computer. Remote registry likely not enabled." ascii wide + $print_str4 = "[Get-DomainGUIDMap] Error in building GUID map: {e}" ascii wide + $str0 = "^[0-9A-F]{8}-([0-9A-F]{4}-){3}[0-9A-F]{12}$" ascii wide + $str1 = "(&(samAccountType=805306368)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(|(homedirectory=*)(scriptpath=*)(profilepath=*)))" ascii wide + $str2 = "^(CN|OU|DC)=" ascii wide + $str3 = "(|(samAccountName={0})(name={1})(displayname={2}))" ascii wide + $str4 = "^(?:[0-9]{1,3}\\.){3}[0-9]{1,3}$" ascii wide + $str5 = "LDAP://|^CN=.*" ascii wide + $str6 = "(objectCategory=groupPolicyContainer)" ascii wide + $str7 = "\\\\{0}\\SysVol\\{1}\\Policies\\{2}" ascii wide + $str8 = "S-1-5-21-[0-9]+-[0-9]+-[0-9]+-[0-9]+$" ascii wide + $str9 = "^S-1-5-.*-[1-9]\\d{3,}$" ascii wide condition: - all of them + $guid or ( all of ($str*) and 1 of ($print_str*)) } -rule ELASTIC_Windows_Vulndriver_Powertool_044A8645 : FILE +rule ELASTIC_Macos_Infostealer_Encodedosascript_Eeb54A7E : FILE MEMORY { meta: - description = "Name: kEvP64.sys" + description = "Detects Macos Infostealer Encodedosascript (Macos.Infostealer.EncodedOsascript)" author = "Elastic Security" - id = "044a8645-cc90-4ab2-8519-e207583de60d" - date = "2022-04-07" - modified = "2022-04-07" + id = "eeb54a7e-ebb3-4bf9-8538-2dbad9e514b9" + date = "2024-08-19" + modified = "2024-08-26" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_PowerTool.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "1aaa9aef39cb3c0a854ecb4ca7d3b213458f302025e0ec5bfbdef973cca9111c" - logic_hash = "b21c16cb72d003c505aa0ac4cc21b92513a100bad6870460090994c02cad875a" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Macos_Infostealer_EncodedOsascript.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c1693ee747e31541919f84dfa89e36ca5b74074044b181656d95d7f40af34a05" + logic_hash = "2f450c9afd92f52cdd8333e39e41b7334a01ddc39371c118260820a878359742" score = 75 - quality = 75 - tags = "FILE" - fingerprint = "f79831f531f20cc1daeb86b860dffa02dd5a9d25c41cc1eff9f04eddbbd37864" - threat_name = "Windows.VulnDriver.PowerTool" - severity = 50 - arch_context = "x86" - scan_context = "file" + quality = 71 + tags = "FILE, MEMORY" + fingerprint = "7b9d3cc64f3cfbdf1f9938ab923ff06eb6aef78fce633af891f5dd6a6b38dd2d" + severity = 100 + arch_context = "x86, arm64" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 6B 00 45 00 76 00 50 00 36 00 34 00 2E 00 73 00 79 00 73 00 00 00 } + $xor_encoded_osascript = "osascript" xor(0x40) + $base32_encoded_osascript = { 4E 35 5A 57 43 34 33 44 4F 4A 55 58 41 35 } + $hex_encoded_osascript = "6f7361736372697074" ascii wide nocase condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name + any of them } -rule ELASTIC_Windows_Vulndriver_Marvinhw_37326842 : FILE +rule ELASTIC_Macos_Infostealer_Mdquerytcc_142313Cb : FILE MEMORY { meta: - description = "Subject: Marvin Test Solutions, Inc., Name: HW.sys, Version: 4.9.8.0" + description = "Detects Macos Infostealer Mdquerytcc (MacOS.Infostealer.MdQueryTCC)" author = "Elastic Security" - id = "37326842-66a3-4058-abb7-d6d48ca58831" - date = "2022-07-21" - modified = "2022-07-21" + id = "142313cb-4726-442d-957c-5078440b8940" + date = "2023-04-11" + modified = "2024-08-19" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_MarvinHW.yar#L1-L22" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "6a4875ae86131a594019dec4abd46ac6ba47e57a88287b814d07d929858fe3e5" - logic_hash = "f37290912ab7d997d718c074eef48a67a36444e9e97592b6be65855ade2ba246" - score = 50 + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Infostealer_MdQueryTCC.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "d895075057e491b34b0f8c0392b44e43ade425d19eaaacea6ef8c5c9bd3487d8" + logic_hash = "e00015867ad0a0c440a49364945fe828d50675ecfd2039028653d97c77cff323" + score = 75 quality = 75 - tags = "FILE" - fingerprint = "f0ac8176d412dfaeb9c37ce18c13dea7cc2783fd37421b69e19c4dfa898e42be" - threat_name = "Windows.VulnDriver.MarvinHW" + tags = "FILE, MEMORY" + fingerprint = "280fa2c49461d0b53425768b9114696104c3ed0241ed157c22e36cdbaa334ac9" severity = 100 - arch_context = "x86" - scan_context = "file" + arch_context = "x86, arm64" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $subject_name = { 06 03 55 04 03 [2] 4D 61 72 76 69 6E 20 54 65 73 74 20 53 6F 6C 75 74 69 6F 6E 73 2C 20 49 6E 63 2E } - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 48 00 57 00 2E 00 73 00 79 00 73 00 00 00 } - $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x09][\x00-\x00])([\x00-\x04][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x08][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x03][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x08][\x00-\x00])([\x00-\x04][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x09][\x00-\x00])([\x00-\x04][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\x07][\x00-\x00]))/ + $string1 = { 6B 4D 44 49 74 65 6D 44 69 73 70 6C 61 79 4E 61 6D 65 20 ( 3D | 3D ) 20 2A 54 43 43 2E 64 62 } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and int16 ( uint32(0x3C)+0x18)==0x020b and $subject_name and $original_file_name and $version + any of them } -rule ELASTIC_Linux_Trojan_Malxmr_7054A0D0 : FILE MEMORY +rule ELASTIC_Linux_Cryptominer_Ksmdbot_Ebeedb3C : FILE MEMORY { meta: - description = "Detects Linux Trojan Malxmr (Linux.Trojan.Malxmr)" + description = "Detects Linux Cryptominer Ksmdbot (Linux.Cryptominer.Ksmdbot)" author = "Elastic Security" - id = "7054a0d0-11d4-4671-a88d-ea933e73fe11" - date = "2021-01-12" - modified = "2021-09-16" + id = "ebeedb3c-adc3-4df8-a8bf-5120802fa3c2" + date = "2022-12-14" + modified = "2024-02-13" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Malxmr.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "3a6b3552ffac13aa70e24fef72b69f683ac221105415efb294fb9a2fc81c260a" - logic_hash = "f7153fb11e0e4bf422021cc0fab99536c2a193198bf70d7f2af2fa5c1971c028" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Cryptominer_Ksmdbot.yar#L1-L23" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "b927e0fe58219305d86df8b3e44493a7c854a6ea4f76d1ebe531a7bfd4365b54" + logic_hash = "67f97cc4f2886ed296b5b3827dc1d1792136ba8d9d27c20b677c9467618c879d" score = 75 - quality = 73 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "9661cc2b7a1d7b882ca39307adc927f5fb73d59f3771a8b456c2cf2ff3d801e9" + fingerprint = "c6b678a94e45441ef960bc7119e2b9742ce8aab7e463897bf4a14aa0c57d507c" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -62087,28 +66296,32 @@ rule ELASTIC_Linux_Trojan_Malxmr_7054A0D0 : FILE MEMORY os = "linux" strings: - $a = { 6E 64 47 56 7A 64 48 52 6C 63 33 52 30 5A 58 4E 30 64 47 56 } + $a1 = { 48 BA 74 63 70 66 69 76 65 6D 4? 8B ?? 24 } + $a2 = { 48 B9 FF FF FF FF 67 65 74 73 48 89 08 48 B9 65 74 73 74 61 74 75 73 48 89 48 } + $a3 = { 48 B? 73 74 61 72 74 6D 69 6E 49 39 ?3 } + $a4 = { 48 BA 6C 6F 61 64 63 6C 69 65 48 8B B4 24 } + $a5 = { 48 BA 73 74 6? 7? 7? 6? 6? 6E 49 39 13 } condition: - all of them + 3 of them } -rule ELASTIC_Linux_Trojan_Malxmr_144994A5 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Mechbot_F2E1C5Aa : FILE MEMORY { meta: - description = "Detects Linux Trojan Malxmr (Linux.Trojan.Malxmr)" + description = "Detects Linux Trojan Mechbot (Linux.Trojan.Mechbot)" author = "Elastic Security" - id = "144994a5-1e37-4913-b7aa-deed638b1a79" + id = "f2e1c5aa-3318-4665-bee4-34a4afcf60bd" date = "2021-01-12" modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Malxmr.yar#L21-L39" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "07db41a4ddaac802b04df5e5bbae0881fead30cb8f6fa53a8a2e1edf14f2d36b" - logic_hash = "4d40337895e63d3dc6f0d94889863f0f5017533658210b902b08d84cf3588cab" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Mechbot.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "5f8e80e6877ff2de09a12135ee1fc17bee8eb6d811a65495bcbcddf14ecb44a3" + logic_hash = "2ba9ece1ab2360702a59a737a20b6dbd8fca276b543477f9290ab80c6f51e2f1" score = 75 - quality = 73 + quality = 75 tags = "FILE, MEMORY" - fingerprint = "473e686a74e76bb879b3e34eb207d966171f3e11cf68bde364316c2ae5cd3dc3" + fingerprint = "4b663b0756f2ae9b43eae29cd0225ad75517ef345982e8fdafa61f3c3db2d9f5" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -62116,60 +66329,62 @@ rule ELASTIC_Linux_Trojan_Malxmr_144994A5 : FILE MEMORY os = "linux" strings: - $a = { 78 71 51 58 5A 5A 4D 31 5A 35 59 6B 4D 78 61 47 4A 58 55 54 4A } + $a = { 45 52 56 45 52 00 42 41 4E 4C 49 53 54 00 42 4F 4F 54 00 42 } condition: all of them } -rule ELASTIC_Windows_Trojan_Azorult_38Fce9Ea : FILE MEMORY +rule ELASTIC_Windows_Vulndriver_Iobitunlocker_Defb90Fd : FILE { meta: - description = "Detects Windows Trojan Azorult (Windows.Trojan.Azorult)" + description = "Name: IObitUnlocker.sys, Version: 1.0.X.Y to 1.3.X.Y" author = "Elastic Security" - id = "38fce9ea-a94e-49d3-8eef-96fe06ad27f8" - date = "2021-08-05" - modified = "2021-10-04" - reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Azorult.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "405d1e6196dc5be1f46a1bd07c655d1d4b36c32f965d9a1b6d4859d3f9b84491" - logic_hash = "e23b21992b7ff577d4521c733929638522f4bf57b54c72e5e46196d028d6be26" + id = "defb90fd-d2ac-4168-b248-f698b590a63f" + date = "2023-07-25" + modified = "2023-07-25" + reference = "https://theevilbit.github.io/posts/iobit_unlocker_lpe/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_IoBitUnlocker.yar#L1-L25" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0aff83f28d70f425539fee3d6a780210d0406264f8a4eb124e32b074e8ffd556" + hash = "5ce1a8eac73ef1d0741f34d9fb2661da322117a63bffe60ccad092da89664c42" + logic_hash = "4b0f440c66b7c9a193f0d6675c2a4246036ebc5c0c83856f45ec40a041e9cd07" score = 75 quality = 75 - tags = "FILE, MEMORY" - fingerprint = "0655018fc803469c6d89193b75b4967fd02400fae07364ffcd11d1bc6cbbe74a" - severity = 100 + tags = "FILE" + fingerprint = "a2015ef9d0f3f5de47cd5c9a64953aef7a860d5cbd7e176df601c67c89294e4f" + threat_name = "Windows.VulnDriver.IoBitUnlocker" + severity = 50 arch_context = "x86" - scan_context = "file, memory" + scan_context = "file" license = "Elastic License v2" os = "windows" strings: - $a1 = "/c %WINDIR%\\system32\\timeout.exe 3 & del \"" wide fullword - $a2 = "%APPDATA%\\.purple\\accounts.xml" wide fullword - $a3 = "%TEMP%\\curbuf.dat" wide fullword - $a4 = "PasswordsList.txt" ascii fullword - $a5 = "Software\\Valve\\Steam" wide fullword + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 [1-4] 49 00 4F 00 62 00 69 00 74 00 55 00 6E 00 6C 00 6F 00 63 00 6B 00 65 00 72 00 2E 00 73 00 79 00 73 } + $product_version = { 50 00 72 00 6F 00 64 00 75 00 63 00 74 00 56 00 65 00 72 00 73 00 69 00 6F 00 6E 00 [1-4] 31 00 2E 00 ( 30 | 31 | 32 | 33 ) 00 } + $subject = { 06 03 55 04 0A [2] 49 4F 62 69 74 20 49 6E 66 6F 72 6D 61 74 69 6F 6E 20 54 65 63 68 6E 6F 6C 6F 67 79 } + $pdb_filename = "IObitUnlocker.pdb" fullword condition: - all of them + int16 ( uint32(0x3C)+0x5c)==0x0001 and (($original_file_name and $product_version) or ($subject and $pdb_filename)) } -rule ELASTIC_Linux_Exploit_Log4J_7Fc4D480 : FILE MEMORY +rule ELASTIC_Linux_Trojan_Pnscan_20E34E35 : FILE MEMORY { meta: - description = "Detects Linux Exploit Log4J (Linux.Exploit.Log4j)" + description = "Detects Linux Trojan Pnscan (Linux.Trojan.Pnscan)" author = "Elastic Security" - id = "7fc4d480-5354-4b0b-93ee-2937ddd1565c" - date = "2021-12-13" - modified = "2022-01-26" - reference = "https://www.elastic.co/security-labs/detecting-log4j2-with-elastic-security" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Log4j.yar#L1-L25" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "b09d8dd9c422e7eb8aa23f8b1204d31fd290252925099300d6d19d73e562ca5e" + id = "20e34e35-8639-4a0d-bfe3-6bfa1570f14d" + date = "2021-01-12" + modified = "2021-09-16" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Pnscan.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "7dbd5b709f16296ba7dac66dc35b9c3373cf88452396d79d0c92d7502c1b0005" + logic_hash = "1e69ef50d25ffd0f38ed0eb81ab3295822aa183c5e06f307caf02826b1dfa011" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "cd06db6f5bebf0412d056017259b5451184d5ba5b2976efd18fa8f96dba6a159" + fingerprint = "07678bd23ae697d42e2c7337675f7a50034b10ec7a749a8802820904a943641a" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -62177,35 +66392,29 @@ rule ELASTIC_Linux_Exploit_Log4J_7Fc4D480 : FILE MEMORY os = "linux" strings: - $jndi1 = "jndi.ldap.LdapCtx.c_lookup" - $jndi2 = "logging.log4j.core.lookup.JndiLookup.lookup" - $jndi3 = "com.sun.jndi.url.ldap.ldapURLContext.lookup" - $exp1 = "Basic/Command/Base64/" - $exp2 = "java.lang.ClassCastException: Exploit" - $exp3 = "WEB-INF/classes/Exploit" - $exp4 = "Exploit.java" + $a = { 4C 00 54 45 4C 20 3A 20 00 3C 49 41 43 3E 00 3C 44 4F 4E 54 3E 00 } condition: - 2 of ($jndi*) and 1 of ($exp*) + all of them } -rule ELASTIC_Windows_Hacktool_Physmem_Cc0978Df : FILE +rule ELASTIC_Windows_Vulndriver_Powertool_044A8645 : FILE { meta: - description = "Name: physmem.sys" + description = "Name: kEvP64.sys" author = "Elastic Security" - id = "cc0978df-153e-4421-8be8-37a0824133e2" + id = "044a8645-cc90-4ab2-8519-e207583de60d" date = "2022-04-07" modified = "2022-04-07" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_PhysMem.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "c299063e3eae8ddc15839767e83b9808fd43418dc5a1af7e4f44b97ba53fbd3d" - logic_hash = "e2fabf5889dbdc98dc6942be4fb0de4351d64a06bab945993b2a2c4afe89984e" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_PowerTool.yar#L1-L20" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "1aaa9aef39cb3c0a854ecb4ca7d3b213458f302025e0ec5bfbdef973cca9111c" + logic_hash = "b21c16cb72d003c505aa0ac4cc21b92513a100bad6870460090994c02cad875a" score = 75 quality = 75 tags = "FILE" - fingerprint = "b94d5530dc3db4101b6ef06dc2421a10785f47bcb26d54f309a250a68699fa83" - threat_name = "Windows.Hacktool.PhysMem" + fingerprint = "f79831f531f20cc1daeb86b860dffa02dd5a9d25c41cc1eff9f04eddbbd37864" + threat_name = "Windows.VulnDriver.PowerTool" severity = 50 arch_context = "x86" scan_context = "file" @@ -62213,28 +66422,28 @@ rule ELASTIC_Windows_Hacktool_Physmem_Cc0978Df : FILE os = "windows" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 70 00 68 00 79 00 73 00 6D 00 65 00 6D 00 2E 00 73 00 79 00 73 00 00 00 } + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 6B 00 45 00 76 00 50 00 36 00 34 00 2E 00 73 00 79 00 73 00 00 00 } condition: int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name } -rule ELASTIC_Windows_Hacktool_Physmem_B3Fa382B : FILE +rule ELASTIC_Windows_Hacktool_Gmer_8Aabdd5E : FILE { meta: - description = "Detects Windows Hacktool Physmem (Windows.Hacktool.PhysMem)" + description = "Detects Windows Hacktool Gmer (Windows.Hacktool.Gmer)" author = "Elastic Security" - id = "b3fa382b-48a5-4004-92ad-bba0d42243ad" + id = "8aabdd5e-1ce7-4257-abaa-8d02dc6856a6" date = "2022-04-04" modified = "2022-04-04" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_PhysMem.yar#L22-L40" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "88df37ede18bea511f1782c1a6c4915690b29591cf2c1bf5f52201fbbb4fa2b9" - logic_hash = "36a60b78de15a52721ad4830b37daffc33d7689e8b180fe148876da00562273a" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_Gmer.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "18c909a2b8c5e16821d6ef908f56881aa0ecceeaccb5fa1e54995935fcfd12f7" + logic_hash = "acdab89a7703a743927cec60fbc84af2fd469403bee6f211c865fb96e9c92498" score = 75 quality = 75 tags = "FILE" - fingerprint = "81285d1d8bdb575cb3ebf7f2df2555544e3f1342917e207def00c358a77cd620" + fingerprint = "960721d4d111a670907fe7d3ce01dfd134ad03a2d8440a945c75a7d46de46238" severity = 50 arch_context = "x86" scan_context = "file" @@ -62242,277 +66451,273 @@ rule ELASTIC_Windows_Hacktool_Physmem_B3Fa382B : FILE os = "windows" strings: - $str1 = "\\Phymemx64.pdb" + $str1 = "\\gmer64.pdb" condition: int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1 } -rule ELASTIC_Multi_Trojan_Coreimpact_37703Dc3 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Xtremerat_Cd5B60Be : FILE MEMORY { meta: - description = "Detects Multi Trojan Coreimpact (Multi.Trojan.Coreimpact)" + description = "Detects Windows Trojan Xtremerat (Windows.Trojan.XtremeRAT)" author = "Elastic Security" - id = "37703dc3-9485-4026-a8b7-82e753993757" - date = "2022-08-10" - modified = "2022-09-29" + id = "cd5b60be-4685-425a-8fe1-8366c0e5b84a" + date = "2022-03-15" + modified = "2022-04-12" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_Trojan_Coreimpact.yar#L1-L23" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "2d954908da9f63cd3942c0df2e8bb5fe861ac5a336ddef2bd0a977cebe030ad7" - logic_hash = "0695f22d6eb8c1b335c43213087539db419562bebd6f5b948cbb168c454bd37c" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_XtremeRAT.yar#L1-L28" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "735f7bf255bdc5ce8e69259c8e24164e5364aeac3ee78782b7b5275c1d793da8" + logic_hash = "a6997ae4842bd45c440925ef2a5848b57c58e2373c0971ce6b328ea297ee97b4" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "5a4d7af7d0fecc05f87ba51f976d78e77622f8afb1eafc175444f45839490109" + fingerprint = "2ee35d7c34374e9f5cffceb36fe1912932288ea4e8211a8b77430b98a9d41fb2" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "multi" + os = "windows" strings: - $str1 = "Uh, oh, exit() failed" fullword - $str2 = "agent_recv" fullword - $str3 = "needroot" fullword - $str4 = "time is running backwards, corrected" fullword - $str5 = "junk pointer, too low to make sense" fullword + $s01 = "SOFTWARE\\XtremeRAT" wide fullword + $s02 = "XTREME" wide fullword + $s03 = "STARTSERVERBUFFER" wide fullword + $s04 = "ENDSERVERBUFFER" wide fullword + $s05 = "ServerKeyloggerU" ascii fullword + $s06 = "TServerKeylogger" ascii fullword + $s07 = "XtremeKeylogger" wide fullword + $s08 = "XTREMEBINDER" wide fullword + $s09 = "UnitInjectServer" ascii fullword + $s10 = "shellexecute=" wide fullword condition: - 3 of them + 7 of ($s*) } -rule ELASTIC_Windows_Trojan_Babylonrat_0F66E73B : FILE MEMORY +rule ELASTIC_Windows_Trojan_Fickerstealer_Cc02E75E : FILE MEMORY { meta: - description = "Detects Windows Trojan Babylonrat (Windows.Trojan.Babylonrat)" + description = "Detects Windows Trojan Fickerstealer (Windows.Trojan.Fickerstealer)" author = "Elastic Security" - id = "0f66e73b-7824-46b6-a9e6-5abf018c9ffa" - date = "2021-09-02" - modified = "2022-01-13" + id = "cc02e75e-2049-4ee4-9302-e491e7dad696" + date = "2021-07-22" + modified = "2021-08-23" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Babylonrat.yar#L1-L22" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "4278064ec50f87bb0471053c068b13955ed9d599434e687a64bf2060438a7511" - logic_hash = "66223dc9e2ef7330e26c91f0c82c555e96e4c794a637ab2cbe36410f3eca202a" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Fickerstealer.yar#L1-L20" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "a4113ccb55e06e783b6cb213647614f039aa7dbb454baa338459ccf37897ebd6" + logic_hash = "ccfd7edf7625c13eea5b88fa29f9b8d3d873688f328f3e52c0500ac722c84511" score = 75 - quality = 50 + quality = 73 tags = "FILE, MEMORY" - fingerprint = "3998824e381f51aaa2c81c12d4c05157c642d8aef39982e35fa3e124191640ea" - severity = 100 + fingerprint = "022088764645d85dd20d1ce201395b4e79e3e716723715687eaecfcbe667615e" + severity = 80 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" os = "windows" strings: - $a1 = "BabylonRAT" wide fullword - $a2 = "Babylon RAT Client" wide fullword - $a3 = "ping 0 & del \"" wide fullword - $a4 = "\\%Y %m %d - %I %M %p" wide fullword + $a1 = "..\\\\?\\.\\UNC\\Windows stdio in console mode does not support writing non-UTF-8 byte sequences" ascii fullword + $a2 = "\"SomeNone" ascii fullword condition: all of them } -rule ELASTIC_Windows_Hacktool_Cheatengine_Fedac96D : FILE +rule ELASTIC_Windows_Trojan_Fickerstealer_F2159Bec : FILE MEMORY { meta: - description = "Subject: Cheat Engine" + description = "Detects Windows Trojan Fickerstealer (Windows.Trojan.Fickerstealer)" author = "Elastic Security" - id = "fedac96d-4c23-4c8d-8476-4c89fd610441" - date = "2022-04-07" - modified = "2022-04-07" + id = "f2159bec-a3ce-47a9-91ad-43b8a19ac172" + date = "2021-07-22" + modified = "2021-08-23" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_CheatEngine.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "b20b339a7b61dc7dbc9a36c45492ba9654a8b8a7c8cbc202ed1dfed427cfd799" - logic_hash = "426b6d388f86dd935d8165af0fb7c8491c987542755ec4c7c53a35a9003f8680" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Fickerstealer.yar#L22-L40" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "a4113ccb55e06e783b6cb213647614f039aa7dbb454baa338459ccf37897ebd6" + logic_hash = "d36cb90b526a291858291d615272baa78881309c83376f4d4cce1768c740ddbc" score = 75 - quality = 35 - tags = "FILE" - fingerprint = "94d375ddab90c27ef22dd18b98952d0ec8a4d911151970d5b9f59654a8e3d7db" - threat_name = "Windows.Hacktool.CheatEngine" - severity = 50 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "0671691c6d5c7177fe155e4076ab39bf5f909ed300f32c1530e80d471dff0296" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" os = "windows" strings: - $subject_name = { 06 03 55 04 03 [2] 43 68 65 61 74 20 45 6E 67 69 6E 65 } + $a1 = { 10 12 F2 0F 10 5A 08 31 C1 89 C6 8B 42 50 89 7D F0 F2 0F 11 8D 18 FF } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $subject_name + all of them } -rule ELASTIC_Windows_Trojan_Nimplant_44Ff3211 : FILE MEMORY +rule ELASTIC_Linux_Rootkit_Adore_Fe3Fd09F : FILE MEMORY { meta: - description = "Detects Windows Trojan Nimplant (Windows.Trojan.Nimplant)" + description = "Detects Linux Rootkit Adore (Linux.Rootkit.Adore)" author = "Elastic Security" - id = "44ff3211-1ba6-4c46-a990-b2419d88367e" - date = "2023-06-23" - modified = "2023-07-10" + id = "fe3fd09f-d170-4bb0-bc8d-6d61bdc22164" + date = "2021-04-06" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Nimplant.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "b56e20384f98e1d2417bb7dcdbfb375987dd075911b74ea7ead082494836b8f4" - logic_hash = "ee519d8d722404ed440b385d283a41921bc34ee11f0e7273cdc074b377494c39" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Rootkit_Adore.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "f4e532b840e279daf3d206e9214a1b065f97deb7c1487a34ac5cbd7cbbf33e1a" + logic_hash = "cc07efb9484562cd870649a38126f08aa4e99ed5ad4662ece0488d9ffd97520e" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "cb7f823b1621e49ffac42e8a3f90ca7f8bac7ae108ca20b9a0884548681d1f87" + fingerprint = "2bab2a4391359c6a7148417b010887d0754b91ac99820258e849e81f7752069f" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = "@NimPlant v" - $a2 = ".Env_NimPlant." - $a3 = "NimPlant.dll" + $a = { 89 C0 89 45 F4 83 7D F4 00 75 17 68 E4 A1 04 08 } condition: - 2 of them + all of them } -rule ELASTIC_Linux_Exploit_Criscras_Fc505C1D : FILE MEMORY +rule ELASTIC_Macos_Trojan_Amcleaner_445Bb666 : FILE MEMORY { meta: - description = "Detects Linux Exploit Criscras (Linux.Exploit.Criscras)" + description = "Detects Macos Trojan Amcleaner (MacOS.Trojan.Amcleaner)" author = "Elastic Security" - id = "fc505c1d-f77d-48cc-b8fe-7b24b9cc6a97" - date = "2021-04-06" - modified = "2021-09-16" + id = "445bb666-1707-4ad9-a409-4a21de352957" + date = "2021-10-05" + modified = "2021-10-25" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Criscras.yar#L1-L19" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "7399f6b8fbd6d6c6fb56ab350c84910fe19cc5da67e4de37065ff3d4648078ab" - logic_hash = "4d84570c13c584fb7360e798df9f3e6039ee74fdb6ad597add0ea150e3deaa80" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Amcleaner.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c85bf71310882bc0c0cf9b74c9931fd19edad97600bc86ca51cf94ed85a78052" + logic_hash = "664829ff761186ec8f3055531b5490b7516756b0aa9d0183d4c17240a5ca44c4" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "bc5e980599c4c8fc3c9b560738d7187a0c91e2813c64b3ad0ff014230100c8d8" + fingerprint = "355c7298a4148be3b80fd841b483421bde28085c21c00d5e4a42949fd8026f5b" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "macos" strings: - $a = { 0C 89 21 89 E3 31 C0 B0 0B CD 80 31 C0 FE C0 CD } + $a = { 10 A0 5B 15 57 A8 8B 17 02 F9 A8 9B E8 D5 8C 96 A7 48 42 91 E5 EC 3D C8 AC 52 } condition: all of them } -rule ELASTIC_Windows_Vulndriver_Rtcore_4Eeb2Ce5 : FILE +rule ELASTIC_Macos_Trojan_Amcleaner_A91D3907 : FILE MEMORY { meta: - description = "Detects Windows Vulndriver Rtcore (Windows.VulnDriver.RtCore)" + description = "Detects Macos Trojan Amcleaner (MacOS.Trojan.Amcleaner)" author = "Elastic Security" - id = "4eeb2ce5-e481-4e9c-beda-2b01f259ed96" - date = "2022-04-04" - modified = "2022-08-30" + id = "a91d3907-5e24-46c0-90ef-ed7f46ad8792" + date = "2021-10-05" + modified = "2021-10-25" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_RtCore.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "01aa278b07b58dc46c84bd0b1b5c8e9ee4e62ea0bf7a695862444af32e87f1fd" - logic_hash = "f547bce6554c60e8f3ef8e128c05533cf1f35ce0ee414d5a1c5e9a205b05d8fe" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Amcleaner.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "dc9c700f3f6a03ecb6e3f2801d4269599c32abce7bc5e6a1b7e6a64b0e025f58" + logic_hash = "e61ceea117acf444a6b137b93d7c335c6eb8a7e13a567177ec4ea44bf64fd5c6" score = 75 - quality = 75 - tags = "FILE" - fingerprint = "cebca7dc572afccf4eb600980b9cbaef0878213f91c04b4605a0cf4d0e5e541f" - severity = 50 + quality = 73 + tags = "FILE, MEMORY" + fingerprint = "c020567fde77a72d27c9c06f6ebb103f910321cc7a1c3b227e0965b079085b49" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $str1 = "\\Device\\RTCore64" wide fullword - $str2 = "Kaspersky Lab Anti-Rootkit Monitor Driver" wide fullword + $a = { 40 22 4E 53 49 6D 61 67 65 56 69 65 77 22 2C 56 69 6E 6E 76 63 6A 76 64 69 5A } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1 and not $str2 + all of them } -rule ELASTIC_Windows_Vulndriver_Hpportio_B31E3473 : FILE +rule ELASTIC_Macos_Trojan_Amcleaner_8Ce3Fea8 : FILE MEMORY { meta: - description = "Name: HpPortIox64.sys, Version: 1.2.0.9" + description = "Detects Macos Trojan Amcleaner (MacOS.Trojan.Amcleaner)" author = "Elastic Security" - id = "b31e3473-b87e-47df-b3ec-b09c69dcbb4e" - date = "2022-04-07" - modified = "2022-04-07" + id = "8ce3fea8-3cc7-4c59-b07c-a6dda0bb6b85" + date = "2021-10-05" + modified = "2021-10-25" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_HpPortIo.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "c5050a2017490fff7aa53c73755982b339ddb0fd7cef2cde32c81bc9834331c5" - logic_hash = "e449b45f3cf2836254614bbdc957aa7093162fc1acd672edd931d5f240503963" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Amcleaner.yar#L41-L59" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "c85bf71310882bc0c0cf9b74c9931fd19edad97600bc86ca51cf94ed85a78052" + logic_hash = "08c4b5b4afefbf1ee207525f9b28bc7eed7b55cb07f8576fddfa0bbe95002769" score = 75 - quality = 75 - tags = "FILE" - fingerprint = "66067334492941eb2da8c72dc0d2f55ba1c2b564904f40b6e77925262501abd9" - threat_name = "Windows.VulnDriver.HpPortIo" - severity = 50 + quality = 73 + tags = "FILE, MEMORY" + fingerprint = "e156d3c7a55cae84481df644569d1c5760e016ddcc7fd05d0f88fa8f9f9ffdae" + severity = 100 arch_context = "x86" - scan_context = "file" + scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 48 00 70 00 50 00 6F 00 72 00 74 00 49 00 6F 00 78 00 36 00 34 00 2E 00 73 00 79 00 73 00 00 00 } - $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x02][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x09][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x01][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ + $a = { 54 40 22 4E 53 54 61 62 6C 65 56 69 65 77 22 2C 56 69 6E 6E 76 63 6B 54 70 51 } condition: - int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version + all of them } -rule ELASTIC_Linux_Ransomware_Akira_02237952 : FILE MEMORY +rule ELASTIC_Windows_Trojan_Dragonbreath_B27Bc56B : FILE MEMORY { meta: - description = "Detects Linux Ransomware Akira (Linux.Ransomware.Akira)" + description = "Detects Windows Trojan Dragonbreath (Windows.Trojan.DragonBreath)" author = "Elastic Security" - id = "02237952-b9ac-44e5-a32f-f3cc8f28a89b" - date = "2023-07-28" - modified = "2024-02-13" + id = "b27bc56b-41a2-4b3d-bff4-a14b90debe08" + date = "2024-06-05" + modified = "2024-06-12" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Ransomware_Akira.yar#L1-L22" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "1d3b5c650533d13c81e325972a912e3ff8776e36e18bca966dae50735f8ab296" - logic_hash = "a9b3cdddb3387251d7da90f32b08b9c1eedcdff1fe90d51f4732183666a6d467" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_DragonBreath.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "45023fd0e694d66c284dfe17f78c624fd7e246a6c36860a0d892d232a30949be" + logic_hash = "b86d5541a7e03a698ad918cdbba987474c6680353b4d2de2f8422ecd0ebcac61" score = 75 - quality = 75 + quality = 69 tags = "FILE, MEMORY" - fingerprint = "7fcfac47be082441f6df149d0615a9d2020ac1e9023eabfcf10db4fe400cd474" + fingerprint = "4bc82f64191cf907d7ecf7da5453258c9be60e5dbaff770ebc22d9629bcbc7e2" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "linux" + os = "windows" strings: - $a1 = "No path to encrypt" fullword - $a2 = "--encryption_percent" fullword - $a3 = "Failed to import public key" fullword - $a4 = "akira_readme.txt" fullword + $a1 = { 50 6C 75 67 69 6E 4D 65 } + $a2 = { 69 73 41 52 44 6C 6C } + $a3 = { 25 64 2D 25 64 2D 25 64 20 25 64 3A 25 64 } condition: - 3 of them + all of them } -rule ELASTIC_Windows_Vulndriver_Microstar_D72B85B2 : FILE +rule ELASTIC_Windows_Vulndriver_Vmdrv_7C674F8E : FILE { meta: - description = "Name: NTIOLib.sys, Version: 1.0.0.0" + description = "Name: vmdrv.sys, Version: 10.0.10011.16384" author = "Elastic Security" - id = "d72b85b2-b51e-4061-909c-cce531513367" + id = "7c674f8e-720c-48ee-9644-5566493d2546" date = "2022-04-07" modified = "2022-04-07" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_MicroStar.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "3ed15a390d8dfbd8a8fb99e8367e19bfd1cced0e629dfe43ccdb46c863394b59" - logic_hash = "04e9c1f318acae5544cdc826938383bf8f6c6b838cb5828a7097383ac564f404" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Vmdrv.yar#L1-L21" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "32cccc4f249499061c0afa18f534c825d01034a1f6815f5506bf4c4ff55d1351" + logic_hash = "87f29b861d5239c60e44541fe31ed90696068225b1b6d824dc9b06fcdb1597ae" score = 75 quality = 75 tags = "FILE" - fingerprint = "a531bc0b1a94b532694c9ae421db258007d835e03cf2580a1b5a10e5686063e5" - threat_name = "Windows.VulnDriver.MicroStar" + fingerprint = "a1ce2c56e5c99aae124d0404750eb8cc970291e8e10cb0c81c8c618eb778c343" + threat_name = "Windows.VulnDriver.Vmdrv" severity = 50 arch_context = "x86" scan_context = "file" @@ -62520,302 +66725,319 @@ rule ELASTIC_Windows_Vulndriver_Microstar_D72B85B2 : FILE os = "windows" strings: - $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 4E 00 54 00 49 00 4F 00 4C 00 69 00 62 00 2E 00 73 00 79 00 73 00 00 00 } - $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x00][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/ + $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 76 00 6D 00 64 00 72 00 76 00 2E 00 73 00 79 00 73 00 00 00 } + $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x00][\x00-\x00])([\x00-\x0a][\x00-\x00])([\x00-\x00][\x00-\x40]|[\x00-\xff][\x00-\x3f])([\x00-\x1b][\x00-\x27]|[\x00-\xff][\x00-\x26])|([\x00-\xff][\x00-\xff])([\x00-\x09][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff])|([\x00-\x00][\x00-\x00])([\x00-\x0a][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\x1a][\x00-\x27]|[\x00-\xff][\x00-\x26]))/ condition: int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version } -rule ELASTIC_Windows_Trojan_Sourshark_F0247Cce : FILE MEMORY +rule ELASTIC_Linux_Cryptominer_Zexaf_B90E7683 : FILE MEMORY { meta: - description = "Detects Windows Trojan Sourshark (Windows.Trojan.SourShark)" + description = "Detects Linux Cryptominer Zexaf (Linux.Cryptominer.Zexaf)" author = "Elastic Security" - id = "f0247cce-b983-41a1-9118-fd4c23e3d099" - date = "2024-06-04" - modified = "2024-06-12" + id = "b90e7683-84bf-4c07-b6ef-54c631280217" + date = "2021-01-12" + modified = "2021-09-16" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_SourShark.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "07eb88c69437ee6e3ea2fbab5f2fbd8e846125d18c1da7d72bb462e9d083c9fc" - logic_hash = "0c5d802b5bfc771bdf5df541b18c7ab9de4f420fd3928bfd85b1a71cca2af1bc" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Cryptominer_Zexaf.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "98650ebb7e463a06e737bcea4fd2b0f9036fafb0638ba8f002e6fe141b9fecfe" + logic_hash = "d8485d8fbf00d5c828d7c6c80fef61f228f308e3d27a762514cfb3f00053b30b" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "174d6683890b855a06c672423b4a0b3aa291558d8a2af4771b931d186ce3cb63" + fingerprint = "4ca9fad98bdde19f71c117af9cb87007dc46494666e7664af111beded1100ae4" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "linux" strings: - $a1 = "%s\\svchost.%s" - $a2 = "crypto_domain" - $a3 = "postback_id" + $a = { 89 F2 C1 E7 18 C1 E2 18 C1 ED 08 09 D5 C1 EE 08 8B 14 24 09 FE } condition: all of them } -rule ELASTIC_Windows_Trojan_Sourshark_Adee8A17 : FILE MEMORY +rule ELASTIC_Macos_Trojan_Bundlore_28B13E67 : FILE MEMORY { meta: - description = "Detects Windows Trojan Sourshark (Windows.Trojan.SourShark)" + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" author = "Elastic Security" - id = "adee8a17-cc0c-40b8-9ee6-a01b41e9befd" - date = "2024-06-04" - modified = "2024-06-12" + id = "28b13e67-e01c-45eb-aae6-ecd02b017a44" + date = "2021-10-05" + modified = "2021-10-25" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_SourShark.yar#L23-L41" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "07eb88c69437ee6e3ea2fbab5f2fbd8e846125d18c1da7d72bb462e9d083c9fc" - logic_hash = "98a4d31849a1828c2154b5032a81580f5dcc8d4a65b96dea3a727e2a82a51666" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L1-L19" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "0b50a38749ea8faf571169ebcfce3dfd668eaefeb9a91d25a96e6b3881e4a3e8" + logic_hash = "586ae19e570c51805afd3727b2e570cdb1c48344aa699e54774a708f02bc3a6f" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "f35ebe8a220693ef6288efae0d325c3f40e70836c088599cb9b620c59fab09da" + fingerprint = "1e85be4432b87214d61e675174f117e36baa8ab949701ee1d980ad5dd8454bac" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $a = { 8B 45 08 8B 4C BE 08 8A 04 02 02 C3 02 C1 0F B6 D8 8B 44 9E 08 89 44 BE 08 8D 42 01 33 D2 89 4C 9E 08 47 83 F8 20 0F 4C D0 81 FF 00 01 00 00 7C CF 8B 16 33 FF 8B 5E 04 39 7D FC 7E 33 0F 1F 00 } + $a = { 05 A5 A3 A9 37 D2 05 13 E9 3E D6 EA 6A EC 9B DC 36 E5 76 A7 53 B3 0F 06 46 D1 } condition: all of them } -rule ELASTIC_Windows_Ransomware_Wannacry_D9855102 : FILE MEMORY +rule ELASTIC_Macos_Trojan_Bundlore_75C8Cb4E : FILE MEMORY { meta: - description = "Detects Windows Ransomware Wannacry (Windows.Ransomware.WannaCry)" + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" author = "Elastic Security" - id = "d9855102-56dc-4e4c-9599-82fa52922b95" - date = "2022-08-29" - modified = "2022-09-29" + id = "75c8cb4e-f8bd-4a2c-8a5e-8500e12a9030" + date = "2021-10-05" + modified = "2021-10-25" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_WannaCry.yar#L1-L26" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0b7878babbaf7c63d808f3ce32c7306cb785fdfb1ceb73be07fb48fdd091fdfb" - logic_hash = "5edf6a42c9f20de3819b46f24be243940b79e7e9004fee3d601794ea0b534cf1" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L21-L39" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "3d69912e19758958e1ebdef5e12c70c705d7911c3b9df03348c5d02dd06ebe4e" + logic_hash = "527fecb8460c0325c009beddd6992e0abbf8c5a05843e4cedf3b17deb4b19a1c" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "f96f2f0eb3cdf6e882adcad06ad10e375412dec99687b3d38d4dbe9bdde52db5" + fingerprint = "db68c315dba62f81168579aead9c5827f7bf1df4a3c2e557b920fa8fbbd6f3c2" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $a1 = "@WanaDecryptor@.exe" wide fullword - $a2 = ".WNCRY" wide fullword - $a3 = "$%d worth of bitcoin" fullword - $a4 = "%d%d.bat" fullword - $a5 = "This folder protects against ransomware. Modifying it will reduce protection" wide fullword - $b1 = { 53 55 56 57 FF 15 D0 70 00 10 8B E8 A1 8C DD 00 10 85 C0 75 6A 68 B8 0B 00 00 FF 15 70 70 00 10 } - $b2 = { A1 90 DD 00 10 53 56 57 85 C0 75 3E 8B 1D 60 71 00 10 8B 3D 70 70 00 10 6A 00 FF D3 83 C4 04 A3 } - $b3 = { 56 8B 74 24 08 57 8B 3D 70 70 00 10 56 E8 2E FF FF FF 83 C4 04 A3 8C DD 00 10 85 C0 75 09 68 88 } + $a = { 35 EE 19 00 00 EA 80 35 E8 19 00 00 3B 80 35 E2 19 00 00 A4 80 35 DC 19 00 00 } condition: - 5 of ($a*) or 1 of ($b*) + all of them } -rule ELASTIC_Windows_Trojan_Qbot_D91C1384 : FILE MEMORY +rule ELASTIC_Macos_Trojan_Bundlore_17B564B4 : FILE MEMORY { meta: - description = "Detects Windows Trojan Qbot (Windows.Trojan.Qbot)" + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" author = "Elastic Security" - id = "d91c1384-839f-4062-8a8d-5cda931029ae" - date = "2021-07-08" - modified = "2021-08-23" - reference = "https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Qbot.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "18ac3870aaa9aaaf6f4a5c0118daa4b43ad93d71c38bf42cb600db3d786c6dda" - logic_hash = "8fd8249a2af236c92ccbc20b2a8380f69ca75976bd64bad167828e9ab4c6ed90" + id = "17b564b4-7452-473f-873f-f907b5b8ebc4" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L41-L59" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "94f6e5ee6eb3a191faaf332ea948301bbb919f4ec6725b258e4f8e07b6a7881d" + logic_hash = "40cd2a793c8ed51a8191ecb9b358f50dc2035d997d0f773f6049f9c272291607" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "1b47ede902b6abfd356236e91ed3e741cf1744c68b6bb566f0d346ea07fee49a" + fingerprint = "7701fab23d59b8c0db381a1140c4e350e2ce24b8114adbdbf3c382c6d82ea531" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $a = { FE 8A 14 06 88 50 FF 8A 54 BC 11 88 10 8A 54 BC 10 88 50 01 47 83 } + $a = { 35 D9 11 00 00 05 80 35 D3 11 00 00 2B 80 35 CD 11 00 00 F6 80 35 C7 11 00 00 } condition: all of them } -rule ELASTIC_Windows_Trojan_Qbot_7D5Dc64A : FILE MEMORY +rule ELASTIC_Macos_Trojan_Bundlore_C90C088A : FILE MEMORY { meta: - description = "Detects Windows Trojan Qbot (Windows.Trojan.Qbot)" + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" author = "Elastic Security" - id = "7d5dc64a-a597-44ac-a0fd-cefffc5e9cff" - date = "2021-10-04" - modified = "2022-01-13" - reference = "https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Qbot.yar#L22-L42" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "a2bacde7210d88675564106406d9c2f3b738e2b1993737cb8bf621b78a9ebf56" - logic_hash = "5c8858502050494ab20a230f04c2c1cb4bfcd80f4a248dad82787d7ce67c741d" + id = "c90c088a-abf5-4e52-a69e-5a4fd4b5cf15" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L61-L79" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "875513f4ebeb63b9e4d82fb5bff2b2dc75b69c0bfa5dd8d2895f22eaa783f372" + logic_hash = "c82c5c8d1e38e0d2631c5611e384eb49b58c64daeafe0cc642682e5c64686b60" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "ab80d96a454e0aad56621e70be4d55f099c41b538a380feb09192d252b4db5aa" + fingerprint = "c2300895f8ff5ae13bc0ed93653afc69b30d1d01f5ce882bd20f2b65426ecb47" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $a1 = "%u.%u.%u.%u.%u.%u.%04x" ascii fullword - $a2 = "stager_1.dll" ascii fullword + $a = { 35 E1 11 00 00 92 80 35 DB 11 00 00 2A 80 35 D5 11 00 00 7F 80 35 CF 11 00 00 } condition: all of them } -rule ELASTIC_Windows_Trojan_Qbot_6Fd34691 : FILE MEMORY +rule ELASTIC_Macos_Trojan_Bundlore_3965578D : FILE MEMORY { meta: - description = "Detects Windows Trojan Qbot (Windows.Trojan.Qbot)" + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" author = "Elastic Security" - id = "6fd34691-10e4-4a66-85ff-1b67ed3da4dd" - date = "2022-03-07" - modified = "2022-04-12" - reference = "https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Qbot.yar#L44-L64" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "0838cd11d6f504203ea98f78cac8f066eb2096a2af16d27fb9903484e7e6a689" - logic_hash = "9422d9f276f0c8c2990ece3282d918abc6fcce7eeb6809d46ae6b768a501a877" + id = "3965578d-3180-48e4-b5be-532e880b1df9" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L81-L99" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "d72543505e36db40e0ccbf14f4ce3853b1022a8aeadd96d173d84e068b4f68fa" + logic_hash = "6bd24640e0a3aa152fcd90b6975ee4fb7e99ab5f2d48d3a861bc804c526c90b6" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "187fc04abcba81a2cbbe839adf99b8ab823cbf65993c8780d25e7874ac185695" + fingerprint = "e41f08618db822ba5185e5dc3f932a72e1070fbb424ff2c097cab5e58ad9e2db" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $a1 = { 75 C9 8B 45 1C 89 45 A4 8B 45 18 89 45 A8 8B 45 14 89 45 AC 8B } - $a2 = "\\stager_1.obf\\Benign\\mfc\\" wide + $a = { 35 33 2A 00 00 60 80 35 2D 2A 00 00 D0 80 35 27 2A 00 00 54 80 35 21 2A 00 00 } condition: - any of them + all of them } -rule ELASTIC_Windows_Trojan_Qbot_3074A8D4 : FILE MEMORY +rule ELASTIC_Macos_Trojan_Bundlore_00D9D0E9 : FILE MEMORY { meta: - description = "Detects Windows Trojan Qbot (Windows.Trojan.Qbot)" + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" author = "Elastic Security" - id = "3074a8d4-d93c-4987-9031-9ecd3881730d" - date = "2022-06-07" - modified = "2022-07-18" - reference = "https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Qbot.yar#L66-L97" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "c2ba065654f13612ae63bca7f972ea91c6fe97291caeaaa3a28a180fb1912b3a" - logic_hash = "90c06bd09fe640bb5a6be8e4f2384fb15c7501674d57db005e790ed336740c99" + id = "00d9d0e9-28d8-4c32-bc6f-52008ee69b07" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L101-L119" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "73069b34e513ff1b742b03fed427dc947c22681f30cf46288a08ca545fc7d7dd" + logic_hash = "535831872408caa27984190d1b1b1a5954e502265925d50457e934219598dbfd" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "c233a0c24576450ce286d96126379b6b28d537619e853d860e2812f521b810ac" + fingerprint = "7dcc6b124d631767c259101f36b4bbd6b9d27b2da474d90e31447ea03a2711a6" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $a1 = "qbot" wide - $a2 = "stager_1.obf\\Benign\\mfc" wide - $a3 = "common.obf\\Benign\\mfc" wide - $a4 = "%u;%u;%u;" - $a5 = "%u.%u.%u.%u.%u.%u.%04x" - $a6 = "%u&%s&%u" - $get_string1 = { 33 D2 8B ?? 6A 5A 5? F7 ?? 8B ?? 08 8A 04 ?? 8B 55 ?? 8B ?? 10 3A 04 ?? } - $get_string2 = { 33 D2 8B ?? F7 75 F4 8B 45 08 8A 04 02 32 04 ?? 88 04 ?? ?? 83 ?? 01 } - $set_key = { 8D 87 00 04 00 00 50 56 E8 ?? ?? ?? ?? 59 8B D0 8B CE E8 } - $do_computer_use_russian_like_keyboard = { B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D } - $execute_each_tasks = { 8B 44 0E ?? 85 C0 74 ?? FF D0 EB ?? 6A 00 6A 00 6A 00 FF 74 0E ?? E8 ?? ?? ?? ?? 83 C4 10 } - $generate_random_alpha_num_string = { 57 E8 ?? ?? ?? ?? 48 50 8D 85 ?? ?? ?? ?? 6A 00 50 E8 ?? ?? ?? ?? 8B 4D ?? 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C } - $load_base64_dll_from_file_and_inject_into_targets = { 10 C7 45 F0 50 00 00 00 83 65 E8 00 83 7D F0 0B 73 08 8B 45 F0 89 } + $a = { 35 8E 11 00 00 55 80 35 88 11 00 00 BC 80 35 82 11 00 00 72 80 35 7C 11 00 00 } condition: - 6 of them + all of them } -rule ELASTIC_Windows_Trojan_Qbot_1Ac22A26 : FILE MEMORY +rule ELASTIC_Macos_Trojan_Bundlore_650B8Ff4 : FILE MEMORY { meta: - description = "Detects Windows Trojan Qbot (Windows.Trojan.Qbot)" + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" author = "Elastic Security" - id = "1ac22a26-ec88-4e88-8fe6-a092bbb61904" - date = "2022-12-29" - modified = "2023-02-01" - reference = "https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Qbot.yar#L99-L136" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "c2ba065654f13612ae63bca7f972ea91c6fe97291caeaaa3a28a180fb1912b3a" - logic_hash = "d9beaf4a8c28a0b3c38dda6bf22a96b8c96ef715bd36de880504a9f970338fe2" + id = "650b8ff4-6cc8-4bfc-ba01-ac9c86410ecc" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L121-L139" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "78fd2c4afd7e810d93d91811888172c4788a0a2af0b88008573ce8b6b819ae5a" + logic_hash = "e8a706db010e9c3d9714d5e7a376e9b2189af382a7b01db9a9e7ee947e9637bb" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "22436c48bc775284d1f682eaeb650fd998302021342efc322c4ca40dd30f1a0d" + fingerprint = "4f4691f6830684a71e7b3ab322bf6ec4638bf0035adf3177dbd0f02e54b3fd80" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $a1 = "qbot" wide - $a2 = "stager_1.obf\\Benign\\mfc" wide - $a3 = "common.obf\\Benign\\mfc" wide - $a4 = "%u;%u;%u" - $a5 = "%u.%u.%u.%u.%u.%u.%04x" - $a6 = "%u&%s&%u" - $a7 = "mnjhuiv40" - $a8 = "\\u%04X" - $get_string1 = { 33 D2 8B ?? 6A ?? 5? F7 ?? 8B ?? 08 8A 04 ?? 8B 55 ?? 8B ?? 10 3A 04 } - $get_string2 = { 8B C6 83 E0 ?? 8A 04 08 3A 04 1E 74 ?? 46 3B F2 72 } - $get_string3 = { 8A 04 ?? 32 04 ?? 88 04 ?? 4? 83 ?? 01 } - $set_key_1 = { 8D 87 00 04 00 00 50 56 E8 [4] 59 8B D0 8B CE E8 } - $set_key_2 = { 59 6A 14 58 6A 0B 66 89 87 [0-1] 20 04 00 00 } - $cccp_keyboard_0 = { 6A ?? 66 89 45 E? 58 6A ?? 66 89 45 E? 58 } - $cccp_keyboard_1 = { 66 8B 84 9? ?? FE FF FF B9 FF 03 00 00 66 23 C1 33 ?? 0F B7 } - $execute_each_tasks = { 8B 0D [4] 83 7C 0E 04 00 74 ?? 83 7C 0E 1C 00 74 ?? 8B 04 0E 85 C0 7E ?? 6B C0 3C } - $generate_random_alpha_num_string = { 57 E8 [4] 48 50 8D 85 [4] 6A 00 50 E8 [4] 8B 4D ?? 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C } - $load_and_inject_b64_dll_from_file = { 6B 45 FC 18 8B 4D F8 83 7C 01 04 00 76 ?? 6A 00 6B 45 FC 18 8B 4D F8 FF 74 01 10 6B 45 FC 18 } - $decipher_rsrc_data = { F6 86 38 04 00 00 04 89 BE 2C 04 00 00 89 BE 28 04 00 00 [2-6] 8B 0B 8D 45 F? 83 65 F? 00 8B D7 50 E8 } + $a = { 35 8B 11 00 00 60 80 35 85 11 00 00 12 80 35 7F 11 00 00 8C 80 35 79 11 00 00 } + + condition: + all of them +} +rule ELASTIC_Macos_Trojan_Bundlore_C8Ad7Edd : FILE MEMORY +{ + meta: + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" + author = "Elastic Security" + id = "c8ad7edd-4233-44ce-a4e5-96dfc3504f8a" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L141-L159" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "d4915473e1096a82afdaee405189a0d0ae961bd11a9e5e9adc420dd64cb48c24" + logic_hash = "be09b4bd612bb499044fe91ca4e1ab62405cf1e4d75b8e1da90e326d1c66e04f" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "c6a8a1d9951863d4277d297dd6ff8ad7b758ca2dfe16740265456bb7bb0fd7d0" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "macos" + + strings: + $a = { 35 74 11 00 00 D5 80 35 6E 11 00 00 57 80 35 68 11 00 00 4C 80 35 62 11 00 00 } + + condition: + all of them +} +rule ELASTIC_Macos_Trojan_Bundlore_Cb7344Eb : FILE MEMORY +{ + meta: + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" + author = "Elastic Security" + id = "cb7344eb-51e6-4f17-a5d4-eea98938945b" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L161-L179" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "53373668d8c5dc17f58768bf59fb5ab6d261a62d0950037f0605f289102e3e56" + logic_hash = "6b5e868dfd14e9b1cdf3caeb1216764361b28c1dd38849526baf5dbdb1020d8d" + score = 75 + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "6041c50c9eefe9cafb8768141cd7692540f6af2cdd6e0a763b7d7e50b8586999" + severity = 100 + arch_context = "x86" + scan_context = "file, memory" + license = "Elastic License v2" + os = "macos" + + strings: + $a = { 35 ED 09 00 00 92 80 35 E7 09 00 00 93 80 35 E1 09 00 00 16 80 35 DB 09 00 00 } condition: - 6 of them + all of them } -rule ELASTIC_Macos_Trojan_Hloader_A3945Baf : FILE MEMORY +rule ELASTIC_Macos_Trojan_Bundlore_753E5738 : FILE MEMORY { meta: - description = "Detects Macos Trojan Hloader (MacOS.Trojan.HLoader)" + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" author = "Elastic Security" - id = "a3945baf-4708-4a0b-8a9b-1a5448ee4bc7" - date = "2023-10-23" - modified = "2023-10-23" + id = "753e5738-0c72-4178-9396-d1950e868104" + date = "2021-10-05" + modified = "2021-10-25" reference = "https://github.com/elastic/protections-artifacts/" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/MacOS_Trojan_HLoader.yar#L1-L21" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - hash = "2360a69e5fd7217e977123c81d3dbb60bf4763a9dae6949bc1900234f7762df1" - logic_hash = "0383485b6bbcdae210a6c949f6796023b2f7ec3f1edbd2116207fc2b75a67849" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L181-L199" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "42aeea232b28724d1fa6e30b1aeb8f8b8c22e1bc8afd1bbb4f90e445e31bdfe9" + logic_hash = "7a6907b51c793e4182c1606eab6f2bcb71f0350a34aef93fa3f3a9f1a49961ba" score = 75 quality = 75 tags = "FILE, MEMORY" - fingerprint = "a48ec79f07a6a53611b1d1e8fe938513ec0ea19344126e07331b48b028cb877e" + fingerprint = "c0a41a8bc7fbf994d3f5a5d6c836db3596b1401b0e209a081354af2190fcb3c2" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -62823,59 +67045,57 @@ rule ELASTIC_Macos_Trojan_Hloader_A3945Baf : FILE MEMORY os = "macos" strings: - $seq_main = { 74 ?? 49 89 C7 48 89 D8 4C 89 FF E8 ?? ?? ?? ?? 48 89 DF 31 F6 BA ?? ?? ?? ?? 4C 89 65 ?? 4D 89 F4 4C 89 F1 4C 8B 75 ?? 41 FF 56 ?? } - $seq_exec = { 48 B8 00 00 00 00 00 00 00 E0 48 89 45 ?? 4C 8D 6D ?? BF 11 00 00 00 E8 ?? ?? ?? ?? 0F 10 45 ?? 0F 11 45 ?? 48 BF 65 78 65 63 46 69 6C 65 48 BE 20 65 72 72 6F 72 20 EF } - $seq_rename = { 41 89 DE 84 DB 74 ?? 48 8B 7D ?? FF 15 ?? ?? ?? ?? E9 ?? ?? ?? ?? 4C 89 E7 E8 ?? ?? ?? ?? } + $a = { 35 9A 11 00 00 96 80 35 94 11 00 00 68 80 35 8E 11 00 00 38 80 35 88 11 00 00 } condition: - 2 of ($seq*) + all of them } -rule ELASTIC_Windows_Ransomware_Ragnarok_1Cab7Ea1 : BETA FILE MEMORY +rule ELASTIC_Macos_Trojan_Bundlore_7B9F0C28 : FILE MEMORY { meta: - description = "Identifies RAGNAROK ransomware" + description = "Detects Macos Trojan Bundlore (MacOS.Trojan.Bundlore)" author = "Elastic Security" - id = "1cab7ea1-8d26-4478-ab41-659c193b5baa" - date = "2020-05-03" - modified = "2021-08-23" - reference = "https://twitter.com/malwrhunterteam/status/1256263426441125888?s=20" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ragnarok.yar#L1-L20" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "8bae3ea4304473209fc770673b680154bf227ce30f6299101d93fe830da0fe91" + id = "7b9f0c28-181d-4fdc-8a57-467d5105129a" + date = "2021-10-05" + modified = "2021-10-25" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Bundlore.yar#L201-L219" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "fc4da125fed359d3e1740dafaa06f4db1ffc91dbf22fd5e7993acf8597c4c283" + logic_hash = "32abbb76c866e3a555ee6a9c39f62a0712f641959b66068abfb4379baa9a9da9" score = 75 - quality = 73 - tags = "BETA, FILE, MEMORY" - fingerprint = "e2a8eabb08cb99c4999e05a06d0d0dce46d7e6375a72a6a5e69d718c3d54a3ad" - threat_name = "Windows.Ransomware.Ragnarok" + quality = 75 + tags = "FILE, MEMORY" + fingerprint = "dde16fdd37a16fa4dae24324283cd4b36ed2eb78f486cedd1a6c7bef7cde7370" severity = 100 arch_context = "x86" scan_context = "file, memory" license = "Elastic License v2" - os = "windows" + os = "macos" strings: - $c1 = ".ragnarok" ascii wide fullword + $a = { 35 B6 15 00 00 81 80 35 B0 15 00 00 14 80 35 AA 15 00 00 BC 80 35 A4 15 00 00 } condition: - 1 of ($c*) + all of them } -rule ELASTIC_Windows_Ransomware_Ragnarok_7E802F95 : BETA FILE MEMORY +rule ELASTIC_Windows_Trojan_Blackshades_9D095C44 : FILE MEMORY { meta: - description = "Identifies RAGNAROK ransomware" + description = "Detects Windows Trojan Blackshades (Windows.Trojan.BlackShades)" author = "Elastic Security" - id = "7e802f95-964e-4dd9-a5d1-13a6cd73d750" - date = "2020-05-03" - modified = "2021-08-23" - reference = "https://twitter.com/malwrhunterteam/status/1256263426441125888?s=20" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ragnarok.yar#L22-L42" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "8f293cdbdc3c395e18c304dfa43d0dcdb52b18bde5b5d084190ceec70aea6cbd" + id = "9d095c44-5047-453e-8435-f30de94565e6" + date = "2022-02-28" + modified = "2022-04-12" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_BlackShades.yar#L1-L26" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "e58e352edaa8ae7f95ab840c53fcaf7f14eb640df9223475304788533713c722" + logic_hash = "2a2e6325d3de9289cc8bc26e1fe89a8fa81d9aae50b92ba2cf21c4cc6556ac9e" score = 75 quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "c62b3706a2024751f1346d0153381ac28057995cf95228e43affc3d1e4ad0fad" - threat_name = "Windows.Ransomware.Ragnarok" + tags = "FILE, MEMORY" + fingerprint = "be7d4c8200c293c3c8046d9f87b0d127ff051679ae1caeab12c533ea4309a1fc" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -62883,29 +67103,35 @@ rule ELASTIC_Windows_Ransomware_Ragnarok_7E802F95 : BETA FILE MEMORY os = "windows" strings: - $d1 = { 68 04 94 42 00 FF 35 A0 77 43 00 } - $d2 = { 68 90 94 42 00 FF 35 A0 77 43 00 E8 8F D6 00 00 8B 40 10 50 } + $a1 = "*\\AD:\\Blackshades Project\\bs_net\\server\\server.vbp" wide fullword + $a2 = "@*\\AD:\\Blackshades Project\\bs_net\\server\\server.vbp" wide fullword + $a3 = "D:\\Blackshades Project\\bs_net\\loginserver\\msvbvm60.dll\\3" ascii fullword + $b1 = "modSniff" ascii fullword + $b2 = "UDPFlood" ascii fullword + $b3 = "\\nir_cmd.bss speak text " wide fullword + $b4 = "\\pws_chro.bss" wide fullword + $b5 = "tmrLiveLogger" ascii fullword condition: - 1 of ($d*) + 1 of ($a*) or all of ($b*) } -rule ELASTIC_Windows_Ransomware_Ragnarok_Efafbe48 : BETA FILE MEMORY +rule ELASTIC_Windows_Trojan_Blackshades_Be382Dac : FILE MEMORY { meta: - description = "Identifies RAGNAROK ransomware" + description = "Detects Windows Trojan Blackshades (Windows.Trojan.BlackShades)" author = "Elastic Security" - id = "efafbe48-7740-4c21-b585-467f7ad76f8d" - date = "2020-05-03" - modified = "2021-08-23" - reference = "https://twitter.com/malwrhunterteam/status/1256263426441125888?s=20" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ragnarok.yar#L44-L71" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "c9d203620e0e6e04d717595ca70a5e5efa74abfc11e4e732d729caab2d246c27" + id = "be382dac-6a6f-43e4-86bb-c62f0db9b43a" + date = "2022-02-28" + modified = "2022-04-12" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_BlackShades.yar#L28-L46" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "e58e352edaa8ae7f95ab840c53fcaf7f14eb640df9223475304788533713c722" + logic_hash = "a13e37e7930d2d1ed1aa4fdeb282f11bfeb7fe008625589e2bfeab0beea43580" score = 75 quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "a1535bc01756ac9e986eb564d712b739df980ddd61cfde5a7b001849a6b07b57" - threat_name = "Windows.Ransomware.Ragnarok" + tags = "FILE, MEMORY" + fingerprint = "e7031c42e51758358db32d8eba95f43be7dd5c4b57e6f9a76f0c3b925eae4e43" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -62913,36 +67139,28 @@ rule ELASTIC_Windows_Ransomware_Ragnarok_Efafbe48 : BETA FILE MEMORY os = "windows" strings: - $a1 = "cmd_firewall" ascii fullword - $a2 = "cmd_recovery" ascii fullword - $a3 = "cmd_boot" ascii fullword - $a4 = "cmd_shadow" ascii fullword - $a5 = "readme_content" ascii fullword - $a6 = "readme_name" ascii fullword - $a8 = "rg_path" ascii fullword - $a9 = "cometosee" ascii fullword - $a10 = "&prv_ip=" ascii fullword + $a1 = { 09 0E 4C 09 10 54 09 0E 4C 09 10 54 09 0E 4C 09 10 54 09 10 54 } condition: - 6 of ($a*) + all of them } -rule ELASTIC_Windows_Ransomware_Ragnarok_5625D3F6 : BETA FILE MEMORY +rule ELASTIC_Windows_Ransomware_Generic_99F5A632 : FILE MEMORY { meta: - description = "Identifies RAGNAROK ransomware" + description = "Detects Windows Ransomware Generic (Windows.Ransomware.Generic)" author = "Elastic Security" - id = "5625d3f6-7071-4a09-8ddf-faa2d081b539" - date = "2020-05-03" - modified = "2021-08-23" - reference = "https://twitter.com/malwrhunterteam/status/1256263426441125888?s=20" - source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Ragnarok.yar#L73-L95" - license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt" - logic_hash = "8c22cf9dfbeba7391f6d2370c88129650ef4c778464e676752de1d0fd9c5b34e" + id = "99f5a632-8562-4321-b707-c5f583b14511" + date = "2022-02-24" + modified = "2022-02-24" + reference = "https://github.com/elastic/protections-artifacts/" + source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Generic.yar#L1-L22" + license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt" + hash = "4dc13bb83a16d4ff9865a51b3e4d24112327c526c1392e14d56f20d6f4eaf382" + logic_hash = "2284cfc91d17816f1733e8fe319af52bc66af467364d27f84e213082c216ae8b" score = 75 - quality = 75 - tags = "BETA, FILE, MEMORY" - fingerprint = "5c0a4e2683991929ff6307855bf895e3f13a61bbcc6b3c4b47d895f818d25343" - threat_name = "Windows.Ransomware.Ragnarok" + quality = 73 + tags = "FILE, MEMORY" + fingerprint = "84ab8d177e50bce1a3eceb99befcf05c7a73ebde2f7ea4010617bf4908257fdb" severity = 100 arch_context = "x86" scan_context = "file, memory" @@ -62950,95 +67168,91 @@ rule ELASTIC_Windows_Ransomware_Ragnarok_5625D3F6 : BETA FILE MEMORY os = "windows" strings: - $b1 = "prv_ip" ascii fullword - $b2 = "%i.%i.%i" ascii fullword - $b3 = "pub_ip" ascii fullword - $b4 = "cometosee" ascii fullword + $a1 = "stephanie.jones2024@protonmail.com" + $a2 = "_/C_/projects/403forBiden/wHiteHousE.init" ascii fullword + $a3 = "All your files, documents, photoes, videos, databases etc. have been successfully encrypted" ascii fullword + $a4 = "
Do not try to decrypt then by yourself - it's impossible" ascii fullword
condition:
- all of ($b*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Xworm_732E6C12 : FILE MEMORY
+rule ELASTIC_Linux_Ransomware_Noescape_6De58E0C : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Xworm (Windows.Trojan.Xworm)"
+ description = "Detects Linux Ransomware Noescape (Linux.Ransomware.NoEscape)"
author = "Elastic Security"
- id = "732e6c12-9ee0-4d04-a6e4-9eef874e2716"
- date = "2023-04-03"
- modified = "2023-04-23"
+ id = "6de58e0c-67f9-4344-9fe9-26bfc37e537e"
+ date = "2023-07-27"
+ modified = "2024-02-13"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Xworm.yar#L1-L25"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "bf5ea8d5fd573abb86de0f27e64df194e7f9efbaadd5063dee8ff9c5c3baeaa2"
- logic_hash = "6aa72029eeeb2edd2472bf0db80b9c0ae4033d7d977cbee75ac94414d1cdff7a"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Ransomware_NoEscape.yar#L1-L21"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "46f1a4c77896f38a387f785b2af535f8c29d40a105b63a259d295cb14d36a561"
+ logic_hash = "c275d0cfdadcaabe57c432956e96b4bb344d947899fa5ad55b872e02b4d44274"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "afbef8e590105e16bbd87bd726f4a3391cd6a4489f7a4255ba78a3af761ad2f0"
+ fingerprint = "60a160abcbb6d93d9ee167663e419047f3297d549c534cbe66d035a0aa36d806"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $str1 = "startsp" ascii wide fullword
- $str2 = "injRun" ascii wide fullword
- $str3 = "getinfo" ascii wide fullword
- $str4 = "Xinfo" ascii wide fullword
- $str5 = "openhide" ascii wide fullword
- $str6 = "WScript.Shell" ascii wide fullword
- $str7 = "hidefolderfile" ascii wide fullword
+ $a1 = "HOW_TO_RECOVER_FILES.txt"
+ $a2 = "large_file_size_mb"
+ $a3 = "note_text"
condition:
all of them
}
-rule ELASTIC_Windows_Hacktool_Blackbone_2Ff5Ec38 : FILE
+rule ELASTIC_Linux_Trojan_Hiddad_E35Bff7B : FILE MEMORY
{
meta:
- description = "Detects Windows Hacktool Blackbone (Windows.Hacktool.BlackBone)"
+ description = "Detects Linux Trojan Hiddad (Linux.Trojan.Hiddad)"
author = "Elastic Security"
- id = "2ff5ec38-ce35-432a-8ffa-d459f84438dd"
- date = "2022-04-04"
- modified = "2022-04-04"
+ id = "e35bff7b-1a93-4cfd-a4b6-1e994c0afa98"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_BlackBone.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "4e3887f950bff034efedd40f1e949579854a24140128246fa6141f2c34de6017"
- logic_hash = "0c32bd04460cdf7a56664253992a684c2c684b15ac9ca853b27ab24f07f71607"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Hiddad.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "22a418e660b5a7a2e0cc1c1f3fe1d150831d75c4fedeed9817a221194522efcf"
+ logic_hash = "3881222807585dc933cb61473751d13297fa7eb085a50d435d3b680354a35ee9"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "e3df60931c040081214296f006d98e155a5dc7e285a840a1decb23186ef67465"
- severity = 50
+ tags = "FILE, MEMORY"
+ fingerprint = "0ed46ca8a8bd567acf59d8a15a9597d7087975e608f42af57d36c31e777bb816"
+ severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $str1 = "BlackBone: %s: ZwCreateThreadEx hThread 0x%X"
+ $a = { 3C 14 48 63 CF 89 FE 48 69 C9 81 80 80 80 C1 FE 1F 48 C1 E9 20 }
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
+ all of them
}
-rule ELASTIC_Windows_Trojan_Amadey_7Abb059B : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Pingpull_09Dd9559 : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Amadey (Windows.Trojan.Amadey)"
+ description = "Detects Windows Trojan Pingpull (Windows.Trojan.Pingpull)"
author = "Elastic Security"
- id = "7abb059b-4001-4eec-8185-1e0497e15062"
- date = "2021-06-28"
- modified = "2021-08-23"
+ id = "09dd9559-ce77-4f55-9e81-3b90add40103"
+ date = "2022-06-16"
+ modified = "2022-07-18"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Amadey.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "33e6b58ce9571ca7208d1c98610005acd439f3e37d2329dae8eb871a2c4c297e"
- logic_hash = "23b75d6df9e2a7f8e1efee46ecaf1fc84247312b19a8a1941ddbca1b2ce5e1db"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Pingpull.yar#L1-L25"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "de14f22c88e552b61c62ab28d27a617fb8c0737350ca7c631de5680850282761"
+ logic_hash = "114674b1a9acfc7643138d3b07885343a50c9d319b8d22a6ef34e916685c4469"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "686ae7cf62941d7db051fa8c45f0f7a27440fa0fdc5f0919c9667dfeca46ca1f"
+ fingerprint = "b471e0f40780523bf396323a3b70fd285944fef2960ae43a36068eaf2f2fea4f"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -63046,57 +67260,63 @@ rule ELASTIC_Windows_Trojan_Amadey_7Abb059B : FILE MEMORY
os = "windows"
strings:
- $a = { 18 83 78 14 10 72 02 8B 00 6A 01 6A 00 6A 00 6A 00 6A 00 56 }
+ $s1 = "PROJECT_%s_%s_%08X" ascii fullword
+ $s2 = "Iph1psvc" ascii fullword
+ $s3 = "IP He1per" ascii fullword
+ $s4 = "If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer."
+ $a1 = { 02 C? 66 C7 44 24 ?? 3A 00 4C 8D 44 24 ?? 88 4C 24 ?? 48 83 C9 FF 88 44 24 ?? F2 AE 33 ?? 0F 1F }
+ $a2 = { 48 85 FF 74 ?? 41 C1 E0 04 0F B6 4C 3C ?? 33 D2 8D 41 ?? ?? 19 77 ?? 80 C1 E0 8D 41 ?? 3C 09 77 }
+ $a3 = { 4C 63 74 24 ?? 48 8B ?? 43 8D 44 36 ?? 4C 63 E8 49 8B CD E8 ?? ?? ?? ?? 48 8B ?? 48 85 C0 0F 84 }
condition:
- all of them
+ 3 of them
}
-rule ELASTIC_Windows_Trojan_Amadey_C4Df8D4A : FILE MEMORY
+rule ELASTIC_Linux_Exploit_CVE_2019_13272_583Dd2C0 : FILE MEMORY CVE_2019_13272
{
meta:
- description = "Detects Windows Trojan Amadey (Windows.Trojan.Amadey)"
+ description = "Detects Linux Exploit Cve 2019 13272 (Linux.Exploit.CVE-2019-13272)"
author = "Elastic Security"
- id = "c4df8d4a-01f4-466f-8225-7c7f462b29e7"
- date = "2021-06-28"
- modified = "2021-08-23"
+ id = "583dd2c0-9e94-4d38-bdff-e6c3b7c7d594"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Amadey.yar#L21-L39"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "9039d31d0bd88d0c15ee9074a84f8d14e13f5447439ba80dd759bf937ed20bf2"
- logic_hash = "7f96c4de585223033fb7e7906be6d6898651ecf30be51ed01abde18ef52c0e1e"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_CVE_2019_13272.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "3191b9473f3e59f55e062e6bdcfe61b88974602c36477bfa6855ccd92ff7ca83"
+ logic_hash = "0b25f0d979d2fc3f7d646a9b3eccf2a293b41181b499c790d3e99515fcd09603"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "4623c591ea465e23f041db77dc68ddfd45034a8bde0f20fd5fbcec060851200c"
+ tags = "FILE, MEMORY, CVE-2019-13272"
+ fingerprint = "afc96d47ad2564f69d2fb9a39e882bfc5b4879f0a8abbf36d5e3af6a52dccd63"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = "D:\\Mktmp\\NL1\\Release\\NL1.pdb" fullword
+ $a = { 48 89 85 40 FF FF FF 48 8B 45 D8 48 83 C0 20 48 89 85 38 FF }
condition:
all of them
}
-rule ELASTIC_Linux_Hacktool_Wipelog_Daea1Aa4 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_CVE_2010_3301_79D52Efd : FILE MEMORY CVE_2010_3301
{
meta:
- description = "Detects Linux Hacktool Wipelog (Linux.Hacktool.Wipelog)"
+ description = "Detects Linux Exploit Cve 2010 3301 (Linux.Exploit.CVE-2010-3301)"
author = "Elastic Security"
- id = "daea1aa4-0df7-4308-83e1-0707dcda2e54"
- date = "2022-03-17"
- modified = "2022-07-22"
+ id = "79d52efd-7955-4aa3-afbe-b7d172c30f34"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Hacktool_Wipelog.yar#L1-L29"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "39b3a95928326012c3b2f64e2663663adde4b028d940c7e804ac4d3953677ea6"
- logic_hash = "e2483b7719f4a1e28ec3732120770066333d8db269c9c9711813a8eeb75176d6"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_CVE_2010_3301.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "53a2163ad17a414d9db95f5287d9981c9410e7eaeea096610ba622eb763a6970"
+ logic_hash = "1d4eb14042f552aa1577d0fe452e92c25bda66d0ad1a66e824677bee65908578"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "93f899e14e6331c2149ba5c0c1e9dd8def5a7d1b6d2a7af66eade991dea77b3c"
+ tags = "FILE, MEMORY, CVE-2010-3301"
+ fingerprint = "22235427bc621e07c16c365ddbf22a4e1c04d7a0f23c3e4c46d967d908256567"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -63104,263 +67324,236 @@ rule ELASTIC_Linux_Hacktool_Wipelog_Daea1Aa4 : FILE MEMORY
os = "linux"
strings:
- $s1 = "Erase one username on tty"
- $s2 = "wipe_utmp"
- $s3 = "wipe_acct"
- $s4 = "wipe_lastlog"
- $s5 = "wipe_wtmp"
- $s6 = "getpwnam"
- $s7 = "ERROR: Can't find user in passwd"
- $s8 = "ERROR: Opening tmp ACCT file"
- $s9 = "/var/log/wtmp"
- $s10 = "/var/log/lastlog"
- $s11 = "Patching %s ...."
+ $a = { E8 3B F9 FF FF 83 7D D4 FF 75 16 48 8D 3D 35 03 }
condition:
- 4 of them
+ all of them
}
-rule ELASTIC_Windows_Exploit_Perfusion_5Ab5Ddee : FILE MEMORY
+rule ELASTIC_Linux_Exploit_CVE_2010_3301_D0Eb0924 : FILE MEMORY CVE_2010_3301
{
meta:
- description = "Detects Windows Exploit Perfusion (Windows.Exploit.Perfusion)"
+ description = "Detects Linux Exploit Cve 2010 3301 (Linux.Exploit.CVE-2010-3301)"
author = "Elastic Security"
- id = "5ab5ddee-e79b-4f1c-bd60-92793f14e490"
- date = "2024-02-28"
- modified = "2024-03-21"
+ id = "d0eb0924-dae1-46f9-a4d0-c9e69f781a22"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Exploit_Perfusion.yar#L1-L22"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "7fdef25acb0d1447203b9768ae58a8e21db24816c602b160d105dab86ae34728"
- logic_hash = "490f3fc89cf78dbe82f1feb012a147a8d187612720efb6e1eb4e97720b26ee59"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_CVE_2010_3301.yar#L21-L39"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "907995e90a80d3ace862f2ffdf13fd361762b5acc5397e14135d85ca6a61619b"
+ logic_hash = "5229be3d1997ee4d05846d6804ffafd36c088dd8607a1fba39a0a43950e448c1"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "c8d13213b20fc99dd71034ddae986c71f6e89f632655e88d5f9c8be1d72c6231"
+ tags = "FILE, MEMORY, CVE-2010-3301"
+ fingerprint = "bb288a990938aa21aba087a0400d6f4765a622f8ed36d1dd7953d09cbb09ff83"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $s1 = "SYSTEM\\CurrentControlSet\\Services\\%ws\\Performance" wide
- $s2 = "Win32_Perf" wide
- $s3 = "CollectPerfData" wide
- $s4 = "%wsperformance_%d_%d_%d.dll" wide
+ $a = { E8 3C FA FF FF 83 7D EC FF 75 19 BF 20 13 40 00 }
condition:
all of them
}
-rule ELASTIC_Windows_Trojan_Diceloader_B32C6B99 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_CVE_2010_3301_A5828970 : FILE MEMORY CVE_2010_3301
{
meta:
- description = "Detects Windows Trojan Diceloader (Windows.Trojan.Diceloader)"
+ description = "Detects Linux Exploit Cve 2010 3301 (Linux.Exploit.CVE-2010-3301)"
author = "Elastic Security"
- id = "b32c6b99-f634-4c6f-98f4-39954ef15afa"
- date = "2021-04-23"
- modified = "2021-08-23"
+ id = "a5828970-7a30-421c-be92-5659c18b88d1"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Diceloader.yar#L1-L25"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "a3b3f56a61c6dc8ba2aa25bdd9bd7dc2c5a4602c2670431c5cbc59a76e2b4c54"
- logic_hash = "f9e023f340edc4c46b2926e750c2ad3a3798e34415e43c0ea2d83073e3dc526a"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_CVE_2010_3301.yar#L41-L59"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "4fc781f765a65b714ec27080f25c03f20e06830216506e06325240068ba62d83"
+ logic_hash = "61b0cb38a6e14efee157547e811450d2ed4674f79ac86656a8d984084f71a665"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "15d4bc57c03a560608ae69551aa46d1786072b3d78d747512f8ac3e6822a7b93"
+ tags = "FILE, MEMORY, CVE-2010-3301"
+ fingerprint = "72223f502b2a129380ab011b785f6589986d2eb177580339755d12840617ce5f"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = "D$0GET " ascii fullword
- $a2 = "D$THostf" ascii fullword
- $a3 = "D$,POST" ascii fullword
- $a4 = "namef" ascii fullword
- $a5 = "send" ascii fullword
- $a6 = "log.ini" wide
- $a7 = { 70 61 73 73 00 00 65 6D 61 69 6C 00 00 6C 6F 67 69 6E 00 00 73 69 67 6E 69 6E 00 00 61 63 63 6F 75 6E 74 00 00 70 65 72 73 69 73 74 65 6E 74 00 00 48 6F 73 74 3A 20 }
+ $a = { E8 7C FC FF FF 83 7D EC FF 75 19 BF 40 0E 40 00 }
condition:
all of them
}
-rule ELASTIC_Windows_Trojan_Diceloader_15Eeb7B9 : FILE MEMORY
+rule ELASTIC_Linux_Trojan_Sqlexp_1Aa5001E : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Diceloader (Windows.Trojan.Diceloader)"
+ description = "Detects Linux Trojan Sqlexp (Linux.Trojan.Sqlexp)"
author = "Elastic Security"
- id = "15eeb7b9-311f-477b-8ae1-b8f689a154b7"
- date = "2021-04-23"
- modified = "2021-08-23"
+ id = "1aa5001e-0609-4830-9c6f-675985fa50cf"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Diceloader.yar#L27-L46"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "a1202df600d11ad2c61050e7ba33701c22c2771b676f54edd1846ef418bea746"
- logic_hash = "f1ab9ad69f9ea75343c7404b82a3f7a4976a442b980a98fe5b95c55d4f9cb34e"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Sqlexp.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "714a520fc69c54bcd422e75f4c3b71ce636cfae7fcec3c5c413d1294747d2dd6"
+ logic_hash = "48c7331c80aa7d918f46d282c6f38b8e780f9b5222cf9304bf1a8bb39cc129ab"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "4cc70bec5d241c6f84010fbfe2eafbc6ec6d753df2bb3f52d9498b54b11fc8cb"
+ fingerprint = "afce33f5bf064afcbd8b1639755733c99171074457272bf08f0c948d67427808"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = { E9 92 9D FF FF C3 E8 }
- $a2 = { E9 E8 61 FF FF C3 E8 }
+ $a = { 89 E3 52 53 89 E1 B0 0B CD 80 00 00 ?? 00 }
condition:
- any of them
+ all of them
}
-rule ELASTIC_Windows_Trojan_Revcoderat_8E6D4182 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Cornelgen_584A227A : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Revcoderat (Windows.Trojan.Revcoderat)"
+ description = "Detects Linux Exploit Cornelgen (Linux.Exploit.Cornelgen)"
author = "Elastic Security"
- id = "8e6d4182-4ea8-4d4c-ad3a-d16b42e387f4"
- date = "2021-09-02"
- modified = "2022-01-13"
+ id = "584a227a-bf17-4620-8b10-97676f12ea5b"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Revcoderat.yar#L1-L22"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "77732e74850050bb6f935945e510d32a0499d820fa1197752df8bd01c66e8210"
- logic_hash = "35626d752b291e343350534aece35f1d875068c2c050d12312a60e67753c71e1"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Cornelgen.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "c823cb669f1d6cb9258d6f0b187609c226af23396f9c5be26eb479e5722a9d97"
+ logic_hash = "db3b6bbab48074449ae8b404f8fa77d93cde1ab8e57bd4ad981ac2afb8226494"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "bc259d888e913dffb4272e2f871592238eb78922989d30ac4dc23cdeb988cc78"
+ fingerprint = "65a23e20166b99544b2d0b4969240618d50e80a53a69829756721e19e4e6899f"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = "PLUGIN_PROCESS_REVERSE_PROXY: Plugin already exists, skipping download!" ascii fullword
- $a2 = "TARGET_HOST_UPDATE(): Sync successful!" ascii fullword
- $a3 = "WEBCAM_ACTIVATE: Plugin already exists, skipping download!" ascii fullword
- $a4 = "send_keylog_get" ascii fullword
+ $a = { 6E 89 E3 52 53 89 E1 B0 0B CD 80 31 C0 40 CD 80 }
condition:
all of them
}
-rule ELASTIC_Windows_Vulndriver_Gvci_F5A35359 : FILE
+rule ELASTIC_Linux_Exploit_Cornelgen_Be0Bc02D : FILE MEMORY
{
meta:
- description = "Detects Windows Vulndriver Gvci (Windows.VulnDriver.Gvci)"
+ description = "Detects Linux Exploit Cornelgen (Linux.Exploit.Cornelgen)"
author = "Elastic Security"
- id = "f5a35359-ee16-444a-aafd-c4ef162e46d4"
- date = "2022-04-04"
- modified = "2022-04-04"
+ id = "be0bc02d-2d9d-4cbe-9d6a-3a88ffa1234b"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_Gvci.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "42f0b036687cbd7717c9efed6991c00d4e3e7b032dc965a2556c02177dfdad0f"
- logic_hash = "beb0c324358a016e708dae30a222373113a7eab8e3d90dfa1bbde6c2f7874362"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Cornelgen.yar#L21-L39"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "24c0ba8ad4f543f9b0aff0d0b66537137bc78606b47ced9b6d08039bbae78d80"
+ logic_hash = "67c4f2d875f233b52fcbc24d9225c51af4dc09c27ce3915f0d756202bd4e5867"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "590e6b10c8bd1c299eb4ecd1368ac05d8811147c7ce3976de5e86d1a6d8bc14f"
- severity = 50
+ tags = "FILE, MEMORY"
+ fingerprint = "6b57eb6fd3c8e28cbff5e7cc51246de74ca7111a9cd1c795b21aa89142a693b4"
+ severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $str1 = "\\GVCIDrv64.pdb"
+ $a = { 8B 44 24 08 A3 B8 9F 04 08 0F B7 05 04 A1 04 08 }
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Godpotato_5F1Aad81 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Cornelgen_03Ee53D3 : FILE MEMORY
{
meta:
- description = "Detects Windows Hacktool Godpotato (Windows.Hacktool.GodPotato)"
+ description = "Detects Linux Exploit Cornelgen (Linux.Exploit.Cornelgen)"
author = "Elastic Security"
- id = "5f1aad81-88d8-4561-a6f9-d7521b9ffdf5"
- date = "2024-06-24"
- modified = "2024-07-02"
+ id = "03ee53d3-4f03-4c5e-9187-45e0e33584b4"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_GodPotato.yar#L1-L28"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "00171bb6e9e4a9b8601e988a8c4ac6f5413e31e1b6d86d24b0b53520cd02184c"
- logic_hash = "3028c84a616d47b37b4ef2d41d35ccef5121c06aa042096bca8ea53b528a1eb9"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Cornelgen.yar#L41-L59"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "711eafd09d4e5433be142d54db153993ee55b6c53779d8ec7e76ca534b4f81a5"
+ logic_hash = "e7d9c66621ad3c56f3bb8150c17b10495053d9485b2143750aeefd3c55ab7943"
score = 75
- quality = 25
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "3645a259f9b5d07bd5ad2ec823fd704eccd0412dd75c47bc82124db9a907da2a"
+ fingerprint = "f2a8ecfffb0328c309a3a5db7e62fae56bf168806a1db961a57effdebba7645e"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = "GodPotato" wide fullword
- $a2 = "GodPotatoContext was not initialized" wide fullword
- $a3 = "GodPotatoStorageTrigger" ascii fullword
- $a4 = "[*] DCOM obj GUID: {0}" wide fullword
- $a5 = "[*] DispatchTable: 0x{0:x}" wide fullword
- $a6 = "[*] UseProtseqFunction: 0x{0:x}" wide fullword
- $a7 = "[*] process start with pid {0}" wide fullword
- $a8 = "[!] ImpersonateNamedPipeClient fail error:{0}" wide fullword
- $a9 = "[*] CoGetInstanceFromIStorage: 0x{0:x}" wide fullword
- $a10 = "[*] Trigger RPCS" wide
+ $a = { C9 B0 27 CD 80 31 C0 B0 3D CD 80 31 C0 8D 5E 02 }
condition:
- 5 of them
+ all of them
}
-rule ELASTIC_Linux_Exploit_CVE_2018_10561_0F246E33 : FILE MEMORY CVE_2018_10561
+rule ELASTIC_Windows_Trojan_Stormkitty_6256031A : FILE MEMORY
{
meta:
- description = "Detects Linux Exploit Cve 2018 10561 (Linux.Exploit.CVE-2018-10561)"
+ description = "Detects Windows Trojan Stormkitty (Windows.Trojan.StormKitty)"
author = "Elastic Security"
- id = "0f246e33-0e98-4778-8a2f-14876d1a0efe"
- date = "2021-01-12"
- modified = "2021-09-16"
+ id = "6256031a-e7dd-423b-a83f-4db428cb3d1b"
+ date = "2022-03-21"
+ modified = "2022-04-12"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_CVE_2018_10561.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "eac08c105495e6fadd8651d2e9e650b6feba601ec78f537b17fb0e73f2973a1c"
- logic_hash = "2c3785ddfded7128e983f3ec17a9f77c856d903f07e325b08f9f463950576ebe"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_StormKitty.yar#L1-L24"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "0c69015f534d1da3770dbc14183474a643c4332de6a599278832abd2b15ba027"
+ logic_hash = "a797e87eaf5b173da9dd43fcff03b3d26198dcafa29c3f2ca369773c73001234"
score = 75
quality = 75
- tags = "FILE, MEMORY, CVE-2018-10561"
- fingerprint = "718b66d3d65d31f0908c8f7d7aee8113e9b51cb576cd725bbca1a23d3ccd4d72"
+ tags = "FILE, MEMORY"
+ fingerprint = "6f0463de42c97701b0f3b8172e7e461501357921a3d11e6ca467bd1ca397d0b6"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $a = { 0B DF 0B 75 87 8C 5C 03 03 7A 4B 7A 95 4A A5 D2 13 6A 6A 5A 5A }
+ $a1 = "https://github.com/LimerBoy/StormKitty" ascii fullword
+ $a2 = "127.0.0.1 www.malwarebytes.com" wide fullword
+ $a3 = "KillDefender"
+ $a4 = "Username: {1}" wide fullword
+ $a5 = "# End of Cookies" wide fullword
+ $a6 = "# End of Passwords" wide fullword
condition:
all of them
}
-rule ELASTIC_Macos_Trojan_Rustbucket_E64F7A92 : FILE MEMORY
+rule ELASTIC_Macos_Trojan_Electrorat_B4Dbfd1D : FILE MEMORY
{
meta:
- description = "Detects Macos Trojan Rustbucket (MacOS.Trojan.RustBucket)"
+ description = "Detects Macos Trojan Electrorat (MacOS.Trojan.Electrorat)"
author = "Elastic Security"
- id = "e64f7a92-e530-4d0b-8ecb-fe5756ad648c"
- date = "2023-06-26"
- modified = "2023-06-29"
- reference = "https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/MacOS_Trojan_RustBucket.yar#L1-L22"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "9ca914b1cfa8c0ba021b9e00bda71f36cad132f27cf16bda6d937badee66c747"
- logic_hash = "bd6005d72faba6aaeebdcbd8c771995cbfc667faf01eb93825afe985954a47fc"
+ id = "b4dbfd1d-4968-4121-a4c2-5935b7f76fc1"
+ date = "2021-09-30"
+ modified = "2021-10-25"
+ reference = "https://github.com/elastic/protections-artifacts/"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Electrorat.yar#L1-L22"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "b1028b38fcce0d54f2013c89a9c0605ccb316c36c27faf3a35adf435837025a4"
+ logic_hash = "a36143a8c93cb187dba0a88a15550219c19f1483502f782dfefc1e53829cfbf1"
score = 75
- quality = 75
+ quality = 71
tags = "FILE, MEMORY"
- fingerprint = "f9907f46c345a874b683809f155691723e3a6df7c48f6f4e6eb627fb3dd7904d"
+ fingerprint = "fa65fc0a8f5b1f63957c586e6ca8e8fbdb811970f25a378a4ff6edf5e5c44da7"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -63368,247 +67561,240 @@ rule ELASTIC_Macos_Trojan_Rustbucket_E64F7A92 : FILE MEMORY
os = "macos"
strings:
- $user_agent = "User-AgentMozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)"
- $install_log = "/var/log/install.log"
- $timestamp = "%Y-%m-%d %H:%M:%S"
+ $a1 = "_TtC9Keylogger9Keylogger" ascii fullword
+ $a2 = "_TtC9Keylogger17CallBackFunctions" ascii fullword
+ $a3 = "\\DELETE-FORWARD" ascii fullword
+ $a4 = "\\CAPSLOCK" ascii fullword
condition:
all of them
}
-rule ELASTIC_Multi_Trojan_Sliver_42298C4A : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Deimos_F53Aee03 : FILE MEMORY
{
meta:
- description = "Detects Multi Trojan Sliver (Multi.Trojan.Sliver)"
+ description = "Detects Windows Trojan Deimos (Windows.Trojan.Deimos)"
author = "Elastic Security"
- id = "42298c4a-fcea-4c5a-b213-32db00e4eb5a"
- date = "2021-10-20"
- modified = "2022-01-14"
- reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_Trojan_Sliver.yar#L1-L25"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "3b45aae401ac64c055982b5f3782a3c4c892bdb9f9a5531657d50c27497c8007"
- logic_hash = "a84bdb51fcdeb4629365bdb727b53087604ee0eb112c8d6c3ecf315598ec678a"
+ id = "f53aee03-74c3-4b40-8ae4-4f1bf35f88c8"
+ date = "2021-09-18"
+ modified = "2022-01-13"
+ reference = "https://www.elastic.co/security-labs/going-coast-to-coast-climbing-the-pyramid-with-the-deimos-implant"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Deimos.yar#L1-L22"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "2c1941847f660a99bbc6de16b00e563f70d900f9dbc40c6734871993961d3d3e"
+ logic_hash = "07675844a8790f8485b6545e7466cdef8ac4f92dec4cd8289aeaad2a0a448691"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "0734b090ea10abedef4d9ed48d45c834dd5cf8e424886a5be98e484f69c5e12a"
+ fingerprint = "12a6d7f9e4f9a937bf1416443dd0d5ee556ac1f67d2b56ad35f9eac2ee6aac74"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "multi"
+ os = "windows"
strings:
- $a1 = ").RequestResend"
- $a2 = ").GetPrivInfo"
- $a3 = ").GetReconnectIntervalSeconds"
- $a4 = ").GetPivotID"
- $a5 = "name=PrivInfo"
- $a6 = "name=ReconnectIntervalSeconds"
- $a7 = "name=PivotID"
+ $a1 = "\\APPDATA\\ROAMING" wide fullword
+ $a2 = "{\"action\":\"ping\",\"" wide fullword
+ $a3 = "Deimos" ascii fullword
condition:
- 2 of them
+ all of ($a*)
}
-rule ELASTIC_Multi_Trojan_Sliver_3Bde542D : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Deimos_C70677B4 : FILE MEMORY
{
meta:
- description = "Detects Multi Trojan Sliver (Multi.Trojan.Sliver)"
+ description = "Detects Windows Trojan Deimos (Windows.Trojan.Deimos)"
author = "Elastic Security"
- id = "3bde542d-df52-4f05-84ff-de67e90592a9"
- date = "2022-08-31"
- modified = "2022-09-29"
- reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_Trojan_Sliver.yar#L27-L50"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "05461e1c2a2e581a7c30e14d04bd3d09670e281f9f7c60f4169e9614d22ce1b3"
- logic_hash = "23a0e28c1423f577a147efdf927f2dc71871760e38d4d7494ead2920b90ef05e"
+ id = "c70677b4-f5ba-440b-ba31-31e80caee2fe"
+ date = "2021-09-18"
+ modified = "2022-01-13"
+ reference = "https://www.elastic.co/security-labs/going-coast-to-coast-climbing-the-pyramid-with-the-deimos-implant"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Deimos.yar#L24-L44"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "2c1941847f660a99bbc6de16b00e563f70d900f9dbc40c6734871993961d3d3e"
+ logic_hash = "c969221f025b114b9d5738d43b6021ab9481dbc6b35eb129ea4f806160b1adc3"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "e52e39644274e3077769da4d04488963c85a0b691dc9973ad12d51eb34ba388b"
+ fingerprint = "ffe0dec3585da9cbb9f8a0fac1bb6fd43d5d6e20a6175aaa889ae13ef2ed101f"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "multi"
+ os = "windows"
strings:
- $a1 = "B/Z-github.com/bishopfox/sliver/protobuf/sliverpbb" ascii fullword
- $b1 = "InvokeSpawnDllReq" ascii fullword
- $b2 = "NetstatReq" ascii fullword
- $b3 = "HTTPSessionInit" ascii fullword
- $b4 = "ScreenshotReq" ascii fullword
- $b5 = "RegistryReadReq" ascii fullword
+ $a1 = { 00 57 00 58 00 59 00 5A 00 5F 00 00 17 75 00 73 00 65 00 72 00 }
+ $a2 = { 0C 08 16 1F 68 9D 08 17 1F 77 9D 08 18 1F 69 9D 08 19 1F 64 9D }
condition:
- 1 of ($a*) or all of ($b*)
+ 1 of ($a*)
}
-rule ELASTIC_Multi_Trojan_Sliver_3D6B7Cd3 : FILE MEMORY
+rule ELASTIC_Windows_Exploit_Generic_E95Cc41C : FILE
{
meta:
- description = "Detects Multi Trojan Sliver (Multi.Trojan.Sliver)"
+ description = "Detects Windows Exploit Generic (Windows.Exploit.Generic)"
author = "Elastic Security"
- id = "3d6b7cd3-f702-470c-819c-8750ec040083"
- date = "2022-12-01"
- modified = "2023-09-20"
+ id = "e95cc41c-6cad-4b9c-b647-3c60e6614e25"
+ date = "2024-02-28"
+ modified = "2024-06-12"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_Trojan_Sliver.yar#L52-L88"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "9846124cfd124eed466465d187eeacb4d405c558dd84ba8e575d8a7b3290403e"
- logic_hash = "3cbd3358b7d59d6a2912069f4cb8de005b6fafd61e44111d1f6cf0418eb2d1fc"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Exploit_Generic.yar#L1-L32"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "4cce9e39c376f67c16df3bcd69efd9b7472c3b478e2e5ef347e1410f1105c38d"
+ logic_hash = "9b620988a6ee84ed0cbb0fb0a3cca633fffc8e6369ed45455e9e1e6c021ea461"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "46d5388bd1fe767a4852c9e35420985d5011368dac6545fd57fbb256de9a94e9"
+ tags = "FILE"
+ fingerprint = "78f78de7cee54107ee7c3de9b152ce3a242c1408115ab0950ccdfc278ed15a19"
severity = 100
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
- os = "multi"
+ os = "windows"
strings:
- $session_start_x86_1 = { 89 4C 24 ?? 89 44 24 ?? 8D 4C 24 ?? 89 4C 24 ?? C6 44 24 ?? ?? 89 04 24 E8 ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? }
- $session_start_x86_2 = { FF 05 ?? ?? ?? ?? 8D 05 ?? ?? ?? ?? 89 04 24 C7 44 24 ?? ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 4C 24 ?? 85 C9 74 ?? B8 ?? ?? ?? ?? }
- $session_start_x86_3 = { E8 ?? ?? ?? ?? 8B 44 24 ?? 85 C0 74 ?? FF 05 ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B 04 24 39 05 ?? ?? ?? ?? 7E ?? C6 44 24 ?? ?? 8B 54 24 ?? 8B 02 FF D0 83 C4 ?? }
- $session_start_x64_1 = { 44 0F 11 7C 24 ?? 48 8D 0D ?? ?? ?? ?? 48 89 4C 24 ?? 48 89 44 24 ?? 48 8D 4C 24 ?? 48 89 4C 24 ?? C6 44 24 ?? ?? 0F 1F 00 E8 ?? ?? ?? ?? 48 89 44 24 ?? 48 C7 44 24 ?? ?? ?? ?? ?? EB ?? E8 ?? ?? ?? ?? E8 ?? ?? ?? ?? }
- $session_start_x64_2 = { E8 ?? ?? ?? ?? 48 85 C0 74 ?? 48 FF 05 ?? ?? ?? ?? 48 8D 05 ?? ?? ?? ?? BB ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 85 DB B9 ?? ?? ?? ?? 48 0F 45 C1 48 39 05 ?? ?? ?? ?? 7E ?? C6 44 24 ?? ?? 48 8B 54 24 ?? 48 8B 02 FF D0 }
- $session_start_x64_3 = { 48 89 6C 24 ?? 48 8D 6C 24 ?? 49 C7 C5 ?? ?? ?? ?? 4C 89 6C 24 ?? C6 44 24 ?? ?? 48 8D 05 ?? ?? ?? ?? 31 DB E8 ?? ?? ?? ?? 44 0F 11 7C 24 ?? 48 8D 0D ?? ?? ?? ?? 48 89 4C 24 ?? 48 89 44 24 ?? 48 8D 4C 24 ?? 48 89 4C 24 ?? C6 44 24 ?? ?? 0F 1F 00 }
- $register_x64_1 = { 48 81 EC ?? ?? ?? ?? 48 89 AC 24 ?? ?? ?? ?? 48 8D AC 24 ?? ?? ?? ?? 90 E8 ?? ?? ?? ?? 48 89 44 24 ?? 48 89 5C 24 ?? 48 89 4C 24 ?? 0F 1F 44 00 ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 85 C9 48 8B 4C 24 ?? BA ?? ?? ?? ?? 48 0F 45 CA 48 89 4C 24 ?? 48 8B 54 24 ?? BE ?? ?? ?? ?? 48 0F 45 D6 48 89 54 24 ?? }
- $register_x64_2 = { 48 8D 1D ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? }
- $register_x64_3 = { E8 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 5C 24 ?? 48 89 4C 24 ?? 66 90 E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 85 C9 48 8B 8C 24 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 0F 45 CA 48 8B 54 24 ?? BE ?? ?? ?? ?? 48 0F 45 D6 48 85 DB 74 ?? 48 8D BC 24 ?? ?? ?? ?? 48 8D 7F ?? 0F 1F 00 48 89 6C 24 ?? 48 8D 6C 24 ?? }
- $register_x64_4 = { 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 89 8C 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 8B 8C 24 ?? ?? ?? ?? 48 85 C9 48 8B 8C 24 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 0F 45 CA 48 89 8C 24 ?? ?? ?? ?? 48 8B B4 24 ?? ?? ?? ?? BF ?? ?? ?? ?? 48 0F 45 F7 48 89 B4 24 ?? ?? ?? ?? }
- $register_x64_5 = { 48 89 84 24 ?? ?? ?? ?? 48 89 5C 24 ?? 48 89 4C 24 ?? E8 ?? ?? ?? ?? 48 8B 4C 24 ?? 48 85 C9 48 8B 8C 24 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 0F 45 CA 48 89 8C 24 ?? ?? ?? ?? 48 8B 54 24 ?? BE ?? ?? ?? ?? 48 0F 45 D6 48 89 54 24 ?? }
- $register_x64_6 = { E8 ?? ?? ?? ?? 48 8B 6D ?? 48 8B 94 24 ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 89 94 24 ?? ?? ?? ?? 48 8B 54 24 ?? 48 89 94 24 ?? ?? ?? ?? 48 89 84 24 ?? ?? ?? ?? 48 89 9C 24 ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? }
- $register_x64_7 = { E8 ?? ?? ?? ?? C7 40 ?? ?? ?? ?? ?? 48 8B 4C 24 ?? 48 89 48 ?? 48 8B 4C 24 ?? 48 89 48 ?? 83 3D ?? ?? ?? ?? ?? 75 ?? }
- $register_x64_8 = { 48 8D 7F ?? 0F 1F 00 48 89 6C 24 ?? 48 8D 6C 24 ?? E8 ?? ?? ?? ?? 48 8B 6D ?? 4C 8D 15 ?? ?? ?? ?? 4C 89 94 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 4C 89 94 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 4C 89 94 24 ?? ?? ?? ?? 48 C7 84 24 ?? ?? ?? ?? ?? ?? ?? ?? 48 8D 84 24 ?? ?? ?? ?? }
- $register_x86_1 = { E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 0C 24 8B 54 24 ?? 85 C0 74 ?? 31 C9 31 D2 89 54 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 04 24 8B 4C 24 ?? 85 C9 74 ?? 8D 7C 24 ?? }
- $register_x86_2 = { 8D 0D ?? ?? ?? ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 89 4C 24 ?? C7 44 24 ?? ?? ?? ?? ?? 8D 44 24 ?? }
- $register_x86_3 = { C7 40 ?? ?? ?? ?? ?? 8D 0D ?? ?? ?? ?? 89 48 ?? 8B 4C 24 ?? 89 48 ?? 8B 4C 24 ?? 89 48 ?? 8B 0D ?? ?? ?? ?? 85 C9 75 ?? }
- $register_x86_4 = { E8 ?? ?? ?? ?? 8B 44 24 ?? 8B 0C 24 8B 54 24 ?? 85 C0 74 ?? 31 C9 31 D2 89 54 24 ?? 89 ?? 24 }
- $register_x86_5 = { 8B 04 24 89 84 24 ?? ?? ?? ?? 8B 4C 24 ?? 89 4C 24 ?? E8 ?? ?? ?? ?? 8B 04 24 8B 4C 24 ?? 8B 54 24 ?? 85 D2 74 ?? 31 C0 31 C9 89 4C 24 ?? 89 84 24 ?? ?? ?? ?? 8D 15 ?? ?? ?? ?? 89 14 24 E8 ?? ?? ?? ?? }
+ $s1 = "Got system privileges" nocase
+ $s2 = "Got SYSTEM token" nocase
+ $s3 = "Got a SYSTEM token" nocase
+ $s4 = "] Duplicating SYSTEM token" nocase
+ $s5 = "] Token Stealing is successful" nocase
+ $s6 = "] Exploit completed" nocase
+ $s7 = "] Got SYSTEM shell." nocase
+ $s8 = "] Spawning SYSTEM shell" nocase
+ $s9 = "we have a SYSTEM shell!" nocase
+ $s10 = "Dropping to System Shell." nocase
+ $s11 = "] Enjoy the NT AUTHORITY\\SYSTEM shell" nocase
+ $s12 = "] SMEP is disabled" nocase
+ $s13 = "] KUSER_SHARED_DATA"
+ $s14 = "] Found System EPROCESS"
condition:
- 1 of ($session_start_*) and 1 of ($register_*)
+ any of them
}
-rule ELASTIC_Linux_Ransomware_Quantum_8513Fb8B : FILE MEMORY
+rule ELASTIC_Windows_Exploit_Generic_008359Cf : FILE
{
meta:
- description = "Detects Linux Ransomware Quantum (Linux.Ransomware.Quantum)"
+ description = "Detects Windows Exploit Generic (Windows.Exploit.Generic)"
author = "Elastic Security"
- id = "8513fb8b-43f7-46b1-8318-5549a7609d3b"
- date = "2023-07-28"
- modified = "2024-02-13"
+ id = "008359cf-5510-4f91-8cb1-7b4ff645bf2d"
+ date = "2024-02-28"
+ modified = "2024-06-12"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Ransomware_Quantum.yar#L1-L20"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "3bcb9ad92fdca53195f390fc4d8d721b504b38deeda25c1189a909a7011406c9"
- logic_hash = "7e24be541bafc2427ecd8f76b7774fb65d7421bc300503eeb068b8104e168c70"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Exploit_Generic.yar#L34-L57"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "73225a3a54560965f4c4fae73f7ee234e31217bc06ff8ba1d0b36ebab5e76a87"
+ logic_hash = "9514241b5573c8d01ccd012195e29aefc3ef8a12eb982e6dd9ec66b00c064bd8"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "1c1af76ab5df8243b8e25555f1762749ca60da56fecea9d4131c612358244525"
+ tags = "FILE"
+ fingerprint = "3ef3b6bbe2141cb8ce47a5ee7c7531e72773d4dc4e478bb792c9230e4948db02"
severity = 100
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $a1 = "All your files are encrypted on all devices across the network"
- $a2 = "process with pid %d is blocking %s, going to kill it"
+ $a1 = { C6 85 ?? 01 00 00 74 C6 85 ?? 01 00 00 58 C6 85 ?? 01 00 00 58 }
+ $a2 = { C6 45 ?? 41 C6 45 ?? 66 C6 45 ?? 64 C6 45 ?? 4F C6 45 ?? 70 C6 45 ?? 65 C6 45 ?? 6E C6 45 ?? 50 C6 45 ?? 61 C6 45 ?? 63 C6 45 ?? 6B C6 45 ?? 65 C6 45 ?? 74 C6 45 ?? 58 C6 45 ?? 58 }
+ $b1 = "NtCreateFile"
+ $b2 = "\\Device\\Afd\\Endpoint" wide nocase
+ $b3 = "\\Device\\Afd\\Endpoint" nocase
+ $b4 = "NtDeviceIoControlFile"
condition:
- all of them
+ 1 of ($a*) and 3 of ($b*)
}
-rule ELASTIC_Windows_Trojan_Rhadamanthys_21B60705 : FILE MEMORY
+rule ELASTIC_Windows_Exploit_Generic_8C54846D : FILE
{
meta:
- description = "Detects Windows Trojan Rhadamanthys (Windows.Trojan.Rhadamanthys)"
+ description = "Detects Windows Exploit Generic (Windows.Exploit.Generic)"
author = "Elastic Security"
- id = "21b60705-9696-43ba-a820-d8ab9c34cca2"
- date = "2023-03-19"
- modified = "2023-04-23"
+ id = "8c54846d-07ee-43bc-93e1-72bf4162ab87"
+ date = "2024-02-29"
+ modified = "2024-06-12"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Rhadamanthys.yar#L1-L25"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "3ba97c51ba503fa4bdcfd5580c75436bc88794b4ae883afa1d92bb0b2a0f5efe"
- logic_hash = "ef3f60689d72553111b42b27e0a1a0316288ae07fbfaf159eea8c76380d528fa"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Exploit_Generic.yar#L59-L87"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "b6ea4815a38e606d4a2d6e6d711e610afec084db6899b7d6fc874491dd939495"
+ logic_hash = "0662c8edb449e15b16be3e53a88cf62af46b4a656c1a49b399e131c2ad71b55a"
score = 75
- quality = 50
- tags = "FILE, MEMORY"
- fingerprint = "8a756bf4a8c9402072531aca2c29a382881c1808a790432ccac2240b35c09383"
+ quality = 71
+ tags = "FILE"
+ fingerprint = "9acb35c06a21e35639c8026a18e919329db82a0629a8e2267f1f4fe00b3bb871"
severity = 100
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
os = "windows"
strings:
- $a1 = "Session\\%u\\MSCTF.Asm.{%08lx-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}" wide fullword
- $a2 = "MSCTF.Asm.{%08lx-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}" wide fullword
- $a3 = " \"%s\",Options_RunDLL %s" wide fullword
- $a4 = "%%TEMP%%\\vcredist_%05x.dll" wide fullword
- $a5 = "%%APPDATA%%\\vcredist_%05x.dll" wide fullword
- $a6 = "TEQUILABOOMBOOM" wide fullword
- $a7 = "%Systemroot%\\system32\\rundll32.exe" wide fullword
+ $a1 = { 5C 63 76 65 2D 32 30 ?? ?? 2D ?? ?? ?? ?? 5C 78 36 34 5C 52 65 6C 65 61 73 65 5C }
+ $a2 = { 5C 43 56 45 2D 32 30 ?? ?? 2D ?? ?? ?? ?? 5C 78 36 34 5C 52 65 6C 65 61 73 65 5C }
+ $a3 = { 5C 78 36 34 5C 52 65 6C 65 61 73 65 5C 43 56 45 2D 32 30 ?? ?? 2D ?? ?? ?? ?? ?? 2E 70 64 62 }
+ $a4 = { 5C 52 65 6C 65 61 73 65 5C 43 56 45 2D 32 30 ?? ?? 2D }
+ $a5 = "\\x64\\Release\\CmdTest.pdb"
+ $a6 = "\\x64\\Release\\RunPS.pdb"
+ $a7 = "X:\\tools\\0day\\"
+ $a8 = "C:\\work\\volodimir_"
+ $a9 = { 78 36 34 5C 52 65 6C 65 61 73 65 5C 65 78 70 6C 6F 69 74 2E 70 64 62 }
+ $b1 = { 5C 43 56 45 2D 32 30 ?? ?? 2D }
+ $b2 = { 5C 78 36 34 5C 52 65 6C 65 61 73 65 5C }
condition:
- 4 of them
+ any of ($a*) or all of ($b*)
}
-rule ELASTIC_Windows_Trojan_Rhadamanthys_1Da1C2C2 : FILE MEMORY
+rule ELASTIC_Macos_Backdoor_Keyboardrecord_832F7Bac : FILE
{
meta:
- description = "Detects Windows Trojan Rhadamanthys (Windows.Trojan.Rhadamanthys)"
+ description = "Detects Macos Backdoor Keyboardrecord (MacOS.Backdoor.Keyboardrecord)"
author = "Elastic Security"
- id = "1da1c2c2-90ea-4f76-aa38-666934c0aa68"
- date = "2023-03-28"
- modified = "2023-04-23"
+ id = "832f7bac-3896-4934-b05f-8215a41cca74"
+ date = "2021-11-11"
+ modified = "2022-07-22"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Rhadamanthys.yar#L27-L52"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "9bfc4fed7afc79a167cac173bf3602f9d1f90595d4e41dab68ff54973f2cedc1"
- logic_hash = "bf5d45fe79dacfc6aee5cfd788ec6ce77e99e55d5a6d294da57c126bedf75ee9"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Backdoor_Keyboardrecord.yar#L1-L23"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "570cd76bf49cf52e0cb347a68bdcf0590b2eaece134e1b1eba7e8d66261bdbe6"
+ logic_hash = "5719681d50134edacb5341034314c33ed27e9325de0ae26b2a01d350429c533b"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "7b3830373b773be03dc6d0f030595f625a2ef0b6a83312a5b0a958c0d2e5b1c0"
+ tags = "FILE"
+ fingerprint = "27aa4380bda0335c672e957ba2ce6fd1f42ccf0acd2eff757e30210c3b4fb2fa"
severity = 100
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
- os = "windows"
+ os = "macos"
strings:
- $a1 = "%s\\tdata\\key_datas" wide fullword
- $a2 = "\\config\\loginusers.vdf" wide fullword
- $a3 = "/bin/KeePassHax.dll" ascii fullword
- $a4 = "%%APPDATA%%\\ns%04x.dll" wide fullword
- $a5 = "\\\\.\\pipe\\{%08lx-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}" wide fullword
- $a6 = " /s /n /i:\"%s,%u,%u,%u\" \"%s\"" wide fullword
- $a7 = "strbuf(%lx) reallocs: %d, length: %d, size: %d" ascii fullword
- $a8 = "SOFTWARE\\FTPWare\\CoreFTP\\Sites\\%s" wide fullword
+ $s1 = "com.ccc.keyboardrecord"
+ $s2 = "com.ccc.write_queue"
+ $s3 = "ps -p %s > /dev/null"
+ $s4 = "useage %s path useragentpid"
+ $s5 = "keyboardRecorderStartPKc"
condition:
- 6 of them
+ 3 of them
}
-rule ELASTIC_Windows_Trojan_Rhadamanthys_Ae00F48C : FILE MEMORY
+rule ELASTIC_Windows_Hacktool_Executeassembly_F41F4Df6 : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Rhadamanthys (Windows.Trojan.Rhadamanthys)"
+ description = "Detects Windows Hacktool Executeassembly (Windows.Hacktool.ExecuteAssembly)"
author = "Elastic Security"
- id = "ae00f48c-f420-4a23-aae7-6f2bde29593c"
- date = "2023-05-05"
- modified = "2023-06-13"
+ id = "f41f4df6-03de-4a03-9dfa-4f9d0f51c2de"
+ date = "2023-03-28"
+ modified = "2023-04-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Rhadamanthys.yar#L54-L74"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "56b5ff5132ec1c5836223ced287d51a9ecee8d2b081f449245e136b1262a8714"
- logic_hash = "423b68717a7aead3c871e7fc744e35dad1cfd7727bfba2bdaec69fb782540380"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_ExecuteAssembly.yar#L1-L20"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "a468ba2ba77aafa2a572c8947d414e74604a7c1c6e68a0b87fbfce4f8854dd61"
+ logic_hash = "ab72dec636a96338e16fd57f2db4bb52e38fe61315b42c2ffe9c4566fc0326d3"
score = 75
- quality = 71
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "8e3d13998a8e512aabf15534d61c06e0c6c51a4e8e46456538c654694310e670"
+ fingerprint = "4875f516551517ec9423f04a9636b65fc717b9e2c9c40379b027ab126e593d23"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -63616,30 +67802,29 @@ rule ELASTIC_Windows_Trojan_Rhadamanthys_Ae00F48C : FILE MEMORY
os = "windows"
strings:
- $a1 = { 75 30 8B 51 28 8B 41 2C 85 DB 74 03 89 53 28 85 D2 74 15 39 }
- $a2 = { 3C 65 74 50 3C 68 74 2A 3C 6E }
- $a3 = { 49 74 39 49 74 2D 49 49 74 29 49 49 74 25 49 49 74 }
+ $bytes0 = { 33 D8 8B C3 C1 E8 05 03 D8 8B C3 C1 E0 04 33 D8 8B C3 C1 E8 11 03 D8 8B C3 C1 E0 19 33 D8 8B C3 C1 E8 06 03 C3 }
+ $bytes1 = { 81 F9 8E 4E 0E EC 74 10 81 F9 AA FC 0D 7C 74 08 81 F9 54 CA AF 91 75 43 }
condition:
all of them
}
-rule ELASTIC_Windows_Trojan_Rhadamanthys_Cf5Dd2E2 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_A310Logger_520Cd7Ec : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Rhadamanthys (Windows.Trojan.Rhadamanthys)"
+ description = "Detects Windows Trojan A310Logger (Windows.Trojan.A310logger)"
author = "Elastic Security"
- id = "cf5dd2e2-a505-4927-8653-3c9addd3ac90"
- date = "2024-04-03"
- modified = "2024-05-08"
+ id = "520cd7ec-840c-4d45-961b-8bc5e329c52f"
+ date = "2022-01-11"
+ modified = "2022-04-12"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Rhadamanthys.yar#L76-L97"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "39ccc224c2c6d89d0bce3d9e2c677465cbc7524f2d2aa903f79ad26b340dec3d"
- logic_hash = "039d6de0d072be6717ba3eb90735d7b4898d3bbac83db4feb75efcdbca8fd98b"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_A310logger.yar#L1-L23"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "60fb9597e5843c72d761525f73ca728409579d81901860981ebd84f7d153cfa3"
+ logic_hash = "6095ce913e3fb1cfc2f1b091598fc06b2dfec30c2353be7df08dcbb1a06b07c3"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "3b2bdfd45a11649deb3430044c7b707aebcf74a3745398e3db09a7465fa62a6c"
+ fingerprint = "f4ee88e555b7bd0102403cc804372f5376debc59555e8e7b4a16e18b04d1b314"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -63647,188 +67832,181 @@ rule ELASTIC_Windows_Trojan_Rhadamanthys_Cf5Dd2E2 : FILE MEMORY
os = "windows"
strings:
- $a1 = { 33 D2 49 8B C4 49 83 C4 57 48 F7 F7 41 8A C2 46 0F B6 04 1A 33 D2 42 8D 4C 05 00 C1 E9 03 F6 E9 8A C8 49 8B C0 41 C0 E8 05 }
- $a2 = { 8A 04 19 32 03 88 04 1A 48 83 C3 01 48 83 EF 01 }
- $a3 = { 4C 01 27 48 8B 0F 48 8B 47 10 C6 04 01 00 48 83 07 01 48 8B 0F 48 8B 47 10 }
- $a4 = { 69 F6 93 01 00 01 0F B6 C0 48 83 C1 01 33 F0 8A 01 84 C0 }
+ $a1 = "/dumps9taw" ascii fullword
+ $a2 = "/logstatus" ascii fullword
+ $a3 = "/checkprotection" ascii fullword
+ $a4 = "[CLIPBOARD]<<" wide fullword
+ $a5 = "&chat_id=" wide fullword
condition:
- 2 of them
+ all of them
}
-rule ELASTIC_Windows_Trojan_Rhadamanthys_C4760266 : FILE MEMORY
+rule ELASTIC_Linux_Ransomware_Quantum_8513Fb8B : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Rhadamanthys (Windows.Trojan.Rhadamanthys)"
+ description = "Detects Linux Ransomware Quantum (Linux.Ransomware.Quantum)"
author = "Elastic Security"
- id = "c4760266-bbff-4428-a7a5-bca7513c7993"
- date = "2024-06-05"
- modified = "2024-06-12"
+ id = "8513fb8b-43f7-46b1-8318-5549a7609d3b"
+ date = "2023-07-28"
+ modified = "2024-02-13"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Rhadamanthys.yar#L99-L117"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "05074675b07feb8e7556c5af449f5e677e0fabfb09b135971afbb11743bf3165"
- logic_hash = "b8c1c56681aac4e1b1741dfa3ea929677214873b6f1795423a80742f699249de"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Ransomware_Quantum.yar#L1-L20"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "3bcb9ad92fdca53195f390fc4d8d721b504b38deeda25c1189a909a7011406c9"
+ logic_hash = "7e24be541bafc2427ecd8f76b7774fb65d7421bc300503eeb068b8104e168c70"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "53a04d385ef3a59b76500effaf740cd0e7d825ea5515f871097d82899b0cfc44"
+ fingerprint = "1c1af76ab5df8243b8e25555f1762749ca60da56fecea9d4131c612358244525"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a = { 55 8B EC 83 EC 14 83 7D 08 00 53 8B D8 74 50 56 57 8B 7D 0C 6A 10 2B FB 5E 56 8D 45 EC 53 50 ?? ?? ?? ?? ?? 83 C4 0C 90 8B 4D 10 8B C3 2B CB 89 75 FC 8A 14 07 32 10 88 14 01 40 FF 4D FC 75 F2 }
+ $a1 = "All your files are encrypted on all devices across the network"
+ $a2 = "process with pid %d is blocking %s, going to kill it"
condition:
all of them
}
-rule ELASTIC_Windows_Hacktool_Gmer_8Aabdd5E : FILE
+rule ELASTIC_Linux_Exploit_Pulse_2Bea17E8 : FILE MEMORY
{
meta:
- description = "Detects Windows Hacktool Gmer (Windows.Hacktool.Gmer)"
+ description = "Detects Linux Exploit Pulse (Linux.Exploit.Pulse)"
author = "Elastic Security"
- id = "8aabdd5e-1ce7-4257-abaa-8d02dc6856a6"
- date = "2022-04-04"
- modified = "2022-04-04"
+ id = "2bea17e8-2324-4502-9ced-7a45d94099ec"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_Gmer.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "18c909a2b8c5e16821d6ef908f56881aa0ecceeaccb5fa1e54995935fcfd12f7"
- logic_hash = "acdab89a7703a743927cec60fbc84af2fd469403bee6f211c865fb96e9c92498"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Pulse.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "c29cb4c2d83127cf4731573a7fac531f90f27799857f5e250b9f71362108f559"
+ logic_hash = "bc71efa6cc79171666d89fe3e755411ee8032f56ae5bd73e0de440eee5b718ab"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "960721d4d111a670907fe7d3ce01dfd134ad03a2d8440a945c75a7d46de46238"
- severity = 50
+ tags = "FILE, MEMORY"
+ fingerprint = "4d57fb355e7d68ad3da26ff3bade291ebbfa8df5f0727579787e33ebee888d41"
+ severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $str1 = "\\gmer64.pdb"
+ $a = { 89 E5 48 8D 45 F8 48 89 45 F8 48 8B 45 F8 48 25 00 F0 FF FF 48 }
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Leigod_89397Ebf : FILE
+rule ELASTIC_Linux_Exploit_Pulse_246E6F31 : FILE MEMORY
{
meta:
- description = "Detects Windows Hacktool Leigod (Windows.Hacktool.LeiGod)"
+ description = "Detects Linux Exploit Pulse (Linux.Exploit.Pulse)"
author = "Elastic Security"
- id = "89397ebf-2fdb-4607-85a1-b9c378b4e256"
- date = "2022-04-04"
- modified = "2022-04-04"
+ id = "246e6f31-fcfb-474e-9709-a5d7ea6586fd"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_LeiGod.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "ae5cc99f3c61c86c7624b064fd188262e0160645c1676d231516bf4e716a22d3"
- logic_hash = "e887c34c624a182a3c57a55abe02784c4350d3956bcfd9f7918f08a464819e63"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Pulse.yar#L21-L39"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "c29cb4c2d83127cf4731573a7fac531f90f27799857f5e250b9f71362108f559"
+ logic_hash = "f6755f10863b78303899cefcd81f609884fbbf2dffabd9219686ed869f2cc7e3"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "04709d703cd0a062029a05baee160eb9579fe0503984f3059ce49e1bcfa6e963"
- severity = 50
+ tags = "FILE, MEMORY"
+ fingerprint = "e98007a2fa62576e1847cf350283f60f1e4e49585574601ab44b304f391240db"
+ severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $str1 = "\\Device\\CtrlLeiGod" wide fullword
+ $a = { 48 8D 45 F8 48 89 45 F8 48 8B 45 F8 48 25 00 E0 FF FF 48 8B 00 48 89 }
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Leigod_3F5C98C4 : FILE
+rule ELASTIC_Windows_Trojan_Gh0St_Ee6De6Bc : FILE MEMORY
{
meta:
- description = "Detects Windows Hacktool Leigod (Windows.Hacktool.LeiGod)"
+ description = "Identifies a variant of Gh0st Rat"
author = "Elastic Security"
- id = "3f5c98c4-03ba-4919-90b0-604d3cb9361e"
- date = "2022-04-04"
- modified = "2022-04-04"
+ id = "ee6de6bc-1648-4a77-9607-e2a211c7bda4"
+ date = "2021-06-10"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_LeiGod.yar#L21-L39"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "0c42fe45ffa9a9c36c87a7f01510a077da6340ffd86bf8509f02c6939da133c5"
- logic_hash = "7570bf1a69df6b493bde41c1de27969e36a3fcb59be574ee2e24e3a61347a146"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Gh0st.yar#L1-L23"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "ea1dc816dfc87c2340a8b8a77a4f97618bccf19ad3b006dce4994be02e13245d"
+ logic_hash = "3619df974c9f4ec76899afbafdfd6839070714862c7361be476cf8f83e766e2f"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "883dcad7097ad5713c4f45ce2fc232c3c1e61cf9dfdc81a194124d5995a64c9e"
- severity = 50
+ tags = "FILE, MEMORY"
+ fingerprint = "3c529043f34ad8a8692b051ad7c03206ce1aafc3a0eb8fcf7f5bcfdcb8c1b455"
+ threat_name = "Windows.Trojan.Gh0st"
+ severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
- $str1 = "\\LgDCatcher.pdb"
+ $a1 = ":]%d-%d-%d %d:%d:%d" ascii fullword
+ $a2 = "[Pause Break]" ascii fullword
+ $a3 = "f-secure.exe" ascii fullword
+ $a4 = "Accept-Language: zh-cn" ascii fullword
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Sharpsccm_9Bef8Dab : FILE MEMORY
+rule ELASTIC_Linux_Cryptominer_Stak_05088561 : FILE MEMORY
{
meta:
- description = "Detects Windows Hacktool Sharpsccm (Windows.Hacktool.SharpSCCM)"
+ description = "Detects Linux Cryptominer Stak (Linux.Cryptominer.Stak)"
author = "Elastic Security"
- id = "9bef8dab-af2e-46be-811a-0ac78d74a4ef"
- date = "2024-03-25"
- modified = "2024-05-08"
+ id = "05088561-ec73-4068-a7f3-3eff612ecd28"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_SharpSCCM.yar#L1-L31"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "2e169c4fd16627029445bb0365a2f9ee61ab6b3757b8ad02fd210ce85dc9c97f"
- logic_hash = "560c780934a63b3c857a09841c09cbc350205868c696fac958e249e1379cc865"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Cryptominer_Stak.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "d0d2bab33076121cf6a0a2c4ff1738759464a09ae4771c39442a865a76daff59"
+ logic_hash = "2b0f8a4efdfb13abcc2a1b43e9c39828ea1de6015fef0ef613bd754da5aa3e9a"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "dfbb7f142628eb7dc6c96dd271562d88a0970534af85464c10232ec01f58e35b"
+ fingerprint = "dfcfa99a2924eb9e8bc0e7b51db6d1b633e742e34add40dc5d1bb90375f85f6e"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $name = "SharpSCCM" wide fullword
- $s1 = "--relay-server" wide fullword
- $s2 = "--username" wide fullword
- $s3 = "--domain" wide fullword
- $s4 = "--sms-provider" wide fullword
- $s5 = "--wmi-namespace" wide fullword
- $s6 = "--management-point" wide fullword
- $s7 = "--get-system" wide fullword
- $s8 = "--run-as-user" wide fullword
- $s9 = "--register-client" wide fullword
- $s10 = "MS_Collection" wide fullword
- $s11 = "SOFTWARE\\Microsoft\\CCM" wide fullword
- $s12 = "CCM_POST" wide fullword
+ $a = { CD 49 8D 4D 07 48 83 E1 F8 48 39 CD 73 55 49 8B 06 48 8B 50 08 48 8D }
condition:
- ($name and 2 of ($s*)) or 7 of ($s*)
+ all of them
}
-rule ELASTIC_Linux_Trojan_Mech_D30Ec0A0 : FILE MEMORY
+rule ELASTIC_Linux_Cryptominer_Stak_Ae8B98A9 : FILE MEMORY
{
meta:
- description = "Detects Linux Trojan Mech (Linux.Trojan.Mech)"
+ description = "Detects Linux Cryptominer Stak (Linux.Cryptominer.Stak)"
author = "Elastic Security"
- id = "d30ec0a0-3fd6-4d83-ad29-9d45704bc8ce"
- date = "2021-04-06"
+ id = "ae8b98a9-cc25-4606-a775-1129e0f08c3b"
+ date = "2021-01-12"
modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Mech.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "710d1a0a8c7eecc6d793933c8a97cec66d284b3687efee7655a2dc31d15c0593"
- logic_hash = "268aeb25d6468412d8123bab5eb2c8bd7704828d0ef3c3d771aa036e374127d7"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Cryptominer_Stak.yar#L21-L38"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "aade76488aa2f557de9082647153cca374a4819cd8e539ebba4bfef2334221b0"
score = 75
- quality = 73
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "061e9f1aade510132674d87ab5981e5b6b0ae3a2782a97d8cc6c2be7b26c6454"
+ fingerprint = "0b5da501c97f53ecd79d708d898d4f5baae3c5fd80a4c39b891a952c0bcc86e5"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -63836,58 +68014,57 @@ rule ELASTIC_Linux_Trojan_Mech_D30Ec0A0 : FILE MEMORY
os = "linux"
strings:
- $a = { 6E 63 20 2D 20 4C 69 6E 75 78 20 32 2E 32 2E 31 }
+ $a = { D1 73 5A 49 8B 06 48 8B 78 08 4C 8B 10 4C 8D 4F 18 4D 89 CB 49 }
condition:
all of them
}
-rule ELASTIC_Windows_Vulndriver_Speedfan_9B590Eee : FILE
+rule ELASTIC_Linux_Cryptominer_Stak_D707Fd3A : FILE MEMORY
{
meta:
- description = "Subject: Sokno S.R.L."
+ description = "Detects Linux Cryptominer Stak (Linux.Cryptominer.Stak)"
author = "Elastic Security"
- id = "9b590eee-5938-4293-afac-c9e730753413"
- date = "2022-04-07"
- modified = "2022-04-07"
+ id = "d707fd3a-41ce-4f88-ad42-d663094db5fb"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_Speedfan.yar#L1-L20"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "22be050955347661685a4343c51f11c7811674e030386d2264cd12ecbf544b7c"
- logic_hash = "6f75c0e6b89dd1ceb85c73b7e51fd261ca2804e14a5f8ed6ce3352b3f1bcdfe4"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Cryptominer_Stak.yar#L40-L58"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "d0d2bab33076121cf6a0a2c4ff1738759464a09ae4771c39442a865a76daff59"
+ logic_hash = "b825247372aace6e3ce0ff1d9685b6bb041b7277f8967d5f5926b49813cfadc9"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "c58a8c3bfa710896c35262cc880b9afbadcdfdd73d9969c707e7b5b64e6a70b5"
- threat_name = "Windows.VulnDriver.Speedfan"
- severity = 50
+ tags = "FILE, MEMORY"
+ fingerprint = "c218a3c637f58a6e0dc2aa774eb681757c94e1d34f622b4ee5520985b893f631"
+ severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $subject_name = { 06 03 55 04 03 [2] 53 6F 6B 6E 6F 20 53 2E 52 2E 4C 2E }
+ $a = { C2 01 48 89 10 49 8B 55 00 48 8B 02 48 8B 4A 10 48 39 C8 74 9E 80 }
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $subject_name
+ all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_69E20012 : FILE MEMORY
+rule ELASTIC_Linux_Cryptominer_Stak_52Dc7Af3 : FILE MEMORY
{
meta:
- description = "Detects Linux Trojan Metasploit (Linux.Trojan.Metasploit)"
+ description = "Detects Linux Cryptominer Stak (Linux.Cryptominer.Stak)"
author = "Elastic Security"
- id = "69e20012-4f5d-42ce-9913-8bf793d2a695"
- date = "2024-05-03"
- modified = "2024-05-21"
+ id = "52dc7af3-a742-4307-a5ae-c929fede1cc4"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L1-L24"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "debb5d12c1b876f47a0057aad19b897c21f17de7b02c0e42f4cce478970f0120"
- logic_hash = "5d3c3e3ba7d5d0c20d2fa1a53032da9a93a6727dcd6cb3497bb7bfb8272e4f2b"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Cryptominer_Stak.yar#L60-L78"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "a9c14b51f95d0c368bf90fb10e7d821a2fbcc79df32fd9f068a7fc053cbd7e83"
+ logic_hash = "81998164f517b6f1ef72b10227cfff86aa8bbd2b4e2668f946c8ed59696ae74d"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "263efec478e54c025ed35bba18a0678ceba36c90f42ccca825f2ba1202e58248"
+ fingerprint = "330262703d3fcdd8b2c217db552f07e19f5df4d6bf115bfa291bb1c7f802ad97"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -63895,255 +68072,241 @@ rule ELASTIC_Linux_Trojan_Metasploit_69E20012 : FILE MEMORY
os = "linux"
strings:
- $mmap = { 31 FF 6A 09 58 99 B6 10 48 89 D6 4D 31 C9 6A 22 41 5A 6A 07 5A 0F 05 48 85 C0 78 }
- $socket = { 41 59 50 6A 29 58 99 6A 02 5F 6A 01 5E [0-6] 0F 05 48 85 C0 78 }
- $connect = { 51 48 89 E6 6A 10 5A 6A 2A 58 0F 05 59 48 85 C0 79 }
- $failure_handler = { 57 6A 23 58 6A 00 6A 05 48 89 E7 48 31 F6 0F 05 59 59 5F 48 85 C0 79 }
- $exit = { 6A 3C 58 6A 01 5F 0F 05 }
- $receive = { 5A 0F 05 48 85 C0 78 }
+ $a = { F9 48 89 D3 4D 8B 74 24 20 48 8D 41 01 4C 29 FB 4C 8D 6B 10 48 }
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_0C629849 : FILE MEMORY
+rule ELASTIC_Linux_Cryptominer_Stak_Bb3153Ac : FILE MEMORY
{
meta:
- description = "Detects Linux Trojan Metasploit (Linux.Trojan.Metasploit)"
+ description = "Detects Linux Cryptominer Stak (Linux.Cryptominer.Stak)"
author = "Elastic Security"
- id = "0c629849-8127-4fec-a225-da29bf41435e"
- date = "2024-05-03"
- modified = "2024-05-21"
+ id = "bb3153ac-b11b-4e84-afab-05dab61424ae"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L26-L48"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "ad070542729f3c80d6a981b351095ab8ac836b89a5c788dff367760a2d8b1dbb"
- logic_hash = "2bea8f569728ba81af4024bf062a06a5c91b1f057a0b62fe6d51b6fcadedf58c"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Cryptominer_Stak.yar#L80-L98"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "5b974b6e6a239bcdc067c53cc8a6180c900052d7874075244dc49aaaa9414cca"
+ logic_hash = "e8516a24358b12863fe52c823ca67f0004457017334fe77dabf5f08d6bf2d907"
score = 75
- quality = 75
+ quality = 73
tags = "FILE, MEMORY"
- fingerprint = "3e98ffa46e438421056bf4424382baa6fbe30e5fc16dbd227bceb834873dbe41"
+ fingerprint = "c4c33125a1fad9ff393138b333a8cebfd67217e90780c45f73f660ed1fd02753"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
os = "linux"
- strings:
- $socket_call = { 6A 29 58 6A 0A 5F 6A 01 5E 31 D2 0F 05 50 5F }
- $populate_sockaddr_in6 = { 99 52 52 52 66 68 }
- $calls = { 6A 31 58 6A 1C 5A 0F 05 6A 32 58 6A 01 5E 0F 05 6A 2B 58 99 52 52 54 5E 6A 1C 48 8D 14 24 0F 05 }
- $dup2 = { 48 97 6A 03 5E 6A 21 58 FF CE 0F 05 E0 F7 }
- $exec_call = { 6A 3B 58 99 48 BB 2F 62 69 6E 2F 73 68 00 53 54 5F 0F 05 }
-
+ strings:
+ $a = { 6C 77 61 79 73 22 2C 20 22 6E 6F 5F 6D 6C 63 6B 22 2C 20 22 }
+
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_849Cc5D5 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Vidar_9007Feb2 : FILE MEMORY
{
meta:
- description = "Detects Linux Trojan Metasploit (Linux.Trojan.Metasploit)"
+ description = "Detects Windows Trojan Vidar (Windows.Trojan.Vidar)"
author = "Elastic Security"
- id = "849cc5d5-737a-4ea4-9bb6-cec26b132ff2"
- date = "2024-05-03"
- modified = "2024-05-21"
+ id = "9007feb2-6ad1-47b6-bae2-3379d114e4f1"
+ date = "2021-06-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L50-L71"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "42d734dbd33295bd68e5a545a29303a2104a5a92e5fee31d645e2a6410cc03e9"
- logic_hash = "01c708b1e000aecf473e0a1cf23f3812a337b9b21f5b81f7a5e481d06fdaeb16"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Vidar.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "34c0cb6eaf2171d3ab9934fe3f962e4e5f5e8528c325abfe464d3c02e5f939ec"
+ logic_hash = "fcdef7397f17ee402155e526c6fa8b51f3ea96e203a095b0b4c36cb7d3cc83d1"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "859638998983b9dc0cffc204985b2c4db8a4fb2a97ff4e791fd6762ff6b1f5da"
+ fingerprint = "8416b14346f833264e32c63253ea0b0fe28e5244302b2e1b266749c543980fe2"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $init1 = { 6A 29 58 99 6A 02 5F 6A 01 5E 0F 05 48 97 }
- $init2 = { 6A 10 5A 6A ?? 58 0F }
- $shell1 = { 6A 03 5E 48 FF CE 6A 21 58 0F 05 75 F6 6A 3B 58 99 48 BB 2F 62 69 6E 2F 73 68 00 53 48 89 E7 52 57 48 89 E6 0F 05 }
- $shell2 = { 48 96 6A 2B 58 0F 05 50 56 5F 6A 09 58 99 B6 10 48 89 D6 4D 31 C9 6A 22 41 5A B2 07 0F 05 48 96 48 97 5F 0F 05 FF E6 }
+ $a = { E8 53 FF D6 50 FF D7 8B 45 F0 8D 48 01 8A 10 40 3A D3 75 F9 }
condition:
- all of ($init*) and 1 of ($shell*)
+ all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_Da378432 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Vidar_114258D5 : FILE MEMORY
{
meta:
- description = "Detects Linux Trojan Metasploit (Linux.Trojan.Metasploit)"
+ description = "Detects Windows Trojan Vidar (Windows.Trojan.Vidar)"
author = "Elastic Security"
- id = "da378432-d549-4ba8-9e33-a0d0656fc032"
- date = "2024-05-03"
- modified = "2024-05-21"
+ id = "114258d5-f05e-46ac-914b-1a7f338ccf58"
+ date = "2021-06-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L73-L93"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "277499da700e0dbe27269c7cfb1fc385313c4483912a9a3f0c15adba33ecd0bf"
- logic_hash = "cd9df6dff23986d61176e4d3440516b0590abdeebef0e456d1f4924724556fe9"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Vidar.yar#L21-L44"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "34c0cb6eaf2171d3ab9934fe3f962e4e5f5e8528c325abfe464d3c02e5f939ec"
+ logic_hash = "9ea3ea0533d14edd0332fa688497efd566a890d1507214fc8591a0a11433d060"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "db6e226c18211d845c3495bb39472646e64842d4e4dd02d9aad29178fd22ea95"
+ fingerprint = "9b4f7619e15398fcafc622af821907e4cf52964c55f6a447327738af26769934"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $str1 = { 6A 29 58 99 6A 02 5F 6A 01 5E 0F 05 48 97 }
- $str2 = { 6A 10 5A 6A ?? 58 0F }
- $str3 = { 6A 03 5E 48 FF CE 6A 21 58 0F 05 75 F6 6A 3B 58 99 48 BB 2F 62 69 6E 2F 73 68 00 53 48 89 E7 52 57 48 89 E6 0F 05 }
+ $a1 = "BinanceChainWallet" fullword
+ $a2 = "*wallet*.dat" fullword
+ $a3 = "SOFTWARE\\monero-project\\monero-core" fullword
+ $b1 = "CC\\%s_%s.txt" fullword
+ $b2 = "History\\%s_%s.txt" fullword
+ $b3 = "Autofill\\%s_%s.txt" fullword
condition:
- all of them
+ 1 of ($a*) and 1 of ($b*)
}
-rule ELASTIC_Linux_Trojan_Metasploit_B957E45D : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Vidar_32Fea8Da : FILE MEMORY
{
meta:
- description = "Detects x86 msfvenom nonx TCP reverse shells"
+ description = "Detects Windows Trojan Vidar (Windows.Trojan.Vidar)"
author = "Elastic Security"
- id = "b957e45d-0eb6-4580-af84-98608bbc34ef"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "32fea8da-b381-459c-8bf4-696388b8edcc"
+ date = "2023-05-04"
+ modified = "2023-06-13"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L95-L115"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "78af84bad4934283024f4bf72dfbf9cc081d2b92a9de32cc36e1289131c783ab"
- logic_hash = "27281303d007e6723308e88f335f52723b3ff0ef733d1a0712f5ba268e53a073"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Vidar.yar#L46-L66"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "6f5c24fc5af2085233c96159402cec9128100c221cb6cb0d1c005ced7225e211"
+ logic_hash = "1a18cdc3bd533c34eb05b239830ecec418dc76ee9f4fcfc48afc73b07d55b3cd"
score = 75
- quality = 75
+ quality = 73
tags = "FILE, MEMORY"
- fingerprint = "ac71352e2b4c8ee8917b1469cd33e6b54eb4cdcd96f02414465127c5cad6b710"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "ebcced7b2924cc9cfe9ed5b5f84a8959e866a984f2b5b6e1ec5b1dd096960325"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $str1 = { 31 DB 53 43 53 6A 02 6A 66 58 89 E1 CD 80 97 5B }
- $str2 = { 66 53 89 E1 6A 66 58 50 51 57 89 E1 43 CD 80 5B 99 B6 0C B0 03 CD 80 }
+ $a1 = { 4F 4B 58 20 57 65 62 33 20 57 61 6C 6C 65 74 }
+ $a2 = { 8B E5 5D C3 5E B8 03 00 00 00 5B 8B E5 5D C3 5E B8 08 00 00 }
+ $a3 = { 83 79 04 00 8B DE 74 08 8B 19 85 DB 74 62 03 D8 8B 03 85 C0 }
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_1A98F2E2 : FILE MEMORY
+rule ELASTIC_Windows_Vulndriver_Asrock_986D2D3C : FILE
{
meta:
- description = "Detects x86 msfvenom nonx TCP bind shells"
+ description = "Detects Windows Vulndriver Asrock (Windows.VulnDriver.Asrock)"
author = "Elastic Security"
- id = "1a98f2e2-9354-4d04-b1c0-d3998e54e2c4"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "986d2d3c-96d1-4c74-a594-51c6df3b2896"
+ date = "2022-04-04"
+ modified = "2022-04-04"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L117-L137"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "89be4507c9c24c4ec9a7282f197a9a6819e696d2832df81f7e544095d048fc22"
- logic_hash = "23ea1c255472a67746b470e50d982bc91d22ede5e2582cf5cfaa90a1ed4e8805"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Asrock.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "3943a796cc7c5352aa57ccf544295bfd6fb69aae147bc8235a00202dc6ed6838"
+ logic_hash = "d767a1ecdff557753f80ac9d73f02364dd035f7a287d0f260316f807364af2d5"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "b9865aad13b4d837e7541fe6a501405aa7d694c8fefd96633c0239031ebec17a"
- threat_name = "Linux.Trojan.Metasploit"
- severity = 100
+ tags = "FILE"
+ fingerprint = "17a021c4130a41ca6714f2dd7f33c100ba61d6d2d4098a858f917ab49894b05b"
+ severity = 50
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $str1 = { 31 DB 53 43 53 6A 02 6A 66 58 99 89 E1 CD 80 96 43 52 }
- $str2 = { 66 53 89 E1 6A 66 58 50 51 56 89 E1 CD 80 B0 66 D1 E3 CD 80 52 52 56 43 89 E1 B0 66 CD 80 93 B6 0C B0 03 CD 80 89 DF }
+ $str1 = "\\AsrDrv106.pdb"
condition:
- all of them
+ int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
}
-rule ELASTIC_Linux_Trojan_Metasploit_D74153F6 : FILE MEMORY
+rule ELASTIC_Windows_Vulndriver_Asrock_Cdf192F9 : FILE
{
meta:
- description = "Detects x86 msfvenom IPv6 TCP reverse shells"
+ description = "Detects Windows Vulndriver Asrock (Windows.VulnDriver.Asrock)"
author = "Elastic Security"
- id = "d74153f6-0047-4576-8c3e-db0525bb3a92"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "cdf192f9-c62f-4e00-b6a9-df85d10fee99"
+ date = "2022-04-04"
+ modified = "2022-04-04"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L139-L159"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "2823d27492e2e7a95b67a08cb269eb6f4175451d58b098ae429330913397d40a"
- logic_hash = "c60e7e63183f5bf0354a03f8399576e494e44a30257339ebccb6c19e954d6f3a"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Asrock.yar#L21-L39"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "2003b478b9fd1b3d76ec5bf4172c2e8915babbbee7ad1783794acbf8d4c2519d"
+ logic_hash = "2f844b6d3fa19fd39097395175162578ad71d78c61dad104efd320cd8285fa6b"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "824baa1ee7fda8074d76e167d3c5cc1911c7224bb72b1add5e360f26689b48c2"
- threat_name = "Linux.Trojan.Metasploit"
- severity = 100
+ tags = "FILE"
+ fingerprint = "f27c61c67b51ab88994742849dcd1311064ef0cacddb57503336d08f45059060"
+ severity = 50
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $str1 = { 31 DB 53 43 53 6A 0A 89 E1 6A 66 58 CD 80 96 99 }
- $str2 = { 89 E1 6A 1C 51 56 89 E1 43 43 6A 66 58 CD 80 89 F3 B6 0C B0 03 CD 80 89 DF }
+ $str1 = "\\AsrDrv103.pdb"
condition:
- all of them
+ int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
}
-rule ELASTIC_Linux_Trojan_Metasploit_F7A31E87 : FILE MEMORY
+rule ELASTIC_Windows_Vulndriver_Asrock_0Eca57Dc : FILE
{
meta:
- description = "Detects x86 msfvenom shell find tag payloads"
+ description = "Name: AsrSetupDrv103.sys, Version: 1.00.00.0000 built by: WinDDK"
author = "Elastic Security"
- id = "f7a31e87-c3d7-4a26-9879-68893780283e"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "0eca57dc-3800-4b0f-99dd-151fcac82136"
+ date = "2023-07-20"
+ modified = "2023-07-20"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L161-L182"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "82b55d8c0f0175d02399aaf88ad9e92e2e37ef27d52c7f71271f3516ba884847"
- logic_hash = "49583ba4f2bedb9337a8c10df4246bb76a3e60b08ba1a6b8684537fee985d911"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_Asrock.yar#L41-L62"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "9d9346e6f46f831e263385a9bd32428e01919cca26a035bbb8e9cb00bf410bc3"
+ hash = "a0728184caead84f2e88777d833765f2d8af6a20aad77b426e07e76ef91f5c3f"
+ logic_hash = "82a0cba571dc58ed8d3fd87d3650ec0c1016e6c8e972547f6120ba91c8febce1"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "7171cb9989405be295479275d8824ced7e3616097db88e3b0f8f1ef6798607e2"
- threat_name = "Linux.Trojan.Metasploit"
- severity = 100
+ tags = "FILE"
+ fingerprint = "6c73b37f5e749161b4fb2f076e82ceb02345894b5db8e1a187019b54e3d1a154"
+ threat_name = "Windows.Vulndriver.Asrock"
+ severity = 50
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $setup = { 31 DB 53 89 E6 6A 40 B7 0A 53 56 53 89 E1 86 FB 66 FF 01 6A 66 58 CD 80 81 3E }
- $payload1 = { 5F FC AD FF }
- $payload2 = { 5F 89 FB 6A 02 59 6A 3F 58 CD 80 49 79 ?? 6A 0B 58 99 52 68 2F 2F 73 68 68 2F 62 69 6E 89 E3 52 53 89 E1 CD 80 }
+ $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 [1-8] 41 00 73 00 72 00 53 00 65 00 74 00 75 00 70 00 44 00 72 00 76 00 31 00 30 00 33 00 2E 00 73 00 79 00 73 }
+ $file_version = { 46 00 69 00 6C 00 65 00 56 00 65 00 72 00 73 00 69 00 6F 00 6E [1-8] 31 00 2E 00 30 00 30 00 2E 00 30 00 30 00 2E 00 30 00 30 00 30 00 30 00 20 00 62 00 75 00 69 00 6C 00 74 00 20 00 62 00 79 00 3A 00 20 00 57 00 69 00 6E 00 44 00 44 00 4B }
condition:
- $setup and 1 of ($payload*)
+ int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $file_version
}
-rule ELASTIC_Linux_Trojan_Metasploit_B0D2D4A4 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_47C64Fb6 : FILE MEMORY
{
meta:
- description = "Detects x86 msfvenom shell find port payloads"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "b0d2d4a4-4fd6-4fc0-959b-89d6969215ed"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "47c64fb6-cfa6-4350-a41f-870b87116b32"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L184-L205"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "a37c888875e84069763303476f0df6769df6015b33aded59fc1e23eb604f2163"
- logic_hash = "bcabf74900222074ecf9051b6e0cb4ca7a240acd047a1b27137d1d198e23f161"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "0caa9035027ff88788e6b8e43bfc012a367a12148be809555c025942054a6360"
+ logic_hash = "7d977edd5fc90c6f03ed5558c690b3dd2102bbff9d7e5124403276405e15201b"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "f6d2e001d8cfb6f086327ddb457a964932a8200ff60ea973b26ac9fb909b4a9c"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "aa286440061fb31167f314111dde7c2f596357b41fb6a5656216892fee6bf56e"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64151,31 +68314,28 @@ rule ELASTIC_Linux_Trojan_Metasploit_B0D2D4A4 : FILE MEMORY
os = "linux"
strings:
- $str1 = { 31 DB 53 89 E7 6A 10 54 57 53 89 E1 B3 07 FF 01 6A 66 58 CD 80 }
- $str2 = { 5B 6A 02 59 B0 3F CD 80 49 }
- $str3 = { 50 68 2F 2F 73 68 68 2F 62 69 6E 89 E3 50 53 89 E1 99 B0 0B CD 80 }
+ $a = { F4 C6 00 FF 8B 45 F4 40 C6 00 25 8B 45 F4 83 C0 02 C7 00 08 00 }
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_5D26689F : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_76C24B62 : FILE MEMORY
{
meta:
- description = "Detects x86 msfvenom bind TCP random port payloads"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "5d26689f-3d3a-41f1-ac32-161b3b312b74"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "76c24b62-e04f-410d-b7cb-668daa9aea20"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L207-L229"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "dafefb4d79d848384442a697b1316d93fef2741fca854be744896ce1d7f82073"
- logic_hash = "e7906273aa7f42920be9d06cdae89c81e0a99e532cdcd7bd714acc5f2bbb0ed5"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L21-L39"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "330de2ca1add7e06389d94dfc541c367a484394c51663b26d27d89346b08ad1b"
+ logic_hash = "ff55d6a316394812cfa1108578aece91050bfb2f7e0f8c0440dcb64156f3e893"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "b78fda9794dc24507405fc04bdc0a3e8abfcdc5c757787b7d9822f4ea2190120"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "907cb776c9200b715c5b20475c2d4b16cb55c607dfb4b57bd3bd95368ce66257"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64183,32 +68343,28 @@ rule ELASTIC_Linux_Trojan_Metasploit_5D26689F : FILE MEMORY
os = "linux"
strings:
- $tiny_bind = { 31 D2 52 68 2F 2F 73 68 68 2F 62 69 6E 68 2D 6C 65 2F 89 E7 52 68 2F 2F 6E 63 68 2F 62 69 6E 89 E3 52 57 53 89 E1 31 C0 B0 0B CD 80 }
- $reg_bind_setup = { 31 DB F7 E3 B0 66 43 52 53 6A 02 89 E1 CD 80 52 50 89 E1 B0 66 B3 04 CD 80 B0 66 43 CD 80 59 93 }
- $reg_bind_dup_loop = { 6A 3F 58 CD 80 49 79 }
- $reg_bind_execve = { B0 0B 68 2F 2F 73 68 68 2F 62 69 6E 89 E3 41 CD 80 }
+ $a = { 00 00 00 31 DB 89 D8 B0 17 CD 80 31 C0 50 50 B0 }
condition:
- ($tiny_bind) or ( all of ($reg_bind*))
+ all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_1C8C98Ae : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_30C21B03 : FILE MEMORY
{
meta:
- description = "Detects x86 msfvenom add user payloads"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "1c8c98ae-46c8-45fe-ab42-7b053f0357ed"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "30c21b03-22fc-4ec8-8b65-084e98da8d8d"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L231-L251"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "1a2c40531584ed485f3ff532f4269241a76ff171956d03e4f0d3f9c950f186d4"
- logic_hash = "fc32aa29f58478f0b7f4f5be61aadec65842c05b7d8ded840530503eae28b8eb"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L41-L59"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "a09c81f185a4ceed134406fa7fefdfa7d8dfc10d639dd044c94fbb6d570fa029"
+ logic_hash = "396965c457b2e02d7d524d9d5fb3cc76852895ed9675c7b1205a94f47ba10144"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "a3b592cc6d9b00f76a1084c7c124cc199149ada5b8dc206cff3133718f045c9d"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "8112c4a9bce4b4c9407e851849a5850fa36591570694950a4b53e8a09a1dd92b"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64216,30 +68372,28 @@ rule ELASTIC_Linux_Trojan_Metasploit_1C8C98Ae : FILE MEMORY
os = "linux"
strings:
- $str1 = { 31 C9 89 CB 6A 46 58 CD 80 6A 05 58 31 C9 51 68 73 73 77 64 68 2F 2F 70 61 68 2F 65 74 63 89 E3 41 B5 04 CD 80 93 }
- $str2 = { 59 8B 51 FC 6A 04 58 CD 80 6A 01 58 CD 80 }
+ $a = { 1B CD 80 31 DB 89 D8 B0 17 CD 80 31 C0 50 50 B0 }
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_47F4B334 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_9Ace9649 : FILE MEMORY
{
meta:
- description = "Detects x86 msfvenom exec payloads"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "47f4b334-619b-4b9c-841d-b00c09dd98e5"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "9ace9649-c74a-4b27-a147-d14123104c0a"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L253-L277"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "c3821f63a7ec8861a6168b4bb494bf8cbac436b3abf5eaffbc6907fd68ebedb8"
- logic_hash = "34c8182d3b5ecbebd122d2d58fc0502a6bbca020b528ffdcc9ee988f21512d99"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L61-L79"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "b38869605521531153cfd8077f05e0d6b52dca0fffbc627a4d5eaa84855a491c"
+ logic_hash = "d7a60b0cb7fcbd9e802660bda3e0456f7f4ef9db38b6dab131c160efce48909e"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "955d65f1097ec9183db8bd3da43090f579a27461ba345bb74f62426734731184"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "2e526d7ec47a30c7683725c2d2c3db0a8267630bb0f270599325d50227f6ae29"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64247,34 +68401,28 @@ rule ELASTIC_Linux_Trojan_Metasploit_47F4B334 : FILE MEMORY
os = "linux"
strings:
- $payload1 = { 31 C9 F7 E1 B0 0B [0-1] 68 2F ?? ?? ?? 68 2F 62 69 6E 89 E3 CD 80 }
- $payload2a = { 31 DB F7 E3 B0 0B 52 }
- $payload2b = { 88 14 1E 52 68 2F 2F 73 68 68 2F 62 69 6E 89 E3 52 56 57 53 89 E1 CD 80 }
- $payload3a = { 6A 0B 58 99 52 }
- $payload3b = { 89 E7 68 2F 73 68 00 68 2F 62 69 6E 89 E3 52 E8 }
- $payload3c = { 57 53 89 E1 CD 80 }
+ $a = { 31 C0 31 DB 31 C9 B0 46 CD 80 31 C0 50 68 2F }
condition:
- $payload1 or ( all of ($payload2*)) or ( all of ($payload3*))
+ all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_0B014E0E : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_705C9589 : FILE MEMORY
{
meta:
- description = "Detects x64 msfvenom exec payloads"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "0b014e0e-3f5a-4dcc-8860-eb101281b8a5"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "705c9589-f735-45ef-8cf0-b99a05905a9f"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L279-L303"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "a24443331508cc72b3391353f91cd009cafcc223ac5939eab12faf57447e3162"
- logic_hash = "cb19a0461d5fe6066d1fed4898ea12a9818be69d870e511559b19d5c7c959819"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L81-L99"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "845727ea46491b46a665d4e1a3a9dbbe6cd0536d070f1c1efd533b91b75cdc88"
+ logic_hash = "9834d564c2acc688750d5e6c53db7c1201ef85c6fb3d1d0ea2425a5ba905ff18"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "7a61a0e169bf6aa8760b42c5b260dee453ea6a85fe9e5da46fb7598994904747"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "d75edca622f0ab8a0b60c4ba5c1026c89d3613c0e101c5c12c03ee08cb7c576e"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64282,34 +68430,28 @@ rule ELASTIC_Linux_Trojan_Metasploit_0B014E0E : FILE MEMORY
os = "linux"
strings:
- $payload1 = { 48 B8 2F [0-1] 62 69 6E 2F 73 68 ?? ?? 50 54 5F 52 5E 6A 3B 58 0F 05 }
- $payload2a = { 48 B8 2F 2F 62 69 6E 2F 73 68 99 EB ?? 5D 52 5B }
- $payload2b = { 54 5E 52 50 54 5F 52 55 56 57 54 5E 6A 3B 58 0F 05 }
- $payload3a = { 48 B8 2F 62 69 6E 2F 73 68 00 99 50 54 5F 52 }
- $payload3b = { 54 5E 52 E8 }
- $payload3c = { 56 57 54 5E 6A 3B 58 0F 05 }
+ $a = { 51 53 8D 0C 24 31 C0 B0 0B CD 80 31 C0 B0 01 CD }
condition:
- $payload1 or ( all of ($payload2*)) or ( all of ($payload3*))
+ all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_Ccc99Be1 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_A677Fb9C : FILE MEMORY
{
meta:
- description = "Detects x64 msfvenom pingback bind shell payloads"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "ccc99be1-6ea9-4090-acba-3bbe82b127c1"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "a677fb9c-0271-4491-a7c7-48504b6ec389"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L305-L327"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "0e9f52d7aa6bff33bfbdba6513d402db3913d4036a5e1c1c83f4ccd5cc8107c8"
- logic_hash = "96af2123251587ece32e424202ff61cfa70faf2916cacddf5fcd9d81bf483032"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L101-L119"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "d20b260c7485173264e3e674adc7563ea3891224a3dc98bdd342ebac4a1349e8"
+ logic_hash = "9b43e651f73d17dbd2143cec4c79929723689ce738924588e38c99a9554e5545"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "88e30402974b853e5f83a3033129d99e7dd1f6b31b5855b1602ef2659a0f7f56"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "b7916eefad806131b39af5f9bef27648e2444c9a9c95216b520d73e64fa734f0"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64317,32 +68459,28 @@ rule ELASTIC_Linux_Trojan_Metasploit_Ccc99Be1 : FILE MEMORY
os = "linux"
strings:
- $str1 = { 56 50 6A 29 58 99 6A 02 5F 6A 01 5E 0F 05 48 85 C0 }
- $str2 = { 51 48 89 E6 54 5E 6A 31 58 6A 10 5A 0F 05 6A 32 58 6A 01 5E 0F 05 }
- $str3 = { 6A 2B 58 99 52 52 54 5E 6A 1C 48 8D 14 24 0F 05 48 97 }
- $str4 = { 5E 48 31 C0 48 FF C0 0F 05 6A 3C 58 6A 01 5F 0F 05 }
+ $a = { 89 C0 89 45 EC 83 7D EC FF 75 1A 83 EC 0C 68 }
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_Ed4B2C85 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_78E50162 : FILE MEMORY
{
meta:
- description = "Detects x64 msfvenom bind TCP random port payloads"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "ed4b2c85-730f-4a77-97ed-5439a0493a4a"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "78e50162-8f1e-4c78-94fe-9b793b006269"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L329-L348"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "0709a60149ca110f6e016a257f9ac35c6f64f50cfbd71075c4ca8bfe843c3211"
- logic_hash = "79e466b2f40a6769db498cc28cb22ba72ec20f92c8450d6f1f8301d00012f967"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L121-L139"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "706c865257d5e1f5f434ae0f31e11dfc7e16423c4c639cb2763ec0f51bc73300"
+ logic_hash = "10a5bef486ec0ececfe0a9edfcad7ce053da2a97028cd1648aa27572fedd8ef6"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "c38513fa6b1ed23ec91ae316af9793c5c01ac94b43ba5502f9c32a0854aec96f"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "a5771dad186d0c23d25efb7b22b11aa0a67148cf6efb9657b09ca6e160c192aa"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64350,29 +68488,28 @@ rule ELASTIC_Linux_Trojan_Metasploit_Ed4B2C85 : FILE MEMORY
os = "linux"
strings:
- $str = { 6A 29 58 99 6A 01 5E 6A 02 5F 0F 05 97 B0 32 0F 05 96 B0 2B 0F 05 97 96 FF CE 6A 21 58 0F 05 75 ?? 52 48 BF 2F 2F 62 69 6E 2F 73 68 57 54 5F B0 3B 0F 05 }
+ $a = { 90 90 90 31 C0 31 DB B0 17 CD 80 31 C0 B0 2E CD }
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_2B0Ad6F0 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_3B767A1F : FILE MEMORY
{
meta:
- description = "Detects x64 msfvenom find TCP port payloads"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "2b0ad6f0-44d2-4e7e-8cca-2b0ae1b88d48"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "3b767a1f-5844-4742-a5fd-ef8a3ddb6c12"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L350-L371"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "aa2bce61511c72ac03562b5178aad57bce8b46916160689ed07693790cbfbeec"
- logic_hash = "91b4547e44c40cafe09dd415f0b5dfe5980fcb10d50aeae844cf21e7608d9a9d"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L141-L159"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "e05fed9e514cccbdb775f295327d8f8838b73ad12f25e7bb0b9d607ff3d0511c"
+ logic_hash = "0f24a7d4e8ff0899430aa0a702000f35039b07400120b382b675825630f0ea4e"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "b15da42f957107d54bfad78eff3a703cc2a54afcef8207d42292f2520690d585"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "2bc0dc4de92306076cda6f2d069855b85861375c8b7eb5324f915a1ed10c39e5"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64380,31 +68517,28 @@ rule ELASTIC_Linux_Trojan_Metasploit_2B0Ad6F0 : FILE MEMORY
os = "linux"
strings:
- $str1 = { 48 31 FF 48 31 DB B3 18 48 29 DC 48 8D 14 24 48 C7 02 10 00 00 00 48 8D 74 24 08 6A 34 58 0F 05 48 FF C7 }
- $str2 = { 48 FF CF 6A 02 5E 6A 21 58 0F 05 48 FF CE 79 }
- $str3 = { 48 89 F3 BB 41 2F 73 68 B8 2F 62 69 6E 48 C1 EB 08 48 C1 E3 20 48 09 D8 50 48 89 E7 48 31 F6 48 89 F2 6A 3B 58 0F 05 }
+ $a = { E3 50 53 89 E1 89 C2 B0 0B CD 80 89 C3 31 C0 40 }
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_Bf205D5A : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_2535C9B6 : FILE MEMORY
{
meta:
- description = "Detects x86 msfvenom bind IPv6 TCP shell payloads "
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "bf205d5a-2bba-497a-8d40-58422e91fe45"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "2535c9b6-a575-4190-8e33-88758675e5b4"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L373-L397"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "2162a89f70edd7a7f93f8972c6a13782fb466cdada41f255f0511730ec20d037"
- logic_hash = "9f4c84fadc3d7555c80efc9c9c5dcb01d4ea65d2ff191aa63ae8316f763ded3f"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L161-L179"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "d0f9cc114f6a1f788f36e359e03a9bbf89c075f41aec006229b6ad20ebbfba0b"
+ logic_hash = "222e929d8352ed02714a59b0e1b9777b0f2d80d63cb369fa9bf33460c84efbb2"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "91ac22c6302de26717f0666c59fa3765144df2d22d0c3a311a106bc1d9d2ae70"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "4ec419bfd0ac83da2f826ba4cbd6a4b05bbd7b6f6cc077529ec4667b7d2f761a"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64412,34 +68546,28 @@ rule ELASTIC_Linux_Trojan_Metasploit_Bf205D5A : FILE MEMORY
os = "linux"
strings:
- $str1 = { 6A 7D 58 99 B2 07 B9 00 10 00 00 89 E3 66 81 E3 00 F0 CD 80 31 DB F7 E3 53 43 53 6A ?? 89 E1 B0 66 CD 80 }
- $str2 = { 51 6A 04 54 6A 02 6A 01 50 }
- $str3 = { 6A 0E 5B 6A 66 58 CD 80 89 F8 83 C4 14 59 5B 5E }
- $str4 = { CD 80 93 B6 0C B0 03 CD 80 87 DF 5B B0 06 CD 80 }
- $ipv6 = { 6A 02 5B 52 52 52 52 52 52 ?? ?? ?? ?? ?? 89 E1 6A 1C }
- $socket = { 51 50 89 E1 6A 66 58 CD 80 D1 E3 B0 66 CD 80 57 43 B0 66 89 51 04 CD 80 }
+ $a = { E8 63 F9 FF FF 83 7D D8 FF 75 14 BF 47 12 40 00 }
condition:
- 3 of ($str*) and $ipv6 and $socket
+ all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_E5B61173 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_6A9B5D50 : FILE MEMORY
{
meta:
- description = "Detects x86 msfvenom stageless TCP reverse shell payload"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "e5b61173-cf1c-4176-bc43-550c0213ce98"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "6a9b5d50-3cd4-4b64-9a52-713e1a8f02b2"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L399-L420"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "8032a7a320102c8e038db16d51b8615ee49f04dab1444326463f75ce0c5947a5"
- logic_hash = "f60d2de0b7fac06b62616d7c7f51e9374df3895eb30a07040e742cbcb462a418"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L181-L199"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "80ab71dc9ed2131b08b5b75b5a4a12719d499c6b6ee6819ad5a6626df4a1b862"
+ logic_hash = "99a18bfb62c195bdea89c688fed4456fee33477878ecdee8a78cd4bf18ad539b"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "7052cce595dbbf36aed5e1edab12a75f06059e6267c859516011d8feb9e328e6"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "7eea1345492359984e9be089c3e7339b79927abcff0ae4a40a713e956bb25919"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64447,31 +68575,28 @@ rule ELASTIC_Linux_Trojan_Metasploit_E5B61173 : FILE MEMORY
os = "linux"
strings:
- $str1 = { 31 DB F7 E3 53 43 53 6A 02 89 E1 B0 66 CD 80 93 59 B0 3F CD 80 49 79 }
- $str2 = { 89 E1 B0 66 50 51 53 B3 03 89 E1 CD 80 52 }
- $str3 = { 89 E3 52 53 89 E1 B0 0B CD 80 }
+ $a = { E8 ?? F9 FF FF 83 7D D8 FF 75 14 BF ?? 13 40 00 }
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Metasploit_Dd5Fd075 : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_66557224 : FILE MEMORY
{
meta:
- description = "Detects x86 msfvenom TCP bind shell payloads"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "dd5fd075-bd52-47a9-b737-e55ab10a071d"
- date = "2024-05-07"
- modified = "2024-05-21"
+ id = "66557224-2c7a-4770-8333-8984d4a7b3f7"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Metasploit.yar#L422-L443"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "b47132a92b66c32c88f39fe36d0287c6b864043273939116225235d4c5b4043a"
- logic_hash = "f5101d5ddb1a84127e755677da70d9154849c546ac6ef0e7ef2639c82911eb92"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L201-L219"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "f58151a2f653972e744822cdc420ab1c2b8b642877d3dfa2e8b2b6915e8edf40"
+ logic_hash = "5583f086d594ebdf5890a8a5fbee5c04fbddfe42adcae07480532d87e474ef0c"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "df2a4f90ec3227555671136c18931118fc9df32340d87aeb3f3fa7fdf2ba6179"
- threat_name = "Linux.Trojan.Metasploit"
+ fingerprint = "88503c2e1e389866962704a8b19a47c22f758bb2cee9b76600e5d9bab125d4ca"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64479,126 +68604,86 @@ rule ELASTIC_Linux_Trojan_Metasploit_Dd5Fd075 : FILE MEMORY
os = "linux"
strings:
- $str1 = { 31 DB F7 E3 53 43 53 6A 02 89 E1 B0 66 CD 80 5B 5E 52 }
- $str2 = { 6A 10 51 50 89 E1 6A 66 58 CD 80 89 41 04 B3 04 B0 66 CD 80 43 B0 66 CD 80 93 59 }
- $str3 = { 6A 3F 58 CD 80 49 79 F8 68 2F 2F 73 68 68 2F 62 69 6E 89 E3 50 53 89 E1 B0 0B CD 80 }
+ $a = { FF FF 83 BD E4 FB FF FF FF 75 1A 83 EC 0C 68 24 }
condition:
all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_C851687A : FILE MEMORY
+rule ELASTIC_Linux_Exploit_Local_6229602F : FILE MEMORY
{
meta:
- description = "Identifies UAC Bypass module from Cobalt Strike"
+ description = "Detects Linux Exploit Local (Linux.Exploit.Local)"
author = "Elastic Security"
- id = "c851687a-aac6-43e7-a0b6-6aed36dcf12e"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "6229602f-1c88-46fa-8fae-a6268ed6d632"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L1-L37"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "7fac6fb24ac18bd69dd9f8f4090c4a77d1cc6554b6ae5c846e32d7666e5a1971"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Exploit_Local.yar#L221-L239"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "4fdb15663a405f6fc4379aad9a5021040d7063b8bb82403bedb9578d45d428fa"
+ logic_hash = "c3ab6a36c0c2d430d576f7c0cfdc6d1affcd99d007e2d05596677da9bda5a19e"
score = 75
- quality = 25
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "70224e28a223d09f2211048936beb9e2d31c0312c97a80e22c85e445f1937c10"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "b26b21518fd436d79d6a23dbf3d7056b7c056e4df6639718e285de096476f61d"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = "bypassuac.dll" ascii fullword
- $a2 = "bypassuac.x64.dll" ascii fullword
- $a3 = "\\\\.\\pipe\\bypassuac" ascii fullword
- $b1 = "\\System32\\sysprep\\sysprep.exe" wide fullword
- $b2 = "[-] Could not write temp DLL to '%S'" ascii fullword
- $b3 = "[*] Cleanup successful" ascii fullword
- $b4 = "\\System32\\cliconfg.exe" wide fullword
- $b5 = "\\System32\\eventvwr.exe" wide fullword
- $b6 = "[-] %S ran too long. Could not terminate the process." ascii fullword
- $b7 = "[*] Wrote hijack DLL to '%S'" ascii fullword
- $b8 = "\\System32\\sysprep\\" wide fullword
- $b9 = "[-] COM initialization failed." ascii fullword
- $b10 = "[-] Privileged file copy failed: %S" ascii fullword
- $b11 = "[-] Failed to start %S: %d" ascii fullword
- $b12 = "ReflectiveLoader"
- $b13 = "[-] '%S' exists in DLL hijack location." ascii fullword
- $b14 = "[-] Cleanup failed. Remove: %S" ascii fullword
- $b15 = "[+] %S ran and exited." ascii fullword
- $b16 = "[+] Privileged file copy success! %S" ascii fullword
+ $a = { 89 C0 89 45 FC 83 7D FC 00 7D 17 68 ?? ?? 04 08 }
condition:
- 2 of ($a*) or 10 of ($b*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_0B58325E : FILE MEMORY
+rule ELASTIC_Linux_Trojan_Shark_B918Ab75 : FILE MEMORY
{
meta:
- description = "Identifies Keylogger module from Cobalt Strike"
+ description = "Detects Linux Trojan Shark (Linux.Trojan.Shark)"
author = "Elastic Security"
- id = "0b58325e-2538-434d-9a2c-26e2c32db039"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "b918ab75-0701-4865-b798-521fdd2ffc28"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L39-L77"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "3822431e946fcc38c700cc8ce213e95f33a155d7f38b6ab2a24cb998d42c8521"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Shark.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "8b6fe9f496996784e42b75fb42702aa47aefe32eac6f63dd16a0eb55358b6054"
+ logic_hash = "16302c29f2ae4109b8679933eb7fd9ef9306b0c215f20e8fff992b0b848974a9"
score = 75
- quality = 73
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "8ecd5bdce925ae5d4f90cecb9bc8c3901b54ba1c899a33354bcf529eeb2485d4"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "15205d58af99b8eae14de2d5762fdc710ef682839967dd56f6d65bd3deaa7981"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = "keylogger.dll" ascii fullword
- $a2 = "keylogger.x64.dll" ascii fullword
- $a3 = "\\\\.\\pipe\\keylogger" ascii fullword
- $a4 = "%cE=======%c" ascii fullword
- $a5 = "[unknown: %02X]" ascii fullword
- $b1 = "ReflectiveLoader"
- $b2 = "%c2%s%c" ascii fullword
- $b3 = "[numlock]" ascii fullword
- $b4 = "%cC%s" ascii fullword
- $b5 = "[backspace]" ascii fullword
- $b6 = "[scroll lock]" ascii fullword
- $b7 = "[control]" ascii fullword
- $b8 = "[left]" ascii fullword
- $b9 = "[page up]" ascii fullword
- $b10 = "[page down]" ascii fullword
- $b11 = "[prtscr]" ascii fullword
- $b12 = "ZRich9" ascii fullword
- $b13 = "[ctrl]" ascii fullword
- $b14 = "[home]" ascii fullword
- $b15 = "[pause]" ascii fullword
- $b16 = "[clear]" ascii fullword
+ $a = { 26 00 C7 46 14 0A 00 00 00 C7 46 18 15 00 00 00 EB 30 C7 46 14 04 00 }
condition:
- 1 of ($a*) and 14 of ($b*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_2B8Cddf8 : FILE MEMORY
+rule ELASTIC_Windows_Hacktool_Coffloader_81Ba13B8 : FILE MEMORY
{
meta:
- description = "Identifies dll load module from Cobalt Strike"
+ description = "Detects Windows Hacktool Coffloader (Windows.Hacktool.COFFLoader)"
author = "Elastic Security"
- id = "2b8cddf8-ca7a-4f85-be9d-6d8534d0482e"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "81ba13b8-8994-4fe9-98e5-44514c554e8b"
+ date = "2024-04-22"
+ modified = "2024-05-08"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L79-L114"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "5502c06d33b93bae3bc25ba7dd6a5a9a3b0b2b43bb7e867e601ecb206bf503ed"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_COFFLoader.yar#L1-L43"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "c2e03659eb1594dc958e01344cfa9ba126d66736b089db5e3dd1b1c3e3e7d2f7"
+ logic_hash = "d4f061af200a0ae9f3276fd6dfcb09ecdf662f29b7c43ea47c69a53d9fe66793"
score = 75
- quality = 43
+ quality = 73
tags = "FILE, MEMORY"
- fingerprint = "0d7d28d79004ca61b0cfdcda29bd95e3333e6fc6e6646a3f6ba058aa01bee188"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "ef9f11d9cd6c3b46f7d13ea039dcad6fa24515495466b1102ec8c1c8bed8853e"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64606,117 +68691,113 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_2B8Cddf8 : FILE MEMORY
os = "windows"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\dllload.x64.o" ascii fullword
- $a2 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\dllload.x86.o" ascii fullword
- $b1 = "__imp_BeaconErrorDD" ascii fullword
- $b2 = "__imp_BeaconErrorNA" ascii fullword
- $b3 = "__imp_BeaconErrorD" ascii fullword
- $b4 = "__imp_BeaconDataInt" ascii fullword
- $b5 = "__imp_KERNEL32$WriteProcessMemory" ascii fullword
- $b6 = "__imp_KERNEL32$OpenProcess" ascii fullword
- $b7 = "__imp_KERNEL32$CreateRemoteThread" ascii fullword
- $b8 = "__imp_KERNEL32$VirtualAllocEx" ascii fullword
- $c1 = "__imp__BeaconErrorDD" ascii fullword
- $c2 = "__imp__BeaconErrorNA" ascii fullword
- $c3 = "__imp__BeaconErrorD" ascii fullword
- $c4 = "__imp__BeaconDataInt" ascii fullword
- $c5 = "__imp__KERNEL32$WriteProcessMemory" ascii fullword
- $c6 = "__imp__KERNEL32$OpenProcess" ascii fullword
- $c7 = "__imp__KERNEL32$CreateRemoteThread" ascii fullword
- $c8 = "__imp__KERNEL32$VirtualAllocEx" ascii fullword
+ $a1 = "BeaconDataParse" ascii fullword
+ $a2 = "BeaconDataInt" ascii fullword
+ $a3 = "BeaconDataShort" ascii fullword
+ $a4 = "BeaconDataLength" ascii fullword
+ $a5 = "BeaconDataExtract" ascii fullword
+ $a6 = "BeaconFormatAlloc" ascii fullword
+ $a7 = "BeaconFormatReset" ascii fullword
+ $a8 = "BeaconFormatFree" ascii fullword
+ $a9 = "BeaconFormatAppend" ascii fullword
+ $a10 = "BeaconFormatPrintf" ascii fullword
+ $a11 = "BeaconFormatToString" ascii fullword
+ $a12 = "BeaconFormatInt" ascii fullword
+ $a13 = "BeaconPrintf" ascii fullword
+ $a14 = "BeaconOutput" ascii fullword
+ $a15 = "BeaconUseToken" ascii fullword
+ $a16 = "BeaconRevertToken" ascii fullword
+ $a17 = "BeaconDataParse" ascii fullword
+ $a18 = "BeaconIsAdmin" ascii fullword
+ $a19 = "BeaconGetSpawnTo" ascii fullword
+ $a20 = "BeaconSpawnTemporaryProcess" ascii fullword
+ $a21 = "BeaconInjectProcess" ascii fullword
+ $a22 = "BeaconInjectTemporaryProcess" ascii fullword
+ $a23 = "BeaconCleanupProcess" ascii fullword
+ $b1 = "COFFLoader.x64.dll"
+ $b2 = "COFFLoader.x86.dll"
condition:
- 1 of ($a*) or 5 of ($b*) or 5 of ($c*)
+ 5 of ($a*) or 1 of ($b*)
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_59B44767 : FILE MEMORY
+rule ELASTIC_Linux_Trojan_Rooter_C8D08D3A : FILE MEMORY
{
meta:
- description = "Identifies getsystem module from Cobalt Strike"
+ description = "Detects Linux Trojan Rooter (Linux.Trojan.Rooter)"
author = "Elastic Security"
- id = "59b44767-c9a5-42c0-b177-7fe49afd7dfb"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "c8d08d3a-ff9c-4545-9f09-45fbe5b534f3"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L116-L142"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "7027d0dcbdb1961d2604f29392a923957d298a047c268553599ea8c881f76a98"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Rooter.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "f55e3aa4d875d8322cdd7caa17aa56e620473fe73c9b5ae0e18da5fbc602a6ba"
+ logic_hash = "c91f3112cc61acec08ab3cd59bab2ae833ba0d8ac565ffb26a46982f38af0e71"
score = 75
- quality = 69
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "882886a282ec78623a0d3096be3d324a8a1b8a23bcb88ea0548df2fae5e27aa5"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "2a09f9fabfefcf44c71ee17b823396991940bedd7a481198683ee3e88979edf4"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\getsystem.x86.o" ascii fullword
- $a2 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\getsystem.x64.o" ascii fullword
- $b1 = "getsystem failed." ascii fullword
- $b2 = "_isSystemSID" ascii fullword
- $b3 = "__imp__NTDLL$NtQuerySystemInformation@16" ascii fullword
- $c1 = "getsystem failed." ascii fullword
- $c2 = "$pdata$isSystemSID" ascii fullword
- $c3 = "$unwind$isSystemSID" ascii fullword
- $c4 = "__imp_NTDLL$NtQuerySystemInformation" ascii fullword
+ $a = { D8 DC 04 08 BB 44 C3 04 08 CD 80 C7 05 48 FB 04 }
condition:
- 1 of ($a*) or 3 of ($b*) or 3 of ($c*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_7Efd3C3F : FILE MEMORY
+rule ELASTIC_Windows_Hacktool_EDRWFP_F6D7Db7A : FILE
{
meta:
- description = "Identifies Hashdump module from Cobalt Strike"
+ description = "Detects Windows Hacktool Edrwfp (Windows.Hacktool.EDRWFP)"
author = "Elastic Security"
- id = "7efd3c3f-1104-4b46-9d1e-dc2c62381b8c"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "f6d7db7a-c55e-41dc-859b-6431464e72f4"
+ date = "2024-06-10"
+ modified = "2024-07-02"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L144-L168"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "45a0aaba6c1be016fc5f4051680ee7e3aa62e8a5d9730b7adab08c14ae37da24"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_EDRWFP.yar#L1-L22"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "a1fc2f3ded852f75e36e70ae39087e21ae5b6af10e2038d04e61bd500ba511e2"
+ logic_hash = "45d427e4f52346b4a18c154bb0afb636c18951fd9c7323846bf2eb7e47928ef6"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "9e7c7c9a7436f5ee4c27fd46d6f06e7c88f4e4d1166759573cedc3ed666e1838"
- threat_name = "Windows.Trojan.CobaltStrike"
- severity = 70
+ tags = "FILE"
+ fingerprint = "11e4224f53ddb5ef18aef5efeaa7ec6ec00072e57db5189e29a04feae6b3da31"
+ severity = 100
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
os = "windows"
strings:
- $a1 = "hashdump.dll" ascii fullword
- $a2 = "hashdump.x64.dll" ascii fullword
- $a3 = "\\\\.\\pipe\\hashdump" ascii fullword
- $a4 = "ReflectiveLoader"
- $a5 = "Global\\SAM" ascii fullword
- $a6 = "Global\\FREE" ascii fullword
- $a7 = "[-] no results." ascii fullword
+ $s1 = "elastic-endpoint.exe"
+ $s2 = "elastic-agent.exe"
+ $s3 = "MsMpEng.exe"
+ $s4 = "FwpmFilterAdd0"
condition:
- 4 of ($a*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_6E971281 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Diceloader_B32C6B99 : FILE MEMORY
{
meta:
- description = "Identifies Interfaces module from Cobalt Strike"
+ description = "Detects Windows Trojan Diceloader (Windows.Trojan.Diceloader)"
author = "Elastic Security"
- id = "6e971281-3ee3-402f-8a72-745ec8fb91fb"
- date = "2021-03-23"
+ id = "b32c6b99-f634-4c6f-98f4-39954ef15afa"
+ date = "2021-04-23"
modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L170-L201"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "f204965c0118dbdfe7e134d319c92b30d22585e888609ff31df90643116a2c38"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Diceloader.yar#L1-L25"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "a3b3f56a61c6dc8ba2aa25bdd9bd7dc2c5a4602c2670431c5cbc59a76e2b4c54"
+ logic_hash = "f9e023f340edc4c46b2926e750c2ad3a3798e34415e43c0ea2d83073e3dc526a"
score = 75
- quality = 51
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "62d97cf73618a1b4d773d5494b2761714be53d5cda774f9a96eaa512c8d5da12"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "15d4bc57c03a560608ae69551aa46d1786072b3d78d747512f8ac3e6822a7b93"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64724,41 +68805,34 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_6E971281 : FILE MEMORY
os = "windows"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\interfaces.x64.o" ascii fullword
- $a2 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\interfaces.x86.o" ascii fullword
- $b1 = "__imp_BeaconFormatAlloc" ascii fullword
- $b2 = "__imp_BeaconFormatPrintf" ascii fullword
- $b3 = "__imp_BeaconOutput" ascii fullword
- $b4 = "__imp_KERNEL32$LocalAlloc" ascii fullword
- $b5 = "__imp_KERNEL32$LocalFree" ascii fullword
- $b6 = "__imp_LoadLibraryA" ascii fullword
- $c1 = "__imp__BeaconFormatAlloc" ascii fullword
- $c2 = "__imp__BeaconFormatPrintf" ascii fullword
- $c3 = "__imp__BeaconOutput" ascii fullword
- $c4 = "__imp__KERNEL32$LocalAlloc" ascii fullword
- $c5 = "__imp__KERNEL32$LocalFree" ascii fullword
- $c6 = "__imp__LoadLibraryA" ascii fullword
+ $a1 = "D$0GET " ascii fullword
+ $a2 = "D$THostf" ascii fullword
+ $a3 = "D$,POST" ascii fullword
+ $a4 = "namef" ascii fullword
+ $a5 = "send" ascii fullword
+ $a6 = "log.ini" wide
+ $a7 = { 70 61 73 73 00 00 65 6D 61 69 6C 00 00 6C 6F 67 69 6E 00 00 73 69 67 6E 69 6E 00 00 61 63 63 6F 75 6E 74 00 00 70 65 72 73 69 73 74 65 6E 74 00 00 48 6F 73 74 3A 20 }
condition:
- 1 of ($a*) or 4 of ($b*) or 4 of ($c*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_09B79Efa : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Diceloader_15Eeb7B9 : FILE MEMORY
{
meta:
- description = "Identifies Invoke Assembly module from Cobalt Strike"
+ description = "Detects Windows Trojan Diceloader (Windows.Trojan.Diceloader)"
author = "Elastic Security"
- id = "09b79efa-55d7-481d-9ee0-74ac5f787cef"
- date = "2021-03-23"
+ id = "15eeb7b9-311f-477b-8ae1-b8f689a154b7"
+ date = "2021-04-23"
modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L203-L232"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "75fd003b9adf03aff8479b1b10da9c94955870b5fa4f1958f870e14acb2793c7"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Diceloader.yar#L27-L46"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "a1202df600d11ad2c61050e7ba33701c22c2771b676f54edd1846ef418bea746"
+ logic_hash = "f1ab9ad69f9ea75343c7404b82a3f7a4976a442b980a98fe5b95c55d4f9cb34e"
score = 75
- quality = 48
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "04ef6555e8668c56c528dc62184331a6562f47652c73de732e5f7c82779f2fd8"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "4cc70bec5d241c6f84010fbfe2eafbc6ec6d753df2bb3f52d9498b54b11fc8cb"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64766,39 +68840,29 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_09B79Efa : FILE MEMORY
os = "windows"
strings:
- $a1 = "invokeassembly.x64.dll" ascii fullword
- $a2 = "invokeassembly.dll" ascii fullword
- $b1 = "[-] Failed to get default AppDomain w/hr 0x%08lx" ascii fullword
- $b2 = "[-] Failed to load the assembly w/hr 0x%08lx" ascii fullword
- $b3 = "[-] Failed to create the runtime host" ascii fullword
- $b4 = "[-] Invoke_3 on EntryPoint failed." ascii fullword
- $b5 = "[-] CLR failed to start w/hr 0x%08lx" ascii fullword
- $b6 = "ReflectiveLoader"
- $b7 = ".NET runtime [ver %S] cannot be loaded" ascii fullword
- $b8 = "[-] No .NET runtime found. :(" ascii fullword
- $b9 = "[-] ICorRuntimeHost::GetDefaultDomain failed w/hr 0x%08lx" ascii fullword
- $c1 = { FF 57 0C 85 C0 78 40 8B 45 F8 8D 55 F4 8B 08 52 50 }
+ $a1 = { E9 92 9D FF FF C3 E8 }
+ $a2 = { E9 E8 61 FF FF C3 E8 }
condition:
- 1 of ($a*) or 3 of ($b*) or 1 of ($c*)
+ any of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_6E77233E : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Havoc_77F3D40E : FILE MEMORY
{
meta:
- description = "Identifies Kerberos module from Cobalt Strike"
+ description = "Detects Windows Trojan Havoc (Windows.Trojan.Havoc)"
author = "Elastic Security"
- id = "6e77233e-7fb4-4295-823d-f97786c5d9c4"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "77f3d40e-9365-4e76-a1a3-36d128e775a9"
+ date = "2022-10-20"
+ modified = "2022-11-24"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L234-L269"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "93aa11523b794402b257d02d4f9edc5ad320bfdb5b8b0f671ff08f399ef9e674"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Havoc.yar#L1-L35"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "3427dac129b760a03f2c40590c01065c9bf2340d2dfa4a4a7cf4830a02e95879"
+ logic_hash = "3d2733ed24d90e9e851ec36a08c497e9c90b47c3dcbb8755e3f6b6a6bd3a8b54"
score = 75
- quality = 63
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "cef2949eae78b1c321c2ec4010749a5ac0551d680bd5eb85493fc88c5227d285"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "95d35d167df7f77f23b1afb1b7655cc47830c9986c54791b562c33db8f2773ae"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64806,45 +68870,44 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_6E77233E : FILE MEMORY
os = "windows"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\kerberos.x64.o" ascii fullword
- $a2 = "$unwind$command_kerberos_ticket_use" ascii fullword
- $a3 = "$pdata$command_kerberos_ticket_use" ascii fullword
- $a4 = "command_kerberos_ticket_use" ascii fullword
- $a5 = "$pdata$command_kerberos_ticket_purge" ascii fullword
- $a6 = "command_kerberos_ticket_purge" ascii fullword
- $a7 = "$unwind$command_kerberos_ticket_purge" ascii fullword
- $a8 = "$unwind$kerberos_init" ascii fullword
- $a9 = "$unwind$KerberosTicketUse" ascii fullword
- $a10 = "KerberosTicketUse" ascii fullword
- $a11 = "$unwind$KerberosTicketPurge" ascii fullword
- $b1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\kerberos.x86.o" ascii fullword
- $b2 = "_command_kerberos_ticket_use" ascii fullword
- $b3 = "_command_kerberos_ticket_purge" ascii fullword
- $b4 = "_kerberos_init" ascii fullword
- $b5 = "_KerberosTicketUse" ascii fullword
- $b6 = "_KerberosTicketPurge" ascii fullword
- $b7 = "_LsaCallKerberosPackage" ascii fullword
+ $core = { 48 ?? ?? 2C 06 00 00 00 ?? ?? 48 ?? ?? 5C 06 00 00 00 ?? ?? ?? ?? ?? ?? 48 8B ?? 5C 06 00 00 ?? F6 99 5A 2E E8 ?? ?? ?? ?? 48 8B ?? 48 ?? ?? 4C 02 00 00 48 8B ?? 5C 06 00 00 ?? 23 DB 07 03 E8 ?? ?? ?? ?? 48 8B ?? 48 ?? ?? 44 02 00 00 48 8B ?? 5C 06 00 00 ?? DA 81 B3 C0 E8 ?? ?? ?? ?? 48 8B ?? 48 ?? ?? 54 02 00 00 48 8B ?? 5C 06 00 00 ?? D7 71 BA 70 E8 ?? ?? ?? ?? 48 8B ?? 48 ?? ?? 64 02 00 00 48 8B ?? 5C 06 00 00 ?? 88 2B 49 8E E8 ?? ?? ?? ?? 48 8B ?? 48 ?? ?? 84 02 00 00 48 8B ?? 5C 06 00 00 ?? EF F0 A1 3A E8 ?? ?? ?? ?? }
+ $commands_table = { 0B 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 64 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 15 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 10 10 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 0C 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? [0-12] 0F 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 14 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 01 20 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 03 20 00 00 ?? ?? ?? ?? ?? ?? ?? ?? C4 09 00 00 ?? ?? ?? ?? ?? ?? ?? ?? CE 09 00 00 ?? ?? ?? ?? ?? ?? ?? ?? D8 09 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 34 08 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 16 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 18 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 1A 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 28 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? 5C 00 00 00 ?? ?? ?? ?? ?? ?? ?? ?? }
+ $hashes_0 = { F6 99 5A 2E }
+ $hashes_1 = { DA 81 B3 C0 }
+ $hashes_2 = { D7 71 BA 70 }
+ $hashes_3 = { 88 2B 49 8E }
+ $hashes_4 = { EF F0 A1 3A }
+ $hashes_5 = { F5 39 34 7C }
+ $hashes_6 = { 2A 92 12 D8 }
+ $hashes_7 = { 8D F1 4F 84 }
+ $hashes_8 = { 5B BC CE 73 }
+ $hashes_9 = { 59 24 93 B8 }
+ $hashes_10 = { 02 9E D0 C2 }
+ $hashes_11 = { E5 36 26 AE }
+ $hashes_12 = { 5C 3C B4 F3 }
+ $hashes_13 = { 2F 87 D8 1C }
+ $hashes_14 = { D7 53 22 AC }
condition:
- 5 of ($a*) or 3 of ($b*)
+ $core or ($commands_table and all of ($hashes*))
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_De42495A : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Havoc_9C7Bb863 : FILE MEMORY
{
meta:
- description = "Identifies Mimikatz module from Cobalt Strike"
+ description = "Detects Windows Trojan Havoc (Windows.Trojan.Havoc)"
author = "Elastic Security"
- id = "de42495a-0002-466e-98b9-19c9ebb9240e"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "9c7bb863-b6c2-4d5f-ae50-0fd900f1d4eb"
+ date = "2023-04-28"
+ modified = "2023-06-13"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L271-L301"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "2a13c73d221d80d25a432f9e0a1387153a78f58719066586e9d80d17613293ef"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Havoc.yar#L37-L56"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "261b92d9e8dcb9d0abf1627b791831ec89779f2b7973b1926c6ec9691288dd57"
+ logic_hash = "c1245c38c54b0a72fb335680d9ea191390e4e2fe7e47a3ed776878c5e01a3e16"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "dab3c25809ec3af70df5a8a04a2efd4e8ecb13a4c87001ea699e7a1512973b82"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "cda55a9e65badb984e71778b081929db2bdef223792b78bba32b2259757f1348"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64852,40 +68915,29 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_De42495A : FILE MEMORY
os = "windows"
strings:
- $a1 = "\\\\.\\pipe\\mimikatz" ascii fullword
- $b1 = "ERROR kuhl_m_dpapi_chrome ; Input 'Login Data' file needed (/in:\"%%localappdata%%\\Google\\Chrome\\User Data\\Default\\Login Da" wide
- $b2 = "ERROR kuhl_m_lsadump_getUsersAndSamKey ; kull_m_registry_RegOpenKeyEx SAM Accounts (0x%08x)" wide fullword
- $b3 = "ERROR kuhl_m_lsadump_getUsersAndSamKey ; kuhl_m_lsadump_getSamKey KO" wide fullword
- $b4 = "ERROR kuhl_m_lsadump_getComputerAndSyskey ; kull_m_registry_RegOpenKeyEx LSA KO" wide fullword
- $b5 = "ERROR kuhl_m_lsadump_lsa_getHandle ; OpenProcess (0x%08x)" wide fullword
- $b6 = "ERROR kuhl_m_lsadump_enumdomains_users ; SamLookupNamesInDomain: %08x" wide fullword
- $b7 = "mimikatz(powershell) # %s" wide fullword
- $b8 = "powershell_reflective_mimikatz" ascii fullword
- $b9 = "mimikatz_dpapi_cache.ndr" wide fullword
- $b10 = "mimikatz.log" wide fullword
- $b11 = "ERROR mimikatz_doLocal" wide
- $b12 = "mimikatz_x64.compressed" wide
+ $a1 = { 56 48 89 E6 48 83 E4 F0 48 83 EC 20 E8 0F 00 00 00 48 89 F4 5E C3 }
+ $a2 = { 65 48 8B 04 25 60 00 00 00 }
condition:
- 1 of ($a*) and 7 of ($b*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_72F68375 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Havoc_88053562 : FILE MEMORY
{
meta:
- description = "Identifies Netdomain module from Cobalt Strike"
+ description = "Detects Windows Trojan Havoc (Windows.Trojan.Havoc)"
author = "Elastic Security"
- id = "72f68375-35ab-49cc-905d-15302389a236"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "88053562-ae19-44fe-8aaf-d6b9687d6b80"
+ date = "2024-01-04"
+ modified = "2024-01-12"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L303-L328"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "912e37829a9f99e00326745343c9e4593cd7cfb8d4dfafc66027cddcb4d883be"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Havoc.yar#L58-L76"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "2f0b59f8220edd0d34fba92905faf0b51aead95d53be8b5f022eed7e21bdb4af"
+ logic_hash = "f79b39cc2ca4bbf6ad4b6585a9914a75797110d6fb68bcb7141c5c3d0429c412"
score = 75
- quality = 63
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "ecc28f414b2c347722b681589da8529c6f3af0491845453874f8fd87c2ae86d7"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "818011b7972ab71cbfe07ec2266f504ba0ec7df30136e414d15366aa68ad5b8a"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64893,35 +68945,28 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_72F68375 : FILE MEMORY
os = "windows"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\net_domain.x64.o" ascii fullword
- $a2 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\net_domain.x86.o" ascii fullword
- $b1 = "__imp_BeaconPrintf" ascii fullword
- $b2 = "__imp_NETAPI32$NetApiBufferFree" ascii fullword
- $b3 = "__imp_NETAPI32$DsGetDcNameA" ascii fullword
- $c1 = "__imp__BeaconPrintf" ascii fullword
- $c2 = "__imp__NETAPI32$NetApiBufferFree" ascii fullword
- $c3 = "__imp__NETAPI32$DsGetDcNameA" ascii fullword
+ $a = { 48 81 EC F8 04 00 00 48 8D 7C 24 78 44 89 8C 24 58 05 00 00 48 8B AC 24 60 05 00 00 4C 8D 6C 24 78 F3 AB B9 59 00 00 00 48 C7 44 24 70 00 00 00 00 C7 44 24 78 68 00 00 00 C7 84 24 B4 00 00 00 }
condition:
- 1 of ($a*) or 2 of ($b*) or 2 of ($c*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_15F680Fb : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Havoc_Ffecc8Af : FILE MEMORY
{
meta:
- description = "Identifies Netview module from Cobalt Strike"
+ description = "Detects Windows Trojan Havoc (Windows.Trojan.Havoc)"
author = "Elastic Security"
- id = "15f680fb-a04f-472d-a182-0b9bee111351"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "ffecc8af-4a64-4252-b7ca-3316d27c3942"
+ date = "2024-04-29"
+ modified = "2024-05-08"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L330-L360"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "0efe368ad82f5b0f6301121bfda9fd049b008ac246368bfa22bd976fa2c56b79"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Havoc.yar#L78-L107"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "495d323651c252e38814b77b9c6c913b9489e769252ac8bbaf8432f15e0efe44"
+ logic_hash = "c9da6215db1de91a6cd52dd6558dc5a60bbd69abc6fa0db8714f001cdae20ddb"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "0ecb8e41c01bf97d6dea4cf6456b769c6dd2a037b37d754f38580bcf561e1d2c"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "d09b0519d518b741cec7f6e42efaa657410edd36d027f54e515be510b33fa821"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -64929,81 +68974,77 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_15F680Fb : FILE MEMORY
os = "windows"
strings:
- $a1 = "netview.x64.dll" ascii fullword
- $a2 = "netview.dll" ascii fullword
- $a3 = "\\\\.\\pipe\\netview" ascii fullword
- $b1 = "Sessions for \\\\%s:" ascii fullword
- $b2 = "Account information for %s on \\\\%s:" ascii fullword
- $b3 = "Users for \\\\%s:" ascii fullword
- $b4 = "Shares at \\\\%s:" ascii fullword
- $b5 = "ReflectiveLoader" ascii fullword
- $b6 = "Password changeable" ascii fullword
- $b7 = "User's Comment" wide fullword
- $b8 = "List of hosts for domain '%s':" ascii fullword
- $b9 = "Password changeable" ascii fullword
- $b10 = "Logged on users at \\\\%s:" ascii fullword
+ $commands_table = { 0B 00 00 00 00 00 00 00 [8] 64 00 00 00 00 00 00 00 [8] 15 00 00 00 00 00 00 00 [8] 10 10 00 00 00 00 00 00 [8] 0C 00 00 00 00 00 00 00 [8] 0F 00 00 00 00 00 00 00 [8] 14 00 00 00 00 00 00 00 [8] 01 20 00 00 00 00 00 00 [8] 03 20 00 00 00 00 00 00 [8] C4 09 00 00 00 00 00 00 [8] CE 09 00 00 00 00 00 00 [8] D8 09 00 00 00 00 00 00 [8] 34 08 00 00 00 00 00 00 [8] 16 00 00 00 00 00 00 00 [8] 18 00 00 00 00 00 00 00 [8] 1A 00 00 00 00 00 00 00 [8] 28 00 00 00 00 00 00 00 [8] E2 09 00 00 00 00 00 00 [8] EC 09 00 00 00 00 00 00 [8] F6 09 00 00 00 00 00 00 [8] 00 0A 00 00 00 00 00 00 [8] 5C 00 00 00 00 00 00 00 }
+ $hash_ldrloaddll = { 43 6A 45 9E }
+ $hash_ldrgetprocedureaddress = { B6 6B CE FC }
+ $hash_ntaddbootentry = { 76 C7 FC 8C }
+ $hash_ntallocatevirtualmemory = { EC B8 83 F7 }
+ $hash_ntfreevirtualmemory = { 09 C6 02 28 }
+ $hash_ntunmapviewofsection = { CD 12 A4 6A }
+ $hash_ntwritevirtualmemory = { 92 01 17 C3 }
+ $hash_ntsetinformationvirtualmemory = { 39 C2 6A 94 }
+ $hash_ntqueryvirtualmemory = { 5D E8 C0 10 }
+ $hash_ntopenprocesstoken = { 99 CA 0D 35 }
+ $hash_ntopenthreadtoken = { D2 47 33 80 }
condition:
- 2 of ($a*) or 6 of ($b*)
+ $commands_table and 4 of ($hash_*)
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_5B4383Ec : FILE MEMORY
+rule ELASTIC_Multi_Trojan_Merlin_32643F4C : FILE MEMORY
{
meta:
- description = "Identifies Portscan module from Cobalt Strike"
+ description = "Detects Multi Trojan Merlin (Multi.Trojan.Merlin)"
author = "Elastic Security"
- id = "5b4383ec-3c93-4e91-850e-d43cc3a86710"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "32643f4c-ee47-4ed2-9807-7b85d3f4e095"
+ date = "2024-03-01"
+ modified = "2024-05-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L362-L392"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "033bd831209958674f6309739d65c58d05acb9d17e53cede1cf171c6d6e84efa"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Multi_Trojan_Merlin.yar#L1-L28"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "84b988c4656677bc021e23df2a81258212d9ceba13be204867ac1d9d706404e2"
+ logic_hash = "7de2deec0e2c7fd3ce2b42762f88bfe87cb4ffb02b697953aa1716425d6f1612"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "283d3d2924e92b31f26ec4fc6b79c51bd652fb1377b6985b003f09f8c3dba66c"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "bce277ef43c67be52b67c4495652e99d4707975c79cb30b54283db56545278ae"
severity = 100
- arch_context = "x86"
+ arch_context = "x86, arm64"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "multi"
strings:
- $a1 = "portscan.x64.dll" ascii fullword
- $a2 = "portscan.dll" ascii fullword
- $a3 = "\\\\.\\pipe\\portscan" ascii fullword
- $b1 = "(ICMP) Target '%s' is alive. [read %d bytes]" ascii fullword
- $b2 = "(ARP) Target '%s' is alive. " ascii fullword
- $b3 = "TARGETS!12345" ascii fullword
- $b4 = "ReflectiveLoader" ascii fullword
- $b5 = "%s:%d (platform: %d version: %d.%d name: %S domain: %S)" ascii fullword
- $b6 = "Scanner module is complete" ascii fullword
- $b7 = "pingpong" ascii fullword
- $b8 = "PORTS!12345" ascii fullword
- $b9 = "%s:%d (%s)" ascii fullword
- $b10 = "PREFERENCES!12345" ascii fullword
+ $a1 = "json:\"killdate,omitempty\""
+ $a2 = "json:\"maxretry,omitempty\""
+ $a3 = "json:\"waittime,omitempty\""
+ $a4 = "json:\"payload,omitempty\""
+ $a5 = "json:\"skew,omitempty\""
+ $a6 = "json:\"command\""
+ $a7 = "json:\"pid,omitempty\""
+ $b1 = "/merlin-agent/commands"
+ $b2 = "/merlin/pkg/jobs"
+ $b3 = "github.com/Ne0nd0g/merlin"
condition:
- 2 of ($a*) or 6 of ($b*)
+ all of ($a*) or all of ($b*)
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_91E08059 : FILE MEMORY
+rule ELASTIC_Windows_Hacktool_Ringq_B9715540 : FILE MEMORY
{
meta:
- description = "Identifies Post Ex module from Cobalt Strike"
+ description = "Detects Windows Hacktool Ringq (Windows.Hacktool.RingQ)"
author = "Elastic Security"
- id = "91e08059-46a8-47d0-91c9-e86874951a4a"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "b9715540-77ae-4723-a29e-d4d88d626982"
+ date = "2024-06-28"
+ modified = "2024-07-26"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L394-L421"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "d5a8c1a0baa5e915cff29bcac33e30a7d7260f938ecaa6171d3aa88425a69266"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_RingQ.yar#L1-L25"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "450e01c32618cd4e4a327147896352ed1b34dca9fb28389dba450acf95f8b735"
+ logic_hash = "80d693c43a7026d28121e035ae875689512fd46d7f06c3f469b83d6fe707f36b"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "d8baacb58a3db00489827275ad6a2d007c018eaecbce469356b068d8a758634b"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "f2a2d97b31cb648a6515dbf02a885a6afd434f38ed555c1e30296b7eb4550438"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -65011,116 +69052,63 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_91E08059 : FILE MEMORY
os = "windows"
strings:
- $a1 = "postex.x64.dll" ascii fullword
- $a2 = "postex.dll" ascii fullword
- $a3 = "RunAsAdminCMSTP" ascii fullword
- $a4 = "KerberosTicketPurge" ascii fullword
- $b1 = "GetSystem" ascii fullword
- $b2 = "HelloWorld" ascii fullword
- $b3 = "KerberosTicketUse" ascii fullword
- $b4 = "SpawnAsAdmin" ascii fullword
- $b5 = "RunAsAdmin" ascii fullword
- $b6 = "NetDomain" ascii fullword
+ $a1 = "Loading Dir main.txt ..." ascii fullword
+ $a2 = "Loading LocalFile ..." ascii fullword
+ $a3 = "No Find main,txt and StringTable ..." ascii fullword
+ $a4 = "https://github.com/T4y1oR/RingQ"
+ $a5 = "RingQ :)" ascii fullword
+ $a6 = "1. Create.exe fscan.exe" ascii fullword
+ $a7 = "C:/Users/username/Documents/file.txt" ascii fullword
condition:
- 2 of ($a*) or 4 of ($b*)
+ 2 of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_Ee756Db7 : FILE MEMORY
+rule ELASTIC_Macos_Trojan_Generic_A829D361 : FILE MEMORY
{
meta:
- description = "Attempts to detect Cobalt Strike based on strings found in BEACON"
+ description = "Detects Macos Trojan Generic (MacOS.Trojan.Generic)"
author = "Elastic Security"
- id = "ee756db7-e177-41f0-af99-c44646d334f7"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "a829d361-ac57-4615-b8e9-16089c44d7af"
+ date = "2021-10-05"
+ modified = "2021-10-25"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L423-L491"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "8d594aa1b889e80000cfcedbfc470a1b768bdcc2a9c436cd449b495c91011918"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Generic.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "5b2a1cd801ae68a890b40dbd1601cdfeb5085574637ae8658417d0975be8acb5"
+ logic_hash = "70a954e8b44b1ce46f5ce0ebcf43b46e1292f0b8cdb46aa67f980d3c9b0a6f61"
score = 75
- quality = 50
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "e589cc259644bc75d6c4db02a624c978e855201cf851c0d87f0d54685ce68f71"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "5dba43dbc5f4d5ee295e65d66dd4e7adbdb7953232faf630b602e6d093f69584"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "macos"
strings:
- $a1 = "%s.4%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%x%x.%s" ascii fullword
- $a2 = "%s.3%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%x%x.%s" ascii fullword
- $a3 = "ppid %d is in a different desktop session (spawned jobs may fail). Use 'ppid' to reset." ascii fullword
- $a4 = "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/'); %s" ascii fullword
- $a5 = "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/')" ascii fullword
- $a6 = "%s.2%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%x%x.%s" ascii fullword
- $a7 = "could not run command (w/ token) because of its length of %d bytes!" ascii fullword
- $a8 = "%s.2%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x.%x%x.%s" ascii fullword
- $a9 = "%s.2%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x.%x%x.%s" ascii fullword
- $a10 = "powershell -nop -exec bypass -EncodedCommand \"%s\"" ascii fullword
- $a11 = "Could not open service control manager on %s: %d" ascii fullword
- $a12 = "%d is an x64 process (can't inject x86 content)" ascii fullword
- $a13 = "%d is an x86 process (can't inject x64 content)" ascii fullword
- $a14 = "Failed to impersonate logged on user %d (%u)" ascii fullword
- $a15 = "could not create remote thread in %d: %d" ascii fullword
- $a16 = "%s.1%08x%08x%08x%08x%08x%08x%08x.%x%x.%s" ascii fullword
- $a17 = "could not write to process memory: %d" ascii fullword
- $a18 = "Could not create service %s on %s: %d" ascii fullword
- $a19 = "Could not delete service %s on %s: %d" ascii fullword
- $a20 = "Could not open process token: %d (%u)" ascii fullword
- $a21 = "%s.1%08x%08x%08x%08x%08x%08x.%x%x.%s" ascii fullword
- $a22 = "Could not start service %s on %s: %d" ascii fullword
- $a23 = "Could not query service %s on %s: %d" ascii fullword
- $a24 = "Could not connect to pipe (%s): %d" ascii fullword
- $a25 = "%s.1%08x%08x%08x%08x%08x.%x%x.%s" ascii fullword
- $a26 = "could not spawn %s (token): %d" ascii fullword
- $a27 = "could not open process %d: %d" ascii fullword
- $a28 = "could not run %s as %s\\%s: %d" ascii fullword
- $a29 = "%s.1%08x%08x%08x%08x.%x%x.%s" ascii fullword
- $a30 = "kerberos ticket use failed:" ascii fullword
- $a31 = "Started service %s on %s" ascii fullword
- $a32 = "%s.1%08x%08x%08x.%x%x.%s" ascii fullword
- $a33 = "I'm already in SMB mode" ascii fullword
- $a34 = "could not spawn %s: %d" ascii fullword
- $a35 = "could not open %s: %d" ascii fullword
- $a36 = "%s.1%08x%08x.%x%x.%s" ascii fullword
- $a37 = "Could not open '%s'" ascii fullword
- $a38 = "%s.1%08x.%x%x.%s" ascii fullword
- $a39 = "%s as %s\\%s: %d" ascii fullword
- $a40 = "%s.1%x.%x%x.%s" ascii fullword
- $a41 = "beacon.x64.dll" ascii fullword
- $a42 = "%s on %s: %d" ascii fullword
- $a43 = "www6.%x%x.%s" ascii fullword
- $a44 = "cdn.%x%x.%s" ascii fullword
- $a45 = "api.%x%x.%s" ascii fullword
- $a46 = "%s (admin)" ascii fullword
- $a47 = "beacon.dll" ascii fullword
- $a48 = "%s%s: %s" ascii fullword
- $a49 = "@%d.%s" ascii fullword
- $a50 = "%02d/%02d/%02d %02d:%02d:%02d" ascii fullword
- $a51 = "Content-Length: %d" ascii fullword
+ $a = { E7 81 6A 12 EA A8 56 6C 86 94 ED F6 E8 D7 35 E1 EC 65 47 BA 8E 46 2C A6 14 5F }
condition:
- 6 of ($a*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_9C0D5561 : FILE MEMORY
+rule ELASTIC_Windows_Exploit_CVE_2022_38028_31Fdb122 : FILE MEMORY CVE_2022_38028
{
meta:
- description = "Identifies PowerShell Runner module from Cobalt Strike"
+ description = "Detects Windows Exploit Cve 2022 38028 (Windows.Exploit.CVE-2022-38028)"
author = "Elastic Security"
- id = "9c0d5561-5b09-44ae-8e8c-336dee606199"
- date = "2021-03-23"
- modified = "2021-10-04"
+ id = "31fdb122-36fd-4fae-b605-542dc344575c"
+ date = "2024-06-06"
+ modified = "2024-06-12"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L493-L523"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "a8929266950e0f540a68c4fedf708e8ddc27f208f9f2866245ad7bb7f6d87913"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Exploit_CVE_2022_38028.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "6b311c0a977d21e772ac4e99762234da852bbf84293386fbe78622a96c0b052f"
+ logic_hash = "df0ef11ce8e840c331d1db8f98917367dc2a33b6f1be48adb9d0b86729ecbe99"
score = 75
- quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "01d53fcdb320f0cd468a2521c3e96dcb0b9aa00e7a7a9442069773c6b3759059"
- threat_name = "Windows.Trojan.CobaltStrike"
+ quality = 73
+ tags = "FILE, MEMORY, CVE-2022-38028"
+ fingerprint = "e489287412ee673f4d93c5efc9e61b5d26d877bb0f4ddf827926b4d5d87dc399"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -65128,344 +69116,234 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_9C0D5561 : FILE MEMORY
os = "windows"
strings:
- $a1 = "PowerShellRunner.dll" wide fullword
- $a2 = "powershell.x64.dll" ascii fullword
- $a3 = "powershell.dll" ascii fullword
- $a4 = "\\\\.\\pipe\\powershell" ascii fullword
- $b1 = "PowerShellRunner.PowerShellRunner" ascii fullword
- $b2 = "Failed to invoke GetOutput w/hr 0x%08lx" ascii fullword
- $b3 = "Failed to get default AppDomain w/hr 0x%08lx" ascii fullword
- $b4 = "ICLRMetaHost::GetRuntime (v4.0.30319) failed w/hr 0x%08lx" ascii fullword
- $b5 = "CustomPSHostUserInterface" ascii fullword
- $b6 = "RuntimeClrHost::GetCurrentAppDomainId failed w/hr 0x%08lx" ascii fullword
- $b7 = "ICorRuntimeHost::GetDefaultDomain failed w/hr 0x%08lx" ascii fullword
- $c1 = { 8B 08 50 FF 51 08 8B 7C 24 1C 8D 4C 24 10 51 C7 }
- $c2 = "z:\\devcenter\\aggressor\\external\\PowerShellRunner\\obj\\Release\\PowerShellRunner.pdb" ascii fullword
+ $a = { 70 72 69 6E 74 54 69 63 6B 65 74 2E 58 6D 6C 4E 6F 64 65 2E 6C 6F 61 64 28 27 25 53 3A 2F 2F 67 6F 27 29 3B }
condition:
- (1 of ($a*) and 4 of ($b*)) or 1 of ($c*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_59Ed9124 : FILE MEMORY
+rule ELASTIC_Linux_Trojan_Masan_5369C678 : FILE MEMORY
{
meta:
- description = "Identifies PsExec module from Cobalt Strike"
+ description = "Detects Linux Trojan Masan (Linux.Trojan.Masan)"
author = "Elastic Security"
- id = "59ed9124-bc20-4ea6-b0a7-63ee3359e69c"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "5369c678-9a74-42fe-a4b3-b4d48126bb22"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L525-L560"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "a50fd291f5f1bf7ec41b1938a32473a23c3c082018b86eab87aff0d95b26ba06"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Masan.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "f2de9f39ca3910d5b383c245d8ca3c1bdf98e2309553599e0283062e0aeff17f"
+ logic_hash = "e57b105004216a6054b0561b69cce00c35255c5bd33aa8e403d0a3967cd0697e"
score = 75
- quality = 43
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "7823e3b98e55a83bf94b0f07e4c116dbbda35adc09fa0b367f8a978a80c2efff"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "5fd243bf05cafd7db33d6c0167f77148ae53983906e917e174978130ae08062a"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\psexec_command.x64.o" ascii fullword
- $a2 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\psexec_command.x86.o" ascii fullword
- $b1 = "__imp_BeaconDataExtract" ascii fullword
- $b2 = "__imp_BeaconDataParse" ascii fullword
- $b3 = "__imp_BeaconDataParse" ascii fullword
- $b4 = "__imp_BeaconDataParse" ascii fullword
- $b5 = "__imp_ADVAPI32$StartServiceA" ascii fullword
- $b6 = "__imp_ADVAPI32$DeleteService" ascii fullword
- $b7 = "__imp_ADVAPI32$QueryServiceStatus" ascii fullword
- $b8 = "__imp_ADVAPI32$CloseServiceHandle" ascii fullword
- $c1 = "__imp__BeaconDataExtract" ascii fullword
- $c2 = "__imp__BeaconDataParse" ascii fullword
- $c3 = "__imp__BeaconDataParse" ascii fullword
- $c4 = "__imp__BeaconDataParse" ascii fullword
- $c5 = "__imp__ADVAPI32$StartServiceA" ascii fullword
- $c6 = "__imp__ADVAPI32$DeleteService" ascii fullword
- $c7 = "__imp__ADVAPI32$QueryServiceStatus" ascii fullword
- $c8 = "__imp__ADVAPI32$CloseServiceHandle" ascii fullword
+ $a = { 89 C0 89 45 E4 83 7D E4 FF 75 ?? 68 ?? 90 04 08 }
condition:
- 1 of ($a*) or 5 of ($b*) or 5 of ($c*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_8A791Eb7 : FILE MEMORY
+rule ELASTIC_Macos_Trojan_Thiefquest_9130C0F3 : FILE MEMORY
{
meta:
- description = "Identifies Registry module from Cobalt Strike"
+ description = "Detects Macos Trojan Thiefquest (MacOS.Trojan.Thiefquest)"
author = "Elastic Security"
- id = "8a791eb7-dc0c-4150-9e5b-2dc21af0c77d"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "9130c0f3-5926-4153-87d8-85a591eed929"
+ date = "2021-09-30"
+ modified = "2021-10-25"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L562-L597"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "d1765e6cac9b1560d6484baa1fa5a1bc0b768a72b389c7c6a60e34115669933e"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Thiefquest.yar#L1-L22"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "bed3561210e44c290cd410adadcdc58462816a03c15d20b5be45d227cd7dca6b"
+ logic_hash = "20e9ea15a437a17c4ef68f2472186f6d1ab3118d5b392f84fcb2bd376ec3863a"
score = 75
- quality = 43
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "4967886ba5e663f2e2dc0631939308d7d8f2194a30590a230973e1b91bd625e1"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "38916235c68a329eea6d41dbfba466367ecc9aad2b8ae324da682a9970ec4930"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "macos"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\registry.x64.o" ascii fullword
- $a2 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\registry.x86.o" ascii fullword
- $b1 = "__imp_ADVAPI32$RegOpenKeyExA" ascii fullword
- $b2 = "__imp_ADVAPI32$RegEnumKeyA" ascii fullword
- $b3 = "__imp_ADVAPI32$RegOpenCurrentUser" ascii fullword
- $b4 = "__imp_ADVAPI32$RegCloseKey" ascii fullword
- $b5 = "__imp_BeaconFormatAlloc" ascii fullword
- $b6 = "__imp_BeaconOutput" ascii fullword
- $b7 = "__imp_BeaconFormatFree" ascii fullword
- $b8 = "__imp_BeaconDataPtr" ascii fullword
- $c1 = "__imp__ADVAPI32$RegOpenKeyExA" ascii fullword
- $c2 = "__imp__ADVAPI32$RegEnumKeyA" ascii fullword
- $c3 = "__imp__ADVAPI32$RegOpenCurrentUser" ascii fullword
- $c4 = "__imp__ADVAPI32$RegCloseKey" ascii fullword
- $c5 = "__imp__BeaconFormatAlloc" ascii fullword
- $c6 = "__imp__BeaconOutput" ascii fullword
- $c7 = "__imp__BeaconFormatFree" ascii fullword
- $c8 = "__imp__BeaconDataPtr" ascii fullword
+ $a1 = "heck_if_targeted" ascii fullword
+ $a2 = "check_command" ascii fullword
+ $a3 = "askroot" ascii fullword
+ $a4 = "iv_rescue_data" ascii fullword
condition:
- 1 of ($a*) or 5 of ($b*) or 5 of ($c*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_D00573A3 : FILE MEMORY
+rule ELASTIC_Macos_Trojan_Thiefquest_Fc2E1271 : FILE MEMORY
{
meta:
- description = "Identifies Screenshot module from Cobalt Strike"
+ description = "Detects Macos Trojan Thiefquest (MacOS.Trojan.Thiefquest)"
author = "Elastic Security"
- id = "d00573a3-db26-4e6b-aabf-7af4a818f383"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "fc2e1271-3c96-4c93-9e3d-212782928e6e"
+ date = "2021-10-05"
+ modified = "2021-10-25"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L599-L625"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "e458d41d28b76c989af6385f183f33aa9e11b93e529f032e95bd75433b80bd69"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Thiefquest.yar#L24-L42"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "12fb0eca3903a3b39ecc3c2aa6c04fe5faa1f43a3d271154d14731d1eb196923"
+ logic_hash = "a20c76e53874fc0fec5fd2660c63c6f1e7c1b2055cbd2a9efdfd114cd6bdda5c"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "b6fa0792b99ea55f359858d225685647f54b55caabe53f58b413083b8ad60e79"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "195e8f65e4ea722f0e1ba171f2ad4ded97d4bc97da38ef8ac8e54b8719e4c5ae"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "macos"
strings:
- $a1 = "screenshot.x64.dll" ascii fullword
- $a2 = "screenshot.dll" ascii fullword
- $a3 = "\\\\.\\pipe\\screenshot" ascii fullword
- $b1 = "1I1n1Q3M5Q5U5Y5]5a5e5i5u5{5" ascii fullword
- $b2 = "GetDesktopWindow" ascii fullword
- $b3 = "CreateCompatibleBitmap" ascii fullword
- $b4 = "GDI32.dll" ascii fullword
- $b5 = "ReflectiveLoader"
- $b6 = "Adobe APP14 marker: version %d, flags 0x%04x 0x%04x, transform %d" ascii fullword
+ $a = { 77 47 72 33 31 30 50 6D 72 7A 30 30 30 30 30 37 33 00 30 30 30 42 67 7B 30 30 }
condition:
- 2 of ($a*) or 5 of ($b*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_7Bcd759C : FILE MEMORY
+rule ELASTIC_Macos_Trojan_Thiefquest_86F9Ef0C : FILE MEMORY
{
meta:
- description = "Identifies SSH Agent module from Cobalt Strike"
+ description = "Detects Macos Trojan Thiefquest (MacOS.Trojan.Thiefquest)"
author = "Elastic Security"
- id = "7bcd759c-8e3d-4559-9381-1f4fe8b3dd95"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "86f9ef0c-832e-4e4a-bd39-c80c1d064dbe"
+ date = "2021-10-05"
+ modified = "2021-10-25"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L627-L648"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "bfbb8e8009182e87c49242ec3da6e98b23447b646f5c7ea5f97196ae929d7c5f"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Thiefquest.yar#L44-L62"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "59fb018e338908eb69be72ab11837baebf8d96cdb289757f1f4977228e7640a0"
+ logic_hash = "426d533d39e594123f742b15d0a93ded986b9b308685f7b2cfaf5de0b32cdbff"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "553085f1d1ca8dcd797360b287951845753eee7370610a1223c815a200a5ed20"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "e8849628ee5449c461f1170c07b6d2ebf4f75d48136f26b52bee9bcf4e164d5b"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "macos"
strings:
- $a1 = "sshagent.x64.dll" ascii fullword
- $a2 = "sshagent.dll" ascii fullword
- $b1 = "\\\\.\\pipe\\sshagent" ascii fullword
- $b2 = "\\\\.\\pipe\\PIPEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" ascii fullword
+ $a = { 6C 65 31 6A 6F 57 4E 33 30 30 30 30 30 33 33 00 30 72 7A 41 43 47 33 57 72 7C }
condition:
- 1 of ($a*) and 1 of ($b*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_A56B820F : FILE MEMORY
+rule ELASTIC_Macos_Trojan_Thiefquest_40F9C1C3 : FILE MEMORY
{
meta:
- description = "Identifies Timestomp module from Cobalt Strike"
+ description = "Detects Macos Trojan Thiefquest (MacOS.Trojan.Thiefquest)"
author = "Elastic Security"
- id = "a56b820f-0a20-4054-9c2d-008862646a78"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "40f9c1c3-29f8-4699-8f66-9b7ddb08f92d"
+ date = "2021-10-05"
+ modified = "2021-10-25"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L650-L685"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "52de8110727c29b0f5c75cd470ce6b80ba7821d0ba78ad074536323e2e80b460"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Thiefquest.yar#L64-L82"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "e402063ca317867de71e8e3189de67988e2be28d5d773bbaf75618202e80f9f6"
+ logic_hash = "546edc2d6d715eac47e7a8d3ceb91cf314fa6dbee04f0475a5c4a84ba53fd722"
score = 75
- quality = 43
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "5418e695bcb1c37e72a7ff24a39219dc12b3fe06c29cedefd500c5e82c362b6d"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "27ec200781541d5b1abc96ffbb54c428b773bffa0744551bbacd605c745b6657"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "macos"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\timestomp.x64.o" ascii fullword
- $a2 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\timestomp.x86.o" ascii fullword
- $b1 = "__imp_KERNEL32$GetFileTime" ascii fullword
- $b2 = "__imp_KERNEL32$SetFileTime" ascii fullword
- $b3 = "__imp_KERNEL32$CloseHandle" ascii fullword
- $b4 = "__imp_KERNEL32$CreateFileA" ascii fullword
- $b5 = "__imp_BeaconDataExtract" ascii fullword
- $b6 = "__imp_BeaconPrintf" ascii fullword
- $b7 = "__imp_BeaconDataParse" ascii fullword
- $b8 = "__imp_BeaconDataExtract" ascii fullword
- $c1 = "__imp__KERNEL32$GetFileTime" ascii fullword
- $c2 = "__imp__KERNEL32$SetFileTime" ascii fullword
- $c3 = "__imp__KERNEL32$CloseHandle" ascii fullword
- $c4 = "__imp__KERNEL32$CreateFileA" ascii fullword
- $c5 = "__imp__BeaconDataExtract" ascii fullword
- $c6 = "__imp__BeaconPrintf" ascii fullword
- $c7 = "__imp__BeaconDataParse" ascii fullword
- $c8 = "__imp__BeaconDataExtract" ascii fullword
+ $a = { 77 47 72 33 31 30 50 6D 72 7A 30 30 30 30 30 37 33 00 33 7C 49 56 7C 6A 30 30 }
condition:
- 1 of ($a*) or 5 of ($b*) or 5 of ($c*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_92F05172 : FILE MEMORY
+rule ELASTIC_Macos_Trojan_Thiefquest_0F9Fe37C : FILE MEMORY
{
meta:
- description = "Identifies UAC cmstp module from Cobalt Strike"
+ description = "Detects Macos Trojan Thiefquest (MacOS.Trojan.Thiefquest)"
author = "Elastic Security"
- id = "92f05172-f15c-4077-a958-b8490378bf08"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "0f9fe37c-77df-4d3d-be8a-c62ea0f6863c"
+ date = "2021-10-05"
+ modified = "2021-10-25"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L687-L716"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "7f0ff4ee14a043d72810826ab9d2b90b0f66724550ba9d3cdd2abe749f4874d0"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Thiefquest.yar#L84-L102"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "12fb0eca3903a3b39ecc3c2aa6c04fe5faa1f43a3d271154d14731d1eb196923"
+ logic_hash = "84f9e8938d7e2b0210003fc8334b8fa781a40afffeda8d2341970b84ed5d3b5a"
score = 75
- quality = 63
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "09b1f7087d45fb4247a33ae3112910bf5426ed750e1e8fe7ba24a9047b76cc82"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "2e809d95981f0ff813947f3be22ab3d3c000a0d348131d5d6c8522447818196d"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "macos"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\uaccmstp.x64.o" ascii fullword
- $a2 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\uaccmstp.x86.o" ascii fullword
- $b1 = "elevate_cmstp" ascii fullword
- $b2 = "$pdata$elevate_cmstp" ascii fullword
- $b3 = "$unwind$elevate_cmstp" ascii fullword
- $c1 = "_elevate_cmstp" ascii fullword
- $c2 = "__imp__OLE32$CoGetObject@16" ascii fullword
- $c3 = "__imp__KERNEL32$GetModuleFileNameA@12" ascii fullword
- $c4 = "__imp__KERNEL32$GetSystemWindowsDirectoryA@8" ascii fullword
- $c5 = "OLDNAMES"
- $c6 = "__imp__BeaconDataParse" ascii fullword
- $c7 = "_willAutoElevate" ascii fullword
+ $a = { 77 47 72 33 31 30 50 6D 72 7A 30 30 30 30 30 37 33 00 33 71 6B 6E 6C 55 30 55 }
condition:
- 1 of ($a*) or 3 of ($b*) or 4 of ($c*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_417239B5 : FILE MEMORY
+rule ELASTIC_Macos_Trojan_Thiefquest_1F4Bac78 : FILE MEMORY
{
meta:
- description = "Identifies UAC token module from Cobalt Strike"
+ description = "Detects Macos Trojan Thiefquest (MacOS.Trojan.Thiefquest)"
author = "Elastic Security"
- id = "417239b5-cf2d-4c85-a022-7a8459c26793"
- date = "2021-03-23"
- modified = "2021-08-23"
+ id = "1f4bac78-ef2b-49cd-8852-e84d792f6e57"
+ date = "2021-10-05"
+ modified = "2021-10-25"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L718-L764"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "fda252747359e677459d82d65c4c9c8f2ff80bc8fd6a38712f858039f3cb8dd1"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/MacOS_Trojan_Thiefquest.yar#L104-L122"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "12fb0eca3903a3b39ecc3c2aa6c04fe5faa1f43a3d271154d14731d1eb196923"
+ logic_hash = "96db33e135138846f978026867bb2536226539997d060f41e7081f7f29b66c85"
score = 75
- quality = 51
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "292afee829e838f9623547f94d0561e8a9115ce7f4c40ae96c6493f3cc5ffa9b"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "e7d1e2009ff9b33d2d237068e2af41a8aa9bd44a446a2840c34955594f060120"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "macos"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\uactoken.x64.o" ascii fullword
- $a2 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\uactoken.x86.o" ascii fullword
- $a3 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\uactoken2.x64.o" ascii fullword
- $a4 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\uactoken2.x86.o" ascii fullword
- $b1 = "$pdata$is_admin_already" ascii fullword
- $b2 = "$unwind$is_admin" ascii fullword
- $b3 = "$pdata$is_admin" ascii fullword
- $b4 = "$unwind$is_admin_already" ascii fullword
- $b5 = "$pdata$RunAsAdmin" ascii fullword
- $b6 = "$unwind$RunAsAdmin" ascii fullword
- $b7 = "is_admin_already" ascii fullword
- $b8 = "is_admin" ascii fullword
- $b9 = "process_walk" ascii fullword
- $b10 = "get_current_sess" ascii fullword
- $b11 = "elevate_try" ascii fullword
- $b12 = "RunAsAdmin" ascii fullword
- $b13 = "is_ctfmon" ascii fullword
- $c1 = "_is_admin_already" ascii fullword
- $c2 = "_is_admin" ascii fullword
- $c3 = "_process_walk" ascii fullword
- $c4 = "_get_current_sess" ascii fullword
- $c5 = "_elevate_try" ascii fullword
- $c6 = "_RunAsAdmin" ascii fullword
- $c7 = "_is_ctfmon" ascii fullword
- $c8 = "_reg_query_dword" ascii fullword
- $c9 = ".drectve" ascii fullword
- $c10 = "_is_candidate" ascii fullword
- $c11 = "_SpawnAsAdmin" ascii fullword
- $c12 = "_SpawnAsAdminX64" ascii fullword
+ $a = { 77 47 72 33 31 30 50 6D 72 7A 30 30 30 30 30 37 33 00 32 33 4F 65 49 66 31 68 }
condition:
- 1 of ($a*) or 9 of ($b*) or 7 of ($c*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_29374056 : FILE MEMORY
+rule ELASTIC_Windows_Backdoor_Teamviewer_Df8E7326 : FILE MEMORY
{
meta:
- description = "Identifies Cobalt Strike MZ Reflective Loader."
+ description = "Detects Windows Backdoor Teamviewer (Windows.Backdoor.TeamViewer)"
author = "Elastic Security"
- id = "29374056-03ce-484b-8b2d-fbf75be86e27"
- date = "2021-03-23"
- modified = "2021-08-23"
- reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L766-L785"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "09755b23a7057c70f3ea242ec48549de65ebc6f13bdc38cbe22d6d758c3718cf"
+ id = "df8e7326-5879-48d7-8a5f-1c9a2d8b7f8d"
+ date = "2022-10-29"
+ modified = "2022-12-20"
+ reference = "https://vms.drweb.com/virus/?i=8172096"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Backdoor_TeamViewer.yar#L1-L25"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "68d9ffb6e00c2694d0d827108d0410d5a66d4f8cf839afddd17c5887b0149350"
+ logic_hash = "3d42c76626c76959e450a81001c73d8d47b52789cab324e0cc7af09303c1367d"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "4cd7552a499687ac0279fb2e25722f979fc5a22afd1ea4abba14a2ef2002dd0f"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "0f2406e98fa1383e39672bd4ec32a111363f7d33f8bc33c2bd7ea36353faab45"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -65473,29 +69351,33 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_29374056 : FILE MEMORY
os = "windows"
strings:
- $a1 = { 4D 5A 41 52 55 48 89 E5 48 81 EC 20 00 00 00 48 8D 1D ?? FF FF FF 48 81 C3 ?? ?? 00 00 FF D3 }
- $a2 = { 4D 5A E8 00 00 00 00 5B 89 DF 52 45 55 89 E5 }
+ $a1 = "m%c%c%c%c%c%c.com" ascii fullword
+ $a2 = "client_id=%.8x&connected=%d&server_port=%d&debug=%d&os=%d.%d.%04d&dgt=%d&dti=%d" ascii fullword
+ $a3 = "\\save.dat" ascii fullword
+ $a4 = "auth_ip" ascii fullword
+ $a5 = "updips" ascii fullword
+ $b1 = { 55 8B EC 56 E8 BF 25 00 00 50 E8 7B 5B 00 00 8B F0 59 85 F6 75 2C 8B 75 08 56 E8 A9 25 00 00 50 }
condition:
- 1 of ($a*)
+ 5 of ($a*) or 1 of ($b*)
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_949F10E3 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Nighthawk_9F3A5Abb : FILE MEMORY
{
meta:
- description = "Identifies the API address lookup function used by Cobalt Strike along with XOR implementation by Cobalt Strike."
+ description = "Detects Windows Trojan Nighthawk (Windows.Trojan.Nighthawk)"
author = "Elastic Security"
- id = "949f10e3-68c9-4600-a620-ed3119e09257"
- date = "2021-03-25"
- modified = "2021-08-23"
+ id = "9f3a5abb-b329-44db-af71-d72eae2737ac"
+ date = "2022-11-24"
+ modified = "2023-06-20"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L787-L806"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "e4b726c83013f4b9c9d61683f78a4a91935225e9ed3de0ce164b96b5a6719579"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Nighthawk.yar#L1-L26"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "b775a8f7629966592cc7727e2081924a7d7cf83edd7447aa60627a2b67d87c94"
+ logic_hash = "27a34e48141fe260c16c12a2652e440d2540ca5f0c84b41c9c4762dcab44ffd4"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "34e04901126a91c866ebf61a61ccbc3ce0477d9614479c42d8ce97a98f2ce2a7"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "a2c49831d048ba91951780f4295895eba3a15f489a39b26b7a27efbc81746e09"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -65503,59 +69385,65 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_949F10E3 : FILE MEMORY
os = "windows"
strings:
- $a1 = { 89 E5 31 D2 64 8B 52 30 8B 52 0C 8B 52 14 8B 72 28 0F B7 4A 26 31 FF 31 C0 AC 3C 61 }
- $a2 = { 8B 07 01 C3 85 C0 75 E5 58 C3 E8 [2] FF FF 31 39 32 2E 31 36 38 2E ?? 2E }
+ $loader_build_iat0 = { B9 BF BF D1 D5 E8 ?? ?? ?? ?? BA 7C 75 84 91 [3-12] E8 ?? ?? ?? ?? BA 47 FB EB 2B [3-12] E8 ?? ?? ?? ?? BA 42 24 3D 39 [3-12] E8 ?? ?? ?? ?? BA E7 E9 EF EE [3-12] E8 ?? ?? ?? ?? BA 47 FD 36 2E [3-12] E8 ?? ?? ?? ?? BA 39 DE 19 3D [3-12] E8 ?? ?? ?? ?? BA 20 DF DB F7 [3-12] E8 ?? ?? ?? ?? BA 45 34 2A 41 [3-12] E8 ?? ?? ?? ?? BA 7D 1C 44 2E [3-12] E8 ?? ?? ?? ?? BA 7D 28 44 2E [3-12] E8 ?? ?? ?? ?? BA 94 36 65 8D [3-12] E8 ?? ?? ?? ?? }
+ $loader_syscall_func = { 65 48 8B 04 25 30 00 00 00 48 8B 80 10 01 00 00 48 89 44 24 F0 65 48 8B 04 25 30 00 00 00 8B 40 68 49 89 CA FF 64 24 F0 }
+ $seq_calc_offset = { 48 8D 0D ?? ?? ?? ?? 51 5A 48 81 C1 ?? ?? ?? ?? 48 81 C2 ?? ?? ?? ?? FF E2 }
+ $seq_keying_registry = { BA ?? ?? ?? ?? 48 8B C8 48 8B D8 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8B CB 4C 8B F0 E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8B CB 4C 8B F8 E8 ?? ?? ?? ?? 0F B6 4E ?? 48 8B D8 83 E9 ?? 74 ?? 83 F9 ?? 75 ?? 48 C7 C1 ?? ?? ?? ?? EB ?? }
+ $seq_keying_hostname_user = { 40 53 48 83 EC ?? 8A 42 ?? 48 8B D9 3C ?? 75 ?? B9 ?? ?? ?? ?? E8 ?? ?? ?? ?? BA ?? ?? ?? ?? 48 8B C8 E8 ?? ?? ?? ?? 48 8D 53 ?? 48 8D 4B ?? C7 02 ?? ?? ?? ?? FF D0 85 C0 0F 95 C0 EB ?? }
+ $seq_keying_file = { E8 ?? ?? ?? ?? 33 DB 48 8D 4E ?? 48 89 5C 24 ?? 45 33 C9 89 5C 24 ?? BA ?? ?? ?? ?? 4C 8B E0 89 5C 24 ?? 44 8D 43 ?? C7 44 24 ?? ?? ?? ?? ?? FF D7 48 8B F8 48 83 F8 ?? 74 ?? 8B 55 ?? 45 33 C9 45 33 C0 48 8B C8 }
+ $seq_crypto_op = { 40 84 F6 74 ?? 48 8B C2 B9 04 00 00 00 F3 0F 6F 44 05 ?? F3 0F 6F 4C 05 ?? 48 8D 40 ?? 66 0F EF C8 F3 0F 7F 4C 05 ?? 48 83 E9 01 }
+ $seq_byte_shift = { 48 83 C3 ?? 8D 4D ?? 48 03 CF 0F B6 41 ?? 0F B6 71 ?? C1 E6 08 0B F0 0F B6 41 ?? C1 E6 08 0B F0 0F B6 01 C1 E6 ?? 0B F0 41 3B 75 ?? 76 ?? B8 ?? ?? ?? ?? EB ?? }
condition:
- all of them
+ ($loader_build_iat0 and $loader_syscall_func) or (2 of ($seq*))
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_8751Cdf9 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Nighthawk_2A2E3B9D : FILE MEMORY
{
meta:
- description = "Identifies Cobalt Strike wininet reverse shellcode along with XOR implementation by Cobalt Strike."
+ description = "Detects Windows Trojan Nighthawk (Windows.Trojan.Nighthawk)"
author = "Elastic Security"
- id = "8751cdf9-4038-42ba-a6eb-f8ac579a4fbb"
- date = "2021-03-25"
- modified = "2021-08-23"
+ id = "2a2e3b9d-e85f-43b6-9754-1aa7c9f6f978"
+ date = "2022-11-24"
+ modified = "2023-06-20"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L808-L827"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "64fae95fd89ad46a50a00c943cf98a997a0842a83be64b3728b25151867b75a8"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Nighthawk.yar#L28-L47"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "38881b87826f184cc91559555a3456ecf00128e01986a9df36a72d60fb179ccf"
+ logic_hash = "c42605ebba900fafb4ec2d34d93bb7adb69e731ce151b82a95889dd0d738da00"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "0988386ef4ba54dd90b0cf6d6a600b38db434e00e569d69d081919cdd3ea4d3f"
- threat_name = "Windows.Trojan.CobaltStrike"
- severity = 99
+ fingerprint = "40912e8d6bd09754046598b1311080e0ec6e040cb1b9ca93003c6314725d4d45"
+ severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
- $a1 = { 68 6E 65 74 00 68 77 69 6E 69 54 68 4C 77 26 07 }
- $a2 = { 8B 07 01 C3 85 C0 75 E5 58 C3 E8 [2] FF FF 31 39 32 2E 31 36 38 2E ?? 2E }
+ $payload_bytes1 = { 66 C1 E0 05 66 33 D0 66 C1 E2 0A 66 0B D1 0F B7 D2 8B CA 0F B7 C2 C1 E9 02 33 CA 66 D1 E8 D1 E9 33 CA C1 E9 02 33 CA C1 E2 0F 83 E1 01 }
+ $payload_bytes2 = { 48 8B D9 44 8B C2 41 C1 E0 0F 8B C2 F7 D0 48 8B F2 44 03 C0 41 8B C0 C1 E8 0C 41 33 C0 8D 04 80 8B C8 C1 E9 04 33 C8 44 69 C1 09 08 00 00 41 8B C0 C1 E8 10 44 33 C0 B8 85 1C A7 AA }
condition:
- all of them
+ any of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_663Fc95D : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Nighthawk_23489175 : FILE MEMORY
{
meta:
- description = "Identifies CobaltStrike via unidentified function code"
+ description = "Detects Windows Trojan Nighthawk (Windows.Trojan.Nighthawk)"
author = "Elastic Security"
- id = "663fc95d-2472-4d52-ad75-c5d86cfc885f"
- date = "2021-04-01"
- modified = "2021-12-17"
+ id = "23489175-ed41-4f43-ac85-b9ae3ffb55d9"
+ date = "2023-06-14"
+ modified = "2023-07-10"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L829-L847"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "842a0a372cfb2316293f4a08e1690194fa98368a9f6ffe9c63222b2c4ab6532c"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Nighthawk.yar#L49-L74"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "697742d5dd071add40b700022fd30424cb231ffde223d21bd83a44890e06762f"
+ logic_hash = "be41fc53f7098ca3cf718e8066a488196423ede993466c9a24ad2af387e03b24"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "d0f781d7e485a7ecfbbfd068601e72430d57ef80fc92a993033deb1ddcee5c48"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "3ff9fe5ef10afa328025a6abd509af788a9b1d5ef73a379e3767b2a4291566a3"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -65563,29 +69451,35 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_663Fc95D : FILE MEMORY
os = "windows"
strings:
- $a = { 48 89 5C 24 08 57 48 83 EC 20 48 8B 59 10 48 8B F9 48 8B 49 08 FF 17 33 D2 41 B8 00 80 00 00 }
+ $pdb = "C:\\Users\\Peter\\Desktop\\dev\\implant\\CommsChannel\\x64\\Release-ReflectiveDLL\\Implant.x64.pdb" ascii fullword
+ $seq_str_decrypt = { 48 8B C3 48 83 7B ?? ?? 72 ?? 48 8B 03 0F BE 14 06 49 8B CF E8 ?? ?? ?? ?? 48 85 C0 74 ?? 49 2B C7 48 8D 0D ?? ?? ?? ?? 8A 0C 08 48 8B C3 48 83 7B ?? ?? 72 ?? 48 8B 03 88 0C 06 }
+ $seq_hvnc = { BA 06 01 00 00 41 B9 00 00 20 A0 41 B8 20 00 00 00 48 8B CE FF 15 }
+ $seq_pe_parsing = { 8B 44 24 ?? 48 6B C0 28 48 8B 4C 24 ?? 8B 44 01 ?? 48 8B 8C 24 ?? ?? ?? ?? 48 03 C8 48 8B C1 48 89 44 24 ?? 8B 44 24 ?? 48 6B C0 28 48 8B 4C 24 ?? 8B 44 01 ?? 89 44 24 ?? EB ?? }
+ $seq_library_resolver = { 48 8B 84 24 ?? ?? ?? ?? 48 89 44 24 ?? 48 8B 44 24 ?? 48 63 40 ?? 48 8B 4C 24 ?? 48 03 C8 48 8B C1 48 89 44 24 ?? B8 ?? ?? ?? ?? 48 6B C0 ?? 48 8B 4C 24 ?? 8B 84 01 ?? ?? ?? ?? 89 44 24 ?? 83 7C 24 ?? ?? 75 ?? 33 C0 E9 ?? ?? ?? ?? }
+ $seq_disk_info = { 4C 8B A3 B0 00 00 00 48 8B BB A8 00 00 00 49 3B FC 0F 84 ?? ?? ?? ?? 48 8D B3 D8 00 00 00 4C 8D B3 F0 00 00 00 4C 8D BB C0 00 00 00 45 33 ED }
+ $seq_keyname = { 8B 4B 08 C1 E1 08 0B 4B 04 C1 E1 10 41 B8 40 00 00 00 48 8D 95 ?? ?? ?? ?? FF 15 ?? ?? ?? ?? }
+ $seq_tcptable = { 41 BF 02 00 00 00 41 3B FF 74 ?? 83 FF 17 41 8B C7 75 ?? B8 08 00 00 00 }
condition:
- all of them
+ (1 of ($pdb)) or (2 of ($seq*))
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_B54B94Ac : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Servhelper_F4Dee200 : FILE MEMORY
{
meta:
- description = "Rule for beacon sleep obfuscation routine"
+ description = "Detects Windows Trojan Servhelper (Windows.Trojan.ServHelper)"
author = "Elastic Security"
- id = "b54b94ac-6ef8-4ee9-a8a6-f7324c1974ca"
- date = "2021-10-21"
- modified = "2022-01-13"
+ id = "f4dee200-5471-472b-a017-bfcc9c291cbe"
+ date = "2022-03-22"
+ modified = "2022-04-12"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L849-L872"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "36d32b1ed967f07a4bd19f5e671294d5359009c04835601f2cc40fb8b54f6a2a"
- logic_hash = "6f63e4c31e55da2008f95e9d05391e40d44e2757c511e666032563ab798e274c"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_ServHelper.yar#L1-L20"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "05d183430a7afe16a3857fc4e87568fcc18518e108823c37eabf0514660aa17c"
+ logic_hash = "abab541ebddf36c05e351d506d4f978a30d8a44ff09233a667d62a1692dabe15"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "2344dd7820656f18cfb774a89d89f5ab65d46cc7761c1f16b7e768df66aa41c8"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "24e49a0c72e665a03cea66614481665eea962a0c6b0a2f9d459866d8070ab456"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -65593,33 +69487,29 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_B54B94Ac : FILE MEMORY
os = "windows"
strings:
- $a_x64 = { 4C 8B 53 08 45 8B 0A 45 8B 5A 04 4D 8D 52 08 45 85 C9 75 05 45 85 DB 74 33 45 3B CB 73 E6 49 8B F9 4C 8B 03 }
- $a_x64_smbtcp = { 4C 8B 07 B8 4F EC C4 4E 41 F7 E1 41 8B C1 C1 EA 02 41 FF C1 6B D2 0D 2B C2 8A 4C 38 10 42 30 0C 06 48 }
- $a_x86 = { 8B 46 04 8B 08 8B 50 04 83 C0 08 89 55 08 89 45 0C 85 C9 75 04 85 D2 74 23 3B CA 73 E6 8B 06 8D 3C 08 33 D2 }
- $a_x86_2 = { 8B 06 8D 3C 08 33 D2 6A 0D 8B C1 5B F7 F3 8A 44 32 08 30 07 41 3B 4D 08 72 E6 8B 45 FC EB C7 }
- $a_x86_smbtcp = { 8B 07 8D 34 08 33 D2 6A 0D 8B C1 5B F7 F3 8A 44 3A 08 30 06 41 3B 4D 08 72 E6 8B 45 FC EB }
+ $a = { 48 8B 45 78 48 63 4D 44 48 8B 55 48 4C 63 45 44 48 0F B7 44 48 FE 66 42 33 44 42 FE 66 89 45 42 48 8D 4D 28 48 0F B7 55 42 E8 ?? ?? ?? ?? 48 8B 4D 70 48 8B 55 28 E8 ?? ?? ?? ?? 83 45 44 01 83 EB 01 85 DB 75 ?? }
+ $b = { 39 5D ?? 0F 8F ?? ?? ?? ?? 2B D8 83 C3 01 48 8B 45 ?? 48 63 4D ?? 66 83 7C 48 ?? 20 72 ?? 48 8B 45 ?? 48 63 4D ?? 66 83 7C 48 ?? 7F 76 ?? 48 8B 45 ?? 48 63 4D ?? 48 0F B7 44 48 ?? 66 83 E8 08 66 83 F8 07 77 ?? B2 01 8B C8 80 E1 7F D3 E2 48 0F B6 05 ?? ?? ?? ?? 84 C2 0F 95 C0 EB ?? 33 C0 84 C0 74 ?? 83 45 ?? 01 }
condition:
any of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_F0B627Fc : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Servhelper_370C5287 : FILE MEMORY
{
meta:
- description = "Rule for beacon reflective loader"
+ description = "Detects Windows Trojan Servhelper (Windows.Trojan.ServHelper)"
author = "Elastic Security"
- id = "f0b627fc-97cd-42cb-9eae-1efb0672762d"
- date = "2021-10-21"
- modified = "2022-01-13"
+ id = "370c5287-0e2f-4113-95b6-53d31671fa46"
+ date = "2022-03-24"
+ modified = "2022-04-12"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L874-L897"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "b362951abd9d96d5ec15d281682fa1c8fe8f8e4e2f264ca86f6b061af607f79b"
- logic_hash = "1087294af3a9ef59c00098f5fd7adfe0b335525e135d95e45ac30e44c6739a72"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_ServHelper.yar#L22-L40"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "05d183430a7afe16a3857fc4e87568fcc18518e108823c37eabf0514660aa17c"
+ logic_hash = "8a2934c28efef6a5fed26dc88d074aee15b0869370c66f6a4d6eaedf070eaa9e"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "fbc94bedd50b5b943553dd438a183a1e763c098a385ac3a4fc9ff24ee30f91e1"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "a66134e9344cc5ba403fe0aad70e8a991c61582d6a5640c3b9e4a554374176a2"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -65627,33 +69517,28 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_F0B627Fc : FILE MEMORY
os = "windows"
strings:
- $beacon_loader_x64 = { 25 FF FF FF 00 3D 41 41 41 00 75 [5-10] 25 FF FF FF 00 3D 42 42 42 00 75 }
- $beacon_loader_x86 = { 25 FF FF FF 00 3D 41 41 41 00 75 [4-8] 81 E1 FF FF FF 00 81 F9 42 42 42 00 75 }
- $beacon_loader_x86_2 = { 81 E1 FF FF FF 00 81 F9 41 41 41 00 75 [4-8] 81 E2 FF FF FF 00 81 FA 42 42 42 00 75 }
- $generic_loader_x64 = { 89 44 24 20 48 8B 44 24 40 0F BE 00 8B 4C 24 20 03 C8 8B C1 89 44 24 20 48 8B 44 24 40 48 FF C0 }
- $generic_loader_x86 = { 83 C4 04 89 45 FC 8B 4D 08 0F BE 11 03 55 FC 89 55 FC 8B 45 08 83 C0 01 89 45 08 8B 4D 08 0F BE }
+ $a = { 00 10 66 01 00 48 66 01 00 98 07 2B 00 50 66 01 00 95 66 01 }
condition:
- any of them
+ all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_Dcdcdd8C : FILE MEMORY
+rule ELASTIC_Windows_Ransomware_Blackmatter_B548D151 : FILE MEMORY
{
meta:
- description = "Rule for beacon sleep PDB"
+ description = "Detects Windows Ransomware Blackmatter (Windows.Ransomware.Blackmatter)"
author = "Elastic Security"
- id = "dcdcdd8c-7395-4453-a74a-60ab8e251a5a"
- date = "2021-10-21"
- modified = "2022-01-13"
+ id = "b548d151-5dde-459b-9d4a-b4a48c1b5545"
+ date = "2021-08-03"
+ modified = "2021-10-04"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L899-L923"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "36d32b1ed967f07a4bd19f5e671294d5359009c04835601f2cc40fb8b54f6a2a"
- logic_hash = "f3ae07282b763d3720e45a84878cc457f65041f381951cdc9affd5e3ce67e6cc"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Blackmatter.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "072158f5588440e6c94cb419ae06a27cf584afe3b0cb09c28eff0b4662c15486"
+ logic_hash = "cf76a311de9d292a2ea09b3937b8eb7fd761b7c33a464a31acf6b9a5bf121959"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "8aed1ae470d06a7aac37896df22b2f915c36845099839a85009212d9051f71e9"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "351658f8fe3f9c956634e3cf7a03b272c55359f069c5200e948d817c6b554c87"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -65661,34 +69546,28 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_Dcdcdd8C : FILE MEMORY
os = "windows"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\sleepmask\\bin\\sleepmask.x64.o" ascii fullword
- $a2 = "Z:\\devcenter\\aggressor\\external\\sleepmask\\bin\\sleepmask.x86.o" ascii fullword
- $a3 = "Z:\\devcenter\\aggressor\\external\\sleepmask\\bin\\sleepmask_smb.x64.o" ascii fullword
- $a4 = "Z:\\devcenter\\aggressor\\external\\sleepmask\\bin\\sleepmask_smb.x86.o" ascii fullword
- $a5 = "Z:\\devcenter\\aggressor\\external\\sleepmask\\bin\\sleepmask_tcp.x64.o" ascii fullword
- $a6 = "Z:\\devcenter\\aggressor\\external\\sleepmask\\bin\\sleepmask_tcp.x86.o" ascii fullword
+ $a1 = { 93 F0 DA 07 E7 F0 DA 07 E0 5B 99 65 47 38 96 6C 75 91 65 46 5A D0 B0 25 DA 90 42 CE F1 73 10 B1 14 BD 3C EC FD 7C AF 9B 8D 86 89 A5 FF C0 3F 78 57 8E E2 AD 2E 3A 2F 74 79 B1 FE 27 69 6B 9F 97 CE C8 67 88 1A 0B 01 F1 B7 76 35 18 E8 FF E1 D7 66 8C 41 03 EB F8 64 E5 7E F1 06 73 AB BF 6B 1D 6A B9 B6 BA 41 A2 91 49 5E 85 51 A0 83 23 46 D6 E0 E5 0F C2 53 89 2A 35 94 AF FC 87 A0 D8 08 E7 B8 DB 08 E7 78 22 E5 7E AE BB EF 16 87 08 3C 47 F0 49 1E 0D 2D 9A 1B 55 54 05 14 69 A3 1B 9C 7A 97 7B CF 85 2B 09 F9 DC 2C EB A6 55 F1 A0 07 B4 AA 80 EA ED 26 87 C0 }
condition:
any of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_A3Fb2616 : FILE MEMORY
+rule ELASTIC_Windows_Ransomware_Blackmatter_8394F6D5 : FILE MEMORY
{
meta:
- description = "Rule for browser pivot "
+ description = "Detects Windows Ransomware Blackmatter (Windows.Ransomware.Blackmatter)"
author = "Elastic Security"
- id = "a3fb2616-b03d-4399-9342-0fc684fb472e"
- date = "2021-10-21"
- modified = "2022-01-13"
+ id = "8394f6d5-4761-4df6-974d-eaa0a25353da"
+ date = "2021-08-03"
+ modified = "2021-10-04"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L925-L947"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "36d32b1ed967f07a4bd19f5e671294d5359009c04835601f2cc40fb8b54f6a2a"
- logic_hash = "a3c36326ccc2bc828f6654ccaba507a283f92146fdc52f71d7d934f6908793e2"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Ransomware_Blackmatter.yar#L21-L39"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "072158f5588440e6c94cb419ae06a27cf584afe3b0cb09c28eff0b4662c15486"
+ logic_hash = "50a9b65ca6dde4fc32d2d57e72042f4380dd6c263ec5c33ce7c158151b91a5ae"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "c15cf6aa7719dac6ed21c10117f28eb4ec56335f80a811b11ab2901ad36f8cf0"
- threat_name = "Windows.Trojan.CobaltStrike"
+ fingerprint = "3825f59ffe9b2adc1f9dd175f4d57c9aa3dd6ff176616ecbe7c673b5b4d414f8"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -65696,155 +69575,144 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_A3Fb2616 : FILE MEMORY
os = "windows"
strings:
- $a1 = "browserpivot.dll" ascii fullword
- $a2 = "browserpivot.x64.dll" ascii fullword
- $b1 = "$$$THREAD.C$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$" ascii fullword
- $b2 = "COBALTSTRIKE" ascii fullword
+ $a1 = { FF E1 D7 66 8C 41 03 EB F8 64 E5 7E F1 06 73 AB BF 6B 1D 6A B9 B6 BA 41 A2 91 49 5E 85 51 A0 83 23 }
condition:
- 1 of ($a*) and 2 of ($b*)
+ any of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_8Ee55Ee5 : FILE MEMORY
+rule ELASTIC_Windows_Hacktool_Netfilter_E8243Dae : FILE
{
meta:
- description = "Rule for wmi exec module"
+ description = "Detects Windows Hacktool Netfilter (Windows.Hacktool.NetFilter)"
author = "Elastic Security"
- id = "8ee55ee5-67f1-4f94-ab93-62bb5cfbeee9"
- date = "2021-10-21"
- modified = "2022-01-13"
+ id = "e8243dae-33d9-4b54-8f4a-ba5cf5241767"
+ date = "2022-04-04"
+ modified = "2023-06-13"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L949-L969"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "36d32b1ed967f07a4bd19f5e671294d5359009c04835601f2cc40fb8b54f6a2a"
- logic_hash = "d0cc321e15660311ae0b8e3261abe716a50a2455f82635c1b02d0a5444c8a89a"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_NetFilter.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "760be95d4c04b10df89a78414facf91c0961020e80561eee6e2cb94b43b76510"
+ logic_hash = "c551bd87e73f980d8836b13449490de5e639d768b72d9006d90969f3140b28e2"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "7e7ed4f00d0914ce0b9f77b6362742a9c8b93a16a6b2a62b70f0f7e15ba3a72b"
- threat_name = "Windows.Trojan.CobaltStrike"
- severity = 100
+ tags = "FILE"
+ fingerprint = "1542c32471f5d3f20beeb60c696085548d675f5d1cab1a0ef85a7060b01f0349"
+ severity = 50
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
os = "windows"
strings:
- $a1 = "Z:\\devcenter\\aggressor\\external\\pxlib\\bin\\wmiexec.x64.o" ascii fullword
- $a2 = "z:\\devcenter\\aggressor\\external\\pxlib\\bin\\wmiexec.x86.o" ascii fullword
+ $str1 = "[NetFlt]:CTRL NDIS ModifyARP"
condition:
- 1 of ($a*)
+ int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_8D5963A2 : FILE MEMORY
+rule ELASTIC_Windows_Hacktool_Netfilter_Dd576D28 : FILE
{
meta:
- description = "Detects Windows Trojan Cobaltstrike (Windows.Trojan.CobaltStrike)"
+ description = "Detects Windows Hacktool Netfilter (Windows.Hacktool.NetFilter)"
author = "Elastic Security"
- id = "8d5963a2-54a9-4705-9f34-0d5f8e6345a2"
- date = "2022-08-10"
- modified = "2022-09-29"
+ id = "dd576d28-b3e7-46b7-b19f-af37af434082"
+ date = "2022-04-04"
+ modified = "2023-06-13"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L971-L989"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "9fe43996a5c4e99aff6e2a1be743fedec35e96d1e6670579beb4f7e7ad591af9"
- logic_hash = "f4f8fba807256bd885ccf4946eec8c2fb76eb04f86ed76d015178fe512a3c091"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_NetFilter.yar#L21-L39"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "88cfe6d7c81d0064045c4198d6ec7d3c50dc3ec8e36e053456ed1b50fc8c23bf"
+ logic_hash = "7635ed94ca77c7705df4d2a9c5546ece86bf831b5bf5355943419174e0387b86"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "228cd65380cf4b04f9fd78e8c30c3352f649ce726202e2dac9f1a96211925e1c"
- severity = 100
+ tags = "FILE"
+ fingerprint = "b47477c371819a456ab24e158d6649e89b4d1756dc6da0b783b351d40b034fac"
+ severity = 50
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
os = "windows"
strings:
- $a = { 40 55 53 56 57 41 54 41 55 41 56 41 57 48 8D 6C 24 D8 48 81 EC 28 01 00 00 45 33 F6 48 8B D9 48 }
+ $str1 = "\\NetProxyDriver.pdb"
condition:
- all of them
+ int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_1787Eef5 : FILE MEMORY
+rule ELASTIC_Windows_Hacktool_Netfilter_B4F2A520 : FILE
{
meta:
- description = "CS shellcode variants"
+ description = "Detects Windows Hacktool Netfilter (Windows.Hacktool.NetFilter)"
author = "Elastic Security"
- id = "1787eef5-ff00-4e19-bd22-c5dfc9488c7b"
- date = "2022-08-29"
- modified = "2022-09-29"
+ id = "b4f2a520-88bf-447e-bbc4-5d8bfd2c9753"
+ date = "2022-04-04"
+ modified = "2023-06-13"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L991-L1014"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "36d32b1ed967f07a4bd19f5e671294d5359009c04835601f2cc40fb8b54f6a2a"
- logic_hash = "0b70c61e986dee3126fec6eea127e01fce4b647aff8e2d2d5072eb8328549225"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_NetFilter.yar#L41-L59"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "5d0d5373c5e52c4405f4bd963413e6ef3490b7c4c919ec2d4e3fb92e91f397a0"
+ logic_hash = "520d2194593f1622a3b905fe182a0773447a4eee3472e7701cce977f5bf4fbae"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "292f15bdc978fc29670126f1bdc72ade1e7faaf1948653f70b6789a82dbee67f"
- threat_name = "Windows.Trojan.CobaltStrike"
- severity = 100
+ tags = "FILE"
+ fingerprint = "1d8da6f78149e2db6b54faa381ce8eb285930226a5b4474e04937893c831809f"
+ severity = 50
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
os = "windows"
strings:
- $a1 = { 55 89 E5 83 EC ?? A1 ?? ?? ?? ?? C7 04 24 ?? ?? ?? ?? 89 44 24 ?? E8 ?? ?? ?? ?? 31 C0 C9 C3 55 }
- $a2 = { 55 89 E5 83 EC ?? A1 ?? ?? ?? ?? 89 04 24 E8 ?? ?? ?? ?? 31 C0 C9 C3 55 89 E5 83 EC ?? 83 7D ?? ?? }
- $a3 = { 55 89 E5 8B 45 ?? 5D FF E0 55 8B 15 ?? ?? ?? ?? 89 E5 8B 45 ?? 85 D2 7E ?? 83 3D ?? ?? ?? ?? ?? }
- $a4 = { 55 89 E5 8B 45 ?? 5D FF E0 55 89 E5 83 EC ?? 8B 15 ?? ?? ?? ?? 8B 45 ?? 85 D2 7E ?? 83 3D ?? ?? ?? ?? ?? }
- $a5 = { 4D 5A 41 52 55 48 89 E5 48 81 EC ?? ?? ?? ?? 48 8D 1D ?? ?? ?? ?? 48 89 DF 48 81 C3 ?? ?? ?? ?? }
+ $str1 = "\\netfilterdrv.pdb"
condition:
- 1 of ($a*)
+ int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_4106070A : FILE MEMORY
+rule ELASTIC_Windows_Hacktool_Netfilter_1Cae6E26 : FILE
{
meta:
- description = "Detects Windows Trojan Cobaltstrike (Windows.Trojan.CobaltStrike)"
+ description = "Detects Windows Hacktool Netfilter (Windows.Hacktool.NetFilter)"
author = "Elastic Security"
- id = "4106070a-24e2-421b-ab83-67b817a9f019"
- date = "2023-05-09"
+ id = "1cae6e26-b0ce-4f53-b88d-975b52ebcca7"
+ date = "2022-04-04"
modified = "2023-06-13"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L1016-L1035"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "98789a11c06c1dfff7e02f66146afca597233c17e0d4900d6a683a150f16b3a4"
- logic_hash = "90f0209a55ca381ca58264664e04c007c799cf558f143d0c02983d4caf47bfb8"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Hacktool_NetFilter.yar#L61-L79"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "e2ec3b2a93c473d88bfdf2deb1969d15ab61737acc1ee8e08234bc5513ee87ea"
+ logic_hash = "29c0edc03934e6e7275c3870a8808e03ec85dacb1f54e10efca3123d2257db98"
score = 75
quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "c12b919064a9cd2a603c134c5f73f6d05ffbf4cbed1e5b5246687378102e4338"
- severity = 100
+ tags = "FILE"
+ fingerprint = "27003a6c9ad814e1ab2e7e284acfebdd18c9dd2af66eb9f44e5a9d59445fa086"
+ severity = 50
arch_context = "x86"
- scan_context = "file, memory"
+ scan_context = "file"
license = "Elastic License v2"
os = "windows"
strings:
- $a1 = { 48 8B 44 24 48 0F B7 00 66 C1 E8 0C 66 83 E0 0F 0F B7 C0 83 }
- $a2 = { 44 24 48 0F B7 00 66 C1 E8 0C 66 83 E0 0F 0F B7 C0 83 F8 0A }
+ $str1 = "\\Driver_Map.pdb"
condition:
- all of them
+ int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_3Dc22D14 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Octopus_15813E26 : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Cobaltstrike (Windows.Trojan.CobaltStrike)"
+ description = "Identifies Octopus, an Open source pre-operation C2 server based on Python and PowerShell"
author = "Elastic Security"
- id = "3dc22d14-a2f4-49cd-a3a8-3f071eddf028"
- date = "2023-05-09"
- modified = "2023-06-13"
+ id = "15813e26-77f8-46cf-a6a3-ae081925b85a"
+ date = "2021-11-10"
+ modified = "2022-01-13"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L1037-L1056"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "7898194ae0244611117ec948eb0b0a5acbc15cd1419b1ecc553404e63bc519f9"
- logic_hash = "2f52cd5f3b782c28e372c3daa9b7ddc4d2b9f68832f5250983412c2e7a755e73"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Octopus.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "0d30b96ead4ccba75e08f6ba1db73cee61a29b5b0c7ee0fb523cbcd61dce9d87"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "0e029fac50ffe8ea3fc5bc22290af69e672895eaa8a1b9f3e9953094c133392c"
+ fingerprint = "a3294547f7e3cead0cd64eb3d2e7dbd8ccfc4d9eedede240a643c8cd114cbcce"
+ threat_name = "Windows.Trojan.Octopus"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -65852,152 +69720,147 @@ rule ELASTIC_Windows_Trojan_Cobaltstrike_3Dc22D14 : FILE MEMORY
os = "windows"
strings:
- $a1 = "%02d/%02d/%02d %02d:%02d:%02d" fullword
- $a2 = "%s as %s\\%s: %d" fullword
+ $a = "C:\\Users\\UNKNOWN\\source\\repos\\OctopusUnmanagedExe\\OctopusUnmanagedExe\\obj\\x64\\Release\\SystemConfiguration.pdb" ascii fullword
condition:
all of them
}
-rule ELASTIC_Windows_Trojan_Cobaltstrike_7F8Da98A : FILE MEMORY
+rule ELASTIC_Linux_Ransomware_Akira_02237952 : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Cobaltstrike (Windows.Trojan.CobaltStrike)"
+ description = "Detects Linux Ransomware Akira (Linux.Ransomware.Akira)"
author = "Elastic Security"
- id = "7f8da98a-3336-482b-91da-82c7cef34c62"
- date = "2023-05-09"
- modified = "2023-06-13"
+ id = "02237952-b9ac-44e5-a32f-f3cc8f28a89b"
+ date = "2023-07-28"
+ modified = "2024-02-13"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_CobaltStrike.yar#L1058-L1076"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "e3bc2bec4a55ad6cfdf49e5dbd4657fc704af1758ca1d6e31b83dcfb8bf0f89d"
- logic_hash = "6c8698d65cbbf893f79ca1de5273535891418c87c234a2542f5f8079e56d9507"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Ransomware_Akira.yar#L1-L22"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "1d3b5c650533d13c81e325972a912e3ff8776e36e18bca966dae50735f8ab296"
+ logic_hash = "a9b3cdddb3387251d7da90f32b08b9c1eedcdff1fe90d51f4732183666a6d467"
score = 75
- quality = 73
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "c375492960a6277bf665bea86302cec774c0d79506e5cb2e456ce59f5e68aa2e"
+ fingerprint = "7fcfac47be082441f6df149d0615a9d2020ac1e9023eabfcf10db4fe400cd474"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = { 25 63 25 63 25 63 25 63 25 63 25 63 25 63 25 63 25 63 4D 53 53 45 2D 25 64 2D 73 65 72 76 65 72 }
+ $a1 = "No path to encrypt" fullword
+ $a2 = "--encryption_percent" fullword
+ $a3 = "Failed to import public key" fullword
+ $a4 = "akira_readme.txt" fullword
condition:
- all of them
+ 3 of them
}
-rule ELASTIC_Windows_Trojan_Quasarrat_E52Df647 : FILE MEMORY
+rule ELASTIC_Linux_Trojan_Kaiji_253C44De : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Quasarrat (Windows.Trojan.Quasarrat)"
+ description = "Detects Linux Trojan Kaiji (Linux.Trojan.Kaiji)"
author = "Elastic Security"
- id = "e52df647-c197-4790-b051-8951fba80c3b"
- date = "2021-06-27"
- modified = "2021-08-23"
+ id = "253c44de-3f48-49f9-998d-1dec2981108c"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Quasarrat.yar#L1-L23"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "a58efd253a25cc764d63476931da2ddb305a0328253a810515f6735a6690de1d"
- logic_hash = "41f32e0c9b3b43d10baef10060e064ad860558bcdeb4281a30d30c16615ed21d"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Kaiji.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "e31eb8880bb084b4c642eba127e64ce99435ea8299a98c183a63a2e6a139d926"
+ logic_hash = "81a07f60765f50c58b2c0f0153367ee570f36c579e9f88fb2f0e49ae5c08773f"
score = 75
- quality = 50
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "c888f0856c6568b83ab60193f8144a61e758e6ff53f6ead8565282ae8b3a9815"
+ fingerprint = "f390a16ca4270dc38ce1a52bbdc1ac57155f369a74005ff2a4e46c6d043b869e"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = "GetKeyloggerLogsResponse" ascii fullword
- $a2 = "DoDownloadAndExecute" ascii fullword
- $a3 = "http://api.ipify.org/" wide fullword
- $a4 = "Domain: {1}{0}Cookie Name: {2}{0}Value: {3}{0}Path: {4}{0}Expired: {5}{0}HttpOnly: {6}{0}Secure: {7}" wide fullword
- $a5 = "\" /sc ONLOGON /tr \"" wide fullword
+ $a = { EB 27 0F B6 1C 10 48 8B 74 24 40 48 8B BC 24 90 00 00 00 88 }
condition:
- 4 of them
+ all of them
}
-rule ELASTIC_Windows_Trojan_Darkgate_Fa1F1338 : FILE MEMORY
+rule ELASTIC_Linux_Trojan_Kaiji_535F07Ac : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Darkgate (Windows.Trojan.DarkGate)"
+ description = "Detects Linux Trojan Kaiji (Linux.Trojan.Kaiji)"
author = "Elastic Security"
- id = "fa1f1338-c920-4db9-a7ec-cd11d7e1558b"
- date = "2023-12-14"
- modified = "2024-01-12"
+ id = "535f07ac-d727-4866-aaed-74d297a1092c"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_DarkGate.yar#L1-L21"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "1fce9ee9254dd0641387cc3b6ea5f6a60f4753132c20ca03ce4eed2aa1042876"
- logic_hash = "d5447a57fc57af52c263b84522346a3e94a464a698de8be77eab3b56156164f2"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Kaiji.yar#L21-L39"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "28b2993d7c8c1d8dfce9cd2206b4a3971d0705fd797b9fde05211686297f6bb0"
+ logic_hash = "539977c1076b71873135cfe02153da87c0e9ac17122f04570977a22c92d2694f"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "182481e23eb10f0a8b7d0d536e2d8d36ab5e51fd798caebff4d38d55b5549244"
+ fingerprint = "8853b2a1d5852e436cab2e3402a5ca13839b3cae6fbb56a74b047234b8c1233b"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $str0 = "DarkGate has recovered from a Critical error"
- $str1 = "Executing DarkGate inside the new desktop..."
- $str2 = "Restart Darkgate "
+ $a = { 44 24 10 48 8B 4C 24 08 48 83 7C 24 18 00 74 26 C6 44 24 57 00 48 8B 84 24 98 00 }
condition:
- 2 of them
+ all of them
}
-rule ELASTIC_Windows_Trojan_Darkgate_07Ef6F14 : FILE MEMORY
+rule ELASTIC_Linux_Trojan_Kaiji_Dcf6565E : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Darkgate (Windows.Trojan.DarkGate)"
+ description = "Detects Linux Trojan Kaiji (Linux.Trojan.Kaiji)"
author = "Elastic Security"
- id = "07ef6f14-4eb5-4c15-94af-117c68106104"
- date = "2023-12-14"
- modified = "2024-02-08"
+ id = "dcf6565e-8287-4d78-b103-53cfab192025"
+ date = "2022-09-12"
+ modified = "2022-10-18"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_DarkGate.yar#L23-L42"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "1fce9ee9254dd0641387cc3b6ea5f6a60f4753132c20ca03ce4eed2aa1042876"
- logic_hash = "2820286b362b107fc7fc3ec8f1a004a7d7926a84318f2943f58239f1f7e8f1f0"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Kaiji.yar#L41-L59"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "49f3086105bdc160248e66334db00ce37cdc9167a98faac98800b2c97515b6e7"
+ logic_hash = "2bc943e100548e9aacd97930b3230353be760c8a292dbbbd1d0b5646f647c4fe"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "fd0aab53bddd3872147aa064a571d118cc00a6643d72c017fe26f6e0d19288e1"
+ fingerprint = "381d6b8f6a95800fe0d20039f991ce82317f60aef100487f3786e6c1e63376e1"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $binary0 = { 8B 04 24 0F B6 44 18 FF 33 F8 43 4E }
- $binary1 = { 8B D7 32 54 1D FF F6 D2 88 54 18 FF 43 4E }
+ $a = { 48 69 D2 9B 00 00 00 48 C1 EA 20 83 C2 64 48 8B 9C 24 B8 00 }
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Cerbu_69D5657E : FILE MEMORY
+rule ELASTIC_Linux_Trojan_Kaiji_91091Be3 : FILE MEMORY
{
meta:
- description = "Detects Linux Trojan Cerbu (Linux.Trojan.Cerbu)"
+ description = "Detects Linux Trojan Kaiji (Linux.Trojan.Kaiji)"
author = "Elastic Security"
- id = "69d5657e-1fe9-4367-b478-218c278c7fbc"
- date = "2021-01-12"
- modified = "2021-09-16"
+ id = "91091be3-8c9e-4d7a-8ca6-cd422afe0aa5"
+ date = "2022-09-12"
+ modified = "2022-10-18"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Cerbu.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "f10bf3cf2fdfbd365d3c2d8dedb2d01b85236eaa97d15370dbcb5166149d70e9"
- logic_hash = "644e8d5a1b5c8618e71497f21b0244215924e293e274b9164692dd927cd74ba8"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Kaiji.yar#L61-L79"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "dca574d13fcbd7d244d434fcbca68136e0097fefc5f131bec36e329448f9a202"
+ logic_hash = "3b55cb3be5775311af4dc90f9624448d30cc58ef1a42729f6ca4eb3b36ad8b06"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "7dfaebc6934c8fa97509831e0011f2befd0dbc24a68e4a07bc1ee0decae45a42"
+ fingerprint = "f583bbef07f41e74ba9646a3e97ef114eb34b1ae820ed499dffaad90db227ca6"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -66005,55 +69868,116 @@ rule ELASTIC_Linux_Trojan_Cerbu_69D5657E : FILE MEMORY
os = "linux"
strings:
- $a = { E8 5B 5E C9 C3 55 89 E5 83 EC 08 83 C4 FC FF 75 0C 6A 05 FF }
+ $a = { 24 18 83 7C 24 1C 02 75 9E 8B 4C 24 64 8B 51 1C 89 54 24 5C }
condition:
all of them
}
-rule ELASTIC_Linux_Cryptominer_Bulz_2Aa8Fbb5 : FILE MEMORY
+rule ELASTIC_Linux_Trojan_Rotajakiro_Fb24F399 : FILE MEMORY
{
meta:
- description = "Detects Linux Cryptominer Bulz (Linux.Cryptominer.Bulz)"
+ description = "Detects Linux Trojan Rotajakiro (Linux.Trojan.Rotajakiro)"
author = "Elastic Security"
- id = "2aa8fbb5-b392-49fc-8f0f-12cd06d534e2"
- date = "2021-01-12"
+ id = "fb24f399-d2bc-4cca-a3b8-4d924f11c83e"
+ date = "2021-06-28"
modified = "2021-09-16"
- reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Cryptominer_Bulz.yar#L1-L18"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "21d8bec73476783e01d2a51a99233f186d7c72b49c9292c42e19e1aa6397d415"
+ reference = "023a7f9ed082d9dd7be6eba5942bfa77f8e618c2d15a8bc384d85223c5b91a0c"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Trojan_Rotajakiro.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "be33fdda50ef0ea1a0cf45835cc2b7a805cecb3fff371ed6d93e01c2d477d867"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "c8fbeae6cf935fe629c37abc4fdcda2c80c1b19fc8b6185a58decead781e1321"
- severity = 100
+ fingerprint = "6b19a49c93a0d3eb380c78ca21ce4f4d2991c35e68d2b75e173dc25118ba2c20"
+ severity = "100"
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
os = "linux"
strings:
- $a = { FE D7 C5 D9 72 F2 09 C5 E9 72 D2 17 C5 E9 EF D4 C5 E9 EF D6 C5 C1 }
+ $a = { 41 56 41 55 41 54 49 89 FD 55 53 48 63 DE 48 83 EC 08 0F B6 17 80 }
condition:
all of them
}
-rule ELASTIC_Linux_Cryptominer_Bulz_0998F811 : FILE MEMORY
+rule ELASTIC_Windows_Vulndriver_Winflash_881758Da : FILE
{
meta:
- description = "Detects Linux Cryptominer Bulz (Linux.Cryptominer.Bulz)"
+ description = "Detects Windows Vulndriver Winflash (Windows.VulnDriver.WinFlash)"
author = "Elastic Security"
- id = "0998f811-7be3-4d46-9dcb-1e8a0f19bab5"
- date = "2021-01-12"
+ id = "881758da-760c-4c50-81f2-8bd698972ba2"
+ date = "2022-04-04"
+ modified = "2022-04-04"
+ reference = "https://github.com/elastic/protections-artifacts/"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_WinFlash.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "8596ea3952d84eeef8f5dc5b0b83014feb101ec295b2d80910f21508a95aa026"
+ logic_hash = "a46ac1f19ba5d9543c88434575870b61fbb935cd4c4e28cb80a077502af7d2db"
+ score = 75
+ quality = 75
+ tags = "FILE"
+ fingerprint = "1c64ee1c3fc6bf93e207810a473367c404c824d0eaba15910b00016e23d53637"
+ severity = 50
+ arch_context = "x86"
+ scan_context = "file"
+ license = "Elastic License v2"
+ os = "windows"
+
+ strings:
+ $str1 = "\\WinFlash64.pdb"
+
+ condition:
+ int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
+}
+rule ELASTIC_Windows_Vulndriver_Microstar_D72B85B2 : FILE
+{
+ meta:
+ description = "Name: NTIOLib.sys, Version: 1.0.0.0"
+ author = "Elastic Security"
+ id = "d72b85b2-b51e-4061-909c-cce531513367"
+ date = "2022-04-07"
+ modified = "2022-04-07"
+ reference = "https://github.com/elastic/protections-artifacts/"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_VulnDriver_MicroStar.yar#L1-L21"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "3ed15a390d8dfbd8a8fb99e8367e19bfd1cced0e629dfe43ccdb46c863394b59"
+ logic_hash = "04e9c1f318acae5544cdc826938383bf8f6c6b838cb5828a7097383ac564f404"
+ score = 75
+ quality = 75
+ tags = "FILE"
+ fingerprint = "a531bc0b1a94b532694c9ae421db258007d835e03cf2580a1b5a10e5686063e5"
+ threat_name = "Windows.VulnDriver.MicroStar"
+ severity = 50
+ arch_context = "x86"
+ scan_context = "file"
+ license = "Elastic License v2"
+ os = "windows"
+
+ strings:
+ $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 4E 00 54 00 49 00 4F 00 4C 00 69 00 62 00 2E 00 73 00 79 00 73 00 00 00 }
+ $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x00][\x00-\x00])([\x00-\x01][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x00][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/
+
+ condition:
+ int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version
+}
+rule ELASTIC_Linux_Shellcode_Generic_5669055F : FILE MEMORY
+{
+ meta:
+ description = "Detects Linux Shellcode Generic (Linux.Shellcode.Generic)"
+ author = "Elastic Security"
+ id = "5669055f-8ce7-4163-af06-cb265fde3eef"
+ date = "2021-04-06"
modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Cryptominer_Bulz.yar#L20-L37"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "178f6c42582dd99cc5418388d020d4d76f2a9204297a673359fe0a300121c35b"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Shellcode_Generic.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "87ef4def16d956cdfecaea899cbb55ff59a6739bbb438bf44a8b5fec7fcfd85b"
+ logic_hash = "735b8dc7fff3c9cc96646a4eb7c5afd70be19dcc821e9e26ce906681130746be"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "c8a83bc305998cb6256b004e9d8ce6d5d1618b107e42be139b73807462b53c31"
+ fingerprint = "616fe440ff330a1d22cacbdc2592c99328ea028700447724d2d5b930554a22f4"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -66061,28 +69985,28 @@ rule ELASTIC_Linux_Cryptominer_Bulz_0998F811 : FILE MEMORY
os = "linux"
strings:
- $a = { 79 70 E4 39 C5 F9 70 C9 4E C5 91 72 F0 12 C5 F9 72 D0 0E C5 91 }
+ $a = { 00 31 C0 31 DB 31 C9 B0 17 CD 80 31 C0 51 B1 06 }
condition:
all of them
}
-rule ELASTIC_Linux_Proxy_Frp_4213778F : FILE MEMORY
+rule ELASTIC_Linux_Shellcode_Generic_D2C96B1D : FILE MEMORY
{
meta:
- description = "Detects Linux Proxy Frp (Linux.Proxy.Frp)"
+ description = "Detects Linux Shellcode Generic (Linux.Shellcode.Generic)"
author = "Elastic Security"
- id = "4213778f-d05e-4af8-9650-2d813d5a64e5"
- date = "2021-10-20"
- modified = "2022-01-26"
+ id = "d2c96b1d-f424-476c-9463-dd34a1da524e"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Proxy_Frp.yar#L1-L28"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "16294086be1cc853f75e864a405f31e2da621cb9d6a59f2a71a2fca4e268b6c2"
- logic_hash = "83eeb632026c38ac08357c27d971da31fbc9a0500ecf489e8332ac5862a77b85"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Shellcode_Generic.yar#L21-L39"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "403d53a65bd77856f7c565307af5003b07413f2aba50869655cdd88ce15b0c82"
+ logic_hash = "33d964e22c8e3046f114e8264d18e8b4a0e7b55eca59151b084db7eea07aa0b1"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "70bb186a9719767a9a60786fbe10bf4cc2f04c19ea58aaaa90018ec89a9f9b84"
+ fingerprint = "ee042895d863310ff493fdd33721571edd322e764a735381d236b2c0a7077cfa"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -66090,507 +70014,484 @@ rule ELASTIC_Linux_Proxy_Frp_4213778F : FILE MEMORY
os = "linux"
strings:
- $s1 = "github.com/fatedier/frp/client/proxy.TcpProxy"
- $s2 = "frp/cmd/frpc/sub/xtcp.go"
- $s3 = "frp/client/proxy/proxy_manager.go"
- $s4 = "fatedier/frp/models/config/proxy.go"
- $s5 = "github.com/fatedier/frp/server/proxy"
- $s6 = "frp/cmd/frps/main.go"
- $p1 = "json:\"remote_port\""
- $p2 = "remote_port"
- $p3 = "remote_addr"
- $p4 = "range section [%s] local_port and remote_port is necessary[ERR]"
+ $a = { 89 E1 8D 54 24 04 5B B0 0B CD 80 31 C0 B0 01 31 }
condition:
- 2 of ($s*) and 2 of ($p*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Deimos_F53Aee03 : FILE MEMORY
+rule ELASTIC_Linux_Shellcode_Generic_30C70926 : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Deimos (Windows.Trojan.Deimos)"
+ description = "Detects Linux Shellcode Generic (Linux.Shellcode.Generic)"
author = "Elastic Security"
- id = "f53aee03-74c3-4b40-8ae4-4f1bf35f88c8"
- date = "2021-09-18"
- modified = "2022-01-13"
- reference = "https://www.elastic.co/security-labs/going-coast-to-coast-climbing-the-pyramid-with-the-deimos-implant"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Deimos.yar#L1-L22"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "2c1941847f660a99bbc6de16b00e563f70d900f9dbc40c6734871993961d3d3e"
- logic_hash = "07675844a8790f8485b6545e7466cdef8ac4f92dec4cd8289aeaad2a0a448691"
+ id = "30c70926-9414-499a-a4db-7c3bb902dd82"
+ date = "2021-04-06"
+ modified = "2021-09-16"
+ reference = "https://github.com/elastic/protections-artifacts/"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Shellcode_Generic.yar#L41-L59"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "a742e23f26726293b1bff3db72864471d6bb4062db1cc6e1c4241f51ec0e21b1"
+ logic_hash = "3594994a911e5428198c472a51de189a6be74895170581ec577c49f8dbb9167a"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "12a6d7f9e4f9a937bf1416443dd0d5ee556ac1f67d2b56ad35f9eac2ee6aac74"
+ fingerprint = "4af586211c56e92b1c60fcd09b4def9801086fbe633418459dc07839fe9c735a"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = "\\APPDATA\\ROAMING" wide fullword
- $a2 = "{\"action\":\"ping\",\"" wide fullword
- $a3 = "Deimos" ascii fullword
+ $a = { E3 52 53 89 E1 31 C0 B0 0B CD 80 31 C0 40 CD 80 }
condition:
- all of ($a*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_Deimos_C70677B4 : FILE MEMORY
+rule ELASTIC_Linux_Shellcode_Generic_224Bdcc4 : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Deimos (Windows.Trojan.Deimos)"
+ description = "Detects Linux Shellcode Generic (Linux.Shellcode.Generic)"
author = "Elastic Security"
- id = "c70677b4-f5ba-440b-ba31-31e80caee2fe"
- date = "2021-09-18"
- modified = "2022-01-13"
- reference = "https://www.elastic.co/security-labs/going-coast-to-coast-climbing-the-pyramid-with-the-deimos-implant"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Deimos.yar#L24-L44"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "2c1941847f660a99bbc6de16b00e563f70d900f9dbc40c6734871993961d3d3e"
- logic_hash = "c969221f025b114b9d5738d43b6021ab9481dbc6b35eb129ea4f806160b1adc3"
+ id = "224bdcc4-4b38-44b5-96c6-d3b378628fa4"
+ date = "2021-01-12"
+ modified = "2021-09-16"
+ reference = "https://github.com/elastic/protections-artifacts/"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Shellcode_Generic.yar#L61-L79"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "bd22648babbee04555cef52bfe3e0285d33852e85d254b8ebc847e4e841b447e"
+ logic_hash = "8c4a2bb63f0926e7373caf0a027179b4730cc589f9af66d2071e88f4165b0f73"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "ffe0dec3585da9cbb9f8a0fac1bb6fd43d5d6e20a6175aaa889ae13ef2ed101f"
+ fingerprint = "e23b239775c321d4326eff2a7edf0787116dd6d8a9e279657e4b2b01b33e72aa"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = { 00 57 00 58 00 59 00 5A 00 5F 00 00 17 75 00 73 00 65 00 72 00 }
- $a2 = { 0C 08 16 1F 68 9D 08 17 1F 77 9D 08 18 1F 69 9D 08 19 1F 64 9D }
+ $a = { 89 E6 6A 10 5A 6A 2A 58 0F 05 48 85 C0 79 1B 49 FF C9 74 22 }
condition:
- 1 of ($a*)
+ all of them
}
-rule ELASTIC_Windows_Trojan_STRRAT_A3E48Cd2 : MEMORY
+rule ELASTIC_Linux_Shellcode_Generic_99B991Cd : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Strrat (Windows.Trojan.STRRAT)"
+ description = "Detects Linux Shellcode Generic (Linux.Shellcode.Generic)"
author = "Elastic Security"
- id = "a3e48cd2-e65f-40db-ab55-8015ad871dd6"
- date = "2024-03-13"
- modified = "2024-03-21"
+ id = "99b991cd-a5ca-475c-8c10-e43b9d22d26e"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_STRRAT.yar#L1-L20"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "97e67ac77d80d26af4897acff2a3f6075e0efe7997a67d8194e799006ed5efc9"
- logic_hash = "32f79695829f703bf9996d212aeb563791aed28e1bbb9f700cb45325fd02db77"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Shellcode_Generic.yar#L81-L99"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "954b5a073ce99075b60beec72936975e48787bea936b4c5f13e254496a20d81d"
+ logic_hash = "664e213314fe1d6f1920de237ebea3a94f7fbc42eff089475674ccef812f0f68"
score = 75
quality = 75
- tags = "MEMORY"
- fingerprint = "efda9a8bd5f9e227a6696de1b4ea7eb7343b08563cfcbe73fdd75164593bd111"
+ tags = "FILE, MEMORY"
+ fingerprint = "ed904a3214ccf43482e3ddf75f3683fea45f7c43a2f1860bac427d7d15d8c399"
severity = 100
arch_context = "x86"
- scan_context = "memory"
+ scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $str1 = "strigoi/server/ping.php?lid="
- $str2 = "/strigoi/server/?hwid="
+ $a = { 6E 89 E3 50 53 89 E1 B0 0B CD 80 00 4C 65 6E 67 }
condition:
all of them
}
-rule ELASTIC_Macos_Backdoor_Fakeflashlxk_06Fd8071 : FILE MEMORY
+rule ELASTIC_Linux_Shellcode_Generic_24B9Aa12 : FILE MEMORY
{
meta:
- description = "Detects Macos Backdoor Fakeflashlxk (MacOS.Backdoor.Fakeflashlxk)"
+ description = "Detects Linux Shellcode Generic (Linux.Shellcode.Generic)"
author = "Elastic Security"
- id = "06fd8071-0370-4ae8-819a-846fa0a79b3d"
- date = "2021-11-11"
- modified = "2022-07-22"
+ id = "24b9aa12-92b2-492d-9a0e-078cdab5830a"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/MacOS_Backdoor_Fakeflashlxk.yar#L1-L21"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "107f844f19e638866d8249e6f735daf650168a48a322d39e39d5e36cfc1c8659"
- logic_hash = "853d44465a472786bb48bbe1009e0ff925f79e4fd72f0eac537dd271c1ec3703"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Shellcode_Generic.yar#L101-L119"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "24b2c1ccbbbe135d40597fbd23f7951d93260d0039e0281919de60fa74eb5977"
+ logic_hash = "4685253eb00a21d6dd6e874ff68209f20c8668262f24767086687555ccf934aa"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "a0e6763428616b46536c6a4eb080bae0cc58ef27678616aa432eb43a3d9c77a1"
+ fingerprint = "0ded0ad2fdfff464bf9a0b5a59b8edfe1151a513203386daae6f9f166fd48e5c"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "macos"
+ os = "linux"
strings:
- $s1 = "/Users/lxk/Library/Developer/Xcode/DerivedData"
- $s2 = "Desktop/SafariFlashActivity/SafariFlashActivity/SafariFlashActivity/"
- $s3 = "/Debug/SafariFlashActivity.build/Objects-normal/x86_64/AppDelegate.o"
+ $a = { 6E 89 E3 89 C1 89 C2 B0 0B CD 80 31 C0 40 CD 80 }
condition:
- 2 of them
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Sharpwmi_A67D6Fe5 : FILE MEMORY
+rule ELASTIC_Linux_Shellcode_Generic_8Ac37612 : FILE MEMORY
{
meta:
- description = "Detects Windows Hacktool Sharpwmi (Windows.Hacktool.SharpWMI)"
+ description = "Detects Linux Shellcode Generic (Linux.Shellcode.Generic)"
author = "Elastic Security"
- id = "a67d6fe5-3ce5-4e63-979e-3fb799d9d173"
- date = "2022-10-20"
- modified = "2022-11-24"
+ id = "8ac37612-aec8-4376-8269-2594152ced8a"
+ date = "2021-04-06"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_SharpWMI.yar#L1-L27"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "2134a5e1a5eece1336f831a7686c5ea3b6ca5aaa63ab7e7820be937da0678e15"
- logic_hash = "de8749951ece8d4798ade4661d531515e12edf8e8606ddc330000d847a66a26c"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Shellcode_Generic.yar#L121-L139"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "c199b902fa4b0fcf54dc6bf3e25ad16c12f862b47e055863a5e9e1f98c6bd6ca"
+ logic_hash = "c0af751bc54dcd9cf834fa5fe9fa120be5e49a56135ebb72fd6073948e956929"
score = 75
- quality = 73
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "20719ea15d4dee90c95b474689752172a6b6fb941dced81803f9f726ddc26d29"
+ fingerprint = "97a3d3e7ff4c9ae31f71e609d10b3b848cb0390ae2d1d738ef53fd23ff0621bc"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $guid = "6DD22880-DAC5-4B4D-9C91-8C35CC7B8180" ascii wide nocase
- $str0 = "powershell -w hidden -nop -c \"$e=([WmiClass]'{0}:{1}').Properties['{2}'].Value;[IO.File]::WriteAllBytes('{3}',[Byte[]][Int[]]($e-split','))\"" ascii wide
- $str1 = "powershell -w hidden -nop -c \"iex($env:{0})\"" ascii wide
- $str2 = "SELECT * FROM Win32_Process" ascii wide
- $str3 = "DOWNLOAD_URL" ascii wide
- $str4 = "TARGET_FILE" ascii wide
- $str5 = "SELECT Enabled,DisplayName,Action,Direction,InstanceID from MSFT_NetFirewallRule WHERE Enabled=1" ascii wide
- $print_str0 = "This may indicate called SharpWMI did not invoked WMI using elevated/impersonated token." ascii wide
- $print_str1 = "[+] Attempted to terminate remote process ({0}). Returned: {1}" ascii wide
+ $a = { 89 E3 ?? 53 89 E1 B0 0B CD 80 00 47 43 43 3A }
+
+ condition:
+ all of them
+}
+rule ELASTIC_Linux_Shellcode_Generic_932Ed0F0 : FILE MEMORY
+{
+ meta:
+ description = "Detects Linux Shellcode Generic (Linux.Shellcode.Generic)"
+ author = "Elastic Security"
+ id = "932ed0f0-bd43-4367-bcc3-ecd8f65b52ee"
+ date = "2021-04-06"
+ modified = "2021-09-16"
+ reference = "https://github.com/elastic/protections-artifacts/"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Shellcode_Generic.yar#L141-L159"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "f357597f718f86258e7a640250f2e9cf1c3363ab5af8ddbbabb10ebfa3c91251"
+ logic_hash = "20ae3f1d96f8afd0900ac919eacaff3bd748a7466af5bb2b9f77cfdc4b8b829e"
+ score = 75
+ quality = 75
+ tags = "FILE, MEMORY"
+ fingerprint = "7aa4619d2629b5d795e675d17a6e962c6d66a75e11fa884c0b195cb566090070"
+ severity = 100
+ arch_context = "x86"
+ scan_context = "file, memory"
+ license = "Elastic License v2"
+ os = "linux"
+
+ strings:
+ $a = { E3 50 89 E2 53 89 E1 B0 0B CD 80 31 C0 40 CD 80 }
condition:
- $guid or ( all of ($str*) and 1 of ($print_str*))
+ all of them
}
-rule ELASTIC_Windows_Virus_Neshta_2A5A14C8 : FILE MEMORY
+rule ELASTIC_Linux_Backdoor_Python_00606Bac : FILE MEMORY
{
meta:
- description = "Detects Windows Virus Neshta (Windows.Virus.Neshta)"
+ description = "Detects Linux Backdoor Python (Linux.Backdoor.Python)"
author = "Elastic Security"
- id = "2a5a14c8-27d8-4658-8941-0bb221d54ad3"
- date = "2024-01-22"
- modified = "2024-02-08"
+ id = "00606bac-83eb-4a58-82d2-e4fd16d30846"
+ date = "2021-01-12"
+ modified = "2021-09-16"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Virus_Neshta.yar#L1-L20"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "f298214764ee9ab690cb4b376d8a7893edcd9c05a3c4e6f3a56010974a130bd7"
- logic_hash = "0b5d0603f4c20a2368f697dd84cfe1790a5d0e5904c76066601c9e3d1b5ed1e1"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Linux_Backdoor_Python.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "b3e3728d43535f47a1c15b915c2d29835d9769a9dc69eb1b16e40d5ba1b98460"
+ logic_hash = "92ad2cf4aa848c8f3bcedd319654bf5ef873cd4daba62572381c7e20f0296b82"
score = 75
- quality = 73
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "4ca7b0c908d08bf8b2041d7b41be8569efa54db99ebf04c7ff290c6bcad7dc02"
+ fingerprint = "cce1d0e7395a74c04f15ff95f6de7fd7d5f46ede83322b832df74133912c0b17"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "windows"
+ os = "linux"
strings:
- $a1 = { 44 65 6C 70 68 69 2D 74 68 65 20 62 65 73 74 2E 20 46 75 63 6B 20 6F 66 66 20 61 6C 6C 20 74 68 65 20 72 65 73 74 2E 20 4E 65 73 68 74 61 20 31 2E 30 20 4D 61 64 65 20 69 6E 20 42 65 6C 61 72 75 73 2E }
- $a2 = { 55 8B EC 81 C4 64 FF FF FF 53 56 57 33 D2 89 95 64 FF FF FF 8B F8 33 C0 55 68 FC 6D 40 00 64 FF 30 64 89 20 8D 85 69 FF FF FF 50 68 97 00 00 00 E8 1B D3 FF FF 33 DB EB 5C 8B F3 81 E6 FF 00 00 }
+ $a = { F4 01 83 45 F8 01 8B 45 F8 0F B6 00 84 C0 75 F2 83 45 F8 01 8B }
condition:
- any of them
+ all of them
}
-rule ELASTIC_Linux_Trojan_Godropper_Bae099Bd : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_01365E46 : FILE MEMORY
{
meta:
- description = "Detects Linux Trojan Godropper (Linux.Trojan.Godropper)"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "bae099bd-c19a-4893-96e8-63132dabce39"
- date = "2021-04-06"
- modified = "2021-09-16"
+ id = "01365e46-c769-4c6e-913a-4d1e42948af2"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Godropper.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "704643f3fd11cda1d52260285bf2a03bccafe59cfba4466427646c1baf93881e"
- logic_hash = "ef6274928f7cfc0312122ac3e4153fb0a78dc7d5fb2d68db6cbe4974f5497210"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L1-L19"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "5c450d4be39caef1d9ec943f5dfeb6517047175fec166a52970c08cd1558e172"
+ logic_hash = "4d61de2cb37e12f62326c1717f6ed44554f5d2aa7ede6033d0c988e5e64df54d"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "5a7b0906ebc47130aefa868643e1e0a40508fe7a25bc55e5c41ff284ca2751e5"
+ fingerprint = "98505c3418945c10bf4f50a183aa49bdbc7c1c306e98132ae3d0fc36e216f191"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $a = { FF FF FF FF 88 DB A2 31 03 A3 5A 5C 9A 19 0E DB }
+ $a = { 8B 43 28 4C 8B 53 18 4C 8B 5B 10 4C 8B 03 4C 8B 4B 08 89 44 24 38 48 89 4C 24 30 4C }
condition:
all of them
}
-rule ELASTIC_Linux_Exploit_Intfour_0Ca45Cd3 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_06Fd4Ac4 : FILE MEMORY
{
meta:
- description = "Detects Linux Exploit Intfour (Linux.Exploit.Intfour)"
+ description = "Identifies Trickbot unpacker"
author = "Elastic Security"
- id = "0ca45cd3-089c-4d7f-9088-dc972c14bd9d"
- date = "2021-01-12"
- modified = "2021-09-16"
+ id = "06fd4ac4-1155-4068-ae63-4d83db2bd942"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Exploit_Intfour.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "9d32c5447aa5182b4be66b7a283616cf531a2fd3ba3dde1bc363b24d8b22682f"
- logic_hash = "088d8daa9ba4f53c8de229282ed8a7b30b1e567687e7807ac6c3df9524dabba9"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L21-L39"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "bde387f1e22d1399fb99f6d41732a37635d8e90f29626f2995914a073a7cac89"
score = 75
- quality = 73
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "8926a8cfd7f3adf29e399a945592063039b80dcc0545b133b453aaf198d31461"
+ fingerprint = "ece49004ed1d27ef92b3b1ec040d06e90687d4ac5a89451e2ae487d92cb24ddd"
+ threat_name = "Windows.Trojan.Trickbot"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $a = { 6D 28 63 6F 64 65 2C 20 31 30 32 34 2C 20 26 6E 65 65 64 6C 65 }
+ $a = { 5F 33 C0 68 ?? ?? 00 00 59 50 E2 FD 8B C7 57 8B EC 05 ?? ?? ?? 00 89 45 04 }
condition:
all of them
}
-rule ELASTIC_Linux_Trojan_Zerobot_185E2396 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_Ce4305D1 : FILE MEMORY
{
meta:
- description = "Strings found in the zerobot startup / persistanse functions"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "185e2396-f9eb-42e6-b78b-f8c01dbd3fd8"
- date = "2022-12-16"
- modified = "2024-02-13"
+ id = "ce4305d1-8a6f-4797-afaf-57e88f3d38e6"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Zerobot.yar#L1-L26"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "f9fc370955490bdf38fc63ca0540ce1ea6f7eca5123aa4eef730cb618da8551f"
- logic_hash = "caa21cc019d8e4549d976f8b4f98d930ef7acf4c39c41956ae35fa78c975e016"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L41-L58"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "c547114475383e5d84f6b8cb72585ddd5778ae3afa491deddeef8a5ec56be1b5"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "f7ce4eebd5f13af3a480dfe23d86394c7e0f85f284a7c2900ab3fad944b08752"
- threat_name = "Linux.Trojan.Zerobot"
+ fingerprint = "ae606e758b02ccf2a9a313aebb10773961121f79a94c447e745289ee045cf4ee"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $startup_method_1_0 = "/usr/bin/sshf"
- $startup_method_1_1 = "start on filesystem"
- $startup_method_1_2 = "exec /usr/bin/sshf"
- $startup_method_2_0 = "Description=Hehehe"
- $startup_method_2_1 = "/lib/systemd/system/sshf.service"
- $start_service_0 = "service enable sshf"
- $start_service_1 = "systemctl enable sshf"
+ $a = { F9 8B 45 F4 89 5D E4 85 D2 74 39 83 C0 02 03 C6 89 45 F4 8B }
condition:
- ( all of ($startup_method_1_*) or all of ($startup_method_2_*)) and 1 of ($start_service_*)
+ all of them
}
-rule ELASTIC_Linux_Trojan_Zerobot_3A5B56Dd : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_1E56Fad7 : FILE MEMORY
{
meta:
- description = "Strings found in the Zerobot Spoofed Header method"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "3a5b56dd-e829-44bb-ae70-d7001addd057"
- date = "2022-12-16"
- modified = "2024-02-13"
+ id = "1e56fad7-383f-4ee0-9f8f-a0b3dcceb691"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Zerobot.yar#L28-L51"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "f9fc370955490bdf38fc63ca0540ce1ea6f7eca5123aa4eef730cb618da8551f"
- logic_hash = "2491fff4ad0327e0440d842f221fb6623c8efd97e2991bf2090abceaef9c2ccf"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L60-L77"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "815b37804f79fb4607e6b84294882d818233c3df13aececb3d341244900a2e44"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "9800a241ab602434426830110ce244cdfd0023176e5fa64e2b8761234ed6f529"
- threat_name = "Linux.Trojan.Zerobot"
+ fingerprint = "a0916134f47df384bbdacff994970f60d3613baa03c0a581b7d1dd476af3121b"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $HootSpoofHeader_0 = "X-Forwarded-Proto: Http"
- $HootSpoofHeader_1 = "X-Forwarded-Host: %s, 1.1.1.1"
- $HootSpoofHeader_2 = "Client-IP: %s"
- $HootSpoofHeader_3 = "Real-IP: %s"
- $HootSpoofHeader_4 = "X-Forwarded-For: %s"
+ $a = { 5B C9 C2 18 00 43 C1 02 10 7C C2 02 10 54 C1 02 10 67 C1 02 10 }
condition:
- 3 of them
+ all of them
}
-rule ELASTIC_Windows_Vulndriver_Vbox_3315863F : FILE
+rule ELASTIC_Windows_Trojan_Trickbot_93C9A2A4 : FILE MEMORY
{
meta:
- description = "Subject: innotek GmbH"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "3315863f-668c-47ec-86c7-85d50c3b97d9"
- date = "2022-04-07"
- modified = "2022-04-07"
+ id = "93c9a2a4-a07a-4ed4-a899-b160d235bf50"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_VBox.yar#L1-L20"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "42d926cfb3794f9b1e3cb397498696cb687f505e15feb9df11b419c49c9af498"
- logic_hash = "ba4e6a94516e36dcd6140b6732d959703e2c58a79add705b9260001ea26db738"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L79-L96"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "dadeeba6147b118b80e014ab067eac7a2c3c2990958a6c7016562d8b64fef53c"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "b0aea1369943318246f1601f823c72f92a0155791661dadc4c854827c295e4bf"
- threat_name = "Windows.VulnDriver.VBox"
- severity = 50
+ tags = "FILE, MEMORY"
+ fingerprint = "0ff82bf9e70304868ff033f0d96e2a140af6e40c09045d12499447ffb94ab838"
+ severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
- $subject_name = { 06 03 55 04 03 [2] 69 6E 6E 6F 74 65 6B 20 47 6D 62 48 }
+ $a = { 6A 01 8B CF FF 50 5C 8B 4F 58 49 89 4F 64 8B 4D F4 8B 45 E4 }
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $subject_name
+ all of them
}
-rule ELASTIC_Windows_Vulndriver_Vbox_1B1C5Cd5 : FILE
+rule ELASTIC_Windows_Trojan_Trickbot_5340Afa3 : FILE MEMORY
{
meta:
- description = "Name: VBoxDrv.sys, Version: 3.0.0.0"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "1b1c5cd5-23d3-4f1f-a396-3f2b18e28b64"
- date = "2022-04-07"
- modified = "2022-04-07"
+ id = "5340afa3-ff90-4f61-a1ac-aba1f32dd375"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_VBox.yar#L22-L42"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "1684e24dae20ab83ab5462aa1ff6473110ec53f52a32cfb8c1fe95a2642c6d22"
- logic_hash = "5fcfffea021aee8d18172383df0e65f8c618fab545c800f1a7b659e8112c6c0f"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L98-L115"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "8b9d3c978f0c4a04ee5b3446b990172206b17496036bc1cc04180ea7e9b99734"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "89dd35bb023ebc03c46c0e70ac975025921da289cb3374f2912fbb323c591bd9"
- threat_name = "Windows.VulnDriver.VBox"
- severity = 50
+ tags = "FILE, MEMORY"
+ fingerprint = "7da4726ccda6a76d2da773d41f012763802d586f64a313c1c37733905ae9da81"
+ severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
- $original_file_name = { 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 65 00 00 00 56 00 42 00 6F 00 78 00 44 00 72 00 76 00 2E 00 73 00 79 00 73 00 00 00 }
- $version = /V\x00S\x00_\x00V\x00E\x00R\x00S\x00I\x00O\x00N\x00_\x00I\x00N\x00F\x00O\x00\x00\x00{0,4}\xbd\x04\xef\xfe[\x00-\xff]{4}(([\x00-\x00][\x00-\x00])([\x00-\x03][\x00-\x00])([\x00-\x00][\x00-\x00])([\x00-\x00][\x00-\x00])|([\x00-\xff][\x00-\xff])([\x00-\x02][\x00-\x00])([\x00-\xff][\x00-\xff])([\x00-\xff][\x00-\xff]))/
+ $a = { E8 0C 89 5D F4 0F B7 DB 03 5D 08 66 83 F8 03 75 0A 8B 45 14 }
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $original_file_name and $version
+ all of them
}
-rule ELASTIC_Windows_Vulndriver_Procid_86605Fa9 : FILE
+rule ELASTIC_Windows_Trojan_Trickbot_E7932501 : FILE MEMORY
{
meta:
- description = "Detects Windows Vulndriver Procid (Windows.VulnDriver.ProcId)"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "86605fa9-bf1a-4c2c-87f5-cb656ebe4cf3"
- date = "2022-04-04"
- modified = "2022-04-04"
+ id = "e7932501-66bf-4713-b10e-bcda29f4b901"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_VulnDriver_ProcId.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "b03f26009de2e8eabfcf6152f49b02a55c5e5d0f73e01d48f5a745f93ce93a29"
- logic_hash = "882cdbd267d812e77e68e7080f1fca0ca3d7e75ab84c583c3ec148894b1cf644"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L117-L134"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "f82704a408a0cf1def2a5926dc4c02fa56afea1422c88ba41af50d44c60edb07"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "6d8d926efd98d6eaa1d06d39fb5babf70abf6f0e639fb74f29f65836a79e4743"
- severity = 50
+ tags = "FILE, MEMORY"
+ fingerprint = "ae31b49266386a6cf42289a08da4a20fc1330096be1dae793de7b7230225bfc7"
+ severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
- $str1 = "\\piddrv64.pdb"
+ $a = { 24 0C 01 00 00 00 85 C0 7C 2F 3B 46 24 7D 2A 8B 4E 20 8D 04 }
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $str1
+ all of them
}
-rule ELASTIC_Linux_Trojan_Xzbackdoor_74E87A9D : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_Cd0868D5 : FILE MEMORY
{
meta:
- description = "Detects Linux Trojan Xzbackdoor (Linux.Trojan.XZBackdoor)"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "74e87a9d-11c1-4e86-bb3c-63a3c51c50df"
- date = "2024-03-30"
- modified = "2024-04-03"
+ id = "cd0868d5-42d8-437f-8c1a-303526c08442"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_XZBackdoor.yar#L1-L23"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "5448850cdc3a7ae41ff53b433c2adbd0ff492515012412ee63a40d2685db3049"
- logic_hash = "c777171c36d9369ade7bf44c7cc4e5aee16bb4c803431bc480cc0f8ebb2819c0"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L136-L153"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "053a99e5e722fd2aa1cae96266cc344954f9c3a12d0851fa9d5e95a6420651f4"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "6ec0ee53f66167f7f2bbe5420aa474681701ed8f889aaad99e3990ecc4fb6716"
+ fingerprint = "2f777285a90fce20cd4eab203f3ec7ed1c62e09fc2dfdce09b57e0802f49628f"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $a1 = "yolAbejyiejuvnup=Evjtgvsh5okmkAvj"
- $a2 = { 0A 31 FD 3B 2F 1F C6 92 92 68 32 52 C8 C1 AC 28 34 D1 F2 C9 75 C4 76 5E B1 F6 88 58 88 93 3E 48 10 0C B0 6C 3A BE 14 EE 89 55 D2 45 00 C7 7F 6E 20 D3 2C 60 2B 2C 6D 31 00 }
- $b1 = { 48 8D 7C 24 08 F3 AB 48 8D 44 24 08 48 89 D1 4C 89 C7 48 89 C2 E8 ?? ?? ?? ?? 89 C2 }
- $b2 = { 31 C0 49 89 FF B9 16 00 00 00 4D 89 C5 48 8D 7C 24 48 4D 89 CE F3 AB 48 8D 44 24 48 }
- $b3 = { 4D 8B 6C 24 08 45 8B 3C 24 4C 8B 63 10 89 85 78 F1 FF FF 31 C0 83 BD 78 F1 FF FF 00 F3 AB 79 07 }
+ $a = { 8D 1C 01 89 54 24 10 8B 54 24 1C 33 C9 66 8B 0B 8D 3C 8A 8B 4C }
condition:
- 1 of ($a*) or all of ($b*)
+ all of them
}
-rule ELASTIC_Linux_Ransomware_Sfile_9E347B52 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_515504E2 : FILE MEMORY
{
meta:
- description = "Detects Linux Ransomware Sfile (Linux.Ransomware.SFile)"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "9e347b52-233a-4956-9f1f-7600c482e280"
- date = "2023-07-29"
- modified = "2024-02-13"
+ id = "515504e2-6b7f-4398-b89b-3af2b46c78a7"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Ransomware_SFile.yar#L1-L20"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "49473adedc4ee9b1252f120ad8a69e165dc62eabfa794370408ae055ec65db9d"
- logic_hash = "394571fd5746132d15da97428c3afc149435d91d5432eadf1c838d4a6433c7c1"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L155-L172"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "5410068e09de4a1283f98f6364ddf243373e228ba060b00699db6323f1167684"
score = 75
- quality = 71
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "094af0030d51d1e28405fc02a51ccc1bedf9e083b3d24b82c36f4b397eefbb0b"
+ fingerprint = "8eb741e1b3bd760e2cf511ad6609ac6f1f510958a05fb093eae26462f16ee1d0"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $a1 = { 49 74 27 73 20 6A 75 73 74 20 61 20 62 75 73 69 6E 65 73 73 2E }
- $a2 = { 41 6C 6C 20 64 61 74 61 20 69 73 20 70 72 6F 70 65 72 6C 79 20 70 72 6F 74 65 63 74 65 64 20 61 67 61 69 6E 73 74 20 75 6E 61 75 74 68 6F 72 69 7A 65 64 20 61 63 63 65 73 73 20 62 79 20 73 74 65 61 64 79 20 65 6E 63 72 79 70 74 69 6F 6E 20 74 65 63 68 6E 6F 6C 6F 67 79 2E }
+ $a = { 6A 00 6A 00 8D 4D E0 51 FF D6 85 C0 74 29 83 F8 FF 74 0C 8D }
condition:
all of them
}
-rule ELASTIC_Windows_Trojan_Farfli_85D1Bcc9 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_A0Fc8F35 : FILE MEMORY
{
meta:
- description = "Detects Windows Trojan Farfli (Windows.Trojan.Farfli)"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "85d1bcc9-c3c7-454c-a77f-0e0de933c4c3"
- date = "2022-02-17"
- modified = "2022-04-12"
+ id = "a0fc8f35-cbeb-43a8-b00d-7a0f981e84e4"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Trojan_Farfli.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "e3e9ea1b547cc235e6f1a78b4ca620c69a54209f84c7de9af17eb5b02e9b58c3"
- logic_hash = "746eb5a2583077189d82d1a96b499ff383f31220845bd8a6df5b7a7ceb11e6fb"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L174-L191"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "7ab2b45ddfc1d7fa409a6ea3dfd8d4940e1bdf3fc0cb6c7e8d49c60e7bda5b1b"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "56a5e4955556d08b80849ea5775f35f5a32999d6b5df92357ab142a4faa74ac3"
+ fingerprint = "033ff4f47fece45dfa7e3ba185df84a767691e56f0081f4ed96f9e2455a563cb"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -66598,57 +70499,55 @@ rule ELASTIC_Windows_Trojan_Farfli_85D1Bcc9 : FILE MEMORY
os = "windows"
strings:
- $a = { AB 66 AB C6 45 D4 25 C6 45 D5 73 C6 45 D6 5C C6 45 D7 25 C6 45 }
+ $a = { 18 33 DB 53 6A 01 53 53 8D 4C 24 34 51 8B F0 89 5C 24 38 FF D7 }
condition:
all of them
}
-rule ELASTIC_Multi_Generic_Threat_19854Dc2 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_Cb95Dc06 : FILE MEMORY
{
meta:
- description = "Detects Multi Generic Threat (Multi.Generic.Threat)"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "19854dc2-a568-4f6c-bd47-bcae9976c66f"
- date = "2024-02-21"
- modified = "2024-06-12"
+ id = "cb95dc06-6383-4487-bf10-7fd68d61e37a"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Multi_Generic_Threat.yar#L1-L19"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "be216fa9cbf0b64d769d1e8ecddcfc3319c7ca8e610e438dcdfefc491730d208"
- logic_hash = "beed6d6cd7b7b6eb3f4ab6a45fd19f2ebfb661e470d468691b68634994e2eef7"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L193-L210"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "563b2311d37ace2d09601a70325352db3fcbf135e7ce518965f5410081b5d626"
score = 75
- quality = 73
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "64d3803490fa71f720678ca2989cc698ea9b1a398d02d6d671fa01e0ff42f8b5"
- severity = 50
+ fingerprint = "0d28f570db007a1b91fe48aba18be7541531cceb7f11a6a4471e92abd55b3b90"
+ severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "multi"
+ os = "windows"
strings:
- $a1 = { 26 2A 73 74 72 75 63 74 20 7B 20 45 6E 74 72 79 53 61 6C 74 20 5B 5D 75 69 6E 74 38 3B 20 4C 65 6E 20 69 6E 74 20 7D }
+ $a = { 08 5F 5E 33 C0 5B 5D C3 8B 55 14 89 02 8B 45 18 5F 89 30 B9 01 00 }
condition:
all of them
}
-rule ELASTIC_Windows_Hacktool_Mimikatz_1388212A : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_9D4D3Fa4 : FILE MEMORY
{
meta:
- description = "Detects Windows Hacktool Mimikatz (Windows.Hacktool.Mimikatz)"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "1388212a-2146-4565-b93d-4555a110364f"
- date = "2021-04-13"
+ id = "9d4d3fa4-4e37-40d7-8399-a49130b7ef49"
+ date = "2021-03-28"
modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_Mimikatz.yar#L1-L43"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "66b4a0681cae02c302a9b6f1d611ac2df8c519d6024abdb506b4b166b93f636a"
- logic_hash = "1b717453810455e3f530e399f5f9f163d1ad0d71a5464fa5c68aa82edd699cda"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L212-L229"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "7c3c9917a95248fd990b6947a0304ded473bf1bcceec8f4498a7955e879d348b"
score = 75
- quality = 73
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "dbbdc492c07e3b95d677044751ee4365ec39244e300db9047ac224029dfe6ab7"
+ fingerprint = "b06c3c7ba1f5823ce381971ed29554e5ddbe327b197de312738165ee8bf6e194"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -66656,199 +70555,139 @@ rule ELASTIC_Windows_Hacktool_Mimikatz_1388212A : FILE MEMORY
os = "windows"
strings:
- $a1 = " Password: %s" wide fullword
- $a2 = " * Session Key : 0x%08x - %s" wide fullword
- $a3 = " * Injecting ticket : " wide fullword
- $a4 = " ## / \\ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )" wide fullword
- $a5 = "Remove mimikatz driver (mimidrv)" wide fullword
- $a6 = "mimikatz(commandline) # %s" wide fullword
- $a7 = " Password: %s" wide fullword
- $a8 = " - SCardControl(FEATURE_CCID_ESC_COMMAND)" wide fullword
- $a9 = " * to 0 will take all 'cmd' and 'mimikatz' process" wide fullword
- $a10 = "** Pass The Ticket **" wide fullword
- $a11 = "-> Ticket : %s" wide fullword
- $a12 = "Busylight Lync model (with bootloader)" wide fullword
- $a13 = "mimikatz.log" wide fullword
- $a14 = "Log mimikatz input/output to file" wide fullword
- $a15 = "ERROR kuhl_m_dpapi_masterkey ; kull_m_dpapi_unprotect_domainkey_with_key" wide fullword
- $a16 = "ERROR kuhl_m_lsadump_dcshadow ; unable to start the server: %08x" wide fullword
- $a17 = "ERROR kuhl_m_sekurlsa_pth ; GetTokenInformation (0x%08x)" wide fullword
- $a18 = "ERROR mimikatz_doLocal ; \"%s\" module not found !" wide fullword
- $a19 = "Install and/or start mimikatz driver (mimidrv)" wide fullword
- $a20 = "Target: %hhu (0x%02x - %s)" wide fullword
- $a21 = "mimikatz Ho, hey! I'm a DC :)" wide fullword
- $a22 = "mimikatz service (mimikatzsvc)" wide fullword
- $a23 = "[masterkey] with DPAPI_SYSTEM (machine, then user): " wide fullword
- $a24 = "$http://blog.gentilkiwi.com/mimikatz 0" ascii fullword
- $a25 = " * Username : %wZ" wide fullword
+ $a = { 89 44 24 18 33 C9 89 44 24 1C 8D 54 24 38 89 44 24 20 33 F6 89 44 }
condition:
- 3 of ($a*)
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Mimikatz_674Fd079 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_34F00046 : FILE MEMORY
{
meta:
- description = "Detection for default mimikatz memssp module"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "674fd079-f7fe-4d89-87e7-ac11aa21c9ed"
- date = "2021-04-14"
+ id = "34f00046-8938-4103-91ec-4a745a627d4a"
+ date = "2021-03-28"
modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_Mimikatz.yar#L45-L77"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "66b4a0681cae02c302a9b6f1d611ac2df8c519d6024abdb506b4b166b93f636a"
- logic_hash = "f63f3de05dd4f4f40cda6df67b75e37d7baa82c4b4cafd3ebdca35adfb0b15f8"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L231-L248"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "f9d646645d6726e3aac5cc3eaea9edf1c89c7e743aff7cfa73998a72f3446711"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "b8f71996180e5f03c10e39eb36b2084ecaff78d7af34bd3d0d75225d2cfad765"
- threat_name = "Windows.Hacktool.Mimikatz"
- severity = 99
+ fingerprint = "5c6f11e2a040ae32336f4b4c4717e0f10c73359899302b77e1803f3a609309c0"
+ severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
- $a1 = { 44 30 00 38 00 }
- $a2 = { 48 78 00 3A 00 }
- $a3 = { 4C 25 00 30 00 }
- $a4 = { 50 38 00 78 00 }
- $a5 = { 54 5D 00 20 00 }
- $a6 = { 58 25 00 77 00 }
- $a7 = { 5C 5A 00 5C 00 }
- $a8 = { 60 25 00 77 00 }
- $a9 = { 64 5A 00 09 00 }
- $a10 = { 6C 5A 00 0A 00 }
- $a11 = { 68 25 00 77 00 }
- $a12 = { 68 25 00 77 00 }
- $a13 = { 6C 5A 00 0A 00 }
- $b1 = { 6D 69 6D 69 C7 84 24 8C 00 00 00 6C 73 61 2E C7 84 24 90 00 00 00 6C 6F 67 }
+ $a = { 30 FF FF FF 03 08 8B 95 30 FF FF FF 2B D1 89 95 30 FF FF FF }
condition:
- all of ($a*) or $b1
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Mimikatz_355D5D3A : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_F2A18B09 : FILE MEMORY
{
meta:
- description = "Detection for Invoke-Mimikatz"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "355d5d3a-e50e-4614-9a84-0da668c40852"
- date = "2021-04-14"
+ id = "f2a18b09-f7b3-4d1a-87ab-3018f520b69c"
+ date = "2021-03-28"
modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_Mimikatz.yar#L79-L112"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "945245ca795e0a3575ee4fdc174df9d377a598476c2bf4bf0cdb0cde4286af96"
- logic_hash = "c6b48ab2cc92deb507d7eead1fb6381ee40b698e84d9eaac45288f95dbda66b3"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L250-L267"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "c4c4b0b1df1e8fde87284fb27d46e917c47b479a675fec60faeca6185511907d"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "9a23845ec9852d2490171af111612dc257a6b21ad7fdfd8bf22d343dc301d135"
- threat_name = "Windows.Hacktool.Mimikatz"
- severity = 90
+ fingerprint = "3e4474205efe22ea0185c49052e259bc08de8da7c924372f6eb984ae36b91a1c"
+ severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
- $a1 = "$PEBytes32 = \"TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACAEAAA4fug4AtAnNIbgBTM0hVGhpcyBwc"
- $a2 = "$PEBytes64 = \"TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEAEAAA4fug4AtAnNIbgBTM0hVGhpcyBwc"
- $b1 = "Write-BytesToMemory -Bytes $Shellcode"
- $b2 = "-MemoryAddress $GetCommandLineWAddrTemp"
- $b3 = "-MemoryAddress $GetCommandLineAAddrTemp"
- $c1 = "Invoke-Command -ScriptBlock $RemoteScriptBlock -ArgumentList @($PEBytes64, $PEBytes32, \"Void\", 0, \"\", $ExeArgs)" fullword
- $c2 = "Invoke-Command -ScriptBlock $RemoteScriptBlock -ArgumentList @($PEBytes64, $PEBytes32, \"Void\", 0, \"\", $ExeArgs) -ComputerNam"
- $c3 = "at: http://blog.gentilkiwi.com"
- $c4 = "on the local computer to dump certificates."
- $c5 = "Throw \"Unable to write shellcode to remote process memory.\"" fullword
- $c6 = "-Command \"privilege::debug exit\" -ComputerName \"computer1\""
- $c7 = "dump credentials without"
- $c8 = "#The shellcode writes the DLL address to memory in the remote process at address $LoadLibraryARetMem, read this memory" fullword
- $c9 = "two remote computers to dump credentials."
- $c10 = "#If a remote process to inject in to is specified, get a handle to it" fullword
+ $a = { 04 39 45 08 75 08 8B 4D F8 8B 41 18 EB 0F 8B 55 F8 8B 02 89 }
condition:
- (1 of ($a*) or 2 of ($b*)) or 5 of ($c*)
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Mimikatz_71Fe23D9 : FILE
+rule ELASTIC_Windows_Trojan_Trickbot_D916Ae65 : FILE MEMORY
{
meta:
- description = "Subject: Benjamin Delpy"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "71fe23d9-ee1a-47fb-a99f-2be2eb9ccb1a"
- date = "2022-04-07"
- modified = "2022-04-07"
+ id = "d916ae65-c97b-495c-89c2-4f1ec90081d2"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_Mimikatz.yar#L114-L133"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "856687718b208341e7caeea2d96da10f880f9b5a75736796a1158d4c8755f678"
- logic_hash = "6d1e84bb8532c6271ad3966055eac8d60ec019d8ae6632efb59463c35b46ad9b"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L269-L286"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "e0aafe498cd9f0e8addfef78027943a754ca797aafae0cb40f1c6425de501339"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "22b1f36e82e604fc3a80bb5abf87aef59957b1ceeb050eea3c9e85fb0b937db1"
- threat_name = "Windows.Hacktool.Mimikatz"
+ tags = "FILE, MEMORY"
+ fingerprint = "2e109ed59a1e759ef089e04c21016482bf70228da30d8b350fc370b4e4d120e0"
severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
- $subject_name = { 06 03 55 04 03 [2] 42 65 6E 6A 61 6D 69 6E 20 44 65 6C 70 79 }
+ $a = { 5F 24 01 10 CF 22 01 10 EC 22 01 10 38 23 01 10 79 23 01 10 82 }
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $subject_name
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Mimikatz_B393864F : FILE
+rule ELASTIC_Windows_Trojan_Trickbot_52722678 : FILE MEMORY
{
meta:
- description = "Subject: Open Source Developer, Benjamin Delpy"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "b393864f-a9b0-47e7-aea4-0fc5a4a22a82"
- date = "2022-04-07"
- modified = "2022-04-07"
+ id = "52722678-afbe-43ec-a39b-6848b7d49488"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_Mimikatz.yar#L135-L154"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "8206ce9c42582ac980ff5d64f8e3e310bc2baa42d1a206dd831c6ab397fbd8fe"
- logic_hash = "d09cb7f753675e0b6ecd8a7977ca7f8d313e5d525f05170fc54b265c2ae6c188"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L288-L305"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "6340171fdde68b32de480f1f410aa4c491a8fffa7c1f699bf5fa72a12ecb77b8"
score = 75
quality = 75
- tags = "FILE"
- fingerprint = "bfd497290db97b7578d59e8d43a28ee736a3d7d23072eb67d28ada85cac08bd3"
- threat_name = "Windows.Hacktool.Mimikatz"
+ tags = "FILE, MEMORY"
+ fingerprint = "e67dda5227be74424656957843777ea533b6800576fd85f978fd8fb50504209c"
severity = 100
arch_context = "x86"
- scan_context = "file"
+ scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
- $subject_name = { 06 03 55 04 03 [2] 4F 70 65 6E 20 53 6F 75 72 63 65 20 44 65 76 65 6C 6F 70 65 72 2C 20 42 65 6E 6A 61 6D 69 6E 20 44 65 6C 70 79 }
+ $a = { 2B 5D 0C 89 5D EC EB 03 8B 5D EC 8A 1C 3B 84 DB 74 0D 38 1F }
condition:
- int16 ( uint32(0x3C)+0x5c)==0x0001 and $subject_name
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Mimikatz_1Ff74F7E : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_28A60148 : FILE MEMORY
{
meta:
- description = "Detects Windows Hacktool Mimikatz (Windows.Hacktool.Mimikatz)"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "1ff74f7e-ec5a-45ae-b51b-2f8205445cc8"
- date = "2023-05-09"
- modified = "2023-06-13"
+ id = "28a60148-2efb-4cd2-ada1-dd2ae2699adf"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_Mimikatz.yar#L156-L175"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "1b6aad500d45de7b076942d31b7c3e77487643811a335ae5ce6783368a4a5081"
- logic_hash = "f47f760b4c373a073399c69681e76eb9dde6cfdb36c1cc31d7131376493931c0"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L307-L324"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "20a26ed3f0da3a77867597494bf0069a2093ec19b1c5e179c0e7934c1b69d4b9"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "6775be439ad1822bcaa04ed2d392143616746cfd674202aa29773c98642346f4"
+ fingerprint = "c857aa792ef247bfcf81e75fb696498b1ba25c09fc04049223a6dfc09cc064b1"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -66856,29 +70695,27 @@ rule ELASTIC_Windows_Hacktool_Mimikatz_1Ff74F7E : FILE MEMORY
os = "windows"
strings:
- $a1 = { 74 65 48 8B 44 24 28 0F B7 80 E0 00 00 00 83 F8 10 75 54 48 8B 44 }
- $a2 = { 74 69 48 8B 44 24 28 0F B7 80 D0 00 00 00 83 F8 10 75 58 48 8B 44 }
+ $a = { C0 31 E8 83 7D 0C 00 89 44 24 38 0F 29 44 24 20 0F 29 44 24 10 0F 29 }
condition:
all of them
}
-rule ELASTIC_Windows_Ransomware_Blackbasta_494D3C54 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_997B25A0 : FILE MEMORY
{
meta:
- description = "Detects Windows Ransomware Blackbasta (Windows.Ransomware.BlackBasta)"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "494d3c54-4690-4334-b64d-ebeeb305de0e"
- date = "2022-08-06"
- modified = "2022-08-16"
+ id = "997b25a0-aeac-4f74-aa87-232c4f8329b6"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_BlackBasta.yar#L1-L27"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "357fe8c56e246ffacd54d12f4deb9f1adb25cb772b5cd2436246da3f2d01c222"
- logic_hash = "1ecb3c95a2d3f91d267f0b625fffc8477612fde9de3942eff8eb13115c0af6b8"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L326-L343"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "ca688086c4628c64c32a99083d620bcb5373e3100d154331451a3e9f86081aca"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "27602cb05c054a1aa9e27b91675d57707f4a63fa91badc83ad86229839778f4e"
+ fingerprint = "0bba1c5284ed0548f51fdfd6fb96e24f92f7f4132caefbf0704efb0b1a64b7c4"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -66886,36 +70723,27 @@ rule ELASTIC_Windows_Ransomware_Blackbasta_494D3C54 : FILE MEMORY
os = "windows"
strings:
- $a1 = "Done time: %.4f seconds, encrypted: %.4f gb" ascii fullword
- $a2 = "Creating readme at %s" wide fullword
- $a3 = "All of your files are currently encrypted by no_name_software." ascii fullword
- $a4 = "DON'T move or rename your files. These parameters can be used for encryption/decryption process." ascii fullword
- $b1 = "Your data are stolen and encrypted" ascii fullword
- $b2 = "bcdedit /deletevalue safeboot" ascii fullword
- $b3 = "Your company id for log in:"
- $byte_seq = { 0F AF 45 DC 8B CB 0F AF 4D DC 0F AF 5D D8 0F AF 55 D8 8B F9 }
- $byte_seq2 = { 18 FF 24 1E 18 FF 64 61 5D FF CF CF CF FF D0 D0 D0 FF D0 D0 D0 FF }
+ $a = { 85 D2 74 F0 C6 45 E1 20 8D 4D E1 C6 45 E2 4A C6 45 E3 4A C6 45 }
condition:
- 4 of them
+ all of them
}
-rule ELASTIC_Windows_Hacktool_Coffloader_81Ba13B8 : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_B17B33A1 : FILE MEMORY
{
meta:
- description = "Detects Windows Hacktool Coffloader (Windows.Hacktool.COFFLoader)"
+ description = "Detects Windows Trojan Trickbot (Windows.Trojan.Trickbot)"
author = "Elastic Security"
- id = "81ba13b8-8994-4fe9-98e5-44514c554e8b"
- date = "2024-04-22"
- modified = "2024-05-08"
+ id = "b17b33a1-1021-4980-8ffd-2e7aa4ca2ae4"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Hacktool_COFFLoader.yar#L1-L43"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "c2e03659eb1594dc958e01344cfa9ba126d66736b089db5e3dd1b1c3e3e7d2f7"
- logic_hash = "d4f061af200a0ae9f3276fd6dfcb09ecdf662f29b7c43ea47c69a53d9fe66793"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L345-L362"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ logic_hash = "7fa69674d1e985bafe310597f23ae80113136768141f0a1931baf88b2509e6ef"
score = 75
- quality = 73
+ quality = 75
tags = "FILE, MEMORY"
- fingerprint = "ef9f11d9cd6c3b46f7d13ea039dcad6fa24515495466b1102ec8c1c8bed8853e"
+ fingerprint = "753d15c1ff0cc4cf75250761360bb35280ff0a1a4d34320df354e0329dd35211"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -66923,52 +70751,29 @@ rule ELASTIC_Windows_Hacktool_Coffloader_81Ba13B8 : FILE MEMORY
os = "windows"
strings:
- $a1 = "BeaconDataParse" ascii fullword
- $a2 = "BeaconDataInt" ascii fullword
- $a3 = "BeaconDataShort" ascii fullword
- $a4 = "BeaconDataLength" ascii fullword
- $a5 = "BeaconDataExtract" ascii fullword
- $a6 = "BeaconFormatAlloc" ascii fullword
- $a7 = "BeaconFormatReset" ascii fullword
- $a8 = "BeaconFormatFree" ascii fullword
- $a9 = "BeaconFormatAppend" ascii fullword
- $a10 = "BeaconFormatPrintf" ascii fullword
- $a11 = "BeaconFormatToString" ascii fullword
- $a12 = "BeaconFormatInt" ascii fullword
- $a13 = "BeaconPrintf" ascii fullword
- $a14 = "BeaconOutput" ascii fullword
- $a15 = "BeaconUseToken" ascii fullword
- $a16 = "BeaconRevertToken" ascii fullword
- $a17 = "BeaconDataParse" ascii fullword
- $a18 = "BeaconIsAdmin" ascii fullword
- $a19 = "BeaconGetSpawnTo" ascii fullword
- $a20 = "BeaconSpawnTemporaryProcess" ascii fullword
- $a21 = "BeaconInjectProcess" ascii fullword
- $a22 = "BeaconInjectTemporaryProcess" ascii fullword
- $a23 = "BeaconCleanupProcess" ascii fullword
- $b1 = "COFFLoader.x64.dll"
- $b2 = "COFFLoader.x86.dll"
+ $a = { 08 53 55 56 57 64 A1 30 00 00 00 89 44 24 10 8B 44 24 10 8B }
condition:
- 5 of ($a*) or 1 of ($b*)
+ all of them
}
-rule ELASTIC_Windows_Ransomware_Akira_C8C298Ba : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_23D77Ae5 : FILE MEMORY
{
meta:
- description = "Detects Windows Ransomware Akira (Windows.Ransomware.Akira)"
+ description = "Targets importDll64 containing Browser data stealer module"
author = "Elastic Security"
- id = "c8c298ba-2760-4880-a54a-3d916049d0ab"
- date = "2024-05-02"
- modified = "2024-05-08"
+ id = "23d77ae5-80de-4bb0-8701-ddcaff443dcc"
+ date = "2021-03-28"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Ransomware_Akira.yar#L1-L24"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- hash = "a2df5477cf924bd41241a3326060cc2f913aff2379858b148ddec455e4da67bc"
- logic_hash = "9058c83693e93f6daee8894453e56e0d9a4867d551ec3a6b66d7a517f65d8b07"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L364-L396"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "844974a2d3266e1f9ba275520c0e8a5d176df69a0ccd5135b99facf798a5d209"
+ logic_hash = "e5f5cf854ebd0e25fffbd6796217f22223a06937e1cacb33baa105ac41731256"
score = 75
quality = 75
tags = "FILE, MEMORY"
- fingerprint = "81c6dfa172ce7f4254e3cc74fcb71786336d39438d6e9379f7611495f54227c9"
+ fingerprint = "d382a99e5eed87cf2eab5e238e445ca0bf7852e40b0dd06a392057e76144699f"
+ threat_name = "Windows.Trojan.Trickbot"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
@@ -66976,89 +70781,123 @@ rule ELASTIC_Windows_Ransomware_Akira_C8C298Ba : FILE MEMORY
os = "windows"
strings:
- $a1 = "akira_readme.txt" ascii fullword
- $a2 = "Number of threads to encrypt = " ascii fullword
- $a3 = "write_encrypt_info error:" ascii fullword
- $a4 = "Log-%d-%m-%Y-%H-%M-%S" ascii fullword
- $a5 = "--encryption_path" wide fullword
- $a6 = "--encryption_percent" wide fullword
+ $a1 = "/system32/cmd.exe /c \"start microsoft-edge:{URL}\"" ascii fullword
+ $a2 = "SELECT name, value, host_key, path, expires_utc, creation_utc, encrypted_value FROM cookies" ascii fullword
+ $a3 = "attempt %d. Cookies not found" ascii fullword
+ $a4 = "attempt %d. History not found" ascii fullword
+ $a5 = "Cookies version is %d (%d)" ascii fullword
+ $a6 = "attempt %d. Local Storage not found" ascii fullword
+ $a7 = "str+='xie.com.'+p+'.guid='+'{'+components[i]+'}\\n';" ascii fullword
+ $a8 = "Browser exec is: %s" ascii fullword
+ $a9 = "found mozilla key: %s" ascii fullword
+ $a10 = "Version %d is not supported" ascii fullword
+ $a11 = "id %d - %s" ascii fullword
+ $a12 = "prot: %s, scope: %s, port: %d" ascii fullword
+ $a13 = "***** Send %d bytes to callback from %s *****" ascii fullword
+ $a14 = "/chrome.exe {URL}" ascii fullword
condition:
- 3 of them
+ 4 of ($a*)
}
-rule ELASTIC_Linux_Trojan_Marut_47Af730D : FILE MEMORY
+rule ELASTIC_Windows_Trojan_Trickbot_5574Be7D : FILE MEMORY
{
meta:
- description = "Detects Linux Trojan Marut (Linux.Trojan.Marut)"
+ description = "Targets injectDll64 containing injection functionality to steal banking credentials"
author = "Elastic Security"
- id = "47af730d-1e03-4d27-9661-84fb12b593bd"
- date = "2021-01-12"
- modified = "2021-09-16"
+ id = "5574be7d-7502-4357-8110-2fb4a661b2bd"
+ date = "2021-03-29"
+ modified = "2021-08-23"
reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Linux_Trojan_Marut.yar#L1-L18"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "048ce8059be6697c5f507fb1912ac2adcedab87c75583dd84700984e6d0d81e6"
+ source_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/yara/rules/Windows_Trojan_Trickbot.yar#L398-L432"
+ license_url = "https://github.com/elastic/protections-artifacts//blob/9f0d93c3c4b1ed8d822c467cfdabfa157721b9bd/LICENSE.txt"
+ hash = "8c5c0d27153f60ef8aec57def2f88e3d5f9a7385b5e8b8177bab55fa7fac7b18"
+ logic_hash = "ed0fc98c5d628ce38b923e1410eaf7a4a65ecffea42bed35314e30c99a52219b"
score = 75
- quality = 75
+ quality = 50
tags = "FILE, MEMORY"
- fingerprint = "4429ef9925aff797ab973f9a5b0efc160a516f425e3b024f22e5a5ddad26c341"
+ fingerprint = "23d9b89917a0fc5aad903595b89b650f6dbb0f82ce28ce8bcc891904f62ccf1b"
+ threat_name = "Windows.Trojan.Trickbot"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
- os = "linux"
+ os = "windows"
strings:
- $a = { 20 89 34 24 FF D1 8B 44 24 0C 0F B6 4C 24 04 8B 54 24 08 85 D2 }
+ $a1 = "webinject64.dll" ascii fullword
+ $a2 = "Mozilla Firefox version: %s" ascii fullword
+ $a3 = "socks=127.0.0.1:" ascii fullword
+ $a4 = "
UserName : " wide ascii
+ $html_pc_name = "
PC Name : " wide ascii
+ $html_os_name = "
OS Full Name : " wide ascii
+ $html_os_platform = "
OS Platform : " wide ascii
+ $html_clipboard = "
[clipboard]" wide ascii
condition:
- all of them
+ 3 of them
}
-rule ELASTIC_Windows_Shellcode_Generic_8C487E57 : FILE MEMORY
+rule CAPE_Agenttesla : FILE
{
meta:
- description = "Detects Windows Shellcode Generic (Windows.Shellcode.Generic)"
- author = "Elastic Security"
- id = "8c487e57-4b8c-488e-a1d9-786ff935fd2c"
- date = "2022-05-23"
- modified = "2022-07-18"
- reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Shellcode_Generic.yar#L1-L18"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "a86ea8e15248e83ce7322c10e308a5a24096b1d7c67f5673687563dec8229dfe"
+ description = "AgentTesla Payload"
+ author = "kevoreilly"
+ id = "f7b930f1-cecb-5d80-809b-9503f282247a"
+ date = "2024-03-22"
+ modified = "2024-03-22"
+ reference = "https://github.com/kevoreilly/CAPEv2"
+ source_url = "https://github.com/kevoreilly/CAPEv2/blob/925ba96aba58057b1d1bae119063fdf41bc0c506/data/yara/CAPE/AgentTesla.yar#L19-L41"
+ license_url = "https://github.com/kevoreilly/CAPEv2/blob/925ba96aba58057b1d1bae119063fdf41bc0c506/LICENSE"
+ logic_hash = "1bf9b26c4cf87e674ddffabe40aba5a45499c6a04d4ff3e43c3cda4cbcb4d188"
score = 75
- quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "834caf96192a513aa93ac48fb8d2f3326bf9f08acaf7a27659f688b26e3e57e4"
- severity = 100
- arch_context = "x86"
- scan_context = "file, memory"
- license = "Elastic License v2"
- os = "windows"
+ quality = 70
+ tags = "FILE"
+ cape_type = "AgentTesla Payload"
strings:
- $a = { FC E8 89 00 00 00 60 89 E5 31 D2 64 8B 52 30 8B 52 0C 8B 52 14 8B 72 28 0F B7 4A 26 31 FF 31 C0 }
+ $string1 = "smtp" wide
+ $string2 = "appdata" wide
+ $string3 = "76487-337-8429955-22614" wide
+ $string4 = "yyyy-MM-dd HH:mm:ss" wide
+ $string6 = "webpanel" wide
+ $string7 = "
UserName :" wide
+ $string8 = "
IP Address :" wide
+ $agt1 = "IELibrary.dll" ascii
+ $agt2 = "C:\\Users\\Admin\\Desktop\\IELibrary\\IELibrary\\obj\\Debug\\IELibrary.pdb" ascii
+ $agt3 = "GetSavedPasswords" ascii
+ $agt4 = "GetSavedCookies" ascii
condition:
- all of them
+ uint16(0)==0x5A4D and ( all of ($string*) or 3 of ($agt*))
}
-rule ELASTIC_Windows_Shellcode_Generic_F27D7Beb : FILE MEMORY
+rule CAPE_Agentteslav2 : FILE
{
meta:
- description = "Detects Windows Shellcode Generic (Windows.Shellcode.Generic)"
- author = "Elastic Security"
- id = "f27d7beb-5ce0-4831-b1ad-320b346612c3"
- date = "2022-06-08"
- modified = "2022-09-29"
- reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Shellcode_Generic.yar#L20-L37"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "8530a74a002d0286711cd86545aff0bf853de6b6684473b6211d678797c3639f"
+ description = "AgenetTesla Type 2 Keylogger payload"
+ author = "ditekshen"
+ id = "e60ecee4-0a97-56a1-b21e-47190f8cd1f8"
+ date = "2024-03-22"
+ modified = "2024-03-22"
+ reference = "https://github.com/kevoreilly/CAPEv2"
+ source_url = "https://github.com/kevoreilly/CAPEv2/blob/925ba96aba58057b1d1bae119063fdf41bc0c506/data/yara/CAPE/AgentTesla.yar#L43-L67"
+ license_url = "https://github.com/kevoreilly/CAPEv2/blob/925ba96aba58057b1d1bae119063fdf41bc0c506/LICENSE"
+ logic_hash = "b45296b3b94fa1ff32de48c94329a17402461fb6696e9390565c4dba9738ed78"
score = 75
- quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "3f8dd6733091ec229e1bebe9e4cd370ad47ab2e3678be4c2d9c450df731a6e5c"
- severity = 100
- arch_context = "x86"
- scan_context = "file, memory"
- license = "Elastic License v2"
- os = "windows"
+ quality = 70
+ tags = "FILE"
+ cape_type = "AgentTesla Payload"
strings:
- $a = { 53 48 89 E3 66 83 E4 00 48 B9 [8] BA 01 00 00 00 41 B8 00 00 00 00 48 B8 [8] FF D0 48 89 DC 5B C3 }
+ $s1 = "get_kbHook" ascii
+ $s2 = "GetPrivateProfileString" ascii
+ $s3 = "get_OSFullName" ascii
+ $s4 = "get_PasswordHash" ascii
+ $s5 = "remove_Key" ascii
+ $s6 = "FtpWebRequest" ascii
+ $s7 = "logins" fullword wide
+ $s8 = "keylog" fullword wide
+ $s9 = "1.85 (Hash, version 2, native byte-order)" wide
+ $cl1 = "Postbox" fullword ascii
+ $cl2 = "BlackHawk" fullword ascii
+ $cl3 = "WaterFox" fullword ascii
+ $cl4 = "CyberFox" fullword ascii
+ $cl5 = "IceDragon" fullword ascii
+ $cl6 = "Thunderbird" fullword ascii
condition:
- all of them
+ ( uint16(0)==0x5a4d and 6 of ($s*)) or (6 of ($s*) and 2 of ($cl*))
}
-rule ELASTIC_Windows_Shellcode_Generic_29Dcbf7A : FILE MEMORY
+rule CAPE_Agentteslav3 : FILE
{
meta:
- description = "Detects Windows Shellcode Generic (Windows.Shellcode.Generic)"
- author = "Elastic Security"
- id = "29dcbf7a-2d3b-4e05-a2be-15623bf62d06"
- date = "2023-05-09"
- modified = "2023-06-13"
- reference = "https://github.com/elastic/protections-artifacts/"
- source_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/yara/rules/Windows_Shellcode_Generic.yar#L39-L56"
- license_url = "https://github.com/elastic/protections-artifacts//blob/9038ed0994941166ede4355ee47e1ae8467ce23e/LICENSE.txt"
- logic_hash = "c2a81cc27e696a2e488df7d2f96784bbaed83df5783efab312fc5ccbfd524b43"
+ description = "AgentTeslaV3 infostealer payload"
+ author = "ditekshen"
+ id = "cfe00382-8663-54a4-a7c4-b932ec7ad5e3"
+ date = "2024-03-22"
+ modified = "2024-03-22"
+ reference = "https://github.com/kevoreilly/CAPEv2"
+ source_url = "https://github.com/kevoreilly/CAPEv2/blob/925ba96aba58057b1d1bae119063fdf41bc0c506/data/yara/CAPE/AgentTesla.yar#L69-L111"
+ license_url = "https://github.com/kevoreilly/CAPEv2/blob/925ba96aba58057b1d1bae119063fdf41bc0c506/LICENSE"
+ logic_hash = "26c4fa0ce8de6982eb599f3872e8ab2a6e83da4741db7f3500c94e0a8fe5d459"
score = 75
- quality = 75
- tags = "FILE, MEMORY"
- fingerprint = "e4664ec7bf7dab3fff873fe4b059e97d2defe3b50e540b96dd98481638dcdcd8"
- severity = 100
- arch_context = "x86"
- scan_context = "file, memory"
- license = "Elastic License v2"
- os = "windows"
+ quality = 68
+ tags = "FILE"
+ cape_type = "AgentTesla payload"
strings:
- $a1 = { FC 48 83 E4 F0 41 57 41 56 41 55 41 54 55 53 56 57 48 83 EC 40 48 83 EC 40 48 83 EC 40 48 89 E3 }
+ $s1 = "get_kbok" fullword ascii
+ $s2 = "get_CHoo" fullword ascii
+ $s3 = "set_passwordIsSet" fullword ascii
+ $s4 = "get_enableLog" fullword ascii
+ $s5 = "bot%telegramapi%" wide
+ $s6 = "KillTorProcess" fullword ascii
+ $s7 = "GetMozilla" ascii
+ $s8 = "torbrowser" wide
+ $s9 = "%chatid%" wide
+ $s10 = "logins" fullword wide
+ $s11 = "credential" fullword wide
+ $s12 = "AccountConfiguration+" wide
+ $s13 = "Stop take screenshot
" ascii wide
+ $c1 = "http://23.227.196.215/" ascii wide
+ $c2 = "http://apple-iclods.org/" ascii wide
+ $c3 = "http://apple-checker.org/" ascii wide
+ $c4 = "http://apple-uptoday.org/" ascii wide
+ $c5 = "http://apple-search.info" ascii wide
+ $d1 = "watch/?" fullword ascii wide
+ $d2 = "search/?" fullword ascii wide
+ $d3 = "find/?" fullword ascii wide
+ $d4 = "results/?" fullword ascii wide
+ $d5 = "open/?" fullword ascii wide
+ $d6 = "search/?" fullword ascii wide
+ $d7 = "close/?" fullword ascii wide
+ $e1 = "itwm=" fullword ascii wide
+ $e2 = "text=" fullword ascii wide
+ $e3 = "from=" fullword ascii wide
+ $e4 = "itwm=" fullword ascii wide
+ $e5 = "ags=" fullword ascii wide
+ $e6 = "btnG=" fullword ascii wide
+ $e7 = "oprnd=" fullword ascii wide
+ $e8 = "itwm=" fullword ascii wide
+ $e9 = "utm=" fullword ascii wide
+ $e10 = "channel=" fullword ascii wide
condition:
- uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550 and 2 of ($Card_Hash*) and all of ($Code_Bytes*) and filesize <400KB and ($Service in (0x2f000..0x30000))
+ BINARYALERT_Macho_PRIVATE and (5 of ($a*) or any of ($b*) or any of ($c*) or 4 of ($d*) or 5 of ($e*))
}
-import "pe"
-
-rule R3C0NST_ATM_CINEO4060_Blackbox : FILE
+rule BINARYALERT_Malware_Macos_Marten4N6_Evilosx
{
meta:
- description = "Detects Malware samples for Diebold Nixdorf CINEO 4060 ATMs used in blackboxing attacks across Europe since May 2021"
- author = "Frank Boldewin (@r3c0nst)"
- id = "8fa26e1c-2931-59c8-9cec-20dc6684b8d6"
- date = "2021-05-25"
- modified = "2022-06-21"
- reference = "https://twitter.com/r3c0nst/status/1539036442516660224"
- source_url = "https://github.com/fboldewin/YARA-rules//blob/54e9e6899b258b72074b2b4db6909257683240c2/ATM_CINEO4060_Blackbox.yar#L3-L27"
- license_url = "N/A"
- logic_hash = "80b919d03c1b9a198611994eaf2fafaf8254c73a6f0edb53b2b3eb90ea70d915"
+ description = "EvilOSX is a pure python, post-exploitation, RAT (Remote Administration Tool) for macOS / OSX."
+ author = "@mimeframe"
+ id = "2b2e62ca-f95c-55c5-aaf6-985aab49dfbb"
+ date = "2017-09-12"
+ modified = "2017-09-12"
+ reference = "https://github.com/Marten4n6/EvilOSX"
+ source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/malware/macos/malware_macos_marten4n6_evilosx.yara#L1-L16"
+ license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
+ logic_hash = "3402ebf34fd507d0c317416bf77bb3d51b67c8b0f099ce68d15ade6a6a2e302a"
score = 75
- quality = 90
- tags = "FILE"
+ quality = 80
+ tags = ""
strings:
- $MyAgent1 = "javaagentsdemo/ClassListingTransformer.class" ascii fullword
- $MyAgent2 = "javaagentsdemo/MyUtils.class" ascii fullword
- $MyAgent3 = "javaagentsdemo/SimplestAgent.class" ascii fullword
- $Hook = "### [HookAPI]: Switching context!" fullword ascii
- $Delphi = "Borland\\Delphi\\RTL" fullword ascii
- $WMIHOOK1 = "TPM_SK.DLL" fullword ascii
- $WMIHOOK2 = "GetPCData" fullword ascii
- $WMIHOOK3 = {60 9C A3 E4 2B 41 00 E8 ?? ?? ?? ?? 9D 61 B8 02 00 00 00 C3}
- $TRICK1 = "USERAUTH.DLL" fullword ascii
- $TRICK2 = "GetAllSticksByID" fullword ascii
- $TRICK3 = {6A 06 8B 45 FC 8B 00 B1 4F BA 1C 00 00 00}
+ $a1 = "icloud_phish_stop" fullword wide ascii
+ $a2 = "icloud_contacts" fullword wide ascii
+ $a3 = "itunes_backups" fullword wide ascii
+ $a4 = "chrome_passwords" fullword wide ascii
+ $a5 = "Starting EvilOSX..." wide ascii
condition:
- ( uint16(0)==0x4b50 and filesize <50KB and all of ($MyAgent*)) or ( uint16(0)==0x5A4D and (pe.characteristics&pe.DLL) and $Hook and $Delphi and all of ($WMIHOOK*) or all of ($TRICK*))
+ 4 of ($a*)
}
-rule R3C0NST_Exploit_Outlook_CVE_2023_23397 : CVE_2023_23397 FILE
+rule BINARYALERT_Malware_Macos_Neoneggplant_Eggshell
{
meta:
- description = "Detects Outlook appointments exploiting CVE-2023-23397"
- author = "Frank Boldewin"
- id = "7e355e5f-93ca-561d-9a12-f73f1d429e4d"
- date = "2023-03-19"
- modified = "2023-03-25"
- reference = "https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/"
- source_url = "https://github.com/fboldewin/YARA-rules//blob/54e9e6899b258b72074b2b4db6909257683240c2/Exploit_Outlook_CVE_2023_23397.yar#L1-L30"
- license_url = "N/A"
- logic_hash = "1847e8223b2f6d3ec5108e15ee46ef031ee1e26d3a5e8ed4a70c77b031f6a5b6"
- score = 75
- quality = 86
- tags = "CVE-2023-23397, FILE"
- Author = "Frank Boldewin (@r3c0nst)"
- Hash1 = "078b5023cae7bd784a84ec4ee8df305ee7825025265bf2ddc1f5238c3e432f5f"
- Hash2 = "a034427fd8524fd62380c881c30b9ab483535974ddd567556692cffc206809d1"
- Hash3 = "e7a1391dd53f349094c1235760ed0642519fd87baf740839817d47488b9aef02"
- Hash4 = "1543677037fa339877e1d6ef2d077f94613afbcd6434d7181a18df74aca7742b"
+ description = "EggShell is an iOS and macOS post exploitation surveillance pentest tool written in Python."
+ author = "@mimeframe"
+ id = "274a34cc-9403-50e6-aa64-683a41bc30e6"
+ date = "2017-09-12"
+ modified = "2017-09-12"
+ reference = "https://github.com/neoneggplant/EggShell"
+ source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/malware/macos/malware_macos_neoneggplant_eggshell.yara#L1-L24"
+ license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
+ logic_hash = "34906db9398313ccb84e67bd98e94324c628aefe3efa6ba3cca2df042b42cbe7"
+ score = 50
+ quality = 80
+ tags = ""
strings:
- $ipmtask = "IPM.Task" wide ascii
- $ipmappointment = "IPM.Appointment" wide ascii
- $ipmtaskb64 = "IPM.Task" base64 base64wide
- $ipmappointmentb64 = "IPM.Appointment" base64 base64wide
- $unc_path1 = { 5C 00 5C 00 (3? 00 2E|3? 00 3? 00 2E|3? 00 3? 00 3? 00 2E) 00 (3? 00 2E|3? 00 3? 00 2E|3? 00 3? 00 3? 00 2E) 00 (3? 00 2E|3? 00 3? 00 2E|3? 00 3? 00 3? 00 2E) 00 (3? 00|3? 00 3? 00|3? 00 3? 00 3? 00) }
- $unc_path2 = { 5C 5C (3? 2E|3? 3? 2E|3? 3? 3? 2E) (3? 2E|3? 3? 2E|3? 3? 3? 2E) (3? 2E|3? 3? 2E|3? 3? 3? 2E) (3?|3? 3?|3? 3? 3?) }
- $unc_a = "\x00\x00\x00\x5c\x5c" base64
- $unc_w = "\x00\x00\x5c\x00\x5c" base64wide
- $mail1 = "from:" ascii wide nocase
- $mail2 = "received:" ascii wide nocase
+ $a1 = "Created By Lucas Jackson (@neoneggplant)" wide ascii
+ $a2 = "SET LHOST (Leave blank for" wide ascii
+ $a3 = "SET LPORT (Leave blank for" wide ascii
+ $b1 = "/tmp/.esplog" wide ascii
+ $b2 = "spGHbigdxMBJpbOCAr3rnS3inCdYQyZV" wide ascii
+ $b3 = "keylogclear" wide ascii
+ $b4 = "getpasscode" wide ascii
+ $c1 = "spGHbigdxMBJpbOCAr3rnS3inCdYQyZV" wide ascii
+ $c2 = "getfacebook" wide ascii
+ $c3 = "type is eggsu" wide ascii
+ $c4 = "rmpersistence" wide ascii
condition:
- (( uint32be(0)==0xD0CF11E0 or uint32be(0)==0x789F3E22) or ( all of ($mail*))) and (($ipmtask or $ipmappointment) or ($ipmtaskb64 or $ipmappointmentb64)) and (($unc_path1 or $unc_path2) or ($unc_a or $unc_w))
+ all of ($a*) or 3 of ($b*) or 3 of ($c*)
}
-import "hash"
+import "pe"
-rule R3C0NST_ATM_Malware_Atmspitter : FILE
+rule BINARYALERT_Malware_Macos_Macspy : FILE
{
meta:
- description = "Detects ATM Malware ATMSpitter"
- author = "Frank Boldewin (@r3c0nst)"
- id = "4497f304-6f04-5f5d-91ba-9124e5262078"
- date = "2016-07-20"
- modified = "2019-03-29"
- reference = "https://topics.amcham.com.tw/2017/02/looking-back-at-the-first-banks-atm-heist/"
- source_url = "https://github.com/fboldewin/YARA-rules//blob/54e9e6899b258b72074b2b4db6909257683240c2/ATM.Malware.ATMSpitter.yar#L3-L21"
- license_url = "N/A"
- hash = "658b0502b53f718bd0611a638dfd5969"
- logic_hash = "684820ed29c50a41bd262862cb97c70c0cbb8554e7e4be300986519423249c50"
+ description = "macSpy is a malware-as-a-service (MaaS) product advertised as the most sophisticated Mac spyware ever"
+ author = "AlienVault Labs"
+ id = "5f9a5ed5-a982-552c-a6df-326228eaf459"
+ date = "2017-08-11"
+ modified = "2017-08-11"
+ reference = "https://www.alienvault.com/blogs/labs-research/macspy-os-x-rat-as-a-service"
+ source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/malware/macos/malware_macos_macspy.yara#L3-L17"
+ license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
+ hash = "6c03e4a9bcb9afaedb7451a33c214ae4"
+ logic_hash = "f04648860c9602e43516113000908008847dacfbe189d79e13737bcd034b68a0"
score = 75
- quality = 65
+ quality = 80
tags = "FILE"
strings:
- $Code_Bytes = { B9 E0 07 00 00 66 ?? ?? ?? ?? 0F 85 DD 02 00 00 66 ?? ?? ?? ?? ?? 0F 85 D1 02 00 00 }
- $Service = "Congratulations! You are very skilled in reverse engineering!" nocase ascii
+ $header0 = {cf fa ed fe}
+ $header1 = {ce fa ed fe}
+ $header2 = {ca fe ba be}
+ $c1 = { 76 31 09 00 76 32 09 00 76 33 09 00 69 31 09 00 69 32 09 00 69 33 09 00 69 34 09 00 66 31 09 00 66 32 09 00 66 33 09 00 66 34 09 00 74 63 3A 00 }
condition:
- (hash.sha256(0, filesize )=="4035d977202b44666885f9781ac8755c799350a03838ff782eb730c0d7069958") or ($Code_Bytes and $Service)
+ ($header0 at 0 or $header1 at 0 or $header2 at 0) and $c1
}
-rule R3C0NST_UNC2891_Steelcorgi : FILE
+rule BINARYALERT_Malware_Macos_Proton_Rat_Generic
{
meta:
- description = "Detects UNC2891 Steelcorgi packed ELF binaries"
- author = "Frank Boldewin (@r3c0nst)"
- id = "94da7da5-5fc3-5221-97d6-1854aa7b1959"
- date = "2022-03-30"
- modified = "2023-01-05"
- reference = "https://github.com/fboldewin/YARA-rules/"
- source_url = "https://github.com/fboldewin/YARA-rules//blob/54e9e6899b258b72074b2b4db6909257683240c2/UNC2891_Steelcorgi.yar#L1-L17"
- license_url = "N/A"
- logic_hash = "4f956b9eaec66bc606ffd0afa2fe9303194e9a8c12d4c3de6ab2334c9856dd99"
+ description = "No description has been set in the source file - BinaryAlert"
+ author = "@mimeframe"
+ id = "75cfaaff-e8d7-5cd4-953b-7d2011139725"
+ date = "2017-08-11"
+ modified = "2017-08-11"
+ reference = "https://objective-see.com/blog/blog_0x1D.html"
+ source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/malware/macos/malware_macos_proton_rat_generic.yara#L3-L21"
+ license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
+ hash = "6a2d0c8b20efc3fa283176a4bc76d6fd"
+ logic_hash = "b7d8660320564cba1d8e2d53d1fdc75509140c7e87a572b27931c62201df2d22"
score = 75
- quality = 90
- tags = "FILE"
- hash1 = "0760cd30d18517e87bf9fd8555513423db1cd80730b47f57167219ddbf91f170"
- hash2 = "3560ed07aac67f73ef910d0b928db3c0bb5f106b5daee054666638b6575a89c5"
- hash3 = "5b4bb50055b31dbd897172583c7046dd27cd03e1e3d84f7a23837e8df7943547"
+ quality = 64
+ tags = ""
strings:
- $pattern1 = {70 61 64 00 6C 63 6B 00}
- $pattern2 = {FF 72 FF 6F FF 63 FF 2F FF 73 FF 65 FF 6C FF 66 FF 2F FF 65 FF 78 FF 65}
+ $a1 = "SRWebSocket" nocase wide ascii
+ $a2 = "SocketRocket" nocase wide ascii
+ $b1 = "SSH tunnel not launched" nocase wide ascii
+ $b2 = "SSH tunnel still running" nocase wide ascii
+ $b3 = "SSH tunnel already launched" nocase wide ascii
+ $b4 = "Entering interactive session." nocase wide ascii
condition:
- uint32(0)==0x464c457f and all of them
+ BINARYALERT_Macho_PRIVATE and any of ($a*) and any of ($b*)
}
-/*
- * YARA Rule Set
- * Repository Name: CAPE
- * Repository: https://github.com/kevoreilly/CAPEv2
- * Retrieval Date: 2024-08-04
- * Git Commit: f9f935f924c6612b13b8f103f53643718282f24b
- * Number of Rules: 95
- * Skipped: 0 (age), 11 (quality), 0 (score), 0 (importance)
- *
- *
- * LICENSE
- *
- * Cuckoo Sandbox is copyrighted by the Cuckoo Foundation and is licensed under
-the following GNU General Public License version 3.
-
- GNU GENERAL PUBLIC LICENSE
- Version 3, 29 June 2007
-
- Copyright (C) 2007 Free Software Foundation, Inc.
UserName : " wide ascii
- $html_pc_name = "
PC Name : " wide ascii
- $html_os_name = "
OS Full Name : " wide ascii
- $html_os_platform = "
OS Platform : " wide ascii
- $html_clipboard = "
[clipboard]" wide ascii
+ $s0 = "VBE7.DLL" fullword ascii
+ $s1 = "TargetPivotTable" fullword ascii
+ $s2 = "DocumentUserPassword" fullword wide
+ $s3 = "DocumentOwnerPassword" fullword wide
+ $s4 = "Scripting.FileSystemObject" fullword wide
+ $s5 = "MSXML2.ServerXMLHTTP" fullword wide
+ $s6 = "Win32_ProcessStartup " fullword ascii
+ $s7 = "Step 3: Start looping through all worksheets" fullword ascii
+ $s8 = "Step 2: Start looping through all worksheets" fullword ascii
+ $s9 = "Stringer" fullword wide
+ $s10 = "-decode -f" fullword wide
+ $s11 = "2. Da biste pogledali dokument, molimo kliknite \"OMOGU" fullword wide
condition:
- 3 of them
+ uint16(0)==0xcfd0 and filesize <200KB and (8 of ($s*) or all of them )
}
-rule CAPE_Agenttesla : FILE
+rule DEADBITS_Dacls_Trojan_Linux
{
meta:
- description = "AgentTesla Payload"
- author = "kevoreilly"
- id = "f7b930f1-cecb-5d80-809b-9503f282247a"
- date = "2024-03-22"
- modified = "2024-03-22"
- reference = "https://github.com/kevoreilly/CAPEv2"
- source_url = "https://github.com/kevoreilly/CAPEv2/blob/f9f935f924c6612b13b8f103f53643718282f24b/data/yara/CAPE/AgentTesla.yar#L19-L41"
- license_url = "https://github.com/kevoreilly/CAPEv2/blob/f9f935f924c6612b13b8f103f53643718282f24b/LICENSE"
- logic_hash = "1bf9b26c4cf87e674ddffabe40aba5a45499c6a04d4ff3e43c3cda4cbcb4d188"
+ description = "No description has been set in the source file - DeadBits"
+ author = "Adam Swanda"
+ id = "bb83ba2b-70a3-5a0f-9588-d93b7f07f67f"
+ date = "2020-01-07"
+ modified = "2020-01-07"
+ reference = "https://github.com/deadbits/yara-rules"
+ source_url = "https://github.com/deadbits/yara-rules//blob/d002f7ecee23e09142a3ac3e79c84f71dda3f001/rules/Dacls_Linux.yara#L1-L32"
+ license_url = "N/A"
+ logic_hash = "752d7daf9178e4fa20f2ce781c6ff70f83758f01479696f0808e1588da9a3d78"
score = 75
- quality = 70
- tags = "FILE"
- cape_type = "AgentTesla Payload"
+ quality = 80
+ tags = ""
+ Author = "Adam M. Swanda"
strings:
- $string1 = "smtp" wide
- $string2 = "appdata" wide
- $string3 = "76487-337-8429955-22614" wide
- $string4 = "yyyy-MM-dd HH:mm:ss" wide
- $string6 = "webpanel" wide
- $string7 = "
UserName :" wide
- $string8 = "
IP Address :" wide
- $agt1 = "IELibrary.dll" ascii
- $agt2 = "C:\\Users\\Admin\\Desktop\\IELibrary\\IELibrary\\obj\\Debug\\IELibrary.pdb" ascii
- $agt3 = "GetSavedPasswords" ascii
- $agt4 = "GetSavedCookies" ascii
+ $cls00 = "c_2910.cls" ascii fullword
+ $cls01 = "k_3872.cls" ascii fullword
+ $str00 = "{\"result\":\"ok\"}" ascii fullword
+ $str01 = "SCAN %s %d.%d.%d.%d %d" ascii fullword
+ $str02 = "/var/run/init.pid" ascii fullword
+ $str03 = "/flash/bin/mountd" ascii fullword
+ $str04 = "Name:" ascii fullword
+ $str05 = "Uid:" ascii fullword
+ $str06 = "Gid:" ascii fullword
+ $str08 = "PPid:" ascii fullword
+ $str09 = "session_id" ascii fullword
condition:
- uint16(0)==0x5A4D and ( all of ($string*) or 3 of ($agt*))
+ uint32be(0x0)==0x7f454c46 and (( all of ($cls*)) or ( all of ($str*)))
}
-rule CAPE_Agentteslav2 : FILE
+rule DEADBITS_Jsworm : MALWARE FILE
{
meta:
- description = "AgenetTesla Type 2 Keylogger payload"
- author = "ditekshen"
- id = "e60ecee4-0a97-56a1-b21e-47190f8cd1f8"
- date = "2024-03-22"
- modified = "2024-03-22"
- reference = "https://github.com/kevoreilly/CAPEv2"
- source_url = "https://github.com/kevoreilly/CAPEv2/blob/f9f935f924c6612b13b8f103f53643718282f24b/data/yara/CAPE/AgentTesla.yar#L43-L67"
- license_url = "https://github.com/kevoreilly/CAPEv2/blob/f9f935f924c6612b13b8f103f53643718282f24b/LICENSE"
- logic_hash = "b45296b3b94fa1ff32de48c94329a17402461fb6696e9390565c4dba9738ed78"
+ description = "No description has been set in the source file - DeadBits"
+ author = "Adam Swanda"
+ id = "6d452d04-b475-5241-890c-68119a7a8691"
+ date = "2019-09-06"
+ modified = "2019-09-06"
+ reference = "https://github.com/deadbits/yara-rules/"
+ source_url = "https://github.com/deadbits/yara-rules//blob/d002f7ecee23e09142a3ac3e79c84f71dda3f001/rules/JSWorm.yara#L1-L38"
+ license_url = "N/A"
+ logic_hash = "99074e25ec15c5b25fa41bef19203f5ddc227acd51fadca1e2c3ece538b3da01"
score = 75
- quality = 70
- tags = "FILE"
- cape_type = "AgentTesla Payload"
+ quality = 78
+ tags = "MALWARE, FILE"
strings:
- $s1 = "get_kbHook" ascii
- $s2 = "GetPrivateProfileString" ascii
- $s3 = "get_OSFullName" ascii
- $s4 = "get_PasswordHash" ascii
- $s5 = "remove_Key" ascii
- $s6 = "FtpWebRequest" ascii
- $s7 = "logins" fullword wide
- $s8 = "keylog" fullword wide
- $s9 = "1.85 (Hash, version 2, native byte-order)" wide
- $cl1 = "Postbox" fullword ascii
- $cl2 = "BlackHawk" fullword ascii
- $cl3 = "WaterFox" fullword ascii
- $cl4 = "CyberFox" fullword ascii
- $cl5 = "IceDragon" fullword ascii
- $cl6 = "Thunderbird" fullword ascii
+ $name00 = "JSWORM" nocase
+ $str00 = "DECRYPT.txt" nocase
+ $str02 = "cmd.exe"
+ $str03 = "/c reg add HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run /v \"zapiska\" /d \"C:\\ProgramData\\"
+ $str04 = /\/c taskkill.exe taskkill \/f \/im (store|sqlserver|dns|sqlwriter)\.exe/
+ $str05 = "/c start C:\\ProgramData\\"
+ $str06 = "/c vssadmin.exe delete shadows /all /quiet"
+ $str07 = "/c bcdedit /set {default} bootstatuspolicy ignoreallfailures -y"
+ $str08 = "/c bcdedit /set {default} recoveryenabled No -y"
+ $str09 = "/c wbadmin delete catalog -quiet"
+ $str10 = "/c wmic shadowcopy delete -y"
+ $uniq00 = "fuckav"
+ $uniq01 = "DECRYPT.hta" nocase
+ $uniq02 = "Backup e-mail for contact :"
+ $uniq03 = "Stop take screenshot
" ascii wide
- $c1 = "http://23.227.196.215/" ascii wide
- $c2 = "http://apple-iclods.org/" ascii wide
- $c3 = "http://apple-checker.org/" ascii wide
- $c4 = "http://apple-uptoday.org/" ascii wide
- $c5 = "http://apple-search.info" ascii wide
- $d1 = "watch/?" fullword ascii wide
- $d2 = "search/?" fullword ascii wide
- $d3 = "find/?" fullword ascii wide
- $d4 = "results/?" fullword ascii wide
- $d5 = "open/?" fullword ascii wide
- $d6 = "search/?" fullword ascii wide
- $d7 = "close/?" fullword ascii wide
- $e1 = "itwm=" fullword ascii wide
- $e2 = "text=" fullword ascii wide
- $e3 = "from=" fullword ascii wide
- $e4 = "itwm=" fullword ascii wide
- $e5 = "ags=" fullword ascii wide
- $e6 = "btnG=" fullword ascii wide
- $e7 = "oprnd=" fullword ascii wide
- $e8 = "itwm=" fullword ascii wide
- $e9 = "utm=" fullword ascii wide
- $e10 = "channel=" fullword ascii wide
+ $s1 = "HttpModule.pdb" ascii wide
+ $s2 = "([\\w+%]+)=([^&]*)"
+ $s3 = "([\\w+%]+)=([^!]*)"
+ $s4 = "cmd.exe"
+ $s5 = "C:\\Users\\Iso\\Documents\\Visual Studio 2013\\Projects\\IIS 5\\x64\\Release\\Vi.pdb" ascii wide
+ $s6 = "AVRSAFunction"
condition:
- BINARYALERT_Macho_PRIVATE and (5 of ($a*) or any of ($b*) or any of ($c*) or 4 of ($d*) or 5 of ($e*))
+ ESET_IIS_Native_Module_PRIVATE and 3 of ($s*)
}
-rule BINARYALERT_Malware_Macos_Marten4N6_Evilosx
+import "pe"
+
+rule ESET_IIS_Group03
{
meta:
- description = "EvilOSX is a pure python, post-exploitation, RAT (Remote Administration Tool) for macOS / OSX."
- author = "@mimeframe"
- id = "2b2e62ca-f95c-55c5-aaf6-985aab49dfbb"
- date = "2017-09-12"
- modified = "2017-09-12"
- reference = "https://github.com/Marten4n6/EvilOSX"
- source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/malware/macos/malware_macos_marten4n6_evilosx.yara#L1-L16"
- license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
- logic_hash = "3402ebf34fd507d0c317416bf77bb3d51b67c8b0f099ce68d15ade6a6a2e302a"
+ description = "Detects Group 3 native IIS malware family"
+ author = "ESET Research"
+ id = "9caf9b3e-611e-5e0e-a7ee-9e7515679022"
+ date = "2021-08-04"
+ modified = "2021-08-04"
+ reference = "https://github.com/eset/malware-ioc/"
+ source_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/badiis/badiis.yar#L157-L176"
+ license_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/LICENSE"
+ logic_hash = "d811c2ac610780bf968e86e8fd302cffc9434902e547399d06fdeb30d1719f51"
score = 75
quality = 80
tags = ""
+ license = "BSD 2-Clause"
+ version = "1"
strings:
- $a1 = "icloud_phish_stop" fullword wide ascii
- $a2 = "icloud_contacts" fullword wide ascii
- $a3 = "itunes_backups" fullword wide ascii
- $a4 = "chrome_passwords" fullword wide ascii
- $a5 = "Starting EvilOSX..." wide ascii
+ $s1 = "IIS-Backdoor.dll"
+ $s2 = "CryptStringToBinaryA"
+ $s3 = "CreateProcessA"
+ $s4 = "X-Cookie"
condition:
- 4 of ($a*)
+ ESET_IIS_Native_Module_PRIVATE and 3 of ($s*)
}
-rule BINARYALERT_Malware_Macos_Neoneggplant_Eggshell
+import "pe"
+
+rule ESET_IIS_Group04_Rgdoor
{
meta:
- description = "EggShell is an iOS and macOS post exploitation surveillance pentest tool written in Python."
- author = "@mimeframe"
- id = "274a34cc-9403-50e6-aa64-683a41bc30e6"
- date = "2017-09-12"
- modified = "2017-09-12"
- reference = "https://github.com/neoneggplant/EggShell"
- source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/malware/macos/malware_macos_neoneggplant_eggshell.yara#L1-L24"
- license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
- logic_hash = "34906db9398313ccb84e67bd98e94324c628aefe3efa6ba3cca2df042b42cbe7"
- score = 50
+ description = "Detects Group 4 native IIS malware family (RGDoor)"
+ author = "ESET Research"
+ id = "64a0e664-a4d9-555b-a11b-5f7d9d0678b1"
+ date = "2021-08-04"
+ modified = "2021-08-04"
+ reference = "https://github.com/eset/malware-ioc/"
+ source_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/badiis/badiis.yar#L178-L199"
+ license_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/LICENSE"
+ logic_hash = "be615dc0cc8bf0fd52cc5a88a3759c1cb1cd18703de74d16f5cce3eabccf91c6"
+ score = 75
quality = 80
tags = ""
+ license = "BSD 2-Clause"
+ version = "1"
strings:
- $a1 = "Created By Lucas Jackson (@neoneggplant)" wide ascii
- $a2 = "SET LHOST (Leave blank for" wide ascii
- $a3 = "SET LPORT (Leave blank for" wide ascii
- $b1 = "/tmp/.esplog" wide ascii
- $b2 = "spGHbigdxMBJpbOCAr3rnS3inCdYQyZV" wide ascii
- $b3 = "keylogclear" wide ascii
- $b4 = "getpasscode" wide ascii
- $c1 = "spGHbigdxMBJpbOCAr3rnS3inCdYQyZV" wide ascii
- $c2 = "getfacebook" wide ascii
- $c3 = "type is eggsu" wide ascii
- $c4 = "rmpersistence" wide ascii
+ $i1 = "RGSESSIONID="
+ $s2 = "upload$"
+ $s3 = "download$"
+ $s4 = "cmd$"
+ $s5 = "cmd.exe"
condition:
- all of ($a*) or 3 of ($b*) or 3 of ($c*)
+ ESET_IIS_Native_Module_PRIVATE and ($i1 or all of ($s*))
}
import "pe"
-rule BINARYALERT_Malware_Macos_Macspy : FILE
+rule ESET_IIS_Group05_Iistealer
{
meta:
- description = "macSpy is a malware-as-a-service (MaaS) product advertised as the most sophisticated Mac spyware ever"
- author = "AlienVault Labs"
- id = "5f9a5ed5-a982-552c-a6df-326228eaf459"
- date = "2017-08-11"
- modified = "2017-08-11"
- reference = "https://www.alienvault.com/blogs/labs-research/macspy-os-x-rat-as-a-service"
- source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/malware/macos/malware_macos_macspy.yara#L3-L17"
- license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
- hash = "6c03e4a9bcb9afaedb7451a33c214ae4"
- logic_hash = "f04648860c9602e43516113000908008847dacfbe189d79e13737bcd034b68a0"
+ description = "Detects Group 5 native IIS malware family (IIStealer)"
+ author = "ESET Research"
+ id = "598ec6b2-0349-5da7-acad-72ef2468b927"
+ date = "2021-08-04"
+ modified = "2021-08-04"
+ reference = "https://github.com/eset/malware-ioc/"
+ source_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/badiis/badiis.yar#L201-L232"
+ license_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/LICENSE"
+ logic_hash = "5dff445121fda59df805d6fcb5db3f8f8e52a6e63e2da2a6875f8c9ad9cafc72"
score = 75
quality = 80
- tags = "FILE"
+ tags = ""
+ license = "BSD 2-Clause"
+ version = "1"
strings:
- $header0 = {cf fa ed fe}
- $header1 = {ce fa ed fe}
- $header2 = {ca fe ba be}
- $c1 = { 76 31 09 00 76 32 09 00 76 33 09 00 69 31 09 00 69 32 09 00 69 33 09 00 69 34 09 00 66 31 09 00 66 32 09 00 66 33 09 00 66 34 09 00 74 63 3A 00 }
+ $s1 = "tojLrGzFMbcDTKcH" ascii wide
+ $s2 = "4vUOj3IutgtrpVwh" ascii wide
+ $s3 = "SoUnRCxgREXMu9bM" ascii wide
+ $s4 = "9Zr1Z78OkgaXj1Xr" ascii wide
+ $s5 = "cache.txt" ascii wide
+ $s6 = "/checkout/checkout.aspx" ascii wide
+ $s7 = "/checkout/Payment.aspx" ascii wide
+ $s8 = "/privacy.aspx"
+ $s9 = "X-IIS-Data"
+ $s10 = "POST"
+ $s11 = {C7 ?? CF 2F 00 63 00 C7 ?? D3 68 00 65 00 C7 ?? D7 63 00 6B 00 C7 ?? DB 6F 00 75 00 C7 ?? DF 74 00 2F 00 C7 ?? E3 63 00 68 00 C7 ?? E7 65 00 63 00 C7 ?? EB 6B 00 6F 00 C7 ?? EF 75 00 74 00 C7 ?? F3 2E 00 61 00 C7 ?? F7 73 00 70 00 C7 ?? FB 78 00 00 00}
+ $s12 = {C7 ?? AF 2F 00 70 00 C7 ?? B3 72 00 69 00 C7 ?? B7 76 00 61 00 C7 ?? BB 63 00 79 00 C7 ?? BF 2E 00 61 00 C7 ?? C3 73 00 70 00 C7 ?? C7 78 00 00 00}
condition:
- ($header0 at 0 or $header1 at 0 or $header2 at 0) and $c1
+ ESET_IIS_Native_Module_PRIVATE and 3 of ($s*)
}
-rule BINARYALERT_Malware_Macos_Bella
+import "pe"
+
+rule ESET_IIS_Group06_ISN
{
meta:
- description = "Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS."
- author = "@mimeframe"
- id = "ca4ab508-8c97-5307-9aaf-db10cfd6ab35"
- date = "2017-09-12"
- modified = "2017-09-12"
- reference = "https://github.com/Trietptm-on-Security/Bella"
- source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/malware/macos/malware_macos_bella.yara#L1-L22"
- license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
- logic_hash = "b9c063b5ec8604958d3417ec8640da4314ebcf60ee55413a2f6fa8d138311614"
+ description = "Detects Group 6 native IIS malware family (ISN)"
+ author = "ESET Research"
+ id = "1f68fc42-61a3-5a7d-9daa-31ae3b561837"
+ date = "2021-08-04"
+ modified = "2021-08-04"
+ reference = "https://github.com/eset/malware-ioc/"
+ source_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/badiis/badiis.yar#L234-L259"
+ license_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/LICENSE"
+ logic_hash = "2f59034a642a9b92fc88922433cd5923be02332159cba5e16d99d9523ed43205"
score = 75
quality = 80
tags = ""
+ license = "BSD 2-Clause"
+ version = "1"
strings:
- $a1 = "Verified! [2FV Enabled] Account ->" wide ascii
- $a2 = "There is no root shell to perform this command. See [rooter] manual entry." wide ascii
- $a3 = "Attempt to escalate Bella to root through a variety of attack vectors." wide ascii
- $a4 = "BELLA IS NOW RUNNING. CONNECT TO BELLA FROM THE CONTROL CENTER." wide ascii
- $b1 = "user_pass_phish" fullword wide ascii
- $b2 = "bella_info" fullword wide ascii
- $b3 = "get_root" fullword wide ascii
- $c1 = "Please specify a bella server." wide ascii
- $c2 = "What port should Bella connect on [Default is 4545]:" wide ascii
+ $s1 = "isn7 config reloaded"
+ $s2 = "isn7 config NOT reloaded, not found or empty"
+ $s3 = "isn7 log deleted"
+ $s4 = "isn7 log not deleted, ERROR 0x%X"
+ $s5 = "isn7 log NOT found"
+ $s6 = "isn_reloadconfig"
+ $s7 = "D:\\soft\\Programming\\C++\\projects\\isapi\\isn7"
+ $s8 = "get POST failed %d"
+ $s9 = "isn7.dll"
condition:
- any of ($a*) or all of ($b*) or all of ($c*)
+ ESET_IIS_Native_Module_PRIVATE and 3 of ($s*)
}
-rule BINARYALERT_Malware_Multi_Pupy_Rat
-{
- meta:
- description = "pupy - opensource cross platform rat and post-exploitation tool"
- author = "@mimeframe"
- id = "b26deb19-85b2-5d39-9ff2-0ab9017f3263"
- date = "2017-09-12"
- modified = "2017-09-12"
- reference = "https://github.com/n1nj4sec/pupy"
- source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/malware/multi/malware_multi_pupy_rat.yara#L1-L16"
- license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
- logic_hash = "bb5d1e7f2aea94dc41efe75690ae31409e8f6305aa6c4ec0cd46922ee8fb7241"
- score = 75
- quality = 74
- tags = ""
-
- strings:
- $a1 = "dumping lsa secrets" nocase wide ascii
- $a2 = "dumping cached domain passwords" nocase wide ascii
- $a3 = "the keylogger is already started" nocase wide ascii
- $a4 = "pupyutils.dns" wide ascii
- $a5 = "pupwinutils.security" wide ascii
- $a6 = "-PUPY_CONFIG_COMES_HERE-" wide ascii
+import "pe"
- condition:
- 3 of ($a*)
-}
-rule BINARYALERT_Malware_Multi_Vesche_Basicrat
+rule ESET_IIS_Group07_Iispy
{
meta:
- description = "cross-platform Python 2.x Remote Access Trojan (RAT)"
- author = "@mimeframe"
- id = "e07a684c-3a3d-5dd3-a540-2cc9a5a170dd"
- date = "2017-09-12"
- modified = "2017-09-12"
- reference = "https://github.com/vesche/basicRAT"
- source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/malware/multi/malware_multi_vesche_basicrat.yara#L1-L15"
- license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
- logic_hash = "1503ce9de4e721903058c77b305ba057052d654ff1875ea880f4319c3e525a29"
+ description = "Detects Group 7 native IIS malware family (IISpy)"
+ author = "ESET Research"
+ id = "64ed0189-a0be-5592-b9c6-1622700a7ed7"
+ date = "2021-08-04"
+ modified = "2021-08-04"
+ reference = "https://github.com/eset/malware-ioc/"
+ source_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/badiis/badiis.yar#L261-L296"
+ license_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/LICENSE"
+ logic_hash = "ec5db5f36d06f9b0bdfe598fc72431da35afc1473dcc29f437a0f48ea9835a03"
score = 75
quality = 80
tags = ""
+ license = "BSD 2-Clause"
+ version = "1"
strings:
- $a1 = "HKCU Run registry key applied" wide ascii
- $a2 = "HKCU Run registry key failed" wide ascii
- $a3 = "Error, platform unsupported." wide ascii
- $a4 = "Persistence successful," wide ascii
- $a5 = "Persistence unsuccessful," wide ascii
+ $s1 = "/credential/username"
+ $s2 = "/credential/password"
+ $s3 = "/computer/domain"
+ $s4 = "/computer/name"
+ $s5 = "/password"
+ $s6 = "/cmd"
+ $s7 = "%.8s%.8s=%.8s%.16s%.8s%.16s"
+ $s8 = "ImpersonateLoggedOnUser"
+ $s9 = "WNetAddConnection2W"
+ $t1 = "X-Forwarded-Proto"
+ $t2 = "Sec-Fetch-Mode"
+ $t3 = "Sec-Fetch-Site"
+ $t4 = "Cookie"
+ $t5 = {49 45 4E 44 AE 42 60 82}
+ $t6 = {89 50 4E 47 0D 0A 1A 0A 00 00 00 0D 49 48 44 52}
condition:
- all of ($a*)
+ ESET_IIS_Native_Module_PRIVATE and 2 of ($s*) and any of ($t*)
}
-rule BINARYALERT_Ransomware_Windows_Powerware_Locky
+import "pe"
+
+rule ESET_IIS_Group08
{
meta:
- description = "PowerWare Ransomware"
- author = "@fusionrace"
- id = "8a1a56af-7a9d-54ed-90b9-daf33735ee1e"
- date = "2017-08-11"
- modified = "2017-08-11"
- reference = "https://researchcenter.paloaltonetworks.com/2016/07/unit42-powerware-ransomware-spoofing-locky-malware-family/"
- source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/ransomware/windows/ransomware_windows_powerware_locky.yara#L1-L17"
- license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
- hash = "3433a4da9d8794709630eb06afd2b8c1"
- logic_hash = "64de34755f706a9fd4c876c473eed4f8922a4450c7ef135b0ab5e49c67363baf"
+ description = "Detects Group 8 native IIS malware family"
+ author = "ESET Research"
+ id = "d0e9a5ec-b7f0-5d3f-93b4-d048503eb210"
+ date = "2021-08-04"
+ modified = "2021-08-04"
+ reference = "https://github.com/eset/malware-ioc/"
+ source_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/badiis/badiis.yar#L298-L337"
+ license_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/LICENSE"
+ logic_hash = "d5826d454d25ecbbb5da464da974023a247517d873cf10dc0eafa91e185451da"
score = 75
- quality = 78
+ quality = 53
tags = ""
+ license = "BSD 2-Clause"
+ version = "1"
strings:
- $s0 = "ScriptRunner.dll" fullword ascii wide
- $s1 = "ScriptRunner.pdb" fullword ascii wide
- $s2 = "fixed.ps1" fullword ascii wide
+ $i1 = "FliterSecurity.dll"
+ $i2 = "IIS7NativeModule.dll"
+ $i3 = "Ver1.0."
+ $s1 = "Cmd"
+ $s2 = "Realy path : %s"
+ $s3 = "Logged On Users : %d"
+ $s4 = "Connect OK!"
+ $s5 = "You are fucked!"
+ $s6 = "Shit!Error"
+ $s7 = "Where is the God!!"
+ $s8 = "Shit!Download False!"
+ $s9 = "Good!Run OK!"
+ $s10 = "Shit!Run False!"
+ $s11 = "Good!Download OK!"
+ $s12 = "[%d]safedog"
+ $s13 = "ed81bfc09d069121"
+ $s14 = "a9478ef01967d190"
+ $s15 = "af964b7479e5aea2"
+ $s16 = "1f9e6526bea65b59"
+ $s17 = "2b9e9de34f782d31"
+ $s18 = "33cc5da72ac9d7bb"
+ $s19 = "b1d71f4c2596cd55"
+ $s20 = "101fb9d9e86d9e6c"
condition:
- all of them
+ ESET_IIS_Native_Module_PRIVATE and 1 of ($i*) and 3 of ($s*)
}
-rule BINARYALERT_Ransomware_Windows_Zcrypt
+import "pe"
+
+rule ESET_IIS_Group09
{
meta:
- description = "Zcrypt will encrypt data and append the .zcrypt extension to the filenames"
- author = "@fusionrace"
- id = "d79cd266-4e77-562c-975c-8bf72efe7242"
- date = "2017-08-11"
- modified = "2017-08-11"
- reference = "https://blog.malwarebytes.com/threat-analysis/2016/06/zcrypt-ransomware/"
- source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/ransomware/windows/ransomware_windows_zcrypt.yara#L1-L23"
- license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
- hash = "d1e75b274211a78d9c5d38c8ff2e1778"
- logic_hash = "df4073363da162e69f29493b5bfb4cb3f3d342357335c13ba6a3ac868607cb25"
+ description = "Detects Group 9 native IIS malware family"
+ author = "ESET Research"
+ id = "69d176bc-73b1-5c4d-bb7e-463d26e8e6a9"
+ date = "2021-08-04"
+ modified = "2021-08-04"
+ reference = "https://github.com/eset/malware-ioc/"
+ source_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/badiis/badiis.yar#L339-L387"
+ license_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/LICENSE"
+ logic_hash = "5f89f9488221b8db8d493b3c23b7f5edd957c15511148eca890558886c128192"
score = 75
- quality = 78
+ quality = 76
tags = ""
+ license = "BSD 2-Clause"
+ version = "1"
strings:
- $u1 = "How to Buy Bitcoins" ascii wide
- $u2 = "ALL YOUR PERSONAL FILES ARE ENCRYPTED" ascii wide
- $u3 = "Click Here to Show Bitcoin Address" ascii wide
- $u4 = "MyEncrypter2.pdb" fullword ascii wide
- $g1 = ".p7b" fullword ascii wide
- $g2 = ".p7c" fullword ascii wide
- $g3 = ".pdd" fullword ascii wide
- $g4 = ".pef" fullword ascii wide
- $g5 = ".pem" fullword ascii wide
- $g6 = "How to decrypt files.html" fullword ascii wide
+ $i1 = "FliterSecurity.dll"
+ $i2 = {56565656565656565656565656565656}
+ $i3 = "app|hot|alp|svf|fkj|mry|poc|doc|20" xor
+ $i4 = "yisouspider|yisou|soso|sogou|m.sogou|sogo|sogou|so.com|baidu|bing|360" xor
+ $i5 = "baidu|m.baidu|soso|sogou|m.sogou|sogo|sogou|so.com|google|youdao" xor
+ $i6 = "118|abc|1go|evk" xor
+ $s1 = "AVCFuckHttpModuleFactory"
+ $s2 = "X-Forward"
+ $s3 = "fuck32.dat"
+ $s4 = "fuck64.dat"
+ $s5 = "&ipzz1="
+ $s6 = "&ipzz2="
+ $s7 = "&uuu="
+ $s8 = "http://20.3323sf.c" xor
+ $s9 = "http://bj.whtjz.c" xor
+ $s10 = "http://bj2.wzrpx.c" xor
+ $s11 = "http://cs.whtjz.c" xor
+ $s12 = "http://df.e652.c" xor
+ $s13 = "http://dfcp.yyphw.c" xor
+ $s14 = "http://es.csdsx.c" xor
+ $s15 = "http://hz.wzrpx.c" xor
+ $s16 = "http://id.3323sf.c" xor
+ $s17 = "http://qp.008php.c" xor
+ $s18 = "http://qp.nmnsw.c" xor
+ $s19 = "http://sc.300bt.c" xor
+ $s20 = "http://sc.wzrpx.c" xor
+ $s21 = "http://sf2223.c" xor
+ $s22 = "http://sx.cmdxb.c" xor
+ $s23 = "http://sz.ycfhx.c" xor
+ $s24 = "http://xpq.0660sf.c" xor
+ $s25 = "http://xsc.b1174.c" xor
condition:
- any of ($u*) or all of ($g*)
+ ESET_IIS_Native_Module_PRIVATE and any of ($i*) and 3 of ($s*)
}
-rule BINARYALERT_Ransomware_Windows_Petya_Variant_1
+import "pe"
+
+rule ESET_IIS_Group10
{
meta:
- description = "Petya Ransomware new variant June 2017 using ETERNALBLUE"
- author = "@fusionrace"
- id = "bf56c0e4-585c-509b-a182-a93c74be7524"
- date = "2017-08-11"
- modified = "2017-08-11"
- reference = "https://gist.github.com/vulnersCom/65fe44d27d29d7a5de4c176baba45759"
- source_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/rules/public/ransomware/windows/ransomware_windows_petya_variant_1.yara#L1-L18"
- license_url = "https://github.com/airbnb/binaryalert//blob/a9c0f06affc35e1f8e45bb77f835b92350c68a0b/LICENSE"
- hash = "71b6a493388e7d0b40c83ce903bc6b04"
- logic_hash = "3733834ee2271a483739b09c4222d222aa4899cab48fd8fc558bdbd9a66bf2d6"
+ description = "Detects Group 10 native IIS malware family"
+ author = "ESET Research"
+ id = "31368b38-9128-594d-888d-e97d3edc7a1f"
+ date = "2021-08-04"
+ modified = "2021-08-04"
+ reference = "https://github.com/eset/malware-ioc/"
+ source_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/badiis/badiis.yar#L389-L423"
+ license_url = "https://github.com/eset/malware-ioc/blob/9b299fc90dc027a039652a8a4ac487ade0a381dd/LICENSE"
+ logic_hash = "48701168d7da726222227ef757f1a4005a49c0bf300123319ce03db09445b3ef"
score = 75
quality = 80
tags = ""
+ license = "BSD 2-Clause"
+ version = "1"
strings:
- $s1 = "Ooops, your important files are encrypted." fullword ascii wide
- $s2 = "Send your Bitcoin wallet ID and personal installation key to e-mail" fullword ascii wide
- $s3 = "wowsmith123456@posteo.net. Your personal installation key:" fullword ascii wide
- $s4 = "Send $300 worth of Bitcoin to following address:" fullword ascii wide
- $s5 = "have been encrypted. Perhaps you are busy looking for a way to recover your" fullword ascii wide
- $s6 = "need to do is submit the payment and purchase the decryption key." fullword ascii wide
+ $s1 = "IIS7.dll"
+ $s2 = "2*ptr_size) or for any d in elf.dynamic : (d.type==elf.DT_INIT_ARRAYSZ and d.val>ptr_size)))
+ filesize <10MB and ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-import "elf"
-
-rule ESET_Ebury_V1_7_Crypto
+rule FIREEYE_RT_Tool_MSIL_Sharpgrep_1 : FILE
{
meta:
- description = "This rule detects the strings decryption routine in Ebury v1.7 and v1.8"
- author = "ESET, spol. s r.o."
- id = "93dadf5f-b572-5217-8c82-4957c6d24955"
- date = "2023-08-01"
- modified = "2024-04-29"
- reference = "https://github.com/eset/malware-ioc/"
- source_url = "https://github.com/eset/malware-ioc/blob/56a9841902ca1b562eaf217df2e45151606d49f2/windigo/ebury.yar#L56-L97"
- license_url = "https://github.com/eset/malware-ioc/blob/56a9841902ca1b562eaf217df2e45151606d49f2/LICENSE"
- hash = "e7debd6e453192ad8376db5bab03ed0d87566591"
- logic_hash = "41908951069a472d7528f2f228f3681f008d16a0436e341d339909efc4933e66"
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'SharpGrep' project."
+ author = "FireEye"
+ id = "c7569d33-f57d-5f9c-aa2a-78866c680b5b"
+ date = "2020-12-09"
+ modified = "2020-12-09"
+ reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/SHARPPGREP/production/yara/Tool_MSIL_SharpGrep_1.yar#L4-L15"
+ license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "c22bfc50b3ab3c4082006aad3c3c89684cffe1e429b001b0bb08758856a47d04"
score = 75
- quality = 80
- tags = ""
- license = "BSD 2-Clause"
- version = 1
+ quality = 73
+ tags = "FILE"
+ rev = 1
strings:
- $64 = {
- 48 69 ( 9C 24 ?? ?? ?? ?? | 5C 24 ?? | D2) 6D 4E C6 41 // imul rbx, [rsp+_buf], 41C64E6Dh
- 8B (0C 16 | 34 07) // mov ecx, [rsi+rdx]
- 48 81 C? 39 30 00 00 // add rbx, 12345
- ( 31 D? | // xor ecx, ebx
- 31 D? 48 89 9C 24 ?? ?? ?? ?? | // mov [rsp+_buf], rbx
- 31 D? 48 89 5C 24 ?? ) // ^ optional
- 89 (0C 10 | 34 01) // mov [rax+rdx], ecx
- 48 83 C? 04 // add rdx, 4
- 48 (81 FA | 3D ) ?? ?? ?? ?? // cmp rdx, _size
- 75 D? // jnz short _begin
- }
- $32 = {
- 69 C9 6D 4E C6 41 // imul ecx, 41C64E6Dh
- 8B B4 1A ?? ?? ?? ?? // mov esi, [edx+ebx+_data]
- 81 C1 39 30 00 00 // add ecx, 12345
- 31 CE // xor esi, ecx
- 89 34 10 // mov [eax+edx], esi
- 83 C2 04 // add edx, 4
- 81 FA ?? ?? ?? ?? // cmp edx, _size
- 75 DD // jnz short loc_69A5
- }
+ $typelibguid0 = "f65d75b5-a2a6-488f-b745-e67fc075f445" ascii nocase wide
condition:
- any of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-/*
- * YARA Rule Set
- * Repository Name: FireEye-RT
- * Repository: https://github.com/mandiant/red_team_tool_countermeasures/
- * Retrieval Date: 2024-08-04
- * Git Commit: 3561b71724dbfa3e2bb78106aaa2d7f8b892c43b
- * Number of Rules: 168
- * Skipped: 0 (age), 4 (quality), 0 (score), 0 (importance)
- *
- *
- * LICENSE
- *
- * BSD 2-Clause License
-
-Copyright (c) 2023, MANDIANT
-
-Redistribution and use in source and binary forms, with or without
-modification, are permitted provided that the following conditions are met:
-
-1. Redistributions of source code must retain the above copyright notice, this
- list of conditions and the following disclaimer.
-
-2. Redistributions in binary form must reproduce the above copyright notice,
- this list of conditions and the following disclaimer in the documentation
- and/or other materials provided with the distribution.
-
-THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
-AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
-IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
-DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
-FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
-DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
-SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
-CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
-OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
-OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
-
- */
-rule FIREEYE_RT_Hunting_Gadgettojscript_1
+rule FIREEYE_RT_Hacktool_MSIL_Wmispy_1 : FILE
{
meta:
- description = "This rule is looking for B64 offsets of LazyNetToJscriptLoader which is a namespace specific to the internal version of the GadgetToJScript tooling."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'WMIspy' project."
author = "FireEye"
- id = "76c932e0-55b3-56ef-bab6-eb6997b51ee7"
+ id = "ac394751-da40-564b-8e24-8f353326b46a"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/G2JS/production/yara/Hunting_GadgetToJScript_1.yar#L4-L17"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/WMISPY/production/yara/HackTool_MSIL_WMIspy_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "7af24305a409a2b8f83ece27bb0f7900"
- logic_hash = "a880c20e61376dacd4e3a04f2cf065f19067c29371180b1dec186172cadf9564"
- score = 50
- quality = 75
- tags = ""
- rev = 4
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "a5a9f7c7a7bfe474e8b21306ea220b4d476832f3ad4fafdd8967a2250d15a701"
+ score = 75
+ quality = 73
+ tags = "FILE"
+ rev = 1
strings:
- $s1 = "GF6eU5ldFRvSnNjcmlwdExvYWRl"
- $s2 = "henlOZXRUb0pzY3JpcHRMb2Fk"
- $s3 = "YXp5TmV0VG9Kc2NyaXB0TG9hZGV"
+ $typelibguid0 = "5ee2bca3-01ad-489b-ab1b-bda7962e06bb" ascii nocase wide
condition:
- any of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Builder_MSIL_G2JS_1 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_WMISPY_2 : FILE
{
meta:
- description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the Gadget2JScript project."
+ description = "wql searches"
author = "FireEye"
- id = "484202c2-ac7d-5e6c-8bf1-3452a357c668"
+ id = "474af878-a657-54bc-a063-04532df928d4"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/G2JS/production/yara/Builder_MSIL_G2JS_1.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/WMISPY/production/yara/APT_HackTool_MSIL_WMISPY_2.yar#L4-L24"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "fa255fdc88ab656ad9bc383f9b322a76"
- logic_hash = "487d8e8deef218412f241d99ce32b63bfeb3568d23048b9dd4afff8f401bfea5"
+ hash = "3651f252d53d2f46040652788499d65a"
+ logic_hash = "553fc1e536482a56b3228a5c9ebac843af9083e8ac864bf65c81b36a39ca5e5e"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
- rev = 2
+ rev = 4
strings:
- $typelibguid1 = "AF9C62A1-F8D2-4BE0-B019-0A7873E81EA9" ascii nocase wide
+ $MSIL = "_CorExeMain"
+ $str1 = "root\\cimv2" wide
+ $str2 = "root\\standardcimv2" wide
+ $str3 = "from MSFT_NetNeighbor" wide
+ $str4 = "from Win32_NetworkLoginProfile" wide
+ $str5 = "from Win32_IP4RouteTable" wide
+ $str6 = "from Win32_DCOMApplication" wide
+ $str7 = "from Win32_SystemDriver" wide
+ $str8 = "from Win32_Share" wide
+ $str9 = "from Win32_Process" wide
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and $typelibguid1
+ ( uint16(0)==0x5A4D) and ( uint32( uint32(0x3C))==0x00004550) and $MSIL and all of ($str*)
}
-rule FIREEYE_RT_Hunting_B64Engine_Dotnettojscript_Dos
+rule FIREEYE_RT_Loader_MSIL_Generic_1 : FILE
{
meta:
- description = "This file may enclude a Base64 encoded .NET executable. This technique is used by the project DotNetToJScript which is used by many malware families including GadgetToJScript."
+ description = "No description has been set in the source file - FireEye-RT"
author = "FireEye"
- id = "24c9c259-9bb9-5f46-9278-4fa20eb3c8c4"
+ id = "f919e3fc-cf76-53af-8f04-24921830666f"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/G2JS/production/yara/Hunting_B64Engine_DotNetToJScript_Dos.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/supplemental/yara/Loader_MSIL_Generic_1.yar#L4-L21"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "7af24305a409a2b8f83ece27bb0f7900"
- logic_hash = "e2afb43af469f8ae02f6fd21db6dbd45c997fb003e3aeeaa0d4ff3e85c64159a"
- score = 50
+ hash = "b8415b4056c10c15da5bba4826a44ffd"
+ logic_hash = "06cddd7e1c1c778348539cfd50f01d55f86689dec86c045d7ce7b9cd71690e07"
+ score = 75
quality = 75
- tags = ""
- rev = 1
+ tags = "FILE"
+ rev = 5
strings:
- $b64_mz = "AAC4AAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAAAAAOH7oOALQJzSG4AUzNIVRoaXMgcHJvZ3JhbSBjYW5ub3QgYmUgcnVuIGluIERPUyBtb2RlLg0NCiQAAAAAAAAAUEU"
+ $MSIL = "_CorExeMain"
+ $opc1 = { 00 72 [4] 0A 72 [4] 0B 06 28 [4] 0C 12 03 FE 15 [4] 12 04 FE 15 [4] 07 14 }
+ $str1 = "DllImportAttribute"
+ $str2 = "FromBase64String"
+ $str3 = "ResumeThread"
+ $str4 = "OpenThread"
+ $str5 = "SuspendThread"
+ $str6 = "QueueUserAPC"
condition:
- $b64_mz
+ ( uint16(0)==0x5A4D) and ( uint32( uint32(0x3C))==0x00004550) and $MSIL and all of them
}
-rule FIREEYE_RT_APT_Hacktool_MSIL_FLUFFY_2 : FILE
+rule FIREEYE_RT_Loader_Win_Generic_20 : FILE
{
meta:
description = "No description has been set in the source file - FireEye-RT"
author = "FireEye"
- id = "ce39710e-7649-5f7d-bbbe-65dc30f678e8"
- date = "2020-12-04"
- date = "2020-12-04"
+ id = "d1d3eff8-d12e-53f6-8c30-06ecedaf3f49"
+ date = "2020-12-02"
+ date = "2020-12-02"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/FLUFFY/production/yara/APT_HackTool_MSIL_FLUFFY_2.yar#L4-L21"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/supplemental/yara/Loader_Win_Generic_20.yar#L4-L19"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "11b5aceb428c3e8c61ed24a8ca50553e"
- logic_hash = "872ab717668375a49d6c7b1927a680747b405c0198fe4fc6f43ccc562870eb37"
+ hash = "5125979110847d35a338caac6bff2aa8"
+ logic_hash = "9611aed2b4e4278d40254cb5c4fe94a458cfa19f10e6fe888bc7ceb166669cc6"
score = 75
quality = 75
tags = "FILE"
rev = 1
strings:
- $s1 = "\x00Asktgt\x00"
- $s2 = "\x00Kerberoast\x00"
- $s3 = "\x00HarvestCommand\x00"
- $s4 = "\x00EnumerateTickets\x00"
- $s5 = "[*] Action: " wide
- $s6 = "\x00Fluffy.Commands\x00"
+ $s0 = { 8B [1-16] 89 [1-16] E8 [4-32] F3 A4 [0-16] 89 [1-8] E8 }
+ $s2 = { 83 EC [4-24] 00 10 00 00 [4-24] C7 44 24 ?? ?? 00 00 00 [0-8] FF 15 [4-24] 89 [1-4] 89 [1-4] 89 [1-8] FF 15 [4-16] 3? ?? 7? [4-24] 20 00 00 00 [4-24] FF 15 [4-32] F3 A5 }
+ $si1 = "VirtualProtect" fullword
+ $si2 = "malloc" fullword
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and all of them
+ ( uint16(0)==0x5A4D) and ( uint32( uint32(0x3C))==0x00004550) and all of them
}
-rule FIREEYE_RT_APT_Hacktool_MSIL_FLUFFY_1 : FILE
+rule FIREEYE_RT_Loader_Win_Generic_19 : FILE
{
meta:
description = "No description has been set in the source file - FireEye-RT"
author = "FireEye"
- id = "6593202d-9b30-59ed-98c0-3e730fb5ceb7"
- date = "2020-12-04"
- date = "2020-12-04"
+ id = "4f4427ee-0f7d-5442-98a6-402d8b797289"
+ date = "2020-12-02"
+ date = "2020-12-02"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/FLUFFY/production/yara/APT_HackTool_MSIL_FLUFFY_1.yar#L4-L18"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/supplemental/yara/Loader_Win_Generic_19.yar#L4-L19"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "11b5aceb428c3e8c61ed24a8ca50553e"
- logic_hash = "4d91c96ab7b628e88f79ee193612acc959448fe2220ef54371f5f5c6e7305d86"
+ hash = "3fb9341fb11eca439b50121c6f7c59c7"
+ logic_hash = "6db9696663c19857c1f89339b8cc9b0565e877f34e8d8cf77b89ef22b3f41683"
score = 75
quality = 75
tags = "FILE"
rev = 1
strings:
- $sb1 = { 0E ?? 1? 72 [4] 28 [2] 00 06 [0-16] 28 [2] 00 0A [2-80] 1F 58 0? [0-32] 28 [2] 00 06 [2-32] 1? 28 [2] 00 06 0? 0? 6F [2] 00 06 [2-4] 1F 0B }
- $sb2 = { 73 [2] 00 06 13 ?? 11 ?? 11 ?? 7D [2] 00 04 11 ?? 73 [2] 00 0A 7D [2] 00 04 0E ?? 2D ?? 11 ?? 7B [2] 00 04 72 [4] 28 [2] 00 0A [2-32] 0? 28 [2] 00 0A [2-16] 11 ?? 7B [2] 00 04 0? 28 [2] 00 0A 1? 28 [2] 00 0A [2-32] 7E [2] 00 0A [0-32] FE 15 [2] 00 02 [0-16] 7D [2] 00 04 28 [2] 00 06 [2-32] 7B [2] 00 04 7D [2] 00 04 [2-32] 7C [2] 00 04 FE 15 [2] 00 02 [0-16] 11 ?? 8C [2] 00 02 28 [2] 00 0A 28 [2] 00 0A [2-80] 8C [2] 00 02 28 [2] 00 0A 12 ?? 12 ?? 12 ?? 28 [2] 00 06 }
- $ss1 = "\x00Fluffy\x00"
+ $s0 = { 8B [1-16] 89 [1-16] E8 [4-32] F3 A4 [0-16] 89 [1-8] E8 }
+ $s1 = { 83 EC [1-16] 04 00 00 00 [1-24] 00 30 00 00 [1-24] FF 15 [4-16] EB [16-64] 20 00 00 00 [0-8] FF 15 [4-32] C7 44 24 ?? 00 00 00 00 [0-8] C7 44 24 ?? 00 00 00 00 [0-16] FF 15 }
+ $si1 = "VirtualProtect" fullword
+ $si2 = "malloc" fullword
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and all of them
+ ( uint16(0)==0x5A4D) and ( uint32( uint32(0x3C))==0x00004550) and all of them
}
-rule FIREEYE_RT_Hacktool_MSIL_SAFETYKATZ_4 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_SHARPZIPLIBZIPPER_1 : FILE
{
meta:
- description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the public SafetyKatz project."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'sharpziplibzipper' project."
author = "FireEye"
- id = "e160b75d-cc39-5e16-86e1-cba9fe64a6b6"
+ id = "392a52be-29ae-58e1-b517-1ab34a1e1fb8"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/SAFETYKATZ/production/yara/HackTool_MSIL_SAFETYKATZ_4.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_SHARPZIPLIBZIPPER_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "45736deb14f3a68e88b038183c23e597"
- logic_hash = "a02b4acea691d485f427ed26487f2f601065901324a8dcd6cd8de9502d8cd897"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "19354edb91a0d79fdf79437f7247bcf155514db40340af91a3320b556dc2e4c2"
score = 75
quality = 73
tags = "FILE"
rev = 3
strings:
- $typelibguid1 = "8347E81B-89FC-42A9-B22C-F59A6A572DEC" ascii nocase wide
+ $typelibguid0 = "485ba350-59c4-4932-a4c1-c96ffec511ef" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and $typelibguid1
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Tool_MSIL_Sharpgrep_1 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_SHARPNATIVEZIPPER_1 : FILE
{
meta:
- description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'SharpGrep' project."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'sharpnativezipper' project."
author = "FireEye"
- id = "c7569d33-f57d-5f9c-aa2a-78866c680b5b"
+ id = "c48835a7-06fe-5b30-be4d-086d98dc7a21"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/SHARPPGREP/production/yara/Tool_MSIL_SharpGrep_1.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_SHARPNATIVEZIPPER_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
hash = "dd8805d0e470e59b829d98397507d8c2"
- logic_hash = "c22bfc50b3ab3c4082006aad3c3c89684cffe1e429b001b0bb08758856a47d04"
+ logic_hash = "fa54375b21abbb613e695f70a15233575fbe6e0536716544bb3b527f5e3ed8c6"
score = 75
quality = 73
tags = "FILE"
- rev = 1
+ rev = 3
strings:
- $typelibguid0 = "f65d75b5-a2a6-488f-b745-e67fc075f445" ascii nocase wide
+ $typelibguid0 = "de5536db-9a35-4e06-bc75-128713ea6d27" ascii nocase wide
condition:
( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Hacktool_PY_Impacketobfuscation_2
+rule FIREEYE_RT_APT_Hacktool_MSIL_SHARPSQLCLIENT_1 : FILE
{
meta:
- description = "wmiexec"
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'sharpsqlclient' project."
author = "FireEye"
- id = "f1059f66-eaff-5866-bafb-c94236cf96a0"
- date = "2020-12-01"
- date = "2020-12-01"
+ id = "4d526c36-f56f-53cf-9bdf-b7a15619eb41"
+ date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/IMPACKETOBF (Wmiexec)/production/yara/HackTool_PY_ImpacketObfuscation_2.yar#L4-L21"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_SHARPSQLCLIENT_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "f3dd8aa567a01098a8a610529d892485"
- logic_hash = "ccbbe507798f16c7acf0780770fdb81b2e7dc333ab8bc51e6216816276c3f14b"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "bc79f80582f4fadecf54d926abdcf61694224654ba5075203f0d1123cf11afc1"
score = 75
- quality = 75
- tags = ""
+ quality = 73
+ tags = "FILE"
rev = 2
strings:
- $s1 = "import random"
- $s2 = "class WMIEXEC" nocase
- $s3 = "class RemoteShell" nocase
- $s4 = /=[\x09\x20]{0,32}str\(int\(time\.time\(\)\)[\x09\x20]{0,32}-[\x09\x20]{0,32}random\.randint\(\d{1,10}[\x09\x20]{0,32},[\x09\x20]{0,32}\d{1,10}\)\)[\x09\x20]{0,32}\+[\x09\x20]{0,32}str\(uuid\.uuid4\(\)\)\.split\([\x22\x27]\-[\x22\x27]\)\[0\]/
- $s5 = /self\.__shell[\x09\x20]{0,32}=[\x09\x20]{0,32}[\x22\x27]cmd.exe[\x09\x20]{1,32}\/q[\x09\x20]{1,32}\/K [\x22\x27]/ nocase
+ $typelibguid0 = "13ed03cd-7430-410d-a069-cf377165fbfd" ascii nocase wide
condition:
- all of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Hacktool_MSIL_Sharpersist_1 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_SHARPPATCHCHECK_1 : FILE
{
meta:
- description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the SharPersist project."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'sharppatchcheck' project."
author = "FireEye"
- id = "586e6c91-6970-57d1-8d8c-05ae9eb6117a"
+ id = "dedc12b9-b9e7-5c13-ad6d-2e286aba2302"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/SHARPERSIST/production/yara/HackTool_MSIL_SharPersist_1.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_SHARPPATCHCHECK_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "98ecf58d48a3eae43899b45cec0fc6b7"
- logic_hash = "cf480026c31b522850e25ba2d7986773d9c664242a2667ecd33151621c98c91e"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "dec6231b656eed1526d4f70fe1b9a476bfb06246f0a7c25f2687d8c68886d400"
score = 75
quality = 73
tags = "FILE"
- rev = 1
+ rev = 2
strings:
- $typelibguid1 = "9D1B853E-58F1-4BA5-AEFC-5C221CA30E48" ascii nocase wide
+ $typelibguid0 = "528b8df5-6e5e-4f3b-b617-ac35ed2f8975" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and $typelibguid1
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Hacktool_MSIL_Sharpersist_2 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_SHARPDNS_1 : FILE
{
meta:
- description = "No description has been set in the source file - FireEye-RT"
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'sharpdns' project."
author = "FireEye"
- id = "49d7891e-b97a-52a8-acfd-bbf986732d6c"
+ id = "db6b45be-f42f-5d0f-b50a-32e7a2cbfce6"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/SHARPERSIST/production/yara/HackTool_MSIL_SharPersist_2.yar#L4-L23"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_SHARPDNS_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "98ecf58d48a3eae43899b45cec0fc6b7"
- logic_hash = "57387352f8fd08e8b859dffc1164d46370f248b337526c265634160010572a00"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "bab36f9b1532c3b24c2aea2907006820ed7cf1c90dae7a8138962e14ac9eff55"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
- rev = 1
+ rev = 2
strings:
- $a1 = "SharPersist.lib"
- $a2 = "SharPersist.exe"
- $b1 = "ERROR: Invalid hotkey location option given." ascii wide
- $b2 = "ERROR: Invalid hotkey given." ascii wide
- $b3 = "ERROR: Keepass configuration file not found." ascii wide
- $b4 = "ERROR: Keepass configuration file was not found." ascii wide
- $b5 = "ERROR: That value already exists in:" ascii wide
- $b6 = "ERROR: Failed to delete hidden registry key." ascii wide
- $pdb1 = "\\SharPersist\\"
- $pdb2 = "\\SharPersist.pdb"
+ $typelibguid0 = "d888cec8-7562-40e9-9c76-2bb9e43bb634" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and ((@pdb2[1]<@pdb1[1]+50) or (1 of ($a*) and 2 of ($b*)))
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Loader_MSIL_Netshshellcoderunner_1 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_SHARPTEMPLATE_1 : FILE
{
meta:
- description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'NetshShellCodeRunner' project."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'sharptemplate' project."
author = "FireEye"
- id = "b3521812-7ea3-5f80-89bd-3bdd71b687f2"
+ id = "0ca9a13c-e0a0-588b-be13-5954b17d95b1"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/NETSHSHELLCODERUNNER/production/yara/Loader_MSIL_NetshShellCodeRunner_1.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_SHARPTEMPLATE_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
hash = "dd8805d0e470e59b829d98397507d8c2"
- logic_hash = "97f6475a9d42697f633e06a9b04a85021ca4920145eb4af257d71b431448f0e9"
+ logic_hash = "9746c1ab7b945d311c53fbdf95993d255369e06b23a3279c9f2e8a4df73ab63c"
score = 75
quality = 73
tags = "FILE"
rev = 2
strings:
- $typelibguid0 = "49c045bc-59bb-4a00-85c3-4beb59b2ee12" ascii nocase wide
+ $typelibguid0 = "e9e452d4-9e58-44ff-ba2d-01b158dda9bb" ascii nocase wide
condition:
( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Builder_MSIL_Sinfuloffice_1 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_SHARPNFS_1 : FILE
{
meta:
- description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'SinfulOffice' project."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'sharpnfs' project."
author = "FireEye"
- id = "cf020fb3-751b-5346-8c0d-dc0a552599a3"
+ id = "b9d1b4e8-644a-5611-85e8-a124f915b443"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/SINFULOFFICE/production/yara/Builder_MSIL_SinfulOffice_1.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_SHARPNFS_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
hash = "dd8805d0e470e59b829d98397507d8c2"
- logic_hash = "b5d49a8720e4daa21e95ec66299daec42e65906017de886ea91f7bb6bfb04c77"
+ logic_hash = "e7f9883376b153849970599d9ecc308882eb86a67834cfd8ab06b44539346125"
score = 75
quality = 73
tags = "FILE"
- rev = 1
+ rev = 3
strings:
- $typelibguid0 = "9940e18f-e3c7-450f-801a-07dd534ccb9a" ascii nocase wide
+ $typelibguid0 = "9f67ebe3-fc9b-40f2-8a18-5940cfed44cf" ascii nocase wide
condition:
( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Methodology_OLE_CHARENCODING_2 : FILE
+rule FIREEYE_RT_Credtheft_MSIL_Credsnatcher_1 : FILE
{
meta:
- description = "Looking for suspicious char encoding"
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'CredSnatcher' project."
author = "FireEye"
- id = "7abd1a11-7a55-50ac-aa6b-537e7c59a5ab"
+ id = "0d8f7495-4748-577d-8ef2-ccc4829fc165"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/SINFULOFFICE/supplemental/yara/Methodology_OLE_CHARENCODING_2.yar#L4-L23"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/CredTheft_MSIL_CredSnatcher_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "41b70737fa8dda75d5e95c82699c2e9b"
- logic_hash = "20843295531dfd88934fe0902a5101c5c0828e82df3289d7f263f16df9c92324"
- score = 65
- quality = 75
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "2c86be1bcf29bcb2c167f9248dee0ab4a5a5c6740fb1f18784ee2e380176df91"
+ score = 75
+ quality = 73
tags = "FILE"
- rev = 4
+ rev = 1
strings:
- $echo1 = "101;99;104;111;32;111;102;102;" ascii wide
- $echo2 = "101:99:104:111:32:111:102:102:" ascii wide
- $echo3 = "101x99x104x111x32x111x102x102x" ascii wide
- $pe1 = "77;90;144;" ascii wide
- $pe2 = "77:90:144:" ascii wide
- $pe3 = "77x90x144x" ascii wide
- $pk1 = "80;75;3;4;" ascii wide
- $pk2 = "80:75:3:4:" ascii wide
- $pk3 = "80x75x3x4x" ascii wide
+ $typelibguid0 = "370b4d21-09d0-433f-b7e4-4ebdd79948ec" ascii nocase wide
condition:
- ( uint32(0)==0xe011cfd0) and filesize <10MB and any of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Hacktool_MSIL_SEATBELT_2 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_SHARPDACL_1 : FILE
{
meta:
- description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the public SeatBelt project."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'sharpdacl' project."
author = "FireEye"
- id = "225b42fe-c73a-59c0-a1f4-1d6dff6e76e1"
+ id = "13f4e3ea-1e36-5fad-9197-66511d6f026a"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/BELTALOWDA/production/yara/HackTool_MSIL_SEATBELT_2.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_SHARPDACL_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "9f401176a9dd18fa2b5b90b4a2aa1356"
- logic_hash = "e48474c5025fd88e3c2824e1e943ff56cde0ea05984aad0249ccf73caa6d4a36"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "5f44ec5ddded18fb3a9132b469b2fe7ccbffb3f907325485f0f72fe3d6bbfa23"
score = 75
quality = 73
tags = "FILE"
rev = 3
strings:
- $typelibguid1 = "AEC32155-D589-4150-8FE7-2900DF4554C8" ascii nocase wide
+ $typelibguid0 = "b3c17fb5-5d5a-4b14-af3c-87a9aa941457" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and $typelibguid1
+ filesize <10MB and ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Hacktool_MSIL_SEATBELT_1 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_SHARPWEBCRAWLER_1 : FILE
{
meta:
- description = "This rule looks for .NET PE files that have regex and format strings found in the public tool SeatBelt. Due to the nature of the regex and format strings used for detection, this rule should detect custom variants of the SeatBelt project."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'sharpwebcrawler' project."
author = "FireEye"
- id = "46477f87-2458-5b8e-894a-9aa536a441ad"
+ id = "29b2a410-bcc4-58df-b192-7a413b3db1c0"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/BELTALOWDA/production/yara/HackTool_MSIL_SEATBELT_1.yar#L4-L25"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_SHARPWEBCRAWLER_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "848837b83865f3854801be1f25cb9f4d"
- logic_hash = "4248e5561ef60e725c23efc89c899d6fc8be5bf2142f700fb70daecd72c30dd8"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "8df328663a813ca0a6864ae0503cbc1b03cfdf839215b9b4f2bb7962adf09bf8"
score = 75
- quality = 30
+ quality = 73
tags = "FILE"
- rev = 3
+ rev = 2
strings:
- $msil = "_CorExeMain" ascii wide
- $str1 = "{ Process = {0}, Path = {1}, CommandLine = {2} }" ascii nocase wide
- $str2 = "Domain=\"(.*)\",Name=\"(.*)\"" ascii nocase wide
- $str3 = "LogonId=\"(\\d+)\"" ascii nocase wide
- $str4 = "{0}.{1}.{2}.{3}" ascii nocase wide
- $str5 = "^\\W*([a-z]:\\\\.+?(\\.exe|\\.dll|\\.sys))\\W*" ascii nocase wide
- $str6 = "*[System/EventID={0}]" ascii nocase wide
- $str7 = "*[System[TimeCreated[@SystemTime >= '{" ascii nocase wide
- $str8 = "(http|ftp|https|file)://([\\w_-]+(?:(?:\\.[\\w_-]+)+))([\\w.,@?^=%&:/~+#-]*[\\w@?^=%&/~+#-])?" ascii nocase wide
- $str9 = "{0}" ascii nocase wide
- $str10 = "{0,-23}" ascii nocase wide
+ $typelibguid0 = "cf27abf4-ef35-46cd-8d0c-756630c686f1" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and $msil and all of ($str*)
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Hacktool_MSIL_Puppyhound_1 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_DNSOVERHTTPS_C2_1 : FILE
{
meta:
- description = "This is a modification of an existing FireEye detection for SharpHound. However, it looks for the string 'PuppyHound' instead of 'SharpHound' as this is all that was needed to detect the PuppyHound variant of SharpHound."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the public 'DoHC2' External C2 project."
author = "FireEye"
- id = "1155f959-c8bc-597a-8a80-abee8d95b6ec"
+ id = "ee71be6c-e3c8-5365-9f32-157f00066c49"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/PUPPYHOUND/production/yara/HackTool_MSIL_PuppyHound_1.yar#L4-L19"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_DNSOVERHTTPS_C2_1.yar#L4-L16"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "eeedc09570324767a3de8205f66a5295"
- logic_hash = "39073bbfef15ecd28c1772e5d01e54c3d5774ecb4c90f0076bda5dc400abacba"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "a482161bbd8e249977f28466ff1381d4693495f8b8ccd9183ae4fde1ec1471eb"
score = 75
- quality = 75
+ quality = 71
tags = "FILE"
- rev = 6
+ rev = 2
strings:
- $1 = "PuppyHound"
- $2 = "UserDomainKey"
- $3 = "LdapBuilder"
- $init = { 28 [2] 00 0A 0A 72 [2] 00 70 1? ?? 28 [2] 00 0A 72 [2] 00 70 1? ?? 28 [2] 00 0A 28 [2] 00 0A 0B 1F 2D }
- $msil = /\x00_Cor(Exe|Dll)Main\x00/
+ $typelibguid0 = "5d9515d0-df67-40ed-a6b2-6619620ef0ef" ascii nocase wide
+ $typelibguid1 = "7266acbb-b10d-4873-9b99-12d2043b1d4e" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and all of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Hacktool_MSIL_Sharphound_3 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_SHARPGOPHER_1 : FILE
{
meta:
- description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the public SharpHound3 project."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'sharpgopher' project."
author = "FireEye"
- id = "456b3208-1e8d-5eb7-81ee-39f1c886c5a7"
+ id = "cc8eb9cd-9a51-5fab-b0a4-247baaa69dd7"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/PUPPYHOUND/production/yara/HackTool_MSIL_SharpHound_3.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_SHARPGOPHER_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "eeedc09570324767a3de8205f66a5295"
- logic_hash = "baeea6cae42c755ee389378229b2b206c82f60f75a5ce5f9cfa06871fc9507d1"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "ac37f77440cb76d7dafa4c9b4130471ca6ca760f6d72691db9ebb8cbaaad0c58"
score = 75
quality = 73
tags = "FILE"
- rev = 4
+ rev = 2
strings:
- $typelibguid1 = "A517A8DE-5834-411D-ABDA-2D0E1766539C" ascii nocase wide
+ $typelibguid0 = "83413a89-7f5f-4c3f-805d-f4692bc60173" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and $typelibguid1
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_APT_Hacktool_MSIL_LUALOADER_1 : FILE
+rule FIREEYE_RT_Credtheft_MSIL_Wcmdump_1 : FILE
{
meta:
- description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'lualoader' project."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'WCMDump' project."
author = "FireEye"
- id = "e8480cf8-1852-5572-8e92-c0ae676b7507"
+ id = "22796ccb-a01e-59d8-8c3a-6cbb62899940"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/LUALOADER/production/yara/APT_HackTool_MSIL_LUALOADER_1.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/CredTheft_MSIL_WCMDump_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
hash = "dd8805d0e470e59b829d98397507d8c2"
- logic_hash = "7e9f9836ec91aa66c8779588cfceff718487f0cb5048d17538c947aba687a4cf"
+ logic_hash = "9fbf53e551342695b306b10f30a3fe32dff359bd70e84e1fa1f190772f5dcbe3"
score = 75
quality = 73
tags = "FILE"
- rev = 3
+ rev = 1
strings:
- $typelibguid0 = "8b546b49-2b2c-4577-a323-76dc713fe2ea" ascii nocase wide
+ $typelibguid0 = "21e322f2-4586-4aeb-b1ed-d240e2a79e19" ascii nocase wide
condition:
( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_APT_Loader_MSIL_LUALOADER_2 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_MODIFIEDSHARPVIEW_1 : FILE
{
meta:
- description = "No description has been set in the source file - FireEye-RT"
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'modifiedsharpview' project."
author = "FireEye"
- id = "f2826dbb-f0a4-5361-94d1-8509c60c4131"
- date = "2020-12-18"
- modified = "2020-12-18"
+ id = "e07d3d4b-fba3-5df7-85f4-927bb8cec2d1"
+ date = "2020-12-09"
+ modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/LUALOADER/production/yara/APT_Loader_MSIL_LUALOADER_2.yar#L4-L19"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_MODIFIEDSHARPVIEW_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- logic_hash = "700927768669eda6976071306e991bfaae136279f4265980521597c699fbed88"
+ hash = "db0eaad52465d5a2b86fdd6a6aa869a5"
+ logic_hash = "a47c48da998243fab92665649fb9d6ecc6ac32e1fd884c2c0d5ccecb05290c10"
score = 75
- quality = 25
+ quality = 73
tags = "FILE"
+ rev = 3
strings:
- $ss1 = "\x3bN\x00e\x00o\x00.\x00I\x00r\x00o\x00n\x00L\x00u\x00a\x00.\x00L\x00u\x00a\x00C\x00o\x00m\x00p\x00i\x00l\x00e\x00O\x00p\x00t\x00i\x00o\x00n\x00s\x00"
- $ss2 = "\x19C\x00o\x00m\x00p\x00i\x00l\x00e\x00C\x00h\x00u\x00n\x00k\x00"
- $ss3 = "\x0fd\x00o\x00c\x00h\x00u\x00n\x00k\x00"
- $ss4 = /.Reflection.Assembly:Load\(\w{1,64}\);?\s{0,245}\w{1,64}\.EntryPoint:Invoke\(nil/ wide
- $ss5 = "1F 8B 08 00 00 00 00 00" wide
- $ss6 = "\x00LoadLibrary\x00"
- $ss7 = "\x00GetProcAddress\x00"
- $ss8 = "\x00VirtualProtect\x00"
+ $typelibguid0 = "22a156ea-2623-45c7-8e50-e864d9fc44d3" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and all of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_APT_Loader_MSIL_LUALOADER_1 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_PRAT_1 : FILE
{
meta:
- description = "No description has been set in the source file - FireEye-RT"
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'prat' project."
author = "FireEye"
- id = "970a869e-bd69-5609-bb8d-77bfa78b0630"
- date = "2020-12-18"
- modified = "2020-12-18"
+ id = "4a876eb0-ed2f-5ef2-a9b3-ba728b07c8c0"
+ date = "2020-12-09"
+ modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/LUALOADER/production/yara/APT_Loader_MSIL_LUALOADER_1.yar#L4-L17"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_PRAT_1.yar#L4-L18"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- logic_hash = "2d73d434ac39ebde990aca817a54208cd04bfbce33f1bcadcf48a50d9389658c"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "d707f017b56b0a873f1edca085ad40fc70cb24e8c9844f377bc28871a941d0b4"
score = 75
- quality = 25
+ quality = 67
tags = "FILE"
+ rev = 3
strings:
- $sb1 = { 1? 72 [4] 14 D0 [2] 00 02 28 [2] 00 0A 1? 8D [2] 00 01 13 ?? 11 ?? 1? 1? 14 28 [2] 00 0A A2 11 ?? 1? 1? 14 28 [2] 00 0A A2 11 ?? 28 [2] 00 0A 28 [2] 00 0A 80 [2] 00 04 7E [2] 00 04 7B [2] 00 0A 7E [2] 00 04 11 ?? 11 ?? 6F [2] 00 0A 6F [2] 00 0A }
- $ss1 = "\x3bN\x00e\x00o\x00.\x00I\x00r\x00o\x00n\x00L\x00u\x00a\x00.\x00L\x00u\x00a\x00C\x00o\x00m\x00p\x00i\x00l\x00e\x00O\x00p\x00t\x00i\x00o\x00n\x00s\x00"
- $ss2 = "\x19C\x00o\x00m\x00p\x00i\x00l\x00e\x00C\x00h\x00u\x00n\x00k\x00"
- $ss3 = "\x0fd\x00o\x00c\x00h\x00u\x00n\x00k\x00"
- $ss4 = /.Reflection.Assembly:Load\(\w{1,64}\);?\s{0,245}\w{1,64}\.EntryPoint:Invoke\(nil/ wide
- $ss5 = "1F 8B 08 00 00 00 00 00" wide
+ $typelibguid0 = "7d1219fb-a954-49a7-96c9-df9e6429a8c7" ascii nocase wide
+ $typelibguid1 = "bc1157c2-aa6d-46f8-8d73-068fc08a6706" ascii nocase wide
+ $typelibguid2 = "c602fae2-b831-41e2-b5f8-d4df6e3255df" ascii nocase wide
+ $typelibguid3 = "dfaa0b7d-6184-4a9a-9eeb-c08622d15801" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and all of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_Hacktool_MSIL_Corehound_1 : FILE
+rule FIREEYE_RT_APT_Hacktool_MSIL_REDTEAMMATERIALS_1 : FILE
{
meta:
- description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'CoreHound' project."
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'red_team_materials' project."
author = "FireEye"
- id = "8c914b34-3e3d-53ae-a5e4-9dbfdff45a24"
+ id = "272cd3e9-884a-566b-ae90-4a79ee726a8d"
date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/COREHOUND/production/yara/HackTool_MSIL_CoreHound_1.yar#L4-L15"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/production/yara/APT_HackTool_MSIL_REDTEAMMATERIALS_1.yar#L4-L16"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
hash = "dd8805d0e470e59b829d98397507d8c2"
- logic_hash = "b0f759709428d5c9404507a13259bf85cb8c405d38b807539098f7cc871023d8"
+ logic_hash = "ca54a1e8335c4256295fc643f5d31eae2e89f020dc7a9b571c4772edaad08022"
score = 75
- quality = 73
+ quality = 71
tags = "FILE"
- rev = 1
+ rev = 3
strings:
- $typelibguid0 = "1fff2aee-a540-4613-94ee-4f208b30c599" ascii nocase wide
+ $typelibguid0 = "86c95a99-a2d6-4ebe-ad5f-9885b06eab12" ascii nocase wide
+ $typelibguid1 = "e06f1411-c7f8-4538-bbb9-46c928732245" ascii nocase wide
condition:
( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_APT_Keylogger_Win32_REDFLARE_1 : FILE
+rule FIREEYE_RT_Loader_MSIL_Netassemblyinject_1 : FILE
{
meta:
- description = "No description has been set in the source file - FireEye-RT"
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'NET-Assembly-Inject' project."
author = "FireEye"
- id = "ad14db66-d640-5712-b2c8-a3d42d5a90f3"
- date = "2020-12-01"
- date = "2020-12-01"
+ id = "62a7dc4c-678b-5f13-9661-4679eafe1c72"
+ date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/REDFLARE/production/yara/APT_Keylogger_Win32_REDFLARE_1.yar#L4-L17"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/NETASSEMBLYINJECT/production/yara/Loader_MSIL_NETAssemblyInject_1.yar#L4-L17"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "d7cfb9fbcf19ce881180f757aeec77dd"
- logic_hash = "aebbaa050bee3775ffac4214ea4ab58284384e7eb41e66ee4838b9359e72821e"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "9a43df9ee26a44f4db5c2d22fbc1a6c86c5af0c9d44a79c6627a4cc8cf31bb8d"
score = 75
- quality = 75
+ quality = 69
tags = "FILE"
rev = 2
strings:
- $create_window = { 6A 00 68 [4] 6A 00 6A 00 68 00 00 00 80 68 00 00 00 80 68 00 00 00 80 68 00 00 00 80 68 00 00 CF 00 68 [4] 68 [4] 6A 00 FF 15 }
- $keys_check = { 6A 14 [0-5] FF [1-5] 6A 10 [0-5] FF [1-5] B9 00 80 FF FF 66 85 C1 75 ?? 68 A0 00 00 00 FF [1-5] B9 00 80 FF FF 66 85 C1 75 ?? 68 A1 00 00 00 FF [1-5] B9 00 80 FF FF 66 85 C1 74 }
+ $typelibguid0 = "af09c8c3-b271-4c6c-8f48-d5f0e1d1cac6" ascii nocase wide
+ $typelibguid1 = "c5e56650-dfb0-4cd9-8d06-51defdad5da1" ascii nocase wide
+ $typelibguid2 = "e8fa7329-8074-4675-9588-d73f88a8b5b6" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D) and ( uint32( uint32(0x3C))==0x00004550) and ( uint16( uint32(0x3C)+0x18)==0x010B) and all of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_APT_Trojan_Win_REDFLARE_1 : FILE
+rule FIREEYE_RT_Hacktool_MSIL_Sharpschtask_1 : FILE
{
meta:
- description = "No description has been set in the source file - FireEye-RT"
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the 'SharpSchtask' project."
author = "FireEye"
- id = "c3054680-9c87-5d90-b78e-b260904340df"
- date = "2020-11-27"
- date = "2020-11-27"
+ id = "5c7a5dee-3bc2-54b2-a7e2-be05ba74d4a1"
+ date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/REDFLARE/production/yara/APT_Trojan_Win_REDFLARE_1.yar#L4-L21"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/SHARPSCHTASK/production/yara/HackTool_MSIL_SharpSchtask_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "100d73b35f23b2fe84bf7cd37140bf4d,4e7e90c7147ee8aa01275894734f4492"
- logic_hash = "08ea2151418f7f75a8b138146c393a5ea85647320cc8e9fe1930d75871ab94bb"
+ hash = "dd8805d0e470e59b829d98397507d8c2"
+ logic_hash = "7437fde82920f4d015a7f149b58924baf6cb220c6f6857d9509e23795ff0811c"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
- rev = 3
+ rev = 1
strings:
- $1 = "initialize" fullword
- $2 = "runCommand" fullword
- $3 = "stop" fullword
- $4 = "fini" fullword
- $5 = "VirtualAllocEx" fullword
- $6 = "WriteProcessMemory" fullword
+ $typelibguid0 = "0a64a5f4-bdb6-443c-bdc7-f6f0bf5b5d6c" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D) and ( uint32( uint32(0x3C))==0x00004550) and all of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and any of them
}
-rule FIREEYE_RT_APT_Loader_Raw64_REDFLARE_1 : FILE
+rule FIREEYE_RT_Hacktool_MSIL_Sharpersist_2 : FILE
{
meta:
description = "No description has been set in the source file - FireEye-RT"
author = "FireEye"
- id = "8e937f6a-404f-53bd-9de2-ed63b1cf48b2"
- date = "2020-11-27"
- date = "2020-11-27"
+ id = "49d7891e-b97a-52a8-acfd-bbf986732d6c"
+ date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/REDFLARE/production/yara/APT_Loader_Raw64_REDFLARE_1.yar#L4-L16"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/SHARPERSIST/production/yara/HackTool_MSIL_SharPersist_2.yar#L4-L23"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "5e14f77f85fd9a5be46e7f04b8a144f5"
- logic_hash = "dac122ccece8a6dd35a5fe9d37860a612aa50ab469b79f4375dbe776f60c7b57"
+ hash = "98ecf58d48a3eae43899b45cec0fc6b7"
+ logic_hash = "57387352f8fd08e8b859dffc1164d46370f248b337526c265634160010572a00"
score = 75
quality = 75
tags = "FILE"
rev = 1
strings:
- $load = { EB ?? 58 48 8B 10 4C 8B 48 ?? 48 8B C8 [1-10] 48 83 C1 ?? 48 03 D1 FF }
+ $a1 = "SharPersist.lib"
+ $a2 = "SharPersist.exe"
+ $b1 = "ERROR: Invalid hotkey location option given." ascii wide
+ $b2 = "ERROR: Invalid hotkey given." ascii wide
+ $b3 = "ERROR: Keepass configuration file not found." ascii wide
+ $b4 = "ERROR: Keepass configuration file was not found." ascii wide
+ $b5 = "ERROR: That value already exists in:" ascii wide
+ $b6 = "ERROR: Failed to delete hidden registry key." ascii wide
+ $pdb1 = "\\SharPersist\\"
+ $pdb2 = "\\SharPersist.pdb"
condition:
- ( uint16(0)!=0x5A4D) and all of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and ((@pdb2[1]<@pdb1[1]+50) or (1 of ($a*) and 2 of ($b*)))
}
-rule FIREEYE_RT_APT_Trojan_Win_REDFLARE_3 : FILE
+rule FIREEYE_RT_Hacktool_MSIL_Sharpersist_1 : FILE
{
meta:
- description = "No description has been set in the source file - FireEye-RT"
+ description = "The TypeLibGUID present in a .NET binary maps directly to the ProjectGuid found in the '.csproj' file of a .NET project. This rule looks for .NET PE files that contain the ProjectGuid found in the SharPersist project."
author = "FireEye"
- id = "2f6785c4-f4d0-52ff-8c46-da953e2ca92a"
- date = "2020-12-01"
- date = "2020-12-01"
+ id = "586e6c91-6970-57d1-8d8c-05ae9eb6117a"
+ date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/REDFLARE/production/yara/APT_Trojan_Win_REDFLARE_3.yar#L4-L19"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/SHARPERSIST/production/yara/HackTool_MSIL_SharPersist_1.yar#L4-L15"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "9ccda4d7511009d5572ef2f8597fba4e,ece07daca53dd0a7c23dacabf50f56f1"
- logic_hash = "ee104bc145686a134e4d6d620dae7d1dacff7645d47f1a8d7a212327352b8e87"
+ hash = "98ecf58d48a3eae43899b45cec0fc6b7"
+ logic_hash = "cf480026c31b522850e25ba2d7986773d9c664242a2667ecd33151621c98c91e"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
rev = 1
strings:
- $calc_image_size = { 28 00 00 00 [2-30] 83 E2 1F [4-20] C1 F8 05 [0-8] 0F AF C? [0-30] C1 E0 02 }
- $str1 = "CreateCompatibleBitmap" fullword
- $str2 = "BitBlt" fullword
- $str3 = "runCommand" fullword
+ $typelibguid1 = "9D1B853E-58F1-4BA5-AEFC-5C221CA30E48" ascii nocase wide
condition:
- ( uint16(0)==0x5A4D) and ( uint32( uint32(0x3C))==0x00004550) and all of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and $typelibguid1
}
-rule FIREEYE_RT_APT_Trojan_Win_REDFLARE_7 : FILE
+rule FIREEYE_RT_APT_Loader_MSIL_WILDCHILD_1 : FILE
{
meta:
description = "No description has been set in the source file - FireEye-RT"
author = "FireEye"
- id = "f891e477-9ff2-57be-9ca5-dd87d9baee29"
- date = "2020-12-02"
- date = "2020-12-02"
+ id = "b9e0707e-98eb-55da-ad1d-6a84bd113747"
+ date = "2020-12-01"
+ date = "2020-12-01"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/REDFLARE/production/yara/APT_Trojan_Win_REDFLARE_7.yar#L4-L21"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/WILDCHILD/production/yara/APT_Loader_MSIL_WILDCHILD_1.yar#L4-L18"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "e7beece34bdf67cbb8297833c5953669, 8025bcbe3cc81fc19021ad0fbc11cf9b"
- logic_hash = "6d7822256ac1bef05304d3396df773e2b20a397311ad820d6ec5fe4cb6bdfbbc"
+ hash = "6f04a93753ae3ae043203437832363c4"
+ logic_hash = "a600c3d127f77dc1f99160e4a242e005970de0abd1798296b6a351b968ca1350"
score = 75
quality = 75
tags = "FILE"
rev = 1
strings:
- $1 = "initialize" fullword
- $2 = "getData" fullword
- $3 = "putData" fullword
- $4 = "fini" fullword
- $5 = "NamedPipe"
- $named_pipe = { 88 13 00 00 [1-8] E8 03 00 00 [20-60] 00 00 00 00 [1-8] 00 00 00 00 [1-40] ( 6A 00 6A 00 6A 03 6A 00 6A 00 68 | 00 00 00 00 [1-6] 00 00 00 00 [1-6] 03 00 00 00 45 33 C? 45 33 C? BA ) 00 00 00 C0 [2-10] FF 15 [4-30] FF 15 [4-7] E7 00 00 00 [4-40] FF 15 [4] 85 C0 }
+ $s1 = "\x00QueueUserAPC\x00"
+ $s2 = "\x00WriteProcessMemory\x00"
+ $sb1 = { 6F [2] 00 0A 28 [2] 00 0A 6F [2] 00 0A 13 ?? 28 [2] 00 0A 28 [2] 00 0A 13 ?? 11 ?? 11 ?? 28 [2] 00 0A [0-16] 7B [2] 00 04 1? 20 [4] 28 [2] 00 0A 11 ?? 28 [2] 00 0A 28 [2] 00 0A 7E [2] 00 0A 7E [2] 00 0A 28 [2] 00 06 [0-16] 14 7E [2] 00 0A 7E [2] 00 0A 1? 20 04 00 08 08 7E [2] 00 0A 14 12 ?? 12 ?? 28 [2] 00 06 [0-16] 7B [2] 00 04 7E [2] 00 0A [0-16] 8E ?? 7E [2] 00 04 7E [2] 00 04 28 [2] 00 06 [4-120] 28 [2] 00 06 [0-80] 6F [2] 00 0A 6F [2] 00 0A 28 [2] 00 06 13 ?? 11 ?? 11 ?? 7E [2] 00 0A 28 [2] 00 06 }
condition:
- ( uint16(0)==0x5A4D) and ( uint32( uint32(0x3C))==0x00004550) and all of them
+ ( uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550) and all of them
}
-rule FIREEYE_RT_APT_Loader_Win64_REDFLARE_2 : FILE
+rule FIREEYE_RT_Dropper_HTA_Wildchild_1 : FILE
{
meta:
- description = "No description has been set in the source file - FireEye-RT"
+ description = "This rule looks for strings present in unobfuscated HTAs generated by the WildChild builder."
author = "FireEye"
- id = "043f4e29-710d-5e17-a0ed-82cd3a565194"
- date = "2020-11-27"
- date = "2020-11-27"
+ id = "f570baa5-7d58-5a0a-b713-769e62076f76"
+ date = "2020-12-09"
modified = "2020-12-09"
reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/REDFLARE/production/yara/APT_Loader_Win64_REDFLARE_2.yar#L4-L18"
+ source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/WILDCHILD/production/yara/Dropper_HTA_WildChild_1.yar#L4-L24"
license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "100d73b35f23b2fe84bf7cd37140bf4d"
- logic_hash = "9fad845ed963fae46ac7ddc44407d5f6ed0a061f6a106764b9f912ef718279b4"
+ hash = "3e61ca5057633459e96897f79970a46d"
+ logic_hash = "60c1d53b8a43b9b7518f3260a4d61c6806641ee894a2a331a3a0a2ea0aff9d99"
score = 75
quality = 75
tags = "FILE"
- rev = 1
+ rev = 5
strings:
- $alloc = { 45 8B C0 33 D2 [2-6] 00 10 00 00 [2-6] 04 00 00 00 [1-6] FF 15 [4-60] FF 15 [4] 85 C0 [4-40] 20 00 00 00 [4-40] FF 15 [4] 85 C0 }
- $inject = { 83 F8 01 [2-20] 33 C0 45 33 C9 [3-10] 45 33 C0 [3-10] 33 D2 [30-100] FF 15 [4] 85 C0 [20-100] 01 00 10 00 [0-10] FF 15 [4] 85 C0 [4-30] FF 15 [4] 85 C0 [2-20] FF 15 [4] 83 F8 FF }
- $s1 = "ResumeThread" fullword
+ $s1 = "processpath" ascii wide
+ $s2 = "v4.0.30319" ascii wide
+ $s3 = "v2.0.50727" ascii wide
+ $s4 = "COMPLUS_Version" ascii wide
+ $s5 = "FromBase64Transform" ascii wide
+ $s6 = "MemoryStream" ascii wide
+ $s7 = "entry_class" ascii wide
+ $s8 = "DynamicInvoke" ascii wide
+ $s9 = "Sendoff" ascii wide
+ $script_header = "" nocase
+ $antiregistration = "" nocase
+ $scriptletend = ""
condition:
- ( uint16(0)==0x5A4D) and ( uint32( uint32(0x3C))==0x00004550) and all of them
+ all of them and @scriptletstart[1]<@registration[1] and @registration[1]<@classid[1] and @classid[1]<@scriptlang[1] and @scriptlang[1]<@cdata[1]
}
-rule FIREEYE_RT_Loader_Win_Generic_20 : FILE
+rule GCTI_Cobaltstrike_Resources_Httpsstager_Bin_V2_5_Through_V4_X
{
meta:
- description = "No description has been set in the source file - FireEye-RT"
- author = "FireEye"
- id = "d1d3eff8-d12e-53f6-8c30-06ecedaf3f49"
- date = "2020-12-02"
- date = "2020-12-02"
- modified = "2020-12-09"
- reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/UNCATEGORIZED/supplemental/yara/Loader_Win_Generic_20.yar#L4-L19"
- license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "5125979110847d35a338caac6bff2aa8"
- logic_hash = "9611aed2b4e4278d40254cb5c4fe94a458cfa19f10e6fe888bc7ceb166669cc6"
+ description = "Cobalt Strike's resources/httpsstager.bin signature for versions 2.5 to 4.x"
+ author = "gssincla@google.com"
+ id = "f45aa40a-3936-50f9-a60e-de7181862d19"
+ date = "2022-11-18"
+ modified = "2022-11-19"
+ reference = "https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse"
+ source_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/YARA/CobaltStrike/CobaltStrike__Resources_Httpsstager_Bin_v2_5_through_v4_x.yara#L17-L95"
+ license_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/LICENSE"
+ hash = "5ebe813a4c899b037ac0ee0962a439833964a7459b7a70f275ac73ea475705b3"
+ logic_hash = "d2f722809a59faf8ecd85e46eadf58bf23ba5f515ad9c949843f1e6bfeec1fbf"
score = 75
- quality = 75
- tags = "FILE"
- rev = 1
+ quality = 85
+ tags = ""
strings:
- $s0 = { 8B [1-16] 89 [1-16] E8 [4-32] F3 A4 [0-16] 89 [1-8] E8 }
- $s2 = { 83 EC [4-24] 00 10 00 00 [4-24] C7 44 24 ?? ?? 00 00 00 [0-8] FF 15 [4-24] 89 [1-4] 89 [1-4] 89 [1-8] FF 15 [4-16] 3? ?? 7? [4-24] 20 00 00 00 [4-24] FF 15 [4-32] F3 A5 }
- $si1 = "VirtualProtect" fullword
- $si2 = "malloc" fullword
+ $apiLocator = {
+ 31 ??
+ AC
+ C1 ?? 0D
+ 01 ??
+ 38 ??
+ 75 ??
+ 03 [2]
+ 3B [2]
+ 75 ??
+ 5?
+ 8B ?? 24
+ 01 ??
+ 66 8B [2]
+ 8B ?? 1C
+ 01 ??
+ 8B ?? 8B
+ 01 ??
+ 89 [3]
+ 5?
+ 5?
+ }
+ $InternetSetOptionA = {
+ 6A 04
+ 5?
+ 6A 1F
+ 5?
+ 68 75 46 9E 86
+ FF
+ }
condition:
- ( uint16(0)==0x5A4D) and ( uint32( uint32(0x3C))==0x00004550) and all of them
+ $apiLocator and $InternetSetOptionA
}
-rule FIREEYE_RT_Dropper_HTA_Wildchild_1 : FILE
+rule GCTI_Cobaltstrike_Resources_Covertvpn_Dll_V2_1_To_V4_X
{
meta:
- description = "This rule looks for strings present in unobfuscated HTAs generated by the WildChild builder."
- author = "FireEye"
- id = "f570baa5-7d58-5a0a-b713-769e62076f76"
- date = "2020-12-09"
- modified = "2020-12-09"
- reference = "https://github.com/mandiant/red_team_tool_countermeasures/"
- source_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/rules/WILDCHILD/production/yara/Dropper_HTA_WildChild_1.yar#L4-L24"
- license_url = "https://github.com/mandiant/red_team_tool_countermeasures//blob/3561b71724dbfa3e2bb78106aaa2d7f8b892c43b/LICENSE.txt"
- hash = "3e61ca5057633459e96897f79970a46d"
- logic_hash = "60c1d53b8a43b9b7518f3260a4d61c6806641ee894a2a331a3a0a2ea0aff9d99"
+ description = "Cobalt Strike's resources/covertvpn.dll signature for version v2.2 to v4.4"
+ author = "gssincla@google.com"
+ id = "a65b855c-5703-5b9f-bb57-da8ebf898f9b"
+ date = "2022-11-18"
+ modified = "2022-11-19"
+ reference = "https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse"
+ source_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/YARA/CobaltStrike/CobaltStrike__Resources_Covertvpn_Dll_v2_1_to_v4_x.yara#L17-L120"
+ license_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/LICENSE"
+ hash = "0a452a94d53e54b1df6ba02bc2f02e06d57153aad111171a94ec65c910d22dcf"
+ logic_hash = "1f6e4254fdfd4f9b13c2000333aabbb7da90d2df7ee1b12faa6ea3c066351468"
score = 75
- quality = 75
- tags = "FILE"
- rev = 5
+ quality = 85
+ tags = ""
strings:
- $s1 = "processpath" ascii wide
- $s2 = "v4.0.30319" ascii wide
- $s3 = "v2.0.50727" ascii wide
- $s4 = "COMPLUS_Version" ascii wide
- $s5 = "FromBase64Transform" ascii wide
- $s6 = "MemoryStream" ascii wide
- $s7 = "entry_class" ascii wide
- $s8 = "DynamicInvoke" ascii wide
- $s9 = "Sendoff" ascii wide
- $script_header = "" nocase
- $antiregistration = "" nocase
- $scriptletend = ""
+ $sequence_0 = { 8b7c2404 66c1c60c 8b742408 f6d7 33cd f7d3 }
+ $sequence_1 = { 8f442434 51 887c2404 66890424 890424 }
+ $sequence_2 = { 8b0c8d20ee4000 8d440104 8020fe ff36 e8???????? 59 }
+ $sequence_3 = { c3 8bff 56 57 33f6 bf???????? 833cf5a4d5400001 }
+ $sequence_4 = { 8b0c8d20ee4000 c1e006 8d440104 8020fe ff36 }
+ $sequence_5 = { c1f805 8d3c8520ee4000 8bf3 83e61f c1e606 8b07 0fbe440604 }
+ $sequence_6 = { 888c05f4fdffff 40 84c9 75ed 8d85f8feffff 6a5c }
+ $sequence_7 = { 50 66a5 ff15???????? 6810270000 ff15???????? }
+ $sequence_8 = { 5b c21000 ff25???????? c705????????6ca14000 }
+ $sequence_9 = { 8f442434 9c 57 ff74243c c24000 686d3f4f6e }
condition:
- all of them and @scriptletstart[1]<@registration[1] and @registration[1]<@classid[1] and @classid[1]<@scriptlang[1] and @scriptlang[1]<@cdata[1]
+ 7 of them and filesize <360448
}
-rule GCTI_Cobaltstrike_Resources_Browserpivot_X64_Bin_V1_48_To_V3_14_And_Sleeve_Browserpivot_X64_Dll_V4_0_To_V4_X
+rule MALPEDIA_Win_Acehash_Auto : FILE
{
meta:
- description = "Cobalt Strike's resources/browserpivot.x64.bin from v1.48 to v3.14 and sleeve/browserpivot.x64.dll from v4.0 to at least v4.4"
- author = "gssincla@google.com"
- id = "a5dfae85-ff9c-5ca5-9ac0-041c6108a6ed"
- date = "2022-11-18"
- modified = "2022-11-19"
- reference = "https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse"
- source_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/YARA/CobaltStrike/CobaltStrike__Resources_Browserpivot_x64_Bin_v1_48_to_v3_14_and_Sleeve_Browserpivot_x64_Dll_v4_0_to_v4_x.yara#L17-L64"
- license_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/LICENSE"
- hash = "0ad32bc4fbf3189e897805cec0acd68326d9c6f714c543bafb9bc40f7ac63f55"
- logic_hash = "a59f19b6e258b724ed88b4255717d066319ba5fb0838d6c6ed11355e9d9b1c22"
+ description = "autogenerated rule brought to you by yara-signator"
+ author = "Felix Bilstein - yara-signator at cocacoding dot com"
+ id = "14f9c3a4-6e4e-554e-b1b7-7826b028e7e0"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acehash"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.acehash_auto.yar#L1-L130"
+ license_url = "N/A"
+ logic_hash = "a82974d1f4758bd3335b7cc99825d249f1ec423d226c32410d6047b493cb8d39"
score = 75
- quality = 85
- tags = ""
+ quality = 75
+ tags = "FILE"
+ version = "1"
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
strings:
- $socket_recv = {
- FF 15 [4]
- 83 ?? FF
- 74 ??
- 85 ??
- 74 ??
- 03 ??
- 83 ?? 02
- 72 ??
- 8D ?? FF
- 80 [2] 0A
- 75 ??
- 8D ?? FE
- 80 [2] 0D
- }
- $fmt = "%1024[^ ] %8[^:]://%1016[^/]%7168[^ ] %1024[^ ]"
+ $sequence_0 = { 4885c0 7420 488d1599dc0200 488bcb ff15???????? 488bc8 }
+ $sequence_1 = { 85c0 0f85e6000000 4c8b470c 488b55d0 488b4f04 ff15???????? 8bd8 }
+ $sequence_2 = { 488b7d98 8b742440 8b542458 41bb00020000 4c8d0d4e23feff 448a3f 4584ff }
+ $sequence_3 = { 7510 b810000000 488b5c2430 4883c420 5f c3 4885db }
+ $sequence_4 = { 85ff 0f8513ffffff 33c0 4c8b642450 4c8b6c2458 488b5c2460 4883c430 }
+ $sequence_5 = { 442b8486a0e10300 4533d8 83bf800000000a 0f863c010000 8b4730 8b4f70 458d0c03 }
+ $sequence_6 = { 8bc3 483bd0 0f871a050000 4c8d151995fdff 4403f2 4b8b8ceaa0511100 8a443108 }
+ $sequence_7 = { 8bfd 66895802 410fb78704100000 0fbfcb }
+ $sequence_8 = { 7cda 440fbf4302 418bd4 488bce 468d048508000000 e8???????? 488d0d33240300 }
+ $sequence_9 = { 48833d????????00 488d0581900300 740f 3908 740e 4883c010 4883780800 }
condition:
- all of them
+ 7 of them and filesize <2318336
}
-rule GCTI_Cobaltstrike_Resources_Artifact32_And_Resources_Dropper_V1_49_To_V3_14
+rule MALPEDIA_Win_Unidentified_106_Auto : FILE
{
meta:
- description = "Cobalt Strike's resources/artifact32{.exe,.dll,big.exe,big.dll} and resources/dropper.exe signature for versions 1.49 to 3.14"
- author = "gssincla@google.com"
- id = "243e3761-cbea-561c-97da-f6ba12ebc7ee"
- date = "2022-11-18"
- modified = "2022-11-19"
- reference = "https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse"
- source_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/YARA/CobaltStrike/CobaltStrike__Resources_Artifact32_and_Resources_Dropper_v1_45_to_v4_x.yara#L17-L32"
- license_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/LICENSE"
- hash = "40fc605a8b95bbd79a3bd7d9af73fbeebe3fada577c99e7a111f6168f6a0d37a"
- logic_hash = "437706c808bca28384a6e8e24fa3ae120a4ebe4166fa4ca3564c58b881fb23a8"
+ description = "autogenerated rule brought to you by yara-signator"
+ author = "Felix Bilstein - yara-signator at cocacoding dot com"
+ id = "149fd261-d790-5329-9f62-f83b72c17c68"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_106"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_106_auto.yar#L1-L134"
+ license_url = "N/A"
+ logic_hash = "b7794c4f304d97457540366e3546931a6b0930939bfed6f5754198d0fc46abff"
score = 75
- quality = 85
- tags = ""
+ quality = 75
+ tags = "FILE"
+ version = "1"
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
strings:
- $payloadDecoder = { 8B [2] 89 ?? 03 [2] 8B [2] 03 [2] 0F B6 18 8B [2] 89 ?? C1 ?? 1F C1 ?? 1E 01 ?? 83 ?? 03 29 ?? 03 [2] 0F B6 00 31 ?? 88 ?? 8B [2] 89 ?? 03 [2] 8B [2] 03 [2] 0F B6 12 }
+ $sequence_0 = { 8bc2 3bd5 7d14 2bea 33d2 448bc5 49c1e002 }
+ $sequence_1 = { d0250000ffff 3d00000d00 740e 8b4b04 53 e8???????? 413bc7 }
+ $sequence_2 = { e8???????? 488b8bf8000000 4889bbf0000000 e8???????? 488b8b00010000 4889bbf8000000 e8???????? }
+ $sequence_3 = { e8???????? e8???????? 8bc8 b881808080 f7e9 03d1 c1fa07 }
+ $sequence_4 = { 8bc1 418d140e 4803c6 41b800100000 66440b833c040000 4889442438 8bc2 }
+ $sequence_5 = { a806 0f85cf020000 bafbff0000 6623c2 6683c802 66898108030000 33c0 }
+ $sequence_6 = { 488d442448 4889442428 4c8bcb 488d442430 418bd7 498bce 4889442420 }
+ $sequence_7 = { e8???????? 85c0 7920 488b0f 488d5710 4885d2 0f8454fbffff }
+ $sequence_8 = { e9???????? 498b5f08 be02000000 440fb7f5 4d03f3 4180fc06 7508 }
+ $sequence_9 = { 90 eb02 eb00 498bc4 488b5c2478 488bac2480000000 4883c440 }
condition:
- any of them
+ 7 of them and filesize <27402240
}
-rule GCTI_Cobaltstrike_Resources_Artifact32_V3_1_And_V3_2
+rule MALPEDIA_Win_Beatdrop_Auto : FILE
{
meta:
- description = "Cobalt Strike's resources/artifact32{.dll,.exe,svc.exe,big.exe,big.dll,bigsvc.exe} and resources/artifact32uac(alt).dll signature for versions 3.1 and 3.2"
- author = "gssincla@google.com"
- id = "4fff7f42-9f50-5945-8ec0-2438ac5c7000"
- date = "2022-11-18"
- modified = "2022-11-19"
- reference = "https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse"
- source_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/YARA/CobaltStrike/CobaltStrike__Resources_Artifact32_and_Resources_Dropper_v1_45_to_v4_x.yara#L34-L60"
- license_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/LICENSE"
- hash = "4f14bcd7803a8e22e81e74d6061d0df9e8bac7f96f1213d062a29a8523ae4624"
- logic_hash = "7a0d33d0260c762b4aa67e4084d7474338c60aa684fd3e622614745d90350da8"
+ description = "autogenerated rule brought to you by yara-signator"
+ author = "Felix Bilstein - yara-signator at cocacoding dot com"
+ id = "b3142cf9-1fa2-58bd-9f49-d91bf2cf24b1"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.beatdrop"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.beatdrop_auto.yar#L1-L124"
+ license_url = "N/A"
+ logic_hash = "171eb025ab1384be132ed16b4793a3dd033a6c86c2974208fbbb41bec30e49af"
score = 75
- quality = 85
- tags = ""
+ quality = 75
+ tags = "FILE"
+ version = "1"
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
strings:
- $decoderFunc = { 89 ?? B? 04 00 00 00 99 F7 FF 8B [2] 8A [2] 30 ?? 8A ?? 4? 88 }
+ $sequence_0 = { e8???????? 4c89f1 e8???????? 4c8d0571aaffff }
+ $sequence_1 = { 4733bc84000c0000 4189c1 4589f0 41c1e918 4433bebc000000 41c1e810 }
+ $sequence_2 = { 0fb6c0 413394b5000c0000 c1eb18 33552c 4133948500040000 4489c0 }
+ $sequence_3 = { 4189d3 0fb6ce 41c1e818 41c1eb18 478b4c8500 4589f8 438b5c9d00 }
+ $sequence_4 = { 4189d3 c1ea18 41c1eb10 335e78 418b1494 4333948c000c0000 450fb6db }
+ $sequence_5 = { 4489cb 334610 41c1eb18 450fb6d2 0fb6df 4333849400040000 }
+ $sequence_6 = { 41c1e818 4189cf 4489d1 478b0484 4733848c000c0000 4589d1 }
+ $sequence_7 = { 488b3d???????? 89d8 4989ce 4989d5 488b0d???????? 4c89c6 4c89cd }
+ $sequence_8 = { 498344241010 eb11 498d4c2408 e8???????? eb05 49ff442418 }
+ $sequence_9 = { e8???????? 4885c0 752c 4c8b4b08 41b813000000 }
condition:
- all of them
+ 7 of them and filesize <584704
}
-rule GCTI_Cobaltstrike_Resources_Artifact32_V3_14_To_V4_X
+rule MALPEDIA_Win_Darkrat_Auto : FILE
{
meta:
- description = "Cobalt Strike's resources/artifact32{.dll,.exe,big.exe,big.dll,bigsvc.exe} signature for versions 3.14 to 4.x and resources/artifact32svc.exe for 3.14 to 4.x and resources/artifact32uac.dll for v3.14 and v4.0"
- author = "gssincla@google.com"
- id = "8a010305-dce5-55f4-b2dd-a736721efe22"
- date = "2022-11-18"
- modified = "2022-11-19"
- reference = "https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse"
- source_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/YARA/CobaltStrike/CobaltStrike__Resources_Artifact32_and_Resources_Dropper_v1_45_to_v4_x.yara#L62-L89"
- license_url = "https://github.com/chronicle/GCTI/blob/1c5fd42b1895098527fde00c2d9757edf6b303bb/LICENSE"
- hash = "888bae8d89c03c1d529b04f9e4a051140ce3d7b39bc9ea021ad9fc7c9f467719"
- logic_hash = "fc5c353c568e33df80fa5bab14d11112ca211e269043b83dba8b7d1a6a008a7b"
+ description = "autogenerated rule brought to you by yara-signator"
+ author = "Felix Bilstein - yara-signator at cocacoding dot com"
+ id = "73555b6d-cd36-53aa-b241-54638d6391a7"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkrat_auto.yar#L1-L124"
+ license_url = "N/A"
+ logic_hash = "e98d828b961bffb4ad606aad50a055367532a60432b86ca76a8c360da1aac44b"
score = 75
- quality = 85
- tags = ""
+ quality = 75
+ tags = "FILE"
+ version = "1"
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
strings:
- $pushFmtStr = { C7 [3] 5C 00 00 00 C7 [3] 65 00 00 00 C7 [3] 70 00 00 00 C7 [3] 69 00 00 00 C7 [3] 70 00 00 00 F7 F1 C7 [3] 5C 00 00 00 C7 [3] 2E 00 00 00 C7 [3] 5C 00 00 00 }
- $fmtStr = "%c%c%c%c%c%c%c%c%cMSSE-%d-server"
+ $sequence_0 = { 837de810 895510 8b4804 8d45d4 0f4345d4 2975b4 }
+ $sequence_1 = { 51 03f8 52 57 e8???????? 8b45c8 83c40c }
+ $sequence_2 = { 51 56 e8???????? 83c40c c6043e00 eb17 57 }
+ $sequence_3 = { 8b7dd4 0f8514ffffff 8b55ec 83fa10 }
+ $sequence_4 = { 8bd0 b805000000 2bd6 8a0e 8d7601 884c32ff 83e801 }
+ $sequence_5 = { e8???????? 83c408 c745e800000000 8d4dd8 }
+ $sequence_6 = { 0b510c 52 e8???????? c745fc04000000 e8???????? 84c0 7507 }
+ $sequence_7 = { 83c408 c745e800000000 8d4dd8 c745ec0f000000 c645d800 }
+ $sequence_8 = { ff75d0 51 8bcb e8???????? 8b75b8 c645fc01 }
+ $sequence_9 = { 895510 8b4804 8d45d4 0f4345d4 2975b4 03c6 ff75b4 }
condition:
- all of them
+ 7 of them and filesize <884736
}
-/*
- * YARA Rule Set
- * Repository Name: Malpedia
- * Repository: https://github.com/malpedia/signator-rules/
- * Retrieval Date: 2024-08-04
- * Git Commit: fbacfc09b84d53d410385e66a8e56f25016c588a
- * Number of Rules: 1382
- * Skipped: 0 (age), 15 (quality), 0 (score), 0 (importance)
- *
- *
- * LICENSE
- *
- * NO LICENSE SET
- */
-rule MALPEDIA_Win_Thanatos_Ransom_Auto : FILE
+rule MALPEDIA_Win_Vawtrak_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fa527852-1102-5288-af99-f970a4826a1e"
+ id = "b724e7c8-fa8b-5ecb-9091-2adfef543aee"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thanatos_ransom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.thanatos_ransom_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vawtrak"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vawtrak_auto.yar#L1-L212"
license_url = "N/A"
- logic_hash = "9c5c5f690fb079c4870ec7aa84eb31a9ced013d63674be92b3d66d32a913f4ab"
+ logic_hash = "2420d7270c56567b74aa80afdfcc3b5893cd81eeb0dabc0a53855a9b85be220c"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -129264,32 +136301,45 @@ rule MALPEDIA_Win_Thanatos_Ransom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ff75e0 e8???????? 8b4df8 8bc7 5f 33cd }
- $sequence_1 = { 8b00 8bc8 e8???????? c645fc0a }
- $sequence_2 = { 50 e8???????? 56 8bd0 c645fc04 }
- $sequence_3 = { 83c404 c60300 ff15???????? 50 e8???????? be14000000 }
- $sequence_4 = { c745500f000000 c7454c00000000 c6453c00 83f810 7242 8b4d54 }
- $sequence_5 = { 88441de8 43 8975e0 83fb04 757c 33f6 8a4435e8 }
- $sequence_6 = { 8b0c85e0774300 8a06 46 8844392c 2bf2 eb14 }
- $sequence_7 = { 0f8580000000 8b4508 dd00 ebc6 c745e0a0bd4200 e9???????? }
- $sequence_8 = { 40 8d4de0 50 ff75e0 e8???????? 8b4df8 }
- $sequence_9 = { e8???????? c70021000000 e9???????? 894ddc c745e034bf4200 e9???????? c745e030bf4200 }
+ $sequence_0 = { 6a01 ff35???????? 6a04 6a01 50 ff15???????? 85c0 }
+ $sequence_1 = { 6a00 6a00 e8???????? 50 ff15???????? }
+ $sequence_2 = { 837d1040 752d 8b4d04 e8???????? 85c0 }
+ $sequence_3 = { 8b4d08 e8???????? 85c0 7415 ff15???????? 50 }
+ $sequence_4 = { ba00ff0000 8bc1 23c2 3bc2 }
+ $sequence_5 = { 750f 33c9 e8???????? 85c0 7404 }
+ $sequence_6 = { b8ff0f0000 6623e8 b800400000 660be8 }
+ $sequence_7 = { 6a08 68???????? 56 ffd7 85c0 }
+ $sequence_8 = { 50 ff15???????? a3???????? 85c0 74e7 }
+ $sequence_9 = { 7528 68???????? ff15???????? 85c0 7504 33c0 }
+ $sequence_10 = { 59 57 8bf0 ff15???????? 8bc6 }
+ $sequence_11 = { e8???????? 33d2 b9ff3f0000 f7f1 }
+ $sequence_12 = { 8bc6 8703 3bc6 74f8 }
+ $sequence_13 = { 56 6a04 53 57 }
+ $sequence_14 = { 7705 80ea61 eb0a 8d42bf }
+ $sequence_15 = { 03c1 8b4d14 8901 33c0 40 }
+ $sequence_16 = { e9???????? 8ac1 c1e904 c0e004 }
+ $sequence_17 = { 8ac8 240f 80e1f0 80c110 32c8 }
+ $sequence_18 = { 3c41 7c11 3c46 7f0d }
+ $sequence_19 = { 48397c2430 7505 bb01000000 8bc3 }
+ $sequence_20 = { 4885c0 7440 ff15???????? 488b0b 33ff 3db7000000 }
+ $sequence_21 = { 0f84ff000000 3d00010000 7320 488b0b }
+ $sequence_22 = { 420fb61408 8bc1 ffc1 42881408 }
condition:
- 7 of them and filesize <516096
+ 7 of them and filesize <1027072
}
-rule MALPEDIA_Win_Webc2_Table_Auto : FILE
+rule MALPEDIA_Win_Derusbi_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "398ecdfa-bd77-5001-b308-7e740d6a25e6"
+ id = "7e17bc22-c095-50d8-a4c2-1bf339697e7b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_table"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_table_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.derusbi"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.derusbi_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "659cc34946aa5d8ea6957b273afd39f56e48147569d9730da4a86aafe181a1ab"
+ logic_hash = "325459f5183ff3b300e1f181ae53b4a2cb1c12e04a563b27e6a394d452c11ac4"
score = 75
quality = 75
tags = "FILE"
@@ -129303,32 +136353,32 @@ rule MALPEDIA_Win_Webc2_Table_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d85e4feffff 50 ff75fc ff15???????? 85c0 0f8461010000 }
- $sequence_1 = { 83c410 881d???????? 8345fc04 ff4dec 0f8567feffff }
- $sequence_2 = { 8dbda1fcffff 889da0fcffff f3ab 66ab aa 8d859cfbffff 6804010000 }
- $sequence_3 = { 53 894dec ffd6 59 }
- $sequence_4 = { 8b45f4 bf???????? 57 50 885c30f4 8b35???????? }
- $sequence_5 = { 50 53 ff15???????? 85c0 750a ff15???????? 32c0 }
- $sequence_6 = { ff75fc 8d85bcfdffff 50 e8???????? 59 }
- $sequence_7 = { 50 8945e8 e8???????? 83c40c 895df8 8d45c4 }
- $sequence_8 = { e8???????? 0fb745e0 50 0fb745de 50 }
- $sequence_9 = { ff7508 6a01 50 ff15???????? 56 }
+ $sequence_0 = { 8b819c000000 8d4de8 51 8d4dec 51 ffb00c010000 c745e810000000 }
+ $sequence_1 = { 8d55ec e8???????? 8d4f08 56 8d55f3 e8???????? 59 }
+ $sequence_2 = { 8913 ff15???????? 83c40c e8???????? b301 57 ff15???????? }
+ $sequence_3 = { 33c5 8945f8 8b4508 66833800 53 56 57 }
+ $sequence_4 = { 8945f8 8b4508 56 57 50 8d8de4fbffff 899590f9ffff }
+ $sequence_5 = { 64a300000000 8b5d0c 8b4508 894c2414 89442418 85db 0f8457050000 }
+ $sequence_6 = { 50 ffd6 b903010000 2bc8 51 8d85ecfdffff 68???????? }
+ $sequence_7 = { 56 56 56 6a03 56 68???????? 6800040000 }
+ $sequence_8 = { ffd3 50 57 ffb5f8fbffff ff15???????? 83c410 85c0 }
+ $sequence_9 = { ffb5d4fdffff 898db8fdffff ffb5ecfdffff ffb5f0fdffff ff15???????? 3bc7 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <360448
}
-rule MALPEDIA_Win_Mosaic_Regressor_Auto : FILE
+rule MALPEDIA_Win_Catchamas_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6545d5ce-704c-5c00-a6cd-ec1b5c909576"
+ id = "f5823958-4dc9-52e1-b587-ac7a6b699e31"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mosaic_regressor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mosaic_regressor_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.catchamas"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.catchamas_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "73c7fd14f8effd7ac9e0816b586de74eff8d0d21c8391e8e84f2921e57196fdb"
+ logic_hash = "49e84bf121f6f46a8c4833df80092f815e20586f9bd57ea545ff931ae803e6c2"
score = 75
quality = 75
tags = "FILE"
@@ -129342,32 +136392,32 @@ rule MALPEDIA_Win_Mosaic_Regressor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 670010 386700 1023 d18a0688078a }
- $sequence_1 = { 8975e0 8db1d0a70010 8975e4 eb2a }
- $sequence_2 = { 85c0 7456 8b4de0 8d0c8de0b70010 8901 8305????????20 }
- $sequence_3 = { f3a4 6a1c 8d8c2480060000 51 6a00 ffd5 8d842478060000 }
- $sequence_4 = { 8d442460 50 6a00 ffd5 8d442458 48 8d4900 }
- $sequence_5 = { 895008 8d542458 52 88480c }
- $sequence_6 = { c744241444000000 8bc8 90 8a10 }
- $sequence_7 = { 6a06 89430c 8d4310 8d89c4a70010 5a }
- $sequence_8 = { 8bff 55 8bec 8b4508 ff34c578a10010 ff15???????? 5d }
- $sequence_9 = { 6a00 6a00 6a00 8d942498080000 }
+ $sequence_0 = { ffd6 6808080000 8d54246c 52 }
+ $sequence_1 = { 5f 5e 8b8c247c200000 33cc e8???????? }
+ $sequence_2 = { 6a00 ff15???????? e8???????? 8bcb 8b5c244c 51 }
+ $sequence_3 = { 6683f814 0f84c4080000 833d????????00 0f85af000000 }
+ $sequence_4 = { 50 bf01000000 ff15???????? 56 ff15???????? 85ff 0f851a010000 }
+ $sequence_5 = { 50 8d8c2494100000 68???????? 51 ff15???????? 83c42c 33c0 }
+ $sequence_6 = { 84c0 8b45e0 7409 e8???????? 8bfc eb32 }
+ $sequence_7 = { ffd7 6a0a 56 8be8 ffd7 8bf8 }
+ $sequence_8 = { 83e802 0f84bf090000 83e80d 0f845a090000 }
+ $sequence_9 = { 51 57 8bf0 50 ebbd e8???????? }
condition:
- 7 of them and filesize <113664
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Zenar_Auto : FILE
+rule MALPEDIA_Win_Tinba_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4a5b8e75-0846-5f97-8625-2c49ccc878e4"
+ id = "8b073df0-6973-5487-9d6c-3a57aeeab821"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zenar"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zenar_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinba"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tinba_auto.yar#L1-L141"
license_url = "N/A"
- logic_hash = "aaf8e2aaae847a92d9529fc5af1d76e9bd4aae4fdb4d807ed83b4a0145bc159f"
+ logic_hash = "3e0ce52a496c3fcf4e972331a3890b233f5a6cdb900c63778e37d0782cfe61e3"
score = 75
quality = 75
tags = "FILE"
@@ -129381,32 +136431,35 @@ rule MALPEDIA_Win_Zenar_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7409 83c024 50 8b08 ff5108 8b4df4 }
- $sequence_1 = { 8bf1 8d8e80020000 e8???????? 8d8e68020000 e8???????? 8bce 5e }
- $sequence_2 = { 8bc7 8bcf 83e03f c1f906 6bf038 03348d98ae4300 }
- $sequence_3 = { 8d8d70ffffff c645fc03 e8???????? 84c0 7406 8ac3 }
- $sequence_4 = { 8bfe 83e03f c1ff06 6bd838 8b04bd98ae4300 f644032801 7444 }
- $sequence_5 = { 55 8bec 0fb701 83ec10 83e811 741a 83e801 }
- $sequence_6 = { 8d4d0c ff7514 8b7d08 8945f8 897314 }
- $sequence_7 = { 8b4dfc 0f95c0 890a c9 c20c00 55 8bec }
- $sequence_8 = { 837d0c04 0f85e3000000 8d4634 50 8d4dc8 e8???????? }
- $sequence_9 = { eb07 8b4584 8930 33db 8d4dd4 e8???????? }
+ $sequence_0 = { 8b7508 ad 50 56 }
+ $sequence_1 = { 8b4510 aa 8b450c ab }
+ $sequence_2 = { 8a241f 88240f 88041f 41 }
+ $sequence_3 = { 6a00 6a00 6a00 ff750c 6a00 6a00 ff7508 }
+ $sequence_4 = { 8b4114 83f8fd 7506 8b4108 8b4014 85c0 7403 }
+ $sequence_5 = { 66b80d0a 66ab b8436f6f6b ab b869653a20 ab }
+ $sequence_6 = { ff15???????? 48 83c420 48 85c0 0f84b4000000 }
+ $sequence_7 = { 814a3500080000 4c 29c6 40 8832 }
+ $sequence_8 = { 8b7d0c 31c9 bb0a000000 31d2 f7f3 52 }
+ $sequence_9 = { 8b4514 8908 290e 8b06 }
+ $sequence_10 = { 66b80d0a 66ab b855736572 ab b82d416765 ab }
+ $sequence_11 = { 73ed 88e8 48 8d1d5a020000 }
+ $sequence_12 = { fd 8b7d0c 83c707 8b4508 83e00f }
condition:
- 7 of them and filesize <519168
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Ranbyus_Auto : FILE
+rule MALPEDIA_Win_Leouncia_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9b877552-6bf5-5d12-bef1-733cc6b8feac"
+ id = "39b73bd1-c371-5610-827d-6193acb69151"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ranbyus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ranbyus_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.leouncia"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.leouncia_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "c376990edfad6c071124a105ec8d7e8afaf3007f10ae4746a7ce39d3890ccde0"
+ logic_hash = "ce0406952808d71dc84c670f24e39c297086db41d40b8ca03d26d62e66180e61"
score = 75
quality = 75
tags = "FILE"
@@ -129420,32 +136473,32 @@ rule MALPEDIA_Win_Ranbyus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7504 83c8ff c3 c7402401000000 }
- $sequence_1 = { 894608 8b44241c 56 68???????? 89460c }
- $sequence_2 = { 83c414 85f6 7414 6a01 6a01 57 }
- $sequence_3 = { 760a 814e2500500000 c6060f 0fb606 5e 5b }
- $sequence_4 = { a1???????? eb09 83780400 7507 8b4034 85c0 }
- $sequence_5 = { e8???????? 59 8b4e05 89410b 8b4605 39780b 7407 }
- $sequence_6 = { 8b4e05 89410b 8b4605 39780b }
- $sequence_7 = { 83c621 8a06 3c46 7240 3c47 }
- $sequence_8 = { 83780400 7507 8b4034 85c0 75f3 c3 }
- $sequence_9 = { c3 837c240800 7467 8b44240c }
+ $sequence_0 = { f3ab 8d442408 50 56 }
+ $sequence_1 = { 52 50 a1???????? 8d8c248c050000 }
+ $sequence_2 = { 83c208 8908 8b4e04 894804 8a0d???????? }
+ $sequence_3 = { ff15???????? 5f b801000000 5e 81c438040000 c3 83c9ff }
+ $sequence_4 = { c3 55 56 57 8d542410 6a10 }
+ $sequence_5 = { 83c424 33d2 33ff 85c0 7e31 }
+ $sequence_6 = { c3 8bc8 83e01f c1f905 8b0c8d60c14000 }
+ $sequence_7 = { ff2485ba504000 834df0ff 8955cc 8955d8 8955e0 8955e4 8955fc }
+ $sequence_8 = { c744241c00000000 c744241400040000 c7450000000000 e8???????? 83c404 8bf0 8d442410 }
+ $sequence_9 = { ff2485ba504000 834df0ff 8955cc 8955d8 8955e0 8955e4 }
condition:
- 7 of them and filesize <638976
+ 7 of them and filesize <114688
}
-rule MALPEDIA_Win_Unidentified_053_Auto : FILE
+rule MALPEDIA_Win_Gold_Dragon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b8635dce-dc5b-565f-a079-d654a222f110"
+ id = "eec5e3d6-5655-50ac-8840-a288ffff9f65"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_053"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_053_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gold_dragon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gold_dragon_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "466de537792d4c8cf5922d9a48018d257023e4a1753f3d834debb6d43be45c35"
+ logic_hash = "eed1b3c473c88d18a03100aac4bac22cf30de04dad45247c9c63eb23fa6434a1"
score = 75
quality = 75
tags = "FILE"
@@ -129459,34 +136512,34 @@ rule MALPEDIA_Win_Unidentified_053_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 753c ff75e4 68???????? e8???????? 85c0 59 }
- $sequence_1 = { c1c603 81ea584dff93 8915???????? e8???????? 42 }
- $sequence_2 = { 8d3c85a8914100 833f00 bb00100000 7520 53 e8???????? }
- $sequence_3 = { ff75f0 50 ff91c4010000 8945f4 85c0 }
- $sequence_4 = { f7d7 c1c30e ffd0 890d???????? 87c7 2bc3 f7da }
- $sequence_5 = { f7db c1c017 e8???????? f7d1 }
- $sequence_6 = { 03f7 46 f7d8 81ebd4b243e9 c1c80c }
- $sequence_7 = { 3b8e50894100 0f8515010000 a1???????? 83f801 0f84df000000 3bc2 }
- $sequence_8 = { 81f669d8509c f7d2 686c6c6f63 e8???????? 4e 03c1 890d???????? }
- $sequence_9 = { 8b048588814100 234508 8b4e14 8d04c1 0fb64801 8b5004 83fa10 }
+ $sequence_0 = { e8???????? 8bc6 83e61f c1f805 59 8b048500954000 8d0cf6 }
+ $sequence_1 = { 85c0 a3???????? 0f848d030000 8b15???????? 68???????? }
+ $sequence_2 = { 0fb6fa 3bc7 7714 8b55fc 8a9200844000 }
+ $sequence_3 = { a3???????? 0f842d040000 8b15???????? 68???????? }
+ $sequence_4 = { a3???????? 0f8422030000 a1???????? 68???????? 50 ffd6 }
+ $sequence_5 = { 8b7d08 8d054c914000 83780800 753b b0ff }
+ $sequence_6 = { 8db60c844000 bf???????? a5 a5 59 }
+ $sequence_7 = { ffd6 85c0 a3???????? 0f84a2050000 }
+ $sequence_8 = { ffd6 85c0 a3???????? 0f84ef010000 68???????? ffd7 }
+ $sequence_9 = { 85c0 a3???????? 0f8424020000 8b15???????? 68???????? 52 }
condition:
- 7 of them and filesize <294912
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Win_Broler_Auto : FILE
+rule MALPEDIA_Win_Purplefox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5abffeef-f83b-5c44-9f6f-38ecebdd4974"
+ id = "864146ba-a135-5d92-a900-c7434a0b6e81"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.broler"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.broler_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.purplefox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.purplefox_auto.yar#L1-L376"
license_url = "N/A"
- logic_hash = "a9e85383ead8a369d8ed21ea68b384350908e471fda84214a900f85e6e6d4412"
+ logic_hash = "2241b5e41c5930d16a914d761ccbb07709436fc80bf5297a0da02f1f8d89a59e"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -129498,32 +136551,62 @@ rule MALPEDIA_Win_Broler_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 68???????? 50 68???????? 56 ff15???????? 898520dffcff }
- $sequence_1 = { 39b820b54100 0f8491000000 ff45e4 83c030 3df0000000 72e7 81ffe8fd0000 }
- $sequence_2 = { e8???????? 83c404 33c0 8845f0 8945f1 8945f5 668945f9 }
- $sequence_3 = { 8d8db0dffcff 51 ba???????? e8???????? }
- $sequence_4 = { e8???????? 83c404 33ff be0f000000 89b588fdffff 89bd84fdffff c68574fdffff00 }
- $sequence_5 = { 33ff 3bcf 7564 c743140f000000 897b10 b8???????? }
- $sequence_6 = { 898ed4030000 8b5004 8996d8030000 8b4808 }
- $sequence_7 = { 899d50fdffff ff15???????? 8b9550fdffff 52 8d45a8 68???????? 50 }
- $sequence_8 = { e8???????? e9???????? 50 8d459c 50 }
- $sequence_9 = { 895910 c741140f000000 8d5508 89a51cdffcff 8819 52 }
+ $sequence_0 = { 8945ec 8d45f0 50 8d4dd8 8d55f8 51 }
+ $sequence_1 = { d2de feca 28c3 80d262 9c }
+ $sequence_2 = { 66f7d9 c1e810 52 66c1d908 0f9fc5 }
+ $sequence_3 = { 8918 e8???????? 4c8d15a7c70000 4885c0 7404 4c8d5010 8bcb }
+ $sequence_4 = { 8d45f8 50 6a00 6a00 c745f800000000 }
+ $sequence_5 = { 488b8d08040000 488d442470 4d8b00 4533c9 ba00000100 4889742428 48899c24f0040000 }
+ $sequence_6 = { ff15???????? 488bc8 ff15???????? 488d1528460000 488bce }
+ $sequence_7 = { 8b04c52cbb4000 5d c3 8bff 55 8bec }
+ $sequence_8 = { ffd6 83c410 8d542424 52 8d442410 e8???????? }
+ $sequence_9 = { 0f1005???????? f20f100d???????? 4889bc24c8000000 33ff }
+ $sequence_10 = { 51 0f9dc3 8b742404 685af85bca 8b7c240c }
+ $sequence_11 = { 56 57 68???????? e8???????? 83c404 6a00 6a00 }
+ $sequence_12 = { cf b94523340a e8???????? 06 }
+ $sequence_13 = { b614 dc1a 7038 1f a5 }
+ $sequence_14 = { 415d 415c 5f c3 4889742478 488bb42490000000 }
+ $sequence_15 = { 8d4df4 51 52 56 6a00 50 }
+ $sequence_16 = { 488b4238 48894108 488b4a50 4885c9 }
+ $sequence_17 = { e8???????? 8dbddcfdffff e8???????? 8dbddcfdffff c745fcffffffff }
+ $sequence_18 = { 6685c9 75f1 8d85f8fdffff 56 33f6 8d5002 }
+ $sequence_19 = { 8944241c 52 8d44241c 50 }
+ $sequence_20 = { 4803d8 41b800040000 48899d00040000 e8???????? e9???????? 488b4c2470 ff15???????? }
+ $sequence_21 = { 448bcf 4889442420 e8???????? 8bc7 488d4dd0 33d2 }
+ $sequence_22 = { 8b703c 66f7da 0fbae603 0fca 20c6 01c6 42 }
+ $sequence_23 = { 4883c308 483bdf 72ed 48833d????????00 741f 488d0d36c60000 e8???????? }
+ $sequence_24 = { 57 68???????? 68???????? bf00500000 ff15???????? 50 ff15???????? }
+ $sequence_25 = { ff15???????? 488d542450 488d0d96b10000 e8???????? }
+ $sequence_26 = { 3bf3 7d1e 8b4de8 ff15???????? 8b4df8 51 }
+ $sequence_27 = { 52 ffd3 85c0 7507 b802000000 eb1a }
+ $sequence_28 = { 9c 368810 c6042413 60 }
+ $sequence_29 = { 668b460c 8b5508 6a01 668945e4 }
+ $sequence_30 = { 4533c0 33d2 4489b424a0000000 4889442420 }
+ $sequence_31 = { a1???????? a3???????? a1???????? c705????????bb454000 8935???????? }
+ $sequence_32 = { e8???????? 83c408 33ff eb23 68???????? }
+ $sequence_33 = { 4885c0 743f 488b0d???????? 488d1551970000 }
+ $sequence_34 = { 8b1d???????? 68???????? 50 ffd3 85c0 750c 8b4f08 }
+ $sequence_35 = { c744246800010000 488bf9 4889742460 89742458 89742450 4889742448 }
+ $sequence_36 = { 488d0de4d20000 483bd9 723e 488d0568d60000 483bd8 7732 488bd3 }
+ $sequence_37 = { 48ffce 75a3 8b4504 03c5 8be8 833800 }
+ $sequence_38 = { 897c2404 e8???????? e8???????? 8d64242c 0f850a000000 660fb6d8 }
+ $sequence_39 = { 56 57 4883ec50 8bc9 488d942480000000 ff15???????? }
condition:
- 7 of them and filesize <275456
+ 7 of them and filesize <1983488
}
-rule MALPEDIA_Win_Bedep_Auto : FILE
+rule MALPEDIA_Win_Comlook_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "38514c33-d67a-59ce-9042-a62977e3ef09"
+ id = "860e6423-7c42-5b7a-b226-a660c40ee352"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bedep"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bedep_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.comlook"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.comlook_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "f62533daae7175b045e5c4c81adb2d2dce588f3fcc3da789cd782a4e3103423f"
+ logic_hash = "4752c20623b9cb3b21f01ebe269fa3b02a3d0ecab0d63ba89a5af7bf48ed8b4a"
score = 75
quality = 75
tags = "FILE"
@@ -129537,32 +136620,32 @@ rule MALPEDIA_Win_Bedep_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4dd4 c70020000000 c7400421020000 8bc6 881e c6460103 }
- $sequence_1 = { 8b4608 e8???????? 85c0 7c19 6a20 8bc7 e8???????? }
- $sequence_2 = { e8???????? 85c0 8945f4 7e3a 837df800 7463 8bcb }
- $sequence_3 = { 33ff 89742418 8974241c 8b542418 56 ff742420 8d4c2430 }
- $sequence_4 = { 7d09 56 e8???????? 59 eb05 8b450c 8930 }
- $sequence_5 = { 397338 89442428 0f85bb000000 6a7c 8d8424a4000000 56 50 }
- $sequence_6 = { 75e2 b001 5e c20400 55 8bec 83e4f8 }
- $sequence_7 = { 56 90 e8???????? 832000 6a04 ff750c 33c9 }
- $sequence_8 = { 8d4568 50 ff7570 90 e8???????? 894570 64a118000000 }
- $sequence_9 = { ff751c 83cb02 ff7520 53 ff7514 50 8d45f4 }
+ $sequence_0 = { c1ff1f 03c1 13d7 2b442434 b900000000 1bd1 33ff }
+ $sequence_1 = { e8???????? 8d45e0 50 c645fc02 e8???????? 83c42c 8bd8 }
+ $sequence_2 = { ff15???????? 83c404 3bf4 e8???????? b843000000 e9???????? c7854cffffff00000000 }
+ $sequence_3 = { e8???????? 8b4e08 80791500 7579 8b01 80781401 7509 }
+ $sequence_4 = { c1ed08 036e04 25ff000000 036c2414 8906 8b0f 0fb6c0 }
+ $sequence_5 = { e9???????? 8b4518 0b451c 7509 33c0 33d2 e9???????? }
+ $sequence_6 = { e8???????? 83c408 85c0 7410 8b4508 8b4df8 894858 }
+ $sequence_7 = { e8???????? 8bf8 83c404 3bfb 0f8eab060000 c7463460210000 895e44 }
+ $sequence_8 = { e8???????? a1???????? 33c4 89442418 53 8b5c2424 8b435c }
+ $sequence_9 = { b8cccccccc 8945f0 8945f4 8945f8 8945fc 8b4508 0590050000 }
condition:
- 7 of them and filesize <557056
+ 7 of them and filesize <4553728
}
-rule MALPEDIA_Win_Mespinoza_Auto : FILE
+rule MALPEDIA_Elf_Persirai_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6af67872-bac6-59d0-8e7f-a6515453822a"
+ id = "a8d888a8-efae-5fcd-8298-ba3399d89281"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mespinoza"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mespinoza_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.persirai"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.persirai_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "b9e1c3335fd9ffa3b60b976c6289b141c236447ff76a5dd17787957756af56c7"
+ logic_hash = "091433f152a0a1932173079b7afa5457b62363ecd6425f8d1d7de8df73a8fbb4"
score = 75
quality = 75
tags = "FILE"
@@ -129576,32 +136659,32 @@ rule MALPEDIA_Win_Mespinoza_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4d9c e8???????? 83eb01 75e7 8b4d0c }
- $sequence_1 = { 897d0c c645fc01 85ff 7446 56 8bcf e8???????? }
- $sequence_2 = { 8b4dc4 8b7dc0 6aff 6a01 }
- $sequence_3 = { 891f 895f04 6a01 895dfc e8???????? 59 894704 }
- $sequence_4 = { 03c1 3bc1 7334 8bde 8bf1 2bf0 }
- $sequence_5 = { 75f9 2bd6 8db5f8feffff 8d5e01 8a06 46 84c0 }
- $sequence_6 = { 83e03f 6bd030 895de4 8b049d00b04700 8945d4 8955e8 8a5c1029 }
- $sequence_7 = { 8b6c240c 56 57 55 8bf9 e8???????? 8b37 }
- $sequence_8 = { 64a300000000 8965f0 8b7508 8b7d0c 8975ec c745fc00000000 0f1f440000 }
- $sequence_9 = { 8bc3 2bc2 894714 8b7508 8bce e8???????? 84c0 }
+ $sequence_0 = { c3 c3 53 83ec08 e8???????? 31d2 8b5c2414 }
+ $sequence_1 = { 8b5c2410 837c241400 740b 83ec0c ff7304 ff13 83c410 }
+ $sequence_2 = { 50 52 e8???????? 58 8d8424d8170000 50 e8???????? }
+ $sequence_3 = { 8d4400e0 50 e8???????? 89c2 a3???????? 83c410 83c8ff }
+ $sequence_4 = { 817c2414ff030000 0f8770030000 8b442414 c1e004 83b888a2050800 0f85df000000 8b0d???????? }
+ $sequence_5 = { c7042408000000 50 a1???????? 6a1a 6a01 50 e8???????? }
+ $sequence_6 = { 83c418 5b c3 81ecac000000 31d2 a1???????? }
+ $sequence_7 = { 85c0 74cb e8???????? 52 52 8b00 }
+ $sequence_8 = { c680b901000000 8b45f0 e8???????? 89f0 8b55f0 e8???????? 8b45f0 }
+ $sequence_9 = { 83c004 89442418 e9???????? bf0a000000 e9???????? bf10000000 e9???????? }
condition:
- 7 of them and filesize <1091584
+ 7 of them and filesize <229376
}
-rule MALPEDIA_Win_Flawedgrace_Auto : FILE
+rule MALPEDIA_Win_Innaput_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "62521b13-13e2-5f89-b92f-7685ad3e5d40"
+ id = "bdbf07bd-d4a4-5362-b354-c606ef8af022"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flawedgrace"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flawedgrace_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.innaput_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.innaput_rat_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "3a2e50b467b7ecb293ee257669feacddf7970c96ed36da3edcb02bab7c5dbcd0"
+ logic_hash = "f6067a2a0e56ef408d96b72de49c1461531d24eb998121258442401a90d43684"
score = 75
quality = 75
tags = "FILE"
@@ -129615,32 +136698,32 @@ rule MALPEDIA_Win_Flawedgrace_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 894110 8b450c 89411c 8a03 884124 8b45f4 c7411800000000 }
- $sequence_1 = { c1e810 0fb6c0 330c85e0bb4500 0fb6c2 c1ea08 330c85e0b34500 334fb8 }
- $sequence_2 = { ff15???????? 8bf8 85ff 0f8493000000 8bce e8???????? 8d5704 }
- $sequence_3 = { 50 8b85c0feffff ff7004 50 e8???????? 8b55e8 }
- $sequence_4 = { c68564dcffffda c68565dcffff02 c68566dcffff48 c68567dcffff65 c68568dcffff61 c68569dcffff70 c6856adcffff52 }
- $sequence_5 = { c6857fcfffff48 c68580cfffff83 c68581cfffffec c68582cfffff20 c68583cfffff4c c68584cfffff8b c68585cfffffc8 }
- $sequence_6 = { 3355f0 33da 8955e8 330c85e0d34500 8bc2 898eb0000000 8bca }
- $sequence_7 = { c6852ee8ffff65 c6852fe8ffff6c c68530e8ffff6f c68531e8ffff63 c68532e8ffff00 c68533e8ffff00 c68534e8ffff50 }
- $sequence_8 = { 8975fc e8???????? 50 83c010 50 51 }
- $sequence_9 = { c68516e5ffff00 c68517e5ffff00 c68518e5ffff00 c68519e5ffff00 c6851ae5ffff00 c6851be5ffff00 c6851ce5ffff00 }
+ $sequence_0 = { e8???????? 59 85c0 7427 ffb720060000 }
+ $sequence_1 = { ffd7 8b4510 898618060000 8b4514 8b00 }
+ $sequence_2 = { 8b06 894710 ff7604 035e08 ff5708 56 ff5708 }
+ $sequence_3 = { 8d7710 eb02 8b36 391e 75fa 6a0c }
+ $sequence_4 = { 8945fc ff15???????? 33db 395f10 }
+ $sequence_5 = { ff15???????? ffb718060000 ff15???????? 85c0 }
+ $sequence_6 = { 8b460c 83f8ff 7404 3bc3 751b }
+ $sequence_7 = { eb02 8b36 391e 75fa 6a0c ff5704 59 }
+ $sequence_8 = { 83f8ff 7404 3bc3 751b }
+ $sequence_9 = { b001 ebd3 55 8bec }
condition:
- 7 of them and filesize <966656
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Shadowhammer_Auto : FILE
+rule MALPEDIA_Win_Azov_Wiper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "194406b6-a98b-5404-b2f3-d5df631c65c0"
+ id = "76e58a84-2854-5930-bc99-d7f7733110e9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shadowhammer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shadowhammer_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.azov_wiper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.azov_wiper_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "34aeb940c0c6ad0698f1f0e3ab023525d38575b33eb7ba408d437819a37427e5"
+ logic_hash = "b6d671c16b8dc6a9d2872e0b93ec5fc03d8fe956d8f9494205bfd799936a0b79"
score = 75
quality = 75
tags = "FILE"
@@ -129654,34 +136737,34 @@ rule MALPEDIA_Win_Shadowhammer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 03d3 03f3 03fb 894dfc 8945f4 }
- $sequence_1 = { c3 e8???????? c21000 8bff 55 8bec 833d????????01 }
- $sequence_2 = { 8dbd7dfdffff ab ab ab ab }
- $sequence_3 = { 58 6a2d 66894584 58 }
- $sequence_4 = { 685ac1cbc2 56 e8???????? 59 59 85c0 }
- $sequence_5 = { c78564ffffff103ee0fc c78568ffffffb0cf4161 c7856cffffffb0fafb19 8dbd70ffffff }
- $sequence_6 = { 8d45e8 50 ff75fc 895de8 8b07 }
- $sequence_7 = { c78544fdffff6a0ad740 c78548fdffff667aadbd 33c0 8dbd4cfdffff ab 889d50fdffff 8dbd51fdffff }
- $sequence_8 = { 8dbdfcfdffff ab 889d00feffff 8dbd01feffff ab ab }
- $sequence_9 = { 8945a8 8d8574ffffff 33ff 8945ac 8d45b8 }
+ $sequence_0 = { 4c8bc8 4885c0 7455 488d442440 }
+ $sequence_1 = { 488d5201 6685c0 75ee 488b05???????? 488bcb 488b10 ff9250010000 }
+ $sequence_2 = { 41ff9288010000 85c0 740f 4881c79a020000 4889bc2410030000 483bbc2418030000 0f8c73ffffff }
+ $sequence_3 = { 48894c2440 4533c0 48898c2470080000 4c8b10 488d842470080000 }
+ $sequence_4 = { 33d2 33c9 48897c2420 4c8b10 41ff92b0000000 8bce }
+ $sequence_5 = { 4c8b00 41ff5058 85c0 0f84c6000000 4c89b42480000000 448d4b04 }
+ $sequence_6 = { 488bcb 4c8b10 41ff9288010000 85c0 740f 4881c79a020000 }
+ $sequence_7 = { 4883ec20 4080e4f0 c645f356 c645f469 c645f572 }
+ $sequence_8 = { 488945f8 4883ec08 48890424 4883ec08 }
+ $sequence_9 = { 0f8493000000 488bd0 488bcb 482bd3 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Gibberish_Auto : FILE
+rule MALPEDIA_Win_Hancitor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "409a50f2-d1ad-54e1-a200-e21294aa9e4e"
+ id = "e94e88e2-da44-5855-8e98-8220d615aa1e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gibberish"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gibberish_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hancitor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hancitor_auto.yar#L1-L234"
license_url = "N/A"
- logic_hash = "57f29d590beea21c748ae9324417e51d5ad871133bb0f66df9972b1b6e5d5d7b"
+ logic_hash = "3fe1f27a710b2ccfc55ec6a2163075344a7f89cf27a8c741d778d1b9ea2b6391"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -129693,34 +136776,48 @@ rule MALPEDIA_Win_Gibberish_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8945a4 e8???????? 8b4dac 8b45a4 6a41 }
- $sequence_1 = { 8b75e8 8b7dec e9???????? f30f7e4de8 0f1045d8 eb03 }
- $sequence_2 = { c1e908 894c2410 8b4c2418 3314c5e1a14700 0fb6c1 c1e908 }
- $sequence_3 = { e8???????? 84c0 0f849a000000 33c0 668985dcf9ffff 8d85e8fbffff 68???????? }
- $sequence_4 = { 8944243c 8b4124 89442440 8b4128 8d4c241c c744241c209d4500 c7442420d49d4500 }
- $sequence_5 = { 894db0 8d4dc0 50 c745d000000000 c745d40f000000 c645c000 e8???????? }
- $sequence_6 = { 81fae3000000 7cc4 81fa6f020000 7d3a 57 8d3c9518bd4700 }
- $sequence_7 = { 68???????? 53 53 ff15???????? 8b55ac 8b4da8 890491 }
- $sequence_8 = { ff15???????? 66898435fdfbffff 83c607 53 56 8d85f8fbffff 50 }
- $sequence_9 = { 8b45d4 8d4dd8 8b55d0 83ff10 8b7dd8 0f43cf 2bc2 }
+ $sequence_0 = { 6a00 6824040000 6a00 6a00 6a00 }
+ $sequence_1 = { 6800010000 6a40 68???????? e8???????? }
+ $sequence_2 = { 8bec a1???????? 85c0 740c ff7508 6a00 50 }
+ $sequence_3 = { 8bec 8b4d08 6a00 6a01 51 }
+ $sequence_4 = { 68???????? ff7508 c605????????00 ff15???????? }
+ $sequence_5 = { a3???????? 85c0 7502 5d c3 ff7508 6a00 }
+ $sequence_6 = { 8b4df4 51 8b55f8 52 8b4510 }
+ $sequence_7 = { 8b4d08 0fbe11 83fa7d 750e }
+ $sequence_8 = { 8bd8 83fbff 7509 6a00 57 }
+ $sequence_9 = { 6a00 6a01 8b5508 52 ff55f4 33c0 8be5 }
+ $sequence_10 = { 8b4df4 8b5104 83ea08 d1ea 8955d4 }
+ $sequence_11 = { c60600 ff15???????? 8b3d???????? 85c0 740a }
+ $sequence_12 = { 8b4dec 8b55f4 035128 8b4518 8910 eb02 }
+ $sequence_13 = { 8945f8 8b4df8 894df4 6a00 6a01 }
+ $sequence_14 = { 7411 8d85f4fdffff 50 8b4d08 51 }
+ $sequence_15 = { 8b4d08 53 56 57 8b413c }
+ $sequence_16 = { 8945cc 8365e400 c745bc0a000000 eb07 8b45bc }
+ $sequence_17 = { c3 4b fd 008d4556f400 08640f08 ed fec3 }
+ $sequence_18 = { a1???????? 8945b4 a1???????? 83c044 a3???????? 8b45b4 83e803 }
+ $sequence_19 = { b9382baa99 c7458ce4f25701 ff15???????? 894da0 a1???????? }
+ $sequence_20 = { 6a00 6a00 ff15???????? c745a064000000 }
+ $sequence_21 = { c645f300 c645fc65 c645fd00 c745f8dc030000 8365b800 }
+ $sequence_22 = { 8945dc e9???????? b9382baa99 c745f464000000 }
+ $sequence_23 = { 0f8482000000 c645f301 0fb645f3 85c0 7476 a1???????? 83c044 }
condition:
- 7 of them and filesize <1068032
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Goldenspy_Auto : FILE
+rule MALPEDIA_Win_Etumbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2db85832-8503-5134-9cf2-a79f16f8ed47"
+ id = "73e6da41-e3d5-504c-8c80-6f8ec05bab3e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.goldenspy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.goldenspy_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.etumbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.etumbot_auto.yar#L1-L332"
license_url = "N/A"
- logic_hash = "45ec0195c1eec86aab8f23405836b0cab0b81ad642d99b8dc40b2feb153827cd"
+ logic_hash = "564ae417565d87b67b974a9ba2ad8948ae9936f9dac5ee557fc27d8a92da27f9"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -129732,32 +136829,59 @@ rule MALPEDIA_Win_Goldenspy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f87e4000000 e9???????? 83c754 837f1000 740f 68???????? 8bcf }
- $sequence_1 = { 83c0fc 83f81f 0f8777060000 52 51 e8???????? 83c408 }
- $sequence_2 = { 8b7608 807e0d00 74a8 8b4de8 8b5de4 }
- $sequence_3 = { e8???????? 8b551c 83fa10 0f82b8fcffff 8b4d08 42 8bc1 }
- $sequence_4 = { e8???????? 51 68???????? 8bcb e8???????? 8b83c8000000 }
- $sequence_5 = { 8d4dd8 6a1a 68???????? c745e800000000 c745ec0f000000 c645d800 e8???????? }
- $sequence_6 = { 57 68???????? e8???????? 8d47ff 83c408 83f804 }
- $sequence_7 = { 75f2 8b5308 8bf2 8b7b14 0f1f00 8a02 42 }
- $sequence_8 = { ff75e4 ff461c 8d4628 50 e8???????? 897e30 c7463400000000 }
- $sequence_9 = { 8b85f8feffff 8b4004 c78405f8feffffb4e24600 8b85f8feffff 8b4804 8d41b0 89840df4feffff }
+ $sequence_0 = { 8811 8a00 02c2 0fb6c0 8a8405fcfeffff 320437 8806 }
+ $sequence_1 = { 8bec 53 56 57 8b3d???????? ffd7 }
+ $sequence_2 = { 7407 8bf9 c1ef18 33c7 f7d1 23c1 }
+ $sequence_3 = { c745ac5c5c4d69 c745b063726f73 c745b46f66745c c745b85c57696e }
+ $sequence_4 = { c1e004 03c1 8bc8 81e1000000f0 7407 8bf9 }
+ $sequence_5 = { 8d45f4 6820a10700 50 68???????? 68???????? }
+ $sequence_6 = { c745c05c5c4375 c745c47272656e c745c874566572 c745cc73696f6e c745d05c5c496e }
+ $sequence_7 = { 42 4e 75df 5f }
+ $sequence_8 = { ffd7 8b7508 8bd8 69f660ea0000 }
+ $sequence_9 = { c745b46f66745c c745b85c57696e c745bc646f7773 c745c05c5c4375 }
+ $sequence_10 = { 57 0fbe38 33f6 33db }
+ $sequence_11 = { c745d47465726e c745d865742053 c745dc65747469 c745e06e677300 }
+ $sequence_12 = { f7d1 23c1 42 4e }
+ $sequence_13 = { ffd7 2bc3 3bc6 72ed }
+ $sequence_14 = { c645bf69 c645c062 c645c16c c645c265 }
+ $sequence_15 = { 80e10f c0e102 c0eb06 02cb }
+ $sequence_16 = { c645c16c c645c265 c645c33b c645c420 }
+ $sequence_17 = { 56 8bf1 8b08 83f903 }
+ $sequence_18 = { c645c54d c645c653 c645c749 c645c845 c645c920 }
+ $sequence_19 = { 84c9 74b6 5f 5e 8bc2 }
+ $sequence_20 = { 33c0 56 89442418 57 89442420 }
+ $sequence_21 = { 0345f0 8b4d08 034dec 8a11 8810 8b45f0 83c001 }
+ $sequence_22 = { 750d 83c01c 8bce 50 e8???????? }
+ $sequence_23 = { 8d4a01 83c404 8bd1 c1e902 f3ab 8bca 83e103 }
+ $sequence_24 = { 83c204 3b5514 7608 83c8ff }
+ $sequence_25 = { 83c104 3b4d14 7608 83c8ff }
+ $sequence_26 = { 53 57 e8???????? 8d86b0000000 50 }
+ $sequence_27 = { 034df0 8b5508 0355ec 8a02 }
+ $sequence_28 = { 52 e8???????? 83c404 e9???????? 6a05 }
+ $sequence_29 = { c645d057 c645d169 c645d26e c645d364 }
+ $sequence_30 = { 6a00 68???????? 6a00 6a00 6a00 51 68???????? }
+ $sequence_31 = { 83fa01 7538 8b4514 8b19 0fb60438 c1e802 }
+ $sequence_32 = { 46 eb0f 0fb6d2 f68201ce400004 7403 40 ff01 }
+ $sequence_33 = { 8b4d08 83c101 894d08 8b550c 83ea03 }
+ $sequence_34 = { 50 57 8bce e8???????? 8d45f0 8d7e70 }
+ $sequence_35 = { c68543fffffff7 c68544ffffff52 c68545ffffff91 c68546ffffff1c c68547fffffff7 c68548ffffff64 c68549ffffffa3 }
+ $sequence_36 = { c685ddfdffffa4 c685defdffffb3 c685dffdffff02 c685e0fdffff30 c685e1fdffffd6 c685e2fdfffffb }
condition:
- 7 of them and filesize <1081344
+ 7 of them and filesize <450560
}
-rule MALPEDIA_Win_Miniasp_Auto : FILE
+rule MALPEDIA_Win_Powerloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a296e0dd-d471-5c91-a6b1-780906aaa535"
+ id = "7f4f5f46-fc37-546a-a6e8-709a0ba38743"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miniasp"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.miniasp_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.powerloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.powerloader_auto.yar#L1-L108"
license_url = "N/A"
- logic_hash = "9a4758ded83cb0970a2c1c85a01ff8f2f0263c333e1e2d45a290cc1db4a95dd4"
+ logic_hash = "793f3dbd327274c0d84943d43e404acbb8cb72be0435ee1a3f9e0ada37088a0f"
score = 75
quality = 75
tags = "FILE"
@@ -129771,32 +136895,32 @@ rule MALPEDIA_Win_Miniasp_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b45c0 898550ffffff 8b8550ffffff 40 89854cffffff 8b8550ffffff }
- $sequence_1 = { ff15???????? 85c0 751b c785c0fbffff10d84000 68???????? 8d85c0fbffff 50 }
- $sequence_2 = { 8b4508 0345f0 0fbe4002 83f841 7c15 8b4508 }
- $sequence_3 = { 747c 8b45f4 8945d8 8b45d8 40 8945d4 8b45d8 }
- $sequence_4 = { 83a564ffffff00 eb0b 1bc0 83d8ff 898564ffffff }
- $sequence_5 = { 6a00 ff75f8 e8???????? 83c40c 6804010000 6a00 }
- $sequence_6 = { 68???????? 8d85c0fbffff 50 e8???????? b001 5f 5e }
- $sequence_7 = { ff15???????? 85c0 7534 ff15???????? 3d882f0000 7427 ff75f8 }
- $sequence_8 = { 0f8516010000 8b45ec 8b00 8b4dec ff5020 8945f4 837df400 }
- $sequence_9 = { 8985ecfbffff 8b85ecfbffff 3b45fc 7728 6a01 68???????? 8b4508 }
+ $sequence_0 = { e8???????? eb22 33c9 66666666660f1f840000000000 0fb6840c30010000 }
+ $sequence_1 = { 8bf2 32db e8???????? 3bc7 7349 }
+ $sequence_2 = { e8???????? 0fb6d8 84c0 7514 }
+ $sequence_3 = { e8???????? 0fb6d8 84c0 7514 ff15???????? }
+ $sequence_4 = { 33d2 c605????????00 e8???????? 0fb6c3 }
+ $sequence_5 = { 32db e8???????? 3bc7 7349 }
+ $sequence_6 = { e8???????? eb22 33c9 66666666660f1f840000000000 }
+ $sequence_7 = { e8???????? 8b7c2430 85ed 740d }
+ $sequence_8 = { ff15???????? 83f81f 7323 ff15???????? }
+ $sequence_9 = { ff15???????? 83f803 7405 83f802 7530 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <155648
}
-rule MALPEDIA_Win_Newbounce_Auto : FILE
+rule MALPEDIA_Win_Findpos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "70b5f47a-ee55-5897-8fcd-06a813c41881"
+ id = "06e6ab2e-1688-507b-a649-5420f969f64c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.newbounce"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.newbounce_auto.yar#L1-L151"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.findpos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.findpos_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "53d4154f041c8f5d8c7be0de086b650af8bff8de758570421d79234a0be341f3"
+ logic_hash = "89f2603a026fe078dffd243a5f02eea72ee3cfa2b2eca87062e133a5a2b51b38"
score = 75
quality = 75
tags = "FILE"
@@ -129810,37 +136934,32 @@ rule MALPEDIA_Win_Newbounce_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83e00f 7e05 2bf0 83c610 }
- $sequence_1 = { ff15???????? 85c0 0f844b010000 ba28000000 }
- $sequence_2 = { ff15???????? 85c0 0f8437020000 8b4c2428 }
- $sequence_3 = { ff15???????? 85c0 0f8436020000 4889bc2428010000 c784242001000022000000 c784241801000073252000 c78424100100006b2d2000 }
- $sequence_4 = { 75f5 49ffc8 75eb 488d8104020000 }
- $sequence_5 = { e8???????? cc b201 488bcf e8???????? 4c8d1d8f920100 488d5547 }
- $sequence_6 = { 75f2 ebe3 488d154ac20100 498bcc 4d8bc7 }
- $sequence_7 = { 75f5 49ffc9 75e8 488d8e54030000 }
- $sequence_8 = { 81e3c0000000 0bf3 c1ee06 0b14b5b0876300 }
- $sequence_9 = { 81e300000600 c1ea14 8b1495b0896300 81e6000f0000 }
- $sequence_10 = { 81e300e00100 0bf3 c1ee0d 0b0cb5b0886300 }
- $sequence_11 = { 81e2ff000000 8b0c8d48436300 8b1c9d48476300 33cb 8b1c85484b6300 2bcb }
- $sequence_12 = { 81e2ff000000 c1e808 c1e208 53 }
- $sequence_13 = { 81e3001e0000 8bef 81e50000e001 0bf5 c1ee15 8b34b5b08d6300 }
- $sequence_14 = { 81e3001e0000 8bd5 81e280010000 0bda 8b14b5b08d6300 }
+ $sequence_0 = { 48 0f844b050000 33c0 8d8c24f0010000 50 51 8d8c243c020000 }
+ $sequence_1 = { 68???????? e8???????? a1???????? 59 59 83c010 a3???????? }
+ $sequence_2 = { 7671 8365d400 8d55d4 8bcf }
+ $sequence_3 = { 8bcf e8???????? 8325????????00 833d????????10 68???????? 0f4335???????? }
+ $sequence_4 = { 8b0cb8 03cb e8???????? 85c0 7414 8b4df0 }
+ $sequence_5 = { eb29 8a01 3c33 7505 }
+ $sequence_6 = { 8945f8 8d45f8 50 c745ec00200000 ff15???????? 85c0 745f }
+ $sequence_7 = { 3b08 7518 53 51 51 6a01 8d45e4 }
+ $sequence_8 = { 50 0fb6c1 50 8d85e8e7ffff 50 }
+ $sequence_9 = { 33f6 46 3bc6 0f8577040000 6a11 ffd7 663bc6 }
condition:
- 7 of them and filesize <8637440
+ 7 of them and filesize <286720
}
-rule MALPEDIA_Win_Cryptoshield_Auto : FILE
+rule MALPEDIA_Win_Greenshaitan_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "96d07897-e994-52cb-aaa7-059e98a50194"
+ id = "d06953fb-38e3-55db-9793-3faef3649e6a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptoshield"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptoshield_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.greenshaitan"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.greenshaitan_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "306896178ef65ef3c9170a20c235107c29dca1bfe925c06dc43c71750e345a6d"
+ logic_hash = "67bf6d74e4d0fa44058834ba5470ffb949ca80488520bfdf122c691ce2d70d18"
score = 75
quality = 75
tags = "FILE"
@@ -129854,32 +136973,32 @@ rule MALPEDIA_Win_Cryptoshield_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b18 8b45fc 85c0 740e }
- $sequence_1 = { 50 ffd7 83c40c 8d442418 50 8d84242c020000 68???????? }
- $sequence_2 = { 50 8d442428 50 ff15???????? 8d842430040000 }
- $sequence_3 = { 85c0 7461 ff7508 6a40 ff15???????? }
- $sequence_4 = { 750b 83c202 66833a00 75ce eb08 }
- $sequence_5 = { 6a00 6a23 50 6a00 ff15???????? 8d85f4fdffff 50 }
- $sequence_6 = { b90a000000 83f801 0f44f1 8b4dfc }
- $sequence_7 = { be09000000 8bc6 5e 8b4dfc 33cd e8???????? 8be5 }
- $sequence_8 = { 56 6814010000 33f6 8d85e0feffff 56 }
- $sequence_9 = { 56 ff15???????? 85ff 0f45df 5f 5e 8bc3 }
+ $sequence_0 = { 8b460c 8d542434 52 50 }
+ $sequence_1 = { 6a00 51 50 b940000000 e8???????? 8bf0 eb02 }
+ $sequence_2 = { 81ce00ffffff 46 8a1c0e 881c0f 88040e 8d4201 99 }
+ $sequence_3 = { 8b442444 8b4c2440 8b7c243c 50 51 8d542418 52 }
+ $sequence_4 = { e8???????? 85ed 740c 8b4500 eb09 8b4500 8bc8 }
+ $sequence_5 = { 51 ff15???????? 8b8c240c200000 5e 5d }
+ $sequence_6 = { 0fb69b685b6e00 8819 0fb6d2 8bda c1eb04 c1e004 0bd8 }
+ $sequence_7 = { 8bc8 ebe1 33c0 397814 770e 85ed 7405 }
+ $sequence_8 = { 33f6 8bc5 99 6a00 52 c644244400 50 }
+ $sequence_9 = { 720d 8b542434 52 e8???????? 83c404 c784248c000000ffffffff 897c2448 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Pony_Auto : FILE
+rule MALPEDIA_Win_Radamant_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d90fd047-9438-55a9-9e35-1d6c2ea6d18d"
+ id = "1ede87f9-320c-576f-9524-930f09ad6207"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pony"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pony_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.radamant"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.radamant_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "8fcd4026be1a9e152c2bd589ec65b90e934cc06d61e86dd6cd06c58ac6d41a1e"
+ logic_hash = "add6ca5b01c9d6d8dad27d0b268d58bbdb18019e152c79d40b24c8426bcce310"
score = 75
quality = 75
tags = "FILE"
@@ -129893,32 +137012,32 @@ rule MALPEDIA_Win_Pony_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c20400 55 89e5 83ec18 53 }
- $sequence_1 = { c745f400000000 8d45f8 50 ff7508 6a00 ff15???????? }
- $sequence_2 = { bfffffffff 33f9 0bf8 33fb 8d941792cc0c8f 03560c }
- $sequence_3 = { ff75e8 ff7508 e8???????? 23d8 ff75ec e8???????? }
- $sequence_4 = { f7d0 50 ff7508 e8???????? c9 c20400 }
- $sequence_5 = { ff7514 e8???????? eb0d 68???????? }
- $sequence_6 = { c9 c20400 55 8bec 83c4fc ff7514 ff7510 }
- $sequence_7 = { ff75c8 e8???????? ff75c4 e8???????? ff75bc }
- $sequence_8 = { b9ffffffff f2ae 3807 75c5 6a1a ff7508 }
- $sequence_9 = { e8???????? ff7510 6a18 ff7508 e8???????? ff7510 }
+ $sequence_0 = { 8802 8b5510 42 8b45f8 }
+ $sequence_1 = { 890424 e8???????? 8b85c8f6ffff 890424 e8???????? 8b85d4f6ffff 890424 }
+ $sequence_2 = { 8d45f0 ff00 eb9b c9 }
+ $sequence_3 = { 01d0 8d148500000000 01d0 29c1 89c8 83c061 8945b0 }
+ $sequence_4 = { 331485b0164100 89d0 8945e8 8b55fc 83c204 8b45f4 c1e818 }
+ $sequence_5 = { 8d148500000000 01d0 29c1 89c8 83c061 8945b0 }
+ $sequence_6 = { c1e818 0fb6c0 0fb680b0094100 31d0 8901 8b4df4 83c124 }
+ $sequence_7 = { 8b8520feffff 890424 e8???????? 83ec0c 83f8ff 752a 8b45c4 }
+ $sequence_8 = { e8???????? 8b45f4 890424 e8???????? 83c424 5b 5d }
+ $sequence_9 = { 8d45e8 c1000a 8b55f4 8d45e8 0110 8b45f0 f7d0 }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Maoloa_Auto : FILE
+rule MALPEDIA_Win_Dnespy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c9cb938f-8aed-56a4-9406-4a70e3564e5d"
+ id = "70dfc3a2-0802-5571-8c6e-dca5ba3f52dd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maoloa"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maoloa_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dnespy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dnespy_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "aa3156b629c721039014b4e703faa79f34b5d8a33e4caf3d82f64b9729ae8335"
+ logic_hash = "5f9d7d06b9dad4ee82945ca7222951c2d8150747511ca4dc6b623794062c6006"
score = 75
quality = 75
tags = "FILE"
@@ -129932,32 +137051,32 @@ rule MALPEDIA_Win_Maoloa_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b55fc 8bcb 85c0 7817 8d45f0 50 e8???????? }
- $sequence_1 = { 50 ffb5f0e4ffff 8b35???????? ffd6 8b85c0e4ffff c1e015 03858ce5ffff }
- $sequence_2 = { 8b4df8 33cd e8???????? 8be5 5d c3 befcffffff }
- $sequence_3 = { 83c404 85f6 0f8590000000 6a01 8bd7 8bcf e8???????? }
- $sequence_4 = { 85c0 8d8d00e0ffff 0f45ce 8bf1 89b5f8dfffff 8d85f8efffff 50 }
- $sequence_5 = { b910000000 0f43c1 8d4c2418 2bf8 }
- $sequence_6 = { 8d97a9cfde4b 33c1 894db4 0345d0 03d0 8b7db4 c1c20b }
- $sequence_7 = { 8bd3 c707ffffffff 8bcf e8???????? 83c404 8bf0 8b85e0f9ffff }
- $sequence_8 = { 0f1f00 0fb601 8d4901 30440eff 0fb641ff 30440aff 83ef01 }
- $sequence_9 = { 5e 5b 8be5 5d c3 8d45f0 8bd1 }
+ $sequence_0 = { 83ec18 8d4508 8bcc 50 e8???????? ba01000000 8d4dc8 }
+ $sequence_1 = { f30f7e4594 8b459c 660fd645a4 8945ac 7209 8b0e 8bc1 }
+ $sequence_2 = { 8bf1 8954240c 57 8b7d08 89442414 837e4c00 7471 }
+ $sequence_3 = { 74e7 83f80d 74e2 40 83f87e 0f878b010000 }
+ $sequence_4 = { 6a50 668945e8 ff15???????? 668945ea 8d45e8 6a10 }
+ $sequence_5 = { 0f84f0000000 8bc8 e8???????? 8bd0 c745e000000000 8bca c745e40f000000 }
+ $sequence_6 = { 6a00 6a00 8d85e0cfffff 50 6a00 ff15???????? ffb5a0cfffff }
+ $sequence_7 = { 8a18 3a19 750a 40 41 3bc2 75f0 }
+ $sequence_8 = { 744b 8d45f4 c745f000000000 50 8d45f8 c745f800000000 50 }
+ $sequence_9 = { c685ebfeffff00 c685ecfeffff0f c685edfeffff0a c685eefeffff03 8a85dcfeffff c685effeffff00 0f1f440000 }
condition:
- 7 of them and filesize <586752
+ 7 of them and filesize <794624
}
-rule MALPEDIA_Win_Mofksys_Auto : FILE
+rule MALPEDIA_Win_Marap_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d4eb461a-0f9d-55f8-ba8b-2ce33ab04b0d"
+ id = "2cc3d8fa-aa39-5bef-af3b-a091606785c2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mofksys"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mofksys_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.marap"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.marap_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "79cea3cada5c4d8bb821159689e5cf75c88595dc32d8f5768a4b2ed694d76584"
+ logic_hash = "981ff96ccf9321bc9cf0b93466d635ede7fbc6c0341e04e670ea58028783ac37"
score = 75
quality = 75
tags = "FILE"
@@ -129971,32 +137090,32 @@ rule MALPEDIA_Win_Mofksys_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? 8bd0 8d4de8 ffd6 8d8d60ffffff }
- $sequence_1 = { 894dd4 c745fc07000000 8b55d8 52 e8???????? ff15???????? 8b45d4 }
- $sequence_2 = { 83c40c c745fca1000000 ba???????? 8d4dc0 ff15???????? 8d4dc0 51 }
- $sequence_3 = { f7de 3bf0 7209 ff15???????? 8b4dc0 8b4118 0fafc6 }
- $sequence_4 = { ff15???????? 83c410 c745fc65000000 ba???????? 8d4dcc ff15???????? a1???????? }
- $sequence_5 = { ff15???????? 8bd0 8d8d7cfcffff ffd6 50 ffd7 }
- $sequence_6 = { a1???????? 8b4de4 50 51 ffd7 8bd0 8d4da8 }
- $sequence_7 = { 3bc3 7d12 68e0000000 68???????? 56 50 }
- $sequence_8 = { 83c201 0f80b2080000 52 8b45d0 50 68???????? }
- $sequence_9 = { e8???????? 8d4ddc ff15???????? c745fc0f000000 68???????? 6a00 ff15???????? }
+ $sequence_0 = { e9???????? 8386e41d000002 e9???????? 8386e41d000003 }
+ $sequence_1 = { 7409 8386e41d000008 eb2f 84c0 7908 018ee41d0000 }
+ $sequence_2 = { ff15???????? 8bf0 89b59cfbffff 83feff 7472 }
+ $sequence_3 = { ff15???????? 85c0 7425 8b480c 8b11 8b02 }
+ $sequence_4 = { 81fb00040000 737e 8bc7 8bd7 668b08 }
+ $sequence_5 = { 0fbe84c1f8cb0010 6a07 c1f804 59 }
+ $sequence_6 = { 83c40c 8d7bfe 668b4702 83c702 6685c0 75f4 }
+ $sequence_7 = { 8d1c8580320110 8b03 83e71f c1e706 8a4c3824 }
+ $sequence_8 = { 8d4310 8d8954f40010 5a 668b31 }
+ $sequence_9 = { 80f901 0f8487000000 6683fa06 7519 84c0 }
condition:
- 7 of them and filesize <401408
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Backconfig_Auto : FILE
+rule MALPEDIA_Win_Auriga_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "18fd149c-ad9b-5433-8651-ac1dcd92de05"
+ id = "3e414b5e-c2de-5c81-b4bc-c099cfe4cd7e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.backconfig"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.backconfig_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.auriga"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.auriga_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "dc29e43fa81d60d5f53e6f4d5e158937c417e8f12650929b20d71338a8cb5ead"
+ logic_hash = "cddd7158b581ccab9be1a01dbee785ac04d84e6e50041126742a64808d1b3062"
score = 75
quality = 75
tags = "FILE"
@@ -130010,32 +137129,32 @@ rule MALPEDIA_Win_Backconfig_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { a1???????? 8b0d???????? 8b15???????? 8985f0feffff a1???????? 6a51 8985fcfeffff }
- $sequence_1 = { e8???????? 8b4de4 83c40c 6bc930 8975e0 8db1682a4100 }
- $sequence_2 = { 8a15???????? 8d8569ffffff 6a00 50 898d64ffffff 889568ffffff }
- $sequence_3 = { c1f805 8d1485c0504100 8b0a 83e61f c1e606 03ce }
- $sequence_4 = { 8bc3 c1f805 8d3c85c0504100 8bf3 83e61f c1e606 8b07 }
- $sequence_5 = { 8b0d???????? 8b15???????? 8985f0feffff a1???????? 6a51 8985fcfeffff 898df4feffff }
- $sequence_6 = { 8d8d2cfdffff 68???????? 51 e8???????? 83c414 68401f0000 }
- $sequence_7 = { 6a00 50 898d64ffffff 889568ffffff e8???????? }
- $sequence_8 = { 8bf1 83e61f 8d3c85c0504100 8b07 c1e606 f644300401 7436 }
- $sequence_9 = { 8bec 8b4508 56 8d34c550224100 833e00 7513 }
+ $sequence_0 = { 90 5f bb???????? 81eb???????? 2bfb 8bf7 e8???????? }
+ $sequence_1 = { 755b 817e0c03001200 7552 57 }
+ $sequence_2 = { e8???????? c9 c20c00 ffb508fcffff 8b8504fcffff 8d8405fcfbffff }
+ $sequence_3 = { 4a 3bda 745e 7345 2bd3 }
+ $sequence_4 = { 7408 8b0d???????? 8908 56 8b7508 837e0400 7422 }
+ $sequence_5 = { 53 53 6a01 6a01 56 ff15???????? 8945dc }
+ $sequence_6 = { 84c0 7511 ff7510 ff15???????? }
+ $sequence_7 = { ff45fc 8b4dec ff4df8 2bcb 295df4 ff45f8 }
+ $sequence_8 = { ffd3 8b45fc 85c0 7539 ff750c 8d45f4 }
+ $sequence_9 = { 8b85e8fbffff 85c0 7566 ffb5ecfbffff 8d85f0fbffff }
condition:
- 7 of them and filesize <217088
+ 7 of them and filesize <75776
}
-rule MALPEDIA_Win_Turian_Auto : FILE
+rule MALPEDIA_Win_Formbook_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ddf0a4a2-a5a9-518b-8b9f-2682f3c9390d"
+ id = "5884ccaf-7c22-509b-b936-d78ce47dc38a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.turian"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.turian_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.formbook_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "9c66c121bddd393e74452e6591ffaf152302a762e1679695f5fb6277ed317972"
+ logic_hash = "1856083163db4d487acf8602c72ba34a2aeebb6a0e8b028efa10c5ca24fd0c49"
score = 75
quality = 75
tags = "FILE"
@@ -130049,32 +137168,32 @@ rule MALPEDIA_Win_Turian_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ff15???????? 89450c 8bf8 33c0 }
- $sequence_1 = { e8???????? 83c404 85c0 740d 8d4c2410 51 }
- $sequence_2 = { ffd7 8b3d???????? 53 ffd7 56 ffd7 83c408 }
- $sequence_3 = { 81ec88000000 53 55 56 57 b921000000 33c0 }
- $sequence_4 = { 85c0 750a 5f 5e 5d 81c49c000000 c3 }
- $sequence_5 = { 729b 53 ff15???????? 83c404 a1???????? 85c0 750f }
- $sequence_6 = { 72ba 68???????? ff15???????? 5f 5e 5d 83c8ff }
- $sequence_7 = { 66a3???????? 5b c3 6a3f 50 }
- $sequence_8 = { 7403 c60000 68???????? 56 ffd7 85c0 }
- $sequence_9 = { ffd5 85c0 750e 8d4f46 8d5642 }
+ $sequence_0 = { 5b 5f 5e 8be5 5d c3 8d0476 }
+ $sequence_1 = { 6a0d 8d8500fcffff 50 56 e8???????? 8d8d00fcffff 51 }
+ $sequence_2 = { 56 e8???????? 8d4df4 51 56 e8???????? 8d55e4 }
+ $sequence_3 = { c3 3c04 752b 8b7518 8b0e 8b5510 8b7d14 }
+ $sequence_4 = { 56 e8???????? 83c418 395df8 0f85a0000000 8b7d18 395f10 }
+ $sequence_5 = { c745fc01000000 e8???????? 6a14 8d4dec 51 50 }
+ $sequence_6 = { e8???????? 83c428 8906 85c0 75a8 5f 33c0 }
+ $sequence_7 = { 56 e8???????? 6a03 ba5c000000 57 56 66891446 }
+ $sequence_8 = { 3b75d0 72c0 8d55f8 52 e8???????? }
+ $sequence_9 = { 8d8df6f7ffff 51 c745fc00000000 668985f4f7ffff e8???????? 8b7508 }
condition:
- 7 of them and filesize <645120
+ 7 of them and filesize <371712
}
-rule MALPEDIA_Win_Jackpos_Auto : FILE
+rule MALPEDIA_Win_Megacortex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "095b3872-c166-52ad-a52d-1faeb1056a2e"
+ id = "7fddab37-921e-5d3c-ad85-73c5c61f21f7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jackpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jackpos_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.megacortex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.megacortex_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "45db7695f021a95c6d3c662e5ca72119b052256c8a3ceeaf6c22b39c2e1870c0"
+ logic_hash = "c51529de49cb40cceae5744ecd99824ed147bc3c171c405f7c4b90f895a230e9"
score = 75
quality = 75
tags = "FILE"
@@ -130088,32 +137207,32 @@ rule MALPEDIA_Win_Jackpos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b5604 eb03 8d5604 2bc7 03c0 50 }
- $sequence_1 = { d1f8 03d0 eb0f 85c0 }
- $sequence_2 = { 75ed 837df408 8b4dfc 7202 }
- $sequence_3 = { 8b4508 e8???????? 8b7d08 8b550c 8b4718 3b7d10 747e }
- $sequence_4 = { 52 8bf0 53 897588 e8???????? }
- $sequence_5 = { 7303 8d45d8 8d4dac 51 50 e8???????? 8b55b4 }
- $sequence_6 = { 85ff 7f87 5f 8bc6 5e 5b }
- $sequence_7 = { 8b4604 33c9 66890c03 5f 8bc6 }
- $sequence_8 = { 765a 8b4a14 57 3bc1 734e 2bc8 8bf9 }
- $sequence_9 = { 037214 ebc4 5f 5e 5d }
+ $sequence_0 = { 50 e8???????? 8b7d0c 8bf0 83c40c 85f6 0f8517010000 }
+ $sequence_1 = { 895d84 7202 8b06 6a00 6800000003 6a03 6a00 }
+ $sequence_2 = { 50 8d85c4fdffff 50 e8???????? 8b95e0fdffff 83c408 c645fc01 }
+ $sequence_3 = { 8d4101 2bf0 89450c 8975ec ff7508 83fe03 0f823a020000 }
+ $sequence_4 = { e8???????? 8b4508 8d4d08 83c404 c645f801 8945fc c7450800000000 }
+ $sequence_5 = { 83f81f 0f87b70e0000 52 51 e8???????? 83c408 33c0 }
+ $sequence_6 = { f7d8 1bc0 23c1 50 8b45ec 51 8bf4 }
+ $sequence_7 = { 1bf6 23f1 8bce 2bca 85f6 be01000000 0f44ce }
+ $sequence_8 = { e8???????? 83c40c 8d8d2cffffff e8???????? 8d8d44ffffff c645fc2e e8???????? }
+ $sequence_9 = { 6a00 6a00 68000000c0 8d45cc c645fc05 50 8d8d28feffff }
condition:
- 7 of them and filesize <319488
+ 7 of them and filesize <1556480
}
-rule MALPEDIA_Win_Diavol_Auto : FILE
+rule MALPEDIA_Win_Classfon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fdab7e4d-8bbf-526f-9dd1-9c3eccb8a369"
+ id = "68a5b428-fba0-5238-83c9-3255bfbb3ff5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.diavol"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.diavol_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.classfon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.classfon_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "8bc41d08eecdbb842d56f4530baf282b624ea1b70952493cedafeb9a5a3b5234"
+ logic_hash = "752d9b4933679b22e7a2ada3974321921c7722355427af1c70ee3b8ff2e5df5f"
score = 75
quality = 75
tags = "FILE"
@@ -130127,32 +137246,32 @@ rule MALPEDIA_Win_Diavol_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8bf0 83feff 0f8474010000 }
- $sequence_1 = { 8d8df8fdffff 51 b9???????? e8???????? 83c404 84c0 }
- $sequence_2 = { 74cf 8bc7 ebce 66833800 7520 }
- $sequence_3 = { e8???????? 8b4df8 83c40c 5f 5e 33cd b001 }
- $sequence_4 = { 83fb01 7503 894df8 8b4d10 8bc3 }
- $sequence_5 = { 752c 6a02 53 ff15???????? }
- $sequence_6 = { e8???????? 83c40c 8b4dfc 5f 5e 33cd b001 }
- $sequence_7 = { 6a10 46 8d843594f7ffff 68???????? 50 e8???????? }
- $sequence_8 = { 8d45e4 50 8bc8 51 57 8bd0 }
- $sequence_9 = { 0f84ee000000 53 57 33db 8d9b00000000 }
+ $sequence_0 = { 85c0 7462 8b542408 8b8e00020000 8b44240c }
+ $sequence_1 = { 8b742418 83f8ff 898600020000 7508 5f 33c0 }
+ $sequence_2 = { 50 ffd3 89be04020000 8b8600020000 3bc7 740e }
+ $sequence_3 = { 8b1d???????? a1???????? 50 57 ff15???????? }
+ $sequence_4 = { 8d4c241c 8d542424 51 8b4c2414 8d442424 52 }
+ $sequence_5 = { 8d842430020000 50 ffd7 8d8c2430010000 51 ffd7 8b542424 }
+ $sequence_6 = { 6a00 6a00 6a00 6802000004 6a00 899610020000 }
+ $sequence_7 = { 68???????? 51 c744242802000000 c744242c2c010000 ff15???????? }
+ $sequence_8 = { 50 ff15???????? 8bd8 83fbff 0f849c000000 8b470c 8b5708 }
+ $sequence_9 = { 0f85c3000000 8b460c 85c0 0f84c0000000 03c5 }
condition:
- 7 of them and filesize <191488
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Telb_Auto : FILE
+rule MALPEDIA_Win_Graphsteel_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "41000399-e9f0-5453-bf9a-ecf53c98abcc"
+ id = "5824e278-153d-5fe0-a214-d93680fdb8e7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.telb"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.telb_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphsteel"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graphsteel_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "96b99ffd86058bdff13d6d8551ee9f8fb32df4a8153fed924c3d3ed45dd1d6ae"
+ logic_hash = "0a7069cfdac89882eeae5b943786ae3bcce2789fc825f256679c381850fffe14"
score = 75
quality = 75
tags = "FILE"
@@ -130166,32 +137285,32 @@ rule MALPEDIA_Win_Telb_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c744242400000000 e8???????? 68???????? ff15???????? a3???????? 8d4c2430 6a12 }
- $sequence_1 = { 68???????? 8d8c24a4000000 e8???????? 8d8c24a0000000 e8???????? 8d8c24a0000000 }
- $sequence_2 = { 668908 8d8d68eeffff c645fc26 e8???????? 8d8d68eeffff e8???????? 8d8dd0efffff }
- $sequence_3 = { 8945fc 85f6 7407 83feff 746f eb69 8b1c9d485c4100 }
- $sequence_4 = { 50 e8???????? 8b853ceeffff 83c40c 8985b0efffff 89b5b4efffff c645fc35 }
- $sequence_5 = { 8d85f0bfffff 50 ff15???????? 85c0 0f847b020000 6800200000 }
- $sequence_6 = { 0f8796150000 52 51 e8???????? 83c408 807c241200 }
- $sequence_7 = { 8d442468 50 e8???????? 837c244408 8d4c2430 }
- $sequence_8 = { 0f438570efffff 8d8d88efffff 50 e8???????? 6a01 68???????? 8d8d88efffff }
- $sequence_9 = { 85f6 0f8551010000 a1???????? b9???????? 83c0f5 50 56 }
+ $sequence_0 = { e8???????? 488d7830 488b4c2440 0f1f4000 e8???????? 4889c3 488d05415b3900 }
+ $sequence_1 = { ffd0 488bb42428010000 488b942410020000 4885d2 0f8401010000 488b4c2450 488d1d88ae4400 }
+ $sequence_2 = { e9???????? a810 0f84f1000000 84d2 0f888c010000 8954245c 83fa0b }
+ $sequence_3 = { e8???????? e8???????? 90 31c9 488d150f198e00 870a 8b0d???????? }
+ $sequence_4 = { e9???????? 4c8b4c2468 4d85c9 0f84b1000000 4c8b9424d8030000 4d8b9a88000000 498b4b08 }
+ $sequence_5 = { e8???????? 4909c5 0fb603 83c05b a8fb 0f85a0000000 488b4340 }
+ $sequence_6 = { e9???????? 8b8424a0010000 4189d9 ba35000000 4c89e9 448b842498010000 41bf06000000 }
+ $sequence_7 = { e9???????? 4885f6 0f8520ffffff 4c8d742440 4889d9 4d8b4550 c744244001080000 }
+ $sequence_8 = { eb11 488d7830 488b9424e0000000 e8???????? 488b542438 48895050 488b542440 }
+ $sequence_9 = { e8???????? c644243507 488d05e3cc3300 488b9c24c8000000 488d4c2435 e8???????? 48c7400806000000 }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <19812352
}
-rule MALPEDIA_Win_Alice_Atm_Auto : FILE
+rule MALPEDIA_Win_Finfisher_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "66f601ee-4bc7-50a3-954d-4444abf4a52f"
+ id = "3ef79a6b-24c3-58ed-a290-c5a2a7e3fb1b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alice_atm"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alice_atm_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.finfisher"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.finfisher_auto.yar#L1-L148"
license_url = "N/A"
- logic_hash = "5f587bc558ca0a42c8c96fe5a1cfb47b3decdd71da86c983392de940e1606224"
+ logic_hash = "dcf5252aa492d908a47d122045beaf12bf03e72009d0665a415b9ab4e015a1e5"
score = 75
quality = 75
tags = "FILE"
@@ -130205,32 +137324,36 @@ rule MALPEDIA_Win_Alice_Atm_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff75f8 8f45fc ff7508 e8???????? 8b45fc }
- $sequence_1 = { 0fb7c0 8945f8 8b7d10 83ff00 0f86c2000000 }
- $sequence_2 = { c9 c20c00 55 8bec 81c4a4feffff }
- $sequence_3 = { 894609 837f0414 7305 8b5704 }
- $sequence_4 = { 897dfc 8d9df6fdffff 53 ff7508 e8???????? 0bc0 }
- $sequence_5 = { 57 e8???????? 0bc0 0f848b000000 53 6804010000 }
- $sequence_6 = { 53 e8???????? 57 6806020000 56 }
- $sequence_7 = { 50 68???????? 68???????? 8d45e8 50 68???????? 6a05 }
- $sequence_8 = { 6a00 6a00 6809100000 ff7320 e8???????? 8945fc }
- $sequence_9 = { 0f85ce000000 68ea030000 ff7508 e8???????? 8bf8 }
+ $sequence_0 = { 68???????? 6804010000 8d85ccf9ffff 50 }
+ $sequence_1 = { 56 8d85ccf9ffff 50 e8???????? }
+ $sequence_2 = { 6a20 6a03 8d8594f7ffff 50 8d8578f7ffff 50 68000000c0 }
+ $sequence_3 = { 663bc1 7506 8345e404 ebd8 }
+ $sequence_4 = { 0f853affffff c785d0fbffffd5d8ffff e9???????? 8b07 83e808 }
+ $sequence_5 = { 52 68a0608000 eb11 8b4708 8b4dd4 }
+ $sequence_6 = { 397714 7403 56 eb02 6a02 56 50 }
+ $sequence_7 = { e8???????? 56 e8???????? 8b861c030000 3d10270000 }
+ $sequence_8 = { 56 8d859cf7ffff 50 56 a1???????? }
+ $sequence_9 = { 85db 7424 8b17 8d448614 8b08 }
+ $sequence_10 = { e9???????? 8b859cf7ffff ff7004 ff15???????? 8985c0f7ffff 8b8d9cf7ffff }
+ $sequence_11 = { 6a09 ff15???????? 3bc6 7490 8bd0 }
+ $sequence_12 = { ffb5b8f7ffff eb5f 8d8578f7ffff 50 6a01 8d85acf7ffff }
+ $sequence_13 = { 8d85acfbffff 50 53 56 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Bootwreck_Auto : FILE
+rule MALPEDIA_Win_Evilgrab_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7e23b82b-3bdc-58cd-906f-3ab5825b9ffb"
+ id = "92d56cb6-a40e-55a9-bb4b-7f3303d7e68c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bootwreck"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bootwreck_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.evilgrab"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.evilgrab_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "49dbec8ae0163fe1b10f7b427af3210b6bbd81884139d209319f2b77e78ba995"
+ logic_hash = "89c0b96a8a59594e704b0e35c7d209399933043505a45ecc6b5a8cd70ad1865a"
score = 75
quality = 75
tags = "FILE"
@@ -130244,32 +137367,71 @@ rule MALPEDIA_Win_Bootwreck_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33ff 897dfc 3b1cfde0c18100 7409 47 897dfc }
- $sequence_1 = { 8d642428 0f8409000000 660fbec2 86c7 8b4510 55 660fb6da }
- $sequence_2 = { 85b178373e03 025ad9 7efa 99 18c7 7e55 }
- $sequence_3 = { c74424147d978300 682dedfcaa 9c 89442418 9c 9c ff742420 }
- $sequence_4 = { ee 5b 7f3f 99 68e43b3fa7 6c }
- $sequence_5 = { 876c2428 66891c24 688106ab60 896c2428 5d 66896c2404 bd???????? }
- $sequence_6 = { 8955fc f9 8d9b00000000 30e1 37 d4b7 8b4d08 }
- $sequence_7 = { ff4638 88c3 66f7d6 b37c 5b 660fb6f9 5f }
- $sequence_8 = { c25400 c7042400000000 60 8774241c 8d64241c 0f8103500500 }
- $sequence_9 = { 8d041f f7c5036c87b2 99 84ed f8 60 6681fb744d }
+ $sequence_0 = { 50 50 50 52 89442440 89442434 89442438 }
+ $sequence_1 = { 8dbdb8f5ffff f3a5 a4 b909000000 be???????? 8dbd5cf4ffff f3a5 }
+ $sequence_2 = { c3 8d45c4 50 6a03 68???????? 8b0e 81c1d2000000 }
+ $sequence_3 = { 8b9534aeffff 52 8bcb e8???????? 85c0 7531 6aa7 }
+ $sequence_4 = { 8b35???????? e9???????? 8b85c8adffff 898540a3ffff 50 e8???????? 8b85c0adffff }
+ $sequence_5 = { 6a00 85f6 6a00 7567 }
+ $sequence_6 = { 52 8b45d4 8b481c 51 e8???????? }
+ $sequence_7 = { 52 8b35???????? ffd6 d1e0 898565a4ffff }
+ $sequence_8 = { 52 68???????? 53 ffd5 83c410 6880000000 53 }
+ $sequence_9 = { 33c0 8dbdf0efffff f3ab c685f0efffffd0 668b5304 52 e8???????? }
+
+ condition:
+ 7 of them and filesize <327680
+}
+rule MALPEDIA_Win_Snojan_Auto : FILE
+{
+ meta:
+ description = "autogenerated rule brought to you by yara-signator"
+ author = "Felix Bilstein - yara-signator at cocacoding dot com"
+ id = "96ddba9d-1a09-5178-a027-761c3b0ea160"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.snojan"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.snojan_auto.yar#L1-L121"
+ license_url = "N/A"
+ logic_hash = "a7da77f2b75075e9b17ce3132c822da8d2432067b99e241b1e6927c5f09a8d94"
+ score = 75
+ quality = 75
+ tags = "FILE"
+ version = "1"
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { ff15???????? 83ec0c 83f8ff 0f8487010000 89c7 b802000000 c70424???????? }
+ $sequence_1 = { b802000000 c70424???????? 6689442420 ff15???????? 83ec04 c70424???????? 89442424 }
+ $sequence_2 = { 8d5c2430 c644241f00 c744240c00000000 c744240800900100 895c2404 893c24 ff15???????? }
+ $sequence_3 = { a1???????? 8b988000986d 85db 74da }
+ $sequence_4 = { 8d860000986d 8955cc e8???????? 8b45cc }
+ $sequence_5 = { 893c24 ff15???????? 83ec10 83f800 }
+ $sequence_6 = { e9???????? 0fb7810000986d 894dc0 89c7 81cf0000ffff 6683b90000986d00 0f48c7 }
+ $sequence_7 = { 85c0 74e9 a1???????? 8b988000986d 85db 74da 895c2404 }
+ $sequence_8 = { 837c243401 753d c744241400000000 c744241000000000 }
+ $sequence_9 = { 85c0 b801000000 0f44d0 8854241f 8974240c 896c2408 }
condition:
- 7 of them and filesize <10821632
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Elf_Persirai_Auto : FILE
+rule MALPEDIA_Win_Polpo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a8d888a8-efae-5fcd-8298-ba3399d89281"
+ id = "f09c9fa9-68a5-510c-9c07-2bf30033e8be"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.persirai"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.persirai_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.polpo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.polpo_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "091433f152a0a1932173079b7afa5457b62363ecd6425f8d1d7de8df73a8fbb4"
+ logic_hash = "d086587d6209a1b4d39f14c8bf11bcdd8bb5ac2527f8607c317abb5534459f55"
score = 75
quality = 75
tags = "FILE"
@@ -130283,32 +137445,32 @@ rule MALPEDIA_Elf_Persirai_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c3 c3 53 83ec08 e8???????? 31d2 8b5c2414 }
- $sequence_1 = { 8b5c2410 837c241400 740b 83ec0c ff7304 ff13 83c410 }
- $sequence_2 = { 50 52 e8???????? 58 8d8424d8170000 50 e8???????? }
- $sequence_3 = { 8d4400e0 50 e8???????? 89c2 a3???????? 83c410 83c8ff }
- $sequence_4 = { 817c2414ff030000 0f8770030000 8b442414 c1e004 83b888a2050800 0f85df000000 8b0d???????? }
- $sequence_5 = { c7042408000000 50 a1???????? 6a1a 6a01 50 e8???????? }
- $sequence_6 = { 83c418 5b c3 81ecac000000 31d2 a1???????? }
- $sequence_7 = { 85c0 74cb e8???????? 52 52 8b00 }
- $sequence_8 = { c680b901000000 8b45f0 e8???????? 89f0 8b55f0 e8???????? 8b45f0 }
- $sequence_9 = { 83c004 89442418 e9???????? bf0a000000 e9???????? bf10000000 e9???????? }
+ $sequence_0 = { 6800040000 8d8decfbffff 51 50 ffd7 6a00 }
+ $sequence_1 = { 50 8d85ecf7ffff 50 8d8decfbffff 51 ff15???????? 40 }
+ $sequence_2 = { 6a02 52 ff15???????? 8b03 50 ff15???????? }
+ $sequence_3 = { c1e606 03348540b30120 8b45f8 8b00 8906 }
+ $sequence_4 = { 57 33c0 6806020000 898d98f9ffff 50 8d8df6fdffff 51 }
+ $sequence_5 = { 8d854cffffff 8bd0 8d642400 8a08 40 3acb 75f9 }
+ $sequence_6 = { 52 50 ff15???????? 6a00 6800040000 8d8dfcfaffff 68???????? }
+ $sequence_7 = { 8a08 40 3acb 75f9 2bc6 8dbd4cf7ffff }
+ $sequence_8 = { 51 8985d0dfffff 8985d4dfffff 8885dcdfffff e8???????? }
+ $sequence_9 = { ffd6 85c0 8b859cfdffff 50 0f8516020000 ff15???????? 8d45a4 }
condition:
- 7 of them and filesize <229376
+ 7 of them and filesize <250880
}
-rule MALPEDIA_Win_Upatre_Auto : FILE
+rule MALPEDIA_Win_Molerat_Loader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1628c1f9-1d48-5501-a98b-2c8f976e35eb"
+ id = "6649c702-0322-5056-bfb1-5bb59b0b659a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.upatre"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.upatre_auto.yar#L1-L164"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.molerat_loader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.molerat_loader_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "ec286f640db5a5b7bffd2eededa524e0947ea3452d78b30e2aeb2f315c32ce53"
+ logic_hash = "9e4d3c42bd1eb8db57dd9c545f5a5ad86009e39e60f601bd2428ef16d555d86e"
score = 75
quality = 75
tags = "FILE"
@@ -130322,38 +137484,32 @@ rule MALPEDIA_Win_Upatre_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 66ab 33c0 66ab bbff0f0000 8b75f0 }
- $sequence_1 = { 8945fc 8bd8 03c1 8bf8 33c0 }
- $sequence_2 = { 894d90 8b4d8c 85c9 7501 c3 57 }
- $sequence_3 = { 7414 4e 56 ff75f0 }
- $sequence_4 = { 0430 66ab 81c60e010000 ac }
- $sequence_5 = { 8945ec 6a00 8d4dc0 51 ff75e0 ff75bc ff75ec }
- $sequence_6 = { 895d98 8bfb 03d8 b91c010000 }
- $sequence_7 = { b900100000 03c1 8945f0 03c1 }
- $sequence_8 = { 83c008 8945bc 8b4dbc 8b5104 52 }
- $sequence_9 = { 8b55d4 8b440a1c 8945f4 8b4df0 }
- $sequence_10 = { 0f94c0 85c0 7436 8b4dd8 83c102 2b4de8 }
- $sequence_11 = { e3c9 1bb6aeaca844 bbcdcc70e8 739c d4ef }
- $sequence_12 = { eb2b 8b4df4 8b510c 52 e8???????? 83c404 0fb7c0 }
- $sequence_13 = { 8b4508 0345f0 0fbe08 8b5510 0faf55f8 0faf55f0 33ca }
- $sequence_14 = { 8945dc 8b4ddc 668b11 668955f0 0fb745f0 }
- $sequence_15 = { 894df4 8b55f4 3b550c 7d28 }
+ $sequence_0 = { 83c40c 68???????? 50 8d8dc0fdffff 51 c645fc18 }
+ $sequence_1 = { 68???????? e8???????? 8b4d58 e8???????? e9???????? 68???????? e8???????? }
+ $sequence_2 = { 7d0d 8a4c181c 888860464400 40 ebe9 33c0 8945e4 }
+ $sequence_3 = { 83c40c 8d957cffffff 52 50 8d85d0fdffff 50 c645fc3a }
+ $sequence_4 = { 50 8b4204 ffd0 8d4d0c e8???????? 8d8da0fdffff c645fc07 }
+ $sequence_5 = { 7f0a 8b08 8b11 50 8b4204 ffd0 c645fc69 }
+ $sequence_6 = { 8b95ecfeffff 8995e8feffff c745fc01000000 b8???????? c3 c645fc00 }
+ $sequence_7 = { 8d4c247c c68424d800000002 e8???????? 8d54247c 52 c7842480000000e8c64300 e8???????? }
+ $sequence_8 = { 83c010 83c404 8945e8 68???????? 68???????? 8d4de4 51 }
+ $sequence_9 = { 8d8d74ffffff c645fc03 e8???????? 8d8574ffffff 50 8d4d5c 68???????? }
condition:
- 7 of them and filesize <294912
+ 7 of them and filesize <688128
}
-rule MALPEDIA_Win_Carberp_Auto : FILE
+rule MALPEDIA_Win_Agendacrypt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ca3e7da8-ad9c-59f4-8614-8b1382409083"
+ id = "20fa12ae-39fc-589c-ac17-0baa3bbfd44a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.carberp"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.carberp_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.agendacrypt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.agendacrypt_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "1e5a666bd6ef8c024c58bd150c2d57a0675cba836a8af1e051301be69118758b"
+ logic_hash = "b4f726649ba175df63b497d8d60f55fe36fe0cd2719e493aac65ae353f8a7651"
score = 75
quality = 75
tags = "FILE"
@@ -130367,32 +137523,32 @@ rule MALPEDIA_Win_Carberp_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b8???????? 50 6a00 50 e8???????? 8b4518 8945e4 }
- $sequence_1 = { 68f5a40f7d 6a0d 6a00 e8???????? 68da6772c2 6a0d 6a00 }
- $sequence_2 = { ff75fc 56 ff15???????? 8bf0 8d45f8 50 e8???????? }
- $sequence_3 = { 0f848d000000 6683f832 0f8483000000 6683f821 0f8548010000 57 8d8588fdffff }
- $sequence_4 = { 7407 50 e8???????? 59 ff45f4 8b45f4 3b45f0 }
- $sequence_5 = { 668945f6 58 6a72 668945f8 58 6a5c 668945fa }
- $sequence_6 = { ff7658 e8???????? 83c418 83665800 5e 5d c3 }
- $sequence_7 = { 59 59 85f6 7419 ff7510 56 6a04 }
- $sequence_8 = { 6800000040 ff7508 ffd0 8bf8 83ffff 7504 33c0 }
- $sequence_9 = { c645f867 c645f96c c645fa57 c645fb6e c645fc64 885dfd 895dc8 }
+ $sequence_0 = { eb20 8b55ec 8975e8 89f1 57 53 e8???????? }
+ $sequence_1 = { 8d55b0 e8???????? eb25 c745b000000000 8d4dd0 8d55b0 e8???????? }
+ $sequence_2 = { c1e204 88443110 89f8 f7d0 c1e004 f30f7e0403 f30f7e4c0308 }
+ $sequence_3 = { c1c71a 31fa 8b7b04 89c3 339d70ffffff 0fcf 21cb }
+ $sequence_4 = { e9???????? 8d543210 8b7508 f20f104a30 f20f114e40 f20f104a28 f20f114e38 }
+ $sequence_5 = { f20f1101 8b55f0 8d4da8 ff7518 ff7514 ff7510 ff750c }
+ $sequence_6 = { f20f1145c8 0f82de010000 80ff0a 894804 0f85c9000000 8b7d0c 8b55ec }
+ $sequence_7 = { f20f114c2438 f20f108c2488000000 f20f11542430 f20f105028 f20f11442440 f20f115c2418 f20f1018 }
+ $sequence_8 = { e8???????? e9???????? ffb424fc000000 e8???????? e9???????? e8???????? 89c3 }
+ $sequence_9 = { ffd1 83c404 8b8c24a0190000 83790400 741f 8b84249c190000 83790809 }
condition:
- 7 of them and filesize <491520
+ 7 of them and filesize <3340288
}
-rule MALPEDIA_Win_Snatch_Loader_Auto : FILE
+rule MALPEDIA_Win_Chir_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "27465de5-7033-587f-a756-9377f064a810"
+ id = "18ccfa9f-30e1-5e52-b265-5cee479b1cb5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.snatch_loader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.snatch_loader_auto.yar#L1-L176"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chir"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chir_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "0092d0e62ac35cefc4568a8a8fbdf579b918d859e448f714bc73aa915417d36e"
+ logic_hash = "3243cfbae6092a474cd7d4359f5703dd14295b3f14d9c12875310667b98d1cdf"
score = 75
quality = 75
tags = "FILE"
@@ -130406,40 +137562,34 @@ rule MALPEDIA_Win_Snatch_Loader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 66894606 a1???????? 85c0 7522 6a02 59 }
- $sequence_1 = { 8bc8 8b45fc 33d2 85c9 5e 0f45c2 8be5 }
- $sequence_2 = { 51 56 56 ffd0 8bc8 8b45fc 33d2 }
- $sequence_3 = { 33f6 8bd9 57 85c0 7522 6a02 }
- $sequence_4 = { ffd0 5f 85c0 7509 8bce e8???????? }
- $sequence_5 = { ffd0 85c0 8bce 0f457dfc }
- $sequence_6 = { 85c0 7505 8b45fc eb0d 53 53 }
- $sequence_7 = { 33f6 8bd6 8975fc 66397102 740b 42 }
- $sequence_8 = { 46 3bf3 76d8 33c0 48 5a 59 }
- $sequence_9 = { 741f 3a0439 7514 41 3b4df8 }
- $sequence_10 = { 68???????? 58 ffd0 8945f0 0bc0 }
- $sequence_11 = { 33d2 33c9 8a0431 0ac0 741f }
- $sequence_12 = { 52 ff750c e8???????? 8945fc 0bc0 7454 394508 }
- $sequence_13 = { 55 8bec 83c4fc 53 33db 837d0800 }
- $sequence_14 = { 3b45fc 773b 8b750c 8b7d10 037508 8bde }
- $sequence_15 = { 7206 3c5a 7702 0c20 c1c210 }
+ $sequence_0 = { 47 8811 3bf8 72e7 }
+ $sequence_1 = { 8d4c3df0 8a11 80f2fc 80c202 }
+ $sequence_2 = { e8???????? 48 59 8bcb 7419 }
+ $sequence_3 = { 5e 7419 8d4c35f8 8a11 80f2fc }
+ $sequence_4 = { 8d45f0 50 c745f021352432 c745f451173300 e8???????? 48 }
+ $sequence_5 = { c745f451173300 e8???????? 48 59 8bfb }
+ $sequence_6 = { 8d4c35f0 8a11 80f2fc 80c202 80f201 }
+ $sequence_7 = { 8a19 80f3fc 80c302 80f301 80c303 42 }
+ $sequence_8 = { 7415 8d4c15f8 8a01 34fc }
+ $sequence_9 = { 8a11 80f2fc 80c202 80f201 80c203 46 8811 }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <286720
}
-rule MALPEDIA_Win_Pitou_Auto : FILE
+rule MALPEDIA_Win_Ccleaner_Backdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8ffbef2d-72c2-5fd0-bc80-d9aaff0b569e"
+ id = "fc5d42e4-2b09-51e8-9476-e6d57b9f6fbe"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pitou"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pitou_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ccleaner_backdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ccleaner_backdoor_auto.yar#L1-L264"
license_url = "N/A"
- logic_hash = "e9d79d3aa0dabaeee54f58f2a742dc54ca18da56fbfe8d220d28635b8791c96b"
+ logic_hash = "437c1ac4e0723d85ccca29c304bbc711ed3ae66fbe1eeb3f8d5172b567e72b6c"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -130451,32 +137601,51 @@ rule MALPEDIA_Win_Pitou_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bda c1e305 03c3 8bda }
- $sequence_1 = { ac 8bda c1e305 03c3 8bda c1eb02 03c3 }
- $sequence_2 = { c1e305 03c3 8bda c1eb02 }
- $sequence_3 = { 8a6201 80f457 8acc 80e103 }
- $sequence_4 = { 8bda c1e305 03c3 8bda c1eb02 03c3 33d0 }
- $sequence_5 = { 8a12 80f257 8ada c0eb02 }
- $sequence_6 = { c1e305 03c3 8bda c1eb02 03c3 33d0 }
- $sequence_7 = { 53 80ef18 80ff10 5b }
- $sequence_8 = { 80f457 8acc 80e103 8aec }
- $sequence_9 = { ac 8bda c1e305 03c3 8bda }
+ $sequence_0 = { 57 ffd6 50 ff15???????? 8b3d???????? }
+ $sequence_1 = { ff15???????? 8b3d???????? 59 ffd7 }
+ $sequence_2 = { 750a b857000780 e9???????? e8???????? }
+ $sequence_3 = { 01460c 488b3f 493bfc 0f8554ffffff }
+ $sequence_4 = { 00cc cc 4883ec28 488b11 }
+ $sequence_5 = { 49 75f9 ffd3 6800400000 }
+ $sequence_6 = { ff75f0 ff15???????? 85c0 0f850c010000 8b35???????? 53 }
+ $sequence_7 = { 01442424 eb30 8b4508 897518 }
+ $sequence_8 = { 03c0 894340 8b7340 418bc4 }
+ $sequence_9 = { 03c6 4863d0 4c8d0c12 4c8d4718 }
+ $sequence_10 = { 03c6 85c0 7f09 488b0a 488b01 ff5008 488b4b28 }
+ $sequence_11 = { 891d???????? 68???????? 6a03 53 68???????? ff742424 891d???????? }
+ $sequence_12 = { 6a04 50 8d45e0 6a04 50 8d85e0feffff 50 }
+ $sequence_13 = { c1e008 8d8418a1000000 50 e8???????? 85c0 7545 }
+ $sequence_14 = { 012e 33c0 5f 5e 5d }
+ $sequence_15 = { 00cc cc 4057 4883ec50 4533db }
+ $sequence_16 = { 8b7df8 0faff8 ffd6 33f8 }
+ $sequence_17 = { 01442454 03d1 294c2450 8b4c2410 }
+ $sequence_18 = { 50 68???????? ff742418 ff15???????? 85c0 0f8579010000 }
+ $sequence_19 = { c7471854b40210 c1e803 3bc1 7302 8bc8 6afd }
+ $sequence_20 = { 3bc2 7661 89450c 8a06 46 50 e8???????? }
+ $sequence_21 = { 013d???????? 8b04b5d8970210 0500080000 3bc8 }
+ $sequence_22 = { 3b7d10 0f8264010000 3bfa 0f835c010000 2bda 8d4602 }
+ $sequence_23 = { 013e 33c0 8b16 83c410 }
+ $sequence_24 = { e8???????? 8b4510 59 f7d8 }
+ $sequence_25 = { 01442418 03c8 8954242c 8b542470 }
+ $sequence_26 = { 01461c 8b542424 85d2 7405 }
+ $sequence_27 = { 01cc cc 48895c2408 57 }
+ $sequence_28 = { 4c 8bca c1e002 4c 03d5 48 }
condition:
- 7 of them and filesize <1106944
+ 7 of them and filesize <377856
}
-rule MALPEDIA_Win_Unidentified_078_Auto : FILE
+rule MALPEDIA_Win_Neutrino_Pos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "de8cdecb-4380-57eb-b923-e2ba443932e2"
+ id = "3a77c0fc-cd49-5986-b2b4-8a8639992c93"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_078"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_078_auto.yar#L1-L110"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.neutrino_pos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.neutrino_pos_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "d08e32bbc4aa8e2920b084e5d720f452f9f589f09a38ee6e42b2e5fd17bef5f8"
+ logic_hash = "d3da7317997b76876b14e53b428d397cde821604c2c6da81c73b18c8b2dd677f"
score = 75
quality = 75
tags = "FILE"
@@ -130490,32 +137659,32 @@ rule MALPEDIA_Win_Unidentified_078_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7d21 8a440b10 3c5c 7419 }
- $sequence_1 = { e8???????? 84c0 7467 f60701 }
- $sequence_2 = { e9???????? 80fa5b 7f3c 80fa28 0f8d94010000 }
- $sequence_3 = { 80fa0d 0f8421010000 80fa1b 0f8576010000 ba02000000 e8???????? }
- $sequence_4 = { 80fa7e 0f8f02010000 e9???????? ba02000000 }
- $sequence_5 = { b901010000 ff15???????? 85c0 740e e8???????? }
- $sequence_6 = { 0f8cee000000 80fa0d 0f8421010000 80fa1b 0f8576010000 }
- $sequence_7 = { 0f8f18010000 80fa23 0f8d82010000 ba02000000 }
- $sequence_8 = { 753f a900004011 7521 a900000600 }
- $sequence_9 = { 0f8d94010000 80fa26 0f8f18010000 80fa23 0f8d82010000 }
+ $sequence_0 = { 68fbd5fba3 43 53 897dfc e8???????? 83c40c 56 }
+ $sequence_1 = { 5a 6a71 6689955affffff 5a 6a61 6689955cffffff }
+ $sequence_2 = { 6863ad115b 6a04 c745e801000000 8945f4 e8???????? 59 }
+ $sequence_3 = { e8???????? 59 59 6a00 56 e9???????? }
+ $sequence_4 = { 6a62 66898556ffffff 58 6a53 66898558ffffff }
+ $sequence_5 = { 59 6a64 66898d6cffffff 59 6a68 66898d6effffff 59 }
+ $sequence_6 = { 6a63 6689854cffffff 58 6a62 6689854effffff 58 6a69 }
+ $sequence_7 = { 66895db2 6a64 8bd9 66895db4 8bd8 66895db6 5b }
+ $sequence_8 = { 8b45e0 8b08 6a03 50 ff5138 }
+ $sequence_9 = { 66894dd6 66894dd8 66894dda 66894ddc 66894dde 66894de0 66894de2 }
condition:
- 7 of them and filesize <688128
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Catchamas_Auto : FILE
+rule MALPEDIA_Win_Stration_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f5823958-4dc9-52e1-b587-ac7a6b699e31"
+ id = "b1ff0234-14a0-5584-b678-4973125b246b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.catchamas"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.catchamas_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stration"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stration_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "49e84bf121f6f46a8c4833df80092f815e20586f9bd57ea545ff931ae803e6c2"
+ logic_hash = "1e976189a59a2a64efd8d3bfcb5fabcc1cb05f5b8a248de2fec831e10609d819"
score = 75
quality = 75
tags = "FILE"
@@ -130529,32 +137698,32 @@ rule MALPEDIA_Win_Catchamas_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd6 6808080000 8d54246c 52 }
- $sequence_1 = { 5f 5e 8b8c247c200000 33cc e8???????? }
- $sequence_2 = { 6a00 ff15???????? e8???????? 8bcb 8b5c244c 51 }
- $sequence_3 = { 6683f814 0f84c4080000 833d????????00 0f85af000000 }
- $sequence_4 = { 50 bf01000000 ff15???????? 56 ff15???????? 85ff 0f851a010000 }
- $sequence_5 = { 50 8d8c2494100000 68???????? 51 ff15???????? 83c42c 33c0 }
- $sequence_6 = { 84c0 8b45e0 7409 e8???????? 8bfc eb32 }
- $sequence_7 = { ffd7 6a0a 56 8be8 ffd7 8bf8 }
- $sequence_8 = { 83e802 0f84bf090000 83e80d 0f845a090000 }
- $sequence_9 = { 51 57 8bf0 50 ebbd e8???????? }
+ $sequence_0 = { 6a00 6a01 baf1000000 8bcb e8???????? 55 6a01 }
+ $sequence_1 = { 56 e8???????? 83c408 6a00 6a01 baf1000000 8bcd }
+ $sequence_2 = { e8???????? 680b040000 56 8944241c }
+ $sequence_3 = { c1fa05 891424 8bd1 52 e8???????? a3???????? 8b4c241c }
+ $sequence_4 = { ba11010000 8bce e8???????? c705????????00000000 }
+ $sequence_5 = { 8b15???????? 89442404 a1???????? 894c2408 8a0d???????? 89442410 8954240c }
+ $sequence_6 = { 33f6 85ff 893d???????? 7517 a1???????? 85c0 c605????????00 }
+ $sequence_7 = { 8a540404 c1e910 32d1 88540404 }
+ $sequence_8 = { 83f80d 7cec 8b15???????? a1???????? 8b0d???????? 891424 668b15???????? }
+ $sequence_9 = { eb05 bd14000000 660935???????? 8d542434 52 8d8424b4000000 }
condition:
- 7 of them and filesize <368640
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Unidentified_109_Auto : FILE
+rule MALPEDIA_Win_Prometei_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c4f891e4-f77b-5dbc-bacf-3b1d550b883c"
+ id = "f30d42cb-2af1-5154-8e15-89c897952439"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_109"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_109_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.prometei"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.prometei_auto.yar#L1-L159"
license_url = "N/A"
- logic_hash = "553f5c1aaae307ba70f86b75a4cbec28cc4c8b523dbd68b695bc6b2028248608"
+ logic_hash = "5377a5e6947b9cd903f94c70f6185011aeea6f018af2aa2974c11199d44376b8"
score = 75
quality = 75
tags = "FILE"
@@ -130568,34 +137737,40 @@ rule MALPEDIA_Win_Unidentified_109_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d55df 488d4df7 4c8d45f7 e8???????? 8bf0 85c0 }
- $sequence_1 = { 7405 85db 0f44d8 0fb68fa2030000 0fbe45ab 3bc1 7e11 }
- $sequence_2 = { e8???????? 488bcb e8???????? 488bdf 4885ff 75b5 488b742430 }
- $sequence_3 = { 8b07 418b09 4883c704 4d8d4904 480fafcd 4803c8 418bc0 }
- $sequence_4 = { 2b8300010000 3bc5 7312 8bd5 488bcb e8???????? 85c0 }
- $sequence_5 = { 4c8b3a 4c8be1 4c8bea 488d4c2420 41b8a8040000 33d2 }
- $sequence_6 = { 23c6 440bf0 8d040a 418bd3 4403f0 418bc3 c1c80b }
- $sequence_7 = { eb77 418d41ff 4863c8 488d048f 33ff 4d8d048a }
- $sequence_8 = { 0f8462020000 83b90001000000 7621 e8???????? 89834c020000 85c0 0f8550020000 }
- $sequence_9 = { 4289449efc 4c3bdd 7c8b 8b442450 8b0b 4c8b742420 8903 }
+ $sequence_0 = { 011d???????? 03c8 8b5de4 a1???????? }
+ $sequence_1 = { 8bf0 83feff 7425 6a00 8d45d8 50 }
+ $sequence_2 = { 014364 8b45e4 014368 5b }
+ $sequence_3 = { bb8c132400 4a af e8???????? 1401 d000 }
+ $sequence_4 = { 014358 8b45f0 01435c 8b45fc }
+ $sequence_5 = { 014368 81434400020000 c7434000000000 83534800 }
+ $sequence_6 = { 8ac2 0245f0 3001 85d2 }
+ $sequence_7 = { 014360 8b45f4 014364 8b45e4 }
+ $sequence_8 = { 8b55f0 33c9 8b75fc 8b45f8 85c0 }
+ $sequence_9 = { 01c8 93 9e b2e0 e605 78a1 a4 }
+ $sequence_10 = { 013d???????? 8b04b5c8054400 0500080000 3bc8 }
+ $sequence_11 = { 01435c 8b45fc 014360 8b45f4 }
+ $sequence_12 = { 014354 8b45e8 014358 8b45f0 }
+ $sequence_13 = { b901000000 89500c 8bc1 f745c000020000 }
+ $sequence_14 = { 8b3d???????? b801000000 33c9 53 0fa2 5b }
+ $sequence_15 = { 8bc1 2bc7 2bd7 0145fc 81c232240000 8bc1 8955e8 }
condition:
- 7 of them and filesize <723968
+ 7 of them and filesize <51014656
}
-rule MALPEDIA_Win_Scanpos_Auto : FILE
+rule MALPEDIA_Win_Dreambot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8293fa8e-4228-517c-a26a-04301bca2110"
+ id = "6c3809b8-d477-5125-8734-0179b265a99d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scanpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.scanpos_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dreambot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dreambot_auto.yar#L1-L1031"
license_url = "N/A"
- logic_hash = "b005df89a44c0f26903a8ba8f3d418d77b4a13957700f79b1d7571fcff516771"
+ logic_hash = "d649e332b74326d8b7e280b52a73b7636b1baab8e64673c71262bd2586c99629"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -130607,32 +137782,141 @@ rule MALPEDIA_Win_Scanpos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c645b800 e8???????? c645fc01 837de810 8b45d4 }
- $sequence_1 = { c745d830124100 e8???????? 8b4508 8b4dec 8945e4 40 }
- $sequence_2 = { 52 57 8bfe 8d75d4 e8???????? be10000000 c645fc00 }
- $sequence_3 = { 80f939 0f8fd3010000 80f930 0f8cca010000 0fbec0 0fbec9 8d848010ffffff }
- $sequence_4 = { 7f04 3bcb 7611 8945d8 }
- $sequence_5 = { 8b4dac c745cc0f000000 c745c800000000 c645b800 e8???????? c645fc01 }
- $sequence_6 = { 50 8d4d80 e8???????? 83c40c 57 }
- $sequence_7 = { 84db 7507 6a01 e8???????? 8d8de8feffff }
- $sequence_8 = { 57 8d8dcbfeffff 51 6804010000 }
- $sequence_9 = { 2bc1 8bcf 03c3 83cfff 2bf8 3bf9 730a }
+ $sequence_0 = { a802 7410 8b4730 a840 7509 83672800 e9???????? }
+ $sequence_1 = { 897b20 8b4320 c6400731 8b742414 8b3e 6a00 }
+ $sequence_2 = { 7454 68???????? 68???????? ff7320 e8???????? }
+ $sequence_3 = { 0f8555ffffff 894730 e9???????? 55 8bec }
+ $sequence_4 = { 85f6 0f84a9000000 e8???????? 85c0 0f8483000000 }
+ $sequence_5 = { e8???????? 8bf8 85ff 755a 39451c 7475 }
+ $sequence_6 = { 751a 395d10 7413 8b4618 e8???????? eb09 ff7618 }
+ $sequence_7 = { 51 51 33c0 50 56 ff5214 8bfb }
+ $sequence_8 = { 53 68???????? eb54 3bf3 745c 395d0c 7457 }
+ $sequence_9 = { 837d0c04 7516 ff7510 ff36 68???????? }
+ $sequence_10 = { ebcc 3bf3 7474 395d0c 746f 6a0d }
+ $sequence_11 = { 3bf3 0f8496000000 395d0c 0f848d000000 6a07 ebdd }
+ $sequence_12 = { 3bf3 0f8481000000 395d0c 747c 6a03 }
+ $sequence_13 = { e8???????? 894508 8b7d08 eb24 a1???????? 85c0 7520 }
+ $sequence_14 = { 745c 395d0c 7457 53 ff750c 8bfe c7450857000000 }
+ $sequence_15 = { e8???????? e9???????? 3bf3 0f8496000000 }
+ $sequence_16 = { 4803542460 41ff5220 4c8b442460 e9???????? }
+ $sequence_17 = { e8???????? 4c8b1d???????? ba0d000000 41834b3401 }
+ $sequence_18 = { 0f84b5000000 413bf5 0f84ac000000 41b807000000 ebd7 493bfd }
+ $sequence_19 = { 4c896c2420 e8???????? 4c8b442468 488b0d???????? 33d2 }
+ $sequence_20 = { 7423 41b904000000 413bf1 7518 8b17 }
+ $sequence_21 = { 418d5620 498bcf ff15???????? 4c8bf0 4885c0 }
+ $sequence_22 = { 498bcb 492bd0 4803542460 41ff5220 }
+ $sequence_23 = { 0f8492000000 41b803000000 ebbd 493bfd 0f8481000000 413bf5 }
+ $sequence_24 = { 4c8b18 488b542460 4533c9 488bc8 41ff5318 }
+ $sequence_25 = { 488d5e10 4533f6 488b0b 2580000000 418d5620 }
+ $sequence_26 = { ff15???????? e9???????? 493bfd 0f84d9000000 }
+ $sequence_27 = { e8???????? eb2c 8b05???????? 413bc5 7528 }
+ $sequence_28 = { 488b9424a8000000 4533c9 4533c0 ff5028 }
+ $sequence_29 = { 0f8481000000 413bf5 747c 41b80d000000 }
+ $sequence_30 = { 488bcf e8???????? e9???????? 493bfd 0f84b5000000 }
+ $sequence_31 = { 5f c3 4053 4883ec20 4c8b4108 488bd9 4d85c0 }
+ $sequence_32 = { 0f849b000000 413bf5 0f8492000000 41b803000000 ebbd }
+ $sequence_33 = { 33d2 89442448 ff15???????? 33d2 }
+ $sequence_34 = { 33d2 3bc2 0f85bd000000 33c0 89942498000000 }
+ $sequence_35 = { e8???????? 488b5c2428 85c0 753e 8b9424c8000000 }
+ $sequence_36 = { 3decc7eea6 0f84e8000000 3d0470a8c4 0f8486000000 }
+ $sequence_37 = { 488b0d???????? 4d8bc4 33d2 ff15???????? 488bf8 }
+ $sequence_38 = { 4883ec30 837a3c04 4c8b2a 488bf2 488bd9 }
+ $sequence_39 = { 89750c 8d750c e8???????? 8bf0 }
+ $sequence_40 = { 4883c208 4883e901 75e2 837c243801 0f86b2000000 }
+ $sequence_41 = { 8b450c 33db 895dfc e8???????? 8945f8 33ff eb03 }
+ $sequence_42 = { 75f5 eb06 8b05???????? 35fc5585cf 4533c9 }
+ $sequence_43 = { ff7310 ff15???????? 33d2 89b7184a0000 39971c4a0000 }
+ $sequence_44 = { ff33 50 6810040000 ff15???????? 8945fc }
+ $sequence_45 = { 56 33f6 46 8945f8 }
+ $sequence_46 = { c3 6a00 6800004000 6a00 ff15???????? a3???????? 85c0 }
+ $sequence_47 = { 46 8945f8 85c0 7551 }
+ $sequence_48 = { 57 4883ec20 8b05???????? 8364243800 }
+ $sequence_49 = { ff15???????? 8945fc 85c0 741a 6804010000 }
+ $sequence_50 = { 85c0 7551 ff33 50 }
+ $sequence_51 = { eb03 8b750c ff75f8 69f60d661900 ff75f4 81c65ff36e3c 89750c }
+ $sequence_52 = { 817424105085b8ed 33ff 47 57 be???????? 56 8d542418 }
+ $sequence_53 = { 1bdb f7db 83c303 ebc4 }
+ $sequence_54 = { 8b9424c8000000 85d2 7421 4533c9 }
+ $sequence_55 = { 4883f8ff 488bf8 7445 488d842488000000 }
+ $sequence_56 = { 48c7c101000080 ff15???????? 85c0 7568 4c8d8c24d0000000 4c8d8424c8000000 488d542428 }
+ $sequence_57 = { 4c8bc3 33d2 ff15???????? 4821742428 4c8d8424c8000000 488d542428 488d4c2450 }
+ $sequence_58 = { 4883c208 4983e801 75e4 8b442420 }
+ $sequence_59 = { 0f84ca010000 8b424c a801 0f840f010000 8b424c }
+ $sequence_60 = { 33c0 89942498000000 899424a8000000 8984249c000000 }
+ $sequence_61 = { 498be9 e8???????? 4885c0 488bf0 0f84a3000000 }
+ $sequence_62 = { 8db4083089b9ed 57 8d45f4 50 }
+ $sequence_63 = { 4d3bef 7415 498bd5 4883c9ff }
+ $sequence_64 = { 8b45fc 0fb700 8bc8 81e100f00000 }
+ $sequence_65 = { ff75fc e8???????? 8b45f0 40 c745e801000000 }
+ $sequence_66 = { 4c8bc6 ff15???????? 488bd8 493bc7 }
+ $sequence_67 = { 395d10 0f8402010000 6a03 eb13 3bf3 }
+ $sequence_68 = { 6a01 eb3d 3bf3 0f8420010000 }
+ $sequence_69 = { 8d85a2fcffff 53 50 895de4 e8???????? }
+ $sequence_70 = { 4885c9 7405 e8???????? 4883c428 c3 4053 }
+ $sequence_71 = { 493bc5 742f 488d4810 ff15???????? }
+ $sequence_72 = { 57 6806020000 668985a0fcffff 8d85a2fcffff 53 }
+ $sequence_73 = { 8be5 5d c20400 8325????????00 6a00 }
+ $sequence_74 = { 740e 44893d???????? 44893d???????? 488d442440 4c8d4c2440 4c8d442440 4889442430 }
+ $sequence_75 = { 89410e 5f 5e 5b c9 c20400 }
+ $sequence_76 = { 8bf0 33db 81c1fefeffff 33c0 83cfff 33d2 895dfc }
+ $sequence_77 = { 59 c20400 a1???????? 53 55 56 57 }
+ $sequence_78 = { 7505 8d5857 eb15 488b05???????? 89702a 48897d00 eb17 }
+ $sequence_79 = { eb08 ff15???????? 8bd8 413bde 0f85fb010000 488b05???????? }
+ $sequence_80 = { 66b90100 4889442420 e8???????? 3bc3 0f859b000000 }
+ $sequence_81 = { a1???????? 83c036 83c9ff f00fc108 }
+ $sequence_82 = { 0f8e2a040000 8a05???????? 4238042b 7521 448bc2 4963ce }
+ $sequence_83 = { e8???????? 488b0d???????? 448be0 f0834156ff 85c0 }
+ $sequence_84 = { 83c036 41 f00fc108 a1???????? 83c01e 50 }
+ $sequence_85 = { 488bf0 eb34 488d0595d6ffff 4885c0 7428 }
+ $sequence_86 = { 6a0a ff15???????? a1???????? 8b4036 }
+ $sequence_87 = { ffb72c080000 e8???????? 5e 5d 5b c3 eb10 }
+ $sequence_88 = { e9???????? 83f916 0f8fa7080000 0f8415080000 }
+ $sequence_89 = { 83c01e 50 ff15???????? 8a06 3a4704 7311 8b0f }
+ $sequence_90 = { 33d2 e8???????? 44892d???????? 33c9 44892d???????? e8???????? 488bcf }
+ $sequence_91 = { 8d4604 66d3e0 66098310170000 8d4103 }
+ $sequence_92 = { 488b0d???????? 4883c12e ff15???????? 4c8b05???????? 448d7b02 }
+ $sequence_93 = { 8b9314170000 83432801 b910000000 8d42f3 2aca }
+ $sequence_94 = { a1???????? 8b4c2404 8908 83c01e 50 ff15???????? }
+ $sequence_95 = { 83a78c00000000 33c0 c3 51 e8???????? }
+ $sequence_96 = { 8b4036 85c0 75ec 8b442404 53 8a1e }
+ $sequence_97 = { 5f 5e 5b c20800 51 53 57 }
+ $sequence_98 = { e9???????? 83e908 74eb 2bcb 0f84fa000000 2bcb }
+ $sequence_99 = { a1???????? 6a00 e8???????? a1???????? 83c01e 50 ff15???????? }
+ $sequence_100 = { c3 33c0 483bc8 7458 488b5128 483bd0 }
+ $sequence_101 = { c9 c20800 55 8bec 81ec1c010000 8d4807 83e1f8 }
+ $sequence_102 = { 5b 8be5 5d c3 0fb708 6683f902 751c }
+ $sequence_103 = { 488bd8 488b05???????? f0834056ff 4885db 0f84ec000000 }
+ $sequence_104 = { ffd7 8b1d???????? 6a3a b8???????? 56 }
+ $sequence_105 = { 48895c2408 57 4883ec30 488bd9 488b0d???????? 488bfa 4883c12e }
+ $sequence_106 = { 488b15???????? 4c8d442468 48c7c101000080 ff15???????? }
+ $sequence_107 = { 83839c000000ff 397818 0f852ffcffff 33c0 }
+ $sequence_108 = { ff35???????? c74424200e440410 c744241c08000000 ffd6 8bf8 }
+ $sequence_109 = { e8???????? 8bf0 83fe0c 74c5 3bf3 0f8581020000 a1???????? }
+ $sequence_110 = { 8b831c70be03 3305???????? 8b3d???????? 50 33f6 56 8bef }
+ $sequence_111 = { c1e804 46 33048d1062be03 85ff }
+ $sequence_112 = { 7470 8b3d???????? 56 c7459c44000000 ffd7 8d45e8 50 }
+ $sequence_113 = { 397dfc 7417 a1???????? 8b55fc 354c4e4c7e 50 }
+ $sequence_114 = { e8???????? 3bc5 89442430 0f84ac010000 53 55 }
+ $sequence_115 = { 3934850875be03 742a 8d41ff 85c0 7c10 3934850875be03 7403 }
+ $sequence_116 = { 8b30 03f5 85f6 89b31c70be03 740a }
+ $sequence_117 = { 68???????? ffd6 a3???????? 33ff 8db7c4260410 }
+ $sequence_118 = { ff75ec 8b3d???????? 8bd8 ffd7 ff75e8 ffd7 eb08 }
condition:
- 7 of them and filesize <229376
+ 7 of them and filesize <802816
}
-rule MALPEDIA_Win_Shakti_Auto : FILE
+rule MALPEDIA_Win_Nautilus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "535cf33d-f06d-5859-b025-0ff160716ffb"
+ id = "bd0f8568-9347-5c4b-aef6-8e7929cf6017"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shakti"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shakti_auto.yar#L1-L172"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nautilus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nautilus_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "6f5489cc7281ed05aa1395fcaba968324612a285b4f1d07b39699fdb3c984697"
+ logic_hash = "6e0983236c8ba852bb2af3aa295c07b825fa6ac12512321743324e3ea59238a7"
score = 75
quality = 75
tags = "FILE"
@@ -130646,40 +137930,34 @@ rule MALPEDIA_Win_Shakti_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945ec 8b4dd4 83c102 894dd4 e9???????? 8b55c0 }
- $sequence_1 = { 0fb711 81fa4d5a0000 752e 8b45c0 8b483c }
- $sequence_2 = { 8b45fc 8b4dd8 0308 894df0 8b55fc }
- $sequence_3 = { 0fb7c2 83f801 753d b9ff0f0000 8b55f0 66230a 0fb7c1 }
- $sequence_4 = { 8b45c0 03423c 8945f8 6a40 }
- $sequence_5 = { 52 6a00 ff55e4 8945d8 8b45f8 8b4854 894de0 }
- $sequence_6 = { 8b45e0 8b0c10 034dc0 baff0f0000 8b45f0 }
- $sequence_7 = { 8b55f8 0355c0 8955f8 8b45f8 }
- $sequence_8 = { 8b742408 85f6 741e 803e00 7512 ff760c e8???????? }
- $sequence_9 = { ff34c5b4a24000 53 57 e8???????? 83c40c 85c0 }
- $sequence_10 = { 50 ff759c ff15???????? 85c0 740d 837d9000 }
- $sequence_11 = { 8bff 55 8bec 8b4508 33c9 3b04cd10a04000 7413 }
- $sequence_12 = { ff15???????? 89459c 83f8ff 7507 32c0 e9???????? 57 }
- $sequence_13 = { bf04010000 57 8d860e080000 50 6a00 }
- $sequence_14 = { 6a08 50 890d???????? ff15???????? }
- $sequence_15 = { 837dd400 a1???????? 7423 c700b8000000 a1???????? }
+ $sequence_0 = { 8bcf e8???????? 8bd8 8bcd e8???????? 85db 8bce }
+ $sequence_1 = { 85c0 740c 488b4598 4833c7 e9???????? c74424200f000000 e9???????? }
+ $sequence_2 = { 8bfe 486313 488d0dcc340600 f6040a02 744b 418d46fa 488bcb }
+ $sequence_3 = { 85c0 7892 488d4c2430 498bd4 e8???????? 85c0 7981 }
+ $sequence_4 = { ba03000000 4d8bc5 8d4aff e8???????? 4c8be0 4885c0 7509 }
+ $sequence_5 = { 85f6 750c 33c0 eb3a 488b0b 49890e eb30 }
+ $sequence_6 = { 85c0 79d6 4c8d45cf 488d55cf 488d4db7 e8???????? 8bd8 }
+ $sequence_7 = { eb07 c745e006000000 488d45e0 41b912000000 4d8bc4 498bd5 488bcf }
+ $sequence_8 = { 4883f803 0f8cef010000 488bd3 488bcd ff95c8010000 85c0 0f8599feffff }
+ $sequence_9 = { e8???????? 85c0 7531 488d4db0 33d2 e8???????? 85c0 }
condition:
- 7 of them and filesize <191488
+ 7 of them and filesize <1302528
}
-rule MALPEDIA_Win_Purplefox_Auto : FILE
+rule MALPEDIA_Win_Tinyfluff_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "864146ba-a135-5d92-a900-c7434a0b6e81"
+ id = "68615fcb-8e02-5dda-b945-ad2728dc7f08"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.purplefox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.purplefox_auto.yar#L1-L376"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinyfluff"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tinyfluff_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "2241b5e41c5930d16a914d761ccbb07709436fc80bf5297a0da02f1f8d89a59e"
+ logic_hash = "7b6f89788f810db3773be969b0bf83c7846502ce63a8bb1297c4bbad49f7e342"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -130691,62 +137969,32 @@ rule MALPEDIA_Win_Purplefox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945ec 8d45f0 50 8d4dd8 8d55f8 51 }
- $sequence_1 = { d2de feca 28c3 80d262 9c }
- $sequence_2 = { 66f7d9 c1e810 52 66c1d908 0f9fc5 }
- $sequence_3 = { 8918 e8???????? 4c8d15a7c70000 4885c0 7404 4c8d5010 8bcb }
- $sequence_4 = { 8d45f8 50 6a00 6a00 c745f800000000 }
- $sequence_5 = { 488b8d08040000 488d442470 4d8b00 4533c9 ba00000100 4889742428 48899c24f0040000 }
- $sequence_6 = { ff15???????? 488bc8 ff15???????? 488d1528460000 488bce }
- $sequence_7 = { 8b04c52cbb4000 5d c3 8bff 55 8bec }
- $sequence_8 = { ffd6 83c410 8d542424 52 8d442410 e8???????? }
- $sequence_9 = { 0f1005???????? f20f100d???????? 4889bc24c8000000 33ff }
- $sequence_10 = { 51 0f9dc3 8b742404 685af85bca 8b7c240c }
- $sequence_11 = { 56 57 68???????? e8???????? 83c404 6a00 6a00 }
- $sequence_12 = { cf b94523340a e8???????? 06 }
- $sequence_13 = { b614 dc1a 7038 1f a5 }
- $sequence_14 = { 415d 415c 5f c3 4889742478 488bb42490000000 }
- $sequence_15 = { 8d4df4 51 52 56 6a00 50 }
- $sequence_16 = { 488b4238 48894108 488b4a50 4885c9 }
- $sequence_17 = { e8???????? 8dbddcfdffff e8???????? 8dbddcfdffff c745fcffffffff }
- $sequence_18 = { 6685c9 75f1 8d85f8fdffff 56 33f6 8d5002 }
- $sequence_19 = { 8944241c 52 8d44241c 50 }
- $sequence_20 = { 4803d8 41b800040000 48899d00040000 e8???????? e9???????? 488b4c2470 ff15???????? }
- $sequence_21 = { 448bcf 4889442420 e8???????? 8bc7 488d4dd0 33d2 }
- $sequence_22 = { 8b703c 66f7da 0fbae603 0fca 20c6 01c6 42 }
- $sequence_23 = { 4883c308 483bdf 72ed 48833d????????00 741f 488d0d36c60000 e8???????? }
- $sequence_24 = { 57 68???????? 68???????? bf00500000 ff15???????? 50 ff15???????? }
- $sequence_25 = { ff15???????? 488d542450 488d0d96b10000 e8???????? }
- $sequence_26 = { 3bf3 7d1e 8b4de8 ff15???????? 8b4df8 51 }
- $sequence_27 = { 52 ffd3 85c0 7507 b802000000 eb1a }
- $sequence_28 = { 9c 368810 c6042413 60 }
- $sequence_29 = { 668b460c 8b5508 6a01 668945e4 }
- $sequence_30 = { 4533c0 33d2 4489b424a0000000 4889442420 }
- $sequence_31 = { a1???????? a3???????? a1???????? c705????????bb454000 8935???????? }
- $sequence_32 = { e8???????? 83c408 33ff eb23 68???????? }
- $sequence_33 = { 4885c0 743f 488b0d???????? 488d1551970000 }
- $sequence_34 = { 8b1d???????? 68???????? 50 ffd3 85c0 750c 8b4f08 }
- $sequence_35 = { c744246800010000 488bf9 4889742460 89742458 89742450 4889742448 }
- $sequence_36 = { 488d0de4d20000 483bd9 723e 488d0568d60000 483bd8 7732 488bd3 }
- $sequence_37 = { 48ffce 75a3 8b4504 03c5 8be8 833800 }
- $sequence_38 = { 897c2404 e8???????? e8???????? 8d64242c 0f850a000000 660fb6d8 }
- $sequence_39 = { 56 57 4883ec50 8bc9 488d942480000000 ff15???????? }
+ $sequence_0 = { 0f84982c0000 c3 833d????????ff 7503 33c0 c3 53 }
+ $sequence_1 = { 8b04bd50704100 03c1 885c302e 46 3bf2 }
+ $sequence_2 = { 83e03f c1f906 6bc038 03048d50704100 }
+ $sequence_3 = { 85c0 7418 8b858cfbffff 85c0 7407 50 }
+ $sequence_4 = { ff15???????? 33f6 e9???????? 8d8de0fbffff 8d5102 668b01 83c102 }
+ $sequence_5 = { 8b049550704100 57 8b7d10 897d98 8955b4 }
+ $sequence_6 = { 83c410 ebe6 8b45f0 8b0c8550704100 8b45f8 807c012800 }
+ $sequence_7 = { 50 6af6 ff15???????? 8b04bd50704100 834c0318ff 33c0 }
+ $sequence_8 = { 56 57 83781408 8bf9 8bf2 897dfc 8bd0 }
+ $sequence_9 = { c1fa06 8934b8 8bc7 83e03f 6bc838 8b049550704100 8b440818 }
condition:
- 7 of them and filesize <1983488
+ 7 of them and filesize <245760
}
-rule MALPEDIA_Win_Cabart_Auto : FILE
+rule MALPEDIA_Win_Webc2_Kt3_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ec8b7b53-684b-5fca-bc08-508467faa1aa"
+ id = "94855d65-b1ce-5b35-9456-d0939a525276"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cabart"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cabart_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_kt3"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_kt3_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "ef91551af86c18985e4a8081f5258aef75a9aeccca976feccaee2997d09b19b6"
+ logic_hash = "a5c2b8d7a42ef74a9adf1d4cae6732c8a660cac1ccf5f008908f03c7dfba3cd1"
score = 75
quality = 75
tags = "FILE"
@@ -130760,32 +138008,32 @@ rule MALPEDIA_Win_Cabart_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8930 8b4510 eb16 395d10 740f }
- $sequence_1 = { 8d8500fcffff 50 ff35???????? be00020000 ff35???????? }
- $sequence_2 = { 3bc3 7620 8d4df0 51 50 }
- $sequence_3 = { 33c0 66898506fcffff 8d8500fcffff 50 ff35???????? be00020000 }
- $sequence_4 = { 8d0c30 3bcf 7732 3bc3 }
- $sequence_5 = { 8d85fcfeffff 68???????? 6804010000 50 ff15???????? 83c410 6a10 }
- $sequence_6 = { 85db 750a 68b90b0000 e8???????? 85ed }
- $sequence_7 = { 3bc7 750a 68ec030000 e9???????? 8bc8 }
- $sequence_8 = { 57 8d45e8 50 6a58 56 }
- $sequence_9 = { ff15???????? 57 8d45f4 50 6a3f 56 c745f40a000000 }
+ $sequence_0 = { 8a92c0c84000 089021d34000 40 3bc7 76f5 41 }
+ $sequence_1 = { ff15???????? 85c0 0f843a010000 83bdf0fbffff00 0f86a4000000 }
+ $sequence_2 = { 836dd001 837dd000 742c 836dd001 }
+ $sequence_3 = { 0345f8 c60000 8b4de8 51 ff15???????? 8b55e8 0fbe02 }
+ $sequence_4 = { 8955a8 66c745c80000 c745cc00000000 66c745ca0000 c745c401010000 8b4508 8945d0 }
+ $sequence_5 = { e8???????? 8945fc 837dfc00 7d05 83c8ff eb25 837dfc00 }
+ $sequence_6 = { 7527 8b55fc 0fbe4202 83f82d 751b }
+ $sequence_7 = { 51 ff15???????? 8945f0 837df000 7511 8b55f8 52 }
+ $sequence_8 = { 8b5508 83c234 83c9ff 33c0 }
+ $sequence_9 = { 8bec 83ec30 53 56 57 8b4508 8945e0 }
condition:
- 7 of them and filesize <32768
+ 7 of them and filesize <114688
}
-rule MALPEDIA_Win_Anatova_Ransom_Auto : FILE
+rule MALPEDIA_Win_Interception_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6cd7c8c4-20c9-5c58-baa7-e42d545001dc"
+ id = "f1a298d5-70e2-5f27-b6ee-691574cd9abf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.anatova_ransom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.anatova_ransom_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.interception"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.interception_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "2867d50f6d60295cd1f6876cf7316363316dea4699194cf318a991da479d380e"
+ logic_hash = "3520af3329a4b24d818d777e1e8f70b92d9cafa69a1f58bf6db64da9ed00530f"
score = 75
quality = 75
tags = "FILE"
@@ -130799,32 +138047,32 @@ rule MALPEDIA_Win_Anatova_Ransom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d05ec570000 48894588 488d05eb570000 48894590 }
- $sequence_1 = { b805000000 4989c3 488b01 4989c2 4c89d1 4c89da e8???????? }
- $sequence_2 = { 4989c2 4c89d1 e8???????? e9???????? 488b45e0 4989c2 4c89d1 }
- $sequence_3 = { e8???????? 488b05???????? 488b0d???????? 488b15???????? 488945f0 488d45fc 4889442420 }
- $sequence_4 = { 4883f800 0f84b2000000 488b05???????? 4883f800 0f84a1000000 488b05???????? }
- $sequence_5 = { 4989c2 4c89d1 e8???????? 488b05???????? 4883f800 0f843e000000 8b05???????? }
- $sequence_6 = { b800000000 4989c3 b802000000 4989c2 4c89d1 4c89da 4c8b1d???????? }
- $sequence_7 = { 4989c0 488b45d8 4989c3 488b45a0 4989c2 4c89d1 4c89da }
- $sequence_8 = { 4989c1 b800000000 4989c0 b800000000 4989c3 }
- $sequence_9 = { 48b80f00000000000000 4989c0 b800000000 4989c3 488d45b1 4989c2 4c89d1 }
+ $sequence_0 = { 83e61f 8d1c8520ae0010 c1e603 8b03 f644300401 7469 57 }
+ $sequence_1 = { 72f1 56 8bf1 c1e603 3b96e8710010 }
+ $sequence_2 = { c1f805 83e61f 8d1c8520ae0010 c1e603 8b03 }
+ $sequence_3 = { ffb6ec710010 8d8560ffffff 50 e8???????? 6810200100 8d8560ffffff }
+ $sequence_4 = { 8bd0 c1f905 83e21f 8b0c8d20ae0010 f644d10401 }
+ $sequence_5 = { 8d3c8520ae0010 c1e603 8b07 03c6 f6400401 7437 }
+ $sequence_6 = { f683c19c001004 7406 8816 46 }
+ $sequence_7 = { 8d542434 f3ab 66ab aa }
+ $sequence_8 = { 8bc8 83e01f c1f905 8b0c8d20ae0010 8a44c104 }
+ $sequence_9 = { 731c 8bc8 83e01f c1f905 8b0c8d20ae0010 f644c10401 8d04c1 }
condition:
- 7 of them and filesize <671744
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Govrat_Auto : FILE
+rule MALPEDIA_Win_Wormhole_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1d47ae50-0c56-5989-81a0-8fdce95f6d20"
+ id = "02cb6b4c-3f82-593d-8995-30894f37de3e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.govrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.govrat_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wormhole"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wormhole_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "fd342f7d8be9492612f2ff02091e469b143bdad77d63d3ee372225f78d66c202"
+ logic_hash = "468c0b29b40a7f8149923ac2555699892601064a2e38020dd68e3cf5b3d71577"
score = 75
quality = 75
tags = "FILE"
@@ -130838,32 +138086,32 @@ rule MALPEDIA_Win_Govrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7725 0fb74002 8d709f 6683fe19 7702 03c2 6685c0 }
- $sequence_1 = { ff37 e8???????? 894620 85c0 7507 b80e000780 5f }
- $sequence_2 = { e8???????? 83ec1c 8bf4 8965b4 }
- $sequence_3 = { e8???????? 6aff 53 8d4db0 51 c645fc06 e8???????? }
- $sequence_4 = { 837dc808 8b75b4 7303 8d75b4 53 51 68???????? }
- $sequence_5 = { 8d7c2428 ab ab 7548 8d442464 50 }
- $sequence_6 = { 0183f0bc0300 8393f4bc030000 e8???????? eb1d 8b45fc 2b45f0 ff75fc }
- $sequence_7 = { 7311 c70485????????e8814300 40 a3???????? c3 55 8bec }
- $sequence_8 = { 83ec18 56 8bf1 8b4610 8955f8 8945f4 83f804 }
- $sequence_9 = { 85f6 7403 832600 837d1000 0f8690000000 8b5d08 }
+ $sequence_0 = { eb1b 3d04000100 752a a1???????? 68???????? 6a06 }
+ $sequence_1 = { 50 56 e8???????? 83c40c 8d4c2408 8d942414010000 }
+ $sequence_2 = { ffd3 6a00 6a00 89442418 8d442428 }
+ $sequence_3 = { e8???????? a1???????? 83c404 50 ff15???????? c705????????00000000 c705????????00000000 }
+ $sequence_4 = { 75f0 a1???????? 85c0 74d5 e8???????? }
+ $sequence_5 = { c705????????01000000 68f4010000 ff15???????? 8b15???????? 52 e8???????? }
+ $sequence_6 = { 85f6 7512 6a04 68???????? 6a28 57 e8???????? }
+ $sequence_7 = { 6a78 6a28 57 50 e8???????? }
+ $sequence_8 = { 8b442404 56 57 8b7c2410 6a78 6a28 }
+ $sequence_9 = { 7564 8b442418 3dff000000 7f59 6a0f }
condition:
- 7 of them and filesize <761856
+ 7 of them and filesize <99576
}
-rule MALPEDIA_Win_Hardrain_Auto : FILE
+rule MALPEDIA_Win_Megumin_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "97910df3-cc32-519a-be42-e878c516a607"
+ id = "992bacc8-d168-5613-b9a1-b270fb7e71d1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hardrain"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hardrain_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.megumin"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.megumin_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "e6beb234b33f52448f8a2b08bdea562633ec321b73d43e884a2e68853ad4b784"
+ logic_hash = "d3f02e69acad5c637179e097455fd85b104ce227d90fce5cb059c87c08c3436c"
score = 75
quality = 75
tags = "FILE"
@@ -130877,34 +138125,34 @@ rule MALPEDIA_Win_Hardrain_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 66c74424380000 f3ab 66ab b981000000 33c0 }
- $sequence_1 = { 51 56 89542414 8944241c e8???????? 83c410 85c0 }
- $sequence_2 = { 8b7c241c 6685ff 7509 5f 83c8ff 5e 83c410 }
- $sequence_3 = { ff15???????? 85c0 7eca 8d442430 }
- $sequence_4 = { 51 8bce e8???????? 85c0 7427 6a14 }
- $sequence_5 = { 68b4000000 52 50 e8???????? }
- $sequence_6 = { 8d842484000000 68???????? 50 e8???????? 8d8c248c000000 6800040000 8d942490040000 }
- $sequence_7 = { 83c418 c3 33c0 33c9 68b4000000 89442408 }
- $sequence_8 = { ff15???????? 8b0e 85c9 7406 8b11 6a01 ff12 }
- $sequence_9 = { 81ec0c010000 8b842414010000 8b942418010000 57 89442404 b942000000 }
+ $sequence_0 = { 8b348510164600 037520 6b45243c 034528 6bc03c 03452c }
+ $sequence_1 = { 8945e8 57 8d4dd8 c745fc00000000 e8???????? 8b45e8 85c0 }
+ $sequence_2 = { 8d45f4 64a300000000 6841010000 8d8528faffff c745fc00000000 6a00 50 }
+ $sequence_3 = { 8d4dd8 8d45c0 50 e8???????? ff37 8d55d7 8d4db0 }
+ $sequence_4 = { c60100 e8???????? 8d4c2430 e8???????? 8bc8 83c418 83791410 }
+ $sequence_5 = { 833d????????00 0f8549870000 8d0d90e74500 ba1d000000 e9???????? 833d????????00 0f852c870000 }
+ $sequence_6 = { 83c404 8d8d14fdffff c645fc1a 51 8bd0 8d8d04fbffff }
+ $sequence_7 = { 0f1f440000 8845eb 8b410c 897da8 8945b0 c645fc02 }
+ $sequence_8 = { 8d4101 8945d8 3dffffff7f 0f8700010000 6a00 6a00 50 }
+ $sequence_9 = { 3bca 763b 8bd1 a81f 7535 8b48fc }
condition:
- 7 of them and filesize <368640
+ 7 of them and filesize <1007616
}
-rule MALPEDIA_Win_Volgmer_Auto : FILE
+rule MALPEDIA_Win_Jripbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6318a069-35e9-5ac9-b46b-f601ef58e4f8"
+ id = "7b1d247f-7cbb-5615-a25c-7a029e86230e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.volgmer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.volgmer_auto.yar#L1-L360"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jripbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jripbot_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "f927338edc5a7e32548016c88c35f08a0b0dddf5ae3c9ab69c63c8695ae3cd83"
+ logic_hash = "e485f4c42ec7ab7e0d2df3f1cd3bb910f7710773a4391061675b3c77a4acf337"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -130916,59 +138164,32 @@ rule MALPEDIA_Win_Volgmer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488b4d40 4833cc e8???????? 4c8d9c2450010000 498b5b18 498b7b20 498be3 }
- $sequence_1 = { 48897c2418 55 488d6c24b0 4881ec50010000 488b05???????? 4833c4 48894540 }
- $sequence_2 = { e8???????? 488b4dc3 41890424 e8???????? }
- $sequence_3 = { d1c6 c1c105 03c6 89742404 03c3 }
- $sequence_4 = { ff15???????? 4885c0 740f 488b4018 488b08 8b01 8905???????? }
- $sequence_5 = { 8b45b0 488d8dc00f0000 4533c9 4889742430 89442428 ba00000080 c744242003000000 }
- $sequence_6 = { e8???????? 488bd8 eb03 488bdf 488d056efeffff }
- $sequence_7 = { 75e9 488d8d90140000 48ffc9 40387101 488d4901 75f6 4c8b45a0 }
- $sequence_8 = { c6843de011000000 488d8de0110000 e8???????? 488b4c2440 488d95e0110000 ff15???????? 0fb63d???????? }
- $sequence_9 = { 488d4d60 41b808040000 8bf8 e8???????? ba32d00200 b940000000 ff55e0 }
- $sequence_10 = { e8???????? 488d8dd2050000 33d2 41b806020000 6689bdd0050000 e8???????? }
- $sequence_11 = { ff15???????? 85c0 7507 b800000100 eb26 }
- $sequence_12 = { e8???????? e8???????? e8???????? e8???????? c705????????04000000 }
- $sequence_13 = { e8???????? 85c0 7466 33d2 488d8c24e4000000 41b804040000 e8???????? }
- $sequence_14 = { 8bd6 c68435000a000000 488d8d000a0000 e8???????? 488d95000a0000 498bce ff15???????? }
- $sequence_15 = { eb17 894638 eb0e c74634047b7300 c7463806000000 }
- $sequence_16 = { 8a07 8b0c9580f16e00 8844192e 8b049580f16e00 804c182d04 }
- $sequence_17 = { 8b4504 8b4d0c 6a00 52 }
- $sequence_18 = { 8b048dd4926d00 ffe0 f7c703000000 7413 8a06 8807 }
- $sequence_19 = { e9???????? c745dc02000000 c745e0e4ba7300 8b4508 8bcf }
- $sequence_20 = { 83c408 85f6 0f84b7010000 8bce 8d85d0fdffff }
- $sequence_21 = { 03048d80f16e00 50 ff15???????? 5d c3 8bff }
- $sequence_22 = { 50 68???????? ff7708 ff95e4f3ffff 817f1400008000 89470c 751c }
- $sequence_23 = { 5f 5e c684101803000000 5b }
- $sequence_24 = { 8a4c2428 8d442428 3acb 741a }
- $sequence_25 = { 40 c745ecb8996d00 894df8 8945fc 64a100000000 8945e8 8d45e8 }
- $sequence_26 = { 50 52 56 6a00 68e9fd0000 ff95e8f3ffff ff7714 }
- $sequence_27 = { 50 51 53 53 6800000008 }
- $sequence_28 = { ff15???????? 8d442408 50 ff15???????? 85c0 5f 740c }
- $sequence_29 = { ba???????? 2bd1 668b0c02 6685c9 }
- $sequence_30 = { c745dc03000000 c745e0e0ba6e00 e9???????? 83e80f 7451 }
- $sequence_31 = { 33d2 05d9e7ffff 56 83f815 0f8711010000 ff2485786b6d00 51 }
- $sequence_32 = { 8a01 41 84c0 75f9 6a00 2bca 8d85d0f5ffff }
- $sequence_33 = { 8d0d90b87300 ba1b000000 e9???????? a900000080 7517 ebd4 a9ffff0f00 }
- $sequence_34 = { e9???????? 894ddc c745e0d8ba6e00 e9???????? c745e0d4ba6e00 eba2 894ddc }
- $sequence_35 = { 8b4de8 8b048580f16e00 f644082840 7409 }
- $sequence_36 = { 396c2434 750b 396c2430 7505 }
+ $sequence_0 = { 48 3b442418 0f822bffffff 8b8c24fc010000 5f 5e 5b }
+ $sequence_1 = { c1e807 8807 02d2 885701 66c7060100 33c9 837b0401 }
+ $sequence_2 = { 8b5d08 c1eb08 23d8 0fb69b38834200 c1e608 33f3 8b5d0c }
+ $sequence_3 = { 8d742414 e8???????? 59 59 eb06 895c240c 33c0 }
+ $sequence_4 = { 33c0 8b8eb8000000 3bc7 0f95c0 6a02 884105 33db }
+ $sequence_5 = { 51 50 56 56 ff750c ff75fc ffd7 }
+ $sequence_6 = { 50 e8???????? 8b1d???????? 83c40c 8d442438 50 ff15???????? }
+ $sequence_7 = { 8b4004 894604 33c0 8b8c242c010000 5f 5e 5b }
+ $sequence_8 = { eb04 8b442430 8b4c241c 2b4c2418 ff742418 8b5c2438 }
+ $sequence_9 = { 7443 3bf8 743f 8b4368 397008 7537 8b4df4 }
condition:
- 7 of them and filesize <393216
+ 7 of them and filesize <507904
}
-rule MALPEDIA_Win_Mm_Core_Auto : FILE
+rule MALPEDIA_Win_Bs2005_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d45aa5c3-0724-55a7-87e0-2c03f652362f"
+ id = "ef8c48f9-bc67-59c3-a57f-caa042b605de"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mm_core"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mm_core_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bs2005"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bs2005_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "3ca1e6eabacd07d91480b5599e1196a1b257af6133657fffc185261c4367958e"
+ logic_hash = "31d800fc437e882f8e75451d429896908d917d51b135f51d420139339a52e53c"
score = 75
quality = 75
tags = "FILE"
@@ -130982,32 +138203,32 @@ rule MALPEDIA_Win_Mm_Core_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7458 57 8b7c240c 85ff 744e 6a40 6800300000 }
- $sequence_1 = { c1f805 8bf7 83e61f c1e606 03348540400110 c745e401000000 }
- $sequence_2 = { 8b45fc ff34c5e41c0110 53 57 e8???????? 83c40c 85c0 }
- $sequence_3 = { 85f6 0f848d000000 8b0e 85c9 7442 8b5608 }
- $sequence_4 = { 8b442424 8b4c242c 8938 8931 }
- $sequence_5 = { 8955d4 8b45d4 8b4814 894ddc }
- $sequence_6 = { 8d4c244c 51 55 55 68???????? 68???????? }
- $sequence_7 = { 57 52 89842480000000 898c2484000000 89bc2488000000 e8???????? 83c40c }
- $sequence_8 = { e8???????? bb???????? 8d742434 e8???????? 8d9c24a8050000 8d742428 e8???????? }
- $sequence_9 = { 8b4dc4 0fb611 0355fc 8955fc 8b45c4 }
+ $sequence_0 = { ff15???????? 85c0 0f845f030000 8b500c }
+ $sequence_1 = { 7505 b83f000000 8d5abf 83c9ff 80fb19 771c 0fbeca }
+ $sequence_2 = { 51 50 8b02 83c041 50 e8???????? 8b974c060000 }
+ $sequence_3 = { 8b02 8a9049000400 8b8f54060000 889111010000 }
+ $sequence_4 = { 51 c645c800 e8???????? 83c40c b9???????? 8d8324010000 8da42400000000 }
+ $sequence_5 = { eb09 3c2f 7505 b93f000000 8d5abf 83c8ff 80fb19 }
+ $sequence_6 = { 50 8d9500ffffff 52 68???????? e8???????? 6804010000 6a00 }
+ $sequence_7 = { ffd6 33c0 68???????? 8d4dec 68???????? 51 8945ec }
+ $sequence_8 = { 8945f8 3b45f0 7cea 8b4510 }
+ $sequence_9 = { 8d419f 3c19 7708 0fbef1 83ee47 eb25 }
condition:
- 7 of them and filesize <319488
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Nimplant_Auto : FILE
+rule MALPEDIA_Win_Absentloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c6b47fc0-6c54-5733-accf-0312881d8593"
+ id = "9aab04f2-7678-5cf8-8d74-f6db3f7fcf22"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nimplant"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nimplant_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.absentloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.absentloader_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "1d2dbc7055590af657485c9c8d5afa6cd108c9897c8a3274dd24779cb78842a6"
+ logic_hash = "77496690e6eb66a44354cd3e27ded72ee59f2468546d53e2a80ae68b108dd0bf"
score = 75
quality = 75
tags = "FILE"
@@ -131021,32 +138242,32 @@ rule MALPEDIA_Win_Nimplant_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4c89e9 0f11642440 e8???????? 803b00 0f8515ffffff 488b4c2468 4885c9 }
- $sequence_1 = { 894c2430 4889ac24b0000000 e9???????? 4981ffff7f0000 4c89f2 488b4b08 490f4ed7 }
- $sequence_2 = { 488d051e3a0800 48895110 48894120 48c741183a000000 48c7410800000000 48c7442420a1060000 e8???????? }
- $sequence_3 = { e8???????? 488b442440 488b542448 44886c0208 4883c001 0f8093040000 488b542448 }
- $sequence_4 = { e8???????? 4c8b442430 48ba0000000000000040 4889f1 4c01e9 0f80b1000000 4885c9 }
- $sequence_5 = { f30f6f25???????? 4889ea 41b8a94d975e 4c89e9 4c899c2408010000 4c89942400010000 0f11a42410010000 }
- $sequence_6 = { 488b9424f0000000 4889d1 4883e904 0f80de0f0000 4839ca 0f8e58100000 4885c9 }
- $sequence_7 = { e8???????? 803b00 488b942488000000 488b842480000000 0f8599feffff 4c8b4e58 4c89f1 }
- $sequence_8 = { 80f90b 0f873b1a0000 0fb6f2 83ee01 4863f6 4883c60c 48c1e604 }
- $sequence_9 = { 4889eb 48897c2440 488b7c2438 4889c5 4c89ee 4c897c2460 }
+ $sequence_0 = { fe81b89406fd 89148d909406fd 8d4dfc e8???????? 5e c9 c3 }
+ $sequence_1 = { eb16 66c704375c6e eb0e 66c704375c74 eb06 66c704375c62 83c602 }
+ $sequence_2 = { e8???????? c645fc12 8bcb 0f2805???????? 0f1145b4 6a7f }
+ $sequence_3 = { 740f 33c0 80b034a606fd2e 40 83f814 72f3 8b0d???????? }
+ $sequence_4 = { 8bec 56 ff7508 8bf1 e8???????? c706841e05fd }
+ $sequence_5 = { 7408 3a8ac05d05fd 755a 8b06 8a08 40 42 }
+ $sequence_6 = { 7e37 68f8aa06fd e8???????? 833d????????ff 59 7523 bffcaa06fd }
+ $sequence_7 = { 7417 6827130000 6830f405fd 68341606fd e8???????? 83c40c 837f2c00 }
+ $sequence_8 = { c9 c3 6a08 b8a30305fd e8???????? 8bf1 8975ec }
+ $sequence_9 = { 84db 743b 8b4608 8378fc00 7432 83ec10 8d4668 }
condition:
- 7 of them and filesize <1811456
+ 7 of them and filesize <794624
}
-rule MALPEDIA_Win_Kimjongrat_Auto : FILE
+rule MALPEDIA_Win_Hlux_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "db4baf64-c410-5dd4-86f2-fb3657762c91"
+ id = "0554b2ef-0799-5994-8001-d3a987727985"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kimjongrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kimjongrat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hlux"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hlux_auto.yar#L1-L158"
license_url = "N/A"
- logic_hash = "515b099b5f4271a4a56e7e428e24670deb74340ff8bb9a2bab6a20ed3f485ca9"
+ logic_hash = "53ff7358e541a46f4d140f6dc71959f0fd15f8b04731bebe36051fa435d4979d"
score = 75
quality = 75
tags = "FILE"
@@ -131060,34 +138281,40 @@ rule MALPEDIA_Win_Kimjongrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? c6840db4edffff2a e9???????? c6840db4edffff26 e9???????? c6840db4edffff5b eb6c }
- $sequence_1 = { e8???????? 8bd8 83c414 85db 0f8508010000 33c9 894de4 }
- $sequence_2 = { ff7004 8d4108 50 e8???????? 8b5508 8b4840 894a20 }
- $sequence_3 = { ff7508 e8???????? 6a01 57 6a4c 56 e8???????? }
- $sequence_4 = { e9???????? 8b4c8f58 894dd0 898d60ffffff 8b55a4 b860240000 66854208 }
- $sequence_5 = { c68540d0ffff00 e8???????? 83c40c ba???????? 33c9 8a02 42 }
- $sequence_6 = { e9???????? c6840da0e8ffff77 e9???????? c6840da0e8ffff76 e9???????? c6840da0e8ffff65 e9???????? }
- $sequence_7 = { ff30 e8???????? 8b450c 83c404 c70000000000 8b55f8 c645f000 }
- $sequence_8 = { e9???????? c6840dccf3ffff2d e9???????? c6840dccf3ffff7d e9???????? c6840dccf3ffff29 e9???????? }
- $sequence_9 = { 8bf8 83c404 897dac 85ff 0f8418f3ffff b800400000 66854608 }
+ $sequence_0 = { 81f949e2a499 750b 83f90e 7406 }
+ $sequence_1 = { 0101 c9 c3 6a10 }
+ $sequence_2 = { 0009 1b4e01 e405 9d }
+ $sequence_3 = { 0088aa4b0023 d18a0688078a 46 018847018a46 }
+ $sequence_4 = { 0130 8b13 8b08 85d2 }
+ $sequence_5 = { b8e3062de4 09c0 7506 898550ffffff 8b8550ffffff ba205af5bb }
+ $sequence_6 = { 7545 8945fc 8b45f0 895de8 81f97a701028 7534 }
+ $sequence_7 = { 0104b9 33c9 83c408 85c0 }
+ $sequence_8 = { 010f 840f 0000 008365f0fe8b }
+ $sequence_9 = { 8b0d???????? 85c9 753f 83f963 753a 8945fc 83f93f }
+ $sequence_10 = { 0104bb 8d1447 89542418 e9???????? }
+ $sequence_11 = { 895de8 33f6 8955cc 83fe13 7503 8975fc 5e }
+ $sequence_12 = { 0000 008365f0fe8b 4d 0883c108e918 }
+ $sequence_13 = { 8945e0 83f9f3 7507 09c9 7403 }
+ $sequence_14 = { 81fb2e5ca766 7503 895de8 8945d4 }
+ $sequence_15 = { 83fbd5 7413 33c0 83f827 7403 }
condition:
- 7 of them and filesize <1572864
+ 7 of them and filesize <3147776
}
-rule MALPEDIA_Win_Chir_Auto : FILE
+rule MALPEDIA_Win_Keyboy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "18ccfa9f-30e1-5e52-b265-5cee479b1cb5"
+ id = "1db1fbfb-59c2-5bfb-976b-a0743f8a46eb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chir"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chir_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.keyboy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.keyboy_auto.yar#L1-L207"
license_url = "N/A"
- logic_hash = "3243cfbae6092a474cd7d4359f5703dd14295b3f14d9c12875310667b98d1cdf"
+ logic_hash = "c0d23ea688bcee5d6eecf54208ea66cac91415e69b2f38d43039891e2137c619"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -131099,32 +138326,44 @@ rule MALPEDIA_Win_Chir_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 47 8811 3bf8 72e7 }
- $sequence_1 = { 8d4c3df0 8a11 80f2fc 80c202 }
- $sequence_2 = { e8???????? 48 59 8bcb 7419 }
- $sequence_3 = { 5e 7419 8d4c35f8 8a11 80f2fc }
- $sequence_4 = { 8d45f0 50 c745f021352432 c745f451173300 e8???????? 48 }
- $sequence_5 = { c745f451173300 e8???????? 48 59 8bfb }
- $sequence_6 = { 8d4c35f0 8a11 80f2fc 80c202 80f201 }
- $sequence_7 = { 8a19 80f3fc 80c302 80f301 80c303 42 }
- $sequence_8 = { 7415 8d4c15f8 8a01 34fc }
- $sequence_9 = { 8a11 80f2fc 80c202 80f201 80c203 46 8811 }
+ $sequence_0 = { 6a00 8945f2 8d45f8 50 6a0e }
+ $sequence_1 = { 51 ff75d8 6a00 ff75c0 }
+ $sequence_2 = { c705????????d468bcb5 c705????????2086e659 c705????????eec45abf c705????????bbee2bd1 c705????????3e20f129 }
+ $sequence_3 = { c705????????890e9944 c705????????dbd99823 c705????????d468bcb5 c705????????2086e659 }
+ $sequence_4 = { 5d c3 3b0d???????? f27502 f2c3 f2e953030000 55 }
+ $sequence_5 = { c705????????0caa6c89 c705????????a856701f c705????????597e743c c705????????0a9769e0 c705????????c4b85363 c705????????3abf261f c705????????890e9944 }
+ $sequence_6 = { 57 68cc020000 8d852cfdffff 8bf2 6a00 50 89b528fdffff }
+ $sequence_7 = { ff75dc ff15???????? 8d45dc 50 }
+ $sequence_8 = { e9???????? bbfeffffff eb05 bbfdffffff }
+ $sequence_9 = { 24a0 3ca0 7518 b800080000 }
+ $sequence_10 = { 6683f806 7404 32c9 eb02 b101 }
+ $sequence_11 = { c705????????34fbfb41 c705????????e6cd2b66 c705????????79e66d38 c705????????ba66ea37 c705????????1671e665 c705????????f3106cb3 c705????????526c1ed0 }
+ $sequence_12 = { e8???????? 85c0 755e 83ff20 }
+ $sequence_13 = { 2408 f6d8 1ac0 24dd }
+ $sequence_14 = { 41 84c0 75f0 8d55ec c745ec5c417070 }
+ $sequence_15 = { 7cd6 5f 5e 8be5 }
+ $sequence_16 = { ff15???????? 8b15???????? 8b4dc0 8945b8 e8???????? }
+ $sequence_17 = { 7207 b901000000 eb0f 3cfe }
+ $sequence_18 = { f7d9 85db 0f44c2 23c8 }
+ $sequence_19 = { 85d2 7e2a 8bce 81e107000080 }
+ $sequence_20 = { 3401 0fbec0 0fafc8 80f185 880c3e 46 }
+ $sequence_21 = { 1ac0 24dd 88474e e8???????? }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <2170880
}
-rule MALPEDIA_Win_Sinowal_Auto : FILE
+rule MALPEDIA_Win_Owlproxy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "31384acf-e07e-5abe-adce-b44a77e374ec"
+ id = "9642ab2d-7dc5-58a6-b1f9-20da6d2b2d38"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sinowal"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sinowal_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.owlproxy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.owlproxy_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "42d79ca235acd4d3a743286e206901b01ddea7a50a0ec3cebf0e0027f96ae13f"
+ logic_hash = "8f3ab8fd440290f6fe4f2136a06c496cf082fcb282138fdbc332de45a924ef6b"
score = 75
quality = 75
tags = "FILE"
@@ -131138,32 +138377,32 @@ rule MALPEDIA_Win_Sinowal_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d95bcfdffff 52 e8???????? 83c40c c745f000000000 }
- $sequence_1 = { 8b450c 8b4d08 8d5401ff 8955fc eb12 8b4508 83c001 }
- $sequence_2 = { c745f400000000 c745f800000000 8b4510 8945fc 8b4510 33d2 b908000000 }
- $sequence_3 = { 6a00 8b45f8 50 ff15???????? 8b45f4 }
- $sequence_4 = { 8b0495d0669600 2500000080 8b4df8 8b148dd4669600 81e2ffffff7f 0bc2 }
- $sequence_5 = { 8945d8 c745e400000000 c745fc00000000 68???????? }
- $sequence_6 = { 837d0800 7406 837d0c00 7502 eb64 8b450c }
- $sequence_7 = { 89048dd0669600 8b55fc 8b45fc 8b0c85d0669600 890c95d0669600 8b55fc }
- $sequence_8 = { 890d???????? c705????????00000000 a1???????? 8b0c85d0669600 894dfc }
- $sequence_9 = { c745f400000000 c745f800000000 c745fc00000000 837d0800 7416 837d0c00 7410 }
+ $sequence_0 = { 488d942450010000 488d8c2430010000 e8???????? 90 4c8d842430010000 4883bc244801000008 4c0f43842430010000 }
+ $sequence_1 = { 488bcb 488905???????? ff15???????? 488d151b580100 483305???????? 488bcb 488905???????? }
+ $sequence_2 = { 4889442428 488d442450 4533c0 488bcf 664489a588010000 4889442420 ff15???????? }
+ $sequence_3 = { 488d4c2440 e8???????? eb27 49c747180f000000 49c7471000000000 41c60700 4533c0 }
+ $sequence_4 = { e8???????? 448bc0 488bd3 488bce e8???????? 84c0 7406 }
+ $sequence_5 = { e8???????? 90 488b4527 4c8b4d0f 6690 48837de700 740a }
+ $sequence_6 = { 4c8bc6 498bd7 488d0c28 e8???????? 4c8b4708 488b542478 }
+ $sequence_7 = { f6c101 7527 458bc6 488d156ee10000 663b1a }
+ $sequence_8 = { 4889442428 488d054eff0100 4889442440 488b442468 48634804 488d0581fe0100 4889440c68 }
+ $sequence_9 = { 89442420 4c8bce 4533c0 488b5610 488b4da8 ff15???????? 85c0 }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <475136
}
-rule MALPEDIA_Win_Dtrack_Auto : FILE
+rule MALPEDIA_Win_Blackpos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a233c383-e1c0-5a80-b962-04f71174b55f"
+ id = "52663687-3a52-5b88-8f0a-e8064cfb2262"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dtrack"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dtrack_auto.yar#L1-L160"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackpos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackpos_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "da8244413760aff3fc60e26778e79f2591abffda2d0aa55a6f2fe1a5cc4b0aa3"
+ logic_hash = "8568ffc0a3f0ef5ce5cdc7a729339af7d16e27d116b4f347ef077609e2cc96da"
score = 75
quality = 75
tags = "FILE"
@@ -131177,37 +138416,32 @@ rule MALPEDIA_Win_Dtrack_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 8b4508 50 e8???????? 83c414 8b4d10 51 }
- $sequence_1 = { ff15???????? 8d85dcfdffff 50 6a01 }
- $sequence_2 = { 8955f0 8b45f0 0fb68899010000 51 8b55f0 }
- $sequence_3 = { 8d85ecfeffff 50 8d8dc8fdffff 51 8d95ccfdffff }
- $sequence_4 = { 0345f4 8810 ebac e9???????? 8be5 }
- $sequence_5 = { 52 8d8590f5ffff 50 ff15???????? c685a0f8ffff00 6803010000 6a00 }
- $sequence_6 = { c685b8fbffff00 6803010000 6a00 8d8db9fbffff 51 e8???????? }
- $sequence_7 = { 51 e8???????? 83c410 8b558c 52 }
- $sequence_8 = { 8b8520f5ffff 8a4801 888d1ff5ffff 838520f5ffff01 }
- $sequence_9 = { d1e9 894df8 8b5518 8955fc c745f000000000 eb09 }
- $sequence_10 = { 8b45fc c1e808 8b4dfc c1e910 }
- $sequence_11 = { c1e810 23c8 33d1 8855f7 8b4df8 c1e908 8b55fc }
- $sequence_12 = { 894d14 8b45f8 c1e018 8b4dfc }
- $sequence_13 = { 6867452301 8b4d10 51 8b55f4 52 }
- $sequence_14 = { eb64 8b4d10 51 6a00 8b55f4 52 e8???????? }
+ $sequence_0 = { e9???????? b800000200 3bf8 7602 8bf8 8d85f4fffdff }
+ $sequence_1 = { 3bca 7408 47 83ff44 72ef eb08 }
+ $sequence_2 = { 83c414 85c0 7433 e8???????? 85c0 }
+ $sequence_3 = { 8d4dbc 51 03c6 50 e8???????? }
+ $sequence_4 = { 3bfb 0f84f8000000 68ff030000 8d85fdfbffff 53 50 }
+ $sequence_5 = { f7f9 8b4dfc 5f 5e 5b 8bc2 }
+ $sequence_6 = { 8b8040f84100 3bf0 7e44 83ee07 eb3f 2503000080 7905 }
+ $sequence_7 = { 3bf7 7513 8d45e0 50 e8???????? 59 }
+ $sequence_8 = { 6a07 59 6804010000 be???????? }
+ $sequence_9 = { e8???????? 83c40c 85c0 7414 6a01 68???????? }
condition:
- 7 of them and filesize <1736704
+ 7 of them and filesize <3293184
}
-rule MALPEDIA_Win_Petya_Auto : FILE
+rule MALPEDIA_Win_Havex_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d9a77562-a232-5aff-a461-f3720889bdae"
+ id = "cb4848d9-dd93-5427-b320-640a482386ab"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.petya"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.petya_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.havex_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.havex_rat_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "e514cd58bfcd6e8ef482bd5780bb94df60b153546d27b2b89cfad52214dcb51a"
+ logic_hash = "fa73eedcf8aaa6cbc56ae3cdeefa1daf5290fc7704b83fa7deffe1125fde8d25"
score = 75
quality = 75
tags = "FILE"
@@ -131221,32 +138455,32 @@ rule MALPEDIA_Win_Petya_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a03 6800001080 51 ff15???????? 83f8ff }
- $sequence_1 = { 57 33ff 3b750c 0f47d9 85db 7410 8b06 }
- $sequence_2 = { 0f42f2 6a04 56 e8???????? 8bd8 }
- $sequence_3 = { 8bc6 8bca c1e303 0facc110 897c2424 c1e810 }
- $sequence_4 = { 8d4e1c e8???????? 8d4e28 e8???????? 8d4e4c e8???????? 837e7400 }
- $sequence_5 = { 83e804 4e 75f5 46 3bf2 53 }
- $sequence_6 = { 8b4e74 03cb e8???????? 47 83c324 3b7e78 72ed }
- $sequence_7 = { 85db 7410 8b06 85c0 7402 ffd0 }
- $sequence_8 = { 0fa4df03 c1e818 884c242c 8bc6 }
- $sequence_9 = { 8d4e04 e8???????? 8d4e10 e8???????? 8d4e1c }
+ $sequence_0 = { 134304 8937 ebd8 8917 c74704ffffff7f 8bc7 5e }
+ $sequence_1 = { 0fb7c0 b9ffff0000 663bc8 7576 834dec04 33f6 3975ec }
+ $sequence_2 = { e8???????? 8bcf c745dcac230510 e8???????? e8???????? c20400 6a30 }
+ $sequence_3 = { 297d78 c78580000000feffffff 29bd80000000 8d4417ff 660fb67801 66c1e908 66c1e708 }
+ $sequence_4 = { 56 8d8550feffff e8???????? ff757c 8d8550feffff ff7574 }
+ $sequence_5 = { 8b7d08 59 59 3bc3 7404 8938 eb02 }
+ $sequence_6 = { 84c0 0f854bffffff 33f6 e9???????? 8bb5c8fdffff e9???????? 55 }
+ $sequence_7 = { 740a 6683f85c 0f858e000000 83c8ff 5f 5e 5b }
+ $sequence_8 = { 68???????? 8d4c2414 e8???????? 8d442410 50 8d4c2430 897c2464 }
+ $sequence_9 = { 5b c9 c3 55 8bec 8b4614 83ec10 }
condition:
- 7 of them and filesize <229376
+ 7 of them and filesize <892928
}
-rule MALPEDIA_Win_Graphite_Auto : FILE
+rule MALPEDIA_Win_Webc2_Yahoo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "22d6771d-6e02-5bad-92aa-7abf2f0540bc"
+ id = "63230a4f-7913-5b93-bb9a-30d89db03d73"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphite"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graphite_auto.yar#L1-L109"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_yahoo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_yahoo_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "fac8314c02add0a1a3fcfc7bc6cd359f12eb58a8246911250bf475b51a803e3f"
+ logic_hash = "f89dfba6353885aa09b69faf5df0db1655d3acae8a14a8bbfd9acb6fd6fd17df"
score = 75
quality = 75
tags = "FILE"
@@ -131260,32 +138494,32 @@ rule MALPEDIA_Win_Graphite_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7513 33d2 e8???????? 84c0 }
- $sequence_1 = { 33d2 e8???????? 84c0 74e4 }
- $sequence_2 = { 81e2ff030000 81e1bf030000 83c940 c1e10a }
- $sequence_3 = { 7513 33d2 e8???????? 84c0 74e4 }
- $sequence_4 = { 81e1bf030000 83c940 c1e10a 0bca }
- $sequence_5 = { ff15???????? 33c0 eb05 b801010000 }
- $sequence_6 = { 85db 7513 33d2 e8???????? 84c0 74e4 }
- $sequence_7 = { 85db 7513 33d2 e8???????? 84c0 }
- $sequence_8 = { 85db 7513 33d2 e8???????? }
- $sequence_9 = { 81e2ff030000 81e1bf030000 83c940 c1e10a 0bca }
+ $sequence_0 = { 59 7513 ff15???????? 8986a0841e00 }
+ $sequence_1 = { 56 ff15???????? 802000 56 e8???????? }
+ $sequence_2 = { 53 50 50 53 ff750c ff15???????? 57 }
+ $sequence_3 = { 39be9c841e00 59 7513 ff15???????? 8986a0841e00 33c0 }
+ $sequence_4 = { c745fc01000000 aa e8???????? 59 8d85f4d7ffff 50 8d45f8 }
+ $sequence_5 = { 50 8d45f8 50 8d85f4afffff }
+ $sequence_6 = { 8b7518 83c414 8d85fcd7ffff 8bcb }
+ $sequence_7 = { 8b4d08 e8???????? 85c0 53 }
+ $sequence_8 = { 59 50 ff75f8 ff75fc ffb69c841e00 ff15???????? }
+ $sequence_9 = { 8d85c8fcffff 68???????? 50 e8???????? 83c410 85c0 7466 }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <8060928
}
-rule MALPEDIA_Win_Avrecon_Auto : FILE
+rule MALPEDIA_Win_Sphijacker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "554ca169-95af-5a89-9a56-ddcba6897449"
+ id = "02bebd5c-3234-51fc-b1c7-c2b759df0e10"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avrecon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avrecon_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sphijacker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sphijacker_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "9c9411fb28d3d6162f9e1c850b8f8c9dc5dad1f470c391d983f628f3870dd7ec"
+ logic_hash = "b2eaf40d7ebf7c9c6d61e8db2a040734266a57e7998ddc628afd90d30231d5ef"
score = 75
quality = 75
tags = "FILE"
@@ -131299,32 +138533,32 @@ rule MALPEDIA_Win_Avrecon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 56 e8???????? 85c0 0f8577020000 8d8584fbffff 50 56 }
- $sequence_1 = { 89b5f0fdffff 899decfdffff 89b5f4feffff 899df0feffff ff15???????? 8945fc }
- $sequence_2 = { 56 47 e8???????? 0fb7f0 663bf3 0f869b030000 }
- $sequence_3 = { e8???????? 53 ff15???????? 8b35???????? 8d4554 50 0fb705???????? }
- $sequence_4 = { e8???????? 83c410 5e c3 55 8bec 81ec04010000 }
- $sequence_5 = { 50 6880000000 57 ff7508 ffd6 6a04 8d45f8 }
- $sequence_6 = { 49 7524 50 a3???????? ff15???????? e8???????? }
- $sequence_7 = { e8???????? 56 6a08 8d45d8 50 ff7508 c645d800 }
- $sequence_8 = { 56 8bf8 ff15???????? 668bc7 5f 5e }
- $sequence_9 = { 50 8d85c0f7ffff 50 e8???????? 8d85a8f7ffff 50 894534 }
+ $sequence_0 = { 488b0d???????? 488d1d19080200 483bcb 740c }
+ $sequence_1 = { 8b7808 e9???????? 488b55c8 4c8d05cbb10100 }
+ $sequence_2 = { 4c8d056b740100 83e23f 488bcf 48c1f906 488d14d2 498b0cc8 8064d138fd }
+ $sequence_3 = { 7c68 488b4718 488b08 420fb70451 2500800000 7455 488b8360040000 }
+ $sequence_4 = { 488bd1 488bc1 48c1f806 4c8d05e4bd0100 83e23f 488d14d2 498b04c0 }
+ $sequence_5 = { 33d2 f20f100d???????? 41b8ee010000 66898dc8070000 }
+ $sequence_6 = { e8???????? 448ba560010000 8b4c2440 488d15d9e8feff 2b4c2444 41b826000000 894c2440 }
+ $sequence_7 = { c744242804000000 488d1585e10100 41b904000000 4889442420 4533c0 c7451088888888 ff15???????? }
+ $sequence_8 = { ff15???????? 488b4d18 4c8d4520 488d159ee00100 ff15???????? 488b4d20 }
+ $sequence_9 = { 8b4814 c1e90c 4184cd 740e 488b8360040000 4883780800 7419 }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <808960
}
-rule MALPEDIA_Win_Bistromath_Auto : FILE
+rule MALPEDIA_Win_Asprox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "62a1b548-25a5-5273-be8b-9848556649f4"
+ id = "828c56dd-0390-5296-8de7-1a48d10f0f57"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bistromath"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bistromath_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.asprox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.asprox_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "b9314d0c2625ba0e21f5bfba175e042ed0e577dd2d934e440857096b6f3294e9"
+ logic_hash = "3b610e4cac05eeb099f6aceb2af12383510de1c04c209adb95ec16fa7dbc09d7"
score = 75
quality = 75
tags = "FILE"
@@ -131338,34 +138572,34 @@ rule MALPEDIA_Win_Bistromath_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 85c0 741d 0f57c0 0f1100 0f114010 660fd64020 }
- $sequence_1 = { ff75f0 56 e8???????? 8b45f8 83c40c c6040600 8bce }
- $sequence_2 = { eb24 8d5001 e8???????? 8bf0 85f6 7416 ff75fc }
- $sequence_3 = { e8???????? 8b4580 46 3bf0 7ce8 33f6 85db }
- $sequence_4 = { e8???????? 8b4c2410 8901 83c718 8b442424 83c104 894c2410 }
- $sequence_5 = { 8b45e8 85c0 0f84bb250000 ff474c 8d535f 8b7f4c 8bce }
- $sequence_6 = { e8???????? 8945e4 85c0 0f84e1010000 ff75f0 33d2 8bcb }
- $sequence_7 = { ff75fc e8???????? 8bf0 83c404 85f6 7418 8d45fc }
- $sequence_8 = { 8b4df8 e8???????? 8b5324 8b4df8 e8???????? 6a30 6a00 }
- $sequence_9 = { 83c404 46 8d7efe 83fe02 7304 33d2 eb2e }
+ $sequence_0 = { 85c0 740f 6a00 ff15???????? 50 ff15???????? ff15???????? }
+ $sequence_1 = { ff15???????? 6a00 6a00 8b5518 52 8b45c4 }
+ $sequence_2 = { 898558ffffff 8b8560ffffff 898570ffffff 8b4ddc 898d30ffffff c78534ffffff00000000 }
+ $sequence_3 = { 0fb655fd 83fa01 0f8503010000 c6859ffeffff00 68???????? ff15???????? 8985a4feffff }
+ $sequence_4 = { ff45fc 83c004 817dfcff000000 7ede 83a34404000000 ba00010000 8d8348040000 }
+ $sequence_5 = { 8d849d20feffff 894dc0 8945b0 8b00 8bcf 2bc8 895dbc }
+ $sequence_6 = { 51 8b952cffffff 52 ff15???????? 898558ffffff 8b8560ffffff 898570ffffff }
+ $sequence_7 = { 57 395d08 0f8498000000 8b750c 3bf3 0f848d000000 8b7d10 }
+ $sequence_8 = { 50 ff15???????? 898558ffffff 8b4dd8 }
+ $sequence_9 = { 8d840a00100000 50 6a00 8b0d???????? 51 ff15???????? 8945fc }
condition:
- 7 of them and filesize <33816576
+ 7 of them and filesize <155648
}
-rule MALPEDIA_Win_Zloader_Auto : FILE
+rule MALPEDIA_Win_Gratem_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "97b40e53-0323-5f57-82eb-14236d63ac31"
+ id = "89f0dee2-28c6-5a10-a3ad-288a448f45ac"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zloader_auto.yar#L1-L384"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gratem"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gratem_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "d615cfd8aec428fea853159c669b5f75c64755d955e56d958f0ce28518a00d78"
+ logic_hash = "b58ab0ade84c3286830362f0f11bfb9519b8733c76dfe4e9cd7ba24746663e50"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -131377,101 +138611,71 @@ rule MALPEDIA_Win_Zloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 6a01 56 ffd0 89f7 89f8 }
- $sequence_1 = { 57 56 83ec0c 8b5d0c 8b7d10 8d75e8 89f1 }
- $sequence_2 = { 55 89e5 56 8b7508 ff36 e8???????? 83c404 }
- $sequence_3 = { 0fb7450c 8d9df0feffff 53 50 ff7508 e8???????? }
- $sequence_4 = { 57 56 8b7d08 57 e8???????? }
- $sequence_5 = { 0fb7c0 57 50 53 e8???????? 83c40c 89f1 }
- $sequence_6 = { 53 56 83ec0c 8d75ec 56 6aff }
- $sequence_7 = { 55 89e5 56 8b750c ff7508 e8???????? 83c404 }
- $sequence_8 = { 56 50 a1???????? 89c1 }
- $sequence_9 = { 5e 8bc3 5b c3 8b44240c }
- $sequence_10 = { 68???????? ff742408 e8???????? 59 59 84c0 741e }
- $sequence_11 = { e8???????? 59 84c0 7432 68???????? ff742408 e8???????? }
- $sequence_12 = { 57 56 50 8b4510 31db }
- $sequence_13 = { e8???????? 03c0 6689442438 8b442438 }
- $sequence_14 = { 6aff 50 e8???????? 8d857cffffff 50 }
- $sequence_15 = { 50 89542444 e8???????? 03c0 }
- $sequence_16 = { 6689442438 8b442438 83c002 668944243a }
- $sequence_17 = { 83c414 c3 56 ff742410 }
- $sequence_18 = { 99 52 50 8d44243c 99 52 50 }
- $sequence_19 = { c6043000 5e c3 56 57 8b7c2414 83ffff }
- $sequence_20 = { 50 56 56 56 ff7514 }
- $sequence_21 = { 83c408 5e 5d c3 55 89e5 57 }
- $sequence_22 = { 6a00 e8???????? 83c414 c3 8b542404 }
- $sequence_23 = { c7462401000000 c7462800004001 e8???????? 89460c }
- $sequence_24 = { 81c4a8020000 5e 5f 5b }
- $sequence_25 = { 55 89e5 53 57 56 81eca8020000 }
- $sequence_26 = { e9???????? 31c0 83c40c 5e 5f }
- $sequence_27 = { 0bc3 a3???????? e8???????? 8bc8 eb06 8b0d???????? 85c9 }
- $sequence_28 = { 89b42430010000 8b842430010000 8b842430010000 890424 c74424041c010000 e8???????? }
- $sequence_29 = { 89cf 8d0476 8945ec 890424 }
- $sequence_30 = { 50 6a72 e8???????? 59 }
- $sequence_31 = { 56 57 ff750c 33db 68???????? 6880000000 50 }
- $sequence_32 = { 8bc2 ebf7 8d442410 50 ff742410 ff742410 ff742410 }
- $sequence_33 = { 56 68???????? ff742410 e8???????? 6823af2930 56 ff742410 }
- $sequence_34 = { 50 e8???????? 68???????? 56 e8???????? 8bf0 59 }
- $sequence_35 = { 5f 5e 5b c3 8bc2 ebf8 53 }
- $sequence_36 = { 33f6 e8???????? ff7508 8d85f0fdffff 68???????? }
- $sequence_37 = { 68???????? 56 e8???????? 5e c3 56 }
- $sequence_38 = { 8d85f0fdffff 68???????? 6804010000 50 e8???????? 83c414 8d45fc }
- $sequence_39 = { 8bc2 ebf8 53 8b5c240c 55 33ed }
+ $sequence_0 = { c744242404000000 ffd5 85c0 0f84b2000000 }
+ $sequence_1 = { 884e13 66a1???????? 33c9 6685c0 741f 0fb7c0 ba000c0000 }
+ $sequence_2 = { ff15???????? 8b442414 50 ff15???????? 8b5c2410 56 }
+ $sequence_3 = { 85c0 7405 e8???????? 8b8c24d4070000 5e 33cc }
+ $sequence_4 = { 663bc2 0f84ac030000 0fb7048d64bc4000 41 }
+ $sequence_5 = { 8b4c2440 8b542418 894114 895110 }
+ $sequence_6 = { 6a00 50 e8???????? 83c40c 6805010000 8d4c2404 51 }
+ $sequence_7 = { 53 ff54244c 85c0 8b442414 }
+ $sequence_8 = { 0fb7c0 baa8540000 663bc2 0f8420050000 0fb7048d64bc4000 41 }
+ $sequence_9 = { 56 8d34c5c0b84000 833e00 7513 50 e8???????? }
condition:
- 7 of them and filesize <1105920
+ 7 of them and filesize <155648
}
-rule MALPEDIA_Win_Unidentified_061_Auto : FILE
+rule MALPEDIA_Win_Nullmixer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "59888b60-a3e6-5e9f-a441-429646fe0731"
- date = "2023-07-11"
- modified = "2023-07-15"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_061"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_061_auto.yar#L1-L123"
+ id = "e761e8a0-6032-5175-8c62-373d3cfdbd32"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nullmixer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nullmixer_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "ee3ce5b6c77f09c690f7a934c26be09c58c4fcdee70275b61c00e527d8aa097d"
+ logic_hash = "ff19905731e10511745fb317854603fdd089737424883a407ad871400c764a1f"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20230705"
- malpedia_hash = "42d0574f4405bd7d2b154d321d345acb18834a41"
- malpedia_version = "20230715"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d85d4fdffff 50 e8???????? c9 }
- $sequence_1 = { 89b5f0fdffff 899decfdffff 89b5f4feffff 899df0feffff ff15???????? 8945fc }
- $sequence_2 = { 51 8365fc00 8d45fc 50 68???????? 6801000080 ff15???????? }
- $sequence_3 = { 8945f0 0fb705???????? 50 ff15???????? 668945ee }
- $sequence_4 = { 68???????? 56 ff15???????? 83c41c 8d4601 5e eb09 }
- $sequence_5 = { 7417 03f3 3bf7 7ccb eb2f 7d29 }
- $sequence_6 = { 83cfff c6457300 3b7566 7cb5 3b7566 }
- $sequence_7 = { 53 57 6a04 33ff 33db }
- $sequence_8 = { 5b c9 c20800 81ec00040000 68???????? 68???????? ff15???????? }
- $sequence_9 = { eb04 c645fb3d 6a05 8d45f8 50 ff750c c645fc00 }
+ $sequence_0 = { 6683fa05 0f8726010000 83e857 83f8ff 0f85d0fcffff 8d7600 }
+ $sequence_1 = { c7442404???????? c70424???????? c705????????d09d4a00 e8???????? c705????????01000000 83ec08 89d9 }
+ $sequence_2 = { a3???????? 8d8568feffff c7442408???????? c7442404???????? 890424 e8???????? 8d8568feffff }
+ $sequence_3 = { 8901 8d44241f 89442408 e8???????? 31d2 c7400800000000 83c00c }
+ $sequence_4 = { c784245001000000000000 31c9 e9???????? 8b8c2450010000 e8???????? b8ffffffff 8b94245c010000 }
+ $sequence_5 = { 01c9 896c2404 894c2408 890424 e8???????? e9???????? 8b442448 }
+ $sequence_6 = { 398424d0000000 0f8430050000 8b06 c744240400000000 89f1 0fb75502 891424 }
+ $sequence_7 = { 83f90f 0f4fc8 8b45a8 3975ac 19f8 0f82d0000000 8b55bc }
+ $sequence_8 = { 83ec04 837d8010 8d75b4 0f94c2 8b4808 39f9 894d8c }
+ $sequence_9 = { 89f1 e8???????? 8b06 89f1 c704242b000000 ff5018 52 }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <2351104
}
-rule MALPEDIA_Win_Lambload_Auto : FILE
+rule MALPEDIA_Win_Teslacrypt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ca98537a-be45-5b55-a54c-745fd9ea79b6"
+ id = "cf4cf463-c704-58da-bdf6-218fd6a96530"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lambload"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lambload_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.teslacrypt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.teslacrypt_auto.yar#L1-L177"
license_url = "N/A"
- logic_hash = "6692a5aefbbf1fabc4e1d13310c5f00b33c64ae692d0893f079fb461da4727d8"
+ logic_hash = "204f6818406ce562647f2b4540c54737aa88569de9afd450b681fd9a49a46e00"
score = 75
quality = 75
tags = "FILE"
@@ -131485,32 +138689,38 @@ rule MALPEDIA_Win_Lambload_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffb5e4f7ffff e8???????? 0fb74624 57 57 6a03 }
- $sequence_1 = { ff15???????? 47 83ff02 7caa 83c8ff 5f 5e }
- $sequence_2 = { 74c5 57 57 57 ff7608 ff15???????? 85c0 }
- $sequence_3 = { 8b6c2424 83c408 3be8 7e02 8be8 }
- $sequence_4 = { 897dfc 897dd8 83ff40 0f8d3b010000 8b34bd00490710 85f6 }
- $sequence_5 = { 83c420 837e1804 750d b800308000 }
- $sequence_6 = { f7f9 8955fc e8???????? 99 b9ffff0000 f7f9 }
- $sequence_7 = { be???????? 50 a5 e8???????? 83c40c }
- $sequence_8 = { 0fb78c05ecfbffff 66898c05f4fdffff 83c002 663bce 75e8 53 8d85ecfbffff }
- $sequence_9 = { 33c0 8a540430 8a8be8330710 32ca 888be8330710 43 3bdd }
+ $sequence_0 = { 31f7 897d24 31f9 894d28 31ca 89552c 89d0 }
+ $sequence_1 = { 334534 894554 334538 894558 }
+ $sequence_2 = { 3345f8 894518 3345fc 89451c 51 52 89f2 }
+ $sequence_3 = { 0f8452030000 81ffc0000000 0f84ac010000 81ffe0000000 740a b8ffffffff }
+ $sequence_4 = { 31f7 897d44 31f9 894d48 31ca }
+ $sequence_5 = { 334538 894558 33453c 89455c 51 52 89f2 }
+ $sequence_6 = { 31f7 897d04 31f9 894d08 }
+ $sequence_7 = { 335d04 334d08 33550c 81ffa0000000 0f8456030000 }
+ $sequence_8 = { 0f842d010000 8b44243c 8b08 83f900 894c2430 741f 8b442464 }
+ $sequence_9 = { 8b4c2430 01c8 8b542474 8b742470 031406 891406 }
+ $sequence_10 = { 890c24 e8???????? 8d0dc1304b00 8b542410 894208 890c24 }
+ $sequence_11 = { 8902 83f800 894c2408 7432 8b442418 83c004 }
+ $sequence_12 = { 31c0 8b4c2414 29c8 8b54240c 21c2 01ca 89542408 }
+ $sequence_13 = { b801000000 8b4c245c 8b9180000000 8b742464 01d6 8b7c2464 8b54170c }
+ $sequence_14 = { c70100000000 c7410c00000000 c7410800000000 8b0d???????? 8b4920 8b742450 8b7a38 }
+ $sequence_15 = { 8b5120 89e6 8d7c2468 897e0c }
condition:
- 7 of them and filesize <1039360
+ 7 of them and filesize <1187840
}
-rule MALPEDIA_Win_Darkshell_Auto : FILE
+rule MALPEDIA_Win_Tildeb_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "54238af5-7449-55bf-9dc2-08b5916a169b"
+ id = "e4d2b91f-a0b2-5435-bc42-03da5ff53194"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkshell"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkshell_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tildeb"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tildeb_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "b58c1bc2e0988d2ff26125d2777445ac18dab56ca2991d83e57c5d570ae3c235"
+ logic_hash = "5eed583e8de669a9ccc3c14def00c8dc34c80dd8549b8a02a48ebd34aae4a3b5"
score = 75
quality = 75
tags = "FILE"
@@ -131524,32 +138734,32 @@ rule MALPEDIA_Win_Darkshell_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c004 8901 83c014 8902 6681380b01 7511 }
- $sequence_1 = { 6a00 6a00 50 53 ffd5 8be8 }
- $sequence_2 = { 7413 8b4c2410 8b54240c 51 52 ffd0 }
- $sequence_3 = { ff542414 53 ff542414 56 ff15???????? }
- $sequence_4 = { 8d542418 6a04 52 684be12200 50 }
- $sequence_5 = { e8???????? 8b4c2414 8bf0 8b442418 6800400000 50 }
- $sequence_6 = { 89442418 ffd7 6a00 6a00 6a00 6a00 }
- $sequence_7 = { 55 ff542424 55 ff542414 53 }
- $sequence_8 = { 8902 6681380b01 7511 8b4c2410 05e0000000 8901 b801000000 }
- $sequence_9 = { ff15???????? 8b542410 8d4c2414 51 6a04 52 }
+ $sequence_0 = { 8d4dbc 51 56 ff15???????? 56 ff15???????? }
+ $sequence_1 = { 6a00 6a00 ff15???????? 85c0 0f84f5090000 68???????? }
+ $sequence_2 = { 57 6a40 c644241300 ff15???????? 50 ff15???????? }
+ $sequence_3 = { 85c0 7445 50 68???????? 68???????? ff15???????? 83c40c }
+ $sequence_4 = { e8???????? 6a00 6a08 8d85d4f5ffff 50 }
+ $sequence_5 = { 68???????? 57 56 ff15???????? 8945bc 85c0 7457 }
+ $sequence_6 = { c3 b815000000 5e 81c494010000 c3 f7d8 5e }
+ $sequence_7 = { eb40 8d458c 50 68???????? eb35 }
+ $sequence_8 = { 53 55 8bac2410010000 56 8b35???????? 57 68???????? }
+ $sequence_9 = { 6800000088 68???????? 68???????? 6a00 ff15???????? 8b0d???????? }
condition:
- 7 of them and filesize <344064
+ 7 of them and filesize <8532488
}
-rule MALPEDIA_Win_Troldesh_Auto : FILE
+rule MALPEDIA_Win_Mechanical_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7a3f582f-20a8-506d-8165-0b2ca7b385f0"
+ id = "2ebc8e2c-9656-5fd5-9240-713f089f8d21"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.troldesh"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.troldesh_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mechanical"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mechanical_auto.yar#L1-L158"
license_url = "N/A"
- logic_hash = "0484cce0fd00b2a95d24b675e3e6f5f144cbe86411aeac4268060b95d7df46bc"
+ logic_hash = "0d673fb1f58f38008ae08ad0a2913e65568b1230b5de3947ba7af4a4e448c6f0"
score = 75
quality = 75
tags = "FILE"
@@ -131563,32 +138773,38 @@ rule MALPEDIA_Win_Troldesh_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff74241c 8d44247c ff74241c 50 e8???????? 8b8e18050000 83c40c }
- $sequence_1 = { e8???????? 8b4510 8b4008 68ffffff7f 6a00 6a0a ff30 }
- $sequence_2 = { eb17 51 50 8d45d8 50 e8???????? 8b4514 }
- $sequence_3 = { ff7314 e8???????? 59 8b4df4 89431c 85c0 7511 }
- $sequence_4 = { e9???????? 8b4ddc e8???????? 33c0 83c604 8975f8 8b7508 }
- $sequence_5 = { e8???????? a3???????? e8???????? 8bf0 8974242c e8???????? 6a00 }
- $sequence_6 = { ff7720 89742414 56 e8???????? 59 59 85c0 }
- $sequence_7 = { ff7508 8bcf 56 ffb754010000 6a04 e8???????? 83c410 }
- $sequence_8 = { e8???????? 85c0 7419 6a14 8d500c 8d4de0 e8???????? }
- $sequence_9 = { e8???????? 8b4514 660fbe00 0fb7c0 50 6a01 e8???????? }
+ $sequence_0 = { 03c7 3bca 72ed 5f }
+ $sequence_1 = { c6025e eb12 c6022f eb0d }
+ $sequence_2 = { 8b442430 488d8c2471110000 33d2 41b803010000 }
+ $sequence_3 = { 0401 3cbe 8844240b 76e2 }
+ $sequence_4 = { 03ce c6840c3801000000 8d8424a05c0000 33f6 }
+ $sequence_5 = { 033485c0e54200 c745e401000000 33db 395e08 }
+ $sequence_6 = { 488d15d9d20000 488bcb e8???????? 85c0 750a 4883c310 }
+ $sequence_7 = { 00686c 42 0023 d18a0688078a }
+ $sequence_8 = { 4488a424300d0000 488905???????? e8???????? 4c8d1d5cd40100 498bcc }
+ $sequence_9 = { eb62 c6023d eb5d c6025f eb58 c6023a }
+ $sequence_10 = { 03c1 1bc9 0bc1 59 e9???????? e8???????? ff742404 }
+ $sequence_11 = { 41c1c90d 8bca 4983c201 4403c8 493bc8 }
+ $sequence_12 = { 033485c0e54200 8b45e4 8b00 8906 }
+ $sequence_13 = { 030495c0e54200 eb05 b8???????? f6400420 }
+ $sequence_14 = { 33d2 41b803010000 4488a42470110000 488905???????? e8???????? }
+ $sequence_15 = { 3c58 7711 480fbec5 428a8c10507c0200 83e10f eb03 }
condition:
- 7 of them and filesize <3915776
+ 7 of them and filesize <434176
}
-rule MALPEDIA_Win_Ruckguv_Auto : FILE
+rule MALPEDIA_Win_Cobalt_Strike_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "70c59136-1542-5cb3-8c7d-52dba7e0bc40"
+ id = "fe16365e-18f7-5cb3-91e7-4778fbcc5b82"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ruckguv"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ruckguv_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cobalt_strike"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cobalt_strike_auto.yar#L1-L157"
license_url = "N/A"
- logic_hash = "a64635c0a8f169255c2ded62c13acd231a3b9a4460e9b10acd2e149c6348dd85"
+ logic_hash = "e575d34f1fe7007aa1601e291288f1136cef68df0b3f455e03eabc3d825e94fe"
score = 75
quality = 75
tags = "FILE"
@@ -131602,32 +138818,38 @@ rule MALPEDIA_Win_Ruckguv_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7403 51 eb04 0fb7c0 50 ff7508 }
- $sequence_1 = { 56 53 e8???????? 8b463c 68f8000000 }
- $sequence_2 = { ff75fc 8d85b0f7ffff 50 ff75f4 }
- $sequence_3 = { 59 894508 85c0 750f 8b470c }
- $sequence_4 = { 85c0 0f848b000000 57 8d3c18 8b470c 85c0 }
- $sequence_5 = { 8a0a 84c9 75f1 c3 682680acc8 }
- $sequence_6 = { 83c0c0 50 8d4640 50 8d4340 }
- $sequence_7 = { 68dff0f081 6a01 e8???????? 83c40c 8d8d9cfdffff 51 ffd0 }
- $sequence_8 = { 6880000000 6a03 56 56 53 }
- $sequence_9 = { 59 59 ff742404 ffd0 c3 6831f478b7 }
+ $sequence_0 = { 3bc7 750d ff15???????? 3d33270000 }
+ $sequence_1 = { e9???????? eb0a b801000000 e9???????? }
+ $sequence_2 = { eb06 0fb6c0 83e07f 85c0 745a }
+ $sequence_3 = { eb68 8b45d4 8b482c 894de0 8b45e0 }
+ $sequence_4 = { ff35???????? ffd6 5e e9???????? 55 }
+ $sequence_5 = { eb4e 83f824 7f09 c745f403000000 }
+ $sequence_6 = { ff761c 83c004 e8???????? 59 59 83f8ff }
+ $sequence_7 = { f3a6 744c 8bf0 6a03 bf???????? 59 }
+ $sequence_8 = { 85c0 741d ff15???????? 85c0 7513 }
+ $sequence_9 = { e9???????? 833d????????01 7505 e8???????? }
+ $sequence_10 = { 8bd0 e8???????? 85c0 7e0e }
+ $sequence_11 = { 85c0 7405 e8???????? 8b0d???????? 85c9 }
+ $sequence_12 = { f3c3 cc 488bc4 48895808 48896810 48897018 }
+ $sequence_13 = { c1e903 ffc1 03c1 3d80000000 }
+ $sequence_14 = { 49ffc7 413bcc 72e9 41894d00 }
+ $sequence_15 = { 48895c2448 48895c2440 4889442438 498b06 }
condition:
- 7 of them and filesize <41024
+ 7 of them and filesize <1015808
}
-rule MALPEDIA_Win_Grey_Energy_Auto : FILE
+rule MALPEDIA_Win_Rambo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4a36cbdc-dd01-583b-ac49-dd33a3c83ba9"
+ id = "9952c16f-0ad8-5b79-a375-78c277443f5b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grey_energy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grey_energy_auto.yar#L1-L164"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rambo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rambo_auto.yar#L1-L172"
license_url = "N/A"
- logic_hash = "48bebd474d43043ec7179ca6aa1110529eaa285ee6fd70578731385cb5b6f92e"
+ logic_hash = "289c05fe82444eba5e21e680847ee18f8bd6fcd3320474143e269d581daca21f"
score = 75
quality = 75
tags = "FILE"
@@ -131641,39 +138863,38 @@ rule MALPEDIA_Win_Grey_Energy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6800000008 57 53 53 }
- $sequence_1 = { e8???????? 68???????? 8945cc e8???????? 68???????? 8945d4 e8???????? }
- $sequence_2 = { 53 53 6800000008 57 }
- $sequence_3 = { 8945d4 e8???????? 68???????? 8945d0 e8???????? }
- $sequence_4 = { 0345f0 0fbe08 8b45f0 33d2 }
- $sequence_5 = { 81e1ff000000 8b45ec 8b55f8 66890c42 }
- $sequence_6 = { 8b45f8 0345ec 8808 eb10 }
- $sequence_7 = { 8b55f0 8b7508 668b1456 66891441 }
- $sequence_8 = { 66890c42 eb14 8b45ec 8b4df8 }
- $sequence_9 = { 53 ff15???????? 8b75f8 85f6 }
- $sequence_10 = { 8b4d08 0fb70c41 8b45f0 33d2 }
- $sequence_11 = { 50 6a40 ff15???????? 8945f8 837df800 7507 }
- $sequence_12 = { 837df800 7507 33c0 e9???????? c745f004000000 }
- $sequence_13 = { 7407 c60100 41 48 75f9 ff75f8 }
- $sequence_14 = { 48 75fa 56 ff15???????? ff75f8 }
- $sequence_15 = { 57 ff75e8 ff75f0 ffd6 }
- $sequence_16 = { e8???????? 8b4508 3bc7 7430 57 }
+ $sequence_0 = { ff7508 e8???????? 59 50 ff7508 ff15???????? 56 }
+ $sequence_1 = { e8???????? ff750c 8d85ecfdffff 50 e8???????? }
+ $sequence_2 = { ff15???????? 83c41c 6a01 58 5e c9 }
+ $sequence_3 = { 85f6 7437 56 6a01 }
+ $sequence_4 = { ff7508 8d85f8feffff 50 e8???????? 8065fe00 8d45fc 50 }
+ $sequence_5 = { 83c428 6a32 ff15???????? 8d85f8faffff 50 68???????? }
+ $sequence_6 = { 56 57 8d85f8faffff 6a01 50 ff15???????? 80a43df8faffff00 }
+ $sequence_7 = { 50 8d85f8feffff 50 c645fc72 }
+ $sequence_8 = { 756b 57 b940000000 8d7c240d 8844240c f3ab }
+ $sequence_9 = { f3aa 8bcb 8d7c2474 8bc1 }
+ $sequence_10 = { e8???????? 8d4c2410 c684240004000007 e8???????? 68b6000000 8d542414 }
+ $sequence_11 = { 8d8c2488000000 e8???????? 57 57 8d4c2424 }
+ $sequence_12 = { e8???????? 8d4c2428 c684240004000005 e8???????? 8d4c2414 c684240004000004 }
+ $sequence_13 = { 8b35???????? a3???????? ffd6 3db7000000 7418 }
+ $sequence_14 = { 89442418 8b4309 84c9 7403 50 }
+ $sequence_15 = { f3a5 8bcb 8d9424f8020000 83e103 f3a4 bf???????? 83c9ff }
condition:
- 7 of them and filesize <303104
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Azorult_Auto : FILE
+rule MALPEDIA_Win_Boaxxe_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b51dfae0-9dbd-5fdb-9b21-c42d24abe8fe"
+ id = "d2861d72-2434-5a6e-bbf4-9290c68bd235"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.azorult"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.azorult_auto.yar#L1-L156"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.boaxxe"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.boaxxe_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "57462241e7f147f9f02722e7f4f98394823c33b074e00b1372b7118c997d7f9f"
+ logic_hash = "232a66e4610caa68487a07fb0b6c51bc622cacc6954ed1eec17df693514e555a"
score = 75
quality = 75
tags = "FILE"
@@ -131687,38 +138908,32 @@ rule MALPEDIA_Win_Azorult_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ba???????? 8d45e8 e8???????? 8d45e4 8b55f8 8a543201 }
- $sequence_1 = { e8???????? 56 8d85a0fdffff b9???????? }
- $sequence_2 = { b9???????? 8b55fc e8???????? 8b859cfdffff e8???????? }
- $sequence_3 = { b80f270000 e8???????? 8945f8 8d55f4 8bc3 }
- $sequence_4 = { b80f270000 e8???????? 8bf0 b80f270000 }
- $sequence_5 = { 7518 56 8b45fc e8???????? 8bc8 8d5301 }
- $sequence_6 = { b80f270000 e8???????? 8bd8 b80f270000 }
- $sequence_7 = { ba03000000 e8???????? 8d858cfdffff e8???????? }
- $sequence_8 = { 7506 ff05???????? 56 e8???????? 59 }
- $sequence_9 = { e8???????? 59 8b45f4 40 }
- $sequence_10 = { 50 e8???????? 59 8bd8 33c0 }
- $sequence_11 = { 85db 7404 8bc3 eb07 }
- $sequence_12 = { 011f 59 8bc3 c1e003 01866caf0100 }
- $sequence_13 = { 014f18 8b4714 85c0 0f854e010000 }
- $sequence_14 = { 014110 5f 5e 5b }
- $sequence_15 = { 01590c 8b45f0 014110 5f }
+ $sequence_0 = { b904000000 e8???????? 8d55c4 66b8c503 e8???????? 8b55c4 a1???????? }
+ $sequence_1 = { 0f8c88000000 8d4df4 8b55f8 8b45f8 e8???????? 8b55f4 8d45f8 }
+ $sequence_2 = { 83c220 8d45f8 e8???????? 8d45f8 e8???????? 8945f4 8b45f4 }
+ $sequence_3 = { 33c0 55 68???????? 64ff30 648920 8bcb b230 }
+ $sequence_4 = { 85db 7410 8b55f4 8b45ec 8bcb e8???????? }
+ $sequence_5 = { 8b45cc e8???????? 8bd8 891d???????? 891d???????? 8d45c8 50 }
+ $sequence_6 = { 01d0 c1e003 8b803c58bc6d 8945ec e9???????? 837de808 }
+ $sequence_7 = { a1???????? e8???????? 8bd0 53 8bc2 e9???????? 33c0 }
+ $sequence_8 = { 0342fc 8945ec 8b45f8 8b00 8b5508 0342fc 8945f0 }
+ $sequence_9 = { b808000000 e8???????? 8b55f8 58 e8???????? 7504 33db }
condition:
- 7 of them and filesize <1753088
+ 7 of them and filesize <1146880
}
-rule MALPEDIA_Win_Killdisk_Auto : FILE
+rule MALPEDIA_Win_Taintedscribe_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fd586ea1-d41c-50af-ab00-4c3fd6d8b593"
+ id = "62c390fd-70d7-5d2c-ab35-2685bb241f72"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.killdisk"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.killdisk_auto.yar#L1-L172"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.taintedscribe"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.taintedscribe_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "5e0faf26e496f52d500cc74a0d402009c944ca198565834d2511070577fb34d3"
+ logic_hash = "9db61e016991abab1a5db24c238ca36eb7d715a36997cda629b6ade68b20e5c3"
score = 75
quality = 75
tags = "FILE"
@@ -131732,38 +138947,32 @@ rule MALPEDIA_Win_Killdisk_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4604 7204 8b08 eb02 8bc8 66891c51 }
- $sequence_1 = { 0f8424020000 8d4c245c b8???????? 8d642400 668b10 }
- $sequence_2 = { 881438 e8???????? 9c c6442408cf 894508 e9???????? }
- $sequence_3 = { 88742408 c70424ba7bbfa4 660fbae408 662dca11 e8???????? 881438 e8???????? }
- $sequence_4 = { 83c40c 68???????? 68e08fc201 e8???????? 8bf0 }
- $sequence_5 = { 8f44241c c64424148e c644240426 e8???????? 4e e8???????? 54 }
- $sequence_6 = { c3 50 ff15???????? 8b8c24d41a0000 }
- $sequence_7 = { 872d???????? 0fc1c2 89e2 66d3c9 66d3c0 }
- $sequence_8 = { e8???????? 84c0 751a a1???????? 50 6802000080 }
- $sequence_9 = { b001 5e 59 c3 837f1800 7413 }
- $sequence_10 = { e8???????? 83c420 6a00 8d442414 }
- $sequence_11 = { 46 66892c24 9c 8d64244c e9???????? 9c 9c }
- $sequence_12 = { 9c 8d642430 e9???????? ff742404 66894500 }
- $sequence_13 = { 8d642454 e9???????? 880424 8774242c 9c 68a12348dd e8???????? }
- $sequence_14 = { 66897c240c 882c24 c64424044f 8d642454 e9???????? }
- $sequence_15 = { 56 e8???????? c1f805 56 8d3c85a098c201 }
+ $sequence_0 = { 8bc8 8b858cf7ffff 83e103 6a02 f3a4 6a00 }
+ $sequence_1 = { 8d4ddc 898db8fcffff 8bcf 0facd108 }
+ $sequence_2 = { 8b5358 898d88fbffff 8b4b50 0f94c0 }
+ $sequence_3 = { 85c0 7405 8b4d98 8908 85db }
+ $sequence_4 = { 894e3c 894e44 895648 33c0 5e 8b4dfc 33cd }
+ $sequence_5 = { 8b4dcc 894308 8b45d0 50 }
+ $sequence_6 = { 42 83fa1c 7cbb 81ff00010000 0f94c1 0fb6c1 68???????? }
+ $sequence_7 = { c68577fbffff01 7507 c68577fbffff00 c78570fbffff08000000 }
+ $sequence_8 = { 83c40c 098658af0100 8d0419 89865caf0100 83f810 }
+ $sequence_9 = { bb01000000 d3e3 33c0 85db 7e1e 8d4900 }
condition:
- 7 of them and filesize <10817536
+ 7 of them and filesize <524288
}
-rule MALPEDIA_Win_Zitmo_Auto : FILE
+rule MALPEDIA_Win_Nagini_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f6f59970-f923-5e51-84d0-3f8e29574b3c"
+ id = "140c68e0-b1a0-5de4-9ceb-f9c4372ec960"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zitmo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zitmo_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nagini"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nagini_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "a3b8b6f5916a461447d9c48219b755dccd1a5d708dba30f1dbbe42f800df788f"
+ logic_hash = "3751db8355d7cf68abbb539627fa735abe39bfd76ce94371ffdf9eba2b1cc16c"
score = 75
quality = 75
tags = "FILE"
@@ -131777,32 +138986,32 @@ rule MALPEDIA_Win_Zitmo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 03d7 8bde f7de ffb544feffff 53 e8???????? c9 }
- $sequence_1 = { 55 8bec 81c47cffffff 317588 f7d7 f7df }
- $sequence_2 = { 23d0 f7d9 8bd6 23d8 }
- $sequence_3 = { c20400 55 8bec 81c410ffffff }
- $sequence_4 = { 55 8bec 81c45cffffff 23cb 8bd6 f7d2 }
- $sequence_5 = { 314dd8 f7d9 48 f7d2 03c1 ffb504ffffff }
- $sequence_6 = { 4a f7d9 23c6 8bcb 46 }
- $sequence_7 = { 4f e8???????? 8bca 03f7 e8???????? 23d7 }
- $sequence_8 = { 81856cffffff36360000 03df f7d1 8bf8 }
- $sequence_9 = { 6a36 6a36 51 ffb550feffff 6834340000 57 8d4d88 }
+ $sequence_0 = { 0131 1f 0031 1f 003422 0337 }
+ $sequence_1 = { a3???????? eb18 6a00 6a00 6a00 6a00 }
+ $sequence_2 = { 83c408 85c0 0f8510010000 837c242808 8d442414 68???????? }
+ $sequence_3 = { 3422 0536240538 27 06 37 260537260535 230434 }
+ $sequence_4 = { 0a06 1408 0412 06 }
+ $sequence_5 = { 720e 4e 42 0fb606 80b87081420000 74e9 8b5ddc }
+ $sequence_6 = { 668944246c a0???????? 8844246e 8a4701 8d7f01 }
+ $sequence_7 = { 6689442444 0f8238020000 ff74242c e8???????? 83c404 e9???????? }
+ $sequence_8 = { 0f835ffbffff 03f3 03d3 83fb1f 0f8715040000 ff249da0c64000 }
+ $sequence_9 = { b3ac 98 b7b0 9c }
condition:
- 7 of them and filesize <843776
+ 7 of them and filesize <12820480
}
-rule MALPEDIA_Win_Wipbot_Auto : FILE
+rule MALPEDIA_Win_Gcleaner_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2dc6790b-0815-56da-b4e1-b1ab1c837c71"
+ id = "6f27809a-4a1b-5d62-97c7-de2eeddc46d9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wipbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wipbot_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gcleaner"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gcleaner_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "b4a431b5982e86b4c79c71104a1485b7ef9ede4d9bcd19d6e305251f54be5168"
+ logic_hash = "7aee09652b701d76a6e86128872cf2cc44b3fc03358e24bd02f64455f78cd161"
score = 75
quality = 75
tags = "FILE"
@@ -131816,32 +139025,32 @@ rule MALPEDIA_Win_Wipbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb05 b8???????? e8???????? 89da 83c9ff e8???????? }
- $sequence_1 = { 5b 5d e9???????? 5a 31c0 5b 5d }
- $sequence_2 = { 4c 8d442428 baff010f00 48 89d9 ffd0 48 }
- $sequence_3 = { b911000000 31c0 c644245e2e 31d2 f3aa c644245f0b c64424601f }
- $sequence_4 = { 85c0 48 89c6 0f94c2 48 85db 0f94c0 }
- $sequence_5 = { 8d44245f 88d1 48 01d0 48 ffc2 3208 }
- $sequence_6 = { eb7d 48 894c2438 e8???????? 01c0 ba9ad65fb0 b98a758b1f }
- $sequence_7 = { 8d55f4 89542408 8d55f0 c744240c00800000 89542404 c70424ffffffff ffd0 }
- $sequence_8 = { 89cb b91d000000 c64424222e f3aa c644242379 c644242446 31c0 }
- $sequence_9 = { 8944240c 8b45a8 83c020 890424 ffd2 85c0 0f9fc0 }
+ $sequence_0 = { 8d8d70feffff 8d45b0 0f4345b0 51 50 }
+ $sequence_1 = { 8bd0 c645fc04 8d4dd8 e8???????? 83c410 }
+ $sequence_2 = { 660fd64010 8345e418 eb10 8d4dc8 }
+ $sequence_3 = { 660fd64610 c742e000000000 c742e40f000000 c642d000 8b42e8 894618 }
+ $sequence_4 = { e8???????? 8d8d60ffffff e8???????? 6a00 6a00 }
+ $sequence_5 = { c642d000 8b42e8 894618 8d42ec 83c61c 3bc7 }
+ $sequence_6 = { eb10 8d4dc8 51 50 }
+ $sequence_7 = { 7438 8035????????2e 8035????????2e 8035????????2e 8035????????2e 8035????????2e 8035????????2e }
+ $sequence_8 = { 52 51 e8???????? 83c408 85ff 0f8807010000 }
+ $sequence_9 = { c645fc02 83fa10 722c 8b4dc8 42 8bc1 }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <540672
}
-rule MALPEDIA_Win_Ehdevel_Auto : FILE
+rule MALPEDIA_Win_Cycbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "df8239a0-64d7-5d90-a037-26c4b02b8a9b"
+ id = "86cbdc6e-7fe8-5962-82c9-3bfe759d3962"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ehdevel"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ehdevel_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cycbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cycbot_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "959b6347dd7f394fa1dd74e2d5d70bd613b6731b1cc6dbc8f1a7abb3467a3ebd"
+ logic_hash = "0df38e9a7bf0b18ae5c795f617ec217aef7020970864c9cdbebdcaf5c85c3174"
score = 75
quality = 75
tags = "FILE"
@@ -131855,32 +139064,32 @@ rule MALPEDIA_Win_Ehdevel_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 e8???????? e9???????? 33d2 68fe070000 52 8d85feefffff }
- $sequence_1 = { 7545 56 c70303000000 ff15???????? 56 ff15???????? 68???????? }
- $sequence_2 = { 8d8dcce7ffff 51 6a00 6813000020 56 c785cce7ffff00000000 c785c8e7ffff04000000 }
- $sequence_3 = { 8d85f0e7ffff 50 56 6a00 6a10 6a02 ff15???????? }
- $sequence_4 = { e8???????? 83c404 33c9 6a08 b8???????? }
- $sequence_5 = { 8d8dd4e5ffff 51 8d95f8f7ffff 6800040000 52 e8???????? }
- $sequence_6 = { 83c410 8b4d0c 8d442408 50 51 }
- $sequence_7 = { 83d8ff 85c0 0f84cffdffff 68???????? 6800040000 57 e8???????? }
- $sequence_8 = { 50 e8???????? 8d8c24d4190000 51 8d9424d8010000 6800040000 52 }
- $sequence_9 = { 8db564f7ffff e8???????? 33d2 899de8f7ffff 89bde4f7ffff 668995d4f7ffff 33c0 }
+ $sequence_0 = { 59 8b45ec e8???????? c3 6834020000 b8???????? e8???????? }
+ $sequence_1 = { 57 ffb5e8feffff ff15???????? 8bb5ecfeffff 2bf3 f7de 1bf6 }
+ $sequence_2 = { c745dc44eb4300 c745e08ceb4300 c745e40cee4300 c745e820ee4300 c745ec34ee4300 c745f0f4ec4300 c745f4fcec4300 }
+ $sequence_3 = { 8b06 8b4008 89480c 8b06 894808 8b4508 8908 }
+ $sequence_4 = { 59 33c0 8d7dc8 f3ab aa 8d45c8 6a21 }
+ $sequence_5 = { 33c0 8903 894304 57 894308 ff15???????? c70300000000 }
+ $sequence_6 = { 8d854cfbffff 50 8bc7 e8???????? 59 59 57 }
+ $sequence_7 = { ff5108 8d85e0fbffff 50 ff15???????? ff85d8fbffff 39bdb4fbffff }
+ $sequence_8 = { 50 e8???????? 837c241801 59 59 7408 c744241807000000 }
+ $sequence_9 = { b90a0a0000 663b4c07fe 7508 8945fc be01000000 40 }
condition:
- 7 of them and filesize <524288
+ 7 of them and filesize <1163264
}
-rule MALPEDIA_Win_Tigerlite_Auto : FILE
+rule MALPEDIA_Win_Maggie_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "aa691ec3-b883-5f5c-8994-9e33da37724e"
+ id = "d5276a3c-46d0-5873-87dd-9d6cf0c2cf8b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tigerlite"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tigerlite_auto.yar#L1-L169"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maggie"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maggie_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "fcf8f4ae129308f814ca77b619fbfadd3ec5da4949cb79481c9fac330ba09f68"
+ logic_hash = "41d76bd3fbb547d408b10f3113f1f0a7db8f68879c6d91dc7c6cf7b7ea8b4803"
score = 75
quality = 75
tags = "FILE"
@@ -131894,38 +139103,32 @@ rule MALPEDIA_Win_Tigerlite_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c1f805 83e71f c1e706 8b0485489d4100 83c00c 03c7 50 }
- $sequence_1 = { 8b85e0f7ffff 85c0 751d 56 ff15???????? b832000000 5f }
- $sequence_2 = { 8b8d24e5ffff 50 8b8528e5ffff 8b0485489d4100 }
- $sequence_3 = { 85c0 740d ff15???????? b8c8000000 eb65 }
- $sequence_4 = { ff15???????? cc 4c8d4510 488d15bbc80100 }
- $sequence_5 = { 41b8ff030000 c6859000000000 e8???????? 488d1528bc0100 488d8d90000000 e8???????? }
- $sequence_6 = { 33c0 8bbdbcfdffff 0fbebcc7f8214100 8bc7 89bdbcfdffff 8bbde4fdffff }
- $sequence_7 = { 668986b8000000 668986be010000 c7466878874100 83a6b803000000 6a0d e8???????? }
- $sequence_8 = { 4863c2 4803d8 eb61 4b8b84ea604a0200 42f644300848 743e 48ffc3 }
- $sequence_9 = { 663955d8 7442 668933 8a45d8 4b8b8cea604a0200 4288443109 }
- $sequence_10 = { 8b3495489d4100 8a441e04 84c0 0f8957020000 }
- $sequence_11 = { 488bcb 488bf8 e8???????? 4885ff 0f8405040000 4c8d4530 488d0da1a40100 }
- $sequence_12 = { 488d4c2440 418bd6 e8???????? e9???????? }
- $sequence_13 = { b9e5000000 8bd8 83e303 e8???????? }
- $sequence_14 = { 3bfa 7556 8bcb e8???????? 53 }
- $sequence_15 = { 8d0c00 894dec eb38 8b45f4 8b0485489d4100 }
+ $sequence_0 = { ff15???????? e8???????? 84c0 74ec e8???????? }
+ $sequence_1 = { ff15???????? 83f8ff 750f ff15???????? 2d33270000 f7d8 1bc0 }
+ $sequence_2 = { 83f8ff 750f ff15???????? 2d33270000 f7d8 1bc0 }
+ $sequence_3 = { 750f ff15???????? 2d33270000 f7d8 1bc0 }
+ $sequence_4 = { ff15???????? 83f8ff 750f ff15???????? 2d33270000 f7d8 }
+ $sequence_5 = { 83f8ff 750f ff15???????? 2d33270000 f7d8 }
+ $sequence_6 = { b8ff000000 663b05???????? 7505 e8???????? e8???????? 84c0 }
+ $sequence_7 = { 663b05???????? 7505 e8???????? e8???????? 84c0 }
+ $sequence_8 = { 7511 ff15???????? 85c0 7407 33c0 }
+ $sequence_9 = { 7511 ff15???????? 85c0 7407 33c0 e9???????? }
condition:
- 7 of them and filesize <349184
+ 7 of them and filesize <611328
}
-rule MALPEDIA_Win_Crypt0L0Cker_Auto : FILE
+rule MALPEDIA_Win_Mikoponi_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3ca18c92-db73-54b4-928d-eb72333dfc4b"
+ id = "e1f9d663-47fc-536a-afed-a18f76559a32"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crypt0l0cker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crypt0l0cker_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mikoponi"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mikoponi_auto.yar#L1-L105"
license_url = "N/A"
- logic_hash = "3ce866cbdb58e590ea553be6664221b117cb83d9a5d4d70643f018e4fb580d20"
+ logic_hash = "e53726bff6b275a8cbfe6479d201a659d381061025ff16663204532183241afc"
score = 75
quality = 75
tags = "FILE"
@@ -131939,32 +139142,30 @@ rule MALPEDIA_Win_Crypt0L0Cker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 0f8486000000 53 8d58ff c1eb02 56 }
- $sequence_1 = { 8b4640 85c0 0f8479000000 83780c00 7473 6800010000 e8???????? }
- $sequence_2 = { 85f6 0f8ead000000 8d4108 8d04b8 894508 8b4510 83c008 }
- $sequence_3 = { 55 56 8d44240f 8bea 50 6a01 ff35???????? }
- $sequence_4 = { 83c40c 33c0 6689043b 897e08 85ff 0f84d6000000 }
- $sequence_5 = { 8b4c243c 8b442430 8911 894104 eb17 8bcf e8???????? }
- $sequence_6 = { b9???????? 3d90010000 0f4cce 8bf1 8b7f04 85f6 74c9 }
- $sequence_7 = { 8bce e8???????? 8bf8 83c408 85ff 7438 83c705 }
- $sequence_8 = { 68???????? 6a05 6840b6b9a6 6a1c e8???????? 83c424 }
- $sequence_9 = { 0f8581020000 807dee81 0f8577020000 ff75ef ff15???????? 8b0f 8bd3 }
+ $sequence_0 = { 8b0f 51 e8???????? 83c404 5d 5f 83c408 }
+ $sequence_1 = { e8???????? 83c404 eb15 8d942464020000 52 8d442418 }
+ $sequence_2 = { 33ed 391d???????? 743d bf???????? }
+ $sequence_3 = { b9???????? 66895010 c7004418a150 e8???????? 8d3c47 }
+ $sequence_4 = { 53 55 e8???????? 83c40c 84c0 7506 83c3ff }
+ $sequence_5 = { 803d????????01 56 7527 8b742408 56 ff15???????? }
+ $sequence_6 = { e8???????? 81c470040000 c3 8b542430 3b542420 750e }
+ $sequence_7 = { 7543 3805???????? 753b 8d8c2464020000 51 68???????? }
condition:
- 7 of them and filesize <917504
+ 7 of them and filesize <330752
}
-rule MALPEDIA_Win_Bitsran_Auto : FILE
+rule MALPEDIA_Win_Stormwind_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e3cfbc68-7ec2-5ca7-89d3-b794638917c8"
+ id = "134843ba-afb3-5108-9e28-7ec5026e872c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bitsran"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bitsran_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stormwind"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stormwind_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "2919e184e2a9722abe679cf353ecc217eb2b7fdd010f4e63772073cd0ac5e798"
+ logic_hash = "81578edc87d2c38ca6c94ce63cf22ed064b72d5bc6a7c525985af57574ba5c73"
score = 75
quality = 75
tags = "FILE"
@@ -131978,34 +139179,34 @@ rule MALPEDIA_Win_Bitsran_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7433 56 57 8bbdf8bfffff c1ef02 }
- $sequence_1 = { 8911 8b0d???????? 8b9d58fdffff eb5e 8b35???????? }
- $sequence_2 = { 85f6 7417 8b4508 50 }
- $sequence_3 = { 50 53 e8???????? 8b9d44fdffff 83ef04 }
- $sequence_4 = { 83c408 85c0 7403 8975fc 8b03 8d55b8 52 }
- $sequence_5 = { 742b 8bc1 2bc1 c1f802 8d348500000000 }
- $sequence_6 = { 8b04c5046f4100 5d c3 8bff }
- $sequence_7 = { 8d95d4fbffff 52 53 ff15???????? 837d1401 7407 }
- $sequence_8 = { 2bc3 c1f802 3dfeffff3f 0f87d0010000 8bca 2bcb }
- $sequence_9 = { 899d58fdffff 3bd9 0f83fe000000 3bd3 0f87f6000000 8b35???????? 2bda }
+ $sequence_0 = { e8???????? 83c404 8bf7 3b3b 75e2 }
+ $sequence_1 = { 83e4f8 81ec1c010000 53 8b5d10 56 57 8b7d0c }
+ $sequence_2 = { e8???????? 83ec0c c745fc00000000 8d4e04 e8???????? 85c0 8b06 }
+ $sequence_3 = { 50 ff7604 56 e8???????? 894604 c745d801000000 8b4804 }
+ $sequence_4 = { 59 8b7d08 33db 391cfd88e40410 755c 6a18 e8???????? }
+ $sequence_5 = { 83fa05 7509 8b852cfdffff 89470c 6bc20c 57 ff90c04e0410 }
+ $sequence_6 = { 8d4de4 e8???????? 68???????? 8d45e4 c745e4740c0410 50 e8???????? }
+ $sequence_7 = { f7fe 57 8bc2 99 }
+ $sequence_8 = { c74508???????? 50 8d4de4 e8???????? 68???????? 8d45e4 c745e4740c0410 }
+ $sequence_9 = { 8975d4 68b8020000 c645fc01 e8???????? }
condition:
- 7 of them and filesize <344064
+ 7 of them and filesize <741376
}
-rule MALPEDIA_Win_Smokeloader_Auto : FILE
+rule MALPEDIA_Win_Darkloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "977bd971-8931-5636-8c4a-15a97d7d7052"
+ id = "601e152a-7554-5605-b5d8-66c528809ef1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.smokeloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.smokeloader_auto.yar#L1-L568"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkloader_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "1e0a8327807cdebec07ee883bf0e214c6531b2f2bf2969115a759b540a5a3955"
+ logic_hash = "3bce0c9d521648c67df3e1e758ce6a8ac769bd1d815dcd4dfd750767fac4bfe8"
score = 75
- quality = 50
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -132017,89 +139218,34 @@ rule MALPEDIA_Win_Smokeloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8d45f0 50 8d45e8 50 8d45e0 50 }
- $sequence_1 = { 57 ff15???????? 6a00 6800000002 6a03 6a00 6a03 }
- $sequence_2 = { 50 8d45e0 50 56 ff15???????? 56 ff15???????? }
- $sequence_3 = { 8bf0 8d45dc 50 6a00 53 ff15???????? }
- $sequence_4 = { 740a 83c104 83f920 72f0 }
- $sequence_5 = { e8???????? 8bf0 8d45fc 50 ff75fc 56 6a19 }
- $sequence_6 = { ff15???????? bf90010000 8bcf e8???????? }
- $sequence_7 = { 0fb64405dc 50 8d45ec 50 }
- $sequence_8 = { 50 56 681f000f00 57 }
- $sequence_9 = { 56 8d45fc 50 57 57 6a19 }
- $sequence_10 = { 668ce8 6685c0 7406 fe05???????? }
- $sequence_11 = { 8b07 03c3 50 ff15???????? }
- $sequence_12 = { 56 ff15???????? 50 56 6a00 ff15???????? }
- $sequence_13 = { 33c0 e9???????? e8???????? b904010000 }
- $sequence_14 = { 88443c18 88543418 0fb64c3c18 0fb6c2 03c8 81e1ff000000 }
- $sequence_15 = { 81e5ff000000 8a442c18 88443c18 47 }
- $sequence_16 = { e8???????? 8bf8 68???????? ff15???????? }
- $sequence_17 = { ebf5 55 8bec 83ec24 8d45f4 53 }
- $sequence_18 = { 50 57 ff15???????? 43 83fb0f }
- $sequence_19 = { 8b7d10 50 57 56 53 e8???????? }
- $sequence_20 = { 8d8de8fdffff 50 50 50 }
- $sequence_21 = { 8d95f0fdffff c70200000000 6800800000 52 51 6aff }
- $sequence_22 = { 8985ecfdffff ffb5f0fdffff 50 53 e8???????? 8d8decfdffff }
- $sequence_23 = { e8???????? 2500300038 005800 2500300038 }
- $sequence_24 = { 8db5f8fdffff c60653 56 6a00 6a00 6a00 }
- $sequence_25 = { 8b4514 898608020000 56 6aff }
- $sequence_26 = { 01d4 8d85f0fdffff 8b750c 8b7d10 50 57 }
- $sequence_27 = { fc 5f 5e 5b }
- $sequence_28 = { 89e5 81ec5c060000 53 56 }
- $sequence_29 = { 30d0 aa e2f3 7505 }
- $sequence_30 = { 89cf fc b280 31db a4 }
- $sequence_31 = { 60 89c6 89cf fc }
- $sequence_32 = { ff15???????? 85c0 747c 488b4c2448 4533c9 488d442440 }
- $sequence_33 = { 488b4547 488907 4885c9 740f 8b450f 48894d17 83c802 }
- $sequence_34 = { 33c9 e8???????? 488bd8 4584ff 7411 41b101 }
- $sequence_35 = { 4f 8d1c10 41 8b4b18 45 }
- $sequence_36 = { 01c4 ffc9 49 8d3c8c }
- $sequence_37 = { 4c 01c7 8b048f 4c }
- $sequence_38 = { 49 8d3c8c 8b37 4c 01c6 }
- $sequence_39 = { 41b104 448bc7 488bcb e8???????? 488b742440 488bc3 488b5c2430 }
- $sequence_40 = { 55 89e5 81ec54040000 53 }
- $sequence_41 = { 33c9 4c897c2428 c744242000a00f00 ff15???????? }
- $sequence_42 = { 8b4b18 45 8b6320 4d }
- $sequence_43 = { 89d0 c1e205 01c2 31c0 ac 01c2 85c0 }
- $sequence_44 = { 83c408 85c0 0f84cb000000 8b45f4 2d10bf3400 0fb74dec }
- $sequence_45 = { 8946fc ad 85c0 75f3 c3 56 }
- $sequence_46 = { 56 ad 01e8 31c9 c1c108 3208 }
- $sequence_47 = { 8b4da0 8b55a4 895148 689d1e6b63 8b45e4 50 }
- $sequence_48 = { 8b45b4 894220 eb10 8b8d78ffffff 8b11 899578ffffff ebae }
- $sequence_49 = { 03471c 8b0428 01e8 5e c3 }
- $sequence_50 = { 5b c9 c20800 55 89e5 83ec04 }
- $sequence_51 = { e8???????? 8945ac 6a00 6a04 8d45b4 50 }
- $sequence_52 = { aa e2f3 7506 7404 }
- $sequence_53 = { 55 8bec 83c4d0 1e 53 }
- $sequence_54 = { 684a0dce09 8b45e4 50 e8???????? 8945a8 8b4da0 8b55a8 }
- $sequence_55 = { 83ec0c e8???????? 8945f8 8b45f8 8b4860 894df4 ff7518 }
- $sequence_56 = { 803800 75f5 31d1 75ec }
- $sequence_57 = { 8b450c 2d10bf3400 8b4d08 c1e103 }
- $sequence_58 = { 8b55f8 0fb70a c1e103 33d2 f7f1 8945fc }
- $sequence_59 = { 5e c3 60 89c6 }
- $sequence_60 = { 9a18a15c5d5d5d d6 0055d0 08a50f375d37 }
- $sequence_61 = { 48 35f94e5d5d d6 59 79de 99 }
- $sequence_62 = { 5d 5d b658 1f 79b6 a888 }
- $sequence_63 = { 0055d0 08a50f375d37 5d 37 }
- $sequence_64 = { 5d 5d 285829 5e cb }
+ $sequence_0 = { e8???????? 8bb42434020000 c1e607 68???????? 89b42438020000 8dbe10a10010 }
+ $sequence_1 = { c70424???????? e8???????? c70424???????? 8bf8 56 e8???????? }
+ $sequence_2 = { 51 ff36 8b00 8b00 8986b0010000 ff96bc010000 }
+ $sequence_3 = { 57 ff74241c e8???????? 03c3 0fb73470 }
+ $sequence_4 = { 3c5f 7447 3c2e 7443 3c7e }
+ $sequence_5 = { 8b7c240c 8bcf 8906 8d5101 8a01 41 84c0 }
+ $sequence_6 = { 84c0 740b 80f90d 7519 }
+ $sequence_7 = { 894c241c 85c9 0f84b3000000 8b4020 }
+ $sequence_8 = { 6bc503 40 50 e8???????? be???????? 8d7c2418 }
+ $sequence_9 = { 83c428 50 6a40 6a05 53 ffd6 }
condition:
- 7 of them and filesize <245760
+ 7 of them and filesize <124928
}
-rule MALPEDIA_Win_Soraya_Auto : FILE
+rule MALPEDIA_Win_Keylogger_Apt3_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "17c03046-2ad1-5623-9130-def458833386"
+ id = "0f9f82cd-fdec-56a7-a0cb-1e9762492ad7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.soraya"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.soraya_auto.yar#L1-L230"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.keylogger_apt3"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.keylogger_apt3_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "43793169adfc64c624ebc876524a7869403686546a466d508c127ca9f78faaa7"
+ logic_hash = "d74e9ef23a0b946252054fc1985382779e2408df3e68ecb0420a27d04cacd609"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -132111,45 +139257,32 @@ rule MALPEDIA_Win_Soraya_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8d48bf 80f919 77f2 }
- $sequence_1 = { e8???????? 488d151af0ffff 488d8d60020000 ff15???????? e8???????? 488d8d60020000 488bd0 }
- $sequence_2 = { 57 8bd8 56 53 e8???????? 8b733c }
- $sequence_3 = { 33c1 99 b99a000000 f7f9 b8fe340000 }
- $sequence_4 = { 488bd0 4c8b4850 498bcb 41b86b000000 }
- $sequence_5 = { 41b800300000 ff15???????? 488b8d50010000 4c8d8d48010000 488bd8 488d8540010000 488d1565f4ffff }
- $sequence_6 = { 8b4c2414 33c6 33ce 03c1 }
- $sequence_7 = { 418bd6 3bcb 72c8 4c891d???????? 488d0d1fe0ffff }
- $sequence_8 = { 894df4 0f8501010000 53 56 8b7178 }
- $sequence_9 = { 8b4a0c 8b7210 03c8 8365fc00 8b55fc ff45fc }
- $sequence_10 = { 488d0dfadfffff ff15???????? 488bc8 e8???????? 488d0df5dfffff ff15???????? 488d15f8dfffff }
- $sequence_11 = { 689b558d52 6853d56c36 68ff555535 68f9d6feff 6888888868 }
- $sequence_12 = { 8b45ec 2bf8 037d10 8b45e8 }
- $sequence_13 = { 2bd0 894de0 3bd1 7649 8b55f8 33d6 }
- $sequence_14 = { 03570c 034f0c 807df800 8a540203 8a4c0102 8855fb }
- $sequence_15 = { 8b3d???????? 6a1c 8d45e0 50 6a00 }
- $sequence_16 = { 7444 53 4883ec30 488bd9 b910270000 ff15???????? 8364242800 }
- $sequence_17 = { 488d0d73f8ffff 498bd8 488bfa ff15???????? }
- $sequence_18 = { 56 57 8d85fcfdffff 6800020000 50 e8???????? }
- $sequence_19 = { ff45dc 295de0 4e 75e8 b844060000 0345c8 }
- $sequence_20 = { 7424 56 6a00 683a040000 ff15???????? 8bf0 85f6 }
- $sequence_21 = { 8dbc07fe3ef2ff 8b45d8 33c6 3bbc05be3ef2ff 0f82bdfdffff }
- $sequence_22 = { 8b45fc 8b4dec 8b4508 8b9578ffffff 8b80d8010000 33d3 }
+ $sequence_0 = { 8be8 8d442458 50 55 57 }
+ $sequence_1 = { 3bf3 7523 68???????? ff15???????? 5f }
+ $sequence_2 = { 8b35???????? 8d6b08 55 50 ffd6 }
+ $sequence_3 = { 7453 53 8b5c240c 55 56 8b35???????? 8d6b08 }
+ $sequence_4 = { 89442420 3bf8 7216 5b 5f }
+ $sequence_5 = { ffd6 50 ffd7 ffd3 89442420 83f8ff 7551 }
+ $sequence_6 = { 0fb69695010000 50 0fb68694010000 51 52 50 }
+ $sequence_7 = { 84c0 75f8 2be9 8d5501 52 }
+ $sequence_8 = { e8???????? 68???????? 68???????? 8d4d7c e8???????? 8b45dc }
+ $sequence_9 = { c7442434d8174300 ffd6 8d542404 52 89442434 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <761856
}
-rule MALPEDIA_Win_Madmax_Auto : FILE
+rule MALPEDIA_Win_Caddywiper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "230eedbf-6cae-5fdd-90b6-aea0b58f95e1"
+ id = "24926b93-f761-5ed3-a63e-3417e035ba52"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.madmax"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.madmax_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.caddywiper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.caddywiper_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "8fadf42f6b346841d23791b849b5705de38f9f89679dc44544ef7b477d437506"
+ logic_hash = "79a75ac7d216323abd7ca177a49671b9ea50088d3b0d895d69cfd4d03ce4d9ea"
score = 75
quality = 75
tags = "FILE"
@@ -132163,32 +139296,32 @@ rule MALPEDIA_Win_Madmax_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { d0cd 99 86d6 4c ae 2f 4e }
- $sequence_1 = { b80c32e173 8ac5 08679e fb 59 8050cb80 baef812a0a }
- $sequence_2 = { e07d d8cc 6a55 60 25a237f301 4a 4c }
- $sequence_3 = { 8d8dd0feffff e8???????? 8db396000000 6a3b 9c f605????????d6 0f851c010000 }
- $sequence_4 = { 93 9f 856d67 664c 8657b6 49 152b9be0c2 }
- $sequence_5 = { d9dd 095527 17 44 4b 60 1f }
- $sequence_6 = { f723 56 c8d95bcc 0e 64a04d98f5db 6e 051e079cc8 }
- $sequence_7 = { ad 7ea5 6abd 650e 9c 3528e563a7 6c }
- $sequence_8 = { f605????????e2 0f851d010000 73e7 f22486 85e6 210a e788 }
- $sequence_9 = { f605????????a5 7531 df2e 8b1b f8 b36a 7928 }
+ $sequence_0 = { 8345b404 66837dac00 75c4 c745a800000000 }
+ $sequence_1 = { c68592feffff64 c68593feffff00 c68594feffff76 c68595feffff00 c68596feffff61 c68597feffff00 }
+ $sequence_2 = { 51 e8???????? 83c408 8985b0fbffff c785f4f1ffff00000000 c68588fbffff4c }
+ $sequence_3 = { e9???????? 6a00 8b95acf1ffff 52 ff9564f7ffff }
+ $sequence_4 = { 8b4dfc 8b5508 c7048a00000000 ebd7 }
+ $sequence_5 = { c645b900 c645ba39 c645bb00 c645bc00 c645bd00 8d4d98 898df4f7ffff }
+ $sequence_6 = { c685a3feffff00 c685a4feffff6c c685a5feffff00 c685a6feffff6c c685a7feffff00 }
+ $sequence_7 = { c6459264 c6459300 8d458c 50 8d8d90feffff }
+ $sequence_8 = { 8985fcf7ffff 8d55c0 52 8d45dc }
+ $sequence_9 = { 7407 8b4598 50 ff55fc 8b4594 8be5 }
condition:
- 7 of them and filesize <3227648
+ 7 of them and filesize <33792
}
-rule MALPEDIA_Win_Nokoyawa_Auto : FILE
+rule MALPEDIA_Win_Obscene_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "71f47de5-b877-5435-a43f-09577ab6e252"
+ id = "b0504e00-5509-5e10-82c6-a688a7937d0f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nokoyawa"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nokoyawa_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.obscene"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.obscene_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "a3e5835d9868e848c4cf7b1e58144cc15b3f0d5c2b0274b447bdec70231f3ad8"
+ logic_hash = "62960aba55b9b132d0d487c37c4dacdc8a915363f3251233103a943c3f791f18"
score = 75
quality = 75
tags = "FILE"
@@ -132202,32 +139335,32 @@ rule MALPEDIA_Win_Nokoyawa_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c8 8bc1 8b4c2420 488b9424c0000000 88040a e9???????? 33c0 }
- $sequence_1 = { 488b4c2460 e8???????? 488b442468 4883e0c0 }
- $sequence_2 = { 890424 8b0424 83c003 99 83e203 03c2 c1f802 }
- $sequence_3 = { 488b4c2448 488b0c01 e8???????? 85c0 7511 c605????????01 e8???????? }
- $sequence_4 = { 89442434 e8???????? 488905???????? 8b442434 }
- $sequence_5 = { 48894c2408 4883ec18 48c7042400000000 488b442420 488b0c24 0fb70448 }
- $sequence_6 = { 8b442420 83c014 89442420 837c242040 }
- $sequence_7 = { 880424 488b442410 48c1e005 4803442410 0fb60c24 4803c1 4889442410 }
- $sequence_8 = { 486bc907 8b4c0c20 8b440420 33c1 b904000000 }
- $sequence_9 = { 8b9424a0000000 03d1 8bca 8d8408a1ebd96e 8b4c2414 03c8 }
+ $sequence_0 = { 6a06 68fc421010 ff35???????? 6aff ff15???????? ff7520 }
+ $sequence_1 = { 68e4401010 e8???????? 59 80a0e240101000 68e4401010 e8???????? 59 }
+ $sequence_2 = { 59 6820431010 68e4401010 e8???????? 59 59 85c0 }
+ $sequence_3 = { 0fbe00 83f809 7416 8b45fc 0fbe00 83f80d }
+ $sequence_4 = { 59 80a012109a0000 68???????? e8???????? }
+ $sequence_5 = { 50 e8???????? 59 68???????? 8d85ecf6ffff 50 }
+ $sequence_6 = { 8bec b8400d0300 e8???????? 68360d0300 ff7508 }
+ $sequence_7 = { 59 59 68c4501010 68d83f1010 6814110010 e8???????? }
+ $sequence_8 = { 0fbe00 83f82d 7409 8b45f8 40 8945f8 eb08 }
+ $sequence_9 = { 8365fc00 6a40 ff7508 ff15???????? 59 59 }
condition:
- 7 of them and filesize <92160
+ 7 of them and filesize <2170880
}
-rule MALPEDIA_Win_Cryptoshuffler_Auto : FILE
+rule MALPEDIA_Win_Elise_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "04846f99-89cf-54cb-88bc-877d2656a7fa"
+ id = "f217246a-45c9-5e4c-8fe4-ae9bb248bda8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptoshuffler"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptoshuffler_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.elise"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.elise_auto.yar#L1-L163"
license_url = "N/A"
- logic_hash = "1d3d096bc8fe94bfe59d829c11ff29d324542295a6195d59ed4b925f302177ea"
+ logic_hash = "4bacbe3f48e2ba0fdae2760e38d43f9e3c8b071aa93c58355438ff735f59b16b"
score = 75
quality = 75
tags = "FILE"
@@ -132241,34 +139374,40 @@ rule MALPEDIA_Win_Cryptoshuffler_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 03fb e8???????? 8bf0 3b35???????? 7430 }
- $sequence_1 = { 83c408 85c0 0f8496040000 6aff 6a00 8d442430 50 }
- $sequence_2 = { 6bc830 8b049578f60210 f644082801 7421 57 }
- $sequence_3 = { 0f57c0 c78424f400000000000000 68???????? 8d8c24e8000000 0f298424e8000000 e8???????? }
- $sequence_4 = { c745ec10f80010 894df8 8945fc 64a100000000 8945e8 }
- $sequence_5 = { e9???????? c745dc03000000 eb7c c745e0e04d0210 ebbb }
- $sequence_6 = { 50 ff15???????? 8d842410030000 50 8d84248c010000 50 }
- $sequence_7 = { e8???????? 8904bd78f60210 85c0 7514 6a0c }
- $sequence_8 = { 0f851b010000 8b01 c6400c01 8b31 c6410c00 }
- $sequence_9 = { 0f1f4000 8b06 8b4e08 3bc1 }
+ $sequence_0 = { 0f8461010000 8d847eee040000 50 e8???????? 85c0 }
+ $sequence_1 = { 8bd0 c1ea0b 0fafd7 3bf2 7312 b800080000 }
+ $sequence_2 = { 8bcb 8dbe06050000 f3ab 8bc2 8bcb }
+ $sequence_3 = { 33c9 33db 663b4e06 731a }
+ $sequence_4 = { 8bcf e8???????? 8365f400 c1e004 0145fc 33f6 46 }
+ $sequence_5 = { 894dec 8945f4 8dbeba0a0000 8bc3 8bce }
+ $sequence_6 = { 7cf5 33c9 888f00010000 888f01010000 }
+ $sequence_7 = { 8d3470 d3e0 0945f4 43 83fb04 72e1 8b45f4 }
+ $sequence_8 = { 888f00010000 888f01010000 8bf7 8945f8 }
+ $sequence_9 = { 8d3400 8b44240c 03c6 50 }
+ $sequence_10 = { eb02 d1e8 4e 75f1 }
+ $sequence_11 = { e8???????? 59 59 33c0 e9???????? 8b35???????? }
+ $sequence_12 = { 42 0fb6fa 8a1c07 881c06 }
+ $sequence_13 = { 897df4 8b7d08 03df 0fb63c06 }
+ $sequence_14 = { 837d0c00 8a8800010000 8a9001010000 0f8e93000000 53 }
+ $sequence_15 = { 301f ff45f8 8b7df8 3b7d0c 0f8c7bffffff 5f 5e }
condition:
- 7 of them and filesize <425984
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Sysraw_Stealer_Auto : FILE
+rule MALPEDIA_Win_R980_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a9e810a6-264f-569e-b3d3-a9931864293b"
+ id = "5cd23ce7-fde9-586e-b7d0-c68d0d4730a5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sysraw_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sysraw_stealer_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.r980"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.r980_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "a25f6b3ba819f069101fb648f9516e51ed0f5298199445e1b66fa7cef9e138d8"
+ logic_hash = "6631f2c285d8397109ba8d7d2192a7dc1832567dbf3b5dac3dd0d91311ae325e"
score = 75
- quality = 75
+ quality = 45
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -132280,32 +139419,32 @@ rule MALPEDIA_Win_Sysraw_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 8d9504ffffff 51 8d8508ffffff 52 8d8d0cffffff }
- $sequence_1 = { ffd6 a1???????? ba???????? 8b4814 c1e102 8bf9 8b480c }
- $sequence_2 = { 51 89558c ffd7 8b558c f7d8 1bc0 f7d8 }
- $sequence_3 = { 7507 c745ec01000000 8b4514 8b7de8 2bc7 6800000040 }
- $sequence_4 = { ff15???????? 8b4dc0 894dd4 8d55c4 52 }
- $sequence_5 = { c7400807000000 c7400c0f000000 c740101f000000 c740143f000000 c740187f000000 }
- $sequence_6 = { 89bde0feffff ffd6 8b3d???????? 50 }
- $sequence_7 = { c7420485ae67bb 8b4590 c7400872f36e3c 8b4d90 c7410c3af54fa5 }
- $sequence_8 = { 53 56 57 8bd0 8bf1 8bf8 8bd9 }
- $sequence_9 = { 8975c8 8975b8 8975a8 ff15???????? 8b45d0 8975cc 50 }
+ $sequence_0 = { 51 8d4dd4 e8???????? 837de810 8d45d4 53 0f4345d4 }
+ $sequence_1 = { e8???????? 56 8b08 8b01 ff5070 56 50 }
+ $sequence_2 = { 8d4dbc e8???????? 8d4dd4 e8???????? 8d4da4 e8???????? 8b4df4 }
+ $sequence_3 = { 85c0 7409 ff7608 50 e8???????? c7460800000000 c7460400000000 }
+ $sequence_4 = { 50 e8???????? 8bce e8???????? 8b4d1c 83c418 }
+ $sequence_5 = { 8bc7 f00fc14104 7515 8b01 ff10 8b4db4 8bc7 }
+ $sequence_6 = { ff4654 837e5440 750c c7465400000000 e8???????? 8b4658 83f8f8 }
+ $sequence_7 = { e8???????? 83ec18 8d8424c0000000 8bcc 50 e8???????? e9???????? }
+ $sequence_8 = { 8bc8 e8???????? 33c9 894ddc 8b448dc8 0f57c0 41 }
+ $sequence_9 = { c745fc00000000 8b30 8d45ec 50 e8???????? 83c404 8d4dec }
condition:
- 7 of them and filesize <1540096
+ 7 of them and filesize <3178496
}
-rule MALPEDIA_Win_Chches_Auto : FILE
+rule MALPEDIA_Win_Graftor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a2d17035-5b65-5ddb-9479-7e5b4a4aa253"
+ id = "7d45e232-2e70-5f76-b127-1013459f5457"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chches"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chches_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graftor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graftor_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "90b994c4c0ea91e131f92144cfcd7cc30920c864cbd411a57992ff45077985cd"
+ logic_hash = "2d0bf0ad42127878b7c1f7be3bcb33cc3ba27a99993b023e29cc91abed5bec59"
score = 75
quality = 75
tags = "FILE"
@@ -132319,32 +139458,32 @@ rule MALPEDIA_Win_Chches_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b45f4 8b7dfc 50 8b8628020000 ffd0 8b45f8 85c0 }
- $sequence_1 = { 85c0 7e0b 8b55f8 8b435c 6aff 52 }
- $sequence_2 = { 8d5f18 85db 7477 8b16 8b4244 8b4018 }
- $sequence_3 = { 8b16 8945fc 8b4244 3bc7 0f842b020000 8b00 8b7dfc }
- $sequence_4 = { b810000000 e8???????? 83c420 8945f0 c745f400000000 85c0 0f8405010000 }
- $sequence_5 = { 66890c78 47 ba2a000000 8d8d98fdffff 66891478 8b9680020000 51 }
- $sequence_6 = { 8b4004 85c0 7475 3902 746d 8b4e64 50 }
- $sequence_7 = { 81e980191001 03c1 50 68bfa2c2cd 687f90b056 68a71001fe 686021a031 }
- $sequence_8 = { 895da0 85db 740f 8b87b8010000 8d5594 52 53 }
- $sequence_9 = { c745f401000000 eb1c 50 6a08 ffd2 50 }
+ $sequence_0 = { 8d742434 c684245803000069 e8???????? 8b54241c 53 e8???????? 59 }
+ $sequence_1 = { 55 8bec 51 8365fc00 56 0528010000 }
+ $sequence_2 = { ff750c 8d7de0 ff7508 e8???????? 8b45e8 8945f0 8b45ec }
+ $sequence_3 = { 8d44247c 50 c684245c03000070 e8???????? 83c40c c684245003000071 8b4c241c }
+ $sequence_4 = { 6a00 eb8b 8b7d0c 8b0f 8b4514 394810 7641 }
+ $sequence_5 = { 55 8bec 83e4f8 6aff 687e634c00 64a100000000 }
+ $sequence_6 = { 8901 33c0 40 e9???????? 8365d800 c745dc34ad4800 a1???????? }
+ $sequence_7 = { ff75ec 8d45e0 53 50 8bc6 e8???????? 8b18 }
+ $sequence_8 = { eb05 a1???????? 8b4dfc 33cd e8???????? c9 c3 }
+ $sequence_9 = { 3bc3 0f8686010000 8b87d0000000 6a64 99 5e f7fe }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <294912
}
-rule MALPEDIA_Win_Flagpro_Auto : FILE
+rule MALPEDIA_Win_Moure_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a8700192-f3cd-586a-895f-7ccfc513b903"
+ id = "d5ea53f7-d6a1-5284-9152-98034607f388"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flagpro"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flagpro_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moure"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moure_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "21ab8654968f01505a5a06c6c338da8446a910a647e36c5322e4febf20ea2d89"
+ logic_hash = "e394b210e6ac1eaa6569608ddb349d4dd1ae50231f20d0924074c460f1fa6782"
score = 75
quality = 75
tags = "FILE"
@@ -132358,32 +139497,32 @@ rule MALPEDIA_Win_Flagpro_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8c2480000000 e8???????? 56 c784249c45010001000000 e8???????? }
- $sequence_1 = { 57 6a00 6a00 6aff 68???????? }
- $sequence_2 = { ffd0 c684249400000002 8b442430 3bc3 7408 8b08 8b5108 }
- $sequence_3 = { 56 57 85c0 740b b900030000 8bf3 }
- $sequence_4 = { 8b442428 3bc3 749d eb93 8b442428 8d54243c 895c243c }
- $sequence_5 = { ba10000000 8d6e04 395618 7221 8b4500 eb1e }
- $sequence_6 = { 39ac24c8000000 7210 8b9424b4000000 52 e8???????? 83c404 899c24c8000000 }
- $sequence_7 = { 33ed 55 68???????? 8d842488030000 50 ff15???????? 8db4243c010000 }
- $sequence_8 = { 8bf0 83c408 3bf3 7571 57 }
- $sequence_9 = { 68???????? 8d8424880c0000 6800040000 50 }
+ $sequence_0 = { 3454 43 1558c950cb 0d487b0d4c 36a373801f1e }
+ $sequence_1 = { bf55602540 006b05 bc7d506700 0033 58 bf35b8bf55 58 }
+ $sequence_2 = { 8b35???????? 57 00d6 0075f0 894508 0075fc 00d6 }
+ $sequence_3 = { 51 51 8b0d???????? 56 33f6 85c9 7509 }
+ $sequence_4 = { 837dbc00 7436 0075bc 8d4ddc e8???????? a1???????? 3bc6 }
+ $sequence_5 = { 82a8a200b000c1 8b00 e100 9e d28bd3977e8d 98 }
+ $sequence_6 = { 68b0704000 007014 007010 e8???????? }
+ $sequence_7 = { 5e 53 43 c1c361 5b c9 51 }
+ $sequence_8 = { 8b01 83e03f 3c02 751c 8b4514 8b10 83e23f }
+ $sequence_9 = { 42 c3 874226 c58035b4fe70 5e }
condition:
- 7 of them and filesize <1411072
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Sword_Auto : FILE
+rule MALPEDIA_Win_Rarstar_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "48310a96-8b09-5184-8f0c-c81d31bbe550"
+ id = "1b0cea37-0a1d-5e66-91fc-944e4e50541c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sword"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sword_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rarstar"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rarstar_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "f0b3a1cc57dfaff82b285dd4a0f174f5006c9f22ab9c244578d6f7f68d086b5a"
+ logic_hash = "2e522865d24e8dea587d8aa292c78791c9371361cc03d604920c80f6d8c9bb83"
score = 75
quality = 75
tags = "FILE"
@@ -132397,32 +139536,32 @@ rule MALPEDIA_Win_Sword_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f7d1 2bf9 8d942484020000 8bf7 8bfa }
- $sequence_1 = { ff15???????? 8b8c2434000100 50 8b84243c000100 8d542424 }
- $sequence_2 = { 50 8d54241c 51 52 ff15???????? 85c0 0f8488090000 }
- $sequence_3 = { 49 885c29ff 807d0022 7520 8d7d01 }
- $sequence_4 = { 83c9ff 33c0 8d942488030000 f2ae f7d1 49 }
- $sequence_5 = { 77c8 bf???????? 83c9ff 33c0 f2ae f7d1 }
- $sequence_6 = { b940000000 33c0 8d7c2419 8894241c010000 f3ab }
- $sequence_7 = { 83c9ff 33c0 f2ae f7d1 2bf9 55 }
- $sequence_8 = { 8dbc2494060000 83c9ff 33c0 f2ae f7d1 49 }
- $sequence_9 = { f7d1 49 83f903 77c8 bf???????? }
+ $sequence_0 = { 8a5e01 83e203 c1fb04 c1e204 }
+ $sequence_1 = { 33d2 b903000000 f7f1 83c408 8bc6 }
+ $sequence_2 = { 85ed 7e6f 8a143e 83c703 c1fa02 83e23f 41 }
+ $sequence_3 = { 0f84c1010000 8b2d???????? 8b4c2434 8b54241c 6a00 }
+ $sequence_4 = { 33db 8a940c24010000 8a5c0c24 03c2 03c3 25ff000080 }
+ $sequence_5 = { ffd6 8d84241c020000 68???????? 50 ffd6 8d8c2424040000 68???????? }
+ $sequence_6 = { 8d8c2420030000 51 52 ffd5 8d842418010000 68???????? }
+ $sequence_7 = { 899c242c030000 899c2428030000 899c2424030000 899c2420030000 bf???????? 83c9ff }
+ $sequence_8 = { f7d1 2bf9 899c2430030000 8bc1 8bf7 8bfa }
+ $sequence_9 = { 8a9405ecfdffff 8890a0d74000 eb1c f6c202 7410 8088????????20 8a9405ecfcffff }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <122880
}
-rule MALPEDIA_Win_Ghole_Auto : FILE
+rule MALPEDIA_Win_Taurus_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4005edf0-acd5-5930-97fb-055e6ab03b5d"
+ id = "1d04f49a-1251-5bc9-a2e1-54ed739ba752"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ghole"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ghole_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.taurus_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.taurus_stealer_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "a19f9cff11c120a5d0a63f0160508dc83f879d2586d9f0ffa0e72d02e6aa023f"
+ logic_hash = "5a56120ca5bf111c092d7e02323e7c3983f49990178f81f0fd9b64062b85cfef"
score = 75
quality = 75
tags = "FILE"
@@ -132436,32 +139575,32 @@ rule MALPEDIA_Win_Ghole_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 740d 8b55fc 48 8b45e8 89908c000000 48 8b55e0 }
- $sequence_1 = { 3b45ec 7591 48 8b05???????? 48 8b00 8b15???????? }
- $sequence_2 = { 89c7 e8???????? 85c0 0f85ac160000 8b850cfdffff 48 8d9518fdffff }
- $sequence_3 = { 90 8b4dc8 8b55c4 48 8b5d98 48 8b4598 }
- $sequence_4 = { 8910 48 8b45e8 48 83c018 48 8b55e8 }
- $sequence_5 = { 85c0 7518 8b45e0 89c7 e8???????? 85c0 750a }
- $sequence_6 = { 48 8b45e0 48 895010 48 8d55d4 48 }
- $sequence_7 = { 894c2408 48 83ec78 c744242050000000 c744242403000000 48 8d0540feffff }
- $sequence_8 = { 4c 8945c0 c745ec00000000 8b05???????? 85c0 750a b800000000 }
- $sequence_9 = { 0f847d0f0000 48 8d95a0faffff 48 8d8520fdffff 48 89d6 }
+ $sequence_0 = { 56 8b7508 eb12 8d4e1c e8???????? 8bce e8???????? }
+ $sequence_1 = { 8d4de8 e8???????? 85f6 7408 8d4dd0 e8???????? 8b4508 }
+ $sequence_2 = { 88550f 88450e 8d450e 51 50 8d4d8c e8???????? }
+ $sequence_3 = { 51 50 8bce e8???????? 8d4dcc e8???????? 8d4db4 }
+ $sequence_4 = { 7305 8a5df3 ebf1 8d45f4 c645ff00 50 8bd6 }
+ $sequence_5 = { 8bc2 c1e802 c1e103 8b0483 d3e8 880432 42 }
+ $sequence_6 = { 8d4ddc e8???????? 8d4d90 e8???????? 8d4d84 e8???????? }
+ $sequence_7 = { c74610fe33b90f c7461465dc040b c74618e3804800 c7461cb5492c0d c7462045909c0f c74624dd90c504 c7462870e8f00e }
+ $sequence_8 = { 0f1145c1 885ddf 0fbe4581 250f000080 7905 48 83c8f0 }
+ $sequence_9 = { 40 83f806 7305 8a5df2 ebf1 8d45f3 c645f900 }
condition:
- 7 of them and filesize <622592
+ 7 of them and filesize <524288
}
-rule MALPEDIA_Win_Simda_Auto : FILE
+rule MALPEDIA_Win_Casper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "be795d70-d5c5-5e96-885a-c6d393925d47"
+ id = "682d09f5-eba1-5466-8515-62dee225f20a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.simda"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.simda_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.casper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.casper_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "3de0f7a52fa615dd54916d8a958f210fe06f4ad101457fb659a131786ec59f6f"
+ logic_hash = "901b4babc945e8ca2e1c5355e28b2f0271cc8d172828c522a735944d40fb2e3b"
score = 75
quality = 75
tags = "FILE"
@@ -132475,32 +139614,32 @@ rule MALPEDIA_Win_Simda_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 c745fc04010000 a4 e8???????? }
- $sequence_1 = { 3bce 8945f4 1bc0 40 57 895dfc }
- $sequence_2 = { c7049f00000000 75f6 8b0f 894d08 }
- $sequence_3 = { 760d 8b7d08 83c704 8d4eff 33c0 }
- $sequence_4 = { c1e110 0b4df4 03d6 83ceff 2bca }
- $sequence_5 = { 8b0d???????? 8945d4 a1???????? 8955dc 0fb615???????? }
- $sequence_6 = { c1eb10 3bce 7601 4b c1ef10 }
- $sequence_7 = { 83c408 85c0 74e4 6a0a 6a00 56 c60000 }
- $sequence_8 = { 8bd1 c1ea10 8955ec 8bf8 }
- $sequence_9 = { 41 eb08 83c102 eb03 83c103 }
+ $sequence_0 = { 47 57 50 6801000080 e8???????? 85c0 756f }
+ $sequence_1 = { e8???????? 8b7b34 85ff 7405 e8???????? }
+ $sequence_2 = { 885006 8b55fc c1ea18 885007 8bd3 c1ea08 885009 }
+ $sequence_3 = { 51 a1???????? 85c0 751a e8???????? 689c9678bf 68???????? }
+ $sequence_4 = { 837de803 752a 837df808 8b75f4 7514 85f6 742b }
+ $sequence_5 = { 8bbb48010000 8b8b68010000 33d2 8bc7 f7f1 85d2 7406 }
+ $sequence_6 = { 8bd8 8d4510 50 81ce19000200 }
+ $sequence_7 = { 85ff 7405 e8???????? 8bce e8???????? 5f 5e }
+ $sequence_8 = { 50 57 57 6800000008 53 57 57 }
+ $sequence_9 = { 7504 8bde eb03 83c305 68???????? 53 e8???????? }
condition:
- 7 of them and filesize <1581056
+ 7 of them and filesize <434176
}
-rule MALPEDIA_Win_8T_Dropper_Auto : FILE
+rule MALPEDIA_Win_Gemcutter_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "62f20b6c-23f8-52e5-8f38-7d977c3fc023"
+ id = "e94125d6-f7ee-5626-bb13-57f31cd4995b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.8t_dropper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.8t_dropper_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gemcutter"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gemcutter_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "f24ad3d6bfd5a20c8c809ac43affb0600d938cb9b1cb9cd8c47771e603e82a25"
+ logic_hash = "cdd9767cb466abee0d56200d0aa911cbda817b83008ef2825b381668a5ec2a45"
score = 75
quality = 75
tags = "FILE"
@@ -132514,32 +139653,32 @@ rule MALPEDIA_Win_8T_Dropper_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 741b 56 6800700000 6a01 68???????? }
- $sequence_1 = { ff74240c e8???????? 83c40c c3 8b442408 83f801 }
- $sequence_2 = { c6440c0e6e 8d4c2408 51 683f000f00 50 }
- $sequence_3 = { 68???????? 50 ff15???????? 85c0 7559 8b4c2408 51 }
- $sequence_4 = { 50 ff15???????? 85c0 7559 8b4c2408 }
- $sequence_5 = { 49 c6440c0c52 c6440c0d75 c6440c0e6e }
- $sequence_6 = { 68???????? 6a02 50 8b442418 }
- $sequence_7 = { 7559 8b4c2408 51 ff15???????? }
- $sequence_8 = { 6800700000 6a01 68???????? e8???????? 56 e8???????? }
- $sequence_9 = { ff15???????? 8d942410010000 6804010000 52 68???????? }
+ $sequence_0 = { ff75fc ff15???????? eb09 ff75fc ff15???????? 3975fc }
+ $sequence_1 = { 8d8500fcffff 50 e8???????? 59 56 ff15???????? }
+ $sequence_2 = { 56 ffd7 53 56 56 56 }
+ $sequence_3 = { 59 53 50 ffd6 0fbe85f0f8ffff 50 }
+ $sequence_4 = { 6a01 ff15???????? 6a01 68???????? e8???????? 6a01 }
+ $sequence_5 = { 50 ff15???????? 83c420 8818 8d85f0fdffff 50 8d85f0f8ffff }
+ $sequence_6 = { 8d85f0fdffff 50 ffd7 8d85f0f8ffff 6800040000 50 }
+ $sequence_7 = { 8d45ac 56 50 e8???????? 83c40c 8d45f0 c745d801000000 }
+ $sequence_8 = { ff15???????? 85c0 0f84df000000 8d85f0f8ffff 68???????? 50 e8???????? }
+ $sequence_9 = { c3 55 8bec 81ec00040000 56 57 68???????? }
condition:
- 7 of them and filesize <147456
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Hlux_Auto : FILE
+rule MALPEDIA_Win_Smarteyes_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0554b2ef-0799-5994-8001-d3a987727985"
+ id = "60f92ddb-7402-5d47-97fc-69a2fdffb7f3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hlux"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hlux_auto.yar#L1-L158"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.smarteyes"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.smarteyes_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "53ff7358e541a46f4d140f6dc71959f0fd15f8b04731bebe36051fa435d4979d"
+ logic_hash = "8c2da2c0cae87308c8e6e0dfb55ae530bef3c36e3693a233b1d96edfb1425c3c"
score = 75
quality = 75
tags = "FILE"
@@ -132553,40 +139692,34 @@ rule MALPEDIA_Win_Hlux_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 81f949e2a499 750b 83f90e 7406 }
- $sequence_1 = { 0101 c9 c3 6a10 }
- $sequence_2 = { 0009 1b4e01 e405 9d }
- $sequence_3 = { 0088aa4b0023 d18a0688078a 46 018847018a46 }
- $sequence_4 = { 0130 8b13 8b08 85d2 }
- $sequence_5 = { b8e3062de4 09c0 7506 898550ffffff 8b8550ffffff ba205af5bb }
- $sequence_6 = { 7545 8945fc 8b45f0 895de8 81f97a701028 7534 }
- $sequence_7 = { 0104b9 33c9 83c408 85c0 }
- $sequence_8 = { 010f 840f 0000 008365f0fe8b }
- $sequence_9 = { 8b0d???????? 85c9 753f 83f963 753a 8945fc 83f93f }
- $sequence_10 = { 0104bb 8d1447 89542418 e9???????? }
- $sequence_11 = { 895de8 33f6 8955cc 83fe13 7503 8975fc 5e }
- $sequence_12 = { 0000 008365f0fe8b 4d 0883c108e918 }
- $sequence_13 = { 8945e0 83f9f3 7507 09c9 7403 }
- $sequence_14 = { 81fb2e5ca766 7503 895de8 8945d4 }
- $sequence_15 = { 83fbd5 7413 33c0 83f827 7403 }
+ $sequence_0 = { 51 8d85d4fdffff 50 e8???????? 8d85d4fdffff 889c35d4fdffff 83c40c }
+ $sequence_1 = { 68???????? e9???????? 53 68???????? e8???????? 33c0 40 }
+ $sequence_2 = { 3bc3 0f8426030000 8d842488040000 50 6804010000 ff15???????? 85c0 }
+ $sequence_3 = { 7478 83c00c 8bc8 8d7901 8a11 41 84d2 }
+ $sequence_4 = { 7413 8d85ecfeffff 57 50 }
+ $sequence_5 = { ff742424 ff742420 ff15???????? 85c0 7547 }
+ $sequence_6 = { e8???????? 59 59 8d8548f5ffff 50 8d9d78f7ffff e8???????? }
+ $sequence_7 = { 7514 8bf9 c744241001000000 e8???????? e9???????? 68???????? 8d442424 }
+ $sequence_8 = { 8d45ff 50 e8???????? 8a4736 8845ff 53 8d45ff }
+ $sequence_9 = { 8bd6 0fb7c0 6683f82f 7406 6683f85c 7502 8bca }
condition:
- 7 of them and filesize <3147776
+ 7 of them and filesize <429056
}
-rule MALPEDIA_Win_Darkme_Auto : FILE
+rule MALPEDIA_Win_Nymaim_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "08b1ecd8-4245-5b36-9b97-82dc7b781460"
+ id = "6fe09b40-4e7e-5960-9e2c-823057d831db"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkme"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkme_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nymaim"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nymaim_auto.yar#L1-L281"
license_url = "N/A"
- logic_hash = "8ec0d0c962cec5e0ecd8c6f133e096757eb87617c4861f80c1b1cf3c91f3cada"
+ logic_hash = "0c0c73586cb65f92c931bae46a77127eb659bbbab03ac07a837f2712a17a227b"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -132598,32 +139731,51 @@ rule MALPEDIA_Win_Darkme_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8dbddcfcffff f3ab b964000000 8dbd18fbffff 68???????? 8985d8fcffff 8985d4fcffff }
- $sequence_1 = { 51 8d55d4 52 6a02 ff15???????? 83c40c 8d45c4 }
- $sequence_2 = { 8b8518ffffff 8b08 8b9518ffffff 52 ff5114 dbe2 }
- $sequence_3 = { 6a00 ff15???????? 50 8b558c 81c2???????? 52 ff15???????? }
- $sequence_4 = { c745880a000000 8b8530ffffff 50 ff15???????? 8945a0 c7459808000000 8b4dd4 }
- $sequence_5 = { 8b8500ffffff 50 8b8dfcfeffff 51 ff15???????? 898594feffff eb0a }
- $sequence_6 = { 05???????? 898588feffff eb12 8b8db4feffff 81c1???????? 898d88feffff 8b9588feffff }
- $sequence_7 = { 83c42c 51 68???????? ff15???????? 85c0 0f851afeffff }
- $sequence_8 = { 8b5144 52 8d8524ffffff 50 8d8d54ffffff 51 ff15???????? }
- $sequence_9 = { 8b08 8b95fcfeffff 52 ff5120 }
+ $sequence_0 = { 89d8 01c8 31d2 f7f7 }
+ $sequence_1 = { 0f94c1 09c8 6bc064 09c0 }
+ $sequence_2 = { 31d2 f7f7 92 31d2 }
+ $sequence_3 = { 92 31d2 bf64000000 f7f7 }
+ $sequence_4 = { c1e105 01c8 c1c307 30c3 }
+ $sequence_5 = { 31c9 38f0 83d100 38d0 83d900 c1e105 }
+ $sequence_6 = { c1eb13 331d???????? 31c3 c1e808 }
+ $sequence_7 = { 00d3 8a16 301e 46 01fb }
+ $sequence_8 = { 8b12 8b4d0c 8b5d18 8b1b 4f 31c0 fec2 }
+ $sequence_9 = { 8b4e08 014e04 8b5e0c 015e08 }
+ $sequence_10 = { c1e808 31c3 895e0c 89d8 }
+ $sequence_11 = { f7e0 0fc8 01d0 894704 }
+ $sequence_12 = { 8b06 c1e00b 3306 8b5604 0116 8b4e08 014e04 }
+ $sequence_13 = { 53 56 57 83ec44 8b4508 8d0d2030d201 }
+ $sequence_14 = { 4409df 4531d0 813d????????7147ed3a 0f84c06efdff 4421da 4431c7 c1c703 }
+ $sequence_15 = { 0f84e0bffcff 443b642460 72b4 85ff 7439 837c246000 7628 }
+ $sequence_16 = { 4531c9 488d442440 813d????????00e8e23a 0f84c1f7feff 31d2 48b9????????00000000 488903 }
+ $sequence_17 = { 448915???????? 8b4548 89442448 488b8588000000 4889442440 488b8580000000 4889442438 }
+ $sequence_18 = { 56 83ec28 8b450c 8b4d08 8d154e30d201 }
+ $sequence_19 = { 55 89e5 83ec10 8b4508 8d0d3430d201 }
+ $sequence_20 = { 83ec44 8b4508 8d0d2030d201 31d2 890c24 c744240400000000 }
+ $sequence_21 = { 0f9e05???????? 4c89fa e8???????? 488d542440 488d8da0000000 890d???????? 8805???????? }
+ $sequence_22 = { 4439a19c000000 0f8456bffcff 4439a194000000 48c705????????b2228979 0f8545bffcff 8b7108 458d6c2401 }
+ $sequence_23 = { 31ed e8???????? 0fb7542430 488d4c2420 0fb7442432 4189d8 c1e209 }
+ $sequence_24 = { 5b 5d c3 8b45f0 8b0c850440d201 }
+ $sequence_25 = { 890424 894c2404 e8???????? 8d0d3430d201 }
+ $sequence_26 = { 31c9 8b55f4 8b75ec 89723c c7424003000000 }
+ $sequence_27 = { 4529d8 4489da 4801ca e8???????? 66813d????????a8c1 0f848bbe0000 44295b68 }
+ $sequence_28 = { 31d2 890c24 c744240400000000 8945f4 8955f0 e8???????? 8d0d8630d201 }
condition:
- 7 of them and filesize <1515520
+ 7 of them and filesize <2375680
}
-rule MALPEDIA_Win_Hazy_Load_Auto : FILE
+rule MALPEDIA_Win_Reactorbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f9ce3341-35f2-576a-ac44-5d1a215a7e85"
+ id = "db667bb6-5a2a-5433-bb3f-44b94a1b8ccd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hazy_load"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hazy_load_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.reactorbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.reactorbot_auto.yar#L1-L159"
license_url = "N/A"
- logic_hash = "2293495fdcc042b4bc9589ccdd3e32857e18de0ce6c242812538dc1d663eb294"
+ logic_hash = "a8dd74cde779dbd1edde8ec6ea240ea579363dd37eac297b9622688e884b36e8"
score = 75
quality = 75
tags = "FILE"
@@ -132637,32 +139789,38 @@ rule MALPEDIA_Win_Hazy_Load_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b904000000 4c8d05f5c50000 488d15aeb20000 e8???????? 488bf8 4885c0 740f }
- $sequence_1 = { 48897c2408 488b15???????? 488d3dd16d0100 8bc2 b940000000 83e03f 2bc8 }
- $sequence_2 = { 488d0db8200100 4183e23f 4903e8 832700 498bf0 }
- $sequence_3 = { 488bf1 41bc02000000 4489742420 418bcc 448d4205 ff15???????? }
- $sequence_4 = { 4b87bcf750140200 33c0 488b5c2450 488b6c2458 488b742460 }
- $sequence_5 = { 483b0d???????? 7417 488d0570630100 483bc8 740b 83791000 7505 }
- $sequence_6 = { 4883675000 488d05ade0ffff 83675800 488d4f28 }
- $sequence_7 = { 488d15a96a0100 83e13f 488bc5 48c1f806 48c1e106 }
- $sequence_8 = { 442bc3 4803d0 4533c9 488bce ff15???????? 85c0 0f8eacfeffff }
- $sequence_9 = { 488d0dc0210100 4183e23f 4903e8 832300 }
+ $sequence_0 = { 50 ff15???????? 8d8d90fdffff 51 8d9580f9ffff }
+ $sequence_1 = { c745f400000000 c745e800000000 c745e400000000 a1???????? 8945e0 }
+ $sequence_2 = { 7418 6aff a1???????? 50 ff15???????? }
+ $sequence_3 = { 837dfcff 7411 8b4dfc 51 ff15???????? }
+ $sequence_4 = { 8b4d08 51 ff15???????? 83c404 8945f0 }
+ $sequence_5 = { 8b4508 50 6804010000 8d8d78f7ffff 51 e8???????? }
+ $sequence_6 = { ff15???????? 8945fc 837dfc00 7479 837dfcff }
+ $sequence_7 = { 7420 8b0d???????? 51 8b15???????? 52 }
+ $sequence_8 = { 83c005 99 b905000000 f7f9 }
+ $sequence_9 = { 6bc005 83e803 99 b999000000 }
+ $sequence_10 = { 69c0b13a0200 99 83e203 03c2 }
+ $sequence_11 = { e8???????? 833d????????00 7509 833d????????00 740b }
+ $sequence_12 = { eb0c c705????????b80b0000 eb0a c705????????e8030000 }
+ $sequence_13 = { 83e101 f7d9 81e12083b8ed 33c1 }
+ $sequence_14 = { 483d00080000 7323 4863442450 488b4c2468 0fb609 888c04e0030000 }
+ $sequence_15 = { 83e203 03c2 c1f802 89442410 8b4c240c }
condition:
- 7 of them and filesize <315392
+ 7 of them and filesize <1032192
}
-rule MALPEDIA_Win_Unidentified_108_Auto : FILE
+rule MALPEDIA_Win_Nightclub_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "91d0ee32-15d3-5f4b-b0c7-e219a3fb056f"
+ id = "fe7b22ba-512f-5e91-8935-479f32d64f06"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_108"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_108_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nightclub"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nightclub_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "bc8d7e8276cd214c62a44b786052de8d0d6c82c70c52e7e29cb797627cab2825"
+ logic_hash = "3d19b2fe0d45f47ba38d0f6076660c3269a68cbecd47ee885f31f66a44204ee7"
score = 75
quality = 75
tags = "FILE"
@@ -132676,32 +139834,32 @@ rule MALPEDIA_Win_Unidentified_108_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d05c7580100 4a8b0ce8 42385cf938 7d4f 400fbece 4084f6 }
- $sequence_1 = { 0f8493010000 488d2d3a100100 83635000 83632c00 e9???????? 48ff4318 837b2800 }
- $sequence_2 = { 660feb0d???????? 4c8d0d44950000 f20f5cca f2410f590cc1 660f28d1 660f28c1 4c8d0d0b850000 }
- $sequence_3 = { 7426 488d5540 803201 488d5201 41ffc0 488d4540 498bcc }
- $sequence_4 = { 4c8d05a8310100 83e23f 488d14d2 498b04c0 f644d03801 }
- $sequence_5 = { 488d1dd6db0100 458bc5 498bcc 48ffc1 4438040b 75f7 4885c9 }
- $sequence_6 = { 458bc5 498bc4 90 48ffc0 44380401 }
- $sequence_7 = { 0fb6557f 4889451f 83f201 488d05dbc90000 49c1e302 4889452f 03d2 }
- $sequence_8 = { 488d9588000000 803201 488d5201 41ffc0 488d8588000000 }
- $sequence_9 = { 7350 488bca 4c8d051d310100 83e13f 488bc2 48c1f806 }
+ $sequence_0 = { ff4808 83c404 3b7514 75b4 5f 5b 8b450c }
+ $sequence_1 = { 8d4dd0 c645f300 ff15???????? 8b4d08 8d45c0 50 51 }
+ $sequence_2 = { 8d75bc e8???????? 8d75e0 e8???????? eb33 8b55bc 8b7d08 }
+ $sequence_3 = { 8da42400000000 8a4701 47 84c0 75f8 b90b000000 be???????? }
+ $sequence_4 = { 83c404 6a00 56 53 8bf8 ff15???????? }
+ $sequence_5 = { 85c0 7505 a1???????? 8bc8 8bff 8a10 40 }
+ $sequence_6 = { 83c408 8bc8 ff15???????? 5f 5e 8be5 5d }
+ $sequence_7 = { 5b b87fe0077e f7ef c1fa08 8bfa c1ef1f 03fa }
+ $sequence_8 = { 8b45f0 83c010 83c310 8945f0 3bc6 75dc }
+ $sequence_9 = { c645f200 ff15???????? c745e001000000 85db 0f848c010000 8b15???????? 8b450c }
condition:
- 7 of them and filesize <307200
+ 7 of them and filesize <247808
}
-rule MALPEDIA_Win_Mocton_Auto : FILE
+rule MALPEDIA_Win_Unidentified_100_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "72b425f0-e1bd-580c-ba97-36f1bcb1157c"
+ id = "ef81c2e4-5fa3-571d-bebe-aeaf2bbd4859"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mocton"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mocton_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_100"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_100_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "f466c26ab0d8cd5071e2b5a32b6cc128a028215985bbf34b30810ffd494c9c82"
+ logic_hash = "144a60b0164255f58e6624e761b77d4aa80b8a589ef3259bf29c12a9ff5a78b0"
score = 75
quality = 75
tags = "FILE"
@@ -132715,32 +139873,32 @@ rule MALPEDIA_Win_Mocton_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4db8 81e1dbb036e4 33c8 334db8 8b55b8 83c201 8955b8 }
- $sequence_1 = { 0b55d0 8b45d0 83e801 8945d0 85d2 741e 8b4dd0 }
- $sequence_2 = { 898584feffff e9???????? 8b8d9cfeffff 83e901 898d9cfeffff 8b959cfeffff 8b859cfeffff }
- $sequence_3 = { b901000000 85c9 741d 8b955ceaffff c1e206 81ca2bb0d5ca 03955ceaffff }
- $sequence_4 = { 0b8dcce9ffff 898dcce9ffff e9???????? 8b95cce9ffff 69d237b0cb41 33c0 81fa237558e2 }
- $sequence_5 = { 7353 8bc1 c1f805 8bf1 8d3c85004d4400 8b07 83e61f }
- $sequence_6 = { 7e3e b8913b77ee 2b8508fdffff 398508fdffff 7c17 8b8d08fdffff c1e105 }
- $sequence_7 = { 0f94c1 81c9efb286ac 7412 8b956cfcffff 039560fcffff 89956cfcffff c785acfcffffeed81864 }
- $sequence_8 = { 894dec eb12 8b55f8 2b55ec 8955f8 8b45ec 83c001 }
- $sequence_9 = { c1e009 05335b8425 2385e4e9ffff 0b85ece9ffff 8985ece9ffff 8b8de4e9ffff }
+ $sequence_0 = { 488d9424f0030000 488b4c2448 e8???????? e9???????? 4c8d8c2490070000 4533c0 488d942470130000 }
+ $sequence_1 = { 4889442420 4c8d8c24e0020000 448b442458 8b54245c 8b4c2454 }
+ $sequence_2 = { 0f8dac000000 c644242000 eb0b 0fb6442420 fec0 88442420 0fb6442420 }
+ $sequence_3 = { 448bc3 488d1580860000 e8???????? 85c0 7429 }
+ $sequence_4 = { 488bf8 33c0 b9fe010000 f3aa 4c8b8c24b8060000 4c8b8424b0060000 488d156dfd0100 }
+ $sequence_5 = { eb1d 488d05a7690100 ffcb 488d0c9b 488d0cc8 ff15???????? ff0d???????? }
+ $sequence_6 = { 488d05a7690100 ffcb 488d0c9b 488d0cc8 ff15???????? }
+ $sequence_7 = { ffc0 8944243c 486344243c 483b442458 7320 486344243c }
+ $sequence_8 = { 33c0 b97a010000 f3aa 488d8424b0190000 488d0deee80100 }
+ $sequence_9 = { 488b842490030000 4889842490000000 48c7442458ffffffff 48ff442458 488b842490000000 488b4c2458 66833c4800 }
condition:
- 7 of them and filesize <573440
+ 7 of them and filesize <372736
}
-rule MALPEDIA_Win_Pngdowner_Auto : FILE
+rule MALPEDIA_Win_Sedll_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "31e7b95d-0a01-5118-aefe-72f10c1de52f"
+ id = "009a21d7-9a67-5650-8e55-9cfcfc21e0f2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pngdowner"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pngdowner_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sedll"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sedll_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "73611f5253baf7f95cf22059dc76ddead3ab9941ef229c965d83aeede8e284a3"
+ logic_hash = "21c4f01124bd0cd6ba61129966ab2fcf5cc6cd643797282b60948edf1b57805e"
score = 75
quality = 75
tags = "FILE"
@@ -132754,32 +139912,32 @@ rule MALPEDIA_Win_Pngdowner_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4508 c705????????01000000 50 a3???????? e8???????? 8db6bcdc4000 bf???????? }
- $sequence_1 = { ff15???????? 85c0 a3???????? 741b 6a00 6a00 }
- $sequence_2 = { 7552 833c8580e0400000 53 57 }
- $sequence_3 = { c74050c0b54000 c7401401000000 c3 56 57 ff15???????? }
- $sequence_4 = { c1ff05 83e11f 8b3cbd40e64000 8d0cc9 8d3c8f eb05 bf???????? }
- $sequence_5 = { 83c8ff 5b 81c420000100 c3 8b3d???????? 8d4c2420 }
- $sequence_6 = { ff74240c e8???????? 83c40c c3 e8???????? 8b4c2404 894814 }
- $sequence_7 = { c3 33c0 5e c3 8b442404 c74050c0b54000 }
- $sequence_8 = { 8b1d???????? b900400000 33c0 8d7c2420 8d542420 }
- $sequence_9 = { ff742404 e8???????? 59 c3 56 8bf1 6a1b }
+ $sequence_0 = { 6a00 6a00 6a00 8d8424b0030000 }
+ $sequence_1 = { 50 ff15???????? 8b4df8 85c9 7407 }
+ $sequence_2 = { 74e3 57 33c9 33ff 85db 0f848f000000 }
+ $sequence_3 = { 56 6800010000 8d85f0feffff 8bf1 6880000000 50 }
+ $sequence_4 = { 8d842484010000 50 8d842498030000 50 ff15???????? }
+ $sequence_5 = { 6a00 53 e8???????? 83c410 6a00 6a00 ff75f4 }
+ $sequence_6 = { ff15???????? 85c0 7523 85ff }
+ $sequence_7 = { 57 6aff ff75fc 6a00 6a00 ffd3 8bc7 }
+ $sequence_8 = { 8b4514 8908 a1???????? 50 }
+ $sequence_9 = { 7604 8bf8 2bfb 8d7701 56 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Socksbot_Auto : FILE
+rule MALPEDIA_Win_Prestige_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9bcf8cfe-6674-56a4-ae23-27a14bd76431"
+ id = "554de8b7-e6ad-5535-8c14-f95b90ec653d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.socksbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.socksbot_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.prestige"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.prestige_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "751966a23ad60ac8819a9938a949afcb7d6a09a99a37898a0110d849f807b7bf"
+ logic_hash = "3d9139c6507e377e5a1b52cf299e6f205e8499ed341925da786360ebd802ec9b"
score = 75
quality = 75
tags = "FILE"
@@ -132793,32 +139951,32 @@ rule MALPEDIA_Win_Socksbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a50 ff7508 33f6 8975fc e8???????? 8bd8 59 }
- $sequence_1 = { 59 e9???????? 55 8bec ff4d0c 7509 ff7508 }
- $sequence_2 = { 46 8a1c39 41 3b4d0c 7cce 5f 8935???????? }
- $sequence_3 = { 6a00 ff7508 6a03 e8???????? 83c410 ff7704 }
- $sequence_4 = { 48 741b 48 7536 53 }
- $sequence_5 = { e8???????? 8bd8 8b45fc 8945f0 83c008 }
- $sequence_6 = { 8b75fc 53 ff15???????? 57 e8???????? }
- $sequence_7 = { 75ed ff7508 6bc94c 8b5dfc 03cf 51 53 }
- $sequence_8 = { 8a0c37 880e 4a 75f7 }
- $sequence_9 = { 81c60c000100 4b 75d2 68???????? ff15???????? a0???????? }
+ $sequence_0 = { 894648 8b7a4c 897e4c 837a4c10 7706 }
+ $sequence_1 = { 03f3 c706652b3030 8d4604 33d2 e9???????? 8bd1 c745c409000000 }
+ $sequence_2 = { 83f826 7603 6a26 58 0fb60c85be534700 0fb63485bf534700 }
+ $sequence_3 = { b9fe020000 3bc1 0f4fc1 8d8decfcffff 50 8985e8fcffff e8???????? }
+ $sequence_4 = { 3bf0 730a 8bc6 89742410 897c2414 50 ff7508 }
+ $sequence_5 = { 8d45fc 50 8bd6 e8???????? 8b7508 8bf8 59 }
+ $sequence_6 = { 8bf2 57 8bf9 8d4e02 668b06 83c602 6685c0 }
+ $sequence_7 = { 85c0 740c 8d432c 8945f8 8b00 }
+ $sequence_8 = { 8945d8 8b45e8 5e 13ce f765e0 6a00 8945ec }
+ $sequence_9 = { 59 c3 8b4c240c 68???????? e8???????? 8b44240c 5e }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <1518592
}
-rule MALPEDIA_Win_Cruloader_Auto : FILE
+rule MALPEDIA_Win_Tarsip_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "975bd752-b718-50f1-9af8-cfa41728edc9"
+ id = "4ad2adc0-f292-5e9b-b3e6-4bd61bcff987"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cruloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cruloader_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tarsip"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tarsip_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "a1572c6250fefbf1b80a173c44c61e578e12fe07ff0f92d960b828b4e32b23d4"
+ logic_hash = "228c42e725c96bb3ed688957a36bb59d0b21035a6d52aae02eb400f7262ce8f7"
score = 75
quality = 75
tags = "FILE"
@@ -132832,32 +139990,32 @@ rule MALPEDIA_Win_Cruloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 ff15???????? 6a04 6800100000 ff35???????? 6a00 }
- $sequence_1 = { 6bf638 8b0c8dd85e4100 80643128fd 5f 5e c9 c3 }
- $sequence_2 = { 0f1005???????? 50 0f1145e0 ff15???????? 33c9 90 8a540dd0 }
- $sequence_3 = { 3bf7 72e9 5f f7d0 5e 8be5 }
- $sequence_4 = { 88540dc0 41 3bc8 7ced }
- $sequence_5 = { 83c404 0f1000 6a00 0f1185ccfbffff ff15???????? }
- $sequence_6 = { 833d????????00 0f851c0e0000 8d0db02f4100 ba1b000000 e9???????? a900000080 7517 }
- $sequence_7 = { 7309 80341961 41 3bca 72f7 e8???????? 8d45ec }
- $sequence_8 = { 0f8c5cffffff c705????????01000000 8b7d08 83c8ff }
- $sequence_9 = { 0f8494010000 8bb5e4fcffff 8d45f4 50 ff7354 57 ff75e8 }
+ $sequence_0 = { 8884244f840000 e8???????? 8d94240c840000 52 }
+ $sequence_1 = { ff15???????? 89ae14420100 8b8610420100 3bc5 }
+ $sequence_2 = { ff15???????? 898614420100 85c0 754f }
+ $sequence_3 = { 80fa2f 7505 b83f000000 8d148500000000 8b442420 c1fa02 c1e106 }
+ $sequence_4 = { ff15???????? 5b 33c0 5e c3 57 6a00 }
+ $sequence_5 = { 8b08 038ea4830000 8b54240c 8a02 8801 }
+ $sequence_6 = { e8???????? 50 e8???????? e8???????? 99 b980841e00 }
+ $sequence_7 = { e8???????? 83c404 c746180f000000 895e14 885e04 8b4c240c 64890d00000000 }
+ $sequence_8 = { 8b442418 0374241c 53 8d542418 52 53 53 }
+ $sequence_9 = { 83bc240c01000010 7210 8b9424f8000000 52 e8???????? 83c404 c784240c0100000f000000 }
condition:
- 7 of them and filesize <196608
+ 7 of them and filesize <360448
}
-rule MALPEDIA_Win_Smarteyes_Auto : FILE
+rule MALPEDIA_Win_Pipcreat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "60f92ddb-7402-5d47-97fc-69a2fdffb7f3"
+ id = "38c9ab7f-3633-5cf9-b43a-1054dcf3eb2e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.smarteyes"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.smarteyes_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pipcreat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pipcreat_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "8c2da2c0cae87308c8e6e0dfb55ae530bef3c36e3693a233b1d96edfb1425c3c"
+ logic_hash = "c78f35b80acd6d02ab8a3808b0a24320b25c92c8bd70c4aff6d75dba01d58da4"
score = 75
quality = 75
tags = "FILE"
@@ -132871,32 +140029,32 @@ rule MALPEDIA_Win_Smarteyes_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 8d85d4fdffff 50 e8???????? 8d85d4fdffff 889c35d4fdffff 83c40c }
- $sequence_1 = { 68???????? e9???????? 53 68???????? e8???????? 33c0 40 }
- $sequence_2 = { 3bc3 0f8426030000 8d842488040000 50 6804010000 ff15???????? 85c0 }
- $sequence_3 = { 7478 83c00c 8bc8 8d7901 8a11 41 84d2 }
- $sequence_4 = { 7413 8d85ecfeffff 57 50 }
- $sequence_5 = { ff742424 ff742420 ff15???????? 85c0 7547 }
- $sequence_6 = { e8???????? 59 59 8d8548f5ffff 50 8d9d78f7ffff e8???????? }
- $sequence_7 = { 7514 8bf9 c744241001000000 e8???????? e9???????? 68???????? 8d442424 }
- $sequence_8 = { 8d45ff 50 e8???????? 8a4736 8845ff 53 8d45ff }
- $sequence_9 = { 8bd6 0fb7c0 6683f82f 7406 6683f85c 7502 8bca }
+ $sequence_0 = { 50 ffd6 85c0 751b 8d851cfeffff c7851cfeffff14010000 }
+ $sequence_1 = { 6a00 8d442420 6a00 50 6a01 6a02 6a20 }
+ $sequence_2 = { 8b4c2404 68???????? 6a01 51 ff15???????? 85c0 }
+ $sequence_3 = { 56 ff15???????? 85c0 741d 6a30 6868420010 }
+ $sequence_4 = { e9???????? 83bd20feffff04 770a 6888410010 e9???????? 83bd20feffff05 8b35???????? }
+ $sequence_5 = { 56 57 be9c400010 8d7df8 8d45f8 a5 50 }
+ $sequence_6 = { eb12 6838470010 ff15???????? 6a20 6898420010 }
+ $sequence_7 = { 59 8d8538ffffff 6a28 50 }
+ $sequence_8 = { 7426 50 50 50 8b15???????? }
+ $sequence_9 = { be???????? 8d7c2414 33c0 f3a5 b975000000 }
condition:
- 7 of them and filesize <429056
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Alphanc_Auto : FILE
+rule MALPEDIA_Win_Yarat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3e24a753-bd90-55fc-a721-b43ae19ca82e"
+ id = "9b4289ae-23e7-5628-ab26-1ca831bf886f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alphanc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alphanc_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yarat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yarat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "76f5a4c48b7d4b7a92e132b26eac0da2bf874f9a491b16e025e278e5810143fc"
+ logic_hash = "6ef74e5effac24b08695314060e4e7e4519b854f50f85d73d7052d0ace49145b"
score = 75
quality = 75
tags = "FILE"
@@ -132910,32 +140068,32 @@ rule MALPEDIA_Win_Alphanc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c3 8b4c2428 85c9 757d 8b4c242c 85c9 7543 }
- $sequence_1 = { e8???????? 83c40c 89442410 85c0 0f84f6010000 8b4d14 8b5510 }
- $sequence_2 = { eb0a 8b4554 c7400c01000000 8b442414 8b4d54 c74538f0000000 894550 }
- $sequence_3 = { 03c1 8b4c2444 13d7 2bc1 8bce 1bd1 8b4c243c }
- $sequence_4 = { 8d55f0 6a00 52 6a04 68???????? 57 ff15???????? }
- $sequence_5 = { 8b4758 8b8840030000 83f90e 7533 c7805403000001000000 8b4f58 39a978010000 }
- $sequence_6 = { 33c0 56 f3ab 8b4e58 8b442424 89a9ec000000 8b5658 }
- $sequence_7 = { 8b4c2430 83c420 8d0c49 8d440804 83f808 0f87d7000000 ff248574354600 }
- $sequence_8 = { 8d4c2424 51 e8???????? 8d542454 52 e8???????? 8d442470 }
- $sequence_9 = { 8b4804 83f905 8954241c 7529 8b5048 55 52 }
+ $sequence_0 = { e8???????? 8b75a8 8bf8 3bf7 7465 8b4e14 83f910 }
+ $sequence_1 = { c70000000200 e9???????? 56 68???????? 57 e8???????? 83c40c }
+ $sequence_2 = { 8d8544feffff 6a00 57 89864c010000 e8???????? 83c414 80bf0b05000000 }
+ $sequence_3 = { e8???????? 83c40c 85d2 0f8f28010000 7c08 85c0 0f831e010000 }
+ $sequence_4 = { 8b8f90050000 83c40c 85c9 7506 8b8f04030000 8b8748050000 8b4040 }
+ $sequence_5 = { 8a18 885dfe 80fb2e 8b5d08 7406 807dfe2c 7534 }
+ $sequence_6 = { 07 20c2 aa 709a 93 a3???????? 9e }
+ $sequence_7 = { 8b75fc 8bc7 c1e808 83e00f 8a80d0070a10 880433 8bda }
+ $sequence_8 = { e8???????? 83c408 85c0 7405 8d7728 eb38 8d85fcefffff }
+ $sequence_9 = { 8b4508 33f6 83f8ff 742d 8d8df4fdffff 51 50 }
condition:
- 7 of them and filesize <2015232
+ 7 of them and filesize <8692736
}
-rule MALPEDIA_Win_Meduza_Auto : FILE
+rule MALPEDIA_Win_Grimagent_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e4f4d329-00f5-5eac-b6fa-1a17dabc236f"
+ id = "228d515c-640e-56ca-8602-96023167bb1e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.meduza"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.meduza_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grimagent"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grimagent_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "5c31e3491e238f84a3f72990d6fa7fa5c8ed914b3efa6ee6f598848d375c51b9"
+ logic_hash = "96dca74317029a89173373ec308b352cf5e1c63ce0e2aa5c10efcec2082d0995"
score = 75
quality = 75
tags = "FILE"
@@ -132949,32 +140107,32 @@ rule MALPEDIA_Win_Meduza_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff75c8 8d55ac c645fc01 8d8d78ffffff e8???????? 83c404 8d4d94 }
- $sequence_1 = { c645fc23 c785f8eaffff02000000 c78548f8ffff3ebfeb85 c7854cf8ffff59dea06d 8b8548f8ffff 8b8d4cf8ffff 898d04f3ffff }
- $sequence_2 = { 83c408 c645fc15 8b4590 3b4580 0f84e9020000 66660f1f840000000000 8d7020 }
- $sequence_3 = { 8d45e0 c645fc02 50 e8???????? 8b4de4 83c404 8bf8 }
- $sequence_4 = { 898538f4ffff 898d3cf4ffff c785d8f6ffffdf03fddd c785dcf6ffffe227d929 8b85d8f6ffff 8b8ddcf6ffff 898540f4ffff }
- $sequence_5 = { 898de4feffff 8985e0feffff c78558ffffff0d5f1759 c7855cfffffff2314621 8b8558ffffff 8b8d5cffffff 898decfeffff }
- $sequence_6 = { c78548f8ffff68297235 c7854cf8ffff9d412b44 8b8548f8ffff 8b8d4cf8ffff 898dbcf5ffff 8985b8f5ffff c78548f8ffff5fcb84e8 }
- $sequence_7 = { 898ddce7ffff c785d8e4ffffdf03fddd c785dce4ffffe227d929 8b85d8e4ffff 8b8ddce4ffff 8985e0e7ffff }
- $sequence_8 = { e9???????? 807b0c00 0f8485010000 6a02 68???????? ff5004 8b4314 }
- $sequence_9 = { c7854cf8ffff9d412b44 8b8548f8ffff 8b8d4cf8ffff 0f288d90f4ffff 898dfcfbffff 8d8d90f4ffff 8985f8fbffff }
+ $sequence_0 = { 55 8bec 83ec18 c745f400000000 c745f800000000 c745e800000000 8b4508 }
+ $sequence_1 = { ebbe 8b550c 8955fc 8b450c 50 e8???????? }
+ $sequence_2 = { 0fb711 3bc2 7514 8b45ec 83c002 }
+ $sequence_3 = { 8b4dfc 0fb711 3bc2 7514 }
+ $sequence_4 = { 8b4508 50 e8???????? 83c404 3945f4 0f8394000000 8b4df0 }
+ $sequence_5 = { 0fb708 3bd1 7576 8b55f0 8955ec c745f800000000 eb09 }
+ $sequence_6 = { 83ec0c 8b450c 8945f8 c745fc00220400 8b4dfc }
+ $sequence_7 = { 8bec 8b4508 0fbe08 85c9 7426 8b5508 }
+ $sequence_8 = { c745e801000000 b801000000 eb1a 8b4df0 }
+ $sequence_9 = { 83c404 3945f8 750e c745e801000000 b801000000 }
condition:
- 7 of them and filesize <1433600
+ 7 of them and filesize <582656
}
-rule MALPEDIA_Win_Hzrat_Auto : FILE
+rule MALPEDIA_Win_Virdetdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4d1bc827-a443-5a54-876f-91ca96256a66"
+ id = "888dbb4a-ac95-59fd-b6c6-805a13eab949"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hzrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hzrat_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.virdetdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.virdetdoor_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "4c8da289e225a98c903b1e25bb40a32ef5f7bbd72fec724a7ddbf67c4f6841b8"
+ logic_hash = "f95b30ef178ddd53d43c681785d15b079df5f7a769adfe7338b74de03b97c177"
score = 75
quality = 75
tags = "FILE"
@@ -132988,32 +140146,32 @@ rule MALPEDIA_Win_Hzrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7526 c745f500000000 8d4df4 8075f642 8075f742 8075f842 6a00 }
- $sequence_1 = { ff15???????? 6689442412 8b44240c 89442414 8d442410 6a10 50 }
- $sequence_2 = { 8bce ff7508 8b4020 ffd0 8b17 8bcf 8ad8 }
- $sequence_3 = { 03da 81fa00010000 7312 8a8758e94200 0803 42 0fb64101 }
- $sequence_4 = { 51 e8???????? 83c408 80bd93feffff00 c6856cfeffff00 7445 }
- $sequence_5 = { 0faee8 e8???????? 8bc8 83c404 85c9 747d }
- $sequence_6 = { 7410 fe8860f14200 8a8060f14200 84c0 7f1f 8bce e8???????? }
- $sequence_7 = { dd4520 83c40c c9 c3 8b04c5c4324200 }
- $sequence_8 = { 7312 0faee8 8b5104 8b4208 }
- $sequence_9 = { c60000 c645fc03 8b9544fbffff 83fa10 }
+ $sequence_0 = { 8b93b0020000 2bc2 50 8b83ac020000 03c2 50 }
+ $sequence_1 = { 83ee01 753e 85ff 7524 390b 7720 3903 }
+ $sequence_2 = { 8d4dc0 e8???????? 85c0 0f84c8000000 }
+ $sequence_3 = { 83fe08 0f43c8 83c602 0fb7444dc0 0bd0 0fb7449dd2 0bd0 }
+ $sequence_4 = { 59 8d44240c 8bce 50 ff7314 57 e8???????? }
+ $sequence_5 = { 0fbfd0 8d8df8fdffff ff7508 50 }
+ $sequence_6 = { 55 8bec 51 51 53 8bc1 33db }
+ $sequence_7 = { ff75f0 8d8b50020000 e8???????? 834dfcff }
+ $sequence_8 = { 3c2e 7404 3c3a 750e 8a0437 88441dc0 43 }
+ $sequence_9 = { 8945f8 8b4508 8bf0 8975f0 8d5808 895df4 }
condition:
- 7 of them and filesize <409600
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Ngioweb_Auto : FILE
+rule MALPEDIA_Win_Gameover_Dga_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1a04caa4-5f94-5038-893b-b414574d57bc"
+ id = "49ca0960-3057-5b3f-bfaa-26bec43ff964"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ngioweb"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ngioweb_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gameover_dga"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gameover_dga_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "53b049f61ecbdc954b47598eb5e1d9de9a9f52f58bb1ef6f666338c0ff24b7f4"
+ logic_hash = "04f58b9dead2fa0c3d00122a20892474bd44e61e3b7f09f6fdc5edfc6227d8a8"
score = 75
quality = 75
tags = "FILE"
@@ -133027,32 +140185,32 @@ rule MALPEDIA_Win_Ngioweb_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4604 897808 eb15 894f08 8b06 89780c 893e }
- $sequence_1 = { 394518 89b39c000000 c783a800000001000000 8983b0000000 7412 50 6884000000 }
- $sequence_2 = { ffd0 85c0 7554 ff75fc 53 }
- $sequence_3 = { 66c745ae6300 66c745ac5400 668975aa 66895dc4 e8???????? 33c0 }
- $sequence_4 = { 668b460c 895f04 8d5f08 53 668907 ff7608 }
- $sequence_5 = { 3bc7 7574 689f860100 6810270000 8d4508 50 }
- $sequence_6 = { 53 8b5d24 68b9ed740a 56 e8???????? ff7518 ff7514 }
- $sequence_7 = { ff75f0 ff15???????? ff15???????? 8b45e8 eb02 33c0 5f }
- $sequence_8 = { 8bc3 5b 5d c21400 57 8b7c2408 85ff }
- $sequence_9 = { 770b 0fb7c0 668b4445d8 668906 46 46 49 }
+ $sequence_0 = { 884617 33c0 40 e9???????? 8a4601 33db 8b6c2434 }
+ $sequence_1 = { 397e08 0f84f0000000 8be9 894c2414 8bd1 8b4604 8a0c03 }
+ $sequence_2 = { 48 7544 397714 763f 8b4710 ff34b0 }
+ $sequence_3 = { 833d????????00 7566 8d8de8fdffff e8???????? 51 be???????? 56 }
+ $sequence_4 = { 5f 5b c20c00 8bcf e8???????? 8bf0 }
+ $sequence_5 = { 56 ff15???????? 85c0 7443 56 be???????? 8d85f8fdffff }
+ $sequence_6 = { 8b84245c010000 40 e9???????? 8b476c 33c9 2bc3 }
+ $sequence_7 = { ff760c ff7608 6a10 e8???????? 84c0 0f847a010000 8364241c00 }
+ $sequence_8 = { e8???????? a1???????? ff7064 ff15???????? 6a53 8d55b8 8bf0 }
+ $sequence_9 = { 7510 8b4f10 e8???????? 85c0 75e5 32c0 }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <540672
}
-rule MALPEDIA_Win_Kdcsponge_Auto : FILE
+rule MALPEDIA_Win_Unidentified_042_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "94fce6ec-ab5d-5082-ad22-afe2db84b161"
+ id = "9e093b61-c910-5742-8226-775531f91d9d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kdcsponge"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kdcsponge_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_042"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_042_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "8a36b853d0e2d90c09d30257cb4cad3c052e41eeb1a598728e2eabfd12dc7098"
+ logic_hash = "7aca5d090ae8281044c7e148c75c276642daf90859ffb2907ade4921d2dec5c9"
score = 75
quality = 75
tags = "FILE"
@@ -133066,32 +140224,32 @@ rule MALPEDIA_Win_Kdcsponge_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 80b9b104000001 c6810904000008 0f85bf000000 80b9ad04000000 c781a004000002000000 c7416002001100 7552 }
- $sequence_1 = { 488b8228040000 4885c0 7507 488b8230040000 4883c002 4803c1 }
- $sequence_2 = { 7507 c681c504000006 c7814004000003000000 c781ca04000004000000 e9???????? e9???????? 3c01 }
- $sequence_3 = { 0f85d5000000 80b9ad04000001 0f85bf000000 f681ae04000008 0f84b2000000 488b896c040000 }
- $sequence_4 = { 898520030000 e8???????? 488d0db15ffcff 48c1e602 0fb784b9c0550400 488d91b04c0400 488d8d24030000 }
- $sequence_5 = { 488b542450 488b4e08 e8???????? 488d4c2440 ff15???????? 0fb74504 ffc7 }
- $sequence_6 = { 448d4020 c745c048895c24 488d55c0 c745c420555657 488d0df1480200 c745c841544155 c745cc41564157 }
- $sequence_7 = { c6830804000001 f20f1005???????? 8b05???????? c7436003000100 eb24 83f807 753d }
- $sequence_8 = { 7507 c681c504000006 ba65000000 c744243004000000 448bca c744242804000000 448bc2 }
- $sequence_9 = { c6470801 e9???????? 41b803000000 488d1578f90000 488bcb e8???????? 85c0 }
+ $sequence_0 = { 85c0 754f 6a02 53 56 8d8d9cfeffff 57 }
+ $sequence_1 = { 56 8d8d68e1ffff 51 8d9554f7ffff 52 89b550f7ffff }
+ $sequence_2 = { 5b 85c0 78dd 8b45fc 8b55f8 0fb64c3801 4a }
+ $sequence_3 = { 8b4db8 895640 8b9518fdffff 895620 8b9520fdffff 894e44 8b8d1cfdffff }
+ $sequence_4 = { 8d8580cbffff 50 6a00 ff15???????? 85c0 7527 8b1d???????? }
+ $sequence_5 = { 5e 8bc7 5f 5d c3 8b7514 85f6 }
+ $sequence_6 = { 8bc3 2bc2 8d0c91 2bf0 42 8d3c87 3bf2 }
+ $sequence_7 = { 85db 0f85af000000 8d45ac 8bf0 8d5d9c 50 }
+ $sequence_8 = { 8d4df8 51 8d5df4 e8???????? 83c408 85c0 780d }
+ $sequence_9 = { 52 50 8d4b70 e8???????? 83c408 85c0 0f850b020000 }
condition:
- 7 of them and filesize <720896
+ 7 of them and filesize <516096
}
-rule MALPEDIA_Win_Soundbite_Auto : FILE
+rule MALPEDIA_Win_Crenufs_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "080e0f3d-446d-56c0-ac80-bd020f7550e1"
+ id = "f753eb30-be4b-5f62-9991-28649f65a79a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.soundbite"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.soundbite_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crenufs"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crenufs_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "dd4f6a00eb49b6e49c1bd5e71a528f06fe40aa9dfa91442cca75ad1ce88ee58a"
+ logic_hash = "62adacba8819f400983ac2aed5807f2d80c5566db3c1a2873916dcd6fb658c9d"
score = 75
quality = 75
tags = "FILE"
@@ -133105,32 +140263,32 @@ rule MALPEDIA_Win_Soundbite_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b5518 48 89451c 8b4a08 3bc8 7702 2bc1 }
- $sequence_1 = { c1e81f 8d4c02ff 398dd4fcffff 7d1f }
- $sequence_2 = { ff15???????? 8a4e02 8066030f 0fb7c0 240f 02c0 02c0 }
- $sequence_3 = { e8???????? 83c428 8d7de0 e8???????? 8b450c 8b4d18 8b5514 }
- $sequence_4 = { c745f0c4e9f2e5 c745f4e3f4eff2 66c745f8f900 894dc0 c745c4d3ffc8ff c745c8c5ffccff c745ccccffb3ff }
- $sequence_5 = { 49 894d18 3bc1 7437 8b7d14 8b5708 }
- $sequence_6 = { 8b4d08 8b550c 8d0411 83f802 }
- $sequence_7 = { 7702 2bc2 8b5104 8b3c82 8b4d2c 8b5528 51 }
- $sequence_8 = { 68???????? ff15???????? 8b7508 c7465ca0634200 83660800 33ff 47 }
- $sequence_9 = { 8d75a0 e8???????? 8b5da0 8b4da4 8bc3 2bc1 }
+ $sequence_0 = { 8b0c8de0934000 25ff000000 c1ea18 33cb 8b1c95e08f4000 8b56f8 }
+ $sequence_1 = { 55 56 57 8bf9 8a4c2444 33ed 884c2425 }
+ $sequence_2 = { ff15???????? 56 8d4d90 c645fc05 ff15???????? 56 8d4de0 }
+ $sequence_3 = { ffd0 83c408 53 ff15???????? 8b44243c 8b4e08 3bc5 }
+ $sequence_4 = { 59 50 57 8d4de0 ff15???????? bf???????? 57 }
+ $sequence_5 = { 750c 8b3d???????? 891d???????? 8d4c2444 ff15???????? 3bfb 7409 }
+ $sequence_6 = { ff15???????? 8d8d3cf2ffff c645fc03 e8???????? c645fc02 56 }
+ $sequence_7 = { 84c0 89542410 743e 3b31 752d 53 56 }
+ $sequence_8 = { 8d4c2444 895c2428 895c2430 33ff ff15???????? a1???????? 48 }
+ $sequence_9 = { 895dfc e8???????? 8b10 8bc8 ff5210 }
condition:
- 7 of them and filesize <409600
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Makloader_Auto : FILE
+rule MALPEDIA_Win_Bleachgap_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "66719c32-80e8-5417-8026-25e6d48fb7fe"
+ id = "1c7bcc3b-871c-5292-a898-130d22929e4c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.makloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.makloader_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bleachgap"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bleachgap_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "5f1f26214c5086a379f59348aefd7c2032c0ef40c82a5b49aca00ae5277c9d78"
+ logic_hash = "feb4beb187c6596a9fcad947329bf36b55b60b3bae8b02c6a93cdc46dd85c07a"
score = 75
quality = 75
tags = "FILE"
@@ -133144,32 +140302,32 @@ rule MALPEDIA_Win_Makloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8a11 88955ce6ffff 838530e6ffff01 80bd5ce6ffff00 }
- $sequence_1 = { 8d45f0 64a300000000 f2c3 8b4de4 33cd f2e8a8e9feff }
- $sequence_2 = { 8d8de4fcffff 898d30e5ffff 8d95d8e5ffff 899534e5ffff 8d8530e5ffff 50 }
- $sequence_3 = { 8b45d4 50 e8???????? 83c408 8945d4 837dd000 }
- $sequence_4 = { 8b9540e5ffff 8bca c1e902 f3a5 8bca }
- $sequence_5 = { 68???????? e8???????? 83c404 83f0ff 50 0fb695e5e5ffff }
- $sequence_6 = { 3bf3 72e9 5f 5e 5b c3 56 }
- $sequence_7 = { 51 e8???????? 83c404 ba01000000 6bca05 8b5508 }
- $sequence_8 = { 8d95e0f3ffff 52 8d8d70e6ffff e8???????? 8d8570ffffff }
- $sequence_9 = { 89856ce6ffff 6a4b 6a00 8d55b0 52 e8???????? 83c40c }
+ $sequence_0 = { 8bec ff750c e8???????? 8bc8 83f9ff 7506 32c0 }
+ $sequence_1 = { c645fc04 8b8d70fbffff 83f910 722f 8b955cfbffff 41 8bc2 }
+ $sequence_2 = { e9???????? ff7104 8d442414 6800010000 50 e8???????? 8d442410 }
+ $sequence_3 = { c68539ffffff7a c6853affffff5f c6853bffffff55 c6853cffffff41 c6853dffffff57 c6853effffff3c c6853fffffff41 }
+ $sequence_4 = { eb0d 8b450c 8945b8 c745b400000000 84c9 8d4dd4 0f44f2 }
+ $sequence_5 = { c6431000 894924 c645fc02 8d45e0 c645e801 0f57c0 660fd607 }
+ $sequence_6 = { 88442426 8b442410 0413 3457 88442427 8b442410 0414 }
+ $sequence_7 = { b801000000 d3e0 8502 0f8459ffffff 8b4614 8b5714 8b0e }
+ $sequence_8 = { ff750c 50 e8???????? 83c410 85c0 0f84d9010000 53 }
+ $sequence_9 = { 8a13 8bc1 8b4df0 43 41 894df4 3810 }
condition:
- 7 of them and filesize <335872
+ 7 of them and filesize <4538368
}
-rule MALPEDIA_Win_Microbackdoor_Auto : FILE
+rule MALPEDIA_Win_Mydogs_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "32768709-e0c4-568e-99b5-4d92498e8c97"
+ id = "8e0c4ca1-c33b-55e0-bdee-122873680dc3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.microbackdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.microbackdoor_auto.yar#L1-L174"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mydogs"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mydogs_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "d87bae84a1434eb391a7ebc0d4af12aee586692c39928b7bf8d060b1c97f49c6"
+ logic_hash = "64d7e86bc2c7d2208d4e1b71baa972c2ebb11908509ae447cb6fe3a57912500e"
score = 75
quality = 75
tags = "FILE"
@@ -133183,38 +140341,32 @@ rule MALPEDIA_Win_Microbackdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb74510 50 ff750c ff15???????? }
- $sequence_1 = { ffd7 eb06 ff15???????? 8bc6 eb06 }
- $sequence_2 = { 488bcd 418bdc 4d8bfc e8???????? 85db 755b 488d842478020000 }
- $sequence_3 = { 8939 488d4c2430 41b89c000000 e8???????? 488d4c2430 }
- $sequence_4 = { 74df 8d047506000000 50 6a40 ff15???????? 8bc8 894d0c }
- $sequence_5 = { 85c0 751d 837c247001 7516 395c2478 7610 488b4c2430 }
- $sequence_6 = { 4885db 7417 0fb7445ffe 6683f85c 7406 6683f82f }
- $sequence_7 = { 498bce 33f6 e8???????? 85ed }
- $sequence_8 = { 498bce 4489bc2488000000 453bc4 4c897c2420 }
- $sequence_9 = { 56 6a00 6a00 68???????? ff75f8 ff15???????? 85c0 }
- $sequence_10 = { ff15???????? 8d4336 50 6a40 ff15???????? 8bf8 }
- $sequence_11 = { 8bf8 897dd4 85ff 7498 837df800 b9???????? 8b5dfc }
- $sequence_12 = { ff15???????? 488bd8 4885c0 7512 ff15???????? 488d0d503e0000 }
- $sequence_13 = { 8bf8 e9???????? 33c0 40 e9???????? ff15???????? }
- $sequence_14 = { 83feff 743b 8b4d0c ff7510 894df4 ff15???????? 668945f2 }
- $sequence_15 = { 85c0 0f84bb010000 66833d????????00 0f84ad010000 }
+ $sequence_0 = { 3db7000000 0f8444010000 68???????? 6804010000 68???????? e8???????? }
+ $sequence_1 = { 884df3 c1fa18 8b5364 8bc2 8bce 0facc108 c1f808 }
+ $sequence_2 = { 5d e9???????? 6a18 68???????? e8???????? 8b4508 8bd8 }
+ $sequence_3 = { 894e64 8b4dec 894650 894658 894660 8b45ee 8d49c4 }
+ $sequence_4 = { 50 ffb5e4eeffff ffb5f8eeffff ff15???????? 85c0 7515 5f }
+ $sequence_5 = { 8bf9 53 895ddc 897de0 e8???????? }
+ $sequence_6 = { 8b4dfc 33cd e8???????? 8be5 5d c3 8d85f4eeffff }
+ $sequence_7 = { 50 8bcf c645ff4b e8???????? 6a01 8d450b 50 }
+ $sequence_8 = { 1ddeb19d01 50 51 89530c e8???????? 894310 }
+ $sequence_9 = { e8???????? 50 6800080000 53 89442434 e8???????? 83c414 }
condition:
- 7 of them and filesize <123904
+ 7 of them and filesize <313344
}
-rule MALPEDIA_Win_Tiop_Auto : FILE
+rule MALPEDIA_Win_Pss_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a48d1e15-9fc1-5bab-9fa2-c3c7b063ec8e"
+ id = "c85e1f97-adb5-5a29-88aa-4e9dab9b1814"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tiop"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tiop_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pss"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pss_auto.yar#L1-L136"
license_url = "N/A"
- logic_hash = "62d0ea75fcf8689409f77f7c307d37bf3637d8a3da71cff9b0be16f18afd1eb3"
+ logic_hash = "3fa2b0cf1b29b7abf02331e25c131d124a839f7a317f2ebb6c59c1c9547e53c0"
score = 75
quality = 75
tags = "FILE"
@@ -133228,34 +140380,37 @@ rule MALPEDIA_Win_Tiop_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 81ec08010000 55 56 57 b940000000 33c0 8d7c2411 }
- $sequence_1 = { ff15???????? 50 ff15???????? 8b3d???????? 8bf0 ffd7 50 }
- $sequence_2 = { 57 33ed b94f000000 33c0 8d7c240c 896c2408 892d???????? }
- $sequence_3 = { ff15???????? 50 8b44241c 53 50 ff5510 8b4c241c }
- $sequence_4 = { 8b7c2410 56 8b35???????? 894704 ffd6 55 ffd6 }
- $sequence_5 = { f3a4 8b442414 8b7500 8b4c2410 2bf0 03d0 897500 }
- $sequence_6 = { eb2e 50 ffd3 8d7c0002 8bc7 83c003 24fc }
- $sequence_7 = { 6a01 6a00 ffd7 8b1d???????? 8bf0 56 89742410 }
- $sequence_8 = { 83c9ff 33c0 83c404 f2ae f7d1 6a10 49 }
- $sequence_9 = { 8b542418 8b4c2420 8b3d???????? 8944240c 8b44242c 89542408 8b542424 }
+ $sequence_0 = { 8d48fe e8???????? e9???????? 83f811 }
+ $sequence_1 = { 7437 ff15???????? 3de5030000 752a }
+ $sequence_2 = { ff15???????? 83ceff 3bc6 7504 }
+ $sequence_3 = { 5e 5b 0f42ca 85c0 0f45c8 }
+ $sequence_4 = { 0fb619 0fb6c0 eb17 81fb00010000 7313 8a87a4f10110 }
+ $sequence_5 = { 8d542418 8bce e8???????? 59 59 }
+ $sequence_6 = { 8bf9 46 85ff 744f 833fff 7410 ff37 }
+ $sequence_7 = { 0fb6c0 5f 5e 5b c9 }
+ $sequence_8 = { 488d4c2428 e8???????? 90 4c8d05b3b70000 488bd0 488d0db1610100 }
+ $sequence_9 = { ff15???????? b001 eb25 e8???????? }
+ $sequence_10 = { e8???????? 90 4c8d05d3b50000 488bd0 }
+ $sequence_11 = { 488bcb e8???????? e9???????? ba80000000 488bcb }
+ $sequence_12 = { 488b4de7 e8???????? 48c745ff07000000 48897df7 }
condition:
- 7 of them and filesize <712704
+ 7 of them and filesize <421888
}
-rule MALPEDIA_Win_Transbox_Auto : FILE
+rule MALPEDIA_Elf_Gobrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6493b67c-879c-5d38-8ca0-5969cb4aa6f0"
+ id = "4556c50c-642d-5e08-a37f-0bca17aca318"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.transbox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.transbox_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.gobrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.gobrat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "d97e3f1924a5eeca38d9aa110b067c359caad44c72bb11cebc9ddfa66ee7e3d6"
- score = 75
- quality = 75
+ logic_hash = "d983e645d32d0df64baf254a8f8a69a3323d191b1dd7ae64a36bbf4746335d3e"
+ score = 60
+ quality = 35
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -133267,19 +140422,19 @@ rule MALPEDIA_Win_Transbox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 64a300000000 eb24 8b048d90b60110 41 50 890d???????? ff15???????? }
- $sequence_1 = { 33c9 83c414 85c0 0f9fc1 8bc1 8b4dfc 33cd }
- $sequence_2 = { 8d4e04 c706???????? 832100 83610400 51 50 ff15???????? }
- $sequence_3 = { e9???????? 55 8bec 56 8b7508 57 bf???????? }
- $sequence_4 = { f7fb 56 8bf0 bbe0077e00 8bc3 2bc6 83f801 }
- $sequence_5 = { f77dfc 50 51 e8???????? 83c40c 69c708020000 5f }
- $sequence_6 = { 8bbdbcd3ffff 53 6a01 8d8d28e1ffff 885dfc }
- $sequence_7 = { 8d85e8fdffff 6808020000 895dfc 53 50 89bddcfdffff 899de4fdffff }
- $sequence_8 = { 33c9 8985dcfcffff 51 50 }
- $sequence_9 = { 8d85f8faffff 50 e8???????? 8bd0 8b02 85c0 7402 }
+ $sequence_0 = { e8???????? 48833800 0f8f28020000 488b942428010000 4885d2 7508 e8???????? }
+ $sequence_1 = { 84c0 745c 488b542430 488b5a30 488b742428 488b4630 488b4e38 }
+ $sequence_2 = { c644242903 488d055aca3200 488d5c2418 e8???????? 4889c3 488d0546ca3200 e8???????? }
+ $sequence_3 = { eb41 488d059c311e00 e8???????? 48c740081c000000 488d0d39a62300 488908 31db }
+ $sequence_4 = { e8???????? 488b942460020000 488b7218 48897020 48837a7000 7542 488d1df7fc3200 }
+ $sequence_5 = { c3 31c0 488b6c2478 4883ec80 c3 488b8c2488000000 488b4110 }
+ $sequence_6 = { f7da 410fafd1 89d2 480fafd3 48c1ea2f 4489c6 41c1e008 }
+ $sequence_7 = { ffd2 b91a000000 4889c7 4889de 31c0 488d1dd7ce2d00 e8???????? }
+ $sequence_8 = { b825010000 e8???????? 4885c9 745d 4883f902 7712 753c }
+ $sequence_9 = { e8???????? 48c7400822000000 488d0de4212200 488908 31db 4889d9 488d3d244d2a00 }
condition:
- 7 of them and filesize <288768
+ 7 of them and filesize <12853248
}
rule MALPEDIA_Win_Nighthawk_Auto : FILE
{
@@ -133320,18 +140475,18 @@ rule MALPEDIA_Win_Nighthawk_Auto : FILE
condition:
7 of them and filesize <1949696
}
-rule MALPEDIA_Win_Isr_Stealer_Auto : FILE
+rule MALPEDIA_Win_Sword_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f92134ff-d8ee-58cb-8cb8-468d7205306f"
+ id = "48310a96-8b09-5184-8f0c-c81d31bbe550"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.isr_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.isr_stealer_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sword"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sword_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "75691989209029cb7a637cf5df87a857ef3ef18b6fe3194f56cba1ecab86658c"
+ logic_hash = "f0b3a1cc57dfaff82b285dd4a0f174f5006c9f22ab9c244578d6f7f68d086b5a"
score = 75
quality = 75
tags = "FILE"
@@ -133345,85 +140500,32 @@ rule MALPEDIA_Win_Isr_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { fb b05e 2bc1 e8???????? 661e }
- $sequence_1 = { 08ac22c115978d 0e e8???????? 07 }
- $sequence_2 = { 1c8b 53 2456 2bd1 807e6543 }
- $sequence_3 = { 46 1e 301b 15c2c8c807 d6 12d8 }
- $sequence_4 = { 8d16 b205 07 d32cb6 08ac22c115978d 0e e8???????? }
- $sequence_5 = { a7 8d16 b205 07 d32cb6 08ac22c115978d }
- $sequence_6 = { 07 fb b05e 2bc1 e8???????? }
- $sequence_7 = { 8d16 b205 07 d32cb6 08ac22c115978d 0e }
- $sequence_8 = { 07 d32cb6 08ac22c115978d 0e e8???????? }
- $sequence_9 = { e8???????? 07 fb b05e 2bc1 e8???????? 661e }
-
- condition:
- 7 of them and filesize <540672
-}
-rule MALPEDIA_Win_Oldbait_Auto : FILE
-{
- meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ebf9fc57-4949-58c7-824e-3ca5b4d74ce5"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.oldbait"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.oldbait_auto.yar#L1-L228"
- license_url = "N/A"
- logic_hash = "d1cd1bc5ec310d79468f4c2de84867d1b6cb0114c1b0bc749b36388cf16e7127"
- score = 75
- quality = 73
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { 05d4db1900 8945f4 ff35???????? ff75fc ff55f4 5f 5e }
- $sequence_1 = { 8bec 8b450c 56 33d2 57 }
- $sequence_2 = { 33d2 57 8b7d08 8d70ff 85f6 7626 }
- $sequence_3 = { 01459c 8b45c8 8945f8 eb05 }
- $sequence_4 = { 69c061ea0000 3571281424 42 3bd6 894510 72da }
- $sequence_5 = { 0145d8 8bb54cffffff 56 ff55d0 }
- $sequence_6 = { 0145d8 33ff 8d837ff61800 803800 }
- $sequence_7 = { 0145d8 8b45f0 ff45ec 0fb64004 }
- $sequence_8 = { 0531b11800 50 8b45f8 0531010000 50 }
- $sequence_9 = { 0145d4 41 c1ea04 75dc }
- $sequence_10 = { 837d2000 7432 66c7045f0d00 43 66c7045f0a00 43 }
- $sequence_11 = { 0145d8 8b45d8 3b45c8 7cc2 }
- $sequence_12 = { 83e107 d3e8 30043a 8b4510 69c061ea0000 3571281424 42 }
- $sequence_13 = { 6a40 6800300000 68d4fd1900 6a00 }
- $sequence_14 = { 894510 72da 8bc7 5f 5e }
- $sequence_15 = { 0103 01451c 8b06 8bc8 c1e906 }
- $sequence_16 = { 8b55fc 8a5d0f 8d4701 83e007 02d9 }
- $sequence_17 = { 7439 8d85bcfdffff 68???????? 50 }
- $sequence_18 = { ffd6 68???????? 53 8945f0 ffd6 6a64 }
- $sequence_19 = { 50 e8???????? ff75f4 8d8578ffffff 68???????? }
- $sequence_20 = { ffd6 ffd0 8d85c0feffff 50 8d85bcfdffff }
- $sequence_21 = { 8945ec ff7508 6a01 6a00 6a00 }
- $sequence_22 = { 8d4df4 8945d4 51 57 50 }
- $sequence_23 = { 57 50 53 68???????? ff35???????? ffd6 ffd0 }
+ $sequence_0 = { f7d1 2bf9 8d942484020000 8bf7 8bfa }
+ $sequence_1 = { ff15???????? 8b8c2434000100 50 8b84243c000100 8d542424 }
+ $sequence_2 = { 50 8d54241c 51 52 ff15???????? 85c0 0f8488090000 }
+ $sequence_3 = { 49 885c29ff 807d0022 7520 8d7d01 }
+ $sequence_4 = { 83c9ff 33c0 8d942488030000 f2ae f7d1 49 }
+ $sequence_5 = { 77c8 bf???????? 83c9ff 33c0 f2ae f7d1 }
+ $sequence_6 = { b940000000 33c0 8d7c2419 8894241c010000 f3ab }
+ $sequence_7 = { 83c9ff 33c0 f2ae f7d1 2bf9 55 }
+ $sequence_8 = { 8dbc2494060000 83c9ff 33c0 f2ae f7d1 49 }
+ $sequence_9 = { f7d1 49 83f903 77c8 bf???????? }
condition:
- 7 of them and filesize <172032
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Yayih_Auto : FILE
+rule MALPEDIA_Win_Bandook_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ad6edea8-11c9-5fa2-96f2-3800b1bd4695"
+ id = "facf6ec8-b33d-5307-a31b-1f1e19226ca5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yayih"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yayih_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bandook"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bandook_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "d13e6780f7fe46f9387338ccdb35700eb9e8a8c2ac7c13f232d1064c9386ae55"
+ logic_hash = "d695c77bc8945b310c81d69b92952d60e6bda737f194777e74e4b6ebb23f8272"
score = 75
quality = 75
tags = "FILE"
@@ -133437,32 +140539,32 @@ rule MALPEDIA_Win_Yayih_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5f ff7508 ff55f4 53 ff15???????? 8bc7 }
- $sequence_1 = { 68???????? e8???????? 8b35???????? 83c40c 50 57 }
- $sequence_2 = { 50 56 e8???????? 59 85c0 59 753c }
- $sequence_3 = { 85c0 59 7507 57 e8???????? 59 e8???????? }
- $sequence_4 = { ff15???????? 56 6880000000 6a03 56 6a01 8d85b8b8ffff }
- $sequence_5 = { 66ab aa 59 33c0 8dbde9faffff 889de8faffff f3ab }
- $sequence_6 = { 3bfe 750a 56 56 56 6a08 }
- $sequence_7 = { e8???????? 6801200000 8d85b8b8ffff 56 50 e8???????? }
- $sequence_8 = { 50 8d854cf6ffff 50 e8???????? 83c430 8d459c 50 }
- $sequence_9 = { 0fafca 0fb65002 03ca 890d???????? 0fb64803 69c960ea0000 }
+ $sequence_0 = { 68???????? ffd6 68???????? 6a01 6a00 ff15???????? 68e8030000 }
+ $sequence_1 = { 8b7c2410 8d442438 50 53 ff15???????? 85c0 0f8529ffffff }
+ $sequence_2 = { 8d95f8f3ffff 8bce 2bd6 0f1f00 8a01 8d4901 }
+ $sequence_3 = { ff15???????? ff35???????? ff15???????? 68???????? 68???????? 8d8424a8010000 68???????? }
+ $sequence_4 = { 8bf9 897da0 8b7308 8d4dbc 897d9c 6a24 68???????? }
+ $sequence_5 = { 83e103 f3a4 8d442428 50 53 ff15???????? 85c0 }
+ $sequence_6 = { 51 e8???????? 83c408 837dbc10 8d45a8 0f4345a8 50 }
+ $sequence_7 = { 88811744c213 84c0 75ed 0fb605???????? f30f7e05???????? a2???????? a1???????? }
+ $sequence_8 = { c705????????80381713 c705????????003a1713 c705????????c03f1713 c705????????80401713 c705????????c0491713 c705????????704b1713 c705????????30451713 }
+ $sequence_9 = { 83c40c 8d842498040000 6a64 50 6a07 6800040000 ff15???????? }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <23088128
}
-rule MALPEDIA_Win_Pikabot_Auto : FILE
+rule MALPEDIA_Win_Ddkong_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "16fbebe5-029d-50d1-a8a8-9f8a45a24f27"
+ id = "0544faa5-2134-56f3-b2ce-99d63d7f2f59"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pikabot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pikabot_auto.yar#L1-L175"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ddkong"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ddkong_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "81c8e73356106864f0a8f72d23108459a17754dd4d587aefd7feb43e822dba1f"
+ logic_hash = "5c0b95ff5255c02a1d1a9b0883f78a353561d54588ac72196452124efb25472a"
score = 75
quality = 75
tags = "FILE"
@@ -133476,41 +140578,34 @@ rule MALPEDIA_Win_Pikabot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945f8 8b4510 8945f4 8b4510 48 }
- $sequence_1 = { 894510 837df400 741a 8b45fc 8b4df8 8a09 }
- $sequence_2 = { 8b4df8 8a09 8808 8b45fc }
- $sequence_3 = { 40 8945fc 8b45f8 40 8945f8 ebd3 8b4508 }
- $sequence_4 = { 8945f8 ebd3 8b4508 c9 c3 55 }
- $sequence_5 = { 83ec0c 8b4508 8945fc 8b450c 8945f8 8b4510 }
- $sequence_6 = { 7ce9 8b4214 2b420c 5f }
- $sequence_7 = { e8???????? ffd0 c9 c3 55 8bec }
- $sequence_8 = { 8bfa 85c9 7436 85ff }
- $sequence_9 = { 8b0cba 03ce e8???????? 8bd0 }
- $sequence_10 = { 8a1c08 8d4320 0fb6c8 8d53bf 80fa19 }
- $sequence_11 = { 40 8945fc 3bc7 72d5 }
- $sequence_12 = { 55 8bec 83ec10 53 56 8b35???????? b84d5a0000 }
- $sequence_13 = { e8???????? 8bd0 e8???????? 3b45fc }
- $sequence_14 = { c3 56 8bf1 85c9 7419 85d2 7415 }
- $sequence_15 = { 84c0 75f6 c60100 8bc6 5e }
- $sequence_16 = { c9 c3 64a130000000 8b4018 c3 55 }
+ $sequence_0 = { c6459765 c6459857 c645996f c6459a77 c6459b36 c6459c34 c6459d46 }
+ $sequence_1 = { c68572ffffff62 c68573ffffff6a c68574ffffff65 c68575ffffff63 c68576ffffff74 889d77ffffff ffd7 }
+ $sequence_2 = { c645d36c c645d465 c645d54e c645d661 c645d76d c645d865 c645d941 }
+ $sequence_3 = { 5b 5d c20c00 ff25???????? ff25???????? 8b4c2404 85c9 }
+ $sequence_4 = { c645f470 ffd6 50 ffd7 8b5d0c bf04010000 }
+ $sequence_5 = { 6a04 e8???????? 83c418 eb2d 6a01 }
+ $sequence_6 = { 7427 837d08ff 7421 8d45dc 6a10 50 ff7508 }
+ $sequence_7 = { c6855affffff65 c6855bffffff4f c6855cffffff62 c6855dffffff6a c6855effffff65 }
+ $sequence_8 = { c6459763 c6459874 c6459969 c6459a76 c6459b65 c6459c43 c6459d6f }
+ $sequence_9 = { c68574ffffff65 c68575ffffff63 c68576ffffff74 889d77ffffff }
condition:
- 7 of them and filesize <1717248
+ 7 of them and filesize <81920
}
-rule MALPEDIA_Win_Grimagent_Auto : FILE
+rule MALPEDIA_Win_Synccrypt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "228d515c-640e-56ca-8602-96023167bb1e"
+ id = "06111ba7-b1d3-5613-b1dc-5c5b2d1d9432"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grimagent"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grimagent_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.synccrypt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.synccrypt_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "96dca74317029a89173373ec308b352cf5e1c63ce0e2aa5c10efcec2082d0995"
+ logic_hash = "f349f89fd6eccd96b82f1ed169c1d5231d52d67328e2977c4a89bd9cc0fef158"
score = 75
- quality = 75
+ quality = 45
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -133522,32 +140617,32 @@ rule MALPEDIA_Win_Grimagent_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 55 8bec 83ec18 c745f400000000 c745f800000000 c745e800000000 8b4508 }
- $sequence_1 = { ebbe 8b550c 8955fc 8b450c 50 e8???????? }
- $sequence_2 = { 0fb711 3bc2 7514 8b45ec 83c002 }
- $sequence_3 = { 8b4dfc 0fb711 3bc2 7514 }
- $sequence_4 = { 8b4508 50 e8???????? 83c404 3945f4 0f8394000000 8b4df0 }
- $sequence_5 = { 0fb708 3bd1 7576 8b55f0 8955ec c745f800000000 eb09 }
- $sequence_6 = { 83ec0c 8b450c 8945f8 c745fc00220400 8b4dfc }
- $sequence_7 = { 8bec 8b4508 0fbe08 85c9 7426 8b5508 }
- $sequence_8 = { c745e801000000 b801000000 eb1a 8b4df0 }
- $sequence_9 = { 83c404 3945f8 750e c745e801000000 b801000000 }
+ $sequence_0 = { c744240477000000 c7042422000000 e8???????? e9???????? c7442410af000000 c744240c94195900 c74424087a000000 }
+ $sequence_1 = { ba01000000 89f8 e8???????? 85c0 8b4c242c 0f84aa000000 8b4714 }
+ $sequence_2 = { 892c24 e8???????? 892c24 89c7 e8???????? 85c0 7517 }
+ $sequence_3 = { c1e806 85c0 7523 897358 83c318 89742408 891c24 }
+ $sequence_4 = { e8???????? 85c0 74c8 8d442414 8974240c 895c2408 89442404 }
+ $sequence_5 = { e8???????? 85c0 0f8413010000 8d7804 89c1 c7406800000000 89c3 }
+ $sequence_6 = { f6400c01 7451 891c24 e8???????? 83c001 c744240897010000 c7442404???????? }
+ $sequence_7 = { c7442404???????? c7042402000000 a3???????? e8???????? c7442404???????? c704240b000000 a3???????? }
+ $sequence_8 = { e8???????? 893424 e8???????? 8b442430 890424 e8???????? 39c7 }
+ $sequence_9 = { 890424 8954240c e8???????? 3b6c2418 8d45fe 746e 8b570c }
condition:
- 7 of them and filesize <582656
+ 7 of them and filesize <4489216
}
-rule MALPEDIA_Win_Royal_Ransom_Auto : FILE
+rule MALPEDIA_Win_Fancyfilter_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "03d0866a-b258-5731-ad57-bc4b0e928885"
+ id = "80aed11c-235c-5a1c-926a-79da2aeef3b0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.royal_ransom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.royal_ransom_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fancyfilter"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fancyfilter_auto.yar#L1-L112"
license_url = "N/A"
- logic_hash = "05d0adf9ccc7ed8f53f566dd8191bfd8d7450964340be8e2ce8cbced72447263"
+ logic_hash = "3c31ea55e7982b34390b9c81f5913450958243c449d75663ce6d5f15ca3bbd38"
score = 75
quality = 75
tags = "FILE"
@@ -133561,32 +140656,32 @@ rule MALPEDIA_Win_Royal_Ransom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 752f e8???????? 4c8d05d60c1400 ba8b010000 488d0d320c1400 e8???????? 4533c0 }
- $sequence_1 = { e9???????? 2bc3 488d0d2df4dfff 488b8ce9d02c2d00 8064f93dfd f7d8 1ac0 }
- $sequence_2 = { e8???????? 33c0 e9???????? 488b4820 e8???????? 85c0 0f8497020000 }
- $sequence_3 = { e8???????? 488d4e24 448bc8 4c8d0579a80d00 ba09000000 e8???????? 488bcb }
- $sequence_4 = { 8bc2 896c2444 418bfe 83fa02 7d3e e8???????? 4c8d05e7a90f00 }
- $sequence_5 = { 488d1507b51300 41b893040000 e8???????? 41b894040000 488d15efb41300 488bcf e8???????? }
- $sequence_6 = { e8???????? baa6000000 4c89742420 4c8bcd 4c8d05f3a80e00 8d4a93 e8???????? }
- $sequence_7 = { 754a e8???????? 4c8d054e820d00 baa2000000 488d0df2810d00 e8???????? 4533c0 }
- $sequence_8 = { b828000000 e8???????? 482be0 488d15fc4fffff 488d0d5de62000 e8???????? 33c9 }
- $sequence_9 = { e8???????? 85c0 7437 488d05297a0000 4c89742430 4889442428 4c8d0d485c0e00 }
+ $sequence_0 = { 740a 66833800 7404 b001 eb02 }
+ $sequence_1 = { a1???????? 83c012 50 ff15???????? }
+ $sequence_2 = { 8b07 83e810 50 83c610 56 }
+ $sequence_3 = { ff15???????? 83c420 83f803 7409 83f806 }
+ $sequence_4 = { 83c012 50 ffd6 a1???????? }
+ $sequence_5 = { 85c0 750d 8b472c a801 7406 83c804 }
+ $sequence_6 = { 85c0 740a 66833800 7404 b001 eb02 }
+ $sequence_7 = { 81e3ffffff00 ff15???????? 50 ff15???????? }
+ $sequence_8 = { 85c0 740a 66833800 7404 b001 }
+ $sequence_9 = { b805400080 c20400 56 8b742408 }
condition:
- 7 of them and filesize <6235136
+ 7 of them and filesize <169984
}
-rule MALPEDIA_Win_Odinaff_Auto : FILE
+rule MALPEDIA_Win_Badencript_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c28375cd-e1a8-5dbb-b117-119bc2a2a6cd"
+ id = "14e6e038-56f2-594e-a7b6-4f5872213cea"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.odinaff"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.odinaff_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badencript"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.badencript_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "de88658965024bda0c5434053043d1a37aa258e92b5fc7491f70abd6c372a45d"
+ logic_hash = "2996c0cacc073d062d9370be45e59795727eb489c538600d3d982f614b0ed8f2"
score = 75
quality = 75
tags = "FILE"
@@ -133600,32 +140695,32 @@ rule MALPEDIA_Win_Odinaff_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 3d1f040000 7505 bf01000000 }
- $sequence_1 = { 740c 57 6a00 ffd3 50 ff15???????? 6a00 }
- $sequence_2 = { 6a08 33ff 57 57 ff15???????? }
- $sequence_3 = { 8bd8 ff15???????? 53 6a00 6a00 56 ff15???????? }
- $sequence_4 = { 49 81c900ffffff 41 8a8138474000 }
- $sequence_5 = { 8b1d???????? 83c40c 6820bf0200 56 ffd3 b900000800 2bc8 }
- $sequence_6 = { c745dc01000000 e8???????? 6a44 8d4580 53 50 e8???????? }
- $sequence_7 = { 7508 ff15???????? eb7b 6a04 }
- $sequence_8 = { e8???????? 8b45f8 83c410 85c0 7408 50 6a00 }
- $sequence_9 = { 8b4d0c 6a00 6880000000 6a02 }
+ $sequence_0 = { 8bfe a1???????? 897de0 394508 7c1f 3934bd48414100 }
+ $sequence_1 = { 8a07 8b0c9548414100 8844192e 8b049548414100 }
+ $sequence_2 = { 6af6 ff15???????? 8b04bd48414100 834c0318ff 33c0 eb16 e8???????? }
+ $sequence_3 = { 53 ffd7 83ee01 75eb 8b4dfc 33c0 }
+ $sequence_4 = { 8b049d48414100 8945d4 8955e8 8a5c1029 80fb02 7405 80fb01 }
+ $sequence_5 = { 660fd60f 8d7f08 8b048d04b54000 ffe0 f7c703000000 }
+ $sequence_6 = { 8b049548414100 f644082801 740b 56 e8???????? 59 }
+ $sequence_7 = { 0f859b010000 c745e0980f4100 8b4508 8bcf 8b7510 c745dc01000000 dd00 }
+ $sequence_8 = { 58 6bc000 c7809439410002000000 6a04 }
+ $sequence_9 = { 50 8b04bd48414100 ff743018 ff15???????? 85c0 0f95c0 5f }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <335872
}
-rule MALPEDIA_Win_Nestegg_Auto : FILE
+rule MALPEDIA_Win_Mindware_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "01b2e0f8-b92c-591f-a2fe-591e7cf3b6b4"
+ id = "205d25dc-9d1d-5cfe-9a1e-fc1d20bf21d6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nestegg"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nestegg_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mindware"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mindware_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "d01d8400ee78b6e2d5585ed1b0eb91726b08169614c693b823bb545acd7b28b3"
+ logic_hash = "0229e104e7ced878ae1d5a8dad7ae14c8a1e11edebe2196883325f14972bfdf1"
score = 75
quality = 75
tags = "FILE"
@@ -133639,32 +140734,32 @@ rule MALPEDIA_Win_Nestegg_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8d5710 6a02 52 8bce e8???????? }
- $sequence_1 = { 83c40c 83feff 7417 ffd7 }
- $sequence_2 = { 8b0d???????? 81c120030000 51 ff15???????? 8b0d???????? 39991c030000 }
- $sequence_3 = { 83f80e 0f84d8000000 83f80f 7520 8d4c2430 56 }
- $sequence_4 = { 56 8bf1 89742404 c706???????? 8b8e24030000 c744241000000000 }
- $sequence_5 = { 85c9 740c 8a09 83e107 8d14c1 89542410 }
- $sequence_6 = { 8b10 6a10 51 8bc8 885c2458 ff5214 }
- $sequence_7 = { c644242f6e c644243065 c644243233 884c2433 885c2434 88542435 }
- $sequence_8 = { c644240d73 884c240e c644240f5f c644241033 }
- $sequence_9 = { e8???????? 8d4c2410 6a04 51 8bce c7442418ff020001 e8???????? }
+ $sequence_0 = { 50 ff15???????? 8dbd48ffffff 32c0 b980000000 f3aa }
+ $sequence_1 = { c78530e9ffffeccc4300 c78534e9fffff4cc4300 c78538e9ffff0ccd4300 c7853ce9ffff18cd4300 c78540e9ffff38cd4300 c78544e9ffff40cd4300 c78548e9ffff4ccd4300 }
+ $sequence_2 = { c7857cf4ffff24e94300 c78580f4ffff38e94300 c78584f4ffff40e94300 c78588f4ffff48e94300 c7858cf4ffff58e94300 }
+ $sequence_3 = { c1e910 335808 0fb6c9 895df4 33148df0d04400 }
+ $sequence_4 = { 894dfc 89482c c1e918 897028 0fb699f0d84400 8b4dfc c1e910 }
+ $sequence_5 = { 0fb6c9 33148dc0c84400 335004 8b4dfc c1e908 8955e8 0fb6d1 }
+ $sequence_6 = { 8bec 837d0c00 764c e8???????? 0fb6c0 85c0 }
+ $sequence_7 = { 6a00 8b856cffffff 50 8b8d68ffffff 51 8b55bc 52 }
+ $sequence_8 = { c78530e6ffff5cc54300 c78534e6ffff68c54300 c78538e6ffff70c54300 c7853ce6ffff78c54300 c78540e6ffff88c54300 c78544e6ffff90c54300 c78548e6ffffa0c54300 }
+ $sequence_9 = { 33d2 034dc8 1355cc 894dc8 8955cc e9???????? 8b45dc }
condition:
- 7 of them and filesize <221184
+ 7 of them and filesize <661504
}
-rule MALPEDIA_Win_New_Ct_Auto : FILE
+rule MALPEDIA_Win_Parasite_Http_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d2add3a1-140a-5bb8-b61a-9a3c6a02e7fc"
+ id = "8396c4fe-e904-583d-8bc2-2a1b61b79bee"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.new_ct"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.new_ct_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.parasite_http"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.parasite_http_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "d5abc4cf0e59662bf031f834b2da1a42e3067fae0164acdda49916fdb832ef21"
+ logic_hash = "37851542b45d72ed626359d2a060741c909807319056a1d140e5557e76485a87"
score = 75
quality = 75
tags = "FILE"
@@ -133678,32 +140773,32 @@ rule MALPEDIA_Win_New_Ct_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 894304 7532 8bfe 83c9ff 33c0 f2ae f7d1 }
- $sequence_1 = { 7472 3c42 746e 33c0 }
- $sequence_2 = { 81ec00040000 53 56 6888030000 33db }
- $sequence_3 = { 7605 b800000100 8b742418 03c7 8d8c24bc070000 8d44301c }
- $sequence_4 = { c644240537 c644240679 c6442407b9 7627 }
- $sequence_5 = { 8bcd 8933 2bce c6043e00 49 33c0 }
- $sequence_6 = { 50 6a00 6a00 68???????? 6a00 68???????? ff15???????? }
- $sequence_7 = { 33c0 8dbc24bd070000 c68424bc07000000 c68424bc0f000000 f3ab 66ab aa }
- $sequence_8 = { 740d 8d942414020000 52 ffd0 83c404 5f 5e }
- $sequence_9 = { 8bbc245c040000 c1e902 f3a5 8bc8 83e103 f3a4 }
+ $sequence_0 = { 57 b900040000 e8???????? 8bf8 85ff 0f848a000000 56 }
+ $sequence_1 = { 50 33c0 895dfc 53 53 }
+ $sequence_2 = { 884df2 8d4dbc 66895dbe 668955c0 66895dc4 668945ce 66c745ec5669 }
+ $sequence_3 = { e8???????? 59 85db 7407 8bcb e8???????? 8b45f0 }
+ $sequence_4 = { 6a36 6689460a 58 6a34 6689460e 58 57 }
+ $sequence_5 = { e8???????? b9???????? 8bd8 e8???????? 33d2 8bcb }
+ $sequence_6 = { 57 8bf9 b9???????? e8???????? b9???????? 8bf0 e8???????? }
+ $sequence_7 = { 57 e8???????? 03c6 50 52 }
+ $sequence_8 = { 740f 8d4dfc 51 51 51 50 }
+ $sequence_9 = { 53 ffd0 8bcf e8???????? 8bce e8???????? 8bcb }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <147456
}
-rule MALPEDIA_Win_Hermeticwizard_Auto : FILE
+rule MALPEDIA_Win_Cheesetray_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "726bd88f-010b-5502-8637-f9d7bbeebd06"
+ id = "eb62b85d-8cb5-5c93-9081-d14aeb9fbc65"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hermeticwizard"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hermeticwizard_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cheesetray"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cheesetray_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "42607a1b485bdd595d314b574245aeda955efc5b6dd3f18356065a03173a4530"
+ logic_hash = "191172cf0a118bdd8e29d678be92e505a1f63a7f2bef651373f2b7d4a4b3676d"
score = 75
quality = 75
tags = "FILE"
@@ -133717,32 +140812,32 @@ rule MALPEDIA_Win_Hermeticwizard_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4608 3b4208 eb31 83f803 7531 8d4a04 8d4604 }
- $sequence_1 = { 33c9 66897dca 6800080000 50 }
- $sequence_2 = { 8b35???????? ffd6 ff75e8 ffd6 5e 8b4508 5f }
- $sequence_3 = { 6bc930 53 8b5d10 8b0485c0dd0110 56 }
- $sequence_4 = { 6689854cffffff 6689854effffff 66898554ffffff 6689855effffff 66898d58ffffff 66898d5affffff 59 }
- $sequence_5 = { 8d4608 50 8d4908 e8???????? }
- $sequence_6 = { 6a02 58 668945e8 8b4104 }
- $sequence_7 = { c3 837d08ff 0f8401070000 e9???????? e9???????? 55 8bec }
- $sequence_8 = { ff15???????? 83f87a 7567 ff75fc 6a08 ff15???????? 50 }
- $sequence_9 = { ff15???????? 85c0 7504 b001 eb3a 57 56 }
+ $sequence_0 = { 66898424c4000000 e8???????? 8b4d08 83c40c 51 8d54240c 33c0 }
+ $sequence_1 = { c20c00 397368 740e 56 e8???????? 83c404 83f8ff }
+ $sequence_2 = { 03cf 8988bc160000 8b3cb5f0234400 8b5d08 85ff 0f8487fdffff 2b14b5282d4400 }
+ $sequence_3 = { 8bf8 85ff 745d 0fb755f0 8b45ec 52 50 }
+ $sequence_4 = { e8???????? 8b442434 3bc7 7403 50 ffd6 }
+ $sequence_5 = { 8d0c00 8d442428 50 52 e8???????? 83c408 894608 }
+ $sequence_6 = { 8bda c1eb18 33049da02d4400 81e2ff000000 330495a0394400 83c120 3341f8 }
+ $sequence_7 = { 8b4dfc 5f 5e a3???????? 890d???????? b801000000 5b }
+ $sequence_8 = { e8???????? 8b45f8 83c40c 53 53 8d4dec 51 }
+ $sequence_9 = { 83c410 33c0 5f 66398500ffffff 740c 40 6683bc4500ffffff00 }
condition:
- 7 of them and filesize <263168
+ 7 of them and filesize <8626176
}
-rule MALPEDIA_Win_Rokrat_Auto : FILE
+rule MALPEDIA_Win_Unidentified_076_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "529b23ea-5ccb-5314-a032-246562122609"
+ id = "c76f9b8e-5a48-5b08-ae0b-831af19ce579"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rokrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rokrat_auto.yar#L1-L152"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_076"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_076_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "99c55c71740e0234c84ec3f4624ede5be8b8eb4baac41c4a1538d8db05d1af41"
+ logic_hash = "afb3d60b25322ebd0dc1ef4a0c20812c54fa6c9c843b7734da080ace48ec2894"
score = 75
quality = 75
tags = "FILE"
@@ -133756,38 +140851,32 @@ rule MALPEDIA_Win_Rokrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? 6a04 33c0 }
- $sequence_1 = { 50 8bcf e8???????? 8d4538 3bd8 }
- $sequence_2 = { 50 0fb74208 c1e910 51 50 }
- $sequence_3 = { 50 8bcb e8???????? 8d4550 }
- $sequence_4 = { 50 e8???????? 8d8edc000000 8d4520 }
- $sequence_5 = { 56 8d4dc0 c745d000000000 668945c0 e8???????? c645fc03 8b45bc }
- $sequence_6 = { 50 ff15???????? e8???????? 40 }
- $sequence_7 = { 51 50 0fb74212 50 }
- $sequence_8 = { 770a 68???????? e8???????? 837e1408 }
- $sequence_9 = { ff15???????? 50 e8???????? 59 6a64 }
- $sequence_10 = { 897dfc e8???????? 68???????? 8d4dd8 }
- $sequence_11 = { c145f41e 8b5dfc 8db4339979825a 8975fc }
- $sequence_12 = { c145f01e 8db4339979825a 8975f4 8b772c }
- $sequence_13 = { c145f41e 8d9c3bd6c162ca 8b792c 337924 }
- $sequence_14 = { c145f41e 8d8c0bdcbc1b8f 894dfc 8bca }
- $sequence_15 = { c145f41e 8d9c1fd6c162ca 8b793c 337930 }
+ $sequence_0 = { 488b5370 488d4520 488bcb 4889442420 e8???????? 8bc8 eb7c }
+ $sequence_1 = { 747b 8d5620 448bce 448bc5 33c9 ff97f8000000 48898748020000 }
+ $sequence_2 = { 488bcf ff9080000000 33d2 33c9 4c63c0 85c0 7e29 }
+ $sequence_3 = { 48894178 488b8f80000000 488b4618 48034f50 48898880000000 488b8f90000000 488b4618 }
+ $sequence_4 = { 458d6502 448bc7 488bce 4489642428 89442420 e8???????? 85c0 }
+ $sequence_5 = { 488d8d40150000 e8???????? 488d1587720000 488d8d14090000 8985d4000000 488d05c3130000 c7853001000000080000 }
+ $sequence_6 = { 4533c9 488bcf 448d420c 48895c2420 e8???????? eb05 bb01000000 }
+ $sequence_7 = { 7f0b 41b907000000 e9???????? 488b83c8000000 488b9360020000 488d8b5c060000 ff90f0070000 }
+ $sequence_8 = { 89442420 e8???????? eb56 83f801 7529 8b8714120000 448b8f10120000 }
+ $sequence_9 = { 415e 415c c3 817d0c08020000 7c05 458bcc eba2 }
condition:
- 7 of them and filesize <2932736
+ 7 of them and filesize <114688
}
-rule MALPEDIA_Win_Bagle_Auto : FILE
+rule MALPEDIA_Win_Heloag_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "df34f7e5-e23a-57ca-9057-158d47df6a58"
+ id = "ef07a0f3-faff-581a-a00e-f3d94c2f2e27"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bagle"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bagle_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.heloag"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.heloag_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "191b784ad61e65e2f10fbf592eeed47046bf8d9317c3471370d1a12460ef9a14"
+ logic_hash = "d41534ff803a8c13a09a17ccbef4333268f3c2d9e67aea8ce8ca3bb7d4a205eb"
score = 75
quality = 75
tags = "FILE"
@@ -133801,32 +140890,38 @@ rule MALPEDIA_Win_Bagle_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b03d f3aa 5b 5f 5e c9 }
- $sequence_1 = { c745f400000000 6a06 6a01 6a02 e8???????? 8bd8 ff7508 }
- $sequence_2 = { e340 ac c1e010 83f901 740b }
- $sequence_3 = { c9 c20c00 c1c206 8bc2 }
- $sequence_4 = { f7d9 2bf9 b03d f3aa 5b 5f 5e }
- $sequence_5 = { 68???????? e8???????? 0bc0 7426 6880000000 68???????? e8???????? }
- $sequence_6 = { c20c00 c1c206 8bc2 243f 3c3e }
- $sequence_7 = { 53 8b7508 8b7d0c 8b4d10 }
- $sequence_8 = { 59 43 83fb12 7508 33db }
- $sequence_9 = { e8???????? 58 c9 c20400 55 8bec 83c4f8 }
+ $sequence_0 = { 66ab aa 83c9ff 8bfe 33c0 }
+ $sequence_1 = { 8bf7 8bfa 8a15???????? c1e902 f3a5 8bc8 }
+ $sequence_2 = { 8d4dbc 51 ffd7 8b45c4 b919000000 }
+ $sequence_3 = { 8b0d???????? 51 e8???????? 6a14 e8???????? 8bf0 83c408 }
+ $sequence_4 = { f3a4 a2???????? a2???????? a3???????? }
+ $sequence_5 = { 7cc4 8b45fc 8b0d???????? 40 }
+ $sequence_6 = { 6a00 6a00 ffd0 33c9 a3???????? 85c0 0f95c1 }
+ $sequence_7 = { 8d8dacfdffff 68???????? 51 e8???????? 8b55b4 83c41c 66c745b80200 }
+ $sequence_8 = { 8b4e0c 3bcd 8b07 89442410 7464 }
+ $sequence_9 = { 894b0c 8a48ff fec1 8848ff eb3c 6a01 55 }
+ $sequence_10 = { 8b4108 50 e8???????? 6a01 }
+ $sequence_11 = { 85c0 7505 a1???????? 8b4c242c }
+ $sequence_12 = { 51 53 68???????? 8d4c2420 ff15???????? }
+ $sequence_13 = { 8a442413 6a00 8bce 8806 ff15???????? }
+ $sequence_14 = { 8b11 8bcf 52 6a00 50 ff15???????? }
+ $sequence_15 = { a1???????? 894304 8b5608 895308 8b4e0c 894b0c }
condition:
- 7 of them and filesize <245760
+ 7 of them and filesize <401408
}
-rule MALPEDIA_Win_Urausy_Auto : FILE
+rule MALPEDIA_Win_Bbsrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "42f215cc-3fcb-5d25-8a29-1c5fcfaf0e92"
+ id = "1bf7f125-76bf-51d8-8714-b1f4351a2fc5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.urausy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.urausy_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bbsrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bbsrat_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "4f1d0bce8598e73699b4a743f6a21ef45b27ed44d43ef0837b1c95c90d3c9c6b"
+ logic_hash = "d09c46b568c20e6cc1497fd9b00b10dfec3bd249a240c9cb1f2d27667bcf264d"
score = 75
quality = 75
tags = "FILE"
@@ -133840,32 +140935,32 @@ rule MALPEDIA_Win_Urausy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 68???????? 68???????? ff7508 e8???????? 6a00 ff35???????? }
- $sequence_1 = { 8bd3 81c2a5000000 50 53 52 51 }
- $sequence_2 = { ff75e4 e8???????? 8945e8 ff35???????? }
- $sequence_3 = { 6a01 ff35???????? e8???????? 6a00 68???????? 68???????? }
- $sequence_4 = { c21000 55 8bec 81c4ecefffff }
- $sequence_5 = { 0f8585000000 6814000000 68???????? 6a04 8d8500fcffff 50 e8???????? }
- $sequence_6 = { 8d85dcf7ffff 50 57 56 }
- $sequence_7 = { 833d????????00 0f8fae050000 c705????????01000000 ff35???????? 8f45f0 ff35???????? 8f45f4 }
- $sequence_8 = { e8???????? ff75fc e8???????? 8b45f8 c9 c20400 ff25???????? }
- $sequence_9 = { e8???????? b800000000 c9 c21400 }
+ $sequence_0 = { e8???????? 8b7c2410 81c610020000 d1eb 45 85db 75b5 }
+ $sequence_1 = { 83c8ff 898e44020000 899648020000 57 894308 894304 8903 }
+ $sequence_2 = { 03c0 03c0 50 898374010000 e8???????? 8b8b74010000 83c404 }
+ $sequence_3 = { 8be5 5d c20c00 51 e8???????? 5e 5b }
+ $sequence_4 = { ffd7 895e24 8b461c 3bc3 741a 53 50 }
+ $sequence_5 = { eb21 83f805 7529 8d8c243c010000 51 8d842448030000 e8???????? }
+ $sequence_6 = { ff15???????? 8bf8 6a10 56 6861001100 }
+ $sequence_7 = { 52 8d6e18 55 8d7e0c 57 894608 e8???????? }
+ $sequence_8 = { ffd7 a3???????? 85c0 7412 8d4c2408 51 }
+ $sequence_9 = { 6a00 52 8bd8 56 895c2428 ff15???????? 8b4f0c }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <434176
}
-rule MALPEDIA_Win_Oski_Auto : FILE
+rule MALPEDIA_Win_Cotx_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e23300f3-24c2-58db-ad53-9ccc894ba178"
+ id = "4cbfd2a1-cbfc-5404-9f22-8e027db9306c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.oski"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.oski_auto.yar#L1-L187"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cotx"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cotx_auto.yar#L1-L111"
license_url = "N/A"
- logic_hash = "32e88579dcf8b669972c260572f27190a2af2a9bf4eb835092b7f8cb9a6a6e17"
+ logic_hash = "5f62f869de8e5b67f4dbb19d8460c8365da1f60d9f53861111556d3c0f9ba6d4"
score = 75
quality = 75
tags = "FILE"
@@ -133879,39 +140974,32 @@ rule MALPEDIA_Win_Oski_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 a1???????? 50 8d8df0feffff 51 e8???????? }
- $sequence_1 = { 25ff7f0000 c3 8bff 55 8bec 83ec14 ff7510 }
- $sequence_2 = { e8???????? 83c40c e8???????? 50 a1???????? 50 }
- $sequence_3 = { 8975f0 e8???????? cc 8bff 55 8bec 8b550c }
- $sequence_4 = { 7408 39b5acfeffff 7787 6803010000 8d95edfeffff 56 }
- $sequence_5 = { 83431810 66898568fbffff 8b4314 85c0 7577 8b8d84fbffff 51 }
- $sequence_6 = { 6a00 6a1a 6a00 8985eceeffff 898df0eeffff }
- $sequence_7 = { 53 68???????? 8d8de4feffff 51 53 }
- $sequence_8 = { e8???????? 83c404 56 8d85ecfeffff 50 8d8dd0fcffff }
- $sequence_9 = { f3c3 e9???????? 8bff 55 8bec 83ec1c a1???????? }
- $sequence_10 = { e8???????? 83c404 8b0d???????? 51 ff15???????? a3???????? 833d????????00 }
- $sequence_11 = { 8b5508 52 a1???????? 50 8d8de8fdffff }
- $sequence_12 = { 83c404 8b55f8 8955f4 8b45f4 50 e8???????? }
- $sequence_13 = { 50 8d4df8 51 6800020000 8b55f4 52 ff15???????? }
- $sequence_14 = { 6a00 e8???????? 83c40c 8985e4fdffff }
- $sequence_15 = { 8d55f4 52 6a00 68???????? ff15???????? 8945f0 }
- $sequence_16 = { 83c220 52 6a00 6a00 ff15???????? }
+ $sequence_0 = { c705????????890e9944 c705????????dbd99823 c705????????d468bcb5 c705????????a1a14538 c705????????2086e659 }
+ $sequence_1 = { 740e 3d10b6afa6 7407 3d36ce164d }
+ $sequence_2 = { 6800f00000 81c600f00000 68???????? 56 e8???????? }
+ $sequence_3 = { 50 51 8d85bcebffff 50 56 }
+ $sequence_4 = { c705????????d468bcb5 c705????????a1a14538 c705????????2086e659 c705????????eec45abf }
+ $sequence_5 = { c705????????9cb95b4c c705????????2d494a94 c705????????8db133d4 c705????????8e220b1d }
+ $sequence_6 = { 6800040000 8d8598f6ffff 6a00 50 e8???????? 83c40c 8d8598feffff }
+ $sequence_7 = { 8d850af8ffff c78500f8ffff52617354 6a00 50 }
+ $sequence_8 = { f3a4 50 0f1185a8faffff e8???????? }
+ $sequence_9 = { 8bce a3???????? e8???????? 8b15???????? 8b4dfc }
condition:
- 7 of them and filesize <423936
+ 7 of them and filesize <1171456
}
-rule MALPEDIA_Win_Karagany_Auto : FILE
+rule MALPEDIA_Win_Cloud_Duke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "edc2e98f-b8d5-5230-8689-3d1d2cb2218e"
+ id = "cde391f0-175a-570d-9bc3-d49da6ef8745"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.karagany"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.karagany_auto.yar#L1-L110"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cloud_duke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cloud_duke_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "52de418a32cc53d0482440cda283dab56320888d4a5fd4c0281ba321f99401f6"
+ logic_hash = "74b144312fec28eba9f5a0427613a86e81c08ef3fe8c6af23e7d4ebef780ba1f"
score = 75
quality = 75
tags = "FILE"
@@ -133925,34 +141013,34 @@ rule MALPEDIA_Win_Karagany_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d85a4fdffff 50 ffd6 68???????? }
- $sequence_1 = { 894ddc 894de4 894df0 894df8 894dfc }
- $sequence_2 = { 57 8bf8 6a03 57 ffd6 }
- $sequence_3 = { 57 8bf8 6a03 57 }
- $sequence_4 = { 6800300000 6800000300 6a00 ff15???????? }
- $sequence_5 = { 8bf8 6a03 57 ffd6 85c0 }
- $sequence_6 = { 8b35???????? 57 8bf8 6a03 }
- $sequence_7 = { 6a40 6800300000 6800000300 6a00 ff15???????? }
- $sequence_8 = { 6a03 53 ffd6 85c0 }
- $sequence_9 = { 57 8bf8 6a03 57 ffd6 85c0 }
+ $sequence_0 = { 8d4c2448 e8???????? 50 8d8c240c010000 e8???????? 8d4c2448 e8???????? }
+ $sequence_1 = { 8d8c240c010000 e8???????? 8d4c2460 e8???????? }
+ $sequence_2 = { 83fe04 7ce3 8b45e8 4b 8ad4 }
+ $sequence_3 = { 8d8c24d8000000 e8???????? 51 8d442434 }
+ $sequence_4 = { 50 e8???????? 8b7c2440 46 3bf7 }
+ $sequence_5 = { eb0a 8b9dd8fbffff eb02 8bde 8b85e8fbffff 8d95e4fbffff 52 }
+ $sequence_6 = { 85c9 7438 83fa01 7533 83bedc00000008 8d86c8000000 7202 }
+ $sequence_7 = { 8d04450c000000 50 6a00 57 }
+ $sequence_8 = { eb02 8bce 8b5518 ff75fc 03d2 895510 }
+ $sequence_9 = { 6806020000 50 668984241c010000 8d84241e010000 50 c744245c00000000 e8???????? }
condition:
- 7 of them and filesize <180224
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Xiaoba_Auto : FILE
+rule MALPEDIA_Win_Darkpulsar_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9683766b-1f7a-5c2a-bffb-7de9b80367d1"
+ id = "b29c7cf0-59bf-59a4-b8c5-d1ee53d551a4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xiaoba"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xiaoba_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkpulsar"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkpulsar_auto.yar#L1-L401"
license_url = "N/A"
- logic_hash = "52112f4a96abd368fbd89cb5e047b8d530704099fd198766e1597b7a0bbb2ccf"
+ logic_hash = "07b3040533891d5ece5d93ef76c617792a76fc1b169e5d22dab675082baad80b"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -133964,32 +141052,66 @@ rule MALPEDIA_Win_Xiaoba_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 58 8945ec e9???????? 8b5dfc 83c320 895dd0 6801030080 }
- $sequence_1 = { b801000000 c20c00 8b9024010000 8b44240c 8910 b801000000 c20c00 }
- $sequence_2 = { 8b5c243c 8b7c2464 8b542428 8b442430 03c3 42 89442430 }
- $sequence_3 = { dc442410 dd5c2410 e9???????? db8740010000 dc6c2418 dd5c2418 e9???????? }
- $sequence_4 = { 8b8894010000 33d2 85c9 0f95c2 8bc2 c20800 8b90b4010000 }
- $sequence_5 = { 8d54b500 8b3c02 8d44f500 83c704 57 50 e8???????? }
- $sequence_6 = { 85c9 7519 8b54240c 33c9 890a 8b8820010000 894a04 }
- $sequence_7 = { 85c0 be???????? 7505 be???????? e8???????? 8b4008 56 }
- $sequence_8 = { 8b10 52 e8???????? 83c404 8b4c2474 8901 8d4c2414 }
- $sequence_9 = { 8903 8965e8 6800000000 6800000000 6800000000 ff75f0 6800000000 }
+ $sequence_0 = { ff25???????? 33c0 40 c20c00 68???????? 64ff3500000000 }
+ $sequence_1 = { c20c00 68???????? 64ff3500000000 8b442410 896c2410 8d6c2410 2be0 }
+ $sequence_2 = { c21000 ff25???????? ff25???????? ff25???????? 33c0 }
+ $sequence_3 = { 3a01 1bc0 83e0fe 40 5f }
+ $sequence_4 = { 803f00 742e 47 ff450c 0fbe07 }
+ $sequence_5 = { 56 8b35???????? 57 8b7d08 eb09 }
+ $sequence_6 = { 59 59 3bd8 74e0 0fb607 }
+ $sequence_7 = { 50 ffd6 8bd8 8b450c 0fbe00 50 ffd6 }
+ $sequence_8 = { 56 e8???????? ff742414 50 e8???????? 83c410 }
+ $sequence_9 = { 6a01 50 ff15???????? 8bf0 59 }
+ $sequence_10 = { 83c410 83f8ff 0f95c1 49 8bc1 }
+ $sequence_11 = { 53 33d2 56 57 33c0 }
+ $sequence_12 = { ffd7 59 5f 5e c3 8b4c2404 85c9 }
+ $sequence_13 = { 8d45cc 50 57 e8???????? 83c410 85c0 }
+ $sequence_14 = { ffd6 59 59 8945f8 }
+ $sequence_15 = { f7d8 59 1bc0 59 40 c3 e9???????? }
+ $sequence_16 = { 8b5d10 56 8b7508 33d2 }
+ $sequence_17 = { e8???????? ff7514 89460c e8???????? }
+ $sequence_18 = { ff15???????? 8bf8 59 59 85ff 7502 }
+ $sequence_19 = { 8bc1 c3 8b442404 85c0 7501 c3 }
+ $sequence_20 = { 33c0 33d2 c3 8bff 55 8bec b863736de0 }
+ $sequence_21 = { e8???????? 59 5e 83f8ff }
+ $sequence_22 = { 59 5e 8b45fc c9 c3 }
+ $sequence_23 = { 56 e8???????? 59 85c0 7625 }
+ $sequence_24 = { e8???????? 8bf0 46 56 ff15???????? 59 }
+ $sequence_25 = { 40 894588 83659800 85c0 }
+ $sequence_26 = { 8903 894304 5f 8bc6 }
+ $sequence_27 = { ff75f0 56 57 ff15???????? 83c40c }
+ $sequence_28 = { 00db 7313 752f 3b742404 0f830b010000 }
+ $sequence_29 = { 8945cc 8945d0 8b4608 6a05 50 885dec }
+ $sequence_30 = { 66894df5 c745f702000000 e8???????? 83c408 }
+ $sequence_31 = { 0fb606 50 ff15???????? 83c41c 85c0 }
+ $sequence_32 = { 48 4e 897c2414 75eb 5f 8d4240 }
+ $sequence_33 = { 668903 8b45e8 8930 33c0 ebdc ff742408 ff15???????? }
+ $sequence_34 = { 00db 7309 75f4 8a1e 46 10db }
+ $sequence_35 = { 00db 7313 75e1 3b742404 0f8318010000 }
+ $sequence_36 = { 51 51 8b4508 8b4d0c 894dfc }
+ $sequence_37 = { 0facf908 c1ef08 48 4e }
+ $sequence_38 = { 8945e0 8945e4 8945d4 8945d8 8b450c 897de8 897ddc }
+ $sequence_39 = { 8d8df9feffff 53 51 899d5ceeffff 899d60eeffff }
+ $sequence_40 = { 8b4d08 8d7d0c 31c0 f3aa }
+ $sequence_41 = { ffd3 ff7594 ff15???????? 83c414 837d9c00 741c 837d0c07 }
+ $sequence_42 = { 33d7 c1ea10 5f 33d1 }
+ $sequence_43 = { 8bec 8b4508 894508 d94508 5d }
condition:
- 7 of them and filesize <5177344
+ 7 of them and filesize <491520
}
-rule MALPEDIA_Win_Formbook_Auto : FILE
+rule MALPEDIA_Win_Sodamaster_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5884ccaf-7c22-509b-b936-d78ce47dc38a"
+ id = "5c8830e9-776d-5d52-b260-bf93f938f131"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.formbook_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sodamaster"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sodamaster_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "1856083163db4d487acf8602c72ba34a2aeebb6a0e8b028efa10c5ca24fd0c49"
+ logic_hash = "a33360882a3ef608d87207bac124912433c6a8960ab3afceadfd4533af00bd98"
score = 75
quality = 75
tags = "FILE"
@@ -134003,32 +141125,32 @@ rule MALPEDIA_Win_Formbook_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5b 5f 5e 8be5 5d c3 8d0476 }
- $sequence_1 = { 6a0d 8d8500fcffff 50 56 e8???????? 8d8d00fcffff 51 }
- $sequence_2 = { 56 e8???????? 8d4df4 51 56 e8???????? 8d55e4 }
- $sequence_3 = { c3 3c04 752b 8b7518 8b0e 8b5510 8b7d14 }
- $sequence_4 = { 56 e8???????? 83c418 395df8 0f85a0000000 8b7d18 395f10 }
- $sequence_5 = { c745fc01000000 e8???????? 6a14 8d4dec 51 50 }
- $sequence_6 = { e8???????? 83c428 8906 85c0 75a8 5f 33c0 }
- $sequence_7 = { 56 e8???????? 6a03 ba5c000000 57 56 66891446 }
- $sequence_8 = { 3b75d0 72c0 8d55f8 52 e8???????? }
- $sequence_9 = { 8d8df6f7ffff 51 c745fc00000000 668985f4f7ffff e8???????? 8b7508 }
+ $sequence_0 = { e8???????? c70009000000 e8???????? ebd2 8bc3 c1f805 8d3c85a0330110 }
+ $sequence_1 = { 8908 894804 8bf0 eb02 33f6 6a40 6800100000 }
+ $sequence_2 = { 8d4900 8d97feefff7f 85d2 7419 8a140e 84d2 7412 }
+ $sequence_3 = { 8945e4 3d01010000 7d0d 8a4c181c 888810080110 40 }
+ $sequence_4 = { 33f6 6a40 6800100000 8d4301 50 6a00 ff15???????? }
+ $sequence_5 = { 83c424 83ffff 5f 5e 5b }
+ $sequence_6 = { 83c8ff e9???????? 8bc6 c1f805 8bfe 53 8d1c85a0330110 }
+ $sequence_7 = { 33f6 8d45f8 50 8b4508 c745e8636d643d c645ec00 }
+ $sequence_8 = { e8???????? 56 e8???????? 83c418 ff15???????? }
+ $sequence_9 = { 6a02 53 68ff010f00 52 }
condition:
- 7 of them and filesize <371712
+ 7 of them and filesize <134144
}
-rule MALPEDIA_Elf_Bashlite_Auto : FILE
+rule MALPEDIA_Win_Brambul_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ca6414ba-2b9c-5f1f-bb06-5810c9d01c02"
+ id = "fb37501d-8a53-5cc7-864b-a2eff1ebf028"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.bashlite_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.brambul"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.brambul_auto.yar#L1-L167"
license_url = "N/A"
- logic_hash = "38a010b68cee7bf4f221088e2245d1e5d0f927b085c409c35c3789c20373d434"
+ logic_hash = "b2fcad7678e1145848466f51e53045ab3d4628142b8e9b03697218392aef0c7d"
score = 75
quality = 75
tags = "FILE"
@@ -134042,32 +141164,38 @@ rule MALPEDIA_Elf_Bashlite_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb19 e8???????? c70016000000 e8???????? c70016000000 }
- $sequence_1 = { 21d0 3345fc c9 c3 55 }
- $sequence_2 = { 750c e8???????? 8b00 83f873 }
- $sequence_3 = { 8b85ecefffff c9 c3 55 }
- $sequence_4 = { 760f e8???????? c7001c000000 31c0 }
- $sequence_5 = { 31c0 eb19 e8???????? c70016000000 }
- $sequence_6 = { e8???????? 89c2 89d0 c1e81f 01d0 d1f8 }
- $sequence_7 = { 85c0 750c c785ecefffff01000000 eb0a c785ecefffff00000000 }
- $sequence_8 = { 85c0 750c c785ecefffff01000000 eb0a c785ecefffff00000000 8b85ecefffff }
- $sequence_9 = { c785ecefffff01000000 eb0a c785ecefffff00000000 8b85ecefffff c9 c3 }
+ $sequence_0 = { 66390a 750c 663908 8dbc5dc4000000 }
+ $sequence_1 = { d3e0 48 234508 8d0440 }
+ $sequence_2 = { 83f801 7269 6a08 6a40 ff15???????? 8b542414 }
+ $sequence_3 = { 8bd9 33ee c1eb14 c1e10c }
+ $sequence_4 = { c1e311 0bf3 8b5824 03f2 23ee 33e9 }
+ $sequence_5 = { 6800400000 6a00 ff15???????? 50 ff15???????? 8bd8 }
+ $sequence_6 = { 6a05 89b5b049ffff 58 8985a849ffff }
+ $sequence_7 = { 25ffff0000 3bf8 7cc9 8bc6 5f 5e 5d }
+ $sequence_8 = { 8d54242c c1e902 f3a5 8bc8 8d442470 }
+ $sequence_9 = { 68???????? ff15???????? 83c408 b804000000 5f 5e 5d }
+ $sequence_10 = { 8b8c2480010000 89942418010000 8984241c010000 8d942418010000 51 8d84245c010000 }
+ $sequence_11 = { 8d45e8 50 8bf3 8d85be49ffff 83e31f 83a5b85dffff00 }
+ $sequence_12 = { 89b404bc000000 83c004 83f840 7cd0 b910000000 }
+ $sequence_13 = { 8d7c2420 f3ab 8d442424 50 56 53 }
+ $sequence_14 = { 50 e8???????? 83f8ff 7517 8d4c2410 }
+ $sequence_15 = { c3 8b442404 c74050f0864000 c7401401000000 }
condition:
- 7 of them and filesize <2310144
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Unidentified_099_Auto : FILE
+rule MALPEDIA_Win_Observer_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "855e4e32-6d4e-59ad-a575-6df1a0196662"
+ id = "536559c4-9574-5591-915f-4694149d7210"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_099"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_099_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.observer_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.observer_stealer_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "258a0ad9f77598150260878a992142883eda125a250cf06189b6139c76537e6e"
+ logic_hash = "7a05fc963c0665c59a8fed1a8fc722896fb246e3248a23ceef5fd4c8486da3c7"
score = 75
quality = 75
tags = "FILE"
@@ -134081,34 +141209,34 @@ rule MALPEDIA_Win_Unidentified_099_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4d8bc4 418bd6 498bcf e8???????? 4c8d8df0010000 458bc6 498bd7 }
- $sequence_1 = { 488d4808 e8???????? 488d057dec0000 488903 488bc3 }
- $sequence_2 = { 488d0deb1effff 48c1e602 0fb784b910600100 488d9100570100 488d8d24030000 4c8bc6 4803cb }
- $sequence_3 = { 0fb6842930ef0100 4883c103 8802 488d5201 4881f959010000 7ce5 4533c9 }
- $sequence_4 = { 443820 75e4 8bca ffc2 4803c9 }
- $sequence_5 = { 488bd6 488be8 4d8d4715 488d442468 488bcd 4889442420 e8???????? }
- $sequence_6 = { 85c0 7424 8b15???????? 33c0 85d2 7418 }
- $sequence_7 = { 488d5b01 4883ef01 75d8 33c0 488dbdf0010000 }
- $sequence_8 = { ba02000000 660f1f440000 488d8980000000 0f1000 0f104810 }
- $sequence_9 = { c7442470fedcba98 c744247476543210 660f1f440000 49ffc0 42803c0000 75f6 488d55d0 }
+ $sequence_0 = { c1ea03 0fb60c02 8bc6 83e007 0fabc1 8b442414 }
+ $sequence_1 = { 8b5c2418 f6c301 746c 8b3e 85ff 7466 8b5e04 }
+ $sequence_2 = { 50 ff15???????? 8b4c2460 8d442440 50 e8???????? 8d4c2440 }
+ $sequence_3 = { e8???????? 68???????? 8d8d54ffffff e8???????? 68???????? 8d8d6cffffff }
+ $sequence_4 = { 59 eb3b 55 8b6b04 2bee c1fd02 56 }
+ $sequence_5 = { 85f6 740b 83feff 0f859a000000 eb6c 8b1c8d287e4300 }
+ $sequence_6 = { 8d8d60ffffff e8???????? 59 83781408 7202 8b00 }
+ $sequence_7 = { 8b442420 8918 5f 5e 5d 5b 83c40c }
+ $sequence_8 = { 85d2 7912 f7da e8???????? 6a2d 8d48fe 58 }
+ $sequence_9 = { 8d7c2468 894c2464 885c2450 ab ab ab ab }
condition:
- 7 of them and filesize <314368
+ 7 of them and filesize <614400
}
-rule MALPEDIA_Win_Unidentified_103_Auto : FILE
+rule MALPEDIA_Win_Qtbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "16a9604f-a791-56b5-96cf-005a08b625a2"
+ id = "ec8aa97a-290d-593c-aa5f-6c160f3c38cf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_103"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_103_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.qtbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.qtbot_auto.yar#L1-L168"
license_url = "N/A"
- logic_hash = "ea0101ff935636b4e103b28ee875e3c3a8b80a54f2863e597f7dff9a335e50db"
- score = 75
- quality = 75
+ logic_hash = "2c7689c956559567f13a9ec6cae95c5c067935d56f8491bff1983eb40f5f2838"
+ score = 60
+ quality = 25
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -134120,32 +141248,38 @@ rule MALPEDIA_Win_Unidentified_103_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85db 0f8506030000 8b442470 ffd0 8b542478 81c41c070000 }
- $sequence_1 = { 8954240c 8b9424e4000000 89742404 83ea04 89542408 8b8404cc0b0000 8b00 }
- $sequence_2 = { 83ec08 85c0 7439 8b8424bc010000 890424 8b44246c ffd0 }
- $sequence_3 = { 0fb613 89c3 8d6c11e0 01d1 }
- $sequence_4 = { 890424 8b842488000000 ffd0 83ec08 8b842484010000 890424 8b8424a4000000 }
- $sequence_5 = { 31db ffd6 c684249803000000 898424bc000000 b878650000 6689842496030000 b865000000 }
- $sequence_6 = { c744240804000000 89442404 8b842484010000 890424 8b8424ac000000 ffd0 }
- $sequence_7 = { 0f84d3070000 81fd03030000 0f85d5060000 8b842484010000 c744240402000000 89fb be01000000 }
- $sequence_8 = { 8bb4244c010000 01ca 880431 0fb68424a5010000 8844290a 0fb68424a6010000 8844290b }
- $sequence_9 = { 83ec08 0fb68c2450040000 84c9 741f 31d2 83c201 }
+ $sequence_0 = { 89450c 8d4301 0fb6d8 8a941dfcfeffff 0fb6c2 }
+ $sequence_1 = { 75e9 5b 5d c20400 }
+ $sequence_2 = { 25ffffff00 42 8a1a 84db }
+ $sequence_3 = { 8b049a 03c6 50 e8???????? }
+ $sequence_4 = { 33c0 53 8a1a 6bc80d 0fb6c3 83c0d0 }
+ $sequence_5 = { 03d6 8b481c 8b4018 03ce }
+ $sequence_6 = { 40 89450c 83ef01 75b1 8b4510 5f 5e }
+ $sequence_7 = { 85ff 7455 8b4510 89450c }
+ $sequence_8 = { 894dfc eb0e 8b14957c300010 49 0fafd1 0155fc }
+ $sequence_9 = { 8bd8 8d7e08 7504 8b2f eb02 }
+ $sequence_10 = { 0fb6805a210010 ff2485f6200010 8b8614080000 3b45f4 7e03 8945f4 8365fc00 }
+ $sequence_11 = { 6a00 ff15???????? 833e05 7521 6a10 6a40 ff15???????? }
+ $sequence_12 = { 8db720080000 833e00 751e 837efcff 7518 8b46f8 8b04855c300010 }
+ $sequence_13 = { 8b46f8 834de4ff 49 c745e8ff000000 8b3c857c300010 }
+ $sequence_14 = { 33c0 8b7df4 8b0c855c300010 c1e705 33d2 03fe }
+ $sequence_15 = { e8???????? 59 837e04ff 8bd8 8d7e08 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Ghost_Secret_Auto : FILE
+rule MALPEDIA_Win_Graphican_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1b3488d9-dad5-57ab-8ddb-ae7fa19ffb25"
+ id = "a2f03fc9-ee25-5fcd-896d-9bb49120884f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ghost_secret"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ghost_secret_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphican"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graphican_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "36f12490c5a1c42890949e26bd5a0482d94d3f78b5528e6a3d7d1ab5deca281b"
+ logic_hash = "a4c9c330e82d4ca3a447533684cd37026bb60c45e700ff39380301b043754c33"
score = 75
quality = 75
tags = "FILE"
@@ -134159,32 +141293,32 @@ rule MALPEDIA_Win_Ghost_Secret_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d852cf1ffff 50 e8???????? 8d8548fbffff 50 e8???????? 59 }
- $sequence_1 = { c68424af050000fd c68424b0050000f6 c68424b105000093 c68424b205000038 c68424b305000032 c68424b405000048 c68424b5050000e5 }
- $sequence_2 = { c68424b902000066 c68424ba02000072 c68424bb0200001a c68424bc0200004a }
- $sequence_3 = { c68424e903000052 c68424ea03000082 c68424eb03000058 c68424ec0300008e }
- $sequence_4 = { c684243e030000f0 c684243f030000f2 c68424400300003b c6842441030000c7 c6842454050000ab c684245505000087 c6842456050000d6 }
- $sequence_5 = { 85c0 740b 33c0 5f 5e 5b 8be5 }
- $sequence_6 = { ff15???????? e9???????? a1???????? 33db 3bc7 7e0e 50 }
- $sequence_7 = { c684247c05000006 c684247d0500003e c684247e05000012 c684247f05000053 c684248005000092 c684248105000042 c6842482050000e8 }
- $sequence_8 = { c644247460 c64424751f c6442476e7 c64424778a c6442478dd c68424f40000006a 888c24f5000000 }
- $sequence_9 = { 83c408 5f 5e 81c400200000 c3 81ecfc000000 }
+ $sequence_0 = { 8d5f07 83e3f8 03d3 3b10 7619 8b06 3bc3 }
+ $sequence_1 = { 3c65 7408 3c45 0f8570010000 47 807def00 897dc0 }
+ $sequence_2 = { 56 57 8bf1 8bfa 85db 7517 68a8010000 }
+ $sequence_3 = { 53 8bf0 6a00 56 e8???????? a1???????? }
+ $sequence_4 = { 8d0c89 8d4c48d0 8a07 42 3c30 7dd4 894de8 }
+ $sequence_5 = { 68???????? 68???????? e8???????? 83c40c 8b4ddc c7461810000000 894e1c }
+ $sequence_6 = { 8d85e8edffff 6a00 50 e8???????? 83c40c 68???????? }
+ $sequence_7 = { 68???????? 68???????? e8???????? 83c40c 8b5624 2b5620 }
+ $sequence_8 = { 8d8dc4efffff 51 50 ffd2 8bb5c4efffff 33ff }
+ $sequence_9 = { 8bd8 e8???????? 8d4311 83c404 }
condition:
- 7 of them and filesize <278528
+ 7 of them and filesize <362496
}
-rule MALPEDIA_Win_Meterpreter_Auto : FILE
+rule MALPEDIA_Win_Bee_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "94296578-89d7-5d7b-b7e4-efe037d64332"
+ id = "cf854a1b-a3fa-5497-9620-9eb04ca1acba"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.meterpreter"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.meterpreter_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bee"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bee_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "71f865d4008295f79c7afc49beb427fb0376821d7b27897466868baff3347cd2"
+ logic_hash = "d1087a1b19c31419362e6bad586912e9950c25554053241c2a8ca3db38a0bc54"
score = 75
quality = 75
tags = "FILE"
@@ -134198,32 +141332,32 @@ rule MALPEDIA_Win_Meterpreter_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 55 8bec dcec 088b55895356 108b3a85ff89 7dfc 750e }
- $sequence_1 = { fc b8c0150000 8b7508 33e5 257e040275 238b1d6a016a 006a00 }
- $sequence_2 = { f1 57 52 bc40e84fff 38ff 83db14 5f }
- $sequence_3 = { 314319 034319 83ebfc 0acb }
- $sequence_4 = { 0000 68ffff0000 52 ffd7 8b2410 }
- $sequence_5 = { 8be5 5d c27f00 8d4df4 8d55ec }
- $sequence_6 = { 51 6a00 6a00 37 0052bf 15???????? 85c0 }
- $sequence_7 = { 8b451c 8d07 a4 52 8d4d18 50 }
- $sequence_8 = { 41 00ff 15???????? 33c0 c3 7790 55 }
- $sequence_9 = { 83ec08 53 8b4708 57 33ff 85db }
+ $sequence_0 = { 0f8326010000 8bce d1e9 ba49922409 2bd1 3bd6 7304 }
+ $sequence_1 = { 83c404 89742418 c644244806 3bf3 741d 8b542414 }
+ $sequence_2 = { 668944241c 52 8d44241c 50 8d4c2438 c744242000000000 e8???????? }
+ $sequence_3 = { e8???????? 8b542424 56 6a00 52 e8???????? 8b7c2434 }
+ $sequence_4 = { 8d8424a4000000 8a10 3a11 751a 3ad3 7412 }
+ $sequence_5 = { 8bf9 80bfd800000000 754e 6a11 6a02 6a02 }
+ $sequence_6 = { e8???????? 8d0cb6 c1e104 03c8 89470c 894710 }
+ $sequence_7 = { 8bc3 8bcf e8???????? 2bf7 b867666666 f7ee }
+ $sequence_8 = { e8???????? 83c414 8b45fc ff34c5e4314200 }
+ $sequence_9 = { 64a300000000 8b6c2420 33db 895d04 885d0c }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <394240
}
-rule MALPEDIA_Win_Bubblewrap_Auto : FILE
+rule MALPEDIA_Win_Doorme_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "72aba578-e67d-518b-a6f8-45bcf7609dfd"
+ id = "86390d1e-5c43-5440-9d47-06677f2da02f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bubblewrap"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bubblewrap_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doorme"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doorme_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "461e952cc7ab9a2107d029741d486c2b8296d9f39ea5fcdb3208aa0e3f3d47fd"
+ logic_hash = "36db3801adbf1063a2540e3d2f2d2feff6537948c8fe3ef7123221f42e10e308"
score = 75
quality = 75
tags = "FILE"
@@ -134237,34 +141371,34 @@ rule MALPEDIA_Win_Bubblewrap_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? 68???????? e8???????? 8b08 83c408 890d???????? 8b5004 }
- $sequence_1 = { ffd6 8d542464 68???????? 52 ffd6 b900020000 }
- $sequence_2 = { 56 57 6a02 8d442418 33f6 55 50 }
- $sequence_3 = { 880c1a 83c9ff f2ae f7d1 49 8d7c1a01 8bd1 }
- $sequence_4 = { 81ec08020000 53 56 57 ff15???????? }
- $sequence_5 = { f3a5 6870010000 e8???????? 8d442448 50 6870010000 }
- $sequence_6 = { 8d6ced00 89542418 c1e503 8bc5 8bdd 25ff030000 }
- $sequence_7 = { 880f 8810 7c89 5d 5f 5e 5b }
- $sequence_8 = { c644241f78 c644242011 c644242106 c644242274 }
- $sequence_9 = { 83c404 a801 740d 8d54240c 52 e8???????? 83c404 }
+ $sequence_0 = { 48837e1810 7203 488b16 4c8b4610 488d4d58 e8???????? 488d5558 }
+ $sequence_1 = { 75f6 488bd7 488d4d68 e8???????? 90 4c8d8d10010000 }
+ $sequence_2 = { 41b111 41b207 450fb6da b312 0fb6f9 40b618 4533e4 }
+ $sequence_3 = { 488b05???????? 4833c4 48894537 488bda 488bf9 4889552f c6459700 }
+ $sequence_4 = { 498b7810 4885ff 7566 48897a10 }
+ $sequence_5 = { 488d5c2478 48837d9010 480f435c2478 488d05a23f0300 488945a0 c74424400e000000 }
+ $sequence_6 = { 488b00 498bcd ff5020 48894580 498b4500 498bcd ff5018 }
+ $sequence_7 = { 75f1 4983e801 75db 4883c510 4c8d15f06b0300 48836c243001 0f8564feffff }
+ $sequence_8 = { 488d8d20030000 e8???????? 488b7d80 488b07 488bcf ff5050 }
+ $sequence_9 = { 4889442440 448bc2 48894c2420 488bd9 }
condition:
- 7 of them and filesize <57136
+ 7 of them and filesize <580608
}
-rule MALPEDIA_Win_Dreambot_Auto : FILE
+rule MALPEDIA_Win_Lock_Pos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6c3809b8-d477-5125-8734-0179b265a99d"
+ id = "d847ae83-76cd-5967-803e-bdb0585a6606"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dreambot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dreambot_auto.yar#L1-L1031"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lock_pos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lock_pos_auto.yar#L1-L140"
license_url = "N/A"
- logic_hash = "d649e332b74326d8b7e280b52a73b7636b1baab8e64673c71262bd2586c99629"
+ logic_hash = "36f811da9c497d4d7cb3a11de01255e73f7c0aa2aa971faa2dbafeeb60cefda6"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -134276,141 +141410,35 @@ rule MALPEDIA_Win_Dreambot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { a802 7410 8b4730 a840 7509 83672800 e9???????? }
- $sequence_1 = { 897b20 8b4320 c6400731 8b742414 8b3e 6a00 }
- $sequence_2 = { 7454 68???????? 68???????? ff7320 e8???????? }
- $sequence_3 = { 0f8555ffffff 894730 e9???????? 55 8bec }
- $sequence_4 = { 85f6 0f84a9000000 e8???????? 85c0 0f8483000000 }
- $sequence_5 = { e8???????? 8bf8 85ff 755a 39451c 7475 }
- $sequence_6 = { 751a 395d10 7413 8b4618 e8???????? eb09 ff7618 }
- $sequence_7 = { 51 51 33c0 50 56 ff5214 8bfb }
- $sequence_8 = { 53 68???????? eb54 3bf3 745c 395d0c 7457 }
- $sequence_9 = { 837d0c04 7516 ff7510 ff36 68???????? }
- $sequence_10 = { ebcc 3bf3 7474 395d0c 746f 6a0d }
- $sequence_11 = { 3bf3 0f8496000000 395d0c 0f848d000000 6a07 ebdd }
- $sequence_12 = { 3bf3 0f8481000000 395d0c 747c 6a03 }
- $sequence_13 = { e8???????? 894508 8b7d08 eb24 a1???????? 85c0 7520 }
- $sequence_14 = { 745c 395d0c 7457 53 ff750c 8bfe c7450857000000 }
- $sequence_15 = { e8???????? e9???????? 3bf3 0f8496000000 }
- $sequence_16 = { 4803542460 41ff5220 4c8b442460 e9???????? }
- $sequence_17 = { e8???????? 4c8b1d???????? ba0d000000 41834b3401 }
- $sequence_18 = { 0f84b5000000 413bf5 0f84ac000000 41b807000000 ebd7 493bfd }
- $sequence_19 = { 4c896c2420 e8???????? 4c8b442468 488b0d???????? 33d2 }
- $sequence_20 = { 7423 41b904000000 413bf1 7518 8b17 }
- $sequence_21 = { 418d5620 498bcf ff15???????? 4c8bf0 4885c0 }
- $sequence_22 = { 498bcb 492bd0 4803542460 41ff5220 }
- $sequence_23 = { 0f8492000000 41b803000000 ebbd 493bfd 0f8481000000 413bf5 }
- $sequence_24 = { 4c8b18 488b542460 4533c9 488bc8 41ff5318 }
- $sequence_25 = { 488d5e10 4533f6 488b0b 2580000000 418d5620 }
- $sequence_26 = { ff15???????? e9???????? 493bfd 0f84d9000000 }
- $sequence_27 = { e8???????? eb2c 8b05???????? 413bc5 7528 }
- $sequence_28 = { 488b9424a8000000 4533c9 4533c0 ff5028 }
- $sequence_29 = { 0f8481000000 413bf5 747c 41b80d000000 }
- $sequence_30 = { 488bcf e8???????? e9???????? 493bfd 0f84b5000000 }
- $sequence_31 = { 5f c3 4053 4883ec20 4c8b4108 488bd9 4d85c0 }
- $sequence_32 = { 0f849b000000 413bf5 0f8492000000 41b803000000 ebbd }
- $sequence_33 = { 33d2 89442448 ff15???????? 33d2 }
- $sequence_34 = { 33d2 3bc2 0f85bd000000 33c0 89942498000000 }
- $sequence_35 = { e8???????? 488b5c2428 85c0 753e 8b9424c8000000 }
- $sequence_36 = { 3decc7eea6 0f84e8000000 3d0470a8c4 0f8486000000 }
- $sequence_37 = { 488b0d???????? 4d8bc4 33d2 ff15???????? 488bf8 }
- $sequence_38 = { 4883ec30 837a3c04 4c8b2a 488bf2 488bd9 }
- $sequence_39 = { 89750c 8d750c e8???????? 8bf0 }
- $sequence_40 = { 4883c208 4883e901 75e2 837c243801 0f86b2000000 }
- $sequence_41 = { 8b450c 33db 895dfc e8???????? 8945f8 33ff eb03 }
- $sequence_42 = { 75f5 eb06 8b05???????? 35fc5585cf 4533c9 }
- $sequence_43 = { ff7310 ff15???????? 33d2 89b7184a0000 39971c4a0000 }
- $sequence_44 = { ff33 50 6810040000 ff15???????? 8945fc }
- $sequence_45 = { 56 33f6 46 8945f8 }
- $sequence_46 = { c3 6a00 6800004000 6a00 ff15???????? a3???????? 85c0 }
- $sequence_47 = { 46 8945f8 85c0 7551 }
- $sequence_48 = { 57 4883ec20 8b05???????? 8364243800 }
- $sequence_49 = { ff15???????? 8945fc 85c0 741a 6804010000 }
- $sequence_50 = { 85c0 7551 ff33 50 }
- $sequence_51 = { eb03 8b750c ff75f8 69f60d661900 ff75f4 81c65ff36e3c 89750c }
- $sequence_52 = { 817424105085b8ed 33ff 47 57 be???????? 56 8d542418 }
- $sequence_53 = { 1bdb f7db 83c303 ebc4 }
- $sequence_54 = { 8b9424c8000000 85d2 7421 4533c9 }
- $sequence_55 = { 4883f8ff 488bf8 7445 488d842488000000 }
- $sequence_56 = { 48c7c101000080 ff15???????? 85c0 7568 4c8d8c24d0000000 4c8d8424c8000000 488d542428 }
- $sequence_57 = { 4c8bc3 33d2 ff15???????? 4821742428 4c8d8424c8000000 488d542428 488d4c2450 }
- $sequence_58 = { 4883c208 4983e801 75e4 8b442420 }
- $sequence_59 = { 0f84ca010000 8b424c a801 0f840f010000 8b424c }
- $sequence_60 = { 33c0 89942498000000 899424a8000000 8984249c000000 }
- $sequence_61 = { 498be9 e8???????? 4885c0 488bf0 0f84a3000000 }
- $sequence_62 = { 8db4083089b9ed 57 8d45f4 50 }
- $sequence_63 = { 4d3bef 7415 498bd5 4883c9ff }
- $sequence_64 = { 8b45fc 0fb700 8bc8 81e100f00000 }
- $sequence_65 = { ff75fc e8???????? 8b45f0 40 c745e801000000 }
- $sequence_66 = { 4c8bc6 ff15???????? 488bd8 493bc7 }
- $sequence_67 = { 395d10 0f8402010000 6a03 eb13 3bf3 }
- $sequence_68 = { 6a01 eb3d 3bf3 0f8420010000 }
- $sequence_69 = { 8d85a2fcffff 53 50 895de4 e8???????? }
- $sequence_70 = { 4885c9 7405 e8???????? 4883c428 c3 4053 }
- $sequence_71 = { 493bc5 742f 488d4810 ff15???????? }
- $sequence_72 = { 57 6806020000 668985a0fcffff 8d85a2fcffff 53 }
- $sequence_73 = { 8be5 5d c20400 8325????????00 6a00 }
- $sequence_74 = { 740e 44893d???????? 44893d???????? 488d442440 4c8d4c2440 4c8d442440 4889442430 }
- $sequence_75 = { 89410e 5f 5e 5b c9 c20400 }
- $sequence_76 = { 8bf0 33db 81c1fefeffff 33c0 83cfff 33d2 895dfc }
- $sequence_77 = { 59 c20400 a1???????? 53 55 56 57 }
- $sequence_78 = { 7505 8d5857 eb15 488b05???????? 89702a 48897d00 eb17 }
- $sequence_79 = { eb08 ff15???????? 8bd8 413bde 0f85fb010000 488b05???????? }
- $sequence_80 = { 66b90100 4889442420 e8???????? 3bc3 0f859b000000 }
- $sequence_81 = { a1???????? 83c036 83c9ff f00fc108 }
- $sequence_82 = { 0f8e2a040000 8a05???????? 4238042b 7521 448bc2 4963ce }
- $sequence_83 = { e8???????? 488b0d???????? 448be0 f0834156ff 85c0 }
- $sequence_84 = { 83c036 41 f00fc108 a1???????? 83c01e 50 }
- $sequence_85 = { 488bf0 eb34 488d0595d6ffff 4885c0 7428 }
- $sequence_86 = { 6a0a ff15???????? a1???????? 8b4036 }
- $sequence_87 = { ffb72c080000 e8???????? 5e 5d 5b c3 eb10 }
- $sequence_88 = { e9???????? 83f916 0f8fa7080000 0f8415080000 }
- $sequence_89 = { 83c01e 50 ff15???????? 8a06 3a4704 7311 8b0f }
- $sequence_90 = { 33d2 e8???????? 44892d???????? 33c9 44892d???????? e8???????? 488bcf }
- $sequence_91 = { 8d4604 66d3e0 66098310170000 8d4103 }
- $sequence_92 = { 488b0d???????? 4883c12e ff15???????? 4c8b05???????? 448d7b02 }
- $sequence_93 = { 8b9314170000 83432801 b910000000 8d42f3 2aca }
- $sequence_94 = { a1???????? 8b4c2404 8908 83c01e 50 ff15???????? }
- $sequence_95 = { 83a78c00000000 33c0 c3 51 e8???????? }
- $sequence_96 = { 8b4036 85c0 75ec 8b442404 53 8a1e }
- $sequence_97 = { 5f 5e 5b c20800 51 53 57 }
- $sequence_98 = { e9???????? 83e908 74eb 2bcb 0f84fa000000 2bcb }
- $sequence_99 = { a1???????? 6a00 e8???????? a1???????? 83c01e 50 ff15???????? }
- $sequence_100 = { c3 33c0 483bc8 7458 488b5128 483bd0 }
- $sequence_101 = { c9 c20800 55 8bec 81ec1c010000 8d4807 83e1f8 }
- $sequence_102 = { 5b 8be5 5d c3 0fb708 6683f902 751c }
- $sequence_103 = { 488bd8 488b05???????? f0834056ff 4885db 0f84ec000000 }
- $sequence_104 = { ffd7 8b1d???????? 6a3a b8???????? 56 }
- $sequence_105 = { 48895c2408 57 4883ec30 488bd9 488b0d???????? 488bfa 4883c12e }
- $sequence_106 = { 488b15???????? 4c8d442468 48c7c101000080 ff15???????? }
- $sequence_107 = { 83839c000000ff 397818 0f852ffcffff 33c0 }
- $sequence_108 = { ff35???????? c74424200e440410 c744241c08000000 ffd6 8bf8 }
- $sequence_109 = { e8???????? 8bf0 83fe0c 74c5 3bf3 0f8581020000 a1???????? }
- $sequence_110 = { 8b831c70be03 3305???????? 8b3d???????? 50 33f6 56 8bef }
- $sequence_111 = { c1e804 46 33048d1062be03 85ff }
- $sequence_112 = { 7470 8b3d???????? 56 c7459c44000000 ffd7 8d45e8 50 }
- $sequence_113 = { 397dfc 7417 a1???????? 8b55fc 354c4e4c7e 50 }
- $sequence_114 = { e8???????? 3bc5 89442430 0f84ac010000 53 55 }
- $sequence_115 = { 3934850875be03 742a 8d41ff 85c0 7c10 3934850875be03 7403 }
- $sequence_116 = { 8b30 03f5 85f6 89b31c70be03 740a }
- $sequence_117 = { 68???????? ffd6 a3???????? 33ff 8db7c4260410 }
- $sequence_118 = { ff75ec 8b3d???????? 8bd8 ffd7 ff75e8 ffd7 eb08 }
+ $sequence_0 = { 8bec 8b4508 8b0d???????? 8b0481 }
+ $sequence_1 = { 55 8bec 837d0800 7704 }
+ $sequence_2 = { 55 8bec 81eca4040000 56 }
+ $sequence_3 = { 8d85f8fdffff 50 6a00 6a00 6a23 6a00 ff15???????? }
+ $sequence_4 = { 0fb64dfb 85c9 741c 8b5514 8b45fc }
+ $sequence_5 = { 2bc8 c745fc04000000 8a1401 8810 40 }
+ $sequence_6 = { 8b55f8 8b4508 8910 8b45c4 }
+ $sequence_7 = { 3bc6 0f85a1000000 32db e8???????? 84db }
+ $sequence_8 = { 8b55fc 8b450c 0fb70c50 334d14 }
+ $sequence_9 = { 33c9 84c0 0f95c1 41 51 ff75e4 }
+ $sequence_10 = { 894dfc 8b55dc 83c201 8955dc ebd2 8b45f8 }
+ $sequence_11 = { e8???????? 83c408 8d9568ffffff 52 e8???????? 83c404 50 }
+ $sequence_12 = { 50 eb4b 8b45f8 3bc3 764e 03c7 }
condition:
- 7 of them and filesize <802816
+ 7 of them and filesize <319488
}
-rule MALPEDIA_Win_Poldat_Auto : FILE
+rule MALPEDIA_Win_Batchwiper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a4b71e9b-caa3-5e09-abcb-8fc111c1e88a"
+ id = "cb044b8c-027b-5368-bd79-45da5d915947"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poldat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poldat_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.batchwiper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.batchwiper_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "eec21397be824c40480269ad179cee66cff4f29ddc631fb679aa6de7be434481"
+ logic_hash = "14983b1d6532d433e6ad6924f17da812f5983b6eabd0fde8fd8892a9d3b6fb0b"
score = 75
quality = 75
tags = "FILE"
@@ -134424,32 +141452,32 @@ rule MALPEDIA_Win_Poldat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b35???????? 6a08 66ab 58 }
- $sequence_1 = { 57 6a05 6a00 68???????? }
- $sequence_2 = { 50 e8???????? 68fe010000 8d86b8070000 57 }
- $sequence_3 = { 8a50ff 881431 41 48 3d???????? 7ff1 8d45fc }
- $sequence_4 = { 8b0c9d68c34100 8b5e04 23ca 03cb 33db 8a1cce 8d34ce }
- $sequence_5 = { 50 ff15???????? 56 e8???????? 59 5f 5e }
- $sequence_6 = { 8b4c241c 8b0c8d68c34100 23cf 03c1 8b4c241c d3ef 03ca }
- $sequence_7 = { 750a c74720a0324000 895728 395724 7507 }
- $sequence_8 = { 7233 e9???????? 8b4c243c 8b5c2410 8b7104 c7411824d84100 }
- $sequence_9 = { f7f9 8bfa ffd6 50 }
+ $sequence_0 = { 83c001 8bce c1e908 330c9de8904000 }
+ $sequence_1 = { 8b0424 894510 8b442408 894514 8b442404 }
+ $sequence_2 = { 8b442408 894514 8b442404 894518 8d44240c }
+ $sequence_3 = { e8???????? 50 31db 3b1c24 756b }
+ $sequence_4 = { 89d8 e8???????? 89c3 83fb01 7531 ff35???????? }
+ $sequence_5 = { 83fb01 7531 ff35???????? ba???????? e8???????? 8b15???????? e8???????? }
+ $sequence_6 = { e8???????? 89c3 83fb01 7531 ff35???????? ba???????? }
+ $sequence_7 = { e8???????? 8d0d28b14000 5a e8???????? 8b15???????? ff35???????? e8???????? }
+ $sequence_8 = { ba???????? e8???????? 8d0d28b14000 5a e8???????? 8b15???????? ff35???????? }
+ $sequence_9 = { c705????????02000000 893d???????? c705????????dd424000 c705????????80464000 c705????????da464000 c705????????00474000 }
condition:
- 7 of them and filesize <247808
+ 7 of them and filesize <270336
}
-rule MALPEDIA_Win_Systembc_Auto : FILE
+rule MALPEDIA_Win_Getmypass_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "33299700-4e02-5584-bb63-8a8197d8417b"
+ id = "083431d4-35f0-5afc-be73-c4abda9f956c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.systembc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.systembc_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.getmypass"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.getmypass_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "29f113c1b3510221b57bbc147c9c5017608a490a95fbc04ce80eea2621980153"
+ logic_hash = "73655fc056c3c045e75de418123d8e1cd087892e700c185d02f9fb25dda3b86c"
score = 75
quality = 75
tags = "FILE"
@@ -134463,32 +141491,32 @@ rule MALPEDIA_Win_Systembc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b8e88010000 8b968c010000 8bb690010000 8945e4 895df4 }
- $sequence_1 = { 52 6a00 6a00 6a00 ffb568f9ffff }
- $sequence_2 = { 668b9554f9ffff 6a00 6a00 6a03 6a00 6a00 }
- $sequence_3 = { 898568f9ffff c7856cf9ffff00040000 8d853cf9ffff 50 6a00 6a00 }
- $sequence_4 = { 81c200008000 81c200100000 81c200200000 6a00 52 }
- $sequence_5 = { 8d851cf4ffff 50 6800010000 57 ffb530f4ffff }
- $sequence_6 = { 50 e8???????? ffd0 8b85f4feffff }
- $sequence_7 = { 43 3b5dfc 7296 33c0 5e 5f }
- $sequence_8 = { 668b9554f9ffff 6a00 6a00 6a03 6a00 }
- $sequence_9 = { 57 56 8b7d10 33c0 }
+ $sequence_0 = { 83c201 8955fc ebcb 837dfc05 7e04 b001 eb02 }
+ $sequence_1 = { 0fb64d08 85c9 7418 8b9594fdffff 52 }
+ $sequence_2 = { 68???????? 68???????? e8???????? 83c408 8945fc 837dfc00 7463 }
+ $sequence_3 = { 6a00 8b45f8 50 ff15???????? e8???????? }
+ $sequence_4 = { 8945f4 837df400 742d 8b55f4 0fb702 83f831 750c }
+ $sequence_5 = { e8???????? 83c404 a3???????? 8b55f8 52 e8???????? 83c404 }
+ $sequence_6 = { 83f835 7409 0fbe4d08 83f934 }
+ $sequence_7 = { e8???????? 83c404 8945fc 837dfcff 740e }
+ $sequence_8 = { 8b55f8 8b4204 2b450c 8b4df8 0301 50 }
+ $sequence_9 = { 83f801 7509 c745e400000000 eb17 8b5508 83c201 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Unidentified_045_Auto : FILE
+rule MALPEDIA_Win_Byeby_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a8bfd3f0-95b3-5af9-8c6f-fa63b3ef83b3"
+ id = "74fc8a87-5c7b-524e-8e78-621f0d855f26"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_045"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_045_auto.yar#L1-L104"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.byeby"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.byeby_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "16726755d5995c8139758648ed741d294bd49338a51b6fd2af1cb4cf9c59e23f"
+ logic_hash = "ea138eeca75e1ffbb323be9c4364fb51ef613b1a9fd77855f97073778ad7174f"
score = 75
quality = 75
tags = "FILE"
@@ -134502,30 +141530,32 @@ rule MALPEDIA_Win_Unidentified_045_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? 83c40c 68???????? 68???????? 68???????? e8???????? }
- $sequence_1 = { 8930 8935???????? eb2b 837d0c02 7528 8b35???????? }
- $sequence_2 = { 8bc7 eb5c 33f6 85f6 7609 }
- $sequence_3 = { 6804010000 8d44244c 57 50 e8???????? 8b35???????? }
- $sequence_4 = { ff15???????? 33f6 56 56 6a02 56 56 }
- $sequence_5 = { 6a01 56 56 ff7508 897dac 56 }
- $sequence_6 = { 3345fc 5e c9 c3 803d????????00 }
- $sequence_7 = { 6a0c 50 57 8975f4 }
+ $sequence_0 = { e8???????? 68???????? 8d45f0 c745f0f4320110 }
+ $sequence_1 = { e8???????? 8b7df0 83c40c 037e74 c7467400000000 eb03 }
+ $sequence_2 = { 8bf0 53 ff742430 6a00 6a00 }
+ $sequence_3 = { 50 8b8528e5ffff 0f94c1 898d3ce5ffff 8b8d24e5ffff 8b048518ab0110 ff3401 }
+ $sequence_4 = { 8b8528e5ffff 8b048518ab0110 ff3401 ff15???????? 8bb540e5ffff 8bbd34e5ffff 85c0 }
+ $sequence_5 = { 8d84245c020000 50 c78424600200005630564d c78424640200005130394e ffd7 40 50 }
+ $sequence_6 = { 8b35???????? 8d442410 50 ff35???????? }
+ $sequence_7 = { 7309 8b04c5e84e0110 5d c3 33c0 }
+ $sequence_8 = { 0f8641010000 8b4c2420 83c714 8bff 837ff005 0f85fa000000 0fb707 }
+ $sequence_9 = { 3b0cc510900110 7427 40 83f82d 72f1 8d41ed }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Advisorsbot_Auto : FILE
+rule MALPEDIA_Win_Kagent_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4423ed68-193a-5b69-9a0c-e4a68868d775"
+ id = "03cb1012-1d40-5351-bbf3-a59896f7ae1b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.advisorsbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.advisorsbot_auto.yar#L1-L169"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kagent"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kagent_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "63e408f2b85153604b6cbce7b119689dceb4fed854cd697bc92427d51dad5ae1"
+ logic_hash = "0b8f6427b4a4852531dd043f44e54d80aff6015551c819a2c415062a93726e8a"
score = 75
quality = 75
tags = "FILE"
@@ -134539,41 +141569,32 @@ rule MALPEDIA_Win_Advisorsbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bc1 2bc2 d1e8 03c2 c1e808 }
- $sequence_1 = { 8bc2 33d2 c1e809 f7f1 }
- $sequence_2 = { 8bc2 33d2 c1e808 f7f1 }
- $sequence_3 = { b89b01a311 f7e1 2bca d1e9 03ca }
- $sequence_4 = { d1e8 03c2 33d2 c1e809 }
- $sequence_5 = { 8bc2 c1e809 33d2 f7f1 }
- $sequence_6 = { 8b442408 8b4c2408 33d2 f7f1 }
- $sequence_7 = { d1e9 03ca 33d2 c1e909 }
- $sequence_8 = { d1e9 03ca c1e907 2bc1 }
- $sequence_9 = { b839811338 f7e1 8bc1 2bc2 }
- $sequence_10 = { d1e9 03ca c1e909 33c8 }
- $sequence_11 = { 8bc2 33d2 c1e804 f7f1 }
- $sequence_12 = { 8bca f7e2 8bc1 2bc2 }
- $sequence_13 = { 668b4c2410 5f 5e 5d }
- $sequence_14 = { 0fb7c1 0fb7ca 33d2 f7f1 }
- $sequence_15 = { 0fb7c0 0fb7c9 33d2 f7f1 }
- $sequence_16 = { 0fb6c0 0fb6c9 33d2 f7f1 }
- $sequence_17 = { 8b442414 8b4c2414 33d2 f7f1 }
- $sequence_18 = { 5e 5d 0fb7c2 5b }
+ $sequence_0 = { 84c9 75f9 2bc2 888c2474020000 33c9 89442440 66894c2452 }
+ $sequence_1 = { e8???????? 8be5 5d c20400 8d4de8 51 c7434c00000080 }
+ $sequence_2 = { 8b75e8 52 51 e8???????? 8b4508 }
+ $sequence_3 = { c645fc04 884b48 0f90c1 f7d9 0bc8 51 }
+ $sequence_4 = { 8bd0 2bd6 0fb70432 0fb70e 2bc1 }
+ $sequence_5 = { 884608 33c9 b801000000 ba02000000 f7e2 0f90c1 f7d9 }
+ $sequence_6 = { 57 ff15???????? 85c0 7514 83c604 81fe???????? 7cd7 }
+ $sequence_7 = { e8???????? 894624 c6462801 8b4624 33c9 895e20 668908 }
+ $sequence_8 = { 0f858cfcffff 8b542420 8d0411 39442438 8b5378 0f94c1 }
+ $sequence_9 = { 50 e8???????? 83c404 8a45f3 8b4df4 64890d00000000 59 }
condition:
- 7 of them and filesize <434176
+ 7 of them and filesize <4972544
}
-rule MALPEDIA_Win_Wmighost_Auto : FILE
+rule MALPEDIA_Win_Laziok_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0b0db58b-a86c-5fcd-a072-2eb1cc17420a"
+ id = "1dcbce9e-9b01-55fc-82f2-025bf107fa98"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wmighost"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wmighost_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.laziok"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.laziok_auto.yar#L1-L101"
license_url = "N/A"
- logic_hash = "ca34789fba1f2bd4e0c465ce04013e3b6750b48b70cd8c7936238cd0c587d01a"
+ logic_hash = "8a49fb3e99a85f8254a739f5aaca9e9bb1b5be0f2dd72574e619043b4fccb1ed"
score = 75
quality = 75
tags = "FILE"
@@ -134587,34 +141608,32 @@ rule MALPEDIA_Win_Wmighost_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 e8???????? 83c40c 68e8030000 ff15???????? e9???????? }
- $sequence_1 = { 83c408 68???????? 8d8df0fcffff 51 }
- $sequence_2 = { c745fc00000000 8d4d08 e8???????? 50 8b45e8 8b08 }
- $sequence_3 = { 8945fc 837dfcff 7505 e9???????? 6a02 }
- $sequence_4 = { 8b550c 52 8d85f0fcffff 50 e8???????? 83c408 }
- $sequence_5 = { 33c1 8b55f8 8882c8304000 8b45f8 0fbe88c8304000 33d2 8a15???????? }
- $sequence_6 = { 66ab aa c685f0fcffff00 b940000000 33c0 8dbdf1fcffff }
- $sequence_7 = { 50 8b4df0 51 e8???????? c745fcffffffff 8d4d08 e8???????? }
- $sequence_8 = { 8dbdfdfeffff f3ab 66ab aa c685f0fcffff00 b940000000 }
- $sequence_9 = { 8955e4 8b45ec 50 8b4de4 51 6aff }
+ $sequence_0 = { 85f6 740b 837c240cff 8937 7502 }
+ $sequence_1 = { 47 68???????? 57 e8???????? 8bf0 59 }
+ $sequence_2 = { 8d85f4fdffff 50 e8???????? 33c0 668945fc }
+ $sequence_3 = { 68ffffff1f 52 e8???????? 83c410 c3 }
+ $sequence_4 = { e8???????? 83c420 5b c20400 }
+ $sequence_5 = { 56 8b7508 833e01 7513 6a00 ff7510 ff750c }
+ $sequence_6 = { 39742410 741b ff742410 ff15???????? 8bf0 }
+ $sequence_7 = { 56 57 ff74240c 33f6 ff35???????? e8???????? }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <688128
}
-rule MALPEDIA_Elf_Blackcat_Auto : FILE
+rule MALPEDIA_Win_Mozart_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8a7e13ba-9ed1-59ed-8fb9-9aaa610fbd94"
+ id = "1438b6f5-0fc9-5eca-9ae3-36eb59239394"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.blackcat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.blackcat_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mozart"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mozart_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "1ac97428ed273512eef4209d87a29f49ce26e88d11cb15b15e2f2687ea017381"
- score = 60
- quality = 45
+ logic_hash = "94b0456ee335dcdb1592bd3a0f2b861e74a91bd5433e8fc753965fb9891ac5e3"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -134626,32 +141645,32 @@ rule MALPEDIA_Elf_Blackcat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 0f0b 90 90 90 90 53 }
- $sequence_1 = { 69c0???????? c1e811 6bf064 29f2 0fb7d2 }
- $sequence_2 = { e8???????? 0f0b 90 53 }
- $sequence_3 = { 89c1 3d???????? 7319 c1e906 }
- $sequence_4 = { 660f7f8424f0010000 660f7f8424e0010000 660f7f8424d0010000 660f7f8424c0010000 660f7f8424b0010000 }
- $sequence_5 = { d1e9 01d1 c1e902 8d14cd00000000 }
- $sequence_6 = { b801000000 81f9???????? 0f823fffffff b802000000 }
- $sequence_7 = { 69c0???????? c1e810 29c2 0fb7d2 d1ea }
- $sequence_8 = { 762a 0fb6c8 8d1489 8d0cd1 }
- $sequence_9 = { e8???????? 0f0b e8???????? 0f0b 90 90 90 }
+ $sequence_0 = { 7c26 80fb39 7f21 885c3418 46 }
+ $sequence_1 = { 66ab e8???????? 8d44242c 50 e8???????? 8d8c2430010000 51 }
+ $sequence_2 = { c1f805 8d1c85c0db4000 8b03 8bf1 83e61f c1e603 8a443004 }
+ $sequence_3 = { 49 7438 49 7471 c1e006 0bc7 }
+ $sequence_4 = { 55 8bec 83e4f8 81ec20020000 a1???????? 8b0d???????? 668b15???????? }
+ $sequence_5 = { 8bf0 83e61f 8d3c8dc0db4000 8b0f c1e603 f644310401 7455 }
+ $sequence_6 = { 8a08 40 84c9 75f9 8b8c2420100000 }
+ $sequence_7 = { 2bc7 3bf0 7202 33f6 8bc5 43 42 }
+ $sequence_8 = { 8b0a 83c502 3be9 7728 }
+ $sequence_9 = { 751a 84c0 7426 8b5608 47 }
condition:
- 7 of them and filesize <8011776
+ 7 of them and filesize <114688
}
-rule MALPEDIA_Win_Pickpocket_Auto : FILE
+rule MALPEDIA_Win_Play_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9a488247-9e86-5930-98a0-6918c231e819"
+ id = "e5dc4ad0-4963-56ca-a5e5-83aec2390f77"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pickpocket"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pickpocket_auto.yar#L1-L111"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.play"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.play_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "d7990d44202646b62032b82a90fb7e07e373731a34449c62076ef24e8ce04d57"
+ logic_hash = "633aef027703dbbff9f2f212af038ee3039813400893deac0150b99c35143631"
score = 75
quality = 75
tags = "FILE"
@@ -134665,32 +141684,32 @@ rule MALPEDIA_Win_Pickpocket_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 750f b962890100 e8???????? }
- $sequence_1 = { 7e1e b9dccc0000 e9???????? b9cecc0000 e9???????? b9c7cc0000 }
- $sequence_2 = { 7404 8b01 eb03 83c8ff 83f804 }
- $sequence_3 = { d3e0 a846 750f b99be00100 e8???????? e9???????? }
- $sequence_4 = { e8???????? 85c0 750e b958de0100 }
- $sequence_5 = { 85c0 750e b958de0100 e8???????? 8bc8 }
- $sequence_6 = { 85c0 740f b989000100 e8???????? }
- $sequence_7 = { 7e16 b91bcc0000 eb05 b916cc0000 }
- $sequence_8 = { eb0c b96ccb0000 eb05 b960cb0000 }
- $sequence_9 = { eb09 8bc7 eb0a b9a9d60000 e8???????? }
+ $sequence_0 = { 0fb78d82feffff 2bc8 899570ffffff 014d84 }
+ $sequence_1 = { 02c1 c645c5ae 8845c3 b937030000 888556ffffff 8a45c7 c6852fffffff00 }
+ $sequence_2 = { 8bd8 899d88fdffff 85db 0f8483040000 8a0b 80f9e9 7409 }
+ $sequence_3 = { c83dad3c d92b e00c 9c 0d05f0657b 4e f30f7e05???????? }
+ $sequence_4 = { 7f06 81c4ab000000 83c410 e8???????? 66f1 }
+ $sequence_5 = { a1???????? 8945bc a1???????? 0f11855cffffff 894594 f30f7e05???????? 8b45f8 }
+ $sequence_6 = { 91 ae 54 ce 3106 f77cf30f 7e05 }
+ $sequence_7 = { 8955f4 8b460c 83ec08 8d0488 8945f8 8d45f4 }
+ $sequence_8 = { 898d48fdffff 66898562fdffff 668985e6fcffff 66398d30fdffff 7634 66ff857cfcffff 8d0432 }
+ $sequence_9 = { 88852effffff 8b8548ffffff fec8 8855ad 88854dffffff 8d45e8 6689bd0cfeffff }
condition:
- 7 of them and filesize <1458176
+ 7 of them and filesize <389120
}
-rule MALPEDIA_Win_Spectre_Auto : FILE
+rule MALPEDIA_Win_Redcurl_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "af0ed3ea-7150-5006-a1e4-f1f71a7eae7a"
+ id = "efe32a98-15fa-5dd0-a3ff-0a4fdcaec5ff"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spectre"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spectre_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redcurl"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redcurl_auto.yar#L1-L190"
license_url = "N/A"
- logic_hash = "168b0e3a3116ff3325056de927c137c412a6159d98ef56a6628c736a2a7417ad"
+ logic_hash = "550bb424cec4343fdcbf9ff6b82c03a2bb6c5d2f01439a45b43da803dcee1f93"
score = 75
quality = 75
tags = "FILE"
@@ -134704,32 +141723,42 @@ rule MALPEDIA_Win_Spectre_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ebe3 83c8ff 5d 5b 59 59 c3 }
- $sequence_1 = { 68???????? ff5604 e9???????? 807c242000 0f8414010000 6a02 }
- $sequence_2 = { 51 e8???????? 59 59 8b8424ec000000 895c2470 896c2474 }
- $sequence_3 = { 50 e8???????? 83c40c 50 8d8424a0000000 50 e8???????? }
- $sequence_4 = { 83e801 7440 83e801 742c 83e801 7418 }
- $sequence_5 = { 894554 53 8d4dc3 e8???????? 8bc8 e8???????? 50 }
- $sequence_6 = { 83f81b 0f8ee3020000 83f81f 0f8eb3020000 83f821 0f8e06020000 83f822 }
- $sequence_7 = { 8b4704 8bcd c6400c01 8b4704 8b4004 c6400c00 8b4704 }
- $sequence_8 = { 51 8d8c2440010000 e8???????? 8d8c24d8000000 e8???????? 8d4c2448 e8???????? }
- $sequence_9 = { c68424c400000000 ff15???????? 59 59 85c0 743d 6a01 }
+ $sequence_0 = { c745f000000000 ff15???????? 8bd0 c7461000000000 8bca c746140f000000 }
+ $sequence_1 = { 8bca c746140f000000 c60600 8d7901 }
+ $sequence_2 = { 99 b91a000000 f7f9 80c261 88143e 47 }
+ $sequence_3 = { 2bc6 48 50 56 }
+ $sequence_4 = { ba???????? 660fd645e0 e8???????? 83c404 }
+ $sequence_5 = { 48 3bc2 0f42d0 0fb6041a 03d3 }
+ $sequence_6 = { ff15???????? 6a00 85c0 744b }
+ $sequence_7 = { 50 e8???????? 8d0c3e 83c40c 3bf1 7410 0fb606 }
+ $sequence_8 = { 6a00 0f434d08 8bf0 6a00 }
+ $sequence_9 = { 0f57c0 c745dc00000000 68???????? ba???????? 660fd645d4 }
+ $sequence_10 = { c745f001000000 e8???????? c745e800000000 c745ec0f000000 c645d800 8d5001 }
+ $sequence_11 = { c745ec0f000000 c645d800 8d5001 8b4610 3bc2 726f }
+ $sequence_12 = { 0154241c 894104 e9???????? 8b44241c }
+ $sequence_13 = { 89542408 f7d0 0385e4fdffff 8995a4fbffff 8944240c }
+ $sequence_14 = { 00c1 83da03 2b54241c 0f8444230000 8b7c241c }
+ $sequence_15 = { 00c1 83db03 2b9d34fdffff 899d44fdffff }
+ $sequence_16 = { 00c2 83de03 2bb500ffffff 89b530ffffff }
+ $sequence_17 = { 00c1 83de03 29de 89b504feffff }
+ $sequence_18 = { 00c1 8d8510feffff 83da03 89442404 }
+ $sequence_19 = { 00c1 8b8300010000 83da03 29fa 7468 }
condition:
- 7 of them and filesize <990208
+ 7 of them and filesize <487424
}
-rule MALPEDIA_Win_Moonwind_Auto : FILE
+rule MALPEDIA_Win_Cloudeye_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "27c4684d-de1d-52d3-b498-3e41ed70b3fe"
+ id = "55cebb53-71a5-52d8-a3dc-f73efa113a86"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moonwind"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moonwind_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cloudeye"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cloudeye_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "4c5abeb5054990236a95ce032241f8cb96582d9f2acb60b8ffe13b68b01f39ef"
+ logic_hash = "ce7b005739a8ed2a89f930168aa824ea8a88d8cc7cac3881e5d28b500fe73c46"
score = 75
quality = 75
tags = "FILE"
@@ -134743,32 +141772,32 @@ rule MALPEDIA_Win_Moonwind_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b11 83c104 c1ea08 881430 8a51fc 40 881430 }
- $sequence_1 = { 8b5dfc 895de4 8b5de4 66c7030200 8b5dfc 83c308 895de4 }
- $sequence_2 = { 53 e8???????? 83c404 8b5d08 8b1b 81c390000000 895dec }
- $sequence_3 = { e8???????? 83c404 83c734 33d2 83c8ff 8917 885704 }
- $sequence_4 = { b801000000 eb05 b800000000 85c0 0f842f000000 8b5d08 8b1b }
- $sequence_5 = { bbdc090000 e8???????? 83c410 8945b8 8b5dbc 85db 7409 }
- $sequence_6 = { ff75fc 6801000000 bb68010000 e8???????? 83c410 8945f0 68???????? }
- $sequence_7 = { 8965f4 8b5d08 ff33 6801000000 ff75f8 ff15???????? }
- $sequence_8 = { 50 e8???????? 8d7c2434 83c9ff 33c0 83c40c f2ae }
- $sequence_9 = { dc25???????? dd5dc4 6801030080 6a00 682c000000 dd45c4 e8???????? }
+ $sequence_0 = { 83c002 668b1c08 668b140e 6639d3 75e4 83e902 83f900 }
+ $sequence_1 = { 7545 66f7c14179 685595db6d e8???????? }
+ $sequence_2 = { e8???????? 5f 59 83c628 41 3b8f04080000 75a8 }
+ $sequence_3 = { 7408 0185f4000000 eba4 85d8 }
+ $sequence_4 = { 89f8 0500080000 50 6aff }
+ $sequence_5 = { 6685d2 e8???????? 84ef 80fd37 57 e8???????? 58 }
+ $sequence_6 = { c3 38ed 817e24200000e0 7473 }
+ $sequence_7 = { 668b00 6631c8 39c8 6631c3 6681fb4d5a 7407 6639c1 }
+ $sequence_8 = { 0fbae11f 0f82d63c0000 61 0faee8 0f31 0faee8 c1e220 }
+ $sequence_9 = { 75e4 83e902 83f900 7deb ff742404 }
condition:
- 7 of them and filesize <1417216
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Win_Grabbot_Auto : FILE
+rule MALPEDIA_Win_Spaceship_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "02308264-bf9f-5ce5-8d58-a146011d85f3"
+ id = "b89dfb6c-e6cf-5987-bb83-c34e2134133d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grabbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grabbot_auto.yar#L1-L161"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spaceship"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spaceship_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "fb36fa0cb6c01a8c284e94b423e764f2d45ce7cf14719bff3ffb20003d9572f1"
+ logic_hash = "411bed797a77bb254c4227872033ffc1c4978f634b16d7697bf043a78e35e5f7"
score = 75
quality = 75
tags = "FILE"
@@ -134782,38 +141811,32 @@ rule MALPEDIA_Win_Grabbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb702 83f85a 770b 83f841 7206 }
- $sequence_1 = { 83f85a 770d 83f841 7208 83c020 }
- $sequence_2 = { 83f841 7206 83c020 0fb7c0 83c202 }
- $sequence_3 = { ffd0 c3 b88dbdc13f 50 e8???????? }
- $sequence_4 = { ffe0 c3 c3 c3 68b9be7238 e8???????? 50 }
- $sequence_5 = { 03c7 813850450000 0f853c010000 0fb74804 ba4c010000 }
- $sequence_6 = { 03c3 813850450000 8945f8 7408 32c0 }
- $sequence_7 = { 7523 8b8c18a0000000 85c9 0f8489000000 837c187405 }
- $sequence_8 = { 56 ffd0 33c9 66894c37fe }
- $sequence_9 = { 7428 8b0d???????? 8908 8b0d???????? 894804 }
- $sequence_10 = { 89480c e9???????? 33c0 e9???????? }
- $sequence_11 = { 894808 8b0d???????? 89480c e9???????? }
- $sequence_12 = { 8bf0 85f6 741d 8d4601 50 e8???????? }
- $sequence_13 = { 85c0 56 0f9fc3 e8???????? 83c414 }
- $sequence_14 = { ff15???????? a3???????? 85c0 7505 83c8ff }
- $sequence_15 = { 741b 8d440002 50 e8???????? }
+ $sequence_0 = { 6689842464030000 6689842466030000 c784246803000028694100 66899c246c030000 668984246e030000 c784247003000018694100 }
+ $sequence_1 = { 66c78424a40400001200 66898424a6040000 c78424a804000070674100 66c78424ac0400001300 66898424ae040000 c78424b004000064674100 }
+ $sequence_2 = { 0f8415010000 bb01000000 3bfb 0f8cff000000 eb04 }
+ $sequence_3 = { 84c0 7547 eb31 8d7502 40 8a10 8aca }
+ $sequence_4 = { 52 e8???????? 83c418 5f 5e 5b 83c410 }
+ $sequence_5 = { 85c0 7454 8a442404 84c0 }
+ $sequence_6 = { 53 ff542428 8d8c2454020000 51 e8???????? }
+ $sequence_7 = { 8b442424 8b0d???????? 56 50 }
+ $sequence_8 = { 8d3c8d00ec4100 c1e603 8b0f 833c31ff }
+ $sequence_9 = { 723c 8d8c2458030000 6a00 8d94245c050000 51 52 ff15???????? }
condition:
- 7 of them and filesize <1335296
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Ceeloader_Auto : FILE
+rule MALPEDIA_Win_Wslink_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "385139d5-6e1c-5e2f-90c3-04a312f22353"
+ id = "20de7893-0402-5999-83e1-25d8d59bd834"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ceeloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ceeloader_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wslink"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wslink_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "5733aa6d7aff1d1a6c42de98107a30359cd04782474df0d5ddf09cf2979a826e"
+ logic_hash = "8ce7768eb8de70c3eb5454e941b335f1710146a120509f2149ca4912b8c000bf"
score = 75
quality = 75
tags = "FILE"
@@ -134827,32 +141850,32 @@ rule MALPEDIA_Win_Ceeloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3bce 33f6 23c7 0bda 8bde c3 0bd3 }
- $sequence_1 = { 448b15???????? 4489c6 4431de 4589c3 4101f3 44891d???????? 4589c3 }
- $sequence_2 = { 664589c2 664489942490030000 440fbe05???????? 4183f074 664589c2 664489942492030000 440fbe05???????? }
- $sequence_3 = { 0bda 8bde 0bd3 3bce 23f3 7a04 0bda }
- $sequence_4 = { 8b842420010000 3b84241c010000 0f8433000000 8b842420010000 898424dc000000 e8???????? 8b8c241c010000 }
- $sequence_5 = { 3bdd 23fd 0bda 8bde 0bd3 3bce 5a }
- $sequence_6 = { 741d 4885ff c6435401 488d0d53880800 480f45cf 48894b48 e8???????? }
- $sequence_7 = { 88542433 0fbe05???????? 83f064 88c2 88542434 0fbe05???????? 83f076 }
- $sequence_8 = { 4489a42464020000 4403bc2464020000 4489bc2460020000 448bbc2460020000 4589dc 4181e45d386101 4489a4245c020000 }
- $sequence_9 = { 41c1e204 4489942448050000 44038c2448050000 44898c2444050000 448b8c2444050000 4189d2 4181e235913d02 }
+ $sequence_0 = { e8???????? 488bf0 4885c0 0f85ab000000 c7442420ec000000 4c8d0dcfbc0600 ba94000000 }
+ $sequence_1 = { e9???????? 488d15beaf0700 41b804000000 488bce e8???????? 85c0 750c }
+ $sequence_2 = { eb2a 8b4718 85c0 750b 488b4f08 e8???????? ffc8 }
+ $sequence_3 = { 48894710 4885c0 7514 c744242085010000 4c8d0d88440a00 e9???????? 8b542460 }
+ $sequence_4 = { e8???????? 85c0 0f848a000000 ffcf ffc3 85ff 7fd3 }
+ $sequence_5 = { 830f04 be01000000 488bcd e8???????? 488bcd e8???????? 488b5c2450 }
+ $sequence_6 = { e8???????? 85c0 0f84c9fdffff 8b8c2400010000 418bc4 85c9 0f94c0 }
+ $sequence_7 = { ba70000000 4c8d0d82120a00 c744242067000000 8d4a94 448d42fa e8???????? 83c8ff }
+ $sequence_8 = { e8???????? 85c0 0f8424feffff 488b03 4d8bcc 4d8bc7 498bd7 }
+ $sequence_9 = { f70300010000 7407 e8???????? eb05 e8???????? 8b5718 33c9 }
condition:
- 7 of them and filesize <2321408
+ 7 of them and filesize <2007040
}
-rule MALPEDIA_Win_Globeimposter_Auto : FILE
+rule MALPEDIA_Win_Nefilim_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4d7b48e1-c009-5b34-a438-f100a6a58894"
+ id = "7c9bb815-6478-5f57-9a80-3013a8b5a537"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.globeimposter"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.globeimposter_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nefilim"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nefilim_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "608bf851e6cd1f78be1de6e26308954d73fd642b69ffa80c802e22a056e6ef77"
+ logic_hash = "0637c290ac474507dfbf7c46615faaf644551a1824ee3d111eec4b7aaf27ae12"
score = 75
quality = 75
tags = "FILE"
@@ -134866,32 +141889,32 @@ rule MALPEDIA_Win_Globeimposter_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c1e810 8bca c1e908 23c7 23cf }
- $sequence_1 = { 6a0c 5f eb0d 3d96000000 1bff }
- $sequence_2 = { 8b4508 8b4e08 89442418 85ff 7452 }
- $sequence_3 = { 0fd4cd 0f6e6f10 0fd4d5 0f7e4f08 0f73d120 0fd4cf 0f6e6f14 }
- $sequence_4 = { 6a02 57 57 6800000040 8d85fcefffff }
- $sequence_5 = { 0fd4cb 0f6e16 0ff4d0 0f6e6604 }
- $sequence_6 = { 83c0fc 3918 7506 83e804 4f 75f6 }
- $sequence_7 = { 83c104 f7db 75d7 5f 5b }
- $sequence_8 = { 8bf0 8b06 8d7604 0119 3919 }
- $sequence_9 = { 8bc7 f7f6 33d2 0fafc6 2bf8 }
+ $sequence_0 = { be00010000 56 e8???????? 56 8944244c }
+ $sequence_1 = { 8945e4 3d00010000 7d10 8a8c181d010000 8888c0e64000 40 }
+ $sequence_2 = { c1f802 6bc003 50 6a00 ff15???????? 50 }
+ $sequence_3 = { 85c0 7506 ff15???????? 8d45d4 50 57 ffd3 }
+ $sequence_4 = { 397c2428 7304 8d442414 68???????? 50 ffd6 85c0 }
+ $sequence_5 = { 50 ffd6 85c0 0f84cf020000 f68424a000000010 8d8424cc000000 }
+ $sequence_6 = { 7421 68???????? 8d442444 e8???????? }
+ $sequence_7 = { 8b3d???????? 8b1d???????? 33c9 8945e4 894de8 8b45e4 d3e8 }
+ $sequence_8 = { 8944244c e8???????? ff74244c 8b542440 89442454 e8???????? }
+ $sequence_9 = { c745eceb7f4000 894df8 8945fc 64a100000000 8945e8 }
condition:
- 7 of them and filesize <327680
+ 7 of them and filesize <142336
}
-rule MALPEDIA_Win_Unidentified_037_Auto : FILE
+rule MALPEDIA_Win_Isaacwiper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9e4cd69e-744d-5d0c-b193-3d15e535bfdb"
+ id = "1329030c-897c-5c01-8c07-662be913ab23"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_037"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_037_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.isaacwiper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.isaacwiper_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "ab9d444ded76b509036904b157e446e552ae52ed50151a488fb9c47db68bb4eb"
+ logic_hash = "ed4c1277cdfb0687c916d7f4c8800e6899b857de5108f3daf478ca99ea587637"
score = 75
quality = 75
tags = "FILE"
@@ -134905,32 +141928,32 @@ rule MALPEDIA_Win_Unidentified_037_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 a3???????? 740c 8b4c2408 8b542404 51 52 }
- $sequence_1 = { 33c0 33d2 33ff 8a0c1f 80f920 7405 80f930 }
- $sequence_2 = { 7506 8b15???????? 8d8424b8040000 52 50 ff15???????? }
- $sequence_3 = { 8a56ff 83e23f 41 4d 8a82d00c0110 8841ff 759c }
- $sequence_4 = { 8b4d20 8b5500 8b4504 8bb424f0040000 51 52 50 }
- $sequence_5 = { ff15???????? 84c0 742d 8b4608 8b5604 8d8dccfcffff }
- $sequence_6 = { 8841ff 759c 5d eb04 8b742410 85ff 7667 }
- $sequence_7 = { 743e 80f920 7439 80f930 7c0d 80f937 7f08 }
- $sequence_8 = { 8b5c2408 8b4314 83f8ff 0f84b1000000 c1e005 8bd0 a1???????? }
- $sequence_9 = { 5e 8b8c241c100000 64890d00000000 81c428100000 c3 83c1fe }
+ $sequence_0 = { 771b 52 51 e8???????? 83c408 5f c706???????? }
+ $sequence_1 = { b804000000 33d2 395138 0f45c2 0b410c 0bc3 50 }
+ $sequence_2 = { 8d0471 3bc8 7319 8d46ff }
+ $sequence_3 = { 5b 8be5 5d c3 6a34 e8???????? 8bf0 }
+ $sequence_4 = { 7576 eb56 8b0485d89e0210 6800080000 6a00 50 8945fc }
+ $sequence_5 = { 744a 83c118 57 8b7d14 894d08 0f1f4000 }
+ $sequence_6 = { 81ecc8090000 56 57 8bf1 c745f800000000 ff15???????? 898538f6ffff }
+ $sequence_7 = { 6685f6 743e 6a00 8bd6 8bcf e8???????? 8ad0 }
+ $sequence_8 = { 85db 0f8454010000 8bc6 83e001 03c8 d1ee }
+ $sequence_9 = { 8bf8 83e03f c1ff06 6bd038 8b34bde8670310 8a441628 }
condition:
- 7 of them and filesize <167936
+ 7 of them and filesize <467968
}
-rule MALPEDIA_Win_Urlzone_Auto : FILE
+rule MALPEDIA_Win_Alma_Locker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "73713fa1-9237-58d2-8cc2-5acf9c265fc9"
+ id = "a8975e90-f59f-53dc-8c8c-bbe753edcfd3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.urlzone"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.urlzone_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alma_locker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alma_locker_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "4cce61429410ef9f511dc19a60899f126670164d7c8bb8ef8edba2014cda32d1"
+ logic_hash = "df780972bf15a2baf7532cad09aa2dd13a5bee9ccc29d4fb62357c0162af8a26"
score = 75
quality = 75
tags = "FILE"
@@ -134944,32 +141967,32 @@ rule MALPEDIA_Win_Urlzone_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7c32 80f839 7f05 80e830 eb22 }
- $sequence_1 = { 80fc39 7f05 80ec30 eb22 }
- $sequence_2 = { 7f05 80ec30 eb22 80fc41 7c54 }
- $sequence_3 = { 80c00a eb10 80f861 7c11 80f866 }
- $sequence_4 = { 5f 5e c3 57 51 89c7 }
- $sequence_5 = { 80c40a eb10 80fc61 7c42 80f866 7f3d }
- $sequence_6 = { 7f0c 80e861 80c00a c0e004 08e0 }
- $sequence_7 = { 80f841 7c23 80f846 7f08 }
- $sequence_8 = { 80f839 7f05 80e830 eb22 80f841 7c23 }
- $sequence_9 = { 80ec30 eb22 80fc41 7c54 }
+ $sequence_0 = { 8d8d6cfeffff e8???????? 83c404 8d4d8c c645fc07 51 8bd0 }
+ $sequence_1 = { 720e ffb5ccfeffff e8???????? 83c404 837da008 720b ff758c }
+ $sequence_2 = { 0304b5e86a0210 59 eb02 8bc3 8a4024 247f 3c01 }
+ $sequence_3 = { 50 ff15???????? 8bf0 89b52cfaffff }
+ $sequence_4 = { 83e11f c1f805 c1e106 8b0485e86a0210 f644080401 7405 }
+ $sequence_5 = { 8d8dd0fbffff e8???????? c645fc03 8d85d0fbffff 83bde4fbffff10 0f4385d0fbffff }
+ $sequence_6 = { b9???????? e8???????? 33c0 c645fc1f 33c9 66a3???????? 66390d???????? }
+ $sequence_7 = { 81fbfeffff7f 0f87ab000000 8b4614 3bc3 7325 ff7610 53 }
+ $sequence_8 = { b9???????? c705????????07000000 0f44f8 c705????????00000000 57 68???????? }
+ $sequence_9 = { 83c404 c78584fbffff0f000000 c78580fbffff00000000 c68570fbffff00 83bd9cfbffff10 720e }
condition:
- 7 of them and filesize <704512
+ 7 of them and filesize <335872
}
-rule MALPEDIA_Win_Mim221_Auto : FILE
+rule MALPEDIA_Win_Webc2_Table_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e2e82536-e29b-53d1-8c95-30ff68363ca9"
+ id = "398ecdfa-bd77-5001-b308-7e740d6a25e6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mim221"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mim221_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_table"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_table_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "bd7d2b077259a6edc03c8b758f8bad3f5a42643cb60c61d80165934010c8f5e6"
+ logic_hash = "659cc34946aa5d8ea6957b273afd39f56e48147569d9730da4a86aafe181a1ab"
score = 75
quality = 75
tags = "FILE"
@@ -134983,32 +142006,32 @@ rule MALPEDIA_Win_Mim221_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 90 4883bc244001000008 720d 488b8c2428010000 e8???????? 4881c420020000 415e }
- $sequence_1 = { c68424b400000061 4488a424b5000000 c68424b600000064 c68424b70000006c 4488ac24b8000000 c68424b900000046 c68424ba00000072 }
- $sequence_2 = { 488b8c2400010000 e8???????? e9???????? 4889442420 4d8bcc 4c8b8424f8010000 488bd6 }
- $sequence_3 = { 57 488bc4 4883ec58 48c7442420feffffff 498bd8 488bf9 }
- $sequence_4 = { 668944243a 668944243c 668944243e 6689442440 488d542420 488bcf 66c74424420000 }
- $sequence_5 = { 3d5a290000 7307 b801000000 eb0a 3d39380000 1bc0 83c003 }
- $sequence_6 = { 66c7803effffff4c00 66b85300 6689842418010000 66c784241a0100004100 6644899c241c010000 66c784241e0100004900 66c78424200100007300 }
- $sequence_7 = { 4157 4881ec88000000 33ff 498be8 488bf1 4c8bfa }
- $sequence_8 = { 3d401f0000 7309 8d7b20 448d6b18 eb1b 3db8240000 730b }
- $sequence_9 = { 488d8c24ca000000 e8???????? c684249003000044 c68424910300008b c684249203000001 c684249303000044 c684249403000039 }
+ $sequence_0 = { 8d85e4feffff 50 ff75fc ff15???????? 85c0 0f8461010000 }
+ $sequence_1 = { 83c410 881d???????? 8345fc04 ff4dec 0f8567feffff }
+ $sequence_2 = { 8dbda1fcffff 889da0fcffff f3ab 66ab aa 8d859cfbffff 6804010000 }
+ $sequence_3 = { 53 894dec ffd6 59 }
+ $sequence_4 = { 8b45f4 bf???????? 57 50 885c30f4 8b35???????? }
+ $sequence_5 = { 50 53 ff15???????? 85c0 750a ff15???????? 32c0 }
+ $sequence_6 = { ff75fc 8d85bcfdffff 50 e8???????? 59 }
+ $sequence_7 = { 50 8945e8 e8???????? 83c40c 895df8 8d45c4 }
+ $sequence_8 = { e8???????? 0fb745e0 50 0fb745de 50 }
+ $sequence_9 = { ff7508 6a01 50 ff15???????? 56 }
condition:
- 7 of them and filesize <471040
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Cohhoc_Auto : FILE
+rule MALPEDIA_Win_Devopt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b68a758f-10e4-5b26-9336-04dc8575909c"
+ id = "b2799a63-9237-56b1-b622-1d4cf3bf7ea8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cohhoc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cohhoc_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.devopt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.devopt_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "ecae8715f2ad96196b29dfd6ae017f72fc211d8d4ab8ab2002ae190526566a13"
+ logic_hash = "f040e8bf75c02b10fb9ecd2b3e85bb747221bae38ed54254a620b66ea3085268"
score = 75
quality = 75
tags = "FILE"
@@ -135022,71 +142045,71 @@ rule MALPEDIA_Win_Cohhoc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 1bc0 83d8ff 85c0 0f84fb000000 bf???????? 8db424b4010000 8a0e }
- $sequence_1 = { 5b 81c49c020000 c3 8b542410 }
- $sequence_2 = { e8???????? 50 6801010000 8bcd e8???????? 8bcd }
- $sequence_3 = { 33c0 5b 83c444 c3 8b542434 8b442458 6a00 }
- $sequence_4 = { 817c240c03010000 0f8494010000 8b35???????? 8d442410 53 50 68???????? }
- $sequence_5 = { 66c74424040010 8974242c 89742430 8b442448 8b4c2444 50 }
- $sequence_6 = { bf01000000 6a00 68???????? ffd6 85ff }
- $sequence_7 = { 88442424 894c2430 8b4c2424 57 51 8b4c2428 e8???????? }
- $sequence_8 = { 6a07 51 6a00 aa }
- $sequence_9 = { 8bc8 8d8424b4010000 83e103 f3a4 be???????? 8a10 8aca }
+ $sequence_0 = { eb42 8b45fc f7402810000000 7402 eb34 8b45fc 80b8a900000000 }
+ $sequence_1 = { eb11 3b5df0 7e02 eba3 8d7600 c745f0ffffffff 8b45f0 }
+ $sequence_2 = { eb0b 8b45fc 8b4034 8945d4 eb25 8b45d0 83e00f }
+ $sequence_3 = { ff9240040000 84c0 7502 eb0b 8b55f8 8b45fc e8???????? }
+ $sequence_4 = { e8???????? 8b45f4 ba???????? 8955e8 8945ec 8d55e8 31c0 }
+ $sequence_5 = { 8b4240 8b55f4 8b4a40 8b11 ff5268 8945f0 89d7 }
+ $sequence_6 = { ff93a8020000 8b45d4 8d40fc 50 8b45d0 8d48fc 8b45f8 }
+ $sequence_7 = { 8d6424e0 53 8945f4 8955fc 894df8 837dfc00 7e02 }
+ $sequence_8 = { ff75f0 ff75fc e8???????? 31d2 58 83c40c 648902 }
+ $sequence_9 = { eb1e 8b45f8 a9ffffffff 7402 eb12 8b45f4 e8???????? }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <4645888
}
-rule MALPEDIA_Win_Sobig_Auto : FILE
+rule MALPEDIA_Win_Unidentified_082_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7eece2fa-1a04-5dd6-834d-8f7a893bf841"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sobig"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sobig_auto.yar#L1-L128"
+ id = "7772581c-e8cf-5615-a758-46ef9c1fc0b0"
+ date = "2021-10-07"
+ modified = "2021-10-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_082"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_082_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "0a10ba676706f70e2749591376b958283b48eb8278fdd736f5378429d6ec57e3"
+ logic_hash = "fdfe1ddce9f77ac8b465b0ddebe868c5e77078cf2b2457573a5b3810682f45ee"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
+ malpedia_rule_date = "20211007"
+ malpedia_hash = "e5b790e0f888f252d49063a1251ca60ec2832535"
+ malpedia_version = "20211008"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? ff35???????? 8d45dc 8bcf 6a00 50 }
- $sequence_1 = { 53 50 ff75ec ff75d8 ff75dc ff15???????? 85c0 }
- $sequence_2 = { 8a450f 33db 8d7e34 53 8bcf }
- $sequence_3 = { 5f 5e c20400 53 56 ff742410 8bf1 }
- $sequence_4 = { e8???????? dd4598 8b4de8 dd5db0 dd45a0 dd5db8 dd45a8 }
- $sequence_5 = { 8d45b4 50 56 56 68???????? 56 56 }
- $sequence_6 = { 8d4db0 e8???????? 8a45b0 83ec10 8bfc 8965e0 53 }
- $sequence_7 = { 8b4d08 68???????? e8???????? 6a01 58 8945ec e9???????? }
- $sequence_8 = { ff35???????? 8d45dc 8bcf 53 }
- $sequence_9 = { ff7508 ff15???????? 85c0 7c43 ff7510 ff15???????? }
+ $sequence_0 = { 4c8d0dbc190200 0f1f4000 0f1f840000000000 418d4801 }
+ $sequence_1 = { ff5018 4c634510 488d0df40a0200 488bd8 33c0 }
+ $sequence_2 = { 4c634510 488d0d93fa0100 488bd8 33c0 488bd3 488905???????? 488905???????? }
+ $sequence_3 = { ff15???????? 488b0cdf ff15???????? 48c704dfffffffff }
+ $sequence_4 = { 4885c0 0f84ac010000 48833d????????00 0f849e010000 48833d????????00 0f8490010000 48833d????????00 }
+ $sequence_5 = { 488b0d???????? 8b5108 488b4910 4533c9 458d4130 4c89742420 }
+ $sequence_6 = { 33c0 e9???????? 8a07 4c8b7c2448 4c8d25a64c0100 4b8b0cfc ffc3 }
+ $sequence_7 = { 0f1f4000 0f1f840000000000 418d4801 0fb6c2 41ffc0 f7da }
+ $sequence_8 = { 488b4f18 4c8d4d10 488b01 488d1587000200 41b810000000 ff5018 4c634510 }
+ $sequence_9 = { 48894598 eb03 4533f6 488b05???????? 80782e00 740a 80782000 }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <414720
}
-rule MALPEDIA_Win_Krdownloader_Auto : FILE
+rule MALPEDIA_Win_Gearshift_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5a82ae0a-fad8-52ec-9981-5ad40d1aeb9f"
+ id = "02540c00-8de2-5ac5-936a-14a6336e7666"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.krdownloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.krdownloader_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gearshift"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gearshift_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "4501a2b9e4a10b142f4eeab904974c078e1ef98420195596ba39d05922e3a30d"
+ logic_hash = "1c8a80ba14390df1b7bcd5e4b955652a287b76aebf22d78fc43b89631a984860"
score = 75
quality = 75
tags = "FILE"
@@ -135100,32 +142123,32 @@ rule MALPEDIA_Win_Krdownloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c645e161 c645e22e c645e370 c645e468 c645e570 c645e63f c645e76d }
- $sequence_1 = { 8b4df4 8b09 e8???????? 8945f0 }
- $sequence_2 = { 7528 8b45fc 0345f4 0fb6482c 51 68???????? }
- $sequence_3 = { e8???????? 8945d8 8b4dfc 51 8b55f8 }
- $sequence_4 = { 7418 8b4dec 0fbe11 0fbe45f3 3bd0 }
- $sequence_5 = { 8955f0 8b45f0 8945f8 c745d800000080 817d1000000080 7310 }
- $sequence_6 = { c745f001000000 eb28 837d0c00 7422 6a04 68???????? 8b4d0c }
- $sequence_7 = { 89815c0d0300 8b55fc 8b82500d0300 50 ff15???????? }
- $sequence_8 = { 735e 8b4dfc 8b5134 83ea01 3955f4 }
- $sequence_9 = { 83c001 8945fc 817dfc6f020000 7d63 8b4dfc 8b55f8 }
+ $sequence_0 = { 4881c4c0000000 5f c3 85c0 0f85a9000000 }
+ $sequence_1 = { 4d8bde 4d2b5d30 0f84a1000000 488b4500 488b5d08 }
+ $sequence_2 = { 4883ec28 48833d????????00 740a b801000000 4883c428 c3 488d0dc9a80000 }
+ $sequence_3 = { 4823f1 66413b7806 0f83ce000000 48895c2448 4c89642450 4c8d25566a0300 4a8d5c003c }
+ $sequence_4 = { 83c8ff e9???????? 4c8bfb 4c8be3 488d05363c0300 49c1fc05 }
+ $sequence_5 = { 4885c0 0f8418010000 4c8d442470 41b910010000 488bd0 488bcb 48897c2420 }
+ $sequence_6 = { 488bd8 ff9688000000 4c8bc3 33d2 488bc8 8947f8 ff96a8000000 }
+ $sequence_7 = { 7522 48ffc1 498d0408 493bc3 7cec 4963c2 4803c6 }
+ $sequence_8 = { 4533c0 33d2 498bcc 44896c2428 48897c2420 ff15???????? ba01000000 }
+ $sequence_9 = { 0fb7d1 eb09 488b4508 488d540102 }
condition:
- 7 of them and filesize <352256
+ 7 of them and filesize <540672
}
-rule MALPEDIA_Win_Redalpha_Auto : FILE
+rule MALPEDIA_Win_Sakula_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "18d7b39f-1fe8-5b57-91e8-72bb40b0300f"
+ id = "877a5bc8-1502-5d2d-ac89-d1f9991b4673"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redalpha"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redalpha_auto.yar#L1-L286"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sakula_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sakula_rat_auto.yar#L1-L234"
license_url = "N/A"
- logic_hash = "062f534aa7bc989cb92a0f507bdc74bdcfcc089d3142c94dc9dd9b9510e4dbdc"
+ logic_hash = "5566117feff4531b6238852b1dd267d13dd172e7c51c8c4e9976cadb5e493558"
score = 75
quality = 73
tags = "FILE"
@@ -135139,53 +142162,45 @@ rule MALPEDIA_Win_Redalpha_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83c40c c0e304 0fb6c3 50 }
- $sequence_1 = { 8b3e 8bce e8???????? 8b4df8 }
- $sequence_2 = { 4585c0 7417 0f1f4000 410fb602 4d8d5201 03c8 }
- $sequence_3 = { 443bd3 7d0b 6645019489a40a0000 eb33 }
- $sequence_4 = { 8b4004 c74408e840d24300 8b41e8 8b5004 }
- $sequence_5 = { 8b3d???????? eb96 8b8b48010000 e8???????? 8bce e8???????? 8b7e04 }
- $sequence_6 = { 8b3f ff750c 53 6aff }
- $sequence_7 = { 8b3e 897df4 0fb607 0fb64f01 }
- $sequence_8 = { 42803c0000 75f6 49ffc0 488d4f0d 488d542450 }
- $sequence_9 = { e8???????? 488d043b 4d63c4 488d8dea020000 }
- $sequence_10 = { 498d4505 894208 d3e5 ffcd 23dd }
- $sequence_11 = { 488b4b10 488b5010 410fb60411 41880408 ff4328 ff4338 }
- $sequence_12 = { 448d4858 e8???????? 85c0 7556 }
- $sequence_13 = { 8b3e 8bcb d3e8 83e001 895d08 }
- $sequence_14 = { 488d542458 4803d0 488bcb e8???????? }
- $sequence_15 = { 8b3d???????? ffd7 ffb548f7ffff ffd7 }
- $sequence_16 = { 50 e8???????? 83c418 c785f0fdffff00000000 8d85f0fdffff 50 6a0b }
- $sequence_17 = { 0f8413050000 8b3c8d8c864000 85ff 755d 33c0 89859cf6ffff 89855cfcffff }
- $sequence_18 = { c3 55 8bec 81ec04010000 56 68cf010040 6a00 }
- $sequence_19 = { 8d7608 660fd60f 8d7f08 8b048d74e84000 }
- $sequence_20 = { 50 8d45f4 64a300000000 683f000f00 }
- $sequence_21 = { 897c2428 e8???????? 83c410 8d442424 50 }
- $sequence_22 = { 50 e8???????? 6aff c645fc01 ff75dc }
- $sequence_23 = { 8b5df4 8bf7 8b4b04 85c9 0f85f2000000 33c0 }
- $sequence_24 = { 7605 e8???????? 8b4f14 8bf0 }
- $sequence_25 = { e8???????? 83f801 7512 68d0070000 ff15???????? e8???????? eb39 }
- $sequence_26 = { 7512 8b04bd30744100 807c302900 7504 }
- $sequence_27 = { 8b8fbc000000 52 ff7730 8b01 ff5004 ff75ec }
- $sequence_28 = { c1f806 83e13f 6bc930 53 56 8b048530744100 33db }
- $sequence_29 = { 89b8bc000000 ff15???????? 894708 ff7518 8b4514 }
- $sequence_30 = { 6bc830 894de0 8b049d581f4000 0fb6440828 83e001 7469 }
+ $sequence_0 = { 6a00 6800010000 6a00 6a00 68???????? }
+ $sequence_1 = { 8bf0 56 6a01 57 53 }
+ $sequence_2 = { 57 56 e8???????? 8d7e10 8ad8 57 8bc7 }
+ $sequence_3 = { 33c9 85f6 7e15 8a0411 84c0 7409 }
+ $sequence_4 = { 53 e8???????? 83c40c 6a00 6a00 57 53 }
+ $sequence_5 = { 8bc7 e8???????? 83c408 833e01 }
+ $sequence_6 = { 50 e8???????? 83c404 32c0 5d }
+ $sequence_7 = { 53 e8???????? 56 e8???????? 83c41c 5f 5b }
+ $sequence_8 = { 66895db0 48895c2450 4889442458 4889442460 }
+ $sequence_9 = { ff15???????? 33d2 488bcb ff15???????? e8???????? 33c9 ff15???????? }
+ $sequence_10 = { 8b45d8 8b5de0 01d8 8945e0 6a01 e8???????? }
+ $sequence_11 = { 4c8bc6 33d2 33c9 448bc8 897c2428 48895c2420 ff15???????? }
+ $sequence_12 = { 0f8516010000 488d15e61c0000 41b804010000 48890d???????? ff15???????? ff15???????? 83f801 }
+ $sequence_13 = { 7459 68???????? 68???????? e8???????? 83f800 }
+ $sequence_14 = { 8945e4 83f800 0f843c010000 6a00 6a00 ff75ec }
+ $sequence_15 = { e8???????? 50 ff75f4 e8???????? 58 eb02 31c0 }
+ $sequence_16 = { 8a03 3c00 7414 b21a }
+ $sequence_17 = { ff15???????? 33d2 488d4deb 448d426c }
+ $sequence_18 = { ff15???????? 488bce 488bd8 ff15???????? 488364243800 488364243000 }
+ $sequence_19 = { e9???????? 31c0 7402 31c0 50 ff75fc e8???????? }
+ $sequence_20 = { ff9080000000 3bc6 741b 488b4dc7 488b01 }
+ $sequence_21 = { 6804010000 ff75fc 6a00 e8???????? ff75fc }
+ $sequence_22 = { 33d2 ff15???????? 3bc6 745f 4c8d4dcf }
condition:
- 7 of them and filesize <606208
+ 7 of them and filesize <229376
}
-rule MALPEDIA_Win_Industrial_Spy_Auto : FILE
+rule MALPEDIA_Win_Adhubllka_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ce5f3e00-b3d5-5d7c-9715-f009f6dd4df1"
+ id = "e0dcc0bf-7466-5a17-86c8-1be553373dbc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.industrial_spy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.industrial_spy_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.adhubllka"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.adhubllka_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "0d309a929b9f93d00c001ba14e0da1de3852467890493f029087eefa2710c99c"
+ logic_hash = "f57dac34b065a20905904e9bce7c25f2f5dcbcedcfe53619de18c646a0c360a6"
score = 75
quality = 75
tags = "FILE"
@@ -135199,32 +142214,32 @@ rule MALPEDIA_Win_Industrial_Spy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f7d1 8d9778a46ad7 23cb 448d8356b7c7e8 418bc3 4123c2 0bc8 }
- $sequence_1 = { 8bc3 448bcf 410f104f10 4c8d442430 }
- $sequence_2 = { 48895c2450 48895c2448 4883e804 4889442440 4533c9 4c8d442444 8b542440 }
- $sequence_3 = { 8b5540 448b4544 4585ed 740f 899380000000 44898384000000 }
- $sequence_4 = { 4c89742420 498bd4 498bcd c644043000 8d4301 0f11440430 410f104720 }
- $sequence_5 = { 4881ec100e0000 4533e4 803d????????1f 7472 448925???????? }
- $sequence_6 = { 837c8dc000 7508 ffca 4883e901 }
- $sequence_7 = { 0f118424e8010000 f20f108424e0010000 f20f118424f8010000 0f108c24b8010000 0f118c2400020000 f20f108424c8010000 f20f11842410020000 }
- $sequence_8 = { 4c8d4d50 895c2420 4c8d85a0030000 488d542430 488d4c2430 e8???????? }
- $sequence_9 = { 0f8df5000000 e8???????? 488b8890000000 48399938010000 7516 488d05cb030100 }
+ $sequence_0 = { e8???????? 8d8d60ffffff e8???????? 0f108560ffffff be18000000 0f1185c0feffff }
+ $sequence_1 = { 0f104590 0f118540ffffff 0f1045a0 0f118550ffffff e8???????? 83c404 8d8d60ffffff }
+ $sequence_2 = { 894d9c 8b4dbc 89458c 8b45c4 897d98 8b7dc0 }
+ $sequence_3 = { 7410 f745d800000002 7407 b801000000 eb02 33c0 }
+ $sequence_4 = { 03c2 898534ffffff 33c7 c1c008 898520ffffff 03c1 8b4ddc }
+ $sequence_5 = { 0fb605???????? c1e108 0bc8 0fb605???????? c1e108 0bc8 }
+ $sequence_6 = { e8???????? 83c404 0f57c0 660f138424501a0000 6a02 }
+ $sequence_7 = { 8d8d60ffffff e8???????? 8d8d60ffffff e8???????? 0f108560ffffff be04000000 0f118510ffffff }
+ $sequence_8 = { 0f1f440000 8b5cbc48 53 ff15???????? 83f801 }
+ $sequence_9 = { ffb590fdffff ff15???????? 85c0 0f8481fdffff 56 e8???????? }
condition:
- 7 of them and filesize <339968
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Ragnarok_Auto : FILE
+rule MALPEDIA_Win_Common_Magic_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a9bce1d7-5883-5de4-9b9b-a02072e8d068"
+ id = "51a78d88-2ba4-5106-aa0c-c758f14020ef"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ragnarok"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ragnarok_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.common_magic"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.common_magic_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "4922b92876243cdefed80b6c256ba49e22b0c6eaa1ad052381af99f572200bea"
+ logic_hash = "b14e276c951448d5c194fa4cd51d59dbec4eb8aa1757a9205bc8d8e9186ff3cd"
score = 75
quality = 75
tags = "FILE"
@@ -135238,32 +142253,32 @@ rule MALPEDIA_Win_Ragnarok_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c1f906 57 6bf838 894df4 8b048d28754300 8b540718 8955ec }
- $sequence_1 = { 884219 0fb6461a 88421a 0fb6461b 88421b 0fb6461c 88421c }
- $sequence_2 = { c1e908 0fb6c9 c1e308 c1ea10 0fb689105c4300 33d9 8b4dfc }
- $sequence_3 = { 8bc8 2345a4 f7d1 234d9c 0bc8 c145980a }
- $sequence_4 = { 0fb689104b4300 33d9 0fb6487e c1e308 0fb689104b4300 33d9 0fb6487d }
- $sequence_5 = { 8b7d08 0fb6ca 333c8d105d4300 8bcf 897d08 334814 894d08 }
- $sequence_6 = { 8b75dc 33f9 037dfc 81c64efd53a9 037d98 c1c209 }
- $sequence_7 = { c1c205 8b7dac 0bc8 034dd8 81c7dcbc1b8f 0355bc 03f9 }
- $sequence_8 = { 8b048528754300 c644032a0a 8b5d08 747f 8b45f8 8b5df0 8b048528754300 }
- $sequence_9 = { 8bf8 89bdb8feffff ff36 68???????? ff35???????? e8???????? 8b4810 }
+ $sequence_0 = { 8d049d78824100 8b30 8945fc 90 }
+ $sequence_1 = { 03c0 eb3c 8bd1 b8feffff7f d1ea 2bc2 }
+ $sequence_2 = { c78578ffffff00000000 c7857cffffff00000000 8d9574ffffff c645fc09 8d8d84feffff }
+ $sequence_3 = { 6689855cffffff b8feffff7f 2bc1 c7856cffffff00000000 c78570ffffff07000000 }
+ $sequence_4 = { 33c9 8bc1 3914c5e84a4100 7408 }
+ $sequence_5 = { c7459c65007800 c745a065000000 83f817 0f82140c0000 83bd58ffffff08 8d8544ffffff }
+ $sequence_6 = { 51 50 51 ffb580feffff 8d8d5cffffff }
+ $sequence_7 = { 51 ffb580feffff 8d8d5cffffff e8???????? 838d78feffff06 8d8de4feffff 83bdf8feffff08 }
+ $sequence_8 = { 8b0c8570804100 8a043b 03ce 8b75dc 03cb 43 }
+ $sequence_9 = { 2bc2 3bc8 760e b8ffffff7f befeffff7f 03c0 }
condition:
- 7 of them and filesize <483328
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Lodeinfo_Auto : FILE
+rule MALPEDIA_Win_Alureon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "47c099ff-69db-5812-85ce-57e24072ce38"
+ id = "d906ba05-9af9-5358-abd3-33a25815a15f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lodeinfo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lodeinfo_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alureon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alureon_auto.yar#L1-L161"
license_url = "N/A"
- logic_hash = "e6a58ad7e2bc0ff5d6e63ebfb8b716b1912a0a95e296af817067906fecf4c3bd"
+ logic_hash = "69c2ddac38bf20f21fb2d59f504ac16289e135ccaf5d5c616ac40bfbb62cd466"
score = 75
quality = 75
tags = "FILE"
@@ -135277,32 +142292,38 @@ rule MALPEDIA_Win_Lodeinfo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 894de0 8955f0 8955f8 8955f4 85ff 740a 381433 }
- $sequence_1 = { 85c0 7412 ff75f4 8b55f0 8bc8 e8???????? 83c404 }
- $sequence_2 = { 85ff 742e 8b4c2444 8bc7 }
- $sequence_3 = { 660fefc8 0f114c0620 0f10440630 0f28ca 660fefc8 0f114c0630 83c040 }
- $sequence_4 = { 5d c3 8b75fc 8b55f0 33c9 85d2 7429 }
- $sequence_5 = { 8bda 8b5508 57 8bf9 895df8 8b06 }
- $sequence_6 = { e8???????? 83c404 894708 85c0 750d 39460c 7408 }
- $sequence_7 = { 03c8 8b4510 d1e9 024fff 884c17ff 8b4dd4 3bf3 }
- $sequence_8 = { eb72 8b45f0 8975f4 c64406ff00 eb65 8b45f8 8d7e01 }
- $sequence_9 = { 85c0 748e 33c0 0f57c0 b920010000 8bfa }
+ $sequence_0 = { 59 32c0 8d7c2420 f3aa 8b4d14 }
+ $sequence_1 = { 3b442410 75cf 33c0 5f 5e 5b c20800 }
+ $sequence_2 = { 6800001000 8d45f8 50 c745d818000000 }
+ $sequence_3 = { 68000010c0 8d45fc 50 c745d818000000 }
+ $sequence_4 = { 6800000080 6a03 56 6a01 }
+ $sequence_5 = { 41 8bca 49 ffc7 }
+ $sequence_6 = { 2bc8 03cf 8908 eb2f 837dfc05 751c }
+ $sequence_7 = { 6800005600 8d45d0 50 53 }
+ $sequence_8 = { 53 ff15???????? 8945f8 56 }
+ $sequence_9 = { c745f000010000 749d ff75e8 ff15???????? }
+ $sequence_10 = { 66a5 8d85a8feffff 50 68???????? a4 }
+ $sequence_11 = { 741c 8d85e4fbffff 50 8d85f8feffff 50 }
+ $sequence_12 = { 837dfc0a 7cc0 eb32 8bc3 }
+ $sequence_13 = { 50 33f6 46 56 8d8424cc000000 50 }
+ $sequence_14 = { 8d8424ec010000 50 68???????? ff15???????? 85c0 0f84f2020000 }
+ $sequence_15 = { ff15???????? 85c0 7409 39b424c8000000 75cf 53 53 }
condition:
- 7 of them and filesize <712704
+ 7 of them and filesize <278528
}
-rule MALPEDIA_Win_Banjori_Auto : FILE
+rule MALPEDIA_Win_Stresspaint_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0d7b2a6e-e2ca-5160-9081-9a7cfdf5e1be"
+ id = "1abc90df-5501-5268-be5d-9ffd5264cf78"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.banjori"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.banjori_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stresspaint"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stresspaint_auto.yar#L1-L151"
license_url = "N/A"
- logic_hash = "9dcfb5d77d585c9251303d49a0603c551cff0efcfccd66cc7c87519a0e64ecdd"
+ logic_hash = "34d2cc78b8a1b3b96faf71dac1e0e5a144bca4946a3f4a475da9ab8b6bdc6c9b"
score = 75
quality = 75
tags = "FILE"
@@ -135316,32 +142337,38 @@ rule MALPEDIA_Win_Banjori_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6800010000 e8???????? 8945f4 81f9000c0000 7308 e8???????? 8945f0 }
- $sequence_1 = { 50 ff15???????? ffb5a0feffff e8???????? 53 53 53 }
- $sequence_2 = { 68???????? ff75fc ff15???????? 53 ff75fc ff15???????? 68???????? }
- $sequence_3 = { ff750c 53 53 53 53 ff7508 ff35???????? }
- $sequence_4 = { 78e1 8945e8 eb18 8d85aafeffff 50 ff75e8 ff15???????? }
- $sequence_5 = { 85c0 7539 68???????? e8???????? 85c0 752b }
- $sequence_6 = { 6802000080 e8???????? 85c0 0f85fe000000 895df0 8d45f0 50 }
- $sequence_7 = { 8945f4 8d45f8 50 6819000200 6a00 68???????? 6802000080 }
- $sequence_8 = { 50 ff35???????? e8???????? e9???????? c745f864000000 68???????? ff15???????? }
- $sequence_9 = { 6a10 8d45b4 50 ff75c4 ff15???????? 85c0 0f883a020000 }
+ $sequence_0 = { 0103 014510 294514 83665800 }
+ $sequence_1 = { 8d540208 8908 8d4a04 8a5202 51 }
+ $sequence_2 = { 8d540203 3bea 7e4d 8b6c241c }
+ $sequence_3 = { 0106 83560400 837d1c00 7494 }
+ $sequence_4 = { 0103 ebaa 8b442408 56 }
+ $sequence_5 = { 0103 014510 294674 8b4674 }
+ $sequence_6 = { 0107 115f04 3bcb 7508 }
+ $sequence_7 = { 0108 8b8e44010000 114804 8b4f18 }
+ $sequence_8 = { 0107 83570400 85c9 7508 }
+ $sequence_9 = { 010b 8945fc 8bc2 83530400 }
+ $sequence_10 = { 8d5318 c7432400200000 66897312 c6431100 890a }
+ $sequence_11 = { 8d540201 52 51 6a39 55 }
+ $sequence_12 = { 8d540101 8bc5 89542430 8b542450 }
+ $sequence_13 = { 8d5338 3b02 740a 41 83c250 3bcf }
+ $sequence_14 = { 8d540201 8915???????? 33c0 8bd6 }
+ $sequence_15 = { 8d540208 8b4500 c70100000000 8b4c2430 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <1155072
}
-rule MALPEDIA_Win_Tiny_Turla_Auto : FILE
+rule MALPEDIA_Win_Yoddos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "03ecfc31-50be-55ad-b8ea-3661b97e212f"
+ id = "731c8af4-0cfb-5784-8919-5690671f4ddf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tiny_turla"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tiny_turla_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yoddos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yoddos_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "78e001a1d7d03185ba347a5f9852159024940a515be46a1732bb8c9313d9ab24"
+ logic_hash = "ffa9bd7fe378e38b72240a0efe08e70cc8c93f69e8ec293489b47b5a90d316d8"
score = 75
quality = 75
tags = "FILE"
@@ -135355,32 +142382,32 @@ rule MALPEDIA_Win_Tiny_Turla_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4533ed 8b7d7f 488b742450 8d4f02 }
- $sequence_1 = { 0f84f8000000 33d2 488d4da0 448d4268 }
- $sequence_2 = { 488b16 8bd8 894567 41b906000200 488d4577 4533c0 }
- $sequence_3 = { 48895c2420 ff15???????? 85c0 750e 488bce }
- $sequence_4 = { ff15???????? 85c0 7516 4533ed }
- $sequence_5 = { 440fb62a 44886d6f 44894d7f 4585c0 7540 }
- $sequence_6 = { ff15???????? b005 e9???????? 8b0f 85c9 }
- $sequence_7 = { 418d511b ff15???????? 488bcb 85c0 0f849b000000 8b7d50 }
- $sequence_8 = { 48c74308ffffffff 488b4b18 4883f9ff 740e ff15???????? }
- $sequence_9 = { 4883ec18 c7042400000000 33c0 83f801 7441 8b0424 488b4c2420 }
+ $sequence_0 = { ff15???????? 85c0 0f84e0010000 8d8584fcffff 56 50 }
+ $sequence_1 = { 66895dd8 66895dda 6a0e e8???????? 59 8a8485a4ecffff 8845dc }
+ $sequence_2 = { 740c ffb5c0fcffff ff15???????? b863000000 90 b89dffffff }
+ $sequence_3 = { c6458e65 c6458f6e c6459055 c6459172 c645926c c6459341 }
+ $sequence_4 = { b89dffffff 90 33db 891d???????? b863000000 90 b89dffffff }
+ $sequence_5 = { 0c01 c1f905 83e61f 88450b 8d3c8d00764100 c1e603 }
+ $sequence_6 = { 895dfc c78538ffffff62000000 68???????? 50 e8???????? ff7508 8d8524feffff }
+ $sequence_7 = { 57 ff7508 e8???????? 8bf8 56 037d08 }
+ $sequence_8 = { 0fb7750c 6683f97e 7502 33c9 0fb7d1 8a945504ffffff 3010 }
+ $sequence_9 = { eb28 8d4df0 6a10 51 }
condition:
- 7 of them and filesize <51200
+ 7 of them and filesize <557056
}
-rule MALPEDIA_Win_Pittytiger_Rat_Auto : FILE
+rule MALPEDIA_Win_Faketc_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9764afd8-8e4e-54dd-9ad2-bd1903f5455d"
+ id = "17b42993-c08e-510a-afaa-62243000eea0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pittytiger_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pittytiger_rat_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.faketc"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.faketc_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "a2f2e591a5e3a3c37398ec723056984b2fa4039658f61ff9463c257a6584be3f"
+ logic_hash = "d424513e0804264658899ed0249bf1311c7683556fe66475d3d53a03a7ef5219"
score = 75
quality = 75
tags = "FILE"
@@ -135394,34 +142421,34 @@ rule MALPEDIA_Win_Pittytiger_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8175ec90b48f19 8175f0596f62d6 885df4 50 8d85d4ffffff }
- $sequence_1 = { a3???????? 0f8451feffff 8d45b8 c745b84f70656e 50 57 }
- $sequence_2 = { ab ab aa 8d7dc8 33c0 a5 }
- $sequence_3 = { 397df8 7678 3bf7 7474 }
- $sequence_4 = { 8bf8 83ffff 7512 ff15???????? }
- $sequence_5 = { 3bc3 a3???????? 0f8476ffffff 8d459c c745ac65416500 50 }
- $sequence_6 = { 7512 ff15???????? 50 53 }
- $sequence_7 = { 50 895df8 ff7510 ff750c ff75fc }
- $sequence_8 = { ff15???????? 85c0 741c 6a40 ff75f0 ffd7 6af1 }
- $sequence_9 = { 8d85dcfdffff 50 8d85e0feffff 50 7407 68???????? eb05 }
+ $sequence_0 = { e8???????? c684248001000002 8b442448 8b5004 8bce ffd2 84c0 }
+ $sequence_1 = { e8???????? 83c410 6a5e 8d8576f7ffff 50 6a00 6a00 }
+ $sequence_2 = { 899158010000 8b4508 8b484c 8b55f8 668b4104 66894248 8b4df8 }
+ $sequence_3 = { e8???????? 83c410 6a00 8b4d8c 51 6a01 8b5508 }
+ $sequence_4 = { ffd6 50 b86f000000 e8???????? 83c404 a3???????? eb06 }
+ $sequence_5 = { e9???????? 8d45d8 50 e8???????? c3 8d8548ffffff 50 }
+ $sequence_6 = { c1fa04 8bc2 c1e81f 03c2 895c2410 0f842b010000 895c241c }
+ $sequence_7 = { e8???????? 8b85b0fdffff 8b0d???????? 8d95b8fdffff 52 68???????? 50 }
+ $sequence_8 = { e8???????? b917000000 8bf0 bf???????? f3a5 66a5 c745fc02000000 }
+ $sequence_9 = { c745fc???????? c745f805000000 eb0e c745fc???????? c745f806000000 8b4d08 8b91fc030000 }
condition:
- 7 of them and filesize <2162688
+ 7 of them and filesize <6864896
}
-rule MALPEDIA_Win_Kurton_Auto : FILE
+rule MALPEDIA_Win_Simplefilemover_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f013ccb0-04a7-5f02-910f-ce10f5a3eef2"
+ id = "21ae03b9-45c9-58fd-b17b-9f1c4dcf7bf7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kurton"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kurton_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.simplefilemover"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.simplefilemover_auto.yar#L1-L219"
license_url = "N/A"
- logic_hash = "dc4903969616e73929d77cdaee0d726bcae8e439ec6bc053e08d133b52122f5e"
+ logic_hash = "81c6919dbb4aaa2e054461ca67f688251b4ccec2baef13a001955aba375181dd"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -135433,32 +142460,44 @@ rule MALPEDIA_Win_Kurton_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89542430 8d8c24b8000000 89542434 50 8954243c }
- $sequence_1 = { 83c8ff eb1f 8bce 83e61f c1f905 8bc6 8b0c8da05b0210 }
- $sequence_2 = { 33c0 8dbc2458010000 c744242800010000 f3ab 8d442428 8d8c2458010000 50 }
- $sequence_3 = { 889c2478040200 e8???????? 89b42474040200 e9???????? b91f000000 }
- $sequence_4 = { 64a100000000 50 64892500000000 81ecb8000000 8a442403 53 }
- $sequence_5 = { 84c0 752b 8b442414 3bc3 }
- $sequence_6 = { 8d88740a0000 8988280b0000 33c9 c780180b0000902f0210 }
- $sequence_7 = { 83c410 c20400 68???????? e8???????? 6a00 6a00 6a01 }
- $sequence_8 = { b91f000000 33c0 8dbc24ad000000 889c24ac000000 f3ab 66ab }
- $sequence_9 = { 895de0 895ddc 895dfc 897de4 740a 803800 7405 }
+ $sequence_0 = { 8bfc f3a5 e8???????? 81c420020000 }
+ $sequence_1 = { 33c0 e9???????? 6820020000 ff15???????? }
+ $sequence_2 = { 81c420020000 85c0 7407 68???????? eb05 68???????? ff15???????? }
+ $sequence_3 = { b988000000 8bf3 8bfc f3a5 }
+ $sequence_4 = { 33ff 884c2408 3bf7 88542424 897c2410 }
+ $sequence_5 = { 7503 8bfa 46 668b4102 83c102 42 }
+ $sequence_6 = { 8b8d54faffff 51 ff15???????? 6a00 6800200000 8d9554daffff }
+ $sequence_7 = { 8b8554faffff 50 ff15???????? 85c0 }
+ $sequence_8 = { 8b74241c 57 8a8800010000 8a9001010000 33ff }
+ $sequence_9 = { ebc2 ebc0 ebbe ebbc ebba ebb8 }
+ $sequence_10 = { e8???????? 81c420020000 85c0 7410 68???????? ff15???????? }
+ $sequence_11 = { 8b4c2414 8d447b02 50 51 }
+ $sequence_12 = { 5f 889000010000 888801010000 5e 83c410 c3 }
+ $sequence_13 = { e9???????? 807d0867 0f848f020000 807d0870 0f8513040000 }
+ $sequence_14 = { 83bd08daffffff 7409 83bd08daffff00 750f c78508daffff00000000 e9???????? 6a04 }
+ $sequence_15 = { 47 897c2418 0fbfff 3bfb 0f8c54ffffff 8a4c242c }
+ $sequence_16 = { 6a64 ff15???????? ff4de0 395de0 7fd4 }
+ $sequence_17 = { 52 8d855cfaffff 50 8d8d60daffff 51 }
+ $sequence_18 = { 8d85b0ddffff 50 e8???????? 8d45dc 57 50 8b45f4 }
+ $sequence_19 = { 50 ff7610 6a00 6a00 ffd7 ff7508 8d4302 }
+ $sequence_20 = { 8b4c2408 8b742424 53 81e1ff000000 }
+ $sequence_21 = { 53 52 ff15???????? 83c408 5f 5e }
condition:
- 7 of them and filesize <344064
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Cryptbot_Auto : FILE
+rule MALPEDIA_Win_Blackcoffee_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1c6d7eb4-b0bc-5398-a1c7-a56c78dd600a"
+ id = "73dd8c3a-f7dc-5a69-bc96-7ac383f83a0a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptbot_auto.yar#L1-L150"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackcoffee"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackcoffee_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "09f972034d92b74b2b134cacc0a51ffba015046eb0d41dcfb99ea848a8d7ad71"
+ logic_hash = "5b61b5b3834a5515967b9008b852cdcc413fc16af2ff85fb0eab8d0101f0945d"
score = 75
quality = 75
tags = "FILE"
@@ -135472,39 +142511,34 @@ rule MALPEDIA_Win_Cryptbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c0 85ed 0f94c0 8be8 }
- $sequence_1 = { 33c0 eb0a b917d90000 e8???????? }
- $sequence_2 = { e9???????? b949dc0000 e9???????? b944dc0000 e9???????? b964dc0000 }
- $sequence_3 = { e8???????? 85c0 750c b961030200 e8???????? }
- $sequence_4 = { 0f9cc0 eb02 32c0 84c0 }
- $sequence_5 = { eb0c b99fed0000 e8???????? 8907 }
- $sequence_6 = { e8???????? 85c0 750e b9ca070200 e8???????? 8bc8 }
- $sequence_7 = { e8???????? 85c0 750f b955960100 e8???????? e9???????? }
- $sequence_8 = { 744e 0fb74802 83e103 3bcb }
- $sequence_9 = { 750b 8bce e8???????? 8b4c2428 }
- $sequence_10 = { 7508 85f6 7404 c6464101 5e c3 }
- $sequence_11 = { 7518 8b542414 83c718 8bcd }
- $sequence_12 = { 7409 33d2 e8???????? 8bf8 43 }
- $sequence_13 = { 2403 80e110 8ad1 3c02 7509 }
- $sequence_14 = { 751f 8bd5 8bce e8???????? }
+ $sequence_0 = { 8d85b4feffff 50 ff75f8 ff15???????? 8b85b4feffff }
+ $sequence_1 = { 8b35???????? 57 33ff 3bc7 7416 57 50 }
+ $sequence_2 = { 8b45fc 83c424 8d44301a 6a1c 6a40 894508 ff15???????? }
+ $sequence_3 = { 890d???????? ebdb 89848a00c0e7ff a1???????? ff05???????? }
+ $sequence_4 = { e8???????? ff36 e8???????? 83c00c 68444e4549 }
+ $sequence_5 = { 8d856cffffff c7856cffffff94000000 50 ff15???????? 6a05 }
+ $sequence_6 = { c20800 55 8bec 81ec98000000 56 57 }
+ $sequence_7 = { 899d30ffffff 66895df0 f3ab 8d7df2 6a0f }
+ $sequence_8 = { 83c00c 0107 8b37 03f3 e8???????? 6854414449 }
+ $sequence_9 = { 57 c7460404100680 897e0c 894614 ff75f8 53 ff15???????? }
condition:
- 7 of them and filesize <11116544
+ 7 of them and filesize <118784
}
-rule MALPEDIA_Win_Kimsuky_Auto : FILE
+rule MALPEDIA_Win_Scout_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "161d56f8-b6bc-5eb6-924b-1d343e294025"
+ id = "782e8973-04d4-5ac6-ba73-37d8fadd11cc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kimsuky"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kimsuky_auto.yar#L1-L285"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scout"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.scout_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "9e58434bf421de4759f7d578f12345202af7c8ac65503745224655e4e4de3bf9"
+ logic_hash = "5102c52e17a0c63528d1a50969c6684ed49d0991b2b60fe184c02299aec673c2"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -135516,53 +142550,32 @@ rule MALPEDIA_Win_Kimsuky_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ffd6 8bd8 85db 7510 5e }
- $sequence_1 = { 6a00 6800f70484 6a00 6a00 68???????? 8d85e4fbffff 50 }
- $sequence_2 = { 8d85ecfbffff 50 8d85f8feffff 50 8d85f4fdffff }
- $sequence_3 = { ffd7 a3???????? 8d85ccf3ffff 50 56 ffd7 }
- $sequence_4 = { 7503 56 eb18 6a00 6a00 6a00 }
- $sequence_5 = { 85c0 7423 6a00 8d85f0feffff 50 68???????? }
- $sequence_6 = { b9???????? e8???????? 8d85f8feffff 50 6a00 6a00 6a1a }
- $sequence_7 = { eb06 ff15???????? 85c0 7421 }
- $sequence_8 = { ff15???????? 85c0 7516 ff15???????? 8bd8 e8???????? }
- $sequence_9 = { 4156 4157 4883ec40 48896c2470 4889742438 4533ff 4c89642428 }
- $sequence_10 = { ebdb 65488b042560000000 48897c2430 48896c2460 }
- $sequence_11 = { 0f857affffff 4c8b7c2460 4c8b6c2420 4c8b642428 488b7c2430 488b742438 488b6c2470 }
- $sequence_12 = { 498bce 418d5001 ffd3 488bc3 4883c440 415f }
- $sequence_13 = { 488b742438 488b6c2470 4d8bc6 4d2b4730 }
- $sequence_14 = { 0f8540feffff 488b6c2460 4c637d3c 33c9 41b800300000 4c03fd }
- $sequence_15 = { 4533ff 4c89642428 4c896c2420 33f6 4533ed 4533e4 }
- $sequence_16 = { 85c0 0f94c1 85c9 0f8494020000 }
- $sequence_17 = { 4c89642430 c744242880000000 c744242002000000 4533c9 4533c0 }
- $sequence_18 = { 85c0 0f8432020000 8b7590 660f1f440000 }
- $sequence_19 = { 8b9590000000 0395d8000000 0395b8000000 8bbda0010000 8d4702 03c2 89442450 }
- $sequence_20 = { 8b4c2468 c6043900 803f00 740d }
- $sequence_21 = { 488d8a38000000 e9???????? 488d8a28010000 e9???????? }
- $sequence_22 = { 85c0 7464 c7453038000000 33c0 }
- $sequence_23 = { 85c0 7471 895c2468 8d4801 }
- $sequence_24 = { 83f809 8d7340 7405 be20000000 c68424a000000000 }
- $sequence_25 = { 668945c4 8b05???????? 8945d8 0fb705???????? }
- $sequence_26 = { 668945ea 6644896dec 4c8d45c0 488d1563c20400 }
- $sequence_27 = { 66894507 884509 895d0b 85ff }
- $sequence_28 = { 668945dc 448d62ff e8???????? 33db }
- $sequence_29 = { 668945b0 488d4db0 e8???????? 488d442450 }
- $sequence_30 = { 668945e8 488bc3 7203 488b03 }
+ $sequence_0 = { 488d537c 41b888140000 488d4df0 e8???????? 41b904000000 }
+ $sequence_1 = { 498bf9 8b0a e8???????? 90 488d1d86780100 488d356f630100 }
+ $sequence_2 = { 736b 488bc3 488bf3 48c1fe06 4c8d2d4ef80000 }
+ $sequence_3 = { 4d8bf8 488bc6 48894df7 488945ef 488d0d36fbfeff 83e03f 458be9 }
+ $sequence_4 = { 488d1520d50000 b805000000 894520 894528 }
+ $sequence_5 = { 7566 b804000000 660f1f840000000000 488d8980000000 }
+ $sequence_6 = { e8???????? 33c0 488b8d90140000 4833cc e8???????? }
+ $sequence_7 = { c745dca8837182 0f1045d0 c744242801000000 8905???????? }
+ $sequence_8 = { 4c89742438 4c897c2430 ff15???????? 33d2 }
+ $sequence_9 = { 75dd 488d05e31b0100 483bd8 74d1 488bcb }
condition:
- 7 of them and filesize <1021952
+ 7 of them and filesize <315392
}
-rule MALPEDIA_Win_Gcman_Auto : FILE
+rule MALPEDIA_Win_Ramdo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c3dd4f52-d013-5409-b72e-5ec2ecf28c4b"
+ id = "5b8e6fef-0e3b-5ed2-888f-7434293b69d6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gcman"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gcman_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ramdo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ramdo_auto.yar#L1-L104"
license_url = "N/A"
- logic_hash = "646fd6c677e3b810f35c02ba75646dde96abf31f60dd053593e8964313629ea3"
+ logic_hash = "915394834672872c9dd5e507ba31a9e70d058b5fc9e0d5522912234c2f6ee339"
score = 75
quality = 75
tags = "FILE"
@@ -135576,32 +142589,32 @@ rule MALPEDIA_Win_Gcman_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { a1???????? 8944240c c7442408???????? 8b85d0ebffff }
- $sequence_1 = { 0375e0 01f1 81e959dc6b54 c1c10f 01d9 89c6 }
- $sequence_2 = { 89442408 c7442404???????? 8d8528eaffff 890424 e8???????? }
- $sequence_3 = { 8944240c c7442408???????? 89542404 8b45f4 890424 }
- $sequence_4 = { c705????????00000000 c705????????00000000 e8???????? 85c0 7439 8d859ceaffff 89442410 }
- $sequence_5 = { c745c400000000 e9???????? c744241c00000000 c744241800000000 c744241403000000 c744241000000000 }
- $sequence_6 = { 83bdd4ebffff00 750c c7042401000000 e8???????? }
- $sequence_7 = { 8b8558efffff 890424 e8???????? 83ec08 81bde8efffff03010000 7405 }
- $sequence_8 = { 89c6 31d6 31ce 0375d8 01f3 81eb1b662419 c1c30b }
- $sequence_9 = { 40 890424 e8???????? 8945fc 8b45fc 89442408 8b450c }
+ $sequence_0 = { 6813299e13 6a00 6a00 e8???????? }
+ $sequence_1 = { ff55f8 8945fc 837dfcff 7411 }
+ $sequence_2 = { 688fe57c18 6a03 6a00 e8???????? }
+ $sequence_3 = { 681186933f 6a03 6a00 e8???????? }
+ $sequence_4 = { 68b20cdc96 6a03 6a00 e8???????? }
+ $sequence_5 = { 6a00 6a00 ff95dcfeffff 8945fc }
+ $sequence_6 = { e8???????? 3db7000000 7405 8b45fc }
+ $sequence_7 = { 681b313f7d 6a03 6a00 e8???????? }
+ $sequence_8 = { 68e9b528b6 6a03 6a00 e8???????? }
+ $sequence_9 = { 68c29e34ea 6a03 6a00 e8???????? }
condition:
- 7 of them and filesize <81920
+ 7 of them and filesize <548864
}
-rule MALPEDIA_Win_Hyperbro_Auto : FILE
+rule MALPEDIA_Win_Wscspl_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3941e796-a485-533f-bda6-3b99f666d1b3"
+ id = "f31d95be-4f0b-51e3-8f5f-15d1afc6eb9e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hyperbro"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hyperbro_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wscspl"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wscspl_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "4bee21ef51c3ea4f0bd6259a2f8a9c95c3e4ba56a999c789fc7f134934b59561"
+ logic_hash = "4a0c5de1937bca874bba721d790f101d8b394ac870591bd7e9ae3e7dc3c9255d"
score = 75
quality = 75
tags = "FILE"
@@ -135615,32 +142628,32 @@ rule MALPEDIA_Win_Hyperbro_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c0 6a40 66890479 e8???????? 6a40 }
- $sequence_1 = { 8b4604 83c004 50 6a00 57 }
- $sequence_2 = { 46 47 83e801 75f5 }
- $sequence_3 = { 8d542428 68???????? c74424200c000000 c744242801000000 89542424 ff15???????? }
- $sequence_4 = { 05ff000000 41 3d01feffff 0f871c010000 8bd5 2bd1 83fa01 }
- $sequence_5 = { 50 8d4c2472 51 6689442474 }
- $sequence_6 = { 6882000000 c706???????? e8???????? 6882000000 6a00 50 }
- $sequence_7 = { e8???????? 83c404 83eb01 79ec 8b4f2c 51 e8???????? }
- $sequence_8 = { 83c410 85ed 750e 8b7c2410 }
- $sequence_9 = { 8b44242c 3bc3 7415 50 e8???????? 83c404 }
+ $sequence_0 = { 740b b855000000 66a3???????? 8b4c2404 51 }
+ $sequence_1 = { 8bcd 8d742414 8d442418 e8???????? 0fbf442414 50 8d4c241c }
+ $sequence_2 = { 8d442430 50 68???????? 6a00 6a00 c744244000000000 }
+ $sequence_3 = { 8b74240c 3bf7 7435 8b3d???????? 8d4900 8b4618 8b4004 }
+ $sequence_4 = { 8d642400 8b0c18 8d1418 bf05000000 }
+ $sequence_5 = { 3bc1 763a 03c9 3bc1 }
+ $sequence_6 = { 663bf8 752f e8???????? 8b0d???????? }
+ $sequence_7 = { 51 ff15???????? ff15???????? 6888130000 }
+ $sequence_8 = { 8b1d???????? 55 33c0 56 83c1fb }
+ $sequence_9 = { 687c230000 8d44240c 6a01 50 ff15???????? 687c230000 68c10b0000 }
condition:
- 7 of them and filesize <352256
+ 7 of them and filesize <901120
}
-rule MALPEDIA_Win_Murofet_Auto : FILE
+rule MALPEDIA_Win_Mongall_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7aa9a2c5-7064-5442-8638-24194df65bf5"
+ id = "df02f29b-7e4c-5b43-ac4d-a0a6d3cf6ee1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.murofet"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.murofet_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mongall"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mongall_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "f1786a85d9dda8157fc7a7bca5587363f921b04e9ce6db23c0c6a6b000291064"
+ logic_hash = "09c3cb724c571a18322afe8d7b1ace648402df7ba3a7200f8ca50d9538f078c7"
score = 75
quality = 75
tags = "FILE"
@@ -135654,32 +142667,32 @@ rule MALPEDIA_Win_Murofet_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3c02 72e5 e8???????? a2???????? 84c0 7510 }
- $sequence_1 = { 7504 3c02 72bf b001 }
- $sequence_2 = { 3c02 72e5 e8???????? a2???????? }
- $sequence_3 = { e8???????? e8???????? 3c02 72e5 e8???????? a2???????? 84c0 }
- $sequence_4 = { 6a10 8d4624 55 50 ff15???????? 83c40c }
- $sequence_5 = { c3 e8???????? 33c0 c20400 55 8bec 83ec68 }
- $sequence_6 = { e8???????? 33c0 c20400 55 8bec 83ec68 53 }
- $sequence_7 = { 6a10 8d4624 55 50 }
- $sequence_8 = { 72e5 e8???????? a2???????? 84c0 7510 }
- $sequence_9 = { ff15???????? c6443eff00 83f8ff 7509 56 }
+ $sequence_0 = { ff15???????? 8b400c 8b08 8b11 52 ff15???????? ba???????? }
+ $sequence_1 = { 85ff 747c 56 57 68???????? e8???????? 68???????? }
+ $sequence_2 = { f3a5 8bc8 8b8500d9ffff 83e103 43 }
+ $sequence_3 = { 59 8985a0fdffff 3bc1 0f87cb090000 ff2485e6574000 838de8fdffffff 89b594fdffff }
+ $sequence_4 = { 8bd8 83fbff 7448 68???????? e8???????? }
+ $sequence_5 = { e8???????? 8bfc 85ff 741d 8b8df4fdffff 56 }
+ $sequence_6 = { 56 8d45f0 33f6 50 8935???????? 8935???????? ff15???????? }
+ $sequence_7 = { 8b7df0 8bc7 5f 5e c60300 }
+ $sequence_8 = { 89b5e4fdffff 89b5e0fdffff 89b5c0fdffff 888deffdffff }
+ $sequence_9 = { 85f6 5e 741d 8d85f8feffff }
condition:
- 7 of them and filesize <622592
+ 7 of them and filesize <199680
}
-rule MALPEDIA_Win_Spora_Ransom_Auto : FILE
+rule MALPEDIA_Win_Downeks_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8b8ba74c-729e-5b95-8216-285cfd8906d9"
+ id = "45e36078-208a-5456-a83d-718f8ea60024"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spora_ransom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spora_ransom_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.downeks"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.downeks_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "4f4859e5c4c90863719bd127457464f7d14cd9fd2e5234c00f8157e8748b1142"
+ logic_hash = "f8eb51f40370e6583f97bf6d6b06a56caeeec4252d81205dee3da42852ee5b8c"
score = 75
quality = 75
tags = "FILE"
@@ -135693,71 +142706,71 @@ rule MALPEDIA_Win_Spora_Ransom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a3a 8d4641 668945f0 58 ff7510 668945f2 ff750c }
- $sequence_1 = { f6c301 742c 6a3a 8d4641 668945f0 58 ff7510 }
- $sequence_2 = { 897df4 85ff 747a 834d08ff }
- $sequence_3 = { 834d08ff 8d45f8 50 57 8d4508 50 }
- $sequence_4 = { 8d4641 668945f0 58 ff7510 668945f2 ff750c 33c0 }
- $sequence_5 = { 33c0 668945f4 8d45f0 50 ff15???????? 50 8d45f0 }
- $sequence_6 = { 0fb600 48 50 ff36 ff15???????? 85c0 }
- $sequence_7 = { c745c800040000 33f6 8d45c4 50 ff15???????? 85c0 750e }
- $sequence_8 = { 50 ff15???????? 85c0 7466 56 57 bf00020000 }
- $sequence_9 = { 0bf0 57 ff15???????? 5f 8bc6 }
+ $sequence_0 = { e9???????? 8b8ddcfeffff 51 ff15???????? 8b8de0feffff 53 }
+ $sequence_1 = { c3 8b4108 c3 b8ccd00904 c3 8bff 55 }
+ $sequence_2 = { 8d4da0 e8???????? 8b4704 85c0 7409 83f8ff 7304 }
+ $sequence_3 = { e8???????? 8bd8 83c40c 85db 0f85cf000000 8b55c0 85d2 }
+ $sequence_4 = { 2bce 51 8bce 2b4d80 8d75a8 8d558c e8???????? }
+ $sequence_5 = { e9???????? 8d75b4 e9???????? 8d75d0 e9???????? 8bb560ffffff e9???????? }
+ $sequence_6 = { c785e8faffff07000000 89b5e4faffff 668995d4faffff e8???????? 8975fc 80fb5c 740a }
+ $sequence_7 = { c1ea08 0fb6d2 8b3c95a0c20804 0fb6d0 8b1495a0c60804 c1e808 0fb6c0 }
+ $sequence_8 = { ff15???????? 8bf0 83c42c 85f6 0f8547feffff 8b45f0 50 }
+ $sequence_9 = { 7488 8b4d0c 833900 7502 8901 8b4d10 8b13 }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <1318912
}
-rule MALPEDIA_Win_Unidentified_063_Auto : FILE
+rule MALPEDIA_Win_Thanatos_Ransom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d22cba4e-b95b-5578-ac95-09534bd7dc14"
- date = "2022-11-21"
- modified = "2022-11-25"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_063"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_063_auto.yar#L1-L124"
+ id = "fa527852-1102-5288-af99-f970a4826a1e"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thanatos_ransom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.thanatos_ransom_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "14c180eecdf0e6fbf2b936d6c444ad58c2e649e1fa770106e8719057ee1aefbd"
+ logic_hash = "9c5c5f690fb079c4870ec7aa84eb31a9ced013d63674be92b3d66d32a913f4ab"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20221118"
- malpedia_hash = "e0702e2e6d1d00da65c8a29a4ebacd0a4c59e1af"
- malpedia_version = "20221125"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d43cf 83f819 770c 6689b550030000 e9???????? }
- $sequence_1 = { 7363 488bf3 4c8d35dfc40100 83e63f 488beb 48c1fd06 48c1e606 }
- $sequence_2 = { e8???????? 4863f8 488d3588800100 488bcb }
- $sequence_3 = { 0f11442478 4c8b4708 488d442470 493bc0 7362 488b07 488d4c2470 }
- $sequence_4 = { 4885c9 7407 48ff25???????? c3 48894c2408 57 4883ec50 }
- $sequence_5 = { 83f801 7518 488b0d???????? 488d05bf5f0100 483bc8 7405 e8???????? }
- $sequence_6 = { 8b8c96d0cd0200 8b534c 33c8 0fb6c1 }
- $sequence_7 = { 0f84e7000000 488b0e 483bc8 740e 4885c9 7406 }
- $sequence_8 = { 498bc2 418be9 48c1f806 488d0d708c0100 4183e23f 4903e8 }
- $sequence_9 = { 488d158a5a0200 488bcb e8???????? 85c0 7499 488d157f5a0200 488bcb }
+ $sequence_0 = { 50 ff75e0 e8???????? 8b4df8 8bc7 5f 33cd }
+ $sequence_1 = { 8b00 8bc8 e8???????? c645fc0a }
+ $sequence_2 = { 50 e8???????? 56 8bd0 c645fc04 }
+ $sequence_3 = { 83c404 c60300 ff15???????? 50 e8???????? be14000000 }
+ $sequence_4 = { c745500f000000 c7454c00000000 c6453c00 83f810 7242 8b4d54 }
+ $sequence_5 = { 88441de8 43 8975e0 83fb04 757c 33f6 8a4435e8 }
+ $sequence_6 = { 8b0c85e0774300 8a06 46 8844392c 2bf2 eb14 }
+ $sequence_7 = { 0f8580000000 8b4508 dd00 ebc6 c745e0a0bd4200 e9???????? }
+ $sequence_8 = { 40 8d4de0 50 ff75e0 e8???????? 8b4df8 }
+ $sequence_9 = { e8???????? c70021000000 e9???????? 894ddc c745e034bf4200 e9???????? c745e030bf4200 }
condition:
- 7 of them and filesize <475136
+ 7 of them and filesize <516096
}
-rule MALPEDIA_Win_Obscene_Auto : FILE
+rule MALPEDIA_Win_Furtim_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b0504e00-5509-5e10-82c6-a688a7937d0f"
+ id = "ff92451b-6d4d-5ce0-b407-7dcb5e6ae2c6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.obscene"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.obscene_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.furtim"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.furtim_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "62960aba55b9b132d0d487c37c4dacdc8a915363f3251233103a943c3f791f18"
+ logic_hash = "01fa4c0038a5d8991914e1859c3786c2de4cd564716dd7c7ecdf607d66ee4df9"
score = 75
quality = 75
tags = "FILE"
@@ -135771,34 +142784,34 @@ rule MALPEDIA_Win_Obscene_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a06 68fc421010 ff35???????? 6aff ff15???????? ff7520 }
- $sequence_1 = { 68e4401010 e8???????? 59 80a0e240101000 68e4401010 e8???????? 59 }
- $sequence_2 = { 59 6820431010 68e4401010 e8???????? 59 59 85c0 }
- $sequence_3 = { 0fbe00 83f809 7416 8b45fc 0fbe00 83f80d }
- $sequence_4 = { 59 80a012109a0000 68???????? e8???????? }
- $sequence_5 = { 50 e8???????? 59 68???????? 8d85ecf6ffff 50 }
- $sequence_6 = { 8bec b8400d0300 e8???????? 68360d0300 ff7508 }
- $sequence_7 = { 59 59 68c4501010 68d83f1010 6814110010 e8???????? }
- $sequence_8 = { 0fbe00 83f82d 7409 8b45f8 40 8945f8 eb08 }
- $sequence_9 = { 8365fc00 6a40 ff7508 ff15???????? 59 59 }
+ $sequence_0 = { 5f 5e c9 c20400 6a0c 68???????? e8???????? }
+ $sequence_1 = { 85c0 7c28 8d45fc 50 6a04 ff15???????? }
+ $sequence_2 = { c7867802000020d94000 c78600050000cb224000 c786f406000032164000 c746601c724400 c7869c06000032254000 c786fc020000ca254000 }
+ $sequence_3 = { 59 85c0 7408 8bce ff96cc050000 5f }
+ $sequence_4 = { 57 8bf1 8dbeb8000000 57 c7071c010000 ff96bc030000 }
+ $sequence_5 = { c9 c20800 8bff 55 8bec 83ec10 ff7508 }
+ $sequence_6 = { 0f85e3000000 39a9c0000000 7542 0fb781cc010000 663bc5 7405 663bc3 }
+ $sequence_7 = { 740f 837dfc01 7509 c686c405000001 eb0e 8bce ff96f8040000 }
+ $sequence_8 = { c745e4e4624400 c745e8ec624400 c745ecf4624400 c745f0fc624400 c745f404634400 c745f8???????? }
+ $sequence_9 = { 389f94010000 7546 80bf9501000015 7535 80bf960100005d 752c 8bce }
condition:
- 7 of them and filesize <2170880
+ 7 of them and filesize <622592
}
-rule MALPEDIA_Win_Sepulcher_Auto : FILE
+rule MALPEDIA_Win_Sierras_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "666ccc80-c712-59f8-bf12-61bac5486b32"
+ id = "605d6eab-f109-574e-b05c-a9ae83591a9c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sepulcher"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sepulcher_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sierras"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sierras_auto.yar#L1-L167"
license_url = "N/A"
- logic_hash = "fea20fdb29a4a6cc26bf9baf225a8110e30f06d577e665b386797a74632bb5da"
+ logic_hash = "a564c7fabb45cfabecce73bb6168ff37faec379b0995b89fe8defbd9d38cf80c"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -135810,32 +142823,38 @@ rule MALPEDIA_Win_Sepulcher_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 56 57 6a43 8bf9 58 6a4d 8db784480000 }
- $sequence_1 = { 7515 6a04 8d45bc 50 e8???????? 8b4db8 8bd0 }
- $sequence_2 = { 58 6a74 59 6a53 668945ea 58 }
- $sequence_3 = { 0fb71408 8bc2 c1e002 66393408 75f1 }
- $sequence_4 = { eb1a 8d45fc 50 8b04bd50de0110 ff743018 }
- $sequence_5 = { 668945d2 b8???????? 66894db4 66894dba 66894dc0 }
- $sequence_6 = { 56 57 6a5a 58 6a52 }
- $sequence_7 = { c1f906 6bd030 8b45fc 03148d50de0110 8b00 894218 }
- $sequence_8 = { 8bd8 895db0 8d0c4dffff0000 51 57 53 e8???????? }
- $sequence_9 = { 58 6a33 668945e8 668945ea 58 6a32 668945ec }
+ $sequence_0 = { f3a4 8d8c2424050000 8d942430080000 51 }
+ $sequence_1 = { 56 8bf1 57 68???????? 8d4604 50 }
+ $sequence_2 = { 50 8d45e0 50 e8???????? eb0f 8b4dec }
+ $sequence_3 = { e8???????? 50 8d442430 50 8d8c24ec000000 }
+ $sequence_4 = { 0f8480030000 8b4dfc ff4df8 0fb611 8bcf }
+ $sequence_5 = { 7507 e8???????? eb05 e8???????? 0175f0 }
+ $sequence_6 = { 8bf1 e8???????? 8b8698010000 5e }
+ $sequence_7 = { 8bc8 83e103 f3a4 8bbc2410040000 }
+ $sequence_8 = { 03fb 3b7d10 72b0 8b5df0 834dfcff 8d4de0 }
+ $sequence_9 = { 8bf1 33db 6a01 6a78 }
+ $sequence_10 = { f2ae f7d1 2bf9 8d942480000000 8bf7 8bd9 8bfa }
+ $sequence_11 = { 8bf1 e8???????? 8b8608010000 5e c3 56 }
+ $sequence_12 = { 397d08 897dfc 0f8cc0000000 837d0801 7e58 }
+ $sequence_13 = { c7401880dd4000 e9???????? 83e00f c70613000000 894648 8b4648 85c0 }
+ $sequence_14 = { 58 0fb688c88c4000 6683bc8e7e0a000000 7506 }
+ $sequence_15 = { 3bf8 7cce 8b442418 83c520 40 83f803 89442418 }
condition:
- 7 of them and filesize <279552
+ 7 of them and filesize <131072
}
-rule MALPEDIA_Win_Doublefantasy_Auto : FILE
+rule MALPEDIA_Win_Bruh_Wiper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fe1fe594-5930-58a6-8152-affb40d52392"
+ id = "8004678f-c7f1-56db-b368-30e9334ba4b0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doublefantasy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doublefantasy_auto.yar#L1-L176"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bruh_wiper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bruh_wiper_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "c2743e8ba6874f5905b98f01968f640324da6dd46040ee9e2e2dc712fae3b7b1"
+ logic_hash = "26b32a2c0d923fc99fb91e4beb18e36e72d9c523fef8bdb0bb63ddd5fd11ff5a"
score = 75
quality = 75
tags = "FILE"
@@ -135849,38 +142868,32 @@ rule MALPEDIA_Win_Doublefantasy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff75e0 e8???????? 8945c4 3d05000780 7458 3d09000c80 }
- $sequence_1 = { 770b 0fb6c0 8a80ad8c2700 eb02 32c0 84c0 7410 }
- $sequence_2 = { 8a80908c2700 eb02 b03d 884103 c3 55 }
- $sequence_3 = { 33d2 8a5001 c1ee06 83e20f c1e202 0bd6 8a92908c2700 }
- $sequence_4 = { ff750c 8b4622 03c6 50 e8???????? 83c40c be???????? }
- $sequence_5 = { 51 68???????? ff750c 8b1d???????? ffd3 83c420 ff75e0 }
- $sequence_6 = { 8a92908c2700 885101 7e1c 0fb67002 }
- $sequence_7 = { ff45f8 3c2b 720f 3c7a 770b 0fb6c0 8a80ad8c2700 }
- $sequence_8 = { 0bd6 837c241001 8a92908c2700 885101 }
- $sequence_9 = { 8a92908c2700 eb02 b23d 837c241002 885102 }
- $sequence_10 = { 85c0 7c6a 8b45e4 8b08 8d954cffffff }
- $sequence_11 = { e8???????? 8b4605 c68094a3270000 ff35???????? ff35???????? e8???????? 83c414 }
- $sequence_12 = { a5 a5 a5 66a5 6a3d 59 }
- $sequence_13 = { 68???????? 68???????? ff15???????? 83c40c 837de000 0f8660010000 }
- $sequence_14 = { ff750c ff7508 ff15???????? 8945a8 3bc3 752b }
- $sequence_15 = { 33ff eb06 56 e8???????? }
+ $sequence_0 = { e8???????? 83c40c be01080000 0f1f8000000000 }
+ $sequence_1 = { 83ee01 75e3 8b4dfc 5f 5e }
+ $sequence_2 = { 8d45f4 57 50 ff15???????? ff15???????? }
+ $sequence_3 = { 68b40200c0 ffd6 8b4dfc 5f 33cd 5e }
+ $sequence_4 = { 6a00 8d85f8fdffff 50 6800020000 8d85fcfdffff 50 }
+ $sequence_5 = { 68???????? 57 ffd3 6800020000 8d85fcfdffff 6a00 }
+ $sequence_6 = { 50 ffd6 8bf0 8d45fb 50 6a00 6a01 }
+ $sequence_7 = { 6800200000 68???????? 57 ffd3 6800020000 8d85fcfdffff }
+ $sequence_8 = { e8???????? 83c40c be01080000 0f1f8000000000 6a00 }
+ $sequence_9 = { 50 ffd6 68???????? 68???????? 8bf8 }
condition:
- 7 of them and filesize <172032
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Atmspitter_Auto : FILE
+rule MALPEDIA_Win_Tigerlite_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f9f02df1-a803-5665-939b-8200861b4172"
+ id = "aa691ec3-b883-5f5c-8994-9e33da37724e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atmspitter"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atmspitter_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tigerlite"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tigerlite_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "97d22d23e6b57a565b78835f63d6efbbbb7ac3961285afa1ce44048c0fb5a727"
+ logic_hash = "fcf8f4ae129308f814ca77b619fbfadd3ec5da4949cb79481c9fac330ba09f68"
score = 75
quality = 75
tags = "FILE"
@@ -135894,32 +142907,38 @@ rule MALPEDIA_Win_Atmspitter_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { a900800000 7422 68???????? e8???????? 83ec24 }
- $sequence_1 = { 8be5 5d c3 8b5c2420 33c0 89442450 }
- $sequence_2 = { 56 89442418 e8???????? 83c40c 8bf0 8974244c }
- $sequence_3 = { a4 c744241831323000 88542422 c744242800000080 89442430 }
- $sequence_4 = { 8b442410 50 53 8d4c2468 68???????? 51 ff15???????? }
- $sequence_5 = { c3 8b04cd14c04000 5d c3 }
- $sequence_6 = { 8975e0 8db190c84000 8975e4 eb2b 8a4601 }
- $sequence_7 = { 6a03 6816011200 68???????? ff15???????? 6a02 6a00 8bf8 }
- $sequence_8 = { 83c404 8d442420 50 ff15???????? a900800000 7422 }
- $sequence_9 = { 6a00 57 ff15???????? 6a00 8d45fc }
+ $sequence_0 = { c1f805 83e71f c1e706 8b0485489d4100 83c00c 03c7 50 }
+ $sequence_1 = { 8b85e0f7ffff 85c0 751d 56 ff15???????? b832000000 5f }
+ $sequence_2 = { 8b8d24e5ffff 50 8b8528e5ffff 8b0485489d4100 }
+ $sequence_3 = { 85c0 740d ff15???????? b8c8000000 eb65 }
+ $sequence_4 = { ff15???????? cc 4c8d4510 488d15bbc80100 }
+ $sequence_5 = { 41b8ff030000 c6859000000000 e8???????? 488d1528bc0100 488d8d90000000 e8???????? }
+ $sequence_6 = { 33c0 8bbdbcfdffff 0fbebcc7f8214100 8bc7 89bdbcfdffff 8bbde4fdffff }
+ $sequence_7 = { 668986b8000000 668986be010000 c7466878874100 83a6b803000000 6a0d e8???????? }
+ $sequence_8 = { 4863c2 4803d8 eb61 4b8b84ea604a0200 42f644300848 743e 48ffc3 }
+ $sequence_9 = { 663955d8 7442 668933 8a45d8 4b8b8cea604a0200 4288443109 }
+ $sequence_10 = { 8b3495489d4100 8a441e04 84c0 0f8957020000 }
+ $sequence_11 = { 488bcb 488bf8 e8???????? 4885ff 0f8405040000 4c8d4530 488d0da1a40100 }
+ $sequence_12 = { 488d4c2440 418bd6 e8???????? e9???????? }
+ $sequence_13 = { b9e5000000 8bd8 83e303 e8???????? }
+ $sequence_14 = { 3bfa 7556 8bcb e8???????? 53 }
+ $sequence_15 = { 8d0c00 894dec eb38 8b45f4 8b0485489d4100 }
condition:
- 7 of them and filesize <147456
+ 7 of them and filesize <349184
}
-rule MALPEDIA_Win_Agfspy_Auto : FILE
+rule MALPEDIA_Win_Remsec_Strider_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "aa314a06-4040-546e-b9cd-d5bfa676b734"
+ id = "5cf05a79-eeb6-5c58-8271-14cb9c81c326"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.agfspy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.agfspy_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.remsec_strider"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.remsec_strider_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "e751bb17a85204a5afd3cbca773cdafd25186332344d59ffe01d62696a3fda9d"
+ logic_hash = "69887265225a27114e8e9d83252b405933e8e0558a06ab3222eee20510a77720"
score = 75
quality = 75
tags = "FILE"
@@ -135933,32 +142952,32 @@ rule MALPEDIA_Win_Agfspy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7527 83fefd 7431 8a4101 3a4201 751a 83fefe }
- $sequence_1 = { 85f6 7539 8d45c0 50 8d45d4 50 e8???????? }
- $sequence_2 = { 731d 8d4101 83fe10 8945d0 8d45c0 0f4345c0 881408 }
- $sequence_3 = { c645fc04 8d45b0 837dc408 51 0f4345b0 8d4d84 50 }
- $sequence_4 = { e8???????? eb46 8b4720 85c0 741f 837e1410 8bce }
- $sequence_5 = { 2bc1 83c0fc 83f81f 7724 e9???????? 32c0 8b4df4 }
- $sequence_6 = { 837de808 0f4375d4 3b55cc 752f 85d2 7413 2bf0 }
- $sequence_7 = { 50 e8???????? 8ac8 8b45b4 83f80c 74e7 }
- $sequence_8 = { 0fb602 eb05 8b01 ff501c 83f8ff 742f 8b0e }
- $sequence_9 = { d1f8 51 8bcb 8d0442 50 52 }
+ $sequence_0 = { 74f7 8b4130 2dbc97e889 f7d8 1bc0 f7d0 }
+ $sequence_1 = { 6a1a 58 6a10 8945e4 8945e8 58 }
+ $sequence_2 = { c9 c20800 55 8bec b804000100 }
+ $sequence_3 = { 85c9 74f7 8b4130 2dbc97e889 }
+ $sequence_4 = { 6803010000 50 ff15???????? 83c414 8d45f0 50 }
+ $sequence_5 = { 0d00000040 50 8d85e8fdffff 50 }
+ $sequence_6 = { ebf5 8b432c ff30 68???????? }
+ $sequence_7 = { 0510010000 68???????? 6803010000 50 }
+ $sequence_8 = { ff772c ff15???????? 85c0 7512 ff15???????? 8bc8 }
+ $sequence_9 = { 85ff 7415 83ff05 7410 68???????? 6a02 }
condition:
- 7 of them and filesize <1482752
+ 7 of them and filesize <344064
}
-rule MALPEDIA_Win_Cmstar_Auto : FILE
+rule MALPEDIA_Win_Anatova_Ransom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "aaad9b46-b601-594d-9a0b-7ba351f67235"
+ id = "6cd7c8c4-20c9-5c58-baa7-e42d545001dc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cmstar"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cmstar_auto.yar#L1-L174"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.anatova_ransom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.anatova_ransom_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "c5a1f8b6b909717cbba254781a42955dfe756a8fae37e256ff72ffa4cd43d897"
+ logic_hash = "2867d50f6d60295cd1f6876cf7316363316dea4699194cf318a991da479d380e"
score = 75
quality = 75
tags = "FILE"
@@ -135972,40 +142991,34 @@ rule MALPEDIA_Win_Cmstar_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 836dfc10 ff75fc 8945e0 8b45dc 83c310 }
- $sequence_1 = { 8b4dec c1e802 6a04 52 8d0481 50 e8???????? }
- $sequence_2 = { ff75e0 ff30 e8???????? 8b4df8 }
- $sequence_3 = { ff15???????? 8bc6 e9???????? 6a10 8d45d0 53 }
- $sequence_4 = { ff15???????? 6a04 e8???????? be00040000 }
- $sequence_5 = { 56 bb04010000 57 53 }
- $sequence_6 = { ff15???????? 6a03 58 5f 5e 5b c9 }
- $sequence_7 = { 85c0 7504 6a03 eb0d 803b4d }
- $sequence_8 = { 81ce00ffffff 46 8a1c06 88542418 881c01 8b5c2418 }
- $sequence_9 = { 8b2d???????? 8b44241c 8bc8 48 85c9 8944241c 7e65 }
- $sequence_10 = { 5d 741c 8a41ff 3ac3 740b 3cff }
- $sequence_11 = { 7505 a1???????? 50 ff15???????? eb17 }
- $sequence_12 = { 8bf0 8d5601 52 e8???????? 83c404 8bf8 8d442414 }
- $sequence_13 = { e9???????? 55 83f801 57 7532 }
- $sequence_14 = { 50 ff15???????? 83f8ff 89442420 7507 33f6 e9???????? }
- $sequence_15 = { 8b5c2408 55 8b6c2414 56 57 8b7c2418 8bcb }
+ $sequence_0 = { 488d05ec570000 48894588 488d05eb570000 48894590 }
+ $sequence_1 = { b805000000 4989c3 488b01 4989c2 4c89d1 4c89da e8???????? }
+ $sequence_2 = { 4989c2 4c89d1 e8???????? e9???????? 488b45e0 4989c2 4c89d1 }
+ $sequence_3 = { e8???????? 488b05???????? 488b0d???????? 488b15???????? 488945f0 488d45fc 4889442420 }
+ $sequence_4 = { 4883f800 0f84b2000000 488b05???????? 4883f800 0f84a1000000 488b05???????? }
+ $sequence_5 = { 4989c2 4c89d1 e8???????? 488b05???????? 4883f800 0f843e000000 8b05???????? }
+ $sequence_6 = { b800000000 4989c3 b802000000 4989c2 4c89d1 4c89da 4c8b1d???????? }
+ $sequence_7 = { 4989c0 488b45d8 4989c3 488b45a0 4989c2 4c89d1 4c89da }
+ $sequence_8 = { 4989c1 b800000000 4989c0 b800000000 4989c3 }
+ $sequence_9 = { 48b80f00000000000000 4989c0 b800000000 4989c3 488d45b1 4989c2 4c89d1 }
condition:
- 7 of them and filesize <4268032
+ 7 of them and filesize <671744
}
-rule MALPEDIA_Win_Kuaibu8_Auto : FILE
+rule MALPEDIA_Win_Remexi_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "91f1248d-ab2b-5079-b9e0-a51e87297924"
+ id = "687f133c-aa4c-5c82-a16b-c166cd521a0e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kuaibu8"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kuaibu8_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.remexi"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.remexi_auto.yar#L1-L209"
license_url = "N/A"
- logic_hash = "cbf2ea9a6bca6a983b840d14cd3e4818a640e713858e86101c3fa57dacf19221"
+ logic_hash = "05a94cf7e4fffe2d3333c852ee9c9ff577487ed8e4c35b0a2c90ccf7655ac3b0"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -136017,32 +143030,43 @@ rule MALPEDIA_Win_Kuaibu8_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 e8???????? 83c404 58 8945e4 8b5ddc }
- $sequence_1 = { 895dc8 6a00 6a00 6a00 6804000080 }
- $sequence_2 = { 52 e8???????? 83c404 8d0c2f 8bf0 8b03 }
- $sequence_3 = { e9???????? 8b5dec e8???????? 8945d8 837dd803 0f8586010000 }
- $sequence_4 = { ff75f4 e8???????? 83c408 83f800 0f8521000000 8b45fc 85c0 }
- $sequence_5 = { 81ec30000000 c745fc00000000 8965f8 8b5d08 ff33 ff15???????? 90 }
- $sequence_6 = { e8???????? 8945d4 8b5ddc 85db 7409 }
- $sequence_7 = { 53 e8???????? 83c404 58 8945f4 6805000000 e8???????? }
- $sequence_8 = { dd5de8 dd45e8 dc25???????? dd5de0 8b5df8 e8???????? b802000000 }
- $sequence_9 = { 83c404 8803 e9???????? bd02000000 55 e8???????? 668b4e0c }
+ $sequence_0 = { 56 c706ffffffff e8???????? 83c404 }
+ $sequence_1 = { 53 50 ff15???????? 3dffffff00 }
+ $sequence_2 = { ff15???????? 8bf0 85f6 7513 8b45d8 }
+ $sequence_3 = { 68???????? 50 ff15???????? 8b0d???????? 8b35???????? 890d???????? 68???????? }
+ $sequence_4 = { 8945e0 8945e4 8945e8 b802000000 }
+ $sequence_5 = { ff15???????? 6a10 8d4ddc 8bf0 51 56 ff15???????? }
+ $sequence_6 = { 8b95d4feffff 52 6a00 68ffff1f00 ffd7 }
+ $sequence_7 = { e8???????? 83ec1c 8bcc 89642430 6aff 53 }
+ $sequence_8 = { 52 56 50 e8???????? 8bf0 eb02 }
+ $sequence_9 = { 57 e8???????? 6a01 6a00 6a00 ff15???????? }
+ $sequence_10 = { 33c0 5f c3 56 ff15???????? 57 8b3d???????? }
+ $sequence_11 = { 8b45d8 8b4818 8b5104 50 8955e0 }
+ $sequence_12 = { 890d???????? 68???????? 41 50 a3???????? }
+ $sequence_13 = { 488bf9 33d2 33c9 e8???????? 488d0d74e90100 4885c0 480f44c1 }
+ $sequence_14 = { 488d15fe730200 488d4c2450 e8???????? 90 41b902000000 }
+ $sequence_15 = { 0f8333010000 488d4550 483bf0 0f8726010000 }
+ $sequence_16 = { 488b0b e8???????? 48c743180f000000 48c7431000000000 c60300 8bc7 488b4c2438 }
+ $sequence_17 = { 4883ec40 48c7442428feffffff 48895c2460 4889742468 488b05???????? }
+ $sequence_18 = { 488d0527dd0100 488981b8000000 4883a17004000000 b90d000000 }
+ $sequence_19 = { 488d4c2470 e8???????? 85c0 750a b902020208 }
+ $sequence_20 = { b902010209 e8???????? 90 48837b1810 }
condition:
- 7 of them and filesize <737280
+ 7 of them and filesize <614400
}
-rule MALPEDIA_Win_Brutpos_Auto : FILE
+rule MALPEDIA_Win_Ksl0T_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bb6abccd-59b3-5a30-9e67-ccbe498737a5"
+ id = "5a4c8dc6-6c96-5c41-9019-3d4bc785a54b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.brutpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.brutpos_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ksl0t"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ksl0t_auto.yar#L1-L172"
license_url = "N/A"
- logic_hash = "89d0bc6a7e52ba9f63dface96ebbf483b03be0cbf8144ed32f3b88bf360b4eda"
+ logic_hash = "5f184f0ae6eb14c42a9f8143b74f6a69a5bb90e2ed5eff63faec19a839c8988a"
score = 75
quality = 75
tags = "FILE"
@@ -136056,32 +143080,38 @@ rule MALPEDIA_Win_Brutpos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 59 58 83c004 83e904 8808 }
- $sequence_1 = { 03c2 034508 2938 83e902 75e8 ebd9 5e }
- $sequence_2 = { 8d5b18 8b5b60 03d8 52 8b35???????? }
- $sequence_3 = { 6681f9df77 7412 0f31 8bd8 }
- $sequence_4 = { 8bd0 ad 8bc8 83e908 66ad 6685c0 740c }
- $sequence_5 = { 8d7c38fc baffffffff 83c704 57 }
- $sequence_6 = { 66ad 6685c0 740c 25ff0f0000 03c2 034508 }
- $sequence_7 = { 52 e8???????? 59 8b09 8bd1 }
- $sequence_8 = { c1e202 03d3 8b12 03d0 }
- $sequence_9 = { 8b5508 8b4204 0fb70a 50 51 807401ff97 }
+ $sequence_0 = { ff15???????? 83c40c 3bf7 7515 ff15???????? }
+ $sequence_1 = { c68424a100000039 c68424a200000039 888c24a3000000 c684248000000026 }
+ $sequence_2 = { c684241001000006 88842411010000 889c2412010000 c684241301000013 }
+ $sequence_3 = { 68???????? 8d8d00080000 51 ff15???????? 8d9500080000 52 }
+ $sequence_4 = { ff942418040000 4c8bd8 488b842420040000 4c899878010000 488d542468 }
+ $sequence_5 = { c68424f600000034 c68424f700000038 c68424f800000030 c68424f900000002 c68424fa00000055 c644245813 c64424593c }
+ $sequence_6 = { c684245a01000021 c684245b01000018 c684245c01000030 c684245d01000026 c684245e01000026 c684245f01000034 }
+ $sequence_7 = { 4881c294000000 41b801000000 488d0dd7e60000 ff15???????? }
+ $sequence_8 = { 8d94241c030000 52 53 89466c ffd7 894670 }
+ $sequence_9 = { 3bcf 7518 81fa00010000 7510 }
+ $sequence_10 = { c684248800000002 c684248900000055 c684241801000000 c68424190100003b c684241a0100003d c684241b0100003a }
+ $sequence_11 = { 84c0 745a 68???????? 68???????? ff15???????? 68???????? 68???????? }
+ $sequence_12 = { 488bce 488905???????? ff15???????? 488bc8 e8???????? 488d1592280000 488bce }
+ $sequence_13 = { ff15???????? 8bf0 6800020000 57 8d95000d0000 52 ff15???????? }
+ $sequence_14 = { 7509 488d0de2450000 eb02 33c9 e8???????? 4883c438 c3 }
+ $sequence_15 = { c68424f801000038 c68424f901000034 c68424fa01000039 c68424fb01000039 c68424fc0100003a }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <196608
}
-rule MALPEDIA_Win_Powerpool_Auto : FILE
+rule MALPEDIA_Win_Adylkuzz_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0805ab0c-2483-51ef-91bd-613062750253"
+ id = "092d1cf3-18b6-52f1-b243-99d6007e2b3c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.powerpool"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.powerpool_auto.yar#L1-L157"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.adylkuzz"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.adylkuzz_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "c10aba7ea9fc986a00a689a799239b370f623f0a4bcaeb12871b3235333f8df6"
+ logic_hash = "de89fec9458f93b8b7ae503a1f8b6b5fd97e3b1bb1f58b10dd0b4e8fc16d178d"
score = 75
quality = 75
tags = "FILE"
@@ -136095,38 +143125,32 @@ rule MALPEDIA_Win_Powerpool_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 741f 90 8b4e54 8a01 }
- $sequence_1 = { 7420 8b4514 8b4dfc 81c12c020000 }
- $sequence_2 = { 895de8 8b5dcc 2bd8 895940 8b5dd0 }
- $sequence_3 = { 005311 40 005d11 40 006711 }
- $sequence_4 = { 7420 83e91d 7412 83e903 0f8515010000 c745dcfcae4400 }
- $sequence_5 = { 7420 3c0a 740c 6a0a 6a01 8d4b14 }
- $sequence_6 = { 741f d945b8 03c0 03c0 }
- $sequence_7 = { 8b5c2410 23da c1ce0a 03f2 23ee 0bdd 035c2418 }
- $sequence_8 = { 895dd0 8b7940 897dcc 3bc7 7613 }
- $sequence_9 = { 7420 807de000 741a 8b4ddc }
- $sequence_10 = { 006711 40 0000 0303 }
- $sequence_11 = { 7420 8b4508 8b4d0c 3bc1 }
- $sequence_12 = { 895ddc 895dfc 8d45e0 50 }
- $sequence_13 = { 895de0 895de4 33c9 66898dd0fdffff }
- $sequence_14 = { 895ddc 8b45e4 50 e8???????? }
- $sequence_15 = { 744f 53 57 8bff 8bc8 }
+ $sequence_0 = { f5 f8 0fb7bc79b0010000 81fa00000001 0f833a000000 3b45fc 0f83c3fc0100 }
+ $sequence_1 = { 8b44242c 8b4804 894c2428 8b4a04 894c2430 8b08 8b02 }
+ $sequence_2 = { e8???????? 807e053d 8944240c 8d4340 754b 89e9 bafe00008d }
+ $sequence_3 = { 891c24 e8???????? c744240401000000 891c24 e8???????? 85c0 7518 }
+ $sequence_4 = { f9 663bc9 33d8 03f8 e9???????? 8b442500 660fbdd5 }
+ $sequence_5 = { f8 f5 03f8 e9???????? ff742500 055a2dd112 8dad04000000 }
+ $sequence_6 = { 89442408 8b4510 89442404 8b03 890424 e8???????? 8b550c }
+ $sequence_7 = { f6c3d8 2dc4275e67 2bce 660fc8 66d3c0 fec8 8d440aa4 }
+ $sequence_8 = { e9???????? 8b4c2500 80c4f7 d2d8 648b01 89442500 81ee04000000 }
+ $sequence_9 = { c7442404ffffffff 891c24 e8???????? 8974240c 89442408 c7442404???????? 891c24 }
condition:
- 7 of them and filesize <819200
+ 7 of them and filesize <6438912
}
-rule MALPEDIA_Win_Caddywiper_Auto : FILE
+rule MALPEDIA_Win_Quantloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "24926b93-f761-5ed3-a63e-3417e035ba52"
+ id = "4febf63d-0f98-5ee5-9cc6-9fa1c2da1c7c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.caddywiper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.caddywiper_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.quantloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.quantloader_auto.yar#L1-L175"
license_url = "N/A"
- logic_hash = "79a75ac7d216323abd7ca177a49671b9ea50088d3b0d895d69cfd4d03ce4d9ea"
+ logic_hash = "02e93017f3318c384f200ca1e9ba6b581c4815c155dd61d906306a2c75ce48f2"
score = 75
quality = 75
tags = "FILE"
@@ -136140,32 +143164,38 @@ rule MALPEDIA_Win_Caddywiper_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8345b404 66837dac00 75c4 c745a800000000 }
- $sequence_1 = { c68592feffff64 c68593feffff00 c68594feffff76 c68595feffff00 c68596feffff61 c68597feffff00 }
- $sequence_2 = { 51 e8???????? 83c408 8985b0fbffff c785f4f1ffff00000000 c68588fbffff4c }
- $sequence_3 = { e9???????? 6a00 8b95acf1ffff 52 ff9564f7ffff }
- $sequence_4 = { 8b4dfc 8b5508 c7048a00000000 ebd7 }
- $sequence_5 = { c645b900 c645ba39 c645bb00 c645bc00 c645bd00 8d4d98 898df4f7ffff }
- $sequence_6 = { c685a3feffff00 c685a4feffff6c c685a5feffff00 c685a6feffff6c c685a7feffff00 }
- $sequence_7 = { c6459264 c6459300 8d458c 50 8d8d90feffff }
- $sequence_8 = { 8985fcf7ffff 8d55c0 52 8d45dc }
- $sequence_9 = { 7407 8b4598 50 ff55fc 8b4594 8be5 }
+ $sequence_0 = { 8d85f8fdffff 890424 e8???????? 8d85f8fdffff 890424 e8???????? }
+ $sequence_1 = { e8???????? c7442404???????? c70424???????? e8???????? 8b450c }
+ $sequence_2 = { e8???????? 85c0 750c c70424???????? e8???????? c70424???????? }
+ $sequence_3 = { e8???????? 85c0 0f94c0 0fb6d8 c744240801000000 8b45f8 }
+ $sequence_4 = { 89442404 c7042400000000 e8???????? 83ec0c 8d85f8f7ffff 89442404 }
+ $sequence_5 = { c744240400000000 c70424???????? e8???????? 83ec14 8945f4 }
+ $sequence_6 = { c70424???????? e8???????? c744240800000000 c7442404???????? c70424???????? }
+ $sequence_7 = { 817d08???????? 7470 817d0c00704000 7467 8b4508 803800 }
+ $sequence_8 = { 8d341e 66ad 6633d0 75df }
+ $sequence_9 = { 75f1 5e 8bc6 8bf7 3bc5 7403 }
+ $sequence_10 = { 61 c3 60 8bd3 8bf2 03763c 2b5634 }
+ $sequence_11 = { 837d5400 7425 64ff3530000000 59 8b490c 8b490c }
+ $sequence_12 = { ff30 6800100000 57 81042400100000 ff550c }
+ $sequence_13 = { 61 c3 58 ffd0 837c240802 7414 64a118000000 }
+ $sequence_14 = { 5d 8bc4 ff7010 ff700c ff7008 ff5550 e8???????? }
+ $sequence_15 = { 85c0 741b a900000080 7504 8d440302 25ffffff7f }
condition:
- 7 of them and filesize <33792
+ 7 of them and filesize <155648
}
-rule MALPEDIA_Win_Linseningsvr_Auto : FILE
+rule MALPEDIA_Win_Afrodita_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "acba9094-ad6f-5dc3-983b-34f0b25c68ba"
+ id = "a57e10f8-454f-5804-9e05-9ca06675125c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.linseningsvr"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.linseningsvr_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.afrodita"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.afrodita_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "2644e1e1ca2803e3e5ff6eb23f753be414d9d9a67fa2dca1bfd8c0b76cd44619"
+ logic_hash = "5b27d8ca339092e6723ab16dacd8e13cc60f1f330873451b2d099d87287bfb55"
score = 75
quality = 75
tags = "FILE"
@@ -136179,32 +143209,32 @@ rule MALPEDIA_Win_Linseningsvr_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 81c4cc0d0000 c3 68ffffff7f 56 ff15???????? 83f8ff }
- $sequence_1 = { 5d b801000000 5b 81c4cc0d0000 }
- $sequence_2 = { 8b4c2428 6a24 8d542464 6a01 52 89442464 }
- $sequence_3 = { 7e16 8b742414 8bd1 8d7c1f18 c1e902 f3a5 8bca }
- $sequence_4 = { f6c202 7410 8088????????20 8a9405ecfcffff ebe3 80a0808b400000 40 }
- $sequence_5 = { 0f858b030000 33c9 8acc 3ac8 }
- $sequence_6 = { 55 6800010000 8d942464040000 6a01 52 e8???????? }
- $sequence_7 = { 8acc 3ac8 0f857f030000 33d2 55 89542432 }
- $sequence_8 = { 66895c2411 89442419 885c2418 8944241d 89442421 6689442425 88442427 }
- $sequence_9 = { 7514 ff15???????? 50 68???????? e8???????? 83c408 55 }
+ $sequence_0 = { 83e615 83ce02 89710c 23c6 74a5 a804 740a }
+ $sequence_1 = { e8???????? 56 8d8558ffffff c745fc05000000 57 83cb08 50 }
+ $sequence_2 = { e8???????? eb02 33ff 8bb57cffffff c745fcffffffff 8b4e2c 85c9 }
+ $sequence_3 = { 8d4f10 e8???????? 8b0f 8b4904 03cf 85c0 7454 }
+ $sequence_4 = { 0f1040c0 0f1149a0 0f104c30c0 8b75e8 660fefc8 0f1040d0 0f114c30c0 }
+ $sequence_5 = { 897304 c6430801 53 8d4de4 }
+ $sequence_6 = { 8b4b08 8b7b0c 897df8 894dfc 3bce }
+ $sequence_7 = { e8???????? 83c40c c744be0400000000 c704be00000000 5e 5b }
+ $sequence_8 = { 50 8bcb ff5720 0375d4 8bce e8???????? }
+ $sequence_9 = { 894f04 8bc7 e9???????? 83f854 0f8fdc010000 83f853 0f8dea020000 }
condition:
- 7 of them and filesize <81360
+ 7 of them and filesize <2334720
}
-rule MALPEDIA_Win_Rofin_Auto : FILE
+rule MALPEDIA_Win_Getmail_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1b07367d-380d-5a5b-bc33-dfe76ecfb58c"
+ id = "44034b05-2864-56ad-b1e2-ce75dcdcb73e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rofin"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rofin_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.getmail"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.getmail_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "8597563e9ea27355f4e9d99fcf2f4a72dc9ad41d82ef13adb90824429264b4c0"
+ logic_hash = "cb48fd93bd0d8eb21e02a5c1c72974fd0280a8132ab759131eea2bb4b2c53aaf"
score = 75
quality = 75
tags = "FILE"
@@ -136218,34 +143248,34 @@ rule MALPEDIA_Win_Rofin_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 014df0 3b06 72b5 eb1a 8b45fc 69c01c010000 03c6 }
- $sequence_1 = { 84c0 c706???????? 7417 8b4604 85c0 7410 }
- $sequence_2 = { 8d442434 53 50 33d2 668b95d0030000 56 8d4c242c }
- $sequence_3 = { c644244163 88542442 c644244528 885c2446 c64424473e c644244800 }
- $sequence_4 = { 8b44240c 8b542404 83ec10 8d4c2400 53 50 }
- $sequence_5 = { 83c408 3bf3 7420 8b4c2420 56 8b513c 52 }
- $sequence_6 = { 72b5 eb1a 8b45fc 69c01c010000 03c6 81781000d00000 7506 }
- $sequence_7 = { f3a4 8d4c246a 6800040000 51 6a00 ff15???????? }
- $sequence_8 = { e8???????? eb73 bf???????? 83c9ff 33c0 f2ae f7d1 }
- $sequence_9 = { 8b45fc 83481c10 8b45fc 89585c 8d45f4 }
+ $sequence_0 = { 896c2460 e8???????? 8d4c2420 8d9424cc000000 51 8d8424a8000000 52 }
+ $sequence_1 = { c68424d000000004 8b040a 813803000930 7508 8b5808 d1eb 80e301 }
+ $sequence_2 = { 55 ffd7 68???????? 55 a3???????? ffd7 8b0d???????? }
+ $sequence_3 = { 50 8b10 ff5208 391d???????? 0f84a2000000 a1???????? }
+ $sequence_4 = { 0f8285feffff 33db 50 e8???????? 83c404 8b442458 50 }
+ $sequence_5 = { c3 57 e8???????? 83c404 3bc5 89432c }
+ $sequence_6 = { 83f961 7208 83f97a 7703 83e957 c0e004 }
+ $sequence_7 = { 8d8c249c000000 8894249c000000 e8???????? 8a442413 6a00 8d8c24ac000000 c68424d400000005 }
+ $sequence_8 = { 8bfe 8b11 2bf8 03c5 57 50 }
+ $sequence_9 = { 8b8424d8000000 33db 3bc3 899c24cc000000 7505 b8???????? 8b8c24dc000000 }
condition:
- 7 of them and filesize <409600
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Anel_Auto : FILE
+rule MALPEDIA_Win_Rdat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "77d9607f-3592-578d-9a57-0a9e2e4b1267"
+ id = "92191fa2-5f3d-5b42-a025-816ea5c7ba9a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.anel"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.anel_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rdat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rdat_auto.yar#L1-L164"
license_url = "N/A"
- logic_hash = "1c7f9ff41f497369b4973c110e6ba50d48e821bb90418969cf9b52dfa74f7f8e"
- score = 75
- quality = 75
+ logic_hash = "258a7b0e2fbdc995f078ce1c969b2a27e77e31fae7722d9e4f1fdbfa2416146c"
+ score = 60
+ quality = 45
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -136257,32 +143287,38 @@ rule MALPEDIA_Win_Anel_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f7fe 43 3bd8 7621 8bd0 d1ea be91cfba01 }
- $sequence_1 = { eb24 8bca 83e910 3b5904 7f17 7c07 }
- $sequence_2 = { 8bf9 2bf8 85c0 7411 eb03 83c010 3bc1 }
- $sequence_3 = { c645fc06 e8???????? c645fc07 8bc8 c645fc08 e8???????? 8bc6 }
- $sequence_4 = { 897814 895810 89458c 8818 8d4678 }
- $sequence_5 = { c1e704 037d08 a5 a5 a5 a5 5f }
- $sequence_6 = { 53 33ff c645fc00 e8???????? 837d1c08 8b4508 7303 }
- $sequence_7 = { 8bec 51 56 8bf0 33c0 894610 c746140f000000 }
- $sequence_8 = { 8d8bd0000000 50 8d55d8 c645fc01 e8???????? 6a01 33ff }
- $sequence_9 = { e8???????? 8bd6 8d8dc8feffff c645fc01 e8???????? c645fc02 83bd04ffffff05 }
+ $sequence_0 = { 3b7744 0f8c19ffffff 8b87ac020000 33ed }
+ $sequence_1 = { 48ffc3 4038341a 75f7 4883791810 488b7910 7203 488b09 }
+ $sequence_2 = { 4863ed 4885ed 0f8ed8000000 8b54b430 }
+ $sequence_3 = { 4c8bc3 4c0f42c7 4d85c0 7504 8bc6 }
+ $sequence_4 = { 4889442470 448bb910010000 4532e4 448aea 488bd9 4585ff 0f8e1e020000 }
+ $sequence_5 = { 4533ff 4c8bf1 44397944 0f8e64010000 }
+ $sequence_6 = { 48894108 4c8b05???????? 488b15???????? 89442420 4d85c0 }
+ $sequence_7 = { 488b09 483bfb 4c8bc3 4c0f42c7 }
+ $sequence_8 = { 45380401 75f7 4c8bc0 498bd1 488d4c2438 }
+ $sequence_9 = { e8???????? 4898 4885c0 751e 483bfb 7313 83c8ff }
+ $sequence_10 = { 85c0 740b b9e8030000 ff15???????? }
+ $sequence_11 = { 4863f0 33d2 8bc2 48c1e006 }
+ $sequence_12 = { 3b566c 0f8d9e000000 488b4660 3b5668 7c1d 2b5668 }
+ $sequence_13 = { 7203 488b00 4c8bc0 498bd7 488d4de0 }
+ $sequence_14 = { 0f84f5000000 4883f910 7205 488b07 }
+ $sequence_15 = { 488d8c2490060000 e8???????? 90 488b942490060000 803a00 7505 4d8bc6 }
condition:
- 7 of them and filesize <376832
+ 7 of them and filesize <1573888
}
-rule MALPEDIA_Win_Rambo_Auto : FILE
+rule MALPEDIA_Win_Nim_Blackout_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9952c16f-0ad8-5b79-a375-78c277443f5b"
+ id = "5ee8f0fb-bcc5-57f1-899f-f87f9c8f8cd3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rambo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rambo_auto.yar#L1-L172"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nim_blackout"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nim_blackout_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "289c05fe82444eba5e21e680847ee18f8bd6fcd3320474143e269d581daca21f"
+ logic_hash = "38658558791a84132e6c1e0a028a41bbfaac44e317840b869e572ec902a09080"
score = 75
quality = 75
tags = "FILE"
@@ -136296,38 +143332,32 @@ rule MALPEDIA_Win_Rambo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff7508 e8???????? 59 50 ff7508 ff15???????? 56 }
- $sequence_1 = { e8???????? ff750c 8d85ecfdffff 50 e8???????? }
- $sequence_2 = { ff15???????? 83c41c 6a01 58 5e c9 }
- $sequence_3 = { 85f6 7437 56 6a01 }
- $sequence_4 = { ff7508 8d85f8feffff 50 e8???????? 8065fe00 8d45fc 50 }
- $sequence_5 = { 83c428 6a32 ff15???????? 8d85f8faffff 50 68???????? }
- $sequence_6 = { 56 57 8d85f8faffff 6a01 50 ff15???????? 80a43df8faffff00 }
- $sequence_7 = { 50 8d85f8feffff 50 c645fc72 }
- $sequence_8 = { 756b 57 b940000000 8d7c240d 8844240c f3ab }
- $sequence_9 = { f3aa 8bcb 8d7c2474 8bc1 }
- $sequence_10 = { e8???????? 8d4c2410 c684240004000007 e8???????? 68b6000000 8d542414 }
- $sequence_11 = { 8d8c2488000000 e8???????? 57 57 8d4c2424 }
- $sequence_12 = { e8???????? 8d4c2428 c684240004000005 e8???????? 8d4c2414 c684240004000004 }
- $sequence_13 = { 8b35???????? a3???????? ffd6 3db7000000 7418 }
- $sequence_14 = { 89442418 8b4309 84c9 7403 50 }
- $sequence_15 = { f3a5 8bcb 8d9424f8020000 83e103 f3a4 bf???????? 83c9ff }
+ $sequence_0 = { 4889c8 83e001 84c0 7405 e8???????? 488b45f0 4885c0 }
+ $sequence_1 = { 48c7401800000000 e9???????? 90 48c745e0c6000000 488d057d5c0200 488945e8 }
+ $sequence_2 = { 488d057ad80000 488905???????? 488d05d85b0200 488905???????? c605????????01 48c705????????60000000 }
+ $sequence_3 = { e8???????? 48c745e0e7000000 488d05c37e0200 488945e8 488b4510 488b00 ba08000000 }
+ $sequence_4 = { e9???????? 90 48c785a800000000000000 48c785a000000000000000 48c7450088010000 488d05885b0100 48894508 }
+ $sequence_5 = { 488945c8 488b4de8 488b55e0 4889d0 4801c0 4801d0 48c1e003 }
+ $sequence_6 = { 488b1402 4889c8 4801c0 4801c8 48c1e004 4889c1 }
+ $sequence_7 = { 488d0542460200 488945c8 488b4510 488b55f8 4889d1 48c1e105 488b55f0 }
+ $sequence_8 = { 488b4588 488945f0 eb49 90 48c745d033000000 488d05f48e0100 488945d8 }
+ $sequence_9 = { 48894508 48c785f800000000000000 48c7450084010000 488d05bf5c0100 48894508 4883bdf000000000 0f84ff000000 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <1068032
}
-rule MALPEDIA_Win_7Ev3N_Auto : FILE
+rule MALPEDIA_Win_Ployx_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cf231267-d18f-5fab-bbdf-ab3bf00ba51c"
+ id = "7a9ae933-1e52-56f8-912b-cfaf3c1a4d79"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.7ev3n"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.7ev3n_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ployx"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ployx_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "3d3793244c4ff8a9f87ce7ce50051977c17fdc03ef0f8a315973a688f14f4ceb"
+ logic_hash = "92d48577836748eb447c5a838f0c9893d40b34aa95d5979c4991a0399ec4439d"
score = 75
quality = 75
tags = "FILE"
@@ -136341,32 +143371,32 @@ rule MALPEDIA_Win_7Ev3N_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8dd0cdffff e8???????? 8bce 2bcf 3bc1 0f8402b10000 }
- $sequence_1 = { 8bd4 89a50cf9ffff c7421407000000 c7421000000000 668902 66398560ffffff 7504 }
- $sequence_2 = { 894104 a0???????? 884108 6a00 8d8504ffffff 50 }
- $sequence_3 = { c785e4fdffff00000000 6a00 c785e0fdffffd0a54500 ff15???????? 33c0 c705????????07000000 }
- $sequence_4 = { 8d85acefffff 50 8d8dd0cdffff e8???????? 8bce 2bcf }
- $sequence_5 = { 6a00 8d85fcfeffff 50 8d8dd0cdffff e8???????? 8bce 2bcb }
- $sequence_6 = { 8dbd38f1ffff 8d4f02 0f1f840000000000 668b07 83c702 6685c0 75f5 }
- $sequence_7 = { 8b0c8d20934500 80643128fd 5f 5e 8be5 5d c3 }
- $sequence_8 = { f30f7e05???????? 660fd68564e6ffff 0fb705???????? 6689856ce6ffff f30f7e05???????? 660fd68558e6ffff 0fb705???????? }
- $sequence_9 = { 0f84724c0000 8dbda0ddffff 8d4f02 0f1f840000000000 668b07 83c702 6685c0 }
+ $sequence_0 = { 8bc3 25ff000000 59 3bf0 59 7443 }
+ $sequence_1 = { 33db 897df8 e8???????? 397dfc 59 59 }
+ $sequence_2 = { 33ff 59 85c0 7e19 8bf0 8bfe 6a20 }
+ $sequence_3 = { 66ab ff35???????? aa 8d8588faffff 68???????? 50 }
+ $sequence_4 = { 8d3c78 8d0437 50 e8???????? 8b4d08 8d3c78 8d0437 }
+ $sequence_5 = { b9???????? b800020000 8d5f02 99 f7fb 47 8901 }
+ $sequence_6 = { 33ff 99 59 f7f9 8bc2 03c1 99 }
+ $sequence_7 = { 59 8945f4 0f848f000000 8d45e8 50 }
+ $sequence_8 = { e8???????? 83c40c 8d85a4fcffff 6a00 50 ff15???????? 8945e8 }
+ $sequence_9 = { 740f 3b7df8 7503 8975f8 57 }
condition:
- 7 of them and filesize <803840
+ 7 of them and filesize <229376
}
-rule MALPEDIA_Win_Cameleon_Auto : FILE
+rule MALPEDIA_Win_Veiledsignal_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "65617330-75c8-57cf-8907-1895d87814f0"
+ id = "caf6fec1-c7fc-5e46-9ec5-501cbcaa1f6a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cameleon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cameleon_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.veiledsignal"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.veiledsignal_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "1c72ed0d3ea99fe45b9cdedee31a0c82e32752220a6d117c9414b55a84125b1d"
+ logic_hash = "36bfcf538a747481c06e92b8c775b0fad665f748b3dccf3367e494f75f4840ed"
score = 75
quality = 75
tags = "FILE"
@@ -136380,32 +143410,32 @@ rule MALPEDIA_Win_Cameleon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 56 57 8bf9 897df0 c745ec00000000 8b07 }
- $sequence_1 = { 8a80f8c70410 8807 47 46 8bcb c6458301 e8???????? }
- $sequence_2 = { 83ec18 8bd4 8965ec c7421000000000 c7421400000000 }
- $sequence_3 = { 8d7dd0 837de408 0f437dd0 83ec18 8bd4 c7421000000000 c7421400000000 }
- $sequence_4 = { 48 a3???????? ff15???????? 8b0d???????? 89048d98ce0510 5d c3 }
- $sequence_5 = { 247f 88441628 eb12 0c80 88441628 8b0cbd50d60510 c644112900 }
- $sequence_6 = { b83b000000 663bc8 0f94c0 84c0 7431 }
- $sequence_7 = { 8d55dc c645fc02 8d8d24ffffff e8???????? 8bc8 8b01 }
- $sequence_8 = { 8bd9 56 57 837b3800 0f848c010000 807b3d00 0f8482010000 }
- $sequence_9 = { 5d c20400 85ff 75d4 897e10 837e1408 720f }
+ $sequence_0 = { 7516 488d05c7390400 4a8b04e8 42385cf839 0f84c2000000 488d05b1390400 }
+ $sequence_1 = { 488d0dbabb0400 48c7040102000000 b808000000 486bc000 488b0d???????? 48894c0420 b808000000 }
+ $sequence_2 = { 0f1f440000 488d54244c 488bce e8???????? 488bcb }
+ $sequence_3 = { 4881c458010000 c3 83f802 7571 488d0516010000 488905???????? 488d0529010000 }
+ $sequence_4 = { 7ec4 83c8ff eb0b 4803f6 418b84f7a8140100 85c0 }
+ $sequence_5 = { 81f95a290000 752b 488d0df8030000 b801000000 48890d???????? }
+ $sequence_6 = { 4c8d0d97960000 498bd1 448d4008 3b0a 742b ffc0 }
+ $sequence_7 = { e8???????? 488bd7 4c8d05e3270400 83e23f 488bcf 48c1f906 }
+ $sequence_8 = { 4883ec20 8b1d???????? eb1d 488d0573b10400 ffcb }
+ $sequence_9 = { ff15???????? 488b55cf 488bc8 ff15???????? 488b4dd7 }
condition:
- 7 of them and filesize <824320
+ 7 of them and filesize <667648
}
-rule MALPEDIA_Win_Htbot_Auto : FILE
+rule MALPEDIA_Win_Isr_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9061a5e4-8534-51fe-80a9-1a440b66e0d7"
+ id = "f92134ff-d8ee-58cb-8cb8-468d7205306f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.htbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.htbot_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.isr_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.isr_stealer_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "90f98baa748c169d2b4b8297454f9f854e4138797b2c83ac6d83acccfa4dd9b0"
+ logic_hash = "75691989209029cb7a637cf5df87a857ef3ef18b6fe3194f56cba1ecab86658c"
score = 75
quality = 75
tags = "FILE"
@@ -136419,32 +143449,32 @@ rule MALPEDIA_Win_Htbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 68???????? 51 ff15???????? 85c0 7524 }
- $sequence_1 = { 56 57 8b7c2440 8b474c 89442414 c7474c00000000 }
- $sequence_2 = { 8908 8b15???????? 8d0c52 83c2ff a3???????? 8d4488f8 8b0d???????? }
- $sequence_3 = { 8b11 50 8b4204 ffd0 8bc5 e9???????? 8d77f0 }
- $sequence_4 = { 51 8bc8 ffd2 8bf8 85ff 0f84ccfeffff 8b4604 }
- $sequence_5 = { 83f801 7e68 8d4d02 6a22 51 }
- $sequence_6 = { 83c010 894510 c684244402000003 a1???????? 8b500c b9???????? ffd2 }
- $sequence_7 = { 8903 c744241c00000000 8b7c2424 8b4708 83c708 8378f400 c744241001000000 }
- $sequence_8 = { 83c010 894514 c684244402000004 a1???????? 8b500c }
- $sequence_9 = { 51 ff15???????? 8d46f0 8d500c 83c9ff f00fc10a 49 }
+ $sequence_0 = { fb b05e 2bc1 e8???????? 661e }
+ $sequence_1 = { 08ac22c115978d 0e e8???????? 07 }
+ $sequence_2 = { 1c8b 53 2456 2bd1 807e6543 }
+ $sequence_3 = { 46 1e 301b 15c2c8c807 d6 12d8 }
+ $sequence_4 = { 8d16 b205 07 d32cb6 08ac22c115978d 0e e8???????? }
+ $sequence_5 = { a7 8d16 b205 07 d32cb6 08ac22c115978d }
+ $sequence_6 = { 07 fb b05e 2bc1 e8???????? }
+ $sequence_7 = { 8d16 b205 07 d32cb6 08ac22c115978d 0e }
+ $sequence_8 = { 07 d32cb6 08ac22c115978d 0e e8???????? }
+ $sequence_9 = { e8???????? 07 fb b05e 2bc1 e8???????? 661e }
condition:
- 7 of them and filesize <196608
+ 7 of them and filesize <540672
}
-rule MALPEDIA_Win_Huskloader_Auto : FILE
+rule MALPEDIA_Win_Seduploader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2b71c66f-6603-595c-99bb-89c942583260"
+ id = "7f16d7a9-71b0-5c84-ab55-9cb76a2d5976"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.huskloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.huskloader_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.seduploader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.seduploader_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "0b5c5ed5027920c73090f364afb1f0be41c97145cf9de72e357bac2712d50fca"
+ logic_hash = "59b0ef9c5ade0664bc2e5b83dd5075b45d913aac7ac67fc4cf5358fb404425b7"
score = 75
quality = 75
tags = "FILE"
@@ -136458,32 +143488,32 @@ rule MALPEDIA_Win_Huskloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bc7 83e03f 6bc838 8b0495e88d0110 }
- $sequence_1 = { 59 e9???????? c745e003000000 e9???????? c745e4c05e0110 ebb8 d9e8 }
- $sequence_2 = { 6a00 681f000f00 50 ff15???????? 85c0 }
- $sequence_3 = { 740e 50 e8???????? 83a6e88d011000 59 83c604 81fe00020000 }
- $sequence_4 = { 8d043b 8b3485601f0110 8d4601 8945fc 8a06 46 }
- $sequence_5 = { 57 8bb81c060000 6a40 6800300000 56 6a00 ff15???????? }
- $sequence_6 = { 85c0 7411 8b35???????? b98b010000 }
- $sequence_7 = { 7420 6bc618 57 8db8288c0110 57 ff15???????? }
- $sequence_8 = { 8b35???????? 85f6 7420 6bc618 57 8db8288c0110 57 }
- $sequence_9 = { 0fb704850c3b0110 8d048508320110 50 8d8590faffff 03c7 50 }
+ $sequence_0 = { 50 ff7630 e8???????? 83c40c 3b4508 }
+ $sequence_1 = { c6411001 c3 55 8bec }
+ $sequence_2 = { 8b4510 83c6fe 8930 8d4601 }
+ $sequence_3 = { 8b4510 83c6fe 8930 8d4601 50 e8???????? }
+ $sequence_4 = { 5e c3 55 8bec e8???????? 8b4d0c }
+ $sequence_5 = { 8b4510 83c6fe 8930 8d4601 50 }
+ $sequence_6 = { e8???????? 8b4510 83c6fe 8930 }
+ $sequence_7 = { ff763c e8???????? 83c40c 3b4508 }
+ $sequence_8 = { ff7630 e8???????? 83c40c 3b4508 }
+ $sequence_9 = { 50 e8???????? 8b4510 83c6fe 8930 8d4601 50 }
condition:
- 7 of them and filesize <229376
+ 7 of them and filesize <401408
}
-rule MALPEDIA_Win_Billgates_Auto : FILE
+rule MALPEDIA_Win_Shipshape_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2ccab9f1-e7c2-5897-af43-0d6c30857357"
+ id = "77ebf79f-670a-594a-bd26-db4684807e7a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.billgates"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.billgates_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shipshape"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shipshape_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "e0a8f89c836a13df9d06b620bc16eb3744a9d5b82a5ea28cb550060f6d08f1fc"
+ logic_hash = "d30091c6ebd49f11de789ea622fcb4cbfab75e230e1b049ba06177bb5b7dc7cb"
score = 75
quality = 75
tags = "FILE"
@@ -136497,32 +143527,32 @@ rule MALPEDIA_Win_Billgates_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3c11 7408 3c22 7404 3c30 }
- $sequence_1 = { 8d8809f9ffff b8c94216b2 f7e9 03d1 }
- $sequence_2 = { 3c58 7507 b802000000 eb02 }
- $sequence_3 = { 740c 3c11 7408 3c22 7404 3c30 }
- $sequence_4 = { 3c10 740c 3c11 7408 }
- $sequence_5 = { 83f8ff 750c ff15???????? 8bd8 f7db }
- $sequence_6 = { 3c11 7408 3c22 7404 }
- $sequence_7 = { ff15???????? 83f8ff 7508 ff15???????? f7d8 85c0 }
- $sequence_8 = { 3c10 740c 3c11 7408 3c22 }
- $sequence_9 = { 3c10 740c 3c11 7408 3c22 7404 }
+ $sequence_0 = { 68???????? 68???????? 8d942440020000 68???????? 52 }
+ $sequence_1 = { 83e103 50 f3a4 ffd3 e9???????? 56 e8???????? }
+ $sequence_2 = { 68???????? 8d942440020000 68???????? 52 e8???????? 83c434 }
+ $sequence_3 = { c1f905 8b0c8d60d54000 f644c10401 8d04c1 7403 8b00 }
+ $sequence_4 = { 8d542438 8d842400070000 52 50 }
+ $sequence_5 = { 8d84244c040000 68???????? 50 e8???????? 8d8c2454040000 51 }
+ $sequence_6 = { 8d4c2414 50 51 6a00 6a00 6a00 }
+ $sequence_7 = { 5b 81c440060000 c3 56 57 }
+ $sequence_8 = { 50 51 ffd3 5f 5e 33c0 }
+ $sequence_9 = { 83c418 3bc6 7e0f 5f 5e }
condition:
- 7 of them and filesize <801792
+ 7 of them and filesize <338386
}
-rule MALPEDIA_Win_Petrwrap_Auto : FILE
+rule MALPEDIA_Win_Protonbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "335058f1-6093-5213-b714-ccf692d43a50"
+ id = "b19d2c4d-3d72-5fe6-aaaa-c0b323237a91"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.petrwrap"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.petrwrap_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.protonbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.protonbot_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "3085058da5fe07c21c7301994557a19255100cfc23f593064f4716726b348a1c"
+ logic_hash = "9f42d2358a0490651f249ec756eecbb8cc6207cec8ace7f179285ca0a209261c"
score = 75
quality = 75
tags = "FILE"
@@ -136536,32 +143566,32 @@ rule MALPEDIA_Win_Petrwrap_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f7e9 c1fa02 8bc2 c1e81f 40 03c2 687f010000 }
- $sequence_1 = { 136c2414 894c2428 8b4c246c 896c2420 8d4960 e8???????? 8b4c2440 }
- $sequence_2 = { 50 57 57 c744242400000000 c744242800000000 c744242c00000000 c744243800000000 }
- $sequence_3 = { 8b7c2418 f7c3fcffffff 0f8496000000 897c2420 8d4900 6a00 56 }
- $sequence_4 = { 53 53 896c2448 8844241f 660fd6442454 e8???????? 83c40c }
- $sequence_5 = { 8bca 83d100 01460c 8b442424 83d100 83c310 83ed04 }
- $sequence_6 = { 89460c 8b06 53 55 8b2f 8b7f04 33db }
- $sequence_7 = { 8b7c2444 33fb 237c2434 23cb }
- $sequence_8 = { 897db0 6a00 ff75c8 ff55d8 6a00 6a16 }
- $sequence_9 = { 7f04 8bc5 eb0e 56 55 e8???????? 8b54242c }
+ $sequence_0 = { 0f434550 6a00 6a00 6a00 }
+ $sequence_1 = { 8b36 8d442408 50 56 e8???????? 83c408 83f808 }
+ $sequence_2 = { e8???????? 8d8dd4feffff e8???????? 83c418 c645fc01 }
+ $sequence_3 = { 899df8fffeff e8???????? 83c410 8bf8 }
+ $sequence_4 = { 8bf1 6a04 c745fc01000000 e8???????? 83c404 8bf8 }
+ $sequence_5 = { 837f1410 7202 8b3f 57 50 e8???????? ffb5d4feffff }
+ $sequence_6 = { 7f8d 5e 5f 33c0 5b 8b4dfc }
+ $sequence_7 = { 50 8d45f4 64a300000000 8bda 8bf9 8d8dd8feffff }
+ $sequence_8 = { 8d85b8fbffff 0f4385b8fbffff 50 8d85d0fbffff 68ff000000 50 e8???????? }
+ $sequence_9 = { b901000000 8bc2 c1e81e 33c2 69d06589076c 03d1 89948d54ecffff }
condition:
- 7 of them and filesize <1024000
+ 7 of them and filesize <1073152
}
-rule MALPEDIA_Win_Electricfish_Auto : FILE
+rule MALPEDIA_Win_Fudmodule_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b2332381-c1cc-58e9-8fab-7070fccf8e24"
+ id = "c661ff1b-7299-5697-883f-829f2d507cdf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.electricfish"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.electricfish_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fudmodule"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fudmodule_auto.yar#L1-L171"
license_url = "N/A"
- logic_hash = "1f7cb8b65f3bb65395bc124290e1a31ce340990c85196e747881fa433bd41f37"
+ logic_hash = "18effdd37514264473c04c4c667c18f4f01327ffa64b50ebf53a4b08029b6c60"
score = 75
quality = 75
tags = "FILE"
@@ -136575,32 +143605,38 @@ rule MALPEDIA_Win_Electricfish_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83c404 85c0 0f84e3fdffff 8b442410 6a00 50 }
- $sequence_1 = { e8???????? 8bd8 83c404 85db 7523 683e010000 68???????? }
- $sequence_2 = { c3 8b5104 57 6a77 68???????? 8910 8b39 }
- $sequence_3 = { 8b442408 6855090000 68???????? 6a41 6896010000 6a14 c70050000000 }
- $sequence_4 = { e8???????? 83c418 85c0 0f8fd7faffff 5f 5e 5d }
- $sequence_5 = { 8945c4 8945c8 8945cc 8945d0 89a540ffffff 6aff 894110 }
- $sequence_6 = { 689b010000 68???????? 6a08 e8???????? 83c40c 85c0 751f }
- $sequence_7 = { 51 55 e8???????? 83c408 3bc3 7504 6a6e }
- $sequence_8 = { c3 57 56 e8???????? 83c408 6893000000 68???????? }
- $sequence_9 = { 0fb74550 c7459418001800 c7459848000000 84db 7402 03c0 0fb74d18 }
+ $sequence_0 = { 0f99c4 660fc8 f6d4 58 e9???????? e9???????? 660fbae405 }
+ $sequence_1 = { 66d3d3 f7db f6d3 4883c420 }
+ $sequence_2 = { e9???????? 0fb78120010000 b9b01d0000 663bc1 76e3 b97d4f0000 }
+ $sequence_3 = { d3d8 31d2 0c5b 89d0 }
+ $sequence_4 = { 498b8c24d8090000 e8???????? 498b8c24e0090000 e8???????? 4983bc24d809000000 488bb42480000000 488b5c2478 }
+ $sequence_5 = { 488d45af 41b908000000 4d8bc5 4889442420 ff96d00d0000 }
+ $sequence_6 = { 0f855b73ffff 66d3fe 80fbfc 09e6 89f9 6681c69719 }
+ $sequence_7 = { 41ffc1 453bc8 7e27 b818000000 8bc8 }
+ $sequence_8 = { 55 57 4154 488dac2400feffff 4881ec00030000 488b05???????? 4833c4 }
+ $sequence_9 = { 210a dd63c2 58 5f }
+ $sequence_10 = { 85c0 755f 488b4c2470 e8???????? 448b86b40c0000 }
+ $sequence_11 = { 0facea1a 56 660fbdf4 0fc1ca 488b5510 d2e5 }
+ $sequence_12 = { f9 81fd658b2961 83c101 84c0 660fbae005 d2fb }
+ $sequence_13 = { 66d3f3 0fcf 8b3e 6681feaa7e 00ef 18cb }
+ $sequence_14 = { 48ff25???????? 4889742410 55 57 4154 488bec 4883ec60 }
+ $sequence_15 = { ff96d00d0000 4c8b5d97 4d3bdc 75c8 }
condition:
- 7 of them and filesize <3162112
+ 7 of them and filesize <795648
}
-rule MALPEDIA_Win_Unidentified_069_Auto : FILE
+rule MALPEDIA_Win_Romeos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "26eb5c23-2d98-5320-b3d2-36b6e8a74eb7"
+ id = "0156645c-05e4-5c43-9143-7d272fa7b808"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_069"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_069_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.romeos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.romeos_auto.yar#L1-L178"
license_url = "N/A"
- logic_hash = "c4b44dbf77c8a02d5a553e1bfca3c92784cdebd7456417ad5b23ba2172632d6b"
+ logic_hash = "c5549ec98f2ed02ef2ebca3bfe2dbd57b9e8c34679be2e9e834dd93b596fc1fe"
score = 75
quality = 75
tags = "FILE"
@@ -136614,32 +143650,38 @@ rule MALPEDIA_Win_Unidentified_069_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd3 33c0 5f 5b c9 c20400 55 }
- $sequence_1 = { 8bc6 c1e710 e8???????? 0fb7c0 0bc7 8945cc }
- $sequence_2 = { ff15???????? 8b3d???????? 8945f0 3bc6 7460 53 }
- $sequence_3 = { 85c0 7520 ff7508 e8???????? 85c0 7414 ff7508 }
- $sequence_4 = { 68???????? 891d???????? 891d???????? ffd6 8b35???????? 68???????? ffd6 }
- $sequence_5 = { 84c0 7504 c645fa01 807dfbff 6a08 5b 0f8581000000 }
- $sequence_6 = { 52 51 50 e8???????? 015608 837de000 8b4608 }
- $sequence_7 = { 7447 8d85c8fdffff 50 e8???????? 6811270000 56 }
- $sequence_8 = { 83e924 85ff 77f3 3bf8 7427 85ff 750e }
- $sequence_9 = { 837d0800 0f85a0000000 e8???????? 8bf0 85f6 0f8491000000 }
+ $sequence_0 = { 750a 5e 33c0 5b 83c408 c20c00 8b06 }
+ $sequence_1 = { bd30000000 33db 85ed 7e0e e8???????? 88441c18 43 }
+ $sequence_2 = { 6a16 8d4c244c 6800200000 51 57 }
+ $sequence_3 = { 83ec08 53 56 8b742418 8bd9 85f6 750a }
+ $sequence_4 = { 5f 5e 5d 5b 81c438200000 c20400 }
+ $sequence_5 = { 8b542408 668902 b001 c3 668b4801 40 51 }
+ $sequence_6 = { 85db 751d 807c244802 0f85e0000000 8d542414 8d442448 }
+ $sequence_7 = { 6a16 8d44244c 52 50 }
+ $sequence_8 = { 68bb010000 8b39 50 ff15???????? 8b8e20030000 50 53 }
+ $sequence_9 = { e8???????? 8bf0 eb02 33f6 53 6800040000 8d4c243c }
+ $sequence_10 = { 50 8bce e8???????? 8d8c2490010000 51 }
+ $sequence_11 = { 81c428010000 c3 5f 5e 5d 83c8ff 5b }
+ $sequence_12 = { 8bf1 57 b940000000 33c0 8d7c2415 c644241400 c744240800000000 }
+ $sequence_13 = { 895c2440 895c2434 895c2438 ff15???????? }
+ $sequence_14 = { 8b442410 85c0 7408 66837c241400 7510 47 }
+ $sequence_15 = { 8b3a eb0d 8b8e20030000 68bb010000 }
condition:
- 7 of them and filesize <434176
+ 7 of them and filesize <294912
}
-rule MALPEDIA_Win_Radrat_Auto : FILE
+rule MALPEDIA_Win_Koobface_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f52e2c5a-eef0-5772-ac88-55315ac8b12c"
+ id = "1ce15537-cef6-5c0e-a9d8-b5edfbbc6020"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.radrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.radrat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.koobface"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.koobface_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "a27dfe470245e6a0fc8e1e694300b8057fe423adc6b34415045732f4d66a4882"
+ logic_hash = "b6b79af3be74d0a2238bfa51c4162b8333d68f5a5fb85b02563c06855a5cb17a"
score = 75
quality = 75
tags = "FILE"
@@ -136653,32 +143695,32 @@ rule MALPEDIA_Win_Radrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8d1cffffff e8???????? c685f0feffff00 c645fc00 8d4dcc e8???????? c745fcffffffff }
- $sequence_1 = { c6855497ffff01 c645fc01 8d8d58ffffff e8???????? c745fcffffffff 8d4d80 e8???????? }
- $sequence_2 = { 8d8d74ffffff e8???????? 68a0000000 8d8d74ffffff e8???????? 6a30 8d8d74ffffff }
- $sequence_3 = { ff15???????? 8b4df4 894168 8b45f4 837868ff 750d ff15???????? }
- $sequence_4 = { 8d8dd8feffff e8???????? 8d8d0cffffff 51 8d55c4 52 8b45ec }
- $sequence_5 = { e8???????? 8a854c98ffff e9???????? 8b8d24d6ffff 83c15c 51 8b9524d6ffff }
- $sequence_6 = { 8d8d50ffffff 51 e8???????? 83c408 8b9548ffffff 83c258 52 }
- $sequence_7 = { e9???????? 8d4d9c e8???????? c645fc01 8d8d38ffffff 51 8d4d9c }
- $sequence_8 = { 8b4dd8 8b9130010000 52 ff15???????? 8b45d8 c7803001000000000000 8b4dd8 }
- $sequence_9 = { 8d8560fbffff 50 8d8da8fdffff e8???????? 89854cf8ffff 8b8d4cf8ffff 898d48f8ffff }
+ $sequence_0 = { 8d850cffffff 50 c745fc26000000 e8???????? 834dfcff 53 }
+ $sequence_1 = { e8???????? 33db 59 889dfaf7ffff 889dfbf7ffff 899decf7ffff 899de0f7ffff }
+ $sequence_2 = { 83bd34c1ffff0a 754c 8d8540c1ffff 6a41 50 }
+ $sequence_3 = { 50 c745cc5cd74100 e8???????? 8b7508 bf63736de0 393e 0f85a5010000 }
+ $sequence_4 = { e8???????? 50 8d8538f4ffff 50 e8???????? 8b8520f4ffff 59 }
+ $sequence_5 = { e8???????? 8b8598faffff c1e803 50 8d85a4faffff 57 50 }
+ $sequence_6 = { 8d8528ffffff 68???????? 50 e8???????? 83c40c 8d8528ffffff 50 }
+ $sequence_7 = { 8d8528ffffff 50 e8???????? 68???????? 8d850857ffff }
+ $sequence_8 = { 8d4de4 51 53 ff90e0000000 837de404 7407 }
+ $sequence_9 = { 68???????? e8???????? 59 57 e8???????? 59 8b4dfc }
condition:
- 7 of them and filesize <2080768
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Roopy_Auto : FILE
+rule MALPEDIA_Win_Htran_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "18fd31da-7cad-5b5e-9e3e-b0b112556109"
+ id = "640e7099-e79d-52c5-9d59-7736988066fb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.roopy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.roopy_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.htran"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.htran_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "6efa923735d84ae0bbc14d021be45ac1298053ce08c8f542f6e92d8a3dac3a28"
+ logic_hash = "572147b50538386d2f3141669299b284d93907b072e98ae962e15d37b04a8bad"
score = 75
quality = 75
tags = "FILE"
@@ -136692,32 +143734,32 @@ rule MALPEDIA_Win_Roopy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d45d8 30c9 6631d2 e8???????? 6a00 8b45ec 8945c0 }
- $sequence_1 = { 89e5 8da42478fdffff 53 56 8945fc }
- $sequence_2 = { 68???????? 64ff30 648920 8d431c 8b55fc e8???????? 89d8 }
- $sequence_3 = { 85db 7403 8b40fc 3d04010000 0f8e91000000 89da }
- $sequence_4 = { e9???????? 8d8decfeffff 8d95a0fcffff b810010000 e8???????? e8???????? }
- $sequence_5 = { c745f800000000 c7859cfeffff00000000 c78598feffff00000000 c78594feffff00000000 c78578fdffff00000000 c7857cfdffff00000000 c78580fdffff00000000 }
- $sequence_6 = { e8???????? 6a00 a1???????? 8945d8 }
- $sequence_7 = { 30d2 e8???????? 6a00 8d45e4 e8???????? 6a00 a1???????? }
- $sequence_8 = { e8???????? 8d8d8cfcffff 6631d2 8d8570fbffff e8???????? 8d858cfcffff 30c9 }
- $sequence_9 = { 8b45dc 8d70ff f745e401000000 740d f745dcffffffff 0f856fffffff 8b45f0 }
+ $sequence_0 = { 6a00 8d8434f0a20000 55 50 53 }
+ $sequence_1 = { 8bc8 83e103 f3a4 8b4c2462 }
+ $sequence_2 = { 83c408 a1???????? 85c0 7405 }
+ $sequence_3 = { 50 51 ffd3 85c0 7d28 bf???????? 83c9ff }
+ $sequence_4 = { ffd5 8bf8 8b442440 50 ff15???????? 50 53 }
+ $sequence_5 = { 8b8424e0420100 33c9 894c2414 53 8b10 }
+ $sequence_6 = { 8816 46 eb0f 0fb6d2 f682c1c3400004 }
+ $sequence_7 = { 89442410 c705????????03000000 8b442410 8b0d???????? 49 743a }
+ $sequence_8 = { c20400 8b542404 8b0d???????? 3915???????? 56 b8???????? }
+ $sequence_9 = { 899424e8010000 89b424e8000000 899424e4000000 33c0 8d8c24e8000000 }
condition:
- 7 of them and filesize <739328
+ 7 of them and filesize <114688
}
-rule MALPEDIA_Win_Herpes_Auto : FILE
+rule MALPEDIA_Win_Unidentified_078_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "81a5deba-39e3-5a1f-937c-6696c1e1bbb2"
+ id = "de8cdecb-4380-57eb-b923-e2ba443932e2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.herpes"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.herpes_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_078"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_078_auto.yar#L1-L110"
license_url = "N/A"
- logic_hash = "e0891dbd163cc34c7d236958d6844c054a085f2a34f7c0d3c53aa2f138d5b650"
+ logic_hash = "d08e32bbc4aa8e2920b084e5d720f452f9f589f09a38ee6e42b2e5fd17bef5f8"
score = 75
quality = 75
tags = "FILE"
@@ -136731,34 +143773,34 @@ rule MALPEDIA_Win_Herpes_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7303 8d4570 ffb580000000 50 8b45f0 03c7 }
- $sequence_1 = { 8d9424380d0000 52 ffd6 eb30 6a38 8d4c241c 51 }
- $sequence_2 = { 68???????? eb05 68???????? 56 ffd7 bb05000000 399d64ffffff }
- $sequence_3 = { 68???????? 89869c010000 ffb604020000 ffd7 68???????? }
- $sequence_4 = { 64a300000000 b80f000000 33ff 8985e4feffff 89bde0feffff }
- $sequence_5 = { 57 ff15???????? 5f 8b4dfc 33cd e8???????? }
- $sequence_6 = { ff15???????? 85c0 742a 8b959cfdffff 52 e8???????? }
- $sequence_7 = { 39bdd4fcffff 7302 8bc3 83ec1c 8bf4 }
- $sequence_8 = { 52 ffd6 68???????? 8d858ffeffff 50 }
- $sequence_9 = { 52 6a00 89bde0fcffff ff15???????? 85c0 745e 8d85e4fcffff }
+ $sequence_0 = { 7d21 8a440b10 3c5c 7419 }
+ $sequence_1 = { e8???????? 84c0 7467 f60701 }
+ $sequence_2 = { e9???????? 80fa5b 7f3c 80fa28 0f8d94010000 }
+ $sequence_3 = { 80fa0d 0f8421010000 80fa1b 0f8576010000 ba02000000 e8???????? }
+ $sequence_4 = { 80fa7e 0f8f02010000 e9???????? ba02000000 }
+ $sequence_5 = { b901010000 ff15???????? 85c0 740e e8???????? }
+ $sequence_6 = { 0f8cee000000 80fa0d 0f8421010000 80fa1b 0f8576010000 }
+ $sequence_7 = { 0f8f18010000 80fa23 0f8d82010000 ba02000000 }
+ $sequence_8 = { 753f a900004011 7521 a900000600 }
+ $sequence_9 = { 0f8d94010000 80fa26 0f8f18010000 80fa23 0f8d82010000 }
condition:
- 7 of them and filesize <319488
+ 7 of them and filesize <688128
}
-rule MALPEDIA_Win_Atmitch_Auto : FILE
+rule MALPEDIA_Win_Spedear_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5a61b640-3c5c-5518-8891-5d83a0b89c2d"
+ id = "064ca511-db37-50e7-a5f5-98bdd145296d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atmitch"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atmitch_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spedear"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spedear_auto.yar#L1-L246"
license_url = "N/A"
- logic_hash = "565ce987fa9e005b7e196a8bfd57c4f682eb318d752a50049029192ea9e40f26"
+ logic_hash = "3ab20c94a066f6f4783dff8cb4bf09780239780b3bd9f55c80bdf4166aa7a997"
score = 75
- quality = 75
+ quality = 71
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -136770,32 +143812,48 @@ rule MALPEDIA_Win_Atmitch_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c644244803 ff15???????? 8d4c2418 51 68???????? }
- $sequence_1 = { 33c4 89842410020000 56 51 8bcc }
- $sequence_2 = { 8bfe f7df 896c241c 0fb744242c 50 51 }
- $sequence_3 = { 51 833d????????00 7422 a1???????? 50 }
- $sequence_4 = { ff15???????? e8???????? 8b0e 8b5138 83c408 }
- $sequence_5 = { c744241c00000000 b8???????? c60000 83c004 3d???????? 7cf3 68???????? }
- $sequence_6 = { 8bcc 89642410 68???????? ff15???????? e8???????? 0fb705???????? 83c408 }
- $sequence_7 = { ff15???????? 83bc24fc00000000 7432 8b4c2408 8b41f4 }
- $sequence_8 = { c644244803 ff15???????? 8d4c2418 51 68???????? 8d542428 52 }
- $sequence_9 = { 83c404 50 ff15???????? 50 51 }
+ $sequence_0 = { 83e207 03c2 c1f803 83c40c }
+ $sequence_1 = { 8b4718 8a5f06 50 894608 e8???????? }
+ $sequence_2 = { 53 50 e8???????? 8b7e0c 895e10 }
+ $sequence_3 = { 894618 ffd7 89461c 5f }
+ $sequence_4 = { 33f6 8b4704 8b4f08 53 50 8bde e8???????? }
+ $sequence_5 = { 8b44240c 8b08 8b442410 53 55 }
+ $sequence_6 = { c1e208 40 0bca 3bc3 7c02 }
+ $sequence_7 = { 5b c20400 8b4c240c 57 53 51 }
+ $sequence_8 = { 6a00 68???????? e8???????? 83c40c 68d0070000 }
+ $sequence_9 = { 833e00 741e 8b5608 8b4604 6a00 }
+ $sequence_10 = { 833e00 741a 6a00 6a00 ff7608 }
+ $sequence_11 = { 6a00 ff7608 ff5604 6800800000 }
+ $sequence_12 = { 394878 7456 39487c 7451 }
+ $sequence_13 = { 8bc7 5e 5f 5b 5d c3 6a08 }
+ $sequence_14 = { ff5604 6800800000 6a00 ff7608 }
+ $sequence_15 = { 74ce 56 53 ff7510 ff75d8 6a00 6a00 }
+ $sequence_16 = { 4154 4883ec20 4c8b5120 4d8be0 488bea 410fb74206 488bf1 }
+ $sequence_17 = { 418d5001 488bcf 4803c7 48894308 }
+ $sequence_18 = { 50 8d4de0 e8???????? 83781410 59 5b 7202 }
+ $sequence_19 = { 750b 488bcf ff15???????? eb07 488bd5 }
+ $sequence_20 = { 488bc3 488d152bd50000 48c1f805 83e11f 488b04c2 486bc958 }
+ $sequence_21 = { 723a 488d05349b0000 483bd8 772e }
+ $sequence_22 = { 488364242000 40886c245c 488d0d10d10000 4c8d4c244c }
+ $sequence_23 = { 8a80b4182400 08443b1d 0fb64601 47 3bf8 76ea }
+ $sequence_24 = { 4883ec20 488d05fe690000 488bfa 488bd9 488901 }
+ $sequence_25 = { 488d15032e0000 488bce 488905???????? ff15???????? }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Lightwork_Auto : FILE
+rule MALPEDIA_Win_Lowzero_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c390e16c-2dcc-559e-9fd3-76f19a07f767"
+ id = "ad1f4f71-db5d-51c4-9bc5-e40c45051891"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lightwork"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lightwork_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lowzero"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lowzero_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "61817aa90179df111fa397aa30e99207b20a485779bb2cd0f0c3ecbb28869217"
+ logic_hash = "bfaa131f289b03263fe3207c7e09eedb0c528831bcdb16b693a70fc486a7a935"
score = 75
quality = 75
tags = "FILE"
@@ -136809,32 +143867,32 @@ rule MALPEDIA_Win_Lightwork_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb7442462 89442404 8b442464 890424 e8???????? }
- $sequence_1 = { c3 55 89e5 83ec38 8b4508 83c07c 8945f0 }
- $sequence_2 = { e8???????? 894508 837d0800 740b 8b4508 890424 }
- $sequence_3 = { c645f700 807df700 0f85b1feffff 8b45ec 890424 e8???????? 8b45f0 }
- $sequence_4 = { c9 c3 55 89e5 83ec28 c7042408000000 e8???????? }
- $sequence_5 = { 8b4014 83c003 8945f4 8b450c }
- $sequence_6 = { 894508 837d0800 741e 8b4508 890424 e8???????? }
- $sequence_7 = { 8b45f8 83c002 01d0 0fb600 0fb6c0 c1e010 0145fc }
- $sequence_8 = { e8???????? 8b4508 c780a401000000000000 90 c9 c3 55 }
- $sequence_9 = { 894508 837d0800 740b 8b4508 890424 e8???????? 8b4508 }
+ $sequence_0 = { 0fb617 47 83fa20 0f83e2000000 42 8d0432 3bc1 }
+ $sequence_1 = { 57 8b423c 8b55f4 03c6 }
+ $sequence_2 = { 2bce 894df0 8d9b00000000 8d1c31 ff7734 85c0 }
+ $sequence_3 = { 7439 03c3 837f1400 7425 }
+ $sequence_4 = { 47 2bc8 8d4602 03c3 3b450c }
+ $sequence_5 = { 8b4d0c 3b7dfc 0f8255feffff 2b7508 5f 8bc6 5e }
+ $sequence_6 = { 8bce 83e21f c1eb05 c1e208 2bca 49 83fb07 }
+ $sequence_7 = { 83ec30 53 56 8bd9 8955f4 33f6 895dfc }
+ $sequence_8 = { 46 47 e9???????? 8bda 8bce 83e21f }
+ $sequence_9 = { e8???????? 5f 5e 5b c70007000000 33c0 8be5 }
condition:
- 7 of them and filesize <1132544
+ 7 of them and filesize <433152
}
-rule MALPEDIA_Win_Lock_Pos_Auto : FILE
+rule MALPEDIA_Win_Ratel_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d847ae83-76cd-5967-803e-bdb0585a6606"
+ id = "0998b123-774e-59b1-8ca2-1a95e1fb9bf7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lock_pos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lock_pos_auto.yar#L1-L140"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ratel"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ratel_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "36f811da9c497d4d7cb3a11de01255e73f7c0aa2aa971faa2dbafeeb60cefda6"
+ logic_hash = "32361790b47e0503007c9763001c72d5f3f0666a6e89a8bab7c3bc0bd295eb6a"
score = 75
quality = 75
tags = "FILE"
@@ -136848,35 +143906,32 @@ rule MALPEDIA_Win_Lock_Pos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bec 8b4508 8b0d???????? 8b0481 }
- $sequence_1 = { 55 8bec 837d0800 7704 }
- $sequence_2 = { 55 8bec 81eca4040000 56 }
- $sequence_3 = { 8d85f8fdffff 50 6a00 6a00 6a23 6a00 ff15???????? }
- $sequence_4 = { 0fb64dfb 85c9 741c 8b5514 8b45fc }
- $sequence_5 = { 2bc8 c745fc04000000 8a1401 8810 40 }
- $sequence_6 = { 8b55f8 8b4508 8910 8b45c4 }
- $sequence_7 = { 3bc6 0f85a1000000 32db e8???????? 84db }
- $sequence_8 = { 8b55fc 8b450c 0fb70c50 334d14 }
- $sequence_9 = { 33c9 84c0 0f95c1 41 51 ff75e4 }
- $sequence_10 = { 894dfc 8b55dc 83c201 8955dc ebd2 8b45f8 }
- $sequence_11 = { e8???????? 83c408 8d9568ffffff 52 e8???????? 83c404 50 }
- $sequence_12 = { 50 eb4b 8b45f8 3bc3 764e 03c7 }
+ $sequence_0 = { 89d9 e8???????? 85c0 75e7 89d9 e8???????? 89d9 }
+ $sequence_1 = { a1???????? 85c0 0f85bb010000 8b41fc 8d50ff 8951fc }
+ $sequence_2 = { 8b442454 8b542414 8b400c 85d2 0f851f040000 83f802 }
+ $sequence_3 = { 8bbc24b0000000 e8???????? 8b00 c744245cffffffff c7442460ffffffff 89442428 8b8424a4000000 }
+ $sequence_4 = { 0f83a3020000 0fb700 6683f8ff b800000000 0f4545ac 8945ac b800000000 }
+ $sequence_5 = { 668993f0000000 c783f400000000000000 c783f800000000000000 c783fc00000000000000 c7830001000000000000 c703???????? c7437c98ce4b00 }
+ $sequence_6 = { c703???????? c7437884124c00 e8???????? 89b3f0000000 83ec04 8d65f4 5b }
+ $sequence_7 = { 0f9fc1 084dc9 8b4d08 8345cc01 8b4108 3b410c 0f8240ffffff }
+ $sequence_8 = { 8b4340 c7431400000000 c7431000000000 0fb67b58 894304 894308 89430c }
+ $sequence_9 = { 8d4304 89c1 89c6 e8???????? 89b3ec000000 83ec04 8d65f4 }
condition:
- 7 of them and filesize <319488
+ 7 of them and filesize <2174976
}
-rule MALPEDIA_Win_Scarabey_Auto : FILE
+rule MALPEDIA_Win_Miuref_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "32f7c136-d07c-5221-8524-163d31e0f9ce"
+ id = "34f2a1cb-9745-52c8-a75d-06d5cdb25bcd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scarabey"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.scarabey_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miuref"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.miuref_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "1ba8f19bbb29b54a80b4850f75f9b4dbbfff504fea1a8a75cc950df78ae9916b"
+ logic_hash = "0abc04edb362ffc2e411d61d44a4ba6937064194bb7ee145b0929a61d91bcae4"
score = 75
quality = 75
tags = "FILE"
@@ -136890,32 +143945,32 @@ rule MALPEDIA_Win_Scarabey_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bf0 85f6 7478 8b8dfcd6ffff 8b95f4d6ffff 8d85fcd6ffff 50 }
- $sequence_1 = { e8???????? c745fcffffffff 8b06 8b7e04 2bf8 85c0 7409 }
- $sequence_2 = { 51 52 ffd3 6a40 6800300000 }
- $sequence_3 = { ff15???????? 56 ff15???????? a1???????? 33f6 56 }
- $sequence_4 = { ba12000000 8d0dd0ad5700 e9???????? db2d???????? d9c9 d9f5 9b }
- $sequence_5 = { 7d04 8944241c 686666aa00 50 33db 6a02 895c2450 }
- $sequence_6 = { 8bc8 8b8524d7ffff 83c005 8d14c500000000 2bd0 a1???????? 03ca }
- $sequence_7 = { e8???????? 8b4d08 8b83d40c0000 8bf0 83f907 7771 ff248d690c4700 }
- $sequence_8 = { eb4c 8d4c2404 68???????? 51 e8???????? 83c408 84c0 }
- $sequence_9 = { c744240808000000 c744240cff000000 ff15???????? 8bce e8???????? 6a00 e8???????? }
+ $sequence_0 = { 59 59 8945fc 85f6 760e 803c072e 7418 }
+ $sequence_1 = { ff15???????? 50 e8???????? ff750c 8906 50 e8???????? }
+ $sequence_2 = { 8bf0 8d7df0 a5 a5 a5 83c418 a5 }
+ $sequence_3 = { 6a02 ff35???????? e8???????? 8bf0 83c40c 85f6 7412 }
+ $sequence_4 = { 8d8300010000 ff75fc 50 e8???????? 68???????? 8d45f8 50 }
+ $sequence_5 = { 8b4124 83f801 7514 ff7514 ff7510 ff750c }
+ $sequence_6 = { 7509 0fb74e06 663bcf 7507 33c0 e9???????? }
+ $sequence_7 = { e8???????? 50 ff35???????? e8???????? 83c43c e9???????? 55 }
+ $sequence_8 = { 8d45d8 50 a5 e8???????? 83c408 8bf0 8bfc }
+ $sequence_9 = { 53 53 ff15???????? 50 a3???????? e8???????? 59 }
condition:
- 7 of them and filesize <3580928
+ 7 of them and filesize <180224
}
-rule MALPEDIA_Win_Powerloader_Auto : FILE
+rule MALPEDIA_Win_Unidentified_091_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7f4f5f46-fc37-546a-a6e8-709a0ba38743"
+ id = "8c2d9d9b-cb98-5dfc-90ce-01312105d94f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.powerloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.powerloader_auto.yar#L1-L108"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_091"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_091_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "793f3dbd327274c0d84943d43e404acbb8cb72be0435ee1a3f9e0ada37088a0f"
+ logic_hash = "5f25d4d54583311a39cbead5d516e9dd7eb57b96b31eb59a9b18d068eb7148c5"
score = 75
quality = 75
tags = "FILE"
@@ -136929,32 +143984,32 @@ rule MALPEDIA_Win_Powerloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? eb22 33c9 66666666660f1f840000000000 0fb6840c30010000 }
- $sequence_1 = { 8bf2 32db e8???????? 3bc7 7349 }
- $sequence_2 = { e8???????? 0fb6d8 84c0 7514 }
- $sequence_3 = { e8???????? 0fb6d8 84c0 7514 ff15???????? }
- $sequence_4 = { 33d2 c605????????00 e8???????? 0fb6c3 }
- $sequence_5 = { 32db e8???????? 3bc7 7349 }
- $sequence_6 = { e8???????? eb22 33c9 66666666660f1f840000000000 }
- $sequence_7 = { e8???????? 8b7c2430 85ed 740d }
- $sequence_8 = { ff15???????? 83f81f 7323 ff15???????? }
- $sequence_9 = { ff15???????? 83f803 7405 83f802 7530 }
+ $sequence_0 = { e8???????? c744244801000000 488d4c2460 48895c2440 4c8d8734030000 48894c2438 4c8d0ddf721400 }
+ $sequence_1 = { e8???????? 482be0 8b3a 488bd9 8b89d4050000 488bf2 85c9 }
+ $sequence_2 = { e9???????? 488d8ab00e0000 e9???????? 488d8ad00e0000 e9???????? 488d8af00e0000 e9???????? }
+ $sequence_3 = { 89742420 498b06 48634804 33d2 4a89543128 eb41 488b01 }
+ $sequence_4 = { eb6f 4c8b5048 4d85d2 7514 c74424207a020000 418d527c 41b884000000 }
+ $sequence_5 = { 742e c7814007000000000000 488d15b7081400 488b8938060000 41b895030000 e8???????? 48c7833806000000000000 }
+ $sequence_6 = { eb0f 488bd3 488d0dabf12500 e8???????? 488b85d0010000 48634804 488d0524fe2500 }
+ $sequence_7 = { e8???????? 90 488bcb e8???????? 85c0 7525 488b4c2438 }
+ $sequence_8 = { ffc3 e8???????? 3bd8 7cc6 41f6c708 0f85d0000000 4c8d058d0c1100 }
+ $sequence_9 = { eb03 890c90 8b4df3 48ffc2 4983c002 483bd1 72db }
condition:
- 7 of them and filesize <155648
+ 7 of them and filesize <5777408
}
-rule MALPEDIA_Win_M0Yv_Auto : FILE
+rule MALPEDIA_Win_Ripper_Atm_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "13583ad1-2b04-58e4-9f81-2e107221c7c3"
+ id = "a163a628-88ff-5ee3-8ab0-3e7869e5ed11"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.m0yv"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.m0yv_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ripper_atm"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ripper_atm_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "885921d8c153e05a9fb6cddfe964abb6a41c6e3fc24a745c88fdae391a38b5ef"
+ logic_hash = "30a8a446c0211fbfa8563685de5143789e29b7c89e693b370c3a643209d252a9"
score = 75
quality = 75
tags = "FILE"
@@ -136968,32 +144023,32 @@ rule MALPEDIA_Win_M0Yv_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 490faff8 4d89c3 4901ff 4c8b1424 490fafd2 48039424b8000000 4c89ef }
- $sequence_1 = { 72e7 4889f9 4889da e8???????? 48c7474800000000 31c0 6690 }
- $sequence_2 = { f6c201 0f84e3000000 4183fb66 775c 744e }
- $sequence_3 = { 4889fa e8???????? 4889f9 4889fa e8???????? 4c89f1 }
- $sequence_4 = { 29e8 488bac24a8000000 894500 895504 44895d08 }
- $sequence_5 = { 490fafc6 4801c2 4889942440010000 4c89842488000000 4c89c0 480fafc1 }
- $sequence_6 = { 4f037ce538 4c21df 4c31d7 4e03bce498000000 4831c1 4901ff 4c89c8 }
- $sequence_7 = { 2b6a24 448901 44894904 44895108 4489590c 44897110 897114 }
- $sequence_8 = { 4883ec28 e8???????? 4885c0 7409 488b4010 }
- $sequence_9 = { c1e802 4122c2 41884041 8bc2 83e003 8a0481 498bc8 }
+ $sequence_0 = { 8b7d08 2175fc 397714 7e2a ff770c 8b33 8bcb }
+ $sequence_1 = { 0f434dd8 837dd408 8d5598 52 8d9550ffffff 52 }
+ $sequence_2 = { 3938 8b45ec 7408 8b4de8 3b4810 7327 8b4e08 }
+ $sequence_3 = { 6a0f 50 ff15???????? 85c0 7402 32c0 c20800 }
+ $sequence_4 = { 8b02 6a04 8b4804 03ca e8???????? }
+ $sequence_5 = { 6a1c e8???????? 59 85c0 7420 33c9 c7400410000000 }
+ $sequence_6 = { c1f805 83e21f 8b0c85f0974400 c1e206 8a441124 3245fe 247f }
+ $sequence_7 = { 51 8d55c8 8d4d8c e8???????? 83c410 84c0 7445 }
+ $sequence_8 = { 8bf9 50 e8???????? ff7518 8d45ec ff7514 8bcf }
+ $sequence_9 = { 03f0 8b442424 2bc1 99 f77c2418 47 3bf8 }
condition:
- 7 of them and filesize <779264
+ 7 of them and filesize <724992
}
-rule MALPEDIA_Win_Romcom_Rat_Auto : FILE
+rule MALPEDIA_Win_Unidentified_003_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "38f54401-b8aa-5a45-84bf-23c46fbb1d9b"
+ id = "078af5cf-1960-57c1-ad2f-834d23801cf0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.romcom_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.romcom_rat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_003"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_003_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "0162bd825b9587687f6d0e11e69966dd0894464ab2922749a2bae5afcccbf5b8"
+ logic_hash = "44e97183e244c5496d21c90ef879a2c3ae0327847947e2b5ee30ab46305a46ce"
score = 75
quality = 75
tags = "FILE"
@@ -137007,32 +144062,32 @@ rule MALPEDIA_Win_Romcom_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b910000000 e8???????? 488945a0 4885c0 7410 44897008 488d0d6fc20400 }
- $sequence_1 = { d3e8 49895108 418901 49895110 0fb60a 83e10f 4a0fbe8401a0ac0600 }
- $sequence_2 = { 488d95e0310000 488d4dc0 e8???????? 448bc6 33d2 488d8de0310000 e8???????? }
- $sequence_3 = { 488b01 488b4030 ff15???????? 83f8ff 7406 41884709 eb03 }
- $sequence_4 = { 482bc1 4883c0f8 4883f81f 0f877d030000 e8???????? 488d4580 48837d9808 }
- $sequence_5 = { 8a4709 3a4508 744b 84c9 7542 488b0f 4885c9 }
- $sequence_6 = { 488d0dbac50400 488908 eb03 498bc6 4c8bc3 488bd0 488bcf }
- $sequence_7 = { eb04 4d895d00 b801000000 41884508 488b542468 eb05 b801000000 }
- $sequence_8 = { f20f10fc f20f58cc f20f10d1 f20f10c1 4c8d0d39090300 f20f101d???????? f20f100d???????? }
- $sequence_9 = { 7510 488d0d12c90500 e8???????? 85c0 742e 32c0 eb33 }
+ $sequence_0 = { 8945ec a1???????? 0fb7506f 0fb7406d c1e210 0bd0 }
+ $sequence_1 = { c68564ffffff01 33c0 8a88c2100900 888c0566ffffff 40 }
+ $sequence_2 = { e8???????? 83c40c 8b07 5d c3 55 8bec }
+ $sequence_3 = { a1???????? ff75f0 ff7028 ff15???????? eb0a }
+ $sequence_4 = { 395da0 740f ff75a4 ff15???????? 895da0 }
+ $sequence_5 = { 3bfe 7502 8bfb 39742410 }
+ $sequence_6 = { 59 85c0 7417 47 81c614010000 3b3d???????? 72c8 }
+ $sequence_7 = { 8bec 81ec20080000 53 56 57 8d85e0fdffff 8945ec }
+ $sequence_8 = { 7575 385d6e 743b 39bd5cffffff 750a c705????????07000000 399d5cffffff }
+ $sequence_9 = { ff15???????? 85c0 0f88b4010000 8b45e4 3bc3 0f84a9010000 8b08 }
condition:
- 7 of them and filesize <1211392
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Sidewalk_Auto : FILE
+rule MALPEDIA_Win_Coronavirus_Ransomware_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "14b78b08-c08d-56d8-91d9-454c97efb0a9"
+ id = "855b633b-3844-51b6-884b-ae39212160b9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sidewalk"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sidewalk_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.coronavirus_ransomware"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.coronavirus_ransomware_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "db7fd110ccdf76bd73169627fa283b7d029f717432de6e469dcea6c6c2ec5ed7"
+ logic_hash = "cdd2b8f03fb9e73cf8c1c825b178f3065340bed6f25c08a712318c114ae54239"
score = 75
quality = 75
tags = "FILE"
@@ -137046,35 +144101,32 @@ rule MALPEDIA_Win_Sidewalk_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4403e8 4133db 418bcd c1c307 }
- $sequence_1 = { 0bc8 41890c10 488d5204 4983e901 75d4 }
- $sequence_2 = { 33c3 c1c207 c1c00c 4403c8 4533d1 }
- $sequence_3 = { 488b05???????? 83780c00 7405 e8???????? }
- $sequence_4 = { 488d040a 483bc6 7ce2 4883c640 }
- $sequence_5 = { 8bc2 33c6 c1c010 4403d8 4133db }
- $sequence_6 = { 750e 488bcf ff15???????? 4885c0 }
- $sequence_7 = { c1c610 4433f2 c1c710 4403df 41c1c610 4503e6 }
- $sequence_8 = { 41c1c610 4503e6 4403cb 4533d1 4403ee 41c1c210 418bc3 }
- $sequence_9 = { 884202 884a03 4183f810 7ccc }
- $sequence_10 = { 0fb642fe c1e108 0bc8 41890c10 }
- $sequence_11 = { ff15???????? 4885c0 750e 488bcf }
- $sequence_12 = { 8a040f 3201 41880408 48ffc1 }
+ $sequence_0 = { 8d9b00000000 0fb708 66890c02 83c002 6685c9 75f1 8d8dec7effff }
+ $sequence_1 = { 894dd8 837e0400 8b5608 c745dc00000000 8955e0 750a 8b45cc }
+ $sequence_2 = { 50 ff15???????? 85c0 7420 b8???????? e8???????? 50 }
+ $sequence_3 = { 68fe1f0000 52 8d859e9fffff 50 e8???????? 33c9 }
+ $sequence_4 = { 83c002 50 52 68???????? 8d8500c0ffff }
+ $sequence_5 = { 53 e8???????? 83c410 85ff 743b 8d4900 803c1fc3 }
+ $sequence_6 = { ff15???????? 8b15???????? a1???????? 83c418 52 6a01 50 }
+ $sequence_7 = { 8b55d0 880417 8b45c8 50 ff15???????? 56 ff15???????? }
+ $sequence_8 = { ffd6 a3???????? eb0a 53 }
+ $sequence_9 = { ff15???????? 85c0 7407 ffd0 a3???????? be???????? e8???????? }
condition:
- 7 of them and filesize <237568
+ 7 of them and filesize <235520
}
-rule MALPEDIA_Win_Alma_Locker_Auto : FILE
+rule MALPEDIA_Win_Narilam_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a8975e90-f59f-53dc-8c8c-bbe753edcfd3"
+ id = "da9d4048-8edf-5bad-820f-4e60bf8a1167"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alma_locker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alma_locker_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.narilam"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.narilam_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "df780972bf15a2baf7532cad09aa2dd13a5bee9ccc29d4fb62357c0162af8a26"
+ logic_hash = "9c97c97f1983ca4888bd0ceffb3db6cc9301c52fb6e7adafbcc7af03cf7073fe"
score = 75
quality = 75
tags = "FILE"
@@ -137088,32 +144140,32 @@ rule MALPEDIA_Win_Alma_Locker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8d6cfeffff e8???????? 83c404 8d4d8c c645fc07 51 8bd0 }
- $sequence_1 = { 720e ffb5ccfeffff e8???????? 83c404 837da008 720b ff758c }
- $sequence_2 = { 0304b5e86a0210 59 eb02 8bc3 8a4024 247f 3c01 }
- $sequence_3 = { 50 ff15???????? 8bf0 89b52cfaffff }
- $sequence_4 = { 83e11f c1f805 c1e106 8b0485e86a0210 f644080401 7405 }
- $sequence_5 = { 8d8dd0fbffff e8???????? c645fc03 8d85d0fbffff 83bde4fbffff10 0f4385d0fbffff }
- $sequence_6 = { b9???????? e8???????? 33c0 c645fc1f 33c9 66a3???????? 66390d???????? }
- $sequence_7 = { 81fbfeffff7f 0f87ab000000 8b4614 3bc3 7325 ff7610 53 }
- $sequence_8 = { b9???????? c705????????07000000 0f44f8 c705????????00000000 57 68???????? }
- $sequence_9 = { 83c404 c78584fbffff0f000000 c78580fbffff00000000 c68570fbffff00 83bd9cfbffff10 720e }
+ $sequence_0 = { e8???????? f645f801 7518 8d55f4 a1???????? e8???????? 8b45f4 }
+ $sequence_1 = { 8d8550ffffff ba02000000 e8???????? 66c785dcfeffffe801 ba???????? 8d854cffffff e8???????? }
+ $sequence_2 = { e8???????? 8b55fc 8bc6 e8???????? 8bf8 e9???????? 8d5308 }
+ $sequence_3 = { eb83 e9???????? 66b86801 ebf5 66b86901 ebef 66b86a01 }
+ $sequence_4 = { e8???????? eb08 8b45fc e8???????? 33c0 5a 59 }
+ $sequence_5 = { e8???????? c3 3a90e2020000 740b 8890e2020000 e8???????? c3 }
+ $sequence_6 = { e8???????? 8bc8 8bd3 8b831c020000 ff9318020000 33c0 8a45ff }
+ $sequence_7 = { a5 a5 a5 8d4584 8d4dd4 ba04000000 e8???????? }
+ $sequence_8 = { ff852cffffff 8d5588 8d45fc e8???????? ff8d2cffffff 8d4588 ba02000000 }
+ $sequence_9 = { 8d8580feffff e8???????? ff854cfeffff 8d9580feffff 8d45fc e8???????? ff8d4cfeffff }
condition:
- 7 of them and filesize <335872
+ 7 of them and filesize <3325952
}
-rule MALPEDIA_Win_Lockergoga_Auto : FILE
+rule MALPEDIA_Win_Powersniff_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1c23217f-5659-545b-a560-32c15b901216"
+ id = "1afa4094-a9fd-5e6f-8667-60dff005c0b1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lockergoga"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lockergoga_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.powersniff"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.powersniff_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "0b1cfe6b39387960d8fabaa4bf38642a4ddd7ce3aadb70d3ac9c167b96d0b767"
+ logic_hash = "7ad286ca27751eb193f2579d1930e5287fef0e22f2b28df0af9c7874b91d42c3"
score = 75
quality = 75
tags = "FILE"
@@ -137127,34 +144179,34 @@ rule MALPEDIA_Win_Lockergoga_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 33c0 897dd4 8b560c 33c9 894514 3bc3 }
- $sequence_1 = { 725e 8b06 8b7e38 8b80e4000000 89459c 3bd7 722c }
- $sequence_2 = { e8???????? 50 ffb5f0feffff 8d85c0feffff c645fc0c 50 8bcf }
- $sequence_3 = { ff10 8d4b10 e8???????? 6a38 53 e8???????? 83c408 }
- $sequence_4 = { e8???????? 8d45d8 c645fc04 50 8bcb e8???????? 8b1b }
- $sequence_5 = { e8???????? 8d45c0 c645fc01 50 8bce e8???????? 8bf0 }
- $sequence_6 = { 8b4df0 33cd e8???????? 8be5 5d c3 ff7594 }
- $sequence_7 = { 8b5904 8b7d0c 8975e8 8975ec 8945f0 c745fc00000000 85ff }
- $sequence_8 = { f30f7e4710 660fd64610 c7471000000000 c747140f000000 c60700 83c718 c745fcffffffff }
- $sequence_9 = { e8???????? 8bc8 3bcf 7413 837f1410 8bc7 7202 }
+ $sequence_0 = { 53 ff35???????? 8945f8 895dfc }
+ $sequence_1 = { 8b45f4 b94d5a0000 663908 7405 6a0b 5b eb0f }
+ $sequence_2 = { 53 56 8b35???????? 57 8d85d8fdffff 50 33db }
+ $sequence_3 = { c1eb10 8975fc 8b75f8 c1ee18 8b34b590780010 0fb6db }
+ $sequence_4 = { 50 8d45f8 50 ff75fc e8???????? 8bd8 3bde }
+ $sequence_5 = { c745fc08000000 eb09 ff15???????? 8945fc 8b45fc 5f 5e }
+ $sequence_6 = { ff15???????? 8bf8 897df0 3bfb 7435 8d4508 50 }
+ $sequence_7 = { 55 8bec 83ec0c 8b473c 03c7 53 8b9880000000 }
+ $sequence_8 = { ff15???????? 85c0 0f84b4000000 8d8590feffff 50 ffd3 034574 }
+ $sequence_9 = { a1???????? 53 68???????? ff750c 8945f8 ff7508 }
condition:
- 7 of them and filesize <2588672
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Win_Retefe_Auto : FILE
+rule MALPEDIA_Win_Grok_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f3caa6e6-3618-52a1-825b-c9f70c1ac6ab"
+ id = "870cf4c1-459b-52f4-a686-b281f5585948"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.retefe"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.retefe_auto.yar#L1-L263"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grok"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grok_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "60c0df86aaa8e365109479b1ca3f3fca53ccf95fd2fbd33ae20876e0704e51b2"
+ logic_hash = "f55e3b1924db1bff1757dac784f11d8f8a3020681a2893ba57b274944ef08137"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -137166,51 +144218,32 @@ rule MALPEDIA_Win_Retefe_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 6a01 ff15???????? 8bf0 85f6 7410 6a09 }
- $sequence_1 = { 51 8bf8 ffd6 85c0 }
- $sequence_2 = { 68f5000000 50 ff15???????? b801000000 }
- $sequence_3 = { e8???????? 6a08 e8???????? 894604 }
- $sequence_4 = { 6a24 6a5a 6a24 e8???????? 81c494000000 }
- $sequence_5 = { 8b4e04 8901 8b4e04 33c0 83c404 394104 }
- $sequence_6 = { 6a0e 6aeb 6a1a 6a96 6a0d }
- $sequence_7 = { 894604 83c404 8bc6 e8???????? }
- $sequence_8 = { 51 ff15???????? 8b95d8efffff 50 52 ff15???????? 50 }
- $sequence_9 = { 52 e8???????? 8b4e04 8901 }
- $sequence_10 = { 6ad1 6a1a 6a55 6ad7 6ad1 }
- $sequence_11 = { 880c10 8b4e04 40 3b4104 }
- $sequence_12 = { 50 e8???????? 83c408 e8???????? 99 b960f59000 }
- $sequence_13 = { 8bec 837d0c00 7409 b80b000280 }
- $sequence_14 = { 56 33f6 8b86a0bf4200 85c0 740e }
- $sequence_15 = { 43 85ff 0f851fffffff 5f }
- $sequence_16 = { 6a00 ffb42424200000 e8???????? 8b8c2418200000 }
- $sequence_17 = { 8b0495a0bf4200 f644082801 7421 57 e8???????? }
- $sequence_18 = { 46 85f6 7410 83fe01 75a0 }
- $sequence_19 = { 0fb611 0fb6c0 eb17 81fa00010000 7313 8a87ccb14200 }
- $sequence_20 = { 8b742414 85f6 7553 32c0 }
- $sequence_21 = { 57 81fb00020000 0f8daa000000 6800080000 }
- $sequence_22 = { 8b4218 a3???????? 8b4a08 890d???????? 8b420c }
- $sequence_23 = { 33c0 668906 8b7c2414 8d5f20 }
- $sequence_24 = { e8???????? 8b404c 83b8a800000000 7512 8b04bda0bf4200 807c302900 7504 }
- $sequence_25 = { 88048d93404300 88048d923c4300 84d2 7412 }
- $sequence_26 = { 8b7004 8b38 4e 8bce e8???????? }
- $sequence_27 = { 8b4d08 85c9 7512 e8???????? 5e }
- $sequence_28 = { 5f 894df0 8b34cd58224100 8b4d08 6a5a 2bce }
+ $sequence_0 = { 39702c 7413 56 ff702c ffd3 a1???????? 89702c }
+ $sequence_1 = { 7c62 a1???????? 397044 7412 56 ff7044 ff15???????? }
+ $sequence_2 = { 51 57 50 e8???????? 83c40c 57 53 }
+ $sequence_3 = { 33ff 897dd8 81ff00010000 7d28 8d0c17 8b4514 03c7 }
+ $sequence_4 = { a1???????? 895820 a1???????? 395824 }
+ $sequence_5 = { 894df4 eb09 8b55f4 83c201 8955f4 8b45f8 83c009 }
+ $sequence_6 = { 5f 56 56 6a22 6a01 56 }
+ $sequence_7 = { 50 e8???????? 3bc3 7d7e 395d08 7479 3d430000c0 }
+ $sequence_8 = { 33ff 47 3bc3 8945fc 0f8c9c000000 391d???????? 7410 }
+ $sequence_9 = { 53 51 03c6 50 e8???????? 8b463c 8d8c3080000000 }
condition:
- 7 of them and filesize <843776
+ 7 of them and filesize <84992
}
-rule MALPEDIA_Win_Unidentified_100_Auto : FILE
+rule MALPEDIA_Win_Noxplayer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ef81c2e4-5fa3-571d-bebe-aeaf2bbd4859"
+ id = "aeae21d3-7da2-50ec-a0e6-bf9f936a4ea7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_100"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_100_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.noxplayer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.noxplayer_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "144a60b0164255f58e6624e761b77d4aa80b8a589ef3259bf29c12a9ff5a78b0"
+ logic_hash = "1a7d1e8968616ef04ac90265f765d718da000484253d6b729f0bd247a60f8bd7"
score = 75
quality = 75
tags = "FILE"
@@ -137224,32 +144257,32 @@ rule MALPEDIA_Win_Unidentified_100_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d9424f0030000 488b4c2448 e8???????? e9???????? 4c8d8c2490070000 4533c0 488d942470130000 }
- $sequence_1 = { 4889442420 4c8d8c24e0020000 448b442458 8b54245c 8b4c2454 }
- $sequence_2 = { 0f8dac000000 c644242000 eb0b 0fb6442420 fec0 88442420 0fb6442420 }
- $sequence_3 = { 448bc3 488d1580860000 e8???????? 85c0 7429 }
- $sequence_4 = { 488bf8 33c0 b9fe010000 f3aa 4c8b8c24b8060000 4c8b8424b0060000 488d156dfd0100 }
- $sequence_5 = { eb1d 488d05a7690100 ffcb 488d0c9b 488d0cc8 ff15???????? ff0d???????? }
- $sequence_6 = { 488d05a7690100 ffcb 488d0c9b 488d0cc8 ff15???????? }
- $sequence_7 = { ffc0 8944243c 486344243c 483b442458 7320 486344243c }
- $sequence_8 = { 33c0 b97a010000 f3aa 488d8424b0190000 488d0deee80100 }
- $sequence_9 = { 488b842490030000 4889842490000000 48c7442458ffffffff 48ff442458 488b842490000000 488b4c2458 66833c4800 }
+ $sequence_0 = { 488941b0 488b42b8 41b8a8000000 488941b8 488b42c0 488941c0 8b42c8 }
+ $sequence_1 = { 413bd0 7511 48ffc1 4883c004 4883f904 7ce7 32c0 }
+ $sequence_2 = { 4803c1 48898398000000 488b4350 488b4818 48898bb0000000 0f28742470 440f28442460 }
+ $sequence_3 = { e8???????? 488d542450 b904010000 ff15???????? 4c8d05403b0300 488d4c2450 ba04010000 }
+ $sequence_4 = { 4c8d4e34 4c8b442458 488bd6 488b4e58 e8???????? 488d5614 488b4e50 }
+ $sequence_5 = { 488d5557 498d4c2408 e8???????? 488bd8 488d45b7 483bd8 7422 }
+ $sequence_6 = { 488bf2 488bf9 488d91c0000000 488d4c2428 e8???????? 90 488dafa0000000 }
+ $sequence_7 = { 4c894c2470 488b4508 4c3bc8 740f 418b4918 390e 7c07 }
+ $sequence_8 = { 8d4801 488d93b8000000 8b02 3bc8 741b 8b83c0000000 488b8b88000000 }
+ $sequence_9 = { 4489642460 4c8d442458 488d542460 488bc8 e8???????? eb03 498bc5 }
condition:
- 7 of them and filesize <372736
+ 7 of them and filesize <742400
}
-rule MALPEDIA_Win_Lockfile_Auto : FILE
+rule MALPEDIA_Win_Doppeldridex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "544691b3-5a18-5d07-a020-f938e5dff9ba"
+ id = "0bf161f5-a608-54fc-8493-d0ca4c837703"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lockfile"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lockfile_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doppeldridex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doppeldridex_auto.yar#L1-L158"
license_url = "N/A"
- logic_hash = "dc414bc646e8b114a7dca14d5155afbe9c4203cc45e95fbd463e125e3eb42e08"
+ logic_hash = "fb6ff8ebf9c5a6a0d85322be3122e60be6bc024bdfc953709614ec984b12824b"
score = 75
quality = 75
tags = "FILE"
@@ -137263,32 +144296,38 @@ rule MALPEDIA_Win_Lockfile_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 418bdc 33d9 8bcb 4123cf 4133cc 03d1 8955bb }
- $sequence_1 = { 488b4b58 49894a48 488b5360 49895250 48837b6010 7731 41c6424101 }
- $sequence_2 = { 488bf1 33d2 e8???????? 33d2 48895618 48895620 }
- $sequence_3 = { e9???????? 4c8d4c245c 4c8d4570 488d15b31e0600 488d8d70020000 e8???????? 488d8d70020000 }
- $sequence_4 = { 85c0 7411 836530fe 488b4d38 4883c178 e8???????? }
- $sequence_5 = { 57 4883ec20 8bfa 488bd9 488b4908 4885c9 740b }
- $sequence_6 = { 0f845c010000 83792801 0f8552010000 e8???????? 8bd8 483bde 480f42de }
- $sequence_7 = { 0f84a5000000 488b0d???????? 488b15???????? 4c3bc1 750d 488bc1 48d1e8 }
- $sequence_8 = { 41c1c802 4123cb 418bd1 0bc8 c1c205 03cd 418bc0 }
- $sequence_9 = { 88458c 8b4580 0409 3465 88458d 8b4580 040a }
+ $sequence_0 = { 01501c 015020 015024 01500c }
+ $sequence_1 = { 33d2 3b7c2414 0f4cd3 032c24 03ee 2bea 8bc5 }
+ $sequence_2 = { 011483 40 3b06 7cf8 }
+ $sequence_3 = { 010c28 8b4e04 42 8d41f8 d1e8 }
+ $sequence_4 = { 017c240c 3b5c2408 0f822affffff ff74240c }
+ $sequence_5 = { 030c24 0fbe01 88442458 85c0 }
+ $sequence_6 = { 01500c 833920 751c 8bc1 }
+ $sequence_7 = { 0306 894218 47 3b7c2408 }
+ $sequence_8 = { 7508 8b45f8 83c40c 5d c3 }
+ $sequence_9 = { 8b459c 83c474 5e 5f 5b }
+ $sequence_10 = { 5e 5f 5d c3 8b45e4 8b4dec 8a1401 }
+ $sequence_11 = { 8945e0 74c2 eb9b 8b45f0 353857544f }
+ $sequence_12 = { 0fb7c7 89442408 894c240c 8b45ac }
+ $sequence_13 = { 8b4da0 83f900 898570ffffff 0f840c010000 e9???????? }
+ $sequence_14 = { 7452 eb22 668b45c6 66c1e801 0fb7c8 }
+ $sequence_15 = { 8b5dbc 891c24 89442404 0fb7c7 }
condition:
- 7 of them and filesize <1163264
+ 7 of them and filesize <360448
}
-rule MALPEDIA_Win_Neteagle_Auto : FILE
+rule MALPEDIA_Win_Nimrev_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1db1653f-5505-5d3a-ba38-0bc41fb6ed7f"
+ id = "62b602c2-9378-5d4d-8f76-ba10a1fe3c95"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.neteagle"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.neteagle_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nimrev"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nimrev_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "6f0c75693d906262c5895d882d984643cdff0e946d0c3df9bf0f7a28d5c9d704"
+ logic_hash = "276c930d9217520c07d5dbe59ac126b04c22edd3ab1aa62095745bbe5305f85e"
score = 75
quality = 75
tags = "FILE"
@@ -137302,32 +144341,32 @@ rule MALPEDIA_Win_Neteagle_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4c2418 e8???????? 8d4c2418 e8???????? 8b84241c300000 89742410 3bc6 }
- $sequence_1 = { 83c408 50 51 8d442428 }
- $sequence_2 = { c68424240200000d 8bcc 8964242c 68???????? e8???????? }
- $sequence_3 = { 6a00 6a00 57 56 6840800000 ff15???????? }
- $sequence_4 = { c684241802000018 8bcc 89642424 8d542428 52 e8???????? 8d442420 }
- $sequence_5 = { 8d4dec e8???????? 6800100000 8d4dec c645fc0d e8???????? 8b16 }
- $sequence_6 = { 8d4c2428 c68424540c000006 e8???????? 8d542414 68???????? 8d442414 52 }
- $sequence_7 = { c684241002000004 e8???????? 8d4e34 c684241002000005 e8???????? 8d4e38 c684241002000006 }
- $sequence_8 = { 52 6a00 6a00 8b3d???????? ffd7 83f820 7f1b }
- $sequence_9 = { 888c0414010000 40 3bc6 7ced 8d942414010000 8d4c240c 52 }
+ $sequence_0 = { ffd0 90 e9???????? 90 b9d0070000 e8???????? }
+ $sequence_1 = { c1e002 01d0 01c0 29c1 89c8 83c030 89c1 }
+ $sequence_2 = { b801000000 eb05 b800000000 8845f7 eb01 90 }
+ $sequence_3 = { b801000000 eb05 b800000000 8845f7 eb01 90 0fb645f7 }
+ $sequence_4 = { eb05 b800000000 8845f7 eb01 90 }
+ $sequence_5 = { 83f001 84c0 7408 90 }
+ $sequence_6 = { 0fb600 3c7d 7407 b801000000 eb05 }
+ $sequence_7 = { 89c1 e8???????? eb04 90 eb01 90 }
+ $sequence_8 = { 3c7d 7407 b801000000 eb05 }
+ $sequence_9 = { eb01 90 0fb645f6 8845f7 }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <1141760
}
-rule MALPEDIA_Win_Tinba_Auto : FILE
+rule MALPEDIA_Win_Starcruft_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8b073df0-6973-5487-9d6c-3a57aeeab821"
+ id = "1dcafb43-c4d2-514a-8438-617d875e41e7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinba"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tinba_auto.yar#L1-L141"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.starcruft"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.starcruft_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "3e0ce52a496c3fcf4e972331a3890b233f5a6cdb900c63778e37d0782cfe61e3"
+ logic_hash = "ba9170fb6918e14feeea6fab09146b237b88c2d2d12a4f68164b770922d2ddd1"
score = 75
quality = 75
tags = "FILE"
@@ -137341,35 +144380,32 @@ rule MALPEDIA_Win_Tinba_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b7508 ad 50 56 }
- $sequence_1 = { 8b4510 aa 8b450c ab }
- $sequence_2 = { 8a241f 88240f 88041f 41 }
- $sequence_3 = { 6a00 6a00 6a00 ff750c 6a00 6a00 ff7508 }
- $sequence_4 = { 8b4114 83f8fd 7506 8b4108 8b4014 85c0 7403 }
- $sequence_5 = { 66b80d0a 66ab b8436f6f6b ab b869653a20 ab }
- $sequence_6 = { ff15???????? 48 83c420 48 85c0 0f84b4000000 }
- $sequence_7 = { 814a3500080000 4c 29c6 40 8832 }
- $sequence_8 = { 8b7d0c 31c9 bb0a000000 31d2 f7f3 52 }
- $sequence_9 = { 8b4514 8908 290e 8b06 }
- $sequence_10 = { 66b80d0a 66ab b855736572 ab b82d416765 ab }
- $sequence_11 = { 73ed 88e8 48 8d1d5a020000 }
- $sequence_12 = { fd 8b7d0c 83c707 8b4508 83e00f }
+ $sequence_0 = { 83bd34fbffff00 7458 0fb64d34 85c9 7419 8b95b4fcffff 899558fbffff }
+ $sequence_1 = { ebbd c7852cfeffff01000000 83bd2cfeffff00 7565 8b4508 898524feffff c78520feffff00000000 }
+ $sequence_2 = { 884def 8b55f0 83c202 8955f0 8b45f0 8945f8 eb09 }
+ $sequence_3 = { 8b55f8 8b85ccfeffff 8b0c90 0fb711 85d2 740b 8b45f8 }
+ $sequence_4 = { 55 8bec 81ec20010000 a1???????? 33c5 8945e4 8b4508 }
+ $sequence_5 = { c685cafcffff26 c685cbfcffffa1 c685ccfcffff8b c685cdfcffff52 c685cefcffff6c c685cffcffffba c685d0fcffffde }
+ $sequence_6 = { 8b4dd4 8908 8b5510 8b02 50 8d4dd8 51 }
+ $sequence_7 = { 8b4dcc 51 e8???????? 83c404 8945f0 8955f4 8b55d0 }
+ $sequence_8 = { e8???????? 83c404 33c0 e9???????? 8b45fc }
+ $sequence_9 = { e8???????? e8???????? c705????????04c02e00 c705????????08c02e00 c705????????0cc12e00 c705????????10c12e00 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <294912
}
-rule MALPEDIA_Win_Ismagent_Auto : FILE
+rule MALPEDIA_Win_Unidentified_013_Korean_Malware_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "efc3a6d8-4046-5104-90f5-9440914b7f87"
+ id = "6cb9e399-7a4a-5f81-aaa6-7cb702a29e01"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ismagent"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ismagent_auto.yar#L1-L102"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_013_korean_malware"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_013_korean_malware_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "d297d8bd0034edde53a6d3eb1d7bb7add88b3f450af6b836362398a9173b61dc"
+ logic_hash = "c008af161ea64c4cea7a6eccb5b08fe1a4b68cae21f50d0dd25e80b0eb93ad58"
score = 75
quality = 75
tags = "FILE"
@@ -137383,30 +144419,32 @@ rule MALPEDIA_Win_Ismagent_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ba???????? 6a00 6800000080 6a00 6a00 68???????? 53 }
- $sequence_1 = { 89442440 85c0 752b 50 68???????? }
- $sequence_2 = { eb7c c745e000fe4100 ebbb d9e8 8b4510 }
- $sequence_3 = { e8???????? 83c408 89442418 85c0 0f8479020000 }
- $sequence_4 = { 68e8030000 ff15???????? 8d8c2418030000 8d5101 }
- $sequence_5 = { 7432 8d842418030000 68???????? 50 e8???????? 8bf0 }
- $sequence_6 = { 8bf2 0f1f4000 8a02 42 84c0 75f9 8dbc2400070000 }
- $sequence_7 = { 8d0439 7413 0f1f4000 803823 740a }
+ $sequence_0 = { 3bd7 7cf5 7f04 3bc5 72ef }
+ $sequence_1 = { 57 a1???????? 33c4 50 8d842458060000 64a300000000 68???????? }
+ $sequence_2 = { 6800040000 8d4c241c 51 57 ffd5 85c0 743f }
+ $sequence_3 = { 81c40c040000 c3 8b2d???????? 8d44240c 50 }
+ $sequence_4 = { e8???????? 83c424 8bd8 8d542414 8d8c2454030000 }
+ $sequence_5 = { 8b44243c ff4c241c 3bf8 7605 e8???????? 8b44242c bb10000000 }
+ $sequence_6 = { 83c428 c3 3c03 0f8558ffffff 83f901 }
+ $sequence_7 = { 8d442414 50 c744242003000000 ff15???????? b902000000 }
+ $sequence_8 = { 68???????? 68???????? e8???????? 83c410 e8???????? b230 }
+ $sequence_9 = { 6a00 6a00 6a00 8bf2 6a00 6a00 8bf9 }
condition:
- 7 of them and filesize <327680
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Deadwood_Auto : FILE
+rule MALPEDIA_Win_Ngioweb_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5f00cc5a-9602-50e1-9261-d675303486e9"
+ id = "1a04caa4-5f94-5038-893b-b414574d57bc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.deadwood"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.deadwood_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ngioweb"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ngioweb_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "ea97d4cccc4d6a9b5e482bbc380fcc6fbef419bedaf1f051b13240e62ed24277"
+ logic_hash = "53b049f61ecbdc954b47598eb5e1d9de9a9f52f58bb1ef6f666338c0ff24b7f4"
score = 75
quality = 75
tags = "FILE"
@@ -137420,32 +144458,32 @@ rule MALPEDIA_Win_Deadwood_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 e8???????? 83c404 33db be0f000000 89b42418010000 899c2414010000 }
- $sequence_1 = { 7303 8d4508 8b5518 52 50 8b4110 50 }
- $sequence_2 = { 7464 8bf0 8b4814 894c2424 3bcb 7504 895c2428 }
- $sequence_3 = { 6a01 8d442414 50 8d4c243c 897c247c c744241878f44500 e8???????? }
- $sequence_4 = { 8bf8 85ff 0f8484000000 53 53 53 53 }
- $sequence_5 = { ff15???????? 6804010000 8d8df4fdffff 51 50 ff15???????? 33d2 }
- $sequence_6 = { e8???????? 8b542460 c7442440e4ba4500 bb???????? 895c2454 8b4204 c7440460c8ba4500 }
- $sequence_7 = { 8b07 8b4804 837c390c00 0f94c1 884dd8 c745fc01000000 84c9 }
- $sequence_8 = { 74ed 89450c 8b13 807a1d00 7404 8b3e eb13 }
- $sequence_9 = { 8bb510ffffff e9???????? c3 8d8d34ffffff e9???????? 8d8d18ffffff e9???????? }
+ $sequence_0 = { 8b4604 897808 eb15 894f08 8b06 89780c 893e }
+ $sequence_1 = { 394518 89b39c000000 c783a800000001000000 8983b0000000 7412 50 6884000000 }
+ $sequence_2 = { ffd0 85c0 7554 ff75fc 53 }
+ $sequence_3 = { 66c745ae6300 66c745ac5400 668975aa 66895dc4 e8???????? 33c0 }
+ $sequence_4 = { 668b460c 895f04 8d5f08 53 668907 ff7608 }
+ $sequence_5 = { 3bc7 7574 689f860100 6810270000 8d4508 50 }
+ $sequence_6 = { 53 8b5d24 68b9ed740a 56 e8???????? ff7518 ff7514 }
+ $sequence_7 = { ff75f0 ff15???????? ff15???????? 8b45e8 eb02 33c0 5f }
+ $sequence_8 = { 8bc3 5b 5d c21400 57 8b7c2408 85ff }
+ $sequence_9 = { 770b 0fb7c0 668b4445d8 668906 46 46 49 }
condition:
- 7 of them and filesize <1055744
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Polyvice_Auto : FILE
+rule MALPEDIA_Win_Miancha_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f632496e-a2f4-5ede-b8be-18463e7a5bac"
+ id = "5e7fc19e-d4d3-5751-a42a-778cf2bcb637"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.polyvice"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.polyvice_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miancha"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.miancha_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "ed3286a18e97148fc13382a255519a25655dd929e966c75502c6a665bf5d62e5"
+ logic_hash = "1f67b71b2562c78fd331e78fe99dcc1e4206e3c62481b807645f41343dd343bc"
score = 75
quality = 75
tags = "FILE"
@@ -137459,32 +144497,32 @@ rule MALPEDIA_Win_Polyvice_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4589cf 4131ed 41c1cf06 4501e5 4589fc 4589cf 41c1cf0b }
- $sequence_1 = { c1c207 31d1 4489c2 c1ca02 01f1 89d6 }
- $sequence_2 = { 448b442438 01d1 01c1 4489c2 4489c0 c1c807 }
- $sequence_3 = { 4409f6 89f5 89c6 4421f6 4421e5 09f5 4489de }
- $sequence_4 = { 4c8d150fc20000 4801de 4c8d0d05ca0000 4c8d05fec50000 4883c310 8b3b 89f9 }
- $sequence_5 = { 66418949fe 89e9 d3e8 4d39cb 75e2 4889d8 4829f0 }
- $sequence_6 = { e9???????? 488d4dcc 31f6 e8???????? 4c8d3531650000 4989c5 eb2d }
- $sequence_7 = { 53 4881ec38030000 488dac2480000000 410fb7400c 410fb77840 450fb77822 668945bc }
- $sequence_8 = { 450fb6ec bf20000000 c744242800000000 0fb7db 4531ff }
- $sequence_9 = { 0fb7c9 0fb74c4b02 664183f802 7508 6683f902 410f44c3 450fb7ed }
+ $sequence_0 = { 7412 8d542418 52 ff15???????? }
+ $sequence_1 = { 6803000080 ff15???????? 85c0 741f 6a00 }
+ $sequence_2 = { 8b15???????? 894808 8a0d???????? 89500c 884810 }
+ $sequence_3 = { 40 50 56 8b35???????? 6a02 6a00 }
+ $sequence_4 = { 85f6 7412 8d542418 52 ff15???????? 50 }
+ $sequence_5 = { ff15???????? 50 ffd6 85c0 741a }
+ $sequence_6 = { 8d542418 52 ff15???????? 50 ffd6 85c0 }
+ $sequence_7 = { 50 68???????? e8???????? 33f6 83c408 }
+ $sequence_8 = { 8910 8b15???????? 894804 8b0d???????? 895008 8a15???????? }
+ $sequence_9 = { 8910 8b15???????? 894804 8b0d???????? 895008 8a15???????? 89480c }
condition:
- 7 of them and filesize <369664
+ 7 of them and filesize <376832
}
-rule MALPEDIA_Win_Aurora_Auto : FILE
+rule MALPEDIA_Win_Zerocleare_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6739f143-45de-5c25-aa97-f9c0ab868c7e"
+ id = "3657cdfc-db20-5908-b80b-f3809b1ef7a0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aurora"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aurora_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zerocleare"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zerocleare_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "401b46f1e5d6c2d35e6c7ba88f463abdb92c79f1d47fd14fd19c66427ffd50ad"
+ logic_hash = "684e088a58b2073463dab14cb1ba7b141fc0ac01570965634aebae02ef8b6f64"
score = 75
quality = 75
tags = "FILE"
@@ -137498,32 +144536,32 @@ rule MALPEDIA_Win_Aurora_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4e14 8945d4 8b4610 3bc1 7530 40 83f8fe }
- $sequence_1 = { c645fc03 8d4dd8 837dec08 8d5dd8 }
- $sequence_2 = { 8aca c0e206 0255d3 c0e902 80e10f }
- $sequence_3 = { ebd9 837b1410 7202 8b1b }
- $sequence_4 = { 3bf3 7469 897de8 c645fc01 85ff 7437 c7471000000000 }
- $sequence_5 = { 6a00 c741140f000000 c7411000000000 68???????? c60100 e8???????? 8d8df8fbffff }
- $sequence_6 = { 83793800 0f45c2 50 e8???????? 8b9df0feffff c745e40f000000 c745e000000000 }
- $sequence_7 = { c785c8f1ffff0f000000 c785c4f1ffff00000000 c685b4f1ffff00 e8???????? 8d8dccf1ffff }
- $sequence_8 = { 68???????? 8d8d24f1ffff c78538f1ffff0f000000 c78534f1ffff00000000 }
- $sequence_9 = { 6a02 68???????? 8d8d14efffff c78528efffff0f000000 }
+ $sequence_0 = { db2d???????? b801000000 833d????????00 0f854f6efeff ba05000000 8d0df0694400 e8???????? }
+ $sequence_1 = { 0f1185d8f7ffff f30f7e4010 660fd685e8f7ffff c7401000000000 c7401407000000 668908 c645fc04 }
+ $sequence_2 = { 6a00 8d45e8 50 6a18 }
+ $sequence_3 = { ffd6 6af4 898578f7ffff ffd6 }
+ $sequence_4 = { 0f114598 0f1145a8 ff15???????? 8bf8 }
+ $sequence_5 = { 895614 7410 c74620df494300 c74624f24a4300 eb0e c7462087414300 }
+ $sequence_6 = { c745e4ad184200 eb08 8d4dd8 e8???????? 837e1808 74f2 8bce }
+ $sequence_7 = { 660f58ca 660f2815???????? f20f59db 660f282d???????? 660f59f5 660f28aa70534400 660f54e5 }
+ $sequence_8 = { 8b04cdd40a4400 5f 5e 5b 8be5 5d c3 }
+ $sequence_9 = { 33c0 8985e4f7ffff 90 8b4c3814 8d1438 8d4101 }
condition:
- 7 of them and filesize <827392
+ 7 of them and filesize <42670080
}
-rule MALPEDIA_Win_Jessiecontea_Auto : FILE
+rule MALPEDIA_Win_Remcos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "526b090a-a995-58b5-b843-1e70dd71cefc"
+ id = "0b71eaff-61b4-55ab-a8af-3cf13e03dd61"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jessiecontea"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jessiecontea_auto.yar#L1-L165"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.remcos_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "c68c31b644ea8b3e7ca9f4e4366853343f61b6640765616026487f548092899b"
+ logic_hash = "d80be2f75bdd44294476100f6767031142d9f2872cceaebec5f1ed9745e8779f"
score = 75
quality = 75
tags = "FILE"
@@ -137537,38 +144575,32 @@ rule MALPEDIA_Win_Jessiecontea_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c78590f4ffff00000000 c7858cf4ffff00000000 c78588f4ffff00000000 c78594f4ffff01000000 c78598f4ffff01000000 e8???????? }
- $sequence_1 = { 3d00010000 0f8f03010000 6a00 6a00 50 }
- $sequence_2 = { 8d85e8fdffff 50 8d85a2f6ffff 50 }
- $sequence_3 = { 57 8b7d18 8945c0 8b4510 }
- $sequence_4 = { eb02 2bf7 6a00 8d85e8b7ffff 50 }
- $sequence_5 = { 5d c3 c705????????31090000 5f 5e 5b 8be5 }
- $sequence_6 = { 56 57 680a020000 8d85d8fbffff 8bf2 6a00 }
- $sequence_7 = { 6880000000 6a01 6a00 6a01 6800000040 8d85f8fbffff 50 }
- $sequence_8 = { 41b800080000 be20000008 e8???????? 33d2 448975c0 }
- $sequence_9 = { 4d8bc8 4d2bcd 6690 488d82fafeff7f }
- $sequence_10 = { 83e03f 2bc8 33c0 48d3c8 488d0d39d20100 4833c2 }
- $sequence_11 = { 7305 44887c3710 488bcb e8???????? 397d50 7230 }
- $sequence_12 = { ff15???????? 85c0 0f8580fcffff 488b4c2460 }
- $sequence_13 = { 892d???????? 8b1d???????? 488d4c2430 8bfd 48896c2430 }
- $sequence_14 = { 4889442440 33d2 4489742448 41b8ff3f0000 488d8d51070000 }
- $sequence_15 = { 488b4d98 488d4588 4889442428 41b902000000 }
+ $sequence_0 = { 7410 6a00 ff35???????? ff15???????? }
+ $sequence_1 = { 50 ff15???????? 8d45f0 33f6 }
+ $sequence_2 = { 6a09 ff35???????? ff15???????? ff35???????? ff15???????? }
+ $sequence_3 = { 8d45f8 50 ff15???????? ff7508 }
+ $sequence_4 = { 7508 ff15???????? 33c0 5f }
+ $sequence_5 = { 6a09 ff35???????? ff15???????? ff35???????? }
+ $sequence_6 = { ff15???????? 50 ff15???????? 8d45f0 33f6 }
+ $sequence_7 = { 50 6a28 ff15???????? 50 ff15???????? 8d45f0 33f6 }
+ $sequence_8 = { 51 51 8d45f8 c745f808000000 50 ff15???????? ff15???????? }
+ $sequence_9 = { 85c0 7410 6a00 ff35???????? ff15???????? }
condition:
- 7 of them and filesize <413696
+ 7 of them and filesize <1054720
}
-rule MALPEDIA_Win_Dmsniff_Auto : FILE
+rule MALPEDIA_Win_Bredolab_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "16f341e6-77a3-5816-ba96-baf125c04244"
+ id = "0b33903d-ad64-555d-936e-aab5345d2509"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dmsniff"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dmsniff_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bredolab"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bredolab_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "97dafc3ba62eb5e1ea05a655f64eed9d043aae4b3733a53f196189f18ab4ea03"
+ logic_hash = "adde67d05e7a2d047afa70901aa11c567b41ad799d4fe97c3d9648b79067c4f5"
score = 75
quality = 75
tags = "FILE"
@@ -137582,34 +144614,34 @@ rule MALPEDIA_Win_Dmsniff_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c661 89f3 881d???????? 8d04bf }
- $sequence_1 = { 50 d93c24 66810c240003 d92c24 83c404 6a00 6a00 }
- $sequence_2 = { 53 56 57 8b5d0c 8b7510 }
- $sequence_3 = { 89fe 46 89b5fcfeffff 899cbd00ffffff 8d85f0feffff 50 6a00 }
- $sequence_4 = { eb15 47 39f7 72d3 ff45fc 8b45f4 3945fc }
- $sequence_5 = { 56 57 8965e8 50 d93c24 }
- $sequence_6 = { eb18 68???????? e8???????? 50 68???????? e8???????? 83c40c }
- $sequence_7 = { e8???????? 50 68???????? e8???????? 83c40c eb18 }
- $sequence_8 = { e8???????? 83c40c eb18 68???????? e8???????? 50 }
- $sequence_9 = { 7316 8bbdfcfeffff 89fe 46 89b5fcfeffff 899cbd00ffffff }
+ $sequence_0 = { 8b4518 89442410 8b4514 8944240c c744240800000000 }
+ $sequence_1 = { baffe8a435 89d1 31d2 f7f1 81c200e1f505 89542408 c7442404???????? }
+ $sequence_2 = { 0f85e8000000 ba???????? 90 31c0 6690 8a8800500010 300c02 }
+ $sequence_3 = { 57 56 53 b86c140000 }
+ $sequence_4 = { f2ae f7d1 8d41ff 81c40c090000 }
+ $sequence_5 = { 8b8318120000 85c0 0f8e88000000 c783381200000c000000 }
+ $sequence_6 = { 0f85c5000000 8b9560feffff 8b02 3b45dc 7437 }
+ $sequence_7 = { 5e 5f c9 c3 8db526ffffff b910000000 }
+ $sequence_8 = { 8b8a1c120000 85c9 0f8ee7000000 31ff 31c0 8d9d20f7ffff 89b514f7ffff }
+ $sequence_9 = { 85c0 753b 0fb78394010000 338396010000 0d00000080 baffe8a435 89d1 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Win_Olympic_Destroyer_Auto : FILE
+rule MALPEDIA_Win_Sparrow_Door_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9f025408-c0a3-516e-ac3a-efc2033f9b9b"
+ id = "0be52ebd-81b0-5548-b0c4-71d664335291"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.olympic_destroyer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.olympic_destroyer_auto.yar#L1-L222"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sparrow_door"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sparrow_door_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "93564b4c61bfe578140a2ed1dd33860e59e2d49295b03d310dd7eaa077d799f2"
+ logic_hash = "a3ea16377775f10fb390048ca81fb5b622cc57fa7d5b14e32fa13a939a085057"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -137621,45 +144653,32 @@ rule MALPEDIA_Win_Olympic_Destroyer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 56 33c0 89542414 57 }
- $sequence_1 = { 6690 3939 770a 8bc1 46 }
- $sequence_2 = { 8b0c8d60ee5500 80643128fd 5f 5e }
- $sequence_3 = { 50 689b000000 e8???????? e9???????? }
- $sequence_4 = { ff15???????? 6880ee3600 ff15???????? 6800000500 56 }
- $sequence_5 = { 50 68???????? e8???????? 83c408 8907 85c0 0f8480000000 }
- $sequence_6 = { a1???????? 85c0 741a 833d????????00 7c0a }
- $sequence_7 = { 50 68???????? 8d85e4fcffff 6805010000 }
- $sequence_8 = { a1???????? c705????????f3274000 8935???????? a3???????? ff15???????? a3???????? 83f8ff }
- $sequence_9 = { 7678 eb06 8b8de8efffff 2b8df0efffff 1b85f4efffff }
- $sequence_10 = { 2bfa 8d0450 57 50 }
- $sequence_11 = { 750b ff15???????? e9???????? 8b3d???????? 6a02 56 }
- $sequence_12 = { 83f8fe 7419 8a4a02 3a4e02 }
- $sequence_13 = { 83ffff 743a 8d857cf9ffff 50 57 ff15???????? }
- $sequence_14 = { 898588f9ffff 8d85e4fbffff 68???????? 50 ff15???????? 83c40c 8d8594f9ffff }
- $sequence_15 = { 8d842494000000 89442424 8d54241c 8b44245c 8d4c2424 6a24 }
- $sequence_16 = { 50 68???????? 8bd7 8bcb e8???????? 8bd8 }
- $sequence_17 = { 8d8580f7ffff 50 56 56 56 56 }
- $sequence_18 = { 89442418 85c0 743a 57 }
- $sequence_19 = { 50 68???????? 8d85ecfdffff 6805010000 }
- $sequence_20 = { ffd6 50 ff15???????? 8d8594f9ffff }
- $sequence_21 = { 50 68???????? e8???????? 83c40c 8903 5f }
- $sequence_22 = { 50 68???????? 8901 ff770c e8???????? 83c40c }
+ $sequence_0 = { 395c240c 7551 8b5604 8b3d???????? 52 68???????? }
+ $sequence_1 = { 57 56 ff15???????? 85c0 0f8491010000 8b44243c 3bc5 }
+ $sequence_2 = { 8d8c2440040000 51 55 8d94243c010000 52 6a00 68e9fd0000 }
+ $sequence_3 = { 53 50 8bf1 895c2430 895c2438 889c244c060000 }
+ $sequence_4 = { 8d44245c 50 e8???????? 83c420 85c0 }
+ $sequence_5 = { a1???????? a3???????? a1???????? c705????????05772a00 8935???????? }
+ $sequence_6 = { e8???????? 8d542470 52 8d442448 50 8b84249c010000 }
+ $sequence_7 = { 50 895c2438 c744244844000000 898c2480000000 c744247401010000 6689542478 889c2490000000 }
+ $sequence_8 = { 894c2418 8954241c 3bc3 7555 }
+ $sequence_9 = { 8d8c2400010000 51 56 52 ffd5 85c0 74a8 }
condition:
- 7 of them and filesize <1392640
+ 7 of them and filesize <155648
}
-rule MALPEDIA_Win_Swen_Auto : FILE
+rule MALPEDIA_Win_Cohhoc_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7f9f6459-0c0a-509f-9c87-8a68bae77e34"
+ id = "b68a758f-10e4-5b26-9336-04dc8575909c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.swen"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.swen_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cohhoc"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cohhoc_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "6a4f1002b8a4868bbe8661a8400f2e2886c507211772c905c6406fbef250b4fb"
+ logic_hash = "ecae8715f2ad96196b29dfd6ae017f72fc211d8d4ab8ab2002ae190526566a13"
score = 75
quality = 75
tags = "FILE"
@@ -137673,32 +144692,32 @@ rule MALPEDIA_Win_Swen_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ab 8d85a8fcffff 50 8d8564fcffff 50 56 56 }
- $sequence_1 = { 6a05 59 be???????? 8dbd1cfeffff f3a5 66a5 }
- $sequence_2 = { 68b0040000 ff15???????? c9 c3 55 8bec 6aff }
- $sequence_3 = { 33c9 85c0 0f95c1 41 890d???????? 8b450c 3905???????? }
- $sequence_4 = { 59 59 50 8d8594fcffff 50 }
- $sequence_5 = { 0fbe4602 8d48df 83f951 7408 83c00a 83f85c 755f }
- $sequence_6 = { 53 6880000000 6a04 53 6a03 6800000040 8d85e4feffff }
- $sequence_7 = { e8???????? 8d85d8fdffff 50 8d8550ffffff 50 e8???????? 8d4603 }
- $sequence_8 = { 0f84b2000000 895de0 8b4de4 c1e902 8b45e0 3bc1 0f839e000000 }
- $sequence_9 = { 3bc3 7410 8d8d80feffff 2bc1 40 40 89857cfeffff }
+ $sequence_0 = { 1bc0 83d8ff 85c0 0f84fb000000 bf???????? 8db424b4010000 8a0e }
+ $sequence_1 = { 5b 81c49c020000 c3 8b542410 }
+ $sequence_2 = { e8???????? 50 6801010000 8bcd e8???????? 8bcd }
+ $sequence_3 = { 33c0 5b 83c444 c3 8b542434 8b442458 6a00 }
+ $sequence_4 = { 817c240c03010000 0f8494010000 8b35???????? 8d442410 53 50 68???????? }
+ $sequence_5 = { 66c74424040010 8974242c 89742430 8b442448 8b4c2444 50 }
+ $sequence_6 = { bf01000000 6a00 68???????? ffd6 85ff }
+ $sequence_7 = { 88442424 894c2430 8b4c2424 57 51 8b4c2428 e8???????? }
+ $sequence_8 = { 6a07 51 6a00 aa }
+ $sequence_9 = { 8bc8 8d8424b4010000 83e103 f3a4 be???????? 8a10 8aca }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Bachosens_Auto : FILE
+rule MALPEDIA_Win_Lobshot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "512fddd0-592d-56ea-af08-938454f6edb9"
+ id = "5bc103fe-8569-5650-9cd3-425031e0ab5f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bachosens"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bachosens_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lobshot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lobshot_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "b427aef6cac4c70adae9906b44868965e5c9a8d697254ea4be31acc54b01936b"
+ logic_hash = "b29ec78bd5106a9ad51352916c3857459a77fea2349f02317d142c1882771dfc"
score = 75
quality = 75
tags = "FILE"
@@ -137712,34 +144731,34 @@ rule MALPEDIA_Win_Bachosens_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7703 80c1e0 3ad1 7513 49ffc0 }
- $sequence_1 = { 660f1f840000000000 410fb707 418b3e 6603c1 4803f9 0fb7c0 }
- $sequence_2 = { 66443908 75f4 443bc1 740a b801000000 }
- $sequence_3 = { 49f7d9 4c8bc5 660f1f840000000000 420fb61407 410fb608 8d429f 3c19 }
- $sequence_4 = { 488bc7 ffc1 488d4001 803800 75f5 33d2 }
- $sequence_5 = { 75f3 418bc9 66390a 7417 }
- $sequence_6 = { 740e 488bc5 ffc2 488d4001 803800 }
- $sequence_7 = { 4c03d1 458b7220 418b521c 4c03f1 458b7a24 4803d1 }
- $sequence_8 = { 0fb70a 418d409f 6683f819 7704 }
- $sequence_9 = { 75f3 418bc9 66390a 7417 488bc2 0f1f840000000000 ffc1 }
+ $sequence_0 = { 895c2414 85f6 7410 6a02 56 ff15???????? 56 }
+ $sequence_1 = { 8b4508 8bd1 85c0 7409 c60200 42 }
+ $sequence_2 = { 728d ff742418 ff15???????? 8b74241c 43 83fb04 0f8e42ffffff }
+ $sequence_3 = { 85d2 7905 895e18 8bd3 57 6a2a }
+ $sequence_4 = { 0f8485000000 8b461c 85c0 747e 8b7804 83ff2a 740d }
+ $sequence_5 = { 0f42c8 33ff 894d08 47 8b4e6c 3bcf 771f }
+ $sequence_6 = { 8b55f8 33ff 85d2 7839 8b5dfc 0fb774bb02 85f6 }
+ $sequence_7 = { 8b4e08 8a86b1160000 88040a ff4614 0fb786b4160000 8386b4160000f3 }
+ $sequence_8 = { 53 ff15???????? 8b0d???????? 8b15???????? 2b15???????? 8d4102 83e902 }
+ $sequence_9 = { 895004 8b8348140000 99 2bc2 8bf0 d1fe }
condition:
- 7 of them and filesize <643072
+ 7 of them and filesize <247808
}
-rule MALPEDIA_Win_Get2_Auto : FILE
+rule MALPEDIA_Win_Jaku_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f91c1425-fc52-545b-9271-7db19be38856"
+ id = "2a488cc0-1b28-5098-bf2b-d901cf20342d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.get2"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.get2_auto.yar#L1-L170"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jaku"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jaku_auto.yar#L1-L268"
license_url = "N/A"
- logic_hash = "5e9d36a39aed19f2ddf758df0012d6d0406c361deba19029a1cb530866b49568"
+ logic_hash = "d05d79a0c954b2e0606ed773ff3f73ae5387638edb50352f452263cfa013d18a"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -137751,40 +144770,53 @@ rule MALPEDIA_Win_Get2_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4004 f644080c06 74d5 8d4d84 e8???????? 8d4584 c645fc03 }
- $sequence_1 = { 0f859a000000 f6c104 7430 8d4c2404 e8???????? }
- $sequence_2 = { e8???????? ff7510 8d4dc0 ff750c e8???????? 83c420 83781410 }
- $sequence_3 = { 57 53 8d4dd8 e8???????? 8bc6 e8???????? c3 }
- $sequence_4 = { 33c0 895dd4 668945d8 51 51 52 }
- $sequence_5 = { 8d44240c 68???????? 50 eb69 f6c102 8d4c2404 742b }
- $sequence_6 = { 8b4910 23c8 0f849e000000 807d0c00 }
- $sequence_7 = { 897e08 33db c745ec07000000 43 897de8 }
- $sequence_8 = { 0f95c3 8bc3 488b5c2450 488b4c2448 }
- $sequence_9 = { 4533f6 4863df 488d0dbc730200 488bc3 83e33f }
- $sequence_10 = { 4885ff 75eb 33c0 48894110 }
- $sequence_11 = { 488bc8 0fb7045e 663901 740f 48ffc3 493bde }
- $sequence_12 = { 663931 7451 488d1590280100 e8???????? 85c0 7441 }
- $sequence_13 = { 7203 488b00 668938 488d8b40010000 }
- $sequence_14 = { 85c0 750d ff15???????? 41898660010000 4032ff }
- $sequence_15 = { 488b4708 4a8b4cf008 488b4618 4c3b24c8 0f85d0fbffff 488b4648 }
+ $sequence_0 = { 8b466c 234634 8b4e40 8b5644 668b7e6c 0fb70441 }
+ $sequence_1 = { 0f84d0000000 8b4d1c 8b550c 0fb709 0fb71c4a }
+ $sequence_2 = { c70610000000 eb1f 56 e8???????? 837d0c06 59 }
+ $sequence_3 = { e8???????? 59 894660 59 837e6003 0f8223010000 }
+ $sequence_4 = { 56 8b7510 57 6a08 33c0 59 }
+ $sequence_5 = { 8b96a4160000 8a0408 8b8ea0160000 66892c4a 8b8e98160000 }
+ $sequence_6 = { 6a0f 58 8d4dc6 8b17 }
+ $sequence_7 = { 83c41c 84c0 742b 8b450c 85c0 }
+ $sequence_8 = { 68???????? ff15???????? c3 b8???????? e8???????? 83ec2c }
+ $sequence_9 = { ff742408 e8???????? c20800 8bc1 }
+ $sequence_10 = { 5b c3 55 8bec 833d????????00 53 56 }
+ $sequence_11 = { 53 68000000a0 6a03 53 }
+ $sequence_12 = { 6a01 03c3 68???????? 50 e8???????? 83c40c 85c0 }
+ $sequence_13 = { 7507 b800308000 eb02 33c0 }
+ $sequence_14 = { 7508 83c8ff e9???????? 8b839f830000 }
+ $sequence_15 = { 75dd 57 e8???????? 59 }
+ $sequence_16 = { 55 56 57 6880020000 }
+ $sequence_17 = { 0245fd 3245fe 8a4dff d2c8 }
+ $sequence_18 = { 016c242c 8b44242c 5f 5e 5d }
+ $sequence_19 = { 50 e8???????? 59 8b4e2c }
+ $sequence_20 = { 85f6 b301 0f8491000000 56 e8???????? }
+ $sequence_21 = { e8???????? 59 eb57 53 }
+ $sequence_22 = { 56 e8???????? 59 8b4620 }
+ $sequence_23 = { 8d4608 57 e8???????? 8365e000 }
+ $sequence_24 = { e8???????? 8b7dd8 397de8 7593 6804010000 8d8574feffff 50 }
+ $sequence_25 = { a4 ff839f830000 8b839f830000 8b8b97830000 8901 33c0 40 }
+ $sequence_26 = { ff75f4 66899e4d720000 8d9e8f7e0000 53 81c6917e0000 }
+ $sequence_27 = { 6a00 e8???????? 50 e8???????? b001 8b55b4 64891500000000 }
+ $sequence_28 = { 6a00 53 e8???????? 0fbe532e }
condition:
- 7 of them and filesize <720896
+ 7 of them and filesize <2220032
}
-rule MALPEDIA_Win_Microcin_Auto : FILE
+rule MALPEDIA_Win_Fickerstealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7e85e39e-7daa-514d-802c-54d6ff85c6e9"
+ id = "45d62189-24df-5dae-af5a-78b51fda916c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.microcin"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.microcin_auto.yar#L1-L465"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fickerstealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fickerstealer_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "3f18992fe004fbfcac38bd4eed04ab5733b0957df603607ba4dee35273474322"
+ logic_hash = "fe62eb4bdda7768c5d67489e8496ef31433ebe8da6a7c001c0177fb4671588ff"
score = 75
- quality = 44
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -137796,72 +144828,32 @@ rule MALPEDIA_Win_Microcin_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 56 ff15???????? 85c0 0f45f7 }
- $sequence_1 = { 442bc3 4803d6 4533c9 ff15???????? 85c0 75d9 488b742438 }
- $sequence_2 = { ff15???????? 488bcb ff15???????? 448bc0 }
- $sequence_3 = { 57 4154 4156 4157 488dac2400fbffff 4881ec00060000 488b05???????? }
- $sequence_4 = { e8???????? 83c40c 8d85f8feffff 6804010000 50 ff15???????? 8d85f8feffff }
- $sequence_5 = { 488b09 418bf8 488bf2 33db }
- $sequence_6 = { ff15???????? 8b3d???????? 8d85e0feffff 50 }
- $sequence_7 = { 488bcb 664489642438 488bf0 ff15???????? }
- $sequence_8 = { 68ffff0000 56 8b35???????? ffd6 }
- $sequence_9 = { 85c0 7e18 80bc35a8feffff3a 741f 8d85a8feffff 46 50 }
- $sequence_10 = { c6840d8002000033 488d8d80020000 ff15???????? 4863c8 c6840d8002000079 }
- $sequence_11 = { ff15???????? 8b1d???????? 8d85a8feffff 50 ffd3 }
- $sequence_12 = { ff15???????? 4863c8 c6840d7002000062 488d8d70020000 ff15???????? 4863c8 }
- $sequence_13 = { ff15???????? 85c0 7426 8b400c }
- $sequence_14 = { 33f6 50 ffd3 85c0 7e18 }
- $sequence_15 = { 488d4c2460 ff15???????? 4863c8 807c0c5f5c 7413 488d4c2460 ff15???????? }
- $sequence_16 = { 41bc14030000 4c8d0574130100 488bcd 418bd4 e8???????? 33c9 85c0 }
- $sequence_17 = { 83c108 51 ff15???????? 8b4dfc }
- $sequence_18 = { 7370 696465726167656e 742e 657865 }
- $sequence_19 = { 6e 6d 656e 7400 }
- $sequence_20 = { 8b4510 8b8c8d78feffff 890c90 ebc8 e9???????? }
- $sequence_21 = { 7647 498bcd e8???????? 4c8d05b7120100 41b903000000 }
- $sequence_22 = { fa fa fa fa fa fa }
- $sequence_23 = { 8b4df0 e8???????? 8d45f8 50 6a00 }
- $sequence_24 = { 6828010000 8d85ccfeffff 6a00 50 }
- $sequence_25 = { 418d7c24e7 85c0 752a 4c8d0502130100 8bd7 498bcd }
- $sequence_26 = { 4c8d056c120100 498bd4 488bcd e8???????? 85c0 7541 4c8bc3 }
- $sequence_27 = { 636373 7673 6873742e65 7865 }
- $sequence_28 = { ff15???????? 8b45f4 8b4824 894dfc 8b55f4 83c208 }
- $sequence_29 = { 8945fc eb42 8b45f8 33d2 }
- $sequence_30 = { 8bd9 488d0d950c0100 ff15???????? 4885c0 7419 488d15730c0100 488bc8 }
- $sequence_31 = { 488d15f8110100 41b810200100 488bcd e8???????? e9???????? 4533c9 4533c0 }
- $sequence_32 = { 8b8504ffffff 898574feffff 8b4d0c 8b91fc020000 8b4508 0390f0040000 8b4d10 }
- $sequence_33 = { 488bcd e8???????? 85c0 751a 488d15f8110100 41b810200100 }
- $sequence_34 = { 8b55fc 83c208 52 ff15???????? 8b45fc c7400421000000 }
- $sequence_35 = { 33c9 4889742420 e8???????? cc 4c8d056c120100 }
- $sequence_36 = { 83ec08 894df8 c745fc00a40000 6a40 6800100000 6800a40000 6a00 }
- $sequence_37 = { 49 53 53 56 43 }
- $sequence_38 = { 8b4c2414 33cc e8???????? 8be5 5d c21000 57 }
- $sequence_39 = { 0115???????? 1515151503 1515151515 1515041515 1515050607 0809 }
- $sequence_40 = { 8d85e8feffff 50 ff95e4feffff 59 59 837d1c00 7513 }
- $sequence_41 = { 8b8431f4dfffff 44 2bd8 45 2b9c31f8dfffff 45 895c2404 }
- $sequence_42 = { 6a00 8d442448 50 ff15???????? 85c0 7420 }
- $sequence_43 = { 8b4c2408 49 8b542410 e8???????? 85c0 74db 89c0 }
- $sequence_44 = { f7f7 8365ec00 85c0 0f8e94010000 8365f000 8b7e44 }
- $sequence_45 = { 89f1 48 8d5510 e8???????? 90 e8???????? bab3c4b3c4 }
- $sequence_46 = { 6a00 8d85b0feffff 50 56 }
- $sequence_47 = { 6a00 56 c785b4feffff00000000 ff15???????? 50 56 }
- $sequence_48 = { 8d44245c 50 ff15???????? 33c0 5f }
- $sequence_49 = { c744241030000000 c744241403000000 c7442418d0114000 c744241c00000000 c744242000000000 89742424 c744242800000000 }
+ $sequence_0 = { 8b55c8 897150 895154 8b75cc 8b55d0 897158 89515c }
+ $sequence_1 = { ba???????? 0f2840f0 0f2808 0f298424a0040000 0f294910 0f2901 6a00 }
+ $sequence_2 = { c1e104 85c0 f20f10840b90000000 f20f108c0b98000000 f20f118c2488000000 f20f11842480000000 f20f10442450 }
+ $sequence_3 = { c1ea04 85d2 0f44d1 0f44f0 89d1 c1e902 6afe }
+ $sequence_4 = { 8b3e e8???????? 84c0 7404 c6470401 8b06 8b08 }
+ $sequence_5 = { 89d3 8954241c 897c2420 c744241801000000 89f1 e8???????? 3c0f }
+ $sequence_6 = { f20f114d9c f20f115594 7514 31d2 8d4ddc 42 e8???????? }
+ $sequence_7 = { e9???????? 8d7c2448 89f9 e8???????? 833f01 0f85ed000000 }
+ $sequence_8 = { 56 53 57 ff750c 50 e8???????? 83c424 }
+ $sequence_9 = { 898d40feffff 89f9 8985d4feffff 8b8570ffffff 8985d8feffff 8b4588 8985dcfeffff }
condition:
- 7 of them and filesize <417792
+ 7 of them and filesize <598016
}
-rule MALPEDIA_Win_Xiangoop_Auto : FILE
+rule MALPEDIA_Win_Polyvice_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bc98151f-3c19-5785-9ae3-c69b23dbc040"
+ id = "f632496e-a2f4-5ede-b8be-18463e7a5bac"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xiangoop"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xiangoop_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.polyvice"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.polyvice_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "94fbd52db4d5481176ad7bfd7bb74c96cb0ad2e3aa8f7b123dd0955d4f95f88c"
+ logic_hash = "ed3286a18e97148fc13382a255519a25655dd929e966c75502c6a665bf5d62e5"
score = 75
quality = 75
tags = "FILE"
@@ -137875,32 +144867,32 @@ rule MALPEDIA_Win_Xiangoop_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b801000000 d1e0 8b55f4 0fb6440208 25ff000000 }
- $sequence_1 = { c1e903 8d540906 8b4508 8990e0010000 c745ec00000000 8b4d08 }
- $sequence_2 = { ebe3 8b45f0 8b0c85a8b00110 8b45ec 807c082800 }
- $sequence_3 = { c1e008 0bc8 ba01000000 6bc203 8b550c 0fb644020c 25ff000000 }
- $sequence_4 = { 8955c8 6804010000 8d85bcfdffff 50 8b4dc8 }
- $sequence_5 = { 81e2ff000000 b801000000 6bc800 8b4510 8854080c 8b4dec }
- $sequence_6 = { c3 b001 c3 c705????????80a50110 b001 c3 68???????? }
- $sequence_7 = { 8b45fc 8b4dfc 034804 894dfc e9???????? b801000000 8be5 }
- $sequence_8 = { 890c02 8b45ec 83c001 8945ec 837dec08 7502 }
- $sequence_9 = { 8b45f4 83c028 8945f4 ebcb }
+ $sequence_0 = { 4589cf 4131ed 41c1cf06 4501e5 4589fc 4589cf 41c1cf0b }
+ $sequence_1 = { c1c207 31d1 4489c2 c1ca02 01f1 89d6 }
+ $sequence_2 = { 448b442438 01d1 01c1 4489c2 4489c0 c1c807 }
+ $sequence_3 = { 4409f6 89f5 89c6 4421f6 4421e5 09f5 4489de }
+ $sequence_4 = { 4c8d150fc20000 4801de 4c8d0d05ca0000 4c8d05fec50000 4883c310 8b3b 89f9 }
+ $sequence_5 = { 66418949fe 89e9 d3e8 4d39cb 75e2 4889d8 4829f0 }
+ $sequence_6 = { e9???????? 488d4dcc 31f6 e8???????? 4c8d3531650000 4989c5 eb2d }
+ $sequence_7 = { 53 4881ec38030000 488dac2480000000 410fb7400c 410fb77840 450fb77822 668945bc }
+ $sequence_8 = { 450fb6ec bf20000000 c744242800000000 0fb7db 4531ff }
+ $sequence_9 = { 0fb7c9 0fb74c4b02 664183f802 7508 6683f902 410f44c3 450fb7ed }
condition:
- 7 of them and filesize <246784
+ 7 of them and filesize <369664
}
-rule MALPEDIA_Win_Regin_Auto : FILE
+rule MALPEDIA_Win_Powerpool_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ce7821ca-cfed-5ada-bd4c-3b99c9cf64f9"
+ id = "0805ab0c-2483-51ef-91bd-613062750253"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.regin"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.regin_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.powerpool"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.powerpool_auto.yar#L1-L157"
license_url = "N/A"
- logic_hash = "985ecd1548d174f4606bb21325679aedf195f3d6056cd99e3d5f01bd16dfaa46"
+ logic_hash = "c10aba7ea9fc986a00a689a799239b370f623f0a4bcaeb12871b3235333f8df6"
score = 75
quality = 75
tags = "FILE"
@@ -137914,32 +144906,38 @@ rule MALPEDIA_Win_Regin_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 49 8363f000 48 8d0504230000 49 8943d8 }
- $sequence_1 = { 48 89442438 b800210000 c7442430204e0000 89442428 }
- $sequence_2 = { 85c0 740c 8b05???????? 39442460 7405 }
- $sequence_3 = { c1e802 41 ffc0 48 8d4c2470 41 }
- $sequence_4 = { 44 8bc1 48 8b0d???????? ff15???????? }
- $sequence_5 = { 48 89442448 48 89442450 b82375f1ba }
- $sequence_6 = { 33c0 48 83c428 c3 48 83ec28 33c9 }
- $sequence_7 = { 0f45df 8bc3 48 8b5c2448 }
- $sequence_8 = { 84c0 44 8d7304 0f45f8 8d4302 44 84c0 }
- $sequence_9 = { 48 8bfb 8bc7 48 8b5c2430 48 }
+ $sequence_0 = { 741f 90 8b4e54 8a01 }
+ $sequence_1 = { 7420 8b4514 8b4dfc 81c12c020000 }
+ $sequence_2 = { 895de8 8b5dcc 2bd8 895940 8b5dd0 }
+ $sequence_3 = { 005311 40 005d11 40 006711 }
+ $sequence_4 = { 7420 83e91d 7412 83e903 0f8515010000 c745dcfcae4400 }
+ $sequence_5 = { 7420 3c0a 740c 6a0a 6a01 8d4b14 }
+ $sequence_6 = { 741f d945b8 03c0 03c0 }
+ $sequence_7 = { 8b5c2410 23da c1ce0a 03f2 23ee 0bdd 035c2418 }
+ $sequence_8 = { 895dd0 8b7940 897dcc 3bc7 7613 }
+ $sequence_9 = { 7420 807de000 741a 8b4ddc }
+ $sequence_10 = { 006711 40 0000 0303 }
+ $sequence_11 = { 7420 8b4508 8b4d0c 3bc1 }
+ $sequence_12 = { 895ddc 895dfc 8d45e0 50 }
+ $sequence_13 = { 895de0 895de4 33c9 66898dd0fdffff }
+ $sequence_14 = { 895ddc 8b45e4 50 e8???????? }
+ $sequence_15 = { 744f 53 57 8bff 8bc8 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <819200
}
-rule MALPEDIA_Win_Purplewave_Auto : FILE
+rule MALPEDIA_Win_Dnschanger_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bc61a32f-ee96-5e25-892f-9d381408f659"
+ id = "ae807a62-5d4f-55b1-a240-1c49a1caed44"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.purplewave"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.purplewave_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dnschanger"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dnschanger_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "5efe0dc0002836bd228e34e2c06d2e0edc1c85c62aac77610517f67f8f987125"
+ logic_hash = "6d81d999d3cf2fb8d24f1a3cbe10fc2c3244404cd2fbc45cfa8a36930b442d5e"
score = 75
quality = 75
tags = "FILE"
@@ -137953,32 +144951,32 @@ rule MALPEDIA_Win_Purplewave_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8d4da4 c645fc12 e8???????? 84db 0f84ca020000 6a40 }
- $sequence_1 = { 0f8415000000 81a53cffffffffbfffff 8d8da8feffff e9???????? c3 8d8d60feffff e9???????? }
- $sequence_2 = { 8d8c2468010000 e8???????? 6a0d e8???????? 59 56 8bd0 }
- $sequence_3 = { 6bc838 57 8b0495201e4900 8a440828 a848 757b 84c0 }
- $sequence_4 = { 8d4dbc e8???????? 8d4dd4 e8???????? 8bc3 e8???????? c20c00 }
- $sequence_5 = { b8???????? e8???????? 8bf9 8db78c000000 8bce e8???????? 84c0 }
- $sequence_6 = { 53 50 e8???????? 83c40c 8d8db8feffff e8???????? 8d95b8feffff }
- $sequence_7 = { 53 68???????? 50 ff5110 ff758c ffd6 50 }
- $sequence_8 = { 0f85d3000000 8d45e8 50 8b06 8b08 83c128 }
- $sequence_9 = { 84c0 750e 8d45d8 50 8d4e6c e8???????? eb49 }
+ $sequence_0 = { ff15???????? 8bf0 8b442414 6800010000 }
+ $sequence_1 = { b301 57 ff15???????? 85f6 740c 56 6a00 }
+ $sequence_2 = { 8bc2 03c7 eb02 8bc7 5f }
+ $sequence_3 = { be04000000 5f 8bc6 5e 81c494000000 }
+ $sequence_4 = { ff7508 66ab aa ff15???????? }
+ $sequence_5 = { 8b542408 53 8a1a 8819 41 42 84db }
+ $sequence_6 = { 3b0e 72f2 57 57 57 }
+ $sequence_7 = { 57 57 56 57 ff75fc ff15???????? }
+ $sequence_8 = { 5e 81c494000000 c3 83f806 }
+ $sequence_9 = { f3aa 8bc6 5f 5e c3 }
condition:
- 7 of them and filesize <1400832
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Boaxxe_Auto : FILE
+rule MALPEDIA_Win_Lunchmoney_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d2861d72-2434-5a6e-bbf4-9290c68bd235"
+ id = "8af393b3-e0ee-5b29-9ae9-6b5b0b5bb360"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.boaxxe"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.boaxxe_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lunchmoney"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lunchmoney_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "232a66e4610caa68487a07fb0b6c51bc622cacc6954ed1eec17df693514e555a"
+ logic_hash = "4e3c0ce49996288518b2f9a0e709877b3f945a71128e29da2214bd53e19246e9"
score = 75
quality = 75
tags = "FILE"
@@ -137992,32 +144990,32 @@ rule MALPEDIA_Win_Boaxxe_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b904000000 e8???????? 8d55c4 66b8c503 e8???????? 8b55c4 a1???????? }
- $sequence_1 = { 0f8c88000000 8d4df4 8b55f8 8b45f8 e8???????? 8b55f4 8d45f8 }
- $sequence_2 = { 83c220 8d45f8 e8???????? 8d45f8 e8???????? 8945f4 8b45f4 }
- $sequence_3 = { 33c0 55 68???????? 64ff30 648920 8bcb b230 }
- $sequence_4 = { 85db 7410 8b55f4 8b45ec 8bcb e8???????? }
- $sequence_5 = { 8b45cc e8???????? 8bd8 891d???????? 891d???????? 8d45c8 50 }
- $sequence_6 = { 01d0 c1e003 8b803c58bc6d 8945ec e9???????? 837de808 }
- $sequence_7 = { a1???????? e8???????? 8bd0 53 8bc2 e9???????? 33c0 }
- $sequence_8 = { 0342fc 8945ec 8b45f8 8b00 8b5508 0342fc 8945f0 }
- $sequence_9 = { b808000000 e8???????? 8b55f8 58 e8???????? 7504 33db }
+ $sequence_0 = { 8b4304 8d4b0c 83791408 8945dc 8b4308 8945e0 7202 }
+ $sequence_1 = { 7405 e8???????? a900000080 751f d9fa 833d????????00 0f85f38b0000 }
+ $sequence_2 = { c1e60a 56 e8???????? 56 8bf8 6a00 57 }
+ $sequence_3 = { 53 8d4d08 e8???????? 83f8ff 750e 68???????? }
+ $sequence_4 = { 8d4dd4 e8???????? 83f8ff 742d 6aff 40 }
+ $sequence_5 = { 7420 53 8d85dcfeffff 50 }
+ $sequence_6 = { ff7580 e8???????? 8b8568ffffff 014588 59 83957cffffff00 837d0800 }
+ $sequence_7 = { 8bcf e8???????? 837f1408 8bc8 }
+ $sequence_8 = { 8bc3 e8???????? c3 53 56 8bf1 57 }
+ $sequence_9 = { 8d86f8000000 83c124 3bc8 740a 6aff 6a00 50 }
condition:
- 7 of them and filesize <1146880
+ 7 of them and filesize <373760
}
-rule MALPEDIA_Win_Lyposit_Auto : FILE
+rule MALPEDIA_Win_Metadatabin_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bce51077-57cf-5adb-b910-01a9e65c59f7"
+ id = "ddd31612-5b1e-5a32-9ee2-3a06fec41c32"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lyposit"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lyposit_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.metadatabin"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.metadatabin_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "6d3a7a695e65723557f6178bebcb83673702ff3e28dbc2c0dd967dcfab1ce86b"
+ logic_hash = "11b64ee680ef1e61921c6aade590c08f83cd6a9ae0a068d4e02dca568fca78c2"
score = 75
quality = 75
tags = "FILE"
@@ -138031,32 +145029,32 @@ rule MALPEDIA_Win_Lyposit_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff510c 3bc3 0f8cf1000000 57 6a40 ffd6 8945dc }
- $sequence_1 = { ff74240c 50 e8???????? a3???????? 59 }
- $sequence_2 = { 33f6 8975d8 8975fc b9???????? e8???????? 50 e8???????? }
- $sequence_3 = { 6a01 e8???????? 83c40c 397d10 7413 ff7510 }
- $sequence_4 = { ff15???????? 8bf8 8975d8 6a04 803e55 7506 8d4601 }
- $sequence_5 = { 83c40c 83f801 0f8556010000 015f3c 295f58 807f6c00 }
- $sequence_6 = { 0f8479010000 8bd8 8b5768 03573c 8b4760 33f6 }
- $sequence_7 = { 29775c 0175fc 837df801 894750 8b475c 743e }
- $sequence_8 = { e8???????? 8945c4 8d4de0 51 ff75d0 56 }
- $sequence_9 = { 8bfe e8???????? 33c0 eb0f 6a08 6a40 ffd3 }
+ $sequence_0 = { 89d1 89c6 8b8424d0000000 11d9 0f92c3 f7e7 89c7 }
+ $sequence_1 = { 8bbde8feffff 0f44c8 01fa 39da 0f4cd3 85ff 0f45da }
+ $sequence_2 = { 8b8c2488000000 13442448 897c243c 660f6e4c243c 89f7 8b74245c 83d300 }
+ $sequence_3 = { 8b742414 8b542424 39de 0f841c010000 0f836e010000 0fb7447430 0512230000 }
+ $sequence_4 = { 8b85f8feffff c744240800000000 895c2404 890424 ff95f4feffff c785fcfeffff01000000 8b8568feffff }
+ $sequence_5 = { f7e3 8b5c2470 01c8 89842458010000 0fb6442428 11c2 89d8 }
+ $sequence_6 = { 897c240c 89fa 89c7 b8ffff0700 660f6e8c2420010000 83d700 660f6e5c240c }
+ $sequence_7 = { 8d34c0 89442424 01f6 01d1 8b542408 11fe 8b7c241c }
+ $sequence_8 = { 89d3 89442418 89f8 039c2480010000 83d100 f7642460 01d8 }
+ $sequence_9 = { 660f70d044 660fefe6 f30f6fb42460050000 660fdbe2 660fefdc 660fefa424a0000000 660f6fc1 }
condition:
- 7 of them and filesize <466944
+ 7 of them and filesize <1263616
}
-rule MALPEDIA_Win_Orangeade_Auto : FILE
+rule MALPEDIA_Win_Romcom_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a790e493-320f-57de-9b62-d13796c94676"
+ id = "38f54401-b8aa-5a45-84bf-23c46fbb1d9b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.orangeade"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.orangeade_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.romcom_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.romcom_rat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "bc9cfd6680cc4f32cd41e9edf43afa43b54975c598906df96ea95e31fa6c1612"
+ logic_hash = "0162bd825b9587687f6d0e11e69966dd0894464ab2922749a2bae5afcccbf5b8"
score = 75
quality = 75
tags = "FILE"
@@ -138070,32 +145068,32 @@ rule MALPEDIA_Win_Orangeade_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bb42428050000 50 8bce e8???????? c744241001000000 }
- $sequence_1 = { 50 8d942470020000 51 52 ff15???????? }
- $sequence_2 = { f3ab 66ab aa 8d842468020000 50 }
- $sequence_3 = { 6881000000 6a00 c784249428010000000000 ff15???????? 8bf0 56 }
- $sequence_4 = { aa b93f000000 33c0 8dbc2465010000 }
- $sequence_5 = { 8d4c2424 c684248828010002 e8???????? 8d4c2410 c684248828010001 e8???????? 8d4c2414 }
- $sequence_6 = { b93f000000 33c0 8d7c2479 885c2478 f3ab }
- $sequence_7 = { 68???????? 8d4c2410 e8???????? 68???????? 6884000000 53 ff15???????? }
- $sequence_8 = { e8???????? 83c404 8d4c2424 c684248828010002 }
- $sequence_9 = { 50 8d4c2410 c684248400000001 e8???????? }
+ $sequence_0 = { b910000000 e8???????? 488945a0 4885c0 7410 44897008 488d0d6fc20400 }
+ $sequence_1 = { d3e8 49895108 418901 49895110 0fb60a 83e10f 4a0fbe8401a0ac0600 }
+ $sequence_2 = { 488d95e0310000 488d4dc0 e8???????? 448bc6 33d2 488d8de0310000 e8???????? }
+ $sequence_3 = { 488b01 488b4030 ff15???????? 83f8ff 7406 41884709 eb03 }
+ $sequence_4 = { 482bc1 4883c0f8 4883f81f 0f877d030000 e8???????? 488d4580 48837d9808 }
+ $sequence_5 = { 8a4709 3a4508 744b 84c9 7542 488b0f 4885c9 }
+ $sequence_6 = { 488d0dbac50400 488908 eb03 498bc6 4c8bc3 488bd0 488bcf }
+ $sequence_7 = { eb04 4d895d00 b801000000 41884508 488b542468 eb05 b801000000 }
+ $sequence_8 = { f20f10fc f20f58cc f20f10d1 f20f10c1 4c8d0d39090300 f20f101d???????? f20f100d???????? }
+ $sequence_9 = { 7510 488d0d12c90500 e8???????? 85c0 742e 32c0 eb33 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <1211392
}
-rule MALPEDIA_Win_Zxxz_Auto : FILE
+rule MALPEDIA_Win_Svcready_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "47a6bdd7-280d-5812-824e-6730815c0329"
+ id = "18ab3505-c0ef-5267-b797-184b8eb52424"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zxxz"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zxxz_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.svcready"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.svcready_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "1197698292204c5d5bb6df77b7c0541f4794374692dc94417033752fb1a653dc"
+ logic_hash = "e011f730891f501adbcafbb04605066e1d9bcba49b0031ae67a9bae5fc387ad9"
score = 75
quality = 75
tags = "FILE"
@@ -138109,34 +145107,34 @@ rule MALPEDIA_Win_Zxxz_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 40 84c9 75ef bf???????? e8???????? 84c0 }
- $sequence_1 = { 8b4c244c 64890d00000000 59 5f 5e 5d 8b4c2434 }
- $sequence_2 = { be04010000 51 89742424 6689842424010000 e8???????? }
- $sequence_3 = { 84c9 75f9 2bc2 8bd0 33c0 33c9 }
- $sequence_4 = { c3 81ecc4010000 a1???????? 33c4 898424bc010000 }
- $sequence_5 = { 7424 8b1d???????? 8d54242c 57 }
- $sequence_6 = { ff15???????? 85c0 7539 3805???????? }
- $sequence_7 = { 7403 8811 41 40 803800 75f0 }
- $sequence_8 = { 681c020000 68???????? ffd6 83c40c 68???????? }
- $sequence_9 = { ff15???????? 8b3d???????? 8bf0 56 6a01 }
+ $sequence_0 = { 33c8 c1ca0d 33ce 8bc3 33c1 c1ce03 894c2418 }
+ $sequence_1 = { 83611000 c741140f000000 68???????? c60100 e8???????? 8365fc00 }
+ $sequence_2 = { 59 59 895dc0 895dc4 895dc8 8b4df4 8bc6 }
+ $sequence_3 = { 8904d1 56 ff742410 8d4f04 e8???????? 8b44240c 5f }
+ $sequence_4 = { 8bd8 8a0b 80f97f 0f855fffffff 8b54240c 8b4d18 }
+ $sequence_5 = { d1cb 33d5 8bc7 c1e003 33da c1cd07 }
+ $sequence_6 = { 33c3 8bd7 33c5 0bd3 8bda 0bd1 33d9 }
+ $sequence_7 = { e8???????? 83c414 eb1a 53 57 e8???????? 668b442430 }
+ $sequence_8 = { c645fc01 8d45d8 ff7508 53 6a10 83ec18 8bcc }
+ $sequence_9 = { 7607 bbffffff7f eb0a b816000000 3bd8 0f42d8 8d4b01 }
condition:
- 7 of them and filesize <4142080
+ 7 of them and filesize <1187840
}
-rule MALPEDIA_Win_Maggie_Auto : FILE
+rule MALPEDIA_Win_Graphdrop_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d5276a3c-46d0-5873-87dd-9d6cf0c2cf8b"
+ id = "9b2ea7f1-3511-52b3-a5e3-7dff660f4219"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maggie"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maggie_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphdrop"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graphdrop_auto.yar#L1-L112"
license_url = "N/A"
- logic_hash = "41d76bd3fbb547d408b10f3113f1f0a7db8f68879c6d91dc7c6cf7b7ea8b4803"
+ logic_hash = "f69680c5241d19c09af86db48aaa89e34bb562d83e95c226a91b7e2e978f1c7f"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -138148,34 +145146,34 @@ rule MALPEDIA_Win_Maggie_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? e8???????? 84c0 74ec e8???????? }
- $sequence_1 = { ff15???????? 83f8ff 750f ff15???????? 2d33270000 f7d8 1bc0 }
- $sequence_2 = { 83f8ff 750f ff15???????? 2d33270000 f7d8 1bc0 }
- $sequence_3 = { 750f ff15???????? 2d33270000 f7d8 1bc0 }
- $sequence_4 = { ff15???????? 83f8ff 750f ff15???????? 2d33270000 f7d8 }
- $sequence_5 = { 83f8ff 750f ff15???????? 2d33270000 f7d8 }
- $sequence_6 = { b8ff000000 663b05???????? 7505 e8???????? e8???????? 84c0 }
- $sequence_7 = { 663b05???????? 7505 e8???????? e8???????? 84c0 }
- $sequence_8 = { 7511 ff15???????? 85c0 7407 33c0 }
- $sequence_9 = { 7511 ff15???????? 85c0 7407 33c0 e9???????? }
+ $sequence_0 = { 4154 90 415c 90 }
+ $sequence_1 = { 4155 49c7c501000000 4150 4152 415a }
+ $sequence_2 = { 52 0f77 90 5a }
+ $sequence_3 = { 0f77 0f77 5b 0f77 }
+ $sequence_4 = { 49c7c501000000 4150 4152 415a 4158 }
+ $sequence_5 = { 52 50 58 5a 49ffc9 }
+ $sequence_6 = { 49c7c501000000 4150 4152 415a 4158 49ffcd }
+ $sequence_7 = { 4150 4152 415a 4158 }
+ $sequence_8 = { 4155 49c7c501000000 4150 4152 415a 4158 49ffcd }
+ $sequence_9 = { 4152 415a 4158 49ffcd }
condition:
- 7 of them and filesize <611328
+ 7 of them and filesize <4186112
}
-rule MALPEDIA_Win_Phorpiex_Auto : FILE
+rule MALPEDIA_Win_Cryptomix_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "eb226bf1-84a3-5e5c-8655-1f02f1d972a0"
+ id = "9865a2c1-f352-5196-8a74-a585373e6231"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phorpiex"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.phorpiex_auto.yar#L1-L284"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptomix"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptomix_auto.yar#L1-L173"
license_url = "N/A"
- logic_hash = "626e70970105507345b3f584dcd1a33bae9d4d1c587f31ce85f081908c2a5392"
+ logic_hash = "2b59fc336b11257878a1c3e0c2e35ea57cb53b57126b62f006b040ede13bda6d"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -138187,52 +145185,38 @@ rule MALPEDIA_Win_Phorpiex_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 ff15???????? ff15???????? 50 e8???????? }
- $sequence_1 = { ff15???????? 85c0 740f 6a07 }
- $sequence_2 = { ff15???????? 85c0 741f 6880000000 }
- $sequence_3 = { 6a20 6a00 6a00 6a00 8b5508 52 6a00 }
- $sequence_4 = { e8???????? 83c410 6a00 6a02 6a02 6a00 6a00 }
- $sequence_5 = { 6a01 6a00 68???????? e8???????? 83c40c 33c0 }
- $sequence_6 = { e8???????? 99 b90d000000 f7f9 }
- $sequence_7 = { 52 ff15???????? 6a00 6a00 6a00 6a00 68???????? }
- $sequence_8 = { 50 e8???????? 83c404 e8???????? e8???????? ff15???????? }
- $sequence_9 = { 68???????? ff15???????? 8d85f8fdffff 50 68???????? }
- $sequence_10 = { 6a00 ff15???????? 85c0 7418 ff15???????? }
- $sequence_11 = { 6a01 ff15???????? ff15???????? b001 }
- $sequence_12 = { 6a00 682a800000 6a00 ff15???????? }
- $sequence_13 = { 52 683f000f00 6a00 68???????? 6802000080 ff15???????? 85c0 }
- $sequence_14 = { 68???????? ff15???????? e9???????? 8d45fc }
- $sequence_15 = { 50 ff15???????? 8945fc 837dfc00 7416 8b4df8 }
- $sequence_16 = { f7f9 81c210270000 52 e8???????? }
- $sequence_17 = { e8???????? 99 b930750000 f7f9 81c210270000 }
- $sequence_18 = { 50 e8???????? 59 59 85c0 7573 }
- $sequence_19 = { 3d00010000 7504 83c8ff c3 8b542404 }
- $sequence_20 = { 7508 6a00 ff15???????? 6804010000 }
- $sequence_21 = { 6a21 50 e8???????? c60000 }
- $sequence_22 = { e8???????? 83c41c 6880000000 8d4c240c 51 ff15???????? 6a00 }
- $sequence_23 = { 52 e8???????? 99 b960ea0000 f7f9 }
- $sequence_24 = { 6880000000 8d8424b4000000 50 6a0c 8d4c2420 51 6800142d00 }
- $sequence_25 = { 83790c00 7419 83791800 7418 83c130 83c004 81f9???????? }
- $sequence_26 = { 72f7 53 33c0 56 57 663bc2 }
- $sequence_27 = { 56 57 68e8030000 ff15???????? e8???????? be???????? }
- $sequence_28 = { 50 8d45ec 50 6805000020 }
- $sequence_29 = { 8d45f8 50 8d45e4 50 6805000020 }
+ $sequence_0 = { c3 68f0767c2a 6a04 e8???????? 59 59 }
+ $sequence_1 = { 02f8 0fb6cf 8d7601 0fb60439 8846ff 881439 33c9 }
+ $sequence_2 = { e8???????? 59 eb03 8b5df0 ff75f8 e8???????? }
+ $sequence_3 = { 7504 6a08 eb35 83f804 }
+ $sequence_4 = { ff4d08 8b4dfc 8ad8 75cc 5f }
+ $sequence_5 = { 59 59 ffd0 83f87a 7413 56 57 }
+ $sequence_6 = { 56 683f000f00 56 56 56 53 57 }
+ $sequence_7 = { ffd0 c3 686ea4ffa5 6a05 }
+ $sequence_8 = { ffd6 85c0 0f856a010000 68???????? 8d85c4f9ffff }
+ $sequence_9 = { 837d0c01 8bbdb8f9ffff a1???????? 68???????? }
+ $sequence_10 = { 68???????? 57 ffd0 ff75fc e8???????? }
+ $sequence_11 = { 8bf1 6a01 899584efffff 89b58cefffff 898588efffff ff15???????? 6808020000 }
+ $sequence_12 = { 8d85c4f9ffff 50 ffd7 85c0 7460 68???????? }
+ $sequence_13 = { 8b35???????? 68007d0000 6a40 c745f8e8030000 }
+ $sequence_14 = { 6a00 6a00 ff15???????? 6896000000 ff15???????? 8b9d80efffff 8d8598f9ffff }
+ $sequence_15 = { 68???????? 56 e8???????? 59 59 85c0 7759 }
condition:
- 7 of them and filesize <2490368
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Darkdew_Auto : FILE
+rule MALPEDIA_Win_Magala_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0ed49e32-b5ea-5f63-b18e-3ccfdc3576f0"
+ id = "57b76c6b-52c3-5f25-9fd2-257d2fe2adf4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkdew"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkdew_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.magala"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.magala_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "0cd505ddc1a03cf19308335c9ef43a0054cd013c3658d925b20aa0cf71f6aa36"
+ logic_hash = "bd9ee6cce82c810cf18ac629b3f76ce4da7e66a1f258b71b1396e2e5be340ce0"
score = 75
quality = 75
tags = "FILE"
@@ -138246,34 +145230,34 @@ rule MALPEDIA_Win_Darkdew_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b55d0 c745b400000000 c745b80f000000 c645a400 83fa08 722e 8b4dbc }
- $sequence_1 = { 03c0 660f283485c0840110 baef7f0000 2bd1 }
- $sequence_2 = { 7202 8b12 8bca c745ac00000000 33c0 c745b007000000 }
- $sequence_3 = { 8d4d9c 8d45d4 c78586feffff00000000 0f434d9c ba14060000 }
- $sequence_4 = { c645fc11 8b55cc 83fa08 7232 8b4db8 8d145502000000 8bc1 }
- $sequence_5 = { 6a00 ff15???????? cc 55 8bec 64a100000000 6aff }
- $sequence_6 = { b991000000 8dbc2470020000 8bf3 f3a5 8bf0 8dbc24b4040000 8d842480030000 }
- $sequence_7 = { e8???????? 8bf8 c645fc19 8d55d4 837de810 }
- $sequence_8 = { 85c0 0f8488000000 8b4df8 8d5823 8b55fc }
- $sequence_9 = { 8db3d0feffff 8bce 83e210 8d7901 0f1f4000 }
+ $sequence_0 = { 8b4004 838c054cffffff04 8b8538ffffff 8b4004 c6840578ffffff30 2b17 744e }
+ $sequence_1 = { 8b7dd0 3bdf 0f849d000000 33c0 c745e800000000 6aff 50 }
+ $sequence_2 = { 8bcf e8???????? 56 8bd0 c645fc0c 8d4da8 e8???????? }
+ $sequence_3 = { 8a55d8 c645fc00 83f810 7242 }
+ $sequence_4 = { e8???????? 8b4df8 83c40c 837e1410 894e10 7211 }
+ $sequence_5 = { 6685c0 75f4 a1???????? 8b550c }
+ $sequence_6 = { 6a01 50 8b08 ff513c 85c0 75b8 50 }
+ $sequence_7 = { 8995e0fdffff 8955fc 8b1d???????? 0f1f8000000000 }
+ $sequence_8 = { c745e800000000 c745ec0f000000 c645d800 e8???????? c745fc00000000 8d4e04 }
+ $sequence_9 = { e8???????? 8b4df8 b853d9de75 8b75f4 33db 2bce f7e9 }
condition:
- 7 of them and filesize <279552
+ 7 of them and filesize <589824
}
-rule MALPEDIA_Win_Winmm_Auto : FILE
+rule MALPEDIA_Win_Nexster_Bot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e5922e79-076b-5a5c-ba27-8c0bb532ca1f"
+ id = "f3849f7f-92fa-5a27-8fce-5cf70a6092f1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winmm"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.winmm_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nexster_bot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nexster_bot_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "9d8038e46a83e5b1250014db0840b8d665afb5078d6d9005cce493b4024246af"
- score = 60
- quality = 35
+ logic_hash = "68d99297d7676950ef20645c2f54f180e697aada925cf75041287d48b2b4b344"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -138285,32 +145269,32 @@ rule MALPEDIA_Win_Winmm_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 740c 663d3000 7406 663d2000 750b 668b042e 03f5 }
- $sequence_1 = { 03ce 7504 33c0 5e }
- $sequence_2 = { 7d03 6a01 5f 85ff 0f8449ffffff }
- $sequence_3 = { 89462c ff15???????? 8bce 894604 e8???????? 85c0 }
- $sequence_4 = { 8bc8 ff5274 c3 33c0 c3 c3 56 }
- $sequence_5 = { 83c308 bf80000000 eb1d 83e86e }
- $sequence_6 = { e8???????? 59 eb1d 6a02 83c304 5f }
- $sequence_7 = { 663d2000 750b 668b042e 03f5 663bc7 75c0 397c2428 }
- $sequence_8 = { 7c02 8bfd 3b7c2428 7f5a 8b7c2428 }
- $sequence_9 = { 83c40c 85c0 752d 83c606 }
+ $sequence_0 = { 52 e8???????? 68ff030000 8d85bd090000 }
+ $sequence_1 = { ff15???????? 668985ae010000 6a10 8d85ac010000 50 57 }
+ $sequence_2 = { 7d10 668b4c4310 66890c45186e4100 40 ebe8 33c0 }
+ $sequence_3 = { 03f9 837d1810 7208 8b5d04 }
+ $sequence_4 = { 33c0 8da42400000000 8a1485d0604100 889405000e0000 40 83f80b }
+ $sequence_5 = { 731a 8bc8 83e01f c1f905 8b0c8d20804100 c1e006 03c1 }
+ $sequence_6 = { 81c404040000 c3 53 56 57 8bf8 }
+ $sequence_7 = { 66898c24bc010000 e9???????? 8b15???????? a1???????? 8b0d???????? 899424b0010000 }
+ $sequence_8 = { 68???????? 52 e8???????? 68???????? 8d85bc110000 50 }
+ $sequence_9 = { 8a08 40 84c9 75f9 8dbdbc150000 2bc6 4f }
condition:
- 7 of them and filesize <278528
+ 7 of them and filesize <245760
}
-rule MALPEDIA_Win_Atlas_Agent_Auto : FILE
+rule MALPEDIA_Win_Orcarat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "31d9d19b-f3ba-501d-964d-67da428e9e82"
+ id = "2de223cb-857a-5d4b-8d3a-323fa4ad4ded"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atlas_agent"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atlas_agent_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.orcarat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.orcarat_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "49564f12d410922863a80d6084c9c71952a7f941729a00c4d7e4e12f95d889bc"
+ logic_hash = "12ec16d312c505ceab125190551fe03bd174598263e03e7c0fe4b3239bc4fe94"
score = 75
quality = 75
tags = "FILE"
@@ -138324,38 +145308,34 @@ rule MALPEDIA_Win_Atlas_Agent_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb60c0a 83e13c c1f902 03c1 }
- $sequence_1 = { 8bc1 99 b903000000 f7f9 c1e002 }
- $sequence_2 = { 4c8b8424c8000000 488b9424c0000000 488b8c2480000000 e8???????? 89442460 }
- $sequence_3 = { 4c8b8424e0000000 488b9424d8000000 488b4c2468 e8???????? }
- $sequence_4 = { 89857cffffff c645fc06 83bd7cffffff00 7417 }
- $sequence_5 = { 898584feffff 8b8584feffff 50 8d8dd4feffff }
- $sequence_6 = { 898588f8ffff 8b9588f8ffff 899584f8ffff c645fc07 }
- $sequence_7 = { 4c8b8424f0000000 488b942488000000 488b8c24e0000000 e8???????? }
- $sequence_8 = { 89857cffffff 83bd7cffffff1e 7302 eb05 }
- $sequence_9 = { 4c8b8424f8000000 488b942400010000 488d8c24f0030000 e8???????? }
- $sequence_10 = { 89857cffffff 8b8d18ffffff 894d80 83bd7cffffff00 }
- $sequence_11 = { 4c8b8c2408010000 4c8d05c2930400 ba40000000 488d4c2470 }
- $sequence_12 = { 89857cffffff 895580 8b4580 3b45dc }
- $sequence_13 = { 4c8b8c2408010000 4c8d442460 488b9424f8000000 488b8c24f0000000 }
+ $sequence_0 = { f2ae 8d84242c110000 f7d1 50 894c2414 51 }
+ $sequence_1 = { 8d8c2418010000 50 51 8d842430110000 52 50 }
+ $sequence_2 = { 56 6a00 8d5708 6a10 }
+ $sequence_3 = { 53 8dbef4020000 51 50 }
+ $sequence_4 = { 8bf0 85f6 7451 8b442414 85c0 7421 }
+ $sequence_5 = { f2ae 8d442420 f7d1 50 894c2418 ff15???????? 50 }
+ $sequence_6 = { 303d???????? 40 00803d400023 d18a0688078a 46 018847018a46 }
+ $sequence_7 = { 5d 5b 81c418020000 c20400 6a01 8d142e }
+ $sequence_8 = { ff15???????? 85c0 0f849e010000 8b0f 53 6a01 51 }
+ $sequence_9 = { 33db 837d0000 762f 8d542410 c744241000000000 52 6800080000 }
condition:
- 7 of them and filesize <857088
+ 7 of them and filesize <114688
}
-rule MALPEDIA_Win_Phobos_Auto : FILE
+rule MALPEDIA_Win_Icedid_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b3fdfb89-c1ef-5439-9836-c8e32a8398db"
+ id = "f1fe8329-9566-5f3c-8226-7a3fb9936918"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phobos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.phobos_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.icedid"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.icedid_auto.yar#L1-L298"
license_url = "N/A"
- logic_hash = "2c179588b445524a4924d6ad3214734291e040f7e6e3be29f272840c2a179aff"
+ logic_hash = "35bc9d0f5535131e0ac355ad775af24bc4cac838dad6434eced01ac7afcde501"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -138367,32 +145347,54 @@ rule MALPEDIA_Win_Phobos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff75fc e8???????? 59 85c0 0f845c010000 395df8 0f8453010000 }
- $sequence_1 = { 59 8d4c0002 8bc7 2bc6 03c1 894ddc 897dd0 }
- $sequence_2 = { 8d5c3801 e8???????? 59 8945fc 8975e4 ff15???????? 6a40 }
- $sequence_3 = { 752e 6683f930 7409 c7450c0a000000 }
- $sequence_4 = { 53 56 c745a044000000 ff15???????? 8945fc 3bc6 }
- $sequence_5 = { 8bf8 57 897de0 e8???????? 83c40c 680a020000 8d5c3801 }
- $sequence_6 = { 8d45f4 50 53 ff15???????? 56 8b35???????? ffd6 }
- $sequence_7 = { 8bf3 2b7010 e8???????? f6472801 8d440006 59 8945fc }
- $sequence_8 = { 7423 a900040000 7518 8b06 ff750c 8b00 ff7020 }
- $sequence_9 = { 83c602 0fb716 83c702 6685d2 75e0 668b06 663b07 }
+ $sequence_0 = { 85c0 7511 56 57 ff15???????? }
+ $sequence_1 = { 50 6801000080 ff15???????? eb13 }
+ $sequence_2 = { 803e00 7427 6a3b 56 ff15???????? 8bf8 }
+ $sequence_3 = { ff15???????? 85c0 7420 837c241000 7419 }
+ $sequence_4 = { 56 ff15???????? 8bf8 85ff 7418 c60700 }
+ $sequence_5 = { 68???????? 6a00 ff15???????? 33c0 40 }
+ $sequence_6 = { 50 ff15???????? 8bf7 8bc6 eb02 }
+ $sequence_7 = { eb0f 6a08 ff15???????? 50 ff15???????? 8906 }
+ $sequence_8 = { e8???????? 8bf0 8d45fc 50 ff75fc 6a05 }
+ $sequence_9 = { 743f 8d5808 0fb713 8954241c }
+ $sequence_10 = { 03c2 eb5c 8d5004 89542414 8b12 85d2 }
+ $sequence_11 = { 66c16c241c0c 0fb7d2 c744241000100000 663b542410 }
+ $sequence_12 = { 47 83c302 3bfd 72c4 }
+ $sequence_13 = { 8d4508 50 0fb6440b34 50 }
+ $sequence_14 = { 89542414 8b12 85d2 7454 8d6af8 d1ed }
+ $sequence_15 = { 47 3b7820 72d1 5b 33c0 40 }
+ $sequence_16 = { ff5010 85c0 7407 33c0 e9???????? }
+ $sequence_17 = { 8a4173 a808 75f5 a804 7406 }
+ $sequence_18 = { ff15???????? 85c0 750a b8010000c0 }
+ $sequence_19 = { 41 02fd c6430503 eb21 41 0fb6c1 }
+ $sequence_20 = { 48 8bfa 48 8bf1 45 8d41ce e8???????? }
+ $sequence_21 = { 7407 41 2bcd 7515 eb0f 44 }
+ $sequence_22 = { 48 8d442458 48 8bf9 48 }
+ $sequence_23 = { 8bce 894348 48 8b15???????? }
+ $sequence_24 = { 7307 4c8b742420 eba1 488bb590020000 }
+ $sequence_25 = { 57 4883ec30 488bf2 488bd9 ff15???????? 4885c0 }
+ $sequence_26 = { 7409 8b4c2478 493b0e 741e 498b1f 4885db }
+ $sequence_27 = { 33d2 488bc8 ff15???????? 488bb590020000 4885f6 7414 ff15???????? }
+ $sequence_28 = { 33d2 488bce ff15???????? 8bd8 49891e 85c0 }
+ $sequence_29 = { 4533c0 c740c803000000 ba00000080 ff15???????? 488bf0 4883f8ff 7507 }
+ $sequence_30 = { 33ff 4d8bf0 482178d8 4c8bfa }
+ $sequence_31 = { 5d c3 488b0d???????? 488d050d1e0000 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <303104
}
-rule MALPEDIA_Win_Casper_Auto : FILE
+rule MALPEDIA_Win_Datper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "682d09f5-eba1-5466-8515-62dee225f20a"
+ id = "144df714-10f7-5eb5-ac00-48d1c0a0517d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.casper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.casper_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.datper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.datper_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "901b4babc945e8ca2e1c5355e28b2f0271cc8d172828c522a735944d40fb2e3b"
+ logic_hash = "96f11afeb919508bb147708a5d367711547bdbf470c62d9b42f3889c5cdbbcd4"
score = 75
quality = 75
tags = "FILE"
@@ -138406,32 +145408,32 @@ rule MALPEDIA_Win_Casper_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 47 57 50 6801000080 e8???????? 85c0 756f }
- $sequence_1 = { e8???????? 8b7b34 85ff 7405 e8???????? }
- $sequence_2 = { 885006 8b55fc c1ea18 885007 8bd3 c1ea08 885009 }
- $sequence_3 = { 51 a1???????? 85c0 751a e8???????? 689c9678bf 68???????? }
- $sequence_4 = { 837de803 752a 837df808 8b75f4 7514 85f6 742b }
- $sequence_5 = { 8bbb48010000 8b8b68010000 33d2 8bc7 f7f1 85d2 7406 }
- $sequence_6 = { 8bd8 8d4510 50 81ce19000200 }
- $sequence_7 = { 85ff 7405 e8???????? 8bce e8???????? 5f 5e }
- $sequence_8 = { 50 57 57 6800000008 53 57 57 }
- $sequence_9 = { 7504 8bde eb03 83c305 68???????? 53 e8???????? }
+ $sequence_0 = { 33c9 ba0c000000 e8???????? c78564d7ffff0c000000 33c0 898568d7ffff }
+ $sequence_1 = { 5a 59 59 648910 68???????? 8d85e8f3ffff }
+ $sequence_2 = { 0fb607 8845f7 0fb6c1 8b55fc 0fb60402 8807 }
+ $sequence_3 = { 50 ff15???????? 85c0 741f 8b8424a80d0000 894348 }
+ $sequence_4 = { 895de4 895de8 895df4 894df0 8955f8 8945fc 8d45fc }
+ $sequence_5 = { 53 e8???????? a3???????? 8d95a8fbffff b8???????? e8???????? 8b85a8fbffff }
+ $sequence_6 = { c78568d7ffff0c000000 33c0 89856cd7ffff c78570d7ffffffffffff 6a00 6a01 8d8568d7ffff }
+ $sequence_7 = { 8b45fc e8???????? 50 e8???????? 8d8564d7ffff 33c9 ba0c000000 }
+ $sequence_8 = { 8d85f0fbffff 50 53 e8???????? 8945f0 a1???????? 50 }
+ $sequence_9 = { 53 e8???????? 6800800000 6a00 56 }
condition:
- 7 of them and filesize <434176
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Mongall_Auto : FILE
+rule MALPEDIA_Win_Sfile_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "df02f29b-7e4c-5b43-ac4d-a0a6d3cf6ee1"
+ id = "2a05bff3-25b7-5fd3-9a80-0b0955cab792"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mongall"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mongall_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sfile"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sfile_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "09c3cb724c571a18322afe8d7b1ace648402df7ba3a7200f8ca50d9538f078c7"
+ logic_hash = "b6be99a284bb08bd87d7e6d12a69d9966762868a0d094add32f60ffa636331bd"
score = 75
quality = 75
tags = "FILE"
@@ -138445,32 +145447,32 @@ rule MALPEDIA_Win_Mongall_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8b400c 8b08 8b11 52 ff15???????? ba???????? }
- $sequence_1 = { 85ff 747c 56 57 68???????? e8???????? 68???????? }
- $sequence_2 = { f3a5 8bc8 8b8500d9ffff 83e103 43 }
- $sequence_3 = { 59 8985a0fdffff 3bc1 0f87cb090000 ff2485e6574000 838de8fdffffff 89b594fdffff }
- $sequence_4 = { 8bd8 83fbff 7448 68???????? e8???????? }
- $sequence_5 = { e8???????? 8bfc 85ff 741d 8b8df4fdffff 56 }
- $sequence_6 = { 56 8d45f0 33f6 50 8935???????? 8935???????? ff15???????? }
- $sequence_7 = { 8b7df0 8bc7 5f 5e c60300 }
- $sequence_8 = { 89b5e4fdffff 89b5e0fdffff 89b5c0fdffff 888deffdffff }
- $sequence_9 = { 85f6 5e 741d 8d85f8feffff }
+ $sequence_0 = { 50 e8???????? 8b4d08 8b5144 }
+ $sequence_1 = { 8b55fc 83c201 8955fc 837dfc08 7d12 }
+ $sequence_2 = { e8???????? 83c41c eb2b 837d0803 7525 }
+ $sequence_3 = { 8bec 83ec20 8b4508 8b888c050000 }
+ $sequence_4 = { eb13 8b55f8 8b4210 8d0c8510000000 }
+ $sequence_5 = { 51 ff15???????? 8b55f0 52 ff15???????? 8b45ec 50 }
+ $sequence_6 = { c745fc08000000 eb09 8b85b8fdffff 8945fc 8b4dfc 83c106 }
+ $sequence_7 = { 8d4c0002 8b55e8 894a04 8b45f8 }
+ $sequence_8 = { 68fc000000 8b4df0 8b11 52 }
+ $sequence_9 = { c60100 837dec00 7547 6af5 ff15???????? 8945f0 }
condition:
- 7 of them and filesize <199680
+ 7 of them and filesize <588800
}
-rule MALPEDIA_Win_Homefry_Auto : FILE
+rule MALPEDIA_Win_Mespinoza_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a10ca8d8-82df-517d-ba70-a87080178507"
+ id = "6af67872-bac6-59d0-8e7f-a6515453822a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.homefry"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.homefry_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mespinoza"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mespinoza_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "17959e0d47a35ecd2de71b5f2bf7c90338d7ed773cdd572cf03461913b5cbcc7"
+ logic_hash = "b9e1c3335fd9ffa3b60b976c6289b141c236447ff76a5dd17787957756af56c7"
score = 75
quality = 75
tags = "FILE"
@@ -138484,32 +145486,32 @@ rule MALPEDIA_Win_Homefry_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 4863d5 4803d0 488b05???????? 488917 48630a }
- $sequence_1 = { 4889b5f0020000 4803cb ff15???????? 85c0 7873 488b95f0020000 }
- $sequence_2 = { 740f 8bcf 4803cd 7408 }
- $sequence_3 = { 8b4c2470 ff15???????? 8b4c2478 488905???????? ff15???????? 488b0d???????? }
- $sequence_4 = { c705????????94000000 ff15???????? 33d2 8d4a02 ff15???????? 488bd8 }
- $sequence_5 = { e8???????? 84c0 0f8418010000 48833d????????00 48899c24a0000000 4889b424a8000000 7471 }
- $sequence_6 = { ff15???????? 488bcb ff15???????? 4881c420040000 }
- $sequence_7 = { 488bc8 e8???????? 84c0 7426 48630d???????? 488bc3 85c9 }
- $sequence_8 = { e8???????? eb05 e8???????? 84c0 7511 488d0ddd180000 }
- $sequence_9 = { 483bdd 72d0 488bcf ff15???????? 33c0 488b5c2430 488b6c2438 }
+ $sequence_0 = { 8d4d9c e8???????? 83eb01 75e7 8b4d0c }
+ $sequence_1 = { 897d0c c645fc01 85ff 7446 56 8bcf e8???????? }
+ $sequence_2 = { 8b4dc4 8b7dc0 6aff 6a01 }
+ $sequence_3 = { 891f 895f04 6a01 895dfc e8???????? 59 894704 }
+ $sequence_4 = { 03c1 3bc1 7334 8bde 8bf1 2bf0 }
+ $sequence_5 = { 75f9 2bd6 8db5f8feffff 8d5e01 8a06 46 84c0 }
+ $sequence_6 = { 83e03f 6bd030 895de4 8b049d00b04700 8945d4 8955e8 8a5c1029 }
+ $sequence_7 = { 8b6c240c 56 57 55 8bf9 e8???????? 8b37 }
+ $sequence_8 = { 64a300000000 8965f0 8b7508 8b7d0c 8975ec c745fc00000000 0f1f440000 }
+ $sequence_9 = { 8bc3 2bc2 894714 8b7508 8bce e8???????? 84c0 }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <1091584
}
-rule MALPEDIA_Win_Nimrev_Auto : FILE
+rule MALPEDIA_Win_Manjusaka_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "62b602c2-9378-5d4d-8f76-ba10a1fe3c95"
+ id = "9f188d62-91cb-5093-86fd-1c78b358599b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nimrev"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nimrev_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.manjusaka"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.manjusaka_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "276c930d9217520c07d5dbe59ac126b04c22edd3ab1aa62095745bbe5305f85e"
+ logic_hash = "dab9ae475e0b441f3d26af80a0ebc722e21c766bc33599d09d1c1a5353ad7516"
score = 75
quality = 75
tags = "FILE"
@@ -138523,32 +145525,32 @@ rule MALPEDIA_Win_Nimrev_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd0 90 e9???????? 90 b9d0070000 e8???????? }
- $sequence_1 = { c1e002 01d0 01c0 29c1 89c8 83c030 89c1 }
- $sequence_2 = { b801000000 eb05 b800000000 8845f7 eb01 90 }
- $sequence_3 = { b801000000 eb05 b800000000 8845f7 eb01 90 0fb645f7 }
- $sequence_4 = { eb05 b800000000 8845f7 eb01 90 }
- $sequence_5 = { 83f001 84c0 7408 90 }
- $sequence_6 = { 0fb600 3c7d 7407 b801000000 eb05 }
- $sequence_7 = { 89c1 e8???????? eb04 90 eb01 90 }
- $sequence_8 = { 3c7d 7407 b801000000 eb05 }
- $sequence_9 = { eb01 90 0fb645f6 8845f7 }
+ $sequence_0 = { ebb8 488d05b77a1000 4889442450 48c744245801000000 48c744246000000000 488d05f9b01100 4889442470 }
+ $sequence_1 = { 4c89bc2480040000 4c8939 4c897108 48895910 48c7411800800000 0f117018 48897930 }
+ $sequence_2 = { 791d 418b4128 41034124 4863c8 488bc2 48f7d8 48c1e00a }
+ $sequence_3 = { 89411c 488b45d7 2b4527 05feffff07 89710c 894120 8b45db }
+ $sequence_4 = { 4989f8 e8???????? 48ffcb 75ed 0f57f6 488d9c2410010000 0f297320 }
+ $sequence_5 = { 898c24f8000000 48896c2448 3b08 0f8c21fdffff 4c8bbc24f0000000 4d85f6 7424 }
+ $sequence_6 = { 814d4002020000 4533c0 48894500 498bcd 83c8ff 66894544 b8c8000000 }
+ $sequence_7 = { 89573c 48894740 895750 488b442e60 48894758 488b442e28 488b4860 }
+ $sequence_8 = { f7d8 894c2420 448bc5 498bcd 1bd2 4533c9 83e2fc }
+ $sequence_9 = { e8???????? 4889d9 e8???????? 488d4f70 e8???????? 488d8fe0000000 e8???????? }
condition:
- 7 of them and filesize <1141760
+ 7 of them and filesize <4772864
}
-rule MALPEDIA_Win_Biscuit_Auto : FILE
+rule MALPEDIA_Win_Payloadbin_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cbdd41f1-3e24-52e8-913d-0c21f28eadad"
+ id = "2565adb0-0fc6-53d7-a6d7-714ee1e92525"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.biscuit"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.biscuit_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.payloadbin"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.payloadbin_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "c4b7181ffb74601ad4f6fe9643262fda887ff950b5291eeca17cee75a1b1c812"
+ logic_hash = "23ee48d932fb0666838e9fe4bd35ace2ae0b6a999ccab2645c6692a493a38f19"
score = 75
quality = 75
tags = "FILE"
@@ -138562,32 +145564,32 @@ rule MALPEDIA_Win_Biscuit_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? a1???????? 898588feffff 83bd88feffff00 0f85bb010000 bf???????? }
- $sequence_1 = { 84c0 894b04 0f84e8feffff 8b542418 52 }
- $sequence_2 = { 8a54040c 40 f6d2 8854040b 3bc1 }
- $sequence_3 = { eb04 8b7c2424 8b4604 53 53 53 }
- $sequence_4 = { e9???????? 8b4de4 bf???????? 33c0 8d9980000000 83c9ff f2ae }
- $sequence_5 = { f2ae f7d1 49 3bd1 731f 8b7de0 8a0c1a }
- $sequence_6 = { 740e 68???????? 57 e8???????? 83c408 f60610 }
- $sequence_7 = { 899538feffff 83bd38feffff00 7511 8b85ccfeffff 2b45e4 8985c0feffff }
- $sequence_8 = { c1e902 f3a5 8bc8 83e103 f3a4 68c8000000 ff15???????? }
- $sequence_9 = { 8bcb e8???????? 84c0 7426 8b7b04 8bcd 8bd1 }
+ $sequence_0 = { eb05 bb08000000 488b0d???????? 4c8bc7 33d2 ff15???????? 413bdf }
+ $sequence_1 = { 668930 41c0f1c1 0fb70f 488bd7 450ad1 4c8bce 66410fabca }
+ $sequence_2 = { e9???????? 6644893c4f 660fc9 488bcf e9???????? ff15???????? e9???????? }
+ $sequence_3 = { f5 4803d5 e9???????? e8???????? 83c340 66413bf2 8d433f }
+ $sequence_4 = { c18c2400000000bb 48f79c2400000000 0f87deb91400 488d642418 9d }
+ $sequence_5 = { 4433c1 664133ce 418b0c84 d2e8 23cd 66410fbcc1 660bc4 }
+ $sequence_6 = { e8???????? c0a4241000000074 6873173773 48818424080000009c149337 49b90d1dba73583cde39 e8???????? 0f8867890000 }
+ $sequence_7 = { 41f6c593 483bc7 e9???????? 0f8482020000 488d4330 488d4b08 e9???????? }
+ $sequence_8 = { 8505bfcdef86 fb beae9070fe 40ad 6f }
+ $sequence_9 = { 6681ac2418000000ff28 4881842408000000b8559f29 e8???????? 9c 4881842408000000157db449 66818424100000001054 50 }
condition:
- 7 of them and filesize <180224
+ 7 of them and filesize <3761152
}
-rule MALPEDIA_Win_Locky_Auto : FILE
+rule MALPEDIA_Win_Webc2_Qbp_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0065ec05-3bad-56a6-868c-9fbbe2e6de6d"
+ id = "b171d237-d33f-5b2c-9bb0-c659a34a40b8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.locky"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.locky_auto.yar#L1-L170"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_qbp"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_qbp_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "3ed4a85dfe440bb226db6c3cc6e1aa5c521449c7aa69fbc084d35b1292d156c0"
+ logic_hash = "d54f700be976af1656f6aaefd7f02b0196b5db00252f63d6c12db29d09a9a088"
score = 75
quality = 75
tags = "FILE"
@@ -138601,38 +145603,32 @@ rule MALPEDIA_Win_Locky_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89b560ffffff 898568ffffff ffd7 8bf8 897de0 3bfb }
- $sequence_1 = { 8b4db8 3975cc 7303 8d4db8 8b45d4 3975e8 }
- $sequence_2 = { 50 50 50 894de8 8b4d08 }
- $sequence_3 = { 8d459c 50 8d45b8 50 e8???????? 59 59 }
- $sequence_4 = { 46 3bf0 7621 8bc8 d1e9 ba49922409 }
- $sequence_5 = { 8bc6 03c1 3810 7412 83ff10 7204 }
- $sequence_6 = { 837e1410 8b4610 7202 8b36 50 56 8d45f0 }
- $sequence_7 = { 83c9ff 8bf0 51 e8???????? 40 50 }
- $sequence_8 = { 03d3 5b c21000 e9???????? 8bff 55 8bec }
- $sequence_9 = { 6a44 90 e9???????? 90 }
- $sequence_10 = { 5d 90 ebf6 90 }
- $sequence_11 = { 83c40c e9???????? 90 8d00 }
- $sequence_12 = { 66ab e9???????? 90 8d36 }
- $sequence_13 = { ff15???????? e9???????? 90 50 90 }
- $sequence_14 = { 66ab 90 e9???????? 8d36 }
- $sequence_15 = { 5e c21000 8bff 55 8bec 33c0 8b4d08 }
+ $sequence_0 = { 85c0 7511 8d85e8fcffff 50 ff15???????? }
+ $sequence_1 = { 3b9090830000 0f8e9d000000 8b4df0 8b819c830000 0345fc 6bc003 99 }
+ $sequence_2 = { 83c40c c785e0fcffff01000000 ff15???????? 8985f4feffff 8b95e0fcffff 52 8b85f0feffff }
+ $sequence_3 = { b9fa000000 2bc8 898dd8fcffff 8b95e8fdffff 52 e8???????? 83c404 }
+ $sequence_4 = { 83ec0c 56 894df4 66c745fc0000 eb0c 668b45fc 66050100 }
+ $sequence_5 = { 85c0 746d 8d4dfc 51 8d55f8 52 e8???????? }
+ $sequence_6 = { 8b450c 25ffff0000 50 8b4dec 51 ff15???????? 8945fc }
+ $sequence_7 = { 0fbf4dec 3bc1 7d7d 8b4de4 e8???????? 668945f4 0fbf55f4 }
+ $sequence_8 = { 81eafd000000 668955ec 66c745e80000 eb0c 668b45e8 66050100 668945e8 }
+ $sequence_9 = { 83bde8fdffff00 7574 6800010000 6a00 8d85ecfdffff 50 }
condition:
- 7 of them and filesize <1122304
+ 7 of them and filesize <630784
}
-rule MALPEDIA_Win_Iisniff_Auto : FILE
+rule MALPEDIA_Win_Pgift_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4d48d0b9-4608-5fda-9d9c-52fef07b4d04"
+ id = "77b72e7a-f170-5cb6-9a32-dd868251e29f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.iisniff"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.iisniff_auto.yar#L1-L161"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pgift"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pgift_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "eea8ed3537fc508bcc20c7dcdf7a5fa6fb525fac16191889baa1f35692f7bc88"
+ logic_hash = "5fec76c05b43d836fa9681344d4e2173c2fdd272e3aa573e02794115bc07ca47"
score = 75
quality = 75
tags = "FILE"
@@ -138646,37 +145642,32 @@ rule MALPEDIA_Win_Iisniff_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7513 8b442414 8b4804 53 }
- $sequence_1 = { 8b8c240c000100 56 8d842414000100 50 51 }
- $sequence_2 = { 7507 be04000000 eb69 c645fc01 8b0f }
- $sequence_3 = { 55 56 8bb42488000000 57 33db }
- $sequence_4 = { 83d8ff 85c0 7537 8dbc24a4000000 e8???????? }
- $sequence_5 = { 5f 5b c20400 8b4038 8b08 890e }
- $sequence_6 = { 8b45cc ff704c e8???????? 59 83f8ff 0f852cffffff }
- $sequence_7 = { 56 8d4dd4 894598 e8???????? 8365fc00 56 8d4d9c }
- $sequence_8 = { 895c241c 89442420 e8???????? 8bf0 }
- $sequence_9 = { e8???????? 83c404 8d8c24fc000000 899c2448010000 89bc2444010000 }
- $sequence_10 = { 6a03 68000000c0 68???????? ff15???????? 6a02 }
- $sequence_11 = { e8???????? 8b4f3c 8b11 8d75c8 56 ff75cc }
- $sequence_12 = { ff75e8 e8???????? 834dfcff 8b45dc }
- $sequence_13 = { c3 ff7508 e8???????? 59 c3 833d????????00 7505 }
- $sequence_14 = { 64a300000000 80bc24a400000000 7409 6a00 6a00 e8???????? 8b410c }
+ $sequence_0 = { 53 ff7508 e8???????? 83450804 83c304 }
+ $sequence_1 = { 2bc8 c1f902 7454 50 8d4de8 }
+ $sequence_2 = { 50 0fb745d4 50 8d45ec ff760c }
+ $sequence_3 = { 8d4df0 c645fc02 e8???????? ff750c }
+ $sequence_4 = { 83f8ff 741e 53 50 8d4de8 e8???????? ff75e8 }
+ $sequence_5 = { 8d4df0 ff3498 e8???????? 83f8ff }
+ $sequence_6 = { 33db 8d4dec 895dfc e8???????? 8d8dd0feffff 895de8 e8???????? }
+ $sequence_7 = { c645fc03 897e38 897e34 897e30 e8???????? 3bc7 }
+ $sequence_8 = { ff7634 53 50 e8???????? 83c40c 8d4638 }
+ $sequence_9 = { 8d4de8 e8???????? 6a5c 8d4de8 c645fc01 }
condition:
- 7 of them and filesize <1441792
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Vyveva_Auto : FILE
+rule MALPEDIA_Win_Babuk_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5f920383-d05c-5c69-8d2c-6a773f2538b6"
+ id = "d5eda12f-ea4b-52c1-b2a1-b261c48c105c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vyveva"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vyveva_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.babuk"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.babuk_auto.yar#L1-L163"
license_url = "N/A"
- logic_hash = "9d5c74e05efbe3ba7525bfb04e432ddba69e01227882b7ebe7ef3564991f92e2"
+ logic_hash = "55094f2694a9f4921a100bba31a1afb9b9947feff6d1ffe3b263a4bd8f4c17f7"
score = 75
quality = 75
tags = "FILE"
@@ -138690,32 +145681,38 @@ rule MALPEDIA_Win_Vyveva_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 58 ff7008 5a 8916 3b4808 7405 }
- $sequence_1 = { 51 8f00 8b4c2408 85c9 7407 51 8f4004 }
- $sequence_2 = { 57 56 51 55 59 e8???????? ff30 }
- $sequence_3 = { 56 59 50 e8???????? 8d8c2494010000 6a04 }
- $sequence_4 = { 740a 394424fc 7404 894424fc 83ec04 5d 83fdff }
- $sequence_5 = { 83ec38 8b15???????? 8d442404 55 56 }
- $sequence_6 = { 2bce 59 7409 33c9 8d4c0e04 83e904 ff5004 }
- $sequence_7 = { 6a00 52 50 6a06 e8???????? 83c404 ffd0 }
- $sequence_8 = { 59 c644247801 e8???????? 8b4c2434 8b442430 8d542428 894c242c }
- $sequence_9 = { 7408 c70100000000 0101 83c008 85c0 7403 55 }
+ $sequence_0 = { ff15???????? 6800000100 e8???????? 83c404 }
+ $sequence_1 = { 50 ff15???????? 83f803 7502 }
+ $sequence_2 = { 8b45fc 83c002 8945fc 837dfc0a 0f83dc000000 8b4dfc }
+ $sequence_3 = { 8b4d08 8b540104 52 8b0401 50 e8???????? }
+ $sequence_4 = { 8b4dfc c1e108 ba01000000 d1e2 8b4508 }
+ $sequence_5 = { 8b95ccfdffff 83c201 8995ccfdffff 83bdccfdffff1f 735f 8d85f4fdffff }
+ $sequence_6 = { 8b4dfc 8b5508 8b44ca04 50 }
+ $sequence_7 = { 8b4d08 c7040100000000 c744010400000000 ba08000000 }
+ $sequence_8 = { 0bca 894dfc 8b45fc c1e008 b901000000 }
+ $sequence_9 = { 8b0401 50 e8???????? 83c408 8945ec 8955f0 }
+ $sequence_10 = { c744010400000000 ba08000000 6bc200 8b4d08 }
+ $sequence_11 = { 8b4508 c704107465206b c745fc00000000 eb09 }
+ $sequence_12 = { 744a 837dd801 7444 8b55ec 52 ff15???????? 8d45ac }
+ $sequence_13 = { e8???????? 83c410 c78574ffffff00000000 eb0f }
+ $sequence_14 = { 57 b808000000 6bc80a 8b5508 c7040a00000000 c7440a0400000000 c745fc00000000 }
+ $sequence_15 = { 51 e8???????? 83c408 8945f4 8955f8 }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <183296
}
-rule MALPEDIA_Win_Revil_Auto : FILE
+rule MALPEDIA_Win_5T_Downloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "81d28baf-82e1-54c0-bbf9-d56336789206"
+ id = "fe4393a3-e3cd-5e60-a348-fa50df874e7a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.revil"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.revil_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.5t_downloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.5t_downloader_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "2c34d02da785d928c9b5b4ca67c597715944f5d05b15c54928c0e64e7282a006"
+ logic_hash = "708a5991b6f83db848239b1110cc9bc587325f0c0450305b55a83b6de5bbd18e"
score = 75
quality = 75
tags = "FILE"
@@ -138729,32 +145726,32 @@ rule MALPEDIA_Win_Revil_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 334f1c 83c720 d1f8 83e801 89450c e9???????? 8b7510 }
- $sequence_1 = { 50 e8???????? 8b7d08 8db568ffffff 83c414 }
- $sequence_2 = { 83e801 eb07 b00a 5d c3 83e862 7428 }
- $sequence_3 = { 8d8510ffffff 50 8d8560ffffff 50 8d45b0 50 e8???????? }
- $sequence_4 = { ff750c 8d45b0 50 8d85c0feffff 50 }
- $sequence_5 = { 8b4508 8b404c 8945f0 8b45e8 894b28 f7d0 23c2 }
- $sequence_6 = { 334de0 8b4048 8b5d08 8945ec 8b4508 }
- $sequence_7 = { ff7520 e8???????? 8d8580feffff 50 ff7524 }
- $sequence_8 = { 8975d8 0fb645ff 0bc8 8bc1 894dd8 }
- $sequence_9 = { 83e813 0f8461060000 83e83d 0f84fa020000 f6c204 7411 80f92c }
+ $sequence_0 = { 7409 83781800 7403 5d }
+ $sequence_1 = { 85c9 7409 83781800 7403 5d }
+ $sequence_2 = { 85c9 7409 83781800 7403 }
+ $sequence_3 = { 85c0 7416 83781400 7510 }
+ $sequence_4 = { 85c9 7409 83781800 7403 5d ffe1 83c8ff }
+ $sequence_5 = { 8b4508 85c0 7416 83781400 7510 }
+ $sequence_6 = { 55 8bec 8b4508 85c0 7416 83781400 7510 }
+ $sequence_7 = { 85c9 7409 83781800 7403 5d ffe1 }
+ $sequence_8 = { 7409 83781800 7403 5d ffe1 83c8ff }
+ $sequence_9 = { 8bec 8b4508 85c0 7416 83781400 7510 }
condition:
- 7 of them and filesize <155794432
+ 7 of them and filesize <539648
}
-rule MALPEDIA_Win_Naikon_Auto : FILE
+rule MALPEDIA_Win_Dyre_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2b0fa492-57d4-5b88-95d9-a0b325c3a81c"
+ id = "a2cdb89d-a2b8-54db-b921-a02d048236a7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.naikon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.naikon_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dyre"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dyre_auto.yar#L1-L170"
license_url = "N/A"
- logic_hash = "10ad96daf91bea73d71b90a544491c018eb03e29efd792a88809f482c814e2f1"
+ logic_hash = "e9097ad46c004cb1ae831fc1ba01674dc80d073ddf943ce6f2fcdbae48599a8a"
score = 75
quality = 75
tags = "FILE"
@@ -138768,32 +145765,38 @@ rule MALPEDIA_Win_Naikon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 881c08 8d4405c9 50 e8???????? 59 8b4d0c 8901 }
- $sequence_1 = { 8d85f8feffff 68???????? 50 e8???????? 8b3d???????? 83c418 8d85a8fcffff }
- $sequence_2 = { ff750c c745f002000000 897dec c745e401000000 57 897de0 ff7508 }
- $sequence_3 = { 53 50 8d85f4fffdff 56 50 ff35???????? }
- $sequence_4 = { 83c418 57 50 8d8528ffffff 50 ffb690000000 e8???????? }
- $sequence_5 = { 6a10 57 681cc10000 897df4 ff750c c745f002000000 }
- $sequence_6 = { 53 53 8b4010 8d4d0c }
- $sequence_7 = { e8???????? 83c40c 837df400 7408 ff75f4 e8???????? }
- $sequence_8 = { 83c41c 33c0 808405dcf9fffffb 40 }
- $sequence_9 = { 6a01 ff35???????? ff15???????? 8bd8 8b4508 46 6a00 }
+ $sequence_0 = { 6814020000 e8???????? 59 c3 }
+ $sequence_1 = { e9???????? 68f4010000 ff15???????? 56 }
+ $sequence_2 = { 7244 6801010000 ff15???????? 8b4d18 663901 }
+ $sequence_3 = { 7502 c9 c3 33c0 837dfc20 }
+ $sequence_4 = { 0fb7c8 c1e110 e8???????? 0fb7c0 0bc1 c9 c3 }
+ $sequence_5 = { 773d 0fbec0 83e857 8ada 2ad9 c1e004 80fb09 }
+ $sequence_6 = { c1fa02 8b1496 83e103 c1e103 }
+ $sequence_7 = { 41 3bc8 7cf4 83f903 }
+ $sequence_8 = { 57 4883ec20 4032ff 488bda 8bf1 4885d2 }
+ $sequence_9 = { 488bc8 ff15???????? 85c0 7455 4c8d442434 }
+ $sequence_10 = { 488bcb e8???????? 4c8d5e01 41b8f7ffffff 6666660f1f840000000000 488bcf 418d4008 }
+ $sequence_11 = { 4433c0 418bc5 23c6 33c8 418bc1 4403c1 }
+ $sequence_12 = { 663907 7530 8b4604 394704 7528 8b4608 394708 }
+ $sequence_13 = { 498d43e8 33ff 488bf2 498943d8 498d4318 488bd9 488bd1 }
+ $sequence_14 = { 440fb69c249f000000 0fb68c249d000000 0fb694249c000000 440fb694249b000000 }
+ $sequence_15 = { 488bcb e8???????? 85c0 750d 33c0 488b5c2430 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <590848
}
-rule MALPEDIA_Win_Taintedscribe_Auto : FILE
+rule MALPEDIA_Win_Avrecon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "62c390fd-70d7-5d2c-ab35-2685bb241f72"
+ id = "554ca169-95af-5a89-9a56-ddcba6897449"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.taintedscribe"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.taintedscribe_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avrecon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avrecon_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "9db61e016991abab1a5db24c238ca36eb7d715a36997cda629b6ade68b20e5c3"
+ logic_hash = "9c9411fb28d3d6162f9e1c850b8f8c9dc5dad1f470c391d983f628f3870dd7ec"
score = 75
quality = 75
tags = "FILE"
@@ -138807,32 +145810,32 @@ rule MALPEDIA_Win_Taintedscribe_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bc8 8b858cf7ffff 83e103 6a02 f3a4 6a00 }
- $sequence_1 = { 8d4ddc 898db8fcffff 8bcf 0facd108 }
- $sequence_2 = { 8b5358 898d88fbffff 8b4b50 0f94c0 }
- $sequence_3 = { 85c0 7405 8b4d98 8908 85db }
- $sequence_4 = { 894e3c 894e44 895648 33c0 5e 8b4dfc 33cd }
- $sequence_5 = { 8b4dcc 894308 8b45d0 50 }
- $sequence_6 = { 42 83fa1c 7cbb 81ff00010000 0f94c1 0fb6c1 68???????? }
- $sequence_7 = { c68577fbffff01 7507 c68577fbffff00 c78570fbffff08000000 }
- $sequence_8 = { 83c40c 098658af0100 8d0419 89865caf0100 83f810 }
- $sequence_9 = { bb01000000 d3e3 33c0 85db 7e1e 8d4900 }
+ $sequence_0 = { 56 e8???????? 85c0 0f8577020000 8d8584fbffff 50 56 }
+ $sequence_1 = { 89b5f0fdffff 899decfdffff 89b5f4feffff 899df0feffff ff15???????? 8945fc }
+ $sequence_2 = { 56 47 e8???????? 0fb7f0 663bf3 0f869b030000 }
+ $sequence_3 = { e8???????? 53 ff15???????? 8b35???????? 8d4554 50 0fb705???????? }
+ $sequence_4 = { e8???????? 83c410 5e c3 55 8bec 81ec04010000 }
+ $sequence_5 = { 50 6880000000 57 ff7508 ffd6 6a04 8d45f8 }
+ $sequence_6 = { 49 7524 50 a3???????? ff15???????? e8???????? }
+ $sequence_7 = { e8???????? 56 6a08 8d45d8 50 ff7508 c645d800 }
+ $sequence_8 = { 56 8bf8 ff15???????? 668bc7 5f 5e }
+ $sequence_9 = { 50 8d85c0f7ffff 50 e8???????? 8d85a8f7ffff 50 894534 }
condition:
- 7 of them and filesize <524288
+ 7 of them and filesize <360448
}
-rule MALPEDIA_Win_Ascentloader_Auto : FILE
+rule MALPEDIA_Win_Apocalypse_Ransom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a27ad34c-c5db-5069-a642-46b14138c3be"
+ id = "d42c3028-47d8-5c2a-8245-ee48597fdb68"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ascentloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ascentloader_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.apocalypse_ransom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.apocalypse_ransom_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "9df20341633fa22f46dd0bb0a3d7ffdb7631f541fddea2f57343c78db84232a1"
+ logic_hash = "3006a8aede4427b243aedfb686311f3de66b1be38f627de23e7cfc996b17033d"
score = 75
quality = 75
tags = "FILE"
@@ -138846,32 +145849,32 @@ rule MALPEDIA_Win_Ascentloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 1bc0 f7d8 eb02 8bc3 85c0 }
- $sequence_1 = { 741b 6a1a 2bf7 59 }
- $sequence_2 = { 85c0 7414 8b0f e8???????? 8b4e48 e8???????? 33c0 }
- $sequence_3 = { 40 001c5b 40 0023 }
- $sequence_4 = { c78564ffffff76650d0a 66c78568ffffff0d0a c6856affffff00 f30f7f856cffffff 660f6f05???????? f30f7f857cffffff }
- $sequence_5 = { 6a01 58 0f43f0 6a22 59 }
- $sequence_6 = { 40 0038 aa 40 }
- $sequence_7 = { 83f8ff 7518 ff15???????? 57 ff15???????? ff15???????? e9???????? }
- $sequence_8 = { 85c0 7508 6a11 e8???????? 59 ff34f5c8484100 }
- $sequence_9 = { 8d45e0 50 56 ff15???????? 8b5dec }
+ $sequence_0 = { ff15???????? 68???????? 8d84240c040000 50 ff15???????? 85c0 742f }
+ $sequence_1 = { 83f8ff 755f 6a01 8d44240c 50 8d8c2410040000 }
+ $sequence_2 = { 0bfb ff15???????? 33d2 83f802 }
+ $sequence_3 = { 8d4c2410 68???????? 51 ff15???????? 83c410 6a00 6a00 }
+ $sequence_4 = { ffd6 b801000000 5e 83c418 c3 33c0 }
+ $sequence_5 = { 68???????? 6a00 ffd7 8bf0 85f6 7504 5f }
+ $sequence_6 = { 83f8ff 7411 50 ff15???????? 8d0424 50 ff15???????? }
+ $sequence_7 = { 83c40c 57 53 ff15???????? 6800800000 }
+ $sequence_8 = { ffd7 85c0 7440 8b1d???????? 8b2d???????? 8b542410 8d4c2410 }
+ $sequence_9 = { 6a03 6800000040 52 ffd6 }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Lightlesscan_Auto : FILE
+rule MALPEDIA_Win_Revil_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0e07ce78-7b41-59eb-abf5-c61709c5b1e0"
+ id = "81d28baf-82e1-54c0-bbf9-d56336789206"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lightlesscan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lightlesscan_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.revil"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.revil_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "75c6d82588f11dc73e097a77d8f1194031d887782bbdd3a0785b555591ab1fe4"
+ logic_hash = "2c34d02da785d928c9b5b4ca67c597715944f5d05b15c54928c0e64e7282a006"
score = 75
quality = 75
tags = "FILE"
@@ -138885,34 +145888,34 @@ rule MALPEDIA_Win_Lightlesscan_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 33db 48895c2460 488b4d70 4885c9 7405 e8???????? }
- $sequence_1 = { b890100000 e8???????? 482be0 48c7442458feffffff 48899c24c8100000 4889b424d0100000 4889bc24d8100000 }
- $sequence_2 = { 4863d8 e8???????? 488bd3 b940000000 ffd0 488d0deaa20300 c705????????01000000 }
- $sequence_3 = { 488d0d50c00100 e8???????? 4983c8ff ba80000000 488905???????? 488d0da05d0500 4885c0 }
- $sequence_4 = { 4881c440020000 5b f3c3 8815???????? 0100 a9150100c7 150100d615 }
- $sequence_5 = { 498bcc e8???????? 488d1564b70500 41b804000000 498bcc e8???????? 488d1567b70500 }
- $sequence_6 = { 4889442420 e8???????? eb0c 4c8d0d68440100 e8???????? 488d0d8cc10100 }
- $sequence_7 = { 488d0d23b40600 ffd0 48833d????????00 7415 488d0db04a0300 e8???????? 488b0d???????? }
- $sequence_8 = { 7506 ff15???????? 4489bc24f8000000 488b07 418bf7 0fb74814 }
- $sequence_9 = { 488d4d30 33d2 41b801100000 e8???????? 33d2 41b8faff0000 488bce }
+ $sequence_0 = { 334f1c 83c720 d1f8 83e801 89450c e9???????? 8b7510 }
+ $sequence_1 = { 50 e8???????? 8b7d08 8db568ffffff 83c414 }
+ $sequence_2 = { 83e801 eb07 b00a 5d c3 83e862 7428 }
+ $sequence_3 = { 8d8510ffffff 50 8d8560ffffff 50 8d45b0 50 e8???????? }
+ $sequence_4 = { ff750c 8d45b0 50 8d85c0feffff 50 }
+ $sequence_5 = { 8b4508 8b404c 8945f0 8b45e8 894b28 f7d0 23c2 }
+ $sequence_6 = { 334de0 8b4048 8b5d08 8945ec 8b4508 }
+ $sequence_7 = { ff7520 e8???????? 8d8580feffff 50 ff7524 }
+ $sequence_8 = { 8975d8 0fb645ff 0bc8 8bc1 894dd8 }
+ $sequence_9 = { 83e813 0f8461060000 83e83d 0f84fa020000 f6c204 7411 80f92c }
condition:
- 7 of them and filesize <1399808
+ 7 of them and filesize <155794432
}
-rule MALPEDIA_Win_Redsalt_Auto : FILE
+rule MALPEDIA_Win_Saint_Bot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "295994ac-254e-59ee-b227-ac14e9e1f055"
+ id = "714c3147-1158-5cc4-a0a2-d44deb9955a4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redsalt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redsalt_auto.yar#L1-L217"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.saint_bot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.saint_bot_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "03f89ce4b045eb8ff5f60169a4045ddc5e403a310ae115cf10989b990183d50a"
+ logic_hash = "74c58e6c0a61984f0e7d1e5e39218efbc9c3b95b70a89e37e515f61493396398"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -138924,47 +145927,32 @@ rule MALPEDIA_Win_Redsalt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 750b 68e8030000 ff15???????? e8???????? }
- $sequence_1 = { 83c414 33c9 83f8ff 0f95c1 }
- $sequence_2 = { e8???????? 85c0 750a 6a32 }
- $sequence_3 = { c745d060ea0000 6a04 8d45d0 50 6806100000 }
- $sequence_4 = { 51 ffd6 85c0 7510 }
- $sequence_5 = { 85c0 7515 c705????????01000000 ff15???????? e9???????? }
- $sequence_6 = { 83c9ff 85f6 7c0e 83fe7f 7f09 }
- $sequence_7 = { 6a01 6a00 6a01 6800000080 }
- $sequence_8 = { 7509 80780120 7503 83c002 }
- $sequence_9 = { 8d8530fcffff 50 e8???????? 83c40c }
- $sequence_10 = { 6a00 52 c744242401000000 8944242c c744243002000000 ff15???????? }
- $sequence_11 = { c60100 5f 5e 33c0 }
- $sequence_12 = { 83c40c eb02 33c0 8b4df4 }
- $sequence_13 = { e8???????? 83c408 6800010000 68???????? }
- $sequence_14 = { c1fa04 c0e302 0ad3 83c004 }
- $sequence_15 = { 833800 750f c705????????01000000 e9???????? }
- $sequence_16 = { eb03 83caff 8b442410 c0e106 }
- $sequence_17 = { f7e7 8bea d1ed 33c0 83ef03 8a06 83c603 }
- $sequence_18 = { c644243423 c644243572 c64424367a c644243700 }
- $sequence_19 = { c8201cdd f7be5b408d58 1b7f01 d2cc }
- $sequence_20 = { d2cc bbe3b46b7e 6aa2 dd45ff }
- $sequence_21 = { e8???????? 85ed 4863cd 488be8 }
- $sequence_22 = { e8???????? 8905???????? 48488b942498020000 488b8c2490020000 }
- $sequence_23 = { e8???????? 8903 83f8ff 0f858e3e0b00 }
- $sequence_24 = { e8???????? 8905???????? 4883c428 7502 }
+ $sequence_0 = { 85f6 7432 837d10ff 7405 3b5d10 744f 6a04 }
+ $sequence_1 = { 894df8 894dec ff15???????? 8d45ec 50 8d45f8 50 }
+ $sequence_2 = { 668945e8 83c002 668945ea 8d45e0 8945d0 }
+ $sequence_3 = { c3 55 8bec 8b550c 53 0fb71a 6685db }
+ $sequence_4 = { 6a78 68f0000000 b800000080 50 50 680000cf00 }
+ $sequence_5 = { 85c0 0f84c7000000 85ff 7404 c6043800 }
+ $sequence_6 = { 58 6a63 668945cc 58 6a30 }
+ $sequence_7 = { 56 57 e8???????? ff75f0 56 57 e8???????? }
+ $sequence_8 = { 57 ff15???????? 56 6880000000 6a02 56 }
+ $sequence_9 = { 8bf0 ff15???????? 6a00 6a06 56 6a04 50 }
condition:
- 7 of them and filesize <2957312
+ 7 of them and filesize <93184
}
-rule MALPEDIA_Win_Buhtrap_Auto : FILE
+rule MALPEDIA_Win_Feodo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "25eb4b11-3715-52d0-a7c7-9dac6aa80ccc"
+ id = "63743f44-4e6b-5a91-9837-bc3f6dee3649"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.buhtrap"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.buhtrap_auto.yar#L1-L162"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.feodo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.feodo_auto.yar#L1-L175"
license_url = "N/A"
- logic_hash = "d4e0c8ac83aa0b6c13a2f72737ffccb143e82cce7ba2ea9d1a844cc8381c4b50"
+ logic_hash = "b3401747482af4dd4837f27d2a5311953b45c82ad5e6a5cd690191bf7d127342"
score = 75
quality = 75
tags = "FILE"
@@ -138978,37 +145966,38 @@ rule MALPEDIA_Win_Buhtrap_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 59 59 84c0 0f8435010000 }
- $sequence_1 = { 7423 8b44240c 33d2 6a64 59 f7f1 }
- $sequence_2 = { c3 b301 ebe1 55 8bec 83ec18 }
- $sequence_3 = { 6a00 50 8d442414 c744242c04000000 }
- $sequence_4 = { 6a06 8bce e8???????? 8a1d???????? 56 }
- $sequence_5 = { 0f8489000000 837d1400 747b 6a09 59 33c0 8d7c242c }
- $sequence_6 = { 7405 e8???????? 85f6 7907 32c0 e9???????? 8365f000 }
- $sequence_7 = { ffd6 57 ffd6 33c0 85db 0f94c0 5f }
- $sequence_8 = { 754e 6a01 53 50 }
- $sequence_9 = { 53 68???????? 890e 894604 e8???????? 50 }
- $sequence_10 = { 897dfc e8???????? 59 84c0 0f8497000000 3bdf }
- $sequence_11 = { 6aff ff742420 ff7624 ffd7 ff742418 e8???????? }
- $sequence_12 = { ffd7 6a00 689385e784 6a28 68???????? }
- $sequence_13 = { 894624 8b442414 894604 a808 7466 }
- $sequence_14 = { 753d 8b4e2c 83c104 e8???????? e8???????? }
+ $sequence_0 = { 83c120 8d51d0 83fa09 7704 8bca eb10 8d519f }
+ $sequence_1 = { 6a00 8d542424 52 6a00 ff15???????? 85c0 }
+ $sequence_2 = { 7422 83e801 7404 83c8ff c3 8b4c2404 b802000000 }
+ $sequence_3 = { 6a00 8d4c240c 51 52 50 8b442414 50 }
+ $sequence_4 = { 56 57 33ff 57 6a02 6a02 57 }
+ $sequence_5 = { 742f 8b0f 6a01 68???????? 68???????? }
+ $sequence_6 = { 50 8b442414 50 ff15???????? 85c0 7405 }
+ $sequence_7 = { 6a00 8d942418020000 52 50 }
+ $sequence_8 = { 3452 e8???????? 0202 0202 1c83 0000 }
+ $sequence_9 = { 229921688d3c 2ee83e207468 60 238b0d03c783 782e 1463 }
+ $sequence_10 = { 006c082e 08cc 6969690bc8cc69 690c2e2e0b8ce0 04f7 e10c 206d53 }
+ $sequence_11 = { 150d14f452 696969697f3cc3 af e2c3 }
+ $sequence_12 = { 041e 6e 18b8161e6e18 b8161e33c9 0000 16 43 }
+ $sequence_13 = { 0404 0404 0316 16 }
+ $sequence_14 = { 0056b0 2e2801 0bd0 83c4ce 00576a 05c705c07f }
+ $sequence_15 = { 007538 034568 3327 325616 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <270336
}
-rule MALPEDIA_Win_Kuluoz_Auto : FILE
+rule MALPEDIA_Win_Socks5_Systemz_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5fb3985a-aeab-550e-a023-7a6297ba36e6"
+ id = "11fdca9d-b672-58c8-b928-df2c27b8d2c6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kuluoz"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kuluoz_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.socks5_systemz"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.socks5_systemz_auto.yar#L1-L97"
license_url = "N/A"
- logic_hash = "50bc1e4e578c80bb3ef2f204a6ac7dc8f957cf6ffcd8541a192712c749d0e03e"
+ logic_hash = "c567898c7f496303ddbf924e08954da7846c60ee6266bcbd0213f34733b6e6b6"
score = 75
quality = 75
tags = "FILE"
@@ -139022,32 +146011,30 @@ rule MALPEDIA_Win_Kuluoz_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 6a00 8b45cc 50 ff55ec 8945c8 837dc800 }
- $sequence_1 = { 52 8b45fc 8b4840 51 e8???????? 83c40c 8b55fc }
- $sequence_2 = { 83c001 8b4d0c 898146120000 837dfc04 7552 }
- $sequence_3 = { 8b4508 50 8d4dd8 51 e8???????? 8b10 }
- $sequence_4 = { 338df4feffff 8985f0feffff 898df4feffff 68ff000000 8d95f8feffff 52 e8???????? }
- $sequence_5 = { 7502 eb05 e9???????? 837dfc06 0f84a2000000 837dfc04 7552 }
- $sequence_6 = { 83fa0a 7409 0fbe4508 83f80d 7504 b001 }
- $sequence_7 = { 8b45fc 0fb60c02 51 e8???????? 0fbed0 3bf2 7404 }
- $sequence_8 = { 8bec 81ec780a0000 a1???????? 33c5 8945fc }
- $sequence_9 = { f7f1 0fbe9204605009 8b45f8 0345fc 0fbe08 }
+ $sequence_0 = { 50 64892500000000 83ec14 894df0 8b45f0 83c018 }
+ $sequence_1 = { 8b45c8 c6041000 b901000000 6bd100 8b8500feffff }
+ $sequence_2 = { 8b45d4 8945e0 8b4ddc 51 }
+ $sequence_3 = { 8b45d8 8945f0 837df000 7413 }
+ $sequence_4 = { 8b45cc c6041000 b901000000 6bd100 8b45c8 c6041000 }
+ $sequence_5 = { 8b45cc 50 e8???????? 59 c3 8d4dd8 }
+ $sequence_6 = { 8b45d0 e9???????? e9???????? 837dcc00 }
+ $sequence_7 = { 8b45d8 50 8b4df0 83c124 }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <491520
}
-rule MALPEDIA_Win_Crat_Auto : FILE
+rule MALPEDIA_Win_Scranos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5ca84b15-9c50-5146-aeb0-8e43c37e0140"
+ id = "366bbb3b-fd76-5e48-ad2c-11dfe56c53aa"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crat_auto.yar#L1-L175"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scranos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.scranos_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "a19b8917ee2e01478bdd8090b22583a65c2cc48e63af4151406da25e5b4c7a8a"
+ logic_hash = "5a9a306a889eeb594e8f9ae05b85780def5b0ff2c4ea6f54823c4b6d5baa27b1"
score = 75
quality = 75
tags = "FILE"
@@ -139061,39 +146048,32 @@ rule MALPEDIA_Win_Crat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 488bd0 488d8d90010000 e8???????? 90 }
- $sequence_1 = { e8???????? 488bd0 488d8d88000000 e8???????? 90 }
- $sequence_2 = { 7406 e8???????? 90 488b542420 4883c2e8 }
- $sequence_3 = { e8???????? 488bc8 4885c0 7433 }
- $sequence_4 = { e8???????? 488bd0 488d8da8010000 e8???????? 90 }
- $sequence_5 = { 48f7c20000ffff 7523 0fb7fa 8bcf e8???????? 4885c0 7427 }
- $sequence_6 = { e8???????? 488bd0 488d4d58 e8???????? 90 }
- $sequence_7 = { ebd0 498bc4 48833d????????10 480f4305???????? 482bc8 }
- $sequence_8 = { 33d2 c1e902 f7f1 eb02 }
- $sequence_9 = { ffd0 85c0 750f ff15???????? }
- $sequence_10 = { 8bcb e8???????? 8b55d8 8b4b0c }
- $sequence_11 = { 8bcb e8???????? 8b4b0c 8d4101 }
- $sequence_12 = { 8b4004 8bca 3bc2 0f47c8 51 8b4d10 e8???????? }
- $sequence_13 = { 8b4b0c 8d4101 89430c c60100 8b4dd4 41 }
- $sequence_14 = { 8b4324 668948fe c740f800000000 c740f400000000 c740f000000000 5f 5e }
- $sequence_15 = { 8b5508 0f57c0 56 8b750c b896000000 f30f7f01 }
- $sequence_16 = { 8b4b0c 8d4101 89430c 8a45d3 8801 8b4dd4 41 }
+ $sequence_0 = { e8???????? 83c404 8b55cc 8d440201 8945cc ebb5 8b4de4 }
+ $sequence_1 = { 8b8e70010000 8d542430 52 8b966c010000 8d442438 50 8d86b0030000 }
+ $sequence_2 = { eb13 8b4608 8b4e04 8b16 50 51 52 }
+ $sequence_3 = { e8???????? 83c428 e9???????? 8b55ec 8b42e4 50 8b4df4 }
+ $sequence_4 = { e8???????? 83c40c 85c0 0f8515070000 8b54241c 52 56 }
+ $sequence_5 = { 89834c010000 7523 8b542410 52 8d442420 50 8d8bc8000000 }
+ $sequence_6 = { 8b4d24 e8???????? 8945a0 8b4da0 894d9c c745fc00000000 8d55ac }
+ $sequence_7 = { 8b55e8 8b849544ffffff 89448d8c 8b4de8 8b948d30ffffff 8b4248 8b4de8 }
+ $sequence_8 = { 8b6c2410 57 8b7d00 8b87840c0000 81c7680c0000 8d4f0c 8944240c }
+ $sequence_9 = { c645fc00 8d4dc8 e8???????? c745fcffffffff 8d4da8 e8???????? 8b4594 }
condition:
- 7 of them and filesize <4161536
+ 7 of them and filesize <2859008
}
-rule MALPEDIA_Win_Dripion_Auto : FILE
+rule MALPEDIA_Win_Fusiondrive_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "89e91029-adf0-5373-91d6-441ac823d2ed"
+ id = "d735e520-5418-5676-9517-95f81cfe7607"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dripion"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dripion_auto.yar#L1-L108"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fusiondrive"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fusiondrive_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "6b099e3758909dfda12afb8709370979b2c037becc9af1305c25dce794b98386"
+ logic_hash = "b988107dd8630d41b8dbc9f6aa013be888aa54392baf79daf500a205d72bf5ae"
score = 75
quality = 75
tags = "FILE"
@@ -139107,32 +146087,32 @@ rule MALPEDIA_Win_Dripion_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd6 8bf8 ffd6 0faff8 ffd6 }
- $sequence_1 = { 03f8 7402 ffd6 ffd6 }
- $sequence_2 = { ffd6 8bf8 ffd6 0faff8 8d3c7f }
- $sequence_3 = { 03f8 ffd6 8bd8 ffd6 0fafd8 ffd6 }
- $sequence_4 = { ffd6 03f8 8d3c7f ffd6 }
- $sequence_5 = { 7513 6a64 ff15???????? 68???????? }
- $sequence_6 = { 8bf8 ffd6 0faff8 8d3c7f }
- $sequence_7 = { ffd6 03f8 ffd6 8bd8 }
- $sequence_8 = { 7402 ffd6 ffd6 ffd6 }
- $sequence_9 = { ffd6 03f8 7402 ffd6 }
+ $sequence_0 = { 48898620020000 0fb7c0 66f3ab 488d3d501c0100 482bfe 8a041f }
+ $sequence_1 = { 0f846f010000 660f6f05???????? f30f7f442470 66c745806557 c6458200 488d542470 488bc8 }
+ $sequence_2 = { 7735 488bd1 4983ff08 7203 }
+ $sequence_3 = { 4c8d4c2440 4983fd08 4d0f43cf 488d7c2420 4983fc08 490f43fa 4c8b5c2450 }
+ $sequence_4 = { 4863c9 4c8d0514070100 488bc1 83e13f 48c1f806 488d14c9 498b04c0 }
+ $sequence_5 = { 0fb60a 83e10f 4c8d05f899ffff 4a0fbe8401a8150100 }
+ $sequence_6 = { 488b542450 488bc8 488902 488b5310 ff15???????? 33c0 }
+ $sequence_7 = { ff15???????? 8d0c4501000000 4103cf 458d7c2402 418bd7 }
+ $sequence_8 = { ff15???????? 3db7000000 0f8432060000 33ff 8bcf }
+ $sequence_9 = { 7528 48897df7 48c745ff07000000 66897de7 }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <290816
}
-rule MALPEDIA_Win_Aveo_Auto : FILE
+rule MALPEDIA_Win_Crosswalk_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "20a83532-4a6e-562c-b0b0-f75c536df8d1"
+ id = "4e86aa0a-7e26-5d10-b3ce-967831f39ceb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aveo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aveo_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crosswalk"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crosswalk_auto.yar#L1-L164"
license_url = "N/A"
- logic_hash = "0a926409298a7da9832c13e4dae3f40393311db59f4c541fcfd58f63e4b0b943"
+ logic_hash = "c5472d51b6e367a8e5153b183b7c173cc8cbe07eef42b7b5523d361aefdeb08e"
score = 75
quality = 75
tags = "FILE"
@@ -139146,32 +146126,38 @@ rule MALPEDIA_Win_Aveo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b85ecfaffff 83c40c 50 8bcb 51 8db5f8fdffff }
- $sequence_1 = { 53 56 57 8db570faffff }
- $sequence_2 = { 8d8d10feffff e8???????? 8b95f8fdffff 52 8bf0 }
- $sequence_3 = { 8b4de0 8d55dc 52 6800008000 }
- $sequence_4 = { 8d8554faffff 8d8d70faffff e8???????? 8b955cfaffff 52 e8???????? }
- $sequence_5 = { 50 f3a4 ff15???????? 6800010000 8d8df8feffff 6a00 51 }
- $sequence_6 = { 53 8d4802 8955f4 56 8a51fe }
- $sequence_7 = { 7424 8b85f4efffff 3bc7 741a }
- $sequence_8 = { c7442418e8030000 ff15???????? 3bc7 740c 68???????? 50 }
- $sequence_9 = { c7430801000000 e8???????? 6a06 89430c 8d4310 8d89d41a4100 5a }
+ $sequence_0 = { 4885c9 7402 ffd1 b801000000 }
+ $sequence_1 = { ff15???????? 448bf0 4533c9 4533c0 }
+ $sequence_2 = { 458bc6 33d2 488bc8 e8???????? 4533c9 }
+ $sequence_3 = { 458d7ee0 418bd7 ff15???????? 4821742420 }
+ $sequence_4 = { 4c8bc6 33d2 410fbe00 49ffc0 }
+ $sequence_5 = { 418bc0 f7e9 03d1 c1fa0b 8bc2 c1e81f 03d0 }
+ $sequence_6 = { d3ca 03d0 4183ef01 75ef }
+ $sequence_7 = { 410fbe00 49ffc0 d3ca 03d0 }
+ $sequence_8 = { 8b45fc 817848f0844100 7409 ff7048 e8???????? }
+ $sequence_9 = { 6a26 58 0fb60c85c6574100 0fb63485c7574100 8bf9 }
+ $sequence_10 = { 7403 ff5508 5d c20400 53 8b1d???????? }
+ $sequence_11 = { 735f 8bc6 8bfe 83e03f c1ff06 6bd830 8b04bd808e4100 }
+ $sequence_12 = { c1f906 03048d808e4100 eb02 8bc6 80782900 }
+ $sequence_13 = { 83e801 0f8501010000 c745e0245b4100 8b4508 8bcf 8b7510 }
+ $sequence_14 = { 740e 50 e8???????? 83a6808e410000 59 }
+ $sequence_15 = { 83e801 0f8580000000 8b4508 dd00 ebc6 c745e0285b4100 e9???????? }
condition:
- 7 of them and filesize <180224
+ 7 of them and filesize <286720
}
-rule MALPEDIA_Win_Hamweq_Auto : FILE
+rule MALPEDIA_Win_Cova_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5d79f276-5807-56d4-9ea0-44042b180646"
+ id = "0c88fb7f-6fc3-555b-938b-30689bfedd71"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hamweq"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hamweq_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cova"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cova_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "f4464ade23ea171530cd0c6e2b15abfaf45c0eb2379ccacb80bd385a306f9a8e"
+ logic_hash = "5acada90a087ad54806fe6fafb57fbcd69c3ce6e348c87bed79cabfe21474d32"
score = 75
quality = 75
tags = "FILE"
@@ -139185,69 +146171,71 @@ rule MALPEDIA_Win_Hamweq_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 51 8b4e08 8945f8 ffb148010000 ff5044 }
- $sequence_1 = { 8d85e4f1ffff 50 ff5744 50 }
- $sequence_2 = { 837c910800 8d449108 894514 0f8438010000 837c910c00 }
- $sequence_3 = { 668b4804 51 ff30 56 e8???????? 83c40c }
- $sequence_4 = { 51 ff5040 8b0e 8d85ecfeffff 53 50 }
- $sequence_5 = { 7504 6afe ebea 8b4e08 8b06 ff7170 }
- $sequence_6 = { 8d4580 8b0b 50 ff5154 }
- $sequence_7 = { 8b06 753c ffb1d8000000 8d8d00feffff 51 }
- $sequence_8 = { 51 8d4d80 51 ff5054 eb12 8b5d08 }
- $sequence_9 = { c3 8b442408 8a08 84c9 7408 }
+ $sequence_0 = { 8b430c 8905???????? 8bd7 4c8d0558bbffff }
+ $sequence_1 = { eb7c 4c8d258e800000 488b0d???????? eb6c }
+ $sequence_2 = { 4881c354020000 83fe06 7298 488d8d70040000 baf80d0000 }
+ $sequence_3 = { 3d80000000 751d 4c8be6 448bfe 4839742450 7419 ff5500 }
+ $sequence_4 = { 4863ca 0fb7444b10 664189844898c90000 ffc2 }
+ $sequence_5 = { 488b0d???????? e9???????? 4c8d25a6800000 488b0d???????? }
+ $sequence_6 = { eb06 8d4257 418800 ffc2 49ffc0 83fa10 }
+ $sequence_7 = { e8???????? 482be0 488b05???????? 4833c4 48898510170000 488dbde0000000 }
+ $sequence_8 = { ff15???????? 488d1574260000 488bce 488905???????? ff15???????? }
+ $sequence_9 = { 41bc14030000 4c8d0520320000 488bcd 418bd4 }
condition:
- 7 of them and filesize <24576
+ 7 of them and filesize <123904
}
-rule MALPEDIA_Win_Unidentified_089_Auto : FILE
+rule MALPEDIA_Win_Blackmatter_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f61e4a77-808b-5e07-801b-03e57ce838b5"
- date = "2023-07-11"
- modified = "2023-07-15"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_089"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_089_auto.yar#L1-L98"
+ id = "08d983f8-89d3-5398-96f5-8f771b0988c8"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackmatter"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackmatter_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "f9666eb88fbd91e0eb2e4b4c8812230b36d73d66192fed407aecfaa8f0ed362a"
+ logic_hash = "67609ff5035d7d172ddf1a903ab845a6e5b4b36e758aab3cb262223fbb37577d"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20230705"
- malpedia_hash = "42d0574f4405bd7d2b154d321d345acb18834a41"
- malpedia_version = "20230715"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 889dd4feffff 899d84feffff 898588feffff 889d74feffff 33c0 }
- $sequence_1 = { 8b4508 e8???????? c20c00 e8???????? cc 6a30 }
- $sequence_2 = { f2e9e3000000 55 8bec eb0d ff7508 e8???????? }
- $sequence_3 = { 83f904 0f8582000000 8b75d0 8bfb }
- $sequence_4 = { eb0f ff7634 57 ff562c }
- $sequence_5 = { 88041e 880c1f 0fb6041e 8b4dfc 03c2 8b550c }
- $sequence_6 = { 3dffffff7f 0f87a2000000 03c0 3d00100000 7227 }
- $sequence_7 = { 56 6a01 8d4dec 8975d8 }
+ $sequence_0 = { 57 c745fc00000000 ff35???????? e8???????? 8bf8 }
+ $sequence_1 = { ff75f8 ff15???????? 85c0 0f85e7000000 68???????? }
+ $sequence_2 = { 83c4d8 53 56 57 c745fc00000000 c745f800000000 }
+ $sequence_3 = { e8???????? 8945fc eb0c 83c702 ff4df8 837df800 }
+ $sequence_4 = { e9???????? ff75c8 e8???????? 8945c4 }
+ $sequence_5 = { ff15???????? 83c40c 8d047500000000 50 8d45da }
+ $sequence_6 = { 85f6 0f842c010000 56 ff35???????? e8???????? ff35???????? e8???????? }
+ $sequence_7 = { f7f1 92 3b4508 720b 3b450c }
+ $sequence_8 = { 8945ec e8???????? e8???????? 803d????????00 7405 }
+ $sequence_9 = { ff75f4 e8???????? 5e 5b 8be5 5d c3 }
condition:
- 7 of them and filesize <389120
+ 7 of them and filesize <194560
}
-rule MALPEDIA_Win_Cloudburst_Auto : FILE
+rule MALPEDIA_Win_Spectre_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6b8a23fb-a80e-5e29-b2d9-5270c8f2c8ea"
+ id = "af0ed3ea-7150-5006-a1e4-f1f71a7eae7a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cloudburst"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cloudburst_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spectre"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spectre_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "308a5032c7dd39db54565ddb9261de5bf1d032e66820b9bf51050b90dd0967a4"
+ logic_hash = "168b0e3a3116ff3325056de927c137c412a6159d98ef56a6628c736a2a7417ad"
score = 75
quality = 75
tags = "FILE"
@@ -139261,32 +146249,32 @@ rule MALPEDIA_Win_Cloudburst_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4533c2 4133e8 45894424f8 41896c24fc 8bc5 }
- $sequence_1 = { 4883ec08 8b05???????? 41be01000000 4c892c24 85c0 }
- $sequence_2 = { 4c892c24 85c0 4c8bd9 4c8bd2 410f44c6 4533ed }
- $sequence_3 = { 488b0d???????? 488d542444 4533c9 4533c0 488bf8 418bdd ff15???????? }
- $sequence_4 = { 458942f4 458b4c24f8 418bc1 c1e818 }
- $sequence_5 = { ba00080000 488bcb e8???????? 4c8d442430 }
- $sequence_6 = { 8b05???????? 41be01000000 4c892c24 85c0 4c8bd9 }
- $sequence_7 = { 03c2 8bc8 83e00f 3bc2 7407 }
- $sequence_8 = { 33d6 41891424 4133d3 33fa 4189542404 33df 41897c2408 }
- $sequence_9 = { 41b904000000 4c8d442440 418d5101 ff15???????? 85c0 74b1 }
+ $sequence_0 = { ebe3 83c8ff 5d 5b 59 59 c3 }
+ $sequence_1 = { 68???????? ff5604 e9???????? 807c242000 0f8414010000 6a02 }
+ $sequence_2 = { 51 e8???????? 59 59 8b8424ec000000 895c2470 896c2474 }
+ $sequence_3 = { 50 e8???????? 83c40c 50 8d8424a0000000 50 e8???????? }
+ $sequence_4 = { 83e801 7440 83e801 742c 83e801 7418 }
+ $sequence_5 = { 894554 53 8d4dc3 e8???????? 8bc8 e8???????? 50 }
+ $sequence_6 = { 83f81b 0f8ee3020000 83f81f 0f8eb3020000 83f821 0f8e06020000 83f822 }
+ $sequence_7 = { 8b4704 8bcd c6400c01 8b4704 8b4004 c6400c00 8b4704 }
+ $sequence_8 = { 51 8d8c2440010000 e8???????? 8d8c24d8000000 e8???????? 8d4c2448 e8???????? }
+ $sequence_9 = { c68424c400000000 ff15???????? 59 59 85c0 743d 6a01 }
condition:
- 7 of them and filesize <2363392
+ 7 of them and filesize <990208
}
-rule MALPEDIA_Win_Vigilant_Cleaner_Auto : FILE
+rule MALPEDIA_Win_Jimmy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a55582e3-616b-5a05-b673-fe9235d58867"
+ id = "6665c46a-fce5-5107-8692-d73430db94ca"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vigilant_cleaner"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vigilant_cleaner_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jimmy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jimmy_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "c5f2d2527d22c9ed364af085c79f4bf3cbb7661e8edd11d29a8f6f3321af29a9"
+ logic_hash = "5955b25aaac6bf582c8efb23dc58fc592d4dcf4b96826a166327d6d4b0ee873a"
score = 75
quality = 75
tags = "FILE"
@@ -139300,34 +146288,34 @@ rule MALPEDIA_Win_Vigilant_Cleaner_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 b868584d56 bb00000000 b90a000000 ba58560000 ed 5b }
- $sequence_1 = { ed 5b 59 5a }
- $sequence_2 = { b90a000000 ba58560000 ed 5b }
- $sequence_3 = { b90a000000 ba58560000 ed 5b 59 5a }
- $sequence_4 = { bb00000000 b90a000000 ba58560000 ed 5b }
- $sequence_5 = { bb00000000 b90a000000 ba58560000 ed 5b 59 }
- $sequence_6 = { b90a000000 ba58560000 ed 5b 59 }
- $sequence_7 = { bb00000000 b90a000000 ba58560000 ed 5b 59 5a }
- $sequence_8 = { b868584d56 bb00000000 b90a000000 ba58560000 ed 5b }
- $sequence_9 = { ba58560000 ed 5b 59 }
+ $sequence_0 = { 8908 eb11 e8???????? 8945f4 ff75f8 e8???????? 59 }
+ $sequence_1 = { 8b4508 83602c00 8b45fc c9 c3 55 8bec }
+ $sequence_2 = { 89814c010000 eb27 a1???????? 8b4de4 898840010000 ff75e4 }
+ $sequence_3 = { ff7508 ff55fc 59 59 c9 c3 55 }
+ $sequence_4 = { 6a73 58 668945f2 6a20 58 668945f4 6a25 }
+ $sequence_5 = { 8b4508 ff702c 8b4508 ff7024 e8???????? 59 59 }
+ $sequence_6 = { 50 8d45c4 50 8b4508 83c008 50 6a00 }
+ $sequence_7 = { 85c0 7419 8b45fc 0fbe00 8b4df8 0fbe09 }
+ $sequence_8 = { e8???????? 59 b001 c9 c20800 }
+ $sequence_9 = { 6a09 e8???????? 59 59 8945fc ff7510 ff750c }
condition:
- 7 of them and filesize <1181696
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Bankshot_Auto : FILE
+rule MALPEDIA_Win_Sobig_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4fd3740f-7572-57c0-9152-6fcb3e7bee0c"
+ id = "7eece2fa-1a04-5dd6-834d-8f7a893bf841"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bankshot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bankshot_auto.yar#L1-L425"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sobig"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sobig_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "c9fc73e4e08c210def43b3c6eab22aa7333e3e000dbbe6d6d67c9182f6534613"
+ logic_hash = "0a10ba676706f70e2749591376b958283b48eb8278fdd736f5378429d6ec57e3"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -139339,67 +146327,32 @@ rule MALPEDIA_Win_Bankshot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bf8 8d5101 8a01 41 84c0 75f9 57 }
- $sequence_1 = { 8bec 81ec48040000 a1???????? 33c5 8945f8 53 }
- $sequence_2 = { e9???????? 57 33ff 8bcf 8bc7 894de4 3998c0e10110 }
- $sequence_3 = { c74048b8e40110 8b4508 6689486c 8b4508 66898872010000 8b4508 83a04c03000000 }
- $sequence_4 = { 33c9 33d2 66898c45f47fffff 8d8df47fffff 8d7102 668b01 83c102 }
- $sequence_5 = { 89855c38ffff fec1 888d6438ffff 85fa 0f84a4000000 }
- $sequence_6 = { 8b45fc 817848b8e40110 7409 ff7048 e8???????? }
- $sequence_7 = { 0f84a6000000 680c400000 8d85e4bfffff 53 50 }
- $sequence_8 = { 680c000200 e8???????? 8bf8 83c404 85ff 0f8429060000 6915????????04010000 }
- $sequence_9 = { 83c40c 8d85bcbaffff 33f6 6828050000 56 50 }
- $sequence_10 = { e8???????? 83c40c e8???????? 99 b907000000 }
- $sequence_11 = { e8???????? 83c404 89861c020000 8b45e0 8d4e0c 6a06 8d90c4e10110 }
- $sequence_12 = { 0f1f4000 80b40d943dffffaa 41 3bca 7cf3 }
- $sequence_13 = { c700???????? 8b4508 898850030000 8b4508 59 c74048b8e40110 }
- $sequence_14 = { 50 e8???????? 83c40c 6b45e430 8945e0 8d80d0e10110 }
- $sequence_15 = { 8b542420 8987d0000000 8b442424 898fd4000000 8917 }
- $sequence_16 = { e8???????? 488d0de7030000 e8???????? 33c0 4883c420 }
- $sequence_17 = { 488d0d1e960000 c705????????30000000 8bd8 c705????????02000000 48c705????????07000000 48893d???????? }
- $sequence_18 = { 8b0c95c8887100 8844192e 8b0495c8887100 804c182d04 ff4604 eb08 }
- $sequence_19 = { 51 ff15???????? 8bf0 83feff 89742410 7544 ff15???????? }
- $sequence_20 = { ff15???????? 68???????? 57 8985bcfbffff }
- $sequence_21 = { 48c744243002000080 e8???????? 488d8c2440020000 33d2 }
- $sequence_22 = { 52 8d85c4fbffff 50 ff15???????? 8d8dd0fdffff }
- $sequence_23 = { 57 83e502 4d ff15???????? 85f6 7407 }
- $sequence_24 = { 8d1c85b4ef0110 33c0 f00fb10b 8b15???????? 83cfff 8bca }
- $sequence_25 = { 7508 8b36 85f6 75e7 eb3a 81c694010000 }
- $sequence_26 = { e9???????? 8d8df0feffff 51 8d95e8feffff }
- $sequence_27 = { ff15???????? 8b8df8f3ffff c7410800000000 8b95f8f3ffff 837a0400 }
- $sequence_28 = { 8dbc24de040000 668974245c f3ab 66ab }
- $sequence_29 = { 85c9 0f85b5010000 488d8c2450030000 e8???????? e9???????? 498d4906 }
- $sequence_30 = { ff15???????? 41b958000000 488d1558530000 458d41d6 }
- $sequence_31 = { 8895affbffff 8b859cfbffff 8a8daffbffff 8808 8b9588fbffff }
- $sequence_32 = { 8b15???????? 6a01 8d4c2414 6a04 51 8944241c }
- $sequence_33 = { c1f906 6bc030 03048d80f10110 50 ff15???????? 5d }
- $sequence_34 = { 33cc e8???????? 8be5 5d c20400 8b8c241c3c0000 83c8ff }
- $sequence_35 = { 7531 e8???????? 8904bdc87f0110 85c0 7514 }
- $sequence_36 = { 6a03 6a00 6a03 8d8424c0040000 68000000c0 50 ff15???????? }
- $sequence_37 = { 33d2 488bc8 4889742448 ff15???????? 896c2460 8bdd }
- $sequence_38 = { 488d9560040000 41b800400000 488bce 89442460 89442468 4889442420 ff15???????? }
- $sequence_39 = { e8???????? 83c404 eb36 8d530c }
- $sequence_40 = { 8d7201 8a0a 42 84c9 75f9 6a00 }
- $sequence_41 = { 8815???????? 488d442438 488d353a490000 41b919000200 4533c0 48c7c102000080 }
- $sequence_42 = { 6bd030 895de4 8b049dc87f0110 8945d4 8955e8 8a5c1029 80fb02 }
- $sequence_43 = { 8b8544d4ffff 83c001 6689856cd4ffff 8a4d1c }
- $sequence_44 = { 51 68???????? 8b4dfc e8???????? b801000000 8be5 }
+ $sequence_0 = { 50 e8???????? ff35???????? 8d45dc 8bcf 6a00 50 }
+ $sequence_1 = { 53 50 ff75ec ff75d8 ff75dc ff15???????? 85c0 }
+ $sequence_2 = { 8a450f 33db 8d7e34 53 8bcf }
+ $sequence_3 = { 5f 5e c20400 53 56 ff742410 8bf1 }
+ $sequence_4 = { e8???????? dd4598 8b4de8 dd5db0 dd45a0 dd5db8 dd45a8 }
+ $sequence_5 = { 8d45b4 50 56 56 68???????? 56 56 }
+ $sequence_6 = { 8d4db0 e8???????? 8a45b0 83ec10 8bfc 8965e0 53 }
+ $sequence_7 = { 8b4d08 68???????? e8???????? 6a01 58 8945ec e9???????? }
+ $sequence_8 = { ff35???????? 8d45dc 8bcf 53 }
+ $sequence_9 = { ff7508 ff15???????? 85c0 7c43 ff7510 ff15???????? }
condition:
- 7 of them and filesize <860160
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Pandora_Auto : FILE
+rule MALPEDIA_Win_Kutaki_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "808a3fc1-f716-514d-83e0-324ab4b5c047"
+ id = "09920faf-098e-5e77-9216-3a3bfa3a1490"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pandora"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pandora_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kutaki"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kutaki_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "9af9b8ff0c31cb495b736863fe90279cd9d4c249691d7818a687e6d77e1bb76b"
+ logic_hash = "cdd66e692bdc9daff0e282b4897c4e9339c8de45be71e54a60a94829ea33b905"
score = 75
quality = 75
tags = "FILE"
@@ -139413,32 +146366,32 @@ rule MALPEDIA_Win_Pandora_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 48ffcb 48899d60020000 48ffc6 c60300 4c8bc6 488d8d60020000 }
- $sequence_1 = { 458bce 41c1c90b 4433c9 44895d40 418bce 458bc3 c1c906 }
- $sequence_2 = { 4885c0 750a b880eeffff e9???????? 4d8bcf 48896c2420 4c8d442430 }
- $sequence_3 = { 488d1d43ef0200 4885c0 7404 488d5820 8bcf e8???????? 8903 }
- $sequence_4 = { 4c8d7c2430 4c2bff 4c8dab80010000 0f1f4000 0f1f840000000000 488bd5 498d4d0f }
- $sequence_5 = { 418bf8 488bea 488bf1 4d85c9 7423 498b4128 }
- $sequence_6 = { 4533b48db0050700 418bcb 44337014 c1e908 0fb6d1 8bcb }
- $sequence_7 = { 452bf8 c1ed08 452be0 8d4147 41c1ef08 41c1ec08 458d48e6 }
- $sequence_8 = { 4403d1 418bc9 4181c139a093fc 41c1c20a 4403d2 f7d1 410bca }
- $sequence_9 = { 79da 85db 0f8538020000 4c8d45cf 498bd7 488d4db7 e8???????? }
+ $sequence_0 = { 52 6a01 6880000000 ff15???????? 83c41c c745fc0c000000 }
+ $sequence_1 = { 0f803a020000 8b450c 8910 e9???????? }
+ $sequence_2 = { ff15???????? 898528ffffff eb0a c78528ffffff00000000 8d4dc8 ff15???????? }
+ $sequence_3 = { ff15???????? 898568feffff eb0a c78568feffff00000000 8b459c 50 ff15???????? }
+ $sequence_4 = { c745fc3c000000 660fb64dd8 6683e10f 666bc910 0f80c9020000 660fb645c8 6699 }
+ $sequence_5 = { 8d4580 50 ff15???????? 8985d4feffff 6aff 8b8dd4feffff 8b11 }
+ $sequence_6 = { 8b45bc 50 8b4db8 51 ff15???????? 898540ffffff }
+ $sequence_7 = { c745fc08000000 6a74 8d855cffffff 50 ff15???????? 6a65 8d8d4cffffff }
+ $sequence_8 = { 50 68???????? ff15???????? 85c0 0f85bc000000 c745fc1a000000 }
+ $sequence_9 = { 52 ff15???????? 898550ffffff 8b4508 }
condition:
- 7 of them and filesize <1032192
+ 7 of them and filesize <1335296
}
-rule MALPEDIA_Win_Shifu_Auto : FILE
+rule MALPEDIA_Win_Corebot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b2b85e64-d954-5aeb-b02a-9d97cb3ba3ee"
+ id = "690f2e96-0cf9-536c-962e-128a98cf1d0b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shifu"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shifu_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.corebot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.corebot_auto.yar#L1-L167"
license_url = "N/A"
- logic_hash = "fa5868e6742fc467c77c9f2e2fa5062fd3f24b48dd60ea0ece307848b06e5759"
+ logic_hash = "f317e1a133d092285e381a2c4a6a16830d0d7cb17eced179ceadea1ad59e039d"
score = 75
quality = 75
tags = "FILE"
@@ -139452,32 +146405,38 @@ rule MALPEDIA_Win_Shifu_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 740d 57 6a1b ba???????? }
- $sequence_1 = { 6a24 ff7508 ffd6 53 8d45f0 50 }
- $sequence_2 = { 83651800 8d941a00010000 895508 8b5510 0fbe1410 89550c 85c9 }
- $sequence_3 = { 740c e8???????? 8325????????00 8d85fcfeffff e8???????? }
- $sequence_4 = { 50 ff75f4 ff15???????? 85c0 7511 ff75f0 8d443701 }
- $sequence_5 = { 668985a2fcffff b8170b0000 66898578fcffff 6a14 58 6689857afcffff 8b4348 }
- $sequence_6 = { 83c102 836d0c02 eb2d 8bd9 8b4f2c 2bd8 035de8 }
- $sequence_7 = { 8975e4 6a0c 58 e8???????? 8965e8 8bfc 3bfe }
- $sequence_8 = { 33c0 5e c9 c20c00 55 8bec 85c9 }
- $sequence_9 = { 56 8d85e8feffff 53 50 ff15???????? 8d85e8feffff 83c410 }
+ $sequence_0 = { 31c0 5e 5d c20800 55 89e5 }
+ $sequence_1 = { 01f3 8b75ec 56 8945f0 }
+ $sequence_2 = { 0fb618 895de8 c745ec07000000 8d141b 84db 8955e8 }
+ $sequence_3 = { 50 e8???????? 83c404 29f7 }
+ $sequence_4 = { 51 ff15???????? 85c0 0f95c0 eb08 c70600000000 }
+ $sequence_5 = { 31f6 8955e8 894dec 43 8b4dec 8d55f0 }
+ $sequence_6 = { 31f6 46 8918 89f0 83c40c 5e 5f }
+ $sequence_7 = { 43 8b4dec 8d55f0 e8???????? 85db 7827 }
+ $sequence_8 = { e8???????? 807e5800 7509 ff7654 ff15???????? 807e5000 7509 }
+ $sequence_9 = { eb10 6800800000 6a00 56 }
+ $sequence_10 = { 85c0 7515 8b4624 3b4620 }
+ $sequence_11 = { ff7010 ff7014 e8???????? 8b45e0 }
+ $sequence_12 = { ff15???????? 8d4634 50 ff15???????? 8d4e0c e8???????? }
+ $sequence_13 = { ff15???????? 807e5000 7509 ff764c ff15???????? 8d4634 50 }
+ $sequence_14 = { ff742428 e8???????? 8b442424 8d4c2410 }
+ $sequence_15 = { 85ff 740f 57 ff7508 }
condition:
- 7 of them and filesize <344064
+ 7 of them and filesize <1302528
}
-rule MALPEDIA_Win_Zerocleare_Auto : FILE
+rule MALPEDIA_Win_Photofork_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3657cdfc-db20-5908-b80b-f3809b1ef7a0"
+ id = "f7484eb7-9c89-5a31-aecd-73c9087aa29d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zerocleare"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zerocleare_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.photofork"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.photofork_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "684e088a58b2073463dab14cb1ba7b141fc0ac01570965634aebae02ef8b6f64"
+ logic_hash = "ff7473e2612dfba9efd366e89c657d77862d4c88088d1b5f47bab69cec947ba6"
score = 75
quality = 75
tags = "FILE"
@@ -139491,71 +146450,78 @@ rule MALPEDIA_Win_Zerocleare_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { db2d???????? b801000000 833d????????00 0f854f6efeff ba05000000 8d0df0694400 e8???????? }
- $sequence_1 = { 0f1185d8f7ffff f30f7e4010 660fd685e8f7ffff c7401000000000 c7401407000000 668908 c645fc04 }
- $sequence_2 = { 6a00 8d45e8 50 6a18 }
- $sequence_3 = { ffd6 6af4 898578f7ffff ffd6 }
- $sequence_4 = { 0f114598 0f1145a8 ff15???????? 8bf8 }
- $sequence_5 = { 895614 7410 c74620df494300 c74624f24a4300 eb0e c7462087414300 }
- $sequence_6 = { c745e4ad184200 eb08 8d4dd8 e8???????? 837e1808 74f2 8bce }
- $sequence_7 = { 660f58ca 660f2815???????? f20f59db 660f282d???????? 660f59f5 660f28aa70534400 660f54e5 }
- $sequence_8 = { 8b04cdd40a4400 5f 5e 5b 8be5 5d c3 }
- $sequence_9 = { 33c0 8985e4f7ffff 90 8b4c3814 8d1438 8d4101 }
+ $sequence_0 = { 33c9 4c8d85f0010000 ff15???????? 33db }
+ $sequence_1 = { 4885d2 7431 488b9278010000 4885d2 753a ba01000000 33c9 }
+ $sequence_2 = { 4d85c9 7535 8d5301 33c9 }
+ $sequence_3 = { ff15???????? 4863c8 48ffc6 4803f9 493bf7 0f825fffffff }
+ $sequence_4 = { 4c8b0d???????? 4d85c9 7430 4d8b8910110000 4d85c9 }
+ $sequence_5 = { 488d55e8 498bcc e8???????? 4c8bbc2498000000 }
+ $sequence_6 = { 5e 5d c3 498bdf 6690 80bbc001000030 }
+ $sequence_7 = { 48ffc1 4883f903 72ea 448b4df8 488d0c7e }
+ $sequence_8 = { 488bd0 488b05???????? 48899040060000 488d4dc0 ffd2 66837dc009 b840000000 }
+ $sequence_9 = { 8b44246c 0fb6442468 84c0 7520 }
condition:
- 7 of them and filesize <42670080
+ 7 of them and filesize <99328
}
-rule MALPEDIA_Win_Unidentified_075_Auto : FILE
+rule MALPEDIA_Win_Redleaves_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "147c0d53-aecb-5cae-ac7f-14d52d3c203f"
- date = "2023-07-11"
- modified = "2023-07-15"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_075"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_075_auto.yar#L1-L115"
+ id = "cc8fab97-eb1b-5c40-a45f-7f10d21eb6b6"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redleaves"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redleaves_auto.yar#L1-L162"
license_url = "N/A"
- logic_hash = "10617fdfd534147bc5e0f7e922724e69d45c37af66d21f98c629fa1bac685120"
+ logic_hash = "1a1a0a58298bb01a37c19c26700f5fe323706257844254db91cc834d1d6766e7"
score = 75
- quality = 75
+ quality = 69
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20230705"
- malpedia_hash = "42d0574f4405bd7d2b154d321d345acb18834a41"
- malpedia_version = "20230715"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83c40c 6808020000 8d95dcf6ffff 52 6a00 }
- $sequence_1 = { 8bc1 5e 5d c3 55 8bec ff15???????? }
- $sequence_2 = { 52 e8???????? 6a00 8d85ace6ffff 50 8d8dbceeffff 51 }
- $sequence_3 = { 83c40c 33c0 668985d4f4ffff 6806020000 }
- $sequence_4 = { 837d9400 740d 8b55fc c7821002000000000000 837df000 }
- $sequence_5 = { 52 ff15???????? 83c410 b853000000 66898550ffffff }
- $sequence_6 = { 33c0 668945d0 8d4dd4 51 }
- $sequence_7 = { 742c 8b4514 85c0 7421 }
- $sequence_8 = { 85c0 0f8431ffffff b901000000 85c9 0f8515ffffff }
- $sequence_9 = { 81eca4000000 894dfc c745f400000000 c745f800000000 }
+ $sequence_0 = { 51 7565 7279 55 7365 7254 }
+ $sequence_1 = { 47 657449 7041 64647254 }
+ $sequence_2 = { 54 53 51 7565 }
+ $sequence_3 = { 9c 894504 9c 9c }
+ $sequence_4 = { 83e901 0f85edffffff 89d0 29f8 5f 5b }
+ $sequence_5 = { 8d64241c d2c0 8a01 9c }
+ $sequence_6 = { 59 89f9 8d64241c d2c0 }
+ $sequence_7 = { 8b04b0 8b4018 898588fdffff 8d8578fdffff }
+ $sequence_8 = { 8b04b0 ff7018 ff701c 8d85acfdffff }
+ $sequence_9 = { 8bec 8b550c 53 8bd9 85d2 7f05 }
+ $sequence_10 = { 50 57 ffb610020000 e8???????? }
+ $sequence_11 = { 8bec a1???????? 56 85c0 7452 }
+ $sequence_12 = { 53 53 6804010000 8d85acfeffff }
+ $sequence_13 = { 8b04b0 83c41c 53 53 }
+ $sequence_14 = { 50 57 ffb60c020000 e8???????? 83c40c 8b860c020000 }
+ $sequence_15 = { 54 9c 60 9c }
+ $sequence_16 = { 9c 9c 8f442420 9c }
condition:
- 7 of them and filesize <393216
+ 7 of them and filesize <1679360
}
-rule MALPEDIA_Win_Gameover_P2P_Auto : FILE
+rule MALPEDIA_Win_Lightbunny_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f23c7d41-302b-54ee-89d3-a1fcd7481d37"
+ id = "546c8a57-6f91-59bb-b683-389534c380bb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gameover_p2p"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gameover_p2p_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lightbunny"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lightbunny_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "15df0db5593f1e0961da9a214002cfa7e3553ad059d6ba39628050e96c9953a2"
+ logic_hash = "4c0608cdc020e5347f646e557ecb414bd8f3027b0aca947da82d4930945e8be1"
score = 75
quality = 75
tags = "FILE"
@@ -139569,34 +146535,34 @@ rule MALPEDIA_Win_Gameover_P2P_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b01 8975dc 85c0 740f ffb09c010000 8d45d4 50 }
- $sequence_1 = { 8d873c010000 50 889f38010000 ffd6 }
- $sequence_2 = { ba???????? 8d8d70fdffff e8???????? 85c0 0f95c0 84c0 7509 }
- $sequence_3 = { 743f 53 8d442420 50 57 56 ff742428 }
- $sequence_4 = { 7769 8a442412 0fb6c0 668901 8a442413 0fb6c0 66894102 }
- $sequence_5 = { 7415 ff770c 8d442418 51 }
- $sequence_6 = { e8???????? 8bf8 689a000000 8bd3 8bce 897c242c }
- $sequence_7 = { b9a6000000 8d5588 e8???????? e8???????? 8bc8 e8???????? 8b750c }
- $sequence_8 = { 85c0 7548 68???????? ff35???????? ffd6 85c0 7537 }
- $sequence_9 = { f3ab 33db 6818010000 66ab 8d842410010000 53 50 }
+ $sequence_0 = { 6bc930 8b048520ae4100 0fb6440828 83e040 5d }
+ $sequence_1 = { 8bc1 83e13f c1f806 6bc930 8b048520ae4100 f644082801 }
+ $sequence_2 = { 83c404 6a02 ff35???????? ffd3 }
+ $sequence_3 = { 894708 0fb74602 50 ff15???????? }
+ $sequence_4 = { ff35???????? ff15???????? c705????????00000000 8b4dfc }
+ $sequence_5 = { 51 ff15???????? 85c0 740e 8b400c 8b00 }
+ $sequence_6 = { 8d3c9d58ab4100 f00fb10f 8bc8 85c9 740b }
+ $sequence_7 = { 83c404 83f801 0f851dffffff 8b5710 33c9 b8???????? 90 }
+ $sequence_8 = { 6bc030 c1f906 03048d20ae4100 eb02 8bc6 80782900 7522 }
+ $sequence_9 = { 8b75f8 33ff 8b0d???????? 8bc6 8945e4 894de8 }
condition:
- 7 of them and filesize <598016
+ 7 of them and filesize <2376704
}
-rule MALPEDIA_Win_Darkloader_Auto : FILE
+rule MALPEDIA_Win_Meterpreter_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "601e152a-7554-5605-b5d8-66c528809ef1"
+ id = "94296578-89d7-5d7b-b7e4-efe037d64332"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkloader_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.meterpreter"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.meterpreter_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "3bce0c9d521648c67df3e1e758ce6a8ac769bd1d815dcd4dfd750767fac4bfe8"
+ logic_hash = "71f865d4008295f79c7afc49beb427fb0376821d7b27897466868baff3347cd2"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -139608,34 +146574,34 @@ rule MALPEDIA_Win_Darkloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8bb42434020000 c1e607 68???????? 89b42438020000 8dbe10a10010 }
- $sequence_1 = { c70424???????? e8???????? c70424???????? 8bf8 56 e8???????? }
- $sequence_2 = { 51 ff36 8b00 8b00 8986b0010000 ff96bc010000 }
- $sequence_3 = { 57 ff74241c e8???????? 03c3 0fb73470 }
- $sequence_4 = { 3c5f 7447 3c2e 7443 3c7e }
- $sequence_5 = { 8b7c240c 8bcf 8906 8d5101 8a01 41 84c0 }
- $sequence_6 = { 84c0 740b 80f90d 7519 }
- $sequence_7 = { 894c241c 85c9 0f84b3000000 8b4020 }
- $sequence_8 = { 6bc503 40 50 e8???????? be???????? 8d7c2418 }
- $sequence_9 = { 83c428 50 6a40 6a05 53 ffd6 }
+ $sequence_0 = { 55 8bec dcec 088b55895356 108b3a85ff89 7dfc 750e }
+ $sequence_1 = { fc b8c0150000 8b7508 33e5 257e040275 238b1d6a016a 006a00 }
+ $sequence_2 = { f1 57 52 bc40e84fff 38ff 83db14 5f }
+ $sequence_3 = { 314319 034319 83ebfc 0acb }
+ $sequence_4 = { 0000 68ffff0000 52 ffd7 8b2410 }
+ $sequence_5 = { 8be5 5d c27f00 8d4df4 8d55ec }
+ $sequence_6 = { 51 6a00 6a00 37 0052bf 15???????? 85c0 }
+ $sequence_7 = { 8b451c 8d07 a4 52 8d4d18 50 }
+ $sequence_8 = { 41 00ff 15???????? 33c0 c3 7790 55 }
+ $sequence_9 = { 83ec08 53 8b4708 57 33ff 85db }
condition:
- 7 of them and filesize <124928
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Mimikatz_Auto : FILE
+rule MALPEDIA_Win_Deadwood_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d4a7b901-d580-5f27-9943-deb2fd01403a"
+ id = "5f00cc5a-9602-50e1-9261-d675303486e9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mimikatz"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mimikatz_auto.yar#L1-L208"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.deadwood"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.deadwood_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "545bdfd9bb109ef6aa7c579d3c8a6e0e694cb1fac0a4b134cb9c66bf853a0582"
+ logic_hash = "ea97d4cccc4d6a9b5e482bbc380fcc6fbef419bedaf1f051b13240e62ed24277"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -139647,44 +146613,32 @@ rule MALPEDIA_Win_Mimikatz_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f7f1 85d2 7406 2bca }
- $sequence_1 = { 83f8ff 750e ff15???????? c7002a000000 }
- $sequence_2 = { c3 81f998000000 7410 81f996000000 7408 }
- $sequence_3 = { e8???????? 894720 85c0 7413 }
- $sequence_4 = { f30f6f4928 f30f7f8c24a0000000 f30f6f4138 f30f7f8424b8000000 }
- $sequence_5 = { 83f812 72f1 33c0 c3 }
- $sequence_6 = { ff5028 8be8 85c0 787a }
- $sequence_7 = { 66894108 33c0 39410c 740b }
- $sequence_8 = { eb0c bfdfff0000 6623fe 6683ef07 8b742474 }
- $sequence_9 = { 6683f83f 7607 32c0 e9???????? }
- $sequence_10 = { 2bc1 85c9 7403 83c008 d1e8 8d441002 }
- $sequence_11 = { ff15???????? b940000000 8bd0 89442430 }
- $sequence_12 = { 3c02 7207 e8???????? eb10 }
- $sequence_13 = { ff15???????? b9e9fd0000 8905???????? ff15???????? }
- $sequence_14 = { 8d04f530d94600 8938 68a00f0000 ff30 83c718 ff15???????? 85c0 }
- $sequence_15 = { 837e1800 7402 ffd0 e8???????? 53 }
- $sequence_16 = { 57 33ff ffb750da4600 ff15???????? 898750da4600 83c704 }
- $sequence_17 = { e8???????? 8d04453cdb4600 8bc8 2bce 6a03 d1f9 68???????? }
- $sequence_18 = { a1???????? a3???????? a1???????? c705????????cf2f4000 8935???????? }
- $sequence_19 = { 8888a0d44600 40 ebe6 ff35???????? ff15???????? }
- $sequence_20 = { 8a80a4d54600 08443b1d 0fb64601 47 3bf8 76ea 8b7d08 }
- $sequence_21 = { 43 83c408 83fb04 7cdc 8b5df8 8ad3 }
+ $sequence_0 = { 51 e8???????? 83c404 33db be0f000000 89b42418010000 899c2414010000 }
+ $sequence_1 = { 7303 8d4508 8b5518 52 50 8b4110 50 }
+ $sequence_2 = { 7464 8bf0 8b4814 894c2424 3bcb 7504 895c2428 }
+ $sequence_3 = { 6a01 8d442414 50 8d4c243c 897c247c c744241878f44500 e8???????? }
+ $sequence_4 = { 8bf8 85ff 0f8484000000 53 53 53 53 }
+ $sequence_5 = { ff15???????? 6804010000 8d8df4fdffff 51 50 ff15???????? 33d2 }
+ $sequence_6 = { e8???????? 8b542460 c7442440e4ba4500 bb???????? 895c2454 8b4204 c7440460c8ba4500 }
+ $sequence_7 = { 8b07 8b4804 837c390c00 0f94c1 884dd8 c745fc01000000 84c9 }
+ $sequence_8 = { 74ed 89450c 8b13 807a1d00 7404 8b3e eb13 }
+ $sequence_9 = { 8bb510ffffff e9???????? c3 8d8d34ffffff e9???????? 8d8d18ffffff e9???????? }
condition:
- 7 of them and filesize <1642496
+ 7 of them and filesize <1055744
}
-rule MALPEDIA_Win_Dircrypt_Auto : FILE
+rule MALPEDIA_Win_Tapaoux_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b395b5b7-d790-5f9f-ab3c-658138d51b34"
+ id = "68d778fd-5462-5b8a-898a-2fe57f5f9d68"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dircrypt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dircrypt_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tapaoux"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tapaoux_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "9b92693268fddc2e1dd801012d692fa19a40b6fbb8b33ec64e384964127e0228"
+ logic_hash = "f82a0c342c816d1880cfb31489fc94204aa3933a5341062512dc21730819514f"
score = 75
quality = 75
tags = "FILE"
@@ -139698,32 +146652,32 @@ rule MALPEDIA_Win_Dircrypt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7531 c705????????01000000 e8???????? e8???????? 833d????????00 7514 68???????? }
- $sequence_1 = { e8???????? e8???????? 68???????? ff15???????? 833d????????00 751a }
- $sequence_2 = { 68???????? e8???????? 05d2070000 50 e8???????? a3???????? 6a13 }
- $sequence_3 = { 8bec 51 6a00 6a00 8d45fc 50 68???????? }
- $sequence_4 = { 68???????? 8d45dc 50 e8???????? 6a00 e8???????? }
- $sequence_5 = { 6801000080 e8???????? e8???????? e8???????? e8???????? }
- $sequence_6 = { e8???????? 05d5070000 50 6a01 6a02 6a08 }
- $sequence_7 = { 68???????? 8d45dc 50 e8???????? 6a00 e8???????? 05d6070000 }
- $sequence_8 = { 833d????????00 7514 68???????? 68???????? e8???????? a3???????? 833d????????00 }
- $sequence_9 = { 51 6a00 6a00 8d45fc 50 68???????? 6802000080 }
+ $sequence_0 = { 83c404 8d9424d0020000 33f6 52 55 ffd3 85c0 }
+ $sequence_1 = { f7d1 49 8d7c2454 894c2418 83c9ff f2ae f7d1 }
+ $sequence_2 = { 52 50 8d4c2420 68???????? 51 eb49 b900010000 }
+ $sequence_3 = { 68???????? 52 ffd6 8d44245c 68???????? 50 }
+ $sequence_4 = { 8be8 83fdff 0f84b0000000 8b3d???????? }
+ $sequence_5 = { 83c404 8d4c2414 50 51 e8???????? 8d54241c }
+ $sequence_6 = { 8d442408 55 50 8d8c241c040000 6800040000 51 56 }
+ $sequence_7 = { c3 8d442408 8d4c240c 50 53 53 }
+ $sequence_8 = { 68???????? 50 e8???????? 8b07 83c418 85c0 7526 }
+ $sequence_9 = { aa 8bb424200c0000 b900010000 33c0 }
condition:
- 7 of them and filesize <671744
+ 7 of them and filesize <294912
}
-rule MALPEDIA_Win_Bart_Auto : FILE
+rule MALPEDIA_Win_Mail_O_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1691d219-2287-5770-a9af-369cb19fd25c"
+ id = "f99f4969-80f4-597a-910e-873dc6aaa6b8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bart"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bart_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mail_o"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mail_o_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "20a38c1c6b8b98b8d85839077c1f03f4679fb05ea3fd09bb3acf392b4f9ee60a"
+ logic_hash = "873a5557134df7611d1b518c4c6caa2026bc1ae07076d192a3e745c13ea47ee0"
score = 75
quality = 75
tags = "FILE"
@@ -139737,32 +146691,32 @@ rule MALPEDIA_Win_Bart_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b0483 3bd0 772e 7205 80c1ff 79e8 33c9 }
- $sequence_1 = { 8b0433 03c2 03c1 3bc2 7404 1bc9 }
- $sequence_2 = { 8a18 894dd0 8955c8 8945cc 57 85f6 }
- $sequence_3 = { 660fd6459c e8???????? 83c410 8d8570ffffff 33c9 ba07000000 }
- $sequence_4 = { e8???????? 8b7598 8d4d9c 8b5590 0fb606 }
- $sequence_5 = { 8b4485dc d3e8 88043a 0fbed3 3bd6 7cde 8bbd58ffffff }
- $sequence_6 = { 7868 8bc8 0fbec2 8b5508 894c2418 8d1482 8a44240e }
- $sequence_7 = { 84db 0f8ed3020000 0fb6d3 8bc7 899564ffffff 0b08 8d4004 }
- $sequence_8 = { 8bca e8???????? 8b4dfc 83c438 33cd 5f 5e }
- $sequence_9 = { 0f88ff000000 8b7df4 83c706 42 }
+ $sequence_0 = { 7707 33c0 e9???????? f683a414000020 7417 8b83700e0000 2500000100 }
+ $sequence_1 = { f20f104c2450 f20f114930 83cbff 8b0f e8???????? 8bc3 488b5c2470 }
+ $sequence_2 = { eb0c 488d15b7940d00 e8???????? 488b4708 488d542440 448b4710 33c9 }
+ $sequence_3 = { b920000000 ffcb ff542428 83f8ff 0f84b2010000 ffc7 85db }
+ $sequence_4 = { 8b5c2438 418d7f10 4533c0 498bce 3bfb 7e23 488d542440 }
+ $sequence_5 = { e8???????? eb17 498b4d10 4d8bf4 418bdc e8???????? eb06 }
+ $sequence_6 = { c744242071000000 448d4041 eb1f 488918 488bd0 488b4d08 e8???????? }
+ $sequence_7 = { 85c0 743c 48ffc3 483b5c2430 72c3 488bcf e8???????? }
+ $sequence_8 = { 84c0 7465 48ffc1 498d0408 483bc2 72df ba00800000 }
+ $sequence_9 = { e8???????? 8bf8 85c0 7556 48837c245000 7505 8d7809 }
condition:
- 7 of them and filesize <163840
+ 7 of them and filesize <5985280
}
-rule MALPEDIA_Win_Multigrain_Pos_Auto : FILE
+rule MALPEDIA_Win_Medusa_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a0867608-6152-525b-bb1e-ffd07d70fa86"
+ id = "e5ced166-c5f3-50c0-9e84-e449f6bff889"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.multigrain_pos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.multigrain_pos_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.medusa"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.medusa_auto.yar#L1-L167"
license_url = "N/A"
- logic_hash = "e5b2ff30a169eba30bec1ec0cb7a796ca39923255067b4e9a8563c5dcf8b4ca3"
+ logic_hash = "b88f5d47ff30b39fc78331a46c037d026177b73d253964f40555a9ce1312bb08"
score = 75
quality = 75
tags = "FILE"
@@ -139776,32 +146730,38 @@ rule MALPEDIA_Win_Multigrain_Pos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c745fc00000000 8b7518 b8cdcccccc 8d0cf504000000 }
- $sequence_1 = { 57 e8???????? 83c404 6a00 c746140f000000 }
- $sequence_2 = { c645fc01 e8???????? 83c408 83bdb4fdffff08 720e ffb5a0fdffff }
- $sequence_3 = { 0f8530020000 68c8000000 50 8d85c4feffff 50 e8???????? 83c40c }
- $sequence_4 = { 0fb64c1e01 c1e905 894df4 eb07 c745f400000000 0fb60c1e 8b55f8 }
- $sequence_5 = { 8bd0 8d4dd8 c645fc03 e8???????? }
- $sequence_6 = { c745e0ffffffff c745e800000000 c745e400000000 c745ec01000000 c745f401000000 }
- $sequence_7 = { e8???????? 83c404 56 ffd3 33db 395f10 56 }
- $sequence_8 = { 81eca8040000 a1???????? 33c4 898424a4040000 56 57 }
- $sequence_9 = { c745f400000000 8b4df0 8b5df8 0fb609 83e101 }
+ $sequence_0 = { 680049ff69 004aff 6a00 4b ff6b00 4c ff6c004d }
+ $sequence_1 = { 1a03 69c421f3ef6a 2048b3 a5 }
+ $sequence_2 = { 52 ff7200 53 ff7300 54 }
+ $sequence_3 = { 317f52 56 5c ab 92 6f 0c48 }
+ $sequence_4 = { 9e 45 334a54 98 56 39ec 51 }
+ $sequence_5 = { 9f c48b2addd977 7612 a5 ba3c533f71 }
+ $sequence_6 = { e60e 6c 7bbc 45 }
+ $sequence_7 = { 54 ff740055 ff7500 56 }
+ $sequence_8 = { 99 5f 68066e570a 4f bfdb4a7adc }
+ $sequence_9 = { 1ddf859f31 e476 0c48 ce 74ec 1b826a013061 }
+ $sequence_10 = { 2a18 ae 085ffb cf }
+ $sequence_11 = { b5f9 43 324dd5 1ddf859f31 e476 0c48 }
+ $sequence_12 = { 5f e1fb 1cc9 3ca5 2c8e a1???????? d528 }
+ $sequence_13 = { b051 9f 4a d7 b9533e507c }
+ $sequence_14 = { 6c 6f aa 97 691c85470859bab566c1a5 }
+ $sequence_15 = { 813bf80937dc 8b4c6386 8608 5f }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <1720320
}
-rule MALPEDIA_Win_Dropshot_Auto : FILE
+rule MALPEDIA_Win_Gameover_P2P_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f835fd17-f919-5a07-a5c9-cff4292c1163"
+ id = "f23c7d41-302b-54ee-89d3-a1fcd7481d37"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dropshot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dropshot_auto.yar#L1-L98"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gameover_p2p"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gameover_p2p_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "98ce90f78c6e888102f62c73a346864796873af9c7b795369b519cebc67a4ac6"
+ logic_hash = "15df0db5593f1e0961da9a214002cfa7e3553ad059d6ba39628050e96c9953a2"
score = 75
quality = 75
tags = "FILE"
@@ -139815,30 +146775,32 @@ rule MALPEDIA_Win_Dropshot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83c40c 6a04 6800100000 6804010000 6a00 ff15???????? }
- $sequence_1 = { ff15???????? 5d c3 3b0d???????? f27502 }
- $sequence_2 = { 6a64 ff15???????? 6800800000 6a00 }
- $sequence_3 = { 6a05 ff15???????? ff15???????? 6a00 }
- $sequence_4 = { eb05 e8???????? 68e8030000 ff15???????? }
- $sequence_5 = { ff15???????? 6a04 6800100000 6808020000 }
- $sequence_6 = { ff15???????? 6a00 ff15???????? 6a00 ff15???????? 6a05 }
- $sequence_7 = { 6a00 6a00 68???????? 6a00 ff15???????? b801000000 }
+ $sequence_0 = { 8b01 8975dc 85c0 740f ffb09c010000 8d45d4 50 }
+ $sequence_1 = { 8d873c010000 50 889f38010000 ffd6 }
+ $sequence_2 = { ba???????? 8d8d70fdffff e8???????? 85c0 0f95c0 84c0 7509 }
+ $sequence_3 = { 743f 53 8d442420 50 57 56 ff742428 }
+ $sequence_4 = { 7769 8a442412 0fb6c0 668901 8a442413 0fb6c0 66894102 }
+ $sequence_5 = { 7415 ff770c 8d442418 51 }
+ $sequence_6 = { e8???????? 8bf8 689a000000 8bd3 8bce 897c242c }
+ $sequence_7 = { b9a6000000 8d5588 e8???????? e8???????? 8bc8 e8???????? 8b750c }
+ $sequence_8 = { 85c0 7548 68???????? ff35???????? ffd6 85c0 7537 }
+ $sequence_9 = { f3ab 33db 6818010000 66ab 8d842410010000 53 50 }
condition:
- 7 of them and filesize <483328
+ 7 of them and filesize <598016
}
-rule MALPEDIA_Win_Webc2_Cson_Auto : FILE
+rule MALPEDIA_Win_Termite_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9e77cd9b-5577-55ec-9bc9-fce8ae6111d5"
+ id = "f52e0f9c-00a2-57d7-aba9-0dbbb1d1c2e2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_cson"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_cson_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.termite"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.termite_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "7c0e799e7902791c334e5b7573181538432e1af2060bac92fa55c2a280799f66"
+ logic_hash = "cc787c4fe1eac82cec1ddbf65768a64c7a8c2c3d8dd4b766767f73077448495f"
score = 75
quality = 75
tags = "FILE"
@@ -139852,34 +146814,34 @@ rule MALPEDIA_Win_Webc2_Cson_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8d85f0feffff 50 e8???????? 6a1e 8db5f6feffff 59 }
- $sequence_1 = { be???????? 8dbd74ffffff 6a0a f3a5 a4 be???????? 56 }
- $sequence_2 = { 50 e8???????? 59 59 ff7508 8d85acfcffff 50 }
- $sequence_3 = { e8???????? 59 59 68???????? ff15???????? 53 bf???????? }
- $sequence_4 = { 83c410 85ff 743f 85c0 743b 2bc7 }
- $sequence_5 = { 8bec 81ec54030000 53 56 8b35???????? 57 33db }
- $sequence_6 = { 83f803 0f859c010000 53 53 53 53 }
- $sequence_7 = { 8d7d81 885d80 f3ab 66ab aa 6a0f 33c0 }
- $sequence_8 = { 8bec 81ec3c060000 53 56 be04010000 }
- $sequence_9 = { 5e 5b c9 c20400 c605????????01 be00900100 6800040000 }
+ $sequence_0 = { 8b4508 c1e003 89c2 c1e206 01d0 05???????? 8d5004 }
+ $sequence_1 = { e8???????? c744240814000000 8d45dc 89442404 8b45f4 890424 }
+ $sequence_2 = { c744241cffffffff c74424188cd44000 c7442414ffffffff 8b4510 89442410 8b450c 8944240c }
+ $sequence_3 = { 837dfc00 75d7 b800000000 c9 c3 55 }
+ $sequence_4 = { 8b10 a1???????? 8b4d08 894c2408 89542404 890424 e8???????? }
+ $sequence_5 = { e8???????? 83f814 7706 837d1400 7f0a b8ffffffff }
+ $sequence_6 = { 837d0c00 750a b800000000 e9???????? 8b450c 8b4010 8945f0 }
+ $sequence_7 = { 89442404 8b45f0 890424 e8???????? c70424???????? e8???????? 8b45f4 }
+ $sequence_8 = { c704240a000000 e8???????? eb0a c745f401000000 eb08 90 c745f400000000 }
+ $sequence_9 = { 83ec04 89442404 8d85b4feffff 890424 e8???????? 8d85b4feffff 89442404 }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <312320
}
-rule MALPEDIA_Win_Keyboy_Auto : FILE
+rule MALPEDIA_Win_Bedep_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1db1fbfb-59c2-5bfb-976b-a0743f8a46eb"
+ id = "38514c33-d67a-59ce-9042-a62977e3ef09"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.keyboy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.keyboy_auto.yar#L1-L207"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bedep"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bedep_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "c0d23ea688bcee5d6eecf54208ea66cac91415e69b2f38d43039891e2137c619"
+ logic_hash = "f62533daae7175b045e5c4c81adb2d2dce588f3fcc3da789cd782a4e3103423f"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -139891,44 +146853,32 @@ rule MALPEDIA_Win_Keyboy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 8945f2 8d45f8 50 6a0e }
- $sequence_1 = { 51 ff75d8 6a00 ff75c0 }
- $sequence_2 = { c705????????d468bcb5 c705????????2086e659 c705????????eec45abf c705????????bbee2bd1 c705????????3e20f129 }
- $sequence_3 = { c705????????890e9944 c705????????dbd99823 c705????????d468bcb5 c705????????2086e659 }
- $sequence_4 = { 5d c3 3b0d???????? f27502 f2c3 f2e953030000 55 }
- $sequence_5 = { c705????????0caa6c89 c705????????a856701f c705????????597e743c c705????????0a9769e0 c705????????c4b85363 c705????????3abf261f c705????????890e9944 }
- $sequence_6 = { 57 68cc020000 8d852cfdffff 8bf2 6a00 50 89b528fdffff }
- $sequence_7 = { ff75dc ff15???????? 8d45dc 50 }
- $sequence_8 = { e9???????? bbfeffffff eb05 bbfdffffff }
- $sequence_9 = { 24a0 3ca0 7518 b800080000 }
- $sequence_10 = { 6683f806 7404 32c9 eb02 b101 }
- $sequence_11 = { c705????????34fbfb41 c705????????e6cd2b66 c705????????79e66d38 c705????????ba66ea37 c705????????1671e665 c705????????f3106cb3 c705????????526c1ed0 }
- $sequence_12 = { e8???????? 85c0 755e 83ff20 }
- $sequence_13 = { 2408 f6d8 1ac0 24dd }
- $sequence_14 = { 41 84c0 75f0 8d55ec c745ec5c417070 }
- $sequence_15 = { 7cd6 5f 5e 8be5 }
- $sequence_16 = { ff15???????? 8b15???????? 8b4dc0 8945b8 e8???????? }
- $sequence_17 = { 7207 b901000000 eb0f 3cfe }
- $sequence_18 = { f7d9 85db 0f44c2 23c8 }
- $sequence_19 = { 85d2 7e2a 8bce 81e107000080 }
- $sequence_20 = { 3401 0fbec0 0fafc8 80f185 880c3e 46 }
- $sequence_21 = { 1ac0 24dd 88474e e8???????? }
+ $sequence_0 = { 8b4dd4 c70020000000 c7400421020000 8bc6 881e c6460103 }
+ $sequence_1 = { 8b4608 e8???????? 85c0 7c19 6a20 8bc7 e8???????? }
+ $sequence_2 = { e8???????? 85c0 8945f4 7e3a 837df800 7463 8bcb }
+ $sequence_3 = { 33ff 89742418 8974241c 8b542418 56 ff742420 8d4c2430 }
+ $sequence_4 = { 7d09 56 e8???????? 59 eb05 8b450c 8930 }
+ $sequence_5 = { 397338 89442428 0f85bb000000 6a7c 8d8424a4000000 56 50 }
+ $sequence_6 = { 75e2 b001 5e c20400 55 8bec 83e4f8 }
+ $sequence_7 = { 56 90 e8???????? 832000 6a04 ff750c 33c9 }
+ $sequence_8 = { 8d4568 50 ff7570 90 e8???????? 894570 64a118000000 }
+ $sequence_9 = { ff751c 83cb02 ff7520 53 ff7514 50 8d45f4 }
condition:
- 7 of them and filesize <2170880
+ 7 of them and filesize <557056
}
-rule MALPEDIA_Win_Longwatch_Auto : FILE
+rule MALPEDIA_Win_Ruckguv_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9cbc3845-247e-5088-802c-974faf2556c3"
+ id = "70c59136-1542-5cb3-8c7d-52dba7e0bc40"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.longwatch"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.longwatch_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ruckguv"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ruckguv_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "f16a1609422dbff4c114599f67e44a3d80148789c090def0703b76643a40482b"
+ logic_hash = "a64635c0a8f169255c2ded62c13acd231a3b9a4460e9b10acd2e149c6348dd85"
score = 75
quality = 75
tags = "FILE"
@@ -139942,32 +146892,32 @@ rule MALPEDIA_Win_Longwatch_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? e8???????? 83c404 833d????????ff 7546 6a00 }
- $sequence_1 = { 8bec 53 8b5d08 33c9 57 33c0 8d3c9d2c074300 }
- $sequence_2 = { 0f8cf8030000 68a1000000 ff15???????? 6683f888 0f8ce3030000 8d46fe }
- $sequence_3 = { eb29 8b55d4 8a07 8b0c95a00b4300 }
- $sequence_4 = { 53 8b5d08 33c9 57 33c0 8d3c9d2c074300 f00fb10f }
- $sequence_5 = { 6bc618 57 8db874074300 57 }
- $sequence_6 = { 8ad3 b9???????? e8???????? 837d9400 8db548ffffff }
- $sequence_7 = { e8???????? ff7364 33c9 8d7b18 84c0 0f44f9 }
- $sequence_8 = { 56 68a0000000 8bf1 ff15???????? }
- $sequence_9 = { c74634d46e4200 6a00 57 8bce e8???????? }
+ $sequence_0 = { 7403 51 eb04 0fb7c0 50 ff7508 }
+ $sequence_1 = { 56 53 e8???????? 8b463c 68f8000000 }
+ $sequence_2 = { ff75fc 8d85b0f7ffff 50 ff75f4 }
+ $sequence_3 = { 59 894508 85c0 750f 8b470c }
+ $sequence_4 = { 85c0 0f848b000000 57 8d3c18 8b470c 85c0 }
+ $sequence_5 = { 8a0a 84c9 75f1 c3 682680acc8 }
+ $sequence_6 = { 83c0c0 50 8d4640 50 8d4340 }
+ $sequence_7 = { 68dff0f081 6a01 e8???????? 83c40c 8d8d9cfdffff 51 ffd0 }
+ $sequence_8 = { 6880000000 6a03 56 56 53 }
+ $sequence_9 = { 59 59 ff742404 ffd0 c3 6831f478b7 }
condition:
- 7 of them and filesize <647168
+ 7 of them and filesize <41024
}
-rule MALPEDIA_Win_Snatchcrypto_Auto : FILE
+rule MALPEDIA_Win_Lurk_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8e680a41-0fdc-5ac7-bc9f-3f795f28f0bb"
+ id = "67fdecf6-fece-5b5e-aa84-6821eaa887bc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.snatchcrypto"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.snatchcrypto_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lurk"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lurk_auto.yar#L1-L180"
license_url = "N/A"
- logic_hash = "276b735298fc8584b98457d3cb267661e785fa3122c696ae64ba4741a5859a9d"
+ logic_hash = "1d68cad8f119a971efeb0a8c788b3983d9ce03607f838f5c4c4d29840d917af1"
score = 75
quality = 75
tags = "FILE"
@@ -139981,34 +146931,40 @@ rule MALPEDIA_Win_Snatchcrypto_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7528 488bd3 488bcf e8???????? 448b87a8020000 488d15d43f0200 448906 }
- $sequence_1 = { 4c8d442430 e8???????? 85c0 0f8533010000 8d7058 8d6814 eb36 }
- $sequence_2 = { ff15???????? 488bf8 4885c0 750f ff15???????? 488d15f7730200 eb27 }
- $sequence_3 = { 0fb74348 ff4320 448b4b20 ffc0 488d1586a70200 440fb7c0 e8???????? }
- $sequence_4 = { 48894598 4889442458 4889442460 0fb6474d 41c1e608 440bf0 0fb6474e }
- $sequence_5 = { 440fb64c3580 4c8d05a73f0100 ba03000000 488bcf e8???????? 48ffc6 4883c702 }
- $sequence_6 = { 4883ec38 ffca 744c 81faff1f0000 754b 33c0 4c8905???????? }
- $sequence_7 = { e8???????? 8bf8 85c0 7907 b8c0feffff eb3f 0fb78394030000 }
- $sequence_8 = { 83c702 3ac1 760a b8bafeffff e9???????? 7368 0fb78b94030000 }
- $sequence_9 = { 488d15e98d0200 498bce 4c8bc0 e8???????? 8d7e3e 448be3 e9???????? }
+ $sequence_0 = { ff7508 ff15???????? 8b35???????? 50 ff7508 }
+ $sequence_1 = { 8b4508 5b 5f 5e c9 c3 55 }
+ $sequence_2 = { 8b4d08 8b5110 83c201 8b4508 895010 8b4dac 51 }
+ $sequence_3 = { f3a5 66a5 33db 395d08 }
+ $sequence_4 = { 72cc 33c9 8bc1 99 6a0b 5f f7ff }
+ $sequence_5 = { c1ee03 33ce eb0e c1e60b 33ce 8bf0 c1ee05 }
+ $sequence_6 = { 59 3bc7 7534 0fbe4203 }
+ $sequence_7 = { 8b3d???????? 33f6 bb24080000 53 6a40 8975ec }
+ $sequence_8 = { ff750c 83ceff ff7508 ff7510 e8???????? 83c418 85c0 }
+ $sequence_9 = { ff750c 57 ff15???????? 85c0 7411 395dfc 750c }
+ $sequence_10 = { 68???????? 8d85ecfeffff 50 ff15???????? 8d85ecfeffff 50 }
+ $sequence_11 = { ebf8 56 8bf0 33c0 85d2 8bca 740c }
+ $sequence_12 = { 8945fc 8b4d10 8b91a4000000 8955f8 837df800 7661 }
+ $sequence_13 = { c9 c3 55 8bec 81ec08010000 6a35 6a40 }
+ $sequence_14 = { 744d 56 8d4508 50 }
+ $sequence_15 = { 83f866 7567 3bf0 7563 0fbe4205 50 e8???????? }
condition:
- 7 of them and filesize <1400832
+ 7 of them and filesize <5316608
}
-rule MALPEDIA_Win_Deltas_Auto : FILE
+rule MALPEDIA_Win_Gootkit_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7da5df4e-29e3-54c4-9a20-6a6e85d7900e"
+ id = "50659808-58ce-5271-8f0d-8034418275c7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.deltas"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.deltas_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gootkit"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gootkit_auto.yar#L1-L327"
license_url = "N/A"
- logic_hash = "dd0f3991acf6e3d198b5d6cf834071e4c8ad802b2fea2e9cf5d21d8d4fb219f6"
+ logic_hash = "a2cf121428fb2173dc07901e77686f48303de5dc8bfa584df38195e7a090200e"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -140020,32 +146976,58 @@ rule MALPEDIA_Win_Deltas_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d542434 898424d8000000 52 ffd6 898424d0000000 8d442458 50 }
- $sequence_1 = { b22e b06c 51 c644240c77 c644240d73 c644240f5f c644241033 }
- $sequence_2 = { c684241002000000 f3ab 66ab aa 8d442408 6804010000 50 }
- $sequence_3 = { 8d742438 8dbc24f4000000 33c0 f3a5 b908000000 8d7c2418 }
- $sequence_4 = { 68???????? 68???????? 50 ffd7 8d8c241c020000 6804010000 8d94241c010000 }
- $sequence_5 = { 57 33f6 b922000000 33c0 }
- $sequence_6 = { 52 ffd6 898424e0000000 8d442440 50 ffd6 }
- $sequence_7 = { 894c242d 56 66894c2435 33f6 89442420 884c2437 57 }
- $sequence_8 = { 0bc1 33c7 0344242c 8d8410442229f4 8bd0 c1e006 c1ea1a }
- $sequence_9 = { c644245400 c684245801000000 f3ab 66ab }
+ $sequence_0 = { 6a04 6800300000 57 6a00 897df8 }
+ $sequence_1 = { 50 ff75fc ffd7 33c9 c745f804000000 41 33f6 }
+ $sequence_2 = { 8945f0 85c0 7435 8b01 ff75f4 03c3 }
+ $sequence_3 = { e8???????? 8bd8 85db 0f45f3 33c0 50 }
+ $sequence_4 = { 83feff 7509 57 ff15???????? 8bf0 53 }
+ $sequence_5 = { 895de8 2bf1 75d5 8b5df0 8b5508 51 }
+ $sequence_6 = { 6a00 53 ff15???????? eb06 8b7dd8 }
+ $sequence_7 = { 8bd6 e8???????? 8b7dfc 59 59 85c0 }
+ $sequence_8 = { f3aa 68???????? ff15???????? 50 }
+ $sequence_9 = { 8b7df4 32c0 8b4de4 f3aa }
+ $sequence_10 = { 50 e8???????? 83c40c 68fd000000 }
+ $sequence_11 = { 50 68???????? ff15???????? 85c0 7505 e8???????? }
+ $sequence_12 = { 50 8b4508 8b00 99 }
+ $sequence_13 = { c705????????01000000 c705????????02000000 8be5 5d c3 }
+ $sequence_14 = { 833d????????00 750a 6a32 ff15???????? }
+ $sequence_15 = { 6808020000 6a00 ff15???????? 50 }
+ $sequence_16 = { e8???????? 6a0c 6a08 ff15???????? 50 ff15???????? }
+ $sequence_17 = { 50 6a02 ff15???????? 6888130000 }
+ $sequence_18 = { e8???????? 8d45fc 50 6a01 6a01 }
+ $sequence_19 = { e8???????? 85c0 750c c705????????03000000 }
+ $sequence_20 = { 8b4508 8b00 99 52 50 6a00 }
+ $sequence_21 = { 68???????? 51 51 ff15???????? 50 }
+ $sequence_22 = { 53 53 53 8901 }
+ $sequence_23 = { 83faff 7508 ff15???????? 8bd0 }
+ $sequence_24 = { e8???????? 3935???????? 7412 83ec0c ba???????? b9???????? }
+ $sequence_25 = { 6a40 6a00 8bf7 57 81e60000ffff e8???????? 8b4608 }
+ $sequence_26 = { ff15???????? a3???????? 391d???????? 7428 85c0 }
+ $sequence_27 = { 8d4204 3bc8 7344 2bca 898de4fdffff 034e0c }
+ $sequence_28 = { ff15???????? 85c0 7510 8d4864 }
+ $sequence_29 = { 0f114710 0f104030 0f114f20 0f104840 0f114730 0f104050 }
+ $sequence_30 = { 85c0 7550 ff15???????? 8bf8 893d???????? }
+ $sequence_31 = { 6a1c 50 56 ff15???????? 8b4de8 }
+ $sequence_32 = { 0f104010 0f110f 0f104820 0f114710 }
+ $sequence_33 = { 0f114f50 0f104060 0f114760 8b4070 894770 be01000000 }
+ $sequence_34 = { 8d4864 ff15???????? ffc3 83fb0a 7cd5 }
+ $sequence_35 = { 0f104050 0f114f40 0f104860 0f114750 0f114f60 b801000000 }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <516096
}
-rule MALPEDIA_Win_Zeus_Sphinx_Auto : FILE
+rule MALPEDIA_Win_Karagany_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4c9695e3-d96e-5f67-a0c2-424bcf596515"
+ id = "edc2e98f-b8d5-5230-8689-3d1d2cb2218e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus_sphinx"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeus_sphinx_auto.yar#L1-L158"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.karagany"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.karagany_auto.yar#L1-L110"
license_url = "N/A"
- logic_hash = "c474cca5e98993ccd970de7e5648248c620e9abab23dec872f161292bb6b1fb0"
+ logic_hash = "52de418a32cc53d0482440cda283dab56320888d4a5fd4c0281ba321f99401f6"
score = 75
quality = 75
tags = "FILE"
@@ -140059,38 +147041,32 @@ rule MALPEDIA_Win_Zeus_Sphinx_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? 891c24 89c6 e8???????? 83c410 8d65f4 }
- $sequence_1 = { 50 e8???????? 83c414 68???????? e8???????? c70424???????? }
- $sequence_2 = { 50 e8???????? 83c410 c74604ffffffff 897508 }
- $sequence_3 = { 50 e8???????? 83c430 85c0 7e0c }
- $sequence_4 = { 52 52 8b6c2444 55 50 e8???????? 8944245c }
- $sequence_5 = { 50 e8???????? 84c0 745f 8d442414 }
- $sequence_6 = { 50 e8???????? 83c420 48 }
- $sequence_7 = { 50 e8???????? 83c418 68???????? 68???????? }
- $sequence_8 = { 01fc eb98 035e14 8ade }
- $sequence_9 = { 010c02 3bf7 0f85f0f50000 e9???????? }
- $sequence_10 = { 003b c09bdbe23ea11c 695600663ec700 de07 }
- $sequence_11 = { 0303 50 ff550c 8b3e }
- $sequence_12 = { 010d???????? 60 5a 98 }
- $sequence_13 = { 020a 42 1af6 af }
- $sequence_14 = { 0162c9 cf 0c06 3c3e }
- $sequence_15 = { 0008 d7 9f b2d3 }
+ $sequence_0 = { 8d85a4fdffff 50 ffd6 68???????? }
+ $sequence_1 = { 894ddc 894de4 894df0 894df8 894dfc }
+ $sequence_2 = { 57 8bf8 6a03 57 ffd6 }
+ $sequence_3 = { 57 8bf8 6a03 57 }
+ $sequence_4 = { 6800300000 6800000300 6a00 ff15???????? }
+ $sequence_5 = { 8bf8 6a03 57 ffd6 85c0 }
+ $sequence_6 = { 8b35???????? 57 8bf8 6a03 }
+ $sequence_7 = { 6a40 6800300000 6800000300 6a00 ff15???????? }
+ $sequence_8 = { 6a03 53 ffd6 85c0 }
+ $sequence_9 = { 57 8bf8 6a03 57 ffd6 85c0 }
condition:
- 7 of them and filesize <3268608
+ 7 of them and filesize <180224
}
-rule MALPEDIA_Win_Nachocheese_Auto : FILE
+rule MALPEDIA_Win_New_Ct_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "eaa2162c-aba5-5a56-92b8-2694c1a819b5"
+ id = "d2add3a1-140a-5bb8-b61a-9a3c6a02e7fc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nachocheese"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nachocheese_auto.yar#L1-L162"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.new_ct"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.new_ct_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "65398c7b0a5280da9a71f8939ca7f529421377deec37e9f371d0deba7b01dc67"
+ logic_hash = "d5abc4cf0e59662bf031f834b2da1a42e3067fae0164acdda49916fdb832ef21"
score = 75
quality = 75
tags = "FILE"
@@ -140104,38 +147080,32 @@ rule MALPEDIA_Win_Nachocheese_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3d9c000000 7c07 3d9f000000 7e0d 33c0 c3 05d13fffff }
- $sequence_1 = { 33f6 397508 0f8ec9000000 b8???????? 48 }
- $sequence_2 = { 2bfa 8d47fd 3901 8901 }
- $sequence_3 = { 02ca 880c3e 8a5005 32d1 8b4dfc 88143e 8a4c0105 }
- $sequence_4 = { 7305 83c303 eb1c 81fb00000100 }
- $sequence_5 = { 33c8 894710 8b4708 33c1 }
- $sequence_6 = { 7305 83c304 eb0f 81fb00000001 }
- $sequence_7 = { 7305 83c302 eb29 81fb00010000 }
- $sequence_8 = { 0f8539ffffff b8???????? 8d5001 8a08 }
- $sequence_9 = { 3d2cc00000 7f18 3d2bc00000 7d1b 3d9c000000 }
- $sequence_10 = { 763a b801011000 f7e6 8bc6 2bc2 d1e8 }
- $sequence_11 = { 0f84bf000000 6803010000 8895f0fcffff 8d95f1fcffff 6a00 52 e8???????? }
- $sequence_12 = { 50 e8???????? 8d8f0e010000 8bc1 83c430 8d5001 }
- $sequence_13 = { 02ca 8b55f4 880c3e 0fb6540205 }
- $sequence_14 = { 50 e8???????? b9???????? 83c424 }
- $sequence_15 = { 50 6a02 51 ff15???????? 83f801 }
+ $sequence_0 = { 894304 7532 8bfe 83c9ff 33c0 f2ae f7d1 }
+ $sequence_1 = { 7472 3c42 746e 33c0 }
+ $sequence_2 = { 81ec00040000 53 56 6888030000 33db }
+ $sequence_3 = { 7605 b800000100 8b742418 03c7 8d8c24bc070000 8d44301c }
+ $sequence_4 = { c644240537 c644240679 c6442407b9 7627 }
+ $sequence_5 = { 8bcd 8933 2bce c6043e00 49 33c0 }
+ $sequence_6 = { 50 6a00 6a00 68???????? 6a00 68???????? ff15???????? }
+ $sequence_7 = { 33c0 8dbc24bd070000 c68424bc07000000 c68424bc0f000000 f3ab 66ab aa }
+ $sequence_8 = { 740d 8d942414020000 52 ffd0 83c404 5f 5e }
+ $sequence_9 = { 8bbc245c040000 c1e902 f3a5 8bc8 83e103 f3a4 }
condition:
- 7 of them and filesize <1064960
+ 7 of them and filesize <122880
}
-rule MALPEDIA_Win_Dented_Auto : FILE
+rule MALPEDIA_Win_Htprat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "484f6875-8da3-59df-9796-ec6e3c5f3480"
+ id = "67b2e8d9-4f49-5cf6-8afe-0a9a5bcb5d69"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dented"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dented_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.htprat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.htprat_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "e9882555c27a882adee62a69216aa411600cf976159b592ea9f38f19d9990be3"
+ logic_hash = "15d5d8ea42e22569434bb0dbf96f0b13036ea7676d82ad93d8f718afb8dd6a66"
score = 75
quality = 75
tags = "FILE"
@@ -140149,32 +147119,32 @@ rule MALPEDIA_Win_Dented_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bf1 e8???????? 83c40c 89bd60ffffff 8d8560ffffff 50 ff15???????? }
- $sequence_1 = { 50 51 ebc7 6a0f 33db 5f 897df4 }
- $sequence_2 = { ffd6 ff75fc ffd6 6a00 6a01 8d4d08 e8???????? }
- $sequence_3 = { ff15???????? 3d0e000780 7422 3d08000c80 741b }
- $sequence_4 = { 8985c4fcffff 8d85f4fdffff 6a40 8985c8fcffff 8d85b4fcffff 5e 50 }
- $sequence_5 = { 8d4dc0 e8???????? 385dc4 7508 6a04 }
- $sequence_6 = { 6a40 5f 57 8d45b8 }
- $sequence_7 = { 8b85f8f7ffff 8a8485fcfbffff 32c1 880416 8b8decf7ffff }
- $sequence_8 = { 48 0d00ffffff 40 8a0a 8985f8f7ffff 8bbdf8f7ffff 0fb6c1 }
- $sequence_9 = { 8b4a38 3b08 6a0f 0f4208 33db 8b4210 }
+ $sequence_0 = { 8b8568efffff 03c6 3b8558efffff 7667 8b8394000000 898560efffff 8b8558efffff }
+ $sequence_1 = { 8bc7 897dcc e8???????? 8b5dc8 3b5f04 740e }
+ $sequence_2 = { 8d4c2418 c68424e800000003 e8???????? 8b00 3bc3 7504 32db }
+ $sequence_3 = { 33d2 f3a6 6aff 58 7404 1bd2 1bd0 }
+ $sequence_4 = { 46 56 8d8d00ffffff e8???????? 53 56 }
+ $sequence_5 = { 85c0 750c e8???????? a3???????? eb13 53 }
+ $sequence_6 = { 8b00 8d8d38efffff 51 8d8d08efffff 51 50 ff33 }
+ $sequence_7 = { 894584 99 f77d8c 8b4590 8a0402 8b5594 }
+ $sequence_8 = { 83c604 3b7734 75ec eb31 83f805 }
+ $sequence_9 = { 8d410c 8bcb e8???????? 84c0 0f84d2000000 8b5d0c }
condition:
- 7 of them and filesize <450560
+ 7 of them and filesize <278528
}
-rule MALPEDIA_Win_Xfsadm_Auto : FILE
+rule MALPEDIA_Win_Seasalt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6a0bbf1b-24f1-56ab-8ac3-dbd47808408e"
+ id = "e41fdf89-eed2-569c-87d1-66ae3f31eb44"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xfsadm"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xfsadm_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.seasalt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.seasalt_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "b3759828684909f4ce479e79726b48d5eca09cda3ca207a8e06b6b8b2444949c"
+ logic_hash = "c4e00a9b356da4bb38f74ae93a3974f0cb2a6403defdfa59feac8c8b4bbe886d"
score = 75
quality = 75
tags = "FILE"
@@ -140188,71 +147158,71 @@ rule MALPEDIA_Win_Xfsadm_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c40c 85c0 0f8431010000 81ff???????? 0f849f000000 6a01 68???????? }
- $sequence_1 = { 50 ff15???????? ffb534fdffff 8bf0 ff15???????? 0fb60d???????? 33c0 }
- $sequence_2 = { 8b7e38 85ff 0f8576010000 53 68f80f0000 e8???????? }
- $sequence_3 = { 85c9 7455 83c60c 3bf1 744e }
- $sequence_4 = { 8b4008 8a0406 3c3d 745e }
- $sequence_5 = { 83fa02 7211 8b4dfc 8a06 46 8b0c8df8d84200 88440f2b }
- $sequence_6 = { 5b 8be5 5d c20800 3c2f 751c }
- $sequence_7 = { 2d10010000 741d 83e801 7521 0fb74510 83f801 }
- $sequence_8 = { 8d460c 83c410 3bc8 7409 51 e8???????? 83c404 }
- $sequence_9 = { 50 e8???????? 8b4e08 8d460c 83c410 3bc8 }
+ $sequence_0 = { 888800d90010 eb1f 83f861 7213 }
+ $sequence_1 = { a3???????? 3bc6 7513 68e0930400 ff15???????? 8975fc }
+ $sequence_2 = { 83d8ff 3bc3 758c b901040000 33c0 }
+ $sequence_3 = { f2ae a1???????? 68???????? f7d1 }
+ $sequence_4 = { 8b8c2454010000 6a00 8d442428 6800010000 50 }
+ $sequence_5 = { 6aff 50 ff15???????? 85c0 6a00 }
+ $sequence_6 = { 8bf7 c1e902 8bfa 8d942488010000 f3a5 }
+ $sequence_7 = { 7ced 55 8bac2418020000 6a00 8d442414 6804020000 50 }
+ $sequence_8 = { 8dbc2419020000 c684241802000000 f3ab 66ab 6a00 }
+ $sequence_9 = { c1e902 83e203 83f908 7229 f3a5 ff2495c8350010 8bc7 }
condition:
- 7 of them and filesize <566272
+ 7 of them and filesize <139264
}
-rule MALPEDIA_Win_Blackpos_Auto : FILE
+rule MALPEDIA_Win_Pvzout_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "52663687-3a52-5b88-8f0a-e8064cfb2262"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackpos_auto.yar#L1-L121"
+ id = "bc80d9fe-85e4-55f8-8d8b-08382557b556"
+ date = "2023-01-25"
+ modified = "2023-01-26"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pvzout"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pvzout_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "8568ffc0a3f0ef5ce5cdc7a729339af7d16e27d116b4f347ef077609e2cc96da"
+ logic_hash = "3b1eb492455f147bf0fe300cd3d173313439f65c62c0ebecede0fab8aacab139"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
+ malpedia_rule_date = "20230124"
+ malpedia_hash = "2ee0eebba83dce3d019a90519f2f972c0fcf9686"
+ malpedia_version = "20230125"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? b800000200 3bf8 7602 8bf8 8d85f4fffdff }
- $sequence_1 = { 3bca 7408 47 83ff44 72ef eb08 }
- $sequence_2 = { 83c414 85c0 7433 e8???????? 85c0 }
- $sequence_3 = { 8d4dbc 51 03c6 50 e8???????? }
- $sequence_4 = { 3bfb 0f84f8000000 68ff030000 8d85fdfbffff 53 50 }
- $sequence_5 = { f7f9 8b4dfc 5f 5e 5b 8bc2 }
- $sequence_6 = { 8b8040f84100 3bf0 7e44 83ee07 eb3f 2503000080 7905 }
- $sequence_7 = { 3bf7 7513 8d45e0 50 e8???????? 59 }
- $sequence_8 = { 6a07 59 6804010000 be???????? }
- $sequence_9 = { e8???????? 83c40c 85c0 7414 6a01 68???????? }
+ $sequence_0 = { 3e3f 19e9 73f8 dca10ebd24e8 252b0026cb }
+ $sequence_1 = { 5a bf95f6810e 75a8 43 1dea50873a d4a1 }
+ $sequence_2 = { 9c b3d7 5a bf95f6810e 75a8 }
+ $sequence_3 = { bbedffffff 03dd 81eb00d00200 83bd8804000000 899d88040000 }
+ $sequence_4 = { 3089f33d80f3 48 e21c 3e3f }
+ $sequence_5 = { 5d bbedffffff 03dd 81eb00d00200 83bd8804000000 }
+ $sequence_6 = { 03dd 81eb00d00200 83bd8804000000 899d88040000 }
+ $sequence_7 = { d4a1 0e 75a8 43 }
+ $sequence_8 = { 81eb00d00200 83bd8804000000 899d88040000 0f85cb030000 8d8594040000 50 }
+ $sequence_9 = { 5a bf95f6810e 75a8 43 1dea50873a d4a1 0e }
condition:
- 7 of them and filesize <3293184
+ 7 of them and filesize <573440
}
-rule MALPEDIA_Win_Finfisher_Auto : FILE
+rule MALPEDIA_Win_Aveo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3ef79a6b-24c3-58ed-a290-c5a2a7e3fb1b"
+ id = "20a83532-4a6e-562c-b0b0-f75c536df8d1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.finfisher"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.finfisher_auto.yar#L1-L148"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aveo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aveo_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "dcf5252aa492d908a47d122045beaf12bf03e72009d0665a415b9ab4e015a1e5"
+ logic_hash = "0a926409298a7da9832c13e4dae3f40393311db59f4c541fcfd58f63e4b0b943"
score = 75
quality = 75
tags = "FILE"
@@ -140266,36 +147236,32 @@ rule MALPEDIA_Win_Finfisher_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? 6804010000 8d85ccf9ffff 50 }
- $sequence_1 = { 56 8d85ccf9ffff 50 e8???????? }
- $sequence_2 = { 6a20 6a03 8d8594f7ffff 50 8d8578f7ffff 50 68000000c0 }
- $sequence_3 = { 663bc1 7506 8345e404 ebd8 }
- $sequence_4 = { 0f853affffff c785d0fbffffd5d8ffff e9???????? 8b07 83e808 }
- $sequence_5 = { 52 68a0608000 eb11 8b4708 8b4dd4 }
- $sequence_6 = { 397714 7403 56 eb02 6a02 56 50 }
- $sequence_7 = { e8???????? 56 e8???????? 8b861c030000 3d10270000 }
- $sequence_8 = { 56 8d859cf7ffff 50 56 a1???????? }
- $sequence_9 = { 85db 7424 8b17 8d448614 8b08 }
- $sequence_10 = { e9???????? 8b859cf7ffff ff7004 ff15???????? 8985c0f7ffff 8b8d9cf7ffff }
- $sequence_11 = { 6a09 ff15???????? 3bc6 7490 8bd0 }
- $sequence_12 = { ffb5b8f7ffff eb5f 8d8578f7ffff 50 6a01 8d85acf7ffff }
- $sequence_13 = { 8d85acfbffff 50 53 56 }
+ $sequence_0 = { 8b85ecfaffff 83c40c 50 8bcb 51 8db5f8fdffff }
+ $sequence_1 = { 53 56 57 8db570faffff }
+ $sequence_2 = { 8d8d10feffff e8???????? 8b95f8fdffff 52 8bf0 }
+ $sequence_3 = { 8b4de0 8d55dc 52 6800008000 }
+ $sequence_4 = { 8d8554faffff 8d8d70faffff e8???????? 8b955cfaffff 52 e8???????? }
+ $sequence_5 = { 50 f3a4 ff15???????? 6800010000 8d8df8feffff 6a00 51 }
+ $sequence_6 = { 53 8d4802 8955f4 56 8a51fe }
+ $sequence_7 = { 7424 8b85f4efffff 3bc7 741a }
+ $sequence_8 = { c7442418e8030000 ff15???????? 3bc7 740c 68???????? 50 }
+ $sequence_9 = { c7430801000000 e8???????? 6a06 89430c 8d4310 8d89d41a4100 5a }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <180224
}
-rule MALPEDIA_Win_Sunorcal_Auto : FILE
+rule MALPEDIA_Win_Pickpocket_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8d478635-7b1a-5ec4-85a6-3854fefcfed4"
+ id = "9a488247-9e86-5930-98a0-6918c231e819"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sunorcal"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sunorcal_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pickpocket"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pickpocket_auto.yar#L1-L111"
license_url = "N/A"
- logic_hash = "58249461fa7cf2580b3033b5e590d54e14d2db390f8c7cf00dbe39cb0b927df2"
+ logic_hash = "d7990d44202646b62032b82a90fb7e07e373731a34449c62076ef24e8ce04d57"
score = 75
quality = 75
tags = "FILE"
@@ -140309,34 +147275,34 @@ rule MALPEDIA_Win_Sunorcal_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a03 e8???????? cc 55 8bec 83ec0c a1???????? }
- $sequence_1 = { c21000 8b442404 8b00 813863736de0 752a 83781003 7524 }
- $sequence_2 = { 5e 5b c21000 8b442404 8b00 813863736de0 752a }
- $sequence_3 = { ff15???????? 33c0 c3 c3 55 8bec }
- $sequence_4 = { 7c02 eb0e e8???????? e8???????? 85c0 }
- $sequence_5 = { 5b c21000 8b442404 8b00 813863736de0 }
- $sequence_6 = { 68b7000000 ff15???????? 6a64 68???????? }
- $sequence_7 = { 5b c21000 8b442404 8b00 813863736de0 752a 83781003 }
- $sequence_8 = { ff15???????? 68b7000000 ff15???????? 6a64 68???????? 6a67 }
- $sequence_9 = { 68???????? ff15???????? 33c0 c3 c3 55 8bec }
+ $sequence_0 = { 85c0 750f b962890100 e8???????? }
+ $sequence_1 = { 7e1e b9dccc0000 e9???????? b9cecc0000 e9???????? b9c7cc0000 }
+ $sequence_2 = { 7404 8b01 eb03 83c8ff 83f804 }
+ $sequence_3 = { d3e0 a846 750f b99be00100 e8???????? e9???????? }
+ $sequence_4 = { e8???????? 85c0 750e b958de0100 }
+ $sequence_5 = { 85c0 750e b958de0100 e8???????? 8bc8 }
+ $sequence_6 = { 85c0 740f b989000100 e8???????? }
+ $sequence_7 = { 7e16 b91bcc0000 eb05 b916cc0000 }
+ $sequence_8 = { eb0c b96ccb0000 eb05 b960cb0000 }
+ $sequence_9 = { eb09 8bc7 eb0a b9a9d60000 e8???????? }
condition:
- 7 of them and filesize <172032
+ 7 of them and filesize <1458176
}
-rule MALPEDIA_Win_Dridex_Auto : FILE
+rule MALPEDIA_Win_Expiro_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fd4d4346-8d83-5613-888d-88569f1753b9"
+ id = "9bf3ea51-503d-5f40-a69a-188866df3f7b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dridex"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dridex_auto.yar#L1-L1066"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.expiro"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.expiro_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "7f3078493ad3e901d3230994f499bb2b8f95c8666fe5cee6d8f3649c308a4e21"
+ logic_hash = "c555162dc1357feb9808816e071d9b9f76383f5167ecd985c2225c4cf3cc9bed"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -140348,151 +147314,32 @@ rule MALPEDIA_Win_Dridex_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd6 85c0 7512 e8???????? eb03 }
- $sequence_1 = { e8???????? b910270000 e8???????? e8???????? }
- $sequence_2 = { c605????????01 c3 c605????????00 c3 }
- $sequence_3 = { 83f8ff 7505 e8???????? 3d34270000 }
- $sequence_4 = { ffd0 85c0 751f e8???????? }
- $sequence_5 = { ffd0 e8???????? 85c0 74de }
- $sequence_6 = { 53 53 53 6a01 53 ffd0 }
- $sequence_7 = { eb0a e8???????? eb03 6a7f 58 }
- $sequence_8 = { c3 31c0 c3 50 }
- $sequence_9 = { 7406 42 803a00 75fa }
- $sequence_10 = { 7403 56 ffd0 33f6 }
- $sequence_11 = { e8???????? 85c0 7407 56 ffd0 }
- $sequence_12 = { 807c241400 7409 8d4c2410 e8???????? }
- $sequence_13 = { e8???????? 6880000000 53 53 }
- $sequence_14 = { e8???????? 85c0 7408 6a00 ffd0 }
- $sequence_15 = { e8???????? 6a00 8d4e1c e8???????? }
- $sequence_16 = { e8???????? eb0a b9d0070000 e8???????? }
- $sequence_17 = { ffd0 5b c3 33c0 }
- $sequence_18 = { c70350000000 eb0d 3da665f63e 7506 }
- $sequence_19 = { e8???????? 85c0 7404 6a7f }
- $sequence_20 = { 85c0 7407 685a040000 ffd0 }
- $sequence_21 = { e8???????? 3db20d7897 7508 c70350000000 }
- $sequence_22 = { 8bc8 e8???????? 6a70 8bc8 e8???????? 6a73 8bc8 }
- $sequence_23 = { 50 e8???????? 8938 8b35???????? }
- $sequence_24 = { 6a00 6a00 8d4dfc 51 6aff }
- $sequence_25 = { e8???????? 6a74 8bc8 e8???????? 6a74 8bc8 }
- $sequence_26 = { 6810270000 50 e8???????? 83c410 }
- $sequence_27 = { 7411 c7461003000000 e8???????? 894614 }
- $sequence_28 = { 85c0 7415 6a01 6a00 6a00 }
- $sequence_29 = { 6a00 8bcf e8???????? 50 ffd6 }
- $sequence_30 = { eb08 83ca20 eb03 83ca10 }
- $sequence_31 = { 46 e8???????? c1e802 3bf0 }
- $sequence_32 = { e8???????? e9???????? 807c245000 740a }
- $sequence_33 = { e8???????? 8d4dc4 e8???????? 5e }
- $sequence_34 = { 6802100000 68ffff0000 ff36 ffd0 }
- $sequence_35 = { ffd0 85c0 7510 e8???????? }
- $sequence_36 = { c20400 55 8bec 83ec34 8365fc00 }
- $sequence_37 = { 89442404 eb00 8b442404 89c1 89ca }
- $sequence_38 = { 7414 31c0 89c1 8b442424 88c2 8854240f }
- $sequence_39 = { 8b442428 6689c1 66894c2458 66894c245a }
- $sequence_40 = { 8a442427 a801 7534 eb00 31c0 89c1 }
- $sequence_41 = { 6a64 59 e8???????? 33c9 e8???????? }
- $sequence_42 = { 51 6801100000 68ffff0000 ff36 }
- $sequence_43 = { 7406 6a02 ff36 ffd0 }
- $sequence_44 = { 740d 40 83c104 3d00100000 }
- $sequence_45 = { 885c2407 89442408 7598 8a442407 a801 }
- $sequence_46 = { c7461002000000 eb0f c7461003000000 e8???????? }
- $sequence_47 = { 890424 894c2404 75dd 8b0424 }
- $sequence_48 = { e8???????? 50 56 8bcb e8???????? 50 e8???????? }
- $sequence_49 = { 8954242c 8b44242c 89c1 89ca }
- $sequence_50 = { eb0a b988130000 e8???????? 33d2 }
- $sequence_51 = { 740a 488d4c2448 e8???????? 488d4c2430 e8???????? e9???????? }
- $sequence_52 = { e8???????? 84c0 740f 6a05 }
- $sequence_53 = { e8???????? 8be8 85ed 7458 }
- $sequence_54 = { e8???????? 6880000000 55 55 }
- $sequence_55 = { ff7508 ffd0 33c0 40 5d }
- $sequence_56 = { c3 55 8bec 837d0800 7422 }
- $sequence_57 = { 8d4de0 51 68???????? ffd0 }
- $sequence_58 = { 6a73 e8???????? 833f00 7523 }
- $sequence_59 = { 6a00 6a02 ffd0 50 }
- $sequence_60 = { e8???????? 8bc8 a1???????? ff30 }
- $sequence_61 = { 5e c3 31c0 89c2 }
- $sequence_62 = { e8???????? 50 ffd7 85c0 7512 }
- $sequence_63 = { eb0c e8???????? 8bf0 eb03 6a7f 5e }
- $sequence_64 = { 8b45cc 31c9 8b55d0 39c2 }
- $sequence_65 = { 8038e9 89c1 8945d0 894dcc }
- $sequence_66 = { e8???????? 50 53 8d4dd0 e8???????? 50 }
- $sequence_67 = { 8b45e8 05ffff0000 25ffff0000 83c001 }
- $sequence_68 = { 8b4de8 81c1ffff0000 81e1ffff0000 83c101 }
- $sequence_69 = { 50 8b442408 8038e9 890424 7517 8b0424 8b4801 }
- $sequence_70 = { 8b704c 2b7134 891424 89742404 894c2418 e8???????? }
- $sequence_71 = { 8b55bc 8955c4 776a 31c0 8b4dac 8b510c }
- $sequence_72 = { 807c0805e9 891424 74e9 8b0424 }
- $sequence_73 = { 8b450c 8b4d08 8b503c 6689d6 6683fe00 89c7 8945f0 }
- $sequence_74 = { 83c001 8b4de8 01c1 894de0 }
- $sequence_75 = { 7517 8b0424 8b4801 89c2 01ca 83c205 }
- $sequence_76 = { 8b513c 6689d6 6683fe00 89cf 8945f0 894dec }
- $sequence_77 = { 01ca 83c205 807c0805e9 891424 }
- $sequence_78 = { 89c7 8945f0 894dec 8955e8 897de4 }
- $sequence_79 = { 5b 5e 5d c3 55 89e5 6a00 }
- $sequence_80 = { 83c001 8b4df8 01c1 894df0 8b45f0 }
- $sequence_81 = { 83c454 5b 5e 5f 5d c3 55 }
- $sequence_82 = { 894df0 8b45f0 83c40c 5e }
- $sequence_83 = { e9???????? 8b45e0 83c438 5f }
- $sequence_84 = { 8945f8 894df4 8975f0 7418 8b45f4 05ffff0000 }
- $sequence_85 = { 25ffff0000 83c001 8b4da8 01c1 }
- $sequence_86 = { 8945c4 894dc0 885dbf 8975b8 }
- $sequence_87 = { c3 55 89e5 57 56 53 83ec54 }
- $sequence_88 = { 5b 5d c3 8b45d0 8b4dd4 668b55d8 31f6 }
- $sequence_89 = { 8b45e0 83c45c 5f 5b 5e 5d }
- $sequence_90 = { 53 56 83ec38 8b450c 8b4d08 }
- $sequence_91 = { c7424800b00400 8b7c2418 c787cc00000000000000 c787c800000000000000 }
- $sequence_92 = { 8955cc 74bc 8b45cc 83c454 5b 5e }
- $sequence_93 = { 6a00 e8???????? 83c408 c3 6a00 68???????? }
- $sequence_94 = { 8d442448 b91c000000 8b542438 891424 89442404 c74424081c000000 894c2434 }
- $sequence_95 = { 893c24 89442404 c744240804000000 8954240c 89ac248c000000 898c2488000000 }
- $sequence_96 = { 8945c8 75e4 83c448 5e 5f 5b 5d }
- $sequence_97 = { 53 83ec74 8b450c 8b4d08 31d2 8b713c }
- $sequence_98 = { 0f85dafeffff 8b45e4 83c474 5b }
- $sequence_99 = { 55 89e5 56 57 53 83ec70 }
- $sequence_100 = { 53 81ecb0000000 8b4508 8d4dd8 c745d800000000 }
- $sequence_101 = { 5b 5d c3 8b45f0 8b0c8504406e00 8b55f8 39d1 }
- $sequence_102 = { 8b0c8504406e00 8b55f8 39d1 8945ec 894de8 7212 }
- $sequence_103 = { 83f900 89442464 0f84f2010000 b801000000 8b4c2468 8b91a4000000 }
- $sequence_104 = { 83c470 5b 5f 5e 5d c3 }
- $sequence_105 = { 8b45e0 83c438 5e 5b }
- $sequence_106 = { 57 83ec20 8b4508 890424 }
- $sequence_107 = { 890424 e8???????? 31c0 83c420 5f }
- $sequence_108 = { c7424800c00400 8b7de4 c787cc00000000000000 c787c800000000000000 }
- $sequence_109 = { 897dd8 8b45d8 83c444 5b 5e 5f }
- $sequence_110 = { e8???????? 8d0d44306e00 31d2 8b75f8 89462c }
- $sequence_111 = { 894620 890c24 c744240400000000 8955e0 e8???????? 8d0dd8306e00 890424 }
- $sequence_112 = { 8d155e306e00 83ec04 891424 8945e8 894de4 }
- $sequence_113 = { 8b55f4 8b75ec 89723c c7424004000000 c742442c0c0200 c7424800b00400 }
- $sequence_114 = { 55 89e5 53 56 57 83ec38 8b450c }
- $sequence_115 = { c742442c0c0200 c7424800b00400 8b7de4 c787cc00000000000000 }
- $sequence_116 = { 8d0dbc306e00 890424 894c2404 e8???????? 8d0d44306e00 }
- $sequence_117 = { 74bc 8b45cc 83c454 5f 5b 5e }
- $sequence_118 = { 0f84e2feffff e9???????? 8b45e0 83c45c 5e 5f 5b }
- $sequence_119 = { 56 53 57 83ec44 8b4508 }
- $sequence_120 = { 8955e0 e8???????? 8d0dd8302700 890424 }
- $sequence_121 = { 89462c 890c24 c744240400000000 8955d8 e8???????? 8d0d04318400 }
- $sequence_122 = { c7424004000000 c7424499040200 c7424800c00400 8b7de4 }
- $sequence_123 = { c3 55 89e5 83ec10 8b4508 8d0d44302500 }
- $sequence_124 = { 56 83ec44 8b4508 8d0d30302500 31d2 890c24 }
- $sequence_125 = { 31c0 8d0d5a232f00 8b55c8 39ca 8945cc 0f84f9000000 }
- $sequence_126 = { 890c24 c744240400000000 8955e4 e8???????? 8d0dc9302f00 890424 894c2404 }
- $sequence_127 = { 8d0d44302f00 31d2 8b75f8 894608 890c24 c744240400000000 }
- $sequence_128 = { 8d0d30302700 31d2 890c24 c744240400000000 8945f0 8955ec e8???????? }
+ $sequence_0 = { 33c9 6689147e 3bcd 5f 1bc0 5e }
+ $sequence_1 = { 52 e8???????? 83c404 33c0 668944244c 6a04 897c2464 }
+ $sequence_2 = { 0f848f000000 803d????????00 0f8582000000 803d????????00 7579 8d8c24cc010000 }
+ $sequence_3 = { 8b4d00 eb02 8bcd 8d3441 0fb703 }
+ $sequence_4 = { b8???????? 8d4c2414 e8???????? 8d442414 50 8d4c2434 51 }
+ $sequence_5 = { 7373 7373 7353 7373 13ea 02abd9737373 }
+ $sequence_6 = { bf5c000000 52 55 8d5fa5 33c0 897c241c }
+ $sequence_7 = { 0fb74208 f6c303 7409 8d04c5c6234100 eb23 f6c30c }
+ $sequence_8 = { 31733e 45 cf 7160 7373 7308 7373 }
+ $sequence_9 = { 7373 7377 7373 7373 7373 7373 93 }
condition:
- 7 of them and filesize <1040384
+ 7 of them and filesize <3776512
}
-rule MALPEDIA_Win_Unidentified_013_Korean_Malware_Auto : FILE
+rule MALPEDIA_Win_Darkmoon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6cb9e399-7a4a-5f81-aaa6-7cb702a29e01"
+ id = "c7bc3212-028b-5215-8293-c0df2749aba3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_013_korean_malware"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_013_korean_malware_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkmoon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkmoon_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "c008af161ea64c4cea7a6eccb5b08fe1a4b68cae21f50d0dd25e80b0eb93ad58"
+ logic_hash = "5987f0c1a065561468c6153b43a5b63a22d14e5454b4b93cd49fdb8fd5a12783"
score = 75
quality = 75
tags = "FILE"
@@ -140506,32 +147353,32 @@ rule MALPEDIA_Win_Unidentified_013_Korean_Malware_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3bd7 7cf5 7f04 3bc5 72ef }
- $sequence_1 = { 57 a1???????? 33c4 50 8d842458060000 64a300000000 68???????? }
- $sequence_2 = { 6800040000 8d4c241c 51 57 ffd5 85c0 743f }
- $sequence_3 = { 81c40c040000 c3 8b2d???????? 8d44240c 50 }
- $sequence_4 = { e8???????? 83c424 8bd8 8d542414 8d8c2454030000 }
- $sequence_5 = { 8b44243c ff4c241c 3bf8 7605 e8???????? 8b44242c bb10000000 }
- $sequence_6 = { 83c428 c3 3c03 0f8558ffffff 83f901 }
- $sequence_7 = { 8d442414 50 c744242003000000 ff15???????? b902000000 }
- $sequence_8 = { 68???????? 68???????? e8???????? 83c410 e8???????? b230 }
- $sequence_9 = { 6a00 6a00 6a00 8bf2 6a00 6a00 8bf9 }
+ $sequence_0 = { c745e435000000 e8???????? 83c418 85c0 }
+ $sequence_1 = { 7432 8d55e4 8d45e8 52 8d4dec 50 8d95e4fdffff }
+ $sequence_2 = { 8dbe48010000 6800f00000 8bcf e8???????? 6800f00000 8bce }
+ $sequence_3 = { 7314 ff7510 ff750c ff7508 }
+ $sequence_4 = { c645fc03 e8???????? 8d4f08 c645fc04 e8???????? }
+ $sequence_5 = { c645fc07 e8???????? eb02 33ff 57 c645fc01 }
+ $sequence_6 = { 83ec10 33c9 8bdc 33d2 8dbe48010000 }
+ $sequence_7 = { 8d860f040000 8945cc eb12 8d86130d0000 }
+ $sequence_8 = { 837df020 750e 8dbdfcfdffff c60720 }
+ $sequence_9 = { 50 837df400 740d 6800800000 6a00 ff75f4 ff5625 }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Deltastealer_Auto : FILE
+rule MALPEDIA_Win_Equationdrug_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e4bcf99b-e757-5705-a59b-a0722820f3d9"
+ id = "37b1b451-51c5-5fbc-9487-21d701b707d2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.deltastealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.deltastealer_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.equationdrug"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.equationdrug_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "f3a202dde71406be69325c7d8bb3b580aed323825ecf5c600f5b385fd3e3e19c"
+ logic_hash = "f8f538888e4dbac5fbcd6d58b6a95043a330081a5194049d400ba3c70341afe9"
score = 75
quality = 75
tags = "FILE"
@@ -140545,32 +147392,32 @@ rule MALPEDIA_Win_Deltastealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4883c428 c3 56 57 53 4883ec30 4c89c6 }
- $sequence_1 = { 4d01c1 4c894c2420 4c89442428 c744243803001100 c744244803001100 488d5c2430 4c8d742440 }
- $sequence_2 = { 57 53 4883ec40 4889d3 488b01 488b7008 488b7810 }
- $sequence_3 = { 84c0 7416 4180bc240802000000 750b 488b842448010000 c60001 4584f6 }
- $sequence_4 = { e8???????? 498b7610 31db 4839df 741e 8a041e 8d48bf }
- $sequence_5 = { 89d7 48ffc3 49895e10 49f7e2 0f80a8000000 400fb6d7 4801d0 }
- $sequence_6 = { c6474001 4889f9 e8???????? 4885c0 7438 4885d2 7433 }
- $sequence_7 = { e8???????? 4489e3 488d4c2460 e8???????? 4989c7 eb21 4584e4 }
- $sequence_8 = { 48895c2420 488d7c2430 41b830000000 41b910000000 4889f9 e8???????? 488b7f18 }
- $sequence_9 = { 6601c8 0f92c2 81f9ffff0000 0f87d8feffff 84d2 0f85d0feffff 4d85f6 }
+ $sequence_0 = { 5b c21000 8bd0 56 81e2ff0f0000 53 83c704 }
+ $sequence_1 = { 0f84f4000000 8b7c2414 f7c7ff010000 0f85e4000000 8b4e04 8d442410 50 }
+ $sequence_2 = { 56 8d4c2418 c644245800 e8???????? 8d4c2414 e8???????? 84c0 }
+ $sequence_3 = { 84c0 741a 668b4ef8 660fbed0 668b46fa 52 50 }
+ $sequence_4 = { 89542414 8b542410 0fbfc2 40 0fafc1 3bfb 73c4 }
+ $sequence_5 = { c644245c00 e8???????? 83c404 89442464 85c0 c644245802 7411 }
+ $sequence_6 = { e8???????? 85c0 0f864b020000 53 8bcd e8???????? 50 }
+ $sequence_7 = { 33c0 eb07 8b4708 2bc6 d1f8 33d2 33db }
+ $sequence_8 = { 8bca b001 83e103 f3a4 5f 5e 5d }
+ $sequence_9 = { 6685c0 7537 8b442408 3dffff0000 772c c1e009 }
condition:
- 7 of them and filesize <3532800
+ 7 of them and filesize <449536
}
-rule MALPEDIA_Win_Data_Exfiltrator_Auto : FILE
+rule MALPEDIA_Win_Babyshark_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a4e15d5b-f5a8-5629-8aa0-4b08d538c94b"
+ id = "bba62dea-b8fb-5177-af59-ee7484609223"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.data_exfiltrator"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.data_exfiltrator_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.babyshark"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.babyshark_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "3310f9551fc82e6e58581f9d53ef710d168d316a9e233b611258320515dc0adb"
+ logic_hash = "170a55c792dd841a430b5276e4b7ea8cd0c0e2d28c406b503a22728951bd6c1d"
score = 75
quality = 75
tags = "FILE"
@@ -140584,34 +147431,34 @@ rule MALPEDIA_Win_Data_Exfiltrator_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488b4c2440 ff15???????? 4889442420 488b542448 }
- $sequence_1 = { e8???????? 4c8b442428 488d152c570000 488b4c2420 e8???????? 41b80a000000 }
- $sequence_2 = { 488d8c24a0000000 e8???????? 488d9424a0000000 488b8c2430010000 e8???????? 488905???????? }
- $sequence_3 = { c68424ba00000078 c68424bb00000078 c68424bc00000078 c68424bd00000078 c68424be00000000 488d8c24a0000000 }
- $sequence_4 = { 48894c2408 4883ec48 48837c246001 752b }
- $sequence_5 = { c6442420fb c6442421fc c6442422fe c6442423ff c6442424aa c64424254d }
- $sequence_6 = { c68424020100006d c684240301000000 c684240401000007 c68424050100006d c68424060100004f c684240701000072 }
- $sequence_7 = { 89442428 837c242800 7c3a 8b442448 39442428 7d30 8b442420 }
- $sequence_8 = { 7417 488b442450 488b4c2448 4803c8 488bc1 }
- $sequence_9 = { 48837c242800 7509 488d05d8250000 eb22 488d542420 488b4c2428 ff15???????? }
+ $sequence_0 = { 83c40c 8d4c2404 6a00 51 ffd6 6a00 }
+ $sequence_1 = { 8bc8 83e01f c1f905 8b0c8d607e4000 8a44c104 83e040 }
+ $sequence_2 = { 8b0c8d607e4000 8a44c104 83e040 c3 a1???????? }
+ $sequence_3 = { bf???????? f3ab 8d3452 895dfc c1e604 aa 8d9ec8674000 }
+ $sequence_4 = { 80e920 ebe0 80a0206c400000 40 3bc6 72be 5e }
+ $sequence_5 = { 8db6bc674000 bf???????? a5 a5 59 a3???????? }
+ $sequence_6 = { 8a8094504000 83e00f eb02 33c0 0fbe84c6b4504000 }
+ $sequence_7 = { c1f804 83f807 8945d0 0f879a060000 ff2485271a4000 834df0ff }
+ $sequence_8 = { 5e 8d0c8dc8614000 3bc1 7304 3910 7402 }
+ $sequence_9 = { ff15???????? 8bf0 68???????? 8d442408 68???????? 50 }
condition:
- 7 of them and filesize <107520
+ 7 of them and filesize <65272
}
-rule MALPEDIA_Win_Virdetdoor_Auto : FILE
+rule MALPEDIA_Win_Lorenz_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "888dbb4a-ac95-59fd-b6c6-805a13eab949"
+ id = "10a95bcc-414b-5fdc-ba6f-70234a4a7232"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.virdetdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.virdetdoor_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lorenz"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lorenz_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "f95b30ef178ddd53d43c681785d15b079df5f7a769adfe7338b74de03b97c177"
- score = 75
- quality = 75
+ logic_hash = "b3150a02c51834520c50a8abe1ab216fe79abbf33e7abc68b4a01a1cc4acdf52"
+ score = 60
+ quality = 45
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -140623,32 +147470,32 @@ rule MALPEDIA_Win_Virdetdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b93b0020000 2bc2 50 8b83ac020000 03c2 50 }
- $sequence_1 = { 83ee01 753e 85ff 7524 390b 7720 3903 }
- $sequence_2 = { 8d4dc0 e8???????? 85c0 0f84c8000000 }
- $sequence_3 = { 83fe08 0f43c8 83c602 0fb7444dc0 0bd0 0fb7449dd2 0bd0 }
- $sequence_4 = { 59 8d44240c 8bce 50 ff7314 57 e8???????? }
- $sequence_5 = { 0fbfd0 8d8df8fdffff ff7508 50 }
- $sequence_6 = { 55 8bec 51 51 53 8bc1 33db }
- $sequence_7 = { ff75f0 8d8b50020000 e8???????? 834dfcff }
- $sequence_8 = { 3c2e 7404 3c3a 750e 8a0437 88441dc0 43 }
- $sequence_9 = { 8945f8 8b4508 8bf0 8975f0 8d5808 895df4 }
+ $sequence_0 = { 8b4de8 e8???????? 898568ffffff eb15 8b55fc 8b4258 8b4df4 }
+ $sequence_1 = { c6412901 837df800 7423 8b55fc c7420c00000000 8b45f8 8b08 }
+ $sequence_2 = { 8b8800080000 e8???????? 8945f0 8b4dfc 8b8900080000 e8???????? 8945e0 }
+ $sequence_3 = { 8b55fc 8b4214 8b08 83e901 8b55fc 8b4214 8908 }
+ $sequence_4 = { ff55e4 8b55f0 89828c000000 8b45f0 8b888c000000 51 8b4dec }
+ $sequence_5 = { 8b4dfc e8???????? 85c0 7426 68???????? 68???????? 6a00 }
+ $sequence_6 = { 8b4dfc e8???????? 8bc8 e8???????? 0fb6c8 85c9 7460 }
+ $sequence_7 = { 8b4df8 83e904 e8???????? 8bc8 e8???????? 0fb6c8 85c9 }
+ $sequence_8 = { 50 e8???????? 8945d8 837dd800 0f8445010000 8b4dd8 d1e1 }
+ $sequence_9 = { 8b4dec 8b11 895004 8b45ec 8945e8 8b4de8 51 }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <2254848
}
-rule MALPEDIA_Win_Havoc_Auto : FILE
+rule MALPEDIA_Win_Cerbu_Miner_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "effddaaf-e7fe-58ad-88f4-e26f6d7794a2"
+ id = "77652d6a-745f-5552-8901-83bf555706f4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.havoc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.havoc_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cerbu_miner"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cerbu_miner_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "dea553016c43a89176918937bfc9793358dadd2541e82f3880161a16c9ccfd07"
+ logic_hash = "e4927a587588bc11053fcbade5bb9500364c9a656d383eb318cc8486464f3cce"
score = 75
quality = 75
tags = "FILE"
@@ -140662,32 +147509,32 @@ rule MALPEDIA_Win_Havoc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7856 488b842488000000 488bb42488000000 4531c9 }
- $sequence_1 = { 48898424ae000000 4c8d442458 ba2a040000 8b842498000000 4889442448 }
- $sequence_2 = { 4488440101 448a440202 4488440102 448a440203 4488440103 4883c004 4883f820 }
- $sequence_3 = { 4885c0 7504 31f6 eb08 488b4030 ffc3 }
- $sequence_4 = { 55 4c89c5 57 56 4889d6 53 }
- $sequence_5 = { 4883ec28 488b410c 488b4904 488d5008 488b05???????? }
- $sequence_6 = { 488d4b10 4c8d4c2460 4889442460 8b442478 ba00000002 4c8d842490000000 }
- $sequence_7 = { f3a5 488bbc2480000000 488b742460 b934010000 f3a5 }
- $sequence_8 = { baff010f00 c744244001000000 4889442444 31c0 85f6 }
- $sequence_9 = { 4155 4154 4531e4 55 57 56 53 }
+ $sequence_0 = { 88b42480000000 eb3f 83e902 7433 83e904 7413 83e909 }
+ $sequence_1 = { 7412 48 8d0d0b360500 48 83c428 48 ff25???????? }
+ $sequence_2 = { 8d4601 c643012e 48 63c8 41 8d4602 48 }
+ $sequence_3 = { 85d2 7427 85c9 b800040000 41 b800080000 44 }
+ $sequence_4 = { f6473801 7402 eb18 48 8bcf ff15???????? f6473801 }
+ $sequence_5 = { e9???????? 45 8bfd 44 89ad50010000 e9???????? 44 }
+ $sequence_6 = { 48 89442420 e8???????? 48 8bd7 48 8bcb }
+ $sequence_7 = { 89b42418010000 8b74242c 83feff 7515 837f0c00 7c0f 48 }
+ $sequence_8 = { 8d057b52f9ff 48 894518 c745b0e6070000 48 c745c000000200 48 }
+ $sequence_9 = { 44 2bc0 44 8903 33c0 48 8b5c2438 }
condition:
- 7 of them and filesize <164864
+ 7 of them and filesize <1040384
}
-rule MALPEDIA_Win_Mmon_Auto : FILE
+rule MALPEDIA_Win_Funny_Dream_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "684efad9-d1d6-5ce6-b6e0-de65ea38db79"
+ id = "342150e9-e685-51fd-bb6e-825e56ff33ab"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mmon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mmon_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.funny_dream"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.funny_dream_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "fc9a1ffbaa9f24fc3223df86b9f3747f68822a1333ac4081d18094cd5050cf44"
+ logic_hash = "93298c694e8a0e9daec0c22ddb9409f4c4088b474ade93c3bf4d76bcd798f980"
score = 75
quality = 75
tags = "FILE"
@@ -140701,32 +147548,32 @@ rule MALPEDIA_Win_Mmon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d04f5c8474200 8938 68a00f0000 ff30 }
- $sequence_1 = { 8d45cc 50 c745ccc8e64100 e8???????? 8b7508 }
- $sequence_2 = { 3c58 770f 0fbec2 0fb68020094200 }
- $sequence_3 = { 6aff 53 6a00 6a00 8bf1 }
- $sequence_4 = { 891d???????? ff15???????? 85c0 7577 8b15???????? }
- $sequence_5 = { 40 0080af4000a4 af 40 }
- $sequence_6 = { 8b44241c 83c404 50 ff15???????? 6880969800 e8???????? }
- $sequence_7 = { 03f9 8bda 83feff 7fa7 b867666666 f7ef c1fa02 }
- $sequence_8 = { eb0a c7854cffffff00000000 b802000000 018554ffffff 018548ffffff 03f8 }
- $sequence_9 = { 64a300000000 8b7d0c 8b07 68???????? 51 50 }
+ $sequence_0 = { c785e0ddffff01000000 50 6880000000 68ffff0000 ffb3c0000000 }
+ $sequence_1 = { 6a00 ff7728 ffd6 6a00 ff7724 ff15???????? 8b4714 }
+ $sequence_2 = { c745d45368656c 50 53 c745d86c457865 c745dc63757465 66c745e04100 }
+ $sequence_3 = { 85c0 0f8494000000 33c9 8a840d3cffffff }
+ $sequence_4 = { ff15???????? 85c0 0f85e7feffff 8d4704 899da0fdffff }
+ $sequence_5 = { 6a00 6800040000 8d842458030000 50 }
+ $sequence_6 = { 50 57 ff15???????? 85c0 7523 8b4618 8b3d???????? }
+ $sequence_7 = { 50 ff15???????? 8d442408 c744240810000000 50 8d442414 0f57c0 }
+ $sequence_8 = { 85c0 0f84f8000000 68???????? 50 ff15???????? }
+ $sequence_9 = { 83c404 8b4f04 85c9 7504 33c0 eb05 8b4708 }
condition:
- 7 of them and filesize <356352
+ 7 of them and filesize <393216
}
-rule MALPEDIA_Win_Oceansalt_Auto : FILE
+rule MALPEDIA_Win_Chairsmack_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4759a01e-4dff-5857-b87f-609205da91fe"
+ id = "89ef8364-1d04-5ec8-8eb0-0caa1f808e4e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.oceansalt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.oceansalt_auto.yar#L1-L173"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chairsmack"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chairsmack_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "5f4a1382e32af57ddc08356072f34b4511a1cb8b2d1541817fa2debd46a6df75"
+ logic_hash = "30e742a004c4313020160ca17f15835b780b5f554d2c7d95b7655ea180005855"
score = 75
quality = 75
tags = "FILE"
@@ -140740,40 +147587,34 @@ rule MALPEDIA_Win_Oceansalt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 6a00 6a02 83f81f }
- $sequence_1 = { 8d95fcfbffff 6800020000 52 e8???????? 83c410 8d85ecfbffff }
- $sequence_2 = { 8d85f4feffff 50 56 ffd7 6a00 }
- $sequence_3 = { 6a00 52 c685fcfbffff00 e8???????? }
- $sequence_4 = { 8b7508 33c0 50 8945f5 668945f9 8845fb 6a07 }
- $sequence_5 = { 8945fc 56 57 6a00 6a02 c785ccfdffff28010000 e8???????? }
- $sequence_6 = { 6a0d 58 5d c3 8b04cd2cf04000 }
- $sequence_7 = { 56 c645f400 ff15???????? 6a00 6a07 8d4df4 }
- $sequence_8 = { 4885c0 7419 488d1573750000 488bc8 ff15???????? }
- $sequence_9 = { b903000000 f3a6 0f8463010000 33c9 0fb6840c8c000000 }
- $sequence_10 = { 33d2 41b82a010000 6689442440 e8???????? ff15???????? 8be8 }
- $sequence_11 = { 33c0 e9???????? 48895c2408 4c63c1 488d1d1d890000 4d8bc8 }
- $sequence_12 = { 0f85d0000000 488d0d6b380000 ff15???????? 488bf0 4885c0 0f848c010000 }
- $sequence_13 = { 488bc8 c744242800000008 c744242003000000 ff15???????? 488bd8 4883f8ff }
- $sequence_14 = { f3a6 749a 488d8c24b0030000 33d2 41b868010000 e8???????? }
- $sequence_15 = { 488d3d94700000 eb0e 488b03 4885c0 7402 ffd0 4883c308 }
+ $sequence_0 = { 8d8c2410010000 c68424840300003a e8???????? 83ec1c 8d842428010000 8bcc 8964242c }
+ $sequence_1 = { 8d4de8 56 c745fc01000000 e8???????? 8b7df0 8d4de8 2b7e08 }
+ $sequence_2 = { 8d4c2464 e8???????? e9???????? 68???????? 8d8c24bc000000 e8???????? 8bd0 }
+ $sequence_3 = { 8b4004 eb03 83c004 51 50 ffb4249c000000 51 }
+ $sequence_4 = { 660f57c4 8b7c2414 8d442421 c644242025 8b5714 f6c220 7409 }
+ $sequence_5 = { 7613 b8feffff7f 8d3419 2bc1 3bd8 7605 befeffff7f }
+ $sequence_6 = { 8d8db8fcffff e9???????? 8d8dd0fdffff e9???????? 8d8dbcfcffff e9???????? 8d8dc0fdffff }
+ $sequence_7 = { c68424b8030000b9 8bcc 68???????? e8???????? c68424b8030000b6 e8???????? 83c430 }
+ $sequence_8 = { 8b148dd06d4a00 81c200080000 3955e4 7366 8b45e4 c6400400 8b4de4 }
+ $sequence_9 = { 0fbe02 85c0 0f848e010000 8b4dfc 51 }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <1974272
}
-rule MALPEDIA_Win_Dorkbot_Ngrbot_Auto : FILE
+rule MALPEDIA_Elf_Blackcat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1046d98a-4609-5bec-b876-b018dbb80d3c"
+ id = "8a7e13ba-9ed1-59ed-8fb9-9aaa610fbd94"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dorkbot_ngrbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dorkbot_ngrbot_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.blackcat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.blackcat_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "bcb266c989d4cc3b19fa74f0744a29c545b0b246dcbae9914be22d057afdb410"
- score = 75
- quality = 75
+ logic_hash = "1ac97428ed273512eef4209d87a29f49ce26e88d11cb15b15e2f2687ea017381"
+ score = 60
+ quality = 45
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -140785,32 +147626,32 @@ rule MALPEDIA_Win_Dorkbot_Ngrbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a5c 56 e8???????? 8b5d0c 6a5c 53 8bf8 }
- $sequence_1 = { ffd6 33c0 a3???????? a3???????? a3???????? 8b45fc }
- $sequence_2 = { c1e704 8b8f84693a02 48 3bc8 0f8289000000 68???????? 8d45ec }
- $sequence_3 = { 3bc6 751a 8b00 898120100000 8b0a 8bb920100000 56 }
- $sequence_4 = { 8b4508 50 8d8da4fdffff 51 68???????? 8d958cf7ffff 6817060000 }
- $sequence_5 = { 8b15???????? 8b1d???????? 6a08 52 ffd3 6804010000 8906 }
- $sequence_6 = { 0145fc ffd3 8bc8 b8d34d6210 f7e1 c1ea06 }
- $sequence_7 = { 6689462d 83c007 66898638100000 5f 895628 c6462c03 b801000000 }
- $sequence_8 = { 53 8d55d4 52 ffd6 85c0 7fdb 5f }
- $sequence_9 = { 0fb6c9 6880000000 83c202 52 8b5508 f7d9 1bc9 }
+ $sequence_0 = { e8???????? 0f0b 90 90 90 90 53 }
+ $sequence_1 = { 69c0???????? c1e811 6bf064 29f2 0fb7d2 }
+ $sequence_2 = { e8???????? 0f0b 90 53 }
+ $sequence_3 = { 89c1 3d???????? 7319 c1e906 }
+ $sequence_4 = { 660f7f8424f0010000 660f7f8424e0010000 660f7f8424d0010000 660f7f8424c0010000 660f7f8424b0010000 }
+ $sequence_5 = { d1e9 01d1 c1e902 8d14cd00000000 }
+ $sequence_6 = { b801000000 81f9???????? 0f823fffffff b802000000 }
+ $sequence_7 = { 69c0???????? c1e810 29c2 0fb7d2 d1ea }
+ $sequence_8 = { 762a 0fb6c8 8d1489 8d0cd1 }
+ $sequence_9 = { e8???????? 0f0b e8???????? 0f0b 90 90 90 }
condition:
- 7 of them and filesize <638976
+ 7 of them and filesize <8011776
}
-rule MALPEDIA_Win_Sodamaster_Auto : FILE
+rule MALPEDIA_Win_Poortry_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5c8830e9-776d-5d52-b260-bf93f938f131"
+ id = "2cf345f6-6c65-548f-9e1e-6a67040df1b7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sodamaster"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sodamaster_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poortry"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poortry_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "a33360882a3ef608d87207bac124912433c6a8960ab3afceadfd4533af00bd98"
+ logic_hash = "3ea6c4ba39d0058f0069c86346c9de0810387b212bcc1f7c57e5a516c20ae9ad"
score = 75
quality = 75
tags = "FILE"
@@ -140824,71 +147665,108 @@ rule MALPEDIA_Win_Sodamaster_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? c70009000000 e8???????? ebd2 8bc3 c1f805 8d3c85a0330110 }
- $sequence_1 = { 8908 894804 8bf0 eb02 33f6 6a40 6800100000 }
- $sequence_2 = { 8d4900 8d97feefff7f 85d2 7419 8a140e 84d2 7412 }
- $sequence_3 = { 8945e4 3d01010000 7d0d 8a4c181c 888810080110 40 }
- $sequence_4 = { 33f6 6a40 6800100000 8d4301 50 6a00 ff15???????? }
- $sequence_5 = { 83c424 83ffff 5f 5e 5b }
- $sequence_6 = { 83c8ff e9???????? 8bc6 c1f805 8bfe 53 8d1c85a0330110 }
- $sequence_7 = { 33f6 8d45f8 50 8b4508 c745e8636d643d c645ec00 }
- $sequence_8 = { e8???????? 56 e8???????? 83c418 ff15???????? }
- $sequence_9 = { 6a02 53 68ff010f00 52 }
+ $sequence_0 = { 41f7d2 f9 4181f80255e860 4181f225619d1f 41f7da f8 4181c2174c0279 }
+ $sequence_1 = { 66f7c4e120 310424 5e 41f6c105 443af4 4863c0 f5 }
+ $sequence_2 = { 66443bf0 56 0fbae697 c1e61f 311424 f9 660fbafec8 }
+ $sequence_3 = { 41f7d3 4151 450aca 6641d3e1 44311c24 4180d1a2 }
+ $sequence_4 = { f8 81f79e0d521c f8 d1cf 81c71d19891d f8 f5 }
+ $sequence_5 = { 4151 41c0e937 4d0fb7c9 313424 450fc0c9 66450fabf1 66410fbae1d7 }
+ $sequence_6 = { 4484c7 81c33f50eb3f 664181f8ec0e f7db 4153 311c24 6641c1c318 }
+ $sequence_7 = { 56 401af3 40d2e6 66f7c4e120 310424 5e 41f6c105 }
+ $sequence_8 = { 4123ea 48c1d5cd 5d f9 4d63c9 4881f98925786f 664185d3 }
+ $sequence_9 = { f6dd 4159 4084ee 40b5c4 9d 66400fbecd 59 }
condition:
- 7 of them and filesize <134144
+ 7 of them and filesize <8078336
}
-rule MALPEDIA_Win_Unidentified_082_Auto : FILE
+rule MALPEDIA_Win_Ryuk_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7772581c-e8cf-5615-a758-46ef9c1fc0b0"
- date = "2021-10-07"
- modified = "2021-10-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_082"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_082_auto.yar#L1-L124"
+ id = "9762637f-3260-5c34-b846-45fb6634f5b4"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ryuk_auto.yar#L1-L425"
license_url = "N/A"
- logic_hash = "fdfe1ddce9f77ac8b465b0ddebe868c5e77078cf2b2457573a5b3810682f45ee"
+ logic_hash = "b1841a1134c1a11658d85f36006ba9e8e5ed64f6492350418145712079afb53f"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20211007"
- malpedia_hash = "e5b790e0f888f252d49063a1251ca60ec2832535"
- malpedia_version = "20211008"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4c8d0dbc190200 0f1f4000 0f1f840000000000 418d4801 }
- $sequence_1 = { ff5018 4c634510 488d0df40a0200 488bd8 33c0 }
- $sequence_2 = { 4c634510 488d0d93fa0100 488bd8 33c0 488bd3 488905???????? 488905???????? }
- $sequence_3 = { ff15???????? 488b0cdf ff15???????? 48c704dfffffffff }
- $sequence_4 = { 4885c0 0f84ac010000 48833d????????00 0f849e010000 48833d????????00 0f8490010000 48833d????????00 }
- $sequence_5 = { 488b0d???????? 8b5108 488b4910 4533c9 458d4130 4c89742420 }
- $sequence_6 = { 33c0 e9???????? 8a07 4c8b7c2448 4c8d25a64c0100 4b8b0cfc ffc3 }
- $sequence_7 = { 0f1f4000 0f1f840000000000 418d4801 0fb6c2 41ffc0 f7da }
- $sequence_8 = { 488b4f18 4c8d4d10 488b01 488d1587000200 41b810000000 ff5018 4c634510 }
- $sequence_9 = { 48894598 eb03 4533f6 488b05???????? 80782e00 740a 80782000 }
+ $sequence_0 = { 68???????? 6a01 6a00 6814010000 }
+ $sequence_1 = { ff15???????? 85c0 7508 6a01 ff15???????? 68???????? 6a01 }
+ $sequence_2 = { 6a08 6a18 68???????? 68???????? 68???????? ff15???????? }
+ $sequence_3 = { 754c b90b010000 66398818000035 753e 8b4508 b9???????? 2bc1 }
+ $sequence_4 = { 68???????? ff15???????? 85c0 7578 6a10 6a18 }
+ $sequence_5 = { 755d a1???????? 81b8????????50450000 754c b90b010000 66398818000035 }
+ $sequence_6 = { 68???????? ff15???????? 85c0 7542 6a28 6a18 }
+ $sequence_7 = { 68c0cf6a00 ff15???????? 6a01 ff15???????? }
+ $sequence_8 = { 7407 b801000000 eb0b eb04 }
+ $sequence_9 = { e8???????? 68e8030000 ff15???????? 68???????? e8???????? }
+ $sequence_10 = { 720f b901000000 6bd103 8b45fc c6041000 }
+ $sequence_11 = { 83c101 ba01000000 d1e2 8b45fc }
+ $sequence_12 = { 8908 895004 837df800 7709 }
+ $sequence_13 = { 89459c 8955a0 8b55a0 3b55f8 0f870b020000 }
+ $sequence_14 = { ba01000000 6bc203 8b55fc 880c02 b804000000 }
+ $sequence_15 = { ff15???????? b811000000 e9???????? e9???????? }
+ $sequence_16 = { ff15???????? 833d????????00 6a10 6a18 }
+ $sequence_17 = { 6a00 6814010000 ff7508 ff35???????? }
+ $sequence_18 = { 7407 48 85c0 7ff0 }
+ $sequence_19 = { ff15???????? b803000000 eb05 b805000000 }
+ $sequence_20 = { 2bf0 33c0 66890473 83ffff }
+ $sequence_21 = { 751b ff35???????? ff35???????? 6a01 68???????? e8???????? }
+ $sequence_22 = { eb0b 8bc1 99 f7fe }
+ $sequence_23 = { 56 ff15???????? 8bcb 8d5102 }
+ $sequence_24 = { 7714 7212 81f9d0070000 770a 85d2 }
+ $sequence_25 = { e8???????? e8???????? b9e8030000 ff15???????? }
+ $sequence_26 = { 668b02 83c202 6685c0 75f5 8d7bfe 2bd6 }
+ $sequence_27 = { 0f9fc0 5d c3 8bff 55 8bec 8b4508 }
+ $sequence_28 = { 5d c3 8bcb 8d5102 }
+ $sequence_29 = { d1fa 2bca 33c0 6689444bfe e9???????? 33c0 }
+ $sequence_30 = { 488bc3 4883c430 5b c3 48895c2408 48896c2410 4889742418 }
+ $sequence_31 = { 68???????? 53 d1fe e8???????? 83c408 8d5002 }
+ $sequence_32 = { 498bc1 c3 4053 4883ec20 8bc1 498bd8 }
+ $sequence_33 = { 50 51 e8???????? 6a00 6840420f00 52 50 }
+ $sequence_34 = { 83c602 6685c9 75f5 2bf2 68???????? 53 }
+ $sequence_35 = { f3a4 8d7afe 668b4702 8d7f02 6685c0 75f4 a1???????? }
+ $sequence_36 = { 4883c428 c3 48895c2408 57 4883ec30 8364242000 }
+ $sequence_37 = { 33c9 ba10270000 41b800100000 448d4904 ff15???????? }
+ $sequence_38 = { f7e1 8bc1 2bc2 d1e8 03c2 c1e806 6bc05a }
+ $sequence_39 = { ff15???????? 41b900300000 c744242040000000 448bc3 488bd6 488bcf }
+ $sequence_40 = { c744242802000000 4533c9 4533c0 c744242002000000 ba000000c0 }
+ $sequence_41 = { ff15???????? 488bd8 ff15???????? 83f820 7510 488bcb ff15???????? }
+ $sequence_42 = { 4533c9 4533c0 c744242003000000 ba00000040 ff15???????? 488bd8 ff15???????? }
+ $sequence_43 = { 66837f0254 750f 66837f0641 7508 }
+ $sequence_44 = { 4889442420 4c8bc6 488bd3 488bcf ff15???????? }
+ $sequence_45 = { ff15???????? 66833f4e 7516 66837f0254 750f }
+ $sequence_46 = { 84c0 746c e8???????? 488d0d63080000 e8???????? e8???????? }
condition:
- 7 of them and filesize <414720
+ 7 of them and filesize <7450624
}
-rule MALPEDIA_Win_Netsupportmanager_Rat_Auto : FILE
+rule MALPEDIA_Win_Arkei_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cef2dd3b-0f7d-59a7-a048-7ced175e981a"
+ id = "d30a73fa-e439-581b-821f-0f94e7403477"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.netsupportmanager_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.netsupportmanager_rat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.arkei_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.arkei_stealer_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "79986ba5845ddb197c2cbb664d974c015a806cc2574092a014c092c0439de61a"
+ logic_hash = "9f5b37522725bf35fb4c723079a0799c573d27f50c2c2a0cc7a8a66eafb6f502"
score = 75
quality = 75
tags = "FILE"
@@ -140902,34 +147780,34 @@ rule MALPEDIA_Win_Netsupportmanager_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8b7df0 3bfb c745fcffffffff 7410 8bcf e8???????? }
- $sequence_1 = { f3a4 8d4dfc 51 e8???????? 83c404 663dffff 668945dc }
- $sequence_2 = { e8???????? 8bcb e8???????? 8b4510 8b08 894b34 8b5004 }
- $sequence_3 = { ff15???????? 85ff 7417 8b1b 81e7ffff0000 6a00 57 }
- $sequence_4 = { c644020400 e8???????? 8b8558ffffff 83c404 85c0 7514 8b9550ffffff }
- $sequence_5 = { e8???????? 8b9750030000 52 e8???????? 8b450c 8b7510 83c408 }
- $sequence_6 = { ff15???????? 85c0 750e 8b45e8 8b4de4 50 51 }
- $sequence_7 = { e8???????? eb02 33c0 c645fc01 8bf0 3bf3 7547 }
- $sequence_8 = { e9???????? 686c010000 e8???????? 8bf0 83c404 897508 85f6 }
- $sequence_9 = { 8d4df0 c745fc00000000 e8???????? 8b4704 85c0 7609 83f8ff }
+ $sequence_0 = { 8d55c4 52 6a18 50 ff15???????? 85c0 }
+ $sequence_1 = { 8be5 5d c3 50 8b45e8 }
+ $sequence_2 = { 894614 897e24 ff15???????? 8bd8 3bdf 0f84e3feffff }
+ $sequence_3 = { 8bf0 ffd3 8bd8 53 56 }
+ $sequence_4 = { 56 53 52 57 50 51 ff15???????? }
+ $sequence_5 = { 8b00 50 ff15???????? 83f8ff 740b a810 7507 }
+ $sequence_6 = { 85c0 0f8458feffff 8b4e20 6a00 8d45e4 50 8d148d28000000 }
+ $sequence_7 = { 8bf0 c70628000000 8b4dc8 894e04 8b55cc 895608 668b45d4 }
+ $sequence_8 = { 8b7614 6a00 8d45e4 50 56 }
+ $sequence_9 = { 56 894590 ff15???????? 8bf8 897d94 83ffff }
condition:
- 7 of them and filesize <4734976
+ 7 of them and filesize <1744896
}
-rule MALPEDIA_Win_Unidentified_081_Auto : FILE
+rule MALPEDIA_Win_Tinynuke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4bef4e35-3450-5f50-98ad-424279417112"
+ id = "d780fd7f-583b-590f-a92f-7ac4fac52f1d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_081"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_081_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinynuke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tinynuke_auto.yar#L1-L294"
license_url = "N/A"
- logic_hash = "0bf113d92abe743278ae5a94b3d8f7a48f5ba7f91d2e79f1d3ac361b6c786f4e"
+ logic_hash = "f182ca1cbc1a4db59bec12699d68404bb9da6364ccc0407277f19ab284be21eb"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -140941,32 +147819,54 @@ rule MALPEDIA_Win_Unidentified_081_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8985c8fdffff 83f808 0f84ab090000 83f807 0f8777090000 ff24854fa44000 33c0 }
- $sequence_1 = { c74518f0944100 50 8d4dc4 e8???????? 68???????? 8d45c4 }
- $sequence_2 = { 68???????? b9???????? e8???????? c645fc03 33c0 }
- $sequence_3 = { eb02 33c0 8bbdc8fdffff 6bc009 0fb6bc38e8544100 8bc7 89bdc8fdffff }
- $sequence_4 = { 8b7508 c7465c48554100 83660800 33ff }
- $sequence_5 = { c645fc01 33c9 66a3???????? 66390d???????? 8bc6 c705????????07000000 0f44c1 }
- $sequence_6 = { 88440a34 8b049dd0d14100 c744023801000000 e9???????? ff15???????? 8bf8 }
- $sequence_7 = { 83e61f c1f805 c1e606 8b0485d0d14100 80643004fd 8b45f8 }
- $sequence_8 = { 6a01 6a00 f7d8 50 53 ff15???????? 8b8d34ffffff }
- $sequence_9 = { ff15???????? 837c241001 7507 b101 e8???????? 8b35???????? }
+ $sequence_0 = { c3 55 8bec 817d0c00040000 }
+ $sequence_1 = { 6aff ff7508 6a00 68e9fd0000 ff15???????? 8bc3 5b }
+ $sequence_2 = { 7625 53 8b5d08 57 8b7d10 57 }
+ $sequence_3 = { ff35???????? a3???????? 57 ff15???????? ff35???????? 8b7dfc }
+ $sequence_4 = { 50 56 57 ff35???????? c745f801000000 }
+ $sequence_5 = { 8d8530f6ffff 50 6802020000 ff15???????? 85c0 }
+ $sequence_6 = { 8945f4 8d85d4feffff 50 ff15???????? }
+ $sequence_7 = { 6a03 53 53 6800000080 50 ff15???????? a3???????? }
+ $sequence_8 = { ff75ec ff75fc e8???????? 83c40c 5f }
+ $sequence_9 = { ff15???????? ff35???????? 8d85a4feffff 50 }
+ $sequence_10 = { 8d85a4feffff 50 ff15???????? ff35???????? }
+ $sequence_11 = { ff15???????? a3???????? ff35???????? ff75f8 }
+ $sequence_12 = { a3???????? 68e2010000 68???????? 68???????? e8???????? }
+ $sequence_13 = { e8???????? eb18 83f803 7519 }
+ $sequence_14 = { 59 a3???????? c9 c3 55 }
+ $sequence_15 = { 6a2a 50 8945fc ff15???????? }
+ $sequence_16 = { a3???????? ff35???????? ff75ec ff15???????? }
+ $sequence_17 = { 8a00 3c0a 7409 3c0d }
+ $sequence_18 = { 50 8d85f0fdffff 50 ff15???????? ff75fc 8d85f0fdffff }
+ $sequence_19 = { ff15???????? 8d85d0fcffff 50 e8???????? 59 }
+ $sequence_20 = { ff15???????? 8b35???????? 8d430c 50 }
+ $sequence_21 = { 8b0f 85c9 742a 8d440b02 85c9 }
+ $sequence_22 = { 8b44241c 8bb0a0000000 2b6834 01de 8b16 85d2 }
+ $sequence_23 = { 8bb90000e06e 0f848e000000 83fa20 0f84f0000000 83fa08 0f84b4000000 }
+ $sequence_24 = { 890424 89442418 e8???????? 89c3 }
+ $sequence_25 = { ffd6 57 53 ffd6 5f 5e 8bc3 }
+ $sequence_26 = { 8b06 85c0 75b7 8b7c241c 8b8780000000 }
+ $sequence_27 = { c744240840000000 891c24 89dd 8944240c 8b442418 89442404 e8???????? }
+ $sequence_28 = { 745c 01d8 890424 e8???????? 83ec04 89c6 }
+ $sequence_29 = { a1???????? 83c014 03c7 894df8 8945f4 7417 }
+ $sequence_30 = { 03c7 83f864 0f873f010000 8b45c0 8b7dbc }
+ $sequence_31 = { c744241000000000 c744240c50c30000 c744240850c30000 c744240400000000 e8???????? }
condition:
- 7 of them and filesize <273408
+ 7 of them and filesize <1196032
}
-rule MALPEDIA_Win_Lockbit_Auto : FILE
+rule MALPEDIA_Win_Xfscashncr_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "945a5bdc-50cc-5372-b470-aafc3e12d474"
+ id = "6ee5ebd5-3415-5529-b820-2ef4f50b7f37"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lockbit"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lockbit_auto.yar#L1-L203"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xfscashncr"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xfscashncr_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "ef292234a38c5f85ea42d6220d555a65163be7c7bef94693195ea2cefdb10cc0"
+ logic_hash = "9081cad85dadcbc9b76a9d19d302868541784728cc3671f5b0e80a45a72963e6"
score = 75
quality = 75
tags = "FILE"
@@ -140980,42 +147880,32 @@ rule MALPEDIA_Win_Lockbit_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f28c8 660f73f904 660fefc8 0f28c1 660f73f804 }
- $sequence_1 = { 50 e8???????? 8d858cfeffff 50 8d45c0 50 8d45a0 }
- $sequence_2 = { fec1 47 4e 85f6 75d2 5d }
- $sequence_3 = { 56 57 8d9d84fcffff b900c2eb0b e2fe e8???????? 53 }
- $sequence_4 = { 6683f866 7706 6683e857 eb17 6683f830 720c 6683f839 }
- $sequence_5 = { 33db 55 8b6d10 8bc1 }
- $sequence_6 = { 8d8550fdffff 50 6a00 ff15???????? }
- $sequence_7 = { 33c0 8d7df0 33c9 53 0fa2 }
- $sequence_8 = { f745f800000002 740c 5f 5e }
- $sequence_9 = { 02d3 8a5c1500 8a541d00 8a541500 fec2 8a441500 }
- $sequence_10 = { 33d0 8bc1 c1e810 0fb6c0 c1e208 }
- $sequence_11 = { 53 56 57 33c0 8b5d14 33c9 33d2 }
- $sequence_12 = { 8d45f8 50 8d45fc 50 ff75fc ff75f4 }
- $sequence_13 = { e9???????? 6683f841 720c 6683f846 7706 6683e837 }
- $sequence_14 = { 6a00 6a00 6800000040 ff75d4 }
- $sequence_15 = { 5b 8907 897704 894f08 89570c f745f800000002 740c }
- $sequence_16 = { 214493fc 8b5df8 8bc3 43 }
- $sequence_17 = { 7407 8bce e8???????? 837b0402 }
- $sequence_18 = { 7414 663901 740f 0f1f440000 }
- $sequence_19 = { 1bdb 83e30b 83c328 ff7518 8b7d08 8d049500000000 ff7514 }
+ $sequence_0 = { 0fb6c8 85c9 744e 8b4d10 e8???????? 0fb730 8b8d54ffffff }
+ $sequence_1 = { 50 8b4de8 8b5110 52 6a00 682d010000 8b45e8 }
+ $sequence_2 = { 898518feffff 8b8d18feffff 898d14feffff c745fc00000000 8b9514feffff 52 e8???????? }
+ $sequence_3 = { 686b070000 68???????? 8b4508 50 e8???????? 83c40c 8b4508 }
+ $sequence_4 = { 8b4de4 66891401 0fb755f4 81fa00800000 7f27 0fb745f4 3d00800000 }
+ $sequence_5 = { 83c418 8b08 8b5004 894d10 895514 c78564ffffff00000000 eb35 }
+ $sequence_6 = { e8???????? 0fb6d0 85d2 7557 837de802 750f 8b4520 }
+ $sequence_7 = { 837d0800 744a b801000000 85c0 7441 8b4508 83c008 }
+ $sequence_8 = { 8b4d08 d9ee d95c81fc 8b55f0 8b4508 d90490 d9ee }
+ $sequence_9 = { 8b5508 83e21f c1e206 8b048dc0195700 0fbe4c1004 81e17fffffff 8b5508 }
condition:
- 7 of them and filesize <2049024
+ 7 of them and filesize <3126272
}
-rule MALPEDIA_Win_Invisimole_Auto : FILE
+rule MALPEDIA_Win_Proto8_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ca18c738-4139-5525-aa28-1ccc54f29c64"
+ id = "67c17406-b8bd-51d3-bd06-6c282d2d9ba4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.invisimole"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.invisimole_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.proto8_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.proto8_rat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "c66d253d3c18c58309d81357b0c6a50ba445964c209a2fd7bab05aae7420f29c"
+ logic_hash = "b74b2b80c633a7bf227b4dcb10a54e0eaa49fb3d590fb7e951e6a918637cc88c"
score = 75
quality = 75
tags = "FILE"
@@ -141029,32 +147919,32 @@ rule MALPEDIA_Win_Invisimole_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 668945f0 8d863e020000 50 ffd7 33c9 668945f2 8d45f8 }
- $sequence_1 = { 8d5590 52 50 e8???????? 83c40c 83f8ff 0f848df1ffff }
- $sequence_2 = { 0fb65714 83c448 6a01 8d45ff 50 56 8855ff }
- $sequence_3 = { 6a01 8d45ff 50 56 c645ff33 }
- $sequence_4 = { 8bec 83ec4c 53 56 8bf0 57 8d45b4 }
- $sequence_5 = { 47 83ff09 72d5 8b0d???????? 56 6a00 51 }
- $sequence_6 = { 57 6860040000 33db 53 56 e8???????? a1???????? }
- $sequence_7 = { 8b45fc 50 a1???????? 6a00 50 ffd7 8b4308 }
- $sequence_8 = { 8b45f4 8a5dfb 50 ff15???????? 8ac3 5f }
- $sequence_9 = { 53 e8???????? 8b75df 81fee6010000 0f8335050000 8a8746020000 0a4710 }
+ $sequence_0 = { 7819 8d4a01 0f1f00 488b5b08 4883e901 75f6 eb07 }
+ $sequence_1 = { f04e0fb13409 483bd0 752b 4885d2 7426 440fb68c24c8000000 498bcc }
+ $sequence_2 = { 488b4008 48894708 488b4630 488907 488b4630 488b4808 488939 }
+ $sequence_3 = { 764f 6666660f1f840000000000 458bc1 8bd5 49c1e006 4c034360 4183780800 }
+ $sequence_4 = { 0f10442428 488b842488000000 0f1100 f20f104c2438 f20f114810 b001 eb02 }
+ $sequence_5 = { e8???????? 84c0 751d 488b03 488bcb ff5018 488bf0 }
+ $sequence_6 = { 4053 4883ec20 488d05634f0400 488bd9 488901 f6c201 740a }
+ $sequence_7 = { f20f114808 0f28cf 488b41e0 f20f594020 f20f114008 488b41e8 f20f594820 }
+ $sequence_8 = { ff15???????? 85c0 757f ff15???????? 3d002f0000 74be 488b4c2440 }
+ $sequence_9 = { 8b842490000000 03ce 894c2428 3bc8 0f829afdffff 4c8b7c2440 4c8b642448 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <2537472
}
-rule MALPEDIA_Win_Icondown_Auto : FILE
+rule MALPEDIA_Win_Treasurehunter_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5fb05a25-c3d8-5c59-95d8-0506e8a3c86e"
+ id = "d910c7d8-579e-5e04-9944-d334673c4daa"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.icondown"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.icondown_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.treasurehunter"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.treasurehunter_auto.yar#L1-L103"
license_url = "N/A"
- logic_hash = "0c8c45a1ce9a6284204f7a9a1969d67da5f4271a6aa51c70c6faebd789509deb"
+ logic_hash = "15ce0cdcd8ce74cbd944226eb16c8cf48295e060eba7d0ca2d750492d2eadd11"
score = 75
quality = 75
tags = "FILE"
@@ -141068,32 +147958,30 @@ rule MALPEDIA_Win_Icondown_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89442420 8b471c d1ee 52 50 83e601 }
- $sequence_1 = { 5f 5e 5d b801000000 5b c20400 8b461c }
- $sequence_2 = { 3bc5 7c10 5f 5e 5d b8feffffff 5b }
- $sequence_3 = { 8b461c 85c0 0f8476010000 8b868c000000 }
- $sequence_4 = { 0fb6da f683c11c450004 7406 8816 46 40 ff01 }
- $sequence_5 = { b81f85eb51 f7e9 c1fa05 8bca b81f85eb51 c1e91f }
- $sequence_6 = { 56 8bf1 33db 57 8975f0 895dec c745e8a4ff4300 }
- $sequence_7 = { e8???????? c7462844d04300 833d????????00 7416 }
- $sequence_8 = { c3 33c0 5e c3 8b442404 c74050f0b94400 }
- $sequence_9 = { c745f020d04300 c745e810000000 e8???????? 85c0 7403 }
+ $sequence_0 = { 75f9 2bf0 e8???????? 8bd0 }
+ $sequence_1 = { 53 56 8b35???????? 8bd9 8b4d08 57 }
+ $sequence_2 = { 8bf8 e8???????? 68???????? 57 e8???????? }
+ $sequence_3 = { 8bd9 8b4d08 57 8955fc e8???????? 8bce 8bf8 }
+ $sequence_4 = { 57 8bf9 8bca e8???????? 8b7508 }
+ $sequence_5 = { 56 50 8903 ff15???????? 8b4dfc }
+ $sequence_6 = { 7e0b 4a e8???????? 0fafc6 5e c3 }
+ $sequence_7 = { e8???????? b9???????? a3???????? e8???????? 5f 5e a3???????? }
condition:
- 7 of them and filesize <5505024
+ 7 of them and filesize <229376
}
-rule MALPEDIA_Win_Friedex_Auto : FILE
+rule MALPEDIA_Win_Unidentified_111_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "97d1751f-5738-5834-8f82-479344539d3a"
+ id = "761c3c1a-627b-5adf-b1c2-f96f11c05a94"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.friedex"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.friedex_auto.yar#L1-L172"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_111"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_111_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "8dffa1fb6804412157c235a0ef3196dc0c5961e846d30c21c59180ff32555e60"
+ logic_hash = "8a86a6eb9509e0a5b4e912cde53abfcabb23f3644fc565d69ca8396c5dc5d7c9"
score = 75
quality = 75
tags = "FILE"
@@ -141107,38 +147995,32 @@ rule MALPEDIA_Win_Friedex_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 57 8bc8 e8???????? 6a26 }
- $sequence_1 = { c20c00 51 51 53 55 8be9 c744240820090d0a }
- $sequence_2 = { 1adb e8???????? 6a20 5f }
- $sequence_3 = { 74f9 33c9 663908 0f94c0 5f 5e 5d }
- $sequence_4 = { 663910 7431 8bd8 8d7102 eb1d }
- $sequence_5 = { 5f 5b 5e 5d c20c00 51 }
- $sequence_6 = { 75c1 6a2a 5f eb06 b001 eb0f 03c5 }
- $sequence_7 = { 6a00 ff760c ffd0 8b442408 5e }
- $sequence_8 = { 8955e0 e8???????? 8d0dd830a500 890424 894c2404 e8???????? }
- $sequence_9 = { 8d055a23a500 31c9 8d55d8 803d????????e9 8955d4 8945d0 }
- $sequence_10 = { 8a2c057530a500 83c001 38e9 8945a0 8955cc 74bc }
- $sequence_11 = { 8d055a23a500 5d c3 55 }
- $sequence_12 = { c7424458270000 c7424800100100 8b7de4 c787cc00000000000000 c787c800000000000000 }
- $sequence_13 = { 8b45a4 8a4daf 31d2 8a2c057530a500 83c001 38e9 }
- $sequence_14 = { 8d0dc930a500 890424 894c2404 e8???????? 8d0d4430a500 31d2 8b75f8 }
- $sequence_15 = { 8d0d4430a500 31d2 890c24 c744240400000000 }
+ $sequence_0 = { 488b4c2428 0fbe09 3bc1 7512 }
+ $sequence_1 = { c744242002000000 e9???????? 837c243406 7511 837c243801 750a }
+ $sequence_2 = { 8b00 488b4c2430 488b09 0fbe0401 48634c2404 488b542428 0fbe0c0a }
+ $sequence_3 = { eb43 41b901000000 448b442424 488b542428 488b4c2448 e8???????? }
+ $sequence_4 = { eb1f c744242000000000 4533c9 4533c0 }
+ $sequence_5 = { 488b4c2448 ff15???????? 89442444 837c244400 7502 eb11 }
+ $sequence_6 = { 488d8c0c60020000 ba02000000 486bd200 4803ca 448bc0 488b542420 e8???????? }
+ $sequence_7 = { 66c1ca08 0fb7d2 4c8b8424a0000000 450fb74006 6641c1c808 450fb7c0 4c8b8c24a0000000 }
+ $sequence_8 = { e8???????? b910000000 e8???????? 4889442448 488b442448 488b4c2450 488908 }
+ $sequence_9 = { 4889542410 48894c2408 4883ec78 c744243000000000 c744243400000000 488b942488000000 488d4c2448 }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <148480
}
-rule MALPEDIA_Win_Lambert_Auto : FILE
+rule MALPEDIA_Win_Wastedloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1c692e32-84a7-5d90-ba02-61a84edfcff0"
+ id = "f15153cb-6336-5eec-a420-db8a6857e34a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lambert"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lambert_auto.yar#L1-L166"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wastedloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wastedloader_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "9e5ed22ba49a751e07cf4ea652d26902b7b8b831105840a55340dbe6f75e09b9"
+ logic_hash = "e6299dacb3891024e6699f166db0ecba511abe3e26d2cc6dc9ddd0929ba5121a"
score = 75
quality = 75
tags = "FILE"
@@ -141152,38 +148034,32 @@ rule MALPEDIA_Win_Lambert_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33f2 8b55e8 33ce 33d1 }
- $sequence_1 = { 4e 8b1f 8919 2bf0 }
- $sequence_2 = { 3bd8 0f826f010000 8a07 8801 41 47 }
- $sequence_3 = { 3bd8 0f82a4000000 83fe06 0f822cffffff }
- $sequence_4 = { 55 8bec 56 8b7510 c1fe04 }
- $sequence_5 = { 2bc1 3bc7 0f82e5010000 8b4508 2bc2 8d7701 }
- $sequence_6 = { 33f1 8b4de4 33ce 314de8 }
- $sequence_7 = { 3b7d10 724d 3bf9 7349 8bc3 2bc1 }
- $sequence_8 = { 6a00 e8???????? 8945fc 8b45fc 8945f4 8b4df4 8b55f4 }
- $sequence_9 = { 50 e8???????? 8945e8 8b4de8 3b4d10 750f }
- $sequence_10 = { 83ec18 8b450c 8b4814 894df0 8b550c 8b4508 }
- $sequence_11 = { 741f 8b4df8 c1e90d 8b55f8 }
- $sequence_12 = { ebce 8b45f8 8be5 5d c20400 55 8bec }
- $sequence_13 = { 8b510c 8b421c 8945f4 8b4df4 894df0 }
- $sequence_14 = { 3b5118 7334 8b45fc 8b4dec }
- $sequence_15 = { e8???????? 8945f8 8b4df8 3b4d08 7508 8b55f4 }
+ $sequence_0 = { b748 00ee 0be6 3bf6 2014dd33b89819 220f }
+ $sequence_1 = { 0fb7485e 83e954 8b55f8 66894a5e }
+ $sequence_2 = { fc b802ec0000 8d6825 94 01dc 00e8 45 }
+ $sequence_3 = { b802ec0000 8d6825 94 01dc 00e8 45 }
+ $sequence_4 = { ec 7ac4 f8 ae fc }
+ $sequence_5 = { 32705b 39e1 108792ff9b95 8abf2ec8650b }
+ $sequence_6 = { 1a00 0071bf 7303 1f c8be8de8 1be8 692405008008202c00700d }
+ $sequence_7 = { 66894118 8b55f8 0fb74218 83e854 8b4df8 66894118 ba8d000000 }
+ $sequence_8 = { 2cbe 832061 5b 5b }
+ $sequence_9 = { 30ac06e68bfc49 23f7 b754 7c49 27 59 }
condition:
- 7 of them and filesize <1212416
+ 7 of them and filesize <2677760
}
-rule MALPEDIA_Win_Lowkey_Auto : FILE
+rule MALPEDIA_Win_Windealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "16d4ae5f-e38d-570e-962d-91656915c4ac"
+ id = "f3b71a3e-a02a-5dce-bc43-cb374750ce4e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lowkey"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lowkey_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.windealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.windealer_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "663feed0bd96ec1d7d11defff75725aca17e4e2539133645562042d15d3f90de"
+ logic_hash = "d82b81175389182c804642799536612f0047302d818841ec0b2b4fd9f2036f88"
score = 75
quality = 75
tags = "FILE"
@@ -141197,32 +148073,32 @@ rule MALPEDIA_Win_Lowkey_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 482be0 488b05???????? 4833c4 48898520200000 33d2 c74590636d642e }
- $sequence_1 = { 488d3547ed0100 eb16 488b3b 4885ff 740a }
- $sequence_2 = { 0f85d7feffff e9???????? b966000000 66894c2435 e9???????? 488d15fa230200 488d8d70010000 }
- $sequence_3 = { b868000000 6689442435 eb49 488d1517250200 488d8d70010000 ff15???????? 85c0 }
- $sequence_4 = { 4833c4 4889842490040000 8bfa 488bd9 4885c9 }
- $sequence_5 = { 85c0 0f84bffeffff b865000000 895c2438 4c8d8570090000 6689442435 488d542430 }
- $sequence_6 = { ff15???????? e9???????? b9d3000000 663bc1 7551 4c3935???????? 7414 }
- $sequence_7 = { c3 4057 4883ec20 488d3d7b2d0100 48393d???????? 742b }
- $sequence_8 = { 5e 5b c3 488bcb ff15???????? 4885c0 7504 }
- $sequence_9 = { eb87 4055 53 57 488dac2470dfffff b890210000 }
+ $sequence_0 = { 50 56 e8???????? 83c410 8b4618 }
+ $sequence_1 = { 6a00 ff15???????? 85c0 7407 50 ff15???????? 6a01 }
+ $sequence_2 = { 6a04 50 6a04 68???????? 68???????? }
+ $sequence_3 = { 50 56 e8???????? 83c410 8b4610 }
+ $sequence_4 = { 53 56 57 68da070000 }
+ $sequence_5 = { 56 57 68da070000 e8???????? }
+ $sequence_6 = { 56 e8???????? 83c410 8b4610 }
+ $sequence_7 = { 6a01 50 56 e8???????? 83c410 8bc7 }
+ $sequence_8 = { 668b91d2070000 8a89d0070000 52 51 }
+ $sequence_9 = { 8b4d08 668b91d2070000 8a89d0070000 52 51 }
condition:
- 7 of them and filesize <643072
+ 7 of them and filesize <770048
}
-rule MALPEDIA_Win_Mindware_Auto : FILE
+rule MALPEDIA_Win_Contopee_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "205d25dc-9d1d-5cfe-9a1e-fc1d20bf21d6"
+ id = "77374f1e-6c89-5026-9b9e-741c43271a9e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mindware"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mindware_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.contopee"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.contopee_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "0229e104e7ced878ae1d5a8dad7ae14c8a1e11edebe2196883325f14972bfdf1"
+ logic_hash = "887c3d1e6d8d0ed992ba95d9f863595a093876d8864d3c96b3a6d6d4a8e08fbb"
score = 75
quality = 75
tags = "FILE"
@@ -141236,32 +148112,32 @@ rule MALPEDIA_Win_Mindware_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ff15???????? 8dbd48ffffff 32c0 b980000000 f3aa }
- $sequence_1 = { c78530e9ffffeccc4300 c78534e9fffff4cc4300 c78538e9ffff0ccd4300 c7853ce9ffff18cd4300 c78540e9ffff38cd4300 c78544e9ffff40cd4300 c78548e9ffff4ccd4300 }
- $sequence_2 = { c7857cf4ffff24e94300 c78580f4ffff38e94300 c78584f4ffff40e94300 c78588f4ffff48e94300 c7858cf4ffff58e94300 }
- $sequence_3 = { c1e910 335808 0fb6c9 895df4 33148df0d04400 }
- $sequence_4 = { 894dfc 89482c c1e918 897028 0fb699f0d84400 8b4dfc c1e910 }
- $sequence_5 = { 0fb6c9 33148dc0c84400 335004 8b4dfc c1e908 8955e8 0fb6d1 }
- $sequence_6 = { 8bec 837d0c00 764c e8???????? 0fb6c0 85c0 }
- $sequence_7 = { 6a00 8b856cffffff 50 8b8d68ffffff 51 8b55bc 52 }
- $sequence_8 = { c78530e6ffff5cc54300 c78534e6ffff68c54300 c78538e6ffff70c54300 c7853ce6ffff78c54300 c78540e6ffff88c54300 c78544e6ffff90c54300 c78548e6ffffa0c54300 }
- $sequence_9 = { 33d2 034dc8 1355cc 894dc8 8955cc e9???????? 8b45dc }
+ $sequence_0 = { c3 8bac244c020000 55 6a00 }
+ $sequence_1 = { 83c41c eb35 8b5614 8b442430 6a00 6aff 42 }
+ $sequence_2 = { 6880000000 50 8d8e6a050000 6880000000 51 }
+ $sequence_3 = { 66896c240c 8d842414020000 50 57 ff15???????? }
+ $sequence_4 = { 7510 ff15???????? 5f 5d 5b 81c4dc040000 c3 }
+ $sequence_5 = { 8bf8 ebc8 ff15???????? 8bf8 ebd1 5f }
+ $sequence_6 = { 7432 6a0f 51 50 e8???????? 8bf0 }
+ $sequence_7 = { 8bd8 8b4608 83f802 8b44242c 0f858e000000 eb04 8b7c2418 }
+ $sequence_8 = { 68???????? 51 ff15???????? 8b84243c020000 8d542428 52 50 }
+ $sequence_9 = { 52 e8???????? 83c430 5f 5e }
condition:
- 7 of them and filesize <661504
+ 7 of them and filesize <180224
}
-rule MALPEDIA_Win_Netrepser_Keylogger_Auto : FILE
+rule MALPEDIA_Win_Rapid_Ransom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "888501fd-ce54-593e-a428-69ec62ec3120"
+ id = "ffd06a30-064b-5d5c-9708-094ba6b3f858"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.netrepser_keylogger"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.netrepser_keylogger_auto.yar#L1-L175"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rapid_ransom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rapid_ransom_auto.yar#L1-L164"
license_url = "N/A"
- logic_hash = "afbddedf93927cf0ceddcdc20a2ff3aea4d270191a04c2cfa6d38a1b702f0067"
+ logic_hash = "467069894b412bd66ec7bc5db00e763aed4734a1d880a5b3cc4cb8b392b71ec1"
score = 75
quality = 75
tags = "FILE"
@@ -141275,40 +148151,39 @@ rule MALPEDIA_Win_Netrepser_Keylogger_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8a55f3 80c201 8855f3 837df807 7517 0fbe45f3 c6840570ffffff3a }
- $sequence_1 = { 51 8b5508 52 ff15???????? eb71 8d45ec 50 }
- $sequence_2 = { 51 680104c378 e8???????? 83c40c 8d55e8 52 }
- $sequence_3 = { 8945f4 8b45f4 33d2 b900ca9a3b f7f1 8955f4 8b55f4 }
- $sequence_4 = { 33c9 894ddc 894de0 894de4 894de8 c745dc10000000 c745e001000000 }
- $sequence_5 = { 8b55f0 52 ff15???????? 8b45c0 8be5 }
- $sequence_6 = { c645f274 c645f369 c645f466 c645f569 }
- $sequence_7 = { 7e0b 83bde4feffff08 7d02 ebcb 83bde4feffff1a 7e0b }
- $sequence_8 = { c744240c57726974 c74424106550726f c744241463657373 c74424184d656d6f c744241c72790000 ff15???????? a3???????? }
- $sequence_9 = { 8b701c 8bcf e8???????? 8b4c240c }
- $sequence_10 = { 51 c74424084f70656e c744240c50726f63 c744241065737300 ff15???????? a3???????? 8b542448 }
- $sequence_11 = { 56 33ff 53 8906 894e08 }
- $sequence_12 = { 68???????? ff15???????? 8bf8 85ff 7472 }
- $sequence_13 = { 55 8b6c244c 85c0 7550 }
- $sequence_14 = { f3a5 8b8c24b4000000 a4 8db329010000 56 }
- $sequence_15 = { b840000000 55 89442410 89442414 8d442410 50 8d4c2418 }
+ $sequence_0 = { 50 6801000004 6800a40000 ff75f8 }
+ $sequence_1 = { 83ec10 53 56 57 8bf9 32db 8bf2 }
+ $sequence_2 = { 83ec1c 53 57 8bf9 8bc2 }
+ $sequence_3 = { ff15???????? 6a00 ff75f8 ff15???????? 5e 5f 8ac3 }
+ $sequence_4 = { 7509 803a00 0f840c010000 8d742464 b8???????? 84db }
+ $sequence_5 = { 56 8bf2 8975fc 57 8bf9 85db }
+ $sequence_6 = { e8???????? 83c430 8d45f4 6800010000 }
+ $sequence_7 = { 7425 ff7514 8b542418 8bce ff7510 c644241701 57 }
+ $sequence_8 = { 0f8483000000 eb7d 8b1c9df8584100 6800080000 }
+ $sequence_9 = { 740e 50 e8???????? 83a6e8d0410000 59 83c604 }
+ $sequence_10 = { 8be5 5d c3 ff75e0 e8???????? 53 e8???????? }
+ $sequence_11 = { eb72 8d04cd00000000 2bc1 46 8935???????? c6048564d3410001 893c856cd34100 }
+ $sequence_12 = { 6804010000 8d85a4feffff 8bf1 6a00 50 }
+ $sequence_13 = { 40 c745ecf54e4000 894df8 8945fc 64a100000000 8945e8 }
+ $sequence_14 = { 83c9ff c7430c01000000 c7431000000000 eb2f }
condition:
- 7 of them and filesize <303104
+ 7 of them and filesize <286720
}
-rule MALPEDIA_Win_Conti_Auto : FILE
+rule MALPEDIA_Win_Adkoob_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "aae9ecae-21cf-5ec8-8511-8157ca36f115"
+ id = "09ef20a4-923f-52b9-be25-7277d044ed19"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.conti"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.conti_auto.yar#L1-L225"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.adkoob"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.adkoob_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "0be9a10d7e2a11f01ccc516eb831064a902454185cea8a72f6170734199b0c59"
+ logic_hash = "0f163717fb5860f8982d25c9dbbe18c357f664ad9d46a5bfca06cc794c00bf30"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -141320,46 +148195,32 @@ rule MALPEDIA_Win_Conti_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 56 57 bf0e000000 8d7101 }
- $sequence_1 = { 8d7f01 0fb6c0 b978000000 2bc8 }
- $sequence_2 = { 57 bf0a000000 8d7101 8d5f75 8a06 8d7601 0fb6c0 }
- $sequence_3 = { 8d7f01 0fb6c0 b96c000000 2bc8 }
- $sequence_4 = { 0f1f4000 8a07 8d7f01 0fb6c0 b948000000 }
- $sequence_5 = { 8975fc 803e00 7541 53 bb0a000000 }
- $sequence_6 = { 8975fc 803e00 7542 53 bb0e000000 }
- $sequence_7 = { 8d7f01 0fb6c0 b909000000 2bc8 }
- $sequence_8 = { e8???????? 8bb6007d0000 85f6 75ef 6aff }
- $sequence_9 = { 50 6a20 ff15???????? 68???????? ff15???????? 68???????? }
- $sequence_10 = { 780e 7f07 3d00005000 7605 }
- $sequence_11 = { 8bec 8b4d08 e8???????? 6a00 ff15???????? }
- $sequence_12 = { 50 8b4508 ff7004 ff15???????? 85c0 7508 6a01 }
- $sequence_13 = { 6810660000 ff7508 ff15???????? 85c0 }
- $sequence_14 = { 85ff 7408 57 56 ff15???????? ff75f8 56 }
- $sequence_15 = { 7411 a801 740d 83f001 50 ff7608 }
- $sequence_16 = { 48894c2430 4c8d45ff 488d4d0f 418bd6 48894c2428 488d4d07 48894c2420 }
- $sequence_17 = { 42884c0500 49ffc0 4983f80d 72af 44884d0f }
- $sequence_18 = { 33d2 ffd0 897c2450 b856555555 }
- $sequence_19 = { 0fb64500 0fb645ff 84c0 755c }
- $sequence_20 = { 488b4f30 488b4738 4885c9 7406 }
- $sequence_21 = { 48894c2448 488d55e0 488d4c2470 4533c0 }
- $sequence_22 = { 42884c0501 49ffc0 4983f80c 72af }
- $sequence_23 = { 41b801000000 488bd3 8bcf ffd0 4d85f6 }
+ $sequence_0 = { ff706c ffb0b0000000 8bc7 6a14 59 99 f7f9 }
+ $sequence_1 = { ff75f0 6a38 5a e8???????? 83c40c 8bce 40 }
+ $sequence_2 = { 8d5801 e9???????? 53 8bcf e8???????? 8b5dd8 84c0 }
+ $sequence_3 = { 8955f8 8b90d4000000 0fb6443b06 c1e108 0bc8 897de8 2bf1 }
+ $sequence_4 = { ff504c 85c0 7536 8b75dc 56 ff15???????? 50 }
+ $sequence_5 = { 8b7508 83fe09 7756 80beac1d4c0000 57 8b3d???????? 0f453d???????? }
+ $sequence_6 = { ff75e8 ff15???????? 837dd000 8b35???????? 7405 ff75d0 ffd6 }
+ $sequence_7 = { ff742418 68???????? e8???????? 83c40c 89442428 85c0 747b }
+ $sequence_8 = { ff7510 8bce ffb578ffffff ff75b8 ff7598 ffb564ffffff ff75c4 }
+ $sequence_9 = { 8b4744 52 50 8b08 ff5114 59 59 }
condition:
- 7 of them and filesize <520192
+ 7 of them and filesize <1867776
}
-rule MALPEDIA_Win_Allaple_Auto : FILE
+rule MALPEDIA_Win_Blackcat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3189c357-03ca-579b-a008-778eac3a8556"
+ id = "64552e7e-a42b-5e42-ac85-4cf9a6355d18"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.allaple"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.allaple_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackcat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackcat_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "415071fc213b7748f93f2d59f832b2786979b53afe7fe779d13e0c2bb9460bfe"
+ logic_hash = "2fe3958ae160b549a525be2a75569af9cb09940744adfe7a2969b920b4e1603b"
score = 75
quality = 75
tags = "FILE"
@@ -141373,32 +148234,32 @@ rule MALPEDIA_Win_Allaple_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ff75a0 e8???????? 83f8ff 756a e8???????? 3d33270000 }
- $sequence_1 = { 7708 2b7b0c 037b14 eb0f 83c328 83c628 }
- $sequence_2 = { 6a40 8b55a8 8d4db0 e8???????? 8b55f8 2355f4 8b45f8 }
- $sequence_3 = { 6a14 ff7508 57 e8???????? 83c714 c70701000000 83c704 }
- $sequence_4 = { 6800800000 6a00 ff75e0 e8???????? eb09 0bc0 7505 }
- $sequence_5 = { 55 8bec 83ec24 8955e0 894de4 c745fc00000000 8b45fc }
- $sequence_6 = { 894174 8b55fc 8b4278 3345f4 8b4df8 894178 8b55fc }
- $sequence_7 = { 0f8539010000 8145f8bc020000 ff75f8 e8???????? 8945f4 ff75fc ff75f4 }
- $sequence_8 = { ff45fc 8b45fc 3b4510 7ce5 8be5 5d c3 }
- $sequence_9 = { 8b4df8 894178 8b55fc 8b427c 3345f4 8b4df8 89417c }
+ $sequence_0 = { c3 894608 c7460400000000 b001 ebe8 89c2 }
+ $sequence_1 = { 7260 8b06 01d8 51 57 50 89cf }
+ $sequence_2 = { 8975dc 8955e0 eb07 31c0 b902000000 }
+ $sequence_3 = { b104 eb0f e8???????? 89c2 c1e018 31c9 }
+ $sequence_4 = { 7504 3c02 7351 88c4 8975cc }
+ $sequence_5 = { 81f9cf040000 0f8fe4000000 81f96b040000 0f84b4010000 81f976040000 }
+ $sequence_6 = { 83ec08 a1???????? c745f800000000 c745fc00000000 85c0 7408 8d4df8 }
+ $sequence_7 = { 8d45f8 50 e8???????? 8b45f8 8b55fc 83c408 }
+ $sequence_8 = { 895804 897008 eb0b 8b45e8 894708 }
+ $sequence_9 = { ff45e4 8a02 42 8955e8 }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <29981696
}
-rule MALPEDIA_Win_Afrodita_Auto : FILE
+rule MALPEDIA_Win_Torisma_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a57e10f8-454f-5804-9e05-9ca06675125c"
+ id = "a1ed0c86-448e-5725-a3d9-4e9a8d06915c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.afrodita"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.afrodita_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.torisma"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.torisma_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "5b27d8ca339092e6723ab16dacd8e13cc60f1f330873451b2d099d87287bfb55"
+ logic_hash = "5ec5e797b8010193d7caa6926dd920962119b17c8339298b3be41306fc75b6f7"
score = 75
quality = 75
tags = "FILE"
@@ -141412,32 +148273,35 @@ rule MALPEDIA_Win_Afrodita_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83e615 83ce02 89710c 23c6 74a5 a804 740a }
- $sequence_1 = { e8???????? 56 8d8558ffffff c745fc05000000 57 83cb08 50 }
- $sequence_2 = { e8???????? eb02 33ff 8bb57cffffff c745fcffffffff 8b4e2c 85c9 }
- $sequence_3 = { 8d4f10 e8???????? 8b0f 8b4904 03cf 85c0 7454 }
- $sequence_4 = { 0f1040c0 0f1149a0 0f104c30c0 8b75e8 660fefc8 0f1040d0 0f114c30c0 }
- $sequence_5 = { 897304 c6430801 53 8d4de4 }
- $sequence_6 = { 8b4b08 8b7b0c 897df8 894dfc 3bce }
- $sequence_7 = { e8???????? 83c40c c744be0400000000 c704be00000000 5e 5b }
- $sequence_8 = { 50 8bcb ff5720 0375d4 8bce e8???????? }
- $sequence_9 = { 894f04 8bc7 e9???????? 83f854 0f8fdc010000 83f853 0f8dea020000 }
+ $sequence_0 = { e8???????? 3d83490000 7507 b883490000 }
+ $sequence_1 = { 7402 eb05 e9???????? b833280000 }
+ $sequence_2 = { e8???????? 3d514b0000 7504 33c0 }
+ $sequence_3 = { 488b4c2470 e8???????? 89442458 817c245870100000 }
+ $sequence_4 = { 030cb540ef0110 eb02 8bca f641247f 759b }
+ $sequence_5 = { b833280000 5f 5e 8be5 5d }
+ $sequence_6 = { 8b55fc 833a00 740c 8b45fc 8b08 51 }
+ $sequence_7 = { 488d442440 488bf8 33c0 b928000000 }
+ $sequence_8 = { 8b4c2430 488b542450 89048a ebb5 }
+ $sequence_9 = { 817dd833280000 7507 c745f433280000 eb07 c745f433280000 }
+ $sequence_10 = { c68424e1000000e9 c68424e2000000c3 c68424e3000000a5 c68424e400000090 }
+ $sequence_11 = { ff2495c0d50010 8bc7 ba03000000 83e904 720c 83e003 }
+ $sequence_12 = { c1e006 0b442414 88442410 8b442440 }
condition:
- 7 of them and filesize <2334720
+ 7 of them and filesize <322560
}
-rule MALPEDIA_Win_Mebromi_Auto : FILE
+rule MALPEDIA_Win_Iisniff_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e0d98380-a60b-51d2-98f3-302d440340e7"
+ id = "4d48d0b9-4608-5fda-9d9c-52fef07b4d04"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mebromi"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mebromi_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.iisniff"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.iisniff_auto.yar#L1-L161"
license_url = "N/A"
- logic_hash = "4361b37a1cf79aacd380ae78b2f2e74bbc44d101b09510c6583cf0529e44be88"
+ logic_hash = "eea8ed3537fc508bcc20c7dcdf7a5fa6fb525fac16191889baa1f35692f7bc88"
score = 75
quality = 75
tags = "FILE"
@@ -141451,32 +148315,37 @@ rule MALPEDIA_Win_Mebromi_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 743a 837d0800 742e 85f6 7419 0fb6da f68301a0290004 }
- $sequence_1 = { 68ff010f00 68???????? ff742410 ff15???????? 8bf0 85f6 7416 }
- $sequence_2 = { 7714 8b55fc 8a9270722900 089001a02900 }
- $sequence_3 = { 683f000f00 55 55 ff15???????? 8bf0 e8???????? 56 }
- $sequence_4 = { 48 750c e8???????? eb05 e8???????? 6a01 }
- $sequence_5 = { 0fb6fa 3bc7 7714 8b55fc 8a9270722900 089001a02900 }
- $sequence_6 = { 2c29 0000 2d29008a46 0323 d18847034ec1 e9???????? }
- $sequence_7 = { 0fb6d2 f68201a0290004 740c ff01 }
- $sequence_8 = { aa 8d9e88722900 803b00 8bcb 742c 8a5101 84d2 }
- $sequence_9 = { 50 6a01 56 ff15???????? 56 8bf8 ff15???????? }
+ $sequence_0 = { 85c0 7513 8b442414 8b4804 53 }
+ $sequence_1 = { 8b8c240c000100 56 8d842414000100 50 51 }
+ $sequence_2 = { 7507 be04000000 eb69 c645fc01 8b0f }
+ $sequence_3 = { 55 56 8bb42488000000 57 33db }
+ $sequence_4 = { 83d8ff 85c0 7537 8dbc24a4000000 e8???????? }
+ $sequence_5 = { 5f 5b c20400 8b4038 8b08 890e }
+ $sequence_6 = { 8b45cc ff704c e8???????? 59 83f8ff 0f852cffffff }
+ $sequence_7 = { 56 8d4dd4 894598 e8???????? 8365fc00 56 8d4d9c }
+ $sequence_8 = { 895c241c 89442420 e8???????? 8bf0 }
+ $sequence_9 = { e8???????? 83c404 8d8c24fc000000 899c2448010000 89bc2444010000 }
+ $sequence_10 = { 6a03 68000000c0 68???????? ff15???????? 6a02 }
+ $sequence_11 = { e8???????? 8b4f3c 8b11 8d75c8 56 ff75cc }
+ $sequence_12 = { ff75e8 e8???????? 834dfcff 8b45dc }
+ $sequence_13 = { c3 ff7508 e8???????? 59 c3 833d????????00 7505 }
+ $sequence_14 = { 64a300000000 80bc24a400000000 7409 6a00 6a00 e8???????? 8b410c }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <1441792
}
-rule MALPEDIA_Win_Sage_Ransom_Auto : FILE
+rule MALPEDIA_Win_Glitch_Pos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "847781b4-d239-5a8c-9601-0e5bac6cb5da"
+ id = "f95f1f9c-9245-5181-9c68-89e1dc86d5ed"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sage_ransom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sage_ransom_auto.yar#L1-L164"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.glitch_pos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.glitch_pos_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "0e6ae75d84196f5850e13769b0aaa494f43257ce3727ef9fdf2f02bbc3316ba8"
+ logic_hash = "27fcd67a00a15c3597cc82166656216e7d9a07529c9493cfeef64f5dddb0c04c"
score = 75
quality = 75
tags = "FILE"
@@ -141490,38 +148359,32 @@ rule MALPEDIA_Win_Sage_Ransom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 56 68???????? e8???????? 83c408 6a00 6a00 }
- $sequence_1 = { 8b74246c 57 c7442408adde9e5a b908000000 8d7c240c f3a5 8b742478 }
- $sequence_2 = { 6a02 ff15???????? 8bf0 8d471c }
- $sequence_3 = { 55 56 894c243c ff15???????? 83f8ff 7541 56 }
- $sequence_4 = { 56 57 6af5 ff15???????? 8b15???????? 83c204 52 }
- $sequence_5 = { 68e0930400 ffd6 6a02 e8???????? 83c404 68c0270900 }
- $sequence_6 = { 0facf014 89442420 c1ee14 8bc6 }
- $sequence_7 = { 83c438 833d????????00 7513 e8???????? 50 }
- $sequence_8 = { 01410c 8b4310 014110 8b4314 }
- $sequence_9 = { 013c13 83c102 46 ebd3 }
- $sequence_10 = { 014114 8b4318 014118 8b431c }
- $sequence_11 = { 0101 8b4304 014104 8b4308 014108 }
- $sequence_12 = { 891c24 89442404 e8???????? 31d2 3955dc 0f86df000000 }
- $sequence_13 = { 014110 8b4314 014114 8b4318 }
- $sequence_14 = { 0119 117104 83c110 83c210 }
- $sequence_15 = { 014108 8b430c 01410c 8b4310 }
+ $sequence_0 = { 83a5d8feffff00 8b45b8 898518ffffff 8d45d0 50 8b8518ffffff }
+ $sequence_1 = { 8b4508 8b00 ff7508 ff9028070000 668b45d4 662d0100 }
+ $sequence_2 = { ffb504ffffff e8???????? 89855cfeffff eb07 83a55cfeffff00 8d8d5cffffff e8???????? }
+ $sequence_3 = { e8???????? 8d8520ffffff 50 8d8530ffffff 50 8d45dc 50 }
+ $sequence_4 = { 68???????? 68???????? e8???????? c78568feffff2cc34600 eb0a c78568feffff2cc34600 8b8568feffff }
+ $sequence_5 = { eb07 83a5fcfdffff00 8d45c4 50 8d45cc 50 6a02 }
+ $sequence_6 = { 8b4d10 660301 0f8058040000 668945ec 8b4508 8b00 }
+ $sequence_7 = { 83c40c 68???????? 6a00 6a06 8b4508 }
+ $sequence_8 = { 8d45b4 50 8d45b8 50 6a03 e8???????? }
+ $sequence_9 = { 8bec 83ec0c 68???????? 64a100000000 50 64892500000000 b8bc000000 }
condition:
- 7 of them and filesize <335872
+ 7 of them and filesize <1024000
}
-rule MALPEDIA_Win_Fengine_Auto : FILE
+rule MALPEDIA_Win_Royal_Ransom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c3f38b1d-0317-5325-80d6-6bc13a77b878"
+ id = "03d0866a-b258-5731-ad57-bc4b0e928885"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fengine"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fengine_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.royal_ransom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.royal_ransom_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "04b59b3b4a1631576dab348f5698f6f17211f788439d858316727821c2f4b921"
+ logic_hash = "05d0adf9ccc7ed8f53f566dd8191bfd8d7450964340be8e2ce8cbced72447263"
score = 75
quality = 75
tags = "FILE"
@@ -141535,34 +148398,34 @@ rule MALPEDIA_Win_Fengine_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 72e2 8b5c2414 8d842490000000 50 }
- $sequence_1 = { 833cfd4010410000 755b 6a18 e8???????? 59 }
- $sequence_2 = { 50 ff15???????? 68???????? 8d85fcf7ffff 6800080000 }
- $sequence_3 = { 7405 352083b8ed 46 3bf7 0f825fffffff 5f }
- $sequence_4 = { c1e81e 83e001 83e101 8d0c48 8bc6 }
- $sequence_5 = { 53 8d4e04 6800080000 51 }
- $sequence_6 = { 56 e8???????? 8b8de4feffff 8b95e0feffff 8b413c 03c6 8bb5dcfeffff }
- $sequence_7 = { 83c408 85c0 750f c705????????03000000 e9???????? ffb5bcfaffff }
- $sequence_8 = { eb23 8b9d2ce5ffff 8a02 8b0c9d60514100 }
- $sequence_9 = { 83e31f c1e306 8b048560514100 0fbe441804 83e001 }
+ $sequence_0 = { 752f e8???????? 4c8d05d60c1400 ba8b010000 488d0d320c1400 e8???????? 4533c0 }
+ $sequence_1 = { e9???????? 2bc3 488d0d2df4dfff 488b8ce9d02c2d00 8064f93dfd f7d8 1ac0 }
+ $sequence_2 = { e8???????? 33c0 e9???????? 488b4820 e8???????? 85c0 0f8497020000 }
+ $sequence_3 = { e8???????? 488d4e24 448bc8 4c8d0579a80d00 ba09000000 e8???????? 488bcb }
+ $sequence_4 = { 8bc2 896c2444 418bfe 83fa02 7d3e e8???????? 4c8d05e7a90f00 }
+ $sequence_5 = { 488d1507b51300 41b893040000 e8???????? 41b894040000 488d15efb41300 488bcf e8???????? }
+ $sequence_6 = { e8???????? baa6000000 4c89742420 4c8bcd 4c8d05f3a80e00 8d4a93 e8???????? }
+ $sequence_7 = { 754a e8???????? 4c8d054e820d00 baa2000000 488d0df2810d00 e8???????? 4533c0 }
+ $sequence_8 = { b828000000 e8???????? 482be0 488d15fc4fffff 488d0d5de62000 e8???????? 33c9 }
+ $sequence_9 = { e8???????? 85c0 7437 488d05297a0000 4c89742430 4889442428 4c8d0d485c0e00 }
condition:
- 7 of them and filesize <210944
+ 7 of them and filesize <6235136
}
-rule MALPEDIA_Win_Elirks_Auto : FILE
+rule MALPEDIA_Win_Hookinjex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "abbbcbca-d514-5806-9c10-833d31c8983a"
+ id = "cc81917a-8c1e-59eb-8738-a94445516bc1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.elirks"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.elirks_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hookinjex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hookinjex_auto.yar#L1-L148"
license_url = "N/A"
- logic_hash = "4de38c5bbb938b8f52d51f635312140a804238195b0d5824203719bed438cd32"
- score = 75
- quality = 75
+ logic_hash = "afb96fa06c3548b099102aa92aa51777edafb1bb6fe4920aba390d45066ccc62"
+ score = 60
+ quality = 25
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -141574,32 +148437,38 @@ rule MALPEDIA_Win_Elirks_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4c2414 51 68???????? 8bf0 ff15???????? }
- $sequence_1 = { 85c0 7417 8b44241c 01442414 03f0 2bf8 e9???????? }
- $sequence_2 = { 51 8d44241c e8???????? 8b8e04600000 83c404 }
- $sequence_3 = { 83c102 66c7012d00 83c102 66c7012d00 83c102 83ef03 83c603 }
- $sequence_4 = { 68???????? 8d442430 e8???????? 83c40c }
- $sequence_5 = { 7fe8 85ff 0f84a1010000 85ff 7e25 }
- $sequence_6 = { c1f803 0faf4608 894614 6a68 }
- $sequence_7 = { 52 ff15???????? 8bd8 83fbff 895c2410 7546 }
- $sequence_8 = { 8d8c2490060000 51 6804010000 ff15???????? 8d9e0c600000 53 6a00 }
- $sequence_9 = { 750b 57 e8???????? 83c404 5e c3 }
+ $sequence_0 = { e8???????? 85c0 740c b913e40000 }
+ $sequence_1 = { e8???????? b964000000 ff15???????? 0fb705???????? }
+ $sequence_2 = { e8???????? 85c0 7507 b80e000000 }
+ $sequence_3 = { e9???????? 488b4c2458 e8???????? 488b4c2450 }
+ $sequence_4 = { e8???????? b95b730100 e8???????? e9???????? }
+ $sequence_5 = { e8???????? 85c0 750f b9dc550100 }
+ $sequence_6 = { e8???????? 833d????????00 7411 b903000000 e8???????? }
+ $sequence_7 = { e8???????? 85c0 7408 803b00 }
+ $sequence_8 = { 48817c243000100000 0f82dc020000 488b442460 4889442438 }
+ $sequence_9 = { 2500180000 3d00080000 750d c78424e800000001000000 eb0b }
+ $sequence_10 = { 25001b0000 3d00100000 750a c744244401000000 }
+ $sequence_11 = { 25001b0000 3d00110000 750d c784243c01000001000000 }
+ $sequence_12 = { 25001b0000 3d00100000 750d c784242401000001000000 }
+ $sequence_13 = { 2500180000 3d00180000 750a c744247c01000000 }
+ $sequence_14 = { 25001b0000 3d00110000 750a c744245c01000000 }
+ $sequence_15 = { 48817c243800100000 0f82f5000000 488b442438 4883c02f }
condition:
- 7 of them and filesize <81920
+ 7 of them and filesize <6545408
}
-rule MALPEDIA_Win_Megumin_Auto : FILE
+rule MALPEDIA_Win_Kikothac_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "992bacc8-d168-5613-b9a1-b270fb7e71d1"
+ id = "48840edd-1eda-587e-96d1-699222be4802"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.megumin"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.megumin_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kikothac"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kikothac_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "d3f02e69acad5c637179e097455fd85b104ce227d90fce5cb059c87c08c3436c"
+ logic_hash = "ddecb618114edd432a6ac40a5ecfd59b3208358e4b28a6940c432c46b4921216"
score = 75
quality = 75
tags = "FILE"
@@ -141613,32 +148482,32 @@ rule MALPEDIA_Win_Megumin_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b348510164600 037520 6b45243c 034528 6bc03c 03452c }
- $sequence_1 = { 8945e8 57 8d4dd8 c745fc00000000 e8???????? 8b45e8 85c0 }
- $sequence_2 = { 8d45f4 64a300000000 6841010000 8d8528faffff c745fc00000000 6a00 50 }
- $sequence_3 = { 8d4dd8 8d45c0 50 e8???????? ff37 8d55d7 8d4db0 }
- $sequence_4 = { c60100 e8???????? 8d4c2430 e8???????? 8bc8 83c418 83791410 }
- $sequence_5 = { 833d????????00 0f8549870000 8d0d90e74500 ba1d000000 e9???????? 833d????????00 0f852c870000 }
- $sequence_6 = { 83c404 8d8d14fdffff c645fc1a 51 8bd0 8d8d04fbffff }
- $sequence_7 = { 0f1f440000 8845eb 8b410c 897da8 8945b0 c645fc02 }
- $sequence_8 = { 8d4101 8945d8 3dffffff7f 0f8700010000 6a00 6a00 50 }
- $sequence_9 = { 3bca 763b 8bd1 a81f 7535 8b48fc }
+ $sequence_0 = { 85c0 7516 8b86942f4100 b301 85c0 740a }
+ $sequence_1 = { 50 ff15???????? a3???????? 3bc3 7507 32c0 5b }
+ $sequence_2 = { 56 33f6 57 8975fc ffd3 85c0 }
+ $sequence_3 = { c60424cd 8d642438 e9???????? c64424046e 895500 9c 6689742408 }
+ $sequence_4 = { c1c80a e9???????? 66894500 9c }
+ $sequence_5 = { 8b441604 51 50 ff15???????? 85c0 7516 }
+ $sequence_6 = { 51 68102ba40e ff3424 9c 8f442438 }
+ $sequence_7 = { 6820040000 57 57 57 }
+ $sequence_8 = { 60 f6c356 c6442404ab 20d0 }
+ $sequence_9 = { e9???????? 8b7c242c 66c70424dc83 98 9f 8b442430 660fbeeb }
condition:
- 7 of them and filesize <1007616
+ 7 of them and filesize <581632
}
-rule MALPEDIA_Win_Cycbot_Auto : FILE
+rule MALPEDIA_Win_Cadelspy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "86cbdc6e-7fe8-5962-82c9-3bfe759d3962"
+ id = "4b5e300d-757a-5fee-8d04-bdd6cbf72a64"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cycbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cycbot_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cadelspy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cadelspy_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "0df38e9a7bf0b18ae5c795f617ec217aef7020970864c9cdbebdcaf5c85c3174"
+ logic_hash = "7f3bdf0fe810a37a01bcc3fbdfdc1fe97ab8b02a604549fa04a7da715441b0c6"
score = 75
quality = 75
tags = "FILE"
@@ -141652,32 +148521,32 @@ rule MALPEDIA_Win_Cycbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 59 8b45ec e8???????? c3 6834020000 b8???????? e8???????? }
- $sequence_1 = { 57 ffb5e8feffff ff15???????? 8bb5ecfeffff 2bf3 f7de 1bf6 }
- $sequence_2 = { c745dc44eb4300 c745e08ceb4300 c745e40cee4300 c745e820ee4300 c745ec34ee4300 c745f0f4ec4300 c745f4fcec4300 }
- $sequence_3 = { 8b06 8b4008 89480c 8b06 894808 8b4508 8908 }
- $sequence_4 = { 59 33c0 8d7dc8 f3ab aa 8d45c8 6a21 }
- $sequence_5 = { 33c0 8903 894304 57 894308 ff15???????? c70300000000 }
- $sequence_6 = { 8d854cfbffff 50 8bc7 e8???????? 59 59 57 }
- $sequence_7 = { ff5108 8d85e0fbffff 50 ff15???????? ff85d8fbffff 39bdb4fbffff }
- $sequence_8 = { 50 e8???????? 837c241801 59 59 7408 c744241807000000 }
- $sequence_9 = { b90a0a0000 663b4c07fe 7508 8945fc be01000000 40 }
+ $sequence_0 = { e8???????? c7042408020000 33f6 56 ff7514 e8???????? 83c40c }
+ $sequence_1 = { e8???????? 68???????? 8d9c2464020000 e8???????? 6828020000 }
+ $sequence_2 = { 46 66833e5c 74f8 8bc6 8d5002 }
+ $sequence_3 = { 59 59 85c0 7524 837d8c05 }
+ $sequence_4 = { ff15???????? ff75fc 8bd8 ff15???????? 5e 8bc3 5b }
+ $sequence_5 = { 57 33ff 893a 8d4802 668b30 40 }
+ $sequence_6 = { 8b0c8d004c0110 83e01f c1e006 8d440124 }
+ $sequence_7 = { 741b 8b07 8bc8 c1f905 83e01f c1e006 8b0c8d004c0110 }
+ $sequence_8 = { 8d442418 50 e8???????? eb0b 50 }
+ $sequence_9 = { 7507 e8???????? eb5f 57 8b7d08 85ff 750a }
condition:
- 7 of them and filesize <1163264
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Yorekey_Auto : FILE
+rule MALPEDIA_Win_Andromut_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0c2854a9-311b-528a-8d3c-9008975025f5"
+ id = "dba8d7dc-66b9-5da2-b280-7c7cd5055ee5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yorekey"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yorekey_auto.yar#L1-L165"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.andromut"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.andromut_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "bfaa0e3abe9f69e663c8e7749df7b846bcbaa395b01b91bd4c5c56f646e51121"
+ logic_hash = "97f484310b347cbce8f6e0e26b13796260e2f5f5c7183f29f706e1875ad44a4f"
score = 75
quality = 75
tags = "FILE"
@@ -141691,37 +148560,32 @@ rule MALPEDIA_Win_Yorekey_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 750a 85c0 7506 ff15???????? }
- $sequence_1 = { 4883ec20 33ff 488d1dc9fa0000 488b0b ff15???????? }
- $sequence_2 = { 33c9 ff15???????? 488bd8 ff15???????? 3db7000000 7509 }
- $sequence_3 = { 8bc6 83f801 7521 a1???????? 50 ff15???????? 68???????? }
- $sequence_4 = { 03048de0404100 eb02 8bc2 f6402480 0f8571ffffff 33f6 3bfe }
- $sequence_5 = { 4803d1 488d0d02090100 442bc6 488b0cc1 498b0c0c ff15???????? 85c0 }
- $sequence_6 = { 7530 a1???????? ba???????? 50 e9???????? a1???????? }
- $sequence_7 = { 488bce e8???????? 488d154c040100 4c63c8 418d4902 }
- $sequence_8 = { 730d 488bd3 488bcf e8???????? eb1c }
- $sequence_9 = { 751b 6a02 33c9 51 }
- $sequence_10 = { 7405 6641894d00 4885f6 7457 483bf7 7252 4d85ff }
- $sequence_11 = { 898570ffffff 89856cffffff 8d4598 b919000000 }
- $sequence_12 = { ff15???????? 488d44243c 448d4f04 4889442428 4c8d05cbfaffff }
- $sequence_13 = { 5a 8985c4fbffff 3bc2 0f8451ffffff 83f807 0f87110a0000 ff2485b19b4000 }
- $sequence_14 = { 55 8bec 51 8bc2 56 8d7002 8d9b00000000 }
+ $sequence_0 = { 8b75f8 6bc828 8b441914 03441910 b9aacd12d8 50 56 }
+ $sequence_1 = { e8???????? 8d850cffffff 50 8d8574ffffff 50 8d95fcfcffff 8d8d74fcffff }
+ $sequence_2 = { c785fcfeffff84408441 c78500ffffff842c8415 c78504ffffff843c840d c78508ffffff841c8423 }
+ $sequence_3 = { e8???????? 8d8de8fcffff 51 8d8dd8faffff 51 ffd0 }
+ $sequence_4 = { 83c40c c745d4e278e238 c745d8de58e218 c745dcdef8dcb8 c745e0e498e0f8 }
+ $sequence_5 = { e9???????? 83bde4feffff06 0f85cf000000 8b85e8feffff 83f803 7524 83ef02 }
+ $sequence_6 = { 8bd0 51 ffb5fcfcffff 8d4dcc e8???????? 59 }
+ $sequence_7 = { f3ab 8b7dfc b802210000 6689443e16 0fb7443e06 }
+ $sequence_8 = { 53 6a0a 6a18 8d8510f4ffff c645fc02 50 e8???????? }
+ $sequence_9 = { 5a 84c0 745c 8d4601 894588 f7e2 0f90c1 }
condition:
- 7 of them and filesize <274432
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Acridrain_Auto : FILE
+rule MALPEDIA_Win_Pandabanker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "82271a88-0572-5daa-a06b-4b68b32ae23f"
+ id = "58cad36d-92dc-5f57-8115-b38a95b1c2cd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acridrain"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.acridrain_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pandabanker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pandabanker_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "2ef6b9a2838948e7218bd1e79fe0257da485657bd990a4bc6b62c314342a8e67"
+ logic_hash = "64182a4cfed301300c0a7df71a34e50b114a69353e8eb5e84fdb9f4804c83f2c"
score = 75
quality = 75
tags = "FILE"
@@ -141735,32 +148599,32 @@ rule MALPEDIA_Win_Acridrain_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb03 8b4dd0 8b45e0 8b55cc 8945cc 8a45f0 8955e0 }
- $sequence_1 = { ff76a4 53 e8???????? 83c428 8945dc e9???????? 6a00 }
- $sequence_2 = { ffd0 8b75f0 8bc8 83c414 85c9 0f85c5000000 0fce }
- $sequence_3 = { eb0c 8b4d9c 83c104 894d9c 8b41fc 8945a0 8bc8 }
- $sequence_4 = { eb5d 8b03 8b8890860000 803900 7520 8d442414 6801040000 }
- $sequence_5 = { 8b8520ffffff 33ff 8b10 85d2 0f8ea6000000 33c9 898d50ffffff }
- $sequence_6 = { f6459c01 0f84ae0b0000 8bc6 83e007 3bf0 0f83d50a0000 e9???????? }
- $sequence_7 = { 8b4748 56 ffd0 8b7584 83c410 8bbd78ffffff eb09 }
- $sequence_8 = { ffb5d0fdffff e8???????? 83c408 8985d4fdffff 85c0 0f85844b0000 ffb5d0fdffff }
- $sequence_9 = { e9???????? 83fe02 750c c7872005000003000000 eb7b c7872005000000000000 83fe03 }
+ $sequence_0 = { 56 8bf2 57 83f8ff 7507 8bce e8???????? }
+ $sequence_1 = { 57 8b4808 8d7c2418 8b4004 }
+ $sequence_2 = { c1e202 8bfe 8bca 45 }
+ $sequence_3 = { 7404 c6400109 8b442430 8bd5 014608 8bcf 56 }
+ $sequence_4 = { eb2c 6a05 5a 8bcf }
+ $sequence_5 = { c6007b 40 85db 7404 c6000a 40 c60000 }
+ $sequence_6 = { e8???????? 8bf0 85f6 7411 8bcf }
+ $sequence_7 = { 85ff 7423 8b0e 8bd5 }
+ $sequence_8 = { e8???????? 8b742414 8bce 8b542418 89742424 e8???????? 84c0 }
+ $sequence_9 = { 7508 33c0 85d2 0f95c0 c3 }
condition:
- 7 of them and filesize <2244608
+ 7 of them and filesize <417792
}
-rule MALPEDIA_Win_Mechanical_Auto : FILE
+rule MALPEDIA_Win_Hdmr_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2ebc8e2c-9656-5fd5-9240-713f089f8d21"
+ id = "efac4b5a-015c-5408-9681-2898b333d92b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mechanical"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mechanical_auto.yar#L1-L158"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hdmr"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hdmr_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "0d673fb1f58f38008ae08ad0a2913e65568b1230b5de3947ba7af4a4e448c6f0"
+ logic_hash = "d93eae97d145bb46a0ed753e26aa98381b2be0cfcaaaf5d8753f4519f5f83cf1"
score = 75
quality = 75
tags = "FILE"
@@ -141774,38 +148638,32 @@ rule MALPEDIA_Win_Mechanical_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 03c7 3bca 72ed 5f }
- $sequence_1 = { c6025e eb12 c6022f eb0d }
- $sequence_2 = { 8b442430 488d8c2471110000 33d2 41b803010000 }
- $sequence_3 = { 0401 3cbe 8844240b 76e2 }
- $sequence_4 = { 03ce c6840c3801000000 8d8424a05c0000 33f6 }
- $sequence_5 = { 033485c0e54200 c745e401000000 33db 395e08 }
- $sequence_6 = { 488d15d9d20000 488bcb e8???????? 85c0 750a 4883c310 }
- $sequence_7 = { 00686c 42 0023 d18a0688078a }
- $sequence_8 = { 4488a424300d0000 488905???????? e8???????? 4c8d1d5cd40100 498bcc }
- $sequence_9 = { eb62 c6023d eb5d c6025f eb58 c6023a }
- $sequence_10 = { 03c1 1bc9 0bc1 59 e9???????? e8???????? ff742404 }
- $sequence_11 = { 41c1c90d 8bca 4983c201 4403c8 493bc8 }
- $sequence_12 = { 033485c0e54200 8b45e4 8b00 8906 }
- $sequence_13 = { 030495c0e54200 eb05 b8???????? f6400420 }
- $sequence_14 = { 33d2 41b803010000 4488a42470110000 488905???????? e8???????? }
- $sequence_15 = { 3c58 7711 480fbec5 428a8c10507c0200 83e10f eb03 }
+ $sequence_0 = { 8945e0 85c0 7461 8d0cbd40d04100 8901 8305????????20 8b11 }
+ $sequence_1 = { 8945ec 894df0 894dfc 8b16 8b523c 50 }
+ $sequence_2 = { c1e810 4a 75e6 eb07 }
+ $sequence_3 = { 56 8b7508 68fe070000 8d85fef7ffff 6a00 }
+ $sequence_4 = { 85db 0f8492010000 8b8d70ffffff 0fb709 }
+ $sequence_5 = { 250000ff00 81e3000000ff 33c3 8bda 81e2ff000000 }
+ $sequence_6 = { 0fb701 0fb71c0f 2bc3 2bc2 }
+ $sequence_7 = { 75ea 8a03 3c61 0fbec0 }
+ $sequence_8 = { 8b400c 51 52 8bce ffd0 5e 5b }
+ $sequence_9 = { 50 ff15???????? 8d8c24780a0000 51 }
condition:
- 7 of them and filesize <434176
+ 7 of them and filesize <284672
}
-rule MALPEDIA_Win_Dramnudge_Auto : FILE
+rule MALPEDIA_Win_Poohmilk_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4e1e9905-62de-5567-9ed7-a82928870a8c"
+ id = "4a533432-ed1d-58b3-b34c-6e80b5d4a8fb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dramnudge"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dramnudge_auto.yar#L1-L90"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poohmilk"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poohmilk_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "221dd8bcd930b6121a924fbe6761de15c83c657ddce0c9178183beb8828f75f7"
+ logic_hash = "ecd179731e16caedb85d9961e87834bc792941e3499df96bf9bfcadeaf395c81"
score = 75
quality = 75
tags = "FILE"
@@ -141819,30 +148677,32 @@ rule MALPEDIA_Win_Dramnudge_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 014218 eb18 03c3 8bd3 }
- $sequence_1 = { 000c00 20b140005f5f 7277 7374 }
- $sequence_2 = { 014318 8b430c 2b4308 03c6 }
- $sequence_3 = { 000c00 e0d9 40 007374 }
- $sequence_4 = { 014318 8b4318 8b55f8 03d6 }
- $sequence_5 = { 007374 643a3a 7275 6e }
- $sequence_6 = { 0000 90 000c00 20b140005f5f }
- $sequence_7 = { 014318 eb5b 33f6 eb01 }
+ $sequence_0 = { d3eb 2bf1 8b0c850c344100 014c822c 40 89856cffffff e9???????? }
+ $sequence_1 = { 898560f3ffff c705????????00000000 ffd7 8d8dccf7ffff 51 }
+ $sequence_2 = { 0301 eb02 33c0 8b4d08 85c9 7406 }
+ $sequence_3 = { 898d74d2ffff 898d78d2ffff 3bd9 7417 3bc1 7513 33c0 }
+ $sequence_4 = { 83ffff 0f8410010000 53 8b1d???????? 6a02 }
+ $sequence_5 = { 8bd6 e8???????? 33c9 3b85a4fdffff 5f }
+ $sequence_6 = { 85c0 0f8499000000 68???????? 8d842424020000 50 ffd6 8b4c2410 }
+ $sequence_7 = { 23fb d3eb 0fbe8a10344100 03f9 }
+ $sequence_8 = { 5e c21000 8bff 55 8bec 8b4d0c }
+ $sequence_9 = { 8b4710 8b4e28 53 52 8b5624 }
condition:
- 7 of them and filesize <1294336
+ 7 of them and filesize <245760
}
-rule MALPEDIA_Win_Zumanek_Auto : FILE
+rule MALPEDIA_Win_Erebus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "87aee693-fd24-5045-ad68-bbf967fca577"
+ id = "3b8e48a2-ab39-5161-a03c-847ada2f2257"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zumanek"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zumanek_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.erebus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.erebus_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "692948458546aa7f1172f720f7a047815fbd39df276c694923c84a71f1135e40"
+ logic_hash = "f6199452e86aabb91b90d01b525d7eacea470d9b218c6e5261dcc5c5c7e57399"
score = 75
quality = 75
tags = "FILE"
@@ -141856,32 +148716,32 @@ rule MALPEDIA_Win_Zumanek_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { fc 81fe382e9330 97 e412 3dd16312c9 103f 0800 }
- $sequence_1 = { 8802 98 811212242434 48 3c91 4a }
- $sequence_2 = { 894612 4d 2454 48 5b 91 }
- $sequence_3 = { 71ef 1a6f35 e30b 5d fc 77f2 f1 }
- $sequence_4 = { 1dba45e22f 91 7c8b e459 0920 122424 }
- $sequence_5 = { 386b95 4c 53 196a17 }
- $sequence_6 = { 4a e8???????? 86b71986f742 06 58 4c 8812 }
- $sequence_7 = { c101f6 53 32b879629b65 76a2 43 fc }
- $sequence_8 = { d9c3 ab 5f c50f 9d 54 f233591b }
- $sequence_9 = { 5a c59cd53a93a658 98 9f f5 6b80e7fa856bb2 55 }
+ $sequence_0 = { 8d4c243c 50 c744245000000000 e8???????? 8d742434 bb01000000 eb53 }
+ $sequence_1 = { ff15???????? 8b4514 8918 8bc7 5f 5b 8be5 }
+ $sequence_2 = { 8d45f0 50 8b8540ffffff 8d8d40ffffff 8b4004 03c8 e8???????? }
+ $sequence_3 = { ff4718 40 ff7718 25ffff0000 50 68???????? 56 }
+ $sequence_4 = { 8d0c2a 894f18 740a 8b4704 034708 3bc8 7506 }
+ $sequence_5 = { 8d4c2418 e8???????? 50 b9???????? c64424302e e8???????? c705????????24215000 }
+ $sequence_6 = { 50 57 53 e8???????? 83c418 8b8c2424020000 64890d00000000 }
+ $sequence_7 = { c74704ffffffff c74710ffffffff c74714ffffffff 8b0f 8b4704 83f9ff 7504 }
+ $sequence_8 = { 8bd0 c645fc1e 8d8d18ffffff e8???????? 8bf0 83c404 81fe???????? }
+ $sequence_9 = { 2b4718 034708 8b5710 0faf570c 3903 89442410 8d442414 }
condition:
- 7 of them and filesize <58867712
+ 7 of them and filesize <2564096
}
-rule MALPEDIA_Win_Bluenoroff_Auto : FILE
+rule MALPEDIA_Win_Xiaoba_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c5a8ede1-c77a-5a4b-899a-3e41c1e4e510"
+ id = "9683766b-1f7a-5c2a-bffb-7de9b80367d1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bluenoroff"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bluenoroff_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xiaoba"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xiaoba_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "65b6fe6298815292c6af264e82e027897f56c9c87e000fed42924fa12c98e75b"
+ logic_hash = "52112f4a96abd368fbd89cb5e047b8d530704099fd198766e1597b7a0bbb2ccf"
score = 75
quality = 75
tags = "FILE"
@@ -141895,32 +148755,32 @@ rule MALPEDIA_Win_Bluenoroff_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83f802 750e 8d95fcfffeff 52 68???????? }
- $sequence_1 = { 8d8df8feffff 51 ff15???????? 0fbe95f8feffff 68???????? }
- $sequence_2 = { 85f6 743a 8d85fcfffeff 50 }
- $sequence_3 = { 894e04 e8???????? 83c40c 5f }
- $sequence_4 = { eb10 85c0 7514 8d85fcfffeff 50 68???????? }
- $sequence_5 = { 83feff 7433 8d4e01 51 6a40 }
- $sequence_6 = { 68ffff0000 50 e8???????? 33c0 }
- $sequence_7 = { 56 6a10 68???????? e8???????? 83c410 813ed0c0b0a0 }
- $sequence_8 = { 33ff 53 ff15???????? 8b450c 85c0 7402 }
- $sequence_9 = { 50 0fb785f4fffeff 51 52 }
+ $sequence_0 = { 58 8945ec e9???????? 8b5dfc 83c320 895dd0 6801030080 }
+ $sequence_1 = { b801000000 c20c00 8b9024010000 8b44240c 8910 b801000000 c20c00 }
+ $sequence_2 = { 8b5c243c 8b7c2464 8b542428 8b442430 03c3 42 89442430 }
+ $sequence_3 = { dc442410 dd5c2410 e9???????? db8740010000 dc6c2418 dd5c2418 e9???????? }
+ $sequence_4 = { 8b8894010000 33d2 85c9 0f95c2 8bc2 c20800 8b90b4010000 }
+ $sequence_5 = { 8d54b500 8b3c02 8d44f500 83c704 57 50 e8???????? }
+ $sequence_6 = { 85c9 7519 8b54240c 33c9 890a 8b8820010000 894a04 }
+ $sequence_7 = { 85c0 be???????? 7505 be???????? e8???????? 8b4008 56 }
+ $sequence_8 = { 8b10 52 e8???????? 83c404 8b4c2474 8901 8d4c2414 }
+ $sequence_9 = { 8903 8965e8 6800000000 6800000000 6800000000 ff75f0 6800000000 }
condition:
- 7 of them and filesize <303104
+ 7 of them and filesize <5177344
}
-rule MALPEDIA_Win_Mortalkombat_Auto : FILE
+rule MALPEDIA_Win_Fakerean_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5bbf17fe-00b4-5a92-b5e3-f942b94b6ce0"
+ id = "a7ea6f88-76f7-54f5-a9b5-14fd4ef8d3d9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mortalkombat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mortalkombat_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fakerean"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fakerean_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "7d4e235b241a7bc491c490ef8ff26987513d97053d43652b54aa2deceb4dd9ea"
+ logic_hash = "7dfee10ceca58c69279376a54d184530389bbd0c9b8b6dd9a398c5796de2f6f3"
score = 75
quality = 75
tags = "FILE"
@@ -141934,32 +148794,32 @@ rule MALPEDIA_Win_Mortalkombat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33d2 ad 3382b96d4000 ab 83c204 }
- $sequence_1 = { 6a00 6803800000 ff75fc e8???????? 83f800 7e35 6a00 }
- $sequence_2 = { 2bc1 81ebb979379e 8bc8 c1e104 }
- $sequence_3 = { 83f8ff 7402 eb67 6a00 6a00 6a02 }
- $sequence_4 = { e8???????? 50 ff75ac e8???????? 8945a4 33c0 50 }
- $sequence_5 = { 803d????????01 7519 68???????? 68???????? 68???????? }
- $sequence_6 = { c705????????f4010000 68???????? e8???????? a3???????? a0???????? }
- $sequence_7 = { ff7514 6a01 6a00 ff7510 ff75f8 }
- $sequence_8 = { 68???????? e8???????? 83c710 6a10 }
- $sequence_9 = { 50 e8???????? ebd8 8b45bc }
+ $sequence_0 = { 752e 8945fc eb29 395dfc 7524 57 8bce }
+ $sequence_1 = { 49 6a01 ff750c 50 57 ff7514 40 }
+ $sequence_2 = { ff15???????? 3d14050000 74e5 ff7508 56 57 ff15???????? }
+ $sequence_3 = { ff7508 ff15???????? 3bc3 0f8495000000 8b400c 8b00 }
+ $sequence_4 = { 59 3bc3 7419 8d5010 e8???????? 8945e0 3bc3 }
+ $sequence_5 = { ff35???????? ff15???????? 6800000500 6aec ff35???????? ff15???????? 680000cf06 }
+ $sequence_6 = { 741a 81fe00020000 7d12 56 8bc7 e8???????? }
+ $sequence_7 = { 8b4df0 6bc018 6bc918 8b4c190c 2b4c1804 f7df }
+ $sequence_8 = { f7d8 1bc0 25bfe0ffff 05401f0000 50 ff35???????? ff15???????? }
+ $sequence_9 = { 8d45f0 50 8d450c 50 ff15???????? 85c0 7431 }
condition:
- 7 of them and filesize <1224704
+ 7 of them and filesize <4071424
}
-rule MALPEDIA_Win_Xfscashncr_Auto : FILE
+rule MALPEDIA_Win_Smac_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6ee5ebd5-3415-5529-b820-2ef4f50b7f37"
+ id = "b9e948cf-fc1c-55b5-a40e-593d0b67f4eb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xfscashncr"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xfscashncr_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.smac"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.smac_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "9081cad85dadcbc9b76a9d19d302868541784728cc3671f5b0e80a45a72963e6"
+ logic_hash = "69ecbaffb88ef2eb7b0bb4fc54b666c372bcfee7df6d63633067f160f5f10295"
score = 75
quality = 75
tags = "FILE"
@@ -141973,32 +148833,32 @@ rule MALPEDIA_Win_Xfscashncr_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb6c8 85c9 744e 8b4d10 e8???????? 0fb730 8b8d54ffffff }
- $sequence_1 = { 50 8b4de8 8b5110 52 6a00 682d010000 8b45e8 }
- $sequence_2 = { 898518feffff 8b8d18feffff 898d14feffff c745fc00000000 8b9514feffff 52 e8???????? }
- $sequence_3 = { 686b070000 68???????? 8b4508 50 e8???????? 83c40c 8b4508 }
- $sequence_4 = { 8b4de4 66891401 0fb755f4 81fa00800000 7f27 0fb745f4 3d00800000 }
- $sequence_5 = { 83c418 8b08 8b5004 894d10 895514 c78564ffffff00000000 eb35 }
- $sequence_6 = { e8???????? 0fb6d0 85d2 7557 837de802 750f 8b4520 }
- $sequence_7 = { 837d0800 744a b801000000 85c0 7441 8b4508 83c008 }
- $sequence_8 = { 8b4d08 d9ee d95c81fc 8b55f0 8b4508 d90490 d9ee }
- $sequence_9 = { 8b5508 83e21f c1e206 8b048dc0195700 0fbe4c1004 81e17fffffff 8b5508 }
+ $sequence_0 = { 66898548ffffff 8bc3 6689854affffff 58 6a74 6689854cffffff 58 }
+ $sequence_1 = { 39bd78feffff 0f86b8000000 ffb578feffff e8???????? ffb578feffff 8bf0 57 }
+ $sequence_2 = { 668945ec 668975ea 8d8598feffff 8bf4 89a578feffff 50 }
+ $sequence_3 = { 8d9d44ffffff e8???????? 6a01 33ff 8bf3 e8???????? 8b1d???????? }
+ $sequence_4 = { e8???????? 83ec1c c68424900100000e 8d842484000000 8bf4 8964245c }
+ $sequence_5 = { 8945f0 3bc3 7514 6a01 33ff 8d7508 e8???????? }
+ $sequence_6 = { 83c42c 33f6 46 5b ffb5f480ffff ff15???????? }
+ $sequence_7 = { 8986d8000000 ffd7 8986dc000000 8bc6 e8???????? c20800 6a00 }
+ $sequence_8 = { 8bf4 89a578feffff 50 e8???????? 83ec1c c645fc04 8d4528 }
+ $sequence_9 = { 66899d42ffffff 5b 6a74 66899d44ffffff 5b }
condition:
- 7 of them and filesize <3126272
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Oddjob_Auto : FILE
+rule MALPEDIA_Win_Pslogger_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "05ff5b48-0b07-5c37-b3fa-78979fc46d1b"
+ id = "15c6e79e-2171-5604-b7eb-21f0a1c9eae7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.oddjob"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.oddjob_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pslogger"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pslogger_auto.yar#L1-L171"
license_url = "N/A"
- logic_hash = "cba635f9b22031c02deb6504fbb70476906689529cb50c775ead5481738df2df"
+ logic_hash = "8992cc308f36218b8fec7cd3351151cd41f7bbe9e5dc91614732d13ffd45e45b"
score = 75
quality = 75
tags = "FILE"
@@ -142012,32 +148872,38 @@ rule MALPEDIA_Win_Oddjob_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 59 8d9530ffffff 6a01 8bcb 8bc2 }
- $sequence_1 = { c68552fbffff43 c68553fbffff5e c68554fbffff5b c68555fbffff8b c68556fbffff4b }
- $sequence_2 = { 663d3600 751f 66837f0234 7518 }
- $sequence_3 = { 50 bf???????? 57 6a04 53 68???????? ffd6 }
- $sequence_4 = { 8bc3 4b 85c0 0f8498000000 0fb7c1 83f841 7c05 }
- $sequence_5 = { c68596faffff24 c68597faffff08 c68598faffff8b c68599faffff43 }
- $sequence_6 = { c685f8f9ffff40 c685f9f9ffff68 889dfaf9ffff c685fbf9ffff10 889dfcf9ffff 889dfdf9ffff c685fef9ffff51 }
- $sequence_7 = { 889d12f8ffff 889d13f8ffff 889d14f8ffff 889d15f8ffff 889d16f8ffff 889d17f8ffff 889d18f8ffff }
- $sequence_8 = { 85c0 7503 897dfc 397de8 7409 ff75e8 ff15???????? }
- $sequence_9 = { 53 68???????? ffd6 85c0 741c 8d85a094ffff }
+ $sequence_0 = { 7463 488bc8 e8???????? 8bc8 e8???????? 85c0 }
+ $sequence_1 = { 488d8c2480030000 e8???????? 488d542420 488bcd }
+ $sequence_2 = { e8???????? e9???????? 4c8bc5 33d2 488bc8 }
+ $sequence_3 = { b9b80b0000 e8???????? 33d2 41b8b80b0000 488bc8 4c8be0 e8???????? }
+ $sequence_4 = { 57 4883ec20 488b19 488bf9 483b5908 7418 }
+ $sequence_5 = { 483bc8 740e 4885c9 7406 ff15???????? }
+ $sequence_6 = { e9???????? 8d4601 4863e8 488bcd }
+ $sequence_7 = { e8???????? b9b80b0000 e8???????? 33d2 }
+ $sequence_8 = { 85c0 0f844c030000 83f826 7603 6a26 58 0fb60c85d64b4200 }
+ $sequence_9 = { 6a00 53 e8???????? ffb5e0feffff 56 ffb5e4feffff 68???????? }
+ $sequence_10 = { 8b7c2410 2bd6 83c7fe 668b4702 }
+ $sequence_11 = { 7504 8816 eb3e c6060d 8b048d88b14200 8854382a }
+ $sequence_12 = { c1fa06 6bc830 8b049588b14200 8a440828 a848 7404 33c0 }
+ $sequence_13 = { 894606 8d4594 50 8d4676 }
+ $sequence_14 = { 6bf830 894df8 6a0a 8b048d88b14200 5b 8b543818 8955ec }
+ $sequence_15 = { 8b049d88b14200 8945d8 85c0 7553 e8???????? 89049d88b14200 }
condition:
- 7 of them and filesize <221184
+ 7 of them and filesize <475136
}
-rule MALPEDIA_Win_Kasperagent_Auto : FILE
+rule MALPEDIA_Win_Chthonic_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "31bd379d-36ff-5056-a7b4-5cc60c9344f8"
+ id = "a742c49c-6e3e-5872-bf95-e2e0adb04114"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kasperagent"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kasperagent_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chthonic"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chthonic_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "a97fb5a8dde23a8ff235ddb0c06e57b70ba205db49e4efcaa1ba693facbe4b47"
+ logic_hash = "836fdc80a654c12e0017df0790b315dbe177f1e5fd0fa5cd260efc9eb4af2475"
score = 75
quality = 75
tags = "FILE"
@@ -142051,32 +148917,32 @@ rule MALPEDIA_Win_Kasperagent_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 84c0 741e 8bd6 57 52 e8???????? }
- $sequence_1 = { ffb4b5b4fdffff 8b95ccfdffff 8b8dd8fdffff e8???????? 59 3bc3 }
- $sequence_2 = { 83c404 8bd8 83caff f00fc117 }
- $sequence_3 = { 33c9 894c2430 894c2434 894c2438 894c243c 85c0 7463 }
- $sequence_4 = { 8d742410 8d442408 c7470800000000 894c240c e8???????? 84c0 }
- $sequence_5 = { 7cb4 8b4c2414 8b01 3b70f8 }
- $sequence_6 = { 66390c78 7535 84db 7524 }
- $sequence_7 = { 8b50f4 52 50 e8???????? 5d }
- $sequence_8 = { 7419 8d642400 3bfa 7311 }
- $sequence_9 = { 8d3451 33ff 3bce 7419 8d642400 3bfa }
+ $sequence_0 = { 7459 4f 8bf0 8bcf d3ee 83e601 }
+ $sequence_1 = { 0f845d010000 4f 8bf0 8bcf }
+ $sequence_2 = { 81cf00ffffff 47 8a01 8845ff 8d84bdfcfbffff 8b10 }
+ $sequence_3 = { 80e17f 8808 b001 5b c3 55 }
+ $sequence_4 = { 8b75f8 83fe02 0f850d010000 8b4df0 }
+ $sequence_5 = { 016e04 83c703 013e 8b36 83c410 }
+ $sequence_6 = { 5e 0f94c0 5b c9 c3 8b041a }
+ $sequence_7 = { 53 ff7510 ff7508 e8???????? 85c0 }
+ $sequence_8 = { 80e17f 8808 b001 5b c3 55 8bec }
+ $sequence_9 = { ff751c ff7518 ff7514 53 ff7510 ff7508 e8???????? }
condition:
- 7 of them and filesize <1605632
+ 7 of them and filesize <425984
}
-rule MALPEDIA_Win_Newpass_Auto : FILE
+rule MALPEDIA_Win_Himera_Loader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dfd78470-0c07-5107-9bdf-99560c1551b3"
+ id = "e46aed8f-6384-5100-b12a-1e2dd8afe756"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.newpass"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.newpass_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.himera_loader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.himera_loader_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "18487b3a938727b19644b6d1320bc7ccc85217d142f24fc2488ac5f5fe73de66"
+ logic_hash = "ec88d24287290abbd140c4f0211e2582e892064d8e933b967abedc9a00192e9f"
score = 75
quality = 75
tags = "FILE"
@@ -142090,32 +148956,32 @@ rule MALPEDIA_Win_Newpass_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4d8bc4 eb0f 4983c8ff 49ffc0 6642833c4700 75f5 488bd7 }
- $sequence_1 = { 488d542470 48837d8810 480f43542470 488b5910 4883791810 7203 }
- $sequence_2 = { 85c0 792e 488b842490000000 4889442428 4c8bce 440fb6c7 488d542470 }
- $sequence_3 = { eb09 418bc7 493bf6 0f95c0 85c0 7906 488b7f10 }
- $sequence_4 = { 7503 488b07 483bc8 741b 448bc2 488bd0 e8???????? }
- $sequence_5 = { c7411006160000 8b4110 0f49c2 488939 894110 b001 }
- $sequence_6 = { 488bcb e8???????? 84c0 753d 488bcb e8???????? 3a4500 }
- $sequence_7 = { 4c0f44ca 41397920 7340 498b4110 488bd3 498bca }
- $sequence_8 = { 7410 4c8bce 488bc8 e8???????? 488bd8 eb03 498bdd }
- $sequence_9 = { 807a1900 7525 488bc2 488b12 807a1900 7539 6666660f1f840000000000 }
+ $sequence_0 = { e8???????? 83c408 8b4dfc 6689411e 6a10 }
+ $sequence_1 = { 64a300000000 894de0 c745dc0c000000 c645e45e c645e55d }
+ $sequence_2 = { 8b4d08 0fb71401 52 e8???????? 83c408 8b4dfc 66894130 }
+ $sequence_3 = { 8d85dcfdffff 50 8d8df8feffff 51 8d95f8feffff 52 8d8deffdffff }
+ $sequence_4 = { c20400 e8???????? 85c0 0f84c1510000 }
+ $sequence_5 = { c645eb1c c645ec2e 64a12c000000 8b08 8b15???????? 3b9104000000 7e4c }
+ $sequence_6 = { 50 8d45f4 64a300000000 894de0 c745dc0a000000 c645e440 c645e55a }
+ $sequence_7 = { c7459c49000000 c645a463 c645a541 c645a654 c645a747 c645a842 c645a942 }
+ $sequence_8 = { c645e801 c645e90e c645ea18 c645eb1a c645ec00 c645ed1e c645ee2e }
+ $sequence_9 = { c745fc00000000 eb09 8b45fc 83c001 8945fc 837dfc25 7321 }
condition:
- 7 of them and filesize <2654208
+ 7 of them and filesize <385024
}
-rule MALPEDIA_Win_Atharvan_Auto : FILE
+rule MALPEDIA_Win_Scarecrow_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "90143155-ec04-5a1a-8f1d-cad8e690d20c"
+ id = "906ba1cc-dc26-55b9-8f54-7f06e242df8d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atharvan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atharvan_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scarecrow"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.scarecrow_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "4ab12aee6394d0021e81333c85382f01af297ccebc032a8d7f39b0ec61d7b92e"
+ logic_hash = "b5b9eded36bc33c6ab271290937feb85fda4ad16d7bb5dd0760ea465825b259d"
score = 75
quality = 75
tags = "FILE"
@@ -142129,32 +148995,32 @@ rule MALPEDIA_Win_Atharvan_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4c8d05ee7a0000 488b9540070000 488bce e8???????? 85c0 750b eb9e }
- $sequence_1 = { 423a9401d4ab0100 7566 488b03 48ffc1 8a10 48ffc0 488903 }
- $sequence_2 = { 498784f6105c0200 4885c0 7409 488bcb ff15???????? 4885db }
- $sequence_3 = { 8d0480 03c0 442be8 0f84cffbffff 418d45ff 8b848228aa0100 }
- $sequence_4 = { 750d 4c8bc6 e8???????? e9???????? 4c8bce 4c8d05e1dd0100 }
- $sequence_5 = { 498bcf ff15???????? 498bcf ff15???????? 488b4c2440 4833cc e8???????? }
- $sequence_6 = { b903000000 4c8d0564a10000 488d1565a10000 e8???????? }
- $sequence_7 = { 498bcf ff15???????? 488bd8 eb02 33db 4c8d3d028cffff 4885db }
- $sequence_8 = { 7528 48833d????????00 741e 488d0d943e0100 e8???????? 85c0 }
- $sequence_9 = { 83f801 751f 488b0d???????? 488d1d356c0100 483bcb 740c }
+ $sequence_0 = { f7f9 85d2 743b 8b45f4 8d4f17 83c00b 99 }
+ $sequence_1 = { 74d9 eb57 99 f7ff 85d2 7450 8b4c2410 }
+ $sequence_2 = { c68574faffff00 c68575faffff4b c68576faffff40 c68577faffff0a c68578faffff40 c68579faffff6e c6857afaffff40 }
+ $sequence_3 = { c6855bfcffff05 c6855cfcffff20 c6855dfcffff08 c6855efcffff20 c6855ffcffff27 c68560fcffff20 }
+ $sequence_4 = { 7905 48 83c8fc 40 744a 8b4df4 8d4303 }
+ $sequence_5 = { 99 f7ff 85d2 752c 0f1f4000 8b859cf7ffff 99 }
+ $sequence_6 = { 0f84f7040000 8d4f03 c745f005000000 660f1f840000000000 c745f405f26700 8b45f4 99 }
+ $sequence_7 = { c645aa00 c645ab6b c645ac00 c645ad48 c645ae00 c645af00 c645b000 }
+ $sequence_8 = { c644246205 c644246347 c644246405 c64424655a c644246605 c644246727 c644246805 }
+ $sequence_9 = { 660f28b870024300 660f54f0 660f5cc6 660f59f4 660f5cf2 f20f58fe 660f59c4 }
condition:
- 7 of them and filesize <348160
+ 7 of them and filesize <501760
}
-rule MALPEDIA_Win_Dinodas_Rat_Auto : FILE
+rule MALPEDIA_Win_Opachki_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0c2a0c7f-3a72-55a1-acff-1cca63da0ecc"
+ id = "19945598-3be8-57e4-97f5-8518d611bbed"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dinodas_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dinodas_rat_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.opachki"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.opachki_auto.yar#L1-L168"
license_url = "N/A"
- logic_hash = "146f67c88b1bd9a83aac7a1be7e8f308bd7d506106d4fba538a0dc2d1ddf0d08"
+ logic_hash = "5313082ce77d197fd4bac8aec4c18a74cf4695d26acd8d2a84b13e24f5666e1a"
score = 75
quality = 75
tags = "FILE"
@@ -142168,32 +149034,38 @@ rule MALPEDIA_Win_Dinodas_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c9 743b 8b10 8b04b2 8b400c 85c0 7409 }
- $sequence_1 = { 6a18 c705????????acff4300 c705????????00000000 e8???????? 83c404 85c0 }
- $sequence_2 = { 50 51 ffd3 83bdb85fffff00 75af 837e2c00 }
- $sequence_3 = { 833c0e00 755b 8b5dd4 8b4304 80781500 8bd3 7522 }
- $sequence_4 = { df6df8 df6de0 def9 dc0d???????? dd45d8 d8d9 dfe0 }
- $sequence_5 = { 83bdd4c3ffff10 7306 8d85c0c3ffff 56 50 57 e8???????? }
- $sequence_6 = { 8344241408 894c2420 83e908 89542434 8b542430 33db 8bf7 }
- $sequence_7 = { 8b55d0 8b45cc 8b4dec 2bd0 41 c1fa02 894dec }
- $sequence_8 = { e8???????? 8b8d6cffffff 8bb568ffffff 2bce b893244992 f7e9 03d1 }
- $sequence_9 = { 7546 8b15???????? 6aff 52 ffd7 8d5d08 8d45f8 }
+ $sequence_0 = { c3 55 8bec 81ec00010000 ff7508 }
+ $sequence_1 = { 83c40c 8b4f04 8d0433 894708 c6040800 }
+ $sequence_2 = { 83c8ff 5f 5b 5e c9 c20800 8bc3 }
+ $sequence_3 = { 741c 8d4dd4 51 8d4df4 51 8d4dec }
+ $sequence_4 = { 885dfc e8???????? ff75e8 8d45f4 }
+ $sequence_5 = { ff7510 ff75fc ff15???????? 85c0 75e2 }
+ $sequence_6 = { 8b4608 8b4e04 c6040800 5f 8bc6 5e }
+ $sequence_7 = { 8bd8 7413 8b4704 03c8 53 }
+ $sequence_8 = { 8a0f 894508 84c9 744d 8a10 53 56 }
+ $sequence_9 = { c0e805 88470a 3c01 ac 7710 80fff6 7503 }
+ $sequence_10 = { aa 8944241c 61 c3 898389838983 898389838983 }
+ $sequence_11 = { f6c140 7412 08d2 7408 }
+ $sequence_12 = { 884707 83c140 eb0a 3ca0 7206 3ca3 }
+ $sequence_13 = { 7404 3c65 7505 884703 ebcc }
+ $sequence_14 = { f3aa 83ef25 8b742424 ac }
+ $sequence_15 = { 898389838983 898389838585 858585858585 878593859a9a }
condition:
- 7 of them and filesize <638976
+ 7 of them and filesize <122880
}
-rule MALPEDIA_Win_Chewbacca_Auto : FILE
+rule MALPEDIA_Win_Zenar_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "222f6780-8c77-5a93-9b3a-f1a76242c8a5"
+ id = "4a5b8e75-0846-5f97-8625-2c49ccc878e4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chewbacca"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chewbacca_auto.yar#L1-L95"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zenar"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zenar_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "026e724d28dad06de27f1ece049f17b6c66ca8975467e2769de70691ea3bc834"
+ logic_hash = "aaf8e2aaae847a92d9529fc5af1d76e9bd4aae4fdb4d807ed83b4a0145bc159f"
score = 75
quality = 75
tags = "FILE"
@@ -142207,30 +149079,32 @@ rule MALPEDIA_Win_Chewbacca_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? c645f401 8a45f4 5b c9 }
- $sequence_1 = { e8???????? c645c800 8b45cc 8b10 }
- $sequence_2 = { e8???????? c645f000 8b45f4 8b80b4010000 }
- $sequence_3 = { e8???????? c645a400 c645f400 806df401 }
- $sequence_4 = { e8???????? c645d001 8a45d0 5f }
- $sequence_5 = { e8???????? c645ec01 e9???????? 8b55dc }
- $sequence_6 = { e8???????? c645f401 e8???????? 8d4590 e8???????? 58 }
- $sequence_7 = { e8???????? c645a400 6a00 8b45f8 8b00 898554ffffff }
+ $sequence_0 = { 85c0 7409 83c024 50 8b08 ff5108 8b4df4 }
+ $sequence_1 = { 8bf1 8d8e80020000 e8???????? 8d8e68020000 e8???????? 8bce 5e }
+ $sequence_2 = { 8bc7 8bcf 83e03f c1f906 6bf038 03348d98ae4300 }
+ $sequence_3 = { 8d8d70ffffff c645fc03 e8???????? 84c0 7406 8ac3 }
+ $sequence_4 = { 8bfe 83e03f c1ff06 6bd838 8b04bd98ae4300 f644032801 7444 }
+ $sequence_5 = { 55 8bec 0fb701 83ec10 83e811 741a 83e801 }
+ $sequence_6 = { 8d4d0c ff7514 8b7d08 8945f8 897314 }
+ $sequence_7 = { 8b4dfc 0f95c0 890a c9 c20c00 55 8bec }
+ $sequence_8 = { 837d0c04 0f85e3000000 8d4634 50 8d4dc8 e8???????? }
+ $sequence_9 = { eb07 8b4584 8930 33db 8d4dd4 e8???????? }
condition:
- 7 of them and filesize <9764864
+ 7 of them and filesize <519168
}
-rule MALPEDIA_Win_Thanatos_Auto : FILE
+rule MALPEDIA_Win_Shadowhammer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3d56c6ff-7a5f-5548-8f3b-06d8d6158f7b"
+ id = "194406b6-a98b-5404-b2f3-d5df631c65c0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thanatos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.thanatos_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shadowhammer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shadowhammer_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "2cc3d4fef37b3d57358c4e21f8e34a4b374cac5e972e715588051a429530df72"
+ logic_hash = "34aeb940c0c6ad0698f1f0e3ab023525d38575b33eb7ba408d437819a37427e5"
score = 75
quality = 75
tags = "FILE"
@@ -142244,32 +149118,32 @@ rule MALPEDIA_Win_Thanatos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85f6 0f849b010000 ff742428 6a00 68ffff1f00 ff15???????? 8bf8 }
- $sequence_1 = { 50 8bda 8bf1 c78560ffffff94000000 e8???????? 83c40c 8d8560ffffff }
- $sequence_2 = { c64435bc46 8d45bc 50 46 ffd7 3bf0 7ce9 }
- $sequence_3 = { 6a00 6a00 68000000c0 68???????? 46 ffd3 8bf8 }
- $sequence_4 = { 83c40c 807d0800 7459 8b4c240c 897c2422 8d4306 8944241e }
- $sequence_5 = { 807d0800 89442414 b80a000000 7524 3bdf }
- $sequence_6 = { 84c0 75f9 2bd7 5f 7409 51 ff15???????? }
- $sequence_7 = { 57 8bf9 8b4e28 8955fc 83f803 0f85e5020000 8b5d08 }
- $sequence_8 = { 893d???????? c705????????ecb40110 f30f7e05???????? 660fd64008 }
- $sequence_9 = { 50 6a02 ff15???????? 8b7514 c705????????c0b30110 85f6 0f8486010000 }
+ $sequence_0 = { 03d3 03f3 03fb 894dfc 8945f4 }
+ $sequence_1 = { c3 e8???????? c21000 8bff 55 8bec 833d????????01 }
+ $sequence_2 = { 8dbd7dfdffff ab ab ab ab }
+ $sequence_3 = { 58 6a2d 66894584 58 }
+ $sequence_4 = { 685ac1cbc2 56 e8???????? 59 59 85c0 }
+ $sequence_5 = { c78564ffffff103ee0fc c78568ffffffb0cf4161 c7856cffffffb0fafb19 8dbd70ffffff }
+ $sequence_6 = { 8d45e8 50 ff75fc 895de8 8b07 }
+ $sequence_7 = { c78544fdffff6a0ad740 c78548fdffff667aadbd 33c0 8dbd4cfdffff ab 889d50fdffff 8dbd51fdffff }
+ $sequence_8 = { 8dbdfcfdffff ab 889d00feffff 8dbd01feffff ab ab }
+ $sequence_9 = { 8945a8 8d8574ffffff 33ff 8945ac 8d45b8 }
condition:
- 7 of them and filesize <1810432
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Stabuniq_Auto : FILE
+rule MALPEDIA_Win_Industrial_Spy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fc58cf81-e26c-5be2-91a6-3fbb3fc72d52"
+ id = "ce5f3e00-b3d5-5d7c-9715-f009f6dd4df1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stabuniq"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stabuniq_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.industrial_spy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.industrial_spy_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "97aa7344abd98ffc46d944f3c78f102b277bbba8d700aca31756ce2df1f26cfc"
+ logic_hash = "0d309a929b9f93d00c001ba14e0da1de3852467890493f029087eefa2710c99c"
score = 75
quality = 75
tags = "FILE"
@@ -142283,34 +149157,34 @@ rule MALPEDIA_Win_Stabuniq_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 8b4d08 ff91a8000000 6a00 6a00 }
- $sequence_1 = { 8b8df4feffff 51 6aff 8b5508 81c2a2050000 }
- $sequence_2 = { 52 8b4510 ff503c 8b4d10 33d2 668b9106020000 }
- $sequence_3 = { 6a00 8b4d08 8b91f8010000 52 8b4508 ff9018010000 837de4ff }
- $sequence_4 = { 8985c8fbffff 8b4d14 51 6a08 8b550c }
- $sequence_5 = { 8b4df8 8b11 035508 8955f4 eb0c 8b45f8 8b4810 }
- $sequence_6 = { 51 e8???????? 8b5508 83c220 895508 c785bcfcffff00000000 8b4510 }
- $sequence_7 = { 51 8b550c ff524c 8945fc 8b45fc 50 }
- $sequence_8 = { 8d85c0fcffff 50 8b4d0c 51 e8???????? eb16 8b5510 }
- $sequence_9 = { 81c155030000 51 e8???????? 6a00 8b5514 52 8b85e8feffff }
+ $sequence_0 = { f7d1 8d9778a46ad7 23cb 448d8356b7c7e8 418bc3 4123c2 0bc8 }
+ $sequence_1 = { 8bc3 448bcf 410f104f10 4c8d442430 }
+ $sequence_2 = { 48895c2450 48895c2448 4883e804 4889442440 4533c9 4c8d442444 8b542440 }
+ $sequence_3 = { 8b5540 448b4544 4585ed 740f 899380000000 44898384000000 }
+ $sequence_4 = { 4c89742420 498bd4 498bcd c644043000 8d4301 0f11440430 410f104720 }
+ $sequence_5 = { 4881ec100e0000 4533e4 803d????????1f 7472 448925???????? }
+ $sequence_6 = { 837c8dc000 7508 ffca 4883e901 }
+ $sequence_7 = { 0f118424e8010000 f20f108424e0010000 f20f118424f8010000 0f108c24b8010000 0f118c2400020000 f20f108424c8010000 f20f11842410020000 }
+ $sequence_8 = { 4c8d4d50 895c2420 4c8d85a0030000 488d542430 488d4c2430 e8???????? }
+ $sequence_9 = { 0f8df5000000 e8???????? 488b8890000000 48399938010000 7516 488d05cb030100 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <339968
}
-rule MALPEDIA_Win_Suppobox_Auto : FILE
+rule MALPEDIA_Win_Wmighost_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4c561dbc-9b95-52c8-b1b6-738a8e400b62"
+ id = "0b0db58b-a86c-5fcd-a072-2eb1cc17420a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.suppobox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.suppobox_auto.yar#L1-L194"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wmighost"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wmighost_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "33ed4ed4c3c8a05bca33fadb06a60aef627f5ee4031100bb5102db6965fc9d6b"
+ logic_hash = "ca34789fba1f2bd4e0c465ce04013e3b6750b48b70cd8c7936238cd0c587d01a"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -142322,44 +149196,32 @@ rule MALPEDIA_Win_Suppobox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7d10 a1???????? 0b05???????? a3???????? }
- $sequence_1 = { 7f10 a1???????? 2305???????? a3???????? }
- $sequence_2 = { 8945f0 a1???????? 83e801 a3???????? }
- $sequence_3 = { 7e10 a1???????? 0305???????? a3???????? }
- $sequence_4 = { 890d???????? e8???????? 8bf0 e8???????? 03f0 }
- $sequence_5 = { 7d10 a1???????? 3305???????? a3???????? }
- $sequence_6 = { 3bc8 7d10 a1???????? 2b05???????? a3???????? }
- $sequence_7 = { 01bdacf7ffff 83c40c 83bdc8f7ffff00 8b95c8f7ffff }
- $sequence_8 = { 8d45f3 83ec04 890424 e8???????? }
- $sequence_9 = { 8d45f3 890424 e8???????? 52 ebc5 }
- $sequence_10 = { 8d45f4 89442408 e9???????? 8b4508 }
- $sequence_11 = { 01c6 39fe 0f8d7e010000 80bc2ef4f7ffff0a }
- $sequence_12 = { 8d45f2 89f1 89442404 c70424???????? }
- $sequence_13 = { 01d8 3b85b0f7ffff 7e2f 8b95c8f7ffff }
- $sequence_14 = { 8d45f2 89442404 8b4508 890424 e8???????? 83ec08 }
- $sequence_15 = { 8d45ef 89d9 890424 e8???????? 51 }
- $sequence_16 = { 01d7 68???????? 57 e8???????? }
- $sequence_17 = { 01c6 ebdb ff7510 57 }
- $sequence_18 = { 01c9 4a 79f2 833b54 }
- $sequence_19 = { 8d45f4 89442408 c744240401000000 893424 }
- $sequence_20 = { 01c6 39fe 0f8d2f020000 80bc2ef4f7ffff0a }
- $sequence_21 = { 019dacf7ffff 83c40c 299dc4f7ffff e9???????? }
+ $sequence_0 = { 52 e8???????? 83c40c 68e8030000 ff15???????? e9???????? }
+ $sequence_1 = { 83c408 68???????? 8d8df0fcffff 51 }
+ $sequence_2 = { c745fc00000000 8d4d08 e8???????? 50 8b45e8 8b08 }
+ $sequence_3 = { 8945fc 837dfcff 7505 e9???????? 6a02 }
+ $sequence_4 = { 8b550c 52 8d85f0fcffff 50 e8???????? 83c408 }
+ $sequence_5 = { 33c1 8b55f8 8882c8304000 8b45f8 0fbe88c8304000 33d2 8a15???????? }
+ $sequence_6 = { 66ab aa c685f0fcffff00 b940000000 33c0 8dbdf1fcffff }
+ $sequence_7 = { 50 8b4df0 51 e8???????? c745fcffffffff 8d4d08 e8???????? }
+ $sequence_8 = { 8dbdfdfeffff f3ab 66ab aa c685f0fcffff00 b940000000 }
+ $sequence_9 = { 8955e4 8b45ec 50 8b4de4 51 6aff }
condition:
- 7 of them and filesize <1875968
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Godzilla_Loader_Auto : FILE
+rule MALPEDIA_Win_Naikon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0aa53e21-de31-5ee8-9359-dc9a54a6a8e0"
+ id = "2b0fa492-57d4-5b88-95d9-a0b325c3a81c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.godzilla_loader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.godzilla_loader_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.naikon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.naikon_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "2d34f8359c26dd7b822a9bcedc09c50858c69dbe831cef14ec0430298405abb3"
+ logic_hash = "10ad96daf91bea73d71b90a544491c018eb03e29efd792a88809f482c814e2f1"
score = 75
quality = 75
tags = "FILE"
@@ -142373,32 +149235,32 @@ rule MALPEDIA_Win_Godzilla_Loader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 a5 ff512c 85c0 756c }
- $sequence_1 = { a5 50 a5 ff512c 85c0 756c }
- $sequence_2 = { 7406 8b08 50 ff511c }
- $sequence_3 = { a5 ff512c 85c0 756c }
- $sequence_4 = { 6a00 8bf8 8d45fc 50 57 6a01 56 }
- $sequence_5 = { 51 56 57 ff7508 ff15???????? 8bf0 56 }
- $sequence_6 = { 52 50 ff91f0000000 85c0 7813 }
- $sequence_7 = { 6a00 6a00 8bf8 8d45fc 50 57 }
- $sequence_8 = { 57 6a01 56 ff7508 8975fc }
- $sequence_9 = { 8b08 50 ff11 85c0 7527 }
+ $sequence_0 = { 881c08 8d4405c9 50 e8???????? 59 8b4d0c 8901 }
+ $sequence_1 = { 8d85f8feffff 68???????? 50 e8???????? 8b3d???????? 83c418 8d85a8fcffff }
+ $sequence_2 = { ff750c c745f002000000 897dec c745e401000000 57 897de0 ff7508 }
+ $sequence_3 = { 53 50 8d85f4fffdff 56 50 ff35???????? }
+ $sequence_4 = { 83c418 57 50 8d8528ffffff 50 ffb690000000 e8???????? }
+ $sequence_5 = { 6a10 57 681cc10000 897df4 ff750c c745f002000000 }
+ $sequence_6 = { 53 53 8b4010 8d4d0c }
+ $sequence_7 = { e8???????? 83c40c 837df400 7408 ff75f4 e8???????? }
+ $sequence_8 = { 83c41c 33c0 808405dcf9fffffb 40 }
+ $sequence_9 = { 6a01 ff35???????? ff15???????? 8bd8 8b4508 46 6a00 }
condition:
- 7 of them and filesize <155648
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Ahtapot_Auto : FILE
+rule MALPEDIA_Win_Fengine_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b3228dcd-5cf8-5afe-a611-92ad75d7ce7a"
+ id = "c3f38b1d-0317-5325-80d6-6bc13a77b878"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ahtapot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ahtapot_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fengine"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fengine_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "69c00171f493e14b569002ab8197f5ff4c272ce4e4b6b3103d5b52b14a5be8a4"
+ logic_hash = "04b59b3b4a1631576dab348f5698f6f17211f788439d858316727821c2f4b921"
score = 75
quality = 75
tags = "FILE"
@@ -142412,32 +149274,32 @@ rule MALPEDIA_Win_Ahtapot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 80e17f 3008 8b06 8bc8 c1f905 8b0c8dc0f24200 83e01f }
- $sequence_1 = { c686c312000001 e9???????? 6a00 6a00 56 68???????? 6a00 }
- $sequence_2 = { 740b 8d85f0fdffff e8???????? 56 8d95f0fdffff 68???????? 52 }
- $sequence_3 = { 8d95f0fdffff 52 ff15???????? 83f8ff 0f8585000000 8d837c060000 50 }
- $sequence_4 = { 8d8e6c020000 51 8d95acf1ffff 68???????? }
- $sequence_5 = { 8d3c85c0f24200 8bf3 83e61f c1e606 8b07 0fbe440604 83e001 }
- $sequence_6 = { 8b958cf3ffff 8b8578f3ffff 8d8da8f3ffff 51 52 68???????? }
- $sequence_7 = { 8b5df0 8bf0 8b45ec 8d140b 52 50 56 }
- $sequence_8 = { 83c404 8b1d???????? 8d95bcf9ffff 52 ffd3 8b859cf1ffff }
- $sequence_9 = { e8???????? 68???????? 8d55ec 52 8975f8 897dfc c745ec20a04200 }
+ $sequence_0 = { 72e2 8b5c2414 8d842490000000 50 }
+ $sequence_1 = { 833cfd4010410000 755b 6a18 e8???????? 59 }
+ $sequence_2 = { 50 ff15???????? 68???????? 8d85fcf7ffff 6800080000 }
+ $sequence_3 = { 7405 352083b8ed 46 3bf7 0f825fffffff 5f }
+ $sequence_4 = { c1e81e 83e001 83e101 8d0c48 8bc6 }
+ $sequence_5 = { 53 8d4e04 6800080000 51 }
+ $sequence_6 = { 56 e8???????? 8b8de4feffff 8b95e0feffff 8b413c 03c6 8bb5dcfeffff }
+ $sequence_7 = { 83c408 85c0 750f c705????????03000000 e9???????? ffb5bcfaffff }
+ $sequence_8 = { eb23 8b9d2ce5ffff 8a02 8b0c9d60514100 }
+ $sequence_9 = { 83e31f c1e306 8b048560514100 0fbe441804 83e001 }
condition:
- 7 of them and filesize <430080
+ 7 of them and filesize <210944
}
-rule MALPEDIA_Win_Grateful_Pos_Auto : FILE
+rule MALPEDIA_Win_Medusalocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "142dbaaf-bae9-512b-8e1e-de26b0ad1d45"
+ id = "ffdd3261-a5ad-520b-a2bf-3c67ba3f2e25"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grateful_pos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grateful_pos_auto.yar#L1-L169"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.medusalocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.medusalocker_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "bd00e16b742e3f98f3581779e2ac022b9c7b51a75c5cf9f592cacfe60dca60a5"
+ logic_hash = "1d388adf94671d416a3d4bdcd878fd62d77b06e7650d468b56f2c1b04655aed4"
score = 75
quality = 75
tags = "FILE"
@@ -142451,40 +149313,34 @@ rule MALPEDIA_Win_Grateful_Pos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb07 b8fcffffff eb02 33c0 }
- $sequence_1 = { 7407 b8f6ffffff eb02 33c0 }
- $sequence_2 = { e8???????? 99 b980ee3600 f7f9 }
- $sequence_3 = { 7411 e8???????? e8???????? 33c0 e9???????? }
- $sequence_4 = { e8???????? 83f801 7510 e8???????? e8???????? }
- $sequence_5 = { eb1a b8fdffffff eb13 b8fcffffff }
- $sequence_6 = { 8bb5f4fffdff 03b5f8fffdff c1ee03 8b4508 8b7810 }
- $sequence_7 = { 6810040000 ff15???????? 8985f4fbffff 83bdf4fbffff00 0f8488010000 8a0d???????? }
- $sequence_8 = { 83fa7b 750a 6a01 e8???????? }
- $sequence_9 = { 8b4dfc 894110 8b550c 8b420c c1e803 50 }
- $sequence_10 = { c745fcffffffff 8d45f4 64a300000000 c3 6a03 e8???????? 59 }
- $sequence_11 = { 7c62 8b8df8fffdff 0fb6940dfefffdff 83fa3a 7d4f 8b85f8fffdff }
- $sequence_12 = { 6bc02a 05???????? 50 e8???????? 83c40c 85c0 7509 }
- $sequence_13 = { 85c0 0f84b2000000 6a03 68???????? 8b8de0fbffff 83e90e }
- $sequence_14 = { 8884248e010000 b801000000 486bc03f 488d0d79e50100 0fbe0401 83f04d 8884248f010000 }
- $sequence_15 = { 488bcd 418bd7 e8???????? 33c9 85c0 0f85bb010000 4c8d35ee481900 }
+ $sequence_0 = { e8???????? 8945e8 eb07 c745e800000000 8b4de8 894de4 c645fc02 }
+ $sequence_1 = { 8b4dd4 e8???????? 83c048 50 8d55d8 }
+ $sequence_2 = { e8???????? 33c0 8845bb c745c488020000 6888020000 e8???????? 83c404 }
+ $sequence_3 = { 83c404 8b08 51 e8???????? 83c410 }
+ $sequence_4 = { 8845d7 8b4d08 e8???????? 0fb6c8 85c9 0f85f6000000 8b5508 }
+ $sequence_5 = { 8d45e8 50 8b4d0c 51 e8???????? 83c404 50 }
+ $sequence_6 = { 33c0 8945e8 668945ec b902000000 6bd100 668b450c }
+ $sequence_7 = { 894508 8b4d08 3b4d0c 7427 8b5508 }
+ $sequence_8 = { 8965d8 8b45e4 83c00c 50 e8???????? e8???????? 8b4de4 }
+ $sequence_9 = { 8b55e0 52 6a01 8b4df0 e8???????? c645fc03 8d8d38ffffff }
condition:
- 7 of them and filesize <3964928
+ 7 of them and filesize <1433600
}
-rule MALPEDIA_Win_Unidentified_001_Auto : FILE
+rule MALPEDIA_Win_Zeus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7c85316d-7785-5af3-87a9-b2590753f62d"
+ id = "7fc58452-b8ed-5f5d-9c4b-1944a46dd13e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_001"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_001_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeus_auto.yar#L1-L231"
license_url = "N/A"
- logic_hash = "4757a1bf889ab5e180c54dba6f09c40c0355df630267d0efd95e630d6757bdc3"
+ logic_hash = "9dc359b19db229cc8d91a3a8afe15f58c5fe776d823ff66891a661f0a8422765"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -142496,34 +149352,48 @@ rule MALPEDIA_Win_Unidentified_001_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6830750000 ffd6 8b4df8 85c9 7483 8d45fc }
- $sequence_1 = { fec1 88143e 3a4801 72e6 5f 5e 5d }
- $sequence_2 = { 2bc6 0f8421fdffff 2df2020000 0f8478fbffff 2d13030000 }
- $sequence_3 = { b952555300 3bc1 7767 74d3 }
- $sequence_4 = { 8bf1 8b06 57 56 ff5048 8bf8 85ff }
- $sequence_5 = { ff15???????? 50 ff15???????? 8bf0 8975f8 3bf3 }
- $sequence_6 = { 893d???????? e9???????? c705????????10000000 e9???????? 2d46494e00 7461 48 }
- $sequence_7 = { 6a04 68???????? 6a07 6800080000 }
- $sequence_8 = { 8935???????? 8d45cc 50 57 }
- $sequence_9 = { 50 ff5108 8b45e4 3bc3 5b 7406 }
+ $sequence_0 = { eb58 833f00 7651 8b5f08 }
+ $sequence_1 = { 8b3a 3b7d08 740a 40 }
+ $sequence_2 = { 8d443604 50 a1???????? 57 }
+ $sequence_3 = { 8d442440 50 8d442428 50 0fb64304 }
+ $sequence_4 = { 8d442448 50 ff15???????? 0fb744244e }
+ $sequence_5 = { 8d4c3110 81f90000a000 7715 8918 c7400400000200 89780c }
+ $sequence_6 = { 8918 c7400400000200 89780c ff4208 890a c645ff01 }
+ $sequence_7 = { 8d442460 50 e8???????? 8b4508 }
+ $sequence_8 = { e8???????? 84c0 7442 6a10 }
+ $sequence_9 = { 891d???????? 891d???????? ffd6 68???????? }
+ $sequence_10 = { 8bf3 6810270000 ff35???????? ff15???????? }
+ $sequence_11 = { 8d8db0fdffff e8???????? 8ad8 84db }
+ $sequence_12 = { 8ac3 5b c20800 55 8bec 83e4f8 }
+ $sequence_13 = { c9 c20400 55 8bec f6451802 }
+ $sequence_14 = { 56 ff15???????? 5e 8ac3 5b c20800 }
+ $sequence_15 = { 84c0 0f84ac000000 b809080002 3945f4 7713 807d0801 0f8598000000 }
+ $sequence_16 = { 0f86e3000000 8b03 3509080002 3d5c5b4550 740b 3d59495351 }
+ $sequence_17 = { c745f809080002 e8???????? 8ad8 f6450c04 7473 }
+ $sequence_18 = { 807b0244 7429 83fe04 0f82ec000000 8b1b 81f309080002 81fb5d515047 }
+ $sequence_19 = { ff35???????? e8???????? 5f 5e 8ac3 }
+ $sequence_20 = { 8d470c 50 c707000e0000 c7470809080002 }
+ $sequence_21 = { b8d5000000 e8???????? 68e6010000 68???????? 6809080002 8bc6 50 }
+ $sequence_22 = { 81fb5d515047 7410 81fb4f4d4156 7408 81fb59495354 7506 b364 }
+ $sequence_23 = { 81fb59495354 7506 b364 6a14 eb18 81fb5a5c4156 740c }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <319488
}
-rule MALPEDIA_Win_Havex_Rat_Auto : FILE
+rule MALPEDIA_Win_Trickbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cb4848d9-dd93-5427-b320-640a482386ab"
+ id = "7ca88b89-dbe0-5ca7-acaa-87de79bf1962"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.havex_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.havex_rat_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.trickbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.trickbot_auto.yar#L1-L637"
license_url = "N/A"
- logic_hash = "fa73eedcf8aaa6cbc56ae3cdeefa1daf5290fc7704b83fa7deffe1125fde8d25"
+ logic_hash = "e3adabeebcd43d3e3c9deb0d5c4eb46cb018beaf463780980939f5dd81bffcd5"
score = 75
- quality = 75
+ quality = 48
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -142535,32 +149405,99 @@ rule MALPEDIA_Win_Havex_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 134304 8937 ebd8 8917 c74704ffffff7f 8bc7 5e }
- $sequence_1 = { 0fb7c0 b9ffff0000 663bc8 7576 834dec04 33f6 3975ec }
- $sequence_2 = { e8???????? 8bcf c745dcac230510 e8???????? e8???????? c20400 6a30 }
- $sequence_3 = { 297d78 c78580000000feffffff 29bd80000000 8d4417ff 660fb67801 66c1e908 66c1e708 }
- $sequence_4 = { 56 8d8550feffff e8???????? ff757c 8d8550feffff ff7574 }
- $sequence_5 = { 8b7d08 59 59 3bc3 7404 8938 eb02 }
- $sequence_6 = { 84c0 0f854bffffff 33f6 e9???????? 8bb5c8fdffff e9???????? 55 }
- $sequence_7 = { 740a 6683f85c 0f858e000000 83c8ff 5f 5e 5b }
- $sequence_8 = { 68???????? 8d4c2414 e8???????? 8d442410 50 8d4c2430 897c2464 }
- $sequence_9 = { 5b c9 c3 55 8bec 8b4614 83ec10 }
+ $sequence_0 = { 83c002 eb0d 2500000080 f7d8 1bc0 83e007 40 }
+ $sequence_1 = { 1bc0 83e020 83c020 eb36 }
+ $sequence_2 = { eb36 2500000080 f7d8 1bc0 83e070 83c010 }
+ $sequence_3 = { f7d8 1bc0 83e002 83c002 eb0d }
+ $sequence_4 = { 83e070 83c010 eb25 a900000040 7411 2500000080 }
+ $sequence_5 = { 7429 a900000040 7411 2500000080 f7d8 1bc0 83e020 }
+ $sequence_6 = { 8b07 a900000020 7429 a900000040 }
+ $sequence_7 = { c705????????fdffffff c705????????feffffff c705????????ffffffff e8???????? }
+ $sequence_8 = { 895df4 895dec 66c745f00005 895dfc }
+ $sequence_9 = { 33ff 57 6880000000 6a02 57 6a01 68000000c0 }
+ $sequence_10 = { 41 83c028 3bce 7ce9 }
+ $sequence_11 = { 488b01 4c8b4120 488b5118 488b4910 }
+ $sequence_12 = { 53 6a03 53 6a01 6800010000 }
+ $sequence_13 = { 4889442428 488b4130 488b4910 4889442420 41ffd2 }
+ $sequence_14 = { 488b01 488b5118 488b4910 ffd0 }
+ $sequence_15 = { 4c8b4928 4c8b4120 488b5118 4889442438 488b4140 }
+ $sequence_16 = { 488b4148 4c8b11 4c8b4928 4c8b4120 }
+ $sequence_17 = { 4889442430 488b4138 4889442428 488b4130 }
+ $sequence_18 = { 488b5118 4889442440 488b4148 4889442438 488b4140 }
+ $sequence_19 = { 4889442438 488b4140 4889442430 488b4138 }
+ $sequence_20 = { 6820bf0200 68905f0100 68905f0100 50 ff15???????? }
+ $sequence_21 = { 2bc2 d1e8 03c2 c1e806 6bc05f }
+ $sequence_22 = { 83780400 7404 8b4008 c3 }
+ $sequence_23 = { 51 68e9fd0000 50 e8???????? }
+ $sequence_24 = { 6a40 6800300000 6a70 6a00 }
+ $sequence_25 = { 833800 751c 83781000 7516 }
+ $sequence_26 = { c3 6a01 ff15???????? 50 }
+ $sequence_27 = { 8b01 59 03d0 52 }
+ $sequence_28 = { 85c0 7f0b e8???????? 8b05???????? }
+ $sequence_29 = { 03d0 52 ebdc 89450c }
+ $sequence_30 = { 8bc1 66ad 85c0 741c }
+ $sequence_31 = { e8???????? 83f801 7411 ba0a000000 }
+ $sequence_32 = { 85c0 741c 3bc1 7213 }
+ $sequence_33 = { 7405 e8???????? ff15???????? 8bc3 }
+ $sequence_34 = { c1e102 2bc1 8b00 894508 }
+ $sequence_35 = { 50 8b450c ff4d0c ba28000000 }
+ $sequence_36 = { 895510 8b4a04 ff5508 8b5510 8b4a0c }
+ $sequence_37 = { 2bc1 8b00 3bc7 72f2 }
+ $sequence_38 = { 8b4a04 ff5508 50 51 }
+ $sequence_39 = { ff4d0c ba28000000 f7e2 8d9500040000 03d0 895510 }
+ $sequence_40 = { 740f 8bc8 e8???????? 8bc3 }
+ $sequence_41 = { 58 41 41 41 41 }
+ $sequence_42 = { 8bcf e8???????? 8bf0 85ed }
+ $sequence_43 = { 85c0 7911 8bc8 e8???????? bb11000000 }
+ $sequence_44 = { e8???????? 85c0 7507 e8???????? eb5b }
+ $sequence_45 = { 89742428 c744242000001f00 ff15???????? 85c0 7911 }
+ $sequence_46 = { 7c22 3c39 7f1e 0fbec0 }
+ $sequence_47 = { 3bd1 0f8293000000 038e8c000000 3bd1 0f8385000000 }
+ $sequence_48 = { ffc1 663938 75f5 6603c9 }
+ $sequence_49 = { ff15???????? 8bf0 c1ee1f 83f601 }
+ $sequence_50 = { 85d2 745b 3bd1 0f8293000000 }
+ $sequence_51 = { 41 50 2bc1 8b00 }
+ $sequence_52 = { 8bc8 33c0 85c9 0f95c0 eb02 }
+ $sequence_53 = { 894504 68f0ff0000 59 8bf7 8bd7 }
+ $sequence_54 = { 8bc7 e8???????? 85c0 0f849f000000 }
+ $sequence_55 = { 8bf7 8bd7 fc 8bc1 }
+ $sequence_56 = { 59 50 e2fd 8bc7 }
+ $sequence_57 = { 8dbf00500310 8bd6 897d08 3bc8 }
+ $sequence_58 = { 6a00 ff15???????? 6a00 6a00 6a00 8d45dc }
+ $sequence_59 = { 8b7d10 2bf9 53 50 }
+ $sequence_60 = { 83c001 8945d4 8b4dfc 51 8b55d4 }
+ $sequence_61 = { 8b4dd0 894dd8 837dd840 760b 8b55d8 }
+ $sequence_62 = { 8d3c0e 2b75f8 33c7 2bd0 ff4dfc 75ba 8b4508 }
+ $sequence_63 = { 42 42 3b5508 7202 8bd6 83c104 }
+ $sequence_64 = { bf31e7bf31 e7bf 31e7 bf31e7bf31 e7bf }
+ $sequence_65 = { 8b01 3302 52 8bd0 51 03cf 51 }
+ $sequence_66 = { 56 57 33f6 bf???????? 833cf594f3000101 }
+ $sequence_67 = { 8945cc ebee 8b45d8 48 50 8b45cc 40 }
+ $sequence_68 = { ff75f8 ff15???????? 8945fc 837dfc00 750d }
+ $sequence_69 = { 6a00 6858020000 ff15???????? 837dfc00 74ce }
+ $sequence_70 = { e8???????? 03c6 50 e8???????? 8b7710 83c40c 2bf3 }
+ $sequence_71 = { 55 8bec 83ec34 c745cc00000000 6a00 685b020000 6a00 }
+ $sequence_72 = { 42 42 8b01 83c202 33c3 890439 }
+ $sequence_73 = { 8945e4 3bc6 7305 8b750c }
+ $sequence_74 = { 9c 000f 9c 000f 9c f7a053f7a053 }
+ $sequence_75 = { 8bec e8???????? 8b4d08 e8???????? 5d c20400 }
+ $sequence_76 = { c705????????ad380001 8935???????? a3???????? ff15???????? a3???????? 83f8ff 0f84c1000000 }
condition:
- 7 of them and filesize <892928
+ 7 of them and filesize <712704
}
-rule MALPEDIA_Win_Nimgrabber_Auto : FILE
+rule MALPEDIA_Win_Polyglotduke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3ff9ecdf-434a-5531-ae47-14063d732bcc"
+ id = "afe4cb05-aa94-5225-84e8-b6489c3e26d1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nimgrabber"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nimgrabber_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.polyglotduke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.polyglotduke_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "d88020b2287429253ba602c12d16ae36bc236c828c7e32d50b3c884fb53a1e20"
+ logic_hash = "37a5b9867f5de08a35688f7a9273792487d4c60d613dec2d499a53b9323d3f00"
score = 75
quality = 75
tags = "FILE"
@@ -142574,32 +149511,32 @@ rule MALPEDIA_Win_Nimgrabber_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f8fa7000000 c7819814000000400000 b800400000 c744240c04000000 c744240800300000 39c7 0f8fd0010000 }
- $sequence_1 = { 8b842490000000 83c004 89442430 0f80de2e0000 8b8424d8000000 8b00 39442430 }
- $sequence_2 = { c705????????b83b4800 c705????????20000000 c705????????02000000 c705????????00254800 668915???????? c605????????01 c705????????00000000 }
- $sequence_3 = { 8d4710 8d5f08 be???????? b90b000000 c743042b000000 c747082b000000 89c7 }
- $sequence_4 = { c1f80c 89442418 89e8 0fb6c0 8d0483 8944241c 8b8084100000 }
- $sequence_5 = { 7f0d b9???????? e8???????? 8b4514 83e801 0f8067160000 894514 }
- $sequence_6 = { c70424???????? 894c2474 89542404 e8???????? 8b4c2474 31c0 894b04 }
- $sequence_7 = { 8b6f04 81fd0000003f 7e28 c704240000003f 89fa 89f1 e8???????? }
- $sequence_8 = { 89f9 e8???????? 8b4c2454 89da e8???????? 8b07 }
- $sequence_9 = { 740a 8b0b 85c9 0f88a6020000 e8???????? 31ed 89442430 }
+ $sequence_0 = { e8???????? 488b5608 448bc7 488bc8 488bd8 e8???????? }
+ $sequence_1 = { 0fb7f9 492bf3 498bcb 33d2 33c0 }
+ $sequence_2 = { 48895c2408 57 4883ec20 488bfa 488bd9 488d0595970000 488981a0000000 }
+ $sequence_3 = { 4c8be8 e8???????? 488d0d88120100 e8???????? 488d4c2430 8bd3 4c8bc0 }
+ $sequence_4 = { 488be8 498bcc e8???????? 488bcf e8???????? }
+ $sequence_5 = { 48894518 e8???????? 488d0dbae30000 48894520 e8???????? 488d0daee30000 }
+ $sequence_6 = { 42392c3e 0f849bfaffff 428b143e 4a8d4c3e04 e8???????? 488d0dec0c0100 ba10000000 }
+ $sequence_7 = { e8???????? b8cdcccccc f7e5 c1ea02 8d0492 2be8 }
+ $sequence_8 = { 99 f77c2428 4863c2 410fb70c46 488b442440 4533f6 66894c4450 }
+ $sequence_9 = { 488bf1 8d4301 ba02000000 498be8 }
condition:
- 7 of them and filesize <1238016
+ 7 of them and filesize <222784
}
-rule MALPEDIA_Win_Hopscotch_Auto : FILE
+rule MALPEDIA_Win_Rombertik_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dd6bd925-f81a-5efa-b164-a58190829fd7"
+ id = "b8dc9071-13ab-5355-92f1-2480db82efe0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hopscotch"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hopscotch_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rombertik"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rombertik_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "1aacad185595691b5a0f903be6e5a023d3d5227283438abf4c811f89adcac931"
+ logic_hash = "c93757fb5684dd7302fa22ed1f1f21c4fae8e9b1525dbcd58ab0d5e9fecbc821"
score = 75
quality = 75
tags = "FILE"
@@ -142613,32 +149550,32 @@ rule MALPEDIA_Win_Hopscotch_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b1d???????? 8d8c24a4010000 6a00 6a00 6a03 6a00 }
- $sequence_1 = { 5b 81c400010000 c3 8b8c2410010000 51 57 }
- $sequence_2 = { ffd7 56 53 8d4c2414 6a08 51 e8???????? }
- $sequence_3 = { ffd7 85c0 753c 8b35???????? ffd6 83f802 742f }
- $sequence_4 = { 7554 33f6 89b5dcfeffff 8b3d???????? 83fe05 7332 }
- $sequence_5 = { 81ec80090000 53 56 57 68???????? e8???????? }
- $sequence_6 = { 68???????? e8???????? 83c408 8d9424a8020000 }
- $sequence_7 = { 56 57 ff15???????? 85c0 7514 8d442414 }
- $sequence_8 = { c7442400ffffffff 50 c7442408ffffffff e8???????? 83c404 8d4c2400 }
- $sequence_9 = { 8b3d???????? 83c408 8d442408 50 ffd7 }
+ $sequence_0 = { 8945f4 3bc1 0f8271ffffff 5f 5e }
+ $sequence_1 = { 8bff 8b4104 85c0 7446 83c0f8 33ff }
+ $sequence_2 = { 8bcf e8???????? 50 8d8dfcfeffff }
+ $sequence_3 = { 47 41 3bfb 72be 8b5df0 }
+ $sequence_4 = { 50 ff15???????? 8bf8 85ff 0f8488000000 }
+ $sequence_5 = { 33db 57 895df8 ff15???????? 85c0 }
+ $sequence_6 = { 8b5d0c 85db 0f84cb000000 837d1400 0f84c1000000 817d18a00f0000 0f87b4000000 }
+ $sequence_7 = { 50 8bc2 50 8d8decfeffff 51 ffd6 }
+ $sequence_8 = { 895dfc 85db 0f84d8000000 85ff }
+ $sequence_9 = { 6a03 6a00 6a02 68000000c0 68???????? ff15???????? 8906 }
condition:
- 7 of them and filesize <1143808
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Doublepulsar_Auto : FILE
+rule MALPEDIA_Win_Covid22_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e4212e3d-0371-55d3-984d-e0909a78bc0f"
+ id = "c5fffc59-fc04-58e5-a2b5-2bc6fea3300e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doublepulsar"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doublepulsar_auto.yar#L1-L175"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.covid22"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.covid22_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "dd8758cb2c036e196362248313c65a128ef51c3148638e90157034cf0392e7be"
+ logic_hash = "905302ef095dc2c070563a8e4e5a8650bbd8c803b32ba6a0b53beb2cdcb2cfaa"
score = 75
quality = 75
tags = "FILE"
@@ -142652,40 +149589,34 @@ rule MALPEDIA_Win_Doublepulsar_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 731b 8a44144d 8d7c244c 8844144c }
- $sequence_1 = { 8d41ff 85c0 7c10 8a1430 80fa5c 7408 }
- $sequence_2 = { 8bc1 8bf7 8bfa 89ac245c020000 c1e902 f3a5 8b542410 }
- $sequence_3 = { 0f8423010000 8b13 68???????? 52 ffd6 83c408 85c0 }
- $sequence_4 = { e8???????? 48 8b4520 48 8b4878 48 }
- $sequence_5 = { 5b 81c4c8040000 c20800 a0???????? }
- $sequence_6 = { 8bc3 5f 5e 5b c3 b8???????? 83f901 }
- $sequence_7 = { 83c410 85c0 740a 68???????? e9???????? 8b442408 53 }
- $sequence_8 = { 53 33c0 56 8b742420 }
- $sequence_9 = { 83c151 57 51 ff5618 85c0 7404 31c0 }
- $sequence_10 = { ffd6 83c408 85c0 0f84990e0000 8b03 68???????? }
- $sequence_11 = { 7414 8b5640 8b4c2414 52 51 }
- $sequence_12 = { 55 e8???????? 8bd8 85db 0f84a0000000 56 }
- $sequence_13 = { 33c0 bade47773f 8d4848 f3aa }
- $sequence_14 = { c1ea18 33c3 8b1c95f0354000 8b56fc 33c3 8b1c8df0414000 }
- $sequence_15 = { 52 ff15???????? 8b4518 83c404 85c0 7517 a1???????? }
+ $sequence_0 = { 8b35???????? 7507 6af6 ffd6 894514 395d18 7507 }
+ $sequence_1 = { 50 8b4508 ff30 ff15???????? 8b45fc c9 }
+ $sequence_2 = { 5a e8???????? ff35???????? 6801000000 e8???????? 21c0 }
+ $sequence_3 = { e8???????? ba???????? 8d0d30b24000 e8???????? ba???????? 8d0d34b24000 e8???????? }
+ $sequence_4 = { 0fb6540c02 83e20f 0fb692e0904000 885005 0fb6540c03 c1ea04 0fb692e0904000 }
+ $sequence_5 = { ff35???????? e8???????? 21c0 0f846f020000 a1???????? }
+ $sequence_6 = { 50 a1???????? 50 50 e8???????? ff05???????? ff35???????? }
+ $sequence_7 = { b801000000 eb02 31c0 21c0 0f8409020000 a1???????? }
+ $sequence_8 = { e8???????? c21000 8b442404 85c0 7413 ff742408 ff30 }
+ $sequence_9 = { 83c404 6801000000 e9???????? 8b15???????? 31c9 e8???????? 750b }
condition:
- 7 of them and filesize <140288
+ 7 of them and filesize <1955840
}
-rule MALPEDIA_Win_Sedreco_Auto : FILE
+rule MALPEDIA_Win_Wpbrutebot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5e87e6b5-1a55-584a-943a-cd1c621a520c"
+ id = "ee6ef210-d105-53c3-a558-0e67b4040536"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sedreco"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sedreco_auto.yar#L1-L450"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wpbrutebot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wpbrutebot_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "480e943eac316911a45e26f995712fa56ee9e542b3cfeab42c526bed2d2dce35"
+ logic_hash = "709c38b5efc64910ec1c02f61c4cfca810d098711a98c2359e209f406eb3230c"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -142697,74 +149628,32 @@ rule MALPEDIA_Win_Sedreco_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 89450c 56 85c0 }
- $sequence_1 = { c645ff30 e8???????? 85c0 7505 }
- $sequence_2 = { 8bec 51 836d0804 53 }
- $sequence_3 = { 836d0804 53 56 8b750c }
- $sequence_4 = { 8b750c 56 e8???????? 6a08 }
- $sequence_5 = { 50 68???????? 6a0d 68???????? }
- $sequence_6 = { 51 6802020000 68???????? 50 }
- $sequence_7 = { 7411 6a04 68???????? 68???????? }
- $sequence_8 = { 7ce0 a1???????? 5e 85c0 }
- $sequence_9 = { ff15???????? 83c604 81fe???????? 7ce0 }
- $sequence_10 = { ffd6 8b0d???????? 898114010000 85c0 }
- $sequence_11 = { ffd6 8b0d???????? 898198000000 85c0 }
- $sequence_12 = { 56 be???????? 8b06 85c0 740f 50 }
- $sequence_13 = { ffd6 8b0d???????? 894160 85c0 }
- $sequence_14 = { ffd6 ffd0 a3???????? 5e 85c0 750a a1???????? }
- $sequence_15 = { 6a01 68???????? ff35???????? ff15???????? ffd0 }
- $sequence_16 = { 488b05???????? ff90e8000000 90 4883c420 }
- $sequence_17 = { 68???????? e8???????? 8b35???????? 83c404 6a00 68???????? 6aff }
- $sequence_18 = { 4889442420 41b906000200 4533c0 488b15???????? 48c7c101000080 488b05???????? ff9038010000 }
- $sequence_19 = { 6800010000 6a00 68???????? e8???????? 6800020000 }
- $sequence_20 = { ffd6 50 68???????? 6aff }
- $sequence_21 = { 488b0d???????? 488b05???????? ff5010 85c0 }
- $sequence_22 = { 50 68???????? 6aff 68???????? 6a00 6a00 ffd6 }
- $sequence_23 = { 4883c428 c3 48890d???????? c3 48895c2410 4889742418 55 }
- $sequence_24 = { 33d2 488d4c2450 488b05???????? ff90d8020000 }
- $sequence_25 = { 4533c9 4533c0 ba000000c0 488b0d???????? 488b05???????? ff5040 }
- $sequence_26 = { 448bc0 ba08000000 488b0d???????? ff15???????? 488905???????? }
- $sequence_27 = { 488b0d???????? 488b05???????? ff5028 48c705????????00000000 }
- $sequence_28 = { ffd6 8b4dfc 5f 5e 33cd b8???????? }
- $sequence_29 = { 7cd5 68???????? e8???????? 8b4dfc 83c404 }
- $sequence_30 = { 53 68???????? ff35???????? ffd6 ffd0 85c0 }
- $sequence_31 = { e8???????? 8b8c2424020000 5b 33cc 33c0 e8???????? }
- $sequence_32 = { 52 50 ff91f0000000 8bf0 }
- $sequence_33 = { a1???????? 33c5 8945fc 6a0a 8d45f4 50 51 }
- $sequence_34 = { 8d55f8 52 50 8b08 ff5124 }
- $sequence_35 = { c20c00 6a02 ff74240c ff74240c e8???????? c20800 ff74240c }
- $sequence_36 = { 57 50 ff512c 8bce }
- $sequence_37 = { ff512c 8bf0 f7de 1bf6 46 }
- $sequence_38 = { 8945fc 8b45f0 8945f4 8b45f4 }
- $sequence_39 = { 50 8b08 ff9180000000 8b06 }
- $sequence_40 = { ff512c 8bce 8bd8 e8???????? 57 }
- $sequence_41 = { 57 c785ecfeffff01000000 c785e8feffffe197af54 0f6e85e8feffff 0f72f002 }
- $sequence_42 = { 83ec24 53 56 57 c745dce197af54 }
- $sequence_43 = { 8d443001 6a00 51 50 }
- $sequence_44 = { 8d7901 8d4c2420 57 ff15???????? 84c0 }
- $sequence_45 = { 6800040000 51 56 8974242c ff15???????? 85c0 0f8484010000 }
- $sequence_46 = { 51 52 ff15???????? 8b442410 8b4e10 }
- $sequence_47 = { a1???????? 8b00 8b4c2420 88440c18 }
- $sequence_48 = { 85db 7548 fec8 53 b9???????? 8842ff }
- $sequence_49 = { e8???????? 8a54240b 83c404 8b4c2430 895c2410 3bcb }
- $sequence_50 = { 52 56 50 ff15???????? 6a01 }
- $sequence_51 = { 8d442428 c684244010000001 8b11 8d4c2418 52 56 }
+ $sequence_0 = { 894f54 897758 89775c e9???????? 85c9 7515 c7475003000000 }
+ $sequence_1 = { f7472c00010000 b35d 7411 8b4730 6a5d 8b4804 8b01 }
+ $sequence_2 = { f6044dc81e5e0002 7410 8bc1 ba01000000 83f020 85d2 0f44c1 }
+ $sequence_3 = { c645fc04 8d8dfcf4ffff e8???????? 68???????? 8bd0 c645fc05 8d8d14f5ffff }
+ $sequence_4 = { ff742420 8b7a08 037c2420 89442448 c744244c01000000 897c2450 8b4a08 }
+ $sequence_5 = { c781f0050000bfe45900 5b 83c408 c3 5f 5e 5d }
+ $sequence_6 = { 7228 8bb504ffffff 8d8504ffffff 50 8bc8 e8???????? 8b8518ffffff }
+ $sequence_7 = { 8b44245c a802 b800000000 0f45d8 895c241c 85f6 7410 }
+ $sequence_8 = { f7e9 d1fa 8bc2 c1e81f 03c2 83f801 762b }
+ $sequence_9 = { ffb7ec0c0000 6a01 53 e8???????? 8be8 83c410 }
condition:
- 7 of them and filesize <1586176
+ 7 of them and filesize <5134336
}
-rule MALPEDIA_Win_Htran_Auto : FILE
+rule MALPEDIA_Win_Bughatch_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "640e7099-e79d-52c5-9d59-7736988066fb"
+ id = "35614cb3-a7b5-53cc-adaa-ae210fa4a880"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.htran"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.htran_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bughatch"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bughatch_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "572147b50538386d2f3141669299b284d93907b072e98ae962e15d37b04a8bad"
+ logic_hash = "5b28b48c5896cf30a835a51ee080a086478b951d2bf5768e0498fb91c61b534d"
score = 75
quality = 75
tags = "FILE"
@@ -142778,32 +149667,32 @@ rule MALPEDIA_Win_Htran_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 8d8434f0a20000 55 50 53 }
- $sequence_1 = { 8bc8 83e103 f3a4 8b4c2462 }
- $sequence_2 = { 83c408 a1???????? 85c0 7405 }
- $sequence_3 = { 50 51 ffd3 85c0 7d28 bf???????? 83c9ff }
- $sequence_4 = { ffd5 8bf8 8b442440 50 ff15???????? 50 53 }
- $sequence_5 = { 8b8424e0420100 33c9 894c2414 53 8b10 }
- $sequence_6 = { 8816 46 eb0f 0fb6d2 f682c1c3400004 }
- $sequence_7 = { 89442410 c705????????03000000 8b442410 8b0d???????? 49 743a }
- $sequence_8 = { c20400 8b542404 8b0d???????? 3915???????? 56 b8???????? }
- $sequence_9 = { 899424e8010000 89b424e8000000 899424e4000000 33c0 8d8c24e8000000 }
+ $sequence_0 = { 51 ff15???????? 68???????? 8d9594f7ffff 52 ff15???????? }
+ $sequence_1 = { 8d8594f7ffff 50 ff15???????? c745d80c000000 c745e001000000 c745dc00000000 8d4d94 }
+ $sequence_2 = { 52 6a00 8b45f8 50 ff15???????? 8945ec 837dec00 }
+ $sequence_3 = { 55 8bec 81ec30010000 c745e000000000 c745e860524000 }
+ $sequence_4 = { 894df4 8d55e4 52 8d4594 50 6a00 6a00 }
+ $sequence_5 = { 8b55ec 52 ff15???????? c745f801000000 8b45fc }
+ $sequence_6 = { 7308 8b45f8 8945f0 eb06 8b4d14 894df0 8b55f0 }
+ $sequence_7 = { ff15???????? 8b4de0 51 ff15???????? 8b45dc }
+ $sequence_8 = { 55 8bec 81ec60030000 837d0800 0f84d2000000 6a44 6a00 }
+ $sequence_9 = { e8???????? 83c40c 85c0 7407 c745fc01000000 8b45f8 50 }
condition:
- 7 of them and filesize <114688
+ 7 of them and filesize <75776
}
-rule MALPEDIA_Win_Roll_Sling_Auto : FILE
+rule MALPEDIA_Win_Lightwork_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2ab89f07-526d-5404-82a8-065dc4627e90"
+ id = "c390e16c-2dcc-559e-9fd3-76f19a07f767"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.roll_sling"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.roll_sling_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lightwork"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lightwork_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "57322c90ec2e7f0f9b25a02d63cfaa81737587c7821fd15face6c16907aace76"
+ logic_hash = "61817aa90179df111fa397aa30e99207b20a485779bb2cd0f0c3ecbb28869217"
score = 75
quality = 75
tags = "FILE"
@@ -142817,32 +149706,32 @@ rule MALPEDIA_Win_Roll_Sling_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c9 ff15???????? 48898424a8000000 4c8bf8 4885c0 7431 ff15???????? }
- $sequence_1 = { 4c8b7dd8 3b5c2440 7306 488b4dd0 ebb9 498bcd }
- $sequence_2 = { b80d000000 41bf0a000000 440f44f8 33db 4c03f7 0f1f4000 66660f1f840000000000 }
- $sequence_3 = { 488b55d0 4883fa10 0f824effffff 48ffc2 488b4db8 488bc1 4881fa00100000 }
- $sequence_4 = { 488905???????? 498bde 4883fa10 480f431d???????? 4803d9 41b823000000 }
- $sequence_5 = { 0f86ec000000 eb0a 48b92700000000000080 e8???????? 4885c0 0f84cc000000 488d7827 }
- $sequence_6 = { e8???????? 41c6042f00 48893e 488bc6 4c8b6c2460 488b7c2458 }
- $sequence_7 = { 41b801010000 e8???????? 418bc6 4d8d4d10 4c8d3d04180100 41be04000000 }
- $sequence_8 = { eb14 4889742420 4c8d4da0 488bd6 }
- $sequence_9 = { 7476 48895c2438 4533c9 4533c0 48897c2420 bad8070000 }
+ $sequence_0 = { 0fb7442462 89442404 8b442464 890424 e8???????? }
+ $sequence_1 = { c3 55 89e5 83ec38 8b4508 83c07c 8945f0 }
+ $sequence_2 = { e8???????? 894508 837d0800 740b 8b4508 890424 }
+ $sequence_3 = { c645f700 807df700 0f85b1feffff 8b45ec 890424 e8???????? 8b45f0 }
+ $sequence_4 = { c9 c3 55 89e5 83ec28 c7042408000000 e8???????? }
+ $sequence_5 = { 8b4014 83c003 8945f4 8b450c }
+ $sequence_6 = { 894508 837d0800 741e 8b4508 890424 e8???????? }
+ $sequence_7 = { 8b45f8 83c002 01d0 0fb600 0fb6c0 c1e010 0145fc }
+ $sequence_8 = { e8???????? 8b4508 c780a401000000000000 90 c9 c3 55 }
+ $sequence_9 = { 894508 837d0800 740b 8b4508 890424 e8???????? 8b4508 }
condition:
- 7 of them and filesize <299008
+ 7 of them and filesize <1132544
}
-rule MALPEDIA_Win_Risepro_Auto : FILE
+rule MALPEDIA_Win_Penco_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "aea6ceb4-8818-596f-b0ea-b016b3dee8c1"
+ id = "0506b7c6-0597-5673-b29d-0e2e4b0bbb8c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.risepro"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.risepro_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.penco"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.penco_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "4bf4a4e2719baa2456fbc7c987c0d3507fd8f7c3c54ce53243c1cdc1f6723c61"
+ logic_hash = "b907c123e9f48e051972fa4ccfde76e3114fafc16984b4ff739806928ca43da4"
score = 75
quality = 75
tags = "FILE"
@@ -142856,32 +149745,32 @@ rule MALPEDIA_Win_Risepro_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb645ff 50 8b4de8 e8???????? 8b4dec 83c901 894dec }
- $sequence_1 = { e8???????? 8945c8 8d4d0c e8???????? 8945cc 8d45d7 50 }
- $sequence_2 = { 8bec 83ec0c 8955f8 894dfc 8b4dfc e8???????? 8bc8 }
- $sequence_3 = { 894214 8b4df8 e8???????? 8945d4 837de010 }
- $sequence_4 = { 8bcc 8965bc 8d552c 52 e8???????? 8945b8 c645fc04 }
- $sequence_5 = { 33c0 8885eafeffff 33c9 888de9feffff }
- $sequence_6 = { 6800000080 680000cf00 68???????? 68???????? 6800020000 ff15???????? 89859cfeffff }
- $sequence_7 = { 6886e4fa74 6829895415 e8???????? 8b4dfc 894108 89510c }
- $sequence_8 = { 33c5 8945ec 56 50 8d45f4 64a300000000 894da8 }
- $sequence_9 = { 85ff 780f 3b3d???????? 7307 }
+ $sequence_0 = { 53 6a01 6800000080 8d9500010000 52 8b1d???????? }
+ $sequence_1 = { 3334bd00d83400 0fb67c2414 3334bd00d43400 8b4c241c 33700c 83c010 8bde }
+ $sequence_2 = { 40 89442418 3b442414 0f82fffeffff eb13 8d042e 68???????? }
+ $sequence_3 = { 741c 68???????? 68ff010f00 56 ff15???????? 56 85c0 }
+ $sequence_4 = { 0fbe80e8983400 83e00f 33f6 eb04 33f6 33c0 }
+ $sequence_5 = { 8d4598 50 6a00 6a00 8d4db8 51 8b55a4 }
+ $sequence_6 = { 33c0 84c9 7428 8d642400 80f930 7c1c 80f939 }
+ $sequence_7 = { 894c2418 8b4c2444 f7f1 33d2 c744242001000000 03442410 89442414 }
+ $sequence_8 = { 7504 8bf0 eb3e 6a0a }
+ $sequence_9 = { 8b349528e83400 8b542428 0fb6f9 3334bd00d83400 8b4c241c c1ea18 33349528ec3400 }
condition:
- 7 of them and filesize <280576
+ 7 of them and filesize <319488
}
-rule MALPEDIA_Win_Adkoob_Auto : FILE
+rule MALPEDIA_Win_Advisorsbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "09ef20a4-923f-52b9-be25-7277d044ed19"
+ id = "4423ed68-193a-5b69-9a0c-e4a68868d775"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.adkoob"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.adkoob_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.advisorsbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.advisorsbot_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "0f163717fb5860f8982d25c9dbbe18c357f664ad9d46a5bfca06cc794c00bf30"
+ logic_hash = "63e408f2b85153604b6cbce7b119689dceb4fed854cd697bc92427d51dad5ae1"
score = 75
quality = 75
tags = "FILE"
@@ -142895,32 +149784,41 @@ rule MALPEDIA_Win_Adkoob_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff706c ffb0b0000000 8bc7 6a14 59 99 f7f9 }
- $sequence_1 = { ff75f0 6a38 5a e8???????? 83c40c 8bce 40 }
- $sequence_2 = { 8d5801 e9???????? 53 8bcf e8???????? 8b5dd8 84c0 }
- $sequence_3 = { 8955f8 8b90d4000000 0fb6443b06 c1e108 0bc8 897de8 2bf1 }
- $sequence_4 = { ff504c 85c0 7536 8b75dc 56 ff15???????? 50 }
- $sequence_5 = { 8b7508 83fe09 7756 80beac1d4c0000 57 8b3d???????? 0f453d???????? }
- $sequence_6 = { ff75e8 ff15???????? 837dd000 8b35???????? 7405 ff75d0 ffd6 }
- $sequence_7 = { ff742418 68???????? e8???????? 83c40c 89442428 85c0 747b }
- $sequence_8 = { ff7510 8bce ffb578ffffff ff75b8 ff7598 ffb564ffffff ff75c4 }
- $sequence_9 = { 8b4744 52 50 8b08 ff5114 59 59 }
+ $sequence_0 = { 8bc1 2bc2 d1e8 03c2 c1e808 }
+ $sequence_1 = { 8bc2 33d2 c1e809 f7f1 }
+ $sequence_2 = { 8bc2 33d2 c1e808 f7f1 }
+ $sequence_3 = { b89b01a311 f7e1 2bca d1e9 03ca }
+ $sequence_4 = { d1e8 03c2 33d2 c1e809 }
+ $sequence_5 = { 8bc2 c1e809 33d2 f7f1 }
+ $sequence_6 = { 8b442408 8b4c2408 33d2 f7f1 }
+ $sequence_7 = { d1e9 03ca 33d2 c1e909 }
+ $sequence_8 = { d1e9 03ca c1e907 2bc1 }
+ $sequence_9 = { b839811338 f7e1 8bc1 2bc2 }
+ $sequence_10 = { d1e9 03ca c1e909 33c8 }
+ $sequence_11 = { 8bc2 33d2 c1e804 f7f1 }
+ $sequence_12 = { 8bca f7e2 8bc1 2bc2 }
+ $sequence_13 = { 668b4c2410 5f 5e 5d }
+ $sequence_14 = { 0fb7c1 0fb7ca 33d2 f7f1 }
+ $sequence_15 = { 0fb7c0 0fb7c9 33d2 f7f1 }
+ $sequence_16 = { 0fb6c0 0fb6c9 33d2 f7f1 }
+ $sequence_17 = { 8b442414 8b4c2414 33d2 f7f1 }
+ $sequence_18 = { 5e 5d 0fb7c2 5b }
condition:
- 7 of them and filesize <1867776
+ 7 of them and filesize <434176
}
-rule MALPEDIA_Win_Pgift_Auto : FILE
+rule MALPEDIA_Win_Woodyrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "77b72e7a-f170-5cb6-9a32-dd868251e29f"
+ id = "ce77dd1e-7a7f-526f-b26a-f53840a84ce1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pgift"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pgift_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.woodyrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.woodyrat_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "5fec76c05b43d836fa9681344d4e2173c2fdd272e3aa573e02794115bc07ca47"
+ logic_hash = "f0e3660df6e09cfccf9351d956d7545670538be69e20bfd57639d1e54207defb"
score = 75
quality = 75
tags = "FILE"
@@ -142934,32 +149832,32 @@ rule MALPEDIA_Win_Pgift_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 ff7508 e8???????? 83450804 83c304 }
- $sequence_1 = { 2bc8 c1f902 7454 50 8d4de8 }
- $sequence_2 = { 50 0fb745d4 50 8d45ec ff760c }
- $sequence_3 = { 8d4df0 c645fc02 e8???????? ff750c }
- $sequence_4 = { 83f8ff 741e 53 50 8d4de8 e8???????? ff75e8 }
- $sequence_5 = { 8d4df0 ff3498 e8???????? 83f8ff }
- $sequence_6 = { 33db 8d4dec 895dfc e8???????? 8d8dd0feffff 895de8 e8???????? }
- $sequence_7 = { c645fc03 897e38 897e34 897e30 e8???????? 3bc7 }
- $sequence_8 = { ff7634 53 50 e8???????? 83c40c 8d4638 }
- $sequence_9 = { 8d4de8 e8???????? 6a5c 8d4de8 c645fc01 }
+ $sequence_0 = { 8b75ec 8985a4ebffff ffb5bcebffff e8???????? 8b7de4 83c404 837de800 }
+ $sequence_1 = { 8d4e4c 54 6a00 e8???????? 8bc8 e8???????? 8d4dd8 }
+ $sequence_2 = { 8d4710 50 8d45cc 50 e8???????? 84c0 7403 }
+ $sequence_3 = { e8???????? c645fc03 8b55cc 83fa10 722c 8b4db8 42 }
+ $sequence_4 = { 8b4328 8bd8 3bfb 742d 8b0f 8b01 ff5008 }
+ $sequence_5 = { 8bc8 83781410 7202 8b08 83781004 753b 8b01 }
+ $sequence_6 = { 83c408 8d4508 6a00 84db 7428 837d1c08 6800000002 }
+ $sequence_7 = { 50 e8???????? 8b7d80 83c404 e9???????? c645fc00 }
+ $sequence_8 = { 7607 be55555515 eb07 03f1 3bf2 0f42f2 }
+ $sequence_9 = { 745d 40 50 e8???????? 8bf0 8b45c8 40 }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <785408
}
-rule MALPEDIA_Win_Tclient_Auto : FILE
+rule MALPEDIA_Win_Rctrl_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f2038e8d-aea1-548a-a845-014bf9e62586"
+ id = "60ae096f-d5f7-57d0-b6f9-cb53f8d1b760"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tclient"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tclient_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rctrl"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rctrl_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "d731098e1e4af77da640d6018efa5a27e1199a8bfd1426735ef45625c1645468"
+ logic_hash = "0c64a52ce76fbe6b25b4079783722f9c8bfa120e4543946e41c97eea8cb03d4d"
score = 75
quality = 75
tags = "FILE"
@@ -142973,32 +149871,32 @@ rule MALPEDIA_Win_Tclient_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8be5 5d c21800 b8???????? e8???????? 83ec70 53 }
- $sequence_1 = { 6685f6 7411 0fb7c2 42 885c0804 0fb7c2 42 }
- $sequence_2 = { e9???????? 6a44 8d442444 53 50 e8???????? 33c0 }
- $sequence_3 = { 50 8d0419 57 50 e8???????? 83c40c b880000000 }
- $sequence_4 = { 894db0 2345a8 33c2 c1c105 034e28 81c29979825a 8b75a8 }
- $sequence_5 = { 8b00 2bc1 8d4a01 3bc1 0f4cc8 894dec 85c9 }
- $sequence_6 = { 59 59 85c0 7443 e9???????? 85f6 741e }
- $sequence_7 = { 57 e8???????? 8b4304 2b4508 50 ff7508 }
- $sequence_8 = { 6bc930 8b0495c0a04700 c644012801 8b0495c0a04700 897c0118 8bfe e9???????? }
- $sequence_9 = { 89bebc010000 8a8398000000 888675030000 0fb68398000000 50 8d4366 50 }
+ $sequence_0 = { e8???????? 85c0 0f8440030000 8b10 8bc8 ff520c 83c010 }
+ $sequence_1 = { 8bf0 56 6a00 6a00 ff15???????? 33c9 894508 }
+ $sequence_2 = { 6a06 e8???????? cc b8???????? c3 55 8bec }
+ $sequence_3 = { 8b473c 8985d4feffff e8???????? 85c0 0f85ef000000 814f2400000400 8b85d8feffff }
+ $sequence_4 = { 33c0 40 8be5 5d c20800 6a14 b8???????? }
+ $sequence_5 = { 898368040000 03c8 83bd7cffffff00 7433 8b855cffffff 8db328040000 03c1 }
+ $sequence_6 = { 75cc 8d4dc8 e8???????? e9???????? e8???????? ffb6f8000000 e8???????? }
+ $sequence_7 = { ff750c 8bd6 e8???????? 8b4518 8d0c3e 8d1400 }
+ $sequence_8 = { 85c0 0f94c0 84c0 7423 6a00 6a00 57 }
+ $sequence_9 = { ff7008 ff75f0 e8???????? 8bf0 eb02 }
condition:
- 7 of them and filesize <1063936
+ 7 of them and filesize <4315136
}
-rule MALPEDIA_Win_Vendetta_Auto : FILE
+rule MALPEDIA_Win_Zupdax_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "966ae160-05eb-53d3-b86d-ed42268f2f0c"
+ id = "0a0ddf15-919a-51b3-8d2b-36d56a66b11c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vendetta"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vendetta_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zupdax"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zupdax_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "4fce9b15fe513b7322e530a7cc2cb9b1afb7d5162c1238338f15db6a45fbd5fd"
+ logic_hash = "b6e9bce8da2b32bfb52c3b6477d889790098710bc4ce9f32e2c7bd1bace10557"
score = 75
quality = 75
tags = "FILE"
@@ -143012,32 +149910,32 @@ rule MALPEDIA_Win_Vendetta_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b04c5e06f4100 5d c3 33c0 5d }
- $sequence_1 = { 83c408 84c0 0f845d010000 6a00 51 0bf9 }
- $sequence_2 = { 660f2815???????? f20f59db 660f282d???????? 660f59f5 660f28aa30914100 }
- $sequence_3 = { 83a500fcffff00 51 8d8df8fbffff e8???????? 898500fcffff }
- $sequence_4 = { 8b4508 dd00 ebc6 c745e0d8924100 e9???????? c745e0e0924100 }
- $sequence_5 = { 6a30 eb27 3bcb 7f0e 7c08 81fa0000800c 7704 }
- $sequence_6 = { 7309 8b04c5e06f4100 5d c3 33c0 5d c3 }
- $sequence_7 = { 85c0 7433 8bce e8???????? 8bf8 }
- $sequence_8 = { 33c9 8bc1 3914c5b89b4100 7408 40 83f81d 7cf1 }
- $sequence_9 = { 53 8d85f0f7ffff 50 56 }
+ $sequence_0 = { 895e2c e8???????? 8b460c 83c404 3bc3 7419 }
+ $sequence_1 = { 8b4c2408 8b7e10 51 e8???????? 8b560c 52 e8???????? }
+ $sequence_2 = { 52 68???????? ff15???????? 8d442444 }
+ $sequence_3 = { e8???????? 83c408 8b4618 50 895e24 895e28 895e2c }
+ $sequence_4 = { 394c2414 765b 53 41 81e1ff000080 }
+ $sequence_5 = { 4b 81cb00ffffff 43 0fb61403 30142f 47 }
+ $sequence_6 = { 895710 8b4614 894e14 8b5718 894714 8b4618 895618 }
+ $sequence_7 = { 2bc2 50 8d54241c 52 }
+ $sequence_8 = { 46 8a1c06 881c01 881406 }
+ $sequence_9 = { 8b4c2408 8b7e10 51 e8???????? }
condition:
- 7 of them and filesize <296960
+ 7 of them and filesize <1032192
}
-rule MALPEDIA_Win_Atomsilo_Auto : FILE
+rule MALPEDIA_Win_Skyplex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5c5abdc6-8981-5d86-b9f4-d4db3c6db3a6"
+ id = "3d9ea458-10c2-53d2-a125-12c3c77bb27b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atomsilo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atomsilo_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.skyplex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.skyplex_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "12073cc9a4e235a243c621f25e39a1bc781a5d45de9a635e40dc44153d51bb08"
+ logic_hash = "d0704b78b2354a7199559252cd2d4f927c47dc758745bd631528996f74a24c6c"
score = 75
quality = 75
tags = "FILE"
@@ -143051,34 +149949,34 @@ rule MALPEDIA_Win_Atomsilo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 90 488d054b810900 488903 488d0571780900 48894308 48c74338ffffffff }
- $sequence_1 = { 4403e8 498b17 48638c24a0000000 4803ca 49890f 483bca 731c }
- $sequence_2 = { 4d8bc4 488bd7 488d8d50010000 e8???????? b930000000 e8???????? 488bd8 }
- $sequence_3 = { 488b7dd0 4885c9 741d 488d51ff 488d14d7 0f1f440000 48833a00 }
- $sequence_4 = { 0409 83f052 8844245d 8b442450 040a 83f045 8844245e }
- $sequence_5 = { 488d05dd6c0700 488907 488bc7 0f104318 488b5c2430 f30f7f4718 4883c420 }
- $sequence_6 = { 4156 4883ec50 488b5830 498bf9 498bf0 4c8bf2 4c8be1 }
- $sequence_7 = { 488d15e7b60500 0fb60c0a c1e103 4863c9 488d1546720900 33440a03 8944243c }
- $sequence_8 = { 0f94c0 480106 ebc0 488b7c2438 4c8b8424f0000000 4c8b9c24c8000000 4c8b9424d0000000 }
- $sequence_9 = { 4883ec28 83792801 8b4228 7423 83f801 740f e8???????? }
+ $sequence_0 = { 6a00 ff15???????? 898508fcffff ff15???????? }
+ $sequence_1 = { c3 8bff 56 57 33ff 8db704984100 ff36 }
+ $sequence_2 = { 59 e9???????? 8b36 8bce c1f905 8b0c8dc0af4100 }
+ $sequence_3 = { 8b7d08 8bc7 c1f805 8d3485c0af4100 8b06 }
+ $sequence_4 = { 50 e8???????? 50 8b4df8 8b11 8b45f8 50 }
+ $sequence_5 = { c785b8f6ffff684c4100 c785bcf6ffffb04c4100 ff15???????? 50 e8???????? 83c404 }
+ $sequence_6 = { 33d2 b9???????? 57 8bc2 c1f805 8b0485c0af4100 8bfa }
+ $sequence_7 = { 83bdf0feffff03 7327 8b85f0feffff 8b0c857c904100 51 }
+ $sequence_8 = { 66898c4558f7ffff 8d9558f7ffff 52 8d8540fbffff 50 }
+ $sequence_9 = { 6a01 ff15???????? c78544f6ffff01000000 eb0f 8b8d44f6ffff 83c101 898d44f6ffff }
condition:
- 7 of them and filesize <1785856
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Bee_Auto : FILE
+rule MALPEDIA_Win_Valley_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cf854a1b-a3fa-5497-9620-9eb04ca1acba"
+ id = "5aadade8-2e86-5c22-9399-653890e95f9a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bee"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bee_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.valley_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.valley_rat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "d1087a1b19c31419362e6bad586912e9950c25554053241c2a8ca3db38a0bc54"
- score = 75
- quality = 75
+ logic_hash = "788630470fd0066c9dad5026f208a936da1b0fab9009cb8b3a3ebf9a9cd14823"
+ score = 60
+ quality = 45
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -143090,32 +149988,32 @@ rule MALPEDIA_Win_Bee_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f8326010000 8bce d1e9 ba49922409 2bd1 3bd6 7304 }
- $sequence_1 = { 83c404 89742418 c644244806 3bf3 741d 8b542414 }
- $sequence_2 = { 668944241c 52 8d44241c 50 8d4c2438 c744242000000000 e8???????? }
- $sequence_3 = { e8???????? 8b542424 56 6a00 52 e8???????? 8b7c2434 }
- $sequence_4 = { 8d8424a4000000 8a10 3a11 751a 3ad3 7412 }
- $sequence_5 = { 8bf9 80bfd800000000 754e 6a11 6a02 6a02 }
- $sequence_6 = { e8???????? 8d0cb6 c1e104 03c8 89470c 894710 }
- $sequence_7 = { 8bc3 8bcf e8???????? 2bf7 b867666666 f7ee }
- $sequence_8 = { e8???????? 83c414 8b45fc ff34c5e4314200 }
- $sequence_9 = { 64a300000000 8b6c2420 33db 895d04 885d0c }
+ $sequence_0 = { 8b4910 e8???????? 2500020000 33d2 0bc2 7506 32c0 }
+ $sequence_1 = { e8???????? 50 8d4708 50 e8???????? 8bbdf0efffff 83c414 }
+ $sequence_2 = { 8bf0 83c404 85f6 742f e8???????? 84c0 ba???????? }
+ $sequence_3 = { 50 e8???????? 8b5654 33c9 8b4508 83c408 894d08 }
+ $sequence_4 = { 8d04dd00000000 50 e8???????? 8bf0 83c404 85f6 7447 }
+ $sequence_5 = { 8bc2 c1e81f 03c2 8d0c40 8b07 8d04c8 894704 }
+ $sequence_6 = { 8b55f4 4f 75ce 8b4df8 8b7d08 8b5510 3bca }
+ $sequence_7 = { 8b36 c6043e00 5f 5e 5d c3 55 }
+ $sequence_8 = { eb64 33c0 668945e4 e8???????? ff75dc 8b7b04 8d45e3 }
+ $sequence_9 = { c745fc00000000 53 8bce e8???????? 8b06 83f801 741e }
condition:
- 7 of them and filesize <394240
+ 7 of them and filesize <2256896
}
-rule MALPEDIA_Win_Merdoor_Auto : FILE
+rule MALPEDIA_Win_Rawpos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a99af5cd-bc04-5bf5-95d0-af03ff89050f"
+ id = "286abeec-e79d-5e9e-ac0c-a8048144fd9d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.merdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.merdoor_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rawpos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rawpos_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "b95cd242972456e72e114f53ab84ee24aaf18f568fbe98e73f19f67ea1e8459f"
+ logic_hash = "aa38577b3237b68cd5a9fc2dd4b4a121098ac6a8fc6a84d75e625596e4cdd326"
score = 75
quality = 75
tags = "FILE"
@@ -143129,34 +150027,34 @@ rule MALPEDIA_Win_Merdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5e 3bc8 7215 50 8d8398000000 50 6aff }
- $sequence_1 = { 8d85f0fdffff 8bcb 50 e8???????? 8b4dfc f7d8 5f }
- $sequence_2 = { 8ac1 eb04 b011 2ac1 f6d0 fec1 }
- $sequence_3 = { 0f87af000000 8d8ee4020000 894df4 7443 8b01 8bf0 8bd0 }
- $sequence_4 = { ffd7 8986c0000000 83bec400000000 750f 8d4588 }
- $sequence_5 = { 3044159c 42 80f90f 72da 660f6f05???????? 32c9 f30f7f853cffffff }
- $sequence_6 = { 85c0 751c 8d85ecfeffff 50 ff15???????? 8b400c 8b00 }
- $sequence_7 = { 85c0 7403 8d3410 8b440b10 85c0 7438 }
- $sequence_8 = { 53 56 8bf1 57 83cfff 8d9eec020000 53 }
- $sequence_9 = { 8986c0000000 83bec400000000 750f 8d4588 50 ff7604 ffd7 }
+ $sequence_0 = { 47 bb01000000 3b5df8 7d17 8b45bc }
+ $sequence_1 = { eb22 8b550c ff02 8b0a 83f963 }
+ $sequence_2 = { 3b7594 7231 8b5520 52 6a00 8b4d18 8bd6 }
+ $sequence_3 = { c700???????? e9???????? bb40000000 ff45e0 e9???????? 33c0 8d55b8 }
+ $sequence_4 = { 7544 56 6a00 8b5518 83c703 52 53 }
+ $sequence_5 = { 83e805 7422 eb3b 8d55b4 8955b0 eb41 8b4db0 }
+ $sequence_6 = { c1e003 33db 8a1a 03c3 83c0d0 8b5dfc ff45fc }
+ $sequence_7 = { 83e201 83c703 8955e4 eb3f 33c9 8a0f }
+ $sequence_8 = { 51 50 ff550c 83c408 ff4df8 f7c601000000 0f855afaffff }
+ $sequence_9 = { 837da4ff 750c 8bc3 43 3b45ec 0f82abfeffff 837de400 }
condition:
- 7 of them and filesize <307200
+ 7 of them and filesize <466944
}
-rule MALPEDIA_Win_Lightbunny_Auto : FILE
+rule MALPEDIA_Win_Konni_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "546c8a57-6f91-59bb-b683-389534c380bb"
+ id = "7138d9e1-4213-5d32-a401-6f7ceedaf286"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lightbunny"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lightbunny_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.konni"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.konni_auto.yar#L1-L461"
license_url = "N/A"
- logic_hash = "4c0608cdc020e5347f646e557ecb414bd8f3027b0aca947da82d4930945e8be1"
+ logic_hash = "81aa3927272d55dae2dfea8fc0fbd2614b2bb50237cc36185301dfe759c8d64e"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -143168,32 +150066,72 @@ rule MALPEDIA_Win_Lightbunny_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6bc930 8b048520ae4100 0fb6440828 83e040 5d }
- $sequence_1 = { 8bc1 83e13f c1f806 6bc930 8b048520ae4100 f644082801 }
- $sequence_2 = { 83c404 6a02 ff35???????? ffd3 }
- $sequence_3 = { 894708 0fb74602 50 ff15???????? }
- $sequence_4 = { ff35???????? ff15???????? c705????????00000000 8b4dfc }
- $sequence_5 = { 51 ff15???????? 85c0 740e 8b400c 8b00 }
- $sequence_6 = { 8d3c9d58ab4100 f00fb10f 8bc8 85c9 740b }
- $sequence_7 = { 83c404 83f801 0f851dffffff 8b5710 33c9 b8???????? 90 }
- $sequence_8 = { 6bc030 c1f906 03048d20ae4100 eb02 8bc6 80782900 7522 }
- $sequence_9 = { 8b75f8 33ff 8b0d???????? 8bc6 8945e4 894de8 }
+ $sequence_0 = { 7908 4e 81ce00ffffff 46 8a9c35f8feffff 8819 889435f8feffff }
+ $sequence_1 = { 8945fc 53 56 57 b910000000 be???????? 8d7db0 }
+ $sequence_2 = { 7527 0fb655eb 0fb645ea 52 }
+ $sequence_3 = { 889435f8feffff 0fb609 0fb6d2 03ca 81e1ff000080 7908 }
+ $sequence_4 = { 0fbef1 d0f9 83e601 884c15f4 8970e8 42 }
+ $sequence_5 = { 49 81c900ffffff 41 8a940df8feffff 8d8c0df8feffff 0fb6da 03f3 }
+ $sequence_6 = { 83e601 897004 d0f9 0fbef1 83e601 8930 }
+ $sequence_7 = { 68b6030000 6a0d 50 ff15???????? }
+ $sequence_8 = { 6a01 ff15???????? 50 a3???????? }
+ $sequence_9 = { 33c9 83f802 7508 890d???????? }
+ $sequence_10 = { eb1e 83f804 740f c705????????02000000 }
+ $sequence_11 = { 740f c705????????02000000 83f801 750a c705????????01000000 890d???????? }
+ $sequence_12 = { 7508 890d???????? eb1e 83f804 }
+ $sequence_13 = { 8916 56 e8???????? 8a8c30dec44600 }
+ $sequence_14 = { e8???????? 83c40c 6804010000 8d8df4fdffff 51 ff15???????? }
+ $sequence_15 = { 83e203 83f908 7229 f3a5 ff2495f0444000 8bc7 }
+ $sequence_16 = { 8d85f8feffff 50 ffd6 68???????? 8d8df0faffff }
+ $sequence_17 = { 4c89742420 ff15???????? 488bd8 4885c0 744f }
+ $sequence_18 = { bbedffffff 03dd 81eb00200200 83bd9404000000 899d94040000 0f85d7030000 }
+ $sequence_19 = { e9???????? 8b35???????? 68???????? 8d85f8feffff }
+ $sequence_20 = { ff95b50f0000 898598040000 8bf0 8d7d51 }
+ $sequence_21 = { 6804010000 8d95f8feffff 52 50 ff15???????? }
+ $sequence_22 = { 50 038594040000 59 0bc9 89851a040000 61 7508 }
+ $sequence_23 = { 8b4e08 33db 56 e8???????? 8a9c30c2c44600 }
+ $sequence_24 = { 8bf0 8d7d51 57 56 ff95b10f0000 ab }
+ $sequence_25 = { 33d2 56 e8???????? 8a9435dec44600 5e 84c0 8bfa }
+ $sequence_26 = { 56 33d2 898ddcfeffff 40 57 }
+ $sequence_27 = { 6808020000 6a00 56 c745fc00010000 e8???????? 83c40c 8d45fc }
+ $sequence_28 = { ebab c745e428614000 817de42c614000 7311 8b45e4 }
+ $sequence_29 = { 6a00 6a00 8d8df8feffff 51 8d95f0fcffff }
+ $sequence_30 = { 68???????? 8d8df0faffff 51 ffd6 8b35???????? }
+ $sequence_31 = { 51 6689442414 e8???????? 6808020000 8d942420020000 6a00 }
+ $sequence_32 = { e8???????? 8a8c30a6c44600 5e 8b442414 03ca 03c1 89442414 }
+ $sequence_33 = { 33c0 56 51 668985e8fdffff e8???????? }
+ $sequence_34 = { 488bda 488b15???????? 4889442458 89442450 488b05???????? 482bc2 }
+ $sequence_35 = { 48ffc9 48ffc1 7440 488d542448 458d4e2e }
+ $sequence_36 = { 8bd9 e8???????? 4885c0 7509 488d051f390100 }
+ $sequence_37 = { 4883ec20 488bd9 e8???????? 4c8d1d4b9b0000 }
+ $sequence_38 = { 488b01 8b08 ff15???????? 488d15f3170100 488bcb }
+ $sequence_39 = { e8???????? 59 3bc7 59 a3???????? 7419 68???????? }
+ $sequence_40 = { 743e 8305????????20 8d0c9de0a30010 8d9080040000 8901 3bc2 }
+ $sequence_41 = { 4885c0 7438 33c0 4883c9ff 4c8d8600010000 488bfb }
+ $sequence_42 = { 8d04c0 8b0c8de0a30010 8a448104 83e040 c3 55 8bec }
+ $sequence_43 = { 83c410 837dfc08 752f 68???????? 53 e8???????? }
+ $sequence_44 = { 448d5bf0 498d4e10 4963d3 4d8bcd 4d8bc4 }
+ $sequence_45 = { 8b8fa8af0100 488b87a0af0100 400fb6d6 f6d2 881401 ff87a8af0100 8b97a8af0100 }
+ $sequence_46 = { 59 8a4dff 8d3c85e0a30010 8bc3 80c901 83e01f 884d0b }
+ $sequence_47 = { 488905???????? 8905???????? 488b05???????? 4533c0 48c7c102000080 488905???????? }
+ $sequence_48 = { 8bc3 c1f905 83e01f 8b0c8de0a30010 8d04c0 }
+ $sequence_49 = { 8b442448 448b6e4c 448b7e44 c1e808 4c8bf3 8b5e48 }
condition:
- 7 of them and filesize <2376704
+ 7 of them and filesize <330752
}
-rule MALPEDIA_Win_Sdbbot_Auto : FILE
+rule MALPEDIA_Win_Misha_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6668321a-45c2-56a4-8219-52041c66e0ea"
+ id = "3791b368-7721-59e9-a6c9-80386ca3e3f7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sdbbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sdbbot_auto.yar#L1-L188"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.misha"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.misha_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "0618d5957379edb357e3ce8de647ff0724885b87e782036bd514add2c7f2cbe6"
+ logic_hash = "20e70ebbe7343afb7f42cf249a2a9fa16b58c61214c6be715dfea2d371ecbbbb"
score = 75
quality = 75
tags = "FILE"
@@ -143207,40 +150145,32 @@ rule MALPEDIA_Win_Sdbbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8bf8 ba4d5a0000 6690 }
- $sequence_1 = { 803e61 7203 83c1e0 81c2ffff0000 03cf }
- $sequence_2 = { 8bcf 85d2 7418 8bfe 2b7df8 }
- $sequence_3 = { 8d4901 8841ff 8d5201 83ee01 }
- $sequence_4 = { 2bd1 03c1 8955ec 8945e4 85d2 0f8560ffffff }
- $sequence_5 = { 8b7028 33c9 0fb75024 0f1f8000000000 0fb63e }
- $sequence_6 = { 8b01 03c6 8945e8 eb2e 3daafc0d7c }
- $sequence_7 = { 6683f803 750b 81e1ff0f0000 013c31 eb27 6683f801 7511 }
- $sequence_8 = { c3 803d????????00 750c c605????????01 }
- $sequence_9 = { 33f6 8a27 83c702 84e4 7437 }
- $sequence_10 = { 7419 0f1f8000000000 0fb602 48ffc2 8801 488d4901 4983e801 }
- $sequence_11 = { 0f1f840000000000 418b49f8 49ffca 418b11 4903ce 458b41fc }
- $sequence_12 = { 7204 4883c0e0 4803c1 48ffc2 664503c1 75e5 3d5bbc4a6a }
- $sequence_13 = { 48833f00 488bd8 75a4 4883c514 837d0000 0f856dffffff }
- $sequence_14 = { 4903ce 41ffd5 488bf0 4885c0 7474 }
- $sequence_15 = { 85c0 0f84bb000000 418b9fb0000000 8bf8 4903de }
- $sequence_16 = { 4d2bc5 0fb601 41880408 488d4901 4883ea01 75ef 450fb74f14 }
- $sequence_17 = { 4d03fd 41b800300000 448d4940 418b5750 ffd6 418b5750 488bc8 }
+ $sequence_0 = { 0fbe09 03c1 894510 8b45f8 40 8945f8 8b4510 }
+ $sequence_1 = { c20400 55 8bec 51 837d0802 7448 837d0804 }
+ $sequence_2 = { 8945dc 817d140000007e 7607 33c0 e9???????? 8b4524 }
+ $sequence_3 = { 32c0 5d c3 56 8bf0 eb0a 8bce }
+ $sequence_4 = { c78510ffffff04040404 c78514ffffff04040404 c78518ffffff04040404 c7851cffffff04040404 c78520ffffff05050505 c78524ffffff05050505 c78528ffffff05050505 }
+ $sequence_5 = { 85c0 7404 2bf3 8930 b001 }
+ $sequence_6 = { 8b450c 0590010000 50 e8???????? 83c414 b001 e9???????? }
+ $sequence_7 = { 8b4dcc 8d440104 8945cc 837d900f 0f829e000000 837d1c00 741d }
+ $sequence_8 = { 50 e8???????? 8b5508 56 6a1c 59 }
+ $sequence_9 = { 8b4514 e8???????? 0fb64524 85c0 7456 6a00 68ffffff7f }
condition:
- 7 of them and filesize <1015808
+ 7 of them and filesize <710656
}
-rule MALPEDIA_Win_Collection_Rat_Auto : FILE
+rule MALPEDIA_Win_Atmosphere_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "57812c72-d174-5305-a791-07d9524d5d58"
+ id = "7ba90f14-d41a-58f9-948d-cf574aec7198"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.collection_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.collection_rat_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atmosphere"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atmosphere_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "47382a0b15866fbc9363efde1f8fbfda4134e668af0afa7d4fd14596481603d4"
+ logic_hash = "0264599b5475822be219779f2f93298a08919e3b2fbd551146e8b50c69fa19e9"
score = 75
quality = 75
tags = "FILE"
@@ -143254,32 +150184,32 @@ rule MALPEDIA_Win_Collection_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488b5567 488d4ef0 4803cf 458bc6 e8???????? 85c0 }
- $sequence_1 = { 488d05870c0100 488bd9 488901 f6c201 740a ba18000000 e8???????? }
- $sequence_2 = { 488b4138 8938 e9???????? 488b05???????? 488b4808 488b4130 }
- $sequence_3 = { 4883c102 33d2 e8???????? 488b0d???????? 488b5108 48894218 488b05???????? }
- $sequence_4 = { 0f8467010000 488bc4 48895808 48897010 48897818 4c897020 55 }
- $sequence_5 = { 458bf0 0fb7f2 4885c9 0f84d1000000 488b9c24a8000000 4885db }
- $sequence_6 = { 83a424b000000000 ba14000000 33c9 448d42fa e8???????? 488d0d74740200 ffd0 }
- $sequence_7 = { e8???????? 482be0 bd00100000 488d8c24e0000000 448bc5 33d2 }
- $sequence_8 = { 488b4a28 e8???????? 84c0 740b 488bd6 498bcd }
- $sequence_9 = { 488b4830 4c89542450 bf03000000 897c2448 488d442468 4889442440 488d8424d0000000 }
+ $sequence_0 = { 83ec14 56 8b7104 85f6 }
+ $sequence_1 = { 88460e 33c0 894612 894616 89461a 884e1e }
+ $sequence_2 = { e8???????? 8b4604 85c0 7504 33f6 eb08 }
+ $sequence_3 = { 8bcf ff5338 5f 5e }
+ $sequence_4 = { c645fc02 8bcc 8965e8 50 51 e8???????? }
+ $sequence_5 = { 8bce 8975e8 8806 ff15???????? }
+ $sequence_6 = { 8bc4 89642410 50 e8???????? }
+ $sequence_7 = { 8b7c240c 8bf1 57 ff15???????? 8b470c }
+ $sequence_8 = { 51 83ec10 8bc4 89642410 50 e8???????? }
+ $sequence_9 = { 8bcc 8965e8 50 51 }
condition:
- 7 of them and filesize <397312
+ 7 of them and filesize <360448
}
-rule MALPEDIA_Win_Evilpony_Auto : FILE
+rule MALPEDIA_Win_Sys10_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e7d929da-c5f9-5c4e-ba1c-7d2c63753499"
+ id = "01030a4d-1840-51b2-a9d0-6bbc4385fa1e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.evilpony"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.evilpony_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sys10"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sys10_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "02845c899902aea9d270d9fa0c1670211f713972016e6e56c5e914a4d2e0626d"
+ logic_hash = "6943a43537b8ee069df094c74ea397f99150d4b78d4cfd8ed6ddb44f86656e07"
score = 75
quality = 75
tags = "FILE"
@@ -143293,32 +150223,32 @@ rule MALPEDIA_Win_Evilpony_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 746e 33c0 6a2d 40 668945f0 58 6a04 }
- $sequence_1 = { e8???????? 50 53 e8???????? 83c410 6a23 }
- $sequence_2 = { ff15???????? 83f8ff 74d6 8bc7 8b4df8 33cd }
- $sequence_3 = { 034df0 03c1 8b4db8 c14da802 8d8401a1ebd96e 8b4dac }
- $sequence_4 = { 33f6 ff15???????? 85c0 782c 53 8bc7 e8???????? }
- $sequence_5 = { e8???????? c9 c3 55 8bec 83ec18 8b4d08 }
- $sequence_6 = { e8???????? 8d855cffffff 50 c7855cffffff94000000 ff15???????? 83bd6cffffff02 7509 }
- $sequence_7 = { 56 e8???????? 83c40c 43 5f 5e 8bc3 }
- $sequence_8 = { c3 85f6 7436 85ff 7432 53 6a00 }
- $sequence_9 = { 39b5f0f7ffff 0f8495000000 39b5e4f7ffff 0f8489000000 6a04 8d9ddcf7ffff c785dcf7ffff1000efbe }
+ $sequence_0 = { 6a03 68???????? 68???????? 51 52 50 ff15???????? }
+ $sequence_1 = { 837e04ff 740b 8b16 52 e8???????? 83c404 }
+ $sequence_2 = { 8b4e0c 51 ff15???????? 8b5608 6aff 52 ff15???????? }
+ $sequence_3 = { 56 e8???????? 83c404 85c0 74c6 8b4c2410 896e10 }
+ $sequence_4 = { 6810270000 ff15???????? 33c0 59 }
+ $sequence_5 = { 837e04ff 740b 8b16 52 }
+ $sequence_6 = { 56 89442414 e8???????? 83c404 85c0 7541 }
+ $sequence_7 = { 52 6a05 50 ffd6 8b5308 }
+ $sequence_8 = { 8d4c2413 51 6800400000 52 50 e8???????? }
+ $sequence_9 = { 8b13 52 ffd7 8b4304 50 ffd7 8b4b08 }
condition:
- 7 of them and filesize <147456
+ 7 of them and filesize <286720
}
-rule MALPEDIA_Win_Jlorat_Auto : FILE
+rule MALPEDIA_Win_H1N1_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "eb5a0545-ab37-5e70-b9eb-6c48eb9adb8a"
+ id = "5e13a49f-72f0-5eb3-a885-2e0245e8f66e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jlorat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jlorat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.h1n1"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.h1n1_auto.yar#L1-L170"
license_url = "N/A"
- logic_hash = "c96d7ee2744d61897b682d97d67d56d29e38731c8c93cf3d00f8d6450ca3d2bf"
+ logic_hash = "842ef63a8a089830b40dfc0f60da9194950df4056683b94edaa8a18caec3ebbd"
score = 75
quality = 75
tags = "FILE"
@@ -143332,32 +150262,38 @@ rule MALPEDIA_Win_Jlorat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83ec10 89c1 83c101 83d200 89542450 31c0 }
- $sequence_1 = { f20f114620 c7464001000000 89e0 8d5620 895004 8908 e8???????? }
- $sequence_2 = { f20f1086d8020000 f20f108ee0020000 f20f118e28030000 f20f118620030000 f20f108630030000 f20f118648030000 f20f108620030000 }
- $sequence_3 = { f6861618000001 0f85c0160000 e9???????? 8b4510 8b08 89e0 894804 }
- $sequence_4 = { eb00 e9???????? 8b559c 8b7580 8b7d84 8b5da4 8b4d88 }
- $sequence_5 = { e8???????? 8945c8 eb00 8b4dc4 8b45c8 c645e300 8945cc }
- $sequence_6 = { c745f0ffffffff 89e0 8d4dd8 8908 e8???????? 8b45c8 8b4de8 }
- $sequence_7 = { f30f118424d8000000 eb43 8b4c2448 8b54244c 89e0 895004 8908 }
- $sequence_8 = { e8???????? 894644 eb00 8b4e44 c601ff c64101ff c64102ff }
- $sequence_9 = { eb09 8b4df4 83c101 894df4 837df40a 7302 ebef }
+ $sequence_0 = { 49 85c9 0f8527ffffff ff75f8 }
+ $sequence_1 = { 49 75b6 8bcf 2b4d0c 83e103 }
+ $sequence_2 = { 83bdecfeffff01 7505 bb07000000 93 5b c9 c3 }
+ $sequence_3 = { aa ac 0ac0 740e 3c3d 740a e8???????? }
+ $sequence_4 = { 0345f4 8b8ba4000000 85c9 742b }
+ $sequence_5 = { ff7508 6a00 ff35???????? 58 ffd0 }
+ $sequence_6 = { 351f5b5742 ab 05f8383ad2 ab ff75fc }
+ $sequence_7 = { 59 85c0 75d1 83bb8000000000 7465 }
+ $sequence_8 = { 8d8614850010 50 ffb610850010 57 }
+ $sequence_9 = { 59 c3 56 8b742408 6804010000 68f8820010 }
+ $sequence_10 = { 330c85908f0010 42 3b54240c 72e4 f7d1 8bc1 }
+ $sequence_11 = { 57 8d3c95c0850010 8b0f 334f04 23cb }
+ $sequence_12 = { 330d???????? 5b 8bc1 83e001 d1e9 330c8500850010 330d???????? }
+ $sequence_13 = { 57 50 e8???????? 68f4600010 56 }
+ $sequence_14 = { 33d2 a3???????? 42 b9c0850010 8b01 c1e81e 3301 }
+ $sequence_15 = { 6800800010 ff742410 e8???????? 6823af2930 56 ff742410 }
condition:
- 7 of them and filesize <10952704
+ 7 of them and filesize <172032
}
-rule MALPEDIA_Win_Furtim_Auto : FILE
+rule MALPEDIA_Win_Jaff_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ff92451b-6d4d-5ce0-b407-7dcb5e6ae2c6"
+ id = "05c08a02-2b7b-5977-8a51-2a2090077d3b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.furtim"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.furtim_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jaff"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jaff_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "01fa4c0038a5d8991914e1859c3786c2de4cd564716dd7c7ecdf607d66ee4df9"
+ logic_hash = "af5ef67353fca994a67e82aadde11782d5e684720bb76ef0f2df38c565071742"
score = 75
quality = 75
tags = "FILE"
@@ -143371,34 +150307,34 @@ rule MALPEDIA_Win_Furtim_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5f 5e c9 c20400 6a0c 68???????? e8???????? }
- $sequence_1 = { 85c0 7c28 8d45fc 50 6a04 ff15???????? }
- $sequence_2 = { c7867802000020d94000 c78600050000cb224000 c786f406000032164000 c746601c724400 c7869c06000032254000 c786fc020000ca254000 }
- $sequence_3 = { 59 85c0 7408 8bce ff96cc050000 5f }
- $sequence_4 = { 57 8bf1 8dbeb8000000 57 c7071c010000 ff96bc030000 }
- $sequence_5 = { c9 c20800 8bff 55 8bec 83ec10 ff7508 }
- $sequence_6 = { 0f85e3000000 39a9c0000000 7542 0fb781cc010000 663bc5 7405 663bc3 }
- $sequence_7 = { 740f 837dfc01 7509 c686c405000001 eb0e 8bce ff96f8040000 }
- $sequence_8 = { c745e4e4624400 c745e8ec624400 c745ecf4624400 c745f0fc624400 c745f404634400 c745f8???????? }
- $sequence_9 = { 389f94010000 7546 80bf9501000015 7535 80bf960100005d 752c 8bce }
+ $sequence_0 = { c746080a000000 c6460c01 ffd7 8b1d???????? 50 ffd3 6a14 }
+ $sequence_1 = { 8bf8 e8???????? 8b4704 48 7818 }
+ $sequence_2 = { 8b4514 8b4d10 6a00 8d55fc 52 50 51 }
+ $sequence_3 = { 72ed 8b45dc 50 6a00 ffd7 50 }
+ $sequence_4 = { ffd3 8945f0 8b450c 8d5de0 8d4df0 e8???????? 8b45e0 }
+ $sequence_5 = { 3b4510 0f82a5feffff 8b4d14 51 6a00 }
+ $sequence_6 = { 8d5598 52 8d45cc 50 e8???????? 8d7da8 }
+ $sequence_7 = { 33c2 2bc2 50 8d95f8fbffff 68???????? }
+ $sequence_8 = { 8d4584 e8???????? 8d7da4 8d75e4 e8???????? 8b55a4 8b3d???????? }
+ $sequence_9 = { c745f00a000000 c645f401 ffd3 50 ff15???????? 8945e8 }
condition:
- 7 of them and filesize <622592
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Batel_Auto : FILE
+rule MALPEDIA_Win_Mystic_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5c784793-7499-59d2-9d6e-e8d3b0a588c6"
+ id = "677c1a33-ba88-5fd2-bb60-e482ebad5ee5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.batel"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.batel_auto.yar#L1-L228"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mystic_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mystic_stealer_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "54d1d1c2accc87182d1d618459ab2c69708bc7f726841a04281db6bdb06903a0"
+ logic_hash = "7ef3f130d7f708fe480ce6294f73f2aa94b8d0f4c6423ffb91a1e80eb925cec4"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -143410,45 +150346,32 @@ rule MALPEDIA_Win_Batel_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c0 5b c21000 3b0d???????? 7502 f3c3 }
- $sequence_1 = { 56 b858212300 be58212300 57 8bf8 3bc6 }
- $sequence_2 = { 7429 68f4202300 56 ff15???????? }
- $sequence_3 = { 7cec 56 57 6a40 6800100000 }
- $sequence_4 = { 7ccd 5f 5e 5d 33c0 5b c21000 }
- $sequence_5 = { c745fc00000000 6800002300 e8???????? 83c404 }
- $sequence_6 = { 689d020000 8d8561fdffff 6a00 50 c68560fdffff00 }
- $sequence_7 = { 8b1d???????? bf01000000 8d642400 68???????? ff15???????? }
- $sequence_8 = { b8???????? 8a10 88940d60fdffff 83c003 }
- $sequence_9 = { a1???????? 85c0 752c 8935???????? 68d0202300 }
- $sequence_10 = { 40 c20c00 55 8bec 81eca0020000 68ee020000 ff15???????? }
- $sequence_11 = { b90b010000 66398818002300 75dd 83b8740023000e 76d4 }
- $sequence_12 = { ffd3 68005c2605 ffd5 47 83ff5a 7ccd 5f }
- $sequence_13 = { 55 8b2d???????? 56 57 68a00f0000 ffd5 }
- $sequence_14 = { 85c0 7412 ffd0 56 }
- $sequence_15 = { 59 6a00 ff15???????? 68d8202300 ff15???????? 833d????????00 }
- $sequence_16 = { 68a00f0000 ffd5 8b1d???????? bf01000000 }
- $sequence_17 = { 50 c68560fdffff00 e8???????? 83c40c 33c9 }
- $sequence_18 = { 85f6 7422 68???????? 56 ff15???????? 85c0 7412 }
- $sequence_19 = { 6a00 ff15???????? 8bf8 b9a7000000 8db560fdffff f3a5 66a5 }
- $sequence_20 = { 6a40 6800100000 689e020000 6a00 ff15???????? }
- $sequence_21 = { 83b8740023000e 76d4 33c9 3988e8002300 0f95c1 8bc1 6a02 }
- $sequence_22 = { 66a5 ffd0 5f 5e }
+ $sequence_0 = { 8b461c 42 8b4e08 895614 8a4007 88040a 8b5614 }
+ $sequence_1 = { 0fb7c7 eb0b 8d4203 8986bc160000 }
+ $sequence_2 = { 6a02 5d 8b4774 3d06010000 }
+ $sequence_3 = { 0fb7d8 668bc3 66d3e0 660bc6 0fb7c0 }
+ $sequence_4 = { eb15 8d4503 8987bc160000 8d4304 }
+ $sequence_5 = { 668b476c 66890451 85f6 741a 8b4f6c }
+ $sequence_6 = { 668bc2 8d5f14 66d3e0 8b0b 660bc6 }
+ $sequence_7 = { eb0c 8d5103 0fb7c0 8996bc160000 0fb7c8 }
+ $sequence_8 = { 8a86b9160000 88040a b110 2a8ebc160000 8b86bc160000 ff4614 }
+ $sequence_9 = { 02c2 03cb 0fb6c0 8a843800010000 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <512000
}
-rule MALPEDIA_Win_Clop_Auto : FILE
+rule MALPEDIA_Win_Darkme_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "59cb28c0-0028-51c2-94ee-931d5b6fa068"
+ id = "08b1ecd8-4245-5b36-9b97-82dc7b781460"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.clop"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.clop_auto.yar#L1-L188"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkme"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkme_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "f2736024915a6a0ca98a26d3016fbd37034bb9a8e1a0f37004991cc314f844e2"
+ logic_hash = "8ec0d0c962cec5e0ecd8c6f133e096757eb87617c4861f80c1b1cf3c91f3cada"
score = 75
quality = 75
tags = "FILE"
@@ -143462,41 +150385,32 @@ rule MALPEDIA_Win_Clop_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c40c 6860070000 6a40 ff15???????? }
- $sequence_1 = { 6a04 6800300000 6887000000 6a00 }
- $sequence_2 = { ff15???????? 56 53 8bf8 ff15???????? 8bf0 56 }
- $sequence_3 = { 57 6a00 ff15???????? 68???????? 8bd8 }
- $sequence_4 = { ff15???????? 8bf0 56 53 ff15???????? 50 }
- $sequence_5 = { 6683e07f 6683f87f 8d642408 0f85fd0b0000 eb00 f30f7e442404 660f2815???????? }
- $sequence_6 = { 50 ff15???????? 83c40c 6860070000 }
- $sequence_7 = { ffd0 c3 8bff 55 8bec 83ec1c 8d4de4 }
- $sequence_8 = { 0f85aa010000 68???????? 8d442450 50 }
- $sequence_9 = { 8be5 5d c20400 56 ff15???????? 6a00 }
- $sequence_10 = { 8d85bcefffff 50 ff15???????? 68???????? }
- $sequence_11 = { 68???????? 68???????? e8???????? 83c424 6aff }
- $sequence_12 = { 6888130000 ffd7 6a00 6a00 6a00 68???????? }
- $sequence_13 = { ff15???????? 68???????? 8d85dcf7ffff 50 }
- $sequence_14 = { 83c408 6aff ff15???????? 33c0 }
- $sequence_15 = { 83c40c 33f6 85ff 7428 }
- $sequence_16 = { 83c424 53 50 ffd6 }
- $sequence_17 = { 6aff ffd7 8b4dfc 33c0 5f }
- $sequence_18 = { 8d8424dc0b0000 50 ffd6 85c0 751a 68???????? 8d8424dc0b0000 }
+ $sequence_0 = { 8dbddcfcffff f3ab b964000000 8dbd18fbffff 68???????? 8985d8fcffff 8985d4fcffff }
+ $sequence_1 = { 51 8d55d4 52 6a02 ff15???????? 83c40c 8d45c4 }
+ $sequence_2 = { 8b8518ffffff 8b08 8b9518ffffff 52 ff5114 dbe2 }
+ $sequence_3 = { 6a00 ff15???????? 50 8b558c 81c2???????? 52 ff15???????? }
+ $sequence_4 = { c745880a000000 8b8530ffffff 50 ff15???????? 8945a0 c7459808000000 8b4dd4 }
+ $sequence_5 = { 8b8500ffffff 50 8b8dfcfeffff 51 ff15???????? 898594feffff eb0a }
+ $sequence_6 = { 05???????? 898588feffff eb12 8b8db4feffff 81c1???????? 898d88feffff 8b9588feffff }
+ $sequence_7 = { 83c42c 51 68???????? ff15???????? 85c0 0f851afeffff }
+ $sequence_8 = { 8b5144 52 8d8524ffffff 50 8d8d54ffffff 51 ff15???????? }
+ $sequence_9 = { 8b08 8b95fcfeffff 52 ff5120 }
condition:
- 7 of them and filesize <796672
+ 7 of them and filesize <1515520
}
-rule MALPEDIA_Win_Backspace_Auto : FILE
+rule MALPEDIA_Win_Coinminer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8637042a-e46d-5e46-8b23-93a8dfec3a24"
+ id = "05a9b3c6-9a1c-50a2-a943-afdee621f718"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.backspace"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.backspace_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.coinminer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.coinminer_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "f8be0bb8ce4eb3c98209ea23733b4688fab87fe72dcb307bd40859035b4f4c31"
+ logic_hash = "254b4cb9ab983948d36cfb896be0834484f66bd70a718e15bb65a41d1319a142"
score = 75
quality = 75
tags = "FILE"
@@ -143510,32 +150424,32 @@ rule MALPEDIA_Win_Backspace_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 40 50 ff15???????? 85c0 0f8fa3000000 }
- $sequence_1 = { 3bfb 59 7405 83c705 }
- $sequence_2 = { 8d8500feffff 50 e8???????? 83c424 85c0 740b ff750c }
- $sequence_3 = { 8b45f8 ff45f8 3d88130000 7f51 ebc9 8a06 }
- $sequence_4 = { 885d91 885d92 885d93 885d94 }
- $sequence_5 = { ff15???????? f7d8 1bc0 59 83e002 59 48 }
- $sequence_6 = { 393d???????? 7552 be00200000 ff75f8 8d85f8dfffff }
- $sequence_7 = { 50 e8???????? 56 e8???????? 8bd8 be???????? 83c306 }
- $sequence_8 = { 8d85f8dfffff 50 e8???????? 59 8bc3 59 e9???????? }
- $sequence_9 = { a3???????? ff75fc ffd6 395dfc }
+ $sequence_0 = { 85d2 750d 8b45f8 8b55fc 5f 5e }
+ $sequence_1 = { 8d7f04 73ef 83c104 8a10 7410 48 ffc0 }
+ $sequence_2 = { e9???????? 6a00 ff742414 ffd6 ff742414 8b3d???????? ffd7 }
+ $sequence_3 = { c3 8bc6 c745f200000000 99 0f57c0 66c745f60000 660fd645ea }
+ $sequence_4 = { 8bf0 e8???????? 8bf8 8d842450130000 }
+ $sequence_5 = { 53 56 8b35???????? 8bd9 57 8b3d???????? }
+ $sequence_6 = { 57 ff15???????? c70300000000 8b4510 5f c70600000000 5e }
+ $sequence_7 = { 9b 53 83473220 2c6a }
+ $sequence_8 = { 8d842434010000 50 ff15???????? 56 e8???????? 57 }
+ $sequence_9 = { 83c408 890d???????? 8bf2 8935???????? 85c9 7504 85f6 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <1523712
}
-rule MALPEDIA_Win_Unidentified_087_Auto : FILE
+rule MALPEDIA_Win_Heriplor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "40b9cd18-d110-5435-969b-5dfac9c340c4"
+ id = "d711b4d9-3914-58b9-9b88-9214444e3dee"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_087"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_087_auto.yar#L1-L174"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.heriplor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.heriplor_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "110739d44f9e53e4e50b40a1961bcb5043ade07265d58318b1d26ddc3eb75b3c"
+ logic_hash = "bf5971e2bb98e2180b60da71db38d7f4898a68723f2588a48c70334b337b7d93"
score = 75
quality = 75
tags = "FILE"
@@ -143549,38 +150463,32 @@ rule MALPEDIA_Win_Unidentified_087_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c7453802000000 ff15???????? 83f801 7409 83f80d 0f8581000000 }
- $sequence_1 = { 4c8d9c2480020000 498b5b28 498b7330 498be3 415c }
- $sequence_2 = { 4d8bcf 4533c0 488d542428 488d4c2450 e8???????? 488d5580 488d4c2450 }
- $sequence_3 = { 895c2420 48895908 4c8bf1 488948c8 }
- $sequence_4 = { 40b601 488bcb ff15???????? 400fb6c6 }
- $sequence_5 = { ff15???????? 483905???????? 752b 8b442460 3905???????? 751f }
- $sequence_6 = { eb09 488b05???????? 33d2 8d3c10 488b4c2450 48634104 f644046006 }
- $sequence_7 = { 488d68a1 4881ece0000000 48c745c7feffffff 48895810 48897818 488b05???????? 4833c4 }
- $sequence_8 = { c6864b01000043 c7466870040210 6a0d e8???????? 59 8365fc00 ff7668 }
- $sequence_9 = { 89430c 8d4310 8d89a4080210 5a 668b31 }
- $sequence_10 = { 6a10 57 ff15???????? 6a00 6a00 6a00 8d8584feffff }
- $sequence_11 = { c745e40f000000 895de0 885dd0 8d45d0 50 }
- $sequence_12 = { ff15???????? 50 8dbdf8feffff e8???????? 83c404 5f }
- $sequence_13 = { c705????????25ca0010 8935???????? a3???????? ff15???????? a3???????? 83f8ff }
- $sequence_14 = { 7461 8d0cbd602c0210 8901 8305????????20 8b11 }
- $sequence_15 = { 85c9 7410 8b14b8 8911 8b0d???????? }
+ $sequence_0 = { c20c00 55 89e5 56 57 33c9 648b4130 }
+ $sequence_1 = { 40 5b 59 89ec }
+ $sequence_2 = { 8a08 84c9 740d 80c960 01cb c1e301 }
+ $sequence_3 = { 668b13 8b0491 01f8 5f 5e 89ec 5d }
+ $sequence_4 = { 89e5 51 53 33db 33c9 8b4508 }
+ $sequence_5 = { 85ff 7420 46 46 }
+ $sequence_6 = { 7407 83c204 43 43 ebe6 33d2 668b13 }
+ $sequence_7 = { 01fb 8b32 01fe 6a01 ff750c }
+ $sequence_8 = { 3b5d0c 7401 40 5b }
+ $sequence_9 = { 01f9 01fa 01fb 8b32 01fe 6a01 ff750c }
condition:
- 7 of them and filesize <462848
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Himan_Auto : FILE
+rule MALPEDIA_Win_Unidentified_044_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a882d092-072a-5641-b214-8642f7cc1e11"
+ id = "a037a55a-a1d2-5696-aa65-bcad92ff6480"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.himan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.himan_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_044"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_044_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "bf239bbd05c563f996119e72de32999d711849487b106db1285219d82e77b92b"
+ logic_hash = "fa0bbb48e3a00969b6207e7af2c24fceeabe6227dd53aafea6a4369ea97af4c2"
score = 75
quality = 75
tags = "FILE"
@@ -143594,34 +150502,34 @@ rule MALPEDIA_Win_Himan_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b7b04 33ee 8b7068 0554010000 c1e204 33f7 }
- $sequence_1 = { 8b442410 3bd0 7422 56 ff15???????? 57 ff15???????? }
- $sequence_2 = { 894c2414 8bcb c1e910 81e1ff000000 }
- $sequence_3 = { c1e008 0bc7 c1e008 0bc1 8bc8 8904b594886e00 }
- $sequence_4 = { 8bda c1eb18 8b2cad948c6e00 332c9d94946e00 8bd9 c1eb10 81e3ff000000 }
- $sequence_5 = { 8b08 50 ff5108 8b8c24a8050000 5f }
- $sequence_6 = { 8d85a0fcffff 50 ff15???????? 8da594d4ffff 5f 5e 5b }
- $sequence_7 = { c1e910 3334adbcc26e00 8beb 81e5ff000000 81e1ff000000 c1eb08 3334adbcba6e00 }
- $sequence_8 = { 333c9594946e00 8b542414 c1ea10 81e2ff000000 333c9594906e00 8bd1 81e2ff000000 }
- $sequence_9 = { c1c108 890cb5948c6e00 8a8ebccb6e00 8bd0 884c2410 8b7c2410 c1c210 }
+ $sequence_0 = { 8bca 8bd8 e8???????? 83c404 84c0 7409 668b542408 }
+ $sequence_1 = { 3bcf 7416 8d9b00000000 80792400 7403 }
+ $sequence_2 = { c3 8b8424e4020000 6a10 6a00 50 }
+ $sequence_3 = { 74b3 33ff 397c2418 76ab 33c0 }
+ $sequence_4 = { ff15???????? 3d1e270000 7552 8b442408 85c0 }
+ $sequence_5 = { 2bf0 03d8 85f6 7fe2 }
+ $sequence_6 = { 803e00 8be8 743f 53 57 }
+ $sequence_7 = { ffd5 8bb42464050000 85c0 7f85 7c24 f644242420 0f8468feffff }
+ $sequence_8 = { c7460403000000 ffd3 5b 5f 32c0 5e }
+ $sequence_9 = { 55 e8???????? 83c40c 84c0 74a0 8a442413 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Win_Grease_Auto : FILE
+rule MALPEDIA_Win_Friedex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "adc1cb70-ca80-5648-8c82-afd04a5873d7"
+ id = "97d1751f-5738-5834-8f82-479344539d3a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grease"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grease_auto.yar#L1-L230"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.friedex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.friedex_auto.yar#L1-L172"
license_url = "N/A"
- logic_hash = "3adaa81800887e757966a0f8096c9ffe86dfca2fec47d710b3b77554cf1c8228"
+ logic_hash = "8dffa1fb6804412157c235a0ef3196dc0c5961e846d30c21c59180ff32555e60"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -143633,47 +150541,40 @@ rule MALPEDIA_Win_Grease_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 50 683f000f00 50 50 50 }
- $sequence_1 = { 488b4c2460 ff15???????? b801000000 488b8c2480020000 4833cc e8???????? 4881c490020000 }
- $sequence_2 = { 4533c0 488bd3 c744242804000000 4889442420 ff15???????? 488b4c2450 ff15???????? }
- $sequence_3 = { 488b05???????? 4833c4 4889842480020000 488d4c2472 }
- $sequence_4 = { c74424281f000200 895c2420 ff15???????? 85c0 0f85e7000000 }
- $sequence_5 = { 4533c9 48897c2440 4889442438 48897c2430 }
- $sequence_6 = { 48895c2440 48895c2458 895c2460 48895c2468 }
- $sequence_7 = { 4889442438 48897c2430 4533c0 c74424283f000f00 897c2420 ff15???????? 85c0 }
- $sequence_8 = { 488b4c2450 488d442458 41b904000000 4533c0 488bd3 }
- $sequence_9 = { 55 68000000c0 50 ff15???????? 8bf0 }
- $sequence_10 = { e9???????? c684342c08000023 e9???????? c684342c08000021 e9???????? c684342c08000025 }
- $sequence_11 = { 51 683f000f00 6a00 8d542424 52 6802000080 ffd7 }
- $sequence_12 = { 85c0 7540 8d542420 52 8b542414 }
- $sequence_13 = { 83c001 3acb 75f7 8b2d???????? }
- $sequence_14 = { 83c404 85f6 8854240c 8d46ff 7412 8a4c040c }
- $sequence_15 = { e9???????? c684341001000066 e9???????? c684341001000068 e9???????? }
- $sequence_16 = { e8???????? 8b0d???????? 51 8d542418 }
- $sequence_17 = { e9???????? c6440c082b e9???????? c6440c083e e9???????? c6440c083d e9???????? }
- $sequence_18 = { c68434240600003f eb12 c68434240600002e eb08 }
- $sequence_19 = { 8a08 40 84c9 7405 46 85c0 }
- $sequence_20 = { 8b9c2418040000 56 57 b90d000000 be???????? }
- $sequence_21 = { 50 897c2430 ffd5 8b542410 6a04 8d4c241c 51 }
- $sequence_22 = { 8d942434010000 52 56 ffd7 b83b000000 53 668984242c010000 }
+ $sequence_0 = { e8???????? 57 8bc8 e8???????? 6a26 }
+ $sequence_1 = { c20c00 51 51 53 55 8be9 c744240820090d0a }
+ $sequence_2 = { 1adb e8???????? 6a20 5f }
+ $sequence_3 = { 74f9 33c9 663908 0f94c0 5f 5e 5d }
+ $sequence_4 = { 663910 7431 8bd8 8d7102 eb1d }
+ $sequence_5 = { 5f 5b 5e 5d c20c00 51 }
+ $sequence_6 = { 75c1 6a2a 5f eb06 b001 eb0f 03c5 }
+ $sequence_7 = { 6a00 ff760c ffd0 8b442408 5e }
+ $sequence_8 = { 8955e0 e8???????? 8d0dd830a500 890424 894c2404 e8???????? }
+ $sequence_9 = { 8d055a23a500 31c9 8d55d8 803d????????e9 8955d4 8945d0 }
+ $sequence_10 = { 8a2c057530a500 83c001 38e9 8945a0 8955cc 74bc }
+ $sequence_11 = { 8d055a23a500 5d c3 55 }
+ $sequence_12 = { c7424458270000 c7424800100100 8b7de4 c787cc00000000000000 c787c800000000000000 }
+ $sequence_13 = { 8b45a4 8a4daf 31d2 8a2c057530a500 83c001 38e9 }
+ $sequence_14 = { 8d0dc930a500 890424 894c2404 e8???????? 8d0d4430a500 31d2 8b75f8 }
+ $sequence_15 = { 8d0d4430a500 31d2 890c24 c744240400000000 }
condition:
- 7 of them and filesize <278528
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_R980_Auto : FILE
+rule MALPEDIA_Win_Blackbasta_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5cd23ce7-fde9-586e-b7d0-c68d0d4730a5"
+ id = "5c8e56ab-6cbd-5deb-8276-9c7c1c51570f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.r980"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.r980_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackbasta"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackbasta_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "6631f2c285d8397109ba8d7d2192a7dc1832567dbf3b5dac3dd0d91311ae325e"
+ logic_hash = "7b0b80b4e818e69a7ef8a8ed63d1384307760adc672033eb9b7389cd6b55895b"
score = 75
- quality = 45
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -143685,32 +150586,32 @@ rule MALPEDIA_Win_R980_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 8d4dd4 e8???????? 837de810 8d45d4 53 0f4345d4 }
- $sequence_1 = { e8???????? 56 8b08 8b01 ff5070 56 50 }
- $sequence_2 = { 8d4dbc e8???????? 8d4dd4 e8???????? 8d4da4 e8???????? 8b4df4 }
- $sequence_3 = { 85c0 7409 ff7608 50 e8???????? c7460800000000 c7460400000000 }
- $sequence_4 = { 50 e8???????? 8bce e8???????? 8b4d1c 83c418 }
- $sequence_5 = { 8bc7 f00fc14104 7515 8b01 ff10 8b4db4 8bc7 }
- $sequence_6 = { ff4654 837e5440 750c c7465400000000 e8???????? 8b4658 83f8f8 }
- $sequence_7 = { e8???????? 83ec18 8d8424c0000000 8bcc 50 e8???????? e9???????? }
- $sequence_8 = { 8bc8 e8???????? 33c9 894ddc 8b448dc8 0f57c0 41 }
- $sequence_9 = { c745fc00000000 8b30 8d45ec 50 e8???????? 83c404 8d4dec }
+ $sequence_0 = { ff7590 8bcf e8???????? 84c0 751f 384704 7507 }
+ $sequence_1 = { 89b574ffffff 894588 89458c e8???????? 84c0 755d 384304 }
+ $sequence_2 = { 5b 8b4df4 64890d00000000 8d656c 5d c3 8d4d30 }
+ $sequence_3 = { e8???????? 83c404 85c0 0f849d010000 8d5823 83e3e0 8943fc }
+ $sequence_4 = { c745e000000000 c745e40f000000 c645d000 c745fc00000000 ff734c e8???????? 83c404 }
+ $sequence_5 = { b867666666 c645e800 f7ea c1fa05 8bc2 c1e81f 03c2 }
+ $sequence_6 = { 85f6 7462 8b7d28 3bf7 7416 0f1f440000 8bce }
+ $sequence_7 = { 56 e8???????? 83463008 83c410 0fb6c3 81c500020000 8b5c2474 }
+ $sequence_8 = { 8d4dc0 e8???????? 837e1401 741a 837dec01 740d 8d45d8 }
+ $sequence_9 = { 83c410 8bce 50 68???????? e8???????? 8bf0 c78574ffffff00000000 }
condition:
- 7 of them and filesize <3178496
+ 7 of them and filesize <1758208
}
-rule MALPEDIA_Win_Zeroaccess_Auto : FILE
+rule MALPEDIA_Win_Maoloa_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dc18e525-3177-5057-b2b8-44deb0459882"
+ id = "c9cb938f-8aed-56a4-9406-4a70e3564e5d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeroaccess"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeroaccess_auto.yar#L1-L151"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maoloa"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maoloa_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "4423d17d4505fc4e1d7ad61f77b371f17ded461805f238fd1e8f686647ad897a"
+ logic_hash = "aa3156b629c721039014b4e703faa79f34b5d8a33e4caf3d82f64b9729ae8335"
score = 75
quality = 75
tags = "FILE"
@@ -143724,37 +150625,32 @@ rule MALPEDIA_Win_Zeroaccess_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 85c0 7408 ff15???????? eb02 }
- $sequence_1 = { 56 56 6a20 6a05 }
- $sequence_2 = { bf03000040 eb05 bf010000c0 85ff }
- $sequence_3 = { 6a01 8d45f4 50 ff7308 ff15???????? 85c0 }
- $sequence_4 = { 6a04 68???????? 6a10 68???????? 68060000c8 ff7708 ff15???????? }
- $sequence_5 = { ff15???????? 85c0 7407 b8e3030000 }
- $sequence_6 = { 56 6a10 8945e8 8d45e4 }
- $sequence_7 = { e8???????? 50 6819000200 8d45f8 }
- $sequence_8 = { 3bc1 7604 83c8ff c3 }
- $sequence_9 = { 50 68???????? 6889001200 8d45fc }
- $sequence_10 = { 56 8d45f8 50 ff15???????? 6a01 8d45f8 50 }
- $sequence_11 = { 33c0 48 83c9ff c744242804000000 48 }
- $sequence_12 = { 85db 741f 8b4304 49 }
- $sequence_13 = { 7615 83780815 750f c705????????01000000 }
- $sequence_14 = { 48 83ec20 41 8bf9 48 8bd9 }
+ $sequence_0 = { 8b55fc 8bcb 85c0 7817 8d45f0 50 e8???????? }
+ $sequence_1 = { 50 ffb5f0e4ffff 8b35???????? ffd6 8b85c0e4ffff c1e015 03858ce5ffff }
+ $sequence_2 = { 8b4df8 33cd e8???????? 8be5 5d c3 befcffffff }
+ $sequence_3 = { 83c404 85f6 0f8590000000 6a01 8bd7 8bcf e8???????? }
+ $sequence_4 = { 85c0 8d8d00e0ffff 0f45ce 8bf1 89b5f8dfffff 8d85f8efffff 50 }
+ $sequence_5 = { b910000000 0f43c1 8d4c2418 2bf8 }
+ $sequence_6 = { 8d97a9cfde4b 33c1 894db4 0345d0 03d0 8b7db4 c1c20b }
+ $sequence_7 = { 8bd3 c707ffffffff 8bcf e8???????? 83c404 8bf0 8b85e0f9ffff }
+ $sequence_8 = { 0f1f00 0fb601 8d4901 30440eff 0fb641ff 30440aff 83ef01 }
+ $sequence_9 = { 5e 5b 8be5 5d c3 8d45f0 8bd1 }
condition:
- 7 of them and filesize <172032
+ 7 of them and filesize <586752
}
-rule MALPEDIA_Win_Trochilus_Rat_Auto : FILE
+rule MALPEDIA_Win_Lcpdot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "59484933-96f5-5392-a130-d1897de1bd22"
+ id = "a95a9872-7a8a-5e4e-81d9-79280cf44b78"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.trochilus_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.trochilus_rat_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lcpdot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lcpdot_auto.yar#L1-L158"
license_url = "N/A"
- logic_hash = "e651983c70589c057f0ef7e60f3a8876ce52f4e099a0b1c41a830840b75beb3c"
+ logic_hash = "3aab7a93128b920a2310606f2af0b9275aa227850391bd4e2d60e74544bd69d0"
score = 75
quality = 75
tags = "FILE"
@@ -143768,32 +150664,37 @@ rule MALPEDIA_Win_Trochilus_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb74636 50 ffd7 0fb7c8 668bd1 662b935e010100 }
- $sequence_1 = { 6a32 56 53 e8???????? }
- $sequence_2 = { 50 ffd3 668b8e52010100 662bc8 6683f903 0f8c9e000000 81863001010018fcffff }
- $sequence_3 = { 56 8bf1 8d5e04 8bcb e8???????? 83f8ff 7407 }
- $sequence_4 = { 8d4de4 51 50 ff7538 ff7534 }
- $sequence_5 = { 5e 5d c20c00 55 8bec 837d08ff 56 }
- $sequence_6 = { 68???????? 50 ff15???????? 85c0 7404 33c0 eb1a }
- $sequence_7 = { ff15???????? 33c0 eb81 55 8bec 51 53 }
- $sequence_8 = { 33db 391f 7e1d 8b4704 8b4c0304 68a01e0110 e8???????? }
- $sequence_9 = { b8fac50010 e8???????? 8bf1 837d0800 7505 8b06 ff505c }
+ $sequence_0 = { e9???????? c705????????01000000 e8???????? 83f801 }
+ $sequence_1 = { 85c9 0f848c000000 53 56 8b7208 }
+ $sequence_2 = { 6a01 52 56 8d8508feffff }
+ $sequence_3 = { e8???????? 85c0 752a 56 ff15???????? }
+ $sequence_4 = { ff24851e884000 838de8fdffffff 89b588fdffff 89b5bcfdffff }
+ $sequence_5 = { 90 488b4308 4885c0 743f 488b0d???????? 488d15ad4f0100 }
+ $sequence_6 = { ffd7 5f 5e c3 55 8bec 81ec400c0000 }
+ $sequence_7 = { 8d8d14f4ffff 51 ebd8 83c320 53 8bce e8???????? }
+ $sequence_8 = { 8b11 8b4228 53 ffd0 33c0 8d55e0 }
+ $sequence_9 = { 85c0 0f8514010000 4c8d2d0a2f0100 41b804010000 }
+ $sequence_10 = { 488d4c2430 e8???????? b920080000 e8???????? }
+ $sequence_11 = { 48894c2408 4881ec88000000 488d0df54d0100 ff15???????? }
+ $sequence_12 = { 488bd9 894110 bf04000000 3daa55aa55 7519 }
+ $sequence_13 = { 7409 488bcf ff15???????? 33c0 488b9c2470040000 488b8c2440040000 4833cc }
+ $sequence_14 = { 488d1d23de0000 488d3d24de0000 eb0e 488b03 4885c0 7402 ffd0 }
condition:
- 7 of them and filesize <630784
+ 7 of them and filesize <257024
}
-rule MALPEDIA_Win_Cloudeye_Auto : FILE
+rule MALPEDIA_Win_Tellyouthepass_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "55cebb53-71a5-52d8-a3dc-f73efa113a86"
+ id = "2f59ff80-ce55-5261-bc1e-9b9085ba348c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cloudeye"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cloudeye_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tellyouthepass"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tellyouthepass_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "ce7b005739a8ed2a89f930168aa824ea8a88d8cc7cac3881e5d28b500fe73c46"
+ logic_hash = "e0931a30828c9c1e2a42766d85093d9ba189ed49cc692d748a9e549b96d308d1"
score = 75
quality = 75
tags = "FILE"
@@ -143807,32 +150708,32 @@ rule MALPEDIA_Win_Cloudeye_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c002 668b1c08 668b140e 6639d3 75e4 83e902 83f900 }
- $sequence_1 = { 7545 66f7c14179 685595db6d e8???????? }
- $sequence_2 = { e8???????? 5f 59 83c628 41 3b8f04080000 75a8 }
- $sequence_3 = { 7408 0185f4000000 eba4 85d8 }
- $sequence_4 = { 89f8 0500080000 50 6aff }
- $sequence_5 = { 6685d2 e8???????? 84ef 80fd37 57 e8???????? 58 }
- $sequence_6 = { c3 38ed 817e24200000e0 7473 }
- $sequence_7 = { 668b00 6631c8 39c8 6631c3 6681fb4d5a 7407 6639c1 }
- $sequence_8 = { 0fbae11f 0f82d63c0000 61 0faee8 0f31 0faee8 c1e220 }
- $sequence_9 = { 75e4 83e902 83f900 7deb ff742404 }
+ $sequence_0 = { 4c895c2438 48895c2430 e8???????? 488d05e4021a00 bb1d000000 e8???????? 488b442450 }
+ $sequence_1 = { 488d05a4bf1700 bb13000000 0f1f440000 e8???????? 8b442414 89c0 e8???????? }
+ $sequence_2 = { e8???????? 488b442428 e8???????? 488d0509dd1700 bb07000000 e8???????? 488b442420 }
+ $sequence_3 = { e9???????? 488d05231a3400 31db 488b6c2458 4883c460 c3 48895c2470 }
+ $sequence_4 = { 7506 48894208 eb09 488d7a08 e8???????? 488bac24f8000000 4881c400010000 }
+ $sequence_5 = { c3 440fb6ac24080a0000 4584ed 0f8471030000 4983fc07 0f85aa010000 4c8b4828 }
+ $sequence_6 = { e8???????? e8???????? 488b4818 488b5820 488b5028 4889c8 4889d1 }
+ $sequence_7 = { 498d7a78 e8???????? 498b9050010000 498b9858010000 498bb060010000 49899a98000000 4989b2a0000000 }
+ $sequence_8 = { 84c0 0f8566feffff 31c0 488b6c2418 4883c420 c3 31c0 }
+ $sequence_9 = { 0f1f00 e8???????? 31db 31c9 488d3d501c0c00 4889c6 31c0 }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <7152640
}
-rule MALPEDIA_Win_Feodo_Auto : FILE
+rule MALPEDIA_Win_Underminer_Ek_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "63743f44-4e6b-5a91-9837-bc3f6dee3649"
+ id = "2ed43350-f854-5062-8561-cad10f7ea1be"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.feodo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.feodo_auto.yar#L1-L175"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.underminer_ek"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.underminer_ek_auto.yar#L1-L176"
license_url = "N/A"
- logic_hash = "b3401747482af4dd4837f27d2a5311953b45c82ad5e6a5cd690191bf7d127342"
+ logic_hash = "39ca462c5e03509c03f5a77251b93a3d7053742d5a8b5f784c7649f495781800"
score = 75
quality = 75
tags = "FILE"
@@ -143846,38 +150747,77 @@ rule MALPEDIA_Win_Feodo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c120 8d51d0 83fa09 7704 8bca eb10 8d519f }
- $sequence_1 = { 6a00 8d542424 52 6a00 ff15???????? 85c0 }
- $sequence_2 = { 7422 83e801 7404 83c8ff c3 8b4c2404 b802000000 }
- $sequence_3 = { 6a00 8d4c240c 51 52 50 8b442414 50 }
- $sequence_4 = { 56 57 33ff 57 6a02 6a02 57 }
- $sequence_5 = { 742f 8b0f 6a01 68???????? 68???????? }
- $sequence_6 = { 50 8b442414 50 ff15???????? 85c0 7405 }
- $sequence_7 = { 6a00 8d942418020000 52 50 }
- $sequence_8 = { 3452 e8???????? 0202 0202 1c83 0000 }
- $sequence_9 = { 229921688d3c 2ee83e207468 60 238b0d03c783 782e 1463 }
- $sequence_10 = { 006c082e 08cc 6969690bc8cc69 690c2e2e0b8ce0 04f7 e10c 206d53 }
- $sequence_11 = { 150d14f452 696969697f3cc3 af e2c3 }
- $sequence_12 = { 041e 6e 18b8161e6e18 b8161e33c9 0000 16 43 }
- $sequence_13 = { 0404 0404 0316 16 }
- $sequence_14 = { 0056b0 2e2801 0bd0 83c4ce 00576a 05c705c07f }
- $sequence_15 = { 007538 034568 3327 325616 }
+ $sequence_0 = { 68d040fa7e 687853fa7e ff742418 ffd0 85c0 }
+ $sequence_1 = { 684c52fa7e 53 ff15???????? 8bf8 85ff 7476 }
+ $sequence_2 = { 1bc0 23c1 83c008 5d c3 8b04c5e48f4200 5d }
+ $sequence_3 = { 884d17 0f8482000000 f6451701 7445 8b4d10 }
+ $sequence_4 = { 68e452fa7e 53 e8???????? 68ef030000 8d4311 68d233fa7e 50 }
+ $sequence_5 = { 51 e8???????? 83c408 8b55dc c745f000000000 }
+ $sequence_6 = { 8b49fc 83c223 2bc1 83c0fc 83f81f 0f87b0130000 52 }
+ $sequence_7 = { f30f7e4110 660fd645f0 c7411000000000 c741140f000000 c60100 837df410 0f4345e0 }
+ $sequence_8 = { 8b4d0c c60102 ebe9 3cbf 770b }
+ $sequence_9 = { 0fb6d1 f604557aa3420001 740f 8b45f0 8b8094000000 }
+ $sequence_10 = { 8bdf 46 ff4d0c c1e010 0fbf16 03d8 8d841a00800000 }
+ $sequence_11 = { 8b34bd6cc64200 eb07 8b34bd38c64200 53 46 }
+ $sequence_12 = { 89451c 7548 803ee8 7559 8b4601 }
+ $sequence_13 = { 6a00 51 50 57 ff15???????? ff75d8 }
+ $sequence_14 = { 49 807dff00 8955ec 894df4 8b0485582c4300 }
+ $sequence_15 = { 5b c9 c3 ff742408 8b442408 ff10 c3 }
+
+ condition:
+ 7 of them and filesize <466944
+}
+rule MALPEDIA_Win_Chiser_Client_Auto : FILE
+{
+ meta:
+ description = "autogenerated rule brought to you by yara-signator"
+ author = "Felix Bilstein - yara-signator at cocacoding dot com"
+ id = "e8afcaec-169c-5519-a609-4458271450b4"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chiser_client"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chiser_client_auto.yar#L1-L124"
+ license_url = "N/A"
+ logic_hash = "3bc0569053961dd359f1e4296146fed96a2d550b29a6ec46396d68a2c22beadc"
+ score = 75
+ quality = 75
+ tags = "FILE"
+ version = "1"
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { 668945b7 488d55b7 488d4dd7 e8???????? b862000000 }
+ $sequence_1 = { 488bcb e8???????? b801000000 4883c430 415e 5f }
+ $sequence_2 = { e8???????? 488d156f390300 488d4c2420 e8???????? cc 48895c2408 4889742410 }
+ $sequence_3 = { ff15???????? 483305???????? 488d15bedf0200 488bcb 488905???????? }
+ $sequence_4 = { 894810 48634810 b802000000 48f7e1 48c7c1ffffffff 480f40c1 }
+ $sequence_5 = { ff15???????? 8bd8 83f801 0f84c7030000 8bc8 83e902 }
+ $sequence_6 = { 4c8d0564070000 eb1e 3d03003000 7509 }
+ $sequence_7 = { 488bc8 488d15a48e0100 ff15???????? 4885c0 0f8432030000 488bc8 e8???????? }
+ $sequence_8 = { 488944246a 89442472 6689442476 c74424502f006900 c74424546e006400 c744245865007800 c744245c2e006800 }
+ $sequence_9 = { 488d1590500200 488d4d20 e8???????? cc 48895d08 4883651000 488b86a8000000 }
condition:
- 7 of them and filesize <270336
+ 7 of them and filesize <714752
}
-rule MALPEDIA_Win_Sidewinder_Auto : FILE
+rule MALPEDIA_Win_Webc2_Greencat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "476f112b-78c8-59d9-8623-54ca0fa7fd69"
+ id = "60cc7c89-f223-5f05-b50e-ef8d73401362"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sidewinder"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sidewinder_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_greencat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_greencat_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "eff1c6e4779cf645096e1bcfd05e39d6cbab1c4bd8a928e81992c305a580a163"
+ logic_hash = "e9fd4938930988d9b35f1bca39290f31fad2f360914fa390eec34fabf9934b56"
score = 75
quality = 75
tags = "FILE"
@@ -143891,32 +150831,32 @@ rule MALPEDIA_Win_Sidewinder_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83a570fdffff00 8b45c4 89853cffffff 8d8544ffffff 50 8b853cffffff 8b00 }
- $sequence_1 = { 50 e8???????? 89852cfbffff e8???????? 8d8568fbffff 50 e8???????? }
- $sequence_2 = { e8???????? 8d45c4 50 8d45a0 50 e8???????? 8d45a0 }
- $sequence_3 = { 8d45e0 50 e8???????? 0fbf45e8 50 ff75e0 e8???????? }
- $sequence_4 = { 7d20 6a30 68???????? ff35???????? ffb534ffffff e8???????? 898504ffffff }
- $sequence_5 = { 8b00 ff7508 ff5004 8b450c 832000 8d45e8 50 }
- $sequence_6 = { e8???????? 8bd0 8d4de8 e8???????? 8d45c8 50 8d45d8 }
- $sequence_7 = { ff5020 dbe2 898528ffffff 83bd28ffffff00 7d1d 6a20 68???????? }
- $sequence_8 = { 8945dc 8d45e4 50 8b45dc 8b00 ff75dc ff5024 }
- $sequence_9 = { ff75b8 ff75d8 6aff 6820110000 e8???????? 83650c00 eb27 }
+ $sequence_0 = { 57 50 e8???????? 59 8bd8 59 eb03 }
+ $sequence_1 = { 59 59 e9???????? ff35???????? ff15???????? 3bc6 }
+ $sequence_2 = { 33f6 895df4 8d450c 50 ff35???????? ff15???????? 817d0c03010000 }
+ $sequence_3 = { 395ddc 752d 391d???????? 7525 3bf3 7521 }
+ $sequence_4 = { e8???????? 83c418 53 6a02 }
+ $sequence_5 = { 8d85fcfeffff 33ff 6804010000 50 }
+ $sequence_6 = { 50 53 ff15???????? 33c9 8945f0 }
+ $sequence_7 = { 8bf0 395ddc 752d 391d???????? 7525 3bf3 7521 }
+ $sequence_8 = { ff75fc ff15???????? 83c428 53 6880000000 }
+ $sequence_9 = { 0fbe4007 83e830 8945f8 8d85f8fdffff 50 }
condition:
- 7 of them and filesize <679936
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Webc2_Adspace_Auto : FILE
+rule MALPEDIA_Win_Smominru_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "31690ec3-53d2-516a-a2ac-2daa7b554ffe"
+ id = "f9ca05ba-f03e-5436-9d57-424a2dfc3ab2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_adspace"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_adspace_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.smominru"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.smominru_auto.yar#L1-L162"
license_url = "N/A"
- logic_hash = "7852a8a7e96f78b645860237edf52acf830636cf13e5faeed5b1eb81bda4c09a"
+ logic_hash = "bda67966371ffe5669f600e524bbc69b988d40d47c3737672a3d574c8f6a0cdf"
score = 75
quality = 75
tags = "FILE"
@@ -143930,32 +150870,38 @@ rule MALPEDIA_Win_Webc2_Adspace_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8580feffff 68???????? 50 ffd6 ff750c 894510 }
- $sequence_1 = { ffd6 8bf8 c70424???????? ffd6 }
- $sequence_2 = { 50 8d8580feffff 50 e8???????? 8b35???????? 8d8580feffff }
- $sequence_3 = { 8d4dec e8???????? 8d4dec e8???????? 6a0a ff15???????? a1???????? }
- $sequence_4 = { c3 56 8b742408 56 e8???????? 59 8b4c2410 }
- $sequence_5 = { 0f84f8010000 80a4241c01000000 6a3f 59 33c0 }
- $sequence_6 = { 7469 6a00 57 56 }
- $sequence_7 = { 50 e8???????? 83c40c 8bf8 8d45fc 50 }
- $sequence_8 = { 59 33c0 85ff 59 }
- $sequence_9 = { a1???????? 40 50 57 56 }
+ $sequence_0 = { 8b474c 894610 8b4750 894614 8b4754 894618 }
+ $sequence_1 = { 0fb7c0 8d4dac 51 50 6a01 }
+ $sequence_2 = { 8bd8 eb06 3b4628 0f94c3 }
+ $sequence_3 = { 0f84694ac17b f6c140 0f856f4ac17b 8ad1 80e23f }
+ $sequence_4 = { 8bd8 eb06 47 ff4df0 }
+ $sequence_5 = { 8bd8 eb02 b301 8bc7 }
+ $sequence_6 = { 8bd8 eb06 ff45f0 4f }
+ $sequence_7 = { 8bd8 eb02 33db 837dfc00 }
+ $sequence_8 = { 6aff e8???????? 85c0 0f8c05e5c07b }
+ $sequence_9 = { ff15???????? 3d03010000 0f8447a0b17b 85c0 0f8c3fa0b17b }
+ $sequence_10 = { 8b37 8975e0 85f6 0f842bfebb7b 83feff 0f8422febb7b 8b5f14 }
+ $sequence_11 = { 8bd8 eb09 55 e8???????? 59 }
+ $sequence_12 = { 0f8c21f7b07b 0fbe75f4 6bf630 e8???????? 8b402c 648b0d18000000 56 }
+ $sequence_13 = { 0f8c79feab7b 8d45c4 50 e8???????? 8b45f0 }
+ $sequence_14 = { 8bd8 e9???????? 8d4df8 8bd7 8bc6 e8???????? 8d4df4 }
+ $sequence_15 = { 8bd8 eb0a 8d45f0 e8???????? }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <8167424
}
-rule MALPEDIA_Win_Lokipws_Auto : FILE
+rule MALPEDIA_Win_Unidentified_094_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "51c802c9-41e6-5018-92e7-bd3c468d0c8a"
+ id = "f5bdd8f3-d974-5222-9555-3631072a29c0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lokipws"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lokipws_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_094"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_094_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "c67ee200474ecbc3881960b10110e8aa7bde902411981013b30687544f7cfcf3"
+ logic_hash = "f3d0ed91e99c9ab03a6ddd24a2a28007a40b7e677077c8b725a5a67f32cc52a7"
score = 75
quality = 75
tags = "FILE"
@@ -143969,32 +150915,32 @@ rule MALPEDIA_Win_Lokipws_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 55 8bec 83ec1c 6a2a 58 6a4d 668945e4 }
- $sequence_1 = { 53 57 a3???????? e8???????? 68???????? 56 }
- $sequence_2 = { 50 688b778dfe 50 e8???????? 8d4df8 }
- $sequence_3 = { 6a00 ff75fc ff35???????? e8???????? 6a00 6a00 }
- $sequence_4 = { 56 ff750c e8???????? 83c40c 85c0 7420 90 }
- $sequence_5 = { 50 ff7508 8975fc e8???????? 8bf8 59 59 }
- $sequence_6 = { 58 66895dc4 668975ca 66897dcc 66895dce 668955d0 66895dd2 }
- $sequence_7 = { 6a02 e8???????? ff750c ff7508 ffd0 5d c3 }
- $sequence_8 = { 668945f2 58 6a6e 668945f6 58 668945fa 33c0 }
- $sequence_9 = { 83fe05 6a02 58 0f47f0 33db 43 3bf3 }
+ $sequence_0 = { 890d???????? 57 8915???????? a3???????? 83ceff b9???????? }
+ $sequence_1 = { 6a5c 68???????? e8???????? 83c408 33c9 }
+ $sequence_2 = { 0fb65004 3015???????? 0fb64805 300d???????? 0fb65006 3015???????? }
+ $sequence_3 = { 83c310 ff4d0c 0f857ffeffff 5f }
+ $sequence_4 = { 0fb65004 3015???????? 0fb64805 300d???????? 0fb65006 3015???????? c3 }
+ $sequence_5 = { 884dff 84d2 7902 341b }
+ $sequence_6 = { 3055fd 0fb61401 3055fe 0fb6540101 3055ff 8b55fc 89540102 }
+ $sequence_7 = { 6a00 6a00 6a00 ff15???????? c3 }
+ $sequence_8 = { 80f31b 8ad3 02d2 84db 7903 80f21b }
+ $sequence_9 = { 890d???????? 57 8915???????? a3???????? }
condition:
- 7 of them and filesize <1327104
+ 7 of them and filesize <524288
}
-rule MALPEDIA_Win_Nozelesn_Decryptor_Auto : FILE
+rule MALPEDIA_Win_Mim221_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5291555a-238b-5124-8c5e-fbe5c6dae533"
+ id = "e2e82536-e29b-53d1-8c95-30ff68363ca9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nozelesn_decryptor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nozelesn_decryptor_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mim221"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mim221_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "1af6964230aa159d6a9d9c0e30b792e1839c5e421f268df94cf1e56da3b12562"
+ logic_hash = "bd7d2b077259a6edc03c8b758f8bad3f5a42643cb60c61d80165934010c8f5e6"
score = 75
quality = 75
tags = "FILE"
@@ -144008,32 +150954,32 @@ rule MALPEDIA_Win_Nozelesn_Decryptor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b459c 8d4dd8 51 8b00 8b701c 8bce e8???????? }
- $sequence_1 = { c7401000000000 c7401407000000 668908 c645fc06 8bb5ccfbffff 85f6 0f848d100000 }
- $sequence_2 = { 8bc1 83e801 747b 83e801 7466 2d0f010000 7416 }
- $sequence_3 = { 3bcf 7c10 7f07 3d???????? 7607 bf???????? eb02 }
- $sequence_4 = { 743f 8b7b0c eb28 8b4608 }
- $sequence_5 = { 8b5508 85d2 7436 8bc2 8945fc 83fa04 721f }
- $sequence_6 = { ff7730 c745fc01000000 8945a0 c645ac00 c645ad00 e8???????? 8d4584 }
- $sequence_7 = { e8???????? 837b3800 884340 7510 8b430c 8bcb 83c804 }
- $sequence_8 = { 33d7 8945e8 33d6 8bf0 c1c20d 33f1 8bc2 }
- $sequence_9 = { 7428 8b03 8d4d90 51 8b7018 8bce e8???????? }
+ $sequence_0 = { 90 4883bc244001000008 720d 488b8c2428010000 e8???????? 4881c420020000 415e }
+ $sequence_1 = { c68424b400000061 4488a424b5000000 c68424b600000064 c68424b70000006c 4488ac24b8000000 c68424b900000046 c68424ba00000072 }
+ $sequence_2 = { 488b8c2400010000 e8???????? e9???????? 4889442420 4d8bcc 4c8b8424f8010000 488bd6 }
+ $sequence_3 = { 57 488bc4 4883ec58 48c7442420feffffff 498bd8 488bf9 }
+ $sequence_4 = { 668944243a 668944243c 668944243e 6689442440 488d542420 488bcf 66c74424420000 }
+ $sequence_5 = { 3d5a290000 7307 b801000000 eb0a 3d39380000 1bc0 83c003 }
+ $sequence_6 = { 66c7803effffff4c00 66b85300 6689842418010000 66c784241a0100004100 6644899c241c010000 66c784241e0100004900 66c78424200100007300 }
+ $sequence_7 = { 4157 4881ec88000000 33ff 498be8 488bf1 4c8bfa }
+ $sequence_8 = { 3d401f0000 7309 8d7b20 448d6b18 eb1b 3db8240000 730b }
+ $sequence_9 = { 488d8c24ca000000 e8???????? c684249003000044 c68424910300008b c684249203000001 c684249303000044 c684249403000039 }
condition:
- 7 of them and filesize <1122304
+ 7 of them and filesize <471040
}
-rule MALPEDIA_Win_Htprat_Auto : FILE
+rule MALPEDIA_Win_Victorygate_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "67b2e8d9-4f49-5cf6-8afe-0a9a5bcb5d69"
+ id = "992c5b2e-f41c-5577-b26b-d319a12e38e1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.htprat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.htprat_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.victorygate"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.victorygate_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "15d5d8ea42e22569434bb0dbf96f0b13036ea7676d82ad93d8f718afb8dd6a66"
+ logic_hash = "ea38784ac607c199e10f70edff21cb5ba2438f5fbaa9d25c8260862ff3bec34e"
score = 75
quality = 75
tags = "FILE"
@@ -144047,34 +150993,34 @@ rule MALPEDIA_Win_Htprat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b8568efffff 03c6 3b8558efffff 7667 8b8394000000 898560efffff 8b8558efffff }
- $sequence_1 = { 8bc7 897dcc e8???????? 8b5dc8 3b5f04 740e }
- $sequence_2 = { 8d4c2418 c68424e800000003 e8???????? 8b00 3bc3 7504 32db }
- $sequence_3 = { 33d2 f3a6 6aff 58 7404 1bd2 1bd0 }
- $sequence_4 = { 46 56 8d8d00ffffff e8???????? 53 56 }
- $sequence_5 = { 85c0 750c e8???????? a3???????? eb13 53 }
- $sequence_6 = { 8b00 8d8d38efffff 51 8d8d08efffff 51 50 ff33 }
- $sequence_7 = { 894584 99 f77d8c 8b4590 8a0402 8b5594 }
- $sequence_8 = { 83c604 3b7734 75ec eb31 83f805 }
- $sequence_9 = { 8d410c 8bcb e8???????? 84c0 0f84d2000000 8b5d0c }
+ $sequence_0 = { 7214 8b49fc 83c223 2bc1 83c0fc 83f81f 0f879a120000 }
+ $sequence_1 = { 8bce c645fc08 e8???????? c645fc01 8b55e8 83fa10 7228 }
+ $sequence_2 = { 8bf8 893b 897b04 03cf 33c0 894b08 eb03 }
+ $sequence_3 = { ff15???????? 85c0 0f8593010000 ff75f8 8d8678020000 6a57 50 }
+ $sequence_4 = { e9???????? 3b0d???????? 7501 c3 e9???????? 55 8bec }
+ $sequence_5 = { 0f8537050000 ff75f8 8d8630020000 6a32 50 }
+ $sequence_6 = { 85c0 7537 b901000000 f00fb10f 85c0 7533 817e340c2b0000 }
+ $sequence_7 = { 8b4128 8b7124 8945b8 3bf0 7436 660f1f440000 8b06 }
+ $sequence_8 = { 57 8b00 8945c4 663908 0f8548060000 8b703c 03f0 }
+ $sequence_9 = { c745fc19000000 83ec18 8b4de0 8bc4 896584 c70000000000 c7401000000000 }
condition:
- 7 of them and filesize <278528
+ 7 of them and filesize <1209344
}
-rule MALPEDIA_Win_Mqsttang_Auto : FILE
+rule MALPEDIA_Win_Volgmer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "37b83f83-ada9-5cb9-9846-c597be16b8c2"
+ id = "6318a069-35e9-5ac9-b46b-f601ef58e4f8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mqsttang"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mqsttang_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.volgmer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.volgmer_auto.yar#L1-L360"
license_url = "N/A"
- logic_hash = "816bebdcfc28d4925b60f084aa814ab97a3079e189efd77c5fe0d0005fa07653"
+ logic_hash = "f927338edc5a7e32548016c88c35f08a0b0dddf5ae3c9ab69c63c8695ae3cd83"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -144086,32 +151032,59 @@ rule MALPEDIA_Win_Mqsttang_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f20f2ac0 f20f5905???????? 660f28c8 660f54ca 660f2ed9 7629 f20f58cb }
- $sequence_1 = { f0832801 8b85c0fdffff 0f845a010000 8b85b4fdffff 89780c 8b400c 85c0 }
- $sequence_2 = { e9???????? 89c7 89d9 89fb e8???????? 89f1 e8???????? }
- $sequence_3 = { ff5074 8b03 83ec04 89d9 8b707c ff5078 890424 }
- $sequence_4 = { e9???????? c74424240a030000 c744242001000000 e9???????? c74424240b030000 c744242000000000 e9???????? }
- $sequence_5 = { e8???????? e9???????? c744240405000000 c70424???????? e8???????? 8d5de4 8b4dd4 }
- $sequence_6 = { e8???????? 8d4c247c e8???????? 8d8c2480000000 e8???????? 8d8c2484000000 e8???????? }
- $sequence_7 = { f6040e10 7441 83c002 47 894338 39bdd8aeffff 77c7 }
- $sequence_8 = { f30f11442430 f20f115c2428 f30f11542420 f30f114c2418 e8???????? f20f106c2438 f20f105c2428 }
- $sequence_9 = { e9???????? c744240cffffffff c7442408???????? 89542404 03400c 890424 e8???????? }
+ $sequence_0 = { 488b4d40 4833cc e8???????? 4c8d9c2450010000 498b5b18 498b7b20 498be3 }
+ $sequence_1 = { 48897c2418 55 488d6c24b0 4881ec50010000 488b05???????? 4833c4 48894540 }
+ $sequence_2 = { e8???????? 488b4dc3 41890424 e8???????? }
+ $sequence_3 = { d1c6 c1c105 03c6 89742404 03c3 }
+ $sequence_4 = { ff15???????? 4885c0 740f 488b4018 488b08 8b01 8905???????? }
+ $sequence_5 = { 8b45b0 488d8dc00f0000 4533c9 4889742430 89442428 ba00000080 c744242003000000 }
+ $sequence_6 = { e8???????? 488bd8 eb03 488bdf 488d056efeffff }
+ $sequence_7 = { 75e9 488d8d90140000 48ffc9 40387101 488d4901 75f6 4c8b45a0 }
+ $sequence_8 = { c6843de011000000 488d8de0110000 e8???????? 488b4c2440 488d95e0110000 ff15???????? 0fb63d???????? }
+ $sequence_9 = { 488d4d60 41b808040000 8bf8 e8???????? ba32d00200 b940000000 ff55e0 }
+ $sequence_10 = { e8???????? 488d8dd2050000 33d2 41b806020000 6689bdd0050000 e8???????? }
+ $sequence_11 = { ff15???????? 85c0 7507 b800000100 eb26 }
+ $sequence_12 = { e8???????? e8???????? e8???????? e8???????? c705????????04000000 }
+ $sequence_13 = { e8???????? 85c0 7466 33d2 488d8c24e4000000 41b804040000 e8???????? }
+ $sequence_14 = { 8bd6 c68435000a000000 488d8d000a0000 e8???????? 488d95000a0000 498bce ff15???????? }
+ $sequence_15 = { eb17 894638 eb0e c74634047b7300 c7463806000000 }
+ $sequence_16 = { 8a07 8b0c9580f16e00 8844192e 8b049580f16e00 804c182d04 }
+ $sequence_17 = { 8b4504 8b4d0c 6a00 52 }
+ $sequence_18 = { 8b048dd4926d00 ffe0 f7c703000000 7413 8a06 8807 }
+ $sequence_19 = { e9???????? c745dc02000000 c745e0e4ba7300 8b4508 8bcf }
+ $sequence_20 = { 83c408 85f6 0f84b7010000 8bce 8d85d0fdffff }
+ $sequence_21 = { 03048d80f16e00 50 ff15???????? 5d c3 8bff }
+ $sequence_22 = { 50 68???????? ff7708 ff95e4f3ffff 817f1400008000 89470c 751c }
+ $sequence_23 = { 5f 5e c684101803000000 5b }
+ $sequence_24 = { 8a4c2428 8d442428 3acb 741a }
+ $sequence_25 = { 40 c745ecb8996d00 894df8 8945fc 64a100000000 8945e8 8d45e8 }
+ $sequence_26 = { 50 52 56 6a00 68e9fd0000 ff95e8f3ffff ff7714 }
+ $sequence_27 = { 50 51 53 53 6800000008 }
+ $sequence_28 = { ff15???????? 8d442408 50 ff15???????? 85c0 5f 740c }
+ $sequence_29 = { ba???????? 2bd1 668b0c02 6685c9 }
+ $sequence_30 = { c745dc03000000 c745e0e0ba6e00 e9???????? 83e80f 7451 }
+ $sequence_31 = { 33d2 05d9e7ffff 56 83f815 0f8711010000 ff2485786b6d00 51 }
+ $sequence_32 = { 8a01 41 84c0 75f9 6a00 2bca 8d85d0f5ffff }
+ $sequence_33 = { 8d0d90b87300 ba1b000000 e9???????? a900000080 7517 ebd4 a9ffff0f00 }
+ $sequence_34 = { e9???????? 894ddc c745e0d8ba6e00 e9???????? c745e0d4ba6e00 eba2 894ddc }
+ $sequence_35 = { 8b4de8 8b048580f16e00 f644082840 7409 }
+ $sequence_36 = { 396c2434 750b 396c2430 7505 }
condition:
- 7 of them and filesize <12651520
+ 7 of them and filesize <393216
}
-rule MALPEDIA_Win_Zhcat_Auto : FILE
+rule MALPEDIA_Win_Ransomlock_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0ba2d083-15f8-52b3-8a0e-523b48182ccb"
+ id = "14d92420-c852-5e3f-a3ed-35c5bfb9c9b6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zhcat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zhcat_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ransomlock"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ransomlock_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "42a0cd82873743b61553ad212467ec7353604cc191810d2e10195e3fc58baf2d"
+ logic_hash = "febe0932e68debf15b0eb0e37d5a00d2ff8a7e3a0c0b884f506cda6ff33b2a0c"
score = 75
quality = 75
tags = "FILE"
@@ -144125,32 +151098,32 @@ rule MALPEDIA_Win_Zhcat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b3d???????? 8b7508 4f 8945fc }
- $sequence_1 = { 741e 8d45f8 8975f8 50 85ff 750a }
- $sequence_2 = { 85c9 759e 56 e8???????? 59 }
- $sequence_3 = { 85c9 759e 56 e8???????? 59 5f 5e }
- $sequence_4 = { 3c74 7404 3c54 7512 8915???????? eb0a }
- $sequence_5 = { 68???????? 56 56 897004 ffd3 6aff }
- $sequence_6 = { ff7508 ff15???????? ff7514 8945e4 8bc7 668945f0 ffd6 }
- $sequence_7 = { eb28 c705????????02000000 eb1c c605????????01 }
- $sequence_8 = { 0fb63e 0fb6c0 eb12 8b45e0 8a80044a4100 08443b1d 0fb64601 }
- $sequence_9 = { ff7508 ff15???????? 57 8bf0 e8???????? 59 5f }
+ $sequence_0 = { 50 e8???????? 83c408 8b0d???????? 6a64 51 ff15???????? }
+ $sequence_1 = { 99 2bc2 6a00 8bd1 d1ea d1f8 }
+ $sequence_2 = { 8b5120 56 50 ffd2 85c0 7807 c745ec01000000 }
+ $sequence_3 = { 0f8418010000 8b08 8d55fc 52 50 8b4120 }
+ $sequence_4 = { 0fb7047521664000 4e 6685c0 75ec 57 68???????? ffd3 }
+ $sequence_5 = { 50 ff15???????? 83c410 6a01 53 }
+ $sequence_6 = { 57 ff15???????? 8d70ff 0fb70477 6685c0 7413 8bff }
+ $sequence_7 = { 90 68???????? 33f6 ff15???????? a1???????? 85c0 7429 }
+ $sequence_8 = { 8b45f0 3bc6 0f8418010000 8b08 8d55fc 52 50 }
+ $sequence_9 = { 52 8d8574fdffff 68???????? 50 ff15???????? 83c410 6a01 }
condition:
- 7 of them and filesize <376832
+ 7 of them and filesize <360448
}
-rule MALPEDIA_Win_Isaacwiper_Auto : FILE
+rule MALPEDIA_Win_Dripion_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1329030c-897c-5c01-8c07-662be913ab23"
+ id = "89e91029-adf0-5373-91d6-441ac823d2ed"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.isaacwiper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.isaacwiper_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dripion"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dripion_auto.yar#L1-L108"
license_url = "N/A"
- logic_hash = "ed4c1277cdfb0687c916d7f4c8800e6899b857de5108f3daf478ca99ea587637"
+ logic_hash = "6b099e3758909dfda12afb8709370979b2c037becc9af1305c25dce794b98386"
score = 75
quality = 75
tags = "FILE"
@@ -144164,32 +151137,32 @@ rule MALPEDIA_Win_Isaacwiper_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 771b 52 51 e8???????? 83c408 5f c706???????? }
- $sequence_1 = { b804000000 33d2 395138 0f45c2 0b410c 0bc3 50 }
- $sequence_2 = { 8d0471 3bc8 7319 8d46ff }
- $sequence_3 = { 5b 8be5 5d c3 6a34 e8???????? 8bf0 }
- $sequence_4 = { 7576 eb56 8b0485d89e0210 6800080000 6a00 50 8945fc }
- $sequence_5 = { 744a 83c118 57 8b7d14 894d08 0f1f4000 }
- $sequence_6 = { 81ecc8090000 56 57 8bf1 c745f800000000 ff15???????? 898538f6ffff }
- $sequence_7 = { 6685f6 743e 6a00 8bd6 8bcf e8???????? 8ad0 }
- $sequence_8 = { 85db 0f8454010000 8bc6 83e001 03c8 d1ee }
- $sequence_9 = { 8bf8 83e03f c1ff06 6bd038 8b34bde8670310 8a441628 }
+ $sequence_0 = { ffd6 8bf8 ffd6 0faff8 ffd6 }
+ $sequence_1 = { 03f8 7402 ffd6 ffd6 }
+ $sequence_2 = { ffd6 8bf8 ffd6 0faff8 8d3c7f }
+ $sequence_3 = { 03f8 ffd6 8bd8 ffd6 0fafd8 ffd6 }
+ $sequence_4 = { ffd6 03f8 8d3c7f ffd6 }
+ $sequence_5 = { 7513 6a64 ff15???????? 68???????? }
+ $sequence_6 = { 8bf8 ffd6 0faff8 8d3c7f }
+ $sequence_7 = { ffd6 03f8 ffd6 8bd8 }
+ $sequence_8 = { 7402 ffd6 ffd6 ffd6 }
+ $sequence_9 = { ffd6 03f8 7402 ffd6 }
condition:
- 7 of them and filesize <467968
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Win_Unidentified_044_Auto : FILE
+rule MALPEDIA_Win_Rorschach_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a037a55a-a1d2-5696-aa65-bcad92ff6480"
+ id = "1c4aea68-8f40-596d-a63a-efb95cb498a7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_044"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_044_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rorschach"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rorschach_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "fa0bbb48e3a00969b6207e7af2c24fceeabe6227dd53aafea6a4369ea97af4c2"
+ logic_hash = "0cdb3537df7f12a9076109ea202e9af8c6db5ccfaaca59c4a71971579385ead3"
score = 75
quality = 75
tags = "FILE"
@@ -144203,32 +151176,32 @@ rule MALPEDIA_Win_Unidentified_044_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bca 8bd8 e8???????? 83c404 84c0 7409 668b542408 }
- $sequence_1 = { 3bcf 7416 8d9b00000000 80792400 7403 }
- $sequence_2 = { c3 8b8424e4020000 6a10 6a00 50 }
- $sequence_3 = { 74b3 33ff 397c2418 76ab 33c0 }
- $sequence_4 = { ff15???????? 3d1e270000 7552 8b442408 85c0 }
- $sequence_5 = { 2bf0 03d8 85f6 7fe2 }
- $sequence_6 = { 803e00 8be8 743f 53 57 }
- $sequence_7 = { ffd5 8bb42464050000 85c0 7f85 7c24 f644242420 0f8468feffff }
- $sequence_8 = { c7460403000000 ffd3 5b 5f 32c0 5e }
- $sequence_9 = { 55 e8???????? 83c40c 84c0 74a0 8a442413 }
+ $sequence_0 = { 33d2 488d8df8020000 e8???????? 88850e030000 b26e 488d8df8020000 e8???????? }
+ $sequence_1 = { f65d7f 488d15ece30000 4c8d05e9e30000 488955df 488d05d2e30000 488955e7 488945bf }
+ $sequence_2 = { f5 66d3f7 66c1f703 d3d7 4801e3 d2f0 c0f807 }
+ $sequence_3 = { f30f7f4de0 660f6f05???????? f30f7f45f0 660f6f0d???????? f30f7f4d00 c74510771a771b c6451477 }
+ $sequence_4 = { 0c40 8845df e8???????? 4c8d05e8180700 488d55c0 488d4da0 e8???????? }
+ $sequence_5 = { 33c0 48894310 48c7431807000000 668903 488b4c2458 4833cc e8???????? }
+ $sequence_6 = { 33d2 488d4da8 e8???????? 8845b4 b272 488d4da8 e8???????? }
+ $sequence_7 = { e8???????? 88851e0b0000 b265 488d8de0080000 e8???????? 88851f0b0000 33d2 }
+ $sequence_8 = { e8???????? c60000 ba0f000000 488d4d99 e8???????? c60000 488d4d99 }
+ $sequence_9 = { f6d4 660fbec0 0f98c0 488d7f01 0fb6c0 0f94c4 88f0 }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <3921930
}
-rule MALPEDIA_Win_Misfox_Auto : FILE
+rule MALPEDIA_Win_Glassrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "927dd41c-de40-5a62-bc60-3c93a08d5568"
+ id = "daeaa019-8217-55aa-beac-5fb62572b79c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.misfox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.misfox_auto.yar#L1-L171"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.glassrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.glassrat_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "73f8e08e5f0adb2064a67b9bd6b00ebff7c94d43d789ff956746926b45ea1124"
+ logic_hash = "c91259f84ec94eec4bc87c666b3c91ba45af3572c135cc4f200070d560141e5d"
score = 75
quality = 75
tags = "FILE"
@@ -144242,38 +151215,32 @@ rule MALPEDIA_Win_Misfox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb6a 56 e8???????? 59 8365fc00 8b049d50870110 }
- $sequence_1 = { 3de4000000 7309 8b04c598230110 5d c3 33c0 5d }
- $sequence_2 = { c705????????01000000 6a04 58 6bc000 8b4d08 8988ac830110 }
- $sequence_3 = { 50 e8???????? 83c40c 6b45e430 8945e0 8d8020770110 8945e4 }
- $sequence_4 = { c745e4ec900110 a1???????? 33db 43 895de0 50 }
- $sequence_5 = { ff37 c745b800000000 53 6a00 51 }
- $sequence_6 = { 8b45b8 52 c70300000000 40 ff37 8945b8 }
- $sequence_7 = { 0f8515010000 51 ba00020000 c744244800080000 8d4c2434 89442444 }
- $sequence_8 = { 48c7c101000080 c7450b00020000 4889442420 44897507 ff15???????? }
- $sequence_9 = { 458bc5 488d9530060000 4803d0 488b442448 488d0dc6da0000 }
- $sequence_10 = { 488b4c2470 48894b10 48895318 e9???????? 488d5720 }
- $sequence_11 = { 488985a0040000 4c8b95f8040000 488d052ce00000 4c8bd9 488d4c2430 }
- $sequence_12 = { f0ff0b 7516 488d0564520100 488b4c2430 483bc8 }
- $sequence_13 = { 488d15fdbc0000 483305???????? 488bcb 488905???????? ff15???????? 488d15f7bc0000 }
- $sequence_14 = { ff15???????? 85c0 7547 488b0f 488d15dd6b0100 }
- $sequence_15 = { 753e 0fb65530 0fb64531 66410fafd5 }
+ $sequence_0 = { 8d542438 83c9ff 33c0 f2ae f7d1 2bf9 8bc1 }
+ $sequence_1 = { ff15???????? 33c0 8b5504 8944241d 8d4c241c }
+ $sequence_2 = { 747a 3bfe 7476 56 56 56 53 }
+ $sequence_3 = { 895db8 895dbc ff15???????? 85c0 0f84bb000000 }
+ $sequence_4 = { 3bc8 b802000000 0f85b4000000 33d2 b909020000 52 83ec10 }
+ $sequence_5 = { 6a04 51 52 8844243b }
+ $sequence_6 = { 8b460c 53 53 57 50 }
+ $sequence_7 = { 8bce ff12 57 ff15???????? 8d4c2420 }
+ $sequence_8 = { 89442418 ff15???????? 8b4d04 8b1d???????? }
+ $sequence_9 = { 89442408 89542404 8a15???????? 33c0 }
condition:
- 7 of them and filesize <266240
+ 7 of them and filesize <81920
}
-rule MALPEDIA_Win_Covid22_Auto : FILE
+rule MALPEDIA_Win_Xpertrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c5fffc59-fc04-58e5-a2b5-2bc6fea3300e"
+ id = "5a6115a3-5806-5873-b6ce-1ac58a01949b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.covid22"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.covid22_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xpertrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xpertrat_auto.yar#L1-L159"
license_url = "N/A"
- logic_hash = "905302ef095dc2c070563a8e4e5a8650bbd8c803b32ba6a0b53beb2cdcb2cfaa"
+ logic_hash = "c8887b0fd33237ed86a90a507f71d2f7eed9cc8f7e7e530376d7c59ae0763d11"
score = 75
quality = 75
tags = "FILE"
@@ -144287,32 +151254,38 @@ rule MALPEDIA_Win_Covid22_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b35???????? 7507 6af6 ffd6 894514 395d18 7507 }
- $sequence_1 = { 50 8b4508 ff30 ff15???????? 8b45fc c9 }
- $sequence_2 = { 5a e8???????? ff35???????? 6801000000 e8???????? 21c0 }
- $sequence_3 = { e8???????? ba???????? 8d0d30b24000 e8???????? ba???????? 8d0d34b24000 e8???????? }
- $sequence_4 = { 0fb6540c02 83e20f 0fb692e0904000 885005 0fb6540c03 c1ea04 0fb692e0904000 }
- $sequence_5 = { ff35???????? e8???????? 21c0 0f846f020000 a1???????? }
- $sequence_6 = { 50 a1???????? 50 50 e8???????? ff05???????? ff35???????? }
- $sequence_7 = { b801000000 eb02 31c0 21c0 0f8409020000 a1???????? }
- $sequence_8 = { e8???????? c21000 8b442404 85c0 7413 ff742408 ff30 }
- $sequence_9 = { 83c404 6801000000 e9???????? 8b15???????? 31c9 e8???????? 750b }
+ $sequence_0 = { 0870ff 0d80000700 0474 ff0478 }
+ $sequence_1 = { ff0a 250004003c 6c 70ff 0808 }
+ $sequence_2 = { ff05???????? 000d???????? 0878ff 0d98000700 6e 74ff }
+ $sequence_3 = { 0808 008f38001b26 001b 0d002a2364 ff08 }
+ $sequence_4 = { ff4d40 ff08 40 0430 ff0a 4c 000c00 }
+ $sequence_5 = { 0000 00a1cc004400 0bc0 7402 ffe0 68???????? }
+ $sequence_6 = { 0808 008a3800cc1c 5e 006c70ff 0808 }
+ $sequence_7 = { 007168 ff0468 ff0a 250004003c }
+ $sequence_8 = { ff15???????? 68fffe0000 ffd3 8bd0 }
+ $sequence_9 = { ff15???????? 68???????? ffd7 8b1d???????? }
+ $sequence_10 = { ff15???????? 6a00 6818000368 8b4508 }
+ $sequence_11 = { ff15???????? 68???????? ff15???????? 50 8d858cfeffff }
+ $sequence_12 = { ff15???????? 69c0e8030000 0f80b50a0000 50 }
+ $sequence_13 = { ff15???????? 6a00 6822000360 8b03 }
+ $sequence_14 = { ff15???????? 6a00 68???????? 6a00 68???????? 8b55e0 }
+ $sequence_15 = { ff15???????? 6a00 6806000368 8b4dd4 }
condition:
- 7 of them and filesize <1955840
+ 7 of them and filesize <8560640
}
-rule MALPEDIA_Win_Metastealer_Auto : FILE
+rule MALPEDIA_Win_Ironhalo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cdc28210-4a73-5ebc-92c2-e9cca60e6ba0"
+ id = "2d227622-166f-50b3-a1ee-3f19a045e93e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.metastealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.metastealer_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ironhalo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ironhalo_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "6d21821c6e275cca2327e10c362ceb42915cf515b000f17d28567b39e609820e"
+ logic_hash = "ff7e4c197682c2fb1b52bad6a60a31bcbdcc6f7acd7ddda36a5021d06aae5146"
score = 75
quality = 75
tags = "FILE"
@@ -144326,32 +151299,32 @@ rule MALPEDIA_Win_Metastealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff7710 50 e8???????? 8b4718 8d4b1c 894318 8d471c }
- $sequence_1 = { 8b4220 894620 8d4228 894224 897a20 c70700000000 8bc6 }
- $sequence_2 = { 8d4dd8 e8???????? c745fc00000000 8d45d8 68a3000000 68???????? 68???????? }
- $sequence_3 = { 8b4104 894610 8b4104 8b400c 85c0 740c 89460c }
- $sequence_4 = { eb0a c70600000000 c6460401 8a45ae 8b7d9c 8845af 660f1f440000 }
- $sequence_5 = { eb0e 0f57c0 660f1345d4 8b7dd8 8b75d4 51 8d4dd4 }
- $sequence_6 = { ff7314 68???????? 56 e8???????? 68???????? 56 e8???????? }
- $sequence_7 = { ffd0 83c40c 85c0 7407 be01000000 eb02 33f6 }
- $sequence_8 = { d945fc 5e 8be5 5d c3 8d8100000038 0bc6 }
- $sequence_9 = { c7411000000000 c7411400000000 837e1408 8975d0 7205 8b16 8955d0 }
+ $sequence_0 = { 808821cf400008 40 3dff000000 72f1 }
+ $sequence_1 = { 33c0 8d7c245c 53 f3ab 8d4c2460 6a07 51 }
+ $sequence_2 = { 6a00 6a00 50 6a00 66c744246c0000 c744246801010000 }
+ $sequence_3 = { 8d542410 8d442424 52 50 ffd6 }
+ $sequence_4 = { 52 aa e8???????? 8dbc2434020000 }
+ $sequence_5 = { 5d c3 8b4c2404 f7c103000000 7414 8a01 41 }
+ $sequence_6 = { 3b35???????? 0f83c5010000 8bc6 83e61f c1f805 c1e603 8d1c8560e04000 }
+ $sequence_7 = { 8816 46 eb0f 0fb6d2 f68221cf400004 7403 40 }
+ $sequence_8 = { 8d542460 68???????? 52 ffd6 8d442460 68???????? 50 }
+ $sequence_9 = { 75d1 55 ff15???????? 5e 5f }
condition:
- 7 of them and filesize <26230784
+ 7 of them and filesize <131072
}
-rule MALPEDIA_Win_Httpdropper_Auto : FILE
+rule MALPEDIA_Win_Soundbite_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "eb6cb470-4fa5-55f1-aaf4-34eabe7782e1"
+ id = "080e0f3d-446d-56c0-ac80-bd020f7550e1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.httpdropper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.httpdropper_auto.yar#L1-L165"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.soundbite"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.soundbite_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "c6973c071283bf0dc986d288edaa8567196f172f5da7a23c655925f94d3c03cb"
+ logic_hash = "dd4f6a00eb49b6e49c1bd5e71a528f06fe40aa9dfa91442cca75ad1ce88ee58a"
score = 75
quality = 75
tags = "FILE"
@@ -144365,38 +151338,32 @@ rule MALPEDIA_Win_Httpdropper_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4c243c 51 8d54241c 52 53 }
- $sequence_1 = { 51 6a00 6a00 68???????? 52 c745f404000000 }
- $sequence_2 = { 7506 c60100 49 ebec 8bc3 }
- $sequence_3 = { e8???????? 6804010000 8d95edfdffff 6a00 52 c685ecfdffff00 }
- $sequence_4 = { 7414 57 c6470300 e8???????? 83c404 }
- $sequence_5 = { 51 8d95ecf8ffff 68???????? 52 e8???????? 8d85f4fdffff }
- $sequence_6 = { 6802000080 ff15???????? 8b85d8fbffff 8d8ddcfbffff 51 }
- $sequence_7 = { c685d4f4ffff00 e8???????? 57 68ff030000 }
- $sequence_8 = { 33c0 ba01000000 f2ae 448bc2 48f7d1 48ffc9 }
- $sequence_9 = { 48c7c102000080 4889442438 48897c2430 c74424283f000f00 897c2420 }
- $sequence_10 = { 33d2 41b804010000 c68424f000000000 e8???????? 488d15520f0200 488d8c24f0000000 }
- $sequence_11 = { 488bfb 488d73ff f2ae 48f7d1 48ffc9 }
- $sequence_12 = { 0fb7cd 4889442428 6689742428 4889442430 ff15???????? 488bcf }
- $sequence_13 = { e8???????? 488d8d81040000 33d2 41b87f0c0000 }
- $sequence_14 = { c1e808 418bd1 4032c7 4a0fbebc35da020000 81e2fdff0000 }
- $sequence_15 = { 488d4df0 e8???????? b801000000 e9???????? }
+ $sequence_0 = { 8b5518 48 89451c 8b4a08 3bc8 7702 2bc1 }
+ $sequence_1 = { c1e81f 8d4c02ff 398dd4fcffff 7d1f }
+ $sequence_2 = { ff15???????? 8a4e02 8066030f 0fb7c0 240f 02c0 02c0 }
+ $sequence_3 = { e8???????? 83c428 8d7de0 e8???????? 8b450c 8b4d18 8b5514 }
+ $sequence_4 = { c745f0c4e9f2e5 c745f4e3f4eff2 66c745f8f900 894dc0 c745c4d3ffc8ff c745c8c5ffccff c745ccccffb3ff }
+ $sequence_5 = { 49 894d18 3bc1 7437 8b7d14 8b5708 }
+ $sequence_6 = { 8b4d08 8b550c 8d0411 83f802 }
+ $sequence_7 = { 7702 2bc2 8b5104 8b3c82 8b4d2c 8b5528 51 }
+ $sequence_8 = { 68???????? ff15???????? 8b7508 c7465ca0634200 83660800 33ff 47 }
+ $sequence_9 = { 8d75a0 e8???????? 8b5da0 8b4da4 8bc3 2bc1 }
condition:
- 7 of them and filesize <524288
+ 7 of them and filesize <409600
}
-rule MALPEDIA_Win_Badencript_Auto : FILE
+rule MALPEDIA_Win_Deputydog_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "14e6e038-56f2-594e-a7b6-4f5872213cea"
+ id = "3ae1b77f-6003-5f42-85fd-2473ea8bd4ab"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badencript"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.badencript_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.deputydog"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.deputydog_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "2996c0cacc073d062d9370be45e59795727eb489c538600d3d982f614b0ed8f2"
+ logic_hash = "027f4c297ed3d9095922a3567db93a8700528916bc6b48fe318198129cac1716"
score = 75
quality = 75
tags = "FILE"
@@ -144410,32 +151377,32 @@ rule MALPEDIA_Win_Badencript_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bfe a1???????? 897de0 394508 7c1f 3934bd48414100 }
- $sequence_1 = { 8a07 8b0c9548414100 8844192e 8b049548414100 }
- $sequence_2 = { 6af6 ff15???????? 8b04bd48414100 834c0318ff 33c0 eb16 e8???????? }
- $sequence_3 = { 53 ffd7 83ee01 75eb 8b4dfc 33c0 }
- $sequence_4 = { 8b049d48414100 8945d4 8955e8 8a5c1029 80fb02 7405 80fb01 }
- $sequence_5 = { 660fd60f 8d7f08 8b048d04b54000 ffe0 f7c703000000 }
- $sequence_6 = { 8b049548414100 f644082801 740b 56 e8???????? 59 }
- $sequence_7 = { 0f859b010000 c745e0980f4100 8b4508 8bcf 8b7510 c745dc01000000 dd00 }
- $sequence_8 = { 58 6bc000 c7809439410002000000 6a04 }
- $sequence_9 = { 50 8b04bd48414100 ff743018 ff15???????? 85c0 0f95c0 5f }
+ $sequence_0 = { 51 56 8bf1 8b461c 8d4e18 ff30 8d45fc }
+ $sequence_1 = { 85ff 7407 8b5510 8a12 8817 }
+ $sequence_2 = { 53 8d4de0 ff15???????? 807df300 7509 }
+ $sequence_3 = { 57 56 e8???????? 83c40c 8d4604 c60664 50 }
+ $sequence_4 = { 8d4580 50 e8???????? 8b4004 59 3bc3 59 }
+ $sequence_5 = { 6a00 56 ff7604 50 ff15???????? 8365f000 6800200000 }
+ $sequence_6 = { 8b7e08 8d1419 397d08 7417 8bc2 2bc1 2bc3 }
+ $sequence_7 = { 8b4d0c 57 ff30 6a00 ff15???????? 8b7d08 8b4f04 }
+ $sequence_8 = { 53 51 ff75e4 50 ff7618 ff15???????? 8b3d???????? }
+ $sequence_9 = { 57 50 ff15???????? 59 84c0 59 740b }
condition:
- 7 of them and filesize <335872
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Win_Gamotrol_Auto : FILE
+rule MALPEDIA_Win_Netkey_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a4423f00-4d12-5905-ae9f-2ac00b302637"
+ id = "76292b9d-6066-51f2-940c-21859c007253"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gamotrol"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gamotrol_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.netkey"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.netkey_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "dbb5086714c8814bb752b80e0051cf0358b1814ba2516480704e9248f4a5718d"
+ logic_hash = "0ca26012e9d146d53c4ba2a355f1655827a5f40d6a52c39d2206e16c6e4d6ec5"
score = 75
quality = 75
tags = "FILE"
@@ -144449,32 +151416,32 @@ rule MALPEDIA_Win_Gamotrol_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5e c3 6a04 b8???????? e8???????? e8???????? 50 }
- $sequence_1 = { ff15???????? 8b4b54 6a04 6800100000 51 56 }
- $sequence_2 = { 90 8bec 85f6 41 49 6843700000 83c40a }
- $sequence_3 = { 6aff 68???????? 68???????? 6a00 ff15???????? 6a00 53 }
- $sequence_4 = { 8be5 90 5d 6803010000 }
- $sequence_5 = { 8d9540fbffff 52 68???????? ffd6 33c0 8945ad 8945b1 }
- $sequence_6 = { c6854fffffff61 c68550ffffff67 889d51ffffff c68552ffffff56 c68553ffffff69 889d54ffffff }
- $sequence_7 = { 0fbec2 0fb680a0ed2e00 83e00f 8b4db8 6bc009 0fb68408c0ed2e00 6a08 }
- $sequence_8 = { 8b01 57 ff5004 5f 5e c3 8b442404 }
- $sequence_9 = { 49 41 49 90 8be5 90 }
+ $sequence_0 = { 83c40c 83c208 8bca 81e11f000080 7905 49 }
+ $sequence_1 = { 83e03f c1ff06 6bd830 8b04bda8214400 f644032801 7444 837c0318ff }
+ $sequence_2 = { 81ec98010000 a1???????? 33c4 89842494010000 b9???????? e8???????? 8d0424 }
+ $sequence_3 = { 83c404 85ff 0f84c7000000 57 53 6a00 56 }
+ $sequence_4 = { 8bc2 8955fc 99 83e21f 8d0c02 c1f905 }
+ $sequence_5 = { 6a01 8845e8 8d45e8 57 50 c745c801000000 e8???????? }
+ $sequence_6 = { 42 668955ec e8???????? 99 be3b000000 f7fe }
+ $sequence_7 = { 780d b801000000 5f 5e 5b 59 }
+ $sequence_8 = { 83c8ff eb07 8b04cd8c6a4300 5f 5e 5b 8be5 }
+ $sequence_9 = { 8d8fd8000000 e8???????? 0f1005???????? 8d95f0fbffff 8d4a01 0f1185f0fbffff }
condition:
- 7 of them and filesize <376832
+ 7 of them and filesize <606208
}
-rule MALPEDIA_Win_Younglotus_Auto : FILE
+rule MALPEDIA_Win_Graphical_Neutrino_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "020c6ff6-d6bb-58fb-b2fa-0c433bea2123"
+ id = "b16102ee-c7a4-5abc-870b-b75814e7493c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.younglotus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.younglotus_auto.yar#L1-L165"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphical_neutrino"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graphical_neutrino_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "b3707e8b206f95395dc2e356973108894d4afdfd30bcae58d7d87fd0cefdf956"
+ logic_hash = "650397c4d3167e6ec1c66b8947fe66982f57b8190e3a878616091180b7325b66"
score = 75
quality = 75
tags = "FILE"
@@ -144488,38 +151455,32 @@ rule MALPEDIA_Win_Younglotus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6802000080 e8???????? 83c41c 6a01 }
- $sequence_1 = { e8???????? 2b450c 50 8b4dfc }
- $sequence_2 = { 8b45e0 25ff000000 e9???????? c745e401000000 8b550c }
- $sequence_3 = { 50 ff15???????? 8b4dfc 8981a4000000 68???????? }
- $sequence_4 = { 50 8b4d0c 81e970010000 51 }
- $sequence_5 = { 83bda4faffff00 751b 68???????? 8d85a8faffff 50 ff15???????? 83c408 }
- $sequence_6 = { 6804010000 6a00 8d8da8faffff 51 6a01 6a00 }
- $sequence_7 = { 83c40c 8b45fc 83c00f 8945f8 6a03 }
- $sequence_8 = { 56 57 68???????? ff15???????? 8945dc 68???????? }
- $sequence_9 = { 50 ffd3 85c0 8945fc 0f84b7000000 }
- $sequence_10 = { 68???????? ffd6 ff7508 e8???????? 8bf8 59 85ff }
- $sequence_11 = { ff7508 50 e8???????? 8d430f }
- $sequence_12 = { 50 8945f4 ffd6 8d4df8 }
- $sequence_13 = { 6a01 53 ff15???????? 8b4de8 6a03 }
- $sequence_14 = { 8945e8 ffd6 68???????? 8945ec ffd7 68???????? }
- $sequence_15 = { ffd0 50 ff55f0 85c0 746f 8b450c }
+ $sequence_0 = { 4489c7 4889f2 48c7410800000000 4531c0 4889d9 4c8d6c2450 e8???????? }
+ $sequence_1 = { ff15???????? 4883fe10 7f1c 41b828400000 }
+ $sequence_2 = { 48c78424c800000002000000 48898424c0000000 e8???????? 4c8da424c0000000 488d842460050000 48c78424c800000002000000 }
+ $sequence_3 = { eb07 b001 80fa09 7478 }
+ $sequence_4 = { 8806 488d4602 885601 eb2d b964000000 }
+ $sequence_5 = { 53 4883ec20 4c8b6108 4889cb 4c3b6110 740f }
+ $sequence_6 = { ebcc 31db 4c89ea 4c89e1 4189de ffc3 }
+ $sequence_7 = { 7430 c605????????01 31c0 8a1403 881406 48ffc0 4883f81f }
+ $sequence_8 = { 4155 4154 53 4883ec20 c60100 4889cb 4989d5 }
+ $sequence_9 = { bd07000000 eb32 41b9a0860100 bd06000000 eb25 41b910270000 bd05000000 }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <674816
}
-rule MALPEDIA_Win_Albaniiutas_Auto : FILE
+rule MALPEDIA_Win_Lambload_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "59f4d909-2fdf-5b2b-b2d0-e08828d007ee"
+ id = "ca98537a-be45-5b55-a54c-745fd9ea79b6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.albaniiutas"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.albaniiutas_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lambload"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lambload_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "121e552bf42e7769ddf3d97832d0aa4668207291feb4416fe4bffab1efac2c40"
+ logic_hash = "6692a5aefbbf1fabc4e1d13310c5f00b33c64ae692d0893f079fb461da4727d8"
score = 75
quality = 75
tags = "FILE"
@@ -144533,32 +151494,32 @@ rule MALPEDIA_Win_Albaniiutas_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c745f800000000 50 8bf2 c745f400000000 8bf9 }
- $sequence_1 = { c1f906 6bc030 03048d90df0210 50 ff15???????? 5d c3 }
- $sequence_2 = { 23c1 eb57 53 8b1c85c8540110 }
- $sequence_3 = { c705????????01000000 c705????????01000000 6a04 58 6bc000 c7806cda021002000000 6a04 }
- $sequence_4 = { 59 83cfff 897de4 8365fc00 8b049d90df0210 8b4de0 f644082801 }
- $sequence_5 = { 898850030000 8b4508 59 c74048c0a40110 8b4508 6689486c }
- $sequence_6 = { 68???????? ffd6 68???????? 8d45d4 c745d400000000 50 e8???????? }
- $sequence_7 = { 83e801 0f8580000000 8b4508 dd00 ebc6 c745e0f87c0110 }
- $sequence_8 = { 660fd60f 8d7f08 8b048dd46a0010 ffe0 f7c703000000 7413 }
- $sequence_9 = { 33048dc01c0110 0fb6ca 33048dc0280110 ff4d08 0f8502feffff 83ff04 }
+ $sequence_0 = { ffb5e4f7ffff e8???????? 0fb74624 57 57 6a03 }
+ $sequence_1 = { ff15???????? 47 83ff02 7caa 83c8ff 5f 5e }
+ $sequence_2 = { 74c5 57 57 57 ff7608 ff15???????? 85c0 }
+ $sequence_3 = { 8b6c2424 83c408 3be8 7e02 8be8 }
+ $sequence_4 = { 897dfc 897dd8 83ff40 0f8d3b010000 8b34bd00490710 85f6 }
+ $sequence_5 = { 83c420 837e1804 750d b800308000 }
+ $sequence_6 = { f7f9 8955fc e8???????? 99 b9ffff0000 f7f9 }
+ $sequence_7 = { be???????? 50 a5 e8???????? 83c40c }
+ $sequence_8 = { 0fb78c05ecfbffff 66898c05f4fdffff 83c002 663bce 75e8 53 8d85ecfbffff }
+ $sequence_9 = { 33c0 8a540430 8a8be8330710 32ca 888be8330710 43 3bdd }
condition:
- 7 of them and filesize <566272
+ 7 of them and filesize <1039360
}
-rule MALPEDIA_Win_Woodyrat_Auto : FILE
+rule MALPEDIA_Win_Bluehaze_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ce77dd1e-7a7f-526f-b26a-f53840a84ce1"
+ id = "b806577a-57c1-570d-aa1c-22fa8aae198a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.woodyrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.woodyrat_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bluehaze"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bluehaze_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "f0e3660df6e09cfccf9351d956d7545670538be69e20bfd57639d1e54207defb"
+ logic_hash = "e848ac1af15ccfaaa261b6df2c92e0cbc62750d10a2cd1c781f26efdf23885e7"
score = 75
quality = 75
tags = "FILE"
@@ -144572,19 +151533,19 @@ rule MALPEDIA_Win_Woodyrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b75ec 8985a4ebffff ffb5bcebffff e8???????? 8b7de4 83c404 837de800 }
- $sequence_1 = { 8d4e4c 54 6a00 e8???????? 8bc8 e8???????? 8d4dd8 }
- $sequence_2 = { 8d4710 50 8d45cc 50 e8???????? 84c0 7403 }
- $sequence_3 = { e8???????? c645fc03 8b55cc 83fa10 722c 8b4db8 42 }
- $sequence_4 = { 8b4328 8bd8 3bfb 742d 8b0f 8b01 ff5008 }
- $sequence_5 = { 8bc8 83781410 7202 8b08 83781004 753b 8b01 }
- $sequence_6 = { 83c408 8d4508 6a00 84db 7428 837d1c08 6800000002 }
- $sequence_7 = { 50 e8???????? 8b7d80 83c404 e9???????? c645fc00 }
- $sequence_8 = { 7607 be55555515 eb07 03f1 3bf2 0f42f2 }
- $sequence_9 = { 745d 40 50 e8???????? 8bf0 8b45c8 40 }
+ $sequence_0 = { 8d85f0feffff 50 8bcf ff15???????? 8b08 8b4904 }
+ $sequence_1 = { 745f 6a30 c7460800000000 e8???????? 83c404 85c0 }
+ $sequence_2 = { 0fbe56ff 4e 51 52 57 ffd3 83c40c }
+ $sequence_3 = { e8???????? 83c408 8bc8 ff15???????? 397314 7204 }
+ $sequence_4 = { 8d4f04 894e30 894e34 8d4708 8d4d10 894610 894614 }
+ $sequence_5 = { 68???????? 64a100000000 50 81ecec050000 a1???????? 33c5 8945ec }
+ $sequence_6 = { 83c420 8d14c500000000 2bd0 8b06 5b 8d0cd0 }
+ $sequence_7 = { 03c2 894508 753d 8b4604 8b0e 3bc8 0f8466010000 }
+ $sequence_8 = { 0b0b 010b 0b0b 0b0b 0b0b 0b0b 0b0b }
+ $sequence_9 = { 33db 8bc7 8bf1 c745e80f000000 895de4 885dd4 8d5001 }
condition:
- 7 of them and filesize <785408
+ 7 of them and filesize <424960
}
rule MALPEDIA_Win_Wannahusky_Auto : FILE
{
@@ -144625,20 +151586,20 @@ rule MALPEDIA_Win_Wannahusky_Auto : FILE
condition:
7 of them and filesize <862208
}
-rule MALPEDIA_Win_Lumma_Auto : FILE
+rule MALPEDIA_Win_Enigma_Loader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "00d0b80d-1d60-5a8c-ab53-b2e4e4ca8bb2"
+ id = "33d20d9c-767a-597b-ae66-93f6af0c58cb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lumma_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.enigma_loader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.enigma_loader_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "5263a9e2f3da4148c4cca89d62ca2919f1c780d4176c9b4897b89aefc59def79"
+ logic_hash = "8a62893fbe7653f384c2f95eb23ec8773d32568e91ea2e5850c81f2ea0184b8d"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -144650,35 +151611,32 @@ rule MALPEDIA_Win_Lumma_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 53 ff767c ff7678 }
- $sequence_1 = { ffd0 83c40c 894648 85c0 }
- $sequence_2 = { ff5130 83c410 85c0 7407 }
- $sequence_3 = { ff7678 ff7644 ff563c 83c414 }
- $sequence_4 = { ff770c ff37 ff7134 ff5130 }
- $sequence_5 = { ff7608 ff7044 ff503c 83c414 }
- $sequence_6 = { 894610 8b461c c1e002 50 }
- $sequence_7 = { 833800 740a e8???????? 833822 }
- $sequence_8 = { 83c40c 6a02 6804010000 e8???????? }
- $sequence_9 = { 017e78 83567c00 017e68 83566c00 }
- $sequence_10 = { 89e5 8b550c 6bd204 89d1 }
- $sequence_11 = { 41 5d 41 5b 41 5c }
- $sequence_12 = { 48 83ec28 0f05 48 83c428 49 }
+ $sequence_0 = { 8b05???????? 33ff 66393d???????? 41bc09cb3d8d 0f1145ea 8945fa 448d770a }
+ $sequence_1 = { 0f840c010000 488b01 4c8d4de0 4c8d4520 488d5530 ff5010 84c0 }
+ $sequence_2 = { e9???????? 488b8aa0000000 4883c108 e9???????? 488b8aa0000000 4883c120 e9???????? }
+ $sequence_3 = { 488d542478 488bcf e8???????? 90 41c6466801 4138b6b0000000 0f85e2040000 }
+ $sequence_4 = { 488d05dfab0200 e9???????? 488d0523ac0200 eb7c 488d056aac0200 eb73 }
+ $sequence_5 = { 498b4210 448b10 410fb609 83e10f 4a0fbe843178940200 428a8c3188940200 4c2bc8 }
+ $sequence_6 = { 4d8b86c8000000 4c898558020000 488b4610 48394608 7529 488b0e 8a11 }
+ $sequence_7 = { cc 33c0 4c8d1d8fbafeff 884118 0f57c0 }
+ $sequence_8 = { 33d2 33c9 ffd0 4889842420010000 4885c0 7510 bab9fa0e75 }
+ $sequence_9 = { 773b 498bc8 e8???????? 488b6c2458 4a8d0ce3 48891f 498bc6 }
condition:
- 7 of them and filesize <1115136
+ 7 of them and filesize <798720
}
-rule MALPEDIA_Win_Doubleback_Auto : FILE
+rule MALPEDIA_Win_Parallax_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cd786c05-6d47-522c-af3e-e773839ffcc7"
+ id = "3331f8f9-ca97-5323-a8b7-4a2a5bd3b734"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doubleback"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doubleback_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.parallax"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.parallax_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "b40ea64a869bfecf3f36d9c35b2ecd274734632c8a0bce79f6229d1b07f00bb7"
+ logic_hash = "2375ab4fbfb357ff0388c05531234fe1711b2c1ab93377989bbf9dcbb0552a8e"
score = 75
quality = 75
tags = "FILE"
@@ -144692,32 +151650,32 @@ rule MALPEDIA_Win_Doubleback_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b9e3050000 eb3b b90b070000 eb34 2d63450000 7428 }
- $sequence_1 = { b9ad060000 eb57 b9a7060000 eb50 b947060000 eb49 }
- $sequence_2 = { eb3b b90b070000 eb34 2d63450000 }
- $sequence_3 = { 3d39380000 741c 3dd73a0000 740e 3dab3f0000 }
- $sequence_4 = { b9e7050000 eb42 b9e3050000 eb3b b90b070000 }
- $sequence_5 = { b90b070000 eb34 2d63450000 7428 2d57020000 }
- $sequence_6 = { 774f 7446 3d00280000 7438 3d5a290000 742a 3d39380000 }
- $sequence_7 = { 7438 3d5a290000 742a 3d39380000 }
- $sequence_8 = { e8???????? 85c0 7508 c60703 e9???????? }
- $sequence_9 = { 7446 3d00280000 7438 3d5a290000 742a 3d39380000 741c }
+ $sequence_0 = { 8dbf8c000000 b934000000 f3a4 5e 56 ff7508 }
+ $sequence_1 = { ff7508 ff9698010000 5e 5d c21400 55 8bec }
+ $sequence_2 = { 8b5234 83c234 8915???????? 83be1801000000 7545 83be1801000000 7401 }
+ $sequence_3 = { ff763c 683c800000 ff35???????? ff92e0010000 6a00 }
+ $sequence_4 = { 7411 8b75ec 8b7de0 8b4de8 f3a4 }
+ $sequence_5 = { 85c0 7418 8bf8 8b35???????? b8ffffffff f0874704 50 }
+ $sequence_6 = { 6a00 ff9628010000 6a04 68???????? }
+ $sequence_7 = { e9???????? 3d34800000 750d ff7514 ff7510 e8???????? eb6d }
+ $sequence_8 = { 8b5634 83c234 52 52 }
+ $sequence_9 = { 83e934 8b4734 83c034 8b15???????? 50 51 ff92dc000000 }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <352256
}
-rule MALPEDIA_Win_Tinyfluff_Auto : FILE
+rule MALPEDIA_Win_Unidentified_092_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "68615fcb-8e02-5dda-b945-ad2728dc7f08"
+ id = "7e18dd30-6337-5c36-a898-b23460fa3b1e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinyfluff"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tinyfluff_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_092"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_092_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "7b6f89788f810db3773be969b0bf83c7846502ce63a8bb1297c4bbad49f7e342"
+ logic_hash = "2159e4ff6c9c542892316c91029887360b4aa3e31c90494be3422bea5bef7c7b"
score = 75
quality = 75
tags = "FILE"
@@ -144731,32 +151689,32 @@ rule MALPEDIA_Win_Tinyfluff_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f84982c0000 c3 833d????????ff 7503 33c0 c3 53 }
- $sequence_1 = { 8b04bd50704100 03c1 885c302e 46 3bf2 }
- $sequence_2 = { 83e03f c1f906 6bc038 03048d50704100 }
- $sequence_3 = { 85c0 7418 8b858cfbffff 85c0 7407 50 }
- $sequence_4 = { ff15???????? 33f6 e9???????? 8d8de0fbffff 8d5102 668b01 83c102 }
- $sequence_5 = { 8b049550704100 57 8b7d10 897d98 8955b4 }
- $sequence_6 = { 83c410 ebe6 8b45f0 8b0c8550704100 8b45f8 807c012800 }
- $sequence_7 = { 50 6af6 ff15???????? 8b04bd50704100 834c0318ff 33c0 }
- $sequence_8 = { 56 57 83781408 8bf9 8bf2 897dfc 8bd0 }
- $sequence_9 = { c1fa06 8934b8 8bc7 83e03f 6bc838 8b049550704100 8b440818 }
+ $sequence_0 = { c78520ffffff00000000 c68510ffffff00 83f810 7241 8b8df8feffff 40 3d00100000 }
+ $sequence_1 = { 723f 8b4c2464 40 3d00100000 722a f6c11f 0f850b010000 }
+ $sequence_2 = { 33f1 8b7df8 0375a4 8bd3 8b5dfc f7d2 8b4de8 }
+ $sequence_3 = { 8b41fc 3bc1 0f83de020000 2bc8 83f904 0f82d3020000 83f923 }
+ $sequence_4 = { 0155ec c1c107 33f1 8bcb 8bd3 }
+ $sequence_5 = { 56 52 50 8b08 ff511c c745fcffffffff 83ceff }
+ $sequence_6 = { 8d8558ffffff 50 0f118568ffffff ffd3 c645fc03 83ec10 }
+ $sequence_7 = { 8bc3 c1c007 8bcb 33d0 897508 f7d1 8bc3 }
+ $sequence_8 = { 83ee01 75e9 8b85e4fbffff 83f814 }
+ $sequence_9 = { 50 56 ffd3 85c0 7f38 68???????? }
condition:
- 7 of them and filesize <245760
+ 7 of them and filesize <10202112
}
-rule MALPEDIA_Win_Paladin_Auto : FILE
+rule MALPEDIA_Win_Unidentified_031_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8e8ee0fc-daaf-5adf-960f-9f0ec8622d0d"
+ id = "f9c620fb-a7af-59b3-88ea-9e26f2264efe"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.paladin"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.paladin_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_031"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_031_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "421e228bfdffaff271db99688d25ef5b69f4b46e3f813d9e9b328d48850dca52"
+ logic_hash = "135d93e7e92e738a5df3c00f6ebb76c4de980af7c891f431b4f3045d05f7757e"
score = 75
quality = 75
tags = "FILE"
@@ -144770,32 +151728,32 @@ rule MALPEDIA_Win_Paladin_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c20800 8d5d04 50 52 }
- $sequence_1 = { ffd7 8b4614 6aff 50 ffd7 8b4e10 }
- $sequence_2 = { 0faff0 83c61f c70728000000 c1fe03 83e6fc 894704 0faff1 }
- $sequence_3 = { 53 55 56 8bf1 57 b918000000 33c0 }
- $sequence_4 = { 33c0 8a41ff 8d1440 8d1492 8d1492 8d1cd0 33d2 }
- $sequence_5 = { 687f030000 6a00 68???????? 8bf0 }
- $sequence_6 = { 33c0 8dbc24a0000000 33d2 899c249c000000 83c40c 89942484000000 f3ab }
- $sequence_7 = { 81c468020000 c20400 53 c645002e bb01000000 eb04 8b742414 }
- $sequence_8 = { 8b4518 83f804 7427 83f802 7422 83f806 741d }
- $sequence_9 = { 83f80d 0f8661010000 eb04 8b6c2410 }
+ $sequence_0 = { 0f84a6010000 3bfd 0f849e010000 50 e8???????? 6a00 6a01 }
+ $sequence_1 = { 891f 8dbe9c000000 8b07 3bc3 7411 50 53 }
+ $sequence_2 = { ffd6 8d4dc8 ffd6 8d4db0 ffd6 8d4d9c ffd6 }
+ $sequence_3 = { c78504fdffff08800000 c7853cfeffff15000000 c78534feffff02000000 ff15???????? c785ecfcffff3c624000 c785e4fcffff08800000 c785fcfdffff18000000 }
+ $sequence_4 = { e8???????? 8945a0 8d7cbdd0 ff37 50 8bce e8???????? }
+ $sequence_5 = { 895508 0f8203ffffff 83c8ff 5f 5e 5b 5d }
+ $sequence_6 = { 51 52 e8???????? 8d9564ffffff 8d4dc8 89856cffffff }
+ $sequence_7 = { 57 50 e8???????? 3bc3 740e 895e7c 3dc3040000 }
+ $sequence_8 = { 8b3f eb03 8b7de0 c7467c01000000 8b4668 ff75e8 57 }
+ $sequence_9 = { 68???????? 85c0 0f9fc3 f7db ff15???????? 0fbfc0 8b55cc }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <1998848
}
-rule MALPEDIA_Win_Nagini_Auto : FILE
+rule MALPEDIA_Win_Nightsky_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "140c68e0-b1a0-5de4-9ceb-f9c4372ec960"
+ id = "8aa7bf90-2e66-55fa-ac44-1eeed72fb6ec"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nagini"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nagini_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nightsky"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nightsky_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "3751db8355d7cf68abbb539627fa735abe39bfd76ce94371ffdf9eba2b1cc16c"
+ logic_hash = "e63cd2d4ab9373a42087ae988b3e3adac99eadab50dc02b0732a77e7f3626d28"
score = 75
quality = 75
tags = "FILE"
@@ -144809,32 +151767,32 @@ rule MALPEDIA_Win_Nagini_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0131 1f 0031 1f 003422 0337 }
- $sequence_1 = { a3???????? eb18 6a00 6a00 6a00 6a00 }
- $sequence_2 = { 83c408 85c0 0f8510010000 837c242808 8d442414 68???????? }
- $sequence_3 = { 3422 0536240538 27 06 37 260537260535 230434 }
- $sequence_4 = { 0a06 1408 0412 06 }
- $sequence_5 = { 720e 4e 42 0fb606 80b87081420000 74e9 8b5ddc }
- $sequence_6 = { 668944246c a0???????? 8844246e 8a4701 8d7f01 }
- $sequence_7 = { 6689442444 0f8238020000 ff74242c e8???????? 83c404 e9???????? }
- $sequence_8 = { 0f835ffbffff 03f3 03d3 83fb1f 0f8715040000 ff249da0c64000 }
- $sequence_9 = { b3ac 98 b7b0 9c }
+ $sequence_0 = { 420fb68c1210ab0400 c1e108 0bc8 420fb6841212ab0400 }
+ $sequence_1 = { 4150 4d0fabe0 66442bc5 311424 6641d3e0 4158 4863d2 }
+ $sequence_2 = { 4883ec48 488364243000 8364242800 41b803000000 488d0dc0460000 4533c9 ba00000040 }
+ $sequence_3 = { 5f c3 488d05cf110000 48b90000000000000080 488987c8000000 488d0557990200 }
+ $sequence_4 = { e8???????? 488d15d92c0100 41b804010000 33c9 c605????????00 ff15???????? }
+ $sequence_5 = { 488d15d4be0000 41b898000000 498bd9 e8???????? 488b8424d0050000 488b9424e8050000 }
+ $sequence_6 = { e41d 1a5b5f a9b7f95f5f b8cbaa75cc d113 0ae4 }
+ $sequence_7 = { 0f8c96000000 3b1d???????? 0f838a000000 488bf3 4c8be3 49c1fc05 4c8d2d7e190100 }
+ $sequence_8 = { 488d0d0fda0000 480f45cf 48894b48 e8???????? eb17 4885ff 488d0dead90000 }
+ $sequence_9 = { 4883ec28 4c8bc1 4c8d0d52bbfdff 498bc9 }
condition:
- 7 of them and filesize <12820480
+ 7 of them and filesize <19536896
}
-rule MALPEDIA_Win_Hermeticwiper_Auto : FILE
+rule MALPEDIA_Win_Appleseed_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ea8155d0-2aad-5127-b709-49a3ac0a065b"
+ id = "5111027d-aef3-530a-baef-816a96e705d5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hermeticwiper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hermeticwiper_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.appleseed"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.appleseed_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "152c562a196a1884f9736d7ace893f74c52047d602608c8f019348b6a2233130"
+ logic_hash = "a810d449fba9d18767008ae79deb61edb7dc0a7b0fedfb1cf50aff52e06540b9"
score = 75
quality = 75
tags = "FILE"
@@ -144848,32 +151806,32 @@ rule MALPEDIA_Win_Hermeticwiper_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b9???????? 8bc7 6690 668b10 663b11 751e 6685d2 }
- $sequence_1 = { 8bf8 85ff 7404 3bfe 750b 33c0 }
- $sequence_2 = { 55 8bec 8b4508 ff30 ff15???????? 6803000280 }
- $sequence_3 = { 8b0d???????? 83e802 7408 83e801 751b 8b7e08 }
- $sequence_4 = { 8b75f8 13550c 6a00 6a00 52 50 56 }
- $sequence_5 = { 33f6 660fd645dc 33ff 8975f4 50 0f1145bc }
- $sequence_6 = { d3e0 8b4dfc 0facd605 c1ea05 8504b1 754e 8b4d14 }
- $sequence_7 = { 7509 3b75d8 7504 8bc2 eb0f 3bcb }
- $sequence_8 = { c20c00 813f46494c45 75d4 f6471601 74ce 0fb77714 }
- $sequence_9 = { ebba f7d0 23c6 8b75e0 89048e 41 }
+ $sequence_0 = { 448bc6 442bc0 488b442450 488d0d65d30100 488b0cc1 4c8d4c244c 488d9520060000 }
+ $sequence_1 = { 4c89b590000000 c6858000000000 4883bde000000010 720c 488b8dc8000000 e8???????? 8bc7 }
+ $sequence_2 = { 90 488d4db8 e8???????? 48833d????????00 0f84b10c0000 }
+ $sequence_3 = { 488bcb ff15???????? ff15???????? 33ff 8bf0 0f1f8000000000 ff15???????? }
+ $sequence_4 = { 90 488d4db8 e8???????? 48833d????????00 0f84c0040000 488d157e170200 488d4db8 }
+ $sequence_5 = { 488bce ff15???????? 4885c0 7411 83caff 488bc8 }
+ $sequence_6 = { e9???????? 488d8af0000000 e9???????? 488b8a60000000 e9???????? 488d8a10010000 e9???????? }
+ $sequence_7 = { 0f8490000000 85db 0f8488000000 41880f 4b8b84e900670300 4183caff 4103da }
+ $sequence_8 = { 48ffc7 803c3a00 75f7 488d4c2450 4c8bc7 e8???????? 488d4c2450 }
+ $sequence_9 = { 48895dc8 c645b800 41b838000000 488d15b81d0200 488d4db8 e8???????? 90 }
condition:
- 7 of them and filesize <247808
+ 7 of them and filesize <497664
}
-rule MALPEDIA_Win_Noxplayer_Auto : FILE
+rule MALPEDIA_Win_Matanbuchus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "aeae21d3-7da2-50ec-a0e6-bf9f936a4ea7"
+ id = "2788ba99-d4a7-56bc-b166-5140402f53be"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.noxplayer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.noxplayer_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.matanbuchus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.matanbuchus_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "1a7d1e8968616ef04ac90265f765d718da000484253d6b729f0bd247a60f8bd7"
+ logic_hash = "78ecf15a99d40895d657b9372a7af5a206c5b9d4887dbdf8360368c6bcd36a27"
score = 75
quality = 75
tags = "FILE"
@@ -144887,34 +151845,34 @@ rule MALPEDIA_Win_Noxplayer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488941b0 488b42b8 41b8a8000000 488941b8 488b42c0 488941c0 8b42c8 }
- $sequence_1 = { 413bd0 7511 48ffc1 4883c004 4883f904 7ce7 32c0 }
- $sequence_2 = { 4803c1 48898398000000 488b4350 488b4818 48898bb0000000 0f28742470 440f28442460 }
- $sequence_3 = { e8???????? 488d542450 b904010000 ff15???????? 4c8d05403b0300 488d4c2450 ba04010000 }
- $sequence_4 = { 4c8d4e34 4c8b442458 488bd6 488b4e58 e8???????? 488d5614 488b4e50 }
- $sequence_5 = { 488d5557 498d4c2408 e8???????? 488bd8 488d45b7 483bd8 7422 }
- $sequence_6 = { 488bf2 488bf9 488d91c0000000 488d4c2428 e8???????? 90 488dafa0000000 }
- $sequence_7 = { 4c894c2470 488b4508 4c3bc8 740f 418b4918 390e 7c07 }
- $sequence_8 = { 8d4801 488d93b8000000 8b02 3bc8 741b 8b83c0000000 488b8b88000000 }
- $sequence_9 = { 4489642460 4c8d442458 488d542460 488bc8 e8???????? eb03 498bc5 }
+ $sequence_0 = { 038c0534fdffff 51 e8???????? ebb4 8b55fc 52 e8???????? }
+ $sequence_1 = { 6a0c 6a0c 68???????? e8???????? }
+ $sequence_2 = { 8b4dfc 038c0534fdffff 51 e8???????? }
+ $sequence_3 = { 8b4df8 8b513c 035508 8955f4 }
+ $sequence_4 = { 6bc200 8b4d08 0fbe1401 33550c }
+ $sequence_5 = { 68f8000000 8d95b8feffff 52 8b45fc 0345ec 50 e8???????? }
+ $sequence_6 = { 8b45f4 c1e818 3345f4 8945f4 694df495e9d15b 894df4 }
+ $sequence_7 = { 51 8b55f0 52 6b45f828 8b4dfc 038c0534fdffff }
+ $sequence_8 = { eb44 b901000000 d1e1 8b55ec }
+ $sequence_9 = { 8b55ec 813a50450000 7407 33c0 e9???????? }
condition:
- 7 of them and filesize <742400
+ 7 of them and filesize <2056192
}
-rule MALPEDIA_Win_Hdmr_Auto : FILE
+rule MALPEDIA_Win_Olympic_Destroyer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "efac4b5a-015c-5408-9681-2898b333d92b"
+ id = "9f025408-c0a3-516e-ac3a-efc2033f9b9b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hdmr"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hdmr_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.olympic_destroyer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.olympic_destroyer_auto.yar#L1-L222"
license_url = "N/A"
- logic_hash = "d93eae97d145bb46a0ed753e26aa98381b2be0cfcaaaf5d8753f4519f5f83cf1"
+ logic_hash = "93564b4c61bfe578140a2ed1dd33860e59e2d49295b03d310dd7eaa077d799f2"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -144926,32 +151884,45 @@ rule MALPEDIA_Win_Hdmr_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945e0 85c0 7461 8d0cbd40d04100 8901 8305????????20 8b11 }
- $sequence_1 = { 8945ec 894df0 894dfc 8b16 8b523c 50 }
- $sequence_2 = { c1e810 4a 75e6 eb07 }
- $sequence_3 = { 56 8b7508 68fe070000 8d85fef7ffff 6a00 }
- $sequence_4 = { 85db 0f8492010000 8b8d70ffffff 0fb709 }
- $sequence_5 = { 250000ff00 81e3000000ff 33c3 8bda 81e2ff000000 }
- $sequence_6 = { 0fb701 0fb71c0f 2bc3 2bc2 }
- $sequence_7 = { 75ea 8a03 3c61 0fbec0 }
- $sequence_8 = { 8b400c 51 52 8bce ffd0 5e 5b }
- $sequence_9 = { 50 ff15???????? 8d8c24780a0000 51 }
+ $sequence_0 = { 56 33c0 89542414 57 }
+ $sequence_1 = { 6690 3939 770a 8bc1 46 }
+ $sequence_2 = { 8b0c8d60ee5500 80643128fd 5f 5e }
+ $sequence_3 = { 50 689b000000 e8???????? e9???????? }
+ $sequence_4 = { ff15???????? 6880ee3600 ff15???????? 6800000500 56 }
+ $sequence_5 = { 50 68???????? e8???????? 83c408 8907 85c0 0f8480000000 }
+ $sequence_6 = { a1???????? 85c0 741a 833d????????00 7c0a }
+ $sequence_7 = { 50 68???????? 8d85e4fcffff 6805010000 }
+ $sequence_8 = { a1???????? c705????????f3274000 8935???????? a3???????? ff15???????? a3???????? 83f8ff }
+ $sequence_9 = { 7678 eb06 8b8de8efffff 2b8df0efffff 1b85f4efffff }
+ $sequence_10 = { 2bfa 8d0450 57 50 }
+ $sequence_11 = { 750b ff15???????? e9???????? 8b3d???????? 6a02 56 }
+ $sequence_12 = { 83f8fe 7419 8a4a02 3a4e02 }
+ $sequence_13 = { 83ffff 743a 8d857cf9ffff 50 57 ff15???????? }
+ $sequence_14 = { 898588f9ffff 8d85e4fbffff 68???????? 50 ff15???????? 83c40c 8d8594f9ffff }
+ $sequence_15 = { 8d842494000000 89442424 8d54241c 8b44245c 8d4c2424 6a24 }
+ $sequence_16 = { 50 68???????? 8bd7 8bcb e8???????? 8bd8 }
+ $sequence_17 = { 8d8580f7ffff 50 56 56 56 56 }
+ $sequence_18 = { 89442418 85c0 743a 57 }
+ $sequence_19 = { 50 68???????? 8d85ecfdffff 6805010000 }
+ $sequence_20 = { ffd6 50 ff15???????? 8d8594f9ffff }
+ $sequence_21 = { 50 68???????? e8???????? 83c40c 8903 5f }
+ $sequence_22 = { 50 68???????? 8901 ff770c e8???????? 83c40c }
condition:
- 7 of them and filesize <284672
+ 7 of them and filesize <1392640
}
-rule MALPEDIA_Win_Zerot_Auto : FILE
+rule MALPEDIA_Win_Bitter_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8ef83190-c437-5c69-9e28-6f4ff8bb0d5f"
+ id = "48708c16-f954-55fa-bcb7-85a1e067df06"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zerot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zerot_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bitter_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bitter_rat_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "0536a182186ebeb3c971f24e54b07f0b9a695f53e7e594ac1e15149db29c5630"
+ logic_hash = "cf289391c2e8c84704b0f60fd200159e5bca809a29a5213fda197ca45567e744"
score = 75
quality = 75
tags = "FILE"
@@ -144965,32 +151936,32 @@ rule MALPEDIA_Win_Zerot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 46 81e6ff000080 7908 }
- $sequence_1 = { 50 68???????? ff15???????? 8b3d???????? 8d85bcfbffff 50 }
- $sequence_2 = { 6a00 ff760c ff15???????? 85c0 7430 6a00 8d85ccf9ffff }
- $sequence_3 = { 8bf8 6a59 ff15???????? 85c0 b9???????? 0f45cf }
- $sequence_4 = { 8b8ef2050000 8d96fa050000 e8???????? 8d8534cdffff 50 6802020000 ff15???????? }
- $sequence_5 = { 85c0 740c 81bd34fcffffc8000000 7421 8b8530fcffff 40 898530fcffff }
- $sequence_6 = { 8d7001 75da 8b35???????? 8d857cffffff 50 ffd6 83c002 }
- $sequence_7 = { 6800020000 8d85bcfdffff 6a00 50 e8???????? 68???????? }
- $sequence_8 = { 880c32 8a47f8 c0e005 02c1 880432 }
- $sequence_9 = { 0f84b6000000 80bd53fcffff00 0f84a9000000 0fb74214 }
+ $sequence_0 = { 8bf4 6830750000 ff15???????? 3bf4 e8???????? e9???????? }
+ $sequence_1 = { e8???????? 8d856cf8ffff 50 8b8da8feffff 51 e8???????? }
+ $sequence_2 = { ff15???????? 3bf4 e8???????? 898574d8ffff 8bf4 8d858cd8ffff }
+ $sequence_3 = { 83c408 8d85fcd8ffff 50 e8???????? 83c404 898558d9ffff 8b8558d9ffff }
+ $sequence_4 = { ff15???????? 3bf4 e8???????? 8945a0 8bf4 6a01 }
+ $sequence_5 = { eb12 8b45f4 83e801 8945f4 8b4de8 83c101 894de8 }
+ $sequence_6 = { 89859cdbffff 8b8d9cdbffff 81e9d3070000 898d9cdbffff 83bd9cdbffff15 0f872b020000 8b959cdbffff }
+ $sequence_7 = { 8d1c8d00124700 8bf0 83e61f c1e606 8b0b 0fbe4c3104 83e101 }
+ $sequence_8 = { e8???????? 83c404 85c0 7420 e8???????? 8bf4 68d0070000 }
+ $sequence_9 = { 3b05???????? 0f8688000000 a1???????? d1e0 3945f8 760b 8b4df8 }
condition:
- 7 of them and filesize <303104
+ 7 of them and filesize <1130496
}
-rule MALPEDIA_Win_Laturo_Auto : FILE
+rule MALPEDIA_Win_Rcs_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a099051d-06cc-5747-80aa-ce74001854da"
+ id = "897f58a2-dc22-5f97-b551-4f423c0a43b4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.laturo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.laturo_auto.yar#L1-L179"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rcs"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rcs_auto.yar#L1-L180"
license_url = "N/A"
- logic_hash = "5c5686ac498628ddacc2bb584f3ee57bf281fd85acd0c0e6dfbd3f9934f8bef4"
+ logic_hash = "6868fef137d3b17f3a70ffb34345814aa00441ab2e72c702d2e7f970155b6f03"
score = 75
quality = 75
tags = "FILE"
@@ -145004,38 +151975,40 @@ rule MALPEDIA_Win_Laturo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 486bc038 488b0d???????? 8b440120 c1e01e c1f81f 3b442450 741a }
- $sequence_1 = { e8???????? 33db 8bf8 85c0 0f8453020000 4c8d2dea040100 }
- $sequence_2 = { 884814 0fb644243c 83f805 7511 0fb6442405 83e001 85c0 }
- $sequence_3 = { 48837c242000 7432 488b442430 4839442420 720c }
- $sequence_4 = { 488d0d13800100 33c0 8b542420 f00fb111 85c0 742c 48837c242820 }
- $sequence_5 = { 4c8d34c0 49c1fc06 4a8b84e1f0a50100 4a8b44f028 488945bf }
- $sequence_6 = { 488b09 448b0481 33d2 b95a000000 ff15???????? }
- $sequence_7 = { 4883f9fd 7706 ff15???????? 488364243000 488d0dfc7b0000 8364242800 41b803000000 }
- $sequence_8 = { 8bc2 8955e4 c1e802 8bf2 8b55f0 83e603 }
- $sequence_9 = { b803000000 50 68???????? ff763c e8???????? 83c40c 85c0 }
- $sequence_10 = { 7510 46 83c028 3bf2 }
- $sequence_11 = { 8a4dfe 84c0 8a45ff 7909 }
- $sequence_12 = { 53 ff15???????? 50 ff15???????? 834f1406 8b15???????? 8b4df4 }
- $sequence_13 = { 6bd730 8b0c8d30430110 c644112800 85f6 740c 56 e8???????? }
- $sequence_14 = { 8945fc ff15???????? 85c0 7460 c603e9 8b4704 2bc3 }
- $sequence_15 = { 83feff 0f8432010000 57 6a01 83caff 8d4de8 }
+ $sequence_0 = { 6a00 6880000000 6a01 6a00 6a05 }
+ $sequence_1 = { 8944245e 89442462 89442466 8944246a }
+ $sequence_2 = { 85ff 0f84d4000000 57 e8???????? }
+ $sequence_3 = { e8???????? 83c430 6aff 68???????? }
+ $sequence_4 = { ff15???????? 5f 5e 5d 5b 33c0 }
+ $sequence_5 = { 40 68???????? 50 e8???????? 83c40c eb0d }
+ $sequence_6 = { 81f1f3221c6a 41 f7c7073ed86f f8 f9 }
+ $sequence_7 = { 742d 8b7d08 8bbfdc000000 b81c010000 f765fc 8985c0feffff }
+ $sequence_8 = { 81f1ff2fe523 80f973 66f7c5db7a f5 }
+ $sequence_9 = { 83f907 773d ff248d6872f301 4f }
+ $sequence_10 = { 8945f4 eb1c 8b86dc000000 8b9014120000 0fb7781c c1e704 8b3c17 }
+ $sequence_11 = { 83f906 775c ff248d602ef001 c705????????803e0000 }
+ $sequence_12 = { 6a0e 6a00 ff75dc e8???????? 83c40c }
+ $sequence_13 = { 0fb7b810120000 c1e704 8b8d48f4fbff 83c103 0fb78c8870020000 c1e104 8b0c11 }
+ $sequence_14 = { 8b37 81c6c8020000 56 ff75fc ff5704 }
+ $sequence_15 = { 8b75ec 0375f8 8b5e0c 39df 7235 035e08 }
+ $sequence_16 = { 8bbfdc000000 8b7730 897734 ff7518 }
+ $sequence_17 = { 8b55fc 8b45f8 52 50 8b7d08 ff97a0000000 }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <11501568
}
-rule MALPEDIA_Win_Latentbot_Auto : FILE
+rule MALPEDIA_Win_Pykspa_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "02ad78f6-9191-5ecc-84c6-a6e6dbb03fa8"
+ id = "c344e44d-277b-5916-93ac-fe5b84ee097a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.latentbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.latentbot_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pykspa"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pykspa_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "efd4cdc341dd3e728319b10f2fc1071c2f12b6836d6f2ac31876c93b1c888c11"
+ logic_hash = "ae1a9dadb1337e6c1ef760caa0d42ce5c68005bd2830f1ee498d2437086c9f33"
score = 75
quality = 75
tags = "FILE"
@@ -145049,32 +152022,32 @@ rule MALPEDIA_Win_Latentbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 48 89742430 4c 892424 4c 8b6118 44 }
- $sequence_1 = { 833a00 7410 49 8b0a }
- $sequence_2 = { 90 0fb7c0 8d68bf 6683fd19 7703 83c020 0fb7c0 }
- $sequence_3 = { c16d5008 836d5808 888c3020290000 eb12 8b4554 8a00 8b4d4c }
- $sequence_4 = { 59 6a46 eb05 6a30 59 6a39 58 }
- $sequence_5 = { 33c9 03f0 13ca 33c0 0375f8 }
- $sequence_6 = { 56 0fb730 6683fe41 720c 6683fe5a 7706 83c620 }
- $sequence_7 = { 837d4c00 8b5d68 0f8408030000 c70624000000 e9???????? }
- $sequence_8 = { 33c9 51 890e 8bdc 52 6a40 }
- $sequence_9 = { 8d45cf 897e04 8bd1 2bc1 881c10 4a 75fa }
+ $sequence_0 = { 8b5c240c 57 8b7c240c 3bfb 7513 57 8b7c2418 }
+ $sequence_1 = { 6a00 c6400e01 ff15???????? cc 55 8bec b89c110000 }
+ $sequence_2 = { c3 a1???????? 85c0 7501 c3 8b4818 85c9 }
+ $sequence_3 = { 381d???????? 8b2d???????? 744f 8d442418 68???????? 50 e8???????? }
+ $sequence_4 = { c60000 807d0000 0f843b010000 57 ff742414 e8???????? 50 }
+ $sequence_5 = { 0f95c0 5e c3 55 8bec 83ec54 53 }
+ $sequence_6 = { ff15???????? 8b35???????? 53 ffd6 8b3d???????? 53 ffd7 }
+ $sequence_7 = { 381d???????? 7508 381d???????? 743e 56 ff15???????? 83f805 }
+ $sequence_8 = { 8d85acfeffff 68???????? 50 e8???????? 85c0 59 59 }
+ $sequence_9 = { 6a05 8bca 33d2 f7f3 8bc7 bb40e20100 03ca }
condition:
- 7 of them and filesize <401408
+ 7 of them and filesize <835584
}
-rule MALPEDIA_Win_Unidentified_020_Cia_Vault7_Auto : FILE
+rule MALPEDIA_Win_Oski_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "229fefe8-12a2-5321-841b-a1c5858ad20f"
+ id = "e23300f3-24c2-58db-ad53-9ccc894ba178"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_020_cia_vault7"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_020_cia_vault7_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.oski"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.oski_auto.yar#L1-L187"
license_url = "N/A"
- logic_hash = "121c8e165e7a80ef0b3dea83e1137d20669defc5a0d83275fbb5b7562347ae72"
+ logic_hash = "32e88579dcf8b669972c260572f27190a2af2a9bf4eb835092b7f8cb9a6a6e17"
score = 75
quality = 75
tags = "FILE"
@@ -145088,32 +152061,39 @@ rule MALPEDIA_Win_Unidentified_020_Cia_Vault7_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a08 6a01 52 ff15???????? 85c0 0f859f000000 8b45d0 }
- $sequence_1 = { 57 ff15???????? 8bf0 85f6 0f8470ffffff 8b85ecfdffff }
- $sequence_2 = { 6a00 6a00 6a00 6a00 8d95f4fdffff 52 6a01 }
- $sequence_3 = { 8bc1 c1f805 8bf1 83e61f 8d3c8520834100 8b07 }
- $sequence_4 = { 0f870d0a0000 ff2485bbce4000 33c0 838df4fbffffff 898598fbffff 8985b0fbffff }
- $sequence_5 = { 33d2 6806020000 52 8d85eafbffff 50 668995e8fbffff e8???????? }
- $sequence_6 = { 5d c3 b984120000 b8???????? }
- $sequence_7 = { 8d45f4 50 52 51 57 ff15???????? 8b4d08 }
- $sequence_8 = { 50 51 ff15???????? 85c0 7420 8b55fc }
- $sequence_9 = { 83ffff 7410 8d4c2420 51 }
+ $sequence_0 = { 50 a1???????? 50 8d8df0feffff 51 e8???????? }
+ $sequence_1 = { 25ff7f0000 c3 8bff 55 8bec 83ec14 ff7510 }
+ $sequence_2 = { e8???????? 83c40c e8???????? 50 a1???????? 50 }
+ $sequence_3 = { 8975f0 e8???????? cc 8bff 55 8bec 8b550c }
+ $sequence_4 = { 7408 39b5acfeffff 7787 6803010000 8d95edfeffff 56 }
+ $sequence_5 = { 83431810 66898568fbffff 8b4314 85c0 7577 8b8d84fbffff 51 }
+ $sequence_6 = { 6a00 6a1a 6a00 8985eceeffff 898df0eeffff }
+ $sequence_7 = { 53 68???????? 8d8de4feffff 51 53 }
+ $sequence_8 = { e8???????? 83c404 56 8d85ecfeffff 50 8d8dd0fcffff }
+ $sequence_9 = { f3c3 e9???????? 8bff 55 8bec 83ec1c a1???????? }
+ $sequence_10 = { e8???????? 83c404 8b0d???????? 51 ff15???????? a3???????? 833d????????00 }
+ $sequence_11 = { 8b5508 52 a1???????? 50 8d8de8fdffff }
+ $sequence_12 = { 83c404 8b55f8 8955f4 8b45f4 50 e8???????? }
+ $sequence_13 = { 50 8d4df8 51 6800020000 8b55f4 52 ff15???????? }
+ $sequence_14 = { 6a00 e8???????? 83c40c 8985e4fdffff }
+ $sequence_15 = { 8d55f4 52 6a00 68???????? ff15???????? 8945f0 }
+ $sequence_16 = { 83c220 52 6a00 6a00 ff15???????? }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <423936
}
-rule MALPEDIA_Win_Doppelpaymer_Auto : FILE
+rule MALPEDIA_Win_Kwampirs_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f239cfc1-7cb1-5c3d-a2a9-bf2ad44d0856"
+ id = "25decd9c-07db-5eba-ac2c-8b87bfe95cdd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doppelpaymer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doppelpaymer_auto.yar#L1-L181"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kwampirs"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kwampirs_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "6c7514bbe70399e920b266dcf23ab956c2fd28d40abc6464ad39f41a291bdfca"
+ logic_hash = "6b54d71a60f0765ea0fd29b4cf202a2af753cd8f92ae599bc00fdafc2b919f65"
score = 75
quality = 75
tags = "FILE"
@@ -145127,40 +152107,32 @@ rule MALPEDIA_Win_Doppelpaymer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 80790600 7523 80790264 751d }
- $sequence_1 = { 80790561 7517 80790361 7511 80790474 }
- $sequence_2 = { e8???????? 8b08 e8???????? 3db6389096 }
- $sequence_3 = { 83ec28 6800002002 6a00 6a01 }
- $sequence_4 = { 80790264 751d 80790561 7517 }
- $sequence_5 = { baffffff7f 43 e8???????? 3bd8 }
- $sequence_6 = { 8d8c2450010000 e8???????? 89bc245c010000 8d442404 }
- $sequence_7 = { e8???????? 8d8c2424030000 e8???????? 6a10 }
- $sequence_8 = { c20400 8b4e44 8b4110 5e }
- $sequence_9 = { 8955ec e8???????? 8d0d6f302b00 890424 894c2404 e8???????? 8d0d34302b00 }
- $sequence_10 = { 890c24 8945c8 e8???????? 8b4de8 890c24 8945c4 }
- $sequence_11 = { c3 8b45e8 b99054c837 8a55f3 80c2c9 2b4df4 }
- $sequence_12 = { 83ec08 8b4508 8b4054 89e1 894104 }
- $sequence_13 = { 8945c4 74d0 e9???????? 31c0 8b4db8 83c104 }
- $sequence_14 = { 5b 5d c3 b8e2f49a29 2b45ec 8b4dcc 81c1ffff0000 }
- $sequence_15 = { e8???????? 8b4de8 8b55d8 895128 8b75c4 897114 }
- $sequence_16 = { a1???????? ffd0 8945bc 31c0 8b4de8 83c154 8b55e8 }
- $sequence_17 = { c20400 8b400c 8b4810 56 8b700c 57 }
+ $sequence_0 = { 50 8d45f0 64a300000000 8965e8 8bf9 33db }
+ $sequence_1 = { e8???????? b001 8b4df0 64890d00000000 59 }
+ $sequence_2 = { 51 e8???????? 83c404 a3???????? 33f6 }
+ $sequence_3 = { 3bf3 7642 56 e8???????? 8907 }
+ $sequence_4 = { 668955f4 33d2 668955f6 e8???????? 83c40c }
+ $sequence_5 = { c3 32c0 8b4df0 64890d00000000 59 }
+ $sequence_6 = { 8d4df0 51 68???????? e8???????? 83c40c 32c0 }
+ $sequence_7 = { 6a00 6800001000 6a03 6a00 }
+ $sequence_8 = { 83c404 8a45e7 8b4df0 64890d00000000 59 5f }
+ $sequence_9 = { 33c5 50 8d45f0 64a300000000 8965e8 8bf9 33db }
condition:
- 7 of them and filesize <7266304
+ 7 of them and filesize <2695168
}
-rule MALPEDIA_Win_Coredn_Auto : FILE
+rule MALPEDIA_Win_Azorult_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "06de0230-4bd5-5e45-a730-cba0310a794f"
+ id = "b51dfae0-9dbd-5fdb-9b21-c42d24abe8fe"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.coredn"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.coredn_auto.yar#L1-L169"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.azorult"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.azorult_auto.yar#L1-L156"
license_url = "N/A"
- logic_hash = "706fde100ad28c7717e1440d078632bf0db4418173418e843d6c6c3781f1d1c0"
+ logic_hash = "57462241e7f147f9f02722e7f4f98394823c33b074e00b1372b7118c997d7f9f"
score = 75
quality = 75
tags = "FILE"
@@ -145174,37 +152146,38 @@ rule MALPEDIA_Win_Coredn_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 56 8d45fc 8bf1 50 e8???????? 85c0 }
- $sequence_1 = { 7506 48 bf7a000780 c60000 8bc7 5f 5b }
- $sequence_2 = { 8a1c06 84db 741c 8818 4a 40 }
- $sequence_3 = { 83ea01 75e7 8851ff b87a000780 }
- $sequence_4 = { 8be5 5d c20400 85c9 7506 48 bf7a000780 }
- $sequence_5 = { 8bec 56 8b7508 ba04010000 2bf1 }
- $sequence_6 = { 8a040e 84c0 7415 8801 41 83ea01 }
- $sequence_7 = { 85d2 750d 8851ff b87a000780 5e }
- $sequence_8 = { 8b550c 83ec20 33c9 8bc1 3914c5a81b4100 7408 }
- $sequence_9 = { 8b45fc 81784890334100 7409 ff7048 e8???????? 59 c70701000000 }
- $sequence_10 = { eb04 85c9 7508 83e802 bb7a000780 33c9 }
- $sequence_11 = { c644241301 f6c301 744c 8b442414 }
- $sequence_12 = { e9???????? c745e0a4124100 eba2 894ddc c745e0a4124100 e9???????? c745dc03000000 }
- $sequence_13 = { 660fd60f 8d7f08 8b048d942e4000 ffe0 f7c703000000 7413 }
- $sequence_14 = { 23c1 eb55 8b1c9d30d24000 56 6800080000 6a00 53 }
+ $sequence_0 = { 50 ba???????? 8d45e8 e8???????? 8d45e4 8b55f8 8a543201 }
+ $sequence_1 = { e8???????? 56 8d85a0fdffff b9???????? }
+ $sequence_2 = { b9???????? 8b55fc e8???????? 8b859cfdffff e8???????? }
+ $sequence_3 = { b80f270000 e8???????? 8945f8 8d55f4 8bc3 }
+ $sequence_4 = { b80f270000 e8???????? 8bf0 b80f270000 }
+ $sequence_5 = { 7518 56 8b45fc e8???????? 8bc8 8d5301 }
+ $sequence_6 = { b80f270000 e8???????? 8bd8 b80f270000 }
+ $sequence_7 = { ba03000000 e8???????? 8d858cfdffff e8???????? }
+ $sequence_8 = { 7506 ff05???????? 56 e8???????? 59 }
+ $sequence_9 = { e8???????? 59 8b45f4 40 }
+ $sequence_10 = { 50 e8???????? 59 8bd8 33c0 }
+ $sequence_11 = { 85db 7404 8bc3 eb07 }
+ $sequence_12 = { 011f 59 8bc3 c1e003 01866caf0100 }
+ $sequence_13 = { 014f18 8b4714 85c0 0f854e010000 }
+ $sequence_14 = { 014110 5f 5e 5b }
+ $sequence_15 = { 01590c 8b45f0 014110 5f }
condition:
- 7 of them and filesize <270336
+ 7 of them and filesize <1753088
}
-rule MALPEDIA_Win_Feed_Load_Auto : FILE
+rule MALPEDIA_Win_Cryptoluck_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "de841c4a-765f-51dc-8d45-847efc3fe997"
+ id = "a59fe2e6-4321-5ca6-b53f-4f7ee8914f9a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.feed_load"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.feed_load_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptoluck"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptoluck_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "904d3316a4655c20d123c0cfc976a8494c8f04b302e9078044dfcb4ef1ebf390"
+ logic_hash = "6db6bc0e7d4030ac1b4c7c7367ac728b4b155db8cbff6f59645d89ef531abf3a"
score = 75
quality = 75
tags = "FILE"
@@ -145218,32 +152191,32 @@ rule MALPEDIA_Win_Feed_Load_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 48897c2428 4d8bc5 41b940200000 e8???????? 85c0 0f84e2000000 }
- $sequence_1 = { 0f97c1 493bd2 eb27 4c8d42ff 418a00 4d8d4c24ff 413801 }
- $sequence_2 = { 41898500400000 488bfd 4d8bfa bd01000000 83fb0d 0f8c42030000 41690ab179379e }
- $sequence_3 = { 668928 e8???????? 4c8d86500c0000 488bcf e8???????? 4c8d442440 488bcf }
- $sequence_4 = { 7876 3b1d???????? 736e 488bc3 488bf3 48c1fe06 4c8d2d7a220200 }
- $sequence_5 = { 0f8c60040000 41837e0800 4c8d05b755ffff 7429 49635608 48035608 0fb60a }
- $sequence_6 = { 8bd5 ff15???????? 448bc5 488bd6 488bc8 4c8bf0 }
- $sequence_7 = { 488bc2 4903c7 4103df 803800 75f5 3bdf 7207 }
- $sequence_8 = { 4c8d3de9c00100 49393cdf 7402 eb22 e8???????? 498904df }
- $sequence_9 = { 488d157b020200 488d4d88 e8???????? cc }
+ $sequence_0 = { 7409 c745d880720010 eb07 c745d878720010 837d1000 7409 c745d475720010 }
+ $sequence_1 = { 44 15f40010ff 35ec001eff 20d7 59 392d???????? 1288ff35d403 }
+ $sequence_2 = { 8b85e4fbffff 50 e8???????? 83c408 8985c4fbffff 83bdc4fbffff00 }
+ $sequence_3 = { 8b4df8 51 ff15???????? 85c0 7431 8b550c }
+ $sequence_4 = { 85c0 0f84e8000000 c745ec00000000 8d45ec 50 8d4df0 51 }
+ $sequence_5 = { ff15???????? 85c0 7419 8b4d14 }
+ $sequence_6 = { 99 2bc2 8bc8 d1f9 8b45ac 99 2bc2 }
+ $sequence_7 = { ff15???????? 8b0d???????? 51 8b95c8fdffff 52 68ff0f0000 }
+ $sequence_8 = { c60000 8b4de0 83c101 894de0 8b55dc }
+ $sequence_9 = { ff15???????? 8985e8faffff 83bde8faffffff 0f84d9000000 b8424d0000 668985d4faffff 8b8df4faffff }
condition:
- 7 of them and filesize <512000
+ 7 of them and filesize <229376
}
-rule MALPEDIA_Win_Playwork_Auto : FILE
+rule MALPEDIA_Win_Bolek_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "18efebc1-2ecf-5ebd-a5ef-f5649e46ba89"
+ id = "21f1a0ba-06a1-5668-aea4-333af031f0f6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.playwork"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.playwork_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bolek"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bolek_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "a4351b5bd2d1c3d515bb6fc22faeca44797e61833bdb6ed02e20384700f78521"
+ logic_hash = "28c372302adc63618e82259e643572bec2793a354bb442ed761054ecd6bf8112"
score = 75
quality = 75
tags = "FILE"
@@ -145257,32 +152230,32 @@ rule MALPEDIA_Win_Playwork_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { a801 7410 e8???????? 6a1a 99 59 }
- $sequence_1 = { 3350fc 0fb6c9 8bf2 c1ee18 }
- $sequence_2 = { 68???????? eb48 68???????? eb41 68???????? 8d85e8f7ffff 68???????? }
- $sequence_3 = { 8b5008 89560c 8b500c 83e904 895610 0f8469010000 }
- $sequence_4 = { 3dea000000 0f850e020000 8b5dfc 85db }
- $sequence_5 = { 8bdf c1eb10 3330 83c010 8975dc 0fb6f3 }
- $sequence_6 = { 8b4014 894618 8d4e1c c1c808 8bd8 8bd0 }
- $sequence_7 = { 03c8 81f9ffff0000 7d04 56 53 ffd7 56 }
- $sequence_8 = { 8d8594f7ffff 50 8d85f4fdffff 50 ff15???????? }
- $sequence_9 = { 0fb6db 3370fc 8bce 8975f8 c1e918 8b3c8d34573f00 8b4df0 }
+ $sequence_0 = { 894c2454 8bc7 8b8c24ac000000 8bdf 0facc808 33ed c1e318 }
+ $sequence_1 = { 3b31 72e1 51 e8???????? 59 8bc7 5f }
+ $sequence_2 = { 8bcd 0fa4c117 0bf9 c1e017 0bd8 8bcd 8b442460 }
+ $sequence_3 = { 8d86f4000000 50 e8???????? 83c418 56 6880000000 ff750c }
+ $sequence_4 = { dd442418 dc0d???????? dd1c24 68???????? 8b1d???????? 8d44242c 6a40 }
+ $sequence_5 = { eb7a 3c03 0f85bf000000 53 6a01 8d442428 50 }
+ $sequence_6 = { 85c9 746f 803900 746a 6a2c 51 890f }
+ $sequence_7 = { e8???????? eb07 814f7c00040000 5f 5e 5d 5b }
+ $sequence_8 = { 89448c20 41 83c304 ebd0 8bac2434030000 8b9c2430030000 85db }
+ $sequence_9 = { 83e4f8 83ec68 8364242000 8364242400 8b450c c744241001234567 c744241489abcdef }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <892928
}
-rule MALPEDIA_Win_Open_Carrot_Auto : FILE
+rule MALPEDIA_Win_Yakuza_Ransomware_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a3d97757-e9bd-5b96-a3d4-9f325722b76a"
+ id = "11a15f28-8d6d-50f2-ab84-992f1017bc03"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.open_carrot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.open_carrot_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yakuza_ransomware"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yakuza_ransomware_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "bc0e7aafdfe5fe87787ac92bf2b362a8818b18c35ce921dfe615312cba0c80f1"
+ logic_hash = "f6b4887f1e5f8fb585f51d15a1308ea3aa15725a1e02d02f26222a8f601e98de"
score = 75
quality = 75
tags = "FILE"
@@ -145296,32 +152269,32 @@ rule MALPEDIA_Win_Open_Carrot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b910000000 e8???????? 4889442430 c700ffffffff 48c74008ffffffff 8b4c2438 8908 }
- $sequence_1 = { b9c8dcfb75 ffc1 c1e106 83e9ff 83c101 6807ab8f5e 4c893424 }
- $sequence_2 = { ffd0 eb05 bd01000000 440fb6e5 443bed 7c7a 488b15???????? }
- $sequence_3 = { 8bc3 e9???????? 41b805000000 488d153c9a1800 488bcf e8???????? 85c0 }
- $sequence_4 = { ffcf 488d9512070000 4903d4 4c63c7 664289b445100f0000 e8???????? 6639b510170000 }
- $sequence_5 = { 4881cb3f000000 48c7c000020000 4981c46f000000 4809f0 4d0fb72424 4881c204000000 4809c6 }
- $sequence_6 = { 83fe07 7772 4c8d0dad8df9ff 4863c6 418b8481f0750600 4903c1 ffe0 }
- $sequence_7 = { e9???????? 488d05de191400 894c2420 4c8d2dabb30f00 89742424 eb42 488d05aeb30f00 }
- $sequence_8 = { 4c8d0d91850b00 8d4a98 448d42ef e8???????? e9???????? 4c8b4310 488bd7 }
- $sequence_9 = { 7422 41b8a3000000 488d15c7ff0900 e8???????? 48898380000000 4885c0 0f842f010000 }
+ $sequence_0 = { 8bd1 d1ea b8ffffff1f 2bc2 3bc8 7607 8bc3 }
+ $sequence_1 = { e8???????? 3b780c 730e 8b4008 8b34b8 85f6 0f85d7000000 }
+ $sequence_2 = { d1f8 837e1408 7202 8b36 50 ff7508 8bce }
+ $sequence_3 = { 6a01 6a01 57 8d4d80 e8???????? 8b4580 8d4d80 }
+ $sequence_4 = { 8d7018 83c030 8b11 03c7 50 03f7 56 }
+ $sequence_5 = { c745fcffffffff 56 8b4de0 41 51 53 8bcf }
+ $sequence_6 = { 8b4f14 8b5614 85c9 743e 85c0 750d e8???????? }
+ $sequence_7 = { eb17 0fb74644 8d4e24 50 e8???????? 6a2d 8d4e24 }
+ $sequence_8 = { 8b06 6a02 51 53 8d8d50ffffff 51 8bce }
+ $sequence_9 = { c745f000000000 c7461000000000 c7461407000000 668906 8945fc 8bc3 c745f001000000 }
condition:
- 7 of them and filesize <8377344
+ 7 of them and filesize <2811904
}
-rule MALPEDIA_Win_Stration_Auto : FILE
+rule MALPEDIA_Win_Stealc_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b1ff0234-14a0-5584-b678-4973125b246b"
+ id = "539cf538-cfac-56e1-8a82-eaf8270c6c0b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stration"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stration_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stealc_auto.yar#L1-L108"
license_url = "N/A"
- logic_hash = "1e976189a59a2a64efd8d3bfcb5fabcc1cb05f5b8a248de2fec831e10609d819"
+ logic_hash = "6bf18991e2a395daac8cbfec9f407668e110581410c7e2de7aedba9cee95d9f0"
score = 75
quality = 75
tags = "FILE"
@@ -145335,32 +152308,32 @@ rule MALPEDIA_Win_Stration_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 6a01 baf1000000 8bcb e8???????? 55 6a01 }
- $sequence_1 = { 56 e8???????? 83c408 6a00 6a01 baf1000000 8bcd }
- $sequence_2 = { e8???????? 680b040000 56 8944241c }
- $sequence_3 = { c1fa05 891424 8bd1 52 e8???????? a3???????? 8b4c241c }
- $sequence_4 = { ba11010000 8bce e8???????? c705????????00000000 }
- $sequence_5 = { 8b15???????? 89442404 a1???????? 894c2408 8a0d???????? 89442410 8954240c }
- $sequence_6 = { 33f6 85ff 893d???????? 7517 a1???????? 85c0 c605????????00 }
- $sequence_7 = { 8a540404 c1e910 32d1 88540404 }
- $sequence_8 = { 83f80d 7cec 8b15???????? a1???????? 8b0d???????? 891424 668b15???????? }
- $sequence_9 = { eb05 bd14000000 660935???????? 8d542434 52 8d8424b4000000 }
+ $sequence_0 = { ff15???????? 85c0 7507 c685e0feffff43 }
+ $sequence_1 = { 68???????? e8???????? e8???????? 83c474 }
+ $sequence_2 = { 50 e8???????? e8???????? 83c474 }
+ $sequence_3 = { e8???????? e8???????? 81c480000000 e9???????? }
+ $sequence_4 = { 50 e8???????? e8???????? 81c484000000 }
+ $sequence_5 = { e8???????? 83c460 e8???????? 83c40c }
+ $sequence_6 = { e8???????? e8???????? 83c418 6a3c }
+ $sequence_7 = { ff15???????? 50 ff15???????? 8b5508 8902 }
+ $sequence_8 = { 50 ff15???????? 8b5508 8902 }
+ $sequence_9 = { 7405 394104 7d07 8b4908 3bca 75f0 8bf9 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <4891648
}
-rule MALPEDIA_Win_Andromut_Auto : FILE
+rule MALPEDIA_Win_Gspy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dba8d7dc-66b9-5da2-b280-7c7cd5055ee5"
+ id = "3f030d66-0807-5220-809f-f602620cbb65"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.andromut"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.andromut_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gspy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gspy_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "97f484310b347cbce8f6e0e26b13796260e2f5f5c7183f29f706e1875ad44a4f"
+ logic_hash = "74604d1b3decfab056910daf59a9f74fcce729f63057c78e0ce83dfa1bab2af0"
score = 75
quality = 75
tags = "FILE"
@@ -145374,32 +152347,32 @@ rule MALPEDIA_Win_Andromut_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b75f8 6bc828 8b441914 03441910 b9aacd12d8 50 56 }
- $sequence_1 = { e8???????? 8d850cffffff 50 8d8574ffffff 50 8d95fcfcffff 8d8d74fcffff }
- $sequence_2 = { c785fcfeffff84408441 c78500ffffff842c8415 c78504ffffff843c840d c78508ffffff841c8423 }
- $sequence_3 = { e8???????? 8d8de8fcffff 51 8d8dd8faffff 51 ffd0 }
- $sequence_4 = { 83c40c c745d4e278e238 c745d8de58e218 c745dcdef8dcb8 c745e0e498e0f8 }
- $sequence_5 = { e9???????? 83bde4feffff06 0f85cf000000 8b85e8feffff 83f803 7524 83ef02 }
- $sequence_6 = { 8bd0 51 ffb5fcfcffff 8d4dcc e8???????? 59 }
- $sequence_7 = { f3ab 8b7dfc b802210000 6689443e16 0fb7443e06 }
- $sequence_8 = { 53 6a0a 6a18 8d8510f4ffff c645fc02 50 e8???????? }
- $sequence_9 = { 5a 84c0 745c 8d4601 894588 f7e2 0f90c1 }
+ $sequence_0 = { 57 52 c70600000000 ff15???????? 8b4608 8b1d???????? 85c0 }
+ $sequence_1 = { 50 8d4c242c 51 e8???????? c744240812000000 eb2f 6a1c }
+ $sequence_2 = { 8d4c2404 51 6a00 50 ff15???????? a3???????? 85c0 }
+ $sequence_3 = { 8b542420 51 57 6800000220 52 e8???????? }
+ $sequence_4 = { ff15???????? 85c0 0f8408010000 56 57 50 e8???????? }
+ $sequence_5 = { 85f6 0f8434ffffff 83f8ff 750d 33c0 3806 }
+ $sequence_6 = { 0f87b0000000 833e00 89742410 76b3 8b4604 a900000c00 }
+ $sequence_7 = { 0f83ed000000 6a10 6a00 8d442440 50 e8???????? c744241468be4200 }
+ $sequence_8 = { 03cb 51 03d6 52 e8???????? 013e eb08 }
+ $sequence_9 = { 6801000080 c744242000000000 c744241c04000000 c744241801000080 83ceff ff15???????? 85c0 }
condition:
- 7 of them and filesize <368640
+ 7 of them and filesize <421888
}
-rule MALPEDIA_Win_Rapid_Ransom_Auto : FILE
+rule MALPEDIA_Win_Imprudentcook_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ffd06a30-064b-5d5c-9708-094ba6b3f858"
+ id = "da16e08a-4583-5528-aff9-b355b3ccc1ad"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rapid_ransom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rapid_ransom_auto.yar#L1-L164"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.imprudentcook"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.imprudentcook_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "467069894b412bd66ec7bc5db00e763aed4734a1d880a5b3cc4cb8b392b71ec1"
+ logic_hash = "dc1ba99de715ff44414f303429509d324c0251135a2ef150545d89588c26b553"
score = 75
quality = 75
tags = "FILE"
@@ -145413,37 +152386,32 @@ rule MALPEDIA_Win_Rapid_Ransom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 6801000004 6800a40000 ff75f8 }
- $sequence_1 = { 83ec10 53 56 57 8bf9 32db 8bf2 }
- $sequence_2 = { 83ec1c 53 57 8bf9 8bc2 }
- $sequence_3 = { ff15???????? 6a00 ff75f8 ff15???????? 5e 5f 8ac3 }
- $sequence_4 = { 7509 803a00 0f840c010000 8d742464 b8???????? 84db }
- $sequence_5 = { 56 8bf2 8975fc 57 8bf9 85db }
- $sequence_6 = { e8???????? 83c430 8d45f4 6800010000 }
- $sequence_7 = { 7425 ff7514 8b542418 8bce ff7510 c644241701 57 }
- $sequence_8 = { 0f8483000000 eb7d 8b1c9df8584100 6800080000 }
- $sequence_9 = { 740e 50 e8???????? 83a6e8d0410000 59 83c604 }
- $sequence_10 = { 8be5 5d c3 ff75e0 e8???????? 53 e8???????? }
- $sequence_11 = { eb72 8d04cd00000000 2bc1 46 8935???????? c6048564d3410001 893c856cd34100 }
- $sequence_12 = { 6804010000 8d85a4feffff 8bf1 6a00 50 }
- $sequence_13 = { 40 c745ecf54e4000 894df8 8945fc 64a100000000 8945e8 }
- $sequence_14 = { 83c9ff c7430c01000000 c7431000000000 eb2f }
+ $sequence_0 = { 488d3c0b 483bf9 4983d200 4883ee18 4d03da 4d03d9 48ffcd }
+ $sequence_1 = { 4983c708 4983c508 48ffc9 75ec 49894500 488b5520 488d4fff }
+ $sequence_2 = { 4d8bc4 498bd2 eb08 4c89642420 4c8bc7 }
+ $sequence_3 = { 488d04ed00000000 4c03f5 4803f5 48ffc3 4c03f8 4c3bf7 7ec8 }
+ $sequence_4 = { 4c8bcf 4d8bc5 498bd4 e8???????? 488b9580000000 41b901000000 4d8bc6 }
+ $sequence_5 = { 4d3bfe 0f8c45ffffff 4c8bac2488000000 4f8d7c2d00 498bde 4d3bf7 }
+ $sequence_6 = { 8807 e9???????? 81fb0b000100 0f8dfb030000 81fb0000007e 0f87f7030000 85db }
+ $sequence_7 = { 4803c2 48c1f806 488bf8 488bd8 488b8424c0000000 4c8d1cf8 48c1e306 }
+ $sequence_8 = { 4833c2 482bc2 488bd3 493bc2 7d1a 4c895c2428 4c89442420 }
+ $sequence_9 = { e9???????? 48ffcd b938000000 90 488bc3 48d3e8 84c0 }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <864256
}
-rule MALPEDIA_Win_Blackbyte_Auto : FILE
+rule MALPEDIA_Win_Acidbox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ae2ced49-3989-5cc9-8c98-64c5f933a895"
+ id = "d24270e3-4ecb-5df0-834e-54ac9b4880c3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackbyte"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackbyte_auto.yar#L1-L158"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acidbox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.acidbox_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "1cee2f7e2bce0af57e75d6fdf4454ccb725b7569d4236140429240d2a7df1fe9"
+ logic_hash = "7566f8c225df846294fd9c5a92e8c14928b074fdcd922768eae6047a40a5ef6e"
score = 75
quality = 75
tags = "FILE"
@@ -145457,40 +152425,34 @@ rule MALPEDIA_Win_Blackbyte_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d15bc010000 4889542478 4889842480000000 488d542478 4889942490000000 c644242701 }
- $sequence_1 = { 488d0db4020000 488908 833d????????00 7520 488b4c2428 48894808 }
- $sequence_2 = { 0fb64210 88442408 0fb64211 88442409 }
- $sequence_3 = { 0fb6420b 8844240b 0fb6420c 8844240c 0fb6420d 8844240d 0fb6420e }
- $sequence_4 = { 488d4a01 488b442428 488b5c2430 4883f903 }
- $sequence_5 = { 0101 ffc5 3b6b68 0f82e6feffff }
- $sequence_6 = { 488d542478 4889942490000000 c644242701 488b9c24a8000000 488b8c24b0000000 e8???????? }
- $sequence_7 = { 488d4250 488b542430 488d5a50 b918000000 }
- $sequence_8 = { 0fb6420d 8844240d 0fb6420e 8844240e 0fb6420f 8844240f }
- $sequence_9 = { 488d542470 4889942488000000 c644241f01 488b9c24a0000000 }
- $sequence_10 = { 488d4a01 488b442430 488b5c2438 90 4883f90f }
- $sequence_11 = { 0fb64212 8844240a 0fb64213 8844240b }
- $sequence_12 = { 0fb6420f 8844240f 488b442408 48894108 }
- $sequence_13 = { 488d5c244b b902000000 0f1f440000 e8???????? }
- $sequence_14 = { 014608 498bce ffd7 448b85e8040000 }
- $sequence_15 = { 0fb64211 88442409 0fb64212 8844240a }
+ $sequence_0 = { 418bb590000000 4903f4 4889742438 413b8594000000 0f8311010000 397e0c 0f8408010000 }
+ $sequence_1 = { 4154 4155 4156 4157 4883ec28 4c8b7128 448b6108 }
+ $sequence_2 = { c780d8feffffd3731048 c780dcfeffffffff00ff c780e0feffffffe0cccc c780e4feffffffff0000 4d8920 4d8921 }
+ $sequence_3 = { 0fb6ca 4103c9 4403f0 0fb74562 41d3e0 418bc9 49ffc7 }
+ $sequence_4 = { ff15???????? 8d043e 898318170000 eb2f 8d8702010000 }
+ $sequence_5 = { 4883c438 c3 488bc4 48895810 48897018 57 4154 }
+ $sequence_6 = { eb09 4584c0 7908 418b4124 89442420 85c0 }
+ $sequence_7 = { 4c8b4de0 c70705000000 f7471000040000 0f840c010000 8b5f48 413bdd 410f47dd }
+ $sequence_8 = { 7d07 8bd7 413bc7 7d03 418bd1 8b4b28 488b4310 }
+ $sequence_9 = { 0fb79f02040000 418b8a14170000 418bc3 2bc3 }
condition:
- 7 of them and filesize <9435136
+ 7 of them and filesize <589824
}
-rule MALPEDIA_Win_Blackshades_Auto : FILE
+rule MALPEDIA_Win_Grease_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "be0044cc-ffdd-5ce8-9261-6f20deb49ec5"
+ id = "adc1cb70-ca80-5648-8c82-afd04a5873d7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackshades"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackshades_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grease"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grease_auto.yar#L1-L230"
license_url = "N/A"
- logic_hash = "5be1fd8de19e4a88da957f4843427153e72a697b528878c27f4d0e3032429536"
+ logic_hash = "3adaa81800887e757966a0f8096c9ffe86dfca2fec47d710b3b77554cf1c8228"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -145502,73 +152464,86 @@ rule MALPEDIA_Win_Blackshades_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff9e0460ff34 6c 60 ff0a }
- $sequence_1 = { 08fe f5 0200 0000 6c 70ff 9e }
- $sequence_2 = { 70ff f30004eb f4 02eb fb cf }
- $sequence_3 = { 351cff1e55 2c00 0d6c04ff1b c700fb301cc9 }
- $sequence_4 = { 58 2f 60 ff6c74ff }
- $sequence_5 = { 2a23 60 ff1b 0d002a460c fff5 0200 0000 }
- $sequence_6 = { 6c ff4a71 70ff 00746c78 ff1b }
- $sequence_7 = { 6c ff4a71 70ff 00746c78 ff1b 4a }
- $sequence_8 = { ff6c48ff 6c 4c ff40fc }
- $sequence_9 = { ff1b 0d002a460c fff5 0200 0000 6c }
+ $sequence_0 = { 52 50 683f000f00 50 50 50 }
+ $sequence_1 = { 488b4c2460 ff15???????? b801000000 488b8c2480020000 4833cc e8???????? 4881c490020000 }
+ $sequence_2 = { 4533c0 488bd3 c744242804000000 4889442420 ff15???????? 488b4c2450 ff15???????? }
+ $sequence_3 = { 488b05???????? 4833c4 4889842480020000 488d4c2472 }
+ $sequence_4 = { c74424281f000200 895c2420 ff15???????? 85c0 0f85e7000000 }
+ $sequence_5 = { 4533c9 48897c2440 4889442438 48897c2430 }
+ $sequence_6 = { 48895c2440 48895c2458 895c2460 48895c2468 }
+ $sequence_7 = { 4889442438 48897c2430 4533c0 c74424283f000f00 897c2420 ff15???????? 85c0 }
+ $sequence_8 = { 488b4c2450 488d442458 41b904000000 4533c0 488bd3 }
+ $sequence_9 = { 55 68000000c0 50 ff15???????? 8bf0 }
+ $sequence_10 = { e9???????? c684342c08000023 e9???????? c684342c08000021 e9???????? c684342c08000025 }
+ $sequence_11 = { 51 683f000f00 6a00 8d542424 52 6802000080 ffd7 }
+ $sequence_12 = { 85c0 7540 8d542420 52 8b542414 }
+ $sequence_13 = { 83c001 3acb 75f7 8b2d???????? }
+ $sequence_14 = { 83c404 85f6 8854240c 8d46ff 7412 8a4c040c }
+ $sequence_15 = { e9???????? c684341001000066 e9???????? c684341001000068 e9???????? }
+ $sequence_16 = { e8???????? 8b0d???????? 51 8d542418 }
+ $sequence_17 = { e9???????? c6440c082b e9???????? c6440c083e e9???????? c6440c083d e9???????? }
+ $sequence_18 = { c68434240600003f eb12 c68434240600002e eb08 }
+ $sequence_19 = { 8a08 40 84c9 7405 46 85c0 }
+ $sequence_20 = { 8b9c2418040000 56 57 b90d000000 be???????? }
+ $sequence_21 = { 50 897c2430 ffd5 8b542410 6a04 8d4c241c 51 }
+ $sequence_22 = { 8d942434010000 52 56 ffd7 b83b000000 53 668984242c010000 }
condition:
- 7 of them and filesize <999424
+ 7 of them and filesize <278528
}
-rule MALPEDIA_Win_Fatal_Rat_Auto : FILE
+rule MALPEDIA_Win_Unidentified_073_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ad01455e-ebcc-5d76-97a6-8783411925c1"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fatal_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fatal_rat_auto.yar#L1-L132"
+ id = "0ba61f73-e46a-5f54-853f-f1f3b502ee26"
+ date = "2022-08-05"
+ modified = "2022-08-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_073"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_073_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "bf12fac2d058bbab9ea0f9b93b84c2577fb8a36680f2394444c1c24a4d7c12b7"
+ logic_hash = "8100472ca712d569bbcdb570af72e3f13986092b4d8ee8e3873da55bef76232d"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
+ malpedia_rule_date = "20220805"
+ malpedia_hash = "6ec06c64bcfdbeda64eff021c766b4ce34542b71"
+ malpedia_version = "20220808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 807dff00 742f 8b4e10 56 034df4 68???????? }
- $sequence_1 = { 55 8bec 8b4508 33d2 3bc2 7432 8b481c }
- $sequence_2 = { 833d????????02 7513 68???????? 8d851cffffff 50 e8???????? 59 }
- $sequence_3 = { c645bb46 c645bc6f c645bd72 c645be6d 885dbf ff15???????? }
- $sequence_4 = { 8b7df8 899e90000000 80662d00 8bce e8???????? 8b8e90000000 8b4614 }
- $sequence_5 = { 48 eb05 8b462c 2bc1 8945f0 8b4508 8b0485d0b40110 }
- $sequence_6 = { c685e0fdffff2e c685e1fdffff65 c685e2fdffff78 c685e3fdffff65 889de4fdffff c645946b c6459573 }
- $sequence_7 = { 8981a4af0600 5d c3 c3 c3 55 8bec }
- $sequence_8 = { 33db a5 a5 53 8d8520feffff 6a2e 50 }
- $sequence_9 = { ff15???????? 53 56 50 a3???????? ff15???????? 80a5ecfbffff00 }
+ $sequence_0 = { 8d8538ffffff 6a00 c746180f000000 8bce }
+ $sequence_1 = { c684242801000019 e8???????? 68???????? 8d8c24c0000000 e8???????? 6aff }
+ $sequence_2 = { 8bce c7461400000000 50 c6460400 e8???????? 83ec1c 8bf4 }
+ $sequence_3 = { 7846 8b451c 8b0e 2bc1 3bc3 7c53 }
+ $sequence_4 = { 8b0d???????? 894df8 eb09 8b55f8 83ea01 8955f8 837df800 }
+ $sequence_5 = { 6a00 8d8424dc000000 50 8d4c2454 e8???????? 83ec1c 8d84240c010000 }
+ $sequence_6 = { 8bec 51 894dfc c705????????90664a00 833d????????00 741c }
+ $sequence_7 = { 6bd103 8982a0784a00 68???????? 8b45fc 50 ff15???????? }
+ $sequence_8 = { 0fb74df8 894de0 668b55e0 668955f8 0fb745fc 0fb74df8 3bc1 }
+ $sequence_9 = { 57 6aff 68???????? 50 ff15???????? }
condition:
- 7 of them and filesize <344064
+ 7 of them and filesize <1974272
}
-rule MALPEDIA_Win_Skyplex_Auto : FILE
+rule MALPEDIA_Win_Suppobox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3d9ea458-10c2-53d2-a125-12c3c77bb27b"
+ id = "4c561dbc-9b95-52c8-b1b6-738a8e400b62"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.skyplex"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.skyplex_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.suppobox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.suppobox_auto.yar#L1-L194"
license_url = "N/A"
- logic_hash = "d0704b78b2354a7199559252cd2d4f927c47dc758745bd631528996f74a24c6c"
+ logic_hash = "33ed4ed4c3c8a05bca33fadb06a60aef627f5ee4031100bb5102db6965fc9d6b"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -145580,32 +152555,44 @@ rule MALPEDIA_Win_Skyplex_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 ff15???????? 898508fcffff ff15???????? }
- $sequence_1 = { c3 8bff 56 57 33ff 8db704984100 ff36 }
- $sequence_2 = { 59 e9???????? 8b36 8bce c1f905 8b0c8dc0af4100 }
- $sequence_3 = { 8b7d08 8bc7 c1f805 8d3485c0af4100 8b06 }
- $sequence_4 = { 50 e8???????? 50 8b4df8 8b11 8b45f8 50 }
- $sequence_5 = { c785b8f6ffff684c4100 c785bcf6ffffb04c4100 ff15???????? 50 e8???????? 83c404 }
- $sequence_6 = { 33d2 b9???????? 57 8bc2 c1f805 8b0485c0af4100 8bfa }
- $sequence_7 = { 83bdf0feffff03 7327 8b85f0feffff 8b0c857c904100 51 }
- $sequence_8 = { 66898c4558f7ffff 8d9558f7ffff 52 8d8540fbffff 50 }
- $sequence_9 = { 6a01 ff15???????? c78544f6ffff01000000 eb0f 8b8d44f6ffff 83c101 898d44f6ffff }
+ $sequence_0 = { 7d10 a1???????? 0b05???????? a3???????? }
+ $sequence_1 = { 7f10 a1???????? 2305???????? a3???????? }
+ $sequence_2 = { 8945f0 a1???????? 83e801 a3???????? }
+ $sequence_3 = { 7e10 a1???????? 0305???????? a3???????? }
+ $sequence_4 = { 890d???????? e8???????? 8bf0 e8???????? 03f0 }
+ $sequence_5 = { 7d10 a1???????? 3305???????? a3???????? }
+ $sequence_6 = { 3bc8 7d10 a1???????? 2b05???????? a3???????? }
+ $sequence_7 = { 01bdacf7ffff 83c40c 83bdc8f7ffff00 8b95c8f7ffff }
+ $sequence_8 = { 8d45f3 83ec04 890424 e8???????? }
+ $sequence_9 = { 8d45f3 890424 e8???????? 52 ebc5 }
+ $sequence_10 = { 8d45f4 89442408 e9???????? 8b4508 }
+ $sequence_11 = { 01c6 39fe 0f8d7e010000 80bc2ef4f7ffff0a }
+ $sequence_12 = { 8d45f2 89f1 89442404 c70424???????? }
+ $sequence_13 = { 01d8 3b85b0f7ffff 7e2f 8b95c8f7ffff }
+ $sequence_14 = { 8d45f2 89442404 8b4508 890424 e8???????? 83ec08 }
+ $sequence_15 = { 8d45ef 89d9 890424 e8???????? 51 }
+ $sequence_16 = { 01d7 68???????? 57 e8???????? }
+ $sequence_17 = { 01c6 ebdb ff7510 57 }
+ $sequence_18 = { 01c9 4a 79f2 833b54 }
+ $sequence_19 = { 8d45f4 89442408 c744240401000000 893424 }
+ $sequence_20 = { 01c6 39fe 0f8d2f020000 80bc2ef4f7ffff0a }
+ $sequence_21 = { 019dacf7ffff 83c40c 299dc4f7ffff e9???????? }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <1875968
}
-rule MALPEDIA_Win_Sparrow_Door_Auto : FILE
+rule MALPEDIA_Win_Chches_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0be52ebd-81b0-5548-b0c4-71d664335291"
+ id = "a2d17035-5b65-5ddb-9479-7e5b4a4aa253"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sparrow_door"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sparrow_door_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chches"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chches_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "a3ea16377775f10fb390048ca81fb5b622cc57fa7d5b14e32fa13a939a085057"
+ logic_hash = "90b994c4c0ea91e131f92144cfcd7cc30920c864cbd411a57992ff45077985cd"
score = 75
quality = 75
tags = "FILE"
@@ -145619,32 +152606,32 @@ rule MALPEDIA_Win_Sparrow_Door_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 395c240c 7551 8b5604 8b3d???????? 52 68???????? }
- $sequence_1 = { 57 56 ff15???????? 85c0 0f8491010000 8b44243c 3bc5 }
- $sequence_2 = { 8d8c2440040000 51 55 8d94243c010000 52 6a00 68e9fd0000 }
- $sequence_3 = { 53 50 8bf1 895c2430 895c2438 889c244c060000 }
- $sequence_4 = { 8d44245c 50 e8???????? 83c420 85c0 }
- $sequence_5 = { a1???????? a3???????? a1???????? c705????????05772a00 8935???????? }
- $sequence_6 = { e8???????? 8d542470 52 8d442448 50 8b84249c010000 }
- $sequence_7 = { 50 895c2438 c744244844000000 898c2480000000 c744247401010000 6689542478 889c2490000000 }
- $sequence_8 = { 894c2418 8954241c 3bc3 7555 }
- $sequence_9 = { 8d8c2400010000 51 56 52 ffd5 85c0 74a8 }
+ $sequence_0 = { 8b45f4 8b7dfc 50 8b8628020000 ffd0 8b45f8 85c0 }
+ $sequence_1 = { 85c0 7e0b 8b55f8 8b435c 6aff 52 }
+ $sequence_2 = { 8d5f18 85db 7477 8b16 8b4244 8b4018 }
+ $sequence_3 = { 8b16 8945fc 8b4244 3bc7 0f842b020000 8b00 8b7dfc }
+ $sequence_4 = { b810000000 e8???????? 83c420 8945f0 c745f400000000 85c0 0f8405010000 }
+ $sequence_5 = { 66890c78 47 ba2a000000 8d8d98fdffff 66891478 8b9680020000 51 }
+ $sequence_6 = { 8b4004 85c0 7475 3902 746d 8b4e64 50 }
+ $sequence_7 = { 81e980191001 03c1 50 68bfa2c2cd 687f90b056 68a71001fe 686021a031 }
+ $sequence_8 = { 895da0 85db 740f 8b87b8010000 8d5594 52 53 }
+ $sequence_9 = { c745f401000000 eb1c 50 6a08 ffd2 50 }
condition:
- 7 of them and filesize <155648
+ 7 of them and filesize <122880
}
-rule MALPEDIA_Win_W32Times_Auto : FILE
+rule MALPEDIA_Win_Hopscotch_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0bfdc72d-d05e-5c1b-8705-7d1b1a1a85f1"
+ id = "dd6bd925-f81a-5efa-b164-a58190829fd7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.w32times"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.w32times_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hopscotch"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hopscotch_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "09784a57b734a06db72c3b3952721b8e38cad13da9a478a5c4cffbebd654009b"
+ logic_hash = "1aacad185595691b5a0f903be6e5a023d3d5227283438abf4c811f89adcac931"
score = 75
quality = 75
tags = "FILE"
@@ -145658,34 +152645,34 @@ rule MALPEDIA_Win_W32Times_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 85c0 0f8487030000 6a01 68???????? }
- $sequence_1 = { 83e103 f3a4 8b35???????? 8d8c24f0020000 68???????? 51 ffd6 }
- $sequence_2 = { 83c408 68???????? ff15???????? 85c0 0f85c6060000 ff15???????? }
- $sequence_3 = { ff15???????? 68???????? ff15???????? 396c2418 7410 6a01 }
- $sequence_4 = { 3b9c24000d0000 0f84cc090000 8a8424f0020000 84c0 0f84bd090000 8a8424e8000000 84c0 }
- $sequence_5 = { 8bfd 83c9ff 33c0 8d9424ec010000 f2ae f7d1 2bf9 }
- $sequence_6 = { 8b15???????? 52 ffd3 892d???????? a1???????? 3bc5 7416 }
- $sequence_7 = { f3a5 8bcd 8d9424f4030000 83e103 f3a4 8dbc24f4040000 }
- $sequence_8 = { 683f000f00 6a00 56 ff15???????? 8bf8 }
- $sequence_9 = { 83c40c 85c0 0f85e00c0000 8b4b04 6a04 }
+ $sequence_0 = { 8b1d???????? 8d8c24a4010000 6a00 6a00 6a03 6a00 }
+ $sequence_1 = { 5b 81c400010000 c3 8b8c2410010000 51 57 }
+ $sequence_2 = { ffd7 56 53 8d4c2414 6a08 51 e8???????? }
+ $sequence_3 = { ffd7 85c0 753c 8b35???????? ffd6 83f802 742f }
+ $sequence_4 = { 7554 33f6 89b5dcfeffff 8b3d???????? 83fe05 7332 }
+ $sequence_5 = { 81ec80090000 53 56 57 68???????? e8???????? }
+ $sequence_6 = { 68???????? e8???????? 83c408 8d9424a8020000 }
+ $sequence_7 = { 56 57 ff15???????? 85c0 7514 8d442414 }
+ $sequence_8 = { c7442400ffffffff 50 c7442408ffffffff e8???????? 83c404 8d4c2400 }
+ $sequence_9 = { 8b3d???????? 83c408 8d442408 50 ffd7 }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <1143808
}
-rule MALPEDIA_Win_Rokku_Auto : FILE
+rule MALPEDIA_Win_Dadjoke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "75b8aef9-2da5-556e-9635-075190f42681"
+ id = "62c26982-fdfa-5ead-84fa-82086121c261"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rokku"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rokku_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dadjoke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dadjoke_auto.yar#L1-L224"
license_url = "N/A"
- logic_hash = "3a863d12b65613db8f002333dfdefeb5bdf603888d10aa587187b07349134f7e"
+ logic_hash = "551e5b1afd2fb8a5c55119844d05872b1d6fb1f0561b620ba9bad0b2cb1592e0"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -145697,32 +152684,44 @@ rule MALPEDIA_Win_Rokku_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f2805???????? 0f114561 8ac1 028541ffffff 30840d42ffffff }
- $sequence_1 = { 8bc1 8b942444000300 0bc2 0f8456020000 6a06 }
- $sequence_2 = { 8d141b f7ea 8bf8 8bda 8bc1 f76c2470 03f8 }
- $sequence_3 = { 89442438 8b44246c 89442418 8b442468 89442414 8b442464 89442444 }
- $sequence_4 = { 8b0e e8???????? 33c9 84c0 0f454d08 890e eb1f }
- $sequence_5 = { c706???????? 8365fc00 8b4e04 85c9 740d 8b01 ff5010 }
- $sequence_6 = { 13ea f76c2454 896c2420 01442410 8d0436 8b742460 }
- $sequence_7 = { 8b7a18 8b5220 337918 335120 23fd 8b4824 23d5 }
- $sequence_8 = { 894d10 8b4c2414 0fa4c119 8b4c2468 c1e019 2bf0 8bc7 }
- $sequence_9 = { 55 56 57 898c24ac000000 8b02 89442454 8b4204 }
+ $sequence_0 = { 56 57 6800081000 6a00 }
+ $sequence_1 = { 8b55bc 52 6800040000 8d8518f5ffff 50 e8???????? }
+ $sequence_2 = { 3d46270000 7406 837dd800 752c }
+ $sequence_3 = { 8345bc01 807df600 75ed 8b7dbc 8bb570ffffff 8b956cffffff }
+ $sequence_4 = { 6a00 6a00 ff15???????? 8945c0 6a00 6a01 }
+ $sequence_5 = { ff15???????? 8945fc 8b4dfc 51 e8???????? 83c404 }
+ $sequence_6 = { e8???????? 83c40c 8d8d28fdffff 51 e8???????? 83c404 }
+ $sequence_7 = { 5e c3 8bff 55 8bec 83ec10 33c0 }
+ $sequence_8 = { ff15???????? 85c0 7417 b920000000 }
+ $sequence_9 = { e8???????? c3 6a04 e8???????? 59 c3 6a0c }
+ $sequence_10 = { 84c0 0f94c1 8bc1 c3 a1???????? c3 8bff }
+ $sequence_11 = { e8???????? 83c40c c7458c00000000 ff15???????? 50 e8???????? }
+ $sequence_12 = { 8b3d???????? 8b1d???????? 51 e8???????? 8bf0 83c404 }
+ $sequence_13 = { 6a40 6800100000 6800004000 6a00 }
+ $sequence_14 = { 0f84d5480000 c3 833d????????ff 7503 33c0 }
+ $sequence_15 = { 7ce7 8d45f4 c645f800 33db 8d7001 33d2 }
+ $sequence_16 = { 8b85e4faffff 8d95e0faffff 52 68???????? 50 8b08 }
+ $sequence_17 = { 8d85e4faffff 50 68???????? 6a01 6a00 68???????? ff15???????? }
+ $sequence_18 = { 884435f4 46 83fe04 7ce7 8d45f4 c645f800 }
+ $sequence_19 = { c745fc14000000 0f1106 894610 8d45fc }
+ $sequence_20 = { 5f 0f44ca 5b 8bc1 5e 5d c3 }
+ $sequence_21 = { 83e13f c1f806 6bc930 8b048558047500 }
condition:
- 7 of them and filesize <548864
+ 7 of them and filesize <344064
}
-rule MALPEDIA_Win_Enigma_Loader_Auto : FILE
+rule MALPEDIA_Win_Cargobay_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "33d20d9c-767a-597b-ae66-93f6af0c58cb"
+ id = "73c95842-79c7-50a5-be49-1d9ec0676b5e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.enigma_loader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.enigma_loader_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cargobay"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cargobay_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "8a62893fbe7653f384c2f95eb23ec8773d32568e91ea2e5850c81f2ea0184b8d"
+ logic_hash = "6881c841016fbba7262559cf71fef612762f65200b77d9ecbf913cbcf1cd6281"
score = 75
quality = 75
tags = "FILE"
@@ -145736,32 +152735,32 @@ rule MALPEDIA_Win_Enigma_Loader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b05???????? 33ff 66393d???????? 41bc09cb3d8d 0f1145ea 8945fa 448d770a }
- $sequence_1 = { 0f840c010000 488b01 4c8d4de0 4c8d4520 488d5530 ff5010 84c0 }
- $sequence_2 = { e9???????? 488b8aa0000000 4883c108 e9???????? 488b8aa0000000 4883c120 e9???????? }
- $sequence_3 = { 488d542478 488bcf e8???????? 90 41c6466801 4138b6b0000000 0f85e2040000 }
- $sequence_4 = { 488d05dfab0200 e9???????? 488d0523ac0200 eb7c 488d056aac0200 eb73 }
- $sequence_5 = { 498b4210 448b10 410fb609 83e10f 4a0fbe843178940200 428a8c3188940200 4c2bc8 }
- $sequence_6 = { 4d8b86c8000000 4c898558020000 488b4610 48394608 7529 488b0e 8a11 }
- $sequence_7 = { cc 33c0 4c8d1d8fbafeff 884118 0f57c0 }
- $sequence_8 = { 33d2 33c9 ffd0 4889842420010000 4885c0 7510 bab9fa0e75 }
- $sequence_9 = { 773b 498bc8 e8???????? 488b6c2458 4a8d0ce3 48891f 498bc6 }
+ $sequence_0 = { e9???????? 4c8b4910 31c0 4c01ca 7216 48395108 7210 }
+ $sequence_1 = { 80bc24b100000000 0f84e2020000 8a8c24b2000000 0fb6d1 83fa2c 743e b800000000 }
+ $sequence_2 = { e8???????? eb56 488db42498010000 41b8b8000000 4889f1 4c89fa e8???????? }
+ $sequence_3 = { c6040800 48ffc1 ebf2 488b4748 41b801000000 4889f9 4c89e2 }
+ $sequence_4 = { eb04 48832300 4889f1 4c89f2 4883c448 5b 5d }
+ $sequence_5 = { e8???????? 0f0b 56 57 4881ec18040000 4889ce 488d7c2428 }
+ $sequence_6 = { ba05000000 e8???????? e9???????? 488d0dddfe0d00 ba09000000 e8???????? 4889c3 }
+ $sequence_7 = { c5fa6f8729020000 c4e27d470d???????? c4e27d4505???????? c5fd6f15???????? c4e26d36c0 c5fdebc1 c5fddb05???????? }
+ $sequence_8 = { 4d896608 488d8c2488000000 488919 48897108 48898424b0000000 4889bc24b8000000 4d8937 }
+ $sequence_9 = { ba08000000 41b908000000 e8???????? 4881c600020000 4889f1 4c89f2 e8???????? }
condition:
- 7 of them and filesize <798720
+ 7 of them and filesize <3432448
}
-rule MALPEDIA_Win_Dorshel_Auto : FILE
+rule MALPEDIA_Win_Crytox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "550d8628-f52a-56de-91a7-ece0c38b96fb"
+ id = "0ddd8657-2514-5374-8039-613e49f7d728"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dorshel"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dorshel_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crytox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crytox_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "364203df24c6a83e17731caab6caa244bb9a531055fdc65fef6d763de8c4fb40"
+ logic_hash = "53a20cdadf7c04d8a44d2123a9699db23173b707dd2f3ef0f82ea172db5f35fb"
score = 75
quality = 75
tags = "FILE"
@@ -145775,34 +152774,34 @@ rule MALPEDIA_Win_Dorshel_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 55 8bec 83ec0c 31c0 648b5030 8b520c 8b5214 }
- $sequence_1 = { 8d7708 8b3f 33fb f3a4 5f }
- $sequence_2 = { 03f8 84c0 75f6 81ff5e515e83 7408 81ff36cadb30 75da }
- $sequence_3 = { 83c004 e2f9 58 54 50 }
- $sequence_4 = { 51 8b0f 33cb 51 ff55f8 8b5df4 }
- $sequence_5 = { 54 50 8b4f04 33cb 51 8b0f }
- $sequence_6 = { ffd5 85c0 74cd 8b07 01c3 }
- $sequence_7 = { ac c1cf0d 03f8 84c0 75f6 81ff5e515e83 7408 }
- $sequence_8 = { 57 6800200000 53 56 68129689e2 ffd5 85c0 }
- $sequence_9 = { 5f 8b4704 33c3 83c104 99 }
+ $sequence_0 = { eb7d 85f6 7479 c645c800 e8???????? 85c0 89c3 }
+ $sequence_1 = { dfe9 0f86c2e3ffff 89442410 89c1 c1fa02 db442410 c1f902 }
+ $sequence_2 = { e8???????? 8b4510 3b4518 741d 0fbf45c4 c1e002 89442408 }
+ $sequence_3 = { e8???????? 89c3 8b45dc 85c0 0f84adfeffff 8d65f4 89d8 }
+ $sequence_4 = { eb02 d9c9 83c301 038d30ffffff 399d04ffffff 7f8e ddd9 }
+ $sequence_5 = { f1 807de700 89d3 7510 6bc22c 80b84442660000 0f85ac000000 }
+ $sequence_6 = { c5c5fe3d???????? c5c572e70e c5fd7f9c24000b0000 c5e572e50e c5d572e60e c5fd7f9c24e0090000 c5ddfe15???????? }
+ $sequence_7 = { dee9 d95dc0 8b45e0 83c001 8d148500000000 8b4508 01d0 }
+ $sequence_8 = { e9???????? 8b7d24 8b4510 85ff c70000000000 742b 8b4508 }
+ $sequence_9 = { dec9 d96c2424 db5c2420 d96c2426 8b742420 d9e8 dfe9 }
condition:
- 7 of them and filesize <24576
+ 7 of them and filesize <6156288
}
-rule MALPEDIA_Win_Badcall_Auto : FILE
+rule MALPEDIA_Win_Bangat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f6c1d400-6aaf-5cd3-88ab-d61e25f09ca7"
+ id = "a2d4fb7c-d848-52ac-b553-710b64461faf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badcall"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.badcall_auto.yar#L1-L157"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bangat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bangat_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "789bf61f14e8f6f349ef8fa3798aaa8ef35e52eb6b6c01f584f1e407643e6f98"
+ logic_hash = "795b6baa10d3ea1f31877796bf7d8c3236899cd7fc3cddcf5f5e7734a685bf62"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -145814,38 +152813,32 @@ rule MALPEDIA_Win_Badcall_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 2bc6 3d00400000 7605 b800400000 }
- $sequence_1 = { a3???????? a1???????? 50 c705????????04000000 }
- $sequence_2 = { 7605 b800400000 8b4f04 6a00 50 }
- $sequence_3 = { 7557 33c0 68???????? a3???????? a3???????? a3???????? }
- $sequence_4 = { 48 7455 48 7434 }
- $sequence_5 = { 8b6c2414 682c010000 8bcf e8???????? }
- $sequence_6 = { 50 c705????????04000000 ff15???????? c20400 a1???????? }
- $sequence_7 = { ff15???????? c20400 c705????????01000000 a1???????? 68???????? }
- $sequence_8 = { 7434 83e803 7557 33c0 }
- $sequence_9 = { 8954240a 66c74424080200 8954240e 894c240c 89542412 }
- $sequence_10 = { 8b6c2414 8bc7 2bc6 3d00400000 }
- $sequence_11 = { 85c0 7e3b 8b4604 8d542418 52 }
- $sequence_12 = { 85db 8bf9 763f 8b6c2414 682c010000 }
- $sequence_13 = { e8???????? 85c0 7534 8bc3 2bc6 3d00400000 }
- $sequence_14 = { 83fe01 7518 53 ff15???????? }
- $sequence_15 = { 85c0 740e 8b4c241c 51 6a01 }
+ $sequence_0 = { 6a01 6800000040 50 e8???????? 83c43c 8bf0 83feff }
+ $sequence_1 = { 13f9 03f0 13fd 8b6c2434 89742418 03de 8b74245c }
+ $sequence_2 = { 8b442424 99 f7fe 83c408 85d2 7425 6815050000 }
+ $sequence_3 = { ff750c 50 ff15???????? 8bf0 ff15???????? 83f850 }
+ $sequence_4 = { 8b4c2474 0bc8 8b442464 0bc2 8b54244c 33f1 33f8 }
+ $sequence_5 = { 83cbff eb11 83fb01 750c 8b5004 85d2 7505 }
+ $sequence_6 = { 8b5704 8b0e 8b3a 8bc1 2bc7 7511 8b7a08 }
+ $sequence_7 = { 8b35???????? 8d45e8 68???????? 50 ffd6 8bf8 59 }
+ $sequence_8 = { 8b4b58 898184030000 8b03 3d00030000 0f8ebf000000 8b442418 8b4c2414 }
+ $sequence_9 = { 75f3 5f 5e 5d b830000000 }
condition:
- 7 of them and filesize <483328
+ 7 of them and filesize <1228800
}
-rule MALPEDIA_Win_Aytoke_Auto : FILE
+rule MALPEDIA_Win_Mgbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f1478c56-9c46-5623-bd25-6c48e27a19e0"
+ id = "dd03dc94-bb3a-5cad-8f13-4bbe4b7f90a6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aytoke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aytoke_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mgbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mgbot_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "7de9f368c79cc6db2fb2092fd19a4e0bd2fcaaf4a3ec4500b832560e5022850b"
+ logic_hash = "7310ce51cc81391fc78e9881bf8f490b2a783d4789728f7661df3e6bdca512d7"
score = 75
quality = 75
tags = "FILE"
@@ -145859,32 +152852,32 @@ rule MALPEDIA_Win_Aytoke_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6685c9 75e9 e9???????? 33c0 8bff 0fb788103a4100 66898c05fcfdffff }
- $sequence_1 = { 3c58 770f 0fbec2 0fbe80f83b4100 83e00f eb02 33c0 }
- $sequence_2 = { 8bd0 83e01f c1fa05 8b149500c44100 59 c1e006 59 }
- $sequence_3 = { 56 e8???????? c1f805 56 8d3c8500c44100 e8???????? 83e01f }
- $sequence_4 = { 90 68???????? e8???????? a1???????? 46 83c004 }
- $sequence_5 = { 2bc2 bb5c000000 85c0 7e16 }
- $sequence_6 = { be01000000 83c104 83c408 3bce }
- $sequence_7 = { 33c0 8d642400 0fb7888c3a4100 66898c05fcfdffff 83c002 6685c9 75e9 }
- $sequence_8 = { 85ff 7424 56 53 6a01 57 }
- $sequence_9 = { 663bc1 0f85cc130000 8d95fcfcffff 52 ff15???????? 68a0000000 }
+ $sequence_0 = { 6808020000 e8???????? 6804010000 8bf0 6a00 }
+ $sequence_1 = { 6808020000 e8???????? 6804010000 8bf0 6a00 56 e8???????? }
+ $sequence_2 = { 5b 8be5 5d c20800 6808020000 }
+ $sequence_3 = { 6808020000 e8???????? 6804010000 8bf0 6a00 56 }
+ $sequence_4 = { 8be5 5d c20800 6808020000 e8???????? }
+ $sequence_5 = { 6808020000 e8???????? 6804010000 8bf0 }
+ $sequence_6 = { 5d c20800 6808020000 e8???????? }
+ $sequence_7 = { 8be5 5d c20800 6808020000 }
+ $sequence_8 = { 5b 8be5 5d c20800 6808020000 e8???????? }
+ $sequence_9 = { 0f8553ffffff 5f 33c0 5e }
condition:
- 7 of them and filesize <425984
+ 7 of them and filesize <1677312
}
-rule MALPEDIA_Win_Smac_Auto : FILE
+rule MALPEDIA_Win_Collection_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b9e948cf-fc1c-55b5-a40e-593d0b67f4eb"
+ id = "57812c72-d174-5305-a791-07d9524d5d58"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.smac"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.smac_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.collection_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.collection_rat_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "69ecbaffb88ef2eb7b0bb4fc54b666c372bcfee7df6d63633067f160f5f10295"
+ logic_hash = "47382a0b15866fbc9363efde1f8fbfda4134e668af0afa7d4fd14596481603d4"
score = 75
quality = 75
tags = "FILE"
@@ -145898,32 +152891,32 @@ rule MALPEDIA_Win_Smac_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 66898548ffffff 8bc3 6689854affffff 58 6a74 6689854cffffff 58 }
- $sequence_1 = { 39bd78feffff 0f86b8000000 ffb578feffff e8???????? ffb578feffff 8bf0 57 }
- $sequence_2 = { 668945ec 668975ea 8d8598feffff 8bf4 89a578feffff 50 }
- $sequence_3 = { 8d9d44ffffff e8???????? 6a01 33ff 8bf3 e8???????? 8b1d???????? }
- $sequence_4 = { e8???????? 83ec1c c68424900100000e 8d842484000000 8bf4 8964245c }
- $sequence_5 = { 8945f0 3bc3 7514 6a01 33ff 8d7508 e8???????? }
- $sequence_6 = { 83c42c 33f6 46 5b ffb5f480ffff ff15???????? }
- $sequence_7 = { 8986d8000000 ffd7 8986dc000000 8bc6 e8???????? c20800 6a00 }
- $sequence_8 = { 8bf4 89a578feffff 50 e8???????? 83ec1c c645fc04 8d4528 }
- $sequence_9 = { 66899d42ffffff 5b 6a74 66899d44ffffff 5b }
+ $sequence_0 = { 488b5567 488d4ef0 4803cf 458bc6 e8???????? 85c0 }
+ $sequence_1 = { 488d05870c0100 488bd9 488901 f6c201 740a ba18000000 e8???????? }
+ $sequence_2 = { 488b4138 8938 e9???????? 488b05???????? 488b4808 488b4130 }
+ $sequence_3 = { 4883c102 33d2 e8???????? 488b0d???????? 488b5108 48894218 488b05???????? }
+ $sequence_4 = { 0f8467010000 488bc4 48895808 48897010 48897818 4c897020 55 }
+ $sequence_5 = { 458bf0 0fb7f2 4885c9 0f84d1000000 488b9c24a8000000 4885db }
+ $sequence_6 = { 83a424b000000000 ba14000000 33c9 448d42fa e8???????? 488d0d74740200 ffd0 }
+ $sequence_7 = { e8???????? 482be0 bd00100000 488d8c24e0000000 448bc5 33d2 }
+ $sequence_8 = { 488b4a28 e8???????? 84c0 740b 488bd6 498bcd }
+ $sequence_9 = { 488b4830 4c89542450 bf03000000 897c2448 488d442468 4889442440 488d8424d0000000 }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <397312
}
-rule MALPEDIA_Win_Quantloader_Auto : FILE
+rule MALPEDIA_Win_Goopic_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4febf63d-0f98-5ee5-9cc6-9fa1c2da1c7c"
+ id = "af6daaef-2e7b-547b-a95b-f4526c03929f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.quantloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.quantloader_auto.yar#L1-L175"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.goopic"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.goopic_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "02e93017f3318c384f200ca1e9ba6b581c4815c155dd61d906306a2c75ce48f2"
+ logic_hash = "09cf2d520274006f21b8dfb7e13c7364d612efefae1767684cd3f4a4dac575b5"
score = 75
quality = 75
tags = "FILE"
@@ -145937,40 +152930,34 @@ rule MALPEDIA_Win_Quantloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d85f8fdffff 890424 e8???????? 8d85f8fdffff 890424 e8???????? }
- $sequence_1 = { e8???????? c7442404???????? c70424???????? e8???????? 8b450c }
- $sequence_2 = { e8???????? 85c0 750c c70424???????? e8???????? c70424???????? }
- $sequence_3 = { e8???????? 85c0 0f94c0 0fb6d8 c744240801000000 8b45f8 }
- $sequence_4 = { 89442404 c7042400000000 e8???????? 83ec0c 8d85f8f7ffff 89442404 }
- $sequence_5 = { c744240400000000 c70424???????? e8???????? 83ec14 8945f4 }
- $sequence_6 = { c70424???????? e8???????? c744240800000000 c7442404???????? c70424???????? }
- $sequence_7 = { 817d08???????? 7470 817d0c00704000 7467 8b4508 803800 }
- $sequence_8 = { 8d341e 66ad 6633d0 75df }
- $sequence_9 = { 75f1 5e 8bc6 8bf7 3bc5 7403 }
- $sequence_10 = { 61 c3 60 8bd3 8bf2 03763c 2b5634 }
- $sequence_11 = { 837d5400 7425 64ff3530000000 59 8b490c 8b490c }
- $sequence_12 = { ff30 6800100000 57 81042400100000 ff550c }
- $sequence_13 = { 61 c3 58 ffd0 837c240802 7414 64a118000000 }
- $sequence_14 = { 5d 8bc4 ff7010 ff700c ff7008 ff5550 e8???????? }
- $sequence_15 = { 85c0 741b a900000080 7504 8d440302 25ffffff7f }
+ $sequence_0 = { 8d85fcf7ffff 50 ff15???????? 6a00 6a00 6a00 6a00 }
+ $sequence_1 = { 57 ff742428 ff15???????? 85c0 740d }
+ $sequence_2 = { c785d0fdffff2c020000 ff15???????? 8bf0 8d85d0fdffff 50 56 }
+ $sequence_3 = { 50 8b08 ff11 8b442414 50 }
+ $sequence_4 = { ff15???????? 8bd7 8d8df8bfffff e8???????? 57 68???????? ff15???????? }
+ $sequence_5 = { 8bfa ffd6 8bd8 895dfc }
+ $sequence_6 = { 50 6aff 68???????? 6a00 6a00 ffd7 8d842448190000 }
+ $sequence_7 = { 0f8664ffffff 8b4dfc 33c0 5f 5e 33cd 5b }
+ $sequence_8 = { 53 ff15???????? 8bf8 85ff 0f84f4000000 56 6a00 }
+ $sequence_9 = { c785c0fdffff305d4000 eb0a c785c0fdffff245d4000 8d85b4fdffff c785c4fdffff3c5d4000 50 }
condition:
- 7 of them and filesize <155648
+ 7 of them and filesize <114688
}
-rule MALPEDIA_Win_Sisfader_Auto : FILE
+rule MALPEDIA_Win_Boatlaunch_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1937373c-a869-5de8-8c47-c30db9548d3e"
+ id = "109242da-f9c2-50c8-b49d-1f772a8283fe"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sisfader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sisfader_auto.yar#L1-L291"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.boatlaunch"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.boatlaunch_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "288baaa87a5a9f6675c09b00537afbaf23a5deab091befb8544155fddb8ada09"
+ logic_hash = "efa924e2b3901352dc645d99e6dd6dafbe8ab78c7c6ccaefe300da9883a180c7"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -145982,54 +152969,40 @@ rule MALPEDIA_Win_Sisfader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c9 741f 33c0 85c9 }
- $sequence_1 = { e8???????? 85c0 b91d000000 0f44d9 }
- $sequence_2 = { 8906 83f824 723e b824000000 }
- $sequence_3 = { 8b4dfc 51 8b55f8 52 e8???????? 83c408 8945f4 }
- $sequence_4 = { 33d2 b904000000 e8???????? 33c0 83f801 7425 baffffffff }
- $sequence_5 = { 83793000 0f85be000000 8b55fc 8b45f0 }
- $sequence_6 = { 837c245000 7402 eb12 c744245401000000 33c0 }
- $sequence_7 = { c705????????07000000 8b442438 8905???????? c705????????00000000 8b442440 8905???????? c705????????b80b0000 }
- $sequence_8 = { 837c242001 7425 837c242002 7441 837c242003 745d 837c242004 }
- $sequence_9 = { 85c0 752b 8d45f8 c745f882000000 50 8d8618010000 50 }
- $sequence_10 = { 66837c246c2e 7518 0fb74c246e 6685c9 }
- $sequence_11 = { 83790800 745d c745f800000000 eb09 8b55f8 83c201 }
- $sequence_12 = { 746b c744242000000000 eb0a 8b442420 }
- $sequence_13 = { 6a04 e8???????? 83c40c 8b4d0c 51 }
- $sequence_14 = { 8b442448 89442420 837c242001 7402 eb05 e8???????? }
- $sequence_15 = { 8b45f0 83781000 750e 8b4df0 8b510c 0355cc 8955e4 }
- $sequence_16 = { 0fb74c247e 6685c9 0f84cd010000 6683f92e 750f }
- $sequence_17 = { 720b 03f0 eb9c 5f 5e 33c0 5b }
- $sequence_18 = { e8???????? b90e000000 ff15???????? 33c0 e9???????? e9???????? ff15???????? }
- $sequence_19 = { 745d 837c242004 7479 837c242005 0f8480000000 }
- $sequence_20 = { ebbc 8b4dfc 8b5108 52 ff15???????? 83c404 8b45fc }
- $sequence_21 = { 8d8574fdffff 6804010000 50 6a00 ff15???????? 8d8574fdffff }
- $sequence_22 = { 7426 8b4f04 85c9 741f }
- $sequence_23 = { 8139aaeeddff 0f858e000000 8b4104 85c0 }
- $sequence_24 = { 8b45fc 8b08 83792800 7457 }
- $sequence_25 = { 85c9 7513 ffb318020000 ff15???????? 33c0 5b }
- $sequence_26 = { 8b45ac 894610 8b45b0 894614 ff15???????? 66894604 8d45e8 }
- $sequence_27 = { 8b55fc 8b4230 50 ff15???????? 83c404 }
- $sequence_28 = { ba08020000 0f114014 c7400856120000 89580c c700aaeeddff }
- $sequence_29 = { 85c0 7416 0f1f4000 8bc1 83e00f 8a0430 30441124 }
+ $sequence_0 = { 4883611000 4883612800 488d4dd8 48c7c2ffff1f00 4c8d45e0 4c8d4d10 }
+ $sequence_1 = { e8???????? 8945e4 6a00 ff75e0 }
+ $sequence_2 = { 2b75ec 0375e4 8b4324 2b45ec 0345e4 }
+ $sequence_3 = { 488d4df0 e8???????? 48c7c1ffffffff 488d55f0 448bc3 e8???????? 3b8558110000 }
+ $sequence_4 = { 480375c8 8b4324 2b45c0 480345c8 488945d0 8b5b18 ad }
+ $sequence_5 = { 85f6 7599 488b0d???????? 33d2 4c8b4500 }
+ $sequence_6 = { 3b8560110000 7526 488b45d0 0fb730 }
+ $sequence_7 = { 488d4dd0 48c7c200001000 4c8d45e0 4c8d4d10 e8???????? 3d0b0000c0 7427 }
+ $sequence_8 = { 50 68ff0f1f00 8d45fc 50 }
+ $sequence_9 = { 8bfe 49 85c9 75ee }
+ $sequence_10 = { e8???????? 8bd8 85db 7452 53 }
+ $sequence_11 = { eb09 8345e802 4b 85db 75af }
+ $sequence_12 = { 50 e8???????? 3d0b0000c0 7423 6a00 ff75f8 e8???????? }
+ $sequence_13 = { 5b 5d c3 48894c2408 89542410 4489442418 }
+ $sequence_14 = { 488b45d8 488d6528 415b 415a 4159 4158 }
+ $sequence_15 = { 8d5ddc c70318000000 c7430400000000 c7430800000000 c7430c00000000 }
condition:
- 7 of them and filesize <417792
+ 7 of them and filesize <33792
}
-rule MALPEDIA_Win_Spider_Rat_Auto : FILE
+rule MALPEDIA_Win_Sepulcher_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8b8fb932-c9c0-5d1a-a1ff-94b4f85b8abe"
+ id = "666ccc80-c712-59f8-bf12-61bac5486b32"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spider_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spider_rat_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sepulcher"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sepulcher_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "86dc62debebef6e9c395034c4368c0804fc586029188907fa2c1533f611f9771"
+ logic_hash = "fea20fdb29a4a6cc26bf9baf225a8110e30f06d577e665b386797a74632bb5da"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -146041,32 +153014,32 @@ rule MALPEDIA_Win_Spider_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 4883c708 488b1f 488bd3 488d8c2490000000 e8???????? }
- $sequence_1 = { 418bc3 4c8d5c2460 498b5b18 498b7328 498be3 5f c3 }
- $sequence_2 = { 488b6c2438 488b742440 8958f0 488b07 4863cb 488b5c2430 c6040100 }
- $sequence_3 = { e8???????? 488b4d70 4883c160 ff15???????? 90 488d05b726fbff eb00 }
- $sequence_4 = { 84c0 7471 4885f6 7505 83fd01 7415 488b8f88000000 }
- $sequence_5 = { 7458 6683fa01 7452 ff15???????? 4c8bc6 8bd5 0fb7cb }
- $sequence_6 = { 7410 488b8f88000000 e8???????? 85c0 7802 33db 8bc3 }
- $sequence_7 = { 498bd8 488bf2 488bf9 4d85c0 7430 4885d2 742b }
- $sequence_8 = { ff15???????? 488bc8 e8???????? 488d15d3b00300 488bce 488905???????? ff15???????? }
- $sequence_9 = { ba03000000 488d442440 448d4a61 448d42fe 4889442420 e8???????? }
+ $sequence_0 = { 56 57 6a43 8bf9 58 6a4d 8db784480000 }
+ $sequence_1 = { 7515 6a04 8d45bc 50 e8???????? 8b4db8 8bd0 }
+ $sequence_2 = { 58 6a74 59 6a53 668945ea 58 }
+ $sequence_3 = { 0fb71408 8bc2 c1e002 66393408 75f1 }
+ $sequence_4 = { eb1a 8d45fc 50 8b04bd50de0110 ff743018 }
+ $sequence_5 = { 668945d2 b8???????? 66894db4 66894dba 66894dc0 }
+ $sequence_6 = { 56 57 6a5a 58 6a52 }
+ $sequence_7 = { c1f906 6bd030 8b45fc 03148d50de0110 8b00 894218 }
+ $sequence_8 = { 8bd8 895db0 8d0c4dffff0000 51 57 53 e8???????? }
+ $sequence_9 = { 58 6a33 668945e8 668945ea 58 6a32 668945ec }
condition:
- 7 of them and filesize <1107968
+ 7 of them and filesize <279552
}
-rule MALPEDIA_Win_Zlob_Auto : FILE
+rule MALPEDIA_Win_Rokku_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4fad6172-d1e7-5d84-af68-8861117c390a"
+ id = "75b8aef9-2da5-556e-9635-075190f42681"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zlob"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zlob_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rokku"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rokku_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "31e17a6dc34e33dac3ecb614a6996745d9221261fdc2596cb1f9e420f9dc5bc9"
+ logic_hash = "3a863d12b65613db8f002333dfdefeb5bdf603888d10aa587187b07349134f7e"
score = 75
quality = 75
tags = "FILE"
@@ -146080,32 +153053,32 @@ rule MALPEDIA_Win_Zlob_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd6 ffd7 68???????? e8???????? c70424???????? 68???????? }
- $sequence_1 = { 50 ff742434 ff15???????? ff742414 e8???????? ff74242c 8b4c243c }
- $sequence_2 = { 5d 8bcb 5b 83c404 ff6024 51 51 }
- $sequence_3 = { 50 e8???????? 8b4508 83c410 83780400 7533 8d85f0eaffff }
- $sequence_4 = { 58 2bc2 03c8 f644240c02 7504 8d4c7102 8bc1 }
- $sequence_5 = { 56 8b35???????? 57 8b3d???????? 0f8407020000 837d10ff }
- $sequence_6 = { ffd7 8b442414 6a01 6a00 6a00 ff30 ff15???????? }
- $sequence_7 = { ff74242c 8901 50 e8???????? 83c410 ffd3 }
- $sequence_8 = { ff75e8 8d4dbc e8???????? ff45f8 8b45f8 3b45e4 0f8cedfdffff }
- $sequence_9 = { 57 8b3d???????? 89442410 8b4508 8b4c2410 }
+ $sequence_0 = { 0f2805???????? 0f114561 8ac1 028541ffffff 30840d42ffffff }
+ $sequence_1 = { 8bc1 8b942444000300 0bc2 0f8456020000 6a06 }
+ $sequence_2 = { 8d141b f7ea 8bf8 8bda 8bc1 f76c2470 03f8 }
+ $sequence_3 = { 89442438 8b44246c 89442418 8b442468 89442414 8b442464 89442444 }
+ $sequence_4 = { 8b0e e8???????? 33c9 84c0 0f454d08 890e eb1f }
+ $sequence_5 = { c706???????? 8365fc00 8b4e04 85c9 740d 8b01 ff5010 }
+ $sequence_6 = { 13ea f76c2454 896c2420 01442410 8d0436 8b742460 }
+ $sequence_7 = { 8b7a18 8b5220 337918 335120 23fd 8b4824 23d5 }
+ $sequence_8 = { 894d10 8b4c2414 0fa4c119 8b4c2468 c1e019 2bf0 8bc7 }
+ $sequence_9 = { 55 56 57 898c24ac000000 8b02 89442454 8b4204 }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <548864
}
-rule MALPEDIA_Win_Dyre_Auto : FILE
+rule MALPEDIA_Win_Jasus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a2cdb89d-a2b8-54db-b921-a02d048236a7"
+ id = "f0f57156-3d71-51a0-8417-ea38ed1ea26d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dyre"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dyre_auto.yar#L1-L170"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jasus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jasus_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "e9097ad46c004cb1ae831fc1ba01674dc80d073ddf943ce6f2fcdbae48599a8a"
+ logic_hash = "8597018770d02606e940d401ffb7afc270f8035f09e3cd93e76c94000290c2f1"
score = 75
quality = 75
tags = "FILE"
@@ -146119,79 +153092,78 @@ rule MALPEDIA_Win_Dyre_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6814020000 e8???????? 59 c3 }
- $sequence_1 = { e9???????? 68f4010000 ff15???????? 56 }
- $sequence_2 = { 7244 6801010000 ff15???????? 8b4d18 663901 }
- $sequence_3 = { 7502 c9 c3 33c0 837dfc20 }
- $sequence_4 = { 0fb7c8 c1e110 e8???????? 0fb7c0 0bc1 c9 c3 }
- $sequence_5 = { 773d 0fbec0 83e857 8ada 2ad9 c1e004 80fb09 }
- $sequence_6 = { c1fa02 8b1496 83e103 c1e103 }
- $sequence_7 = { 41 3bc8 7cf4 83f903 }
- $sequence_8 = { 57 4883ec20 4032ff 488bda 8bf1 4885d2 }
- $sequence_9 = { 488bc8 ff15???????? 85c0 7455 4c8d442434 }
- $sequence_10 = { 488bcb e8???????? 4c8d5e01 41b8f7ffffff 6666660f1f840000000000 488bcf 418d4008 }
- $sequence_11 = { 4433c0 418bc5 23c6 33c8 418bc1 4403c1 }
- $sequence_12 = { 663907 7530 8b4604 394704 7528 8b4608 394708 }
- $sequence_13 = { 498d43e8 33ff 488bf2 498943d8 498d4318 488bd9 488bd1 }
- $sequence_14 = { 440fb69c249f000000 0fb68c249d000000 0fb694249c000000 440fb694249b000000 }
- $sequence_15 = { 488bcb e8???????? 85c0 750d 33c0 488b5c2430 }
+ $sequence_0 = { 50 51 6689956cffffff ffd3 83c40c 833d????????00 }
+ $sequence_1 = { 8955f8 8955e8 8955ec c745f0ffffffff 84c0 7410 8d642400 }
+ $sequence_2 = { 84c0 7543 8b45fc 85c0 745a 68???????? }
+ $sequence_3 = { 39580c 0f828d000000 0fb71437 8b4e1a 33c0 89442414 89442418 }
+ $sequence_4 = { 8945f0 894df8 b801000000 837dec00 745d 85c0 7559 }
+ $sequence_5 = { 8b1481 40 89560c 8906 8b5e0c 895e14 8a03 }
+ $sequence_6 = { 47 897e14 897e70 c686c800000043 c6864b01000043 c74668d0f24100 6a0d }
+ $sequence_7 = { 894de8 8945e4 c745ec00c94100 c745f001010000 c745f41e010000 c745f80f000000 }
+ $sequence_8 = { 8bc6 c1f805 8d1485809d4300 8b0a }
+ $sequence_9 = { e8???????? 0fb71d???????? 8945fc 0fb705???????? 56 68???????? e8???????? }
condition:
- 7 of them and filesize <590848
+ 7 of them and filesize <507904
}
-rule MALPEDIA_Win_Voidoor_Auto : FILE
+rule MALPEDIA_Win_Coredn_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "71f97a7b-09b8-5977-a64d-26462fe6285b"
+ id = "06de0230-4bd5-5e45-a730-cba0310a794f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.voidoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.voidoor_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.coredn"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.coredn_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "c8a62c7797e4a86d80b8a858487a45d1e5042e60b70ed193ca612e4172a00dd8"
+ logic_hash = "706fde100ad28c7717e1440d078632bf0db4418173418e843d6c6c3781f1d1c0"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { e8???????? 83c410 83bfb40b000000 752e ff33 83bf500b000000 ffb608400000 }
- $sequence_1 = { c645fc10 e8???????? c78574feffff0f000000 c78570feffff00000000 c68560feffff00 8d9560feffff 8d8d78feffff }
- $sequence_2 = { 03f5 7458 803e2f 7509 83f804 7d04 40 }
- $sequence_3 = { 55 8bd8 ff15???????? 83c414 85db 0f85c3010000 8b542440 }
- $sequence_4 = { 8b742414 c744240800000000 83bec802000000 8b1e 57 8b834c010000 8dbe68050000 }
- $sequence_5 = { c60201 8b10 2bca 83f906 7d0a b801000000 5e }
- $sequence_6 = { 33c0 5f 59 c3 56 57 e8???????? }
- $sequence_7 = { b91b000000 5e 0f44d9 5d 8bc3 5b 83c408 }
- $sequence_8 = { e8???????? 83c40c 89442418 8983ac030000 68???????? 53 e8???????? }
- $sequence_9 = { c6434501 3944241c 7520 85f6 0f8565ffffff 837c243020 7337 }
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { 51 56 8d45fc 8bf1 50 e8???????? 85c0 }
+ $sequence_1 = { 7506 48 bf7a000780 c60000 8bc7 5f 5b }
+ $sequence_2 = { 8a1c06 84db 741c 8818 4a 40 }
+ $sequence_3 = { 83ea01 75e7 8851ff b87a000780 }
+ $sequence_4 = { 8be5 5d c20400 85c9 7506 48 bf7a000780 }
+ $sequence_5 = { 8bec 56 8b7508 ba04010000 2bf1 }
+ $sequence_6 = { 8a040e 84c0 7415 8801 41 83ea01 }
+ $sequence_7 = { 85d2 750d 8851ff b87a000780 5e }
+ $sequence_8 = { 8b550c 83ec20 33c9 8bc1 3914c5a81b4100 7408 }
+ $sequence_9 = { 8b45fc 81784890334100 7409 ff7048 e8???????? 59 c70701000000 }
+ $sequence_10 = { eb04 85c9 7508 83e802 bb7a000780 33c9 }
+ $sequence_11 = { c644241301 f6c301 744c 8b442414 }
+ $sequence_12 = { e9???????? c745e0a4124100 eba2 894ddc c745e0a4124100 e9???????? c745dc03000000 }
+ $sequence_13 = { 660fd60f 8d7f08 8b048d942e4000 ffe0 f7c703000000 7413 }
+ $sequence_14 = { 23c1 eb55 8b1c9d30d24000 56 6800080000 6a00 53 }
condition:
- 7 of them and filesize <1744896
+ 7 of them and filesize <270336
}
-rule MALPEDIA_Win_Cryptic_Convo_Auto : FILE
+rule MALPEDIA_Win_Ghost_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c0d84b8c-dd86-5e0b-b294-081ee84952b7"
+ id = "a811e919-423f-5da5-9744-a836ad0cfe7b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptic_convo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptic_convo_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ghost_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ghost_rat_auto.yar#L1-L294"
license_url = "N/A"
- logic_hash = "39890a4d7eaef0b28d86a0d6d65ec4ed011fdfc3e00013a201ada7ffacfd1cd9"
+ logic_hash = "566fcbf38da6404d1cfb5b85cb33273a727f786f21d6a86dff53a4e450ad50b1"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -146203,32 +153175,54 @@ rule MALPEDIA_Win_Cryptic_Convo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bf8 ffd6 85ff 7515 8d45e8 68???????? }
- $sequence_1 = { 75f9 8dbddcfaffff 2bc2 4f 8a4f01 }
- $sequence_2 = { 399e88000000 7445 399e8c000000 743d 6a40 6800300000 ff7510 }
- $sequence_3 = { c20400 0fb7442404 ff742408 50 e8???????? c20800 }
- $sequence_4 = { 50 6a01 6a00 68???????? 57 ffd3 85c0 }
- $sequence_5 = { a4 33c0 8a88d0474000 884c05e8 40 84c9 }
- $sequence_6 = { f3a4 8dbddcfaffff 4f 8a4701 47 84c0 75f8 }
- $sequence_7 = { 85c0 7407 c605????????01 be???????? 8d7d98 a5 66a5 }
- $sequence_8 = { 894584 ffd6 53 57 89458c ff15???????? }
- $sequence_9 = { 8d45c8 66a5 50 53 }
+ $sequence_0 = { 6a01 56 ff15???????? 5e c20800 }
+ $sequence_1 = { 8bd9 e8???????? 8b4d08 3bc8 }
+ $sequence_2 = { 8b400c 85c0 7505 a1???????? 50 8bce }
+ $sequence_3 = { 8be5 5d c20400 894df4 }
+ $sequence_4 = { 894df4 c745f800000000 df6df4 83ec08 dc0d???????? }
+ $sequence_5 = { 6a6b 8bce e8???????? 5f }
+ $sequence_6 = { e8???????? 8b8e549f0000 83c41c 89848e14030000 8b86549f0000 }
+ $sequence_7 = { 8d7b01 c60396 f3a5 53 8bcd }
+ $sequence_8 = { 8db714030000 8b06 6aff 50 }
+ $sequence_9 = { 8b5614 8b02 8b400c 85c0 }
+ $sequence_10 = { e9???????? 8d45dc 50 681f000200 }
+ $sequence_11 = { 50 ff15???????? ffb6a8000000 ff15???????? ffb6ac000000 }
+ $sequence_12 = { 8dbd85feffff f3ab 66ab aa }
+ $sequence_13 = { 6a00 6a00 c705????????20010000 e8???????? 8b35???????? }
+ $sequence_14 = { e8???????? 8d85c0feffff 50 57 ff15???????? 8bf8 83ffff }
+ $sequence_15 = { 83c40c 8d85b8feffff 50 8d85b4fdffff }
+ $sequence_16 = { 8bce e8???????? 8b4df4 5f b001 5e }
+ $sequence_17 = { 8bf0 83c40c 46 750b 5f 5e 33c0 }
+ $sequence_18 = { ff15???????? 6a01 ff7620 ff15???????? 8b4e04 e8???????? }
+ $sequence_19 = { ff7510 ff75dc ff15???????? 85c0 7507 c745e401000000 834dfcff }
+ $sequence_20 = { 56 53 e8???????? 83c408 84c0 750b }
+ $sequence_21 = { 68???????? 50 6802000080 e8???????? 83c41c 5f 5e }
+ $sequence_22 = { 6a00 50 e8???????? 83c40c ff7508 6a40 ff15???????? }
+ $sequence_23 = { 8365fc00 ff7508 ff15???????? 40 50 ff15???????? 59 }
+ $sequence_24 = { 8b4608 8b7e20 8b36 813f6b006500 7406 }
+ $sequence_25 = { c7014c696272 83e9fc c70161727941 83e9fc }
+ $sequence_26 = { 813f6b006500 7406 813f4b004500 75e8 }
+ $sequence_27 = { c7014c6f6164 83e9fc c7014c696272 83e9fc }
+ $sequence_28 = { 7475 8b45bc 8b08 894db4 }
+ $sequence_29 = { 8911 eb26 8b45b4 8b4d08 8d540102 }
+ $sequence_30 = { 8b55dc 8b7a18 8b7220 0375f8 33c9 }
+ $sequence_31 = { 6bc928 8b9538ffffff 8b8560ffffff 03440a0c 8985fcfeffff }
condition:
- 7 of them and filesize <97280
+ 7 of them and filesize <357376
}
-rule MALPEDIA_Win_Temp_Stealer_Auto : FILE
+rule MALPEDIA_Win_Mofksys_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f2cc61b5-19bf-56a2-9eca-3f40739e6ccc"
+ id = "d4eb461a-0f9d-55f8-ba8b-2ce33ab04b0d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.temp_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.temp_stealer_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mofksys"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mofksys_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "225e1e9fc27831c15c6655569f2cde4ac7e8ac8903eef398ab726a5dfa80c059"
+ logic_hash = "79cea3cada5c4d8bb821159689e5cf75c88595dc32d8f5768a4b2ed694d76584"
score = 75
quality = 75
tags = "FILE"
@@ -146242,32 +153236,32 @@ rule MALPEDIA_Win_Temp_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4d8bc7 498bce e8???????? 4885c0 7405 492bc6 eb04 }
- $sequence_1 = { 488d4c2430 e8???????? 488b442430 48635004 488d051a730300 4889441430 488b442430 }
- $sequence_2 = { 5e 5d c3 4889542410 48894c2408 55 53 }
- $sequence_3 = { 488d4dc0 e8???????? 0f10442460 0f1145c0 0f104c2470 0f114dd0 660f6f05???????? }
- $sequence_4 = { 418ac7 84c0 0f8408010000 8b4c2448 488d154240fdff 2b4c244c 41b826000000 }
- $sequence_5 = { 488d4c2430 e8???????? 488d542430 488d4c2470 e8???????? 90 }
- $sequence_6 = { 488d4c2450 e8???????? 660f6f05???????? 488d152a670300 488d4de0 4c896de0 f30f7f45f0 }
- $sequence_7 = { 4183f805 0f8582000000 8b470c 458d487a c744243001000000 4c8d05ee7f0100 89442428 }
- $sequence_8 = { ff15???????? 4c8be0 488985a0000000 488d15b9a30300 488bcb ff15???????? 4c8bf8 }
- $sequence_9 = { 488d4c2458 e8???????? 90 488d8d48010000 e8???????? 488d45a8 }
+ $sequence_0 = { 50 e8???????? 8bd0 8d4de8 ffd6 8d8d60ffffff }
+ $sequence_1 = { 894dd4 c745fc07000000 8b55d8 52 e8???????? ff15???????? 8b45d4 }
+ $sequence_2 = { 83c40c c745fca1000000 ba???????? 8d4dc0 ff15???????? 8d4dc0 51 }
+ $sequence_3 = { f7de 3bf0 7209 ff15???????? 8b4dc0 8b4118 0fafc6 }
+ $sequence_4 = { ff15???????? 83c410 c745fc65000000 ba???????? 8d4dcc ff15???????? a1???????? }
+ $sequence_5 = { ff15???????? 8bd0 8d8d7cfcffff ffd6 50 ffd7 }
+ $sequence_6 = { a1???????? 8b4de4 50 51 ffd7 8bd0 8d4da8 }
+ $sequence_7 = { 3bc3 7d12 68e0000000 68???????? 56 50 }
+ $sequence_8 = { 83c201 0f80b2080000 52 8b45d0 50 68???????? }
+ $sequence_9 = { e8???????? 8d4ddc ff15???????? c745fc0f000000 68???????? 6a00 ff15???????? }
condition:
- 7 of them and filesize <652288
+ 7 of them and filesize <401408
}
-rule MALPEDIA_Win_Webc2_Ugx_Auto : FILE
+rule MALPEDIA_Win_Tiger_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "af26c213-66d2-5675-81ab-6f59f34ddb98"
+ id = "c2ea69b5-54d0-5c61-bb49-4f65b838d0af"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_ugx"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_ugx_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tiger_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tiger_rat_auto.yar#L1-L165"
license_url = "N/A"
- logic_hash = "c0369798dbc9b5bf726746a205f3377c225f0e99dd41f08ae5697ccf08cc0c9d"
+ logic_hash = "bed3ce3d252a7d616792a16e358ffda1357857c1fa2b5862a7f71cbabe456650"
score = 75
quality = 75
tags = "FILE"
@@ -146281,34 +153275,40 @@ rule MALPEDIA_Win_Webc2_Ugx_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d458c 895dec 50 8d8568ffffff 50 }
- $sequence_1 = { 59 745e 8d4640 50 ff750c ffd3 59 }
- $sequence_2 = { 50 ff15???????? 85c0 7455 8d85a8feffff 53 50 }
- $sequence_3 = { ff9698060000 8bf8 85ff 0f84b5000000 8d866e0c0000 50 57 }
- $sequence_4 = { 8d85a8feffff 68???????? 50 ffd6 }
- $sequence_5 = { 50 ff55fc 8bc3 eb48 ff15???????? 56 }
- $sequence_6 = { 8d8584fdffff 50 ff55bc 50 8d8584fdffff 50 }
- $sequence_7 = { 8d8584f9ffff 57 50 ff55f0 }
- $sequence_8 = { ff5508 ff7510 e9???????? 53 }
- $sequence_9 = { 8d85a8feffff 68???????? 50 ffd6 8d85a8feffff 68???????? 50 }
+ $sequence_0 = { 4883c128 4889742448 48897c2450 ff15???????? }
+ $sequence_1 = { 0f11400c 488b4e28 488b5618 488b01 ff5010 }
+ $sequence_2 = { 4883c108 e8???????? 4d8b4618 41b901000000 }
+ $sequence_3 = { 33d2 41b80c000100 488bd8 e8???????? 4c63442430 488b4f08 }
+ $sequence_4 = { 4883c108 413bc0 7cef eb06 4898 }
+ $sequence_5 = { 4883c110 e8???????? 896e30 381f }
+ $sequence_6 = { 4883c10c e8???????? 488b4f28 488b5718 }
+ $sequence_7 = { 4883c110 48c741180f000000 33ed 48896910 408829 48c746500f000000 }
+ $sequence_8 = { 7ce0 488bce ff15???????? 8b0d???????? }
+ $sequence_9 = { ff15???????? 488bc8 ff15???????? ba0a000000 }
+ $sequence_10 = { 0b05???????? 8905???????? ff15???????? ff15???????? b9e8030000 8bd8 }
+ $sequence_11 = { 4c2bf3 8905???????? 493bf7 0f83c8000000 48896c2478 4c896c2430 41bd00f00000 }
+ $sequence_12 = { c705????????02000000 488905???????? 488d0556eb0100 48891d???????? 488905???????? 33c0 488905???????? }
+ $sequence_13 = { 8b05???????? 4d8bf4 2305???????? 4c03fe 4c2bf3 8905???????? }
+ $sequence_14 = { 4c8d35046c0100 49833cde00 7407 b801000000 eb5e }
+ $sequence_15 = { 8bd8 e8???????? 2bc3 3d70170000 7cf2 e8???????? }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <557056
}
-rule MALPEDIA_Win_Qtbot_Auto : FILE
+rule MALPEDIA_Win_Darkside_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ec8aa97a-290d-593c-aa5f-6c160f3c38cf"
+ id = "4e98e522-42dc-58c9-8c11-9325d3b56f3a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.qtbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.qtbot_auto.yar#L1-L168"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkside"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkside_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "2c7689c956559567f13a9ec6cae95c5c067935d56f8491bff1983eb40f5f2838"
- score = 60
- quality = 25
+ logic_hash = "e40a0efe65c9a50695ac0381c3b73c18492ef0b0fce9893dbb25777c239f867f"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -146320,38 +153320,32 @@ rule MALPEDIA_Win_Qtbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89450c 8d4301 0fb6d8 8a941dfcfeffff 0fb6c2 }
- $sequence_1 = { 75e9 5b 5d c20400 }
- $sequence_2 = { 25ffffff00 42 8a1a 84db }
- $sequence_3 = { 8b049a 03c6 50 e8???????? }
- $sequence_4 = { 33c0 53 8a1a 6bc80d 0fb6c3 83c0d0 }
- $sequence_5 = { 03d6 8b481c 8b4018 03ce }
- $sequence_6 = { 40 89450c 83ef01 75b1 8b4510 5f 5e }
- $sequence_7 = { 85ff 7455 8b4510 89450c }
- $sequence_8 = { 894dfc eb0e 8b14957c300010 49 0fafd1 0155fc }
- $sequence_9 = { 8bd8 8d7e08 7504 8b2f eb02 }
- $sequence_10 = { 0fb6805a210010 ff2485f6200010 8b8614080000 3b45f4 7e03 8945f4 8365fc00 }
- $sequence_11 = { 6a00 ff15???????? 833e05 7521 6a10 6a40 ff15???????? }
- $sequence_12 = { 8db720080000 833e00 751e 837efcff 7518 8b46f8 8b04855c300010 }
- $sequence_13 = { 8b46f8 834de4ff 49 c745e8ff000000 8b3c857c300010 }
- $sequence_14 = { 33c0 8b7df4 8b0c855c300010 c1e705 33d2 03fe }
- $sequence_15 = { e8???????? 59 837e04ff 8bd8 8d7e08 }
+ $sequence_0 = { 8bd8 68ff000000 57 e8???????? 81c7ff000000 }
+ $sequence_1 = { 85d2 7407 52 57 }
+ $sequence_2 = { b9ff000000 33d2 f7f1 85c0 7418 }
+ $sequence_3 = { 57 e8???????? 81c7ff000000 4b }
+ $sequence_4 = { fec1 75d2 5f 5e 5a 59 5b }
+ $sequence_5 = { 56 57 b9f0000000 be???????? }
+ $sequence_6 = { 8b7d08 8b450c b9ff000000 33d2 f7f1 }
+ $sequence_7 = { 56 57 b9f0000000 be???????? 8b4508 }
+ $sequence_8 = { e8???????? 5f 5e 5a 59 5b 5d }
+ $sequence_9 = { 81ea10101010 2d10101010 81eb10101010 81ef10101010 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <286720
}
-rule MALPEDIA_Win_Tellyouthepass_Auto : FILE
+rule MALPEDIA_Win_Eagerbee_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2f59ff80-ce55-5261-bc1e-9b9085ba348c"
+ id = "2c944b22-0670-5d3a-8325-748c1204ab76"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tellyouthepass"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tellyouthepass_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.eagerbee"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.eagerbee_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "e0931a30828c9c1e2a42766d85093d9ba189ed49cc692d748a9e549b96d308d1"
+ logic_hash = "128c0a374c8b1a00f6b82c3fc65b3e7ab4f3e40ebdc9cd2ac65e4a7f259bdca2"
score = 75
quality = 75
tags = "FILE"
@@ -146365,32 +153359,32 @@ rule MALPEDIA_Win_Tellyouthepass_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4c895c2438 48895c2430 e8???????? 488d05e4021a00 bb1d000000 e8???????? 488b442450 }
- $sequence_1 = { 488d05a4bf1700 bb13000000 0f1f440000 e8???????? 8b442414 89c0 e8???????? }
- $sequence_2 = { e8???????? 488b442428 e8???????? 488d0509dd1700 bb07000000 e8???????? 488b442420 }
- $sequence_3 = { e9???????? 488d05231a3400 31db 488b6c2458 4883c460 c3 48895c2470 }
- $sequence_4 = { 7506 48894208 eb09 488d7a08 e8???????? 488bac24f8000000 4881c400010000 }
- $sequence_5 = { c3 440fb6ac24080a0000 4584ed 0f8471030000 4983fc07 0f85aa010000 4c8b4828 }
- $sequence_6 = { e8???????? e8???????? 488b4818 488b5820 488b5028 4889c8 4889d1 }
- $sequence_7 = { 498d7a78 e8???????? 498b9050010000 498b9858010000 498bb060010000 49899a98000000 4989b2a0000000 }
- $sequence_8 = { 84c0 0f8566feffff 31c0 488b6c2418 4883c420 c3 31c0 }
- $sequence_9 = { 0f1f00 e8???????? 31db 31c9 488d3d501c0c00 4889c6 31c0 }
+ $sequence_0 = { 493bc7 753b 488b05???????? ff05???????? 488bcb ff90f8000000 488d1560d80100 }
+ $sequence_1 = { 488d15b7aa0100 41b908000000 48c7c101000080 498943d8 c744245810000000 ff15???????? 85c0 }
+ $sequence_2 = { 0f44d8 eb0b 8b7c245c e8???????? 8bd8 85db 7415 }
+ $sequence_3 = { 744c 488d15be810200 488bcb 4d8bc7 e8???????? 488b05???????? }
+ $sequence_4 = { 8b01 eb06 ff90c0000000 410fb7cc eb3b 488bcf }
+ $sequence_5 = { 85c0 751e 4c8b4c2448 4c8b442440 488d1517640100 488b4c2430 ff15???????? }
+ $sequence_6 = { 8d6f07 458d77c7 8d5fce 488d8c2470010000 664489bc2470010000 6689bc2472010000 }
+ $sequence_7 = { c68424c20000006f c68424c300000073 4088bc24c4000000 c68424c500000073 c68424c60000006f c68424c700000063 4488bc24c8000000 }
+ $sequence_8 = { 8bd8 ebbf ff90e0000000 8bd8 85db 0f8481020000 3bdf }
+ $sequence_9 = { 4533c9 4533c0 48896c2458 4489642450 4489742454 48898698080000 c7869408000004000000 }
condition:
- 7 of them and filesize <7152640
+ 7 of them and filesize <422912
}
-rule MALPEDIA_Win_Roopirs_Auto : FILE
+rule MALPEDIA_Win_Grillmark_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "57676d4c-d0d7-5b4f-80a4-819b4d474425"
+ id = "891e7259-5469-58d4-a39e-a516f4f2c7d3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.roopirs"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.roopirs_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grillmark"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grillmark_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "d4e144778ab9b98b475c3cbfeb400528a9373556893774f62bba1f2eb8f36265"
+ logic_hash = "fc8f047bb79d7c6ba82d87162ce46a1dc6555c1672864dfce07f64d88dd917ae"
score = 75
quality = 75
tags = "FILE"
@@ -146404,32 +153398,32 @@ rule MALPEDIA_Win_Roopirs_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c745fc47000000 8b4dd8 51 68???????? ff15???????? 8945c0 }
- $sequence_1 = { 50 ff15???????? 898530ffffff eb0a c78530ffffff00000000 33c9 837da800 }
- $sequence_2 = { ff15???????? 8d4db0 ff15???????? c745fc07000000 833d????????00 751c 68???????? }
- $sequence_3 = { 8945b0 837db000 7d1d 6a20 68???????? 8b45dc 50 }
- $sequence_4 = { 8d55d4 52 6a05 ff15???????? 83c418 8d45bc 50 }
- $sequence_5 = { 8b02 8b4d80 51 ff5014 dbe2 89857cffffff }
- $sequence_6 = { 8b4508 50 8b08 ff5104 8b5514 56 8d45bc }
- $sequence_7 = { c78544ffffff00000000 8b45ac 89458c 8d4dcc 51 8b558c }
- $sequence_8 = { 68???????? 68???????? ff15???????? c78548ffffffd4624000 eb0a }
- $sequence_9 = { 8d4dc8 ff15???????? c745fc07000000 8b4dd8 51 68???????? }
+ $sequence_0 = { 83bd44ffffff04 7705 bb???????? 83bd44ffffff05 8b8548ffffff 7528 85c0 }
+ $sequence_1 = { 5e 5d c21400 55 8bec 56 68???????? }
+ $sequence_2 = { 59 7e13 50 57 6800000002 ff15???????? 8bd8 }
+ $sequence_3 = { 7409 ff75fc ff15???????? 56 56 56 }
+ $sequence_4 = { 66895dc4 50 c745c001010000 e8???????? ff7508 8d8590feffff 50 }
+ $sequence_5 = { 6a09 ab 59 8d7dc0 8975bc 8975f8 }
+ $sequence_6 = { 8dbdfdfeffff 889dfcfeffff 53 f3ab 66ab aa 8d85fcfeffff }
+ $sequence_7 = { 8d85f8fdffff 50 750d ffd7 8d85f4fcffff 50 }
+ $sequence_8 = { ff75f8 56 ff7508 ff75fc e8???????? 83c418 }
+ $sequence_9 = { ffd6 85c0 7473 8d45c8 }
condition:
- 7 of them and filesize <344064
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Treasurehunter_Auto : FILE
+rule MALPEDIA_Win_Tonedeaf_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d910c7d8-579e-5e04-9944-d334673c4daa"
+ id = "5115d077-589f-5849-9e66-466eacfeb8fa"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.treasurehunter"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.treasurehunter_auto.yar#L1-L103"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tonedeaf"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tonedeaf_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "15ce0cdcd8ce74cbd944226eb16c8cf48295e060eba7d0ca2d750492d2eadd11"
+ logic_hash = "05f38897859076fdc96710dcc7b02a4e168a1e7a497536a51feb5fc01846d4dd"
score = 75
quality = 75
tags = "FILE"
@@ -146443,30 +153437,32 @@ rule MALPEDIA_Win_Treasurehunter_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 75f9 2bf0 e8???????? 8bd0 }
- $sequence_1 = { 53 56 8b35???????? 8bd9 8b4d08 57 }
- $sequence_2 = { 8bf8 e8???????? 68???????? 57 e8???????? }
- $sequence_3 = { 8bd9 8b4d08 57 8955fc e8???????? 8bce 8bf8 }
- $sequence_4 = { 57 8bf9 8bca e8???????? 8b7508 }
- $sequence_5 = { 56 50 8903 ff15???????? 8b4dfc }
- $sequence_6 = { 7e0b 4a e8???????? 0fafc6 5e c3 }
- $sequence_7 = { e8???????? b9???????? a3???????? e8???????? 5f 5e a3???????? }
+ $sequence_0 = { ff15???????? 56 ff15???????? 56 ff15???????? 56 e8???????? }
+ $sequence_1 = { 2bf1 8bc3 46 d1e8 }
+ $sequence_2 = { 8bc3 46 d1e8 33d2 }
+ $sequence_3 = { 8b45ec 85c0 740b 6a08 50 }
+ $sequence_4 = { 884c32ff 84c9 75f3 8bf3 8a03 43 84c0 }
+ $sequence_5 = { 8b5004 8d4af8 898c153cffffff 8d45a8 c745fc01000000 50 }
+ $sequence_6 = { 56 6a00 ff15???????? 56 ff15???????? 56 ff15???????? }
+ $sequence_7 = { 83f801 732f 8b0f 8bc1 }
+ $sequence_8 = { 0f57c0 c745dc00000000 33c0 660fd645d4 33db 8945d8 }
+ $sequence_9 = { 75f3 8bf3 8a03 43 84c0 75f9 }
condition:
- 7 of them and filesize <229376
+ 7 of them and filesize <851968
}
-rule MALPEDIA_Win_Onliner_Auto : FILE
+rule MALPEDIA_Win_Hamweq_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c0a25174-badc-5a1b-a67c-48cbb1aef2be"
+ id = "5d79f276-5807-56d4-9ea0-44042b180646"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.onliner"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.onliner_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hamweq"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hamweq_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "6df36365f1b8dbe7cdb1d0b03d64f7da847c99d2518d7b5ebc1610f68ca3a069"
+ logic_hash = "f4464ade23ea171530cd0c6e2b15abfaf45c0eb2379ccacb80bd385a306f9a8e"
score = 75
quality = 75
tags = "FILE"
@@ -146480,32 +153476,32 @@ rule MALPEDIA_Win_Onliner_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f8274ffffff 6683ff04 0f8596000000 33ff 8d45e4 668b55ee c1e202 }
- $sequence_1 = { 8d8db4feffff 8bd3 8bc6 8b38 ff570c 8b85b4feffff 5a }
- $sequence_2 = { 85c0 7405 3b50fc 7205 e8???????? 42 8d4410ff }
- $sequence_3 = { 50 6a00 8bc3 e8???????? 50 ff15???????? }
- $sequence_4 = { 3b45e4 0f84ab000000 ff45e4 807dee00 742c 8b55e4 2bd0 }
- $sequence_5 = { 3345fc 03c6 0345cc 05c8fbd3e7 ba14000000 e8???????? 03c7 }
- $sequence_6 = { 8bda 8bf0 8bc3 ba02000000 e8???????? 8bc3 e8???????? }
- $sequence_7 = { 33c0 8945ec 837df000 7426 83caff 8b45f8 }
- $sequence_8 = { 3bc3 7c07 807c1eff20 74f4 57 b9ffffff7f 8bd3 }
- $sequence_9 = { 8b45fc 8b88d0010000 ba02000000 8b45fc 8b18 ff534c ff75e4 }
+ $sequence_0 = { 53 51 8b4e08 8945f8 ffb148010000 ff5044 }
+ $sequence_1 = { 8d85e4f1ffff 50 ff5744 50 }
+ $sequence_2 = { 837c910800 8d449108 894514 0f8438010000 837c910c00 }
+ $sequence_3 = { 668b4804 51 ff30 56 e8???????? 83c40c }
+ $sequence_4 = { 51 ff5040 8b0e 8d85ecfeffff 53 50 }
+ $sequence_5 = { 7504 6afe ebea 8b4e08 8b06 ff7170 }
+ $sequence_6 = { 8d4580 8b0b 50 ff5154 }
+ $sequence_7 = { 8b06 753c ffb1d8000000 8d8d00feffff 51 }
+ $sequence_8 = { 51 8d4d80 51 ff5054 eb12 8b5d08 }
+ $sequence_9 = { c3 8b442408 8a08 84c9 7408 }
condition:
- 7 of them and filesize <1736704
+ 7 of them and filesize <24576
}
-rule MALPEDIA_Win_Selfmake_Auto : FILE
+rule MALPEDIA_Win_Entryshell_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ca04d6b7-e045-5526-8793-d9e1e0d359e9"
+ id = "602f60d0-cc33-528b-8fdb-8d928745f559"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.selfmake"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.selfmake_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.entryshell"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.entryshell_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "c57531acfc321c5fdc74a4f21330394c8edf44f2f30ab3dcaf573b2b773dc0b6"
+ logic_hash = "870b124d6520583c6a18845739a5248302a0431048dbb7822501065378b2f353"
score = 75
quality = 75
tags = "FILE"
@@ -146519,32 +153515,32 @@ rule MALPEDIA_Win_Selfmake_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c104 3bf0 7ce3 68???????? }
- $sequence_1 = { 83e107 894df4 8b55f4 52 ff15???????? a1???????? 8be5 }
- $sequence_2 = { 8d742430 742e e8???????? 6aff }
- $sequence_3 = { 47 84c0 75f8 66a1???????? 668907 8d44243c 8bd0 }
- $sequence_4 = { 8945f8 837df800 7408 8b45f8 e9???????? e8???????? }
- $sequence_5 = { 8b4b2c 6a00 6a01 51 ffd0 8b16 83c604 }
- $sequence_6 = { 7604 2bf1 eb02 33f6 8b4310 25c0010000 83f840 }
- $sequence_7 = { 81fa???????? 7209 83c014 3bc1 72eb }
- $sequence_8 = { 51 e8???????? 8b742418 8bbc2418020000 }
- $sequence_9 = { e8???????? 56 e8???????? 8b442424 8b35???????? 83c414 50 }
+ $sequence_0 = { 85db 7517 53 8d95e4dfffff 8b8d8cddffff }
+ $sequence_1 = { 771d 8d8290c72501 8d5001 660f1f440000 }
+ $sequence_2 = { 83c40c 8d8424a8080000 50 6804010000 ff15???????? 8d442450 50 }
+ $sequence_3 = { 8b46f8 0fb684054fffffff 8842fd 83ef01 75a1 0f1003 53 }
+ $sequence_4 = { 83c404 84c0 0f8495010000 8bbdf4efffff 85ff 0f84eefcffff 6a20 }
+ $sequence_5 = { e8???????? 59 83cfff 897de4 33c9 894dfc 8b049d78512501 }
+ $sequence_6 = { 8945f8 53 8b5d08 0f57c0 56 57 895de8 }
+ $sequence_7 = { 83c40c 8d4ffe 668b4102 8d4902 6685c0 75f4 e9???????? }
+ $sequence_8 = { 8a0445399f2401 eb02 32c0 0fb64d0c 0fb6c0 6bc009 03c1 }
+ $sequence_9 = { 02d2 029013800000 02d2 029014800000 02d2 029015800000 02d2 }
condition:
- 7 of them and filesize <932864
+ 7 of them and filesize <663552
}
-rule MALPEDIA_Win_Pinchduke_Auto : FILE
+rule MALPEDIA_Win_Darkbit_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cba434ff-ad3f-569d-a5ea-a8661b7af309"
+ id = "58b27aad-7d48-54be-9cff-6269fdf4ce6e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pinchduke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pinchduke_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkbit"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkbit_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "91b75415e43b3618cf4d35265fc79e44823a3f174f6cf370c8d280ecd6905acb"
+ logic_hash = "06c0013c639973d9f2d79cd394915657a8e01f1fe7c56128c97a4b11c48d29ab"
score = 75
quality = 75
tags = "FILE"
@@ -146558,32 +153554,32 @@ rule MALPEDIA_Win_Pinchduke_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a01 895dd4 895dd8 895ddc c645e030 895de1 }
- $sequence_1 = { 9b d93c24 9b 58 50 80e4f3 80cc08 }
- $sequence_2 = { 85d2 7416 8d4c50fe 2bf0 57 668b3c0e 668939 }
- $sequence_3 = { 83c40c 8d857bffffff 50 8d4dc4 e8???????? 8d8d7bffffff e8???????? }
- $sequence_4 = { 50 ff15???????? 3bc3 89456c 0f84cc020000 }
- $sequence_5 = { 8945fc e8???????? 83c410 ff75fc 56 ff15???????? 56 }
- $sequence_6 = { 64a118000000 3e8b4030 3e0fb64002 890424 8b0424 59 c3 }
- $sequence_7 = { 6a00 ff7510 ff75fc ffd6 85c0 7404 33c0 }
- $sequence_8 = { 85d2 75f5 8bc7 5f 5e c3 8b4c240c }
- $sequence_9 = { e8???????? 8d85e4f7ffff 50 e8???????? 83ec0c 8bcc 50 }
+ $sequence_0 = { e8???????? 48898424f0140000 48899c2498020000 488b0d???????? 48898c2478100000 488d05c1742500 90 }
+ $sequence_1 = { eb23 4889c7 488b8c24d0180000 e8???????? 488d7810 488b8424c8180000 6690 }
+ $sequence_2 = { e8???????? 4889842410010000 48899c2418070000 488b442460 48c7c3feffffff e8???????? 4889842470010000 }
+ $sequence_3 = { eb11 488d7818 488b8c24f0110000 e8???????? 488b8c24e8030000 48894810 833d????????00 }
+ $sequence_4 = { 833d????????00 7515 488b8c24a81e0000 488908 488905???????? 90 eb1c }
+ $sequence_5 = { e8???????? 488b542440 48895008 833d????????00 750d 488b9424c0000000 488910 }
+ $sequence_6 = { e8???????? 4889842428080000 48899c2480110000 488b8424a0080000 48c7c3ffffffff 0f1f440000 e8???????? }
+ $sequence_7 = { e8???????? 488d8424d8000000 488b9c2408010000 90 e8???????? b801000000 eb21 }
+ $sequence_8 = { e8???????? 803d????????00 7431 488d1543fa1a00 488915???????? 833d????????00 7509 }
+ $sequence_9 = { ffd2 84c0 7556 488d0509aa3000 488b5c2430 488b4c2438 e8???????? }
condition:
- 7 of them and filesize <223680
+ 7 of them and filesize <11612160
}
-rule MALPEDIA_Win_Mangzamel_Auto : FILE
+rule MALPEDIA_Win_Poison_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "efd17f11-bd84-5994-8489-ce27d4f0f0e6"
+ id = "3901c97f-e38d-5819-991e-493be520fc51"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mangzamel"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mangzamel_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poison_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poison_rat_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "e3b6cc187254084e27045992bdf0d8b8ff879105635bf8f3e82d14e2723774a4"
+ logic_hash = "b960cb72b2615d9b184a9e25264d3c87f1ec796c5d1b6fa8620d3a64be9786ae"
score = 75
quality = 75
tags = "FILE"
@@ -146597,32 +153593,32 @@ rule MALPEDIA_Win_Mangzamel_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b7508 837e1410 7404 32c0 eb6e 8b06 53 }
- $sequence_1 = { 8d8dd4feffff e8???????? 33db 8d8dc0fdffff 895dfc e8???????? 8d85d4feffff }
- $sequence_2 = { 6a00 8bce ff7674 e8???????? 6a01 6804000102 8bce }
- $sequence_3 = { ff7508 e8???????? 84c0 7404 c645f301 8b4df4 }
- $sequence_4 = { 8bd0 8b00 8b5208 3932 7506 837a0400 }
- $sequence_5 = { e8???????? 33c0 8bce 50 50 50 ff742414 }
- $sequence_6 = { 8bce ff7508 ff5040 8ac3 5e 5b 5d }
- $sequence_7 = { 57 8b7c2414 33c0 8907 8b0d???????? 3bc8 }
- $sequence_8 = { 8d4b6c e8???????? 5e 5b c3 56 8bf1 }
- $sequence_9 = { 8b74240c 57 8b7c240c 8d4602 50 57 e8???????? }
+ $sequence_0 = { 6880000000 8d85d4fcffff 52 50 e8???????? }
+ $sequence_1 = { 40 83f810 7cee 83ee10 4f 75ac 33c0 }
+ $sequence_2 = { 81e1ff000000 83c010 331cad30a44000 8b68f8 }
+ $sequence_3 = { e8???????? 8d8560ffffff 68???????? 50 e8???????? ffb6eca94000 }
+ $sequence_4 = { 81e5ff000000 333cad30a44000 8b68fc 33fd 8bea }
+ $sequence_5 = { f3a5 ff249578334000 8bc7 ba03000000 }
+ $sequence_6 = { 33c9 897c2418 8a6e08 8a4e09 }
+ $sequence_7 = { c1ea18 81e5ff000000 330c9530984000 8bd7 81e2ff000000 330c9530a44000 8b10 }
+ $sequence_8 = { 8b34b530984000 8b1cbd309c4000 c1e908 33f3 81e1ff000000 8b0c8d30804000 }
+ $sequence_9 = { 8bf1 c1f805 83e61f 8d3c8580c54000 c1e603 8b07 }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <101688
}
-rule MALPEDIA_Win_Mount_Locker_Auto : FILE
+rule MALPEDIA_Win_Rover_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6832e6a1-eaa1-5e1c-99c0-2c5304573141"
+ id = "1dedd2f8-89d8-5b82-937e-e4187a543962"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mount_locker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mount_locker_auto.yar#L1-L152"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rover"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rover_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "bff6076907046250738924c00fe6ba5da63e4a09d46fe90acd3aa54210bff35b"
+ logic_hash = "6367e2cdf56f70609689c8633064a076a7b96ec3143349e9ae15d5e0ca66c168"
score = 75
quality = 75
tags = "FILE"
@@ -146636,38 +153632,32 @@ rule MALPEDIA_Win_Mount_Locker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 81f900000780 7503 0fb7c0 3d2e050000 }
- $sequence_1 = { f30f5905???????? 0f5ad0 66490f7ed0 e8???????? }
- $sequence_2 = { 4d8bc8 4c8bc2 4c8bf2 8bf1 }
- $sequence_3 = { 8bc8 81e10000ffff 81f900000780 7503 }
- $sequence_4 = { 488b0b 41b902000000 4533c0 33d2 }
- $sequence_5 = { 488d4df0 4889442428 4533c9 4533c0 }
- $sequence_6 = { 488bcb 488b15???????? e8???????? 85c0 }
- $sequence_7 = { 488364242000 4533c9 488b4c2458 33d2 c744243001000000 c744243c02000000 }
- $sequence_8 = { 4c8bf2 8bf1 33d2 33c9 }
- $sequence_9 = { ff15???????? 85c0 7509 f0ff05???????? }
- $sequence_10 = { b905000000 ff15???????? 3d040000c0 7494 85c0 }
- $sequence_11 = { 7505 e8???????? 833d????????00 7409 833d????????00 }
- $sequence_12 = { 8d442430 68???????? 50 ffd7 }
- $sequence_13 = { a1???????? 83f804 7515 68???????? }
- $sequence_14 = { 8bf0 85f6 7424 6800010000 }
- $sequence_15 = { ff15???????? 85c0 7409 f0ff05???????? eb1e 56 }
+ $sequence_0 = { 6800120000 885c247b ff15???????? 85c0 0f8422010000 8b35???????? 8d542460 }
+ $sequence_1 = { ff15???????? 8d4c2404 c684249c00000000 ff15???????? 8d8c24a4000000 c784249c000000ffffffff }
+ $sequence_2 = { 83ed01 0f8464010000 83ed04 0f845b010000 83bba402000000 8b6a28 896c240c }
+ $sequence_3 = { 85db 0f856f030000 8b471c 85c0 7421 50 8d442414 }
+ $sequence_4 = { 8bf0 83c404 3bf3 7537 a1???????? 8b4824 8d542438 }
+ $sequence_5 = { 50 8b442458 68???????? 50 e8???????? 83c410 85c0 }
+ $sequence_6 = { 8b8fb0050000 8d6b50 89442410 8987b0050000 8b85a8000000 8bd0 80e215 }
+ $sequence_7 = { 83e802 7426 83e815 740f 683f270000 ff15???????? 83c8ff }
+ $sequence_8 = { 83c40c c3 6a2f 57 ffd6 83c408 85c0 }
+ $sequence_9 = { 57 e8???????? 56 e8???????? 83c40c c744242c04000000 }
condition:
- 7 of them and filesize <368640
+ 7 of them and filesize <704512
}
-rule MALPEDIA_Win_Manjusaka_Auto : FILE
+rule MALPEDIA_Win_Hyperbro_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9f188d62-91cb-5093-86fd-1c78b358599b"
+ id = "3941e796-a485-533f-bda6-3b99f666d1b3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.manjusaka"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.manjusaka_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hyperbro"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hyperbro_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "dab9ae475e0b441f3d26af80a0ebc722e21c766bc33599d09d1c1a5353ad7516"
+ logic_hash = "4bee21ef51c3ea4f0bd6259a2f8a9c95c3e4ba56a999c789fc7f134934b59561"
score = 75
quality = 75
tags = "FILE"
@@ -146681,32 +153671,32 @@ rule MALPEDIA_Win_Manjusaka_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ebb8 488d05b77a1000 4889442450 48c744245801000000 48c744246000000000 488d05f9b01100 4889442470 }
- $sequence_1 = { 4c89bc2480040000 4c8939 4c897108 48895910 48c7411800800000 0f117018 48897930 }
- $sequence_2 = { 791d 418b4128 41034124 4863c8 488bc2 48f7d8 48c1e00a }
- $sequence_3 = { 89411c 488b45d7 2b4527 05feffff07 89710c 894120 8b45db }
- $sequence_4 = { 4989f8 e8???????? 48ffcb 75ed 0f57f6 488d9c2410010000 0f297320 }
- $sequence_5 = { 898c24f8000000 48896c2448 3b08 0f8c21fdffff 4c8bbc24f0000000 4d85f6 7424 }
- $sequence_6 = { 814d4002020000 4533c0 48894500 498bcd 83c8ff 66894544 b8c8000000 }
- $sequence_7 = { 89573c 48894740 895750 488b442e60 48894758 488b442e28 488b4860 }
- $sequence_8 = { f7d8 894c2420 448bc5 498bcd 1bd2 4533c9 83e2fc }
- $sequence_9 = { e8???????? 4889d9 e8???????? 488d4f70 e8???????? 488d8fe0000000 e8???????? }
+ $sequence_0 = { 33c0 6a40 66890479 e8???????? 6a40 }
+ $sequence_1 = { 8b4604 83c004 50 6a00 57 }
+ $sequence_2 = { 46 47 83e801 75f5 }
+ $sequence_3 = { 8d542428 68???????? c74424200c000000 c744242801000000 89542424 ff15???????? }
+ $sequence_4 = { 05ff000000 41 3d01feffff 0f871c010000 8bd5 2bd1 83fa01 }
+ $sequence_5 = { 50 8d4c2472 51 6689442474 }
+ $sequence_6 = { 6882000000 c706???????? e8???????? 6882000000 6a00 50 }
+ $sequence_7 = { e8???????? 83c404 83eb01 79ec 8b4f2c 51 e8???????? }
+ $sequence_8 = { 83c410 85ed 750e 8b7c2410 }
+ $sequence_9 = { 8b44242c 3bc3 7415 50 e8???????? 83c404 }
condition:
- 7 of them and filesize <4772864
+ 7 of them and filesize <352256
}
-rule MALPEDIA_Win_Cerber_Auto : FILE
+rule MALPEDIA_Win_Unidentified_020_Cia_Vault7_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1b1175b4-aaae-5323-bbb6-472b8daa3220"
+ id = "229fefe8-12a2-5321-841b-a1c5858ad20f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cerber"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cerber_auto.yar#L1-L101"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_020_cia_vault7"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_020_cia_vault7_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "90183139badfe5f943ec4dd7b3bc0305f6ea2215a75a5dc8603646346366cf36"
+ logic_hash = "121c8e165e7a80ef0b3dea83e1137d20669defc5a0d83275fbb5b7562347ae72"
score = 75
quality = 75
tags = "FILE"
@@ -146720,30 +153710,32 @@ rule MALPEDIA_Win_Cerber_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4a 79f6 5f 8bc6 }
- $sequence_1 = { 85c0 750c 8b33 e8???????? 832300 eb0e 8b4dfc }
- $sequence_2 = { 33f9 8b88e0000000 894dd0 8b88e4000000 899864010000 8b5dd8 }
- $sequence_3 = { 4a 79e6 47 3b7d0c }
- $sequence_4 = { 51 53 56 8bf0 57 85f6 7508 }
- $sequence_5 = { 4a b800000080 83e904 eb02 }
- $sequence_6 = { 895df4 33c9 83fa08 0f9dc1 854df4 7515 }
- $sequence_7 = { 33f9 8b88e8feffff 234808 8998fc000000 8b5874 }
+ $sequence_0 = { 6a08 6a01 52 ff15???????? 85c0 0f859f000000 8b45d0 }
+ $sequence_1 = { 57 ff15???????? 8bf0 85f6 0f8470ffffff 8b85ecfdffff }
+ $sequence_2 = { 6a00 6a00 6a00 6a00 8d95f4fdffff 52 6a01 }
+ $sequence_3 = { 8bc1 c1f805 8bf1 83e61f 8d3c8520834100 8b07 }
+ $sequence_4 = { 0f870d0a0000 ff2485bbce4000 33c0 838df4fbffffff 898598fbffff 8985b0fbffff }
+ $sequence_5 = { 33d2 6806020000 52 8d85eafbffff 50 668995e8fbffff e8???????? }
+ $sequence_6 = { 5d c3 b984120000 b8???????? }
+ $sequence_7 = { 8d45f4 50 52 51 57 ff15???????? 8b4d08 }
+ $sequence_8 = { 50 51 ff15???????? 85c0 7420 8b55fc }
+ $sequence_9 = { 83ffff 7410 8d4c2420 51 }
condition:
- 7 of them and filesize <573440
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Virtualgate_Auto : FILE
+rule MALPEDIA_Win_Hoplight_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5ab8135e-3bbe-5abd-acc2-717daf53613e"
+ id = "d07c2fe2-ecaa-5d6d-9200-86c11ba23c84"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.virtualgate"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.virtualgate_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hoplight"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hoplight_auto.yar#L1-L90"
license_url = "N/A"
- logic_hash = "5ca5297d10bab80aa59720f493a7b89d0ffff3ac0eaaf62e59c4e5ea64ea6f84"
+ logic_hash = "247623c43b610ddcbb448aac3610ffa1141476124d800ee4677cf300abbf0143"
score = 75
quality = 75
tags = "FILE"
@@ -146757,32 +153749,30 @@ rule MALPEDIA_Win_Virtualgate_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4157 4883ec38 4c63e9 488bf2 498bc5 488d0dc7f10000 }
- $sequence_1 = { 4b8794fed02a0200 eb2d 4c8b15???????? ebb8 4c8b15???????? 418bc2 b940000000 }
- $sequence_2 = { 8d58b0 498bce 448bc3 488d1580bd0000 e8???????? 85c0 7429 }
- $sequence_3 = { ff15???????? c705????????00001000 eb26 4183f802 }
- $sequence_4 = { 488bc8 ff15???????? 3b05???????? 488bcb 89442450 7608 }
- $sequence_5 = { 48894527 498bc0 48ffc0 41381407 75f7 498bc8 48ffc1 }
- $sequence_6 = { 4c8d05b4d30000 488d15b1d30000 e8???????? 4885c0 7416 }
- $sequence_7 = { 488bf5 4803d2 498b94d750b50100 e8???????? 85c0 }
- $sequence_8 = { 4c8d058dbe0100 488bd5 48c1fa06 4c893403 488bc5 }
- $sequence_9 = { 488b8c2420800200 4833cc e8???????? 488b9c2450800200 }
+ $sequence_0 = { 488b4c2460 e8???????? 8b442428 488d0d5e680200 }
+ $sequence_1 = { 488b5260 8b0481 894208 488b842480000000 }
+ $sequence_2 = { 8b442424 25ff000000 8bc0 488d0d87740200 }
+ $sequence_3 = { 4889542420 4d8bc8 488b442440 4c8bc0 }
+ $sequence_4 = { 4c8bb42498040000 488b8d80030000 4833cc e8???????? }
+ $sequence_5 = { 488d4c2460 e8???????? 488b842470020000 488b4060 }
+ $sequence_6 = { 4833c4 48898424f8000000 c744242800000000 488b842410010000 }
+ $sequence_7 = { 4c8d05883c0300 488bd0 488b4c2450 e8???????? }
condition:
- 7 of them and filesize <323584
+ 7 of them and filesize <765952
}
-rule MALPEDIA_Win_Himera_Loader_Auto : FILE
+rule MALPEDIA_Win_Kasperagent_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e46aed8f-6384-5100-b12a-1e2dd8afe756"
+ id = "31bd379d-36ff-5056-a7b4-5cc60c9344f8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.himera_loader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.himera_loader_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kasperagent"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kasperagent_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "ec88d24287290abbd140c4f0211e2582e892064d8e933b967abedc9a00192e9f"
+ logic_hash = "a97fb5a8dde23a8ff235ddb0c06e57b70ba205db49e4efcaa1ba693facbe4b47"
score = 75
quality = 75
tags = "FILE"
@@ -146796,34 +153786,34 @@ rule MALPEDIA_Win_Himera_Loader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83c408 8b4dfc 6689411e 6a10 }
- $sequence_1 = { 64a300000000 894de0 c745dc0c000000 c645e45e c645e55d }
- $sequence_2 = { 8b4d08 0fb71401 52 e8???????? 83c408 8b4dfc 66894130 }
- $sequence_3 = { 8d85dcfdffff 50 8d8df8feffff 51 8d95f8feffff 52 8d8deffdffff }
- $sequence_4 = { c20400 e8???????? 85c0 0f84c1510000 }
- $sequence_5 = { c645eb1c c645ec2e 64a12c000000 8b08 8b15???????? 3b9104000000 7e4c }
- $sequence_6 = { 50 8d45f4 64a300000000 894de0 c745dc0a000000 c645e440 c645e55a }
- $sequence_7 = { c7459c49000000 c645a463 c645a541 c645a654 c645a747 c645a842 c645a942 }
- $sequence_8 = { c645e801 c645e90e c645ea18 c645eb1a c645ec00 c645ed1e c645ee2e }
- $sequence_9 = { c745fc00000000 eb09 8b45fc 83c001 8945fc 837dfc25 7321 }
+ $sequence_0 = { 84c0 741e 8bd6 57 52 e8???????? }
+ $sequence_1 = { ffb4b5b4fdffff 8b95ccfdffff 8b8dd8fdffff e8???????? 59 3bc3 }
+ $sequence_2 = { 83c404 8bd8 83caff f00fc117 }
+ $sequence_3 = { 33c9 894c2430 894c2434 894c2438 894c243c 85c0 7463 }
+ $sequence_4 = { 8d742410 8d442408 c7470800000000 894c240c e8???????? 84c0 }
+ $sequence_5 = { 7cb4 8b4c2414 8b01 3b70f8 }
+ $sequence_6 = { 66390c78 7535 84db 7524 }
+ $sequence_7 = { 8b50f4 52 50 e8???????? 5d }
+ $sequence_8 = { 7419 8d642400 3bfa 7311 }
+ $sequence_9 = { 8d3451 33ff 3bce 7419 8d642400 3bfa }
condition:
- 7 of them and filesize <385024
+ 7 of them and filesize <1605632
}
-rule MALPEDIA_Win_Rdat_Auto : FILE
+rule MALPEDIA_Win_Turla_Rpc_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "92191fa2-5f3d-5b42-a025-816ea5c7ba9a"
+ id = "d062a0c9-c6c6-5f57-a60f-6c6b55d2f616"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rdat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rdat_auto.yar#L1-L164"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.turla_rpc"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.turla_rpc_auto.yar#L1-L171"
license_url = "N/A"
- logic_hash = "258a7b0e2fbdc995f078ce1c969b2a27e77e31fae7722d9e4f1fdbfa2416146c"
- score = 60
- quality = 45
+ logic_hash = "696b632d482c9df6571dae61d7a8f9238e184ca30e0aa7fbb216cfbf4128270e"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -146835,38 +153825,38 @@ rule MALPEDIA_Win_Rdat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3b7744 0f8c19ffffff 8b87ac020000 33ed }
- $sequence_1 = { 48ffc3 4038341a 75f7 4883791810 488b7910 7203 488b09 }
- $sequence_2 = { 4863ed 4885ed 0f8ed8000000 8b54b430 }
- $sequence_3 = { 4c8bc3 4c0f42c7 4d85c0 7504 8bc6 }
- $sequence_4 = { 4889442470 448bb910010000 4532e4 448aea 488bd9 4585ff 0f8e1e020000 }
- $sequence_5 = { 4533ff 4c8bf1 44397944 0f8e64010000 }
- $sequence_6 = { 48894108 4c8b05???????? 488b15???????? 89442420 4d85c0 }
- $sequence_7 = { 488b09 483bfb 4c8bc3 4c0f42c7 }
- $sequence_8 = { 45380401 75f7 4c8bc0 498bd1 488d4c2438 }
- $sequence_9 = { e8???????? 4898 4885c0 751e 483bfb 7313 83c8ff }
- $sequence_10 = { 85c0 740b b9e8030000 ff15???????? }
- $sequence_11 = { 4863f0 33d2 8bc2 48c1e006 }
- $sequence_12 = { 3b566c 0f8d9e000000 488b4660 3b5668 7c1d 2b5668 }
- $sequence_13 = { 7203 488b00 4c8bc0 498bd7 488d4de0 }
- $sequence_14 = { 0f84f5000000 4883f910 7205 488b07 }
- $sequence_15 = { 488d8c2490060000 e8???????? 90 488b942490060000 803a00 7505 4d8bc6 }
+ $sequence_0 = { c645bc55 c7854001000030163930 c78544010000343b2025 c6854801000055 c78560010000013c3830 c785640100003a202155 }
+ $sequence_1 = { c744244806393030 66c744244c2555 c785c000000006302110 c785c400000027273a27 c785c8000000183a3130 c685cc00000055 }
+ $sequence_2 = { c7456016273034 c745642130133c c7456839300255 c7851001000016273034 c7851401000021300527 c785180100003a363026 }
+ $sequence_3 = { c745b06970746f c745b472536163 66c745b86c00 ff15???????? }
+ $sequence_4 = { c7850401000030102d36 c785080100003025213c 66c7850c0100003a3b c6850e01000055 c745c007303431 }
+ $sequence_5 = { 488bd8 ffd3 488d4d70 488bf8 ffd3 }
+ $sequence_6 = { c6458e55 c744245033273034 66c74424543155 c744243033273030 c644243455 c744244033263030 66c74424443e55 }
+ $sequence_7 = { c6852e01000055 c745b0193a3431 c745b4193c3727 c745b834272c14 c645bc55 c7854001000030163930 c78544010000343b2025 }
+ $sequence_8 = { c7851401000021300527 c785180100003a363026 66c7851c0100002602 c6851e01000055 }
+ $sequence_9 = { c7854cffffff00000000 c78548ffffff00000000 c78554ffffff00000000 c78550ffffff00000000 c745bc53003a00 c745c028004d00 c745c44c003b00 }
+ $sequence_10 = { 56 ffd3 8987d8000000 8d87dc000000 }
+ $sequence_11 = { 68???????? ff15???????? 8b4dfc 33c0 5f 5e }
+ $sequence_12 = { 8bf8 85ff 7514 8d45ac 50 ff15???????? }
+ $sequence_13 = { 57 ff15???????? 8b85b8fdffff ffb5bcfdffff a3???????? }
+ $sequence_14 = { 68???????? e8???????? 6a03 68???????? 8d0c45ac880110 8bc1 }
+ $sequence_15 = { 8d45c8 50 ffd6 8bf8 8d8558ffffff }
condition:
- 7 of them and filesize <1573888
+ 7 of them and filesize <311296
}
-rule MALPEDIA_Win_Rifdoor_Auto : FILE
+rule MALPEDIA_Win_Blackbyte_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "10650b5d-c263-58c2-9892-48c8752426d4"
+ id = "ae2ced49-3989-5cc9-8c98-64c5f933a895"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rifdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rifdoor_auto.yar#L1-L174"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackbyte"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackbyte_auto.yar#L1-L158"
license_url = "N/A"
- logic_hash = "041eb6ebe0e6f7a680f9d10fa1b95fdf41bb567152330eaf4a0d973e56aa2474"
+ logic_hash = "1cee2f7e2bce0af57e75d6fdf4454ccb725b7569d4236140429240d2a7df1fe9"
score = 75
quality = 75
tags = "FILE"
@@ -146880,38 +153870,38 @@ rule MALPEDIA_Win_Rifdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8be5 5d c20400 6804010000 8d54240c }
- $sequence_1 = { 0f8484000000 391d???????? 747c 391d???????? 7474 391d???????? 746c }
- $sequence_2 = { ba4f000000 8bc2 668944243c b952000000 66894c2438 668954243a }
- $sequence_3 = { 83c408 85c0 7405 bf01000000 8d542410 52 ff15???????? }
- $sequence_4 = { 830eff 2b34bd605d4100 c1fe06 8bc7 c1e005 }
- $sequence_5 = { b001 5e 81c408010000 c3 5f 32c0 }
- $sequence_6 = { 8d4c2454 51 8b4c2410 8d54242c e8???????? 83c408 85c0 }
- $sequence_7 = { 83c408 a3???????? e9???????? 3c01 }
- $sequence_8 = { 53 56 8b35???????? 57 3b35???????? 7d4a }
- $sequence_9 = { 50 8b410c ffd0 8b95f0f7ffff }
- $sequence_10 = { e8???????? 8b1d???????? 33c0 83c40c 33d2 }
- $sequence_11 = { 68ff000000 8d9524faffff 52 ff15???????? }
- $sequence_12 = { 75f9 8d8de8fbffff 2bc2 51 40 }
- $sequence_13 = { c1ee08 0bd6 884101 03c2 8d1400 33d0 }
- $sequence_14 = { ff15???????? 68???????? 6a00 6801001f00 ff15???????? 5f 5e }
- $sequence_15 = { 8d8424a8010000 50 53 ff15???????? 85c0 7507 53 }
+ $sequence_0 = { 488d15bc010000 4889542478 4889842480000000 488d542478 4889942490000000 c644242701 }
+ $sequence_1 = { 488d0db4020000 488908 833d????????00 7520 488b4c2428 48894808 }
+ $sequence_2 = { 0fb64210 88442408 0fb64211 88442409 }
+ $sequence_3 = { 0fb6420b 8844240b 0fb6420c 8844240c 0fb6420d 8844240d 0fb6420e }
+ $sequence_4 = { 488d4a01 488b442428 488b5c2430 4883f903 }
+ $sequence_5 = { 0101 ffc5 3b6b68 0f82e6feffff }
+ $sequence_6 = { 488d542478 4889942490000000 c644242701 488b9c24a8000000 488b8c24b0000000 e8???????? }
+ $sequence_7 = { 488d4250 488b542430 488d5a50 b918000000 }
+ $sequence_8 = { 0fb6420d 8844240d 0fb6420e 8844240e 0fb6420f 8844240f }
+ $sequence_9 = { 488d542470 4889942488000000 c644241f01 488b9c24a0000000 }
+ $sequence_10 = { 488d4a01 488b442430 488b5c2438 90 4883f90f }
+ $sequence_11 = { 0fb64212 8844240a 0fb64213 8844240b }
+ $sequence_12 = { 0fb6420f 8844240f 488b442408 48894108 }
+ $sequence_13 = { 488d5c244b b902000000 0f1f440000 e8???????? }
+ $sequence_14 = { 014608 498bce ffd7 448b85e8040000 }
+ $sequence_15 = { 0fb64211 88442409 0fb64212 8844240a }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <9435136
}
-rule MALPEDIA_Win_Gandcrab_Auto : FILE
+rule MALPEDIA_Win_Shifu_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8fb97f0d-f07e-528f-846a-617ae03e5a0b"
+ id = "b2b85e64-d954-5aeb-b02a-9d97cb3ba3ee"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gandcrab"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gandcrab_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shifu"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shifu_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "51f7c1543a06dc758514ed4496666d6ea311b3c69b16117153a658edbbb8509b"
+ logic_hash = "fa5868e6742fc467c77c9f2e2fa5062fd3f24b48dd60ea0ece307848b06e5759"
score = 75
quality = 75
tags = "FILE"
@@ -146925,32 +153915,32 @@ rule MALPEDIA_Win_Gandcrab_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? ff7728 8bf0 ff15???????? 03c3 8d5e04 }
- $sequence_1 = { 7403 83c314 837f7400 741b ff777c ff15???????? ff7778 }
- $sequence_2 = { 8d5e04 03d8 837f2400 741b ff772c }
- $sequence_3 = { ff774c 8bf0 ff15???????? 03c3 8d5e04 03d8 }
- $sequence_4 = { 03c3 8d5e04 03d8 837f5400 741b }
- $sequence_5 = { 03c3 8d5e04 03d8 837f3000 741b }
- $sequence_6 = { ff774c 8bf0 ff15???????? 03c3 8d5e04 }
- $sequence_7 = { 837f1800 741b ff7720 ff15???????? }
- $sequence_8 = { 03d8 837f6000 7403 83c314 837f7400 741b ff777c }
- $sequence_9 = { ff15???????? 03c3 8d5e04 03d8 837f3000 }
+ $sequence_0 = { 85c0 740d 57 6a1b ba???????? }
+ $sequence_1 = { 6a24 ff7508 ffd6 53 8d45f0 50 }
+ $sequence_2 = { 83651800 8d941a00010000 895508 8b5510 0fbe1410 89550c 85c9 }
+ $sequence_3 = { 740c e8???????? 8325????????00 8d85fcfeffff e8???????? }
+ $sequence_4 = { 50 ff75f4 ff15???????? 85c0 7511 ff75f0 8d443701 }
+ $sequence_5 = { 668985a2fcffff b8170b0000 66898578fcffff 6a14 58 6689857afcffff 8b4348 }
+ $sequence_6 = { 83c102 836d0c02 eb2d 8bd9 8b4f2c 2bd8 035de8 }
+ $sequence_7 = { 8975e4 6a0c 58 e8???????? 8965e8 8bfc 3bfe }
+ $sequence_8 = { 33c0 5e c9 c20c00 55 8bec 85c9 }
+ $sequence_9 = { 56 8d85e8feffff 53 50 ff15???????? 8d85e8feffff 83c410 }
condition:
- 7 of them and filesize <1024000
+ 7 of them and filesize <344064
}
-rule MALPEDIA_Win_Pykspa_Auto : FILE
+rule MALPEDIA_Win_Hazy_Load_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c344e44d-277b-5916-93ac-fe5b84ee097a"
+ id = "f9ce3341-35f2-576a-ac44-5d1a215a7e85"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pykspa"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pykspa_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hazy_load"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hazy_load_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "ae1a9dadb1337e6c1ef760caa0d42ce5c68005bd2830f1ee498d2437086c9f33"
+ logic_hash = "2293495fdcc042b4bc9589ccdd3e32857e18de0ce6c242812538dc1d663eb294"
score = 75
quality = 75
tags = "FILE"
@@ -146964,32 +153954,32 @@ rule MALPEDIA_Win_Pykspa_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b5c240c 57 8b7c240c 3bfb 7513 57 8b7c2418 }
- $sequence_1 = { 6a00 c6400e01 ff15???????? cc 55 8bec b89c110000 }
- $sequence_2 = { c3 a1???????? 85c0 7501 c3 8b4818 85c9 }
- $sequence_3 = { 381d???????? 8b2d???????? 744f 8d442418 68???????? 50 e8???????? }
- $sequence_4 = { c60000 807d0000 0f843b010000 57 ff742414 e8???????? 50 }
- $sequence_5 = { 0f95c0 5e c3 55 8bec 83ec54 53 }
- $sequence_6 = { ff15???????? 8b35???????? 53 ffd6 8b3d???????? 53 ffd7 }
- $sequence_7 = { 381d???????? 7508 381d???????? 743e 56 ff15???????? 83f805 }
- $sequence_8 = { 8d85acfeffff 68???????? 50 e8???????? 85c0 59 59 }
- $sequence_9 = { 6a05 8bca 33d2 f7f3 8bc7 bb40e20100 03ca }
+ $sequence_0 = { b904000000 4c8d05f5c50000 488d15aeb20000 e8???????? 488bf8 4885c0 740f }
+ $sequence_1 = { 48897c2408 488b15???????? 488d3dd16d0100 8bc2 b940000000 83e03f 2bc8 }
+ $sequence_2 = { 488d0db8200100 4183e23f 4903e8 832700 498bf0 }
+ $sequence_3 = { 488bf1 41bc02000000 4489742420 418bcc 448d4205 ff15???????? }
+ $sequence_4 = { 4b87bcf750140200 33c0 488b5c2450 488b6c2458 488b742460 }
+ $sequence_5 = { 483b0d???????? 7417 488d0570630100 483bc8 740b 83791000 7505 }
+ $sequence_6 = { 4883675000 488d05ade0ffff 83675800 488d4f28 }
+ $sequence_7 = { 488d15a96a0100 83e13f 488bc5 48c1f806 48c1e106 }
+ $sequence_8 = { 442bc3 4803d0 4533c9 488bce ff15???????? 85c0 0f8eacfeffff }
+ $sequence_9 = { 488d0dc0210100 4183e23f 4903e8 832300 }
condition:
- 7 of them and filesize <835584
+ 7 of them and filesize <315392
}
-rule MALPEDIA_Win_Matryoshka_Rat_Auto : FILE
+rule MALPEDIA_Win_Cruloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3e8b1848-3ea9-5312-86aa-83712c0906a6"
+ id = "975bd752-b718-50f1-9af8-cfa41728edc9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.matryoshka_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.matryoshka_rat_auto.yar#L1-L141"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cruloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cruloader_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "e63bf906be3841d18c1769641826f4871bcf6c179928d9c22e19c757766e13e1"
+ logic_hash = "a1572c6250fefbf1b80a173c44c61e578e12fe07ff0f92d960b828b4e32b23d4"
score = 75
quality = 75
tags = "FILE"
@@ -147003,36 +153993,32 @@ rule MALPEDIA_Win_Matryoshka_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b037 c3 b073 c3 }
- $sequence_1 = { c3 b06f c3 b063 c3 }
- $sequence_2 = { 8b46fc 8947fc 49 75ed 5f ff4210 }
- $sequence_3 = { 8b4704 ff4710 ff07 8b0488 }
- $sequence_4 = { 74e3 440fb603 430fbe841040d30500 85c0 }
- $sequence_5 = { 8b4708 3b470c 7507 8bcf }
- $sequence_6 = { 74e2 ff8170040000 83b97004000002 0f8493010000 83cfff 488d2d572c0300 }
- $sequence_7 = { 74e9 488d15b9450400 488bcb e8???????? }
- $sequence_8 = { 74de 83cbff 488bca e8???????? 90 48897c2420 }
- $sequence_9 = { 8b4708 b120 8b570c 8b7718 }
- $sequence_10 = { 74e6 488d152fac0300 488bcb e8???????? }
- $sequence_11 = { 8b4704 8b3491 890491 8bd6 }
- $sequence_12 = { 74e2 ff8170040000 83b97004000002 0f84eb010000 83cfff 4c8d3dde290300 }
- $sequence_13 = { 8b4704 8bf1 33d1 81e6ff030000 }
+ $sequence_0 = { 53 ff15???????? 6a04 6800100000 ff35???????? 6a00 }
+ $sequence_1 = { 6bf638 8b0c8dd85e4100 80643128fd 5f 5e c9 c3 }
+ $sequence_2 = { 0f1005???????? 50 0f1145e0 ff15???????? 33c9 90 8a540dd0 }
+ $sequence_3 = { 3bf7 72e9 5f f7d0 5e 8be5 }
+ $sequence_4 = { 88540dc0 41 3bc8 7ced }
+ $sequence_5 = { 83c404 0f1000 6a00 0f1185ccfbffff ff15???????? }
+ $sequence_6 = { 833d????????00 0f851c0e0000 8d0db02f4100 ba1b000000 e9???????? a900000080 7517 }
+ $sequence_7 = { 7309 80341961 41 3bca 72f7 e8???????? 8d45ec }
+ $sequence_8 = { 0f8c5cffffff c705????????01000000 8b7d08 83c8ff }
+ $sequence_9 = { 0f8494010000 8bb5e4fcffff 8d45f4 50 ff7354 57 ff75e8 }
condition:
- 7 of them and filesize <843776
+ 7 of them and filesize <196608
}
-rule MALPEDIA_Win_Yakuza_Ransomware_Auto : FILE
+rule MALPEDIA_Win_Cosmicduke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "11a15f28-8d6d-50f2-ab84-992f1017bc03"
+ id = "a26b55b5-f92c-59e0-aeb7-97b4045e507d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yakuza_ransomware"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yakuza_ransomware_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cosmicduke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cosmicduke_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "f6b4887f1e5f8fb585f51d15a1308ea3aa15725a1e02d02f26222a8f601e98de"
+ logic_hash = "ac4cc48798cdbb14b22137cd5139a9905a17da02e3b6c8aa744a86c9cd8ba953"
score = 75
quality = 75
tags = "FILE"
@@ -147046,32 +154032,32 @@ rule MALPEDIA_Win_Yakuza_Ransomware_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bd1 d1ea b8ffffff1f 2bc2 3bc8 7607 8bc3 }
- $sequence_1 = { e8???????? 3b780c 730e 8b4008 8b34b8 85f6 0f85d7000000 }
- $sequence_2 = { d1f8 837e1408 7202 8b36 50 ff7508 8bce }
- $sequence_3 = { 6a01 6a01 57 8d4d80 e8???????? 8b4580 8d4d80 }
- $sequence_4 = { 8d7018 83c030 8b11 03c7 50 03f7 56 }
- $sequence_5 = { c745fcffffffff 56 8b4de0 41 51 53 8bcf }
- $sequence_6 = { 8b4f14 8b5614 85c9 743e 85c0 750d e8???????? }
- $sequence_7 = { eb17 0fb74644 8d4e24 50 e8???????? 6a2d 8d4e24 }
- $sequence_8 = { 8b06 6a02 51 53 8d8d50ffffff 51 8bce }
- $sequence_9 = { c745f000000000 c7461000000000 c7461407000000 668906 8945fc 8bc3 c745f001000000 }
+ $sequence_0 = { ff542418 83c602 47 3b742428 72ce 8b4514 }
+ $sequence_1 = { ff8688050000 b001 5f c3 6a1f 5a 8bc1 }
+ $sequence_2 = { c1e104 03cb 898439142c0000 e9???????? 3975e4 7408 ff75e4 }
+ $sequence_3 = { 8d7c241c e8???????? 3ac3 0f84ac010000 8b442420 89442430 8d842438200000 }
+ $sequence_4 = { 85db 7507 32c0 e9???????? 837d1400 74f3 807d1000 }
+ $sequence_5 = { 6a01 68???????? 56 53 e8???????? b001 5f }
+ $sequence_6 = { 8bc7 8d4c2414 e8???????? 53 8d44243c 50 }
+ $sequence_7 = { e8???????? 0fb7c0 894510 6685c0 7512 33c0 40 }
+ $sequence_8 = { ff7508 8bf0 8d85ecfdffff 50 ff15???????? 8b3d???????? }
+ $sequence_9 = { e8???????? 84c0 742f 838c244c300000ff 8d74240c e8???????? 8b4508 }
condition:
- 7 of them and filesize <2811904
+ 7 of them and filesize <456704
}
-rule MALPEDIA_Win_Onionduke_Auto : FILE
+rule MALPEDIA_Win_Yayih_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bc18bebb-924f-5db1-bda1-575db25c40f5"
+ id = "ad6edea8-11c9-5fa2-96f2-3800b1bd4695"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.onionduke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.onionduke_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yayih"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yayih_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "2b5a6150c91e41c1ea04d8a66d543531da34a08cde94cd3e5e729e90a4473cac"
+ logic_hash = "d13e6780f7fe46f9387338ccdb35700eb9e8a8c2ac7c13f232d1064c9386ae55"
score = 75
quality = 75
tags = "FILE"
@@ -147085,32 +154071,32 @@ rule MALPEDIA_Win_Onionduke_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33d2 895e68 66895658 8b550c 8d4202 c645fc04 8945ec }
- $sequence_1 = { c1e81f 03c2 897dcc 0f84d0000000 897dd0 eb02 }
- $sequence_2 = { 384b01 7506 40 380c18 }
- $sequence_3 = { 894ee4 894ffc 8d4eec 8d57ec 8d5fec }
- $sequence_4 = { 56 8bf1 837e0c00 751e 6a04 e8???????? 83c404 }
- $sequence_5 = { 3bfb 72ac 5f 5e }
- $sequence_6 = { 8b4e44 8b09 85d2 7405 }
- $sequence_7 = { 8910 894ed0 8b56e0 8957e0 8b56e4 }
- $sequence_8 = { e8???????? 83c404 33c0 eb66 8bc6 8d5001 }
- $sequence_9 = { 80f90f 7f05 80c157 eb02 32c9 }
+ $sequence_0 = { 5f ff7508 ff55f4 53 ff15???????? 8bc7 }
+ $sequence_1 = { 68???????? e8???????? 8b35???????? 83c40c 50 57 }
+ $sequence_2 = { 50 56 e8???????? 59 85c0 59 753c }
+ $sequence_3 = { 85c0 59 7507 57 e8???????? 59 e8???????? }
+ $sequence_4 = { ff15???????? 56 6880000000 6a03 56 6a01 8d85b8b8ffff }
+ $sequence_5 = { 66ab aa 59 33c0 8dbde9faffff 889de8faffff f3ab }
+ $sequence_6 = { 3bfe 750a 56 56 56 6a08 }
+ $sequence_7 = { e8???????? 6801200000 8d85b8b8ffff 56 50 e8???????? }
+ $sequence_8 = { 50 8d854cf6ffff 50 e8???????? 83c430 8d459c 50 }
+ $sequence_9 = { 0fafca 0fb65002 03ca 890d???????? 0fb64803 69c960ea0000 }
condition:
- 7 of them and filesize <671744
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Gratem_Auto : FILE
+rule MALPEDIA_Win_Moonwind_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "89f0dee2-28c6-5a10-a3ad-288a448f45ac"
+ id = "27c4684d-de1d-52d3-b498-3e41ed70b3fe"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gratem"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gratem_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moonwind"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moonwind_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "b58ab0ade84c3286830362f0f11bfb9519b8733c76dfe4e9cd7ba24746663e50"
+ logic_hash = "4c5abeb5054990236a95ce032241f8cb96582d9f2acb60b8ffe13b68b01f39ef"
score = 75
quality = 75
tags = "FILE"
@@ -147124,32 +154110,32 @@ rule MALPEDIA_Win_Gratem_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c744242404000000 ffd5 85c0 0f84b2000000 }
- $sequence_1 = { 884e13 66a1???????? 33c9 6685c0 741f 0fb7c0 ba000c0000 }
- $sequence_2 = { ff15???????? 8b442414 50 ff15???????? 8b5c2410 56 }
- $sequence_3 = { 85c0 7405 e8???????? 8b8c24d4070000 5e 33cc }
- $sequence_4 = { 663bc2 0f84ac030000 0fb7048d64bc4000 41 }
- $sequence_5 = { 8b4c2440 8b542418 894114 895110 }
- $sequence_6 = { 6a00 50 e8???????? 83c40c 6805010000 8d4c2404 51 }
- $sequence_7 = { 53 ff54244c 85c0 8b442414 }
- $sequence_8 = { 0fb7c0 baa8540000 663bc2 0f8420050000 0fb7048d64bc4000 41 }
- $sequence_9 = { 56 8d34c5c0b84000 833e00 7513 50 e8???????? }
+ $sequence_0 = { 8b11 83c104 c1ea08 881430 8a51fc 40 881430 }
+ $sequence_1 = { 8b5dfc 895de4 8b5de4 66c7030200 8b5dfc 83c308 895de4 }
+ $sequence_2 = { 53 e8???????? 83c404 8b5d08 8b1b 81c390000000 895dec }
+ $sequence_3 = { e8???????? 83c404 83c734 33d2 83c8ff 8917 885704 }
+ $sequence_4 = { b801000000 eb05 b800000000 85c0 0f842f000000 8b5d08 8b1b }
+ $sequence_5 = { bbdc090000 e8???????? 83c410 8945b8 8b5dbc 85db 7409 }
+ $sequence_6 = { ff75fc 6801000000 bb68010000 e8???????? 83c410 8945f0 68???????? }
+ $sequence_7 = { 8965f4 8b5d08 ff33 6801000000 ff75f8 ff15???????? }
+ $sequence_8 = { 50 e8???????? 8d7c2434 83c9ff 33c0 83c40c f2ae }
+ $sequence_9 = { dc25???????? dd5dc4 6801030080 6a00 682c000000 dd45c4 e8???????? }
condition:
- 7 of them and filesize <155648
+ 7 of them and filesize <1417216
}
-rule MALPEDIA_Win_Cradlecore_Auto : FILE
+rule MALPEDIA_Win_Alma_Communicator_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "de5cfc2b-ebd2-5b2c-afe8-802a7c966fb2"
+ id = "bb280ae5-df93-5ddd-a029-1d8f19d4cee3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cradlecore"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cradlecore_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alma_communicator"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alma_communicator_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "50e3eefefe56e4c7c3dbb9ce61b4c12511d78dda94103f69f932673a673b2621"
+ logic_hash = "ceeffab13f59872b0e8352c80061e88c0752f86bcb15a8ae0c39228603990d18"
score = 75
quality = 75
tags = "FILE"
@@ -147163,32 +154149,32 @@ rule MALPEDIA_Win_Cradlecore_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 03f2 eb5c 8b45f4 8b0c85f01f4300 f644190448 7437 }
- $sequence_1 = { 720f 8b06 5f c60000 8bc6 }
- $sequence_2 = { 83e908 8d7608 660fd60f 8d7f08 8b048db8734000 ffe0 f7c703000000 }
- $sequence_3 = { e8???????? 51 51 53 8bd9 33c0 8945f0 }
- $sequence_4 = { e8???????? 83c410 3bc3 75cf 0fb644240f e9???????? c74424340f000000 }
- $sequence_5 = { 80fb5a 7e53 80fb2d 744e 80fb2e }
- $sequence_6 = { 8b5df4 8b7df0 33f6 8bce 8b75fc }
- $sequence_7 = { 7204 8b1e eb02 8bde 8b450c 33d2 8b4d08 }
- $sequence_8 = { 59 50 8d45d0 8bce 50 e8???????? 837da010 }
- $sequence_9 = { 53 50 68???????? 53 ff15???????? 8d4de8 c745e868747470 }
+ $sequence_0 = { 8a4a1c 884807 a1???????? c6400800 e8???????? 59 }
+ $sequence_1 = { 8945f0 8b450c 8945f4 8b4514 40 c745ec93f84000 894df8 }
+ $sequence_2 = { 8bcb 898554f7ffff e8???????? 8bcb 898550f7ffff 6a02 5f }
+ $sequence_3 = { e8???????? 83c40c 8d8d58ffffff 8d5102 }
+ $sequence_4 = { 8974241c 68d0070000 832600 897c2424 }
+ $sequence_5 = { 668b4f02 03fe 663bca 75f5 ffb53cf7ffff 8907 6bc328 }
+ $sequence_6 = { 0f85aa010000 33c0 40 8985ccebffff }
+ $sequence_7 = { 7204 3c7a 7608 3c2b 7404 3c2f }
+ $sequence_8 = { 88840d20f6ffff 41 84c0 75ed 8d8d20f6ffff 49 8a4101 }
+ $sequence_9 = { 8a01 41 84c0 75f9 8a442454 2bca 83f901 }
condition:
- 7 of them and filesize <450560
+ 7 of them and filesize <245760
}
-rule MALPEDIA_Win_Flashflood_Auto : FILE
+rule MALPEDIA_Win_Paladin_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2b564813-7b00-54ab-b562-7a8de5369185"
+ id = "8e8ee0fc-daaf-5adf-960f-9f0ec8622d0d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flashflood"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flashflood_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.paladin"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.paladin_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "3006626d1ecba778668c15e0aafe5a9ff5cdfe4debbbd864318346fc290d9ab7"
+ logic_hash = "421e228bfdffaff271db99688d25ef5b69f4b46e3f813d9e9b328d48850dca52"
score = 75
quality = 75
tags = "FILE"
@@ -147202,32 +154188,32 @@ rule MALPEDIA_Win_Flashflood_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8145f800809b07 8d45f8 50 }
- $sequence_1 = { 56 e8???????? 40 8945f8 0fbe06 50 }
- $sequence_2 = { c3 b8???????? c3 55 8bec 81ec88020000 }
- $sequence_3 = { 8bec 81ec10060000 56 6a5c ff750c ff15???????? 8bf0 }
- $sequence_4 = { 6bc90c 8b91f0914000 8955f4 8b450c 6bc00c }
- $sequence_5 = { ff5164 85c0 0f85c5010000 8d55f4 8b45ec 52 }
- $sequence_6 = { 33c0 eb0a 57 ff15???????? 6a01 58 5f }
- $sequence_7 = { 85f6 59 0f842b020000 ff7508 8d85f0fbffff 50 e8???????? }
- $sequence_8 = { 50 e8???????? 8d85c0fdffff 50 8d85c0fbffff ff7508 }
- $sequence_9 = { 83c62c 6a2e 56 ff15???????? 8b3d???????? 59 }
+ $sequence_0 = { c20800 8d5d04 50 52 }
+ $sequence_1 = { ffd7 8b4614 6aff 50 ffd7 8b4e10 }
+ $sequence_2 = { 0faff0 83c61f c70728000000 c1fe03 83e6fc 894704 0faff1 }
+ $sequence_3 = { 53 55 56 8bf1 57 b918000000 33c0 }
+ $sequence_4 = { 33c0 8a41ff 8d1440 8d1492 8d1492 8d1cd0 33d2 }
+ $sequence_5 = { 687f030000 6a00 68???????? 8bf0 }
+ $sequence_6 = { 33c0 8dbc24a0000000 33d2 899c249c000000 83c40c 89942484000000 f3ab }
+ $sequence_7 = { 81c468020000 c20400 53 c645002e bb01000000 eb04 8b742414 }
+ $sequence_8 = { 8b4518 83f804 7427 83f802 7422 83f806 741d }
+ $sequence_9 = { 83f80d 0f8661010000 eb04 8b6c2410 }
condition:
- 7 of them and filesize <114688
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Evilgrab_Auto : FILE
+rule MALPEDIA_Win_Hikit_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "92d56cb6-a40e-55a9-bb4b-7f3303d7e68c"
+ id = "bd6e764b-576f-54ee-bfa6-5e7a42269dfd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.evilgrab"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.evilgrab_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hikit"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hikit_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "89c0b96a8a59594e704b0e35c7d209399933043505a45ecc6b5a8cd70ad1865a"
+ logic_hash = "dc92a800adf1985c32a4ddd1d9a2bce0a144c5995b6902cad53971cf4e90fb53"
score = 75
quality = 75
tags = "FILE"
@@ -147241,34 +154227,34 @@ rule MALPEDIA_Win_Evilgrab_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 50 50 52 89442440 89442434 89442438 }
- $sequence_1 = { 8dbdb8f5ffff f3a5 a4 b909000000 be???????? 8dbd5cf4ffff f3a5 }
- $sequence_2 = { c3 8d45c4 50 6a03 68???????? 8b0e 81c1d2000000 }
- $sequence_3 = { 8b9534aeffff 52 8bcb e8???????? 85c0 7531 6aa7 }
- $sequence_4 = { 8b35???????? e9???????? 8b85c8adffff 898540a3ffff 50 e8???????? 8b85c0adffff }
- $sequence_5 = { 6a00 85f6 6a00 7567 }
- $sequence_6 = { 52 8b45d4 8b481c 51 e8???????? }
- $sequence_7 = { 52 8b35???????? ffd6 d1e0 898565a4ffff }
- $sequence_8 = { 52 68???????? 53 ffd5 83c410 6880000000 53 }
- $sequence_9 = { 33c0 8dbdf0efffff f3ab c685f0efffffd0 668b5304 52 e8???????? }
+ $sequence_0 = { 33c0 e9???????? 48 8d44244e 48 898424b8000000 48 }
+ $sequence_1 = { 89442428 48 837c242800 747e 33c0 83f801 7444 }
+ $sequence_2 = { c7432000000000 48 8b442430 48 83781800 741c 48 }
+ $sequence_3 = { e8???????? 8bf8 85ff 7408 81ff20a00400 7508 8b06 }
+ $sequence_4 = { 6a00 50 ff15???????? 85c0 0f84a3000000 33ff }
+ $sequence_5 = { 8bd5 8bce e8???????? f7d8 1bc0 40 894608 }
+ $sequence_6 = { 6689046e 8b2d???????? 53 ffd5 56 68???????? 8d4c2410 }
+ $sequence_7 = { 8d05b2210000 48 89442428 eb0d 48 8b442428 }
+ $sequence_8 = { 894120 48 8b4c2460 8b44240c 894104 48 8b4c2460 }
+ $sequence_9 = { 4c 8d442478 baffff1f00 ff15???????? 898424b0000000 83bc24b000000000 7444 }
condition:
- 7 of them and filesize <327680
+ 7 of them and filesize <573440
}
-rule MALPEDIA_Win_Plead_Auto : FILE
+rule MALPEDIA_Win_Babar_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fd5a06dc-6983-5a74-97bc-98455f57d710"
+ id = "907c27e3-2fb8-508f-9c67-d8826ced6045"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.plead"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.plead_auto.yar#L1-L235"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.babar"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.babar_auto.yar#L1-L166"
license_url = "N/A"
- logic_hash = "6a7ab17d07de8a4ca9e1e2599ef78a9a501e90d23119efee05ad014354df9153"
+ logic_hash = "8e0331df8b3130917de8e5e3d5d2fa36fbe1f95285a5ec05160d56f936d6e114"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -147280,85 +154266,77 @@ rule MALPEDIA_Win_Plead_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 85c0 750c c745fcfcffffff e9???????? 395d18 }
- $sequence_1 = { ebda 33f6 c745fcf8ffffff 3bf7 }
- $sequence_2 = { bf00800000 57 53 56 897d14 }
- $sequence_3 = { e8???????? 817d14e8030000 53 56 }
- $sequence_4 = { 59 5e c20400 8b4c2404 56 }
- $sequence_5 = { 50 ff15???????? 6a3f 33c0 59 }
- $sequence_6 = { 8d4dfc 51 8d4dd8 51 }
- $sequence_7 = { 8d4514 53 50 56 53 6a05 }
- $sequence_8 = { ff15???????? 50 ff15???????? 33c0 81c418020000 }
- $sequence_9 = { 5e 5b 33c0 81c418020000 c21000 8b84241c020000 }
- $sequence_10 = { 7cf1 ffd3 8b35???????? 2bc7 3de8030000 }
- $sequence_11 = { 8b5508 52 ff15???????? 6aff a1???????? 50 ff15???????? }
- $sequence_12 = { 50 8b1d???????? ffd3 85c0 743b }
- $sequence_13 = { 8b8c241c020000 68???????? 51 ff15???????? }
- $sequence_14 = { 5d 8a44341c 32c2 8844341c 46 3bf1 }
- $sequence_15 = { c705????????01000000 ff15???????? 8b1d???????? ffd3 8bf8 33f6 8bcf }
- $sequence_16 = { 648b1530000000 8b520c 8b521c 8b5a08 }
- $sequence_17 = { 8b430c 034510 6a04 6800100000 51 50 }
- $sequence_18 = { 8d7a08 e8???????? 52 e8???????? e9???????? 0fb755e0 83fa08 }
- $sequence_19 = { e8???????? b02c aa 8b4510 85c0 }
- $sequence_20 = { 33c0 f3aa eb10 e8???????? 8b4314 034508 }
- $sequence_21 = { 8b5324 f7c200000002 7412 6800400000 8b4310 50 }
- $sequence_22 = { e8???????? 0fb64de2 8b55ec 8b7df0 8b07 }
- $sequence_23 = { b940000000 50 e2fd 56 394510 747e }
+ $sequence_0 = { 3bd6 0f86f9feffff 8b54243c 8b442438 }
+ $sequence_1 = { 3bd6 0f8c7affffff 8bbc24d0000000 ddd9 }
+ $sequence_2 = { 3bd5 7e47 8d0c9500000000 2bd9 }
+ $sequence_3 = { 3bd5 0f8671ffffff 8144241890020000 ddd8 816c242880020000 83c710 81c680020000 }
+ $sequence_4 = { 46 8d44af08 8d5708 8d4cb500 d942f8 }
+ $sequence_5 = { 3bd6 0f82eefeffff 8b742458 03f5 }
+ $sequence_6 = { 3bd6 721b 57 8bcb }
+ $sequence_7 = { 3bd6 72d9 33f6 eb08 }
+ $sequence_8 = { 8906 0f8496000000 50 ffd7 894604 8b0d???????? 894e08 }
+ $sequence_9 = { 8d8407d8988069 c1c007 8bfa 03c6 33fe }
+ $sequence_10 = { 803800 8b0d???????? 741d 803900 7506 8b0d???????? 8a11 }
+ $sequence_11 = { 23d1 33d0 0354244c 8d94322108b449 c1ca0a 03d1 8bf1 }
+ $sequence_12 = { 57 8d3c85a09e0110 8b07 03c3 8a4824 }
+ $sequence_13 = { e8???????? 57 e8???????? 83c410 8d842480000000 50 ffd5 }
+ $sequence_14 = { 0fb64e04 884804 8b5604 c1ea08 885005 0fb64e06 }
+ $sequence_15 = { 8b4b04 55 8b2d???????? 68???????? }
condition:
- 7 of them and filesize <8224768
+ 7 of them and filesize <1294336
}
-rule MALPEDIA_Win_Unidentified_101_Auto : FILE
+rule MALPEDIA_Win_Blackmagic_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1e5a977c-e7e9-5732-97b6-6aadc4f691fc"
- date = "2023-03-28"
- modified = "2023-04-07"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_101"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_101_auto.yar#L1-L128"
+ id = "dd528f6f-030a-5c0c-abc0-3a9e54fb0bef"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackmagic"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackmagic_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "71f0751fbd77a928634515b558d06922b4bf4a312042d6abbd6ba70171c64843"
+ logic_hash = "9b47417ce0472639cee5ef75e6c79509f45487b7ad058f003aa41d6f30ea451f"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20230328"
- malpedia_hash = "9d2d75cef573c1c2d861f5197df8f563b05a305d"
- malpedia_version = "20230407"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c70016000000 e8???????? 83c8ff e9???????? 498bc4 488d0ddb070100 83e03f }
- $sequence_1 = { 6689842404010000 b865000000 6689842406010000 33c0 6689842408010000 }
- $sequence_2 = { 33c0 b968000000 f3aa 488d842400010000 4889442448 488d842430020000 4889442440 }
- $sequence_3 = { 4889742410 57 4883ec20 418bf0 4c8d0debb40000 8bda 4c8d05dab40000 }
- $sequence_4 = { c744243000000000 4c8d4c2430 4c8b442440 8b542468 488b4c2460 }
- $sequence_5 = { c68424e900000065 c68424ea00000057 c68424eb00000000 c644243052 c644243165 c644243261 c644243364 }
- $sequence_6 = { 428a8c1910e40100 4c2bc0 418b40fc 4d894108 d3e8 41894120 }
- $sequence_7 = { 48c744242000000000 4c8d8c24c8000000 448b442450 488b542458 488b4c2470 ff15???????? }
- $sequence_8 = { 41b804010000 488d942400030000 33c9 ff15???????? c744245801000000 e8???????? 833d????????01 }
- $sequence_9 = { 7528 48833d????????00 741e 488d0dd8450100 e8???????? 85c0 740e }
+ $sequence_0 = { 488d15b40c0700 488bcd e8???????? 488b4620 488903 488b5c2430 488b6c2438 }
+ $sequence_1 = { 4c8b01 ba01000000 41ff10 90 488bc7 488b4c2458 4833cc }
+ $sequence_2 = { 4863d0 488d4dd0 488b94d3086c0700 e8???????? 488b0d???????? 0fbe01 }
+ $sequence_3 = { 3bc3 740a 8b5c245c 85db 748d eb35 ff15???????? }
+ $sequence_4 = { 48895e08 488b4718 4c894010 488b4718 49894018 4c894718 49897810 }
+ $sequence_5 = { 0f114160 0f104070 488b8090000000 0f114170 0f118980000000 48898190000000 488d0587eaffff }
+ $sequence_6 = { 0f867d030000 458d7302 448d7d02 8bc5 4c8d1483 418b3a }
+ $sequence_7 = { 41f782b800000000080000 7427 498b8ad0000000 410fb6d3 e8???????? 440fb65c2430 0fbec8 }
+ $sequence_8 = { 488bd0 e8???????? 488b5308 498bce 482b13 48c1fa02 e8???????? }
+ $sequence_9 = { 4881f900100000 7223 488d4127 483bc1 0f8681000000 488bc8 e8???????? }
condition:
- 7 of them and filesize <402432
+ 7 of them and filesize <1416192
}
-rule MALPEDIA_Win_Dispcashbr_Auto : FILE
+rule MALPEDIA_Win_Heyoka_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "02a73395-ac12-50d4-b2ec-e868c4b1a459"
+ id = "86cada76-df01-530f-8812-d25a9cd3eeea"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dispcashbr"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dispcashbr_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.heyoka"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.heyoka_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "60c8be22bea8462dd56c514e62576b626445f5aa18aea505cf9cb5c5983fb848"
+ logic_hash = "a93bcd2aa0b2cb88631752f25ba4416145dab56370097ba7d811f589f6be863b"
score = 75
quality = 75
tags = "FILE"
@@ -147372,32 +154350,32 @@ rule MALPEDIA_Win_Dispcashbr_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83ec08 c7442408ceffffff c7442404???????? }
- $sequence_1 = { e8???????? 83ec08 c7442408eaffffff c7442404???????? }
- $sequence_2 = { e8???????? 83ec08 c7442408ceffffff c7442404???????? a1???????? 83c020 }
- $sequence_3 = { a1???????? 83c020 890424 e8???????? eb45 c70424f5ffffff e8???????? }
- $sequence_4 = { 83ec08 c7442408f2ffffff c7442404???????? a1???????? 83c020 890424 e8???????? }
- $sequence_5 = { 83ec08 c7442408d9ffffff c7442404???????? a1???????? 83c020 890424 }
- $sequence_6 = { 890424 e8???????? 83ec08 c7442408d7ffffff }
- $sequence_7 = { 890424 e8???????? 83ec08 c7442408c9ffffff c7442404???????? }
- $sequence_8 = { 83ec04 c744240404000000 890424 e8???????? 83ec08 c7442408f2ffffff c7442404???????? }
- $sequence_9 = { c70424f5ffffff e8???????? 83ec04 c744240404000000 }
+ $sequence_0 = { 8b4d0c 8b510c 83c204 52 8b45fc 50 }
+ $sequence_1 = { c745f800000000 c745f000000000 c745f400000000 c745ec00000000 8b4514 6bc005 c1e803 }
+ $sequence_2 = { 8b45dc 50 e8???????? 83c410 8945d8 837dd800 750c }
+ $sequence_3 = { 83ec08 894df8 8b45f8 c700???????? 8b4df8 c7810c09000000000000 8b55f8 }
+ $sequence_4 = { e8???????? 83c408 8b5518 52 8b45dc 83c004 }
+ $sequence_5 = { e8???????? 83c408 eb17 837d0803 7511 68???????? }
+ $sequence_6 = { 8bec 83ec08 8b4508 50 6a01 e8???????? 83c408 }
+ $sequence_7 = { 7423 8bce 8bc6 c1f905 83e01f 8b0c8da0d80110 }
+ $sequence_8 = { 51 e8???????? 83c404 8b45e0 83c00c 8be5 }
+ $sequence_9 = { 8955f8 8b45fc 8b4df4 8b55f8 0faf948134e30000 8b4df4 8bc2 }
condition:
- 7 of them and filesize <123904
+ 7 of them and filesize <270336
}
-rule MALPEDIA_Win_Mykings_Spreader_Auto : FILE
+rule MALPEDIA_Win_Solarbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "96a12e80-b15f-580e-920d-d6c0d35464b0"
+ id = "8e3c74e1-0da4-57ab-ab5f-74e62e2d1f7c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mykings_spreader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mykings_spreader_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.solarbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.solarbot_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "1bcd674173fea4b83a2f4219e8f61306a972490f94a89cfaf5e1f466fdec8eff"
+ logic_hash = "2b058f45b0c5077e371ef262d327c05a0be6ae89bd9fed8f4379a07e0dfd6a86"
score = 75
quality = 75
tags = "FILE"
@@ -147411,32 +154389,32 @@ rule MALPEDIA_Win_Mykings_Spreader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7519 51 55 8bce e8???????? 6a00 6a00 }
- $sequence_1 = { 8b1e ff938c000000 8b0424 8b5014 85d2 7507 bf00000000 }
- $sequence_2 = { e8???????? 837e1800 7439 8b4620 c1e003 89c7 8b4618 }
- $sequence_3 = { 89c1 c745f401000000 3b4df4 723d ff4df4 8d7600 ff45f4 }
- $sequence_4 = { 68???????? 50 ff15???????? a3???????? 83c0fe 40 40 }
- $sequence_5 = { 8942fc 89d8 c1f81f 8b1424 8b7208 8b4a0c 29de }
- $sequence_6 = { eb02 b300 e8???????? 8d45cc e8???????? c745cc00000000 58 }
- $sequence_7 = { 33d2 b9???????? 8bc2 8bf2 c1f805 83e61f 8b0485a02e4100 }
- $sequence_8 = { 89d8 29f0 85c0 7e39 8b55f4 85d2 7505 }
- $sequence_9 = { 8b7508 8b36 8975c8 8b7d08 8b7f04 }
+ $sequence_0 = { 0f8407feffff bb01000000 4b 90 43 8b854cfeffff }
+ $sequence_1 = { 50 8d8500fcffff 50 6a00 }
+ $sequence_2 = { 85db 7463 ff75f8 e8???????? 84c0 7457 }
+ $sequence_3 = { 8d85f4fdffff 50 e8???????? 6a0c 8d85e8fdffff 50 e8???????? }
+ $sequence_4 = { 50 e8???????? 680c010000 8d85f4faffff }
+ $sequence_5 = { 8b4508 8945cc 8b7d0c 8b4510 }
+ $sequence_6 = { 53 e8???????? 83fe0c 7509 ff75f0 }
+ $sequence_7 = { 85c0 0f847d000000 ff75f4 e8???????? }
+ $sequence_8 = { c645c401 eb23 6a00 6a00 6a00 }
+ $sequence_9 = { 83c040 8985e4fdffff 8b85e0fdffff 0385d0fdffff 8b583c 83bdccfdffff0c }
condition:
- 7 of them and filesize <1581056
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Pseudo_Manuscrypt_Auto : FILE
+rule MALPEDIA_Win_Petya_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "31787da1-ee36-51da-9ab0-837844c74a17"
+ id = "d9a77562-a232-5aff-a461-f3720889bdae"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pseudo_manuscrypt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pseudo_manuscrypt_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.petya"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.petya_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "f95219f8df4fada7a5809becd0c4a0a18721619c73177d4ad9f3ddc17aca2388"
+ logic_hash = "e514cd58bfcd6e8ef482bd5780bb94df60b153546d27b2b89cfad52214dcb51a"
score = 75
quality = 75
tags = "FILE"
@@ -147450,32 +154428,32 @@ rule MALPEDIA_Win_Pseudo_Manuscrypt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f8473ffffff 8bd6 8bcf e8???????? 85c0 0f8f62ffffff 53 }
- $sequence_1 = { 668906 e8???????? 8b45fc 83c404 8bfb 3b18 75bd }
- $sequence_2 = { 33db 8d857cfdffff 53 50 53 683f010f00 53 }
- $sequence_3 = { 6a00 6a00 6a00 6a18 ffd6 6a00 6a00 }
- $sequence_4 = { 8bec 56 8bb17c010000 85f6 742a 8b4508 33d2 }
- $sequence_5 = { 6a04 68ffff0000 53 ffd6 0bc7 5f 5e }
- $sequence_6 = { 57 8945fc 8d140b 8bc8 0f44d3 52 e8???????? }
- $sequence_7 = { 7554 5f 33c0 5e 8b4dfc 33cd e8???????? }
- $sequence_8 = { 89442474 8d842480000000 6804010000 50 c744246c01010000 ff15???????? 68???????? }
- $sequence_9 = { 8d85d0fdffff 50 56 ff15???????? 85c0 742c 53 }
+ $sequence_0 = { 6a03 6800001080 51 ff15???????? 83f8ff }
+ $sequence_1 = { 57 33ff 3b750c 0f47d9 85db 7410 8b06 }
+ $sequence_2 = { 0f42f2 6a04 56 e8???????? 8bd8 }
+ $sequence_3 = { 8bc6 8bca c1e303 0facc110 897c2424 c1e810 }
+ $sequence_4 = { 8d4e1c e8???????? 8d4e28 e8???????? 8d4e4c e8???????? 837e7400 }
+ $sequence_5 = { 83e804 4e 75f5 46 3bf2 53 }
+ $sequence_6 = { 8b4e74 03cb e8???????? 47 83c324 3b7e78 72ed }
+ $sequence_7 = { 85db 7410 8b06 85c0 7402 ffd0 }
+ $sequence_8 = { 0fa4df03 c1e818 884c242c 8bc6 }
+ $sequence_9 = { 8d4e04 e8???????? 8d4e10 e8???????? 8d4e1c }
condition:
- 7 of them and filesize <753664
+ 7 of them and filesize <229376
}
-rule MALPEDIA_Win_Fickerstealer_Auto : FILE
+rule MALPEDIA_Win_Vohuk_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "45d62189-24df-5dae-af5a-78b51fda916c"
+ id = "411a3e2f-1751-5273-acfa-62305bd7fa2f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fickerstealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fickerstealer_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vohuk"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vohuk_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "fe62eb4bdda7768c5d67489e8496ef31433ebe8da6a7c001c0177fb4671588ff"
+ logic_hash = "2ed67cd931d1a068f4ca262bb4544ee71becc9ba564d979b0f2e30b12b56f8a3"
score = 75
quality = 75
tags = "FILE"
@@ -147489,32 +154467,32 @@ rule MALPEDIA_Win_Fickerstealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b55c8 897150 895154 8b75cc 8b55d0 897158 89515c }
- $sequence_1 = { ba???????? 0f2840f0 0f2808 0f298424a0040000 0f294910 0f2901 6a00 }
- $sequence_2 = { c1e104 85c0 f20f10840b90000000 f20f108c0b98000000 f20f118c2488000000 f20f11842480000000 f20f10442450 }
- $sequence_3 = { c1ea04 85d2 0f44d1 0f44f0 89d1 c1e902 6afe }
- $sequence_4 = { 8b3e e8???????? 84c0 7404 c6470401 8b06 8b08 }
- $sequence_5 = { 89d3 8954241c 897c2420 c744241801000000 89f1 e8???????? 3c0f }
- $sequence_6 = { f20f114d9c f20f115594 7514 31d2 8d4ddc 42 e8???????? }
- $sequence_7 = { e9???????? 8d7c2448 89f9 e8???????? 833f01 0f85ed000000 }
- $sequence_8 = { 56 53 57 ff750c 50 e8???????? 83c424 }
- $sequence_9 = { 898d40feffff 89f9 8985d4feffff 8b8570ffffff 8985d8feffff 8b4588 8985dcfeffff }
+ $sequence_0 = { ff35???????? 8d45ba 50 e8???????? 83c408 e9???????? c745b48f00a000 }
+ $sequence_1 = { e8???????? c7451850000000 837d1800 7e20 33c9 8a840df4f9ffff 8d4901 }
+ $sequence_2 = { 50 ff15???????? a3???????? 33f6 b818000000 c745b245007d00 c745b666006300 }
+ $sequence_3 = { a3???????? c745b6b700b400 c745bab100fb00 c745be82009e00 c745c2f800f400 c745c6e400fb00 c745caf900b100 }
+ $sequence_4 = { 8b0d???????? bac1655634 8b75f8 6892000000 e8???????? 8d4d94 51 }
+ $sequence_5 = { 33c9 8d4900 8a840d48e6ffff 8d4901 88840d57ffffff 8b45fc 48 }
+ $sequence_6 = { 85c0 7413 8b4b14 c6431c00 e8???????? 5f 5e }
+ $sequence_7 = { 88840d57ffffff 8b45fc 48 8945fc 837dfc00 7fe2 8d85d8fcffff }
+ $sequence_8 = { 8d45f2 803d????????01 8945dc 8d45ea 7403 }
+ $sequence_9 = { c5fe6f4580 c4e37d4645a031 c5fe7f8080000000 c5fe6f85e0feffff c4e37d468500ffffff31 c5fe7f80a0000000 }
condition:
- 7 of them and filesize <598016
+ 7 of them and filesize <260096
}
-rule MALPEDIA_Win_Greenshaitan_Auto : FILE
+rule MALPEDIA_Win_Boldmove_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d06953fb-38e3-55db-9793-3faef3649e6a"
+ id = "ede55e68-ab48-582c-bf7e-2cb826551211"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.greenshaitan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.greenshaitan_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.boldmove"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.boldmove_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "67bf6d74e4d0fa44058834ba5470ffb949ca80488520bfdf122c691ce2d70d18"
+ logic_hash = "d529b7724e2e647d4848b38aca8e76a61b2caa5c4bf1c77fa8242a3dc71a9c2d"
score = 75
quality = 75
tags = "FILE"
@@ -147528,32 +154506,32 @@ rule MALPEDIA_Win_Greenshaitan_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b460c 8d542434 52 50 }
- $sequence_1 = { 6a00 51 50 b940000000 e8???????? 8bf0 eb02 }
- $sequence_2 = { 81ce00ffffff 46 8a1c0e 881c0f 88040e 8d4201 99 }
- $sequence_3 = { 8b442444 8b4c2440 8b7c243c 50 51 8d542418 52 }
- $sequence_4 = { e8???????? 85ed 740c 8b4500 eb09 8b4500 8bc8 }
- $sequence_5 = { 51 ff15???????? 8b8c240c200000 5e 5d }
- $sequence_6 = { 0fb69b685b6e00 8819 0fb6d2 8bda c1eb04 c1e004 0bd8 }
- $sequence_7 = { 8bc8 ebe1 33c0 397814 770e 85ed 7405 }
- $sequence_8 = { 33f6 8bc5 99 6a00 52 c644244400 50 }
- $sequence_9 = { 720d 8b542434 52 e8???????? 83c404 c784248c000000ffffffff 897c2448 }
+ $sequence_0 = { 0fb655e4 d3e2 8b8b24300000 09d0 880431 31c0 }
+ $sequence_1 = { 891c24 e8???????? 893424 e8???????? 8b442434 85c0 }
+ $sequence_2 = { 0f85cf060000 c744246800000000 8b4c2434 b801000000 85c9 0f4fc1 8984249c000000 }
+ $sequence_3 = { 83cd02 89442448 e9???????? 8d4701 83cd08 89442448 }
+ $sequence_4 = { e8???????? 89c5 8b442438 892c24 89442404 e8???????? 8b4c2424 }
+ $sequence_5 = { 8b442420 89fb 8b10 e9???????? 85f6 7e03 83ee01 }
+ $sequence_6 = { 8b8314100000 31d2 39d0 740c 39b49318100000 7418 42 }
+ $sequence_7 = { 85db 0f84561d0000 81fe00040000 b800040000 0f4ec6 890424 89442440 }
+ $sequence_8 = { 8d4f04 7415 837c242801 0f8473050000 837c242805 7503 0fbec0 }
+ $sequence_9 = { 8b8310080000 31d2 39d0 740c 39b49314080000 }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <242688
}
-rule MALPEDIA_Win_Nymaim2_Auto : FILE
+rule MALPEDIA_Win_Winsloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cd5e7949-7b9c-5324-8001-074a99f4915b"
+ id = "3816b057-ecfc-5190-8abf-a0a65a8930f8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nymaim2"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nymaim2_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winsloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.winsloader_auto.yar#L1-L171"
license_url = "N/A"
- logic_hash = "37921c250fe69562f60d707b47002bf6c0dd5723b18e1c13d6bd87f6fbea9446"
+ logic_hash = "2eada578907b5f770ab8c1dc3588915ff9d4c97daa18d7827115e92744f234da"
score = 75
quality = 75
tags = "FILE"
@@ -147567,32 +154545,38 @@ rule MALPEDIA_Win_Nymaim2_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8d4de4 c645fc45 e8???????? 8d4de0 c645fc05 e8???????? }
- $sequence_1 = { e8???????? 83ec20 56 33f6 3935???????? 7546 68da010000 }
- $sequence_2 = { 50 8d45f0 50 e8???????? e8???????? 834dfcff 8d4df0 }
- $sequence_3 = { e8???????? 8b7510 59 59 8b16 50 8bce }
- $sequence_4 = { c645fc46 e8???????? 8d4de4 c645fc1b e8???????? 8d4ddc e8???????? }
- $sequence_5 = { 8d45d4 8bce 50 c645fc01 e8???????? 8d45c0 8d4dd4 }
- $sequence_6 = { 56 8bcf c645fc09 ff5008 51 8d4604 8bcc }
- $sequence_7 = { 8d4df0 e9???????? 8d4dc0 e9???????? 8d4dec e9???????? 8b45e8 }
- $sequence_8 = { 8d86640c0000 8bd9 03c9 c1eb1f 0bd9 c746040e000000 33da }
- $sequence_9 = { 8bc8 c645fc03 e8???????? 51 8bcc 8965ec 50 }
+ $sequence_0 = { 83c40c 6800040000 8d8dfcf7ffff 51 }
+ $sequence_1 = { 8bf8 83c434 85ff 7510 }
+ $sequence_2 = { 89941d02fcffff 89841d06fcffff b8???????? 898c1d0afcffff 83c410 }
+ $sequence_3 = { 68???????? 51 e8???????? 68???????? 8d5c3e04 e8???????? }
+ $sequence_4 = { 898c1d0afcffff 83c410 66c7841d0efcffff4501 8d7001 8a08 }
+ $sequence_5 = { 8d8375050000 6a00 a3???????? ff15???????? }
+ $sequence_6 = { 0fb7c0 8bf0 6689841d10fcffff 56 83c316 8d941dfcfbffff 68???????? }
+ $sequence_7 = { f3a5 66a5 8b15???????? 8990fa0d0000 8b0d???????? }
+ $sequence_8 = { 8bd8 c745fcffffffff 85db 7516 56 e8???????? }
+ $sequence_9 = { c3 e8???????? 85c0 0f8487660000 c3 833d????????ff 7503 }
+ $sequence_10 = { 894dfc 80fb08 750f 32db }
+ $sequence_11 = { 33c0 40 e9???????? 8365c800 c745cc231a0110 a1???????? 8d4dc8 }
+ $sequence_12 = { 8d940dfcfbffff 52 e8???????? 83c40c 0fb685f7f3ffff }
+ $sequence_13 = { c1e100 8b9568f3ffff 8991a8ad0110 8b85f8f3ffff 05b4130000 668985f0f3ffff }
+ $sequence_14 = { 8841ff 83ea01 75f2 8b542424 8a1a 8d4701 50 }
+ $sequence_15 = { 8b049594440110 8985ccf6ffff 85c0 757c 50 8985d4f4ffff 89855cfcffff }
condition:
- 7 of them and filesize <753664
+ 7 of them and filesize <270336
}
-rule MALPEDIA_Win_Yahoyah_Auto : FILE
+rule MALPEDIA_Win_Ayegent_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8071f7bc-1af0-58b6-8984-8add890e5a04"
+ id = "38c6d34b-791e-51ab-b755-5bf91f226c75"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yahoyah"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yahoyah_auto.yar#L1-L158"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ayegent"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ayegent_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "5a0539481a7f5653801a561ffa29165f1f4bf92248a27b13820a8f2035c6eb1c"
+ logic_hash = "7245e65e015426e49adecdb4c2a9413e067a055fe3d65973ee2cacb00da6dd3e"
score = 75
quality = 75
tags = "FILE"
@@ -147606,37 +154590,32 @@ rule MALPEDIA_Win_Yahoyah_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 6a02 53 6af0 }
- $sequence_1 = { 50 6800080000 ff15???????? ff15???????? }
- $sequence_2 = { 53 53 56 53 ff15???????? 68d0070000 }
- $sequence_3 = { 50 e8???????? 83c418 6a02 53 }
- $sequence_4 = { ff15???????? 6a2e 68???????? e8???????? }
- $sequence_5 = { e8???????? 59 53 53 6a03 0fb7c8 }
- $sequence_6 = { 52 c1e808 23c1 50 68???????? }
- $sequence_7 = { ff15???????? 85c0 7501 c3 56 }
- $sequence_8 = { 23d1 52 8bd0 c1ea18 52 0fb6d0 }
- $sequence_9 = { eb19 ff15???????? 0fb7c0 50 68???????? }
- $sequence_10 = { 6a1a 50 e8???????? bf???????? }
- $sequence_11 = { ff15???????? 6a3a 56 e8???????? 8bf0 83c410 }
- $sequence_12 = { 90 33c9 33c0 648b3530000000 8b760c }
- $sequence_13 = { 90 68add13441 ffb53ffbffff 6a00 e8???????? 898521f1ffff e8???????? }
- $sequence_14 = { 90 90 90 90 90 68add13441 ffb53ffbffff }
+ $sequence_0 = { 80a0609d400000 40 41 41 3bc6 }
+ $sequence_1 = { 8d442448 53 50 68???????? 53 }
+ $sequence_2 = { 68???????? ffd6 8bf8 33f6 3bfb 897c241c 0f8cf9000000 }
+ $sequence_3 = { ff15???????? 8b4c2428 8b542424 51 8b4c2424 52 }
+ $sequence_4 = { 8d542440 51 52 ff15???????? 85c0 0f8415030000 8b3d???????? }
+ $sequence_5 = { 52 50 ffd6 6a00 8d8c2414010000 }
+ $sequence_6 = { 83c408 aa 8d842450040000 6804010000 }
+ $sequence_7 = { 55 56 8bb42438050000 33db }
+ $sequence_8 = { 72f1 56 8bf1 c1e603 3b9668774000 0f851c010000 }
+ $sequence_9 = { 53 51 68???????? ffd6 85c0 }
condition:
- 7 of them and filesize <483328
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Win_Pipcreat_Auto : FILE
+rule MALPEDIA_Win_Bit_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "38c9ab7f-3633-5cf9-b43a-1054dcf3eb2e"
+ id = "49210a4b-5430-57e8-a054-5667e0ae3196"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pipcreat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pipcreat_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bit_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bit_rat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "c78f35b80acd6d02ab8a3808b0a24320b25c92c8bd70c4aff6d75dba01d58da4"
+ logic_hash = "eb9ba4fd39163b3bb9047c43b4366afc9171afe908b68fc3b3d7fbbef1990e08"
score = 75
quality = 75
tags = "FILE"
@@ -147650,32 +154629,32 @@ rule MALPEDIA_Win_Pipcreat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ffd6 85c0 751b 8d851cfeffff c7851cfeffff14010000 }
- $sequence_1 = { 6a00 8d442420 6a00 50 6a01 6a02 6a20 }
- $sequence_2 = { 8b4c2404 68???????? 6a01 51 ff15???????? 85c0 }
- $sequence_3 = { 56 ff15???????? 85c0 741d 6a30 6868420010 }
- $sequence_4 = { e9???????? 83bd20feffff04 770a 6888410010 e9???????? 83bd20feffff05 8b35???????? }
- $sequence_5 = { 56 57 be9c400010 8d7df8 8d45f8 a5 50 }
- $sequence_6 = { eb12 6838470010 ff15???????? 6a20 6898420010 }
- $sequence_7 = { 59 8d8538ffffff 6a28 50 }
- $sequence_8 = { 7426 50 50 50 8b15???????? }
- $sequence_9 = { be???????? 8d7c2414 33c0 f3a5 b975000000 }
+ $sequence_0 = { 85c9 753f 6a00 6a00 68c1000000 6809020000 6a28 }
+ $sequence_1 = { ff7608 ff74241c e8???????? 8be8 83c408 85ed 7425 }
+ $sequence_2 = { e8???????? 8be8 83c408 85ed 7930 6a00 6a00 }
+ $sequence_3 = { 8be5 5d c3 8b4510 8320b7 c7400400000000 33c0 }
+ $sequence_4 = { e8???????? 83c408 85c0 74cf 894704 8b450c 895f10 }
+ $sequence_5 = { f20f114af8 f20f1142f0 0fbf06 660f6ec8 0fbf46fe 83c608 f30fe6c9 }
+ $sequence_6 = { f644242401 895c2410 7413 83faff 0f84f5000000 42 89542414 }
+ $sequence_7 = { eb12 6a00 6a00 6a06 6a79 6a2c e8???????? }
+ $sequence_8 = { f00fc14108 48 7505 8b01 ff5004 8b4df4 64890d00000000 }
+ $sequence_9 = { c70100000000 83c104 83c204 3bce 75e8 8bc2 5e }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <19405824
}
-rule MALPEDIA_Win_Murkytop_Auto : FILE
+rule MALPEDIA_Win_Pay2Key_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "98a068e3-7271-5cdb-a55e-1253046c8910"
+ id = "26097eea-fdd3-5ff6-a78a-aae3970171ae"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.murkytop"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.murkytop_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pay2key"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pay2key_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "c9438f0871f1117619cdcbc50e1d21cb20b4d3848dd8784e1c0798685d05cf91"
+ logic_hash = "fed562ca29ad610b012032606168f69e452506f6e6212e1bb41332762ffb58be"
score = 75
quality = 75
tags = "FILE"
@@ -147689,32 +154668,32 @@ rule MALPEDIA_Win_Murkytop_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7c17 b8555555d5 f7e9 c1fa02 8bc2 c1e81f 03c2 }
- $sequence_1 = { 56 e8???????? 83c410 8b9d1befffff 8d9c1defeeffff 33f6 8bff }
- $sequence_2 = { 83e01f c1f905 8b0c8de0f54100 c1e006 0fbe440104 83e040 }
- $sequence_3 = { 8d4508 50 6a00 57 6a00 6800130000 ff15???????? }
- $sequence_4 = { 56 ffd7 50 ff15???????? 85c0 0f850b010000 }
- $sequence_5 = { 8b1d???????? 56 57 8bf8 8d45f8 }
- $sequence_6 = { 8b3d???????? 8bc7 85ff 7e16 8d0cfd48f54100 8b11 }
- $sequence_7 = { c1fa02 8955d4 3bdf 754e }
- $sequence_8 = { 897de4 c745e014000000 897dec 894dd8 8945dc }
- $sequence_9 = { c1e106 030c9de0f54100 eb02 8bca f641247f 7526 83f8ff }
+ $sequence_0 = { f7d1 33d2 3b4dfc 8bcb 0f43d0 3bd7 0f43fa }
+ $sequence_1 = { e8???????? 8d4e2c e8???????? 8d4e14 e8???????? c74604???????? 8b7e10 }
+ $sequence_2 = { ffd7 837d1c08 8d5508 8d7508 0f435508 0f437508 }
+ $sequence_3 = { c745fc00000000 833e00 7517 68de020000 68???????? 68???????? }
+ $sequence_4 = { 50 e8???????? 83ec18 c645fc05 8bcc 896584 c7411000000000 }
+ $sequence_5 = { 3bf7 0f8595f7ffff 83cfff c745fc07000000 8b750c 85f6 7429 }
+ $sequence_6 = { eb05 6880000000 8bce e8???????? 8b4e20 8bc3 8b09 }
+ $sequence_7 = { c7461000000000 7202 8b36 33c0 668906 8db758030000 8b4614 }
+ $sequence_8 = { 3bf7 758c 8b5dec ff7314 8b35???????? ffd6 }
+ $sequence_9 = { eb02 33c0 894758 8d5758 8a4304 88475c e8???????? }
condition:
- 7 of them and filesize <294912
+ 7 of them and filesize <2252800
}
-rule MALPEDIA_Win_Shareip_Auto : FILE
+rule MALPEDIA_Win_Flagpro_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1e2be420-f7e3-538b-a25d-892f460d058e"
+ id = "a8700192-f3cd-586a-895f-7ccfc513b903"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shareip"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shareip_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flagpro"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flagpro_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "22b55834a3d563030497f1fde153bdd0a045ee32bc87427f1091c9e8cd08bbb9"
+ logic_hash = "21ab8654968f01505a5a06c6c338da8446a910a647e36c5322e4febf20ea2d89"
score = 75
quality = 75
tags = "FILE"
@@ -147728,34 +154707,34 @@ rule MALPEDIA_Win_Shareip_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8534feffff e9???????? 8d8da8feffff e9???????? 8d8558feffff e9???????? 8d8544ffffff }
- $sequence_1 = { 894638 85c9 740f 8bd0 8d4900 8a01 8802 }
- $sequence_2 = { 8a8064954500 08443b1d 0fb64601 47 3bf8 76ea 8b7d08 }
- $sequence_3 = { 395c2444 7426 3bc3 7422 50 e8???????? 8b4c2444 }
- $sequence_4 = { 834dfcff 894614 83c40c 8d45e4 50 e8???????? 8b07 }
- $sequence_5 = { 8b44241c 50 8d8c24a0010000 51 53 53 53 }
- $sequence_6 = { 55 8d4c245c e8???????? 8bd8 895c2414 83fbff 7541 }
- $sequence_7 = { 837de800 7e50 8b03 8b4804 0fb7541930 8d0419 8b4828 }
- $sequence_8 = { 8b9a80f34400 33f3 8b4538 33db 8b553c 33c6 33d6 }
- $sequence_9 = { 33c0 eb05 1bc0 83d8ff 3bc3 7506 895c2418 }
+ $sequence_0 = { 8d8c2480000000 e8???????? 56 c784249c45010001000000 e8???????? }
+ $sequence_1 = { 57 6a00 6a00 6aff 68???????? }
+ $sequence_2 = { ffd0 c684249400000002 8b442430 3bc3 7408 8b08 8b5108 }
+ $sequence_3 = { 56 57 85c0 740b b900030000 8bf3 }
+ $sequence_4 = { 8b442428 3bc3 749d eb93 8b442428 8d54243c 895c243c }
+ $sequence_5 = { ba10000000 8d6e04 395618 7221 8b4500 eb1e }
+ $sequence_6 = { 39ac24c8000000 7210 8b9424b4000000 52 e8???????? 83c404 899c24c8000000 }
+ $sequence_7 = { 33ed 55 68???????? 8d842488030000 50 ff15???????? 8db4243c010000 }
+ $sequence_8 = { 8bf0 83c408 3bf3 7571 57 }
+ $sequence_9 = { 68???????? 8d8424880c0000 6800040000 50 }
condition:
- 7 of them and filesize <811008
+ 7 of them and filesize <1411072
}
-rule MALPEDIA_Win_Tidepool_Auto : FILE
+rule MALPEDIA_Win_Ranbyus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "736615ac-754a-59af-859e-d31c5da8062a"
+ id = "9b877552-6bf5-5d12-bef1-733cc6b8feac"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tidepool"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tidepool_auto.yar#L1-L265"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ranbyus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ranbyus_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "6d671b94ab0cdccf8b9683ef25d1220e65648f34328ff5e4475983ab8ad7951c"
+ logic_hash = "c376990edfad6c071124a105ec8d7e8afaf3007f10ae4746a7ce39d3890ccde0"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -147767,51 +154746,32 @@ rule MALPEDIA_Win_Tidepool_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 50 8b08 ff91a4000000 }
- $sequence_1 = { 8b4df4 64890d00000000 59 5f 5e 5b 8b8d00030000 }
- $sequence_2 = { 8b8d00030000 33cd e8???????? 81c504030000 }
- $sequence_3 = { 83c404 8bc6 5e c20400 80790800 }
- $sequence_4 = { 53 6a02 8bf1 e8???????? }
- $sequence_5 = { 6800000040 8d4500 50 ff15???????? }
- $sequence_6 = { 2bc8 83e906 51 83c006 50 }
- $sequence_7 = { e8???????? 83c40c 803d????????37 7518 68???????? }
- $sequence_8 = { 8b4654 8d9698000000 52 8d5678 8b08 }
- $sequence_9 = { 52 50 8b08 ff91f8000000 85c0 }
- $sequence_10 = { 8b4654 50 8b08 ff5138 }
- $sequence_11 = { 8d5658 52 50 ff91d0000000 33ff }
- $sequence_12 = { c3 56 8bf1 e8???????? 8b4654 }
- $sequence_13 = { 8d45ec 50 681f000200 53 }
- $sequence_14 = { 6810270000 ff15???????? 8b45ec 8b08 }
- $sequence_15 = { 681f000200 56 68???????? 6801000080 }
- $sequence_16 = { 75f9 b8???????? b900000400 c60000 40 49 }
- $sequence_17 = { e8???????? 68???????? 68???????? 68???????? 8d4500 }
- $sequence_18 = { 57 50 6802020000 ff15???????? 68???????? ff15???????? }
- $sequence_19 = { 8bc6 5e 5b c20400 6a14 68???????? }
- $sequence_20 = { 6805400080 e8???????? 8b542424 52 53 }
- $sequence_21 = { 33c9 8aea 83c003 83c504 }
- $sequence_22 = { ff75ec ff15???????? 8b35???????? 6a04 }
- $sequence_23 = { 83651400 8b07 83c40c 837d0c00 0f8ed1000000 8b4d08 41 }
- $sequence_24 = { 8bec 8b4508 56 833c850811011000 }
- $sequence_25 = { 50 ff7508 ff15???????? 395dfc 53 }
- $sequence_26 = { 50 8d4604 50 e8???????? 8d45e0 6a04 }
- $sequence_27 = { 50 89450c ff15???????? 53 ff75fc ff75f8 }
- $sequence_28 = { 8365ec00 8945f4 8d3dd8e30010 8b45f4 d1e0 03f8 }
+ $sequence_0 = { 7504 83c8ff c3 c7402401000000 }
+ $sequence_1 = { 894608 8b44241c 56 68???????? 89460c }
+ $sequence_2 = { 83c414 85f6 7414 6a01 6a01 57 }
+ $sequence_3 = { 760a 814e2500500000 c6060f 0fb606 5e 5b }
+ $sequence_4 = { a1???????? eb09 83780400 7507 8b4034 85c0 }
+ $sequence_5 = { e8???????? 59 8b4e05 89410b 8b4605 39780b 7407 }
+ $sequence_6 = { 8b4e05 89410b 8b4605 39780b }
+ $sequence_7 = { 83c621 8a06 3c46 7240 3c47 }
+ $sequence_8 = { 83780400 7507 8b4034 85c0 75f3 c3 }
+ $sequence_9 = { c3 837c240800 7467 8b44240c }
condition:
- 7 of them and filesize <1998848
+ 7 of them and filesize <638976
}
-rule MALPEDIA_Win_Ratankba_Auto : FILE
+rule MALPEDIA_Win_Doubleback_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fd423e85-7c69-52a0-9324-ef5e9762e7e8"
+ id = "cd786c05-6d47-522c-af3e-e773839ffcc7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ratankba"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ratankba_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doubleback"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doubleback_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "49523307c1fdb5d69527def26960d83b0ac500a3f11bec0bed9b0e81e333a8ec"
+ logic_hash = "b40ea64a869bfecf3f36d9c35b2ecd274734632c8a0bce79f6229d1b07f00bb7"
score = 75
quality = 75
tags = "FILE"
@@ -147825,32 +154785,32 @@ rule MALPEDIA_Win_Ratankba_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5d c20800 8b4d0c 803900 7416 807d0b00 7410 }
- $sequence_1 = { 53 b8???????? 668911 e8???????? 8d8ec0000000 c645fc05 33c0 }
- $sequence_2 = { 53 ff15???????? 85c0 740e 8b45fc 85c0 7407 }
- $sequence_3 = { 55 8bec ff4724 8b4724 53 56 394718 }
- $sequence_4 = { e8???????? 8b4310 33ff 3bc7 7649 397e10 7644 }
- $sequence_5 = { 720a b857000780 e8???????? 8b4b04 5f 8944d104 8bc2 }
- $sequence_6 = { 83c414 85c0 744f 8bc8 e8???????? 8bf0 a1???????? }
- $sequence_7 = { 0f849b010000 83c302 46 ebaa 8b5710 8bc6 8955e4 }
- $sequence_8 = { 8975f4 85f6 790b 5e 83c8ff 5b 8be5 }
- $sequence_9 = { 56 66898578efffff 51 83c8ff 8dbd78efffff c7858cefffff07000000 }
+ $sequence_0 = { b9e3050000 eb3b b90b070000 eb34 2d63450000 7428 }
+ $sequence_1 = { b9ad060000 eb57 b9a7060000 eb50 b947060000 eb49 }
+ $sequence_2 = { eb3b b90b070000 eb34 2d63450000 }
+ $sequence_3 = { 3d39380000 741c 3dd73a0000 740e 3dab3f0000 }
+ $sequence_4 = { b9e7050000 eb42 b9e3050000 eb3b b90b070000 }
+ $sequence_5 = { b90b070000 eb34 2d63450000 7428 2d57020000 }
+ $sequence_6 = { 774f 7446 3d00280000 7438 3d5a290000 742a 3d39380000 }
+ $sequence_7 = { 7438 3d5a290000 742a 3d39380000 }
+ $sequence_8 = { e8???????? 85c0 7508 c60703 e9???????? }
+ $sequence_9 = { 7446 3d00280000 7438 3d5a290000 742a 3d39380000 741c }
condition:
- 7 of them and filesize <303104
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Gacrux_Auto : FILE
+rule MALPEDIA_Win_Hunter_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0c66c13b-77d9-5c78-ab68-75b7e55560db"
+ id = "a2ce8975-358a-5feb-855e-0c18799189f7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gacrux"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gacrux_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hunter"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hunter_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "bb1a910d98caf8e19645b8aead4c6d896507b388f794dfe868a61d77f59f135d"
+ logic_hash = "4840112788d43f80efa44bf4553c38cceb240b146b43c82ea7ba535d388455f9"
score = 75
quality = 75
tags = "FILE"
@@ -147864,34 +154824,34 @@ rule MALPEDIA_Win_Gacrux_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f848e000000 41 83482120 49 8b01 49 83c108 }
- $sequence_1 = { 894808 48 8b4c2430 48 894810 8b4c2444 }
- $sequence_2 = { 48 03ca 849c013c010000 740b 41 81cb00300000 45 }
- $sequence_3 = { 6bc838 48 8b05???????? 8b540120 c1ea02 1bd2 3bd6 }
- $sequence_4 = { 7543 48 85db 7409 }
- $sequence_5 = { 8b3a 48 8bcd 48 c1e91d 48 8bc5 }
- $sequence_6 = { 41 ffc1 49 83c204 41 81f900010000 }
- $sequence_7 = { 0fb7ee 66c1ed08 45 8a780c 45 8bda 45 }
- $sequence_8 = { 56 41 57 48 83ec50 49 63e8 }
- $sequence_9 = { 4d 033e 45 0fb6ed 49 8bcf }
+ $sequence_0 = { 8d4323 03c8 8d83b5000000 038d3cffffff 03c8 8d83ae000000 03ce }
+ $sequence_1 = { 8b5f08 8b440104 8945f0 8b13 8bc8 e8???????? 85c0 }
+ $sequence_2 = { 8d4b38 0faf4dbc 898d34fdffff 8b8d1cffffff 0fafce 8d7375 898d8cfeffff }
+ $sequence_3 = { 8bf9 6b1f14 8b743b0c eb38 0fbf0475080f4700 83f8c2 7433 }
+ $sequence_4 = { 8b4c2440 6aff e8???????? 59 8b4c2448 33c0 89442424 }
+ $sequence_5 = { 53 6a68 5a e8???????? 83c40c b208 8bce }
+ $sequence_6 = { 8b4630 8b14b8 85d2 7405 e8???????? b980000000 e8???????? }
+ $sequence_7 = { c3 51 56 57 8bf1 33c0 8b7e1c }
+ $sequence_8 = { 8b4614 89442418 85c0 750c 385c2431 7506 885c2430 }
+ $sequence_9 = { 8d8d04f8ffff e9???????? 8d8d1cf8ffff e9???????? 8d8de0feffff e9???????? 8d8d34f8ffff }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <1056768
}
-rule MALPEDIA_Win_Moriagent_Auto : FILE
+rule MALPEDIA_Win_9002_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0b12c276-52ba-56f2-9890-c8bf86de4e3d"
+ id = "49e80af5-ef9d-5bf8-b3b9-b7af1f356471"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moriagent"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moriagent_auto.yar#L1-L169"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.9002"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.9002_auto.yar#L1-L290"
license_url = "N/A"
- logic_hash = "0ba5f6f81e0a998dcf4930d5e902ddcfa057da2849fe14345a41be1a23cd042b"
+ logic_hash = "9d293b5dc33eac56c2e3f0cda3054624c24835d742e33a63df2c2aa725e52d40"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -147903,37 +154863,53 @@ rule MALPEDIA_Win_Moriagent_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b802000000 eb05 b801000000 33ff }
- $sequence_1 = { cc 488bc8 e8???????? 48897d00 48c745080f000000 c645f000 488b4528 }
- $sequence_2 = { cc 488bc8 e8???????? 48897da0 48c745a80f000000 c6459000 }
- $sequence_3 = { cc 488bc8 e8???????? 48897d18 48c745200f000000 c6450800 }
- $sequence_4 = { 83bd98efffff10 8bb5c4efffff 8b8d94efffff 660f7ec8 51 0f43d0 }
- $sequence_5 = { cc 488bc8 e8???????? 48897dd0 48c745d80f000000 c645c000 }
- $sequence_6 = { cc 488bc8 e8???????? 48897dc0 48c745c80f000000 c645b000 }
- $sequence_7 = { cc 488bc8 e8???????? 48897d20 48c745280f000000 c6451000 }
- $sequence_8 = { 8d8de4feffff e9???????? 8d8d30ffffff e9???????? 8d8dccfeffff }
- $sequence_9 = { 0f87df160000 52 51 e8???????? 8b85e8eeffff }
- $sequence_10 = { eb06 8bb5e4eeffff 8b857cefffff 85c0 0f84bd080000 80bdc7eeffff00 }
- $sequence_11 = { c785e0feffff0f000000 c685ccfeffff00 6a04 68???????? c7411000000000 c741140f000000 c60100 }
- $sequence_12 = { 0f1006 8b85e8eeffff 0f1185b4efffff f30f7e4610 660fd685c4efffff c7461000000000 c746140f000000 }
- $sequence_13 = { c746140f000000 c60600 8b5d1c 8d4d08 8b5508 8d7d08 8b4518 }
- $sequence_14 = { cc 488bc8 e8???????? 48897de0 48c745e80f000000 c645d000 }
+ $sequence_0 = { 7514 8b4714 8b08 51 e8???????? 8b5714 }
+ $sequence_1 = { 51 8944241c c744241801000000 ff15???????? 3d02010000 }
+ $sequence_2 = { 7504 33ed eb04 2bc8 }
+ $sequence_3 = { 8bd1 2bd0 3bda 7223 }
+ $sequence_4 = { 6a02 ff15???????? 68???????? ff15???????? 6a00 }
+ $sequence_5 = { 8b5c2408 6bdb08 03c3 8b00 }
+ $sequence_6 = { 33c9 3bc8 1bd2 f7da 8915???????? }
+ $sequence_7 = { 03c3 8b00 5b ffd0 8945fc }
+ $sequence_8 = { 51 e8???????? 6a06 6a01 6a02 e8???????? }
+ $sequence_9 = { 8be9 53 50 e8???????? }
+ $sequence_10 = { 7504 33d2 eb05 8b5608 2bd0 3bfa }
+ $sequence_11 = { 682c010000 50 ffd3 3d02010000 7508 }
+ $sequence_12 = { 6a00 6a02 6a03 6a00 e8???????? }
+ $sequence_13 = { 75f6 eb2f 8b542430 8b7c2414 8b6c2430 }
+ $sequence_14 = { 668b3c59 730d 33c9 8a0a }
+ $sequence_15 = { 59 8b0485e0d50010 8d0cf6 8064880400 85ff }
+ $sequence_16 = { 0311 8955fc 837df800 0f86e3000000 8b4508 03450c 2b45f8 }
+ $sequence_17 = { 68???????? 8d4610 50 8d4c2418 51 ff15???????? }
+ $sequence_18 = { 896f2c 8b4748 3bc5 740c 50 }
+ $sequence_19 = { 8d4c240c c644243002 ff15???????? 8bc6 }
+ $sequence_20 = { 6a00 8bd8 51 57 53 }
+ $sequence_21 = { 8b4c242c 5f 89411c 8b442410 895118 8b542434 894124 }
+ $sequence_22 = { 33c4 50 8d442428 64a300000000 8bf1 89742408 68???????? }
+ $sequence_23 = { 8939 89742410 e9???????? 33f6 83ff14 }
+ $sequence_24 = { 0fb74e08 0fafcf 5f 03c1 5e }
+ $sequence_25 = { 031481 52 8b450c 50 }
+ $sequence_26 = { 5d 83c410 c3 8b4508 85c0 7499 }
+ $sequence_27 = { 2bc5 c1ef05 2bcf 2bf5 66898c5a98010000 33c9 }
+ $sequence_28 = { 64a300000000 8b7c2444 8bf1 33db 57 8d4e10 89742414 }
+ $sequence_29 = { 8b742408 57 85f6 742e 0fb74602 8b7c2410 3bf8 }
+ $sequence_30 = { 8b5c2424 3bcb 0f83f6040000 33db }
condition:
- 7 of them and filesize <1347904
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Cargobay_Auto : FILE
+rule MALPEDIA_Win_Gaudox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "73c95842-79c7-50a5-be49-1d9ec0676b5e"
+ id = "1eecaa5e-0125-509a-9dab-e8ce2f4b63fe"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cargobay"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cargobay_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gaudox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gaudox_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "6881c841016fbba7262559cf71fef612762f65200b77d9ecbf913cbcf1cd6281"
+ logic_hash = "7eb2982f230b20ae36bb88377d3dc0b3ae4c2623263daca498d5416d3995e6aa"
score = 75
quality = 75
tags = "FILE"
@@ -147947,32 +154923,32 @@ rule MALPEDIA_Win_Cargobay_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 4c8b4910 31c0 4c01ca 7216 48395108 7210 }
- $sequence_1 = { 80bc24b100000000 0f84e2020000 8a8c24b2000000 0fb6d1 83fa2c 743e b800000000 }
- $sequence_2 = { e8???????? eb56 488db42498010000 41b8b8000000 4889f1 4c89fa e8???????? }
- $sequence_3 = { c6040800 48ffc1 ebf2 488b4748 41b801000000 4889f9 4c89e2 }
- $sequence_4 = { eb04 48832300 4889f1 4c89f2 4883c448 5b 5d }
- $sequence_5 = { e8???????? 0f0b 56 57 4881ec18040000 4889ce 488d7c2428 }
- $sequence_6 = { ba05000000 e8???????? e9???????? 488d0dddfe0d00 ba09000000 e8???????? 4889c3 }
- $sequence_7 = { c5fa6f8729020000 c4e27d470d???????? c4e27d4505???????? c5fd6f15???????? c4e26d36c0 c5fdebc1 c5fddb05???????? }
- $sequence_8 = { 4d896608 488d8c2488000000 488919 48897108 48898424b0000000 4889bc24b8000000 4d8937 }
- $sequence_9 = { ba08000000 41b908000000 e8???????? 4881c600020000 4889f1 4c89f2 e8???????? }
+ $sequence_0 = { 7403 c60000 8bce e8???????? 8b45f8 85c0 7410 }
+ $sequence_1 = { 837df000 0f849a000000 6a00 8d95c4feffff 52 b804000000 6bc800 }
+ $sequence_2 = { 8d8c2458030000 e8???????? 8bf0 85f6 0f88df000000 a1???????? 8d8c2450030000 }
+ $sequence_3 = { a1???????? 57 ffb0b8000000 eb26 8bb8b0000000 83ff54 }
+ $sequence_4 = { 13c9 66f3ab 8b450c 03f0 8bc6 5f 5e }
+ $sequence_5 = { 56 8b7014 81feb8000000 7729 68???????? b9???????? e8???????? }
+ $sequence_6 = { ff75fc 8bf0 6a08 6a00 e8???????? 85f6 782a }
+ $sequence_7 = { 8b45f4 8b5018 85d2 74ec 6a00 6a00 68d113282e }
+ $sequence_8 = { 57 85c0 0f84ad010000 85d2 0f84a5010000 8b7d08 85ff }
+ $sequence_9 = { 8d442460 50 6a27 6a00 e8???????? 85c0 781c }
condition:
- 7 of them and filesize <3432448
+ 7 of them and filesize <155648
}
-rule MALPEDIA_Win_Chairsmack_Auto : FILE
+rule MALPEDIA_Win_Cmsbrute_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "89ef8364-1d04-5ec8-8eb0-0caa1f808e4e"
+ id = "8f79cbd4-e913-5f2c-8c88-b934c5aa8f71"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chairsmack"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chairsmack_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cmsbrute"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cmsbrute_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "30e742a004c4313020160ca17f15835b780b5f554d2c7d95b7655ea180005855"
+ logic_hash = "9b2fd3bf8cbe0036d7312658e08a3f69e7f5e49973eb02bc9f177311ac61fa60"
score = 75
quality = 75
tags = "FILE"
@@ -147986,32 +154962,32 @@ rule MALPEDIA_Win_Chairsmack_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8c2410010000 c68424840300003a e8???????? 83ec1c 8d842428010000 8bcc 8964242c }
- $sequence_1 = { 8d4de8 56 c745fc01000000 e8???????? 8b7df0 8d4de8 2b7e08 }
- $sequence_2 = { 8d4c2464 e8???????? e9???????? 68???????? 8d8c24bc000000 e8???????? 8bd0 }
- $sequence_3 = { 8b4004 eb03 83c004 51 50 ffb4249c000000 51 }
- $sequence_4 = { 660f57c4 8b7c2414 8d442421 c644242025 8b5714 f6c220 7409 }
- $sequence_5 = { 7613 b8feffff7f 8d3419 2bc1 3bd8 7605 befeffff7f }
- $sequence_6 = { 8d8db8fcffff e9???????? 8d8dd0fdffff e9???????? 8d8dbcfcffff e9???????? 8d8dc0fdffff }
- $sequence_7 = { c68424b8030000b9 8bcc 68???????? e8???????? c68424b8030000b6 e8???????? 83c430 }
- $sequence_8 = { 8b148dd06d4a00 81c200080000 3955e4 7366 8b45e4 c6400400 8b4de4 }
- $sequence_9 = { 0fbe02 85c0 0f848e010000 8b4dfc 51 }
+ $sequence_0 = { ff7004 51 ff7510 8b4d08 ff750c 56 e8???????? }
+ $sequence_1 = { e8???????? ff4de0 8bde 75e4 8b75d8 832700 6a00 }
+ $sequence_2 = { ffb068010000 ff15???????? 8b06 83a06801000000 8b442418 59 59 }
+ $sequence_3 = { eb0f e8???????? 59 50 8d75b4 e8???????? 59 }
+ $sequence_4 = { eb02 8b01 3945fc 0f8d8a000000 8b45fc e8???????? 8bf0 }
+ $sequence_5 = { ff75c4 8b4dcc ff75d4 8bd8 0fb7463e 50 53 }
+ $sequence_6 = { eb02 33ff 8bb59cfdffff 51 e8???????? 59 85ff }
+ $sequence_7 = { ff75e4 57 e8???????? 83c414 85c0 7425 8bf7 }
+ $sequence_8 = { ff742430 e8???????? 89442430 8b4304 8378041b 8b30 8b7808 }
+ $sequence_9 = { ff15???????? 8945cc 8b35???????? 83cfff 3bdf 7403 53 }
condition:
- 7 of them and filesize <1974272
+ 7 of them and filesize <5275648
}
-rule MALPEDIA_Win_Atmosphere_Auto : FILE
+rule MALPEDIA_Win_Arefty_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7ba90f14-d41a-58f9-948d-cf574aec7198"
+ id = "290417d3-5ee5-5229-8624-fd994b33b5b6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atmosphere"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atmosphere_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.arefty"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.arefty_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "0264599b5475822be219779f2f93298a08919e3b2fbd551146e8b50c69fa19e9"
+ logic_hash = "f5f9e554cdcd0132916bd1281d9476767533aa9af2658a9193107a622555119f"
score = 75
quality = 75
tags = "FILE"
@@ -148025,34 +155001,34 @@ rule MALPEDIA_Win_Atmosphere_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83ec14 56 8b7104 85f6 }
- $sequence_1 = { 88460e 33c0 894612 894616 89461a 884e1e }
- $sequence_2 = { e8???????? 8b4604 85c0 7504 33f6 eb08 }
- $sequence_3 = { 8bcf ff5338 5f 5e }
- $sequence_4 = { c645fc02 8bcc 8965e8 50 51 e8???????? }
- $sequence_5 = { 8bce 8975e8 8806 ff15???????? }
- $sequence_6 = { 8bc4 89642410 50 e8???????? }
- $sequence_7 = { 8b7c240c 8bf1 57 ff15???????? 8b470c }
- $sequence_8 = { 51 83ec10 8bc4 89642410 50 e8???????? }
- $sequence_9 = { 8bcc 8965e8 50 51 }
+ $sequence_0 = { 57 e8???????? 83c404 83fbff 7407 53 }
+ $sequence_1 = { 50 53 ff15???????? 680000a000 e8???????? }
+ $sequence_2 = { 680000a000 57 53 ff15???????? 85c0 }
+ $sequence_3 = { 680000a000 57 53 ff15???????? }
+ $sequence_4 = { 57 e8???????? 83c404 83fbff 7407 53 ff15???????? }
+ $sequence_5 = { ff15???????? 680000a000 e8???????? 8bf8 }
+ $sequence_6 = { 0fb6041e 50 8b07 68???????? 6a03 8d04b0 }
+ $sequence_7 = { 8b07 68???????? 6a03 8d04b0 50 e8???????? 46 }
+ $sequence_8 = { 50 53 ff15???????? 680000a000 e8???????? 8bf8 83c404 }
+ $sequence_9 = { 50 53 ff15???????? 680000a000 }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <237568
}
-rule MALPEDIA_Win_Vidar_Auto : FILE
+rule MALPEDIA_Win_Magic_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "82d78950-07cb-574b-bd37-68a5c755b922"
+ id = "fef12775-f5d4-5648-9916-cb915f91f28b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vidar_auto.yar#L1-L344"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.magic_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.magic_rat_auto.yar#L1-L111"
license_url = "N/A"
- logic_hash = "a393071c5079ff4f7beb96e2467045a96573fe4c259d05f0ce07fde763d7466d"
- score = 75
- quality = 73
+ logic_hash = "d23de63f3611a6306ebe3970ddd7285c351120d5c12dbd45ba2d1d594ef068a3"
+ score = 60
+ quality = 45
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -148064,60 +155040,32 @@ rule MALPEDIA_Win_Vidar_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 25ff7f0000 c3 e8???????? 8b486c 3b0d???????? 7410 }
- $sequence_1 = { 05c39e2600 894114 c1e810 25ff7f0000 c3 e8???????? }
- $sequence_2 = { 8d8d68fdffff 51 50 ff15???????? }
- $sequence_3 = { 7202 8b00 8d8d68fdffff 51 }
- $sequence_4 = { 740a b800000500 e9???????? 57 }
- $sequence_5 = { 56 8b742408 8b865caf0100 57 }
- $sequence_6 = { 895dd0 c746140f000000 895e10 8975cc }
- $sequence_7 = { 8b8648af0100 c1e803 038644af0100 5e 5d c3 }
- $sequence_8 = { 895dfc e8???????? 83781408 c645fc01 }
- $sequence_9 = { 8b7508 33ff 89b55cfdffff 89bd60fdffff }
- $sequence_10 = { 5f c6043300 8bc6 5e 5b c20400 }
- $sequence_11 = { 50 ff15???????? 8b4da0 8901 85c0 }
- $sequence_12 = { 83781410 7202 8b00 50 8b45a0 }
- $sequence_13 = { eb02 33c0 5f 5e c9 c3 6a04 }
- $sequence_14 = { 5e c20400 ff742408 e8???????? 59 83f8ff 7503 }
- $sequence_15 = { c9 c3 8b542408 85d2 7503 }
- $sequence_16 = { 0fb605???????? 50 0fb605???????? 50 0fb605???????? 50 6a01 }
- $sequence_17 = { 53 50 899e6caf0600 e8???????? }
- $sequence_18 = { 53 68???????? 8d8da8000000 e8???????? }
- $sequence_19 = { c3 55 8bec 83ec0c 8365fc00 8365f400 8365f800 }
- $sequence_20 = { c20400 56 8bf1 e8???????? 6a00 ff74240c 8bce }
- $sequence_21 = { 0faf450c 50 e8???????? 59 }
- $sequence_22 = { 8b4508 8906 8b450c 894608 }
- $sequence_23 = { 8b4120 8910 8b4130 8910 c3 56 }
- $sequence_24 = { e8???????? c9 c3 55 8bec 83ec18 8b450c }
- $sequence_25 = { 8d852cffffff 50 8d459c 50 }
- $sequence_26 = { 6860ea0000 6a00 ff15???????? 50 }
- $sequence_27 = { 50 ff15???????? 6a1a e8???????? }
- $sequence_28 = { 5f c21000 8bff 55 8bec 6a0a }
- $sequence_29 = { e8???????? 83c410 85c0 7404 6a99 ebcc }
- $sequence_30 = { 7410 84c0 7406 3ac8 7c14 }
- $sequence_31 = { 7408 ff36 e8???????? 59 834e04ff 8b06 }
- $sequence_32 = { e8???????? 83c408 84c0 740e 68???????? }
- $sequence_33 = { 6a0b 6a10 e8???????? 83c41c 8be5 }
- $sequence_34 = { eb0b 8b45f4 0500040000 8945f4 }
- $sequence_35 = { 83ec08 dd4508 dd1c24 6a0b 6a08 }
- $sequence_36 = { 8bc6 8b35???????? 99 2bc2 }
- $sequence_37 = { 8bc6 5f 5e 5d 5b 81c460010000 c3 }
+ $sequence_0 = { 85c0 7407 3dffff0000 756f }
+ $sequence_1 = { f20f2ac9 f20f5cc1 f20f58c3 f20f2cc0 }
+ $sequence_2 = { 0f84b8000000 83faff 7408 f0830001 }
+ $sequence_3 = { 660f2ec2 7308 660f5705???????? 660f2ee2 f20f59c5 7308 660f5725???????? }
+ $sequence_4 = { 29c2 89d0 c1f80e f7d8 eb08 }
+ $sequence_5 = { 8b01 81e20080ffff 25ff7f0000 09d0 }
+ $sequence_6 = { 8b4500 85c0 0f8472010000 83f8ff 740b f0836d0001 }
+ $sequence_7 = { f20f58c3 f20f2cd0 01ca e9???????? }
+ $sequence_8 = { 85d2 740b 83faff 74ad f0832801 }
+ $sequence_9 = { 81fa???????? 7442 81fa???????? 744a }
condition:
- 7 of them and filesize <2793472
+ 7 of them and filesize <41843712
}
-rule MALPEDIA_Win_Downdelph_Auto : FILE
+rule MALPEDIA_Win_Rustock_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9652ab66-5cde-50a7-9cf0-943c75b27c39"
+ id = "cb44bdc8-a730-56ac-98ad-0553c4475f0d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.downdelph"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.downdelph_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rustock"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rustock_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "800e73805e0adaa63996d81ee2c529d701882055ee15e51dd88ba5a4c6bc228a"
+ logic_hash = "5fff7e7d2c26e2013c1d3a65535e3ac75dc9cd45cc7a0c04309e438d2a86951e"
score = 75
quality = 75
tags = "FILE"
@@ -148131,32 +155079,32 @@ rule MALPEDIA_Win_Downdelph_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c9 0f84d2feffff 53 56 57 89c3 }
- $sequence_1 = { 83c4f8 8bf2 33d2 8bdc }
- $sequence_2 = { e8???????? 48 50 8bc3 b901000000 8b15???????? }
- $sequence_3 = { 8d55d8 e8???????? 8b5708 88041a }
- $sequence_4 = { 53 56 33db 899de0fbffff }
- $sequence_5 = { 0f8cd6020000 46 33ff 8b15???????? 8bc7 e8???????? }
- $sequence_6 = { 8b45fc e8???????? 50 8b45f0 }
- $sequence_7 = { 2bd3 2bd7 8bfa 85ff 7d02 33ff }
- $sequence_8 = { 68???????? 64ff32 648922 6a00 6800000080 }
- $sequence_9 = { ff05???????? 7544 b8???????? e8???????? b8???????? }
+ $sequence_0 = { 8d6424fc 892c24 31ed 01e5 8d6424e4 50 }
+ $sequence_1 = { 031d???????? 21db 5e 5a }
+ $sequence_2 = { 8bd8 85db 7439 8b4dc0 33c0 8bfb 8bd1 }
+ $sequence_3 = { 83c604 56 53 ff15???????? 53 }
+ $sequence_4 = { 833d????????00 7421 56 e8???????? 85c0 59 75ac }
+ $sequence_5 = { 50 ff7520 e8???????? 83c418 8945cc 3bc7 74d4 }
+ $sequence_6 = { ff750c e8???????? 68e8030000 ff15???????? e8???????? 8bf8 }
+ $sequence_7 = { 59 8945c4 83f8ff 7507 33c0 e9???????? 3b4520 }
+ $sequence_8 = { ebb5 7402 ebd3 8b1c24 68???????? }
+ $sequence_9 = { 014514 a1???????? 83f802 0f84de010000 3bc7 }
condition:
- 7 of them and filesize <172032
+ 7 of them and filesize <565248
}
-rule MALPEDIA_Win_Catb_Auto : FILE
+rule MALPEDIA_Win_Vflooder_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "515d6ff4-29b8-5f9d-8e4d-ae72db2e24b8"
+ id = "9887b2d4-11f9-501f-8a80-a11d525400b9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.catb"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.catb_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vflooder"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vflooder_auto.yar#L1-L106"
license_url = "N/A"
- logic_hash = "9a8c29b856252443b361ebb50acc406bc1908e5c4eee2fd3c5627837db3c96fd"
+ logic_hash = "c395df9bf0cea55ef8201fced5f6d58ff4786707da9a8f0c23e3a94a9aa3418e"
score = 75
quality = 75
tags = "FILE"
@@ -148170,32 +155118,32 @@ rule MALPEDIA_Win_Catb_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 418bcc e8???????? 85c0 0f8484000000 488b442440 488d0d22920300 }
- $sequence_1 = { 4c8d050e9c0300 83e23f 488bcb 48c1f906 488d14d2 498b0cc8 8064d138fd }
- $sequence_2 = { 488d159bdc0000 483950f0 740b 488b10 }
- $sequence_3 = { 4c8d0da47f0000 b903000000 4c8d05907f0000 488d15f9750000 e8???????? 4885c0 740f }
- $sequence_4 = { 4533c0 488d0d8e0e0400 baa00f0000 e8???????? 85c0 740a ff05???????? }
- $sequence_5 = { 4c8d0d6bab0300 4c8bc6 488bd7 488bcb e8???????? }
- $sequence_6 = { 4c8d0d922affff 4c8b4570 8b5568 488b4d60 }
- $sequence_7 = { 4053 4883ec20 8bd9 4c8d0d05d00000 }
- $sequence_8 = { 488d0d72190400 e8???????? 488b442438 488905???????? 488d442438 4883c008 }
- $sequence_9 = { 488bc3 498784f6803c0400 4885c0 7409 }
+ $sequence_0 = { 60 ff35???????? 8f442438 9c }
+ $sequence_1 = { 3b45f0 60 9c 8d642424 }
+ $sequence_2 = { 9c 60 9c 9c 8d642430 }
+ $sequence_3 = { 9c ff742404 8d642434 e9???????? }
+ $sequence_4 = { e9???????? ff742408 8f4500 60 }
+ $sequence_5 = { 0000 43 7265 61 7465 }
+ $sequence_6 = { f5 83ef04 f5 ff37 }
+ $sequence_7 = { e8???????? 0000 43 7265 }
+ $sequence_8 = { b02e f5 f2ae e8???????? }
+ $sequence_9 = { 9c f2ae 9c 9c }
condition:
- 7 of them and filesize <593920
+ 7 of them and filesize <860160
}
-rule MALPEDIA_Win_Calmthorn_Auto : FILE
+rule MALPEDIA_Win_Urlzone_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8cbb3f25-515c-5fed-8b4e-4a931d9bfb1a"
+ id = "73713fa1-9237-58d2-8cc2-5acf9c265fc9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.calmthorn"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.calmthorn_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.urlzone"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.urlzone_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "98170ddc8dfcd366956427aafd69264166f05ad426e5dc909d0630e51620ea92"
+ logic_hash = "4cce61429410ef9f511dc19a60899f126670164d7c8bb8ef8edba2014cda32d1"
score = 75
quality = 75
tags = "FILE"
@@ -148209,32 +155157,32 @@ rule MALPEDIA_Win_Calmthorn_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c78548adffff00000000 eb0f 8b8548adffff 83c001 898548adffff 8b8d68f9ffff 51 }
- $sequence_1 = { e8???????? 83c404 3985dcf3ffff 7d20 8b954cfaffff 83c201 89954cfaffff }
- $sequence_2 = { 0f57c0 660f13857498ffff eb1e 8b957498ffff 83c201 8b857898ffff 83d000 }
- $sequence_3 = { eb1e 8b85bc86ffff 83c001 8b8dc086ffff 83d100 8985bc86ffff 898dc086ffff }
- $sequence_4 = { 8b959875ffff 83d200 898d9475ffff 89959875ffff 83bd9875ffff00 7722 720c }
- $sequence_5 = { ebb7 0fb6952cfdffff 83fa01 7552 c7855cbdffff00000000 eb0f 8b855cbdffff }
- $sequence_6 = { ebba 0fb68d5efdffff 83f901 7556 0f57c0 660f1385c472ffff eb1e }
- $sequence_7 = { 8a95b7fdffff 80c201 8895b7fdffff ebbd 0fb6859efdffff 83f801 7552 }
- $sequence_8 = { 8b8518f8ffff 0fbe08 85c9 7502 eb02 ebba 0fb69591fdffff }
- $sequence_9 = { eb0f 8b8d34f0ffff 83c101 898d34f0ffff 8b9564f6ffff 52 e8???????? }
+ $sequence_0 = { 7c32 80f839 7f05 80e830 eb22 }
+ $sequence_1 = { 80fc39 7f05 80ec30 eb22 }
+ $sequence_2 = { 7f05 80ec30 eb22 80fc41 7c54 }
+ $sequence_3 = { 80c00a eb10 80f861 7c11 80f866 }
+ $sequence_4 = { 5f 5e c3 57 51 89c7 }
+ $sequence_5 = { 80c40a eb10 80fc61 7c42 80f866 7f3d }
+ $sequence_6 = { 7f0c 80e861 80c00a c0e004 08e0 }
+ $sequence_7 = { 80f841 7c23 80f846 7f08 }
+ $sequence_8 = { 80f839 7f05 80e830 eb22 80f841 7c23 }
+ $sequence_9 = { 80ec30 eb22 80fc41 7c54 }
condition:
- 7 of them and filesize <2322432
+ 7 of them and filesize <704512
}
-rule MALPEDIA_Win_Rerdom_Auto : FILE
+rule MALPEDIA_Win_Doublefantasy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "26b21d13-90fc-5a47-a822-e7b7af65cf28"
+ id = "fe1fe594-5930-58a6-8152-affb40d52392"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rerdom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rerdom_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doublefantasy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doublefantasy_auto.yar#L1-L176"
license_url = "N/A"
- logic_hash = "f1628ed7c3a0f5463a2b7ad02b3e6deb2af0e74d20f58edaa325cbcbd6ff539b"
+ logic_hash = "c2743e8ba6874f5905b98f01968f640324da6dd46040ee9e2e2dc712fae3b7b1"
score = 75
quality = 75
tags = "FILE"
@@ -148248,32 +155196,38 @@ rule MALPEDIA_Win_Rerdom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85f6 7425 8b550c b8???????? e8???????? 3bc7 }
- $sequence_1 = { 89470c 8b4508 894708 eb1c 33db 53 }
- $sequence_2 = { 8b44240c 21b0cc000000 21b0d0000000 8bd8 8d842412060000 50 83ceff }
- $sequence_3 = { e9???????? 83f801 7533 8b4e04 8b97d0000000 8b4608 }
- $sequence_4 = { e8???????? 53 a3???????? 57 8bc6 e8???????? 5f }
- $sequence_5 = { 8b742430 8d4618 50 8d4c2428 e8???????? 84c0 741e }
- $sequence_6 = { 7527 8b4510 85c0 7405 }
- $sequence_7 = { 3bde 0f84c5000000 8b430c 3bc6 0f84ba000000 897510 8b00 }
- $sequence_8 = { 8b450c e8???????? 8945e4 85c0 7427 8365fc00 ff750c }
- $sequence_9 = { 41 66890456 0fb7044b 6685c0 75ec 8bc3 }
+ $sequence_0 = { ff75e0 e8???????? 8945c4 3d05000780 7458 3d09000c80 }
+ $sequence_1 = { 770b 0fb6c0 8a80ad8c2700 eb02 32c0 84c0 7410 }
+ $sequence_2 = { 8a80908c2700 eb02 b03d 884103 c3 55 }
+ $sequence_3 = { 33d2 8a5001 c1ee06 83e20f c1e202 0bd6 8a92908c2700 }
+ $sequence_4 = { ff750c 8b4622 03c6 50 e8???????? 83c40c be???????? }
+ $sequence_5 = { 51 68???????? ff750c 8b1d???????? ffd3 83c420 ff75e0 }
+ $sequence_6 = { 8a92908c2700 885101 7e1c 0fb67002 }
+ $sequence_7 = { ff45f8 3c2b 720f 3c7a 770b 0fb6c0 8a80ad8c2700 }
+ $sequence_8 = { 0bd6 837c241001 8a92908c2700 885101 }
+ $sequence_9 = { 8a92908c2700 eb02 b23d 837c241002 885102 }
+ $sequence_10 = { 85c0 7c6a 8b45e4 8b08 8d954cffffff }
+ $sequence_11 = { e8???????? 8b4605 c68094a3270000 ff35???????? ff35???????? e8???????? 83c414 }
+ $sequence_12 = { a5 a5 a5 66a5 6a3d 59 }
+ $sequence_13 = { 68???????? 68???????? ff15???????? 83c40c 837de000 0f8660010000 }
+ $sequence_14 = { ff750c ff7508 ff15???????? 8945a8 3bc3 752b }
+ $sequence_15 = { 33ff eb06 56 e8???????? }
condition:
- 7 of them and filesize <352256
+ 7 of them and filesize <172032
}
-rule MALPEDIA_Win_Webc2_Qbp_Auto : FILE
+rule MALPEDIA_Win_Jlorat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b171d237-d33f-5b2c-9bb0-c659a34a40b8"
+ id = "eb5a0545-ab37-5e70-b9eb-6c48eb9adb8a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_qbp"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_qbp_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jlorat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jlorat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "d54f700be976af1656f6aaefd7f02b0196b5db00252f63d6c12db29d09a9a088"
+ logic_hash = "c96d7ee2744d61897b682d97d67d56d29e38731c8c93cf3d00f8d6450ca3d2bf"
score = 75
quality = 75
tags = "FILE"
@@ -148287,32 +155241,32 @@ rule MALPEDIA_Win_Webc2_Qbp_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7511 8d85e8fcffff 50 ff15???????? }
- $sequence_1 = { 3b9090830000 0f8e9d000000 8b4df0 8b819c830000 0345fc 6bc003 99 }
- $sequence_2 = { 83c40c c785e0fcffff01000000 ff15???????? 8985f4feffff 8b95e0fcffff 52 8b85f0feffff }
- $sequence_3 = { b9fa000000 2bc8 898dd8fcffff 8b95e8fdffff 52 e8???????? 83c404 }
- $sequence_4 = { 83ec0c 56 894df4 66c745fc0000 eb0c 668b45fc 66050100 }
- $sequence_5 = { 85c0 746d 8d4dfc 51 8d55f8 52 e8???????? }
- $sequence_6 = { 8b450c 25ffff0000 50 8b4dec 51 ff15???????? 8945fc }
- $sequence_7 = { 0fbf4dec 3bc1 7d7d 8b4de4 e8???????? 668945f4 0fbf55f4 }
- $sequence_8 = { 81eafd000000 668955ec 66c745e80000 eb0c 668b45e8 66050100 668945e8 }
- $sequence_9 = { 83bde8fdffff00 7574 6800010000 6a00 8d85ecfdffff 50 }
+ $sequence_0 = { e8???????? 83ec10 89c1 83c101 83d200 89542450 31c0 }
+ $sequence_1 = { f20f114620 c7464001000000 89e0 8d5620 895004 8908 e8???????? }
+ $sequence_2 = { f20f1086d8020000 f20f108ee0020000 f20f118e28030000 f20f118620030000 f20f108630030000 f20f118648030000 f20f108620030000 }
+ $sequence_3 = { f6861618000001 0f85c0160000 e9???????? 8b4510 8b08 89e0 894804 }
+ $sequence_4 = { eb00 e9???????? 8b559c 8b7580 8b7d84 8b5da4 8b4d88 }
+ $sequence_5 = { e8???????? 8945c8 eb00 8b4dc4 8b45c8 c645e300 8945cc }
+ $sequence_6 = { c745f0ffffffff 89e0 8d4dd8 8908 e8???????? 8b45c8 8b4de8 }
+ $sequence_7 = { f30f118424d8000000 eb43 8b4c2448 8b54244c 89e0 895004 8908 }
+ $sequence_8 = { e8???????? 894644 eb00 8b4e44 c601ff c64101ff c64102ff }
+ $sequence_9 = { eb09 8b4df4 83c101 894df4 837df40a 7302 ebef }
condition:
- 7 of them and filesize <630784
+ 7 of them and filesize <10952704
}
-rule MALPEDIA_Win_Eyservice_Auto : FILE
+rule MALPEDIA_Win_Gopuram_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e6b201c5-31f5-59a2-a52d-309e470fcb5a"
+ id = "886a3e56-99e6-5544-870d-cee2f3bf23a6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.eyservice"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.eyservice_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gopuram"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gopuram_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "a8d5ae517d0720536deb96b397532bb33ed4fe4db40da33e37b572e015c805c7"
+ logic_hash = "4e587acafeaded148024e517c8ecf7276743814969e25e84b3cedf8d114b44f9"
score = 75
quality = 75
tags = "FILE"
@@ -148326,32 +155280,32 @@ rule MALPEDIA_Win_Eyservice_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c1f802 3bf0 72da eb22 8b0d???????? 2b0d???????? c1f902 }
- $sequence_1 = { 6a01 6a01 68???????? ffd6 83c410 8d542410 52 }
- $sequence_2 = { 83bef800000000 747c 8d4c2408 e8???????? a1???????? 8d4c2408 51 }
- $sequence_3 = { 6808020000 8d8e34020000 51 e8???????? 85c0 7c1e }
- $sequence_4 = { 83c404 8bc8 e8???????? 8bf0 8bce e8???????? 8b4f10 }
- $sequence_5 = { e8???????? b901000000 66894f08 5f 5e 5d 8d410d }
- $sequence_6 = { 68???????? 8d542418 52 ff15???????? 85c0 754f 88442414 }
- $sequence_7 = { 50 03f7 56 e8???????? 8b4c2420 83c410 5f }
- $sequence_8 = { a3???????? e8???????? 6a06 68???????? 56 a3???????? }
- $sequence_9 = { 85c0 7459 66837d005c 7452 66837c24145c 754a }
+ $sequence_0 = { e8???????? 48894308 4885c0 7412 418d562f 488bc8 e8???????? }
+ $sequence_1 = { 448bfb 48895dc7 8bcb 48895d9f 48895db7 48895d97 48895da7 }
+ $sequence_2 = { 8bc1 83e010 c1e804 898508010000 f6c104 7507 f6c108 }
+ $sequence_3 = { e8???????? eb21 c7442420210e0480 41b99e100000 4c8d05938b0600 8bd7 488bce }
+ $sequence_4 = { ff05???????? b801000000 4883c428 c3 ff0d???????? 751a 488b0d???????? }
+ $sequence_5 = { e9???????? 488b0d???????? 488b01 ff90f8000000 83f805 0f84e1fdffff 488b0d???????? }
+ $sequence_6 = { 66094354 8b8597000000 83c0fc 83f801 0f8755010000 488b742448 418bf9 }
+ $sequence_7 = { 89543104 488d051c8b0300 48898698040000 4889aea0040000 4889aea8040000 4889aeb0040000 488d8eb8040000 }
+ $sequence_8 = { 890d???????? c705????????09000380 8bcf 488d05ce350900 6690 3b70fc 7508 }
+ $sequence_9 = { bf01000000 e9???????? 488b0d???????? 488b01 ff90f8000000 83f805 7463 }
condition:
- 7 of them and filesize <452608
+ 7 of them and filesize <1591296
}
-rule MALPEDIA_Win_Netspy_Auto : FILE
+rule MALPEDIA_Win_Redyms_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "59f8d53f-335b-5ed2-a6be-e28bbbbbcf22"
+ id = "da0046e8-7d1d-55ff-bc47-8c4a49be473c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.netspy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.netspy_auto.yar#L1-L104"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redyms"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redyms_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "5f6115aa578488570bf6917737e346bbf4658a865ab8c32a6d3ce07b27ad566b"
+ logic_hash = "5d36da1238e7bd61b571d2194e775b3f30f76bd59bc3908f725087cbecb38f2e"
score = 75
quality = 75
tags = "FILE"
@@ -148365,30 +155319,32 @@ rule MALPEDIA_Win_Netspy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f45c8 488b85e8330000 8908 8b15???????? 833d????????0a 0f9cc1 }
- $sequence_1 = { 4989e1 4c898d905b0000 e8???????? 4829c4 488b85f81e0000 4989e1 }
- $sequence_2 = { e9???????? 488b85003a0000 8b10 89d1 }
- $sequence_3 = { c3 488b4df0 b810000000 e8???????? 4829c4 }
- $sequence_4 = { 488b8578430000 8b00 898580430000 8b15???????? 833d????????0a 0f9cc1 }
- $sequence_5 = { 4889e1 e8???????? 4829c4 488b85d8310000 4889e2 458910 }
- $sequence_6 = { e8???????? 4829c4 488b8540150000 4989e1 4c898d00600000 e8???????? }
- $sequence_7 = { a801 0f8515000000 65488b042560000000 488985406b0000 e9???????? 488b85406b0000 488b4018 }
+ $sequence_0 = { 32d8 80f3fb 8819 40 41 6683f805 72ee }
+ $sequence_1 = { 8b4604 50 6a00 ffd3 50 ffd7 56 }
+ $sequence_2 = { 33c5 8945fc 56 8b35???????? 8d4ddc 8bd1 }
+ $sequence_3 = { 85f6 0f84e4000000 8b3d???????? 8d4de8 8bd1 33c0 }
+ $sequence_4 = { a1???????? 33c5 8945fc 56 c785ccfeffff04010000 7203 }
+ $sequence_5 = { c745d000000000 ff15???????? 5f 85c0 }
+ $sequence_6 = { 7417 8b45f4 8b4df8 50 51 56 ff15???????? }
+ $sequence_7 = { 8b4608 8b4e04 50 6a00 e8???????? 83c408 }
+ $sequence_8 = { 83c8ff 5b 8be5 5d c3 8bc6 5f }
+ $sequence_9 = { 8d5828 53 8945fc ffd7 83caff 8bc6 f00fc110 }
condition:
- 7 of them and filesize <12033024
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Ripper_Atm_Auto : FILE
+rule MALPEDIA_Win_Icefog_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a163a628-88ff-5ee3-8ab0-3e7869e5ed11"
+ id = "048267f9-e0c5-52eb-96a2-fb16cbcf8de1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ripper_atm"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ripper_atm_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.icefog"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.icefog_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "30a8a446c0211fbfa8563685de5143789e29b7c89e693b370c3a643209d252a9"
+ logic_hash = "1d4c21c23eefcc954f2b32ae717065ebcfe80845052716e0c9e4c85776b4e83c"
score = 75
quality = 75
tags = "FILE"
@@ -148402,32 +155358,32 @@ rule MALPEDIA_Win_Ripper_Atm_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b7d08 2175fc 397714 7e2a ff770c 8b33 8bcb }
- $sequence_1 = { 0f434dd8 837dd408 8d5598 52 8d9550ffffff 52 }
- $sequence_2 = { 3938 8b45ec 7408 8b4de8 3b4810 7327 8b4e08 }
- $sequence_3 = { 6a0f 50 ff15???????? 85c0 7402 32c0 c20800 }
- $sequence_4 = { 8b02 6a04 8b4804 03ca e8???????? }
- $sequence_5 = { 6a1c e8???????? 59 85c0 7420 33c9 c7400410000000 }
- $sequence_6 = { c1f805 83e21f 8b0c85f0974400 c1e206 8a441124 3245fe 247f }
- $sequence_7 = { 51 8d55c8 8d4d8c e8???????? 83c410 84c0 7445 }
- $sequence_8 = { 8bf9 50 e8???????? ff7518 8d45ec ff7514 8bcf }
- $sequence_9 = { 03f0 8b442424 2bc1 99 f77c2418 47 3bf8 }
+ $sequence_0 = { 80e3fb 899588feffff 33d2 80c327 85ff 0f94c2 85d2 }
+ $sequence_1 = { c78530ffffff05000000 eb0f 83f803 750a c78530ffffff02000000 8b4604 50 }
+ $sequence_2 = { 751e 8b4d0c 8d450c 50 57 51 e8???????? }
+ $sequence_3 = { 8bec 53 56 33f6 39770c 7e24 33db }
+ $sequence_4 = { 8b5108 8b45f4 03d3 52 53 50 6a03 }
+ $sequence_5 = { 50 e8???????? 8b0e 8d55d4 68ffffff7f 52 894de8 }
+ $sequence_6 = { 8b5610 0bf8 8b4508 52 50 e8???????? 8b4e18 }
+ $sequence_7 = { 50 51 e8???????? 8bd8 83c408 85db 0f841b010000 }
+ $sequence_8 = { e8???????? 53 e8???????? 53 57 e8???????? 83c42c }
+ $sequence_9 = { dfe0 ddd9 f6c441 0f8572010000 dd05???????? d8d1 dfe0 }
condition:
- 7 of them and filesize <724992
+ 7 of them and filesize <1187840
}
-rule MALPEDIA_Win_Doppeldridex_Auto : FILE
+rule MALPEDIA_Win_Rekoobew_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0bf161f5-a608-54fc-8493-d0ca4c837703"
+ id = "73ccfc35-4eed-5955-a644-c948264eda18"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doppeldridex"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doppeldridex_auto.yar#L1-L158"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rekoobew"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rekoobew_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "fb6ff8ebf9c5a6a0d85322be3122e60be6bc024bdfc953709614ec984b12824b"
+ logic_hash = "445ddabcfd3896aee22b87d60b9d2106a9693bf00a56789028f0bf36c80e8900"
score = 75
quality = 75
tags = "FILE"
@@ -148441,38 +155397,32 @@ rule MALPEDIA_Win_Doppeldridex_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 01501c 015020 015024 01500c }
- $sequence_1 = { 33d2 3b7c2414 0f4cd3 032c24 03ee 2bea 8bc5 }
- $sequence_2 = { 011483 40 3b06 7cf8 }
- $sequence_3 = { 010c28 8b4e04 42 8d41f8 d1e8 }
- $sequence_4 = { 017c240c 3b5c2408 0f822affffff ff74240c }
- $sequence_5 = { 030c24 0fbe01 88442458 85c0 }
- $sequence_6 = { 01500c 833920 751c 8bc1 }
- $sequence_7 = { 0306 894218 47 3b7c2408 }
- $sequence_8 = { 7508 8b45f8 83c40c 5d c3 }
- $sequence_9 = { 8b459c 83c474 5e 5f 5b }
- $sequence_10 = { 5e 5f 5d c3 8b45e4 8b4dec 8a1401 }
- $sequence_11 = { 8945e0 74c2 eb9b 8b45f0 353857544f }
- $sequence_12 = { 0fb7c7 89442408 894c240c 8b45ac }
- $sequence_13 = { 8b4da0 83f900 898570ffffff 0f840c010000 e9???????? }
- $sequence_14 = { 7452 eb22 668b45c6 66c1e801 0fb7c8 }
- $sequence_15 = { 8b5dbc 891c24 89442404 0fb7c7 }
+ $sequence_0 = { 337dec 337dd0 d1c7 897db8 8d8c39dcbc1b8f 894df0 89c1 }
+ $sequence_1 = { 89e5 57 56 53 81ecbc000000 e8???????? 8945e0 }
+ $sequence_2 = { 89df 0fb63482 c1e618 0fb65c8201 }
+ $sequence_3 = { 8b1c9de0944000 c1e310 31df 8b4dd8 0fb6dd 8b1c9de0944000 c1e308 }
+ $sequence_4 = { 7409 3b7510 0f8fd3000000 0fb645e8 c1e004 89c7 b8ffffffff }
+ $sequence_5 = { c744240808000000 89742404 891c24 e8???????? c744240804000000 897c2404 891c24 }
+ $sequence_6 = { 8b3c95e07c4000 33bb54010000 8b55f0 c1ea18 333c95e0704000 89f2 c1ea10 }
+ $sequence_7 = { 56 53 83ec5c 8b450c 0fb65003 0fb638 }
+ $sequence_8 = { 89f1 31d1 31d9 8d0c0f 89c7 c1c705 01f9 }
+ $sequence_9 = { 895008 8b500c 89d6 c1ee18 8b3cb5e0944000 89d6 }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <248832
}
-rule MALPEDIA_Win_Sendsafe_Auto : FILE
+rule MALPEDIA_Win_Rhysida_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cb217c22-cbf0-508f-ac96-405f94d46039"
+ id = "64a6dc82-3050-56af-987a-eca5c9c0ccdc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sendsafe"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sendsafe_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rhysida"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rhysida_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "e90570bf37f8e67b125b5c0e63f782c1ecedcd1e6ef21243ea37efff8deeb91b"
+ logic_hash = "c700e285aaa62eb845c4c4a22ba3b4990a79a21d47e9845ba892bd45fa758d74"
score = 75
quality = 75
tags = "FILE"
@@ -148481,37 +155431,37 @@ rule MALPEDIA_Win_Sendsafe_Auto : FILE
signator_config = "callsandjumps;datarefs;binvalue"
malpedia_rule_date = "20231130"
malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { ff36 f30f6f442438 8d442428 50 660fefc8 50 8b4608 }
- $sequence_1 = { f20f5e15???????? f20f59ca f20f58c1 f20f2cc8 894dd4 8b550c 83ba381c000000 }
- $sequence_2 = { e8???????? 8b8510feffff e9???????? 6800010000 8b9588feffff 52 e8???????? }
- $sequence_3 = { c1e000 8b4dfc 0fbe1401 85d2 7409 8b45f8 83c001 }
- $sequence_4 = { e8???????? 83c40c 8983b0010000 85c0 750a 6815060000 e9???????? }
- $sequence_5 = { e8???????? 83c414 85c0 0f84e1010000 ff7518 8d4704 57 }
- $sequence_6 = { eb07 c745fc00000000 8b5508 8b4204 3b45fc 7404 33c0 }
- $sequence_7 = { 8b783c 037904 8b8610010000 8bef c1f808 896c2414 8807 }
- $sequence_8 = { 8b4620 83c408 314500 8b4624 314504 8b4628 314648 }
- $sequence_9 = { eb06 8b55f4 8955f0 b801000000 6bc800 8b55f0 0fbe040a }
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { ba28000000 4889c1 e8???????? 8945f8 837df800 7407 b804000000 }
+ $sequence_1 = { 4863d0 488b4510 4801d0 0fb600 0fb6c0 8b55f4 c1ea06 }
+ $sequence_2 = { f6431920 0f84c7feffff 4983c101 e9???????? 4531c0 4889f2 89e9 }
+ $sequence_3 = { 8b45fc 4863c8 4889c8 48c1e002 4801c8 48c1e003 4889c1 }
+ $sequence_4 = { baafa96e5e 89c8 f7ea c1fa0b 89c8 c1f81f 29c2 }
+ $sequence_5 = { 8b45f8 4863d0 488b4510 4801d0 0fb600 0fb6d0 8b45f8 }
+ $sequence_6 = { e8???????? eb01 90 8b45f0 0faf45b8 89c2 488d45a0 }
+ $sequence_7 = { 85c0 74da 85db 4889742428 0f848d010000 8d4bff 488d742460 }
+ $sequence_8 = { c1e903 f348ab ff15???????? 83f812 7472 488b8b38020000 e8???????? }
+ $sequence_9 = { 5f 5d 415c 415d c3 b80d000000 ebd7 }
condition:
- 7 of them and filesize <3743744
+ 7 of them and filesize <2369536
}
-rule MALPEDIA_Win_Mydoom_Auto : FILE
+rule MALPEDIA_Win_Systembc_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fbb873d9-471c-5df6-b7cb-17b11908448b"
+ id = "33299700-4e02-5584-bb63-8a8197d8417b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mydoom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mydoom_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.systembc"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.systembc_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "29814c8a4a60df1d6a473af327bca4071707640dfe79f325f53607e3865352f9"
+ logic_hash = "29f113c1b3510221b57bbc147c9c5017608a490a95fbc04ce80eea2621980153"
score = 75
quality = 75
tags = "FILE"
@@ -148525,32 +155475,32 @@ rule MALPEDIA_Win_Mydoom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f94c2 83f842 0f94c0 09d0 ba00000000 a801 0f8531010000 }
- $sequence_1 = { 49 c744241000000000 8d85c4fdffff 8944240c 894c2408 }
- $sequence_2 = { 891c24 e8???????? 85c0 743c 8b85d8feffff 89442404 891c24 }
- $sequence_3 = { 891c24 e8???????? 83ec04 c744240402000000 }
- $sequence_4 = { 85c0 89c3 7413 89f6 8dbc2700000000 ff149df8354200 }
- $sequence_5 = { 8d9dc8f9ffff 891c24 e8???????? 8d8568f9ffff 89442424 89742420 }
- $sequence_6 = { 83ec58 895df4 8975f8 897dfc 8b7510 0fb74514 668945e6 }
- $sequence_7 = { 89e5 56 53 83ec10 8b750c 83fe01 }
- $sequence_8 = { 890424 e8???????? e8???????? 8db406fc2f0000 0fb745e6 }
- $sequence_9 = { 85d0 7547 85f6 750c 8b0d???????? 85c9 7546 }
+ $sequence_0 = { 8b8e88010000 8b968c010000 8bb690010000 8945e4 895df4 }
+ $sequence_1 = { 52 6a00 6a00 6a00 ffb568f9ffff }
+ $sequence_2 = { 668b9554f9ffff 6a00 6a00 6a03 6a00 6a00 }
+ $sequence_3 = { 898568f9ffff c7856cf9ffff00040000 8d853cf9ffff 50 6a00 6a00 }
+ $sequence_4 = { 81c200008000 81c200100000 81c200200000 6a00 52 }
+ $sequence_5 = { 8d851cf4ffff 50 6800010000 57 ffb530f4ffff }
+ $sequence_6 = { 50 e8???????? ffd0 8b85f4feffff }
+ $sequence_7 = { 43 3b5dfc 7296 33c0 5e 5f }
+ $sequence_8 = { 668b9554f9ffff 6a00 6a00 6a03 6a00 }
+ $sequence_9 = { 57 56 8b7d10 33c0 }
condition:
- 7 of them and filesize <114688
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Ayegent_Auto : FILE
+rule MALPEDIA_Win_Pandora_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "38c6d34b-791e-51ab-b755-5bf91f226c75"
+ id = "808a3fc1-f716-514d-83e0-324ab4b5c047"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ayegent"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ayegent_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pandora"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pandora_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "7245e65e015426e49adecdb4c2a9413e067a055fe3d65973ee2cacb00da6dd3e"
+ logic_hash = "9af9b8ff0c31cb495b736863fe90279cd9d4c249691d7818a687e6d77e1bb76b"
score = 75
quality = 75
tags = "FILE"
@@ -148564,34 +155514,34 @@ rule MALPEDIA_Win_Ayegent_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 80a0609d400000 40 41 41 3bc6 }
- $sequence_1 = { 8d442448 53 50 68???????? 53 }
- $sequence_2 = { 68???????? ffd6 8bf8 33f6 3bfb 897c241c 0f8cf9000000 }
- $sequence_3 = { ff15???????? 8b4c2428 8b542424 51 8b4c2424 52 }
- $sequence_4 = { 8d542440 51 52 ff15???????? 85c0 0f8415030000 8b3d???????? }
- $sequence_5 = { 52 50 ffd6 6a00 8d8c2414010000 }
- $sequence_6 = { 83c408 aa 8d842450040000 6804010000 }
- $sequence_7 = { 55 56 8bb42438050000 33db }
- $sequence_8 = { 72f1 56 8bf1 c1e603 3b9668774000 0f851c010000 }
- $sequence_9 = { 53 51 68???????? ffd6 85c0 }
+ $sequence_0 = { 48ffcb 48899d60020000 48ffc6 c60300 4c8bc6 488d8d60020000 }
+ $sequence_1 = { 458bce 41c1c90b 4433c9 44895d40 418bce 458bc3 c1c906 }
+ $sequence_2 = { 4885c0 750a b880eeffff e9???????? 4d8bcf 48896c2420 4c8d442430 }
+ $sequence_3 = { 488d1d43ef0200 4885c0 7404 488d5820 8bcf e8???????? 8903 }
+ $sequence_4 = { 4c8d7c2430 4c2bff 4c8dab80010000 0f1f4000 0f1f840000000000 488bd5 498d4d0f }
+ $sequence_5 = { 418bf8 488bea 488bf1 4d85c9 7423 498b4128 }
+ $sequence_6 = { 4533b48db0050700 418bcb 44337014 c1e908 0fb6d1 8bcb }
+ $sequence_7 = { 452bf8 c1ed08 452be0 8d4147 41c1ef08 41c1ec08 458d48e6 }
+ $sequence_8 = { 4403d1 418bc9 4181c139a093fc 41c1c20a 4403d2 f7d1 410bca }
+ $sequence_9 = { 79da 85db 0f8538020000 4c8d45cf 498bd7 488d4db7 e8???????? }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <1032192
}
-rule MALPEDIA_Win_Teleport_Auto : FILE
+rule MALPEDIA_Win_Ghostemperor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "20d896b0-1f61-5a48-80a3-7c8e4c6de03e"
+ id = "22543585-64e5-59d9-a95f-0fb017ff004e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.teleport"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.teleport_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ghostemperor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ghostemperor_auto.yar#L1-L228"
license_url = "N/A"
- logic_hash = "a391399ac3b60b63dbd3a4a77f0c3e70c536a7803fbc2f2dce00674fad1b8479"
+ logic_hash = "91e3702f968d398f5f44f42cafec6cc32480eb0e4729b0b5f30643c45ff1a402"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -148603,32 +155553,45 @@ rule MALPEDIA_Win_Teleport_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 8945fc 68???????? c745f001000000 }
- $sequence_1 = { 57 8bfa 897de8 89b7a0000000 8b4104 8987a4000000 8b5108 }
- $sequence_2 = { 8806 46 89b504ffffff 8b8d04ffffff 0fb6f0 8d85f8feffff 56 }
- $sequence_3 = { c685effeffff00 50 6a00 6a00 c785e0feffff14000000 c785e4feffff00000000 c785f0feffff01000000 }
- $sequence_4 = { 8d8d80f7ffff 899d68f7ffff e8???????? 83cb08 f6c304 740e }
- $sequence_5 = { 8b35???????? 6a28 85f6 7451 c78560f7ffff80b54200 e8???????? 898584f7ffff }
- $sequence_6 = { 668945a8 eb17 837e3408 8d4620 c7401000000000 7202 8b00 }
- $sequence_7 = { 330c8560c24200 0fb6c2 330c8560b64200 8bc3 c1e810 894de0 898f94000000 }
- $sequence_8 = { 1bc0 83c801 85c0 0f8400010000 b8???????? 8d8d60fdffff 6690 }
- $sequence_9 = { 894110 7208 8b09 898d74ffffff 8d0436 50 }
+ $sequence_0 = { b801000000 4883c428 5b 5d 5f 5e }
+ $sequence_1 = { 31d2 41b801000000 4531c9 ff15???????? }
+ $sequence_2 = { 41c1ea03 4183e007 4585d2 0f84b9000000 }
+ $sequence_3 = { 8b5b10 4885db 7431 c7471800000000 89d9 }
+ $sequence_4 = { e8???????? 48c7470800000000 c7471000000000 4c8d7e18 4c89f9 ff15???????? 448b4648 }
+ $sequence_5 = { 4885c9 740d e8???????? 48c7460800000000 }
+ $sequence_6 = { 4989c9 4889d0 458d5aff 41f6c203 7427 4489d1 83e103 }
+ $sequence_7 = { 4883c410 c3 ff25???????? ff25???????? ff25???????? ff25???????? ff25???????? }
+ $sequence_8 = { 4889c1 4863c6 488d0440 48c1e004 4801c8 eb02 31c0 }
+ $sequence_9 = { 31f6 31d2 660f1f440000 488b3cf0 49313cf1 }
+ $sequence_10 = { c74424504900df00 c744245436004d00 c74424586b007100 c744245cf5003400 }
+ $sequence_11 = { 0f8883020000 33d2 c78594000000f1008500 c78598000000a8003f00 448d630e c7859c000000f7003100 }
+ $sequence_12 = { 01c1 89ca c1ea1f c1f904 }
+ $sequence_13 = { 488d4dd0 48895dd8 895de0 4c8bea e8???????? be08020000 8bce }
+ $sequence_14 = { 00c2 488b8568020000 8854080c 488b85b0020000 }
+ $sequence_15 = { 00c1 488b8568020000 488b95b0020000 884c100c 488b85b0020000 488b85b0020000 488b85b0020000 }
+ $sequence_16 = { 85c0 7417 418bce 448bc7 48034e08 488bd5 e8???????? }
+ $sequence_17 = { 7212 4d8b5a10 4d85db 7409 48895c2448 5b }
+ $sequence_18 = { 01c3 69cbe8030000 81c130750000 4883ec20 }
+ $sequence_19 = { 01d1 89ca c1e205 89cb }
+ $sequence_20 = { 7449 8b5c2448 488bc7 d1eb ffcb }
+ $sequence_21 = { 48895c2408 57 4883ec20 488d0557540000 488bd9 488901 }
+ $sequence_22 = { c3 83c8ff ebf5 b801000000 ebee }
condition:
- 7 of them and filesize <458752
+ 7 of them and filesize <1115136
}
-rule MALPEDIA_Win_Erbium_Stealer_Auto : FILE
+rule MALPEDIA_Win_Photoloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "db565cb3-5b9a-5302-b069-7b70d89c0685"
+ id = "317a851b-1405-50a0-9b40-ce8155fbfa48"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.erbium_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.erbium_stealer_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.photoloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.photoloader_auto.yar#L1-L159"
license_url = "N/A"
- logic_hash = "a012e65d267d16fa63c21194de269ccb3721cbb6b9dd72f9bc3dc93b5920b64d"
+ logic_hash = "c73e7831cd0e2d402a5233934c3321f9665203a6373de35d59f2fa5b935ee161"
score = 75
quality = 75
tags = "FILE"
@@ -148642,32 +155605,38 @@ rule MALPEDIA_Win_Erbium_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b55f4 52 ff15???????? 898578ffffff 8b450c 0fb708 }
- $sequence_1 = { e9???????? b808000000 6bc809 8b55f4 837c0a6400 7448 b808000000 }
- $sequence_2 = { 6a04 ff7508 8d4df8 ff75e4 ff75e0 6a00 }
- $sequence_3 = { 8d8424a0000000 7409 83c002 66833800 }
- $sequence_4 = { 6a00 6800100000 68???????? 8b45e8 }
- $sequence_5 = { ff15???????? eb08 33c0 eb04 8b442414 33ff 33db }
- $sequence_6 = { 8b11 81e200000080 741a 8b45f0 8b08 81e1ffff0000 }
- $sequence_7 = { 8955f8 b808000000 6bc805 8b55f4 }
- $sequence_8 = { 897dfc 3bf8 7455 0fb74f2c }
- $sequence_9 = { 83c102 51 8b55d0 52 ff55cc 8b4de8 8901 }
+ $sequence_0 = { 0d00000005 e9???????? 8bd7 397b1c 7640 }
+ $sequence_1 = { 8bf7 8d6f10 ff15???????? 0f31 }
+ $sequence_2 = { c0c003 0fb6c8 8bc1 83e10f }
+ $sequence_3 = { 33c9 b801000000 0fa2 89442420 895c2424 }
+ $sequence_4 = { 33c9 b800000040 0fa2 895f0c }
+ $sequence_5 = { 0fa2 894704 33c9 b800000040 }
+ $sequence_6 = { 895c2424 894c2428 8954242c 0f31 }
+ $sequence_7 = { f7411400000020 7407 8b41f8 3901 7714 }
+ $sequence_8 = { 85d2 7417 448bc2 0f31 48c1e220 480bc2 8801 }
+ $sequence_9 = { 1bc0 23442410 3b03 7418 }
+ $sequence_10 = { 8903 8d44242c 50 6804010000 ff15???????? ff35???????? 8d4c2430 }
+ $sequence_11 = { 5d c3 8b4d08 8b45fc 8901 8b450c }
+ $sequence_12 = { c3 55 8bec 81ec18020000 53 8ad9 }
+ $sequence_13 = { 8b5604 8d44240c 8b0e 55 }
+ $sequence_14 = { 51 8d855cffffff 8bf2 68???????? }
+ $sequence_15 = { 56 33c0 8d6c240c 57 }
condition:
- 7 of them and filesize <33792
+ 7 of them and filesize <107520
}
-rule MALPEDIA_Win_Puzzlemaker_Auto : FILE
+rule MALPEDIA_Win_Unidentified_037_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e93d66ca-a521-530d-a49f-9104b54671e2"
+ id = "9e4cd69e-744d-5d0c-b193-3d15e535bfdb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.puzzlemaker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.puzzlemaker_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_037"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_037_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "f4b400ba752d2bb5a757bcaa926474306cca33660eefc885e89a26d2aeb5ebe7"
+ logic_hash = "ab9d444ded76b509036904b157e446e552ae52ed50151a488fb9c47db68bb4eb"
score = 75
quality = 75
tags = "FILE"
@@ -148681,32 +155650,32 @@ rule MALPEDIA_Win_Puzzlemaker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 48890b 488d5308 488d4808 0f1102 e8???????? 488d053c0e0100 488903 }
- $sequence_1 = { f20f5cca f2410f590cc1 660f28d1 660f28c1 4c8d0dbb980000 f20f101d???????? }
- $sequence_2 = { 0fb705???????? 66d1e8 6683e07f f30f6f05???????? }
- $sequence_3 = { e8???????? 488bd8 488945a7 4885c0 7432 }
- $sequence_4 = { 48895db7 4885db 0f84ca000000 4c896c2428 4c896c2420 4c8d4d07 4533c0 }
- $sequence_5 = { 4489542444 81fae9fd0000 0f857e010000 4c8d3deddafeff }
- $sequence_6 = { 488910 48895008 c3 4883ec28 4885c9 7411 488d0590e30100 }
- $sequence_7 = { c705????????090400c0 c705????????01000000 c705????????01000000 b808000000 486bc000 488d0da6f80100 8b542430 }
- $sequence_8 = { 48898520050000 488b05???????? 488d154a1b0200 488b0d???????? 4533ed 488985f8010000 }
- $sequence_9 = { 488d0db4270100 e8???????? 85c0 740e ba01000000 488bcd ff15???????? }
+ $sequence_0 = { 85c0 a3???????? 740c 8b4c2408 8b542404 51 52 }
+ $sequence_1 = { 33c0 33d2 33ff 8a0c1f 80f920 7405 80f930 }
+ $sequence_2 = { 7506 8b15???????? 8d8424b8040000 52 50 ff15???????? }
+ $sequence_3 = { 8a56ff 83e23f 41 4d 8a82d00c0110 8841ff 759c }
+ $sequence_4 = { 8b4d20 8b5500 8b4504 8bb424f0040000 51 52 50 }
+ $sequence_5 = { ff15???????? 84c0 742d 8b4608 8b5604 8d8dccfcffff }
+ $sequence_6 = { 8841ff 759c 5d eb04 8b742410 85ff 7667 }
+ $sequence_7 = { 743e 80f920 7439 80f930 7c0d 80f937 7f08 }
+ $sequence_8 = { 8b5c2408 8b4314 83f8ff 0f84b1000000 c1e005 8bd0 a1???????? }
+ $sequence_9 = { 5e 8b8c241c100000 64890d00000000 81c428100000 c3 83c1fe }
condition:
- 7 of them and filesize <331776
+ 7 of them and filesize <167936
}
-rule MALPEDIA_Win_Tinytyphon_Auto : FILE
+rule MALPEDIA_Win_Acridrain_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7815c923-a900-5d01-9a5b-05c1d0e30118"
+ id = "82271a88-0572-5daa-a06b-4b68b32ae23f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinytyphon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tinytyphon_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acridrain"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.acridrain_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "e057b3aaf1408e310c88894f8b7bb86876f0ba7268b4daf2dcf5c0bb823f13c5"
+ logic_hash = "2ef6b9a2838948e7218bd1e79fe0257da485657bd990a4bc6b62c314342a8e67"
score = 75
quality = 75
tags = "FILE"
@@ -148720,32 +155689,32 @@ rule MALPEDIA_Win_Tinytyphon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c745b430144000 c745b834144000 c745bc38144000 c745c03c144000 c745c440144000 }
- $sequence_1 = { 50 8b0d???????? 51 e8???????? 83c420 8b955cffffff 52 }
- $sequence_2 = { 68???????? 8d85e8feffff 50 ff15???????? 8d8dccfdffff 51 }
- $sequence_3 = { 034df4 034df0 894dd4 8b5508 }
- $sequence_4 = { 034df8 0fbe11 85d2 0f84fe010000 8b4508 0345f8 }
- $sequence_5 = { 0345c0 8a08 880a ebdf 8d55d8 52 }
- $sequence_6 = { eba9 68a01f0000 ff15???????? 6a0f 8d8df0feffff 51 }
- $sequence_7 = { 034a58 8b45f8 8d8c0878a46ad7 894df8 8b55f8 c1e207 8b45f8 }
- $sequence_8 = { 83bde4feffffff 750a c785e4feffff00000000 83bde4feffff00 7505 }
- $sequence_9 = { 52 8d85f0feffff 50 8d8dd0fdffff }
+ $sequence_0 = { eb03 8b4dd0 8b45e0 8b55cc 8945cc 8a45f0 8955e0 }
+ $sequence_1 = { ff76a4 53 e8???????? 83c428 8945dc e9???????? 6a00 }
+ $sequence_2 = { ffd0 8b75f0 8bc8 83c414 85c9 0f85c5000000 0fce }
+ $sequence_3 = { eb0c 8b4d9c 83c104 894d9c 8b41fc 8945a0 8bc8 }
+ $sequence_4 = { eb5d 8b03 8b8890860000 803900 7520 8d442414 6801040000 }
+ $sequence_5 = { 8b8520ffffff 33ff 8b10 85d2 0f8ea6000000 33c9 898d50ffffff }
+ $sequence_6 = { f6459c01 0f84ae0b0000 8bc6 83e007 3bf0 0f83d50a0000 e9???????? }
+ $sequence_7 = { 8b4748 56 ffd0 8b7584 83c410 8bbd78ffffff eb09 }
+ $sequence_8 = { ffb5d0fdffff e8???????? 83c408 8985d4fdffff 85c0 0f85844b0000 ffb5d0fdffff }
+ $sequence_9 = { e9???????? 83fe02 750c c7872005000003000000 eb7b c7872005000000000000 83fe03 }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <2244608
}
-rule MALPEDIA_Win_Postnaptea_Auto : FILE
+rule MALPEDIA_Win_Eyservice_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "66a4e77d-c854-5ed3-94ad-0ea65d80b627"
+ id = "e6b201c5-31f5-59a2-a52d-309e470fcb5a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.postnaptea"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.postnaptea_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.eyservice"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.eyservice_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "8a33afe097a88ce8212670a3e80b58d6a5513693490a76a85e445ee8529ba924"
+ logic_hash = "a8d5ae517d0720536deb96b397532bb33ed4fe4db40da33e37b572e015c805c7"
score = 75
quality = 75
tags = "FILE"
@@ -148759,32 +155728,32 @@ rule MALPEDIA_Win_Postnaptea_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c744247418f561f5 c744247867f50000 4863c2 488d4c2450 488d0c41 0fb7c2 662bc3 }
- $sequence_1 = { ffc2 83fa1a 72e3 6644896c2474 488d442440 488bd3 0f1f440000 }
- $sequence_2 = { ffd7 85c0 0f842c010000 4c8d052d4b0600 ba04010000 498bce e8???????? }
- $sequence_3 = { e9???????? 418b8520280000 4d8bce 48634c2440 4c8bc6 2bc1 48034c2460 }
- $sequence_4 = { c745c000f50cf5 c745c407f528f5 c745c80cf508f5 c745cc02f53cf5 c745d006f50bf5 c745d419f50bf5 c745d81bf54ef5 }
- $sequence_5 = { ff15???????? 4533e4 4d85f6 0f8418100000 498bce e9???????? 448b85b0000000 }
- $sequence_6 = { c7851001000031f56df5 c785140100006df54ef5 c7851801000005f50ef5 c7851c0100000ff50000 418bd4 0f1f440000 4863c2 }
- $sequence_7 = { c78520020000a081b081 c78524020000a281ba81 c78528020000fa81b181 c7852c020000ba81bb81 33c0 66898530020000 418bd5 }
- $sequence_8 = { 488b05???????? 4885c0 7515 488d55b0 b9bd59e821 e8???????? 488905???????? }
- $sequence_9 = { ffd7 c7856007000079f57af5 c785640700007bf515f5 c785680700000df528f5 c7856c0700006bf540f5 c7857007000020f506f5 c7857407000007f516f5 }
+ $sequence_0 = { c1f802 3bf0 72da eb22 8b0d???????? 2b0d???????? c1f902 }
+ $sequence_1 = { 6a01 6a01 68???????? ffd6 83c410 8d542410 52 }
+ $sequence_2 = { 83bef800000000 747c 8d4c2408 e8???????? a1???????? 8d4c2408 51 }
+ $sequence_3 = { 6808020000 8d8e34020000 51 e8???????? 85c0 7c1e }
+ $sequence_4 = { 83c404 8bc8 e8???????? 8bf0 8bce e8???????? 8b4f10 }
+ $sequence_5 = { e8???????? b901000000 66894f08 5f 5e 5d 8d410d }
+ $sequence_6 = { 68???????? 8d542418 52 ff15???????? 85c0 754f 88442414 }
+ $sequence_7 = { 50 03f7 56 e8???????? 8b4c2420 83c410 5f }
+ $sequence_8 = { a3???????? e8???????? 6a06 68???????? 56 a3???????? }
+ $sequence_9 = { 85c0 7459 66837d005c 7452 66837c24145c 754a }
condition:
- 7 of them and filesize <2457600
+ 7 of them and filesize <452608
}
-rule MALPEDIA_Win_Bka_Trojaner_Auto : FILE
+rule MALPEDIA_Win_Pwnpos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a0a20d3c-b939-5a5e-b947-ecd1e3a9e77c"
+ id = "abbe2d0a-a645-5f32-9b7c-0253f67ad1b4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bka_trojaner"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bka_trojaner_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pwnpos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pwnpos_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "b96818656a5fc18803f0bf1dba8c00052206b33d8bd6ff1c085aa051852c2a47"
+ logic_hash = "7bd328aa33dd14635d4dbb434ca27c66253964455bceaea97af6eb90a2de7f21"
score = 75
quality = 75
tags = "FILE"
@@ -148798,32 +155767,32 @@ rule MALPEDIA_Win_Bka_Trojaner_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 2bc1 33ff 89442428 397c2420 894c2438 897c242c }
- $sequence_1 = { 8b542414 68ff030000 8d8c2468040000 03da 8b54241c 51 }
- $sequence_2 = { 50 57 e8???????? 85c0 75c6 5d }
- $sequence_3 = { 56 ff5124 85c0 7517 8b44247c 5f }
- $sequence_4 = { 85c0 7439 53 8b1d???????? 55 8b2d???????? 8bff }
- $sequence_5 = { 8b54240c 8b4c2404 8b8170ffffff 52 8b54240c 81c170ffffff 52 }
- $sequence_6 = { 6a10 68???????? 68???????? 52 ff15???????? 83c8ff }
- $sequence_7 = { e8???????? 59 59 8945c4 a1???????? }
- $sequence_8 = { c7440a04???????? 8b4104 8b4004 8d9078ffffff 891408 8b4104 }
- $sequence_9 = { 752d 837df800 7424 ff7508 8d4608 e8???????? ff7508 }
+ $sequence_0 = { 8d8dbcf9ffff 3985b4f9ffff 8b85a0f9ffff 7306 8d85a0f9ffff 51 50 }
+ $sequence_1 = { 391d???????? 0f84a4000000 8d75d4 e8???????? 68???????? 50 c645fc01 }
+ $sequence_2 = { 51 c745fc00000000 ffd3 85c0 7507 e8???????? eb0c }
+ $sequence_3 = { 6800400000 8d8c2494000000 51 ff15???????? 85c0 7526 8b8c2498400000 }
+ $sequence_4 = { 762a 56 e8???????? 8d0445fc6c4400 8bc8 }
+ $sequence_5 = { 89564c 895e44 6a08 b9???????? }
+ $sequence_6 = { eb14 807a2100 740a 3935???????? 7302 8bd1 }
+ $sequence_7 = { 3d00010000 752d 837c241c00 7626 }
+ $sequence_8 = { e9???????? 8d9580f9ffff 52 b801000000 898d84f9ffff 898d88f9ffff 6a02 }
+ $sequence_9 = { 8bd1 8b09 eb03 8b4908 80792100 74e6 5f }
condition:
- 7 of them and filesize <221184
+ 7 of them and filesize <638976
}
-rule MALPEDIA_Win_Mystic_Stealer_Auto : FILE
+rule MALPEDIA_Win_Ufrstealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "677c1a33-ba88-5fd2-bb60-e482ebad5ee5"
+ id = "87df7a80-59b4-5e49-9e5c-787423bd5a1a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mystic_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mystic_stealer_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ufrstealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ufrstealer_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "7ef3f130d7f708fe480ce6294f73f2aa94b8d0f4c6423ffb91a1e80eb925cec4"
+ logic_hash = "bbd8353728980ed7d41eeaaf6b45527dc201d1c8bc1c51c590cb1fee36b76ae8"
score = 75
quality = 75
tags = "FILE"
@@ -148837,32 +155806,32 @@ rule MALPEDIA_Win_Mystic_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b461c 42 8b4e08 895614 8a4007 88040a 8b5614 }
- $sequence_1 = { 0fb7c7 eb0b 8d4203 8986bc160000 }
- $sequence_2 = { 6a02 5d 8b4774 3d06010000 }
- $sequence_3 = { 0fb7d8 668bc3 66d3e0 660bc6 0fb7c0 }
- $sequence_4 = { eb15 8d4503 8987bc160000 8d4304 }
- $sequence_5 = { 668b476c 66890451 85f6 741a 8b4f6c }
- $sequence_6 = { 668bc2 8d5f14 66d3e0 8b0b 660bc6 }
- $sequence_7 = { eb0c 8d5103 0fb7c0 8996bc160000 0fb7c8 }
- $sequence_8 = { 8a86b9160000 88040a b110 2a8ebc160000 8b86bc160000 ff4614 }
- $sequence_9 = { 02c2 03cb 0fb6c0 8a843800010000 }
+ $sequence_0 = { 6a01 6a00 6a00 68???????? 6a00 68???????? ff15???????? }
+ $sequence_1 = { 0bc0 7529 8b43fc 03d8 8b03 83c304 83f8ff }
+ $sequence_2 = { ffb5ecf3ffff ff15???????? 5b 5f 5e c9 }
+ $sequence_3 = { 894df4 8b75f4 83ee01 c745f008000000 0fb64eff 0fb616 83f97f }
+ $sequence_4 = { 03c1 80383a 7505 c60000 eb03 49 }
+ $sequence_5 = { ff35???????? ff15???????? 85c0 0f842debffff a3???????? 68???????? ff15???????? }
+ $sequence_6 = { 0f85c0000000 0fb60d???????? a1???????? 8808 8305????????01 894dfc bb???????? }
+ $sequence_7 = { 8d45dc 6a04 50 e8???????? 8305????????04 e8???????? }
+ $sequence_8 = { 50 68???????? 68???????? 6a00 ff15???????? 68???????? ff15???????? }
+ $sequence_9 = { c745d80e000000 33c0 8b75d8 8bc8 8db65c884200 }
condition:
- 7 of them and filesize <512000
+ 7 of them and filesize <770048
}
-rule MALPEDIA_Win_Coronavirus_Ransomware_Auto : FILE
+rule MALPEDIA_Win_Thunker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "855b633b-3844-51b6-884b-ae39212160b9"
+ id = "ef50f850-b9ad-5639-a44d-12383e7ab286"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.coronavirus_ransomware"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.coronavirus_ransomware_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thunker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.thunker_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "cdd2b8f03fb9e73cf8c1c825b178f3065340bed6f25c08a712318c114ae54239"
+ logic_hash = "9bc1b7f9eb35f46db81209055d59765c3ce32324a39fc618186d9d412df8d09c"
score = 75
quality = 75
tags = "FILE"
@@ -148876,32 +155845,32 @@ rule MALPEDIA_Win_Coronavirus_Ransomware_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d9b00000000 0fb708 66890c02 83c002 6685c9 75f1 8d8dec7effff }
- $sequence_1 = { 894dd8 837e0400 8b5608 c745dc00000000 8955e0 750a 8b45cc }
- $sequence_2 = { 50 ff15???????? 85c0 7420 b8???????? e8???????? 50 }
- $sequence_3 = { 68fe1f0000 52 8d859e9fffff 50 e8???????? 33c9 }
- $sequence_4 = { 83c002 50 52 68???????? 8d8500c0ffff }
- $sequence_5 = { 53 e8???????? 83c410 85ff 743b 8d4900 803c1fc3 }
- $sequence_6 = { ff15???????? 8b15???????? a1???????? 83c418 52 6a01 50 }
- $sequence_7 = { 8b55d0 880417 8b45c8 50 ff15???????? 56 ff15???????? }
- $sequence_8 = { ffd6 a3???????? eb0a 53 }
- $sequence_9 = { ff15???????? 85c0 7407 ffd0 a3???????? be???????? e8???????? }
+ $sequence_0 = { 89c7 50 68???????? 8dbd00feffff 57 e8???????? 83c420 }
+ $sequence_1 = { e8???????? 89c6 83feff 7420 }
+ $sequence_2 = { 8d8500feffff 50 56 e8???????? 89c7 83ffff }
+ $sequence_3 = { e8???????? 83c40c 89c7 e8???????? 8985ecfdffff }
+ $sequence_4 = { d1ea 8995e8fdffff 56 e8???????? 6a08 68???????? 68???????? }
+ $sequence_5 = { 68204e0000 68d3710000 50 e8???????? 6a00 68804f1200 68dd710000 }
+ $sequence_6 = { 83c40c 8d8544edffff 50 e8???????? 8985c4edffff 8b400c }
+ $sequence_7 = { 7433 7c79 3df1710000 7447 }
+ $sequence_8 = { 8d85f0edffff 50 57 e8???????? 83bdf0eeffff05 752e }
+ $sequence_9 = { e8???????? 68???????? e8???????? 83c41c 68???????? 68???????? e8???????? }
condition:
- 7 of them and filesize <235520
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Blackmatter_Auto : FILE
+rule MALPEDIA_Win_Erbium_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "08d983f8-89d3-5398-96f5-8f771b0988c8"
+ id = "db565cb3-5b9a-5302-b069-7b70d89c0685"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackmatter"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackmatter_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.erbium_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.erbium_stealer_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "67609ff5035d7d172ddf1a903ab845a6e5b4b36e758aab3cb262223fbb37577d"
+ logic_hash = "a012e65d267d16fa63c21194de269ccb3721cbb6b9dd72f9bc3dc93b5920b64d"
score = 75
quality = 75
tags = "FILE"
@@ -148915,32 +155884,32 @@ rule MALPEDIA_Win_Blackmatter_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 c745fc00000000 ff35???????? e8???????? 8bf8 }
- $sequence_1 = { ff75f8 ff15???????? 85c0 0f85e7000000 68???????? }
- $sequence_2 = { 83c4d8 53 56 57 c745fc00000000 c745f800000000 }
- $sequence_3 = { e8???????? 8945fc eb0c 83c702 ff4df8 837df800 }
- $sequence_4 = { e9???????? ff75c8 e8???????? 8945c4 }
- $sequence_5 = { ff15???????? 83c40c 8d047500000000 50 8d45da }
- $sequence_6 = { 85f6 0f842c010000 56 ff35???????? e8???????? ff35???????? e8???????? }
- $sequence_7 = { f7f1 92 3b4508 720b 3b450c }
- $sequence_8 = { 8945ec e8???????? e8???????? 803d????????00 7405 }
- $sequence_9 = { ff75f4 e8???????? 5e 5b 8be5 5d c3 }
+ $sequence_0 = { 8b55f4 52 ff15???????? 898578ffffff 8b450c 0fb708 }
+ $sequence_1 = { e9???????? b808000000 6bc809 8b55f4 837c0a6400 7448 b808000000 }
+ $sequence_2 = { 6a04 ff7508 8d4df8 ff75e4 ff75e0 6a00 }
+ $sequence_3 = { 8d8424a0000000 7409 83c002 66833800 }
+ $sequence_4 = { 6a00 6800100000 68???????? 8b45e8 }
+ $sequence_5 = { ff15???????? eb08 33c0 eb04 8b442414 33ff 33db }
+ $sequence_6 = { 8b11 81e200000080 741a 8b45f0 8b08 81e1ffff0000 }
+ $sequence_7 = { 8955f8 b808000000 6bc805 8b55f4 }
+ $sequence_8 = { 897dfc 3bf8 7455 0fb74f2c }
+ $sequence_9 = { 83c102 51 8b55d0 52 ff55cc 8b4de8 8901 }
condition:
- 7 of them and filesize <194560
+ 7 of them and filesize <33792
}
-rule MALPEDIA_Win_Sepsys_Auto : FILE
+rule MALPEDIA_Win_Nosu_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d155b3c0-24fe-546c-9cf6-d2f1eeec70b2"
+ id = "d0493836-076e-53ac-80d2-093749a42975"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sepsys"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sepsys_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nosu"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nosu_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "89f35a98ab7f5302d816a97393fda02a0779a3eb472a7bbe6cda60406ec5b6de"
+ logic_hash = "8ab8c6afe29bf167cf16b426bd8eca0dcd4e462cdef53cd757a920fd1f6ec318"
score = 75
quality = 75
tags = "FILE"
@@ -148954,32 +155923,32 @@ rule MALPEDIA_Win_Sepsys_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb00 c685b500000000 488b4df8 488b55e8 4c8b45f0 e8???????? 488955e0 }
- $sequence_1 = { eb13 488b442448 4839442450 7407 b837000000 eb0e 488d4c2460 }
- $sequence_2 = { e9???????? 0fb74b02 81f9e8030000 7338 41b801000000 6683f90a 723f }
- $sequence_3 = { c685b604000000 488d8da0000000 e8???????? ebd8 488b4508 488d4d20 48894da8 }
- $sequence_4 = { e8???????? 41b801000000 488d9424a0000000 488d8c24d8000000 e8???????? 488b442460 488b4008 }
- $sequence_5 = { e8???????? 4889442430 488b442430 4889442450 488b542450 488b4c2438 e8???????? }
- $sequence_6 = { 488b842400010000 4889842400020000 8b8c24c8010000 338c24f8010000 8b9424cc010000 339424fc010000 448b8424d0010000 }
- $sequence_7 = { e8???????? 488945b0 eb00 488b45b0 48898518010000 eb0b 488b45b8 }
- $sequence_8 = { d3e0 488b4c2430 89411c 4533c0 33d2 33c9 e8???????? }
- $sequence_9 = { e8???????? 488b4c2430 ff15???????? 33d2 488d8c2460010000 e8???????? 4889442430 }
+ $sequence_0 = { 50 8d4730 50 ff15???????? 03c0 8d5730 50 }
+ $sequence_1 = { 399628040000 7438 399648010000 7430 3996b8020000 7428 8b8e48060000 }
+ $sequence_2 = { 8bcf 8938 e8???????? 894500 85c0 }
+ $sequence_3 = { e8???????? 59 85c0 7444 8b7c2410 bd???????? 55 }
+ $sequence_4 = { 0f45cf 03ce 84c0 8b4508 51 ff742420 0f45d7 }
+ $sequence_5 = { 7462 803b22 0f85d4010000 8d470c 50 8d5708 8d4c2418 }
+ $sequence_6 = { 53 50 53 a5 8d942440080000 53 53 }
+ $sequence_7 = { 8b442434 59 c60004 8b442430 c640010e }
+ $sequence_8 = { 50 8d8e280a0000 e8???????? 59 8d442468 50 8d442424 }
+ $sequence_9 = { 8d96a8000000 8d4e48 e8???????? 59 59 84c0 742c }
condition:
- 7 of them and filesize <4538368
+ 7 of them and filesize <513024
}
-rule MALPEDIA_Win_Unidentified_098_Auto : FILE
+rule MALPEDIA_Win_Zxxz_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8f47cad5-b04b-526a-bf75-a80f46978296"
+ id = "47a6bdd7-280d-5812-824e-6730815c0329"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_098"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_098_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zxxz"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zxxz_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "5873ddf57107eab8629c385b87e703377b84a728d15aa8f227623b130059db6e"
+ logic_hash = "1197698292204c5d5bb6df77b7c0541f4794374692dc94417033752fb1a653dc"
score = 75
quality = 75
tags = "FILE"
@@ -148993,34 +155962,34 @@ rule MALPEDIA_Win_Unidentified_098_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c644247f00 e9???????? 41bdffffffff 4885db 7412 488b4310 483b4318 }
- $sequence_1 = { e9???????? 8d48bf 83f905 0f8716ffffff 83e837 c1e00c 89c6 }
- $sequence_2 = { 7eac 85c0 78a8 488b4318 31d2 4885c0 75ab }
- $sequence_3 = { f6c202 410f45c0 4883c102 01d2 668941fe 4939c9 75ce }
- $sequence_4 = { b801000000 4d85c0 7486 488b542450 4c89e1 e8???????? 85c0 }
- $sequence_5 = { ff15???????? 410fb61424 e9???????? 4c89f8 4829d8 4801c7 4d85ed }
- $sequence_6 = { 85d2 0f88d5000000 4c8d5904 4189d2 4c8d4910 83fa0f 7e33 }
- $sequence_7 = { 488d542440 4939d4 7411 4c89e1 8844242f e8???????? 0fb644242f }
- $sequence_8 = { 897c2450 41bd01000000 44894c2434 4889442458 e9???????? 488b03 4489442434 }
- $sequence_9 = { e9???????? 498b4610 493b4618 0f838d010000 0fb700 6683f8ff b900000000 }
+ $sequence_0 = { 40 84c9 75ef bf???????? e8???????? 84c0 }
+ $sequence_1 = { 8b4c244c 64890d00000000 59 5f 5e 5d 8b4c2434 }
+ $sequence_2 = { be04010000 51 89742424 6689842424010000 e8???????? }
+ $sequence_3 = { 84c9 75f9 2bc2 8bd0 33c0 33c9 }
+ $sequence_4 = { c3 81ecc4010000 a1???????? 33c4 898424bc010000 }
+ $sequence_5 = { 7424 8b1d???????? 8d54242c 57 }
+ $sequence_6 = { ff15???????? 85c0 7539 3805???????? }
+ $sequence_7 = { 7403 8811 41 40 803800 75f0 }
+ $sequence_8 = { 681c020000 68???????? ffd6 83c40c 68???????? }
+ $sequence_9 = { ff15???????? 8b3d???????? 8bf0 56 6a01 }
condition:
- 7 of them and filesize <3345408
+ 7 of them and filesize <4142080
}
-rule MALPEDIA_Win_Hancitor_Auto : FILE
+rule MALPEDIA_Win_Agent_Btz_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e94e88e2-da44-5855-8e98-8220d615aa1e"
+ id = "bbd1b361-56e8-5c44-8191-97b61949c3a6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hancitor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hancitor_auto.yar#L1-L234"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_btz"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.agent_btz_auto.yar#L1-L506"
license_url = "N/A"
- logic_hash = "3fe1f27a710b2ccfc55ec6a2163075344a7f89cf27a8c741d778d1b9ea2b6391"
+ logic_hash = "2cf1b97d42e6d02bf37e0a76317aec03ba7908a0448935a35dc2a10793f4265a"
score = 75
- quality = 73
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -149032,46 +156001,82 @@ rule MALPEDIA_Win_Hancitor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 6824040000 6a00 6a00 6a00 }
- $sequence_1 = { 6800010000 6a40 68???????? e8???????? }
- $sequence_2 = { 8bec a1???????? 85c0 740c ff7508 6a00 50 }
- $sequence_3 = { 8bec 8b4d08 6a00 6a01 51 }
- $sequence_4 = { 68???????? ff7508 c605????????00 ff15???????? }
- $sequence_5 = { a3???????? 85c0 7502 5d c3 ff7508 6a00 }
- $sequence_6 = { 8b4df4 51 8b55f8 52 8b4510 }
- $sequence_7 = { 8b4d08 0fbe11 83fa7d 750e }
- $sequence_8 = { 8bd8 83fbff 7509 6a00 57 }
- $sequence_9 = { 6a00 6a01 8b5508 52 ff55f4 33c0 8be5 }
- $sequence_10 = { 8b4df4 8b5104 83ea08 d1ea 8955d4 }
- $sequence_11 = { c60600 ff15???????? 8b3d???????? 85c0 740a }
- $sequence_12 = { 8b4dec 8b55f4 035128 8b4518 8910 eb02 }
- $sequence_13 = { 8945f8 8b4df8 894df4 6a00 6a01 }
- $sequence_14 = { 7411 8d85f4fdffff 50 8b4d08 51 }
- $sequence_15 = { 8b4d08 53 56 57 8b413c }
- $sequence_16 = { 8945cc 8365e400 c745bc0a000000 eb07 8b45bc }
- $sequence_17 = { c3 4b fd 008d4556f400 08640f08 ed fec3 }
- $sequence_18 = { a1???????? 8945b4 a1???????? 83c044 a3???????? 8b45b4 83e803 }
- $sequence_19 = { b9382baa99 c7458ce4f25701 ff15???????? 894da0 a1???????? }
- $sequence_20 = { 6a00 6a00 ff15???????? c745a064000000 }
- $sequence_21 = { c645f300 c645fc65 c645fd00 c745f8dc030000 8365b800 }
- $sequence_22 = { 8945dc e9???????? b9382baa99 c745f464000000 }
- $sequence_23 = { 0f8482000000 c645f301 0fb645f3 85c0 7476 a1???????? 83c044 }
+ $sequence_0 = { c74608ffffffff f644240801 7409 56 e8???????? 83c404 8bc6 }
+ $sequence_1 = { ffd6 8d54240c 52 ffd7 }
+ $sequence_2 = { ffd3 85c0 75d8 5f 5e 5b }
+ $sequence_3 = { ff15???????? b800000f00 8b4df4 64890d00000000 }
+ $sequence_4 = { c706???????? c7460c00000000 895e08 895e04 }
+ $sequence_5 = { b805000f00 8b4df4 64890d00000000 5f 5e }
+ $sequence_6 = { 895e08 895e04 c7461000000000 895e14 }
+ $sequence_7 = { 56 6a00 68???????? 8935???????? }
+ $sequence_8 = { 8b4608 c706???????? 85c0 7413 }
+ $sequence_9 = { 83f8ff 740e 50 ff15???????? c74608ffffffff f644240801 }
+ $sequence_10 = { 8d542408 52 c744240c30000000 c744241003000000 }
+ $sequence_11 = { 6801010000 ff15???????? 85c0 7415 }
+ $sequence_12 = { 51 6a00 6819000200 6a00 68???????? }
+ $sequence_13 = { 6a0a 68???????? 6a01 6a00 }
+ $sequence_14 = { 50 68???????? 6a01 68???????? e8???????? 83c410 }
+ $sequence_15 = { 6a01 6a04 6a01 68???????? }
+ $sequence_16 = { 68???????? 6a01 e8???????? 50 e8???????? 83c41c }
+ $sequence_17 = { 89461c 3dea000000 740b 3de5030000 }
+ $sequence_18 = { 7511 e8???????? 83c020 50 e8???????? }
+ $sequence_19 = { 6a01 68???????? e8???????? 83c414 5f 5e }
+ $sequence_20 = { 50 e8???????? 83c408 6800010000 e8???????? }
+ $sequence_21 = { 0fb605???????? 66890d???????? 0fb60d???????? 660fafca 6603c8 }
+ $sequence_22 = { 59 6a69 66894de8 59 }
+ $sequence_23 = { 5e 8bc3 5b c9 c3 83c8ff eb11 }
+ $sequence_24 = { c684248d00000065 c684248e00000050 c684248f00000072 c68424900000006f c684249100000063 c684249200000065 }
+ $sequence_25 = { c68424900000006f c684249100000063 c684249200000065 c684249300000073 c684249400000073 c684249500000057 c684249600000000 }
+ $sequence_26 = { c684248800000043 c684248900000072 c684248a00000065 c684248b00000061 c684248c00000074 c684248d00000065 c684248e00000050 }
+ $sequence_27 = { 57 53 897dfc 897e1c }
+ $sequence_28 = { 59 6a65 668945f0 66894dec 59 6a25 58 }
+ $sequence_29 = { 59 6a70 66894dea 59 }
+ $sequence_30 = { c684241601000074 c684241701000045 c684241801000072 c684241901000072 c684241a0100006f c684241b01000072 }
+ $sequence_31 = { ebd2 c78424a000000068000000 c78424dc00000001000000 33c0 66898424e0000000 }
+ $sequence_32 = { c684249600000000 c684241001000047 c684241101000065 c684241201000074 c68424130100004c c684241401000061 }
+ $sequence_33 = { 59 6a70 66894de4 8bc8 }
+ $sequence_34 = { 51 6a05 ff75fc 897df0 }
+ $sequence_35 = { c684241201000074 c68424130100004c c684241401000061 c684241501000073 c684241601000074 c684241701000045 c684241801000072 }
+ $sequence_36 = { 6a00 6a27 6a02 6a00 6a01 }
+ $sequence_37 = { 8d8505feffff 50 e8???????? 83c40c }
+ $sequence_38 = { c645d316 c645d43a c645d53b c645d63b }
+ $sequence_39 = { c645cb30 c645cc27 c645cd3b c645ce30 }
+ $sequence_40 = { 488b4338 33d2 488bce 448d4220 }
+ $sequence_41 = { 488b4608 488b0e 48894628 488b4638 4c8d4c2450 448bc3 488bd7 }
+ $sequence_42 = { 4533c9 488bd6 ff90c8010000 8bf8 85c0 }
+ $sequence_43 = { 488b4638 488b0e 4c8d442450 4533c9 }
+ $sequence_44 = { 488bf0 c70005000000 85db 7415 4c8b4f38 }
+ $sequence_45 = { 488b0f 48894108 488b0f 488b4108 48894128 488b0f }
+ $sequence_46 = { 83c904 c1e803 448bc9 440fafc8 }
+ $sequence_47 = { 488bcf c744242088130000 e8???????? 488b5738 }
+ $sequence_48 = { 488b0f 488901 488b07 488338ff }
+ $sequence_49 = { 488bce 8bd8 ff92e8010000 488b6c2458 8bc3 488b5c2450 }
+ $sequence_50 = { 488b0f 894130 eb06 488b07 896830 }
+ $sequence_51 = { 488b07 896830 33c0 488b5c2458 }
+ $sequence_52 = { 8d8594faffff 50 68???????? ff15???????? }
+ $sequence_53 = { 013d???????? 8b04b5100b4200 0500080000 3bc8 }
+ $sequence_54 = { 0304b5100b4200 59 5e eb05 }
+ $sequence_55 = { 001cbe 40 0023 d18a0688078a 46 }
+ $sequence_56 = { 030c85100b4200 eb02 8bcb f6412480 }
+ $sequence_57 = { 0304b5100b4200 59 eb02 8bc3 }
+ $sequence_58 = { 0304b5100b4200 59 eb05 b8???????? }
+ $sequence_59 = { 0304b5100b4200 beffff0000 59 59 }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <5577728
}
-rule MALPEDIA_Win_Rad_Auto : FILE
+rule MALPEDIA_Win_3Cx_Backdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7146ba59-d944-5b98-95a4-2cbd8d5bc1ff"
+ id = "28fbb43b-1b49-58bb-9ada-865931dff5e6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rad"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rad_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.3cx_backdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.3cx_backdoor_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "ca5f1a440d85092616999ffada86b8990e8f68350339b252577329abb6a444ee"
+ logic_hash = "c22c772229b5508424567ef1d7e35b9960a69d5aa0f1d8dfccaad31a703d6c0c"
score = 75
quality = 75
tags = "FILE"
@@ -149085,34 +156090,34 @@ rule MALPEDIA_Win_Rad_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c644242000 e8???????? 8d542420 52 8d8c2498000000 c684240c06000018 ff15???????? }
- $sequence_1 = { 8b8680000000 3bc3 741b 8bbe84000000 e8???????? 8b8680000000 }
- $sequence_2 = { a1???????? 33c4 89442434 8b4508 8b00 85c0 751a }
- $sequence_3 = { 8b84241c010000 50 ffd6 83c404 8b8c2400060000 64890d00000000 }
- $sequence_4 = { 8d8d70ffffff ff25???????? 8b8578ffffff 83e002 0f8413000000 83a578fffffffd }
- $sequence_5 = { ffd3 8d8c2494000000 c684240806000005 ff15???????? 8b4c2418 51 8d8c2498000000 }
- $sequence_6 = { ff15???????? 8d8c2494000000 c684240806000020 ff15???????? b8???????? 8d4c2420 }
- $sequence_7 = { e8???????? 8bc7 50 c645fc02 e8???????? 8bc8 }
- $sequence_8 = { 720a 8b4c2434 51 ffd6 83c404 8d9424a8000000 52 }
- $sequence_9 = { 8d7e04 c645fc29 8d4f04 c706???????? 89bd10fdffff ff15???????? }
+ $sequence_0 = { 8bc8 c1e907 33c1 81c287d61200 8bc8 c1e116 33c1 }
+ $sequence_1 = { 84d2 7430 3811 742c e8???????? c70016000000 }
+ $sequence_2 = { 8bfb 48895c2430 4c89742428 4983e7f0 4d8d243f 498d442410 }
+ $sequence_3 = { 4a0fbe841940250300 428a8c1950250300 482bd0 8b42fc d3e8 49895108 41894118 }
+ $sequence_4 = { 4c8bce 4c8bc5 488bd7 498bcf e8???????? 498bc6 488b5c2460 }
+ $sequence_5 = { 498bd7 4489642448 48897c2440 44894c2438 4c8d4d97 4889442430 4489642428 }
+ $sequence_6 = { 7428 85db 7524 488d0d7ef90200 e8???????? 85c0 7510 }
+ $sequence_7 = { 4889742458 488b7108 33d2 488bce 48c1eb05 492bc9 }
+ $sequence_8 = { 4983c708 4533d2 32d2 4c897c2420 80fb30 7512 b201 }
+ $sequence_9 = { 0fb608 880a 488d5210 488b4808 48894af8 448820 }
condition:
- 7 of them and filesize <207872
+ 7 of them and filesize <585728
}
-rule MALPEDIA_Win_Enfal_Auto : FILE
+rule MALPEDIA_Win_Gozi_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7c648ee2-e4dd-541c-9b47-28a132a1416c"
+ id = "4c65f4c6-680c-5313-afa1-f0c350a0bb9e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.enfal"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.enfal_auto.yar#L1-L112"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gozi"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gozi_auto.yar#L1-L297"
license_url = "N/A"
- logic_hash = "4106f1f3c4e35436925009af22c1e6b23f6200a61794638682b09644acc42fa2"
+ logic_hash = "d1afd0d2426cb263c17dc36f11639d4b538234ba95ec55283f83783334fcf5d3"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -149124,32 +156129,54 @@ rule MALPEDIA_Win_Enfal_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd6 68???????? 57 8945d8 ffd6 68???????? 53 }
- $sequence_1 = { 51 53 ff505c 85c0 }
- $sequence_2 = { 50 6a00 6a01 ff7608 }
- $sequence_3 = { 57 6800000040 51 ff5010 8bd8 }
- $sequence_4 = { 81ec4c0a0000 80a5b4f9ffff00 56 baff000000 }
- $sequence_5 = { 8b4b24 8b431c 8b5320 8365fc00 }
- $sequence_6 = { 50 e8???????? 83c410 8b461c }
- $sequence_7 = { 8bec 81eccc040000 53 56 8b35???????? 57 }
- $sequence_8 = { ffd0 5e c3 ff15???????? 5e c3 }
- $sequence_9 = { 66a5 a4 be???????? 8dbd60ffffff }
+ $sequence_0 = { 8b4dfc f3a4 b0e9 aa }
+ $sequence_1 = { ee 7f7b 36110b 33745571 de7e75 cd18 4a }
+ $sequence_2 = { 3327 72e7 3ebb4a68d947 d93e 257296bc4a 1b6b61 9f }
+ $sequence_3 = { e8???????? 0bc0 7522 6a01 6a00 }
+ $sequence_4 = { 2bfb 8b5518 8b12 6a00 }
+ $sequence_5 = { 4e b64e 0fc0d6 69d5920d9cef }
+ $sequence_6 = { 0fadce 80eede c0ca12 2af4 8af4 }
+ $sequence_7 = { 894598 50 e8???????? 8b4650 8b7c0704 }
+ $sequence_8 = { 83c101 894df4 8b55ec 83ea02 3955f4 0f8d45040000 }
+ $sequence_9 = { 94 6e 8ee1 54 }
+ $sequence_10 = { 7516 c78554ffffff06000000 c78558ffffff00000000 eb14 }
+ $sequence_11 = { bf???????? 8bdf c70747494638 66c747043761 83c706 8b450c }
+ $sequence_12 = { c9 50 0c73 0e 96 3b5375 }
+ $sequence_13 = { ffd7 03f0 56 53 33f6 56 }
+ $sequence_14 = { ad b710 2dc7ce5bbb d6 b6c6 }
+ $sequence_15 = { ff75e4 ffd0 c3 6a68 68???????? e8???????? }
+ $sequence_16 = { 0f8229feffff 5f 5e 5b c9 c21000 }
+ $sequence_17 = { c9 c20800 6a00 8d87950c0000 }
+ $sequence_18 = { 84c1 0fb3ea f6c1ba 0fce }
+ $sequence_19 = { 96 3b5375 60 d3e0 90 48 }
+ $sequence_20 = { 69d5ca659407 f6de c645ff61 a1???????? 8b0d???????? 6a00 }
+ $sequence_21 = { 83c101 894d90 0fb755e4 52 8b4590 }
+ $sequence_22 = { b87e8da638 e022 3a56b9 036890 2b02 9a102a6715fb53 }
+ $sequence_23 = { dc6f1b 95 bf633629a8 02738f }
+ $sequence_24 = { 83bd54ffffff03 7c0a c78554ffffff00000000 eb95 33c0 8b55f4 }
+ $sequence_25 = { 0fbe4415ec 8b8d4cffffff 038d58ffffff 0fbe11 33d0 8b854cffffff }
+ $sequence_26 = { 41 4e 75ea 5e }
+ $sequence_27 = { 0f8447010000 83f8ff 0f843e010000 682000cc00 56 }
+ $sequence_28 = { 837df800 75c7 ff75fc e8???????? c9 }
+ $sequence_29 = { 0fb3ce 86d6 2af4 b252 b0ca c745fc00000000 }
+ $sequence_30 = { e8???????? 59 8bf0 89b5e0f2ffff }
+ $sequence_31 = { 85c0 7404 8365f800 85f6 7407 8b06 }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <568320
}
-rule MALPEDIA_Win_Matanbuchus_Auto : FILE
+rule MALPEDIA_Win_Fireball_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2788ba99-d4a7-56bc-b166-5140402f53be"
+ id = "41b2d4de-af91-5e95-ba91-5bc661ef7417"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.matanbuchus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.matanbuchus_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fireball"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fireball_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "78ecf15a99d40895d657b9372a7af5a206c5b9d4887dbdf8360368c6bcd36a27"
+ logic_hash = "0f627ea55086f489b8cd11c65d68f2e0680aa8b1619660718f20b28106c4357c"
score = 75
quality = 75
tags = "FILE"
@@ -149163,32 +156190,32 @@ rule MALPEDIA_Win_Matanbuchus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 038c0534fdffff 51 e8???????? ebb4 8b55fc 52 e8???????? }
- $sequence_1 = { 6a0c 6a0c 68???????? e8???????? }
- $sequence_2 = { 8b4dfc 038c0534fdffff 51 e8???????? }
- $sequence_3 = { 8b4df8 8b513c 035508 8955f4 }
- $sequence_4 = { 6bc200 8b4d08 0fbe1401 33550c }
- $sequence_5 = { 68f8000000 8d95b8feffff 52 8b45fc 0345ec 50 e8???????? }
- $sequence_6 = { 8b45f4 c1e818 3345f4 8945f4 694df495e9d15b 894df4 }
- $sequence_7 = { 51 8b55f0 52 6b45f828 8b4dfc 038c0534fdffff }
- $sequence_8 = { eb44 b901000000 d1e1 8b55ec }
- $sequence_9 = { 8b55ec 813a50450000 7407 33c0 e9???????? }
+ $sequence_0 = { 52 8bce e8???????? b101 e8???????? }
+ $sequence_1 = { 30a830ac30b0 30b830cc30e8 30f0 30f4 3010 3118 311c31 }
+ $sequence_2 = { 8b0f 8bc1 c1f805 83e11f 8b0485000a2500 c1e106 80640804fe }
+ $sequence_3 = { 68???????? 8d8c24a4000000 c78424b800000007000000 c78424b400000000000000 }
+ $sequence_4 = { c78424a400000000000000 6689842494000000 837c247808 720c ff742464 e8???????? }
+ $sequence_5 = { 53 ff15???????? 85c0 0f85c2feffff }
+ $sequence_6 = { c78518f5ffff07000000 c78514f5ffff00000000 66898504f5ffff 83bdf4f5ffff08 720e }
+ $sequence_7 = { c68558fbffff00 7504 33c9 eb12 8d8d64f9ffff }
+ $sequence_8 = { 8d442417 50 8d542434 8d8c2498000000 c744244c07000000 c744244800000000 e8???????? }
+ $sequence_9 = { 8bf1 c785e8fbffff00000000 e8???????? 83c40c 8d85ecfbffff 6808020000 }
condition:
- 7 of them and filesize <2056192
+ 7 of them and filesize <335872
}
-rule MALPEDIA_Win_Deputydog_Auto : FILE
+rule MALPEDIA_Win_Attor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3ae1b77f-6003-5f42-85fd-2473ea8bd4ab"
+ id = "de68d27a-a7e8-5baa-94a2-9db640461043"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.deputydog"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.deputydog_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.attor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.attor_auto.yar#L1-L165"
license_url = "N/A"
- logic_hash = "027f4c297ed3d9095922a3567db93a8700528916bc6b48fe318198129cac1716"
+ logic_hash = "9ffbefbd2b4397dd03e1eba42ffa85ea59dac9e4723a113680ffe4af7c4fe1e3"
score = 75
quality = 75
tags = "FILE"
@@ -149202,32 +156229,38 @@ rule MALPEDIA_Win_Deputydog_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 56 8bf1 8b461c 8d4e18 ff30 8d45fc }
- $sequence_1 = { 85ff 7407 8b5510 8a12 8817 }
- $sequence_2 = { 53 8d4de0 ff15???????? 807df300 7509 }
- $sequence_3 = { 57 56 e8???????? 83c40c 8d4604 c60664 50 }
- $sequence_4 = { 8d4580 50 e8???????? 8b4004 59 3bc3 59 }
- $sequence_5 = { 6a00 56 ff7604 50 ff15???????? 8365f000 6800200000 }
- $sequence_6 = { 8b7e08 8d1419 397d08 7417 8bc2 2bc1 2bc3 }
- $sequence_7 = { 8b4d0c 57 ff30 6a00 ff15???????? 8b7d08 8b4f04 }
- $sequence_8 = { 53 51 ff75e4 50 ff7618 ff15???????? 8b3d???????? }
- $sequence_9 = { 57 50 ff15???????? 59 84c0 59 740b }
+ $sequence_0 = { 83f801 7411 3d81000000 740a }
+ $sequence_1 = { 33c0 488b6c2450 4883c420 415c 5f 5e }
+ $sequence_2 = { 488b8c24b0000000 4c8b642468 4885c9 7402 8919 408ac5 }
+ $sequence_3 = { 488b8c2490000000 4885c9 0f8441020000 41b802000000 8bd5 ff15???????? 85c0 }
+ $sequence_4 = { 48395c2430 0f8447010000 b101 e8???????? }
+ $sequence_5 = { 48c744243000000000 7414 33c9 e8???????? 488b8c2490000000 }
+ $sequence_6 = { 7435 488b442440 488b8c2490000000 4533c0 418d5002 4d8bcf }
+ $sequence_7 = { 4533c0 4d8bcc 418d5002 44896c2420 ff15???????? }
+ $sequence_8 = { 8b4c2418 50 55 8b2d???????? 6a00 }
+ $sequence_9 = { 740a 83f808 7405 83f811 }
+ $sequence_10 = { 56 ff15???????? 8d4c2418 8d54241c 51 52 }
+ $sequence_11 = { 83c408 eb06 8b35???????? 897c241c 8b7c2420 85ff }
+ $sequence_12 = { 83c40c 89442420 85c0 0f842b010000 8b4c2430 8d7108 }
+ $sequence_13 = { 85c0 0f840c010000 8b54241c 57 52 }
+ $sequence_14 = { 897504 c644241301 740a 8b4c2418 }
+ $sequence_15 = { 8b44243c 3bc7 7434 8b54241c }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <2023424
}
-rule MALPEDIA_Win_Rctrl_Auto : FILE
+rule MALPEDIA_Win_Tiny_Turla_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "60ae096f-d5f7-57d0-b6f9-cb53f8d1b760"
+ id = "03ecfc31-50be-55ad-b8ea-3661b97e212f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rctrl"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rctrl_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tiny_turla"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tiny_turla_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "0c64a52ce76fbe6b25b4079783722f9c8bfa120e4543946e41c97eea8cb03d4d"
+ logic_hash = "78e001a1d7d03185ba347a5f9852159024940a515be46a1732bb8c9313d9ab24"
score = 75
quality = 75
tags = "FILE"
@@ -149241,32 +156274,32 @@ rule MALPEDIA_Win_Rctrl_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 85c0 0f8440030000 8b10 8bc8 ff520c 83c010 }
- $sequence_1 = { 8bf0 56 6a00 6a00 ff15???????? 33c9 894508 }
- $sequence_2 = { 6a06 e8???????? cc b8???????? c3 55 8bec }
- $sequence_3 = { 8b473c 8985d4feffff e8???????? 85c0 0f85ef000000 814f2400000400 8b85d8feffff }
- $sequence_4 = { 33c0 40 8be5 5d c20800 6a14 b8???????? }
- $sequence_5 = { 898368040000 03c8 83bd7cffffff00 7433 8b855cffffff 8db328040000 03c1 }
- $sequence_6 = { 75cc 8d4dc8 e8???????? e9???????? e8???????? ffb6f8000000 e8???????? }
- $sequence_7 = { ff750c 8bd6 e8???????? 8b4518 8d0c3e 8d1400 }
- $sequence_8 = { 85c0 0f94c0 84c0 7423 6a00 6a00 57 }
- $sequence_9 = { ff7008 ff75f0 e8???????? 8bf0 eb02 }
+ $sequence_0 = { 4533ed 8b7d7f 488b742450 8d4f02 }
+ $sequence_1 = { 0f84f8000000 33d2 488d4da0 448d4268 }
+ $sequence_2 = { 488b16 8bd8 894567 41b906000200 488d4577 4533c0 }
+ $sequence_3 = { 48895c2420 ff15???????? 85c0 750e 488bce }
+ $sequence_4 = { ff15???????? 85c0 7516 4533ed }
+ $sequence_5 = { 440fb62a 44886d6f 44894d7f 4585c0 7540 }
+ $sequence_6 = { ff15???????? b005 e9???????? 8b0f 85c9 }
+ $sequence_7 = { 418d511b ff15???????? 488bcb 85c0 0f849b000000 8b7d50 }
+ $sequence_8 = { 48c74308ffffffff 488b4b18 4883f9ff 740e ff15???????? }
+ $sequence_9 = { 4883ec18 c7042400000000 33c0 83f801 7441 8b0424 488b4c2420 }
condition:
- 7 of them and filesize <4315136
+ 7 of them and filesize <51200
}
-rule MALPEDIA_Win_Atmii_Auto : FILE
+rule MALPEDIA_Win_Grabbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a3746494-2207-5da0-bb5a-0a2c92906b78"
+ id = "02308264-bf9f-5ce5-8d58-a146011d85f3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atmii"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atmii_auto.yar#L1-L170"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grabbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grabbot_auto.yar#L1-L161"
license_url = "N/A"
- logic_hash = "32f9cc90bb902f5f085ec60f456bf3e42304f21478253b8a2c4851a4d1f531ad"
+ logic_hash = "fb36fa0cb6c01a8c284e94b423e764f2d45ce7cf14719bff3ffb20003d9572f1"
score = 75
quality = 75
tags = "FILE"
@@ -149280,38 +156313,38 @@ rule MALPEDIA_Win_Atmii_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a03 68000000c0 8b0d???????? 51 ff15???????? 8945fc }
- $sequence_1 = { 8945ee 0fb705???????? 52 682e010000 50 895dd9 }
- $sequence_2 = { 68???????? 50 ffd7 8d9dfcfbffff }
- $sequence_3 = { 8d8dd1f9ffff 51 8895c4f9ffff ff15???????? }
- $sequence_4 = { 8d95fcfdffff 6a00 52 e8???????? 8b35???????? 83c424 68???????? }
- $sequence_5 = { 8945fc 837dfc00 7454 8b4dfc 0fb611 }
- $sequence_6 = { 51 e8???????? 8b55f4 83c414 6a00 }
- $sequence_7 = { 83c414 8d9df8fcffff e8???????? 8b45f8 85c0 7407 }
- $sequence_8 = { 68???????? 68c3000000 8d85f8fcffff 68???????? 50 }
- $sequence_9 = { 5f 5b 8be5 5d c3 68???????? 680b010000 }
- $sequence_10 = { 837d0803 0f8ceb000000 53 8b1d???????? 57 68???????? }
- $sequence_11 = { ffd3 68???????? 68???????? 8985c5f9ffff ffd7 }
- $sequence_12 = { c745f800000000 ff15???????? 85c0 0f94c0 8845ff 84c0 742e }
- $sequence_13 = { 85ff 0f8448030000 8d55f0 52 6800040000 }
- $sequence_14 = { ff2485181d0010 68???????? 8d8df8feffff 51 eb2f 68???????? }
- $sequence_15 = { 81ea???????? 83c204 f7d2 8955ed }
+ $sequence_0 = { 0fb702 83f85a 770b 83f841 7206 }
+ $sequence_1 = { 83f85a 770d 83f841 7208 83c020 }
+ $sequence_2 = { 83f841 7206 83c020 0fb7c0 83c202 }
+ $sequence_3 = { ffd0 c3 b88dbdc13f 50 e8???????? }
+ $sequence_4 = { ffe0 c3 c3 c3 68b9be7238 e8???????? 50 }
+ $sequence_5 = { 03c7 813850450000 0f853c010000 0fb74804 ba4c010000 }
+ $sequence_6 = { 03c3 813850450000 8945f8 7408 32c0 }
+ $sequence_7 = { 7523 8b8c18a0000000 85c9 0f8489000000 837c187405 }
+ $sequence_8 = { 56 ffd0 33c9 66894c37fe }
+ $sequence_9 = { 7428 8b0d???????? 8908 8b0d???????? 894804 }
+ $sequence_10 = { 89480c e9???????? 33c0 e9???????? }
+ $sequence_11 = { 894808 8b0d???????? 89480c e9???????? }
+ $sequence_12 = { 8bf0 85f6 741d 8d4601 50 e8???????? }
+ $sequence_13 = { 85c0 56 0f9fc3 e8???????? 83c414 }
+ $sequence_14 = { ff15???????? a3???????? 85c0 7505 83c8ff }
+ $sequence_15 = { 741b 8d440002 50 e8???????? }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <1335296
}
-rule MALPEDIA_Win_Hotwax_Auto : FILE
+rule MALPEDIA_Win_Aurora_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "34df7b39-b5de-5d0e-aea3-1ec834745896"
+ id = "6739f143-45de-5c25-aa97-f9c0ab868c7e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hotwax"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hotwax_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aurora"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aurora_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "f7aa59232edd43ba4670389edd9f2f755cdf2f70e16334cd9db9000bdc1ab730"
+ logic_hash = "401b46f1e5d6c2d35e6c7ba88f463abdb92c79f1d47fd14fd19c66427ffd50ad"
score = 75
quality = 75
tags = "FILE"
@@ -149325,32 +156358,32 @@ rule MALPEDIA_Win_Hotwax_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7e74 817d0063736de0 7528 48833d????????00 741e 488d0d5dee0000 }
- $sequence_1 = { 488bd7 ff15???????? 418d8770050000 4489bdcc040000 c745a400080000 8945a0 }
- $sequence_2 = { 4889842410030000 488bf9 488d8c2401020000 33d2 41b803010000 c684240002000000 }
- $sequence_3 = { 488bd9 4885c0 7479 488d0d7fe50000 483bc1 746d 488b8310010000 }
- $sequence_4 = { 4533db 488d9424f0000000 41b803010000 44895c2440 4c895c2448 ff15???????? 833d????????00 }
- $sequence_5 = { 486bd258 490394c1a04b0100 f6423880 742c }
- $sequence_6 = { 488bcb 488905???????? ff15???????? 488d1547d20000 488bcb 488905???????? ff15???????? }
- $sequence_7 = { cc 4c8d05f8530000 498bd4 488bcd e8???????? 85c0 }
- $sequence_8 = { 488b0d???????? eb7c 4c8d256a830000 488b0d???????? eb6c e8???????? }
- $sequence_9 = { 488d0d50bf0000 ba01000000 e8???????? 4c8d442440 }
+ $sequence_0 = { 8b4e14 8945d4 8b4610 3bc1 7530 40 83f8fe }
+ $sequence_1 = { c645fc03 8d4dd8 837dec08 8d5dd8 }
+ $sequence_2 = { 8aca c0e206 0255d3 c0e902 80e10f }
+ $sequence_3 = { ebd9 837b1410 7202 8b1b }
+ $sequence_4 = { 3bf3 7469 897de8 c645fc01 85ff 7437 c7471000000000 }
+ $sequence_5 = { 6a00 c741140f000000 c7411000000000 68???????? c60100 e8???????? 8d8df8fbffff }
+ $sequence_6 = { 83793800 0f45c2 50 e8???????? 8b9df0feffff c745e40f000000 c745e000000000 }
+ $sequence_7 = { c785c8f1ffff0f000000 c785c4f1ffff00000000 c685b4f1ffff00 e8???????? 8d8dccf1ffff }
+ $sequence_8 = { 68???????? 8d8d24f1ffff c78538f1ffff0f000000 c78534f1ffff00000000 }
+ $sequence_9 = { 6a02 68???????? 8d8d14efffff c78528efffff0f000000 }
condition:
- 7 of them and filesize <198656
+ 7 of them and filesize <827392
}
-rule MALPEDIA_Win_Tofsee_Auto : FILE
+rule MALPEDIA_Win_Httpsuploader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2d8fcb5e-0a8a-503a-9ded-9601f9237fa2"
+ id = "be17d448-1d90-5f75-8f13-d63b39944dc3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tofsee"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tofsee_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.httpsuploader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.httpsuploader_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "def89a492b1a308a2f7b3c5c33eb9a3e8527d0ce6d7ff4abe57189bca63d387c"
+ logic_hash = "5be7e6e5938fcb4fa9787510fb0867a1f442345e4d8453db75c177a24413afa4"
score = 75
quality = 75
tags = "FILE"
@@ -149364,32 +156397,32 @@ rule MALPEDIA_Win_Tofsee_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8584feffff 50 68b7000000 68a9000000 6a0c 68???????? 68???????? }
- $sequence_1 = { f7f3 8b450c 8a0402 88043e 46 3b7508 7ce0 }
- $sequence_2 = { f7fb 80c261 881431 49 47 85c9 }
- $sequence_3 = { bf???????? 8b46fc 48 744d 48 743a }
- $sequence_4 = { 5e 5b c9 c3 56 57 ff15???????? }
- $sequence_5 = { 33c0 eb3a 8b4b3c 03cb 813950450000 75ef }
- $sequence_6 = { 0f8ee8f7ffff 5b 8b4570 83c004 50 ff15???????? ff7564 }
- $sequence_7 = { 8b4038 40 57 8bcb 8945fc e8???????? 8bc8 }
- $sequence_8 = { 55 56 57 8bf1 ffd3 8b3d???????? 8be8 }
- $sequence_9 = { c0e105 0ad9 32da 34c6 881e 46 3bf7 }
+ $sequence_0 = { 33ff 33d2 41b806020000 6689bc2470020000 e8???????? 488d4c2451 33d2 }
+ $sequence_1 = { 33d2 33c9 897c2428 48895c2420 ff15???????? eb3b 488d0dc3bd0000 }
+ $sequence_2 = { 4883ec20 488bfa 488bd9 488d0501700000 488981a0000000 83611000 }
+ $sequence_3 = { 4c8bc0 418bd4 e8???????? 488d8dd0000000 ff15???????? }
+ $sequence_4 = { 488d0d6c280000 4533c9 ba00000040 4489442420 ff15???????? }
+ $sequence_5 = { 4c8d25cf7d0000 f0ff09 7511 488b8eb8000000 493bcc }
+ $sequence_6 = { 488d0543b50000 eb04 4883c014 4883c428 c3 4053 }
+ $sequence_7 = { 488d158e380000 488bc8 ff15???????? 4885c0 0f847a010000 }
+ $sequence_8 = { 81fa01010000 7d13 4863ca 8a44191c 4288840170fa0000 }
+ $sequence_9 = { 745e 6666660f1f840000000000 488b0d???????? 488d542440 4533c9 4533c0 ff15???????? }
condition:
- 7 of them and filesize <147456
+ 7 of them and filesize <190464
}
-rule MALPEDIA_Win_Gemcutter_Auto : FILE
+rule MALPEDIA_Win_Shylock_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e94125d6-f7ee-5626-bb13-57f31cd4995b"
+ id = "c0c6612f-064a-5f55-82bb-f58e63a548a1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gemcutter"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gemcutter_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shylock"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shylock_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "cdd9767cb466abee0d56200d0aa911cbda817b83008ef2825b381668a5ec2a45"
+ logic_hash = "2cab0a97d5d39d5cf87c312cbde6ff184fa1776200cc626b918f5dce9951a83d"
score = 75
quality = 75
tags = "FILE"
@@ -149403,32 +156436,32 @@ rule MALPEDIA_Win_Gemcutter_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff75fc ff15???????? eb09 ff75fc ff15???????? 3975fc }
- $sequence_1 = { 8d8500fcffff 50 e8???????? 59 56 ff15???????? }
- $sequence_2 = { 56 ffd7 53 56 56 56 }
- $sequence_3 = { 59 53 50 ffd6 0fbe85f0f8ffff 50 }
- $sequence_4 = { 6a01 ff15???????? 6a01 68???????? e8???????? 6a01 }
- $sequence_5 = { 50 ff15???????? 83c420 8818 8d85f0fdffff 50 8d85f0f8ffff }
- $sequence_6 = { 8d85f0fdffff 50 ffd7 8d85f0f8ffff 6800040000 50 }
- $sequence_7 = { 8d45ac 56 50 e8???????? 83c40c 8d45f0 c745d801000000 }
- $sequence_8 = { ff15???????? 85c0 0f84df000000 8d85f0f8ffff 68???????? 50 e8???????? }
- $sequence_9 = { c3 55 8bec 81ec00040000 56 57 68???????? }
+ $sequence_0 = { e8???????? 8d8534ffffff 50 b8???????? e8???????? 59 50 }
+ $sequence_1 = { 8db544ffffff e8???????? 8bc6 50 8d45f8 e8???????? ff30 }
+ $sequence_2 = { c22c00 0fb64001 50 8d45c8 50 8b45d4 8b30 }
+ $sequence_3 = { c745fc04010000 ff75e4 e8???????? 83c410 ff45f8 3d03010000 0f8559ffffff }
+ $sequence_4 = { e8???????? 3c01 743b 8d8588feffff 50 b8???????? e8???????? }
+ $sequence_5 = { 57 8b7d08 8b4d0c 8a4510 fc f2ae 7504 }
+ $sequence_6 = { 8945b0 8d856cffffff 50 8b45fc ff7018 ff9540ffffff 898534ffffff }
+ $sequence_7 = { 8d75f8 8bfc e8???????? 8d8504ffffff 50 ff7508 e8???????? }
+ $sequence_8 = { 51 33d2 8d5df8 e8???????? 8d45ec e8???????? 8bf8 }
+ $sequence_9 = { e8???????? e8???????? 59 59 8bf0 e8???????? 8d75fc }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <630784
}
-rule MALPEDIA_Win_Bohmini_Auto : FILE
+rule MALPEDIA_Win_Listrix_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c674d076-0d8a-5cd0-a61f-b74753074ae4"
+ id = "f00b612a-8ee6-5314-b10b-7290e9e1e604"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bohmini"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bohmini_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.listrix"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.listrix_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "924ffc111e8f5edb5600c44b643235932f72ba9b2a992fa2571ad4dc6b3c6eb8"
+ logic_hash = "2287c5f695d49f8318bd5f0c78a77cdf4d2c441f03bbfda75594fd76fd20827f"
score = 75
quality = 75
tags = "FILE"
@@ -149442,32 +156475,32 @@ rule MALPEDIA_Win_Bohmini_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 896c2410 896c2414 0f86c5000000 8b7c2420 }
- $sequence_1 = { 6a00 6a00 8bca 83c11a 51 6a00 6a00 }
- $sequence_2 = { 8d542414 6a00 52 ff15???????? 85c0 }
- $sequence_3 = { ff15???????? 3bc3 a3???????? 7512 5f 5e }
- $sequence_4 = { 6800040000 50 53 ff15???????? 50 ff15???????? }
- $sequence_5 = { 4a 741a 4a 7543 e8???????? 03c6 33d2 }
- $sequence_6 = { 83c410 85c0 7507 6891130000 eb2a }
- $sequence_7 = { 8b5608 52 ffd5 40 50 }
- $sequence_8 = { 52 e8???????? 40 50 8d8424b8010000 50 }
- $sequence_9 = { 8b2d???????? 8b3e 51 6a00 ffd5 50 ffd3 }
+ $sequence_0 = { 8d8dc0f5ffff 51 ffd3 85c0 7454 57 }
+ $sequence_1 = { 85f6 740d f68594f5ffff10 0f84ac010000 8b1d???????? 68???????? 8d85c0f5ffff }
+ $sequence_2 = { 8d46ff 50 8b8584f5ffff 51 52 50 8d8df4fbffff }
+ $sequence_3 = { 8d85f4f7ffff 50 ff15???????? 8b7518 }
+ $sequence_4 = { 89b588f5ffff 397510 0f8e4c020000 57 8d85f4f7ffff 50 }
+ $sequence_5 = { 50 8d4c2470 51 c744242430794000 }
+ $sequence_6 = { c1e802 89442408 c744240c02000000 85c0 0f8408010000 }
+ $sequence_7 = { 8bc7 c1f805 c1e606 033485e0ad4000 8b45f8 8b00 }
+ $sequence_8 = { a1???????? c705????????cc274000 8935???????? a3???????? ff15???????? a3???????? }
+ $sequence_9 = { 6a00 8d95e4f9ffff 52 ff15???????? 85c0 0f84bb000000 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Molerat_Loader_Auto : FILE
+rule MALPEDIA_Win_Rgdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6649c702-0322-5056-bfb1-5bb59b0b659a"
+ id = "4140ffd6-129c-5510-99e3-ad151c975d1e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.molerat_loader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.molerat_loader_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rgdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rgdoor_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "9e4d3c42bd1eb8db57dd9c545f5a5ad86009e39e60f601bd2428ef16d555d86e"
+ logic_hash = "bf6d408b52f68286adc8c589928141fb2586a77ca6ee142e58e02ec6b6fb2c0d"
score = 75
quality = 75
tags = "FILE"
@@ -149481,32 +156514,32 @@ rule MALPEDIA_Win_Molerat_Loader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c40c 68???????? 50 8d8dc0fdffff 51 c645fc18 }
- $sequence_1 = { 68???????? e8???????? 8b4d58 e8???????? e9???????? 68???????? e8???????? }
- $sequence_2 = { 7d0d 8a4c181c 888860464400 40 ebe9 33c0 8945e4 }
- $sequence_3 = { 83c40c 8d957cffffff 52 50 8d85d0fdffff 50 c645fc3a }
- $sequence_4 = { 50 8b4204 ffd0 8d4d0c e8???????? 8d8da0fdffff c645fc07 }
- $sequence_5 = { 7f0a 8b08 8b11 50 8b4204 ffd0 c645fc69 }
- $sequence_6 = { 8b95ecfeffff 8995e8feffff c745fc01000000 b8???????? c3 c645fc00 }
- $sequence_7 = { 8d4c247c c68424d800000002 e8???????? 8d54247c 52 c7842480000000e8c64300 e8???????? }
- $sequence_8 = { 83c010 83c404 8945e8 68???????? 68???????? 8d4de4 51 }
- $sequence_9 = { 8d8d74ffffff c645fc03 e8???????? 8d8574ffffff 50 8d4d5c 68???????? }
+ $sequence_0 = { 7512 448bfb 448be3 4c8d35d4870100 e9???????? bd01000000 ba98000000 }
+ $sequence_1 = { 488bce eb9d 33db 41b803010000 488bd6 e8???????? }
+ $sequence_2 = { 4533f6 eb0e 4983ceff 90 49ffc6 42381c32 75f7 }
+ $sequence_3 = { e8???????? b802000000 eb30 48837dd010 720a 488b4db8 }
+ $sequence_4 = { e8???????? 488d05554b0200 4889442458 488d15398d0200 488d4c2458 }
+ $sequence_5 = { e8???????? 83f8ff 0f8490050000 80bc247001000077 750a 8bde 448be6 }
+ $sequence_6 = { 8938 e8???????? 488d1d8b390200 4885c0 7404 }
+ $sequence_7 = { 4883ec20 488d3d8bf90100 48393d???????? 742b }
+ $sequence_8 = { 48837db010 480f435598 41b822000000 488d8de8000000 e8???????? 4885c0 488b85e0000000 }
+ $sequence_9 = { 488bce ff15???????? 8bf8 eb25 488b8c2490000000 e9???????? 48895c2420 }
condition:
- 7 of them and filesize <688128
+ 7 of them and filesize <475136
}
-rule MALPEDIA_Win_Polpo_Auto : FILE
+rule MALPEDIA_Win_Tofsee_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f09c9fa9-68a5-510c-9c07-2bf30033e8be"
+ id = "2d8fcb5e-0a8a-503a-9ded-9601f9237fa2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.polpo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.polpo_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tofsee"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tofsee_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "d086587d6209a1b4d39f14c8bf11bcdd8bb5ac2527f8607c317abb5534459f55"
+ logic_hash = "def89a492b1a308a2f7b3c5c33eb9a3e8527d0ce6d7ff4abe57189bca63d387c"
score = 75
quality = 75
tags = "FILE"
@@ -149520,34 +156553,34 @@ rule MALPEDIA_Win_Polpo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6800040000 8d8decfbffff 51 50 ffd7 6a00 }
- $sequence_1 = { 50 8d85ecf7ffff 50 8d8decfbffff 51 ff15???????? 40 }
- $sequence_2 = { 6a02 52 ff15???????? 8b03 50 ff15???????? }
- $sequence_3 = { c1e606 03348540b30120 8b45f8 8b00 8906 }
- $sequence_4 = { 57 33c0 6806020000 898d98f9ffff 50 8d8df6fdffff 51 }
- $sequence_5 = { 8d854cffffff 8bd0 8d642400 8a08 40 3acb 75f9 }
- $sequence_6 = { 52 50 ff15???????? 6a00 6800040000 8d8dfcfaffff 68???????? }
- $sequence_7 = { 8a08 40 3acb 75f9 2bc6 8dbd4cf7ffff }
- $sequence_8 = { 51 8985d0dfffff 8985d4dfffff 8885dcdfffff e8???????? }
- $sequence_9 = { ffd6 85c0 8b859cfdffff 50 0f8516020000 ff15???????? 8d45a4 }
+ $sequence_0 = { 8d8584feffff 50 68b7000000 68a9000000 6a0c 68???????? 68???????? }
+ $sequence_1 = { f7f3 8b450c 8a0402 88043e 46 3b7508 7ce0 }
+ $sequence_2 = { f7fb 80c261 881431 49 47 85c9 }
+ $sequence_3 = { bf???????? 8b46fc 48 744d 48 743a }
+ $sequence_4 = { 5e 5b c9 c3 56 57 ff15???????? }
+ $sequence_5 = { 33c0 eb3a 8b4b3c 03cb 813950450000 75ef }
+ $sequence_6 = { 0f8ee8f7ffff 5b 8b4570 83c004 50 ff15???????? ff7564 }
+ $sequence_7 = { 8b4038 40 57 8bcb 8945fc e8???????? 8bc8 }
+ $sequence_8 = { 55 56 57 8bf1 ffd3 8b3d???????? 8be8 }
+ $sequence_9 = { c0e105 0ad9 32da 34c6 881e 46 3bf7 }
condition:
- 7 of them and filesize <250880
+ 7 of them and filesize <147456
}
-rule MALPEDIA_Win_Kutaki_Auto : FILE
+rule MALPEDIA_Win_Mosquito_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "09920faf-098e-5e77-9216-3a3bfa3a1490"
+ id = "d845e95b-9b1b-51f7-92b1-5c116f68e381"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kutaki"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kutaki_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mosquito"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mosquito_auto.yar#L1-L192"
license_url = "N/A"
- logic_hash = "cdd66e692bdc9daff0e282b4897c4e9339c8de45be71e54a60a94829ea33b905"
+ logic_hash = "87ba9d2670a970e725fcb73c4f11150d5260680ad8d699153882d887044e12b1"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -149559,32 +156592,43 @@ rule MALPEDIA_Win_Kutaki_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 6a01 6880000000 ff15???????? 83c41c c745fc0c000000 }
- $sequence_1 = { 0f803a020000 8b450c 8910 e9???????? }
- $sequence_2 = { ff15???????? 898528ffffff eb0a c78528ffffff00000000 8d4dc8 ff15???????? }
- $sequence_3 = { ff15???????? 898568feffff eb0a c78568feffff00000000 8b459c 50 ff15???????? }
- $sequence_4 = { c745fc3c000000 660fb64dd8 6683e10f 666bc910 0f80c9020000 660fb645c8 6699 }
- $sequence_5 = { 8d4580 50 ff15???????? 8985d4feffff 6aff 8b8dd4feffff 8b11 }
- $sequence_6 = { 8b45bc 50 8b4db8 51 ff15???????? 898540ffffff }
- $sequence_7 = { c745fc08000000 6a74 8d855cffffff 50 ff15???????? 6a65 8d8d4cffffff }
- $sequence_8 = { 50 68???????? ff15???????? 85c0 0f85bc000000 c745fc1a000000 }
- $sequence_9 = { 52 ff15???????? 898550ffffff 8b4508 }
+ $sequence_0 = { f3a5 ff942464020000 81c450020000 85c0 }
+ $sequence_1 = { 52 50 6a00 6801c1fd7d }
+ $sequence_2 = { f7d8 1bc0 83e0b4 83c04c }
+ $sequence_3 = { 8b10 8bc8 57 6842730000 ff5204 56 }
+ $sequence_4 = { b994000000 8bfc f3a5 ff942464020000 }
+ $sequence_5 = { 8b10 8bc8 ff5204 56 }
+ $sequence_6 = { e8???????? 85c0 7517 8bcb e8???????? 8b7328 }
+ $sequence_7 = { e8???????? 6a20 e8???????? 83c40c }
+ $sequence_8 = { 8b00 33ff 57 6880000000 6a03 57 }
+ $sequence_9 = { e8???????? 6a20 8bf0 e8???????? 8bc8 }
+ $sequence_10 = { 8bfc f3a5 ff942460020000 81c450020000 }
+ $sequence_11 = { 6824080000 50 e8???????? 83c410 }
+ $sequence_12 = { 0000 006301 1000 7500 }
+ $sequence_13 = { 0000 0018 a0???????? 57 }
+ $sequence_14 = { 0000 0001 1001 c550f0 8b8078005900 }
+ $sequence_15 = { 0000 0032 08804d086440 5e }
+ $sequence_16 = { 0000 00645657 8b7dc2 0400 }
+ $sequence_17 = { 0000 006500 676c 0010 }
+ $sequence_18 = { ff15???????? 6a00 56 ff15???????? 8903 83f8ff }
+ $sequence_19 = { 0000 00748078 3001 40 }
+ $sequence_20 = { 6aff 5d c28bcf 7300 6a01 }
condition:
- 7 of them and filesize <1335296
+ 7 of them and filesize <1015808
}
-rule MALPEDIA_Win_Quarterrig_Auto : FILE
+rule MALPEDIA_Win_Bernhardpos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b690a4f4-b484-55ac-b058-10bc50927e69"
+ id = "7b2918eb-6e4b-588b-9817-19ede384242f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.quarterrig"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.quarterrig_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bernhardpos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bernhardpos_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "311b3b8ecf53c484bcc2dd986bb0e82467b08ff5a42c5d9fde578d475409e28c"
+ logic_hash = "b0e71b787dda9e2d7e79e7ddddae77406aa6aa8d138e23e43da621be02324cd1"
score = 75
quality = 75
tags = "FILE"
@@ -149598,32 +156642,32 @@ rule MALPEDIA_Win_Quarterrig_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 32c0 e9???????? 8b15???????? 498bce ff15???????? 3d02010000 }
- $sequence_1 = { 884597 33ff 897d9b 41f7411800400000 7528 410f1000 f30f7f45a7 }
- $sequence_2 = { 4883c438 c3 488d0d53c10500 e8???????? 833d????????ff 75d2 c605????????01 }
- $sequence_3 = { 65488b042558000000 ba04000000 488b0cc8 8b040a 3905???????? 7f19 488d0513cc0500 }
- $sequence_4 = { 488b5590 4883fa10 720d 48ffc2 488b4c2478 e8???????? 4c896d88 }
- $sequence_5 = { 488d0569fe0500 488b4c2448 4833cc e8???????? 0f28742460 0f287c2450 }
- $sequence_6 = { eb3a e8???????? 4c8bc0 80780500 7429 33d2 }
- $sequence_7 = { 4c89b690000000 4c89b698000000 0f108780000000 0f118680000000 0f108f90000000 0f118e90000000 4c89b790000000 }
- $sequence_8 = { 4c8bcf 4533c0 488d5510 488d4c2478 e8???????? 83cb01 }
- $sequence_9 = { 48895520 c744243402000000 41b840000000 458d78d0 418bd7 488d4d28 e8???????? }
+ $sequence_0 = { 0f840a010000 8d85ecfbffff 50 682a020000 68???????? 8b8df0fbffff }
+ $sequence_1 = { ff15???????? 8b8d54feffff 668901 6a10 8d855cfeffff 50 }
+ $sequence_2 = { 0fbe5415f8 33ca 8b4508 0345f4 8808 ebc7 5f }
+ $sequence_3 = { 8945fc 8b45fc 8b4d08 03483c 894df4 }
+ $sequence_4 = { 8808 ebc7 5f 5e 5b }
+ $sequence_5 = { 668b0d???????? 66894dfc 8a15???????? 8855fe 8d45f8 50 ff15???????? }
+ $sequence_6 = { 83e863 5f 5e 5b }
+ $sequence_7 = { 51 ff15???????? 8d85ecfeffff 50 e8???????? 83c404 85c0 }
+ $sequence_8 = { eb2c 33c0 eb2d 33c0 eb29 }
+ $sequence_9 = { e8???????? 83c404 6a01 8d85d0feffff 50 ff15???????? }
condition:
- 7 of them and filesize <971776
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Agendacrypt_Auto : FILE
+rule MALPEDIA_Win_Stegoloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "20fa12ae-39fc-589c-ac17-0baa3bbfd44a"
+ id = "e9d6ede2-9401-5de2-b06b-905a99f741c9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.agendacrypt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.agendacrypt_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stegoloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stegoloader_auto.yar#L1-L174"
license_url = "N/A"
- logic_hash = "b4f726649ba175df63b497d8d60f55fe36fe0cd2719e493aac65ae353f8a7651"
+ logic_hash = "b778718a0682061dce35a7f47c0081e22977d884e10f4fca4ca7c1e5214e1ed2"
score = 75
quality = 75
tags = "FILE"
@@ -149637,32 +156681,38 @@ rule MALPEDIA_Win_Agendacrypt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb20 8b55ec 8975e8 89f1 57 53 e8???????? }
- $sequence_1 = { 8d55b0 e8???????? eb25 c745b000000000 8d4dd0 8d55b0 e8???????? }
- $sequence_2 = { c1e204 88443110 89f8 f7d0 c1e004 f30f7e0403 f30f7e4c0308 }
- $sequence_3 = { c1c71a 31fa 8b7b04 89c3 339d70ffffff 0fcf 21cb }
- $sequence_4 = { e9???????? 8d543210 8b7508 f20f104a30 f20f114e40 f20f104a28 f20f114e38 }
- $sequence_5 = { f20f1101 8b55f0 8d4da8 ff7518 ff7514 ff7510 ff750c }
- $sequence_6 = { f20f1145c8 0f82de010000 80ff0a 894804 0f85c9000000 8b7d0c 8b55ec }
- $sequence_7 = { f20f114c2438 f20f108c2488000000 f20f11542430 f20f105028 f20f11442440 f20f115c2418 f20f1018 }
- $sequence_8 = { e8???????? e9???????? ffb424fc000000 e8???????? e9???????? e8???????? 89c3 }
- $sequence_9 = { ffd1 83c404 8b8c24a0190000 83790400 741f 8b84249c190000 83790809 }
+ $sequence_0 = { f7db 1bdb f7d3 235dfc 3bdf 7409 }
+ $sequence_1 = { 4a 75f0 8a043e 46 84c0 7669 0fb6c0 }
+ $sequence_2 = { 59 eb32 8bc8 837db806 }
+ $sequence_3 = { 59 7422 43 3b5e14 76e2 ff45fc 837dfc02 }
+ $sequence_4 = { 0f84f9010000 c645a443 c645a54d c645a644 }
+ $sequence_5 = { c645e968 c645ea65 c645eb6c c645ec6c c645ed5f c645ee54 c645ef72 }
+ $sequence_6 = { 7415 ff75f4 8bcb ff7604 }
+ $sequence_7 = { 8d0481 8b0438 03c7 3bc6 720e 8b4df0 03ce }
+ $sequence_8 = { ff742414 8bce ff5004 84c0 }
+ $sequence_9 = { 03df 8b03 03c7 33c9 3808 7407 }
+ $sequence_10 = { 8d0448 0fb70438 eb07 662b5e10 0fb7c3 8b4e1c }
+ $sequence_11 = { 83c604 4b 890411 75db eb0a }
+ $sequence_12 = { 33db 56 668945f4 83c002 33f6 3bd3 }
+ $sequence_13 = { 7e68 8b4d0c 8b4508 53 56 57 8b7d10 }
+ $sequence_14 = { 7409 8b01 6a01 ff10 897d0c }
+ $sequence_15 = { 8a4510 f6d8 1bc0 83e004 894510 e8???????? 3bc3 }
condition:
- 7 of them and filesize <3340288
+ 7 of them and filesize <802816
}
-rule MALPEDIA_Win_Comlook_Auto : FILE
+rule MALPEDIA_Win_Curator_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "860e6423-7c42-5b7a-b226-a660c40ee352"
+ id = "fc957193-82db-5d48-97f1-8bf3e9847701"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.comlook"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.comlook_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.curator"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.curator_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "4752c20623b9cb3b21f01ebe269fa3b02a3d0ecab0d63ba89a5af7bf48ed8b4a"
+ logic_hash = "a3bde063a66b4d9394e6eeb42680e73ad8b937005775febd69fd7690156b149c"
score = 75
quality = 75
tags = "FILE"
@@ -149676,32 +156726,32 @@ rule MALPEDIA_Win_Comlook_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c1ff1f 03c1 13d7 2b442434 b900000000 1bd1 33ff }
- $sequence_1 = { e8???????? 8d45e0 50 c645fc02 e8???????? 83c42c 8bd8 }
- $sequence_2 = { ff15???????? 83c404 3bf4 e8???????? b843000000 e9???????? c7854cffffff00000000 }
- $sequence_3 = { e8???????? 8b4e08 80791500 7579 8b01 80781401 7509 }
- $sequence_4 = { c1ed08 036e04 25ff000000 036c2414 8906 8b0f 0fb6c0 }
- $sequence_5 = { e9???????? 8b4518 0b451c 7509 33c0 33d2 e9???????? }
- $sequence_6 = { e8???????? 83c408 85c0 7410 8b4508 8b4df8 894858 }
- $sequence_7 = { e8???????? 8bf8 83c404 3bfb 0f8eab060000 c7463460210000 895e44 }
- $sequence_8 = { e8???????? a1???????? 33c4 89442418 53 8b5c2424 8b435c }
- $sequence_9 = { b8cccccccc 8945f0 8945f4 8945f8 8945fc 8b4508 0590050000 }
+ $sequence_0 = { 428a8c01e0590600 482bd0 8b42fc d3e8 49895708 41894718 0fb60a }
+ $sequence_1 = { 4903c1 483bc3 0f84b3000000 4983c004 413bca 72e0 488d6b10 }
+ $sequence_2 = { 7507 8bc6 e9???????? 44396728 0f8527010000 8d14f5ffffffff 488d4c2458 }
+ $sequence_3 = { 448b542424 be01000000 389c24b8000000 7449 385c2420 }
+ $sequence_4 = { 8b4308 25ffffff0f 3dffffff0f 740b 488b03 488bd8 4885c0 }
+ $sequence_5 = { 660f7ef9 d1c1 894a30 660f6dff 660f7ef9 c1c10a 890a }
+ $sequence_6 = { f60708 7505 4885c0 7508 48c7432000409901 488b5c2438 4883c420 }
+ $sequence_7 = { 4183fc01 740b 41bc01000000 e9???????? 488b4dd7 e8???????? 488b4ddf }
+ $sequence_8 = { 0f843ffeffff 488d55c0 488d4db0 e8???????? e9???????? 488d46ff 488905???????? }
+ $sequence_9 = { 0f4ed0 e8???????? 488d1517130400 488d4c2420 e8???????? cc }
condition:
- 7 of them and filesize <4553728
+ 7 of them and filesize <1265664
}
-rule MALPEDIA_Win_Powersniff_Auto : FILE
+rule MALPEDIA_Win_Quickmute_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1afa4094-a9fd-5e6f-8667-60dff005c0b1"
+ id = "3ebd5405-d3fe-5b1c-9991-79b28ea4d116"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.powersniff"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.powersniff_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.quickmute"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.quickmute_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "7ad286ca27751eb193f2579d1930e5287fef0e22f2b28df0af9c7874b91d42c3"
+ logic_hash = "94d7bee668e9656185345d12aa56e27e4c1baa2644d60d5f43d4b597af8c5206"
score = 75
quality = 75
tags = "FILE"
@@ -149715,34 +156765,34 @@ rule MALPEDIA_Win_Powersniff_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 ff35???????? 8945f8 895dfc }
- $sequence_1 = { 8b45f4 b94d5a0000 663908 7405 6a0b 5b eb0f }
- $sequence_2 = { 53 56 8b35???????? 57 8d85d8fdffff 50 33db }
- $sequence_3 = { c1eb10 8975fc 8b75f8 c1ee18 8b34b590780010 0fb6db }
- $sequence_4 = { 50 8d45f8 50 ff75fc e8???????? 8bd8 3bde }
- $sequence_5 = { c745fc08000000 eb09 ff15???????? 8945fc 8b45fc 5f 5e }
- $sequence_6 = { ff15???????? 8bf8 897df0 3bfb 7435 8d4508 50 }
- $sequence_7 = { 55 8bec 83ec0c 8b473c 03c7 53 8b9880000000 }
- $sequence_8 = { ff15???????? 85c0 0f84b4000000 8d8590feffff 50 ffd3 034574 }
- $sequence_9 = { a1???????? 53 68???????? ff750c 8945f8 ff7508 }
+ $sequence_0 = { 6a00 ff15???????? 50 ff15???????? 5f c3 }
+ $sequence_1 = { 750c 8d4dd8 51 56 }
+ $sequence_2 = { 8d55c0 52 56 ffd7 a3???????? 833d????????00 c6854cffffff54 }
+ $sequence_3 = { 8d9578edffff 52 6a03 ff15???????? 3bc3 745c }
+ $sequence_4 = { 885dae 391d???????? 750c 8d4da8 }
+ $sequence_5 = { 56 68???????? ff15???????? 83c408 8b751c }
+ $sequence_6 = { 7510 53 6a40 ff15???????? 53 }
+ $sequence_7 = { c7459030002900 c7459420006c00 c7459869006b00 c7459c65002000 }
+ $sequence_8 = { 6a00 50 8946f8 ff15???????? }
+ $sequence_9 = { c78542ffffff63746f72 66c78546ffffff7957 c68548ffffff00 750f }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <146432
}
-rule MALPEDIA_Win_Stinger_Auto : FILE
+rule MALPEDIA_Win_Red_Gambler_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "03e2d1ca-b846-5787-b683-28feb74dae3e"
+ id = "4317a3dc-c3fe-56b3-9554-1937ca266fd2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stinger"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stinger_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.red_gambler"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.red_gambler_auto.yar#L1-L292"
license_url = "N/A"
- logic_hash = "64d2d0bb18e9f4889ac80d1e49c5ab473a950fa26645e6f561f71db4e8eb08f3"
+ logic_hash = "7119f21e00db57c2b9d697114a153bc44616294e27589a57d490b5463e3562f7"
score = 75
- quality = 75
+ quality = 71
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -149754,32 +156804,54 @@ rule MALPEDIA_Win_Stinger_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bec 81ec10000000 6804000080 6a00 8b5d08 }
- $sequence_1 = { f6c441 0f854d010000 8b45f4 50 8b5d08 ff33 }
- $sequence_2 = { 895df8 8965f4 ff75fc ff15???????? 90 90 }
- $sequence_3 = { 6806000000 e8???????? 83c404 e9???????? 8be5 5d c21000 }
- $sequence_4 = { e9???????? 68???????? 8b5d0c ff33 e8???????? 83c408 }
- $sequence_5 = { a1???????? 85c0 891c85ecbe4000 750a }
- $sequence_6 = { 6806000000 e8???????? 83c404 a3???????? 8965f8 68???????? }
- $sequence_7 = { ff75fc 6802000000 bb94020000 e8???????? 83c41c 8945e8 }
- $sequence_8 = { 6800000000 6800000000 68???????? ff35???????? 6800000000 ff15???????? 90 }
- $sequence_9 = { 8b5d08 ff33 b902000000 e8???????? 83c408 8945f0 ff750c }
+ $sequence_0 = { 807e01a2 7535 807e02c3 752f 68???????? 68???????? ff15???????? }
+ $sequence_1 = { 68???????? c745ece80f13fc ffd6 a3???????? }
+ $sequence_2 = { 68ff000000 8d8df0fcffff 51 ff15???????? 85c0 }
+ $sequence_3 = { 3bf1 72bf 5e 33c0 5b }
+ $sequence_4 = { e8???????? 8bf8 83c404 83ffff 74e1 57 8d4c244c }
+ $sequence_5 = { 8d4c2414 51 6a40 6a07 }
+ $sequence_6 = { 68???????? 68???????? ffd6 5e 85c0 7505 }
+ $sequence_7 = { 894dec 8955f0 8945f4 ff15???????? }
+ $sequence_8 = { 2b2a bee7eee947 7c26 0e }
+ $sequence_9 = { 8d4d98 51 ff15???????? 8d5598 52 8d8598fdffff }
+ $sequence_10 = { 7456 7b78 cd50 d46e }
+ $sequence_11 = { bc340e65bc 691fd8727fcf 14cf fd }
+ $sequence_12 = { 9e e779 9e 54 }
+ $sequence_13 = { 51 ff15???????? 83c414 6a00 6a00 8d9598fbffff }
+ $sequence_14 = { ff15???????? 6800010000 8d8d98fdffff 51 8d9598feffff 52 }
+ $sequence_15 = { 52 8d8598fdffff 50 68???????? }
+ $sequence_16 = { 3c3d 9e e7bd e600 3e3e25162f062d }
+ $sequence_17 = { 6a00 6a00 8d9598fbffff 52 68???????? 6a00 6a00 }
+ $sequence_18 = { 50 4c 48 44 40 6c }
+ $sequence_19 = { 6800010000 8d8dfcfdffff 51 6a00 }
+ $sequence_20 = { 68???????? 8d8d98fbffff 68???????? 51 ff15???????? 83c414 }
+ $sequence_21 = { 7c0e 07 642827 3ccf }
+ $sequence_22 = { 8d9598feffff 52 ff15???????? 8d8594fbffff 50 8d4d98 51 }
+ $sequence_23 = { 6800010000 8d85fcfeffff 50 6a00 ff15???????? }
+ $sequence_24 = { 2f 74be 6f 665b }
+ $sequence_25 = { 68???????? ff15???????? 8b7508 c7465c486b4000 83660800 }
+ $sequence_26 = { 6888130000 ffd7 6800010000 8d95fcfeffff }
+ $sequence_27 = { 55 8bec 8b4508 ff34c5d0814000 }
+ $sequence_28 = { 8bf8 ffd3 8bd8 ffd7 8b3d???????? 6aff ffd7 }
+ $sequence_29 = { 83f805 7d10 668b4c4310 66890c4580974000 40 ebe8 }
+ $sequence_30 = { 6a5c 8d8dfcfeffff 51 ff15???????? }
+ $sequence_31 = { 8bec 8b4508 33c9 3b04cd10804000 }
condition:
- 7 of them and filesize <197096
+ 7 of them and filesize <327680
}
-rule MALPEDIA_Win_Komprogo_Auto : FILE
+rule MALPEDIA_Win_Ketrum_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c2da7eb7-9058-5d5c-a1b3-cf7ec20183b8"
+ id = "675a5c68-35f7-5e7a-83cc-0627e32f2bf0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.komprogo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.komprogo_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ketrum"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ketrum_auto.yar#L1-L174"
license_url = "N/A"
- logic_hash = "9104f7103ef4ffc58ac248efbbf51156333295a0a474355899a4b0ca03e1b39e"
+ logic_hash = "b179771de79024de54f910e3eea2ec187acafed93fd395a9caebde5421ab28f1"
score = 75
quality = 75
tags = "FILE"
@@ -149793,32 +156865,38 @@ rule MALPEDIA_Win_Komprogo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8670720300 89861b630000 8d96f0a80300 8996e51d0300 8d8e40490400 }
- $sequence_1 = { 8d86a82f0400 89862cb50200 8d86a8700300 89862cd50000 8d86f0380400 898616410200 8d8680720300 }
- $sequence_2 = { 51 8d8618cf0300 8bcf e8???????? 83c404 }
- $sequence_3 = { 8d96e4970300 899625080100 898633080100 8d96d0700300 8996e5650200 8d96f4380400 899643080100 }
- $sequence_4 = { 8d9614790300 899694e70300 8d86242c0400 8986c1210300 8d86e15c0300 898636ca0000 8d86a8ad0300 }
- $sequence_5 = { 0f859e000000 85f6 0f8496000000 8b433c 0fb7541814 }
- $sequence_6 = { 898e47bd0200 8d8e20e20300 898e4f7e0200 8d9694a30300 899674750300 8d8ea82f0400 898e897e0200 }
- $sequence_7 = { ff15???????? 8b95f0fdffff 8902 33db 85f6 7445 8bb5f0fdffff }
- $sequence_8 = { 52 ffd7 8b85d0f3ffff 50 ffd7 8b4df8 5f }
- $sequence_9 = { 8d86e0930200 8986d4930200 8d8ec1610300 898e14b20300 }
+ $sequence_0 = { 83e13f 5f 3bc8 7203 }
+ $sequence_1 = { 8d85fcebffff 50 8d85fcd3ffff 68???????? 50 ffd7 }
+ $sequence_2 = { ff15???????? ffb5f0cbffff ff15???????? ffb5e8cbffff ffb5f4cbffff }
+ $sequence_3 = { ab ab ab ab 68???????? 6a15 bf???????? }
+ $sequence_4 = { e8???????? 59 85db 7e15 57 8b7d08 2bfe }
+ $sequence_5 = { 33c0 0fb7f0 8bc6 c1e610 ba???????? }
+ $sequence_6 = { 7434 b9???????? 8bc1 8d7001 8a10 40 }
+ $sequence_7 = { 85c0 7404 33c0 eb5e 6880000000 56 }
+ $sequence_8 = { 397010 7699 837b1408 7204 8b13 eb02 }
+ $sequence_9 = { 8a4c181c 8888b0f74100 40 ebe9 33c0 8945e4 }
+ $sequence_10 = { 6a04 8d8520efffff 50 6a1f 57 }
+ $sequence_11 = { 8b8da4fdffff 2bc1 2bc6 50 03ce 51 }
+ $sequence_12 = { 3bf9 732c 8b16 3bd7 7726 8bc7 2bc2 }
+ $sequence_13 = { 8365fc00 83c074 50 8b4508 e8???????? }
+ $sequence_14 = { 89a570feffff 6a0f 5f 897e14 895e10 }
+ $sequence_15 = { 33ff 8d759c e8???????? 33c0 40 e8???????? }
condition:
- 7 of them and filesize <1045504
+ 7 of them and filesize <4599808
}
-rule MALPEDIA_Win_Marap_Auto : FILE
+rule MALPEDIA_Win_Lokipws_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2cc3d8fa-aa39-5bef-af3b-a091606785c2"
+ id = "51c802c9-41e6-5018-92e7-bd3c468d0c8a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.marap"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.marap_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lokipws"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lokipws_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "981ff96ccf9321bc9cf0b93466d635ede7fbc6c0341e04e670ea58028783ac37"
+ logic_hash = "c67ee200474ecbc3881960b10110e8aa7bde902411981013b30687544f7cfcf3"
score = 75
quality = 75
tags = "FILE"
@@ -149832,34 +156910,34 @@ rule MALPEDIA_Win_Marap_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 8386e41d000002 e9???????? 8386e41d000003 }
- $sequence_1 = { 7409 8386e41d000008 eb2f 84c0 7908 018ee41d0000 }
- $sequence_2 = { ff15???????? 8bf0 89b59cfbffff 83feff 7472 }
- $sequence_3 = { ff15???????? 85c0 7425 8b480c 8b11 8b02 }
- $sequence_4 = { 81fb00040000 737e 8bc7 8bd7 668b08 }
- $sequence_5 = { 0fbe84c1f8cb0010 6a07 c1f804 59 }
- $sequence_6 = { 83c40c 8d7bfe 668b4702 83c702 6685c0 75f4 }
- $sequence_7 = { 8d1c8580320110 8b03 83e71f c1e706 8a4c3824 }
- $sequence_8 = { 8d4310 8d8954f40010 5a 668b31 }
- $sequence_9 = { 80f901 0f8487000000 6683fa06 7519 84c0 }
+ $sequence_0 = { 55 8bec 83ec1c 6a2a 58 6a4d 668945e4 }
+ $sequence_1 = { 53 57 a3???????? e8???????? 68???????? 56 }
+ $sequence_2 = { 50 688b778dfe 50 e8???????? 8d4df8 }
+ $sequence_3 = { 6a00 ff75fc ff35???????? e8???????? 6a00 6a00 }
+ $sequence_4 = { 56 ff750c e8???????? 83c40c 85c0 7420 90 }
+ $sequence_5 = { 50 ff7508 8975fc e8???????? 8bf8 59 59 }
+ $sequence_6 = { 58 66895dc4 668975ca 66897dcc 66895dce 668955d0 66895dd2 }
+ $sequence_7 = { 6a02 e8???????? ff750c ff7508 ffd0 5d c3 }
+ $sequence_8 = { 668945f2 58 6a6e 668945f6 58 668945fa 33c0 }
+ $sequence_9 = { 83fe05 6a02 58 0f47f0 33db 43 3bf3 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <1327104
}
-rule MALPEDIA_Win_Op_Blockbuster_Auto : FILE
+rule MALPEDIA_Win_Krdownloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "25f80772-0fe0-5361-8b46-20a23fa9313b"
+ id = "5a82ae0a-fad8-52ec-9981-5ad40d1aeb9f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.op_blockbuster"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.op_blockbuster_auto.yar#L1-L321"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.krdownloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.krdownloader_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "7067748769cd92b2df2df661ece0caacb6285e4ff10828657376fad1bbae3d46"
+ logic_hash = "4501a2b9e4a10b142f4eeab904974c078e1ef98420195596ba39d05922e3a30d"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -149871,58 +156949,34 @@ rule MALPEDIA_Win_Op_Blockbuster_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 e8???????? 85c0 7407 83f802 }
- $sequence_1 = { f3ab 66ab aa 5f 85f6 }
- $sequence_2 = { ff15???????? 6808400000 6a40 ff15???????? }
- $sequence_3 = { 56 57 683c400000 6a40 }
- $sequence_4 = { e8???????? 6800400000 6a00 ff15???????? }
- $sequence_5 = { c701???????? 8b497c 85c9 7407 51 }
- $sequence_6 = { 8a08 80f920 7505 83c021 eb05 }
- $sequence_7 = { 68???????? 56 ff15???????? 68???????? 56 a3???????? e8???????? }
- $sequence_8 = { 56 50 8d45fc 6a04 50 }
- $sequence_9 = { 7412 68???????? 50 e8???????? 59 a3???????? 59 }
- $sequence_10 = { 3c70 7f04 0409 eb06 }
- $sequence_11 = { 3c69 7c08 3c70 7f04 }
- $sequence_12 = { 488b05???????? 4833c4 48898424d0030000 33c0 488be9 }
- $sequence_13 = { c3 56 53 6a01 57 e8???????? }
- $sequence_14 = { 56 6a00 ff15???????? 8bf8 85ff 7504 5f }
- $sequence_15 = { 8bc6 5f 5e c3 33c0 6a00 }
- $sequence_16 = { 33c0 ebac 498bcc ff15???????? 488d4d70 }
- $sequence_17 = { ff15???????? 85f6 7404 85c0 }
- $sequence_18 = { 57 e8???????? 56 e8???????? 83c414 b801000000 }
- $sequence_19 = { 68???????? 56 e8???????? 56 e8???????? 83c438 }
- $sequence_20 = { 0f84df010000 8b542444 488bcf 442bea 4585ed }
- $sequence_21 = { ff15???????? 85c0 0f84e7010000 488d558c 488d8dd0020000 ff15???????? }
- $sequence_22 = { c3 33c0 ebf8 53 33db 391d???????? 56 }
- $sequence_23 = { a3???????? 5e c3 68???????? ff15???????? 85c0 }
- $sequence_24 = { e8???????? 85c0 7429 488d542468 4c8bce 41b804000000 488bcf }
- $sequence_25 = { 83fb01 7524 488d942490010000 4d8bc4 488bcd }
- $sequence_26 = { 8b86d8974400 85c0 740e 50 e8???????? }
- $sequence_27 = { 83e03f 6bc830 8b0495d8974400 f644082801 7421 57 e8???????? }
- $sequence_28 = { c1fa06 8bc6 83e03f 6bc830 8b0495d8974400 885c0128 8b0495d8974400 }
- $sequence_29 = { 81ec54080000 56 57 33f6 b9ff010000 33c0 8dbdaef7ffff }
- $sequence_30 = { f3ab 8bca 83e103 f3aa 8b4df8 }
- $sequence_31 = { 57 50 ff5114 85c0 0f8c8c000000 }
- $sequence_32 = { ffd6 6a00 6a00 8d8424140c0000 6a00 }
- $sequence_33 = { 58 7577 ff7508 8b7d08 }
+ $sequence_0 = { c645e161 c645e22e c645e370 c645e468 c645e570 c645e63f c645e76d }
+ $sequence_1 = { 8b4df4 8b09 e8???????? 8945f0 }
+ $sequence_2 = { 7528 8b45fc 0345f4 0fb6482c 51 68???????? }
+ $sequence_3 = { e8???????? 8945d8 8b4dfc 51 8b55f8 }
+ $sequence_4 = { 7418 8b4dec 0fbe11 0fbe45f3 3bd0 }
+ $sequence_5 = { 8955f0 8b45f0 8945f8 c745d800000080 817d1000000080 7310 }
+ $sequence_6 = { c745f001000000 eb28 837d0c00 7422 6a04 68???????? 8b4d0c }
+ $sequence_7 = { 89815c0d0300 8b55fc 8b82500d0300 50 ff15???????? }
+ $sequence_8 = { 735e 8b4dfc 8b5134 83ea01 3955f4 }
+ $sequence_9 = { 83c001 8945fc 817dfc6f020000 7d63 8b4dfc 8b55f8 }
condition:
- 7 of them and filesize <74309632
+ 7 of them and filesize <352256
}
-rule MALPEDIA_Win_Jaku_Auto : FILE
+rule MALPEDIA_Win_Atmspitter_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2a488cc0-1b28-5098-bf2b-d901cf20342d"
+ id = "f9f02df1-a803-5665-939b-8200861b4172"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jaku"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jaku_auto.yar#L1-L268"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atmspitter"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atmspitter_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "d05d79a0c954b2e0606ed773ff3f73ae5387638edb50352f452263cfa013d18a"
+ logic_hash = "97d22d23e6b57a565b78835f63d6efbbbb7ac3961285afa1ce44048c0fb5a727"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -149934,51 +156988,32 @@ rule MALPEDIA_Win_Jaku_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b466c 234634 8b4e40 8b5644 668b7e6c 0fb70441 }
- $sequence_1 = { 0f84d0000000 8b4d1c 8b550c 0fb709 0fb71c4a }
- $sequence_2 = { c70610000000 eb1f 56 e8???????? 837d0c06 59 }
- $sequence_3 = { e8???????? 59 894660 59 837e6003 0f8223010000 }
- $sequence_4 = { 56 8b7510 57 6a08 33c0 59 }
- $sequence_5 = { 8b96a4160000 8a0408 8b8ea0160000 66892c4a 8b8e98160000 }
- $sequence_6 = { 6a0f 58 8d4dc6 8b17 }
- $sequence_7 = { 83c41c 84c0 742b 8b450c 85c0 }
- $sequence_8 = { 68???????? ff15???????? c3 b8???????? e8???????? 83ec2c }
- $sequence_9 = { ff742408 e8???????? c20800 8bc1 }
- $sequence_10 = { 5b c3 55 8bec 833d????????00 53 56 }
- $sequence_11 = { 53 68000000a0 6a03 53 }
- $sequence_12 = { 6a01 03c3 68???????? 50 e8???????? 83c40c 85c0 }
- $sequence_13 = { 7507 b800308000 eb02 33c0 }
- $sequence_14 = { 7508 83c8ff e9???????? 8b839f830000 }
- $sequence_15 = { 75dd 57 e8???????? 59 }
- $sequence_16 = { 55 56 57 6880020000 }
- $sequence_17 = { 0245fd 3245fe 8a4dff d2c8 }
- $sequence_18 = { 016c242c 8b44242c 5f 5e 5d }
- $sequence_19 = { 50 e8???????? 59 8b4e2c }
- $sequence_20 = { 85f6 b301 0f8491000000 56 e8???????? }
- $sequence_21 = { e8???????? 59 eb57 53 }
- $sequence_22 = { 56 e8???????? 59 8b4620 }
- $sequence_23 = { 8d4608 57 e8???????? 8365e000 }
- $sequence_24 = { e8???????? 8b7dd8 397de8 7593 6804010000 8d8574feffff 50 }
- $sequence_25 = { a4 ff839f830000 8b839f830000 8b8b97830000 8901 33c0 40 }
- $sequence_26 = { ff75f4 66899e4d720000 8d9e8f7e0000 53 81c6917e0000 }
- $sequence_27 = { 6a00 e8???????? 50 e8???????? b001 8b55b4 64891500000000 }
- $sequence_28 = { 6a00 53 e8???????? 0fbe532e }
+ $sequence_0 = { a900800000 7422 68???????? e8???????? 83ec24 }
+ $sequence_1 = { 8be5 5d c3 8b5c2420 33c0 89442450 }
+ $sequence_2 = { 56 89442418 e8???????? 83c40c 8bf0 8974244c }
+ $sequence_3 = { a4 c744241831323000 88542422 c744242800000080 89442430 }
+ $sequence_4 = { 8b442410 50 53 8d4c2468 68???????? 51 ff15???????? }
+ $sequence_5 = { c3 8b04cd14c04000 5d c3 }
+ $sequence_6 = { 8975e0 8db190c84000 8975e4 eb2b 8a4601 }
+ $sequence_7 = { 6a03 6816011200 68???????? ff15???????? 6a02 6a00 8bf8 }
+ $sequence_8 = { 83c404 8d442420 50 ff15???????? a900800000 7422 }
+ $sequence_9 = { 6a00 57 ff15???????? 6a00 8d45fc }
condition:
- 7 of them and filesize <2220032
+ 7 of them and filesize <147456
}
-rule MALPEDIA_Win_Hesperbot_Auto : FILE
+rule MALPEDIA_Win_Krbanker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a7df8c05-0ba7-5df5-beac-3b2d7fa2a54e"
+ id = "236e4eb3-f9a9-5a5c-939d-2dd344c94ac6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hesperbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hesperbot_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.krbanker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.krbanker_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "791429e92dde914e6ba42c9451f8338c991a26d1b1d12ebf3b674c1fb1ca0de1"
+ logic_hash = "d1369d0e33548d319048c3c036e2e47c22a922a80b7ada061139a11ddd9f8b91"
score = 75
quality = 75
tags = "FILE"
@@ -149992,32 +157027,32 @@ rule MALPEDIA_Win_Hesperbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33f0 8b442440 0b442438 33cf 23442448 8b7c2444 8b5c2440 }
- $sequence_1 = { f60602 740e 8bc6 e8???????? 85c0 7403 8326fd }
- $sequence_2 = { 85f6 7454 817d0818040000 724b 57 8b3e }
- $sequence_3 = { 59 59 85c0 741e ff7510 8b450c 8d4ddc }
- $sequence_4 = { 8d45ec b975382414 46 e8???????? 8d45ec 6a10 50 }
- $sequence_5 = { 03f3 837f1800 7639 8b0e 03cb e8???????? 3b4508 }
- $sequence_6 = { 8b01 eb0b 8b5008 3b54240c }
- $sequence_7 = { c9 c3 64a130000000 c3 55 8bec 83ec48 }
- $sequence_8 = { 56 33f6 85c0 741a 0fb71471 83fa41 720c }
- $sequence_9 = { 7308 e8???????? 33d2 42 }
+ $sequence_0 = { 83c404 58 8945dc 837ddc00 }
+ $sequence_1 = { 83c404 58 8945fc b8???????? 50 }
+ $sequence_2 = { 6801000000 bb40010000 e8???????? 83c410 8945c8 6801010080 6a00 }
+ $sequence_3 = { 0faf03 ebf5 8bc8 c3 55 8bec 83c4f4 }
+ $sequence_4 = { 75a4 dd442410 e8???????? 8ad8 }
+ $sequence_5 = { 7762 7415 3d04000080 7417 3d01010080 }
+ $sequence_6 = { bb40010000 e8???????? 83c410 8945cc ff75cc ff75d0 }
+ $sequence_7 = { 8a5c2410 8ac3 5e 5b c3 8b542410 83ec0c }
+ $sequence_8 = { 8b5dfc 83c304 895df8 8965f4 ff7514 }
+ $sequence_9 = { 03d8 895dd4 8b5df8 e8???????? }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <1826816
}
-rule MALPEDIA_Win_Heloag_Auto : FILE
+rule MALPEDIA_Win_Httpdropper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ef07a0f3-faff-581a-a00e-f3d94c2f2e27"
+ id = "eb6cb470-4fa5-55f1-aaf4-34eabe7782e1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.heloag"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.heloag_auto.yar#L1-L169"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.httpdropper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.httpdropper_auto.yar#L1-L165"
license_url = "N/A"
- logic_hash = "d41534ff803a8c13a09a17ccbef4333268f3c2d9e67aea8ce8ca3bb7d4a205eb"
+ logic_hash = "c6973c071283bf0dc986d288edaa8567196f172f5da7a23c655925f94d3c03cb"
score = 75
quality = 75
tags = "FILE"
@@ -150031,38 +157066,38 @@ rule MALPEDIA_Win_Heloag_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 66ab aa 83c9ff 8bfe 33c0 }
- $sequence_1 = { 8bf7 8bfa 8a15???????? c1e902 f3a5 8bc8 }
- $sequence_2 = { 8d4dbc 51 ffd7 8b45c4 b919000000 }
- $sequence_3 = { 8b0d???????? 51 e8???????? 6a14 e8???????? 8bf0 83c408 }
- $sequence_4 = { f3a4 a2???????? a2???????? a3???????? }
- $sequence_5 = { 7cc4 8b45fc 8b0d???????? 40 }
- $sequence_6 = { 6a00 6a00 ffd0 33c9 a3???????? 85c0 0f95c1 }
- $sequence_7 = { 8d8dacfdffff 68???????? 51 e8???????? 8b55b4 83c41c 66c745b80200 }
- $sequence_8 = { 8b4e0c 3bcd 8b07 89442410 7464 }
- $sequence_9 = { 894b0c 8a48ff fec1 8848ff eb3c 6a01 55 }
- $sequence_10 = { 8b4108 50 e8???????? 6a01 }
- $sequence_11 = { 85c0 7505 a1???????? 8b4c242c }
- $sequence_12 = { 51 53 68???????? 8d4c2420 ff15???????? }
- $sequence_13 = { 8a442413 6a00 8bce 8806 ff15???????? }
- $sequence_14 = { 8b11 8bcf 52 6a00 50 ff15???????? }
- $sequence_15 = { a1???????? 894304 8b5608 895308 8b4e0c 894b0c }
+ $sequence_0 = { 8d4c243c 51 8d54241c 52 53 }
+ $sequence_1 = { 51 6a00 6a00 68???????? 52 c745f404000000 }
+ $sequence_2 = { 7506 c60100 49 ebec 8bc3 }
+ $sequence_3 = { e8???????? 6804010000 8d95edfdffff 6a00 52 c685ecfdffff00 }
+ $sequence_4 = { 7414 57 c6470300 e8???????? 83c404 }
+ $sequence_5 = { 51 8d95ecf8ffff 68???????? 52 e8???????? 8d85f4fdffff }
+ $sequence_6 = { 6802000080 ff15???????? 8b85d8fbffff 8d8ddcfbffff 51 }
+ $sequence_7 = { c685d4f4ffff00 e8???????? 57 68ff030000 }
+ $sequence_8 = { 33c0 ba01000000 f2ae 448bc2 48f7d1 48ffc9 }
+ $sequence_9 = { 48c7c102000080 4889442438 48897c2430 c74424283f000f00 897c2420 }
+ $sequence_10 = { 33d2 41b804010000 c68424f000000000 e8???????? 488d15520f0200 488d8c24f0000000 }
+ $sequence_11 = { 488bfb 488d73ff f2ae 48f7d1 48ffc9 }
+ $sequence_12 = { 0fb7cd 4889442428 6689742428 4889442430 ff15???????? 488bcf }
+ $sequence_13 = { e8???????? 488d8d81040000 33d2 41b87f0c0000 }
+ $sequence_14 = { c1e808 418bd1 4032c7 4a0fbebc35da020000 81e2fdff0000 }
+ $sequence_15 = { 488d4df0 e8???????? b801000000 e9???????? }
condition:
- 7 of them and filesize <401408
+ 7 of them and filesize <524288
}
-rule MALPEDIA_Win_Teslacrypt_Auto : FILE
+rule MALPEDIA_Win_Unidentified_041_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cf4cf463-c704-58da-bdf6-218fd6a96530"
+ id = "54c40e17-80e5-57a5-babe-281dfc0f14df"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.teslacrypt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.teslacrypt_auto.yar#L1-L177"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_041"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_041_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "204f6818406ce562647f2b4540c54737aa88569de9afd450b681fd9a49a46e00"
+ logic_hash = "72336cc9bc2b4e7b40dbb912cf40721cd5c8d54310aa5ce8f7ef42d8a402b398"
score = 75
quality = 75
tags = "FILE"
@@ -150076,40 +157111,34 @@ rule MALPEDIA_Win_Teslacrypt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 31f7 897d24 31f9 894d28 31ca 89552c 89d0 }
- $sequence_1 = { 334534 894554 334538 894558 }
- $sequence_2 = { 3345f8 894518 3345fc 89451c 51 52 89f2 }
- $sequence_3 = { 0f8452030000 81ffc0000000 0f84ac010000 81ffe0000000 740a b8ffffffff }
- $sequence_4 = { 31f7 897d44 31f9 894d48 31ca }
- $sequence_5 = { 334538 894558 33453c 89455c 51 52 89f2 }
- $sequence_6 = { 31f7 897d04 31f9 894d08 }
- $sequence_7 = { 335d04 334d08 33550c 81ffa0000000 0f8456030000 }
- $sequence_8 = { 0f842d010000 8b44243c 8b08 83f900 894c2430 741f 8b442464 }
- $sequence_9 = { 8b4c2430 01c8 8b542474 8b742470 031406 891406 }
- $sequence_10 = { 890c24 e8???????? 8d0dc1304b00 8b542410 894208 890c24 }
- $sequence_11 = { 8902 83f800 894c2408 7432 8b442418 83c004 }
- $sequence_12 = { 31c0 8b4c2414 29c8 8b54240c 21c2 01ca 89542408 }
- $sequence_13 = { b801000000 8b4c245c 8b9180000000 8b742464 01d6 8b7c2464 8b54170c }
- $sequence_14 = { c70100000000 c7410c00000000 c7410800000000 8b0d???????? 8b4920 8b742450 8b7a38 }
- $sequence_15 = { 8b5120 89e6 8d7c2468 897e0c }
+ $sequence_0 = { ff761c ff7618 ff7304 e8???????? 8d45bf c645bf0d 50 }
+ $sequence_1 = { 885d9b e9???????? 391f 75c7 385e04 752e }
+ $sequence_2 = { 8b3f 8d44242c 50 53 68???????? 57 6a02 }
+ $sequence_3 = { c645fc02 8b08 52 53 50 ff5118 85c0 }
+ $sequence_4 = { eb05 be57000780 5f 8bc6 5e 5b c20400 }
+ $sequence_5 = { 85c0 7509 56 e8???????? 59 eba7 8d47ff }
+ $sequence_6 = { ff75e0 e8???????? 8b45f0 83c418 2b06 8bce c1f802 }
+ $sequence_7 = { 7430 ff7508 8bfe 33c0 ab ab ab }
+ $sequence_8 = { ff5024 85c0 0f8889040000 33c0 8dbd22fdffff 66898520fdffff ab }
+ $sequence_9 = { 8d8d54ffffff e8???????? 8bc6 e9???????? ff15???????? 50 8d8d28ffffff }
condition:
- 7 of them and filesize <1187840
+ 7 of them and filesize <1097728
}
-rule MALPEDIA_Win_Industroyer_Auto : FILE
+rule MALPEDIA_Win_Isfb_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9c6bfb9f-c466-5000-a18a-b1782556f295"
+ id = "2206addc-4ea1-5ebc-8989-ba5f49383e7b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.industroyer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.industroyer_auto.yar#L1-L379"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.isfb"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.isfb_auto.yar#L1-L1623"
license_url = "N/A"
- logic_hash = "10be42e3e137c59c80c36fac63f4d878185befa45cbf0b3714b0e9925e862e84"
+ logic_hash = "dcaa8c2fe85dec9e7e215d7d6083b8c053dc5e8814c7849f4addcdf0f2d4a23f"
score = 75
- quality = 73
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -150121,62 +157150,212 @@ rule MALPEDIA_Win_Industroyer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 50 ff750c ff15???????? 8d45fc 50 8d45f8 }
- $sequence_1 = { 68f4010000 ff15???????? 33c0 50 }
- $sequence_2 = { 50 8945e0 e8???????? 8945f8 e8???????? 50 8945e4 }
- $sequence_3 = { 6808020000 50 ff7710 ff15???????? }
- $sequence_4 = { ff7710 6a03 56 e8???????? 83c424 894708 85c0 }
- $sequence_5 = { ff15???????? 8bd8 8d8598fdffff 6804010000 50 68???????? ff15???????? }
- $sequence_6 = { 6a02 50 53 68000000c0 56 c745f40c000000 895dfc }
- $sequence_7 = { 6a4c e8???????? 8bf0 8d8510ffffff 6a4c }
- $sequence_8 = { 8bf9 ff15???????? 3bf8 0f84bb000000 }
- $sequence_9 = { 8b7508 ff7604 8b06 ffd0 56 e8???????? }
- $sequence_10 = { ffd6 85c0 7431 ff35???????? }
- $sequence_11 = { 8bd8 85db 0f849d000000 8d85d0fdffff c785d0fdffff2c020000 50 53 }
- $sequence_12 = { 683f010f00 6a00 8d85a0f3ffff 50 6802000080 ff15???????? 85c0 }
- $sequence_13 = { 85c0 0f85bb000000 6800020000 8d85a0fbffff 50 }
- $sequence_14 = { bfffff0000 0f46f9 3d00005000 b900400000 }
- $sequence_15 = { 8d8c2468020000 e8???????? 8d442418 50 ff742414 ff15???????? }
- $sequence_16 = { eb07 8b0cc5dc084100 894de4 85c9 }
- $sequence_17 = { 0f8501010000 c745e0e4ff4000 8b4508 8bcf }
- $sequence_18 = { 6a0a 8854382a 8b048dd01f0210 8874382b 8b048dd01f0210 5a }
- $sequence_19 = { 0f8580000000 8b4508 dd00 ebc6 c745e0e8ff4000 }
- $sequence_20 = { 6689823e020000 0fb68340020000 888240020000 8d8344020000 50 e8???????? }
- $sequence_21 = { 50 ff15???????? 6a02 ff15???????? 50 ffd6 ff770c }
- $sequence_22 = { 0fb605???????? 88413e 0f1005???????? 0f118133010000 a1???????? 898143010000 }
- $sequence_23 = { 83e901 740d 83e902 7521 }
- $sequence_24 = { 660f28b820004100 660f54f0 660f5cc6 660f59f4 660f5cf2 f20f58fe }
- $sequence_25 = { 807b0100 0f85fc000000 a840 0f85d5000000 ff35???????? ff15???????? }
- $sequence_26 = { 89422c 0fb64330 884230 0fb64331 884231 0fb64332 }
- $sequence_27 = { 746a ff7508 8b15???????? 51 8bcb e8???????? }
- $sequence_28 = { 85c0 7450 6aff 56 ff15???????? }
- $sequence_29 = { ba???????? 0f94c1 884b32 84c9 a1???????? f30f7e05???????? }
- $sequence_30 = { 8b442418 89442440 8d44243c 50 ff15???????? 50 }
- $sequence_31 = { ff15???????? 68???????? ff15???????? 85c0 7417 68???????? }
- $sequence_32 = { 83c410 84c0 0f84b9010000 8b8520ffffff 8bbd1cffffff 2bc7 }
- $sequence_33 = { 8d4dc8 ff30 e8???????? 8d4d84 83ff02 0f86a4000000 }
- $sequence_34 = { e8???????? 6a00 56 8d8d08feffff e8???????? }
- $sequence_35 = { 8bce 8907 53 894704 e8???????? 8b4308 }
- $sequence_36 = { 53 8b1c85205e4400 56 6800080000 }
- $sequence_37 = { 8945e4 8d83bc000000 50 e8???????? 6a28 e8???????? }
- $sequence_38 = { 0fb7c1 8945f8 3905???????? 7f26 663b4df4 7320 }
- $sequence_39 = { 33c5 8945fc 8365e000 53 8b5d0c 56 }
+ $sequence_0 = { e8???????? eb02 33c0 3bc7 741b 50 }
+ $sequence_1 = { 741b 50 33c0 e8???????? 3bc7 }
+ $sequence_2 = { ff75f0 ff75f4 6822010000 e9???????? ff7508 }
+ $sequence_3 = { 58 e8???????? 3bc7 7406 50 }
+ $sequence_4 = { 3bc7 7413 50 6a10 58 e8???????? }
+ $sequence_5 = { ff35???????? e8???????? 8bf0 3bf3 7443 6aff 68806967ff }
+ $sequence_6 = { 50 e8???????? 83c40c e8???????? 3bc7 }
+ $sequence_7 = { 6a64 ff15???????? a1???????? 85c0 7407 83ee64 }
+ $sequence_8 = { ff35???????? ff15???????? 85c0 a3???????? 7402 ffe0 c20400 }
+ $sequence_9 = { 5d 5b 59 c20400 8325????????00 6a00 68???????? }
+ $sequence_10 = { 7406 50 e8???????? 3bdf 7414 }
+ $sequence_11 = { a1???????? 85c0 751a 68???????? ff35???????? ff15???????? 85c0 }
+ $sequence_12 = { 3c05 7506 84e4 7704 3ac0 }
+ $sequence_13 = { c20400 55 8bec 83ec0c a1???????? 8365f800 }
+ $sequence_14 = { 2b55fc 8b7d10 0155fc 83451004 }
+ $sequence_15 = { 83e103 740d 51 50 ff7510 e8???????? 83c40c }
+ $sequence_16 = { 0155fc 83451004 83c004 49 8917 75e9 }
+ $sequence_17 = { 7417 8b10 2b55fc 8b7d10 }
+ $sequence_18 = { 3bc3 7512 e8???????? 3bc3 a3???????? }
+ $sequence_19 = { 895df4 0f84c7000000 56 53 }
+ $sequence_20 = { b8???????? 7505 b8???????? 53 bb60ea0000 }
+ $sequence_21 = { 68000f0000 e8???????? 8bd8 85db 895df4 0f84c7000000 }
+ $sequence_22 = { 837b240c 56 57 8b3b 897c241c 760a 8b4b20 }
+ $sequence_23 = { 894b34 8b4b24 2b4b28 894c2410 8b4b34 f6c140 }
+ $sequence_24 = { 58 e8???????? 85c0 740d 8906 83c604 }
+ $sequence_25 = { 8b442418 894110 836334f9 c7432c01000000 8b4334 }
+ $sequence_26 = { e8???????? 8b4320 897324 897328 83c40c 8974240c c6401a00 }
+ $sequence_27 = { 57 33ff 3bdf 7414 }
+ $sequence_28 = { ff35???????? 0fc8 50 a1???????? }
+ $sequence_29 = { 8a4604 2404 f6d8 1bc0 }
+ $sequence_30 = { c6400731 8b74241c 8b1e 6a00 ff37 ff15???????? 2b442414 }
+ $sequence_31 = { ff15???????? 8b442414 8b4c240c 8907 8b442418 }
+ $sequence_32 = { 83ec14 8364240400 53 8b5d0c 837b240c 56 }
+ $sequence_33 = { 2b442414 50 8b07 03442418 50 56 ff5310 }
+ $sequence_34 = { 837d0800 7408 ff7508 e8???????? 8bc7 5f 5e }
+ $sequence_35 = { 752f 8b450c 8930 eb33 }
+ $sequence_36 = { 74a3 33ff eb0b 33ff eb03 }
+ $sequence_37 = { 6a01 33db 53 ff35???????? e8???????? 8bf0 }
+ $sequence_38 = { 50 8d4508 50 53 8bc6 }
+ $sequence_39 = { 8bd1 83c128 4e 7404 3bd0 74e7 3bd0 }
+ $sequence_40 = { 488bcf c744242860ea0000 4c0f45c8 48895c2420 }
+ $sequence_41 = { 3bc8 7415 8b5210 3bd0 }
+ $sequence_42 = { 53 8bc6 e8???????? 85c0 7516 }
+ $sequence_43 = { 6a0b eb02 6a02 58 }
+ $sequence_44 = { 85ff 750e 837d0800 7408 }
+ $sequence_45 = { 488bcf ff15???????? 4c8964dd00 83c301 4885ff 4c8be7 }
+ $sequence_46 = { 498bcc ff15???????? 33db 66ba2000 }
+ $sequence_47 = { 415c 5f 5e 5d 5b c3 8b4754 }
+ $sequence_48 = { 75c4 48892e eb02 33db 488b0d???????? 885e08 }
+ $sequence_49 = { c21000 55 8bec 83ec14 a1???????? 53 }
+ $sequence_50 = { 53 b800080000 50 56 ff35???????? }
+ $sequence_51 = { e8???????? be01000000 8bc6 4883c440 415e }
+ $sequence_52 = { 33db 66ba2000 498bcc ff15???????? 4885c0 }
+ $sequence_53 = { e8???????? 85c0 742d ff75fc 6a0d }
+ $sequence_54 = { 742d ff75fc 6a0d 58 e8???????? 85c0 }
+ $sequence_55 = { ff15???????? 4885c0 488be8 7453 }
+ $sequence_56 = { 4c0f45c8 48895c2420 e8???????? 85c0 8bd8 }
+ $sequence_57 = { 51 50 57 6a01 ff75e0 68???????? e8???????? }
+ $sequence_58 = { ff15???????? bb01000000 498bcc eb07 83c301 488d4801 66ba2000 }
+ $sequence_59 = { 8bd5 488bcf bb57000000 e8???????? }
+ $sequence_60 = { e8???????? 3bc3 740f 8b35???????? 50 83c604 }
+ $sequence_61 = { a810 ff750c 7535 68???????? ff75f8 }
+ $sequence_62 = { ff75f8 ffd6 8b4df4 66c7015c00 }
+ $sequence_63 = { 8945e0 e8???????? 85c0 0f84dc000000 8b45e0 8d4de0 3bc1 }
+ $sequence_64 = { 33db 53 ff35???????? c745f408000000 ff15???????? 3bc3 8945f8 }
+ $sequence_65 = { 6641b85c00 33d2 488bcd ff15???????? }
+ $sequence_66 = { 50 83c604 e8???????? 3bfb }
+ $sequence_67 = { b90e010000 41b800000100 4889442420 e8???????? e9???????? }
+ $sequence_68 = { 6a01 e8???????? 85db 7423 8b0d???????? }
+ $sequence_69 = { 50 e8???????? 3bfb 7414 }
+ $sequence_70 = { 72c1 eb0c bb7f000000 eb05 bb7e000000 }
+ $sequence_71 = { 33d2 ff15???????? 488bdf 8bf7 483bdf }
+ $sequence_72 = { 4883c608 83fd05 72c1 eb0c }
+ $sequence_73 = { 3bc3 8945f4 741a ff750c 668918 68???????? }
+ $sequence_74 = { 50 8bd7 e8???????? eb02 33c0 3bc3 7413 }
+ $sequence_75 = { a840 0f84e2000000 8b7334 8d442418 50 8d442410 50 }
+ $sequence_76 = { 8b7508 e8???????? 33f6 3975fc }
+ $sequence_77 = { ff7510 57 ff750c 53 e8???????? 3bfe 740e }
+ $sequence_78 = { 0f8544010000 8b472c a801 742d ff37 e8???????? 85c0 }
+ $sequence_79 = { e8???????? 3bfe 740e 57 56 ff35???????? ff15???????? }
+ $sequence_80 = { ff5214 8bf7 8bfe e8???????? 5f 5e }
+ $sequence_81 = { 5b 8be5 5d c20800 8b4330 a804 0f8451ffffff }
+ $sequence_82 = { c744242000010000 ff15???????? 4883f8ff 488bf8 7442 }
+ $sequence_83 = { ff15???????? 53 56 ff35???????? ff15???????? 5b 5f }
+ $sequence_84 = { 3975fc 7410 ff75fc 56 ff35???????? ff15???????? 53 }
+ $sequence_85 = { 83bc248800000000 4c8b442440 488b542448 894c2430 }
+ $sequence_86 = { 752e 53 e8???????? 6a01 6a01 }
+ $sequence_87 = { 56 ff35???????? 8945f8 ff15???????? 8bd8 3bde }
+ $sequence_88 = { e8???????? 85c0 0f85d7000000 8b4604 }
+ $sequence_89 = { 7505 894720 eb0b 8b4f30 84c9 0f8992000000 }
+ $sequence_90 = { 83632800 e9???????? 8b4330 a840 0f84e2000000 8b7334 }
+ $sequence_91 = { 0f854affffff 894330 e9???????? 55 }
+ $sequence_92 = { c9 c20400 51 56 ff74240c }
+ $sequence_93 = { 4803df 410fb64101 33d2 488d0cc3 }
+ $sequence_94 = { 85d2 4d8bf1 458bf8 8bc2 }
+ $sequence_95 = { e8???????? 8d45fc 50 8b4508 e8???????? }
+ $sequence_96 = { 50 57 e8???????? e9???????? 68???????? }
+ $sequence_97 = { ff15???????? 488bcf 48870d???????? 483bcf }
+ $sequence_98 = { 33db 895d08 eb03 8b5d08 }
+ $sequence_99 = { 488d0cc3 48890d???????? 410fb64103 488d0cc3 }
+ $sequence_100 = { ff15???????? 4885db 740c 4c8b0d???????? e9???????? }
+ $sequence_101 = { c3 418bd8 4803df 410fb64101 }
+ $sequence_102 = { e8???????? 85c0 7507 33db 895d08 }
+ $sequence_103 = { 488bce ff15???????? 488b0d???????? 33d2 4c63c0 }
+ $sequence_104 = { 6a00 ff35???????? ff15???????? 33db 6a01 }
+ $sequence_105 = { 8a4b1c 488b4558 4c8b4d30 4c8b4510 }
+ $sequence_106 = { 448be8 418b4310 41394308 410f474308 }
+ $sequence_107 = { 488d0cc3 48890d???????? 410fb64102 488d0cc3 }
+ $sequence_108 = { 33d2 ff15???????? 483bc3 4c8be8 }
+ $sequence_109 = { 33d2 498bcc 498bfd e8???????? 493bc5 7405 }
+ $sequence_110 = { 5b c3 a1???????? 83c040 50 ff15???????? eb08 }
+ $sequence_111 = { 8b3d???????? 56 ffd7 53 56 }
+ $sequence_112 = { e8???????? 0945fc 47 83c304 3b3e 72dc 8b45fc }
+ $sequence_113 = { c9 c20400 53 56 8bf0 8a06 }
+ $sequence_114 = { 8bf1 05fefeffff 33db 33c9 }
+ $sequence_115 = { 8b02 43 8acb d3c0 33c6 33442410 8bf0 }
+ $sequence_116 = { ff15???????? 8ac3 5b c9 c20400 53 }
+ $sequence_117 = { 8bf0 8932 83c204 ff4c240c 75e6 5e 5b }
+ $sequence_118 = { 4533c9 4889442428 215c2420 4533c0 }
+ $sequence_119 = { 50 8d442430 50 8d442428 50 8d442428 }
+ $sequence_120 = { 480f45f2 832700 458be0 bb08000000 }
+ $sequence_121 = { ff15???????? 4c8d4c2450 4c8d442458 8d5001 488bce e8???????? 85c0 }
+ $sequence_122 = { ff15???????? 4883f8ff 4c8be0 0f8583000000 488b0d???????? 4d8bc5 }
+ $sequence_123 = { e9???????? 33c9 bb26040000 48870d???????? }
+ $sequence_124 = { ff15???????? 49bb00c0692ac9000000 488bcf 4c019c24d8010000 ff15???????? 6641b85c00 33d2 }
+ $sequence_125 = { 83c701 e9???????? 488b8424c8010000 498bcc bb01000000 4c8928 }
+ $sequence_126 = { ff15???????? 488d542440 488bcd ff15???????? 4883f8ff }
+ $sequence_127 = { 4c8bc7 33d2 ff15???????? 33ff 4885ff }
+ $sequence_128 = { 488bd6 ff15???????? eb14 488b0d???????? 4c8bc7 33d2 }
+ $sequence_129 = { 6a00 ff35???????? ffd3 8bd8 85db 7476 }
+ $sequence_130 = { 41b905000000 488bd8 ff15???????? 488bcb }
+ $sequence_131 = { 4c8be8 0f841c010000 448b05???????? 33d2 488bc8 4c33c7 e8???????? }
+ $sequence_132 = { 7416 a1???????? 83c004 50 be???????? }
+ $sequence_133 = { 498bcf ff15???????? 448bf0 488bce ff15???????? }
+ $sequence_134 = { 895df4 895df0 c745f857000000 bf19010000 }
+ $sequence_135 = { 7520 41390424 741a 498d4c2401 }
+ $sequence_136 = { 488b0d???????? 448bc0 8bd8 33d2 4983c001 }
+ $sequence_137 = { a1???????? 25efff0000 0bc2 e9???????? }
+ $sequence_138 = { 4c63c0 33d2 4983c00c ff15???????? }
+ $sequence_139 = { 215c2420 4533c9 4533c0 33d2 ff15???????? 85c0 7511 }
+ $sequence_140 = { 6a03 8935???????? 8935???????? 8935???????? }
+ $sequence_141 = { e9???????? 488bcb ff15???????? a810 }
+ $sequence_142 = { 803f2a 750b 4883c701 83c3ff }
+ $sequence_143 = { 41be01000000 33c9 418bd6 ff15???????? }
+ $sequence_144 = { 53 56 8bf1 05fefeffff }
+ $sequence_145 = { 57 4154 4155 4156 4883ec50 488bf1 }
+ $sequence_146 = { 5e 33c0 c9 c20400 55 8bec 51 }
+ $sequence_147 = { 4889040f 4883c708 492bf6 75db }
+ $sequence_148 = { 8bc6 e8???????? 8b06 8b08 57 ff7510 }
+ $sequence_149 = { 750a 488bcf e8???????? 8bd8 488b0d???????? 4c8bc7 }
+ $sequence_150 = { 5f c20400 55 8bec 83e4f8 81ec9c000000 }
+ $sequence_151 = { 488d542438 488bcb e8???????? eb02 }
+ $sequence_152 = { 8bc7 e8???????? 8d4618 8b08 50 51 }
+ $sequence_153 = { 6a20 40 50 ffd6 }
+ $sequence_154 = { 488bd3 ff15???????? 488b8c2428020000 8bf0 ff15???????? }
+ $sequence_155 = { 7417 4863461c 2b6e1c 4c03e8 488b4610 48894718 }
+ $sequence_156 = { 21442428 488b8c2428020000 488364242000 448d4803 }
+ $sequence_157 = { 21b42410020000 eb0d ff15???????? 89842410020000 }
+ $sequence_158 = { 488bcb ff15???????? 8bc8 ff15???????? 21b42410020000 }
+ $sequence_159 = { 4885c9 7405 e8???????? 4883c428 c3 488d82204a0000 488982284a0000 }
+ $sequence_160 = { 418bcd e8???????? 8b842410020000 4c8d9c24f0010000 }
+ $sequence_161 = { 488b15???????? 4c8d842428020000 48c7c101000080 ff15???????? }
+ $sequence_162 = { e8???????? 5e 5f c9 c3 51 53 }
+ $sequence_163 = { 50 57 6a01 ff7508 ffd6 85c0 742b }
+ $sequence_164 = { 448bcf 4533c0 e8???????? 483bc3 488905???????? 0f84dc000000 }
+ $sequence_165 = { e8???????? 488b0d???????? 4c8bc3 33d2 ff15???????? 488b0d???????? 4c8bc7 }
+ $sequence_166 = { 4c8d40cc 33d2 33c9 e8???????? 85c0 0f8561010000 }
+ $sequence_167 = { 7415 397b44 7510 488b0b e8???????? 85c0 0f859b000000 }
+ $sequence_168 = { ffc1 807c043000 7531 8bd3 2bd1 8917 }
+ $sequence_169 = { 84c0 0f89a3000000 8b434c a804 7415 397b44 7510 }
+ $sequence_170 = { 7505 217b3c eb0b 8b434c 84c0 0f89a3000000 8b434c }
+ $sequence_171 = { 85c0 0f8561010000 8b4348 a801 742c }
+ $sequence_172 = { 742c 488b0b e8???????? 85c0 0f85e8000000 488b4608 488b0e }
+ $sequence_173 = { 85c0 0f859b000000 4863533c 488b4608 }
+ $sequence_174 = { ba10000000 488bc8 e8???????? 48898424e0010000 4885c0 }
+ $sequence_175 = { 4c8d442470 488d542440 e8???????? 8bd8 85c0 }
+ $sequence_176 = { 33d2 468d44385f ff15???????? 4c8bf0 }
+ $sequence_177 = { 488bf8 4885c0 7427 488d542420 b901020000 ff15???????? 85c0 }
+ $sequence_178 = { 4c89642448 ff15???????? 8bd8 83f8ff }
+ $sequence_179 = { 488bc8 458bf9 33ff e8???????? 4c8be8 4885c0 7508 }
+ $sequence_180 = { 8bd8 85c0 0f85f3010000 4c8b842418020000 8d5808 488d8c24b0000000 4d85c0 }
+ $sequence_181 = { 448d4256 ff15???????? 4c8be0 4885c0 0f8405010000 ff15???????? }
+ $sequence_182 = { 90 57 51 8b742420 8b7c241c 8b4c2434 }
+ $sequence_183 = { 56 57 51 90 8b742428 }
+ $sequence_184 = { 8b5508 035510 8b3a 83c204 }
+ $sequence_185 = { 01f2 6683f9ff 896c2428 7508 }
+ $sequence_186 = { eb67 8044241301 0fb6ca 01cb 30c9 eb59 }
+ $sequence_187 = { 83c304 894c2410 56 90 }
+ $sequence_188 = { 5e 01d5 01d3 b101 3b5c2428 0f8266ffffff }
+ $sequence_189 = { 8b5d10 6601da c1ca03 895510 3010 }
condition:
- 7 of them and filesize <983040
+ 7 of them and filesize <2940928
}
-rule MALPEDIA_Win_Gup_Proxy_Auto : FILE
+rule MALPEDIA_Win_Phandoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5c3bfea3-920f-5316-9eb6-180474d2cca9"
+ id = "1f3ac76b-bd09-5712-8c06-9b7787ce6d6a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gup_proxy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gup_proxy_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phandoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.phandoor_auto.yar#L1-L152"
license_url = "N/A"
- logic_hash = "d81f0061756179ec05e7cc548d81d0721d972a5a55f0d637cdd705d25b38ea90"
+ logic_hash = "bcca1bd5fcc5f942c80e8300ebd91840d93d57fc52bf130291de8a118788c527"
score = 75
quality = 75
tags = "FILE"
@@ -150190,32 +157369,37 @@ rule MALPEDIA_Win_Gup_Proxy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c744244400000000 c644243400 e8???????? c784242002000000000000 8d4c2444 6a00 }
- $sequence_1 = { c1e606 03348510974100 33db 395e08 }
- $sequence_2 = { 8b04bd10974100 830c06ff 33c0 eb16 e8???????? c70009000000 }
- $sequence_3 = { c1f805 c1e606 8b048510974100 80643004fd 8b45f8 8b55fc 5f }
- $sequence_4 = { c78588feffffc22eab48 50 8bce e8???????? 8bc3 889d88feffff c1e818 }
- $sequence_5 = { c3 b8???????? c705????????61984000 a3???????? c705????????f2984000 c705????????4c994000 c705????????d1994000 }
- $sequence_6 = { c784242002000000000000 8d4c2444 6a00 68???????? c74424600f000000 c744245c00000000 c644244c00 }
- $sequence_7 = { ebb4 c745e4d8a04100 a1???????? eb1a c745e4d4a04100 a1???????? }
- $sequence_8 = { ff15???????? 8b04bd10974100 830c06ff 33c0 }
- $sequence_9 = { 53 ff15???????? 83f8ff 752a 32c0 }
+ $sequence_0 = { 0f8482000000 833d????????00 7479 833d????????00 7470 833d????????00 }
+ $sequence_1 = { 833d????????00 0f8452010000 833d????????00 0f8445010000 833d????????00 }
+ $sequence_2 = { 83c40c 83c302 3bbe90010000 72d7 }
+ $sequence_3 = { 83c404 8d55fc 8bf0 52 56 }
+ $sequence_4 = { 0f84c7010000 833d????????00 0f84ba010000 833d????????00 0f84ad010000 833d????????00 }
+ $sequence_5 = { 50 8bf9 c645f400 c745f500000000 e8???????? }
+ $sequence_6 = { 32d3 32d0 8b45f4 81e1fe010000 c1e018 0b45f8 }
+ $sequence_7 = { a3???????? a3???????? a3???????? a3???????? 898de8feffff }
+ $sequence_8 = { 83c404 893e 8b4604 3bc7 740c }
+ $sequence_9 = { 6a01 51 52 8b5508 }
+ $sequence_10 = { 668901 5e c3 33d2 }
+ $sequence_11 = { 33c0 3b35???????? 7327 57 }
+ $sequence_12 = { 56 8b35???????? 57 68???????? 50 c705????????03000000 }
+ $sequence_13 = { 6a01 53 51 8bc8 }
+ $sequence_14 = { 56 8b7308 85f6 7420 }
condition:
- 7 of them and filesize <247808
+ 7 of them and filesize <2124800
}
-rule MALPEDIA_Win_Cmsbrute_Auto : FILE
+rule MALPEDIA_Win_Simda_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8f79cbd4-e913-5f2c-8c88-b934c5aa8f71"
+ id = "be795d70-d5c5-5e96-885a-c6d393925d47"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cmsbrute"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cmsbrute_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.simda"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.simda_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "9b2fd3bf8cbe0036d7312658e08a3f69e7f5e49973eb02bc9f177311ac61fa60"
+ logic_hash = "3de0f7a52fa615dd54916d8a958f210fe06f4ad101457fb659a131786ec59f6f"
score = 75
quality = 75
tags = "FILE"
@@ -150229,32 +157413,32 @@ rule MALPEDIA_Win_Cmsbrute_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff7004 51 ff7510 8b4d08 ff750c 56 e8???????? }
- $sequence_1 = { e8???????? ff4de0 8bde 75e4 8b75d8 832700 6a00 }
- $sequence_2 = { ffb068010000 ff15???????? 8b06 83a06801000000 8b442418 59 59 }
- $sequence_3 = { eb0f e8???????? 59 50 8d75b4 e8???????? 59 }
- $sequence_4 = { eb02 8b01 3945fc 0f8d8a000000 8b45fc e8???????? 8bf0 }
- $sequence_5 = { ff75c4 8b4dcc ff75d4 8bd8 0fb7463e 50 53 }
- $sequence_6 = { eb02 33ff 8bb59cfdffff 51 e8???????? 59 85ff }
- $sequence_7 = { ff75e4 57 e8???????? 83c414 85c0 7425 8bf7 }
- $sequence_8 = { ff742430 e8???????? 89442430 8b4304 8378041b 8b30 8b7808 }
- $sequence_9 = { ff15???????? 8945cc 8b35???????? 83cfff 3bdf 7403 53 }
+ $sequence_0 = { 50 c745fc04010000 a4 e8???????? }
+ $sequence_1 = { 3bce 8945f4 1bc0 40 57 895dfc }
+ $sequence_2 = { c7049f00000000 75f6 8b0f 894d08 }
+ $sequence_3 = { 760d 8b7d08 83c704 8d4eff 33c0 }
+ $sequence_4 = { c1e110 0b4df4 03d6 83ceff 2bca }
+ $sequence_5 = { 8b0d???????? 8945d4 a1???????? 8955dc 0fb615???????? }
+ $sequence_6 = { c1eb10 3bce 7601 4b c1ef10 }
+ $sequence_7 = { 83c408 85c0 74e4 6a0a 6a00 56 c60000 }
+ $sequence_8 = { 8bd1 c1ea10 8955ec 8bf8 }
+ $sequence_9 = { 41 eb08 83c102 eb03 83c103 }
condition:
- 7 of them and filesize <5275648
+ 7 of them and filesize <1581056
}
-rule MALPEDIA_Win_Ramsay_Auto : FILE
+rule MALPEDIA_Win_Strifewater_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "419ecbad-236d-5c68-9c96-e25af72dd2b4"
+ id = "a7c325df-e174-5ac3-901f-1a7ff4cd21d1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ramsay"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ramsay_auto.yar#L1-L167"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.strifewater_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.strifewater_rat_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "eb3826746ddecabb3a90d33f9a9bdc63a3e0601a54105640bc672d97b2815450"
+ logic_hash = "d8e033b18ffd1945f4234d82e35ef039ad0fd09fec88b912a93b43fc77397cc7"
score = 75
quality = 75
tags = "FILE"
@@ -150268,40 +157452,34 @@ rule MALPEDIA_Win_Ramsay_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7514 ff15???????? 83f820 }
- $sequence_1 = { 83f820 7502 eb07 33c0 e9???????? }
- $sequence_2 = { ff15???????? 85c0 7502 eb02 ebb1 }
- $sequence_3 = { 83c201 8955f8 837df808 731e 8b45f8 }
- $sequence_4 = { 894df1 884df5 c745ec00000000 6a06 8d55f0 52 }
- $sequence_5 = { 83c404 8945f8 8b4d08 83c101 51 6a00 8b55f8 }
- $sequence_6 = { 8b02 ba02000000 f7e2 0f90c1 f7d9 }
- $sequence_7 = { 8945f8 837df8ff 7507 33c0 e9???????? 6a00 8b4df8 }
- $sequence_8 = { 8a481c 884a15 8b5508 8b4508 }
- $sequence_9 = { 3b4d08 732c e8???????? 33d2 b93e000000 }
- $sequence_10 = { ff15???????? 85c0 751a 8b4df8 51 }
- $sequence_11 = { ff15???????? 33c0 e9???????? e8???????? 85c0 7507 33c0 }
- $sequence_12 = { e8???????? eb2b 83f8ff 7526 4c8d253b490100 }
- $sequence_13 = { e8???????? eb20 488d542470 488d0d1afa0100 e8???????? 4533c0 33d2 }
- $sequence_14 = { e8???????? eb2d 4863442468 488b4c2458 }
- $sequence_15 = { e8???????? eb31 488b8c2428110000 e8???????? }
+ $sequence_0 = { 83630800 488d0d10400500 48890b c6434400 448ac6 488bd0 }
+ $sequence_1 = { 4183c9ff 4d8bc7 66448926 4889742420 8d4a03 ff15???????? f7d8 }
+ $sequence_2 = { 663b3d???????? 0f8559010000 663b1d???????? 0f854c010000 66443b35???????? 0f853e010000 }
+ $sequence_3 = { 488d05bb720600 488bf9 488901 8bda 488b4910 e8???????? 488b4f18 }
+ $sequence_4 = { 4803c0 480101 4803db eb22 498b06 498bce }
+ $sequence_5 = { 488bf8 48898424c0000000 488b4e08 4885c9 7509 488d15fc350900 eb0d }
+ $sequence_6 = { 0903 e9???????? 488d05d8940500 0f100f 0f1006 f30f7f4dd0 f30f7f45e0 }
+ $sequence_7 = { 418d45ff 410fb68c8332b30800 410fb6b48333b30800 8bd9 }
+ $sequence_8 = { 498b4e08 4c8d4508 33d2 ff15???????? 488b7508 4c8d4530 488bce }
+ $sequence_9 = { 884dd8 488bd3 482bd7 48d1fa 4883fa0f 7426 41b001 }
condition:
- 7 of them and filesize <2031616
+ 7 of them and filesize <1552384
}
-rule MALPEDIA_Win_Gozi_Auto : FILE
+rule MALPEDIA_Win_Newposthings_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4c65f4c6-680c-5313-afa1-f0c350a0bb9e"
+ id = "d2908836-d6a9-5323-a30e-68bb82428f91"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gozi"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gozi_auto.yar#L1-L297"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.newposthings"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.newposthings_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "d1afd0d2426cb263c17dc36f11639d4b538234ba95ec55283f83783334fcf5d3"
+ logic_hash = "aacccdc30f2a004211f7fc15df6e0bf41cf9693ce7a4e367dede73ae07376ff4"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -150313,54 +157491,32 @@ rule MALPEDIA_Win_Gozi_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4dfc f3a4 b0e9 aa }
- $sequence_1 = { ee 7f7b 36110b 33745571 de7e75 cd18 4a }
- $sequence_2 = { 3327 72e7 3ebb4a68d947 d93e 257296bc4a 1b6b61 9f }
- $sequence_3 = { e8???????? 0bc0 7522 6a01 6a00 }
- $sequence_4 = { 2bfb 8b5518 8b12 6a00 }
- $sequence_5 = { 4e b64e 0fc0d6 69d5920d9cef }
- $sequence_6 = { 0fadce 80eede c0ca12 2af4 8af4 }
- $sequence_7 = { 894598 50 e8???????? 8b4650 8b7c0704 }
- $sequence_8 = { 83c101 894df4 8b55ec 83ea02 3955f4 0f8d45040000 }
- $sequence_9 = { 94 6e 8ee1 54 }
- $sequence_10 = { 7516 c78554ffffff06000000 c78558ffffff00000000 eb14 }
- $sequence_11 = { bf???????? 8bdf c70747494638 66c747043761 83c706 8b450c }
- $sequence_12 = { c9 50 0c73 0e 96 3b5375 }
- $sequence_13 = { ffd7 03f0 56 53 33f6 56 }
- $sequence_14 = { ad b710 2dc7ce5bbb d6 b6c6 }
- $sequence_15 = { ff75e4 ffd0 c3 6a68 68???????? e8???????? }
- $sequence_16 = { 0f8229feffff 5f 5e 5b c9 c21000 }
- $sequence_17 = { c9 c20800 6a00 8d87950c0000 }
- $sequence_18 = { 84c1 0fb3ea f6c1ba 0fce }
- $sequence_19 = { 96 3b5375 60 d3e0 90 48 }
- $sequence_20 = { 69d5ca659407 f6de c645ff61 a1???????? 8b0d???????? 6a00 }
- $sequence_21 = { 83c101 894d90 0fb755e4 52 8b4590 }
- $sequence_22 = { b87e8da638 e022 3a56b9 036890 2b02 9a102a6715fb53 }
- $sequence_23 = { dc6f1b 95 bf633629a8 02738f }
- $sequence_24 = { 83bd54ffffff03 7c0a c78554ffffff00000000 eb95 33c0 8b55f4 }
- $sequence_25 = { 0fbe4415ec 8b8d4cffffff 038d58ffffff 0fbe11 33d0 8b854cffffff }
- $sequence_26 = { 41 4e 75ea 5e }
- $sequence_27 = { 0f8447010000 83f8ff 0f843e010000 682000cc00 56 }
- $sequence_28 = { 837df800 75c7 ff75fc e8???????? c9 }
- $sequence_29 = { 0fb3ce 86d6 2af4 b252 b0ca c745fc00000000 }
- $sequence_30 = { e8???????? 59 8bf0 89b5e0f2ffff }
- $sequence_31 = { 85c0 7404 8365f800 85f6 7407 8b06 }
+ $sequence_0 = { 8a4601 3c30 7c04 3c39 7e0a 3c3d 7406 }
+ $sequence_1 = { 7423 3d00000400 7550 80c980 884c3704 8b0c9d481d0210 8a443124 }
+ $sequence_2 = { 83e61f 8b0485481d0210 c1e606 80643004fd 8b45f8 8b55fc 5f }
+ $sequence_3 = { ff7510 ff750c 56 6843120110 e8???????? 83c418 85c0 }
+ $sequence_4 = { 83c602 663906 74f8 6a03 56 68548e0110 e8???????? }
+ $sequence_5 = { 50 c644245c00 8bce e8???????? 8bf0 eb02 33f6 }
+ $sequence_6 = { e8???????? 50 8bcb e8???????? c745fc00000000 c745f001000000 8bc3 }
+ $sequence_7 = { 8b049538f34500 47 ff3418 ff15???????? 85c0 750a ff15???????? }
+ $sequence_8 = { 83c204 8955e0 eb86 890cb538f34500 }
+ $sequence_9 = { e8???????? c745fc00000000 83ec18 8bcc 896588 6aff }
condition:
- 7 of them and filesize <568320
+ 7 of them and filesize <827392
}
-rule MALPEDIA_Win_3Cx_Backdoor_Auto : FILE
+rule MALPEDIA_Win_Unidentified_039_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "28fbb43b-1b49-58bb-9ada-865931dff5e6"
+ id = "79803854-9c28-5ee4-826a-7f1227d74ba5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.3cx_backdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.3cx_backdoor_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_039"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_039_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "c22c772229b5508424567ef1d7e35b9960a69d5aa0f1d8dfccaad31a703d6c0c"
+ logic_hash = "58c8fb21d6ae978d62ed7528cfbdb8da381c56d520ca5623fbbc73c80d3173d3"
score = 75
quality = 75
tags = "FILE"
@@ -150374,32 +157530,32 @@ rule MALPEDIA_Win_3Cx_Backdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bc8 c1e907 33c1 81c287d61200 8bc8 c1e116 33c1 }
- $sequence_1 = { 84d2 7430 3811 742c e8???????? c70016000000 }
- $sequence_2 = { 8bfb 48895c2430 4c89742428 4983e7f0 4d8d243f 498d442410 }
- $sequence_3 = { 4a0fbe841940250300 428a8c1950250300 482bd0 8b42fc d3e8 49895108 41894118 }
- $sequence_4 = { 4c8bce 4c8bc5 488bd7 498bcf e8???????? 498bc6 488b5c2460 }
- $sequence_5 = { 498bd7 4489642448 48897c2440 44894c2438 4c8d4d97 4889442430 4489642428 }
- $sequence_6 = { 7428 85db 7524 488d0d7ef90200 e8???????? 85c0 7510 }
- $sequence_7 = { 4889742458 488b7108 33d2 488bce 48c1eb05 492bc9 }
- $sequence_8 = { 4983c708 4533d2 32d2 4c897c2420 80fb30 7512 b201 }
- $sequence_9 = { 0fb608 880a 488d5210 488b4808 48894af8 448820 }
+ $sequence_0 = { b8???????? e8???????? 8365fc00 8365cc00 c745dce7600000 c745ec89640000 }
+ $sequence_1 = { c745f00b090000 c745f089000000 8975c0 c745f4b76e0000 c745fc9e540000 c745f8a7600000 }
+ $sequence_2 = { c74530284c0000 c7453425120000 c745281f480000 c74538136b0000 c74520825d0000 c7451c84360000 8b4530 }
+ $sequence_3 = { 69c9de3f0000 33c1 8945dc 8b4510 8b4d0c 3bc8 7d0c }
+ $sequence_4 = { 8bec 51 51 c745f81d2d0000 c745f8d33a0000 c745fc9a790000 }
+ $sequence_5 = { c745d0e5720000 8b45d0 8b4dd4 0fafc1 8b4dd8 8b55dc }
+ $sequence_6 = { 6bc01f c1e704 83c30c 03fa 33d2 }
+ $sequence_7 = { 69c0295a0000 8945e4 e8???????? c745e0f9750000 c745f0b56c0000 c745ec29110000 }
+ $sequence_8 = { 8d45f4 64a300000000 c3 6a00 6a01 ff74240c }
+ $sequence_9 = { c745e863430000 8b45e4 59 8b4df8 23c1 8b4de8 81e931570000 }
condition:
- 7 of them and filesize <585728
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Fast_Pos_Auto : FILE
+rule MALPEDIA_Win_Void_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2b4b0c9d-f48b-554f-8a11-82dc9864cf63"
+ id = "71ce776b-404f-5334-912d-5acada68aa35"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fast_pos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fast_pos_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.void"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.void_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "cc5eee3320509f0e654a55f4440afe73bd9962689fcfc57ca050257ab2933ad2"
+ logic_hash = "c9d396773d78302d4ad6bf52fbcd07db1d946f6b7dffcc9d3a1efd465ff43099"
score = 75
quality = 75
tags = "FILE"
@@ -150413,32 +157569,30 @@ rule MALPEDIA_Win_Fast_Pos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c785e4feffff04010000 ff15???????? e8???????? 8bc8 33c0 }
- $sequence_1 = { e8???????? 8b95e4feffff 83c408 85c0 0f9485ebfeffff 83c2f0 }
- $sequence_2 = { 52 8d8de0feffff e8???????? 8bb5e0feffff 6a44 8d857cfeffff }
- $sequence_3 = { 6a00 6a00 68???????? ffb5e8feffff ff15???????? 85c0 7517 }
- $sequence_4 = { c645fc07 e8???????? 8bf0 c645fc08 ff15???????? }
- $sequence_5 = { 68???????? 56 c785e8feffff01000000 e8???????? 83c40c 8bc6 }
- $sequence_6 = { 68ffff1f00 ff15???????? 6a00 50 }
- $sequence_7 = { e8???????? 6a10 68???????? 68???????? 6a00 ff15???????? 6a00 }
- $sequence_8 = { 50 ff36 8d85e0feffff 68???????? }
- $sequence_9 = { 5d c20400 8b01 6a01 ff76f4 ff10 8bf8 }
+ $sequence_0 = { 6a09 8d4c2410 51 50 e8???????? 85c0 7518 }
+ $sequence_1 = { 5d c20c00 6a00 ff750c 50 e8???????? 50 }
+ $sequence_2 = { 807d6b00 0f8483000000 6a02 8d4dc4 e8???????? 8d45c4 c745fc02000000 }
+ $sequence_3 = { 0f43c6 50 ff7514 8d45ac ff7510 50 53 }
+ $sequence_4 = { 5b 8bc1 8b4c2440 5e 5d 33cc e8???????? }
+ $sequence_5 = { 7473 8d4dec 8975ec e8???????? 53 8bcf 8b00 }
+ $sequence_6 = { 854110 7419 8d45e4 6a01 50 e8???????? 83c408 }
+ $sequence_7 = { 894610 c1e102 51 8d0490 6a00 50 e8???????? }
condition:
- 7 of them and filesize <327680
+ 7 of them and filesize <2744320
}
-rule MALPEDIA_Win_Auriga_Auto : FILE
+rule MALPEDIA_Win_Chinotto_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3e414b5e-c2de-5c81-b4bc-c099cfe4cd7e"
+ id = "eb163619-c453-5aad-acb2-63f8cb2fc096"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.auriga"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.auriga_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chinotto"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chinotto_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "cddd7158b581ccab9be1a01dbee785ac04d84e6e50041126742a64808d1b3062"
+ logic_hash = "68ff4e71579a9ee7d4f8a0767737ed2f326ba91b5ade5aa40e96479fa8db4fb8"
score = 75
quality = 75
tags = "FILE"
@@ -150452,32 +157606,32 @@ rule MALPEDIA_Win_Auriga_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 90 5f bb???????? 81eb???????? 2bfb 8bf7 e8???????? }
- $sequence_1 = { 755b 817e0c03001200 7552 57 }
- $sequence_2 = { e8???????? c9 c20c00 ffb508fcffff 8b8504fcffff 8d8405fcfbffff }
- $sequence_3 = { 4a 3bda 745e 7345 2bd3 }
- $sequence_4 = { 7408 8b0d???????? 8908 56 8b7508 837e0400 7422 }
- $sequence_5 = { 53 53 6a01 6a01 56 ff15???????? 8945dc }
- $sequence_6 = { 84c0 7511 ff7510 ff15???????? }
- $sequence_7 = { ff45fc 8b4dec ff4df8 2bcb 295df4 ff45f8 }
- $sequence_8 = { ffd3 8b45fc 85c0 7539 ff750c 8d45f4 }
- $sequence_9 = { 8b85e8fbffff 85c0 7566 ffb5ecfbffff 8d85f0fbffff }
+ $sequence_0 = { 034d0c 53 56 57 8b7848 8b774c }
+ $sequence_1 = { 6a1a e8???????? 8bd8 b906000000 be???????? 8bfb f3a5 }
+ $sequence_2 = { c745f800000000 8955c8 85d2 7505 ba02000000 8b461c 8bf8 }
+ $sequence_3 = { 57 8945f0 8d5801 740e 8b4e1c 2b4e40 }
+ $sequence_4 = { 837dfc00 7514 837dd000 0f8421080000 837e2000 0f8417080000 }
+ $sequence_5 = { 8d8dd0fbffff 68???????? 51 ffd6 83c418 8d95a4f1ffff 52 }
+ $sequence_6 = { 8b5620 57 8b7e24 8bc2 0bc7 7412 8bc2 }
+ $sequence_7 = { 8a08 40 84c9 75f9 2bc7 8b7d18 }
+ $sequence_8 = { 83c434 5f 5e 33cd 8d85e0fdfcff 5b }
+ $sequence_9 = { 8b471c 50 0fafc1 034710 8d55f8 }
condition:
- 7 of them and filesize <75776
+ 7 of them and filesize <300032
}
-rule MALPEDIA_Win_Faketc_Auto : FILE
+rule MALPEDIA_Win_Taleret_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "17b42993-c08e-510a-afaa-62243000eea0"
+ id = "90652d3d-3308-5c4e-91b0-de6f7ec4ea56"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.faketc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.faketc_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.taleret"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.taleret_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "d424513e0804264658899ed0249bf1311c7683556fe66475d3d53a03a7ef5219"
+ logic_hash = "0af9ed1f3725609b54a6e19f400c5abe16095e727614fae56d9f4e23ded04fd2"
score = 75
quality = 75
tags = "FILE"
@@ -150491,32 +157645,32 @@ rule MALPEDIA_Win_Faketc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? c684248001000002 8b442448 8b5004 8bce ffd2 84c0 }
- $sequence_1 = { e8???????? 83c410 6a5e 8d8576f7ffff 50 6a00 6a00 }
- $sequence_2 = { 899158010000 8b4508 8b484c 8b55f8 668b4104 66894248 8b4df8 }
- $sequence_3 = { e8???????? 83c410 6a00 8b4d8c 51 6a01 8b5508 }
- $sequence_4 = { ffd6 50 b86f000000 e8???????? 83c404 a3???????? eb06 }
- $sequence_5 = { e9???????? 8d45d8 50 e8???????? c3 8d8548ffffff 50 }
- $sequence_6 = { c1fa04 8bc2 c1e81f 03c2 895c2410 0f842b010000 895c241c }
- $sequence_7 = { e8???????? 8b85b0fdffff 8b0d???????? 8d95b8fdffff 52 68???????? 50 }
- $sequence_8 = { e8???????? b917000000 8bf0 bf???????? f3a5 66a5 c745fc02000000 }
- $sequence_9 = { c745fc???????? c745f805000000 eb0e c745fc???????? c745f806000000 8b4d08 8b91fc030000 }
+ $sequence_0 = { c68424b40300000d e8???????? 50 8d4b18 }
+ $sequence_1 = { 8b44240c 8b4c2408 8b542404 6a00 6a00 6a03 68???????? }
+ $sequence_2 = { 51 50 68???????? 890d???????? }
+ $sequence_3 = { 8d442408 c744242401000000 50 ff15???????? 85c0 7528 8b4c2438 }
+ $sequence_4 = { 8d4e3c c644241c05 e8???????? 8d4e40 c644241c06 e8???????? }
+ $sequence_5 = { c60600 e8???????? 83c40c 85c0 7526 57 8d8c24e8000000 }
+ $sequence_6 = { 85c0 0f85b2000000 a1???????? 668b0d???????? 8a15???????? 89842480000000 }
+ $sequence_7 = { c684247016000001 e8???????? 8b9c247c160000 8b6c241c e9???????? 8b442424 8b4c2414 }
+ $sequence_8 = { 8a440444 eb02 b03d 83fd01 884301 7e33 }
+ $sequence_9 = { e8???????? 83c408 33f6 e8???????? 8a96f0700010 32d0 }
condition:
- 7 of them and filesize <6864896
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Makadocs_Auto : FILE
+rule MALPEDIA_Win_Carberp_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a9ee5e42-4244-5209-b209-43e241078b80"
+ id = "ca3e7da8-ad9c-59f4-8614-8b1382409083"
date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.makadocs"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.makadocs_auto.yar#L1-L132"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.carberp"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.carberp_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "9e569b2ca005ed56a66b13fc4754517215725a380988d948b175ea6348c2d54c"
+ logic_hash = "1e5a666bd6ef8c024c58bd150c2d57a0675cba836a8af1e051301be69118758b"
score = 75
quality = 75
tags = "FILE"
@@ -150530,32 +157684,32 @@ rule MALPEDIA_Win_Makadocs_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b5d08 56 57 33f6 33ff 897dfc 3b1cfdf0524200 }
- $sequence_1 = { 8bc6 89a554ffffff 8bfc e8???????? 83c010 8907 51 }
- $sequence_2 = { 8b42f4 8d7001 8b42f8 b901000000 2b4afc 2bc6 0bc1 }
- $sequence_3 = { 83c408 52 8b54243c 8d442438 50 8d4c2478 51 }
- $sequence_4 = { 83c408 c644246834 8b00 8d4c2420 51 8bc8 e8???????? }
- $sequence_5 = { 8b442410 56 e8???????? 85f6 7409 }
- $sequence_6 = { c645fc41 8bc4 89a54cffffff 50 b9???????? e8???????? 8dbd54ffffff }
- $sequence_7 = { ffd5 8b06 3b78f8 7f0f 8978f4 8b0e c6040f00 }
- $sequence_8 = { 8b4c2410 51 ffd7 85c0 744c 8b44241c 50 }
- $sequence_9 = { 3c09 0fb6c0 7605 83c037 eb03 83c030 8806 }
+ $sequence_0 = { b8???????? 50 6a00 50 e8???????? 8b4518 8945e4 }
+ $sequence_1 = { 68f5a40f7d 6a0d 6a00 e8???????? 68da6772c2 6a0d 6a00 }
+ $sequence_2 = { ff75fc 56 ff15???????? 8bf0 8d45f8 50 e8???????? }
+ $sequence_3 = { 0f848d000000 6683f832 0f8483000000 6683f821 0f8548010000 57 8d8588fdffff }
+ $sequence_4 = { 7407 50 e8???????? 59 ff45f4 8b45f4 3b45f0 }
+ $sequence_5 = { 668945f6 58 6a72 668945f8 58 6a5c 668945fa }
+ $sequence_6 = { ff7658 e8???????? 83c418 83665800 5e 5d c3 }
+ $sequence_7 = { 59 59 85f6 7419 ff7510 56 6a04 }
+ $sequence_8 = { 6800000040 ff7508 ffd0 8bf8 83ffff 7504 33c0 }
+ $sequence_9 = { c645f867 c645f96c c645fa57 c645fb6e c645fc64 885dfd 895dc8 }
condition:
- 7 of them and filesize <344064
+ 7 of them and filesize <491520
}
-rule MALPEDIA_Win_Alpc_Lpe_Auto : FILE
+rule MALPEDIA_Win_Zeus_Openssl_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1d3d4f14-881f-5a73-b345-a76e12b3dfd0"
+ id = "8c3065fc-d922-5a5a-97bb-f5578c899954"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alpc_lpe"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alpc_lpe_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus_openssl"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeus_openssl_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "21b1493d78b90781647fb0ea2e97a709ccc21e177ddf748dd3e2118819bbc37e"
+ logic_hash = "87e8b70576343bf43fa1d91175bc18c4648aa0bc5e7b7de2b8eae5131a311e26"
score = 75
quality = 75
tags = "FILE"
@@ -150569,34 +157723,34 @@ rule MALPEDIA_Win_Alpc_Lpe_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ba31000000 4c8d05b3a10000 448bcb 482bd6 e8???????? 4883c603 881f }
- $sequence_1 = { 4533c0 48c7c102000080 4889442420 ff15???????? ff15???????? 488b4c2448 }
- $sequence_2 = { 57 4881ec58010000 488d6c2420 488bfc b956000000 }
- $sequence_3 = { 488b8d00010000 e8???????? 488b8dd8000000 488bd1 488bc8 e8???????? }
- $sequence_4 = { e8???????? 488d0da1af0000 e8???????? 488d0d85af0000 }
- $sequence_5 = { 488bc8 e8???????? 488b5508 488b8d00010000 }
- $sequence_6 = { e8???????? 488d0dc1ad0000 e8???????? 488d0da5ad0000 }
- $sequence_7 = { 488d6c2430 488bfc b98a000000 b8cccccccc f3ab 488b8c2448020000 488b05???????? }
- $sequence_8 = { 488d1deb7e0000 4184c0 7539 410bc0 488d542458 488d0ddfd30000 8905???????? }
- $sequence_9 = { 488b4c2438 488d442430 4889442428 4c8d4c2434 488d442440 4533c0 488d1548830000 }
+ $sequence_0 = { c1e205 2bd1 8bce c7460471000000 }
+ $sequence_1 = { eb04 807dfd05 7607 814a1800100100 8a4dfe }
+ $sequence_2 = { 8b45f4 8b4850 8b45d0 23c2 894dcc 8b0481 8bc8 }
+ $sequence_3 = { 895df0 0fb6de 0145f8 0fb745d2 0fb6ca 03cb bf01000000 }
+ $sequence_4 = { 48 7526 804dff04 884a01 eb19 804dff02 884a01 }
+ $sequence_5 = { 894a04 83c620 83c120 81fee00f0000 }
+ $sequence_6 = { 83c608 03d0 895dfc 8955f8 897df0 3b75cc 72dc }
+ $sequence_7 = { 8b8d7cffffff 830204 5e c70101000000 33c0 5b }
+ $sequence_8 = { 898bc41b0000 8b5dfc 2bf1 8b7df4 8bc8 c1e908 0fb6c9 }
+ $sequence_9 = { d1e8 83fe1f 7eeb 6683bfb800000000 7537 6683bfbc00000000 752d }
condition:
- 7 of them and filesize <540672
+ 7 of them and filesize <4546560
}
-rule MALPEDIA_Win_Disttrack_Auto : FILE
+rule MALPEDIA_Win_Bazarbackdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2e51f756-65a0-5587-a62f-f2956dec5749"
+ id = "5d2ecc0c-54dd-5654-9202-132113260f24"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.disttrack"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.disttrack_auto.yar#L1-L264"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bazarbackdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bazarbackdoor_auto.yar#L1-L638"
license_url = "N/A"
- logic_hash = "ea5b03edf12e9b7619694e3ef0c115e1438e4209a3ddaae7b74afa494e3c57a2"
+ logic_hash = "bfaa99dbae5ad02f0954740ed30f16e2a148a8070db46fd5f787ce6fb0204c77"
score = 75
- quality = 73
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -150608,51 +157762,102 @@ rule MALPEDIA_Win_Disttrack_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 6a00 6a00 6848000700 }
- $sequence_1 = { ff15???????? 5d 5b 8bc7 5f 5e }
- $sequence_2 = { 68???????? ff15???????? 8d45dc 50 ff15???????? 8b4ddc }
- $sequence_3 = { e8???????? 6a07 e8???????? 59 c3 6a10 }
- $sequence_4 = { e8???????? 83c404 50 e8???????? 83c404 68???????? ff15???????? }
- $sequence_5 = { 488bc8 e8???????? ebd1 498b94dca0940100 }
- $sequence_6 = { 41bd08000000 4180fdfe 760d 488d0d392e0100 e8???????? }
- $sequence_7 = { 7442 488d157a840000 488bcf e8???????? 85c0 7525 }
- $sequence_8 = { 895c2440 895c2444 899c24d8000000 899c24b0000000 899c24b8000000 }
- $sequence_9 = { 884c30ff 3bf3 72e6 8b75ec 6a00 }
- $sequence_10 = { c3 8b04cd44ec4200 5d c3 0544ffffff }
- $sequence_11 = { 57 4883ec20 488d0dc74a0100 e8???????? 48833d????????00 7510 488d0db14a0100 }
- $sequence_12 = { 0fb7da 6683fa30 0f862b010000 8b44241c 33c9 66894c4422 66895c4420 }
- $sequence_13 = { 885df3 8b4104 80781900 8bf9 7514 38580c }
- $sequence_14 = { c7450800000000 e8???????? 68???????? 8d4df4 51 c745f46c924100 }
- $sequence_15 = { e8???????? 03f0 56 e8???????? 83c404 c745fc00000000 }
- $sequence_16 = { 51 ff15???????? 8b55d4 8955e4 8b45d8 }
- $sequence_17 = { 8bc1 eb0c 0fb6c9 0fbe8968004200 }
- $sequence_18 = { 8b4004 80781900 74ee 80791900 7505 8bc8 }
- $sequence_19 = { 4533c0 498bd4 33c9 c744242800000008 895c2420 ff15???????? 85c0 }
- $sequence_20 = { 75f9 2bc2 56 57 8d7801 }
- $sequence_21 = { be01000000 4883630800 488d05cf450100 488903 488d4c2428 }
- $sequence_22 = { 48634804 488d05b0270100 48894419e8 4883c430 }
- $sequence_23 = { 52 50 68???????? ff15???????? 8d34f5b0044200 89442420 33ff }
- $sequence_24 = { 7d13 4863ca 8a44191c 42888401602a0200 ffc2 ebe1 }
- $sequence_25 = { 8d842498030000 64a300000000 8b4508 33db 89442430 }
- $sequence_26 = { 3bc3 0f8476010000 68???????? 68???????? }
+ $sequence_0 = { 488bce 4889442420 ff15???????? 85c0 780a }
+ $sequence_1 = { 488bce ffd0 eb03 488bc3 }
+ $sequence_2 = { b803000000 e9???????? 488b5568 4c8d85f0040000 488b4c2450 bb08000000 }
+ $sequence_3 = { e9???????? 488b4c2458 488d55e0 ff15???????? }
+ $sequence_4 = { 4533c0 c744242002000000 ba00000040 ffd0 }
+ $sequence_5 = { 0fb70f ff15???????? 0fb74f02 0fb7d8 ff15???????? }
+ $sequence_6 = { 488d4d80 e8???????? 498bd6 488d4d80 }
+ $sequence_7 = { 7507 33c0 e9???????? b8ff000000 }
+ $sequence_8 = { 0fb7d8 ff15???????? 0fb74f08 440fb7e8 }
+ $sequence_9 = { 4885c9 7406 488b11 ff5210 ff15???????? }
+ $sequence_10 = { e8???????? cc e8???????? cc 4053 4883ec20 b902000000 }
+ $sequence_11 = { c3 0fb74c0818 b80b010000 663bc8 }
+ $sequence_12 = { e8???????? 4c89e1 e8???????? 8b05???????? }
+ $sequence_13 = { 4533c9 4889442428 488d95a0070000 488d442470 41b80f100000 }
+ $sequence_14 = { 0fb6c9 4881e9c0000000 48c1e108 4803c8 8bc1 488d94059f070000 }
+ $sequence_15 = { 31ff 4889c1 31d2 4989f0 }
+ $sequence_16 = { 4889f1 e8???????? 8b05???????? 8b0d???????? }
+ $sequence_17 = { 4c89742440 4c89742438 4489742430 4c89742428 }
+ $sequence_18 = { ff15???????? 4889c1 31d2 4d89e0 }
+ $sequence_19 = { 418d5508 488bc8 ff15???????? 488bd8 }
+ $sequence_20 = { e8???????? 4889c7 8b05???????? 8b0d???????? }
+ $sequence_21 = { 488d9590050000 488bce ff15???????? 85c0 }
+ $sequence_22 = { 488d442470 41b80f100000 488bce 4889442420 }
+ $sequence_23 = { ff15???????? ff15???????? 4d8bc5 33d2 488bc8 }
+ $sequence_24 = { 0fafc8 89c8 83f0fe 85c8 0f95c0 0f94c3 }
+ $sequence_25 = { c744242003000000 4889f9 ba00000080 41b801000000 }
+ $sequence_26 = { c744242800000001 4533c9 4533c0 c744242002000000 ba1f000f00 }
+ $sequence_27 = { 83fe09 0f9fc2 83fe0a 0f9cc1 }
+ $sequence_28 = { 4889442428 488d95b0030000 488d4580 41b80f100000 }
+ $sequence_29 = { 4d8bc7 33d2 488bc8 ff15???????? ff15???????? }
+ $sequence_30 = { 08ca 80f201 7502 ebfe }
+ $sequence_31 = { 48c744243000000000 c744242880000000 c744242003000000 4889f9 }
+ $sequence_32 = { 0f94c3 83f809 0f9fc2 83f80a 0f9cc0 30d8 }
+ $sequence_33 = { 0fb65305 33c0 80f973 0f94c0 }
+ $sequence_34 = { 0f9fc1 83fa0a 0f9cc2 30da 08c1 80f101 08d1 }
+ $sequence_35 = { 7528 0fb64b04 0fb6d1 80f973 }
+ $sequence_36 = { 4889c1 31d2 4989f8 ff15???????? 4885c0 }
+ $sequence_37 = { ff15???????? 31ed 4889c1 31d2 4989d8 }
+ $sequence_38 = { 488bd3 e8???????? ff15???????? 4c8bc3 33d2 }
+ $sequence_39 = { 0fb6d1 80f973 7504 0fb65305 }
+ $sequence_40 = { 08c1 80f101 7502 ebfe }
+ $sequence_41 = { e8???????? 4889f9 4889f2 ffd0 }
+ $sequence_42 = { 0f9cc2 30da 7509 08c1 }
+ $sequence_43 = { 85da 0f94c3 83fd0a 0f9cc2 }
+ $sequence_44 = { 84d2 7405 80fa2e 750f }
+ $sequence_45 = { 4889c1 31d2 4d89e8 ff15???????? }
+ $sequence_46 = { 4889c1 31d2 4d89f8 ffd3 }
+ $sequence_47 = { e8???????? 4c897c2420 4889d9 89fa }
+ $sequence_48 = { 89f0 4883c450 5b 5f }
+ $sequence_49 = { 8d4833 ff15???????? c744242810000000 4533c9 }
+ $sequence_50 = { 6a00 56 ff15???????? 5f 5e 5d 8bc3 }
+ $sequence_51 = { 689c7d9d93 6a04 5a e8???????? 59 59 85c0 }
+ $sequence_52 = { 8d44244c 50 6a00 ff74243c 53 55 ff15???????? }
+ $sequence_53 = { 6685ff 0f849c000000 837c2460ff 0f858c000000 }
+ $sequence_54 = { 50 0fb745e8 50 68???????? e8???????? }
+ $sequence_55 = { 66890d???????? 0fb7ca ff15???????? b901000000 66c746020100 668906 }
+ $sequence_56 = { 7506 8b0e 894c2460 0fb7c0 }
+ $sequence_57 = { 8a842483030000 81fe80000000 760b 24f2 0c02 }
+ $sequence_58 = { 57 8d4101 6a0e 8bf0 5f 8a11 }
+ $sequence_59 = { 7406 6a35 ffd0 eb02 33c0 }
+ $sequence_60 = { ffd6 8d7001 56 6a08 ff15???????? 50 }
+ $sequence_61 = { 740d 33d2 83f902 0f95c2 83c224 }
+ $sequence_62 = { 0f95c2 83c224 eb05 ba29000000 }
+ $sequence_63 = { 660f73d801 660febd0 660f7ed0 84c0 }
+ $sequence_64 = { 750b 8ac1 2ac2 fec8 88041a }
+ $sequence_65 = { 8d4701 84c9 0f45c7 803a00 8bf8 }
+ $sequence_66 = { 6a00 6a00 50 8d4601 }
+ $sequence_67 = { c1f808 0fb6c0 50 0fb6c2 }
+ $sequence_68 = { 83c410 b800308804 6a00 50 }
+ $sequence_69 = { 81feff030000 733c 8a02 3cc0 721e 0fb6c8 }
+ $sequence_70 = { 89542410 48894c2408 4883ec48 8b442458 89442424 48c744242800000000 }
+ $sequence_71 = { 488b442430 488b8c2410010000 48894830 488b442430 488b8c2418010000 48894838 488b442430 }
+ $sequence_72 = { 488bca 448bc0 488bd1 488b4c2430 e8???????? 488b442428 }
+ $sequence_73 = { ff15???????? 33c0 eb47 488b442430 8b4014 }
+ $sequence_74 = { 4825ffff0000 488b8c2488000000 4c8b4140 488bd0 }
+ $sequence_75 = { 488b442430 48c7404800000000 488b442430 eb14 }
+ $sequence_76 = { eb1f 488b442430 8b4024 2580000000 }
+ $sequence_77 = { 488b442458 488b00 b908000000 486bc909 488d840888000000 4889442428 488b442428 }
condition:
- 7 of them and filesize <1112064
+ 7 of them and filesize <2088960
}
-rule MALPEDIA_Win_Prikormka_Auto : FILE
+rule MALPEDIA_Win_Orpcbackdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "942667ef-c0ed-5e6f-acdd-388f6c8d0b49"
+ id = "605ecf11-b36e-51cd-8e37-c406fe5ee743"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.prikormka"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.prikormka_auto.yar#L1-L426"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.orpcbackdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.orpcbackdoor_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "7c65eb7008c5e728405addd601d63974803e3912597af2618d49b7f4b185b6c5"
+ logic_hash = "a975ab0f24495978f9e8b667b3f6b02066e8ac424646b3588e19f69238c5dbdd"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -150664,71 +157869,34 @@ rule MALPEDIA_Win_Prikormka_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d0446 50 e8???????? 83c40c 6a00 56 }
- $sequence_1 = { 8d1446 52 e8???????? 83c40c }
- $sequence_2 = { ffd3 8b2d???????? 85c0 7405 }
- $sequence_3 = { 51 e8???????? 83c40c 68???????? ffd7 }
- $sequence_4 = { 85f6 7420 68???????? ffd7 }
- $sequence_5 = { ff15???????? 68???????? ffd7 03c0 50 }
- $sequence_6 = { 8b1d???????? 83c40c 6a00 56 ffd3 8b2d???????? }
- $sequence_7 = { 56 ffd3 85c0 7405 6a02 56 }
- $sequence_8 = { 740e 68???????? 50 ff15???????? ffd0 }
- $sequence_9 = { 68???????? 6a00 6a00 ff15???????? 85c0 7502 59 }
- $sequence_10 = { 83c40c 8d442404 50 ff15???????? 5e }
- $sequence_11 = { 7408 41 42 3bce }
- $sequence_12 = { 85c0 7502 59 c3 50 ff15???????? b801000000 }
- $sequence_13 = { c3 57 6a00 6a00 6a00 6a02 }
- $sequence_14 = { 68???????? ff15???????? 0fb7c0 6683f805 }
- $sequence_15 = { ff15???????? ffd0 c705????????01000000 c705????????01000000 }
- $sequence_16 = { 5e 85c0 7422 68???????? 50 }
- $sequence_17 = { 0fb7c0 6683f805 7d09 b801000000 }
- $sequence_18 = { 5e 85c0 7414 c705????????01000000 }
- $sequence_19 = { 33f6 e8???????? e8???????? e8???????? e8???????? e8???????? e8???????? }
- $sequence_20 = { 50 e8???????? 8b2d???????? 83c40c 6a00 }
- $sequence_21 = { ff15???????? 8bf0 ff15???????? 3db7000000 751f 56 }
- $sequence_22 = { 83c102 6685d2 75f5 2bce 8d1400 52 d1f9 }
- $sequence_23 = { 75f5 8b0d???????? 2bc2 8b15???????? d1f8 }
- $sequence_24 = { 751f 56 ff15???????? 33c0 }
- $sequence_25 = { 6685c9 75f5 2bc6 8d0c12 }
- $sequence_26 = { 2bc6 8d0c12 51 d1f8 }
- $sequence_27 = { 8b35???????? 83c40c 68???????? ffd6 03c0 }
- $sequence_28 = { 50 e8???????? b8???????? 83c40c 8d5002 }
- $sequence_29 = { 75f5 8d0c12 2bc6 51 d1f8 8d544408 }
- $sequence_30 = { d1f8 8d7102 8da42400000000 668b11 83c102 }
- $sequence_31 = { 85c0 7409 6a02 68???????? }
- $sequence_32 = { 50 ff15???????? 0fb74c2416 0fb7542414 }
- $sequence_33 = { d1f8 8bd0 b8???????? 8d7002 8da42400000000 668b08 83c002 }
- $sequence_34 = { 6685c9 75f5 2bc2 b9???????? d1f8 8d7102 668b11 }
- $sequence_35 = { ffd6 50 68???????? 57 ffd6 03c7 50 }
- $sequence_36 = { 56 57 68???????? 33ff 57 57 ff15???????? }
- $sequence_37 = { e8???????? 83c40c eb0d 6a00 6800020000 }
- $sequence_38 = { d1f8 8d7102 668b11 83c102 6685d2 75f5 8d1400 }
- $sequence_39 = { 6685d2 75f5 8d1400 2bce 52 d1f9 }
- $sequence_40 = { 6a00 6800020000 ff15???????? 68???????? }
- $sequence_41 = { e8???????? 83c40c 6a00 68???????? ffd3 85c0 7409 }
- $sequence_42 = { 6a5c 99 5f f7ff 83f801 }
- $sequence_43 = { 0f87f5090000 ff248505eb0010 33c0 838df4fbffffff 8985a0fbffff }
- $sequence_44 = { 48 48 8975f4 7479 83e848 745f }
- $sequence_45 = { 56 8bc3 2bc1 6a5c 99 }
- $sequence_46 = { 32a832d232e0 32e6 3209 3310 3329 333d???????? 335f33 }
+ $sequence_0 = { 8b45fc 83e818 50 e8???????? 59 59 }
+ $sequence_1 = { 59 ffb5e4f6feff ffb568f5feff 8d8594f9ffff 50 e8???????? 83c40c }
+ $sequence_2 = { 6a0c 59 be???????? 8dbdc0faffff f3a5 66a5 a4 }
+ $sequence_3 = { 8b45c4 0fbe00 83f87f 7452 8b45c4 0fbe00 85c0 }
+ $sequence_4 = { 753e 8b45c8 40 40 3b4524 7734 8b4520 }
+ $sequence_5 = { 83a5b0fdffff00 8d85b0fdffff 50 6a02 8b85b4fdffff 8b00 ffb5b4fdffff }
+ $sequence_6 = { 8841fd eb0e a1???????? 0345f4 c640fd00 eb05 }
+ $sequence_7 = { 6a01 6a40 6a01 6a01 8d8da8fcfeff e8???????? 50 }
+ $sequence_8 = { 3c5a 7712 0fbec1 83e820 83e07f 8a044589700310 }
+ $sequence_9 = { 0fbe4001 83f858 7508 8b45c4 40 40 }
condition:
- 7 of them and filesize <401408
+ 7 of them and filesize <918528
}
-rule MALPEDIA_Win_Silence_Auto : FILE
+rule MALPEDIA_Win_Dorshel_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f44b3bc4-8edd-502b-bd51-3105b7335797"
+ id = "550d8628-f52a-56de-91a7-ece0c38b96fb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.silence"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.silence_auto.yar#L1-L413"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dorshel"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dorshel_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "c771c849ed5f5e02e308e7f1e45bb9b0766da378108a761728400240a10fde1e"
+ logic_hash = "364203df24c6a83e17731caab6caa244bb9a531055fdc65fef6d763de8c4fb40"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -150740,69 +157908,32 @@ rule MALPEDIA_Win_Silence_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d45fc 50 6a00 6a00 68???????? c745fc00000000 }
- $sequence_1 = { 740a 8a4801 40 84c9 75f4 eb05 803800 }
- $sequence_2 = { 8b4908 e8???????? cc 8325????????00 c3 6a08 }
- $sequence_3 = { 683f020f00 6a00 68???????? 6801000080 ff15???????? 68???????? }
- $sequence_4 = { 3b0d???????? 7502 f3c3 e9???????? e8???????? e9???????? 6a14 }
- $sequence_5 = { 68???????? ffd6 8b45fc 85c0 }
- $sequence_6 = { ff15???????? 6a00 6800000004 6a00 }
- $sequence_7 = { 46 56 8d85f8feffff 50 }
- $sequence_8 = { 6801000080 ff15???????? 56 8d85f8feffff }
- $sequence_9 = { 8bd8 68???????? 53 ff15???????? 6a00 }
- $sequence_10 = { 8b35???????? 6a00 6a00 6a00 6a00 8d45fc 50 }
- $sequence_11 = { 6a00 8bf8 6a00 57 ff15???????? 8d45fc 50 }
- $sequence_12 = { 40 84c9 75f4 eb0d 803800 7408 }
- $sequence_13 = { 803800 7408 8a5a01 42 84db }
- $sequence_14 = { 5e 5b 5d c3 c60200 42 }
- $sequence_15 = { 8d85b8f7ffff 50 6800080000 8d85bcf7ffff }
- $sequence_16 = { 8b85b8f7ffff 85c0 75b6 ffb5acf7ffff }
- $sequence_17 = { 83c41c 895ef8 897ef0 5b 5f }
- $sequence_18 = { 8bf9 e8???????? ff37 8b35???????? }
- $sequence_19 = { ff501c 8b17 8bcf ff5210 8b17 }
- $sequence_20 = { 7412 8b01 52 8d95f0fdffff 52 ff10 }
- $sequence_21 = { 8d8dfcfbffff 51 ffb5f0fbffff 8bcb ff5038 }
- $sequence_22 = { 0346f4 57 ff7508 50 e8???????? 83c40c }
- $sequence_23 = { 03d7 3b56f0 7611 8b46ec }
- $sequence_24 = { 85c9 7408 8b06 51 8bce ff501c }
- $sequence_25 = { d3e0 0fb6c8 8b05???????? d3e0 }
- $sequence_26 = { ff15???????? ba180c0000 b940000000 ff15???????? }
- $sequence_27 = { ff15???????? 488d542430 488d8c2440020000 ff15???????? }
- $sequence_28 = { 8b05???????? d3e0 8b0d???????? 03c8 }
- $sequence_29 = { e8???????? ba00040000 b940000000 ff15???????? }
- $sequence_30 = { ff15???????? 41b804010000 488d542430 488d4c2430 ff15???????? 85c0 }
- $sequence_31 = { d3f8 0fb60d???????? d3e0 85c0 }
- $sequence_32 = { 99 83e203 03c2 c1f802 89442440 }
- $sequence_33 = { ff15???????? c20800 53 8b1d???????? 57 0f57c0 }
- $sequence_34 = { 5e 85c0 7507 68???????? ffd7 5f }
- $sequence_35 = { 7507 68???????? ffd7 6a00 6a00 6a01 6a00 }
- $sequence_36 = { 750e 68???????? ff15???????? c20800 }
- $sequence_37 = { 8d0441 33d2 b905000000 f7f1 }
- $sequence_38 = { c705????????00000000 c705????????00000000 ffd3 8b3d???????? 85c0 7507 }
- $sequence_39 = { 68???????? ff15???????? a3???????? 85c0 750e 68???????? }
- $sequence_40 = { 8bec ff4d08 755d 833d????????04 7554 }
- $sequence_41 = { c705????????04000000 ff15???????? 85c0 750b 68???????? ff15???????? }
- $sequence_42 = { ff15???????? 68c0d40100 ff15???????? e9???????? }
- $sequence_43 = { 03048db0354200 50 ff15???????? 5d }
- $sequence_44 = { 0305???????? 0b45f0 3305???????? a3???????? }
- $sequence_45 = { 03048db0354200 eb02 8bc6 80782900 }
- $sequence_46 = { 03048db0354200 eb05 b8???????? f6402820 }
+ $sequence_0 = { 55 8bec 83ec0c 31c0 648b5030 8b520c 8b5214 }
+ $sequence_1 = { 8d7708 8b3f 33fb f3a4 5f }
+ $sequence_2 = { 03f8 84c0 75f6 81ff5e515e83 7408 81ff36cadb30 75da }
+ $sequence_3 = { 83c004 e2f9 58 54 50 }
+ $sequence_4 = { 51 8b0f 33cb 51 ff55f8 8b5df4 }
+ $sequence_5 = { 54 50 8b4f04 33cb 51 8b0f }
+ $sequence_6 = { ffd5 85c0 74cd 8b07 01c3 }
+ $sequence_7 = { ac c1cf0d 03f8 84c0 75f6 81ff5e515e83 7408 }
+ $sequence_8 = { 57 6800200000 53 56 68129689e2 ffd5 85c0 }
+ $sequence_9 = { 5f 8b4704 33c3 83c104 99 }
condition:
- 7 of them and filesize <70128640
+ 7 of them and filesize <24576
}
-rule MALPEDIA_Win_Sysjoker_Auto : FILE
+rule MALPEDIA_Win_Clambling_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "42bbdbb2-321a-5c06-b4e0-64934ffdbef1"
+ id = "55c68f1e-9478-508c-963a-a6b0515c5aac"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sysjoker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sysjoker_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.clambling"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.clambling_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "272a60e5cac852c8fc52dd28ee7d3d45f227ab0f82269e4ab7d14e4de95e70fb"
+ logic_hash = "bda71815f9f64d048a93fa253b5199d20d6e6d47cb677b3884b8c43571e95a8e"
score = 75
quality = 75
tags = "FILE"
@@ -150816,34 +157947,34 @@ rule MALPEDIA_Win_Sysjoker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? 837de400 7416 }
- $sequence_1 = { c746140f000000 c60600 e8???????? c7461060000000 8d4dd4 c746146f000000 0f1005???????? }
- $sequence_2 = { ffd6 e9???????? 8bb5a8efffff 85f6 0f84ce000000 6808020000 8d85e8fdffff }
- $sequence_3 = { 8d4dac e8???????? 8d4dc8 e8???????? 8d8d74ffffff c645fc1b e8???????? }
- $sequence_4 = { 8bc2 b9ffffff7f 83c80f 3dffffff7f 0f47c1 894584 40 }
- $sequence_5 = { 7cd5 33db 395d90 7650 0f1f4000 660f1f840000000000 83bd78ffffff10 }
- $sequence_6 = { 6a02 68???????? e8???????? 8b8534efffff 83c618 8b8d4cefffff 40 }
- $sequence_7 = { e8???????? 83c404 8b8780000000 33f6 89b534efffff }
- $sequence_8 = { 6a01 8bce e8???????? 84c0 0f84c2feffff e9???????? 8b4778 }
- $sequence_9 = { e8???????? 83c010 8906 51 c645fc25 8bf4 89b508fdffff }
+ $sequence_0 = { 6689bc24b0000000 ff15???????? 3bc7 7508 }
+ $sequence_1 = { 488bd9 498d53e8 418d4802 498943f0 ff15???????? }
+ $sequence_2 = { 751b e9???????? bb46270000 eb0f ff15???????? 8bd8 eb05 }
+ $sequence_3 = { 3bc3 751f 8b4c2428 488d942490020000 ff15???????? }
+ $sequence_4 = { eb0f ff15???????? 8bd8 eb05 bbc7040000 }
+ $sequence_5 = { 7507 66893d???????? 488b0d???????? 488d542430 ff15???????? 448b442430 }
+ $sequence_6 = { 7408 488bcb e8???????? 488b5c2458 }
+ $sequence_7 = { 4c8d442430 33d2 c744243001000000 c744243c02000000 ff15???????? 85c0 }
+ $sequence_8 = { b8b4050000 eb13 488b03 488bd7 488bcb }
+ $sequence_9 = { 41b805000000 48894c2420 33c9 8bd5 }
condition:
- 7 of them and filesize <832512
+ 7 of them and filesize <412672
}
-rule MALPEDIA_Win_Kleptoparasite_Stealer_Auto : FILE
+rule MALPEDIA_Win_Miniblindingcan_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d0389ad4-24e3-5ce2-885f-8e2d3c44dd15"
+ id = "92bc3e0e-6544-5def-8326-ac0c583fd403"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kleptoparasite_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kleptoparasite_stealer_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miniblindingcan"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.miniblindingcan_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "1caf749c6c15dea159c6ab2428d269f9b9674545b72666548fcdc2b3e50e89c9"
- score = 60
- quality = 35
+ logic_hash = "7b8607880b97335be49c71c4d350efefeb788c1420c4ead3bd8ed006de1090db"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -150855,32 +157986,32 @@ rule MALPEDIA_Win_Kleptoparasite_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7405 8901 895104 8be5 5d c3 3b0d???????? }
- $sequence_1 = { ebe4 6a0c 68???????? e8???????? 8365e400 33c0 8b7d08 }
- $sequence_2 = { e8???????? cc 55 8bec 56 e8???????? 8b7508 }
- $sequence_3 = { 895104 8be5 5d c3 3b0d???????? 7502 }
- $sequence_4 = { b8???????? c3 e9???????? 55 8bec 56 e8???????? }
- $sequence_5 = { 59 c3 6a10 68???????? e8???????? 33ff 897de0 }
- $sequence_6 = { 895104 8be5 5d c3 3b0d???????? }
- $sequence_7 = { cc 55 8bec 56 e8???????? 8b7508 6a02 }
- $sequence_8 = { 8901 895104 8be5 5d c3 3b0d???????? 7502 }
- $sequence_9 = { c3 e9???????? 55 8bec 56 e8???????? 8bf0 }
+ $sequence_0 = { 899424b0000000 81faff000000 7c37 b881808080 488bce f7e2 c1ea07 }
+ $sequence_1 = { 8bc6 45338c8c600a0200 c1e808 c1eb08 41c1ea10 0fb6c8 410fb6c0 }
+ $sequence_2 = { 48ffc1 49ffc8 75ed 488b542428 4c8d442420 488bce e8???????? }
+ $sequence_3 = { 660f6e7310 488d4c2438 f30fe6f6 ff15???????? 488d542430 488d4c2438 ff15???????? }
+ $sequence_4 = { 483b442420 0f8710040000 4883fd0f 0f82e7030000 488d7df1 c606f0 }
+ $sequence_5 = { 488d0579340000 488905???????? e9???????? 81fb39380000 7513 488d0553340000 488905???????? }
+ $sequence_6 = { 48ffc6 448bc1 f7e1 c1ea07 4c89442430 8bc2 }
+ $sequence_7 = { 488bc8 ff15???????? 488d1528a70000 488bce 488905???????? ff15???????? 488bc8 }
+ $sequence_8 = { 488b4590 83a0c8000000fd 83c8ff e9???????? 4183cfff f6431840 4c8d0dc50dffff }
+ $sequence_9 = { 740a b801000000 e9???????? 4533c9 }
condition:
- 7 of them and filesize <3006464
+ 7 of them and filesize <453632
}
-rule MALPEDIA_Win_Rombertik_Auto : FILE
+rule MALPEDIA_Win_Waterminer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b8dc9071-13ab-5355-92f1-2480db82efe0"
+ id = "a6c61a63-af94-546a-ae52-fcf958232615"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rombertik"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rombertik_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.waterminer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.waterminer_auto.yar#L1-L159"
license_url = "N/A"
- logic_hash = "c93757fb5684dd7302fa22ed1f1f21c4fae8e9b1525dbcd58ab0d5e9fecbc821"
+ logic_hash = "3dbc2a8def87fd5744e5b18617b0d65739b7ff2d0b5a69125fd601baee65e3fe"
score = 75
quality = 75
tags = "FILE"
@@ -150894,32 +158025,38 @@ rule MALPEDIA_Win_Rombertik_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945f4 3bc1 0f8271ffffff 5f 5e }
- $sequence_1 = { 8bff 8b4104 85c0 7446 83c0f8 33ff }
- $sequence_2 = { 8bcf e8???????? 50 8d8dfcfeffff }
- $sequence_3 = { 47 41 3bfb 72be 8b5df0 }
- $sequence_4 = { 50 ff15???????? 8bf8 85ff 0f8488000000 }
- $sequence_5 = { 33db 57 895df8 ff15???????? 85c0 }
- $sequence_6 = { 8b5d0c 85db 0f84cb000000 837d1400 0f84c1000000 817d18a00f0000 0f87b4000000 }
- $sequence_7 = { 50 8bc2 50 8d8decfeffff 51 ffd6 }
- $sequence_8 = { 895dfc 85db 0f84d8000000 85ff }
- $sequence_9 = { 6a03 6a00 6a02 68000000c0 68???????? ff15???????? 8906 }
+ $sequence_0 = { 8b8514f3ffff e9???????? 83bda4f5ffff00 0f8532010000 8b8db8f5ffff c1e104 83bc0dbcf9ffff00 }
+ $sequence_1 = { 03442410 4403e8 428b4405e7 418bd5 }
+ $sequence_2 = { 03bc24a8000000 488bcd 4c8d0d35cb0300 83e13f }
+ $sequence_3 = { 51 b804000000 6bc019 8b8880434b00 330d???????? 894dfc 740d }
+ $sequence_4 = { 8b8da4fbffff 83e901 898da4fbffff 83bd10fbffff00 }
+ $sequence_5 = { 8bcd 50 8d15b0854300 e8???????? }
+ $sequence_6 = { 03c0 2bc8 0f84ec040000 8d41ff 8b848288d20600 }
+ $sequence_7 = { 0344240c 4403d0 488d051a560500 418b0400 }
+ $sequence_8 = { 03c1 03d0 488d051e580500 418b0400 }
+ $sequence_9 = { 83bd60ffffff0b 0f8711060000 8b8d60ffffff ff248d74304800 0fbe55d3 }
+ $sequence_10 = { 02c8 41880c18 418a03 240f }
+ $sequence_11 = { 0344240c 4403d0 428b4405e7 418bd2 }
+ $sequence_12 = { 02d0 49ffc3 418d4001 881418 }
+ $sequence_13 = { c78538fbffff01000000 eb0a c78538fbffff00000000 8b8538fbffff 898530fbffff }
+ $sequence_14 = { 8b95c4fbffff 8995f0fbffff 8b85ecfbffff 055d010000 898580fbffff }
+ $sequence_15 = { 33c5 8945fc 8bf4 6a00 8bfc ff15???????? 3bfc }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <1556480
}
-rule MALPEDIA_Win_Pcshare_Auto : FILE
+rule MALPEDIA_Win_Unidentified_096_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7acb8456-1058-55a0-81ba-27e3cb590933"
+ id = "22c09f40-2011-5730-9e32-986d3f55e0d2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pcshare"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pcshare_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_096"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_096_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "7ae15dd51d8c67d0995dcb010803cd76a95f2636c119f9eefe8dfedf04aaf2b7"
+ logic_hash = "5261db5ca22f6df28b3364eb8987d65dbffd712b51f02eb4b92928e711dc9c45"
score = 75
quality = 75
tags = "FILE"
@@ -150933,32 +158070,32 @@ rule MALPEDIA_Win_Pcshare_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b48fc 03f7 8b78f8 8bd1 03fb c1e902 }
- $sequence_1 = { 33ed 8d0c18 8bc3 99 }
- $sequence_2 = { e8???????? 85c0 59 743e 8305????????20 8d0c9da0720610 }
- $sequence_3 = { 8bc6 8b0c8da0720610 8d04c0 80648104fd 8d448104 8bc7 5f }
- $sequence_4 = { 8d4c2418 50 51 e8???????? 83c40c 84c0 7439 }
- $sequence_5 = { c1e705 f6441f0e01 7428 8b4c2474 81e2ffff2f00 895008 8b542440 }
- $sequence_6 = { 51 eb07 8b16 8d441a02 }
- $sequence_7 = { 85c0 7505 b8???????? 8078fffe 732f }
- $sequence_8 = { 83c418 894c2424 b940000000 f3ab 66ab aa b940000000 }
- $sequence_9 = { 3bd0 0f8c93fdffff 33ed 5b 8b74243c 8a4c241c }
+ $sequence_0 = { 896c2444 c744244806000000 896c244c c744245010304000 }
+ $sequence_1 = { ff15???????? 8bf0 a1???????? 3bf0 }
+ $sequence_2 = { b021 a2???????? eb56 b040 a2???????? eb4d }
+ $sequence_3 = { b02b eb11 b02d eb0d f644240c01 740b b02e }
+ $sequence_4 = { 68???????? 52 e8???????? 83c424 8b4c242a 6683f930 0f8283000000 }
+ $sequence_5 = { 90 6aff 68???????? 68???????? 64a100000000 }
+ $sequence_6 = { 8b4c2420 8b54241c 8b442414 51 52 68ff000000 }
+ $sequence_7 = { 3dff000000 741d 8b4c2420 8b54241c 51 52 }
+ $sequence_8 = { b029 a2???????? eb5f b021 }
+ $sequence_9 = { 56 8b35???????? 57 6a14 ffd6 6a10 0fbfd8 }
condition:
- 7 of them and filesize <893708
+ 7 of them and filesize <25648
}
-rule MALPEDIA_Elf_Mirai_Auto : FILE
+rule MALPEDIA_Win_Waterspout_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "99bf67bb-d881-5d1d-9ccf-8805d4c126fc"
+ id = "966cd02d-f7ac-590a-a30e-6be6c0215ec6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.mirai_auto.yar#L1-L92"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.waterspout"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.waterspout_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "53d684afadf5b7afddedfe71964fc5273146fef2945717259a3274aa2e1d04ee"
+ logic_hash = "791d1c9b538b0f8a628f6a3764a4be7336ff1d48478e7334334b2fc3c8924313"
score = 75
quality = 75
tags = "FILE"
@@ -150972,30 +158109,32 @@ rule MALPEDIA_Elf_Mirai_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6689432a e8???????? c7433400000000 894330 }
- $sequence_1 = { 89d0 c1e005 01d0 89ca }
- $sequence_2 = { 894330 c6433801 c6433903 c6433a03 c6433b06 }
- $sequence_3 = { 66c1e808 d0e8 8d04c0 28c2 }
- $sequence_4 = { 3c19 7705 8d42e0 8801 }
- $sequence_5 = { 807c242b00 66894304 7406 66c743064000 c643092f }
- $sequence_6 = { 66894104 7406 66c741064000 c6410911 }
- $sequence_7 = { 8b1408 895310 8b54080c 66895314 }
+ $sequence_0 = { fec8 53 8841ff 8d4c2418 ff15???????? eb3a 3bf3 }
+ $sequence_1 = { c684243a01000023 c684243b0100003d c684243c010000ee c684243d0100004c c684243e01000095 c684243f0100000b c684244001000042 }
+ $sequence_2 = { 8d4c244c 68???????? 51 ff15???????? 8d7c2454 83c9ff 33c0 }
+ $sequence_3 = { 51 52 ff15???????? 85c0 7415 a1???????? 3bc3 }
+ $sequence_4 = { 50 8b842410200000 51 52 68???????? 50 }
+ $sequence_5 = { 6a00 a4 ff15???????? 50 ff15???????? 8b742460 }
+ $sequence_6 = { 0f84aa000000 6a00 56 55 }
+ $sequence_7 = { 8d542414 51 52 ffd6 83f801 74db 5f }
+ $sequence_8 = { a3???????? 8b442428 68???????? 6a00 6a6b }
+ $sequence_9 = { 33c0 8dbdfcfeffff 85f6 f3ab 7511 8d85fcfeffff 50 }
condition:
- 7 of them and filesize <2228224
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Client_Maximus_Auto : FILE
+rule MALPEDIA_Win_Unidentified_001_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9ae68e0c-f7b3-57b3-a5e5-43c9d1c73212"
+ id = "7c85316d-7785-5af3-87a9-b2590753f62d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.client_maximus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.client_maximus_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_001"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_001_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "b18f0f0d0ef0e4099637c9406b0101b6f1ae3668adb85f5994962285717f3168"
+ logic_hash = "4757a1bf889ab5e180c54dba6f09c40c0355df630267d0efd95e630d6757bdc3"
score = 75
quality = 75
tags = "FILE"
@@ -151009,32 +158148,32 @@ rule MALPEDIA_Win_Client_Maximus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89f0 0fb6c0 0fb61403 88140b 83c101 89fa 81f900010000 }
- $sequence_1 = { 89e5 56 53 83ec10 8b1d???????? }
- $sequence_2 = { 893424 ff15???????? 83ec08 85c0 7411 }
- $sequence_3 = { e8???????? 8b4304 85c0 741d 8b5330 c744240800800000 c744240400000000 }
- $sequence_4 = { 39730c 7fe1 891424 e8???????? }
- $sequence_5 = { 7429 c70424???????? ff15???????? 83ec04 a3???????? }
- $sequence_6 = { 8b4628 85c0 7535 c70424???????? }
- $sequence_7 = { a3???????? c7442404???????? 893424 ff15???????? 83ec08 85c0 7411 }
- $sequence_8 = { 89c8 0fb63c0b 99 f77c241c 89f8 }
- $sequence_9 = { 89f8 02441500 01c6 89f0 0fb6c0 }
+ $sequence_0 = { 6830750000 ffd6 8b4df8 85c9 7483 8d45fc }
+ $sequence_1 = { fec1 88143e 3a4801 72e6 5f 5e 5d }
+ $sequence_2 = { 2bc6 0f8421fdffff 2df2020000 0f8478fbffff 2d13030000 }
+ $sequence_3 = { b952555300 3bc1 7767 74d3 }
+ $sequence_4 = { 8bf1 8b06 57 56 ff5048 8bf8 85ff }
+ $sequence_5 = { ff15???????? 50 ff15???????? 8bf0 8975f8 3bf3 }
+ $sequence_6 = { 893d???????? e9???????? c705????????10000000 e9???????? 2d46494e00 7461 48 }
+ $sequence_7 = { 6a04 68???????? 6a07 6800080000 }
+ $sequence_8 = { 8935???????? 8d45cc 50 57 }
+ $sequence_9 = { 50 ff5108 8b45e4 3bc3 5b 7406 }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Snifula_Auto : FILE
+rule MALPEDIA_Win_Aytoke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3dffa8bc-fef5-5d9b-860e-b2ad6113d3e0"
+ id = "f1478c56-9c46-5623-bd25-6c48e27a19e0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.snifula"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.snifula_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aytoke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aytoke_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "5394c0842b5f05f382e3a7b0318fd2397f5c79fe7938989019ff20c4e8348941"
+ logic_hash = "7de9f368c79cc6db2fb2092fd19a4e0bd2fcaaf4a3ec4500b832560e5022850b"
score = 75
quality = 75
tags = "FILE"
@@ -151048,32 +158187,32 @@ rule MALPEDIA_Win_Snifula_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 ff35???????? ffd7 6800040000 53 ff35???????? }
- $sequence_1 = { 53 6a00 ff35???????? ff15???????? b8???????? 83c9ff }
- $sequence_2 = { 6a00 ff35???????? 8945fc ff15???????? 8bf8 85ff }
- $sequence_3 = { a1???????? 85c0 75ef 53 57 bb???????? }
- $sequence_4 = { ff15???????? 8bf8 83ffff 747f 53 8d450c 50 }
- $sequence_5 = { e8???????? 85c0 740c 81386368756e 7504 834e1002 8bc6 }
- $sequence_6 = { c1e802 25ff000000 8d44c72c 8b18 3bd8 7432 }
- $sequence_7 = { 83f803 7533 ff7304 8bc7 ff750c e8???????? 8b4724 }
- $sequence_8 = { 68???????? 56 ff15???????? 83c414 68???????? 56 }
- $sequence_9 = { 53 50 889c243c010000 e8???????? a1???????? 83c43c 895c2430 }
+ $sequence_0 = { 6685c9 75e9 e9???????? 33c0 8bff 0fb788103a4100 66898c05fcfdffff }
+ $sequence_1 = { 3c58 770f 0fbec2 0fbe80f83b4100 83e00f eb02 33c0 }
+ $sequence_2 = { 8bd0 83e01f c1fa05 8b149500c44100 59 c1e006 59 }
+ $sequence_3 = { 56 e8???????? c1f805 56 8d3c8500c44100 e8???????? 83e01f }
+ $sequence_4 = { 90 68???????? e8???????? a1???????? 46 83c004 }
+ $sequence_5 = { 2bc2 bb5c000000 85c0 7e16 }
+ $sequence_6 = { be01000000 83c104 83c408 3bce }
+ $sequence_7 = { 33c0 8d642400 0fb7888c3a4100 66898c05fcfdffff 83c002 6685c9 75e9 }
+ $sequence_8 = { 85ff 7424 56 53 6a01 57 }
+ $sequence_9 = { 663bc1 0f85cc130000 8d95fcfcffff 52 ff15???????? 68a0000000 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <425984
}
-rule MALPEDIA_Win_Action_Rat_Auto : FILE
+rule MALPEDIA_Win_Emdivi_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b171bb40-9b64-5f84-b8a8-e9db33470a7a"
+ id = "c7c959fb-e496-5370-834c-2f119e1d6751"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.action_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.action_rat_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.emdivi"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.emdivi_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "d6b5f7381b8e2ad2725999fb927500f671ba77c3542ba9198900375907d98a2d"
+ logic_hash = "e1fc98ee3cf386dcf808c43ff2c4f0b6085fa811a19f892f7791e8e62f91b120"
score = 75
quality = 75
tags = "FILE"
@@ -151087,32 +158226,32 @@ rule MALPEDIA_Win_Action_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4d0c e8???????? 8b4508 8b4df4 64890d00000000 59 5b }
- $sequence_1 = { 8b55f8 52 8b4dfc 83c134 e8???????? 8b00 50 }
- $sequence_2 = { 83c270 52 8b4dfc 83c170 }
- $sequence_3 = { e8???????? c745d400000000 eb09 8b4dd4 83c101 894dd4 8d4d0c }
- $sequence_4 = { 7420 0fb645fb 50 8b4df4 8b4918 e8???????? 0fb6d0 }
- $sequence_5 = { 0fb74202 50 ff15???????? 0fb7c8 8b5514 890a }
- $sequence_6 = { 6a00 8b45fc 50 8b4d08 51 e8???????? 83c418 }
- $sequence_7 = { e8???????? 8d8ddcfbffff e8???????? c645fc0e 6a00 68e0930400 6a00 }
- $sequence_8 = { 0de0000000 b901000000 6bd100 8b4d0c 880411 8b5508 c1fa06 }
- $sequence_9 = { 8b4df4 3b4df8 750b 68???????? ff15???????? 8b55ec 833a22 }
+ $sequence_0 = { 0fbe441fff 83c404 2bd8 8bf3 8d4601 }
+ $sequence_1 = { 59 c745e401000000 c745e803000000 c745ec05000000 894df0 c745f408000000 c745f80a000000 }
+ $sequence_2 = { c645f800 e8???????? 8b45d4 5b 8b4dfc 33cd 5f }
+ $sequence_3 = { ff5108 e8???????? c3 beff010000 56 }
+ $sequence_4 = { ff750c 8365e000 ff7508 33c0 c645e400 8d7de5 }
+ $sequence_5 = { 5f c9 c3 6a1f }
+ $sequence_6 = { eb07 888415b4fdffff 42 41 41 }
+ $sequence_7 = { 8bf0 e8???????? 99 2bf7 f7fe }
+ $sequence_8 = { 55 8bec 53 56 6a03 5b }
+ $sequence_9 = { 83e003 33d2 3955f0 8945f8 }
condition:
- 7 of them and filesize <480256
+ 7 of them and filesize <581632
}
-rule MALPEDIA_Win_Boatlaunch_Auto : FILE
+rule MALPEDIA_Win_Feed_Load_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "109242da-f9c2-50c8-b49d-1f772a8283fe"
+ id = "de841c4a-765f-51dc-8d45-847efc3fe997"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.boatlaunch"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.boatlaunch_auto.yar#L1-L169"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.feed_load"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.feed_load_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "efa924e2b3901352dc645d99e6dd6dafbe8ab78c7c6ccaefe300da9883a180c7"
+ logic_hash = "904d3316a4655c20d123c0cfc976a8494c8f04b302e9078044dfcb4ef1ebf390"
score = 75
quality = 75
tags = "FILE"
@@ -151126,38 +158265,32 @@ rule MALPEDIA_Win_Boatlaunch_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4883611000 4883612800 488d4dd8 48c7c2ffff1f00 4c8d45e0 4c8d4d10 }
- $sequence_1 = { e8???????? 8945e4 6a00 ff75e0 }
- $sequence_2 = { 2b75ec 0375e4 8b4324 2b45ec 0345e4 }
- $sequence_3 = { 488d4df0 e8???????? 48c7c1ffffffff 488d55f0 448bc3 e8???????? 3b8558110000 }
- $sequence_4 = { 480375c8 8b4324 2b45c0 480345c8 488945d0 8b5b18 ad }
- $sequence_5 = { 85f6 7599 488b0d???????? 33d2 4c8b4500 }
- $sequence_6 = { 3b8560110000 7526 488b45d0 0fb730 }
- $sequence_7 = { 488d4dd0 48c7c200001000 4c8d45e0 4c8d4d10 e8???????? 3d0b0000c0 7427 }
- $sequence_8 = { 50 68ff0f1f00 8d45fc 50 }
- $sequence_9 = { 8bfe 49 85c9 75ee }
- $sequence_10 = { e8???????? 8bd8 85db 7452 53 }
- $sequence_11 = { eb09 8345e802 4b 85db 75af }
- $sequence_12 = { 50 e8???????? 3d0b0000c0 7423 6a00 ff75f8 e8???????? }
- $sequence_13 = { 5b 5d c3 48894c2408 89542410 4489442418 }
- $sequence_14 = { 488b45d8 488d6528 415b 415a 4159 4158 }
- $sequence_15 = { 8d5ddc c70318000000 c7430400000000 c7430800000000 c7430c00000000 }
+ $sequence_0 = { 48897c2428 4d8bc5 41b940200000 e8???????? 85c0 0f84e2000000 }
+ $sequence_1 = { 0f97c1 493bd2 eb27 4c8d42ff 418a00 4d8d4c24ff 413801 }
+ $sequence_2 = { 41898500400000 488bfd 4d8bfa bd01000000 83fb0d 0f8c42030000 41690ab179379e }
+ $sequence_3 = { 668928 e8???????? 4c8d86500c0000 488bcf e8???????? 4c8d442440 488bcf }
+ $sequence_4 = { 7876 3b1d???????? 736e 488bc3 488bf3 48c1fe06 4c8d2d7a220200 }
+ $sequence_5 = { 0f8c60040000 41837e0800 4c8d05b755ffff 7429 49635608 48035608 0fb60a }
+ $sequence_6 = { 8bd5 ff15???????? 448bc5 488bd6 488bc8 4c8bf0 }
+ $sequence_7 = { 488bc2 4903c7 4103df 803800 75f5 3bdf 7207 }
+ $sequence_8 = { 4c8d3de9c00100 49393cdf 7402 eb22 e8???????? 498904df }
+ $sequence_9 = { 488d157b020200 488d4d88 e8???????? cc }
condition:
- 7 of them and filesize <33792
+ 7 of them and filesize <512000
}
-rule MALPEDIA_Win_Jimmy_Auto : FILE
+rule MALPEDIA_Win_Kimjongrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6665c46a-fce5-5107-8692-d73430db94ca"
+ id = "db4baf64-c410-5dd4-86f2-fb3657762c91"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jimmy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jimmy_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kimjongrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kimjongrat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "5955b25aaac6bf582c8efb23dc58fc592d4dcf4b96826a166327d6d4b0ee873a"
+ logic_hash = "515b099b5f4271a4a56e7e428e24670deb74340ff8bb9a2bab6a20ed3f485ca9"
score = 75
quality = 75
tags = "FILE"
@@ -151171,32 +158304,32 @@ rule MALPEDIA_Win_Jimmy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8908 eb11 e8???????? 8945f4 ff75f8 e8???????? 59 }
- $sequence_1 = { 8b4508 83602c00 8b45fc c9 c3 55 8bec }
- $sequence_2 = { 89814c010000 eb27 a1???????? 8b4de4 898840010000 ff75e4 }
- $sequence_3 = { ff7508 ff55fc 59 59 c9 c3 55 }
- $sequence_4 = { 6a73 58 668945f2 6a20 58 668945f4 6a25 }
- $sequence_5 = { 8b4508 ff702c 8b4508 ff7024 e8???????? 59 59 }
- $sequence_6 = { 50 8d45c4 50 8b4508 83c008 50 6a00 }
- $sequence_7 = { 85c0 7419 8b45fc 0fbe00 8b4df8 0fbe09 }
- $sequence_8 = { e8???????? 59 b001 c9 c20800 }
- $sequence_9 = { 6a09 e8???????? 59 59 8945fc ff7510 ff750c }
+ $sequence_0 = { e9???????? c6840db4edffff2a e9???????? c6840db4edffff26 e9???????? c6840db4edffff5b eb6c }
+ $sequence_1 = { e8???????? 8bd8 83c414 85db 0f8508010000 33c9 894de4 }
+ $sequence_2 = { ff7004 8d4108 50 e8???????? 8b5508 8b4840 894a20 }
+ $sequence_3 = { ff7508 e8???????? 6a01 57 6a4c 56 e8???????? }
+ $sequence_4 = { e9???????? 8b4c8f58 894dd0 898d60ffffff 8b55a4 b860240000 66854208 }
+ $sequence_5 = { c68540d0ffff00 e8???????? 83c40c ba???????? 33c9 8a02 42 }
+ $sequence_6 = { e9???????? c6840da0e8ffff77 e9???????? c6840da0e8ffff76 e9???????? c6840da0e8ffff65 e9???????? }
+ $sequence_7 = { ff30 e8???????? 8b450c 83c404 c70000000000 8b55f8 c645f000 }
+ $sequence_8 = { e9???????? c6840dccf3ffff2d e9???????? c6840dccf3ffff7d e9???????? c6840dccf3ffff29 e9???????? }
+ $sequence_9 = { 8bf8 83c404 897dac 85ff 0f8418f3ffff b800400000 66854608 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <1572864
}
-rule MALPEDIA_Win_Ratel_Auto : FILE
+rule MALPEDIA_Win_Uacme_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0998b123-774e-59b1-8ca2-1a95e1fb9bf7"
+ id = "f5c3a5f2-a252-5543-b1be-134e5f419833"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ratel"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ratel_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.uacme"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.uacme_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "32361790b47e0503007c9763001c72d5f3f0666a6e89a8bab7c3bc0bd295eb6a"
+ logic_hash = "9cc750a1f13cae79bcf2cd2e379aedeb4cbdf45f9813c77d239c596ff07109f6"
score = 75
quality = 75
tags = "FILE"
@@ -151210,32 +158343,32 @@ rule MALPEDIA_Win_Ratel_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89d9 e8???????? 85c0 75e7 89d9 e8???????? 89d9 }
- $sequence_1 = { a1???????? 85c0 0f85bb010000 8b41fc 8d50ff 8951fc }
- $sequence_2 = { 8b442454 8b542414 8b400c 85d2 0f851f040000 83f802 }
- $sequence_3 = { 8bbc24b0000000 e8???????? 8b00 c744245cffffffff c7442460ffffffff 89442428 8b8424a4000000 }
- $sequence_4 = { 0f83a3020000 0fb700 6683f8ff b800000000 0f4545ac 8945ac b800000000 }
- $sequence_5 = { 668993f0000000 c783f400000000000000 c783f800000000000000 c783fc00000000000000 c7830001000000000000 c703???????? c7437c98ce4b00 }
- $sequence_6 = { c703???????? c7437884124c00 e8???????? 89b3f0000000 83ec04 8d65f4 5b }
- $sequence_7 = { 0f9fc1 084dc9 8b4d08 8345cc01 8b4108 3b410c 0f8240ffffff }
- $sequence_8 = { 8b4340 c7431400000000 c7431000000000 0fb67b58 894304 894308 89430c }
- $sequence_9 = { 8d4304 89c1 89c6 e8???????? 89b3ec000000 83ec04 8d65f4 }
+ $sequence_0 = { ba???????? e8???????? 8d8df0fbffff e8???????? 8bf8 85ff 741b }
+ $sequence_1 = { ff9620060000 33c0 5e 8be5 5d c20400 }
+ $sequence_2 = { eb23 8b4d08 e8???????? 03c0 }
+ $sequence_3 = { 8d45d8 50 6804900000 56 ff15???????? 6808700000 56 }
+ $sequence_4 = { ba???????? 8d8940040000 e8???????? 8b45fc ff7010 ffd6 }
+ $sequence_5 = { 8bd8 85db 74d3 8b5508 8bcb e8???????? }
+ $sequence_6 = { 668974242e ff15???????? 85c0 0f88c9040000 ff15???????? b940040000 }
+ $sequence_7 = { e8???????? 8bce 8d85e0fbffff 8818 40 83e901 }
+ $sequence_8 = { b9???????? e8???????? 6683bdf0fbffff00 8bf0 740d 8d85f0fbffff 50 }
+ $sequence_9 = { 8d85f0fbffff 50 8d85e0f7ffff 50 e8???????? 8bd8 }
condition:
- 7 of them and filesize <2174976
+ 7 of them and filesize <565248
}
-rule MALPEDIA_Win_Gh0Sttimes_Auto : FILE
+rule MALPEDIA_Win_Xbtl_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "edb23d28-51bf-5c0e-a6f1-7bed7d79f2ed"
+ id = "7372571c-d52e-5b5b-bd42-81e7e356cc7e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gh0sttimes"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gh0sttimes_auto.yar#L1-L163"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xbtl"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xbtl_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "cd1718bc24ef159d263847a726492a25887a81e094fffc2e2f0e4d7ba74c2151"
+ logic_hash = "b45bdfe7ddb3c3bebb25f685acba4274921aebf8fbd081dea272d3bf592a2a7b"
score = 75
quality = 75
tags = "FILE"
@@ -151249,38 +158382,32 @@ rule MALPEDIA_Win_Gh0Sttimes_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 899df0fdffff 899decfdffff 889df4fdffff 889df5fdffff 889df6fdffff 889df7fdffff 889df8fdffff }
- $sequence_1 = { 52 50 8985dcfdffff e8???????? }
- $sequence_2 = { 50 ff15???????? 85c0 750f 5b }
- $sequence_3 = { 33c5 8945fc 8b4508 53 33db 8d8de0fdffff 51 }
- $sequence_4 = { 0f852c010000 b8???????? 8d5001 8d642400 }
- $sequence_5 = { 8b0e 51 ff15???????? 43 }
- $sequence_6 = { 6a09 8d4df0 c645f070 8945f5 e8???????? 8b4dfc 5f }
- $sequence_7 = { 0f8638010000 83c708 8b57fc 8b85ecfdffff 52 }
- $sequence_8 = { 488b4c2438 488d442430 488d150c710200 4889442428 }
- $sequence_9 = { 488b4c2438 488d442434 4c8d4c2430 4889442428 488d442440 488d1520790200 }
- $sequence_10 = { 488b8f40010000 ff15???????? 488b8f40010000 ff15???????? 48c78740010000ffffffff }
- $sequence_11 = { 488b4c2430 488b4968 e8???????? 4c8b5c2430 }
- $sequence_12 = { 488b4c2430 83490c08 a808 7409 488b442430 83480c04 }
- $sequence_13 = { 488b4c2430 48c1e80c f7d0 334108 }
- $sequence_14 = { 488b4c2438 488d442430 488d15da700200 4889442428 }
- $sequence_15 = { 488b4c2430 488b4968 33c0 66890451 488b442430 }
+ $sequence_0 = { ffd7 50 ffd3 8bd8 85f6 7406 8d45e8 }
+ $sequence_1 = { 99 8bd8 8bc1 99 33f6 0bf0 3135???????? }
+ $sequence_2 = { 8d45ec 8d95f0fdffff e8???????? 8b85d4fdffff 56 56 6a03 }
+ $sequence_3 = { 85d2 782a 895dfc 8b4d08 0fb63c0a 8b460c 0345fc }
+ $sequence_4 = { 0fb67808 89948dc0feffff 0fb65007 c1e208 0bd7 }
+ $sequence_5 = { 83c41c 8d4c2410 51 ffd7 8b442434 8b4c2428 8b1d???????? }
+ $sequence_6 = { 8bd6 897c2420 2bd0 0fb708 66890c02 83c002 }
+ $sequence_7 = { 03048de0c04200 eb02 8bc2 f6402480 7417 e8???????? c70016000000 }
+ $sequence_8 = { 81e600ff00ff c1c208 81e2ff00ff00 0bf2 897018 8b491c }
+ $sequence_9 = { 8b5708 40 83c410 894704 3bc2 7e16 8d0412 }
condition:
- 7 of them and filesize <548864
+ 7 of them and filesize <401408
}
-rule MALPEDIA_Win_Slub_Auto : FILE
+rule MALPEDIA_Win_Decaf_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "195b7942-1783-5df2-bcee-76020ab94f8f"
+ id = "871b7c64-9bb1-5d5d-b760-fe69f683da0a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.slub"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.slub_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.decaf"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.decaf_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "654a15994e2d79fd54a129ac2f9c4ef4cc1a02067acc10e29921ff8e80b39dab"
+ logic_hash = "2f8679cf6195e76585744c378fca956597817fdb2b26b865768f35c66fced6eb"
score = 75
quality = 75
tags = "FILE"
@@ -151294,32 +158421,32 @@ rule MALPEDIA_Win_Slub_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff742420 55 e8???????? 83c414 89442414 85c0 0f8512010000 }
- $sequence_1 = { 807c241200 7407 c686e808000000 80beb406000000 740f ffb6b0060000 ff15???????? }
- $sequence_2 = { c785bcf8ffffcce48f00 8bc8 c785c0f8ffffa0358400 c785c4f8ffff90e98500 e8???????? 8d95bcf8ffff c785bcf8ffffd8e48f00 }
- $sequence_3 = { 85ff 750e 837d2c10 8d4518 0f43c2 3a08 7c13 }
- $sequence_4 = { 85c0 0f8443ffffff 8b96f4000000 85d2 0f8435ffffff 8b8df0000000 6690 }
- $sequence_5 = { 6800000100 6a00 6801000100 56 ff15???????? 89442414 85c0 }
- $sequence_6 = { 898640010000 85c0 0f8416050000 57 e8???????? 83c404 85c0 }
- $sequence_7 = { e8???????? 50 68???????? ffb50cfdffff e8???????? ffb50cfdffff }
- $sequence_8 = { 8d8dc8ebffff 50 ffb5c8ebffff e8???????? 8b85c4ebffff c785dcebffff0f000000 c785d8ebffff00000000 }
- $sequence_9 = { 8b86dc050000 89863c040000 8b86e0050000 898694040000 8b86e4050000 898640040000 8b86e8050000 }
+ $sequence_0 = { e8???????? e8???????? 48898424a8180000 48899c2440060000 488b0d???????? 48898c2420230000 488d0543040c00 }
+ $sequence_1 = { 4c8b442470 4889c7 4889ce 488b442440 c7041fcacccec6 b905000000 e9???????? }
+ $sequence_2 = { e9???????? 4c8d4302 4c39c6 7337 4c89442468 488d05d8a30300 4889d9 }
+ $sequence_3 = { c3 488d0582761b00 bb10000000 e8???????? 4889f8 b900200000 e8???????? }
+ $sequence_4 = { e8???????? 488b8c24b8040000 48894808 833d????????00 7514 488b8c2410160000 488908 }
+ $sequence_5 = { eb1c 4889c7 488b8c24f0120000 e8???????? 488d3d53871f00 e8???????? e8???????? }
+ $sequence_6 = { e8???????? 488d05d4ad1300 488d1d95d21900 e8???????? 4d8d6830 4c89d6 4d89ea }
+ $sequence_7 = { e9???????? 90 66c744244f1c14 0fb654244f 88542445 440fb6442450 4488442444 }
+ $sequence_8 = { c6041f95 31c9 e9???????? 4983f809 754d 4c8d4301 4c39c6 }
+ $sequence_9 = { e9???????? 48895c2428 4889442430 488d0d664c1d00 bf0d000000 e8???????? 4885c0 }
condition:
- 7 of them and filesize <1785856
+ 7 of them and filesize <7193600
}
-rule MALPEDIA_Win_Nocturnalstealer_Auto : FILE
+rule MALPEDIA_Win_Bistromath_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "16d4de33-3c54-5479-87ac-366869086324"
+ id = "62a1b548-25a5-5273-be8b-9848556649f4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nocturnalstealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nocturnalstealer_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bistromath"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bistromath_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "6f15e0c8b7c880f99f33b6a9409ba20c65fe7c5674e094de4ef3ad4c2fb61399"
+ logic_hash = "b9314d0c2625ba0e21f5bfba175e042ed0e577dd2d934e440857096b6f3294e9"
score = 75
quality = 75
tags = "FILE"
@@ -151333,32 +158460,32 @@ rule MALPEDIA_Win_Nocturnalstealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff3424 5e 56 e9???????? 81e945418082 01ca e9???????? }
- $sequence_1 = { e9???????? 09d6 5f 81e220000000 ba00000000 81f700000080 81eeffffff7f }
- $sequence_2 = { e9???????? 01742404 ff3424 5e 57 89e7 e9???????? }
- $sequence_3 = { 89ef ba00020000 2524000000 09cb 05ffffff7f 81e6ffffff7f 81c7a2000000 }
- $sequence_4 = { e9???????? 83c004 330424 310424 330424 5c 55 }
- $sequence_5 = { b8b4888b7f 251810fb62 253a26e37e 05b68054fc 31c7 e9???????? 331c24 }
- $sequence_6 = { e9???????? 8d852731bc18 52 89e2 50 b804000000 01c2 }
- $sequence_7 = { e9???????? 895c2404 8b1c24 83c404 893424 890424 e9???????? }
- $sequence_8 = { e9???????? 57 891c24 890424 e9???????? 81c704000000 81c704000000 }
- $sequence_9 = { f7d8 f7d0 c1e808 c1e802 e9???????? 29cf 8b0c24 }
+ $sequence_0 = { e8???????? 85c0 741d 0f57c0 0f1100 0f114010 660fd64020 }
+ $sequence_1 = { ff75f0 56 e8???????? 8b45f8 83c40c c6040600 8bce }
+ $sequence_2 = { eb24 8d5001 e8???????? 8bf0 85f6 7416 ff75fc }
+ $sequence_3 = { e8???????? 8b4580 46 3bf0 7ce8 33f6 85db }
+ $sequence_4 = { e8???????? 8b4c2410 8901 83c718 8b442424 83c104 894c2410 }
+ $sequence_5 = { 8b45e8 85c0 0f84bb250000 ff474c 8d535f 8b7f4c 8bce }
+ $sequence_6 = { e8???????? 8945e4 85c0 0f84e1010000 ff75f0 33d2 8bcb }
+ $sequence_7 = { ff75fc e8???????? 8bf0 83c404 85f6 7418 8d45fc }
+ $sequence_8 = { 8b4df8 e8???????? 8b5324 8b4df8 e8???????? 6a30 6a00 }
+ $sequence_9 = { 83c404 46 8d7efe 83fe02 7304 33d2 eb2e }
condition:
- 7 of them and filesize <10739712
+ 7 of them and filesize <33816576
}
-rule MALPEDIA_Win_Photolite_Auto : FILE
+rule MALPEDIA_Win_Milkmaid_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "91b305a0-4121-51a1-b4d2-2f8343c04744"
+ id = "7c60d500-9a52-5cea-8bfb-4d836c40072e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.photolite"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.photolite_auto.yar#L1-L166"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.milkmaid"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.milkmaid_auto.yar#L1-L100"
license_url = "N/A"
- logic_hash = "caefd484ddfe657e42e053f8e8452f60715f0696ed8aba66627e49aa5e3366fe"
+ logic_hash = "c4a5987f68f519192a013c67faec02935457872f835e55aadbf7cdc1a7483580"
score = 75
quality = 75
tags = "FILE"
@@ -151372,38 +158499,30 @@ rule MALPEDIA_Win_Photolite_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c7859802000042cc7257 c7859c02000075cc545d c785a002000040c02638 8b8594020000 8a8590020000 84c0 751e }
- $sequence_1 = { ff15???????? 498bd6 488d4d76 ff15???????? 8a4301 }
- $sequence_2 = { c7859405000037f43a3a c785980500002fef391c c7859c0500000be1241d c785a00500002fe54a79 8b8590050000 8a858c050000 84c0 }
- $sequence_3 = { 8a85e0020000 84c0 751e 488bcb 8b848de4020000 }
- $sequence_4 = { 4803cf 483bce 72e5 885c244c c744245057106c10 c7442454556a4c30 }
- $sequence_5 = { 8bc3 4d03ca 85d2 7474 448bc0 }
- $sequence_6 = { 7421 0f1002 488bc2 482bc6 482bc7 }
- $sequence_7 = { 7307 488b7c2430 eba3 488b5c2448 }
- $sequence_8 = { 48895d38 48895da0 895d30 488b01 ff5070 8bf8 85c0 }
- $sequence_9 = { 488bd8 4885c0 0f8419010000 488b15???????? }
- $sequence_10 = { 488bcb ffd0 ffc6 41b8bb010000 8bd6 }
- $sequence_11 = { 84c0 0f85f5000000 4885db 7451 488b05???????? 4885c0 7426 }
- $sequence_12 = { 72e9 4c8d442444 41b901000000 488d047e 410fb6d1 }
- $sequence_13 = { 3dc8000000 0f849d000000 488b5d28 4885db }
- $sequence_14 = { 75f2 33db 4084f6 0f84e6000000 }
- $sequence_15 = { 488d542474 488d8de0020000 ff15???????? 408874245c }
+ $sequence_0 = { 7440 56 ff15???????? 8d4c2414 }
+ $sequence_1 = { c68424dc28010002 e8???????? 8d4c2410 c68424dc28010001 }
+ $sequence_2 = { 50 53 ff15???????? 8d4c2478 c68424dc28010002 }
+ $sequence_3 = { 6a00 ff15???????? 6aff 8d4c2408 e8???????? 68???????? 8d4c2408 }
+ $sequence_4 = { 895c2428 7513 8b5508 52 53 }
+ $sequence_5 = { 8d442408 57 50 e8???????? 83c404 33db }
+ $sequence_6 = { 8be9 896c2420 8a8528280100 84c0 7528 8b4d04 }
+ $sequence_7 = { 51 8d8c2480000000 c68424e428010003 e8???????? b911000000 }
condition:
- 7 of them and filesize <99328
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Reactorbot_Auto : FILE
+rule MALPEDIA_Win_Luca_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "db667bb6-5a2a-5433-bb3f-44b94a1b8ccd"
+ id = "8a0c166d-37f3-5a13-bfc2-83fc09a4679d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.reactorbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.reactorbot_auto.yar#L1-L159"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.luca_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.luca_stealer_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "a8dd74cde779dbd1edde8ec6ea240ea579363dd37eac297b9622688e884b36e8"
+ logic_hash = "f2eabac635b7bb4e193cfff7279ec9fd429ac964f492c856eb49bfd67aa7534f"
score = 75
quality = 75
tags = "FILE"
@@ -151417,38 +158536,32 @@ rule MALPEDIA_Win_Reactorbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ff15???????? 8d8d90fdffff 51 8d9580f9ffff }
- $sequence_1 = { c745f400000000 c745e800000000 c745e400000000 a1???????? 8945e0 }
- $sequence_2 = { 7418 6aff a1???????? 50 ff15???????? }
- $sequence_3 = { 837dfcff 7411 8b4dfc 51 ff15???????? }
- $sequence_4 = { 8b4d08 51 ff15???????? 83c404 8945f0 }
- $sequence_5 = { 8b4508 50 6804010000 8d8d78f7ffff 51 e8???????? }
- $sequence_6 = { ff15???????? 8945fc 837dfc00 7479 837dfcff }
- $sequence_7 = { 7420 8b0d???????? 51 8b15???????? 52 }
- $sequence_8 = { 83c005 99 b905000000 f7f9 }
- $sequence_9 = { 6bc005 83e803 99 b999000000 }
- $sequence_10 = { 69c0b13a0200 99 83e203 03c2 }
- $sequence_11 = { e8???????? 833d????????00 7509 833d????????00 740b }
- $sequence_12 = { eb0c c705????????b80b0000 eb0a c705????????e8030000 }
- $sequence_13 = { 83e101 f7d9 81e12083b8ed 33c1 }
- $sequence_14 = { 483d00080000 7323 4863442450 488b4c2468 0fb609 888c04e0030000 }
- $sequence_15 = { 83e203 03c2 c1f802 89442410 8b4c240c }
+ $sequence_0 = { e8???????? 488bf8 81e7ffffff3f 498b4e60 488b5910 4885db 7452 }
+ $sequence_1 = { f645ef02 741d 807df101 7417 b201 488d4de7 e8???????? }
+ $sequence_2 = { eb06 4531c0 4889d0 48c7837802000002000000 44888380020000 c6838102000000 48898388020000 }
+ $sequence_3 = { e8???????? 498b0f 498b4708 4983670800 4885c0 740f 4883c420 }
+ $sequence_4 = { ff15???????? 894530 85c0 0f842b520000 488dbd501f0000 8b0f e8???????? }
+ $sequence_5 = { e8???????? 85c0 0f85be000000 488bcb e8???????? 488b8798090000 498bce }
+ $sequence_6 = { e8???????? 85c0 740c 488b0b 8a0439 2c3a 3c01 }
+ $sequence_7 = { e9???????? 488d3515b8d8ff eb03 4d03fd 410fb607 4484ac30009e4100 75ef }
+ $sequence_8 = { e9???????? b009 eb4f 488b842490000000 66c7000109 e9???????? 488db424e0000000 }
+ $sequence_9 = { eb86 e8???????? 0f0b 4157 4156 4155 4154 }
condition:
- 7 of them and filesize <1032192
+ 7 of them and filesize <9285632
}
-rule MALPEDIA_Win_Blackmagic_Auto : FILE
+rule MALPEDIA_Win_Milum_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dd528f6f-030a-5c0c-abc0-3a9e54fb0bef"
+ id = "a4720d6d-5a40-5b38-8cc6-14b0dce6d896"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackmagic"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackmagic_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.milum"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.milum_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "9b47417ce0472639cee5ef75e6c79509f45487b7ad058f003aa41d6f30ea451f"
+ logic_hash = "3d087e33a30d06df9f4db7e1d4f924bf7ada8b431d51e99d5cf8912956a67294"
score = 75
quality = 75
tags = "FILE"
@@ -151462,32 +158575,32 @@ rule MALPEDIA_Win_Blackmagic_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d15b40c0700 488bcd e8???????? 488b4620 488903 488b5c2430 488b6c2438 }
- $sequence_1 = { 4c8b01 ba01000000 41ff10 90 488bc7 488b4c2458 4833cc }
- $sequence_2 = { 4863d0 488d4dd0 488b94d3086c0700 e8???????? 488b0d???????? 0fbe01 }
- $sequence_3 = { 3bc3 740a 8b5c245c 85db 748d eb35 ff15???????? }
- $sequence_4 = { 48895e08 488b4718 4c894010 488b4718 49894018 4c894718 49897810 }
- $sequence_5 = { 0f114160 0f104070 488b8090000000 0f114170 0f118980000000 48898190000000 488d0587eaffff }
- $sequence_6 = { 0f867d030000 458d7302 448d7d02 8bc5 4c8d1483 418b3a }
- $sequence_7 = { 41f782b800000000080000 7427 498b8ad0000000 410fb6d3 e8???????? 440fb65c2430 0fbec8 }
- $sequence_8 = { 488bd0 e8???????? 488b5308 498bce 482b13 48c1fa02 e8???????? }
- $sequence_9 = { 4881f900100000 7223 488d4127 483bc1 0f8681000000 488bc8 e8???????? }
+ $sequence_0 = { 8db53cffffff e8???????? 83c41c c645fc20 50 8d4d90 e8???????? }
+ $sequence_1 = { 837b1800 0f8507010000 8b45f0 50 8d75dc e8???????? 837b1800 }
+ $sequence_2 = { 50 e8???????? 8bc6 eb0f 885dfc 8d8d34ffffff }
+ $sequence_3 = { 8b4dcc 8b55c8 83c40c c78574ffffff44000000 8945ac 894db4 814da001010000 }
+ $sequence_4 = { 8d8d10feffff e8???????? c645fc1e 8d8df4fdffff e8???????? c645fc1d }
+ $sequence_5 = { 2bc6 c7421803000000 89421c 395a18 0f849cfeffff ddd8 ddd8 }
+ $sequence_6 = { 6bc064 2bc8 8d045590a64600 0fb610 8816 0fb64001 884601 }
+ $sequence_7 = { 385f45 7503 895704 8b7a04 897e04 8b7804 3b5704 }
+ $sequence_8 = { 8bca eb0e 8b55e8 2bd1 8b4e44 8955d4 894ddc }
+ $sequence_9 = { 8d7508 83ec1c 8bcc 8bc6 c741140f000000 895910 896598 }
condition:
- 7 of them and filesize <1416192
+ 7 of them and filesize <1076224
}
-rule MALPEDIA_Win_Whiskerspy_Auto : FILE
+rule MALPEDIA_Win_Unidentified_006_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ad364f6a-593c-546a-abca-058cacdb86c1"
+ id = "1d29f273-95a4-58bd-87cd-6ac677036b5c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.whiskerspy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.whiskerspy_auto.yar#L1-L150"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_006"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_006_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "5c2084905c4059cab930cb01fc75781ec2a6ce873c993665138e09c62922860b"
+ logic_hash = "dd723dd2c53afa22a9c28d9c9c06ec724a63cc0cfcf78b59a425b4cdf0fd8bc1"
score = 75
quality = 75
tags = "FILE"
@@ -151501,37 +158614,32 @@ rule MALPEDIA_Win_Whiskerspy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b06 8bcf d3e8 a801 }
- $sequence_1 = { 488bcf c645e57d c645e67d c645e77d c645e87d }
- $sequence_2 = { 458bc6 488d95c0020000 488d8d80010000 ff15???????? 488d4c2460 ff15???????? }
- $sequence_3 = { 5d c3 418bca 48899c2440020000 }
- $sequence_4 = { 33c0 e9???????? c685c0020000c8 c685c1020000d3 }
- $sequence_5 = { e8???????? 0f2805???????? 4c8d45b0 0f280d???????? 488d55f0 }
- $sequence_6 = { 8bf9 488d1507c10000 b903000000 4c8d05f3c00000 e8???????? }
- $sequence_7 = { 85c0 7428 817c245000040000 74b4 eb1c }
- $sequence_8 = { 0fbec1 83e820 83e07f 8b04c5d43f4300 }
- $sequence_9 = { 33c5 8945fc 53 8bd9 899540ffffff 8b4d0c }
- $sequence_10 = { f30f38f6f8 897de4 b800000000 8b7de8 660f38f6f9 }
- $sequence_11 = { 8b45ec 3bc6 7c3a 7f04 }
- $sequence_12 = { 6af6 ff15???????? 8b04bd403d4400 834c0318ff 33c0 }
- $sequence_13 = { 75f8 8bfe 8bca 8bb588feffff }
- $sequence_14 = { a3???????? 8bcf e8???????? 8325????????00 8325????????00 }
+ $sequence_0 = { 3907 7417 833e00 7408 ff36 e8???????? 59 }
+ $sequence_1 = { 6a00 8d45fc 897dfc 50 8d45f8 50 6a00 }
+ $sequence_2 = { 85c9 7410 8b55f4 85d2 7409 e8???????? 894708 }
+ $sequence_3 = { 8bf0 57 56 e8???????? 83c410 33c0 }
+ $sequence_4 = { 85f6 7410 57 8b7d0c 2bf8 }
+ $sequence_5 = { 0fb6875c204000 47 03c6 83c603 25ff000000 }
+ $sequence_6 = { eb45 8b7510 85f6 743c }
+ $sequence_7 = { 8b4dfc 83c40c 8bf7 8bd7 85c9 7421 83ff0c }
+ $sequence_8 = { 33ff 53 ff15???????? 53 ff15???????? }
+ $sequence_9 = { 57 6a40 8bc2 33ff 6800300000 50 }
condition:
- 7 of them and filesize <591872
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Ramnit_Auto : FILE
+rule MALPEDIA_Win_Mole_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9f7bb136-c877-5703-86ba-5c3c0993dd1e"
+ id = "36f8515b-9850-5f6a-9da2-fab216acb0f1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ramnit"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ramnit_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mole"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mole_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "a743fa525eb529644f7aae0eeccbdf2bcc4af05febdbf59986022c9547272ab4"
+ logic_hash = "9e8bd455bb765e10346652a5931be596133d0a24ad14fb98b5a58db6c1dd57c3"
score = 75
quality = 75
tags = "FILE"
@@ -151545,32 +158653,32 @@ rule MALPEDIA_Win_Ramnit_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3a06 7512 47 46 e2f6 b801000000 59 }
- $sequence_1 = { 750b 4f 3b7d08 73e7 bf00000000 }
- $sequence_2 = { 57 56 fc 807d1401 }
- $sequence_3 = { 5f 59 5a 5b c9 c20800 55 }
- $sequence_4 = { ff750c ff75fc e8???????? 0bc0 7429 }
- $sequence_5 = { 8bc7 5a 5b 59 5f }
- $sequence_6 = { 8bc1 f7d0 48 59 5f 5e }
- $sequence_7 = { f3a4 fc 5e 5f 59 5a }
- $sequence_8 = { 8bd7 2b5508 59 5f 5e }
- $sequence_9 = { 8b5d0c 4b f7d3 23c3 }
+ $sequence_0 = { 81bdf0fdffff99000000 0f8787710000 8b95f0fdffff 0fb68248c04000 ff248514c04000 81bdf0fdffffd3a7d105 0f8794000000 }
+ $sequence_1 = { 6bc000 0385bcf9ffff 898588e5ffff 837d1401 751a 68???????? 68???????? }
+ $sequence_2 = { 81bdf0fdffffcde5d405 0f8458400000 81bdf0fdffff41e6d405 0f849e440000 81bdf0fdffff44e6d405 0f84742c0000 e9???????? }
+ $sequence_3 = { e9???????? 81bdf0fdffff5625d105 0f8786000000 81bdf0fdffff5625d105 0f8494710000 81bdf0fdffffc624d105 7745 }
+ $sequence_4 = { 8d959cefffff 52 68???????? 6801000080 ff15???????? 898584efffff 8d85d4fbffff }
+ $sequence_5 = { 8d85ace4ffff 50 6a05 68???????? 8b8dc4e4ffff 51 ff15???????? }
+ $sequence_6 = { c7802ceb410002000000 6a04 58 6bc000 8b0d???????? 894c05f8 6a04 }
+ $sequence_7 = { 8d9530e2ffff 52 e8???????? 83c404 6a64 68???????? 8d85ecfbffff }
+ $sequence_8 = { 83c410 8d959cf9ffff 52 8b8590e5ffff }
+ $sequence_9 = { e8???????? e8???????? 898580f7ffff 81bd80f7ffff00300000 7575 6a00 }
condition:
- 7 of them and filesize <470016
+ 7 of them and filesize <297984
}
-rule MALPEDIA_Win_Matrix_Banker_Auto : FILE
+rule MALPEDIA_Win_Manitsme_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5e463068-e12b-5f8d-ab9f-c81457da2c25"
+ id = "e6602fda-fe01-560f-b18c-c680ffd15493"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.matrix_banker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.matrix_banker_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.manitsme"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.manitsme_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "8e0666cd40465e0b5fba82c6d7538e5812414aad17fe7eeb1cf9c0a79b729bb8"
+ logic_hash = "d15a6ee2f4daf2c5f96b25b50dc747d6c2f7c5b49f115484153e22e9303b3c0c"
score = 75
quality = 75
tags = "FILE"
@@ -151584,71 +158692,71 @@ rule MALPEDIA_Win_Matrix_Banker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb0b 8d4abf 80f905 7703 }
- $sequence_1 = { 8d489f 80f905 7704 04a9 eb0a 8d48bf }
- $sequence_2 = { 8d4a9f 80f905 7705 80c2a9 eb0b }
- $sequence_3 = { 7705 80c2a9 eb0b 8d4abf 80f905 7703 80c2c9 }
- $sequence_4 = { 80f905 7702 04c9 8d4ad0 }
- $sequence_5 = { 80c2a9 eb0b 8d4abf 80f905 7703 80c2c9 }
- $sequence_6 = { ff15???????? e8???????? 85c0 740a e8???????? 83f8ff }
- $sequence_7 = { eb18 8d4a9f 80f905 7705 80c2a9 }
- $sequence_8 = { eb18 8d4a9f 80f905 7705 }
- $sequence_9 = { 8d489f 80f905 7704 04a9 eb0a 8d48bf 80f905 }
+ $sequence_0 = { 8b4c2438 33cc e8???????? 83c440 c3 6a0b 68???????? }
+ $sequence_1 = { 894c243c 894c2440 2bd0 8a08 880c02 83c001 84c9 }
+ $sequence_2 = { 6a00 6804040000 68???????? 57 }
+ $sequence_3 = { 83c408 eb09 57 e8???????? 83c404 8b15???????? 52 }
+ $sequence_4 = { 8b35???????? 57 8b3d???????? 8da42400000000 8d442428 50 }
+ $sequence_5 = { 8d442418 50 68fc030000 8d4c2424 }
+ $sequence_6 = { 897c2420 ff15???????? 8b0d???????? 51 ff15???????? 6a02 }
+ $sequence_7 = { 53 ff15???????? 68???????? 8d442418 50 c744241c401b0110 e8???????? }
+ $sequence_8 = { 897c2420 c744241c01000000 ff15???????? 83f8ff 7434 8d4c2408 }
+ $sequence_9 = { 8975e4 33c0 39b858340110 7467 ff45e4 }
condition:
- 7 of them and filesize <422912
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Knot_Auto : FILE
+rule MALPEDIA_Win_Tclient_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a6e6a5bf-ddf5-50fd-bee4-72bdce46b16d"
+ id = "f2038e8d-aea1-548a-a845-014bf9e62586"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.knot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.knot_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tclient"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tclient_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "1eb2f0d25dde1dc340b502f0b94dbb26bfbabe3643f1c7382f79e2ee4892b78f"
+ logic_hash = "d731098e1e4af77da640d6018efa5a27e1199a8bfd1426735ef45625c1645468"
score = 75
quality = 75
tags = "FILE"
version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { 50 8b8ddcfdffff 51 6a00 6a00 6a01 }
- $sequence_1 = { 55 8bec 81ec34010000 6a00 }
- $sequence_2 = { 6a18 6a00 6a00 68???????? ff15???????? 8d95f0f9ffff }
- $sequence_3 = { ff15???????? 83c408 6a01 6a00 }
- $sequence_4 = { 83bdd4fdffff00 7443 8b85d8fdffff 50 8b8ddcfdffff 51 }
- $sequence_5 = { 6800000040 8d95e0fdffff 52 ff15???????? }
- $sequence_6 = { ff15???????? 8b55ec 52 ff15???????? 8b45e8 50 ff15???????? }
- $sequence_7 = { 6a00 6a00 68???????? ff15???????? 8d95f0f9ffff 52 e8???????? }
- $sequence_8 = { 52 ff15???????? 85c0 7507 32c0 e9???????? c785d8fdffff00000000 }
- $sequence_9 = { 83c408 68???????? 8b8d74f7ffff 51 e8???????? }
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { 8be5 5d c21800 b8???????? e8???????? 83ec70 53 }
+ $sequence_1 = { 6685f6 7411 0fb7c2 42 885c0804 0fb7c2 42 }
+ $sequence_2 = { e9???????? 6a44 8d442444 53 50 e8???????? 33c0 }
+ $sequence_3 = { 50 8d0419 57 50 e8???????? 83c40c b880000000 }
+ $sequence_4 = { 894db0 2345a8 33c2 c1c105 034e28 81c29979825a 8b75a8 }
+ $sequence_5 = { 8b00 2bc1 8d4a01 3bc1 0f4cc8 894dec 85c9 }
+ $sequence_6 = { 59 59 85c0 7443 e9???????? 85f6 741e }
+ $sequence_7 = { 57 e8???????? 8b4304 2b4508 50 ff7508 }
+ $sequence_8 = { 6bc930 8b0495c0a04700 c644012801 8b0495c0a04700 897c0118 8bfe e9???????? }
+ $sequence_9 = { 89bebc010000 8a8398000000 888675030000 0fb68398000000 50 8d4366 50 }
condition:
- 7 of them and filesize <59392
+ 7 of them and filesize <1063936
}
-rule MALPEDIA_Win_Brbbot_Auto : FILE
+rule MALPEDIA_Win_Khrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e240fcbc-2659-5f11-92b2-f24493c78ffd"
+ id = "cae82139-c683-5bf8-8807-a11668477f96"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.brbbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.brbbot_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.khrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.khrat_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "d23aa206f76a72b99ca843cfc9c1f11b947cf7f249b06e1b49eb77df3aca0670"
+ logic_hash = "074673c423b5c49f07577630b1f328510bc324887f41ca6e4261bb8bfff0e2f0"
score = 75
quality = 75
tags = "FILE"
@@ -151662,32 +158770,32 @@ rule MALPEDIA_Win_Brbbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7509 488d0daad10000 eb02 33c9 e8???????? 4883c438 }
- $sequence_1 = { f2ae 48f7d1 48ffc9 4c8bc1 498d8e10040000 488bd5 e8???????? }
- $sequence_2 = { 48f7d1 4c8d41ff 488d8b04010000 e8???????? }
- $sequence_3 = { 885c2470 448bee 448bfe e8???????? 488b05???????? 4889442458 }
- $sequence_4 = { 48895808 488970e8 33ff 488978b8 4c8960e0 }
- $sequence_5 = { 48f7d1 48ffc9 4881f904010000 0f8724010000 4883c9ff }
- $sequence_6 = { 81fa01010000 7d13 4863ca 8a44191c 42888401c0230100 }
- $sequence_7 = { 488bfa ff15???????? 4c8d4704 488bc8 ba08000000 ff15???????? }
- $sequence_8 = { 4c8b7540 8bd8 85c0 0f88d6020000 4c8d4da8 }
- $sequence_9 = { 33d2 488bce e8???????? ff15???????? 4c8bc6 488bc8 33d2 }
+ $sequence_0 = { 8d858cfbffff 50 68f4030000 57 }
+ $sequence_1 = { 66c745e00000 8b859cfbffff 8945e8 8b8590fbffff 8945ec 8945f0 }
+ $sequence_2 = { c9 c20400 55 8bec 81c4d0f9ffff }
+ $sequence_3 = { 81c448feffff c705????????ffffffff 8d8572feffff 50 6802020000 e8???????? 6a06 }
+ $sequence_4 = { 68???????? 6a00 e8???????? 0bc0 0f840e010000 }
+ $sequence_5 = { 66c746326500 66c746347700 66c746363a00 66c746380000 8db500feffff }
+ $sequence_6 = { ff35???????? 8f45e6 8d45e2 50 e8???????? c9 }
+ $sequence_7 = { eb25 ff35???????? e8???????? 8d85d4fdffff }
+ $sequence_8 = { c9 c3 55 8bec 83c4fc 833d????????ff }
+ $sequence_9 = { 50 8d85bcf8ffff 50 8d85dcf8ffff 50 8d8500ffffff }
condition:
- 7 of them and filesize <198656
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Chiser_Client_Auto : FILE
+rule MALPEDIA_Win_Spyder_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e8afcaec-169c-5519-a609-4458271450b4"
+ id = "3ab12f00-3358-5020-939c-e2c585a1665c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chiser_client"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chiser_client_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spyder"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spyder_auto.yar#L1-L176"
license_url = "N/A"
- logic_hash = "3bc0569053961dd359f1e4296146fed96a2d550b29a6ec46396d68a2c22beadc"
+ logic_hash = "bab678e49456b3f7ffea3f1f145c31d0ca13e5400d7a321bcd98016f59a4377c"
score = 75
quality = 75
tags = "FILE"
@@ -151701,34 +158809,40 @@ rule MALPEDIA_Win_Chiser_Client_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 668945b7 488d55b7 488d4dd7 e8???????? b862000000 }
- $sequence_1 = { 488bcb e8???????? b801000000 4883c430 415e 5f }
- $sequence_2 = { e8???????? 488d156f390300 488d4c2420 e8???????? cc 48895c2408 4889742410 }
- $sequence_3 = { ff15???????? 483305???????? 488d15bedf0200 488bcb 488905???????? }
- $sequence_4 = { 894810 48634810 b802000000 48f7e1 48c7c1ffffffff 480f40c1 }
- $sequence_5 = { ff15???????? 8bd8 83f801 0f84c7030000 8bc8 83e902 }
- $sequence_6 = { 4c8d0564070000 eb1e 3d03003000 7509 }
- $sequence_7 = { 488bc8 488d15a48e0100 ff15???????? 4885c0 0f8432030000 488bc8 e8???????? }
- $sequence_8 = { 488944246a 89442472 6689442476 c74424502f006900 c74424546e006400 c744245865007800 c744245c2e006800 }
- $sequence_9 = { 488d1590500200 488d4d20 e8???????? cc 48895d08 4883651000 488b86a8000000 }
+ $sequence_0 = { 4053 4883ec20 8bd9 488d0da5a40000 ff15???????? 4885c0 7419 }
+ $sequence_1 = { 0f8493010000 488d156a5f0000 488bc8 ff15???????? 4885c0 0f847a010000 }
+ $sequence_2 = { 756e 488d4b04 4c8d05563e0000 418d5216 e8???????? 85c0 7437 }
+ $sequence_3 = { eb17 488b5638 498bcc ff5630 b97f000000 ff15???????? }
+ $sequence_4 = { 7422 488d15795e0000 488bce ff15???????? 488bc8 }
+ $sequence_5 = { 496374243c 4903f4 813e50450000 740b b9c1000000 }
+ $sequence_6 = { 7647 498bcd e8???????? 4c8d05478a0000 41b903000000 488d4c45bc 488bc1 }
+ $sequence_7 = { 85c0 7408 8bcb ff15???????? e8???????? 488d15faa20000 }
+ $sequence_8 = { 8b7d0c 8d0540460910 83780800 754e b741 b35a }
+ $sequence_9 = { 50 a3???????? e8???????? 8db6843d0910 bf???????? }
+ $sequence_10 = { 888800490910 eb1f 83f861 7213 83f87a 770e 8088????????20 }
+ $sequence_11 = { 83c424 aa 8d842484000000 6804010000 50 53 }
+ $sequence_12 = { 81e1ffff0000 50 51 68???????? 8d54243c }
+ $sequence_13 = { 68???????? 8d44242c 8d8c2494050000 50 68???????? }
+ $sequence_14 = { b801000000 5b 81c47c150000 c3 5f 5e 33c0 }
+ $sequence_15 = { 0fb6d2 f682014a091004 7403 40 }
condition:
- 7 of them and filesize <714752
+ 7 of them and filesize <1458176
}
-rule MALPEDIA_Win_Slingshot_Auto : FILE
+rule MALPEDIA_Win_Raccoon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bf558dcd-c863-525d-b34a-1a56d33f94ec"
+ id = "4a27386e-afe9-5aa0-b437-cb8672f32902"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.slingshot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.slingshot_auto.yar#L1-L218"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.raccoon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.raccoon_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "1e413348df71e72118297c6913e2a6da9548aa658d39b7dcd425460f21f929c0"
+ logic_hash = "744c135940d1e7204980afbdf51c2b964c1deff72c5358a0844976025962517f"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -151740,45 +158854,32 @@ rule MALPEDIA_Win_Slingshot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 33db 53 ff15???????? 8bf0 3bf3 }
- $sequence_1 = { 3bcb 7512 ff7708 ff37 }
- $sequence_2 = { 48 8bf0 66895804 66897806 85ed }
- $sequence_3 = { e8???????? e8???????? 8945d8 8955dc 3bc3 7d09 52 }
- $sequence_4 = { e8???????? ff7004 8d742420 ff30 e8???????? 395c241c 7523 }
- $sequence_5 = { 8be8 49 3bc6 750f baec040000 b90e000780 }
- $sequence_6 = { e8???????? 59 8d75a4 e8???????? 8d7594 }
- $sequence_7 = { 3bcb 7442 395dfc 7414 }
- $sequence_8 = { 3bcb 7504 6a08 eb7a }
- $sequence_9 = { 3919 740a 48 83c102 48 83e801 75f0 }
- $sequence_10 = { 833d????????00 7546 b918000000 e8???????? 48 }
- $sequence_11 = { 0f848a050000 45 33e4 0fb74c2448 83e961 }
- $sequence_12 = { 3bcb 7552 dd45f0 dd4720 }
- $sequence_13 = { 8bce 49 3bfe 741a }
- $sequence_14 = { 59 c20400 8b4608 83f8ff }
- $sequence_15 = { 3bcb 7461 8b01 83f807 }
- $sequence_16 = { 3bcb 753c ff7708 eb28 }
- $sequence_17 = { eb29 48 8d4c2448 e8???????? }
- $sequence_18 = { e9???????? 8d85d0fdffff 50 ff15???????? }
- $sequence_19 = { 894c9a08 8b5df8 03cb 8b5d0c 23c8 }
- $sequence_20 = { ff7508 ffd7 85c0 7516 ff15???????? 6843458a04 }
- $sequence_21 = { 0d00000780 8906 e8???????? 48 8bd6 48 }
- $sequence_22 = { 3bcb 743b 6afe 58 8901 }
+ $sequence_0 = { 8bf0 8975f0 85f6 7422 8d45ec c706???????? }
+ $sequence_1 = { e8???????? 68???????? eb31 51 }
+ $sequence_2 = { 8b45e8 3bc6 7c31 7f04 3bde 762b }
+ $sequence_3 = { 53 50 8d45e0 895dd0 }
+ $sequence_4 = { ff15???????? 8945f4 40 03c7 50 8945f0 }
+ $sequence_5 = { ff15???????? 8bf0 83feff 7437 837b1410 7202 8b1b }
+ $sequence_6 = { 8d45ec c706???????? 50 53 ff75e4 895dec ff15???????? }
+ $sequence_7 = { 57 33db 8bf9 53 6aff 53 }
+ $sequence_8 = { 6a01 52 52 52 52 }
+ $sequence_9 = { 0f85dd000000 57 57 57 57 8d45fc }
condition:
- 7 of them and filesize <663552
+ 7 of them and filesize <1212416
}
-rule MALPEDIA_Win_Milum_Auto : FILE
+rule MALPEDIA_Win_Lowkey_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a4720d6d-5a40-5b38-8cc6-14b0dce6d896"
+ id = "16d4ae5f-e38d-570e-962d-91656915c4ac"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.milum"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.milum_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lowkey"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lowkey_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "3d087e33a30d06df9f4db7e1d4f924bf7ada8b431d51e99d5cf8912956a67294"
+ logic_hash = "663feed0bd96ec1d7d11defff75725aca17e4e2539133645562042d15d3f90de"
score = 75
quality = 75
tags = "FILE"
@@ -151792,32 +158893,32 @@ rule MALPEDIA_Win_Milum_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8db53cffffff e8???????? 83c41c c645fc20 50 8d4d90 e8???????? }
- $sequence_1 = { 837b1800 0f8507010000 8b45f0 50 8d75dc e8???????? 837b1800 }
- $sequence_2 = { 50 e8???????? 8bc6 eb0f 885dfc 8d8d34ffffff }
- $sequence_3 = { 8b4dcc 8b55c8 83c40c c78574ffffff44000000 8945ac 894db4 814da001010000 }
- $sequence_4 = { 8d8d10feffff e8???????? c645fc1e 8d8df4fdffff e8???????? c645fc1d }
- $sequence_5 = { 2bc6 c7421803000000 89421c 395a18 0f849cfeffff ddd8 ddd8 }
- $sequence_6 = { 6bc064 2bc8 8d045590a64600 0fb610 8816 0fb64001 884601 }
- $sequence_7 = { 385f45 7503 895704 8b7a04 897e04 8b7804 3b5704 }
- $sequence_8 = { 8bca eb0e 8b55e8 2bd1 8b4e44 8955d4 894ddc }
- $sequence_9 = { 8d7508 83ec1c 8bcc 8bc6 c741140f000000 895910 896598 }
+ $sequence_0 = { 482be0 488b05???????? 4833c4 48898520200000 33d2 c74590636d642e }
+ $sequence_1 = { 488d3547ed0100 eb16 488b3b 4885ff 740a }
+ $sequence_2 = { 0f85d7feffff e9???????? b966000000 66894c2435 e9???????? 488d15fa230200 488d8d70010000 }
+ $sequence_3 = { b868000000 6689442435 eb49 488d1517250200 488d8d70010000 ff15???????? 85c0 }
+ $sequence_4 = { 4833c4 4889842490040000 8bfa 488bd9 4885c9 }
+ $sequence_5 = { 85c0 0f84bffeffff b865000000 895c2438 4c8d8570090000 6689442435 488d542430 }
+ $sequence_6 = { ff15???????? e9???????? b9d3000000 663bc1 7551 4c3935???????? 7414 }
+ $sequence_7 = { c3 4057 4883ec20 488d3d7b2d0100 48393d???????? 742b }
+ $sequence_8 = { 5e 5b c3 488bcb ff15???????? 4885c0 7504 }
+ $sequence_9 = { eb87 4055 53 57 488dac2470dfffff b890210000 }
condition:
- 7 of them and filesize <1076224
+ 7 of them and filesize <643072
}
-rule MALPEDIA_Win_Webmonitor_Auto : FILE
+rule MALPEDIA_Win_Flawedgrace_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "aca2309c-f3e7-5982-bcd7-9e22f09c3e41"
+ id = "62521b13-13e2-5f89-b92f-7685ad3e5d40"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webmonitor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webmonitor_auto.yar#L1-L158"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flawedgrace"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flawedgrace_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "7913959618328b6198214b581f33ca34a8ffc8b00c2415ca23bf0e5f2e066370"
+ logic_hash = "3a2e50b467b7ecb293ee257669feacddf7970c96ed36da3edcb02bab7c5dbcd0"
score = 75
quality = 75
tags = "FILE"
@@ -151831,38 +158932,32 @@ rule MALPEDIA_Win_Webmonitor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 06 000b 3a58ff 1b03 fd 006cff1e e00e }
- $sequence_1 = { 41 0080cd41009c d34100 e8???????? }
- $sequence_2 = { 0094be4100d891 41 0084e84100a872 42 00a06a4200f8 }
- $sequence_3 = { 0028 fa 41 0014b4 42 }
- $sequence_4 = { b9???????? ffe1 ba???????? b9???????? ffe1 ba???????? b9???????? }
- $sequence_5 = { 000e 6c 74ff f5 }
- $sequence_6 = { ff05???????? 000d???????? 04b8 fe04e4 fd 04e0 fd }
- $sequence_7 = { 00dc 7442 000477 42 0028 }
- $sequence_8 = { 00e8 dd7000 008bf98b5d1c 8d4de4 }
- $sequence_9 = { 00d1 6848007269 48 00856948008b }
- $sequence_10 = { 0108 eb5a 8b4508 83ceff }
- $sequence_11 = { 0108 8b442410 891e 894604 }
- $sequence_12 = { 00d1 6848004069 48 00d1 }
- $sequence_13 = { 000f b681 fc b84500ff24 }
- $sequence_14 = { 00e8 f61c00 008bd9895df0 8b451c }
- $sequence_15 = { 00856948008b ff558b ec 83ec0c }
+ $sequence_0 = { 894110 8b450c 89411c 8a03 884124 8b45f4 c7411800000000 }
+ $sequence_1 = { c1e810 0fb6c0 330c85e0bb4500 0fb6c2 c1ea08 330c85e0b34500 334fb8 }
+ $sequence_2 = { ff15???????? 8bf8 85ff 0f8493000000 8bce e8???????? 8d5704 }
+ $sequence_3 = { 50 8b85c0feffff ff7004 50 e8???????? 8b55e8 }
+ $sequence_4 = { c68564dcffffda c68565dcffff02 c68566dcffff48 c68567dcffff65 c68568dcffff61 c68569dcffff70 c6856adcffff52 }
+ $sequence_5 = { c6857fcfffff48 c68580cfffff83 c68581cfffffec c68582cfffff20 c68583cfffff4c c68584cfffff8b c68585cfffffc8 }
+ $sequence_6 = { 3355f0 33da 8955e8 330c85e0d34500 8bc2 898eb0000000 8bca }
+ $sequence_7 = { c6852ee8ffff65 c6852fe8ffff6c c68530e8ffff6f c68531e8ffff63 c68532e8ffff00 c68533e8ffff00 c68534e8ffff50 }
+ $sequence_8 = { 8975fc e8???????? 50 83c010 50 51 }
+ $sequence_9 = { c68516e5ffff00 c68517e5ffff00 c68518e5ffff00 c68519e5ffff00 c6851ae5ffff00 c6851be5ffff00 c6851ce5ffff00 }
condition:
- 7 of them and filesize <1867776
+ 7 of them and filesize <966656
}
-rule MALPEDIA_Win_Session_Manager_Auto : FILE
+rule MALPEDIA_Win_Logpos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dc2cef80-2dcf-5809-93bd-82c69da769f0"
+ id = "1863375d-233c-50fe-9230-efcb27bcbb2c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.session_manager"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.session_manager_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.logpos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.logpos_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "603fcab78a4336ae9ff58b2ce6e64cc670272e944fe82c789ba11945e145dd5d"
+ logic_hash = "c3acfde126a6fa182645fe56f6caf8ed6c2b8f53215730338bb39d48d6bd3dac"
score = 75
quality = 75
tags = "FILE"
@@ -151876,32 +158971,32 @@ rule MALPEDIA_Win_Session_Manager_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4c89b848240000 4c89b850240000 4c89b858240000 4c89b860240000 4c89b868240000 4c89b870240000 }
- $sequence_1 = { 4c8d35fb2d0100 83e63f 488beb 48c1fd06 48c1e606 498b04ee }
- $sequence_2 = { 4c89b838060000 4c89b840060000 4c89b848060000 4c89b850060000 4c89b858060000 4c89b860060000 4c89b868060000 }
- $sequence_3 = { 4c89b8100b0000 4c89b8180b0000 4c89b8200b0000 4c89b8280b0000 4c89b8300b0000 4c89b8380b0000 }
- $sequence_4 = { 4c89b8c8180000 4c89b8d0180000 4c89b8d8180000 4c89b8e0180000 4c89b8e8180000 4c89b8f0180000 }
- $sequence_5 = { 4c89b890030000 4c89b898030000 4c89b8a0030000 4c89b8a8030000 4c89b8b0030000 4c89b8b8030000 4c89b8c0030000 }
- $sequence_6 = { 4c89b820220000 4c89b828220000 4c89b830220000 4c89b838220000 4c89b840220000 4c89b848220000 4c89b850220000 }
- $sequence_7 = { ff15???????? 488d0df81b0200 ff15???????? 488d0d7b170200 ff15???????? }
- $sequence_8 = { 488d0dd7070000 e8???????? e8???????? 488d0d42070000 e8???????? }
- $sequence_9 = { 4533c9 458d4101 488d542450 488bcb ff90a8000000 }
+ $sequence_0 = { 89e5 0fb64508 83f830 0f8c13000000 83f839 0f8f0a000000 }
+ $sequence_1 = { 89ec 5d c3 55 89e5 83ec20 53 }
+ $sequence_2 = { 884c2408 0fb6442408 83f841 0f8c09000000 83f85a 0f8e37000000 0fb6442408 }
+ $sequence_3 = { 53 e8???????? 894330 682a5a9294 ff33 ff7370 }
+ $sequence_4 = { 8b4d10 8a450c 8b7d08 fc f3aa 61 }
+ $sequence_5 = { ff9380000000 48 83c420 48 85f6 7409 48 }
+ $sequence_6 = { c785f8fbffff01000000 68f4010000 ff15???????? 0fb69507fcffff b90f000000 }
+ $sequence_7 = { 83f800 0f8537000000 833d????????00 0f852a000000 837d1400 0f848c000000 }
+ $sequence_8 = { 5a c9 c3 41 52 }
+ $sequence_9 = { 0f8549000000 8b45fc c680a360400000 8b45fc }
condition:
- 7 of them and filesize <372736
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Locky_Decryptor_Auto : FILE
+rule MALPEDIA_Win_Phobos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7272c171-5952-5404-84f8-64d1272487e9"
+ id = "b3fdfb89-c1ef-5439-9836-c8e32a8398db"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.locky_decryptor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.locky_decryptor_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phobos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.phobos_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "608b3ec7b9a67c8bdfea65d7f94d3ac9056bb8fb93478235380693008ad0bb57"
+ logic_hash = "2c179588b445524a4924d6ad3214734291e040f7e6e3be29f272840c2a179aff"
score = 75
quality = 75
tags = "FILE"
@@ -151915,32 +159010,32 @@ rule MALPEDIA_Win_Locky_Decryptor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d7c2420 c684249000000001 e8???????? 6a01 33ff }
- $sequence_1 = { 56 6a5c 8bf0 e8???????? }
- $sequence_2 = { 58 33db 33c9 8945e0 }
- $sequence_3 = { 8d45e0 50 33ff 6880000000 897dc0 ff15???????? 50 }
- $sequence_4 = { 66890e 56 8d8ddcfbffff e8???????? 8bc6 }
- $sequence_5 = { 50 e8???????? 8364247800 56 50 8d442420 }
- $sequence_6 = { 68???????? 8d8504ffffff e9???????? 015ddc 6a00 5b }
- $sequence_7 = { 56 e8???????? 8b4df4 83c40c 5f 5e 8bc3 }
- $sequence_8 = { 894c2410 3bda 7e6c 33d2 c7442418f0ffffff }
- $sequence_9 = { ff15???????? c745fc0a000000 395de4 740f }
+ $sequence_0 = { ff75fc e8???????? 59 85c0 0f845c010000 395df8 0f8453010000 }
+ $sequence_1 = { 59 8d4c0002 8bc7 2bc6 03c1 894ddc 897dd0 }
+ $sequence_2 = { 8d5c3801 e8???????? 59 8945fc 8975e4 ff15???????? 6a40 }
+ $sequence_3 = { 752e 6683f930 7409 c7450c0a000000 }
+ $sequence_4 = { 53 56 c745a044000000 ff15???????? 8945fc 3bc6 }
+ $sequence_5 = { 8bf8 57 897de0 e8???????? 83c40c 680a020000 8d5c3801 }
+ $sequence_6 = { 8d45f4 50 53 ff15???????? 56 8b35???????? ffd6 }
+ $sequence_7 = { 8bf3 2b7010 e8???????? f6472801 8d440006 59 8945fc }
+ $sequence_8 = { 7423 a900040000 7518 8b06 ff750c 8b00 ff7020 }
+ $sequence_9 = { 83c602 0fb716 83c702 6685d2 75e0 668b06 663b07 }
condition:
- 7 of them and filesize <278528
+ 7 of them and filesize <139264
}
-rule MALPEDIA_Win_Pirpi_Auto : FILE
+rule MALPEDIA_Win_Data_Exfiltrator_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "98537945-bca9-5f78-aa80-688498d88ff3"
+ id = "a4e15d5b-f5a8-5629-8aa0-4b08d538c94b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pirpi"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pirpi_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.data_exfiltrator"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.data_exfiltrator_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "b10391fa85a6d93cb62abde2610054ffc017de9bf6b1bef0a98b13168e41c382"
+ logic_hash = "3310f9551fc82e6e58581f9d53ef710d168d316a9e233b611258320515dc0adb"
score = 75
quality = 75
tags = "FILE"
@@ -151954,32 +159049,32 @@ rule MALPEDIA_Win_Pirpi_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 33ff 8945f4 85c0 897dfc }
- $sequence_1 = { 46 3bf7 72eb c6043b00 5d 8bc7 }
- $sequence_2 = { 50 ff15???????? 83c414 8d8c2434010000 }
- $sequence_3 = { 8bd8 83c408 85db 7515 68???????? 50 }
- $sequence_4 = { 83c404 85ed 7513 53 ff15???????? 5f 5e }
- $sequence_5 = { 56 ff15???????? 56 8be8 ff15???????? 33d2 3bea }
- $sequence_6 = { 33c0 f2ae f7d1 49 83f920 7350 }
- $sequence_7 = { 03d8 f3a4 c6042b00 eb6e }
- $sequence_8 = { 55 c744242018000000 e8???????? 83f87a 753b 55 8b2d???????? }
- $sequence_9 = { 89442414 7516 ff15???????? 894504 c744241000000000 e9???????? }
+ $sequence_0 = { 488b4c2440 ff15???????? 4889442420 488b542448 }
+ $sequence_1 = { e8???????? 4c8b442428 488d152c570000 488b4c2420 e8???????? 41b80a000000 }
+ $sequence_2 = { 488d8c24a0000000 e8???????? 488d9424a0000000 488b8c2430010000 e8???????? 488905???????? }
+ $sequence_3 = { c68424ba00000078 c68424bb00000078 c68424bc00000078 c68424bd00000078 c68424be00000000 488d8c24a0000000 }
+ $sequence_4 = { 48894c2408 4883ec48 48837c246001 752b }
+ $sequence_5 = { c6442420fb c6442421fc c6442422fe c6442423ff c6442424aa c64424254d }
+ $sequence_6 = { c68424020100006d c684240301000000 c684240401000007 c68424050100006d c68424060100004f c684240701000072 }
+ $sequence_7 = { 89442428 837c242800 7c3a 8b442448 39442428 7d30 8b442420 }
+ $sequence_8 = { 7417 488b442450 488b4c2448 4803c8 488bc1 }
+ $sequence_9 = { 48837c242800 7509 488d05d8250000 eb22 488d542420 488b4c2428 ff15???????? }
condition:
- 7 of them and filesize <327680
+ 7 of them and filesize <107520
}
-rule MALPEDIA_Win_Eternal_Petya_Auto : FILE
+rule MALPEDIA_Win_Sepsys_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bf49aeac-2e4f-5384-8db1-b43fb4139322"
+ id = "d155b3c0-24fe-546c-9cf6-d2f1eeec70b2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.eternal_petya"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.eternal_petya_auto.yar#L1-L162"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sepsys"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sepsys_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "715ae6ddfaceb7ac967a454caeda07039960e25d99f3dc3f83571a182c2a56de"
+ logic_hash = "89f35a98ab7f5302d816a97393fda02a0779a3eb472a7bbe6cda60406ec5b6de"
score = 75
quality = 75
tags = "FILE"
@@ -151993,40 +159088,34 @@ rule MALPEDIA_Win_Eternal_Petya_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 55 8bec 51 57 68000000f0 }
- $sequence_1 = { 53 8d4644 50 53 }
- $sequence_2 = { 57 68000000f0 6a18 33ff }
- $sequence_3 = { 53 6a21 8d460c 50 }
- $sequence_4 = { 68f0000000 6a40 ff15???????? 8bd8 }
- $sequence_5 = { 49 75f2 8b4364 034360 8b4b68 894dd4 }
- $sequence_6 = { 8945d0 8bc7 8b7df8 d3e8 8b4de0 03c1 8d3c87 }
- $sequence_7 = { 55 8bec 8b4d0c baff000000 }
- $sequence_8 = { 8d4508 50 53 ff750c 897508 }
- $sequence_9 = { 68???????? e8???????? 85c0 7403 83ce02 }
- $sequence_10 = { 68e8030000 ff15???????? 3bfe 75d3 }
- $sequence_11 = { 55 8bec 8b5508 53 56 57 8b721c }
- $sequence_12 = { 8b07 85c0 75c3 8b75f4 }
- $sequence_13 = { e8???????? 894610 895614 8bc6 5f 5e }
- $sequence_14 = { 898502fcffff 8b85e8fbffff 99 81e2ff010000 }
- $sequence_15 = { 56 51 ffd3 8b15???????? 56 52 8985f0fbffff }
+ $sequence_0 = { eb00 c685b500000000 488b4df8 488b55e8 4c8b45f0 e8???????? 488955e0 }
+ $sequence_1 = { eb13 488b442448 4839442450 7407 b837000000 eb0e 488d4c2460 }
+ $sequence_2 = { e9???????? 0fb74b02 81f9e8030000 7338 41b801000000 6683f90a 723f }
+ $sequence_3 = { c685b604000000 488d8da0000000 e8???????? ebd8 488b4508 488d4d20 48894da8 }
+ $sequence_4 = { e8???????? 41b801000000 488d9424a0000000 488d8c24d8000000 e8???????? 488b442460 488b4008 }
+ $sequence_5 = { e8???????? 4889442430 488b442430 4889442450 488b542450 488b4c2438 e8???????? }
+ $sequence_6 = { 488b842400010000 4889842400020000 8b8c24c8010000 338c24f8010000 8b9424cc010000 339424fc010000 448b8424d0010000 }
+ $sequence_7 = { e8???????? 488945b0 eb00 488b45b0 48898518010000 eb0b 488b45b8 }
+ $sequence_8 = { d3e0 488b4c2430 89411c 4533c0 33d2 33c9 e8???????? }
+ $sequence_9 = { e8???????? 488b4c2430 ff15???????? 33d2 488d8c2460010000 e8???????? 4889442430 }
condition:
- 7 of them and filesize <851968
+ 7 of them and filesize <4538368
}
-rule MALPEDIA_Win_Nullmixer_Auto : FILE
+rule MALPEDIA_Win_Sedreco_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e761e8a0-6032-5175-8c62-373d3cfdbd32"
+ id = "5e87e6b5-1a55-584a-943a-cd1c621a520c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nullmixer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nullmixer_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sedreco"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sedreco_auto.yar#L1-L450"
license_url = "N/A"
- logic_hash = "ff19905731e10511745fb317854603fdd089737424883a407ad871400c764a1f"
+ logic_hash = "480e943eac316911a45e26f995712fa56ee9e542b3cfeab42c526bed2d2dce35"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -152038,34 +159127,76 @@ rule MALPEDIA_Win_Nullmixer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6683fa05 0f8726010000 83e857 83f8ff 0f85d0fcffff 8d7600 }
- $sequence_1 = { c7442404???????? c70424???????? c705????????d09d4a00 e8???????? c705????????01000000 83ec08 89d9 }
- $sequence_2 = { a3???????? 8d8568feffff c7442408???????? c7442404???????? 890424 e8???????? 8d8568feffff }
- $sequence_3 = { 8901 8d44241f 89442408 e8???????? 31d2 c7400800000000 83c00c }
- $sequence_4 = { c784245001000000000000 31c9 e9???????? 8b8c2450010000 e8???????? b8ffffffff 8b94245c010000 }
- $sequence_5 = { 01c9 896c2404 894c2408 890424 e8???????? e9???????? 8b442448 }
- $sequence_6 = { 398424d0000000 0f8430050000 8b06 c744240400000000 89f1 0fb75502 891424 }
- $sequence_7 = { 83f90f 0f4fc8 8b45a8 3975ac 19f8 0f82d0000000 8b55bc }
- $sequence_8 = { 83ec04 837d8010 8d75b4 0f94c2 8b4808 39f9 894d8c }
- $sequence_9 = { 89f1 e8???????? 8b06 89f1 c704242b000000 ff5018 52 }
+ $sequence_0 = { e8???????? 89450c 56 85c0 }
+ $sequence_1 = { c645ff30 e8???????? 85c0 7505 }
+ $sequence_2 = { 8bec 51 836d0804 53 }
+ $sequence_3 = { 836d0804 53 56 8b750c }
+ $sequence_4 = { 8b750c 56 e8???????? 6a08 }
+ $sequence_5 = { 50 68???????? 6a0d 68???????? }
+ $sequence_6 = { 51 6802020000 68???????? 50 }
+ $sequence_7 = { 7411 6a04 68???????? 68???????? }
+ $sequence_8 = { 7ce0 a1???????? 5e 85c0 }
+ $sequence_9 = { ff15???????? 83c604 81fe???????? 7ce0 }
+ $sequence_10 = { ffd6 8b0d???????? 898114010000 85c0 }
+ $sequence_11 = { ffd6 8b0d???????? 898198000000 85c0 }
+ $sequence_12 = { 56 be???????? 8b06 85c0 740f 50 }
+ $sequence_13 = { ffd6 8b0d???????? 894160 85c0 }
+ $sequence_14 = { ffd6 ffd0 a3???????? 5e 85c0 750a a1???????? }
+ $sequence_15 = { 6a01 68???????? ff35???????? ff15???????? ffd0 }
+ $sequence_16 = { 488b05???????? ff90e8000000 90 4883c420 }
+ $sequence_17 = { 68???????? e8???????? 8b35???????? 83c404 6a00 68???????? 6aff }
+ $sequence_18 = { 4889442420 41b906000200 4533c0 488b15???????? 48c7c101000080 488b05???????? ff9038010000 }
+ $sequence_19 = { 6800010000 6a00 68???????? e8???????? 6800020000 }
+ $sequence_20 = { ffd6 50 68???????? 6aff }
+ $sequence_21 = { 488b0d???????? 488b05???????? ff5010 85c0 }
+ $sequence_22 = { 50 68???????? 6aff 68???????? 6a00 6a00 ffd6 }
+ $sequence_23 = { 4883c428 c3 48890d???????? c3 48895c2410 4889742418 55 }
+ $sequence_24 = { 33d2 488d4c2450 488b05???????? ff90d8020000 }
+ $sequence_25 = { 4533c9 4533c0 ba000000c0 488b0d???????? 488b05???????? ff5040 }
+ $sequence_26 = { 448bc0 ba08000000 488b0d???????? ff15???????? 488905???????? }
+ $sequence_27 = { 488b0d???????? 488b05???????? ff5028 48c705????????00000000 }
+ $sequence_28 = { ffd6 8b4dfc 5f 5e 33cd b8???????? }
+ $sequence_29 = { 7cd5 68???????? e8???????? 8b4dfc 83c404 }
+ $sequence_30 = { 53 68???????? ff35???????? ffd6 ffd0 85c0 }
+ $sequence_31 = { e8???????? 8b8c2424020000 5b 33cc 33c0 e8???????? }
+ $sequence_32 = { 52 50 ff91f0000000 8bf0 }
+ $sequence_33 = { a1???????? 33c5 8945fc 6a0a 8d45f4 50 51 }
+ $sequence_34 = { 8d55f8 52 50 8b08 ff5124 }
+ $sequence_35 = { c20c00 6a02 ff74240c ff74240c e8???????? c20800 ff74240c }
+ $sequence_36 = { 57 50 ff512c 8bce }
+ $sequence_37 = { ff512c 8bf0 f7de 1bf6 46 }
+ $sequence_38 = { 8945fc 8b45f0 8945f4 8b45f4 }
+ $sequence_39 = { 50 8b08 ff9180000000 8b06 }
+ $sequence_40 = { ff512c 8bce 8bd8 e8???????? 57 }
+ $sequence_41 = { 57 c785ecfeffff01000000 c785e8feffffe197af54 0f6e85e8feffff 0f72f002 }
+ $sequence_42 = { 83ec24 53 56 57 c745dce197af54 }
+ $sequence_43 = { 8d443001 6a00 51 50 }
+ $sequence_44 = { 8d7901 8d4c2420 57 ff15???????? 84c0 }
+ $sequence_45 = { 6800040000 51 56 8974242c ff15???????? 85c0 0f8484010000 }
+ $sequence_46 = { 51 52 ff15???????? 8b442410 8b4e10 }
+ $sequence_47 = { a1???????? 8b00 8b4c2420 88440c18 }
+ $sequence_48 = { 85db 7548 fec8 53 b9???????? 8842ff }
+ $sequence_49 = { e8???????? 8a54240b 83c404 8b4c2430 895c2410 3bcb }
+ $sequence_50 = { 52 56 50 ff15???????? 6a01 }
+ $sequence_51 = { 8d442428 c684244010000001 8b11 8d4c2418 52 56 }
condition:
- 7 of them and filesize <2351104
+ 7 of them and filesize <1586176
}
-rule MALPEDIA_Win_Artra_Auto : FILE
+rule MALPEDIA_Win_Bachosens_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e3b6f047-fdc2-51fa-b830-434c73cd7acb"
+ id = "512fddd0-592d-56ea-af08-938454f6edb9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.artra"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.artra_auto.yar#L1-L244"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bachosens"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bachosens_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "071975b61ff1770e71eaa8840068c294ba8aa67d37ecde4d3c9fbb80c75c80c8"
+ logic_hash = "b427aef6cac4c70adae9906b44868965e5c9a8d697254ea4be31acc54b01936b"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -152077,47 +159208,32 @@ rule MALPEDIA_Win_Artra_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b442410 5f 5e 83c41c c21000 5f 33c0 }
- $sequence_1 = { 5f 8a08 40 84c9 75f9 2bc2 880c30 }
- $sequence_2 = { 75f9 2bc7 3bc8 72e3 8bc6 }
- $sequence_3 = { 57 33c9 8d7801 8da42400000000 8a10 }
- $sequence_4 = { 800431f3 8bc6 41 8d7801 }
- $sequence_5 = { 72e3 8bc6 8d5001 5f 8a08 }
- $sequence_6 = { 2bc2 03fb 8a4f01 47 }
- $sequence_7 = { 85ff 0f8488000000 6a00 57 ff15???????? }
- $sequence_8 = { 8b2d???????? 90 8b542410 8d4c2410 51 }
- $sequence_9 = { 40 42 84c9 75f6 e8???????? }
- $sequence_10 = { e8???????? 8b3d???????? 6a00 6a00 6a00 8d442414 50 }
- $sequence_11 = { 57 ff15???????? 6a6d 56 ff15???????? 8bf0 }
- $sequence_12 = { 6a00 8935???????? ff15???????? 8bf8 85ff 0f8488000000 }
- $sequence_13 = { 8d442414 50 ffd7 85c0 7445 }
- $sequence_14 = { 8b1d???????? 55 8b2d???????? 90 }
- $sequence_15 = { 8a15???????? 8817 8d842484020000 8bc8 8bff 8a10 }
- $sequence_16 = { e8???????? 8bce c644241800 e8???????? 8b47fc }
- $sequence_17 = { c64424204d c644242161 c644242263 c644242368 c64424256e c644242665 c644242747 }
- $sequence_18 = { 2bcd 8bfe 8d642400 8a1401 fec2 }
- $sequence_19 = { 33c0 0fbe0c30 8d519f 83fa05 }
- $sequence_20 = { be0c000000 8a1401 feca 8810 }
- $sequence_21 = { ffd6 85c0 75cc 5d 5b 8b442410 }
- $sequence_22 = { 83c40c 8b4508 8b7dfc 8be5 5d c3 33c0 }
- $sequence_23 = { e8???????? 6a00 8d44242c 50 6a00 683f000f00 6a00 }
- $sequence_24 = { 51 ffd6 85c0 7444 }
+ $sequence_0 = { 7703 80c1e0 3ad1 7513 49ffc0 }
+ $sequence_1 = { 660f1f840000000000 410fb707 418b3e 6603c1 4803f9 0fb7c0 }
+ $sequence_2 = { 66443908 75f4 443bc1 740a b801000000 }
+ $sequence_3 = { 49f7d9 4c8bc5 660f1f840000000000 420fb61407 410fb608 8d429f 3c19 }
+ $sequence_4 = { 488bc7 ffc1 488d4001 803800 75f5 33d2 }
+ $sequence_5 = { 75f3 418bc9 66390a 7417 }
+ $sequence_6 = { 740e 488bc5 ffc2 488d4001 803800 }
+ $sequence_7 = { 4c03d1 458b7220 418b521c 4c03f1 458b7a24 4803d1 }
+ $sequence_8 = { 0fb70a 418d409f 6683f819 7704 }
+ $sequence_9 = { 75f3 418bc9 66390a 7417 488bc2 0f1f840000000000 ffc1 }
condition:
- 7 of them and filesize <811008
+ 7 of them and filesize <643072
}
-rule MALPEDIA_Win_Rhttpctrl_Auto : FILE
+rule MALPEDIA_Win_Rumish_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "22fa66be-3212-5731-af64-75e4d7422a17"
+ id = "c7d955e8-6589-5477-8769-7cb86586e6f1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rhttpctrl"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rhttpctrl_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rumish"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rumish_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "1c3d2b43c54e91473434d199f4328e6fb482c73192965602da658da1f5036d20"
+ logic_hash = "eaf86e8ce2c9b9b903be9f070aac683527bbc8f25626d1b33901e14e32dd278c"
score = 75
quality = 75
tags = "FILE"
@@ -152131,34 +159247,34 @@ rule MALPEDIA_Win_Rhttpctrl_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83c404 833d????????ff 7533 ff15???????? 68???????? c705????????dcfb4100 }
- $sequence_1 = { e8???????? 8b404c 83b8a800000000 750e 8b04bd30424200 807c302900 741d }
- $sequence_2 = { ffb5dcfbffff c785d8fbffff10fc4100 ff15???????? 33c0 }
- $sequence_3 = { c645d800 68???????? 8d45d8 660fd645e9 }
- $sequence_4 = { 8be5 5d c3 68???????? ff15???????? 833d????????00 b301 }
- $sequence_5 = { 3bf1 756e 8b4bf0 8d73f0 8b01 ff5010 397e0c }
- $sequence_6 = { 8b08 85c9 7407 395004 }
- $sequence_7 = { 50 8d842498000000 50 e8???????? 83cbff 85c0 }
- $sequence_8 = { 50 56 ff15???????? 85c0 7536 8b4714 8b35???????? }
- $sequence_9 = { 57 e8???????? ffb5f8feffff 8d85fcfeffff 50 }
+ $sequence_0 = { 8d450c 50 e8???????? 8b4df8 e8???????? 8b45f8 8be5 }
+ $sequence_1 = { eb46 68???????? 8d8d78feffff e8???????? eb34 68???????? 8d8d78feffff }
+ $sequence_2 = { 7375 8b9570ffffff 0faf5580 039574ffffff 899574feffff 8d8574feffff 50 }
+ $sequence_3 = { 898534ffffff 8b8d34ffffff 3b4d94 7d40 e8???????? 8985a8feffff }
+ $sequence_4 = { 8d8df0faffff e8???????? e9???????? 68???????? 8d8df0faffff e8???????? e9???????? }
+ $sequence_5 = { 0fbf4dbc 898d30ffffff 8b9530ffffff 83ea04 899530ffffff 83bd30ffffff0b 0f87a4020000 }
+ $sequence_6 = { 7d5d e8???????? 898560ffffff db8560ffffff dc0d???????? dc35???????? d9bd5effffff }
+ $sequence_7 = { e8???????? 6a01 8b55f0 52 8b4d9c 83c10c e8???????? }
+ $sequence_8 = { 8bec 83ec08 894df8 51 8bcc 8965fc 8d450c }
+ $sequence_9 = { 83e901 898d80feffff 8d9580feffff 52 8d4d84 e8???????? 8b4580 }
condition:
- 7 of them and filesize <339968
+ 7 of them and filesize <770048
}
-rule MALPEDIA_Win_Flawedammyy_Auto : FILE
+rule MALPEDIA_Win_Montysthree_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3bd73c1c-99e8-572f-ab1b-fa9278709331"
+ id = "5df0d300-da50-5a49-9998-41d773ee6c8b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flawedammyy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flawedammyy_auto.yar#L1-L298"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.montysthree"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.montysthree_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "4dc76e66643bc2a94f8c1ec04c44669739ca4e00a00102a02a05781e927a5ab3"
+ logic_hash = "00fdc41dcd00cadf758a1f9a8aa235f12bbf1e307fd238ef7d6a32ae7dd0988d"
score = 75
- quality = 33
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -152170,54 +159286,32 @@ rule MALPEDIA_Win_Flawedammyy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0000 0404 0404 0404 0401 }
- $sequence_1 = { 8bc4 83ec10 660fd600 f30f7e45ac }
- $sequence_2 = { 00b3854200e5 854200 37 864200 }
- $sequence_3 = { 8d85bcfcffff 68???????? 50 ffd3 68dff0f081 6a01 e8???????? }
- $sequence_4 = { ffd6 8d8594f3ffff 50 68???????? 68???????? }
- $sequence_5 = { 004bbf 42 0062bf 42 }
- $sequence_6 = { 0039 e342 0048e3 42 }
- $sequence_7 = { ff05???????? f7460c0c010000 7554 833cbd7cae410000 53 }
- $sequence_8 = { 8d85bcfdffff 50 ffd3 8b45fc 80384d 0f85a7000000 8078015a }
- $sequence_9 = { e8???????? 53 8d85c0fdffff 50 56 e8???????? }
- $sequence_10 = { 0018 874200 58 874200 }
- $sequence_11 = { 8b35???????? 8d85a0f6ffff 50 8d85a8f8ffff }
- $sequence_12 = { 002a e342 0039 e342 }
- $sequence_13 = { 8bf0 ff5208 85f6 0f8818feffff ff7508 8d4df0 e8???????? }
- $sequence_14 = { 0022 8a4200 828a4200bb8a42 00ff }
- $sequence_15 = { 0062bf 42 0079bf 42 }
- $sequence_16 = { ff15???????? 8b75d8 e9???????? 8d85d0feffff 68???????? 50 ff15???????? }
- $sequence_17 = { 8b46f8 834de4ff 49 c745e8ff000000 8b3c857c303400 c745ecffff0000 0faff9 }
- $sequence_18 = { 4e 48 75f7 68???????? 57 ff15???????? }
- $sequence_19 = { 8bdf 8b06 83661c00 83f807 0f87c9000000 ff248580233400 }
- $sequence_20 = { 8b46f8 8b04855c303400 c1e002 50 6a40 }
- $sequence_21 = { 8b4ef8 83f907 0f8781000000 ff248dfd243400 }
- $sequence_22 = { 7330 ff75f8 ff15???????? 81c600040000 6a42 56 }
- $sequence_23 = { eb0e 8b14957c303400 49 0fafd1 0155fc }
- $sequence_24 = { 83f937 7f2a 8d44c1d0 0fbe0a }
- $sequence_25 = { 33db 83f855 0f872affffff 0fb6805a213400 ff2485f6203400 8b8614080000 }
- $sequence_26 = { 56 8a0a 80f930 7569 }
- $sequence_27 = { 395d08 88987830ca01 0f8484010000 ff75fc 8b35???????? ffd6 f6450802 }
- $sequence_28 = { 50 e8???????? ff75ac 8b3d???????? ffd7 ff75a8 ffd7 }
- $sequence_29 = { ff248580233400 832700 e9???????? 55 e8???????? eb1a }
- $sequence_30 = { 895df0 ffd6 53 ff75dc 6813100000 ff35???????? }
- $sequence_31 = { 0f8781000000 ff248dfd243400 881f eb76 }
+ $sequence_0 = { ff15???????? 8bf0 3bf3 89754c }
+ $sequence_1 = { 8bd4 46 62807013e64e 13e6 d1b660d40c3e }
+ $sequence_2 = { 8d4d70 e8???????? ff30 687b020000 57 68???????? e8???????? }
+ $sequence_3 = { ff75f0 ffd6 8bc7 f7d8 }
+ $sequence_4 = { 50 bf00040000 57 ff15???????? 85c0 8d8574f7ffff 7405 }
+ $sequence_5 = { ff7508 53 ff15???????? 53 8d83080a0000 50 }
+ $sequence_6 = { 8d4d28 e8???????? 50 68???????? e8???????? }
+ $sequence_7 = { 8933 39753c 8b457c 8930 753d 39756c }
+ $sequence_8 = { e8???????? 8d8570fdffff 50 8d4dc4 }
+ $sequence_9 = { ff756c ff15???????? 8d4524 50 8d4d4c e8???????? eb25 }
condition:
- 7 of them and filesize <1350656
+ 7 of them and filesize <458752
}
-rule MALPEDIA_Win_Luca_Stealer_Auto : FILE
+rule MALPEDIA_Win_Dexbia_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8a0c166d-37f3-5a13-bfc2-83fc09a4679d"
+ id = "2a243938-7809-594c-bcba-7fd4f6425c32"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.luca_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.luca_stealer_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dexbia"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dexbia_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "f2eabac635b7bb4e193cfff7279ec9fd429ac964f492c856eb49bfd67aa7534f"
+ logic_hash = "13aa7ee33f2f2a26f0806c6fd2186fbe2a0332c45fef215a0c0786ff94a8b62c"
score = 75
quality = 75
tags = "FILE"
@@ -152231,32 +159325,32 @@ rule MALPEDIA_Win_Luca_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 488bf8 81e7ffffff3f 498b4e60 488b5910 4885db 7452 }
- $sequence_1 = { f645ef02 741d 807df101 7417 b201 488d4de7 e8???????? }
- $sequence_2 = { eb06 4531c0 4889d0 48c7837802000002000000 44888380020000 c6838102000000 48898388020000 }
- $sequence_3 = { e8???????? 498b0f 498b4708 4983670800 4885c0 740f 4883c420 }
- $sequence_4 = { ff15???????? 894530 85c0 0f842b520000 488dbd501f0000 8b0f e8???????? }
- $sequence_5 = { e8???????? 85c0 0f85be000000 488bcb e8???????? 488b8798090000 498bce }
- $sequence_6 = { e8???????? 85c0 740c 488b0b 8a0439 2c3a 3c01 }
- $sequence_7 = { e9???????? 488d3515b8d8ff eb03 4d03fd 410fb607 4484ac30009e4100 75ef }
- $sequence_8 = { e9???????? b009 eb4f 488b842490000000 66c7000109 e9???????? 488db424e0000000 }
- $sequence_9 = { eb86 e8???????? 0f0b 4157 4156 4155 4154 }
+ $sequence_0 = { 8bfd b908000000 be???????? 83c520 83c320 }
+ $sequence_1 = { a3???????? e8???????? 8db6ec894000 bf???????? }
+ $sequence_2 = { ff15???????? 85c0 740c 8b442414 85c0 742a }
+ $sequence_3 = { 5b 81c4e81b0000 c20400 57 ff15???????? b97f000000 33c0 }
+ $sequence_4 = { f3a5 8bcb 8d442410 83e103 50 f3a4 68???????? }
+ $sequence_5 = { 5e 5d 33c0 5b 81c408100000 c3 68???????? }
+ $sequence_6 = { 50 ffd5 a1???????? 85c0 0f841dffffff e8???????? 5f }
+ $sequence_7 = { 80e920 ebe0 80a0a09e400000 40 }
+ $sequence_8 = { 81c408100000 c3 ff15???????? 6a00 ff15???????? 5f 5e }
+ $sequence_9 = { 83c404 8bf0 33c0 89442414 8944241c }
condition:
- 7 of them and filesize <9285632
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Unidentified_031_Auto : FILE
+rule MALPEDIA_Win_Fast_Pos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f9c620fb-a7af-59b3-88ea-9e26f2264efe"
+ id = "2b4b0c9d-f48b-554f-8a11-82dc9864cf63"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_031"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_031_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fast_pos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fast_pos_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "135d93e7e92e738a5df3c00f6ebb76c4de980af7c891f431b4f3045d05f7757e"
+ logic_hash = "cc5eee3320509f0e654a55f4440afe73bd9962689fcfc57ca050257ab2933ad2"
score = 75
quality = 75
tags = "FILE"
@@ -152270,32 +159364,32 @@ rule MALPEDIA_Win_Unidentified_031_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f84a6010000 3bfd 0f849e010000 50 e8???????? 6a00 6a01 }
- $sequence_1 = { 891f 8dbe9c000000 8b07 3bc3 7411 50 53 }
- $sequence_2 = { ffd6 8d4dc8 ffd6 8d4db0 ffd6 8d4d9c ffd6 }
- $sequence_3 = { c78504fdffff08800000 c7853cfeffff15000000 c78534feffff02000000 ff15???????? c785ecfcffff3c624000 c785e4fcffff08800000 c785fcfdffff18000000 }
- $sequence_4 = { e8???????? 8945a0 8d7cbdd0 ff37 50 8bce e8???????? }
- $sequence_5 = { 895508 0f8203ffffff 83c8ff 5f 5e 5b 5d }
- $sequence_6 = { 51 52 e8???????? 8d9564ffffff 8d4dc8 89856cffffff }
- $sequence_7 = { 57 50 e8???????? 3bc3 740e 895e7c 3dc3040000 }
- $sequence_8 = { 8b3f eb03 8b7de0 c7467c01000000 8b4668 ff75e8 57 }
- $sequence_9 = { 68???????? 85c0 0f9fc3 f7db ff15???????? 0fbfc0 8b55cc }
+ $sequence_0 = { c785e4feffff04010000 ff15???????? e8???????? 8bc8 33c0 }
+ $sequence_1 = { e8???????? 8b95e4feffff 83c408 85c0 0f9485ebfeffff 83c2f0 }
+ $sequence_2 = { 52 8d8de0feffff e8???????? 8bb5e0feffff 6a44 8d857cfeffff }
+ $sequence_3 = { 6a00 6a00 68???????? ffb5e8feffff ff15???????? 85c0 7517 }
+ $sequence_4 = { c645fc07 e8???????? 8bf0 c645fc08 ff15???????? }
+ $sequence_5 = { 68???????? 56 c785e8feffff01000000 e8???????? 83c40c 8bc6 }
+ $sequence_6 = { 68ffff1f00 ff15???????? 6a00 50 }
+ $sequence_7 = { e8???????? 6a10 68???????? 68???????? 6a00 ff15???????? 6a00 }
+ $sequence_8 = { 50 ff36 8d85e0feffff 68???????? }
+ $sequence_9 = { 5d c20400 8b01 6a01 ff76f4 ff10 8bf8 }
condition:
- 7 of them and filesize <1998848
+ 7 of them and filesize <327680
}
-rule MALPEDIA_Win_Laziok_Auto : FILE
+rule MALPEDIA_Win_Pseudo_Manuscrypt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1dcbce9e-9b01-55fc-82f2-025bf107fa98"
+ id = "31787da1-ee36-51da-9ab0-837844c74a17"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.laziok"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.laziok_auto.yar#L1-L101"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pseudo_manuscrypt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pseudo_manuscrypt_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "8a49fb3e99a85f8254a739f5aaca9e9bb1b5be0f2dd72574e619043b4fccb1ed"
+ logic_hash = "f95219f8df4fada7a5809becd0c4a0a18721619c73177d4ad9f3ddc17aca2388"
score = 75
quality = 75
tags = "FILE"
@@ -152309,30 +159403,32 @@ rule MALPEDIA_Win_Laziok_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85f6 740b 837c240cff 8937 7502 }
- $sequence_1 = { 47 68???????? 57 e8???????? 8bf0 59 }
- $sequence_2 = { 8d85f4fdffff 50 e8???????? 33c0 668945fc }
- $sequence_3 = { 68ffffff1f 52 e8???????? 83c410 c3 }
- $sequence_4 = { e8???????? 83c420 5b c20400 }
- $sequence_5 = { 56 8b7508 833e01 7513 6a00 ff7510 ff750c }
- $sequence_6 = { 39742410 741b ff742410 ff15???????? 8bf0 }
- $sequence_7 = { 56 57 ff74240c 33f6 ff35???????? e8???????? }
+ $sequence_0 = { 0f8473ffffff 8bd6 8bcf e8???????? 85c0 0f8f62ffffff 53 }
+ $sequence_1 = { 668906 e8???????? 8b45fc 83c404 8bfb 3b18 75bd }
+ $sequence_2 = { 33db 8d857cfdffff 53 50 53 683f010f00 53 }
+ $sequence_3 = { 6a00 6a00 6a00 6a18 ffd6 6a00 6a00 }
+ $sequence_4 = { 8bec 56 8bb17c010000 85f6 742a 8b4508 33d2 }
+ $sequence_5 = { 6a04 68ffff0000 53 ffd6 0bc7 5f 5e }
+ $sequence_6 = { 57 8945fc 8d140b 8bc8 0f44d3 52 e8???????? }
+ $sequence_7 = { 7554 5f 33c0 5e 8b4dfc 33cd e8???????? }
+ $sequence_8 = { 89442474 8d842480000000 6804010000 50 c744246c01010000 ff15???????? 68???????? }
+ $sequence_9 = { 8d85d0fdffff 50 56 ff15???????? 85c0 742c 53 }
condition:
- 7 of them and filesize <688128
+ 7 of them and filesize <753664
}
-rule MALPEDIA_Win_Squirrelwaffle_Auto : FILE
+rule MALPEDIA_Win_Screencap_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "67d18a0f-cebe-56e6-8b79-40dff03f1fb3"
+ id = "104aba67-45fe-5a81-add7-5f096073514f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.squirrelwaffle"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.squirrelwaffle_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.screencap"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.screencap_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "2fb7fd7c7f2885b81fdacc79e3b0b0578babd5d7d5854f31f47508825bacd6eb"
+ logic_hash = "d12bc6cdd7eeaf3c014435658ac08460e21def542afb74f89d01054fc70f3f9a"
score = 75
quality = 75
tags = "FILE"
@@ -152346,32 +159442,32 @@ rule MALPEDIA_Win_Squirrelwaffle_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd6 85c0 0f85d9000000 8b458c }
- $sequence_1 = { 0f431d???????? 8a00 85c9 7416 51 }
- $sequence_2 = { 83c40c 8b36 ba???????? 85f6 0f853cffffff 8b7d88 }
- $sequence_3 = { 85c0 0f8453020000 8b4a14 48 8945f0 8bc2 }
- $sequence_4 = { 8b7310 2bc6 8975f8 57 3bc2 0f8214010000 8d0416 }
- $sequence_5 = { b803000000 0f438d10fefeff ba???????? 83fe03 }
- $sequence_6 = { 0f1185f8fdfeff f30f7e4710 660fd68508fefeff c7471000000000 c747140f000000 }
- $sequence_7 = { 8db5f8fbffff 8d34c6 837e1410 8bc6 7202 }
- $sequence_8 = { 897714 eb26 8b0d???????? 0f57c0 }
- $sequence_9 = { c645cc00 8d4dd8 ff75cc 6a08 }
+ $sequence_0 = { 488b4c2450 488364242000 488d0591e90000 488b0cc8 4c8d4c2458 488d542460 498b0c0f }
+ $sequence_1 = { 41c1eb05 418d5f01 41c1e302 83fe08 }
+ $sequence_2 = { 4883ec20 4c8d25a09c0000 33f6 33db 498bfc 837f0801 7526 }
+ $sequence_3 = { 39842420100000 0f869f010000 6a04 687c334700 55 e8???????? }
+ $sequence_4 = { 488bce ff15???????? bf00080000 3bdf 7702 }
+ $sequence_5 = { 72ed 48833d????????00 741f 488d0d06130100 e8???????? }
+ $sequence_6 = { 8bdf e8???????? 85ff 741c 488d4c2450 0fb601 84c0 }
+ $sequence_7 = { 3bf8 0f869c000000 6a04 687c334700 55 e8???????? }
+ $sequence_8 = { 8d854c100000 50 ff15???????? 8bf0 8975e0 85f6 0f84bb030000 }
+ $sequence_9 = { 89470c 894710 894714 8d854c2c0000 50 e8???????? 6805040000 }
condition:
- 7 of them and filesize <147456
+ 7 of them and filesize <1391616
}
-rule MALPEDIA_Win_Wannacryptor_Auto : FILE
+rule MALPEDIA_Win_Thanatos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e56d2000-fe42-59bd-8926-478b3a54b7b3"
+ id = "3d56c6ff-7a5f-5548-8f3b-06d8d6158f7b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wannacryptor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wannacryptor_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thanatos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.thanatos_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "c696b2074a3cd60e9575143d9577c550babed6e9c2f46c424c5b90d1a1647723"
+ logic_hash = "2cc3d4fef37b3d57358c4e21f8e34a4b374cac5e972e715588051a429530df72"
score = 75
quality = 75
tags = "FILE"
@@ -152385,32 +159481,32 @@ rule MALPEDIA_Win_Wannacryptor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 56 8bf1 57 8b7c241c 8b4670 }
- $sequence_1 = { 8854243c 8b44243c 50 51 8bce }
- $sequence_2 = { b801000000 33ff 85c0 7e76 8bd8 8b5500 03cf }
- $sequence_3 = { 8bce e8???????? 8a4649 84c0 7419 8b4620 }
- $sequence_4 = { ff15???????? 50 e8???????? 85c0 742e 8b4004 8d542404 }
- $sequence_5 = { 8b4674 c6464801 85c0 7509 6a00 }
- $sequence_6 = { 50 ff15???????? 50 e8???????? 8b4820 6a00 6a00 }
- $sequence_7 = { 8b4678 8d7e44 85c0 755f 8b17 }
- $sequence_8 = { e8???????? 8d4648 8d4c2410 50 c744243000000000 }
- $sequence_9 = { 57 8b7c241c 8b4670 85c0 7503 }
+ $sequence_0 = { 85f6 0f849b010000 ff742428 6a00 68ffff1f00 ff15???????? 8bf8 }
+ $sequence_1 = { 50 8bda 8bf1 c78560ffffff94000000 e8???????? 83c40c 8d8560ffffff }
+ $sequence_2 = { c64435bc46 8d45bc 50 46 ffd7 3bf0 7ce9 }
+ $sequence_3 = { 6a00 6a00 68000000c0 68???????? 46 ffd3 8bf8 }
+ $sequence_4 = { 83c40c 807d0800 7459 8b4c240c 897c2422 8d4306 8944241e }
+ $sequence_5 = { 807d0800 89442414 b80a000000 7524 3bdf }
+ $sequence_6 = { 84c0 75f9 2bd7 5f 7409 51 ff15???????? }
+ $sequence_7 = { 57 8bf9 8b4e28 8955fc 83f803 0f85e5020000 8b5d08 }
+ $sequence_8 = { 893d???????? c705????????ecb40110 f30f7e05???????? 660fd64008 }
+ $sequence_9 = { 50 6a02 ff15???????? 8b7514 c705????????c0b30110 85f6 0f8486010000 }
condition:
- 7 of them and filesize <540672
+ 7 of them and filesize <1810432
}
-rule MALPEDIA_Win_Farseer_Auto : FILE
+rule MALPEDIA_Win_Whiteblackcrypt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bdb1b674-d96e-50d4-8dbe-83cb253d9330"
+ id = "6157b109-2151-5074-8840-c27487c07a25"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.farseer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.farseer_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.whiteblackcrypt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.whiteblackcrypt_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "17f8792326231b41b2e91221ee87a535fdccf3e2e964ba78d0722fea338c91a0"
+ logic_hash = "f60c96c165ea27ee68f018ece2d6f92a309aa90e387cd2c1a16407c43ba45f47"
score = 75
quality = 75
tags = "FILE"
@@ -152424,32 +159520,32 @@ rule MALPEDIA_Win_Farseer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4c2434 e8???????? eb10 6a06 68???????? 8d4c2438 }
- $sequence_1 = { 50 8d4c2440 51 8d542478 }
- $sequence_2 = { e8???????? 8d742414 e8???????? 53 50 83c8ff 8d742438 }
- $sequence_3 = { 8d442434 50 e8???????? c68424c402000002 8b8424cc000000 bb10000000 399c24e0000000 }
- $sequence_4 = { 0f8c6cffffff 33ed 8d9424ac010000 68???????? 52 e8???????? 83c408 }
- $sequence_5 = { 33db 6aff 899c2498000000 53 8d8424a4000000 be0f000000 50 }
- $sequence_6 = { 7510 8bc1 eb0c 0fb6c9 0fbe8940454200 03c1 40 }
- $sequence_7 = { 83c404 83bc24e402000010 7210 8b9424d0020000 52 e8???????? 83c404 }
- $sequence_8 = { 85410c 7405 e8???????? 8d742440 e8???????? 85c0 }
- $sequence_9 = { e9???????? 8bc3 c1f805 8d048520634200 83e31f 8985e4efffff 8b00 }
+ $sequence_0 = { 790d b910270000 ff15???????? ebea e8???????? b805000030 31c9 }
+ $sequence_1 = { 75ed 0f118fb0000000 4883c310 ebc4 4883c420 5b 5e }
+ $sequence_2 = { 4883ec38 83fa02 744c 7707 83fa01 745a eb4d }
+ $sequence_3 = { 75a2 5b 5e c3 4c8d4a10 48c1e104 }
+ $sequence_4 = { 488d0d583d0000 c705????????01000000 e8???????? 4885c0 7414 b801000000 }
+ $sequence_5 = { 4889c6 4889c7 4489f0 f3aa 4889f1 e8???????? }
+ $sequence_6 = { 4881ecb0030000 4c8d0504420000 31c0 41b9ffff0000 }
+ $sequence_7 = { 8801 48ffc1 ebe8 c3 55 }
+ $sequence_8 = { 7412 8d509f 80fa19 7703 }
+ $sequence_9 = { f20f2ad2 48895c2420 dd442420 f20f11542428 dd442428 d9c9 d9fd }
condition:
- 7 of them and filesize <347328
+ 7 of them and filesize <99328
}
-rule MALPEDIA_Win_Deathransom_Auto : FILE
+rule MALPEDIA_Win_Torrentlocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4e39de37-0fee-5b21-a4db-fc348269215e"
+ id = "56bf47db-a6d1-5792-b5b6-3656138ac949"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.deathransom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.deathransom_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.torrentlocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.torrentlocker_auto.yar#L1-L170"
license_url = "N/A"
- logic_hash = "8362ae87c1f20555b6e75c6240bf76604d10b1d1a7af4c90e341b81be4a45543"
+ logic_hash = "9124185b3dba8eb6288bd309dcd17a816c52adb0e1e08ff17bcd23b3d53099e4"
score = 75
quality = 75
tags = "FILE"
@@ -152463,32 +159559,38 @@ rule MALPEDIA_Win_Deathransom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b55d8 33c3 03c1 81c216c1a419 03d0 8bcf 0155ec }
- $sequence_1 = { 03d1 c1c007 0355a8 8bcf c1c90b 33c8 8955d8 }
- $sequence_2 = { 742d 8b45f8 ba20000000 2bd6 8bca d3e8 8bce }
- $sequence_3 = { 0f8278010000 8b5df4 8d4dd8 56 8bd3 837b0400 }
- $sequence_4 = { c3 83f802 7546 6820020000 6a08 c745fc20020000 ff15???????? }
- $sequence_5 = { 8d8d90fdffff e8???????? 8d8d90fdffff e8???????? 8d8d90fdffff e8???????? 6a50 }
- $sequence_6 = { 0b7de4 237ddc 8b55f4 0bf8 897de0 8bc6 014de0 }
- $sequence_7 = { 8b45dc 8bc8 0155e8 c1c00a }
- $sequence_8 = { 85c9 0f95c0 2bc8 33c0 c1e905 }
- $sequence_9 = { c1e810 884311 8bc1 c1e808 884312 884b13 8b4f1c }
+ $sequence_0 = { c3 83f801 7405 83f802 }
+ $sequence_1 = { 8b0d???????? 5f c7000c000000 894804 }
+ $sequence_2 = { 85c0 7514 e8???????? 3d00000600 }
+ $sequence_3 = { 50 56 6a00 6a01 6a02 ff15???????? }
+ $sequence_4 = { 8b0d???????? 890e e8???????? 8bd8 e8???????? 6a00 6a01 }
+ $sequence_5 = { 83ec24 6a00 6a01 68???????? ff15???????? 85c0 7551 }
+ $sequence_6 = { 56 ff15???????? 83f802 740f 83f803 740a }
+ $sequence_7 = { e8???????? 3d00000600 1bc0 40 a3???????? eb05 }
+ $sequence_8 = { 83c002 6685c9 75f5 2bc2 d1f8 8d440014 }
+ $sequence_9 = { 52 50 ff15???????? 85c0 7519 8b0d???????? 51 }
+ $sequence_10 = { 51 6a01 6a00 0d00800000 50 6a00 }
+ $sequence_11 = { 8b0d???????? 5f 894e0c 5e }
+ $sequence_12 = { 8b0d???????? 6a00 6a00 57 }
+ $sequence_13 = { 48 85c0 7ff4 5f 33c0 5e c3 }
+ $sequence_14 = { 8b0d???????? 57 6a00 51 ff15???????? 8bc6 }
+ $sequence_15 = { c705????????00000000 e8???????? 8bf0 e8???????? }
condition:
- 7 of them and filesize <133120
+ 7 of them and filesize <933888
}
-rule MALPEDIA_Win_Gearshift_Auto : FILE
+rule MALPEDIA_Win_Flashflood_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "02540c00-8de2-5ac5-936a-14a6336e7666"
+ id = "2b564813-7b00-54ab-b562-7a8de5369185"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gearshift"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gearshift_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flashflood"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flashflood_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "1c8a80ba14390df1b7bcd5e4b955652a287b76aebf22d78fc43b89631a984860"
+ logic_hash = "3006626d1ecba778668c15e0aafe5a9ff5cdfe4debbbd864318346fc290d9ab7"
score = 75
quality = 75
tags = "FILE"
@@ -152502,32 +159604,32 @@ rule MALPEDIA_Win_Gearshift_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4881c4c0000000 5f c3 85c0 0f85a9000000 }
- $sequence_1 = { 4d8bde 4d2b5d30 0f84a1000000 488b4500 488b5d08 }
- $sequence_2 = { 4883ec28 48833d????????00 740a b801000000 4883c428 c3 488d0dc9a80000 }
- $sequence_3 = { 4823f1 66413b7806 0f83ce000000 48895c2448 4c89642450 4c8d25566a0300 4a8d5c003c }
- $sequence_4 = { 83c8ff e9???????? 4c8bfb 4c8be3 488d05363c0300 49c1fc05 }
- $sequence_5 = { 4885c0 0f8418010000 4c8d442470 41b910010000 488bd0 488bcb 48897c2420 }
- $sequence_6 = { 488bd8 ff9688000000 4c8bc3 33d2 488bc8 8947f8 ff96a8000000 }
- $sequence_7 = { 7522 48ffc1 498d0408 493bc3 7cec 4963c2 4803c6 }
- $sequence_8 = { 4533c0 33d2 498bcc 44896c2428 48897c2420 ff15???????? ba01000000 }
- $sequence_9 = { 0fb7d1 eb09 488b4508 488d540102 }
+ $sequence_0 = { ff15???????? 8145f800809b07 8d45f8 50 }
+ $sequence_1 = { 56 e8???????? 40 8945f8 0fbe06 50 }
+ $sequence_2 = { c3 b8???????? c3 55 8bec 81ec88020000 }
+ $sequence_3 = { 8bec 81ec10060000 56 6a5c ff750c ff15???????? 8bf0 }
+ $sequence_4 = { 6bc90c 8b91f0914000 8955f4 8b450c 6bc00c }
+ $sequence_5 = { ff5164 85c0 0f85c5010000 8d55f4 8b45ec 52 }
+ $sequence_6 = { 33c0 eb0a 57 ff15???????? 6a01 58 5f }
+ $sequence_7 = { 85f6 59 0f842b020000 ff7508 8d85f0fbffff 50 e8???????? }
+ $sequence_8 = { 50 e8???????? 8d85c0fdffff 50 8d85c0fbffff ff7508 }
+ $sequence_9 = { 83c62c 6a2e 56 ff15???????? 8b3d???????? 59 }
condition:
- 7 of them and filesize <540672
+ 7 of them and filesize <114688
}
-rule MALPEDIA_Win_Seasalt_Auto : FILE
+rule MALPEDIA_Win_Radrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e41fdf89-eed2-569c-87d1-66ae3f31eb44"
+ id = "f52e2c5a-eef0-5772-ac88-55315ac8b12c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.seasalt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.seasalt_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.radrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.radrat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "c4e00a9b356da4bb38f74ae93a3974f0cb2a6403defdfa59feac8c8b4bbe886d"
+ logic_hash = "a27dfe470245e6a0fc8e1e694300b8057fe423adc6b34415045732f4d66a4882"
score = 75
quality = 75
tags = "FILE"
@@ -152541,32 +159643,32 @@ rule MALPEDIA_Win_Seasalt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 888800d90010 eb1f 83f861 7213 }
- $sequence_1 = { a3???????? 3bc6 7513 68e0930400 ff15???????? 8975fc }
- $sequence_2 = { 83d8ff 3bc3 758c b901040000 33c0 }
- $sequence_3 = { f2ae a1???????? 68???????? f7d1 }
- $sequence_4 = { 8b8c2454010000 6a00 8d442428 6800010000 50 }
- $sequence_5 = { 6aff 50 ff15???????? 85c0 6a00 }
- $sequence_6 = { 8bf7 c1e902 8bfa 8d942488010000 f3a5 }
- $sequence_7 = { 7ced 55 8bac2418020000 6a00 8d442414 6804020000 50 }
- $sequence_8 = { 8dbc2419020000 c684241802000000 f3ab 66ab 6a00 }
- $sequence_9 = { c1e902 83e203 83f908 7229 f3a5 ff2495c8350010 8bc7 }
+ $sequence_0 = { 8d8d1cffffff e8???????? c685f0feffff00 c645fc00 8d4dcc e8???????? c745fcffffffff }
+ $sequence_1 = { c6855497ffff01 c645fc01 8d8d58ffffff e8???????? c745fcffffffff 8d4d80 e8???????? }
+ $sequence_2 = { 8d8d74ffffff e8???????? 68a0000000 8d8d74ffffff e8???????? 6a30 8d8d74ffffff }
+ $sequence_3 = { ff15???????? 8b4df4 894168 8b45f4 837868ff 750d ff15???????? }
+ $sequence_4 = { 8d8dd8feffff e8???????? 8d8d0cffffff 51 8d55c4 52 8b45ec }
+ $sequence_5 = { e8???????? 8a854c98ffff e9???????? 8b8d24d6ffff 83c15c 51 8b9524d6ffff }
+ $sequence_6 = { 8d8d50ffffff 51 e8???????? 83c408 8b9548ffffff 83c258 52 }
+ $sequence_7 = { e9???????? 8d4d9c e8???????? c645fc01 8d8d38ffffff 51 8d4d9c }
+ $sequence_8 = { 8b4dd8 8b9130010000 52 ff15???????? 8b45d8 c7803001000000000000 8b4dd8 }
+ $sequence_9 = { 8d8560fbffff 50 8d8da8fdffff e8???????? 89854cf8ffff 8b8d4cf8ffff 898d48f8ffff }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <2080768
}
-rule MALPEDIA_Win_Hawkball_Auto : FILE
+rule MALPEDIA_Win_Unidentified_105_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e8db5e2d-29c9-5590-a712-0f60cd9571dc"
+ id = "80a8f5ec-0d23-5074-b907-8dcd99006ffb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hawkball"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hawkball_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_105"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_105_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "781a6bce01e178f537c586fc2b1e607c4503cf63fe51435a8db976da2766e5fa"
+ logic_hash = "03b63f792ccab1aa0e70284622fef7dcf74ab6cde5a0b9206fdbab8d689a2bd1"
score = 75
quality = 75
tags = "FILE"
@@ -152580,32 +159682,32 @@ rule MALPEDIA_Win_Hawkball_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83780c00 7506 33c0 8be5 }
- $sequence_1 = { 53 e8???????? 037dfc 83c40c 81ffffff0300 }
- $sequence_2 = { 0f84c6000000 6a04 8d442418 c744241860ea0000 50 6a06 57 }
- $sequence_3 = { 53 ff15???????? ff742414 8b35???????? ffd6 53 }
- $sequence_4 = { 85c9 746d 837dfc28 7d13 6b55fc05 69c2e8030000 }
- $sequence_5 = { 50 ff15???????? 897001 c600ff c7400500000000 }
- $sequence_6 = { b9???????? e8???????? a3???????? 833d????????00 740b 8b0d???????? }
- $sequence_7 = { 837dfc28 7d13 6b55fc05 69c2e8030000 50 }
- $sequence_8 = { 7405 8d4a10 eb47 b911000000 }
- $sequence_9 = { 8be5 5d c3 6a59 ff15???????? 85c0 }
+ $sequence_0 = { 85c0 0f95c0 84c0 742c }
+ $sequence_1 = { 8bf8 8d4f02 b856555555 f7e9 8bc2 c1e81f 03c2 }
+ $sequence_2 = { 6a00 8d8dd0feffff 51 8d95fcfeffff }
+ $sequence_3 = { 8d8d94feffff 51 6800000010 50 52 ff15???????? 85c0 }
+ $sequence_4 = { e8???????? 83c404 50 e8???????? a1???????? 6800020000 }
+ $sequence_5 = { 83f8ff 7459 8d9424a0010000 52 }
+ $sequence_6 = { 68???????? 56 e8???????? 8bc6 83c454 }
+ $sequence_7 = { 8bf8 8d4f02 b856555555 f7e9 8bc2 }
+ $sequence_8 = { 8b3d???????? 8d45e4 50 33f6 }
+ $sequence_9 = { 6800100000 8d85f8efffff 50 51 }
condition:
- 7 of them and filesize <229376
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Rarstar_Auto : FILE
+rule MALPEDIA_Win_Killav_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1b0cea37-0a1d-5e66-91fc-944e4e50541c"
+ id = "1d5124ec-5245-51ca-8b54-4fbeb7c8a843"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rarstar"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rarstar_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.killav"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.killav_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "2e522865d24e8dea587d8aa292c78791c9371361cc03d604920c80f6d8c9bb83"
+ logic_hash = "6bdcae63c9d790007a185fb309199c790674ed97c7a86b96314a377ad757753a"
score = 75
quality = 75
tags = "FILE"
@@ -152619,32 +159721,32 @@ rule MALPEDIA_Win_Rarstar_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8a5e01 83e203 c1fb04 c1e204 }
- $sequence_1 = { 33d2 b903000000 f7f1 83c408 8bc6 }
- $sequence_2 = { 85ed 7e6f 8a143e 83c703 c1fa02 83e23f 41 }
- $sequence_3 = { 0f84c1010000 8b2d???????? 8b4c2434 8b54241c 6a00 }
- $sequence_4 = { 33db 8a940c24010000 8a5c0c24 03c2 03c3 25ff000080 }
- $sequence_5 = { ffd6 8d84241c020000 68???????? 50 ffd6 8d8c2424040000 68???????? }
- $sequence_6 = { 8d8c2420030000 51 52 ffd5 8d842418010000 68???????? }
- $sequence_7 = { 899c242c030000 899c2428030000 899c2424030000 899c2420030000 bf???????? 83c9ff }
- $sequence_8 = { f7d1 2bf9 899c2430030000 8bc1 8bf7 8bfa }
- $sequence_9 = { 8a9405ecfdffff 8890a0d74000 eb1c f6c202 7410 8088????????20 8a9405ecfcffff }
+ $sequence_0 = { c745e4e8e24200 e9???????? 894de0 c745e4e8e24200 e9???????? }
+ $sequence_1 = { 8955e0 8b048d70ba4300 f644102801 747c }
+ $sequence_2 = { 6a20 c745e000000000 e8???????? 8bf0 83c404 8975e0 }
+ $sequence_3 = { 8b45f8 8b55f0 8b048570ba4300 807c022800 }
+ $sequence_4 = { e8???????? 8b35???????? 6a00 6880000000 6a03 6a00 6a00 }
+ $sequence_5 = { c645fc1c 50 8d4dd0 e8???????? c645fc00 8b55ec 83fa08 }
+ $sequence_6 = { 8b049570ba4300 885c012e 8b049570ba4300 804c012d04 }
+ $sequence_7 = { 8d45d8 c645fc37 50 8d4dd0 }
+ $sequence_8 = { 6bf838 894df8 8b048d70ba4300 33c9 }
+ $sequence_9 = { e8???????? 8d45d8 c645fc08 50 8d4dd0 }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <517120
}
-rule MALPEDIA_Win_Pipemon_Auto : FILE
+rule MALPEDIA_Win_Chaperone_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fb1257dc-1899-57a8-9bb3-37873100ec17"
+ id = "5069c84b-f6f9-588d-8536-63d238bdb1de"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pipemon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pipemon_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chaperone"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chaperone_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "a7cf49399560b8b73200f34644a487f3922c8589009d7d641339ef3a3238ec7b"
+ logic_hash = "9d40dc4ee44ea2fe4f6bf05be1cccf6d78aa19e4569d2284fce73479ea6dfe7a"
score = 75
quality = 75
tags = "FILE"
@@ -152658,32 +159760,32 @@ rule MALPEDIA_Win_Pipemon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 418bf8 4903fe 85db 0f84a1000000 6690 49634e3c }
- $sequence_1 = { 7516 488d05bd360100 488b4c2430 483bc8 7405 e8???????? 488b05???????? }
- $sequence_2 = { 85c0 7427 488b4c2438 488d1526d90000 ff15???????? }
- $sequence_3 = { b906000000 48898620020000 0fb7c0 66f3ab 488d3d2c3b0100 }
- $sequence_4 = { 488d4c2438 e8???????? 4c8d4820 4889442420 4c8bc3 488d5590 488d4c2438 }
- $sequence_5 = { 4881c458010000 c3 83f801 7529 b803000000 488b8c2440010000 4833cc }
- $sequence_6 = { 458d4d02 458bc7 488d542450 488bc8 }
- $sequence_7 = { e8???????? 4881c498000000 c3 448b442430 488d1543fe0100 33c0 488d4c2440 }
- $sequence_8 = { ffc8 3d03010000 7734 488d44244c 488bd7 }
- $sequence_9 = { 80bd8008000000 0f84b6010000 4d85ed 0f84b6000000 }
+ $sequence_0 = { f3a4 488dbc2458010000 488d35d6490100 b918000000 f3a4 48c784245001000000000000 83bc249002000000 }
+ $sequence_1 = { 85c9 782e 3b0d???????? 7326 4863c9 488d15f8ca0100 488bc1 }
+ $sequence_2 = { eb05 1bc0 83d8ff 85c0 0f8475010000 488d15aeaf0100 488d8c24ec040000 }
+ $sequence_3 = { 488d9424a8020000 488b4c2430 ff15???????? 81bc24a802000003010000 0f8486000000 }
+ $sequence_4 = { 751f 83bc24d001000002 7515 83bc24c801000001 720b c78424a801000005000000 83bc24c401000006 }
+ $sequence_5 = { 488d94088c020000 488b8c2438490000 e8???????? 89842444490000 83bc244449000000 }
+ $sequence_6 = { ff15???????? 488905???????? 48833d????????00 750b c78424c801000002000000 488d9424a0020000 488b8c2480030000 }
+ $sequence_7 = { 0fb702 66898424d0000000 488d9424f0020000 488d8c24d0000000 ff15???????? 488d8c24d0000000 ff15???????? }
+ $sequence_8 = { ff15???????? 66ba5c00 488d4c2440 e8???????? 4889842450020000 488b842450020000 4883c002 }
+ $sequence_9 = { 49c1fe05 4c8d3d40cc0100 83e61f 486bf658 4b8b04f7 0fbe4c3008 83e101 }
condition:
- 7 of them and filesize <389120
+ 7 of them and filesize <373760
}
-rule MALPEDIA_Win_Leouncia_Auto : FILE
+rule MALPEDIA_Win_Grey_Energy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "39b73bd1-c371-5610-827d-6193acb69151"
+ id = "4a36cbdc-dd01-583b-ac49-dd33a3c83ba9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.leouncia"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.leouncia_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grey_energy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grey_energy_auto.yar#L1-L164"
license_url = "N/A"
- logic_hash = "ce0406952808d71dc84c670f24e39c297086db41d40b8ca03d26d62e66180e61"
+ logic_hash = "48bebd474d43043ec7179ca6aa1110529eaa285ee6fd70578731385cb5b6f92e"
score = 75
quality = 75
tags = "FILE"
@@ -152697,32 +159799,39 @@ rule MALPEDIA_Win_Leouncia_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f3ab 8d442408 50 56 }
- $sequence_1 = { 52 50 a1???????? 8d8c248c050000 }
- $sequence_2 = { 83c208 8908 8b4e04 894804 8a0d???????? }
- $sequence_3 = { ff15???????? 5f b801000000 5e 81c438040000 c3 83c9ff }
- $sequence_4 = { c3 55 56 57 8d542410 6a10 }
- $sequence_5 = { 83c424 33d2 33ff 85c0 7e31 }
- $sequence_6 = { c3 8bc8 83e01f c1f905 8b0c8d60c14000 }
- $sequence_7 = { ff2485ba504000 834df0ff 8955cc 8955d8 8955e0 8955e4 8955fc }
- $sequence_8 = { c744241c00000000 c744241400040000 c7450000000000 e8???????? 83c404 8bf0 8d442410 }
- $sequence_9 = { ff2485ba504000 834df0ff 8955cc 8955d8 8955e0 8955e4 }
+ $sequence_0 = { 6800000008 57 53 53 }
+ $sequence_1 = { e8???????? 68???????? 8945cc e8???????? 68???????? 8945d4 e8???????? }
+ $sequence_2 = { 53 53 6800000008 57 }
+ $sequence_3 = { 8945d4 e8???????? 68???????? 8945d0 e8???????? }
+ $sequence_4 = { 0345f0 0fbe08 8b45f0 33d2 }
+ $sequence_5 = { 81e1ff000000 8b45ec 8b55f8 66890c42 }
+ $sequence_6 = { 8b45f8 0345ec 8808 eb10 }
+ $sequence_7 = { 8b55f0 8b7508 668b1456 66891441 }
+ $sequence_8 = { 66890c42 eb14 8b45ec 8b4df8 }
+ $sequence_9 = { 53 ff15???????? 8b75f8 85f6 }
+ $sequence_10 = { 8b4d08 0fb70c41 8b45f0 33d2 }
+ $sequence_11 = { 50 6a40 ff15???????? 8945f8 837df800 7507 }
+ $sequence_12 = { 837df800 7507 33c0 e9???????? c745f004000000 }
+ $sequence_13 = { 7407 c60100 41 48 75f9 ff75f8 }
+ $sequence_14 = { 48 75fa 56 ff15???????? ff75f8 }
+ $sequence_15 = { 57 ff75e8 ff75f0 ffd6 }
+ $sequence_16 = { e8???????? 8b4508 3bc7 7430 57 }
condition:
- 7 of them and filesize <114688
+ 7 of them and filesize <303104
}
-rule MALPEDIA_Win_Prilex_Auto : FILE
+rule MALPEDIA_Win_Webc2_Cson_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "33d37f97-5d7f-5370-b6c1-4299d7c65706"
+ id = "9e77cd9b-5577-55ec-9bc9-fce8ae6111d5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.prilex"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.prilex_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_cson"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_cson_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "3845b326ac2cf1def622498895bf69526e3d4fb73889990b08fc4c5071c0498b"
+ logic_hash = "7c0e799e7902791c334e5b7573181538432e1af2060bac92fa55c2a280799f66"
score = 75
quality = 75
tags = "FILE"
@@ -152736,32 +159845,32 @@ rule MALPEDIA_Win_Prilex_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8be8 ffd7 8d442410 8d4c2414 }
- $sequence_1 = { 8b0f 51 ff15???????? 8945e4 68???????? }
- $sequence_2 = { 8d442424 6a0c 8b11 50 52 56 }
- $sequence_3 = { e8???????? 5d 8d4c2420 8d542414 51 }
- $sequence_4 = { ff15???????? c745fc02000000 8b4510 33c9 833800 0f95c1 }
- $sequence_5 = { 8d858cfdffff 52 8d8d9cfdffff 50 51 }
- $sequence_6 = { 83c104 898d24ffffff c7851cffffff03400000 8d951cffffff 52 8d458c 50 }
- $sequence_7 = { 8d8dacfdffff 68???????? 52 898d54fdffff c7854cfdffff08400000 }
- $sequence_8 = { e8???????? 8bf0 ff15???????? 8d45ac }
- $sequence_9 = { ffd6 50 8d4da0 68???????? 51 ffd6 }
+ $sequence_0 = { e8???????? 8d85f0feffff 50 e8???????? 6a1e 8db5f6feffff 59 }
+ $sequence_1 = { be???????? 8dbd74ffffff 6a0a f3a5 a4 be???????? 56 }
+ $sequence_2 = { 50 e8???????? 59 59 ff7508 8d85acfcffff 50 }
+ $sequence_3 = { e8???????? 59 59 68???????? ff15???????? 53 bf???????? }
+ $sequence_4 = { 83c410 85ff 743f 85c0 743b 2bc7 }
+ $sequence_5 = { 8bec 81ec54030000 53 56 8b35???????? 57 33db }
+ $sequence_6 = { 83f803 0f859c010000 53 53 53 53 }
+ $sequence_7 = { 8d7d81 885d80 f3ab 66ab aa 6a0f 33c0 }
+ $sequence_8 = { 8bec 81ec3c060000 53 56 be04010000 }
+ $sequence_9 = { 5e 5b c9 c20400 c605????????01 be00900100 6800040000 }
condition:
- 7 of them and filesize <450560
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Raccoon_Auto : FILE
+rule MALPEDIA_Win_Nitol_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4a27386e-afe9-5aa0-b437-cb8672f32902"
+ id = "198cac67-df3a-5f33-8def-8dcd3146a557"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.raccoon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.raccoon_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nitol"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nitol_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "744c135940d1e7204980afbdf51c2b964c1deff72c5358a0844976025962517f"
+ logic_hash = "e9d7d8e217f108c3161acd931dc4e0ba15adf22ad1ef941917cfc7f75a6244b1"
score = 75
quality = 75
tags = "FILE"
@@ -152775,32 +159884,32 @@ rule MALPEDIA_Win_Raccoon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bf0 8975f0 85f6 7422 8d45ec c706???????? }
- $sequence_1 = { e8???????? 68???????? eb31 51 }
- $sequence_2 = { 8b45e8 3bc6 7c31 7f04 3bde 762b }
- $sequence_3 = { 53 50 8d45e0 895dd0 }
- $sequence_4 = { ff15???????? 8945f4 40 03c7 50 8945f0 }
- $sequence_5 = { ff15???????? 8bf0 83feff 7437 837b1410 7202 8b1b }
- $sequence_6 = { 8d45ec c706???????? 50 53 ff75e4 895dec ff15???????? }
- $sequence_7 = { 57 33db 8bf9 53 6aff 53 }
- $sequence_8 = { 6a01 52 52 52 52 }
- $sequence_9 = { 0f85dd000000 57 57 57 57 8d45fc }
+ $sequence_0 = { 8945d0 885dd4 c645d506 ffd6 668945d6 }
+ $sequence_1 = { 50 ff15???????? 6860ea0000 8945f8 66895de8 e8???????? 59 }
+ $sequence_2 = { ff742430 ffd7 8d442430 55 50 53 56 }
+ $sequence_3 = { 7424 48 0f85c0fdffff 6a01 }
+ $sequence_4 = { 8b35???????? 833d????????01 7465 ffd6 6a0a 99 59 }
+ $sequence_5 = { 8bf8 8bcf 8b07 ff5068 85c0 8945ec 7457 }
+ $sequence_6 = { 7524 8d8594feffff 50 8d8514ffffff 50 8d8514faffff 68???????? }
+ $sequence_7 = { 7419 4a 7416 4a 7406 c6043778 eb1b }
+ $sequence_8 = { 53 ff15???????? e9???????? 6a40 33c0 }
+ $sequence_9 = { ff15???????? 53 8d8df8fcffff 6a0a }
condition:
- 7 of them and filesize <1212416
+ 7 of them and filesize <139264
}
-rule MALPEDIA_Win_Freenki_Auto : FILE
+rule MALPEDIA_Win_Virtualgate_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "96c9c22a-8c0f-508a-9c8b-2adc585b1381"
+ id = "5ab8135e-3bbe-5abd-acc2-717daf53613e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.freenki"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.freenki_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.virtualgate"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.virtualgate_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "ea73b0cd02f4881d245e91a02d5574d630e230bb3618aadd7337accb2e33b167"
+ logic_hash = "5ca5297d10bab80aa59720f493a7b89d0ffff3ac0eaaf62e59c4e5ea64ea6f84"
score = 75
quality = 75
tags = "FILE"
@@ -152814,32 +159923,32 @@ rule MALPEDIA_Win_Freenki_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83e03f 6bc830 8b049578394200 c644082801 897de4 c745fcfeffffff }
- $sequence_1 = { 57 e8???????? 83c404 ff75f8 e8???????? 8bf8 }
- $sequence_2 = { f7d9 0bc8 51 53 e8???????? ffb504e7ffff 8bd8 }
- $sequence_3 = { 68???????? 50 ff5110 8b55b8 8b4dcc 2bd1 0f1f440000 }
- $sequence_4 = { 6bd830 8b04bd78394200 f644032801 7444 837c0318ff 743d e8???????? }
- $sequence_5 = { e8???????? 8b3d???????? 33db 0f1f8000000000 8d853cd4ffff 50 }
- $sequence_6 = { 64a300000000 8bf1 89b5e4edffff 33c0 c785c0edffff00000000 }
- $sequence_7 = { 6bce4c 53 0f100419 0f1100 e8???????? 8b4dfc 83c404 }
- $sequence_8 = { 68???????? ffb5e0f9ffff ff15???????? f7d8 5e }
- $sequence_9 = { dd00 ebc6 c745e0b8de4100 e9???????? c745e0c0de4100 e9???????? }
+ $sequence_0 = { 4157 4883ec38 4c63e9 488bf2 498bc5 488d0dc7f10000 }
+ $sequence_1 = { 4b8794fed02a0200 eb2d 4c8b15???????? ebb8 4c8b15???????? 418bc2 b940000000 }
+ $sequence_2 = { 8d58b0 498bce 448bc3 488d1580bd0000 e8???????? 85c0 7429 }
+ $sequence_3 = { ff15???????? c705????????00001000 eb26 4183f802 }
+ $sequence_4 = { 488bc8 ff15???????? 3b05???????? 488bcb 89442450 7608 }
+ $sequence_5 = { 48894527 498bc0 48ffc0 41381407 75f7 498bc8 48ffc1 }
+ $sequence_6 = { 4c8d05b4d30000 488d15b1d30000 e8???????? 4885c0 7416 }
+ $sequence_7 = { 488bf5 4803d2 498b94d750b50100 e8???????? 85c0 }
+ $sequence_8 = { 4c8d058dbe0100 488bd5 48c1fa06 4c893403 488bc5 }
+ $sequence_9 = { 488b8c2420800200 4833cc e8???????? 488b9c2450800200 }
condition:
- 7 of them and filesize <327680
+ 7 of them and filesize <323584
}
-rule MALPEDIA_Win_Credraptor_Auto : FILE
+rule MALPEDIA_Win_Kivars_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "744ed2ca-2dde-53b2-b19d-4369cb84cbb1"
+ id = "81082c3d-5064-55a3-8cee-83fb88e85d6c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.credraptor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.credraptor_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kivars"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kivars_auto.yar#L1-L170"
license_url = "N/A"
- logic_hash = "751cbf31cf2ad7ebff2dead521605a0ec12dc4ff6ec97fefa5bfc3c13ba5bce0"
+ logic_hash = "57db268647853b0be399381edf4cd6dc1a86ac28f0c0a8c22aae4b45830a7fb0"
score = 75
quality = 75
tags = "FILE"
@@ -152853,32 +159962,38 @@ rule MALPEDIA_Win_Credraptor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { bb???????? 8bf8 e8???????? 8945fc 8b45f8 83c408 85c0 }
- $sequence_1 = { c6402597 895028 8b5120 89502c 8bce 8bc3 e8???????? }
- $sequence_2 = { 8d4db4 e8???????? 85c0 754b 8d55b4 52 e8???????? }
- $sequence_3 = { b800020000 660bc8 8b45f8 5f 894604 894624 66894e1c }
- $sequence_4 = { a900050000 7565 837b1c00 745f 8b4df8 8b5110 52 }
- $sequence_5 = { 8b8e14020000 8975f0 895df8 e8???????? 8bf8 83c404 897dfc }
- $sequence_6 = { 8db5c8fdffff e8???????? 85c0 7430 8b8dccfdffff 8b7f0c 8b95c8fdffff }
- $sequence_7 = { 894d94 8bff 8a01 dd8574ffffff dd05???????? 3c25 7409 }
- $sequence_8 = { c7461000000000 53 c60600 e8???????? 83c404 807f4100 8bdf }
- $sequence_9 = { bb07000000 85ff 7439 ba60240000 6685571c 7409 57 }
+ $sequence_0 = { c705????????00000000 c644245423 c744245002000000 488d4c2450 e8???????? }
+ $sequence_1 = { 8d542440 8944244c 894c243c 6a14 }
+ $sequence_2 = { 8d8c247c010000 51 e8???????? 83c404 33c0 5f 5e }
+ $sequence_3 = { 44894c2420 4c89442418 89542410 48894c2408 4881eca8000000 488b05???????? }
+ $sequence_4 = { ff15???????? 8bc8 8d7308 83e908 8dbc2492000000 8bd1 }
+ $sequence_5 = { 4889842470020000 ff15???????? 89842430020000 c784242002000001000000 c784242c02000002000000 c64424707d }
+ $sequence_6 = { 755d 4c8b8424e0050000 488d942460020000 488d8c2450010000 e8???????? }
+ $sequence_7 = { 4883c005 4889442428 488b842470100000 4883c009 }
+ $sequence_8 = { 894c2430 89442444 894c2434 89442448 894c2438 8d542440 8944244c }
+ $sequence_9 = { 488d942440010000 488d4c2430 e8???????? 8b442434 83e001 85c0 }
+ $sequence_10 = { 50 8b4d18 51 8d5514 }
+ $sequence_11 = { 7476 eb09 80fb3d 0f8489000000 0fbe5c2412 c0e202 8a5c1c14 }
+ $sequence_12 = { 488bc8 ff15???????? 8b842460110000 ffc0 }
+ $sequence_13 = { 83fffe 741b 83ffff 0f858c000000 8d8c247c010000 }
+ $sequence_14 = { 8bf0 83c609 33ff 6a74 897c2414 e8???????? 83c404 }
+ $sequence_15 = { 48894c2408 4881ec68030000 48c7842448030000feffffff 488d8c2430010000 e8???????? }
condition:
- 7 of them and filesize <1728512
+ 7 of them and filesize <196608
}
-rule MALPEDIA_Win_Kwampirs_Auto : FILE
+rule MALPEDIA_Win_Sinowal_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "25decd9c-07db-5eba-ac2c-8b87bfe95cdd"
+ id = "31384acf-e07e-5abe-adce-b44a77e374ec"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kwampirs"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kwampirs_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sinowal"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sinowal_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "6b54d71a60f0765ea0fd29b4cf202a2af753cd8f92ae599bc00fdafc2b919f65"
+ logic_hash = "42d79ca235acd4d3a743286e206901b01ddea7a50a0ec3cebf0e0027f96ae13f"
score = 75
quality = 75
tags = "FILE"
@@ -152892,32 +160007,32 @@ rule MALPEDIA_Win_Kwampirs_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 8d45f0 64a300000000 8965e8 8bf9 33db }
- $sequence_1 = { e8???????? b001 8b4df0 64890d00000000 59 }
- $sequence_2 = { 51 e8???????? 83c404 a3???????? 33f6 }
- $sequence_3 = { 3bf3 7642 56 e8???????? 8907 }
- $sequence_4 = { 668955f4 33d2 668955f6 e8???????? 83c40c }
- $sequence_5 = { c3 32c0 8b4df0 64890d00000000 59 }
- $sequence_6 = { 8d4df0 51 68???????? e8???????? 83c40c 32c0 }
- $sequence_7 = { 6a00 6800001000 6a03 6a00 }
- $sequence_8 = { 83c404 8a45e7 8b4df0 64890d00000000 59 5f }
- $sequence_9 = { 33c5 50 8d45f0 64a300000000 8965e8 8bf9 33db }
+ $sequence_0 = { 8d95bcfdffff 52 e8???????? 83c40c c745f000000000 }
+ $sequence_1 = { 8b450c 8b4d08 8d5401ff 8955fc eb12 8b4508 83c001 }
+ $sequence_2 = { c745f400000000 c745f800000000 8b4510 8945fc 8b4510 33d2 b908000000 }
+ $sequence_3 = { 6a00 8b45f8 50 ff15???????? 8b45f4 }
+ $sequence_4 = { 8b0495d0669600 2500000080 8b4df8 8b148dd4669600 81e2ffffff7f 0bc2 }
+ $sequence_5 = { 8945d8 c745e400000000 c745fc00000000 68???????? }
+ $sequence_6 = { 837d0800 7406 837d0c00 7502 eb64 8b450c }
+ $sequence_7 = { 89048dd0669600 8b55fc 8b45fc 8b0c85d0669600 890c95d0669600 8b55fc }
+ $sequence_8 = { 890d???????? c705????????00000000 a1???????? 8b0c85d0669600 894dfc }
+ $sequence_9 = { c745f400000000 c745f800000000 c745fc00000000 837d0800 7416 837d0c00 7410 }
condition:
- 7 of them and filesize <2695168
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Miragefox_Auto : FILE
+rule MALPEDIA_Win_Avzhan_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7d7cd6d5-44d9-5ffc-a5c9-9ff4ba40c5bc"
+ id = "ae24c209-0bbe-565c-a4e8-dc5e113ea302"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miragefox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.miragefox_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avzhan"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avzhan_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "f8d9e523d9895537a03eee9c6c67877c75001719916af13d5bd2cc1c1b329b5b"
+ logic_hash = "e5753cf0528c1786d65aca4559b3855c06a602b71f8830b1dc3d077867894002"
score = 75
quality = 75
tags = "FILE"
@@ -152931,71 +160046,71 @@ rule MALPEDIA_Win_Miragefox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 50 c6450805 e8???????? be1c810000 8d4508 56 }
- $sequence_1 = { 7509 0fb68340f62a00 eb02 8bc3 5b c9 c3 }
- $sequence_2 = { 8985f07fffff 6a00 0f94c0 83c023 8885ec7fffff 8d85e0f7feff }
- $sequence_3 = { 7417 8bf9 c1ff05 83e11f 8b3cbd20f52a00 }
- $sequence_4 = { 57 e8???????? 8d4604 6a19 }
- $sequence_5 = { 6a00 50 e8???????? 8b4510 83c40c 8985147cffff }
- $sequence_6 = { 6802800000 8d8520010000 53 50 e8???????? 8b4510 83c418 }
- $sequence_7 = { 6800400000 50 ff75fc ff15???????? 8b8514010000 2b75f4 }
- $sequence_8 = { b820080100 e8???????? 53 56 ff7518 6a00 6a01 }
- $sequence_9 = { e8???????? 834dfcff 8d4dec e8???????? e9???????? bf18800000 }
+ $sequence_0 = { f3aa 8b3d???????? 833d????????01 7418 }
+ $sequence_1 = { 75e8 6a14 ff15???????? 833d????????01 75d2 }
+ $sequence_2 = { 8bf0 8dbc2404020000 83c9ff 33c0 83c408 f2ae }
+ $sequence_3 = { 68???????? 51 ff15???????? 8b2d???????? 8b1d???????? b910000000 }
+ $sequence_4 = { 8d442464 52 50 e8???????? 83c404 50 e8???????? }
+ $sequence_5 = { 6a00 6a00 6a00 6a00 6a00 8d8c2418020000 6a00 }
+ $sequence_6 = { 83c408 f2ae f7d1 6a00 51 8d8c2404020000 51 }
+ $sequence_7 = { 8bc3 83c408 c1e010 668bc3 8b1d???????? c1e902 }
+ $sequence_8 = { 6a00 51 6a00 ffd5 85c0 }
+ $sequence_9 = { 51 8d842484010000 52 50 }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <122880
}
-rule MALPEDIA_Win_Azov_Wiper_Auto : FILE
+rule MALPEDIA_Win_Unidentified_061_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "76e58a84-2854-5930-bc99-d7f7733110e9"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.azov_wiper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.azov_wiper_auto.yar#L1-L118"
+ id = "59888b60-a3e6-5e9f-a441-429646fe0731"
+ date = "2023-07-11"
+ modified = "2023-07-15"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_061"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_061_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "b6d671c16b8dc6a9d2872e0b93ec5fc03d8fe956d8f9494205bfd799936a0b79"
+ logic_hash = "ee3ce5b6c77f09c690f7a934c26be09c58c4fcdee70275b61c00e527d8aa097d"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
+ malpedia_rule_date = "20230705"
+ malpedia_hash = "42d0574f4405bd7d2b154d321d345acb18834a41"
+ malpedia_version = "20230715"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4c8bc8 4885c0 7455 488d442440 }
- $sequence_1 = { 488d5201 6685c0 75ee 488b05???????? 488bcb 488b10 ff9250010000 }
- $sequence_2 = { 41ff9288010000 85c0 740f 4881c79a020000 4889bc2410030000 483bbc2418030000 0f8c73ffffff }
- $sequence_3 = { 48894c2440 4533c0 48898c2470080000 4c8b10 488d842470080000 }
- $sequence_4 = { 33d2 33c9 48897c2420 4c8b10 41ff92b0000000 8bce }
- $sequence_5 = { 4c8b00 41ff5058 85c0 0f84c6000000 4c89b42480000000 448d4b04 }
- $sequence_6 = { 488bcb 4c8b10 41ff9288010000 85c0 740f 4881c79a020000 }
- $sequence_7 = { 4883ec20 4080e4f0 c645f356 c645f469 c645f572 }
- $sequence_8 = { 488945f8 4883ec08 48890424 4883ec08 }
- $sequence_9 = { 0f8493000000 488bd0 488bcb 482bd3 }
+ $sequence_0 = { 8d85d4fdffff 50 e8???????? c9 }
+ $sequence_1 = { 89b5f0fdffff 899decfdffff 89b5f4feffff 899df0feffff ff15???????? 8945fc }
+ $sequence_2 = { 51 8365fc00 8d45fc 50 68???????? 6801000080 ff15???????? }
+ $sequence_3 = { 8945f0 0fb705???????? 50 ff15???????? 668945ee }
+ $sequence_4 = { 68???????? 56 ff15???????? 83c41c 8d4601 5e eb09 }
+ $sequence_5 = { 7417 03f3 3bf7 7ccb eb2f 7d29 }
+ $sequence_6 = { 83cfff c6457300 3b7566 7cb5 3b7566 }
+ $sequence_7 = { 53 57 6a04 33ff 33db }
+ $sequence_8 = { 5b c9 c20800 81ec00040000 68???????? 68???????? ff15???????? }
+ $sequence_9 = { eb04 c645fb3d 6a05 8d45f8 50 ff750c c645fc00 }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <360448
}
-rule MALPEDIA_Win_Putabmow_Auto : FILE
+rule MALPEDIA_Win_Defray_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "118d99b8-b7d8-55d9-89f4-cf8d56f456ff"
+ id = "ee2cc914-ed1c-504f-bf38-50caf0bf4350"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.putabmow"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.putabmow_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.defray"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.defray_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "4091b5988ccb2a8139f14760c8b7e9d61862064b8efc99f4d36fbebf2dc41c73"
+ logic_hash = "6779b35681313abc4956d5610d5c5eb736ab6b4450531cda5b5e81d10fef89b6"
score = 75
quality = 75
tags = "FILE"
@@ -153009,32 +160124,32 @@ rule MALPEDIA_Win_Putabmow_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 016306 07 015100 07 015600 0801 51 }
- $sequence_1 = { e8???????? 8b55f0 8b4a0c 894d08 894dec 8d4118 89420c }
- $sequence_2 = { 50 51 8d3c01 eb51 ff752c 8b7524 51 }
- $sequence_3 = { 05eb004805 f0005005 f0005005 f0005005 f0005005 f0005005 f0005005 }
- $sequence_4 = { c74424540f000000 85c0 7c16 7f04 85f6 7410 89442418 }
- $sequence_5 = { 8d4c241c e8???????? c744247001000000 6a01 51 68???????? 8d4c2424 }
- $sequence_6 = { e8???????? 83c404 89442428 c7842480000000ffffffff 8b4c241c 85c9 }
- $sequence_7 = { 85c0 7413 6a00 8d8c24c8070000 51 8bc8 e8???????? }
- $sequence_8 = { ff15???????? 85c0 0f8420010000 837e1408 7204 8b06 }
- $sequence_9 = { e9???????? 8d8d50f7ffff e9???????? 8b85fcf4ffff 50 e8???????? 59 }
+ $sequence_0 = { 3bc1 75c3 894db4 8d8d60ffffff e8???????? 84c0 7419 }
+ $sequence_1 = { 8b0b 8bc1 83e13f c1f806 6bc930 8b048568f34800 }
+ $sequence_2 = { 33c0 8dbd94f5ffff a5 a5 a5 8dbda0f5ffff be???????? }
+ $sequence_3 = { 2bf2 8d7b1f c1ef05 c1fe02 897d08 3bfe 7322 }
+ $sequence_4 = { 83c9f8 41 0f2825???????? 8bd6 0f282d???????? 2bd1 0f57db }
+ $sequence_5 = { 33c6 03d0 8b85e0feffff 03940514ffffff 039008d54700 03d7 8bbde4feffff }
+ $sequence_6 = { 56 6a02 51 8975fc 8975f8 ff15???????? }
+ $sequence_7 = { 663907 7407 83c702 3bfe 75f4 3bfe 0f8434feffff }
+ $sequence_8 = { 8bf0 85f6 0f8528050000 8b45d8 c745f4006d4100 8945f8 837d1000 }
+ $sequence_9 = { 6a0c 99 5f f7ff 8365e000 8b7508 85c0 }
condition:
- 7 of them and filesize <704512
+ 7 of them and filesize <1253376
}
-rule MALPEDIA_Win_Clipog_Auto : FILE
+rule MALPEDIA_Win_Mokes_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "46aafcb1-e1b8-5042-a65a-96aaea69b545"
+ id = "5228f490-0d80-56e9-a8cc-72e35ac44ea7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.clipog"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.clipog_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mokes"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mokes_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "d53a5689475b1eada9174cbb0eba62d34ac88574fbde919bc04ba3774f961a03"
+ logic_hash = "be97fd0567c8d98c1350b6cf1d21361ab6916096a99c6915f04160ab0a34cb53"
score = 75
quality = 75
tags = "FILE"
@@ -153048,34 +160163,34 @@ rule MALPEDIA_Win_Clipog_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c744242880000000 c744242004000000 4533c9 418d5104 458d4101 ff15???????? 48898710180000 }
- $sequence_1 = { 4c8bea 4b8b8cf7907c0200 4c8b15???????? 4883cfff 418bc2 498bd2 4833d1 }
- $sequence_2 = { 83c7f8 81ffd6000000 0f87eb030000 488d1531c5ffff 0fb6843a24410000 8b8c824c400000 4803ca }
- $sequence_3 = { 48895808 48896810 48897018 48897820 4156 33ed 4c8d352e910000 }
- $sequence_4 = { 4c8d0d13210100 8bf9 488d150a210100 b907000000 4c8d05f6200100 e8???????? }
- $sequence_5 = { eb7a 488d0dd0140200 e8???????? 85c0 0f94c0 eb67 }
- $sequence_6 = { 488d15b6e80100 e9???????? 488d15bae80100 e9???????? }
- $sequence_7 = { 488d1585ee0000 488d0d76ee0000 e8???????? 0fb605???????? }
- $sequence_8 = { e9???????? 4c8d256b4e0100 8bee 498bc4 41bf01000000 }
- $sequence_9 = { f20f1000 8b7808 e9???????? 488d05ae920100 4a8b0ce8 42f644313880 }
+ $sequence_0 = { f6c101 0f85b0000000 8b442424 8b00 3d???????? 0f849f000000 8b4804 }
+ $sequence_1 = { f20f1001 660f2fc1 0f28c3 f20f5cc7 0f47c1 f20f1008 f20f59c2 }
+ $sequence_2 = { ff9050010000 8b8bac010000 8d83ac010000 89442424 85c9 740b 83790400 }
+ $sequence_3 = { ff5030 89442410 83f8ff 7512 8b4508 c700???????? 5f }
+ $sequence_4 = { f20f1025???????? f30fe6db f30fe6d2 f30fe6c9 f30fe6c0 f20f59dc f20f59d4 }
+ $sequence_5 = { ffd0 8d4900 3d???????? 0f84cb000000 8b00 85c0 75ef }
+ $sequence_6 = { e8???????? 8d4e14 e8???????? 8d4e34 e8???????? 5f 5e }
+ $sequence_7 = { ff750c c70000000000 e8???????? 8b4508 8bce c706???????? c74608???????? }
+ $sequence_8 = { e8???????? 8b75e4 8b4e0c 03ce 8b4604 8d0445feffffff 50 }
+ $sequence_9 = { f20f1005???????? 660f2fc1 0f82ac010000 f20f108e88000000 f20f109690000000 f20f5c9680000000 f20f5c4e78 }
condition:
- 7 of them and filesize <372736
+ 7 of them and filesize <18505728
}
-rule MALPEDIA_Win_Fatduke_Auto : FILE
+rule MALPEDIA_Win_Strongpity_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1df82884-dd37-5110-97a3-f389ea498843"
+ id = "74f27818-19f0-5cf0-92fb-64e00785ec08"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fatduke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fatduke_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.strongpity"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.strongpity_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "40661bdfa7c29a9f9d4cfc7da5ee8f1460f5e36e7c11bd94001d922b76261842"
- score = 75
- quality = 75
+ logic_hash = "61a3d3556929a6d92379ea8e74c4d3e507b020fc18a8d58904a2026c1434bfed"
+ score = 60
+ quality = 45
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -153087,32 +160202,38 @@ rule MALPEDIA_Win_Fatduke_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 807b0d00 7552 ff7608 8bc8 e8???????? 8b36 8d7b10 }
- $sequence_1 = { 8bcb 85f6 7455 83ee04 7211 8b01 3b02 }
- $sequence_2 = { ff75f0 c746140f000000 c7461000000000 c60600 e8???????? 8b4b04 83c404 }
- $sequence_3 = { e8???????? c745c000000000 c745c400000000 c745c40f000000 c745c000000000 c645b000 3bc1 }
- $sequence_4 = { e8???????? 83c404 c745bc0f000000 c745b800000000 c645a800 c745fcffffffff 837dec10 }
- $sequence_5 = { c7864c01000000000000 c6863c01000000 c645fc0b 83be3801000010 720e ffb624010000 e8???????? }
- $sequence_6 = { f7d3 23da 7419 2bf9 8bff 8a040f 8d4901 }
- $sequence_7 = { 83ec1c a1???????? 33c5 8945fc 8b4508 8b4910 8945e4 }
- $sequence_8 = { 8d4e08 51 e8???????? c745fcffffffff 8bc6 8b4df4 64890d00000000 }
- $sequence_9 = { ff75c0 e8???????? 83c404 c745d40f000000 8ac3 c745d000000000 c645c000 }
+ $sequence_0 = { 50 33c0 d1f9 50 51 53 }
+ $sequence_1 = { 75f8 ff75d0 68???????? ff36 e8???????? }
+ $sequence_2 = { 41 83ea01 75f7 50 e8???????? 59 }
+ $sequence_3 = { e8???????? 8b4608 83c418 6a2f 59 }
+ $sequence_4 = { 8945f8 f7d8 56 57 }
+ $sequence_5 = { 33db c745f804000000 53 ff7710 895df4 ff770c }
+ $sequence_6 = { ba???????? f3a5 8bf2 668b02 83c202 }
+ $sequence_7 = { 83e801 7408 6a02 58 884612 }
+ $sequence_8 = { 0107 83be8800000002 8b07 0f85ad000000 83f814 }
+ $sequence_9 = { 012e 885c240a e9???????? 84db 0f8434020000 }
+ $sequence_10 = { 5f 8d4503 5d 5b 8b4c2428 }
+ $sequence_11 = { 7417 48 7545 39812c020000 7433 8b8124020000 }
+ $sequence_12 = { 5f 8b4c2408 5e 5b }
+ $sequence_13 = { 5f 8d4502 5d 5e 5b 8b4c2468 }
+ $sequence_14 = { 012e 885c240a ebc3 80fb5d 7520 837c240c00 0f85fe020000 }
+ $sequence_15 = { 5f 8bc3 5b c3 8d4638 50 e8???????? }
condition:
- 7 of them and filesize <9012224
+ 7 of them and filesize <999424
}
-rule MALPEDIA_Win_Crutch_Auto : FILE
+rule MALPEDIA_Win_Orchard_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1c62c9a2-5abd-50e0-9062-2bd78d3ac79d"
+ id = "68833672-b2e1-5b37-9ae2-2dac96bba231"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crutch"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crutch_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.orchard"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.orchard_auto.yar#L1-L159"
license_url = "N/A"
- logic_hash = "af046e99ef1615cf66ae4969fa3fcc0ac2b09e87e76d784694e80263151a794f"
+ logic_hash = "70c3ab090316ecb85f40208f530bb1fb9e1727e271d34e7cabe8cdcf998bd59f"
score = 75
quality = 75
tags = "FILE"
@@ -153126,34 +160247,40 @@ rule MALPEDIA_Win_Crutch_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7536 8b8740030000 f7404000c00000 51 740f 8b4e6c 51 }
- $sequence_1 = { 8b442430 85c0 742b 8b942488000000 8b8c2484000000 52 8b54243c }
- $sequence_2 = { 8b01 50 ff30 51 ff32 8bcb e8???????? }
- $sequence_3 = { 50 8d4ddc e8???????? eb3a 8dbd1cffffff 8d3cd7 8d8514ffffff }
- $sequence_4 = { 8b6c2408 7426 8b03 50 ff15???????? 8b8efc040000 51 }
- $sequence_5 = { 0f84f9000000 b9???????? 8bc6 8d642400 8a10 3a11 751a }
- $sequence_6 = { 81c2cc000000 89542408 8b54240c 89542404 e9???????? 81f9244e0000 }
- $sequence_7 = { 7506 8b7c2428 eb4a 41 51 ff15???????? 8bf8 }
- $sequence_8 = { b823000000 5e c3 8d471f c1e004 8bcf c1e104 }
- $sequence_9 = { 8bf1 8a02 8806 8d4e18 8b4208 894608 8b420c }
+ $sequence_0 = { 83c404 e8???????? 99 b95b000000 f7f9 }
+ $sequence_1 = { 6a01 c645fc08 e8???????? 894604 83c404 8d4718 897034 }
+ $sequence_2 = { 56 ff15???????? ff15???????? 50 6a00 }
+ $sequence_3 = { 8b8550fdffff 83e001 0f8412000000 83a550fdfffffe }
+ $sequence_4 = { 8a45ef 884740 7510 8b470c 8bcf 6a00 }
+ $sequence_5 = { 8d442410 50 ff15???????? 6685c0 }
+ $sequence_6 = { 8b5de8 894348 8b5de0 c70600000000 }
+ $sequence_7 = { 8b75a8 46 56 e8???????? }
+ $sequence_8 = { 8b54240c 83d200 03c1 8b4c2420 }
+ $sequence_9 = { f7f9 81c2d0070000 52 ffd6 }
+ $sequence_10 = { 8b10 8bc8 6a01 ff12 837f3800 8a45ef }
+ $sequence_11 = { 8b07 6a08 895de0 8b4004 }
+ $sequence_12 = { 83f81f 0f877e030000 52 51 e8???????? }
+ $sequence_13 = { 8b7c2424 89542428 8b54240c 83d200 }
+ $sequence_14 = { 50 ff15???????? 83f805 7507 }
+ $sequence_15 = { 8bc8 83e01f c1f905 8b0c8d00755d00 c1e006 8d44010c 50 }
condition:
- 7 of them and filesize <1067008
+ 7 of them and filesize <4716352
}
-rule MALPEDIA_Win_Remcom_Auto : FILE
+rule MALPEDIA_Win_Rikamanu_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a3eb8b2b-3833-5f4e-a476-a250aeb73992"
+ id = "08f5de79-f86c-592e-8a15-71782197d327"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.remcom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.remcom_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rikamanu"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rikamanu_auto.yar#L1-L297"
license_url = "N/A"
- logic_hash = "4f3e16a0ac97921c2fcb2fdd27863c94129d85212bc306f9915a79a291488cb1"
+ logic_hash = "3cf2bc6d93646710c8204bdc714006eac60fd0ca80947c5c7ae6ad8dcd343296"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -153165,32 +160292,52 @@ rule MALPEDIA_Win_Remcom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8be5 5d c3 53 56 8d95f8feffff }
- $sequence_1 = { 83c8ff 89463c 894638 894640 8b8708110000 50 8d9f0c110000 }
- $sequence_2 = { e8???????? a1???????? 33c5 8945fc 56 8b7508 68???????? }
- $sequence_3 = { 50 8d9f0c110000 53 68???????? 8d55e0 68???????? }
- $sequence_4 = { 008891400023 d18a0688078a 46 018847018a46 }
- $sequence_5 = { 52 ffd3 85c0 7507 ffd7 8945f0 eb78 }
- $sequence_6 = { 6a00 6a01 8d4de0 51 ffd3 8d45f4 50 }
- $sequence_7 = { 8d8e00100000 f7d8 1bc0 23c1 8d8de4feffff }
- $sequence_8 = { 8b7508 8d34f528e54000 391e 7404 8bc7 }
- $sequence_9 = { 6a00 51 ffd7 8b4638 6a00 50 ffd7 }
+ $sequence_0 = { e8???????? 6a14 ff15???????? a801 }
+ $sequence_1 = { 50 ff15???????? 8b35???????? 3d80969800 }
+ $sequence_2 = { 8b85e4fdffff 8d8dccfdffff 51 8d9588fdffff 52 8b95f0fdffff 53 }
+ $sequence_3 = { 68???????? 51 c744241c6c714000 e8???????? 33d2 6a0c 8954240a }
+ $sequence_4 = { 0fb6442404 8a4c240c 848821ae4000 751c 837c240800 740e 0fb70445faa64000 }
+ $sequence_5 = { 83c42c 5f eb26 8d4508 8db62c724000 6a00 }
+ $sequence_6 = { 8088????????10 8ac8 80c120 888820ad4000 eb1f 83f861 }
+ $sequence_7 = { 0fbe05???????? 83e802 7413 83e806 7407 bf???????? eb0c }
+ $sequence_8 = { 57 ff15???????? 33c0 40 ebcc }
+ $sequence_9 = { eba1 8b85f0fdffff 6a04 8d95ecfdffff }
+ $sequence_10 = { 51 68???????? 55 ffd3 bf???????? 83c9ff 33c0 }
+ $sequence_11 = { 6a04 55 83e103 6a01 8d44246c }
+ $sequence_12 = { 6a00 6a00 55 ffd7 55 }
+ $sequence_13 = { 56 ff15???????? 8b842470020000 03f8 57 56 ff15???????? }
+ $sequence_14 = { 8987709a2400 83c704 83ff28 72e6 5f }
+ $sequence_15 = { 83c40c 33c0 6808020000 8d95f4fdffff 52 }
+ $sequence_16 = { 8d34c570902400 833e00 7513 50 }
+ $sequence_17 = { 8d4508 8db62c724000 6a00 50 ff36 e8???????? 59 }
+ $sequence_18 = { 891d???????? 891d???????? ff15???????? 8d85f8feffff }
+ $sequence_19 = { 7373 8bc8 8bf0 c1f905 83e61f 8d3c8de0b84000 c1e603 }
+ $sequence_20 = { 391d???????? 0f849e000000 33c0 663bcb 0f95c0 }
+ $sequence_21 = { 8bec 8b450c 56 beff000000 3bc6 7518 }
+ $sequence_22 = { 8945e4 3d00010000 7d10 8a8c181d010000 888808972400 40 ebe6 }
+ $sequence_23 = { 85c0 74c9 33c9 33c0 890d???????? bf???????? 890d???????? }
+ $sequence_24 = { ebe3 80a0a0a6400000 40 41 41 3bc6 }
+ $sequence_25 = { ff15???????? ff750c e8???????? 59 3bc3 }
+ $sequence_26 = { 40 3acb 75f9 2bc2 8d95f8feffff }
+ $sequence_27 = { 8b54240c 81fa80000000 7c0e 0fba25????????01 0f820b070000 57 }
+ $sequence_28 = { 7457 68???????? 56 ffd5 85c0 744b 8a0e }
+ $sequence_29 = { c1e106 8b0485383f4100 f644080401 7405 8b0408 5d }
condition:
- 7 of them and filesize <155648
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Stowaway_Auto : FILE
+rule MALPEDIA_Win_Unidentified_045_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e2cf60b5-46e1-5dce-b54e-4eae51e51190"
+ id = "a8bfd3f0-95b3-5af9-8c6f-fa63b3ef83b3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stowaway"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stowaway_auto.yar#L1-L110"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_045"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_045_auto.yar#L1-L104"
license_url = "N/A"
- logic_hash = "ba9de78202a4b50e7d737f5edb3449679cab84813a913aa4817b5b87ab2181a8"
+ logic_hash = "16726755d5995c8139758648ed741d294bd49338a51b6fd2af1cb4cf9c59e23f"
score = 75
quality = 75
tags = "FILE"
@@ -153204,31 +160351,30 @@ rule MALPEDIA_Win_Stowaway_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b07 09c0 743c 8b5f04 }
- $sequence_1 = { 09c0 7407 8903 83c304 ebe1 }
- $sequence_2 = { 50 54 6a04 53 57 ffd5 8d879f010000 }
- $sequence_3 = { 89f9 57 48 f2ae 55 }
- $sequence_4 = { 8d879f010000 80207f 8060287f 58 50 }
- $sequence_5 = { 95 8a07 47 08c0 74dc 89f9 57 }
- $sequence_6 = { 76e8 77e8 78e8 79e8 }
- $sequence_7 = { 8a7cbe46 a3???????? 4e fb b501 }
- $sequence_8 = { 78e8 79e8 7ae8 ce f67be8 7ce8 7de8 }
+ $sequence_0 = { 50 e8???????? 83c40c 68???????? 68???????? 68???????? e8???????? }
+ $sequence_1 = { 8930 8935???????? eb2b 837d0c02 7528 8b35???????? }
+ $sequence_2 = { 8bc7 eb5c 33f6 85f6 7609 }
+ $sequence_3 = { 6804010000 8d44244c 57 50 e8???????? 8b35???????? }
+ $sequence_4 = { ff15???????? 33f6 56 56 6a02 56 56 }
+ $sequence_5 = { 6a01 56 56 ff7508 897dac 56 }
+ $sequence_6 = { 3345fc 5e c9 c3 803d????????00 }
+ $sequence_7 = { 6a0c 50 57 8975f4 }
condition:
- 7 of them and filesize <8003584
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Fuwuqidrama_Auto : FILE
+rule MALPEDIA_Win_Knot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2e69e70e-5601-5931-bcd7-e645b5b9c52f"
+ id = "a6e6a5bf-ddf5-50fd-bee4-72bdce46b16d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fuwuqidrama"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fuwuqidrama_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.knot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.knot_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "8de556fe8f63afd7a879ecce2fdbb1a150474ddb330c86740527423f92305d9c"
+ logic_hash = "1eb2f0d25dde1dc340b502f0b94dbb26bfbabe3643f1c7382f79e2ee4892b78f"
score = 75
quality = 75
tags = "FILE"
@@ -153242,32 +160388,32 @@ rule MALPEDIA_Win_Fuwuqidrama_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b44241c 8db08c000000 8b8314140000 83f802 764a 8d6b1a 85ed }
- $sequence_1 = { 8b842490020000 52 50 8d4c2444 68???????? 51 }
- $sequence_2 = { 8917 8b542414 894704 b801000000 894f08 89570c 5f }
- $sequence_3 = { 57 33ff 8bd9 57 57 8d4c2430 }
- $sequence_4 = { 8bdf 036908 c1c305 036c2424 c1c61e 89742418 8b712c }
- $sequence_5 = { 83c508 55 ffd7 8a542412 899ec8030000 8896c4030000 899ecc030000 }
- $sequence_6 = { 8bdf 036918 c1c305 036c2410 c1c61e 89742428 8d9c2bd6c162ca }
- $sequence_7 = { ff5220 8d460c 50 ff15???????? 8b4624 }
- $sequence_8 = { 50 ffd6 8d4c242c 6a02 8d542418 51 52 }
- $sequence_9 = { 3d10270000 0f87e7020000 8b5708 8b4704 52 50 8bcf }
+ $sequence_0 = { 50 8b8ddcfdffff 51 6a00 6a00 6a01 }
+ $sequence_1 = { 55 8bec 81ec34010000 6a00 }
+ $sequence_2 = { 6a18 6a00 6a00 68???????? ff15???????? 8d95f0f9ffff }
+ $sequence_3 = { ff15???????? 83c408 6a01 6a00 }
+ $sequence_4 = { 83bdd4fdffff00 7443 8b85d8fdffff 50 8b8ddcfdffff 51 }
+ $sequence_5 = { 6800000040 8d95e0fdffff 52 ff15???????? }
+ $sequence_6 = { ff15???????? 8b55ec 52 ff15???????? 8b45e8 50 ff15???????? }
+ $sequence_7 = { 6a00 6a00 68???????? ff15???????? 8d95f0f9ffff 52 e8???????? }
+ $sequence_8 = { 52 ff15???????? 85c0 7507 32c0 e9???????? c785d8fdffff00000000 }
+ $sequence_9 = { 83c408 68???????? 8b8d74f7ffff 51 e8???????? }
condition:
- 7 of them and filesize <245760
+ 7 of them and filesize <59392
}
-rule MALPEDIA_Win_Maudi_Auto : FILE
+rule MALPEDIA_Win_Wastedlocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3e4205bc-621f-57ac-9783-0d7a80e63274"
+ id = "b7e51866-b49c-5bda-b9e7-206c33d8d8a8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maudi"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maudi_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wastedlocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wastedlocker_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "ae4372c99a5ab8731cfa27286c0755a13272fa053f753c6557e155320ea94c91"
+ logic_hash = "f3876fe06c43f4da1aa2e85c3923ddbcdfed237d9e82449557581810436fb80c"
score = 75
quality = 75
tags = "FILE"
@@ -153281,32 +160427,32 @@ rule MALPEDIA_Win_Maudi_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5d 8b542408 4a 0f85d9000000 68???????? 87d1 }
- $sequence_1 = { 87d1 87ca 51 51 51 }
- $sequence_2 = { 56 55 89e5 5d 89e6 fc ad }
- $sequence_3 = { 89e5 5d 89e6 fc ad 6804010000 56 }
- $sequence_4 = { 59 ffe7 6800400000 6a00 57 68???????? }
- $sequence_5 = { cd03 cd02 68???????? 87d1 87ca 51 }
- $sequence_6 = { 59 59 ffe7 6800400000 6a00 }
- $sequence_7 = { 6804010000 56 50 68???????? 87d1 }
- $sequence_8 = { 59 59 ff25???????? 55 }
- $sequence_9 = { 5d b986180000 55 89e5 5d be???????? }
+ $sequence_0 = { e8???????? 8bf0 ff7508 6a00 ff35???????? ff15???????? 5f }
+ $sequence_1 = { 8945e4 8d45dc 50 c745dc18000000 897de0 }
+ $sequence_2 = { 50 e8???????? 83c40c 56 8d85c8f1ffff 53 50 }
+ $sequence_3 = { ffd3 8bf8 85ff 7419 6a20 57 ffd3 }
+ $sequence_4 = { 8d45ec 50 8d45d4 50 6816011200 }
+ $sequence_5 = { 3b45d0 0f8382000000 894dd8 394de0 740b 0fb703 034710 }
+ $sequence_6 = { ff35???????? ff15???????? 5f ff75f8 ff15???????? }
+ $sequence_7 = { 6a00 ff35???????? ff15???????? 8bd8 85db 7469 8b450c }
+ $sequence_8 = { 2500f0ffff 56 0500100000 50 56 b812345607 }
+ $sequence_9 = { bf04010000 ffd3 8bf0 85f6 746a 57 56 }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <147456
}
-rule MALPEDIA_Win_Xpertrat_Auto : FILE
+rule MALPEDIA_Win_Chainshot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5a6115a3-5806-5873-b6ce-1ac58a01949b"
+ id = "beaf03a9-9558-5280-a84b-64277bd4ffc2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xpertrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xpertrat_auto.yar#L1-L159"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chainshot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chainshot_auto.yar#L1-L111"
license_url = "N/A"
- logic_hash = "c8887b0fd33237ed86a90a507f71d2f7eed9cc8f7e7e530376d7c59ae0763d11"
+ logic_hash = "ba9c33c28d22ea04923b796ce7a5cfd0e30c1f14b0a956e4cbe61344e61c7def"
score = 75
quality = 75
tags = "FILE"
@@ -153320,38 +160466,32 @@ rule MALPEDIA_Win_Xpertrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0870ff 0d80000700 0474 ff0478 }
- $sequence_1 = { ff0a 250004003c 6c 70ff 0808 }
- $sequence_2 = { ff05???????? 000d???????? 0878ff 0d98000700 6e 74ff }
- $sequence_3 = { 0808 008f38001b26 001b 0d002a2364 ff08 }
- $sequence_4 = { ff4d40 ff08 40 0430 ff0a 4c 000c00 }
- $sequence_5 = { 0000 00a1cc004400 0bc0 7402 ffe0 68???????? }
- $sequence_6 = { 0808 008a3800cc1c 5e 006c70ff 0808 }
- $sequence_7 = { 007168 ff0468 ff0a 250004003c }
- $sequence_8 = { ff15???????? 68fffe0000 ffd3 8bd0 }
- $sequence_9 = { ff15???????? 68???????? ffd7 8b1d???????? }
- $sequence_10 = { ff15???????? 6a00 6818000368 8b4508 }
- $sequence_11 = { ff15???????? 68???????? ff15???????? 50 8d858cfeffff }
- $sequence_12 = { ff15???????? 69c0e8030000 0f80b50a0000 50 }
- $sequence_13 = { ff15???????? 6a00 6822000360 8b03 }
- $sequence_14 = { ff15???????? 6a00 68???????? 6a00 68???????? 8b55e0 }
- $sequence_15 = { ff15???????? 6a00 6806000368 8b4dd4 }
+ $sequence_0 = { 731b 85c9 7906 b840000000 }
+ $sequence_1 = { 8d68fc c70726000000 e9???????? c70709000000 bd02000000 }
+ $sequence_2 = { 7509 e8???????? 85c0 7808 }
+ $sequence_3 = { 6683f819 7705 8d4220 eb03 0fb7c2 0fb7c0 }
+ $sequence_4 = { b901070080 e8???????? eb89 8bd7 }
+ $sequence_5 = { 7408 ffd0 8905???????? bfa3000080 e9???????? }
+ $sequence_6 = { ffc8 0f843a110000 ffc8 7427 83e803 0f844a110000 }
+ $sequence_7 = { 7408 ffd0 8905???????? bb82000080 }
+ $sequence_8 = { 8d4a02 b8abaaaaaa f7e1 d1ea }
+ $sequence_9 = { ffc8 747a ffc8 7461 83e802 }
condition:
- 7 of them and filesize <8560640
+ 7 of them and filesize <802816
}
-rule MALPEDIA_Win_Glitch_Pos_Auto : FILE
+rule MALPEDIA_Win_Clop_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f95f1f9c-9245-5181-9c68-89e1dc86d5ed"
+ id = "59cb28c0-0028-51c2-94ee-931d5b6fa068"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.glitch_pos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.glitch_pos_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.clop"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.clop_auto.yar#L1-L188"
license_url = "N/A"
- logic_hash = "27fcd67a00a15c3597cc82166656216e7d9a07529c9493cfeef64f5dddb0c04c"
+ logic_hash = "f2736024915a6a0ca98a26d3016fbd37034bb9a8e1a0f37004991cc314f844e2"
score = 75
quality = 75
tags = "FILE"
@@ -153365,32 +160505,41 @@ rule MALPEDIA_Win_Glitch_Pos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83a5d8feffff00 8b45b8 898518ffffff 8d45d0 50 8b8518ffffff }
- $sequence_1 = { 8b4508 8b00 ff7508 ff9028070000 668b45d4 662d0100 }
- $sequence_2 = { ffb504ffffff e8???????? 89855cfeffff eb07 83a55cfeffff00 8d8d5cffffff e8???????? }
- $sequence_3 = { e8???????? 8d8520ffffff 50 8d8530ffffff 50 8d45dc 50 }
- $sequence_4 = { 68???????? 68???????? e8???????? c78568feffff2cc34600 eb0a c78568feffff2cc34600 8b8568feffff }
- $sequence_5 = { eb07 83a5fcfdffff00 8d45c4 50 8d45cc 50 6a02 }
- $sequence_6 = { 8b4d10 660301 0f8058040000 668945ec 8b4508 8b00 }
- $sequence_7 = { 83c40c 68???????? 6a00 6a06 8b4508 }
- $sequence_8 = { 8d45b4 50 8d45b8 50 6a03 e8???????? }
- $sequence_9 = { 8bec 83ec0c 68???????? 64a100000000 50 64892500000000 b8bc000000 }
+ $sequence_0 = { 83c40c 6860070000 6a40 ff15???????? }
+ $sequence_1 = { 6a04 6800300000 6887000000 6a00 }
+ $sequence_2 = { ff15???????? 56 53 8bf8 ff15???????? 8bf0 56 }
+ $sequence_3 = { 57 6a00 ff15???????? 68???????? 8bd8 }
+ $sequence_4 = { ff15???????? 8bf0 56 53 ff15???????? 50 }
+ $sequence_5 = { 6683e07f 6683f87f 8d642408 0f85fd0b0000 eb00 f30f7e442404 660f2815???????? }
+ $sequence_6 = { 50 ff15???????? 83c40c 6860070000 }
+ $sequence_7 = { ffd0 c3 8bff 55 8bec 83ec1c 8d4de4 }
+ $sequence_8 = { 0f85aa010000 68???????? 8d442450 50 }
+ $sequence_9 = { 8be5 5d c20400 56 ff15???????? 6a00 }
+ $sequence_10 = { 8d85bcefffff 50 ff15???????? 68???????? }
+ $sequence_11 = { 68???????? 68???????? e8???????? 83c424 6aff }
+ $sequence_12 = { 6888130000 ffd7 6a00 6a00 6a00 68???????? }
+ $sequence_13 = { ff15???????? 68???????? 8d85dcf7ffff 50 }
+ $sequence_14 = { 83c408 6aff ff15???????? 33c0 }
+ $sequence_15 = { 83c40c 33f6 85ff 7428 }
+ $sequence_16 = { 83c424 53 50 ffd6 }
+ $sequence_17 = { 6aff ffd7 8b4dfc 33c0 5f }
+ $sequence_18 = { 8d8424dc0b0000 50 ffd6 85c0 751a 68???????? 8d8424dc0b0000 }
condition:
- 7 of them and filesize <1024000
+ 7 of them and filesize <796672
}
-rule MALPEDIA_Win_Webc2_Rave_Auto : FILE
+rule MALPEDIA_Win_Necurs_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ea4a2e95-f571-5243-9ef5-0d9d72800185"
+ id = "3d1b7316-0e79-5ade-97ef-8f3ac3ffb54d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_rave"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_rave_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.necurs"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.necurs_auto.yar#L1-L159"
license_url = "N/A"
- logic_hash = "2cbb2512779b7c01486a2ad87d98dfe34ac5aeaa8fcccabe432ae13b764de599"
+ logic_hash = "75c1414f6695a00e2fea038874de3164067ad0287567965dcfd36d5ca522d078"
score = 75
quality = 75
tags = "FILE"
@@ -153404,32 +160553,38 @@ rule MALPEDIA_Win_Webc2_Rave_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f8454010000 8b35???????? 8d542414 6a00 }
- $sequence_1 = { 0f84ea000000 8d542414 6a00 52 8d44241a 6a01 }
- $sequence_2 = { 56 68???????? 53 52 ffd7 3bc3 894614 }
- $sequence_3 = { f7d1 49 3bd9 72e5 }
- $sequence_4 = { 8d442418 50 51 e8???????? 85c0 74b1 }
- $sequence_5 = { 895c2448 ffd7 3bc3 894610 7517 }
- $sequence_6 = { 7418 8b742418 46 4f }
- $sequence_7 = { 33c9 33f6 85ed 7e45 8b942414020000 53 }
- $sequence_8 = { 03d1 8bca 894c2414 7872 }
- $sequence_9 = { e8???????? 83c404 ff15???????? 85ff }
+ $sequence_0 = { 13f2 a3???????? 8935???????? 890d???????? 8bc1 5e }
+ $sequence_1 = { 030d???????? a3???????? a1???????? 13f2 a3???????? }
+ $sequence_2 = { 13f2 33d2 030d???????? a3???????? }
+ $sequence_3 = { 8bc2 034508 5e 5d c3 55 }
+ $sequence_4 = { 03c8 a1???????? 13f2 33d2 }
+ $sequence_5 = { 56 8bf2 ba06e0a636 f7e2 }
+ $sequence_6 = { 397508 7604 33c0 eb12 }
+ $sequence_7 = { 2b7508 33d2 46 f7f6 8bc2 034508 }
+ $sequence_8 = { 8d85ecfbffff 57 50 e8???????? 83c410 }
+ $sequence_9 = { 33d7 33c1 52 50 }
+ $sequence_10 = { 6a7d 50 ffd6 59 }
+ $sequence_11 = { 8bc1 0bc7 7409 8bc1 8bd7 e9???????? }
+ $sequence_12 = { 57 57 8d8574ffffff 50 }
+ $sequence_13 = { 6a7b 50 ffd6 8bf8 59 59 }
+ $sequence_14 = { 53 ff15???????? 59 33c0 5e }
+ $sequence_15 = { a1???????? 33d2 f7f1 ff05???????? }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <475136
}
-rule MALPEDIA_Win_Rgdoor_Auto : FILE
+rule MALPEDIA_Win_Onliner_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4140ffd6-129c-5510-99e3-ad151c975d1e"
+ id = "c0a25174-badc-5a1b-a67c-48cbb1aef2be"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rgdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rgdoor_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.onliner"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.onliner_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "bf6d408b52f68286adc8c589928141fb2586a77ca6ee142e58e02ec6b6fb2c0d"
+ logic_hash = "6df36365f1b8dbe7cdb1d0b03d64f7da847c99d2518d7b5ebc1610f68ca3a069"
score = 75
quality = 75
tags = "FILE"
@@ -153443,32 +160598,32 @@ rule MALPEDIA_Win_Rgdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7512 448bfb 448be3 4c8d35d4870100 e9???????? bd01000000 ba98000000 }
- $sequence_1 = { 488bce eb9d 33db 41b803010000 488bd6 e8???????? }
- $sequence_2 = { 4533f6 eb0e 4983ceff 90 49ffc6 42381c32 75f7 }
- $sequence_3 = { e8???????? b802000000 eb30 48837dd010 720a 488b4db8 }
- $sequence_4 = { e8???????? 488d05554b0200 4889442458 488d15398d0200 488d4c2458 }
- $sequence_5 = { e8???????? 83f8ff 0f8490050000 80bc247001000077 750a 8bde 448be6 }
- $sequence_6 = { 8938 e8???????? 488d1d8b390200 4885c0 7404 }
- $sequence_7 = { 4883ec20 488d3d8bf90100 48393d???????? 742b }
- $sequence_8 = { 48837db010 480f435598 41b822000000 488d8de8000000 e8???????? 4885c0 488b85e0000000 }
- $sequence_9 = { 488bce ff15???????? 8bf8 eb25 488b8c2490000000 e9???????? 48895c2420 }
+ $sequence_0 = { 0f8274ffffff 6683ff04 0f8596000000 33ff 8d45e4 668b55ee c1e202 }
+ $sequence_1 = { 8d8db4feffff 8bd3 8bc6 8b38 ff570c 8b85b4feffff 5a }
+ $sequence_2 = { 85c0 7405 3b50fc 7205 e8???????? 42 8d4410ff }
+ $sequence_3 = { 50 6a00 8bc3 e8???????? 50 ff15???????? }
+ $sequence_4 = { 3b45e4 0f84ab000000 ff45e4 807dee00 742c 8b55e4 2bd0 }
+ $sequence_5 = { 3345fc 03c6 0345cc 05c8fbd3e7 ba14000000 e8???????? 03c7 }
+ $sequence_6 = { 8bda 8bf0 8bc3 ba02000000 e8???????? 8bc3 e8???????? }
+ $sequence_7 = { 33c0 8945ec 837df000 7426 83caff 8b45f8 }
+ $sequence_8 = { 3bc3 7c07 807c1eff20 74f4 57 b9ffffff7f 8bd3 }
+ $sequence_9 = { 8b45fc 8b88d0010000 ba02000000 8b45fc 8b18 ff534c ff75e4 }
condition:
- 7 of them and filesize <475136
+ 7 of them and filesize <1736704
}
-rule MALPEDIA_Win_Joanap_Auto : FILE
+rule MALPEDIA_Win_Jupiter_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7b68fae3-26c2-54e0-a3e7-133f1581d080"
+ id = "36445056-0ae8-5be8-adc6-1a78abf2ec58"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.joanap"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.joanap_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jupiter"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jupiter_auto.yar#L1-L112"
license_url = "N/A"
- logic_hash = "e8c4ce689f2f9423d9b3c5df5ab94aca097fbbc5a318100a67230ed53bf34f3c"
+ logic_hash = "f1911af4b4fd9bd3e29d91af55822bde97c05f4b517de64421dfe8b0d1264d94"
score = 75
quality = 75
tags = "FILE"
@@ -153482,32 +160637,32 @@ rule MALPEDIA_Win_Joanap_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b8c242c010000 66c74424140200 51 c744241c7f000001 ff15???????? 8d542414 }
- $sequence_1 = { 56 85c0 57 0f8483000000 53 ff15???????? 50 }
- $sequence_2 = { 0f8488000000 6a04 e8???????? 8b442414 8d6b06 66897304 }
- $sequence_3 = { f7d1 49 81f908020000 7332 56 ff15???????? 8bf8 }
- $sequence_4 = { 750c 8d8c24b8020000 e9???????? 8d8c241b020000 51 56 ffd7 }
- $sequence_5 = { 85c0 0f85cbfeffff 8b4c2410 51 ff15???????? 57 ff15???????? }
- $sequence_6 = { ff15???????? 85c0 0f84cf000000 8b4c2420 51 6a01 68ff0f1f00 }
- $sequence_7 = { 55 8bac2420010000 56 8b35???????? 57 33ff 8b842424010000 }
- $sequence_8 = { 8b442414 83c018 47 3dd0020000 89442414 0f8c73ffffff 8b742410 }
- $sequence_9 = { 0bc0 5b 81c470210000 c3 6a01 6820bf0200 8d8c2488010000 }
+ $sequence_0 = { 8a4147 884104 8a4146 884105 8b4144 c1f808 884106 }
+ $sequence_1 = { c605????????01 66c705????????0101 c605????????01 c605????????01 66c705????????0101 }
+ $sequence_2 = { 8b4144 c1f808 884106 8a4144 884107 }
+ $sequence_3 = { 884105 8b4144 c1f808 884106 8a4144 }
+ $sequence_4 = { 50 6802000000 ff35???????? ff35???????? }
+ $sequence_5 = { 66c705????????0101 c605????????01 c605????????01 c605????????01 }
+ $sequence_6 = { 884105 8b4144 c1f808 884106 8a4144 884107 }
+ $sequence_7 = { c1f808 884106 8a4144 884107 }
+ $sequence_8 = { c605????????01 66c705????????0101 c605????????01 c605????????01 }
+ $sequence_9 = { 884104 8a4146 884105 8b4144 }
condition:
- 7 of them and filesize <270336
+ 7 of them and filesize <224112
}
-rule MALPEDIA_Win_Ransomlock_Auto : FILE
+rule MALPEDIA_Elf_Satori_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "14d92420-c852-5e3f-a3ed-35c5bfb9c9b6"
+ id = "ef9a3def-11bf-57c1-9abe-eaf3ea87bbf4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ransomlock"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ransomlock_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.satori"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.satori_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "febe0932e68debf15b0eb0e37d5a00d2ff8a7e3a0c0b884f506cda6ff33b2a0c"
+ logic_hash = "acc91f43f84cb8d9ebcbacb4d453867e5ba0d238d6255f05df970cd0ecb540bb"
score = 75
quality = 75
tags = "FILE"
@@ -153521,32 +160676,32 @@ rule MALPEDIA_Win_Ransomlock_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? 83c408 8b0d???????? 6a64 51 ff15???????? }
- $sequence_1 = { 99 2bc2 6a00 8bd1 d1ea d1f8 }
- $sequence_2 = { 8b5120 56 50 ffd2 85c0 7807 c745ec01000000 }
- $sequence_3 = { 0f8418010000 8b08 8d55fc 52 50 8b4120 }
- $sequence_4 = { 0fb7047521664000 4e 6685c0 75ec 57 68???????? ffd3 }
- $sequence_5 = { 50 ff15???????? 83c410 6a01 53 }
- $sequence_6 = { 57 ff15???????? 8d70ff 0fb70477 6685c0 7413 8bff }
- $sequence_7 = { 90 68???????? 33f6 ff15???????? a1???????? 85c0 7429 }
- $sequence_8 = { 8b45f0 3bc6 0f8418010000 8b08 8d55fc 52 50 }
- $sequence_9 = { 52 8d8574fdffff 68???????? 50 ff15???????? 83c410 6a01 }
+ $sequence_0 = { 85c0 7804 8b542414 89d0 83c41c }
+ $sequence_1 = { e8???????? b9???????? b802000000 89ca e8???????? }
+ $sequence_2 = { 89c6 53 89d3 83ec10 52 e8???????? }
+ $sequence_3 = { b802000000 e8???????? b905000000 ba???????? b802000000 e8???????? b908000000 }
+ $sequence_4 = { c744244800000000 e9???????? 8b542404 8b3482 6bc018 03442464 }
+ $sequence_5 = { e8???????? 83c414 6a1f e8???????? c7042420000000 e8???????? c785280400001e000000 }
+ $sequence_6 = { 85c0 7416 83ec0c ff35???????? e8???????? 59 6a00 }
+ $sequence_7 = { 3b410c 747c 8b45bc 83ec0c 8b55cc 8d5def 8945e0 }
+ $sequence_8 = { 6a04 56 53 e8???????? 8844243a 83c420 6a00 }
+ $sequence_9 = { 6a15 68???????? 6a1d e8???????? 83c40c 6a15 68???????? }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <122880
}
-rule MALPEDIA_Win_Bleachgap_Auto : FILE
+rule MALPEDIA_Win_Mykings_Spreader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1c7bcc3b-871c-5292-a898-130d22929e4c"
+ id = "96a12e80-b15f-580e-920d-d6c0d35464b0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bleachgap"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bleachgap_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mykings_spreader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mykings_spreader_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "feb4beb187c6596a9fcad947329bf36b55b60b3bae8b02c6a93cdc46dd85c07a"
+ logic_hash = "1bcd674173fea4b83a2f4219e8f61306a972490f94a89cfaf5e1f466fdec8eff"
score = 75
quality = 75
tags = "FILE"
@@ -153560,71 +160715,71 @@ rule MALPEDIA_Win_Bleachgap_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bec ff750c e8???????? 8bc8 83f9ff 7506 32c0 }
- $sequence_1 = { c645fc04 8b8d70fbffff 83f910 722f 8b955cfbffff 41 8bc2 }
- $sequence_2 = { e9???????? ff7104 8d442414 6800010000 50 e8???????? 8d442410 }
- $sequence_3 = { c68539ffffff7a c6853affffff5f c6853bffffff55 c6853cffffff41 c6853dffffff57 c6853effffff3c c6853fffffff41 }
- $sequence_4 = { eb0d 8b450c 8945b8 c745b400000000 84c9 8d4dd4 0f44f2 }
- $sequence_5 = { c6431000 894924 c645fc02 8d45e0 c645e801 0f57c0 660fd607 }
- $sequence_6 = { 88442426 8b442410 0413 3457 88442427 8b442410 0414 }
- $sequence_7 = { b801000000 d3e0 8502 0f8459ffffff 8b4614 8b5714 8b0e }
- $sequence_8 = { ff750c 50 e8???????? 83c410 85c0 0f84d9010000 53 }
- $sequence_9 = { 8a13 8bc1 8b4df0 43 41 894df4 3810 }
+ $sequence_0 = { 7519 51 55 8bce e8???????? 6a00 6a00 }
+ $sequence_1 = { 8b1e ff938c000000 8b0424 8b5014 85d2 7507 bf00000000 }
+ $sequence_2 = { e8???????? 837e1800 7439 8b4620 c1e003 89c7 8b4618 }
+ $sequence_3 = { 89c1 c745f401000000 3b4df4 723d ff4df4 8d7600 ff45f4 }
+ $sequence_4 = { 68???????? 50 ff15???????? a3???????? 83c0fe 40 40 }
+ $sequence_5 = { 8942fc 89d8 c1f81f 8b1424 8b7208 8b4a0c 29de }
+ $sequence_6 = { eb02 b300 e8???????? 8d45cc e8???????? c745cc00000000 58 }
+ $sequence_7 = { 33d2 b9???????? 8bc2 8bf2 c1f805 83e61f 8b0485a02e4100 }
+ $sequence_8 = { 89d8 29f0 85c0 7e39 8b55f4 85d2 7505 }
+ $sequence_9 = { 8b7508 8b36 8975c8 8b7d08 8b7f04 }
condition:
- 7 of them and filesize <4538368
+ 7 of them and filesize <1581056
}
-rule MALPEDIA_Win_Glassrat_Auto : FILE
+rule MALPEDIA_Win_Unidentified_101_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "daeaa019-8217-55aa-beac-5fb62572b79c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.glassrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.glassrat_auto.yar#L1-L117"
+ id = "1e5a977c-e7e9-5732-97b6-6aadc4f691fc"
+ date = "2023-03-28"
+ modified = "2023-04-07"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_101"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_101_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "c91259f84ec94eec4bc87c666b3c91ba45af3572c135cc4f200070d560141e5d"
+ logic_hash = "71f0751fbd77a928634515b558d06922b4bf4a312042d6abbd6ba70171c64843"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
+ malpedia_rule_date = "20230328"
+ malpedia_hash = "9d2d75cef573c1c2d861f5197df8f563b05a305d"
+ malpedia_version = "20230407"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d542438 83c9ff 33c0 f2ae f7d1 2bf9 8bc1 }
- $sequence_1 = { ff15???????? 33c0 8b5504 8944241d 8d4c241c }
- $sequence_2 = { 747a 3bfe 7476 56 56 56 53 }
- $sequence_3 = { 895db8 895dbc ff15???????? 85c0 0f84bb000000 }
- $sequence_4 = { 3bc8 b802000000 0f85b4000000 33d2 b909020000 52 83ec10 }
- $sequence_5 = { 6a04 51 52 8844243b }
- $sequence_6 = { 8b460c 53 53 57 50 }
- $sequence_7 = { 8bce ff12 57 ff15???????? 8d4c2420 }
- $sequence_8 = { 89442418 ff15???????? 8b4d04 8b1d???????? }
- $sequence_9 = { 89442408 89542404 8a15???????? 33c0 }
+ $sequence_0 = { c70016000000 e8???????? 83c8ff e9???????? 498bc4 488d0ddb070100 83e03f }
+ $sequence_1 = { 6689842404010000 b865000000 6689842406010000 33c0 6689842408010000 }
+ $sequence_2 = { 33c0 b968000000 f3aa 488d842400010000 4889442448 488d842430020000 4889442440 }
+ $sequence_3 = { 4889742410 57 4883ec20 418bf0 4c8d0debb40000 8bda 4c8d05dab40000 }
+ $sequence_4 = { c744243000000000 4c8d4c2430 4c8b442440 8b542468 488b4c2460 }
+ $sequence_5 = { c68424e900000065 c68424ea00000057 c68424eb00000000 c644243052 c644243165 c644243261 c644243364 }
+ $sequence_6 = { 428a8c1910e40100 4c2bc0 418b40fc 4d894108 d3e8 41894120 }
+ $sequence_7 = { 48c744242000000000 4c8d8c24c8000000 448b442450 488b542458 488b4c2470 ff15???????? }
+ $sequence_8 = { 41b804010000 488d942400030000 33c9 ff15???????? c744245801000000 e8???????? 833d????????01 }
+ $sequence_9 = { 7528 48833d????????00 741e 488d0dd8450100 e8???????? 85c0 740e }
condition:
- 7 of them and filesize <81920
+ 7 of them and filesize <402432
}
-rule MALPEDIA_Win_Flusihoc_Auto : FILE
+rule MALPEDIA_Win_Lightneuron_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "78da62a5-c798-5ed3-b0d2-4c7f68889a1b"
+ id = "539cc86b-948c-5a39-97ed-a3902d358bcb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flusihoc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flusihoc_auto.yar#L1-L168"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lightneuron"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lightneuron_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "9c728cded699d733d4c529cd8d0e45713d382315b1100a325978e10da75fc22d"
+ logic_hash = "eb817806e099f7ab1d4d5a04d338d80185e8c65715cfe2e18f8deb16ab95898d"
score = 75
quality = 75
tags = "FILE"
@@ -153638,38 +160793,32 @@ rule MALPEDIA_Win_Flusihoc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bec 83e4f8 81ece40b0000 a1???????? }
- $sequence_1 = { 53 56 57 6a40 8d442428 6a00 50 }
- $sequence_2 = { 50 f3a5 c684246402000000 e8???????? }
- $sequence_3 = { a1???????? 33c4 89842450160000 53 56 8b7508 57 }
- $sequence_4 = { 52 ffd6 6a0a ff15???????? }
- $sequence_5 = { 7507 80864d01000004 83f822 7506 }
- $sequence_6 = { ffd3 8b442410 6aff 50 ff15???????? }
- $sequence_7 = { 50 f3a5 c684246401000000 e8???????? 83c40c }
- $sequence_8 = { 6a00 50 c744242c44000000 e8???????? }
- $sequence_9 = { 83f822 7506 fe8e42010000 3d14010000 7506 }
- $sequence_10 = { 8b8c245c160000 5f 5e 5b 33cc 33c0 e8???????? }
- $sequence_11 = { ff15???????? 8b4c2410 51 ffd6 8b542414 52 ffd6 }
- $sequence_12 = { 3d68010000 7505 fe06 fe4e17 83f834 7503 fe4e18 }
- $sequence_13 = { 51 6a00 ff15???????? 8d95f4feffff 52 6806000200 }
- $sequence_14 = { 6804010000 8d85f8feffff 50 6a01 }
- $sequence_15 = { 68???????? 6802000080 ff15???????? 85c0 752f 8b8df4feffff }
+ $sequence_0 = { e8???????? 488d8c2434010000 33d2 41b800010000 89b42430010000 e8???????? 488bcf }
+ $sequence_1 = { 0f4ed9 3bc5 770b 3beb 7707 b801000000 eb02 }
+ $sequence_2 = { 85d2 7e24 488b8f80000000 e8???????? 488b8f80000000 4885c9 740c }
+ $sequence_3 = { e8???????? 8bf0 85c0 7502 893b 85f6 754c }
+ $sequence_4 = { 4503c1 453bc1 4183d200 4403c0 443bc0 45894304 }
+ $sequence_5 = { 448bc3 e8???????? 448bc3 33d2 498bcd e8???????? 498bcd }
+ $sequence_6 = { 4c0f45c0 488b05???????? 4885c0 480f45d0 488d442448 4889442430 4c896c2428 }
+ $sequence_7 = { 488bd0 498bcc e8???????? 4d8b0c24 458b44240c 33d2 }
+ $sequence_8 = { 48895c2428 89442420 e8???????? 448b05???????? 4533c9 ba9d010000 b900001000 }
+ $sequence_9 = { 4533c9 4533c0 babf000000 b900001000 48895c2428 89442420 e8???????? }
condition:
- 7 of them and filesize <319488
+ 7 of them and filesize <573440
}
-rule MALPEDIA_Win_Funny_Dream_Auto : FILE
+rule MALPEDIA_Win_Bunitu_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "342150e9-e685-51fd-bb6e-825e56ff33ab"
+ id = "fdd29b03-d926-5cbf-98be-29b287d71b21"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.funny_dream"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.funny_dream_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bunitu"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bunitu_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "93298c694e8a0e9daec0c22ddb9409f4c4088b474ade93c3bf4d76bcd798f980"
+ logic_hash = "c3bd7c13018c7a8c4646040c13e12026479d672a4bbef2d99f41e09a2ac2f388"
score = 75
quality = 75
tags = "FILE"
@@ -153683,32 +160832,32 @@ rule MALPEDIA_Win_Funny_Dream_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c785e0ddffff01000000 50 6880000000 68ffff0000 ffb3c0000000 }
- $sequence_1 = { 6a00 ff7728 ffd6 6a00 ff7724 ff15???????? 8b4714 }
- $sequence_2 = { c745d45368656c 50 53 c745d86c457865 c745dc63757465 66c745e04100 }
- $sequence_3 = { 85c0 0f8494000000 33c9 8a840d3cffffff }
- $sequence_4 = { ff15???????? 85c0 0f85e7feffff 8d4704 899da0fdffff }
- $sequence_5 = { 6a00 6800040000 8d842458030000 50 }
- $sequence_6 = { 50 57 ff15???????? 85c0 7523 8b4618 8b3d???????? }
- $sequence_7 = { 50 ff15???????? 8d442408 c744240810000000 50 8d442414 0f57c0 }
- $sequence_8 = { 85c0 0f84f8000000 68???????? 50 ff15???????? }
- $sequence_9 = { 83c404 8b4f04 85c9 7504 33c0 eb05 8b4708 }
+ $sequence_0 = { 68???????? 50 6a00 68???????? 6a00 50 ff15???????? }
+ $sequence_1 = { 58 6a02 ffb524fdffff ff15???????? ffb524fdffff }
+ $sequence_2 = { 50 ff75ec e8???????? 0bc0 7e18 50 }
+ $sequence_3 = { 48 40 8d443825 668b00 }
+ $sequence_4 = { c70003000000 ffb524fdffff 8f4004 ffb528fdffff 8f4008 }
+ $sequence_5 = { ffb524fdffff e8???????? eb12 6a08 68???????? ffb524fdffff e8???????? }
+ $sequence_6 = { 59 8bd0 8bdf b82f000000 }
+ $sequence_7 = { 895004 b9???????? 8d55fc 52 6800000100 50 51 }
+ $sequence_8 = { c70003000000 ff75f0 8f4004 ff75ec 8f4008 }
+ $sequence_9 = { 837df000 7614 6a02 ff75f0 ff15???????? }
condition:
- 7 of them and filesize <393216
+ 7 of them and filesize <221184
}
-rule MALPEDIA_Win_Miuref_Auto : FILE
+rule MALPEDIA_Win_Strelastealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "34f2a1cb-9745-52c8-a75d-06d5cdb25bcd"
+ id = "308b6312-f55e-5e44-8b26-8341d0a5504a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miuref"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.miuref_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.strelastealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.strelastealer_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "0abc04edb362ffc2e411d61d44a4ba6937064194bb7ee145b0929a61d91bcae4"
+ logic_hash = "4a18fbcab2ec145e1ed1c3a8aa2118c83ff2631df0db61e9cbe03afa397c02a3"
score = 75
quality = 75
tags = "FILE"
@@ -153722,32 +160871,38 @@ rule MALPEDIA_Win_Miuref_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 59 59 8945fc 85f6 760e 803c072e 7418 }
- $sequence_1 = { ff15???????? 50 e8???????? ff750c 8906 50 e8???????? }
- $sequence_2 = { 8bf0 8d7df0 a5 a5 a5 83c418 a5 }
- $sequence_3 = { 6a02 ff35???????? e8???????? 8bf0 83c40c 85f6 7412 }
- $sequence_4 = { 8d8300010000 ff75fc 50 e8???????? 68???????? 8d45f8 50 }
- $sequence_5 = { 8b4124 83f801 7514 ff7514 ff7510 ff750c }
- $sequence_6 = { 7509 0fb74e06 663bcf 7507 33c0 e9???????? }
- $sequence_7 = { e8???????? 50 ff35???????? e8???????? 83c43c e9???????? 55 }
- $sequence_8 = { 8d45d8 50 a5 e8???????? 83c408 8bf0 8bfc }
- $sequence_9 = { 53 53 ff15???????? 50 a3???????? e8???????? 59 }
+ $sequence_0 = { 0f85e6030000 6804010000 8d942464010000 53 52 e8???????? }
+ $sequence_1 = { ff15???????? 8b442434 8b4c2438 53 }
+ $sequence_2 = { 488945f0 488d15d8a20000 b805000000 894520 }
+ $sequence_3 = { 885909 b801000000 83c404 51 0fb69220a30010 3011 33d2 }
+ $sequence_4 = { ff15???????? 33c9 8be8 85db 7612 8bc1 }
+ $sequence_5 = { 48895c2408 4889742410 57 4c8bd2 488d351b43ffff }
+ $sequence_6 = { 488d442478 33d2 4889442430 c744242801000000 4c897c2420 }
+ $sequence_7 = { 488d15eba10000 488d0dc4a10000 e8???????? 488d15e8a10000 488d0dd9a10000 }
+ $sequence_8 = { 0f85bc030000 8b442414 53 53 53 53 8d54244c }
+ $sequence_9 = { 740d 488bc8 49878cff20ac0100 eb0a 4d87b4ff20ac0100 33c0 }
+ $sequence_10 = { 4c8d05c7680100 c744243000020080 488d1548690100 48897c2428 4533c9 }
+ $sequence_11 = { 53 4883ec20 488d057f740000 488bd9 483bc8 7418 }
+ $sequence_12 = { 488d3de6070100 eb07 488d3dc5070100 4533ed }
+ $sequence_13 = { 51 6a00 6a00 6a1a 6a00 ff15???????? 68???????? }
+ $sequence_14 = { 51 8d94247c040000 52 ff15???????? }
+ $sequence_15 = { 8b4508 ff34c580b10010 ff15???????? 5d c3 6a0c }
condition:
- 7 of them and filesize <180224
+ 7 of them and filesize <266240
}
-rule MALPEDIA_Win_Wastedloader_Auto : FILE
+rule MALPEDIA_Win_Pkybot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f15153cb-6336-5eec-a420-db8a6857e34a"
+ id = "b29148a6-8685-5645-99d4-ca854d32849e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wastedloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wastedloader_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pkybot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pkybot_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "e6299dacb3891024e6699f166db0ecba511abe3e26d2cc6dc9ddd0929ba5121a"
+ logic_hash = "809773f54b9553ffea062fd7f87645abd3e261a3e38fb26640ff099fc49a005e"
score = 75
quality = 75
tags = "FILE"
@@ -153761,32 +160916,32 @@ rule MALPEDIA_Win_Wastedloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b748 00ee 0be6 3bf6 2014dd33b89819 220f }
- $sequence_1 = { 0fb7485e 83e954 8b55f8 66894a5e }
- $sequence_2 = { fc b802ec0000 8d6825 94 01dc 00e8 45 }
- $sequence_3 = { b802ec0000 8d6825 94 01dc 00e8 45 }
- $sequence_4 = { ec 7ac4 f8 ae fc }
- $sequence_5 = { 32705b 39e1 108792ff9b95 8abf2ec8650b }
- $sequence_6 = { 1a00 0071bf 7303 1f c8be8de8 1be8 692405008008202c00700d }
- $sequence_7 = { 66894118 8b55f8 0fb74218 83e854 8b4df8 66894118 ba8d000000 }
- $sequence_8 = { 2cbe 832061 5b 5b }
- $sequence_9 = { 30ac06e68bfc49 23f7 b754 7c49 27 59 }
+ $sequence_0 = { ff15???????? 8bf8 83ffff 7429 56 56 }
+ $sequence_1 = { 8d45e0 50 8b06 83c004 50 }
+ $sequence_2 = { 8b4e04 21413c c741300e000000 897938 5f 5e }
+ $sequence_3 = { 7409 ff75dc e8???????? 59 56 }
+ $sequence_4 = { 8b0d???????? 894108 e8???????? a3???????? }
+ $sequence_5 = { 7518 ff35???????? e8???????? 59 893d???????? 893d???????? }
+ $sequence_6 = { 56 a3???????? e8???????? 83c448 }
+ $sequence_7 = { 57 6a10 ff7510 8d45ec 50 e8???????? }
+ $sequence_8 = { 7430 50 3bf7 7507 e8???????? eb05 e8???????? }
+ $sequence_9 = { 8d85ecfdffff 50 8d45f4 50 53 57 ff75fc }
condition:
- 7 of them and filesize <2677760
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Sedll_Auto : FILE
+rule MALPEDIA_Win_Maudi_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "009a21d7-9a67-5650-8e55-9cfcfc21e0f2"
+ id = "3e4205bc-621f-57ac-9783-0d7a80e63274"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sedll"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sedll_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maudi"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maudi_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "21c4f01124bd0cd6ba61129966ab2fcf5cc6cd643797282b60948edf1b57805e"
+ logic_hash = "ae4372c99a5ab8731cfa27286c0755a13272fa053f753c6557e155320ea94c91"
score = 75
quality = 75
tags = "FILE"
@@ -153800,34 +160955,34 @@ rule MALPEDIA_Win_Sedll_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 6a00 6a00 8d8424b0030000 }
- $sequence_1 = { 50 ff15???????? 8b4df8 85c9 7407 }
- $sequence_2 = { 74e3 57 33c9 33ff 85db 0f848f000000 }
- $sequence_3 = { 56 6800010000 8d85f0feffff 8bf1 6880000000 50 }
- $sequence_4 = { 8d842484010000 50 8d842498030000 50 ff15???????? }
- $sequence_5 = { 6a00 53 e8???????? 83c410 6a00 6a00 ff75f4 }
- $sequence_6 = { ff15???????? 85c0 7523 85ff }
- $sequence_7 = { 57 6aff ff75fc 6a00 6a00 ffd3 8bc7 }
- $sequence_8 = { 8b4514 8908 a1???????? 50 }
- $sequence_9 = { 7604 8bf8 2bfb 8d7701 56 }
+ $sequence_0 = { 5d 8b542408 4a 0f85d9000000 68???????? 87d1 }
+ $sequence_1 = { 87d1 87ca 51 51 51 }
+ $sequence_2 = { 56 55 89e5 5d 89e6 fc ad }
+ $sequence_3 = { 89e5 5d 89e6 fc ad 6804010000 56 }
+ $sequence_4 = { 59 ffe7 6800400000 6a00 57 68???????? }
+ $sequence_5 = { cd03 cd02 68???????? 87d1 87ca 51 }
+ $sequence_6 = { 59 59 ffe7 6800400000 6a00 }
+ $sequence_7 = { 6804010000 56 50 68???????? 87d1 }
+ $sequence_8 = { 59 59 ff25???????? 55 }
+ $sequence_9 = { 5d b986180000 55 89e5 5d be???????? }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Cerbu_Miner_Auto : FILE
+rule MALPEDIA_Win_Soraya_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "77652d6a-745f-5552-8901-83bf555706f4"
+ id = "17c03046-2ad1-5623-9130-def458833386"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cerbu_miner"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cerbu_miner_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.soraya"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.soraya_auto.yar#L1-L230"
license_url = "N/A"
- logic_hash = "e4927a587588bc11053fcbade5bb9500364c9a656d383eb318cc8486464f3cce"
+ logic_hash = "43793169adfc64c624ebc876524a7869403686546a466d508c127ca9f78faaa7"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -153839,32 +160994,45 @@ rule MALPEDIA_Win_Cerbu_Miner_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 88b42480000000 eb3f 83e902 7433 83e904 7413 83e909 }
- $sequence_1 = { 7412 48 8d0d0b360500 48 83c428 48 ff25???????? }
- $sequence_2 = { 8d4601 c643012e 48 63c8 41 8d4602 48 }
- $sequence_3 = { 85d2 7427 85c9 b800040000 41 b800080000 44 }
- $sequence_4 = { f6473801 7402 eb18 48 8bcf ff15???????? f6473801 }
- $sequence_5 = { e9???????? 45 8bfd 44 89ad50010000 e9???????? 44 }
- $sequence_6 = { 48 89442420 e8???????? 48 8bd7 48 8bcb }
- $sequence_7 = { 89b42418010000 8b74242c 83feff 7515 837f0c00 7c0f 48 }
- $sequence_8 = { 8d057b52f9ff 48 894518 c745b0e6070000 48 c745c000000200 48 }
- $sequence_9 = { 44 2bc0 44 8903 33c0 48 8b5c2438 }
+ $sequence_0 = { ff15???????? 8d48bf 80f919 77f2 }
+ $sequence_1 = { e8???????? 488d151af0ffff 488d8d60020000 ff15???????? e8???????? 488d8d60020000 488bd0 }
+ $sequence_2 = { 57 8bd8 56 53 e8???????? 8b733c }
+ $sequence_3 = { 33c1 99 b99a000000 f7f9 b8fe340000 }
+ $sequence_4 = { 488bd0 4c8b4850 498bcb 41b86b000000 }
+ $sequence_5 = { 41b800300000 ff15???????? 488b8d50010000 4c8d8d48010000 488bd8 488d8540010000 488d1565f4ffff }
+ $sequence_6 = { 8b4c2414 33c6 33ce 03c1 }
+ $sequence_7 = { 418bd6 3bcb 72c8 4c891d???????? 488d0d1fe0ffff }
+ $sequence_8 = { 894df4 0f8501010000 53 56 8b7178 }
+ $sequence_9 = { 8b4a0c 8b7210 03c8 8365fc00 8b55fc ff45fc }
+ $sequence_10 = { 488d0dfadfffff ff15???????? 488bc8 e8???????? 488d0df5dfffff ff15???????? 488d15f8dfffff }
+ $sequence_11 = { 689b558d52 6853d56c36 68ff555535 68f9d6feff 6888888868 }
+ $sequence_12 = { 8b45ec 2bf8 037d10 8b45e8 }
+ $sequence_13 = { 2bd0 894de0 3bd1 7649 8b55f8 33d6 }
+ $sequence_14 = { 03570c 034f0c 807df800 8a540203 8a4c0102 8855fb }
+ $sequence_15 = { 8b3d???????? 6a1c 8d45e0 50 6a00 }
+ $sequence_16 = { 7444 53 4883ec30 488bd9 b910270000 ff15???????? 8364242800 }
+ $sequence_17 = { 488d0d73f8ffff 498bd8 488bfa ff15???????? }
+ $sequence_18 = { 56 57 8d85fcfdffff 6800020000 50 e8???????? }
+ $sequence_19 = { ff45dc 295de0 4e 75e8 b844060000 0345c8 }
+ $sequence_20 = { 7424 56 6a00 683a040000 ff15???????? 8bf0 85f6 }
+ $sequence_21 = { 8dbc07fe3ef2ff 8b45d8 33c6 3bbc05be3ef2ff 0f82bdfdffff }
+ $sequence_22 = { 8b45fc 8b4dec 8b4508 8b9578ffffff 8b80d8010000 33d3 }
condition:
- 7 of them and filesize <1040384
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Erebus_Auto : FILE
+rule MALPEDIA_Win_Regretlocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3b8e48a2-ab39-5161-a03c-847ada2f2257"
+ id = "e84161b8-423e-557e-8de0-b1e67c3c2a4c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.erebus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.erebus_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.regretlocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.regretlocker_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "f6199452e86aabb91b90d01b525d7eacea470d9b218c6e5261dcc5c5c7e57399"
+ logic_hash = "54bb2aadd5c37dd020832b423319961afea1e93662e9effb9e0b762d9355990d"
score = 75
quality = 75
tags = "FILE"
@@ -153878,32 +161046,32 @@ rule MALPEDIA_Win_Erebus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4c243c 50 c744245000000000 e8???????? 8d742434 bb01000000 eb53 }
- $sequence_1 = { ff15???????? 8b4514 8918 8bc7 5f 5b 8be5 }
- $sequence_2 = { 8d45f0 50 8b8540ffffff 8d8d40ffffff 8b4004 03c8 e8???????? }
- $sequence_3 = { ff4718 40 ff7718 25ffff0000 50 68???????? 56 }
- $sequence_4 = { 8d0c2a 894f18 740a 8b4704 034708 3bc8 7506 }
- $sequence_5 = { 8d4c2418 e8???????? 50 b9???????? c64424302e e8???????? c705????????24215000 }
- $sequence_6 = { 50 57 53 e8???????? 83c418 8b8c2424020000 64890d00000000 }
- $sequence_7 = { c74704ffffffff c74710ffffffff c74714ffffffff 8b0f 8b4704 83f9ff 7504 }
- $sequence_8 = { 8bd0 c645fc1e 8d8d18ffffff e8???????? 8bf0 83c404 81fe???????? }
- $sequence_9 = { 2b4718 034708 8b5710 0faf570c 3903 89442410 8d442414 }
+ $sequence_0 = { 8945e0 3bd8 742a 83ec18 8bcc 53 }
+ $sequence_1 = { 8d8568ffffff 50 e8???????? 83ec10 c645fc04 8bcc 6a06 }
+ $sequence_2 = { e8???????? 6aff 8bcb e8???????? 8d8df4feffff e8???????? 8d8d78ffffff }
+ $sequence_3 = { 8d4510 50 8d8578fdffff 50 8d45ec 50 e8???????? }
+ $sequence_4 = { 2b45fc 6a18 59 99 f7f9 ff750c 6bc018 }
+ $sequence_5 = { 3bf0 59 59 0f95c0 5f 5e }
+ $sequence_6 = { 50 f2c3 55 8bec 8b4508 56 }
+ $sequence_7 = { 83ec18 8bcc 57 e8???????? e8???????? 83c418 8d4dbc }
+ $sequence_8 = { 50 57 ff15???????? 85c0 0f8529ffffff 57 ff15???????? }
+ $sequence_9 = { 64890d00000000 5b c9 c21800 8b411c 8b10 85d2 }
condition:
- 7 of them and filesize <2564096
+ 7 of them and filesize <1021952
}
-rule MALPEDIA_Win_Floki_Bot_Auto : FILE
+rule MALPEDIA_Win_Udpos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1cde0271-e319-5f49-b7d9-6126f8e6a662"
+ id = "49a8c6d9-3919-52d8-b9a1-bc6d433f2d9f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.floki_bot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.floki_bot_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.udpos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.udpos_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "de31350a6a6eca83bc8efd1fc6e07ad972095e30f5b6c290e1bfd7b68f7ea01f"
+ logic_hash = "ffccd56d9879c5a40153befe0b99e30b88fecb63ad13af5b9ec71c40ee069e0c"
score = 75
quality = 75
tags = "FILE"
@@ -153917,32 +161085,32 @@ rule MALPEDIA_Win_Floki_Bot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff7508 e8???????? 83f8ff 7511 ff7518 ff7514 53 }
- $sequence_1 = { 68???????? 53 89460c e8???????? 85c0 }
- $sequence_2 = { c3 e8???????? 84c0 742c 56 ff15???????? 8bf0 }
- $sequence_3 = { 53 e8???????? eb5e 8d45f4 99 8945b4 8b4508 }
- $sequence_4 = { 83f840 7205 83c8ff eb63 56 6a04 8985fcfeffff }
- $sequence_5 = { 3bd1 72f3 eb05 83faff 7527 8d7101 }
- $sequence_6 = { e8???????? 83ffff 0f8472ffffff 3bfb 7404 c645fb00 8a45fb }
- $sequence_7 = { 3b4e48 7612 ff7004 6a03 ff7644 51 ff10 }
- $sequence_8 = { 56 6800040000 ff15???????? 8bf8 3bfe 0f8483000000 8d45e8 }
- $sequence_9 = { 8bf7 e8???????? 8b7d0c 8b5d14 837d1000 742e 33c0 }
+ $sequence_0 = { 8bc8 23cf 0bf1 8b4dfc 03d6 0353fc 8bf0 }
+ $sequence_1 = { 8b4dfc 83c404 5f 8bc3 33cd }
+ $sequence_2 = { 52 e8???????? 83c418 833d????????00 0f8596000000 8d85ccf3ffff 50 }
+ $sequence_3 = { 8888f8e84000 40 ebe6 ff35???????? ff15???????? 85c0 7513 }
+ $sequence_4 = { 7e1e 8d575c 85f6 7517 6639944dfcfdffff 7508 be01000000 }
+ $sequence_5 = { 51 e8???????? a1???????? 8b3d???????? 83c418 }
+ $sequence_6 = { 7e0d 83f809 7e08 a1???????? 8b7024 56 8d4d9c }
+ $sequence_7 = { e8???????? 68f4010000 6a00 8d8dc8fcffff 51 e9???????? }
+ $sequence_8 = { ffd6 8d953cffffff 52 8d85e0f8ffff 50 ffd6 }
+ $sequence_9 = { 40 3bc3 7cef 8b85a0feffff 50 e8???????? }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <163840
}
-rule MALPEDIA_Win_Sneepy_Auto : FILE
+rule MALPEDIA_Win_W32Times_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "92a9a098-af3e-565a-a77d-ae1e4fe61438"
+ id = "0bfdc72d-d05e-5c1b-8705-7d1b1a1a85f1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sneepy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sneepy_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.w32times"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.w32times_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "0102a60e328cb3b8b2c7928ec4f988725df8b07a3b2131190567958f6bfcc033"
+ logic_hash = "09784a57b734a06db72c3b3952721b8e38cad13da9a478a5c4cffbebd654009b"
score = 75
quality = 75
tags = "FILE"
@@ -153956,34 +161124,34 @@ rule MALPEDIA_Win_Sneepy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83c40c 33c0 8a8810234100 }
- $sequence_1 = { 83f8ff 0f85abfeffff 5f 5e }
- $sequence_2 = { 8945e4 8845e8 e8???????? 8d55e4 83c404 2bd0 8a08 }
- $sequence_3 = { ffd6 85c0 740d 8b85b8feffff 50 ffd6 }
- $sequence_4 = { e8???????? 83c40c 32c0 5e 8b4dfc }
- $sequence_5 = { 68???????? 8945f4 8845f8 e8???????? 8d55f4 83c404 }
- $sequence_6 = { ff15???????? 8bc8 8a10 40 }
- $sequence_7 = { 33c0 8b4d08 3b0cc520de4000 740a 40 83f816 72ee }
- $sequence_8 = { 668b0d???????? 8a15???????? 668908 6a50 }
- $sequence_9 = { 33c0 8945e4 83f805 7d10 668b4c4310 66890c4514314100 }
+ $sequence_0 = { e8???????? 85c0 0f8487030000 6a01 68???????? }
+ $sequence_1 = { 83e103 f3a4 8b35???????? 8d8c24f0020000 68???????? 51 ffd6 }
+ $sequence_2 = { 83c408 68???????? ff15???????? 85c0 0f85c6060000 ff15???????? }
+ $sequence_3 = { ff15???????? 68???????? ff15???????? 396c2418 7410 6a01 }
+ $sequence_4 = { 3b9c24000d0000 0f84cc090000 8a8424f0020000 84c0 0f84bd090000 8a8424e8000000 84c0 }
+ $sequence_5 = { 8bfd 83c9ff 33c0 8d9424ec010000 f2ae f7d1 2bf9 }
+ $sequence_6 = { 8b15???????? 52 ffd3 892d???????? a1???????? 3bc5 7416 }
+ $sequence_7 = { f3a5 8bcd 8d9424f4030000 83e103 f3a4 8dbc24f4040000 }
+ $sequence_8 = { 683f000f00 6a00 56 ff15???????? 8bf8 }
+ $sequence_9 = { 83c40c 85c0 0f85e00c0000 8b4b04 6a04 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <122880
}
-rule MALPEDIA_Win_Duqu_Auto : FILE
+rule MALPEDIA_Win_Conti_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4f983d2e-8e54-5fa3-99e8-f35467f58ba0"
+ id = "aae9ecae-21cf-5ec8-8511-8157ca36f115"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.duqu"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.duqu_auto.yar#L1-L157"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.conti"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.conti_auto.yar#L1-L225"
license_url = "N/A"
- logic_hash = "c9f95c9fbccbdcbcab2eb713244b96d59984c1db33c0129682f88201221bf820"
+ logic_hash = "0be9a10d7e2a11f01ccc516eb831064a902454185cea8a72f6170734199b0c59"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -153995,38 +161163,46 @@ rule MALPEDIA_Win_Duqu_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bcb e8???????? bacdc185ad 89464c }
- $sequence_1 = { 85f6 7eb3 b8c64ff867 8bde 8bd7 89442420 }
- $sequence_2 = { 8b5c2414 85db 0f8402ffffff 46 }
- $sequence_3 = { 85c0 0f848b020000 ba10ee27d3 8bcf e8???????? 894624 85c0 }
- $sequence_4 = { 0f84f7000000 0fb706 b9ab4f5ecd 33c1 }
- $sequence_5 = { 56 51 8bf2 e8???????? }
- $sequence_6 = { 83c120 0fb7c9 8bc1 0fafc9 83e007 }
- $sequence_7 = { 85c0 7465 e8???????? 85c0 }
- $sequence_8 = { 55 8bec 81ec08020000 56 8bf2 8d95f8fdffff }
- $sequence_9 = { 8bcb e8???????? bafa67937e 894648 8bcf }
- $sequence_10 = { 8bf2 57 8d8e14020000 e8???????? }
- $sequence_11 = { 8bf2 57 8d4e4c e8???????? }
- $sequence_12 = { 8bf2 8bf9 ff15???????? 56 }
- $sequence_13 = { 8bf2 57 8d8ecc000000 e8???????? }
- $sequence_14 = { 8bf2 57 8d8e0c020000 e8???????? }
- $sequence_15 = { 8bf2 57 8bf9 85f6 7425 66833e00 }
+ $sequence_0 = { 56 57 bf0e000000 8d7101 }
+ $sequence_1 = { 8d7f01 0fb6c0 b978000000 2bc8 }
+ $sequence_2 = { 57 bf0a000000 8d7101 8d5f75 8a06 8d7601 0fb6c0 }
+ $sequence_3 = { 8d7f01 0fb6c0 b96c000000 2bc8 }
+ $sequence_4 = { 0f1f4000 8a07 8d7f01 0fb6c0 b948000000 }
+ $sequence_5 = { 8975fc 803e00 7541 53 bb0a000000 }
+ $sequence_6 = { 8975fc 803e00 7542 53 bb0e000000 }
+ $sequence_7 = { 8d7f01 0fb6c0 b909000000 2bc8 }
+ $sequence_8 = { e8???????? 8bb6007d0000 85f6 75ef 6aff }
+ $sequence_9 = { 50 6a20 ff15???????? 68???????? ff15???????? 68???????? }
+ $sequence_10 = { 780e 7f07 3d00005000 7605 }
+ $sequence_11 = { 8bec 8b4d08 e8???????? 6a00 ff15???????? }
+ $sequence_12 = { 50 8b4508 ff7004 ff15???????? 85c0 7508 6a01 }
+ $sequence_13 = { 6810660000 ff7508 ff15???????? 85c0 }
+ $sequence_14 = { 85ff 7408 57 56 ff15???????? ff75f8 56 }
+ $sequence_15 = { 7411 a801 740d 83f001 50 ff7608 }
+ $sequence_16 = { 48894c2430 4c8d45ff 488d4d0f 418bd6 48894c2428 488d4d07 48894c2420 }
+ $sequence_17 = { 42884c0500 49ffc0 4983f80d 72af 44884d0f }
+ $sequence_18 = { 33d2 ffd0 897c2450 b856555555 }
+ $sequence_19 = { 0fb64500 0fb645ff 84c0 755c }
+ $sequence_20 = { 488b4f30 488b4738 4885c9 7406 }
+ $sequence_21 = { 48894c2448 488d55e0 488d4c2470 4533c0 }
+ $sequence_22 = { 42884c0501 49ffc0 4983f80c 72af }
+ $sequence_23 = { 41b801000000 488bd3 8bcf ffd0 4d85f6 }
condition:
- 7 of them and filesize <18759680
+ 7 of them and filesize <520192
}
-rule MALPEDIA_Win_Darkside_Auto : FILE
+rule MALPEDIA_Win_Nemim_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4e98e522-42dc-58c9-8c11-9325d3b56f3a"
+ id = "7264494b-d73b-5298-a829-f60e4932364f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkside"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkside_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nemim"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nemim_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "e40a0efe65c9a50695ac0381c3b73c18492ef0b0fce9893dbb25777c239f867f"
+ logic_hash = "0e5cb332d550079bcd770b6c5ca18dad9c60646bca1f9092ed4ed3564e5ea600"
score = 75
quality = 75
tags = "FILE"
@@ -154040,32 +161216,32 @@ rule MALPEDIA_Win_Darkside_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bd8 68ff000000 57 e8???????? 81c7ff000000 }
- $sequence_1 = { 85d2 7407 52 57 }
- $sequence_2 = { b9ff000000 33d2 f7f1 85c0 7418 }
- $sequence_3 = { 57 e8???????? 81c7ff000000 4b }
- $sequence_4 = { fec1 75d2 5f 5e 5a 59 5b }
- $sequence_5 = { 56 57 b9f0000000 be???????? }
- $sequence_6 = { 8b7d08 8b450c b9ff000000 33d2 f7f1 }
- $sequence_7 = { 56 57 b9f0000000 be???????? 8b4508 }
- $sequence_8 = { e8???????? 5f 5e 5a 59 5b 5d }
- $sequence_9 = { 81ea10101010 2d10101010 81eb10101010 81ef10101010 }
+ $sequence_0 = { a1???????? c1e002 89b48050744300 8b0d???????? 893d???????? 890d???????? }
+ $sequence_1 = { eb3b a1???????? 68???????? 50 e8???????? 83c408 }
+ $sequence_2 = { 5e 5b c9 c20400 8bc1 c700???????? c3 }
+ $sequence_3 = { 5e 5d b801000000 5b 81c4bc000000 c3 }
+ $sequence_4 = { 8d44240c 55 50 56 c744241828010000 e8???????? 85c0 }
+ $sequence_5 = { 51 e8???????? 8dbc24600a0000 83c9ff 33c0 }
+ $sequence_6 = { 8b16 c1ea08 885001 8b0e c1e910 }
+ $sequence_7 = { 52 e8???????? 8b4c2440 8944244c b801000000 }
+ $sequence_8 = { 83fe10 7cde c605????????00 b90b000000 be???????? 8dbc2410010000 }
+ $sequence_9 = { 8844244c e8???????? 68???????? e8???????? 68???????? 8bf0 }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <499712
}
-rule MALPEDIA_Win_Kpot_Stealer_Auto : FILE
+rule MALPEDIA_Win_Mars_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e45631fb-3fb5-58e0-9b9b-6b34d42ff6ce"
+ id = "d22235ef-5968-5e10-be47-3cfb22c5f1b3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kpot_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kpot_stealer_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mars_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mars_stealer_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "16f05178ea617d4330175d94df8b79c29f673ce62148ecbf2153af87111da7a0"
+ logic_hash = "b25b9578c7efb2902b746c00b6410a6cd2ad1c64e90ea264af3674a130d6b800"
score = 75
quality = 75
tags = "FILE"
@@ -154079,32 +161255,32 @@ rule MALPEDIA_Win_Kpot_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 03c6 50 ff75f4 e8???????? 59 59 8d4df8 }
- $sequence_1 = { 0bce 8bc1 c1e804 33c2 250f0f0f0f 33d0 }
- $sequence_2 = { 55 8bec ff7508 ff15???????? 83f8ff 7409 a8a7 }
- $sequence_3 = { 8b4604 8b5df4 03d2 8d445802 e8???????? }
- $sequence_4 = { 85c0 7427 8b45f8 03c6 50 }
- $sequence_5 = { 57 8bf8 8b4518 0fb67005 }
- $sequence_6 = { 8b45f4 c1e918 884b07 8945fc 8b45f0 83c308 ff4dec }
- $sequence_7 = { 5e 5b c9 c3 0fb70f 6685c9 7440 }
- $sequence_8 = { a8a7 7405 33c0 40 5d }
- $sequence_9 = { 8bc1 c1e810 884306 8b45f4 }
+ $sequence_0 = { 33049508674100 894508 8b4d0c 83c101 894d0c 8b550c }
+ $sequence_1 = { 8b5118 52 8b853cfbffff 8b4814 }
+ $sequence_2 = { 898564e6ffff 83bd64e6ffff00 0f8405030000 6a00 }
+ $sequence_3 = { a1???????? 50 8b4d08 51 e8???????? 83c410 6a04 }
+ $sequence_4 = { 8b5508 c1ea08 33148d08674100 895508 8b450c }
+ $sequence_5 = { 52 8d85e8feffff 50 68???????? 8b4df8 51 }
+ $sequence_6 = { 837df820 0f8d61030000 6804010000 8d8de8feffff 51 e8???????? }
+ $sequence_7 = { 2b4d08 c681407c410000 8b550c 8955f8 }
+ $sequence_8 = { 8b953cfbffff 8b4214 83c020 50 6a00 }
+ $sequence_9 = { 52 8b85fcfbffff 50 ff15???????? 89857cdeffff }
condition:
7 of them and filesize <219136
}
-rule MALPEDIA_Win_Turla_Rpc_Auto : FILE
+rule MALPEDIA_Win_Quickheal_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d062a0c9-c6c6-5f57-a60f-6c6b55d2f616"
+ id = "1144a28c-6891-50e3-aab7-fbd2738d1ce6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.turla_rpc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.turla_rpc_auto.yar#L1-L171"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.quickheal"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.quickheal_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "696b632d482c9df6571dae61d7a8f9238e184ca30e0aa7fbb216cfbf4128270e"
+ logic_hash = "c8252dc1fbd623ed33de5c38485302af864b4c120786c74e672f39f82eb29422"
score = 75
quality = 75
tags = "FILE"
@@ -154118,38 +161294,32 @@ rule MALPEDIA_Win_Turla_Rpc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c645bc55 c7854001000030163930 c78544010000343b2025 c6854801000055 c78560010000013c3830 c785640100003a202155 }
- $sequence_1 = { c744244806393030 66c744244c2555 c785c000000006302110 c785c400000027273a27 c785c8000000183a3130 c685cc00000055 }
- $sequence_2 = { c7456016273034 c745642130133c c7456839300255 c7851001000016273034 c7851401000021300527 c785180100003a363026 }
- $sequence_3 = { c745b06970746f c745b472536163 66c745b86c00 ff15???????? }
- $sequence_4 = { c7850401000030102d36 c785080100003025213c 66c7850c0100003a3b c6850e01000055 c745c007303431 }
- $sequence_5 = { 488bd8 ffd3 488d4d70 488bf8 ffd3 }
- $sequence_6 = { c6458e55 c744245033273034 66c74424543155 c744243033273030 c644243455 c744244033263030 66c74424443e55 }
- $sequence_7 = { c6852e01000055 c745b0193a3431 c745b4193c3727 c745b834272c14 c645bc55 c7854001000030163930 c78544010000343b2025 }
- $sequence_8 = { c7851401000021300527 c785180100003a363026 66c7851c0100002602 c6851e01000055 }
- $sequence_9 = { c7854cffffff00000000 c78548ffffff00000000 c78554ffffff00000000 c78550ffffff00000000 c745bc53003a00 c745c028004d00 c745c44c003b00 }
- $sequence_10 = { 56 ffd3 8987d8000000 8d87dc000000 }
- $sequence_11 = { 68???????? ff15???????? 8b4dfc 33c0 5f 5e }
- $sequence_12 = { 8bf8 85ff 7514 8d45ac 50 ff15???????? }
- $sequence_13 = { 57 ff15???????? 8b85b8fdffff ffb5bcfdffff a3???????? }
- $sequence_14 = { 68???????? e8???????? 6a03 68???????? 8d0c45ac880110 8bc1 }
- $sequence_15 = { 8d45c8 50 ffd6 8bf8 8d8558ffffff }
+ $sequence_0 = { 7ce2 b814010000 8a8c28f8feffff 888c0484000000 40 3d30010000 72ea }
+ $sequence_1 = { 3bf3 0f840b030000 8d4e02 8d542424 51 }
+ $sequence_2 = { ff15???????? 8d542410 8d8424fc060000 52 6819000200 53 }
+ $sequence_3 = { 49 51 6a06 52 ffd5 83c408 }
+ $sequence_4 = { 2bce 51 56 50 56 e8???????? 83c410 }
+ $sequence_5 = { 8d445d0c 83c408 33f6 6683f93b }
+ $sequence_6 = { 83c102 3bc6 7cf0 5f }
+ $sequence_7 = { 7207 885101 04fc eb04 c6410100 3c02 7209 }
+ $sequence_8 = { f7d1 49 8dbc2414010000 8bd1 83c9ff f2ae a1???????? }
+ $sequence_9 = { 52 ffd7 85c0 7418 8b442410 c744241404010000 50 }
condition:
- 7 of them and filesize <311296
+ 7 of them and filesize <553984
}
-rule MALPEDIA_Win_Doorme_Auto : FILE
+rule MALPEDIA_Win_Trochilus_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "86390d1e-5c43-5440-9d47-06677f2da02f"
+ id = "59484933-96f5-5392-a130-d1897de1bd22"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doorme"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doorme_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.trochilus_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.trochilus_rat_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "36db3801adbf1063a2540e3d2f2d2feff6537948c8fe3ef7123221f42e10e308"
+ logic_hash = "e651983c70589c057f0ef7e60f3a8876ce52f4e099a0b1c41a830840b75beb3c"
score = 75
quality = 75
tags = "FILE"
@@ -154163,32 +161333,32 @@ rule MALPEDIA_Win_Doorme_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 48837e1810 7203 488b16 4c8b4610 488d4d58 e8???????? 488d5558 }
- $sequence_1 = { 75f6 488bd7 488d4d68 e8???????? 90 4c8d8d10010000 }
- $sequence_2 = { 41b111 41b207 450fb6da b312 0fb6f9 40b618 4533e4 }
- $sequence_3 = { 488b05???????? 4833c4 48894537 488bda 488bf9 4889552f c6459700 }
- $sequence_4 = { 498b7810 4885ff 7566 48897a10 }
- $sequence_5 = { 488d5c2478 48837d9010 480f435c2478 488d05a23f0300 488945a0 c74424400e000000 }
- $sequence_6 = { 488b00 498bcd ff5020 48894580 498b4500 498bcd ff5018 }
- $sequence_7 = { 75f1 4983e801 75db 4883c510 4c8d15f06b0300 48836c243001 0f8564feffff }
- $sequence_8 = { 488d8d20030000 e8???????? 488b7d80 488b07 488bcf ff5050 }
- $sequence_9 = { 4889442440 448bc2 48894c2420 488bd9 }
+ $sequence_0 = { 0fb74636 50 ffd7 0fb7c8 668bd1 662b935e010100 }
+ $sequence_1 = { 6a32 56 53 e8???????? }
+ $sequence_2 = { 50 ffd3 668b8e52010100 662bc8 6683f903 0f8c9e000000 81863001010018fcffff }
+ $sequence_3 = { 56 8bf1 8d5e04 8bcb e8???????? 83f8ff 7407 }
+ $sequence_4 = { 8d4de4 51 50 ff7538 ff7534 }
+ $sequence_5 = { 5e 5d c20c00 55 8bec 837d08ff 56 }
+ $sequence_6 = { 68???????? 50 ff15???????? 85c0 7404 33c0 eb1a }
+ $sequence_7 = { ff15???????? 33c0 eb81 55 8bec 51 53 }
+ $sequence_8 = { 33db 391f 7e1d 8b4704 8b4c0304 68a01e0110 e8???????? }
+ $sequence_9 = { b8fac50010 e8???????? 8bf1 837d0800 7505 8b06 ff505c }
condition:
- 7 of them and filesize <580608
+ 7 of them and filesize <630784
}
-rule MALPEDIA_Win_Darkmoon_Auto : FILE
+rule MALPEDIA_Win_Bohmini_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c7bc3212-028b-5215-8293-c0df2749aba3"
+ id = "c674d076-0d8a-5cd0-a61f-b74753074ae4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkmoon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkmoon_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bohmini"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bohmini_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "5987f0c1a065561468c6153b43a5b63a22d14e5454b4b93cd49fdb8fd5a12783"
+ logic_hash = "924ffc111e8f5edb5600c44b643235932f72ba9b2a992fa2571ad4dc6b3c6eb8"
score = 75
quality = 75
tags = "FILE"
@@ -154202,32 +161372,32 @@ rule MALPEDIA_Win_Darkmoon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c745e435000000 e8???????? 83c418 85c0 }
- $sequence_1 = { 7432 8d55e4 8d45e8 52 8d4dec 50 8d95e4fdffff }
- $sequence_2 = { 8dbe48010000 6800f00000 8bcf e8???????? 6800f00000 8bce }
- $sequence_3 = { 7314 ff7510 ff750c ff7508 }
- $sequence_4 = { c645fc03 e8???????? 8d4f08 c645fc04 e8???????? }
- $sequence_5 = { c645fc07 e8???????? eb02 33ff 57 c645fc01 }
- $sequence_6 = { 83ec10 33c9 8bdc 33d2 8dbe48010000 }
- $sequence_7 = { 8d860f040000 8945cc eb12 8d86130d0000 }
- $sequence_8 = { 837df020 750e 8dbdfcfdffff c60720 }
- $sequence_9 = { 50 837df400 740d 6800800000 6a00 ff75f4 ff5625 }
+ $sequence_0 = { 896c2410 896c2414 0f86c5000000 8b7c2420 }
+ $sequence_1 = { 6a00 6a00 8bca 83c11a 51 6a00 6a00 }
+ $sequence_2 = { 8d542414 6a00 52 ff15???????? 85c0 }
+ $sequence_3 = { ff15???????? 3bc3 a3???????? 7512 5f 5e }
+ $sequence_4 = { 6800040000 50 53 ff15???????? 50 ff15???????? }
+ $sequence_5 = { 4a 741a 4a 7543 e8???????? 03c6 33d2 }
+ $sequence_6 = { 83c410 85c0 7507 6891130000 eb2a }
+ $sequence_7 = { 8b5608 52 ffd5 40 50 }
+ $sequence_8 = { 52 e8???????? 40 50 8d8424b8010000 50 }
+ $sequence_9 = { 8b2d???????? 8b3e 51 6a00 ffd5 50 ffd3 }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <139264
}
-rule MALPEDIA_Win_Ransomexx_Auto : FILE
+rule MALPEDIA_Win_Rc2Fm_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f239143d-e5d1-5c3c-aec9-a76464ab403c"
+ id = "e4f1d324-0720-53a3-a9da-cb15ebd44ad4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ransomexx"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ransomexx_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rc2fm"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rc2fm_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "3b39ad6bc64b52ed616287d6ece517d9776b1298e49d7060ccab50a0c57b68b4"
+ logic_hash = "2b4b23efded831a0bcad4decee49c98aca63a9f5af170fcd017bff9b432b8451"
score = 75
quality = 75
tags = "FILE"
@@ -154241,32 +161411,32 @@ rule MALPEDIA_Win_Ransomexx_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bc3 8d75e0 e8???????? 8bf0 85f6 0f85f8020000 eb07 }
- $sequence_1 = { 6884010000 6a08 c745fc04010000 ffd7 50 ff15???????? 8bf0 }
- $sequence_2 = { 8b4f08 3bce 7425 8b4704 03c0 03c0 }
- $sequence_3 = { 8bf8 85ff 752c 8d55f8 c70601000000 6a02 }
- $sequence_4 = { c1ee0a 33fe 8bf7 8b7dfc 039c3da4feffff 03f3 }
- $sequence_5 = { c1ee03 33fe 03df 8b7dfc 039c3db8feffff 8bb43d94feffff 03f3 }
- $sequence_6 = { 837df801 0f8612010000 8b4df8 8b5f04 49 b801000000 d3e0 }
- $sequence_7 = { 8b55f0 8b4508 8d4dd0 51 52 57 50 }
- $sequence_8 = { 56 50 e8???????? 8b07 83c40c 8975fc }
- $sequence_9 = { 39742420 0f862e010000 8d642400 837c242001 7540 837c242400 7539 }
+ $sequence_0 = { 48894c2408 55 57 4154 4156 488d6c24c1 4881ecb8000000 }
+ $sequence_1 = { 4883ec20 498bf1 4d8bf0 4c8bfa 488bd9 ff15???????? }
+ $sequence_2 = { 415c 5f 5b c3 488b09 4889ac2480000000 }
+ $sequence_3 = { b001 eb14 448bc3 ba00000500 b91b000100 e8???????? }
+ $sequence_4 = { 488b4808 4c897d00 4c89742460 48894df8 8d4e14 e8???????? 6690 }
+ $sequence_5 = { 448bc0 e8???????? eb0f ba0a000b00 b911000100 e8???????? 488b0d???????? }
+ $sequence_6 = { 0fb68c28304c0200 eb0c 48c1e807 0fb68c28304d0200 4863c1 448bd7 66ff8483b0090000 }
+ $sequence_7 = { 88040a ff4328 8b5328 0fb64745 488b4b10 88040a ff4328 }
+ $sequence_8 = { 83b98804000000 488bd9 7431 ff8b88040000 8b8388040000 4c8b84c360040000 4d85c0 }
+ $sequence_9 = { 0f8781010000 83fd09 0f8778010000 448b642478 4183fc04 0f8769010000 488b4938 }
condition:
- 7 of them and filesize <372736
+ 7 of them and filesize <410624
}
-rule MALPEDIA_Win_Dnespy_Auto : FILE
+rule MALPEDIA_Win_Liteduke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "70dfc3a2-0802-5571-8c6e-dca5ba3f52dd"
+ id = "c89a689f-3dfd-5d2a-aec1-28f7aca47554"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dnespy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dnespy_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.liteduke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.liteduke_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "5f9d7d06b9dad4ee82945ca7222951c2d8150747511ca4dc6b623794062c6006"
+ logic_hash = "5d6b62682cd8e4bed5eedc1b6f48e136bed91567c9f36c00bf40e1cbea238867"
score = 75
quality = 75
tags = "FILE"
@@ -154280,32 +161450,32 @@ rule MALPEDIA_Win_Dnespy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83ec18 8d4508 8bcc 50 e8???????? ba01000000 8d4dc8 }
- $sequence_1 = { f30f7e4594 8b459c 660fd645a4 8945ac 7209 8b0e 8bc1 }
- $sequence_2 = { 8bf1 8954240c 57 8b7d08 89442414 837e4c00 7471 }
- $sequence_3 = { 74e7 83f80d 74e2 40 83f87e 0f878b010000 }
- $sequence_4 = { 6a50 668945e8 ff15???????? 668945ea 8d45e8 6a10 }
- $sequence_5 = { 0f84f0000000 8bc8 e8???????? 8bd0 c745e000000000 8bca c745e40f000000 }
- $sequence_6 = { 6a00 6a00 8d85e0cfffff 50 6a00 ff15???????? ffb5a0cfffff }
- $sequence_7 = { 8a18 3a19 750a 40 41 3bc2 75f0 }
- $sequence_8 = { 744b 8d45f4 c745f000000000 50 8d45f8 c745f800000000 50 }
- $sequence_9 = { c685ebfeffff00 c685ecfeffff0f c685edfeffff0a c685eefeffff03 8a85dcfeffff c685effeffff00 0f1f440000 }
+ $sequence_0 = { ff7508 ff15???????? ff75fc ff15???????? 5b 5e }
+ $sequence_1 = { 6800010000 ff15???????? c3 68???????? ff15???????? }
+ $sequence_2 = { 5b 5e 5f 8b45d8 c9 c20400 55 }
+ $sequence_3 = { 41 83f904 7cdd 5f 5e }
+ $sequence_4 = { c9 c20800 55 89e5 ff7508 e8???????? }
+ $sequence_5 = { c20c00 c70101000000 61 c9 c20c00 c70100000000 61 }
+ $sequence_6 = { c1c006 243f 3c3e 7205 c0e002 2c0e 2c04 }
+ $sequence_7 = { 46 8a06 8807 46 43 41 42 }
+ $sequence_8 = { b800000000 8a03 c1e804 83f809 7f05 83c030 eb03 }
+ $sequence_9 = { 56 e8???????? 83c40c ff750c 56 e8???????? 83c408 }
condition:
- 7 of them and filesize <794624
+ 7 of them and filesize <1171456
}
-rule MALPEDIA_Win_Bookcodesrat_Auto : FILE
+rule MALPEDIA_Win_Slave_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "12c3f4c8-ae45-5c42-aff9-36df89db636e"
+ id = "2db01cdc-36fb-5960-a7bc-78a56f81c6bb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bookcodesrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bookcodesrat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.slave"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.slave_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "4448935151876512796b7de65b4c6301493ba2a3fb6e7bb9bd7b534c17d01712"
+ logic_hash = "b1287622c49df3c1a2838a3a773babcdc61506504422851d523ef94f6f257153"
score = 75
quality = 75
tags = "FILE"
@@ -154319,32 +161489,32 @@ rule MALPEDIA_Win_Bookcodesrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 488d0d97900100 ff15???????? 833d????????00 750a b901000000 e8???????? }
- $sequence_1 = { 33c0 48c7471807000000 48894710 668907 4883c728 493bfe 75d7 }
- $sequence_2 = { 488b5c2430 488b742438 4883c420 5f c3 482bf3 66660f1f840000000000 }
- $sequence_3 = { 4883c9ff 33c0 488dbb40080000 66f2af 48f7d1 48ffc9 74e8 }
- $sequence_4 = { 0f858a000000 ba04010000 488bce ffd7 85c0 744e 33c0 }
- $sequence_5 = { 0f1f440000 ffc6 4c8b4310 4883c8ff 492bc0 4883f801 0f868a000000 }
- $sequence_6 = { 75ee 488d8d50010000 33d2 41b808020000 e8???????? 488b4c2438 488d442430 }
- $sequence_7 = { 488d4c2420 ba04010000 ff15???????? 33c0 4883c9ff 488d7c2420 66f2af }
- $sequence_8 = { ff15???????? 418985a8010000 32db 48897c2430 897c2428 897c2420 4533c9 }
- $sequence_9 = { 4863c2 4c8bc1 8bd1 888c0560080000 6690 420fb68405a0020000 49ffc0 }
+ $sequence_0 = { ff15???????? 85c0 0f84e0020000 6a04 6800100000 6800100000 }
+ $sequence_1 = { 7514 66837b0600 7405 8a4306 }
+ $sequence_2 = { 0fbf4720 33d2 50 0fb6c1 68???????? 83c008 }
+ $sequence_3 = { 730d 810e00000800 808b0603000040 8b4610 808b0603000010 8a55ff }
+ $sequence_4 = { c74710d5000000 eb10 c7471095000000 eb07 c7471085000000 f70700400000 742f }
+ $sequence_5 = { c1c90d 33c8 8b7dd4 8b45e8 03fa c1c802 33c8 }
+ $sequence_6 = { 83ec24 53 32c0 32c9 56 8b7508 }
+ $sequence_7 = { 8a8e08010000 f6c210 0f8411040000 8b8610030000 0b8614030000 0f84c2000000 f6c240 }
+ $sequence_8 = { 8bc6 c1c806 33c8 8bc3 3345d4 034da0 }
+ $sequence_9 = { 8bd8 0b5df4 2345f4 03ca 235de0 0bd8 8b55ac }
condition:
- 7 of them and filesize <544768
+ 7 of them and filesize <532480
}
-rule MALPEDIA_Win_Glupteba_Auto : FILE
+rule MALPEDIA_Win_Skinnyboy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "09a70f19-6d2a-5533-851a-d46346a3f052"
+ id = "c1dca40b-594e-536c-99f6-c4dd1e2fe372"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.glupteba"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.glupteba_auto.yar#L1-L163"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.skinnyboy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.skinnyboy_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "f2320a7d413271b6097cf4accf3d3e4465e91ebbc62274538ef55443d4833776"
+ logic_hash = "70d89835d7c3795dc1cc1ad5fe812e10b23259f8f17b962d2f0a6c8239d19e5a"
score = 75
quality = 75
tags = "FILE"
@@ -154358,38 +161528,32 @@ rule MALPEDIA_Win_Glupteba_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c8 c1e102 33c8 03c9 }
- $sequence_1 = { ff75dc ff7508 ff75e2 e8???????? 83c410 ff35???????? ff15???????? }
- $sequence_2 = { 50 8d85fcf7ffff 50 56 e8???????? 68e8030000 8d85fcf7ffff }
- $sequence_3 = { 59 7e17 83c0fc 33c9 85c0 7e0e }
- $sequence_4 = { 334e04 8b75d0 33cf 8b7ddc c1ef08 c1ee10 }
- $sequence_5 = { 85c0 0f8435010000 807df473 7550 0fb745f7 50 }
- $sequence_6 = { 0f8f9c010000 894df8 ff7518 53 53 e8???????? }
- $sequence_7 = { 46 8975f8 83f810 7cd9 8d48f0 f7d9 1bc9 }
- $sequence_8 = { 0101 03d3 8b4620 8bcb }
- $sequence_9 = { 00cd 3e46 005e3e 46 }
- $sequence_10 = { 0107 eb4d 8b02 89442418 }
- $sequence_11 = { 00f1 3d46005e3e 46 00cd }
- $sequence_12 = { 0012 3f 46 008bff558bec }
- $sequence_13 = { 0106 830702 392e 75a0 }
- $sequence_14 = { 005e3e 46 00ff 3e46 }
- $sequence_15 = { 00ff 3e46 0012 3f }
+ $sequence_0 = { 6a03 6a00 6a00 68bb010000 ffb5ccfeffff 56 ff15???????? }
+ $sequence_1 = { ff30 8945f0 ff36 8975f4 }
+ $sequence_2 = { 660fd68564feffff f30f7e05???????? 8d8576feffff 6a00 50 660fd6856cfeffff e8???????? }
+ $sequence_3 = { ffd7 ffd3 6a00 6a00 }
+ $sequence_4 = { c7856cffffff464b1153 c78570ffffff05170610 c78574ffffff035d591e c78578ffffff01591244 }
+ $sequence_5 = { c1fb05 8bfe 83e71f c1e706 8b049d10110110 }
+ $sequence_6 = { ff15???????? 8bf0 89b5d8feffff ffd3 }
+ $sequence_7 = { c745bc79000000 660fd645c0 660fd645c8 c745e457000000 660fd645e8 660fd645f0 }
+ $sequence_8 = { 85d2 740f 668b444de4 6631444dd0 41 3bca }
+ $sequence_9 = { 8d45f4 50 ff7308 ff15???????? 8b15???????? 85c0 }
condition:
- 7 of them and filesize <1417216
+ 7 of them and filesize <176128
}
-rule MALPEDIA_Win_Fct_Auto : FILE
+rule MALPEDIA_Win_Lodeinfo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2b1f29a9-1362-5741-a18b-c3a100da706f"
+ id = "47c099ff-69db-5812-85ce-57e24072ce38"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fct"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fct_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lodeinfo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lodeinfo_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "d2be9c8f676646ff8bb82d16a11f73bdaff1325b5ad55ea7931b7cc2d022d940"
+ logic_hash = "e6a58ad7e2bc0ff5d6e63ebfb8b716b1912a0a95e296af817067906fecf4c3bd"
score = 75
quality = 75
tags = "FILE"
@@ -154403,32 +161567,32 @@ rule MALPEDIA_Win_Fct_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83e801 0f8595010000 c745e438324100 e9???????? 894de0 c745e438324100 e9???????? }
- $sequence_1 = { c3 c705????????80554100 b001 c3 68???????? e8???????? c70424???????? }
- $sequence_2 = { e9???????? 8b1f 8d049d58634100 8b30 }
- $sequence_3 = { 8bc6 83e03f 6bc838 894de0 8b049d50614100 f644082801 7469 }
- $sequence_4 = { 6a04 e8???????? 83bd48fdffff08 8d8d34fdffff 8d45d8 }
- $sequence_5 = { c70021000000 eb44 c745e002000000 c745e444324100 8b4508 8bcf 8b7510 }
- $sequence_6 = { 50 8b04bd50614100 ff743018 ff15???????? 85c0 7404 b001 }
- $sequence_7 = { 56 33f6 8b8650614100 85c0 740e 50 e8???????? }
- $sequence_8 = { 660fd60f 8d7f08 8b048d84514000 ffe0 f7c703000000 7413 }
- $sequence_9 = { 68???????? c68524fdffff00 8d4dd8 ffb524fdffff 6a01 e8???????? }
+ $sequence_0 = { 894de0 8955f0 8955f8 8955f4 85ff 740a 381433 }
+ $sequence_1 = { 85c0 7412 ff75f4 8b55f0 8bc8 e8???????? 83c404 }
+ $sequence_2 = { 85ff 742e 8b4c2444 8bc7 }
+ $sequence_3 = { 660fefc8 0f114c0620 0f10440630 0f28ca 660fefc8 0f114c0630 83c040 }
+ $sequence_4 = { 5d c3 8b75fc 8b55f0 33c9 85d2 7429 }
+ $sequence_5 = { 8bda 8b5508 57 8bf9 895df8 8b06 }
+ $sequence_6 = { e8???????? 83c404 894708 85c0 750d 39460c 7408 }
+ $sequence_7 = { 03c8 8b4510 d1e9 024fff 884c17ff 8b4dd4 3bf3 }
+ $sequence_8 = { eb72 8b45f0 8975f4 c64406ff00 eb65 8b45f8 8d7e01 }
+ $sequence_9 = { 85c0 748e 33c0 0f57c0 b920010000 8bfa }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <712704
}
-rule MALPEDIA_Win_Curator_Auto : FILE
+rule MALPEDIA_Win_Goggles_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fc957193-82db-5d48-97f1-8bf3e9847701"
+ id = "5a06c6e9-c0df-5eb2-9be8-0912ecacc960"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.curator"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.curator_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.goggles"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.goggles_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "a3bde063a66b4d9394e6eeb42680e73ad8b937005775febd69fd7690156b149c"
+ logic_hash = "6adf86a94e27e4da9bbef6eb899bde95be7c68b8b1a213561e769f61dd93d169"
score = 75
quality = 75
tags = "FILE"
@@ -154442,32 +161606,32 @@ rule MALPEDIA_Win_Curator_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 428a8c01e0590600 482bd0 8b42fc d3e8 49895708 41894718 0fb60a }
- $sequence_1 = { 4903c1 483bc3 0f84b3000000 4983c004 413bca 72e0 488d6b10 }
- $sequence_2 = { 7507 8bc6 e9???????? 44396728 0f8527010000 8d14f5ffffffff 488d4c2458 }
- $sequence_3 = { 448b542424 be01000000 389c24b8000000 7449 385c2420 }
- $sequence_4 = { 8b4308 25ffffff0f 3dffffff0f 740b 488b03 488bd8 4885c0 }
- $sequence_5 = { 660f7ef9 d1c1 894a30 660f6dff 660f7ef9 c1c10a 890a }
- $sequence_6 = { f60708 7505 4885c0 7508 48c7432000409901 488b5c2438 4883c420 }
- $sequence_7 = { 4183fc01 740b 41bc01000000 e9???????? 488b4dd7 e8???????? 488b4ddf }
- $sequence_8 = { 0f843ffeffff 488d55c0 488d4db0 e8???????? e9???????? 488d46ff 488905???????? }
- $sequence_9 = { 0f4ed0 e8???????? 488d1517130400 488d4c2420 e8???????? cc }
+ $sequence_0 = { c1fa02 83e23f 8a8a10400010 880c33 }
+ $sequence_1 = { 51 e8???????? 8b1d???????? b941000000 33c0 }
+ $sequence_2 = { 8d54247c 51 52 8d842488010000 68???????? 50 }
+ $sequence_3 = { 6a01 51 ff15???????? 8b742430 8b542431 }
+ $sequence_4 = { 53 ff15???????? 83c414 33c0 85ed }
+ $sequence_5 = { 51 ff15???????? 83c9ff bf???????? 33c0 83c414 }
+ $sequence_6 = { c744241002000000 8d8c2480020000 51 ff15???????? 8b442410 5f 5e }
+ $sequence_7 = { ffd5 8bf0 8bc7 99 f77c242c 81ee???????? 0fbe8288410010 }
+ $sequence_8 = { 2bd6 56 57 03ea ffd3 57 }
+ $sequence_9 = { a0???????? 55 57 88442410 }
condition:
- 7 of them and filesize <1265664
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Kins_Auto : FILE
+rule MALPEDIA_Win_Sage_Ransom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4907ff1e-c41f-5c86-b473-4fc349042db0"
+ id = "847781b4-d239-5a8c-9601-0e5bac6cb5da"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kins"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kins_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sage_ransom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sage_ransom_auto.yar#L1-L164"
license_url = "N/A"
- logic_hash = "f9718717a3f75dea9d210a3bb9fec1b2557a6447053917656440c5e0062c5092"
+ logic_hash = "0e6ae75d84196f5850e13769b0aaa494f43257ce3727ef9fdf2f02bbc3316ba8"
score = 75
quality = 75
tags = "FILE"
@@ -154481,32 +161645,38 @@ rule MALPEDIA_Win_Kins_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 8d45dc 8d75cc e8???????? 83f8ff 741f 8bc6 }
- $sequence_1 = { 8bfe 337dfc 23f8 33fe 037df0 8d9417937198fd 8b7dfc }
- $sequence_2 = { e8???????? 83f8ff 743d 47 3bfa }
- $sequence_3 = { f7d3 0bde 33d8 035df4 8dbc3ba72394ab c1c70f 8bd8 }
- $sequence_4 = { c1e008 0bc2 0fb65116 0fb64917 c1e008 0bc2 }
- $sequence_5 = { 0fb6c0 83e07f 8bf2 746f 0fb61c39 c1e608 48 }
- $sequence_6 = { 40 85f6 75d8 8b7510 3b16 7719 }
- $sequence_7 = { 33de 23df 33da 035908 8d840378a46ad7 c1c007 03c7 }
- $sequence_8 = { 8d8578fcffff 50 8d857cfdffff 50 }
- $sequence_9 = { ff4118 8b4118 83f838 762b eb0b c644081c00 }
+ $sequence_0 = { 57 56 68???????? e8???????? 83c408 6a00 6a00 }
+ $sequence_1 = { 8b74246c 57 c7442408adde9e5a b908000000 8d7c240c f3a5 8b742478 }
+ $sequence_2 = { 6a02 ff15???????? 8bf0 8d471c }
+ $sequence_3 = { 55 56 894c243c ff15???????? 83f8ff 7541 56 }
+ $sequence_4 = { 56 57 6af5 ff15???????? 8b15???????? 83c204 52 }
+ $sequence_5 = { 68e0930400 ffd6 6a02 e8???????? 83c404 68c0270900 }
+ $sequence_6 = { 0facf014 89442420 c1ee14 8bc6 }
+ $sequence_7 = { 83c438 833d????????00 7513 e8???????? 50 }
+ $sequence_8 = { 01410c 8b4310 014110 8b4314 }
+ $sequence_9 = { 013c13 83c102 46 ebd3 }
+ $sequence_10 = { 014114 8b4318 014118 8b431c }
+ $sequence_11 = { 0101 8b4304 014104 8b4308 014108 }
+ $sequence_12 = { 891c24 89442404 e8???????? 31d2 3955dc 0f86df000000 }
+ $sequence_13 = { 014110 8b4314 014114 8b4318 }
+ $sequence_14 = { 0119 117104 83c110 83c210 }
+ $sequence_15 = { 014108 8b430c 01410c 8b4310 }
condition:
- 7 of them and filesize <548864
+ 7 of them and filesize <335872
}
-rule MALPEDIA_Win_Badhatch_Auto : FILE
+rule MALPEDIA_Win_Ati_Agent_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e8145868-3ca1-5c30-b22c-ef0d5f024b54"
+ id = "aa24ad24-7301-5b4c-b856-1e1a4ef6bc2f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badhatch"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.badhatch_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ati_agent"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ati_agent_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "a465c1cdccc061411fd4300f0446fb5369592ae409bf62acf36666de581c3980"
+ logic_hash = "724a5b5da348b3df222a7dbd0e29ff96d89b57311395a8ccd89f777e74414508"
score = 75
quality = 75
tags = "FILE"
@@ -154520,34 +161690,34 @@ rule MALPEDIA_Win_Badhatch_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 6a00 50 ffd7 56 6a00 ff35???????? }
- $sequence_1 = { 8b7730 59 59 8975f0 85f6 7514 }
- $sequence_2 = { 8bc7 99 0145e0 1155e4 eb0e }
- $sequence_3 = { ff7618 ff15???????? 85c0 740e ff15???????? 8945e4 e9???????? }
- $sequence_4 = { 8bf0 59 85f6 750e eb40 ff15???????? 8bf0 }
- $sequence_5 = { 8945e4 ff45d0 e9???????? 395de4 0f8574060000 68???????? ff7618 }
- $sequence_6 = { 50 ff15???????? 85c0 0f8524010000 8d45ec 50 8d8594f5ffff }
- $sequence_7 = { 8bd8 48 83e90c 85db 75f1 5b }
- $sequence_8 = { 5e c9 c3 55 8bec 83e4f8 81ec38020000 }
- $sequence_9 = { 50 ff15???????? 8945ec 3bc3 7509 }
+ $sequence_0 = { 488bc8 ff15???????? 488d1548a20000 488bce 488905???????? }
+ $sequence_1 = { e8???????? 488d2d24a60000 4c8d250dd80000 83f8ff 7435 488bcf e8???????? }
+ $sequence_2 = { 488d442460 488d942490010000 4533c9 4889442448 48894c2440 }
+ $sequence_3 = { 488b05???????? 4833c4 4889442438 498bf0 488bfa 488bd9 }
+ $sequence_4 = { 488d0526d80000 488d0cc8 48890f ff15???????? }
+ $sequence_5 = { e9???????? 4881ec28050000 488b05???????? 4833c4 4889842410050000 488b05???????? 4885c0 }
+ $sequence_6 = { 488d8c24f0000000 ba04010000 4889442420 e8???????? 4c8d5c2438 488d9424f0000000 41b919010200 }
+ $sequence_7 = { 442bc0 488b442450 488d0d85be0000 488b0cc1 }
+ $sequence_8 = { 897c2428 897c2420 c784248000000068000000 ff15???????? }
+ $sequence_9 = { 8bf8 85c0 750d 488bce e8???????? e9???????? 4c8d2d6dc10000 }
condition:
- 7 of them and filesize <156672
+ 7 of them and filesize <172032
}
-rule MALPEDIA_Win_Soul_Auto : FILE
+rule MALPEDIA_Win_Mosaic_Regressor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ea0bc590-52b0-5914-b399-85653bff4505"
+ id = "6545d5ce-704c-5c00-a6cd-ec1b5c909576"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.soul"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.soul_auto.yar#L1-L234"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mosaic_regressor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mosaic_regressor_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "192d2467d64d6ffcab9581013b65d7e42a7f1082991c14dd63a3ef2c42177610"
+ logic_hash = "73c7fd14f8effd7ac9e0816b586de74eff8d0d21c8391e8e84f2921e57196fdb"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -154559,45 +161729,32 @@ rule MALPEDIA_Win_Soul_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c404 33f6 897304 8b4304 }
- $sequence_1 = { 897304 8b4304 5f 5e 5b }
- $sequence_2 = { 40 803800 75f8 c745fc00000000 90 }
- $sequence_3 = { 75f8 803e00 8bc6 7409 90 fe08 40 }
- $sequence_4 = { d3e2 8515???????? 7405 e8???????? }
- $sequence_5 = { 8b03 8b36 50 e8???????? 8bf8 }
- $sequence_6 = { 5d c3 57 eb05 85f6 }
- $sequence_7 = { ff25???????? ff25???????? ff25???????? ff25???????? 48895c2408 4889742410 57 }
- $sequence_8 = { ff45fc 85f6 7506 837dfc04 7cda }
- $sequence_9 = { c745fc00000000 8da42400000000 8b4df8 51 }
- $sequence_10 = { e9???????? 8b531c c1e002 8bc8 }
- $sequence_11 = { 6644896c2438 48837f1808 7319 4c8b4710 49ffc0 4d03c0 }
- $sequence_12 = { 4983fc08 7208 498bcd e8???????? b801000000 488b8db0010000 4833cc }
- $sequence_13 = { 7475 453bcc 7370 488b5330 4c8b5318 488b7338 }
- $sequence_14 = { 48895c2420 ff16 85c0 0f85f7000000 488b442420 4885c0 0f84e4000000 }
- $sequence_15 = { 4c8bac2470020000 4c8ba42478020000 488bb424a8020000 488b9c2498020000 488bac24a0020000 488b8c2460020000 4833cc }
- $sequence_16 = { 8bc1 c1e805 478d541201 662bc8 }
- $sequence_17 = { 0f8889000000 7e74 817d0063736de0 7528 48833d????????00 741e 488d0d49ad0000 }
- $sequence_18 = { 3d06010000 7309 4585ff 0f84bd020000 85c0 0f8410040000 458bc5 }
- $sequence_19 = { 4883c302 85c0 75ed 85d2 7416 4885ff }
- $sequence_20 = { 488bcf ff15???????? 400fb6de 85c0 be00000000 0f44de 48837c247808 }
- $sequence_21 = { 488d4de0 e8???????? 90 4c8d056e310200 488bd0 488d4db8 }
- $sequence_22 = { 41d3ed 83ff20 7321 85f6 0f84d30c0000 410fb60424 }
+ $sequence_0 = { e8???????? 670010 386700 1023 d18a0688078a }
+ $sequence_1 = { 8975e0 8db1d0a70010 8975e4 eb2a }
+ $sequence_2 = { 85c0 7456 8b4de0 8d0c8de0b70010 8901 8305????????20 }
+ $sequence_3 = { f3a4 6a1c 8d8c2480060000 51 6a00 ffd5 8d842478060000 }
+ $sequence_4 = { 8d442460 50 6a00 ffd5 8d442458 48 8d4900 }
+ $sequence_5 = { 895008 8d542458 52 88480c }
+ $sequence_6 = { c744241444000000 8bc8 90 8a10 }
+ $sequence_7 = { 6a06 89430c 8d4310 8d89c4a70010 5a }
+ $sequence_8 = { 8bff 55 8bec 8b4508 ff34c578a10010 ff15???????? 5d }
+ $sequence_9 = { 6a00 6a00 6a00 8d942498080000 }
condition:
- 7 of them and filesize <1400832
+ 7 of them and filesize <113664
}
-rule MALPEDIA_Win_Stealc_Auto : FILE
+rule MALPEDIA_Win_Anel_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "539cf538-cfac-56e1-8a82-eaf8270c6c0b"
+ id = "77d9607f-3592-578d-9a57-0a9e2e4b1267"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stealc_auto.yar#L1-L108"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.anel"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.anel_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "6bf18991e2a395daac8cbfec9f407668e110581410c7e2de7aedba9cee95d9f0"
+ logic_hash = "1c7f9ff41f497369b4973c110e6ba50d48e821bb90418969cf9b52dfa74f7f8e"
score = 75
quality = 75
tags = "FILE"
@@ -154611,32 +161768,32 @@ rule MALPEDIA_Win_Stealc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 85c0 7507 c685e0feffff43 }
- $sequence_1 = { 68???????? e8???????? e8???????? 83c474 }
- $sequence_2 = { 50 e8???????? e8???????? 83c474 }
- $sequence_3 = { e8???????? e8???????? 81c480000000 e9???????? }
- $sequence_4 = { 50 e8???????? e8???????? 81c484000000 }
- $sequence_5 = { e8???????? 83c460 e8???????? 83c40c }
- $sequence_6 = { e8???????? e8???????? 83c418 6a3c }
- $sequence_7 = { ff15???????? 50 ff15???????? 8b5508 8902 }
- $sequence_8 = { 50 ff15???????? 8b5508 8902 }
- $sequence_9 = { 7405 394104 7d07 8b4908 3bca 75f0 8bf9 }
+ $sequence_0 = { f7fe 43 3bd8 7621 8bd0 d1ea be91cfba01 }
+ $sequence_1 = { eb24 8bca 83e910 3b5904 7f17 7c07 }
+ $sequence_2 = { 8bf9 2bf8 85c0 7411 eb03 83c010 3bc1 }
+ $sequence_3 = { c645fc06 e8???????? c645fc07 8bc8 c645fc08 e8???????? 8bc6 }
+ $sequence_4 = { 897814 895810 89458c 8818 8d4678 }
+ $sequence_5 = { c1e704 037d08 a5 a5 a5 a5 5f }
+ $sequence_6 = { 53 33ff c645fc00 e8???????? 837d1c08 8b4508 7303 }
+ $sequence_7 = { 8bec 51 56 8bf0 33c0 894610 c746140f000000 }
+ $sequence_8 = { 8d8bd0000000 50 8d55d8 c645fc01 e8???????? 6a01 33ff }
+ $sequence_9 = { e8???????? 8bd6 8d8dc8feffff c645fc01 e8???????? c645fc02 83bd04ffffff05 }
condition:
- 7 of them and filesize <4891648
+ 7 of them and filesize <376832
}
-rule MALPEDIA_Win_Orcarat_Auto : FILE
+rule MALPEDIA_Win_Lilith_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2de223cb-857a-5d4b-8d3a-323fa4ad4ded"
+ id = "7c9f283d-efd5-5ce1-a88d-5c399c9e9911"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.orcarat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.orcarat_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lilith"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lilith_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "12ec16d312c505ceab125190551fe03bd174598263e03e7c0fe4b3239bc4fe94"
+ logic_hash = "9246de5695a5f1adcfda29165a048565982f491bffcb4e11939fadd1e6d8bd64"
score = 75
quality = 75
tags = "FILE"
@@ -154650,32 +161807,32 @@ rule MALPEDIA_Win_Orcarat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f2ae 8d84242c110000 f7d1 50 894c2414 51 }
- $sequence_1 = { 8d8c2418010000 50 51 8d842430110000 52 50 }
- $sequence_2 = { 56 6a00 8d5708 6a10 }
- $sequence_3 = { 53 8dbef4020000 51 50 }
- $sequence_4 = { 8bf0 85f6 7451 8b442414 85c0 7421 }
- $sequence_5 = { f2ae 8d442420 f7d1 50 894c2418 ff15???????? 50 }
- $sequence_6 = { 303d???????? 40 00803d400023 d18a0688078a 46 018847018a46 }
- $sequence_7 = { 5d 5b 81c418020000 c20400 6a01 8d142e }
- $sequence_8 = { ff15???????? 85c0 0f849e010000 8b0f 53 6a01 51 }
- $sequence_9 = { 33db 837d0000 762f 8d542410 c744241000000000 52 6800080000 }
+ $sequence_0 = { 50 ff15???????? 6857040000 898698210000 ff15???????? }
+ $sequence_1 = { e8???????? 8bce e8???????? 83c418 8bcf e8???????? 8d4dd0 }
+ $sequence_2 = { 8b0c85a84b4300 8b45e8 f644012880 7446 0fbec3 83e800 742e }
+ $sequence_3 = { 25f0070000 660f28a010e94200 660f28b800e54200 660f54f0 660f5cc6 660f59f4 660f5cf2 }
+ $sequence_4 = { 8b0485a84b4300 80640828fe ff33 e8???????? 59 e9???????? 8b0b }
+ $sequence_5 = { c60000 833d????????10 b8???????? c745cc01000000 0f4305???????? }
+ $sequence_6 = { e9???????? c745dc03000000 c745e0c8874200 e9???????? }
+ $sequence_7 = { c1fa06 8934b8 8bc7 83e03f 6bc830 8b0495a84b4300 8b440818 }
+ $sequence_8 = { 8b4d08 898814434300 68???????? e8???????? 8be5 }
+ $sequence_9 = { 660f122c8510a74200 03c0 660f28348520ab4200 ba7f3e0400 e9???????? 8bd0 }
condition:
- 7 of them and filesize <114688
+ 7 of them and filesize <499712
}
-rule MALPEDIA_Win_Tempedreve_Auto : FILE
+rule MALPEDIA_Win_Hermeticwizard_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e62cef01-6d44-587e-a3de-2c290fdad6d7"
+ id = "726bd88f-010b-5502-8637-f9d7bbeebd06"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tempedreve"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tempedreve_auto.yar#L1-L163"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hermeticwizard"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hermeticwizard_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "5e6b4c6e2f4e0f76996895055b92463fa9cea8a31f828bb15d4eb02a56497fa3"
+ logic_hash = "42607a1b485bdd595d314b574245aeda955efc5b6dd3f18356065a03173a4530"
score = 75
quality = 75
tags = "FILE"
@@ -154689,40 +161846,34 @@ rule MALPEDIA_Win_Tempedreve_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 011e 015e10 015e0c 0fb75706 }
- $sequence_1 = { 011a 8b87dc000000 83c204 03c6 }
- $sequence_2 = { 01042f 034c2ff8 8d45ec 894c2ff8 }
- $sequence_3 = { 754f 85f6 744b 214524 8d4520 }
- $sequence_4 = { 011a 45 8d14a9 8b02 }
- $sequence_5 = { 0103 a1???????? 83c004 50 ff15???????? }
- $sequence_6 = { 0104b7 8b8424a8000000 83c704 4d }
- $sequence_7 = { 010f 8b07 83c704 3bc1 }
- $sequence_8 = { 89542430 eb09 83f801 0f86c8010000 0fb64500 0fb64d01 }
- $sequence_9 = { 85c0 0f85a9090000 53 8916 8d4e04 }
- $sequence_10 = { 8bc8 c1e903 8d440140 c20400 }
- $sequence_11 = { 899e1c040000 895c2458 3bc3 0f86eb070000 8d9b00000000 8b44245c 85c0 }
- $sequence_12 = { 55 51 8bce 8d5c0301 e8???????? 3bd8 8b5c2458 }
- $sequence_13 = { 72f3 8b4c2414 8b6c2428 3bda 0f84e1000000 }
- $sequence_14 = { 8b6c2410 8bd3 2bd7 52 55 8bce e8???????? }
- $sequence_15 = { 8b542430 3bda 7320 8d4d02 8be8 2b6c2428 }
+ $sequence_0 = { 8b4608 3b4208 eb31 83f803 7531 8d4a04 8d4604 }
+ $sequence_1 = { 33c9 66897dca 6800080000 50 }
+ $sequence_2 = { 8b35???????? ffd6 ff75e8 ffd6 5e 8b4508 5f }
+ $sequence_3 = { 6bc930 53 8b5d10 8b0485c0dd0110 56 }
+ $sequence_4 = { 6689854cffffff 6689854effffff 66898554ffffff 6689855effffff 66898d58ffffff 66898d5affffff 59 }
+ $sequence_5 = { 8d4608 50 8d4908 e8???????? }
+ $sequence_6 = { 6a02 58 668945e8 8b4104 }
+ $sequence_7 = { c3 837d08ff 0f8401070000 e9???????? e9???????? 55 8bec }
+ $sequence_8 = { ff15???????? 83f87a 7567 ff75fc 6a08 ff15???????? 50 }
+ $sequence_9 = { ff15???????? 85c0 7504 b001 eb3a 57 56 }
condition:
- 7 of them and filesize <155648
+ 7 of them and filesize <263168
}
-rule MALPEDIA_Win_Plugx_Auto : FILE
+rule MALPEDIA_Win_Zhcat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f3050f8b-cffb-5dba-854a-dbf0ccdc7dc1"
+ id = "0ba2d083-15f8-52b3-8a0e-523b48182ccb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.plugx"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.plugx_auto.yar#L1-L275"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zhcat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zhcat_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "dee163361f083ebb03bd1347d736d4fc9d87c0c2c6fd15ac5989d8dd6f5a5f80"
+ logic_hash = "42a0cd82873743b61553ad212467ec7353604cc191810d2e10195e3fc58baf2d"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -154734,55 +161885,34 @@ rule MALPEDIA_Win_Plugx_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 56 57 6a1c 8bf8 }
- $sequence_1 = { 33d2 f7f3 33d2 8945fc }
- $sequence_2 = { 55 8bec a1???????? 83ec5c 53 }
- $sequence_3 = { 55 8bec 51 0fb74612 }
- $sequence_4 = { 51 53 6a00 6a00 6a02 ffd0 85c0 }
- $sequence_5 = { 41 3bca 7ce0 3bca }
- $sequence_6 = { 56 8b750c 8b4604 050070ffff }
- $sequence_7 = { 6a00 6800100000 6800100000 68ff000000 6a00 6803000040 }
- $sequence_8 = { e8???????? 3de5030000 7407 e8???????? }
- $sequence_9 = { e8???????? 85c0 7508 e8???????? 8945fc }
- $sequence_10 = { 50 ff15???????? a3???????? 8b4d18 }
- $sequence_11 = { 85c0 7413 e8???????? 3de5030000 }
- $sequence_12 = { e8???????? 85c0 7407 b84f050000 }
- $sequence_13 = { e8???????? 85c0 750a e8???????? 8945fc }
- $sequence_14 = { 6a00 6a04 6a00 6a01 6800000040 57 }
- $sequence_15 = { 6a00 6819000200 6a00 6a00 6a00 51 }
- $sequence_16 = { 56 56 6a01 56 ffd0 }
- $sequence_17 = { 85c0 750d e8???????? 8945f4 }
- $sequence_18 = { 57 e8???????? eb0c e8???????? }
- $sequence_19 = { 50 ff75e8 6802000080 e8???????? }
- $sequence_20 = { 6a00 ff7028 e8???????? 83c408 85c0 }
- $sequence_21 = { 6808020000 6a00 ff742450 e8???????? 83c40c }
- $sequence_22 = { 6a02 6a00 e8???????? c705????????00000000 }
- $sequence_23 = { 6800080000 68???????? e8???????? 6800080000 68???????? e8???????? }
- $sequence_24 = { 5e 5f 5b 5d c3 64a118000000 }
- $sequence_25 = { 81ec90010000 e8???????? e8???????? e8???????? }
- $sequence_26 = { 68???????? 6830750000 68e8030000 ff36 }
- $sequence_27 = { 5f 5b 5d c20400 55 53 57 }
- $sequence_28 = { 50 56 ffb42480000000 ff15???????? }
- $sequence_29 = { 6808020000 6a00 ff74242c e8???????? }
- $sequence_30 = { 6a01 6a00 e8???????? a3???????? 6800080000 }
+ $sequence_0 = { 8b3d???????? 8b7508 4f 8945fc }
+ $sequence_1 = { 741e 8d45f8 8975f8 50 85ff 750a }
+ $sequence_2 = { 85c9 759e 56 e8???????? 59 }
+ $sequence_3 = { 85c9 759e 56 e8???????? 59 5f 5e }
+ $sequence_4 = { 3c74 7404 3c54 7512 8915???????? eb0a }
+ $sequence_5 = { 68???????? 56 56 897004 ffd3 6aff }
+ $sequence_6 = { ff7508 ff15???????? ff7514 8945e4 8bc7 668945f0 ffd6 }
+ $sequence_7 = { eb28 c705????????02000000 eb1c c605????????01 }
+ $sequence_8 = { 0fb63e 0fb6c0 eb12 8b45e0 8a80044a4100 08443b1d 0fb64601 }
+ $sequence_9 = { ff7508 ff15???????? 57 8bf0 e8???????? 59 5f }
condition:
- 7 of them and filesize <1284096
+ 7 of them and filesize <376832
}
-rule MALPEDIA_Win_Mylobot_Auto : FILE
+rule MALPEDIA_Win_Cobint_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7a067cd7-af50-5d95-bc8a-c729265f1a45"
+ id = "817f690c-d59f-5f8a-a3d9-41671b2ba114"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mylobot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mylobot_auto.yar#L1-L164"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cobint"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cobint_auto.yar#L1-L246"
license_url = "N/A"
- logic_hash = "e9a5b8dbe1c5cc719187453536536d6ca11df9a61a8a5853882ca3075e6106f0"
+ logic_hash = "138f47bd93e47d27bded8ff6cb142802d64943eb32ae6054eb04266b57a32a5b"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -154794,38 +161924,46 @@ rule MALPEDIA_Win_Mylobot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff5014 56 6a00 50 8947f8 }
- $sequence_1 = { 89442414 75c7 eb02 33f6 85f6 741c }
- $sequence_2 = { 0f8344030000 8b0c83 8b442428 3bc8 0f823e020000 03442418 }
- $sequence_3 = { 83c41c 2b4734 7409 50 53 e8???????? }
- $sequence_4 = { 898108010000 8d442414 50 68???????? }
- $sequence_5 = { 51 ff742410 50 8d84248c020000 50 }
- $sequence_6 = { a1???????? 53 ff507c 8bf8 85ff 0f8491000000 8d442410 }
- $sequence_7 = { 81eccc000000 8b450c 53 56 57 8b00 }
- $sequence_8 = { 75cc 80bdfcfdffff01 0f8581000000 68???????? ff15???????? }
- $sequence_9 = { c785d4fdffff28010000 ff15???????? 8d8dd4fdffff 8bf8 }
- $sequence_10 = { 2bc2 8bc8 8bc3 8d7801 }
- $sequence_11 = { 83bd48ffffff00 0f85e9000000 807dda01 0f95c0 }
- $sequence_12 = { 7857 8b07 85c0 7462 }
- $sequence_13 = { ffd3 68???????? 8d742414 e8???????? 83c404 85c0 }
- $sequence_14 = { 897df4 3bc7 743d 8d55f4 }
- $sequence_15 = { 8bf0 81fed0040000 750e 8b4718 50 57 }
+ $sequence_0 = { 83c410 5e 5d c3 a1???????? 56 33f6 }
+ $sequence_1 = { 3931 740d 40 83c110 83f820 }
+ $sequence_2 = { 57 ff15???????? 8b15???????? 8bc6 8bca }
+ $sequence_3 = { ff7508 e8???????? 83c40c 0fb6c0 5d c3 ff751c }
+ $sequence_4 = { 33f6 a1???????? 03c6 3938 }
+ $sequence_5 = { ffd6 f7d8 c745f404000000 1bc0 }
+ $sequence_6 = { 6a65 eb31 85db 743a 3bde 7336 53 }
+ $sequence_7 = { 59 5d c3 ff7508 6a00 ff35???????? }
+ $sequence_8 = { 90 90 e10b 96 7c90 90 }
+ $sequence_9 = { 90 90 749b 807ce19a80 7c90 }
+ $sequence_10 = { 807c909090 90 90 90 90 90 }
+ $sequence_11 = { 3c2e 7404 3c2c 7506 41 8a0431 2c20 }
+ $sequence_12 = { ffd6 6a04 8d45c0 c745c001000000 }
+ $sequence_13 = { 7202 04e0 8bcf 0fb6c0 c1c108 03c7 }
+ $sequence_14 = { c745c001000000 50 6a41 53 ffd6 baf608f7a4 }
+ $sequence_15 = { 837d1000 740d 8b5508 0355f0 }
+ $sequence_16 = { 0355f0 8a45ec 8802 eb0b 8b4d08 034df0 8a55ed }
+ $sequence_17 = { 83c005 c3 31b7807c30ae 807c909090 90 bdfd807c90 90 }
+ $sequence_18 = { 3bcf 7ce2 8b4dbc 8d9524feffff e8???????? 8d8524feffff 50 }
+ $sequence_19 = { 8d3c08 66391e 75e3 8b5df4 }
+ $sequence_20 = { 749b 807ce19a80 7c90 90 90 90 }
+ $sequence_21 = { 8bcf 8bf0 e8???????? 8945f8 8d45c4 50 8d45f0 }
+ $sequence_22 = { 90 90 bffc807c28 1a807c170e81 7cd7 9b }
+ $sequence_23 = { 8b75f8 85c0 7412 814df080330000 8d45f0 6a04 50 }
condition:
- 7 of them and filesize <8028160
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Crytox_Auto : FILE
+rule MALPEDIA_Win_Hermes_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0ddd8657-2514-5374-8039-613e49f7d728"
+ id = "61ab2fc1-04d0-5933-ac64-b12602279b7d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crytox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crytox_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hermes"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hermes_auto.yar#L1-L111"
license_url = "N/A"
- logic_hash = "53a20cdadf7c04d8a44d2123a9699db23173b707dd2f3ef0f82ea172db5f35fb"
+ logic_hash = "9cfed48151b17cbf55d1481eb34069ea472830263b97aa44ce683b55da6f12b5"
score = 75
quality = 75
tags = "FILE"
@@ -154839,32 +161977,32 @@ rule MALPEDIA_Win_Crytox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb7d 85f6 7479 c645c800 e8???????? 85c0 89c3 }
- $sequence_1 = { dfe9 0f86c2e3ffff 89442410 89c1 c1fa02 db442410 c1f902 }
- $sequence_2 = { e8???????? 8b4510 3b4518 741d 0fbf45c4 c1e002 89442408 }
- $sequence_3 = { e8???????? 89c3 8b45dc 85c0 0f84adfeffff 8d65f4 89d8 }
- $sequence_4 = { eb02 d9c9 83c301 038d30ffffff 399d04ffffff 7f8e ddd9 }
- $sequence_5 = { f1 807de700 89d3 7510 6bc22c 80b84442660000 0f85ac000000 }
- $sequence_6 = { c5c5fe3d???????? c5c572e70e c5fd7f9c24000b0000 c5e572e50e c5d572e60e c5fd7f9c24e0090000 c5ddfe15???????? }
- $sequence_7 = { dee9 d95dc0 8b45e0 83c001 8d148500000000 8b4508 01d0 }
- $sequence_8 = { e9???????? 8b7d24 8b4510 85ff c70000000000 742b 8b4508 }
- $sequence_9 = { dec9 d96c2424 db5c2420 d96c2426 8b742420 d9e8 dfe9 }
+ $sequence_0 = { 6a01 6810660000 ff75fc ff15???????? }
+ $sequence_1 = { ff15???????? 33d2 6a79 59 f7f1 83c261 }
+ $sequence_2 = { 6a01 ff15???????? 8d45fc 50 }
+ $sequence_3 = { 8b4508 83c801 50 6a01 ff75fc }
+ $sequence_4 = { 8b4508 83c801 50 6a01 ff75fc ff15???????? }
+ $sequence_5 = { 50 8b4508 83c801 50 }
+ $sequence_6 = { 6a04 6800100000 6888130000 6a00 }
+ $sequence_7 = { 50 6a01 6810660000 ff75fc ff15???????? }
+ $sequence_8 = { 6800100000 6888130000 6a00 ff15???????? }
+ $sequence_9 = { 50 8d45fc 50 ff15???????? 6a20 }
condition:
- 7 of them and filesize <6156288
+ 7 of them and filesize <7192576
}
-rule MALPEDIA_Win_Fishmaster_Auto : FILE
+rule MALPEDIA_Win_Logtu_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ac4d1a12-e633-54d1-8952-cc6fd81de034"
+ id = "c67bd86c-2bf9-53d0-9e56-6b46a7295f73"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fishmaster"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fishmaster_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.logtu"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.logtu_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "ee895ce428e3021476e31fc5a4cbc7a0e07349c7fde3100efce8681f3e034d54"
+ logic_hash = "a1a55d055cae44fc8e92b272f8aaf6bf080cbc3cc39bc731b57992d62cbc8c84"
score = 75
quality = 75
tags = "FILE"
@@ -154878,32 +162016,32 @@ rule MALPEDIA_Win_Fishmaster_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4883f81f 7736 498bc8 e8???????? 48c7471000000000 }
- $sequence_1 = { e8???????? 488bc3 4c8b4318 4983f810 }
- $sequence_2 = { 7203 498b06 40883c08 c644080100 e9???????? 440fb6cf }
- $sequence_3 = { 488d156e220000 488bcb ff15???????? 488d156e220000 488bcb ff15???????? 4c8be8 }
- $sequence_4 = { 4157 4883ec60 488bfa 488bd9 33f6 897098 488970b0 }
- $sequence_5 = { 48837f1810 7203 488b07 488d4c2438 }
- $sequence_6 = { 0fb65310 8d42ff 3cfd 7718 88940d84000000 4883c314 }
- $sequence_7 = { 46383400 75f7 488d9580000000 488d4d20 e8???????? }
- $sequence_8 = { 480f434c2440 420fb6440803 4288440904 488d442440 48837c245810 480f43442440 488d4c2440 }
- $sequence_9 = { 4c8b45f8 488d15ce200000 488bcf ff15???????? 488bf8 4c89742430 4489742428 }
+ $sequence_0 = { 8bf0 8d85a4fdffff 68???????? 50 ff15???????? }
+ $sequence_1 = { ff15???????? 8d8534ffffff 50 ff15???????? 6a01 }
+ $sequence_2 = { 50 6a64 6a00 ff15???????? 85c0 7509 8b45bc }
+ $sequence_3 = { 8bec 81ec98050000 a1???????? 33c5 8945fc 53 }
+ $sequence_4 = { 55 8bec 81ec98050000 a1???????? 33c5 8945fc 53 }
+ $sequence_5 = { 8d8574faffff 50 8d8534ffffff 50 }
+ $sequence_6 = { 50 8d85fcf7ffff 68???????? 50 e8???????? 8d85fcf7ffff 6800040000 }
+ $sequence_7 = { 6a01 8bf0 8d85a4fdffff 68???????? }
+ $sequence_8 = { 8d8584faffff 50 8d8574faffff 50 8d8534ffffff }
+ $sequence_9 = { 8d8578faffff 50 8d8584faffff 50 }
condition:
- 7 of them and filesize <812032
+ 7 of them and filesize <924672
}
-rule MALPEDIA_Win_Alma_Communicator_Auto : FILE
+rule MALPEDIA_Win_Redshawl_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bb280ae5-df93-5ddd-a029-1d8f19d4cee3"
+ id = "6da43ccb-6114-536f-a2d4-a0a197b8eb4b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alma_communicator"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alma_communicator_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redshawl"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redshawl_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "ceeffab13f59872b0e8352c80061e88c0752f86bcb15a8ae0c39228603990d18"
+ logic_hash = "b081202974eb2cc07597ec5bbbc48f26672d398acc6550f420b42ca3feedcaae"
score = 75
quality = 75
tags = "FILE"
@@ -154917,77 +162055,85 @@ rule MALPEDIA_Win_Alma_Communicator_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8a4a1c 884807 a1???????? c6400800 e8???????? 59 }
- $sequence_1 = { 8945f0 8b450c 8945f4 8b4514 40 c745ec93f84000 894df8 }
- $sequence_2 = { 8bcb 898554f7ffff e8???????? 8bcb 898550f7ffff 6a02 5f }
- $sequence_3 = { e8???????? 83c40c 8d8d58ffffff 8d5102 }
- $sequence_4 = { 8974241c 68d0070000 832600 897c2424 }
- $sequence_5 = { 668b4f02 03fe 663bca 75f5 ffb53cf7ffff 8907 6bc328 }
- $sequence_6 = { 0f85aa010000 33c0 40 8985ccebffff }
- $sequence_7 = { 7204 3c7a 7608 3c2b 7404 3c2f }
- $sequence_8 = { 88840d20f6ffff 41 84c0 75ed 8d8d20f6ffff 49 8a4101 }
- $sequence_9 = { 8a01 41 84c0 75f9 8a442454 2bca 83f901 }
+ $sequence_0 = { ffc6 488d0c80 488d05baaa0000 488d0cc8 48890f ff15???????? 85c0 }
+ $sequence_1 = { e8???????? 488b8b58010000 e8???????? 488d7b58 be06000000 488d0519c30000 483947f0 }
+ $sequence_2 = { 488bce 488bc6 488d15709a0000 83e11f }
+ $sequence_3 = { 488b8b58010000 e8???????? 488d7b58 be06000000 488d0519c30000 }
+ $sequence_4 = { e9???????? 4c8d2552940000 488b0d???????? eb7c }
+ $sequence_5 = { eb76 33c9 488d1543bb0000 48891401 4883c230 4883c108 48ffcb }
+ $sequence_6 = { 8905???????? 8b430c 8905???????? 8bd7 4c8d0520d1ffff 89542420 }
+ $sequence_7 = { 8bd8 488bcf ff15???????? 488b742438 8bc3 }
+ $sequence_8 = { 72ed 48833d????????00 741f 488d0dc2c10000 e8???????? 85c0 }
+ $sequence_9 = { 4c8d251ac70000 4863f8 49833cfc00 752b b900100000 }
condition:
- 7 of them and filesize <245760
+ 7 of them and filesize <174080
}
-rule MALPEDIA_Win_Photoloader_Auto : FILE
+rule MALPEDIA_Win_Uroburos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "317a851b-1405-50a0-9b40-ce8155fbfa48"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.photoloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.photoloader_auto.yar#L1-L159"
+ id = "205256f7-2469-53ee-990c-6fdfb536a7d1"
+ date = "2023-01-25"
+ modified = "2023-01-26"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.uroburos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.uroburos_auto.yar#L1-L234"
license_url = "N/A"
- logic_hash = "c73e7831cd0e2d402a5233934c3321f9665203a6373de35d59f2fa5b935ee161"
+ logic_hash = "7cd6167d1ac85667ccf6f37a04c885a4dbb4d487c7aa8e68ed00f9a40de671ad"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
+ malpedia_rule_date = "20230124"
+ malpedia_hash = "2ee0eebba83dce3d019a90519f2f972c0fcf9686"
+ malpedia_version = "20230125"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0d00000005 e9???????? 8bd7 397b1c 7640 }
- $sequence_1 = { 8bf7 8d6f10 ff15???????? 0f31 }
- $sequence_2 = { c0c003 0fb6c8 8bc1 83e10f }
- $sequence_3 = { 33c9 b801000000 0fa2 89442420 895c2424 }
- $sequence_4 = { 33c9 b800000040 0fa2 895f0c }
- $sequence_5 = { 0fa2 894704 33c9 b800000040 }
- $sequence_6 = { 895c2424 894c2428 8954242c 0f31 }
- $sequence_7 = { f7411400000020 7407 8b41f8 3901 7714 }
- $sequence_8 = { 85d2 7417 448bc2 0f31 48c1e220 480bc2 8801 }
- $sequence_9 = { 1bc0 23442410 3b03 7418 }
- $sequence_10 = { 8903 8d44242c 50 6804010000 ff15???????? ff35???????? 8d4c2430 }
- $sequence_11 = { 5d c3 8b4d08 8b45fc 8901 8b450c }
- $sequence_12 = { c3 55 8bec 81ec18020000 53 8ad9 }
- $sequence_13 = { 8b5604 8d44240c 8b0e 55 }
- $sequence_14 = { 51 8d855cffffff 8bf2 68???????? }
- $sequence_15 = { 56 33c0 8d6c240c 57 }
+ $sequence_0 = { 7526 85d2 7411 8b493c }
+ $sequence_1 = { 85d2 7406 8d4801 0fafcd }
+ $sequence_2 = { 09c9 7407 ffd1 a1???????? 832d????????04 3905???????? 73de }
+ $sequence_3 = { 85c0 7405 e9???????? 448bc7 }
+ $sequence_4 = { 8b493c 8bc2 4881c108010000 483bc1 }
+ $sequence_5 = { 29c0 eb4e 57 56 }
+ $sequence_6 = { 85c0 750d 48837c245000 0f95c0 8803 33c0 }
+ $sequence_7 = { 895c2430 e9???????? 33d2 448d4268 }
+ $sequence_8 = { 09c0 7503 21450c 837d0c00 }
+ $sequence_9 = { 83fe01 89450c 750c 09c0 7537 57 50 }
+ $sequence_10 = { 54 5d 53 8b5d08 56 8b750c 09f6 }
+ $sequence_11 = { 5f 09ff 59 751e 56 ff15???????? 8d86e8030000 }
+ $sequence_12 = { 40 c20c00 55 54 5d }
+ $sequence_13 = { 7704 4183c220 4585c9 740a 453bca 7505 4d85c0 }
+ $sequence_14 = { 8bc1 f7f5 85d2 7406 }
+ $sequence_15 = { 7433 eb13 8b0d???????? 8b09 09c9 7407 }
+ $sequence_16 = { 48 8bf0 49 2bf5 4c }
+ $sequence_17 = { 83c601 49 83c508 41 3bdf 7c82 45 }
+ $sequence_18 = { 750a 8d43ff e9???????? 33db }
+ $sequence_19 = { b901000000 e8???????? 48 85c0 48 8bd8 }
+ $sequence_20 = { 85c0 7434 48 83c310 83c701 48 }
+ $sequence_21 = { ff15???????? 44 8bd8 49 c1e320 4c }
+ $sequence_22 = { 8b8f58010000 e8???????? 48 895c2430 }
+ $sequence_23 = { 8b5c2450 48 83c448 c3 4c 8bc6 }
condition:
- 7 of them and filesize <107520
+ 7 of them and filesize <1136640
}
-rule MALPEDIA_Win_Portdoor_Auto : FILE
+rule MALPEDIA_Win_Nocturnalstealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "84ef053f-8b45-5899-91c4-5c0973d7e3db"
+ id = "16d4de33-3c54-5479-87ac-366869086324"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.portdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.portdoor_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nocturnalstealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nocturnalstealer_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "23b6dfc496aede71e92bc63441565950d5591602bef8ef2eba1715ff0ea58fc2"
+ logic_hash = "6f15e0c8b7c880f99f33b6a9409ba20c65fe7c5674e094de4ef3ad4c2fb61399"
score = 75
quality = 75
tags = "FILE"
@@ -155001,32 +162147,32 @@ rule MALPEDIA_Win_Portdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? 83f8ff 8906 0f95c0 eb2f 807e5100 }
- $sequence_1 = { 50 8d85fcf3ffff 50 e8???????? 8bf0 }
- $sequence_2 = { ff5718 8903 6a04 59 8d4102 33d2 }
- $sequence_3 = { 8945a8 eb04 8365a800 8b45a8 894590 834dfcff 8b4590 }
- $sequence_4 = { 50 8b8528e5ffff 0f94c1 898d3ce5ffff 8b8d24e5ffff 8b0485b80f0210 ff3401 }
- $sequence_5 = { 894224 6689424c 894248 88424e 8a01 88040b }
- $sequence_6 = { 7e21 8b450c 6a00 2bc6 }
- $sequence_7 = { 51 51 8d45f8 895df8 }
- $sequence_8 = { e8???????? 8bf8 b8eeff0000 59 668907 8b450c 885f02 }
- $sequence_9 = { e8???????? a1???????? 33c5 8945fc 53 8b5d08 8d85fdfbffff }
+ $sequence_0 = { ff3424 5e 56 e9???????? 81e945418082 01ca e9???????? }
+ $sequence_1 = { e9???????? 09d6 5f 81e220000000 ba00000000 81f700000080 81eeffffff7f }
+ $sequence_2 = { e9???????? 01742404 ff3424 5e 57 89e7 e9???????? }
+ $sequence_3 = { 89ef ba00020000 2524000000 09cb 05ffffff7f 81e6ffffff7f 81c7a2000000 }
+ $sequence_4 = { e9???????? 83c004 330424 310424 330424 5c 55 }
+ $sequence_5 = { b8b4888b7f 251810fb62 253a26e37e 05b68054fc 31c7 e9???????? 331c24 }
+ $sequence_6 = { e9???????? 8d852731bc18 52 89e2 50 b804000000 01c2 }
+ $sequence_7 = { e9???????? 895c2404 8b1c24 83c404 893424 890424 e9???????? }
+ $sequence_8 = { e9???????? 57 891c24 890424 e9???????? 81c704000000 81c704000000 }
+ $sequence_9 = { f7d8 f7d0 c1e808 c1e802 e9???????? 29cf 8b0c24 }
condition:
- 7 of them and filesize <297984
+ 7 of them and filesize <10739712
}
-rule MALPEDIA_Win_Mail_O_Auto : FILE
+rule MALPEDIA_Win_Redpepper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f99f4969-80f4-597a-910e-873dc6aaa6b8"
+ id = "6d36eb39-39c8-5443-a77b-2290277533bd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mail_o"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mail_o_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redpepper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redpepper_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "873a5557134df7611d1b518c4c6caa2026bc1ae07076d192a3e745c13ea47ee0"
+ logic_hash = "e4e4c0e91e25e59e6fb978e405ca0275203329718b6dc395151e5d470e453248"
score = 75
quality = 75
tags = "FILE"
@@ -155039,33 +162185,33 @@ rule MALPEDIA_Win_Mail_O_Auto : FILE
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
- strings:
- $sequence_0 = { 7707 33c0 e9???????? f683a414000020 7417 8b83700e0000 2500000100 }
- $sequence_1 = { f20f104c2450 f20f114930 83cbff 8b0f e8???????? 8bc3 488b5c2470 }
- $sequence_2 = { eb0c 488d15b7940d00 e8???????? 488b4708 488d542440 448b4710 33c9 }
- $sequence_3 = { b920000000 ffcb ff542428 83f8ff 0f84b2010000 ffc7 85db }
- $sequence_4 = { 8b5c2438 418d7f10 4533c0 498bce 3bfb 7e23 488d542440 }
- $sequence_5 = { e8???????? eb17 498b4d10 4d8bf4 418bdc e8???????? eb06 }
- $sequence_6 = { c744242071000000 448d4041 eb1f 488918 488bd0 488b4d08 e8???????? }
- $sequence_7 = { 85c0 743c 48ffc3 483b5c2430 72c3 488bcf e8???????? }
- $sequence_8 = { 84c0 7465 48ffc1 498d0408 483bc2 72df ba00800000 }
- $sequence_9 = { e8???????? 8bf8 85c0 7556 48837c245000 7505 8d7809 }
+ strings:
+ $sequence_0 = { 57 8bf9 8b870c1e0000 85c0 }
+ $sequence_1 = { 8b500c 41 83f904 8b12 8a540aff }
+ $sequence_2 = { 8b4d10 881e 50 8901 e8???????? 59 }
+ $sequence_3 = { 8b4520 3bc7 7439 68a1000000 68???????? 50 e8???????? }
+ $sequence_4 = { 53 55 56 33f6 57 8b7c2428 }
+ $sequence_5 = { 752d 689f000000 68???????? 6a26 }
+ $sequence_6 = { c3 8b7c2418 85ff 7432 e8???????? }
+ $sequence_7 = { 8845f3 8845f4 8845f7 8845f8 }
+ $sequence_8 = { 8b742414 6a0f f7d1 49 56 8be9 e8???????? }
+ $sequence_9 = { e8???????? 8b44241c 8b6c2428 8b4c2418 }
condition:
- 7 of them and filesize <5985280
+ 7 of them and filesize <2482176
}
-rule MALPEDIA_Win_Crypto_Fortress_Auto : FILE
+rule MALPEDIA_Win_Mutabaha_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6a23a7a3-8360-570b-be01-5aa731924fe0"
+ id = "04cdad38-c730-58bf-ac9f-7881643cfe37"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crypto_fortress"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crypto_fortress_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mutabaha"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mutabaha_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "cb9e8ad6d0528bcc920d7d8992919925e873e6ab7fd21de603b21e974fe6d2be"
+ logic_hash = "21a56ac17d7181e1f264aab4aad9c0f8a40e021362f525e9ed7460f5330637ce"
score = 75
quality = 75
tags = "FILE"
@@ -155079,32 +162225,32 @@ rule MALPEDIA_Win_Crypto_Fortress_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffb5a8feffff e8???????? 68???????? ffb5a8feffff e8???????? }
- $sequence_1 = { a3???????? 68???????? ff35???????? e8???????? 85c0 0f846f030000 }
- $sequence_2 = { aa 3407 aa 045a aa }
- $sequence_3 = { e8???????? 85c0 0f846f030000 a3???????? 68???????? ff35???????? e8???????? }
- $sequence_4 = { ff35???????? e8???????? 85c0 0f8456060000 a3???????? 8d3dccec4000 33c0 }
- $sequence_5 = { 2cff aa 2cf9 aa 2c4c }
- $sequence_6 = { aa 2c4e aa 0444 aa 2cff aa }
- $sequence_7 = { c9 c20800 55 8bec 83c4f8 8b4508 }
- $sequence_8 = { aa 341b aa 2c27 aa 3441 aa }
- $sequence_9 = { aa 340a aa 3421 aa 0433 aa }
+ $sequence_0 = { 50 8d9518ffffff 8d8d68feffff e8???????? 8d8d48ffffff c645fc09 }
+ $sequence_1 = { 8b85dcfdffff 83f808 7213 40 8d8dc8fdffff 50 ffb5c8fdffff }
+ $sequence_2 = { c745b800000000 c645a800 c745c06cac4700 85c0 7409 50 e8???????? }
+ $sequence_3 = { 85d2 7424 8b7c2424 8d4f08 833900 740a 40 }
+ $sequence_4 = { 0fb7f8 eb43 83f803 7536 ff734c ff75d4 e8???????? }
+ $sequence_5 = { c745ec00000000 668945dc e8???????? 8d45dc c745fc05000000 50 8bce }
+ $sequence_6 = { e8???????? c7465400000000 8bc6 8b4df4 64890d00000000 59 5e }
+ $sequence_7 = { 8d8d84fdffff c78598fdffff07000000 c78594fdffff00000000 66898584fdffff e8???????? 57 ba???????? }
+ $sequence_8 = { 0103 115304 33c0 5f 5e 5b 8be5 }
+ $sequence_9 = { e9???????? 8d8d5cffffff e9???????? 8d4dbc e9???????? 8d4dd4 e9???????? }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <1220608
}
-rule MALPEDIA_Win_Avzhan_Auto : FILE
+rule MALPEDIA_Win_Nokki_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ae24c209-0bbe-565c-a4e8-dc5e113ea302"
+ id = "02120b2b-1366-521d-89f5-fe0cec012c20"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avzhan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avzhan_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nokki"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nokki_auto.yar#L1-L156"
license_url = "N/A"
- logic_hash = "e5753cf0528c1786d65aca4559b3855c06a602b71f8830b1dc3d077867894002"
+ logic_hash = "e29386a66940956320f6fdb11113fafeb375dcdfcfa05926d55033ad903bf7f3"
score = 75
quality = 75
tags = "FILE"
@@ -155118,32 +162264,36 @@ rule MALPEDIA_Win_Avzhan_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f3aa 8b3d???????? 833d????????01 7418 }
- $sequence_1 = { 75e8 6a14 ff15???????? 833d????????01 75d2 }
- $sequence_2 = { 8bf0 8dbc2404020000 83c9ff 33c0 83c408 f2ae }
- $sequence_3 = { 68???????? 51 ff15???????? 8b2d???????? 8b1d???????? b910000000 }
- $sequence_4 = { 8d442464 52 50 e8???????? 83c404 50 e8???????? }
- $sequence_5 = { 6a00 6a00 6a00 6a00 6a00 8d8c2418020000 6a00 }
- $sequence_6 = { 83c408 f2ae f7d1 6a00 51 8d8c2404020000 51 }
- $sequence_7 = { 8bc3 83c408 c1e010 668bc3 8b1d???????? c1e902 }
- $sequence_8 = { 6a00 51 6a00 ffd5 85c0 }
- $sequence_9 = { 51 8d842484010000 52 50 }
+ $sequence_0 = { e8???????? 33d2 68ce070000 52 }
+ $sequence_1 = { e8???????? 33c9 68ce070000 51 }
+ $sequence_2 = { 8b420c 898d08f8ffff b9???????? 89b518f8ffff ffd0 }
+ $sequence_3 = { 884c0204 8b06 8bd0 83e01f c1fa05 8b149580054100 c1e006 }
+ $sequence_4 = { 8d8daaddffff 51 668985a8ddffff e8???????? 6800010000 8d95f0feffff 6a00 }
+ $sequence_5 = { 6a01 6a00 ff15???????? 8bf8 85ff 0f848a000000 6a00 }
+ $sequence_6 = { 51 8d9520f8ffff 52 e8???????? 83c408 85c0 744a }
+ $sequence_7 = { ffd6 57 ffd6 68a0bb0d00 }
+ $sequence_8 = { 8a8c181d010000 888888054100 40 ebe6 ff35???????? }
+ $sequence_9 = { 33ff ffb7d4ec4000 ff15???????? 8987d4ec4000 83c704 83ff28 }
+ $sequence_10 = { 83c40c 6804010000 8d95f4fdffff 52 6a00 ffd6 }
+ $sequence_11 = { 8d7810 89bd68e8ffff 8b8d60e8ffff 8b9564e8ffff 8d856ce8ffff 50 }
+ $sequence_12 = { 8bce e8???????? 33d2 6806020000 52 8d85eafdffff 50 }
+ $sequence_13 = { 8d8df4fdffff 51 ffd3 8d95f4fdffff 68???????? }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <454656
}
-rule MALPEDIA_Win_Silon_Auto : FILE
+rule MALPEDIA_Win_Turla_Silentmoon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "74e356eb-e3ab-55df-a58b-86af4144d8aa"
+ id = "74286b0f-5712-5890-afe4-259cc8765b9b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.silon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.silon_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.turla_silentmoon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.turla_silentmoon_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "e4ecb086584bedec65219eab1069013db28049e75ec56b31d70ca83f4cf849d8"
+ logic_hash = "f84d11e90ac1422010cde8ffffe4ee94ce33e7fe9731643e241a69ac7f1c820c"
score = 75
quality = 75
tags = "FILE"
@@ -155157,32 +162307,32 @@ rule MALPEDIA_Win_Silon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83ec18 c745f000000000 c745f400000000 c745f800000000 33c0 8945fc }
- $sequence_1 = { 83c408 8945f4 837df400 7507 33c0 e9???????? c745f800000000 }
- $sequence_2 = { 81ec3c020000 c785c4fdffff00000000 c745fc00000000 c745f800000000 837d0800 }
- $sequence_3 = { 0fbe11 83fa61 7c20 8b4508 0345fc 0fbe08 83f97a }
- $sequence_4 = { 8b4d0c 8b55f8 895104 8b45f4 50 e8???????? 83c404 }
- $sequence_5 = { 6a00 8d8df4feffff 51 8d95f8feffff 52 6a01 8b4508 }
- $sequence_6 = { 50 e8???????? 83c408 eb61 8b4d08 }
- $sequence_7 = { e8???????? 83c404 8b55fc 52 e8???????? 83c404 8945ec }
- $sequence_8 = { 8b5508 8955e8 837de800 7507 33c0 e9???????? 8b45e8 }
- $sequence_9 = { 5d c20c00 ff25???????? 60 33c9 8b742424 33c0 }
+ $sequence_0 = { 88442453 a1???????? 89442430 a0???????? 53 56 88442444 }
+ $sequence_1 = { 8b4508 85c0 0f84f9010000 8938 5e 5b 8be5 }
+ $sequence_2 = { 51 6800001000 53 56 ff15???????? 83f801 }
+ $sequence_3 = { b950000000 e8???????? 83c404 6a08 b990000000 e8???????? }
+ $sequence_4 = { 8b94bd28feffff 8d441001 8b55f0 8955d4 8b94bd28feffff 8955d8 8b55f0 }
+ $sequence_5 = { 3bd1 7c9a 0fb608 3bd1 7e66 83be5c02000008 7c2f }
+ $sequence_6 = { 48 83f803 0f878a000000 ff248588344000 8bc3 e8???????? }
+ $sequence_7 = { 85ff 0f8f82fcffff 5f 5b }
+ $sequence_8 = { 7e0a 8b4df0 8b7dd8 33c0 f3ab 8145d808040000 }
+ $sequence_9 = { 741f 8b4508 85c0 7406 c700faffffff c787c4130000faffffff 5e }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Xdspy_Auto : FILE
+rule MALPEDIA_Win_Boxcaon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "770ce833-e4ad-5e91-a2e8-e19a8fcb8719"
+ id = "a730ae2b-b623-5088-86a7-4d1a4eb89ea5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xdspy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xdspy_auto.yar#L1-L167"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.boxcaon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.boxcaon_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "f9c3ada66244c45df3d3dc2c6a2b3ef1f7e34e7bdca43fe98eeac2240819a0e8"
+ logic_hash = "5b71da83cc61472fd3b6239fea0178674ab4b3cf9a9678dbeeda07cdd88e683a"
score = 75
quality = 75
tags = "FILE"
@@ -155196,38 +162346,32 @@ rule MALPEDIA_Win_Xdspy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d45ec 50 ff35???????? e8???????? 83f8ff }
- $sequence_1 = { ffb56cd8ffff 8d8570d8ffff 6800040000 6a01 50 e8???????? }
- $sequence_2 = { 8b36 8bce c1f905 8b0c8d804e4100 }
- $sequence_3 = { ff7580 8b3d???????? ffd7 8d4580 50 68???????? 56 }
- $sequence_4 = { 8d45e0 50 57 8d85e02a0000 50 ff75dc ffd3 }
- $sequence_5 = { 83c414 83c8ff e9???????? 8bc6 c1f805 57 8d3c85804e4100 }
- $sequence_6 = { 8b4de0 8d0c8d804e4100 8901 8305????????20 }
- $sequence_7 = { 8d8510ecffff 57 50 e8???????? ffb56cd8ffff }
- $sequence_8 = { 0f1f4000 660f1f840000000000 420fb68431309b1700 88840db0080000 488d4901 }
- $sequence_9 = { 488b15???????? 488d8da0080000 ffd0 660f6f0d???????? 488d3550331700 }
- $sequence_10 = { c705????????67736666 c705????????6e747764 c705????????73752f65 66c705????????6d6d 488d1563121700 }
- $sequence_11 = { 488d4901 84c0 75e8 80bd400c000000 488d85400c0000 7413 }
- $sequence_12 = { 4883f860 7ccf 488d15f85c1700 488d0d41e60100 4c8d0552e60100 }
- $sequence_13 = { fe08 488d4001 803800 75f5 488d8db0080000 ff15???????? }
- $sequence_14 = { 83f9ff 0f8496010000 ba01000000 448d420f }
- $sequence_15 = { 33c9 ff15???????? 48898424a8000000 660f6f05???????? }
+ $sequence_0 = { 897e14 897e70 c686c800000043 c6864b01000043 c7466890b54000 6a0d e8???????? }
+ $sequence_1 = { 8bd3 66899424e0000000 5a 6a50 66899424e2000000 8bd1 66899424e4000000 }
+ $sequence_2 = { 8888b8b84000 40 ebe6 ff35???????? }
+ $sequence_3 = { 8bec 33c0 8b4d08 3b0cc5408a4000 740a }
+ $sequence_4 = { c78424980000003c000000 ff15???????? 56 33ff }
+ $sequence_5 = { e8???????? 84c0 741a 8d4c2410 8d8424d8020000 2bc1 }
+ $sequence_6 = { 89bc24ac000000 89b424b4000000 c78424980000003c000000 ff15???????? }
+ $sequence_7 = { 33c9 66890c06 68???????? 8d442414 50 e8???????? }
+ $sequence_8 = { 0020 1f 40 00441f40 0023 d18a0688078a 46 }
+ $sequence_9 = { 33c0 c7461407000000 668906 8b4508 8b5810 57 }
condition:
- 7 of them and filesize <3244032
+ 7 of them and filesize <256000
}
-rule MALPEDIA_Win_Zupdax_Auto : FILE
+rule MALPEDIA_Win_Former_First_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0a0ddf15-919a-51b3-8d2b-36d56a66b11c"
+ id = "e13a8bc3-e4cb-54c7-a2c1-b71b74a37c2c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zupdax"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zupdax_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.former_first_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.former_first_rat_auto.yar#L1-L167"
license_url = "N/A"
- logic_hash = "b6e9bce8da2b32bfb52c3b6477d889790098710bc4ce9f32e2c7bd1bace10557"
+ logic_hash = "79676675a5e0c5d1eb84217b80928525157e507544e18d7d0452685a540a1268"
score = 75
quality = 75
tags = "FILE"
@@ -155241,32 +162385,38 @@ rule MALPEDIA_Win_Zupdax_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 895e2c e8???????? 8b460c 83c404 3bc3 7419 }
- $sequence_1 = { 8b4c2408 8b7e10 51 e8???????? 8b560c 52 e8???????? }
- $sequence_2 = { 52 68???????? ff15???????? 8d442444 }
- $sequence_3 = { e8???????? 83c408 8b4618 50 895e24 895e28 895e2c }
- $sequence_4 = { 394c2414 765b 53 41 81e1ff000080 }
- $sequence_5 = { 4b 81cb00ffffff 43 0fb61403 30142f 47 }
- $sequence_6 = { 895710 8b4614 894e14 8b5718 894714 8b4618 895618 }
- $sequence_7 = { 2bc2 50 8d54241c 52 }
- $sequence_8 = { 46 8a1c06 881c01 881406 }
- $sequence_9 = { 8b4c2408 8b7e10 51 e8???????? }
+ $sequence_0 = { 899424ec030000 898c24e8030000 8b4f10 8d9424e8030000 6a00 52 898424f8030000 }
+ $sequence_1 = { 894c240c 8bd3 3bc1 7420 8d642400 8bf0 }
+ $sequence_2 = { 52 bb1c000000 8d742428 894c245c c744246000000000 }
+ $sequence_3 = { e8???????? 8b8d0cffffff 68???????? 51 e8???????? }
+ $sequence_4 = { ff15???????? 33c0 66833d????????09 0f94c0 a3???????? 6808020000 }
+ $sequence_5 = { c785e8feffff0f000000 899decfeffff 899df0feffff 899d04ffffff 899df4feffff }
+ $sequence_6 = { e8???????? 8d8de0feffff 51 bb08000000 e8???????? 8b9df8feffff 57 }
+ $sequence_7 = { 8bf2 8bfb 81c208020000 b982000000 81c308020000 f3a5 3bd0 }
+ $sequence_8 = { 48897c2428 488d05169b0200 488907 488d4f08 e8???????? }
+ $sequence_9 = { 480f42db 4883792010 7206 488b4908 eb04 }
+ $sequence_10 = { 48837e2008 7209 488b4e08 e8???????? 488d4608 }
+ $sequence_11 = { 48895c2468 0f28442450 660f7f442450 0f284c2460 660f7f4c2460 }
+ $sequence_12 = { 48896c2460 40886c2450 488bcb e8???????? }
+ $sequence_13 = { 488d4754 48894760 48832100 488b4748 48832000 }
+ $sequence_14 = { 90 48017e20 488b7620 4881c670ffffff }
+ $sequence_15 = { 488b7968 488d0532800200 8bf2 488bd9 }
condition:
- 7 of them and filesize <1032192
+ 7 of them and filesize <626688
}
-rule MALPEDIA_Win_Hui_Loader_Auto : FILE
+rule MALPEDIA_Win_Targetcompany_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "175084ea-2a45-5f42-bda4-3cc233036dd9"
+ id = "e6fff5d7-7001-551f-9dad-753a10f6e88e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hui_loader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hui_loader_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.targetcompany"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.targetcompany_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "96ca3a225904ad2e70a598c1b3c7fa88d26822a60a6742e1663517bed35c0526"
+ logic_hash = "a6f3e9a1f1d0d374d374e6c7006eb751526bddf3371b115cfe046f8accd1d439"
score = 75
quality = 75
tags = "FILE"
@@ -155280,32 +162430,32 @@ rule MALPEDIA_Win_Hui_Loader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? 51 8bf8 ffd5 8d9424b8010000 8d842488090000 }
- $sequence_1 = { ffd0 68e8030000 ffd6 8b0d???????? 51 ff15???????? 5f }
- $sequence_2 = { 8b1402 3bd3 7406 c70109000000 }
- $sequence_3 = { 83e01f c1f905 8d04c0 8b0c8d60e20010 8d44810c 50 }
- $sequence_4 = { 52 50 a3???????? ff15???????? a1???????? }
- $sequence_5 = { 83c628 83f90a 7cd9 33d2 }
- $sequence_6 = { 8d4a01 0338 83c004 49 75f8 42 83c628 }
- $sequence_7 = { c20400 8b15???????? 33c0 68???????? 52 }
- $sequence_8 = { ff15???????? a3???????? 33ff 8d4c2428 }
- $sequence_9 = { 7e0f 8b4efc 8b5401fc 031401 8b0e 891401 }
+ $sequence_0 = { ff15???????? 85c0 7475 fe85a7fdffff 80bda7fdffff0c }
+ $sequence_1 = { 53 ff15???????? ff75e8 ff15???????? ff75e0 ff15???????? 3975f0 }
+ $sequence_2 = { eb43 b900100000 3bc1 733a 53 51 }
+ $sequence_3 = { 83c424 33cd 33c0 5f e8???????? c9 c3 }
+ $sequence_4 = { 813d????????a9aaaa0a 722b 68???????? 8d4dd4 }
+ $sequence_5 = { e8???????? 57 6a0c 5a 8bce 8d45e0 e8???????? }
+ $sequence_6 = { 83ec40 53 56 33f6 57 8d5dc4 }
+ $sequence_7 = { 50 8d45b0 50 e8???????? 8d45b0 50 8d85c0feffff }
+ $sequence_8 = { bf???????? 8d75e8 e8???????? 8b1d???????? 8d75f0 }
+ $sequence_9 = { 8945ec e8???????? 53 6a01 8d758c e8???????? 53 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <328704
}
-rule MALPEDIA_Win_Leash_Auto : FILE
+rule MALPEDIA_Win_Hawkball_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cb5c9738-3925-5a03-a07d-f456311bbe1c"
+ id = "e8db5e2d-29c9-5590-a712-0f60cd9571dc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.leash"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.leash_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hawkball"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hawkball_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "ba62c5a8d74be4d262e44012cbb9d0d01e64bb5749bfbb2b1403f379db7c0758"
+ logic_hash = "781a6bce01e178f537c586fc2b1e607c4503cf63fe51435a8db976da2766e5fa"
score = 75
quality = 75
tags = "FILE"
@@ -155319,32 +162469,32 @@ rule MALPEDIA_Win_Leash_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83c408 85c0 7511 8b8b08080000 56 e8???????? }
- $sequence_1 = { 8a45ef 885def 3ac3 7404 c645ef01 }
- $sequence_2 = { 6a01 6a02 ff15???????? 83f8ff 89831c180000 7519 5f }
- $sequence_3 = { 33c0 f2ae f7d1 49 51 e8???????? 8be8 }
- $sequence_4 = { 2bf9 8d93fe030000 8bc1 8bf7 8bfa 52 }
- $sequence_5 = { 8b5808 33c0 8a442413 33fb 33db }
- $sequence_6 = { 8bc1 8bf7 8bfa 8d9510ffffff }
- $sequence_7 = { 85ff c744242800000000 7e58 8bd8 895c2410 }
- $sequence_8 = { 8bd1 8bf0 c1e902 f3a5 8bca 83c404 83e103 }
- $sequence_9 = { 894518 8b4514 99 83e203 03c2 8b5518 }
+ $sequence_0 = { 83780c00 7506 33c0 8be5 }
+ $sequence_1 = { 53 e8???????? 037dfc 83c40c 81ffffff0300 }
+ $sequence_2 = { 0f84c6000000 6a04 8d442418 c744241860ea0000 50 6a06 57 }
+ $sequence_3 = { 53 ff15???????? ff742414 8b35???????? ffd6 53 }
+ $sequence_4 = { 85c9 746d 837dfc28 7d13 6b55fc05 69c2e8030000 }
+ $sequence_5 = { 50 ff15???????? 897001 c600ff c7400500000000 }
+ $sequence_6 = { b9???????? e8???????? a3???????? 833d????????00 740b 8b0d???????? }
+ $sequence_7 = { 837dfc28 7d13 6b55fc05 69c2e8030000 50 }
+ $sequence_8 = { 7405 8d4a10 eb47 b911000000 }
+ $sequence_9 = { 8be5 5d c3 6a59 ff15???????? 85c0 }
condition:
- 7 of them and filesize <761856
+ 7 of them and filesize <229376
}
-rule MALPEDIA_Win_Redcurl_Auto : FILE
+rule MALPEDIA_Win_Maui_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "efe32a98-15fa-5dd0-a3ff-0a4fdcaec5ff"
+ id = "3b08a716-7f90-5bcd-af98-705f5527c8fd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redcurl"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redcurl_auto.yar#L1-L190"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maui"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maui_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "550bb424cec4343fdcbf9ff6b82c03a2bb6c5d2f01439a45b43da803dcee1f93"
+ logic_hash = "da972ed3bba518a07c1d6cad703f6be4a891f59859651a81726f8cacb62eabef"
score = 75
quality = 75
tags = "FILE"
@@ -155358,42 +162508,32 @@ rule MALPEDIA_Win_Redcurl_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c745f000000000 ff15???????? 8bd0 c7461000000000 8bca c746140f000000 }
- $sequence_1 = { 8bca c746140f000000 c60600 8d7901 }
- $sequence_2 = { 99 b91a000000 f7f9 80c261 88143e 47 }
- $sequence_3 = { 2bc6 48 50 56 }
- $sequence_4 = { ba???????? 660fd645e0 e8???????? 83c404 }
- $sequence_5 = { 48 3bc2 0f42d0 0fb6041a 03d3 }
- $sequence_6 = { ff15???????? 6a00 85c0 744b }
- $sequence_7 = { 50 e8???????? 8d0c3e 83c40c 3bf1 7410 0fb606 }
- $sequence_8 = { 6a00 0f434d08 8bf0 6a00 }
- $sequence_9 = { 0f57c0 c745dc00000000 68???????? ba???????? 660fd645d4 }
- $sequence_10 = { c745f001000000 e8???????? c745e800000000 c745ec0f000000 c645d800 8d5001 }
- $sequence_11 = { c745ec0f000000 c645d800 8d5001 8b4610 3bc2 726f }
- $sequence_12 = { 0154241c 894104 e9???????? 8b44241c }
- $sequence_13 = { 89542408 f7d0 0385e4fdffff 8995a4fbffff 8944240c }
- $sequence_14 = { 00c1 83da03 2b54241c 0f8444230000 8b7c241c }
- $sequence_15 = { 00c1 83db03 2b9d34fdffff 899d44fdffff }
- $sequence_16 = { 00c2 83de03 2bb500ffffff 89b530ffffff }
- $sequence_17 = { 00c1 83de03 29de 89b504feffff }
- $sequence_18 = { 00c1 8d8510feffff 83da03 89442404 }
- $sequence_19 = { 00c1 8b8300010000 83da03 29fa 7468 }
+ $sequence_0 = { 8b1b 895c2410 a810 0f841a010000 57 51 25c0000000 }
+ $sequence_1 = { 83c40c 85c0 7515 53 e8???????? 57 e8???????? }
+ $sequence_2 = { 83c404 5f 5b 5e 5d c3 8bce }
+ $sequence_3 = { c1e010 094610 0fb64101 41 99 0fa4c208 095614 }
+ $sequence_4 = { e8???????? 83c408 85c0 0f846b010000 3b5d20 8d4518 7e0a }
+ $sequence_5 = { 85c0 750a 68d0010000 e9???????? 8b542438 8b02 56 }
+ $sequence_6 = { e8???????? 83c40c 85c0 0f849b010000 8d442428 57 50 }
+ $sequence_7 = { 8bac24a4000000 f7463c00010000 753a 8b4628 8b10 89542460 8b5004 }
+ $sequence_8 = { 50 50 50 50 e8???????? 83c414 ff33 }
+ $sequence_9 = { e8???????? 53 89442438 8907 e8???????? 53 89442460 }
condition:
- 7 of them and filesize <487424
+ 7 of them and filesize <1616896
}
-rule MALPEDIA_Win_Punkey_Pos_Auto : FILE
+rule MALPEDIA_Win_Woody_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "846510df-399c-5c73-991a-33d5b6390d78"
+ id = "35fc0a5e-5caa-5b81-a357-ce6a48801a6d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.punkey_pos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.punkey_pos_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.woody"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.woody_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "afbb6da5e69098feb647a1b39faf19c917a9fcb87281ef711eecf3479b712e35"
+ logic_hash = "d359ba0a50d4da9f9c37f195345e1d8ee165deec7ea255ed2ce67ccf9ad5785a"
score = 75
quality = 75
tags = "FILE"
@@ -155407,32 +162547,32 @@ rule MALPEDIA_Win_Punkey_Pos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd7 a3???????? 85c0 74ae 5f }
- $sequence_1 = { 8bec 837d0c01 56 57 756b }
- $sequence_2 = { 837d0c01 56 57 756b 8b4508 }
- $sequence_3 = { ff15???????? 8bf0 85f6 7508 5f 33c0 5e }
- $sequence_4 = { 33c0 5e 5d c20c00 8b3d???????? }
- $sequence_5 = { 68e7070000 50 ff15???????? ff05???????? 8b0d???????? }
- $sequence_6 = { 55 8bec 8b4508 85c0 7919 8b4d10 8b550c }
- $sequence_7 = { 6a02 a3???????? ff15???????? a3???????? 33c0 }
- $sequence_8 = { 52 50 a1???????? 50 ff15???????? 5d c20c00 }
- $sequence_9 = { 8bf0 85f6 7508 5f 33c0 5e }
+ $sequence_0 = { 85c0 59 7412 8d4604 50 8d85e4feffff }
+ $sequence_1 = { 0f8501ffffff 53 ff15???????? a1???????? 85c0 7410 6860ea0000 }
+ $sequence_2 = { 8975ec 3bce 8b35???????? 894ddc 0f86b1000000 8d580a 8b4df4 }
+ $sequence_3 = { 8d8e10010000 c645fc01 e8???????? 8d8e18010000 c645fc02 e8???????? 8d8e20010000 }
+ $sequence_4 = { 50 e8???????? 8b45f4 83c424 813800000080 7239 8b75c8 }
+ $sequence_5 = { 59 5b 0f94c0 5f 5e c9 c20c00 }
+ $sequence_6 = { 48 0f8592000000 6a00 6a00 6a00 ff15???????? }
+ $sequence_7 = { 85db 7503 57 eb15 8d45fc 6a00 50 }
+ $sequence_8 = { 8945e0 294de0 894d14 8b45e0 8b4d14 03c1 8d4db0 }
+ $sequence_9 = { 3bcb 89442450 7412 8b8e0c010000 c74424540e000000 3bcb 7504 }
condition:
- 7 of them and filesize <499712
+ 7 of them and filesize <409600
}
-rule MALPEDIA_Win_Medusalocker_Auto : FILE
+rule MALPEDIA_Win_Rofin_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ffdd3261-a5ad-520b-a2bf-3c67ba3f2e25"
+ id = "1b07367d-380d-5a5b-bc33-dfe76ecfb58c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.medusalocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.medusalocker_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rofin"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rofin_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "1d388adf94671d416a3d4bdcd878fd62d77b06e7650d468b56f2c1b04655aed4"
+ logic_hash = "8597563e9ea27355f4e9d99fcf2f4a72dc9ad41d82ef13adb90824429264b4c0"
score = 75
quality = 75
tags = "FILE"
@@ -155446,32 +162586,32 @@ rule MALPEDIA_Win_Medusalocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8945e8 eb07 c745e800000000 8b4de8 894de4 c645fc02 }
- $sequence_1 = { 8b4dd4 e8???????? 83c048 50 8d55d8 }
- $sequence_2 = { e8???????? 33c0 8845bb c745c488020000 6888020000 e8???????? 83c404 }
- $sequence_3 = { 83c404 8b08 51 e8???????? 83c410 }
- $sequence_4 = { 8845d7 8b4d08 e8???????? 0fb6c8 85c9 0f85f6000000 8b5508 }
- $sequence_5 = { 8d45e8 50 8b4d0c 51 e8???????? 83c404 50 }
- $sequence_6 = { 33c0 8945e8 668945ec b902000000 6bd100 668b450c }
- $sequence_7 = { 894508 8b4d08 3b4d0c 7427 8b5508 }
- $sequence_8 = { 8965d8 8b45e4 83c00c 50 e8???????? e8???????? 8b4de4 }
- $sequence_9 = { 8b55e0 52 6a01 8b4df0 e8???????? c645fc03 8d8d38ffffff }
+ $sequence_0 = { 014df0 3b06 72b5 eb1a 8b45fc 69c01c010000 03c6 }
+ $sequence_1 = { 84c0 c706???????? 7417 8b4604 85c0 7410 }
+ $sequence_2 = { 8d442434 53 50 33d2 668b95d0030000 56 8d4c242c }
+ $sequence_3 = { c644244163 88542442 c644244528 885c2446 c64424473e c644244800 }
+ $sequence_4 = { 8b44240c 8b542404 83ec10 8d4c2400 53 50 }
+ $sequence_5 = { 83c408 3bf3 7420 8b4c2420 56 8b513c 52 }
+ $sequence_6 = { 72b5 eb1a 8b45fc 69c01c010000 03c6 81781000d00000 7506 }
+ $sequence_7 = { f3a4 8d4c246a 6800040000 51 6a00 ff15???????? }
+ $sequence_8 = { e8???????? eb73 bf???????? 83c9ff 33c0 f2ae f7d1 }
+ $sequence_9 = { 8b45fc 83481c10 8b45fc 89585c 8d45f4 }
condition:
- 7 of them and filesize <1433600
+ 7 of them and filesize <409600
}
-rule MALPEDIA_Win_Malumpos_Auto : FILE
+rule MALPEDIA_Win_Whispergate_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "011d5980-db12-575d-b128-68c240971c82"
+ id = "6714083d-3e17-55d3-a1f8-8bf9ddb1ef17"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.malumpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.malumpos_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.whispergate"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.whispergate_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "1d9a68f5cdfadc8f79ba4d8f4695a01ec544e2c566edbd712a7ed582b4a68976"
+ logic_hash = "32397ef108fba7d133f035121fc33f6fa3fbeba74a5870442ebf4d00a19bf608"
score = 75
quality = 75
tags = "FILE"
@@ -155485,32 +162625,32 @@ rule MALPEDIA_Win_Malumpos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85f6 7907 0d80000000 eb27 }
- $sequence_1 = { 53 50 c78500fdffff07000100 895d4c 895dcc e8???????? }
- $sequence_2 = { 59 8d45cc 50 ff15???????? 6a44 }
- $sequence_3 = { 0f1f00 0f1f00 0f1f00 0f1f00 6a72 }
- $sequence_4 = { 3bc8 0f86f1feffff ff770c 50 e8???????? }
- $sequence_5 = { 7805 0500000000 57 3500000000 }
- $sequence_6 = { 8a0432 3c3d 7506 8365fc00 eb0d }
- $sequence_7 = { e8???????? 68???????? a3???????? ffd0 810d????????00200000 be???????? c745f468e50300 }
- $sequence_8 = { 6683f300 55 51 7204 }
- $sequence_9 = { 8d4520 50 ff15???????? 8d4520 }
+ $sequence_0 = { 89d0 80f92f 0f846b060000 80f95c 0f8462060000 8d50ff }
+ $sequence_1 = { 0f8409010000 83fb2f 0f8400010000 83fb5c }
+ $sequence_2 = { f6044840 0f8448ffffff 397dcc 7275 8b45d0 85c0 756e }
+ $sequence_3 = { 53 31c0 0fa2 85c0 0f84db000000 }
+ $sequence_4 = { 85ed 75d3 8b542420 8b742424 }
+ $sequence_5 = { 55 57 56 53 81ec2c010000 8b842440010000 85c0 }
+ $sequence_6 = { 75e8 890424 e8???????? 89c7 8b44241c }
+ $sequence_7 = { 56 53 83ec10 8b742420 813e???????? 740e }
+ $sequence_8 = { e9???????? 837dd427 0f84e4000000 83c001 }
+ $sequence_9 = { 83c001 85c9 751e 83fa2a 7444 83fa3f 743f }
condition:
- 7 of them and filesize <542720
+ 7 of them and filesize <114688
}
-rule MALPEDIA_Win_Parallax_Auto : FILE
+rule MALPEDIA_Win_Grateful_Pos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3331f8f9-ca97-5323-a8b7-4a2a5bd3b734"
+ id = "142dbaaf-bae9-512b-8e1e-de26b0ad1d45"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.parallax"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.parallax_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grateful_pos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grateful_pos_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "2375ab4fbfb357ff0388c05531234fe1711b2c1ab93377989bbf9dcbb0552a8e"
+ logic_hash = "bd00e16b742e3f98f3581779e2ac022b9c7b51a75c5cf9f592cacfe60dca60a5"
score = 75
quality = 75
tags = "FILE"
@@ -155524,32 +162664,38 @@ rule MALPEDIA_Win_Parallax_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8dbf8c000000 b934000000 f3a4 5e 56 ff7508 }
- $sequence_1 = { ff7508 ff9698010000 5e 5d c21400 55 8bec }
- $sequence_2 = { 8b5234 83c234 8915???????? 83be1801000000 7545 83be1801000000 7401 }
- $sequence_3 = { ff763c 683c800000 ff35???????? ff92e0010000 6a00 }
- $sequence_4 = { 7411 8b75ec 8b7de0 8b4de8 f3a4 }
- $sequence_5 = { 85c0 7418 8bf8 8b35???????? b8ffffffff f0874704 50 }
- $sequence_6 = { 6a00 ff9628010000 6a04 68???????? }
- $sequence_7 = { e9???????? 3d34800000 750d ff7514 ff7510 e8???????? eb6d }
- $sequence_8 = { 8b5634 83c234 52 52 }
- $sequence_9 = { 83e934 8b4734 83c034 8b15???????? 50 51 ff92dc000000 }
+ $sequence_0 = { eb07 b8fcffffff eb02 33c0 }
+ $sequence_1 = { 7407 b8f6ffffff eb02 33c0 }
+ $sequence_2 = { e8???????? 99 b980ee3600 f7f9 }
+ $sequence_3 = { 7411 e8???????? e8???????? 33c0 e9???????? }
+ $sequence_4 = { e8???????? 83f801 7510 e8???????? e8???????? }
+ $sequence_5 = { eb1a b8fdffffff eb13 b8fcffffff }
+ $sequence_6 = { 8bb5f4fffdff 03b5f8fffdff c1ee03 8b4508 8b7810 }
+ $sequence_7 = { 6810040000 ff15???????? 8985f4fbffff 83bdf4fbffff00 0f8488010000 8a0d???????? }
+ $sequence_8 = { 83fa7b 750a 6a01 e8???????? }
+ $sequence_9 = { 8b4dfc 894110 8b550c 8b420c c1e803 50 }
+ $sequence_10 = { c745fcffffffff 8d45f4 64a300000000 c3 6a03 e8???????? 59 }
+ $sequence_11 = { 7c62 8b8df8fffdff 0fb6940dfefffdff 83fa3a 7d4f 8b85f8fffdff }
+ $sequence_12 = { 6bc02a 05???????? 50 e8???????? 83c40c 85c0 7509 }
+ $sequence_13 = { 85c0 0f84b2000000 6a03 68???????? 8b8de0fbffff 83e90e }
+ $sequence_14 = { 8884248e010000 b801000000 486bc03f 488d0d79e50100 0fbe0401 83f04d 8884248f010000 }
+ $sequence_15 = { 488bcd 418bd7 e8???????? 33c9 85c0 0f85bb010000 4c8d35ee481900 }
condition:
- 7 of them and filesize <352256
+ 7 of them and filesize <3964928
}
-rule MALPEDIA_Win_Kegotip_Auto : FILE
+rule MALPEDIA_Win_Arik_Keylogger_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "00ad7f0a-dc8e-510c-a1d3-35279f77a6e7"
+ id = "85657a12-5353-59c6-96c2-3cad36ac8818"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kegotip"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kegotip_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.arik_keylogger"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.arik_keylogger_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "32b69314873829a2218a5374ade1e7ef8ad560cb68aa690aa8ede1fd50d9aa93"
+ logic_hash = "f00c46b1c19068a9b1d9eb23a1cbe0ffd294a87bebb3732b435039b4cebfac37"
score = 75
quality = 75
tags = "FILE"
@@ -155563,32 +162709,32 @@ rule MALPEDIA_Win_Kegotip_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb6d e9???????? eb63 c745f400000000 }
- $sequence_1 = { e8???????? 83c40c c705????????94000000 68???????? }
- $sequence_2 = { 83c201 8955ec 8b45f8 83c004 8945f8 }
- $sequence_3 = { 89420c 8b4dfc c7412400000000 8b55fc a1???????? 894210 6a10 }
- $sequence_4 = { 8b55f8 83c201 8955f8 ebe0 8b45f8 0fbe08 }
- $sequence_5 = { 6800100000 6800000800 6a00 ff15???????? 8945fc 837dfc00 7504 }
- $sequence_6 = { 0f8592000000 8b4508 0345e8 0fb648ff 51 }
- $sequence_7 = { 52 8b4508 50 8d4df4 51 6a00 68???????? }
- $sequence_8 = { 8b85fcfdffff 0fbe8c0500feffff 83f97a 7f1e 8b95fcfdffff 0fbe841500feffff 83e820 }
- $sequence_9 = { 8d85b0feffff 50 6a00 8d8dd8feffff 51 ff15???????? }
+ $sequence_0 = { 8b45fc f7402801000000 755a 8b45fc 8b55fc 8b12 ff927c040000 }
+ $sequence_1 = { dd5df8 e8???????? ba???????? 8d45c0 e8???????? 58 85c0 }
+ $sequence_2 = { 8b804c010000 e8???????? e8???????? 84c0 7424 8b45f8 8b804c010000 }
+ $sequence_3 = { b003 e9???????? b004 e9???????? b005 e9???????? b006 }
+ $sequence_4 = { e8???????? 8b45ec 8908 8b45f0 8b08 034df4 7105 }
+ $sequence_5 = { e8???????? 50 85c0 0f8528010000 8b45b8 e8???????? c745b400000000 }
+ $sequence_6 = { eb16 8b45fc 8b4004 0d00001000 0d00002000 8b55fc 894204 }
+ $sequence_7 = { f3a5 8b45f4 83b8d002000000 7432 8b45f8 50 8b4518 }
+ $sequence_8 = { 8b45f4 e8???????? 8b45f4 83c024 8a4d08 8d55ec e8???????? }
+ $sequence_9 = { 8d45d4 e8???????? c745d400000000 8d45d0 e8???????? c745d000000000 8b4614 }
condition:
- 7 of them and filesize <278528
+ 7 of them and filesize <4947968
}
-rule MALPEDIA_Win_Manitsme_Auto : FILE
+rule MALPEDIA_Win_Amtsol_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e6602fda-fe01-560f-b18c-c680ffd15493"
+ id = "c4e6651d-976c-58ca-adc5-c02364c8423a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.manitsme"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.manitsme_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.amtsol"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.amtsol_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "d15a6ee2f4daf2c5f96b25b50dc747d6c2f7c5b49f115484153e22e9303b3c0c"
+ logic_hash = "27d50e01d30776676c026a6886e9d6b54d3f1024ee993525160ca52cbcf77c05"
score = 75
quality = 75
tags = "FILE"
@@ -155602,32 +162748,32 @@ rule MALPEDIA_Win_Manitsme_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4c2438 33cc e8???????? 83c440 c3 6a0b 68???????? }
- $sequence_1 = { 894c243c 894c2440 2bd0 8a08 880c02 83c001 84c9 }
- $sequence_2 = { 6a00 6804040000 68???????? 57 }
- $sequence_3 = { 83c408 eb09 57 e8???????? 83c404 8b15???????? 52 }
- $sequence_4 = { 8b35???????? 57 8b3d???????? 8da42400000000 8d442428 50 }
- $sequence_5 = { 8d442418 50 68fc030000 8d4c2424 }
- $sequence_6 = { 897c2420 ff15???????? 8b0d???????? 51 ff15???????? 6a02 }
- $sequence_7 = { 53 ff15???????? 68???????? 8d442418 50 c744241c401b0110 e8???????? }
- $sequence_8 = { 897c2420 c744241c01000000 ff15???????? 83f8ff 7434 8d4c2408 }
- $sequence_9 = { 8975e4 33c0 39b858340110 7467 ff45e4 }
+ $sequence_0 = { 33c8 234df0 8945fc 8b45f8 33cb 034e34 6a05 }
+ $sequence_1 = { 53 ff7580 ff7594 ff36 }
+ $sequence_2 = { 885d6f ff75d4 8d4510 50 8d4568 50 }
+ $sequence_3 = { 53 8b5d0c 8bce 2bde 3b7d10 7d23 }
+ $sequence_4 = { c645d543 c645d668 c645d765 c645d863 c645d96b c645da3a 885ddb }
+ $sequence_5 = { 8bec 8b4508 33c9 3bc1 7504 33c0 5d }
+ $sequence_6 = { ff15???????? 83f8ff 752b 8d45e8 50 c645e823 c645e92d }
+ $sequence_7 = { 85c0 7524 a1???????? a3???????? a1???????? c705????????b2194100 8935???????? }
+ $sequence_8 = { 0f84bf000000 56 53 50 e8???????? 56 }
+ $sequence_9 = { e8???????? 8d443001 59 895df4 3818 0f8430010000 50 }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <335872
}
-rule MALPEDIA_Win_Industroyer2_Auto : FILE
+rule MALPEDIA_Win_Bid_Ransomware_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "01c28e59-8cb1-5bf1-9de6-64ce0dd77d4a"
+ id = "123f6d77-eca2-5400-ac56-e3f30e76b796"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.industroyer2"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.industroyer2_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bid_ransomware"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bid_ransomware_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "bbf01a0f560944dbb85cdfc8fdeff74a884348b77c6b1a1a74790ea421be78c4"
+ logic_hash = "040b1903110ce367e4f39e634882ebba58d8e30bf0983ec0eaeaeca56a956f74"
score = 75
quality = 75
tags = "FILE"
@@ -155641,32 +162787,32 @@ rule MALPEDIA_Win_Industroyer2_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 732c 837df800 7426 8b45fc 8b4df4 8b1481 89559c }
- $sequence_1 = { 89480c 8b55fc 8b451c 894210 694d18a0860100 034d1c }
- $sequence_2 = { eb07 c745d000000000 8b4508 8a4dd0 888845000100 }
- $sequence_3 = { 8b4d08 e8???????? 8945fc 68???????? 8b4508 50 }
- $sequence_4 = { 885103 8b45fc 8b4804 8b551c 8b8238000100 894104 8b4dfc }
- $sequence_5 = { c1e200 8b45fc 8b4d08 8a1411 885005 b801000000 d1e0 }
- $sequence_6 = { 8b4df0 51 ff15???????? 85c0 7406 c645ff01 eb04 }
- $sequence_7 = { c6400c00 8b4dfc c641140a 6a04 8b55fc 83c210 52 }
- $sequence_8 = { 837df800 742c 8b55fc 8b45f4 8b0c90 898d78ffffff 8b9578ffffff }
- $sequence_9 = { 8b45fc 50 e8???????? 0fb6c8 85c9 7444 68???????? }
+ $sequence_0 = { c705????????20202020 68???????? 50 e8???????? }
+ $sequence_1 = { 6a00 e8???????? ff75fc e8???????? c9 c3 }
+ $sequence_2 = { ff75b0 e8???????? ff75b0 e8???????? 6800800000 ff75a8 }
+ $sequence_3 = { 55 8bec 83c4f4 6800800000 6a40 }
+ $sequence_4 = { 881f 83c701 83f800 77e3 eb0e }
+ $sequence_5 = { 8b4d08 80c141 c745c05c5c3f5c 884dc4 c745c53a5c2a2e }
+ $sequence_6 = { 53 6a00 6a00 6a00 ff75e4 e8???????? }
+ $sequence_7 = { 8945f0 eb15 ff75f4 e8???????? }
+ $sequence_8 = { 68ea030000 ff35???????? e8???????? 8945fc }
+ $sequence_9 = { e8???????? 8b85acfdffff 83e001 7414 8b7508 }
condition:
- 7 of them and filesize <100352
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Fanny_Auto : FILE
+rule MALPEDIA_Win_Madmax_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cd0c75da-8b4c-5363-98ec-15a67064033c"
+ id = "230eedbf-6cae-5fdd-90b6-aea0b58f95e1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fanny"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fanny_auto.yar#L1-L171"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.madmax"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.madmax_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "415f51a7b92a8dd2e587e9f69b01a611a89ad0fc5dace80d2d81091a3ef0d182"
+ logic_hash = "8fadf42f6b346841d23791b849b5705de38f9f89679dc44544ef7b477d437506"
score = 75
quality = 75
tags = "FILE"
@@ -155680,38 +162826,32 @@ rule MALPEDIA_Win_Fanny_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b45c0 85c0 7422 8935???????? 6a00 }
- $sequence_1 = { 8955d0 0fb645cf 3de9000000 7423 0fb64dcf }
- $sequence_2 = { 8b4dfc 8b11 52 ff15???????? 85c0 7502 }
- $sequence_3 = { 53 ff15???????? 8bf0 83c420 85f6 0f846a010000 }
- $sequence_4 = { 8b450c 8945d4 c745c400000000 8b4dc4 3b4dd0 7d26 6a00 }
- $sequence_5 = { 53 ff15???????? 8bf0 85f6 7420 6a03 }
- $sequence_6 = { eb05 1bc0 83d8ff 85c0 7517 8b842418010000 }
- $sequence_7 = { eb57 8b450c 8a4dd0 88481f 8b55d0 52 8b4510 }
- $sequence_8 = { 8b4dfc c7410c00000000 ff15???????? 8b55fc }
- $sequence_9 = { 53 ff15???????? be00000200 56 }
- $sequence_10 = { 5b c9 c3 80a5dcfeffff00 }
- $sequence_11 = { 50 e8???????? 83c424 eb03 8b7508 }
- $sequence_12 = { 53 ff15???????? 8d85e8fdffff 50 ff15???????? }
- $sequence_13 = { 6800400000 6a00 ff15???????? 897c2410 56 }
- $sequence_14 = { 53 ff15???????? 8bf0 59 85f6 0f84e9000000 8a4508 }
- $sequence_15 = { 33c0 83e103 f3a4 8b13 8b4d00 85d2 760e }
+ $sequence_0 = { d0cd 99 86d6 4c ae 2f 4e }
+ $sequence_1 = { b80c32e173 8ac5 08679e fb 59 8050cb80 baef812a0a }
+ $sequence_2 = { e07d d8cc 6a55 60 25a237f301 4a 4c }
+ $sequence_3 = { 8d8dd0feffff e8???????? 8db396000000 6a3b 9c f605????????d6 0f851c010000 }
+ $sequence_4 = { 93 9f 856d67 664c 8657b6 49 152b9be0c2 }
+ $sequence_5 = { d9dd 095527 17 44 4b 60 1f }
+ $sequence_6 = { f723 56 c8d95bcc 0e 64a04d98f5db 6e 051e079cc8 }
+ $sequence_7 = { ad 7ea5 6abd 650e 9c 3528e563a7 6c }
+ $sequence_8 = { f605????????e2 0f851d010000 73e7 f22486 85e6 210a e788 }
+ $sequence_9 = { f605????????a5 7531 df2e 8b1b f8 b36a 7928 }
condition:
- 7 of them and filesize <368640
+ 7 of them and filesize <3227648
}
-rule MALPEDIA_Win_Loup_Auto : FILE
+rule MALPEDIA_Win_Greetingghoul_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f9d1b576-d285-5231-afcb-2e4f16800d77"
+ id = "b976275f-692f-5ebe-b54a-1ebae523b638"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.loup"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.loup_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.greetingghoul"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.greetingghoul_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "ff0573e37f479d8813fb50aaed8f812906a0bad4de56fabb213fa961c6890498"
+ logic_hash = "0a3e95007607705383664f43202a90a64da5b8da6ba3c7b7040fd8c369e8d944"
score = 75
quality = 75
tags = "FILE"
@@ -155725,32 +162865,32 @@ rule MALPEDIA_Win_Loup_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c404 85c0 741c 0fb745f4 50 e8???????? }
- $sequence_1 = { 81781422059319 740c 8b4dfc 81791400409901 7522 e8???????? 8b55fc }
- $sequence_2 = { 8b0d???????? 898dc8fbffff 8b15???????? 8995ccfbffff a1???????? 8985d0fbffff }
- $sequence_3 = { 8b85d0f1ffff 53 56 ff3485647b4100 50 }
- $sequence_4 = { 8b7508 57 85d2 744f 33ff 393a }
- $sequence_5 = { 81f247656e75 b804000000 6bc803 8b440de0 35696e6549 }
- $sequence_6 = { 8b4df4 84c0 0f84defeffff c745dc01000000 e9???????? 5f 5e }
- $sequence_7 = { 668945e8 33c0 668945ea c745ee01000000 b804000000 668945ec }
- $sequence_8 = { b804000000 c1e002 c784055cffffff01000000 8d855cffffff 8945d5 }
- $sequence_9 = { 85c0 7443 0fb745f4 50 }
+ $sequence_0 = { 56 57 8bf9 33f6 8a17 80fa20 }
+ $sequence_1 = { 750d 8a5702 83c702 bb10000000 }
+ $sequence_2 = { 03f1 eb03 83ceff 8a17 84d2 75a9 }
+ $sequence_3 = { 2bc8 7409 8b7df8 4e 43 }
+ $sequence_4 = { 751f 41 84c0 7405 83ea01 75eb 8b5dfc }
+ $sequence_5 = { 43 895dfc 47 eba7 5f 5e 83c8ff }
+ $sequence_6 = { 8a1a 8d5201 8a08 3acb 750c 40 84c9 }
+ $sequence_7 = { 33db 895dfc 8945f4 3806 740b }
+ $sequence_8 = { 83c404 891e 85db 746f 8b7508 0f57c0 57 }
+ $sequence_9 = { 7457 8d42d0 3c09 7708 }
condition:
- 7 of them and filesize <257024
+ 7 of them and filesize <696320
}
-rule MALPEDIA_Win_Hotcroissant_Auto : FILE
+rule MALPEDIA_Win_Darkmegi_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "250e256f-bf01-5062-b0b5-f902754e1ec1"
+ id = "b4298044-373c-5ebc-af72-71a8178891f9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hotcroissant"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hotcroissant_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkmegi"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkmegi_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "2f7df521e2093bda16bb20427bf0af1885ac8e8db0533585bb878e9befdcfdd1"
+ logic_hash = "594b35440f1c502a0c2d0a5e3fa86f0d3dc6b2f476ed2e839ff20aa39301e384"
score = 75
quality = 75
tags = "FILE"
@@ -155764,34 +162904,34 @@ rule MALPEDIA_Win_Hotcroissant_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c705????????01000000 ffd6 6800040000 68???????? }
- $sequence_1 = { 68???????? 68???????? 68???????? c705????????0c000000 c705????????00000000 c705????????01000000 }
- $sequence_2 = { 25ff7f0000 33c9 7707 3d00400000 7608 6a0a ff15???????? }
- $sequence_3 = { 83e780 c1e307 33fb c1e711 c1e808 46 0bc7 }
- $sequence_4 = { 85c0 7506 6a0a ffd6 }
- $sequence_5 = { 6a00 68703a0000 6a00 50 ffd7 85c0 }
- $sequence_6 = { e8???????? 6a00 c705????????00000000 ff15???????? 6a00 }
- $sequence_7 = { 8d958cc5ffff 52 50 ff15???????? 85c0 }
- $sequence_8 = { ff15???????? 85c0 7506 6a0a }
- $sequence_9 = { 56 6a01 50 ff15???????? a1???????? }
+ $sequence_0 = { 81c43c010000 c3 8b442448 6a00 6a00 50 }
+ $sequence_1 = { c3 8b44244c 56 3d50450000 7411 }
+ $sequence_2 = { 3db7000000 7517 56 ff15???????? 56 }
+ $sequence_3 = { ff15???????? 83c40c 8d4c2464 8d942478050000 8d442444 }
+ $sequence_4 = { 8b548c2c 668b02 50 ffd5 }
+ $sequence_5 = { 0fb6d2 f6820196b40204 7403 40 }
+ $sequence_6 = { 49 6a01 8dbc0ca9030000 ffd6 6a01 }
+ $sequence_7 = { 81e1ffff0000 3bc1 0f8c9bfeffff 33db 8b94249e030000 }
+ $sequence_8 = { 52 e8???????? 83c404 8bd8 85f6 7426 }
+ $sequence_9 = { 33c0 5e 83c468 c21000 e8???????? }
condition:
- 7 of them and filesize <591872
+ 7 of them and filesize <90304
}
-rule MALPEDIA_Win_Agent_Btz_Auto : FILE
+rule MALPEDIA_Win_Meduza_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bbd1b361-56e8-5c44-8191-97b61949c3a6"
+ id = "e4f4d329-00f5-5eac-b6fa-1a17dabc236f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_btz"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.agent_btz_auto.yar#L1-L506"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.meduza"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.meduza_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "2cf1b97d42e6d02bf37e0a76317aec03ba7908a0448935a35dc2a10793f4265a"
+ logic_hash = "5c31e3491e238f84a3f72990d6fa7fa5c8ed914b3efa6ee6f598848d375c51b9"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -155803,82 +162943,32 @@ rule MALPEDIA_Win_Agent_Btz_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c74608ffffffff f644240801 7409 56 e8???????? 83c404 8bc6 }
- $sequence_1 = { ffd6 8d54240c 52 ffd7 }
- $sequence_2 = { ffd3 85c0 75d8 5f 5e 5b }
- $sequence_3 = { ff15???????? b800000f00 8b4df4 64890d00000000 }
- $sequence_4 = { c706???????? c7460c00000000 895e08 895e04 }
- $sequence_5 = { b805000f00 8b4df4 64890d00000000 5f 5e }
- $sequence_6 = { 895e08 895e04 c7461000000000 895e14 }
- $sequence_7 = { 56 6a00 68???????? 8935???????? }
- $sequence_8 = { 8b4608 c706???????? 85c0 7413 }
- $sequence_9 = { 83f8ff 740e 50 ff15???????? c74608ffffffff f644240801 }
- $sequence_10 = { 8d542408 52 c744240c30000000 c744241003000000 }
- $sequence_11 = { 6801010000 ff15???????? 85c0 7415 }
- $sequence_12 = { 51 6a00 6819000200 6a00 68???????? }
- $sequence_13 = { 6a0a 68???????? 6a01 6a00 }
- $sequence_14 = { 50 68???????? 6a01 68???????? e8???????? 83c410 }
- $sequence_15 = { 6a01 6a04 6a01 68???????? }
- $sequence_16 = { 68???????? 6a01 e8???????? 50 e8???????? 83c41c }
- $sequence_17 = { 89461c 3dea000000 740b 3de5030000 }
- $sequence_18 = { 7511 e8???????? 83c020 50 e8???????? }
- $sequence_19 = { 6a01 68???????? e8???????? 83c414 5f 5e }
- $sequence_20 = { 50 e8???????? 83c408 6800010000 e8???????? }
- $sequence_21 = { 0fb605???????? 66890d???????? 0fb60d???????? 660fafca 6603c8 }
- $sequence_22 = { 59 6a69 66894de8 59 }
- $sequence_23 = { 5e 8bc3 5b c9 c3 83c8ff eb11 }
- $sequence_24 = { c684248d00000065 c684248e00000050 c684248f00000072 c68424900000006f c684249100000063 c684249200000065 }
- $sequence_25 = { c68424900000006f c684249100000063 c684249200000065 c684249300000073 c684249400000073 c684249500000057 c684249600000000 }
- $sequence_26 = { c684248800000043 c684248900000072 c684248a00000065 c684248b00000061 c684248c00000074 c684248d00000065 c684248e00000050 }
- $sequence_27 = { 57 53 897dfc 897e1c }
- $sequence_28 = { 59 6a65 668945f0 66894dec 59 6a25 58 }
- $sequence_29 = { 59 6a70 66894dea 59 }
- $sequence_30 = { c684241601000074 c684241701000045 c684241801000072 c684241901000072 c684241a0100006f c684241b01000072 }
- $sequence_31 = { ebd2 c78424a000000068000000 c78424dc00000001000000 33c0 66898424e0000000 }
- $sequence_32 = { c684249600000000 c684241001000047 c684241101000065 c684241201000074 c68424130100004c c684241401000061 }
- $sequence_33 = { 59 6a70 66894de4 8bc8 }
- $sequence_34 = { 51 6a05 ff75fc 897df0 }
- $sequence_35 = { c684241201000074 c68424130100004c c684241401000061 c684241501000073 c684241601000074 c684241701000045 c684241801000072 }
- $sequence_36 = { 6a00 6a27 6a02 6a00 6a01 }
- $sequence_37 = { 8d8505feffff 50 e8???????? 83c40c }
- $sequence_38 = { c645d316 c645d43a c645d53b c645d63b }
- $sequence_39 = { c645cb30 c645cc27 c645cd3b c645ce30 }
- $sequence_40 = { 488b4338 33d2 488bce 448d4220 }
- $sequence_41 = { 488b4608 488b0e 48894628 488b4638 4c8d4c2450 448bc3 488bd7 }
- $sequence_42 = { 4533c9 488bd6 ff90c8010000 8bf8 85c0 }
- $sequence_43 = { 488b4638 488b0e 4c8d442450 4533c9 }
- $sequence_44 = { 488bf0 c70005000000 85db 7415 4c8b4f38 }
- $sequence_45 = { 488b0f 48894108 488b0f 488b4108 48894128 488b0f }
- $sequence_46 = { 83c904 c1e803 448bc9 440fafc8 }
- $sequence_47 = { 488bcf c744242088130000 e8???????? 488b5738 }
- $sequence_48 = { 488b0f 488901 488b07 488338ff }
- $sequence_49 = { 488bce 8bd8 ff92e8010000 488b6c2458 8bc3 488b5c2450 }
- $sequence_50 = { 488b0f 894130 eb06 488b07 896830 }
- $sequence_51 = { 488b07 896830 33c0 488b5c2458 }
- $sequence_52 = { 8d8594faffff 50 68???????? ff15???????? }
- $sequence_53 = { 013d???????? 8b04b5100b4200 0500080000 3bc8 }
- $sequence_54 = { 0304b5100b4200 59 5e eb05 }
- $sequence_55 = { 001cbe 40 0023 d18a0688078a 46 }
- $sequence_56 = { 030c85100b4200 eb02 8bcb f6412480 }
- $sequence_57 = { 0304b5100b4200 59 eb02 8bc3 }
- $sequence_58 = { 0304b5100b4200 59 eb05 b8???????? }
- $sequence_59 = { 0304b5100b4200 beffff0000 59 59 }
+ $sequence_0 = { ff75c8 8d55ac c645fc01 8d8d78ffffff e8???????? 83c404 8d4d94 }
+ $sequence_1 = { c645fc23 c785f8eaffff02000000 c78548f8ffff3ebfeb85 c7854cf8ffff59dea06d 8b8548f8ffff 8b8d4cf8ffff 898d04f3ffff }
+ $sequence_2 = { 83c408 c645fc15 8b4590 3b4580 0f84e9020000 66660f1f840000000000 8d7020 }
+ $sequence_3 = { 8d45e0 c645fc02 50 e8???????? 8b4de4 83c404 8bf8 }
+ $sequence_4 = { 898538f4ffff 898d3cf4ffff c785d8f6ffffdf03fddd c785dcf6ffffe227d929 8b85d8f6ffff 8b8ddcf6ffff 898540f4ffff }
+ $sequence_5 = { 898de4feffff 8985e0feffff c78558ffffff0d5f1759 c7855cfffffff2314621 8b8558ffffff 8b8d5cffffff 898decfeffff }
+ $sequence_6 = { c78548f8ffff68297235 c7854cf8ffff9d412b44 8b8548f8ffff 8b8d4cf8ffff 898dbcf5ffff 8985b8f5ffff c78548f8ffff5fcb84e8 }
+ $sequence_7 = { 898ddce7ffff c785d8e4ffffdf03fddd c785dce4ffffe227d929 8b85d8e4ffff 8b8ddce4ffff 8985e0e7ffff }
+ $sequence_8 = { e9???????? 807b0c00 0f8485010000 6a02 68???????? ff5004 8b4314 }
+ $sequence_9 = { c7854cf8ffff9d412b44 8b8548f8ffff 8b8d4cf8ffff 0f288d90f4ffff 898dfcfbffff 8d8d90f4ffff 8985f8fbffff }
condition:
- 7 of them and filesize <5577728
+ 7 of them and filesize <1433600
}
-rule MALPEDIA_Win_Rcs_Auto : FILE
+rule MALPEDIA_Win_Mrac_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "897f58a2-dc22-5f97-b551-4f423c0a43b4"
+ id = "f610a0ea-21d4-5420-9cb8-a0ef900d553a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rcs"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rcs_auto.yar#L1-L180"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mrac"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mrac_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "6868fef137d3b17f3a70ffb34345814aa00441ab2e72c702d2e7f970155b6f03"
+ logic_hash = "39e0c8c23990eee898b7d74c2127c69decfcb303742ac7378812e728f22f2f91"
score = 75
quality = 75
tags = "FILE"
@@ -155892,40 +162982,32 @@ rule MALPEDIA_Win_Rcs_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 6880000000 6a01 6a00 6a05 }
- $sequence_1 = { 8944245e 89442462 89442466 8944246a }
- $sequence_2 = { 85ff 0f84d4000000 57 e8???????? }
- $sequence_3 = { e8???????? 83c430 6aff 68???????? }
- $sequence_4 = { ff15???????? 5f 5e 5d 5b 33c0 }
- $sequence_5 = { 40 68???????? 50 e8???????? 83c40c eb0d }
- $sequence_6 = { 81f1f3221c6a 41 f7c7073ed86f f8 f9 }
- $sequence_7 = { 742d 8b7d08 8bbfdc000000 b81c010000 f765fc 8985c0feffff }
- $sequence_8 = { 81f1ff2fe523 80f973 66f7c5db7a f5 }
- $sequence_9 = { 83f907 773d ff248d6872f301 4f }
- $sequence_10 = { 8945f4 eb1c 8b86dc000000 8b9014120000 0fb7781c c1e704 8b3c17 }
- $sequence_11 = { 83f906 775c ff248d602ef001 c705????????803e0000 }
- $sequence_12 = { 6a0e 6a00 ff75dc e8???????? 83c40c }
- $sequence_13 = { 0fb7b810120000 c1e704 8b8d48f4fbff 83c103 0fb78c8870020000 c1e104 8b0c11 }
- $sequence_14 = { 8b37 81c6c8020000 56 ff75fc ff5704 }
- $sequence_15 = { 8b75ec 0375f8 8b5e0c 39df 7235 035e08 }
- $sequence_16 = { 8bbfdc000000 8b7730 897734 ff7518 }
- $sequence_17 = { 8b55fc 8b45f8 52 50 8b7d08 ff97a0000000 }
+ $sequence_0 = { 8d8c24d40a0000 6a0f 888424ea0a0000 e8???????? 346c 8d8c24d40a0000 6a10 }
+ $sequence_1 = { 8d8c24c8030000 e8???????? 046e 8d8c24c4030000 6a77 888424c8030000 e8???????? }
+ $sequence_2 = { 6a0a 88842475060000 e8???????? 3451 8d8c2464060000 6a0b 88842476060000 }
+ $sequence_3 = { c684240b07000079 c684240c07000079 c684240d0700007b c684240e0700007e c684240f0700007e c684241007000032 c68424110700003d }
+ $sequence_4 = { 8d8c249c000000 6a27 888424a8000000 e8???????? 0454 8d8c249c000000 6a27 }
+ $sequence_5 = { 041d 342f 8885a1fbffff 8b8580fbffff 041e 3471 8885a2fbffff }
+ $sequence_6 = { 8d4c2460 6a4f 88442470 e8???????? 0456 8d4c2460 6a4f }
+ $sequence_7 = { 3462 8845b0 8b459c 0411 346a 8845b1 8b459c }
+ $sequence_8 = { 3474 8d8c2414050000 6a06 88842421050000 e8???????? 346f 8d8c2414050000 }
+ $sequence_9 = { 040f 3472 88842433140000 8b842420140000 0410 3469 }
condition:
- 7 of them and filesize <11501568
+ 7 of them and filesize <745472
}
-rule MALPEDIA_Win_Pteranodon_Auto : FILE
+rule MALPEDIA_Win_Playwork_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "547312ac-3667-5c97-9fc9-daff4d88f305"
+ id = "18efebc1-2ecf-5ebd-a5ef-f5649e46ba89"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pteranodon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pteranodon_auto.yar#L1-L173"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.playwork"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.playwork_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "5752ea7e57aaa9393a80bd68b7b77d472dc2c58ad73fb0c8d5639c2a359a3d60"
+ logic_hash = "a4351b5bd2d1c3d515bb6fc22faeca44797e61833bdb6ed02e20384700f78521"
score = 75
quality = 75
tags = "FILE"
@@ -155939,38 +163021,32 @@ rule MALPEDIA_Win_Pteranodon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 394614 7320 51 50 8bce }
- $sequence_1 = { 8d8dc0f8ffff e9???????? 8d8dc0f8ffff e9???????? 8d8dc0f8ffff e9???????? 8d8d08f9ffff }
- $sequence_2 = { 59 83e03f 59 6bc838 8b04b5e0874300 03c1 }
- $sequence_3 = { 8d45f0 50 ff15???????? 83f802 7541 8d4df0 e8???????? }
- $sequence_4 = { 8b04f5b49b0210 5f 5e 5b 5d }
- $sequence_5 = { ffd0 0fb7f0 8bcf 8b07 8b4008 ffd0 }
- $sequence_6 = { c7869800000038c90210 c7460401000000 8b4dfc 5f 5e 33cd }
- $sequence_7 = { 0f8490000000 53 6a00 56 e8???????? }
- $sequence_8 = { 2bd0 d1fa 8d7902 668b01 83c102 }
- $sequence_9 = { 8d8d78f8ffff c645fc1e e8???????? 8b851cf9ffff 83f810 7213 40 }
- $sequence_10 = { 660f28aa802c4300 660f54e5 660f58fe 660f58fc 660f59c8 f20f59d8 }
- $sequence_11 = { 3bc1 7419 85c0 b001 }
- $sequence_12 = { 1bc0 23c1 83c008 5d c3 8b04c5849f4200 }
- $sequence_13 = { c3 8b04c58cbf0210 5d c3 }
- $sequence_14 = { c645fc0b 8d8df0f8ffff e8???????? 8d8d20f9ffff c645fc0c 03ce }
- $sequence_15 = { 53 e8???????? 83c404 8945ec 53 8bd8 }
+ $sequence_0 = { a801 7410 e8???????? 6a1a 99 59 }
+ $sequence_1 = { 3350fc 0fb6c9 8bf2 c1ee18 }
+ $sequence_2 = { 68???????? eb48 68???????? eb41 68???????? 8d85e8f7ffff 68???????? }
+ $sequence_3 = { 8b5008 89560c 8b500c 83e904 895610 0f8469010000 }
+ $sequence_4 = { 3dea000000 0f850e020000 8b5dfc 85db }
+ $sequence_5 = { 8bdf c1eb10 3330 83c010 8975dc 0fb6f3 }
+ $sequence_6 = { 8b4014 894618 8d4e1c c1c808 8bd8 8bd0 }
+ $sequence_7 = { 03c8 81f9ffff0000 7d04 56 53 ffd7 56 }
+ $sequence_8 = { 8d8594f7ffff 50 8d85f4fdffff 50 ff15???????? }
+ $sequence_9 = { 0fb6db 3370fc 8bce 8975f8 c1e918 8b3c8d34573f00 8b4df0 }
condition:
- 7 of them and filesize <499712
+ 7 of them and filesize <360448
}
-rule MALPEDIA_Win_Collectorgoomba_Auto : FILE
+rule MALPEDIA_Win_Cloudburst_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ee60f6dc-0e40-5600-9363-18addef799db"
+ id = "6b8a23fb-a80e-5e29-b2d9-5270c8f2c8ea"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.collectorgoomba"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.collectorgoomba_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cloudburst"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cloudburst_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "b5a8ed8c5e59ef8c9c917b7f2556669b4a98ddcbc5ddbd63af8e98206da01974"
+ logic_hash = "308a5032c7dd39db54565ddb9261de5bf1d032e66820b9bf51050b90dd0967a4"
score = 75
quality = 75
tags = "FILE"
@@ -155984,32 +163060,32 @@ rule MALPEDIA_Win_Collectorgoomba_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb91 8b450c 833801 7e04 834dfcff 837dfc00 7c1c }
- $sequence_1 = { 8b8084000000 8945fc 837dfc00 756e 8b4508 83787c00 7465 }
- $sequence_2 = { ff30 ff75f8 ff75fc ff7508 e8???????? 83c410 8b4508 }
- $sequence_3 = { 83c007 894588 ff758c ff7588 8d8528fdffff 50 8d4dc4 }
- $sequence_4 = { ffb574ffffff e8???????? 59 59 8845e6 8a45e6 8845e5 }
- $sequence_5 = { c705????????020a010d c705????????04050f01 833d????????00 740a c705????????04060b08 c705????????0206030b c705????????08050a0e }
- $sequence_6 = { ff704c 8b4508 ff30 e8???????? 59 59 8945d4 }
- $sequence_7 = { e8???????? 83c40c ebd1 33c0 40 c1e005 c64405d000 }
- $sequence_8 = { ff75fc e8???????? 59 59 ebad ff75d0 6a00 }
- $sequence_9 = { 8bec 83ec10 8b4508 8945f0 8b45f0 8b8018010000 8945f4 }
+ $sequence_0 = { 4533c2 4133e8 45894424f8 41896c24fc 8bc5 }
+ $sequence_1 = { 4883ec08 8b05???????? 41be01000000 4c892c24 85c0 }
+ $sequence_2 = { 4c892c24 85c0 4c8bd9 4c8bd2 410f44c6 4533ed }
+ $sequence_3 = { 488b0d???????? 488d542444 4533c9 4533c0 488bf8 418bdd ff15???????? }
+ $sequence_4 = { 458942f4 458b4c24f8 418bc1 c1e818 }
+ $sequence_5 = { ba00080000 488bcb e8???????? 4c8d442430 }
+ $sequence_6 = { 8b05???????? 41be01000000 4c892c24 85c0 4c8bd9 }
+ $sequence_7 = { 03c2 8bc8 83e00f 3bc2 7407 }
+ $sequence_8 = { 33d6 41891424 4133d3 33fa 4189542404 33df 41897c2408 }
+ $sequence_9 = { 41b904000000 4c8d442440 418d5101 ff15???????? 85c0 74b1 }
condition:
- 7 of them and filesize <1400832
+ 7 of them and filesize <2363392
}
-rule MALPEDIA_Win_Blackbasta_Auto : FILE
+rule MALPEDIA_Win_Backconfig_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5c8e56ab-6cbd-5deb-8276-9c7c1c51570f"
+ id = "18fd149c-ad9b-5433-8651-ac1dcd92de05"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackbasta"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackbasta_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.backconfig"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.backconfig_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "7b0b80b4e818e69a7ef8a8ed63d1384307760adc672033eb9b7389cd6b55895b"
+ logic_hash = "dc29e43fa81d60d5f53e6f4d5e158937c417e8f12650929b20d71338a8cb5ead"
score = 75
quality = 75
tags = "FILE"
@@ -156023,34 +163099,34 @@ rule MALPEDIA_Win_Blackbasta_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff7590 8bcf e8???????? 84c0 751f 384704 7507 }
- $sequence_1 = { 89b574ffffff 894588 89458c e8???????? 84c0 755d 384304 }
- $sequence_2 = { 5b 8b4df4 64890d00000000 8d656c 5d c3 8d4d30 }
- $sequence_3 = { e8???????? 83c404 85c0 0f849d010000 8d5823 83e3e0 8943fc }
- $sequence_4 = { c745e000000000 c745e40f000000 c645d000 c745fc00000000 ff734c e8???????? 83c404 }
- $sequence_5 = { b867666666 c645e800 f7ea c1fa05 8bc2 c1e81f 03c2 }
- $sequence_6 = { 85f6 7462 8b7d28 3bf7 7416 0f1f440000 8bce }
- $sequence_7 = { 56 e8???????? 83463008 83c410 0fb6c3 81c500020000 8b5c2474 }
- $sequence_8 = { 8d4dc0 e8???????? 837e1401 741a 837dec01 740d 8d45d8 }
- $sequence_9 = { 83c410 8bce 50 68???????? e8???????? 8bf0 c78574ffffff00000000 }
+ $sequence_0 = { a1???????? 8b0d???????? 8b15???????? 8985f0feffff a1???????? 6a51 8985fcfeffff }
+ $sequence_1 = { e8???????? 8b4de4 83c40c 6bc930 8975e0 8db1682a4100 }
+ $sequence_2 = { 8a15???????? 8d8569ffffff 6a00 50 898d64ffffff 889568ffffff }
+ $sequence_3 = { c1f805 8d1485c0504100 8b0a 83e61f c1e606 03ce }
+ $sequence_4 = { 8bc3 c1f805 8d3c85c0504100 8bf3 83e61f c1e606 8b07 }
+ $sequence_5 = { 8b0d???????? 8b15???????? 8985f0feffff a1???????? 6a51 8985fcfeffff 898df4feffff }
+ $sequence_6 = { 8d8d2cfdffff 68???????? 51 e8???????? 83c414 68401f0000 }
+ $sequence_7 = { 6a00 50 898d64ffffff 889568ffffff e8???????? }
+ $sequence_8 = { 8bf1 83e61f 8d3c85c0504100 8b07 c1e606 f644300401 7436 }
+ $sequence_9 = { 8bec 8b4508 56 8d34c550224100 833e00 7513 }
condition:
- 7 of them and filesize <1758208
+ 7 of them and filesize <217088
}
-rule MALPEDIA_Win_Vohuk_Auto : FILE
+rule MALPEDIA_Win_Maktub_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "411a3e2f-1751-5273-acfa-62305bd7fa2f"
+ id = "e3bef5b1-ffc5-599d-9917-312a2370b890"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vohuk"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vohuk_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maktub"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maktub_auto.yar#L1-L203"
license_url = "N/A"
- logic_hash = "2ed67cd931d1a068f4ca262bb4544ee71becc9ba564d979b0f2e30b12b56f8a3"
+ logic_hash = "e077a57d767e9de98d639131f563ec23078961a903d866aaf47969e99e6c3d2f"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -156062,32 +163138,44 @@ rule MALPEDIA_Win_Vohuk_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff35???????? 8d45ba 50 e8???????? 83c408 e9???????? c745b48f00a000 }
- $sequence_1 = { e8???????? c7451850000000 837d1800 7e20 33c9 8a840df4f9ffff 8d4901 }
- $sequence_2 = { 50 ff15???????? a3???????? 33f6 b818000000 c745b245007d00 c745b666006300 }
- $sequence_3 = { a3???????? c745b6b700b400 c745bab100fb00 c745be82009e00 c745c2f800f400 c745c6e400fb00 c745caf900b100 }
- $sequence_4 = { 8b0d???????? bac1655634 8b75f8 6892000000 e8???????? 8d4d94 51 }
- $sequence_5 = { 33c9 8d4900 8a840d48e6ffff 8d4901 88840d57ffffff 8b45fc 48 }
- $sequence_6 = { 85c0 7413 8b4b14 c6431c00 e8???????? 5f 5e }
- $sequence_7 = { 88840d57ffffff 8b45fc 48 8945fc 837dfc00 7fe2 8d85d8fcffff }
- $sequence_8 = { 8d45f2 803d????????01 8945dc 8d45ea 7403 }
- $sequence_9 = { c5fe6f4580 c4e37d4645a031 c5fe7f8080000000 c5fe6f85e0feffff c4e37d468500ffffff31 c5fe7f80a0000000 }
+ $sequence_0 = { ffd0 f7d8 1bc0 f7d8 8be5 }
+ $sequence_1 = { c7450c00000000 50 6a01 56 }
+ $sequence_2 = { ff30 8b86a4000000 ffd0 8b75b4 }
+ $sequence_3 = { ff30 8b83a4000000 ffd0 8b75d4 }
+ $sequence_4 = { ff7508 ffd7 50 ffd6 53 8b5d08 6af4 }
+ $sequence_5 = { ff30 8b8690000000 6a00 ffd0 }
+ $sequence_6 = { ff30 8b4704 6a00 56 ffd0 85c0 }
+ $sequence_7 = { c74508???????? e9???????? 50 ff15???????? 85c0 7f1e a1???????? }
+ $sequence_8 = { ff7004 ff30 e8???????? 8bc7 5f 5e }
+ $sequence_9 = { f8 39dc f5 f7de }
+ $sequence_10 = { f8 57 c64424084b 88442404 }
+ $sequence_11 = { f8 60 0145e0 f8 }
+ $sequence_12 = { f8 50 55 660fa3d5 }
+ $sequence_13 = { 8d4f0c e8???????? 8d4de8 e8???????? }
+ $sequence_14 = { 8d4f04 8b01 ff7508 ff5010 8bd8 }
+ $sequence_15 = { f8 3a07 6868c51b01 8d7f01 }
+ $sequence_16 = { 8d4f04 8b45f4 8b31 2bc2 }
+ $sequence_17 = { 8d4f04 e8???????? 8d5608 8d4f08 }
+ $sequence_18 = { 8d4f08 e8???????? 8d560c 8d4f0c e8???????? }
+ $sequence_19 = { 8d4f0c e8???????? 5f 5e 5d c20400 }
+ $sequence_20 = { f8 12644a00 40 d4b5 }
+ $sequence_21 = { 8d4f10 50 e8???????? 8d45f8 }
condition:
- 7 of them and filesize <260096
+ 7 of them and filesize <3063808
}
-rule MALPEDIA_Win_Conficker_Auto : FILE
+rule MALPEDIA_Win_Nachocheese_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3a6101de-ccfd-52f9-bf48-95f37d3da01a"
+ id = "eaa2162c-aba5-5a56-92b8-2694c1a819b5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.conficker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.conficker_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nachocheese"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nachocheese_auto.yar#L1-L162"
license_url = "N/A"
- logic_hash = "a2e85b8534ced36c659844072e09fbb061c134856a103a96122c39a859220309"
+ logic_hash = "65398c7b0a5280da9a71f8939ca7f529421377deec37e9f371d0deba7b01dc67"
score = 75
quality = 75
tags = "FILE"
@@ -156101,32 +163189,38 @@ rule MALPEDIA_Win_Conficker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ebe4 f60638 75a8 b008 d0ef 1400 }
- $sequence_1 = { df6de8 51 df6df8 51 }
- $sequence_2 = { 8bec 83ec20 8b0d???????? a1???????? 8365f800 56 }
- $sequence_3 = { 3c04 7415 42 42 60 b066 f2ae }
- $sequence_4 = { c3 6a10 68???????? e8???????? 68???????? ff15???????? }
- $sequence_5 = { 3345f8 33c7 33c6 50 ff15???????? 59 5f }
- $sequence_6 = { 8b4508 33d2 8910 895004 33c9 894c8808 41 }
- $sequence_7 = { 8d85f8fbffff ff7510 50 e8???????? }
- $sequence_8 = { 8954241c 61 c3 ac }
- $sequence_9 = { 55 8bec 83ec20 8b0d???????? a1???????? }
+ $sequence_0 = { 3d9c000000 7c07 3d9f000000 7e0d 33c0 c3 05d13fffff }
+ $sequence_1 = { 33f6 397508 0f8ec9000000 b8???????? 48 }
+ $sequence_2 = { 2bfa 8d47fd 3901 8901 }
+ $sequence_3 = { 02ca 880c3e 8a5005 32d1 8b4dfc 88143e 8a4c0105 }
+ $sequence_4 = { 7305 83c303 eb1c 81fb00000100 }
+ $sequence_5 = { 33c8 894710 8b4708 33c1 }
+ $sequence_6 = { 7305 83c304 eb0f 81fb00000001 }
+ $sequence_7 = { 7305 83c302 eb29 81fb00010000 }
+ $sequence_8 = { 0f8539ffffff b8???????? 8d5001 8a08 }
+ $sequence_9 = { 3d2cc00000 7f18 3d2bc00000 7d1b 3d9c000000 }
+ $sequence_10 = { 763a b801011000 f7e6 8bc6 2bc2 d1e8 }
+ $sequence_11 = { 0f84bf000000 6803010000 8895f0fcffff 8d95f1fcffff 6a00 52 e8???????? }
+ $sequence_12 = { 50 e8???????? 8d8f0e010000 8bc1 83c430 8d5001 }
+ $sequence_13 = { 02ca 8b55f4 880c3e 0fb6540205 }
+ $sequence_14 = { 50 e8???????? b9???????? 83c424 }
+ $sequence_15 = { 50 6a02 51 ff15???????? 83f801 }
condition:
- 7 of them and filesize <335872
+ 7 of them and filesize <1064960
}
-rule MALPEDIA_Win_Bumblebee_Auto : FILE
+rule MALPEDIA_Win_Starsypound_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2d631f7c-7434-5c27-9009-44b4e59637b5"
+ id = "70e37162-3a73-596a-8d7d-42b9d85b78f7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bumblebee"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bumblebee_auto.yar#L1-L109"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.starsypound"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.starsypound_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "5441d9d4140ebd43dfbd5141b1d6fd9472ec1ff4702b3388ec7d6ec403a89c52"
+ logic_hash = "abf4ae91c4287e1227ba24bd55f61dc3c1250c1b8b21f760166157e29806933f"
score = 75
quality = 75
tags = "FILE"
@@ -156140,30 +163234,32 @@ rule MALPEDIA_Win_Bumblebee_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb7570e 6623d1 740d 0fbe470d b90d000000 2bc8 }
- $sequence_1 = { 0f44c1 833c1800 7475 837c180400 746e 8b1418 488b05???????? }
- $sequence_2 = { 0f88cc000000 4863533c 488b05???????? 4803d6 4885c0 0f84b5000000 488d4c2430 }
- $sequence_3 = { 0f880c010000 488b7580 4885f6 0f84ff000000 488b05???????? 4885c0 0f84ef000000 }
- $sequence_4 = { 0f8895000000 8b7b28 b8c0000000 4803fe ba64860000 66395304 8d4810 }
- $sequence_5 = { 0fbec0 8d59e8 8d1c58 ffc2 }
- $sequence_6 = { 0f57c0 c744242800000008 4c8d45d0 488975d8 8d4640 488975e0 }
- $sequence_7 = { 0f8840010000 488b05???????? 4885c0 0f8430010000 488b542448 488d4c2438 48894c2420 }
+ $sequence_0 = { ff15???????? 8dbc2458010000 83c9ff 33c0 }
+ $sequence_1 = { 68???????? 52 e8???????? 83c420 85c0 7444 8b5304 }
+ $sequence_2 = { 53 56 57 6a18 e8???????? 8bb42424040000 }
+ $sequence_3 = { 8d4c2428 68???????? 51 e8???????? 56 8d542434 }
+ $sequence_4 = { 8bfd 8d44240c f3a5 8b5500 8b3d???????? 6a00 }
+ $sequence_5 = { 885c3438 c744241804010000 ff15???????? 8dbc2458010000 83c9ff 33c0 }
+ $sequence_6 = { 50 8d4c2424 56 51 52 }
+ $sequence_7 = { f3a4 885c0444 bf???????? 83c9ff 33c0 33f6 }
+ $sequence_8 = { 83c40c 85c0 7e2b eb08 }
+ $sequence_9 = { e8???????? 68c0270900 ff15???????? e8???????? 5f }
condition:
- 7 of them and filesize <4825088
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Sagerunex_Auto : FILE
+rule MALPEDIA_Win_Vskimmer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f1b502b3-b120-59e0-983f-cafb93914bcc"
+ id = "fc191c93-ce90-5418-a28d-2b3fa9eb623e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sagerunex"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sagerunex_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vskimmer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vskimmer_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "08cdcbbbd6ca868eddb1becc5a51582d041936061352010bb8c3c5ac48e633a5"
+ logic_hash = "81aef2465b53cd0c0e1b48561687f8c8208fd8d87041be709dd2217d8a17703f"
score = 75
quality = 75
tags = "FILE"
@@ -156177,69 +163273,71 @@ rule MALPEDIA_Win_Sagerunex_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4c8bb424d8010000 c744245001000000 4c896c2458 4c896c2460 4885c9 742c 4a8d04fd00000000 }
- $sequence_1 = { 72d1 498bd4 483bd7 488d4de7 480f42fa 488bd7 e8???????? }
- $sequence_2 = { c74324a44ffabe 488bcb 89b3e8000000 c70340000000 e8???????? 488d442420 c60000 }
- $sequence_3 = { 498bcc e8???????? 85c0 7849 488d45b0 488d55f0 498bcf }
- $sequence_4 = { e8???????? e8???????? ffc7 448bc0 b84fecc44e 41f7e8 c1fa03 }
- $sequence_5 = { 4d894838 4c8b5340 458bca 4983d300 49c1ea20 418bc9 4d0fafcf }
- $sequence_6 = { 894260 33d2 e8???????? 488d442470 488d15d0230300 }
- $sequence_7 = { 83f803 7cc5 eb04 897c2450 443bfe 752a 448b7c2444 }
- $sequence_8 = { 498bcf c745df02000000 c745fb01000000 c745e301000000 ff15???????? 85c0 7507 }
- $sequence_9 = { 4403c0 418bc6 4503c2 c1c007 c1ca0b 33d0 418bc6 }
+ $sequence_0 = { 3bc3 7402 8bf0 8bd6 f7da 8a07 }
+ $sequence_1 = { 68???????? 50 e8???????? 59 59 85c0 0f8445010000 }
+ $sequence_2 = { 33c0 0fbe84c188e54100 6a07 c1f804 59 }
+ $sequence_3 = { 75f8 ff36 e8???????? 59 8b4508 }
+ $sequence_4 = { 8b4508 8bf1 8b4d0c 8b7e04 }
+ $sequence_5 = { 5e 5b c3 8b94c110010000 8bb110020000 8b44c108 2bc6 }
+ $sequence_6 = { 3bd7 749c 8b8324020000 2580000000 0f95c0 0fb6c0 50 }
+ $sequence_7 = { 7e7b 8b460c ff36 03c7 50 }
+ $sequence_8 = { 7413 c685b3fdffff01 3bf3 7408 8b451c 8906 }
+ $sequence_9 = { 83e803 0f846a010000 48 7439 48 742d 8b4508 }
condition:
- 7 of them and filesize <619520
+ 7 of them and filesize <376832
}
-rule MALPEDIA_Win_Pocodown_Auto : FILE
+rule MALPEDIA_Win_Mmon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "57027d9b-6e81-5ca8-a0ac-bbfd288eda02"
+ id = "684efad9-d1d6-5ce6-b6e0-de65ea38db79"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pocodown"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pocodown_auto.yar#L1-L101"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mmon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mmon_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "d2d2c3510515a24653939603c26fb696816a72e2a82e1c859f658b0238b45291"
+ logic_hash = "fc9a1ffbaa9f24fc3223df86b9f3747f68822a1333ac4081d18094cd5050cf44"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { 8b84248c000000 ffc8 898424a0010000 c784248800000000000000 ba01000000 488b8c24e0010000 }
- $sequence_1 = { 8b84248c000000 ffc8 8984248c000000 83bc248c00000007 0f875d010000 486384248c000000 }
- $sequence_2 = { 8b842490000000 25ff000000 488b4c2430 884101 }
- $sequence_3 = { 8b84248c020000 8944244c 488b8c2420030000 e8???????? }
- $sequence_4 = { 8b842490000000 2500040000 85c0 740a c744245000000000 eb0a 8b442448 }
- $sequence_5 = { 8b84248c020000 448bc0 ba5c000000 488d8c24f0010000 e8???????? }
- $sequence_6 = { 8b84248c020000 448bc0 488d9424f0010000 488d8c24a0020000 e8???????? }
- $sequence_7 = { 8b842490000000 39442420 0f83e0000000 488d442438 41b808000000 488b542440 }
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { 8d04f5c8474200 8938 68a00f0000 ff30 }
+ $sequence_1 = { 8d45cc 50 c745ccc8e64100 e8???????? 8b7508 }
+ $sequence_2 = { 3c58 770f 0fbec2 0fb68020094200 }
+ $sequence_3 = { 6aff 53 6a00 6a00 8bf1 }
+ $sequence_4 = { 891d???????? ff15???????? 85c0 7577 8b15???????? }
+ $sequence_5 = { 40 0080af4000a4 af 40 }
+ $sequence_6 = { 8b44241c 83c404 50 ff15???????? 6880969800 e8???????? }
+ $sequence_7 = { 03f9 8bda 83feff 7fa7 b867666666 f7ef c1fa02 }
+ $sequence_8 = { eb0a c7854cffffff00000000 b802000000 018554ffffff 018548ffffff 03f8 }
+ $sequence_9 = { 64a300000000 8b7d0c 8b07 68???????? 51 50 }
condition:
- 7 of them and filesize <6703104
+ 7 of them and filesize <356352
}
-rule MALPEDIA_Win_Cuba_Auto : FILE
+rule MALPEDIA_Win_Aukill_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8e1fe25d-f2c0-551f-8e41-a3623d0fa4f8"
+ id = "a6d13b29-a1c3-5db7-ac5c-09009229e7b9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cuba"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cuba_auto.yar#L1-L166"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aukill"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aukill_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "9f0de113045e5c6c763dd8b7a39764d54e03c53f19ccc2d0320fdbbeb66fa89e"
+ logic_hash = "ebc3504ab44ddd68fe35d4be4361ca674b2d7f3006cec23148755c773291be1b"
score = 75
quality = 75
tags = "FILE"
@@ -156253,38 +163351,32 @@ rule MALPEDIA_Win_Cuba_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0019 43 41 00444341 }
- $sequence_1 = { ffb5fcfeffff ffb5fcfdffff ff15???????? 85c0 750d 8b95c0fbffff 53 }
- $sequence_2 = { 33d2 85c0 7e0c 807c95bc19 740c 42 3bd0 }
- $sequence_3 = { 85c0 0f84b4000000 8bbdc8fbffff 53 68???????? 8d85f0fbffff 50 }
- $sequence_4 = { 000d???????? 384100 b538 41 }
- $sequence_5 = { 0026 45 41 003a }
- $sequence_6 = { 85c0 750c 57 ff15???????? e9???????? 56 ff15???????? }
- $sequence_7 = { 0012 45 41 0026 }
- $sequence_8 = { 6a02 6a00 688b010000 ff75f4 ff15???????? ff75f4 f7d8 }
- $sequence_9 = { 757a ffb5d4fbffff 50 6800040000 }
- $sequence_10 = { 8945f4 8b4514 40 c745ecac9c4000 894df8 8945fc }
- $sequence_11 = { 0026 43 41 00b043410062 }
- $sequence_12 = { 000c43 41 0035???????? 43 }
- $sequence_13 = { 003a 45 41 004245 }
- $sequence_14 = { 03f0 c1ca16 8b85e0feffff 03b40510ffffff 03b0f4b14100 03b5e8feffff 8d0437 }
- $sequence_15 = { 000446 41 00d1 45 }
+ $sequence_0 = { 85c0 751f 488b4c2458 ff15???????? }
+ $sequence_1 = { 0fb7da 8bf9 e8???????? 4c8bc8 4533c0 }
+ $sequence_2 = { 4533c0 33d2 488bcb ff15???????? 85c0 7526 488bcb }
+ $sequence_3 = { 4889442420 ff15???????? 85c0 751f 488b4c2458 ff15???????? }
+ $sequence_4 = { 751d 488bcb ff15???????? ff15???????? }
+ $sequence_5 = { 4489442420 453b01 7346 4b8d1440 410f104cd108 0f114c2428 f2410f1044d118 }
+ $sequence_6 = { 448d4920 48894c2450 488b0d???????? 48897c2458 }
+ $sequence_7 = { 488bd3 33c9 ff15???????? 85c0 751f }
+ $sequence_8 = { 48895c2408 57 4883ec60 488bfa 8bd9 e8???????? 33c9 }
+ $sequence_9 = { ffc2 80f920 75ee 4c63c2 }
condition:
- 7 of them and filesize <1094656
+ 7 of them and filesize <446464
}
-rule MALPEDIA_Win_Orchard_Auto : FILE
+rule MALPEDIA_Win_Firechili_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "68833672-b2e1-5b37-9ae2-2dac96bba231"
+ id = "1e675a4c-a97c-5312-b559-588fd9dfae94"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.orchard"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.orchard_auto.yar#L1-L159"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.firechili"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.firechili_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "70c3ab090316ecb85f40208f530bb1fb9e1727e271d34e7cabe8cdcf998bd59f"
+ logic_hash = "39f362d1cc29968bda0685edf846cfad0cc3545d7d80fc48d26a5fd5a4bdf9c6"
score = 75
quality = 75
tags = "FILE"
@@ -156298,38 +163390,32 @@ rule MALPEDIA_Win_Orchard_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c404 e8???????? 99 b95b000000 f7f9 }
- $sequence_1 = { 6a01 c645fc08 e8???????? 894604 83c404 8d4718 897034 }
- $sequence_2 = { 56 ff15???????? ff15???????? 50 6a00 }
- $sequence_3 = { 8b8550fdffff 83e001 0f8412000000 83a550fdfffffe }
- $sequence_4 = { 8a45ef 884740 7510 8b470c 8bcf 6a00 }
- $sequence_5 = { 8d442410 50 ff15???????? 6685c0 }
- $sequence_6 = { 8b5de8 894348 8b5de0 c70600000000 }
- $sequence_7 = { 8b75a8 46 56 e8???????? }
- $sequence_8 = { 8b54240c 83d200 03c1 8b4c2420 }
- $sequence_9 = { f7f9 81c2d0070000 52 ffd6 }
- $sequence_10 = { 8b10 8bc8 6a01 ff12 837f3800 8a45ef }
- $sequence_11 = { 8b07 6a08 895de0 8b4004 }
- $sequence_12 = { 83f81f 0f877e030000 52 51 e8???????? }
- $sequence_13 = { 8b7c2424 89542428 8b54240c 83d200 }
- $sequence_14 = { 50 ff15???????? 83f805 7507 }
- $sequence_15 = { 8bc8 83e01f c1f905 8b0c8d00755d00 c1e006 8d44010c 50 }
+ $sequence_0 = { 7d11 48837c242000 7509 b201 33c9 e8???????? 33c0 }
+ $sequence_1 = { 488b7c2458 488b6c2460 4885f6 744e }
+ $sequence_2 = { 4533c0 4889742420 488d55f7 ff15???????? }
+ $sequence_3 = { c744242866730000 4533c0 33d2 48c744242008020000 ff15???????? c605????????01 488bd7 }
+ $sequence_4 = { 488b7c2430 488b742438 4c8b6c2428 498b442408 }
+ $sequence_5 = { c3 4c8bdc 4d894318 49895310 53 56 4883ec68 }
+ $sequence_6 = { 418bc6 81c200040000 4a393400 740c ffc1 48ffc0 483bc2 }
+ $sequence_7 = { 4889742458 418d5020 48897c2460 ff15???????? 8bf8 85c0 784b }
+ $sequence_8 = { 4c8bc1 488bc1 6690 66833800 }
+ $sequence_9 = { 488d05ff500000 c605????????01 488905???????? 488905???????? 4883c420 }
condition:
- 7 of them and filesize <4716352
+ 7 of them and filesize <91136
}
-rule MALPEDIA_Win_Hermes_Auto : FILE
+rule MALPEDIA_Win_Crylocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "61ab2fc1-04d0-5933-ac64-b12602279b7d"
+ id = "4bfc7917-6752-5365-845d-244ec08bbbad"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hermes"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hermes_auto.yar#L1-L111"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crylocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crylocker_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "9cfed48151b17cbf55d1481eb34069ea472830263b97aa44ce683b55da6f12b5"
+ logic_hash = "846ce0f815360303954c01156a8157bafbdde3bd263a1bdd7a06f8c9923993ce"
score = 75
quality = 75
tags = "FILE"
@@ -156343,32 +163429,32 @@ rule MALPEDIA_Win_Hermes_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a01 6810660000 ff75fc ff15???????? }
- $sequence_1 = { ff15???????? 33d2 6a79 59 f7f1 83c261 }
- $sequence_2 = { 6a01 ff15???????? 8d45fc 50 }
- $sequence_3 = { 8b4508 83c801 50 6a01 ff75fc }
- $sequence_4 = { 8b4508 83c801 50 6a01 ff75fc ff15???????? }
- $sequence_5 = { 50 8b4508 83c801 50 }
- $sequence_6 = { 6a04 6800100000 6888130000 6a00 }
- $sequence_7 = { 50 6a01 6810660000 ff75fc ff15???????? }
- $sequence_8 = { 6800100000 6888130000 6a00 ff15???????? }
- $sequence_9 = { 50 8d45fc 50 ff15???????? 6a20 }
+ $sequence_0 = { 51 8d542458 52 e8???????? 8d44245c }
+ $sequence_1 = { 50 e8???????? 8d4c2404 6a01 51 e8???????? }
+ $sequence_2 = { 6a03 50 e8???????? 8b5c2448 8b0b 51 8d54243c }
+ $sequence_3 = { 68???????? 53 e8???????? 83c408 53 85c0 7440 }
+ $sequence_4 = { 85c0 750b 5b b8f9ffffff 5d 83c410 c3 }
+ $sequence_5 = { 8d442430 50 e8???????? 8d4c2434 68???????? 51 e8???????? }
+ $sequence_6 = { 50 50 8b44244c 50 6a00 6a00 56 }
+ $sequence_7 = { 0f8430020000 8d4c2404 51 e8???????? 8d542408 }
+ $sequence_8 = { e8???????? 8b1d???????? 83c428 50 ffd3 8b542430 }
+ $sequence_9 = { e8???????? 8d4c2408 6aff 51 e8???????? 8d542410 6a02 }
condition:
- 7 of them and filesize <7192576
+ 7 of them and filesize <139264
}
-rule MALPEDIA_Win_Tmanger_Auto : FILE
+rule MALPEDIA_Win_Gibberish_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "78f3e107-dd73-5ac6-8162-9004595db040"
+ id = "409a50f2-d1ad-54e1-a200-e21294aa9e4e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tmanger"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tmanger_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gibberish"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gibberish_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "3ce75b695b98335702f80c133e38f084863185b63bd0e2de7bf59d414a1dae17"
+ logic_hash = "57f29d590beea21c748ae9324417e51d5ad871133bb0f66df9972b1b6e5d5d7b"
score = 75
quality = 75
tags = "FILE"
@@ -156382,32 +163468,32 @@ rule MALPEDIA_Win_Tmanger_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c7415d382cd7bd c74161d47bdb0f c741651f013f62 c74169388b8e92 c7416d9b14f6a0 }
- $sequence_1 = { c741103a71c135 c74114c2a02ab0 c74118d95dc845 c7411cf8f0564e c7412066b8276e }
- $sequence_2 = { c74169388b8e92 c7416d9b14f6a0 c7417180fcd6bb c74175d7401d36 }
- $sequence_3 = { c7410c16d9fdf8 c741103a71c135 c74114c2a02ab0 c74118d95dc845 c7411cf8f0564e }
- $sequence_4 = { c7412425d933d1 c7412861fdc72a c7412cdf9134d2 c74130324d251d c74134375ec19d }
- $sequence_5 = { c74169388b8e92 c7416d9b14f6a0 c7417180fcd6bb c74175d7401d36 c7417958fffa19 66c7417dfc19 }
- $sequence_6 = { c7412066b8276e c7412425d933d1 c7412861fdc72a c7412cdf9134d2 c74130324d251d c74134375ec19d }
- $sequence_7 = { c741594d68b93a c7415d382cd7bd c74161d47bdb0f c741651f013f62 }
- $sequence_8 = { c741510f9f2997 c7415565449eac c741594d68b93a c7415d382cd7bd c74161d47bdb0f c741651f013f62 }
- $sequence_9 = { c741594d68b93a c7415d382cd7bd c74161d47bdb0f c741651f013f62 c74169388b8e92 }
+ $sequence_0 = { ff15???????? 8945a4 e8???????? 8b4dac 8b45a4 6a41 }
+ $sequence_1 = { 8b75e8 8b7dec e9???????? f30f7e4de8 0f1045d8 eb03 }
+ $sequence_2 = { c1e908 894c2410 8b4c2418 3314c5e1a14700 0fb6c1 c1e908 }
+ $sequence_3 = { e8???????? 84c0 0f849a000000 33c0 668985dcf9ffff 8d85e8fbffff 68???????? }
+ $sequence_4 = { 8944243c 8b4124 89442440 8b4128 8d4c241c c744241c209d4500 c7442420d49d4500 }
+ $sequence_5 = { 894db0 8d4dc0 50 c745d000000000 c745d40f000000 c645c000 e8???????? }
+ $sequence_6 = { 81fae3000000 7cc4 81fa6f020000 7d3a 57 8d3c9518bd4700 }
+ $sequence_7 = { 68???????? 53 53 ff15???????? 8b55ac 8b4da8 890491 }
+ $sequence_8 = { ff15???????? 66898435fdfbffff 83c607 53 56 8d85f8fbffff 50 }
+ $sequence_9 = { 8b45d4 8d4dd8 8b55d0 83ff10 8b7dd8 0f43cf 2bc2 }
condition:
- 7 of them and filesize <8252416
+ 7 of them and filesize <1068032
}
-rule MALPEDIA_Win_Khrat_Auto : FILE
+rule MALPEDIA_Win_Mm_Core_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cae82139-c683-5bf8-8807-a11668477f96"
+ id = "d45aa5c3-0724-55a7-87e0-2c03f652362f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.khrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.khrat_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mm_core"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mm_core_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "074673c423b5c49f07577630b1f328510bc324887f41ca6e4261bb8bfff0e2f0"
+ logic_hash = "3ca1e6eabacd07d91480b5599e1196a1b257af6133657fffc185261c4367958e"
score = 75
quality = 75
tags = "FILE"
@@ -156421,32 +163507,32 @@ rule MALPEDIA_Win_Khrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d858cfbffff 50 68f4030000 57 }
- $sequence_1 = { 66c745e00000 8b859cfbffff 8945e8 8b8590fbffff 8945ec 8945f0 }
- $sequence_2 = { c9 c20400 55 8bec 81c4d0f9ffff }
- $sequence_3 = { 81c448feffff c705????????ffffffff 8d8572feffff 50 6802020000 e8???????? 6a06 }
- $sequence_4 = { 68???????? 6a00 e8???????? 0bc0 0f840e010000 }
- $sequence_5 = { 66c746326500 66c746347700 66c746363a00 66c746380000 8db500feffff }
- $sequence_6 = { ff35???????? 8f45e6 8d45e2 50 e8???????? c9 }
- $sequence_7 = { eb25 ff35???????? e8???????? 8d85d4fdffff }
- $sequence_8 = { c9 c3 55 8bec 83c4fc 833d????????ff }
- $sequence_9 = { 50 8d85bcf8ffff 50 8d85dcf8ffff 50 8d8500ffffff }
+ $sequence_0 = { 7458 57 8b7c240c 85ff 744e 6a40 6800300000 }
+ $sequence_1 = { c1f805 8bf7 83e61f c1e606 03348540400110 c745e401000000 }
+ $sequence_2 = { 8b45fc ff34c5e41c0110 53 57 e8???????? 83c40c 85c0 }
+ $sequence_3 = { 85f6 0f848d000000 8b0e 85c9 7442 8b5608 }
+ $sequence_4 = { 8b442424 8b4c242c 8938 8931 }
+ $sequence_5 = { 8955d4 8b45d4 8b4814 894ddc }
+ $sequence_6 = { 8d4c244c 51 55 55 68???????? 68???????? }
+ $sequence_7 = { 57 52 89842480000000 898c2484000000 89bc2488000000 e8???????? 83c40c }
+ $sequence_8 = { e8???????? bb???????? 8d742434 e8???????? 8d9c24a8050000 8d742428 e8???????? }
+ $sequence_9 = { 8b4dc4 0fb611 0355fc 8955fc 8b45c4 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <319488
}
-rule MALPEDIA_Win_Unidentified_094_Auto : FILE
+rule MALPEDIA_Win_Atmitch_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f5bdd8f3-d974-5222-9555-3631072a29c0"
+ id = "5a61b640-3c5c-5518-8891-5d83a0b89c2d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_094"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_094_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atmitch"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atmitch_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "f3d0ed91e99c9ab03a6ddd24a2a28007a40b7e677077c8b725a5a67f32cc52a7"
+ logic_hash = "565ce987fa9e005b7e196a8bfd57c4f682eb318d752a50049029192ea9e40f26"
score = 75
quality = 75
tags = "FILE"
@@ -156460,32 +163546,32 @@ rule MALPEDIA_Win_Unidentified_094_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 890d???????? 57 8915???????? a3???????? 83ceff b9???????? }
- $sequence_1 = { 6a5c 68???????? e8???????? 83c408 33c9 }
- $sequence_2 = { 0fb65004 3015???????? 0fb64805 300d???????? 0fb65006 3015???????? }
- $sequence_3 = { 83c310 ff4d0c 0f857ffeffff 5f }
- $sequence_4 = { 0fb65004 3015???????? 0fb64805 300d???????? 0fb65006 3015???????? c3 }
- $sequence_5 = { 884dff 84d2 7902 341b }
- $sequence_6 = { 3055fd 0fb61401 3055fe 0fb6540101 3055ff 8b55fc 89540102 }
- $sequence_7 = { 6a00 6a00 6a00 ff15???????? c3 }
- $sequence_8 = { 80f31b 8ad3 02d2 84db 7903 80f21b }
- $sequence_9 = { 890d???????? 57 8915???????? a3???????? }
+ $sequence_0 = { c644244803 ff15???????? 8d4c2418 51 68???????? }
+ $sequence_1 = { 33c4 89842410020000 56 51 8bcc }
+ $sequence_2 = { 8bfe f7df 896c241c 0fb744242c 50 51 }
+ $sequence_3 = { 51 833d????????00 7422 a1???????? 50 }
+ $sequence_4 = { ff15???????? e8???????? 8b0e 8b5138 83c408 }
+ $sequence_5 = { c744241c00000000 b8???????? c60000 83c004 3d???????? 7cf3 68???????? }
+ $sequence_6 = { 8bcc 89642410 68???????? ff15???????? e8???????? 0fb705???????? 83c408 }
+ $sequence_7 = { ff15???????? 83bc24fc00000000 7432 8b4c2408 8b41f4 }
+ $sequence_8 = { c644244803 ff15???????? 8d4c2418 51 68???????? 8d542428 52 }
+ $sequence_9 = { 83c404 50 ff15???????? 50 51 }
condition:
- 7 of them and filesize <524288
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Shadowpad_Auto : FILE
+rule MALPEDIA_Win_Rockloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c7d36336-f736-58f8-9fa1-3e3ab1239351"
+ id = "175eaa7b-da5b-50b8-b46d-cecd53211dcf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shadowpad"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shadowpad_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rockloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rockloader_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "af53d025dfe83e5b7a4ca7b9e68b22a960854fdb5b48b2d1cee2b2ef3fbc15f2"
+ logic_hash = "8a75e6c1f9302fef80e04ef409ea5d10afc0d829be15769e71fe72b02405b4ff"
score = 75
quality = 75
tags = "FILE"
@@ -156499,32 +163585,32 @@ rule MALPEDIA_Win_Shadowpad_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 59 8d75dc a3???????? e8???????? 53 ff15???????? }
- $sequence_1 = { 5b c9 c3 55 8bec b8f8100000 e8???????? }
- $sequence_2 = { 8bec 53 57 ff7508 ff15???????? 8d7801 }
- $sequence_3 = { 8d45e8 50 53 8d75d0 }
- $sequence_4 = { 7e25 8a0c56 8a445601 80e961 2c6a }
- $sequence_5 = { 50 6a04 5f e8???????? 85c0 75ae 8d4310 }
- $sequence_6 = { 83ec24 53 56 57 33ff 393d???????? }
- $sequence_7 = { e8???????? 8b1d???????? 50 ffd3 6800010000 668945f0 }
- $sequence_8 = { 8bfe 8d45e8 895de8 895dec 895df4 895df0 885df8 }
- $sequence_9 = { 0fb639 c1ce08 83cf20 03f7 83c102 81f6a3d9357c 663919 }
+ $sequence_0 = { e8???????? dc1d???????? dfe0 f6c441 740f }
+ $sequence_1 = { e8???????? 85c0 74b4 c6002c 40 837d0c00 7404 }
+ $sequence_2 = { 8a06 3c22 750c ff7508 8bc6 e8???????? }
+ $sequence_3 = { 8b45f4 8945e8 8d45f8 50 8d45e4 }
+ $sequence_4 = { eb05 68???????? e8???????? 8bf8 8bc7 }
+ $sequence_5 = { e8???????? 33f6 53 8975f8 }
+ $sequence_6 = { 3975f4 7e55 53 8b45f8 }
+ $sequence_7 = { ff4608 8b7f08 85ff 7452 8b4508 }
+ $sequence_8 = { d9ee 53 56 dd55ec d9e8 33f6 }
+ $sequence_9 = { 8975f8 db45f8 8365f800 dec1 dd5ddc 9b }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Heriplor_Auto : FILE
+rule MALPEDIA_Win_Diztakun_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d711b4d9-3914-58b9-9b88-9214444e3dee"
+ id = "7edd86e4-2270-51c2-83a8-ad0918813862"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.heriplor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.heriplor_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.diztakun"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.diztakun_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "bf5971e2bb98e2180b60da71db38d7f4898a68723f2588a48c70334b337b7d93"
+ logic_hash = "6061dd34695b43b9aac4a4105a7b2b736c3a3c9564c659ddb77165c4b09e4e8b"
score = 75
quality = 75
tags = "FILE"
@@ -156538,34 +163624,34 @@ rule MALPEDIA_Win_Heriplor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c20c00 55 89e5 56 57 33c9 648b4130 }
- $sequence_1 = { 40 5b 59 89ec }
- $sequence_2 = { 8a08 84c9 740d 80c960 01cb c1e301 }
- $sequence_3 = { 668b13 8b0491 01f8 5f 5e 89ec 5d }
- $sequence_4 = { 89e5 51 53 33db 33c9 8b4508 }
- $sequence_5 = { 85ff 7420 46 46 }
- $sequence_6 = { 7407 83c204 43 43 ebe6 33d2 668b13 }
- $sequence_7 = { 01fb 8b32 01fe 6a01 ff750c }
- $sequence_8 = { 3b5d0c 7401 40 5b }
- $sequence_9 = { 01f9 01fa 01fb 8b32 01fe 6a01 ff750c }
+ $sequence_0 = { 4a 85d2 0f8fb3010000 8b08 8b11 50 }
+ $sequence_1 = { 51 ff15???????? 8d742408 e8???????? 5f }
+ $sequence_2 = { 8b08 8b11 50 8b4204 ffd0 c68424d807000019 8b442430 }
+ $sequence_3 = { 83e01f c1f905 8b0c8d60d74400 c1e006 03c1 f6400401 7524 }
+ $sequence_4 = { 8945f4 8b4514 40 c745ec3f344200 894df8 }
+ $sequence_5 = { 50 889c24e4070000 e8???????? 83c40c c68424d807000011 }
+ $sequence_6 = { 8b4c240c 8b5720 8d442408 50 51 }
+ $sequence_7 = { 85d2 740b 8b450c 8b80a4914400 eb09 8b450c 8b8070914400 }
+ $sequence_8 = { e8???????? 59 59 85c0 0f84d9000000 68???????? 53 }
+ $sequence_9 = { e8???????? 83bfac00000000 755e 8d4c2474 51 8d54241c 52 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <688128
}
-rule MALPEDIA_Win_Infy_Auto : FILE
+rule MALPEDIA_Win_Cutwail_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "57c24fda-e429-5a88-80d2-235251d4052e"
+ id = "62e269de-1aa8-5a3f-857f-84d4e225d36e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.infy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.infy_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cutwail"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cutwail_auto.yar#L1-L165"
license_url = "N/A"
- logic_hash = "97f3b09f4f39ef998f79ec8093433c607a41cb99a12ab0573691bf5dec73bf57"
- score = 60
- quality = 45
+ logic_hash = "c6c78a26e86e94e8584b09088785fb67085bf6ba9ec9ef8f1d52fe4203a44bcb"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -156577,32 +163663,38 @@ rule MALPEDIA_Win_Infy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7e24 8945d4 807de300 7409 8b45e4 66833820 }
- $sequence_1 = { 7409 8b13 8bc3 e8???????? 85c0 7405 83e804 }
- $sequence_2 = { 57 33c9 894df8 8955f0 }
- $sequence_3 = { 7553 837e1400 7442 837e1c00 }
- $sequence_4 = { 668378f602 7412 6a00 89e0 }
- $sequence_5 = { 68???????? 8d45c8 ba09000000 e8???????? 8d45ec }
- $sequence_6 = { 807de300 7409 8b45e4 66833820 7304 33c0 eb02 }
- $sequence_7 = { c1e002 034610 f6400380 0f94c2 83e201 8955e0 85d2 }
- $sequence_8 = { e8???????? 8bd0 81e2ff000000 2500ff0000 c1e808 83fa05 7505 }
- $sequence_9 = { e8???????? 83c40c 5b 5d c20800 55 8bec }
+ $sequence_0 = { 8808 ebc1 8b5508 03550c c60200 c745fc01000000 8b45fc }
+ $sequence_1 = { 3930 0f8491010000 8b08 8b09 894d40 }
+ $sequence_2 = { eb12 8d45f4 50 8b4704 }
+ $sequence_3 = { 59 e9???????? 8b7de0 8b45f8 83f808 }
+ $sequence_4 = { 8b8568feffff 0560ea0000 39855cfeffff 7633 8b8d5cfeffff 898d68feffff e8???????? }
+ $sequence_5 = { 8b400c 894564 8d4568 50 }
+ $sequence_6 = { c7410400000000 6830750000 ff15???????? 8b55fc 8b02 50 }
+ $sequence_7 = { 837d1000 7d04 32c0 eb7d }
+ $sequence_8 = { 84c0 745e 46 8a06 }
+ $sequence_9 = { 51 e8???????? 83c40c c785e0fdffff00000000 c785dcfdffff00000000 }
+ $sequence_10 = { 3bdf 894510 0f84ecfdffff 53 50 }
+ $sequence_11 = { 68a6000000 89450c e8???????? 03c3 50 }
+ $sequence_12 = { e8???????? 83c410 8985ecfdffff 83bdecfdffffff 0f84ae000000 8b95e4fdffff }
+ $sequence_13 = { 76ce 8b7d6c 83ff1d 740e }
+ $sequence_14 = { 7509 c68563feffff01 eb77 83bd6cfeffff05 7d6e ff15???????? 89855cfeffff }
+ $sequence_15 = { e8???????? 83c414 8b85dcfdffff 2b85d8fdffff 0345fc }
condition:
- 7 of them and filesize <147456
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Killav_Auto : FILE
+rule MALPEDIA_Win_Backspace_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1d5124ec-5245-51ca-8b54-4fbeb7c8a843"
+ id = "8637042a-e46d-5e46-8b23-93a8dfec3a24"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.killav"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.killav_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.backspace"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.backspace_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "6bdcae63c9d790007a185fb309199c790674ed97c7a86b96314a377ad757753a"
+ logic_hash = "f8be0bb8ce4eb3c98209ea23733b4688fab87fe72dcb307bd40859035b4f4c31"
score = 75
quality = 75
tags = "FILE"
@@ -156616,32 +163708,32 @@ rule MALPEDIA_Win_Killav_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c745e4e8e24200 e9???????? 894de0 c745e4e8e24200 e9???????? }
- $sequence_1 = { 8955e0 8b048d70ba4300 f644102801 747c }
- $sequence_2 = { 6a20 c745e000000000 e8???????? 8bf0 83c404 8975e0 }
- $sequence_3 = { 8b45f8 8b55f0 8b048570ba4300 807c022800 }
- $sequence_4 = { e8???????? 8b35???????? 6a00 6880000000 6a03 6a00 6a00 }
- $sequence_5 = { c645fc1c 50 8d4dd0 e8???????? c645fc00 8b55ec 83fa08 }
- $sequence_6 = { 8b049570ba4300 885c012e 8b049570ba4300 804c012d04 }
- $sequence_7 = { 8d45d8 c645fc37 50 8d4dd0 }
- $sequence_8 = { 6bf838 894df8 8b048d70ba4300 33c9 }
- $sequence_9 = { e8???????? 8d45d8 c645fc08 50 8d4dd0 }
+ $sequence_0 = { 57 40 50 ff15???????? 85c0 0f8fa3000000 }
+ $sequence_1 = { 3bfb 59 7405 83c705 }
+ $sequence_2 = { 8d8500feffff 50 e8???????? 83c424 85c0 740b ff750c }
+ $sequence_3 = { 8b45f8 ff45f8 3d88130000 7f51 ebc9 8a06 }
+ $sequence_4 = { 885d91 885d92 885d93 885d94 }
+ $sequence_5 = { ff15???????? f7d8 1bc0 59 83e002 59 48 }
+ $sequence_6 = { 393d???????? 7552 be00200000 ff75f8 8d85f8dfffff }
+ $sequence_7 = { 50 e8???????? 56 e8???????? 8bd8 be???????? 83c306 }
+ $sequence_8 = { 8d85f8dfffff 50 e8???????? 59 8bc3 59 e9???????? }
+ $sequence_9 = { a3???????? ff75fc ffd6 395dfc }
condition:
- 7 of them and filesize <517120
+ 7 of them and filesize <131072
}
-rule MALPEDIA_Win_Winordll64_Auto : FILE
+rule MALPEDIA_Win_Wipbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "32ecf8d5-2cad-5cae-b550-c4e57fba7837"
+ id = "2dc6790b-0815-56da-b4e1-b1ab1c837c71"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winordll64"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.winordll64_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wipbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wipbot_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "633c933d5010a60000a71f7674b6b6d81d1af8a3edb249e8b101bbf4eb8e443f"
+ logic_hash = "b4a431b5982e86b4c79c71104a1485b7ef9ede4d9bcd19d6e305251f54be5168"
score = 75
quality = 75
tags = "FILE"
@@ -156655,32 +163747,32 @@ rule MALPEDIA_Win_Winordll64_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 488d4dbc ff15???????? 488d15ae1c0100 488bc8 e8???????? 85c0 }
- $sequence_1 = { 4833c4 488985581d0000 488bd9 b838070000 48ffc8 c6040100 75f7 }
- $sequence_2 = { 48897c2420 ff15???????? 85c0 7426 448b842490000000 4c8d4c2430 }
- $sequence_3 = { e9???????? ba12000000 ebf0 48897c2440 897c2448 488d442448 4889442420 }
- $sequence_4 = { e8???????? 4c8d0513c50000 41b903000000 488d4c45bc 488bc1 492bc5 }
- $sequence_5 = { 488bcf c744243001000000 448be8 ff15???????? }
- $sequence_6 = { 663918 75f5 4c8d4da0 48837db808 4c0f434da0 486307 }
- $sequence_7 = { 7423 83fefe 741e 488bce 488bc6 488d1554370100 83e11f }
- $sequence_8 = { 7767 488d4d98 482bcb 48b8abaaaaaaaaaaaa2a 48f7e9 488bf2 }
- $sequence_9 = { 0f84bd010000 488b4c2450 4533c0 418bd5 ff15???????? 85c0 0f847b010000 }
+ $sequence_0 = { eb05 b8???????? e8???????? 89da 83c9ff e8???????? }
+ $sequence_1 = { 5b 5d e9???????? 5a 31c0 5b 5d }
+ $sequence_2 = { 4c 8d442428 baff010f00 48 89d9 ffd0 48 }
+ $sequence_3 = { b911000000 31c0 c644245e2e 31d2 f3aa c644245f0b c64424601f }
+ $sequence_4 = { 85c0 48 89c6 0f94c2 48 85db 0f94c0 }
+ $sequence_5 = { 8d44245f 88d1 48 01d0 48 ffc2 3208 }
+ $sequence_6 = { eb7d 48 894c2438 e8???????? 01c0 ba9ad65fb0 b98a758b1f }
+ $sequence_7 = { 8d55f4 89542408 8d55f0 c744240c00800000 89542404 c70424ffffffff ffd0 }
+ $sequence_8 = { 89cb b91d000000 c64424222e f3aa c644242379 c644242446 31c0 }
+ $sequence_9 = { 8944240c 8b45a8 83c020 890424 ffd2 85c0 0f9fc0 }
condition:
- 7 of them and filesize <278528
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Cryptolocker_Auto : FILE
+rule MALPEDIA_Win_Hzrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ef7778bc-4b3f-57b9-be94-b68bbd4e0a82"
+ id = "4d1bc827-a443-5a54-876f-91ca96256a66"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptolocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptolocker_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hzrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hzrat_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "308de5ca9cd2927cd67ef4efc7cb0917b58e872fb565dc9ff1066d1520a7dec9"
+ logic_hash = "4c8da289e225a98c903b1e25bb40a32ef5f7bbd72fec724a7ddbf67c4f6841b8"
score = 75
quality = 75
tags = "FILE"
@@ -156694,32 +163786,32 @@ rule MALPEDIA_Win_Cryptolocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4a9f 6683f905 770f c1e004 }
- $sequence_1 = { 0f858f000000 a1???????? 85c0 7509 }
- $sequence_2 = { 898431ecfeffff 8b4ee8 85c9 740e 8b01 }
- $sequence_3 = { ff7720 56 ff15???????? 8b4510 8b4b04 5f 5e }
- $sequence_4 = { 7405 83f802 7549 85c9 }
- $sequence_5 = { 8b75fc 33c9 85c0 0f48f1 7522 85f6 781e }
- $sequence_6 = { c20800 55 8bec 83ec08 53 56 8b7508 }
- $sequence_7 = { 8b4ee8 85c9 740e 8b01 6a01 8b4004 03c8 }
- $sequence_8 = { 55 8bec 56 8b750c 8d8600ffffff 83f801 7723 }
- $sequence_9 = { 0fb7044a 83f820 740f 83f809 7205 83f80d }
+ $sequence_0 = { 7526 c745f500000000 8d4df4 8075f642 8075f742 8075f842 6a00 }
+ $sequence_1 = { ff15???????? 6689442412 8b44240c 89442414 8d442410 6a10 50 }
+ $sequence_2 = { 8bce ff7508 8b4020 ffd0 8b17 8bcf 8ad8 }
+ $sequence_3 = { 03da 81fa00010000 7312 8a8758e94200 0803 42 0fb64101 }
+ $sequence_4 = { 51 e8???????? 83c408 80bd93feffff00 c6856cfeffff00 7445 }
+ $sequence_5 = { 0faee8 e8???????? 8bc8 83c404 85c9 747d }
+ $sequence_6 = { 7410 fe8860f14200 8a8060f14200 84c0 7f1f 8bce e8???????? }
+ $sequence_7 = { dd4520 83c40c c9 c3 8b04c5c4324200 }
+ $sequence_8 = { 7312 0faee8 8b5104 8b4208 }
+ $sequence_9 = { c60000 c645fc03 8b9544fbffff 83fa10 }
condition:
- 7 of them and filesize <778240
+ 7 of them and filesize <409600
}
-rule MALPEDIA_Win_Neddnloader_Auto : FILE
+rule MALPEDIA_Win_Dyepack_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8eecbeb9-33c7-5f00-852d-691f303c8b89"
+ id = "66b3574f-c7a6-53f0-85d5-ab2a32e5f41d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.neddnloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.neddnloader_auto.yar#L1-L169"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dyepack"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dyepack_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "318d1d367a3335dce76e46790f71f42f9c5ddb3e28ec2c109117f64c52aadcd2"
+ logic_hash = "9d7b8dddf2871fef90109ccabdb579a142d1f80f2c5a6a3cb7a4f53499a52084"
score = 75
quality = 75
tags = "FILE"
@@ -156733,38 +163825,32 @@ rule MALPEDIA_Win_Neddnloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c204 3bcf 72f0 8d43ff }
- $sequence_1 = { 69c0b179379e c1e813 03c9 0fb73411 }
- $sequence_2 = { 8b5508 69c0b179379e c1e813 33c9 66890c42 }
- $sequence_3 = { 8d43ff 3bc8 7311 0fb702 }
- $sequence_4 = { 8bc1 2b45fc 5f 5e }
- $sequence_5 = { eb02 0008 8b45f8 83c0f4 897dfc }
- $sequence_6 = { 663bc6 7506 83c102 83c202 3bcb 7307 }
- $sequence_7 = { 7311 0fb702 0fb731 663bc6 7506 83c102 }
- $sequence_8 = { 488bf2 41c1ed04 492bf0 41ffc5 488bd3 488bcf }
- $sequence_9 = { 410fb6c0 4133b48e803c0100 4133b48680480100 418bc0 41337530 c1e808 0fb6d0 }
- $sequence_10 = { 0fb6c8 410fb6c0 4133bc8e803c0100 4133bc8680480100 41337d60 418bc0 }
- $sequence_11 = { 448bce 448bc7 488bd0 498bce e8???????? 448bf0 }
- $sequence_12 = { 488d3d24570000 eb0e 488b03 4885c0 7402 }
- $sequence_13 = { 0fb6d0 418bc6 458b949480440100 c1e810 0fb6c8 8bc5 }
- $sequence_14 = { 488d0d14100100 baa00f0000 488bc5 83e51f 48c1f805 486bed58 }
- $sequence_15 = { ff5348 b97f000000 ff15???????? eb1e 488b5350 498bcd ff5348 }
+ $sequence_0 = { 53 53 56 ffd7 8b442414 8b4c2410 33ed }
+ $sequence_1 = { 7cb2 7f08 8b4c2410 3be9 }
+ $sequence_2 = { 8b442414 8b4c2410 33ed 33ff 3bc3 7c60 7f0a }
+ $sequence_3 = { 741e 8b442418 3bc3 7416 03e8 8b442414 13fb }
+ $sequence_4 = { 1bc7 7815 7f08 81f900100000 }
+ $sequence_5 = { 56 ff15???????? 8b8c2428100000 53 51 }
+ $sequence_6 = { 3bcb 765a eb04 8b4c2410 2bcd }
+ $sequence_7 = { ff15???????? 85c0 741e 8b442418 3bc3 7416 03e8 }
+ $sequence_8 = { 5f 5e 5b 81c414100000 c3 8b3d???????? }
+ $sequence_9 = { ffd7 8d4c2418 53 51 8d54242c }
condition:
- 7 of them and filesize <3438592
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Datper_Auto : FILE
+rule MALPEDIA_Win_Ragnarlocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "144df714-10f7-5eb5-ac00-48d1c0a0517d"
+ id = "e474a54c-f0e2-58cf-8fb5-f5efe389dd86"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.datper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.datper_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ragnarlocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ragnarlocker_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "96f11afeb919508bb147708a5d367711547bdbf470c62d9b42f3889c5cdbbcd4"
+ logic_hash = "0ce73fa8ff409c8b46cae101a5ed771c097f4c9fb16c4b873e6cf25053373d48"
score = 75
quality = 75
tags = "FILE"
@@ -156778,34 +163864,34 @@ rule MALPEDIA_Win_Datper_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c9 ba0c000000 e8???????? c78564d7ffff0c000000 33c0 898568d7ffff }
- $sequence_1 = { 5a 59 59 648910 68???????? 8d85e8f3ffff }
- $sequence_2 = { 0fb607 8845f7 0fb6c1 8b55fc 0fb60402 8807 }
- $sequence_3 = { 50 ff15???????? 85c0 741f 8b8424a80d0000 894348 }
- $sequence_4 = { 895de4 895de8 895df4 894df0 8955f8 8945fc 8d45fc }
- $sequence_5 = { 53 e8???????? a3???????? 8d95a8fbffff b8???????? e8???????? 8b85a8fbffff }
- $sequence_6 = { c78568d7ffff0c000000 33c0 89856cd7ffff c78570d7ffffffffffff 6a00 6a01 8d8568d7ffff }
- $sequence_7 = { 8b45fc e8???????? 50 e8???????? 8d8564d7ffff 33c9 ba0c000000 }
- $sequence_8 = { 8d85f0fbffff 50 53 e8???????? 8945f0 a1???????? 50 }
- $sequence_9 = { 53 e8???????? 6800800000 6a00 56 }
+ $sequence_0 = { 898df4feffff 894dc0 8b4f14 898decfeffff 894df8 8b4d0c 0fb601 }
+ $sequence_1 = { 33f1 8b4de8 8bd0 2345d4 3355d4 2355c8 33d0 }
+ $sequence_2 = { 0fb6c5 6a04 0bd0 0fb6c1 6800300000 c1e208 53 }
+ $sequence_3 = { 039d28ffffff 13bd24ffffff 035d94 137d98 81c338b548f3 81d75bc25639 015df4 }
+ $sequence_4 = { 0fa4ca17 c1ee09 c1e117 0bda 8b55dc 0bf1 8b4de0 }
+ $sequence_5 = { 8bfa 8b4dd4 8bf1 337de8 3375f4 237dac 2355e8 }
+ $sequence_6 = { 897dfc 8bbd34ffffff 8bf7 8bcf c1e618 0facd108 }
+ $sequence_7 = { 3375ec 8b55e8 2355c0 2375d4 33fa 8b4df4 234dec }
+ $sequence_8 = { 03c3 8945b8 13cf 33ff 894de0 }
+ $sequence_9 = { c1e108 0bc8 0fb64604 c1e108 0bc8 894b14 0f114318 }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <147456
}
-rule MALPEDIA_Win_Cueisfry_Auto : FILE
+rule MALPEDIA_Win_Hyperssl_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7fd15319-e895-59d1-bc47-6c7854fd0773"
+ id = "2b769147-d4c5-504a-a0e4-deff8d9a685b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cueisfry"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cueisfry_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hyperssl"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hyperssl_auto.yar#L1-L217"
license_url = "N/A"
- logic_hash = "312c24021c3e8bf9c6e0d5e58840583a4541e92e9f141ae7391f901c409f9736"
+ logic_hash = "f5cbe0c98412e251badcd68fd5914804f5830187a82b3a89143d596e8e3b1b20"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -156817,34 +163903,48 @@ rule MALPEDIA_Win_Cueisfry_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? b8???????? c3 8b45ec c745fcffffffff 85c0 7406 }
- $sequence_1 = { f3a5 52 e8???????? 8d44241c }
- $sequence_2 = { e8???????? 85c0 750c 55 ff15???????? e9???????? }
- $sequence_3 = { 8944241c 7c0d 80f95a 7f08 0fbee9 }
- $sequence_4 = { 8975dc e8???????? 8b45ec 3bc7 750d }
- $sequence_5 = { 8d4c2408 50 e8???????? b91f000000 33c0 8d7c2431 c644243000 }
- $sequence_6 = { ff15???????? 8bb424a8010000 8d4c240c 51 8bce }
- $sequence_7 = { 5f 5e 5d 32c0 5b 81c424030000 c3 }
- $sequence_8 = { 8d4c240c c68424a001000001 e8???????? 8d8c24ac010000 889c24a0010000 e8???????? }
- $sequence_9 = { 6a00 ff15???????? 68d0070000 ff15???????? 8d94249c000000 6a00 }
+ $sequence_0 = { 0108 3310 c1c607 c1c210 }
+ $sequence_1 = { 33c3 8b5c244c c1ee12 0bfe 33cf 8bf2 }
+ $sequence_2 = { 0105???????? 8d8d5cffffff 89855cffffff 898560ffffff }
+ $sequence_3 = { 2bf0 5f 8a10 301401 8a10 301406 40 }
+ $sequence_4 = { 40 4f 75f2 5f 5e e9???????? c3 }
+ $sequence_5 = { 7436 8b413c 03c1 742a }
+ $sequence_6 = { 03c1 742a 8b4028 03c1 }
+ $sequence_7 = { 0101 0100 0100 0100 }
+ $sequence_8 = { 0100 0200 0200 0002 0002 }
+ $sequence_9 = { 33c0 40 5d c20c00 6a08 }
+ $sequence_10 = { 0108 3908 1bc9 f7d9 }
+ $sequence_11 = { 8b4028 03c1 7423 56 57 }
+ $sequence_12 = { ff15???????? 8bc8 85c9 7436 8b413c }
+ $sequence_13 = { 0105???????? 8d558c 89458c 894590 }
+ $sequence_14 = { c20c00 6a08 68???????? e8???????? 8b450c 83f801 }
+ $sequence_15 = { 0101 014514 2bf3 8b5d0c }
+ $sequence_16 = { 01442428 8b442428 884500 45 }
+ $sequence_17 = { 017e0c 5f 8bc6 5e c20800 }
+ $sequence_18 = { 017e0c 395e10 740f ff7610 }
+ $sequence_19 = { 017e08 8bc3 e8???????? c20400 }
+ $sequence_20 = { 017e0c 8d4d08 e8???????? 5f }
+ $sequence_21 = { 011d???????? 5f 8935???????? 5e }
+ $sequence_22 = { 017e08 50 e8???????? ff0d???????? }
+ $sequence_23 = { 016b08 897b04 5f 5e }
condition:
- 7 of them and filesize <81920
+ 7 of them and filesize <835584
}
-rule MALPEDIA_Win_8Base_Auto : FILE
+rule MALPEDIA_Win_Hive_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7c9b0c56-079f-5ac3-b0fc-c036345ce952"
+ id = "d6a0e69c-8ba3-5e7b-a7ea-75f1727a32de"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.8base"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.8base_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hive"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hive_auto.yar#L1-L183"
license_url = "N/A"
- logic_hash = "ea755be9fd3154ace1513f9f57e59c67fbe5ae97b6b4073ab7fa5cccbb0a5bb8"
+ logic_hash = "6114f2e9f03828db87c71adf2ad1d3eed20f57d01fa9bb999ecd2843927df4e0"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -156856,32 +163956,43 @@ rule MALPEDIA_Win_8Base_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 ff15???????? 8d8e04a2feff 81f98c230000 770b }
- $sequence_1 = { f8 290c67 98 a6 73c2 }
- $sequence_2 = { 8815???????? c605????????6f 880d???????? c605????????65 c605????????63 }
- $sequence_3 = { 8d3485c0289100 8b06 83e71f c1e706 03c7 8a5824 }
- $sequence_4 = { c684249c00000002 50 c7442410043a4000 e8???????? }
- $sequence_5 = { d3ea 89542414 8b442434 01442414 8b442424 31442410 }
- $sequence_6 = { ff15???????? 8b442414 40 3d???????? 89442414 0f8c0effffff 8b35???????? }
- $sequence_7 = { 8bf7 83e61f c1e606 033485c0289100 c745e401000000 }
- $sequence_8 = { 6689442416 33c9 668954241a 8d442434 50 66894c241c 8b4c241c }
- $sequence_9 = { 899c24ac000000 3bfb 7449 8b8424b8000000 56 8d742418 }
+ $sequence_0 = { 31c0 b91d000000 31d2 31db }
+ $sequence_1 = { b807000000 b9d4000000 31d2 31db }
+ $sequence_2 = { 89c2 e8???????? b801000000 e8???????? }
+ $sequence_3 = { 31c9 31d2 bb54000000 31f6 }
+ $sequence_4 = { 89d1 e8???????? b802000000 e8???????? }
+ $sequence_5 = { 31c9 31d2 bb08000000 becb000000 31ff }
+ $sequence_6 = { 89d0 b90d000000 e8???????? b90d000000 }
+ $sequence_7 = { 31db 31ff eb31 31c0 }
+ $sequence_8 = { 31ff e8???????? 833d????????00 7511 }
+ $sequence_9 = { 89d1 e8???????? b901000000 e8???????? }
+ $sequence_10 = { 81c4b0000000 c3 e8???????? 90 }
+ $sequence_11 = { 31c9 31d2 bb09000000 bee0000000 }
+ $sequence_12 = { 31c0 eb17 0fb6940496000000 0fb674041c 31d6 }
+ $sequence_13 = { 01c1 83c101 83f90c 0f820fffffff }
+ $sequence_14 = { 01c1 c1e106 400fb6d6 01ca }
+ $sequence_15 = { 01c8 c1e006 400fb6cf 01c1 }
+ $sequence_16 = { 01c1 c1e106 0fb6c2 01c8 }
+ $sequence_17 = { 01c2 b8ffffff03 21c5 21c3 }
+ $sequence_18 = { 01c0 4000f8 0fb6c0 48898424b0000000 }
+ $sequence_19 = { 01ca c1e206 0fb6c3 01d0 }
+ $sequence_20 = { 01c8 89c1 c1e91f ffc9 }
condition:
- 7 of them and filesize <10838016
+ 7 of them and filesize <7946240
}
-rule MALPEDIA_Win_Sharpknot_Auto : FILE
+rule MALPEDIA_Win_Zerot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "50369af8-b07e-5fc0-8a81-2caae560d6bb"
+ id = "8ef83190-c437-5c69-9e28-6f4ff8bb0d5f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sharpknot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sharpknot_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zerot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zerot_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "c9ade7f96a822eb5e208dc6f180c2f1529ab39e41f40e8790faf2abbc1ccb7f4"
+ logic_hash = "0536a182186ebeb3c971f24e54b07f0b9a695f53e7e594ac1e15149db29c5630"
score = 75
quality = 75
tags = "FILE"
@@ -156895,32 +164006,32 @@ rule MALPEDIA_Win_Sharpknot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8d8c246c020000 c7842498050000ffffffff e8???????? 8b8c2490050000 }
- $sequence_1 = { 8bf8 85ff 0f84a7000000 8b442434 53 }
- $sequence_2 = { 7c0a 817c241400000400 7304 8b7c2414 6a00 }
- $sequence_3 = { 8bd8 0f8494000000 85db 0f848c000000 }
- $sequence_4 = { 6804010000 8d842454010000 57 50 e8???????? }
- $sequence_5 = { 2beb 8bc1 8bf7 8bfa 53 c1e902 f3a5 }
- $sequence_6 = { 50 ff15???????? 8b8c2428020000 6a00 6880000000 6a02 6a00 }
- $sequence_7 = { 57 ff15???????? 8b1d???????? 8d4c243c 8bf0 51 }
- $sequence_8 = { 50 57 ff15???????? 8b1d???????? 8d4c243c }
- $sequence_9 = { 68???????? 51 ffd5 8d542410 8d842450010000 52 50 }
+ $sequence_0 = { ff15???????? 46 81e6ff000080 7908 }
+ $sequence_1 = { 50 68???????? ff15???????? 8b3d???????? 8d85bcfbffff 50 }
+ $sequence_2 = { 6a00 ff760c ff15???????? 85c0 7430 6a00 8d85ccf9ffff }
+ $sequence_3 = { 8bf8 6a59 ff15???????? 85c0 b9???????? 0f45cf }
+ $sequence_4 = { 8b8ef2050000 8d96fa050000 e8???????? 8d8534cdffff 50 6802020000 ff15???????? }
+ $sequence_5 = { 85c0 740c 81bd34fcffffc8000000 7421 8b8530fcffff 40 898530fcffff }
+ $sequence_6 = { 8d7001 75da 8b35???????? 8d857cffffff 50 ffd6 83c002 }
+ $sequence_7 = { 6800020000 8d85bcfdffff 6a00 50 e8???????? 68???????? }
+ $sequence_8 = { 880c32 8a47f8 c0e005 02c1 880432 }
+ $sequence_9 = { 0f84b6000000 80bd53fcffff00 0f84a9000000 0fb74214 }
condition:
- 7 of them and filesize <1032192
+ 7 of them and filesize <303104
}
-rule MALPEDIA_Win_Pandabanker_Auto : FILE
+rule MALPEDIA_Win_Brutpos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "58cad36d-92dc-5f57-8115-b38a95b1c2cd"
+ id = "bb6abccd-59b3-5a30-9e67-ccbe498737a5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pandabanker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pandabanker_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.brutpos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.brutpos_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "64182a4cfed301300c0a7df71a34e50b114a69353e8eb5e84fdb9f4804c83f2c"
+ logic_hash = "89d0bc6a7e52ba9f63dface96ebbf483b03be0cbf8144ed32f3b88bf360b4eda"
score = 75
quality = 75
tags = "FILE"
@@ -156934,34 +164045,34 @@ rule MALPEDIA_Win_Pandabanker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 56 8bf2 57 83f8ff 7507 8bce e8???????? }
- $sequence_1 = { 57 8b4808 8d7c2418 8b4004 }
- $sequence_2 = { c1e202 8bfe 8bca 45 }
- $sequence_3 = { 7404 c6400109 8b442430 8bd5 014608 8bcf 56 }
- $sequence_4 = { eb2c 6a05 5a 8bcf }
- $sequence_5 = { c6007b 40 85db 7404 c6000a 40 c60000 }
- $sequence_6 = { e8???????? 8bf0 85f6 7411 8bcf }
- $sequence_7 = { 85ff 7423 8b0e 8bd5 }
- $sequence_8 = { e8???????? 8b742414 8bce 8b542418 89742424 e8???????? 84c0 }
- $sequence_9 = { 7508 33c0 85d2 0f95c0 c3 }
+ $sequence_0 = { 59 58 83c004 83e904 8808 }
+ $sequence_1 = { 03c2 034508 2938 83e902 75e8 ebd9 5e }
+ $sequence_2 = { 8d5b18 8b5b60 03d8 52 8b35???????? }
+ $sequence_3 = { 6681f9df77 7412 0f31 8bd8 }
+ $sequence_4 = { 8bd0 ad 8bc8 83e908 66ad 6685c0 740c }
+ $sequence_5 = { 8d7c38fc baffffffff 83c704 57 }
+ $sequence_6 = { 66ad 6685c0 740c 25ff0f0000 03c2 034508 }
+ $sequence_7 = { 52 e8???????? 59 8b09 8bd1 }
+ $sequence_8 = { c1e202 03d3 8b12 03d0 }
+ $sequence_9 = { 8b5508 8b4204 0fb70a 50 51 807401ff97 }
condition:
- 7 of them and filesize <417792
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Cherry_Picker_Auto : FILE
+rule MALPEDIA_Win_Virut_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4ae5e79a-a840-5921-89d9-37d4576478a8"
+ id = "d1cda5ac-7426-54df-b118-5de8978eea9c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cherry_picker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cherry_picker_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.virut"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.virut_auto.yar#L1-L166"
license_url = "N/A"
- logic_hash = "34271a3488eb7c13dc528b66980352e939907040bf405db0ad386d2bee3e0b44"
+ logic_hash = "2bad431ccdf4fab7d1de984be24a8fafd07e087427bb72238bd9b56468720628"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -156973,32 +164084,38 @@ rule MALPEDIA_Win_Cherry_Picker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? 68???????? a3???????? ffd6 69c0e8030000 68???????? }
- $sequence_1 = { 80fa3b 7503 83c9ff 8817 47 }
- $sequence_2 = { 68???????? 56 89442420 ffd3 68???????? 56 }
- $sequence_3 = { 8bf0 0fbec9 81e6ff000000 33f1 }
- $sequence_4 = { a1???????? 53 8b1d???????? 56 57 6aff }
- $sequence_5 = { a3???????? 85c0 7512 68???????? 50 50 }
- $sequence_6 = { ff15???????? 8bf0 68???????? 56 ffd3 68???????? 56 }
- $sequence_7 = { 6800010000 68???????? 68???????? 68???????? 68???????? ffd6 68???????? }
- $sequence_8 = { a1???????? 56 6aff 50 8bf1 }
- $sequence_9 = { ffd6 68???????? 6800010000 68???????? }
+ $sequence_0 = { 89442418 3bc3 0f8441020000 6801040000 8d8424fc050000 53 50 }
+ $sequence_1 = { 33f6 8bca 83c107 3bcb 7e1b }
+ $sequence_2 = { 0f8402010000 803f4d 0f85f9000000 807f015a }
+ $sequence_3 = { 6a00 59 e30a 6a0a }
+ $sequence_4 = { ff74241c 6a40 ff15???????? 8bf8 33c0 3bf3 }
+ $sequence_5 = { 8bf0 3bf3 0f8e82000000 ff74240c 57 56 }
+ $sequence_6 = { 51 6800040000 8d8c2404060000 51 89442428 }
+ $sequence_7 = { 8bcb f3a6 61 7405 }
+ $sequence_8 = { 8bd4 6a00 52 ff32 }
+ $sequence_9 = { 33d2 8bcf 52 f6d9 52 83e103 6a40 }
+ $sequence_10 = { 6800030084 51 51 56 }
+ $sequence_11 = { 49 4e 45 54 2e44 4c }
+ $sequence_12 = { 53 8d442444 50 8d8424e0020000 50 ffd6 }
+ $sequence_13 = { eb49 395c240c 7449 33c0 395c240c 7e24 }
+ $sequence_14 = { 6a10 59 f3ab 50 50 }
+ $sequence_15 = { 66ab 8d4704 ab 32e4 ac }
condition:
- 7 of them and filesize <712704
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Hi_Zor_Rat_Auto : FILE
+rule MALPEDIA_Win_Touchmove_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3dc62db9-3a05-5424-a3c8-d6fd9e595782"
+ id = "a88e9c25-4116-5e49-8a2c-fef3336f0802"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hi_zor_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hi_zor_rat_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.touchmove"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.touchmove_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "3acb0fc19d1323e3198577328eeef1259397f6589eae60512b85396f5cbd245b"
+ logic_hash = "519a7e3bd048a6a0769391087a62b1ec389f7202cc576a740e9eb0fb3d43844d"
score = 75
quality = 75
tags = "FILE"
@@ -157012,32 +164129,32 @@ rule MALPEDIA_Win_Hi_Zor_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c644303080 8b4e24 83e13f 80f937 7614 8bc6 e8???????? }
- $sequence_1 = { ff15???????? 8b4d08 57 8bf0 51 56 }
- $sequence_2 = { e8???????? 8b1d???????? 83c418 6804010000 8d8df4fdffff 51 }
- $sequence_3 = { 23da 8bfa 8b5014 f7d7 }
- $sequence_4 = { 8b5818 8db41e604b0000 c1e610 c1ef10 0bfe }
- $sequence_5 = { 037018 f7d2 8975f8 897014 8bfa 0b55f8 }
- $sequence_6 = { 57 51 50 8945f4 e8???????? 8b450c }
- $sequence_7 = { 50 51 e8???????? 83c424 893e 5f 5e }
- $sequence_8 = { ffd6 8b55ec 83c404 52 ffd6 83c404 }
- $sequence_9 = { 83c40c 6a00 8d450c 50 6800e00100 8d4608 50 }
+ $sequence_0 = { 41b800040000 488d8c2452010000 e8???????? 4c8d442448 488d152df90000 }
+ $sequence_1 = { 488d157af70000 488d8d90000000 e8???????? 4c8d8590000000 33d2 33c9 }
+ $sequence_2 = { 7528 48833d????????00 741e 488d0d499f0000 e8???????? 85c0 }
+ $sequence_3 = { 41b8ee000000 488d8d92430000 e8???????? c6858044000000 33d2 41b8ff000000 488d8d81440000 }
+ $sequence_4 = { ff15???????? 488d442450 4889442420 458bce 4533c0 488d9580410000 48c7c102000080 }
+ $sequence_5 = { 0f8514010000 4c8d2d36cd0000 41b804010000 668935???????? 498bd5 ff15???????? 418d7c24e7 }
+ $sequence_6 = { 48833d????????00 0f844d040000 48833d????????00 0f843f040000 }
+ $sequence_7 = { 833d????????00 7505 e8???????? 488d3d40e00000 41b804010000 }
+ $sequence_8 = { 488bfb 488bf3 48c1fe05 4c8d25bebd0000 83e71f 486bff58 }
+ $sequence_9 = { 8bc8 e8???????? ebc9 488bcb 488bc3 488d1597e40000 48c1f805 }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <224256
}
-rule MALPEDIA_Win_Ati_Agent_Auto : FILE
+rule MALPEDIA_Win_Ave_Maria_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "aa24ad24-7301-5b4c-b856-1e1a4ef6bc2f"
+ id = "410b5f16-91ac-5311-b6ab-598dd1954c39"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ati_agent"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ati_agent_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ave_maria"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ave_maria_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "724a5b5da348b3df222a7dbd0e29ff96d89b57311395a8ccd89f777e74414508"
+ logic_hash = "d6a2fe1f05fe69e9ea5ce04e4093200d3e962df5b8f3c4c00fc93efedbc85567"
score = 75
quality = 75
tags = "FILE"
@@ -157051,34 +164168,34 @@ rule MALPEDIA_Win_Ati_Agent_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488bc8 ff15???????? 488d1548a20000 488bce 488905???????? }
- $sequence_1 = { e8???????? 488d2d24a60000 4c8d250dd80000 83f8ff 7435 488bcf e8???????? }
- $sequence_2 = { 488d442460 488d942490010000 4533c9 4889442448 48894c2440 }
- $sequence_3 = { 488b05???????? 4833c4 4889442438 498bf0 488bfa 488bd9 }
- $sequence_4 = { 488d0526d80000 488d0cc8 48890f ff15???????? }
- $sequence_5 = { e9???????? 4881ec28050000 488b05???????? 4833c4 4889842410050000 488b05???????? 4885c0 }
- $sequence_6 = { 488d8c24f0000000 ba04010000 4889442420 e8???????? 4c8d5c2438 488d9424f0000000 41b919010200 }
- $sequence_7 = { 442bc0 488b442450 488d0d85be0000 488b0cc1 }
- $sequence_8 = { 897c2428 897c2420 c784248000000068000000 ff15???????? }
- $sequence_9 = { 8bf8 85c0 750d 488bce e8???????? e9???????? 4c8d2d6dc10000 }
+ $sequence_0 = { 8b07 ff740610 8d4614 50 8d45f8 50 }
+ $sequence_1 = { 52 8b08 6a01 50 ff510c 85c0 74c1 }
+ $sequence_2 = { 6a0a 03c1 59 8bf8 f3a5 8d4d30 }
+ $sequence_3 = { 0f57c0 c745e015000000 50 8d4de0 0f1145e8 e8???????? 8bc8 }
+ $sequence_4 = { 803800 7509 33c0 5b c3 33c0 40 }
+ $sequence_5 = { 8bc7 99 2bc1 8bcf 1bd6 52 50 }
+ $sequence_6 = { ff500c 8b06 68???????? ff37 8b08 }
+ $sequence_7 = { 51 54 8bce e8???????? 8b4d08 e8???????? 83c410 }
+ $sequence_8 = { 300431 41 3bcf 7ced 5f 8bc6 5e }
+ $sequence_9 = { 83ec18 53 8bd9 56 57 895df8 }
condition:
- 7 of them and filesize <172032
+ 7 of them and filesize <237568
}
-rule MALPEDIA_Win_Isfb_Auto : FILE
+rule MALPEDIA_Win_Phorpiex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2206addc-4ea1-5ebc-8989-ba5f49383e7b"
+ id = "eb226bf1-84a3-5e5c-8655-1f02f1d972a0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.isfb"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.isfb_auto.yar#L1-L1623"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phorpiex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.phorpiex_auto.yar#L1-L284"
license_url = "N/A"
- logic_hash = "dcaa8c2fe85dec9e7e215d7d6083b8c053dc5e8814c7849f4addcdf0f2d4a23f"
+ logic_hash = "626e70970105507345b3f584dcd1a33bae9d4d1c587f31ce85f081908c2a5392"
score = 75
- quality = 50
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -157090,212 +164207,52 @@ rule MALPEDIA_Win_Isfb_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? eb02 33c0 3bc7 741b 50 }
- $sequence_1 = { 741b 50 33c0 e8???????? 3bc7 }
- $sequence_2 = { ff75f0 ff75f4 6822010000 e9???????? ff7508 }
- $sequence_3 = { 58 e8???????? 3bc7 7406 50 }
- $sequence_4 = { 3bc7 7413 50 6a10 58 e8???????? }
- $sequence_5 = { ff35???????? e8???????? 8bf0 3bf3 7443 6aff 68806967ff }
- $sequence_6 = { 50 e8???????? 83c40c e8???????? 3bc7 }
- $sequence_7 = { 6a64 ff15???????? a1???????? 85c0 7407 83ee64 }
- $sequence_8 = { ff35???????? ff15???????? 85c0 a3???????? 7402 ffe0 c20400 }
- $sequence_9 = { 5d 5b 59 c20400 8325????????00 6a00 68???????? }
- $sequence_10 = { 7406 50 e8???????? 3bdf 7414 }
- $sequence_11 = { a1???????? 85c0 751a 68???????? ff35???????? ff15???????? 85c0 }
- $sequence_12 = { 3c05 7506 84e4 7704 3ac0 }
- $sequence_13 = { c20400 55 8bec 83ec0c a1???????? 8365f800 }
- $sequence_14 = { 2b55fc 8b7d10 0155fc 83451004 }
- $sequence_15 = { 83e103 740d 51 50 ff7510 e8???????? 83c40c }
- $sequence_16 = { 0155fc 83451004 83c004 49 8917 75e9 }
- $sequence_17 = { 7417 8b10 2b55fc 8b7d10 }
- $sequence_18 = { 3bc3 7512 e8???????? 3bc3 a3???????? }
- $sequence_19 = { 895df4 0f84c7000000 56 53 }
- $sequence_20 = { b8???????? 7505 b8???????? 53 bb60ea0000 }
- $sequence_21 = { 68000f0000 e8???????? 8bd8 85db 895df4 0f84c7000000 }
- $sequence_22 = { 837b240c 56 57 8b3b 897c241c 760a 8b4b20 }
- $sequence_23 = { 894b34 8b4b24 2b4b28 894c2410 8b4b34 f6c140 }
- $sequence_24 = { 58 e8???????? 85c0 740d 8906 83c604 }
- $sequence_25 = { 8b442418 894110 836334f9 c7432c01000000 8b4334 }
- $sequence_26 = { e8???????? 8b4320 897324 897328 83c40c 8974240c c6401a00 }
- $sequence_27 = { 57 33ff 3bdf 7414 }
- $sequence_28 = { ff35???????? 0fc8 50 a1???????? }
- $sequence_29 = { 8a4604 2404 f6d8 1bc0 }
- $sequence_30 = { c6400731 8b74241c 8b1e 6a00 ff37 ff15???????? 2b442414 }
- $sequence_31 = { ff15???????? 8b442414 8b4c240c 8907 8b442418 }
- $sequence_32 = { 83ec14 8364240400 53 8b5d0c 837b240c 56 }
- $sequence_33 = { 2b442414 50 8b07 03442418 50 56 ff5310 }
- $sequence_34 = { 837d0800 7408 ff7508 e8???????? 8bc7 5f 5e }
- $sequence_35 = { 752f 8b450c 8930 eb33 }
- $sequence_36 = { 74a3 33ff eb0b 33ff eb03 }
- $sequence_37 = { 6a01 33db 53 ff35???????? e8???????? 8bf0 }
- $sequence_38 = { 50 8d4508 50 53 8bc6 }
- $sequence_39 = { 8bd1 83c128 4e 7404 3bd0 74e7 3bd0 }
- $sequence_40 = { 488bcf c744242860ea0000 4c0f45c8 48895c2420 }
- $sequence_41 = { 3bc8 7415 8b5210 3bd0 }
- $sequence_42 = { 53 8bc6 e8???????? 85c0 7516 }
- $sequence_43 = { 6a0b eb02 6a02 58 }
- $sequence_44 = { 85ff 750e 837d0800 7408 }
- $sequence_45 = { 488bcf ff15???????? 4c8964dd00 83c301 4885ff 4c8be7 }
- $sequence_46 = { 498bcc ff15???????? 33db 66ba2000 }
- $sequence_47 = { 415c 5f 5e 5d 5b c3 8b4754 }
- $sequence_48 = { 75c4 48892e eb02 33db 488b0d???????? 885e08 }
- $sequence_49 = { c21000 55 8bec 83ec14 a1???????? 53 }
- $sequence_50 = { 53 b800080000 50 56 ff35???????? }
- $sequence_51 = { e8???????? be01000000 8bc6 4883c440 415e }
- $sequence_52 = { 33db 66ba2000 498bcc ff15???????? 4885c0 }
- $sequence_53 = { e8???????? 85c0 742d ff75fc 6a0d }
- $sequence_54 = { 742d ff75fc 6a0d 58 e8???????? 85c0 }
- $sequence_55 = { ff15???????? 4885c0 488be8 7453 }
- $sequence_56 = { 4c0f45c8 48895c2420 e8???????? 85c0 8bd8 }
- $sequence_57 = { 51 50 57 6a01 ff75e0 68???????? e8???????? }
- $sequence_58 = { ff15???????? bb01000000 498bcc eb07 83c301 488d4801 66ba2000 }
- $sequence_59 = { 8bd5 488bcf bb57000000 e8???????? }
- $sequence_60 = { e8???????? 3bc3 740f 8b35???????? 50 83c604 }
- $sequence_61 = { a810 ff750c 7535 68???????? ff75f8 }
- $sequence_62 = { ff75f8 ffd6 8b4df4 66c7015c00 }
- $sequence_63 = { 8945e0 e8???????? 85c0 0f84dc000000 8b45e0 8d4de0 3bc1 }
- $sequence_64 = { 33db 53 ff35???????? c745f408000000 ff15???????? 3bc3 8945f8 }
- $sequence_65 = { 6641b85c00 33d2 488bcd ff15???????? }
- $sequence_66 = { 50 83c604 e8???????? 3bfb }
- $sequence_67 = { b90e010000 41b800000100 4889442420 e8???????? e9???????? }
- $sequence_68 = { 6a01 e8???????? 85db 7423 8b0d???????? }
- $sequence_69 = { 50 e8???????? 3bfb 7414 }
- $sequence_70 = { 72c1 eb0c bb7f000000 eb05 bb7e000000 }
- $sequence_71 = { 33d2 ff15???????? 488bdf 8bf7 483bdf }
- $sequence_72 = { 4883c608 83fd05 72c1 eb0c }
- $sequence_73 = { 3bc3 8945f4 741a ff750c 668918 68???????? }
- $sequence_74 = { 50 8bd7 e8???????? eb02 33c0 3bc3 7413 }
- $sequence_75 = { a840 0f84e2000000 8b7334 8d442418 50 8d442410 50 }
- $sequence_76 = { 8b7508 e8???????? 33f6 3975fc }
- $sequence_77 = { ff7510 57 ff750c 53 e8???????? 3bfe 740e }
- $sequence_78 = { 0f8544010000 8b472c a801 742d ff37 e8???????? 85c0 }
- $sequence_79 = { e8???????? 3bfe 740e 57 56 ff35???????? ff15???????? }
- $sequence_80 = { ff5214 8bf7 8bfe e8???????? 5f 5e }
- $sequence_81 = { 5b 8be5 5d c20800 8b4330 a804 0f8451ffffff }
- $sequence_82 = { c744242000010000 ff15???????? 4883f8ff 488bf8 7442 }
- $sequence_83 = { ff15???????? 53 56 ff35???????? ff15???????? 5b 5f }
- $sequence_84 = { 3975fc 7410 ff75fc 56 ff35???????? ff15???????? 53 }
- $sequence_85 = { 83bc248800000000 4c8b442440 488b542448 894c2430 }
- $sequence_86 = { 752e 53 e8???????? 6a01 6a01 }
- $sequence_87 = { 56 ff35???????? 8945f8 ff15???????? 8bd8 3bde }
- $sequence_88 = { e8???????? 85c0 0f85d7000000 8b4604 }
- $sequence_89 = { 7505 894720 eb0b 8b4f30 84c9 0f8992000000 }
- $sequence_90 = { 83632800 e9???????? 8b4330 a840 0f84e2000000 8b7334 }
- $sequence_91 = { 0f854affffff 894330 e9???????? 55 }
- $sequence_92 = { c9 c20400 51 56 ff74240c }
- $sequence_93 = { 4803df 410fb64101 33d2 488d0cc3 }
- $sequence_94 = { 85d2 4d8bf1 458bf8 8bc2 }
- $sequence_95 = { e8???????? 8d45fc 50 8b4508 e8???????? }
- $sequence_96 = { 50 57 e8???????? e9???????? 68???????? }
- $sequence_97 = { ff15???????? 488bcf 48870d???????? 483bcf }
- $sequence_98 = { 33db 895d08 eb03 8b5d08 }
- $sequence_99 = { 488d0cc3 48890d???????? 410fb64103 488d0cc3 }
- $sequence_100 = { ff15???????? 4885db 740c 4c8b0d???????? e9???????? }
- $sequence_101 = { c3 418bd8 4803df 410fb64101 }
- $sequence_102 = { e8???????? 85c0 7507 33db 895d08 }
- $sequence_103 = { 488bce ff15???????? 488b0d???????? 33d2 4c63c0 }
- $sequence_104 = { 6a00 ff35???????? ff15???????? 33db 6a01 }
- $sequence_105 = { 8a4b1c 488b4558 4c8b4d30 4c8b4510 }
- $sequence_106 = { 448be8 418b4310 41394308 410f474308 }
- $sequence_107 = { 488d0cc3 48890d???????? 410fb64102 488d0cc3 }
- $sequence_108 = { 33d2 ff15???????? 483bc3 4c8be8 }
- $sequence_109 = { 33d2 498bcc 498bfd e8???????? 493bc5 7405 }
- $sequence_110 = { 5b c3 a1???????? 83c040 50 ff15???????? eb08 }
- $sequence_111 = { 8b3d???????? 56 ffd7 53 56 }
- $sequence_112 = { e8???????? 0945fc 47 83c304 3b3e 72dc 8b45fc }
- $sequence_113 = { c9 c20400 53 56 8bf0 8a06 }
- $sequence_114 = { 8bf1 05fefeffff 33db 33c9 }
- $sequence_115 = { 8b02 43 8acb d3c0 33c6 33442410 8bf0 }
- $sequence_116 = { ff15???????? 8ac3 5b c9 c20400 53 }
- $sequence_117 = { 8bf0 8932 83c204 ff4c240c 75e6 5e 5b }
- $sequence_118 = { 4533c9 4889442428 215c2420 4533c0 }
- $sequence_119 = { 50 8d442430 50 8d442428 50 8d442428 }
- $sequence_120 = { 480f45f2 832700 458be0 bb08000000 }
- $sequence_121 = { ff15???????? 4c8d4c2450 4c8d442458 8d5001 488bce e8???????? 85c0 }
- $sequence_122 = { ff15???????? 4883f8ff 4c8be0 0f8583000000 488b0d???????? 4d8bc5 }
- $sequence_123 = { e9???????? 33c9 bb26040000 48870d???????? }
- $sequence_124 = { ff15???????? 49bb00c0692ac9000000 488bcf 4c019c24d8010000 ff15???????? 6641b85c00 33d2 }
- $sequence_125 = { 83c701 e9???????? 488b8424c8010000 498bcc bb01000000 4c8928 }
- $sequence_126 = { ff15???????? 488d542440 488bcd ff15???????? 4883f8ff }
- $sequence_127 = { 4c8bc7 33d2 ff15???????? 33ff 4885ff }
- $sequence_128 = { 488bd6 ff15???????? eb14 488b0d???????? 4c8bc7 33d2 }
- $sequence_129 = { 6a00 ff35???????? ffd3 8bd8 85db 7476 }
- $sequence_130 = { 41b905000000 488bd8 ff15???????? 488bcb }
- $sequence_131 = { 4c8be8 0f841c010000 448b05???????? 33d2 488bc8 4c33c7 e8???????? }
- $sequence_132 = { 7416 a1???????? 83c004 50 be???????? }
- $sequence_133 = { 498bcf ff15???????? 448bf0 488bce ff15???????? }
- $sequence_134 = { 895df4 895df0 c745f857000000 bf19010000 }
- $sequence_135 = { 7520 41390424 741a 498d4c2401 }
- $sequence_136 = { 488b0d???????? 448bc0 8bd8 33d2 4983c001 }
- $sequence_137 = { a1???????? 25efff0000 0bc2 e9???????? }
- $sequence_138 = { 4c63c0 33d2 4983c00c ff15???????? }
- $sequence_139 = { 215c2420 4533c9 4533c0 33d2 ff15???????? 85c0 7511 }
- $sequence_140 = { 6a03 8935???????? 8935???????? 8935???????? }
- $sequence_141 = { e9???????? 488bcb ff15???????? a810 }
- $sequence_142 = { 803f2a 750b 4883c701 83c3ff }
- $sequence_143 = { 41be01000000 33c9 418bd6 ff15???????? }
- $sequence_144 = { 53 56 8bf1 05fefeffff }
- $sequence_145 = { 57 4154 4155 4156 4883ec50 488bf1 }
- $sequence_146 = { 5e 33c0 c9 c20400 55 8bec 51 }
- $sequence_147 = { 4889040f 4883c708 492bf6 75db }
- $sequence_148 = { 8bc6 e8???????? 8b06 8b08 57 ff7510 }
- $sequence_149 = { 750a 488bcf e8???????? 8bd8 488b0d???????? 4c8bc7 }
- $sequence_150 = { 5f c20400 55 8bec 83e4f8 81ec9c000000 }
- $sequence_151 = { 488d542438 488bcb e8???????? eb02 }
- $sequence_152 = { 8bc7 e8???????? 8d4618 8b08 50 51 }
- $sequence_153 = { 6a20 40 50 ffd6 }
- $sequence_154 = { 488bd3 ff15???????? 488b8c2428020000 8bf0 ff15???????? }
- $sequence_155 = { 7417 4863461c 2b6e1c 4c03e8 488b4610 48894718 }
- $sequence_156 = { 21442428 488b8c2428020000 488364242000 448d4803 }
- $sequence_157 = { 21b42410020000 eb0d ff15???????? 89842410020000 }
- $sequence_158 = { 488bcb ff15???????? 8bc8 ff15???????? 21b42410020000 }
- $sequence_159 = { 4885c9 7405 e8???????? 4883c428 c3 488d82204a0000 488982284a0000 }
- $sequence_160 = { 418bcd e8???????? 8b842410020000 4c8d9c24f0010000 }
- $sequence_161 = { 488b15???????? 4c8d842428020000 48c7c101000080 ff15???????? }
- $sequence_162 = { e8???????? 5e 5f c9 c3 51 53 }
- $sequence_163 = { 50 57 6a01 ff7508 ffd6 85c0 742b }
- $sequence_164 = { 448bcf 4533c0 e8???????? 483bc3 488905???????? 0f84dc000000 }
- $sequence_165 = { e8???????? 488b0d???????? 4c8bc3 33d2 ff15???????? 488b0d???????? 4c8bc7 }
- $sequence_166 = { 4c8d40cc 33d2 33c9 e8???????? 85c0 0f8561010000 }
- $sequence_167 = { 7415 397b44 7510 488b0b e8???????? 85c0 0f859b000000 }
- $sequence_168 = { ffc1 807c043000 7531 8bd3 2bd1 8917 }
- $sequence_169 = { 84c0 0f89a3000000 8b434c a804 7415 397b44 7510 }
- $sequence_170 = { 7505 217b3c eb0b 8b434c 84c0 0f89a3000000 8b434c }
- $sequence_171 = { 85c0 0f8561010000 8b4348 a801 742c }
- $sequence_172 = { 742c 488b0b e8???????? 85c0 0f85e8000000 488b4608 488b0e }
- $sequence_173 = { 85c0 0f859b000000 4863533c 488b4608 }
- $sequence_174 = { ba10000000 488bc8 e8???????? 48898424e0010000 4885c0 }
- $sequence_175 = { 4c8d442470 488d542440 e8???????? 8bd8 85c0 }
- $sequence_176 = { 33d2 468d44385f ff15???????? 4c8bf0 }
- $sequence_177 = { 488bf8 4885c0 7427 488d542420 b901020000 ff15???????? 85c0 }
- $sequence_178 = { 4c89642448 ff15???????? 8bd8 83f8ff }
- $sequence_179 = { 488bc8 458bf9 33ff e8???????? 4c8be8 4885c0 7508 }
- $sequence_180 = { 8bd8 85c0 0f85f3010000 4c8b842418020000 8d5808 488d8c24b0000000 4d85c0 }
- $sequence_181 = { 448d4256 ff15???????? 4c8be0 4885c0 0f8405010000 ff15???????? }
- $sequence_182 = { 90 57 51 8b742420 8b7c241c 8b4c2434 }
- $sequence_183 = { 56 57 51 90 8b742428 }
- $sequence_184 = { 8b5508 035510 8b3a 83c204 }
- $sequence_185 = { 01f2 6683f9ff 896c2428 7508 }
- $sequence_186 = { eb67 8044241301 0fb6ca 01cb 30c9 eb59 }
- $sequence_187 = { 83c304 894c2410 56 90 }
- $sequence_188 = { 5e 01d5 01d3 b101 3b5c2428 0f8266ffffff }
- $sequence_189 = { 8b5d10 6601da c1ca03 895510 3010 }
+ $sequence_0 = { 6a00 ff15???????? ff15???????? 50 e8???????? }
+ $sequence_1 = { ff15???????? 85c0 740f 6a07 }
+ $sequence_2 = { ff15???????? 85c0 741f 6880000000 }
+ $sequence_3 = { 6a20 6a00 6a00 6a00 8b5508 52 6a00 }
+ $sequence_4 = { e8???????? 83c410 6a00 6a02 6a02 6a00 6a00 }
+ $sequence_5 = { 6a01 6a00 68???????? e8???????? 83c40c 33c0 }
+ $sequence_6 = { e8???????? 99 b90d000000 f7f9 }
+ $sequence_7 = { 52 ff15???????? 6a00 6a00 6a00 6a00 68???????? }
+ $sequence_8 = { 50 e8???????? 83c404 e8???????? e8???????? ff15???????? }
+ $sequence_9 = { 68???????? ff15???????? 8d85f8fdffff 50 68???????? }
+ $sequence_10 = { 6a00 ff15???????? 85c0 7418 ff15???????? }
+ $sequence_11 = { 6a01 ff15???????? ff15???????? b001 }
+ $sequence_12 = { 6a00 682a800000 6a00 ff15???????? }
+ $sequence_13 = { 52 683f000f00 6a00 68???????? 6802000080 ff15???????? 85c0 }
+ $sequence_14 = { 68???????? ff15???????? e9???????? 8d45fc }
+ $sequence_15 = { 50 ff15???????? 8945fc 837dfc00 7416 8b4df8 }
+ $sequence_16 = { f7f9 81c210270000 52 e8???????? }
+ $sequence_17 = { e8???????? 99 b930750000 f7f9 81c210270000 }
+ $sequence_18 = { 50 e8???????? 59 59 85c0 7573 }
+ $sequence_19 = { 3d00010000 7504 83c8ff c3 8b542404 }
+ $sequence_20 = { 7508 6a00 ff15???????? 6804010000 }
+ $sequence_21 = { 6a21 50 e8???????? c60000 }
+ $sequence_22 = { e8???????? 83c41c 6880000000 8d4c240c 51 ff15???????? 6a00 }
+ $sequence_23 = { 52 e8???????? 99 b960ea0000 f7f9 }
+ $sequence_24 = { 6880000000 8d8424b4000000 50 6a0c 8d4c2420 51 6800142d00 }
+ $sequence_25 = { 83790c00 7419 83791800 7418 83c130 83c004 81f9???????? }
+ $sequence_26 = { 72f7 53 33c0 56 57 663bc2 }
+ $sequence_27 = { 56 57 68e8030000 ff15???????? e8???????? be???????? }
+ $sequence_28 = { 50 8d45ec 50 6805000020 }
+ $sequence_29 = { 8d45f8 50 8d45e4 50 6805000020 }
condition:
- 7 of them and filesize <2940928
+ 7 of them and filesize <2490368
}
-rule MALPEDIA_Win_Gophe_Auto : FILE
+rule MALPEDIA_Win_Exaramel_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "16e0cb01-a4d6-50a6-a1a9-0b51a47ac5bb"
+ id = "55f2eda2-5892-5031-b695-0db68fb2d622"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gophe"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gophe_auto.yar#L1-L156"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.exaramel"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.exaramel_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "76443f258bf0b4ec57a2e148e70e44580d537156fff783e9c0d09eeae8abd68d"
+ logic_hash = "746a3a522250db31852461e3a3a31996745122c83c94633343076460de517b9c"
score = 75
quality = 75
tags = "FILE"
@@ -157309,38 +164266,32 @@ rule MALPEDIA_Win_Gophe_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 833902 0f94c0 84c0 7407 }
- $sequence_1 = { b905000000 ff15???????? 8b05???????? 85c0 }
- $sequence_2 = { 56 8b7510 57 68???????? c70605000000 }
- $sequence_3 = { b801000000 eb09 83c8ff eb04 }
- $sequence_4 = { 51 a1???????? 33c5 50 8d45f4 64a300000000 68e0000000 }
- $sequence_5 = { 5b 8be5 5d c3 b896ffffff }
- $sequence_6 = { 64a300000000 68e0000000 e8???????? 83c404 }
- $sequence_7 = { 6805010000 8d85e0fdffff 50 68???????? }
- $sequence_8 = { 85c9 0f94c0 89431c 85c9 }
- $sequence_9 = { 7838 488b4c2440 ff15???????? 8bf8 }
- $sequence_10 = { 2bf0 b8abaaaa2a f7ee c1fa03 8bf2 }
- $sequence_11 = { 8bf8 488b4c2440 488b01 ff5010 85ff }
- $sequence_12 = { e8???????? 488d942488000000 488d4c2460 e8???????? }
- $sequence_13 = { c684249000000000 488b542440 488b4a10 668379300b }
- $sequence_14 = { 6a00 56 e8???????? 83c40c c706ffffffff }
- $sequence_15 = { 5d c3 b896ffffff 5f 5e 5b }
+ $sequence_0 = { 8bf0 85f6 7425 8d4e02 51 e8???????? 8b4d0c }
+ $sequence_1 = { 83c408 85c0 7834 ff750c ff7508 ff75fc }
+ $sequence_2 = { 3934bd60dd4100 7531 e8???????? 8904bd60dd4100 }
+ $sequence_3 = { 8be5 5d c3 81f903000080 7519 ff35???????? b8???????? }
+ $sequence_4 = { 7439 6aff 50 ff15???????? 85c0 7538 56 }
+ $sequence_5 = { 50 e8???????? ffb5f0fdffff e8???????? 83c414 8b4dfc }
+ $sequence_6 = { ffb5a4faffff ff15???????? 85c0 0f85c1feffff 33f6 }
+ $sequence_7 = { 5d c3 f68594f7ffff10 746d }
+ $sequence_8 = { 744b 817df4e8030000 b801000000 68f0030000 0f42f0 }
+ $sequence_9 = { c3 8b03 8d4dec 51 6800040000 }
condition:
- 7 of them and filesize <1582080
+ 7 of them and filesize <294912
}
-rule MALPEDIA_Win_Derusbi_Auto : FILE
+rule MALPEDIA_Win_Onionduke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7e17bc22-c095-50d8-a4c2-1bf339697e7b"
+ id = "bc18bebb-924f-5db1-bda1-575db25c40f5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.derusbi"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.derusbi_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.onionduke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.onionduke_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "325459f5183ff3b300e1f181ae53b4a2cb1c12e04a563b27e6a394d452c11ac4"
+ logic_hash = "2b5a6150c91e41c1ea04d8a66d543531da34a08cde94cd3e5e729e90a4473cac"
score = 75
quality = 75
tags = "FILE"
@@ -157354,32 +164305,32 @@ rule MALPEDIA_Win_Derusbi_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b819c000000 8d4de8 51 8d4dec 51 ffb00c010000 c745e810000000 }
- $sequence_1 = { 8d55ec e8???????? 8d4f08 56 8d55f3 e8???????? 59 }
- $sequence_2 = { 8913 ff15???????? 83c40c e8???????? b301 57 ff15???????? }
- $sequence_3 = { 33c5 8945f8 8b4508 66833800 53 56 57 }
- $sequence_4 = { 8945f8 8b4508 56 57 50 8d8de4fbffff 899590f9ffff }
- $sequence_5 = { 64a300000000 8b5d0c 8b4508 894c2414 89442418 85db 0f8457050000 }
- $sequence_6 = { 50 ffd6 b903010000 2bc8 51 8d85ecfdffff 68???????? }
- $sequence_7 = { 56 56 56 6a03 56 68???????? 6800040000 }
- $sequence_8 = { ffd3 50 57 ffb5f8fbffff ff15???????? 83c410 85c0 }
- $sequence_9 = { ffb5d4fdffff 898db8fdffff ffb5ecfdffff ffb5f0fdffff ff15???????? 3bc7 }
+ $sequence_0 = { 33d2 895e68 66895658 8b550c 8d4202 c645fc04 8945ec }
+ $sequence_1 = { c1e81f 03c2 897dcc 0f84d0000000 897dd0 eb02 }
+ $sequence_2 = { 384b01 7506 40 380c18 }
+ $sequence_3 = { 894ee4 894ffc 8d4eec 8d57ec 8d5fec }
+ $sequence_4 = { 56 8bf1 837e0c00 751e 6a04 e8???????? 83c404 }
+ $sequence_5 = { 3bfb 72ac 5f 5e }
+ $sequence_6 = { 8b4e44 8b09 85d2 7405 }
+ $sequence_7 = { 8910 894ed0 8b56e0 8957e0 8b56e4 }
+ $sequence_8 = { e8???????? 83c404 33c0 eb66 8bc6 8d5001 }
+ $sequence_9 = { 80f90f 7f05 80c157 eb02 32c9 }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <671744
}
-rule MALPEDIA_Win_Artfulpie_Auto : FILE
+rule MALPEDIA_Win_Nabucur_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "76593040-a588-559b-a14b-1edef48802a1"
+ id = "01e16fcc-e93c-502a-bf23-e97657c28f28"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.artfulpie"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.artfulpie_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nabucur"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nabucur_auto.yar#L1-L161"
license_url = "N/A"
- logic_hash = "61512abd96fd629a35a0b2673ca4f2027db7aa6e8bcee3bfbea21b9b36b003b2"
+ logic_hash = "6100efc8bca15f40de853b2fa2bd4731e512123d488b941f31d2f09287a69887"
score = 75
quality = 75
tags = "FILE"
@@ -157393,32 +164344,38 @@ rule MALPEDIA_Win_Artfulpie_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 894ddc c745e0a8204100 e9???????? c745e0a4204100 }
- $sequence_1 = { 8d1c8568524100 8b03 8b15???????? 83cfff 8bca 8bf2 }
- $sequence_2 = { 23c1 83c008 5d c3 8b04c544ec4000 5d }
- $sequence_3 = { 7514 8b7830 8b00 397838 740a 33d2 }
- $sequence_4 = { 6a00 8d854cfcffff c745fc2a2f2a00 50 }
- $sequence_5 = { 660f282d???????? 660f59f5 660f28aa101f4100 660f54e5 660f58fe 660f58fc 660f59c8 }
- $sequence_6 = { e8???????? 85c0 7432 8bcb e8???????? }
- $sequence_7 = { 8b5d10 8b0485984e4100 56 8b7508 57 8b4c0818 }
- $sequence_8 = { 50 53 ff15???????? 85c0 7455 8b7df0 }
- $sequence_9 = { 6a41 5f 894df0 8b34cdf00e4100 8b4d08 6a5a }
+ $sequence_0 = { 48 49 85c0 75fa }
+ $sequence_1 = { 48 5f 894500 5d }
+ $sequence_2 = { 48 83e908 85c0 75f0 57 }
+ $sequence_3 = { 48 83e904 85c0 7ff3 8bf0 8b442448 }
+ $sequence_4 = { 48 83f801 89442418 0f8f15ffffff }
+ $sequence_5 = { 33ff 33f6 4a c744244001000000 }
+ $sequence_6 = { 009eaa030000 0fb686aa030000 57 83f80a 0f876d010000 }
+ $sequence_7 = { 48 8906 8d442410 50 }
+ $sequence_8 = { ba86a33ffb 83e904 ba575a2bfd eb69 83f901 7519 }
+ $sequence_9 = { 3f 71e3 0c42 869576f1896a 86f6 }
+ $sequence_10 = { 732e 5c 54 7346 b654 8c534c }
+ $sequence_11 = { 141b 46 ec 54 732e }
+ $sequence_12 = { 01e4 01f4 1481 0491 00850cf41196 }
+ $sequence_13 = { ff75f8 ff35???????? ff15???????? 8b7520 8b45e4 }
+ $sequence_14 = { 8b4608 50 ff15???????? 61 eb11 }
+ $sequence_15 = { 06 e409 9a1496099a1581 0d911c9060 9d 01e4 }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <1949696
}
-rule MALPEDIA_Win_Mutabaha_Auto : FILE
+rule MALPEDIA_Win_Dustman_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "04cdad38-c730-58bf-ac9f-7881643cfe37"
+ id = "36b1ddf2-cf7c-571e-9cd1-f2576b628e0f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mutabaha"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mutabaha_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dustman"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dustman_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "21a56ac17d7181e1f264aab4aad9c0f8a40e021362f525e9ed7460f5330637ce"
+ logic_hash = "7655ffd1fc19c69013d45a561f004630940d9eb32b369648a9a2d4d61dad6d9e"
score = 75
quality = 75
tags = "FILE"
@@ -157432,32 +164389,32 @@ rule MALPEDIA_Win_Mutabaha_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 8d9518ffffff 8d8d68feffff e8???????? 8d8d48ffffff c645fc09 }
- $sequence_1 = { 8b85dcfdffff 83f808 7213 40 8d8dc8fdffff 50 ffb5c8fdffff }
- $sequence_2 = { c745b800000000 c645a800 c745c06cac4700 85c0 7409 50 e8???????? }
- $sequence_3 = { 85d2 7424 8b7c2424 8d4f08 833900 740a 40 }
- $sequence_4 = { 0fb7f8 eb43 83f803 7536 ff734c ff75d4 e8???????? }
- $sequence_5 = { c745ec00000000 668945dc e8???????? 8d45dc c745fc05000000 50 8bce }
- $sequence_6 = { e8???????? c7465400000000 8bc6 8b4df4 64890d00000000 59 5e }
- $sequence_7 = { 8d8d84fdffff c78598fdffff07000000 c78594fdffff00000000 66898584fdffff e8???????? 57 ba???????? }
- $sequence_8 = { 0103 115304 33c0 5f 5e 5b 8be5 }
- $sequence_9 = { e9???????? 8d8d5cffffff e9???????? 8d4dbc e9???????? 8d4dd4 e9???????? }
+ $sequence_0 = { 488d150d620100 4b8d1c36 4c897710 4c8bc3 488bce }
+ $sequence_1 = { 448d4303 895c2428 488d0ddb720000 4533c9 4489442420 }
+ $sequence_2 = { 4903cb 48894d48 488bca 492bca 4c8d9dca010000 4903cb 48894d50 }
+ $sequence_3 = { 884803 420fb60c20 884804 420fb60c28 884805 0fb60c10 }
+ $sequence_4 = { f20f102d???????? f20f590d???????? f20f59ee f20f5ce9 f2410f1004c1 488d15767f0000 f20f1014c2 }
+ $sequence_5 = { 7405 e8???????? b001 4883c428 c3 488d158ba50000 }
+ $sequence_6 = { 492bca 4c8d9dcd010000 4903cb 48894d68 488bca 492bca 4c8d9dce010000 }
+ $sequence_7 = { 488d053f1f0000 498b0b 4889442450 488b85e0040000 4889442460 486385f0040000 }
+ $sequence_8 = { e8???????? 4885c0 7509 488d0597420100 eb04 4883c024 }
+ $sequence_9 = { 48c1e028 480bd8 0fb6852e020000 48c1e030 480bd8 0fb6852f020000 48c1e038 }
condition:
- 7 of them and filesize <1220608
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Qhost_Auto : FILE
+rule MALPEDIA_Win_Alpc_Lpe_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5a22ec0c-4f17-55ab-b241-2378f7015545"
+ id = "1d3d4f14-881f-5a73-b345-a76e12b3dfd0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.qhost"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.qhost_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alpc_lpe"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alpc_lpe_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "c30effbf965ec02215e2576b89ba366bebeed097f08848009dcc3ab3b7556ec0"
+ logic_hash = "21b1493d78b90781647fb0ea2e97a709ccc21e177ddf748dd3e2118819bbc37e"
score = 75
quality = 75
tags = "FILE"
@@ -157471,32 +164428,32 @@ rule MALPEDIA_Win_Qhost_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c60000 8b4dfc 83e901 894dfc ebdc 8b4508 }
- $sequence_1 = { 40 884598 8b0d???????? 51 e8???????? }
- $sequence_2 = { ff15???????? 898550beffff c78538beffff00000000 837df400 }
- $sequence_3 = { 7507 b805000080 eb36 8b5508 52 68???????? e8???????? }
- $sequence_4 = { 03d0 52 ff15???????? 83c408 }
- $sequence_5 = { 68???????? 68???????? 68ff030000 68???????? ff15???????? 83c410 }
- $sequence_6 = { 837df800 0f84dc000000 c7854cbeffff00000000 c78550beffff00000000 eb1e }
- $sequence_7 = { 68???????? 680f270000 68???????? ff15???????? 83c410 ff15???????? }
- $sequence_8 = { 8bec 81ec6c0b0000 c785f0fdffff00000000 c785e8fdffff00000000 c785d4fdffff00000000 c745fc00000000 c785f4fdffff00000000 }
- $sequence_9 = { 50 6800040000 8d8d00fcffff 51 8b95c8fbffff 52 }
+ $sequence_0 = { ba31000000 4c8d05b3a10000 448bcb 482bd6 e8???????? 4883c603 881f }
+ $sequence_1 = { 4533c0 48c7c102000080 4889442420 ff15???????? ff15???????? 488b4c2448 }
+ $sequence_2 = { 57 4881ec58010000 488d6c2420 488bfc b956000000 }
+ $sequence_3 = { 488b8d00010000 e8???????? 488b8dd8000000 488bd1 488bc8 e8???????? }
+ $sequence_4 = { e8???????? 488d0da1af0000 e8???????? 488d0d85af0000 }
+ $sequence_5 = { 488bc8 e8???????? 488b5508 488b8d00010000 }
+ $sequence_6 = { e8???????? 488d0dc1ad0000 e8???????? 488d0da5ad0000 }
+ $sequence_7 = { 488d6c2430 488bfc b98a000000 b8cccccccc f3ab 488b8c2448020000 488b05???????? }
+ $sequence_8 = { 488d1deb7e0000 4184c0 7539 410bc0 488d542458 488d0ddfd30000 8905???????? }
+ $sequence_9 = { 488b4c2438 488d442430 4889442428 4c8d4c2434 488d442440 4533c0 488d1548830000 }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <540672
}
-rule MALPEDIA_Win_Udpos_Auto : FILE
+rule MALPEDIA_Win_Gcman_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "49a8c6d9-3919-52d8-b9a1-bc6d433f2d9f"
+ id = "c3dd4f52-d013-5409-b72e-5ec2ecf28c4b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.udpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.udpos_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gcman"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gcman_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "ffccd56d9879c5a40153befe0b99e30b88fecb63ad13af5b9ec71c40ee069e0c"
+ logic_hash = "646fd6c677e3b810f35c02ba75646dde96abf31f60dd053593e8964313629ea3"
score = 75
quality = 75
tags = "FILE"
@@ -157510,87 +164467,77 @@ rule MALPEDIA_Win_Udpos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bc8 23cf 0bf1 8b4dfc 03d6 0353fc 8bf0 }
- $sequence_1 = { 8b4dfc 83c404 5f 8bc3 33cd }
- $sequence_2 = { 52 e8???????? 83c418 833d????????00 0f8596000000 8d85ccf3ffff 50 }
- $sequence_3 = { 8888f8e84000 40 ebe6 ff35???????? ff15???????? 85c0 7513 }
- $sequence_4 = { 7e1e 8d575c 85f6 7517 6639944dfcfdffff 7508 be01000000 }
- $sequence_5 = { 51 e8???????? a1???????? 8b3d???????? 83c418 }
- $sequence_6 = { 7e0d 83f809 7e08 a1???????? 8b7024 56 8d4d9c }
- $sequence_7 = { e8???????? 68f4010000 6a00 8d8dc8fcffff 51 e9???????? }
- $sequence_8 = { ffd6 8d953cffffff 52 8d85e0f8ffff 50 ffd6 }
- $sequence_9 = { 40 3bc3 7cef 8b85a0feffff 50 e8???????? }
+ $sequence_0 = { a1???????? 8944240c c7442408???????? 8b85d0ebffff }
+ $sequence_1 = { 0375e0 01f1 81e959dc6b54 c1c10f 01d9 89c6 }
+ $sequence_2 = { 89442408 c7442404???????? 8d8528eaffff 890424 e8???????? }
+ $sequence_3 = { 8944240c c7442408???????? 89542404 8b45f4 890424 }
+ $sequence_4 = { c705????????00000000 c705????????00000000 e8???????? 85c0 7439 8d859ceaffff 89442410 }
+ $sequence_5 = { c745c400000000 e9???????? c744241c00000000 c744241800000000 c744241403000000 c744241000000000 }
+ $sequence_6 = { 83bdd4ebffff00 750c c7042401000000 e8???????? }
+ $sequence_7 = { 8b8558efffff 890424 e8???????? 83ec08 81bde8efffff03010000 7405 }
+ $sequence_8 = { 89c6 31d6 31ce 0375d8 01f3 81eb1b662419 c1c30b }
+ $sequence_9 = { 40 890424 e8???????? 8945fc 8b45fc 89442408 8b450c }
condition:
- 7 of them and filesize <163840
+ 7 of them and filesize <81920
}
-rule MALPEDIA_Win_Uroburos_Auto : FILE
+rule MALPEDIA_Win_Matryoshka_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "205256f7-2469-53ee-990c-6fdfb536a7d1"
- date = "2023-01-25"
- modified = "2023-01-26"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.uroburos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.uroburos_auto.yar#L1-L234"
+ id = "3e8b1848-3ea9-5312-86aa-83712c0906a6"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.matryoshka_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.matryoshka_rat_auto.yar#L1-L141"
license_url = "N/A"
- logic_hash = "7cd6167d1ac85667ccf6f37a04c885a4dbb4d487c7aa8e68ed00f9a40de671ad"
+ logic_hash = "e63bf906be3841d18c1769641826f4871bcf6c179928d9c22e19c757766e13e1"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20230124"
- malpedia_hash = "2ee0eebba83dce3d019a90519f2f972c0fcf9686"
- malpedia_version = "20230125"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7526 85d2 7411 8b493c }
- $sequence_1 = { 85d2 7406 8d4801 0fafcd }
- $sequence_2 = { 09c9 7407 ffd1 a1???????? 832d????????04 3905???????? 73de }
- $sequence_3 = { 85c0 7405 e9???????? 448bc7 }
- $sequence_4 = { 8b493c 8bc2 4881c108010000 483bc1 }
- $sequence_5 = { 29c0 eb4e 57 56 }
- $sequence_6 = { 85c0 750d 48837c245000 0f95c0 8803 33c0 }
- $sequence_7 = { 895c2430 e9???????? 33d2 448d4268 }
- $sequence_8 = { 09c0 7503 21450c 837d0c00 }
- $sequence_9 = { 83fe01 89450c 750c 09c0 7537 57 50 }
- $sequence_10 = { 54 5d 53 8b5d08 56 8b750c 09f6 }
- $sequence_11 = { 5f 09ff 59 751e 56 ff15???????? 8d86e8030000 }
- $sequence_12 = { 40 c20c00 55 54 5d }
- $sequence_13 = { 7704 4183c220 4585c9 740a 453bca 7505 4d85c0 }
- $sequence_14 = { 8bc1 f7f5 85d2 7406 }
- $sequence_15 = { 7433 eb13 8b0d???????? 8b09 09c9 7407 }
- $sequence_16 = { 48 8bf0 49 2bf5 4c }
- $sequence_17 = { 83c601 49 83c508 41 3bdf 7c82 45 }
- $sequence_18 = { 750a 8d43ff e9???????? 33db }
- $sequence_19 = { b901000000 e8???????? 48 85c0 48 8bd8 }
- $sequence_20 = { 85c0 7434 48 83c310 83c701 48 }
- $sequence_21 = { ff15???????? 44 8bd8 49 c1e320 4c }
- $sequence_22 = { 8b8f58010000 e8???????? 48 895c2430 }
- $sequence_23 = { 8b5c2450 48 83c448 c3 4c 8bc6 }
+ $sequence_0 = { b037 c3 b073 c3 }
+ $sequence_1 = { c3 b06f c3 b063 c3 }
+ $sequence_2 = { 8b46fc 8947fc 49 75ed 5f ff4210 }
+ $sequence_3 = { 8b4704 ff4710 ff07 8b0488 }
+ $sequence_4 = { 74e3 440fb603 430fbe841040d30500 85c0 }
+ $sequence_5 = { 8b4708 3b470c 7507 8bcf }
+ $sequence_6 = { 74e2 ff8170040000 83b97004000002 0f8493010000 83cfff 488d2d572c0300 }
+ $sequence_7 = { 74e9 488d15b9450400 488bcb e8???????? }
+ $sequence_8 = { 74de 83cbff 488bca e8???????? 90 48897c2420 }
+ $sequence_9 = { 8b4708 b120 8b570c 8b7718 }
+ $sequence_10 = { 74e6 488d152fac0300 488bcb e8???????? }
+ $sequence_11 = { 8b4704 8b3491 890491 8bd6 }
+ $sequence_12 = { 74e2 ff8170040000 83b97004000002 0f84eb010000 83cfff 4c8d3dde290300 }
+ $sequence_13 = { 8b4704 8bf1 33d1 81e6ff030000 }
condition:
- 7 of them and filesize <1136640
+ 7 of them and filesize <843776
}
-rule MALPEDIA_Win_Unidentified_107_Auto : FILE
+rule MALPEDIA_Win_Coreshell_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3e7e44ff-0f02-5267-8346-e5f949ff1ff2"
+ id = "f8b1ab7a-5e3f-5f01-8787-4d480849e1bc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_107"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_107_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.coreshell"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.coreshell_auto.yar#L1-L424"
license_url = "N/A"
- logic_hash = "36a3784a29d5434d0fa9e9c5acdfc21d8509c8e92eeaa689801f442b7fb11fdb"
+ logic_hash = "23addbe4ab3205859c50e41702fa9e9c554a336132b182d2582fda2f9387a324"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -157602,32 +164549,70 @@ rule MALPEDIA_Win_Unidentified_107_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4139d9 75d8 4c89e1 e8???????? }
- $sequence_1 = { 48897008 4c89e1 ff15???????? 488b05???????? 4c89e1 48891d???????? }
- $sequence_2 = { 0f83d6fdffff 4c8b35???????? 8b7304 448b2b 4883c308 4c01f6 44032e }
- $sequence_3 = { 034208 4839c1 7214 4883c228 }
- $sequence_4 = { 0f8584000000 4c8b3e 4929c7 4901cf }
- $sequence_5 = { e8???????? 4c89e1 ff15???????? 31c0 4883c428 }
- $sequence_6 = { 8b15???????? 85d2 0f8ea1feffff 488b35???????? 31db 4c8d65fc }
- $sequence_7 = { e8???????? 4989c7 48b9ca0e99c700000000 e8???????? 4883c464 488b4c2408 }
- $sequence_8 = { 4183fc01 0f85a9feffff 8b05???????? 85c0 0f8e9bfeffff 83e801 488b1d???????? }
- $sequence_9 = { 4c89442418 4c894c2420 4883ec64 48c7c10f15af3d }
+ $sequence_0 = { 68???????? 52 ffd7 ffd0 }
+ $sequence_1 = { 56 6810270000 ff15???????? be06000000 e8???????? 85c0 7401 }
+ $sequence_2 = { 56 ff15???????? 83c40c 3bc6 }
+ $sequence_3 = { c20400 50 a1???????? 6a00 }
+ $sequence_4 = { 8b15???????? 6a01 51 68???????? 52 }
+ $sequence_5 = { 50 57 6a08 51 ff15???????? 8bf8 85ff }
+ $sequence_6 = { 50 ff15???????? 83c404 32db }
+ $sequence_7 = { 56 6a00 6a00 681c800000 6a00 }
+ $sequence_8 = { 6a00 6a00 ff15???????? 8bf0 ff15???????? 50 }
+ $sequence_9 = { 6804010000 6a08 8b15???????? 52 ff15???????? }
+ $sequence_10 = { 8d4c2400 56 51 6a00 }
+ $sequence_11 = { 85c0 7402 eb14 c745f000000000 68e0930400 }
+ $sequence_12 = { 68???????? 50 a3???????? ffd6 a3???????? a1???????? }
+ $sequence_13 = { 8bf1 8b4604 85c0 7407 50 ff15???????? 8b36 }
+ $sequence_14 = { ff15???????? ffd0 85c0 7508 ff15???????? }
+ $sequence_15 = { 68???????? 6800080000 8d85fcefffff 50 ff15???????? }
+ $sequence_16 = { 68???????? 50 ffd6 6a00 6a00 6a00 }
+ $sequence_17 = { 51 56 8d442404 6a00 8bf1 50 }
+ $sequence_18 = { 51 8b0d???????? 52 50 57 68???????? 51 }
+ $sequence_19 = { 81e1ffff0000 81e1ffff0000 81e1ff000000 81e1ff000000 }
+ $sequence_20 = { 8d55f0 52 e8???????? 83c408 33c0 8b4df0 64890d00000000 }
+ $sequence_21 = { ff15???????? 50 68???????? 68???????? 8985f0fdffff 8d85f4fdffff 6804010000 }
+ $sequence_22 = { 85ed 7476 85ff 7516 8b5c241c 8b0d???????? 53 }
+ $sequence_23 = { 8b15???????? 57 6a00 52 ff15???????? 8b0d???????? 8bf0 }
+ $sequence_24 = { 8985f0fdffff 8d85f4fdffff 6804010000 50 ff15???????? 83c414 }
+ $sequence_25 = { c1e908 81e1ff000000 0fb6d1 52 }
+ $sequence_26 = { 8b8dd8edffff 51 8d95f4edffff 52 68???????? }
+ $sequence_27 = { 81e2ffff0000 81e2ffff0000 c1ea08 81e2ff000000 }
+ $sequence_28 = { 83c414 8d8df4fdffff 51 ff15???????? }
+ $sequence_29 = { 50 68???????? 8b0d???????? 51 ff15???????? ffd0 }
+ $sequence_30 = { 6888130000 ff15???????? c745f000000000 c745f400000000 }
+ $sequence_31 = { 56 51 56 6a01 }
+ $sequence_32 = { 8be8 8b442410 50 e8???????? }
+ $sequence_33 = { 8d8dfcefffff 51 ff15???????? ba00080000 }
+ $sequence_34 = { 50 ff15???????? a1???????? 83c418 }
+ $sequence_35 = { ffd6 ffd0 68???????? a3???????? }
+ $sequence_36 = { 57 8b3d???????? 68???????? ffd7 8b35???????? 68???????? 50 }
+ $sequence_37 = { 8908 813800000000 0f94c2 8b35???????? 8b3d???????? 0faff6 81c601000000 }
+ $sequence_38 = { 8908 813800000000 0f95c2 8b35???????? }
+ $sequence_39 = { a3???????? ffd7 8bd8 68???????? 53 }
+ $sequence_40 = { 53 a3???????? ffd6 68???????? a3???????? }
+ $sequence_41 = { 5f 5d c3 89e0 c70010270000 }
+ $sequence_42 = { 5f 5b 5d c3 b81c000000 }
+ $sequence_43 = { 8908 8b15???????? 89d6 81c609000000 }
+ $sequence_44 = { bf04010000 57 6a08 ff35???????? ff15???????? }
+ $sequence_45 = { 29d6 01f0 a3???????? e9???????? }
+ $sequence_46 = { 8908 8b00 8b5004 8b35???????? }
+ $sequence_47 = { 29d6 0faff0 31d2 f7f6 }
condition:
- 7 of them and filesize <254976
+ 7 of them and filesize <303100
}
-rule MALPEDIA_Win_Breach_Rat_Auto : FILE
+rule MALPEDIA_Win_Lyposit_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f70ab09f-8643-5192-b966-55a3dab88920"
+ id = "bce51077-57cf-5adb-b910-01a9e65c59f7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.breach_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.breach_rat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lyposit"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lyposit_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "8cb7f4b75bac273a3c54152da1b9e63a78dde17954dfd874b266899e47404327"
+ logic_hash = "6d3a7a695e65723557f6178bebcb83673702ff3e28dbc2c0dd967dcfab1ce86b"
score = 75
quality = 75
tags = "FILE"
@@ -157641,34 +164626,34 @@ rule MALPEDIA_Win_Breach_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5e 5b 8be5 5d c20400 884c240f 8d442418 }
- $sequence_1 = { 50 8bce e8???????? 8bc8 e8???????? 8d8dacf6ffff c745fcffffffff }
- $sequence_2 = { c1e81f 03c2 8985d8feffff 0f8479080000 83c724 89bde0feffff 8d9b00000000 }
- $sequence_3 = { c741140f000000 c7411000000000 c60100 e8???????? ff7510 8d4dd4 ff750c }
- $sequence_4 = { 8be5 5d c3 68???????? 8bce e8???????? b001 }
- $sequence_5 = { 8b5508 8bcb 0fb712 8bff 663910 7408 83c002 }
- $sequence_6 = { 42 8b5de0 3bd6 72f2 8b45a4 2bc6 50 }
- $sequence_7 = { c7471800010000 8b4df4 8bc7 c7470400000000 c7470800000000 5f 5e }
- $sequence_8 = { eb20 84c9 74ed 8b4df0 8d45d8 50 e8???????? }
- $sequence_9 = { e8???????? 68???????? 8d859cf4ffff c745fc5c000000 50 8bce e8???????? }
+ $sequence_0 = { ff510c 3bc3 0f8cf1000000 57 6a40 ffd6 8945dc }
+ $sequence_1 = { ff74240c 50 e8???????? a3???????? 59 }
+ $sequence_2 = { 33f6 8975d8 8975fc b9???????? e8???????? 50 e8???????? }
+ $sequence_3 = { 6a01 e8???????? 83c40c 397d10 7413 ff7510 }
+ $sequence_4 = { ff15???????? 8bf8 8975d8 6a04 803e55 7506 8d4601 }
+ $sequence_5 = { 83c40c 83f801 0f8556010000 015f3c 295f58 807f6c00 }
+ $sequence_6 = { 0f8479010000 8bd8 8b5768 03573c 8b4760 33f6 }
+ $sequence_7 = { 29775c 0175fc 837df801 894750 8b475c 743e }
+ $sequence_8 = { e8???????? 8945c4 8d4de0 51 ff75d0 56 }
+ $sequence_9 = { 8bfe e8???????? 33c0 eb0f 6a08 6a40 ffd3 }
condition:
- 7 of them and filesize <645120
+ 7 of them and filesize <466944
}
-rule MALPEDIA_Win_Zeus_Auto : FILE
+rule MALPEDIA_Win_Cameleon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7fc58452-b8ed-5f5d-9c4b-1944a46dd13e"
+ id = "65617330-75c8-57cf-8907-1895d87814f0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeus_auto.yar#L1-L231"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cameleon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cameleon_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "9dc359b19db229cc8d91a3a8afe15f58c5fe776d823ff66891a661f0a8422765"
+ logic_hash = "1c72ed0d3ea99fe45b9cdedee31a0c82e32752220a6d117c9414b55a84125b1d"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -157680,46 +164665,32 @@ rule MALPEDIA_Win_Zeus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb58 833f00 7651 8b5f08 }
- $sequence_1 = { 8b3a 3b7d08 740a 40 }
- $sequence_2 = { 8d443604 50 a1???????? 57 }
- $sequence_3 = { 8d442440 50 8d442428 50 0fb64304 }
- $sequence_4 = { 8d442448 50 ff15???????? 0fb744244e }
- $sequence_5 = { 8d4c3110 81f90000a000 7715 8918 c7400400000200 89780c }
- $sequence_6 = { 8918 c7400400000200 89780c ff4208 890a c645ff01 }
- $sequence_7 = { 8d442460 50 e8???????? 8b4508 }
- $sequence_8 = { e8???????? 84c0 7442 6a10 }
- $sequence_9 = { 891d???????? 891d???????? ffd6 68???????? }
- $sequence_10 = { 8bf3 6810270000 ff35???????? ff15???????? }
- $sequence_11 = { 8d8db0fdffff e8???????? 8ad8 84db }
- $sequence_12 = { 8ac3 5b c20800 55 8bec 83e4f8 }
- $sequence_13 = { c9 c20400 55 8bec f6451802 }
- $sequence_14 = { 56 ff15???????? 5e 8ac3 5b c20800 }
- $sequence_15 = { 84c0 0f84ac000000 b809080002 3945f4 7713 807d0801 0f8598000000 }
- $sequence_16 = { 0f86e3000000 8b03 3509080002 3d5c5b4550 740b 3d59495351 }
- $sequence_17 = { c745f809080002 e8???????? 8ad8 f6450c04 7473 }
- $sequence_18 = { 807b0244 7429 83fe04 0f82ec000000 8b1b 81f309080002 81fb5d515047 }
- $sequence_19 = { ff35???????? e8???????? 5f 5e 8ac3 }
- $sequence_20 = { 8d470c 50 c707000e0000 c7470809080002 }
- $sequence_21 = { b8d5000000 e8???????? 68e6010000 68???????? 6809080002 8bc6 50 }
- $sequence_22 = { 81fb5d515047 7410 81fb4f4d4156 7408 81fb59495354 7506 b364 }
- $sequence_23 = { 81fb59495354 7506 b364 6a14 eb18 81fb5a5c4156 740c }
+ $sequence_0 = { 53 56 57 8bf9 897df0 c745ec00000000 8b07 }
+ $sequence_1 = { 8a80f8c70410 8807 47 46 8bcb c6458301 e8???????? }
+ $sequence_2 = { 83ec18 8bd4 8965ec c7421000000000 c7421400000000 }
+ $sequence_3 = { 8d7dd0 837de408 0f437dd0 83ec18 8bd4 c7421000000000 c7421400000000 }
+ $sequence_4 = { 48 a3???????? ff15???????? 8b0d???????? 89048d98ce0510 5d c3 }
+ $sequence_5 = { 247f 88441628 eb12 0c80 88441628 8b0cbd50d60510 c644112900 }
+ $sequence_6 = { b83b000000 663bc8 0f94c0 84c0 7431 }
+ $sequence_7 = { 8d55dc c645fc02 8d8d24ffffff e8???????? 8bc8 8b01 }
+ $sequence_8 = { 8bd9 56 57 837b3800 0f848c010000 807b3d00 0f8482010000 }
+ $sequence_9 = { 5d c20400 85ff 75d4 897e10 837e1408 720f }
condition:
- 7 of them and filesize <319488
+ 7 of them and filesize <824320
}
-rule MALPEDIA_Win_Betabot_Auto : FILE
+rule MALPEDIA_Win_Globeimposter_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "66328af7-8459-5b35-88d1-7e63b7ee5eb4"
+ id = "4d7b48e1-c009-5b34-a438-f100a6a58894"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.betabot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.betabot_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.globeimposter"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.globeimposter_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "51b7b8c3c50a8d4a628d1b4c5d49a49007142cba41644cf909b7bfdb76b9cbc5"
+ logic_hash = "608bf851e6cd1f78be1de6e26308954d73fd642b69ffa80c802e22a056e6ef77"
score = 75
quality = 75
tags = "FILE"
@@ -157733,32 +164704,32 @@ rule MALPEDIA_Win_Betabot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d85e4f7ffff 89bde8f7ffff 50 33ff 56 47 56 }
- $sequence_1 = { 8d44244c 50 ff15???????? 8d442448 50 e8???????? 8d442448 }
- $sequence_2 = { 32c0 e9???????? 6a40 5e e8???????? a3???????? }
- $sequence_3 = { 884617 2407 80fa40 7413 80fa80 7404 }
- $sequence_4 = { 85c0 7503 6afd 58 5f 5e 5b }
- $sequence_5 = { c20400 55 8bec 83ec18 53 56 8365f800 }
- $sequence_6 = { a1???????? 85c0 740b 8d4dfc 51 ff7508 ffd0 }
- $sequence_7 = { bbb0040000 85f6 7433 a1???????? 48 50 }
- $sequence_8 = { 8a460a 3cb9 740c 3c33 7408 c70302000000 eb34 }
- $sequence_9 = { 7470 66397508 746a 6a02 59 ff7508 66894de8 }
+ $sequence_0 = { c1e810 8bca c1e908 23c7 23cf }
+ $sequence_1 = { 6a0c 5f eb0d 3d96000000 1bff }
+ $sequence_2 = { 8b4508 8b4e08 89442418 85ff 7452 }
+ $sequence_3 = { 0fd4cd 0f6e6f10 0fd4d5 0f7e4f08 0f73d120 0fd4cf 0f6e6f14 }
+ $sequence_4 = { 6a02 57 57 6800000040 8d85fcefffff }
+ $sequence_5 = { 0fd4cb 0f6e16 0ff4d0 0f6e6604 }
+ $sequence_6 = { 83c0fc 3918 7506 83e804 4f 75f6 }
+ $sequence_7 = { 83c104 f7db 75d7 5f 5b }
+ $sequence_8 = { 8bf0 8b06 8d7604 0119 3919 }
+ $sequence_9 = { 8bc7 f7f6 33d2 0fafc6 2bf8 }
condition:
- 7 of them and filesize <835584
+ 7 of them and filesize <327680
}
-rule MALPEDIA_Win_Cinobi_Auto : FILE
+rule MALPEDIA_Win_Tokyox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "853d9242-221d-59c1-ad19-29eb6c5779a8"
+ id = "6ca744f8-6e83-57d0-b9b1-d948cf62f189"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cinobi"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cinobi_auto.yar#L1-L162"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tokyox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tokyox_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "57c1141de6150455825b72381295eb849d072a659e2915f93f96811cd61f7768"
+ logic_hash = "6c96cc95cf53b382f98148013ad4ad66eb649ce28d4ba112298bfa55f06ac1c7"
score = 75
quality = 75
tags = "FILE"
@@ -157772,37 +164743,32 @@ rule MALPEDIA_Win_Cinobi_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c9 c3 55 8bec 51 e8???????? 58 }
- $sequence_1 = { 8845df 8b45bc 8a400c 8845e0 }
- $sequence_2 = { 0f8554010000 6a04 58 8b4df4 }
- $sequence_3 = { 33c0 66898588faffff 8b85a8faffff 660fbe4008 66898584f5ffff 8b85a8faffff 660fbe4020 }
- $sequence_4 = { e8???????? 59 59 84c0 751e 6810270000 }
- $sequence_5 = { 8a4642 88842456010000 8a4647 88842457010000 8a4646 88842458010000 }
- $sequence_6 = { 8b45f8 8b75f4 83c0f0 50 }
- $sequence_7 = { ff705f 8b45c0 ffb0b7000000 ff75dc }
- $sequence_8 = { 8b45c0 ff705f 8b45c0 ffb09f000000 ff75dc e8???????? 83c40c }
- $sequence_9 = { 2402 88460e b001 5f 5b }
- $sequence_10 = { 6880000000 ff7508 8b45f8 ff5073 ff7508 8b45f8 }
- $sequence_11 = { 8b45bc 8a4053 8845f7 8b45bc 8a400c 8845f8 }
- $sequence_12 = { 57 6800100000 ff75f8 ff75f0 ff9303010000 }
- $sequence_13 = { 885de0 8a5823 884de9 8a4839 885de1 8a581d 884dea }
- $sequence_14 = { 8b85a8faffff 660fbe4003 668945ba 8b85a8faffff 660fbe4013 }
+ $sequence_0 = { 6685c0 75e8 8d8570ffffff 8bf0 }
+ $sequence_1 = { bb0f000000 8975d8 8975e8 51 68ffff0000 50 }
+ $sequence_2 = { ff15???????? 85c0 0f8456010000 837d1000 751b 68c8000000 }
+ $sequence_3 = { 8d4598 8bcb 50 6888130000 8d45dc 50 e8???????? }
+ $sequence_4 = { 8d854cf5ffff 50 68???????? ff15???????? }
+ $sequence_5 = { 0f114590 0f104010 0f1145c0 0f1145a0 }
+ $sequence_6 = { ff730c ffd7 e9???????? 8d8550ffffff 0f57c0 50 0f114310 }
+ $sequence_7 = { 8d85f0faffff c645a000 50 ff75a0 8d4de8 }
+ $sequence_8 = { 8bf8 56 53 57 e8???????? 0f1045d0 }
+ $sequence_9 = { 668903 8d5101 8a01 41 84c0 75f9 ff75f8 }
condition:
- 7 of them and filesize <32768
+ 7 of them and filesize <237568
}
-rule MALPEDIA_Win_Boldmove_Auto : FILE
+rule MALPEDIA_Win_Divergent_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ede55e68-ab48-582c-bf7e-2cb826551211"
+ id = "14cdfb94-4b91-530e-a0fa-873505b81024"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.boldmove"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.boldmove_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.divergent"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.divergent_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "d529b7724e2e647d4848b38aca8e76a61b2caa5c4bf1c77fa8242a3dc71a9c2d"
+ logic_hash = "60d51f83c6b67d5042579114a766b27aab37221121fff155d69e0a695b8fbbca"
score = 75
quality = 75
tags = "FILE"
@@ -157816,34 +164782,34 @@ rule MALPEDIA_Win_Boldmove_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb655e4 d3e2 8b8b24300000 09d0 880431 31c0 }
- $sequence_1 = { 891c24 e8???????? 893424 e8???????? 8b442434 85c0 }
- $sequence_2 = { 0f85cf060000 c744246800000000 8b4c2434 b801000000 85c9 0f4fc1 8984249c000000 }
- $sequence_3 = { 83cd02 89442448 e9???????? 8d4701 83cd08 89442448 }
- $sequence_4 = { e8???????? 89c5 8b442438 892c24 89442404 e8???????? 8b4c2424 }
- $sequence_5 = { 8b442420 89fb 8b10 e9???????? 85f6 7e03 83ee01 }
- $sequence_6 = { 8b8314100000 31d2 39d0 740c 39b49318100000 7418 42 }
- $sequence_7 = { 85db 0f84561d0000 81fe00040000 b800040000 0f4ec6 890424 89442440 }
- $sequence_8 = { 8d4f04 7415 837c242801 0f8473050000 837c242805 7503 0fbec0 }
- $sequence_9 = { 8b8310080000 31d2 39d0 740c 39b49314080000 }
+ $sequence_0 = { 8bc1 880438 40 3d00010000 7cf5 8b450c }
+ $sequence_1 = { 83c418 85db 0f8537ffffff 5f 5e 68???????? ff15???????? }
+ $sequence_2 = { 3b4510 7518 ff7510 8b4704 ff750c }
+ $sequence_3 = { 85c0 750a 830604 5e 5d e9???????? 33c0 }
+ $sequence_4 = { ff15???????? 837e0800 7412 ff7608 ff15???????? ff7608 e8???????? }
+ $sequence_5 = { 3bf1 7421 3bf9 741d 3bc1 7419 c1e204 }
+ $sequence_6 = { 85db 0f84da000000 3975f4 0f84d1000000 53 e8???????? 8945e4 }
+ $sequence_7 = { 5d c3 ff25???????? 55 8bec 837d0800 741f }
+ $sequence_8 = { e8???????? 8bf8 83c414 85ff 742c 8b463c ff743054 }
+ $sequence_9 = { 0fb6f1 0fb6ca 0fb60406 034510 03c8 81e1ff000080 7908 }
condition:
- 7 of them and filesize <242688
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Skipper_Auto : FILE
+rule MALPEDIA_Win_Lazardoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4df8b68e-8938-5eb7-bba0-86905918e37c"
+ id = "2eb37290-3e1c-5665-a83e-f5adb7297910"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.skipper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.skipper_auto.yar#L1-L431"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lazardoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lazardoor_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "dd8f2a613ae1336f9183e3a024858c9c0abef8aafde3712e59fe4ab047db7609"
+ logic_hash = "0bf4197e05236eb2be49432405132a9996b398c538e39f55b3ceea025a90e3ab"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -157855,67 +164821,32 @@ rule MALPEDIA_Win_Skipper_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 6a00 6a03 68???????? 68???????? 6a50 }
- $sequence_1 = { 59 5d c3 55 8bec 33c0 50 }
- $sequence_2 = { e8???????? 6804010000 e8???????? 6804010000 8bf8 }
- $sequence_3 = { ff15???????? 6a00 6a00 6a00 6a00 68???????? 68???????? }
- $sequence_4 = { e8???????? 6a04 e8???????? 8bf8 57 6a04 68???????? }
- $sequence_5 = { 0fb6c3 03c8 81e1ff000080 7908 49 81c900ffffff 41 }
- $sequence_6 = { 8b4d08 0fb68405fcfeffff 320439 47 8847ff 4e 0f8568ffffff }
- $sequence_7 = { 7c0e 0fba25????????01 0f824a0e0000 57 8bf9 83fa04 7231 }
- $sequence_8 = { e8???????? 83c404 6a00 6a64 52 50 }
- $sequence_9 = { 8a85effeffff 888415f0feffff e9???????? c785dcfeffff00000000 }
- $sequence_10 = { 898ddcfeffff 8b95dcfeffff 3b5514 0f8dcf000000 8b45f8 }
- $sequence_11 = { 0fb6d2 8a8415f0feffff 8885eefeffff 8b4d10 038ddcfeffff 0fbe11 }
- $sequence_12 = { c1e81f 03d0 418bc1 8d1492 }
- $sequence_13 = { 0fb602 418800 44880a 410fb610 4103d1 }
- $sequence_14 = { 81e2ff000080 7908 4a 81ca00ffffff 42 0fb6d2 8a8415f0feffff }
- $sequence_15 = { 51 6a0b 68???????? 8b15???????? 52 68???????? e8???????? }
- $sequence_16 = { 0fb645f8 8a8c15f0feffff 888c05f0feffff 0fb655fc 8a85effeffff }
- $sequence_17 = { 33c9 4963e9 498bf8 488d1424 448bd1 8bc1 0f1f840000000000 }
- $sequence_18 = { 4181c800ffffff 41ffc0 410fb6c0 488d1424 41ffc1 4803d0 48ffc3 }
- $sequence_19 = { 81c900ffffff ffc1 4863c1 0fb61404 4403d2 4181e2ff000080 }
- $sequence_20 = { 0fb6c2 49ffc3 0fb61404 4232541fff }
- $sequence_21 = { 48896c2410 4889742418 48897c2420 4156 4881ec10010000 488b05???????? 4833c4 }
- $sequence_22 = { 8b85e0feffff 83c001 8985e0feffff 81bde0feffff00010000 }
- $sequence_23 = { 4232541fff 418853ff 48ffcb 0f8575ffffff }
- $sequence_24 = { 81ec24010000 a1???????? 33c5 8945f4 c745f800000000 }
- $sequence_25 = { 3d02010000 7513 8b4d08 e8???????? 68e8030000 ff15???????? }
- $sequence_26 = { 7528 48833d????????00 741e 488d0de59b0000 e8???????? 85c0 740e }
- $sequence_27 = { 895704 66a1???????? 66894708 8a0d???????? 884f0a e8???????? 0fb6d0 }
- $sequence_28 = { 85d2 740c c785d4feffff3a040000 eb0a c785d4feffffffff1f00 }
- $sequence_29 = { 68???????? 68???????? 8d4d20 0f434d20 68bb010000 51 50 }
- $sequence_30 = { ffb5b0faffff e9???????? 8d8580faffff 50 6a00 ffb590faffff }
- $sequence_31 = { 33c0 e9???????? 8975e4 33c0 39b8b8a62300 0f8491000000 }
- $sequence_32 = { 488bc3 488d15cfa30000 48c1f805 83e11f 488b04c2 486bc958 }
- $sequence_33 = { 48ffc8 90 80780100 488d4001 75f6 }
- $sequence_34 = { ff15???????? 41b900800000 41b804010000 488bd3 488bcf ff15???????? }
- $sequence_35 = { b81a000000 eb23 488d0da39a0000 48890c03 4883c130 }
- $sequence_36 = { 8b0c85606d4100 c1e206 8a441124 3245fe 247f 30441124 8b37 }
- $sequence_37 = { 8b7508 8d34f570a02300 391e 7404 }
- $sequence_38 = { e8???????? 488db328010000 488d7b28 bd06000000 488d051dad0000 483947f0 }
- $sequence_39 = { e8???????? 59 8945e4 8b7508 c7465cd8812300 33ff 47 }
- $sequence_40 = { 8bff 55 8bec 8b4508 ff34c570a02300 }
- $sequence_41 = { 8a80b4a62300 08443b1d 0fb64601 47 3bf8 }
- $sequence_42 = { 488d1d24a50000 8bef 488b33 4885f6 }
- $sequence_43 = { a3???????? a1???????? c705????????66162300 8935???????? a3???????? ff15???????? }
- $sequence_44 = { 488d05a59a0000 740f 3908 740e 4883c010 4883780800 }
+ $sequence_0 = { 488bd1 488bc1 48c1f806 4c8d05f4f60000 }
+ $sequence_1 = { 428a8c3998a50100 482bd0 8b42fc d3e8 443bc8 0f8d09010000 488b4b28 }
+ $sequence_2 = { 4053 4883ec20 488d05575a0100 488bd9 488901 f6c201 740a }
+ $sequence_3 = { 8905???????? 0f1105???????? 8b15???????? 4533c9 488b0d???????? 4533c0 }
+ $sequence_4 = { 4d85c0 7410 488d15615b0200 488bc8 }
+ $sequence_5 = { 44392d???????? 743d 4533c9 4c896c2430 c744242880000000 }
+ $sequence_6 = { 660f6e5cc610 660f62d8 660f6fc7 660f6cda 660ffec4 660f76de }
+ $sequence_7 = { 33d2 e8???????? 3bc3 7565 03fb 8b1d???????? 3bfb }
+ $sequence_8 = { ba5a540000 e9???????? 8b05???????? 85c0 }
+ $sequence_9 = { 4c8bc1 b84d5a0000 66390525b6ffff 7578 48630d58b6ffff 488d1515b6ffff 4803ca }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <405504
}
-rule MALPEDIA_Win_Varenyky_Auto : FILE
+rule MALPEDIA_Win_Regin_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "799963a3-0366-58c7-b923-0a51c9db342a"
+ id = "ce7821ca-cfed-5ada-bd4c-3b99c9cf64f9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.varenyky"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.varenyky_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.regin"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.regin_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "9e07244b9e5d336f26b69f46ff4024108fa6443c2648edcc9fb5aa11d967154b"
+ logic_hash = "985ecd1548d174f4606bb21325679aedf195f3d6056cd99e3d5f01bd16dfaa46"
score = 75
quality = 75
tags = "FILE"
@@ -157929,32 +164860,32 @@ rule MALPEDIA_Win_Varenyky_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b3d???????? 8b542418 6a00 52 8d8424c0130000 50 55 }
- $sequence_1 = { 8d542435 6a00 52 c644243c00 e8???????? }
- $sequence_2 = { 6880000000 8bd6 52 ff15???????? 6803010000 8d842485020000 }
- $sequence_3 = { 83c40c 6a40 898424a4010000 898c249c010000 8a0d???????? 899424a0010000 8d442450 }
- $sequence_4 = { 03f0 0fbe01 3bc3 75f0 }
- $sequence_5 = { 57 e8???????? 83c404 3c32 }
- $sequence_6 = { 8d84244d030000 53 50 c744242404010000 889c2454030000 e8???????? }
- $sequence_7 = { 51 ffd6 68???????? 8d542474 52 ffd7 }
- $sequence_8 = { 56 57 6803010000 8d44243d 53 50 885c2444 }
- $sequence_9 = { 41 03e8 0fbe01 3bc3 75f0 0fbe842440020000 }
+ $sequence_0 = { 49 8363f000 48 8d0504230000 49 8943d8 }
+ $sequence_1 = { 48 89442438 b800210000 c7442430204e0000 89442428 }
+ $sequence_2 = { 85c0 740c 8b05???????? 39442460 7405 }
+ $sequence_3 = { c1e802 41 ffc0 48 8d4c2470 41 }
+ $sequence_4 = { 44 8bc1 48 8b0d???????? ff15???????? }
+ $sequence_5 = { 48 89442448 48 89442450 b82375f1ba }
+ $sequence_6 = { 33c0 48 83c428 c3 48 83ec28 33c9 }
+ $sequence_7 = { 0f45df 8bc3 48 8b5c2448 }
+ $sequence_8 = { 84c0 44 8d7304 0f45f8 8d4302 44 84c0 }
+ $sequence_9 = { 48 8bfb 8bc7 48 8b5c2430 48 }
condition:
- 7 of them and filesize <24846336
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Prometei_Auto : FILE
+rule MALPEDIA_Win_Sslmm_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f30d42cb-2af1-5154-8e15-89c897952439"
+ id = "66fe7984-4fbf-52ff-a40d-1ce2823f2352"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.prometei"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.prometei_auto.yar#L1-L159"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sslmm"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sslmm_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "5377a5e6947b9cd903f94c70f6185011aeea6f018af2aa2974c11199d44376b8"
+ logic_hash = "d75465397d6b8b1866eed0e7ec1b8ff2d24536787a6f5113faf56887d0bb752f"
score = 75
quality = 75
tags = "FILE"
@@ -157968,38 +164899,32 @@ rule MALPEDIA_Win_Prometei_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 011d???????? 03c8 8b5de4 a1???????? }
- $sequence_1 = { 8bf0 83feff 7425 6a00 8d45d8 50 }
- $sequence_2 = { 014364 8b45e4 014368 5b }
- $sequence_3 = { bb8c132400 4a af e8???????? 1401 d000 }
- $sequence_4 = { 014358 8b45f0 01435c 8b45fc }
- $sequence_5 = { 014368 81434400020000 c7434000000000 83534800 }
- $sequence_6 = { 8ac2 0245f0 3001 85d2 }
- $sequence_7 = { 014360 8b45f4 014364 8b45e4 }
- $sequence_8 = { 8b55f0 33c9 8b75fc 8b45f8 85c0 }
- $sequence_9 = { 01c8 93 9e b2e0 e605 78a1 a4 }
- $sequence_10 = { 013d???????? 8b04b5c8054400 0500080000 3bc8 }
- $sequence_11 = { 01435c 8b45fc 014360 8b45f4 }
- $sequence_12 = { 014354 8b45e8 014358 8b45f0 }
- $sequence_13 = { b901000000 89500c 8bc1 f745c000020000 }
- $sequence_14 = { 8b3d???????? b801000000 33c9 53 0fa2 5b }
- $sequence_15 = { 8bc1 2bc7 2bd7 0145fc 81c232240000 8bc1 8955e8 }
+ $sequence_0 = { 89542440 8d4c2418 89442414 89542444 }
+ $sequence_1 = { 8b8c2484000000 8bbc2480000000 8b54247c 51 57 52 8bcb }
+ $sequence_2 = { 8b442438 89742418 89542468 89442460 8b44241c 33f6 8d542428 }
+ $sequence_3 = { e9???????? ff15???????? 50 eb13 5f 5e }
+ $sequence_4 = { 8b868c000000 68???????? 85c0 7413 6800000200 6a00 }
+ $sequence_5 = { 83c40c 899374010000 33ed 8b8374010000 }
+ $sequence_6 = { 83f8ff 0f8477020000 3bc5 0f84fb010000 8b9374010000 55 03d0 }
+ $sequence_7 = { 83c414 3bc3 770a 6a0a }
+ $sequence_8 = { 8db120010000 8b780c 42 897814 8b7808 897810 }
+ $sequence_9 = { 8b7c2424 e9???????? 50 8bcf eb2e }
condition:
- 7 of them and filesize <51014656
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Breakthrough_Loader_Auto : FILE
+rule MALPEDIA_Win_Leash_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c04a79be-d1c6-5097-81f4-9cd0a78c5ca6"
+ id = "cb5c9738-3925-5a03-a07d-f456311bbe1c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.breakthrough_loader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.breakthrough_loader_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.leash"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.leash_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "6b4d6b03c6e2480f390e69c1bdad99aa25aa8d566c5f76108e42a507f3962675"
+ logic_hash = "ba62c5a8d74be4d262e44012cbb9d0d01e64bb5749bfbb2b1403f379db7c0758"
score = 75
quality = 75
tags = "FILE"
@@ -158013,34 +164938,34 @@ rule MALPEDIA_Win_Breakthrough_Loader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7e2a 8b7df8 660f1f840000000000 0fb7444e08 a900300000 740a }
- $sequence_1 = { 5d c3 8b4d14 890e 8b4d24 }
- $sequence_2 = { 8945e8 8945f8 8b4508 56 be???????? c745eca07d4400 57 }
- $sequence_3 = { 8b450c 0fb68401d86a4400 c1e804 5d }
- $sequence_4 = { 85f6 742d 83f910 8d442420 0f43442420 881418 }
- $sequence_5 = { e8???????? 33c0 c744242c07000000 8d8c2490000000 }
- $sequence_6 = { 8bc7 83e03f 6bc830 8b049540354500 f644082801 7421 57 }
- $sequence_7 = { 83e03f 6bc030 59 59 0304bd40354500 5f eb05 }
- $sequence_8 = { 8b0cbd40354500 83c410 8b7de8 89440f20 8bc6 }
- $sequence_9 = { 8b3e 8d0417 3bd0 731d 8d47ff 8906 8b4b20 }
+ $sequence_0 = { e8???????? 83c408 85c0 7511 8b8b08080000 56 e8???????? }
+ $sequence_1 = { 8a45ef 885def 3ac3 7404 c645ef01 }
+ $sequence_2 = { 6a01 6a02 ff15???????? 83f8ff 89831c180000 7519 5f }
+ $sequence_3 = { 33c0 f2ae f7d1 49 51 e8???????? 8be8 }
+ $sequence_4 = { 2bf9 8d93fe030000 8bc1 8bf7 8bfa 52 }
+ $sequence_5 = { 8b5808 33c0 8a442413 33fb 33db }
+ $sequence_6 = { 8bc1 8bf7 8bfa 8d9510ffffff }
+ $sequence_7 = { 85ff c744242800000000 7e58 8bd8 895c2410 }
+ $sequence_8 = { 8bd1 8bf0 c1e902 f3a5 8bca 83c404 83e103 }
+ $sequence_9 = { 894518 8b4514 99 83e203 03c2 8b5518 }
condition:
- 7 of them and filesize <753664
+ 7 of them and filesize <761856
}
-rule MALPEDIA_Win_Flame_Auto : FILE
+rule MALPEDIA_Win_Moker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f06c53ca-bcca-52e9-9b77-6f299afc1e85"
+ id = "18389526-a462-5233-a3a7-297ee29d064f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flame"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flame_auto.yar#L1-L154"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moker_auto.yar#L1-L160"
license_url = "N/A"
- logic_hash = "6d731bccc4a2ab5daf3cc3b64a3620582f6b712bc70665127cfafd95a28c1921"
+ logic_hash = "12a75630b6f84d2ec097d0e96068cb391171b00fda112afc8eea40b8efef358b"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -158052,37 +164977,38 @@ rule MALPEDIA_Win_Flame_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 741a 83f901 7415 e8???????? }
- $sequence_1 = { 8b8ea4000000 48b8abaaaaaaaaaaaaaa 4c8bc5 48f7e1 }
- $sequence_2 = { a3???????? 85c0 0f84c8fcffff 68???????? ff35???????? e8???????? }
- $sequence_3 = { 744c 8b7518 ff75f8 8bce e8???????? 8b06 }
- $sequence_4 = { 8b8ea0000000 48c1ea03 4803cd ff15???????? }
- $sequence_5 = { ffd7 90 eb00 4883c430 5f 5e }
- $sequence_6 = { 8b8ea0000000 4803cd ff15???????? 84c0 }
- $sequence_7 = { 58 5e 5d c3 c701???????? c3 }
- $sequence_8 = { 8b400c 83c006 50 ff15???????? 33db }
- $sequence_9 = { 8365fc00 e9???????? b8???????? e8???????? }
- $sequence_10 = { 7422 663b3b 0f94c0 84c0 }
- $sequence_11 = { ff15???????? 85c0 742e 56 8b35???????? 8d4514 }
- $sequence_12 = { 8b90b0000000 4903d3 eb64 448bc0 }
- $sequence_13 = { 8b8c2490000000 8bc3 4823c8 8b348e eb27 f6c240 0f8539020000 }
- $sequence_14 = { ff15???????? 834dfcff 8d4de0 e8???????? b001 }
+ $sequence_0 = { 0302 8945d4 8b4dd4 83c102 }
+ $sequence_1 = { 0302 8945e8 eb09 8b45e8 }
+ $sequence_2 = { 0302 8945e8 8b4df8 8b55fc }
+ $sequence_3 = { 0302 50 e8???????? 83c404 3b450c 750b 8b4df0 }
+ $sequence_4 = { 0301 8945e0 e8???????? 8b55e8 }
+ $sequence_5 = { 0302 8945dc 8b45dc 83c002 }
+ $sequence_6 = { 6a00 6a04 6a01 68000000c0 }
+ $sequence_7 = { 0100 83c414 85c0 7502 eb0a }
+ $sequence_8 = { 89e5 ff7508 ed 2e5c 034508 }
+ $sequence_9 = { 48 8b7c2428 48 39f7 7413 fc }
+ $sequence_10 = { 49 8b4c2408 ffd0 48 }
+ $sequence_11 = { d16000 d0806200a501 40 00b070e000e0 31e0 00d5 31c0 }
+ $sequence_12 = { 880424 49 89442430 49 89742458 66813e4d5a }
+ $sequence_13 = { 50 51 52 48 }
+ $sequence_14 = { c20800 55 89e5 ff750c ed }
+ $sequence_15 = { 89e5 60 8b7d08 6887000000 ed }
condition:
- 7 of them and filesize <1676288
+ 7 of them and filesize <1761280
}
-rule MALPEDIA_Win_Medusa_Auto : FILE
+rule MALPEDIA_Win_Shujin_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e5ced166-c5f3-50c0-9e84-e449f6bff889"
+ id = "20683034-d09a-5705-9d80-d7edf3a7d88d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.medusa"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.medusa_auto.yar#L1-L167"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shujin"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shujin_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "b88f5d47ff30b39fc78331a46c037d026177b73d253964f40555a9ce1312bb08"
+ logic_hash = "b1da2f105214e6f844dccb186e5a1748a5be3983c376113a3f54dc8e70f99c20"
score = 75
quality = 75
tags = "FILE"
@@ -158096,38 +165022,32 @@ rule MALPEDIA_Win_Medusa_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 680049ff69 004aff 6a00 4b ff6b00 4c ff6c004d }
- $sequence_1 = { 1a03 69c421f3ef6a 2048b3 a5 }
- $sequence_2 = { 52 ff7200 53 ff7300 54 }
- $sequence_3 = { 317f52 56 5c ab 92 6f 0c48 }
- $sequence_4 = { 9e 45 334a54 98 56 39ec 51 }
- $sequence_5 = { 9f c48b2addd977 7612 a5 ba3c533f71 }
- $sequence_6 = { e60e 6c 7bbc 45 }
- $sequence_7 = { 54 ff740055 ff7500 56 }
- $sequence_8 = { 99 5f 68066e570a 4f bfdb4a7adc }
- $sequence_9 = { 1ddf859f31 e476 0c48 ce 74ec 1b826a013061 }
- $sequence_10 = { 2a18 ae 085ffb cf }
- $sequence_11 = { b5f9 43 324dd5 1ddf859f31 e476 0c48 }
- $sequence_12 = { 5f e1fb 1cc9 3ca5 2c8e a1???????? d528 }
- $sequence_13 = { b051 9f 4a d7 b9533e507c }
- $sequence_14 = { 6c 6f aa 97 691c85470859bab566c1a5 }
- $sequence_15 = { 813bf80937dc 8b4c6386 8608 5f }
+ $sequence_0 = { e8???????? ff7660 8b1d???????? 6a01 bf80000000 57 }
+ $sequence_1 = { ff15???????? 85c0 0f8431010000 53 897df4 }
+ $sequence_2 = { 6aff 50 ff15???????? 57 8b7d10 83ff01 }
+ $sequence_3 = { 8bf9 ba???????? 0fb67201 8a0a 8b1f d3e3 0fb60c06 }
+ $sequence_4 = { 83615400 53 56 57 8d7108 c7450805000000 8b46f8 }
+ $sequence_5 = { ff45f8 817df870170000 72c9 e9???????? 807daa01 8b45e8 8d1c06 }
+ $sequence_6 = { 8b5508 0facc21a c1f81a 8bd8 8955e4 }
+ $sequence_7 = { c1ef10 8d8d9cf9ffff 2bf9 03f8 a0???????? a801 7421 }
+ $sequence_8 = { 895008 8b680c 8bd5 896c2410 }
+ $sequence_9 = { 8d1c06 83c40c 8975f8 3bf3 731e }
condition:
- 7 of them and filesize <1720320
+ 7 of them and filesize <172032
}
-rule MALPEDIA_Win_Crosswalk_Auto : FILE
+rule MALPEDIA_Win_Amadey_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4e86aa0a-7e26-5d10-b3ce-967831f39ceb"
+ id = "bcbf3802-d510-5a36-b69a-5e392988dabd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crosswalk"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crosswalk_auto.yar#L1-L164"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.amadey_auto.yar#L1-L208"
license_url = "N/A"
- logic_hash = "c5472d51b6e367a8e5153b183b7c173cc8cbe07eef42b7b5523d361aefdeb08e"
+ logic_hash = "c915860f91ad45f2eb5b15d5deb4fc25f32146851585f24cbb18a6984390dbf0"
score = 75
quality = 75
tags = "FILE"
@@ -158141,38 +165061,42 @@ rule MALPEDIA_Win_Crosswalk_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4885c9 7402 ffd1 b801000000 }
- $sequence_1 = { ff15???????? 448bf0 4533c9 4533c0 }
- $sequence_2 = { 458bc6 33d2 488bc8 e8???????? 4533c9 }
- $sequence_3 = { 458d7ee0 418bd7 ff15???????? 4821742420 }
- $sequence_4 = { 4c8bc6 33d2 410fbe00 49ffc0 }
- $sequence_5 = { 418bc0 f7e9 03d1 c1fa0b 8bc2 c1e81f 03d0 }
- $sequence_6 = { d3ca 03d0 4183ef01 75ef }
- $sequence_7 = { 410fbe00 49ffc0 d3ca 03d0 }
- $sequence_8 = { 8b45fc 817848f0844100 7409 ff7048 e8???????? }
- $sequence_9 = { 6a26 58 0fb60c85c6574100 0fb63485c7574100 8bf9 }
- $sequence_10 = { 7403 ff5508 5d c20400 53 8b1d???????? }
- $sequence_11 = { 735f 8bc6 8bfe 83e03f c1ff06 6bd830 8b04bd808e4100 }
- $sequence_12 = { c1f906 03048d808e4100 eb02 8bc6 80782900 }
- $sequence_13 = { 83e801 0f8501010000 c745e0245b4100 8b4508 8bcf 8b7510 }
- $sequence_14 = { 740e 50 e8???????? 83a6808e410000 59 }
- $sequence_15 = { 83e801 0f8580000000 8b4508 dd00 ebc6 c745e0285b4100 e9???????? }
+ $sequence_0 = { ebb0 b8???????? 83c410 5b }
+ $sequence_1 = { e8???????? 89c2 8b45f4 89d1 ba00000000 f7f1 }
+ $sequence_2 = { c744240805000000 c744240402000000 890424 e8???????? }
+ $sequence_3 = { c9 c3 55 89e5 81ecc8010000 }
+ $sequence_4 = { c70424???????? e8???????? 8b45fc 89442408 c7442404???????? 8b4508 890424 }
+ $sequence_5 = { c744240800020000 8d85f8fdffff 89442404 891424 e8???????? 83ec20 }
+ $sequence_6 = { c70424???????? e8???????? 890424 e8???????? 84c0 7407 c745fc05000000 }
+ $sequence_7 = { 83ec04 8945f4 837df400 7454 8b4508 890424 }
+ $sequence_8 = { 83fa10 722f 8b8d78feffff 42 }
+ $sequence_9 = { 8b8d78feffff 42 8bc1 81fa00100000 7214 8b49fc }
+ $sequence_10 = { 68???????? e8???????? 8d4dcc e8???????? 83c418 }
+ $sequence_11 = { 68???????? e8???????? 8d4db4 e8???????? 83c418 }
+ $sequence_12 = { 52 6a02 6a00 51 ff75f8 ff15???????? ff75f8 }
+ $sequence_13 = { 8bce e8???????? e8???????? 83c418 e8???????? e9???????? 52 }
+ $sequence_14 = { c705????????0c000000 eb31 c705????????0d000000 eb25 83f901 750c }
+ $sequence_15 = { 50 68???????? 83ec18 8bcc 68???????? e8???????? }
+ $sequence_16 = { 8bcc 68???????? e8???????? 8d8d78feffff e8???????? 83c418 }
+ $sequence_17 = { c78584fdffff0f000000 c68570fdffff00 83fa10 722f 8b8d58fdffff 42 }
+ $sequence_18 = { c78520fdffff00000000 c78524fdffff0f000000 c68510fdffff00 83fa10 722f }
+ $sequence_19 = { 51 e8???????? 83c408 8b950cfdffff c78520fdffff00000000 c78524fdffff0f000000 }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <529408
}
-rule MALPEDIA_Win_Lolsnif_Auto : FILE
+rule MALPEDIA_Win_Rook_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1d5fbfc8-0217-55f5-a391-424b7e7d3b81"
+ id = "18a58274-365f-5d90-8056-28a56db76f76"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lolsnif"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lolsnif_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rook"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rook_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "9bce9d984017297751bb54a3f5eaf0b3b4bc516f4f45f71420e0fbe5f0438c0a"
+ logic_hash = "8b05af9f0d6f5102cdf2e062676438cba9dcdb9d6b25adc560d5025ee81a7b52"
score = 75
quality = 75
tags = "FILE"
@@ -158186,32 +165110,32 @@ rule MALPEDIA_Win_Lolsnif_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c745ecebfecccc 8945f8 895dfc e8???????? 85c0 0f84e6000000 c745fc10000000 }
- $sequence_1 = { 8d4510 50 ff35???????? e8???????? 8bf8 85ff 0f8576010000 }
- $sequence_2 = { 8945fc 7460 894508 ff35???????? 8b450c ff7510 e8???????? }
- $sequence_3 = { 6817010000 1bc0 51 23c6 50 e8???????? e9???????? }
- $sequence_4 = { 3bf1 742b 53 8b5f04 }
- $sequence_5 = { 8bf8 85ff 754c 8b45fc }
- $sequence_6 = { 6a20 50 ff15???????? 3bc3 0f84eb000000 68???????? 50 }
- $sequence_7 = { 8b471c 3bc3 7411 50 53 ff35???????? ff15???????? }
- $sequence_8 = { 85c0 0f841b020000 50 ff7320 e8???????? 8bf0 }
- $sequence_9 = { bf02010000 eb08 ff15???????? 8bf8 }
+ $sequence_0 = { 488d05478d0200 c7470801000000 48c7471003000000 48894748 488d05c59e0200 }
+ $sequence_1 = { 0f8521ffffff 44882b eb7b 488b9540070000 4c8d05979e0000 498bce }
+ $sequence_2 = { 85c0 0f85f5020000 488b8d08080000 488d85f8070000 4c89a424c0080000 488d15ffb90400 }
+ $sequence_3 = { ff15???????? 488bd3 488d0d82ac0400 448bc0 e8???????? 488b0d???????? 4c8bc3 }
+ $sequence_4 = { 4433d0 418bc1 48c1e808 0fb6c8 41c1e208 420fb6843170990500 4433d0 }
+ $sequence_5 = { 488d85f8070000 4c89a424c0080000 488d15ffb90400 4889442428 4c8d25d3450500 4c89ac24b8080000 }
+ $sequence_6 = { 488d542460 488d0d1c380500 e8???????? 488d9510020000 498bcc ff15???????? 4839bd10020000 }
+ $sequence_7 = { 48894760 488d0535980200 c7475001000000 48c7475804000000 48894778 488d050b710300 c7476801000000 }
+ $sequence_8 = { 4898 4d8d3446 83ed01 7586 4885f6 0f84d3000000 488bce }
+ $sequence_9 = { 4c8d05f7140300 488986b0000000 488d8e98000000 e8???????? 8bd8 85c0 0f8517ffffff }
condition:
- 7 of them and filesize <425984
+ 7 of them and filesize <843776
}
-rule MALPEDIA_Win_Getmypass_Auto : FILE
+rule MALPEDIA_Win_Lockergoga_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "083431d4-35f0-5afc-be73-c4abda9f956c"
+ id = "1c23217f-5659-545b-a560-32c15b901216"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.getmypass"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.getmypass_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lockergoga"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lockergoga_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "73655fc056c3c045e75de418123d8e1cd087892e700c185d02f9fb25dda3b86c"
+ logic_hash = "0b1cfe6b39387960d8fabaa4bf38642a4ddd7ce3aadb70d3ac9c167b96d0b767"
score = 75
quality = 75
tags = "FILE"
@@ -158225,34 +165149,34 @@ rule MALPEDIA_Win_Getmypass_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c201 8955fc ebcb 837dfc05 7e04 b001 eb02 }
- $sequence_1 = { 0fb64d08 85c9 7418 8b9594fdffff 52 }
- $sequence_2 = { 68???????? 68???????? e8???????? 83c408 8945fc 837dfc00 7463 }
- $sequence_3 = { 6a00 8b45f8 50 ff15???????? e8???????? }
- $sequence_4 = { 8945f4 837df400 742d 8b55f4 0fb702 83f831 750c }
- $sequence_5 = { e8???????? 83c404 a3???????? 8b55f8 52 e8???????? 83c404 }
- $sequence_6 = { 83f835 7409 0fbe4d08 83f934 }
- $sequence_7 = { e8???????? 83c404 8945fc 837dfcff 740e }
- $sequence_8 = { 8b55f8 8b4204 2b450c 8b4df8 0301 50 }
- $sequence_9 = { 83f801 7509 c745e400000000 eb17 8b5508 83c201 }
+ $sequence_0 = { e9???????? 33c0 897dd4 8b560c 33c9 894514 3bc3 }
+ $sequence_1 = { 725e 8b06 8b7e38 8b80e4000000 89459c 3bd7 722c }
+ $sequence_2 = { e8???????? 50 ffb5f0feffff 8d85c0feffff c645fc0c 50 8bcf }
+ $sequence_3 = { ff10 8d4b10 e8???????? 6a38 53 e8???????? 83c408 }
+ $sequence_4 = { e8???????? 8d45d8 c645fc04 50 8bcb e8???????? 8b1b }
+ $sequence_5 = { e8???????? 8d45c0 c645fc01 50 8bce e8???????? 8bf0 }
+ $sequence_6 = { 8b4df0 33cd e8???????? 8be5 5d c3 ff7594 }
+ $sequence_7 = { 8b5904 8b7d0c 8975e8 8975ec 8945f0 c745fc00000000 85ff }
+ $sequence_8 = { f30f7e4710 660fd64610 c7471000000000 c747140f000000 c60700 83c718 c745fcffffffff }
+ $sequence_9 = { e8???????? 8bc8 3bcf 7413 837f1410 8bc7 7202 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <2588672
}
-rule MALPEDIA_Win_Whiteblackcrypt_Auto : FILE
+rule MALPEDIA_Win_Neutrino_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6157b109-2151-5074-8840-c27487c07a25"
+ id = "b9eb1524-9975-578b-ab6d-93138480d1f6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.whiteblackcrypt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.whiteblackcrypt_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.neutrino"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.neutrino_auto.yar#L1-L324"
license_url = "N/A"
- logic_hash = "f60c96c165ea27ee68f018ece2d6f92a309aa90e387cd2c1a16407c43ba45f47"
- score = 75
- quality = 75
+ logic_hash = "b8cd6770a3479380c0f958a2776eccb26f589975e6ef7e101cff7469e248afc4"
+ score = 60
+ quality = 43
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -158264,32 +165188,55 @@ rule MALPEDIA_Win_Whiteblackcrypt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 790d b910270000 ff15???????? ebea e8???????? b805000030 31c9 }
- $sequence_1 = { 75ed 0f118fb0000000 4883c310 ebc4 4883c420 5b 5e }
- $sequence_2 = { 4883ec38 83fa02 744c 7707 83fa01 745a eb4d }
- $sequence_3 = { 75a2 5b 5e c3 4c8d4a10 48c1e104 }
- $sequence_4 = { 488d0d583d0000 c705????????01000000 e8???????? 4885c0 7414 b801000000 }
- $sequence_5 = { 4889c6 4889c7 4489f0 f3aa 4889f1 e8???????? }
- $sequence_6 = { 4881ecb0030000 4c8d0504420000 31c0 41b9ffff0000 }
- $sequence_7 = { 8801 48ffc1 ebe8 c3 55 }
- $sequence_8 = { 7412 8d509f 80fa19 7703 }
- $sequence_9 = { f20f2ad2 48895c2420 dd442420 f20f11542428 dd442428 d9c9 d9fd }
+ $sequence_0 = { ff15???????? c1e010 50 ff15???????? }
+ $sequence_1 = { 50 6a0b 6a07 e8???????? }
+ $sequence_2 = { 50 6a05 6a03 e8???????? }
+ $sequence_3 = { 85c9 7439 8b550c 8955fc 8b45fc 0fbe08 85c9 }
+ $sequence_4 = { 0fbe02 85c0 7447 8b4df4 0fbe11 8b45fc 0fbe08 }
+ $sequence_5 = { 0404 0404 0404 0402 0202 0202 }
+ $sequence_6 = { 8b4d0c 894dfc 8b55f4 83c201 8955f4 ebaf 8b45f4 }
+ $sequence_7 = { 0404 0404 010404 0202 }
+ $sequence_8 = { 020402 0404 0404 0404 0404 0404 0403 }
+ $sequence_9 = { 51 0fb655e7 52 8b45e0 50 e8???????? }
+ $sequence_10 = { 0fbe08 85c9 741b 8b55fc 0fbe02 8b4df8 0fbe11 }
+ $sequence_11 = { 894dfc 8b55fc 0fbe02 85c0 750f 8b4d0c 894dfc }
+ $sequence_12 = { 6a00 ff15???????? 6880000000 ff15???????? }
+ $sequence_13 = { 010404 0202 020402 0404 }
+ $sequence_14 = { e9???????? 6a01 ff15???????? 85c0 }
+ $sequence_15 = { 52 ff15???????? 83f8ff 7504 32c0 eb02 b001 }
+ $sequence_16 = { 894d08 0fb6550c 83fa01 7509 8b4508 83c001 894508 }
+ $sequence_17 = { 7407 814a1800300000 f645fe01 0f8494020000 834a1801 8b45f4 }
+ $sequence_18 = { 6a1c 5b 8d4de0 51 50 895de0 ff15???????? }
+ $sequence_19 = { 8a00 ff45f4 8b7218 8ad8 c0eb06 885dfc }
+ $sequence_20 = { 7354 8b3b 0fb6f2 6a05 58 2bc6 8d1437 }
+ $sequence_21 = { 51 ff35???????? c7460480000000 ff15???????? 8906 }
+ $sequence_22 = { 33d2 81e100f0ffff eb08 3bc1 7409 8bd0 }
+ $sequence_23 = { f645fe02 740a 834a1804 8a03 884210 43 f645fe40 }
+ $sequence_24 = { 83c120 81fae00f0000 76ea 8b0d???????? 8908 a3???????? 5f }
+ $sequence_25 = { 8d85b8feffff 50 68???????? ff15???????? 8945fc }
+ $sequence_26 = { 83c40c 6804010000 8d85f8fdffff 50 }
+ $sequence_27 = { 7507 68???????? eb05 68???????? 50 ff510c }
+ $sequence_28 = { 7522 be???????? ff15???????? 57 8906 ff15???????? 83c604 }
+ $sequence_29 = { 7412 68???????? 50 ff15???????? f7d8 1bc0 }
+ $sequence_30 = { 57 33ff 393d???????? 7522 be???????? }
+ $sequence_31 = { ff15???????? 50 ff15???????? 837dfc00 0f95c0 c9 }
+ $sequence_32 = { ff750c ff7508 ff15???????? 83f8ff 0f95c0 }
condition:
- 7 of them and filesize <99328
+ 7 of them and filesize <507904
}
-rule MALPEDIA_Win_Dnschanger_Auto : FILE
+rule MALPEDIA_Win_Odinaff_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ae807a62-5d4f-55b1-a240-1c49a1caed44"
+ id = "c28375cd-e1a8-5dbb-b117-119bc2a2a6cd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dnschanger"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dnschanger_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.odinaff"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.odinaff_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "6d81d999d3cf2fb8d24f1a3cbe10fc2c3244404cd2fbc45cfa8a36930b442d5e"
+ logic_hash = "de88658965024bda0c5434053043d1a37aa258e92b5fc7491f70abd6c372a45d"
score = 75
quality = 75
tags = "FILE"
@@ -158303,32 +165250,32 @@ rule MALPEDIA_Win_Dnschanger_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8bf0 8b442414 6800010000 }
- $sequence_1 = { b301 57 ff15???????? 85f6 740c 56 6a00 }
- $sequence_2 = { 8bc2 03c7 eb02 8bc7 5f }
- $sequence_3 = { be04000000 5f 8bc6 5e 81c494000000 }
- $sequence_4 = { ff7508 66ab aa ff15???????? }
- $sequence_5 = { 8b542408 53 8a1a 8819 41 42 84db }
- $sequence_6 = { 3b0e 72f2 57 57 57 }
- $sequence_7 = { 57 57 56 57 ff75fc ff15???????? }
- $sequence_8 = { 5e 81c494000000 c3 83f806 }
- $sequence_9 = { f3aa 8bc6 5f 5e c3 }
+ $sequence_0 = { ff15???????? 3d1f040000 7505 bf01000000 }
+ $sequence_1 = { 740c 57 6a00 ffd3 50 ff15???????? 6a00 }
+ $sequence_2 = { 6a08 33ff 57 57 ff15???????? }
+ $sequence_3 = { 8bd8 ff15???????? 53 6a00 6a00 56 ff15???????? }
+ $sequence_4 = { 49 81c900ffffff 41 8a8138474000 }
+ $sequence_5 = { 8b1d???????? 83c40c 6820bf0200 56 ffd3 b900000800 2bc8 }
+ $sequence_6 = { c745dc01000000 e8???????? 6a44 8d4580 53 50 e8???????? }
+ $sequence_7 = { 7508 ff15???????? eb7b 6a04 }
+ $sequence_8 = { e8???????? 8b45f8 83c410 85c0 7408 50 6a00 }
+ $sequence_9 = { 8b4d0c 6a00 6880000000 6a02 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Btcware_Auto : FILE
+rule MALPEDIA_Win_Buterat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "66d799b0-12ae-5de4-8213-c0d10e51387d"
+ id = "3e97b50a-971b-5a6b-945e-3e34fedb231a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.btcware"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.btcware_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.buterat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.buterat_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "150a811146243acd5ee4c0630508ee4be9bafcd2cf3745d9f46eb9848c5a7f93"
+ logic_hash = "eb64ab06f54c3ecee14053c6efd01e298ad3b6ab4366443760576f0899003a4d"
score = 75
quality = 75
tags = "FILE"
@@ -158342,32 +165289,32 @@ rule MALPEDIA_Win_Btcware_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 ff15???????? 8b4524 83f810 7242 8b4d10 }
- $sequence_1 = { c7404818c14100 8b4508 6689486c 8b4508 66898872010000 8d4dff 8b4508 }
- $sequence_2 = { 33c5 8945fc 8b450c 56 8b7508 680a010000 }
- $sequence_3 = { 33c0 85ff 7e18 0fb78c4490020000 663bce 7406 66894c5440 }
- $sequence_4 = { 50 8d44241c 50 ff74241c ff15???????? 85c0 7446 }
- $sequence_5 = { 33db 895610 c746140f000000 8975d4 8955e4 }
- $sequence_6 = { 8d85f8efffff 50 ffd7 85c0 0f84ac000000 8d85f4efffff }
- $sequence_7 = { 85c0 0f84ac000000 8d85f4efffff 50 }
- $sequence_8 = { 6800010000 8d85fcfcffff 50 68???????? ff15???????? 8b35???????? }
- $sequence_9 = { 8d85e0efffff 50 6a00 6800800000 ffb5f0efffff 8d85fcefffff 50 }
+ $sequence_0 = { 56 8d4dfc 51 57 50 53 }
+ $sequence_1 = { 750a 56 6a07 e8???????? 59 59 ff750c }
+ $sequence_2 = { ff15???????? 8b5d75 53 33c0 e8???????? 85c0 59 }
+ $sequence_3 = { 56 57 33f6 e8???????? 85c0 59 0f868b000000 }
+ $sequence_4 = { 750b e8???????? 99 f77dfc 8bda 837d6806 }
+ $sequence_5 = { 8d8564dfffff 50 8bc3 e8???????? 83c40c ff75f4 ffd7 }
+ $sequence_6 = { 8bec b800100000 e8???????? 8b4d08 }
+ $sequence_7 = { e8???????? 83c40c 85c0 0f8424010000 68???????? 53 68???????? }
+ $sequence_8 = { 41 41 47 3b7d0c 72cd 5b 33c0 }
+ $sequence_9 = { 33db 385d1c 56 57 895df0 750d 8a4518 }
condition:
- 7 of them and filesize <458752
+ 7 of them and filesize <278528
}
-rule MALPEDIA_Win_Starcruft_Auto : FILE
+rule MALPEDIA_Win_Darkcloud_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1dcafb43-c4d2-514a-8438-617d875e41e7"
+ id = "b0268fec-89c8-5323-9f85-c9d45089af7c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.starcruft"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.starcruft_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkcloud"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkcloud_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "ba9170fb6918e14feeea6fab09146b237b88c2d2d12a4f68164b770922d2ddd1"
+ logic_hash = "500bafad0751f0834ef38cd2423929e4bf071aa68fdd5512e97c403f17f02fd3"
score = 75
quality = 75
tags = "FILE"
@@ -158381,32 +165328,71 @@ rule MALPEDIA_Win_Starcruft_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83bd34fbffff00 7458 0fb64d34 85c9 7419 8b95b4fcffff 899558fbffff }
- $sequence_1 = { ebbd c7852cfeffff01000000 83bd2cfeffff00 7565 8b4508 898524feffff c78520feffff00000000 }
- $sequence_2 = { 884def 8b55f0 83c202 8955f0 8b45f0 8945f8 eb09 }
- $sequence_3 = { 8b55f8 8b85ccfeffff 8b0c90 0fb711 85d2 740b 8b45f8 }
- $sequence_4 = { 55 8bec 81ec20010000 a1???????? 33c5 8945e4 8b4508 }
- $sequence_5 = { c685cafcffff26 c685cbfcffffa1 c685ccfcffff8b c685cdfcffff52 c685cefcffff6c c685cffcffffba c685d0fcffffde }
- $sequence_6 = { 8b4dd4 8908 8b5510 8b02 50 8d4dd8 51 }
- $sequence_7 = { 8b4dcc 51 e8???????? 83c404 8945f0 8955f4 8b55d0 }
- $sequence_8 = { e8???????? 83c404 33c0 e9???????? 8b45fc }
- $sequence_9 = { e8???????? e8???????? c705????????04c02e00 c705????????08c02e00 c705????????0cc12e00 c705????????10c12e00 }
+ $sequence_0 = { 83c414 8d4db0 ff15???????? c745fc23000000 8b4d08 894da8 }
+ $sequence_1 = { 894598 894db0 8945a8 894dc0 8945b8 ff15???????? 50 }
+ $sequence_2 = { 6a00 51 8bf0 ff15???????? 50 56 6a00 }
+ $sequence_3 = { 8d8d68ffffff 51 ff15???????? c745fc06000000 ba???????? 8d4dcc ff15???????? }
+ $sequence_4 = { 8d855cffffff 8d8df8feffff 50 8d954cffffff 51 52 c7851cffffff08000000 }
+ $sequence_5 = { 668b55dc 663b954cffffff 0f8ff4000000 c745fc0c000000 8d45dc 894584 c7857cffffff02400000 }
+ $sequence_6 = { ff15???????? 8bd0 8d8df0feffff ff15???????? 50 8b559c 52 }
+ $sequence_7 = { 668b00 8975dc 662d0100 8975cc 0f80e4000000 8975ac 894584 }
+ $sequence_8 = { 50 8d4d94 51 e8???????? 8bd0 8d4d84 ff15???????? }
+ $sequence_9 = { ff15???????? 8bd0 8d4da8 ff15???????? 8d5588 52 8d458c }
+
+ condition:
+ 7 of them and filesize <622592
+}
+rule MALPEDIA_Win_Spider_Rat_Auto : FILE
+{
+ meta:
+ description = "autogenerated rule brought to you by yara-signator"
+ author = "Felix Bilstein - yara-signator at cocacoding dot com"
+ id = "8b8fb932-c9c0-5d1a-a1ff-94b4f85b8abe"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spider_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spider_rat_auto.yar#L1-L132"
+ license_url = "N/A"
+ logic_hash = "86dc62debebef6e9c395034c4368c0804fc586029188907fa2c1533f611f9771"
+ score = 75
+ quality = 75
+ tags = "FILE"
+ version = "1"
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { e9???????? 4883c708 488b1f 488bd3 488d8c2490000000 e8???????? }
+ $sequence_1 = { 418bc3 4c8d5c2460 498b5b18 498b7328 498be3 5f c3 }
+ $sequence_2 = { 488b6c2438 488b742440 8958f0 488b07 4863cb 488b5c2430 c6040100 }
+ $sequence_3 = { e8???????? 488b4d70 4883c160 ff15???????? 90 488d05b726fbff eb00 }
+ $sequence_4 = { 84c0 7471 4885f6 7505 83fd01 7415 488b8f88000000 }
+ $sequence_5 = { 7458 6683fa01 7452 ff15???????? 4c8bc6 8bd5 0fb7cb }
+ $sequence_6 = { 7410 488b8f88000000 e8???????? 85c0 7802 33db 8bc3 }
+ $sequence_7 = { 498bd8 488bf2 488bf9 4d85c0 7430 4885d2 742b }
+ $sequence_8 = { ff15???????? 488bc8 e8???????? 488d15d3b00300 488bce 488905???????? ff15???????? }
+ $sequence_9 = { ba03000000 488d442440 448d4a61 448d42fe 4889442420 e8???????? }
condition:
- 7 of them and filesize <294912
+ 7 of them and filesize <1107968
}
-rule MALPEDIA_Win_Cova_Auto : FILE
+rule MALPEDIA_Win_Zitmo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0c88fb7f-6fc3-555b-938b-30689bfedd71"
+ id = "f6f59970-f923-5e51-84d0-3f8e29574b3c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cova"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cova_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zitmo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zitmo_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "5acada90a087ad54806fe6fafb57fbcd69c3ce6e348c87bed79cabfe21474d32"
+ logic_hash = "a3b8b6f5916a461447d9c48219b755dccd1a5d708dba30f1dbbe42f800df788f"
score = 75
quality = 75
tags = "FILE"
@@ -158420,32 +165406,32 @@ rule MALPEDIA_Win_Cova_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b430c 8905???????? 8bd7 4c8d0558bbffff }
- $sequence_1 = { eb7c 4c8d258e800000 488b0d???????? eb6c }
- $sequence_2 = { 4881c354020000 83fe06 7298 488d8d70040000 baf80d0000 }
- $sequence_3 = { 3d80000000 751d 4c8be6 448bfe 4839742450 7419 ff5500 }
- $sequence_4 = { 4863ca 0fb7444b10 664189844898c90000 ffc2 }
- $sequence_5 = { 488b0d???????? e9???????? 4c8d25a6800000 488b0d???????? }
- $sequence_6 = { eb06 8d4257 418800 ffc2 49ffc0 83fa10 }
- $sequence_7 = { e8???????? 482be0 488b05???????? 4833c4 48898510170000 488dbde0000000 }
- $sequence_8 = { ff15???????? 488d1574260000 488bce 488905???????? ff15???????? }
- $sequence_9 = { 41bc14030000 4c8d0520320000 488bcd 418bd4 }
+ $sequence_0 = { 03d7 8bde f7de ffb544feffff 53 e8???????? c9 }
+ $sequence_1 = { 55 8bec 81c47cffffff 317588 f7d7 f7df }
+ $sequence_2 = { 23d0 f7d9 8bd6 23d8 }
+ $sequence_3 = { c20400 55 8bec 81c410ffffff }
+ $sequence_4 = { 55 8bec 81c45cffffff 23cb 8bd6 f7d2 }
+ $sequence_5 = { 314dd8 f7d9 48 f7d2 03c1 ffb504ffffff }
+ $sequence_6 = { 4a f7d9 23c6 8bcb 46 }
+ $sequence_7 = { 4f e8???????? 8bca 03f7 e8???????? 23d7 }
+ $sequence_8 = { 81856cffffff36360000 03df f7d1 8bf8 }
+ $sequence_9 = { 6a36 6a36 51 ffb550feffff 6834340000 57 8d4d88 }
condition:
- 7 of them and filesize <123904
+ 7 of them and filesize <843776
}
-rule MALPEDIA_Win_Cobalt_Strike_Auto : FILE
+rule MALPEDIA_Win_Concealment_Troy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fe16365e-18f7-5cb3-91e7-4778fbcc5b82"
+ id = "e9475a7d-b707-5e2f-9e3a-86f91b19814e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cobalt_strike"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cobalt_strike_auto.yar#L1-L157"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.concealment_troy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.concealment_troy_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "e575d34f1fe7007aa1601e291288f1136cef68df0b3f455e03eabc3d825e94fe"
+ logic_hash = "b699251c533e7fec5531f5ef6172ec9300c9329b32d1137bef102f716d43b763"
score = 75
quality = 75
tags = "FILE"
@@ -158459,38 +165445,32 @@ rule MALPEDIA_Win_Cobalt_Strike_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3bc7 750d ff15???????? 3d33270000 }
- $sequence_1 = { e9???????? eb0a b801000000 e9???????? }
- $sequence_2 = { eb06 0fb6c0 83e07f 85c0 745a }
- $sequence_3 = { eb68 8b45d4 8b482c 894de0 8b45e0 }
- $sequence_4 = { ff35???????? ffd6 5e e9???????? 55 }
- $sequence_5 = { eb4e 83f824 7f09 c745f403000000 }
- $sequence_6 = { ff761c 83c004 e8???????? 59 59 83f8ff }
- $sequence_7 = { f3a6 744c 8bf0 6a03 bf???????? 59 }
- $sequence_8 = { 85c0 741d ff15???????? 85c0 7513 }
- $sequence_9 = { e9???????? 833d????????01 7505 e8???????? }
- $sequence_10 = { 8bd0 e8???????? 85c0 7e0e }
- $sequence_11 = { 85c0 7405 e8???????? 8b0d???????? 85c9 }
- $sequence_12 = { f3c3 cc 488bc4 48895808 48896810 48897018 }
- $sequence_13 = { c1e903 ffc1 03c1 3d80000000 }
- $sequence_14 = { 49ffc7 413bcc 72e9 41894d00 }
- $sequence_15 = { 48895c2448 48895c2440 4889442438 498b06 }
+ $sequence_0 = { 6a00 6a04 6a00 6aff ff15???????? e8???????? 50 }
+ $sequence_1 = { 56 57 b900000000 8b7508 0fb68600010000 0fb69e01010000 33d2 }
+ $sequence_2 = { 894d80 c7458410000000 33c0 88440590 40 3d00010000 }
+ $sequence_3 = { 50 8d8c2438050000 51 e8???????? 8d942434030000 }
+ $sequence_4 = { 75f6 80bc242001000022 0f854e040000 6808020000 8d942434090000 }
+ $sequence_5 = { 51 e8???????? 8bf0 83c408 85f6 7523 }
+ $sequence_6 = { e8???????? 8d8c243c030000 68???????? 51 e8???????? }
+ $sequence_7 = { 50 ffd5 bb???????? 8bf8 e8???????? 8b35???????? 50 }
+ $sequence_8 = { 55 8bec 83e4f8 b834130000 e8???????? a1???????? 33c4 }
+ $sequence_9 = { 8b1495a0774100 c1e006 8d440224 802080 884dfd 8065fd48 884dff }
condition:
- 7 of them and filesize <1015808
+ 7 of them and filesize <229376
}
-rule MALPEDIA_Win_Opachki_Auto : FILE
+rule MALPEDIA_Win_Lockfile_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "19945598-3be8-57e4-97f5-8518d611bbed"
+ id = "544691b3-5a18-5d07-a020-f938e5dff9ba"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.opachki"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.opachki_auto.yar#L1-L168"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lockfile"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lockfile_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "5313082ce77d197fd4bac8aec4c18a74cf4695d26acd8d2a84b13e24f5666e1a"
+ logic_hash = "dc414bc646e8b114a7dca14d5155afbe9c4203cc45e95fbd463e125e3eb42e08"
score = 75
quality = 75
tags = "FILE"
@@ -158504,38 +165484,32 @@ rule MALPEDIA_Win_Opachki_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c3 55 8bec 81ec00010000 ff7508 }
- $sequence_1 = { 83c40c 8b4f04 8d0433 894708 c6040800 }
- $sequence_2 = { 83c8ff 5f 5b 5e c9 c20800 8bc3 }
- $sequence_3 = { 741c 8d4dd4 51 8d4df4 51 8d4dec }
- $sequence_4 = { 885dfc e8???????? ff75e8 8d45f4 }
- $sequence_5 = { ff7510 ff75fc ff15???????? 85c0 75e2 }
- $sequence_6 = { 8b4608 8b4e04 c6040800 5f 8bc6 5e }
- $sequence_7 = { 8bd8 7413 8b4704 03c8 53 }
- $sequence_8 = { 8a0f 894508 84c9 744d 8a10 53 56 }
- $sequence_9 = { c0e805 88470a 3c01 ac 7710 80fff6 7503 }
- $sequence_10 = { aa 8944241c 61 c3 898389838983 898389838983 }
- $sequence_11 = { f6c140 7412 08d2 7408 }
- $sequence_12 = { 884707 83c140 eb0a 3ca0 7206 3ca3 }
- $sequence_13 = { 7404 3c65 7505 884703 ebcc }
- $sequence_14 = { f3aa 83ef25 8b742424 ac }
- $sequence_15 = { 898389838983 898389838585 858585858585 878593859a9a }
+ $sequence_0 = { 418bdc 33d9 8bcb 4123cf 4133cc 03d1 8955bb }
+ $sequence_1 = { 488b4b58 49894a48 488b5360 49895250 48837b6010 7731 41c6424101 }
+ $sequence_2 = { 488bf1 33d2 e8???????? 33d2 48895618 48895620 }
+ $sequence_3 = { e9???????? 4c8d4c245c 4c8d4570 488d15b31e0600 488d8d70020000 e8???????? 488d8d70020000 }
+ $sequence_4 = { 85c0 7411 836530fe 488b4d38 4883c178 e8???????? }
+ $sequence_5 = { 57 4883ec20 8bfa 488bd9 488b4908 4885c9 740b }
+ $sequence_6 = { 0f845c010000 83792801 0f8552010000 e8???????? 8bd8 483bde 480f42de }
+ $sequence_7 = { 0f84a5000000 488b0d???????? 488b15???????? 4c3bc1 750d 488bc1 48d1e8 }
+ $sequence_8 = { 41c1c802 4123cb 418bd1 0bc8 c1c205 03cd 418bc0 }
+ $sequence_9 = { 88458c 8b4580 0409 3465 88458d 8b4580 040a }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <1163264
}
-rule MALPEDIA_Win_Taidoor_Auto : FILE
+rule MALPEDIA_Win_Turian_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ede5ce97-d13f-50cf-a7ae-7678b51deb4c"
+ id = "ddf0a4a2-a5a9-518b-8b9f-2682f3c9390d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.taidoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.taidoor_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.turian"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.turian_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "9a08978fbb3ba0f91c4ac24abe796c18c68bd8ea90cbb67ac44eb5676631b436"
+ logic_hash = "9c66c121bddd393e74452e6591ffaf152302a762e1679695f5fb6277ed317972"
score = 75
quality = 75
tags = "FILE"
@@ -158549,32 +165523,32 @@ rule MALPEDIA_Win_Taidoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7cf5 c745fcfcffffff 33ff 33db }
- $sequence_1 = { f775fc 8bf2 8d04f6 ffb485f4b7ffff ff15???????? 85c0 }
- $sequence_2 = { 59 8d85a0fdffff 59 50 e8???????? }
- $sequence_3 = { 57 a0???????? c745fc01000000 8ac8 f6d9 1bc9 33db }
- $sequence_4 = { 66ab aa 895dfc ffd6 40 85c0 7e29 }
- $sequence_5 = { b940420f00 f7f9 8d45e0 52 ff35???????? ff35???????? }
- $sequence_6 = { ff75f0 ffd6 8d4d08 885dfc e8???????? 834dfcff 8d4d10 }
- $sequence_7 = { ff75ec 8d4df0 e8???????? 8b450c 46 3b70f8 7cdc }
- $sequence_8 = { e8???????? ff75ec 8d85a0fdffff 50 51 8bcc 8965f4 }
- $sequence_9 = { bf80020000 57 c745fc01000000 ffd3 8bf0 }
+ $sequence_0 = { 50 ff15???????? 89450c 8bf8 33c0 }
+ $sequence_1 = { e8???????? 83c404 85c0 740d 8d4c2410 51 }
+ $sequence_2 = { ffd7 8b3d???????? 53 ffd7 56 ffd7 83c408 }
+ $sequence_3 = { 81ec88000000 53 55 56 57 b921000000 33c0 }
+ $sequence_4 = { 85c0 750a 5f 5e 5d 81c49c000000 c3 }
+ $sequence_5 = { 729b 53 ff15???????? 83c404 a1???????? 85c0 750f }
+ $sequence_6 = { 72ba 68???????? ff15???????? 5f 5e 5d 83c8ff }
+ $sequence_7 = { 66a3???????? 5b c3 6a3f 50 }
+ $sequence_8 = { 7403 c60000 68???????? 56 ffd7 85c0 }
+ $sequence_9 = { ffd5 85c0 750e 8d4f46 8d5642 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <645120
}
-rule MALPEDIA_Win_Victorygate_Auto : FILE
+rule MALPEDIA_Win_Cuegoe_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "992c5b2e-f41c-5577-b26b-d319a12e38e1"
+ id = "eccb0436-f9ed-5e03-8d27-4464cf8de9a1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.victorygate"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.victorygate_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cuegoe"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cuegoe_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "ea38784ac607c199e10f70edff21cb5ba2438f5fbaa9d25c8260862ff3bec34e"
+ logic_hash = "9bdbb34dedb6d213b915fa268b74e0986ed09811af8e7637c05b65b2310f3a18"
score = 75
quality = 75
tags = "FILE"
@@ -158588,32 +165562,32 @@ rule MALPEDIA_Win_Victorygate_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7214 8b49fc 83c223 2bc1 83c0fc 83f81f 0f879a120000 }
- $sequence_1 = { 8bce c645fc08 e8???????? c645fc01 8b55e8 83fa10 7228 }
- $sequence_2 = { 8bf8 893b 897b04 03cf 33c0 894b08 eb03 }
- $sequence_3 = { ff15???????? 85c0 0f8593010000 ff75f8 8d8678020000 6a57 50 }
- $sequence_4 = { e9???????? 3b0d???????? 7501 c3 e9???????? 55 8bec }
- $sequence_5 = { 0f8537050000 ff75f8 8d8630020000 6a32 50 }
- $sequence_6 = { 85c0 7537 b901000000 f00fb10f 85c0 7533 817e340c2b0000 }
- $sequence_7 = { 8b4128 8b7124 8945b8 3bf0 7436 660f1f440000 8b06 }
- $sequence_8 = { 57 8b00 8945c4 663908 0f8548060000 8b703c 03f0 }
- $sequence_9 = { c745fc19000000 83ec18 8b4de0 8bc4 896584 c70000000000 c7401000000000 }
+ $sequence_0 = { 397d68 7409 ff7568 e8???????? 59 6a57 5e }
+ $sequence_1 = { 50 895de4 e8???????? 837d2808 8b4514 }
+ $sequence_2 = { 0f8390feffff 8b0488 0fb6c8 894538 c16d3808 894d3c }
+ $sequence_3 = { 6a00 50 e8???????? 83c40c 33c0 89442410 e9???????? }
+ $sequence_4 = { 6a0a 8d45e8 8975e4 e8???????? 8d5dd0 e8???????? }
+ $sequence_5 = { 50 e8???????? 8d4570 50 ff750c 8d85d0030000 56 }
+ $sequence_6 = { 69c0a0860100 8a563c c7460c01000000 885608 89442410 3bd8 0f8387050000 }
+ $sequence_7 = { 8b0488 0fb6c8 894538 c16d3808 894d3c 899d40040000 8b15???????? }
+ $sequence_8 = { 8d858c000000 50 8d8574ffffff 6a4c 50 e8???????? 59 }
+ $sequence_9 = { 0f94c1 888c286c0d0000 03c7 89442410 837c241010 0f8c7affffff }
condition:
- 7 of them and filesize <1209344
+ 7 of them and filesize <540672
}
-rule MALPEDIA_Win_Former_First_Rat_Auto : FILE
+rule MALPEDIA_Win_Purplewave_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e13a8bc3-e4cb-54c7-a2c1-b71b74a37c2c"
+ id = "bc61a32f-ee96-5e25-892f-9d381408f659"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.former_first_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.former_first_rat_auto.yar#L1-L167"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.purplewave"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.purplewave_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "79676675a5e0c5d1eb84217b80928525157e507544e18d7d0452685a540a1268"
+ logic_hash = "5efe0dc0002836bd228e34e2c06d2e0edc1c85c62aac77610517f67f8f987125"
score = 75
quality = 75
tags = "FILE"
@@ -158627,38 +165601,32 @@ rule MALPEDIA_Win_Former_First_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 899424ec030000 898c24e8030000 8b4f10 8d9424e8030000 6a00 52 898424f8030000 }
- $sequence_1 = { 894c240c 8bd3 3bc1 7420 8d642400 8bf0 }
- $sequence_2 = { 52 bb1c000000 8d742428 894c245c c744246000000000 }
- $sequence_3 = { e8???????? 8b8d0cffffff 68???????? 51 e8???????? }
- $sequence_4 = { ff15???????? 33c0 66833d????????09 0f94c0 a3???????? 6808020000 }
- $sequence_5 = { c785e8feffff0f000000 899decfeffff 899df0feffff 899d04ffffff 899df4feffff }
- $sequence_6 = { e8???????? 8d8de0feffff 51 bb08000000 e8???????? 8b9df8feffff 57 }
- $sequence_7 = { 8bf2 8bfb 81c208020000 b982000000 81c308020000 f3a5 3bd0 }
- $sequence_8 = { 48897c2428 488d05169b0200 488907 488d4f08 e8???????? }
- $sequence_9 = { 480f42db 4883792010 7206 488b4908 eb04 }
- $sequence_10 = { 48837e2008 7209 488b4e08 e8???????? 488d4608 }
- $sequence_11 = { 48895c2468 0f28442450 660f7f442450 0f284c2460 660f7f4c2460 }
- $sequence_12 = { 48896c2460 40886c2450 488bcb e8???????? }
- $sequence_13 = { 488d4754 48894760 48832100 488b4748 48832000 }
- $sequence_14 = { 90 48017e20 488b7620 4881c670ffffff }
- $sequence_15 = { 488b7968 488d0532800200 8bf2 488bd9 }
+ $sequence_0 = { e8???????? 8d4da4 c645fc12 e8???????? 84db 0f84ca020000 6a40 }
+ $sequence_1 = { 0f8415000000 81a53cffffffffbfffff 8d8da8feffff e9???????? c3 8d8d60feffff e9???????? }
+ $sequence_2 = { 8d8c2468010000 e8???????? 6a0d e8???????? 59 56 8bd0 }
+ $sequence_3 = { 6bc838 57 8b0495201e4900 8a440828 a848 757b 84c0 }
+ $sequence_4 = { 8d4dbc e8???????? 8d4dd4 e8???????? 8bc3 e8???????? c20c00 }
+ $sequence_5 = { b8???????? e8???????? 8bf9 8db78c000000 8bce e8???????? 84c0 }
+ $sequence_6 = { 53 50 e8???????? 83c40c 8d8db8feffff e8???????? 8d95b8feffff }
+ $sequence_7 = { 53 68???????? 50 ff5110 ff758c ffd6 50 }
+ $sequence_8 = { 0f85d3000000 8d45e8 50 8b06 8b08 83c128 }
+ $sequence_9 = { 84c0 750e 8d45d8 50 8d4e6c e8???????? eb49 }
condition:
- 7 of them and filesize <626688
+ 7 of them and filesize <1400832
}
-rule MALPEDIA_Win_Lilith_Auto : FILE
+rule MALPEDIA_Win_Crypt0L0Cker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7c9f283d-efd5-5ce1-a88d-5c399c9e9911"
+ id = "3ca18c92-db73-54b4-928d-eb72333dfc4b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lilith"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lilith_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crypt0l0cker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crypt0l0cker_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "9246de5695a5f1adcfda29165a048565982f491bffcb4e11939fadd1e6d8bd64"
+ logic_hash = "3ce866cbdb58e590ea553be6664221b117cb83d9a5d4d70643f018e4fb580d20"
score = 75
quality = 75
tags = "FILE"
@@ -158672,32 +165640,32 @@ rule MALPEDIA_Win_Lilith_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ff15???????? 6857040000 898698210000 ff15???????? }
- $sequence_1 = { e8???????? 8bce e8???????? 83c418 8bcf e8???????? 8d4dd0 }
- $sequence_2 = { 8b0c85a84b4300 8b45e8 f644012880 7446 0fbec3 83e800 742e }
- $sequence_3 = { 25f0070000 660f28a010e94200 660f28b800e54200 660f54f0 660f5cc6 660f59f4 660f5cf2 }
- $sequence_4 = { 8b0485a84b4300 80640828fe ff33 e8???????? 59 e9???????? 8b0b }
- $sequence_5 = { c60000 833d????????10 b8???????? c745cc01000000 0f4305???????? }
- $sequence_6 = { e9???????? c745dc03000000 c745e0c8874200 e9???????? }
- $sequence_7 = { c1fa06 8934b8 8bc7 83e03f 6bc830 8b0495a84b4300 8b440818 }
- $sequence_8 = { 8b4d08 898814434300 68???????? e8???????? 8be5 }
- $sequence_9 = { 660f122c8510a74200 03c0 660f28348520ab4200 ba7f3e0400 e9???????? 8bd0 }
+ $sequence_0 = { 85c0 0f8486000000 53 8d58ff c1eb02 56 }
+ $sequence_1 = { 8b4640 85c0 0f8479000000 83780c00 7473 6800010000 e8???????? }
+ $sequence_2 = { 85f6 0f8ead000000 8d4108 8d04b8 894508 8b4510 83c008 }
+ $sequence_3 = { 55 56 8d44240f 8bea 50 6a01 ff35???????? }
+ $sequence_4 = { 83c40c 33c0 6689043b 897e08 85ff 0f84d6000000 }
+ $sequence_5 = { 8b4c243c 8b442430 8911 894104 eb17 8bcf e8???????? }
+ $sequence_6 = { b9???????? 3d90010000 0f4cce 8bf1 8b7f04 85f6 74c9 }
+ $sequence_7 = { 8bce e8???????? 8bf8 83c408 85ff 7438 83c705 }
+ $sequence_8 = { 68???????? 6a05 6840b6b9a6 6a1c e8???????? 83c424 }
+ $sequence_9 = { 0f8581020000 807dee81 0f8577020000 ff75ef ff15???????? 8b0f 8bd3 }
condition:
- 7 of them and filesize <499712
+ 7 of them and filesize <917504
}
-rule MALPEDIA_Win_Acidbox_Auto : FILE
+rule MALPEDIA_Win_Glasses_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d24270e3-4ecb-5df0-834e-54ac9b4880c3"
+ id = "c6da4c93-ee41-5868-bb14-5b5963376366"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acidbox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.acidbox_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.glasses"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.glasses_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "7566f8c225df846294fd9c5a92e8c14928b074fdcd922768eae6047a40a5ef6e"
+ logic_hash = "6195d6cdd9cb4570720f28f4358090026d5f6751f78a62fc950fb9d18ef5a646"
score = 75
quality = 75
tags = "FILE"
@@ -158711,32 +165679,32 @@ rule MALPEDIA_Win_Acidbox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 418bb590000000 4903f4 4889742438 413b8594000000 0f8311010000 397e0c 0f8408010000 }
- $sequence_1 = { 4154 4155 4156 4157 4883ec28 4c8b7128 448b6108 }
- $sequence_2 = { c780d8feffffd3731048 c780dcfeffffffff00ff c780e0feffffffe0cccc c780e4feffffffff0000 4d8920 4d8921 }
- $sequence_3 = { 0fb6ca 4103c9 4403f0 0fb74562 41d3e0 418bc9 49ffc7 }
- $sequence_4 = { ff15???????? 8d043e 898318170000 eb2f 8d8702010000 }
- $sequence_5 = { 4883c438 c3 488bc4 48895810 48897018 57 4154 }
- $sequence_6 = { eb09 4584c0 7908 418b4124 89442420 85c0 }
- $sequence_7 = { 4c8b4de0 c70705000000 f7471000040000 0f840c010000 8b5f48 413bdd 410f47dd }
- $sequence_8 = { 7d07 8bd7 413bc7 7d03 418bd1 8b4b28 488b4310 }
- $sequence_9 = { 0fb79f02040000 418b8a14170000 418bc3 2bc3 }
+ $sequence_0 = { e8???????? 8bf0 83c40c 3bf3 0f85e8fdffff 8d4590 50 }
+ $sequence_1 = { e8???????? 8d852cfbffff 50 6a00 6a50 68???????? 8d8de4faffff }
+ $sequence_2 = { e8???????? 83bdd8fdffff00 0f849e000000 8bcb e8???????? 85c0 740d }
+ $sequence_3 = { e9???????? 8d8d38f9ffff e9???????? 8d8dfcf8ffff e9???????? 8d8dacf8ffff e9???????? }
+ $sequence_4 = { 8bf1 8975f0 c706???????? 8d8e84000000 c745fc01000000 c7460800000000 e8???????? }
+ $sequence_5 = { e8???????? 83b94814000002 0f8d54ffffff ff894c140000 8b814c140000 8b91580b0000 899481540b0000 }
+ $sequence_6 = { ff0d???????? 53 8bcf e8???????? c645ff00 5f 5e }
+ $sequence_7 = { ffd2 84c0 0f840b010000 8d4da4 e8???????? 8bf8 8b45cc }
+ $sequence_8 = { eb10 8bce e8???????? 8b5d18 8945e8 895dec 8b7510 }
+ $sequence_9 = { e8???????? 899e7c070000 e9???????? 83f801 7524 6a02 e8???????? }
condition:
- 7 of them and filesize <589824
+ 7 of them and filesize <4177920
}
-rule MALPEDIA_Win_Balkan_Door_Auto : FILE
+rule MALPEDIA_Win_Disk_Knight_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9f746f91-5631-5121-b4e8-99ba1997828d"
+ id = "9beebfb6-ef57-52bd-934c-31d9b91ab2bc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.balkan_door"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.balkan_door_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.disk_knight"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.disk_knight_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "3ecc62d6dd03e7104a1dd179870266fc7dbfc3c0ad204dec134adb374e60ab02"
+ logic_hash = "e89ae24c28bc10924a7fb7bbea0ccafb184ecff432361cc9f981384efa6a4077"
score = 75
quality = 75
tags = "FILE"
@@ -158750,34 +165718,34 @@ rule MALPEDIA_Win_Balkan_Door_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ff15???????? 8bf8 89bd3cefffff }
- $sequence_1 = { 8bf0 85f6 740b 6a00 6a00 56 ff15???????? }
- $sequence_2 = { ffd7 85c0 741a 8d85d0fdffff c785d0fdffff2c020000 50 56 }
- $sequence_3 = { 8d85f4fdffff 50 ffd7 85c0 741a 8d85d0fdffff c785d0fdffff2c020000 }
- $sequence_4 = { c785d0fdffff2c020000 50 56 ffd3 }
- $sequence_5 = { 56 ff15???????? 8b4dfc 8b85ccfdffff 33cd 5e e8???????? }
- $sequence_6 = { e8???????? 83c404 8bbd3cefffff 6a00 }
- $sequence_7 = { 8b85d8fdffff 8985ccfdffff 5f 5b 56 }
- $sequence_8 = { 683f000f00 68???????? 57 ff15???????? }
- $sequence_9 = { 50 57 6a00 6a13 ffb53cefffff ff15???????? 85c0 }
+ $sequence_0 = { 897d8c 897d88 ff15???????? 8b1d???????? 8d4dc4 51 }
+ $sequence_1 = { c745f0e01b4000 33c0 8945f4 8945f8 8845e0 6a01 ff15???????? }
+ $sequence_2 = { ff15???????? f7d8 1bc0 23f0 8d45b0 50 8d4dc0 }
+ $sequence_3 = { 8d8d7cffffff 51 56 ff5220 dbe2 85c0 7d0f }
+ $sequence_4 = { 8b4710 8d5594 52 50 8b08 ff9138010000 85c0 }
+ $sequence_5 = { 895004 8b8d48ffffff 894808 8b954cffffff 89500c 8b85e0feffff 8b08 }
+ $sequence_6 = { 3bc8 7d7d 8d9574ffffff 52 6a01 56 e8???????? }
+ $sequence_7 = { ff15???????? 8b3d???????? 83c40c 85f6 0f84d1010000 a1???????? 85c0 }
+ $sequence_8 = { e8???????? 8bf0 ff15???????? 8d54240c 8d8424a0000000 52 50 }
+ $sequence_9 = { 8b45d0 0f80ea060000 69db00010000 99 0f80dd060000 2bc2 899d10ffffff }
condition:
- 7 of them and filesize <352256
+ 7 of them and filesize <868352
}
-rule MALPEDIA_Win_Lobshot_Auto : FILE
+rule MALPEDIA_Win_Maze_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5bc103fe-8569-5650-9cd3-425031e0ab5f"
+ id = "107fc7f0-df43-5a49-b2af-87c958bef91f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lobshot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lobshot_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maze"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maze_auto.yar#L1-L201"
license_url = "N/A"
- logic_hash = "b29ec78bd5106a9ad51352916c3857459a77fea2349f02317d142c1882771dfc"
+ logic_hash = "114687adcaa31dee32acfd0d8a276547892002fc6701cc69c1544ebdb3b57221"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -158789,32 +165757,41 @@ rule MALPEDIA_Win_Lobshot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 895c2414 85f6 7410 6a02 56 ff15???????? 56 }
- $sequence_1 = { 8b4508 8bd1 85c0 7409 c60200 42 }
- $sequence_2 = { 728d ff742418 ff15???????? 8b74241c 43 83fb04 0f8e42ffffff }
- $sequence_3 = { 85d2 7905 895e18 8bd3 57 6a2a }
- $sequence_4 = { 0f8485000000 8b461c 85c0 747e 8b7804 83ff2a 740d }
- $sequence_5 = { 0f42c8 33ff 894d08 47 8b4e6c 3bcf 771f }
- $sequence_6 = { 8b55f8 33ff 85d2 7839 8b5dfc 0fb774bb02 85f6 }
- $sequence_7 = { 8b4e08 8a86b1160000 88040a ff4614 0fb786b4160000 8386b4160000f3 }
- $sequence_8 = { 53 ff15???????? 8b0d???????? 8b15???????? 2b15???????? 8d4102 83e902 }
- $sequence_9 = { 895004 8b8348140000 99 2bc2 8bf0 d1fe }
+ $sequence_0 = { 53 57 56 83ec10 8b4510 8b4d0c }
+ $sequence_1 = { 8945f0 c745f000000000 8b45f0 83c410 5e 5f }
+ $sequence_2 = { 60 8b7d08 8b4d10 8b450c f3aa 61 8945f0 }
+ $sequence_3 = { 83ec10 8b4510 8b4d0c 8b5508 837d0800 8945ec }
+ $sequence_4 = { 8945ec 894de8 8955e4 7509 c745f000000000 eb17 60 }
+ $sequence_5 = { 89c8 0500000001 83d200 89d7 }
+ $sequence_6 = { 89c7 e8???????? 83c40c 57 55 8dbc24f4000000 }
+ $sequence_7 = { 89c8 01d6 ba53c6f0ff f7e2 }
+ $sequence_8 = { 41 41 41 41 41 41 41 }
+ $sequence_9 = { 83ec20 56 be???????? 56 6a00 6801001200 }
+ $sequence_10 = { 8d45ec 56 8945f8 6a00 8d45f4 50 c745f40c000000 }
+ $sequence_11 = { b904000000 6bd109 8b4d08 8b941100100000 c1ea0a }
+ $sequence_12 = { b948040000 b8cccccccc f3ab a1???????? 33c5 8945ec 50 }
+ $sequence_13 = { 898d6cfeffff 8b4dfc 8b5508 8b848a10080000 }
+ $sequence_14 = { 8b8c1040100000 c1e10a ba04000000 c1e200 8b4508 8b941040100000 c1ea16 }
+ $sequence_15 = { 899594fdffff 8b8d9cfdffff 338d98fdffff 038d94fdffff 8b55fc }
+ $sequence_16 = { 8b54813c c1e209 8b45fc 8b4d08 8b44813c }
+ $sequence_17 = { 8985e4feffff 8b45fc 8b4d08 8b548134 }
+ $sequence_18 = { 8b4dfc 8b5508 8b848a1c080000 c1e017 8b4dfc 8b5508 8b8c8a1c080000 }
condition:
- 7 of them and filesize <247808
+ 7 of them and filesize <2318336
}
-rule MALPEDIA_Win_Yoddos_Auto : FILE
+rule MALPEDIA_Win_Murkytop_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "731c8af4-0cfb-5784-8919-5690671f4ddf"
+ id = "98a068e3-7271-5cdb-a55e-1253046c8910"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yoddos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yoddos_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.murkytop"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.murkytop_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "ffa9bd7fe378e38b72240a0efe08e70cc8c93f69e8ec293489b47b5a90d316d8"
+ logic_hash = "c9438f0871f1117619cdcbc50e1d21cb20b4d3848dd8784e1c0798685d05cf91"
score = 75
quality = 75
tags = "FILE"
@@ -158828,32 +165805,32 @@ rule MALPEDIA_Win_Yoddos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 85c0 0f84e0010000 8d8584fcffff 56 50 }
- $sequence_1 = { 66895dd8 66895dda 6a0e e8???????? 59 8a8485a4ecffff 8845dc }
- $sequence_2 = { 740c ffb5c0fcffff ff15???????? b863000000 90 b89dffffff }
- $sequence_3 = { c6458e65 c6458f6e c6459055 c6459172 c645926c c6459341 }
- $sequence_4 = { b89dffffff 90 33db 891d???????? b863000000 90 b89dffffff }
- $sequence_5 = { 0c01 c1f905 83e61f 88450b 8d3c8d00764100 c1e603 }
- $sequence_6 = { 895dfc c78538ffffff62000000 68???????? 50 e8???????? ff7508 8d8524feffff }
- $sequence_7 = { 57 ff7508 e8???????? 8bf8 56 037d08 }
- $sequence_8 = { 0fb7750c 6683f97e 7502 33c9 0fb7d1 8a945504ffffff 3010 }
- $sequence_9 = { eb28 8d4df0 6a10 51 }
+ $sequence_0 = { 7c17 b8555555d5 f7e9 c1fa02 8bc2 c1e81f 03c2 }
+ $sequence_1 = { 56 e8???????? 83c410 8b9d1befffff 8d9c1defeeffff 33f6 8bff }
+ $sequence_2 = { 83e01f c1f905 8b0c8de0f54100 c1e006 0fbe440104 83e040 }
+ $sequence_3 = { 8d4508 50 6a00 57 6a00 6800130000 ff15???????? }
+ $sequence_4 = { 56 ffd7 50 ff15???????? 85c0 0f850b010000 }
+ $sequence_5 = { 8b1d???????? 56 57 8bf8 8d45f8 }
+ $sequence_6 = { 8b3d???????? 8bc7 85ff 7e16 8d0cfd48f54100 8b11 }
+ $sequence_7 = { c1fa02 8955d4 3bdf 754e }
+ $sequence_8 = { 897de4 c745e014000000 897dec 894dd8 8945dc }
+ $sequence_9 = { c1e106 030c9de0f54100 eb02 8bca f641247f 7526 83f8ff }
condition:
- 7 of them and filesize <557056
+ 7 of them and filesize <294912
}
-rule MALPEDIA_Win_Http_Troy_Auto : FILE
+rule MALPEDIA_Win_Kazuar_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e1b34482-29c1-5d78-b5ec-9dc58faf8306"
+ id = "bbccb83c-4401-524c-a829-9e1fecf876f5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.http_troy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.http_troy_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kazuar"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kazuar_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "772a93ccc4b452bdc4c7e0291c378f7eec15f191b5f119cfc79098a0f26a733e"
+ logic_hash = "8a42fd36e815cd90ae38c5e050f60bebec4410e7ad562404ae7ac137541dd601"
score = 75
quality = 75
tags = "FILE"
@@ -158867,32 +165844,32 @@ rule MALPEDIA_Win_Http_Troy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { dd45f8 dae9 59 59 dfe0 f6c444 7a05 }
- $sequence_1 = { c3 8b8384400000 85c0 0f84bd010000 8b54240c 52 8b542414 }
- $sequence_2 = { ff00 85d2 744e 8d45ec 50 53 8bcf }
- $sequence_3 = { 8b4c2420 b801000000 89410c 8b4c2418 5f 5e e8???????? }
- $sequence_4 = { 56 57 e8???????? 59 59 eb7d dd4508 }
- $sequence_5 = { 83c604 3b742408 72ef 5e c3 56 8bf0 }
- $sequence_6 = { 6a01 68???????? ffd3 85c0 0f857afeffff 393cb5c8540310 742e }
- $sequence_7 = { 50 8d4c240c 51 6a00 683f000f00 6a00 }
- $sequence_8 = { e8???????? 8b0d???????? 83c408 3bc1 741f 83c702 }
- $sequence_9 = { e8???????? 83c41c 8d942418010000 52 ffd3 85c0 7430 }
+ $sequence_0 = { e8???????? 3d88ae6393 7506 498b4310 eb0f }
+ $sequence_1 = { e8???????? 4c8d4c2428 31d2 31c9 01c0 4c89442438 6689442430 }
+ $sequence_2 = { 8d8b80030000 894c240c 8d8b00030000 894c2408 8d4b08 894c2404 }
+ $sequence_3 = { 740a 81ea00204000 01d0 eb02 31c0 5d c3 }
+ $sequence_4 = { 7452 83b98c00000000 7449 4c01de }
+ $sequence_5 = { 8b45dc 8b10 890424 ff520c 85c0 52 }
+ $sequence_6 = { 8b461c 498d1493 8b0402 4c01d8 }
+ $sequence_7 = { 8bb188000000 85f6 7452 83b98c00000000 7449 4c01de 31db }
+ $sequence_8 = { 89d7 7463 4863493c 4c01d9 8bb188000000 85f6 7452 }
+ $sequence_9 = { 890424 894c2410 8d8b80030000 894c240c 8d8b00030000 }
condition:
- 7 of them and filesize <475136
+ 7 of them and filesize <81920
}
-rule MALPEDIA_Win_Vskimmer_Auto : FILE
+rule MALPEDIA_Win_Nemty_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fc191c93-ce90-5418-a28d-2b3fa9eb623e"
+ id = "63cde4fd-76ae-5ec0-8a56-1ffc39628f31"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vskimmer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vskimmer_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nemty"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nemty_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "81aef2465b53cd0c0e1b48561687f8c8208fd8d87041be709dd2217d8a17703f"
+ logic_hash = "ab3eef0d79392145b4ed1a1315366f250ca5ff150cf5d778f7e9e8528f09f4dc"
score = 75
quality = 75
tags = "FILE"
@@ -158906,32 +165883,32 @@ rule MALPEDIA_Win_Vskimmer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3bc3 7402 8bf0 8bd6 f7da 8a07 }
- $sequence_1 = { 68???????? 50 e8???????? 59 59 85c0 0f8445010000 }
- $sequence_2 = { 33c0 0fbe84c188e54100 6a07 c1f804 59 }
- $sequence_3 = { 75f8 ff36 e8???????? 59 8b4508 }
- $sequence_4 = { 8b4508 8bf1 8b4d0c 8b7e04 }
- $sequence_5 = { 5e 5b c3 8b94c110010000 8bb110020000 8b44c108 2bc6 }
- $sequence_6 = { 3bd7 749c 8b8324020000 2580000000 0f95c0 0fb6c0 50 }
- $sequence_7 = { 7e7b 8b460c ff36 03c7 50 }
- $sequence_8 = { 7413 c685b3fdffff01 3bf3 7408 8b451c 8906 }
- $sequence_9 = { 83e803 0f846a010000 48 7439 48 742d 8b4508 }
+ $sequence_0 = { 51 e8???????? 59 e8???????? 83c438 85c0 }
+ $sequence_1 = { 8945a4 a1???????? 59 bf???????? 8bca 83f810 7302 }
+ $sequence_2 = { 81ec18040000 a1???????? 33c5 8945fc 837d2010 8b4508 }
+ $sequence_3 = { 83781408 8b4810 57 7202 8b00 8b3d???????? 33db }
+ $sequence_4 = { 6a1c 99 5e f7fe 33db 895dd8 }
+ $sequence_5 = { 33ff e8???????? 83c61c 3b7510 75ef 6a00 }
+ $sequence_6 = { 83ec1c 8bd8 8bc4 68???????? e8???????? }
+ $sequence_7 = { 8db4248c000000 e8???????? 53 8d742454 }
+ $sequence_8 = { 7509 be???????? 85c0 7405 }
+ $sequence_9 = { 837d3810 8bf8 8b4524 59 7303 8d4524 837d3810 }
condition:
- 7 of them and filesize <376832
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Cloud_Duke_Auto : FILE
+rule MALPEDIA_Win_Lowball_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cde391f0-175a-570d-9bc3-d49da6ef8745"
+ id = "5424f572-46b4-58bc-b4a0-f5f116f9edc3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cloud_duke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cloud_duke_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lowball"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lowball_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "74b144312fec28eba9f5a0427613a86e81c08ef3fe8c6af23e7d4ebef780ba1f"
+ logic_hash = "40672e1fab5ab37bc1a93541afc7340032670ae9b7325b888c89c49deec74a07"
score = 75
quality = 75
tags = "FILE"
@@ -158945,32 +165922,32 @@ rule MALPEDIA_Win_Cloud_Duke_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4c2448 e8???????? 50 8d8c240c010000 e8???????? 8d4c2448 e8???????? }
- $sequence_1 = { 8d8c240c010000 e8???????? 8d4c2460 e8???????? }
- $sequence_2 = { 83fe04 7ce3 8b45e8 4b 8ad4 }
- $sequence_3 = { 8d8c24d8000000 e8???????? 51 8d442434 }
- $sequence_4 = { 50 e8???????? 8b7c2440 46 3bf7 }
- $sequence_5 = { eb0a 8b9dd8fbffff eb02 8bde 8b85e8fbffff 8d95e4fbffff 52 }
- $sequence_6 = { 85c9 7438 83fa01 7533 83bedc00000008 8d86c8000000 7202 }
- $sequence_7 = { 8d04450c000000 50 6a00 57 }
- $sequence_8 = { eb02 8bce 8b5518 ff75fc 03d2 895510 }
- $sequence_9 = { 6806020000 50 668984241c010000 8d84241e010000 50 c744245c00000000 e8???????? }
+ $sequence_0 = { 0f8436010000 8b942430060000 33c9 85d2 740c 8bfa }
+ $sequence_1 = { ff54242c 5f 5e 5d 33c0 }
+ $sequence_2 = { 8d4f01 51 e8???????? 56 8bd8 ff15???????? }
+ $sequence_3 = { 68???????? f3a4 6a00 ff54242c 6810270000 ff15???????? bf???????? }
+ $sequence_4 = { 85ff 897c240c 0f848c000000 8b942420020000 55 }
+ $sequence_5 = { c1e902 f3a5 8bcb 8d84244c0d0000 83e103 50 }
+ $sequence_6 = { 83c410 85c0 752d 68b80b0000 ffd3 8d8c24400a0000 8d94241c010000 }
+ $sequence_7 = { 8bc1 8bf7 8bfa 8d942434070000 c1e902 f3a5 8bc8 }
+ $sequence_8 = { ff15???????? 83c404 89442410 b905000000 be???????? }
+ $sequence_9 = { 6a00 6a00 68bb010000 51 56 }
condition:
- 7 of them and filesize <368640
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Rincux_Auto : FILE
+rule MALPEDIA_Win_Dented_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f27efa3f-a583-5935-b25f-3d309003cd7f"
+ id = "484f6875-8da3-59df-9796-ec6e3c5f3480"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rincux"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rincux_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dented"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dented_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "bab1d2c8fa3084a76a95e14132fec6ddc959ff0aa0d14a5e81e01f5b29b7ad34"
+ logic_hash = "e9882555c27a882adee62a69216aa411600cf976159b592ea9f38f19d9990be3"
score = 75
quality = 75
tags = "FILE"
@@ -158984,32 +165961,32 @@ rule MALPEDIA_Win_Rincux_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 742d b9fa000000 33c0 8dbc24c0000000 8d9424c0000000 f3ab 8d8c24b0000000 }
- $sequence_1 = { 8bcd 52 57 e8???????? 8b442410 8d4c2424 6a04 }
- $sequence_2 = { 7425 8b442410 8d4c2424 88442424 }
- $sequence_3 = { c68424fd00000076 888c24fe000000 888424ff000000 c68424000100005c c684240101000052 c684240201000044 c684240301000050 }
- $sequence_4 = { c20800 33c0 8a4701 894614 8b4df4 64890d00000000 }
- $sequence_5 = { ff15???????? 83f8ff 7511 8b16 52 ff15???????? 5f }
- $sequence_6 = { 5e 83c42c c20400 8b542438 8d4c2408 51 52 }
- $sequence_7 = { 84c0 74d8 5f 5e 5d 5b }
- $sequence_8 = { 53 57 8b7c242c 6683f90e 7502 }
- $sequence_9 = { 50 68???????? e9???????? 40 c745fc00000000 50 e8???????? }
+ $sequence_0 = { 8bf1 e8???????? 83c40c 89bd60ffffff 8d8560ffffff 50 ff15???????? }
+ $sequence_1 = { 50 51 ebc7 6a0f 33db 5f 897df4 }
+ $sequence_2 = { ffd6 ff75fc ffd6 6a00 6a01 8d4d08 e8???????? }
+ $sequence_3 = { ff15???????? 3d0e000780 7422 3d08000c80 741b }
+ $sequence_4 = { 8985c4fcffff 8d85f4fdffff 6a40 8985c8fcffff 8d85b4fcffff 5e 50 }
+ $sequence_5 = { 8d4dc0 e8???????? 385dc4 7508 6a04 }
+ $sequence_6 = { 6a40 5f 57 8d45b8 }
+ $sequence_7 = { 8b85f8f7ffff 8a8485fcfbffff 32c1 880416 8b8decf7ffff }
+ $sequence_8 = { 48 0d00ffffff 40 8a0a 8985f8f7ffff 8bbdf8f7ffff 0fb6c1 }
+ $sequence_9 = { 8b4a38 3b08 6a0f 0f4208 33db 8b4210 }
condition:
- 7 of them and filesize <392192
+ 7 of them and filesize <450560
}
-rule MALPEDIA_Win_C0D0So0_Auto : FILE
+rule MALPEDIA_Win_Gamotrol_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7fd27b52-4a26-50f0-a471-2ac29e8cd05c"
+ id = "a4423f00-4d12-5905-ae9f-2ac00b302637"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.c0d0so0"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.c0d0so0_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gamotrol"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gamotrol_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "80f1d1736e25190b04ddf50f3339fde0073091aa1984fb16860f6c3d691cdb86"
+ logic_hash = "dbb5086714c8814bb752b80e0051cf0358b1814ba2516480704e9248f4a5718d"
score = 75
quality = 75
tags = "FILE"
@@ -159023,32 +166000,32 @@ rule MALPEDIA_Win_C0D0So0_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 895dfc 8975f4 ff15???????? ff75f8 }
- $sequence_1 = { 7404 0006 eb02 2806 0fb6c0 03d0 03f0 }
- $sequence_2 = { 807e0d00 c6460801 7469 8b460e 8b1d???????? 8365f800 83c012 }
- $sequence_3 = { 53 8b5f04 c745f401000000 0f86f4000000 56 8bb080000000 6a14 }
- $sequence_4 = { 83c204 83f914 7ceb 8bc7 8b4dfc 33cd }
- $sequence_5 = { 752c 6a01 56 e8???????? 59 59 }
- $sequence_6 = { 50 33ff ff15???????? 8d4598 50 ff15???????? }
- $sequence_7 = { ff7334 ffd6 8945fc 85c0 }
- $sequence_8 = { 3acb 75f6 8bc7 5f 5e }
- $sequence_9 = { 33ff 53 47 e8???????? 59 eb0b 56 }
+ $sequence_0 = { 5e c3 6a04 b8???????? e8???????? e8???????? 50 }
+ $sequence_1 = { ff15???????? 8b4b54 6a04 6800100000 51 56 }
+ $sequence_2 = { 90 8bec 85f6 41 49 6843700000 83c40a }
+ $sequence_3 = { 6aff 68???????? 68???????? 6a00 ff15???????? 6a00 53 }
+ $sequence_4 = { 8be5 90 5d 6803010000 }
+ $sequence_5 = { 8d9540fbffff 52 68???????? ffd6 33c0 8945ad 8945b1 }
+ $sequence_6 = { c6854fffffff61 c68550ffffff67 889d51ffffff c68552ffffff56 c68553ffffff69 889d54ffffff }
+ $sequence_7 = { 0fbec2 0fb680a0ed2e00 83e00f 8b4db8 6bc009 0fb68408c0ed2e00 6a08 }
+ $sequence_8 = { 8b01 57 ff5004 5f 5e c3 8b442404 }
+ $sequence_9 = { 49 41 49 90 8be5 90 }
condition:
- 7 of them and filesize <450560
+ 7 of them and filesize <376832
}
-rule MALPEDIA_Win_Bundestrojaner_Auto : FILE
+rule MALPEDIA_Win_Neteagle_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f8dcad82-5285-5492-8b50-3aca915a7d86"
+ id = "1db1653f-5505-5d3a-ba38-0bc41fb6ed7f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bundestrojaner"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bundestrojaner_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.neteagle"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.neteagle_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "14c57bb4c31bed67bf98bb86f0286f3377181b876957cd1f8d67f51314c230ea"
+ logic_hash = "6f0c75693d906262c5895d882d984643cdff0e946d0c3df9bf0f7a28d5c9d704"
score = 75
quality = 75
tags = "FILE"
@@ -159062,32 +166039,32 @@ rule MALPEDIA_Win_Bundestrojaner_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 894c2414 33ff 85c0 897c2410 741f 47 d1f8 }
- $sequence_1 = { 3bc8 7cc3 8b5608 8b4e70 d9442460 42 897e04 }
- $sequence_2 = { 50 8d55fc 51 52 e8???????? 8b87c0000000 b980000000 }
- $sequence_3 = { 56 8b742438 57 8b7c242c 8bc7 c744241000000000 }
- $sequence_4 = { 8b4e34 8d1482 52 50 8b460c 50 51 }
- $sequence_5 = { 83c420 8b5104 85d2 0f95c2 83f806 885114 }
- $sequence_6 = { d9c9 d959fc 3b5610 7cdb ddd8 8b4610 8b5c2418 }
- $sequence_7 = { 75fb 83fe0b 7e15 8b442414 50 8b08 c7411406000000 }
- $sequence_8 = { 8d54241c 89442420 8b44240c 6a00 52 6a00 }
- $sequence_9 = { dd1c24 e8???????? 83c408 e8???????? 85c0 8944241c 7d04 }
+ $sequence_0 = { 8d4c2418 e8???????? 8d4c2418 e8???????? 8b84241c300000 89742410 3bc6 }
+ $sequence_1 = { 83c408 50 51 8d442428 }
+ $sequence_2 = { c68424240200000d 8bcc 8964242c 68???????? e8???????? }
+ $sequence_3 = { 6a00 6a00 57 56 6840800000 ff15???????? }
+ $sequence_4 = { c684241802000018 8bcc 89642424 8d542428 52 e8???????? 8d442420 }
+ $sequence_5 = { 8d4dec e8???????? 6800100000 8d4dec c645fc0d e8???????? 8b16 }
+ $sequence_6 = { 8d4c2428 c68424540c000006 e8???????? 8d542414 68???????? 8d442414 52 }
+ $sequence_7 = { c684241002000004 e8???????? 8d4e34 c684241002000005 e8???????? 8d4e38 c684241002000006 }
+ $sequence_8 = { 52 6a00 6a00 8b3d???????? ffd7 83f820 7f1b }
+ $sequence_9 = { 888c0414010000 40 3bc6 7ced 8d942414010000 8d4c240c 52 }
condition:
- 7 of them and filesize <729088
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Stuxnet_Auto : FILE
+rule MALPEDIA_Win_Metastealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e84f453f-688f-5279-9168-a0cb915408b7"
+ id = "cdc28210-4a73-5ebc-92c2-e9cca60e6ba0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stuxnet"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stuxnet_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.metastealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.metastealer_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "9f5d56947917572e8a9b84c0e49b11ae5a34a590900f3243fcc05249be23cf0d"
+ logic_hash = "6d21821c6e275cca2327e10c362ceb42915cf515b000f17d28567b39e609820e"
score = 75
quality = 75
tags = "FILE"
@@ -159101,32 +166078,32 @@ rule MALPEDIA_Win_Stuxnet_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8b5dec 8b45f0 895df4 8945f8 ff770c 8d75ec }
- $sequence_1 = { c20400 b8???????? e8???????? 51 6a08 e8???????? 59 }
- $sequence_2 = { e8???????? 33db 895dfc 53 8d45d8 50 6802000080 }
- $sequence_3 = { 6aff 68???????? 64a100000000 50 64892500000000 83ec64 8d442420 }
- $sequence_4 = { eb02 33f6 c645fc00 8b4f1c 3bf1 740a 85c9 }
- $sequence_5 = { 837df008 8b45dc 7303 8d45dc 50 8d431c e8???????? }
- $sequence_6 = { c706???????? e8???????? c645fc01 c6462400 834dfcff 8b4df4 8bc6 }
- $sequence_7 = { a5 50 a5 ff5130 85c0 7cb0 8b9b48080000 }
- $sequence_8 = { ff750c ff7510 8d45e4 50 e8???????? c645fc01 8d4def }
- $sequence_9 = { ff7508 8d4df4 e8???????? 837d14ff 7d04 33c0 eb12 }
+ $sequence_0 = { ff7710 50 e8???????? 8b4718 8d4b1c 894318 8d471c }
+ $sequence_1 = { 8b4220 894620 8d4228 894224 897a20 c70700000000 8bc6 }
+ $sequence_2 = { 8d4dd8 e8???????? c745fc00000000 8d45d8 68a3000000 68???????? 68???????? }
+ $sequence_3 = { 8b4104 894610 8b4104 8b400c 85c0 740c 89460c }
+ $sequence_4 = { eb0a c70600000000 c6460401 8a45ae 8b7d9c 8845af 660f1f440000 }
+ $sequence_5 = { eb0e 0f57c0 660f1345d4 8b7dd8 8b75d4 51 8d4dd4 }
+ $sequence_6 = { ff7314 68???????? 56 e8???????? 68???????? 56 e8???????? }
+ $sequence_7 = { ffd0 83c40c 85c0 7407 be01000000 eb02 33f6 }
+ $sequence_8 = { d945fc 5e 8be5 5d c3 8d8100000038 0bc6 }
+ $sequence_9 = { c7411000000000 c7411400000000 837e1408 8975d0 7205 8b16 8955d0 }
condition:
- 7 of them and filesize <2495488
+ 7 of them and filesize <26230784
}
-rule MALPEDIA_Win_Lcpdot_Auto : FILE
+rule MALPEDIA_Win_Crat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a95a9872-7a8a-5e4e-81d9-79280cf44b78"
+ id = "5ca84b15-9c50-5146-aeb0-8e43c37e0140"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lcpdot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lcpdot_auto.yar#L1-L158"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crat_auto.yar#L1-L175"
license_url = "N/A"
- logic_hash = "3aab7a93128b920a2310606f2af0b9275aa227850391bd4e2d60e74544bd69d0"
+ logic_hash = "a19b8917ee2e01478bdd8090b22583a65c2cc48e63af4151406da25e5b4c7a8a"
score = 75
quality = 75
tags = "FILE"
@@ -159140,37 +166117,39 @@ rule MALPEDIA_Win_Lcpdot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? c705????????01000000 e8???????? 83f801 }
- $sequence_1 = { 85c9 0f848c000000 53 56 8b7208 }
- $sequence_2 = { 6a01 52 56 8d8508feffff }
- $sequence_3 = { e8???????? 85c0 752a 56 ff15???????? }
- $sequence_4 = { ff24851e884000 838de8fdffffff 89b588fdffff 89b5bcfdffff }
- $sequence_5 = { 90 488b4308 4885c0 743f 488b0d???????? 488d15ad4f0100 }
- $sequence_6 = { ffd7 5f 5e c3 55 8bec 81ec400c0000 }
- $sequence_7 = { 8d8d14f4ffff 51 ebd8 83c320 53 8bce e8???????? }
- $sequence_8 = { 8b11 8b4228 53 ffd0 33c0 8d55e0 }
- $sequence_9 = { 85c0 0f8514010000 4c8d2d0a2f0100 41b804010000 }
- $sequence_10 = { 488d4c2430 e8???????? b920080000 e8???????? }
- $sequence_11 = { 48894c2408 4881ec88000000 488d0df54d0100 ff15???????? }
- $sequence_12 = { 488bd9 894110 bf04000000 3daa55aa55 7519 }
- $sequence_13 = { 7409 488bcf ff15???????? 33c0 488b9c2470040000 488b8c2440040000 4833cc }
- $sequence_14 = { 488d1d23de0000 488d3d24de0000 eb0e 488b03 4885c0 7402 ffd0 }
+ $sequence_0 = { e8???????? 488bd0 488d8d90010000 e8???????? 90 }
+ $sequence_1 = { e8???????? 488bd0 488d8d88000000 e8???????? 90 }
+ $sequence_2 = { 7406 e8???????? 90 488b542420 4883c2e8 }
+ $sequence_3 = { e8???????? 488bc8 4885c0 7433 }
+ $sequence_4 = { e8???????? 488bd0 488d8da8010000 e8???????? 90 }
+ $sequence_5 = { 48f7c20000ffff 7523 0fb7fa 8bcf e8???????? 4885c0 7427 }
+ $sequence_6 = { e8???????? 488bd0 488d4d58 e8???????? 90 }
+ $sequence_7 = { ebd0 498bc4 48833d????????10 480f4305???????? 482bc8 }
+ $sequence_8 = { 33d2 c1e902 f7f1 eb02 }
+ $sequence_9 = { ffd0 85c0 750f ff15???????? }
+ $sequence_10 = { 8bcb e8???????? 8b55d8 8b4b0c }
+ $sequence_11 = { 8bcb e8???????? 8b4b0c 8d4101 }
+ $sequence_12 = { 8b4004 8bca 3bc2 0f47c8 51 8b4d10 e8???????? }
+ $sequence_13 = { 8b4b0c 8d4101 89430c c60100 8b4dd4 41 }
+ $sequence_14 = { 8b4324 668948fe c740f800000000 c740f400000000 c740f000000000 5f 5e }
+ $sequence_15 = { 8b5508 0f57c0 56 8b750c b896000000 f30f7f01 }
+ $sequence_16 = { 8b4b0c 8d4101 89430c 8a45d3 8801 8b4dd4 41 }
condition:
- 7 of them and filesize <257024
+ 7 of them and filesize <4161536
}
-rule MALPEDIA_Win_Ice_Ix_Auto : FILE
+rule MALPEDIA_Win_Yanluowang_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f7014fa0-a713-5faf-ab08-c5718709e2e0"
+ id = "f8b88dbc-f363-5fc7-a947-363c58e30984"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ice_ix"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ice_ix_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yanluowang"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yanluowang_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "fab5667b12ec8f3fc934ce2ccdb85e5f1acf73115ae434c2a20cd983e8b43fbd"
+ logic_hash = "6b0c4fbf1cf464112256b7ec1836b8a801dfd07954f33f682759e2bccef6aa82"
score = 75
quality = 75
tags = "FILE"
@@ -159184,34 +166163,34 @@ rule MALPEDIA_Win_Ice_Ix_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3bc3 748c 6a01 8d4584 50 6883346425 e8???????? }
- $sequence_1 = { 85db 0f844b020000 81fe00020000 0f873f020000 83fe06 0f86e5000000 8b03 }
- $sequence_2 = { 50 e8???????? 50 53 8d857cfeffff 50 e8???????? }
- $sequence_3 = { 56 57 6a02 5b 53 6821634578 }
- $sequence_4 = { 8d75b8 b891000000 e8???????? 8d75d0 b892000000 e8???????? 8d75dc }
- $sequence_5 = { 0f84dc000000 8d442420 50 ff15???????? 8db424c0000000 b8a2000000 e8???????? }
- $sequence_6 = { 6a73 8d74243c 58 e8???????? 8bc6 89442410 }
- $sequence_7 = { 6a42 8db550ffffff 58 e8???????? 8b75f4 8b55f0 3bf7 }
- $sequence_8 = { 0f84a7000000 83f8ff 0f849e000000 6a3b 8d75e0 58 897dec }
- $sequence_9 = { 68cc000000 6a2d 58 e8???????? ff75d0 ff15???????? 5f }
+ $sequence_0 = { 50 c745c8eca14400 c745cc02000000 e8???????? 8d45f8 50 8d8578ffffff }
+ $sequence_1 = { 7402 8913 8d510c 33ff 85d2 7402 }
+ $sequence_2 = { 85c1 750c 3bd1 1bd2 23d0 23542430 }
+ $sequence_3 = { 85c0 7402 8908 8b55d8 8d4804 33d6 85c9 }
+ $sequence_4 = { 8b048528c44500 6975d007536554 33048d28c04500 8945c0 8b45f8 8b4dc0 c1e808 }
+ $sequence_5 = { 8b4508 8bd6 33d7 f7d6 }
+ $sequence_6 = { 83c438 c645fc14 8d8d78eeffff ffb5e8eeffff ffb5b8eeffff ffb5b4eeffff ffb57ceeffff }
+ $sequence_7 = { 8b01 85c0 0f84cc2b0200 83f808 7d0f 6bc018 }
+ $sequence_8 = { 84ff 7557 8b95acf5ffff 8bc2 8b8da8f5ffff 2bc1 }
+ $sequence_9 = { 337dc8 8b4514 85c0 7402 8938 8d7904 33d2 }
condition:
- 7 of them and filesize <327680
+ 7 of them and filesize <834560
}
-rule MALPEDIA_Win_Dustman_Auto : FILE
+rule MALPEDIA_Win_Emotet_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "36b1ddf2-cf7c-571e-9cd1-f2576b628e0f"
+ id = "66e086d2-a552-5582-bb27-ef248a857482"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dustman"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dustman_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.emotet"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.emotet_auto.yar#L1-L609"
license_url = "N/A"
- logic_hash = "7655ffd1fc19c69013d45a561f004630940d9eb32b369648a9a2d4d61dad6d9e"
+ logic_hash = "0a0e9e76b9d5a85025f54433e276f35bcb5e942e8559eb03880f6fd71aab7315"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -159223,34 +166202,97 @@ rule MALPEDIA_Win_Dustman_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d150d620100 4b8d1c36 4c897710 4c8bc3 488bce }
- $sequence_1 = { 448d4303 895c2428 488d0ddb720000 4533c9 4489442420 }
- $sequence_2 = { 4903cb 48894d48 488bca 492bca 4c8d9dca010000 4903cb 48894d50 }
- $sequence_3 = { 884803 420fb60c20 884804 420fb60c28 884805 0fb60c10 }
- $sequence_4 = { f20f102d???????? f20f590d???????? f20f59ee f20f5ce9 f2410f1004c1 488d15767f0000 f20f1014c2 }
- $sequence_5 = { 7405 e8???????? b001 4883c428 c3 488d158ba50000 }
- $sequence_6 = { 492bca 4c8d9dcd010000 4903cb 48894d68 488bca 492bca 4c8d9dce010000 }
- $sequence_7 = { 488d053f1f0000 498b0b 4889442450 488b85e0040000 4889442460 486385f0040000 }
- $sequence_8 = { e8???????? 4885c0 7509 488d0597420100 eb04 4883c024 }
- $sequence_9 = { 48c1e028 480bd8 0fb6852e020000 48c1e030 480bd8 0fb6852f020000 48c1e038 }
+ $sequence_0 = { 3c41 7c04 3c5a 7e03 c60158 }
+ $sequence_1 = { 7e13 3c61 7c04 3c7a 7e0b 3c41 7c04 }
+ $sequence_2 = { 3c30 7c04 3c39 7e13 3c61 }
+ $sequence_3 = { c60158 41 803900 75dd }
+ $sequence_4 = { 33c0 3903 5f 5e 0f95c0 5b 8be5 }
+ $sequence_5 = { 83c020 eb03 0fb7c0 69d23f000100 }
+ $sequence_6 = { c1e808 8d5204 c1e910 8842fd 884afe }
+ $sequence_7 = { 880a 8bc1 c1e808 8d5204 }
+ $sequence_8 = { 8d5801 f6c30f 7406 83e3f0 }
+ $sequence_9 = { 8b4604 8b16 8945fc 8d45f8 }
+ $sequence_10 = { 83c410 8b45fc 0106 294604 }
+ $sequence_11 = { 03878c000000 50 ff15???????? 017758 }
+ $sequence_12 = { 8bfa 8bf1 ff15???????? 8b17 83c40c }
+ $sequence_13 = { 8945fc 8d45f8 6a04 50 ff760c }
+ $sequence_14 = { 8b17 83c40c 8b4d0c 8bc2 0bc1 83f8ff }
+ $sequence_15 = { c745fc04000000 50 8d45f8 81ca00000020 50 52 51 }
+ $sequence_16 = { 66c1e808 4d8d4004 418840fd 418848fe }
+ $sequence_17 = { 418848fe 66c1e908 418848ff 4d3bd9 72cf }
+ $sequence_18 = { 2bca d1e9 03ca c1e906 894c2430 }
+ $sequence_19 = { 418bd0 d3e2 418bcb d3e0 }
+ $sequence_20 = { 488bd3 488bcf 488b5c2460 4883c450 }
+ $sequence_21 = { d3e7 83f841 7208 83f85a }
+ $sequence_22 = { 418808 0fb7c1 c1e910 66c1e808 }
+ $sequence_23 = { 49895b08 49896b10 49897318 49897b20 4156 4883ec70 }
+ $sequence_24 = { 48895010 4c894018 4c894820 c3 }
+ $sequence_25 = { c1e807 46 83f87f 77f7 }
+ $sequence_26 = { 84c0 75f2 eb03 c60100 }
+ $sequence_27 = { f7e1 b84fecc44e 2bca d1e9 }
+ $sequence_28 = { 8bd3 8b0f e8???????? 85c0 }
+ $sequence_29 = { 7423 8a01 3c30 7c04 }
+ $sequence_30 = { 83c104 894e04 8b00 85c0 }
+ $sequence_31 = { 7907 83c107 3bf7 72e8 }
+ $sequence_32 = { 56 57 6a1e 8d45e0 }
+ $sequence_33 = { 52 52 52 52 68???????? 52 }
+ $sequence_34 = { 83ec48 53 56 57 6a44 }
+ $sequence_35 = { 83f87f 760d 8d642400 c1e807 }
+ $sequence_36 = { 83f87f 7609 c1e807 41 83f87f 77f7 }
+ $sequence_37 = { 6a00 6aff 50 51 ff15???????? }
+ $sequence_38 = { 50 6a00 6a01 6a00 ff15???????? a3???????? }
+ $sequence_39 = { 6a00 ff75fc 6800040000 6a00 6a00 6a00 }
+ $sequence_40 = { 50 56 6800800000 6a6a }
+ $sequence_41 = { 53 56 8bf1 bb00c34c84 }
+ $sequence_42 = { 56 68400000f0 6a18 33f6 56 56 }
+ $sequence_43 = { 55 89e5 648b0d18000000 8b4130 83b8a400000006 }
+ $sequence_44 = { 8b5508 befbffffff c600e9 29d6 01ce 897001 }
+ $sequence_45 = { 50 51 52 01c8 01d0 }
+ $sequence_46 = { 8b7d08 83fe00 8945f0 894dec }
+ $sequence_47 = { 89d6 83c60c 8b7df4 8b4c0f0c }
+ $sequence_48 = { 8bec 83ec08 56 57 8bf1 33ff }
+ $sequence_49 = { 51 8d4df8 51 ff75f8 50 6a03 6a30 }
+ $sequence_50 = { 8b466c 5f 5e 5b 8be5 5d }
+ $sequence_51 = { 8b5d08 b8afa96e5e 56 57 00b807000000 008b45fc33d2 00b871800780 }
+ $sequence_52 = { 8bf1 bb00c34c84 57 33ff }
+ $sequence_53 = { 83ec10 53 6a00 8d45fc }
+ $sequence_54 = { 6a03 6a00 6a00 ff7508 53 50 }
+ $sequence_55 = { 8b7020 8b7840 89c3 83c33c }
+ $sequence_56 = { c605????????00 0fb6d8 e8???????? 0fb6c3 }
+ $sequence_57 = { e8???????? 84c0 7519 33c9 }
+ $sequence_58 = { ff15???????? 83f803 7405 83f802 751e }
+ $sequence_59 = { 7519 33c9 0f1f4000 0fb6840c30010000 }
+ $sequence_60 = { 743e 8b5c2430 85db 741d }
+ $sequence_61 = { 8bf8 e8???????? eb04 8b7c2430 }
+ $sequence_62 = { 31c9 89e2 31f6 89720c 897208 }
+ $sequence_63 = { 488d15e70f0000 e8???????? 84c0 0f84f1000000 48899c2480030000 }
+ $sequence_64 = { 84c0 7466 0f1f4000 488b9c2448040000 4885db }
+ $sequence_65 = { 8b4a48 894e20 83c418 5e c3 }
+ $sequence_66 = { 8b4c241c 0f44c8 2b5134 8b442420 890424 89542404 894c2418 }
+ $sequence_67 = { 897204 8932 8b15???????? 8944247c f20f11442470 }
+ $sequence_68 = { 813c3850450000 0f44f5 895e34 890424 }
+ $sequence_69 = { e8???????? 8d0d2231d800 890424 894c2404 e8???????? 8b4c242c 894130 }
+ $sequence_70 = { 8bf8 85ff 7443 be???????? e8???????? }
+ $sequence_71 = { 8b442450 894c2414 8b4c2418 8908 }
+ $sequence_72 = { 8b5010 51 52 c745f48072e601 e8???????? 8bd8 85db }
condition:
- 7 of them and filesize <368640
+ 7 of them and filesize <733184
}
-rule MALPEDIA_Win_Valley_Rat_Auto : FILE
+rule MALPEDIA_Win_Harnig_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5aadade8-2e86-5c22-9399-653890e95f9a"
+ id = "4db6d1ff-ae88-5c90-aeff-64f63eac36fc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.valley_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.valley_rat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.harnig"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.harnig_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "788630470fd0066c9dad5026f208a936da1b0fab9009cb8b3a3ebf9a9cd14823"
- score = 60
- quality = 45
+ logic_hash = "278559dff9c1abda460af9efb2388b0afb57c006c8438cf3b67adcf26f15e5f4"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -159262,34 +166304,34 @@ rule MALPEDIA_Win_Valley_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4910 e8???????? 2500020000 33d2 0bc2 7506 32c0 }
- $sequence_1 = { e8???????? 50 8d4708 50 e8???????? 8bbdf0efffff 83c414 }
- $sequence_2 = { 8bf0 83c404 85f6 742f e8???????? 84c0 ba???????? }
- $sequence_3 = { 50 e8???????? 8b5654 33c9 8b4508 83c408 894d08 }
- $sequence_4 = { 8d04dd00000000 50 e8???????? 8bf0 83c404 85f6 7447 }
- $sequence_5 = { 8bc2 c1e81f 03c2 8d0c40 8b07 8d04c8 894704 }
- $sequence_6 = { 8b55f4 4f 75ce 8b4df8 8b7d08 8b5510 3bca }
- $sequence_7 = { 8b36 c6043e00 5f 5e 5d c3 55 }
- $sequence_8 = { eb64 33c0 668945e4 e8???????? ff75dc 8b7b04 8d45e3 }
- $sequence_9 = { c745fc00000000 53 8bce e8???????? 8b06 83f801 741e }
+ $sequence_0 = { c20800 6a05 ff742408 e8???????? c20400 53 }
+ $sequence_1 = { 8bca 8dbde8fbffff f3ab 8d45f0 50 8d85e8fbffff }
+ $sequence_2 = { ffd0 eb0b 68???????? ff15???????? 8bc8 }
+ $sequence_3 = { 03c1 5e c9 c20800 8b542404 8a0a 33c0 }
+ $sequence_4 = { 0bc6 5e c20800 6a05 }
+ $sequence_5 = { 56 8d85e0fdffff 50 ffd3 8d45e0 50 }
+ $sequence_6 = { 56 57 ba00010000 33c0 8bca 8dbde8f7ffff f3ab }
+ $sequence_7 = { 85c0 746b 8b45f8 68f1cbf7ae }
+ $sequence_8 = { ff5150 8b45fc 8b08 8d9524fdffff 52 8d9590feffff }
+ $sequence_9 = { 8a0a 33c0 84c9 7419 56 8bf0 }
condition:
- 7 of them and filesize <2256896
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Wslink_Auto : FILE
+rule MALPEDIA_Win_Rovnix_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "20de7893-0402-5999-83e1-25d8d59bd834"
+ id = "6d0efd0b-959b-5f07-9cf2-cb58dc189913"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wslink"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wslink_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rovnix"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rovnix_auto.yar#L1-L389"
license_url = "N/A"
- logic_hash = "8ce7768eb8de70c3eb5454e941b335f1710146a120509f2149ca4912b8c000bf"
+ logic_hash = "5e2878b298d1848da7bc42b9c6ab694e8616fdab743143a73f75bed6d973bc79"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -159301,34 +166343,68 @@ rule MALPEDIA_Win_Wslink_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 488bf0 4885c0 0f85ab000000 c7442420ec000000 4c8d0dcfbc0600 ba94000000 }
- $sequence_1 = { e9???????? 488d15beaf0700 41b804000000 488bce e8???????? 85c0 750c }
- $sequence_2 = { eb2a 8b4718 85c0 750b 488b4f08 e8???????? ffc8 }
- $sequence_3 = { 48894710 4885c0 7514 c744242085010000 4c8d0d88440a00 e9???????? 8b542460 }
- $sequence_4 = { e8???????? 85c0 0f848a000000 ffcf ffc3 85ff 7fd3 }
- $sequence_5 = { 830f04 be01000000 488bcd e8???????? 488bcd e8???????? 488b5c2450 }
- $sequence_6 = { e8???????? 85c0 0f84c9fdffff 8b8c2400010000 418bc4 85c9 0f94c0 }
- $sequence_7 = { ba70000000 4c8d0d82120a00 c744242067000000 8d4a94 448d42fa e8???????? 83c8ff }
- $sequence_8 = { e8???????? 85c0 0f8424feffff 488b03 4d8bcc 4d8bc7 498bd7 }
- $sequence_9 = { f70300010000 7407 e8???????? eb05 e8???????? 8b5718 33c9 }
+ $sequence_0 = { 8bf8 83c335 c1e902 ad 2bc3 ab e2fa }
+ $sequence_1 = { 7405 57 6a00 ffd2 89442408 }
+ $sequence_2 = { 83e7f0 89542418 83c710 8bea }
+ $sequence_3 = { be???????? 8b15???????? 83e7f0 89542418 }
+ $sequence_4 = { 60 bf40090000 be???????? 8b15???????? }
+ $sequence_5 = { ff15???????? 8b550c 884304 8bc2 c1e802 25ff000000 8d4cc324 }
+ $sequence_6 = { 83c220 85c0 7404 3bc2 }
+ $sequence_7 = { 7405 8d4e1c 8908 8b4508 }
+ $sequence_8 = { 7511 ff4e18 7505 e8???????? }
+ $sequence_9 = { 85c0 e8???????? 8be5 5d }
+ $sequence_10 = { 894804 8b4608 8b4e0c 8901 894804 8b4718 }
+ $sequence_11 = { 8936 8d7e08 897f04 893f 894e14 895e10 }
+ $sequence_12 = { 83f919 7703 83c220 85c0 }
+ $sequence_13 = { 8975d0 c745d800020000 8975d4 8975dc 8975e0 }
+ $sequence_14 = { 8b7e10 eb06 8b5d0c 8b7d08 8bcf ff15???????? }
+ $sequence_15 = { 7521 8bc3 c1e802 25ff000000 8d4cc724 8b01 }
+ $sequence_16 = { 5d c3 85c9 e8???????? }
+ $sequence_17 = { 5d c3 85c0 e8???????? }
+ $sequence_18 = { 16 85c9 23d2 59 }
+ $sequence_19 = { 55 8bec 85db 85c9 }
+ $sequence_20 = { 23db 81e1ff000000 23c9 83440c0404 }
+ $sequence_21 = { 23c9 81e1ffff0000 85c0 51 85c9 e8???????? 8be5 }
+ $sequence_22 = { 8b4d08 85d2 81e1ff000000 85db 83440c0404 23d2 }
+ $sequence_23 = { 45 7d58 95 08c1 a3???????? 5c 46 }
+ $sequence_24 = { 59 23db 23d2 81e1ffff0000 85c0 85c0 51 }
+ $sequence_25 = { 20a8261ce0dc 3d6235c121 652572f7a5a7 ce }
+ $sequence_26 = { 7e27 0cc7 8e610b 69f8d60e5ca1 2e08450d }
+ $sequence_27 = { 03ea 680c000000 012c24 8b0d???????? }
+ $sequence_28 = { 17 d3fb 7127 49 ee }
+ $sequence_29 = { 4c8bdc 49895b08 49897310 57 4883ec30 33c0 }
+ $sequence_30 = { 4b af 7dce 98 }
+ $sequence_31 = { 498be8 488bfa 7429 498d4320 488bd1 498d4bc8 }
+ $sequence_32 = { 498b5b38 498b6b40 498b7348 8bc7 498be3 415f }
+ $sequence_33 = { 61 54 99 46 45 e7f2 0ad7 }
+ $sequence_34 = { 807bf9f3 53 56 b88302010b 92 090468 }
+ $sequence_35 = { 59 85c0 85c0 81e1ffff0000 23d2 85db 51 }
+ $sequence_36 = { ff15???????? 4c8d5c2460 498b5b18 498b6b20 }
+ $sequence_37 = { 488364245800 488364247000 488364247800 488d442430 4c8d4c2440 }
+ $sequence_38 = { 46 92 c55151 a2???????? d24b46 }
+ $sequence_39 = { ff15???????? b8feff0000 483bf0 480f47f0 }
+ $sequence_40 = { 23d2 85db 8b4d08 85db }
+ $sequence_41 = { 81e1ffff0000 23d2 23c9 51 85c0 e8???????? }
+ $sequence_42 = { e19b 06 6d 99 }
+ $sequence_43 = { 61 c0390e 60 da57b2 }
condition:
- 7 of them and filesize <2007040
+ 7 of them and filesize <548864
}
-rule MALPEDIA_Win_Mosquito_Auto : FILE
+rule MALPEDIA_Win_Downdelph_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d845e95b-9b1b-51f7-92b1-5c116f68e381"
+ id = "9652ab66-5cde-50a7-9cf0-943c75b27c39"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mosquito"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mosquito_auto.yar#L1-L192"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.downdelph"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.downdelph_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "87ba9d2670a970e725fcb73c4f11150d5260680ad8d699153882d887044e12b1"
+ logic_hash = "800e73805e0adaa63996d81ee2c529d701882055ee15e51dd88ba5a4c6bc228a"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -159340,43 +166416,32 @@ rule MALPEDIA_Win_Mosquito_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f3a5 ff942464020000 81c450020000 85c0 }
- $sequence_1 = { 52 50 6a00 6801c1fd7d }
- $sequence_2 = { f7d8 1bc0 83e0b4 83c04c }
- $sequence_3 = { 8b10 8bc8 57 6842730000 ff5204 56 }
- $sequence_4 = { b994000000 8bfc f3a5 ff942464020000 }
- $sequence_5 = { 8b10 8bc8 ff5204 56 }
- $sequence_6 = { e8???????? 85c0 7517 8bcb e8???????? 8b7328 }
- $sequence_7 = { e8???????? 6a20 e8???????? 83c40c }
- $sequence_8 = { 8b00 33ff 57 6880000000 6a03 57 }
- $sequence_9 = { e8???????? 6a20 8bf0 e8???????? 8bc8 }
- $sequence_10 = { 8bfc f3a5 ff942460020000 81c450020000 }
- $sequence_11 = { 6824080000 50 e8???????? 83c410 }
- $sequence_12 = { 0000 006301 1000 7500 }
- $sequence_13 = { 0000 0018 a0???????? 57 }
- $sequence_14 = { 0000 0001 1001 c550f0 8b8078005900 }
- $sequence_15 = { 0000 0032 08804d086440 5e }
- $sequence_16 = { 0000 00645657 8b7dc2 0400 }
- $sequence_17 = { 0000 006500 676c 0010 }
- $sequence_18 = { ff15???????? 6a00 56 ff15???????? 8903 83f8ff }
- $sequence_19 = { 0000 00748078 3001 40 }
- $sequence_20 = { 6aff 5d c28bcf 7300 6a01 }
+ $sequence_0 = { 85c9 0f84d2feffff 53 56 57 89c3 }
+ $sequence_1 = { 83c4f8 8bf2 33d2 8bdc }
+ $sequence_2 = { e8???????? 48 50 8bc3 b901000000 8b15???????? }
+ $sequence_3 = { 8d55d8 e8???????? 8b5708 88041a }
+ $sequence_4 = { 53 56 33db 899de0fbffff }
+ $sequence_5 = { 0f8cd6020000 46 33ff 8b15???????? 8bc7 e8???????? }
+ $sequence_6 = { 8b45fc e8???????? 50 8b45f0 }
+ $sequence_7 = { 2bd3 2bd7 8bfa 85ff 7d02 33ff }
+ $sequence_8 = { 68???????? 64ff32 648922 6a00 6800000080 }
+ $sequence_9 = { ff05???????? 7544 b8???????? e8???????? b8???????? }
condition:
- 7 of them and filesize <1015808
+ 7 of them and filesize <172032
}
-rule MALPEDIA_Win_Babyshark_Auto : FILE
+rule MALPEDIA_Win_Terminator_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bba62dea-b8fb-5177-af59-ee7484609223"
+ id = "9d4805e3-697a-5809-9888-0af99434fee9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.babyshark"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.babyshark_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.terminator_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.terminator_rat_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "170a55c792dd841a430b5276e4b7ea8cd0c0e2d28c406b503a22728951bd6c1d"
+ logic_hash = "460088279758b4b56f7253332ea9c90ec016fa5d0376dce042f468a189f77f7d"
score = 75
quality = 75
tags = "FILE"
@@ -159390,32 +166455,32 @@ rule MALPEDIA_Win_Babyshark_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c40c 8d4c2404 6a00 51 ffd6 6a00 }
- $sequence_1 = { 8bc8 83e01f c1f905 8b0c8d607e4000 8a44c104 83e040 }
- $sequence_2 = { 8b0c8d607e4000 8a44c104 83e040 c3 a1???????? }
- $sequence_3 = { bf???????? f3ab 8d3452 895dfc c1e604 aa 8d9ec8674000 }
- $sequence_4 = { 80e920 ebe0 80a0206c400000 40 3bc6 72be 5e }
- $sequence_5 = { 8db6bc674000 bf???????? a5 a5 59 a3???????? }
- $sequence_6 = { 8a8094504000 83e00f eb02 33c0 0fbe84c6b4504000 }
- $sequence_7 = { c1f804 83f807 8945d0 0f879a060000 ff2485271a4000 834df0ff }
- $sequence_8 = { 5e 8d0c8dc8614000 3bc1 7304 3910 7402 }
- $sequence_9 = { ff15???????? 8bf0 68???????? 8d442408 68???????? 50 }
+ $sequence_0 = { ffb519010000 8947fc 8b47f4 8b4008 894708 e8???????? 8b47fc }
+ $sequence_1 = { c70020000000 8b852d010000 2b08 894804 }
+ $sequence_2 = { 33db 395e0c 752f 6a40 6800100000 6800180000 }
+ $sequence_3 = { 26a130000000 07 8b400c 8b701c }
+ $sequence_4 = { 50 ffb525010000 ff95e1000000 85c0 }
+ $sequence_5 = { eb31 ff9509010000 3d4c270000 750e }
+ $sequence_6 = { 57 8bfc 81ec04040000 53 56 33db }
+ $sequence_7 = { 8b4b0c ac 3459 c0c803 3448 c0c803 }
+ $sequence_8 = { ffb519010000 8947fc 8b47f4 8b4008 }
+ $sequence_9 = { 60 33c0 8b4f0c 8b7f08 }
condition:
- 7 of them and filesize <65272
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Mirage_Auto : FILE
+rule MALPEDIA_Win_Flying_Dutchman_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1bf63709-182f-50be-a8ab-e40f87c0e4e9"
+ id = "bcfa70ed-52d3-5ff6-98d2-54bf0fdb6694"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mirage"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mirage_auto.yar#L1-L173"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flying_dutchman"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flying_dutchman_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "dc6fe884f3e04eb4b8ba5e715519d9f15ffa67807a8e3bc171df65981afb64ab"
+ logic_hash = "395092a50a0edc892d45a5d410470e4cbf5a35f346d3d2f6d581d10febaed0cd"
score = 75
quality = 75
tags = "FILE"
@@ -159429,38 +166494,32 @@ rule MALPEDIA_Win_Mirage_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6801000080 ff15???????? 85c0 7556 }
- $sequence_1 = { 50 6a01 6a06 c645ff01 }
- $sequence_2 = { a0???????? 8d8d90feffff ff35???????? 50 ff75ec ff75e8 e8???????? }
- $sequence_3 = { 50 8d857cfdffff 50 e8???????? 59 59 8d8580feffff }
- $sequence_4 = { 3b4510 894514 731f 6802800000 8d8520010000 53 }
- $sequence_5 = { ff7518 e8???????? 83c41c 85ff 7613 8b4518 57 }
- $sequence_6 = { 50 53 68???????? c745f804010000 ff75fc ff15???????? }
- $sequence_7 = { 395df4 0f85b1000000 3bf3 0f85a9000000 381f }
- $sequence_8 = { ff7518 03fb e8???????? 33db 59 }
- $sequence_9 = { 57 8b7d18 8bf1 8d5f19 88461c 53 e8???????? }
- $sequence_10 = { e8???????? 50 8d8520f9ffff e9???????? }
- $sequence_11 = { 85c0 5e 7507 8b45f8 }
- $sequence_12 = { 50 8b08 ff517c 8b06 8d55f4 52 50 }
- $sequence_13 = { e8???????? 8d45e4 56 83c704 }
- $sequence_14 = { ff15???????? 8d85f4f0ffff 53 50 68???????? 56 e8???????? }
- $sequence_15 = { 56 50 e8???????? 83c414 e9???????? ff75f0 e8???????? }
+ $sequence_0 = { 66890c02 83c002 6685c9 75f1 e9???????? 8b85e8feffff 83e800 }
+ $sequence_1 = { 48 0f84f8000000 48 0f853d010000 83bd44fcffff06 7553 8b35???????? }
+ $sequence_2 = { 8bec 51 56 6a18 e8???????? 33f6 }
+ $sequence_3 = { 8d442430 50 89742438 895c2434 68???????? eb40 57 }
+ $sequence_4 = { ff75f0 f3a5 ff75f4 ff15???????? ff75f4 8b35???????? ffd6 }
+ $sequence_5 = { 3bfb 7531 6a14 e8???????? 8bf0 59 }
+ $sequence_6 = { ff15???????? 3bc7 7504 33c0 eb1f 0fbf480a }
+ $sequence_7 = { 0f8489000000 48 747f 2ddb030000 }
+ $sequence_8 = { e8???????? 8be5 5d c20800 55 8bec 81eca8000000 }
+ $sequence_9 = { 832600 83660400 83660800 c3 8b4b04 56 57 }
condition:
- 7 of them and filesize <1695744
+ 7 of them and filesize <276480
}
-rule MALPEDIA_Win_Unidentified_096_Auto : FILE
+rule MALPEDIA_Win_Webc2_Ausov_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "22c09f40-2011-5730-9e32-986d3f55e0d2"
+ id = "452f6306-c16f-58b7-84a1-ee288d662c0a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_096"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_096_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_ausov"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_ausov_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "5261db5ca22f6df28b3364eb8987d65dbffd712b51f02eb4b92928e711dc9c45"
+ logic_hash = "e12dc956bf634cd764e774e1669338328ccbb898d34279d3918e11978d93f5a2"
score = 75
quality = 75
tags = "FILE"
@@ -159474,32 +166533,32 @@ rule MALPEDIA_Win_Unidentified_096_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 896c2444 c744244806000000 896c244c c744245010304000 }
- $sequence_1 = { ff15???????? 8bf0 a1???????? 3bf0 }
- $sequence_2 = { b021 a2???????? eb56 b040 a2???????? eb4d }
- $sequence_3 = { b02b eb11 b02d eb0d f644240c01 740b b02e }
- $sequence_4 = { 68???????? 52 e8???????? 83c424 8b4c242a 6683f930 0f8283000000 }
- $sequence_5 = { 90 6aff 68???????? 68???????? 64a100000000 }
- $sequence_6 = { 8b4c2420 8b54241c 8b442414 51 52 68ff000000 }
- $sequence_7 = { 3dff000000 741d 8b4c2420 8b54241c 51 52 }
- $sequence_8 = { b029 a2???????? eb5f b021 }
- $sequence_9 = { 56 8b35???????? 57 6a14 ffd6 6a10 0fbfd8 }
+ $sequence_0 = { 0f8501000000 f8 8b95f8fbffff 0355fc 8995f8fbffff 0f8407000000 }
+ $sequence_1 = { 83bdc4fdffff00 7507 33c0 e9???????? 8d8da8faffff 898d4cfaffff }
+ $sequence_2 = { 0f8487000000 8b3d???????? 68???????? 56 }
+ $sequence_3 = { 0f8407000000 0f8501000000 f8 68???????? }
+ $sequence_4 = { 83c101 894df8 8b55f8 3b55f4 7d31 0f8407000000 }
+ $sequence_5 = { f7d1 83c1ff 51 8d95f8feffff 52 }
+ $sequence_6 = { 0f8501000000 f8 68???????? 8d8dfcfbffff 51 }
+ $sequence_7 = { 6804010000 8d85a8faffff 50 68???????? ff15???????? 8985c4fdffff 83bdc4fdffff00 }
+ $sequence_8 = { 81ec10040000 53 56 57 0f8407000000 0f8501000000 }
+ $sequence_9 = { e8???????? 83c404 8b4d0c 894104 e9???????? 8dbdfcfbffff 83c9ff }
condition:
- 7 of them and filesize <25648
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Glooxmail_Auto : FILE
+rule MALPEDIA_Win_Malumpos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9fc08289-2c15-5e6a-a020-5e3374a227b0"
+ id = "011d5980-db12-575d-b128-68c240971c82"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.glooxmail"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.glooxmail_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.malumpos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.malumpos_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "3f9c49f2bcdac7dc8871b003117cb741dd79fa085062dcf8b6237e67caf4dc2a"
+ logic_hash = "1d9a68f5cdfadc8f79ba4d8f4695a01ec544e2c566edbd712a7ed582b4a68976"
score = 75
quality = 75
tags = "FILE"
@@ -159513,32 +166572,32 @@ rule MALPEDIA_Win_Glooxmail_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 834dfcff 6a00 53 8d4d38 }
- $sequence_1 = { e8???????? 899c2460800000 895c240c 895c2410 68ff7f0000 8d442451 53 }
- $sequence_2 = { 57 8d8c24f4030000 e8???????? 8d8c2418080000 51 8d8c24f4030000 c684246408000030 }
- $sequence_3 = { 0f840c000000 8365f0fe 8d4dc4 e9???????? c3 8b542408 8d420c }
- $sequence_4 = { b8???????? e9???????? 8d4d00 e9???????? 8d4dd4 e9???????? 8d4dd4 }
- $sequence_5 = { 59 c3 8b85acf7ffff 2500000400 0f8415000000 81a5acf7fffffffffbff }
- $sequence_6 = { e8???????? 8bd9 895de8 8d7b04 8d7308 c703???????? c707???????? }
- $sequence_7 = { c700???????? c74004???????? c74008???????? c7400cb04a4400 c74010bc4a4400 c74014c84a4400 c74018d44a4400 }
- $sequence_8 = { 8d8d2cffffff e9???????? c3 8b542408 8d82acfbffff 8b8aa8fbffff 33c8 }
- $sequence_9 = { ff750c 8b01 ff5044 84c0 7504 b301 eb02 }
+ $sequence_0 = { 85f6 7907 0d80000000 eb27 }
+ $sequence_1 = { 53 50 c78500fdffff07000100 895d4c 895dcc e8???????? }
+ $sequence_2 = { 59 8d45cc 50 ff15???????? 6a44 }
+ $sequence_3 = { 0f1f00 0f1f00 0f1f00 0f1f00 6a72 }
+ $sequence_4 = { 3bc8 0f86f1feffff ff770c 50 e8???????? }
+ $sequence_5 = { 7805 0500000000 57 3500000000 }
+ $sequence_6 = { 8a0432 3c3d 7506 8365fc00 eb0d }
+ $sequence_7 = { e8???????? 68???????? a3???????? ffd0 810d????????00200000 be???????? c745f468e50300 }
+ $sequence_8 = { 6683f300 55 51 7204 }
+ $sequence_9 = { 8d4520 50 ff15???????? 8d4520 }
condition:
- 7 of them and filesize <761856
+ 7 of them and filesize <542720
}
-rule MALPEDIA_Win_Decaf_Auto : FILE
+rule MALPEDIA_Win_Zeus_Mailsniffer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "871b7c64-9bb1-5d5d-b760-fe69f683da0a"
+ id = "4733ffb9-de21-5ee6-bd3e-4039874823ba"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.decaf"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.decaf_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus_mailsniffer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeus_mailsniffer_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "2f8679cf6195e76585744c378fca956597817fdb2b26b865768f35c66fced6eb"
+ logic_hash = "43d5df07bea6317ea4eb20e7781c6702e7589e518cedd0ad1502aceef73d3213"
score = 75
quality = 75
tags = "FILE"
@@ -159552,32 +166611,32 @@ rule MALPEDIA_Win_Decaf_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? e8???????? 48898424a8180000 48899c2440060000 488b0d???????? 48898c2420230000 488d0543040c00 }
- $sequence_1 = { 4c8b442470 4889c7 4889ce 488b442440 c7041fcacccec6 b905000000 e9???????? }
- $sequence_2 = { e9???????? 4c8d4302 4c39c6 7337 4c89442468 488d05d8a30300 4889d9 }
- $sequence_3 = { c3 488d0582761b00 bb10000000 e8???????? 4889f8 b900200000 e8???????? }
- $sequence_4 = { e8???????? 488b8c24b8040000 48894808 833d????????00 7514 488b8c2410160000 488908 }
- $sequence_5 = { eb1c 4889c7 488b8c24f0120000 e8???????? 488d3d53871f00 e8???????? e8???????? }
- $sequence_6 = { e8???????? 488d05d4ad1300 488d1d95d21900 e8???????? 4d8d6830 4c89d6 4d89ea }
- $sequence_7 = { e9???????? 90 66c744244f1c14 0fb654244f 88542445 440fb6442450 4488442444 }
- $sequence_8 = { c6041f95 31c9 e9???????? 4983f809 754d 4c8d4301 4c39c6 }
- $sequence_9 = { e9???????? 48895c2428 4889442430 488d0d664c1d00 bf0d000000 e8???????? 4885c0 }
+ $sequence_0 = { 6a01 56 e8???????? 83c40c 85c0 7473 807b0e02 }
+ $sequence_1 = { 53 6880000000 6a03 53 53 68000000c0 8bc6 }
+ $sequence_2 = { 68???????? ff750c ff15???????? 83c40c 85c0 0f85bc000000 ffd6 }
+ $sequence_3 = { 0f84e2020000 53 8d4594 50 8d4588 50 c7459401000000 }
+ $sequence_4 = { 8b4510 0118 ff45d8 837dc800 0f8480000000 ff75f4 }
+ $sequence_5 = { 33f6 e8???????? 83c40c 84c0 0f843d020000 8b45f4 }
+ $sequence_6 = { 56 ff75fc e8???????? 83c414 8bf8 8b35???????? ff15???????? }
+ $sequence_7 = { 0f8c5b010000 40 3b442410 72dd e9???????? 50 }
+ $sequence_8 = { 74f4 6a08 8d442430 53 }
+ $sequence_9 = { 2bd1 eb99 55 8bec 83e4f8 81ecfc0e0000 53 }
condition:
- 7 of them and filesize <7193600
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Reaver_Auto : FILE
+rule MALPEDIA_Win_Dramnudge_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "92b8afe7-b0ea-5ba5-8d5f-5512437f6132"
+ id = "4e1e9905-62de-5567-9ed7-a82928870a8c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.reaver"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.reaver_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dramnudge"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dramnudge_auto.yar#L1-L90"
license_url = "N/A"
- logic_hash = "8a78ae101ee8d9e477556b7d81328c10daa6a32306210d234ed44ad07120f4bd"
+ logic_hash = "221dd8bcd930b6121a924fbe6761de15c83c657ddce0c9178183beb8828f75f7"
score = 75
quality = 75
tags = "FILE"
@@ -159591,32 +166650,30 @@ rule MALPEDIA_Win_Reaver_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 85c0 7453 8d45f4 50 ff7508 }
- $sequence_1 = { 50 ff7508 6a00 ff15???????? 85c0 7440 }
- $sequence_2 = { ff15???????? 85c0 7453 8d45f4 }
- $sequence_3 = { 85c0 7453 8d45f4 50 ff7508 }
- $sequence_4 = { 85c0 7440 8b45f4 6a00 8945e8 }
- $sequence_5 = { 85c0 7440 8b45f4 6a00 }
- $sequence_6 = { 85c0 740d ff15???????? 3d14050000 7504 33c0 }
- $sequence_7 = { 8bec 83ec1c 8d45fc 50 68ff010f00 }
- $sequence_8 = { 8bec 83ec1c 8d45fc 50 68ff010f00 ff15???????? 50 }
- $sequence_9 = { 85c0 740d ff15???????? 3d14050000 }
+ $sequence_0 = { 014218 eb18 03c3 8bd3 }
+ $sequence_1 = { 000c00 20b140005f5f 7277 7374 }
+ $sequence_2 = { 014318 8b430c 2b4308 03c6 }
+ $sequence_3 = { 000c00 e0d9 40 007374 }
+ $sequence_4 = { 014318 8b4318 8b55f8 03d6 }
+ $sequence_5 = { 007374 643a3a 7275 6e }
+ $sequence_6 = { 0000 90 000c00 20b140005f5f }
+ $sequence_7 = { 014318 eb5b 33f6 eb01 }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <1294336
}
-rule MALPEDIA_Win_Nemim_Auto : FILE
+rule MALPEDIA_Win_Duqu_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7264494b-d73b-5298-a829-f60e4932364f"
+ id = "4f983d2e-8e54-5fa3-99e8-f35467f58ba0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nemim"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nemim_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.duqu"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.duqu_auto.yar#L1-L157"
license_url = "N/A"
- logic_hash = "0e5cb332d550079bcd770b6c5ca18dad9c60646bca1f9092ed4ed3564e5ea600"
+ logic_hash = "c9f95c9fbccbdcbcab2eb713244b96d59984c1db33c0129682f88201221bf820"
score = 75
quality = 75
tags = "FILE"
@@ -159630,32 +166687,38 @@ rule MALPEDIA_Win_Nemim_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { a1???????? c1e002 89b48050744300 8b0d???????? 893d???????? 890d???????? }
- $sequence_1 = { eb3b a1???????? 68???????? 50 e8???????? 83c408 }
- $sequence_2 = { 5e 5b c9 c20400 8bc1 c700???????? c3 }
- $sequence_3 = { 5e 5d b801000000 5b 81c4bc000000 c3 }
- $sequence_4 = { 8d44240c 55 50 56 c744241828010000 e8???????? 85c0 }
- $sequence_5 = { 51 e8???????? 8dbc24600a0000 83c9ff 33c0 }
- $sequence_6 = { 8b16 c1ea08 885001 8b0e c1e910 }
- $sequence_7 = { 52 e8???????? 8b4c2440 8944244c b801000000 }
- $sequence_8 = { 83fe10 7cde c605????????00 b90b000000 be???????? 8dbc2410010000 }
- $sequence_9 = { 8844244c e8???????? 68???????? e8???????? 68???????? 8bf0 }
+ $sequence_0 = { 8bcb e8???????? bacdc185ad 89464c }
+ $sequence_1 = { 85f6 7eb3 b8c64ff867 8bde 8bd7 89442420 }
+ $sequence_2 = { 8b5c2414 85db 0f8402ffffff 46 }
+ $sequence_3 = { 85c0 0f848b020000 ba10ee27d3 8bcf e8???????? 894624 85c0 }
+ $sequence_4 = { 0f84f7000000 0fb706 b9ab4f5ecd 33c1 }
+ $sequence_5 = { 56 51 8bf2 e8???????? }
+ $sequence_6 = { 83c120 0fb7c9 8bc1 0fafc9 83e007 }
+ $sequence_7 = { 85c0 7465 e8???????? 85c0 }
+ $sequence_8 = { 55 8bec 81ec08020000 56 8bf2 8d95f8fdffff }
+ $sequence_9 = { 8bcb e8???????? bafa67937e 894648 8bcf }
+ $sequence_10 = { 8bf2 57 8d8e14020000 e8???????? }
+ $sequence_11 = { 8bf2 57 8d4e4c e8???????? }
+ $sequence_12 = { 8bf2 8bf9 ff15???????? 56 }
+ $sequence_13 = { 8bf2 57 8d8ecc000000 e8???????? }
+ $sequence_14 = { 8bf2 57 8d8e0c020000 e8???????? }
+ $sequence_15 = { 8bf2 57 8bf9 85f6 7425 66833e00 }
condition:
- 7 of them and filesize <499712
+ 7 of them and filesize <18759680
}
-rule MALPEDIA_Win_Astralocker_Auto : FILE
+rule MALPEDIA_Win_Netrepser_Keylogger_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0d5879c8-ffd6-54eb-8701-3a0bd5bd2437"
+ id = "888501fd-ce54-593e-a428-69ec62ec3120"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.astralocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.astralocker_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.netrepser_keylogger"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.netrepser_keylogger_auto.yar#L1-L175"
license_url = "N/A"
- logic_hash = "04cf0865e55d3f7d37324f7ff4a5b3ef42183f756ec3ed69d17a248a6814ecfc"
+ logic_hash = "afbddedf93927cf0ceddcdc20a2ff3aea4d270191a04c2cfa6d38a1b702f0067"
score = 75
quality = 75
tags = "FILE"
@@ -159669,33 +166732,39 @@ rule MALPEDIA_Win_Astralocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b5508 8b440a04 50 8b0c0a 51 e8???????? }
- $sequence_1 = { 83c102 894dfc 837dfc0a 0f83dc000000 8b55fc 8b4508 }
- $sequence_2 = { 6bc20a 8b4d08 33d2 33f6 891401 }
- $sequence_3 = { 6bc20a 8b4d08 33d2 33f6 }
- $sequence_4 = { 8b440a04 50 8b0c0a 51 e8???????? 83c408 8945ec }
- $sequence_5 = { 894dfc 837dfc0a 0f83dc000000 8b55fc 8b4508 8b4cd004 }
- $sequence_6 = { 8b4508 8b4cd004 51 8b14d0 52 e8???????? }
- $sequence_7 = { 33c0 33f6 89040a 89740a04 }
- $sequence_8 = { ba08000000 6bc20a 8b4d08 33d2 33f6 891401 89740104 }
- $sequence_9 = { 33c0 33f6 89040a 89740a04 c745fc00000000 eb09 }
+ $sequence_0 = { 8a55f3 80c201 8855f3 837df807 7517 0fbe45f3 c6840570ffffff3a }
+ $sequence_1 = { 51 8b5508 52 ff15???????? eb71 8d45ec 50 }
+ $sequence_2 = { 51 680104c378 e8???????? 83c40c 8d55e8 52 }
+ $sequence_3 = { 8945f4 8b45f4 33d2 b900ca9a3b f7f1 8955f4 8b55f4 }
+ $sequence_4 = { 33c9 894ddc 894de0 894de4 894de8 c745dc10000000 c745e001000000 }
+ $sequence_5 = { 8b55f0 52 ff15???????? 8b45c0 8be5 }
+ $sequence_6 = { c645f274 c645f369 c645f466 c645f569 }
+ $sequence_7 = { 7e0b 83bde4feffff08 7d02 ebcb 83bde4feffff1a 7e0b }
+ $sequence_8 = { c744240c57726974 c74424106550726f c744241463657373 c74424184d656d6f c744241c72790000 ff15???????? a3???????? }
+ $sequence_9 = { 8b701c 8bcf e8???????? 8b4c240c }
+ $sequence_10 = { 51 c74424084f70656e c744240c50726f63 c744241065737300 ff15???????? a3???????? 8b542448 }
+ $sequence_11 = { 56 33ff 53 8906 894e08 }
+ $sequence_12 = { 68???????? ff15???????? 8bf8 85ff 7472 }
+ $sequence_13 = { 55 8b6c244c 85c0 7550 }
+ $sequence_14 = { f3a5 8b8c24b4000000 a4 8db329010000 56 }
+ $sequence_15 = { b840000000 55 89442410 89442414 8d442410 50 8d4c2418 }
condition:
- 7 of them and filesize <191488
+ 7 of them and filesize <303104
}
-rule MALPEDIA_Win_Bhunt_Auto : FILE
+rule MALPEDIA_Win_Rerdom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5486e0c5-654b-5b43-b68d-10c1b78a90c9"
+ id = "26b21d13-90fc-5a47-a822-e7b7af65cf28"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bhunt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bhunt_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rerdom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rerdom_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "f1702c9f5cf7c98ee774218c3a385f625fff81483374971b8b6cf77e6b060de8"
- score = 50
+ logic_hash = "f1628ed7c3a0f5463a2b7ad02b3e6deb2af0e74d20f58edaa325cbcbd6ff539b"
+ score = 75
quality = 75
tags = "FILE"
version = "1"
@@ -159708,32 +166777,32 @@ rule MALPEDIA_Win_Bhunt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { feca f8 d0c2 f5 f8 32da 80ffd4 }
- $sequence_1 = { 85c0 751a 8b442410 50 8bd5 8bc3 e8???????? }
- $sequence_2 = { 8902 660fbcc0 8b07 8dbf04000000 663bcf 66f7c4ab75 33c3 }
- $sequence_3 = { bbff000000 8bc3 8d7c2414 66c784241e1200000800 e8???????? 59 8d8600120000 }
- $sequence_4 = { 0fb7c2 8b55f0 03450c 2bd1 0fb74dfc }
- $sequence_5 = { ff7304 c645d405 56 e8???????? ff7304 ff36 e8???????? }
- $sequence_6 = { 83a530ffffff00 c7852cffffff01000000 ffb530ffffff ffb52cffffff 52 ffb544ffffff e8???????? }
- $sequence_7 = { 5f 9c 04f8 26ed c59818579fa0 5f e7e6 }
- $sequence_8 = { 52 3a21 a7 a2???????? 50 9d 03890023b0b3 }
- $sequence_9 = { ac 2a7279 bfae9603f7 6c a3???????? 9f 97 }
+ $sequence_0 = { 85f6 7425 8b550c b8???????? e8???????? 3bc7 }
+ $sequence_1 = { 89470c 8b4508 894708 eb1c 33db 53 }
+ $sequence_2 = { 8b44240c 21b0cc000000 21b0d0000000 8bd8 8d842412060000 50 83ceff }
+ $sequence_3 = { e9???????? 83f801 7533 8b4e04 8b97d0000000 8b4608 }
+ $sequence_4 = { e8???????? 53 a3???????? 57 8bc6 e8???????? 5f }
+ $sequence_5 = { 8b742430 8d4618 50 8d4c2428 e8???????? 84c0 741e }
+ $sequence_6 = { 7527 8b4510 85c0 7405 }
+ $sequence_7 = { 3bde 0f84c5000000 8b430c 3bc6 0f84ba000000 897510 8b00 }
+ $sequence_8 = { 8b450c e8???????? 8945e4 85c0 7427 8365fc00 ff750c }
+ $sequence_9 = { 41 66890456 0fb7044b 6685c0 75ec 8bc3 }
condition:
- 7 of them and filesize <19161088
+ 7 of them and filesize <352256
}
-rule MALPEDIA_Win_Qadars_Auto : FILE
+rule MALPEDIA_Win_Mangzamel_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9fe67d17-52ae-502a-8e0c-394e495a69f5"
+ id = "efd17f11-bd84-5994-8489-ce27d4f0f0e6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.qadars"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.qadars_auto.yar#L1-L161"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mangzamel"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mangzamel_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "3d2af7ca0745a690ff7b2f329cb25b898b4988f89dfff4953c93c63e52507d01"
+ logic_hash = "e3b6cc187254084e27045992bdf0d8b8ff879105635bf8f3e82d14e2723774a4"
score = 75
quality = 75
tags = "FILE"
@@ -159747,38 +166816,32 @@ rule MALPEDIA_Win_Qadars_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 48 c7048100000000 75f4 8b06 }
- $sequence_1 = { 8b4d10 8939 5f 8bc6 5e 5b }
- $sequence_2 = { 747a 8b45fc 3b4604 7650 33c9 }
- $sequence_3 = { 33c9 8908 894804 53 8b5d0c 8b4308 56 }
- $sequence_4 = { 83e940 0f8589040000 bb???????? 8b701c }
- $sequence_5 = { 33c0 6808020000 50 8d8de6fdffff 51 668985e4fdffff e8???????? }
- $sequence_6 = { 894608 85c0 75ee eb32 85db }
- $sequence_7 = { ff470c 8d4dc4 8955d0 e8???????? 8b75f4 }
- $sequence_8 = { 6a00 8d4df4 51 6a04 8d55f8 }
- $sequence_9 = { 6a01 6a08 ff15???????? 83c408 }
- $sequence_10 = { 6a01 8b55fc 52 ff15???????? 83c408 }
- $sequence_11 = { 83c40c 6805010000 8d8df8feffff 51 }
- $sequence_12 = { 51 8b55f0 52 ff15???????? 83c40c }
- $sequence_13 = { 83c408 6a09 8d4dc4 51 8b5518 }
- $sequence_14 = { 83c408 837de000 740c 8b4de0 }
- $sequence_15 = { 83c408 837df800 747f 8b4df8 }
+ $sequence_0 = { 8b7508 837e1410 7404 32c0 eb6e 8b06 53 }
+ $sequence_1 = { 8d8dd4feffff e8???????? 33db 8d8dc0fdffff 895dfc e8???????? 8d85d4feffff }
+ $sequence_2 = { 6a00 8bce ff7674 e8???????? 6a01 6804000102 8bce }
+ $sequence_3 = { ff7508 e8???????? 84c0 7404 c645f301 8b4df4 }
+ $sequence_4 = { 8bd0 8b00 8b5208 3932 7506 837a0400 }
+ $sequence_5 = { e8???????? 33c0 8bce 50 50 50 ff742414 }
+ $sequence_6 = { 8bce ff7508 ff5040 8ac3 5e 5b 5d }
+ $sequence_7 = { 57 8b7c2414 33c0 8907 8b0d???????? 3bc8 }
+ $sequence_8 = { 8d4b6c e8???????? 5e 5b c3 56 8bf1 }
+ $sequence_9 = { 8b74240c 57 8b7c240c 8d4602 50 57 e8???????? }
condition:
- 7 of them and filesize <630784
+ 7 of them and filesize <360448
}
-rule MALPEDIA_Win_Goopic_Auto : FILE
+rule MALPEDIA_Win_Grimplant_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "af6daaef-2e7b-547b-a95b-f4526c03929f"
+ id = "c3eab5e9-e64a-5697-878f-14199bbf7239"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.goopic"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.goopic_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grimplant"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grimplant_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "09cf2d520274006f21b8dfb7e13c7364d612efefae1767684cd3f4a4dac575b5"
+ logic_hash = "eec64e00f45245d4dee8d091e0d2ebea0088235a6d441087ed38c039f05955af"
score = 75
quality = 75
tags = "FILE"
@@ -159792,34 +166855,34 @@ rule MALPEDIA_Win_Goopic_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d85fcf7ffff 50 ff15???????? 6a00 6a00 6a00 6a00 }
- $sequence_1 = { 57 ff742428 ff15???????? 85c0 740d }
- $sequence_2 = { c785d0fdffff2c020000 ff15???????? 8bf0 8d85d0fdffff 50 56 }
- $sequence_3 = { 50 8b08 ff11 8b442414 50 }
- $sequence_4 = { ff15???????? 8bd7 8d8df8bfffff e8???????? 57 68???????? ff15???????? }
- $sequence_5 = { 8bfa ffd6 8bd8 895dfc }
- $sequence_6 = { 50 6aff 68???????? 6a00 6a00 ffd7 8d842448190000 }
- $sequence_7 = { 0f8664ffffff 8b4dfc 33c0 5f 5e 33cd 5b }
- $sequence_8 = { 53 ff15???????? 8bf8 85ff 0f84f4000000 56 6a00 }
- $sequence_9 = { c785c0fdffff305d4000 eb0a c785c0fdffff245d4000 8d85b4fdffff c785c4fdffff3c5d4000 50 }
+ $sequence_0 = { e9???????? 3c08 7465 eb15 3c0e 0f8ff5000000 90 }
+ $sequence_1 = { ffd2 eb3d 488b4c2428 488b91d0000000 488b442438 ffd2 4885c0 }
+ $sequence_2 = { eb1f 488db8486a0100 488d15ac5c5000 e8???????? 488db8506a0100 e8???????? 440f11b8586a0100 }
+ $sequence_3 = { ffd2 b914000000 4889c7 4889de 31c0 488d1da6514200 e8???????? }
+ $sequence_4 = { ffd1 4883f805 0f85f2100000 0f1005???????? 0f11442478 0f1005???????? 0f11842488000000 }
+ $sequence_5 = { 746c 4c8b4018 49ffc0 4c394020 7d5f 488d05a3ab1d00 0f1f00 }
+ $sequence_6 = { 90 488d05cbd28b00 e8???????? 488b442470 4c8b442440 4c8b4c2458 e9???????? }
+ $sequence_7 = { c6401801 440f113c24 48c744241000000000 488b9c2480000000 4889c1 488bbc24a0000000 488bb424a8000000 }
+ $sequence_8 = { 90 488d0567839000 e8???????? 8b542440 448b8424b0000000 448b4c2444 89d0 }
+ $sequence_9 = { eb0f 4889c7 488d159ceb1300 e8???????? 488d0588670a00 488b5c2448 b906000000 }
condition:
- 7 of them and filesize <114688
+ 7 of them and filesize <19940352
}
-rule MALPEDIA_Win_Emdivi_Auto : FILE
+rule MALPEDIA_Win_Colony_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c7c959fb-e496-5370-834c-2f119e1d6751"
+ id = "2ec04e04-70c5-5f61-acc9-0f96a006c29a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.emdivi"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.emdivi_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.colony"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.colony_auto.yar#L1-L225"
license_url = "N/A"
- logic_hash = "e1fc98ee3cf386dcf808c43ff2c4f0b6085fa811a19f892f7791e8e62f91b120"
+ logic_hash = "a79879d34246651b7f75532605ca94c4866e5edbca41b238eabaad9f54198dce"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -159831,34 +166894,48 @@ rule MALPEDIA_Win_Emdivi_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fbe441fff 83c404 2bd8 8bf3 8d4601 }
- $sequence_1 = { 59 c745e401000000 c745e803000000 c745ec05000000 894df0 c745f408000000 c745f80a000000 }
- $sequence_2 = { c645f800 e8???????? 8b45d4 5b 8b4dfc 33cd 5f }
- $sequence_3 = { ff5108 e8???????? c3 beff010000 56 }
- $sequence_4 = { ff750c 8365e000 ff7508 33c0 c645e400 8d7de5 }
- $sequence_5 = { 5f c9 c3 6a1f }
- $sequence_6 = { eb07 888415b4fdffff 42 41 41 }
- $sequence_7 = { 8bf0 e8???????? 99 2bf7 f7fe }
- $sequence_8 = { 55 8bec 53 56 6a03 5b }
- $sequence_9 = { 83e003 33d2 3955f0 8945f8 }
+ $sequence_0 = { 0118 e9???????? 6a00 6818200000 }
+ $sequence_1 = { 0118 e9???????? c745ec00000000 85db }
+ $sequence_2 = { 03c1 50 e8???????? 83c40c 8b45f0 }
+ $sequence_3 = { 8b421c 2b4218 660f6ec0 f30fe6c0 }
+ $sequence_4 = { 8b4214 2b4210 660f6ec0 f30fe6c0 }
+ $sequence_5 = { 0101 0101 0101 0202 0202 0200 }
+ $sequence_6 = { 69d200008f04 2bc8 c1e910 69c161a4f778 2bd0 }
+ $sequence_7 = { 0102 894dec 3bcb 7c85 }
+ $sequence_8 = { 7407 b901000000 eb0a 33c9 803f01 0f95c1 33c0 }
+ $sequence_9 = { 8b420c 2b4208 660f6ec0 f30fe6c0 }
+ $sequence_10 = { 034de8 894604 893e 8930 }
+ $sequence_11 = { 740f 0301 eb0b a801 }
+ $sequence_12 = { 03f1 ff15???????? 8b0d???????? 53 }
+ $sequence_13 = { 03c0 8985bcfbffff 8d85bcfbffff 6a00 }
+ $sequence_14 = { 8a4202 8841ff 8b02 c1e808 }
+ $sequence_15 = { 660f6e4104 f30fe6c0 84c0 7509 }
+ $sequence_16 = { 488d15e5980000 483305???????? 488bcb 488905???????? ff15???????? 488d15e7980000 483305???????? }
+ $sequence_17 = { e8???????? 4803db 4c8d3590fc0000 49833cde00 7407 }
+ $sequence_18 = { 837b0801 7524 4863c6 488d15551a0100 4533c0 488d0c80 ffc6 }
+ $sequence_19 = { 488905???????? ff15???????? 488d15f3980000 483305???????? 488bcb 488905???????? }
+ $sequence_20 = { 488d3d0cb8ffff 488bcf e8???????? 85c0 }
+ $sequence_21 = { 488d1552fb0000 483950f0 740c 488b10 4885d2 7404 f044010a }
+ $sequence_22 = { 0f8c65030000 488d3534ac0000 4883ee60 4585ed 0f843f030000 }
+ $sequence_23 = { 3b0d???????? 7367 4863c1 4c8d354acd0000 488bf8 83e01f 48c1ff05 }
condition:
- 7 of them and filesize <581632
+ 7 of them and filesize <7599104
}
-rule MALPEDIA_Win_Qakbot_Auto : FILE
+rule MALPEDIA_Win_Doppelpaymer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "241bd352-128e-5f57-a961-1a32ff520127"
+ id = "f239cfc1-7cb1-5c3d-a2a9-bf2ad44d0856"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.qakbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.qakbot_auto.yar#L1-L449"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doppelpaymer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doppelpaymer_auto.yar#L1-L181"
license_url = "N/A"
- logic_hash = "9011c5853a3a4bce7115bdec7dfc8cc7a3dbd683d5e3bd577fb86bb5ca62af81"
+ logic_hash = "6c7514bbe70399e920b266dcf23ab956c2fd28d40abc6464ad39f41a291bdfca"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -159870,75 +166947,40 @@ rule MALPEDIA_Win_Qakbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c9 c3 55 8bec 81ecc4090000 }
- $sequence_1 = { 33c0 7402 ebfa e8???????? }
- $sequence_2 = { 7402 ebfa 33c0 7402 }
- $sequence_3 = { 7402 ebfa eb06 33c0 }
- $sequence_4 = { e8???????? 33c9 85c0 0f9fc1 41 }
- $sequence_5 = { 50 e8???????? 8b06 47 59 }
- $sequence_6 = { 8d45fc 6aff 50 e8???????? }
- $sequence_7 = { 59 59 33c0 7402 }
- $sequence_8 = { e8???????? 59 59 6afb e9???????? }
- $sequence_9 = { 740d 8d45fc 6a00 50 }
- $sequence_10 = { 50 8d8534f6ffff 6a00 50 e8???????? }
- $sequence_11 = { 8945fc e8???????? 8bf0 8d45fc 50 e8???????? }
- $sequence_12 = { 33c0 e9???????? 33c0 7402 }
- $sequence_13 = { 7402 ebfa e9???????? 6a00 }
- $sequence_14 = { 8975f8 8975f0 8975f4 e8???????? }
- $sequence_15 = { eb0b c644301c00 ff465c 8b465c 83f840 7cf0 }
- $sequence_16 = { 7cef eb10 c644301c00 ff465c 8b465c 83f838 }
- $sequence_17 = { e8???????? 83c410 33c0 7402 }
- $sequence_18 = { 85c0 750a 33c0 7402 }
- $sequence_19 = { c644061c00 ff465c 837e5c38 7cef eb10 c644301c00 }
- $sequence_20 = { 7507 c7466401000000 83f840 7507 }
- $sequence_21 = { 837dfc00 750b 33c0 7402 }
- $sequence_22 = { e8???????? e8???????? 33c0 7402 }
- $sequence_23 = { 833d????????00 7508 33c0 7402 }
- $sequence_24 = { c7466001000000 33c0 40 5e }
- $sequence_25 = { 7402 ebfa 837d1000 7408 }
- $sequence_26 = { 80ea80 8855f0 e8???????? 0fb64df7 }
- $sequence_27 = { 50 8d45d8 50 8d45d4 50 8d45ec }
- $sequence_28 = { 56 e8???????? 8b45fc 83c40c 40 }
- $sequence_29 = { 6a00 6800600900 6a00 ff15???????? }
- $sequence_30 = { 50 ff5508 8bf0 59 }
- $sequence_31 = { 6a00 58 0f95c0 40 50 }
- $sequence_32 = { 57 ff15???????? 33c0 85f6 0f94c0 }
- $sequence_33 = { 750c 57 ff15???????? 6afe 58 }
- $sequence_34 = { c3 33c9 3d80000000 0f94c1 }
- $sequence_35 = { 6a02 ff15???????? 8bf8 83c8ff }
- $sequence_36 = { 50 e8???????? 6a40 8d4590 }
- $sequence_37 = { 8d85e4fcffff 50 8d85e4fdffff 50 }
- $sequence_38 = { 56 e8???????? 83c40c 8d4514 50 }
- $sequence_39 = { e8???????? 6a00 8d45d4 50 68???????? }
- $sequence_40 = { 5d c3 33c9 66890c46 }
- $sequence_41 = { 8b4a04 83c204 03f0 85c9 75e1 }
- $sequence_42 = { 01f1 898424a8000000 899424ac000000 8d8424b4000000 89c2 8db424c4000000 }
- $sequence_43 = { 8a442417 8b4c2410 0485 88440c66 89ca 83c201 }
- $sequence_44 = { ffd3 85ff 741b 6808020000 6a00 }
- $sequence_45 = { 88442401 894c245c 0f847afdffff e9???????? }
- $sequence_46 = { 89442410 884c2417 eb94 55 89e5 31c0 }
- $sequence_47 = { 8945fc 8b4518 53 8b5d10 56 8945c4 }
- $sequence_48 = { 8b742420 81c638a1e7c3 39f0 89442410 894c240c 89542408 7408 }
- $sequence_49 = { 8b74242c bb3c13b648 f7e3 69f63c13b648 01f2 89442428 8954242c }
- $sequence_50 = { 8b4c2444 ffd1 83ec08 b901000000 ba66000000 31ff 89c3 }
- $sequence_51 = { 89e0 89580c bb04000000 895808 8b5c246c 895804 8b9c2480000000 }
- $sequence_52 = { 8bf0 83c40c 85f6 0f84f8000000 a1???????? }
+ $sequence_0 = { 80790600 7523 80790264 751d }
+ $sequence_1 = { 80790561 7517 80790361 7511 80790474 }
+ $sequence_2 = { e8???????? 8b08 e8???????? 3db6389096 }
+ $sequence_3 = { 83ec28 6800002002 6a00 6a01 }
+ $sequence_4 = { 80790264 751d 80790561 7517 }
+ $sequence_5 = { baffffff7f 43 e8???????? 3bd8 }
+ $sequence_6 = { 8d8c2450010000 e8???????? 89bc245c010000 8d442404 }
+ $sequence_7 = { e8???????? 8d8c2424030000 e8???????? 6a10 }
+ $sequence_8 = { c20400 8b4e44 8b4110 5e }
+ $sequence_9 = { 8955ec e8???????? 8d0d6f302b00 890424 894c2404 e8???????? 8d0d34302b00 }
+ $sequence_10 = { 890c24 8945c8 e8???????? 8b4de8 890c24 8945c4 }
+ $sequence_11 = { c3 8b45e8 b99054c837 8a55f3 80c2c9 2b4df4 }
+ $sequence_12 = { 83ec08 8b4508 8b4054 89e1 894104 }
+ $sequence_13 = { 8945c4 74d0 e9???????? 31c0 8b4db8 83c104 }
+ $sequence_14 = { 5b 5d c3 b8e2f49a29 2b45ec 8b4dcc 81c1ffff0000 }
+ $sequence_15 = { e8???????? 8b4de8 8b55d8 895128 8b75c4 897114 }
+ $sequence_16 = { a1???????? ffd0 8945bc 31c0 8b4de8 83c154 8b55e8 }
+ $sequence_17 = { c20400 8b400c 8b4810 56 8b700c 57 }
condition:
- 7 of them and filesize <4883456
+ 7 of them and filesize <7266304
}
-rule MALPEDIA_Win_Aukill_Auto : FILE
+rule MALPEDIA_Win_Scarabey_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a6d13b29-a1c3-5db7-ac5c-09009229e7b9"
+ id = "32f7c136-d07c-5221-8524-163d31e0f9ce"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aukill"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aukill_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scarabey"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.scarabey_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "ebc3504ab44ddd68fe35d4be4361ca674b2d7f3006cec23148755c773291be1b"
+ logic_hash = "1ba8f19bbb29b54a80b4850f75f9b4dbbfff504fea1a8a75cc950df78ae9916b"
score = 75
quality = 75
tags = "FILE"
@@ -159952,34 +166994,34 @@ rule MALPEDIA_Win_Aukill_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 751f 488b4c2458 ff15???????? }
- $sequence_1 = { 0fb7da 8bf9 e8???????? 4c8bc8 4533c0 }
- $sequence_2 = { 4533c0 33d2 488bcb ff15???????? 85c0 7526 488bcb }
- $sequence_3 = { 4889442420 ff15???????? 85c0 751f 488b4c2458 ff15???????? }
- $sequence_4 = { 751d 488bcb ff15???????? ff15???????? }
- $sequence_5 = { 4489442420 453b01 7346 4b8d1440 410f104cd108 0f114c2428 f2410f1044d118 }
- $sequence_6 = { 448d4920 48894c2450 488b0d???????? 48897c2458 }
- $sequence_7 = { 488bd3 33c9 ff15???????? 85c0 751f }
- $sequence_8 = { 48895c2408 57 4883ec60 488bfa 8bd9 e8???????? 33c9 }
- $sequence_9 = { ffc2 80f920 75ee 4c63c2 }
+ $sequence_0 = { 8bf0 85f6 7478 8b8dfcd6ffff 8b95f4d6ffff 8d85fcd6ffff 50 }
+ $sequence_1 = { e8???????? c745fcffffffff 8b06 8b7e04 2bf8 85c0 7409 }
+ $sequence_2 = { 51 52 ffd3 6a40 6800300000 }
+ $sequence_3 = { ff15???????? 56 ff15???????? a1???????? 33f6 56 }
+ $sequence_4 = { ba12000000 8d0dd0ad5700 e9???????? db2d???????? d9c9 d9f5 9b }
+ $sequence_5 = { 7d04 8944241c 686666aa00 50 33db 6a02 895c2450 }
+ $sequence_6 = { 8bc8 8b8524d7ffff 83c005 8d14c500000000 2bd0 a1???????? 03ca }
+ $sequence_7 = { e8???????? 8b4d08 8b83d40c0000 8bf0 83f907 7771 ff248d690c4700 }
+ $sequence_8 = { eb4c 8d4c2404 68???????? 51 e8???????? 83c408 84c0 }
+ $sequence_9 = { c744240808000000 c744240cff000000 ff15???????? 8bce e8???????? 6a00 e8???????? }
condition:
- 7 of them and filesize <446464
+ 7 of them and filesize <3580928
}
-rule MALPEDIA_Win_Felismus_Auto : FILE
+rule MALPEDIA_Win_Sisfader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5818ed3f-2431-5f26-88a0-82a8f566adf3"
+ id = "1937373c-a869-5de8-8c47-c30db9548d3e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.felismus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.felismus_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sisfader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sisfader_auto.yar#L1-L291"
license_url = "N/A"
- logic_hash = "dea5875d596c4ef87d002c63282ac83d0f7df95527f5e0d6e66faa21ccc2e20e"
+ logic_hash = "288baaa87a5a9f6675c09b00537afbaf23a5deab091befb8544155fddb8ada09"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -159991,32 +167033,52 @@ rule MALPEDIA_Win_Felismus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8b35???????? 83c404 53 ffd6 8b442410 }
- $sequence_1 = { 8b4e08 8b560c 89442418 8b4610 894c241c 89442424 }
- $sequence_2 = { 89542410 8b5110 56 2be8 57 89542420 bb01000000 }
- $sequence_3 = { 8d5640 8bfa f3ab 8b4618 33c9 85c0 7e24 }
- $sequence_4 = { 66ab aa b940000000 33c0 8dbc24b1050000 }
- $sequence_5 = { 85c0 740f 8d8c2414010000 68???????? 51 eb0d 8d942414010000 }
- $sequence_6 = { 8b442424 50 56 ff15???????? 56 ff15???????? 83f8ff }
- $sequence_7 = { 7cd0 8b461c 8bce 50 e8???????? 8b7e1c }
- $sequence_8 = { 51 8bfb 83c9ff 33c0 895514 f2ae f7d1 }
- $sequence_9 = { 83c408 85ff 742b 57 ff15???????? 83f816 7e1f }
+ $sequence_0 = { 85c9 741f 33c0 85c9 }
+ $sequence_1 = { e8???????? 85c0 b91d000000 0f44d9 }
+ $sequence_2 = { 8906 83f824 723e b824000000 }
+ $sequence_3 = { 8b4dfc 51 8b55f8 52 e8???????? 83c408 8945f4 }
+ $sequence_4 = { 33d2 b904000000 e8???????? 33c0 83f801 7425 baffffffff }
+ $sequence_5 = { 83793000 0f85be000000 8b55fc 8b45f0 }
+ $sequence_6 = { 837c245000 7402 eb12 c744245401000000 33c0 }
+ $sequence_7 = { c705????????07000000 8b442438 8905???????? c705????????00000000 8b442440 8905???????? c705????????b80b0000 }
+ $sequence_8 = { 837c242001 7425 837c242002 7441 837c242003 745d 837c242004 }
+ $sequence_9 = { 85c0 752b 8d45f8 c745f882000000 50 8d8618010000 50 }
+ $sequence_10 = { 66837c246c2e 7518 0fb74c246e 6685c9 }
+ $sequence_11 = { 83790800 745d c745f800000000 eb09 8b55f8 83c201 }
+ $sequence_12 = { 746b c744242000000000 eb0a 8b442420 }
+ $sequence_13 = { 6a04 e8???????? 83c40c 8b4d0c 51 }
+ $sequence_14 = { 8b442448 89442420 837c242001 7402 eb05 e8???????? }
+ $sequence_15 = { 8b45f0 83781000 750e 8b4df0 8b510c 0355cc 8955e4 }
+ $sequence_16 = { 0fb74c247e 6685c9 0f84cd010000 6683f92e 750f }
+ $sequence_17 = { 720b 03f0 eb9c 5f 5e 33c0 5b }
+ $sequence_18 = { e8???????? b90e000000 ff15???????? 33c0 e9???????? e9???????? ff15???????? }
+ $sequence_19 = { 745d 837c242004 7479 837c242005 0f8480000000 }
+ $sequence_20 = { ebbc 8b4dfc 8b5108 52 ff15???????? 83c404 8b45fc }
+ $sequence_21 = { 8d8574fdffff 6804010000 50 6a00 ff15???????? 8d8574fdffff }
+ $sequence_22 = { 7426 8b4f04 85c9 741f }
+ $sequence_23 = { 8139aaeeddff 0f858e000000 8b4104 85c0 }
+ $sequence_24 = { 8b45fc 8b08 83792800 7457 }
+ $sequence_25 = { 85c9 7513 ffb318020000 ff15???????? 33c0 5b }
+ $sequence_26 = { 8b45ac 894610 8b45b0 894614 ff15???????? 66894604 8d45e8 }
+ $sequence_27 = { 8b55fc 8b4230 50 ff15???????? 83c404 }
+ $sequence_28 = { ba08020000 0f114014 c7400856120000 89580c c700aaeeddff }
+ $sequence_29 = { 85c0 7416 0f1f4000 8bc1 83e00f 8a0430 30441124 }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <417792
}
-rule MALPEDIA_Win_Void_Auto : FILE
+rule MALPEDIA_Win_8Base_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "71ce776b-404f-5334-912d-5acada68aa35"
+ id = "7c9b0c56-079f-5ac3-b0fc-c036345ce952"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.void"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.void_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.8base"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.8base_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "c9d396773d78302d4ad6bf52fbcd07db1d946f6b7dffcc9d3a1efd465ff43099"
+ logic_hash = "ea755be9fd3154ace1513f9f57e59c67fbe5ae97b6b4073ab7fa5cccbb0a5bb8"
score = 75
quality = 75
tags = "FILE"
@@ -160030,30 +167092,32 @@ rule MALPEDIA_Win_Void_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a09 8d4c2410 51 50 e8???????? 85c0 7518 }
- $sequence_1 = { 5d c20c00 6a00 ff750c 50 e8???????? 50 }
- $sequence_2 = { 807d6b00 0f8483000000 6a02 8d4dc4 e8???????? 8d45c4 c745fc02000000 }
- $sequence_3 = { 0f43c6 50 ff7514 8d45ac ff7510 50 53 }
- $sequence_4 = { 5b 8bc1 8b4c2440 5e 5d 33cc e8???????? }
- $sequence_5 = { 7473 8d4dec 8975ec e8???????? 53 8bcf 8b00 }
- $sequence_6 = { 854110 7419 8d45e4 6a01 50 e8???????? 83c408 }
- $sequence_7 = { 894610 c1e102 51 8d0490 6a00 50 e8???????? }
+ $sequence_0 = { 6a00 ff15???????? 8d8e04a2feff 81f98c230000 770b }
+ $sequence_1 = { f8 290c67 98 a6 73c2 }
+ $sequence_2 = { 8815???????? c605????????6f 880d???????? c605????????65 c605????????63 }
+ $sequence_3 = { 8d3485c0289100 8b06 83e71f c1e706 03c7 8a5824 }
+ $sequence_4 = { c684249c00000002 50 c7442410043a4000 e8???????? }
+ $sequence_5 = { d3ea 89542414 8b442434 01442414 8b442424 31442410 }
+ $sequence_6 = { ff15???????? 8b442414 40 3d???????? 89442414 0f8c0effffff 8b35???????? }
+ $sequence_7 = { 8bf7 83e61f c1e606 033485c0289100 c745e401000000 }
+ $sequence_8 = { 6689442416 33c9 668954241a 8d442434 50 66894c241c 8b4c241c }
+ $sequence_9 = { 899c24ac000000 3bfb 7449 8b8424b8000000 56 8d742418 }
condition:
- 7 of them and filesize <2744320
+ 7 of them and filesize <10838016
}
-rule MALPEDIA_Win_Danabot_Auto : FILE
+rule MALPEDIA_Win_Crypto_Fortress_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6c78b1f9-714b-5978-8883-c700c384c0f3"
+ id = "6a23a7a3-8360-570b-be01-5aa731924fe0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.danabot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.danabot_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crypto_fortress"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crypto_fortress_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "4cb498ddb7090d3a6017b222a7d9cd57acddd4317f82294d9c05727c52600ae4"
+ logic_hash = "cb9e8ad6d0528bcc920d7d8992919925e873e6ab7fd21de603b21e974fe6d2be"
score = 75
quality = 75
tags = "FILE"
@@ -160067,32 +167131,32 @@ rule MALPEDIA_Win_Danabot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7405 83e804 8b00 83f814 7e18 8b45fc 50 }
- $sequence_1 = { c1e803 83e03f 83f838 730b ba38000000 }
- $sequence_2 = { 8b03 50 8b44242c 50 6a14 }
- $sequence_3 = { 8b45f8 85c0 7407 83e804 }
- $sequence_4 = { 8b16 e8???????? 8b07 50 8b442428 50 6a0a }
- $sequence_5 = { 50 6a14 688a4c2a8d 8bc6 8b4d00 8b17 }
- $sequence_6 = { 3b85d0feffff 7452 8b85d0feffff 50 6a00 }
- $sequence_7 = { 6a00 49 75f9 51 53 56 bb???????? }
- $sequence_8 = { 8b0f 8b16 e8???????? 8b07 50 8b442454 50 }
- $sequence_9 = { 56 57 8bf1 8955f8 8945fc 8d45fc }
+ $sequence_0 = { ffb5a8feffff e8???????? 68???????? ffb5a8feffff e8???????? }
+ $sequence_1 = { a3???????? 68???????? ff35???????? e8???????? 85c0 0f846f030000 }
+ $sequence_2 = { aa 3407 aa 045a aa }
+ $sequence_3 = { e8???????? 85c0 0f846f030000 a3???????? 68???????? ff35???????? e8???????? }
+ $sequence_4 = { ff35???????? e8???????? 85c0 0f8456060000 a3???????? 8d3dccec4000 33c0 }
+ $sequence_5 = { 2cff aa 2cf9 aa 2c4c }
+ $sequence_6 = { aa 2c4e aa 0444 aa 2cff aa }
+ $sequence_7 = { c9 c20800 55 8bec 83c4f8 8b4508 }
+ $sequence_8 = { aa 341b aa 2c27 aa 3441 aa }
+ $sequence_9 = { aa 340a aa 3421 aa 0433 aa }
condition:
- 7 of them and filesize <237568
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Remy_Auto : FILE
+rule MALPEDIA_Win_Blindingcan_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7ce97943-cfc3-5429-92c7-f07c9ff48391"
+ id = "cb880a40-09fd-57de-a5ce-976bc164d187"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.remy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.remy_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blindingcan"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blindingcan_auto.yar#L1-L180"
license_url = "N/A"
- logic_hash = "8cc4f887faa36fa3ebf369fe88c2b140d588410f99b73c322f37daf8b5d5619a"
+ logic_hash = "7d6669fb427721c8bcc6cd766a15275abac3a422e034ffec946a676b43de9099"
score = 75
quality = 75
tags = "FILE"
@@ -160106,32 +167170,38 @@ rule MALPEDIA_Win_Remy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c404 3bc3 7420 50 8bc6 8d7c241c }
- $sequence_1 = { 56 81c30f010000 53 e8???????? 8d46f0 }
- $sequence_2 = { 3dc8000000 0f85c50b0000 6a28 8d742424 895c2424 895c2428 895c242c }
- $sequence_3 = { 5d c3 8b7dfc 8d4fff 81f9ffff0000 7728 }
- $sequence_4 = { 7451 8d4634 898638100000 8d8634100000 c70000100000 895d0c 895d08 }
- $sequence_5 = { 51 8d570c 52 e8???????? 83c40c 8b4508 83c010 }
- $sequence_6 = { 8b5604 2bc8 2bd0 c1f902 c1fa02 3bd1 }
- $sequence_7 = { 8d8748100000 57 8908 8d4da4 51 8d55a0 52 }
- $sequence_8 = { 8d4d90 e8???????? 83c41c c645fc02 895e40 8bff 8b4d94 }
- $sequence_9 = { 50 ff15???????? 8b95b4feffff 52 ff15???????? 8b4df4 64890d00000000 }
+ $sequence_0 = { 83c40c 68???????? 68???????? ff15???????? 689c040000 85c0 }
+ $sequence_1 = { 750a 8b10 8994bdfcfdffff 47 83c00c 49 }
+ $sequence_2 = { c785bcfdffff661fcba8 c785c0fdffffc0f0d181 c785c4fdffff1f08c3d4 c785c8fdffff28edbc6a c785ccfdffff12aff210 }
+ $sequence_3 = { c745e4ef0dfff5 c745e85acd9c1d c745ec36c2f964 c745f0a70d9fae c745f48f2aedf1 }
+ $sequence_4 = { c78594feffff657f9183 c78598feffffa78b5b05 c7859cfeffff87f53e0c c785a0feffff074f9b22 }
+ $sequence_5 = { c745ac84b1df57 c745b0c8cbfee9 c745b4567e337f c745b8e958e686 }
+ $sequence_6 = { c78548feffffdfc2f62c c7854cfeffff17516633 c78550fefffff76c7e7e c78554feffffa14b0c27 c78558feffff10c0aac6 c7855cfeffff489a8471 c78560feffff9cab4ad6 }
+ $sequence_7 = { 740c a810 7408 c68435a8fcffff01 46 83fe1a }
+ $sequence_8 = { f7fe 8bca e8???????? 85c0 7409 e8???????? }
+ $sequence_9 = { 55 4154 4155 488da8e8f3ffff 4881ec000d0000 488b05???????? 4833c4 }
+ $sequence_10 = { 8bd5 664489642422 6689442420 895c2428 e8???????? 8bd3 488bcf }
+ $sequence_11 = { 85c0 751b e8???????? 4885c0 7461 448bc7 488d55c0 }
+ $sequence_12 = { 81e909200000 746e 83e907 745f ffc9 744d ffc9 }
+ $sequence_13 = { 410fb6c4 0fb68c2810be0100 41335518 400fb6c6 0fb6842810be0100 c1e108 33c8 }
+ $sequence_14 = { 488b4dc8 488d45c0 4c8d4db0 4889442428 488d0552d30100 488d1586340100 4533c0 }
+ $sequence_15 = { ff15???????? 4883ceff 4c8be8 4889442440 483bc6 752d ff15???????? }
condition:
- 7 of them and filesize <507904
+ 7 of them and filesize <363520
}
-rule MALPEDIA_Win_Elise_Auto : FILE
+rule MALPEDIA_Win_Unidentified_071_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f217246a-45c9-5e4c-8fe4-ae9bb248bda8"
+ id = "9e4ae8e5-b01b-5dfb-9ebf-d96081ff094b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.elise"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.elise_auto.yar#L1-L163"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_071"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_071_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "4bacbe3f48e2ba0fdae2760e38d43f9e3c8b071aa93c58355438ff735f59b16b"
+ logic_hash = "cf757bc05d123f04b705025eb8059bfc6f948c6a237ae24790160c041569438f"
score = 75
quality = 75
tags = "FILE"
@@ -160145,38 +167215,32 @@ rule MALPEDIA_Win_Elise_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f8461010000 8d847eee040000 50 e8???????? 85c0 }
- $sequence_1 = { 8bd0 c1ea0b 0fafd7 3bf2 7312 b800080000 }
- $sequence_2 = { 8bcb 8dbe06050000 f3ab 8bc2 8bcb }
- $sequence_3 = { 33c9 33db 663b4e06 731a }
- $sequence_4 = { 8bcf e8???????? 8365f400 c1e004 0145fc 33f6 46 }
- $sequence_5 = { 894dec 8945f4 8dbeba0a0000 8bc3 8bce }
- $sequence_6 = { 7cf5 33c9 888f00010000 888f01010000 }
- $sequence_7 = { 8d3470 d3e0 0945f4 43 83fb04 72e1 8b45f4 }
- $sequence_8 = { 888f00010000 888f01010000 8bf7 8945f8 }
- $sequence_9 = { 8d3400 8b44240c 03c6 50 }
- $sequence_10 = { eb02 d1e8 4e 75f1 }
- $sequence_11 = { e8???????? 59 59 33c0 e9???????? 8b35???????? }
- $sequence_12 = { 42 0fb6fa 8a1c07 881c06 }
- $sequence_13 = { 897df4 8b7d08 03df 0fb63c06 }
- $sequence_14 = { 837d0c00 8a8800010000 8a9001010000 0f8e93000000 53 }
- $sequence_15 = { 301f ff45f8 8b7df8 3b7d0c 0f8c7bffffff 5f 5e }
+ $sequence_0 = { e8???????? ff35???????? a3???????? a1???????? 0faf05???????? a3???????? e8???????? }
+ $sequence_1 = { 6a20 8901 83c8ff 5a 895104 894108 d1e8 }
+ $sequence_2 = { 8bd9 8b4b10 2bc1 894c2404 3bc2 0f82a7000000 8b4314 }
+ $sequence_3 = { 6a10 5a 0f44ca 51 50 ff15???????? }
+ $sequence_4 = { c3 33c0 c3 8b5108 b8ffffff0f }
+ $sequence_5 = { ff36 e8???????? 8b0e 8b4608 2bc1 894df8 6a18 }
+ $sequence_6 = { 8b4c2420 8d346d00000000 8b542428 56 ff742428 8d044a }
+ $sequence_7 = { c20400 55 8bec 8b450c ff7510 2b4508 c1f804 }
+ $sequence_8 = { 0f8290000000 8b4314 55 56 57 8d3c11 }
+ $sequence_9 = { 85c0 8b4314 740d 25ffffff82 0d00000002 894314 0fb64b01 }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <1220608
}
-rule MALPEDIA_Win_Eagerbee_Auto : FILE
+rule MALPEDIA_Win_Netwire_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2c944b22-0670-5d3a-8325-748c1204ab76"
+ id = "7e349eff-bed6-58da-b13d-023150840eee"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.eagerbee"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.eagerbee_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.netwire"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.netwire_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "128c0a374c8b1a00f6b82c3fc65b3e7ab4f3e40ebdc9cd2ac65e4a7f259bdca2"
+ logic_hash = "d56dccb0a24c96c7c7e1e50a683192f0a074d28ee0f4b72f3b3f8446384ae89a"
score = 75
quality = 75
tags = "FILE"
@@ -160190,32 +167254,32 @@ rule MALPEDIA_Win_Eagerbee_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 493bc7 753b 488b05???????? ff05???????? 488bcb ff90f8000000 488d1560d80100 }
- $sequence_1 = { 488d15b7aa0100 41b908000000 48c7c101000080 498943d8 c744245810000000 ff15???????? 85c0 }
- $sequence_2 = { 0f44d8 eb0b 8b7c245c e8???????? 8bd8 85db 7415 }
- $sequence_3 = { 744c 488d15be810200 488bcb 4d8bc7 e8???????? 488b05???????? }
- $sequence_4 = { 8b01 eb06 ff90c0000000 410fb7cc eb3b 488bcf }
- $sequence_5 = { 85c0 751e 4c8b4c2448 4c8b442440 488d1517640100 488b4c2430 ff15???????? }
- $sequence_6 = { 8d6f07 458d77c7 8d5fce 488d8c2470010000 664489bc2470010000 6689bc2472010000 }
- $sequence_7 = { c68424c20000006f c68424c300000073 4088bc24c4000000 c68424c500000073 c68424c60000006f c68424c700000063 4488bc24c8000000 }
- $sequence_8 = { 8bd8 ebbf ff90e0000000 8bd8 85db 0f8481020000 3bdf }
- $sequence_9 = { 4533c9 4533c0 48896c2458 4489642450 4489742454 48898698080000 c7869408000004000000 }
+ $sequence_0 = { c7042449000000 e8???????? c7042446000000 e8???????? c7042400000000 e8???????? }
+ $sequence_1 = { c7042401000080 e8???????? c7042410000000 e8???????? }
+ $sequence_2 = { c744240c00000000 c744240800000000 c744240400000000 c7042408000000 e8???????? 83ec14 }
+ $sequence_3 = { 740c c7042400000000 e8???????? c70424???????? e8???????? }
+ $sequence_4 = { e8???????? a3???????? c7042440000000 e8???????? }
+ $sequence_5 = { c70424d0070000 e8???????? e9???????? e8???????? }
+ $sequence_6 = { c744241000000000 c744240c00000000 c744240800000000 c744240400000000 c7042408000000 e8???????? 83ec14 }
+ $sequence_7 = { c744242c00000000 c744242800000000 c744242400000000 c7442420fdffffff c744241c00000000 c744241800000000 }
+ $sequence_8 = { c7042400000000 e8???????? c70424???????? e8???????? }
+ $sequence_9 = { e8???????? eb11 c7042496000000 e8???????? }
condition:
- 7 of them and filesize <422912
+ 7 of them and filesize <416768
}
-rule MALPEDIA_Win_Nettraveler_Auto : FILE
+rule MALPEDIA_Win_Ramsay_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "494d7b5b-e566-59c9-b0c7-fe620930e93d"
+ id = "419ecbad-236d-5c68-9c96-e25af72dd2b4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nettraveler"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nettraveler_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ramsay"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ramsay_auto.yar#L1-L167"
license_url = "N/A"
- logic_hash = "ca8cfc3fd83dc1a9e063f01d8d61d4c33014172373ecd89db27946ab9125b077"
+ logic_hash = "eb3826746ddecabb3a90d33f9a9bdc63a3e0601a54105640bc672d97b2815450"
score = 75
quality = 75
tags = "FILE"
@@ -160229,34 +167293,40 @@ rule MALPEDIA_Win_Nettraveler_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd3 c70424???????? ff7508 a3???????? }
- $sequence_1 = { 81ec8c000000 56 57 ff7508 8bf1 e8???????? 8bf8 }
- $sequence_2 = { 83650800 83c70c 83c428 85ff 897df0 0f8eb6000000 bf00040000 }
- $sequence_3 = { 53 68???????? ffd6 80a5dcf7ffff00 59 59 baff000000 }
- $sequence_4 = { 0bdf 33da 035dc4 8d9c18827e53f7 8bc3 c1e81a c1e306 }
- $sequence_5 = { 0bd7 8b7dfc 0355e4 8dbc178a4c2a8d 8bd7 c1e214 c1ef0c }
- $sequence_6 = { ff750c ff75d4 50 e8???????? 83c414 8945ec }
- $sequence_7 = { e8???????? 83c418 8d45fc 897dfc 50 }
- $sequence_8 = { ffd7 8945fc 8d4308 50 ffd7 8065e400 }
- $sequence_9 = { 33df 035dc0 8d9c1992cc0c8f 8bcb c1e30a c1e916 0bcb }
+ $sequence_0 = { 85c0 7514 ff15???????? 83f820 }
+ $sequence_1 = { 83f820 7502 eb07 33c0 e9???????? }
+ $sequence_2 = { ff15???????? 85c0 7502 eb02 ebb1 }
+ $sequence_3 = { 83c201 8955f8 837df808 731e 8b45f8 }
+ $sequence_4 = { 894df1 884df5 c745ec00000000 6a06 8d55f0 52 }
+ $sequence_5 = { 83c404 8945f8 8b4d08 83c101 51 6a00 8b55f8 }
+ $sequence_6 = { 8b02 ba02000000 f7e2 0f90c1 f7d9 }
+ $sequence_7 = { 8945f8 837df8ff 7507 33c0 e9???????? 6a00 8b4df8 }
+ $sequence_8 = { 8a481c 884a15 8b5508 8b4508 }
+ $sequence_9 = { 3b4d08 732c e8???????? 33d2 b93e000000 }
+ $sequence_10 = { ff15???????? 85c0 751a 8b4df8 51 }
+ $sequence_11 = { ff15???????? 33c0 e9???????? e8???????? 85c0 7507 33c0 }
+ $sequence_12 = { e8???????? eb2b 83f8ff 7526 4c8d253b490100 }
+ $sequence_13 = { e8???????? eb20 488d542470 488d0d1afa0100 e8???????? 4533c0 33d2 }
+ $sequence_14 = { e8???????? eb2d 4863442468 488b4c2458 }
+ $sequence_15 = { e8???????? eb31 488b8c2428110000 e8???????? }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <2031616
}
-rule MALPEDIA_Win_Virlock_Auto : FILE
+rule MALPEDIA_Win_Oceansalt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a53ad870-36e8-5483-a3c7-250260a5d06b"
+ id = "4759a01e-4dff-5857-b87f-609205da91fe"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.virlock"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.virlock_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.oceansalt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.oceansalt_auto.yar#L1-L173"
license_url = "N/A"
- logic_hash = "2251c81b77f733b642183ccf22ad3a25fb0df2e83278219ff44fcff0baf92b0d"
+ logic_hash = "5f4a1382e32af57ddc08356072f34b4511a1cb8b2d1541817fa2debd46a6df75"
score = 75
- quality = 69
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -160268,32 +167338,38 @@ rule MALPEDIA_Win_Virlock_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? e8???????? ff15???????? 61 3bcb 7532 60 }
- $sequence_1 = { 9d cde6 81b4e570805c4af32b0cf0 e602 a4 b592 9c }
- $sequence_2 = { 68???????? eb0a 68???????? 68???????? e8???????? 83fa00 751b }
- $sequence_3 = { 81f2???????? 81f35e473bfc 81f308f661fc 81f37dc97000 e8???????? bb8aedf4f9 baf2edecff }
- $sequence_4 = { 45 58 58 46 54 4f 53 }
- $sequence_5 = { eb07 3106 83c604 ebea 83f901 754a }
- $sequence_6 = { 42 4b 4e 53 47 4b 56 }
- $sequence_7 = { 44 56 53 49 4f 45 }
- $sequence_8 = { 8bf8 90 e9???????? 8807 90 42 90 }
- $sequence_9 = { bb53203dfd 3106 83c604 bb975ea4f7 ebb5 83f901 }
+ $sequence_0 = { ff15???????? 6a00 6a02 83f81f }
+ $sequence_1 = { 8d95fcfbffff 6800020000 52 e8???????? 83c410 8d85ecfbffff }
+ $sequence_2 = { 8d85f4feffff 50 56 ffd7 6a00 }
+ $sequence_3 = { 6a00 52 c685fcfbffff00 e8???????? }
+ $sequence_4 = { 8b7508 33c0 50 8945f5 668945f9 8845fb 6a07 }
+ $sequence_5 = { 8945fc 56 57 6a00 6a02 c785ccfdffff28010000 e8???????? }
+ $sequence_6 = { 6a0d 58 5d c3 8b04cd2cf04000 }
+ $sequence_7 = { 56 c645f400 ff15???????? 6a00 6a07 8d4df4 }
+ $sequence_8 = { 4885c0 7419 488d1573750000 488bc8 ff15???????? }
+ $sequence_9 = { b903000000 f3a6 0f8463010000 33c9 0fb6840c8c000000 }
+ $sequence_10 = { 33d2 41b82a010000 6689442440 e8???????? ff15???????? 8be8 }
+ $sequence_11 = { 33c0 e9???????? 48895c2408 4c63c1 488d1d1d890000 4d8bc8 }
+ $sequence_12 = { 0f85d0000000 488d0d6b380000 ff15???????? 488bf0 4885c0 0f848c010000 }
+ $sequence_13 = { 488bc8 c744242800000008 c744242003000000 ff15???????? 488bd8 4883f8ff }
+ $sequence_14 = { f3a6 749a 488d8c24b0030000 33d2 41b868010000 e8???????? }
+ $sequence_15 = { 488d3d94700000 eb0e 488b03 4885c0 7402 ffd0 4883c308 }
condition:
- 7 of them and filesize <4202496
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Diceloader_Auto : FILE
+rule MALPEDIA_Win_Joao_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "29011295-3bc8-5840-8c7d-e823af0d9069"
+ id = "d37cc5ea-3d73-5336-a732-17564803dcb9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.diceloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.diceloader_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.joao"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.joao_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "3c776f38a1a79f5ecd47a0499d8c206a83999319aa99b844edf38b2b9ae751b8"
+ logic_hash = "86dd7ba6af2ece0f6d3df07328920c1e2520bb8d3e325d921ed8a0a42914959d"
score = 75
quality = 75
tags = "FILE"
@@ -160307,32 +167383,32 @@ rule MALPEDIA_Win_Diceloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7419 e8???????? 8bf0 83f8fe 0f840a010000 83f8ff }
- $sequence_1 = { 75cf 488325????????00 488d0d3a220000 448905???????? c705????????01000000 ff15???????? 488325????????00 }
- $sequence_2 = { 75e5 448d4301 41b9983a0000 488d1daa2a0000 8bcf 488bd3 ff15???????? }
- $sequence_3 = { 8b0491 4903c5 498907 33c9 eb2a }
- $sequence_4 = { 498b7318 498be3 5f c3 4053 4883ec20 33db }
- $sequence_5 = { 7453 33d2 458d460e 488d4c2420 e8???????? 0fb7ce }
- $sequence_6 = { 8bf0 83f8fe 0f840a010000 83f8ff 0f8406010000 4533ff 3bf3 }
- $sequence_7 = { 4c8d4820 ba05000000 44894024 448bc1 c740e808000000 8d4afe e8???????? }
- $sequence_8 = { e8???????? 498bd5 488d0dea1f0000 e8???????? }
- $sequence_9 = { 8d4860 e8???????? 488bcd 488bf8 895808 }
+ $sequence_0 = { 8bce 897dfc e8???????? 837de810 c745fcffffffff 720c 8b45d4 }
+ $sequence_1 = { 8b4e08 2b0e c1f905 3bc8 }
+ $sequence_2 = { 8d4dd0 51 8bce 897dfc e8???????? }
+ $sequence_3 = { 50 6a0f 68???????? e8???????? 8b5510 8d8df8feffff }
+ $sequence_4 = { 8b4804 8b4c3138 c645ef01 4b }
+ $sequence_5 = { 8d45f8 50 8bce c745f809000000 897dfc e8???????? 8d4df8 }
+ $sequence_6 = { e8???????? 8b4604 83e7e0 033e }
+ $sequence_7 = { 8b4c3224 8b443220 c645fc03 85c9 7c15 7f04 }
+ $sequence_8 = { 8d4dd4 e8???????? 8d4dd0 51 8bce 897dfc e8???????? }
+ $sequence_9 = { 8b4e08 2b0e c1f905 3bc8 736a 8d7e0c 50 }
condition:
- 7 of them and filesize <41984
+ 7 of them and filesize <2867200
}
-rule MALPEDIA_Elf_Satori_Auto : FILE
+rule MALPEDIA_Win_Lazarus_Killdisk_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ef9a3def-11bf-57c1-9abe-eaf3ea87bbf4"
+ id = "37962373-db6b-5a82-a667-796eaa294f65"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.satori"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.satori_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lazarus_killdisk"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lazarus_killdisk_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "acc91f43f84cb8d9ebcbacb4d453867e5ba0d238d6255f05df970cd0ecb540bb"
+ logic_hash = "f14584aa2cdb4f56b5df407c3c19c0436c1677938983b3e7a6f77f9ce3d89a22"
score = 75
quality = 75
tags = "FILE"
@@ -160346,32 +167422,32 @@ rule MALPEDIA_Elf_Satori_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7804 8b542414 89d0 83c41c }
- $sequence_1 = { e8???????? b9???????? b802000000 89ca e8???????? }
- $sequence_2 = { 89c6 53 89d3 83ec10 52 e8???????? }
- $sequence_3 = { b802000000 e8???????? b905000000 ba???????? b802000000 e8???????? b908000000 }
- $sequence_4 = { c744244800000000 e9???????? 8b542404 8b3482 6bc018 03442464 }
- $sequence_5 = { e8???????? 83c414 6a1f e8???????? c7042420000000 e8???????? c785280400001e000000 }
- $sequence_6 = { 85c0 7416 83ec0c ff35???????? e8???????? 59 6a00 }
- $sequence_7 = { 3b410c 747c 8b45bc 83ec0c 8b55cc 8d5def 8945e0 }
- $sequence_8 = { 6a04 56 53 e8???????? 8844243a 83c420 6a00 }
- $sequence_9 = { 6a15 68???????? 6a1d e8???????? 83c40c 6a15 68???????? }
+ $sequence_0 = { 8b530c 8b4308 33c9 8d4402ff 0fa4c109 }
+ $sequence_1 = { e8???????? 83c40c 57 8d4c242c }
+ $sequence_2 = { 8bf0 83feff 740e 8bce e8???????? 56 }
+ $sequence_3 = { 6a00 6800000002 ffd3 8bf0 83feff 7409 6a00 }
+ $sequence_4 = { 7438 8d55f0 52 68???????? }
+ $sequence_5 = { 89842430020000 53 56 57 e8???????? 8b1d???????? 33ff }
+ $sequence_6 = { 68???????? 57 ff15???????? 8b45a2 8b4da6 8b55ae }
+ $sequence_7 = { 8d95c0fdffff c1e009 52 50 57 }
+ $sequence_8 = { 40 83c610 8985e4fdffff 83f804 }
+ $sequence_9 = { 8d5de8 8955ec 894df4 8945f0 e8???????? 807db600 }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <209920
}
-rule MALPEDIA_Win_Synflooder_Auto : FILE
+rule MALPEDIA_Win_Ehdevel_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "355e06d2-d319-5e82-9247-ae8f46ddbac0"
+ id = "df8239a0-64d7-5d90-a037-26c4b02b8a9b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.synflooder"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.synflooder_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ehdevel"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ehdevel_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "95bdce90d0fd23dc18864dd54db497d62acdb308355c11b707eb697b526800c1"
+ logic_hash = "959b6347dd7f394fa1dd74e2d5d70bd613b6731b1cc6dbc8f1a7abb3467a3ebd"
score = 75
quality = 75
tags = "FILE"
@@ -160385,32 +167461,32 @@ rule MALPEDIA_Win_Synflooder_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff35???????? ff15???????? 85c0 7442 8b7df4 85ff }
- $sequence_1 = { 83e61f 8d3c8520fc4000 8b07 c1e606 }
- $sequence_2 = { 750b 56 e8???????? 59 85c0 7407 }
- $sequence_3 = { e8???????? 83c408 8b542420 52 68???????? e8???????? }
- $sequence_4 = { 53 56 57 7408 33c0 40 e9???????? }
- $sequence_5 = { c7465c20b04000 83660800 33ff 47 }
- $sequence_6 = { 55 8bec 81ec98050000 a1???????? 33c5 8945fc 8d8568faffff }
- $sequence_7 = { 8bf0 89742414 83feff 7524 68???????? e8???????? 83c404 }
- $sequence_8 = { ff15???????? 83f8ff 7524 68???????? e8???????? 83c404 }
- $sequence_9 = { 33db 85db 7466 8d45f4 50 ff75f8 53 }
+ $sequence_0 = { 51 e8???????? e9???????? 33d2 68fe070000 52 8d85feefffff }
+ $sequence_1 = { 7545 56 c70303000000 ff15???????? 56 ff15???????? 68???????? }
+ $sequence_2 = { 8d8dcce7ffff 51 6a00 6813000020 56 c785cce7ffff00000000 c785c8e7ffff04000000 }
+ $sequence_3 = { 8d85f0e7ffff 50 56 6a00 6a10 6a02 ff15???????? }
+ $sequence_4 = { e8???????? 83c404 33c9 6a08 b8???????? }
+ $sequence_5 = { 8d8dd4e5ffff 51 8d95f8f7ffff 6800040000 52 e8???????? }
+ $sequence_6 = { 83c410 8b4d0c 8d442408 50 51 }
+ $sequence_7 = { 83d8ff 85c0 0f84cffdffff 68???????? 6800040000 57 e8???????? }
+ $sequence_8 = { 50 e8???????? 8d8c24d4190000 51 8d9424d8010000 6800040000 52 }
+ $sequence_9 = { 8db564f7ffff e8???????? 33d2 899de8f7ffff 89bde4f7ffff 668995d4f7ffff 33c0 }
condition:
- 7 of them and filesize <163840
+ 7 of them and filesize <524288
}
-rule MALPEDIA_Win_Waterspout_Auto : FILE
+rule MALPEDIA_Win_Spyeye_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "966cd02d-f7ac-590a-a30e-6be6c0215ec6"
+ id = "4b228779-0f96-5a8e-b676-8a6d855d1452"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.waterspout"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.waterspout_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spyeye"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spyeye_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "791d1c9b538b0f8a628f6a3764a4be7336ff1d48478e7334334b2fc3c8924313"
+ logic_hash = "54f45a6b713b51a15663c9347e916cec35361fbd1f12608b97d32ef9d0a49fb7"
score = 75
quality = 75
tags = "FILE"
@@ -160424,34 +167500,34 @@ rule MALPEDIA_Win_Waterspout_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { fec8 53 8841ff 8d4c2418 ff15???????? eb3a 3bf3 }
- $sequence_1 = { c684243a01000023 c684243b0100003d c684243c010000ee c684243d0100004c c684243e01000095 c684243f0100000b c684244001000042 }
- $sequence_2 = { 8d4c244c 68???????? 51 ff15???????? 8d7c2454 83c9ff 33c0 }
- $sequence_3 = { 51 52 ff15???????? 85c0 7415 a1???????? 3bc3 }
- $sequence_4 = { 50 8b842410200000 51 52 68???????? 50 }
- $sequence_5 = { 6a00 a4 ff15???????? 50 ff15???????? 8b742460 }
- $sequence_6 = { 0f84aa000000 6a00 56 55 }
- $sequence_7 = { 8d542414 51 52 ffd6 83f801 74db 5f }
- $sequence_8 = { a3???????? 8b442428 68???????? 6a00 6a6b }
- $sequence_9 = { 33c0 8dbdfcfeffff 85f6 f3ab 7511 8d85fcfeffff 50 }
+ $sequence_0 = { 8d4de8 51 8d4de0 51 50 e8???????? 85c0 }
+ $sequence_1 = { 6a07 6800000040 57 e8???????? 8bf8 83ffff }
+ $sequence_2 = { 6889000000 ff7508 33db 897df8 }
+ $sequence_3 = { 57 6800000002 6a03 57 6a01 56 }
+ $sequence_4 = { 56 6880000000 6a02 eb08 56 6880000000 6a04 }
+ $sequence_5 = { 85c0 7407 c745f801000000 397dfc 740e }
+ $sequence_6 = { be80000000 56 6a03 57 6a01 6889000000 ff7508 }
+ $sequence_7 = { 53 e8???????? 85c0 7407 c745f801000000 397dfc 740e }
+ $sequence_8 = { 8965fc ff7510 ff750c ff7508 ffd0 8b65fc }
+ $sequence_9 = { 7454 57 56 6a03 }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <741376
}
-rule MALPEDIA_Win_Bazarbackdoor_Auto : FILE
+rule MALPEDIA_Win_Sysget_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5d2ecc0c-54dd-5654-9202-132113260f24"
+ id = "950c6328-1de5-5d85-b009-d36eceeda441"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bazarbackdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bazarbackdoor_auto.yar#L1-L638"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sysget"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sysget_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "bfaa99dbae5ad02f0954740ed30f16e2a148a8070db46fd5f787ce6fb0204c77"
+ logic_hash = "98d11ad376be93c301b2c1f8309ca9e93b58254eeadefcb865a1a57e18934a28"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -160463,100 +167539,32 @@ rule MALPEDIA_Win_Bazarbackdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488bce 4889442420 ff15???????? 85c0 780a }
- $sequence_1 = { 488bce ffd0 eb03 488bc3 }
- $sequence_2 = { b803000000 e9???????? 488b5568 4c8d85f0040000 488b4c2450 bb08000000 }
- $sequence_3 = { e9???????? 488b4c2458 488d55e0 ff15???????? }
- $sequence_4 = { 4533c0 c744242002000000 ba00000040 ffd0 }
- $sequence_5 = { 0fb70f ff15???????? 0fb74f02 0fb7d8 ff15???????? }
- $sequence_6 = { 488d4d80 e8???????? 498bd6 488d4d80 }
- $sequence_7 = { 7507 33c0 e9???????? b8ff000000 }
- $sequence_8 = { 0fb7d8 ff15???????? 0fb74f08 440fb7e8 }
- $sequence_9 = { 4885c9 7406 488b11 ff5210 ff15???????? }
- $sequence_10 = { e8???????? cc e8???????? cc 4053 4883ec20 b902000000 }
- $sequence_11 = { c3 0fb74c0818 b80b010000 663bc8 }
- $sequence_12 = { e8???????? 4c89e1 e8???????? 8b05???????? }
- $sequence_13 = { 4533c9 4889442428 488d95a0070000 488d442470 41b80f100000 }
- $sequence_14 = { 0fb6c9 4881e9c0000000 48c1e108 4803c8 8bc1 488d94059f070000 }
- $sequence_15 = { 31ff 4889c1 31d2 4989f0 }
- $sequence_16 = { 4889f1 e8???????? 8b05???????? 8b0d???????? }
- $sequence_17 = { 4c89742440 4c89742438 4489742430 4c89742428 }
- $sequence_18 = { ff15???????? 4889c1 31d2 4d89e0 }
- $sequence_19 = { 418d5508 488bc8 ff15???????? 488bd8 }
- $sequence_20 = { e8???????? 4889c7 8b05???????? 8b0d???????? }
- $sequence_21 = { 488d9590050000 488bce ff15???????? 85c0 }
- $sequence_22 = { 488d442470 41b80f100000 488bce 4889442420 }
- $sequence_23 = { ff15???????? ff15???????? 4d8bc5 33d2 488bc8 }
- $sequence_24 = { 0fafc8 89c8 83f0fe 85c8 0f95c0 0f94c3 }
- $sequence_25 = { c744242003000000 4889f9 ba00000080 41b801000000 }
- $sequence_26 = { c744242800000001 4533c9 4533c0 c744242002000000 ba1f000f00 }
- $sequence_27 = { 83fe09 0f9fc2 83fe0a 0f9cc1 }
- $sequence_28 = { 4889442428 488d95b0030000 488d4580 41b80f100000 }
- $sequence_29 = { 4d8bc7 33d2 488bc8 ff15???????? ff15???????? }
- $sequence_30 = { 08ca 80f201 7502 ebfe }
- $sequence_31 = { 48c744243000000000 c744242880000000 c744242003000000 4889f9 }
- $sequence_32 = { 0f94c3 83f809 0f9fc2 83f80a 0f9cc0 30d8 }
- $sequence_33 = { 0fb65305 33c0 80f973 0f94c0 }
- $sequence_34 = { 0f9fc1 83fa0a 0f9cc2 30da 08c1 80f101 08d1 }
- $sequence_35 = { 7528 0fb64b04 0fb6d1 80f973 }
- $sequence_36 = { 4889c1 31d2 4989f8 ff15???????? 4885c0 }
- $sequence_37 = { ff15???????? 31ed 4889c1 31d2 4989d8 }
- $sequence_38 = { 488bd3 e8???????? ff15???????? 4c8bc3 33d2 }
- $sequence_39 = { 0fb6d1 80f973 7504 0fb65305 }
- $sequence_40 = { 08c1 80f101 7502 ebfe }
- $sequence_41 = { e8???????? 4889f9 4889f2 ffd0 }
- $sequence_42 = { 0f9cc2 30da 7509 08c1 }
- $sequence_43 = { 85da 0f94c3 83fd0a 0f9cc2 }
- $sequence_44 = { 84d2 7405 80fa2e 750f }
- $sequence_45 = { 4889c1 31d2 4d89e8 ff15???????? }
- $sequence_46 = { 4889c1 31d2 4d89f8 ffd3 }
- $sequence_47 = { e8???????? 4c897c2420 4889d9 89fa }
- $sequence_48 = { 89f0 4883c450 5b 5f }
- $sequence_49 = { 8d4833 ff15???????? c744242810000000 4533c9 }
- $sequence_50 = { 6a00 56 ff15???????? 5f 5e 5d 8bc3 }
- $sequence_51 = { 689c7d9d93 6a04 5a e8???????? 59 59 85c0 }
- $sequence_52 = { 8d44244c 50 6a00 ff74243c 53 55 ff15???????? }
- $sequence_53 = { 6685ff 0f849c000000 837c2460ff 0f858c000000 }
- $sequence_54 = { 50 0fb745e8 50 68???????? e8???????? }
- $sequence_55 = { 66890d???????? 0fb7ca ff15???????? b901000000 66c746020100 668906 }
- $sequence_56 = { 7506 8b0e 894c2460 0fb7c0 }
- $sequence_57 = { 8a842483030000 81fe80000000 760b 24f2 0c02 }
- $sequence_58 = { 57 8d4101 6a0e 8bf0 5f 8a11 }
- $sequence_59 = { 7406 6a35 ffd0 eb02 33c0 }
- $sequence_60 = { ffd6 8d7001 56 6a08 ff15???????? 50 }
- $sequence_61 = { 740d 33d2 83f902 0f95c2 83c224 }
- $sequence_62 = { 0f95c2 83c224 eb05 ba29000000 }
- $sequence_63 = { 660f73d801 660febd0 660f7ed0 84c0 }
- $sequence_64 = { 750b 8ac1 2ac2 fec8 88041a }
- $sequence_65 = { 8d4701 84c9 0f45c7 803a00 8bf8 }
- $sequence_66 = { 6a00 6a00 50 8d4601 }
- $sequence_67 = { c1f808 0fb6c0 50 0fb6c2 }
- $sequence_68 = { 83c410 b800308804 6a00 50 }
- $sequence_69 = { 81feff030000 733c 8a02 3cc0 721e 0fb6c8 }
- $sequence_70 = { 89542410 48894c2408 4883ec48 8b442458 89442424 48c744242800000000 }
- $sequence_71 = { 488b442430 488b8c2410010000 48894830 488b442430 488b8c2418010000 48894838 488b442430 }
- $sequence_72 = { 488bca 448bc0 488bd1 488b4c2430 e8???????? 488b442428 }
- $sequence_73 = { ff15???????? 33c0 eb47 488b442430 8b4014 }
- $sequence_74 = { 4825ffff0000 488b8c2488000000 4c8b4140 488bd0 }
- $sequence_75 = { 488b442430 48c7404800000000 488b442430 eb14 }
- $sequence_76 = { eb1f 488b442430 8b4024 2580000000 }
- $sequence_77 = { 488b442458 488b00 b908000000 486bc909 488d840888000000 4889442428 488b442428 }
+ $sequence_0 = { 56 6a20 8d45cc 50 53 53 }
+ $sequence_1 = { f3a5 33f6 8d4435f0 8a08 f6d1 80f15f }
+ $sequence_2 = { 58 6a00 ff15???????? 6a01 8d85ecf9ffff 50 8d85ecf1ffff }
+ $sequence_3 = { 8985c8f9ffff 83c032 50 66a5 e8???????? 83c428 }
+ $sequence_4 = { 33f6 8d4435f0 8a08 f6d1 80f15f 46 }
+ $sequence_5 = { 75f5 8dbdecfeffff 2bc2 83ef02 668b4f02 83c702 6685c9 }
+ $sequence_6 = { 83c424 6800010000 ffb5f8feffff c1e306 8d841dfcfeffff 50 ff15???????? }
+ $sequence_7 = { 6a50 68???????? 50 ff15???????? a3???????? a1???????? }
+ $sequence_8 = { 51 ff36 897d0c 50 53 }
+ $sequence_9 = { 8d459c 50 56 56 6a20 53 }
condition:
- 7 of them and filesize <2088960
+ 7 of them and filesize <352256
}
-rule MALPEDIA_Win_Avcrypt_Auto : FILE
+rule MALPEDIA_Win_Xdspy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f0c2c6c6-0e09-5b4b-89b9-13d38222f492"
+ id = "770ce833-e4ad-5e91-a2e8-e19a8fcb8719"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avcrypt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avcrypt_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xdspy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xdspy_auto.yar#L1-L167"
license_url = "N/A"
- logic_hash = "ac05395b3ceaf430ebcb56d0def5da87a92c07f9636a33b891b2fc3647618543"
+ logic_hash = "f9c3ada66244c45df3d3dc2c6a2b3ef1f7e34e7bdca43fe98eeac2240819a0e8"
score = 75
quality = 75
tags = "FILE"
@@ -160570,71 +167578,77 @@ rule MALPEDIA_Win_Avcrypt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? ffd3 834dfcff 8d4dd8 56 6a01 e8???????? }
- $sequence_1 = { 8bc7 8bcf c1f805 83e11f c1e106 030c8580b54300 eb05 }
- $sequence_2 = { 8d4dc0 56 e8???????? 59 6a0e 33f6 5b }
- $sequence_3 = { c705????????70484300 c705????????8cbf4300 890d???????? 8935???????? }
- $sequence_4 = { 50 ff15???????? 83c8ff e9???????? 57 6a09 59 }
- $sequence_5 = { ff15???????? 85c0 7507 68???????? ffd6 895de4 837dd000 }
- $sequence_6 = { 68???????? e8???????? 83ec18 c745fc15000000 8bcc 8965d4 53 }
- $sequence_7 = { c645fc0e 837db800 7519 68???????? 8d8d78ffffff e8???????? }
- $sequence_8 = { e8???????? 68???????? 8d8d84feffff c645fc08 e8???????? 68???????? 8d8d9cfeffff }
- $sequence_9 = { e8???????? c645fc01 8b5de0 85db 7404 8b13 }
+ $sequence_0 = { 8d45ec 50 ff35???????? e8???????? 83f8ff }
+ $sequence_1 = { ffb56cd8ffff 8d8570d8ffff 6800040000 6a01 50 e8???????? }
+ $sequence_2 = { 8b36 8bce c1f905 8b0c8d804e4100 }
+ $sequence_3 = { ff7580 8b3d???????? ffd7 8d4580 50 68???????? 56 }
+ $sequence_4 = { 8d45e0 50 57 8d85e02a0000 50 ff75dc ffd3 }
+ $sequence_5 = { 83c414 83c8ff e9???????? 8bc6 c1f805 57 8d3c85804e4100 }
+ $sequence_6 = { 8b4de0 8d0c8d804e4100 8901 8305????????20 }
+ $sequence_7 = { 8d8510ecffff 57 50 e8???????? ffb56cd8ffff }
+ $sequence_8 = { 0f1f4000 660f1f840000000000 420fb68431309b1700 88840db0080000 488d4901 }
+ $sequence_9 = { 488b15???????? 488d8da0080000 ffd0 660f6f0d???????? 488d3550331700 }
+ $sequence_10 = { c705????????67736666 c705????????6e747764 c705????????73752f65 66c705????????6d6d 488d1563121700 }
+ $sequence_11 = { 488d4901 84c0 75e8 80bd400c000000 488d85400c0000 7413 }
+ $sequence_12 = { 4883f860 7ccf 488d15f85c1700 488d0d41e60100 4c8d0552e60100 }
+ $sequence_13 = { fe08 488d4001 803800 75f5 488d8db0080000 ff15???????? }
+ $sequence_14 = { 83f9ff 0f8496010000 ba01000000 448d420f }
+ $sequence_15 = { 33c9 ff15???????? 48898424a8000000 660f6f05???????? }
condition:
- 7 of them and filesize <6160384
+ 7 of them and filesize <3244032
}
-rule MALPEDIA_Win_Hermes_Ransom_Auto : FILE
+rule MALPEDIA_Win_Combos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "88136c82-87ab-5f89-8963-9afb9534a540"
- date = "2021-10-07"
- modified = "2021-10-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hermes_ransom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hermes_ransom_auto.yar#L1-L125"
+ id = "1f17e5a0-ef31-5686-bb42-b8b65987952e"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.combos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.combos_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "2bb9637b7e3ee9fcdd4e957eade001e8c8132e1b7c987ea6727ab44eda025915"
+ logic_hash = "037e9ec47814518fd1ef388425768f46eed22a270b66cf4ee1793ac0871a3237"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20211007"
- malpedia_hash = "e5b790e0f888f252d49063a1251ca60ec2832535"
- malpedia_version = "20211008"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 59 59 8945e0 837ddc00 7506 837de000 7405 }
- $sequence_1 = { 8d45dc 50 ff75d8 8d8560ffffff 50 ff75e0 ff15???????? }
- $sequence_2 = { 33c0 668945e2 33c0 8945e4 8945e8 837df020 }
- $sequence_3 = { 6a00 8d85a4f9ffff 50 ff15???????? 5f 5e 8be5 }
- $sequence_4 = { 0fb7844504f7ffff 83f83b 741f 8b45d8 8b4df0 668b8c4d04f7ffff }
- $sequence_5 = { 8365c800 8365d000 c745b840420f00 8365e000 eb07 8b45e0 40 }
- $sequence_6 = { 59 6bc900 668981e8c34000 6a02 }
- $sequence_7 = { 59 59 6a0f 6a00 8d45bc 50 }
- $sequence_8 = { 8365f000 8b45f0 8945f8 837df800 7456 }
- $sequence_9 = { 83e002 7415 ff750c ff75fc e8???????? 59 }
+ $sequence_0 = { 57 68ffff1f00 8d45e4 50 }
+ $sequence_1 = { be???????? 8b4c2410 8bfb 8bc1 6a01 c1e902 f3a5 }
+ $sequence_2 = { 57 57 53 56 8b8dd8feffff }
+ $sequence_3 = { 89bdd4feffff 897dfc 8b4508 50 }
+ $sequence_4 = { 8d054c160110 83780800 754e b741 b35a b620 }
+ $sequence_5 = { 53 8d44240c 55 56 89442410 57 c744241000000000 }
+ $sequence_6 = { 740e 50 ff15???????? 830d????????ff c3 8b442404 c74050b0110110 }
+ $sequence_7 = { 7514 8b442408 8b4c2410 5e }
+ $sequence_8 = { 0bc5 33c1 8b848600ffffff 0bc7 5f 5e 5d }
+ $sequence_9 = { 83ec08 55 56 8b742414 85f6 0f8412010000 }
condition:
- 7 of them and filesize <7192576
+ 7 of them and filesize <163840
}
-rule MALPEDIA_Win_Strelastealer_Auto : FILE
+rule MALPEDIA_Win_Phoreal_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "308b6312-f55e-5e44-8b26-8341d0a5504a"
+ id = "edae0032-d1e1-5b3c-8d3f-ebef8f58d4b7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.strelastealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.strelastealer_auto.yar#L1-L169"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phoreal"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.phoreal_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "4a18fbcab2ec145e1ed1c3a8aa2118c83ff2631df0db61e9cbe03afa397c02a3"
+ logic_hash = "d8f5fe4e88399cfa18864e41db820daba4b617ffb107b587cb04424a8ab682db"
score = 75
quality = 75
tags = "FILE"
@@ -160648,38 +167662,32 @@ rule MALPEDIA_Win_Strelastealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f85e6030000 6804010000 8d942464010000 53 52 e8???????? }
- $sequence_1 = { ff15???????? 8b442434 8b4c2438 53 }
- $sequence_2 = { 488945f0 488d15d8a20000 b805000000 894520 }
- $sequence_3 = { 885909 b801000000 83c404 51 0fb69220a30010 3011 33d2 }
- $sequence_4 = { ff15???????? 33c9 8be8 85db 7612 8bc1 }
- $sequence_5 = { 48895c2408 4889742410 57 4c8bd2 488d351b43ffff }
- $sequence_6 = { 488d442478 33d2 4889442430 c744242801000000 4c897c2420 }
- $sequence_7 = { 488d15eba10000 488d0dc4a10000 e8???????? 488d15e8a10000 488d0dd9a10000 }
- $sequence_8 = { 0f85bc030000 8b442414 53 53 53 53 8d54244c }
- $sequence_9 = { 740d 488bc8 49878cff20ac0100 eb0a 4d87b4ff20ac0100 33c0 }
- $sequence_10 = { 4c8d05c7680100 c744243000020080 488d1548690100 48897c2428 4533c9 }
- $sequence_11 = { 53 4883ec20 488d057f740000 488bd9 483bc8 7418 }
- $sequence_12 = { 488d3de6070100 eb07 488d3dc5070100 4533ed }
- $sequence_13 = { 51 6a00 6a00 6a1a 6a00 ff15???????? 68???????? }
- $sequence_14 = { 51 8d94247c040000 52 ff15???????? }
- $sequence_15 = { 8b4508 ff34c580b10010 ff15???????? 5d c3 6a0c }
+ $sequence_0 = { 8d4c2414 51 8b4b04 8d542410 52 8d442418 50 }
+ $sequence_1 = { 8b570c 8d442440 6a00 50 895350 }
+ $sequence_2 = { 56 57 33ff 8bf0 8d4701 }
+ $sequence_3 = { 75c4 8d8de4fdffff c645fc02 e8???????? bf10000000 397de4 720c }
+ $sequence_4 = { 8b54245c 51 8b4c245c 52 8b542458 51 48 }
+ $sequence_5 = { 03c3 83c9ff 2bc8 3bca }
+ $sequence_6 = { 8b7510 b90e000000 f3a5 5e 5f 8be5 5d }
+ $sequence_7 = { 6a01 6a00 6a00 51 50 ff15???????? 85c0 }
+ $sequence_8 = { 52 8d434e 50 8d434b 8d534d 8d4b4c 50 }
+ $sequence_9 = { 894de0 894de4 8b8d78fdffff 8d1447 51 52 }
condition:
- 7 of them and filesize <266240
+ 7 of them and filesize <622592
}
-rule MALPEDIA_Win_Common_Magic_Auto : FILE
+rule MALPEDIA_Win_Klrd_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "51a78d88-2ba4-5106-aa0c-c758f14020ef"
+ id = "f2ac53cd-82a8-55ea-badd-f6f1aae58f93"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.common_magic"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.common_magic_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.klrd"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.klrd_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "b14e276c951448d5c194fa4cd51d59dbec4eb8aa1757a9205bc8d8e9186ff3cd"
+ logic_hash = "0fc6f030ea4bb49d87359f96c6eceeeaeffbdd94bdee42030f76f2d7ec66a19a"
score = 75
quality = 75
tags = "FILE"
@@ -160693,32 +167701,32 @@ rule MALPEDIA_Win_Common_Magic_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d049d78824100 8b30 8945fc 90 }
- $sequence_1 = { 03c0 eb3c 8bd1 b8feffff7f d1ea 2bc2 }
- $sequence_2 = { c78578ffffff00000000 c7857cffffff00000000 8d9574ffffff c645fc09 8d8d84feffff }
- $sequence_3 = { 6689855cffffff b8feffff7f 2bc1 c7856cffffff00000000 c78570ffffff07000000 }
- $sequence_4 = { 33c9 8bc1 3914c5e84a4100 7408 }
- $sequence_5 = { c7459c65007800 c745a065000000 83f817 0f82140c0000 83bd58ffffff08 8d8544ffffff }
- $sequence_6 = { 51 50 51 ffb580feffff 8d8d5cffffff }
- $sequence_7 = { 51 ffb580feffff 8d8d5cffffff e8???????? 838d78feffff06 8d8de4feffff 83bdf8feffff08 }
- $sequence_8 = { 8b0c8570804100 8a043b 03ce 8b75dc 03cb 43 }
- $sequence_9 = { 2bc2 3bc8 760e b8ffffff7f befeffff7f 03c0 }
+ $sequence_0 = { 8d85fcefffff 50 e8???????? 59 50 }
+ $sequence_1 = { 8d85fcefffff 50 57 ff15???????? 57 ff15???????? }
+ $sequence_2 = { e8???????? 59 50 8d85fcefffff 50 57 }
+ $sequence_3 = { 3c00 0f8485020000 3c03 0f847d020000 3c09 0f8475020000 3c08 }
+ $sequence_4 = { c685c0fdffff00 68ff000000 6a00 8d85c1fdffff 50 e8???????? 83c40c }
+ $sequence_5 = { 59 59 ff7510 ff750c ff7508 ff35???????? ff15???????? }
+ $sequence_6 = { ebcc 8a85e7feffff 8885acfcffff 80bdacfcffff08 742f }
+ $sequence_7 = { 56 56 6a04 56 56 68000000c0 68???????? }
+ $sequence_8 = { 59 8d7dec f3a5 8b45ec 25ff000000 8885e7feffff 3c00 }
+ $sequence_9 = { ffb5b0fcffff ff15???????? 8985c8feffff 83bdc8feffff00 7515 ff15???????? }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Protonbot_Auto : FILE
+rule MALPEDIA_Win_Mocton_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b19d2c4d-3d72-5fe6-aaaa-c0b323237a91"
+ id = "72b425f0-e1bd-580c-ba97-36f1bcb1157c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.protonbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.protonbot_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mocton"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mocton_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "9f42d2358a0490651f249ec756eecbb8cc6207cec8ace7f179285ca0a209261c"
+ logic_hash = "f466c26ab0d8cd5071e2b5a32b6cc128a028215985bbf34b30810ffd494c9c82"
score = 75
quality = 75
tags = "FILE"
@@ -160732,32 +167740,32 @@ rule MALPEDIA_Win_Protonbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f434550 6a00 6a00 6a00 }
- $sequence_1 = { 8b36 8d442408 50 56 e8???????? 83c408 83f808 }
- $sequence_2 = { e8???????? 8d8dd4feffff e8???????? 83c418 c645fc01 }
- $sequence_3 = { 899df8fffeff e8???????? 83c410 8bf8 }
- $sequence_4 = { 8bf1 6a04 c745fc01000000 e8???????? 83c404 8bf8 }
- $sequence_5 = { 837f1410 7202 8b3f 57 50 e8???????? ffb5d4feffff }
- $sequence_6 = { 7f8d 5e 5f 33c0 5b 8b4dfc }
- $sequence_7 = { 50 8d45f4 64a300000000 8bda 8bf9 8d8dd8feffff }
- $sequence_8 = { 8d85b8fbffff 0f4385b8fbffff 50 8d85d0fbffff 68ff000000 50 e8???????? }
- $sequence_9 = { b901000000 8bc2 c1e81e 33c2 69d06589076c 03d1 89948d54ecffff }
+ $sequence_0 = { 8b4db8 81e1dbb036e4 33c8 334db8 8b55b8 83c201 8955b8 }
+ $sequence_1 = { 0b55d0 8b45d0 83e801 8945d0 85d2 741e 8b4dd0 }
+ $sequence_2 = { 898584feffff e9???????? 8b8d9cfeffff 83e901 898d9cfeffff 8b959cfeffff 8b859cfeffff }
+ $sequence_3 = { b901000000 85c9 741d 8b955ceaffff c1e206 81ca2bb0d5ca 03955ceaffff }
+ $sequence_4 = { 0b8dcce9ffff 898dcce9ffff e9???????? 8b95cce9ffff 69d237b0cb41 33c0 81fa237558e2 }
+ $sequence_5 = { 7353 8bc1 c1f805 8bf1 8d3c85004d4400 8b07 83e61f }
+ $sequence_6 = { 7e3e b8913b77ee 2b8508fdffff 398508fdffff 7c17 8b8d08fdffff c1e105 }
+ $sequence_7 = { 0f94c1 81c9efb286ac 7412 8b956cfcffff 039560fcffff 89956cfcffff c785acfcffffeed81864 }
+ $sequence_8 = { 894dec eb12 8b55f8 2b55ec 8955f8 8b45ec 83c001 }
+ $sequence_9 = { c1e009 05335b8425 2385e4e9ffff 0b85ece9ffff 8985ece9ffff 8b8de4e9ffff }
condition:
- 7 of them and filesize <1073152
+ 7 of them and filesize <573440
}
-rule MALPEDIA_Win_Juicy_Potato_Auto : FILE
+rule MALPEDIA_Win_Mulcom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "03dfaa0e-28b0-58bd-8b17-d8d3c88d86a7"
+ id = "8b428090-6e4d-587e-a305-32305b35e9f8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.juicy_potato"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.juicy_potato_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mulcom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mulcom_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "270473eb74e147cca3eabdeead641e5c572494e923c2e4deeae8d94ea8e99f5c"
+ logic_hash = "0fb6c90115244992995c28d6d59f0334f00cc1075a3607803abc8b37e1b5b55f"
score = 75
quality = 75
tags = "FILE"
@@ -160771,32 +167779,32 @@ rule MALPEDIA_Win_Juicy_Potato_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488b5010 498b4910 48ffc9 488bc2 48d1e8 4823c8 }
- $sequence_1 = { 4053 4883ec20 488bd9 488bc2 488d0dade40100 48890b 488d5308 }
- $sequence_2 = { 488d5e08 488b03 6683382d 0f8598010000 0fb74002 83c09f }
- $sequence_3 = { 4889450f 4883c8ff 488955ff 488bc8 }
- $sequence_4 = { 488bd7 4c8d05dec60300 83e23f 488bcf 48c1f906 48c1e206 498b0cc8 }
- $sequence_5 = { 48894728 4883f8ff 7437 448b4310 488b5320 488bc8 ff15???????? }
- $sequence_6 = { e8???????? ff15???????? b801000000 e9???????? 488b5c2438 4885db 7470 }
- $sequence_7 = { 488d15159c0100 ff15???????? 4885c0 0f8429030000 488bc8 e8???????? 488bcb }
- $sequence_8 = { 7509 488d056f200400 eb04 4883c024 8938 e8???????? 488d1d57200400 }
- $sequence_9 = { ff15???????? ba10000000 663bc2 7312 488bd3 488d0d6df80200 ff15???????? }
+ $sequence_0 = { 4883ec40 33ff 48c740f007000000 488978e8 488d4c2420 668978d8 4d85c0 }
+ $sequence_1 = { e8???????? 4c8b4310 488bd3 48837b1808 7203 488b13 4981f804010000 }
+ $sequence_2 = { e8???????? 488d4de8 e8???????? 488d4dc8 e8???????? 488d4da8 e8???????? }
+ $sequence_3 = { 48897020 488b05???????? 4833c4 48898510020000 498bf8 488bda 4889542438 }
+ $sequence_4 = { 33d2 33c9 458bc6 ff15???????? 85c0 0f8412020000 }
+ $sequence_5 = { e8???????? 488d4c2460 e8???????? 90 488dbea0000000 488d9580010000 }
+ $sequence_6 = { 4c897de0 488d45d0 48837de810 480f4345d0 448838 8b542440 483b55e0 }
+ $sequence_7 = { 4d63df 4c015d00 478d6c2fff eb3f 4585e4 7511 8b74243c }
+ $sequence_8 = { cc e8???????? cc 4c8bc2 488b5108 48395110 0f848b000000 }
+ $sequence_9 = { 410fb7d0 ff5018 440fb7c0 49ffce 418bff 66453be0 0f45fb }
condition:
- 7 of them and filesize <736256
+ 7 of them and filesize <867328
}
-rule MALPEDIA_Win_Mbrlock_Auto : FILE
+rule MALPEDIA_Win_Xxmm_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "daa9848d-eee7-57fa-b29b-86c1367b5691"
+ id = "2f4f20e9-d761-523e-a241-a1e4f366495b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mbrlock"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mbrlock_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xxmm"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xxmm_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "7a0dcc0e30832e7304006fa42a5eab963221d66f36bad91605b77fec2d75b555"
+ logic_hash = "0f663d162fed444e7f08fa4fe0acf57f92808d6dc37ba8437dff740dddaf561a"
score = 75
quality = 75
tags = "FILE"
@@ -160810,32 +167818,32 @@ rule MALPEDIA_Win_Mbrlock_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 898e94000000 8945e4 e9???????? 8b5d10 8b7d14 8b4e0c }
- $sequence_1 = { 8bcb bd01000000 e8???????? 8bf0 85f6 0f84f8000000 85ed }
- $sequence_2 = { 8b4de8 8bc1 25ffff0000 2d4c450000 7475 83e802 7433 }
- $sequence_3 = { e8???????? 8b45ec 3d00800000 74ab 8b450c 8d5594 }
- $sequence_4 = { 894e30 50 53 8bcf e8???????? 85c0 7505 }
- $sequence_5 = { e8???????? 8bd0 85d2 7424 817f1402000080 7519 8b470c }
- $sequence_6 = { 8bcf e8???????? 8b4d08 894144 8b45ec 85c0 7505 }
- $sequence_7 = { 33d2 8bd9 668b144590844a00 8b4c2430 8954242c 8bc1 be02000000 }
- $sequence_8 = { 68ac5e0110 56 50 53 8bcf e8???????? }
- $sequence_9 = { a3???????? 39a81c010000 7405 8b4010 eb02 33c0 ffd0 }
+ $sequence_0 = { 6a00 ff15???????? 53 57 50 8945fc e8???????? }
+ $sequence_1 = { 6a00 ff55ec ff7650 8bf8 }
+ $sequence_2 = { 8b7c0e20 8b440e24 03f9 03c1 }
+ $sequence_3 = { 897d10 3bdf 7673 8b4508 2bc6 }
+ $sequence_4 = { c3 55 8bec 51 51 8b03 8b08 }
+ $sequence_5 = { 0f84bc000000 397d10 0f84b3000000 3bf7 }
+ $sequence_6 = { 034df8 83c0f8 d1e8 8d7a08 897df4 7450 }
+ $sequence_7 = { 0fb74606 8945e8 85c0 7429 8b47f8 }
+ $sequence_8 = { 3b7114 7303 8bc6 c3 53 0fb75806 57 }
+ $sequence_9 = { 41 4a 75f7 8b5dfc 83c728 837de800 75d7 }
condition:
- 7 of them and filesize <2031616
+ 7 of them and filesize <540672
}
-rule MALPEDIA_Win_Pkybot_Auto : FILE
+rule MALPEDIA_Win_Glupteba_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b29148a6-8685-5645-99d4-ca854d32849e"
+ id = "09a70f19-6d2a-5533-851a-d46346a3f052"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pkybot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pkybot_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.glupteba"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.glupteba_auto.yar#L1-L163"
license_url = "N/A"
- logic_hash = "809773f54b9553ffea062fd7f87645abd3e261a3e38fb26640ff099fc49a005e"
+ logic_hash = "f2320a7d413271b6097cf4accf3d3e4465e91ebbc62274538ef55443d4833776"
score = 75
quality = 75
tags = "FILE"
@@ -160849,32 +167857,38 @@ rule MALPEDIA_Win_Pkybot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8bf8 83ffff 7429 56 56 }
- $sequence_1 = { 8d45e0 50 8b06 83c004 50 }
- $sequence_2 = { 8b4e04 21413c c741300e000000 897938 5f 5e }
- $sequence_3 = { 7409 ff75dc e8???????? 59 56 }
- $sequence_4 = { 8b0d???????? 894108 e8???????? a3???????? }
- $sequence_5 = { 7518 ff35???????? e8???????? 59 893d???????? 893d???????? }
- $sequence_6 = { 56 a3???????? e8???????? 83c448 }
- $sequence_7 = { 57 6a10 ff7510 8d45ec 50 e8???????? }
- $sequence_8 = { 7430 50 3bf7 7507 e8???????? eb05 e8???????? }
- $sequence_9 = { 8d85ecfdffff 50 8d45f4 50 53 57 ff75fc }
+ $sequence_0 = { 33c8 c1e102 33c8 03c9 }
+ $sequence_1 = { ff75dc ff7508 ff75e2 e8???????? 83c410 ff35???????? ff15???????? }
+ $sequence_2 = { 50 8d85fcf7ffff 50 56 e8???????? 68e8030000 8d85fcf7ffff }
+ $sequence_3 = { 59 7e17 83c0fc 33c9 85c0 7e0e }
+ $sequence_4 = { 334e04 8b75d0 33cf 8b7ddc c1ef08 c1ee10 }
+ $sequence_5 = { 85c0 0f8435010000 807df473 7550 0fb745f7 50 }
+ $sequence_6 = { 0f8f9c010000 894df8 ff7518 53 53 e8???????? }
+ $sequence_7 = { 46 8975f8 83f810 7cd9 8d48f0 f7d9 1bc9 }
+ $sequence_8 = { 0101 03d3 8b4620 8bcb }
+ $sequence_9 = { 00cd 3e46 005e3e 46 }
+ $sequence_10 = { 0107 eb4d 8b02 89442418 }
+ $sequence_11 = { 00f1 3d46005e3e 46 00cd }
+ $sequence_12 = { 0012 3f 46 008bff558bec }
+ $sequence_13 = { 0106 830702 392e 75a0 }
+ $sequence_14 = { 005e3e 46 00ff 3e46 }
+ $sequence_15 = { 00ff 3e46 0012 3f }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <1417216
}
-rule MALPEDIA_Win_Webc2_Kt3_Auto : FILE
+rule MALPEDIA_Win_Mistcloak_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "94855d65-b1ce-5b35-9456-d0939a525276"
+ id = "bcb29aaa-c37e-5c55-be1e-5d06aa41cabd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_kt3"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_kt3_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mistcloak"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mistcloak_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "a5c2b8d7a42ef74a9adf1d4cae6732c8a660cac1ccf5f008908f03c7dfba3cd1"
+ logic_hash = "6962ced189f702e03fc18d236cee46a2a0844476537e8c819ea6f1c43f9c0922"
score = 75
quality = 75
tags = "FILE"
@@ -160888,32 +167902,32 @@ rule MALPEDIA_Win_Webc2_Kt3_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8a92c0c84000 089021d34000 40 3bc7 76f5 41 }
- $sequence_1 = { ff15???????? 85c0 0f843a010000 83bdf0fbffff00 0f86a4000000 }
- $sequence_2 = { 836dd001 837dd000 742c 836dd001 }
- $sequence_3 = { 0345f8 c60000 8b4de8 51 ff15???????? 8b55e8 0fbe02 }
- $sequence_4 = { 8955a8 66c745c80000 c745cc00000000 66c745ca0000 c745c401010000 8b4508 8945d0 }
- $sequence_5 = { e8???????? 8945fc 837dfc00 7d05 83c8ff eb25 837dfc00 }
- $sequence_6 = { 7527 8b55fc 0fbe4202 83f82d 751b }
- $sequence_7 = { 51 ff15???????? 8945f0 837df000 7511 8b55f8 52 }
- $sequence_8 = { 8b5508 83c234 83c9ff 33c0 }
- $sequence_9 = { 8bec 83ec30 53 56 57 8b4508 8945e0 }
+ $sequence_0 = { 8b049590500110 f644082801 740b 56 e8???????? 59 8bf0 }
+ $sequence_1 = { 660f282d???????? 660f59f5 660f28aa70100110 660f54e5 660f58fe 660f58fc }
+ $sequence_2 = { 8b0c8590500110 8b45f8 807c012800 7d46 }
+ $sequence_3 = { 0f85b1000000 8b4508 dd00 ebc2 c745e418120110 eb19 }
+ $sequence_4 = { 6bc618 57 8db8104e0110 57 }
+ $sequence_5 = { 7429 83e805 7415 83e801 0f8595010000 c745e408120110 }
+ $sequence_6 = { c745e408120110 e9???????? c745e404120110 e9???????? 894de0 c745e404120110 e9???????? }
+ $sequence_7 = { 85f6 7420 6bc618 57 8db8104e0110 57 }
+ $sequence_8 = { 8bc1 3914c5781a0110 7408 40 }
+ $sequence_9 = { 8b45b4 8b0c8590500110 8a043b 03ce 8b75dc 03cb 43 }
condition:
- 7 of them and filesize <114688
+ 7 of them and filesize <196608
}
-rule MALPEDIA_Win_Xsplus_Auto : FILE
+rule MALPEDIA_Win_Juicy_Potato_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fb41ffbb-1e2d-5bdd-9365-c97018c55362"
+ id = "03dfaa0e-28b0-58bd-8b17-d8d3c88d86a7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xsplus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xsplus_auto.yar#L1-L178"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.juicy_potato"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.juicy_potato_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "1413c5b641befe4b985d097bf7fa94a2fd076afb28674d33f79669c0d9d8240e"
+ logic_hash = "270473eb74e147cca3eabdeead641e5c572494e923c2e4deeae8d94ea8e99f5c"
score = 75
quality = 75
tags = "FILE"
@@ -160927,39 +167941,32 @@ rule MALPEDIA_Win_Xsplus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b761c 8b4608 8b7e20 8b36 66394f18 75f2 }
- $sequence_1 = { 0fb602 33c1 8b4d0c 034dfc 8801 }
- $sequence_2 = { 83c408 8945f0 837df000 750f }
- $sequence_3 = { e9???????? 8be5 5d c3 3b0d???????? }
- $sequence_4 = { 8b45f4 83c001 8945f4 ebbf eb2c 6a08 8d4df8 }
- $sequence_5 = { 895018 8b4df8 8b511c 83ea01 }
- $sequence_6 = { c6864b01000043 c74668e0a34000 6a0d e8???????? 59 8365fc00 }
- $sequence_7 = { 0345fc 8a08 880a c745f800000000 }
- $sequence_8 = { 8d8df4fdffff 51 ff15???????? 8985ecfcffff 83bdecfcffffff 7565 6804010000 }
- $sequence_9 = { 8b5118 d1e2 8b45f8 895018 8b4df8 }
- $sequence_10 = { c745fc04000000 eb2d 8b5510 83e204 }
- $sequence_11 = { 83c101 898de8feffff 8b550c 52 e8???????? }
- $sequence_12 = { 8a800ca84000 08443b1d 0fb64601 47 3bf8 76ea }
- $sequence_13 = { 8a15???????? 889500ffffff b93f000000 33c0 8dbd01ffffff f3ab 66ab }
- $sequence_14 = { f3a5 8b45fc ffd0 5f 5e 8be5 }
- $sequence_15 = { 8b4d08 51 ff15???????? b801000000 e9???????? 6a00 ff15???????? }
- $sequence_16 = { 8975e0 8db120a84000 8975e4 eb2a 8a4601 }
+ $sequence_0 = { 488b5010 498b4910 48ffc9 488bc2 48d1e8 4823c8 }
+ $sequence_1 = { 4053 4883ec20 488bd9 488bc2 488d0dade40100 48890b 488d5308 }
+ $sequence_2 = { 488d5e08 488b03 6683382d 0f8598010000 0fb74002 83c09f }
+ $sequence_3 = { 4889450f 4883c8ff 488955ff 488bc8 }
+ $sequence_4 = { 488bd7 4c8d05dec60300 83e23f 488bcf 48c1f906 48c1e206 498b0cc8 }
+ $sequence_5 = { 48894728 4883f8ff 7437 448b4310 488b5320 488bc8 ff15???????? }
+ $sequence_6 = { e8???????? ff15???????? b801000000 e9???????? 488b5c2438 4885db 7470 }
+ $sequence_7 = { 488d15159c0100 ff15???????? 4885c0 0f8429030000 488bc8 e8???????? 488bcb }
+ $sequence_8 = { 7509 488d056f200400 eb04 4883c024 8938 e8???????? 488d1d57200400 }
+ $sequence_9 = { ff15???????? ba10000000 663bc2 7312 488bd3 488d0d6df80200 ff15???????? }
condition:
- 7 of them and filesize <597872
+ 7 of them and filesize <736256
}
-rule MALPEDIA_Win_Listrix_Auto : FILE
+rule MALPEDIA_Win_Domino_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f00b612a-8ee6-5314-b10b-7290e9e1e604"
+ id = "eddf3fd4-b67b-5548-8ce8-44ad7e57875e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.listrix"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.listrix_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.domino"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.domino_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "2287c5f695d49f8318bd5f0c78a77cdf4d2c441f03bbfda75594fd76fd20827f"
+ logic_hash = "bd7ff729d0491d94e0d98300cebe034f3949530bba7c0c3abfe7de162ca0ef3c"
score = 75
quality = 75
tags = "FILE"
@@ -160973,32 +167980,32 @@ rule MALPEDIA_Win_Listrix_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8dc0f5ffff 51 ffd3 85c0 7454 57 }
- $sequence_1 = { 85f6 740d f68594f5ffff10 0f84ac010000 8b1d???????? 68???????? 8d85c0f5ffff }
- $sequence_2 = { 8d46ff 50 8b8584f5ffff 51 52 50 8d8df4fbffff }
- $sequence_3 = { 8d85f4f7ffff 50 ff15???????? 8b7518 }
- $sequence_4 = { 89b588f5ffff 397510 0f8e4c020000 57 8d85f4f7ffff 50 }
- $sequence_5 = { 50 8d4c2470 51 c744242430794000 }
- $sequence_6 = { c1e802 89442408 c744240c02000000 85c0 0f8408010000 }
- $sequence_7 = { 8bc7 c1f805 c1e606 033485e0ad4000 8b45f8 8b00 }
- $sequence_8 = { a1???????? c705????????cc274000 8935???????? a3???????? ff15???????? a3???????? }
- $sequence_9 = { 6a00 8d95e4f9ffff 52 ff15???????? 85c0 0f84bb000000 }
+ $sequence_0 = { b940000000 488bd8 ff15???????? 4c63c3 }
+ $sequence_1 = { 8bc6 4881c470010000 415f 415e 415d 415c }
+ $sequence_2 = { 41b800300000 488bd6 33c9 4c8bf6 ff15???????? }
+ $sequence_3 = { 498bd0 492bc8 4963c1 4c8d1d622e0000 428a0418 320411 }
+ $sequence_4 = { 7d07 ffc8 83c8f0 ffc0 48ffc2 }
+ $sequence_5 = { 4889742410 57 4883ec20 4863fa 488bf1 4885c9 750e }
+ $sequence_6 = { 488b1a 488bfa 488bf1 8b13 488bce e8???????? }
+ $sequence_7 = { 895c2420 66899c24b0000000 ff15???????? 85c0 741a 488b4c2458 }
+ $sequence_8 = { 7f20 488b0b 4885c9 7406 ff15???????? 48832300 83c8ff }
+ $sequence_9 = { e8???????? 4533c9 448bc7 488bd6 488bcb e8???????? 488b5c2438 }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <50176
}
-rule MALPEDIA_Win_Zeoticus_Auto : FILE
+rule MALPEDIA_Win_Mpkbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c2a18f25-bc43-5657-ba7f-277a7d143bb2"
+ id = "72738a74-041e-590e-bcbe-fef59ce6d7c8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeoticus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeoticus_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mpkbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mpkbot_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "a4d1e69467730f44a44fc31899a04b37f3c67c9d35561598e18a4009fa030896"
+ logic_hash = "84a9c41e42e448fecfbe039fb747c3f04c473f008e3e19f5ee4ba318bc990491"
score = 75
quality = 75
tags = "FILE"
@@ -161012,32 +168019,32 @@ rule MALPEDIA_Win_Zeoticus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b901000000 8b442404 0f44f1 85c0 7407 50 ff15???????? }
- $sequence_1 = { 6a00 6a02 6a01 6a00 6a00 6a00 6890010000 }
- $sequence_2 = { 53 68???????? 50 89048d00574300 ff15???????? a1???????? 83c410 }
- $sequence_3 = { 8b0d???????? 8d442420 6a00 6a00 6a00 6a25 6800800000 }
- $sequence_4 = { 8d4c2430 6a18 51 ffd0 a1???????? 83c408 85c0 }
- $sequence_5 = { 42 88440e14 8b4c2424 41 894c2424 83fa0b }
- $sequence_6 = { 56 57 8b7c2414 894c2418 390f 0f86df010000 }
- $sequence_7 = { a3???????? c705????????00000000 c705????????00000000 c705????????00000000 e8???????? 8b4c2408 8b542404 }
- $sequence_8 = { 56 57 894c2410 8b7810 8bf7 90 }
- $sequence_9 = { 83c408 a3???????? ff742420 ffd0 85c0 754a }
+ $sequence_0 = { 68???????? 50 ff15???????? a3???????? 8d45fc 50 683f000f00 }
+ $sequence_1 = { a3???????? 8d45fc 50 683f000f00 6a00 }
+ $sequence_2 = { 38450c 740a eb05 38450c 7503 }
+ $sequence_3 = { 8d55f8 52 56 6a20 68???????? }
+ $sequence_4 = { 55 8bec 56 57 6a00 ff15???????? 8bf0 }
+ $sequence_5 = { 0fb630 8975d4 db45d4 d84dc4 }
+ $sequence_6 = { 8bf0 0fb7450c 50 0fb74508 50 56 }
+ $sequence_7 = { 7507 38450c 740a eb05 }
+ $sequence_8 = { ff15???????? ff7508 a3???????? ffd0 5d c3 55 }
+ $sequence_9 = { ff15???????? ffd6 50 ffd7 }
condition:
- 7 of them and filesize <468992
+ 7 of them and filesize <139264
}
-rule MALPEDIA_Win_Alreay_Auto : FILE
+rule MALPEDIA_Win_Hermeticwiper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9cdb1d27-466b-525b-895d-ad710c42b112"
+ id = "ea8155d0-2aad-5127-b709-49a3ac0a065b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alreay"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alreay_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hermeticwiper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hermeticwiper_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "9b54d114d735844c857255b8100f13777f444dd5372ec863d1d85e3d492b2e7d"
+ logic_hash = "152c562a196a1884f9736d7ace893f74c52047d602608c8f019348b6a2233130"
score = 75
quality = 75
tags = "FILE"
@@ -161051,32 +168058,32 @@ rule MALPEDIA_Win_Alreay_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bca 83e103 03eb f3aa e9???????? 83fa07 7511 }
- $sequence_1 = { 89b48484010000 8a442418 fec0 885c2420 8b5c2424 88442418 8b442420 }
- $sequence_2 = { 894c2404 7407 b802000000 eb1d 8b90e8010000 85d2 7411 }
- $sequence_3 = { 89442428 85c0 0f850c010000 8b442420 3bc7 7608 8bd7 }
- $sequence_4 = { 8b8574010000 8bd1 23d0 83faff 0f848d000000 3bc3 7c55 }
- $sequence_5 = { 8b15???????? 8b442414 8b742444 8b4c2448 42 40 83c604 }
- $sequence_6 = { 8a16 8bcf 84d2 8bc6 741d 8a10 80fa5c }
- $sequence_7 = { 8b8268020000 3bc1 0f852f040000 8b86b4040000 8bca 8b916c020000 3bd0 }
- $sequence_8 = { bb16000000 3bc3 bf15000000 0f85f5010000 8b7500 8b86cc000000 8bd0 }
- $sequence_9 = { 8d7c2448 83c9ff 33c0 8b54241c f2ae f7d1 49 }
+ $sequence_0 = { b9???????? 8bc7 6690 668b10 663b11 751e 6685d2 }
+ $sequence_1 = { 8bf8 85ff 7404 3bfe 750b 33c0 }
+ $sequence_2 = { 55 8bec 8b4508 ff30 ff15???????? 6803000280 }
+ $sequence_3 = { 8b0d???????? 83e802 7408 83e801 751b 8b7e08 }
+ $sequence_4 = { 8b75f8 13550c 6a00 6a00 52 50 56 }
+ $sequence_5 = { 33f6 660fd645dc 33ff 8975f4 50 0f1145bc }
+ $sequence_6 = { d3e0 8b4dfc 0facd605 c1ea05 8504b1 754e 8b4d14 }
+ $sequence_7 = { 7509 3b75d8 7504 8bc2 eb0f 3bcb }
+ $sequence_8 = { c20c00 813f46494c45 75d4 f6471601 74ce 0fb77714 }
+ $sequence_9 = { ebba f7d0 23c6 8b75e0 89048e 41 }
condition:
- 7 of them and filesize <1867776
+ 7 of them and filesize <247808
}
-rule MALPEDIA_Win_Netkey_Auto : FILE
+rule MALPEDIA_Win_Pinchduke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "76292b9d-6066-51f2-940c-21859c007253"
+ id = "cba434ff-ad3f-569d-a5ea-a8661b7af309"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.netkey"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.netkey_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pinchduke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pinchduke_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "0ca26012e9d146d53c4ba2a355f1655827a5f40d6a52c39d2206e16c6e4d6ec5"
+ logic_hash = "91b75415e43b3618cf4d35265fc79e44823a3f174f6cf370c8d280ecd6905acb"
score = 75
quality = 75
tags = "FILE"
@@ -161090,32 +168097,32 @@ rule MALPEDIA_Win_Netkey_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c40c 83c208 8bca 81e11f000080 7905 49 }
- $sequence_1 = { 83e03f c1ff06 6bd830 8b04bda8214400 f644032801 7444 837c0318ff }
- $sequence_2 = { 81ec98010000 a1???????? 33c4 89842494010000 b9???????? e8???????? 8d0424 }
- $sequence_3 = { 83c404 85ff 0f84c7000000 57 53 6a00 56 }
- $sequence_4 = { 8bc2 8955fc 99 83e21f 8d0c02 c1f905 }
- $sequence_5 = { 6a01 8845e8 8d45e8 57 50 c745c801000000 e8???????? }
- $sequence_6 = { 42 668955ec e8???????? 99 be3b000000 f7fe }
- $sequence_7 = { 780d b801000000 5f 5e 5b 59 }
- $sequence_8 = { 83c8ff eb07 8b04cd8c6a4300 5f 5e 5b 8be5 }
- $sequence_9 = { 8d8fd8000000 e8???????? 0f1005???????? 8d95f0fbffff 8d4a01 0f1185f0fbffff }
+ $sequence_0 = { 6a01 895dd4 895dd8 895ddc c645e030 895de1 }
+ $sequence_1 = { 9b d93c24 9b 58 50 80e4f3 80cc08 }
+ $sequence_2 = { 85d2 7416 8d4c50fe 2bf0 57 668b3c0e 668939 }
+ $sequence_3 = { 83c40c 8d857bffffff 50 8d4dc4 e8???????? 8d8d7bffffff e8???????? }
+ $sequence_4 = { 50 ff15???????? 3bc3 89456c 0f84cc020000 }
+ $sequence_5 = { 8945fc e8???????? 83c410 ff75fc 56 ff15???????? 56 }
+ $sequence_6 = { 64a118000000 3e8b4030 3e0fb64002 890424 8b0424 59 c3 }
+ $sequence_7 = { 6a00 ff7510 ff75fc ffd6 85c0 7404 33c0 }
+ $sequence_8 = { 85d2 75f5 8bc7 5f 5e c3 8b4c240c }
+ $sequence_9 = { e8???????? 8d85e4f7ffff 50 e8???????? 83ec0c 8bcc 50 }
condition:
- 7 of them and filesize <606208
+ 7 of them and filesize <223680
}
-rule MALPEDIA_Win_Sarhust_Auto : FILE
+rule MALPEDIA_Win_Pillowmint_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "50274b48-711c-5f29-acdb-11078c70fee8"
+ id = "f86758a5-97c5-5c70-a000-bfe6ecf0e5d4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sarhust"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sarhust_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pillowmint"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pillowmint_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "0160e7f1d6d7f85de80fabf97a5a855a2c32446045510933894141374e273156"
+ logic_hash = "33c9d52674ffef90debdc06a4a267346eaf178ee863fdca6106f4bbf407b2817"
score = 75
quality = 75
tags = "FILE"
@@ -161129,32 +168136,32 @@ rule MALPEDIA_Win_Sarhust_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8d4cffffff e8???????? 8d8d4cffffff e8???????? 8d8d4cffffff }
- $sequence_1 = { e8???????? 8d8d4cffffff e8???????? 8d8d4cffffff e8???????? 6a00 ff15???????? }
- $sequence_2 = { e8???????? 8d8d4cffffff e8???????? 8d8d4cffffff e8???????? 6a00 }
- $sequence_3 = { eb08 8b4520 8b4d0c 8908 }
- $sequence_4 = { 6801000080 ff15???????? 85c0 7408 ff15???????? }
- $sequence_5 = { 8d8d4cffffff e8???????? 8d8d4cffffff e8???????? 6a00 ff15???????? }
- $sequence_6 = { e8???????? 8d8d4cffffff e8???????? 6a00 ff15???????? }
- $sequence_7 = { 8d8d4cffffff e8???????? 8d8d4cffffff e8???????? 6a00 }
- $sequence_8 = { 8d8d4cffffff e8???????? 8d8d4cffffff e8???????? 8d8d4cffffff e8???????? 6a00 }
- $sequence_9 = { 8d8d4cffffff e8???????? 6a00 ff15???????? }
+ $sequence_0 = { 4883ec48 488b05???????? 4833c4 4889442438 83fa01 0f8580000000 }
+ $sequence_1 = { 90 4c8bc0 488d1533c00000 488d4d40 e8???????? 90 4c8d051ec00000 }
+ $sequence_2 = { 488bd8 488b00 80781900 74e9 493bd8 741e 8b4320 }
+ $sequence_3 = { 4889bc2418010000 c684240801000000 41b810000000 488d155dc00200 488d8c2408010000 e8???????? }
+ $sequence_4 = { 49c1f803 498bc0 48c1e83f 4c03c0 0f84e0050000 498bd1 4c3bc3 }
+ $sequence_5 = { ff15???????? ba04010000 488d4c2430 4c8d05a2630300 395c2420 7507 4c8d05ad630300 }
+ $sequence_6 = { 0f95c0 48ffc0 480faf45df 48ffc8 48014368 48837de710 7209 }
+ $sequence_7 = { 488bd6 488d4d97 e8???????? 90 4c8d6597 48837daf10 4c0f436597 }
+ $sequence_8 = { ff15???????? 833d????????04 0f8cf6030000 48c785980000000f000000 4533f6 4c89b590000000 }
+ $sequence_9 = { 3b3d???????? 0f8392000000 488bc7 4c8bf7 49c1fe05 4c8d2d4bd30100 83e01f }
condition:
- 7 of them and filesize <114688
+ 7 of them and filesize <4667392
}
-rule MALPEDIA_Win_Typehash_Auto : FILE
+rule MALPEDIA_Win_Satana_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "edf296ed-fbc4-5bd8-b180-ef55e989c944"
+ id = "d19234af-c9bd-5654-81eb-f961478057fe"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.typehash"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.typehash_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.satana"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.satana_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "9451e6a97a0b537ea280e22049617c90fd5aa93257a4b129bfda6427a2eb4eeb"
+ logic_hash = "bdc48675727bdd579a6ca8ed3a223cef8d8ab6026da5d019b40d5fe8d696eb85"
score = 75
quality = 75
tags = "FILE"
@@ -161168,32 +168175,32 @@ rule MALPEDIA_Win_Typehash_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83e11f 8b0485e03d4100 8d04c8 eb05 b8???????? f6400420 740d }
- $sequence_1 = { c3 8bc8 83e01f c1f905 8b0c8de03d4100 8a44c104 }
- $sequence_2 = { e8???????? 6a01 8d4c2450 c68424cc00000001 e8???????? bf???????? }
- $sequence_3 = { 8944240c c744241004000000 7460 8b2d???????? 8b3d???????? }
- $sequence_4 = { c1f805 c1e603 8d1c85e03d4100 8b0485e03d4100 03c6 8a5004 }
- $sequence_5 = { 50 51 6813000020 56 c744242000000000 c744242404000000 ffd7 }
- $sequence_6 = { 03c8 3bc1 7d1e 8d1440 2bc8 8d1495e8294100 832200 }
- $sequence_7 = { 3bf3 7505 be???????? 8b54242c 8b442430 8bcf 55 }
- $sequence_8 = { 837d1805 7538 837d1000 7508 8bb6b42b4100 }
- $sequence_9 = { e8???????? 68???????? 8d45c8 c745c8e4e74000 50 }
+ $sequence_0 = { 8b3d???????? 90 ffd6 68e8030000 ffd7 }
+ $sequence_1 = { ff15???????? 8b459c 50 ff15???????? 8b4ddc 010d???????? }
+ $sequence_2 = { 8d8c2468020000 51 e8???????? 8b442410 8d542418 52 }
+ $sequence_3 = { 8b5108 ffd2 6a00 8b45fc 8b480c ffd1 8be5 }
+ $sequence_4 = { 68???????? e8???????? 83c414 53 6880000000 }
+ $sequence_5 = { 83c002 663bcb 75f1 8d8de89effff 51 e8???????? }
+ $sequence_6 = { 57 50 68???????? e8???????? 83c414 833d????????00 745a }
+ $sequence_7 = { ffd3 8bf8 a1???????? 57 }
+ $sequence_8 = { 105353 bf60600157 ff7528 fc ffd6 0105???????? f8 }
+ $sequence_9 = { ff15???????? e8???????? 837de401 0f8e12030000 8b4704 }
condition:
- 7 of them and filesize <180224
+ 7 of them and filesize <221184
}
-rule MALPEDIA_Win_Redshawl_Auto : FILE
+rule MALPEDIA_Win_Flowershop_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6da43ccb-6114-536f-a2d4-a0a197b8eb4b"
+ id = "8ec68082-5d4c-584e-ad88-66456b2a097b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redshawl"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redshawl_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flowershop"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flowershop_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "b081202974eb2cc07597ec5bbbc48f26672d398acc6550f420b42ca3feedcaae"
+ logic_hash = "f019e2c8acff91329c227db3e65589276d7267039537efb349a1a4ca0b28047b"
score = 75
quality = 75
tags = "FILE"
@@ -161207,32 +168214,32 @@ rule MALPEDIA_Win_Redshawl_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffc6 488d0c80 488d05baaa0000 488d0cc8 48890f ff15???????? 85c0 }
- $sequence_1 = { e8???????? 488b8b58010000 e8???????? 488d7b58 be06000000 488d0519c30000 483947f0 }
- $sequence_2 = { 488bce 488bc6 488d15709a0000 83e11f }
- $sequence_3 = { 488b8b58010000 e8???????? 488d7b58 be06000000 488d0519c30000 }
- $sequence_4 = { e9???????? 4c8d2552940000 488b0d???????? eb7c }
- $sequence_5 = { eb76 33c9 488d1543bb0000 48891401 4883c230 4883c108 48ffcb }
- $sequence_6 = { 8905???????? 8b430c 8905???????? 8bd7 4c8d0520d1ffff 89542420 }
- $sequence_7 = { 8bd8 488bcf ff15???????? 488b742438 8bc3 }
- $sequence_8 = { 72ed 48833d????????00 741f 488d0dc2c10000 e8???????? 85c0 }
- $sequence_9 = { 4c8d251ac70000 4863f8 49833cfc00 752b b900100000 }
+ $sequence_0 = { 0f857d030000 e9???????? 8325????????00 8b15???????? 85d2 760b 8bca }
+ $sequence_1 = { ff750c ff15???????? 8bf0 d1e6 0fb7c6 50 8d470a }
+ $sequence_2 = { 33f6 85c0 761e bb???????? 53 57 e8???????? }
+ $sequence_3 = { 8b45f0 8b3d???????? 8db008010000 56 6a08 ffd7 50 }
+ $sequence_4 = { 33ff 80240100 217dfc 8d450c 50 8d4508 50 }
+ $sequence_5 = { 85c0 740a 3b4514 7705 6a01 58 eb02 }
+ $sequence_6 = { c3 895104 c3 56 8b742408 57 8b4604 }
+ $sequence_7 = { e8???????? 33c0 eb7b 6a01 5e 837c241005 7c5e }
+ $sequence_8 = { 33c0 5f 2bd1 c7450824000000 3b7d0c 7712 8b5c0afc }
+ $sequence_9 = { 33f6 eb4b 8b7d08 3b7dfc 741c 8d45fc 50 }
condition:
- 7 of them and filesize <174080
+ 7 of them and filesize <829440
}
-rule MALPEDIA_Win_Webc2_Ausov_Auto : FILE
+rule MALPEDIA_Win_Buzus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "452f6306-c16f-58b7-84a1-ee288d662c0a"
+ id = "abeb46d7-6b5d-534d-9d29-46b219047b43"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_ausov"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_ausov_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.buzus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.buzus_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "e12dc956bf634cd764e774e1669338328ccbb898d34279d3918e11978d93f5a2"
+ logic_hash = "4ce965d715abb7623aae188d8dd7527d9c7207cb501cc27ac457187efef652e0"
score = 75
quality = 75
tags = "FILE"
@@ -161246,34 +168253,34 @@ rule MALPEDIA_Win_Webc2_Ausov_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f8501000000 f8 8b95f8fbffff 0355fc 8995f8fbffff 0f8407000000 }
- $sequence_1 = { 83bdc4fdffff00 7507 33c0 e9???????? 8d8da8faffff 898d4cfaffff }
- $sequence_2 = { 0f8487000000 8b3d???????? 68???????? 56 }
- $sequence_3 = { 0f8407000000 0f8501000000 f8 68???????? }
- $sequence_4 = { 83c101 894df8 8b55f8 3b55f4 7d31 0f8407000000 }
- $sequence_5 = { f7d1 83c1ff 51 8d95f8feffff 52 }
- $sequence_6 = { 0f8501000000 f8 68???????? 8d8dfcfbffff 51 }
- $sequence_7 = { 6804010000 8d85a8faffff 50 68???????? ff15???????? 8985c4fdffff 83bdc4fdffff00 }
- $sequence_8 = { 81ec10040000 53 56 57 0f8407000000 0f8501000000 }
- $sequence_9 = { e8???????? 83c404 8b4d0c 894104 e9???????? 8dbdfcfbffff 83c9ff }
+ $sequence_0 = { 5d 7413 68???????? 50 ffd6 3bc3 a3???????? }
+ $sequence_1 = { 4e 46 897508 ebbd 803e2a 750b 83f801 }
+ $sequence_2 = { ff75c0 ff75bc 50 e8???????? 83c40c 83f801 0f85e4000000 }
+ $sequence_3 = { e8???????? 8d8554fdffff 50 8d85ccfdffff 50 68???????? }
+ $sequence_4 = { 68???????? 6a01 56 68???????? 33ff 8975f0 8975f4 }
+ $sequence_5 = { 50 ff15???????? be???????? 8d84242c280000 }
+ $sequence_6 = { 898524ffffff 8b45bc 89850cffffff 8b45d8 898514ffffff 6bc03c 6a31 }
+ $sequence_7 = { 385802 750e 0fbe5001 c68415b0feffff01 eb28 80fa2d 7539 }
+ $sequence_8 = { 6a03 58 8945b8 6a3c 59 3bc1 7603 }
+ $sequence_9 = { 68???????? 50 ff7508 e8???????? 83c41c 8b45d4 68b80b0000 }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <679936
}
-rule MALPEDIA_Win_Vawtrak_Auto : FILE
+rule MALPEDIA_Win_Blackenergy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b724e7c8-fa8b-5ecb-9091-2adfef543aee"
+ id = "5db0ecdd-a93d-527c-8567-cf3a04744f9e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vawtrak"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vawtrak_auto.yar#L1-L212"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackenergy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackenergy_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "2420d7270c56567b74aa80afdfcc3b5893cd81eeb0dabc0a53855a9b85be220c"
+ logic_hash = "0197d7c7455032dc4a706fe02d56c8be876c2f6b4f29a6658284a54a2993239d"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -161285,45 +168292,32 @@ rule MALPEDIA_Win_Vawtrak_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a01 ff35???????? 6a04 6a01 50 ff15???????? 85c0 }
- $sequence_1 = { 6a00 6a00 e8???????? 50 ff15???????? }
- $sequence_2 = { 837d1040 752d 8b4d04 e8???????? 85c0 }
- $sequence_3 = { 8b4d08 e8???????? 85c0 7415 ff15???????? 50 }
- $sequence_4 = { ba00ff0000 8bc1 23c2 3bc2 }
- $sequence_5 = { 750f 33c9 e8???????? 85c0 7404 }
- $sequence_6 = { b8ff0f0000 6623e8 b800400000 660be8 }
- $sequence_7 = { 6a08 68???????? 56 ffd7 85c0 }
- $sequence_8 = { 50 ff15???????? a3???????? 85c0 74e7 }
- $sequence_9 = { 7528 68???????? ff15???????? 85c0 7504 33c0 }
- $sequence_10 = { 59 57 8bf0 ff15???????? 8bc6 }
- $sequence_11 = { e8???????? 33d2 b9ff3f0000 f7f1 }
- $sequence_12 = { 8bc6 8703 3bc6 74f8 }
- $sequence_13 = { 56 6a04 53 57 }
- $sequence_14 = { 7705 80ea61 eb0a 8d42bf }
- $sequence_15 = { 03c1 8b4d14 8901 33c0 40 }
- $sequence_16 = { e9???????? 8ac1 c1e904 c0e004 }
- $sequence_17 = { 8ac8 240f 80e1f0 80c110 32c8 }
- $sequence_18 = { 3c41 7c11 3c46 7f0d }
- $sequence_19 = { 48397c2430 7505 bb01000000 8bc3 }
- $sequence_20 = { 4885c0 7440 ff15???????? 488b0b 33ff 3db7000000 }
- $sequence_21 = { 0f84ff000000 3d00010000 7320 488b0b }
- $sequence_22 = { 420fb61408 8bc1 ffc1 42881408 }
+ $sequence_0 = { bb01000000 eb02 03d8 8bc2 e9???????? 8b4df4 014dd8 }
+ $sequence_1 = { 39750c 740c 56 56 ff7508 ff550c }
+ $sequence_2 = { 8b7df4 8b75f0 8b4d08 f3a4 a1???????? 33c9 3bc1 }
+ $sequence_3 = { e8???????? 2bc6 3bc7 760f 6bd20a 47 e8???????? }
+ $sequence_4 = { 0f848f000000 53 8d45f0 50 8d45d8 50 }
+ $sequence_5 = { 58 e8???????? 85c0 75ae 5e 5f c9 }
+ $sequence_6 = { 85c0 7441 8b5dc8 8b5b28 85db 7427 8b4de4 }
+ $sequence_7 = { 33f6 56 6810000002 6a03 56 6a01 6800000080 }
+ $sequence_8 = { 8b583c 03d8 895dc8 8b4334 8945e0 33f6 46 }
+ $sequence_9 = { 50 ff15???????? 50 ff5508 6a02 }
condition:
- 7 of them and filesize <1027072
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Graphsteel_Auto : FILE
+rule MALPEDIA_Win_Derohe_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5824e278-153d-5fe0-a214-d93680fdb8e7"
+ id = "082c8bb6-5e90-542b-87a2-cd5536e22be3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphsteel"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graphsteel_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.derohe"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.derohe_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "0a7069cfdac89882eeae5b943786ae3bcce2789fc825f256679c381850fffe14"
+ logic_hash = "3afbf42b0aba27d1df54ba6496f4a588ae2f7c7ec09fa3d922d168dfad26c783"
score = 75
quality = 75
tags = "FILE"
@@ -161337,33 +168331,33 @@ rule MALPEDIA_Win_Graphsteel_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 488d7830 488b4c2440 0f1f4000 e8???????? 4889c3 488d05415b3900 }
- $sequence_1 = { ffd0 488bb42428010000 488b942410020000 4885d2 0f8401010000 488b4c2450 488d1d88ae4400 }
- $sequence_2 = { e9???????? a810 0f84f1000000 84d2 0f888c010000 8954245c 83fa0b }
- $sequence_3 = { e8???????? e8???????? 90 31c9 488d150f198e00 870a 8b0d???????? }
- $sequence_4 = { e9???????? 4c8b4c2468 4d85c9 0f84b1000000 4c8b9424d8030000 4d8b9a88000000 498b4b08 }
- $sequence_5 = { e8???????? 4909c5 0fb603 83c05b a8fb 0f85a0000000 488b4340 }
- $sequence_6 = { e9???????? 8b8424a0010000 4189d9 ba35000000 4c89e9 448b842498010000 41bf06000000 }
- $sequence_7 = { e9???????? 4885f6 0f8520ffffff 4c8d742440 4889d9 4d8b4550 c744244001080000 }
- $sequence_8 = { eb11 488d7830 488b9424e0000000 e8???????? 488b542438 48895050 488b542440 }
- $sequence_9 = { e8???????? c644243507 488d05e3cc3300 488b9c24c8000000 488d4c2435 e8???????? 48c7400806000000 }
+ $sequence_0 = { ffd0 8b542404 c60424e3 8b02 ffd0 8b542404 c6042405 }
+ $sequence_1 = { ffd0 8b542404 c604247d 8b02 ffd0 8b542404 c60424df }
+ $sequence_2 = { ffd0 8b542404 c60424a1 8b02 ffd0 8b542404 c60424e8 }
+ $sequence_3 = { ffd0 8b442418 8b4c2414 8b542420 898a8c010000 8b0d???????? 85c9 }
+ $sequence_4 = { ffd0 8b542404 c60424de 8b02 ffd0 8b542404 c60424b8 }
+ $sequence_5 = { ffd0 8b542404 c60424cc 8b02 ffd0 8b542404 c6042462 }
+ $sequence_6 = { e8???????? 8b44241c 8b4c2420 8b542424 8b5c2434 894b08 89530c }
+ $sequence_7 = { ffd0 8b542404 c604247d 8b02 ffd0 8b542404 c60424a4 }
+ $sequence_8 = { ffd2 8b442404 83c0fa 83f801 0f869e000000 90 8b4c242c }
+ $sequence_9 = { ffd0 8b542404 c60424e0 8b02 ffd0 8b542404 c6042407 }
condition:
- 7 of them and filesize <19812352
+ 7 of them and filesize <35788800
}
-rule MALPEDIA_Win_Wndtest_Auto : FILE
+rule MALPEDIA_Win_Mebromi_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a60fab9e-f350-5d99-8e55-84b700dcda0e"
+ id = "e0d98380-a60b-51d2-98f3-302d440340e7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wndtest"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wndtest_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mebromi"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mebromi_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "c7d0b1dfe74b472c5174a4761a9428ccee3d781f889972cf04ca5a6d741a211f"
- score = 50
+ logic_hash = "4361b37a1cf79aacd380ae78b2f2e74bbc44d101b09510c6583cf0529e44be88"
+ score = 75
quality = 75
tags = "FILE"
version = "1"
@@ -161376,32 +168370,32 @@ rule MALPEDIA_Win_Wndtest_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d1439 8a0410 320419 41 }
- $sequence_1 = { 56 ffd7 8b0d???????? a3???????? a1???????? }
- $sequence_2 = { 56 0fbe7001 83f60d 57 }
- $sequence_3 = { 880c3e 5f 5e 8be5 }
- $sequence_4 = { 75ea 8bcb 0fb6d2 c1e918 33ca c1e308 }
- $sequence_5 = { a3???????? a1???????? 50 51 e8???????? 83c408 50 }
- $sequence_6 = { 2bc2 40 50 e8???????? 8bd0 }
- $sequence_7 = { ffd7 8b15???????? a3???????? a1???????? 52 50 e8???????? }
- $sequence_8 = { 83c404 33c9 8d460a ba02000000 f7e2 }
- $sequence_9 = { 8b0d???????? 894808 e9???????? 8d46fe 8bff 668b4802 }
+ $sequence_0 = { 743a 837d0800 742e 85f6 7419 0fb6da f68301a0290004 }
+ $sequence_1 = { 68ff010f00 68???????? ff742410 ff15???????? 8bf0 85f6 7416 }
+ $sequence_2 = { 7714 8b55fc 8a9270722900 089001a02900 }
+ $sequence_3 = { 683f000f00 55 55 ff15???????? 8bf0 e8???????? 56 }
+ $sequence_4 = { 48 750c e8???????? eb05 e8???????? 6a01 }
+ $sequence_5 = { 0fb6fa 3bc7 7714 8b55fc 8a9270722900 089001a02900 }
+ $sequence_6 = { 2c29 0000 2d29008a46 0323 d18847034ec1 e9???????? }
+ $sequence_7 = { 0fb6d2 f68201a0290004 740c ff01 }
+ $sequence_8 = { aa 8d9e88722900 803b00 8bcb 742c 8a5101 84d2 }
+ $sequence_9 = { 50 6a01 56 ff15???????? 56 8bf8 ff15???????? }
condition:
- 7 of them and filesize <901120
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Bravonc_Auto : FILE
+rule MALPEDIA_Win_Cradlecore_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e1447c3c-8c4c-54e5-9d2c-b00b52d2dc03"
+ id = "de5cfc2b-ebd2-5b2c-afe8-802a7c966fb2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bravonc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bravonc_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cradlecore"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cradlecore_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "76468ca1f8266a49d1bb0da33f680bf0a2046353d9d66d58507a76281c00d1b6"
+ logic_hash = "50e3eefefe56e4c7c3dbb9ce61b4c12511d78dda94103f69f932673a673b2621"
score = 75
quality = 75
tags = "FILE"
@@ -161415,32 +168409,32 @@ rule MALPEDIA_Win_Bravonc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f8c05040000 8b06 3b7804 0f8dfa030000 395e04 7407 50 }
- $sequence_1 = { 5b c3 55 8bec 53 33db 395d0c }
- $sequence_2 = { 57 ff75ec 334dec 030a 034df0 8d8401d6c162ca 8945f0 }
- $sequence_3 = { 8907 8b45f4 2bfb 59 59 8907 8b45fc }
- $sequence_4 = { 83c430 8bce 53 56 e8???????? 5f 5e }
- $sequence_5 = { e8???????? 8b0e 030f c1e104 2bc1 eb08 8d4de0 }
- $sequence_6 = { ff75f0 e8???????? 8b4df8 83c440 334dec 57 }
- $sequence_7 = { 335dfc 3175fc 83c118 ff4df0 8bf2 8b55fc 8955f8 }
- $sequence_8 = { 83450c08 ebd2 d36d08 8b0c8590b24000 234d08 014df0 8bc8 }
- $sequence_9 = { 03f3 2bfb 03f3 890f }
+ $sequence_0 = { 03f2 eb5c 8b45f4 8b0c85f01f4300 f644190448 7437 }
+ $sequence_1 = { 720f 8b06 5f c60000 8bc6 }
+ $sequence_2 = { 83e908 8d7608 660fd60f 8d7f08 8b048db8734000 ffe0 f7c703000000 }
+ $sequence_3 = { e8???????? 51 51 53 8bd9 33c0 8945f0 }
+ $sequence_4 = { e8???????? 83c410 3bc3 75cf 0fb644240f e9???????? c74424340f000000 }
+ $sequence_5 = { 80fb5a 7e53 80fb2d 744e 80fb2e }
+ $sequence_6 = { 8b5df4 8b7df0 33f6 8bce 8b75fc }
+ $sequence_7 = { 7204 8b1e eb02 8bde 8b450c 33d2 8b4d08 }
+ $sequence_8 = { 59 50 8d45d0 8bce 50 e8???????? 837da010 }
+ $sequence_9 = { 53 50 68???????? 53 ff15???????? 8d4de8 c745e868747470 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <450560
}
-rule MALPEDIA_Win_Pebbledash_Auto : FILE
+rule MALPEDIA_Win_Sathurbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3f16c34e-ab8c-5fd5-9a27-9934f8af2f6b"
+ id = "74231d79-bc89-53a0-abc2-544d7739c735"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pebbledash"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pebbledash_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sathurbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sathurbot_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "477e05e2df7e0e436b23bf26c9707de6486fd65cc8fb3dc50d94f319663b31bc"
+ logic_hash = "3f29ba6959f8023f24a58bd7b1fb03852622ec3e610d203883720a7aae8ca8ad"
score = 75
quality = 75
tags = "FILE"
@@ -161454,32 +168448,32 @@ rule MALPEDIA_Win_Pebbledash_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 25ffff0000 3bd0 740a b800000004 e9???????? 83bd74fbffff00 751a }
- $sequence_1 = { 8be5 5d c3 55 8bec 81ecd0000000 c68530ffffff8e }
- $sequence_2 = { 51 e8???????? 83c418 8d55f0 52 8d85a4f3ffff 50 }
- $sequence_3 = { 8d95a0f5ffff 52 ff15???????? 898594f7ffff 83bd94f7ffffff 7505 }
- $sequence_4 = { a3???????? 833d????????00 742c 8b55f0 8955dc 8b45dc 8945e0 }
- $sequence_5 = { 8d1c85609f4200 c1e603 8b03 f644300401 7469 57 }
- $sequence_6 = { 8b08 8b550c 8b4110 8902 8d8d70feffff 51 8b550c }
- $sequence_7 = { 8b45e8 83c001 8945e8 837de80e 733b }
- $sequence_8 = { 51 e8???????? 83c40c 817d0c1e010000 7f15 837d101e }
- $sequence_9 = { 8b55fc 0355e4 33c0 8a02 83f850 753b 8b4dfc }
+ $sequence_0 = { f6c101 0f94c0 813d????????0a000000 0f9cc1 08c1 b86b2c1f0a b9b2fd990f }
+ $sequence_1 = { b94d1e0277 0f45c1 e9???????? 3ddc03f324 0f8582f1ffff a1???????? 8d48ff }
+ $sequence_2 = { e9???????? 81ff6e65f902 7f1b 81ffded97800 ba96b0469a 0f8548e7ffff bfadab28bf }
+ $sequence_3 = { e9???????? b817aff9fc e9???????? 3dcf25ea47 0f85eef0ffff a1???????? 8d48ff }
+ $sequence_4 = { f6c101 0f94c0 813d????????0a000000 0f9cc1 08c1 b8d3b4c9a9 b9c79b14fb }
+ $sequence_5 = { c744240400000000 89f1 e8???????? 83ec0c bafb0541ae b828f7da39 eb8f }
+ $sequence_6 = { b994a742ce 0f45c1 e9???????? 3d98320e47 0f8561fcffff 8a45ea 8a4deb }
+ $sequence_7 = { f6c201 ba67157693 b85ee72ce5 0f45d0 e9???????? 3d4c9cd69e 89c2 }
+ $sequence_8 = { e8???????? 83ec0c 8b45f0 8945d8 894610 89f1 e8???????? }
+ $sequence_9 = { bf51a32250 81fa39ccdcb8 74d7 ebfe 8b4304 83ec04 890424 }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <2727936
}
-rule MALPEDIA_Win_Nim_Blackout_Auto : FILE
+rule MALPEDIA_Win_Badflick_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5ee8f0fb-bcc5-57f1-899f-f87f9c8f8cd3"
+ id = "24a1778a-a3eb-561a-a408-849c5f96759c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nim_blackout"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nim_blackout_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badflick"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.badflick_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "38658558791a84132e6c1e0a028a41bbfaac44e317840b869e572ec902a09080"
+ logic_hash = "416482f46b00136f041d59b3fa9a5b2a608db531874355803fb74761c46fd686"
score = 75
quality = 75
tags = "FILE"
@@ -161493,32 +168487,32 @@ rule MALPEDIA_Win_Nim_Blackout_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4889c8 83e001 84c0 7405 e8???????? 488b45f0 4885c0 }
- $sequence_1 = { 48c7401800000000 e9???????? 90 48c745e0c6000000 488d057d5c0200 488945e8 }
- $sequence_2 = { 488d057ad80000 488905???????? 488d05d85b0200 488905???????? c605????????01 48c705????????60000000 }
- $sequence_3 = { e8???????? 48c745e0e7000000 488d05c37e0200 488945e8 488b4510 488b00 ba08000000 }
- $sequence_4 = { e9???????? 90 48c785a800000000000000 48c785a000000000000000 48c7450088010000 488d05885b0100 48894508 }
- $sequence_5 = { 488945c8 488b4de8 488b55e0 4889d0 4801c0 4801d0 48c1e003 }
- $sequence_6 = { 488b1402 4889c8 4801c0 4801c8 48c1e004 4889c1 }
- $sequence_7 = { 488d0542460200 488945c8 488b4510 488b55f8 4889d1 48c1e105 488b55f0 }
- $sequence_8 = { 488b4588 488945f0 eb49 90 48c745d033000000 488d05f48e0100 488945d8 }
- $sequence_9 = { 48894508 48c785f800000000000000 48c7450084010000 488d05bf5c0100 48894508 4883bdf000000000 0f84ff000000 }
+ $sequence_0 = { 74e2 6800800000 53 ff75f8 ff75e4 ff15???????? }
+ $sequence_1 = { 56 ff75fc ff15???????? 53 ff15???????? 33c0 5f }
+ $sequence_2 = { 8d4598 53 50 c7459044000000 895d94 e8???????? 33c0 }
+ $sequence_3 = { 8bec 51 51 8b4d0c 8b4101 53 56 }
+ $sequence_4 = { 68???????? 50 ffd7 be???????? 56 }
+ $sequence_5 = { 8945fc ffd6 8bf0 8d85e8fcffff 50 }
+ $sequence_6 = { 5d c3 b001 c3 55 8bec }
+ $sequence_7 = { 50 8b4704 03450c 50 8b47fc 0345f8 }
+ $sequence_8 = { 85c0 0f85e7000000 6a01 ff7305 }
+ $sequence_9 = { ff750c e8???????? 50 e8???????? 59 59 56 }
condition:
- 7 of them and filesize <1068032
+ 7 of them and filesize <81920
}
-rule MALPEDIA_Win_Pwndlocker_Auto : FILE
+rule MALPEDIA_Win_Danabot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "68fbdce5-97ba-5b4c-a728-8efe50c54b3b"
+ id = "6c78b1f9-714b-5978-8883-c700c384c0f3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pwndlocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pwndlocker_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.danabot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.danabot_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "035ce763bc16632a928a77294057e290950a177cc8c2678dfab31b46c9b29c9e"
+ logic_hash = "4cb498ddb7090d3a6017b222a7d9cd57acddd4317f82294d9c05727c52600ae4"
score = 75
quality = 75
tags = "FILE"
@@ -161532,32 +168526,32 @@ rule MALPEDIA_Win_Pwndlocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c1cf0d 01c7 ebf4 3b7df0 75e0 5a }
- $sequence_1 = { 01d8 83c078 8b00 8d3403 8b4e18 }
- $sequence_2 = { c1cf0d 01c7 ebf4 3b7df0 }
- $sequence_3 = { ebf4 3b7df0 75e0 5a 8b7224 01de 31c0 }
- $sequence_4 = { 31ff 31c0 fc ac 84c0 7407 }
- $sequence_5 = { c1cf0d 01c7 ebf4 3b7df0 75e0 5a 8b7224 }
- $sequence_6 = { 01de 31ff 31c0 fc }
- $sequence_7 = { 668b044e 8b721c 01de 8b0486 }
- $sequence_8 = { fc ac 84c0 7407 c1cf0d 01c7 ebf4 }
- $sequence_9 = { 01da 56 e334 49 8d348a }
+ $sequence_0 = { 7405 83e804 8b00 83f814 7e18 8b45fc 50 }
+ $sequence_1 = { c1e803 83e03f 83f838 730b ba38000000 }
+ $sequence_2 = { 8b03 50 8b44242c 50 6a14 }
+ $sequence_3 = { 8b45f8 85c0 7407 83e804 }
+ $sequence_4 = { 8b16 e8???????? 8b07 50 8b442428 50 6a0a }
+ $sequence_5 = { 50 6a14 688a4c2a8d 8bc6 8b4d00 8b17 }
+ $sequence_6 = { 3b85d0feffff 7452 8b85d0feffff 50 6a00 }
+ $sequence_7 = { 6a00 49 75f9 51 53 56 bb???????? }
+ $sequence_8 = { 8b0f 8b16 e8???????? 8b07 50 8b442454 50 }
+ $sequence_9 = { 56 57 8bf1 8955f8 8945fc 8d45fc }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <237568
}
-rule MALPEDIA_Win_Play_Auto : FILE
+rule MALPEDIA_Elf_Hideandseek_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e5dc4ad0-4963-56ca-a5e5-83aec2390f77"
+ id = "8886e955-536d-56f5-a630-bf2b9ef8b07e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.play"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.play_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.hideandseek"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.hideandseek_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "633aef027703dbbff9f2f212af038ee3039813400893deac0150b99c35143631"
+ logic_hash = "c312d2a4b534a00f51e15be6e1572c868a1bf84ffb4d93cf13ce0449e347f5bb"
score = 75
quality = 75
tags = "FILE"
@@ -161571,32 +168565,32 @@ rule MALPEDIA_Win_Play_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb78d82feffff 2bc8 899570ffffff 014d84 }
- $sequence_1 = { 02c1 c645c5ae 8845c3 b937030000 888556ffffff 8a45c7 c6852fffffff00 }
- $sequence_2 = { 8bd8 899d88fdffff 85db 0f8483040000 8a0b 80f9e9 7409 }
- $sequence_3 = { c83dad3c d92b e00c 9c 0d05f0657b 4e f30f7e05???????? }
- $sequence_4 = { 7f06 81c4ab000000 83c410 e8???????? 66f1 }
- $sequence_5 = { a1???????? 8945bc a1???????? 0f11855cffffff 894594 f30f7e05???????? 8b45f8 }
- $sequence_6 = { 91 ae 54 ce 3106 f77cf30f 7e05 }
- $sequence_7 = { 8955f4 8b460c 83ec08 8d0488 8945f8 8d45f4 }
- $sequence_8 = { 898d48fdffff 66898562fdffff 668985e6fcffff 66398d30fdffff 7634 66ff857cfcffff 8d0432 }
- $sequence_9 = { 88852effffff 8b8548ffffff fec8 8855ad 88854dffffff 8d45e8 6689bd0cfeffff }
+ $sequence_0 = { 53 83ec14 8b44242c 8a5c2430 ff7004 ff74242c e8???????? }
+ $sequence_1 = { e8???????? 83c410 84c0 752e 83ec0c 8d84241c120000 50 }
+ $sequence_2 = { 8d44244c 50 e8???????? 5b 8d442440 50 e8???????? }
+ $sequence_3 = { 89ca 8b0424 0fa4d91e 31c8 8b4c2430 0fa4d31e 8b542404 }
+ $sequence_4 = { 7411 0f821e040000 83f802 0f8508040000 eb04 50 50 }
+ $sequence_5 = { be00000000 b800000000 c1e210 09c6 c1e718 31db 0fb64504 }
+ $sequence_6 = { 50 e8???????? 83c410 84c0 741a 8b542414 c7434403000000 }
+ $sequence_7 = { 817e0c00010000 751a 8d5610 8d4650 53 68c0000000 50 }
+ $sequence_8 = { 56 53 8b7c2410 803d????????00 7561 83ec0c 6800000011 }
+ $sequence_9 = { 50 8b8424ec000000 ff7008 e8???????? 89f2 8b8424f0000000 }
condition:
- 7 of them and filesize <389120
+ 7 of them and filesize <196608
}
-rule MALPEDIA_Win_Tokyox_Auto : FILE
+rule MALPEDIA_Elf_Babuk_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6ca744f8-6e83-57d0-b9b1-d948cf62f189"
+ id = "0f03a128-b2bf-587f-bb2c-939b9b8a07cd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tokyox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tokyox_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.babuk"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.babuk_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "6c96cc95cf53b382f98148013ad4ad66eb649ce28d4ba112298bfa55f06ac1c7"
+ logic_hash = "1ffac28a8690c44fcc8b3792df7481d8deebcbe27a55524336d71b5e562fe261"
score = 75
quality = 75
tags = "FILE"
@@ -161610,32 +168604,32 @@ rule MALPEDIA_Win_Tokyox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6685c0 75e8 8d8570ffffff 8bf0 }
- $sequence_1 = { bb0f000000 8975d8 8975e8 51 68ffff0000 50 }
- $sequence_2 = { ff15???????? 85c0 0f8456010000 837d1000 751b 68c8000000 }
- $sequence_3 = { 8d4598 8bcb 50 6888130000 8d45dc 50 e8???????? }
- $sequence_4 = { 8d854cf5ffff 50 68???????? ff15???????? }
- $sequence_5 = { 0f114590 0f104010 0f1145c0 0f1145a0 }
- $sequence_6 = { ff730c ffd7 e9???????? 8d8550ffffff 0f57c0 50 0f114310 }
- $sequence_7 = { 8d85f0faffff c645a000 50 ff75a0 8d4de8 }
- $sequence_8 = { 8bf8 56 53 57 e8???????? 0f1045d0 }
- $sequence_9 = { 668903 8d5101 8a01 41 84c0 75f9 ff75f8 }
+ $sequence_0 = { f7e2 89942488020000 898424a4000000 89e8 f7e1 89942484020000 898424a0000000 }
+ $sequence_1 = { 895c2404 e8???????? eba0 0fb6c1 3d88000000 0f8374020000 c1e007 }
+ $sequence_2 = { e8???????? 31c0 eb08 898c8490000000 40 83f806 7d5a }
+ $sequence_3 = { 8b9c2490000000 8d2c18 8d4c0314 8b942400010000 8b8424fc000000 8b9c24f8000000 39c1 }
+ $sequence_4 = { e8???????? e8???????? 8b442458 8b4018 c680b500000002 8b44247c 8b4c2478 }
+ $sequence_5 = { e8???????? 0fb644240c 84c0 7539 90 658b0500000000 8b80fcffffff }
+ $sequence_6 = { 8b492c 8b5c2414 01d3 895904 8b4818 8b492c }
+ $sequence_7 = { e8???????? e8???????? 658b0500000000 8b80fcffffff 8b4018 8b0c24 894824 }
+ $sequence_8 = { c1fd1f 21dd 8d3c2e 89bc24f8000000 8b6c2450 e9???????? 39f5 }
+ $sequence_9 = { 89442408 e8???????? 8b44240c 8b4c2410 890d???????? 890d???????? 8b15???????? }
condition:
- 7 of them and filesize <237568
+ 7 of them and filesize <4186112
}
-rule MALPEDIA_Win_Salgorea_Auto : FILE
+rule MALPEDIA_Win_Royal_Dns_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "485be719-ad86-58c5-b98c-1fa9d3a194c2"
+ id = "8e27ee32-9aaf-59db-953d-0696af40bcce"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.salgorea"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.salgorea_auto.yar#L1-L163"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.royal_dns"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.royal_dns_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "a8561e214f866675e949632f523697275b0bd60d695b553a0e222be68943af7d"
+ logic_hash = "f281d4e3be759adcb32b06448d83aa5fdafcb96a4b912bbb46b43de4955e29ec"
score = 75
quality = 75
tags = "FILE"
@@ -161649,38 +168643,32 @@ rule MALPEDIA_Win_Salgorea_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b5c240c 53 9d 8b5c2404 }
- $sequence_1 = { 51 66b9b469 66f7f1 f7da }
- $sequence_2 = { 51 6698 f7db 33d2 b889510000 b98c0b0000 }
- $sequence_3 = { 66c1e303 f6d1 f8 6633d2 66b8b96a 66b9ada1 66f7f1 }
- $sequence_4 = { 66c1e306 80eb38 80e6ee f8 f6d1 52 40 }
- $sequence_5 = { 8b5c2404 f8 99 8b1424 f5 66f7d8 8b442410 }
- $sequence_6 = { 66c1e804 8b44240c 0fbafa00 0fbcd2 }
- $sequence_7 = { 8b5c240c 53 d50a 48 d40a 22c9 }
- $sequence_8 = { a1???????? 8945cc 8d45cc 3930 }
- $sequence_9 = { 8d87d8010000 50 8d83d8010000 50 }
- $sequence_10 = { 8d8850040000 8d984c040000 8b4510 8b00 }
- $sequence_11 = { 8d885c040000 8d9858040000 e9???????? 8b7508 }
- $sequence_12 = { 8d87d8010000 50 e8???????? 59 59 85c0 }
- $sequence_13 = { 8d87d8010000 50 8d83b0020000 50 e8???????? 59 }
- $sequence_14 = { 8d8860010000 0fb701 a801 740a }
- $sequence_15 = { 8d8840010000 8d9044010000 56 8b750c }
+ $sequence_0 = { 50 e8???????? 8b4dfc 8b85b4fcffff 83c404 }
+ $sequence_1 = { e8???????? 83c40c 8bc6 eb15 8d8da1f1ffff }
+ $sequence_2 = { ff15???????? 3d02010000 8b85e0fdffff 7533 6a00 50 }
+ $sequence_3 = { 4a 759a 8b55fc 85ff 7468 0fb606 c1e802 }
+ $sequence_4 = { 0fb61406 c1ea03 0fb69248132500 8811 0fb61c06 0fb6540601 c1ea06 }
+ $sequence_5 = { 80e301 0ac3 8845ed 8a45f8 8ad8 8345e805 }
+ $sequence_6 = { 8d8dfcfeffff 83c40c 33c0 2bd1 }
+ $sequence_7 = { 7504 33c0 eb0a 0fb6c8 }
+ $sequence_8 = { 0fb61c30 0fb6543001 03db 03db c1ea06 0bd3 }
+ $sequence_9 = { 8a17 8816 47 46 48 }
condition:
- 7 of them and filesize <2007040
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Spaceship_Auto : FILE
+rule MALPEDIA_Win_Putabmow_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b89dfb6c-e6cf-5987-bb83-c34e2134133d"
+ id = "118d99b8-b7d8-55d9-89f4-cf8d56f456ff"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spaceship"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spaceship_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.putabmow"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.putabmow_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "411bed797a77bb254c4227872033ffc1c4978f634b16d7697bf043a78e35e5f7"
+ logic_hash = "4091b5988ccb2a8139f14760c8b7e9d61862064b8efc99f4d36fbebf2dc41c73"
score = 75
quality = 75
tags = "FILE"
@@ -161694,34 +168682,34 @@ rule MALPEDIA_Win_Spaceship_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6689842464030000 6689842466030000 c784246803000028694100 66899c246c030000 668984246e030000 c784247003000018694100 }
- $sequence_1 = { 66c78424a40400001200 66898424a6040000 c78424a804000070674100 66c78424ac0400001300 66898424ae040000 c78424b004000064674100 }
- $sequence_2 = { 0f8415010000 bb01000000 3bfb 0f8cff000000 eb04 }
- $sequence_3 = { 84c0 7547 eb31 8d7502 40 8a10 8aca }
- $sequence_4 = { 52 e8???????? 83c418 5f 5e 5b 83c410 }
- $sequence_5 = { 85c0 7454 8a442404 84c0 }
- $sequence_6 = { 53 ff542428 8d8c2454020000 51 e8???????? }
- $sequence_7 = { 8b442424 8b0d???????? 56 50 }
- $sequence_8 = { 8d3c8d00ec4100 c1e603 8b0f 833c31ff }
- $sequence_9 = { 723c 8d8c2458030000 6a00 8d94245c050000 51 52 ff15???????? }
+ $sequence_0 = { 016306 07 015100 07 015600 0801 51 }
+ $sequence_1 = { e8???????? 8b55f0 8b4a0c 894d08 894dec 8d4118 89420c }
+ $sequence_2 = { 50 51 8d3c01 eb51 ff752c 8b7524 51 }
+ $sequence_3 = { 05eb004805 f0005005 f0005005 f0005005 f0005005 f0005005 f0005005 }
+ $sequence_4 = { c74424540f000000 85c0 7c16 7f04 85f6 7410 89442418 }
+ $sequence_5 = { 8d4c241c e8???????? c744247001000000 6a01 51 68???????? 8d4c2424 }
+ $sequence_6 = { e8???????? 83c404 89442428 c7842480000000ffffffff 8b4c241c 85c9 }
+ $sequence_7 = { 85c0 7413 6a00 8d8c24c8070000 51 8bc8 e8???????? }
+ $sequence_8 = { ff15???????? 85c0 0f8420010000 837e1408 7204 8b06 }
+ $sequence_9 = { e9???????? 8d8d50f7ffff e9???????? 8b85fcf4ffff 50 e8???????? 59 }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <704512
}
-rule MALPEDIA_Win_Redleaves_Auto : FILE
+rule MALPEDIA_Win_Safenet_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cc8fab97-eb1b-5c40-a45f-7f10d21eb6b6"
+ id = "ac7a694f-f64f-5870-a7d7-8253326e6bdf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redleaves"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redleaves_auto.yar#L1-L162"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.safenet"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.safenet_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "1a1a0a58298bb01a37c19c26700f5fe323706257844254db91cc834d1d6766e7"
+ logic_hash = "2a23436dc4bc12ef6d7e9d46230626c8fc77e510b9c9904c537608f099e6c2ff"
score = 75
- quality = 69
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -161733,39 +168721,32 @@ rule MALPEDIA_Win_Redleaves_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 7565 7279 55 7365 7254 }
- $sequence_1 = { 47 657449 7041 64647254 }
- $sequence_2 = { 54 53 51 7565 }
- $sequence_3 = { 9c 894504 9c 9c }
- $sequence_4 = { 83e901 0f85edffffff 89d0 29f8 5f 5b }
- $sequence_5 = { 8d64241c d2c0 8a01 9c }
- $sequence_6 = { 59 89f9 8d64241c d2c0 }
- $sequence_7 = { 8b04b0 8b4018 898588fdffff 8d8578fdffff }
- $sequence_8 = { 8b04b0 ff7018 ff701c 8d85acfdffff }
- $sequence_9 = { 8bec 8b550c 53 8bd9 85d2 7f05 }
- $sequence_10 = { 50 57 ffb610020000 e8???????? }
- $sequence_11 = { 8bec a1???????? 56 85c0 7452 }
- $sequence_12 = { 53 53 6804010000 8d85acfeffff }
- $sequence_13 = { 8b04b0 83c41c 53 53 }
- $sequence_14 = { 50 57 ffb60c020000 e8???????? 83c40c 8b860c020000 }
- $sequence_15 = { 54 9c 60 9c }
- $sequence_16 = { 9c 9c 8f442420 9c }
+ $sequence_0 = { 8b4004 50 c3 8b442404 668b08 }
+ $sequence_1 = { 50 ff15???????? 85c0 7511 6a01 5b }
+ $sequence_2 = { 57 8d45e6 6a02 50 e8???????? 836d0804 83c420 }
+ $sequence_3 = { 8b08 50 897920 8b4df0 83602000 e8???????? }
+ $sequence_4 = { ff7008 ff7604 ff15???????? 8bcf e8???????? }
+ $sequence_5 = { 8d4db8 c645fc01 e8???????? 6a01 8d4dcc 885dfc }
+ $sequence_6 = { 57 ff7614 ff55f8 85c0 0f85d7000000 397df4 }
+ $sequence_7 = { ffd6 83c414 8d85b0fbffff ff77f8 }
+ $sequence_8 = { ff750c e8???????? ff75ec e8???????? ff75e8 e8???????? }
+ $sequence_9 = { bf???????? 8b45d4 85c0 7505 b8???????? 57 50 }
condition:
- 7 of them and filesize <1679360
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Ddkong_Auto : FILE
+rule MALPEDIA_Win_Credraptor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0544faa5-2134-56f3-b2ce-99d63d7f2f59"
+ id = "744ed2ca-2dde-53b2-b19d-4369cb84cbb1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ddkong"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ddkong_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.credraptor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.credraptor_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "5c0b95ff5255c02a1d1a9b0883f78a353561d54588ac72196452124efb25472a"
+ logic_hash = "751cbf31cf2ad7ebff2dead521605a0ec12dc4ff6ec97fefa5bfc3c13ba5bce0"
score = 75
quality = 75
tags = "FILE"
@@ -161775,36 +168756,36 @@ rule MALPEDIA_Win_Ddkong_Auto : FILE
malpedia_rule_date = "20231130"
malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { c6459765 c6459857 c645996f c6459a77 c6459b36 c6459c34 c6459d46 }
- $sequence_1 = { c68572ffffff62 c68573ffffff6a c68574ffffff65 c68575ffffff63 c68576ffffff74 889d77ffffff ffd7 }
- $sequence_2 = { c645d36c c645d465 c645d54e c645d661 c645d76d c645d865 c645d941 }
- $sequence_3 = { 5b 5d c20c00 ff25???????? ff25???????? 8b4c2404 85c9 }
- $sequence_4 = { c645f470 ffd6 50 ffd7 8b5d0c bf04010000 }
- $sequence_5 = { 6a04 e8???????? 83c418 eb2d 6a01 }
- $sequence_6 = { 7427 837d08ff 7421 8d45dc 6a10 50 ff7508 }
- $sequence_7 = { c6855affffff65 c6855bffffff4f c6855cffffff62 c6855dffffff6a c6855effffff65 }
- $sequence_8 = { c6459763 c6459874 c6459969 c6459a76 c6459b65 c6459c43 c6459d6f }
- $sequence_9 = { c68574ffffff65 c68575ffffff63 c68576ffffff74 889d77ffffff }
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { bb???????? 8bf8 e8???????? 8945fc 8b45f8 83c408 85c0 }
+ $sequence_1 = { c6402597 895028 8b5120 89502c 8bce 8bc3 e8???????? }
+ $sequence_2 = { 8d4db4 e8???????? 85c0 754b 8d55b4 52 e8???????? }
+ $sequence_3 = { b800020000 660bc8 8b45f8 5f 894604 894624 66894e1c }
+ $sequence_4 = { a900050000 7565 837b1c00 745f 8b4df8 8b5110 52 }
+ $sequence_5 = { 8b8e14020000 8975f0 895df8 e8???????? 8bf8 83c404 897dfc }
+ $sequence_6 = { 8db5c8fdffff e8???????? 85c0 7430 8b8dccfdffff 8b7f0c 8b95c8fdffff }
+ $sequence_7 = { 894d94 8bff 8a01 dd8574ffffff dd05???????? 3c25 7409 }
+ $sequence_8 = { c7461000000000 53 c60600 e8???????? 83c404 807f4100 8bdf }
+ $sequence_9 = { bb07000000 85ff 7439 ba60240000 6685571c 7409 57 }
condition:
- 7 of them and filesize <81920
+ 7 of them and filesize <1728512
}
-rule MALPEDIA_Win_Fobber_Auto : FILE
+rule MALPEDIA_Win_Onhat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ab54349a-7d99-57ef-92f9-d6c817ce7b6a"
+ id = "59032243-71bc-5ccf-a304-ec07259d2d04"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fobber"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fobber_auto.yar#L1-L175"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.onhat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.onhat_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "16740b1e84557358ab17bd4ccf852daa4c4e1c0339646d5e9060d6d119fab8ab"
+ logic_hash = "0a14e4700b595808dab4fc1d09b95f2e90fdba52a26f4d889c5bc554e4997af3"
score = 75
quality = 75
tags = "FILE"
@@ -161818,40 +168799,34 @@ rule MALPEDIA_Win_Fobber_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89e5 51 8b4510 8b5508 8b4d0c 3002 c0c803 }
- $sequence_1 = { 89e5 6a00 ff750c ff7508 e8???????? }
- $sequence_2 = { 89e5 31c0 50 50 ff750c ff7508 50 }
- $sequence_3 = { 57 51 8b7d08 30c0 31c9 f7d1 fc }
- $sequence_4 = { e303 4f 89f8 5f 59 }
- $sequence_5 = { 8b750c 8b4d10 39f7 760e 8d0431 39f8 7607 }
- $sequence_6 = { 660fc146f9 6685c0 7515 0fb646f8 50 0fb746f6 }
- $sequence_7 = { 55 89e5 6800800000 6a00 }
- $sequence_8 = { 750f 0fb703 83f861 0f8301fe0000 }
- $sequence_9 = { 57 33714b 8aa07b74cafc 16 aa 5a }
- $sequence_10 = { 7527 e8???????? 83c020 3bf0 0f8434510100 e8???????? }
- $sequence_11 = { 000f 843d???????? 328801008bff 55 8bec ff7514 6a00 }
- $sequence_12 = { c00f84 40 17 0100 8b4d08 83600400 }
- $sequence_13 = { 7706 6205???????? 294a75 f2149c 7674 }
- $sequence_14 = { e8???????? 85f6 0f84fd610100 8b45d4 }
- $sequence_15 = { 7508 e8???????? 59 59 5d c3 53 }
+ $sequence_0 = { 68???????? e8???????? 83c404 b806000080 5f 5e 5d }
+ $sequence_1 = { c684242c01000048 889c242d010000 c684242e01000045 c684242f0100004e }
+ $sequence_2 = { 8d7c2414 bee8030000 f3ab 8b8c2424010000 b8d34d6210 f7e1 c1ea06 }
+ $sequence_3 = { 88542408 f3ab 8b8c240c200000 88542406 66ab aa 8d842410200000 }
+ $sequence_4 = { 57 32d2 b9ff070000 33c0 8d7c2409 88542408 }
+ $sequence_5 = { 53 ff15???????? 8bf0 3bf3 7526 }
+ $sequence_6 = { 33c9 8a4c2432 8ac7 52 50 c1eb18 51 }
+ $sequence_7 = { 8d7710 6a00 8d842424010000 56 50 51 e8???????? }
+ $sequence_8 = { 8d54241c 55 55 52 68???????? 55 55 }
+ $sequence_9 = { c644242852 c644242955 885c242a c644242b41 c644242c44 c644242d44 c644242e52 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Darkvnc_Auto : FILE
+rule MALPEDIA_Win_Dridex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c383bb27-eefd-56e4-99f1-129a7cd0febf"
+ id = "fd4d4346-8d83-5613-888d-88569f1753b9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkvnc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkvnc_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dridex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dridex_auto.yar#L1-L1066"
license_url = "N/A"
- logic_hash = "59a6ef1d2e391f7957c06b061626ceb22bd1c35faf4777593f7b9c101df055cb"
+ logic_hash = "7f3078493ad3e901d3230994f499bb2b8f95c8666fe5cee6d8f3649c308a4e21"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -161863,32 +168838,151 @@ rule MALPEDIA_Win_Darkvnc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c1e904 4103ce 446bc11f 48634b28 418bd0 c1ea08 881401 }
- $sequence_1 = { 488b4c2438 894148 c744244001000000 4c8b8c24a0000000 4c8b842498000000 8b942490000000 33c9 }
- $sequence_2 = { 418bca d1e9 03c1 8a4d0c 99 41f7fa d3e0 }
- $sequence_3 = { 41f7fb d2e0 41880432 49ffc2 4c3bd3 7ce5 488b5c2408 }
- $sequence_4 = { 668944244c 488d4c2440 e8???????? 668944244e c744244400000000 eb0a 8b442444 }
- $sequence_5 = { 418bc8 44888438d8000000 458d5801 44019fd8000100 418bc5 410fafc4 44899c24c0040000 }
- $sequence_6 = { ff15???????? 33d2 b903000000 f7f1 89442428 c744242400000000 ba09000000 }
- $sequence_7 = { eb0c 498b4770 4b8d0c76 4c8d2cc8 4d85ed 750a bb27030980 }
- $sequence_8 = { 8d5808 e9???????? 488b4c2460 488d85b0000000 4533c0 4889442420 4d8bcf }
- $sequence_9 = { 4d85e4 7416 498bcf e8???????? 0c80 488bcd 8ad0 }
+ $sequence_0 = { ffd6 85c0 7512 e8???????? eb03 }
+ $sequence_1 = { e8???????? b910270000 e8???????? e8???????? }
+ $sequence_2 = { c605????????01 c3 c605????????00 c3 }
+ $sequence_3 = { 83f8ff 7505 e8???????? 3d34270000 }
+ $sequence_4 = { ffd0 85c0 751f e8???????? }
+ $sequence_5 = { ffd0 e8???????? 85c0 74de }
+ $sequence_6 = { 53 53 53 6a01 53 ffd0 }
+ $sequence_7 = { eb0a e8???????? eb03 6a7f 58 }
+ $sequence_8 = { c3 31c0 c3 50 }
+ $sequence_9 = { 7406 42 803a00 75fa }
+ $sequence_10 = { 7403 56 ffd0 33f6 }
+ $sequence_11 = { e8???????? 85c0 7407 56 ffd0 }
+ $sequence_12 = { 807c241400 7409 8d4c2410 e8???????? }
+ $sequence_13 = { e8???????? 6880000000 53 53 }
+ $sequence_14 = { e8???????? 85c0 7408 6a00 ffd0 }
+ $sequence_15 = { e8???????? 6a00 8d4e1c e8???????? }
+ $sequence_16 = { e8???????? eb0a b9d0070000 e8???????? }
+ $sequence_17 = { ffd0 5b c3 33c0 }
+ $sequence_18 = { c70350000000 eb0d 3da665f63e 7506 }
+ $sequence_19 = { e8???????? 85c0 7404 6a7f }
+ $sequence_20 = { 85c0 7407 685a040000 ffd0 }
+ $sequence_21 = { e8???????? 3db20d7897 7508 c70350000000 }
+ $sequence_22 = { 8bc8 e8???????? 6a70 8bc8 e8???????? 6a73 8bc8 }
+ $sequence_23 = { 50 e8???????? 8938 8b35???????? }
+ $sequence_24 = { 6a00 6a00 8d4dfc 51 6aff }
+ $sequence_25 = { e8???????? 6a74 8bc8 e8???????? 6a74 8bc8 }
+ $sequence_26 = { 6810270000 50 e8???????? 83c410 }
+ $sequence_27 = { 7411 c7461003000000 e8???????? 894614 }
+ $sequence_28 = { 85c0 7415 6a01 6a00 6a00 }
+ $sequence_29 = { 6a00 8bcf e8???????? 50 ffd6 }
+ $sequence_30 = { eb08 83ca20 eb03 83ca10 }
+ $sequence_31 = { 46 e8???????? c1e802 3bf0 }
+ $sequence_32 = { e8???????? e9???????? 807c245000 740a }
+ $sequence_33 = { e8???????? 8d4dc4 e8???????? 5e }
+ $sequence_34 = { 6802100000 68ffff0000 ff36 ffd0 }
+ $sequence_35 = { ffd0 85c0 7510 e8???????? }
+ $sequence_36 = { c20400 55 8bec 83ec34 8365fc00 }
+ $sequence_37 = { 89442404 eb00 8b442404 89c1 89ca }
+ $sequence_38 = { 7414 31c0 89c1 8b442424 88c2 8854240f }
+ $sequence_39 = { 8b442428 6689c1 66894c2458 66894c245a }
+ $sequence_40 = { 8a442427 a801 7534 eb00 31c0 89c1 }
+ $sequence_41 = { 6a64 59 e8???????? 33c9 e8???????? }
+ $sequence_42 = { 51 6801100000 68ffff0000 ff36 }
+ $sequence_43 = { 7406 6a02 ff36 ffd0 }
+ $sequence_44 = { 740d 40 83c104 3d00100000 }
+ $sequence_45 = { 885c2407 89442408 7598 8a442407 a801 }
+ $sequence_46 = { c7461002000000 eb0f c7461003000000 e8???????? }
+ $sequence_47 = { 890424 894c2404 75dd 8b0424 }
+ $sequence_48 = { e8???????? 50 56 8bcb e8???????? 50 e8???????? }
+ $sequence_49 = { 8954242c 8b44242c 89c1 89ca }
+ $sequence_50 = { eb0a b988130000 e8???????? 33d2 }
+ $sequence_51 = { 740a 488d4c2448 e8???????? 488d4c2430 e8???????? e9???????? }
+ $sequence_52 = { e8???????? 84c0 740f 6a05 }
+ $sequence_53 = { e8???????? 8be8 85ed 7458 }
+ $sequence_54 = { e8???????? 6880000000 55 55 }
+ $sequence_55 = { ff7508 ffd0 33c0 40 5d }
+ $sequence_56 = { c3 55 8bec 837d0800 7422 }
+ $sequence_57 = { 8d4de0 51 68???????? ffd0 }
+ $sequence_58 = { 6a73 e8???????? 833f00 7523 }
+ $sequence_59 = { 6a00 6a02 ffd0 50 }
+ $sequence_60 = { e8???????? 8bc8 a1???????? ff30 }
+ $sequence_61 = { 5e c3 31c0 89c2 }
+ $sequence_62 = { e8???????? 50 ffd7 85c0 7512 }
+ $sequence_63 = { eb0c e8???????? 8bf0 eb03 6a7f 5e }
+ $sequence_64 = { 8b45cc 31c9 8b55d0 39c2 }
+ $sequence_65 = { 8038e9 89c1 8945d0 894dcc }
+ $sequence_66 = { e8???????? 50 53 8d4dd0 e8???????? 50 }
+ $sequence_67 = { 8b45e8 05ffff0000 25ffff0000 83c001 }
+ $sequence_68 = { 8b4de8 81c1ffff0000 81e1ffff0000 83c101 }
+ $sequence_69 = { 50 8b442408 8038e9 890424 7517 8b0424 8b4801 }
+ $sequence_70 = { 8b704c 2b7134 891424 89742404 894c2418 e8???????? }
+ $sequence_71 = { 8b55bc 8955c4 776a 31c0 8b4dac 8b510c }
+ $sequence_72 = { 807c0805e9 891424 74e9 8b0424 }
+ $sequence_73 = { 8b450c 8b4d08 8b503c 6689d6 6683fe00 89c7 8945f0 }
+ $sequence_74 = { 83c001 8b4de8 01c1 894de0 }
+ $sequence_75 = { 7517 8b0424 8b4801 89c2 01ca 83c205 }
+ $sequence_76 = { 8b513c 6689d6 6683fe00 89cf 8945f0 894dec }
+ $sequence_77 = { 01ca 83c205 807c0805e9 891424 }
+ $sequence_78 = { 89c7 8945f0 894dec 8955e8 897de4 }
+ $sequence_79 = { 5b 5e 5d c3 55 89e5 6a00 }
+ $sequence_80 = { 83c001 8b4df8 01c1 894df0 8b45f0 }
+ $sequence_81 = { 83c454 5b 5e 5f 5d c3 55 }
+ $sequence_82 = { 894df0 8b45f0 83c40c 5e }
+ $sequence_83 = { e9???????? 8b45e0 83c438 5f }
+ $sequence_84 = { 8945f8 894df4 8975f0 7418 8b45f4 05ffff0000 }
+ $sequence_85 = { 25ffff0000 83c001 8b4da8 01c1 }
+ $sequence_86 = { 8945c4 894dc0 885dbf 8975b8 }
+ $sequence_87 = { c3 55 89e5 57 56 53 83ec54 }
+ $sequence_88 = { 5b 5d c3 8b45d0 8b4dd4 668b55d8 31f6 }
+ $sequence_89 = { 8b45e0 83c45c 5f 5b 5e 5d }
+ $sequence_90 = { 53 56 83ec38 8b450c 8b4d08 }
+ $sequence_91 = { c7424800b00400 8b7c2418 c787cc00000000000000 c787c800000000000000 }
+ $sequence_92 = { 8955cc 74bc 8b45cc 83c454 5b 5e }
+ $sequence_93 = { 6a00 e8???????? 83c408 c3 6a00 68???????? }
+ $sequence_94 = { 8d442448 b91c000000 8b542438 891424 89442404 c74424081c000000 894c2434 }
+ $sequence_95 = { 893c24 89442404 c744240804000000 8954240c 89ac248c000000 898c2488000000 }
+ $sequence_96 = { 8945c8 75e4 83c448 5e 5f 5b 5d }
+ $sequence_97 = { 53 83ec74 8b450c 8b4d08 31d2 8b713c }
+ $sequence_98 = { 0f85dafeffff 8b45e4 83c474 5b }
+ $sequence_99 = { 55 89e5 56 57 53 83ec70 }
+ $sequence_100 = { 53 81ecb0000000 8b4508 8d4dd8 c745d800000000 }
+ $sequence_101 = { 5b 5d c3 8b45f0 8b0c8504406e00 8b55f8 39d1 }
+ $sequence_102 = { 8b0c8504406e00 8b55f8 39d1 8945ec 894de8 7212 }
+ $sequence_103 = { 83f900 89442464 0f84f2010000 b801000000 8b4c2468 8b91a4000000 }
+ $sequence_104 = { 83c470 5b 5f 5e 5d c3 }
+ $sequence_105 = { 8b45e0 83c438 5e 5b }
+ $sequence_106 = { 57 83ec20 8b4508 890424 }
+ $sequence_107 = { 890424 e8???????? 31c0 83c420 5f }
+ $sequence_108 = { c7424800c00400 8b7de4 c787cc00000000000000 c787c800000000000000 }
+ $sequence_109 = { 897dd8 8b45d8 83c444 5b 5e 5f }
+ $sequence_110 = { e8???????? 8d0d44306e00 31d2 8b75f8 89462c }
+ $sequence_111 = { 894620 890c24 c744240400000000 8955e0 e8???????? 8d0dd8306e00 890424 }
+ $sequence_112 = { 8d155e306e00 83ec04 891424 8945e8 894de4 }
+ $sequence_113 = { 8b55f4 8b75ec 89723c c7424004000000 c742442c0c0200 c7424800b00400 }
+ $sequence_114 = { 55 89e5 53 56 57 83ec38 8b450c }
+ $sequence_115 = { c742442c0c0200 c7424800b00400 8b7de4 c787cc00000000000000 }
+ $sequence_116 = { 8d0dbc306e00 890424 894c2404 e8???????? 8d0d44306e00 }
+ $sequence_117 = { 74bc 8b45cc 83c454 5f 5b 5e }
+ $sequence_118 = { 0f84e2feffff e9???????? 8b45e0 83c45c 5e 5f 5b }
+ $sequence_119 = { 56 53 57 83ec44 8b4508 }
+ $sequence_120 = { 8955e0 e8???????? 8d0dd8302700 890424 }
+ $sequence_121 = { 89462c 890c24 c744240400000000 8955d8 e8???????? 8d0d04318400 }
+ $sequence_122 = { c7424004000000 c7424499040200 c7424800c00400 8b7de4 }
+ $sequence_123 = { c3 55 89e5 83ec10 8b4508 8d0d44302500 }
+ $sequence_124 = { 56 83ec44 8b4508 8d0d30302500 31d2 890c24 }
+ $sequence_125 = { 31c0 8d0d5a232f00 8b55c8 39ca 8945cc 0f84f9000000 }
+ $sequence_126 = { 890c24 c744240400000000 8955e4 e8???????? 8d0dc9302f00 890424 894c2404 }
+ $sequence_127 = { 8d0d44302f00 31d2 8b75f8 894608 890c24 c744240400000000 }
+ $sequence_128 = { 8d0d30302700 31d2 890c24 c744240400000000 8945f0 8955ec e8???????? }
condition:
- 7 of them and filesize <606208
+ 7 of them and filesize <1040384
}
-rule MALPEDIA_Elf_Babuk_Auto : FILE
+rule MALPEDIA_Win_Newsreels_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0f03a128-b2bf-587f-bb2c-939b9b8a07cd"
+ id = "d0a51f50-02b3-5e2e-87a4-1bcf6809c906"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.babuk"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.babuk_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.newsreels"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.newsreels_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "1ffac28a8690c44fcc8b3792df7481d8deebcbe27a55524336d71b5e562fe261"
+ logic_hash = "fc1a2dbb3b05d6d5724530e791c74623a98e89ee20e6cc268616876a0ad255a8"
score = 75
quality = 75
tags = "FILE"
@@ -161902,32 +168996,32 @@ rule MALPEDIA_Elf_Babuk_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f7e2 89942488020000 898424a4000000 89e8 f7e1 89942484020000 898424a0000000 }
- $sequence_1 = { 895c2404 e8???????? eba0 0fb6c1 3d88000000 0f8374020000 c1e007 }
- $sequence_2 = { e8???????? 31c0 eb08 898c8490000000 40 83f806 7d5a }
- $sequence_3 = { 8b9c2490000000 8d2c18 8d4c0314 8b942400010000 8b8424fc000000 8b9c24f8000000 39c1 }
- $sequence_4 = { e8???????? e8???????? 8b442458 8b4018 c680b500000002 8b44247c 8b4c2478 }
- $sequence_5 = { e8???????? 0fb644240c 84c0 7539 90 658b0500000000 8b80fcffffff }
- $sequence_6 = { 8b492c 8b5c2414 01d3 895904 8b4818 8b492c }
- $sequence_7 = { e8???????? e8???????? 658b0500000000 8b80fcffffff 8b4018 8b0c24 894824 }
- $sequence_8 = { c1fd1f 21dd 8d3c2e 89bc24f8000000 8b6c2450 e9???????? 39f5 }
- $sequence_9 = { 89442408 e8???????? 8b44240c 8b4c2410 890d???????? 890d???????? 8b15???????? }
+ $sequence_0 = { 7516 39ac247c030000 7d37 5e 5d 83c8ff }
+ $sequence_1 = { 53 53 8d8424e0030000 68???????? 50 66899c24a0000000 c784249c00000001010000 }
+ $sequence_2 = { ff15???????? e9???????? 6a4d 6a08 68???????? e8???????? 8b35???????? }
+ $sequence_3 = { 6a4d f2ae f7d1 49 }
+ $sequence_4 = { 8d542460 8d4c2454 83c448 8b02 8b11 3bc2 }
+ $sequence_5 = { 83c408 85db 750a 5e 5d }
+ $sequence_6 = { 33f6 e8???????? 8bd8 83c408 85db 7516 }
+ $sequence_7 = { 51 e8???????? 8b742430 8b542431 8b442432 81e6ff000000 8b4c2433 }
+ $sequence_8 = { 8b9c24e0110000 8808 8b15???????? 8bcb 8bc1 }
+ $sequence_9 = { 51 6a09 6a08 52 66894808 e8???????? }
condition:
- 7 of them and filesize <4186112
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Ziyangrat_Auto : FILE
+rule MALPEDIA_Win_Tiop_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "61b87837-dc98-50eb-8916-bc6cbc20d03f"
+ id = "a48d1e15-9fc1-5bab-9fa2-c3c7b063ec8e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ziyangrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ziyangrat_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tiop"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tiop_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "63664fb49a7b130cd77da76446f0977d6b37fb6657ee0279b7de100f4571b771"
+ logic_hash = "62d0ea75fcf8689409f77f7c307d37bf3637d8a3da71cff9b0be16f18afd1eb3"
score = 75
quality = 75
tags = "FILE"
@@ -161941,34 +169035,34 @@ rule MALPEDIA_Win_Ziyangrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89442405 89442409 668944240d 8844240f 8b11 8d442410 }
- $sequence_1 = { c3 8b9c24a4000000 68???????? 53 8d4c2444 }
- $sequence_2 = { c68424e200000069 888424e3000000 889c24e4000000 888c24eb000000 c68424ec00000047 c68424ed00000020 }
- $sequence_3 = { b93f000000 33c0 8dbc2441010000 889c2440010000 b265 f3ab }
- $sequence_4 = { 8dbd48f7ffff 83c9ff 33c0 f2ae f7d1 83c1ff 51 }
- $sequence_5 = { 889c2410020000 89442461 889c2410070000 6689442465 889c2410030000 }
- $sequence_6 = { 8b4c2410 56 50 51 e8???????? 68???????? 8d542420 }
- $sequence_7 = { 48 0d0000ffff 40 6689442408 25ffff0000 8d1440 }
- $sequence_8 = { 50 e8???????? 83c40c 85c0 752a e8???????? }
- $sequence_9 = { 8b7c240c 8b04bd10894000 8d1cbd10894000 3d00100000 0f84c8000000 8b04bd20094100 56 }
+ $sequence_0 = { 81ec08010000 55 56 57 b940000000 33c0 8d7c2411 }
+ $sequence_1 = { ff15???????? 50 ff15???????? 8b3d???????? 8bf0 ffd7 50 }
+ $sequence_2 = { 57 33ed b94f000000 33c0 8d7c240c 896c2408 892d???????? }
+ $sequence_3 = { ff15???????? 50 8b44241c 53 50 ff5510 8b4c241c }
+ $sequence_4 = { 8b7c2410 56 8b35???????? 894704 ffd6 55 ffd6 }
+ $sequence_5 = { f3a4 8b442414 8b7500 8b4c2410 2bf0 03d0 897500 }
+ $sequence_6 = { eb2e 50 ffd3 8d7c0002 8bc7 83c003 24fc }
+ $sequence_7 = { 6a01 6a00 ffd7 8b1d???????? 8bf0 56 89742410 }
+ $sequence_8 = { 83c9ff 33c0 83c404 f2ae f7d1 6a10 49 }
+ $sequence_9 = { 8b542418 8b4c2420 8b3d???????? 8944240c 8b44242c 89542408 8b542424 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <712704
}
-rule MALPEDIA_Win_Rm3_Auto : FILE
+rule MALPEDIA_Win_Misfox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7719069f-32fe-5972-8438-aed4e36844e7"
+ id = "927dd41c-de40-5a62-bc60-3c93a08d5568"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rm3"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rm3_auto.yar#L1-L378"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.misfox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.misfox_auto.yar#L1-L171"
license_url = "N/A"
- logic_hash = "108e288ac75d378107658478aa6294381528e48e962e4f140c133bb5541af046"
+ logic_hash = "73f8e08e5f0adb2064a67b9bd6b00ebff7c94d43d789ff956746926b45ea1124"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -161980,62 +169074,38 @@ rule MALPEDIA_Win_Rm3_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d7c13ff 4a f7d2 23fa 3bf8 7609 }
- $sequence_1 = { 8b4138 8b5608 8d5410ff 48 f7d0 }
- $sequence_2 = { 8b45f8 83c628 ff4dfc 85c0 }
- $sequence_3 = { 8931 8b7004 897104 8b4808 ff7004 }
- $sequence_4 = { 034c240c 8b00 51 03c2 50 e8???????? }
- $sequence_5 = { 3bf8 7609 8b413c 8d5418ff eb0a }
- $sequence_6 = { 8b460c 03c2 394508 7303 8975f8 8b45f8 }
- $sequence_7 = { 8b5e10 8d4438ff 4f f7d7 23c7 8d7c13ff 4a }
- $sequence_8 = { 41 ff4508 ff4d0c 885405fc }
- $sequence_9 = { 57 8bc3 8d9568ffffff e8???????? 8b849d64ffffff }
- $sequence_10 = { e8???????? 8b5508 57 8bc3 8d8d58feffff e8???????? }
- $sequence_11 = { 8b750c 50 8db4b558feffff 894510 }
- $sequence_12 = { 8bf0 2b7508 f7de 1bf6 83e60b }
- $sequence_13 = { e8???????? 8bd8 85db 7420 8d45fc }
- $sequence_14 = { e8???????? 2bf3 89750c 0f88b3000000 8d3c1e 8dbcbd58feffff }
- $sequence_15 = { 744b 8975fc 6a18 5e }
- $sequence_16 = { 33d2 4533c0 410fc9 48f7b42488000000 8b15???????? }
- $sequence_17 = { 488bf3 488bce e8???????? 4885c0 488bd8 7415 }
- $sequence_18 = { 4155 4156 4157 4883ec30 4c8b05???????? 49b91ddd6c4f91f44525 }
- $sequence_19 = { 41be18000000 488b15???????? 488b4270 488bc8 48c1e90c 4833c1 488bc8 }
- $sequence_20 = { 57 4154 4155 4156 4157 4883ec20 4c8b05???????? }
- $sequence_21 = { 488bc1 48c1e81b 4833c1 33c9 480fafc3 }
- $sequence_22 = { ff15???????? 85c0 7445 488d4c2468 ff15???????? ff15???????? }
- $sequence_23 = { 488d4c2440 4c8bce 4c8bc5 498bd4 }
- $sequence_24 = { 899568ffffff 89b564ffffff 889d63ffffff 7570 31c0 89855cffffff eb16 }
- $sequence_25 = { 8d0d84308702 31d2 8b75f0 89462c 890c24 }
- $sequence_26 = { 885801 39d7 897db8 8975b4 75d7 8d45d4 }
- $sequence_27 = { a1???????? 6a00 6a00 6a00 6a00 68???????? ffd0 }
- $sequence_28 = { ffd0 8d0dd1318702 890424 894c2404 e8???????? 83f800 }
- $sequence_29 = { 52 8bb5e0fbffff 56 8985d0fbffff 8995ccfbffff 898dc8fbffff ffd7 }
- $sequence_30 = { 8945d0 8b45d0 8b4dd4 8b55ec 01ca 891424 }
- $sequence_31 = { 897dec 8955e8 8975e4 ffd3 83ec10 890424 }
- $sequence_32 = { 53 57 56 83ec20 8b450c 8b4d08 31d2 }
- $sequence_33 = { 890c24 c744240400000000 8955dc e8???????? 8d0d77318702 890424 }
- $sequence_34 = { 8b7834 8b5f3c 8945f0 89f8 01d8 813c1f50450000 }
- $sequence_35 = { 8bbd64fdffff 897e08 8b9d68fdffff 891e }
- $sequence_36 = { c7460cfe308702 c74604???????? 8b35???????? 8985e0fdffff 898ddcfdffff 8995d8fdffff }
- $sequence_37 = { 898dfcfeffff e8???????? 890424 8b853cffffff 89442404 }
- $sequence_38 = { 89e2 894a04 c70204010000 8b15???????? 8985e8fdffff 898de4fdffff }
- $sequence_39 = { 8b5924 89855cffffff 89d8 c1e81e 83e001 }
+ $sequence_0 = { eb6a 56 e8???????? 59 8365fc00 8b049d50870110 }
+ $sequence_1 = { 3de4000000 7309 8b04c598230110 5d c3 33c0 5d }
+ $sequence_2 = { c705????????01000000 6a04 58 6bc000 8b4d08 8988ac830110 }
+ $sequence_3 = { 50 e8???????? 83c40c 6b45e430 8945e0 8d8020770110 8945e4 }
+ $sequence_4 = { c745e4ec900110 a1???????? 33db 43 895de0 50 }
+ $sequence_5 = { ff37 c745b800000000 53 6a00 51 }
+ $sequence_6 = { 8b45b8 52 c70300000000 40 ff37 8945b8 }
+ $sequence_7 = { 0f8515010000 51 ba00020000 c744244800080000 8d4c2434 89442444 }
+ $sequence_8 = { 48c7c101000080 c7450b00020000 4889442420 44897507 ff15???????? }
+ $sequence_9 = { 458bc5 488d9530060000 4803d0 488b442448 488d0dc6da0000 }
+ $sequence_10 = { 488b4c2470 48894b10 48895318 e9???????? 488d5720 }
+ $sequence_11 = { 488985a0040000 4c8b95f8040000 488d052ce00000 4c8bd9 488d4c2430 }
+ $sequence_12 = { f0ff0b 7516 488d0564520100 488b4c2430 483bc8 }
+ $sequence_13 = { 488d15fdbc0000 483305???????? 488bcb 488905???????? ff15???????? 488d15f7bc0000 }
+ $sequence_14 = { ff15???????? 85c0 7547 488b0f 488d15dd6b0100 }
+ $sequence_15 = { 753e 0fb65530 0fb64531 66410fafd5 }
condition:
- 7 of them and filesize <221184
+ 7 of them and filesize <266240
}
-rule MALPEDIA_Win_Koadic_Auto : FILE
+rule MALPEDIA_Win_Unidentified_103_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e207fda4-6d66-54cd-bdbd-2bc35fe49343"
+ id = "16a9604f-a791-56b5-96cf-005a08b625a2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.koadic"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.koadic_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_103"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_103_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "4723d27185eb97d6e28808abd0dca69a0777b4b3cb3951837b42f0c81d537f3d"
+ logic_hash = "ea0101ff935636b4e103b28ee875e3c3a8b80a54f2863e597f7dff9a335e50db"
score = 75
quality = 75
tags = "FILE"
@@ -162049,33 +169119,33 @@ rule MALPEDIA_Win_Koadic_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f84b4020000 53 56 57 8b7c2424 bb01000000 83ffff }
- $sequence_1 = { 035c2408 53 58 e8???????? a3???????? 8b5c2414 035c2408 }
- $sequence_2 = { 83fb01 0f8da9000000 8b542404 ff35???????? e8???????? 8b15???????? }
- $sequence_3 = { 50 8d4c2420 51 e8???????? e9???????? 6a08 }
- $sequence_4 = { 3b1c24 7527 8b15???????? ff35???????? e8???????? 8d05c8334100 50 }
- $sequence_5 = { 72f1 eb07 8b34c5c4124100 8bc6 8d5001 }
- $sequence_6 = { 7507 c7450c02104100 53 56 8b7508 f6462c01 57 }
- $sequence_7 = { 50 68???????? ff35???????? e8???????? 21c0 7414 ff35???????? }
- $sequence_8 = { e8???????? 890424 6800000000 e8???????? a3???????? ff35???????? ff742404 }
- $sequence_9 = { ff15???????? 8b542434 81c200000800 89542428 eb04 8b5c2414 8b442434 }
+ $sequence_0 = { 85db 0f8506030000 8b442470 ffd0 8b542478 81c41c070000 }
+ $sequence_1 = { 8954240c 8b9424e4000000 89742404 83ea04 89542408 8b8404cc0b0000 8b00 }
+ $sequence_2 = { 83ec08 85c0 7439 8b8424bc010000 890424 8b44246c ffd0 }
+ $sequence_3 = { 0fb613 89c3 8d6c11e0 01d1 }
+ $sequence_4 = { 890424 8b842488000000 ffd0 83ec08 8b842484010000 890424 8b8424a4000000 }
+ $sequence_5 = { 31db ffd6 c684249803000000 898424bc000000 b878650000 6689842496030000 b865000000 }
+ $sequence_6 = { c744240804000000 89442404 8b842484010000 890424 8b8424ac000000 ffd0 }
+ $sequence_7 = { 0f84d3070000 81fd03030000 0f85d5060000 8b842484010000 c744240402000000 89fb be01000000 }
+ $sequence_8 = { 8bb4244c010000 01ca 880431 0fb68424a5010000 8844290a 0fb68424a6010000 8844290b }
+ $sequence_9 = { 83ec08 0fb68c2450040000 84c9 741f 31d2 83c201 }
condition:
- 7 of them and filesize <180224
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Electric_Powder_Auto : FILE
+rule MALPEDIA_Win_Bhunt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6da8b24a-07fd-5fc6-a509-6cbc31d92594"
+ id = "5486e0c5-654b-5b43-b68d-10c1b78a90c9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.electric_powder"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.electric_powder_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bhunt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bhunt_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "38cd56e857c27f71ed9be956ee8235c5f49da7b5b360cadbe53a42a73ba8199e"
- score = 75
+ logic_hash = "f1702c9f5cf7c98ee774218c3a385f625fff81483374971b8b6cf77e6b060de8"
+ score = 50
quality = 75
tags = "FILE"
version = "1"
@@ -162088,32 +169158,32 @@ rule MALPEDIA_Win_Electric_Powder_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3b4e08 0f8324010000 8b4604 c704c810000000 8b4608 83e801 8945fc }
- $sequence_1 = { 03c0 660f289800904300 660f2835???????? 660f59cf 660f58d1 660f70caee f20f59d7 }
- $sequence_2 = { 8d8d20fdffff c78530fdffff00000000 c78534fdffff0f000000 c68520fdffff00 e8???????? c745fc00000000 8d8d20fdffff }
- $sequence_3 = { 7202 8b39 8b4110 85c0 7449 48 83ceff }
- $sequence_4 = { 0f8389010000 8b5604 3bc8 0f8388010000 8b44fa04 8944ca04 }
- $sequence_5 = { c645fc20 51 8bd0 8d8d78fcffff e8???????? 83c404 68???????? }
- $sequence_6 = { 50 51 8d8d68faffff e8???????? 83bd7cfaffff08 8d8568faffff }
- $sequence_7 = { 7202 8b3f 83fa08 731a }
- $sequence_8 = { 83c404 89b518efffff 85f6 0f84be000000 8b8d40efffff 03c9 }
- $sequence_9 = { 83f8ff 773b 83f8ef 7736 8b4f04 83c010 50 }
+ $sequence_0 = { feca f8 d0c2 f5 f8 32da 80ffd4 }
+ $sequence_1 = { 85c0 751a 8b442410 50 8bd5 8bc3 e8???????? }
+ $sequence_2 = { 8902 660fbcc0 8b07 8dbf04000000 663bcf 66f7c4ab75 33c3 }
+ $sequence_3 = { bbff000000 8bc3 8d7c2414 66c784241e1200000800 e8???????? 59 8d8600120000 }
+ $sequence_4 = { 0fb7c2 8b55f0 03450c 2bd1 0fb74dfc }
+ $sequence_5 = { ff7304 c645d405 56 e8???????? ff7304 ff36 e8???????? }
+ $sequence_6 = { 83a530ffffff00 c7852cffffff01000000 ffb530ffffff ffb52cffffff 52 ffb544ffffff e8???????? }
+ $sequence_7 = { 5f 9c 04f8 26ed c59818579fa0 5f e7e6 }
+ $sequence_8 = { 52 3a21 a7 a2???????? 50 9d 03890023b0b3 }
+ $sequence_9 = { ac 2a7279 bfae9603f7 6c a3???????? 9f 97 }
condition:
- 7 of them and filesize <565248
+ 7 of them and filesize <19161088
}
-rule MALPEDIA_Win_Lazarus_Killdisk_Auto : FILE
+rule MALPEDIA_Win_Nimgrabber_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "37962373-db6b-5a82-a667-796eaa294f65"
+ id = "3ff9ecdf-434a-5531-ae47-14063d732bcc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lazarus_killdisk"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lazarus_killdisk_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nimgrabber"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nimgrabber_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "f14584aa2cdb4f56b5df407c3c19c0436c1677938983b3e7a6f77f9ce3d89a22"
+ logic_hash = "d88020b2287429253ba602c12d16ae36bc236c828c7e32d50b3c884fb53a1e20"
score = 75
quality = 75
tags = "FILE"
@@ -162127,71 +169197,71 @@ rule MALPEDIA_Win_Lazarus_Killdisk_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b530c 8b4308 33c9 8d4402ff 0fa4c109 }
- $sequence_1 = { e8???????? 83c40c 57 8d4c242c }
- $sequence_2 = { 8bf0 83feff 740e 8bce e8???????? 56 }
- $sequence_3 = { 6a00 6800000002 ffd3 8bf0 83feff 7409 6a00 }
- $sequence_4 = { 7438 8d55f0 52 68???????? }
- $sequence_5 = { 89842430020000 53 56 57 e8???????? 8b1d???????? 33ff }
- $sequence_6 = { 68???????? 57 ff15???????? 8b45a2 8b4da6 8b55ae }
- $sequence_7 = { 8d95c0fdffff c1e009 52 50 57 }
- $sequence_8 = { 40 83c610 8985e4fdffff 83f804 }
- $sequence_9 = { 8d5de8 8955ec 894df4 8945f0 e8???????? 807db600 }
+ $sequence_0 = { 0f8fa7000000 c7819814000000400000 b800400000 c744240c04000000 c744240800300000 39c7 0f8fd0010000 }
+ $sequence_1 = { 8b842490000000 83c004 89442430 0f80de2e0000 8b8424d8000000 8b00 39442430 }
+ $sequence_2 = { c705????????b83b4800 c705????????20000000 c705????????02000000 c705????????00254800 668915???????? c605????????01 c705????????00000000 }
+ $sequence_3 = { 8d4710 8d5f08 be???????? b90b000000 c743042b000000 c747082b000000 89c7 }
+ $sequence_4 = { c1f80c 89442418 89e8 0fb6c0 8d0483 8944241c 8b8084100000 }
+ $sequence_5 = { 7f0d b9???????? e8???????? 8b4514 83e801 0f8067160000 894514 }
+ $sequence_6 = { c70424???????? 894c2474 89542404 e8???????? 8b4c2474 31c0 894b04 }
+ $sequence_7 = { 8b6f04 81fd0000003f 7e28 c704240000003f 89fa 89f1 e8???????? }
+ $sequence_8 = { 89f9 e8???????? 8b4c2454 89da e8???????? 8b07 }
+ $sequence_9 = { 740a 8b0b 85c9 0f88a6020000 e8???????? 31ed 89442430 }
condition:
- 7 of them and filesize <209920
+ 7 of them and filesize <1238016
}
-rule MALPEDIA_Win_Derohe_Auto : FILE
+rule MALPEDIA_Win_Hermes_Ransom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "082c8bb6-5e90-542b-87a2-cd5536e22be3"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.derohe"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.derohe_auto.yar#L1-L134"
+ id = "88136c82-87ab-5f89-8963-9afb9534a540"
+ date = "2021-10-07"
+ modified = "2021-10-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hermes_ransom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hermes_ransom_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "3afbf42b0aba27d1df54ba6496f4a588ae2f7c7ec09fa3d922d168dfad26c783"
+ logic_hash = "2bb9637b7e3ee9fcdd4e957eade001e8c8132e1b7c987ea6727ab44eda025915"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
+ malpedia_rule_date = "20211007"
+ malpedia_hash = "e5b790e0f888f252d49063a1251ca60ec2832535"
+ malpedia_version = "20211008"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd0 8b542404 c60424e3 8b02 ffd0 8b542404 c6042405 }
- $sequence_1 = { ffd0 8b542404 c604247d 8b02 ffd0 8b542404 c60424df }
- $sequence_2 = { ffd0 8b542404 c60424a1 8b02 ffd0 8b542404 c60424e8 }
- $sequence_3 = { ffd0 8b442418 8b4c2414 8b542420 898a8c010000 8b0d???????? 85c9 }
- $sequence_4 = { ffd0 8b542404 c60424de 8b02 ffd0 8b542404 c60424b8 }
- $sequence_5 = { ffd0 8b542404 c60424cc 8b02 ffd0 8b542404 c6042462 }
- $sequence_6 = { e8???????? 8b44241c 8b4c2420 8b542424 8b5c2434 894b08 89530c }
- $sequence_7 = { ffd0 8b542404 c604247d 8b02 ffd0 8b542404 c60424a4 }
- $sequence_8 = { ffd2 8b442404 83c0fa 83f801 0f869e000000 90 8b4c242c }
- $sequence_9 = { ffd0 8b542404 c60424e0 8b02 ffd0 8b542404 c6042407 }
+ $sequence_0 = { 59 59 8945e0 837ddc00 7506 837de000 7405 }
+ $sequence_1 = { 8d45dc 50 ff75d8 8d8560ffffff 50 ff75e0 ff15???????? }
+ $sequence_2 = { 33c0 668945e2 33c0 8945e4 8945e8 837df020 }
+ $sequence_3 = { 6a00 8d85a4f9ffff 50 ff15???????? 5f 5e 8be5 }
+ $sequence_4 = { 0fb7844504f7ffff 83f83b 741f 8b45d8 8b4df0 668b8c4d04f7ffff }
+ $sequence_5 = { 8365c800 8365d000 c745b840420f00 8365e000 eb07 8b45e0 40 }
+ $sequence_6 = { 59 6bc900 668981e8c34000 6a02 }
+ $sequence_7 = { 59 59 6a0f 6a00 8d45bc 50 }
+ $sequence_8 = { 8365f000 8b45f0 8945f8 837df800 7456 }
+ $sequence_9 = { 83e002 7415 ff750c ff75fc e8???????? 59 }
condition:
- 7 of them and filesize <35788800
+ 7 of them and filesize <7192576
}
-rule MALPEDIA_Win_Vflooder_Auto : FILE
+rule MALPEDIA_Win_Sunorcal_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9887b2d4-11f9-501f-8a80-a11d525400b9"
+ id = "8d478635-7b1a-5ec4-85a6-3854fefcfed4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vflooder"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vflooder_auto.yar#L1-L106"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sunorcal"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sunorcal_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "c395df9bf0cea55ef8201fced5f6d58ff4786707da9a8f0c23e3a94a9aa3418e"
+ logic_hash = "58249461fa7cf2580b3033b5e590d54e14d2db390f8c7cf00dbe39cb0b927df2"
score = 75
quality = 75
tags = "FILE"
@@ -162205,34 +169275,34 @@ rule MALPEDIA_Win_Vflooder_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 60 ff35???????? 8f442438 9c }
- $sequence_1 = { 3b45f0 60 9c 8d642424 }
- $sequence_2 = { 9c 60 9c 9c 8d642430 }
- $sequence_3 = { 9c ff742404 8d642434 e9???????? }
- $sequence_4 = { e9???????? ff742408 8f4500 60 }
- $sequence_5 = { 0000 43 7265 61 7465 }
- $sequence_6 = { f5 83ef04 f5 ff37 }
- $sequence_7 = { e8???????? 0000 43 7265 }
- $sequence_8 = { b02e f5 f2ae e8???????? }
- $sequence_9 = { 9c f2ae 9c 9c }
+ $sequence_0 = { 6a03 e8???????? cc 55 8bec 83ec0c a1???????? }
+ $sequence_1 = { c21000 8b442404 8b00 813863736de0 752a 83781003 7524 }
+ $sequence_2 = { 5e 5b c21000 8b442404 8b00 813863736de0 752a }
+ $sequence_3 = { ff15???????? 33c0 c3 c3 55 8bec }
+ $sequence_4 = { 7c02 eb0e e8???????? e8???????? 85c0 }
+ $sequence_5 = { 5b c21000 8b442404 8b00 813863736de0 }
+ $sequence_6 = { 68b7000000 ff15???????? 6a64 68???????? }
+ $sequence_7 = { 5b c21000 8b442404 8b00 813863736de0 752a 83781003 }
+ $sequence_8 = { ff15???????? 68b7000000 ff15???????? 6a64 68???????? 6a67 }
+ $sequence_9 = { 68???????? ff15???????? 33c0 c3 c3 55 8bec }
condition:
- 7 of them and filesize <860160
+ 7 of them and filesize <172032
}
-rule MALPEDIA_Win_Final1Stspy_Auto : FILE
+rule MALPEDIA_Win_Winnti_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7c2b072b-c27f-54e3-a7df-2dc853163db8"
+ id = "3bce81c4-b806-55af-b179-e7a33535f793"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.final1stspy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.final1stspy_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winnti"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.winnti_auto.yar#L1-L247"
license_url = "N/A"
- logic_hash = "654817f55704ecafec1c10904f1a6a25212804a4fb3c152f1d4aecbab6ecef0c"
+ logic_hash = "bb0b6cf106deb97c4eb44fec946685f152141bb95569eea2bec56d5f75cb75c8"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -162244,32 +169314,46 @@ rule MALPEDIA_Win_Final1Stspy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 03d0 8b45fc 8a4803 c1e206 80f93d 7508 }
- $sequence_1 = { 51 56 8d55fc c745fc00000000 e8???????? 8bf0 }
- $sequence_2 = { 8a1d???????? 8b4dfc 83c104 894dfc }
- $sequence_3 = { eb2e 85ff 7594 b8???????? 6690 3ad9 }
- $sequence_4 = { 81e7ff070080 7908 4f 81cf00f8ffff }
- $sequence_5 = { 0f114c0f10 83c120 3bca 7cd4 3bce }
- $sequence_6 = { 84db 7410 8a11 8acb 3aca 7425 8a4801 }
- $sequence_7 = { 81cf00f8ffff 47 33f6 85ff 7e0a }
- $sequence_8 = { 8945fc 57 8d7e01 8a06 }
- $sequence_9 = { 7410 8a11 8acb 3aca }
+ $sequence_0 = { 51 52 8bce e8???????? 53 8bf8 ff15???????? }
+ $sequence_1 = { ff15???????? 663dffff 747b 663dfeff 7475 8b942494020000 83c9ff }
+ $sequence_2 = { c22000 8b4d00 56 6a03 68c8000000 51 ff15???????? }
+ $sequence_3 = { 8bf0 83c404 85f6 7509 5f 5e 83c8ff }
+ $sequence_4 = { 807a025c 75bf 83c203 8a0a 56 33f6 b801000000 }
+ $sequence_5 = { 895e08 895e0c ffd7 50 }
+ $sequence_6 = { 83c404 85db 0f84da000000 55 8b6c2430 56 57 }
+ $sequence_7 = { 6a01 52 6a02 8974243c 89742430 c644244800 ff15???????? }
+ $sequence_8 = { 488d8a40000000 e9???????? 488b8a40000000 4883c108 e9???????? 488b8a80000000 e9???????? }
+ $sequence_9 = { 48037c2470 48897c2478 488b8c2400010000 4885c9 741f 4183fe01 7513 }
+ $sequence_10 = { 4c8d25b6f10000 498b0c24 4d8bc5 488bd3 e8???????? 85c0 }
+ $sequence_11 = { 4803f7 4c03f7 41ffca 660f1f840000000000 478d0c1a }
+ $sequence_12 = { 75f8 488d15e1160000 b12e 482bd0 }
+ $sequence_13 = { 4963f9 48897db7 453bc5 0f8e4f020000 418bc0 412bc5 448be0 }
+ $sequence_14 = { 3918 0f4c18 3bcb 0f8d87000000 488d3d979c0a00 ba58000000 488bcd }
+ $sequence_15 = { 4c2bc1 0f1f00 410fb6440801 8811 }
+ $sequence_16 = { 4d85ed 7429 488d15fcd70a00 498bcd }
+ $sequence_17 = { 4c8bc7 48894768 488d4567 ba18822200 }
+ $sequence_18 = { 4889542410 53 4881ecb0000000 33db }
+ $sequence_19 = { 488d542450 4438742450 740a 6690 48ffc2 }
+ $sequence_20 = { 488d1debad0000 488d3d64ae0000 eb0e 488b03 4885c0 7402 }
+ $sequence_21 = { 8a45d9 4b8b8cf800a20b00 88443139 4b8b84f800a20b00 8854303a eb4c 493bde }
+ $sequence_22 = { 57 4156 4157 4883ec30 4c8bf1 33ff }
+ $sequence_23 = { 44895c391c 4963cb 488bd1 48c1fa10 498b8680000000 }
condition:
- 7 of them and filesize <557056
+ 7 of them and filesize <1581056
}
-rule MALPEDIA_Win_Maui_Auto : FILE
+rule MALPEDIA_Win_Purelocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3b08a716-7f90-5bcd-af98-705f5527c8fd"
+ id = "d1d522a1-058f-5ee5-85f2-56e8688f09bf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maui"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maui_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.purelocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.purelocker_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "da972ed3bba518a07c1d6cad703f6be4a891f59859651a81726f8cacb62eabef"
+ logic_hash = "42140169d70d3c64021f0eb71e13968d0cb2f62e4e2540159ee39f96b2cca71d"
score = 75
quality = 75
tags = "FILE"
@@ -162283,71 +169367,71 @@ rule MALPEDIA_Win_Maui_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b1b 895c2410 a810 0f841a010000 57 51 25c0000000 }
- $sequence_1 = { 83c40c 85c0 7515 53 e8???????? 57 e8???????? }
- $sequence_2 = { 83c404 5f 5b 5e 5d c3 8bce }
- $sequence_3 = { c1e010 094610 0fb64101 41 99 0fa4c208 095614 }
- $sequence_4 = { e8???????? 83c408 85c0 0f846b010000 3b5d20 8d4518 7e0a }
- $sequence_5 = { 85c0 750a 68d0010000 e9???????? 8b542438 8b02 56 }
- $sequence_6 = { e8???????? 83c40c 85c0 0f849b010000 8d442428 57 50 }
- $sequence_7 = { 8bac24a4000000 f7463c00010000 753a 8b4628 8b10 89542460 8b5004 }
- $sequence_8 = { 50 50 50 50 e8???????? 83c414 ff33 }
- $sequence_9 = { e8???????? 53 89442438 8907 e8???????? 53 89442460 }
+ $sequence_0 = { c7042400000000 8d442434 50 8d842440040000 50 8d842440020000 }
+ $sequence_1 = { c1e908 81e1ff000000 331c85201c0110 8b442414 8b148d20180110 335f08 }
+ $sequence_2 = { 8b442410 0fb6c0 330c8520300110 8bc6 }
+ $sequence_3 = { 6a00 85c9 59 751a 8bda 53 }
+ $sequence_4 = { 53 ba17000000 83ec04 c7042400000000 4a 75f3 e8???????? }
+ $sequence_5 = { 8d1524400110 59 e8???????? 741e 8b542468 52 }
+ $sequence_6 = { 50 31c0 50 8b15???????? 52 e8???????? 5a }
+ $sequence_7 = { e8???????? 8d1524400110 8d0d285e0110 e8???????? 8d1524400110 8d0d845d0110 }
+ $sequence_8 = { e8???????? e8???????? 011424 e8???????? 58 8b542408 52 }
+ $sequence_9 = { 50 680a000000 ff742418 e8???????? e8???????? 52 e8???????? }
condition:
- 7 of them and filesize <1616896
+ 7 of them and filesize <193536
}
-rule MALPEDIA_Win_Mulcom_Auto : FILE
+rule MALPEDIA_Win_Unidentified_063_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8b428090-6e4d-587e-a305-32305b35e9f8"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mulcom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mulcom_auto.yar#L1-L132"
+ id = "d22cba4e-b95b-5578-ac95-09534bd7dc14"
+ date = "2022-11-21"
+ modified = "2022-11-25"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_063"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_063_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "0fb6c90115244992995c28d6d59f0334f00cc1075a3607803abc8b37e1b5b55f"
+ logic_hash = "14c180eecdf0e6fbf2b936d6c444ad58c2e649e1fa770106e8719057ee1aefbd"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
+ malpedia_rule_date = "20221118"
+ malpedia_hash = "e0702e2e6d1d00da65c8a29a4ebacd0a4c59e1af"
+ malpedia_version = "20221125"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4883ec40 33ff 48c740f007000000 488978e8 488d4c2420 668978d8 4d85c0 }
- $sequence_1 = { e8???????? 4c8b4310 488bd3 48837b1808 7203 488b13 4981f804010000 }
- $sequence_2 = { e8???????? 488d4de8 e8???????? 488d4dc8 e8???????? 488d4da8 e8???????? }
- $sequence_3 = { 48897020 488b05???????? 4833c4 48898510020000 498bf8 488bda 4889542438 }
- $sequence_4 = { 33d2 33c9 458bc6 ff15???????? 85c0 0f8412020000 }
- $sequence_5 = { e8???????? 488d4c2460 e8???????? 90 488dbea0000000 488d9580010000 }
- $sequence_6 = { 4c897de0 488d45d0 48837de810 480f4345d0 448838 8b542440 483b55e0 }
- $sequence_7 = { 4d63df 4c015d00 478d6c2fff eb3f 4585e4 7511 8b74243c }
- $sequence_8 = { cc e8???????? cc 4c8bc2 488b5108 48395110 0f848b000000 }
- $sequence_9 = { 410fb7d0 ff5018 440fb7c0 49ffce 418bff 66453be0 0f45fb }
+ $sequence_0 = { 8d43cf 83f819 770c 6689b550030000 e9???????? }
+ $sequence_1 = { 7363 488bf3 4c8d35dfc40100 83e63f 488beb 48c1fd06 48c1e606 }
+ $sequence_2 = { e8???????? 4863f8 488d3588800100 488bcb }
+ $sequence_3 = { 0f11442478 4c8b4708 488d442470 493bc0 7362 488b07 488d4c2470 }
+ $sequence_4 = { 4885c9 7407 48ff25???????? c3 48894c2408 57 4883ec50 }
+ $sequence_5 = { 83f801 7518 488b0d???????? 488d05bf5f0100 483bc8 7405 e8???????? }
+ $sequence_6 = { 8b8c96d0cd0200 8b534c 33c8 0fb6c1 }
+ $sequence_7 = { 0f84e7000000 488b0e 483bc8 740e 4885c9 7406 }
+ $sequence_8 = { 498bc2 418be9 48c1f806 488d0d708c0100 4183e23f 4903e8 }
+ $sequence_9 = { 488d158a5a0200 488bcb e8???????? 85c0 7499 488d157f5a0200 488bcb }
condition:
- 7 of them and filesize <867328
+ 7 of them and filesize <475136
}
-rule MALPEDIA_Win_Gold_Dragon_Auto : FILE
+rule MALPEDIA_Win_Crutch_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "eec5e3d6-5655-50ac-8840-a288ffff9f65"
+ id = "1c62c9a2-5abd-50e0-9062-2bd78d3ac79d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gold_dragon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gold_dragon_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crutch"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crutch_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "eed1b3c473c88d18a03100aac4bac22cf30de04dad45247c9c63eb23fa6434a1"
+ logic_hash = "af046e99ef1615cf66ae4969fa3fcc0ac2b09e87e76d784694e80263151a794f"
score = 75
quality = 75
tags = "FILE"
@@ -162361,32 +169445,32 @@ rule MALPEDIA_Win_Gold_Dragon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8bc6 83e61f c1f805 59 8b048500954000 8d0cf6 }
- $sequence_1 = { 85c0 a3???????? 0f848d030000 8b15???????? 68???????? }
- $sequence_2 = { 0fb6fa 3bc7 7714 8b55fc 8a9200844000 }
- $sequence_3 = { a3???????? 0f842d040000 8b15???????? 68???????? }
- $sequence_4 = { a3???????? 0f8422030000 a1???????? 68???????? 50 ffd6 }
- $sequence_5 = { 8b7d08 8d054c914000 83780800 753b b0ff }
- $sequence_6 = { 8db60c844000 bf???????? a5 a5 59 }
- $sequence_7 = { ffd6 85c0 a3???????? 0f84a2050000 }
- $sequence_8 = { ffd6 85c0 a3???????? 0f84ef010000 68???????? ffd7 }
- $sequence_9 = { 85c0 a3???????? 0f8424020000 8b15???????? 68???????? 52 }
+ $sequence_0 = { 7536 8b8740030000 f7404000c00000 51 740f 8b4e6c 51 }
+ $sequence_1 = { 8b442430 85c0 742b 8b942488000000 8b8c2484000000 52 8b54243c }
+ $sequence_2 = { 8b01 50 ff30 51 ff32 8bcb e8???????? }
+ $sequence_3 = { 50 8d4ddc e8???????? eb3a 8dbd1cffffff 8d3cd7 8d8514ffffff }
+ $sequence_4 = { 8b6c2408 7426 8b03 50 ff15???????? 8b8efc040000 51 }
+ $sequence_5 = { 0f84f9000000 b9???????? 8bc6 8d642400 8a10 3a11 751a }
+ $sequence_6 = { 81c2cc000000 89542408 8b54240c 89542404 e9???????? 81f9244e0000 }
+ $sequence_7 = { 7506 8b7c2428 eb4a 41 51 ff15???????? 8bf8 }
+ $sequence_8 = { b823000000 5e c3 8d471f c1e004 8bcf c1e104 }
+ $sequence_9 = { 8bf1 8a02 8806 8d4e18 8b4208 894608 8b420c }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <1067008
}
-rule MALPEDIA_Win_Buer_Auto : FILE
+rule MALPEDIA_Win_Pngdowner_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "29f2986a-0230-51bb-b9a2-7f550ca2fb77"
+ id = "31e7b95d-0a01-5118-aefe-72f10c1de52f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.buer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.buer_auto.yar#L1-L170"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pngdowner"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pngdowner_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "2390d8b9be10e4a78955cb4e4f9dfe589bef2af5ea30193017caa2f367cbde8d"
+ logic_hash = "73611f5253baf7f95cf22059dc76ddead3ab9941ef229c965d83aeede8e284a3"
score = 75
quality = 75
tags = "FILE"
@@ -162400,38 +169484,32 @@ rule MALPEDIA_Win_Buer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4014 8b00 8b4010 8945fc 61 8b45fc }
- $sequence_1 = { 7507 e8???????? eb05 e8???????? 46 83fe20 7cd1 }
- $sequence_2 = { 60 64a130000000 8b400c 8b4014 8b00 8b4010 }
- $sequence_3 = { 8bc2 eb19 33c0 85d2 7e13 3bc7 }
- $sequence_4 = { 8b55e8 015158 8b55d8 894148 8b45dc 03c6 89414c }
- $sequence_5 = { c1e104 0bc8 6a02 5b }
- $sequence_6 = { 8945f8 ff15???????? 59 59 85c0 }
- $sequence_7 = { 8365fc00 53 56 57 60 64a130000000 8b400c }
- $sequence_8 = { c744240402000000 8d442428 c7442408???????? c744240c01000000 }
- $sequence_9 = { e8???????? 80fb03 7705 80fb02 }
- $sequence_10 = { e8???????? 0f0b b92c000000 ba01000000 e8???????? 0f0b 89f9 }
- $sequence_11 = { c744240401000000 c7442408???????? c744240c01000000 89442410 }
- $sequence_12 = { e8???????? 56 6a00 50 e8???????? c7471c01000000 }
- $sequence_13 = { c744240800000000 57 e8???????? 85c0 }
- $sequence_14 = { cd29 0f0b cc 8b442404 833800 7406 ba???????? }
- $sequence_15 = { e8???????? 80fb05 ba01000000 0fb6c3 }
+ $sequence_0 = { 8b4508 c705????????01000000 50 a3???????? e8???????? 8db6bcdc4000 bf???????? }
+ $sequence_1 = { ff15???????? 85c0 a3???????? 741b 6a00 6a00 }
+ $sequence_2 = { 7552 833c8580e0400000 53 57 }
+ $sequence_3 = { c74050c0b54000 c7401401000000 c3 56 57 ff15???????? }
+ $sequence_4 = { c1ff05 83e11f 8b3cbd40e64000 8d0cc9 8d3c8f eb05 bf???????? }
+ $sequence_5 = { 83c8ff 5b 81c420000100 c3 8b3d???????? 8d4c2420 }
+ $sequence_6 = { ff74240c e8???????? 83c40c c3 e8???????? 8b4c2404 894814 }
+ $sequence_7 = { c3 33c0 5e c3 8b442404 c74050c0b54000 }
+ $sequence_8 = { 8b1d???????? b900400000 33c0 8d7c2420 8d542420 }
+ $sequence_9 = { ff742404 e8???????? 59 c3 56 8bf1 6a1b }
condition:
- 7 of them and filesize <3031040
+ 7 of them and filesize <131072
}
-rule MALPEDIA_Win_Chaperone_Auto : FILE
+rule MALPEDIA_Win_Poslurp_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5069c84b-f6f9-588d-8536-63d238bdb1de"
+ id = "7a8f0443-88b1-5a4f-a35b-b7bc9acf8924"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chaperone"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chaperone_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poslurp"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poslurp_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "9d40dc4ee44ea2fe4f6bf05be1cccf6d78aa19e4569d2284fce73479ea6dfe7a"
+ logic_hash = "95156f0f62f3b9458f6ba6ac285abaa70aca50d75127c0a8cc32d91b8191c0ea"
score = 75
quality = 75
tags = "FILE"
@@ -162445,33 +169523,33 @@ rule MALPEDIA_Win_Chaperone_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f3a4 488dbc2458010000 488d35d6490100 b918000000 f3a4 48c784245001000000000000 83bc249002000000 }
- $sequence_1 = { 85c9 782e 3b0d???????? 7326 4863c9 488d15f8ca0100 488bc1 }
- $sequence_2 = { eb05 1bc0 83d8ff 85c0 0f8475010000 488d15aeaf0100 488d8c24ec040000 }
- $sequence_3 = { 488d9424a8020000 488b4c2430 ff15???????? 81bc24a802000003010000 0f8486000000 }
- $sequence_4 = { 751f 83bc24d001000002 7515 83bc24c801000001 720b c78424a801000005000000 83bc24c401000006 }
- $sequence_5 = { 488d94088c020000 488b8c2438490000 e8???????? 89842444490000 83bc244449000000 }
- $sequence_6 = { ff15???????? 488905???????? 48833d????????00 750b c78424c801000002000000 488d9424a0020000 488b8c2480030000 }
- $sequence_7 = { 0fb702 66898424d0000000 488d9424f0020000 488d8c24d0000000 ff15???????? 488d8c24d0000000 ff15???????? }
- $sequence_8 = { ff15???????? 66ba5c00 488d4c2440 e8???????? 4889842450020000 488b842450020000 4883c002 }
- $sequence_9 = { 49c1fe05 4c8d3d40cc0100 83e61f 486bf658 4b8b04f7 0fbe4c3008 83e101 }
+ $sequence_0 = { 0f87fd000000 668378203d 0f85f2000000 498bce }
+ $sequence_1 = { cc 33c9 ff15???????? cc 488bac2440010000 }
+ $sequence_2 = { 488bf5 498bfc f3a4 498bcc e8???????? }
+ $sequence_3 = { ff15???????? 4c8be8 4885c0 0f84c2000000 4863453c }
+ $sequence_4 = { 488d15a9100000 41b93f000f00 4533c0 48c7c102000080 }
+ $sequence_5 = { 418bc1 41ffc0 486bc022 4803c2 48ffc2 }
+ $sequence_6 = { 0f8301010000 418bd6 498bcf 8bfb 412bd7 }
+ $sequence_7 = { 0f84ae000000 80393d 0f85a5000000 418bd6 }
+ $sequence_8 = { 418bc8 ffce 488bd5 2bcd 8bfb }
+ $sequence_9 = { 488bd8 4883f8ff 0f84c8010000 448b05???????? 4889ac24a0020000 4889b424a8020000 4889bc24b0020000 }
condition:
- 7 of them and filesize <373760
+ 7 of them and filesize <50176
}
-rule MALPEDIA_Win_Safenet_Auto : FILE
+rule MALPEDIA_Win_Wndtest_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ac7a694f-f64f-5870-a7d7-8253326e6bdf"
+ id = "a60fab9e-f350-5d99-8e55-84b700dcda0e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.safenet"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.safenet_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wndtest"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wndtest_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "2a23436dc4bc12ef6d7e9d46230626c8fc77e510b9c9904c537608f099e6c2ff"
- score = 75
+ logic_hash = "c7d0b1dfe74b472c5174a4761a9428ccee3d781f889972cf04ca5a6d741a211f"
+ score = 50
quality = 75
tags = "FILE"
version = "1"
@@ -162484,32 +169562,32 @@ rule MALPEDIA_Win_Safenet_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4004 50 c3 8b442404 668b08 }
- $sequence_1 = { 50 ff15???????? 85c0 7511 6a01 5b }
- $sequence_2 = { 57 8d45e6 6a02 50 e8???????? 836d0804 83c420 }
- $sequence_3 = { 8b08 50 897920 8b4df0 83602000 e8???????? }
- $sequence_4 = { ff7008 ff7604 ff15???????? 8bcf e8???????? }
- $sequence_5 = { 8d4db8 c645fc01 e8???????? 6a01 8d4dcc 885dfc }
- $sequence_6 = { 57 ff7614 ff55f8 85c0 0f85d7000000 397df4 }
- $sequence_7 = { ffd6 83c414 8d85b0fbffff ff77f8 }
- $sequence_8 = { ff750c e8???????? ff75ec e8???????? ff75e8 e8???????? }
- $sequence_9 = { bf???????? 8b45d4 85c0 7505 b8???????? 57 50 }
+ $sequence_0 = { 8d1439 8a0410 320419 41 }
+ $sequence_1 = { 56 ffd7 8b0d???????? a3???????? a1???????? }
+ $sequence_2 = { 56 0fbe7001 83f60d 57 }
+ $sequence_3 = { 880c3e 5f 5e 8be5 }
+ $sequence_4 = { 75ea 8bcb 0fb6d2 c1e918 33ca c1e308 }
+ $sequence_5 = { a3???????? a1???????? 50 51 e8???????? 83c408 50 }
+ $sequence_6 = { 2bc2 40 50 e8???????? 8bd0 }
+ $sequence_7 = { ffd7 8b15???????? a3???????? a1???????? 52 50 e8???????? }
+ $sequence_8 = { 83c404 33c9 8d460a ba02000000 f7e2 }
+ $sequence_9 = { 8b0d???????? 894808 e9???????? 8d46fe 8bff 668b4802 }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <901120
}
-rule MALPEDIA_Win_Hoplight_Auto : FILE
+rule MALPEDIA_Win_Citadel_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d07c2fe2-ecaa-5d6d-9200-86c11ba23c84"
+ id = "cf6cb189-c7d7-5571-b2ec-c3b6f165f615"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hoplight"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hoplight_auto.yar#L1-L90"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.citadel"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.citadel_auto.yar#L1-L167"
license_url = "N/A"
- logic_hash = "247623c43b610ddcbb448aac3610ffa1141476124d800ee4677cf300abbf0143"
+ logic_hash = "8e88ac7355b3e3defd358849e38b9e68e570cd840f3a9a1ae754cb483f4c91f5"
score = 75
quality = 75
tags = "FILE"
@@ -162523,32 +169601,40 @@ rule MALPEDIA_Win_Hoplight_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488b4c2460 e8???????? 8b442428 488d0d5e680200 }
- $sequence_1 = { 488b5260 8b0481 894208 488b842480000000 }
- $sequence_2 = { 8b442424 25ff000000 8bc0 488d0d87740200 }
- $sequence_3 = { 4889542420 4d8bc8 488b442440 4c8bc0 }
- $sequence_4 = { 4c8bb42498040000 488b8d80030000 4833cc e8???????? }
- $sequence_5 = { 488d4c2460 e8???????? 488b842470020000 488b4060 }
- $sequence_6 = { 4833c4 48898424f8000000 c744242800000000 488b842410010000 }
- $sequence_7 = { 4c8d05883c0300 488bd0 488b4c2450 e8???????? }
+ $sequence_0 = { eb0e 6800800000 53 57 }
+ $sequence_1 = { 55 8bec ff7508 e8???????? e8???????? 5d }
+ $sequence_2 = { eb03 83c002 68???????? 50 ff15???????? }
+ $sequence_3 = { e8???????? e8???????? 5d ff25???????? 55 8bec ff7508 }
+ $sequence_4 = { 33c0 5f 5e c20400 55 8bec 8b4d0c }
+ $sequence_5 = { e8???????? 8d7c0201 8bc7 e8???????? }
+ $sequence_6 = { 50 e8???????? 6a44 5a 52 }
+ $sequence_7 = { 50 8d5dfc e8???????? 8b4dfc }
+ $sequence_8 = { 884601 33c0 6689460c ff4df8 }
+ $sequence_9 = { 8a5602 8b4e10 8a5e14 fec8 32d0 8ac2 3245fe }
+ $sequence_10 = { 8845fe c645ff00 763c 8a06 }
+ $sequence_11 = { 3aca 73fa 0fb6c9 8b04c8 ebae 32c0 5f }
+ $sequence_12 = { 33c0 6689460e 0fb74606 6685c0 7432 }
+ $sequence_13 = { 85c0 7409 3255fd 8a0f ffd0 8807 }
+ $sequence_14 = { 6685c0 7432 66ff460e 6639460e }
+ $sequence_15 = { 6639460c 7228 8b4610 8a4e05 8a5614 85c0 }
condition:
- 7 of them and filesize <765952
+ 7 of them and filesize <1236992
}
-rule MALPEDIA_Win_Liteduke_Auto : FILE
+rule MALPEDIA_Win_Kimsuky_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c89a689f-3dfd-5d2a-aec1-28f7aca47554"
+ id = "161d56f8-b6bc-5eb6-924b-1d343e294025"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.liteduke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.liteduke_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kimsuky"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kimsuky_auto.yar#L1-L285"
license_url = "N/A"
- logic_hash = "5d6b62682cd8e4bed5eedc1b6f48e136bed91567c9f36c00bf40e1cbea238867"
+ logic_hash = "9e58434bf421de4759f7d578f12345202af7c8ac65503745224655e4e4de3bf9"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -162560,32 +169646,53 @@ rule MALPEDIA_Win_Liteduke_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff7508 ff15???????? ff75fc ff15???????? 5b 5e }
- $sequence_1 = { 6800010000 ff15???????? c3 68???????? ff15???????? }
- $sequence_2 = { 5b 5e 5f 8b45d8 c9 c20400 55 }
- $sequence_3 = { 41 83f904 7cdd 5f 5e }
- $sequence_4 = { c9 c20800 55 89e5 ff7508 e8???????? }
- $sequence_5 = { c20c00 c70101000000 61 c9 c20c00 c70100000000 61 }
- $sequence_6 = { c1c006 243f 3c3e 7205 c0e002 2c0e 2c04 }
- $sequence_7 = { 46 8a06 8807 46 43 41 42 }
- $sequence_8 = { b800000000 8a03 c1e804 83f809 7f05 83c030 eb03 }
- $sequence_9 = { 56 e8???????? 83c40c ff750c 56 e8???????? 83c408 }
+ $sequence_0 = { 50 ffd6 8bd8 85db 7510 5e }
+ $sequence_1 = { 6a00 6800f70484 6a00 6a00 68???????? 8d85e4fbffff 50 }
+ $sequence_2 = { 8d85ecfbffff 50 8d85f8feffff 50 8d85f4fdffff }
+ $sequence_3 = { ffd7 a3???????? 8d85ccf3ffff 50 56 ffd7 }
+ $sequence_4 = { 7503 56 eb18 6a00 6a00 6a00 }
+ $sequence_5 = { 85c0 7423 6a00 8d85f0feffff 50 68???????? }
+ $sequence_6 = { b9???????? e8???????? 8d85f8feffff 50 6a00 6a00 6a1a }
+ $sequence_7 = { eb06 ff15???????? 85c0 7421 }
+ $sequence_8 = { ff15???????? 85c0 7516 ff15???????? 8bd8 e8???????? }
+ $sequence_9 = { 4156 4157 4883ec40 48896c2470 4889742438 4533ff 4c89642428 }
+ $sequence_10 = { ebdb 65488b042560000000 48897c2430 48896c2460 }
+ $sequence_11 = { 0f857affffff 4c8b7c2460 4c8b6c2420 4c8b642428 488b7c2430 488b742438 488b6c2470 }
+ $sequence_12 = { 498bce 418d5001 ffd3 488bc3 4883c440 415f }
+ $sequence_13 = { 488b742438 488b6c2470 4d8bc6 4d2b4730 }
+ $sequence_14 = { 0f8540feffff 488b6c2460 4c637d3c 33c9 41b800300000 4c03fd }
+ $sequence_15 = { 4533ff 4c89642428 4c896c2420 33f6 4533ed 4533e4 }
+ $sequence_16 = { 85c0 0f94c1 85c9 0f8494020000 }
+ $sequence_17 = { 4c89642430 c744242880000000 c744242002000000 4533c9 4533c0 }
+ $sequence_18 = { 85c0 0f8432020000 8b7590 660f1f440000 }
+ $sequence_19 = { 8b9590000000 0395d8000000 0395b8000000 8bbda0010000 8d4702 03c2 89442450 }
+ $sequence_20 = { 8b4c2468 c6043900 803f00 740d }
+ $sequence_21 = { 488d8a38000000 e9???????? 488d8a28010000 e9???????? }
+ $sequence_22 = { 85c0 7464 c7453038000000 33c0 }
+ $sequence_23 = { 85c0 7471 895c2468 8d4801 }
+ $sequence_24 = { 83f809 8d7340 7405 be20000000 c68424a000000000 }
+ $sequence_25 = { 668945c4 8b05???????? 8945d8 0fb705???????? }
+ $sequence_26 = { 668945ea 6644896dec 4c8d45c0 488d1563c20400 }
+ $sequence_27 = { 66894507 884509 895d0b 85ff }
+ $sequence_28 = { 668945dc 448d62ff e8???????? 33db }
+ $sequence_29 = { 668945b0 488d4db0 e8???????? 488d442450 }
+ $sequence_30 = { 668945e8 488bc3 7203 488b03 }
condition:
- 7 of them and filesize <1171456
+ 7 of them and filesize <1021952
}
-rule MALPEDIA_Win_Slave_Auto : FILE
+rule MALPEDIA_Win_Avaddon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2db01cdc-36fb-5960-a7bc-78a56f81c6bb"
+ id = "63f23353-9bc4-58e9-928a-ae89a2672871"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.slave"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.slave_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avaddon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avaddon_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "b1287622c49df3c1a2838a3a773babcdc61506504422851d523ef94f6f257153"
+ logic_hash = "a18db52df950b60c5b6d6008b561a4d13093802e02b6d570e4f6e8e4ed4f56e8"
score = 75
quality = 75
tags = "FILE"
@@ -162599,32 +169706,32 @@ rule MALPEDIA_Win_Slave_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 85c0 0f84e0020000 6a04 6800100000 6800100000 }
- $sequence_1 = { 7514 66837b0600 7405 8a4306 }
- $sequence_2 = { 0fbf4720 33d2 50 0fb6c1 68???????? 83c008 }
- $sequence_3 = { 730d 810e00000800 808b0603000040 8b4610 808b0603000010 8a55ff }
- $sequence_4 = { c74710d5000000 eb10 c7471095000000 eb07 c7471085000000 f70700400000 742f }
- $sequence_5 = { c1c90d 33c8 8b7dd4 8b45e8 03fa c1c802 33c8 }
- $sequence_6 = { 83ec24 53 32c0 32c9 56 8b7508 }
- $sequence_7 = { 8a8e08010000 f6c210 0f8411040000 8b8610030000 0b8614030000 0f84c2000000 f6c240 }
- $sequence_8 = { 8bc6 c1c806 33c8 8bc3 3345d4 034da0 }
- $sequence_9 = { 8bd8 0b5df4 2345f4 03ca 235de0 0bd8 8b55ac }
+ $sequence_0 = { 55 8bec 83e4f8 8b11 83ec14 0faf5104 53 }
+ $sequence_1 = { 52 50 e8???????? 8bf0 8bfa 8b4508 03f3 }
+ $sequence_2 = { 8d4dcc e9???????? 8d4d88 e9???????? 8d4db4 e9???????? 8d4de4 }
+ $sequence_3 = { 8b4df0 e9???????? 8d4dbc e9???????? 8b542408 8d420c 8b4ac0 }
+ $sequence_4 = { 57 56 e8???????? 83c408 85c0 7535 837e6402 }
+ $sequence_5 = { 8bd0 e8???????? 8b5604 83c404 }
+ $sequence_6 = { ff75b4 e8???????? 83c408 47 897dac 81fffe000000 0f8654feffff }
+ $sequence_7 = { 8bc8 2bce 0fafcb 890a 83c204 8b4de4 41 }
+ $sequence_8 = { 034b08 4e 8b4588 6a00 52 51 56 }
+ $sequence_9 = { 8d4dd8 e8???????? c645fc0d 8b4f14 3b4f18 7437 c7411000000000 }
condition:
- 7 of them and filesize <532480
+ 7 of them and filesize <2343936
}
-rule MALPEDIA_Win_Carrotball_Auto : FILE
+rule MALPEDIA_Win_Bumblebee_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8d1dffb9-f801-5b51-998b-8e4431af5d29"
+ id = "2d631f7c-7434-5c27-9009-44b4e59637b5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.carrotball"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.carrotball_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bumblebee"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bumblebee_auto.yar#L1-L109"
license_url = "N/A"
- logic_hash = "8cb2e3b01c31931d0c5f23b61551aa799de8dd787a3493373f0ac01ba6f109d9"
+ logic_hash = "5441d9d4140ebd43dfbd5141b1d6fd9472ec1ff4702b3388ec7d6ec403a89c52"
score = 75
quality = 75
tags = "FILE"
@@ -162638,32 +169745,30 @@ rule MALPEDIA_Win_Carrotball_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? eb36 68???????? 56 ff15???????? }
- $sequence_1 = { 6a04 58 6bc000 c7807430001002000000 6a04 }
- $sequence_2 = { 5f 8b4dfc 33cd 33c0 e8???????? 8be5 5d }
- $sequence_3 = { ffd6 5e 5f 8b4dfc 33cd 33c0 }
- $sequence_4 = { 68???????? ff15???????? eb36 68???????? 56 }
- $sequence_5 = { 8bf0 85f6 0f84ac000000 68???????? }
- $sequence_6 = { 56 ff15???????? 85c0 7432 8d85ecfdffff }
- $sequence_7 = { ff15???????? 8bf8 85ff 0f84d9000000 56 }
- $sequence_8 = { ff15???????? 8bf0 85f6 0f84ac000000 68???????? 56 ff15???????? }
- $sequence_9 = { 6bc000 c7807430001002000000 6a04 58 6bc000 }
+ $sequence_0 = { 0fb7570e 6623d1 740d 0fbe470d b90d000000 2bc8 }
+ $sequence_1 = { 0f44c1 833c1800 7475 837c180400 746e 8b1418 488b05???????? }
+ $sequence_2 = { 0f88cc000000 4863533c 488b05???????? 4803d6 4885c0 0f84b5000000 488d4c2430 }
+ $sequence_3 = { 0f880c010000 488b7580 4885f6 0f84ff000000 488b05???????? 4885c0 0f84ef000000 }
+ $sequence_4 = { 0f8895000000 8b7b28 b8c0000000 4803fe ba64860000 66395304 8d4810 }
+ $sequence_5 = { 0fbec0 8d59e8 8d1c58 ffc2 }
+ $sequence_6 = { 0f57c0 c744242800000008 4c8d45d0 488975d8 8d4640 488975e0 }
+ $sequence_7 = { 0f8840010000 488b05???????? 4885c0 0f8430010000 488b542448 488d4c2438 48894c2420 }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <4825088
}
-rule MALPEDIA_Win_Poscardstealer_Auto : FILE
+rule MALPEDIA_Win_Collectorgoomba_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "30b86ec5-11cf-5ead-8d33-f96f4fd997a4"
+ id = "ee60f6dc-0e40-5600-9363-18addef799db"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poscardstealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poscardstealer_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.collectorgoomba"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.collectorgoomba_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "e2bc29fc53d916c8c6261d35dc13ec4aa0c9f6d2e8252ac3a60894a094beda3f"
+ logic_hash = "b5a8ed8c5e59ef8c9c917b7f2556669b4a98ddcbc5ddbd63af8e98206da01974"
score = 75
quality = 75
tags = "FILE"
@@ -162677,32 +169782,32 @@ rule MALPEDIA_Win_Poscardstealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c645fc01 e8???????? 8d4db8 51 50 8d55d4 }
- $sequence_1 = { 33d2 bb07000000 895de8 8975e4 }
- $sequence_2 = { 50 ff15???????? 8bf0 8d45b0 50 }
- $sequence_3 = { 03c8 83fb10 7303 8d55d4 }
- $sequence_4 = { 8bd1 c1fa05 c1e006 030495e0794200 eb05 b8???????? f6400420 }
- $sequence_5 = { c785e8feffff7ce74100 8b8520ffffff c645fc07 894598 }
- $sequence_6 = { 8b4da4 8b5590 8bc2 83f908 7303 }
- $sequence_7 = { 885dd4 e8???????? 8b0d???????? 8b35???????? 2bce b893244992 f7e9 }
- $sequence_8 = { 6800000040 50 ff15???????? 8bf0 8d45c4 50 }
- $sequence_9 = { e9???????? 8d8d58feffff e9???????? 8d8d10ffffff e9???????? 8d8d48ffffff e9???????? }
+ $sequence_0 = { eb91 8b450c 833801 7e04 834dfcff 837dfc00 7c1c }
+ $sequence_1 = { 8b8084000000 8945fc 837dfc00 756e 8b4508 83787c00 7465 }
+ $sequence_2 = { ff30 ff75f8 ff75fc ff7508 e8???????? 83c410 8b4508 }
+ $sequence_3 = { 83c007 894588 ff758c ff7588 8d8528fdffff 50 8d4dc4 }
+ $sequence_4 = { ffb574ffffff e8???????? 59 59 8845e6 8a45e6 8845e5 }
+ $sequence_5 = { c705????????020a010d c705????????04050f01 833d????????00 740a c705????????04060b08 c705????????0206030b c705????????08050a0e }
+ $sequence_6 = { ff704c 8b4508 ff30 e8???????? 59 59 8945d4 }
+ $sequence_7 = { e8???????? 83c40c ebd1 33c0 40 c1e005 c64405d000 }
+ $sequence_8 = { ff75fc e8???????? 59 59 ebad ff75d0 6a00 }
+ $sequence_9 = { 8bec 83ec10 8b4508 8945f0 8b45f0 8b8018010000 8945f4 }
condition:
- 7 of them and filesize <362496
+ 7 of them and filesize <1400832
}
-rule MALPEDIA_Win_Excalibur_Auto : FILE
+rule MALPEDIA_Win_Moriagent_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2f6333bc-c895-5bb8-bab8-691e82e18cbb"
+ id = "0b12c276-52ba-56f2-9890-c8bf86de4e3d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.excalibur"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.excalibur_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moriagent"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moriagent_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "2c11504edbec5bcce0250be14d19518961ccd4df7434fa2cf5c1fc07833012b8"
+ logic_hash = "0ba5f6f81e0a998dcf4930d5e902ddcfa057da2849fe14345a41be1a23cd042b"
score = 75
quality = 75
tags = "FILE"
@@ -162716,32 +169821,37 @@ rule MALPEDIA_Win_Excalibur_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 c745fc00000000 e8???????? c645fc01 8bbdece5ffff 8b9dd8e5ffff 8d8dd8e5ffff }
- $sequence_1 = { 884c241f b90f000000 c644242000 0f57c0 660fd6442420 8d442420 83f910 }
- $sequence_2 = { 50 e8???????? 8b55e4 83c40c 6bd230 8d8210074400 8945e4 }
- $sequence_3 = { 7514 8b4738 8b4f3c 8902 8b471c 8908 8b472c }
- $sequence_4 = { 99 2bc2 8b5508 d1f8 2b14c5605f4300 7413 85d2 }
- $sequence_5 = { 80b86004440000 74e9 8b5ddc 0fb606 0fbe8060044400 85c0 7510 }
- $sequence_6 = { 6689141e 8945f8 46 03f6 0fb7141e 81ff00000001 7314 }
- $sequence_7 = { c645fc01 8bbdece5ffff 8b9dd8e5ffff 8d8dd8e5ffff 83ff10 0f43cb 6a00 }
- $sequence_8 = { 8bb540e5ffff e9???????? 8bb540e5ffff e9???????? 8b8530e5ffff 8b0485c0324400 f644060480 }
- $sequence_9 = { 8975fc 8b45e0 8b0485c0324400 f644030401 7428 57 e8???????? }
+ $sequence_0 = { b802000000 eb05 b801000000 33ff }
+ $sequence_1 = { cc 488bc8 e8???????? 48897d00 48c745080f000000 c645f000 488b4528 }
+ $sequence_2 = { cc 488bc8 e8???????? 48897da0 48c745a80f000000 c6459000 }
+ $sequence_3 = { cc 488bc8 e8???????? 48897d18 48c745200f000000 c6450800 }
+ $sequence_4 = { 83bd98efffff10 8bb5c4efffff 8b8d94efffff 660f7ec8 51 0f43d0 }
+ $sequence_5 = { cc 488bc8 e8???????? 48897dd0 48c745d80f000000 c645c000 }
+ $sequence_6 = { cc 488bc8 e8???????? 48897dc0 48c745c80f000000 c645b000 }
+ $sequence_7 = { cc 488bc8 e8???????? 48897d20 48c745280f000000 c6451000 }
+ $sequence_8 = { 8d8de4feffff e9???????? 8d8d30ffffff e9???????? 8d8dccfeffff }
+ $sequence_9 = { 0f87df160000 52 51 e8???????? 8b85e8eeffff }
+ $sequence_10 = { eb06 8bb5e4eeffff 8b857cefffff 85c0 0f84bd080000 80bdc7eeffff00 }
+ $sequence_11 = { c785e0feffff0f000000 c685ccfeffff00 6a04 68???????? c7411000000000 c741140f000000 c60100 }
+ $sequence_12 = { 0f1006 8b85e8eeffff 0f1185b4efffff f30f7e4610 660fd685c4efffff c7461000000000 c746140f000000 }
+ $sequence_13 = { c746140f000000 c60600 8b5d1c 8d4d08 8b5508 8d7d08 8b4518 }
+ $sequence_14 = { cc 488bc8 e8???????? 48897de0 48c745e80f000000 c645d000 }
condition:
- 7 of them and filesize <1253376
+ 7 of them and filesize <1347904
}
-rule MALPEDIA_Win_Runningrat_Auto : FILE
+rule MALPEDIA_Win_Roopirs_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dfc93b52-63e2-55d7-a28a-ac61edd067cb"
+ id = "57676d4c-d0d7-5b4f-80a4-819b4d474425"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.runningrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.runningrat_auto.yar#L1-L161"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.roopirs"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.roopirs_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "93ccf5e13fdb9515ec5cdc43025f3b9796a39f81cb6409c0f2fa39eb59211d22"
+ logic_hash = "d4e144778ab9b98b475c3cbfeb400528a9373556893774f62bba1f2eb8f36265"
score = 75
quality = 75
tags = "FILE"
@@ -162755,37 +169865,32 @@ rule MALPEDIA_Win_Runningrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 56 ff15???????? 8b8c2418010000 }
- $sequence_1 = { 8b4904 56 8b742410 56 8d542414 50 }
- $sequence_2 = { 85c0 7404 50 ff5650 8b5660 }
- $sequence_3 = { 8988100b0000 8d88740a0000 8988280b0000 33c9 c780180b000080cd0110 89901c0b0000 c780240b000098cd0110 }
- $sequence_4 = { 894554 89542428 b910000000 33c0 8d7c2438 }
- $sequence_5 = { 8d442440 c1e902 f3a5 8bca 50 83e103 }
- $sequence_6 = { 5d 33c0 5b 81c4f8020000 c20400 8b35???????? 6800000100 }
- $sequence_7 = { c7462400000000 83c610 6a00 56 ff15???????? 5e }
- $sequence_8 = { 7cd9 8bf2 8b8e80000000 b8cdcccccc f7a684000000 c1ea04 }
- $sequence_9 = { 83c404 395630 740d 8b542418 }
- $sequence_10 = { 8d942410010000 52 6a00 6a00 }
- $sequence_11 = { 8d842432020000 6a00 50 c684242c02000046 }
- $sequence_12 = { 83ea01 898c3c90000000 75ed 8bd3 33ff 8d4900 }
- $sequence_13 = { 8b742424 e9???????? 6803010000 8d442431 6a00 50 }
- $sequence_14 = { 33c0 e8???????? 81c468040000 c3 3b0d???????? 7502 }
+ $sequence_0 = { c745fc47000000 8b4dd8 51 68???????? ff15???????? 8945c0 }
+ $sequence_1 = { 50 ff15???????? 898530ffffff eb0a c78530ffffff00000000 33c9 837da800 }
+ $sequence_2 = { ff15???????? 8d4db0 ff15???????? c745fc07000000 833d????????00 751c 68???????? }
+ $sequence_3 = { 8945b0 837db000 7d1d 6a20 68???????? 8b45dc 50 }
+ $sequence_4 = { 8d55d4 52 6a05 ff15???????? 83c418 8d45bc 50 }
+ $sequence_5 = { 8b02 8b4d80 51 ff5014 dbe2 89857cffffff }
+ $sequence_6 = { 8b4508 50 8b08 ff5104 8b5514 56 8d45bc }
+ $sequence_7 = { c78544ffffff00000000 8b45ac 89458c 8d4dcc 51 8b558c }
+ $sequence_8 = { 68???????? 68???????? ff15???????? c78548ffffffd4624000 eb0a }
+ $sequence_9 = { 8d4dc8 ff15???????? c745fc07000000 8b4dd8 51 68???????? }
condition:
- 7 of them and filesize <278528
+ 7 of them and filesize <344064
}
-rule MALPEDIA_Win_Smominru_Auto : FILE
+rule MALPEDIA_Win_Mirrorkey_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f9ca05ba-f03e-5436-9d57-424a2dfc3ab2"
+ id = "e800f2ca-d12e-53d0-a0d8-c0a956e2c2e3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.smominru"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.smominru_auto.yar#L1-L162"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mirrorkey"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mirrorkey_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "bda67966371ffe5669f600e524bbc69b988d40d47c3737672a3d574c8f6a0cdf"
+ logic_hash = "63df7495a525d1f228b934ad2c4fefa8fb21a89fd4e60713963ec70e2cb5c67e"
score = 75
quality = 75
tags = "FILE"
@@ -162799,38 +169904,32 @@ rule MALPEDIA_Win_Smominru_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b474c 894610 8b4750 894614 8b4754 894618 }
- $sequence_1 = { 0fb7c0 8d4dac 51 50 6a01 }
- $sequence_2 = { 8bd8 eb06 3b4628 0f94c3 }
- $sequence_3 = { 0f84694ac17b f6c140 0f856f4ac17b 8ad1 80e23f }
- $sequence_4 = { 8bd8 eb06 47 ff4df0 }
- $sequence_5 = { 8bd8 eb02 b301 8bc7 }
- $sequence_6 = { 8bd8 eb06 ff45f0 4f }
- $sequence_7 = { 8bd8 eb02 33db 837dfc00 }
- $sequence_8 = { 6aff e8???????? 85c0 0f8c05e5c07b }
- $sequence_9 = { ff15???????? 3d03010000 0f8447a0b17b 85c0 0f8c3fa0b17b }
- $sequence_10 = { 8b37 8975e0 85f6 0f842bfebb7b 83feff 0f8422febb7b 8b5f14 }
- $sequence_11 = { 8bd8 eb09 55 e8???????? 59 }
- $sequence_12 = { 0f8c21f7b07b 0fbe75f4 6bf630 e8???????? 8b402c 648b0d18000000 56 }
- $sequence_13 = { 0f8c79feab7b 8d45c4 50 e8???????? 8b45f0 }
- $sequence_14 = { 8bd8 e9???????? 8d4df8 8bd7 8bc6 e8???????? 8d4df4 }
- $sequence_15 = { 8bd8 eb0a 8d45f0 e8???????? }
+ $sequence_0 = { 0f57c0 0f1145d8 ff15???????? c70016000000 ff15???????? 8d45d4 50 }
+ $sequence_1 = { 895914 0fb77806 85ff 7414 8d4b10 8b4104 0301 }
+ $sequence_2 = { ff15???????? 83c40c c744241000000000 33c0 c644242c00 8944242d 8d742433 }
+ $sequence_3 = { 8bf9 8b7508 8d45a4 50 }
+ $sequence_4 = { 83c004 8b7dfc 83ff01 7f87 5f }
+ $sequence_5 = { 730b 68???????? ff15???????? 894610 837e1410 }
+ $sequence_6 = { 897508 2bda ebaa 8d5aff 83c704 eba2 }
+ $sequence_7 = { 8d4dd8 50 e8???????? 8d4d8c e8???????? 837de808 7d15 }
+ $sequence_8 = { 6a00 51 89542414 ff15???????? 83c408 83f8ff }
+ $sequence_9 = { 53 8b5d0c 894dfc 8b4d08 56 }
condition:
- 7 of them and filesize <8167424
+ 7 of them and filesize <117760
}
-rule MALPEDIA_Win_Helauto_Auto : FILE
+rule MALPEDIA_Win_Blacklotus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8190d0b6-60e2-55b8-bbd3-4f8143a5c37c"
+ id = "84ef9a0b-6544-5450-8b66-292ec2ba5dbd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.helauto"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.helauto_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blacklotus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blacklotus_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "4d9d81740e3a201d5c095a9d2008fa9ef0381381c707cf34a732c2ace99e1c38"
+ logic_hash = "94ccc2d7ff61cb6463b78893aadb2549c584433629bcbab33ca8298790f40cde"
score = 75
quality = 75
tags = "FILE"
@@ -162844,32 +169943,32 @@ rule MALPEDIA_Win_Helauto_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b45d4 83c40c 898568ffffff 8b45d0 }
- $sequence_1 = { ff75ec ffd6 6830750000 eb48 }
- $sequence_2 = { 69c060ea0000 83c430 3d60ea0000 a3???????? }
- $sequence_3 = { 85c0 0f841f010000 8b3d???????? 6a05 8d85a8f3ffff 68???????? }
- $sequence_4 = { 59 50 8d8574ffffff 50 53 53 ff75fc }
- $sequence_5 = { 85c0 7508 53 ff15???????? 59 33c0 }
- $sequence_6 = { 50 ff15???????? 83c40c 85c0 0f8593000000 50 }
- $sequence_7 = { 68???????? 50 ff15???????? 83c40c 85c0 0f8593000000 }
- $sequence_8 = { 8d4608 50 68???????? 53 e8???????? 83c418 83feff }
- $sequence_9 = { 51 8d4df0 e8???????? 8365fc00 8d4df0 }
+ $sequence_0 = { 443bca 7319 69c03f000100 4883c102 4103c0 41ffc1 440fb701 }
+ $sequence_1 = { c745cfc1afbd03 c745d301138a6b c745d73a911141 c745db4f67dcea c745df97f2cfce }
+ $sequence_2 = { 448bc6 488d155b1d0000 488bcb e8???????? 488bf0 }
+ $sequence_3 = { 770b 418b4908 03ca 413bcb 770e 6641ffc2 4983c128 }
+ $sequence_4 = { 42883c10 4183fb3c 0f8c45ffffff 498d8af0000000 41b810000000 498bd6 }
+ $sequence_5 = { 488d1588f7ffff e8???????? 488b05???????? 488bcb ff5020 488b5c2430 488b742438 }
+ $sequence_6 = { 4632440c30 eb1b 418af1 83f804 }
+ $sequence_7 = { 4889442428 4c8bc5 488bd3 48897c2420 }
+ $sequence_8 = { 740b 4883c602 483bf7 72bd eb0c bb03000000 eb05 }
+ $sequence_9 = { 48897010 48897818 4c897020 55 488d68c8 4881ec30010000 4c8bd1 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <181248
}
-rule MALPEDIA_Win_Lowzero_Auto : FILE
+rule MALPEDIA_Win_Stop_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ad1f4f71-db5d-51c4-9bc5-e40c45051891"
+ id = "fe824146-93e4-5101-ac02-1276fa1eda55"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lowzero"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lowzero_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stop"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stop_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "bfaa131f289b03263fe3207c7e09eedb0c528831bcdb16b693a70fc486a7a935"
+ logic_hash = "d919a89d4ce45439e081288fd345725318b761c87669a03e35d3c6db03d1320c"
score = 75
quality = 75
tags = "FILE"
@@ -162883,32 +169982,32 @@ rule MALPEDIA_Win_Lowzero_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb617 47 83fa20 0f83e2000000 42 8d0432 3bc1 }
- $sequence_1 = { 57 8b423c 8b55f4 03c6 }
- $sequence_2 = { 2bce 894df0 8d9b00000000 8d1c31 ff7734 85c0 }
- $sequence_3 = { 7439 03c3 837f1400 7425 }
- $sequence_4 = { 47 2bc8 8d4602 03c3 3b450c }
- $sequence_5 = { 8b4d0c 3b7dfc 0f8255feffff 2b7508 5f 8bc6 5e }
- $sequence_6 = { 8bce 83e21f c1eb05 c1e208 2bca 49 83fb07 }
- $sequence_7 = { 83ec30 53 56 8bd9 8955f4 33f6 895dfc }
- $sequence_8 = { 46 47 e9???????? 8bda 8bce 83e21f }
- $sequence_9 = { e8???????? 5f 5e 5b c70007000000 33c0 8be5 }
+ $sequence_0 = { 6a00 8d45e0 50 ffd6 85c0 75e2 6a64 }
+ $sequence_1 = { ffd0 5d c3 8b0d???????? 33d2 85c9 }
+ $sequence_2 = { 57 6a00 8bd9 6a00 6a12 ff33 }
+ $sequence_3 = { 56 57 6a00 8bd9 6a00 6a12 }
+ $sequence_4 = { ff750c ff7508 ffd0 5d c3 8b0d???????? }
+ $sequence_5 = { ff15???????? 50 e8???????? c745fc00000000 }
+ $sequence_6 = { 75e2 6a64 ff15???????? ffd3 }
+ $sequence_7 = { 68???????? 6a00 6a00 ff15???????? 33c9 894604 85c0 }
+ $sequence_8 = { 6a00 ff15???????? 33c9 894604 }
+ $sequence_9 = { 6a00 ff15???????? 33c9 894604 85c0 5e 0f95c1 }
condition:
- 7 of them and filesize <433152
+ 7 of them and filesize <6029312
}
-rule MALPEDIA_Win_Goggles_Auto : FILE
+rule MALPEDIA_Win_Hellokitty_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5a06c6e9-c0df-5eb2-9be8-0912ecacc960"
+ id = "deb7a825-f579-50f4-a7a3-d6eebbf360da"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.goggles"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.goggles_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hellokitty"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hellokitty_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "6adf86a94e27e4da9bbef6eb899bde95be7c68b8b1a213561e769f61dd93d169"
+ logic_hash = "aa8f4a4903065b9814083d80e7b1fe6c3f259f31453cf2a2b84676c3d1765b58"
score = 75
quality = 75
tags = "FILE"
@@ -162922,34 +170021,34 @@ rule MALPEDIA_Win_Goggles_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c1fa02 83e23f 8a8a10400010 880c33 }
- $sequence_1 = { 51 e8???????? 8b1d???????? b941000000 33c0 }
- $sequence_2 = { 8d54247c 51 52 8d842488010000 68???????? 50 }
- $sequence_3 = { 6a01 51 ff15???????? 8b742430 8b542431 }
- $sequence_4 = { 53 ff15???????? 83c414 33c0 85ed }
- $sequence_5 = { 51 ff15???????? 83c9ff bf???????? 33c0 83c414 }
- $sequence_6 = { c744241002000000 8d8c2480020000 51 ff15???????? 8b442410 5f 5e }
- $sequence_7 = { ffd5 8bf0 8bc7 99 f77c242c 81ee???????? 0fbe8288410010 }
- $sequence_8 = { 2bd6 56 57 03ea ffd3 57 }
- $sequence_9 = { a0???????? 55 57 88442410 }
+ $sequence_0 = { 8975fc 8d4e08 c706???????? e8???????? 6818010000 8d86d0030000 6a00 }
+ $sequence_1 = { 23df 234df0 8bc7 c1c802 0bd9 33d0 03de }
+ $sequence_2 = { 7509 0fb64702 3a4604 7411 83c32c 41 83c72c }
+ $sequence_3 = { 33d2 8b45ec 8bf1 0fa4c11e c1ee02 0bd1 c1e01e }
+ $sequence_4 = { 8b048520364200 56 8b7508 57 8b4c0818 8b4514 832600 }
+ $sequence_5 = { 33ca 8bd1 894dec 8988a8000000 33d3 }
+ $sequence_6 = { 8b759c 03c2 8bd1 8945f8 8bc1 c1c807 c1c20e }
+ $sequence_7 = { 8b45c0 3175c4 8bf0 0facc81c c1e604 0bd0 c1e91c }
+ $sequence_8 = { 8bf8 83c020 59 f3a5 8b7508 83ee20 89450c }
+ $sequence_9 = { c1ce02 8b45d0 03cf 3345ec 3345c4 3345f0 8b7df4 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <319488
}
-rule MALPEDIA_Win_Simplefilemover_Auto : FILE
+rule MALPEDIA_Win_Final1Stspy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "21ae03b9-45c9-58fd-b17b-9f1c4dcf7bf7"
+ id = "7c2b072b-c27f-54e3-a7df-2dc853163db8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.simplefilemover"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.simplefilemover_auto.yar#L1-L219"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.final1stspy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.final1stspy_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "81c6919dbb4aaa2e054461ca67f688251b4ccec2baef13a001955aba375181dd"
+ logic_hash = "654817f55704ecafec1c10904f1a6a25212804a4fb3c152f1d4aecbab6ecef0c"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -162961,44 +170060,32 @@ rule MALPEDIA_Win_Simplefilemover_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bfc f3a5 e8???????? 81c420020000 }
- $sequence_1 = { 33c0 e9???????? 6820020000 ff15???????? }
- $sequence_2 = { 81c420020000 85c0 7407 68???????? eb05 68???????? ff15???????? }
- $sequence_3 = { b988000000 8bf3 8bfc f3a5 }
- $sequence_4 = { 33ff 884c2408 3bf7 88542424 897c2410 }
- $sequence_5 = { 7503 8bfa 46 668b4102 83c102 42 }
- $sequence_6 = { 8b8d54faffff 51 ff15???????? 6a00 6800200000 8d9554daffff }
- $sequence_7 = { 8b8554faffff 50 ff15???????? 85c0 }
- $sequence_8 = { 8b74241c 57 8a8800010000 8a9001010000 33ff }
- $sequence_9 = { ebc2 ebc0 ebbe ebbc ebba ebb8 }
- $sequence_10 = { e8???????? 81c420020000 85c0 7410 68???????? ff15???????? }
- $sequence_11 = { 8b4c2414 8d447b02 50 51 }
- $sequence_12 = { 5f 889000010000 888801010000 5e 83c410 c3 }
- $sequence_13 = { e9???????? 807d0867 0f848f020000 807d0870 0f8513040000 }
- $sequence_14 = { 83bd08daffffff 7409 83bd08daffff00 750f c78508daffff00000000 e9???????? 6a04 }
- $sequence_15 = { 47 897c2418 0fbfff 3bfb 0f8c54ffffff 8a4c242c }
- $sequence_16 = { 6a64 ff15???????? ff4de0 395de0 7fd4 }
- $sequence_17 = { 52 8d855cfaffff 50 8d8d60daffff 51 }
- $sequence_18 = { 8d85b0ddffff 50 e8???????? 8d45dc 57 50 8b45f4 }
- $sequence_19 = { 50 ff7610 6a00 6a00 ffd7 ff7508 8d4302 }
- $sequence_20 = { 8b4c2408 8b742424 53 81e1ff000000 }
- $sequence_21 = { 53 52 ff15???????? 83c408 5f 5e }
+ $sequence_0 = { 03d0 8b45fc 8a4803 c1e206 80f93d 7508 }
+ $sequence_1 = { 51 56 8d55fc c745fc00000000 e8???????? 8bf0 }
+ $sequence_2 = { 8a1d???????? 8b4dfc 83c104 894dfc }
+ $sequence_3 = { eb2e 85ff 7594 b8???????? 6690 3ad9 }
+ $sequence_4 = { 81e7ff070080 7908 4f 81cf00f8ffff }
+ $sequence_5 = { 0f114c0f10 83c120 3bca 7cd4 3bce }
+ $sequence_6 = { 84db 7410 8a11 8acb 3aca 7425 8a4801 }
+ $sequence_7 = { 81cf00f8ffff 47 33f6 85ff 7e0a }
+ $sequence_8 = { 8945fc 57 8d7e01 8a06 }
+ $sequence_9 = { 7410 8a11 8acb 3aca }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <557056
}
-rule MALPEDIA_Win_Graphican_Auto : FILE
+rule MALPEDIA_Win_Kardonloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a2f03fc9-ee25-5fcd-896d-9bb49120884f"
+ id = "3f6a3bad-df12-536d-9e36-cfe1dc9fa562"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphican"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graphican_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kardonloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kardonloader_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "a4c9c330e82d4ca3a447533684cd37026bb60c45e700ff39380301b043754c33"
+ logic_hash = "4fe311b419f6bafe180c85c33e9d2d9d1da43b3315ab993943a70f218a823338"
score = 75
quality = 75
tags = "FILE"
@@ -163012,32 +170099,32 @@ rule MALPEDIA_Win_Graphican_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d5f07 83e3f8 03d3 3b10 7619 8b06 3bc3 }
- $sequence_1 = { 3c65 7408 3c45 0f8570010000 47 807def00 897dc0 }
- $sequence_2 = { 56 57 8bf1 8bfa 85db 7517 68a8010000 }
- $sequence_3 = { 53 8bf0 6a00 56 e8???????? a1???????? }
- $sequence_4 = { 8d0c89 8d4c48d0 8a07 42 3c30 7dd4 894de8 }
- $sequence_5 = { 68???????? 68???????? e8???????? 83c40c 8b4ddc c7461810000000 894e1c }
- $sequence_6 = { 8d85e8edffff 6a00 50 e8???????? 83c40c 68???????? }
- $sequence_7 = { 68???????? 68???????? e8???????? 83c40c 8b5624 2b5620 }
- $sequence_8 = { 8d8dc4efffff 51 50 ffd2 8bb5c4efffff 33ff }
- $sequence_9 = { 8bd8 e8???????? 8d4311 83c404 }
+ $sequence_0 = { 83e13f c1e806 03c3 8a0490 88443702 8a0419 8b4d0c }
+ $sequence_1 = { 5e 8be5 5d c3 6a00 ff15???????? cc }
+ $sequence_2 = { e8???????? 83c438 85c0 7405 83c004 }
+ $sequence_3 = { 56 ff7508 68???????? e8???????? 85c0 0f8421010000 }
+ $sequence_4 = { 50 56 e8???????? 83c40c 894714 b001 5f }
+ $sequence_5 = { e8???????? 59 50 8d8550faffff 50 }
+ $sequence_6 = { 50 ff35???????? ff35???????? e8???????? 83c438 e9???????? 5f }
+ $sequence_7 = { 750b c74704???????? 0fb7720a 6a05 58 663bf0 750e }
+ $sequence_8 = { c0e204 8b45fc 880c30 0fb6441f02 8a8018314000 c0e802 }
+ $sequence_9 = { 50 8d85e4fdffff 50 8d85e8feffff 68???????? 50 }
condition:
- 7 of them and filesize <362496
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Unidentified_023_Auto : FILE
+rule MALPEDIA_Win_Kuluoz_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f77c5286-0b1f-561f-8f58-a27a0408436a"
+ id = "5fb3985a-aeab-550e-a023-7a6297ba36e6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_023"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_023_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kuluoz"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kuluoz_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "1eec10f2afa6bd7e6a1d69558f2f25a771bedb385bd839fc0b4d5b578eec4086"
+ logic_hash = "50bc1e4e578c80bb3ef2f204a6ac7dc8f957cf6ffcd8541a192712c749d0e03e"
score = 75
quality = 75
tags = "FILE"
@@ -163051,34 +170138,34 @@ rule MALPEDIA_Win_Unidentified_023_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? ff15???????? 3bf4 e8???????? b801000000 52 }
- $sequence_1 = { 894df4 8a15???????? 8855f8 837d0c01 7514 8bf4 68???????? }
- $sequence_2 = { 8855f8 837d0c01 7514 8bf4 }
- $sequence_3 = { 8945f0 8b0d???????? 894df4 8a15???????? 8855f8 837d0c01 }
- $sequence_4 = { 8855f8 837d0c01 7514 8bf4 68???????? }
- $sequence_5 = { 68???????? ff15???????? 3bf4 e8???????? b801000000 52 8bcd }
- $sequence_6 = { 0909 0909 0407 0807 8d4900 4f }
- $sequence_7 = { 8a15???????? 8855f8 837d0c01 7514 8bf4 }
- $sequence_8 = { 8945f0 8b0d???????? 894df4 8a15???????? 8855f8 837d0c01 7514 }
- $sequence_9 = { 7514 8bf4 68???????? ff15???????? 3bf4 e8???????? b801000000 }
+ $sequence_0 = { 6a00 6a00 8b45cc 50 ff55ec 8945c8 837dc800 }
+ $sequence_1 = { 52 8b45fc 8b4840 51 e8???????? 83c40c 8b55fc }
+ $sequence_2 = { 83c001 8b4d0c 898146120000 837dfc04 7552 }
+ $sequence_3 = { 8b4508 50 8d4dd8 51 e8???????? 8b10 }
+ $sequence_4 = { 338df4feffff 8985f0feffff 898df4feffff 68ff000000 8d95f8feffff 52 e8???????? }
+ $sequence_5 = { 7502 eb05 e9???????? 837dfc06 0f84a2000000 837dfc04 7552 }
+ $sequence_6 = { 83fa0a 7409 0fbe4508 83f80d 7504 b001 }
+ $sequence_7 = { 8b45fc 0fb60c02 51 e8???????? 0fbed0 3bf2 7404 }
+ $sequence_8 = { 8bec 81ec780a0000 a1???????? 33c5 8945fc }
+ $sequence_9 = { f7f1 0fbe9204605009 8b45f8 0345fc 0fbe08 }
condition:
- 7 of them and filesize <1433600
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Logtu_Auto : FILE
+rule MALPEDIA_Win_Cobra_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c67bd86c-2bf9-53d0-9e56-6b46a7295f73"
+ id = "962ae883-d522-5f88-b272-e61709553508"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.logtu"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.logtu_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cobra"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cobra_auto.yar#L1-L488"
license_url = "N/A"
- logic_hash = "a1a55d055cae44fc8e92b272f8aaf6bf080cbc3cc39bc731b57992d62cbc8c84"
+ logic_hash = "0f157bf0768b0eaaf80d53d6edd02f203144bcb1fce66a02d72ea93d53a8a5ec"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -163090,32 +170177,78 @@ rule MALPEDIA_Win_Logtu_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bf0 8d85a4fdffff 68???????? 50 ff15???????? }
- $sequence_1 = { ff15???????? 8d8534ffffff 50 ff15???????? 6a01 }
- $sequence_2 = { 50 6a64 6a00 ff15???????? 85c0 7509 8b45bc }
- $sequence_3 = { 8bec 81ec98050000 a1???????? 33c5 8945fc 53 }
- $sequence_4 = { 55 8bec 81ec98050000 a1???????? 33c5 8945fc 53 }
- $sequence_5 = { 8d8574faffff 50 8d8534ffffff 50 }
- $sequence_6 = { 50 8d85fcf7ffff 68???????? 50 e8???????? 8d85fcf7ffff 6800040000 }
- $sequence_7 = { 6a01 8bf0 8d85a4fdffff 68???????? }
- $sequence_8 = { 8d8584faffff 50 8d8574faffff 50 8d8534ffffff }
- $sequence_9 = { 8d8578faffff 50 8d8584faffff 50 }
+ $sequence_0 = { 7511 e8???????? 85c0 7508 ff15???????? }
+ $sequence_1 = { ff25???????? 53 56 57 8bd9 33f6 }
+ $sequence_2 = { 7514 391d???????? 754d 33c0 }
+ $sequence_3 = { 85c0 0f8e8c000000 83e801 8905???????? }
+ $sequence_4 = { 751c 8bcf ff15???????? 8d8fe8030000 8bf9 }
+ $sequence_5 = { 757f 8b05???????? 85c0 0f8e8c000000 }
+ $sequence_6 = { 5b c3 85db 7405 83fb03 }
+ $sequence_7 = { 85c0 750e 3905???????? 7e2c ff0d???????? 83f801 8b0d???????? }
+ $sequence_8 = { e8???????? 85c0 750e 33ff 8bc7 }
+ $sequence_9 = { 5f 5e 5b c3 85ff 7418 }
+ $sequence_10 = { 753c b980000000 e8???????? 85c0 a3???????? 7504 33c0 }
+ $sequence_11 = { 5e 5b c3 83fb01 7405 83fb02 }
+ $sequence_12 = { 33d2 b9e8030000 f7f1 83f805 }
+ $sequence_13 = { c9 c3 3ac8 7606 8ad1 }
+ $sequence_14 = { d2e0 0802 ff45f8 837df808 7c0b 8a041f 47 }
+ $sequence_15 = { e8???????? 83c410 85c0 7517 ff7520 ff751c }
+ $sequence_16 = { 7407 33c0 e9???????? ff15???????? e9???????? }
+ $sequence_17 = { 7f07 e8???????? eb26 83c0ff }
+ $sequence_18 = { e8???????? eb6d e8???????? 85c0 }
+ $sequence_19 = { e8???????? 33db 3bc3 741a }
+ $sequence_20 = { e8???????? 8bc7 eb0e 4883c108 e8???????? b801005921 }
+ $sequence_21 = { 85c0 7564 488b0b 488b01 }
+ $sequence_22 = { ff5024 488d4d08 e8???????? 488d4d08 e8???????? 488bcd }
+ $sequence_23 = { ff501c 488d4d08 e8???????? 498bce e8???????? 48832700 ba02000000 }
+ $sequence_24 = { ff5064 488b0e 4883c108 e8???????? 488b5c2430 488b6c2438 488b742440 }
+ $sequence_25 = { 83781400 750a b865005921 e9???????? }
+ $sequence_26 = { 8bec 56 6a00 6880000000 6a03 6a00 6a03 }
+ $sequence_27 = { 83feff 7505 33c0 5e 5d c3 8b4d08 }
+ $sequence_28 = { 6a03 68000000c0 50 ff15???????? 8bf0 83feff 7505 }
+ $sequence_29 = { 83c0fe 668b4802 83c002 663bcb 75f4 8b15???????? 8b0d???????? }
+ $sequence_30 = { 8908 8b0d???????? 895004 894808 33c0 }
+ $sequence_31 = { c3 8b4d08 57 51 6a00 }
+ $sequence_32 = { 6689440ffc 6685c0 75ee f685c003000010 }
+ $sequence_33 = { 8d45e8 50 6a00 6aff e8???????? 85c0 }
+ $sequence_34 = { 68???????? 51 ffd6 83c40c 6a28 }
+ $sequence_35 = { ff15???????? 83f87a 740b 3d230000c0 }
+ $sequence_36 = { 8b7d0c 3bc3 7508 3bfb }
+ $sequence_37 = { ff15???????? 488bcf ff15???????? 41b701 }
+ $sequence_38 = { 48894c2450 4c89642448 488d4c2468 48894c2440 4c89642438 }
+ $sequence_39 = { 75e8 85f6 74e4 418936 b801000000 4881c4480d0000 }
+ $sequence_40 = { 48f7d1 66837c4bfc5c 7413 488bfb 4883c9ff 66f2af 8b05???????? }
+ $sequence_41 = { 8d8588feffff 68???????? 50 ff15???????? 83c42c }
+ $sequence_42 = { b914000000 84c0 0f45f9 488bce }
+ $sequence_43 = { 488bce 8bd7 ff15???????? 85c0 }
+ $sequence_44 = { 7507 32c0 e9???????? c745b818000000 }
+ $sequence_45 = { 668b08 83c002 6685c9 75f5 2bc2 d1f8 66837c43fe5c }
+ $sequence_46 = { 05a1000000 50 8d84249c0d0000 68???????? }
+ $sequence_47 = { 0f8456feffff 807c241301 6800080000 0f8544020000 }
+ $sequence_48 = { 0f8431ffffff 8b4d08 5f 8931 }
+ $sequence_49 = { 0f84100f0000 6800080000 57 56 }
+ $sequence_50 = { 05a2000000 50 8d94249c0d0000 68???????? }
+ $sequence_51 = { 05a2000000 50 8d8c249c0d0000 68???????? }
+ $sequence_52 = { 668cc8 c3 53 50 }
+ $sequence_53 = { 85c0 740a b8050000c0 e9???????? }
+ $sequence_54 = { c745bc04390100 66c745d81800 66c745da1a00 c745dc10390100 }
+ $sequence_55 = { c745bc01000000 c745c000000000 6a00 6a00 8d55ac 52 }
condition:
- 7 of them and filesize <924672
+ 7 of them and filesize <1368064
}
-rule MALPEDIA_Win_Rumish_Auto : FILE
+rule MALPEDIA_Win_Miniasp_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c7d955e8-6589-5477-8769-7cb86586e6f1"
+ id = "a296e0dd-d471-5c91-a6b1-780906aaa535"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rumish"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rumish_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miniasp"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.miniasp_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "eaf86e8ce2c9b9b903be9f070aac683527bbc8f25626d1b33901e14e32dd278c"
+ logic_hash = "9a4758ded83cb0970a2c1c85a01ff8f2f0263c333e1e2d45a290cc1db4a95dd4"
score = 75
quality = 75
tags = "FILE"
@@ -163129,32 +170262,32 @@ rule MALPEDIA_Win_Rumish_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d450c 50 e8???????? 8b4df8 e8???????? 8b45f8 8be5 }
- $sequence_1 = { eb46 68???????? 8d8d78feffff e8???????? eb34 68???????? 8d8d78feffff }
- $sequence_2 = { 7375 8b9570ffffff 0faf5580 039574ffffff 899574feffff 8d8574feffff 50 }
- $sequence_3 = { 898534ffffff 8b8d34ffffff 3b4d94 7d40 e8???????? 8985a8feffff }
- $sequence_4 = { 8d8df0faffff e8???????? e9???????? 68???????? 8d8df0faffff e8???????? e9???????? }
- $sequence_5 = { 0fbf4dbc 898d30ffffff 8b9530ffffff 83ea04 899530ffffff 83bd30ffffff0b 0f87a4020000 }
- $sequence_6 = { 7d5d e8???????? 898560ffffff db8560ffffff dc0d???????? dc35???????? d9bd5effffff }
- $sequence_7 = { e8???????? 6a01 8b55f0 52 8b4d9c 83c10c e8???????? }
- $sequence_8 = { 8bec 83ec08 894df8 51 8bcc 8965fc 8d450c }
- $sequence_9 = { 83e901 898d80feffff 8d9580feffff 52 8d4d84 e8???????? 8b4580 }
+ $sequence_0 = { 8b45c0 898550ffffff 8b8550ffffff 40 89854cffffff 8b8550ffffff }
+ $sequence_1 = { ff15???????? 85c0 751b c785c0fbffff10d84000 68???????? 8d85c0fbffff 50 }
+ $sequence_2 = { 8b4508 0345f0 0fbe4002 83f841 7c15 8b4508 }
+ $sequence_3 = { 747c 8b45f4 8945d8 8b45d8 40 8945d4 8b45d8 }
+ $sequence_4 = { 83a564ffffff00 eb0b 1bc0 83d8ff 898564ffffff }
+ $sequence_5 = { 6a00 ff75f8 e8???????? 83c40c 6804010000 6a00 }
+ $sequence_6 = { 68???????? 8d85c0fbffff 50 e8???????? b001 5f 5e }
+ $sequence_7 = { ff15???????? 85c0 7534 ff15???????? 3d882f0000 7427 ff75f8 }
+ $sequence_8 = { 0f8516010000 8b45ec 8b00 8b4dec ff5020 8945f4 837df400 }
+ $sequence_9 = { 8985ecfbffff 8b85ecfbffff 3b45fc 7728 6a01 68???????? 8b4508 }
condition:
- 7 of them and filesize <770048
+ 7 of them and filesize <139264
}
-rule MALPEDIA_Win_Banpolmex_Auto : FILE
+rule MALPEDIA_Win_Bluelight_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f5c73e0b-c575-562f-9127-4bdfc5c88735"
+ id = "80cf9226-cefd-5819-9dda-98c83a2352a6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.banpolmex"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.banpolmex_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bluelight"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bluelight_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "5c80d00898c7981631095abf56b16c379bf161bce0c3d518d50cadc7dd22c1a6"
+ logic_hash = "ac28d46c928f9de871e1c7301334eafe0ce66f50fc56cf0b475e83370bd02ded"
score = 75
quality = 75
tags = "FILE"
@@ -163168,32 +170301,32 @@ rule MALPEDIA_Win_Banpolmex_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7419 4c8b0f 8bd0 41b801000000 498bcc e8???????? 4883f801 }
- $sequence_1 = { ff15???????? 488d1530980800 488bcb 488905???????? ff15???????? 488d1529980800 488bcb }
- $sequence_2 = { c3 488d15ea560200 488bcf e8???????? b80a000000 488b5c2460 4883c420 }
- $sequence_3 = { 0f97c0 890d???????? 4883c428 c3 8b0d???????? 44891d???????? 3bc1 }
- $sequence_4 = { 448d4201 4d8bb4c5a8010000 488bcb e8???????? 85c0 7919 488d156ca70100 }
- $sequence_5 = { 4d016810 4d016018 49017020 49017828 49015830 4d015838 4d015040 }
- $sequence_6 = { 660f1f440000 483bd5 7733 488bca 4869c988000000 4903c9 428b44210c }
- $sequence_7 = { 4883ec28 488b0d???????? 4885c9 7409 83caff ff15???????? 33c0 }
- $sequence_8 = { 4c8b5c2420 488b442428 4c011b 480107 0fb7442438 66ffc0 6689442438 }
- $sequence_9 = { 4c897c2458 3c02 0f85a4000000 41b803000000 4533ff 898c24a8000000 44898424b0000000 }
+ $sequence_0 = { c7466400000000 6a01 8d4510 c645fc03 50 8d45e0 68???????? }
+ $sequence_1 = { e8???????? 85c0 0f85e1040000 8b55c0 8b4638 8d4aff 0fc9 }
+ $sequence_2 = { b97bfe0000 e8???????? 8945f8 8b4dfc e8???????? 83670c00 8b45f8 }
+ $sequence_3 = { 8bce e8???????? 8bd8 895dc4 85db 0f84bf0e0000 8b5348 }
+ $sequence_4 = { 884508 8b4204 8945d8 8b02 8b75d8 3b30 8b75f0 }
+ $sequence_5 = { f3a5 eb23 ff742420 68???????? eb92 8d4101 8bcb }
+ $sequence_6 = { ff248504d44600 6a00 c743140f000000 8bcb c7431000000000 68???????? c60300 }
+ $sequence_7 = { 7414 8bce e8???????? 814b0400000100 894308 8b45fc 8bd0 }
+ $sequence_8 = { e8???????? 8bd0 52 e8???????? 83c404 8b4518 8b4df4 }
+ $sequence_9 = { f7410400000400 7408 8b4114 8b4804 eb03 8b490c 85c9 }
condition:
- 7 of them and filesize <1555456
+ 7 of them and filesize <2191360
}
-rule MALPEDIA_Win_Regretlocker_Auto : FILE
+rule MALPEDIA_Win_Mortalkombat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e84161b8-423e-557e-8de0-b1e67c3c2a4c"
+ id = "5bbf17fe-00b4-5a92-b5e3-f942b94b6ce0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.regretlocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.regretlocker_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mortalkombat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mortalkombat_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "54bb2aadd5c37dd020832b423319961afea1e93662e9effb9e0b762d9355990d"
+ logic_hash = "7d4e235b241a7bc491c490ef8ff26987513d97053d43652b54aa2deceb4dd9ea"
score = 75
quality = 75
tags = "FILE"
@@ -163207,32 +170340,32 @@ rule MALPEDIA_Win_Regretlocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945e0 3bd8 742a 83ec18 8bcc 53 }
- $sequence_1 = { 8d8568ffffff 50 e8???????? 83ec10 c645fc04 8bcc 6a06 }
- $sequence_2 = { e8???????? 6aff 8bcb e8???????? 8d8df4feffff e8???????? 8d8d78ffffff }
- $sequence_3 = { 8d4510 50 8d8578fdffff 50 8d45ec 50 e8???????? }
- $sequence_4 = { 2b45fc 6a18 59 99 f7f9 ff750c 6bc018 }
- $sequence_5 = { 3bf0 59 59 0f95c0 5f 5e }
- $sequence_6 = { 50 f2c3 55 8bec 8b4508 56 }
- $sequence_7 = { 83ec18 8bcc 57 e8???????? e8???????? 83c418 8d4dbc }
- $sequence_8 = { 50 57 ff15???????? 85c0 0f8529ffffff 57 ff15???????? }
- $sequence_9 = { 64890d00000000 5b c9 c21800 8b411c 8b10 85d2 }
+ $sequence_0 = { 33d2 ad 3382b96d4000 ab 83c204 }
+ $sequence_1 = { 6a00 6803800000 ff75fc e8???????? 83f800 7e35 6a00 }
+ $sequence_2 = { 2bc1 81ebb979379e 8bc8 c1e104 }
+ $sequence_3 = { 83f8ff 7402 eb67 6a00 6a00 6a02 }
+ $sequence_4 = { e8???????? 50 ff75ac e8???????? 8945a4 33c0 50 }
+ $sequence_5 = { 803d????????01 7519 68???????? 68???????? 68???????? }
+ $sequence_6 = { c705????????f4010000 68???????? e8???????? a3???????? a0???????? }
+ $sequence_7 = { ff7514 6a01 6a00 ff7510 ff75f8 }
+ $sequence_8 = { 68???????? e8???????? 83c710 6a10 }
+ $sequence_9 = { 50 e8???????? ebd8 8b45bc }
condition:
- 7 of them and filesize <1021952
+ 7 of them and filesize <1224704
}
-rule MALPEDIA_Win_Magniber_Auto : FILE
+rule MALPEDIA_Win_Daxin_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "05f5671a-f33b-5211-a81c-43695f05ea5d"
+ id = "f296881b-770d-5563-abfb-71fa7b0b574a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.magniber"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.magniber_auto.yar#L1-L164"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.daxin"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.daxin_auto.yar#L1-L156"
license_url = "N/A"
- logic_hash = "a03ae86175c535bb9d3d882302b08d3c7bb8579783b2000a5224d25eaa155af3"
+ logic_hash = "474b282908002ac6ff5a401d8cd2ee0d1c71eaec687bd0f7b672c512154787e2"
score = 75
quality = 75
tags = "FILE"
@@ -163246,78 +170379,78 @@ rule MALPEDIA_Win_Magniber_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? 83c408 837dfc00 7502 eb31 6a00 }
- $sequence_1 = { 8b45e8 50 ff15???????? 8b4df4 51 }
- $sequence_2 = { c785a0fafffff0934000 c785a4fafffff8934000 c785a8faffff00944000 c785acfaffff08944000 }
- $sequence_3 = { 50 8b4df4 51 ff15???????? 8b45f8 99 }
- $sequence_4 = { 83c408 8b4dfc 8b55f8 6689044a }
- $sequence_5 = { c7852cfbffff14954000 c78530fbffff1c954000 c78534fbffff24954000 c78538fbffff2c954000 c7853cfbffff34954000 c78540fbffff40954000 }
- $sequence_6 = { 66894da4 ba2f000000 668955a6 b853000000 668945a8 b943000000 }
- $sequence_7 = { 0f842e010000 660f57c0 660f1345b0 6a00 8d4df8 51 6a10 }
- $sequence_8 = { f76e9f 32d8 2d7a350e78 95 }
- $sequence_9 = { 4834b0 184026 e221 a1????????05eef081 e0f8 29aed0515fa6 8d4f0e }
- $sequence_10 = { 56 18cb 52 fc 285f44 c1c70d 11fb }
- $sequence_11 = { e8???????? 32cb 5a b3b1 }
- $sequence_12 = { 4e4e54 70ac 52 f8 a6 6e }
- $sequence_13 = { 29aed0515fa6 8d4f0e 7f4c c82cd1c6 1a32 b636 }
- $sequence_14 = { 5a b3b1 3e6c 21746c2e 4834b0 184026 }
+ $sequence_0 = { 2bc2 d1f8 99 f7f9 }
+ $sequence_1 = { ff15???????? 488b0d???????? 483bcb 7458 895c2448 48895c2440 895c2438 }
+ $sequence_2 = { 751a baea050000 33c9 41b84d4b4353 }
+ $sequence_3 = { ff15???????? 488983f8000000 4883a3d800000000 33d2 488d8bb0000000 448d4220 e8???????? }
+ $sequence_4 = { 83e21f 03c2 8bc8 83e01f c1f905 2bc2 488b5328 }
+ $sequence_5 = { ff15???????? 488b0d???????? 48832700 33d2 4533c0 }
+ $sequence_6 = { 83e27f 03c2 83e07f 2bc2 4863c8 8a8419c5010000 }
+ $sequence_7 = { 83e3e0 41b84d4b4353 83c320 83e203 03c2 895910 c1f802 }
+ $sequence_8 = { 88480d 8b5368 42 895368 }
+ $sequence_9 = { 884c241b c744241c08000000 c783b401000001000000 ff93f0020000 }
+ $sequence_10 = { 884c2450 83c9ff 33c0 f2ae }
+ $sequence_11 = { 885004 33c0 f2ae f7d1 }
+ $sequence_12 = { 88480d 8b4500 50 ff5018 }
+ $sequence_13 = { 884805 8b0b b807000000 c6410600 8b4b04 3bc8 }
+ $sequence_14 = { 88482b 81c6a1000000 8990b0000000 3bf2 }
condition:
- 7 of them and filesize <117760
+ 7 of them and filesize <3475456
}
-rule MALPEDIA_Win_Divergent_Auto : FILE
+rule MALPEDIA_Win_Unidentified_075_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "14cdfb94-4b91-530e-a0fa-873505b81024"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.divergent"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.divergent_auto.yar#L1-L131"
+ id = "147c0d53-aecb-5cae-ac7f-14d52d3c203f"
+ date = "2023-07-11"
+ modified = "2023-07-15"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_075"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_075_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "60d51f83c6b67d5042579114a766b27aab37221121fff155d69e0a695b8fbbca"
+ logic_hash = "10617fdfd534147bc5e0f7e922724e69d45c37af66d21f98c629fa1bac685120"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
+ malpedia_rule_date = "20230705"
+ malpedia_hash = "42d0574f4405bd7d2b154d321d345acb18834a41"
+ malpedia_version = "20230715"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bc1 880438 40 3d00010000 7cf5 8b450c }
- $sequence_1 = { 83c418 85db 0f8537ffffff 5f 5e 68???????? ff15???????? }
- $sequence_2 = { 3b4510 7518 ff7510 8b4704 ff750c }
- $sequence_3 = { 85c0 750a 830604 5e 5d e9???????? 33c0 }
- $sequence_4 = { ff15???????? 837e0800 7412 ff7608 ff15???????? ff7608 e8???????? }
- $sequence_5 = { 3bf1 7421 3bf9 741d 3bc1 7419 c1e204 }
- $sequence_6 = { 85db 0f84da000000 3975f4 0f84d1000000 53 e8???????? 8945e4 }
- $sequence_7 = { 5d c3 ff25???????? 55 8bec 837d0800 741f }
- $sequence_8 = { e8???????? 8bf8 83c414 85ff 742c 8b463c ff743054 }
- $sequence_9 = { 0fb6f1 0fb6ca 0fb60406 034510 03c8 81e1ff000080 7908 }
+ $sequence_0 = { e8???????? 83c40c 6808020000 8d95dcf6ffff 52 6a00 }
+ $sequence_1 = { 8bc1 5e 5d c3 55 8bec ff15???????? }
+ $sequence_2 = { 52 e8???????? 6a00 8d85ace6ffff 50 8d8dbceeffff 51 }
+ $sequence_3 = { 83c40c 33c0 668985d4f4ffff 6806020000 }
+ $sequence_4 = { 837d9400 740d 8b55fc c7821002000000000000 837df000 }
+ $sequence_5 = { 52 ff15???????? 83c410 b853000000 66898550ffffff }
+ $sequence_6 = { 33c0 668945d0 8d4dd4 51 }
+ $sequence_7 = { 742c 8b4514 85c0 7421 }
+ $sequence_8 = { 85c0 0f8431ffffff b901000000 85c9 0f8515ffffff }
+ $sequence_9 = { 81eca4000000 894dfc c745f400000000 c745f800000000 }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <393216
}
-rule MALPEDIA_Win_Iconic_Stealer_Auto : FILE
+rule MALPEDIA_Win_Qakbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "152db8f5-915a-5ca5-a7d4-f3818a40ffaf"
+ id = "241bd352-128e-5f57-a961-1a32ff520127"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.iconic_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.iconic_stealer_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.qakbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.qakbot_auto.yar#L1-L449"
license_url = "N/A"
- logic_hash = "dec19b483e0961df8b3ae7026df8b4a85577bd9230fffbf8dd9f39001dd5f48b"
+ logic_hash = "9011c5853a3a4bce7115bdec7dfc8cc7a3dbd683d5e3bd577fb86bb5ca62af81"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -163329,32 +170462,75 @@ rule MALPEDIA_Win_Iconic_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 4c8b13 4c8d05e6c60300 488bc6 488bce 83e03f 48c1f906 }
- $sequence_1 = { eb29 488d0c76 8d4601 898790000000 488b8788000000 c704c876000000 8954c804 }
- $sequence_2 = { 894338 66897318 66894b3e 6644896316 6644894b3c 663bf1 0f85dc000000 }
- $sequence_3 = { e8???????? 4881c430020000 415f 415d 415c 5f 5e }
- $sequence_4 = { 5f 5e 5d c3 40f6c504 7419 4c8bc7 }
- $sequence_5 = { eb05 b901000000 894f28 4885db 741f 8b4f28 48895f10 }
- $sequence_6 = { f2490f2ad5 488d4dc7 f20f5e15???????? 66490f7ed0 e8???????? e9???????? 448b44242c }
- $sequence_7 = { ffc7 4883c108 3bfa 7cf1 e9???????? 488b4b20 4885c9 }
- $sequence_8 = { e9???????? 488b75a8 4c8b442470 8b06 83c003 413b00 7e1f }
- $sequence_9 = { c7430400000000 41ba1f000000 49bb1142082184104208 418b49f8 85c9 745b 8d4701 }
+ $sequence_0 = { c9 c3 55 8bec 81ecc4090000 }
+ $sequence_1 = { 33c0 7402 ebfa e8???????? }
+ $sequence_2 = { 7402 ebfa 33c0 7402 }
+ $sequence_3 = { 7402 ebfa eb06 33c0 }
+ $sequence_4 = { e8???????? 33c9 85c0 0f9fc1 41 }
+ $sequence_5 = { 50 e8???????? 8b06 47 59 }
+ $sequence_6 = { 8d45fc 6aff 50 e8???????? }
+ $sequence_7 = { 59 59 33c0 7402 }
+ $sequence_8 = { e8???????? 59 59 6afb e9???????? }
+ $sequence_9 = { 740d 8d45fc 6a00 50 }
+ $sequence_10 = { 50 8d8534f6ffff 6a00 50 e8???????? }
+ $sequence_11 = { 8945fc e8???????? 8bf0 8d45fc 50 e8???????? }
+ $sequence_12 = { 33c0 e9???????? 33c0 7402 }
+ $sequence_13 = { 7402 ebfa e9???????? 6a00 }
+ $sequence_14 = { 8975f8 8975f0 8975f4 e8???????? }
+ $sequence_15 = { eb0b c644301c00 ff465c 8b465c 83f840 7cf0 }
+ $sequence_16 = { 7cef eb10 c644301c00 ff465c 8b465c 83f838 }
+ $sequence_17 = { e8???????? 83c410 33c0 7402 }
+ $sequence_18 = { 85c0 750a 33c0 7402 }
+ $sequence_19 = { c644061c00 ff465c 837e5c38 7cef eb10 c644301c00 }
+ $sequence_20 = { 7507 c7466401000000 83f840 7507 }
+ $sequence_21 = { 837dfc00 750b 33c0 7402 }
+ $sequence_22 = { e8???????? e8???????? 33c0 7402 }
+ $sequence_23 = { 833d????????00 7508 33c0 7402 }
+ $sequence_24 = { c7466001000000 33c0 40 5e }
+ $sequence_25 = { 7402 ebfa 837d1000 7408 }
+ $sequence_26 = { 80ea80 8855f0 e8???????? 0fb64df7 }
+ $sequence_27 = { 50 8d45d8 50 8d45d4 50 8d45ec }
+ $sequence_28 = { 56 e8???????? 8b45fc 83c40c 40 }
+ $sequence_29 = { 6a00 6800600900 6a00 ff15???????? }
+ $sequence_30 = { 50 ff5508 8bf0 59 }
+ $sequence_31 = { 6a00 58 0f95c0 40 50 }
+ $sequence_32 = { 57 ff15???????? 33c0 85f6 0f94c0 }
+ $sequence_33 = { 750c 57 ff15???????? 6afe 58 }
+ $sequence_34 = { c3 33c9 3d80000000 0f94c1 }
+ $sequence_35 = { 6a02 ff15???????? 8bf8 83c8ff }
+ $sequence_36 = { 50 e8???????? 6a40 8d4590 }
+ $sequence_37 = { 8d85e4fcffff 50 8d85e4fdffff 50 }
+ $sequence_38 = { 56 e8???????? 83c40c 8d4514 50 }
+ $sequence_39 = { e8???????? 6a00 8d45d4 50 68???????? }
+ $sequence_40 = { 5d c3 33c9 66890c46 }
+ $sequence_41 = { 8b4a04 83c204 03f0 85c9 75e1 }
+ $sequence_42 = { 01f1 898424a8000000 899424ac000000 8d8424b4000000 89c2 8db424c4000000 }
+ $sequence_43 = { 8a442417 8b4c2410 0485 88440c66 89ca 83c201 }
+ $sequence_44 = { ffd3 85ff 741b 6808020000 6a00 }
+ $sequence_45 = { 88442401 894c245c 0f847afdffff e9???????? }
+ $sequence_46 = { 89442410 884c2417 eb94 55 89e5 31c0 }
+ $sequence_47 = { 8945fc 8b4518 53 8b5d10 56 8945c4 }
+ $sequence_48 = { 8b742420 81c638a1e7c3 39f0 89442410 894c240c 89542408 7408 }
+ $sequence_49 = { 8b74242c bb3c13b648 f7e3 69f63c13b648 01f2 89442428 8954242c }
+ $sequence_50 = { 8b4c2444 ffd1 83ec08 b901000000 ba66000000 31ff 89c3 }
+ $sequence_51 = { 89e0 89580c bb04000000 895808 8b5c246c 895804 8b9c2480000000 }
+ $sequence_52 = { 8bf0 83c40c 85f6 0f84f8000000 a1???????? }
condition:
- 7 of them and filesize <2401280
+ 7 of them and filesize <4883456
}
-rule MALPEDIA_Win_Bangat_Auto : FILE
+rule MALPEDIA_Win_Nettraveler_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a2d4fb7c-d848-52ac-b553-710b64461faf"
+ id = "494d7b5b-e566-59c9-b0c7-fe620930e93d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bangat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bangat_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nettraveler"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nettraveler_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "795b6baa10d3ea1f31877796bf7d8c3236899cd7fc3cddcf5f5e7734a685bf62"
+ logic_hash = "ca8cfc3fd83dc1a9e063f01d8d61d4c33014172373ecd89db27946ab9125b077"
score = 75
quality = 75
tags = "FILE"
@@ -163368,32 +170544,32 @@ rule MALPEDIA_Win_Bangat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a01 6800000040 50 e8???????? 83c43c 8bf0 83feff }
- $sequence_1 = { 13f9 03f0 13fd 8b6c2434 89742418 03de 8b74245c }
- $sequence_2 = { 8b442424 99 f7fe 83c408 85d2 7425 6815050000 }
- $sequence_3 = { ff750c 50 ff15???????? 8bf0 ff15???????? 83f850 }
- $sequence_4 = { 8b4c2474 0bc8 8b442464 0bc2 8b54244c 33f1 33f8 }
- $sequence_5 = { 83cbff eb11 83fb01 750c 8b5004 85d2 7505 }
- $sequence_6 = { 8b5704 8b0e 8b3a 8bc1 2bc7 7511 8b7a08 }
- $sequence_7 = { 8b35???????? 8d45e8 68???????? 50 ffd6 8bf8 59 }
- $sequence_8 = { 8b4b58 898184030000 8b03 3d00030000 0f8ebf000000 8b442418 8b4c2414 }
- $sequence_9 = { 75f3 5f 5e 5d b830000000 }
+ $sequence_0 = { ffd3 c70424???????? ff7508 a3???????? }
+ $sequence_1 = { 81ec8c000000 56 57 ff7508 8bf1 e8???????? 8bf8 }
+ $sequence_2 = { 83650800 83c70c 83c428 85ff 897df0 0f8eb6000000 bf00040000 }
+ $sequence_3 = { 53 68???????? ffd6 80a5dcf7ffff00 59 59 baff000000 }
+ $sequence_4 = { 0bdf 33da 035dc4 8d9c18827e53f7 8bc3 c1e81a c1e306 }
+ $sequence_5 = { 0bd7 8b7dfc 0355e4 8dbc178a4c2a8d 8bd7 c1e214 c1ef0c }
+ $sequence_6 = { ff750c ff75d4 50 e8???????? 83c414 8945ec }
+ $sequence_7 = { e8???????? 83c418 8d45fc 897dfc 50 }
+ $sequence_8 = { ffd7 8945fc 8d4308 50 ffd7 8065e400 }
+ $sequence_9 = { 33df 035dc0 8d9c1992cc0c8f 8bcb c1e30a c1e916 0bcb }
condition:
- 7 of them and filesize <1228800
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Retro_Auto : FILE
+rule MALPEDIA_Win_Iispy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a4751029-21e3-5dc7-8b10-667fe3852f4c"
+ id = "204a2c38-8895-5ac0-a1fb-2cdf3f008fea"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.retro"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.retro_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.iispy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.iispy_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "a167f37f4c1b5df11b8ae00c368ae3ba7079a871854da90fb0bcfd20e0f3d7b0"
+ logic_hash = "7326802c4105c66879b54e4bc2a70df2a9f75047a51ff2245fe60a57fbe51d36"
score = 75
quality = 75
tags = "FILE"
@@ -163407,32 +170583,32 @@ rule MALPEDIA_Win_Retro_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 49ffcb 8941ec 418b440af0 8941f0 418b440af4 }
- $sequence_1 = { 8b442420 4863c8 ba04000000 e8???????? 4c8bb42478400000 4c8ba42480400000 488bb42488400000 }
- $sequence_2 = { 488b742468 488dab00120000 f30f100d???????? 4963c5 448b848308130000 418d4701 410fafc0 }
- $sequence_3 = { f30f58c2 f30f58c1 f30f58c5 4883c478 c3 660feb15???????? f30f5c15???????? }
- $sequence_4 = { f3410f1081f8550100 410f2fc0 7604 f30f59e8 8d442eff 4863c8 }
- $sequence_5 = { 418bd4 e8???????? 33c9 85c0 0f8514010000 4c8d2df2e70300 }
- $sequence_6 = { f30f59e8 418d4424ff 4863c8 483bcd 7c2e 0f1f00 660f6e0c8b }
- $sequence_7 = { 4881c460260000 415f 415e 415d 5f 5e 5b }
- $sequence_8 = { 48c1f905 4c8d05db7f0500 83e21f 486bd258 490314c8 488d0d79700200 eb11 }
- $sequence_9 = { f20f1035???????? 0f297c2430 0f57ff 33ff 83bab412000002 488bda 4c8bc9 }
+ $sequence_0 = { ebdc 837b1800 0f85f6000000 3bce 7436 8a01 3c5d }
+ $sequence_1 = { d1e8 03d0 8b5e0c 8b7d08 2bd9 03fb }
+ $sequence_2 = { 85c0 755e f7459c00100000 7503 8b7608 }
+ $sequence_3 = { ff2485887a0010 51 8bcf e8???????? 8b17 8b4210 2b420c }
+ $sequence_4 = { 6a00 ff75e4 c745e800000000 ffd6 85c0 0f856effffff eb0c }
+ $sequence_5 = { 85f6 0f84c1010000 0fb7460e 8bc8 c1e90a f6c101 }
+ $sequence_6 = { 0f1145c8 8b4810 894dc4 b903000000 0f1100 6689480e 8d4dc8 }
+ $sequence_7 = { 8955b4 8d0409 50 6a00 52 e8???????? b800100000 }
+ $sequence_8 = { f6430801 7411 8d5304 8bcf e8???????? 5f 5e }
+ $sequence_9 = { 8b742424 8b7c2420 884c240b 89742410 897c241c e9???????? 3bf8 }
condition:
- 7 of them and filesize <1409024
+ 7 of them and filesize <397312
}
-rule MALPEDIA_Win_Corebot_Auto : FILE
+rule MALPEDIA_Win_Evilbunny_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "690f2e96-0cf9-536c-962e-128a98cf1d0b"
+ id = "2b83805d-7841-5694-8ab4-bb4f9f22ae07"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.corebot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.corebot_auto.yar#L1-L167"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.evilbunny"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.evilbunny_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "f317e1a133d092285e381a2c4a6a16830d0d7cb17eced179ceadea1ad59e039d"
+ logic_hash = "7c88ed9ce9cea56ac78c56ce0f41ba384f06b92b5a02fe2a2de304167eb32f00"
score = 75
quality = 75
tags = "FILE"
@@ -163446,40 +170622,34 @@ rule MALPEDIA_Win_Corebot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 31c0 5e 5d c20800 55 89e5 }
- $sequence_1 = { 01f3 8b75ec 56 8945f0 }
- $sequence_2 = { 0fb618 895de8 c745ec07000000 8d141b 84db 8955e8 }
- $sequence_3 = { 50 e8???????? 83c404 29f7 }
- $sequence_4 = { 51 ff15???????? 85c0 0f95c0 eb08 c70600000000 }
- $sequence_5 = { 31f6 8955e8 894dec 43 8b4dec 8d55f0 }
- $sequence_6 = { 31f6 46 8918 89f0 83c40c 5e 5f }
- $sequence_7 = { 43 8b4dec 8d55f0 e8???????? 85db 7827 }
- $sequence_8 = { e8???????? 807e5800 7509 ff7654 ff15???????? 807e5000 7509 }
- $sequence_9 = { eb10 6800800000 6a00 56 }
- $sequence_10 = { 85c0 7515 8b4624 3b4620 }
- $sequence_11 = { ff7010 ff7014 e8???????? 8b45e0 }
- $sequence_12 = { ff15???????? 8d4634 50 ff15???????? 8d4e0c e8???????? }
- $sequence_13 = { ff15???????? 807e5000 7509 ff764c ff15???????? 8d4634 50 }
- $sequence_14 = { ff742428 e8???????? 8b442424 8d4c2410 }
- $sequence_15 = { 85ff 740f 57 ff7508 }
+ $sequence_0 = { 8b4dec 8b5104 8b45ec 8b4804 8b12 8bf4 51 }
+ $sequence_1 = { eb09 8b450c 8b80b0d91a00 3bf0 7e44 83ee07 eb3f }
+ $sequence_2 = { c1e104 8b5508 8b4220 8d4c08f0 8b5508 894a1c 8b4508 }
+ $sequence_3 = { 8b4df8 51 e8???????? 83c404 83c028 50 6a00 }
+ $sequence_4 = { e8???????? 83c40c 8b55f8 8b4204 50 68???????? 8b4d08 }
+ $sequence_5 = { e8???????? 83c40c 837dd808 7308 8b45d8 89458c eb07 }
+ $sequence_6 = { c1ea0a 33c2 038558ffffff 8b8d38ffffff c1e907 8b9538ffffff c1e219 }
+ $sequence_7 = { e8???????? 034508 50 e8???????? 83c40c 8b45f4 50 }
+ $sequence_8 = { c7000b000000 e9???????? 8b4d0c 8b5108 52 6a00 6a05 }
+ $sequence_9 = { 8b5598 8b45f8 8902 8b4598 52 8bcd 50 }
condition:
- 7 of them and filesize <1302528
+ 7 of them and filesize <1695744
}
-rule MALPEDIA_Win_Oni_Auto : FILE
+rule MALPEDIA_Win_Ketrican_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ffe7d6a1-e7f2-579d-b056-7e9412d8f38a"
+ id = "03c6cec7-6d12-51a2-b1a9-8239f834bf9b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.oni"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.oni_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ketrican"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ketrican_auto.yar#L1-L227"
license_url = "N/A"
- logic_hash = "ef51460421d5bc54251bcf8ac5edcdde6a15b31e2116a2189b470d64d9b9ae34"
+ logic_hash = "c6a0e9c9ef6d7c9c9c9505df3e47863f2b32a94701647f7dc167a7885087d327"
score = 75
- quality = 75
+ quality = 71
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -163491,32 +170661,45 @@ rule MALPEDIA_Win_Oni_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 8d4db0 c645b000 e8???????? 8b0d???????? b8abaaaa2a 8b3d???????? }
- $sequence_1 = { 83f904 0f828d000000 83f923 0f8789000000 8bc8 }
- $sequence_2 = { ff75ec 51 ff36 8b55e8 8bcb e8???????? 83c410 }
- $sequence_3 = { 7f07 3bc7 0f4fd8 8bfb 6aff 8d4701 }
- $sequence_4 = { 3a45ec 753e 8b45f0 8b048590884300 }
- $sequence_5 = { 8d0dc0254300 ba1b000000 e9???????? a900000080 }
- $sequence_6 = { 660fd685c8feffff 33ff 6800010000 899dc8feffff 89bdccfeffff 899dd0feffff ff15???????? }
- $sequence_7 = { 8901 0fb602 5f 5e 5b 8b4c2430 33cc }
- $sequence_8 = { 8b542428 8b442414 85f6 0f8422ffffff }
- $sequence_9 = { f6c104 7519 f6c102 8d4df8 7540 eb6a }
+ $sequence_0 = { 8965f0 33db 895dfc 33c0 }
+ $sequence_1 = { 7417 6a0a 6a1f 68???????? }
+ $sequence_2 = { e8???????? 83c010 8906 c3 56 }
+ $sequence_3 = { 8bd1 e8???????? 5f 5e c3 55 8bec }
+ $sequence_4 = { 8b06 5d c20400 55 8bec 8b4508 894508 }
+ $sequence_5 = { 8bc1 8945f0 834dfcff e8???????? }
+ $sequence_6 = { 8901 5b 5d c20800 680e000780 e8???????? cc }
+ $sequence_7 = { 680e000780 e8???????? cc 8b06 83e810 8b08 }
+ $sequence_8 = { 48 7445 48 743a 48 }
+ $sequence_9 = { 884603 83c604 8345f804 8b45f8 5f }
+ $sequence_10 = { 58 668945d8 6a72 58 }
+ $sequence_11 = { 6a00 8d85f1fbffff 50 e8???????? 83c40c 6800040000 }
+ $sequence_12 = { ff7508 53 53 ffd6 5f 5e }
+ $sequence_13 = { 740a 48 754a e8???????? }
+ $sequence_14 = { 83c002 663bd3 75f5 2bc1 d1f8 8d7001 6800080200 }
+ $sequence_15 = { e8???????? 8b8a8c2f0000 33c8 e8???????? b8???????? }
+ $sequence_16 = { ff15???????? 68???????? c705????????98824100 a3???????? }
+ $sequence_17 = { 8d420c 8b4ae8 33c8 e8???????? 8b8a4c010000 }
+ $sequence_18 = { 33c8 e8???????? 8b8ae8080000 33c8 e8???????? }
+ $sequence_19 = { 8d4dd0 e9???????? 8d4de0 e9???????? 8d4db8 e9???????? 8d4ddc }
+ $sequence_20 = { b8???????? e9???????? 8b542408 8d420c 8b8aa4feffff 33c8 }
+ $sequence_21 = { c705????????98824100 a3???????? c605????????00 e8???????? 59 }
+ $sequence_22 = { 8b8a54ffffff 33c8 e8???????? 8b8adc090000 33c8 e8???????? }
condition:
- 7 of them and filesize <499712
+ 7 of them and filesize <1449984
}
-rule MALPEDIA_Win_Lpeclient_Auto : FILE
+rule MALPEDIA_Win_Deltastealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ff5559d0-76ba-5f50-8136-3eeb9fa351f1"
+ id = "e4bcf99b-e757-5705-a59b-a0722820f3d9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lpeclient"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lpeclient_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.deltastealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.deltastealer_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "cc71b8a0d92e690c3547182b96989e3a466b7b3af36dfae852a2105f4c91b9a4"
+ logic_hash = "f3a202dde71406be69325c7d8bb3b580aed323825ecf5c600f5b385fd3e3e19c"
score = 75
quality = 75
tags = "FILE"
@@ -163530,32 +170713,32 @@ rule MALPEDIA_Win_Lpeclient_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f0ff03 8bce e8???????? eb2b 83f8ff 7526 4c8d2567f60000 }
- $sequence_1 = { 33c0 80f90a 0f94c0 8944244c 488d054a1b0100 }
- $sequence_2 = { 33c0 488bfe 66f2af 48f7d1 48ffc9 0f8456010000 }
- $sequence_3 = { e8???????? c1eb03 85db 0f8e52130000 8b4c2450 8b542450 4c8d5e02 }
- $sequence_4 = { 498be3 5f c3 48895c2410 4889742418 57 4881ec30020000 }
- $sequence_5 = { 7406 81f1783bf682 48ffc7 48ffca 75e6 443bc1 410f94c5 }
- $sequence_6 = { 0fb64c38ff 4132c8 880a 4183c10b 41ffc2 }
- $sequence_7 = { 0bd8 418b0424 8d0c03 8bfb 448bc1 48c1e918 83e10f }
- $sequence_8 = { 488d0d0f570100 ff15???????? 4c8b4308 488d1546e90000 488d0df74e0100 ff15???????? 488d0d9a480100 }
- $sequence_9 = { 33db c74424646b000000 ff15???????? 448d4b01 448d4307 488d95a00b0000 }
+ $sequence_0 = { 4883c428 c3 56 57 53 4883ec30 4c89c6 }
+ $sequence_1 = { 4d01c1 4c894c2420 4c89442428 c744243803001100 c744244803001100 488d5c2430 4c8d742440 }
+ $sequence_2 = { 57 53 4883ec40 4889d3 488b01 488b7008 488b7810 }
+ $sequence_3 = { 84c0 7416 4180bc240802000000 750b 488b842448010000 c60001 4584f6 }
+ $sequence_4 = { e8???????? 498b7610 31db 4839df 741e 8a041e 8d48bf }
+ $sequence_5 = { 89d7 48ffc3 49895e10 49f7e2 0f80a8000000 400fb6d7 4801d0 }
+ $sequence_6 = { c6474001 4889f9 e8???????? 4885c0 7438 4885d2 7433 }
+ $sequence_7 = { e8???????? 4489e3 488d4c2460 e8???????? 4989c7 eb21 4584e4 }
+ $sequence_8 = { 48895c2420 488d7c2430 41b830000000 41b910000000 4889f9 e8???????? 488b7f18 }
+ $sequence_9 = { 6601c8 0f92c2 81f9ffff0000 0f87d8feffff 84d2 0f85d0feffff 4d85f6 }
condition:
- 7 of them and filesize <289792
+ 7 of them and filesize <3532800
}
-rule MALPEDIA_Win_Cutwail_Auto : FILE
+rule MALPEDIA_Win_Jssloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "62e269de-1aa8-5a3f-857f-84d4e225d36e"
+ id = "e1eaf0bc-7617-5378-87a8-cba9c6423b69"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cutwail"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cutwail_auto.yar#L1-L165"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jssloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jssloader_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "c6c78a26e86e94e8584b09088785fb67085bf6ba9ec9ef8f1d52fe4203a44bcb"
+ logic_hash = "186e7df3cf3822e82929f92759ecc1d78a3a2d538dfeac54de7cfb7d33d930ef"
score = 75
quality = 75
tags = "FILE"
@@ -163569,40 +170752,34 @@ rule MALPEDIA_Win_Cutwail_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8808 ebc1 8b5508 03550c c60200 c745fc01000000 8b45fc }
- $sequence_1 = { 3930 0f8491010000 8b08 8b09 894d40 }
- $sequence_2 = { eb12 8d45f4 50 8b4704 }
- $sequence_3 = { 59 e9???????? 8b7de0 8b45f8 83f808 }
- $sequence_4 = { 8b8568feffff 0560ea0000 39855cfeffff 7633 8b8d5cfeffff 898d68feffff e8???????? }
- $sequence_5 = { 8b400c 894564 8d4568 50 }
- $sequence_6 = { c7410400000000 6830750000 ff15???????? 8b55fc 8b02 50 }
- $sequence_7 = { 837d1000 7d04 32c0 eb7d }
- $sequence_8 = { 84c0 745e 46 8a06 }
- $sequence_9 = { 51 e8???????? 83c40c c785e0fdffff00000000 c785dcfdffff00000000 }
- $sequence_10 = { 3bdf 894510 0f84ecfdffff 53 50 }
- $sequence_11 = { 68a6000000 89450c e8???????? 03c3 50 }
- $sequence_12 = { e8???????? 83c410 8985ecfdffff 83bdecfdffffff 0f84ae000000 8b95e4fdffff }
- $sequence_13 = { 76ce 8b7d6c 83ff1d 740e }
- $sequence_14 = { 7509 c68563feffff01 eb77 83bd6cfeffff05 7d6e ff15???????? 89855cfeffff }
- $sequence_15 = { e8???????? 83c414 8b85dcfdffff 2b85d8fdffff 0345fc }
+ $sequence_0 = { 89b5e0fbffff 660fd685e4fbffff 89b5ecfbffff 89b5e4fbffff 89b5e8fbffff 89b5ecfbffff }
+ $sequence_1 = { 0f4345b4 50 ff15???????? 8bf0 89b5c0fdffff 83feff 0f84b9020000 }
+ $sequence_2 = { 8945fc 56 8b7508 8d85fcfeffff 6800010000 6a00 50 }
+ $sequence_3 = { 899d0cffffff 6a04 68???????? c745d000000000 c745d40f000000 c645c000 e8???????? }
+ $sequence_4 = { 2bc6 83c0fc 83f81f 0f8797010000 e9???????? 8b854cfeffff 8d4804 }
+ $sequence_5 = { 51 ffb570feffff 8d4dcc e8???????? c645fc0b 8b55e0 8bc2 }
+ $sequence_6 = { 3b85ecfbffff 740a 8808 ff85e8fbffff }
+ $sequence_7 = { 8bc1 83e13f c1f806 6bc938 8b0485701d4400 80640828fe ff33 }
+ $sequence_8 = { 03f0 56 e8???????? 8b8534ffffff 83c40c 8b8d54feffff }
+ $sequence_9 = { 03f0 56 e8???????? 8b854cffffff 83c40c c6043000 8bb568feffff }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <581632
}
-rule MALPEDIA_Win_Hyperssl_Auto : FILE
+rule MALPEDIA_Win_Tandfuy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2b769147-d4c5-504a-a0e4-deff8d9a685b"
+ id = "38730032-1555-50d4-b759-37b770d675ac"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hyperssl"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hyperssl_auto.yar#L1-L217"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tandfuy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tandfuy_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "f5cbe0c98412e251badcd68fd5914804f5830187a82b3a89143d596e8e3b1b20"
+ logic_hash = "7ea6bc2b0de15e30b85cc41fe9dae28b9e373e31fa36302d55838d87545cc73b"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -163614,46 +170791,32 @@ rule MALPEDIA_Win_Hyperssl_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0108 3310 c1c607 c1c210 }
- $sequence_1 = { 33c3 8b5c244c c1ee12 0bfe 33cf 8bf2 }
- $sequence_2 = { 0105???????? 8d8d5cffffff 89855cffffff 898560ffffff }
- $sequence_3 = { 2bf0 5f 8a10 301401 8a10 301406 40 }
- $sequence_4 = { 40 4f 75f2 5f 5e e9???????? c3 }
- $sequence_5 = { 7436 8b413c 03c1 742a }
- $sequence_6 = { 03c1 742a 8b4028 03c1 }
- $sequence_7 = { 0101 0100 0100 0100 }
- $sequence_8 = { 0100 0200 0200 0002 0002 }
- $sequence_9 = { 33c0 40 5d c20c00 6a08 }
- $sequence_10 = { 0108 3908 1bc9 f7d9 }
- $sequence_11 = { 8b4028 03c1 7423 56 57 }
- $sequence_12 = { ff15???????? 8bc8 85c9 7436 8b413c }
- $sequence_13 = { 0105???????? 8d558c 89458c 894590 }
- $sequence_14 = { c20c00 6a08 68???????? e8???????? 8b450c 83f801 }
- $sequence_15 = { 0101 014514 2bf3 8b5d0c }
- $sequence_16 = { 01442428 8b442428 884500 45 }
- $sequence_17 = { 017e0c 5f 8bc6 5e c20800 }
- $sequence_18 = { 017e0c 395e10 740f ff7610 }
- $sequence_19 = { 017e08 8bc3 e8???????? c20400 }
- $sequence_20 = { 017e0c 8d4d08 e8???????? 5f }
- $sequence_21 = { 011d???????? 5f 8935???????? 5e }
- $sequence_22 = { 017e08 50 e8???????? ff0d???????? }
- $sequence_23 = { 016b08 897b04 5f 5e }
+ $sequence_0 = { 52 8b942458010000 25ff000000 81e1ff000000 50 }
+ $sequence_1 = { f68221eb6e0004 7403 40 ff01 ff01 40 e9???????? }
+ $sequence_2 = { e8???????? 83c404 85c0 0f8440010000 b93e000000 33c0 8dbdd8f9ffff }
+ $sequence_3 = { 8bec 8b4508 ff3485a0d66e00 ff15???????? 5d c3 55 }
+ $sequence_4 = { 6a00 51 6a02 52 56 ff15???????? 56 }
+ $sequence_5 = { 52 33c9 8a4801 51 33d2 8a10 }
+ $sequence_6 = { f3ab 8dbc2474020000 83c9ff f2ae f7d1 2bf9 8bc1 }
+ $sequence_7 = { 7562 b8???????? 81c49c000000 c3 83f806 7551 }
+ $sequence_8 = { 8d95e8feffff 8b7d08 83c9ff 33c0 f2ae f7d1 }
+ $sequence_9 = { 6800000080 56 f3ab ff15???????? 8bd8 }
condition:
- 7 of them and filesize <835584
+ 7 of them and filesize <155648
}
-rule MALPEDIA_Win_Skinnyboy_Auto : FILE
+rule MALPEDIA_Win_Biscuit_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c1dca40b-594e-536c-99f6-c4dd1e2fe372"
+ id = "cbdd41f1-3e24-52e8-913d-0c21f28eadad"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.skinnyboy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.skinnyboy_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.biscuit"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.biscuit_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "70d89835d7c3795dc1cc1ad5fe812e10b23259f8f17b962d2f0a6c8239d19e5a"
+ logic_hash = "c4b7181ffb74601ad4f6fe9643262fda887ff950b5291eeca17cee75a1b1c812"
score = 75
quality = 75
tags = "FILE"
@@ -163667,32 +170830,32 @@ rule MALPEDIA_Win_Skinnyboy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a03 6a00 6a00 68bb010000 ffb5ccfeffff 56 ff15???????? }
- $sequence_1 = { ff30 8945f0 ff36 8975f4 }
- $sequence_2 = { 660fd68564feffff f30f7e05???????? 8d8576feffff 6a00 50 660fd6856cfeffff e8???????? }
- $sequence_3 = { ffd7 ffd3 6a00 6a00 }
- $sequence_4 = { c7856cffffff464b1153 c78570ffffff05170610 c78574ffffff035d591e c78578ffffff01591244 }
- $sequence_5 = { c1fb05 8bfe 83e71f c1e706 8b049d10110110 }
- $sequence_6 = { ff15???????? 8bf0 89b5d8feffff ffd3 }
- $sequence_7 = { c745bc79000000 660fd645c0 660fd645c8 c745e457000000 660fd645e8 660fd645f0 }
- $sequence_8 = { 85d2 740f 668b444de4 6631444dd0 41 3bca }
- $sequence_9 = { 8d45f4 50 ff7308 ff15???????? 8b15???????? 85c0 }
+ $sequence_0 = { e9???????? a1???????? 898588feffff 83bd88feffff00 0f85bb010000 bf???????? }
+ $sequence_1 = { 84c0 894b04 0f84e8feffff 8b542418 52 }
+ $sequence_2 = { 8a54040c 40 f6d2 8854040b 3bc1 }
+ $sequence_3 = { eb04 8b7c2424 8b4604 53 53 53 }
+ $sequence_4 = { e9???????? 8b4de4 bf???????? 33c0 8d9980000000 83c9ff f2ae }
+ $sequence_5 = { f2ae f7d1 49 3bd1 731f 8b7de0 8a0c1a }
+ $sequence_6 = { 740e 68???????? 57 e8???????? 83c408 f60610 }
+ $sequence_7 = { 899538feffff 83bd38feffff00 7511 8b85ccfeffff 2b45e4 8985c0feffff }
+ $sequence_8 = { c1e902 f3a5 8bc8 83e103 f3a4 68c8000000 ff15???????? }
+ $sequence_9 = { 8bcb e8???????? 84c0 7426 8b7b04 8bcd 8bd1 }
condition:
- 7 of them and filesize <176128
+ 7 of them and filesize <180224
}
-rule MALPEDIA_Win_Poison_Rat_Auto : FILE
+rule MALPEDIA_Win_Open_Carrot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3901c97f-e38d-5819-991e-493be520fc51"
+ id = "a3d97757-e9bd-5b96-a3d4-9f325722b76a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poison_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poison_rat_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.open_carrot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.open_carrot_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "b960cb72b2615d9b184a9e25264d3c87f1ec796c5d1b6fa8620d3a64be9786ae"
+ logic_hash = "bc0e7aafdfe5fe87787ac92bf2b362a8818b18c35ce921dfe615312cba0c80f1"
score = 75
quality = 75
tags = "FILE"
@@ -163706,32 +170869,32 @@ rule MALPEDIA_Win_Poison_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6880000000 8d85d4fcffff 52 50 e8???????? }
- $sequence_1 = { 40 83f810 7cee 83ee10 4f 75ac 33c0 }
- $sequence_2 = { 81e1ff000000 83c010 331cad30a44000 8b68f8 }
- $sequence_3 = { e8???????? 8d8560ffffff 68???????? 50 e8???????? ffb6eca94000 }
- $sequence_4 = { 81e5ff000000 333cad30a44000 8b68fc 33fd 8bea }
- $sequence_5 = { f3a5 ff249578334000 8bc7 ba03000000 }
- $sequence_6 = { 33c9 897c2418 8a6e08 8a4e09 }
- $sequence_7 = { c1ea18 81e5ff000000 330c9530984000 8bd7 81e2ff000000 330c9530a44000 8b10 }
- $sequence_8 = { 8b34b530984000 8b1cbd309c4000 c1e908 33f3 81e1ff000000 8b0c8d30804000 }
- $sequence_9 = { 8bf1 c1f805 83e61f 8d3c8580c54000 c1e603 8b07 }
+ $sequence_0 = { b910000000 e8???????? 4889442430 c700ffffffff 48c74008ffffffff 8b4c2438 8908 }
+ $sequence_1 = { b9c8dcfb75 ffc1 c1e106 83e9ff 83c101 6807ab8f5e 4c893424 }
+ $sequence_2 = { ffd0 eb05 bd01000000 440fb6e5 443bed 7c7a 488b15???????? }
+ $sequence_3 = { 8bc3 e9???????? 41b805000000 488d153c9a1800 488bcf e8???????? 85c0 }
+ $sequence_4 = { ffcf 488d9512070000 4903d4 4c63c7 664289b445100f0000 e8???????? 6639b510170000 }
+ $sequence_5 = { 4881cb3f000000 48c7c000020000 4981c46f000000 4809f0 4d0fb72424 4881c204000000 4809c6 }
+ $sequence_6 = { 83fe07 7772 4c8d0dad8df9ff 4863c6 418b8481f0750600 4903c1 ffe0 }
+ $sequence_7 = { e9???????? 488d05de191400 894c2420 4c8d2dabb30f00 89742424 eb42 488d05aeb30f00 }
+ $sequence_8 = { 4c8d0d91850b00 8d4a98 448d42ef e8???????? e9???????? 4c8b4310 488bd7 }
+ $sequence_9 = { 7422 41b8a3000000 488d15c7ff0900 e8???????? 48898380000000 4885c0 0f842f010000 }
condition:
- 7 of them and filesize <101688
+ 7 of them and filesize <8377344
}
-rule MALPEDIA_Win_Poohmilk_Auto : FILE
+rule MALPEDIA_Win_Spybot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4a533432-ed1d-58b3-b34c-6e80b5d4a8fb"
+ id = "bb20c1b9-da8a-50d3-8d1c-08fd01abaeb2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poohmilk"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poohmilk_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spybot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spybot_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "ecd179731e16caedb85d9961e87834bc792941e3499df96bf9bfcadeaf395c81"
+ logic_hash = "f1b579b5b1ee691f466e64e8179031f49e4fd32bcc6dd2bb1d3af2d36456dc74"
score = 75
quality = 75
tags = "FILE"
@@ -163745,32 +170908,32 @@ rule MALPEDIA_Win_Poohmilk_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { d3eb 2bf1 8b0c850c344100 014c822c 40 89856cffffff e9???????? }
- $sequence_1 = { 898560f3ffff c705????????00000000 ffd7 8d8dccf7ffff 51 }
- $sequence_2 = { 0301 eb02 33c0 8b4d08 85c9 7406 }
- $sequence_3 = { 898d74d2ffff 898d78d2ffff 3bd9 7417 3bc1 7513 33c0 }
- $sequence_4 = { 83ffff 0f8410010000 53 8b1d???????? 6a02 }
- $sequence_5 = { 8bd6 e8???????? 33c9 3b85a4fdffff 5f }
- $sequence_6 = { 85c0 0f8499000000 68???????? 8d842424020000 50 ffd6 8b4c2410 }
- $sequence_7 = { 23fb d3eb 0fbe8a10344100 03f9 }
- $sequence_8 = { 5e c21000 8bff 55 8bec 8b4d0c }
- $sequence_9 = { 8b4710 8b4e28 53 52 8b5624 }
+ $sequence_0 = { 50 ffb574ffffff ff750c e8???????? 83c428 e9???????? }
+ $sequence_1 = { 50 e8???????? 83c40c 8d4508 be08010000 50 }
+ $sequence_2 = { 8d45ec 50 e8???????? 8d45ec 885dee 50 8d8548ffffff }
+ $sequence_3 = { 80bd48ffffff30 7c09 80bd48ffffff39 7e16 6a03 8d8548ffffff 68???????? }
+ $sequence_4 = { 56 68???????? e8???????? 59 85c0 59 0f85d7000000 }
+ $sequence_5 = { 3b35???????? 0f83c5010000 8bc6 83e61f c1f805 c1e603 8d1c85e07e5100 }
+ $sequence_6 = { 69c034020000 59 389890814400 0f84fb2b0000 395df4 0f84f22b0000 ff7520 }
+ $sequence_7 = { 8d850cfbffff 53 50 68???????? 53 53 ff15???????? }
+ $sequence_8 = { 898510fbffff 8b45fc 898598fbffff 8b45f8 3bf3 89859cfbffff 751c }
+ $sequence_9 = { 750b 57 ff15???????? 8bc6 eb02 }
condition:
- 7 of them and filesize <245760
+ 7 of them and filesize <2367488
}
-rule MALPEDIA_Win_Glasses_Auto : FILE
+rule MALPEDIA_Win_Transbox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c6da4c93-ee41-5868-bb14-5b5963376366"
+ id = "6493b67c-879c-5d38-8ca0-5969cb4aa6f0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.glasses"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.glasses_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.transbox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.transbox_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "6195d6cdd9cb4570720f28f4358090026d5f6751f78a62fc950fb9d18ef5a646"
+ logic_hash = "d97e3f1924a5eeca38d9aa110b067c359caad44c72bb11cebc9ddfa66ee7e3d6"
score = 75
quality = 75
tags = "FILE"
@@ -163784,32 +170947,32 @@ rule MALPEDIA_Win_Glasses_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8bf0 83c40c 3bf3 0f85e8fdffff 8d4590 50 }
- $sequence_1 = { e8???????? 8d852cfbffff 50 6a00 6a50 68???????? 8d8de4faffff }
- $sequence_2 = { e8???????? 83bdd8fdffff00 0f849e000000 8bcb e8???????? 85c0 740d }
- $sequence_3 = { e9???????? 8d8d38f9ffff e9???????? 8d8dfcf8ffff e9???????? 8d8dacf8ffff e9???????? }
- $sequence_4 = { 8bf1 8975f0 c706???????? 8d8e84000000 c745fc01000000 c7460800000000 e8???????? }
- $sequence_5 = { e8???????? 83b94814000002 0f8d54ffffff ff894c140000 8b814c140000 8b91580b0000 899481540b0000 }
- $sequence_6 = { ff0d???????? 53 8bcf e8???????? c645ff00 5f 5e }
- $sequence_7 = { ffd2 84c0 0f840b010000 8d4da4 e8???????? 8bf8 8b45cc }
- $sequence_8 = { eb10 8bce e8???????? 8b5d18 8945e8 895dec 8b7510 }
- $sequence_9 = { e8???????? 899e7c070000 e9???????? 83f801 7524 6a02 e8???????? }
+ $sequence_0 = { 64a300000000 eb24 8b048d90b60110 41 50 890d???????? ff15???????? }
+ $sequence_1 = { 33c9 83c414 85c0 0f9fc1 8bc1 8b4dfc 33cd }
+ $sequence_2 = { 8d4e04 c706???????? 832100 83610400 51 50 ff15???????? }
+ $sequence_3 = { e9???????? 55 8bec 56 8b7508 57 bf???????? }
+ $sequence_4 = { f7fb 56 8bf0 bbe0077e00 8bc3 2bc6 83f801 }
+ $sequence_5 = { f77dfc 50 51 e8???????? 83c40c 69c708020000 5f }
+ $sequence_6 = { 8bbdbcd3ffff 53 6a01 8d8d28e1ffff 885dfc }
+ $sequence_7 = { 8d85e8fdffff 6808020000 895dfc 53 50 89bddcfdffff 899de4fdffff }
+ $sequence_8 = { 33c9 8985dcfcffff 51 50 }
+ $sequence_9 = { 8d85f8faffff 50 e8???????? 8bd0 8b02 85c0 7402 }
condition:
- 7 of them and filesize <4177920
+ 7 of them and filesize <288768
}
-rule MALPEDIA_Win_Syscon_Auto : FILE
+rule MALPEDIA_Win_Colibri_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "10b2a70f-de71-5dcd-8008-91d876f6f351"
+ id = "92334149-98b7-5fb0-8e08-056f3f401efb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.syscon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.syscon_auto.yar#L1-L166"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.colibri"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.colibri_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "f7cdfe4679f457a034e50dc400c88cdf6f80bb02175055d824368da084861b59"
+ logic_hash = "70a6e8c65b49a36e967be3c5e646c3791445447505e2691dc2dc449a828d2e49"
score = 75
quality = 75
tags = "FILE"
@@ -163823,38 +170986,32 @@ rule MALPEDIA_Win_Syscon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83e4f8 81ecdc0b0000 a1???????? 33c4 898424d80b0000 53 56 }
- $sequence_1 = { 0f84af000000 53 57 8bc6 e8???????? 83c408 }
- $sequence_2 = { 0f84d8000000 6a00 8d4dfc 51 53 }
- $sequence_3 = { ffd7 8d4c2428 51 8d942414040000 68???????? }
- $sequence_4 = { 88040f 47 897df8 8b45f4 03c6 }
- $sequence_5 = { ffd6 68???????? ffd6 5f 5e b801000000 }
- $sequence_6 = { ffd6 68???????? c745fc00000000 ffd6 }
- $sequence_7 = { 8935???????? ffd7 8d5e01 85c0 7539 a1???????? }
- $sequence_8 = { ff15???????? 488905???????? 4885c0 0f84fbf8ffff }
- $sequence_9 = { 4885c0 7486 488364242000 4c8d8d90030000 448bc3 488bd0 488bcf }
- $sequence_10 = { 80bd3006000020 418bce 7511 488d8530060000 }
- $sequence_11 = { 33d2 e8???????? 488d0da4320000 ff15???????? 488d9520040000 488d0d90320000 448bc0 }
- $sequence_12 = { 488d8d10020000 ff15???????? 488d4d90 448bc3 }
- $sequence_13 = { 488d5590 488d0daa300000 448bc0 e8???????? }
- $sequence_14 = { 488d542450 488d0dad290000 448bc0 e8???????? 488b0d???????? }
- $sequence_15 = { 488d4c2420 4c8bc6 33d2 e8???????? 488d0dc5450000 }
+ $sequence_0 = { 8b4dfc 8d4901 e8???????? 56 56 8bd8 }
+ $sequence_1 = { 0f4575f4 59 e8???????? ba1f90113c 8bc8 e8???????? ffd0 }
+ $sequence_2 = { 83c602 0fb706 8bd0 6685c0 75e2 8933 33c0 }
+ $sequence_3 = { 8bf1 8bfa 897df8 85f6 7502 }
+ $sequence_4 = { 897c2440 57 eba2 8364243c00 eb1b }
+ $sequence_5 = { 8d8578f9ffff 33ff 6804010000 50 57 6a02 59 }
+ $sequence_6 = { 8365f800 50 e8???????? 59 85c0 7413 8b4dfc }
+ $sequence_7 = { 668945a4 6689855effffff 66894d96 59 6a76 58 6a69 }
+ $sequence_8 = { 7445 8b4878 85c9 743e 33ff 39787c 7437 }
+ $sequence_9 = { c1e81f 8d0448 8b0c85c0124000 8d45d4 }
condition:
- 7 of them and filesize <120832
+ 7 of them and filesize <51200
}
-rule MALPEDIA_Win_Bluelight_Auto : FILE
+rule MALPEDIA_Win_Alphanc_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "80cf9226-cefd-5819-9dda-98c83a2352a6"
+ id = "3e24a753-bd90-55fc-a721-b43ae19ca82e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bluelight"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bluelight_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alphanc"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alphanc_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "ac28d46c928f9de871e1c7301334eafe0ce66f50fc56cf0b475e83370bd02ded"
+ logic_hash = "76f5a4c48b7d4b7a92e132b26eac0da2bf874f9a491b16e025e278e5810143fc"
score = 75
quality = 75
tags = "FILE"
@@ -163868,32 +171025,32 @@ rule MALPEDIA_Win_Bluelight_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c7466400000000 6a01 8d4510 c645fc03 50 8d45e0 68???????? }
- $sequence_1 = { e8???????? 85c0 0f85e1040000 8b55c0 8b4638 8d4aff 0fc9 }
- $sequence_2 = { b97bfe0000 e8???????? 8945f8 8b4dfc e8???????? 83670c00 8b45f8 }
- $sequence_3 = { 8bce e8???????? 8bd8 895dc4 85db 0f84bf0e0000 8b5348 }
- $sequence_4 = { 884508 8b4204 8945d8 8b02 8b75d8 3b30 8b75f0 }
- $sequence_5 = { f3a5 eb23 ff742420 68???????? eb92 8d4101 8bcb }
- $sequence_6 = { ff248504d44600 6a00 c743140f000000 8bcb c7431000000000 68???????? c60300 }
- $sequence_7 = { 7414 8bce e8???????? 814b0400000100 894308 8b45fc 8bd0 }
- $sequence_8 = { e8???????? 8bd0 52 e8???????? 83c404 8b4518 8b4df4 }
- $sequence_9 = { f7410400000400 7408 8b4114 8b4804 eb03 8b490c 85c9 }
+ $sequence_0 = { c3 8b4c2428 85c9 757d 8b4c242c 85c9 7543 }
+ $sequence_1 = { e8???????? 83c40c 89442410 85c0 0f84f6010000 8b4d14 8b5510 }
+ $sequence_2 = { eb0a 8b4554 c7400c01000000 8b442414 8b4d54 c74538f0000000 894550 }
+ $sequence_3 = { 03c1 8b4c2444 13d7 2bc1 8bce 1bd1 8b4c243c }
+ $sequence_4 = { 8d55f0 6a00 52 6a04 68???????? 57 ff15???????? }
+ $sequence_5 = { 8b4758 8b8840030000 83f90e 7533 c7805403000001000000 8b4f58 39a978010000 }
+ $sequence_6 = { 33c0 56 f3ab 8b4e58 8b442424 89a9ec000000 8b5658 }
+ $sequence_7 = { 8b4c2430 83c420 8d0c49 8d440804 83f808 0f87d7000000 ff248574354600 }
+ $sequence_8 = { 8d4c2424 51 e8???????? 8d542454 52 e8???????? 8d442470 }
+ $sequence_9 = { 8b4804 83f905 8954241c 7529 8b5048 55 52 }
condition:
- 7 of them and filesize <2191360
+ 7 of them and filesize <2015232
}
-rule MALPEDIA_Win_Flowershop_Auto : FILE
+rule MALPEDIA_Win_Zlob_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8ec68082-5d4c-584e-ad88-66456b2a097b"
+ id = "4fad6172-d1e7-5d84-af68-8861117c390a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flowershop"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flowershop_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zlob"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zlob_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "f019e2c8acff91329c227db3e65589276d7267039537efb349a1a4ca0b28047b"
+ logic_hash = "31e17a6dc34e33dac3ecb614a6996745d9221261fdc2596cb1f9e420f9dc5bc9"
score = 75
quality = 75
tags = "FILE"
@@ -163907,32 +171064,32 @@ rule MALPEDIA_Win_Flowershop_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f857d030000 e9???????? 8325????????00 8b15???????? 85d2 760b 8bca }
- $sequence_1 = { ff750c ff15???????? 8bf0 d1e6 0fb7c6 50 8d470a }
- $sequence_2 = { 33f6 85c0 761e bb???????? 53 57 e8???????? }
- $sequence_3 = { 8b45f0 8b3d???????? 8db008010000 56 6a08 ffd7 50 }
- $sequence_4 = { 33ff 80240100 217dfc 8d450c 50 8d4508 50 }
- $sequence_5 = { 85c0 740a 3b4514 7705 6a01 58 eb02 }
- $sequence_6 = { c3 895104 c3 56 8b742408 57 8b4604 }
- $sequence_7 = { e8???????? 33c0 eb7b 6a01 5e 837c241005 7c5e }
- $sequence_8 = { 33c0 5f 2bd1 c7450824000000 3b7d0c 7712 8b5c0afc }
- $sequence_9 = { 33f6 eb4b 8b7d08 3b7dfc 741c 8d45fc 50 }
+ $sequence_0 = { ffd6 ffd7 68???????? e8???????? c70424???????? 68???????? }
+ $sequence_1 = { 50 ff742434 ff15???????? ff742414 e8???????? ff74242c 8b4c243c }
+ $sequence_2 = { 5d 8bcb 5b 83c404 ff6024 51 51 }
+ $sequence_3 = { 50 e8???????? 8b4508 83c410 83780400 7533 8d85f0eaffff }
+ $sequence_4 = { 58 2bc2 03c8 f644240c02 7504 8d4c7102 8bc1 }
+ $sequence_5 = { 56 8b35???????? 57 8b3d???????? 0f8407020000 837d10ff }
+ $sequence_6 = { ffd7 8b442414 6a01 6a00 6a00 ff30 ff15???????? }
+ $sequence_7 = { ff74242c 8901 50 e8???????? 83c410 ffd3 }
+ $sequence_8 = { ff75e8 8d4dbc e8???????? ff45f8 8b45f8 3b45e4 0f8cedfdffff }
+ $sequence_9 = { 57 8b3d???????? 89442410 8b4508 8b4c2410 }
condition:
- 7 of them and filesize <829440
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Crypmic_Auto : FILE
+rule MALPEDIA_Win_Makop_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "50202601-a687-564d-add6-7e6f376e5e2e"
+ id = "0ddd5ad6-ed99-5e37-bafe-b552882375b1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crypmic"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crypmic_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.makop"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.makop_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "9041d9d560914890b77f3fcac1afa5aa11364ed26eb5680a449dc6f4542c2153"
+ logic_hash = "153590702efa562c07e5adda47cdb1581820d31e1d121adbb82083fd02f6f827"
score = 75
quality = 75
tags = "FILE"
@@ -163946,34 +171103,34 @@ rule MALPEDIA_Win_Crypmic_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 395818 764a 8b7820 03f9 }
- $sequence_1 = { 2bc1 74ec 46 3b75fc 770b 8b55f8 }
- $sequence_2 = { 8b4de4 894f04 8b4de8 894f08 668b4df0 66894f0c 668b45f2 }
- $sequence_3 = { 33d2 8d642400 8d4001 66890c17 }
- $sequence_4 = { 50 8b4608 6a08 ff7604 ffd0 }
- $sequence_5 = { 33c0 8bcf 66894302 e8???????? }
- $sequence_6 = { 43 83c704 3b5818 72bb 5f }
- $sequence_7 = { 55 8bec 83ec0c 8b413c 53 8b440878 03c1 }
- $sequence_8 = { 5d c20800 8b55fc 8b4224 8d0458 0fb70c08 8b421c }
- $sequence_9 = { 8b440878 03c1 8945fc 395818 }
+ $sequence_0 = { 55 8bec 83e4f8 81ec10040000 53 55 56 }
+ $sequence_1 = { 8b84244c010000 8bcb 51 8b8c244c010000 52 50 51 }
+ $sequence_2 = { 117c241c 8bb840080000 017c2420 8bb844080000 117c2424 8b8050080000 3bc3 }
+ $sequence_3 = { 3d11010000 0f8567030000 0fb7442444 0517fcffff 83f806 0f8754030000 ff24859c4f4000 }
+ $sequence_4 = { 53 ff15???????? 85c0 0f84f1000000 6a00 8d442418 }
+ $sequence_5 = { 8d442418 50 51 e8???????? 85c0 0f85cb000000 }
+ $sequence_6 = { bb01000000 395d08 7571 b8???????? 668b08 83c002 6685c9 }
+ $sequence_7 = { 5e 5b 83c41c c3 ff15???????? 50 }
+ $sequence_8 = { 33db 3bf3 740f 56 895e18 895e1c }
+ $sequence_9 = { 895c241c 895c2420 895c2424 745e 90 8b06 }
condition:
- 7 of them and filesize <81920
+ 7 of them and filesize <107520
}
-rule MALPEDIA_Win_Satana_Auto : FILE
+rule MALPEDIA_Win_Tidepool_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d19234af-c9bd-5654-81eb-f961478057fe"
+ id = "736615ac-754a-59af-859e-d31c5da8062a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.satana"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.satana_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tidepool"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tidepool_auto.yar#L1-L265"
license_url = "N/A"
- logic_hash = "bdc48675727bdd579a6ca8ed3a223cef8d8ab6026da5d019b40d5fe8d696eb85"
+ logic_hash = "6d671b94ab0cdccf8b9683ef25d1220e65648f34328ff5e4475983ab8ad7951c"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -163985,32 +171142,51 @@ rule MALPEDIA_Win_Satana_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b3d???????? 90 ffd6 68e8030000 ffd7 }
- $sequence_1 = { ff15???????? 8b459c 50 ff15???????? 8b4ddc 010d???????? }
- $sequence_2 = { 8d8c2468020000 51 e8???????? 8b442410 8d542418 52 }
- $sequence_3 = { 8b5108 ffd2 6a00 8b45fc 8b480c ffd1 8be5 }
- $sequence_4 = { 68???????? e8???????? 83c414 53 6880000000 }
- $sequence_5 = { 83c002 663bcb 75f1 8d8de89effff 51 e8???????? }
- $sequence_6 = { 57 50 68???????? e8???????? 83c414 833d????????00 745a }
- $sequence_7 = { ffd3 8bf8 a1???????? 57 }
- $sequence_8 = { 105353 bf60600157 ff7528 fc ffd6 0105???????? f8 }
- $sequence_9 = { ff15???????? e8???????? 837de401 0f8e12030000 8b4704 }
+ $sequence_0 = { 6a00 50 8b08 ff91a4000000 }
+ $sequence_1 = { 8b4df4 64890d00000000 59 5f 5e 5b 8b8d00030000 }
+ $sequence_2 = { 8b8d00030000 33cd e8???????? 81c504030000 }
+ $sequence_3 = { 83c404 8bc6 5e c20400 80790800 }
+ $sequence_4 = { 53 6a02 8bf1 e8???????? }
+ $sequence_5 = { 6800000040 8d4500 50 ff15???????? }
+ $sequence_6 = { 2bc8 83e906 51 83c006 50 }
+ $sequence_7 = { e8???????? 83c40c 803d????????37 7518 68???????? }
+ $sequence_8 = { 8b4654 8d9698000000 52 8d5678 8b08 }
+ $sequence_9 = { 52 50 8b08 ff91f8000000 85c0 }
+ $sequence_10 = { 8b4654 50 8b08 ff5138 }
+ $sequence_11 = { 8d5658 52 50 ff91d0000000 33ff }
+ $sequence_12 = { c3 56 8bf1 e8???????? 8b4654 }
+ $sequence_13 = { 8d45ec 50 681f000200 53 }
+ $sequence_14 = { 6810270000 ff15???????? 8b45ec 8b08 }
+ $sequence_15 = { 681f000200 56 68???????? 6801000080 }
+ $sequence_16 = { 75f9 b8???????? b900000400 c60000 40 49 }
+ $sequence_17 = { e8???????? 68???????? 68???????? 68???????? 8d4500 }
+ $sequence_18 = { 57 50 6802020000 ff15???????? 68???????? ff15???????? }
+ $sequence_19 = { 8bc6 5e 5b c20400 6a14 68???????? }
+ $sequence_20 = { 6805400080 e8???????? 8b542424 52 53 }
+ $sequence_21 = { 33c9 8aea 83c003 83c504 }
+ $sequence_22 = { ff75ec ff15???????? 8b35???????? 6a04 }
+ $sequence_23 = { 83651400 8b07 83c40c 837d0c00 0f8ed1000000 8b4d08 41 }
+ $sequence_24 = { 8bec 8b4508 56 833c850811011000 }
+ $sequence_25 = { 50 ff7508 ff15???????? 395dfc 53 }
+ $sequence_26 = { 50 8d4604 50 e8???????? 8d45e0 6a04 }
+ $sequence_27 = { 50 89450c ff15???????? 53 ff75fc ff75f8 }
+ $sequence_28 = { 8365ec00 8945f4 8d3dd8e30010 8b45f4 d1e0 03f8 }
condition:
- 7 of them and filesize <221184
+ 7 of them and filesize <1998848
}
-rule MALPEDIA_Win_H1N1_Auto : FILE
+rule MALPEDIA_Win_Sasfis_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5e13a49f-72f0-5eb3-a885-2e0245e8f66e"
+ id = "5e363129-1d9b-5d5a-8006-da18dff7062a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.h1n1"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.h1n1_auto.yar#L1-L170"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sasfis"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sasfis_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "842ef63a8a089830b40dfc0f60da9194950df4056683b94edaa8a18caec3ebbd"
+ logic_hash = "7eee2ccd93eb9390961368e951e0384a076b29fc7a953a6afc5b8df0aa798b71"
score = 75
quality = 75
tags = "FILE"
@@ -164024,38 +171200,32 @@ rule MALPEDIA_Win_H1N1_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 49 85c9 0f8527ffffff ff75f8 }
- $sequence_1 = { 49 75b6 8bcf 2b4d0c 83e103 }
- $sequence_2 = { 83bdecfeffff01 7505 bb07000000 93 5b c9 c3 }
- $sequence_3 = { aa ac 0ac0 740e 3c3d 740a e8???????? }
- $sequence_4 = { 0345f4 8b8ba4000000 85c9 742b }
- $sequence_5 = { ff7508 6a00 ff35???????? 58 ffd0 }
- $sequence_6 = { 351f5b5742 ab 05f8383ad2 ab ff75fc }
- $sequence_7 = { 59 85c0 75d1 83bb8000000000 7465 }
- $sequence_8 = { 8d8614850010 50 ffb610850010 57 }
- $sequence_9 = { 59 c3 56 8b742408 6804010000 68f8820010 }
- $sequence_10 = { 330c85908f0010 42 3b54240c 72e4 f7d1 8bc1 }
- $sequence_11 = { 57 8d3c95c0850010 8b0f 334f04 23cb }
- $sequence_12 = { 330d???????? 5b 8bc1 83e001 d1e9 330c8500850010 330d???????? }
- $sequence_13 = { 57 50 e8???????? 68f4600010 56 }
- $sequence_14 = { 33d2 a3???????? 42 b9c0850010 8b01 c1e81e 3301 }
- $sequence_15 = { 6800800010 ff742410 e8???????? 6823af2930 56 ff742410 }
+ $sequence_0 = { 8433 a6 0d60ca8b0c 646b1a5c }
+ $sequence_1 = { d7 4b 7ca9 bc74460651 130d???????? 37 d502 }
+ $sequence_2 = { 157e2808b7 0016 2038 2410 }
+ $sequence_3 = { 60 0c1c 0430 00242c 1838 3c00 3808 }
+ $sequence_4 = { 84df 66ffc5 8b742448 66f7df }
+ $sequence_5 = { f9 f6c77d 660fbae10b 83c504 }
+ $sequence_6 = { 657326 6e 346f 6f 68432b3501 }
+ $sequence_7 = { 6681cf5b01 81ec9c000000 57 60 5f }
+ $sequence_8 = { 2909 26df6883 95 7800 e8???????? 15afb28a60 38342c }
+ $sequence_9 = { 260c16 005220 0410 1400 }
condition:
- 7 of them and filesize <172032
+ 7 of them and filesize <8060928
}
-rule MALPEDIA_Win_Wonknu_Auto : FILE
+rule MALPEDIA_Win_Xpan_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ddaff543-6be8-5c88-9c2c-3d8f03caff26"
+ id = "7325c725-fe3e-5c78-bad6-69f44695968e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wonknu"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wonknu_auto.yar#L1-L111"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xpan"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xpan_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "97458316dc025f2ef3806add4e0540e6bc317fe3a272c04393704aa62f6ae30d"
+ logic_hash = "be7f9da8e0e3ad23e9493cdb12bfec902f58437483383423a4e4858dbe439d66"
score = 75
quality = 75
tags = "FILE"
@@ -164069,32 +171239,32 @@ rule MALPEDIA_Win_Wonknu_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8bfc b901050000 f3a5 8bcb }
- $sequence_1 = { e8???????? 8bfc b901050000 f3a5 8bcb e8???????? }
- $sequence_2 = { b901050000 f3a5 8bcb e8???????? 803b00 }
- $sequence_3 = { 6a04 50 ff15???????? 68???????? }
- $sequence_4 = { e8???????? 8bfc b901050000 f3a5 8bcb e8???????? 803b00 }
- $sequence_5 = { e8???????? 8bfc b901050000 f3a5 }
- $sequence_6 = { eb08 c6840550ffffff00 8d8550ffffff 50 }
- $sequence_7 = { 53 56 57 6804140000 }
- $sequence_8 = { c6840550ffffff00 8d8550ffffff 50 e8???????? }
- $sequence_9 = { 8d7e28 57 ff15???????? 8b4608 }
+ $sequence_0 = { 83c001 c7450cffffffff 894108 8b4108 3b410c 0f83cb050000 0fb600 }
+ $sequence_1 = { 8bb018010000 85f6 0f8557010000 8b01 89cd 83f84d 0f870d1d0000 }
+ $sequence_2 = { 8b5d20 83e001 05ffffff7f 8903 8b451c c70004000000 807dbc00 }
+ $sequence_3 = { 8b442428 895c2404 89442408 ff15???????? 39c3 7247 }
+ $sequence_4 = { ffd5 83ec04 83fe05 75ea 8d7338 c7431cffffffff }
+ $sequence_5 = { 8b55d0 c645c201 0fbed8 0fb65210 e9???????? c645c100 c645c201 }
+ $sequence_6 = { 8b930c010000 88442418 be01000000 c683ff00000000 c7442404ff000000 891c24 89542408 }
+ $sequence_7 = { 0fb644242c 89442404 89f0 83c002 890424 e8???????? e9???????? }
+ $sequence_8 = { e9???????? 8d489f 80f905 0f874b0e0000 83e857 e9???????? 8b931c010000 }
+ $sequence_9 = { 31c0 e9???????? 8b44241c 897c243c 89442438 8d442438 898310010000 }
condition:
- 7 of them and filesize <540672
+ 7 of them and filesize <3235840
}
-rule MALPEDIA_Win_Unidentified_003_Auto : FILE
+rule MALPEDIA_Win_Unidentified_080_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "078af5cf-1960-57c1-ad2f-834d23801cf0"
+ id = "b4f490ab-c91a-5e77-9e61-88b48864f732"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_003"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_003_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_080"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_080_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "44e97183e244c5496d21c90ef879a2c3ae0327847947e2b5ee30ab46305a46ce"
+ logic_hash = "a554ba61b72496370ffd16dee0c3f2b6444ec6fc0c35b79b5428032562bbd4cc"
score = 75
quality = 75
tags = "FILE"
@@ -164108,32 +171278,32 @@ rule MALPEDIA_Win_Unidentified_003_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945ec a1???????? 0fb7506f 0fb7406d c1e210 0bd0 }
- $sequence_1 = { c68564ffffff01 33c0 8a88c2100900 888c0566ffffff 40 }
- $sequence_2 = { e8???????? 83c40c 8b07 5d c3 55 8bec }
- $sequence_3 = { a1???????? ff75f0 ff7028 ff15???????? eb0a }
- $sequence_4 = { 395da0 740f ff75a4 ff15???????? 895da0 }
- $sequence_5 = { 3bfe 7502 8bfb 39742410 }
- $sequence_6 = { 59 85c0 7417 47 81c614010000 3b3d???????? 72c8 }
- $sequence_7 = { 8bec 81ec20080000 53 56 57 8d85e0fdffff 8945ec }
- $sequence_8 = { 7575 385d6e 743b 39bd5cffffff 750a c705????????07000000 399d5cffffff }
- $sequence_9 = { ff15???????? 85c0 0f88b4010000 8b45e4 3bc3 0f84a9010000 8b08 }
+ $sequence_0 = { 51 53 8bd8 837b2c00 56 7571 8b4324 }
+ $sequence_1 = { 0bf2 89701c 83c020 83c120 ff8d74ffffff 0f8560feffff 8b8570ffffff }
+ $sequence_2 = { 8b4508 8b4808 8b500c 2bd1 894dfc 3bd3 7277 }
+ $sequence_3 = { 3bd6 7312 8b03 833c9000 8d0490 7402 }
+ $sequence_4 = { 8dbd40ffffff e8???????? 8bb53cffffff 83c620 c645fc0f 8b06 33ff }
+ $sequence_5 = { 83e73f 0b0cbdb8840210 83e03f 0b0c85b8860210 8b42f4 33c6 8bf8 }
+ $sequence_6 = { 8bec 83ec10 53 8bd8 ff4320 56 33f6 }
+ $sequence_7 = { 8bf0 83feff 7509 c68568ffffff0b eb66 8b4dbc }
+ $sequence_8 = { 57 50 8d45f4 64a300000000 33ff 33f6 }
+ $sequence_9 = { 8b4e30 8d5508 52 8b562c 50 51 52 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <392192
}
-rule MALPEDIA_Win_Targetcompany_Auto : FILE
+rule MALPEDIA_Win_Pony_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e6fff5d7-7001-551f-9dad-753a10f6e88e"
+ id = "d90fd047-9438-55a9-9e35-1d6c2ea6d18d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.targetcompany"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.targetcompany_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pony"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pony_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "a6f3e9a1f1d0d374d374e6c7006eb751526bddf3371b115cfe046f8accd1d439"
+ logic_hash = "8fcd4026be1a9e152c2bd589ec65b90e934cc06d61e86dd6cd06c58ac6d41a1e"
score = 75
quality = 75
tags = "FILE"
@@ -164147,32 +171317,32 @@ rule MALPEDIA_Win_Targetcompany_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 85c0 7475 fe85a7fdffff 80bda7fdffff0c }
- $sequence_1 = { 53 ff15???????? ff75e8 ff15???????? ff75e0 ff15???????? 3975f0 }
- $sequence_2 = { eb43 b900100000 3bc1 733a 53 51 }
- $sequence_3 = { 83c424 33cd 33c0 5f e8???????? c9 c3 }
- $sequence_4 = { 813d????????a9aaaa0a 722b 68???????? 8d4dd4 }
- $sequence_5 = { e8???????? 57 6a0c 5a 8bce 8d45e0 e8???????? }
- $sequence_6 = { 83ec40 53 56 33f6 57 8d5dc4 }
- $sequence_7 = { 50 8d45b0 50 e8???????? 8d45b0 50 8d85c0feffff }
- $sequence_8 = { bf???????? 8d75e8 e8???????? 8b1d???????? 8d75f0 }
- $sequence_9 = { 8945ec e8???????? 53 6a01 8d758c e8???????? 53 }
+ $sequence_0 = { c20400 55 89e5 83ec18 53 }
+ $sequence_1 = { c745f400000000 8d45f8 50 ff7508 6a00 ff15???????? }
+ $sequence_2 = { bfffffffff 33f9 0bf8 33fb 8d941792cc0c8f 03560c }
+ $sequence_3 = { ff75e8 ff7508 e8???????? 23d8 ff75ec e8???????? }
+ $sequence_4 = { f7d0 50 ff7508 e8???????? c9 c20400 }
+ $sequence_5 = { ff7514 e8???????? eb0d 68???????? }
+ $sequence_6 = { c9 c20400 55 8bec 83c4fc ff7514 ff7510 }
+ $sequence_7 = { ff75c8 e8???????? ff75c4 e8???????? ff75bc }
+ $sequence_8 = { b9ffffffff f2ae 3807 75c5 6a1a ff7508 }
+ $sequence_9 = { e8???????? ff7510 6a18 ff7508 e8???????? ff7510 }
condition:
- 7 of them and filesize <328704
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Pss_Auto : FILE
+rule MALPEDIA_Win_Enfal_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c85e1f97-adb5-5a29-88aa-4e9dab9b1814"
+ id = "7c648ee2-e4dd-541c-9b47-28a132a1416c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pss"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pss_auto.yar#L1-L136"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.enfal"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.enfal_auto.yar#L1-L112"
license_url = "N/A"
- logic_hash = "3fa2b0cf1b29b7abf02331e25c131d124a839f7a317f2ebb6c59c1c9547e53c0"
+ logic_hash = "4106f1f3c4e35436925009af22c1e6b23f6200a61794638682b09644acc42fa2"
score = 75
quality = 75
tags = "FILE"
@@ -164186,35 +171356,32 @@ rule MALPEDIA_Win_Pss_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d48fe e8???????? e9???????? 83f811 }
- $sequence_1 = { 7437 ff15???????? 3de5030000 752a }
- $sequence_2 = { ff15???????? 83ceff 3bc6 7504 }
- $sequence_3 = { 5e 5b 0f42ca 85c0 0f45c8 }
- $sequence_4 = { 0fb619 0fb6c0 eb17 81fb00010000 7313 8a87a4f10110 }
- $sequence_5 = { 8d542418 8bce e8???????? 59 59 }
- $sequence_6 = { 8bf9 46 85ff 744f 833fff 7410 ff37 }
- $sequence_7 = { 0fb6c0 5f 5e 5b c9 }
- $sequence_8 = { 488d4c2428 e8???????? 90 4c8d05b3b70000 488bd0 488d0db1610100 }
- $sequence_9 = { ff15???????? b001 eb25 e8???????? }
- $sequence_10 = { e8???????? 90 4c8d05d3b50000 488bd0 }
- $sequence_11 = { 488bcb e8???????? e9???????? ba80000000 488bcb }
- $sequence_12 = { 488b4de7 e8???????? 48c745ff07000000 48897df7 }
+ $sequence_0 = { ffd6 68???????? 57 8945d8 ffd6 68???????? 53 }
+ $sequence_1 = { 51 53 ff505c 85c0 }
+ $sequence_2 = { 50 6a00 6a01 ff7608 }
+ $sequence_3 = { 57 6800000040 51 ff5010 8bd8 }
+ $sequence_4 = { 81ec4c0a0000 80a5b4f9ffff00 56 baff000000 }
+ $sequence_5 = { 8b4b24 8b431c 8b5320 8365fc00 }
+ $sequence_6 = { 50 e8???????? 83c410 8b461c }
+ $sequence_7 = { 8bec 81eccc040000 53 56 8b35???????? 57 }
+ $sequence_8 = { ffd0 5e c3 ff15???????? 5e c3 }
+ $sequence_9 = { 66a5 a4 be???????? 8dbd60ffffff }
condition:
- 7 of them and filesize <421888
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Bandit_Auto : FILE
+rule MALPEDIA_Win_Ratankba_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4242f486-f361-5c1c-837c-874b9d2592eb"
+ id = "fd423e85-7c69-52a0-9324-ef5e9762e7e8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bandit"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bandit_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ratankba"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ratankba_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "e59306c04a92c7c36290cce1b84004757d2fea7b6a860dd6621dd5fc2300ad60"
+ logic_hash = "49523307c1fdb5d69527def26960d83b0ac500a3f11bec0bed9b0e81e333a8ec"
score = 75
quality = 75
tags = "FILE"
@@ -164228,34 +171395,34 @@ rule MALPEDIA_Win_Bandit_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 488d0d9ca6a100 48894820 833d????????00 750b 488b4c2478 48894828 }
- $sequence_1 = { c3 4889d0 e8???????? 84c0 744e 488b4c2428 488b11 }
- $sequence_2 = { 83c301 4883c604 4501f1 e8???????? 4139df 75d6 8b742460 }
- $sequence_3 = { e9???????? 488d5f01 4839da 731d 4889f0 4889d1 bf01000000 }
- $sequence_4 = { e8???????? 48c7401801000000 488d0d1c9c5e00 48894810 4889c3 488d0530636a00 488b6c2440 }
- $sequence_5 = { ffd2 4889442438 48895c2440 48894c2448 48897c2450 90 488b7c2430 }
- $sequence_6 = { c644242701 488b4210 488b5c2428 488b4c2430 488b7c2438 6690 e8???????? }
- $sequence_7 = { 8894249d000000 0fb654246c 4129d7 4488bc249e000000 0fb6542474 440fb6442425 4429c2 }
- $sequence_8 = { e8???????? 4889d7 c60700 488d050e9a6b00 e8???????? 488b4c2438 488b542448 }
- $sequence_9 = { c604085c 49f7d9 49c1f93f 4c8d5101 4d21ca 4e8d0c10 48f7df }
+ $sequence_0 = { 5d c20800 8b4d0c 803900 7416 807d0b00 7410 }
+ $sequence_1 = { 53 b8???????? 668911 e8???????? 8d8ec0000000 c645fc05 33c0 }
+ $sequence_2 = { 53 ff15???????? 85c0 740e 8b45fc 85c0 7407 }
+ $sequence_3 = { 55 8bec ff4724 8b4724 53 56 394718 }
+ $sequence_4 = { e8???????? 8b4310 33ff 3bc7 7649 397e10 7644 }
+ $sequence_5 = { 720a b857000780 e8???????? 8b4b04 5f 8944d104 8bc2 }
+ $sequence_6 = { 83c414 85c0 744f 8bc8 e8???????? 8bf0 a1???????? }
+ $sequence_7 = { 0f849b010000 83c302 46 ebaa 8b5710 8bc6 8955e4 }
+ $sequence_8 = { 8975f4 85f6 790b 5e 83c8ff 5b 8be5 }
+ $sequence_9 = { 56 66898578efffff 51 83c8ff 8dbd78efffff c7858cefffff07000000 }
condition:
- 7 of them and filesize <29914112
+ 7 of them and filesize <303104
}
-rule MALPEDIA_Win_Blister_Auto : FILE
+rule MALPEDIA_Win_Holerun_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e15c5b26-46b1-50a6-b793-c24acb88c7d0"
+ id = "3860635a-d58f-5696-9faf-227bf0bff05b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blister"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blister_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.holerun"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.holerun_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "2e7268df1a1003febf7615ed82849d5ba6785115864de7e2d3f4d8bf888a50fc"
- score = 60
- quality = 25
+ logic_hash = "5a5dd43f05b56cbfa86f75c5f65da136c78c894cffec56359e16aa1bc679245f"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -164267,32 +171434,32 @@ rule MALPEDIA_Win_Blister_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33f6 8d4447fe 8975fc 8945f8 3bfe 0f8447010000 }
- $sequence_1 = { 57 ff75fc ffd6 85c0 7529 33c9 41 }
- $sequence_2 = { e8???????? 8bf0 85f6 7c2e 6a04 58 8d4d08 }
- $sequence_3 = { 8bff 55 8bec b8dc140000 e8???????? a1???????? 33c5 }
- $sequence_4 = { 8b3d???????? 6870010000 684c040000 ff7604 ffd7 8b1d???????? }
- $sequence_5 = { 8d45a0 50 ff750c c745a060000000 6891100000 ff36 }
- $sequence_6 = { ff7604 ff75f4 ff75e8 6a02 ff75fc ff15???????? 85c0 }
- $sequence_7 = { 8b4e28 8d45f8 50 895df8 e8???????? }
- $sequence_8 = { ff15???????? 8bc8 0fb701 f7d8 1bc0 23c1 5e }
- $sequence_9 = { 50 8b859cf7ffff 8b8c052cf7ffff e8???????? 8985a8f7ffff 85c0 0f8cf9010000 }
+ $sequence_0 = { 85c0 740c c785ec00000000000000 eb63 488b05???????? }
+ $sequence_1 = { e8???????? 8b45c4 83f840 7472 8b45c4 83f804 }
+ $sequence_2 = { c744242000010000 41b901000000 41b800000000 ba03000000 4889c1 }
+ $sequence_3 = { 488b85e0000000 488b4020 4889c1 488b05???????? ffd0 }
+ $sequence_4 = { ffd0 488b85e0000000 488b4020 4889c1 488b05???????? }
+ $sequence_5 = { ffd0 8b85cc030000 4881c458040000 5b 5d c3 }
+ $sequence_6 = { 4883c00f 48c1e804 48c1e004 e8???????? 4829c4 }
+ $sequence_7 = { eb1e 8345f401 488345f828 488b45e8 0fb74006 0fb7c0 }
+ $sequence_8 = { c705????????00000000 c705????????00000000 8b45fc 8905???????? }
+ $sequence_9 = { 488b4d10 e8???????? 4885c0 7507 b8ffffffff eb05 }
condition:
- 7 of them and filesize <1822720
+ 7 of them and filesize <156672
}
-rule MALPEDIA_Win_Crenufs_Auto : FILE
+rule MALPEDIA_Win_Unidentified_107_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f753eb30-be4b-5f62-9991-28649f65a79a"
+ id = "3e7e44ff-0f02-5267-8346-e5f949ff1ff2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crenufs"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crenufs_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_107"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_107_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "62adacba8819f400983ac2aed5807f2d80c5566db3c1a2873916dcd6fb658c9d"
+ logic_hash = "36a3784a29d5434d0fa9e9c5acdfc21d8509c8e92eeaa689801f442b7fb11fdb"
score = 75
quality = 75
tags = "FILE"
@@ -164306,32 +171473,32 @@ rule MALPEDIA_Win_Crenufs_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b0c8de0934000 25ff000000 c1ea18 33cb 8b1c95e08f4000 8b56f8 }
- $sequence_1 = { 55 56 57 8bf9 8a4c2444 33ed 884c2425 }
- $sequence_2 = { ff15???????? 56 8d4d90 c645fc05 ff15???????? 56 8d4de0 }
- $sequence_3 = { ffd0 83c408 53 ff15???????? 8b44243c 8b4e08 3bc5 }
- $sequence_4 = { 59 50 57 8d4de0 ff15???????? bf???????? 57 }
- $sequence_5 = { 750c 8b3d???????? 891d???????? 8d4c2444 ff15???????? 3bfb 7409 }
- $sequence_6 = { ff15???????? 8d8d3cf2ffff c645fc03 e8???????? c645fc02 56 }
- $sequence_7 = { 84c0 89542410 743e 3b31 752d 53 56 }
- $sequence_8 = { 8d4c2444 895c2428 895c2430 33ff ff15???????? a1???????? 48 }
- $sequence_9 = { 895dfc e8???????? 8b10 8bc8 ff5210 }
+ $sequence_0 = { 4139d9 75d8 4c89e1 e8???????? }
+ $sequence_1 = { 48897008 4c89e1 ff15???????? 488b05???????? 4c89e1 48891d???????? }
+ $sequence_2 = { 0f83d6fdffff 4c8b35???????? 8b7304 448b2b 4883c308 4c01f6 44032e }
+ $sequence_3 = { 034208 4839c1 7214 4883c228 }
+ $sequence_4 = { 0f8584000000 4c8b3e 4929c7 4901cf }
+ $sequence_5 = { e8???????? 4c89e1 ff15???????? 31c0 4883c428 }
+ $sequence_6 = { 8b15???????? 85d2 0f8ea1feffff 488b35???????? 31db 4c8d65fc }
+ $sequence_7 = { e8???????? 4989c7 48b9ca0e99c700000000 e8???????? 4883c464 488b4c2408 }
+ $sequence_8 = { 4183fc01 0f85a9feffff 8b05???????? 85c0 0f8e9bfeffff 83e801 488b1d???????? }
+ $sequence_9 = { 4c89442418 4c894c2420 4883ec64 48c7c10f15af3d }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <254976
}
-rule MALPEDIA_Win_Wpbrutebot_Auto : FILE
+rule MALPEDIA_Win_Unidentified_074_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ee6ef210-d105-53c3-a558-0e67b4040536"
+ id = "0d21a50a-0481-57c8-ac0f-f7fe46c9359f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wpbrutebot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wpbrutebot_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_074"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_074_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "709c38b5efc64910ec1c02f61c4cfca810d098711a98c2359e209f406eb3230c"
+ logic_hash = "e6b5821f00996c51a196dd1c4d62a76bb0e0925ea653a38d0c3db163875f48e7"
score = 75
quality = 75
tags = "FILE"
@@ -164345,32 +171512,32 @@ rule MALPEDIA_Win_Wpbrutebot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 894f54 897758 89775c e9???????? 85c9 7515 c7475003000000 }
- $sequence_1 = { f7472c00010000 b35d 7411 8b4730 6a5d 8b4804 8b01 }
- $sequence_2 = { f6044dc81e5e0002 7410 8bc1 ba01000000 83f020 85d2 0f44c1 }
- $sequence_3 = { c645fc04 8d8dfcf4ffff e8???????? 68???????? 8bd0 c645fc05 8d8d14f5ffff }
- $sequence_4 = { ff742420 8b7a08 037c2420 89442448 c744244c01000000 897c2450 8b4a08 }
- $sequence_5 = { c781f0050000bfe45900 5b 83c408 c3 5f 5e 5d }
- $sequence_6 = { 7228 8bb504ffffff 8d8504ffffff 50 8bc8 e8???????? 8b8518ffffff }
- $sequence_7 = { 8b44245c a802 b800000000 0f45d8 895c241c 85f6 7410 }
- $sequence_8 = { f7e9 d1fa 8bc2 c1e81f 03c2 83f801 762b }
- $sequence_9 = { ffb7ec0c0000 6a01 53 e8???????? 8be8 83c410 }
+ $sequence_0 = { 50 ffb578dfffff e8???????? 33c0 c7858cdfffff07000000 c78588dfffff00000000 66898578dfffff }
+ $sequence_1 = { 50 e8???????? 6aff 6a01 83ec08 c745fc00000000 8d4dd8 }
+ $sequence_2 = { 3bc1 7432 8b4d08 8d041e 8a0408 3a02 7516 }
+ $sequence_3 = { 50 ff15???????? 8bf0 85f6 0f84c4010000 837f1000 }
+ $sequence_4 = { 50 899d6cdfffff c78568dfffff00000000 660fd645e4 e8???????? }
+ $sequence_5 = { c78524e7ffff07000000 66898510e7ffff 8d85f8e6ffff 50 8d8540e7ffff c78520e7ffff00000000 50 }
+ $sequence_6 = { 8d4e01 8a06 46 84c0 75f9 8d4588 }
+ $sequence_7 = { e8???????? 83c40c 019dc4feffff 8b85c4feffff }
+ $sequence_8 = { 83ec08 8845f0 8d45f0 50 e8???????? 884435e8 }
+ $sequence_9 = { 8d8d70e7ffff 6a12 33c0 c78584e7ffff07000000 }
condition:
- 7 of them and filesize <5134336
+ 7 of them and filesize <335872
}
-rule MALPEDIA_Win_Stealbit_Auto : FILE
+rule MALPEDIA_Win_Startpage_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ba610849-1495-5151-b945-327f0dc5f838"
+ id = "bf47ff90-3238-555c-bf4a-537084ae22d6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stealbit"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stealbit_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.startpage"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.startpage_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "0ba0bc4f1da3f2dc67b8b88d21908b92c199e11ae8a3f814064895150fd93270"
+ logic_hash = "9dae8bd02cc42718a63c04f81edbd9a29e9f4300c24f882a2c1fba0669713697"
score = 75
quality = 75
tags = "FILE"
@@ -164384,32 +171551,32 @@ rule MALPEDIA_Win_Stealbit_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4e30 e8???????? 8b4e30 e8???????? 83663000 8d562c }
- $sequence_1 = { 8d8580fbffff 50 e8???????? 8bc8 e8???????? ffd0 8bd8 }
- $sequence_2 = { 8bfa 8bd9 e8???????? 8bc8 e8???????? ffd0 8bf0 }
- $sequence_3 = { e8???????? 8bc8 e8???????? ffd0 6a02 68bf000000 53 }
- $sequence_4 = { c786a802000000000000 8d7e50 33db 8b4620 }
- $sequence_5 = { 6a6f 66898546ffffff 33c0 66898548ffffff 58 6a63 668985d2fcffff }
- $sequence_6 = { 66899570feffff 66899574feffff 5a 6a6d 58 6a69 66898500feffff }
- $sequence_7 = { 6689859afeffff 33c0 668955de 5a 6a61 6689bd86feffff }
- $sequence_8 = { 8945f8 e8???????? 03c0 8bce 8bd0 e8???????? 6a0c }
- $sequence_9 = { e8???????? 8bc8 e8???????? 3d15cffdb1 740b 46 3bf7 }
+ $sequence_0 = { 8945ec 85db 740c 8b0b 85c9 7406 0fb701 }
+ $sequence_1 = { 83eb01 75f1 8b75f8 8b06 33c9 663b08 759d }
+ $sequence_2 = { 75f5 2bd1 d1fa 5b 52 ff7508 8bcf }
+ $sequence_3 = { 8901 89742410 eb06 8931 8b742410 8b44241c 85c0 }
+ $sequence_4 = { 8bec a1???????? 85c0 740e 50 e8???????? 8325????????00 }
+ $sequence_5 = { 722e 8b4dc0 40 3d00100000 721a f6c11f 759c }
+ $sequence_6 = { 8b03 8bfb 53 ff5004 8b7508 33c9 8bc3 }
+ $sequence_7 = { e8???????? 59 c645fc01 8b8de0feffff 83c1f0 e8???????? 51 }
+ $sequence_8 = { 755f 8a0a 8d4201 8907 80f975 7553 8b4db8 }
+ $sequence_9 = { 8907 50 50 8945fc ff35???????? ff31 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <2277376
}
-rule MALPEDIA_Win_Unidentified_110_Auto : FILE
+rule MALPEDIA_Win_Pteranodon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "264cfac8-ace3-5d01-a52d-48fde572696d"
+ id = "547312ac-3667-5c97-9fc9-daff4d88f305"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_110"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_110_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pteranodon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pteranodon_auto.yar#L1-L173"
license_url = "N/A"
- logic_hash = "d08f798b1cfbec1be54b7df96bb36676a27b486448d2260bb80e971ad4c99ec2"
+ logic_hash = "5752ea7e57aaa9393a80bd68b7b77d472dc2c58ad73fb0c8d5639c2a359a3d60"
score = 75
quality = 75
tags = "FILE"
@@ -164423,32 +171590,38 @@ rule MALPEDIA_Win_Unidentified_110_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff5638 4839d8 756f 488b37 ba08000000 4889f9 e8???????? }
- $sequence_1 = { 7809 488d1542850a00 59 c3 b907000000 cd29 0f0b }
- $sequence_2 = { 8b842440010000 898424f0000000 0f28842420010000 0f288c2430010000 0f298c24e0000000 0f298424d0000000 8b8424c8000000 }
- $sequence_3 = { 884710 4883670800 c6471100 488d542428 48891a 4c8d052abf0e00 eb3e }
- $sequence_4 = { 488d95100a0000 48c70208000000 488d8d70120000 e8???????? e9???????? 4c8bb568130000 6a0c }
- $sequence_5 = { 488d8c24f0010000 e8???????? 41bf01000000 e9???????? 488dac2460010000 488b4530 4889842400010000 }
- $sequence_6 = { 4c89fa 4989c0 e8???????? 488b8698000000 4801d8 483b8690000000 7763 }
- $sequence_7 = { 89ca b101 e9???????? b103 e9???????? 4c8b01 410fb64810 }
- $sequence_8 = { ffe1 31c9 4883bc241801000004 0f84f8620000 488b942448030000 488b32 4883fe02 }
- $sequence_9 = { eb02 31c0 4883c428 c3 4c8d0df4bf0900 4889c1 4c89c2 }
+ $sequence_0 = { 394614 7320 51 50 8bce }
+ $sequence_1 = { 8d8dc0f8ffff e9???????? 8d8dc0f8ffff e9???????? 8d8dc0f8ffff e9???????? 8d8d08f9ffff }
+ $sequence_2 = { 59 83e03f 59 6bc838 8b04b5e0874300 03c1 }
+ $sequence_3 = { 8d45f0 50 ff15???????? 83f802 7541 8d4df0 e8???????? }
+ $sequence_4 = { 8b04f5b49b0210 5f 5e 5b 5d }
+ $sequence_5 = { ffd0 0fb7f0 8bcf 8b07 8b4008 ffd0 }
+ $sequence_6 = { c7869800000038c90210 c7460401000000 8b4dfc 5f 5e 33cd }
+ $sequence_7 = { 0f8490000000 53 6a00 56 e8???????? }
+ $sequence_8 = { 2bd0 d1fa 8d7902 668b01 83c102 }
+ $sequence_9 = { 8d8d78f8ffff c645fc1e e8???????? 8b851cf9ffff 83f810 7213 40 }
+ $sequence_10 = { 660f28aa802c4300 660f54e5 660f58fe 660f58fc 660f59c8 f20f59d8 }
+ $sequence_11 = { 3bc1 7419 85c0 b001 }
+ $sequence_12 = { 1bc0 23c1 83c008 5d c3 8b04c5849f4200 }
+ $sequence_13 = { c3 8b04c58cbf0210 5d c3 }
+ $sequence_14 = { c645fc0b 8d8df0f8ffff e8???????? 8d8d20f9ffff c645fc0c 03ce }
+ $sequence_15 = { 53 e8???????? 83c404 8945ec 53 8bd8 }
condition:
- 7 of them and filesize <3217408
+ 7 of them and filesize <499712
}
-rule MALPEDIA_Win_Saigon_Auto : FILE
+rule MALPEDIA_Win_Satellite_Turla_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a473943a-8ea5-58ac-80e3-98de6dfb8169"
+ id = "79b83503-3c79-5740-8814-f6490a13be5c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.saigon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.saigon_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.satellite_turla"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.satellite_turla_auto.yar#L1-L160"
license_url = "N/A"
- logic_hash = "a5d9048555d265aef66c2410783198e6f4dd9139107e5b71b76341530d3b556c"
+ logic_hash = "5508d48c958832fbb5bd1d9983eb0158b4a79197acb610f43056e5475e8173ec"
score = 75
quality = 75
tags = "FILE"
@@ -164462,32 +171635,38 @@ rule MALPEDIA_Win_Saigon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7508 ff15???????? 8bd8 4c8d5c2450 8bc3 498b5b20 498b6b28 }
- $sequence_1 = { 4889442440 488364243800 488364243000 4533c0 488bd3 33c9 }
- $sequence_2 = { ff15???????? 33ed 488bcb 85c0 }
- $sequence_3 = { 7459 f60301 742c 418bcf 488bd0 4903cc e8???????? }
- $sequence_4 = { 488b0d???????? 4c8bc7 33d2 8bd8 ff15???????? eb1e }
- $sequence_5 = { 4156 4157 4883ec60 4c8bea 488d50c8 4d8bf9 e8???????? }
- $sequence_6 = { ffd0 85c0 790e 8bc8 }
- $sequence_7 = { 4c8d8584020000 488d8c2460060000 448bcb 418bd6 e8???????? }
- $sequence_8 = { 33d2 8d440036 448bc0 448be0 ff15???????? }
- $sequence_9 = { 8d4f01 448bcf 4c8bc6 894c2428 33c9 33d2 }
+ $sequence_0 = { 0105???????? 81c3b0020000 2945e0 75ae 837dd400 }
+ $sequence_1 = { 51 8d9514fbffff 52 a1???????? }
+ $sequence_2 = { 0108 833e00 7fc7 db46fc }
+ $sequence_3 = { 0105???????? 83c410 29442418 75a9 }
+ $sequence_4 = { 0108 833e00 7c1f 8b542410 }
+ $sequence_5 = { 0105???????? 83c410 29442420 75aa }
+ $sequence_6 = { 0108 833a00 7c23 8b442428 }
+ $sequence_7 = { 0108 833e00 7cc7 7e39 }
+ $sequence_8 = { c645da14 c645db14 e8???????? 83c40c 8d45d0 }
+ $sequence_9 = { c645de47 c645df5b c645e04d c645e160 c645e249 c645e346 c645e44c }
+ $sequence_10 = { 6a0a 50 e8???????? 83c40c 8d45f4 885dfd 50 }
+ $sequence_11 = { 8d7da0 f3ab 8d459c 50 ff15???????? }
+ $sequence_12 = { 3bf8 72ee 6880000000 56 ff15???????? }
+ $sequence_13 = { c645ac05 c645ad07 c645ae07 c645af0b c645b004 c645b10e c645b226 }
+ $sequence_14 = { 7506 46 47 3bf8 }
+ $sequence_15 = { 6a55 8d45b8 6a0c 50 c645b816 }
condition:
- 7 of them and filesize <147456
+ 7 of them and filesize <1040384
}
-rule MALPEDIA_Win_Babylon_Rat_Auto : FILE
+rule MALPEDIA_Win_Homefry_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "520c4cbb-7168-5cad-9ac5-61fcc34e0523"
+ id = "a10ca8d8-82df-517d-ba70-a87080178507"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.babylon_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.babylon_rat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.homefry"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.homefry_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "d4eca63a433742f88d4570a738d70afc76a66ddfd0669e9e8d639b4f32143e21"
+ logic_hash = "17959e0d47a35ecd2de71b5f2bf7c90338d7ed773cdd572cf03461913b5cbcc7"
score = 75
quality = 75
tags = "FILE"
@@ -164501,34 +171680,34 @@ rule MALPEDIA_Win_Babylon_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff75ec 8908 e8???????? 83c40c 85c0 7407 8b4808 }
- $sequence_1 = { ff761c 6a44 57 e8???????? 83c418 eb36 6a00 }
- $sequence_2 = { f6c23e 0f84ac000000 8bc3 83e01a 663bc3 740e 8bc3 }
- $sequence_3 = { ffb50cffffff ffb5f0feffff e8???????? 8bc8 e8???????? 660f28c8 eb54 }
- $sequence_4 = { e8???????? 56 e8???????? 59 50 56 8d8dc8fbffff }
- $sequence_5 = { ff15???????? 50 680a190000 e9???????? e8???????? 8945f8 59 }
- $sequence_6 = { ff36 0fb6c9 51 ff761c ff7510 ff7508 e8???????? }
- $sequence_7 = { c645fc01 85c0 7404 8b10 eb02 8bd3 8b45e8 }
- $sequence_8 = { ff7708 6a77 53 e8???????? ff751c 53 e8???????? }
- $sequence_9 = { ff7514 ff7510 57 e8???????? 83c40c eb79 53 }
+ $sequence_0 = { e8???????? 4863d5 4803d0 488b05???????? 488917 48630a }
+ $sequence_1 = { 4889b5f0020000 4803cb ff15???????? 85c0 7873 488b95f0020000 }
+ $sequence_2 = { 740f 8bcf 4803cd 7408 }
+ $sequence_3 = { 8b4c2470 ff15???????? 8b4c2478 488905???????? ff15???????? 488b0d???????? }
+ $sequence_4 = { c705????????94000000 ff15???????? 33d2 8d4a02 ff15???????? 488bd8 }
+ $sequence_5 = { e8???????? 84c0 0f8418010000 48833d????????00 48899c24a0000000 4889b424a8000000 7471 }
+ $sequence_6 = { ff15???????? 488bcb ff15???????? 4881c420040000 }
+ $sequence_7 = { 488bc8 e8???????? 84c0 7426 48630d???????? 488bc3 85c9 }
+ $sequence_8 = { e8???????? eb05 e8???????? 84c0 7511 488d0ddd180000 }
+ $sequence_9 = { 483bdd 72d0 488bcf ff15???????? 33c0 488b5c2430 488b6c2438 }
condition:
- 7 of them and filesize <1604608
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Duuzer_Auto : FILE
+rule MALPEDIA_Win_Karius_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "df8c3768-3cdc-5b0e-a660-661bdb978bfa"
+ id = "ed0a7186-5551-553c-ac59-b131d3af72d8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.duuzer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.duuzer_auto.yar#L1-L145"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.karius"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.karius_auto.yar#L1-L249"
license_url = "N/A"
- logic_hash = "13aac089d76bc4f63a9fe69893726cbd97eb78875b3161a00634aa641d0ec8d3"
+ logic_hash = "b146425f067402ca1aeb5e04aa4caed2d124eb5c4ba40f66c5f112d8e9115a94"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -164540,37 +171719,49 @@ rule MALPEDIA_Win_Duuzer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83f804 7408 83c8ff e9???????? }
- $sequence_1 = { 0145f0 1155f4 85c9 7533 }
- $sequence_2 = { 57 4154 4155 4881ec88080000 488b05???????? 4833c4 }
- $sequence_3 = { 00f4 c640001c c740008a460323 d188470383ee }
- $sequence_4 = { 56 57 b830910000 e8???????? }
- $sequence_5 = { 56 57 b8a0010100 e8???????? }
- $sequence_6 = { 56 57 488dac2410fcffff 4881ecf0040000 }
- $sequence_7 = { 01442410 3bfb 75c4 8b4630 }
- $sequence_8 = { 57 4154 4883ec20 448be2 }
- $sequence_9 = { 57 4154 4155 4156 4883ec30 488b05???????? }
- $sequence_10 = { 014dec 83bf8400000000 7708 398780000000 }
- $sequence_11 = { 57 4154 4155 4883ec20 33f6 488bd9 }
- $sequence_12 = { 014dec 66837dec00 0f8efc010000 0fbf45ec }
- $sequence_13 = { 00e0 3541000436 41 0023 }
- $sequence_14 = { 010b 014e4c 014e48 014e54 }
+ $sequence_0 = { 4c8b8424a0000000 bf01000000 8bd7 498bce ffd3 4183bf8c00000000 }
+ $sequence_1 = { 4d03d6 448bcd 85db 0f8477000000 8bb424b0000000 }
+ $sequence_2 = { 0f84b3000000 458b9f88000000 4d03de 418b5b18 85db }
+ $sequence_3 = { ffd3 4183bf8c00000000 0f84b3000000 458b9f88000000 }
+ $sequence_4 = { 488b05???????? 4885c0 7512 ff15???????? 488905???????? }
+ $sequence_5 = { 8bb424b0000000 418b10 8bcd 4903d6 0fb602 }
+ $sequence_6 = { c3 85c0 7505 e8???????? b801000000 }
+ $sequence_7 = { 85db 0f849d000000 41837b1400 0f8492000000 }
+ $sequence_8 = { 0f8492000000 458b4320 458b5324 33ed 4d03c6 4d03d6 }
+ $sequence_9 = { 8d7b01 448bfb 448be3 4885c9 }
+ $sequence_10 = { 56 be???????? 33d2 8a040a 3a06 7522 }
+ $sequence_11 = { 83e830 89450c db450c 8a07 d9ca d8c9 }
+ $sequence_12 = { b801000000 8702 83f801 74f4 }
+ $sequence_13 = { 752c 8a4701 3c30 7c25 3c39 }
+ $sequence_14 = { 488d4b10 488d542450 41b804000000 c6430f68 }
+ $sequence_15 = { 4d8bcf 33d2 41b800001000 488bce }
+ $sequence_16 = { 803e5d 7508 5f 5b 8d4601 5e }
+ $sequence_17 = { 7505 8d7b02 eb09 6685c0 }
+ $sequence_18 = { 8d7308 56 ffd7 50 56 e8???????? }
+ $sequence_19 = { ff15???????? 4c8be8 498bce ff15???????? 4d85ed }
+ $sequence_20 = { 8b4dfc 83c404 8945f4 83c706 050024ffff }
+ $sequence_21 = { 4d8bc7 488bd0 488bce ff15???????? }
+ $sequence_22 = { e9???????? 8b45f8 5f 5b 5e }
+ $sequence_23 = { 8b4508 85c0 7417 8b4008 85c0 7412 8b4d0c }
+ $sequence_24 = { 7405 f60001 7502 33c0 }
+ $sequence_25 = { 448bc0 33d2 488bce ff15???????? 4c8bf0 4885c0 }
+ $sequence_26 = { 48895c2420 4d8bcc 4d8bc7 488bd0 }
condition:
- 7 of them and filesize <491520
+ 7 of them and filesize <434176
}
-rule MALPEDIA_Win_Icexloader_Auto : FILE
+rule MALPEDIA_Win_Mqsttang_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f5f07cf1-ebb8-58bc-85cf-c8730868788c"
+ id = "37b83f83-ada9-5cb9-9846-c597be16b8c2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.icexloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.icexloader_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mqsttang"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mqsttang_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "3e81383223a4cc1ff73f88f3e7f296bd8191bce05edbae01407537facee45b04"
+ logic_hash = "816bebdcfc28d4925b60f084aa814ab97a3079e189efd77c5fe0d0005fa07653"
score = 75
quality = 75
tags = "FILE"
@@ -164584,32 +171775,32 @@ rule MALPEDIA_Win_Icexloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 750c 83caff 85c9 7405 8b01 8d50ff 8b4508 }
- $sequence_1 = { 8985acfeffff 8b85c4feffff 8b10 894c2408 8b8db4feffff 890424 894c2404 }
- $sequence_2 = { 8b4520 8910 c745e001000000 eb0a 90 eb07 90 }
- $sequence_3 = { e8???????? ba04000000 0fb7c0 40 8985d0e6ffff 8b85e4e6ffff e8???????? }
- $sequence_4 = { c705????????04000000 66c705????????1903 c605????????01 c705????????14000000 c705????????e0d74300 c705????????aa914200 }
- $sequence_5 = { 55 ba7c000000 89e5 56 53 83ec30 894de4 }
- $sequence_6 = { c705????????00d44300 c705????????95904200 c705????????18e44300 c605????????01 c705????????00000000 c705????????80d44300 c705????????9d904200 }
- $sequence_7 = { 83bd14ffffff00 7405 e8???????? e8???????? 8b8d64feffff e8???????? e8???????? }
- $sequence_8 = { 57 56 89d6 ba01000000 53 89cb 83ec2c }
- $sequence_9 = { b8???????? e8???????? ba0c000000 8d45a4 e8???????? ba???????? b9???????? }
+ $sequence_0 = { f20f2ac0 f20f5905???????? 660f28c8 660f54ca 660f2ed9 7629 f20f58cb }
+ $sequence_1 = { f0832801 8b85c0fdffff 0f845a010000 8b85b4fdffff 89780c 8b400c 85c0 }
+ $sequence_2 = { e9???????? 89c7 89d9 89fb e8???????? 89f1 e8???????? }
+ $sequence_3 = { ff5074 8b03 83ec04 89d9 8b707c ff5078 890424 }
+ $sequence_4 = { e9???????? c74424240a030000 c744242001000000 e9???????? c74424240b030000 c744242000000000 e9???????? }
+ $sequence_5 = { e8???????? e9???????? c744240405000000 c70424???????? e8???????? 8d5de4 8b4dd4 }
+ $sequence_6 = { e8???????? 8d4c247c e8???????? 8d8c2480000000 e8???????? 8d8c2484000000 e8???????? }
+ $sequence_7 = { f6040e10 7441 83c002 47 894338 39bdd8aeffff 77c7 }
+ $sequence_8 = { f30f11442430 f20f115c2428 f30f11542420 f30f114c2418 e8???????? f20f106c2438 f20f105c2428 }
+ $sequence_9 = { e9???????? c744240cffffffff c7442408???????? 89542404 03400c 890424 e8???????? }
condition:
- 7 of them and filesize <656384
+ 7 of them and filesize <12651520
}
-rule MALPEDIA_Win_Adhubllka_Auto : FILE
+rule MALPEDIA_Win_Bouncer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e0dcc0bf-7466-5a17-86c8-1be553373dbc"
+ id = "87d70146-e2c3-5ac4-84a7-b98c5e250ffd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.adhubllka"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.adhubllka_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bouncer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bouncer_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "f57dac34b065a20905904e9bce7c25f2f5dcbcedcfe53619de18c646a0c360a6"
+ logic_hash = "5df724a9e6c42e3be58b79859bcd4fd49abf6f303058e1f4cc9822918e05c24a"
score = 75
quality = 75
tags = "FILE"
@@ -164623,32 +171814,32 @@ rule MALPEDIA_Win_Adhubllka_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8d8d60ffffff e8???????? 0f108560ffffff be18000000 0f1185c0feffff }
- $sequence_1 = { 0f104590 0f118540ffffff 0f1045a0 0f118550ffffff e8???????? 83c404 8d8d60ffffff }
- $sequence_2 = { 894d9c 8b4dbc 89458c 8b45c4 897d98 8b7dc0 }
- $sequence_3 = { 7410 f745d800000002 7407 b801000000 eb02 33c0 }
- $sequence_4 = { 03c2 898534ffffff 33c7 c1c008 898520ffffff 03c1 8b4ddc }
- $sequence_5 = { 0fb605???????? c1e108 0bc8 0fb605???????? c1e108 0bc8 }
- $sequence_6 = { e8???????? 83c404 0f57c0 660f138424501a0000 6a02 }
- $sequence_7 = { 8d8d60ffffff e8???????? 8d8d60ffffff e8???????? 0f108560ffffff be04000000 0f118510ffffff }
- $sequence_8 = { 0f1f440000 8b5cbc48 53 ff15???????? 83f801 }
- $sequence_9 = { ffb590fdffff ff15???????? 85c0 0f8481fdffff 56 e8???????? }
+ $sequence_0 = { 53 be???????? 83ec34 6a0d 59 8bfc }
+ $sequence_1 = { a1???????? 56 3bc3 7422 }
+ $sequence_2 = { 8dbda6f8ffff 33f6 f3ab 66ab 6a1e 8d45a8 56 }
+ $sequence_3 = { e8???????? 83c414 397e18 0f85ce020000 3bc3 7d50 33c9 }
+ $sequence_4 = { 3bc3 0f84870e0000 50 ff15???????? }
+ $sequence_5 = { 8bec 81ec14040000 53 56 57 6a40 ff15???????? }
+ $sequence_6 = { 8d8534ffffff 57 50 e9???????? }
+ $sequence_7 = { 56 be???????? 57 56 e8???????? 8bd8 c7042499050000 }
+ $sequence_8 = { 8945d0 0f8e740e0000 8d85a0fcffff 50 ff75fc e8???????? }
+ $sequence_9 = { 897db0 8975c4 ff750c 8975bc 8975c0 }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <335872
}
-rule MALPEDIA_Win_Nitol_Auto : FILE
+rule MALPEDIA_Win_Rhttpctrl_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "198cac67-df3a-5f33-8def-8dcd3146a557"
+ id = "22fa66be-3212-5731-af64-75e4d7422a17"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nitol"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nitol_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rhttpctrl"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rhttpctrl_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "e9d7d8e217f108c3161acd931dc4e0ba15adf22ad1ef941917cfc7f75a6244b1"
+ logic_hash = "1c3d2b43c54e91473434d199f4328e6fb482c73192965602da658da1f5036d20"
score = 75
quality = 75
tags = "FILE"
@@ -164662,34 +171853,34 @@ rule MALPEDIA_Win_Nitol_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945d0 885dd4 c645d506 ffd6 668945d6 }
- $sequence_1 = { 50 ff15???????? 6860ea0000 8945f8 66895de8 e8???????? 59 }
- $sequence_2 = { ff742430 ffd7 8d442430 55 50 53 56 }
- $sequence_3 = { 7424 48 0f85c0fdffff 6a01 }
- $sequence_4 = { 8b35???????? 833d????????01 7465 ffd6 6a0a 99 59 }
- $sequence_5 = { 8bf8 8bcf 8b07 ff5068 85c0 8945ec 7457 }
- $sequence_6 = { 7524 8d8594feffff 50 8d8514ffffff 50 8d8514faffff 68???????? }
- $sequence_7 = { 7419 4a 7416 4a 7406 c6043778 eb1b }
- $sequence_8 = { 53 ff15???????? e9???????? 6a40 33c0 }
- $sequence_9 = { ff15???????? 53 8d8df8fcffff 6a0a }
+ $sequence_0 = { e8???????? 83c404 833d????????ff 7533 ff15???????? 68???????? c705????????dcfb4100 }
+ $sequence_1 = { e8???????? 8b404c 83b8a800000000 750e 8b04bd30424200 807c302900 741d }
+ $sequence_2 = { ffb5dcfbffff c785d8fbffff10fc4100 ff15???????? 33c0 }
+ $sequence_3 = { c645d800 68???????? 8d45d8 660fd645e9 }
+ $sequence_4 = { 8be5 5d c3 68???????? ff15???????? 833d????????00 b301 }
+ $sequence_5 = { 3bf1 756e 8b4bf0 8d73f0 8b01 ff5010 397e0c }
+ $sequence_6 = { 8b08 85c9 7407 395004 }
+ $sequence_7 = { 50 8d842498000000 50 e8???????? 83cbff 85c0 }
+ $sequence_8 = { 50 56 ff15???????? 85c0 7536 8b4714 8b35???????? }
+ $sequence_9 = { 57 e8???????? ffb5f8feffff 8d85fcfeffff 50 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <339968
}
-rule MALPEDIA_Win_Ariabody_Auto : FILE
+rule MALPEDIA_Win_Plugx_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "58204a37-6e57-54ad-a9ad-f1e207420b64"
+ id = "f3050f8b-cffb-5dba-854a-dbf0ccdc7dc1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ariabody"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ariabody_auto.yar#L1-L175"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.plugx"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.plugx_auto.yar#L1-L275"
license_url = "N/A"
- logic_hash = "eeda1b828c38fb501f5c05c0fadc1525e86a5abb54edde2f591e92fd62c5dd82"
+ logic_hash = "dee163361f083ebb03bd1347d736d4fc9d87c0c2c6fd15ac5989d8dd6f5a5f80"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -164701,38 +171892,53 @@ rule MALPEDIA_Win_Ariabody_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb13 8b16 8bcf e8???????? 8906 85c0 }
- $sequence_1 = { 8bcf 0fb6c0 50 ff75fc e8???????? }
- $sequence_2 = { 7402 32c3 88040a 41 }
- $sequence_3 = { 8a01 84c0 7406 3ac3 7402 }
- $sequence_4 = { 56 8d0c30 ffd1 8bc6 5f }
- $sequence_5 = { 8bf2 56 8d55fc 03f9 e8???????? 59 85c0 }
- $sequence_6 = { 83ec50 53 57 8bd9 e8???????? 8bf8 893b }
- $sequence_7 = { ff5304 8bf8 893e eb13 8b16 8bcf }
- $sequence_8 = { 33d2 488d8c2498000000 41b800010000 41ffc7 ff9510020000 }
- $sequence_9 = { 48895c2408 57 4883ec20 4863d9 488d3da4d30000 4803db 48833cdf00 }
- $sequence_10 = { eb17 83f802 7512 488d4c2430 488d942420060000 e8???????? }
- $sequence_11 = { 33ff 488d0480 418b4cc60c 418b54c614 4903cc 458b44c610 4803d3 }
- $sequence_12 = { e8???????? 3d5595db6d 741d 4d8b7f18 }
- $sequence_13 = { 41b820000000 488d942444010000 4c8d8c2468010000 48c7402000000000 41ff96d0000000 85c0 7429 }
- $sequence_14 = { 4c89e1 4533c9 8b942464010000 41ff96c0000000 4889e0 4c89e1 41b820000000 }
- $sequence_15 = { 8b0b e8???????? 48630b 4c8d2dd59f0000 488bc1 }
+ $sequence_0 = { 51 56 57 6a1c 8bf8 }
+ $sequence_1 = { 33d2 f7f3 33d2 8945fc }
+ $sequence_2 = { 55 8bec a1???????? 83ec5c 53 }
+ $sequence_3 = { 55 8bec 51 0fb74612 }
+ $sequence_4 = { 51 53 6a00 6a00 6a02 ffd0 85c0 }
+ $sequence_5 = { 41 3bca 7ce0 3bca }
+ $sequence_6 = { 56 8b750c 8b4604 050070ffff }
+ $sequence_7 = { 6a00 6800100000 6800100000 68ff000000 6a00 6803000040 }
+ $sequence_8 = { e8???????? 3de5030000 7407 e8???????? }
+ $sequence_9 = { e8???????? 85c0 7508 e8???????? 8945fc }
+ $sequence_10 = { 50 ff15???????? a3???????? 8b4d18 }
+ $sequence_11 = { 85c0 7413 e8???????? 3de5030000 }
+ $sequence_12 = { e8???????? 85c0 7407 b84f050000 }
+ $sequence_13 = { e8???????? 85c0 750a e8???????? 8945fc }
+ $sequence_14 = { 6a00 6a04 6a00 6a01 6800000040 57 }
+ $sequence_15 = { 6a00 6819000200 6a00 6a00 6a00 51 }
+ $sequence_16 = { 56 56 6a01 56 ffd0 }
+ $sequence_17 = { 85c0 750d e8???????? 8945f4 }
+ $sequence_18 = { 57 e8???????? eb0c e8???????? }
+ $sequence_19 = { 50 ff75e8 6802000080 e8???????? }
+ $sequence_20 = { 6a00 ff7028 e8???????? 83c408 85c0 }
+ $sequence_21 = { 6808020000 6a00 ff742450 e8???????? 83c40c }
+ $sequence_22 = { 6a02 6a00 e8???????? c705????????00000000 }
+ $sequence_23 = { 6800080000 68???????? e8???????? 6800080000 68???????? e8???????? }
+ $sequence_24 = { 5e 5f 5b 5d c3 64a118000000 }
+ $sequence_25 = { 81ec90010000 e8???????? e8???????? e8???????? }
+ $sequence_26 = { 68???????? 6830750000 68e8030000 ff36 }
+ $sequence_27 = { 5f 5b 5d c20400 55 53 57 }
+ $sequence_28 = { 50 56 ffb42480000000 ff15???????? }
+ $sequence_29 = { 6808020000 6a00 ff74242c e8???????? }
+ $sequence_30 = { 6a01 6a00 e8???????? a3???????? 6800080000 }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <1284096
}
-rule MALPEDIA_Win_Ksl0T_Auto : FILE
+rule MALPEDIA_Win_Donot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5a4c8dc6-6c96-5c41-9019-3d4bc785a54b"
+ id = "38387986-3cf2-52ef-b35f-48e7a3ada73a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ksl0t"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ksl0t_auto.yar#L1-L172"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.donot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.donot_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "5f184f0ae6eb14c42a9f8143b74f6a69a5bb90e2ed5eff63faec19a839c8988a"
+ logic_hash = "856eb217efb67c7a23eb4ad0af50dccbe8bb723a98d81632999df9a793bf3e4e"
score = 75
quality = 75
tags = "FILE"
@@ -164746,38 +171952,32 @@ rule MALPEDIA_Win_Ksl0T_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 83c40c 3bf7 7515 ff15???????? }
- $sequence_1 = { c68424a100000039 c68424a200000039 888c24a3000000 c684248000000026 }
- $sequence_2 = { c684241001000006 88842411010000 889c2412010000 c684241301000013 }
- $sequence_3 = { 68???????? 8d8d00080000 51 ff15???????? 8d9500080000 52 }
- $sequence_4 = { ff942418040000 4c8bd8 488b842420040000 4c899878010000 488d542468 }
- $sequence_5 = { c68424f600000034 c68424f700000038 c68424f800000030 c68424f900000002 c68424fa00000055 c644245813 c64424593c }
- $sequence_6 = { c684245a01000021 c684245b01000018 c684245c01000030 c684245d01000026 c684245e01000026 c684245f01000034 }
- $sequence_7 = { 4881c294000000 41b801000000 488d0dd7e60000 ff15???????? }
- $sequence_8 = { 8d94241c030000 52 53 89466c ffd7 894670 }
- $sequence_9 = { 3bcf 7518 81fa00010000 7510 }
- $sequence_10 = { c684248800000002 c684248900000055 c684241801000000 c68424190100003b c684241a0100003d c684241b0100003a }
- $sequence_11 = { 84c0 745a 68???????? 68???????? ff15???????? 68???????? 68???????? }
- $sequence_12 = { 488bce 488905???????? ff15???????? 488bc8 e8???????? 488d1592280000 488bce }
- $sequence_13 = { ff15???????? 8bf0 6800020000 57 8d95000d0000 52 ff15???????? }
- $sequence_14 = { 7509 488d0de2450000 eb02 33c9 e8???????? 4883c438 c3 }
- $sequence_15 = { c68424f801000038 c68424f901000034 c68424fa01000039 c68424fb01000039 c68424fc0100003a }
+ $sequence_0 = { 8b04c580b80310 5d c3 33c0 }
+ $sequence_1 = { c7461400000000 0f1106 f30f7e45e4 660fd64610 c745e400000000 c745e80f000000 85d2 }
+ $sequence_2 = { 03d3 d1fa 8d4102 894738 8b4710 8918 8b4720 }
+ $sequence_3 = { e8???????? 8b15???????? b910000000 2bd6 8a0432 8d7601 3046ff }
+ $sequence_4 = { 7361 8bc6 8bde 83e03f c1fb06 6bc838 8b049d187b0410 }
+ $sequence_5 = { c645fc02 8d4dbc e8???????? 8bf8 83c404 3bf7 7465 }
+ $sequence_6 = { 0f438540ffffff 50 ff15???????? c645fc1b 8b559c 83fa10 722c }
+ $sequence_7 = { c6861002000000 8b8e0c020000 83f910 722f 8b86f8010000 41 81f900100000 }
+ $sequence_8 = { c685bcedffff00 8d5101 8a01 41 84c0 75f9 }
+ $sequence_9 = { c6863801000000 8b8e34010000 83f910 722f 8b8620010000 41 81f900100000 }
condition:
- 7 of them and filesize <196608
+ 7 of them and filesize <626688
}
-rule MALPEDIA_Win_Jssloader_Auto : FILE
+rule MALPEDIA_Win_C0D0So0_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e1eaf0bc-7617-5378-87a8-cba9c6423b69"
+ id = "7fd27b52-4a26-50f0-a471-2ac29e8cd05c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jssloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jssloader_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.c0d0so0"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.c0d0so0_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "186e7df3cf3822e82929f92759ecc1d78a3a2d538dfeac54de7cfb7d33d930ef"
+ logic_hash = "80f1d1736e25190b04ddf50f3339fde0073091aa1984fb16860f6c3d691cdb86"
score = 75
quality = 75
tags = "FILE"
@@ -164791,34 +171991,34 @@ rule MALPEDIA_Win_Jssloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89b5e0fbffff 660fd685e4fbffff 89b5ecfbffff 89b5e4fbffff 89b5e8fbffff 89b5ecfbffff }
- $sequence_1 = { 0f4345b4 50 ff15???????? 8bf0 89b5c0fdffff 83feff 0f84b9020000 }
- $sequence_2 = { 8945fc 56 8b7508 8d85fcfeffff 6800010000 6a00 50 }
- $sequence_3 = { 899d0cffffff 6a04 68???????? c745d000000000 c745d40f000000 c645c000 e8???????? }
- $sequence_4 = { 2bc6 83c0fc 83f81f 0f8797010000 e9???????? 8b854cfeffff 8d4804 }
- $sequence_5 = { 51 ffb570feffff 8d4dcc e8???????? c645fc0b 8b55e0 8bc2 }
- $sequence_6 = { 3b85ecfbffff 740a 8808 ff85e8fbffff }
- $sequence_7 = { 8bc1 83e13f c1f806 6bc938 8b0485701d4400 80640828fe ff33 }
- $sequence_8 = { 03f0 56 e8???????? 8b8534ffffff 83c40c 8b8d54feffff }
- $sequence_9 = { 03f0 56 e8???????? 8b854cffffff 83c40c c6043000 8bb568feffff }
+ $sequence_0 = { 895dfc 8975f4 ff15???????? ff75f8 }
+ $sequence_1 = { 7404 0006 eb02 2806 0fb6c0 03d0 03f0 }
+ $sequence_2 = { 807e0d00 c6460801 7469 8b460e 8b1d???????? 8365f800 83c012 }
+ $sequence_3 = { 53 8b5f04 c745f401000000 0f86f4000000 56 8bb080000000 6a14 }
+ $sequence_4 = { 83c204 83f914 7ceb 8bc7 8b4dfc 33cd }
+ $sequence_5 = { 752c 6a01 56 e8???????? 59 59 }
+ $sequence_6 = { 50 33ff ff15???????? 8d4598 50 ff15???????? }
+ $sequence_7 = { ff7334 ffd6 8945fc 85c0 }
+ $sequence_8 = { 3acb 75f6 8bc7 5f 5e }
+ $sequence_9 = { 33ff 53 47 e8???????? 59 eb0b 56 }
condition:
- 7 of them and filesize <581632
+ 7 of them and filesize <450560
}
-rule MALPEDIA_Win_Romeos_Auto : FILE
+rule MALPEDIA_Win_Polyglot_Ransom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0156645c-05e4-5c43-9143-7d272fa7b808"
+ id = "d8c62ea3-2069-58e5-94bb-e4265ed7677c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.romeos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.romeos_auto.yar#L1-L178"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.polyglot_ransom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.polyglot_ransom_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "c5549ec98f2ed02ef2ebca3bfe2dbd57b9e8c34679be2e9e834dd93b596fc1fe"
+ logic_hash = "ecee7d25f676a4e4884cb2efcc0294d55515d4c6450d9ce1a59e043bd0d80704"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -164830,38 +172030,32 @@ rule MALPEDIA_Win_Romeos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 750a 5e 33c0 5b 83c408 c20c00 8b06 }
- $sequence_1 = { bd30000000 33db 85ed 7e0e e8???????? 88441c18 43 }
- $sequence_2 = { 6a16 8d4c244c 6800200000 51 57 }
- $sequence_3 = { 83ec08 53 56 8b742418 8bd9 85f6 750a }
- $sequence_4 = { 5f 5e 5d 5b 81c438200000 c20400 }
- $sequence_5 = { 8b542408 668902 b001 c3 668b4801 40 51 }
- $sequence_6 = { 85db 751d 807c244802 0f85e0000000 8d542414 8d442448 }
- $sequence_7 = { 6a16 8d44244c 52 50 }
- $sequence_8 = { 68bb010000 8b39 50 ff15???????? 8b8e20030000 50 53 }
- $sequence_9 = { e8???????? 8bf0 eb02 33f6 53 6800040000 8d4c243c }
- $sequence_10 = { 50 8bce e8???????? 8d8c2490010000 51 }
- $sequence_11 = { 81c428010000 c3 5f 5e 5d 83c8ff 5b }
- $sequence_12 = { 8bf1 57 b940000000 33c0 8d7c2415 c644241400 c744240800000000 }
- $sequence_13 = { 895c2440 895c2434 895c2438 ff15???????? }
- $sequence_14 = { 8b442410 85c0 7408 66837c241400 7510 47 }
- $sequence_15 = { 8b3a eb0d 8b8e20030000 68bb010000 }
+ $sequence_0 = { ff74244c e8???????? 8944241c 894c2448 6a07 895c2450 }
+ $sequence_1 = { 6a30 e8???????? 59 59 8d4d80 51 6801010000 }
+ $sequence_2 = { ff5004 83c328 ff4d10 75ad ff75f0 ff15???????? }
+ $sequence_3 = { be???????? 66f7c30040 6a04 5a 747a 6681fb0b40 756c }
+ $sequence_4 = { 50 68???????? e8???????? 8b85f0fdffff 59 59 8b08 }
+ $sequence_5 = { 627265 206f20 656c 696d696e617220 61 7263 6869766f73 }
+ $sequence_6 = { eb4f 8bf3 8bf9 a5 a5 a5 a5 }
+ $sequence_7 = { 59 59 751c 8b45fc 8b4020 85c0 }
+ $sequence_8 = { 5e c20400 68???????? 6a20 33c0 }
+ $sequence_9 = { 40 5e eb02 32c0 8b4d74 33cd }
condition:
- 7 of them and filesize <294912
+ 7 of them and filesize <1392640
}
-rule MALPEDIA_Win_Webc2_Bolid_Auto : FILE
+rule MALPEDIA_Win_Xsplus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "05fc3e6a-bc1e-5e27-996e-6357de6a9e2c"
+ id = "fb41ffbb-1e2d-5bdd-9365-c97018c55362"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_bolid"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_bolid_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xsplus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xsplus_auto.yar#L1-L178"
license_url = "N/A"
- logic_hash = "938464f6c09d72401fc04aa41413a321a3c389b634663fb70512029f39441d8b"
+ logic_hash = "1413c5b641befe4b985d097bf7fa94a2fd076afb28674d33f79669c0d9d8240e"
score = 75
quality = 75
tags = "FILE"
@@ -164875,32 +172069,39 @@ rule MALPEDIA_Win_Webc2_Bolid_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 741e 8b4c240c 51 ff15???????? 56 68???????? e8???????? }
- $sequence_1 = { e8???????? 8d8c24d4000000 c684242c02000004 51 8bcd e8???????? 8b15???????? }
- $sequence_2 = { 8bcb e8???????? 85c0 0f84fa000000 8b550c 42 }
- $sequence_3 = { 49 885c2454 51 68???????? 8d4c2444 }
- $sequence_4 = { 83c40c 8b15???????? 8d4de4 52 }
- $sequence_5 = { e8???????? 6a01 8d4c2440 c644245800 e8???????? 8b4c2460 }
- $sequence_6 = { f3a4 8b35???????? 8d4c2410 51 6a26 52 89442420 }
- $sequence_7 = { 8b458c 3bc3 7505 b8???????? }
- $sequence_8 = { 50 ff5104 33db 6a01 }
- $sequence_9 = { 53 880e 8bce e8???????? 8b15???????? 8d44245c }
+ $sequence_0 = { 8b761c 8b4608 8b7e20 8b36 66394f18 75f2 }
+ $sequence_1 = { 0fb602 33c1 8b4d0c 034dfc 8801 }
+ $sequence_2 = { 83c408 8945f0 837df000 750f }
+ $sequence_3 = { e9???????? 8be5 5d c3 3b0d???????? }
+ $sequence_4 = { 8b45f4 83c001 8945f4 ebbf eb2c 6a08 8d4df8 }
+ $sequence_5 = { 895018 8b4df8 8b511c 83ea01 }
+ $sequence_6 = { c6864b01000043 c74668e0a34000 6a0d e8???????? 59 8365fc00 }
+ $sequence_7 = { 0345fc 8a08 880a c745f800000000 }
+ $sequence_8 = { 8d8df4fdffff 51 ff15???????? 8985ecfcffff 83bdecfcffffff 7565 6804010000 }
+ $sequence_9 = { 8b5118 d1e2 8b45f8 895018 8b4df8 }
+ $sequence_10 = { c745fc04000000 eb2d 8b5510 83e204 }
+ $sequence_11 = { 83c101 898de8feffff 8b550c 52 e8???????? }
+ $sequence_12 = { 8a800ca84000 08443b1d 0fb64601 47 3bf8 76ea }
+ $sequence_13 = { 8a15???????? 889500ffffff b93f000000 33c0 8dbd01ffffff f3ab 66ab }
+ $sequence_14 = { f3a5 8b45fc ffd0 5f 5e 8be5 }
+ $sequence_15 = { 8b4d08 51 ff15???????? b801000000 e9???????? 6a00 ff15???????? }
+ $sequence_16 = { 8975e0 8db120a84000 8975e4 eb2a 8a4601 }
condition:
- 7 of them and filesize <163840
+ 7 of them and filesize <597872
}
-rule MALPEDIA_Win_Flying_Dutchman_Auto : FILE
+rule MALPEDIA_Win_Rad_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bcfa70ed-52d3-5ff6-98d2-54bf0fdb6694"
+ id = "7146ba59-d944-5b98-95a4-2cbd8d5bc1ff"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flying_dutchman"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flying_dutchman_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rad"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rad_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "395092a50a0edc892d45a5d410470e4cbf5a35f346d3d2f6d581d10febaed0cd"
+ logic_hash = "ca5f1a440d85092616999ffada86b8990e8f68350339b252577329abb6a444ee"
score = 75
quality = 75
tags = "FILE"
@@ -164914,34 +172115,34 @@ rule MALPEDIA_Win_Flying_Dutchman_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 66890c02 83c002 6685c9 75f1 e9???????? 8b85e8feffff 83e800 }
- $sequence_1 = { 48 0f84f8000000 48 0f853d010000 83bd44fcffff06 7553 8b35???????? }
- $sequence_2 = { 8bec 51 56 6a18 e8???????? 33f6 }
- $sequence_3 = { 8d442430 50 89742438 895c2434 68???????? eb40 57 }
- $sequence_4 = { ff75f0 f3a5 ff75f4 ff15???????? ff75f4 8b35???????? ffd6 }
- $sequence_5 = { 3bfb 7531 6a14 e8???????? 8bf0 59 }
- $sequence_6 = { ff15???????? 3bc7 7504 33c0 eb1f 0fbf480a }
- $sequence_7 = { 0f8489000000 48 747f 2ddb030000 }
- $sequence_8 = { e8???????? 8be5 5d c20800 55 8bec 81eca8000000 }
- $sequence_9 = { 832600 83660400 83660800 c3 8b4b04 56 57 }
+ $sequence_0 = { c644242000 e8???????? 8d542420 52 8d8c2498000000 c684240c06000018 ff15???????? }
+ $sequence_1 = { 8b8680000000 3bc3 741b 8bbe84000000 e8???????? 8b8680000000 }
+ $sequence_2 = { a1???????? 33c4 89442434 8b4508 8b00 85c0 751a }
+ $sequence_3 = { 8b84241c010000 50 ffd6 83c404 8b8c2400060000 64890d00000000 }
+ $sequence_4 = { 8d8d70ffffff ff25???????? 8b8578ffffff 83e002 0f8413000000 83a578fffffffd }
+ $sequence_5 = { ffd3 8d8c2494000000 c684240806000005 ff15???????? 8b4c2418 51 8d8c2498000000 }
+ $sequence_6 = { ff15???????? 8d8c2494000000 c684240806000020 ff15???????? b8???????? 8d4c2420 }
+ $sequence_7 = { e8???????? 8bc7 50 c645fc02 e8???????? 8bc8 }
+ $sequence_8 = { 720a 8b4c2434 51 ffd6 83c404 8d9424a8000000 52 }
+ $sequence_9 = { 8d7e04 c645fc29 8d4f04 c706???????? 89bd10fdffff ff15???????? }
condition:
- 7 of them and filesize <276480
+ 7 of them and filesize <207872
}
-rule MALPEDIA_Win_Owlproxy_Auto : FILE
+rule MALPEDIA_Win_Bankshot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9642ab2d-7dc5-58a6-b1f9-20da6d2b2d38"
+ id = "4fd3740f-7572-57c0-9152-6fcb3e7bee0c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.owlproxy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.owlproxy_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bankshot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bankshot_auto.yar#L1-L425"
license_url = "N/A"
- logic_hash = "8f3ab8fd440290f6fe4f2136a06c496cf082fcb282138fdbc332de45a924ef6b"
+ logic_hash = "c9fc73e4e08c210def43b3c6eab22aa7333e3e000dbbe6d6d67c9182f6534613"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -164953,32 +172154,67 @@ rule MALPEDIA_Win_Owlproxy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d942450010000 488d8c2430010000 e8???????? 90 4c8d842430010000 4883bc244801000008 4c0f43842430010000 }
- $sequence_1 = { 488bcb 488905???????? ff15???????? 488d151b580100 483305???????? 488bcb 488905???????? }
- $sequence_2 = { 4889442428 488d442450 4533c0 488bcf 664489a588010000 4889442420 ff15???????? }
- $sequence_3 = { 488d4c2440 e8???????? eb27 49c747180f000000 49c7471000000000 41c60700 4533c0 }
- $sequence_4 = { e8???????? 448bc0 488bd3 488bce e8???????? 84c0 7406 }
- $sequence_5 = { e8???????? 90 488b4527 4c8b4d0f 6690 48837de700 740a }
- $sequence_6 = { 4c8bc6 498bd7 488d0c28 e8???????? 4c8b4708 488b542478 }
- $sequence_7 = { f6c101 7527 458bc6 488d156ee10000 663b1a }
- $sequence_8 = { 4889442428 488d054eff0100 4889442440 488b442468 48634804 488d0581fe0100 4889440c68 }
- $sequence_9 = { 89442420 4c8bce 4533c0 488b5610 488b4da8 ff15???????? 85c0 }
+ $sequence_0 = { 8bf8 8d5101 8a01 41 84c0 75f9 57 }
+ $sequence_1 = { 8bec 81ec48040000 a1???????? 33c5 8945f8 53 }
+ $sequence_2 = { e9???????? 57 33ff 8bcf 8bc7 894de4 3998c0e10110 }
+ $sequence_3 = { c74048b8e40110 8b4508 6689486c 8b4508 66898872010000 8b4508 83a04c03000000 }
+ $sequence_4 = { 33c9 33d2 66898c45f47fffff 8d8df47fffff 8d7102 668b01 83c102 }
+ $sequence_5 = { 89855c38ffff fec1 888d6438ffff 85fa 0f84a4000000 }
+ $sequence_6 = { 8b45fc 817848b8e40110 7409 ff7048 e8???????? }
+ $sequence_7 = { 0f84a6000000 680c400000 8d85e4bfffff 53 50 }
+ $sequence_8 = { 680c000200 e8???????? 8bf8 83c404 85ff 0f8429060000 6915????????04010000 }
+ $sequence_9 = { 83c40c 8d85bcbaffff 33f6 6828050000 56 50 }
+ $sequence_10 = { e8???????? 83c40c e8???????? 99 b907000000 }
+ $sequence_11 = { e8???????? 83c404 89861c020000 8b45e0 8d4e0c 6a06 8d90c4e10110 }
+ $sequence_12 = { 0f1f4000 80b40d943dffffaa 41 3bca 7cf3 }
+ $sequence_13 = { c700???????? 8b4508 898850030000 8b4508 59 c74048b8e40110 }
+ $sequence_14 = { 50 e8???????? 83c40c 6b45e430 8945e0 8d80d0e10110 }
+ $sequence_15 = { 8b542420 8987d0000000 8b442424 898fd4000000 8917 }
+ $sequence_16 = { e8???????? 488d0de7030000 e8???????? 33c0 4883c420 }
+ $sequence_17 = { 488d0d1e960000 c705????????30000000 8bd8 c705????????02000000 48c705????????07000000 48893d???????? }
+ $sequence_18 = { 8b0c95c8887100 8844192e 8b0495c8887100 804c182d04 ff4604 eb08 }
+ $sequence_19 = { 51 ff15???????? 8bf0 83feff 89742410 7544 ff15???????? }
+ $sequence_20 = { ff15???????? 68???????? 57 8985bcfbffff }
+ $sequence_21 = { 48c744243002000080 e8???????? 488d8c2440020000 33d2 }
+ $sequence_22 = { 52 8d85c4fbffff 50 ff15???????? 8d8dd0fdffff }
+ $sequence_23 = { 57 83e502 4d ff15???????? 85f6 7407 }
+ $sequence_24 = { 8d1c85b4ef0110 33c0 f00fb10b 8b15???????? 83cfff 8bca }
+ $sequence_25 = { 7508 8b36 85f6 75e7 eb3a 81c694010000 }
+ $sequence_26 = { e9???????? 8d8df0feffff 51 8d95e8feffff }
+ $sequence_27 = { ff15???????? 8b8df8f3ffff c7410800000000 8b95f8f3ffff 837a0400 }
+ $sequence_28 = { 8dbc24de040000 668974245c f3ab 66ab }
+ $sequence_29 = { 85c9 0f85b5010000 488d8c2450030000 e8???????? e9???????? 498d4906 }
+ $sequence_30 = { ff15???????? 41b958000000 488d1558530000 458d41d6 }
+ $sequence_31 = { 8895affbffff 8b859cfbffff 8a8daffbffff 8808 8b9588fbffff }
+ $sequence_32 = { 8b15???????? 6a01 8d4c2414 6a04 51 8944241c }
+ $sequence_33 = { c1f906 6bc030 03048d80f10110 50 ff15???????? 5d }
+ $sequence_34 = { 33cc e8???????? 8be5 5d c20400 8b8c241c3c0000 83c8ff }
+ $sequence_35 = { 7531 e8???????? 8904bdc87f0110 85c0 7514 }
+ $sequence_36 = { 6a03 6a00 6a03 8d8424c0040000 68000000c0 50 ff15???????? }
+ $sequence_37 = { 33d2 488bc8 4889742448 ff15???????? 896c2460 8bdd }
+ $sequence_38 = { 488d9560040000 41b800400000 488bce 89442460 89442468 4889442420 ff15???????? }
+ $sequence_39 = { e8???????? 83c404 eb36 8d530c }
+ $sequence_40 = { 8d7201 8a0a 42 84c9 75f9 6a00 }
+ $sequence_41 = { 8815???????? 488d442438 488d353a490000 41b919000200 4533c0 48c7c102000080 }
+ $sequence_42 = { 6bd030 895de4 8b049dc87f0110 8945d4 8955e8 8a5c1029 80fb02 }
+ $sequence_43 = { 8b8544d4ffff 83c001 6689856cd4ffff 8a4d1c }
+ $sequence_44 = { 51 68???????? 8b4dfc e8???????? b801000000 8be5 }
condition:
- 7 of them and filesize <475136
+ 7 of them and filesize <860160
}
-rule MALPEDIA_Win_Crylocker_Auto : FILE
+rule MALPEDIA_Win_Slothfulmedia_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4bfc7917-6752-5365-845d-244ec08bbbad"
+ id = "e689a948-8c82-52e0-a234-12c770624669"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crylocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crylocker_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.slothfulmedia"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.slothfulmedia_auto.yar#L1-L171"
license_url = "N/A"
- logic_hash = "846ce0f815360303954c01156a8157bafbdde3bd263a1bdd7a06f8c9923993ce"
+ logic_hash = "0fe44aa9ee5461148172e6c82a2b51d37b08cccc220629908d9ee4d92a4c22d4"
score = 75
quality = 75
tags = "FILE"
@@ -164992,32 +172228,38 @@ rule MALPEDIA_Win_Crylocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 8d542458 52 e8???????? 8d44245c }
- $sequence_1 = { 50 e8???????? 8d4c2404 6a01 51 e8???????? }
- $sequence_2 = { 6a03 50 e8???????? 8b5c2448 8b0b 51 8d54243c }
- $sequence_3 = { 68???????? 53 e8???????? 83c408 53 85c0 7440 }
- $sequence_4 = { 85c0 750b 5b b8f9ffffff 5d 83c410 c3 }
- $sequence_5 = { 8d442430 50 e8???????? 8d4c2434 68???????? 51 e8???????? }
- $sequence_6 = { 50 50 8b44244c 50 6a00 6a00 56 }
- $sequence_7 = { 0f8430020000 8d4c2404 51 e8???????? 8d542408 }
- $sequence_8 = { e8???????? 8b1d???????? 83c428 50 ffd3 8b542430 }
- $sequence_9 = { e8???????? 8d4c2408 6aff 51 e8???????? 8d542410 6a02 }
+ $sequence_0 = { e9???????? 5f 8d4638 5e }
+ $sequence_1 = { 8938 8bd8 83c008 8945fc }
+ $sequence_2 = { 68???????? be04010000 33c9 56 }
+ $sequence_3 = { 83c002 663bca 75f5 2bc6 d1f8 }
+ $sequence_4 = { 40 e8???????? bb04010000 53 8d85e0fdffff 50 }
+ $sequence_5 = { 8b835c040000 68???????? 0564010000 6a05 50 e8???????? 83c418 }
+ $sequence_6 = { 0fb7f0 f7de 6aff ff7508 }
+ $sequence_7 = { 8d444606 83c410 0375f0 891c08 ff45fc }
+ $sequence_8 = { 6689442414 e8???????? 83c40c 6a00 ff15???????? }
+ $sequence_9 = { ff15???????? 8b8c2410020000 5f 5e 33cc 33c0 }
+ $sequence_10 = { 68???????? ffd6 85c0 7507 ffd7 83f805 }
+ $sequence_11 = { 5e 33cc 33c0 e8???????? 81c40c020000 c21000 3b0d???????? }
+ $sequence_12 = { 8d54240c 6a00 52 e8???????? 83c40c 6804010000 8d44240c }
+ $sequence_13 = { 6a04 6a00 8d4c2410 51 ff15???????? 8b8c2410020000 5f }
+ $sequence_14 = { 6a00 ff15???????? 8b35???????? 8b3d???????? 90 68???????? ffd6 }
+ $sequence_15 = { 68d0070000 ff15???????? 33c0 6806020000 50 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <122880
}
-rule MALPEDIA_Win_Remsec_Strider_Auto : FILE
+rule MALPEDIA_Win_Postnaptea_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5cf05a79-eeb6-5c58-8271-14cb9c81c326"
+ id = "66a4e77d-c854-5ed3-94ad-0ea65d80b627"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.remsec_strider"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.remsec_strider_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.postnaptea"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.postnaptea_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "69887265225a27114e8e9d83252b405933e8e0558a06ab3222eee20510a77720"
+ logic_hash = "8a33afe097a88ce8212670a3e80b58d6a5513693490a76a85e445ee8529ba924"
score = 75
quality = 75
tags = "FILE"
@@ -165031,32 +172273,32 @@ rule MALPEDIA_Win_Remsec_Strider_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 74f7 8b4130 2dbc97e889 f7d8 1bc0 f7d0 }
- $sequence_1 = { 6a1a 58 6a10 8945e4 8945e8 58 }
- $sequence_2 = { c9 c20800 55 8bec b804000100 }
- $sequence_3 = { 85c9 74f7 8b4130 2dbc97e889 }
- $sequence_4 = { 6803010000 50 ff15???????? 83c414 8d45f0 50 }
- $sequence_5 = { 0d00000040 50 8d85e8fdffff 50 }
- $sequence_6 = { ebf5 8b432c ff30 68???????? }
- $sequence_7 = { 0510010000 68???????? 6803010000 50 }
- $sequence_8 = { ff772c ff15???????? 85c0 7512 ff15???????? 8bc8 }
- $sequence_9 = { 85ff 7415 83ff05 7410 68???????? 6a02 }
+ $sequence_0 = { c744247418f561f5 c744247867f50000 4863c2 488d4c2450 488d0c41 0fb7c2 662bc3 }
+ $sequence_1 = { ffc2 83fa1a 72e3 6644896c2474 488d442440 488bd3 0f1f440000 }
+ $sequence_2 = { ffd7 85c0 0f842c010000 4c8d052d4b0600 ba04010000 498bce e8???????? }
+ $sequence_3 = { e9???????? 418b8520280000 4d8bce 48634c2440 4c8bc6 2bc1 48034c2460 }
+ $sequence_4 = { c745c000f50cf5 c745c407f528f5 c745c80cf508f5 c745cc02f53cf5 c745d006f50bf5 c745d419f50bf5 c745d81bf54ef5 }
+ $sequence_5 = { ff15???????? 4533e4 4d85f6 0f8418100000 498bce e9???????? 448b85b0000000 }
+ $sequence_6 = { c7851001000031f56df5 c785140100006df54ef5 c7851801000005f50ef5 c7851c0100000ff50000 418bd4 0f1f440000 4863c2 }
+ $sequence_7 = { c78520020000a081b081 c78524020000a281ba81 c78528020000fa81b181 c7852c020000ba81bb81 33c0 66898530020000 418bd5 }
+ $sequence_8 = { 488b05???????? 4885c0 7515 488d55b0 b9bd59e821 e8???????? 488905???????? }
+ $sequence_9 = { ffd7 c7856007000079f57af5 c785640700007bf515f5 c785680700000df528f5 c7856c0700006bf540f5 c7857007000020f506f5 c7857407000007f516f5 }
condition:
- 7 of them and filesize <344064
+ 7 of them and filesize <2457600
}
-rule MALPEDIA_Win_Mrdec_Auto : FILE
+rule MALPEDIA_Win_Petrwrap_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5cd525b0-3fcd-5de1-aa88-bd5dca592c29"
+ id = "335058f1-6093-5213-b714-ccf692d43a50"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mrdec"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mrdec_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.petrwrap"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.petrwrap_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "c22120d79fe39ae9d27a4d21c75a9bbd9a26aee0b664e8fa2f821d0411c6aa0d"
+ logic_hash = "3085058da5fe07c21c7301994557a19255100cfc23f593064f4716726b348a1c"
score = 75
quality = 75
tags = "FILE"
@@ -165070,32 +172312,32 @@ rule MALPEDIA_Win_Mrdec_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c64446fa00 57 56 e8???????? 68???????? 56 e8???????? }
- $sequence_1 = { 6a00 8d45cc 50 68ef000000 68???????? }
- $sequence_2 = { 50 ff75f0 6a00 6a00 6a00 ff75e8 e8???????? }
- $sequence_3 = { 7532 68dc050000 ff75dc 68???????? e8???????? }
- $sequence_4 = { 6a00 6814010000 68???????? ff75d8 e8???????? 8d3550514000 }
- $sequence_5 = { 8bec ff7508 6a40 e8???????? 0bc0 750c 68c8000000 }
- $sequence_6 = { 81c700020000 68???????? 57 e8???????? 68???????? 57 e8???????? }
- $sequence_7 = { 59 51 80c141 884808 ff05???????? 6a00 6a00 }
- $sequence_8 = { 6a02 e8???????? 0bc0 0f8530010000 c745f000400000 ff75f0 }
- $sequence_9 = { 6a00 6a00 e8???????? ff75dc e8???????? }
+ $sequence_0 = { f7e9 c1fa02 8bc2 c1e81f 40 03c2 687f010000 }
+ $sequence_1 = { 136c2414 894c2428 8b4c246c 896c2420 8d4960 e8???????? 8b4c2440 }
+ $sequence_2 = { 50 57 57 c744242400000000 c744242800000000 c744242c00000000 c744243800000000 }
+ $sequence_3 = { 8b7c2418 f7c3fcffffff 0f8496000000 897c2420 8d4900 6a00 56 }
+ $sequence_4 = { 53 53 896c2448 8844241f 660fd6442454 e8???????? 83c40c }
+ $sequence_5 = { 8bca 83d100 01460c 8b442424 83d100 83c310 83ed04 }
+ $sequence_6 = { 89460c 8b06 53 55 8b2f 8b7f04 33db }
+ $sequence_7 = { 8b7c2444 33fb 237c2434 23cb }
+ $sequence_8 = { 897db0 6a00 ff75c8 ff55d8 6a00 6a16 }
+ $sequence_9 = { 7f04 8bc5 eb0e 56 55 e8???????? 8b54242c }
condition:
- 7 of them and filesize <44864
+ 7 of them and filesize <1024000
}
-rule MALPEDIA_Win_Avos_Locker_Auto : FILE
+rule MALPEDIA_Win_Cmstar_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7ba0a3b7-52b3-54b0-beef-ae9816fdb70a"
+ id = "aaad9b46-b601-594d-9a0b-7ba351f67235"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avos_locker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avos_locker_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cmstar"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cmstar_auto.yar#L1-L174"
license_url = "N/A"
- logic_hash = "20760e04f44624b7366badbec4c361401e8cc12f236ee2efc4fb15277f942fc5"
+ logic_hash = "c5a1f8b6b909717cbba254781a42955dfe756a8fae37e256ff72ffa4cd43d897"
score = 75
quality = 75
tags = "FILE"
@@ -165109,32 +172351,38 @@ rule MALPEDIA_Win_Avos_Locker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d85a8f9ffff 50 8d85fcf5ffff 50 8d8514f6ffff 50 83ec18 }
- $sequence_1 = { 8b4024 ffd0 c645fc0a c78598f9ffff00000000 c7859cf9ffff00000000 8b08 898d98f9ffff }
- $sequence_2 = { 59 3b4580 7359 807d8600 8a8848ef4900 8b857cffffff 8808 }
- $sequence_3 = { 8d8d05efffff e8???????? 8a8d23f0ffff 8808 46 ebbd 6a22 }
- $sequence_4 = { 53 50 e8???????? 83c408 c745fcffffffff 57 8b45d8 }
- $sequence_5 = { 8bd3 3ac1 7501 46 42 8a02 84c0 }
- $sequence_6 = { c745e800000000 660fd645e4 837de810 8945d4 8b75cc 0f43d0 8b45d0 }
- $sequence_7 = { 33c5 50 8d45f4 64a300000000 8b4d0c 8b4508 81f900100000 }
- $sequence_8 = { 8a42ff 84c0 75eb 81fe59ee4ef8 740b 8b7118 85ff }
- $sequence_9 = { 89958cecffff c645fc35 8bca 8d7102 668b01 83c102 6685c0 }
+ $sequence_0 = { 836dfc10 ff75fc 8945e0 8b45dc 83c310 }
+ $sequence_1 = { 8b4dec c1e802 6a04 52 8d0481 50 e8???????? }
+ $sequence_2 = { ff75e0 ff30 e8???????? 8b4df8 }
+ $sequence_3 = { ff15???????? 8bc6 e9???????? 6a10 8d45d0 53 }
+ $sequence_4 = { ff15???????? 6a04 e8???????? be00040000 }
+ $sequence_5 = { 56 bb04010000 57 53 }
+ $sequence_6 = { ff15???????? 6a03 58 5f 5e 5b c9 }
+ $sequence_7 = { 85c0 7504 6a03 eb0d 803b4d }
+ $sequence_8 = { 81ce00ffffff 46 8a1c06 88542418 881c01 8b5c2418 }
+ $sequence_9 = { 8b2d???????? 8b44241c 8bc8 48 85c9 8944241c 7e65 }
+ $sequence_10 = { 5d 741c 8a41ff 3ac3 740b 3cff }
+ $sequence_11 = { 7505 a1???????? 50 ff15???????? eb17 }
+ $sequence_12 = { 8bf0 8d5601 52 e8???????? 83c404 8bf8 8d442414 }
+ $sequence_13 = { e9???????? 55 83f801 57 7532 }
+ $sequence_14 = { 50 ff15???????? 83f8ff 89442420 7507 33f6 e9???????? }
+ $sequence_15 = { 8b5c2408 55 8b6c2414 56 57 8b7c2418 8bcb }
condition:
- 7 of them and filesize <1701888
+ 7 of them and filesize <4268032
}
-rule MALPEDIA_Win_Rc2Fm_Auto : FILE
+rule MALPEDIA_Win_Conficker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e4f1d324-0720-53a3-a9da-cb15ebd44ad4"
+ id = "3a6101de-ccfd-52f9-bf48-95f37d3da01a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rc2fm"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rc2fm_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.conficker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.conficker_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "2b4b23efded831a0bcad4decee49c98aca63a9f5af170fcd017bff9b432b8451"
+ logic_hash = "a2e85b8534ced36c659844072e09fbb061c134856a103a96122c39a859220309"
score = 75
quality = 75
tags = "FILE"
@@ -165148,34 +172396,34 @@ rule MALPEDIA_Win_Rc2Fm_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 48894c2408 55 57 4154 4156 488d6c24c1 4881ecb8000000 }
- $sequence_1 = { 4883ec20 498bf1 4d8bf0 4c8bfa 488bd9 ff15???????? }
- $sequence_2 = { 415c 5f 5b c3 488b09 4889ac2480000000 }
- $sequence_3 = { b001 eb14 448bc3 ba00000500 b91b000100 e8???????? }
- $sequence_4 = { 488b4808 4c897d00 4c89742460 48894df8 8d4e14 e8???????? 6690 }
- $sequence_5 = { 448bc0 e8???????? eb0f ba0a000b00 b911000100 e8???????? 488b0d???????? }
- $sequence_6 = { 0fb68c28304c0200 eb0c 48c1e807 0fb68c28304d0200 4863c1 448bd7 66ff8483b0090000 }
- $sequence_7 = { 88040a ff4328 8b5328 0fb64745 488b4b10 88040a ff4328 }
- $sequence_8 = { 83b98804000000 488bd9 7431 ff8b88040000 8b8388040000 4c8b84c360040000 4d85c0 }
- $sequence_9 = { 0f8781010000 83fd09 0f8778010000 448b642478 4183fc04 0f8769010000 488b4938 }
+ $sequence_0 = { ebe4 f60638 75a8 b008 d0ef 1400 }
+ $sequence_1 = { df6de8 51 df6df8 51 }
+ $sequence_2 = { 8bec 83ec20 8b0d???????? a1???????? 8365f800 56 }
+ $sequence_3 = { 3c04 7415 42 42 60 b066 f2ae }
+ $sequence_4 = { c3 6a10 68???????? e8???????? 68???????? ff15???????? }
+ $sequence_5 = { 3345f8 33c7 33c6 50 ff15???????? 59 5f }
+ $sequence_6 = { 8b4508 33d2 8910 895004 33c9 894c8808 41 }
+ $sequence_7 = { 8d85f8fbffff ff7510 50 e8???????? }
+ $sequence_8 = { 8954241c 61 c3 ac }
+ $sequence_9 = { 55 8bec 83ec20 8b0d???????? a1???????? }
condition:
- 7 of them and filesize <410624
+ 7 of them and filesize <335872
}
-rule MALPEDIA_Win_Xpan_Auto : FILE
+rule MALPEDIA_Win_Pushdo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7325c725-fe3e-5c78-bad6-69f44695968e"
+ id = "ad774ebd-627a-5818-9f5f-1b251e52fd7e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xpan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xpan_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pushdo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pushdo_auto.yar#L1-L208"
license_url = "N/A"
- logic_hash = "be7f9da8e0e3ad23e9493cdb12bfec902f58437483383423a4e4858dbe439d66"
+ logic_hash = "daece01a3a8065197470b42fa0923405b1cfbd8c63e62002ad7e9af51850eb51"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -165187,32 +172435,43 @@ rule MALPEDIA_Win_Xpan_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c001 c7450cffffffff 894108 8b4108 3b410c 0f83cb050000 0fb600 }
- $sequence_1 = { 8bb018010000 85f6 0f8557010000 8b01 89cd 83f84d 0f870d1d0000 }
- $sequence_2 = { 8b5d20 83e001 05ffffff7f 8903 8b451c c70004000000 807dbc00 }
- $sequence_3 = { 8b442428 895c2404 89442408 ff15???????? 39c3 7247 }
- $sequence_4 = { ffd5 83ec04 83fe05 75ea 8d7338 c7431cffffffff }
- $sequence_5 = { 8b55d0 c645c201 0fbed8 0fb65210 e9???????? c645c100 c645c201 }
- $sequence_6 = { 8b930c010000 88442418 be01000000 c683ff00000000 c7442404ff000000 891c24 89542408 }
- $sequence_7 = { 0fb644242c 89442404 89f0 83c002 890424 e8???????? e9???????? }
- $sequence_8 = { e9???????? 8d489f 80f905 0f874b0e0000 83e857 e9???????? 8b931c010000 }
- $sequence_9 = { 31c0 e9???????? 8b44241c 897c243c 89442438 8d442438 898310010000 }
+ $sequence_0 = { 50 ff15???????? 33d2 b9ffff0000 }
+ $sequence_1 = { f7f9 33c9 ba88020000 f7e2 0f90c1 }
+ $sequence_2 = { 8b45fc b10b d3c0 61 }
+ $sequence_3 = { 81ec18010000 6800010000 6a00 8d85f0feffff }
+ $sequence_4 = { 736a 8b45fc 0fbe8c05f0feffff 038de8feffff 8b45fc }
+ $sequence_5 = { 0fbe1410 03ca 81e1ff000000 898de8feffff 8b85e8feffff 8a8c05f0feffff }
+ $sequence_6 = { c785e8feffff00000000 c745f400000000 c745fc00000000 eb09 8b55fc 83c201 8955fc }
+ $sequence_7 = { 33d1 8b450c 0345fc 8810 e9???????? }
+ $sequence_8 = { e8???????? 83c41c 85c0 7503 8975fc }
+ $sequence_9 = { 53 53 894808 8b4e14 50 }
+ $sequence_10 = { 53 6a18 ffd6 ffb5f4f7ffff 8d85f4fbffff 50 }
+ $sequence_11 = { 0fb6c3 6a03 33d2 5f f7f7 }
+ $sequence_12 = { 8d45ec 50 8d4598 50 57 57 }
+ $sequence_13 = { 52 8d8588fbffff 50 e8???????? }
+ $sequence_14 = { a1???????? 6bc00a 057f0a0000 33d2 b9a1190000 f7f1 }
+ $sequence_15 = { e8???????? 89859cd3ffff 83bd9cd3ffff00 0f8ea0000000 8d8550d3ffff 50 }
+ $sequence_16 = { 3b4dd8 7f28 8b55e4 3b55d8 0f85cf000000 8b45d8 }
+ $sequence_17 = { 81bd5cfeffff70170000 0f83e2010000 8b855cfeffff 33d2 b964000000 f7f1 85d2 }
+ $sequence_18 = { ff55e4 8945c8 eb11 8b4dd4 }
+ $sequence_19 = { 83c404 c1e002 8945e4 8b4de4 }
+ $sequence_20 = { 50 8b4dfc 51 e8???????? 85c0 7c3b 8b55f0 }
condition:
- 7 of them and filesize <3235840
+ 7 of them and filesize <163840
}
-rule MALPEDIA_Win_Cotx_Auto : FILE
+rule MALPEDIA_Win_Danbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4cbfd2a1-cbfc-5404-9f22-8e027db9306c"
+ id = "2c585571-1377-525b-81df-f475b9f7d032"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cotx"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cotx_auto.yar#L1-L111"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.danbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.danbot_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "5f62f869de8e5b67f4dbb19d8460c8365da1f60d9f53861111556d3c0f9ba6d4"
+ logic_hash = "7b636202f57d607cd3195402deda2493294df662e32f18cd69328119b0c63f1c"
score = 75
quality = 75
tags = "FILE"
@@ -165226,32 +172485,32 @@ rule MALPEDIA_Win_Cotx_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c705????????890e9944 c705????????dbd99823 c705????????d468bcb5 c705????????a1a14538 c705????????2086e659 }
- $sequence_1 = { 740e 3d10b6afa6 7407 3d36ce164d }
- $sequence_2 = { 6800f00000 81c600f00000 68???????? 56 e8???????? }
- $sequence_3 = { 50 51 8d85bcebffff 50 56 }
- $sequence_4 = { c705????????d468bcb5 c705????????a1a14538 c705????????2086e659 c705????????eec45abf }
- $sequence_5 = { c705????????9cb95b4c c705????????2d494a94 c705????????8db133d4 c705????????8e220b1d }
- $sequence_6 = { 6800040000 8d8598f6ffff 6a00 50 e8???????? 83c40c 8d8598feffff }
- $sequence_7 = { 8d850af8ffff c78500f8ffff52617354 6a00 50 }
- $sequence_8 = { f3a4 50 0f1185a8faffff e8???????? }
- $sequence_9 = { 8bce a3???????? e8???????? 8b15???????? 8b4dfc }
+ $sequence_0 = { 66893c48 448b4374 488b4b68 41ffc8 4d03c0 e8???????? 48638bac000000 }
+ $sequence_1 = { 8a4004 88040a 44016b28 8b5328 488b4330 488b4b10 8a4005 }
+ $sequence_2 = { 483bd7 7213 48ffc2 4c8bc3 488b8c2480030000 e8???????? 4c89b42490030000 }
+ $sequence_3 = { e9???????? 488b8a80000000 e9???????? 488b8a78000000 e9???????? 488b8a28000000 e9???????? }
+ $sequence_4 = { 4154 4155 4157 4881ec10060000 48c780a8fafffffeffffff 48895808 48897010 }
+ $sequence_5 = { 488b9424f0000000 4883fa10 7214 48ffc2 4d8bc4 488b8c24d8000000 e8???????? }
+ $sequence_6 = { 48ffc2 4d8bc6 488b8c2428010000 e8???????? 48899c2438010000 4889bc2440010000 889c2428010000 }
+ $sequence_7 = { 488b55df 4883fa08 7212 48ffc2 41b802000000 488b4dc7 e8???????? }
+ $sequence_8 = { 0fb6442420 84db 410f44c4 8ad8 895c2420 eb25 4c8b742460 }
+ $sequence_9 = { ffd3 99 33c2 2bc2 89442430 448be0 4c89642450 }
condition:
- 7 of them and filesize <1171456
+ 7 of them and filesize <1492992
}
-rule MALPEDIA_Win_Roseam_Auto : FILE
+rule MALPEDIA_Win_Tflower_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "88276476-b18b-5edc-880f-eae459b2a660"
+ id = "b4660b68-51d0-51ac-bbdd-acf4449bc6d1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.roseam"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.roseam_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tflower"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tflower_auto.yar#L1-L158"
license_url = "N/A"
- logic_hash = "3438063035004ab07a2e8d6bda2a389a18e5085289cc780bdf790db5294b5e20"
+ logic_hash = "82eb88790bbfb711d9ea01573d045bd4c38f5ceb308c5ccacf5ea018abeab10b"
score = 75
quality = 75
tags = "FILE"
@@ -165265,32 +172524,38 @@ rule MALPEDIA_Win_Roseam_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 895514 eb38 895514 68???????? 68???????? 50 }
- $sequence_1 = { 8b8c2490000000 89442408 8d44240c 6a0a }
- $sequence_2 = { 8b12 66c745ec0200 8955f0 c745fc20000000 68???????? 50 9c }
- $sequence_3 = { f2ae f7d1 49 894dec 8d0489 99 }
- $sequence_4 = { 81fbff000000 895de8 0f84e2010000 8b4df8 83f903 }
- $sequence_5 = { 57 b914000000 be???????? 8d7d90 f3a5 33d2 a4 }
- $sequence_6 = { 58 68???????? ffd6 b91f000000 33c0 }
- $sequence_7 = { 5d 58 8d8d58ffffff 8d95f4fcffff 51 }
- $sequence_8 = { 83c40c f3ab 66ab aa e8???????? 8985f4fcffff }
- $sequence_9 = { 894df0 eb0d 33c9 894dec 894df0 }
+ $sequence_0 = { 0001 0200 0103 0303 }
+ $sequence_1 = { 0001 7708 00f3 7608 }
+ $sequence_2 = { 0002 7408 00f7 7308 }
+ $sequence_3 = { 001a 0c05 003c0c 05004e0c05 }
+ $sequence_4 = { 0008 7408 0002 7408 }
+ $sequence_5 = { c1e104 0fb6d0 8b84248c000000 c1e204 8baa406f4f00 }
+ $sequence_6 = { 000f 7708 0001 7708 }
+ $sequence_7 = { c7405420164600 eb5e 57 e8???????? }
+ $sequence_8 = { 3bf7 72e3 5b 5f b001 5e }
+ $sequence_9 = { 0010 740b 0021 740b }
+ $sequence_10 = { 0fb6c0 330c85c0fe4e00 0fb6c3 8b5f28 330c85c0fa4e00 33f1 8d0411 }
+ $sequence_11 = { 8b75fc 8b7df4 c60301 eb06 8b75fc 8b7df4 }
+ $sequence_12 = { 894c2448 7436 8b442410 8d90c8795000 }
+ $sequence_13 = { 330c8520dd4e00 8b442414 c1e818 330c8520d94e00 8b44242c 0fb6c0 }
+ $sequence_14 = { 6a35 eb2b 8bfb eb04 8b442414 ff742420 }
+ $sequence_15 = { 000b 8605???????? 007885 0500788605 }
condition:
- 7 of them and filesize <221184
+ 7 of them and filesize <6578176
}
-rule MALPEDIA_Win_Rtpos_Auto : FILE
+rule MALPEDIA_Win_Dma_Locker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "77dcd653-95cb-55c4-91a1-f9b9e9596fd3"
+ id = "a8f397b8-8b2b-5241-983c-0be688886121"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rtpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rtpos_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dma_locker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dma_locker_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "4ad89a49b88ba1ea262b015470065dd4f3f20d950975a1f27ea85a4b99624bd0"
+ logic_hash = "b77f5ca2d335c463d6c2790ec00b5fbc00e6cee8478dbf10e4d2132a598117f8"
score = 75
quality = 75
tags = "FILE"
@@ -165304,34 +172569,34 @@ rule MALPEDIA_Win_Rtpos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68a8040000 8b45ec 50 e8???????? 83c408 c3 8b542408 }
- $sequence_1 = { 83e908 8d7608 660fd60f 8d7f08 8b048d74b44000 }
- $sequence_2 = { 8b0cc5c4ae4200 894de4 85c9 7455 }
- $sequence_3 = { 7619 8b4dd4 51 ff15???????? }
- $sequence_4 = { 8d45d8 50 6a00 8b4dd4 51 }
- $sequence_5 = { 85c0 752c 6a00 68???????? 68???????? 6a02 68???????? }
- $sequence_6 = { 8bec 53 8b5d08 33c9 57 33c0 8d3c9d5c654300 }
- $sequence_7 = { 33c5 8945fc c745d800000000 c745dc00000000 33c0 }
- $sequence_8 = { 2b45c4 3b45f0 7619 8b4dd4 51 ff15???????? }
- $sequence_9 = { 6bc030 03048db86a4300 50 ff15???????? 5d c3 }
+ $sequence_0 = { e8???????? 8bf0 eb02 33f6 6803010000 8d8c24a1040000 }
+ $sequence_1 = { 57 56 e8???????? 83c40c 84db }
+ $sequence_2 = { 8bc7 e8???????? 84c0 741f 8b4f10 8b13 57 }
+ $sequence_3 = { 8a5dfd 32ca 8a55fc 32cb 8848ff 8aca }
+ $sequence_4 = { 8b5e04 8b0e 8945ec 8b55ec }
+ $sequence_5 = { ffd7 85c0 7fe3 5f }
+ $sequence_6 = { e8???????? 8b442420 8b00 83c40c 8d4c2424 51 }
+ $sequence_7 = { 52 ff15???????? a1???????? 6a00 50 ff15???????? e9???????? }
+ $sequence_8 = { 7545 68???????? e8???????? 8b95b0f6ffff 83c404 52 ff15???????? }
+ $sequence_9 = { 385e14 0f85e8000000 8b4618 83f8ff 7407 50 ff15???????? }
condition:
- 7 of them and filesize <507904
+ 7 of them and filesize <532480
}
-rule MALPEDIA_Win_Synccrypt_Auto : FILE
+rule MALPEDIA_Win_Cherry_Picker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "06111ba7-b1d3-5613-b1dc-5c5b2d1d9432"
+ id = "4ae5e79a-a840-5921-89d9-37d4576478a8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.synccrypt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.synccrypt_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cherry_picker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cherry_picker_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "f349f89fd6eccd96b82f1ed169c1d5231d52d67328e2977c4a89bd9cc0fef158"
+ logic_hash = "34271a3488eb7c13dc528b66980352e939907040bf405db0ad386d2bee3e0b44"
score = 75
- quality = 45
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -165343,32 +172608,32 @@ rule MALPEDIA_Win_Synccrypt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c744240477000000 c7042422000000 e8???????? e9???????? c7442410af000000 c744240c94195900 c74424087a000000 }
- $sequence_1 = { ba01000000 89f8 e8???????? 85c0 8b4c242c 0f84aa000000 8b4714 }
- $sequence_2 = { 892c24 e8???????? 892c24 89c7 e8???????? 85c0 7517 }
- $sequence_3 = { c1e806 85c0 7523 897358 83c318 89742408 891c24 }
- $sequence_4 = { e8???????? 85c0 74c8 8d442414 8974240c 895c2408 89442404 }
- $sequence_5 = { e8???????? 85c0 0f8413010000 8d7804 89c1 c7406800000000 89c3 }
- $sequence_6 = { f6400c01 7451 891c24 e8???????? 83c001 c744240897010000 c7442404???????? }
- $sequence_7 = { c7442404???????? c7042402000000 a3???????? e8???????? c7442404???????? c704240b000000 a3???????? }
- $sequence_8 = { e8???????? 893424 e8???????? 8b442430 890424 e8???????? 39c7 }
- $sequence_9 = { 890424 8954240c e8???????? 3b6c2418 8d45fe 746e 8b570c }
+ $sequence_0 = { 68???????? 68???????? a3???????? ffd6 69c0e8030000 68???????? }
+ $sequence_1 = { 80fa3b 7503 83c9ff 8817 47 }
+ $sequence_2 = { 68???????? 56 89442420 ffd3 68???????? 56 }
+ $sequence_3 = { 8bf0 0fbec9 81e6ff000000 33f1 }
+ $sequence_4 = { a1???????? 53 8b1d???????? 56 57 6aff }
+ $sequence_5 = { a3???????? 85c0 7512 68???????? 50 50 }
+ $sequence_6 = { ff15???????? 8bf0 68???????? 56 ffd3 68???????? 56 }
+ $sequence_7 = { 6800010000 68???????? 68???????? 68???????? 68???????? ffd6 68???????? }
+ $sequence_8 = { a1???????? 56 6aff 50 8bf1 }
+ $sequence_9 = { ffd6 68???????? 6800010000 68???????? }
condition:
- 7 of them and filesize <4489216
+ 7 of them and filesize <712704
}
-rule MALPEDIA_Win_Meow_Auto : FILE
+rule MALPEDIA_Win_Vermilion_Strike_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3f4c85a0-7273-573d-9e5f-b6afea896e94"
+ id = "cba78739-b046-53e4-ac8a-fb7e1edf89cf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.meow"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.meow_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vermilion_strike"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vermilion_strike_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "0e149c089578c6685626f307f9368d702f8c85f1bb4a2cbda9a3a1cb6a651295"
+ logic_hash = "1312a531701a8eef40faaee34110290f7221a3999f3d5685ddec7e08b4b4a11d"
score = 75
quality = 75
tags = "FILE"
@@ -165382,32 +172647,32 @@ rule MALPEDIA_Win_Meow_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c685cefaffff53 c685cffaffff63 c685d0faffff53 c685d1faffff53 c685d2faffff53 8a85c9faffff e8???????? }
- $sequence_1 = { 72dc ff75ec 8d4599 50 e8???????? 8b33 ba0f000000 }
- $sequence_2 = { 0f8441070000 c745f4bb195c00 be03000000 8b45f4 99 f7fe 85d2 }
- $sequence_3 = { 99 f7f9 8b45f4 85d2 7403 48 eb01 }
- $sequence_4 = { 743b 8b45f0 83c117 83c00b 99 f7f9 8945f0 }
- $sequence_5 = { c685dbfdffff5f c685dcfdffff7d c685ddfdffff7d c685defdffff7d 8a85d5fdffff e8???????? 898564f5ffff }
- $sequence_6 = { 7907 48 83c8fc 83c001 7463 8b4c2410 8d4303 }
- $sequence_7 = { 8a01 8d4901 0fb6c0 83e871 6bc037 99 f7fb }
- $sequence_8 = { c6854dfeffff4c c6854efeffff3b c6854ffeffff6b c68550feffff3b c68551feffff26 c68552feffff3b c68553feffff18 }
- $sequence_9 = { 99 f7f9 85d2 7445 8b442410 8d4f17 83c00b }
+ $sequence_0 = { 0f8e3f010000 56 55 8d442444 e8???????? 85ff 751b }
+ $sequence_1 = { ff15???????? 8bf7 e8???????? 8b15???????? 6a00 6a01 }
+ $sequence_2 = { 51 8d4601 e8???????? 6a30 53 8bc6 8d7c2444 }
+ $sequence_3 = { 8bd8 8beb 897c2418 85c0 7517 e8???????? 33c0 }
+ $sequence_4 = { 6a00 6a00 6a03 6a00 6a00 50 53 }
+ $sequence_5 = { 83c8ff 8bf7 c744244802000000 e8???????? 885c2440 396c2428 720d }
+ $sequence_6 = { 83c004 395e18 7205 8b7604 eb03 83c604 8b3d???????? }
+ $sequence_7 = { 8bc1 57 c746180f000000 c7461400000000 c744240400000000 c6460400 }
+ $sequence_8 = { 6a02 8bc3 7413 68???????? e8???????? 6a02 68???????? }
+ $sequence_9 = { 3bc5 7405 e8???????? 2bdf 8b542424 52 }
condition:
- 7 of them and filesize <492544
+ 7 of them and filesize <540672
}
-rule MALPEDIA_Win_Bolek_Auto : FILE
+rule MALPEDIA_Win_Applejeus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "21f1a0ba-06a1-5668-aea4-333af031f0f6"
+ id = "2b213dd7-4b0e-53d6-9398-7bec043b88e3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bolek"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bolek_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.applejeus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.applejeus_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "28c372302adc63618e82259e643572bec2793a354bb442ed761054ecd6bf8112"
+ logic_hash = "0a3d67a5753a00f446b4f5eec17ef4a4499de52aeb8e82581c3d643c4e67e3d2"
score = 75
quality = 75
tags = "FILE"
@@ -165421,32 +172686,32 @@ rule MALPEDIA_Win_Bolek_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 894c2454 8bc7 8b8c24ac000000 8bdf 0facc808 33ed c1e318 }
- $sequence_1 = { 3b31 72e1 51 e8???????? 59 8bc7 5f }
- $sequence_2 = { 8bcd 0fa4c117 0bf9 c1e017 0bd8 8bcd 8b442460 }
- $sequence_3 = { 8d86f4000000 50 e8???????? 83c418 56 6880000000 ff750c }
- $sequence_4 = { dd442418 dc0d???????? dd1c24 68???????? 8b1d???????? 8d44242c 6a40 }
- $sequence_5 = { eb7a 3c03 0f85bf000000 53 6a01 8d442428 50 }
- $sequence_6 = { 85c9 746f 803900 746a 6a2c 51 890f }
- $sequence_7 = { e8???????? eb07 814f7c00040000 5f 5e 5d 5b }
- $sequence_8 = { 89448c20 41 83c304 ebd0 8bac2434030000 8b9c2430030000 85db }
- $sequence_9 = { 83e4f8 83ec68 8364242000 8364242400 8b450c c744241001234567 c744241489abcdef }
+ $sequence_0 = { 8902 8b4608 8b08 8b4604 810044f3ffff 8100bc0c0000 }
+ $sequence_1 = { 8b4604 8b00 33c2 0f8583000000 c745f45b000000 8b45f4 83f032 }
+ $sequence_2 = { 8945dc 8d45d0 c745d0a08e4200 897dd4 8975d8 0f1145b0 }
+ $sequence_3 = { 8b4a04 50 0f1145c8 c745a8e0294200 0f1145d8 897dac 8975b0 }
+ $sequence_4 = { e8???????? 8b4dc8 83c414 8945cc 89851cffffff c700???????? 897004 }
+ $sequence_5 = { c745e400000000 8b410c 50 6a00 51 8b04851cfb4600 ffd0 }
+ $sequence_6 = { c68589f5ffff7d c6858af5ffff85 c6858bf5ffff72 c6858cf5ffff83 c6858df5ffff59 c6858ef5ffff3a c6858ff5ffff77 }
+ $sequence_7 = { 8d4db0 e9???????? 8d4db4 e9???????? 8d4dac e9???????? 8b542408 }
+ $sequence_8 = { e8???????? 8b7588 8d4d94 83c418 e8???????? c78568ffffffd5030000 8b8568ffffff }
+ $sequence_9 = { 8d85d42e0000 50 ff15???????? 57 ff15???????? e9???????? ff15???????? }
condition:
- 7 of them and filesize <892928
+ 7 of them and filesize <1245184
}
-rule MALPEDIA_Win_Kerrdown_Auto : FILE
+rule MALPEDIA_Win_Kpot_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4e6c0456-511b-5ce5-b1ea-436b1b2f6672"
+ id = "e45631fb-3fb5-58e0-9b9b-6b34d42ff6ce"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kerrdown"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kerrdown_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kpot_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kpot_stealer_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "a33ff3dd3ba2b88105d1e9461a66c5947186b615b759549afa7c04ba76dcfedd"
+ logic_hash = "16f05178ea617d4330175d94df8b79c29f673ce62148ecbf2153af87111da7a0"
score = 75
quality = 75
tags = "FILE"
@@ -165460,32 +172725,32 @@ rule MALPEDIA_Win_Kerrdown_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5d c20800 85f6 75b2 83ff10 8935???????? b8???????? }
- $sequence_1 = { 8bec 8b0d???????? b8???????? 8b15???????? 57 8b3d???????? 83ff10 }
- $sequence_2 = { 8aca c0e206 c0e902 80e10f 02c8 8a45eb 243f }
- $sequence_3 = { b8???????? 0f43d1 b9???????? 2bc2 50 }
- $sequence_4 = { 0f43c1 3d???????? 773e 83ff10 }
- $sequence_5 = { 83ff10 ba???????? b8???????? 0f43d1 b9???????? 2bc2 }
- $sequence_6 = { 80e10f 02c8 8a45eb 243f }
- $sequence_7 = { ff750c 83ff10 ba???????? b8???????? 0f43d1 b9???????? 2bc2 }
- $sequence_8 = { e8???????? 46 83fe03 7cec 8b4de0 }
- $sequence_9 = { 0f854d0d0000 eb00 f30f7e442404 660f2815???????? 660f28c8 }
+ $sequence_0 = { 03c6 50 ff75f4 e8???????? 59 59 8d4df8 }
+ $sequence_1 = { 0bce 8bc1 c1e804 33c2 250f0f0f0f 33d0 }
+ $sequence_2 = { 55 8bec ff7508 ff15???????? 83f8ff 7409 a8a7 }
+ $sequence_3 = { 8b4604 8b5df4 03d2 8d445802 e8???????? }
+ $sequence_4 = { 85c0 7427 8b45f8 03c6 50 }
+ $sequence_5 = { 57 8bf8 8b4518 0fb67005 }
+ $sequence_6 = { 8b45f4 c1e918 884b07 8945fc 8b45f0 83c308 ff4dec }
+ $sequence_7 = { 5e 5b c9 c3 0fb70f 6685c9 7440 }
+ $sequence_8 = { a8a7 7405 33c0 40 5d }
+ $sequence_9 = { 8bc1 c1e810 884306 8b45f4 }
condition:
- 7 of them and filesize <278528
+ 7 of them and filesize <219136
}
-rule MALPEDIA_Win_Equationdrug_Auto : FILE
+rule MALPEDIA_Win_Locky_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "37b1b451-51c5-5fbc-9487-21d701b707d2"
+ id = "0065ec05-3bad-56a6-868c-9fbbe2e6de6d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.equationdrug"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.equationdrug_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.locky"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.locky_auto.yar#L1-L170"
license_url = "N/A"
- logic_hash = "f8f538888e4dbac5fbcd6d58b6a95043a330081a5194049d400ba3c70341afe9"
+ logic_hash = "3ed4a85dfe440bb226db6c3cc6e1aa5c521449c7aa69fbc084d35b1292d156c0"
score = 75
quality = 75
tags = "FILE"
@@ -165499,32 +172764,38 @@ rule MALPEDIA_Win_Equationdrug_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5b c21000 8bd0 56 81e2ff0f0000 53 83c704 }
- $sequence_1 = { 0f84f4000000 8b7c2414 f7c7ff010000 0f85e4000000 8b4e04 8d442410 50 }
- $sequence_2 = { 56 8d4c2418 c644245800 e8???????? 8d4c2414 e8???????? 84c0 }
- $sequence_3 = { 84c0 741a 668b4ef8 660fbed0 668b46fa 52 50 }
- $sequence_4 = { 89542414 8b542410 0fbfc2 40 0fafc1 3bfb 73c4 }
- $sequence_5 = { c644245c00 e8???????? 83c404 89442464 85c0 c644245802 7411 }
- $sequence_6 = { e8???????? 85c0 0f864b020000 53 8bcd e8???????? 50 }
- $sequence_7 = { 33c0 eb07 8b4708 2bc6 d1f8 33d2 33db }
- $sequence_8 = { 8bca b001 83e103 f3a4 5f 5e 5d }
- $sequence_9 = { 6685c0 7537 8b442408 3dffff0000 772c c1e009 }
+ $sequence_0 = { 89b560ffffff 898568ffffff ffd7 8bf8 897de0 3bfb }
+ $sequence_1 = { 8b4db8 3975cc 7303 8d4db8 8b45d4 3975e8 }
+ $sequence_2 = { 50 50 50 894de8 8b4d08 }
+ $sequence_3 = { 8d459c 50 8d45b8 50 e8???????? 59 59 }
+ $sequence_4 = { 46 3bf0 7621 8bc8 d1e9 ba49922409 }
+ $sequence_5 = { 8bc6 03c1 3810 7412 83ff10 7204 }
+ $sequence_6 = { 837e1410 8b4610 7202 8b36 50 56 8d45f0 }
+ $sequence_7 = { 83c9ff 8bf0 51 e8???????? 40 50 }
+ $sequence_8 = { 03d3 5b c21000 e9???????? 8bff 55 8bec }
+ $sequence_9 = { 6a44 90 e9???????? 90 }
+ $sequence_10 = { 5d 90 ebf6 90 }
+ $sequence_11 = { 83c40c e9???????? 90 8d00 }
+ $sequence_12 = { 66ab e9???????? 90 8d36 }
+ $sequence_13 = { ff15???????? e9???????? 90 50 90 }
+ $sequence_14 = { 66ab 90 e9???????? 8d36 }
+ $sequence_15 = { 5e c21000 8bff 55 8bec 33c0 8b4d08 }
condition:
- 7 of them and filesize <449536
+ 7 of them and filesize <1122304
}
-rule MALPEDIA_Win_Icefog_Auto : FILE
+rule MALPEDIA_Win_Royalcli_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "048267f9-e0c5-52eb-96a2-fb16cbcf8de1"
+ id = "8a3d9888-c19a-51e8-8633-e1429e45af66"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.icefog"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.icefog_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.royalcli"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.royalcli_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "1d4c21c23eefcc954f2b32ae717065ebcfe80845052716e0c9e4c85776b4e83c"
+ logic_hash = "5cdfe5e738245420de8a121061e185e2740c336e09d01f0babed3f279bcde56b"
score = 75
quality = 75
tags = "FILE"
@@ -165538,32 +172809,32 @@ rule MALPEDIA_Win_Icefog_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 80e3fb 899588feffff 33d2 80c327 85ff 0f94c2 85d2 }
- $sequence_1 = { c78530ffffff05000000 eb0f 83f803 750a c78530ffffff02000000 8b4604 50 }
- $sequence_2 = { 751e 8b4d0c 8d450c 50 57 51 e8???????? }
- $sequence_3 = { 8bec 53 56 33f6 39770c 7e24 33db }
- $sequence_4 = { 8b5108 8b45f4 03d3 52 53 50 6a03 }
- $sequence_5 = { 50 e8???????? 8b0e 8d55d4 68ffffff7f 52 894de8 }
- $sequence_6 = { 8b5610 0bf8 8b4508 52 50 e8???????? 8b4e18 }
- $sequence_7 = { 50 51 e8???????? 8bd8 83c408 85db 0f841b010000 }
- $sequence_8 = { e8???????? 53 e8???????? 53 57 e8???????? 83c42c }
- $sequence_9 = { dfe0 ddd9 f6c441 0f8572010000 dd05???????? d8d1 dfe0 }
+ $sequence_0 = { 41 3bcf 7cb5 56 }
+ $sequence_1 = { e8???????? 33f6 83c42c 3bc6 0f8c19050000 83bda4feffff1c 0f8c0c050000 }
+ $sequence_2 = { 5d c3 56 ff15???????? 5b 5f 33c0 }
+ $sequence_3 = { 898dccf9ffff 7d10 33c0 8b4dfc }
+ $sequence_4 = { 8b08 8d954cf7ffff 52 68???????? }
+ $sequence_5 = { 33f6 ff15???????? e9???????? 8b4708 }
+ $sequence_6 = { 6a01 50 e8???????? 56 8945dc e8???????? 8b55e0 }
+ $sequence_7 = { 83c414 8955e4 2bd0 8d9b00000000 }
+ $sequence_8 = { 8bbdd4f9ffff 8b9dc4f9ffff 807c3b0f00 751c 8b4b08 8b5508 }
+ $sequence_9 = { 50 e8???????? 6820010000 8d8dc0fdffff 56 51 e8???????? }
condition:
- 7 of them and filesize <1187840
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Pwnpos_Auto : FILE
+rule MALPEDIA_Win_Fakeword_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "abbe2d0a-a645-5f32-9b7c-0253f67ad1b4"
+ id = "dff35d24-3d8a-5dd3-be0c-60e6ee2ac528"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pwnpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pwnpos_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fakeword"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fakeword_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "7bd328aa33dd14635d4dbb434ca27c66253964455bceaea97af6eb90a2de7f21"
+ logic_hash = "ba7599fef3200798ceac9b8a2a397ab651b3acac17ae30ecdd8eedb5f787592d"
score = 75
quality = 75
tags = "FILE"
@@ -165577,32 +172848,32 @@ rule MALPEDIA_Win_Pwnpos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8dbcf9ffff 3985b4f9ffff 8b85a0f9ffff 7306 8d85a0f9ffff 51 50 }
- $sequence_1 = { 391d???????? 0f84a4000000 8d75d4 e8???????? 68???????? 50 c645fc01 }
- $sequence_2 = { 51 c745fc00000000 ffd3 85c0 7507 e8???????? eb0c }
- $sequence_3 = { 6800400000 8d8c2494000000 51 ff15???????? 85c0 7526 8b8c2498400000 }
- $sequence_4 = { 762a 56 e8???????? 8d0445fc6c4400 8bc8 }
- $sequence_5 = { 89564c 895e44 6a08 b9???????? }
- $sequence_6 = { eb14 807a2100 740a 3935???????? 7302 8bd1 }
- $sequence_7 = { 3d00010000 752d 837c241c00 7626 }
- $sequence_8 = { e9???????? 8d9580f9ffff 52 b801000000 898d84f9ffff 898d88f9ffff 6a02 }
- $sequence_9 = { 8bd1 8b09 eb03 8b4908 80792100 74e6 5f }
+ $sequence_0 = { 52 68???????? a3???????? 890d???????? c744240c10000000 c605????????11 c605????????22 }
+ $sequence_1 = { eb03 8b7de8 8d14b6 893d???????? }
+ $sequence_2 = { 7516 8b0a 8b6f34 25ff0f0000 03c3 03c1 }
+ $sequence_3 = { 6a00 6a10 8d7e14 56 6a04 }
+ $sequence_4 = { c684247603000031 754d 8d442454 8d8c2477030000 50 56 }
+ $sequence_5 = { 03c3 89442410 8b4804 85c9 750b 8b480c }
+ $sequence_6 = { 8b4701 8d4f09 8d743809 56 51 ff15???????? 83c408 }
+ $sequence_7 = { 8d1c02 3bd9 72f1 c6040f00 }
+ $sequence_8 = { b808000000 5e 83c440 c3 81fea1000000 7528 }
+ $sequence_9 = { 57 33c0 85d2 7e19 8bca 8bf3 8be9 }
condition:
- 7 of them and filesize <638976
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Rovnix_Auto : FILE
+rule MALPEDIA_Win_Yty_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6d0efd0b-959b-5f07-9cf2-cb58dc189913"
+ id = "02d4730a-30ed-52fc-baae-eabe1247d262"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rovnix"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rovnix_auto.yar#L1-L389"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yty"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yty_auto.yar#L1-L501"
license_url = "N/A"
- logic_hash = "5e2878b298d1848da7bc42b9c6ab694e8616fdab743143a73f75bed6d973bc79"
+ logic_hash = "379d5918b4988ca6f478472e8b6e04b973c7dd65b7661d4073d168551cfe004f"
score = 75
quality = 50
tags = "FILE"
@@ -165616,66 +172887,77 @@ rule MALPEDIA_Win_Rovnix_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bf8 83c335 c1e902 ad 2bc3 ab e2fa }
- $sequence_1 = { 7405 57 6a00 ffd2 89442408 }
- $sequence_2 = { 83e7f0 89542418 83c710 8bea }
- $sequence_3 = { be???????? 8b15???????? 83e7f0 89542418 }
- $sequence_4 = { 60 bf40090000 be???????? 8b15???????? }
- $sequence_5 = { ff15???????? 8b550c 884304 8bc2 c1e802 25ff000000 8d4cc324 }
- $sequence_6 = { 83c220 85c0 7404 3bc2 }
- $sequence_7 = { 7405 8d4e1c 8908 8b4508 }
- $sequence_8 = { 7511 ff4e18 7505 e8???????? }
- $sequence_9 = { 85c0 e8???????? 8be5 5d }
- $sequence_10 = { 894804 8b4608 8b4e0c 8901 894804 8b4718 }
- $sequence_11 = { 8936 8d7e08 897f04 893f 894e14 895e10 }
- $sequence_12 = { 83f919 7703 83c220 85c0 }
- $sequence_13 = { 8975d0 c745d800020000 8975d4 8975dc 8975e0 }
- $sequence_14 = { 8b7e10 eb06 8b5d0c 8b7d08 8bcf ff15???????? }
- $sequence_15 = { 7521 8bc3 c1e802 25ff000000 8d4cc724 8b01 }
- $sequence_16 = { 5d c3 85c9 e8???????? }
- $sequence_17 = { 5d c3 85c0 e8???????? }
- $sequence_18 = { 16 85c9 23d2 59 }
- $sequence_19 = { 55 8bec 85db 85c9 }
- $sequence_20 = { 23db 81e1ff000000 23c9 83440c0404 }
- $sequence_21 = { 23c9 81e1ffff0000 85c0 51 85c9 e8???????? 8be5 }
- $sequence_22 = { 8b4d08 85d2 81e1ff000000 85db 83440c0404 23d2 }
- $sequence_23 = { 45 7d58 95 08c1 a3???????? 5c 46 }
- $sequence_24 = { 59 23db 23d2 81e1ffff0000 85c0 85c0 51 }
- $sequence_25 = { 20a8261ce0dc 3d6235c121 652572f7a5a7 ce }
- $sequence_26 = { 7e27 0cc7 8e610b 69f8d60e5ca1 2e08450d }
- $sequence_27 = { 03ea 680c000000 012c24 8b0d???????? }
- $sequence_28 = { 17 d3fb 7127 49 ee }
- $sequence_29 = { 4c8bdc 49895b08 49897310 57 4883ec30 33c0 }
- $sequence_30 = { 4b af 7dce 98 }
- $sequence_31 = { 498be8 488bfa 7429 498d4320 488bd1 498d4bc8 }
- $sequence_32 = { 498b5b38 498b6b40 498b7348 8bc7 498be3 415f }
- $sequence_33 = { 61 54 99 46 45 e7f2 0ad7 }
- $sequence_34 = { 807bf9f3 53 56 b88302010b 92 090468 }
- $sequence_35 = { 59 85c0 85c0 81e1ffff0000 23d2 85db 51 }
- $sequence_36 = { ff15???????? 4c8d5c2460 498b5b18 498b6b20 }
- $sequence_37 = { 488364245800 488364247000 488364247800 488d442430 4c8d4c2440 }
- $sequence_38 = { 46 92 c55151 a2???????? d24b46 }
- $sequence_39 = { ff15???????? b8feff0000 483bf0 480f47f0 }
- $sequence_40 = { 23d2 85db 8b4d08 85db }
- $sequence_41 = { 81e1ffff0000 23d2 23c9 51 85c0 e8???????? }
- $sequence_42 = { e19b 06 6d 99 }
- $sequence_43 = { 61 c0390e 60 da57b2 }
+ $sequence_0 = { 0f840c000000 8365d8fe 8b7508 e9???????? }
+ $sequence_1 = { 8d45f4 64a300000000 8b7508 33ff 897dd8 }
+ $sequence_2 = { 8975e0 85c9 7407 8b11 8b4204 ffd0 c745fc00000000 }
+ $sequence_3 = { 668910 8bc6 5b 8be5 5d c20400 }
+ $sequence_4 = { ffd2 8b8568ffffff 8b08 8b5108 50 }
+ $sequence_5 = { eb69 8a1402 2ad1 8bfe 80ea13 }
+ $sequence_6 = { 6a00 8d4508 c746140f000000 c7461000000000 }
+ $sequence_7 = { 750c 680e000780 e8???????? 33ff c745fcffffffff }
+ $sequence_8 = { 80ea04 b904000000 eb23 8b5508 397d1c 7303 }
+ $sequence_9 = { 85c0 52 0f95c3 ffd6 }
+ $sequence_10 = { 2ad1 8bfe 80ea04 b901000000 e9???????? }
+ $sequence_11 = { 40 3b4610 0f82dbfeffff 397d1c }
+ $sequence_12 = { 83c40c 8d8de8fdffff 51 53 53 }
+ $sequence_13 = { 8b4e10 397e14 7211 8a1402 8b3e }
+ $sequence_14 = { 894608 8945fc 56 c745f001000000 }
+ $sequence_15 = { 8bcf e8???????? 8b0e 8b5104 8b443238 }
+ $sequence_16 = { 53 50 e8???????? 83c40c 8d8de8fdffff }
+ $sequence_17 = { 7303 8d5508 8b4e10 397e14 7214 }
+ $sequence_18 = { 8bfe 8a1402 2ad1 80ea13 33c9 881407 }
+ $sequence_19 = { 8b4c3138 33db 895de8 885def 8975e0 }
+ $sequence_20 = { 807def00 8b5de8 7503 83cb02 8b16 8b4a04 }
+ $sequence_21 = { c0ea02 8ac4 80e20f c0e004 }
+ $sequence_22 = { 8b07 eb02 8bc7 8b4de0 }
+ $sequence_23 = { 8b4c1938 895dd4 85c9 7405 8b01 ff5004 c745fc00000000 }
+ $sequence_24 = { 8b85c4f5ffff 50 e8???????? 83c404 8d95c0f5ffff 33c9 52 }
+ $sequence_25 = { 8bcc 8975f4 50 e8???????? ff7510 8d4dd4 }
+ $sequence_26 = { 762a 8b4d08 8b5108 8a8210a04600 2c01 8845ff 8b4d08 }
+ $sequence_27 = { 68???????? ff15???????? 3bf4 e8???????? 8bf4 8b4594 50 }
+ $sequence_28 = { b9???????? e8???????? 51 8d8d90bcf0ff }
+ $sequence_29 = { 6bf630 8b0c8d60cb4300 80643128fd 5f }
+ $sequence_30 = { 8bec 8b4508 8bc8 83e01f c1f905 8b0c8da0244300 }
+ $sequence_31 = { 83e61f 8d3c8da0244300 8b0f c1e606 833c0eff 7535 833d????????01 }
+ $sequence_32 = { c745e401000000 e9???????? c745e000000000 8b15???????? a1???????? 01d0 }
+ $sequence_33 = { ff15???????? 85c0 0f85e3020000 68???????? 50 50 ff15???????? }
+ $sequence_34 = { 8b4804 8d4190 89840df0b8f0ff 8d8d04b9f0ff e8???????? 8b85f4b8f0ff 8b4004 }
+ $sequence_35 = { 0f851f040000 8d853cfeffff 83c01c 890424 }
+ $sequence_36 = { 8b4d0c 83e13f 6bd130 8b048500b04600 }
+ $sequence_37 = { 3bf4 e8???????? 8bf4 8b8574fcffff 50 ff15???????? 3bf4 }
+ $sequence_38 = { 01ca 0fb612 89d1 8b550c 01ca 8810 }
+ $sequence_39 = { 740c c785d4ddffffac084500 eb0a c785d4ddffffd4d44400 8b85a4ddffff 50 }
+ $sequence_40 = { 8b4508 890424 e8???????? 8945d8 837dd800 0f847a050000 }
+ $sequence_41 = { e8???????? c78562feffff00000000 8d8566feffff b960000000 bb00000000 }
+ $sequence_42 = { 8d8da8efffff e8???????? 50 8d8dd0efffff e8???????? 8d8da8efffff e9???????? }
+ $sequence_43 = { e8???????? 83ec0c 8d8ddcfbffff 0f1000 0f1105???????? f30f7e4010 }
+ $sequence_44 = { f3ab c745f800000000 c745d400000000 8b450c }
+ $sequence_45 = { e8???????? c78324020000ffffffff c78328020000ffffffff 83c414 5b }
+ $sequence_46 = { 56 53 83ec14 8b5c2420 e8???????? 85db c70000000000 }
+ $sequence_47 = { e9???????? 8975e4 33c0 39b880f94200 }
+ $sequence_48 = { 750c c785bcddffff60084500 eb0a c785bcddffffd4d44400 b802000000 }
+ $sequence_49 = { 83e63f c1ff06 6bf630 8b04bd60cb4300 f644302880 741f e8???????? }
+ $sequence_50 = { 8d15f0224100 e8???????? 58 5a }
+ $sequence_51 = { 83e826 89c2 a1???????? c744240800000000 89542404 890424 e8???????? }
+ $sequence_52 = { 0f87b1030000 ff24bd41574200 8b41e4 3b42e4 7478 0fb642e4 0fb671e4 }
+ $sequence_53 = { 57 897de8 ff15???????? 8bd0 8955ec c645fc01 c746140f000000 }
+ $sequence_54 = { c745dc03000000 eb7c c745e088044300 ebbb d9e8 }
condition:
- 7 of them and filesize <548864
+ 7 of them and filesize <1097728
}
-rule MALPEDIA_Win_Avaddon_Auto : FILE
+rule MALPEDIA_Win_Mbrlock_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "63f23353-9bc4-58e9-928a-ae89a2672871"
+ id = "daa9848d-eee7-57fa-b29b-86c1367b5691"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avaddon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avaddon_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mbrlock"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mbrlock_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "a18db52df950b60c5b6d6008b561a4d13093802e02b6d570e4f6e8e4ed4f56e8"
+ logic_hash = "7a0dcc0e30832e7304006fa42a5eab963221d66f36bad91605b77fec2d75b555"
score = 75
quality = 75
tags = "FILE"
@@ -165689,32 +172971,32 @@ rule MALPEDIA_Win_Avaddon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 55 8bec 83e4f8 8b11 83ec14 0faf5104 53 }
- $sequence_1 = { 52 50 e8???????? 8bf0 8bfa 8b4508 03f3 }
- $sequence_2 = { 8d4dcc e9???????? 8d4d88 e9???????? 8d4db4 e9???????? 8d4de4 }
- $sequence_3 = { 8b4df0 e9???????? 8d4dbc e9???????? 8b542408 8d420c 8b4ac0 }
- $sequence_4 = { 57 56 e8???????? 83c408 85c0 7535 837e6402 }
- $sequence_5 = { 8bd0 e8???????? 8b5604 83c404 }
- $sequence_6 = { ff75b4 e8???????? 83c408 47 897dac 81fffe000000 0f8654feffff }
- $sequence_7 = { 8bc8 2bce 0fafcb 890a 83c204 8b4de4 41 }
- $sequence_8 = { 034b08 4e 8b4588 6a00 52 51 56 }
- $sequence_9 = { 8d4dd8 e8???????? c645fc0d 8b4f14 3b4f18 7437 c7411000000000 }
+ $sequence_0 = { 898e94000000 8945e4 e9???????? 8b5d10 8b7d14 8b4e0c }
+ $sequence_1 = { 8bcb bd01000000 e8???????? 8bf0 85f6 0f84f8000000 85ed }
+ $sequence_2 = { 8b4de8 8bc1 25ffff0000 2d4c450000 7475 83e802 7433 }
+ $sequence_3 = { e8???????? 8b45ec 3d00800000 74ab 8b450c 8d5594 }
+ $sequence_4 = { 894e30 50 53 8bcf e8???????? 85c0 7505 }
+ $sequence_5 = { e8???????? 8bd0 85d2 7424 817f1402000080 7519 8b470c }
+ $sequence_6 = { 8bcf e8???????? 8b4d08 894144 8b45ec 85c0 7505 }
+ $sequence_7 = { 33d2 8bd9 668b144590844a00 8b4c2430 8954242c 8bc1 be02000000 }
+ $sequence_8 = { 68ac5e0110 56 50 53 8bcf e8???????? }
+ $sequence_9 = { a3???????? 39a81c010000 7405 8b4010 eb02 33c0 ffd0 }
condition:
- 7 of them and filesize <2343936
+ 7 of them and filesize <2031616
}
-rule MALPEDIA_Win_Dharma_Auto : FILE
+rule MALPEDIA_Win_Hacksfase_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e57e8a97-3ba4-55fc-8a7a-2d2cd02d04a4"
+ id = "efd0a25a-4cca-56d9-81da-25a62e74a476"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dharma"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dharma_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hacksfase"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hacksfase_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "7cad44063f19785eb5f21218749fc586efdec21afeaf1b9147edb5d8331036bc"
+ logic_hash = "cb98da9c56e02049453f68129b331881a66f9a471f383d0aefdbab19d12d9c15"
score = 75
quality = 75
tags = "FILE"
@@ -165728,34 +173010,34 @@ rule MALPEDIA_Win_Dharma_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945e8 8b45ec 8b4808 8b55ec }
- $sequence_1 = { 8b4824 8b5508 8b4218 8d0c48 51 68ff7f0000 }
- $sequence_2 = { 68???????? 6a00 6a00 e8???????? eb0e 8b4dfc 51 }
- $sequence_3 = { 8b45e4 034530 8945e4 8b4dfc 034d30 894dfc 6a06 }
- $sequence_4 = { a1???????? 898574ffffff 6880000000 68???????? 8b8d74ffffff 51 68???????? }
- $sequence_5 = { 8945fc 8b4d08 0fb711 d1fa 8955e0 8b45f8 c1e818 }
- $sequence_6 = { 741a 8b5508 83c22c 8b4dfc 8b8108000100 }
- $sequence_7 = { 8b0c85b8bf4000 81e10000ff00 33d1 8b45f4 }
- $sequence_8 = { d1f8 8d4c0002 51 e8???????? 83c404 8b55ec 8b4a08 }
- $sequence_9 = { 8b55f4 83c201 8955f4 eba3 8b45f8 50 e8???????? }
+ $sequence_0 = { 81ec1c080000 53 55 56 57 6a1c 32db }
+ $sequence_1 = { 897ddc 8b45d0 03c0 8945d0 8d4dd0 51 }
+ $sequence_2 = { 53 51 ff7628 895dbc 895dc4 895dc0 895dc8 }
+ $sequence_3 = { 895008 8b4120 8b5508 895020 8b4120 }
+ $sequence_4 = { 85c0 7509 b908000000 8bfb }
+ $sequence_5 = { a806 746c b9???????? c78424bc02000003000000 c78424c002000002000000 c78424c4020000ffffffff c78424b802000010000000 }
+ $sequence_6 = { ffd6 85c0 740a 33c0 5e 81c490010000 }
+ $sequence_7 = { 83ec18 8b4120 56 33f6 }
+ $sequence_8 = { 89842418040000 e8???????? b9???????? e8???????? }
+ $sequence_9 = { ff75f0 ffd7 6a18 e8???????? }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Bandook_Auto : FILE
+rule MALPEDIA_Win_Zloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "facf6ec8-b33d-5307-a31b-1f1e19226ca5"
+ id = "97b40e53-0323-5f57-82eb-14236d63ac31"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bandook"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bandook_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zloader_auto.yar#L1-L384"
license_url = "N/A"
- logic_hash = "d695c77bc8945b310c81d69b92952d60e6bda737f194777e74e4b6ebb23f8272"
+ logic_hash = "d615cfd8aec428fea853159c669b5f75c64755d955e56d958f0ce28518a00d78"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -165767,32 +173049,62 @@ rule MALPEDIA_Win_Bandook_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? ffd6 68???????? 6a01 6a00 ff15???????? 68e8030000 }
- $sequence_1 = { 8b7c2410 8d442438 50 53 ff15???????? 85c0 0f8529ffffff }
- $sequence_2 = { 8d95f8f3ffff 8bce 2bd6 0f1f00 8a01 8d4901 }
- $sequence_3 = { ff15???????? ff35???????? ff15???????? 68???????? 68???????? 8d8424a8010000 68???????? }
- $sequence_4 = { 8bf9 897da0 8b7308 8d4dbc 897d9c 6a24 68???????? }
- $sequence_5 = { 83e103 f3a4 8d442428 50 53 ff15???????? 85c0 }
- $sequence_6 = { 51 e8???????? 83c408 837dbc10 8d45a8 0f4345a8 50 }
- $sequence_7 = { 88811744c213 84c0 75ed 0fb605???????? f30f7e05???????? a2???????? a1???????? }
- $sequence_8 = { c705????????80381713 c705????????003a1713 c705????????c03f1713 c705????????80401713 c705????????c0491713 c705????????704b1713 c705????????30451713 }
- $sequence_9 = { 83c40c 8d842498040000 6a64 50 6a07 6800040000 ff15???????? }
+ $sequence_0 = { 57 6a01 56 ffd0 89f7 89f8 }
+ $sequence_1 = { 57 56 83ec0c 8b5d0c 8b7d10 8d75e8 89f1 }
+ $sequence_2 = { 55 89e5 56 8b7508 ff36 e8???????? 83c404 }
+ $sequence_3 = { 0fb7450c 8d9df0feffff 53 50 ff7508 e8???????? }
+ $sequence_4 = { 57 56 8b7d08 57 e8???????? }
+ $sequence_5 = { 0fb7c0 57 50 53 e8???????? 83c40c 89f1 }
+ $sequence_6 = { 53 56 83ec0c 8d75ec 56 6aff }
+ $sequence_7 = { 55 89e5 56 8b750c ff7508 e8???????? 83c404 }
+ $sequence_8 = { 56 50 a1???????? 89c1 }
+ $sequence_9 = { 5e 8bc3 5b c3 8b44240c }
+ $sequence_10 = { 68???????? ff742408 e8???????? 59 59 84c0 741e }
+ $sequence_11 = { e8???????? 59 84c0 7432 68???????? ff742408 e8???????? }
+ $sequence_12 = { 57 56 50 8b4510 31db }
+ $sequence_13 = { e8???????? 03c0 6689442438 8b442438 }
+ $sequence_14 = { 6aff 50 e8???????? 8d857cffffff 50 }
+ $sequence_15 = { 50 89542444 e8???????? 03c0 }
+ $sequence_16 = { 6689442438 8b442438 83c002 668944243a }
+ $sequence_17 = { 83c414 c3 56 ff742410 }
+ $sequence_18 = { 99 52 50 8d44243c 99 52 50 }
+ $sequence_19 = { c6043000 5e c3 56 57 8b7c2414 83ffff }
+ $sequence_20 = { 50 56 56 56 ff7514 }
+ $sequence_21 = { 83c408 5e 5d c3 55 89e5 57 }
+ $sequence_22 = { 6a00 e8???????? 83c414 c3 8b542404 }
+ $sequence_23 = { c7462401000000 c7462800004001 e8???????? 89460c }
+ $sequence_24 = { 81c4a8020000 5e 5f 5b }
+ $sequence_25 = { 55 89e5 53 57 56 81eca8020000 }
+ $sequence_26 = { e9???????? 31c0 83c40c 5e 5f }
+ $sequence_27 = { 0bc3 a3???????? e8???????? 8bc8 eb06 8b0d???????? 85c9 }
+ $sequence_28 = { 89b42430010000 8b842430010000 8b842430010000 890424 c74424041c010000 e8???????? }
+ $sequence_29 = { 89cf 8d0476 8945ec 890424 }
+ $sequence_30 = { 50 6a72 e8???????? 59 }
+ $sequence_31 = { 56 57 ff750c 33db 68???????? 6880000000 50 }
+ $sequence_32 = { 8bc2 ebf7 8d442410 50 ff742410 ff742410 ff742410 }
+ $sequence_33 = { 56 68???????? ff742410 e8???????? 6823af2930 56 ff742410 }
+ $sequence_34 = { 50 e8???????? 68???????? 56 e8???????? 8bf0 59 }
+ $sequence_35 = { 5f 5e 5b c3 8bc2 ebf8 53 }
+ $sequence_36 = { 33f6 e8???????? ff7508 8d85f0fdffff 68???????? }
+ $sequence_37 = { 68???????? 56 e8???????? 5e c3 56 }
+ $sequence_38 = { 8d85f0fdffff 68???????? 6804010000 50 e8???????? 83c414 8d45fc }
+ $sequence_39 = { 8bc2 ebf8 53 8b5c240c 55 33ed }
condition:
- 7 of them and filesize <23088128
+ 7 of them and filesize <1105920
}
-rule MALPEDIA_Win_Getmail_Auto : FILE
+rule MALPEDIA_Win_Spora_Ransom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "44034b05-2864-56ad-b1e2-ce75dcdcb73e"
+ id = "8b8ba74c-729e-5b95-8216-285cfd8906d9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.getmail"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.getmail_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spora_ransom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spora_ransom_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "cb48fd93bd0d8eb21e02a5c1c72974fd0280a8132ab759131eea2bb4b2c53aaf"
+ logic_hash = "4f4859e5c4c90863719bd127457464f7d14cd9fd2e5234c00f8157e8748b1142"
score = 75
quality = 75
tags = "FILE"
@@ -165806,34 +173118,34 @@ rule MALPEDIA_Win_Getmail_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 896c2460 e8???????? 8d4c2420 8d9424cc000000 51 8d8424a8000000 52 }
- $sequence_1 = { c68424d000000004 8b040a 813803000930 7508 8b5808 d1eb 80e301 }
- $sequence_2 = { 55 ffd7 68???????? 55 a3???????? ffd7 8b0d???????? }
- $sequence_3 = { 50 8b10 ff5208 391d???????? 0f84a2000000 a1???????? }
- $sequence_4 = { 0f8285feffff 33db 50 e8???????? 83c404 8b442458 50 }
- $sequence_5 = { c3 57 e8???????? 83c404 3bc5 89432c }
- $sequence_6 = { 83f961 7208 83f97a 7703 83e957 c0e004 }
- $sequence_7 = { 8d8c249c000000 8894249c000000 e8???????? 8a442413 6a00 8d8c24ac000000 c68424d400000005 }
- $sequence_8 = { 8bfe 8b11 2bf8 03c5 57 50 }
- $sequence_9 = { 8b8424d8000000 33db 3bc3 899c24cc000000 7505 b8???????? 8b8c24dc000000 }
+ $sequence_0 = { 6a3a 8d4641 668945f0 58 ff7510 668945f2 ff750c }
+ $sequence_1 = { f6c301 742c 6a3a 8d4641 668945f0 58 ff7510 }
+ $sequence_2 = { 897df4 85ff 747a 834d08ff }
+ $sequence_3 = { 834d08ff 8d45f8 50 57 8d4508 50 }
+ $sequence_4 = { 8d4641 668945f0 58 ff7510 668945f2 ff750c 33c0 }
+ $sequence_5 = { 33c0 668945f4 8d45f0 50 ff15???????? 50 8d45f0 }
+ $sequence_6 = { 0fb600 48 50 ff36 ff15???????? 85c0 }
+ $sequence_7 = { c745c800040000 33f6 8d45c4 50 ff15???????? 85c0 750e }
+ $sequence_8 = { 50 ff15???????? 85c0 7466 56 57 bf00020000 }
+ $sequence_9 = { 0bf0 57 ff15???????? 5f 8bc6 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Beepservice_Auto : FILE
+rule MALPEDIA_Win_Floxif_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1d7d7c47-2c0e-5f10-8d42-753504cd309b"
+ id = "dcbc6afb-5640-594e-8001-abd00982f671"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.beepservice"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.beepservice_auto.yar#L1-L282"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.floxif"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.floxif_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "1b28ba46a772486fbc8465a9c3e2af5f383317dc6efaca43bb04db774c11995d"
+ logic_hash = "0032adeaefefb80d7e1e935d3a462c453aec0c986c2f0bdf2924a1a8da50b164"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -165845,51 +173157,32 @@ rule MALPEDIA_Win_Beepservice_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd6 8bc8 ff15???????? 50 }
- $sequence_1 = { 8b0d???????? 68???????? ffd6 8bc8 }
- $sequence_2 = { e8???????? 83f801 7505 e8???????? 68???????? 68???????? }
- $sequence_3 = { 7512 6888130000 68???????? e8???????? 83c408 }
- $sequence_4 = { 83c408 e9???????? 68???????? e8???????? 83c404 6a00 }
- $sequence_5 = { 683f000f00 6a00 68???????? ff15???????? }
- $sequence_6 = { ff7604 68???????? e8???????? ff7608 e8???????? 83c40c }
- $sequence_7 = { 83ffff 750e ff15???????? 50 68???????? eb43 }
- $sequence_8 = { 68???????? 57 ff15???????? 85c0 741c 3975fc }
- $sequence_9 = { ff7604 e8???????? 83f814 59 }
- $sequence_10 = { e8???????? 83f820 59 730f ff7618 68???????? e8???????? }
- $sequence_11 = { e8???????? ff7610 e8???????? 50 ff7610 53 e8???????? }
- $sequence_12 = { 83c410 8d4c2408 6a00 6a00 }
- $sequence_13 = { bf???????? a3???????? 83c404 a3???????? a3???????? 66a3???????? f3ab }
- $sequence_14 = { 85c0 742b 817c240400240000 7521 56 }
- $sequence_15 = { ffd7 8d442414 50 56 }
- $sequence_16 = { 8bca 83e103 f3a4 8b7314 83c9ff 8bfe }
- $sequence_17 = { e8???????? 83c404 50 8b4d0c 8b5114 }
- $sequence_18 = { e8???????? 83c408 33c0 e9???????? c785f8fdffff00240000 6a00 8d95f4fdffff }
- $sequence_19 = { 8b0d???????? ff15???????? 8bc8 ff15???????? 8b15???????? 52 }
- $sequence_20 = { 8b511c 52 e8???????? 83c404 83f820 }
- $sequence_21 = { 6a01 6a00 6a00 6a05 e8???????? 83c414 }
- $sequence_22 = { e8???????? 6a00 6a00 b907000000 6a00 }
- $sequence_23 = { c3 68e8030000 6a02 6a00 6a00 6a02 }
- $sequence_24 = { 6a04 e8???????? 83c414 85c0 7510 ff15???????? }
- $sequence_25 = { 50 53 c744241428010000 e8???????? }
- $sequence_26 = { bf???????? 83c9ff 33d2 b301 f2ae f7d1 49 }
- $sequence_27 = { b90a000000 be???????? bf???????? 33c0 f3a5 bf???????? 83c9ff }
- $sequence_28 = { 52 89442424 ff15???????? 8bf0 85f6 7505 }
+ $sequence_0 = { e8???????? 8945fc 837dfc02 7709 c745f401000000 eb09 8b45fc }
+ $sequence_1 = { 3955f4 0f83c9000000 68???????? e8???????? }
+ $sequence_2 = { 8b55fc c70200000000 8b45fc c7401000000000 8b45fc 8be5 }
+ $sequence_3 = { c645e500 c645e6e1 c645e700 c645e87d c645e973 c645ea7a c645eb30 }
+ $sequence_4 = { c645e500 c645e6bb c645e700 c645e828 c645e92b c645ea23 }
+ $sequence_5 = { 7505 e9???????? 837dd800 7406 837dd805 7502 eb92 }
+ $sequence_6 = { 83ec14 894df8 8b45f8 8b4808 }
+ $sequence_7 = { ebaa 8d4d08 e8???????? 3945fc 7526 8d4d18 e8???????? }
+ $sequence_8 = { 8b55fc 837a0400 7507 e8???????? eb11 8b4dfc e8???????? }
+ $sequence_9 = { e8???????? e8???????? 83c410 eb44 83ec10 8bcc 8d5508 }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <352256
}
-rule MALPEDIA_Win_Mgbot_Auto : FILE
+rule MALPEDIA_Win_Lethic_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dd03dc94-bb3a-5cad-8f13-4bbe4b7f90a6"
+ id = "89881c0c-ddd2-5773-9144-03db6590b3cc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mgbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mgbot_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lethic"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lethic_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "7310ce51cc81391fc78e9881bf8f490b2a783d4789728f7661df3e6bdca512d7"
+ logic_hash = "3125ec39e54752d0947a08a6149f6c0dbb19d9ccd38ebef90b278b6227c3cc5c"
score = 75
quality = 75
tags = "FILE"
@@ -165903,32 +173196,32 @@ rule MALPEDIA_Win_Mgbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6808020000 e8???????? 6804010000 8bf0 6a00 }
- $sequence_1 = { 6808020000 e8???????? 6804010000 8bf0 6a00 56 e8???????? }
- $sequence_2 = { 5b 8be5 5d c20800 6808020000 }
- $sequence_3 = { 6808020000 e8???????? 6804010000 8bf0 6a00 56 }
- $sequence_4 = { 8be5 5d c20800 6808020000 e8???????? }
- $sequence_5 = { 6808020000 e8???????? 6804010000 8bf0 }
- $sequence_6 = { 5d c20800 6808020000 e8???????? }
- $sequence_7 = { 8be5 5d c20800 6808020000 }
- $sequence_8 = { 5b 8be5 5d c20800 6808020000 e8???????? }
- $sequence_9 = { 0f8553ffffff 5f 33c0 5e }
+ $sequence_0 = { 837df400 7507 33c0 e9???????? 8b55f4 8b4218 }
+ $sequence_1 = { 33c0 e9???????? 8b45fc 8b4d10 894804 }
+ $sequence_2 = { 50 8b4dfc 83c108 51 8b55f4 }
+ $sequence_3 = { 8b45fc 8b08 894dfc ebec 8b55fc }
+ $sequence_4 = { eb42 6a10 8b55fc 83c208 52 }
+ $sequence_5 = { ebec 8b55fc 8b45f4 8b08 890a 8b55fc }
+ $sequence_6 = { 8945fc c745f801000000 837dfc00 7507 33c0 e9???????? 8b45fc }
+ $sequence_7 = { 3b55f8 7411 8b45fc c60000 }
+ $sequence_8 = { 8b08 890a 8b55fc 8b02 8945fc 8b4df4 51 }
+ $sequence_9 = { eb42 6a10 8b55fc 83c208 52 8b45fc 8b4818 }
condition:
- 7 of them and filesize <1677312
+ 7 of them and filesize <81920
}
-rule MALPEDIA_Win_Blindingcan_Auto : FILE
+rule MALPEDIA_Win_Unidentified_108_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cb880a40-09fd-57de-a5ce-976bc164d187"
+ id = "91d0ee32-15d3-5f4b-b0c7-e219a3fb056f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blindingcan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blindingcan_auto.yar#L1-L180"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_108"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_108_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "7d6669fb427721c8bcc6cd766a15275abac3a422e034ffec946a676b43de9099"
+ logic_hash = "bc8d7e8276cd214c62a44b786052de8d0d6c82c70c52e7e29cb797627cab2825"
score = 75
quality = 75
tags = "FILE"
@@ -165942,38 +173235,32 @@ rule MALPEDIA_Win_Blindingcan_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c40c 68???????? 68???????? ff15???????? 689c040000 85c0 }
- $sequence_1 = { 750a 8b10 8994bdfcfdffff 47 83c00c 49 }
- $sequence_2 = { c785bcfdffff661fcba8 c785c0fdffffc0f0d181 c785c4fdffff1f08c3d4 c785c8fdffff28edbc6a c785ccfdffff12aff210 }
- $sequence_3 = { c745e4ef0dfff5 c745e85acd9c1d c745ec36c2f964 c745f0a70d9fae c745f48f2aedf1 }
- $sequence_4 = { c78594feffff657f9183 c78598feffffa78b5b05 c7859cfeffff87f53e0c c785a0feffff074f9b22 }
- $sequence_5 = { c745ac84b1df57 c745b0c8cbfee9 c745b4567e337f c745b8e958e686 }
- $sequence_6 = { c78548feffffdfc2f62c c7854cfeffff17516633 c78550fefffff76c7e7e c78554feffffa14b0c27 c78558feffff10c0aac6 c7855cfeffff489a8471 c78560feffff9cab4ad6 }
- $sequence_7 = { 740c a810 7408 c68435a8fcffff01 46 83fe1a }
- $sequence_8 = { f7fe 8bca e8???????? 85c0 7409 e8???????? }
- $sequence_9 = { 55 4154 4155 488da8e8f3ffff 4881ec000d0000 488b05???????? 4833c4 }
- $sequence_10 = { 8bd5 664489642422 6689442420 895c2428 e8???????? 8bd3 488bcf }
- $sequence_11 = { 85c0 751b e8???????? 4885c0 7461 448bc7 488d55c0 }
- $sequence_12 = { 81e909200000 746e 83e907 745f ffc9 744d ffc9 }
- $sequence_13 = { 410fb6c4 0fb68c2810be0100 41335518 400fb6c6 0fb6842810be0100 c1e108 33c8 }
- $sequence_14 = { 488b4dc8 488d45c0 4c8d4db0 4889442428 488d0552d30100 488d1586340100 4533c0 }
- $sequence_15 = { ff15???????? 4883ceff 4c8be8 4889442440 483bc6 752d ff15???????? }
+ $sequence_0 = { 488d05c7580100 4a8b0ce8 42385cf938 7d4f 400fbece 4084f6 }
+ $sequence_1 = { 0f8493010000 488d2d3a100100 83635000 83632c00 e9???????? 48ff4318 837b2800 }
+ $sequence_2 = { 660feb0d???????? 4c8d0d44950000 f20f5cca f2410f590cc1 660f28d1 660f28c1 4c8d0d0b850000 }
+ $sequence_3 = { 7426 488d5540 803201 488d5201 41ffc0 488d4540 498bcc }
+ $sequence_4 = { 4c8d05a8310100 83e23f 488d14d2 498b04c0 f644d03801 }
+ $sequence_5 = { 488d1dd6db0100 458bc5 498bcc 48ffc1 4438040b 75f7 4885c9 }
+ $sequence_6 = { 458bc5 498bc4 90 48ffc0 44380401 }
+ $sequence_7 = { 0fb6557f 4889451f 83f201 488d05dbc90000 49c1e302 4889452f 03d2 }
+ $sequence_8 = { 488d9588000000 803201 488d5201 41ffc0 488d8588000000 }
+ $sequence_9 = { 7350 488bca 4c8d051d310100 83e13f 488bc2 48c1f806 }
condition:
- 7 of them and filesize <363520
+ 7 of them and filesize <307200
}
-rule MALPEDIA_Win_Wininetloader_Auto : FILE
+rule MALPEDIA_Win_Govrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1f5f1063-d131-51ec-8fa2-72e334bf0ad8"
+ id = "1d47ae50-0c56-5989-81a0-8fdce95f6d20"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wininetloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wininetloader_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.govrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.govrat_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "18fd24bb687ec61c125dfaa2108b7d0deaa39d2f9fd1538d0119b221d934fb42"
+ logic_hash = "fd342f7d8be9492612f2ff02091e469b143bdad77d63d3ee372225f78d66c202"
score = 75
quality = 75
tags = "FILE"
@@ -165987,19 +173274,19 @@ rule MALPEDIA_Win_Wininetloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7510 0fb611 0fb6c2 80fa28 7423 80fa29 741e }
- $sequence_1 = { 4c8bac2480000000 90 493bdf 74db 0fb633 498bcd 410fb61424 }
- $sequence_2 = { 48897c2460 4d8bc5 488b542438 488bc8 e8???????? 4b8d042e 4889442458 }
- $sequence_3 = { 90 488d5508 48837d2008 480f435508 488b4518 4c8d0c42 4c8d4508 }
- $sequence_4 = { e8???????? 3a03 7516 488bcf e8???????? 4c8b45f8 488b4df0 }
- $sequence_5 = { 4c8be0 4889442450 4885db 7427 488b03 488bcb 488b4010 }
- $sequence_6 = { 4c894d08 33db 448bf3 895c2470 49395910 752b 488d15b6ea1100 }
- $sequence_7 = { 3a8c2ab8a80e00 0f8585000000 488b03 48ffc2 8a08 48ffc0 488903 }
- $sequence_8 = { 488d1d48970500 807e5704 7704 488b5e48 48ffc7 803c3b00 75f7 }
- $sequence_9 = { eb21 48c74424200f000000 4c8d0d54fd0900 4533c0 418d500f 488d4c2430 e8???????? }
+ $sequence_0 = { 7725 0fb74002 8d709f 6683fe19 7702 03c2 6685c0 }
+ $sequence_1 = { ff37 e8???????? 894620 85c0 7507 b80e000780 5f }
+ $sequence_2 = { e8???????? 83ec1c 8bf4 8965b4 }
+ $sequence_3 = { e8???????? 6aff 53 8d4db0 51 c645fc06 e8???????? }
+ $sequence_4 = { 837dc808 8b75b4 7303 8d75b4 53 51 68???????? }
+ $sequence_5 = { 8d7c2428 ab ab 7548 8d442464 50 }
+ $sequence_6 = { 0183f0bc0300 8393f4bc030000 e8???????? eb1d 8b45fc 2b45f0 ff75fc }
+ $sequence_7 = { 7311 c70485????????e8814300 40 a3???????? c3 55 8bec }
+ $sequence_8 = { 83ec18 56 8bf1 8b4610 8955f8 8945f4 83f804 }
+ $sequence_9 = { 85f6 7403 832600 837d1000 0f8690000000 8b5d08 }
condition:
- 7 of them and filesize <2659328
+ 7 of them and filesize <761856
}
rule MALPEDIA_Win_Dairy_Auto : FILE
{
@@ -166038,20 +173325,59 @@ rule MALPEDIA_Win_Dairy_Auto : FILE
$sequence_9 = { 81e3ff030080 7908 4b 81cb00fcffff 43 2bc3 33ff }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <212992
+}
+rule MALPEDIA_Win_Mapiget_Auto : FILE
+{
+ meta:
+ description = "autogenerated rule brought to you by yara-signator"
+ author = "Felix Bilstein - yara-signator at cocacoding dot com"
+ id = "51e9978a-f3a2-5a57-b2db-e31705d960d6"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mapiget"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mapiget_auto.yar#L1-L118"
+ license_url = "N/A"
+ logic_hash = "0c633dd4b3de0327e913721fdea6a98365647ad6509020036346423432ca814a"
+ score = 75
+ quality = 75
+ tags = "FILE"
+ version = "1"
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { 773c 33d2 8a9178154000 ff24956c154000 6683780400 }
+ $sequence_1 = { 75f4 8d0c49 5e 8d0c8dd8ea4000 3bc1 }
+ $sequence_2 = { 52 e8???????? 83c404 6683bc456effffff0a 7517 8d8570ffffff }
+ $sequence_3 = { 8d95f0f9ffff 6800020000 52 e8???????? 83c40c 85c0 0f84c1010000 }
+ $sequence_4 = { 741e 8bc7 8bcf c1f805 83e11f 8b048520174100 8d04c8 }
+ $sequence_5 = { e8???????? 8b54240c 83c408 52 }
+ $sequence_6 = { 8d85f0feffff 8d8d70ffffff 50 8d95f0fdffff }
+ $sequence_7 = { 85c0 7520 8d8df0f9ffff 8d95f0fdffff 51 52 }
+ $sequence_8 = { 83c404 3bf7 0f846bfdffff 56 }
+ $sequence_9 = { c705????????0d000000 c3 8b04d5540c4100 a3???????? c3 81f9bc000000 }
+
+ condition:
+ 7 of them and filesize <163840
}
-rule MALPEDIA_Win_Backswap_Auto : FILE
+rule MALPEDIA_Win_Avos_Locker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8b9036c3-1342-5fdd-b202-655dad83c8d1"
+ id = "7ba0a3b7-52b3-54b0-beef-ae9816fdb70a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.backswap"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.backswap_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avos_locker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avos_locker_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "a378488e042d6e06f37e68439e6beddf9b3f11fc0a2449d478058f24368f291d"
+ logic_hash = "20760e04f44624b7366badbec4c361401e8cc12f236ee2efc4fb15277f942fc5"
score = 75
quality = 75
tags = "FILE"
@@ -166065,32 +173391,32 @@ rule MALPEDIA_Win_Backswap_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5f 5a 5b c9 c21000 83f0ff 5e }
- $sequence_1 = { 8b7508 ff4508 8bfb 3bd3 0f8572ffffff 33c9 e9???????? }
- $sequence_2 = { 33d2 8bdf 4b eb1c 85c9 }
- $sequence_3 = { eb1c 85c9 7508 3bdf 7404 }
- $sequence_4 = { ebd4 3c3f 74c4 3c2a 7508 8bdf 897508 }
- $sequence_5 = { f366a5 59 5f 5e c9 c20c00 55 }
- $sequence_6 = { 74ed 33c0 eb04 8bc6 }
- $sequence_7 = { 4b eb1c 85c9 7508 3bdf 7404 8bce }
- $sequence_8 = { 83f0ff 5e 5f 5a 5b }
- $sequence_9 = { 7482 8b7508 ff4508 8bfb 3bd3 0f8572ffffff 33c9 }
+ $sequence_0 = { 8d85a8f9ffff 50 8d85fcf5ffff 50 8d8514f6ffff 50 83ec18 }
+ $sequence_1 = { 8b4024 ffd0 c645fc0a c78598f9ffff00000000 c7859cf9ffff00000000 8b08 898d98f9ffff }
+ $sequence_2 = { 59 3b4580 7359 807d8600 8a8848ef4900 8b857cffffff 8808 }
+ $sequence_3 = { 8d8d05efffff e8???????? 8a8d23f0ffff 8808 46 ebbd 6a22 }
+ $sequence_4 = { 53 50 e8???????? 83c408 c745fcffffffff 57 8b45d8 }
+ $sequence_5 = { 8bd3 3ac1 7501 46 42 8a02 84c0 }
+ $sequence_6 = { c745e800000000 660fd645e4 837de810 8945d4 8b75cc 0f43d0 8b45d0 }
+ $sequence_7 = { 33c5 50 8d45f4 64a300000000 8b4d0c 8b4508 81f900100000 }
+ $sequence_8 = { 8a42ff 84c0 75eb 81fe59ee4ef8 740b 8b7118 85ff }
+ $sequence_9 = { 89958cecffff c645fc35 8bca 8d7102 668b01 83c102 6685c0 }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <1701888
}
-rule MALPEDIA_Win_Comebacker_Auto : FILE
+rule MALPEDIA_Win_Icondown_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "af10d661-f74a-5650-87c7-273e1e7e9537"
+ id = "5fb05a25-c3d8-5c59-95d8-0506e8a3c86e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.comebacker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.comebacker_auto.yar#L1-L159"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.icondown"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.icondown_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "4674cd33cc3ed96f3f2fa7f30959d540c5b651afcce920e84c014122f3c7af23"
+ logic_hash = "0c8c45a1ce9a6284204f7a9a1969d67da5f4271a6aa51c70c6faebd789509deb"
score = 75
quality = 75
tags = "FILE"
@@ -166104,39 +173430,34 @@ rule MALPEDIA_Win_Comebacker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6683f809 7f04 0430 eb02 }
- $sequence_1 = { 4c8d0d7ad60300 8d5049 8d48e0 448d4013 c7442420bb020000 e8???????? }
- $sequence_2 = { 41894704 418bc4 48c1e810 0fb6c8 418bc0 0fb6943170e30400 }
- $sequence_3 = { 4c8d0dc2a10300 8d5078 8d4803 448d4041 }
- $sequence_4 = { 4c8d9db0070000 488d8580020000 4c895c2440 89742438 4489742430 }
- $sequence_5 = { 3241ff 48ffca 88440bff 75ed 488bfe }
- $sequence_6 = { 4c8d0daf4d0300 baca000000 b910000000 e8???????? 488bcf }
- $sequence_7 = { 4c89ac2408290300 664489b5a0050000 e8???????? 488d8d92030000 }
- $sequence_8 = { ff15???????? 83bdc4f8ffff00 741c 68???????? e8???????? 69c0e8030000 83c404 }
- $sequence_9 = { c74424183ba7ca84 c744241c85ae67bb c74424202bf894fe c744242472f36e3c }
- $sequence_10 = { 8a44242a 8b1c8d38640410 8b048538600410 8bca 33c3 }
- $sequence_11 = { 8d1433 52 50 ff15???????? 85c0 0f8435ffffff 8b15???????? }
- $sequence_12 = { 68???????? 52 ffd7 8d85fcf7ffff 83c408 8d5002 668b08 }
- $sequence_13 = { 83f906 0f87c1000000 ff248d302a0210 8b4810 85c9 74d6 8b490c }
- $sequence_14 = { 8b8dacfeffff 51 e8???????? 8b9db0feffff }
+ $sequence_0 = { 89442420 8b471c d1ee 52 50 83e601 }
+ $sequence_1 = { 5f 5e 5d b801000000 5b c20400 8b461c }
+ $sequence_2 = { 3bc5 7c10 5f 5e 5d b8feffffff 5b }
+ $sequence_3 = { 8b461c 85c0 0f8476010000 8b868c000000 }
+ $sequence_4 = { 0fb6da f683c11c450004 7406 8816 46 40 ff01 }
+ $sequence_5 = { b81f85eb51 f7e9 c1fa05 8bca b81f85eb51 c1e91f }
+ $sequence_6 = { 56 8bf1 33db 57 8975f0 895dec c745e8a4ff4300 }
+ $sequence_7 = { e8???????? c7462844d04300 833d????????00 7416 }
+ $sequence_8 = { c3 33c0 5e c3 8b442404 c74050f0b94400 }
+ $sequence_9 = { c745f020d04300 c745e810000000 e8???????? 85c0 7403 }
condition:
- 7 of them and filesize <1429504
+ 7 of them and filesize <5505024
}
-rule MALPEDIA_Win_Colony_Auto : FILE
+rule MALPEDIA_Win_Retro_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2ec04e04-70c5-5f61-acc9-0f96a006c29a"
+ id = "a4751029-21e3-5dc7-8b10-667fe3852f4c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.colony"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.colony_auto.yar#L1-L225"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.retro"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.retro_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "a79879d34246651b7f75532605ca94c4866e5edbca41b238eabaad9f54198dce"
+ logic_hash = "a167f37f4c1b5df11b8ae00c368ae3ba7079a871854da90fb0bcfd20e0f3d7b0"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -166148,87 +173469,73 @@ rule MALPEDIA_Win_Colony_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0118 e9???????? 6a00 6818200000 }
- $sequence_1 = { 0118 e9???????? c745ec00000000 85db }
- $sequence_2 = { 03c1 50 e8???????? 83c40c 8b45f0 }
- $sequence_3 = { 8b421c 2b4218 660f6ec0 f30fe6c0 }
- $sequence_4 = { 8b4214 2b4210 660f6ec0 f30fe6c0 }
- $sequence_5 = { 0101 0101 0101 0202 0202 0200 }
- $sequence_6 = { 69d200008f04 2bc8 c1e910 69c161a4f778 2bd0 }
- $sequence_7 = { 0102 894dec 3bcb 7c85 }
- $sequence_8 = { 7407 b901000000 eb0a 33c9 803f01 0f95c1 33c0 }
- $sequence_9 = { 8b420c 2b4208 660f6ec0 f30fe6c0 }
- $sequence_10 = { 034de8 894604 893e 8930 }
- $sequence_11 = { 740f 0301 eb0b a801 }
- $sequence_12 = { 03f1 ff15???????? 8b0d???????? 53 }
- $sequence_13 = { 03c0 8985bcfbffff 8d85bcfbffff 6a00 }
- $sequence_14 = { 8a4202 8841ff 8b02 c1e808 }
- $sequence_15 = { 660f6e4104 f30fe6c0 84c0 7509 }
- $sequence_16 = { 488d15e5980000 483305???????? 488bcb 488905???????? ff15???????? 488d15e7980000 483305???????? }
- $sequence_17 = { e8???????? 4803db 4c8d3590fc0000 49833cde00 7407 }
- $sequence_18 = { 837b0801 7524 4863c6 488d15551a0100 4533c0 488d0c80 ffc6 }
- $sequence_19 = { 488905???????? ff15???????? 488d15f3980000 483305???????? 488bcb 488905???????? }
- $sequence_20 = { 488d3d0cb8ffff 488bcf e8???????? 85c0 }
- $sequence_21 = { 488d1552fb0000 483950f0 740c 488b10 4885d2 7404 f044010a }
- $sequence_22 = { 0f8c65030000 488d3534ac0000 4883ee60 4585ed 0f843f030000 }
- $sequence_23 = { 3b0d???????? 7367 4863c1 4c8d354acd0000 488bf8 83e01f 48c1ff05 }
+ $sequence_0 = { 49ffcb 8941ec 418b440af0 8941f0 418b440af4 }
+ $sequence_1 = { 8b442420 4863c8 ba04000000 e8???????? 4c8bb42478400000 4c8ba42480400000 488bb42488400000 }
+ $sequence_2 = { 488b742468 488dab00120000 f30f100d???????? 4963c5 448b848308130000 418d4701 410fafc0 }
+ $sequence_3 = { f30f58c2 f30f58c1 f30f58c5 4883c478 c3 660feb15???????? f30f5c15???????? }
+ $sequence_4 = { f3410f1081f8550100 410f2fc0 7604 f30f59e8 8d442eff 4863c8 }
+ $sequence_5 = { 418bd4 e8???????? 33c9 85c0 0f8514010000 4c8d2df2e70300 }
+ $sequence_6 = { f30f59e8 418d4424ff 4863c8 483bcd 7c2e 0f1f00 660f6e0c8b }
+ $sequence_7 = { 4881c460260000 415f 415e 415d 5f 5e 5b }
+ $sequence_8 = { 48c1f905 4c8d05db7f0500 83e21f 486bd258 490314c8 488d0d79700200 eb11 }
+ $sequence_9 = { f20f1035???????? 0f297c2430 0f57ff 33ff 83bab412000002 488bda 4c8bc9 }
condition:
- 7 of them and filesize <7599104
+ 7 of them and filesize <1409024
}
-rule MALPEDIA_Win_Pvzout_Auto : FILE
+rule MALPEDIA_Win_Swen_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bc80d9fe-85e4-55f8-8d8b-08382557b556"
- date = "2023-01-25"
- modified = "2023-01-26"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pvzout"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pvzout_auto.yar#L1-L115"
+ id = "7f9f6459-0c0a-509f-9c87-8a68bae77e34"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.swen"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.swen_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "3b1eb492455f147bf0fe300cd3d173313439f65c62c0ebecede0fab8aacab139"
+ logic_hash = "6a4f1002b8a4868bbe8661a8400f2e2886c507211772c905c6406fbef250b4fb"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20230124"
- malpedia_hash = "2ee0eebba83dce3d019a90519f2f972c0fcf9686"
- malpedia_version = "20230125"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3e3f 19e9 73f8 dca10ebd24e8 252b0026cb }
- $sequence_1 = { 5a bf95f6810e 75a8 43 1dea50873a d4a1 }
- $sequence_2 = { 9c b3d7 5a bf95f6810e 75a8 }
- $sequence_3 = { bbedffffff 03dd 81eb00d00200 83bd8804000000 899d88040000 }
- $sequence_4 = { 3089f33d80f3 48 e21c 3e3f }
- $sequence_5 = { 5d bbedffffff 03dd 81eb00d00200 83bd8804000000 }
- $sequence_6 = { 03dd 81eb00d00200 83bd8804000000 899d88040000 }
- $sequence_7 = { d4a1 0e 75a8 43 }
- $sequence_8 = { 81eb00d00200 83bd8804000000 899d88040000 0f85cb030000 8d8594040000 50 }
- $sequence_9 = { 5a bf95f6810e 75a8 43 1dea50873a d4a1 0e }
+ $sequence_0 = { ab 8d85a8fcffff 50 8d8564fcffff 50 56 56 }
+ $sequence_1 = { 6a05 59 be???????? 8dbd1cfeffff f3a5 66a5 }
+ $sequence_2 = { 68b0040000 ff15???????? c9 c3 55 8bec 6aff }
+ $sequence_3 = { 33c9 85c0 0f95c1 41 890d???????? 8b450c 3905???????? }
+ $sequence_4 = { 59 59 50 8d8594fcffff 50 }
+ $sequence_5 = { 0fbe4602 8d48df 83f951 7408 83c00a 83f85c 755f }
+ $sequence_6 = { 53 6880000000 6a04 53 6a03 6800000040 8d85e4feffff }
+ $sequence_7 = { e8???????? 8d85d8fdffff 50 8d8550ffffff 50 e8???????? 8d4603 }
+ $sequence_8 = { 0f84b2000000 895de0 8b4de4 c1e902 8b45e0 3bc1 0f839e000000 }
+ $sequence_9 = { 3bc3 7410 8d8d80feffff 2bc1 40 40 89857cfeffff }
condition:
- 7 of them and filesize <573440
+ 7 of them and filesize <286720
}
-rule MALPEDIA_Win_Satan_Auto : FILE
+rule MALPEDIA_Win_Lumma_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ddfd46bc-87c6-53ce-9595-be9a6a99e4e0"
+ id = "00d0b80d-1d60-5a8c-ab53-b2e4e4ca8bb2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.satan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.satan_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lumma_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "6170986a4237acbed4cbbf775dbbfb72e2b63776fab2b68ba052c6ad44853238"
+ logic_hash = "5263a9e2f3da4148c4cca89d62ca2919f1c780d4176c9b4897b89aefc59def79"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -166240,32 +173547,35 @@ rule MALPEDIA_Win_Satan_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8be5 5d c20800 8b45e4 c745b800000000 c745bc00000000 }
- $sequence_1 = { 52 ff15???????? 8b4508 8b0c85e8c24700 83e102 740d 8d95e4dfffff }
- $sequence_2 = { ffb5c4e7ffff 8985a0e7ffff ffb5bce7ffff c745ec04000000 }
- $sequence_3 = { 57 50 8d45f4 64a300000000 8d4dd0 e8???????? }
- $sequence_4 = { e8???????? 8b85acfeffff 83f810 7212 40 6a01 }
- $sequence_5 = { eb9b 8b4dfc c1f906 8b55fc 83e23f 6bc230 03048d40e04700 }
- $sequence_6 = { e8???????? 8845dc c745fc01000000 84c0 0f84b3010000 8d45d0 50 }
- $sequence_7 = { 8d0c8584d64700 51 e8???????? 83c408 }
- $sequence_8 = { 64a300000000 68b8000000 8d8598fdffff 6a00 50 e8???????? 68???????? }
- $sequence_9 = { 8b5508 83e23f 6bd230 8b0c8d40e04700 8844112d 8b45ec d1e0 }
+ $sequence_0 = { 57 53 ff767c ff7678 }
+ $sequence_1 = { ffd0 83c40c 894648 85c0 }
+ $sequence_2 = { ff5130 83c410 85c0 7407 }
+ $sequence_3 = { ff7678 ff7644 ff563c 83c414 }
+ $sequence_4 = { ff770c ff37 ff7134 ff5130 }
+ $sequence_5 = { ff7608 ff7044 ff503c 83c414 }
+ $sequence_6 = { 894610 8b461c c1e002 50 }
+ $sequence_7 = { 833800 740a e8???????? 833822 }
+ $sequence_8 = { 83c40c 6a02 6804010000 e8???????? }
+ $sequence_9 = { 017e78 83567c00 017e68 83566c00 }
+ $sequence_10 = { 89e5 8b550c 6bd204 89d1 }
+ $sequence_11 = { 41 5d 41 5b 41 5c }
+ $sequence_12 = { 48 83ec28 0f05 48 83c428 49 }
condition:
- 7 of them and filesize <1163264
+ 7 of them and filesize <1115136
}
-rule MALPEDIA_Win_Dexbia_Auto : FILE
+rule MALPEDIA_Win_Catb_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2a243938-7809-594c-bcba-7fd4f6425c32"
+ id = "515d6ff4-29b8-5f9d-8e4d-ae72db2e24b8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dexbia"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dexbia_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.catb"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.catb_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "13aa7ee33f2f2a26f0806c6fd2186fbe2a0332c45fef215a0c0786ff94a8b62c"
+ logic_hash = "9a8c29b856252443b361ebb50acc406bc1908e5c4eee2fd3c5627837db3c96fd"
score = 75
quality = 75
tags = "FILE"
@@ -166279,32 +173589,32 @@ rule MALPEDIA_Win_Dexbia_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bfd b908000000 be???????? 83c520 83c320 }
- $sequence_1 = { a3???????? e8???????? 8db6ec894000 bf???????? }
- $sequence_2 = { ff15???????? 85c0 740c 8b442414 85c0 742a }
- $sequence_3 = { 5b 81c4e81b0000 c20400 57 ff15???????? b97f000000 33c0 }
- $sequence_4 = { f3a5 8bcb 8d442410 83e103 50 f3a4 68???????? }
- $sequence_5 = { 5e 5d 33c0 5b 81c408100000 c3 68???????? }
- $sequence_6 = { 50 ffd5 a1???????? 85c0 0f841dffffff e8???????? 5f }
- $sequence_7 = { 80e920 ebe0 80a0a09e400000 40 }
- $sequence_8 = { 81c408100000 c3 ff15???????? 6a00 ff15???????? 5f 5e }
- $sequence_9 = { 83c404 8bf0 33c0 89442414 8944241c }
+ $sequence_0 = { 418bcc e8???????? 85c0 0f8484000000 488b442440 488d0d22920300 }
+ $sequence_1 = { 4c8d050e9c0300 83e23f 488bcb 48c1f906 488d14d2 498b0cc8 8064d138fd }
+ $sequence_2 = { 488d159bdc0000 483950f0 740b 488b10 }
+ $sequence_3 = { 4c8d0da47f0000 b903000000 4c8d05907f0000 488d15f9750000 e8???????? 4885c0 740f }
+ $sequence_4 = { 4533c0 488d0d8e0e0400 baa00f0000 e8???????? 85c0 740a ff05???????? }
+ $sequence_5 = { 4c8d0d6bab0300 4c8bc6 488bd7 488bcb e8???????? }
+ $sequence_6 = { 4c8d0d922affff 4c8b4570 8b5568 488b4d60 }
+ $sequence_7 = { 4053 4883ec20 8bd9 4c8d0d05d00000 }
+ $sequence_8 = { 488d0d72190400 e8???????? 488b442438 488905???????? 488d442438 4883c008 }
+ $sequence_9 = { 488bc3 498784f6803c0400 4885c0 7409 }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <593920
}
-rule MALPEDIA_Win_Hacksfase_Auto : FILE
+rule MALPEDIA_Win_Webc2_Ugx_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "efd0a25a-4cca-56d9-81da-25a62e74a476"
+ id = "af26c213-66d2-5675-81ab-6f59f34ddb98"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hacksfase"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hacksfase_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_ugx"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_ugx_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "cb98da9c56e02049453f68129b331881a66f9a471f383d0aefdbab19d12d9c15"
+ logic_hash = "c0369798dbc9b5bf726746a205f3377c225f0e99dd41f08ae5697ccf08cc0c9d"
score = 75
quality = 75
tags = "FILE"
@@ -166318,32 +173628,32 @@ rule MALPEDIA_Win_Hacksfase_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 81ec1c080000 53 55 56 57 6a1c 32db }
- $sequence_1 = { 897ddc 8b45d0 03c0 8945d0 8d4dd0 51 }
- $sequence_2 = { 53 51 ff7628 895dbc 895dc4 895dc0 895dc8 }
- $sequence_3 = { 895008 8b4120 8b5508 895020 8b4120 }
- $sequence_4 = { 85c0 7509 b908000000 8bfb }
- $sequence_5 = { a806 746c b9???????? c78424bc02000003000000 c78424c002000002000000 c78424c4020000ffffffff c78424b802000010000000 }
- $sequence_6 = { ffd6 85c0 740a 33c0 5e 81c490010000 }
- $sequence_7 = { 83ec18 8b4120 56 33f6 }
- $sequence_8 = { 89842418040000 e8???????? b9???????? e8???????? }
- $sequence_9 = { ff75f0 ffd7 6a18 e8???????? }
+ $sequence_0 = { 8d458c 895dec 50 8d8568ffffff 50 }
+ $sequence_1 = { 59 745e 8d4640 50 ff750c ffd3 59 }
+ $sequence_2 = { 50 ff15???????? 85c0 7455 8d85a8feffff 53 50 }
+ $sequence_3 = { ff9698060000 8bf8 85ff 0f84b5000000 8d866e0c0000 50 57 }
+ $sequence_4 = { 8d85a8feffff 68???????? 50 ffd6 }
+ $sequence_5 = { 50 ff55fc 8bc3 eb48 ff15???????? 56 }
+ $sequence_6 = { 8d8584fdffff 50 ff55bc 50 8d8584fdffff 50 }
+ $sequence_7 = { 8d8584f9ffff 57 50 ff55f0 }
+ $sequence_8 = { ff5508 ff7510 e9???????? 53 }
+ $sequence_9 = { 8d85a8feffff 68???????? 50 ffd6 8d85a8feffff 68???????? 50 }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Nightsky_Auto : FILE
+rule MALPEDIA_Win_Prilex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8aa7bf90-2e66-55fa-ac44-1eeed72fb6ec"
+ id = "33d37f97-5d7f-5370-b6c1-4299d7c65706"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nightsky"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nightsky_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.prilex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.prilex_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "e63cd2d4ab9373a42087ae988b3e3adac99eadab50dc02b0732a77e7f3626d28"
+ logic_hash = "3845b326ac2cf1def622498895bf69526e3d4fb73889990b08fc4c5071c0498b"
score = 75
quality = 75
tags = "FILE"
@@ -166357,32 +173667,32 @@ rule MALPEDIA_Win_Nightsky_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 420fb68c1210ab0400 c1e108 0bc8 420fb6841212ab0400 }
- $sequence_1 = { 4150 4d0fabe0 66442bc5 311424 6641d3e0 4158 4863d2 }
- $sequence_2 = { 4883ec48 488364243000 8364242800 41b803000000 488d0dc0460000 4533c9 ba00000040 }
- $sequence_3 = { 5f c3 488d05cf110000 48b90000000000000080 488987c8000000 488d0557990200 }
- $sequence_4 = { e8???????? 488d15d92c0100 41b804010000 33c9 c605????????00 ff15???????? }
- $sequence_5 = { 488d15d4be0000 41b898000000 498bd9 e8???????? 488b8424d0050000 488b9424e8050000 }
- $sequence_6 = { e41d 1a5b5f a9b7f95f5f b8cbaa75cc d113 0ae4 }
- $sequence_7 = { 0f8c96000000 3b1d???????? 0f838a000000 488bf3 4c8be3 49c1fc05 4c8d2d7e190100 }
- $sequence_8 = { 488d0d0fda0000 480f45cf 48894b48 e8???????? eb17 4885ff 488d0dead90000 }
- $sequence_9 = { 4883ec28 4c8bc1 4c8d0d52bbfdff 498bc9 }
+ $sequence_0 = { 8be8 ffd7 8d442410 8d4c2414 }
+ $sequence_1 = { 8b0f 51 ff15???????? 8945e4 68???????? }
+ $sequence_2 = { 8d442424 6a0c 8b11 50 52 56 }
+ $sequence_3 = { e8???????? 5d 8d4c2420 8d542414 51 }
+ $sequence_4 = { ff15???????? c745fc02000000 8b4510 33c9 833800 0f95c1 }
+ $sequence_5 = { 8d858cfdffff 52 8d8d9cfdffff 50 51 }
+ $sequence_6 = { 83c104 898d24ffffff c7851cffffff03400000 8d951cffffff 52 8d458c 50 }
+ $sequence_7 = { 8d8dacfdffff 68???????? 52 898d54fdffff c7854cfdffff08400000 }
+ $sequence_8 = { e8???????? 8bf0 ff15???????? 8d45ac }
+ $sequence_9 = { ffd6 50 8d4da0 68???????? 51 ffd6 }
condition:
- 7 of them and filesize <19536896
+ 7 of them and filesize <450560
}
-rule MALPEDIA_Win_Mimic_Auto : FILE
+rule MALPEDIA_Win_Bitsran_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "868573b4-62fd-5cb9-b5b2-294037fc58d9"
+ id = "e3cfbc68-7ec2-5ca7-89d3-b794638917c8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mimic"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mimic_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bitsran"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bitsran_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "254f11d4299c867206c2f429f422756a353d8d6c35de138faa70cb17074bdf11"
+ logic_hash = "2919e184e2a9722abe679cf353ecc217eb2b7fdd010f4e63772073cd0ac5e798"
score = 75
quality = 75
tags = "FILE"
@@ -166396,34 +173706,34 @@ rule MALPEDIA_Win_Mimic_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7f4a 7c05 3945e0 7343 8b55dc 83fa08 0f82b4000000 }
- $sequence_1 = { 81fe2c010000 7f1d 68e8030000 ffd7 ffd3 85c0 74dd }
- $sequence_2 = { 837db810 51 0f4345a4 8d4d84 03c2 50 e8???????? }
- $sequence_3 = { a3???????? 8b8548feffff 894804 8d8d30feffff e8???????? 6a20 ffb530feffff }
- $sequence_4 = { 0f43c2 0f43da 8d0470 8db5ccfdffff 8bc8 0f43f2 33ff }
- $sequence_5 = { 42 41 3bd6 7cf4 3bd6 751f 6a61 }
- $sequence_6 = { c745fc02000000 a801 743a 83e0fe 894584 83ff08 }
- $sequence_7 = { 50 ffd6 68???????? c645fc40 e8???????? }
- $sequence_8 = { 8d8d18ffffff e9???????? 8d4dc0 e9???????? 8d4dd8 e9???????? 8b542408 }
- $sequence_9 = { 8b483c 898424e4000000 89ac24e0000000 894c2438 0f1f4000 0f1f840000000000 8bb424fc010000 }
+ $sequence_0 = { 85c0 7433 56 57 8bbdf8bfffff c1ef02 }
+ $sequence_1 = { 8911 8b0d???????? 8b9d58fdffff eb5e 8b35???????? }
+ $sequence_2 = { 85f6 7417 8b4508 50 }
+ $sequence_3 = { 50 53 e8???????? 8b9d44fdffff 83ef04 }
+ $sequence_4 = { 83c408 85c0 7403 8975fc 8b03 8d55b8 52 }
+ $sequence_5 = { 742b 8bc1 2bc1 c1f802 8d348500000000 }
+ $sequence_6 = { 8b04c5046f4100 5d c3 8bff }
+ $sequence_7 = { 8d95d4fbffff 52 53 ff15???????? 837d1401 7407 }
+ $sequence_8 = { 2bc3 c1f802 3dfeffff3f 0f87d0010000 8bca 2bcb }
+ $sequence_9 = { 899d58fdffff 3bd9 0f83fe000000 3bd3 0f87f6000000 8b35???????? 2bda }
condition:
- 7 of them and filesize <4204544
+ 7 of them and filesize <344064
}
-rule MALPEDIA_Win_Virut_Auto : FILE
+rule MALPEDIA_Win_Stuxnet_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d1cda5ac-7426-54df-b118-5de8978eea9c"
+ id = "e84f453f-688f-5279-9168-a0cb915408b7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.virut"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.virut_auto.yar#L1-L166"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stuxnet"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stuxnet_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "2bad431ccdf4fab7d1de984be24a8fafd07e087427bb72238bd9b56468720628"
+ logic_hash = "9f5d56947917572e8a9b84c0e49b11ae5a34a590900f3243fcc05249be23cf0d"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -166435,38 +173745,32 @@ rule MALPEDIA_Win_Virut_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89442418 3bc3 0f8441020000 6801040000 8d8424fc050000 53 50 }
- $sequence_1 = { 33f6 8bca 83c107 3bcb 7e1b }
- $sequence_2 = { 0f8402010000 803f4d 0f85f9000000 807f015a }
- $sequence_3 = { 6a00 59 e30a 6a0a }
- $sequence_4 = { ff74241c 6a40 ff15???????? 8bf8 33c0 3bf3 }
- $sequence_5 = { 8bf0 3bf3 0f8e82000000 ff74240c 57 56 }
- $sequence_6 = { 51 6800040000 8d8c2404060000 51 89442428 }
- $sequence_7 = { 8bcb f3a6 61 7405 }
- $sequence_8 = { 8bd4 6a00 52 ff32 }
- $sequence_9 = { 33d2 8bcf 52 f6d9 52 83e103 6a40 }
- $sequence_10 = { 6800030084 51 51 56 }
- $sequence_11 = { 49 4e 45 54 2e44 4c }
- $sequence_12 = { 53 8d442444 50 8d8424e0020000 50 ffd6 }
- $sequence_13 = { eb49 395c240c 7449 33c0 395c240c 7e24 }
- $sequence_14 = { 6a10 59 f3ab 50 50 }
- $sequence_15 = { 66ab 8d4704 ab 32e4 ac }
+ $sequence_0 = { e8???????? 8b5dec 8b45f0 895df4 8945f8 ff770c 8d75ec }
+ $sequence_1 = { c20400 b8???????? e8???????? 51 6a08 e8???????? 59 }
+ $sequence_2 = { e8???????? 33db 895dfc 53 8d45d8 50 6802000080 }
+ $sequence_3 = { 6aff 68???????? 64a100000000 50 64892500000000 83ec64 8d442420 }
+ $sequence_4 = { eb02 33f6 c645fc00 8b4f1c 3bf1 740a 85c9 }
+ $sequence_5 = { 837df008 8b45dc 7303 8d45dc 50 8d431c e8???????? }
+ $sequence_6 = { c706???????? e8???????? c645fc01 c6462400 834dfcff 8b4df4 8bc6 }
+ $sequence_7 = { a5 50 a5 ff5130 85c0 7cb0 8b9b48080000 }
+ $sequence_8 = { ff750c ff7510 8d45e4 50 e8???????? c645fc01 8d4def }
+ $sequence_9 = { ff7508 8d4df4 e8???????? 837d14ff 7d04 33c0 eb12 }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <2495488
}
-rule MALPEDIA_Win_Fusiondrive_Auto : FILE
+rule MALPEDIA_Win_Koadic_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d735e520-5418-5676-9517-95f81cfe7607"
+ id = "e207fda4-6d66-54cd-bdbd-2bc35fe49343"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fusiondrive"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fusiondrive_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.koadic"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.koadic_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "b988107dd8630d41b8dbc9f6aa013be888aa54392baf79daf500a205d72bf5ae"
+ logic_hash = "4723d27185eb97d6e28808abd0dca69a0777b4b3cb3951837b42f0c81d537f3d"
score = 75
quality = 75
tags = "FILE"
@@ -166480,32 +173784,32 @@ rule MALPEDIA_Win_Fusiondrive_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 48898620020000 0fb7c0 66f3ab 488d3d501c0100 482bfe 8a041f }
- $sequence_1 = { 0f846f010000 660f6f05???????? f30f7f442470 66c745806557 c6458200 488d542470 488bc8 }
- $sequence_2 = { 7735 488bd1 4983ff08 7203 }
- $sequence_3 = { 4c8d4c2440 4983fd08 4d0f43cf 488d7c2420 4983fc08 490f43fa 4c8b5c2450 }
- $sequence_4 = { 4863c9 4c8d0514070100 488bc1 83e13f 48c1f806 488d14c9 498b04c0 }
- $sequence_5 = { 0fb60a 83e10f 4c8d05f899ffff 4a0fbe8401a8150100 }
- $sequence_6 = { 488b542450 488bc8 488902 488b5310 ff15???????? 33c0 }
- $sequence_7 = { ff15???????? 8d0c4501000000 4103cf 458d7c2402 418bd7 }
- $sequence_8 = { ff15???????? 3db7000000 0f8432060000 33ff 8bcf }
- $sequence_9 = { 7528 48897df7 48c745ff07000000 66897de7 }
+ $sequence_0 = { 0f84b4020000 53 56 57 8b7c2424 bb01000000 83ffff }
+ $sequence_1 = { 035c2408 53 58 e8???????? a3???????? 8b5c2414 035c2408 }
+ $sequence_2 = { 83fb01 0f8da9000000 8b542404 ff35???????? e8???????? 8b15???????? }
+ $sequence_3 = { 50 8d4c2420 51 e8???????? e9???????? 6a08 }
+ $sequence_4 = { 3b1c24 7527 8b15???????? ff35???????? e8???????? 8d05c8334100 50 }
+ $sequence_5 = { 72f1 eb07 8b34c5c4124100 8bc6 8d5001 }
+ $sequence_6 = { 7507 c7450c02104100 53 56 8b7508 f6462c01 57 }
+ $sequence_7 = { 50 68???????? ff35???????? e8???????? 21c0 7414 ff35???????? }
+ $sequence_8 = { e8???????? 890424 6800000000 e8???????? a3???????? ff35???????? ff742404 }
+ $sequence_9 = { ff15???????? 8b542434 81c200000800 89542428 eb04 8b5c2414 8b442434 }
condition:
- 7 of them and filesize <290816
+ 7 of them and filesize <180224
}
-rule MALPEDIA_Win_Underminer_Ek_Auto : FILE
+rule MALPEDIA_Win_Saigon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2ed43350-f854-5062-8561-cad10f7ea1be"
+ id = "a473943a-8ea5-58ac-80e3-98de6dfb8169"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.underminer_ek"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.underminer_ek_auto.yar#L1-L176"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.saigon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.saigon_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "39ca462c5e03509c03f5a77251b93a3d7053742d5a8b5f784c7649f495781800"
+ logic_hash = "a5d9048555d265aef66c2410783198e6f4dd9139107e5b71b76341530d3b556c"
score = 75
quality = 75
tags = "FILE"
@@ -166519,40 +173823,34 @@ rule MALPEDIA_Win_Underminer_Ek_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68d040fa7e 687853fa7e ff742418 ffd0 85c0 }
- $sequence_1 = { 684c52fa7e 53 ff15???????? 8bf8 85ff 7476 }
- $sequence_2 = { 1bc0 23c1 83c008 5d c3 8b04c5e48f4200 5d }
- $sequence_3 = { 884d17 0f8482000000 f6451701 7445 8b4d10 }
- $sequence_4 = { 68e452fa7e 53 e8???????? 68ef030000 8d4311 68d233fa7e 50 }
- $sequence_5 = { 51 e8???????? 83c408 8b55dc c745f000000000 }
- $sequence_6 = { 8b49fc 83c223 2bc1 83c0fc 83f81f 0f87b0130000 52 }
- $sequence_7 = { f30f7e4110 660fd645f0 c7411000000000 c741140f000000 c60100 837df410 0f4345e0 }
- $sequence_8 = { 8b4d0c c60102 ebe9 3cbf 770b }
- $sequence_9 = { 0fb6d1 f604557aa3420001 740f 8b45f0 8b8094000000 }
- $sequence_10 = { 8bdf 46 ff4d0c c1e010 0fbf16 03d8 8d841a00800000 }
- $sequence_11 = { 8b34bd6cc64200 eb07 8b34bd38c64200 53 46 }
- $sequence_12 = { 89451c 7548 803ee8 7559 8b4601 }
- $sequence_13 = { 6a00 51 50 57 ff15???????? ff75d8 }
- $sequence_14 = { 49 807dff00 8955ec 894df4 8b0485582c4300 }
- $sequence_15 = { 5b c9 c3 ff742408 8b442408 ff10 c3 }
+ $sequence_0 = { 7508 ff15???????? 8bd8 4c8d5c2450 8bc3 498b5b20 498b6b28 }
+ $sequence_1 = { 4889442440 488364243800 488364243000 4533c0 488bd3 33c9 }
+ $sequence_2 = { ff15???????? 33ed 488bcb 85c0 }
+ $sequence_3 = { 7459 f60301 742c 418bcf 488bd0 4903cc e8???????? }
+ $sequence_4 = { 488b0d???????? 4c8bc7 33d2 8bd8 ff15???????? eb1e }
+ $sequence_5 = { 4156 4157 4883ec60 4c8bea 488d50c8 4d8bf9 e8???????? }
+ $sequence_6 = { ffd0 85c0 790e 8bc8 }
+ $sequence_7 = { 4c8d8584020000 488d8c2460060000 448bcb 418bd6 e8???????? }
+ $sequence_8 = { 33d2 8d440036 448bc0 448be0 ff15???????? }
+ $sequence_9 = { 8d4f01 448bcf 4c8bc6 894c2428 33c9 33d2 }
condition:
- 7 of them and filesize <466944
+ 7 of them and filesize <147456
}
-rule MALPEDIA_Win_Xbtl_Auto : FILE
+rule MALPEDIA_Win_Kleptoparasite_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7372571c-d52e-5b5b-bd42-81e7e356cc7e"
+ id = "d0389ad4-24e3-5ce2-885f-8e2d3c44dd15"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xbtl"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xbtl_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kleptoparasite_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kleptoparasite_stealer_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "b45bdfe7ddb3c3bebb25f685acba4274921aebf8fbd081dea272d3bf592a2a7b"
- score = 75
- quality = 75
+ logic_hash = "1caf749c6c15dea159c6ab2428d269f9b9674545b72666548fcdc2b3e50e89c9"
+ score = 60
+ quality = 35
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -166564,32 +173862,32 @@ rule MALPEDIA_Win_Xbtl_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd7 50 ffd3 8bd8 85f6 7406 8d45e8 }
- $sequence_1 = { 99 8bd8 8bc1 99 33f6 0bf0 3135???????? }
- $sequence_2 = { 8d45ec 8d95f0fdffff e8???????? 8b85d4fdffff 56 56 6a03 }
- $sequence_3 = { 85d2 782a 895dfc 8b4d08 0fb63c0a 8b460c 0345fc }
- $sequence_4 = { 0fb67808 89948dc0feffff 0fb65007 c1e208 0bd7 }
- $sequence_5 = { 83c41c 8d4c2410 51 ffd7 8b442434 8b4c2428 8b1d???????? }
- $sequence_6 = { 8bd6 897c2420 2bd0 0fb708 66890c02 83c002 }
- $sequence_7 = { 03048de0c04200 eb02 8bc2 f6402480 7417 e8???????? c70016000000 }
- $sequence_8 = { 81e600ff00ff c1c208 81e2ff00ff00 0bf2 897018 8b491c }
- $sequence_9 = { 8b5708 40 83c410 894704 3bc2 7e16 8d0412 }
+ $sequence_0 = { 7405 8901 895104 8be5 5d c3 3b0d???????? }
+ $sequence_1 = { ebe4 6a0c 68???????? e8???????? 8365e400 33c0 8b7d08 }
+ $sequence_2 = { e8???????? cc 55 8bec 56 e8???????? 8b7508 }
+ $sequence_3 = { 895104 8be5 5d c3 3b0d???????? 7502 }
+ $sequence_4 = { b8???????? c3 e9???????? 55 8bec 56 e8???????? }
+ $sequence_5 = { 59 c3 6a10 68???????? e8???????? 33ff 897de0 }
+ $sequence_6 = { 895104 8be5 5d c3 3b0d???????? }
+ $sequence_7 = { cc 55 8bec 56 e8???????? 8b7508 6a02 }
+ $sequence_8 = { 8901 895104 8be5 5d c3 3b0d???????? 7502 }
+ $sequence_9 = { c3 e9???????? 55 8bec 56 e8???????? 8bf0 }
condition:
- 7 of them and filesize <401408
+ 7 of them and filesize <3006464
}
-rule MALPEDIA_Win_Findpos_Auto : FILE
+rule MALPEDIA_Win_Ghost_Secret_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "06e6ab2e-1688-507b-a649-5420f969f64c"
+ id = "1b3488d9-dad5-57ab-8ddb-ae7fa19ffb25"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.findpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.findpos_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ghost_secret"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ghost_secret_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "89f2603a026fe078dffd243a5f02eea72ee3cfa2b2eca87062e133a5a2b51b38"
+ logic_hash = "36f12490c5a1c42890949e26bd5a0482d94d3f78b5528e6a3d7d1ab5deca281b"
score = 75
quality = 75
tags = "FILE"
@@ -166603,32 +173901,32 @@ rule MALPEDIA_Win_Findpos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 48 0f844b050000 33c0 8d8c24f0010000 50 51 8d8c243c020000 }
- $sequence_1 = { 68???????? e8???????? a1???????? 59 59 83c010 a3???????? }
- $sequence_2 = { 7671 8365d400 8d55d4 8bcf }
- $sequence_3 = { 8bcf e8???????? 8325????????00 833d????????10 68???????? 0f4335???????? }
- $sequence_4 = { 8b0cb8 03cb e8???????? 85c0 7414 8b4df0 }
- $sequence_5 = { eb29 8a01 3c33 7505 }
- $sequence_6 = { 8945f8 8d45f8 50 c745ec00200000 ff15???????? 85c0 745f }
- $sequence_7 = { 3b08 7518 53 51 51 6a01 8d45e4 }
- $sequence_8 = { 50 0fb6c1 50 8d85e8e7ffff 50 }
- $sequence_9 = { 33f6 46 3bc6 0f8577040000 6a11 ffd7 663bc6 }
+ $sequence_0 = { 8d852cf1ffff 50 e8???????? 8d8548fbffff 50 e8???????? 59 }
+ $sequence_1 = { c68424af050000fd c68424b0050000f6 c68424b105000093 c68424b205000038 c68424b305000032 c68424b405000048 c68424b5050000e5 }
+ $sequence_2 = { c68424b902000066 c68424ba02000072 c68424bb0200001a c68424bc0200004a }
+ $sequence_3 = { c68424e903000052 c68424ea03000082 c68424eb03000058 c68424ec0300008e }
+ $sequence_4 = { c684243e030000f0 c684243f030000f2 c68424400300003b c6842441030000c7 c6842454050000ab c684245505000087 c6842456050000d6 }
+ $sequence_5 = { 85c0 740b 33c0 5f 5e 5b 8be5 }
+ $sequence_6 = { ff15???????? e9???????? a1???????? 33db 3bc7 7e0e 50 }
+ $sequence_7 = { c684247c05000006 c684247d0500003e c684247e05000012 c684247f05000053 c684248005000092 c684248105000042 c6842482050000e8 }
+ $sequence_8 = { c644247460 c64424751f c6442476e7 c64424778a c6442478dd c68424f40000006a 888c24f5000000 }
+ $sequence_9 = { 83c408 5f 5e 81c400200000 c3 81ecfc000000 }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <278528
}
-rule MALPEDIA_Win_Downeks_Auto : FILE
+rule MALPEDIA_Win_Webc2_Head_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "45e36078-208a-5456-a83d-718f8ea60024"
+ id = "fbb157f3-5522-59eb-8966-994ac95b42ec"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.downeks"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.downeks_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_head"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_head_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "f8eb51f40370e6583f97bf6d6b06a56caeeec4252d81205dee3da42852ee5b8c"
+ logic_hash = "3accb9e007709b9cb8a99022cd642781f2c16d496b60a9e07fc0420c29da6736"
score = 75
quality = 75
tags = "FILE"
@@ -166642,32 +173940,32 @@ rule MALPEDIA_Win_Downeks_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 8b8ddcfeffff 51 ff15???????? 8b8de0feffff 53 }
- $sequence_1 = { c3 8b4108 c3 b8ccd00904 c3 8bff 55 }
- $sequence_2 = { 8d4da0 e8???????? 8b4704 85c0 7409 83f8ff 7304 }
- $sequence_3 = { e8???????? 8bd8 83c40c 85db 0f85cf000000 8b55c0 85d2 }
- $sequence_4 = { 2bce 51 8bce 2b4d80 8d75a8 8d558c e8???????? }
- $sequence_5 = { e9???????? 8d75b4 e9???????? 8d75d0 e9???????? 8bb560ffffff e9???????? }
- $sequence_6 = { c785e8faffff07000000 89b5e4faffff 668995d4faffff e8???????? 8975fc 80fb5c 740a }
- $sequence_7 = { c1ea08 0fb6d2 8b3c95a0c20804 0fb6d0 8b1495a0c60804 c1e808 0fb6c0 }
- $sequence_8 = { ff15???????? 8bf0 83c42c 85f6 0f8547feffff 8b45f0 50 }
- $sequence_9 = { 7488 8b4d0c 833900 7502 8901 8b4d10 8b13 }
+ $sequence_0 = { 8a8c0cc0000000 eb02 b13d c1e810 83e03f 0fbec9 }
+ $sequence_1 = { 68???????? 55 55 896c2434 ffd7 }
+ $sequence_2 = { 8d942444080000 03f0 51 50 52 55 ff15???????? }
+ $sequence_3 = { e8???????? 83c40c 85c0 0f8554020000 b900050000 }
+ $sequence_4 = { 33db 89442418 52 c6450000 }
+ $sequence_5 = { 7513 8dbc2444040000 83c9ff f2ae f7d1 49 894c241c }
+ $sequence_6 = { 89442410 c1e002 89442418 8b4c2424 }
+ $sequence_7 = { eb02 b03d 884303 8b442410 }
+ $sequence_8 = { 83c410 c3 5f c6450000 5e }
+ $sequence_9 = { 2500ff0000 45 3d003d0000 7435 }
condition:
- 7 of them and filesize <1318912
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Quickheal_Auto : FILE
+rule MALPEDIA_Win_Predator_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1144a28c-6891-50e3-aab7-fbd2738d1ce6"
+ id = "139b7e6c-7d6f-5725-bc06-83e05af2728a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.quickheal"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.quickheal_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.predator"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.predator_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "c8252dc1fbd623ed33de5c38485302af864b4c120786c74e672f39f82eb29422"
+ logic_hash = "4f1faf378ed80607ad7505f3b525c8d2a5bbf8d81c1cadcdd453ab7a1d609878"
score = 75
quality = 75
tags = "FILE"
@@ -166681,32 +173979,32 @@ rule MALPEDIA_Win_Quickheal_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7ce2 b814010000 8a8c28f8feffff 888c0484000000 40 3d30010000 72ea }
- $sequence_1 = { 3bf3 0f840b030000 8d4e02 8d542424 51 }
- $sequence_2 = { ff15???????? 8d542410 8d8424fc060000 52 6819000200 53 }
- $sequence_3 = { 49 51 6a06 52 ffd5 83c408 }
- $sequence_4 = { 2bce 51 56 50 56 e8???????? 83c410 }
- $sequence_5 = { 8d445d0c 83c408 33f6 6683f93b }
- $sequence_6 = { 83c102 3bc6 7cf0 5f }
- $sequence_7 = { 7207 885101 04fc eb04 c6410100 3c02 7209 }
- $sequence_8 = { f7d1 49 8dbc2414010000 8bd1 83c9ff f2ae a1???????? }
- $sequence_9 = { 52 ffd7 85c0 7418 8b442410 c744241404010000 50 }
+ $sequence_0 = { 55 8bec 83ec18 8bc2 56 8bf1 8d4dfd }
+ $sequence_1 = { 80c230 8811 85c0 75f2 51 8d45fd }
+ $sequence_2 = { 8d4dfd 57 6a0a 5f 85c0 7916 }
+ $sequence_3 = { 03c2 8bce 50 e8???????? 5f 8bc6 5e }
+ $sequence_4 = { 7508 83c8ff e9???????? ff75ec e8???????? }
+ $sequence_5 = { 83ec18 8bc2 56 8bf1 8d4dfd }
+ $sequence_6 = { ff75ec e8???????? 59 8bf0 }
+ $sequence_7 = { 7508 83c8ff e9???????? ff75ec e8???????? 59 8bf0 }
+ $sequence_8 = { 894e08 89560c 834dfcff 8b4df4 64890d00000000 5f 5e }
+ $sequence_9 = { 8b00 57 03c2 8bce }
condition:
- 7 of them and filesize <553984
+ 7 of them and filesize <2211840
}
-rule MALPEDIA_Win_Yarat_Auto : FILE
+rule MALPEDIA_Win_Qhost_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9b4289ae-23e7-5628-ab26-1ca831bf886f"
+ id = "5a22ec0c-4f17-55ab-b241-2378f7015545"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yarat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yarat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.qhost"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.qhost_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "6ef74e5effac24b08695314060e4e7e4519b854f50f85d73d7052d0ace49145b"
+ logic_hash = "c30effbf965ec02215e2576b89ba366bebeed097f08848009dcc3ab3b7556ec0"
score = 75
quality = 75
tags = "FILE"
@@ -166720,32 +174018,32 @@ rule MALPEDIA_Win_Yarat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8b75a8 8bf8 3bf7 7465 8b4e14 83f910 }
- $sequence_1 = { c70000000200 e9???????? 56 68???????? 57 e8???????? 83c40c }
- $sequence_2 = { 8d8544feffff 6a00 57 89864c010000 e8???????? 83c414 80bf0b05000000 }
- $sequence_3 = { e8???????? 83c40c 85d2 0f8f28010000 7c08 85c0 0f831e010000 }
- $sequence_4 = { 8b8f90050000 83c40c 85c9 7506 8b8f04030000 8b8748050000 8b4040 }
- $sequence_5 = { 8a18 885dfe 80fb2e 8b5d08 7406 807dfe2c 7534 }
- $sequence_6 = { 07 20c2 aa 709a 93 a3???????? 9e }
- $sequence_7 = { 8b75fc 8bc7 c1e808 83e00f 8a80d0070a10 880433 8bda }
- $sequence_8 = { e8???????? 83c408 85c0 7405 8d7728 eb38 8d85fcefffff }
- $sequence_9 = { 8b4508 33f6 83f8ff 742d 8d8df4fdffff 51 50 }
+ $sequence_0 = { c60000 8b4dfc 83e901 894dfc ebdc 8b4508 }
+ $sequence_1 = { 40 884598 8b0d???????? 51 e8???????? }
+ $sequence_2 = { ff15???????? 898550beffff c78538beffff00000000 837df400 }
+ $sequence_3 = { 7507 b805000080 eb36 8b5508 52 68???????? e8???????? }
+ $sequence_4 = { 03d0 52 ff15???????? 83c408 }
+ $sequence_5 = { 68???????? 68???????? 68ff030000 68???????? ff15???????? 83c410 }
+ $sequence_6 = { 837df800 0f84dc000000 c7854cbeffff00000000 c78550beffff00000000 eb1e }
+ $sequence_7 = { 68???????? 680f270000 68???????? ff15???????? 83c410 ff15???????? }
+ $sequence_8 = { 8bec 81ec6c0b0000 c785f0fdffff00000000 c785e8fdffff00000000 c785d4fdffff00000000 c745fc00000000 c785f4fdffff00000000 }
+ $sequence_9 = { 50 6800040000 8d8d00fcffff 51 8b95c8fbffff 52 }
condition:
- 7 of them and filesize <8692736
+ 7 of them and filesize <286720
}
-rule MALPEDIA_Win_Ryuk_Stealer_Auto : FILE
+rule MALPEDIA_Win_Balkan_Door_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "129184de-8948-5274-9e65-221045ceab9c"
+ id = "9f746f91-5631-5121-b4e8-99ba1997828d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ryuk_stealer_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.balkan_door"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.balkan_door_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "32617ac72ab27e6e0bdc0cedf044a04c83b7c2ead314f2e254d4a430611a1927"
+ logic_hash = "3ecc62d6dd03e7104a1dd179870266fc7dbfc3c0ad204dec134adb374e60ab02"
score = 75
quality = 75
tags = "FILE"
@@ -166759,32 +174057,32 @@ rule MALPEDIA_Win_Ryuk_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7410 83ff01 755d 8bcb }
- $sequence_1 = { ff15???????? 33ff 0fb60437 50 }
- $sequence_2 = { 75f5 2bd1 8d8db4fdffff d1fa 8d7102 }
- $sequence_3 = { 50 e8???????? 83c40c ff15???????? 33d2 b910270000 }
- $sequence_4 = { 83ff01 755d 8bcb e8???????? }
- $sequence_5 = { 50 ff15???????? 8bf0 ff15???????? 85c0 7518 }
- $sequence_6 = { 83ff01 755d 8bcb e8???????? 3bc7 }
- $sequence_7 = { 99 b9a0860100 f7f9 81c2f8240100 52 ff15???????? }
- $sequence_8 = { 7560 8d85b4fdffff 68???????? 50 }
- $sequence_9 = { ff15???????? 8d442454 50 ff15???????? 50 }
+ $sequence_0 = { 50 ff15???????? 8bf8 89bd3cefffff }
+ $sequence_1 = { 8bf0 85f6 740b 6a00 6a00 56 ff15???????? }
+ $sequence_2 = { ffd7 85c0 741a 8d85d0fdffff c785d0fdffff2c020000 50 56 }
+ $sequence_3 = { 8d85f4fdffff 50 ffd7 85c0 741a 8d85d0fdffff c785d0fdffff2c020000 }
+ $sequence_4 = { c785d0fdffff2c020000 50 56 ffd3 }
+ $sequence_5 = { 56 ff15???????? 8b4dfc 8b85ccfdffff 33cd 5e e8???????? }
+ $sequence_6 = { e8???????? 83c404 8bbd3cefffff 6a00 }
+ $sequence_7 = { 8b85d8fdffff 8985ccfdffff 5f 5b 56 }
+ $sequence_8 = { 683f000f00 68???????? 57 ff15???????? }
+ $sequence_9 = { 50 57 6a00 6a13 ffb53cefffff ff15???????? 85c0 }
condition:
- 7 of them and filesize <368640
+ 7 of them and filesize <352256
}
-rule MALPEDIA_Win_Chainshot_Auto : FILE
+rule MALPEDIA_Win_Kurton_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "beaf03a9-9558-5280-a84b-64277bd4ffc2"
+ id = "f013ccb0-04a7-5f02-910f-ce10f5a3eef2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chainshot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chainshot_auto.yar#L1-L111"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kurton"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kurton_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "ba9c33c28d22ea04923b796ce7a5cfd0e30c1f14b0a956e4cbe61344e61c7def"
+ logic_hash = "dc4903969616e73929d77cdaee0d726bcae8e439ec6bc053e08d133b52122f5e"
score = 75
quality = 75
tags = "FILE"
@@ -166798,32 +174096,32 @@ rule MALPEDIA_Win_Chainshot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 731b 85c9 7906 b840000000 }
- $sequence_1 = { 8d68fc c70726000000 e9???????? c70709000000 bd02000000 }
- $sequence_2 = { 7509 e8???????? 85c0 7808 }
- $sequence_3 = { 6683f819 7705 8d4220 eb03 0fb7c2 0fb7c0 }
- $sequence_4 = { b901070080 e8???????? eb89 8bd7 }
- $sequence_5 = { 7408 ffd0 8905???????? bfa3000080 e9???????? }
- $sequence_6 = { ffc8 0f843a110000 ffc8 7427 83e803 0f844a110000 }
- $sequence_7 = { 7408 ffd0 8905???????? bb82000080 }
- $sequence_8 = { 8d4a02 b8abaaaaaa f7e1 d1ea }
- $sequence_9 = { ffc8 747a ffc8 7461 83e802 }
+ $sequence_0 = { 89542430 8d8c24b8000000 89542434 50 8954243c }
+ $sequence_1 = { 83c8ff eb1f 8bce 83e61f c1f905 8bc6 8b0c8da05b0210 }
+ $sequence_2 = { 33c0 8dbc2458010000 c744242800010000 f3ab 8d442428 8d8c2458010000 50 }
+ $sequence_3 = { 889c2478040200 e8???????? 89b42474040200 e9???????? b91f000000 }
+ $sequence_4 = { 64a100000000 50 64892500000000 81ecb8000000 8a442403 53 }
+ $sequence_5 = { 84c0 752b 8b442414 3bc3 }
+ $sequence_6 = { 8d88740a0000 8988280b0000 33c9 c780180b0000902f0210 }
+ $sequence_7 = { 83c410 c20400 68???????? e8???????? 6a00 6a00 6a01 }
+ $sequence_8 = { b91f000000 33c0 8dbc24ad000000 889c24ac000000 f3ab 66ab }
+ $sequence_9 = { 895de0 895ddc 895dfc 897de4 740a 803800 7405 }
condition:
- 7 of them and filesize <802816
+ 7 of them and filesize <344064
}
-rule MALPEDIA_Win_Shujin_Auto : FILE
+rule MALPEDIA_Win_Webc2_Div_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "20683034-d09a-5705-9d80-d7edf3a7d88d"
+ id = "ec34042e-e794-5a2f-acc9-f1f4c0dd235a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shujin"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shujin_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_div"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_div_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "b1da2f105214e6f844dccb186e5a1748a5be3983c376113a3f54dc8e70f99c20"
+ logic_hash = "11aa7a8bbe87a55b44481499db0ce13e00127df87edb76e8d3596bc6375e5a87"
score = 75
quality = 75
tags = "FILE"
@@ -166837,32 +174135,32 @@ rule MALPEDIA_Win_Shujin_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? ff7660 8b1d???????? 6a01 bf80000000 57 }
- $sequence_1 = { ff15???????? 85c0 0f8431010000 53 897df4 }
- $sequence_2 = { 6aff 50 ff15???????? 57 8b7d10 83ff01 }
- $sequence_3 = { 8bf9 ba???????? 0fb67201 8a0a 8b1f d3e3 0fb60c06 }
- $sequence_4 = { 83615400 53 56 57 8d7108 c7450805000000 8b46f8 }
- $sequence_5 = { ff45f8 817df870170000 72c9 e9???????? 807daa01 8b45e8 8d1c06 }
- $sequence_6 = { 8b5508 0facc21a c1f81a 8bd8 8955e4 }
- $sequence_7 = { c1ef10 8d8d9cf9ffff 2bf9 03f8 a0???????? a801 7421 }
- $sequence_8 = { 895008 8b680c 8bd5 896c2410 }
- $sequence_9 = { 8d1c06 83c40c 8975f8 3bf3 731e }
+ $sequence_0 = { 5f e9???????? 6a3c 51 e9???????? 85c0 0f842c010000 }
+ $sequence_1 = { 81c2b4000000 69d260ea0000 895604 eb73 8d4505 50 }
+ $sequence_2 = { ff15???????? ff7508 8b35???????? 85c0 7512 }
+ $sequence_3 = { 771a 8b442414 0540f087fc 50 ffd5 015c2410 8144241460ce5800 }
+ $sequence_4 = { 894508 7509 57 ff15???????? eb54 a0???????? }
+ $sequence_5 = { 894c243c ff15???????? 85c0 5f 750a }
+ $sequence_6 = { f7d1 2bf9 8d95f0feffff 8bf7 8bfa 8bd1 }
+ $sequence_7 = { f7d1 49 8bf1 8d7e01 }
+ $sequence_8 = { 8885ecf9ffff 33c0 8dbdedf9ffff 8975f8 f3ab }
+ $sequence_9 = { 8bc5 bb16000000 99 f7ff 8bc1 8d3c9510114000 99 }
condition:
- 7 of them and filesize <172032
+ 7 of them and filesize <32768
}
-rule MALPEDIA_Win_Skip20_Auto : FILE
+rule MALPEDIA_Win_Client_Maximus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "82237026-0542-5063-b5ce-819de193cfa5"
+ id = "9ae68e0c-f7b3-57b3-a5e5-43c9d1c73212"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.skip20"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.skip20_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.client_maximus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.client_maximus_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "21de0ff5fbd1c6f42d6edbb2c240ff9a5cc9d69d730f1c14e8fabd969797a013"
+ logic_hash = "b18f0f0d0ef0e4099637c9406b0101b6f1ae3668adb85f5994962285717f3168"
score = 75
quality = 75
tags = "FILE"
@@ -166876,32 +174174,32 @@ rule MALPEDIA_Win_Skip20_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c9 7448 ffc9 7432 ffc9 0f85150a0000 }
- $sequence_1 = { 782e 3b0d???????? 7326 4863c9 488d1504fe0400 488bc1 }
- $sequence_2 = { 0fb74c247a 0fb7542478 89442438 894c2430 89542428 488d15e62f0100 }
- $sequence_3 = { 741c 3d00010000 740e 3d00020000 7536 4180493347 eb2f }
- $sequence_4 = { e9???????? 4883bc24e000000000 7409 83fa01 0f842cf9ffff 83fa05 }
- $sequence_5 = { 488db424ec000000 0f1f00 413bfc 732a 448b06 8bd7 }
- $sequence_6 = { 418bb482a08a0100 eb07 4c8d15b4b2ffff 8bd6 81e200004000 747e 41ff4c2418 }
- $sequence_7 = { 488d3d071f0500 ba58000000 488bcd e8???????? 4885c0 7468 }
- $sequence_8 = { 89542428 488d15652f0100 440fb7442470 440fb74c2472 440fb7542476 4489542420 488d0db72f0100 }
- $sequence_9 = { 89442438 0fb74c247a 894c2430 0fb7542478 89542428 488d15ae290100 }
+ $sequence_0 = { 89f0 0fb6c0 0fb61403 88140b 83c101 89fa 81f900010000 }
+ $sequence_1 = { 89e5 56 53 83ec10 8b1d???????? }
+ $sequence_2 = { 893424 ff15???????? 83ec08 85c0 7411 }
+ $sequence_3 = { e8???????? 8b4304 85c0 741d 8b5330 c744240800800000 c744240400000000 }
+ $sequence_4 = { 39730c 7fe1 891424 e8???????? }
+ $sequence_5 = { 7429 c70424???????? ff15???????? 83ec04 a3???????? }
+ $sequence_6 = { 8b4628 85c0 7535 c70424???????? }
+ $sequence_7 = { a3???????? c7442404???????? 893424 ff15???????? 83ec08 85c0 7411 }
+ $sequence_8 = { 89c8 0fb63c0b 99 f77c241c 89f8 }
+ $sequence_9 = { 89f8 02441500 01c6 89f0 0fb6c0 }
condition:
- 7 of them and filesize <794624
+ 7 of them and filesize <106496
}
-rule MALPEDIA_Win_Zeus_Mailsniffer_Auto : FILE
+rule MALPEDIA_Win_Cerber_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4733ffb9-de21-5ee6-bd3e-4039874823ba"
+ id = "1b1175b4-aaae-5323-bbb6-472b8daa3220"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus_mailsniffer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeus_mailsniffer_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cerber"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cerber_auto.yar#L1-L101"
license_url = "N/A"
- logic_hash = "43d5df07bea6317ea4eb20e7781c6702e7589e518cedd0ad1502aceef73d3213"
+ logic_hash = "90183139badfe5f943ec4dd7b3bc0305f6ea2215a75a5dc8603646346366cf36"
score = 75
quality = 75
tags = "FILE"
@@ -166915,34 +174213,32 @@ rule MALPEDIA_Win_Zeus_Mailsniffer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a01 56 e8???????? 83c40c 85c0 7473 807b0e02 }
- $sequence_1 = { 53 6880000000 6a03 53 53 68000000c0 8bc6 }
- $sequence_2 = { 68???????? ff750c ff15???????? 83c40c 85c0 0f85bc000000 ffd6 }
- $sequence_3 = { 0f84e2020000 53 8d4594 50 8d4588 50 c7459401000000 }
- $sequence_4 = { 8b4510 0118 ff45d8 837dc800 0f8480000000 ff75f4 }
- $sequence_5 = { 33f6 e8???????? 83c40c 84c0 0f843d020000 8b45f4 }
- $sequence_6 = { 56 ff75fc e8???????? 83c414 8bf8 8b35???????? ff15???????? }
- $sequence_7 = { 0f8c5b010000 40 3b442410 72dd e9???????? 50 }
- $sequence_8 = { 74f4 6a08 8d442430 53 }
- $sequence_9 = { 2bd1 eb99 55 8bec 83e4f8 81ecfc0e0000 53 }
+ $sequence_0 = { 4a 79f6 5f 8bc6 }
+ $sequence_1 = { 85c0 750c 8b33 e8???????? 832300 eb0e 8b4dfc }
+ $sequence_2 = { 33f9 8b88e0000000 894dd0 8b88e4000000 899864010000 8b5dd8 }
+ $sequence_3 = { 4a 79e6 47 3b7d0c }
+ $sequence_4 = { 51 53 56 8bf0 57 85f6 7508 }
+ $sequence_5 = { 4a b800000080 83e904 eb02 }
+ $sequence_6 = { 895df4 33c9 83fa08 0f9dc1 854df4 7515 }
+ $sequence_7 = { 33f9 8b88e8feffff 234808 8998fc000000 8b5874 }
condition:
- 7 of them and filesize <368640
+ 7 of them and filesize <573440
}
-rule MALPEDIA_Win_Blackcat_Auto : FILE
+rule MALPEDIA_Win_Badnews_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "64552e7e-a42b-5e42-ac85-4cf9a6355d18"
+ id = "82b67459-b37a-5597-851f-c5e10ae625fd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackcat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackcat_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badnews"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.badnews_auto.yar#L1-L214"
license_url = "N/A"
- logic_hash = "2fe3958ae160b549a525be2a75569af9cb09940744adfe7a2969b920b4e1603b"
+ logic_hash = "bc13ea27737db6028c742e92e044e676e8322f3710d6ba3506e9723f27d2a819"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -166954,32 +174250,44 @@ rule MALPEDIA_Win_Blackcat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c3 894608 c7460400000000 b001 ebe8 89c2 }
- $sequence_1 = { 7260 8b06 01d8 51 57 50 89cf }
- $sequence_2 = { 8975dc 8955e0 eb07 31c0 b902000000 }
- $sequence_3 = { b104 eb0f e8???????? 89c2 c1e018 31c9 }
- $sequence_4 = { 7504 3c02 7351 88c4 8975cc }
- $sequence_5 = { 81f9cf040000 0f8fe4000000 81f96b040000 0f84b4010000 81f976040000 }
- $sequence_6 = { 83ec08 a1???????? c745f800000000 c745fc00000000 85c0 7408 8d4df8 }
- $sequence_7 = { 8d45f8 50 e8???????? 8b45f8 8b55fc 83c408 }
- $sequence_8 = { 895804 897008 eb0b 8b45e8 894708 }
- $sequence_9 = { ff45e4 8a02 42 8955e8 }
+ $sequence_0 = { 50 e8???????? 83c404 68???????? 6804010000 ff15???????? }
+ $sequence_1 = { c78534ffffff47657457 c78538ffffff696e646f c7853cffffff77546578 66c78540ffffff7457 }
+ $sequence_2 = { c705????????55736572 c705????????33322e64 66c705????????6c6c c605????????00 }
+ $sequence_3 = { eb02 33c9 c0e004 02c1 3423 c0c003 }
+ $sequence_4 = { 8945fc 53 56 57 8d8534ffffff }
+ $sequence_5 = { 55 8bec 8b450c 3d01020000 }
+ $sequence_6 = { d1f9 68???????? 03c9 51 }
+ $sequence_7 = { 68???????? 6a1a 68???????? 57 }
+ $sequence_8 = { 6a02 68???????? 50 a3???????? }
+ $sequence_9 = { 8bf0 56 ff15???????? 50 6a40 }
+ $sequence_10 = { 56 ffd3 85c0 7403 83c608 8a06 }
+ $sequence_11 = { 57 6a00 6880000000 6a04 6a00 6a01 6a04 }
+ $sequence_12 = { ff15???????? 85c0 7405 83c004 }
+ $sequence_13 = { 68???????? ff15???????? b8???????? 83c424 8d5002 668b08 }
+ $sequence_14 = { e8???????? 68???????? 8d45f4 c745f4682f0110 50 e8???????? cc }
+ $sequence_15 = { 83e61f c1f805 c1e606 c1e910 c0e107 8b1485d0a70110 }
+ $sequence_16 = { 8d8d54ffffff 8d5101 90 8a01 }
+ $sequence_17 = { 7414 8bc2 c1f805 83e21f c1e206 031485d0a70110 }
+ $sequence_18 = { 8b048dd0a70110 4e 807d1300 8955e4 c64418050a }
+ $sequence_19 = { 58 668986b8000000 668986be010000 c7466848960110 }
+ $sequence_20 = { 2bc2 8bf0 d1fe 6a55 ff34f5e0470110 ff7508 e8???????? }
+ $sequence_21 = { 41 84c0 75f9 2bce 741c 804415ec03 }
condition:
- 7 of them and filesize <29981696
+ 7 of them and filesize <612352
}
-rule MALPEDIA_Win_Winsloader_Auto : FILE
+rule MALPEDIA_Win_Bka_Trojaner_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3816b057-ecfc-5190-8abf-a0a65a8930f8"
+ id = "a0a20d3c-b939-5a5e-b947-ecd1e3a9e77c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winsloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.winsloader_auto.yar#L1-L171"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bka_trojaner"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bka_trojaner_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "2eada578907b5f770ab8c1dc3588915ff9d4c97daa18d7827115e92744f234da"
+ logic_hash = "b96818656a5fc18803f0bf1dba8c00052206b33d8bd6ff1c085aa051852c2a47"
score = 75
quality = 75
tags = "FILE"
@@ -166993,38 +174301,32 @@ rule MALPEDIA_Win_Winsloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c40c 6800040000 8d8dfcf7ffff 51 }
- $sequence_1 = { 8bf8 83c434 85ff 7510 }
- $sequence_2 = { 89941d02fcffff 89841d06fcffff b8???????? 898c1d0afcffff 83c410 }
- $sequence_3 = { 68???????? 51 e8???????? 68???????? 8d5c3e04 e8???????? }
- $sequence_4 = { 898c1d0afcffff 83c410 66c7841d0efcffff4501 8d7001 8a08 }
- $sequence_5 = { 8d8375050000 6a00 a3???????? ff15???????? }
- $sequence_6 = { 0fb7c0 8bf0 6689841d10fcffff 56 83c316 8d941dfcfbffff 68???????? }
- $sequence_7 = { f3a5 66a5 8b15???????? 8990fa0d0000 8b0d???????? }
- $sequence_8 = { 8bd8 c745fcffffffff 85db 7516 56 e8???????? }
- $sequence_9 = { c3 e8???????? 85c0 0f8487660000 c3 833d????????ff 7503 }
- $sequence_10 = { 894dfc 80fb08 750f 32db }
- $sequence_11 = { 33c0 40 e9???????? 8365c800 c745cc231a0110 a1???????? 8d4dc8 }
- $sequence_12 = { 8d940dfcfbffff 52 e8???????? 83c40c 0fb685f7f3ffff }
- $sequence_13 = { c1e100 8b9568f3ffff 8991a8ad0110 8b85f8f3ffff 05b4130000 668985f0f3ffff }
- $sequence_14 = { 8841ff 83ea01 75f2 8b542424 8a1a 8d4701 50 }
- $sequence_15 = { 8b049594440110 8985ccf6ffff 85c0 757c 50 8985d4f4ffff 89855cfcffff }
+ $sequence_0 = { 2bc1 33ff 89442428 397c2420 894c2438 897c242c }
+ $sequence_1 = { 8b542414 68ff030000 8d8c2468040000 03da 8b54241c 51 }
+ $sequence_2 = { 50 57 e8???????? 85c0 75c6 5d }
+ $sequence_3 = { 56 ff5124 85c0 7517 8b44247c 5f }
+ $sequence_4 = { 85c0 7439 53 8b1d???????? 55 8b2d???????? 8bff }
+ $sequence_5 = { 8b54240c 8b4c2404 8b8170ffffff 52 8b54240c 81c170ffffff 52 }
+ $sequence_6 = { 6a10 68???????? 68???????? 52 ff15???????? 83c8ff }
+ $sequence_7 = { e8???????? 59 59 8945c4 a1???????? }
+ $sequence_8 = { c7440a04???????? 8b4104 8b4004 8d9078ffffff 891408 8b4104 }
+ $sequence_9 = { 752d 837df800 7424 ff7508 8d4608 e8???????? ff7508 }
condition:
- 7 of them and filesize <270336
+ 7 of them and filesize <221184
}
-rule MALPEDIA_Win_Combos_Auto : FILE
+rule MALPEDIA_Win_Woolger_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1f17e5a0-ef31-5686-bb42-b8b65987952e"
+ id = "903b676c-1246-53ac-bdc3-0b77fc0dda3c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.combos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.combos_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.woolger"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.woolger_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "037e9ec47814518fd1ef388425768f46eed22a270b66cf4ee1793ac0871a3237"
+ logic_hash = "403d441c2bcd327a0a5f26d737426637c32fb82ed6205c2fd16dc75ea4a861d4"
score = 75
quality = 75
tags = "FILE"
@@ -167038,32 +174340,32 @@ rule MALPEDIA_Win_Combos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 68ffff1f00 8d45e4 50 }
- $sequence_1 = { be???????? 8b4c2410 8bfb 8bc1 6a01 c1e902 f3a5 }
- $sequence_2 = { 57 57 53 56 8b8dd8feffff }
- $sequence_3 = { 89bdd4feffff 897dfc 8b4508 50 }
- $sequence_4 = { 8d054c160110 83780800 754e b741 b35a b620 }
- $sequence_5 = { 53 8d44240c 55 56 89442410 57 c744241000000000 }
- $sequence_6 = { 740e 50 ff15???????? 830d????????ff c3 8b442404 c74050b0110110 }
- $sequence_7 = { 7514 8b442408 8b4c2410 5e }
- $sequence_8 = { 0bc5 33c1 8b848600ffffff 0bc7 5f 5e 5d }
- $sequence_9 = { 83ec08 55 56 8b742414 85f6 0f8412010000 }
+ $sequence_0 = { 83f814 750a be???????? e9???????? 83f81b }
+ $sequence_1 = { 83ec54 6a40 8d45b0 6a00 50 c745ac44000000 e8???????? }
+ $sequence_2 = { 33c5 8945fc 33c0 668945d4 }
+ $sequence_3 = { 6685c0 8d85fcfeffff 50 0f95c3 ff15???????? 8b4f08 }
+ $sequence_4 = { 52 ff15???????? 83f801 0f858d000000 }
+ $sequence_5 = { 6a00 68???????? ff15???????? 68???????? 6a01 6a00 }
+ $sequence_6 = { 66a5 8dbdfcf8ffff 4f 8a4701 47 84c0 }
+ $sequence_7 = { 6a00 8d8dd4f4ffff 51 ffd6 85c0 75db }
+ $sequence_8 = { 83c414 81ffb80b0000 5f 7c40 e8???????? e8???????? }
+ $sequence_9 = { 3da2000000 0f8403010000 3da3000000 0f84f8000000 3da4000000 0f84e6000000 3da5000000 }
condition:
- 7 of them and filesize <163840
+ 7 of them and filesize <196608
}
-rule MALPEDIA_Win_Webc2_Div_Auto : FILE
+rule MALPEDIA_Win_Crypmic_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ec34042e-e794-5a2f-acc9-f1f4c0dd235a"
+ id = "50202601-a687-564d-add6-7e6f376e5e2e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_div"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_div_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.crypmic"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.crypmic_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "11aa7a8bbe87a55b44481499db0ce13e00127df87edb76e8d3596bc6375e5a87"
+ logic_hash = "9041d9d560914890b77f3fcac1afa5aa11364ed26eb5680a449dc6f4542c2153"
score = 75
quality = 75
tags = "FILE"
@@ -167077,32 +174379,32 @@ rule MALPEDIA_Win_Webc2_Div_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 5f e9???????? 6a3c 51 e9???????? 85c0 0f842c010000 }
- $sequence_1 = { 81c2b4000000 69d260ea0000 895604 eb73 8d4505 50 }
- $sequence_2 = { ff15???????? ff7508 8b35???????? 85c0 7512 }
- $sequence_3 = { 771a 8b442414 0540f087fc 50 ffd5 015c2410 8144241460ce5800 }
- $sequence_4 = { 894508 7509 57 ff15???????? eb54 a0???????? }
- $sequence_5 = { 894c243c ff15???????? 85c0 5f 750a }
- $sequence_6 = { f7d1 2bf9 8d95f0feffff 8bf7 8bfa 8bd1 }
- $sequence_7 = { f7d1 49 8bf1 8d7e01 }
- $sequence_8 = { 8885ecf9ffff 33c0 8dbdedf9ffff 8975f8 f3ab }
- $sequence_9 = { 8bc5 bb16000000 99 f7ff 8bc1 8d3c9510114000 99 }
+ $sequence_0 = { 395818 764a 8b7820 03f9 }
+ $sequence_1 = { 2bc1 74ec 46 3b75fc 770b 8b55f8 }
+ $sequence_2 = { 8b4de4 894f04 8b4de8 894f08 668b4df0 66894f0c 668b45f2 }
+ $sequence_3 = { 33d2 8d642400 8d4001 66890c17 }
+ $sequence_4 = { 50 8b4608 6a08 ff7604 ffd0 }
+ $sequence_5 = { 33c0 8bcf 66894302 e8???????? }
+ $sequence_6 = { 43 83c704 3b5818 72bb 5f }
+ $sequence_7 = { 55 8bec 83ec0c 8b413c 53 8b440878 03c1 }
+ $sequence_8 = { 5d c20800 8b55fc 8b4224 8d0458 0fb70c08 8b421c }
+ $sequence_9 = { 8b440878 03c1 8945fc 395818 }
condition:
- 7 of them and filesize <32768
+ 7 of them and filesize <81920
}
-rule MALPEDIA_Win_Moonbounce_Auto : FILE
+rule MALPEDIA_Win_Hui_Loader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c186ffa8-3b28-566b-9f82-5819628ca523"
+ id = "175084ea-2a45-5f42-bda4-3cc233036dd9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moonbounce"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moonbounce_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hui_loader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hui_loader_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "081fa4bc70b28c3a98dc6caeb9104489e42b513d1d76e6dfbd571155c86ff551"
+ logic_hash = "96ca3a225904ad2e70a598c1b3c7fa88d26822a60a6742e1663517bed35c0526"
score = 75
quality = 75
tags = "FILE"
@@ -167116,34 +174418,34 @@ rule MALPEDIA_Win_Moonbounce_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7413 8d041e 85c0 0f8407feffff ff7704 6a01 }
- $sequence_1 = { 3bfe 7426 56 56 56 56 }
- $sequence_2 = { 6a04 6800200000 ff7650 50 ff5708 8bd8 85db }
- $sequence_3 = { 8b5de8 5e 5f 8bc3 5b }
- $sequence_4 = { 833800 7413 8345fc04 8b45fc 8b00 }
- $sequence_5 = { 56 57 6a30 33ff 57 ff15???????? }
- $sequence_6 = { a3???????? 3935???????? 7441 3935???????? }
- $sequence_7 = { 8d45e8 50 ffd7 84c0 0f8482000000 }
- $sequence_8 = { 8b400c 85c0 0f8495000000 03c3 50 ff570c }
- $sequence_9 = { 3bfe 7426 56 56 56 56 68???????? }
+ $sequence_0 = { 68???????? 51 8bf8 ffd5 8d9424b8010000 8d842488090000 }
+ $sequence_1 = { ffd0 68e8030000 ffd6 8b0d???????? 51 ff15???????? 5f }
+ $sequence_2 = { 8b1402 3bd3 7406 c70109000000 }
+ $sequence_3 = { 83e01f c1f905 8d04c0 8b0c8d60e20010 8d44810c 50 }
+ $sequence_4 = { 52 50 a3???????? ff15???????? a1???????? }
+ $sequence_5 = { 83c628 83f90a 7cd9 33d2 }
+ $sequence_6 = { 8d4a01 0338 83c004 49 75f8 42 83c628 }
+ $sequence_7 = { c20400 8b15???????? 33c0 68???????? 52 }
+ $sequence_8 = { ff15???????? a3???????? 33ff 8d4c2428 }
+ $sequence_9 = { 7e0f 8b4efc 8b5401fc 031401 8b0e 891401 }
condition:
- 7 of them and filesize <70912
+ 7 of them and filesize <131072
}
-rule MALPEDIA_Win_Cobra_Auto : FILE
+rule MALPEDIA_Win_Cabart_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "962ae883-d522-5f88-b272-e61709553508"
+ id = "ec8b7b53-684b-5fca-bc08-508467faa1aa"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cobra"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cobra_auto.yar#L1-L488"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cabart"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cabart_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "0f157bf0768b0eaaf80d53d6edd02f203144bcb1fce66a02d72ea93d53a8a5ec"
+ logic_hash = "ef91551af86c18985e4a8081f5258aef75a9aeccca976feccaee2997d09b19b6"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -167154,79 +174456,33 @@ rule MALPEDIA_Win_Cobra_Auto : FILE
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
- strings:
- $sequence_0 = { 7511 e8???????? 85c0 7508 ff15???????? }
- $sequence_1 = { ff25???????? 53 56 57 8bd9 33f6 }
- $sequence_2 = { 7514 391d???????? 754d 33c0 }
- $sequence_3 = { 85c0 0f8e8c000000 83e801 8905???????? }
- $sequence_4 = { 751c 8bcf ff15???????? 8d8fe8030000 8bf9 }
- $sequence_5 = { 757f 8b05???????? 85c0 0f8e8c000000 }
- $sequence_6 = { 5b c3 85db 7405 83fb03 }
- $sequence_7 = { 85c0 750e 3905???????? 7e2c ff0d???????? 83f801 8b0d???????? }
- $sequence_8 = { e8???????? 85c0 750e 33ff 8bc7 }
- $sequence_9 = { 5f 5e 5b c3 85ff 7418 }
- $sequence_10 = { 753c b980000000 e8???????? 85c0 a3???????? 7504 33c0 }
- $sequence_11 = { 5e 5b c3 83fb01 7405 83fb02 }
- $sequence_12 = { 33d2 b9e8030000 f7f1 83f805 }
- $sequence_13 = { c9 c3 3ac8 7606 8ad1 }
- $sequence_14 = { d2e0 0802 ff45f8 837df808 7c0b 8a041f 47 }
- $sequence_15 = { e8???????? 83c410 85c0 7517 ff7520 ff751c }
- $sequence_16 = { 7407 33c0 e9???????? ff15???????? e9???????? }
- $sequence_17 = { 7f07 e8???????? eb26 83c0ff }
- $sequence_18 = { e8???????? eb6d e8???????? 85c0 }
- $sequence_19 = { e8???????? 33db 3bc3 741a }
- $sequence_20 = { e8???????? 8bc7 eb0e 4883c108 e8???????? b801005921 }
- $sequence_21 = { 85c0 7564 488b0b 488b01 }
- $sequence_22 = { ff5024 488d4d08 e8???????? 488d4d08 e8???????? 488bcd }
- $sequence_23 = { ff501c 488d4d08 e8???????? 498bce e8???????? 48832700 ba02000000 }
- $sequence_24 = { ff5064 488b0e 4883c108 e8???????? 488b5c2430 488b6c2438 488b742440 }
- $sequence_25 = { 83781400 750a b865005921 e9???????? }
- $sequence_26 = { 8bec 56 6a00 6880000000 6a03 6a00 6a03 }
- $sequence_27 = { 83feff 7505 33c0 5e 5d c3 8b4d08 }
- $sequence_28 = { 6a03 68000000c0 50 ff15???????? 8bf0 83feff 7505 }
- $sequence_29 = { 83c0fe 668b4802 83c002 663bcb 75f4 8b15???????? 8b0d???????? }
- $sequence_30 = { 8908 8b0d???????? 895004 894808 33c0 }
- $sequence_31 = { c3 8b4d08 57 51 6a00 }
- $sequence_32 = { 6689440ffc 6685c0 75ee f685c003000010 }
- $sequence_33 = { 8d45e8 50 6a00 6aff e8???????? 85c0 }
- $sequence_34 = { 68???????? 51 ffd6 83c40c 6a28 }
- $sequence_35 = { ff15???????? 83f87a 740b 3d230000c0 }
- $sequence_36 = { 8b7d0c 3bc3 7508 3bfb }
- $sequence_37 = { ff15???????? 488bcf ff15???????? 41b701 }
- $sequence_38 = { 48894c2450 4c89642448 488d4c2468 48894c2440 4c89642438 }
- $sequence_39 = { 75e8 85f6 74e4 418936 b801000000 4881c4480d0000 }
- $sequence_40 = { 48f7d1 66837c4bfc5c 7413 488bfb 4883c9ff 66f2af 8b05???????? }
- $sequence_41 = { 8d8588feffff 68???????? 50 ff15???????? 83c42c }
- $sequence_42 = { b914000000 84c0 0f45f9 488bce }
- $sequence_43 = { 488bce 8bd7 ff15???????? 85c0 }
- $sequence_44 = { 7507 32c0 e9???????? c745b818000000 }
- $sequence_45 = { 668b08 83c002 6685c9 75f5 2bc2 d1f8 66837c43fe5c }
- $sequence_46 = { 05a1000000 50 8d84249c0d0000 68???????? }
- $sequence_47 = { 0f8456feffff 807c241301 6800080000 0f8544020000 }
- $sequence_48 = { 0f8431ffffff 8b4d08 5f 8931 }
- $sequence_49 = { 0f84100f0000 6800080000 57 56 }
- $sequence_50 = { 05a2000000 50 8d94249c0d0000 68???????? }
- $sequence_51 = { 05a2000000 50 8d8c249c0d0000 68???????? }
- $sequence_52 = { 668cc8 c3 53 50 }
- $sequence_53 = { 85c0 740a b8050000c0 e9???????? }
- $sequence_54 = { c745bc04390100 66c745d81800 66c745da1a00 c745dc10390100 }
- $sequence_55 = { c745bc01000000 c745c000000000 6a00 6a00 8d55ac 52 }
+ strings:
+ $sequence_0 = { 8930 8b4510 eb16 395d10 740f }
+ $sequence_1 = { 8d8500fcffff 50 ff35???????? be00020000 ff35???????? }
+ $sequence_2 = { 3bc3 7620 8d4df0 51 50 }
+ $sequence_3 = { 33c0 66898506fcffff 8d8500fcffff 50 ff35???????? be00020000 }
+ $sequence_4 = { 8d0c30 3bcf 7732 3bc3 }
+ $sequence_5 = { 8d85fcfeffff 68???????? 6804010000 50 ff15???????? 83c410 6a10 }
+ $sequence_6 = { 85db 750a 68b90b0000 e8???????? 85ed }
+ $sequence_7 = { 3bc7 750a 68ec030000 e9???????? 8bc8 }
+ $sequence_8 = { 57 8d45e8 50 6a58 56 }
+ $sequence_9 = { ff15???????? 57 8d45f4 50 6a3f 56 c745f40a000000 }
condition:
- 7 of them and filesize <1368064
+ 7 of them and filesize <32768
}
-rule MALPEDIA_Win_Metadatabin_Auto : FILE
+rule MALPEDIA_Win_Unidentified_070_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ddd31612-5b1e-5a32-9ee2-3a06fec41c32"
+ id = "7ae3ca74-0486-51ae-ba4c-20ff0ab01fe5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.metadatabin"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.metadatabin_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_070"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_070_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "11b64ee680ef1e61921c6aade590c08f83cd6a9ae0a068d4e02dca568fca78c2"
+ logic_hash = "bd634ade531926df7fb9636e5fb1e66cb3297f9900a01fa2493788383a51b75e"
score = 75
quality = 75
tags = "FILE"
@@ -167240,32 +174496,32 @@ rule MALPEDIA_Win_Metadatabin_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89d1 89c6 8b8424d0000000 11d9 0f92c3 f7e7 89c7 }
- $sequence_1 = { 8bbde8feffff 0f44c8 01fa 39da 0f4cd3 85ff 0f45da }
- $sequence_2 = { 8b8c2488000000 13442448 897c243c 660f6e4c243c 89f7 8b74245c 83d300 }
- $sequence_3 = { 8b742414 8b542424 39de 0f841c010000 0f836e010000 0fb7447430 0512230000 }
- $sequence_4 = { 8b85f8feffff c744240800000000 895c2404 890424 ff95f4feffff c785fcfeffff01000000 8b8568feffff }
- $sequence_5 = { f7e3 8b5c2470 01c8 89842458010000 0fb6442428 11c2 89d8 }
- $sequence_6 = { 897c240c 89fa 89c7 b8ffff0700 660f6e8c2420010000 83d700 660f6e5c240c }
- $sequence_7 = { 8d34c0 89442424 01f6 01d1 8b542408 11fe 8b7c241c }
- $sequence_8 = { 89d3 89442418 89f8 039c2480010000 83d100 f7642460 01d8 }
- $sequence_9 = { 660f70d044 660fefe6 f30f6fb42460050000 660fdbe2 660fefdc 660fefa424a0000000 660f6fc1 }
+ $sequence_0 = { 6a04 50 ff15???????? 8945fc 85c0 }
+ $sequence_1 = { 6a00 6a00 6a04 50 ff15???????? 8945fc 85c0 }
+ $sequence_2 = { 33c0 c20400 3b0d???????? 7502 }
+ $sequence_3 = { 6a00 6a04 50 ff15???????? 8945fc }
+ $sequence_4 = { 6a00 6a04 50 ff15???????? 8945fc 85c0 }
+ $sequence_5 = { 6a00 6a00 6a00 6a04 50 ff15???????? 8945fc }
+ $sequence_6 = { 6a00 6a00 6a04 50 ff15???????? 8945fc }
+ $sequence_7 = { 6a00 8d45f4 50 ff75fc 57 56 }
+ $sequence_8 = { 8bf9 c78424cc00000000000000 66c78424d00000000010 e8???????? 83c40c 8d442424 50 }
+ $sequence_9 = { 6a00 56 ff15???????? 8945f8 85c0 0f8493000000 6a00 }
condition:
- 7 of them and filesize <1263616
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Win_Ironhalo_Auto : FILE
+rule MALPEDIA_Win_Kelihos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2d227622-166f-50b3-a1ee-3f19a045e93e"
+ id = "5eeb2760-12b0-5f38-935d-d1f5e018b5d9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ironhalo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ironhalo_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kelihos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kelihos_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "ff7e4c197682c2fb1b52bad6a60a31bcbdcc6f7acd7ddda36a5021d06aae5146"
+ logic_hash = "0a57f5287680233f80bcd1391dc843be1b51717107a9ac1743ac21e2bb163525"
score = 75
quality = 75
tags = "FILE"
@@ -167279,32 +174535,32 @@ rule MALPEDIA_Win_Ironhalo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 808821cf400008 40 3dff000000 72f1 }
- $sequence_1 = { 33c0 8d7c245c 53 f3ab 8d4c2460 6a07 51 }
- $sequence_2 = { 6a00 6a00 50 6a00 66c744246c0000 c744246801010000 }
- $sequence_3 = { 8d542410 8d442424 52 50 ffd6 }
- $sequence_4 = { 52 aa e8???????? 8dbc2434020000 }
- $sequence_5 = { 5d c3 8b4c2404 f7c103000000 7414 8a01 41 }
- $sequence_6 = { 3b35???????? 0f83c5010000 8bc6 83e61f c1f805 c1e603 8d1c8560e04000 }
- $sequence_7 = { 8816 46 eb0f 0fb6d2 f68221cf400004 7403 40 }
- $sequence_8 = { 8d542460 68???????? 52 ffd6 8d442460 68???????? 50 }
- $sequence_9 = { 75d1 55 ff15???????? 5e 5f }
+ $sequence_0 = { e8???????? 59 59 c644241701 84c0 7505 c644241700 }
+ $sequence_1 = { ff7508 ff75fc ff7508 50 51 ff750c 56 }
+ $sequence_2 = { e8???????? 6a00 6a01 8d4dc0 e8???????? 8a45ef e8???????? }
+ $sequence_3 = { e8???????? b001 e8???????? c20800 6a18 b8???????? e8???????? }
+ $sequence_4 = { e8???????? 83c40c 53 6a01 8d8ddcfdffff e8???????? 53 }
+ $sequence_5 = { e8???????? c645fc02 807dd800 0f84f7000000 8b06 8b4004 03c6 }
+ $sequence_6 = { ff75ac 8d7db8 895da8 e8???????? 83c40c 84c0 0f840b010000 }
+ $sequence_7 = { 8b4d0c 8b5508 6a00 6a10 50 51 52 }
+ $sequence_8 = { c3 6a10 b8???????? e8???????? 8b7d08 33db 53 }
+ $sequence_9 = { e8???????? eb02 33c0 e8???????? c20400 83c1f8 8b01 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <4702208
}
-rule MALPEDIA_Win_Expiro_Auto : FILE
+rule MALPEDIA_Win_Ransomexx_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9bf3ea51-503d-5f40-a69a-188866df3f7b"
+ id = "f239143d-e5d1-5c3c-aec9-a76464ab403c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.expiro"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.expiro_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ransomexx"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ransomexx_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "c555162dc1357feb9808816e071d9b9f76383f5167ecd985c2225c4cf3cc9bed"
+ logic_hash = "3b39ad6bc64b52ed616287d6ece517d9776b1298e49d7060ccab50a0c57b68b4"
score = 75
quality = 75
tags = "FILE"
@@ -167318,32 +174574,32 @@ rule MALPEDIA_Win_Expiro_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c9 6689147e 3bcd 5f 1bc0 5e }
- $sequence_1 = { 52 e8???????? 83c404 33c0 668944244c 6a04 897c2464 }
- $sequence_2 = { 0f848f000000 803d????????00 0f8582000000 803d????????00 7579 8d8c24cc010000 }
- $sequence_3 = { 8b4d00 eb02 8bcd 8d3441 0fb703 }
- $sequence_4 = { b8???????? 8d4c2414 e8???????? 8d442414 50 8d4c2434 51 }
- $sequence_5 = { 7373 7373 7353 7373 13ea 02abd9737373 }
- $sequence_6 = { bf5c000000 52 55 8d5fa5 33c0 897c241c }
- $sequence_7 = { 0fb74208 f6c303 7409 8d04c5c6234100 eb23 f6c30c }
- $sequence_8 = { 31733e 45 cf 7160 7373 7308 7373 }
- $sequence_9 = { 7373 7377 7373 7373 7373 7373 93 }
+ $sequence_0 = { 8bc3 8d75e0 e8???????? 8bf0 85f6 0f85f8020000 eb07 }
+ $sequence_1 = { 6884010000 6a08 c745fc04010000 ffd7 50 ff15???????? 8bf0 }
+ $sequence_2 = { 8b4f08 3bce 7425 8b4704 03c0 03c0 }
+ $sequence_3 = { 8bf8 85ff 752c 8d55f8 c70601000000 6a02 }
+ $sequence_4 = { c1ee0a 33fe 8bf7 8b7dfc 039c3da4feffff 03f3 }
+ $sequence_5 = { c1ee03 33fe 03df 8b7dfc 039c3db8feffff 8bb43d94feffff 03f3 }
+ $sequence_6 = { 837df801 0f8612010000 8b4df8 8b5f04 49 b801000000 d3e0 }
+ $sequence_7 = { 8b55f0 8b4508 8d4dd0 51 52 57 50 }
+ $sequence_8 = { 56 50 e8???????? 8b07 83c40c 8975fc }
+ $sequence_9 = { 39742420 0f862e010000 8d642400 837c242001 7540 837c242400 7539 }
condition:
- 7 of them and filesize <3776512
+ 7 of them and filesize <372736
}
-rule MALPEDIA_Win_Thunker_Auto : FILE
+rule MALPEDIA_Win_Fct_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ef50f850-b9ad-5639-a44d-12383e7ab286"
+ id = "2b1f29a9-1362-5741-a18b-c3a100da706f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thunker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.thunker_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fct"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fct_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "9bc1b7f9eb35f46db81209055d59765c3ce32324a39fc618186d9d412df8d09c"
+ logic_hash = "d2be9c8f676646ff8bb82d16a11f73bdaff1325b5ad55ea7931b7cc2d022d940"
score = 75
quality = 75
tags = "FILE"
@@ -167357,34 +174613,34 @@ rule MALPEDIA_Win_Thunker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89c7 50 68???????? 8dbd00feffff 57 e8???????? 83c420 }
- $sequence_1 = { e8???????? 89c6 83feff 7420 }
- $sequence_2 = { 8d8500feffff 50 56 e8???????? 89c7 83ffff }
- $sequence_3 = { e8???????? 83c40c 89c7 e8???????? 8985ecfdffff }
- $sequence_4 = { d1ea 8995e8fdffff 56 e8???????? 6a08 68???????? 68???????? }
- $sequence_5 = { 68204e0000 68d3710000 50 e8???????? 6a00 68804f1200 68dd710000 }
- $sequence_6 = { 83c40c 8d8544edffff 50 e8???????? 8985c4edffff 8b400c }
- $sequence_7 = { 7433 7c79 3df1710000 7447 }
- $sequence_8 = { 8d85f0edffff 50 57 e8???????? 83bdf0eeffff05 752e }
- $sequence_9 = { e8???????? 68???????? e8???????? 83c41c 68???????? 68???????? e8???????? }
+ $sequence_0 = { 83e801 0f8595010000 c745e438324100 e9???????? 894de0 c745e438324100 e9???????? }
+ $sequence_1 = { c3 c705????????80554100 b001 c3 68???????? e8???????? c70424???????? }
+ $sequence_2 = { e9???????? 8b1f 8d049d58634100 8b30 }
+ $sequence_3 = { 8bc6 83e03f 6bc838 894de0 8b049d50614100 f644082801 7469 }
+ $sequence_4 = { 6a04 e8???????? 83bd48fdffff08 8d8d34fdffff 8d45d8 }
+ $sequence_5 = { c70021000000 eb44 c745e002000000 c745e444324100 8b4508 8bcf 8b7510 }
+ $sequence_6 = { 50 8b04bd50614100 ff743018 ff15???????? 85c0 7404 b001 }
+ $sequence_7 = { 56 33f6 8b8650614100 85c0 740e 50 e8???????? }
+ $sequence_8 = { 660fd60f 8d7f08 8b048d84514000 ffe0 f7c703000000 7413 }
+ $sequence_9 = { 68???????? c68524fdffff00 8d4dd8 ffb524fdffff 6a01 e8???????? }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Vmzeus_Auto : FILE
+rule MALPEDIA_Win_Retefe_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6aa23f59-07e5-5545-b355-8ded6d796e51"
+ id = "f3caa6e6-3618-52a1-825b-c9f70c1ac6ab"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vmzeus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vmzeus_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.retefe"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.retefe_auto.yar#L1-L263"
license_url = "N/A"
- logic_hash = "cf57c567165f41d1d66d4120ec9208acf9ea89868aae72faa87074d6a7fc07a0"
+ logic_hash = "60c0df86aaa8e365109479b1ca3f3fca53ccf95fd2fbd33ae20876e0704e51b2"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -167396,32 +174652,51 @@ rule MALPEDIA_Win_Vmzeus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 32c0 6a4c 8d7c242c 59 f3aa }
- $sequence_1 = { 32c0 6a4c 8d7c242c 59 f3aa }
- $sequence_2 = { 6a04 58 e9???????? 32c0 6a4c 8d7c242c 59 }
- $sequence_3 = { 6a10 32c0 59 8bfb }
- $sequence_4 = { f3a4 b001 eb02 32c0 5f 5e }
- $sequence_5 = { 32c0 6a4c 8d7c242c 59 }
- $sequence_6 = { 6a10 32c0 59 8bfb f3aa }
- $sequence_7 = { 58 e9???????? 32c0 6a4c }
- $sequence_8 = { f3a4 b001 eb02 32c0 5f }
- $sequence_9 = { e9???????? 32c0 6a4c 8d7c242c }
+ $sequence_0 = { 6a00 6a01 ff15???????? 8bf0 85f6 7410 6a09 }
+ $sequence_1 = { 51 8bf8 ffd6 85c0 }
+ $sequence_2 = { 68f5000000 50 ff15???????? b801000000 }
+ $sequence_3 = { e8???????? 6a08 e8???????? 894604 }
+ $sequence_4 = { 6a24 6a5a 6a24 e8???????? 81c494000000 }
+ $sequence_5 = { 8b4e04 8901 8b4e04 33c0 83c404 394104 }
+ $sequence_6 = { 6a0e 6aeb 6a1a 6a96 6a0d }
+ $sequence_7 = { 894604 83c404 8bc6 e8???????? }
+ $sequence_8 = { 51 ff15???????? 8b95d8efffff 50 52 ff15???????? 50 }
+ $sequence_9 = { 52 e8???????? 8b4e04 8901 }
+ $sequence_10 = { 6ad1 6a1a 6a55 6ad7 6ad1 }
+ $sequence_11 = { 880c10 8b4e04 40 3b4104 }
+ $sequence_12 = { 50 e8???????? 83c408 e8???????? 99 b960f59000 }
+ $sequence_13 = { 8bec 837d0c00 7409 b80b000280 }
+ $sequence_14 = { 56 33f6 8b86a0bf4200 85c0 740e }
+ $sequence_15 = { 43 85ff 0f851fffffff 5f }
+ $sequence_16 = { 6a00 ffb42424200000 e8???????? 8b8c2418200000 }
+ $sequence_17 = { 8b0495a0bf4200 f644082801 7421 57 e8???????? }
+ $sequence_18 = { 46 85f6 7410 83fe01 75a0 }
+ $sequence_19 = { 0fb611 0fb6c0 eb17 81fa00010000 7313 8a87ccb14200 }
+ $sequence_20 = { 8b742414 85f6 7553 32c0 }
+ $sequence_21 = { 57 81fb00020000 0f8daa000000 6800080000 }
+ $sequence_22 = { 8b4218 a3???????? 8b4a08 890d???????? 8b420c }
+ $sequence_23 = { 33c0 668906 8b7c2414 8d5f20 }
+ $sequence_24 = { e8???????? 8b404c 83b8a800000000 7512 8b04bda0bf4200 807c302900 7504 }
+ $sequence_25 = { 88048d93404300 88048d923c4300 84d2 7412 }
+ $sequence_26 = { 8b7004 8b38 4e 8bce e8???????? }
+ $sequence_27 = { 8b4d08 85c9 7512 e8???????? 5e }
+ $sequence_28 = { 5f 894df0 8b34cd58224100 8b4d08 6a5a 2bce }
condition:
- 7 of them and filesize <475136
+ 7 of them and filesize <843776
}
-rule MALPEDIA_Win_Koobface_Auto : FILE
+rule MALPEDIA_Win_Skip20_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1ce15537-cef6-5c0e-a9d8-b5edfbbc6020"
+ id = "82237026-0542-5063-b5ce-819de193cfa5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.koobface"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.koobface_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.skip20"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.skip20_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "b6b79af3be74d0a2238bfa51c4162b8333d68f5a5fb85b02563c06855a5cb17a"
+ logic_hash = "21de0ff5fbd1c6f42d6edbb2c240ff9a5cc9d69d730f1c14e8fabd969797a013"
score = 75
quality = 75
tags = "FILE"
@@ -167435,32 +174710,32 @@ rule MALPEDIA_Win_Koobface_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d850cffffff 50 c745fc26000000 e8???????? 834dfcff 53 }
- $sequence_1 = { e8???????? 33db 59 889dfaf7ffff 889dfbf7ffff 899decf7ffff 899de0f7ffff }
- $sequence_2 = { 83bd34c1ffff0a 754c 8d8540c1ffff 6a41 50 }
- $sequence_3 = { 50 c745cc5cd74100 e8???????? 8b7508 bf63736de0 393e 0f85a5010000 }
- $sequence_4 = { e8???????? 50 8d8538f4ffff 50 e8???????? 8b8520f4ffff 59 }
- $sequence_5 = { e8???????? 8b8598faffff c1e803 50 8d85a4faffff 57 50 }
- $sequence_6 = { 8d8528ffffff 68???????? 50 e8???????? 83c40c 8d8528ffffff 50 }
- $sequence_7 = { 8d8528ffffff 50 e8???????? 68???????? 8d850857ffff }
- $sequence_8 = { 8d4de4 51 53 ff90e0000000 837de404 7407 }
- $sequence_9 = { 68???????? e8???????? 59 57 e8???????? 59 8b4dfc }
+ $sequence_0 = { 85c9 7448 ffc9 7432 ffc9 0f85150a0000 }
+ $sequence_1 = { 782e 3b0d???????? 7326 4863c9 488d1504fe0400 488bc1 }
+ $sequence_2 = { 0fb74c247a 0fb7542478 89442438 894c2430 89542428 488d15e62f0100 }
+ $sequence_3 = { 741c 3d00010000 740e 3d00020000 7536 4180493347 eb2f }
+ $sequence_4 = { e9???????? 4883bc24e000000000 7409 83fa01 0f842cf9ffff 83fa05 }
+ $sequence_5 = { 488db424ec000000 0f1f00 413bfc 732a 448b06 8bd7 }
+ $sequence_6 = { 418bb482a08a0100 eb07 4c8d15b4b2ffff 8bd6 81e200004000 747e 41ff4c2418 }
+ $sequence_7 = { 488d3d071f0500 ba58000000 488bcd e8???????? 4885c0 7468 }
+ $sequence_8 = { 89542428 488d15652f0100 440fb7442470 440fb74c2472 440fb7542476 4489542420 488d0db72f0100 }
+ $sequence_9 = { 89442438 0fb74c247a 894c2430 0fb7542478 89542428 488d15ae290100 }
condition:
- 7 of them and filesize <368640
+ 7 of them and filesize <794624
}
-rule MALPEDIA_Win_Netwire_Auto : FILE
+rule MALPEDIA_Win_Acronym_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7e349eff-bed6-58da-b13d-023150840eee"
+ id = "3a02b0db-7dab-59f7-8844-7d3e20bbfec7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.netwire"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.netwire_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acronym"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.acronym_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "d56dccb0a24c96c7c7e1e50a683192f0a074d28ee0f4b72f3b3f8446384ae89a"
+ logic_hash = "f0c8874a39c6e7d48d0efb9f6335d89bb8e6f6e657bab8b7e1fc238f6642ecb8"
score = 75
quality = 75
tags = "FILE"
@@ -167474,32 +174749,32 @@ rule MALPEDIA_Win_Netwire_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c7042449000000 e8???????? c7042446000000 e8???????? c7042400000000 e8???????? }
- $sequence_1 = { c7042401000080 e8???????? c7042410000000 e8???????? }
- $sequence_2 = { c744240c00000000 c744240800000000 c744240400000000 c7042408000000 e8???????? 83ec14 }
- $sequence_3 = { 740c c7042400000000 e8???????? c70424???????? e8???????? }
- $sequence_4 = { e8???????? a3???????? c7042440000000 e8???????? }
- $sequence_5 = { c70424d0070000 e8???????? e9???????? e8???????? }
- $sequence_6 = { c744241000000000 c744240c00000000 c744240800000000 c744240400000000 c7042408000000 e8???????? 83ec14 }
- $sequence_7 = { c744242c00000000 c744242800000000 c744242400000000 c7442420fdffffff c744241c00000000 c744241800000000 }
- $sequence_8 = { c7042400000000 e8???????? c70424???????? e8???????? }
- $sequence_9 = { e8???????? eb11 c7042496000000 e8???????? }
+ $sequence_0 = { 89550c 8b4510 034508 8a08 884dff 8b5510 03550c }
+ $sequence_1 = { 8b55e8 8a45f4 88040a ebac 33c9 75fc 8be5 }
+ $sequence_2 = { 50 ff15???????? 8945f8 8b4dfc 8b5110 52 8b45fc }
+ $sequence_3 = { e8???????? 8bc8 e8???????? 0fb6d0 85d2 0f85d4000000 8b450c }
+ $sequence_4 = { c745fc00000000 eb09 8b45fc 83c001 8945fc 8b4df4 83c104 }
+ $sequence_5 = { 6a00 6a00 ff15???????? b901000000 85c9 0f84fd000000 c745f000000000 }
+ $sequence_6 = { 2b55bc 8955b8 8b45b8 8945cc 33c9 75fc 8b55dc }
+ $sequence_7 = { 8b0c90 83c101 8b55f4 8b45f0 0fb754505e 8b45ec 69c008040000 }
+ $sequence_8 = { 8b4508 50 e8???????? 83c410 ebaa 8b45c4 69c0c51d0000 }
+ $sequence_9 = { 69d208040000 8b7508 8d941660b10000 89048a 8b45f4 8b4df0 0fb754411c }
condition:
- 7 of them and filesize <416768
+ 7 of them and filesize <466944
}
-rule MALPEDIA_Win_Byeby_Auto : FILE
+rule MALPEDIA_Win_Zeroaccess_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "74fc8a87-5c7b-524e-8e78-621f0d855f26"
+ id = "dc18e525-3177-5057-b2b8-44deb0459882"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.byeby"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.byeby_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeroaccess"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeroaccess_auto.yar#L1-L151"
license_url = "N/A"
- logic_hash = "ea138eeca75e1ffbb323be9c4364fb51ef613b1a9fd77855f97073778ad7174f"
+ logic_hash = "4423d17d4505fc4e1d7ad61f77b371f17ded461805f238fd1e8f686647ad897a"
score = 75
quality = 75
tags = "FILE"
@@ -167513,32 +174788,37 @@ rule MALPEDIA_Win_Byeby_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 68???????? 8d45f0 c745f0f4320110 }
- $sequence_1 = { e8???????? 8b7df0 83c40c 037e74 c7467400000000 eb03 }
- $sequence_2 = { 8bf0 53 ff742430 6a00 6a00 }
- $sequence_3 = { 50 8b8528e5ffff 0f94c1 898d3ce5ffff 8b8d24e5ffff 8b048518ab0110 ff3401 }
- $sequence_4 = { 8b8528e5ffff 8b048518ab0110 ff3401 ff15???????? 8bb540e5ffff 8bbd34e5ffff 85c0 }
- $sequence_5 = { 8d84245c020000 50 c78424600200005630564d c78424640200005130394e ffd7 40 50 }
- $sequence_6 = { 8b35???????? 8d442410 50 ff35???????? }
- $sequence_7 = { 7309 8b04c5e84e0110 5d c3 33c0 }
- $sequence_8 = { 0f8641010000 8b4c2420 83c714 8bff 837ff005 0f85fa000000 0fb707 }
- $sequence_9 = { 3b0cc510900110 7427 40 83f82d 72f1 8d41ed }
+ $sequence_0 = { ff15???????? 85c0 7408 ff15???????? eb02 }
+ $sequence_1 = { 56 56 6a20 6a05 }
+ $sequence_2 = { bf03000040 eb05 bf010000c0 85ff }
+ $sequence_3 = { 6a01 8d45f4 50 ff7308 ff15???????? 85c0 }
+ $sequence_4 = { 6a04 68???????? 6a10 68???????? 68060000c8 ff7708 ff15???????? }
+ $sequence_5 = { ff15???????? 85c0 7407 b8e3030000 }
+ $sequence_6 = { 56 6a10 8945e8 8d45e4 }
+ $sequence_7 = { e8???????? 50 6819000200 8d45f8 }
+ $sequence_8 = { 3bc1 7604 83c8ff c3 }
+ $sequence_9 = { 50 68???????? 6889001200 8d45fc }
+ $sequence_10 = { 56 8d45f8 50 ff15???????? 6a01 8d45f8 50 }
+ $sequence_11 = { 33c0 48 83c9ff c744242804000000 48 }
+ $sequence_12 = { 85db 741f 8b4304 49 }
+ $sequence_13 = { 7615 83780815 750f c705????????01000000 }
+ $sequence_14 = { 48 83ec20 41 8bf9 48 8bd9 }
condition:
- 7 of them and filesize <253952
+ 7 of them and filesize <172032
}
-rule MALPEDIA_Win_Bredolab_Auto : FILE
+rule MALPEDIA_Win_Graphite_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0b33903d-ad64-555d-936e-aab5345d2509"
+ id = "22d6771d-6e02-5bad-92aa-7abf2f0540bc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bredolab"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bredolab_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphite"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graphite_auto.yar#L1-L109"
license_url = "N/A"
- logic_hash = "adde67d05e7a2d047afa70901aa11c567b41ad799d4fe97c3d9648b79067c4f5"
+ logic_hash = "fac8314c02add0a1a3fcfc7bc6cd359f12eb58a8246911250bf475b51a803e3f"
score = 75
quality = 75
tags = "FILE"
@@ -167552,32 +174832,32 @@ rule MALPEDIA_Win_Bredolab_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4518 89442410 8b4514 8944240c c744240800000000 }
- $sequence_1 = { baffe8a435 89d1 31d2 f7f1 81c200e1f505 89542408 c7442404???????? }
- $sequence_2 = { 0f85e8000000 ba???????? 90 31c0 6690 8a8800500010 300c02 }
- $sequence_3 = { 57 56 53 b86c140000 }
- $sequence_4 = { f2ae f7d1 8d41ff 81c40c090000 }
- $sequence_5 = { 8b8318120000 85c0 0f8e88000000 c783381200000c000000 }
- $sequence_6 = { 0f85c5000000 8b9560feffff 8b02 3b45dc 7437 }
- $sequence_7 = { 5e 5f c9 c3 8db526ffffff b910000000 }
- $sequence_8 = { 8b8a1c120000 85c9 0f8ee7000000 31ff 31c0 8d9d20f7ffff 89b514f7ffff }
- $sequence_9 = { 85c0 753b 0fb78394010000 338396010000 0d00000080 baffe8a435 89d1 }
+ $sequence_0 = { 7513 33d2 e8???????? 84c0 }
+ $sequence_1 = { 33d2 e8???????? 84c0 74e4 }
+ $sequence_2 = { 81e2ff030000 81e1bf030000 83c940 c1e10a }
+ $sequence_3 = { 7513 33d2 e8???????? 84c0 74e4 }
+ $sequence_4 = { 81e1bf030000 83c940 c1e10a 0bca }
+ $sequence_5 = { ff15???????? 33c0 eb05 b801010000 }
+ $sequence_6 = { 85db 7513 33d2 e8???????? 84c0 74e4 }
+ $sequence_7 = { 85db 7513 33d2 e8???????? 84c0 }
+ $sequence_8 = { 85db 7513 33d2 e8???????? }
+ $sequence_9 = { 81e2ff030000 81e1bf030000 83c940 c1e10a 0bca }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Observer_Stealer_Auto : FILE
+rule MALPEDIA_Win_Babylon_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "536559c4-9574-5591-915f-4694149d7210"
+ id = "520c4cbb-7168-5cad-9ac5-61fcc34e0523"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.observer_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.observer_stealer_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.babylon_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.babylon_rat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "7a05fc963c0665c59a8fed1a8fc722896fb246e3248a23ceef5fd4c8486da3c7"
+ logic_hash = "d4eca63a433742f88d4570a738d70afc76a66ddfd0669e9e8d639b4f32143e21"
score = 75
quality = 75
tags = "FILE"
@@ -167591,32 +174871,32 @@ rule MALPEDIA_Win_Observer_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c1ea03 0fb60c02 8bc6 83e007 0fabc1 8b442414 }
- $sequence_1 = { 8b5c2418 f6c301 746c 8b3e 85ff 7466 8b5e04 }
- $sequence_2 = { 50 ff15???????? 8b4c2460 8d442440 50 e8???????? 8d4c2440 }
- $sequence_3 = { e8???????? 68???????? 8d8d54ffffff e8???????? 68???????? 8d8d6cffffff }
- $sequence_4 = { 59 eb3b 55 8b6b04 2bee c1fd02 56 }
- $sequence_5 = { 85f6 740b 83feff 0f859a000000 eb6c 8b1c8d287e4300 }
- $sequence_6 = { 8d8d60ffffff e8???????? 59 83781408 7202 8b00 }
- $sequence_7 = { 8b442420 8918 5f 5e 5d 5b 83c40c }
- $sequence_8 = { 85d2 7912 f7da e8???????? 6a2d 8d48fe 58 }
- $sequence_9 = { 8d7c2468 894c2464 885c2450 ab ab ab ab }
+ $sequence_0 = { ff75ec 8908 e8???????? 83c40c 85c0 7407 8b4808 }
+ $sequence_1 = { ff761c 6a44 57 e8???????? 83c418 eb36 6a00 }
+ $sequence_2 = { f6c23e 0f84ac000000 8bc3 83e01a 663bc3 740e 8bc3 }
+ $sequence_3 = { ffb50cffffff ffb5f0feffff e8???????? 8bc8 e8???????? 660f28c8 eb54 }
+ $sequence_4 = { e8???????? 56 e8???????? 59 50 56 8d8dc8fbffff }
+ $sequence_5 = { ff15???????? 50 680a190000 e9???????? e8???????? 8945f8 59 }
+ $sequence_6 = { ff36 0fb6c9 51 ff761c ff7510 ff7508 e8???????? }
+ $sequence_7 = { c645fc01 85c0 7404 8b10 eb02 8bd3 8b45e8 }
+ $sequence_8 = { ff7708 6a77 53 e8???????? ff751c 53 e8???????? }
+ $sequence_9 = { ff7514 ff7510 57 e8???????? 83c40c eb79 53 }
condition:
- 7 of them and filesize <614400
+ 7 of them and filesize <1604608
}
-rule MALPEDIA_Win_Rorschach_Auto : FILE
+rule MALPEDIA_Win_Ragnarok_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1c4aea68-8f40-596d-a63a-efb95cb498a7"
+ id = "a9bce1d7-5883-5de4-9b9b-a02072e8d068"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rorschach"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rorschach_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ragnarok"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ragnarok_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "0cdb3537df7f12a9076109ea202e9af8c6db5ccfaaca59c4a71971579385ead3"
+ logic_hash = "4922b92876243cdefed80b6c256ba49e22b0c6eaa1ad052381af99f572200bea"
score = 75
quality = 75
tags = "FILE"
@@ -167630,32 +174910,32 @@ rule MALPEDIA_Win_Rorschach_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33d2 488d8df8020000 e8???????? 88850e030000 b26e 488d8df8020000 e8???????? }
- $sequence_1 = { f65d7f 488d15ece30000 4c8d05e9e30000 488955df 488d05d2e30000 488955e7 488945bf }
- $sequence_2 = { f5 66d3f7 66c1f703 d3d7 4801e3 d2f0 c0f807 }
- $sequence_3 = { f30f7f4de0 660f6f05???????? f30f7f45f0 660f6f0d???????? f30f7f4d00 c74510771a771b c6451477 }
- $sequence_4 = { 0c40 8845df e8???????? 4c8d05e8180700 488d55c0 488d4da0 e8???????? }
- $sequence_5 = { 33c0 48894310 48c7431807000000 668903 488b4c2458 4833cc e8???????? }
- $sequence_6 = { 33d2 488d4da8 e8???????? 8845b4 b272 488d4da8 e8???????? }
- $sequence_7 = { e8???????? 88851e0b0000 b265 488d8de0080000 e8???????? 88851f0b0000 33d2 }
- $sequence_8 = { e8???????? c60000 ba0f000000 488d4d99 e8???????? c60000 488d4d99 }
- $sequence_9 = { f6d4 660fbec0 0f98c0 488d7f01 0fb6c0 0f94c4 88f0 }
+ $sequence_0 = { c1f906 57 6bf838 894df4 8b048d28754300 8b540718 8955ec }
+ $sequence_1 = { 884219 0fb6461a 88421a 0fb6461b 88421b 0fb6461c 88421c }
+ $sequence_2 = { c1e908 0fb6c9 c1e308 c1ea10 0fb689105c4300 33d9 8b4dfc }
+ $sequence_3 = { 8bc8 2345a4 f7d1 234d9c 0bc8 c145980a }
+ $sequence_4 = { 0fb689104b4300 33d9 0fb6487e c1e308 0fb689104b4300 33d9 0fb6487d }
+ $sequence_5 = { 8b7d08 0fb6ca 333c8d105d4300 8bcf 897d08 334814 894d08 }
+ $sequence_6 = { 8b75dc 33f9 037dfc 81c64efd53a9 037d98 c1c209 }
+ $sequence_7 = { c1c205 8b7dac 0bc8 034dd8 81c7dcbc1b8f 0355bc 03f9 }
+ $sequence_8 = { 8b048528754300 c644032a0a 8b5d08 747f 8b45f8 8b5df0 8b048528754300 }
+ $sequence_9 = { 8bf8 89bdb8feffff ff36 68???????? ff35???????? e8???????? 8b4810 }
condition:
- 7 of them and filesize <3921930
+ 7 of them and filesize <483328
}
-rule MALPEDIA_Win_Predator_Auto : FILE
+rule MALPEDIA_Win_Bart_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "139b7e6c-7d6f-5725-bc06-83e05af2728a"
+ id = "1691d219-2287-5770-a9af-369cb19fd25c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.predator"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.predator_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bart"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bart_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "4f1faf378ed80607ad7505f3b525c8d2a5bbf8d81c1cadcdd453ab7a1d609878"
+ logic_hash = "20a38c1c6b8b98b8d85839077c1f03f4679fb05ea3fd09bb3acf392b4f9ee60a"
score = 75
quality = 75
tags = "FILE"
@@ -167669,32 +174949,32 @@ rule MALPEDIA_Win_Predator_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 55 8bec 83ec18 8bc2 56 8bf1 8d4dfd }
- $sequence_1 = { 80c230 8811 85c0 75f2 51 8d45fd }
- $sequence_2 = { 8d4dfd 57 6a0a 5f 85c0 7916 }
- $sequence_3 = { 03c2 8bce 50 e8???????? 5f 8bc6 5e }
- $sequence_4 = { 7508 83c8ff e9???????? ff75ec e8???????? }
- $sequence_5 = { 83ec18 8bc2 56 8bf1 8d4dfd }
- $sequence_6 = { ff75ec e8???????? 59 8bf0 }
- $sequence_7 = { 7508 83c8ff e9???????? ff75ec e8???????? 59 8bf0 }
- $sequence_8 = { 894e08 89560c 834dfcff 8b4df4 64890d00000000 5f 5e }
- $sequence_9 = { 8b00 57 03c2 8bce }
+ $sequence_0 = { 8b0483 3bd0 772e 7205 80c1ff 79e8 33c9 }
+ $sequence_1 = { 8b0433 03c2 03c1 3bc2 7404 1bc9 }
+ $sequence_2 = { 8a18 894dd0 8955c8 8945cc 57 85f6 }
+ $sequence_3 = { 660fd6459c e8???????? 83c410 8d8570ffffff 33c9 ba07000000 }
+ $sequence_4 = { e8???????? 8b7598 8d4d9c 8b5590 0fb606 }
+ $sequence_5 = { 8b4485dc d3e8 88043a 0fbed3 3bd6 7cde 8bbd58ffffff }
+ $sequence_6 = { 7868 8bc8 0fbec2 8b5508 894c2418 8d1482 8a44240e }
+ $sequence_7 = { 84db 0f8ed3020000 0fb6d3 8bc7 899564ffffff 0b08 8d4004 }
+ $sequence_8 = { 8bca e8???????? 8b4dfc 83c438 33cd 5f 5e }
+ $sequence_9 = { 0f88ff000000 8b7df4 83c706 42 }
condition:
- 7 of them and filesize <2211840
+ 7 of them and filesize <163840
}
-rule MALPEDIA_Win_Blackenergy_Auto : FILE
+rule MALPEDIA_Win_Bootwreck_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5db0ecdd-a93d-527c-8567-cf3a04744f9e"
+ id = "7e23b82b-3bdc-58cd-906f-3ab5825b9ffb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackenergy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blackenergy_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bootwreck"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bootwreck_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "0197d7c7455032dc4a706fe02d56c8be876c2f6b4f29a6658284a54a2993239d"
+ logic_hash = "49dbec8ae0163fe1b10f7b427af3210b6bbd81884139d209319f2b77e78ba995"
score = 75
quality = 75
tags = "FILE"
@@ -167708,32 +174988,32 @@ rule MALPEDIA_Win_Blackenergy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { bb01000000 eb02 03d8 8bc2 e9???????? 8b4df4 014dd8 }
- $sequence_1 = { 39750c 740c 56 56 ff7508 ff550c }
- $sequence_2 = { 8b7df4 8b75f0 8b4d08 f3a4 a1???????? 33c9 3bc1 }
- $sequence_3 = { e8???????? 2bc6 3bc7 760f 6bd20a 47 e8???????? }
- $sequence_4 = { 0f848f000000 53 8d45f0 50 8d45d8 50 }
- $sequence_5 = { 58 e8???????? 85c0 75ae 5e 5f c9 }
- $sequence_6 = { 85c0 7441 8b5dc8 8b5b28 85db 7427 8b4de4 }
- $sequence_7 = { 33f6 56 6810000002 6a03 56 6a01 6800000080 }
- $sequence_8 = { 8b583c 03d8 895dc8 8b4334 8945e0 33f6 46 }
- $sequence_9 = { 50 ff15???????? 50 ff5508 6a02 }
+ $sequence_0 = { 33ff 897dfc 3b1cfde0c18100 7409 47 897dfc }
+ $sequence_1 = { 8d642428 0f8409000000 660fbec2 86c7 8b4510 55 660fb6da }
+ $sequence_2 = { 85b178373e03 025ad9 7efa 99 18c7 7e55 }
+ $sequence_3 = { c74424147d978300 682dedfcaa 9c 89442418 9c 9c ff742420 }
+ $sequence_4 = { ee 5b 7f3f 99 68e43b3fa7 6c }
+ $sequence_5 = { 876c2428 66891c24 688106ab60 896c2428 5d 66896c2404 bd???????? }
+ $sequence_6 = { 8955fc f9 8d9b00000000 30e1 37 d4b7 8b4d08 }
+ $sequence_7 = { ff4638 88c3 66f7d6 b37c 5b 660fb6f9 5f }
+ $sequence_8 = { c25400 c7042400000000 60 8774241c 8d64241c 0f8103500500 }
+ $sequence_9 = { 8d041f f7c5036c87b2 99 84ed f8 60 6681fb744d }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <10821632
}
-rule MALPEDIA_Win_Rustock_Auto : FILE
+rule MALPEDIA_Win_Sanny_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cb44bdc8-a730-56ac-98ad-0553c4475f0d"
+ id = "de370068-b36d-54a3-8d87-5388d41e6079"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rustock"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rustock_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sanny"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sanny_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "5fff7e7d2c26e2013c1d3a65535e3ac75dc9cd45cc7a0c04309e438d2a86951e"
+ logic_hash = "d17095442c6476759b49de20e09af803b9389d5106c74ad1d4cc2616aa104b23"
score = 75
quality = 75
tags = "FILE"
@@ -167747,32 +175027,32 @@ rule MALPEDIA_Win_Rustock_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d6424fc 892c24 31ed 01e5 8d6424e4 50 }
- $sequence_1 = { 031d???????? 21db 5e 5a }
- $sequence_2 = { 8bd8 85db 7439 8b4dc0 33c0 8bfb 8bd1 }
- $sequence_3 = { 83c604 56 53 ff15???????? 53 }
- $sequence_4 = { 833d????????00 7421 56 e8???????? 85c0 59 75ac }
- $sequence_5 = { 50 ff7520 e8???????? 83c418 8945cc 3bc7 74d4 }
- $sequence_6 = { ff750c e8???????? 68e8030000 ff15???????? e8???????? 8bf8 }
- $sequence_7 = { 59 8945c4 83f8ff 7507 33c0 e9???????? 3b4520 }
- $sequence_8 = { ebb5 7402 ebd3 8b1c24 68???????? }
- $sequence_9 = { 014514 a1???????? 83f802 0f84de010000 3bc7 }
+ $sequence_0 = { 51 8bcb e8???????? 8b5310 68???????? 8d442a08 }
+ $sequence_1 = { 8b842430060000 8d742410 8d5901 b987000000 53 81ec1c020000 8bfc }
+ $sequence_2 = { ebd3 53 55 56 57 }
+ $sequence_3 = { 52 68???????? 56 e8???????? 8b44244c }
+ $sequence_4 = { 8bc2 c1c60a 03f1 f7d0 0bc6 33c1 }
+ $sequence_5 = { ae 40 00bcae4000e0ae 40 0023 d18a0688078a }
+ $sequence_6 = { 55 68???????? 55 e8???????? 8b4c2424 83c410 55 }
+ $sequence_7 = { 663918 747f 668b11 6683fa41 720c }
+ $sequence_8 = { f3ab 8b0d???????? aa 898c2408010000 b906000000 33c0 8dbc240d010000 }
+ $sequence_9 = { 8b44241c 8d9424dc000000 52 50 ffd5 b925000000 33c0 }
condition:
- 7 of them and filesize <565248
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Batchwiper_Auto : FILE
+rule MALPEDIA_Win_Thunderx_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cb044b8c-027b-5368-bd79-45da5d915947"
+ id = "bd791591-7f4e-54f3-bf78-0dd306ad53b2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.batchwiper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.batchwiper_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thunderx"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.thunderx_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "14983b1d6532d433e6ad6924f17da812f5983b6eabd0fde8fd8892a9d3b6fb0b"
+ logic_hash = "088c8f2e806c5cf8226a8db8f2cdc4a3ddd2da7bdf68b4f2265db3773cd1c842"
score = 75
quality = 75
tags = "FILE"
@@ -167786,32 +175066,32 @@ rule MALPEDIA_Win_Batchwiper_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c001 8bce c1e908 330c9de8904000 }
- $sequence_1 = { 8b0424 894510 8b442408 894514 8b442404 }
- $sequence_2 = { 8b442408 894514 8b442404 894518 8d44240c }
- $sequence_3 = { e8???????? 50 31db 3b1c24 756b }
- $sequence_4 = { 89d8 e8???????? 89c3 83fb01 7531 ff35???????? }
- $sequence_5 = { 83fb01 7531 ff35???????? ba???????? e8???????? 8b15???????? e8???????? }
- $sequence_6 = { e8???????? 89c3 83fb01 7531 ff35???????? ba???????? }
- $sequence_7 = { e8???????? 8d0d28b14000 5a e8???????? 8b15???????? ff35???????? e8???????? }
- $sequence_8 = { ba???????? e8???????? 8d0d28b14000 5a e8???????? 8b15???????? ff35???????? }
- $sequence_9 = { c705????????02000000 893d???????? c705????????dd424000 c705????????80464000 c705????????da464000 c705????????00474000 }
+ $sequence_0 = { 50 e8???????? c9 c3 c705????????58004200 b001 c3 }
+ $sequence_1 = { b9???????? e8???????? 0fb60d???????? 84c0 6a01 58 0f45c8 }
+ $sequence_2 = { 51 53 8b5d10 8bd1 56 57 8955fc }
+ $sequence_3 = { 8d8d9cfbffff e8???????? 8d8d84fbffff e8???????? 8d8d6cfbffff e8???????? }
+ $sequence_4 = { 6a02 8d44241c 895c2424 50 53 53 }
+ $sequence_5 = { e8???????? 84c0 7558 83c718 3b7da0 75ea 8d4de0 }
+ $sequence_6 = { 89459c 8945a0 e8???????? 84c0 0f858d000000 395f10 }
+ $sequence_7 = { 03d1 8b0c85701b4200 8a0433 43 88440a2e 8b4dd8 8b55b4 }
+ $sequence_8 = { 8932 897204 897208 5e 5d c20400 6a18 }
+ $sequence_9 = { 8d8dd0fdffff e8???????? 8d4dac c645fc06 }
condition:
- 7 of them and filesize <270336
+ 7 of them and filesize <319488
}
-rule MALPEDIA_Win_Strifewater_Rat_Auto : FILE
+rule MALPEDIA_Win_Matsnu_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a7c325df-e174-5ac3-901f-1a7ff4cd21d1"
+ id = "c9a7bdf6-1deb-5130-82f0-9b1058e504ad"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.strifewater_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.strifewater_rat_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.matsnu"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.matsnu_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "d8e033b18ffd1945f4234d82e35ef039ad0fd09fec88b912a93b43fc77397cc7"
+ logic_hash = "e4de93852a1879de4977ea1cd375165f9dcf6c32de8c352e98b35973d623758e"
score = 75
quality = 75
tags = "FILE"
@@ -167825,32 +175105,32 @@ rule MALPEDIA_Win_Strifewater_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83630800 488d0d10400500 48890b c6434400 448ac6 488bd0 }
- $sequence_1 = { 4183c9ff 4d8bc7 66448926 4889742420 8d4a03 ff15???????? f7d8 }
- $sequence_2 = { 663b3d???????? 0f8559010000 663b1d???????? 0f854c010000 66443b35???????? 0f853e010000 }
- $sequence_3 = { 488d05bb720600 488bf9 488901 8bda 488b4910 e8???????? 488b4f18 }
- $sequence_4 = { 4803c0 480101 4803db eb22 498b06 498bce }
- $sequence_5 = { 488bf8 48898424c0000000 488b4e08 4885c9 7509 488d15fc350900 eb0d }
- $sequence_6 = { 0903 e9???????? 488d05d8940500 0f100f 0f1006 f30f7f4dd0 f30f7f45e0 }
- $sequence_7 = { 418d45ff 410fb68c8332b30800 410fb6b48333b30800 8bd9 }
- $sequence_8 = { 498b4e08 4c8d4508 33d2 ff15???????? 488b7508 4c8d4530 488bce }
- $sequence_9 = { 884dd8 488bd3 482bd7 48d1fa 4883fa0f 7426 41b001 }
+ $sequence_0 = { e9???????? 8985bcfbffff 83bdb0fbffff01 0f8588000000 8b85bcfbffff 8985c4fbffff 8b85c0fbffff }
+ $sequence_1 = { eb04 c647023d 837d1003 7213 }
+ $sequence_2 = { eb04 c647023d 837d1003 7213 31c0 8a4602 243f }
+ $sequence_3 = { 8b45e0 3b450c 0f8391000000 c745e800000000 }
+ $sequence_4 = { 750f c785a4fbffff02000000 e9???????? 8985bcfbffff 83bdb0fbffff01 0f8588000000 8b85bcfbffff }
+ $sequence_5 = { 85c0 0f84a6000000 8945fc 8b45e0 3b450c }
+ $sequence_6 = { c78570f3ffff00000000 c78574f3ffff00000000 c78578f3ffff00000000 c7857cf3ffff00000000 }
+ $sequence_7 = { 751d ff45da ba00000000 8b45da }
+ $sequence_8 = { 3b45ba 7228 8b7d08 8b4704 3b45ba 751d }
+ $sequence_9 = { 89e5 81ec18020000 c785e8fdffff00000000 c785ecfdffff00000000 c785f0fdffff00000000 }
condition:
- 7 of them and filesize <1552384
+ 7 of them and filesize <606992
}
-rule MALPEDIA_Win_Ddkeylogger_Auto : FILE
+rule MALPEDIA_Win_Fuxsocy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "32af4d2e-12e0-5512-a4a7-e09c0d4c8550"
+ id = "acae4e77-3091-5877-bdf5-d5242a4de3aa"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ddkeylogger"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ddkeylogger_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fuxsocy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fuxsocy_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "03458a2b11f7d3c85fa0851f46b24d084521ba159cb6b960088359db4227b8a0"
+ logic_hash = "7715515075d3596588ef1486b8f0b7f8a98d13af15afc29c2d4231048e4e16d8"
score = 75
quality = 75
tags = "FILE"
@@ -167864,34 +175144,34 @@ rule MALPEDIA_Win_Ddkeylogger_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bf7 83e61f c1e606 03348580ee4500 }
- $sequence_1 = { 51 894df4 8955fc 8945f8 e8???????? 83c408 }
- $sequence_2 = { 8bc8 c1e902 f3a5 8bc8 8d95e8faffff 83e103 52 }
- $sequence_3 = { 0fb64f08 80cbff d2e3 40 f6d3 205c30ff 0fb64f08 }
- $sequence_4 = { 0405 c3 f6c20c 7409 f6c208 0f95c0 }
- $sequence_5 = { 52 50 8b81e0000000 ffd0 837df804 75e8 }
- $sequence_6 = { c745fc00000000 e8???????? 83c40c 8d85ccfaffff 50 8d8df0fdffff 51 }
- $sequence_7 = { 50 57 ffd3 8945bc 8d45c8 50 }
- $sequence_8 = { ff248d4cf74000 8d48cf 80f908 7706 6a03 }
- $sequence_9 = { 6bc930 8975e0 8db1c0624100 8975e4 }
+ $sequence_0 = { 72f0 8bcf e8???????? 5f 5e 5d ff74240c }
+ $sequence_1 = { 8b4e08 890491 ff06 eb02 891e 5b 5f }
+ $sequence_2 = { 6689442420 8d442422 53 50 894c2420 885c2413 895c2418 }
+ $sequence_3 = { 85c0 7426 68???????? 68???????? ff15???????? 50 ff15???????? }
+ $sequence_4 = { 6804010000 8d85ccfdffff 50 ff15???????? 68???????? 8d85ccfdffff 50 }
+ $sequence_5 = { e8???????? 59 59 eb4b 807e0200 7404 85db }
+ $sequence_6 = { c745f808020000 ff15???????? 85c0 753d 8d85e8fdffff 50 }
+ $sequence_7 = { 33f6 ff15???????? 8bc8 e8???????? 85c0 7426 68???????? }
+ $sequence_8 = { 68???????? 50 8d54241c 8d4c2424 e8???????? 83c40c 83c310 }
+ $sequence_9 = { 50 ff74241c 33c9 ff74242c 41 c744242c32000000 c744246804000000 }
condition:
- 7 of them and filesize <808960
+ 7 of them and filesize <131072
}
-rule MALPEDIA_Win_Badnews_Auto : FILE
+rule MALPEDIA_Win_Badhatch_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "82b67459-b37a-5597-851f-c5e10ae625fd"
+ id = "e8145868-3ca1-5c30-b22c-ef0d5f024b54"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badnews"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.badnews_auto.yar#L1-L214"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badhatch"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.badhatch_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "bc13ea27737db6028c742e92e044e676e8322f3710d6ba3506e9723f27d2a819"
+ logic_hash = "a465c1cdccc061411fd4300f0446fb5369592ae409bf62acf36666de581c3980"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -167903,44 +175183,32 @@ rule MALPEDIA_Win_Badnews_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? 83c404 68???????? 6804010000 ff15???????? }
- $sequence_1 = { c78534ffffff47657457 c78538ffffff696e646f c7853cffffff77546578 66c78540ffffff7457 }
- $sequence_2 = { c705????????55736572 c705????????33322e64 66c705????????6c6c c605????????00 }
- $sequence_3 = { eb02 33c9 c0e004 02c1 3423 c0c003 }
- $sequence_4 = { 8945fc 53 56 57 8d8534ffffff }
- $sequence_5 = { 55 8bec 8b450c 3d01020000 }
- $sequence_6 = { d1f9 68???????? 03c9 51 }
- $sequence_7 = { 68???????? 6a1a 68???????? 57 }
- $sequence_8 = { 6a02 68???????? 50 a3???????? }
- $sequence_9 = { 8bf0 56 ff15???????? 50 6a40 }
- $sequence_10 = { 56 ffd3 85c0 7403 83c608 8a06 }
- $sequence_11 = { 57 6a00 6880000000 6a04 6a00 6a01 6a04 }
- $sequence_12 = { ff15???????? 85c0 7405 83c004 }
- $sequence_13 = { 68???????? ff15???????? b8???????? 83c424 8d5002 668b08 }
- $sequence_14 = { e8???????? 68???????? 8d45f4 c745f4682f0110 50 e8???????? cc }
- $sequence_15 = { 83e61f c1f805 c1e606 c1e910 c0e107 8b1485d0a70110 }
- $sequence_16 = { 8d8d54ffffff 8d5101 90 8a01 }
- $sequence_17 = { 7414 8bc2 c1f805 83e21f c1e206 031485d0a70110 }
- $sequence_18 = { 8b048dd0a70110 4e 807d1300 8955e4 c64418050a }
- $sequence_19 = { 58 668986b8000000 668986be010000 c7466848960110 }
- $sequence_20 = { 2bc2 8bf0 d1fe 6a55 ff34f5e0470110 ff7508 e8???????? }
- $sequence_21 = { 41 84c0 75f9 2bce 741c 804415ec03 }
+ $sequence_0 = { 53 6a00 50 ffd7 56 6a00 ff35???????? }
+ $sequence_1 = { 8b7730 59 59 8975f0 85f6 7514 }
+ $sequence_2 = { 8bc7 99 0145e0 1155e4 eb0e }
+ $sequence_3 = { ff7618 ff15???????? 85c0 740e ff15???????? 8945e4 e9???????? }
+ $sequence_4 = { 8bf0 59 85f6 750e eb40 ff15???????? 8bf0 }
+ $sequence_5 = { 8945e4 ff45d0 e9???????? 395de4 0f8574060000 68???????? ff7618 }
+ $sequence_6 = { 50 ff15???????? 85c0 0f8524010000 8d45ec 50 8d8594f5ffff }
+ $sequence_7 = { 8bd8 48 83e90c 85db 75f1 5b }
+ $sequence_8 = { 5e c9 c3 55 8bec 83e4f8 81ec38020000 }
+ $sequence_9 = { 50 ff15???????? 8945ec 3bc3 7509 }
condition:
- 7 of them and filesize <612352
+ 7 of them and filesize <156672
}
-rule MALPEDIA_Win_Parasite_Http_Auto : FILE
+rule MALPEDIA_Win_Forest_Tiger_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8396c4fe-e904-583d-8bc2-2a1b61b79bee"
+ id = "2947155f-bcbc-5d27-b13d-2d3d872fe248"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.parasite_http"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.parasite_http_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.forest_tiger"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.forest_tiger_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "37851542b45d72ed626359d2a060741c909807319056a1d140e5557e76485a87"
+ logic_hash = "baf01183ad62d9cfadf21ee10ad4e3a50b3d3f1c1788ceb5d46999aa5751e1b0"
score = 75
quality = 75
tags = "FILE"
@@ -167954,32 +175222,32 @@ rule MALPEDIA_Win_Parasite_Http_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 b900040000 e8???????? 8bf8 85ff 0f848a000000 56 }
- $sequence_1 = { 50 33c0 895dfc 53 53 }
- $sequence_2 = { 884df2 8d4dbc 66895dbe 668955c0 66895dc4 668945ce 66c745ec5669 }
- $sequence_3 = { e8???????? 59 85db 7407 8bcb e8???????? 8b45f0 }
- $sequence_4 = { 6a36 6689460a 58 6a34 6689460e 58 57 }
- $sequence_5 = { e8???????? b9???????? 8bd8 e8???????? 33d2 8bcb }
- $sequence_6 = { 57 8bf9 b9???????? e8???????? b9???????? 8bf0 e8???????? }
- $sequence_7 = { 57 e8???????? 03c6 50 52 }
- $sequence_8 = { 740f 8d4dfc 51 51 51 50 }
- $sequence_9 = { 53 ffd0 8bcf e8???????? 8bce e8???????? 8bcb }
+ $sequence_0 = { 833f01 0f94c0 84c0 7407 }
+ $sequence_1 = { 833f01 0f94c0 84c0 7407 e8???????? eb05 }
+ $sequence_2 = { 833f01 0f94c0 84c0 7407 e8???????? }
+ $sequence_3 = { 833f01 0f94c0 84c0 7407 e8???????? eb05 e8???????? }
+ $sequence_4 = { 6a0c 51 e8???????? 83c410 8b858cf8ffff 3bc3 746e }
+ $sequence_5 = { 4885c9 740c e8???????? 4c8935???????? 488d0ddf710200 ff15???????? }
+ $sequence_6 = { 741b 498d8c243a250000 458ac6 b213 e8???????? f7d8 1bdb }
+ $sequence_7 = { 51 e8???????? 83c410 81c6a8000000 8bc6 8d5002 668b08 }
+ $sequence_8 = { c20400 8b4508 c7462c00000080 c74644ffffffff 85c0 7403 894644 }
+ $sequence_9 = { 7416 4883ffff 7410 8bcd e8???????? 488bcf ffd0 }
condition:
- 7 of them and filesize <147456
+ 7 of them and filesize <709632
}
-rule MALPEDIA_Win_Woolger_Auto : FILE
+rule MALPEDIA_Win_Whitebird_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "903b676c-1246-53ac-bdc3-0b77fc0dda3c"
+ id = "18c8f315-82f9-5211-979b-cd91dd0f89f6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.woolger"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.woolger_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.whitebird"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.whitebird_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "403d441c2bcd327a0a5f26d737426637c32fb82ed6205c2fd16dc75ea4a861d4"
+ logic_hash = "9614af5c53f8ac08af22eb37dac785c96bbf80265ac7367d1874d42f77f5a2ec"
score = 75
quality = 75
tags = "FILE"
@@ -167993,32 +175261,32 @@ rule MALPEDIA_Win_Woolger_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83f814 750a be???????? e9???????? 83f81b }
- $sequence_1 = { 83ec54 6a40 8d45b0 6a00 50 c745ac44000000 e8???????? }
- $sequence_2 = { 33c5 8945fc 33c0 668945d4 }
- $sequence_3 = { 6685c0 8d85fcfeffff 50 0f95c3 ff15???????? 8b4f08 }
- $sequence_4 = { 52 ff15???????? 83f801 0f858d000000 }
- $sequence_5 = { 6a00 68???????? ff15???????? 68???????? 6a01 6a00 }
- $sequence_6 = { 66a5 8dbdfcf8ffff 4f 8a4701 47 84c0 }
- $sequence_7 = { 6a00 8d8dd4f4ffff 51 ffd6 85c0 75db }
- $sequence_8 = { 83c414 81ffb80b0000 5f 7c40 e8???????? e8???????? }
- $sequence_9 = { 3da2000000 0f8403010000 3da3000000 0f84f8000000 3da4000000 0f84e6000000 3da5000000 }
+ $sequence_0 = { 8a4302 84c0 7408 3c01 7404 }
+ $sequence_1 = { 8a4301 3c01 7404 3c02 }
+ $sequence_2 = { 8a4302 84c0 7408 3c01 7404 3c02 }
+ $sequence_3 = { eb09 80f92f 0f95c1 80c13f }
+ $sequence_4 = { 8a4302 84c0 7408 3c01 }
+ $sequence_5 = { ffb5c0fbffff 8930 ff15???????? 01b5c4fbffff ff8dbcfbffff 75dd ffb5c0fbffff }
+ $sequence_6 = { ff15???????? 488bcb ff15???????? b801000000 488b8c2480040000 4833cc e8???????? }
+ $sequence_7 = { 8b4d08 836d0808 d3e3 095d0c 46 3bf7 72ec }
+ $sequence_8 = { 488d542468 498bcd ffd0 3bc3 8bd0 7c28 8b442478 }
+ $sequence_9 = { 4833c4 4889842450250000 418bf9 458be0 448bf2 89542454 4c8be9 }
condition:
- 7 of them and filesize <196608
+ 7 of them and filesize <139264
}
-rule MALPEDIA_Win_Alureon_Auto : FILE
+rule MALPEDIA_Win_Gandcrab_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d906ba05-9af9-5358-abd3-33a25815a15f"
+ id = "8fb97f0d-f07e-528f-846a-617ae03e5a0b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alureon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alureon_auto.yar#L1-L161"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gandcrab"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gandcrab_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "69c2ddac38bf20f21fb2d59f504ac16289e135ccaf5d5c616ac40bfbb62cd466"
+ logic_hash = "51f7c1543a06dc758514ed4496666d6ea311b3c69b16117153a658edbbb8509b"
score = 75
quality = 75
tags = "FILE"
@@ -168032,38 +175300,32 @@ rule MALPEDIA_Win_Alureon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 59 32c0 8d7c2420 f3aa 8b4d14 }
- $sequence_1 = { 3b442410 75cf 33c0 5f 5e 5b c20800 }
- $sequence_2 = { 6800001000 8d45f8 50 c745d818000000 }
- $sequence_3 = { 68000010c0 8d45fc 50 c745d818000000 }
- $sequence_4 = { 6800000080 6a03 56 6a01 }
- $sequence_5 = { 41 8bca 49 ffc7 }
- $sequence_6 = { 2bc8 03cf 8908 eb2f 837dfc05 751c }
- $sequence_7 = { 6800005600 8d45d0 50 53 }
- $sequence_8 = { 53 ff15???????? 8945f8 56 }
- $sequence_9 = { c745f000010000 749d ff75e8 ff15???????? }
- $sequence_10 = { 66a5 8d85a8feffff 50 68???????? a4 }
- $sequence_11 = { 741c 8d85e4fbffff 50 8d85f8feffff 50 }
- $sequence_12 = { 837dfc0a 7cc0 eb32 8bc3 }
- $sequence_13 = { 50 33f6 46 56 8d8424cc000000 50 }
- $sequence_14 = { 8d8424ec010000 50 68???????? ff15???????? 85c0 0f84f2020000 }
- $sequence_15 = { ff15???????? 85c0 7409 39b424c8000000 75cf 53 53 }
+ $sequence_0 = { ff15???????? ff7728 8bf0 ff15???????? 03c3 8d5e04 }
+ $sequence_1 = { 7403 83c314 837f7400 741b ff777c ff15???????? ff7778 }
+ $sequence_2 = { 8d5e04 03d8 837f2400 741b ff772c }
+ $sequence_3 = { ff774c 8bf0 ff15???????? 03c3 8d5e04 03d8 }
+ $sequence_4 = { 03c3 8d5e04 03d8 837f5400 741b }
+ $sequence_5 = { 03c3 8d5e04 03d8 837f3000 741b }
+ $sequence_6 = { ff774c 8bf0 ff15???????? 03c3 8d5e04 }
+ $sequence_7 = { 837f1800 741b ff7720 ff15???????? }
+ $sequence_8 = { 03d8 837f6000 7403 83c314 837f7400 741b ff777c }
+ $sequence_9 = { ff15???????? 03c3 8d5e04 03d8 837f3000 }
condition:
- 7 of them and filesize <278528
+ 7 of them and filesize <1024000
}
-rule MALPEDIA_Win_Cheesetray_Auto : FILE
+rule MALPEDIA_Win_Dnspionage_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "eb62b85d-8cb5-5c93-9081-d14aeb9fbc65"
+ id = "80d80ee2-7c3c-5a6f-84fc-982c0a0f58b9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cheesetray"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cheesetray_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dnspionage"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dnspionage_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "191172cf0a118bdd8e29d678be92e505a1f63a7f2bef651373f2b7d4a4b3676d"
+ logic_hash = "6f236089a9c79217d1f5a567e48544242146a1c819e624fb6aad3710206efaec"
score = 75
quality = 75
tags = "FILE"
@@ -168077,34 +175339,34 @@ rule MALPEDIA_Win_Cheesetray_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 66898424c4000000 e8???????? 8b4d08 83c40c 51 8d54240c 33c0 }
- $sequence_1 = { c20c00 397368 740e 56 e8???????? 83c404 83f8ff }
- $sequence_2 = { 03cf 8988bc160000 8b3cb5f0234400 8b5d08 85ff 0f8487fdffff 2b14b5282d4400 }
- $sequence_3 = { 8bf8 85ff 745d 0fb755f0 8b45ec 52 50 }
- $sequence_4 = { e8???????? 8b442434 3bc7 7403 50 ffd6 }
- $sequence_5 = { 8d0c00 8d442428 50 52 e8???????? 83c408 894608 }
- $sequence_6 = { 8bda c1eb18 33049da02d4400 81e2ff000000 330495a0394400 83c120 3341f8 }
- $sequence_7 = { 8b4dfc 5f 5e a3???????? 890d???????? b801000000 5b }
- $sequence_8 = { e8???????? 8b45f8 83c40c 53 53 8d4dec 51 }
- $sequence_9 = { 83c410 33c0 5f 66398500ffffff 740c 40 6683bc4500ffffff00 }
+ $sequence_0 = { f7470c00020000 7507 8bc8 e8???????? 894320 85c0 }
+ $sequence_1 = { 50 8d45f4 50 6a13 57 }
+ $sequence_2 = { 0f1f8000000000 8bc7 8d5001 8a08 40 84c9 75f9 }
+ $sequence_3 = { c7450c00000000 8d4d0c ba???????? 51 8d4df4 51 }
+ $sequence_4 = { 83f97f 7307 be7f000000 eb11 8bf7 8d4e01 0f1f00 }
+ $sequence_5 = { 33f6 397510 762c 8b45f0 }
+ $sequence_6 = { 8b4810 e8???????? a3???????? e9???????? }
+ $sequence_7 = { 57 8bfa 85f6 0f8487000000 85ff 0f847f000000 }
+ $sequence_8 = { 7202 8b12 56 52 8d8518feffff }
+ $sequence_9 = { 8bce 8903 83c408 c1e902 }
condition:
- 7 of them and filesize <8626176
+ 7 of them and filesize <786432
}
-rule MALPEDIA_Win_Emotet_Auto : FILE
+rule MALPEDIA_Win_Xfsadm_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "66e086d2-a552-5582-bb27-ef248a857482"
+ id = "6a0bbf1b-24f1-56ab-8ac3-dbd47808408e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.emotet"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.emotet_auto.yar#L1-L609"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xfsadm"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xfsadm_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "0a0e9e76b9d5a85025f54433e276f35bcb5e942e8559eb03880f6fd71aab7315"
+ logic_hash = "b3759828684909f4ce479e79726b48d5eca09cda3ca207a8e06b6b8b2444949c"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -168116,95 +175378,32 @@ rule MALPEDIA_Win_Emotet_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3c41 7c04 3c5a 7e03 c60158 }
- $sequence_1 = { 7e13 3c61 7c04 3c7a 7e0b 3c41 7c04 }
- $sequence_2 = { 3c30 7c04 3c39 7e13 3c61 }
- $sequence_3 = { c60158 41 803900 75dd }
- $sequence_4 = { 33c0 3903 5f 5e 0f95c0 5b 8be5 }
- $sequence_5 = { 83c020 eb03 0fb7c0 69d23f000100 }
- $sequence_6 = { c1e808 8d5204 c1e910 8842fd 884afe }
- $sequence_7 = { 880a 8bc1 c1e808 8d5204 }
- $sequence_8 = { 8d5801 f6c30f 7406 83e3f0 }
- $sequence_9 = { 8b4604 8b16 8945fc 8d45f8 }
- $sequence_10 = { 83c410 8b45fc 0106 294604 }
- $sequence_11 = { 03878c000000 50 ff15???????? 017758 }
- $sequence_12 = { 8bfa 8bf1 ff15???????? 8b17 83c40c }
- $sequence_13 = { 8945fc 8d45f8 6a04 50 ff760c }
- $sequence_14 = { 8b17 83c40c 8b4d0c 8bc2 0bc1 83f8ff }
- $sequence_15 = { c745fc04000000 50 8d45f8 81ca00000020 50 52 51 }
- $sequence_16 = { 66c1e808 4d8d4004 418840fd 418848fe }
- $sequence_17 = { 418848fe 66c1e908 418848ff 4d3bd9 72cf }
- $sequence_18 = { 2bca d1e9 03ca c1e906 894c2430 }
- $sequence_19 = { 418bd0 d3e2 418bcb d3e0 }
- $sequence_20 = { 488bd3 488bcf 488b5c2460 4883c450 }
- $sequence_21 = { d3e7 83f841 7208 83f85a }
- $sequence_22 = { 418808 0fb7c1 c1e910 66c1e808 }
- $sequence_23 = { 49895b08 49896b10 49897318 49897b20 4156 4883ec70 }
- $sequence_24 = { 48895010 4c894018 4c894820 c3 }
- $sequence_25 = { c1e807 46 83f87f 77f7 }
- $sequence_26 = { 84c0 75f2 eb03 c60100 }
- $sequence_27 = { f7e1 b84fecc44e 2bca d1e9 }
- $sequence_28 = { 8bd3 8b0f e8???????? 85c0 }
- $sequence_29 = { 7423 8a01 3c30 7c04 }
- $sequence_30 = { 83c104 894e04 8b00 85c0 }
- $sequence_31 = { 7907 83c107 3bf7 72e8 }
- $sequence_32 = { 56 57 6a1e 8d45e0 }
- $sequence_33 = { 52 52 52 52 68???????? 52 }
- $sequence_34 = { 83ec48 53 56 57 6a44 }
- $sequence_35 = { 83f87f 760d 8d642400 c1e807 }
- $sequence_36 = { 83f87f 7609 c1e807 41 83f87f 77f7 }
- $sequence_37 = { 6a00 6aff 50 51 ff15???????? }
- $sequence_38 = { 50 6a00 6a01 6a00 ff15???????? a3???????? }
- $sequence_39 = { 6a00 ff75fc 6800040000 6a00 6a00 6a00 }
- $sequence_40 = { 50 56 6800800000 6a6a }
- $sequence_41 = { 53 56 8bf1 bb00c34c84 }
- $sequence_42 = { 56 68400000f0 6a18 33f6 56 56 }
- $sequence_43 = { 55 89e5 648b0d18000000 8b4130 83b8a400000006 }
- $sequence_44 = { 8b5508 befbffffff c600e9 29d6 01ce 897001 }
- $sequence_45 = { 50 51 52 01c8 01d0 }
- $sequence_46 = { 8b7d08 83fe00 8945f0 894dec }
- $sequence_47 = { 89d6 83c60c 8b7df4 8b4c0f0c }
- $sequence_48 = { 8bec 83ec08 56 57 8bf1 33ff }
- $sequence_49 = { 51 8d4df8 51 ff75f8 50 6a03 6a30 }
- $sequence_50 = { 8b466c 5f 5e 5b 8be5 5d }
- $sequence_51 = { 8b5d08 b8afa96e5e 56 57 00b807000000 008b45fc33d2 00b871800780 }
- $sequence_52 = { 8bf1 bb00c34c84 57 33ff }
- $sequence_53 = { 83ec10 53 6a00 8d45fc }
- $sequence_54 = { 6a03 6a00 6a00 ff7508 53 50 }
- $sequence_55 = { 8b7020 8b7840 89c3 83c33c }
- $sequence_56 = { c605????????00 0fb6d8 e8???????? 0fb6c3 }
- $sequence_57 = { e8???????? 84c0 7519 33c9 }
- $sequence_58 = { ff15???????? 83f803 7405 83f802 751e }
- $sequence_59 = { 7519 33c9 0f1f4000 0fb6840c30010000 }
- $sequence_60 = { 743e 8b5c2430 85db 741d }
- $sequence_61 = { 8bf8 e8???????? eb04 8b7c2430 }
- $sequence_62 = { 31c9 89e2 31f6 89720c 897208 }
- $sequence_63 = { 488d15e70f0000 e8???????? 84c0 0f84f1000000 48899c2480030000 }
- $sequence_64 = { 84c0 7466 0f1f4000 488b9c2448040000 4885db }
- $sequence_65 = { 8b4a48 894e20 83c418 5e c3 }
- $sequence_66 = { 8b4c241c 0f44c8 2b5134 8b442420 890424 89542404 894c2418 }
- $sequence_67 = { 897204 8932 8b15???????? 8944247c f20f11442470 }
- $sequence_68 = { 813c3850450000 0f44f5 895e34 890424 }
- $sequence_69 = { e8???????? 8d0d2231d800 890424 894c2404 e8???????? 8b4c242c 894130 }
- $sequence_70 = { 8bf8 85ff 7443 be???????? e8???????? }
- $sequence_71 = { 8b442450 894c2414 8b4c2418 8908 }
- $sequence_72 = { 8b5010 51 52 c745f48072e601 e8???????? 8bd8 85db }
+ $sequence_0 = { 83c40c 85c0 0f8431010000 81ff???????? 0f849f000000 6a01 68???????? }
+ $sequence_1 = { 50 ff15???????? ffb534fdffff 8bf0 ff15???????? 0fb60d???????? 33c0 }
+ $sequence_2 = { 8b7e38 85ff 0f8576010000 53 68f80f0000 e8???????? }
+ $sequence_3 = { 85c9 7455 83c60c 3bf1 744e }
+ $sequence_4 = { 8b4008 8a0406 3c3d 745e }
+ $sequence_5 = { 83fa02 7211 8b4dfc 8a06 46 8b0c8df8d84200 88440f2b }
+ $sequence_6 = { 5b 8be5 5d c20800 3c2f 751c }
+ $sequence_7 = { 2d10010000 741d 83e801 7521 0fb74510 83f801 }
+ $sequence_8 = { 8d460c 83c410 3bc8 7409 51 e8???????? 83c404 }
+ $sequence_9 = { 50 e8???????? 8b4e08 8d460c 83c410 3bc8 }
condition:
- 7 of them and filesize <733184
+ 7 of them and filesize <566272
}
-rule MALPEDIA_Win_Sombrat_Auto : FILE
+rule MALPEDIA_Win_Atlas_Agent_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "829e34aa-1da2-5a33-9238-c1cc0c096058"
+ id = "31d9d19b-f3ba-501d-964d-67da428e9e82"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sombrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sombrat_auto.yar#L1-L149"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atlas_agent"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atlas_agent_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "a1432e014afc208b0318e2ead477453bc5bd4bddb98bd4c2d60380403a2290c4"
+ logic_hash = "49564f12d410922863a80d6084c9c71952a7f941729a00c4d7e4e12f95d889bc"
score = 75
quality = 75
tags = "FILE"
@@ -168218,38 +175417,36 @@ rule MALPEDIA_Win_Sombrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 014114 8b7508 837df800 8b5df4 }
- $sequence_1 = { 01041e 8b4508 42 8d7308 }
- $sequence_2 = { 0144244a 894e0c ffb72c010000 ff15???????? }
- $sequence_3 = { 01420c 8b11 294210 8b09 }
- $sequence_4 = { 0145e4 8b55f8 83c40c 294644 }
- $sequence_5 = { 0000 e8???????? c70424???????? 8d5f0c 68???????? }
- $sequence_6 = { 7514 8b4610 8d8de4fffeff 2b4618 03c3 }
- $sequence_7 = { 014114 014620 f6460c04 8945e0 742d }
- $sequence_8 = { 015f08 33c0 488b4c2470 4833cc }
- $sequence_9 = { 0145f1 4533c9 4533c0 488b16 }
- $sequence_10 = { 016b08 488d05dc980500 41b9e7160000 4889442420 }
- $sequence_11 = { 015f08 83bfd800000016 0f856c020000 488b87c8000000 }
- $sequence_12 = { 016b08 33c0 e9???????? 33ff }
- $sequence_13 = { 01448c20 48ffc1 493bc9 7cf1 }
- $sequence_14 = { 015f08 33c0 e9???????? 488b4760 }
- $sequence_15 = { 015f08 488bcf e8???????? 8bf0 }
+ $sequence_0 = { 0fb60c0a 83e13c c1f902 03c1 }
+ $sequence_1 = { 8bc1 99 b903000000 f7f9 c1e002 }
+ $sequence_2 = { 4c8b8424c8000000 488b9424c0000000 488b8c2480000000 e8???????? 89442460 }
+ $sequence_3 = { 4c8b8424e0000000 488b9424d8000000 488b4c2468 e8???????? }
+ $sequence_4 = { 89857cffffff c645fc06 83bd7cffffff00 7417 }
+ $sequence_5 = { 898584feffff 8b8584feffff 50 8d8dd4feffff }
+ $sequence_6 = { 898588f8ffff 8b9588f8ffff 899584f8ffff c645fc07 }
+ $sequence_7 = { 4c8b8424f0000000 488b942488000000 488b8c24e0000000 e8???????? }
+ $sequence_8 = { 89857cffffff 83bd7cffffff1e 7302 eb05 }
+ $sequence_9 = { 4c8b8424f8000000 488b942400010000 488d8c24f0030000 e8???????? }
+ $sequence_10 = { 89857cffffff 8b8d18ffffff 894d80 83bd7cffffff00 }
+ $sequence_11 = { 4c8b8c2408010000 4c8d05c2930400 ba40000000 488d4c2470 }
+ $sequence_12 = { 89857cffffff 895580 8b4580 3b45dc }
+ $sequence_13 = { 4c8b8c2408010000 4c8d442460 488b9424f8000000 488b8c24f0000000 }
condition:
- 7 of them and filesize <1466368
+ 7 of them and filesize <857088
}
-rule MALPEDIA_Win_Mbrlocker_Auto : FILE
+rule MALPEDIA_Win_Darkvnc_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6a472526-8a03-5ccc-a5eb-10b46b34c6da"
+ id = "c383bb27-eefd-56e4-99f1-129a7cd0febf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mbrlocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mbrlocker_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkvnc"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkvnc_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "2abe677d378843746aa6479444a4219927906b009fff2766ade4f081783dbae6"
+ logic_hash = "59a6ef1d2e391f7957c06b061626ceb22bd1c35faf4777593f7b9c101df055cb"
score = 75
quality = 75
tags = "FILE"
@@ -168263,32 +175460,32 @@ rule MALPEDIA_Win_Mbrlocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 8b35???????? 8b3d???????? 6a10 68???????? }
- $sequence_1 = { 68fe000000 68???????? ffd7 83c408 }
- $sequence_2 = { 68ac000000 68???????? e8???????? 68ac000000 68???????? ffd7 83c408 }
- $sequence_3 = { c705????????ba514000 c705????????00020000 68fe000000 68???????? ffd6 83c408 68ff000000 }
- $sequence_4 = { 68ac000000 68???????? e8???????? e8???????? }
- $sequence_5 = { 68ff000000 68ac000000 68???????? e8???????? e8???????? 68ff000000 68ac000000 }
- $sequence_6 = { ac 30c8 aa 4a 75f9 61 c9 }
- $sequence_7 = { 68fe000000 68???????? e8???????? 68fe000000 }
- $sequence_8 = { 68fe000000 68???????? e8???????? e8???????? 68ff000000 68fe000000 }
- $sequence_9 = { 31c8 e8???????? 68ac000000 68???????? }
+ $sequence_0 = { c1e904 4103ce 446bc11f 48634b28 418bd0 c1ea08 881401 }
+ $sequence_1 = { 488b4c2438 894148 c744244001000000 4c8b8c24a0000000 4c8b842498000000 8b942490000000 33c9 }
+ $sequence_2 = { 418bca d1e9 03c1 8a4d0c 99 41f7fa d3e0 }
+ $sequence_3 = { 41f7fb d2e0 41880432 49ffc2 4c3bd3 7ce5 488b5c2408 }
+ $sequence_4 = { 668944244c 488d4c2440 e8???????? 668944244e c744244400000000 eb0a 8b442444 }
+ $sequence_5 = { 418bc8 44888438d8000000 458d5801 44019fd8000100 418bc5 410fafc4 44899c24c0040000 }
+ $sequence_6 = { ff15???????? 33d2 b903000000 f7f1 89442428 c744242400000000 ba09000000 }
+ $sequence_7 = { eb0c 498b4770 4b8d0c76 4c8d2cc8 4d85ed 750a bb27030980 }
+ $sequence_8 = { 8d5808 e9???????? 488b4c2460 488d85b0000000 4533c0 4889442420 4d8bcf }
+ $sequence_9 = { 4d85e4 7416 498bcf e8???????? 0c80 488bcd 8ad0 }
condition:
- 7 of them and filesize <43008
+ 7 of them and filesize <606208
}
-rule MALPEDIA_Win_Scarecrow_Auto : FILE
+rule MALPEDIA_Win_R77_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "906ba1cc-dc26-55b9-8f54-7f06e242df8d"
+ id = "79566c97-5b66-5f14-a1d3-bc9852e6d698"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scarecrow"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.scarecrow_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.r77"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.r77_auto.yar#L1-L154"
license_url = "N/A"
- logic_hash = "b5b9eded36bc33c6ab271290937feb85fda4ad16d7bb5dd0760ea465825b259d"
+ logic_hash = "76c887c6ccc22f9627519af58959f5ccdb37c325ffba24612ced9e4b32cde701"
score = 75
quality = 75
tags = "FILE"
@@ -168302,32 +175499,36 @@ rule MALPEDIA_Win_Scarecrow_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f7f9 85d2 743b 8b45f4 8d4f17 83c00b 99 }
- $sequence_1 = { 74d9 eb57 99 f7ff 85d2 7450 8b4c2410 }
- $sequence_2 = { c68574faffff00 c68575faffff4b c68576faffff40 c68577faffff0a c68578faffff40 c68579faffff6e c6857afaffff40 }
- $sequence_3 = { c6855bfcffff05 c6855cfcffff20 c6855dfcffff08 c6855efcffff20 c6855ffcffff27 c68560fcffff20 }
- $sequence_4 = { 7905 48 83c8fc 40 744a 8b4df4 8d4303 }
- $sequence_5 = { 99 f7ff 85d2 752c 0f1f4000 8b859cf7ffff 99 }
- $sequence_6 = { 0f84f7040000 8d4f03 c745f005000000 660f1f840000000000 c745f405f26700 8b45f4 99 }
- $sequence_7 = { c645aa00 c645ab6b c645ac00 c645ad48 c645ae00 c645af00 c645b000 }
- $sequence_8 = { c644246205 c644246347 c644246405 c64424655a c644246605 c644246727 c644246805 }
- $sequence_9 = { 660f28b870024300 660f54f0 660f5cc6 660f59f4 660f5cf2 f20f58fe 660f59c4 }
+ $sequence_0 = { 740c 8b4f0c e8???????? 85c0 }
+ $sequence_1 = { 740b 8b0f e8???????? 85c0 }
+ $sequence_2 = { 33c9 4c8d05e3d40000 488d15e4d40000 e8???????? 4885c0 740f }
+ $sequence_3 = { 0f8517030000 488d0d58ad0100 ff15???????? 4885c0 7412 }
+ $sequence_4 = { 4c8d058bfb0000 488b45e0 48c1e820 85c0 755d 8b45e0 }
+ $sequence_5 = { 33d2 660f1344243c 33c9 e8???????? 59 }
+ $sequence_6 = { f7d8 1bc0 40 85c0 750b 46 3b37 }
+ $sequence_7 = { c1fa06 6bc838 8b0495f8a00110 f644082801 7422 8d4508 8975f8 }
+ $sequence_8 = { 745c ffc1 413bc8 72f1 4885ff }
+ $sequence_9 = { 660f58e0 660fc5c400 25f0070000 660f28a050680110 660f28b840640110 660f54f0 660f5cc6 }
+ $sequence_10 = { 7408 8b442430 8bc8 cd29 488d0df6980100 }
+ $sequence_11 = { 03f3 03c3 894508 833e00 7447 8b7df0 8b08 }
+ $sequence_12 = { 488b03 833800 7513 488d15e3a70000 488d0dbca70000 }
+ $sequence_13 = { 33c0 c3 56 e8???????? ff15???????? }
condition:
- 7 of them and filesize <501760
+ 7 of them and filesize <350208
}
-rule MALPEDIA_Win_Evilbunny_Auto : FILE
+rule MALPEDIA_Win_Darkpink_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2b83805d-7841-5694-8ab4-bb4f9f22ae07"
+ id = "5843ba22-3e12-5b07-a302-af204fd4f478"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.evilbunny"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.evilbunny_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkpink"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkpink_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "7c88ed9ce9cea56ac78c56ce0f41ba384f06b92b5a02fe2a2de304167eb32f00"
+ logic_hash = "f794d5918ecf33b4e0beff127be6289d027ab1ea81bf4922e3a718a3afdf8df9"
score = 75
quality = 75
tags = "FILE"
@@ -168341,32 +175542,32 @@ rule MALPEDIA_Win_Evilbunny_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4dec 8b5104 8b45ec 8b4804 8b12 8bf4 51 }
- $sequence_1 = { eb09 8b450c 8b80b0d91a00 3bf0 7e44 83ee07 eb3f }
- $sequence_2 = { c1e104 8b5508 8b4220 8d4c08f0 8b5508 894a1c 8b4508 }
- $sequence_3 = { 8b4df8 51 e8???????? 83c404 83c028 50 6a00 }
- $sequence_4 = { e8???????? 83c40c 8b55f8 8b4204 50 68???????? 8b4d08 }
- $sequence_5 = { e8???????? 83c40c 837dd808 7308 8b45d8 89458c eb07 }
- $sequence_6 = { c1ea0a 33c2 038558ffffff 8b8d38ffffff c1e907 8b9538ffffff c1e219 }
- $sequence_7 = { e8???????? 034508 50 e8???????? 83c40c 8b45f4 50 }
- $sequence_8 = { c7000b000000 e9???????? 8b4d0c 8b5108 52 6a00 6a05 }
- $sequence_9 = { 8b5598 8b45f8 8902 8b4598 52 8bcd 50 }
+ $sequence_0 = { 8b048d442a4000 ffe0 f7c703000000 7413 }
+ $sequence_1 = { 57 50 683f000f00 6a00 68???????? 6801000080 }
+ $sequence_2 = { c3 c705????????08924100 b001 c3 68???????? e8???????? c70424???????? }
+ $sequence_3 = { 8d41fc 50 56 57 e8???????? 57 }
+ $sequence_4 = { 8b85b0f8ffff 0fb70485c43c4100 8d0485c0334100 50 8d8590faffff 03c7 50 }
+ $sequence_5 = { 33f6 8b86f09d4100 85c0 740e }
+ $sequence_6 = { 68???????? ff75f4 ffd6 85c0 0f85ca000000 50 8d45f8 }
+ $sequence_7 = { 8b0495f09d4100 f644082801 7421 57 }
+ $sequence_8 = { e8???????? 6a44 8d45ac 6a00 50 }
+ $sequence_9 = { 6a26 58 0fb60c85c63c4100 0fb63485c73c4100 8bf9 8985b0f8ffff c1e702 }
condition:
- 7 of them and filesize <1695744
+ 7 of them and filesize <237568
}
-rule MALPEDIA_Win_Asprox_Auto : FILE
+rule MALPEDIA_Win_Privateloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "828c56dd-0390-5296-8de7-1a48d10f0f57"
+ id = "704976b4-103d-5caa-b3a7-f03a44637bd7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.asprox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.asprox_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.privateloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.privateloader_auto.yar#L1-L183"
license_url = "N/A"
- logic_hash = "3b610e4cac05eeb099f6aceb2af12383510de1c04c209adb95ec16fa7dbc09d7"
+ logic_hash = "15e13900aae7d6be3cc889a3774b293d4c50bba5cbabc1926697368cc70d28fc"
score = 75
quality = 75
tags = "FILE"
@@ -168380,32 +175581,41 @@ rule MALPEDIA_Win_Asprox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 740f 6a00 ff15???????? 50 ff15???????? ff15???????? }
- $sequence_1 = { ff15???????? 6a00 6a00 8b5518 52 8b45c4 }
- $sequence_2 = { 898558ffffff 8b8560ffffff 898570ffffff 8b4ddc 898d30ffffff c78534ffffff00000000 }
- $sequence_3 = { 0fb655fd 83fa01 0f8503010000 c6859ffeffff00 68???????? ff15???????? 8985a4feffff }
- $sequence_4 = { ff45fc 83c004 817dfcff000000 7ede 83a34404000000 ba00010000 8d8348040000 }
- $sequence_5 = { 8d849d20feffff 894dc0 8945b0 8b00 8bcf 2bc8 895dbc }
- $sequence_6 = { 51 8b952cffffff 52 ff15???????? 898558ffffff 8b8560ffffff 898570ffffff }
- $sequence_7 = { 57 395d08 0f8498000000 8b750c 3bf3 0f848d000000 8b7d10 }
- $sequence_8 = { 50 ff15???????? 898558ffffff 8b4dd8 }
- $sequence_9 = { 8d840a00100000 50 6a00 8b0d???????? 51 ff15???????? 8945fc }
+ $sequence_0 = { 8965ec 8b55ec 8955e8 8d45f8 }
+ $sequence_1 = { 894df4 8b55fc 837a1410 7209 }
+ $sequence_2 = { 0fb64dec 85c9 7408 8b55fc 8b02 8945e8 }
+ $sequence_3 = { 8b4dec 8b5508 895110 8b4508 8945e4 8b4de8 034de4 }
+ $sequence_4 = { 8b45d8 8b4ddc 8b55d0 8b75d4 }
+ $sequence_5 = { 8b4dec e8???????? 8b4df0 e8???????? 8845fc }
+ $sequence_6 = { 8975d4 8b45d0 8b55d4 5e }
+ $sequence_7 = { 8b4de8 8b75ec 2bc8 1bf2 894de0 8975e4 a1???????? }
+ $sequence_8 = { e8???????? 33d2 b93f000000 f7f1 }
+ $sequence_9 = { 8b4590 8b4d94 8b5588 8b758c }
+ $sequence_10 = { a3???????? 33c0 5e c3 3b0d???????? }
+ $sequence_11 = { 896c2404 8bec 81ec68010000 a1???????? 33c5 8945fc 56 }
+ $sequence_12 = { d81d???????? c9 b8ffffffff 99 c3 56 8b35???????? }
+ $sequence_13 = { 13f1 83c201 8955e0 83d600 }
+ $sequence_14 = { 6a04 8d4310 50 6a06 }
+ $sequence_15 = { 7507 6800008000 eb02 6a00 }
+ $sequence_16 = { 8b45e4 50 51 52 }
+ $sequence_17 = { 0bc8 56 57 7529 }
+ $sequence_18 = { 03d0 8b4d9c 13f1 83c201 }
condition:
- 7 of them and filesize <155648
+ 7 of them and filesize <3670016
}
-rule MALPEDIA_Win_Babar_Auto : FILE
+rule MALPEDIA_Win_Stowaway_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "907c27e3-2fb8-508f-9c67-d8826ced6045"
+ id = "e2cf60b5-46e1-5dce-b54e-4eae51e51190"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.babar"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.babar_auto.yar#L1-L166"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stowaway"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stowaway_auto.yar#L1-L110"
license_url = "N/A"
- logic_hash = "8e0331df8b3130917de8e5e3d5d2fa36fbe1f95285a5ec05160d56f936d6e114"
+ logic_hash = "ba9de78202a4b50e7d737f5edb3449679cab84813a913aa4817b5b87ab2181a8"
score = 75
quality = 75
tags = "FILE"
@@ -168419,38 +175629,31 @@ rule MALPEDIA_Win_Babar_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3bd6 0f86f9feffff 8b54243c 8b442438 }
- $sequence_1 = { 3bd6 0f8c7affffff 8bbc24d0000000 ddd9 }
- $sequence_2 = { 3bd5 7e47 8d0c9500000000 2bd9 }
- $sequence_3 = { 3bd5 0f8671ffffff 8144241890020000 ddd8 816c242880020000 83c710 81c680020000 }
- $sequence_4 = { 46 8d44af08 8d5708 8d4cb500 d942f8 }
- $sequence_5 = { 3bd6 0f82eefeffff 8b742458 03f5 }
- $sequence_6 = { 3bd6 721b 57 8bcb }
- $sequence_7 = { 3bd6 72d9 33f6 eb08 }
- $sequence_8 = { 8906 0f8496000000 50 ffd7 894604 8b0d???????? 894e08 }
- $sequence_9 = { 8d8407d8988069 c1c007 8bfa 03c6 33fe }
- $sequence_10 = { 803800 8b0d???????? 741d 803900 7506 8b0d???????? 8a11 }
- $sequence_11 = { 23d1 33d0 0354244c 8d94322108b449 c1ca0a 03d1 8bf1 }
- $sequence_12 = { 57 8d3c85a09e0110 8b07 03c3 8a4824 }
- $sequence_13 = { e8???????? 57 e8???????? 83c410 8d842480000000 50 ffd5 }
- $sequence_14 = { 0fb64e04 884804 8b5604 c1ea08 885005 0fb64e06 }
- $sequence_15 = { 8b4b04 55 8b2d???????? 68???????? }
+ $sequence_0 = { 8b07 09c0 743c 8b5f04 }
+ $sequence_1 = { 09c0 7407 8903 83c304 ebe1 }
+ $sequence_2 = { 50 54 6a04 53 57 ffd5 8d879f010000 }
+ $sequence_3 = { 89f9 57 48 f2ae 55 }
+ $sequence_4 = { 8d879f010000 80207f 8060287f 58 50 }
+ $sequence_5 = { 95 8a07 47 08c0 74dc 89f9 57 }
+ $sequence_6 = { 76e8 77e8 78e8 79e8 }
+ $sequence_7 = { 8a7cbe46 a3???????? 4e fb b501 }
+ $sequence_8 = { 78e8 79e8 7ae8 ce f67be8 7ce8 7de8 }
condition:
- 7 of them and filesize <1294336
+ 7 of them and filesize <8003584
}
-rule MALPEDIA_Win_Colibri_Auto : FILE
+rule MALPEDIA_Win_Teleport_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "92334149-98b7-5fb0-8e08-056f3f401efb"
+ id = "20d896b0-1f61-5a48-80a3-7c8e4c6de03e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.colibri"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.colibri_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.teleport"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.teleport_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "70a6e8c65b49a36e967be3c5e646c3791445447505e2691dc2dc449a828d2e49"
+ logic_hash = "a391399ac3b60b63dbd3a4a77f0c3e70c536a7803fbc2f2dce00674fad1b8479"
score = 75
quality = 75
tags = "FILE"
@@ -168464,34 +175667,34 @@ rule MALPEDIA_Win_Colibri_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4dfc 8d4901 e8???????? 56 56 8bd8 }
- $sequence_1 = { 0f4575f4 59 e8???????? ba1f90113c 8bc8 e8???????? ffd0 }
- $sequence_2 = { 83c602 0fb706 8bd0 6685c0 75e2 8933 33c0 }
- $sequence_3 = { 8bf1 8bfa 897df8 85f6 7502 }
- $sequence_4 = { 897c2440 57 eba2 8364243c00 eb1b }
- $sequence_5 = { 8d8578f9ffff 33ff 6804010000 50 57 6a02 59 }
- $sequence_6 = { 8365f800 50 e8???????? 59 85c0 7413 8b4dfc }
- $sequence_7 = { 668945a4 6689855effffff 66894d96 59 6a76 58 6a69 }
- $sequence_8 = { 7445 8b4878 85c9 743e 33ff 39787c 7437 }
- $sequence_9 = { c1e81f 8d0448 8b0c85c0124000 8d45d4 }
+ $sequence_0 = { 50 8945fc 68???????? c745f001000000 }
+ $sequence_1 = { 57 8bfa 897de8 89b7a0000000 8b4104 8987a4000000 8b5108 }
+ $sequence_2 = { 8806 46 89b504ffffff 8b8d04ffffff 0fb6f0 8d85f8feffff 56 }
+ $sequence_3 = { c685effeffff00 50 6a00 6a00 c785e0feffff14000000 c785e4feffff00000000 c785f0feffff01000000 }
+ $sequence_4 = { 8d8d80f7ffff 899d68f7ffff e8???????? 83cb08 f6c304 740e }
+ $sequence_5 = { 8b35???????? 6a28 85f6 7451 c78560f7ffff80b54200 e8???????? 898584f7ffff }
+ $sequence_6 = { 668945a8 eb17 837e3408 8d4620 c7401000000000 7202 8b00 }
+ $sequence_7 = { 330c8560c24200 0fb6c2 330c8560b64200 8bc3 c1e810 894de0 898f94000000 }
+ $sequence_8 = { 1bc0 83c801 85c0 0f8400010000 b8???????? 8d8d60fdffff 6690 }
+ $sequence_9 = { 894110 7208 8b09 898d74ffffff 8d0436 50 }
condition:
- 7 of them and filesize <51200
+ 7 of them and filesize <458752
}
-rule MALPEDIA_Win_Moker_Auto : FILE
+rule MALPEDIA_Win_Herpes_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "18389526-a462-5233-a3a7-297ee29d064f"
+ id = "81a5deba-39e3-5a1f-937c-6696c1e1bbb2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moker_auto.yar#L1-L160"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.herpes"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.herpes_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "12a75630b6f84d2ec097d0e96068cb391171b00fda112afc8eea40b8efef358b"
+ logic_hash = "e0891dbd163cc34c7d236958d6844c054a085f2a34f7c0d3c53aa2f138d5b650"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -168503,38 +175706,32 @@ rule MALPEDIA_Win_Moker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0302 8945d4 8b4dd4 83c102 }
- $sequence_1 = { 0302 8945e8 eb09 8b45e8 }
- $sequence_2 = { 0302 8945e8 8b4df8 8b55fc }
- $sequence_3 = { 0302 50 e8???????? 83c404 3b450c 750b 8b4df0 }
- $sequence_4 = { 0301 8945e0 e8???????? 8b55e8 }
- $sequence_5 = { 0302 8945dc 8b45dc 83c002 }
- $sequence_6 = { 6a00 6a04 6a01 68000000c0 }
- $sequence_7 = { 0100 83c414 85c0 7502 eb0a }
- $sequence_8 = { 89e5 ff7508 ed 2e5c 034508 }
- $sequence_9 = { 48 8b7c2428 48 39f7 7413 fc }
- $sequence_10 = { 49 8b4c2408 ffd0 48 }
- $sequence_11 = { d16000 d0806200a501 40 00b070e000e0 31e0 00d5 31c0 }
- $sequence_12 = { 880424 49 89442430 49 89742458 66813e4d5a }
- $sequence_13 = { 50 51 52 48 }
- $sequence_14 = { c20800 55 89e5 ff750c ed }
- $sequence_15 = { 89e5 60 8b7d08 6887000000 ed }
+ $sequence_0 = { 7303 8d4570 ffb580000000 50 8b45f0 03c7 }
+ $sequence_1 = { 8d9424380d0000 52 ffd6 eb30 6a38 8d4c241c 51 }
+ $sequence_2 = { 68???????? eb05 68???????? 56 ffd7 bb05000000 399d64ffffff }
+ $sequence_3 = { 68???????? 89869c010000 ffb604020000 ffd7 68???????? }
+ $sequence_4 = { 64a300000000 b80f000000 33ff 8985e4feffff 89bde0feffff }
+ $sequence_5 = { 57 ff15???????? 5f 8b4dfc 33cd e8???????? }
+ $sequence_6 = { ff15???????? 85c0 742a 8b959cfdffff 52 e8???????? }
+ $sequence_7 = { 39bdd4fcffff 7302 8bc3 83ec1c 8bf4 }
+ $sequence_8 = { 52 ffd6 68???????? 8d858ffeffff 50 }
+ $sequence_9 = { 52 6a00 89bde0fcffff ff15???????? 85c0 745e 8d85e4fcffff }
condition:
- 7 of them and filesize <1761280
+ 7 of them and filesize <319488
}
-rule MALPEDIA_Win_Unidentified_006_Auto : FILE
+rule MALPEDIA_Win_Vendetta_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1d29f273-95a4-58bd-87cd-6ac677036b5c"
+ id = "966ae160-05eb-53d3-b86d-ed42268f2f0c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_006"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_006_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vendetta"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vendetta_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "dd723dd2c53afa22a9c28d9c9c06ec724a63cc0cfcf78b59a425b4cdf0fd8bc1"
+ logic_hash = "4fce9b15fe513b7322e530a7cc2cb9b1afb7d5162c1238338f15db6a45fbd5fd"
score = 75
quality = 75
tags = "FILE"
@@ -168548,32 +175745,32 @@ rule MALPEDIA_Win_Unidentified_006_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3907 7417 833e00 7408 ff36 e8???????? 59 }
- $sequence_1 = { 6a00 8d45fc 897dfc 50 8d45f8 50 6a00 }
- $sequence_2 = { 85c9 7410 8b55f4 85d2 7409 e8???????? 894708 }
- $sequence_3 = { 8bf0 57 56 e8???????? 83c410 33c0 }
- $sequence_4 = { 85f6 7410 57 8b7d0c 2bf8 }
- $sequence_5 = { 0fb6875c204000 47 03c6 83c603 25ff000000 }
- $sequence_6 = { eb45 8b7510 85f6 743c }
- $sequence_7 = { 8b4dfc 83c40c 8bf7 8bd7 85c9 7421 83ff0c }
- $sequence_8 = { 33ff 53 ff15???????? 53 ff15???????? }
- $sequence_9 = { 57 6a40 8bc2 33ff 6800300000 50 }
+ $sequence_0 = { 8b04c5e06f4100 5d c3 33c0 5d }
+ $sequence_1 = { 83c408 84c0 0f845d010000 6a00 51 0bf9 }
+ $sequence_2 = { 660f2815???????? f20f59db 660f282d???????? 660f59f5 660f28aa30914100 }
+ $sequence_3 = { 83a500fcffff00 51 8d8df8fbffff e8???????? 898500fcffff }
+ $sequence_4 = { 8b4508 dd00 ebc6 c745e0d8924100 e9???????? c745e0e0924100 }
+ $sequence_5 = { 6a30 eb27 3bcb 7f0e 7c08 81fa0000800c 7704 }
+ $sequence_6 = { 7309 8b04c5e06f4100 5d c3 33c0 5d c3 }
+ $sequence_7 = { 85c0 7433 8bce e8???????? 8bf8 }
+ $sequence_8 = { 33c9 8bc1 3914c5b89b4100 7408 40 83f81d 7cf1 }
+ $sequence_9 = { 53 8d85f0f7ffff 50 56 }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <296960
}
-rule MALPEDIA_Win_Royalcli_Auto : FILE
+rule MALPEDIA_Win_Alice_Atm_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8a3d9888-c19a-51e8-8633-e1429e45af66"
+ id = "66f601ee-4bc7-50a3-954d-4444abf4a52f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.royalcli"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.royalcli_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.alice_atm"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.alice_atm_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "5cdfe5e738245420de8a121061e185e2740c336e09d01f0babed3f279bcde56b"
+ logic_hash = "5f587bc558ca0a42c8c96fe5a1cfb47b3decdd71da86c983392de940e1606224"
score = 75
quality = 75
tags = "FILE"
@@ -168587,32 +175784,32 @@ rule MALPEDIA_Win_Royalcli_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 41 3bcf 7cb5 56 }
- $sequence_1 = { e8???????? 33f6 83c42c 3bc6 0f8c19050000 83bda4feffff1c 0f8c0c050000 }
- $sequence_2 = { 5d c3 56 ff15???????? 5b 5f 33c0 }
- $sequence_3 = { 898dccf9ffff 7d10 33c0 8b4dfc }
- $sequence_4 = { 8b08 8d954cf7ffff 52 68???????? }
- $sequence_5 = { 33f6 ff15???????? e9???????? 8b4708 }
- $sequence_6 = { 6a01 50 e8???????? 56 8945dc e8???????? 8b55e0 }
- $sequence_7 = { 83c414 8955e4 2bd0 8d9b00000000 }
- $sequence_8 = { 8bbdd4f9ffff 8b9dc4f9ffff 807c3b0f00 751c 8b4b08 8b5508 }
- $sequence_9 = { 50 e8???????? 6820010000 8d8dc0fdffff 56 51 e8???????? }
+ $sequence_0 = { ff75f8 8f45fc ff7508 e8???????? 8b45fc }
+ $sequence_1 = { 0fb7c0 8945f8 8b7d10 83ff00 0f86c2000000 }
+ $sequence_2 = { c9 c20c00 55 8bec 81c4a4feffff }
+ $sequence_3 = { 894609 837f0414 7305 8b5704 }
+ $sequence_4 = { 897dfc 8d9df6fdffff 53 ff7508 e8???????? 0bc0 }
+ $sequence_5 = { 57 e8???????? 0bc0 0f848b000000 53 6804010000 }
+ $sequence_6 = { 53 e8???????? 57 6806020000 56 }
+ $sequence_7 = { 50 68???????? 68???????? 8d45e8 50 68???????? 6a05 }
+ $sequence_8 = { 6a00 6a00 6809100000 ff7320 e8???????? 8945fc }
+ $sequence_9 = { 0f85ce000000 68ea030000 ff7508 e8???????? 8bf8 }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Lowball_Auto : FILE
+rule MALPEDIA_Win_Newbounce_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5424f572-46b4-58bc-b4a0-f5f116f9edc3"
+ id = "70b5f47a-ee55-5897-8fcd-06a813c41881"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lowball"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lowball_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.newbounce"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.newbounce_auto.yar#L1-L151"
license_url = "N/A"
- logic_hash = "40672e1fab5ab37bc1a93541afc7340032670ae9b7325b888c89c49deec74a07"
+ logic_hash = "53d4154f041c8f5d8c7be0de086b650af8bff8de758570421d79234a0be341f3"
score = 75
quality = 75
tags = "FILE"
@@ -168626,32 +175823,37 @@ rule MALPEDIA_Win_Lowball_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f8436010000 8b942430060000 33c9 85d2 740c 8bfa }
- $sequence_1 = { ff54242c 5f 5e 5d 33c0 }
- $sequence_2 = { 8d4f01 51 e8???????? 56 8bd8 ff15???????? }
- $sequence_3 = { 68???????? f3a4 6a00 ff54242c 6810270000 ff15???????? bf???????? }
- $sequence_4 = { 85ff 897c240c 0f848c000000 8b942420020000 55 }
- $sequence_5 = { c1e902 f3a5 8bcb 8d84244c0d0000 83e103 50 }
- $sequence_6 = { 83c410 85c0 752d 68b80b0000 ffd3 8d8c24400a0000 8d94241c010000 }
- $sequence_7 = { 8bc1 8bf7 8bfa 8d942434070000 c1e902 f3a5 8bc8 }
- $sequence_8 = { ff15???????? 83c404 89442410 b905000000 be???????? }
- $sequence_9 = { 6a00 6a00 68bb010000 51 56 }
+ $sequence_0 = { 83e00f 7e05 2bf0 83c610 }
+ $sequence_1 = { ff15???????? 85c0 0f844b010000 ba28000000 }
+ $sequence_2 = { ff15???????? 85c0 0f8437020000 8b4c2428 }
+ $sequence_3 = { ff15???????? 85c0 0f8436020000 4889bc2428010000 c784242001000022000000 c784241801000073252000 c78424100100006b2d2000 }
+ $sequence_4 = { 75f5 49ffc8 75eb 488d8104020000 }
+ $sequence_5 = { e8???????? cc b201 488bcf e8???????? 4c8d1d8f920100 488d5547 }
+ $sequence_6 = { 75f2 ebe3 488d154ac20100 498bcc 4d8bc7 }
+ $sequence_7 = { 75f5 49ffc9 75e8 488d8e54030000 }
+ $sequence_8 = { 81e3c0000000 0bf3 c1ee06 0b14b5b0876300 }
+ $sequence_9 = { 81e300000600 c1ea14 8b1495b0896300 81e6000f0000 }
+ $sequence_10 = { 81e300e00100 0bf3 c1ee0d 0b0cb5b0886300 }
+ $sequence_11 = { 81e2ff000000 8b0c8d48436300 8b1c9d48476300 33cb 8b1c85484b6300 2bcb }
+ $sequence_12 = { 81e2ff000000 c1e808 c1e208 53 }
+ $sequence_13 = { 81e3001e0000 8bef 81e50000e001 0bf5 c1ee15 8b34b5b08d6300 }
+ $sequence_14 = { 81e3001e0000 8bd5 81e280010000 0bda 8b14b5b08d6300 }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <8637440
}
-rule MALPEDIA_Win_Termite_Auto : FILE
+rule MALPEDIA_Win_M0Yv_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f52e0f9c-00a2-57d7-aba9-0dbbb1d1c2e2"
+ id = "13583ad1-2b04-58e4-9f81-2e107221c7c3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.termite"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.termite_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.m0yv"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.m0yv_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "cc787c4fe1eac82cec1ddbf65768a64c7a8c2c3d8dd4b766767f73077448495f"
+ logic_hash = "885921d8c153e05a9fb6cddfe964abb6a41c6e3fc24a745c88fdae391a38b5ef"
score = 75
quality = 75
tags = "FILE"
@@ -168665,32 +175867,32 @@ rule MALPEDIA_Win_Termite_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4508 c1e003 89c2 c1e206 01d0 05???????? 8d5004 }
- $sequence_1 = { e8???????? c744240814000000 8d45dc 89442404 8b45f4 890424 }
- $sequence_2 = { c744241cffffffff c74424188cd44000 c7442414ffffffff 8b4510 89442410 8b450c 8944240c }
- $sequence_3 = { 837dfc00 75d7 b800000000 c9 c3 55 }
- $sequence_4 = { 8b10 a1???????? 8b4d08 894c2408 89542404 890424 e8???????? }
- $sequence_5 = { e8???????? 83f814 7706 837d1400 7f0a b8ffffffff }
- $sequence_6 = { 837d0c00 750a b800000000 e9???????? 8b450c 8b4010 8945f0 }
- $sequence_7 = { 89442404 8b45f0 890424 e8???????? c70424???????? e8???????? 8b45f4 }
- $sequence_8 = { c704240a000000 e8???????? eb0a c745f401000000 eb08 90 c745f400000000 }
- $sequence_9 = { 83ec04 89442404 8d85b4feffff 890424 e8???????? 8d85b4feffff 89442404 }
+ $sequence_0 = { 490faff8 4d89c3 4901ff 4c8b1424 490fafd2 48039424b8000000 4c89ef }
+ $sequence_1 = { 72e7 4889f9 4889da e8???????? 48c7474800000000 31c0 6690 }
+ $sequence_2 = { f6c201 0f84e3000000 4183fb66 775c 744e }
+ $sequence_3 = { 4889fa e8???????? 4889f9 4889fa e8???????? 4c89f1 }
+ $sequence_4 = { 29e8 488bac24a8000000 894500 895504 44895d08 }
+ $sequence_5 = { 490fafc6 4801c2 4889942440010000 4c89842488000000 4c89c0 480fafc1 }
+ $sequence_6 = { 4f037ce538 4c21df 4c31d7 4e03bce498000000 4831c1 4901ff 4c89c8 }
+ $sequence_7 = { 2b6a24 448901 44894904 44895108 4489590c 44897110 897114 }
+ $sequence_8 = { 4883ec28 e8???????? 4885c0 7409 488b4010 }
+ $sequence_9 = { c1e802 4122c2 41884041 8bc2 83e003 8a0481 498bc8 }
condition:
- 7 of them and filesize <312320
+ 7 of them and filesize <779264
}
-rule MALPEDIA_Win_Usbferry_Auto : FILE
+rule MALPEDIA_Win_Zeus_Sphinx_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "62065071-13fe-542b-a291-fb80bd43202d"
+ id = "4c9695e3-d96e-5f67-a0c2-424bcf596515"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.usbferry"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.usbferry_auto.yar#L1-L169"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus_sphinx"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeus_sphinx_auto.yar#L1-L158"
license_url = "N/A"
- logic_hash = "886d5513793c468df6b8e0477647a179848882846be144ad6058e6cfbd13a26d"
+ logic_hash = "c474cca5e98993ccd970de7e5648248c620e9abab23dec872f161292bb6b1fb0"
score = 75
quality = 75
tags = "FILE"
@@ -168704,38 +175906,38 @@ rule MALPEDIA_Win_Usbferry_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 8b45e0 50 ff15???????? 85c0 742c }
- $sequence_1 = { 8b9598f5ffff 2b9588f5ffff 8b8588f5ffff 89857cf5ffff 899578f5ffff }
- $sequence_2 = { e9???????? ff75e0 a1???????? ff5060 8d45e0 }
- $sequence_3 = { c3 3b0d???????? f27502 f2c3 f2e960030000 55 }
- $sequence_4 = { 8b525c e8???????? 8b15???????? 8b4d84 ff7210 89425c }
- $sequence_5 = { 803f2e 7402 33ff 85ff 7407 8d45e9 }
- $sequence_6 = { c645df6f c645e06e c645e100 c685a4f5ffff00 68ff030000 }
- $sequence_7 = { 2b858cf5ffff 8b8d8cf5ffff 898d84f5ffff 898580f5ffff 8d95a8feffff 83c2ff }
- $sequence_8 = { 8b7d0c 33db 895ddc c745e000040000 895dfc 8d45dc }
- $sequence_9 = { 89814c010000 8b09 e8???????? 8b0d???????? ff7110 8b9154010000 }
- $sequence_10 = { ff7110 8b517c 894178 8b09 e8???????? 8b0d???????? }
- $sequence_11 = { 8a460e 8bcf 8845fb 8d45fb }
- $sequence_12 = { 33c5 8945fc c685fcfffeff00 68ffff0000 }
- $sequence_13 = { 8885a0f5ffff 838590f5ffff01 80bda0f5ffff00 75e1 }
- $sequence_14 = { 0f2805???????? 0f1145c8 6a00 0f2805???????? 0f1145d8 50 }
- $sequence_15 = { 50 8d45f0 64a300000000 c745e000000000 c745fc00000000 837d2000 }
+ $sequence_0 = { 50 e8???????? 891c24 89c6 e8???????? 83c410 8d65f4 }
+ $sequence_1 = { 50 e8???????? 83c414 68???????? e8???????? c70424???????? }
+ $sequence_2 = { 50 e8???????? 83c410 c74604ffffffff 897508 }
+ $sequence_3 = { 50 e8???????? 83c430 85c0 7e0c }
+ $sequence_4 = { 52 52 8b6c2444 55 50 e8???????? 8944245c }
+ $sequence_5 = { 50 e8???????? 84c0 745f 8d442414 }
+ $sequence_6 = { 50 e8???????? 83c420 48 }
+ $sequence_7 = { 50 e8???????? 83c418 68???????? 68???????? }
+ $sequence_8 = { 01fc eb98 035e14 8ade }
+ $sequence_9 = { 010c02 3bf7 0f85f0f50000 e9???????? }
+ $sequence_10 = { 003b c09bdbe23ea11c 695600663ec700 de07 }
+ $sequence_11 = { 0303 50 ff550c 8b3e }
+ $sequence_12 = { 010d???????? 60 5a 98 }
+ $sequence_13 = { 020a 42 1af6 af }
+ $sequence_14 = { 0162c9 cf 0c06 3c3e }
+ $sequence_15 = { 0008 d7 9f b2d3 }
condition:
- 7 of them and filesize <638976
+ 7 of them and filesize <3268608
}
-rule MALPEDIA_Win_Stormwind_Auto : FILE
+rule MALPEDIA_Win_Kronos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "134843ba-afb3-5108-9e28-7ec5026e872c"
+ id = "8d31fd16-d4f2-5a2a-96ec-ac39493ba957"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stormwind"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stormwind_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kronos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kronos_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "81578edc87d2c38ca6c94ce63cf22ed064b72d5bc6a7c525985af57574ba5c73"
+ logic_hash = "9add781f31640b82e44b92fb87f47ac9fbcee8b3e1525e4790235c25c58c2848"
score = 75
quality = 75
tags = "FILE"
@@ -168749,32 +175951,32 @@ rule MALPEDIA_Win_Stormwind_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83c404 8bf7 3b3b 75e2 }
- $sequence_1 = { 83e4f8 81ec1c010000 53 8b5d10 56 57 8b7d0c }
- $sequence_2 = { e8???????? 83ec0c c745fc00000000 8d4e04 e8???????? 85c0 8b06 }
- $sequence_3 = { 50 ff7604 56 e8???????? 894604 c745d801000000 8b4804 }
- $sequence_4 = { 59 8b7d08 33db 391cfd88e40410 755c 6a18 e8???????? }
- $sequence_5 = { 83fa05 7509 8b852cfdffff 89470c 6bc20c 57 ff90c04e0410 }
- $sequence_6 = { 8d4de4 e8???????? 68???????? 8d45e4 c745e4740c0410 50 e8???????? }
- $sequence_7 = { f7fe 57 8bc2 99 }
- $sequence_8 = { c74508???????? 50 8d4de4 e8???????? 68???????? 8d45e4 c745e4740c0410 }
- $sequence_9 = { 8975d4 68b8020000 c645fc01 e8???????? }
+ $sequence_0 = { 8d542450 52 03c6 50 57 ffd3 85c0 }
+ $sequence_1 = { 813e50450000 7549 57 56 ff75fc e8???????? 8b450c }
+ $sequence_2 = { e8???????? 33db 6a40 8d4628 53 50 }
+ $sequence_3 = { e8???????? 85db 0f854fffffff eb1c 8d4dd0 be02000000 e8???????? }
+ $sequence_4 = { 897804 8930 ff461c 6a00 }
+ $sequence_5 = { 803d????????01 56 750f 33f6 8d4df0 e8???????? 8bc6 }
+ $sequence_6 = { eb1d 8b0f e8???????? 8b0f 8b30 6a04 e8???????? }
+ $sequence_7 = { 0355dc 8b45e8 2b45ec 03ca 3b450c 7356 29450c }
+ $sequence_8 = { c3 55 8bec 83ec5c 56 8d45a4 50 }
+ $sequence_9 = { 3b7104 7505 8b06 894104 3b7108 7506 8b5604 }
condition:
- 7 of them and filesize <741376
+ 7 of them and filesize <1302528
}
-rule MALPEDIA_Win_Wastedlocker_Auto : FILE
+rule MALPEDIA_Win_Pirpi_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b7e51866-b49c-5bda-b9e7-206c33d8d8a8"
+ id = "98537945-bca9-5f78-aa80-688498d88ff3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wastedlocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wastedlocker_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pirpi"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pirpi_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "f3876fe06c43f4da1aa2e85c3923ddbcdfed237d9e82449557581810436fb80c"
+ logic_hash = "b10391fa85a6d93cb62abde2610054ffc017de9bf6b1bef0a98b13168e41c382"
score = 75
quality = 75
tags = "FILE"
@@ -168788,32 +175990,32 @@ rule MALPEDIA_Win_Wastedlocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8bf0 ff7508 6a00 ff35???????? ff15???????? 5f }
- $sequence_1 = { 8945e4 8d45dc 50 c745dc18000000 897de0 }
- $sequence_2 = { 50 e8???????? 83c40c 56 8d85c8f1ffff 53 50 }
- $sequence_3 = { ffd3 8bf8 85ff 7419 6a20 57 ffd3 }
- $sequence_4 = { 8d45ec 50 8d45d4 50 6816011200 }
- $sequence_5 = { 3b45d0 0f8382000000 894dd8 394de0 740b 0fb703 034710 }
- $sequence_6 = { ff35???????? ff15???????? 5f ff75f8 ff15???????? }
- $sequence_7 = { 6a00 ff35???????? ff15???????? 8bd8 85db 7469 8b450c }
- $sequence_8 = { 2500f0ffff 56 0500100000 50 56 b812345607 }
- $sequence_9 = { bf04010000 ffd3 8bf0 85f6 746a 57 56 }
+ $sequence_0 = { e8???????? 33ff 8945f4 85c0 897dfc }
+ $sequence_1 = { 46 3bf7 72eb c6043b00 5d 8bc7 }
+ $sequence_2 = { 50 ff15???????? 83c414 8d8c2434010000 }
+ $sequence_3 = { 8bd8 83c408 85db 7515 68???????? 50 }
+ $sequence_4 = { 83c404 85ed 7513 53 ff15???????? 5f 5e }
+ $sequence_5 = { 56 ff15???????? 56 8be8 ff15???????? 33d2 3bea }
+ $sequence_6 = { 33c0 f2ae f7d1 49 83f920 7350 }
+ $sequence_7 = { 03d8 f3a4 c6042b00 eb6e }
+ $sequence_8 = { 55 c744242018000000 e8???????? 83f87a 753b 55 8b2d???????? }
+ $sequence_9 = { 89442414 7516 ff15???????? 894504 c744241000000000 e9???????? }
condition:
- 7 of them and filesize <147456
+ 7 of them and filesize <327680
}
-rule MALPEDIA_Win_Tildeb_Auto : FILE
+rule MALPEDIA_Win_Atmii_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e4d2b91f-a0b2-5435-bc42-03da5ff53194"
+ id = "a3746494-2207-5da0-bb5a-0a2c92906b78"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tildeb"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tildeb_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atmii"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atmii_auto.yar#L1-L170"
license_url = "N/A"
- logic_hash = "5eed583e8de669a9ccc3c14def00c8dc34c80dd8549b8a02a48ebd34aae4a3b5"
+ logic_hash = "32f9cc90bb902f5f085ec60f456bf3e42304f21478253b8a2c4851a4d1f531ad"
score = 75
quality = 75
tags = "FILE"
@@ -168827,32 +176029,38 @@ rule MALPEDIA_Win_Tildeb_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4dbc 51 56 ff15???????? 56 ff15???????? }
- $sequence_1 = { 6a00 6a00 ff15???????? 85c0 0f84f5090000 68???????? }
- $sequence_2 = { 57 6a40 c644241300 ff15???????? 50 ff15???????? }
- $sequence_3 = { 85c0 7445 50 68???????? 68???????? ff15???????? 83c40c }
- $sequence_4 = { e8???????? 6a00 6a08 8d85d4f5ffff 50 }
- $sequence_5 = { 68???????? 57 56 ff15???????? 8945bc 85c0 7457 }
- $sequence_6 = { c3 b815000000 5e 81c494010000 c3 f7d8 5e }
- $sequence_7 = { eb40 8d458c 50 68???????? eb35 }
- $sequence_8 = { 53 55 8bac2410010000 56 8b35???????? 57 68???????? }
- $sequence_9 = { 6800000088 68???????? 68???????? 6a00 ff15???????? 8b0d???????? }
+ $sequence_0 = { 6a03 68000000c0 8b0d???????? 51 ff15???????? 8945fc }
+ $sequence_1 = { 8945ee 0fb705???????? 52 682e010000 50 895dd9 }
+ $sequence_2 = { 68???????? 50 ffd7 8d9dfcfbffff }
+ $sequence_3 = { 8d8dd1f9ffff 51 8895c4f9ffff ff15???????? }
+ $sequence_4 = { 8d95fcfdffff 6a00 52 e8???????? 8b35???????? 83c424 68???????? }
+ $sequence_5 = { 8945fc 837dfc00 7454 8b4dfc 0fb611 }
+ $sequence_6 = { 51 e8???????? 8b55f4 83c414 6a00 }
+ $sequence_7 = { 83c414 8d9df8fcffff e8???????? 8b45f8 85c0 7407 }
+ $sequence_8 = { 68???????? 68c3000000 8d85f8fcffff 68???????? 50 }
+ $sequence_9 = { 5f 5b 8be5 5d c3 68???????? 680b010000 }
+ $sequence_10 = { 837d0803 0f8ceb000000 53 8b1d???????? 57 68???????? }
+ $sequence_11 = { ffd3 68???????? 68???????? 8985c5f9ffff ffd7 }
+ $sequence_12 = { c745f800000000 ff15???????? 85c0 0f94c0 8845ff 84c0 742e }
+ $sequence_13 = { 85ff 0f8448030000 8d55f0 52 6800040000 }
+ $sequence_14 = { ff2485181d0010 68???????? 8d8df8feffff 51 eb2f 68???????? }
+ $sequence_15 = { 81ea???????? 83c204 f7d2 8955ed }
condition:
- 7 of them and filesize <8532488
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Anchormtea_Auto : FILE
+rule MALPEDIA_Win_Elirks_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1f1be8a6-a512-5951-b4a5-8a59e9561b7d"
+ id = "abbbcbca-d514-5806-9c10-833d31c8983a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.anchormtea"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.anchormtea_auto.yar#L1-L156"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.elirks"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.elirks_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "36b7e20db6ab94edc928176040f9980c01a0a26295c603a430e96744ecfde5c2"
+ logic_hash = "4de38c5bbb938b8f52d51f635312140a804238195b0d5824203719bed438cd32"
score = 75
quality = 75
tags = "FILE"
@@ -168866,39 +176074,34 @@ rule MALPEDIA_Win_Anchormtea_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? f7d8 1bc0 83e002 }
- $sequence_1 = { 33c0 6689047e eb14 51 }
- $sequence_2 = { 83f81f 0f87f3080000 52 51 e8???????? }
- $sequence_3 = { 7409 488bcf ff15???????? 33f6 4c8b7c2448 4c8b642460 }
- $sequence_4 = { 488905???????? 488d055b7e0200 488905???????? 488d05897d0200 48890d???????? 48890d???????? }
- $sequence_5 = { 899d1cffffff ffd7 50 ffd6 }
- $sequence_6 = { 8b9580f7ffff 89856cf7ffff 8b85acf7ffff 2bc7 898d5cf7ffff 89bd64f7ffff }
- $sequence_7 = { 4983ff10 4c0f43f7 4c8b6c2470 4983fd0b 725f 4f8d242e }
- $sequence_8 = { 51 57 8d4dd8 e8???????? 33d2 895588 90 }
- $sequence_9 = { 4883c0f8 4883f81f 772e e8???????? 8bc6 }
- $sequence_10 = { 488d9510020000 488bcb ff15???????? 413b7624 }
- $sequence_11 = { 4a8d3c39 488bc6 482bc2 4869d88c090000 }
- $sequence_12 = { 33ff 488945d0 488d45e0 4533c9 4889442448 4533c0 }
- $sequence_13 = { 740e 6a40 68???????? 68???????? ffd7 8d45f8 }
- $sequence_14 = { 7514 3b8598fdffff 1bc0 238598fdffff }
+ $sequence_0 = { 8d4c2414 51 68???????? 8bf0 ff15???????? }
+ $sequence_1 = { 85c0 7417 8b44241c 01442414 03f0 2bf8 e9???????? }
+ $sequence_2 = { 51 8d44241c e8???????? 8b8e04600000 83c404 }
+ $sequence_3 = { 83c102 66c7012d00 83c102 66c7012d00 83c102 83ef03 83c603 }
+ $sequence_4 = { 68???????? 8d442430 e8???????? 83c40c }
+ $sequence_5 = { 7fe8 85ff 0f84a1010000 85ff 7e25 }
+ $sequence_6 = { c1f803 0faf4608 894614 6a68 }
+ $sequence_7 = { 52 ff15???????? 8bd8 83fbff 895c2410 7546 }
+ $sequence_8 = { 8d8c2490060000 51 6804010000 ff15???????? 8d9e0c600000 53 6a00 }
+ $sequence_9 = { 750b 57 e8???????? 83c404 5e c3 }
condition:
- 7 of them and filesize <839680
+ 7 of them and filesize <81920
}
-rule MALPEDIA_Win_Icedid_Auto : FILE
+rule MALPEDIA_Win_Campoloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f1fe8329-9566-5f3c-8226-7a3fb9936918"
+ id = "00b62c88-0d38-56b9-90a5-7c85290ffbe9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.icedid"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.icedid_auto.yar#L1-L298"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.campoloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.campoloader_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "35bc9d0f5535131e0ac355ad775af24bc4cac838dad6434eced01ac7afcde501"
+ logic_hash = "dae472a7090c99e8a9ce136356f9bc867c42c508ecb59c9f6aa0187832a15e3c"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -168910,54 +176113,32 @@ rule MALPEDIA_Win_Icedid_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7511 56 57 ff15???????? }
- $sequence_1 = { 50 6801000080 ff15???????? eb13 }
- $sequence_2 = { 803e00 7427 6a3b 56 ff15???????? 8bf8 }
- $sequence_3 = { ff15???????? 85c0 7420 837c241000 7419 }
- $sequence_4 = { 56 ff15???????? 8bf8 85ff 7418 c60700 }
- $sequence_5 = { 68???????? 6a00 ff15???????? 33c0 40 }
- $sequence_6 = { 50 ff15???????? 8bf7 8bc6 eb02 }
- $sequence_7 = { eb0f 6a08 ff15???????? 50 ff15???????? 8906 }
- $sequence_8 = { e8???????? 8bf0 8d45fc 50 ff75fc 6a05 }
- $sequence_9 = { 743f 8d5808 0fb713 8954241c }
- $sequence_10 = { 03c2 eb5c 8d5004 89542414 8b12 85d2 }
- $sequence_11 = { 66c16c241c0c 0fb7d2 c744241000100000 663b542410 }
- $sequence_12 = { 47 83c302 3bfd 72c4 }
- $sequence_13 = { 8d4508 50 0fb6440b34 50 }
- $sequence_14 = { 89542414 8b12 85d2 7454 8d6af8 d1ed }
- $sequence_15 = { 47 3b7820 72d1 5b 33c0 40 }
- $sequence_16 = { ff5010 85c0 7407 33c0 e9???????? }
- $sequence_17 = { 8a4173 a808 75f5 a804 7406 }
- $sequence_18 = { ff15???????? 85c0 750a b8010000c0 }
- $sequence_19 = { 41 02fd c6430503 eb21 41 0fb6c1 }
- $sequence_20 = { 48 8bfa 48 8bf1 45 8d41ce e8???????? }
- $sequence_21 = { 7407 41 2bcd 7515 eb0f 44 }
- $sequence_22 = { 48 8d442458 48 8bf9 48 }
- $sequence_23 = { 8bce 894348 48 8b15???????? }
- $sequence_24 = { 7307 4c8b742420 eba1 488bb590020000 }
- $sequence_25 = { 57 4883ec30 488bf2 488bd9 ff15???????? 4885c0 }
- $sequence_26 = { 7409 8b4c2478 493b0e 741e 498b1f 4885db }
- $sequence_27 = { 33d2 488bc8 ff15???????? 488bb590020000 4885f6 7414 ff15???????? }
- $sequence_28 = { 33d2 488bce ff15???????? 8bd8 49891e 85c0 }
- $sequence_29 = { 4533c0 c740c803000000 ba00000080 ff15???????? 488bf0 4883f8ff 7507 }
- $sequence_30 = { 33ff 4d8bf0 482178d8 4c8bfa }
- $sequence_31 = { 5d c3 488b0d???????? 488d050d1e0000 }
+ $sequence_0 = { 83ec1c a1???????? 33c5 8945fc a1???????? 8945e4 }
+ $sequence_1 = { 898d58efffff c78584efffff00000000 8d55f4 52 8b8558efffff 50 }
+ $sequence_2 = { ff15???????? ff15???????? 8b8584efffff 8b4dfc 33cd e8???????? }
+ $sequence_3 = { 8b9584efffff 039574efffff c60200 8b450c }
+ $sequence_4 = { ff15???????? 898550efffff 0fb78554efffff 50 }
+ $sequence_5 = { 038d8cefffff 898d74efffff e9???????? 8b9584efffff 039574efffff c60200 8b450c }
+ $sequence_6 = { ff15???????? 8945f8 68???????? 8b45fc 50 }
+ $sequence_7 = { 6a01 6a00 6a00 6800000040 8b4510 }
+ $sequence_8 = { 8b8558efffff 50 8d8df0feffff 51 }
+ $sequence_9 = { 8b8d70efffff 51 8b9584efffff 52 ff15???????? }
condition:
- 7 of them and filesize <303104
+ 7 of them and filesize <66560
}
-rule MALPEDIA_Win_Spybot_Auto : FILE
+rule MALPEDIA_Win_Sykipot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bb20c1b9-da8a-50d3-8d1c-08fd01abaeb2"
+ id = "6685d9d7-6a5e-5dd1-be8d-f9a06a5df784"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spybot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spybot_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sykipot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sykipot_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "f1b579b5b1ee691f466e64e8179031f49e4fd32bcc6dd2bb1d3af2d36456dc74"
+ logic_hash = "fc1ea45bf7dc961b3986859ea4bfe6fc9a7dfe7e53218e4f87e591fa79b5c1da"
score = 75
quality = 75
tags = "FILE"
@@ -168971,32 +176152,32 @@ rule MALPEDIA_Win_Spybot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ffb574ffffff ff750c e8???????? 83c428 e9???????? }
- $sequence_1 = { 50 e8???????? 83c40c 8d4508 be08010000 50 }
- $sequence_2 = { 8d45ec 50 e8???????? 8d45ec 885dee 50 8d8548ffffff }
- $sequence_3 = { 80bd48ffffff30 7c09 80bd48ffffff39 7e16 6a03 8d8548ffffff 68???????? }
- $sequence_4 = { 56 68???????? e8???????? 59 85c0 59 0f85d7000000 }
- $sequence_5 = { 3b35???????? 0f83c5010000 8bc6 83e61f c1f805 c1e603 8d1c85e07e5100 }
- $sequence_6 = { 69c034020000 59 389890814400 0f84fb2b0000 395df4 0f84f22b0000 ff7520 }
- $sequence_7 = { 8d850cfbffff 53 50 68???????? 53 53 ff15???????? }
- $sequence_8 = { 898510fbffff 8b45fc 898598fbffff 8b45f8 3bf3 89859cfbffff 751c }
- $sequence_9 = { 750b 57 ff15???????? 8bc6 eb02 }
+ $sequence_0 = { 8d8c2488000000 51 ffd5 68???????? 68???????? ffd3 83c408 }
+ $sequence_1 = { 56 c744246004000000 ffd7 8b4c244c 6a04 }
+ $sequence_2 = { 50 51 8bcd e8???????? 8b13 8d442414 52 }
+ $sequence_3 = { 50 8db42498000000 83ec44 8bfc }
+ $sequence_4 = { 5d b80e000000 5b 81c45c180000 c3 56 8b35???????? }
+ $sequence_5 = { 8bcc 8911 8b94244c060000 894104 895108 8bcd }
+ $sequence_6 = { 55 56 ff15???????? 85c0 57 7513 ff15???????? }
+ $sequence_7 = { bf???????? a3???????? f3ab b941000000 bf???????? f3ab b941000000 }
+ $sequence_8 = { 83ec44 b911000000 8db424e8000000 8bfc f3a5 8bcd e8???????? }
+ $sequence_9 = { c24800 8b442404 56 57 }
condition:
- 7 of them and filesize <2367488
+ 7 of them and filesize <286720
}
-rule MALPEDIA_Win_Kazuar_Auto : FILE
+rule MALPEDIA_Win_Buer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bbccb83c-4401-524c-a829-9e1fecf876f5"
+ id = "29f2986a-0230-51bb-b9a2-7f550ca2fb77"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kazuar"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kazuar_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.buer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.buer_auto.yar#L1-L170"
license_url = "N/A"
- logic_hash = "8a42fd36e815cd90ae38c5e050f60bebec4410e7ad562404ae7ac137541dd601"
+ logic_hash = "2390d8b9be10e4a78955cb4e4f9dfe589bef2af5ea30193017caa2f367cbde8d"
score = 75
quality = 75
tags = "FILE"
@@ -169010,32 +176191,38 @@ rule MALPEDIA_Win_Kazuar_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 3d88ae6393 7506 498b4310 eb0f }
- $sequence_1 = { e8???????? 4c8d4c2428 31d2 31c9 01c0 4c89442438 6689442430 }
- $sequence_2 = { 8d8b80030000 894c240c 8d8b00030000 894c2408 8d4b08 894c2404 }
- $sequence_3 = { 740a 81ea00204000 01d0 eb02 31c0 5d c3 }
- $sequence_4 = { 7452 83b98c00000000 7449 4c01de }
- $sequence_5 = { 8b45dc 8b10 890424 ff520c 85c0 52 }
- $sequence_6 = { 8b461c 498d1493 8b0402 4c01d8 }
- $sequence_7 = { 8bb188000000 85f6 7452 83b98c00000000 7449 4c01de 31db }
- $sequence_8 = { 89d7 7463 4863493c 4c01d9 8bb188000000 85f6 7452 }
- $sequence_9 = { 890424 894c2410 8d8b80030000 894c240c 8d8b00030000 }
+ $sequence_0 = { 8b4014 8b00 8b4010 8945fc 61 8b45fc }
+ $sequence_1 = { 7507 e8???????? eb05 e8???????? 46 83fe20 7cd1 }
+ $sequence_2 = { 60 64a130000000 8b400c 8b4014 8b00 8b4010 }
+ $sequence_3 = { 8bc2 eb19 33c0 85d2 7e13 3bc7 }
+ $sequence_4 = { 8b55e8 015158 8b55d8 894148 8b45dc 03c6 89414c }
+ $sequence_5 = { c1e104 0bc8 6a02 5b }
+ $sequence_6 = { 8945f8 ff15???????? 59 59 85c0 }
+ $sequence_7 = { 8365fc00 53 56 57 60 64a130000000 8b400c }
+ $sequence_8 = { c744240402000000 8d442428 c7442408???????? c744240c01000000 }
+ $sequence_9 = { e8???????? 80fb03 7705 80fb02 }
+ $sequence_10 = { e8???????? 0f0b b92c000000 ba01000000 e8???????? 0f0b 89f9 }
+ $sequence_11 = { c744240401000000 c7442408???????? c744240c01000000 89442410 }
+ $sequence_12 = { e8???????? 56 6a00 50 e8???????? c7471c01000000 }
+ $sequence_13 = { c744240800000000 57 e8???????? 85c0 }
+ $sequence_14 = { cd29 0f0b cc 8b442404 833800 7406 ba???????? }
+ $sequence_15 = { e8???????? 80fb05 ba01000000 0fb6c3 }
condition:
- 7 of them and filesize <81920
+ 7 of them and filesize <3031040
}
-rule MALPEDIA_Win_Mewsei_Auto : FILE
+rule MALPEDIA_Win_Httpbrowser_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "78bf6ca7-ef3d-53c3-89fb-bc5bc524aac5"
+ id = "86ed1f1e-9c83-5189-8446-3be88e9701cf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mewsei"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mewsei_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.httpbrowser"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.httpbrowser_auto.yar#L1-L178"
license_url = "N/A"
- logic_hash = "3736165e5248449b2b75237b3807b31270781b320dfabe4092f7167612f74bb7"
+ logic_hash = "5b5149262889d64634c3067408a546cd5b0c2e08f2004303b6cf9132eb7eeb82"
score = 75
quality = 75
tags = "FILE"
@@ -169049,32 +176236,38 @@ rule MALPEDIA_Win_Mewsei_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 337df8 8b5dfc 237df4 337df0 037dc0 8dbc1faf0f7cf5 }
- $sequence_1 = { e8???????? 50 8bc7 e8???????? 83c404 e8???????? 50 }
- $sequence_2 = { 0fbe7c0602 57 e8???????? 83c404 85c0 7405 8d47d0 }
- $sequence_3 = { 8b4610 8b0cb8 8911 8b55f8 }
- $sequence_4 = { 57 e8???????? 8b1d???????? 83c410 6a00 }
- $sequence_5 = { 83c404 895df8 85db 750c 6a01 e8???????? 83c404 }
- $sequence_6 = { 6a01 6a0e 56 ff15???????? }
- $sequence_7 = { 6a04 8d4df8 51 6a04 6a00 56 }
- $sequence_8 = { ff15???????? 57 8bf0 53 56 ff15???????? 50 }
- $sequence_9 = { 337df4 337dfc 037dcc 8dbc1ff87ca21f 8b5df0 c1c710 }
+ $sequence_0 = { 50 ff7508 6a00 53 ffd6 8b45fc 33c9 }
+ $sequence_1 = { 50 895de0 ff5604 8945f0 85db 0f8489010000 }
+ $sequence_2 = { 33c5 8945fc 53 56 57 8d859cfeffff 33ff }
+ $sequence_3 = { 8d85f0fdffff 50 8d85d0f5ffff 50 ff15???????? }
+ $sequence_4 = { 56 6a03 6800000040 8d85f4fdffff 50 ff15???????? }
+ $sequence_5 = { e8???????? 83c40c 33c0 56 668985c8f3ffff 8d85caf3ffff }
+ $sequence_6 = { 83c438 ff15???????? 8d85f4fdffff 50 53 57 }
+ $sequence_7 = { ffb5f4edffff 8d85fcfdffff ffb5f8edffff 68???????? 50 }
+ $sequence_8 = { e8???????? 68c20ddf13 56 a3???????? e8???????? 83c438 }
+ $sequence_9 = { 6a00 6810040000 ff15???????? 8bf0 57 6a0e 56 }
+ $sequence_10 = { 83c414 c745ec00000000 68???????? 50 9c b80a000000 51 }
+ $sequence_11 = { b905000000 8db524ffffff 8dbda4feffff 8945e4 }
+ $sequence_12 = { 33c0 8dbd26ffffff 66899524ffffff f3ab 8955e8 8955f8 8955fc }
+ $sequence_13 = { 40 0068ae 224000 50 b822010000 }
+ $sequence_14 = { 8895a0c5ffff f3ab aa b91f000000 33c0 8dbd4affffff 66899548ffffff }
+ $sequence_15 = { 8b15???????? 8945d8 a1???????? 894ddc 668b0d???????? }
condition:
- 7 of them and filesize <504832
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Powerduke_Auto : FILE
+rule MALPEDIA_Win_Deltas_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6d856194-c9fe-5330-9bd8-d5a96e01d2f2"
+ id = "7da5df4e-29e3-54c4-9a20-6a6e85d7900e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.powerduke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.powerduke_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.deltas"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.deltas_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "8396f645fb90ff46635658086ca415f6d857b1da2dac7ff489b34d4ef5885286"
+ logic_hash = "dd0f3991acf6e3d198b5d6cf834071e4c8ad802b2fea2e9cf5d21d8d4fb219f6"
score = 75
quality = 75
tags = "FILE"
@@ -169088,32 +176281,32 @@ rule MALPEDIA_Win_Powerduke_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c705????????00000000 6a04 6800300000 ff7518 }
- $sequence_1 = { ff75e4 ff75bc ff15???????? 09c0 7473 }
- $sequence_2 = { 6a00 ff15???????? 09c0 0f8412010000 8945e4 53 50 }
- $sequence_3 = { b801000000 c9 c20c00 55 89e5 81ec080c0000 }
- $sequence_4 = { 89f7 31c9 803c0f3a 7409 }
- $sequence_5 = { 09c0 7505 b850000000 8945ec c6040e00 }
- $sequence_6 = { c70000000000 837d2000 740f 8b4520 }
- $sequence_7 = { c20400 55 89e5 56 57 8b750c }
- $sequence_8 = { 0f8493000000 c745f901000000 89c3 be???????? }
- $sequence_9 = { 6a00 57 ff15???????? 09c0 }
+ $sequence_0 = { 8d542434 898424d8000000 52 ffd6 898424d0000000 8d442458 50 }
+ $sequence_1 = { b22e b06c 51 c644240c77 c644240d73 c644240f5f c644241033 }
+ $sequence_2 = { c684241002000000 f3ab 66ab aa 8d442408 6804010000 50 }
+ $sequence_3 = { 8d742438 8dbc24f4000000 33c0 f3a5 b908000000 8d7c2418 }
+ $sequence_4 = { 68???????? 68???????? 50 ffd7 8d8c241c020000 6804010000 8d94241c010000 }
+ $sequence_5 = { 57 33f6 b922000000 33c0 }
+ $sequence_6 = { 52 ffd6 898424e0000000 8d442440 50 ffd6 }
+ $sequence_7 = { 894c242d 56 66894c2435 33f6 89442420 884c2437 57 }
+ $sequence_8 = { 0bc1 33c7 0344242c 8d8410442229f4 8bd0 c1e006 c1ea1a }
+ $sequence_9 = { c644245400 c684245801000000 f3ab 66ab }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <90112
}
-rule MALPEDIA_Win_Webc2_Head_Auto : FILE
+rule MALPEDIA_Win_Quarterrig_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fbb157f3-5522-59eb-8966-994ac95b42ec"
+ id = "b690a4f4-b484-55ac-b058-10bc50927e69"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_head"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_head_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.quarterrig"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.quarterrig_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "3accb9e007709b9cb8a99022cd642781f2c16d496b60a9e07fc0420c29da6736"
+ logic_hash = "311b3b8ecf53c484bcc2dd986bb0e82467b08ff5a42c5d9fde578d475409e28c"
score = 75
quality = 75
tags = "FILE"
@@ -169127,32 +176320,32 @@ rule MALPEDIA_Win_Webc2_Head_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8a8c0cc0000000 eb02 b13d c1e810 83e03f 0fbec9 }
- $sequence_1 = { 68???????? 55 55 896c2434 ffd7 }
- $sequence_2 = { 8d942444080000 03f0 51 50 52 55 ff15???????? }
- $sequence_3 = { e8???????? 83c40c 85c0 0f8554020000 b900050000 }
- $sequence_4 = { 33db 89442418 52 c6450000 }
- $sequence_5 = { 7513 8dbc2444040000 83c9ff f2ae f7d1 49 894c241c }
- $sequence_6 = { 89442410 c1e002 89442418 8b4c2424 }
- $sequence_7 = { eb02 b03d 884303 8b442410 }
- $sequence_8 = { 83c410 c3 5f c6450000 5e }
- $sequence_9 = { 2500ff0000 45 3d003d0000 7435 }
+ $sequence_0 = { 32c0 e9???????? 8b15???????? 498bce ff15???????? 3d02010000 }
+ $sequence_1 = { 884597 33ff 897d9b 41f7411800400000 7528 410f1000 f30f7f45a7 }
+ $sequence_2 = { 4883c438 c3 488d0d53c10500 e8???????? 833d????????ff 75d2 c605????????01 }
+ $sequence_3 = { 65488b042558000000 ba04000000 488b0cc8 8b040a 3905???????? 7f19 488d0513cc0500 }
+ $sequence_4 = { 488b5590 4883fa10 720d 48ffc2 488b4c2478 e8???????? 4c896d88 }
+ $sequence_5 = { 488d0569fe0500 488b4c2448 4833cc e8???????? 0f28742460 0f287c2450 }
+ $sequence_6 = { eb3a e8???????? 4c8bc0 80780500 7429 33d2 }
+ $sequence_7 = { 4c89b690000000 4c89b698000000 0f108780000000 0f118680000000 0f108f90000000 0f118e90000000 4c89b790000000 }
+ $sequence_8 = { 4c8bcf 4533c0 488d5510 488d4c2478 e8???????? 83cb01 }
+ $sequence_9 = { 48895520 c744243402000000 41b840000000 458d78d0 418bd7 488d4d28 e8???????? }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <971776
}
-rule MALPEDIA_Win_Pay2Key_Auto : FILE
+rule MALPEDIA_Win_Poison_Ivy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "26097eea-fdd3-5ff6-a78a-aae3970171ae"
+ id = "ec8c2f98-412f-543c-9758-b1aacde91b4e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pay2key"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pay2key_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poison_ivy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poison_ivy_auto.yar#L1-L91"
license_url = "N/A"
- logic_hash = "fed562ca29ad610b012032606168f69e452506f6e6212e1bb41332762ffb58be"
+ logic_hash = "431acfd8496c54390529508a28488eb12118d11f97e2de9a76cce0e819bacb59"
score = 75
quality = 75
tags = "FILE"
@@ -169166,32 +176359,29 @@ rule MALPEDIA_Win_Pay2Key_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f7d1 33d2 3b4dfc 8bcb 0f43d0 3bd7 0f43fa }
- $sequence_1 = { e8???????? 8d4e2c e8???????? 8d4e14 e8???????? c74604???????? 8b7e10 }
- $sequence_2 = { ffd7 837d1c08 8d5508 8d7508 0f435508 0f437508 }
- $sequence_3 = { c745fc00000000 833e00 7517 68de020000 68???????? 68???????? }
- $sequence_4 = { 50 e8???????? 83ec18 c645fc05 8bcc 896584 c7411000000000 }
- $sequence_5 = { 3bf7 0f8595f7ffff 83cfff c745fc07000000 8b750c 85f6 7429 }
- $sequence_6 = { eb05 6880000000 8bce e8???????? 8b4e20 8bc3 8b09 }
- $sequence_7 = { c7461000000000 7202 8b36 33c0 668906 8db758030000 8b4614 }
- $sequence_8 = { 3bf7 758c 8b5dec ff7314 8b35???????? ffd6 }
- $sequence_9 = { eb02 33c0 894758 8d5758 8a4304 88475c e8???????? }
+ $sequence_0 = { ff9681000000 80beaf08000001 7507 b902000080 eb05 }
+ $sequence_1 = { b902000080 eb05 b901000080 8d45fc }
+ $sequence_2 = { 51 ff5635 68ff000000 8d86b1060000 }
+ $sequence_3 = { 50 6a01 6a00 8d86120e0000 50 ff75fc }
+ $sequence_4 = { b901000080 8d45fc 50 683f000f00 6a00 57 51 }
+ $sequence_5 = { 51 57 ff9681000000 8d45fc }
+ $sequence_6 = { 8d86120e0000 50 ff75fc ff563d ff75fc ff5631 }
condition:
- 7 of them and filesize <2252800
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Babuk_Auto : FILE
+rule MALPEDIA_Win_Carbanak_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d5eda12f-ea4b-52c1-b2a1-b261c48c105c"
+ id = "c07fe935-504c-5c98-a746-fcd9d2cd2656"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.babuk"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.babuk_auto.yar#L1-L163"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.carbanak"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.carbanak_auto.yar#L1-L108"
license_url = "N/A"
- logic_hash = "55094f2694a9f4921a100bba31a1afb9b9947feff6d1ffe3b263a4bd8f4c17f7"
+ logic_hash = "71119e0e8f2ea511e845d7f70364c6b521841c48aa27c3226400782c05c0bf22"
score = 75
quality = 75
tags = "FILE"
@@ -169205,38 +176395,32 @@ rule MALPEDIA_Win_Babuk_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 6800000100 e8???????? 83c404 }
- $sequence_1 = { 50 ff15???????? 83f803 7502 }
- $sequence_2 = { 8b45fc 83c002 8945fc 837dfc0a 0f83dc000000 8b4dfc }
- $sequence_3 = { 8b4d08 8b540104 52 8b0401 50 e8???????? }
- $sequence_4 = { 8b4dfc c1e108 ba01000000 d1e2 8b4508 }
- $sequence_5 = { 8b95ccfdffff 83c201 8995ccfdffff 83bdccfdffff1f 735f 8d85f4fdffff }
- $sequence_6 = { 8b4dfc 8b5508 8b44ca04 50 }
- $sequence_7 = { 8b4d08 c7040100000000 c744010400000000 ba08000000 }
- $sequence_8 = { 0bca 894dfc 8b45fc c1e008 b901000000 }
- $sequence_9 = { 8b0401 50 e8???????? 83c408 8945ec 8955f0 }
- $sequence_10 = { c744010400000000 ba08000000 6bc200 8b4d08 }
- $sequence_11 = { 8b4508 c704107465206b c745fc00000000 eb09 }
- $sequence_12 = { 744a 837dd801 7444 8b55ec 52 ff15???????? 8d45ac }
- $sequence_13 = { e8???????? 83c410 c78574ffffff00000000 eb0f }
- $sequence_14 = { 57 b808000000 6bc80a 8b5508 c7040a00000000 c7440a0400000000 c745fc00000000 }
- $sequence_15 = { 51 e8???????? 83c408 8945f4 8955f8 }
+ $sequence_0 = { 7f05 83c061 eb03 83c027 }
+ $sequence_1 = { 7907 32c0 e9???????? 7507 b001 }
+ $sequence_2 = { 32c0 e9???????? 7507 b001 }
+ $sequence_3 = { 2bd1 81e921100000 8bc1 c1f80e 0cc0 }
+ $sequence_4 = { 8b4608 eb02 8bc3 85c0 }
+ $sequence_5 = { c3 8d4120 3c1f 7705 0fb6c1 }
+ $sequence_6 = { 7c0d e8???????? 84c0 7504 }
+ $sequence_7 = { 7c0d e8???????? 84c0 7504 33c0 }
+ $sequence_8 = { e9???????? 3d2c5c0700 750a e8???????? }
+ $sequence_9 = { 3d2c5c0700 750a e8???????? e9???????? }
condition:
- 7 of them and filesize <183296
+ 7 of them and filesize <658432
}
-rule MALPEDIA_Win_Rarog_Auto : FILE
+rule MALPEDIA_Win_Pikabot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "af269765-c756-5cee-8964-0f35e326beb2"
+ id = "16fbebe5-029d-50d1-a8a8-9f8a45a24f27"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rarog"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rarog_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pikabot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pikabot_auto.yar#L1-L175"
license_url = "N/A"
- logic_hash = "90be509347cdd78e80ac954224309fb579e700a948cbf60773c02796ec820629"
+ logic_hash = "81c8e73356106864f0a8f72d23108459a17754dd4d587aefd7feb43e822dba1f"
score = 75
quality = 75
tags = "FILE"
@@ -169250,32 +176434,39 @@ rule MALPEDIA_Win_Rarog_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8db5c8fdffff e9???????? 8b542408 8d420c 8b8ab8fdffff }
- $sequence_1 = { 83781410 7202 8b00 8b35???????? 53 53 50 }
- $sequence_2 = { 8d8d28fdffff e8???????? 53 53 68???????? 8d85e8feffff 50 }
- $sequence_3 = { 50 68???????? 51 e8???????? 83c40c 83ec1c c645fc21 }
- $sequence_4 = { 8b75ac 46 56 53 ff15???????? 89459c }
- $sequence_5 = { 68???????? 50 8d4dd0 e8???????? 59 59 8d8d9cfeffff }
- $sequence_6 = { ff7508 6a00 6a01 ff15???????? 8bf0 85f6 7409 }
- $sequence_7 = { 57 83c8ff e8???????? 53 68???????? 83c8ff }
- $sequence_8 = { 59 8b7508 8d34f5501d4300 391e 7404 8bc7 eb6d }
- $sequence_9 = { c1e002 c1eb06 0bc3 8a80c0b64200 884102 0fbe443202 83e03f }
+ $sequence_0 = { 8945f8 8b4510 8945f4 8b4510 48 }
+ $sequence_1 = { 894510 837df400 741a 8b45fc 8b4df8 8a09 }
+ $sequence_2 = { 8b4df8 8a09 8808 8b45fc }
+ $sequence_3 = { 40 8945fc 8b45f8 40 8945f8 ebd3 8b4508 }
+ $sequence_4 = { 8945f8 ebd3 8b4508 c9 c3 55 }
+ $sequence_5 = { 83ec0c 8b4508 8945fc 8b450c 8945f8 8b4510 }
+ $sequence_6 = { 7ce9 8b4214 2b420c 5f }
+ $sequence_7 = { e8???????? ffd0 c9 c3 55 8bec }
+ $sequence_8 = { 8bfa 85c9 7436 85ff }
+ $sequence_9 = { 8b0cba 03ce e8???????? 8bd0 }
+ $sequence_10 = { 8a1c08 8d4320 0fb6c8 8d53bf 80fa19 }
+ $sequence_11 = { 40 8945fc 3bc7 72d5 }
+ $sequence_12 = { 55 8bec 83ec10 53 56 8b35???????? b84d5a0000 }
+ $sequence_13 = { e8???????? 8bd0 e8???????? 3b45fc }
+ $sequence_14 = { c3 56 8bf1 85c9 7419 85d2 7415 }
+ $sequence_15 = { 84c0 75f6 c60100 8bc6 5e }
+ $sequence_16 = { c9 c3 64a130000000 8b4018 c3 55 }
condition:
- 7 of them and filesize <598016
+ 7 of them and filesize <1717248
}
-rule MALPEDIA_Win_Slothfulmedia_Auto : FILE
+rule MALPEDIA_Win_Pebbledash_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e689a948-8c82-52e0-a234-12c770624669"
+ id = "3f16c34e-ab8c-5fd5-9a27-9934f8af2f6b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.slothfulmedia"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.slothfulmedia_auto.yar#L1-L171"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pebbledash"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pebbledash_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "0fe44aa9ee5461148172e6c82a2b51d37b08cccc220629908d9ee4d92a4c22d4"
+ logic_hash = "477e05e2df7e0e436b23bf26c9707de6486fd65cc8fb3dc50d94f319663b31bc"
score = 75
quality = 75
tags = "FILE"
@@ -169289,38 +176480,32 @@ rule MALPEDIA_Win_Slothfulmedia_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 5f 8d4638 5e }
- $sequence_1 = { 8938 8bd8 83c008 8945fc }
- $sequence_2 = { 68???????? be04010000 33c9 56 }
- $sequence_3 = { 83c002 663bca 75f5 2bc6 d1f8 }
- $sequence_4 = { 40 e8???????? bb04010000 53 8d85e0fdffff 50 }
- $sequence_5 = { 8b835c040000 68???????? 0564010000 6a05 50 e8???????? 83c418 }
- $sequence_6 = { 0fb7f0 f7de 6aff ff7508 }
- $sequence_7 = { 8d444606 83c410 0375f0 891c08 ff45fc }
- $sequence_8 = { 6689442414 e8???????? 83c40c 6a00 ff15???????? }
- $sequence_9 = { ff15???????? 8b8c2410020000 5f 5e 33cc 33c0 }
- $sequence_10 = { 68???????? ffd6 85c0 7507 ffd7 83f805 }
- $sequence_11 = { 5e 33cc 33c0 e8???????? 81c40c020000 c21000 3b0d???????? }
- $sequence_12 = { 8d54240c 6a00 52 e8???????? 83c40c 6804010000 8d44240c }
- $sequence_13 = { 6a04 6a00 8d4c2410 51 ff15???????? 8b8c2410020000 5f }
- $sequence_14 = { 6a00 ff15???????? 8b35???????? 8b3d???????? 90 68???????? ffd6 }
- $sequence_15 = { 68d0070000 ff15???????? 33c0 6806020000 50 }
+ $sequence_0 = { 25ffff0000 3bd0 740a b800000004 e9???????? 83bd74fbffff00 751a }
+ $sequence_1 = { 8be5 5d c3 55 8bec 81ecd0000000 c68530ffffff8e }
+ $sequence_2 = { 51 e8???????? 83c418 8d55f0 52 8d85a4f3ffff 50 }
+ $sequence_3 = { 8d95a0f5ffff 52 ff15???????? 898594f7ffff 83bd94f7ffffff 7505 }
+ $sequence_4 = { a3???????? 833d????????00 742c 8b55f0 8955dc 8b45dc 8945e0 }
+ $sequence_5 = { 8d1c85609f4200 c1e603 8b03 f644300401 7469 57 }
+ $sequence_6 = { 8b08 8b550c 8b4110 8902 8d8d70feffff 51 8b550c }
+ $sequence_7 = { 8b45e8 83c001 8945e8 837de80e 733b }
+ $sequence_8 = { 51 e8???????? 83c40c 817d0c1e010000 7f15 837d101e }
+ $sequence_9 = { 8b55fc 0355e4 33c0 8a02 83f850 753b 8b4dfc }
condition:
- 7 of them and filesize <122880
+ 7 of them and filesize <360448
}
-rule MALPEDIA_Win_Privateloader_Auto : FILE
+rule MALPEDIA_Win_Roll_Sling_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "704976b4-103d-5caa-b3a7-f03a44637bd7"
+ id = "2ab89f07-526d-5404-82a8-065dc4627e90"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.privateloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.privateloader_auto.yar#L1-L183"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.roll_sling"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.roll_sling_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "15e13900aae7d6be3cc889a3774b293d4c50bba5cbabc1926697368cc70d28fc"
+ logic_hash = "57322c90ec2e7f0f9b25a02d63cfaa81737587c7821fd15face6c16907aace76"
score = 75
quality = 75
tags = "FILE"
@@ -169334,80 +176519,71 @@ rule MALPEDIA_Win_Privateloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8965ec 8b55ec 8955e8 8d45f8 }
- $sequence_1 = { 894df4 8b55fc 837a1410 7209 }
- $sequence_2 = { 0fb64dec 85c9 7408 8b55fc 8b02 8945e8 }
- $sequence_3 = { 8b4dec 8b5508 895110 8b4508 8945e4 8b4de8 034de4 }
- $sequence_4 = { 8b45d8 8b4ddc 8b55d0 8b75d4 }
- $sequence_5 = { 8b4dec e8???????? 8b4df0 e8???????? 8845fc }
- $sequence_6 = { 8975d4 8b45d0 8b55d4 5e }
- $sequence_7 = { 8b4de8 8b75ec 2bc8 1bf2 894de0 8975e4 a1???????? }
- $sequence_8 = { e8???????? 33d2 b93f000000 f7f1 }
- $sequence_9 = { 8b4590 8b4d94 8b5588 8b758c }
- $sequence_10 = { a3???????? 33c0 5e c3 3b0d???????? }
- $sequence_11 = { 896c2404 8bec 81ec68010000 a1???????? 33c5 8945fc 56 }
- $sequence_12 = { d81d???????? c9 b8ffffffff 99 c3 56 8b35???????? }
- $sequence_13 = { 13f1 83c201 8955e0 83d600 }
- $sequence_14 = { 6a04 8d4310 50 6a06 }
- $sequence_15 = { 7507 6800008000 eb02 6a00 }
- $sequence_16 = { 8b45e4 50 51 52 }
- $sequence_17 = { 0bc8 56 57 7529 }
- $sequence_18 = { 03d0 8b4d9c 13f1 83c201 }
+ $sequence_0 = { 33c9 ff15???????? 48898424a8000000 4c8bf8 4885c0 7431 ff15???????? }
+ $sequence_1 = { 4c8b7dd8 3b5c2440 7306 488b4dd0 ebb9 498bcd }
+ $sequence_2 = { b80d000000 41bf0a000000 440f44f8 33db 4c03f7 0f1f4000 66660f1f840000000000 }
+ $sequence_3 = { 488b55d0 4883fa10 0f824effffff 48ffc2 488b4db8 488bc1 4881fa00100000 }
+ $sequence_4 = { 488905???????? 498bde 4883fa10 480f431d???????? 4803d9 41b823000000 }
+ $sequence_5 = { 0f86ec000000 eb0a 48b92700000000000080 e8???????? 4885c0 0f84cc000000 488d7827 }
+ $sequence_6 = { e8???????? 41c6042f00 48893e 488bc6 4c8b6c2460 488b7c2458 }
+ $sequence_7 = { 41b801010000 e8???????? 418bc6 4d8d4d10 4c8d3d04180100 41be04000000 }
+ $sequence_8 = { eb14 4889742420 4c8d4da0 488bd6 }
+ $sequence_9 = { 7476 48895c2438 4533c9 4533c0 48897c2420 bad8070000 }
condition:
- 7 of them and filesize <3670016
+ 7 of them and filesize <299008
}
-rule MALPEDIA_Win_Makop_Ransomware_Auto : FILE
+rule MALPEDIA_Win_Hardrain_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cd34e745-9497-5ffc-bd73-ecb5996e2067"
- date = "2023-07-11"
- modified = "2023-07-15"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.makop_ransomware"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.makop_ransomware_auto.yar#L1-L124"
+ id = "97910df3-cc32-519a-be42-e878c516a607"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hardrain"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hardrain_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "3c7cc3419f322a8e9eb8473ecaf54fc5da0725e8a0f35ff3f90245e28389848b"
+ logic_hash = "e6beb234b33f52448f8a2b08bdea562633ec321b73d43e884a2e68853ad4b784"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20230705"
- malpedia_hash = "42d0574f4405bd7d2b154d321d345acb18834a41"
- malpedia_version = "20230715"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb02 33f6 803d????????00 751f 803d????????00 7516 80fb01 }
- $sequence_1 = { 52 50 51 e8???????? 8b542430 83c40c 68e0930400 }
- $sequence_2 = { 52 66c7060802 66c746041066 c6460820 }
- $sequence_3 = { 56 ff15???????? 85c0 750b 8906 32c0 5e }
- $sequence_4 = { 83c001 84c9 75f7 2bc7 83e801 39442404 720a }
- $sequence_5 = { ffd6 85ff 740f 85db 740b 837c242000 7404 }
- $sequence_6 = { 8b2d???????? 3beb 742e 8b4524 3bc3 7407 50 }
- $sequence_7 = { 7416 e8???????? 6a00 e8???????? 83c404 }
- $sequence_8 = { e8???????? 8b442418 83c40c 8b4f0c }
- $sequence_9 = { 742f 33c0 3906 763d 8d4c2448 }
+ $sequence_0 = { 66c74424380000 f3ab 66ab b981000000 33c0 }
+ $sequence_1 = { 51 56 89542414 8944241c e8???????? 83c410 85c0 }
+ $sequence_2 = { 8b7c241c 6685ff 7509 5f 83c8ff 5e 83c410 }
+ $sequence_3 = { ff15???????? 85c0 7eca 8d442430 }
+ $sequence_4 = { 51 8bce e8???????? 85c0 7427 6a14 }
+ $sequence_5 = { 68b4000000 52 50 e8???????? }
+ $sequence_6 = { 8d842484000000 68???????? 50 e8???????? 8d8c248c000000 6800040000 8d942490040000 }
+ $sequence_7 = { 83c418 c3 33c0 33c9 68b4000000 89442408 }
+ $sequence_8 = { ff15???????? 8b0e 85c9 7406 8b11 6a01 ff12 }
+ $sequence_9 = { 81ec0c010000 8b842414010000 8b942418010000 57 89442404 b942000000 }
condition:
- 7 of them and filesize <107520
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Tabmsgsql_Auto : FILE
+rule MALPEDIA_Win_Goldenspy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "95969567-7681-52bb-9f9f-efce304f47a8"
+ id = "2db85832-8503-5134-9cf2-a79f16f8ed47"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tabmsgsql"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tabmsgsql_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.goldenspy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.goldenspy_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "7b59d9e77530877005ccccefb5d251d16423422a57046d3f1c0987aa86d57fc9"
+ logic_hash = "45ec0195c1eec86aab8f23405836b0cab0b81ad642d99b8dc40b2feb153827cd"
score = 75
quality = 75
tags = "FILE"
@@ -169421,32 +176597,32 @@ rule MALPEDIA_Win_Tabmsgsql_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c0 f2ae f7d1 2bf9 8bd1 8bf7 8bbc24a4010000 }
- $sequence_1 = { 8a443901 c0fb02 8a80c8244100 c0e004 02c3 880416 }
- $sequence_2 = { 8882c8254100 48 42 83f841 }
- $sequence_3 = { 8bf8 75ce 8b6c2414 8b542418 b8ad8bdb68 }
- $sequence_4 = { 6804010000 8b842478030000 52 c744242844000000 c744245401010000 8b08 8b400c }
- $sequence_5 = { f2ae f7d1 49 8d85c8f7ffff }
- $sequence_6 = { 0f8eb2000000 8b7c2414 0fbe05???????? 33db 8a1c39 3bd8 }
- $sequence_7 = { ff15???????? b940000000 33c0 bf???????? 68???????? f3ab 68???????? }
- $sequence_8 = { a1???????? 50 ff15???????? b940000000 33c0 bf???????? }
- $sequence_9 = { 33c0 8a443901 c0fb02 8a80c8244100 c0e004 02c3 880416 }
+ $sequence_0 = { 0f87e4000000 e9???????? 83c754 837f1000 740f 68???????? 8bcf }
+ $sequence_1 = { 83c0fc 83f81f 0f8777060000 52 51 e8???????? 83c408 }
+ $sequence_2 = { 8b7608 807e0d00 74a8 8b4de8 8b5de4 }
+ $sequence_3 = { e8???????? 8b551c 83fa10 0f82b8fcffff 8b4d08 42 8bc1 }
+ $sequence_4 = { e8???????? 51 68???????? 8bcb e8???????? 8b83c8000000 }
+ $sequence_5 = { 8d4dd8 6a1a 68???????? c745e800000000 c745ec0f000000 c645d800 e8???????? }
+ $sequence_6 = { 57 68???????? e8???????? 8d47ff 83c408 83f804 }
+ $sequence_7 = { 75f2 8b5308 8bf2 8b7b14 0f1f00 8a02 42 }
+ $sequence_8 = { ff75e4 ff461c 8d4628 50 e8???????? 897e30 c7463400000000 }
+ $sequence_9 = { 8b85f8feffff 8b4004 c78405f8feffffb4e24600 8b85f8feffff 8b4804 8d41b0 89840df4feffff }
condition:
- 7 of them and filesize <163840
+ 7 of them and filesize <1081344
}
-rule MALPEDIA_Win_R77_Auto : FILE
+rule MALPEDIA_Win_Freenki_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "79566c97-5b66-5f14-a1d3-bc9852e6d698"
+ id = "96c9c22a-8c0f-508a-9c8b-2adc585b1381"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.r77"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.r77_auto.yar#L1-L154"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.freenki"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.freenki_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "76c887c6ccc22f9627519af58959f5ccdb37c325ffba24612ced9e4b32cde701"
+ logic_hash = "ea73b0cd02f4881d245e91a02d5574d630e230bb3618aadd7337accb2e33b167"
score = 75
quality = 75
tags = "FILE"
@@ -169460,36 +176636,32 @@ rule MALPEDIA_Win_R77_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 740c 8b4f0c e8???????? 85c0 }
- $sequence_1 = { 740b 8b0f e8???????? 85c0 }
- $sequence_2 = { 33c9 4c8d05e3d40000 488d15e4d40000 e8???????? 4885c0 740f }
- $sequence_3 = { 0f8517030000 488d0d58ad0100 ff15???????? 4885c0 7412 }
- $sequence_4 = { 4c8d058bfb0000 488b45e0 48c1e820 85c0 755d 8b45e0 }
- $sequence_5 = { 33d2 660f1344243c 33c9 e8???????? 59 }
- $sequence_6 = { f7d8 1bc0 40 85c0 750b 46 3b37 }
- $sequence_7 = { c1fa06 6bc838 8b0495f8a00110 f644082801 7422 8d4508 8975f8 }
- $sequence_8 = { 745c ffc1 413bc8 72f1 4885ff }
- $sequence_9 = { 660f58e0 660fc5c400 25f0070000 660f28a050680110 660f28b840640110 660f54f0 660f5cc6 }
- $sequence_10 = { 7408 8b442430 8bc8 cd29 488d0df6980100 }
- $sequence_11 = { 03f3 03c3 894508 833e00 7447 8b7df0 8b08 }
- $sequence_12 = { 488b03 833800 7513 488d15e3a70000 488d0dbca70000 }
- $sequence_13 = { 33c0 c3 56 e8???????? ff15???????? }
+ $sequence_0 = { 83e03f 6bc830 8b049578394200 c644082801 897de4 c745fcfeffffff }
+ $sequence_1 = { 57 e8???????? 83c404 ff75f8 e8???????? 8bf8 }
+ $sequence_2 = { f7d9 0bc8 51 53 e8???????? ffb504e7ffff 8bd8 }
+ $sequence_3 = { 68???????? 50 ff5110 8b55b8 8b4dcc 2bd1 0f1f440000 }
+ $sequence_4 = { 6bd830 8b04bd78394200 f644032801 7444 837c0318ff 743d e8???????? }
+ $sequence_5 = { e8???????? 8b3d???????? 33db 0f1f8000000000 8d853cd4ffff 50 }
+ $sequence_6 = { 64a300000000 8bf1 89b5e4edffff 33c0 c785c0edffff00000000 }
+ $sequence_7 = { 6bce4c 53 0f100419 0f1100 e8???????? 8b4dfc 83c404 }
+ $sequence_8 = { 68???????? ffb5e0f9ffff ff15???????? f7d8 5e }
+ $sequence_9 = { dd00 ebc6 c745e0b8de4100 e9???????? c745e0c0de4100 e9???????? }
condition:
- 7 of them and filesize <350208
+ 7 of them and filesize <327680
}
-rule MALPEDIA_Win_Computrace_Auto : FILE
+rule MALPEDIA_Win_Poweliks_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4429b6f7-4609-5864-be9b-bd86b296052a"
+ id = "14491e8d-2d96-5692-9946-38a18e40eb85"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.computrace"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.computrace_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poweliks"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poweliks_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "d8751f69a58562c91660e3060ff3b6e112f846c07b191aab11a4034542037b61"
+ logic_hash = "38ca9b6ecbf4df7389b1ea24aaf1d7d4d015a732f44c61342f6c9c25d4c2ea48"
score = 75
quality = 75
tags = "FILE"
@@ -169503,32 +176675,32 @@ rule MALPEDIA_Win_Computrace_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff75cc e8???????? 3975e4 753a }
- $sequence_1 = { e8???????? 8a4002 8b0d???????? 8801 ff35???????? }
- $sequence_2 = { 740e 837de400 7408 037de4 897dd8 eba6 8b4514 }
- $sequence_3 = { 7503 800e08 e8???????? 894604 ff750c 8f4618 }
- $sequence_4 = { e30d 83c00a 51 ff750c 50 e8???????? }
- $sequence_5 = { e8???????? 837de400 0f8593feffff 8b86481b0000 83786c00 0f8483feffff }
- $sequence_6 = { 8b7508 80665cfe 33c0 8945fc 8845fb 6689461a 48 }
- $sequence_7 = { 7414 c745dc01000000 897d8c 6af1 }
- $sequence_8 = { e8???????? 8945e4 3bc6 7417 }
- $sequence_9 = { ff15???????? f7d8 1bc0 40 57 }
+ $sequence_0 = { eb0b 8b5118 ebc9 8b5dec 8b75e8 8b45f8 8b0c87 }
+ $sequence_1 = { c745b4726f6341 c745b864647265 66c745bc7373 c645be00 8bc8 57 }
+ $sequence_2 = { 83ff0c 7439 3bc8 75ce 8b5508 }
+ $sequence_3 = { 8d5598 33ff 2bf2 8d147e 8a541598 32547d98 }
+ $sequence_4 = { 7415 8b7d08 8b720c 81c704110000 03f7 8b7a04 }
+ $sequence_5 = { 663b4b06 7333 8b4a08 8b32 3bce 7602 8bce }
+ $sequence_6 = { 33c9 663b4b06 7333 8b4a08 8b32 3bce 7602 }
+ $sequence_7 = { 57 0fb65dfe 81e307000080 7905 4b }
+ $sequence_8 = { 8b3486 8365fc00 03ca 894df4 8d45d0 03f2 2945f4 }
+ $sequence_9 = { 3a5c0db0 7506 40 83f80f }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <115712
}
-rule MALPEDIA_Win_Httpsuploader_Auto : FILE
+rule MALPEDIA_Win_Mariposa_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "be17d448-1d90-5f75-8f13-d63b39944dc3"
+ id = "2a3a2192-1985-5afb-a3c8-457f3f4c729c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.httpsuploader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.httpsuploader_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mariposa"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mariposa_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "5be7e6e5938fcb4fa9787510fb0867a1f442345e4d8453db75c177a24413afa4"
+ logic_hash = "343ac33f57cd9cc9bfc1841bf1bd211734de245f417ee554220587a46ed4086f"
score = 75
quality = 75
tags = "FILE"
@@ -169537,37 +176709,37 @@ rule MALPEDIA_Win_Httpsuploader_Auto : FILE
signator_config = "callsandjumps;datarefs;binvalue"
malpedia_rule_date = "20231130"
malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { 33ff 33d2 41b806020000 6689bc2470020000 e8???????? 488d4c2451 33d2 }
- $sequence_1 = { 33d2 33c9 897c2428 48895c2420 ff15???????? eb3b 488d0dc3bd0000 }
- $sequence_2 = { 4883ec20 488bfa 488bd9 488d0501700000 488981a0000000 83611000 }
- $sequence_3 = { 4c8bc0 418bd4 e8???????? 488d8dd0000000 ff15???????? }
- $sequence_4 = { 488d0d6c280000 4533c9 ba00000040 4489442420 ff15???????? }
- $sequence_5 = { 4c8d25cf7d0000 f0ff09 7511 488b8eb8000000 493bcc }
- $sequence_6 = { 488d0543b50000 eb04 4883c014 4883c428 c3 4053 }
- $sequence_7 = { 488d158e380000 488bc8 ff15???????? 4885c0 0f847a010000 }
- $sequence_8 = { 81fa01010000 7d13 4863ca 8a44191c 4288840170fa0000 }
- $sequence_9 = { 745e 6666660f1f840000000000 488b0d???????? 488d542440 4533c9 4533c0 ff15???????? }
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { 55 8bec 53 56 bb???????? 43 }
+ $sequence_1 = { ffd3 33c0 50 e8???????? 33c0 }
+ $sequence_2 = { 53 56 bb???????? 43 }
+ $sequence_3 = { 885c0cff e2f1 ba???????? 2bd6 8bdc 03da 4b }
+ $sequence_4 = { 8a1c0e 02d8 32dc fec0 885c0cff e2f1 }
+ $sequence_5 = { 8bdc 03da 4b 54 ffd3 33c0 }
+ $sequence_6 = { 885c0cff e2f1 ba???????? 2bd6 }
+ $sequence_7 = { 8a4301 8a6302 f6d0 02c4 d0f8 8a1c0e }
+ $sequence_8 = { 53 56 bb???????? 43 803b00 }
+ $sequence_9 = { 03da 4b 54 ffd3 33c0 }
condition:
- 7 of them and filesize <190464
+ 7 of them and filesize <311296
}
-rule MALPEDIA_Win_Rhino_Auto : FILE
+rule MALPEDIA_Win_Plaintee_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "11a60875-723d-53d2-ab23-e9023e9a450c"
+ id = "e3bbe66b-b26a-510d-8a1b-05b2e6f7426c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rhino"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rhino_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.plaintee"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.plaintee_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "06d154dd08a9cc876dd4f55564b3f05b1da55b4793bd9c16429a3bb1cbe16dda"
+ logic_hash = "8bcc878fa501588c97ae4d4926e84d32a4619fd799353944068271d6d4e36727"
score = 75
quality = 75
tags = "FILE"
@@ -169581,32 +176753,32 @@ rule MALPEDIA_Win_Rhino_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4160 c3 6a40 58 c3 b8???????? e8???????? }
- $sequence_1 = { c745f00f000000 885ddc 53 be04010000 895dfc 56 8d4ddc }
- $sequence_2 = { c1c105 8b400c 89442440 8bc5 034c2440 33c3 23c6 }
- $sequence_3 = { 2b16 b8ffffff03 c1fa06 2bc2 3bc1 7217 8d040a }
- $sequence_4 = { e8???????? 8bf9 897df0 8b7508 8d4f0c c74704???????? 56 }
- $sequence_5 = { e8???????? 895d60 897d64 8b06 8d4de0 51 8bce }
- $sequence_6 = { 890496 85c9 75e6 42 3b54240c 72ec 33c0 }
- $sequence_7 = { 74af 8b4634 8d4d08 51 50 50 894508 }
- $sequence_8 = { 5e 64890d00000000 c9 c3 8b514c 395148 57 }
- $sequence_9 = { 8b4f14 8b4114 3b410c 7507 8bcf e8???????? 33c0 }
+ $sequence_0 = { 8d4c2404 6a00 8d542404 51 52 ffd0 8b4c2400 }
+ $sequence_1 = { 8bf1 6802020000 ff15???????? 85c0 740a b001 }
+ $sequence_2 = { 50 8d853c010000 50 8b8538010000 6a5a 52 }
+ $sequence_3 = { 8d442400 56 50 8bf1 6802020000 ff15???????? }
+ $sequence_4 = { 5e 81c490010000 c3 8bce }
+ $sequence_5 = { 85f6 74c6 8bce e8???????? }
+ $sequence_6 = { f3ab 66ab b900010000 33c0 }
+ $sequence_7 = { eb02 33f6 8bce e8???????? 8a8669010000 }
+ $sequence_8 = { 68ac010000 e8???????? 83c404 85c0 7412 }
+ $sequence_9 = { 750a b001 5e 81c490010000 c3 }
condition:
- 7 of them and filesize <1288192
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Newposthings_Auto : FILE
+rule MALPEDIA_Win_Mailto_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d2908836-d6a9-5323-a30e-68bb82428f91"
+ id = "ea0d0ed3-d3ad-5738-b388-39bdea82080a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.newposthings"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.newposthings_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mailto"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mailto_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "aacccdc30f2a004211f7fc15df6e0bf41cf9693ce7a4e367dede73ae07376ff4"
+ logic_hash = "f253c860f2dfd876ea6c63e66e3d4bfe3e95a5b5178079f30b977b373576f89e"
score = 75
quality = 75
tags = "FILE"
@@ -169620,32 +176792,32 @@ rule MALPEDIA_Win_Newposthings_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8a4601 3c30 7c04 3c39 7e0a 3c3d 7406 }
- $sequence_1 = { 7423 3d00000400 7550 80c980 884c3704 8b0c9d481d0210 8a443124 }
- $sequence_2 = { 83e61f 8b0485481d0210 c1e606 80643004fd 8b45f8 8b55fc 5f }
- $sequence_3 = { ff7510 ff750c 56 6843120110 e8???????? 83c418 85c0 }
- $sequence_4 = { 83c602 663906 74f8 6a03 56 68548e0110 e8???????? }
- $sequence_5 = { 50 c644245c00 8bce e8???????? 8bf0 eb02 33f6 }
- $sequence_6 = { e8???????? 50 8bcb e8???????? c745fc00000000 c745f001000000 8bc3 }
- $sequence_7 = { 8b049538f34500 47 ff3418 ff15???????? 85c0 750a ff15???????? }
- $sequence_8 = { 83c204 8955e0 eb86 890cb538f34500 }
- $sequence_9 = { e8???????? c745fc00000000 83ec18 8bcc 896588 6aff }
+ $sequence_0 = { 47 3bfb 7297 8b44241c 8930 8b442420 85c0 }
+ $sequence_1 = { 83c404 85f6 7429 85ed 7419 8b742414 }
+ $sequence_2 = { 8b442418 8938 8b44241c 85c0 7402 8930 }
+ $sequence_3 = { 55 56 57 8b7c2424 c744241400000000 85ff 7457 }
+ $sequence_4 = { 85f6 0f8477010000 e8???????? 3b7014 0f8469010000 8b0d???????? 85c9 }
+ $sequence_5 = { 8b08 ff5130 85c0 7822 ff74242c e8???????? }
+ $sequence_6 = { 897c242c 8bc8 89442420 c1f81a c1f91f 23c8 8bc1 }
+ $sequence_7 = { 40 eb64 83ff01 7522 0fb6d1 bf02000000 83e203 }
+ $sequence_8 = { 0fb6466b 884118 0fb6466f 88411c 0fb64652 884101 0fb64656 }
+ $sequence_9 = { 0f84ef000000 6a20 e8???????? 83c404 89442410 85c0 }
condition:
- 7 of them and filesize <827392
+ 7 of them and filesize <180224
}
-rule MALPEDIA_Win_Thumbthief_Auto : FILE
+rule MALPEDIA_Win_Scieron_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "37aaa405-1531-5214-b674-b08465e47533"
+ id = "f9adad1f-0463-5c84-9844-b56939af8a07"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thumbthief"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.thumbthief_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scieron"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.scieron_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "f526be6ecad90c989de9ad949776796071b33db6ed80435843c6bf3aac7a3492"
+ logic_hash = "0253954720ef9ca79516bb585b52e8d461b9169ed80f649da26edf6b8044019f"
score = 75
quality = 75
tags = "FILE"
@@ -169659,32 +176831,32 @@ rule MALPEDIA_Win_Thumbthief_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 689c000000 b8???????? e8???????? 33db 8d4db4 895dec }
- $sequence_1 = { f6431002 0f85e1000000 85f6 0f44f3 89758c b800040000 66854310 }
- $sequence_2 = { ffb58cfeffff 8d8d30ffffff e8???????? 8d8de0feffff 807def00 7408 ffb5acfeffff }
- $sequence_3 = { f20f1085ecfeffff 8d8574ffffff 51 51 f20f110424 50 8d85f4feffff }
- $sequence_4 = { e8???????? c645fc02 8d8d58ffffff e8???????? c645fc03 8d8d18ffffff e8???????? }
- $sequence_5 = { bf48030000 8d85a4fcffff 57 6a00 50 e8???????? 83c40c }
- $sequence_6 = { eb77 68???????? eb70 68???????? eb69 8bc3 2d04130400 }
- $sequence_7 = { ff75f8 85c0 743c ff75f4 ba07000000 8bcf e8???????? }
- $sequence_8 = { e8???????? b8???????? e9???????? 8d4ddc e9???????? 8d4dbc e9???????? }
- $sequence_9 = { ff15???????? 8b4704 5f 85c0 740a 894508 5d }
+ $sequence_0 = { 8bc6 ff75f8 e8???????? 59 59 }
+ $sequence_1 = { 57 ff7508 8d859cf9ffff 68???????? }
+ $sequence_2 = { 68???????? ff15???????? 50 ffd3 ffd0 807d0c02 742a }
+ $sequence_3 = { 8bec 83e4f8 b81c800000 e8???????? 53 }
+ $sequence_4 = { 897574 ff15???????? 8d4574 50 56 56 }
+ $sequence_5 = { eb65 8b4734 50 894574 8d472c 50 }
+ $sequence_6 = { 8bf8 85ff 7418 8d45fc }
+ $sequence_7 = { 40 40 663938 75df }
+ $sequence_8 = { 033e 68???????? 68???????? ff15???????? }
+ $sequence_9 = { 83a61c02000000 33c0 40 5f 5d }
condition:
- 7 of them and filesize <4235264
+ 7 of them and filesize <100352
}
-rule MALPEDIA_Win_Bs2005_Auto : FILE
+rule MALPEDIA_Win_Cryptolocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ef8c48f9-bc67-59c3-a57f-caa042b605de"
+ id = "ef7778bc-4b3f-57b9-be94-b68bbd4e0a82"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bs2005"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bs2005_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptolocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptolocker_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "31d800fc437e882f8e75451d429896908d917d51b135f51d420139339a52e53c"
+ logic_hash = "308de5ca9cd2927cd67ef4efc7cb0917b58e872fb565dc9ff1066d1520a7dec9"
score = 75
quality = 75
tags = "FILE"
@@ -169698,32 +176870,32 @@ rule MALPEDIA_Win_Bs2005_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 85c0 0f845f030000 8b500c }
- $sequence_1 = { 7505 b83f000000 8d5abf 83c9ff 80fb19 771c 0fbeca }
- $sequence_2 = { 51 50 8b02 83c041 50 e8???????? 8b974c060000 }
- $sequence_3 = { 8b02 8a9049000400 8b8f54060000 889111010000 }
- $sequence_4 = { 51 c645c800 e8???????? 83c40c b9???????? 8d8324010000 8da42400000000 }
- $sequence_5 = { eb09 3c2f 7505 b93f000000 8d5abf 83c8ff 80fb19 }
- $sequence_6 = { 50 8d9500ffffff 52 68???????? e8???????? 6804010000 6a00 }
- $sequence_7 = { ffd6 33c0 68???????? 8d4dec 68???????? 51 8945ec }
- $sequence_8 = { 8945f8 3b45f0 7cea 8b4510 }
- $sequence_9 = { 8d419f 3c19 7708 0fbef1 83ee47 eb25 }
+ $sequence_0 = { 8d4a9f 6683f905 770f c1e004 }
+ $sequence_1 = { 0f858f000000 a1???????? 85c0 7509 }
+ $sequence_2 = { 898431ecfeffff 8b4ee8 85c9 740e 8b01 }
+ $sequence_3 = { ff7720 56 ff15???????? 8b4510 8b4b04 5f 5e }
+ $sequence_4 = { 7405 83f802 7549 85c9 }
+ $sequence_5 = { 8b75fc 33c9 85c0 0f48f1 7522 85f6 781e }
+ $sequence_6 = { c20800 55 8bec 83ec08 53 56 8b7508 }
+ $sequence_7 = { 8b4ee8 85c9 740e 8b01 6a01 8b4004 03c8 }
+ $sequence_8 = { 55 8bec 56 8b750c 8d8600ffffff 83f801 7723 }
+ $sequence_9 = { 0fb7044a 83f820 740f 83f809 7205 83f80d }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <778240
}
-rule MALPEDIA_Win_Heyoka_Auto : FILE
+rule MALPEDIA_Win_Fanny_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "86cada76-df01-530f-8812-d25a9cd3eeea"
+ id = "cd0c75da-8b4c-5363-98ec-15a67064033c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.heyoka"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.heyoka_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fanny"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fanny_auto.yar#L1-L171"
license_url = "N/A"
- logic_hash = "a93bcd2aa0b2cb88631752f25ba4416145dab56370097ba7d811f589f6be863b"
+ logic_hash = "415f51a7b92a8dd2e587e9f69b01a611a89ad0fc5dace80d2d81091a3ef0d182"
score = 75
quality = 75
tags = "FILE"
@@ -169737,34 +176909,40 @@ rule MALPEDIA_Win_Heyoka_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4d0c 8b510c 83c204 52 8b45fc 50 }
- $sequence_1 = { c745f800000000 c745f000000000 c745f400000000 c745ec00000000 8b4514 6bc005 c1e803 }
- $sequence_2 = { 8b45dc 50 e8???????? 83c410 8945d8 837dd800 750c }
- $sequence_3 = { 83ec08 894df8 8b45f8 c700???????? 8b4df8 c7810c09000000000000 8b55f8 }
- $sequence_4 = { e8???????? 83c408 8b5518 52 8b45dc 83c004 }
- $sequence_5 = { e8???????? 83c408 eb17 837d0803 7511 68???????? }
- $sequence_6 = { 8bec 83ec08 8b4508 50 6a01 e8???????? 83c408 }
- $sequence_7 = { 7423 8bce 8bc6 c1f905 83e01f 8b0c8da0d80110 }
- $sequence_8 = { 51 e8???????? 83c404 8b45e0 83c00c 8be5 }
- $sequence_9 = { 8955f8 8b45fc 8b4df4 8b55f8 0faf948134e30000 8b4df4 8bc2 }
+ $sequence_0 = { 8b45c0 85c0 7422 8935???????? 6a00 }
+ $sequence_1 = { 8955d0 0fb645cf 3de9000000 7423 0fb64dcf }
+ $sequence_2 = { 8b4dfc 8b11 52 ff15???????? 85c0 7502 }
+ $sequence_3 = { 53 ff15???????? 8bf0 83c420 85f6 0f846a010000 }
+ $sequence_4 = { 8b450c 8945d4 c745c400000000 8b4dc4 3b4dd0 7d26 6a00 }
+ $sequence_5 = { 53 ff15???????? 8bf0 85f6 7420 6a03 }
+ $sequence_6 = { eb05 1bc0 83d8ff 85c0 7517 8b842418010000 }
+ $sequence_7 = { eb57 8b450c 8a4dd0 88481f 8b55d0 52 8b4510 }
+ $sequence_8 = { 8b4dfc c7410c00000000 ff15???????? 8b55fc }
+ $sequence_9 = { 53 ff15???????? be00000200 56 }
+ $sequence_10 = { 5b c9 c3 80a5dcfeffff00 }
+ $sequence_11 = { 50 e8???????? 83c424 eb03 8b7508 }
+ $sequence_12 = { 53 ff15???????? 8d85e8fdffff 50 ff15???????? }
+ $sequence_13 = { 6800400000 6a00 ff15???????? 897c2410 56 }
+ $sequence_14 = { 53 ff15???????? 8bf0 59 85f6 0f84e9000000 8a4508 }
+ $sequence_15 = { 33c0 83e103 f3a4 8b13 8b4d00 85d2 760e }
condition:
- 7 of them and filesize <270336
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Etumbot_Auto : FILE
+rule MALPEDIA_Win_Meow_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "73e6da41-e3d5-504c-8c80-6f8ec05bab3e"
+ id = "3f4c85a0-7273-573d-9e5f-b6afea896e94"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.etumbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.etumbot_auto.yar#L1-L332"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.meow"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.meow_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "564ae417565d87b67b974a9ba2ad8948ae9936f9dac5ee557fc27d8a92da27f9"
+ logic_hash = "0e149c089578c6685626f307f9368d702f8c85f1bb4a2cbda9a3a1cb6a651295"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -169776,59 +176954,32 @@ rule MALPEDIA_Win_Etumbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8811 8a00 02c2 0fb6c0 8a8405fcfeffff 320437 8806 }
- $sequence_1 = { 8bec 53 56 57 8b3d???????? ffd7 }
- $sequence_2 = { 7407 8bf9 c1ef18 33c7 f7d1 23c1 }
- $sequence_3 = { c745ac5c5c4d69 c745b063726f73 c745b46f66745c c745b85c57696e }
- $sequence_4 = { c1e004 03c1 8bc8 81e1000000f0 7407 8bf9 }
- $sequence_5 = { 8d45f4 6820a10700 50 68???????? 68???????? }
- $sequence_6 = { c745c05c5c4375 c745c47272656e c745c874566572 c745cc73696f6e c745d05c5c496e }
- $sequence_7 = { 42 4e 75df 5f }
- $sequence_8 = { ffd7 8b7508 8bd8 69f660ea0000 }
- $sequence_9 = { c745b46f66745c c745b85c57696e c745bc646f7773 c745c05c5c4375 }
- $sequence_10 = { 57 0fbe38 33f6 33db }
- $sequence_11 = { c745d47465726e c745d865742053 c745dc65747469 c745e06e677300 }
- $sequence_12 = { f7d1 23c1 42 4e }
- $sequence_13 = { ffd7 2bc3 3bc6 72ed }
- $sequence_14 = { c645bf69 c645c062 c645c16c c645c265 }
- $sequence_15 = { 80e10f c0e102 c0eb06 02cb }
- $sequence_16 = { c645c16c c645c265 c645c33b c645c420 }
- $sequence_17 = { 56 8bf1 8b08 83f903 }
- $sequence_18 = { c645c54d c645c653 c645c749 c645c845 c645c920 }
- $sequence_19 = { 84c9 74b6 5f 5e 8bc2 }
- $sequence_20 = { 33c0 56 89442418 57 89442420 }
- $sequence_21 = { 0345f0 8b4d08 034dec 8a11 8810 8b45f0 83c001 }
- $sequence_22 = { 750d 83c01c 8bce 50 e8???????? }
- $sequence_23 = { 8d4a01 83c404 8bd1 c1e902 f3ab 8bca 83e103 }
- $sequence_24 = { 83c204 3b5514 7608 83c8ff }
- $sequence_25 = { 83c104 3b4d14 7608 83c8ff }
- $sequence_26 = { 53 57 e8???????? 8d86b0000000 50 }
- $sequence_27 = { 034df0 8b5508 0355ec 8a02 }
- $sequence_28 = { 52 e8???????? 83c404 e9???????? 6a05 }
- $sequence_29 = { c645d057 c645d169 c645d26e c645d364 }
- $sequence_30 = { 6a00 68???????? 6a00 6a00 6a00 51 68???????? }
- $sequence_31 = { 83fa01 7538 8b4514 8b19 0fb60438 c1e802 }
- $sequence_32 = { 46 eb0f 0fb6d2 f68201ce400004 7403 40 ff01 }
- $sequence_33 = { 8b4d08 83c101 894d08 8b550c 83ea03 }
- $sequence_34 = { 50 57 8bce e8???????? 8d45f0 8d7e70 }
- $sequence_35 = { c68543fffffff7 c68544ffffff52 c68545ffffff91 c68546ffffff1c c68547fffffff7 c68548ffffff64 c68549ffffffa3 }
- $sequence_36 = { c685ddfdffffa4 c685defdffffb3 c685dffdffff02 c685e0fdffff30 c685e1fdffffd6 c685e2fdfffffb }
+ $sequence_0 = { c685cefaffff53 c685cffaffff63 c685d0faffff53 c685d1faffff53 c685d2faffff53 8a85c9faffff e8???????? }
+ $sequence_1 = { 72dc ff75ec 8d4599 50 e8???????? 8b33 ba0f000000 }
+ $sequence_2 = { 0f8441070000 c745f4bb195c00 be03000000 8b45f4 99 f7fe 85d2 }
+ $sequence_3 = { 99 f7f9 8b45f4 85d2 7403 48 eb01 }
+ $sequence_4 = { 743b 8b45f0 83c117 83c00b 99 f7f9 8945f0 }
+ $sequence_5 = { c685dbfdffff5f c685dcfdffff7d c685ddfdffff7d c685defdffff7d 8a85d5fdffff e8???????? 898564f5ffff }
+ $sequence_6 = { 7907 48 83c8fc 83c001 7463 8b4c2410 8d4303 }
+ $sequence_7 = { 8a01 8d4901 0fb6c0 83e871 6bc037 99 f7fb }
+ $sequence_8 = { c6854dfeffff4c c6854efeffff3b c6854ffeffff6b c68550feffff3b c68551feffff26 c68552feffff3b c68553feffff18 }
+ $sequence_9 = { 99 f7f9 85d2 7445 8b442410 8d4f17 83c00b }
condition:
- 7 of them and filesize <450560
+ 7 of them and filesize <492544
}
-rule MALPEDIA_Win_Shimrat_Auto : FILE
+rule MALPEDIA_Win_Dtrack_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9f2cf600-46fb-5fe2-9403-91a4ffe5dc91"
+ id = "a233c383-e1c0-5a80-b962-04f71174b55f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shimrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shimrat_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dtrack"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dtrack_auto.yar#L1-L160"
license_url = "N/A"
- logic_hash = "4e378ef30b6703953f18ff74f4c2d2ea366c27ea22af1636e2d889f102c09783"
+ logic_hash = "da8244413760aff3fc60e26778e79f2591abffda2d0aa55a6f2fe1a5cc4b0aa3"
score = 75
quality = 75
tags = "FILE"
@@ -169842,32 +176993,37 @@ rule MALPEDIA_Win_Shimrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 59 59 6a01 8d452c }
- $sequence_1 = { eb1a 83f802 7513 83ec0c 8d4660 8bcc 50 }
- $sequence_2 = { ff7508 8d85fcfeffff 50 e8???????? 59 59 85c0 }
- $sequence_3 = { ff15???????? 8d4df4 e8???????? 8d4d08 e8???????? 5e }
- $sequence_4 = { e8???????? 59 59 895e1c ff15???????? 8bce 899ec0000000 }
- $sequence_5 = { ff15???????? 8bce 899ec0000000 e8???????? 85c0 750e }
- $sequence_6 = { 837d0800 7424 837d0c00 741e ff7510 ff750c }
- $sequence_7 = { 50 8bce e8???????? 85c0 74d9 ff75e8 8d4df0 }
- $sequence_8 = { 6a00 68???????? 53 ffd7 ff7570 ff15???????? e9???????? }
- $sequence_9 = { 83c414 50 8d4f6c e8???????? }
+ $sequence_0 = { 52 8b4508 50 e8???????? 83c414 8b4d10 51 }
+ $sequence_1 = { ff15???????? 8d85dcfdffff 50 6a01 }
+ $sequence_2 = { 8955f0 8b45f0 0fb68899010000 51 8b55f0 }
+ $sequence_3 = { 8d85ecfeffff 50 8d8dc8fdffff 51 8d95ccfdffff }
+ $sequence_4 = { 0345f4 8810 ebac e9???????? 8be5 }
+ $sequence_5 = { 52 8d8590f5ffff 50 ff15???????? c685a0f8ffff00 6803010000 6a00 }
+ $sequence_6 = { c685b8fbffff00 6803010000 6a00 8d8db9fbffff 51 e8???????? }
+ $sequence_7 = { 51 e8???????? 83c410 8b558c 52 }
+ $sequence_8 = { 8b8520f5ffff 8a4801 888d1ff5ffff 838520f5ffff01 }
+ $sequence_9 = { d1e9 894df8 8b5518 8955fc c745f000000000 eb09 }
+ $sequence_10 = { 8b45fc c1e808 8b4dfc c1e910 }
+ $sequence_11 = { c1e810 23c8 33d1 8855f7 8b4df8 c1e908 8b55fc }
+ $sequence_12 = { 894d14 8b45f8 c1e018 8b4dfc }
+ $sequence_13 = { 6867452301 8b4d10 51 8b55f4 52 }
+ $sequence_14 = { eb64 8b4d10 51 6a00 8b55f4 52 e8???????? }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <1736704
}
-rule MALPEDIA_Win_Terminator_Rat_Auto : FILE
+rule MALPEDIA_Win_Iconic_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9d4805e3-697a-5809-9888-0af99434fee9"
+ id = "152db8f5-915a-5ca5-a7d4-f3818a40ffaf"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.terminator_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.terminator_rat_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.iconic_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.iconic_stealer_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "460088279758b4b56f7253332ea9c90ec016fa5d0376dce042f468a189f77f7d"
+ logic_hash = "dec19b483e0961df8b3ae7026df8b4a85577bd9230fffbf8dd9f39001dd5f48b"
score = 75
quality = 75
tags = "FILE"
@@ -169881,32 +177037,32 @@ rule MALPEDIA_Win_Terminator_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffb519010000 8947fc 8b47f4 8b4008 894708 e8???????? 8b47fc }
- $sequence_1 = { c70020000000 8b852d010000 2b08 894804 }
- $sequence_2 = { 33db 395e0c 752f 6a40 6800100000 6800180000 }
- $sequence_3 = { 26a130000000 07 8b400c 8b701c }
- $sequence_4 = { 50 ffb525010000 ff95e1000000 85c0 }
- $sequence_5 = { eb31 ff9509010000 3d4c270000 750e }
- $sequence_6 = { 57 8bfc 81ec04040000 53 56 33db }
- $sequence_7 = { 8b4b0c ac 3459 c0c803 3448 c0c803 }
- $sequence_8 = { ffb519010000 8947fc 8b47f4 8b4008 }
- $sequence_9 = { 60 33c0 8b4f0c 8b7f08 }
+ $sequence_0 = { e9???????? 4c8b13 4c8d05e6c60300 488bc6 488bce 83e03f 48c1f906 }
+ $sequence_1 = { eb29 488d0c76 8d4601 898790000000 488b8788000000 c704c876000000 8954c804 }
+ $sequence_2 = { 894338 66897318 66894b3e 6644896316 6644894b3c 663bf1 0f85dc000000 }
+ $sequence_3 = { e8???????? 4881c430020000 415f 415d 415c 5f 5e }
+ $sequence_4 = { 5f 5e 5d c3 40f6c504 7419 4c8bc7 }
+ $sequence_5 = { eb05 b901000000 894f28 4885db 741f 8b4f28 48895f10 }
+ $sequence_6 = { f2490f2ad5 488d4dc7 f20f5e15???????? 66490f7ed0 e8???????? e9???????? 448b44242c }
+ $sequence_7 = { ffc7 4883c108 3bfa 7cf1 e9???????? 488b4b20 4885c9 }
+ $sequence_8 = { e9???????? 488b75a8 4c8b442470 8b06 83c003 413b00 7e1f }
+ $sequence_9 = { c7430400000000 41ba1f000000 49bb1142082184104208 418b49f8 85c9 745b 8d4701 }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <2401280
}
-rule MALPEDIA_Win_Amtsol_Auto : FILE
+rule MALPEDIA_Win_Winordll64_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c4e6651d-976c-58ca-adc5-c02364c8423a"
+ id = "32ecf8d5-2cad-5cae-b550-c4e57fba7837"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.amtsol"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.amtsol_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winordll64"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.winordll64_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "27d50e01d30776676c026a6886e9d6b54d3f1024ee993525160ca52cbcf77c05"
+ logic_hash = "633c933d5010a60000a71f7674b6b6d81d1af8a3edb249e8b101bbf4eb8e443f"
score = 75
quality = 75
tags = "FILE"
@@ -169920,32 +177076,32 @@ rule MALPEDIA_Win_Amtsol_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c8 234df0 8945fc 8b45f8 33cb 034e34 6a05 }
- $sequence_1 = { 53 ff7580 ff7594 ff36 }
- $sequence_2 = { 885d6f ff75d4 8d4510 50 8d4568 50 }
- $sequence_3 = { 53 8b5d0c 8bce 2bde 3b7d10 7d23 }
- $sequence_4 = { c645d543 c645d668 c645d765 c645d863 c645d96b c645da3a 885ddb }
- $sequence_5 = { 8bec 8b4508 33c9 3bc1 7504 33c0 5d }
- $sequence_6 = { ff15???????? 83f8ff 752b 8d45e8 50 c645e823 c645e92d }
- $sequence_7 = { 85c0 7524 a1???????? a3???????? a1???????? c705????????b2194100 8935???????? }
- $sequence_8 = { 0f84bf000000 56 53 50 e8???????? 56 }
- $sequence_9 = { e8???????? 8d443001 59 895df4 3818 0f8430010000 50 }
+ $sequence_0 = { e8???????? 488d4dbc ff15???????? 488d15ae1c0100 488bc8 e8???????? 85c0 }
+ $sequence_1 = { 4833c4 488985581d0000 488bd9 b838070000 48ffc8 c6040100 75f7 }
+ $sequence_2 = { 48897c2420 ff15???????? 85c0 7426 448b842490000000 4c8d4c2430 }
+ $sequence_3 = { e9???????? ba12000000 ebf0 48897c2440 897c2448 488d442448 4889442420 }
+ $sequence_4 = { e8???????? 4c8d0513c50000 41b903000000 488d4c45bc 488bc1 492bc5 }
+ $sequence_5 = { 488bcf c744243001000000 448be8 ff15???????? }
+ $sequence_6 = { 663918 75f5 4c8d4da0 48837db808 4c0f434da0 486307 }
+ $sequence_7 = { 7423 83fefe 741e 488bce 488bc6 488d1554370100 83e11f }
+ $sequence_8 = { 7767 488d4d98 482bcb 48b8abaaaaaaaaaaaa2a 48f7e9 488bf2 }
+ $sequence_9 = { 0f84bd010000 488b4c2450 4533c0 418bd5 ff15???????? 85c0 0f847b010000 }
condition:
- 7 of them and filesize <335872
+ 7 of them and filesize <278528
}
-rule MALPEDIA_Win_Dubrute_Auto : FILE
+rule MALPEDIA_Win_Snifula_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "91c95b88-1aba-547d-a2e7-1c5fddf4a9b5"
+ id = "3dffa8bc-fef5-5d9b-860e-b2ad6113d3e0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dubrute"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dubrute_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.snifula"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.snifula_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "96123f7850603b9e3ec4473b7e8755ea7a00903c8750eba6148228fb5b3de4ca"
+ logic_hash = "5394c0842b5f05f382e3a7b0318fd2397f5c79fe7938989019ff20c4e8348941"
score = 75
quality = 75
tags = "FILE"
@@ -169959,32 +177115,32 @@ rule MALPEDIA_Win_Dubrute_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d45dc dd5de4 50 c645fc0d ff15???????? 8d4df0 c645fc08 }
- $sequence_1 = { 83c410 83f8ff 743b 85c0 741c 03f0 56 }
- $sequence_2 = { 83e906 7426 49 741a 49 740e 49 }
- $sequence_3 = { 7427 48 7413 48 48 7551 57 }
- $sequence_4 = { 5e 5d c3 8b4c2408 81f9ff000000 7e1b 8b442404 }
- $sequence_5 = { e8???????? 83c410 ff866c090000 5e c3 55 8bec }
- $sequence_6 = { 7520 8b06 8b4018 8b00 ff30 e8???????? 6a06 }
- $sequence_7 = { 57 53 ff15???????? 8b3d???????? 8325????????00 8b37 3bf7 }
- $sequence_8 = { 56 53 68???????? e8???????? 83c40c 837d1400 }
- $sequence_9 = { 8a48ff 884e01 83c603 837df000 7fd4 e9???????? f745f0f8ffffff }
+ $sequence_0 = { 53 ff35???????? ffd7 6800040000 53 ff35???????? }
+ $sequence_1 = { 53 6a00 ff35???????? ff15???????? b8???????? 83c9ff }
+ $sequence_2 = { 6a00 ff35???????? 8945fc ff15???????? 8bf8 85ff }
+ $sequence_3 = { a1???????? 85c0 75ef 53 57 bb???????? }
+ $sequence_4 = { ff15???????? 8bf8 83ffff 747f 53 8d450c 50 }
+ $sequence_5 = { e8???????? 85c0 740c 81386368756e 7504 834e1002 8bc6 }
+ $sequence_6 = { c1e802 25ff000000 8d44c72c 8b18 3bd8 7432 }
+ $sequence_7 = { 83f803 7533 ff7304 8bc7 ff750c e8???????? 8b4724 }
+ $sequence_8 = { 68???????? 56 ff15???????? 83c414 68???????? 56 }
+ $sequence_9 = { 53 50 889c243c010000 e8???????? a1???????? 83c43c 895c2430 }
condition:
- 7 of them and filesize <598016
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Snojan_Auto : FILE
+rule MALPEDIA_Win_Urausy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "96ddba9d-1a09-5178-a027-761c3b0ea160"
+ id = "42f215cc-3fcb-5d25-8a29-1c5fcfaf0e92"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.snojan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.snojan_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.urausy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.urausy_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "a7da77f2b75075e9b17ce3132c822da8d2432067b99e241b1e6927c5f09a8d94"
+ logic_hash = "4f1d0bce8598e73699b4a743f6a21ef45b27ed44d43ef0837b1c95c90d3c9c6b"
score = 75
quality = 75
tags = "FILE"
@@ -169998,32 +177154,32 @@ rule MALPEDIA_Win_Snojan_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 83ec0c 83f8ff 0f8487010000 89c7 b802000000 c70424???????? }
- $sequence_1 = { b802000000 c70424???????? 6689442420 ff15???????? 83ec04 c70424???????? 89442424 }
- $sequence_2 = { 8d5c2430 c644241f00 c744240c00000000 c744240800900100 895c2404 893c24 ff15???????? }
- $sequence_3 = { a1???????? 8b988000986d 85db 74da }
- $sequence_4 = { 8d860000986d 8955cc e8???????? 8b45cc }
- $sequence_5 = { 893c24 ff15???????? 83ec10 83f800 }
- $sequence_6 = { e9???????? 0fb7810000986d 894dc0 89c7 81cf0000ffff 6683b90000986d00 0f48c7 }
- $sequence_7 = { 85c0 74e9 a1???????? 8b988000986d 85db 74da 895c2404 }
- $sequence_8 = { 837c243401 753d c744241400000000 c744241000000000 }
- $sequence_9 = { 85c0 b801000000 0f44d0 8854241f 8974240c 896c2408 }
+ $sequence_0 = { 6a00 68???????? 68???????? ff7508 e8???????? 6a00 ff35???????? }
+ $sequence_1 = { 8bd3 81c2a5000000 50 53 52 51 }
+ $sequence_2 = { ff75e4 e8???????? 8945e8 ff35???????? }
+ $sequence_3 = { 6a01 ff35???????? e8???????? 6a00 68???????? 68???????? }
+ $sequence_4 = { c21000 55 8bec 81c4ecefffff }
+ $sequence_5 = { 0f8585000000 6814000000 68???????? 6a04 8d8500fcffff 50 e8???????? }
+ $sequence_6 = { 8d85dcf7ffff 50 57 56 }
+ $sequence_7 = { 833d????????00 0f8fae050000 c705????????01000000 ff35???????? 8f45f0 ff35???????? 8f45f4 }
+ $sequence_8 = { e8???????? ff75fc e8???????? 8b45f8 c9 c20400 ff25???????? }
+ $sequence_9 = { e8???????? b800000000 c9 c21400 }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <98304
}
-rule MALPEDIA_Win_Ismdoor_Auto : FILE
+rule MALPEDIA_Win_Rtpos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e9177277-98bb-546b-913b-803dfeefda39"
+ id = "77dcd653-95cb-55c4-91a1-f9b9e9596fd3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ismdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ismdoor_auto.yar#L1-L156"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rtpos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rtpos_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "489ff4b41f2f5bc83c56e62265d852f18476e83488ad914ef361d6d410139690"
+ logic_hash = "4ad89a49b88ba1ea262b015470065dd4f3f20d950975a1f27ea85a4b99624bd0"
score = 75
quality = 75
tags = "FILE"
@@ -170037,37 +177193,32 @@ rule MALPEDIA_Win_Ismdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83f8ff 7504 32c0 eb05 c0e804 2401 84c0 }
- $sequence_1 = { 90 48897c2428 488d4da0 48894c2420 4c8d4d80 4c8bc3 }
- $sequence_2 = { 7405 488b00 ebdd 48894500 }
- $sequence_3 = { 89442420 48c7411807000000 48894110 668901 c744242001000000 }
- $sequence_4 = { 7613 498d4970 418bc2 41ffc2 }
- $sequence_5 = { 41ffc7 0f1f4000 418b16 488d4d38 e8???????? }
- $sequence_6 = { 8bd8 33c9 ff15???????? 488bc8 }
- $sequence_7 = { 488bd6 488bcf ff5030 488bc8 }
- $sequence_8 = { 884c0dd8 41 83f910 7cf6 }
- $sequence_9 = { 83f802 7506 c6473c00 eb04 40 }
- $sequence_10 = { 8b4804 83b9ec97480000 0f94c0 8845e4 c745fc01000000 }
- $sequence_11 = { c745f804000000 57 8a68fe 8d4004 8a48fb 8a78fc }
- $sequence_12 = { 886dff 81e61f000080 7905 4e 83cee0 46 }
- $sequence_13 = { e8???????? 83c404 c744246c0f000000 c744246800000000 c644245800 837c243c08 }
- $sequence_14 = { 75f2 8b7d10 8b07 3bf0 7421 8b4f04 }
+ $sequence_0 = { 68a8040000 8b45ec 50 e8???????? 83c408 c3 8b542408 }
+ $sequence_1 = { 83e908 8d7608 660fd60f 8d7f08 8b048d74b44000 }
+ $sequence_2 = { 8b0cc5c4ae4200 894de4 85c9 7455 }
+ $sequence_3 = { 7619 8b4dd4 51 ff15???????? }
+ $sequence_4 = { 8d45d8 50 6a00 8b4dd4 51 }
+ $sequence_5 = { 85c0 752c 6a00 68???????? 68???????? 6a02 68???????? }
+ $sequence_6 = { 8bec 53 8b5d08 33c9 57 33c0 8d3c9d5c654300 }
+ $sequence_7 = { 33c5 8945fc c745d800000000 c745dc00000000 33c0 }
+ $sequence_8 = { 2b45c4 3b45f0 7619 8b4dd4 51 ff15???????? }
+ $sequence_9 = { 6bc030 03048db86a4300 50 ff15???????? 5d c3 }
condition:
- 7 of them and filesize <1933312
+ 7 of them and filesize <507904
}
-rule MALPEDIA_Win_Upas_Auto : FILE
+rule MALPEDIA_Win_Unidentified_098_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4474338e-2402-5a41-aa33-f4db4dabe7ff"
+ id = "8f47cad5-b04b-526a-bf75-a80f46978296"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.upas"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.upas_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_098"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_098_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "13e71741a108b9f3493f31fa88f76272d0cb37e67292b4fc5655cf9c429831b0"
+ logic_hash = "5873ddf57107eab8629c385b87e703377b84a728d15aa8f227623b130059db6e"
score = 75
quality = 75
tags = "FILE"
@@ -170081,32 +177232,32 @@ rule MALPEDIA_Win_Upas_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 8d45f8 50 8d45f0 50 ff15???????? }
- $sequence_1 = { ffd6 33c0 eb18 6a00 57 }
- $sequence_2 = { ff751c e8???????? ff7620 ff763c e8???????? 8b4d10 8bd8 }
- $sequence_3 = { ff15???????? 8945fc 3bc7 7504 33c0 eb64 56 }
- $sequence_4 = { 50 53 ff15???????? 8945f4 3bc3 7504 }
- $sequence_5 = { 83c420 53 6880000000 6a02 53 53 68000000c0 }
- $sequence_6 = { 8944b5dc 837cb5dc00 59 59 7406 46 83fe07 }
- $sequence_7 = { ff15???????? ff75e8 8d4598 6a22 50 e8???????? }
- $sequence_8 = { 72d1 5e c3 8b442410 8b08 3b0d???????? }
- $sequence_9 = { ff15???????? 85c0 742d 8d8500fdffff 50 }
+ $sequence_0 = { c644247f00 e9???????? 41bdffffffff 4885db 7412 488b4310 483b4318 }
+ $sequence_1 = { e9???????? 8d48bf 83f905 0f8716ffffff 83e837 c1e00c 89c6 }
+ $sequence_2 = { 7eac 85c0 78a8 488b4318 31d2 4885c0 75ab }
+ $sequence_3 = { f6c202 410f45c0 4883c102 01d2 668941fe 4939c9 75ce }
+ $sequence_4 = { b801000000 4d85c0 7486 488b542450 4c89e1 e8???????? 85c0 }
+ $sequence_5 = { ff15???????? 410fb61424 e9???????? 4c89f8 4829d8 4801c7 4d85ed }
+ $sequence_6 = { 85d2 0f88d5000000 4c8d5904 4189d2 4c8d4910 83fa0f 7e33 }
+ $sequence_7 = { 488d542440 4939d4 7411 4c89e1 8844242f e8???????? 0fb644242f }
+ $sequence_8 = { 897c2450 41bd01000000 44894c2434 4889442458 e9???????? 488b03 4489442434 }
+ $sequence_9 = { e9???????? 498b4610 493b4618 0f838d010000 0fb700 6683f8ff b900000000 }
condition:
- 7 of them and filesize <114688
+ 7 of them and filesize <3345408
}
-rule MALPEDIA_Win_Suncrypt_Auto : FILE
+rule MALPEDIA_Win_Ncctrojan_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "93d1d1b0-e368-5e85-941c-a502b4af6a15"
+ id = "964a63a1-2a33-5eff-ac10-defb358349c1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.suncrypt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.suncrypt_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ncctrojan"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ncctrojan_auto.yar#L1-L159"
license_url = "N/A"
- logic_hash = "3fd8ca759efc6a63a6777db0d881129a01860e6b4243db4bd8968c844a421043"
+ logic_hash = "ca1178d41ac898e0a6dcd72371fc848e91a6cf3f5857a4b6b78db9de7f47f454"
score = 75
quality = 75
tags = "FILE"
@@ -170120,32 +177271,38 @@ rule MALPEDIA_Win_Suncrypt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 6a00 6a00 6a03 6a00 6a00 ff75b8 }
- $sequence_1 = { 8b8d60ffffff 8945c8 8b856cffffff 8945ac 8b8564ffffff 8945cc 8b855cffffff }
- $sequence_2 = { c645f84c c645f90e c645fa44 c645fb4c c645fc4c 8a45f4 c645fd00 }
- $sequence_3 = { 02ca 0fbec0 33c8 884c15ec 42 83fa11 72e8 }
- $sequence_4 = { 894dd0 034d98 8bf9 337dcc c1c70c 03c7 898534ffffff }
- $sequence_5 = { c3 8b07 0fb74f0e 8b4004 8b0488 894724 }
- $sequence_6 = { 8b7308 83c140 8b7da0 894df4 8b4df0 eb7e }
- $sequence_7 = { 8b45a8 0411 c645be00 83f00a 33d2 8845bd 8a45ac }
- $sequence_8 = { 660f6dec 660fefd8 660f6ccc 0f28a500feffff 0f1118 83c010 0f1007 }
- $sequence_9 = { 7324 8d0c10 2bf2 894df0 8b4df8 2bca }
+ $sequence_0 = { 7536 8b85e8feffff 85c0 750a 68???????? }
+ $sequence_1 = { 68???????? e9???????? 83f801 750a }
+ $sequence_2 = { 83f801 750a 68???????? e9???????? 83f802 }
+ $sequence_3 = { 68e9fd0000 ffd6 8d8decfdffff 5f 8d5102 5e 668b01 }
+ $sequence_4 = { 8b442420 83c40c 83c008 836c240c01 89442414 0f85fffdffff }
+ $sequence_5 = { 8d4a10 0f1f840000000000 0f1041f0 83c020 }
+ $sequence_6 = { ffd6 50 8d85dcfdffff 50 }
+ $sequence_7 = { e8???????? 83c40c 85c0 752f 6a06 8d85c4bfffff }
+ $sequence_8 = { 51 f2c3 8b4df0 33cd f2e8bef6ffff }
+ $sequence_9 = { 83c414 e8???????? 84c0 7517 }
+ $sequence_10 = { 33c5 8945fc 56 6890010000 }
+ $sequence_11 = { 83faff 0f94c0 84c0 7405 }
+ $sequence_12 = { 83c418 83c008 03c6 8bcf }
+ $sequence_13 = { 0fb601 50 8d45d0 68???????? 50 }
+ $sequence_14 = { 83ec14 c645fc1f 8d95e8feffff 8bcc }
+ $sequence_15 = { 668bc1 8be5 5d c3 56 8bf1 }
condition:
- 7 of them and filesize <172032
+ 7 of them and filesize <1160192
}
-rule MALPEDIA_Win_Mole_Auto : FILE
+rule MALPEDIA_Win_Jessiecontea_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "36f8515b-9850-5f6a-9da2-fab216acb0f1"
+ id = "526b090a-a995-58b5-b843-1e70dd71cefc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mole"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mole_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jessiecontea"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jessiecontea_auto.yar#L1-L165"
license_url = "N/A"
- logic_hash = "9e8bd455bb765e10346652a5931be596133d0a24ad14fb98b5a58db6c1dd57c3"
+ logic_hash = "c68c31b644ea8b3e7ca9f4e4366853343f61b6640765616026487f548092899b"
score = 75
quality = 75
tags = "FILE"
@@ -170159,34 +177316,40 @@ rule MALPEDIA_Win_Mole_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 81bdf0fdffff99000000 0f8787710000 8b95f0fdffff 0fb68248c04000 ff248514c04000 81bdf0fdffffd3a7d105 0f8794000000 }
- $sequence_1 = { 6bc000 0385bcf9ffff 898588e5ffff 837d1401 751a 68???????? 68???????? }
- $sequence_2 = { 81bdf0fdffffcde5d405 0f8458400000 81bdf0fdffff41e6d405 0f849e440000 81bdf0fdffff44e6d405 0f84742c0000 e9???????? }
- $sequence_3 = { e9???????? 81bdf0fdffff5625d105 0f8786000000 81bdf0fdffff5625d105 0f8494710000 81bdf0fdffffc624d105 7745 }
- $sequence_4 = { 8d959cefffff 52 68???????? 6801000080 ff15???????? 898584efffff 8d85d4fbffff }
- $sequence_5 = { 8d85ace4ffff 50 6a05 68???????? 8b8dc4e4ffff 51 ff15???????? }
- $sequence_6 = { c7802ceb410002000000 6a04 58 6bc000 8b0d???????? 894c05f8 6a04 }
- $sequence_7 = { 8d9530e2ffff 52 e8???????? 83c404 6a64 68???????? 8d85ecfbffff }
- $sequence_8 = { 83c410 8d959cf9ffff 52 8b8590e5ffff }
- $sequence_9 = { e8???????? e8???????? 898580f7ffff 81bd80f7ffff00300000 7575 6a00 }
+ $sequence_0 = { c78590f4ffff00000000 c7858cf4ffff00000000 c78588f4ffff00000000 c78594f4ffff01000000 c78598f4ffff01000000 e8???????? }
+ $sequence_1 = { 3d00010000 0f8f03010000 6a00 6a00 50 }
+ $sequence_2 = { 8d85e8fdffff 50 8d85a2f6ffff 50 }
+ $sequence_3 = { 57 8b7d18 8945c0 8b4510 }
+ $sequence_4 = { eb02 2bf7 6a00 8d85e8b7ffff 50 }
+ $sequence_5 = { 5d c3 c705????????31090000 5f 5e 5b 8be5 }
+ $sequence_6 = { 56 57 680a020000 8d85d8fbffff 8bf2 6a00 }
+ $sequence_7 = { 6880000000 6a01 6a00 6a01 6800000040 8d85f8fbffff 50 }
+ $sequence_8 = { 41b800080000 be20000008 e8???????? 33d2 448975c0 }
+ $sequence_9 = { 4d8bc8 4d2bcd 6690 488d82fafeff7f }
+ $sequence_10 = { 83e03f 2bc8 33c0 48d3c8 488d0d39d20100 4833c2 }
+ $sequence_11 = { 7305 44887c3710 488bcb e8???????? 397d50 7230 }
+ $sequence_12 = { ff15???????? 85c0 0f8580fcffff 488b4c2460 }
+ $sequence_13 = { 892d???????? 8b1d???????? 488d4c2430 8bfd 48896c2430 }
+ $sequence_14 = { 4889442440 33d2 4489742448 41b8ff3f0000 488d8d51070000 }
+ $sequence_15 = { 488b4d98 488d4588 4889442428 41b902000000 }
condition:
- 7 of them and filesize <297984
+ 7 of them and filesize <413696
}
-rule MALPEDIA_Win_Trickbot_Auto : FILE
+rule MALPEDIA_Win_Avcrypt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7ca88b89-dbe0-5ca7-acaa-87de79bf1962"
+ id = "f0c2c6c6-0e09-5b4b-89b9-13d38222f492"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.trickbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.trickbot_auto.yar#L1-L637"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avcrypt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avcrypt_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "e3adabeebcd43d3e3c9deb0d5c4eb46cb018beaf463780980939f5dd81bffcd5"
+ logic_hash = "ac05395b3ceaf430ebcb56d0def5da87a92c07f9636a33b891b2fc3647618543"
score = 75
- quality = 48
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -170198,99 +177361,32 @@ rule MALPEDIA_Win_Trickbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c002 eb0d 2500000080 f7d8 1bc0 83e007 40 }
- $sequence_1 = { 1bc0 83e020 83c020 eb36 }
- $sequence_2 = { eb36 2500000080 f7d8 1bc0 83e070 83c010 }
- $sequence_3 = { f7d8 1bc0 83e002 83c002 eb0d }
- $sequence_4 = { 83e070 83c010 eb25 a900000040 7411 2500000080 }
- $sequence_5 = { 7429 a900000040 7411 2500000080 f7d8 1bc0 83e020 }
- $sequence_6 = { 8b07 a900000020 7429 a900000040 }
- $sequence_7 = { c705????????fdffffff c705????????feffffff c705????????ffffffff e8???????? }
- $sequence_8 = { 895df4 895dec 66c745f00005 895dfc }
- $sequence_9 = { 33ff 57 6880000000 6a02 57 6a01 68000000c0 }
- $sequence_10 = { 41 83c028 3bce 7ce9 }
- $sequence_11 = { 488b01 4c8b4120 488b5118 488b4910 }
- $sequence_12 = { 53 6a03 53 6a01 6800010000 }
- $sequence_13 = { 4889442428 488b4130 488b4910 4889442420 41ffd2 }
- $sequence_14 = { 488b01 488b5118 488b4910 ffd0 }
- $sequence_15 = { 4c8b4928 4c8b4120 488b5118 4889442438 488b4140 }
- $sequence_16 = { 488b4148 4c8b11 4c8b4928 4c8b4120 }
- $sequence_17 = { 4889442430 488b4138 4889442428 488b4130 }
- $sequence_18 = { 488b5118 4889442440 488b4148 4889442438 488b4140 }
- $sequence_19 = { 4889442438 488b4140 4889442430 488b4138 }
- $sequence_20 = { 6820bf0200 68905f0100 68905f0100 50 ff15???????? }
- $sequence_21 = { 2bc2 d1e8 03c2 c1e806 6bc05f }
- $sequence_22 = { 83780400 7404 8b4008 c3 }
- $sequence_23 = { 51 68e9fd0000 50 e8???????? }
- $sequence_24 = { 6a40 6800300000 6a70 6a00 }
- $sequence_25 = { 833800 751c 83781000 7516 }
- $sequence_26 = { c3 6a01 ff15???????? 50 }
- $sequence_27 = { 8b01 59 03d0 52 }
- $sequence_28 = { 85c0 7f0b e8???????? 8b05???????? }
- $sequence_29 = { 03d0 52 ebdc 89450c }
- $sequence_30 = { 8bc1 66ad 85c0 741c }
- $sequence_31 = { e8???????? 83f801 7411 ba0a000000 }
- $sequence_32 = { 85c0 741c 3bc1 7213 }
- $sequence_33 = { 7405 e8???????? ff15???????? 8bc3 }
- $sequence_34 = { c1e102 2bc1 8b00 894508 }
- $sequence_35 = { 50 8b450c ff4d0c ba28000000 }
- $sequence_36 = { 895510 8b4a04 ff5508 8b5510 8b4a0c }
- $sequence_37 = { 2bc1 8b00 3bc7 72f2 }
- $sequence_38 = { 8b4a04 ff5508 50 51 }
- $sequence_39 = { ff4d0c ba28000000 f7e2 8d9500040000 03d0 895510 }
- $sequence_40 = { 740f 8bc8 e8???????? 8bc3 }
- $sequence_41 = { 58 41 41 41 41 }
- $sequence_42 = { 8bcf e8???????? 8bf0 85ed }
- $sequence_43 = { 85c0 7911 8bc8 e8???????? bb11000000 }
- $sequence_44 = { e8???????? 85c0 7507 e8???????? eb5b }
- $sequence_45 = { 89742428 c744242000001f00 ff15???????? 85c0 7911 }
- $sequence_46 = { 7c22 3c39 7f1e 0fbec0 }
- $sequence_47 = { 3bd1 0f8293000000 038e8c000000 3bd1 0f8385000000 }
- $sequence_48 = { ffc1 663938 75f5 6603c9 }
- $sequence_49 = { ff15???????? 8bf0 c1ee1f 83f601 }
- $sequence_50 = { 85d2 745b 3bd1 0f8293000000 }
- $sequence_51 = { 41 50 2bc1 8b00 }
- $sequence_52 = { 8bc8 33c0 85c9 0f95c0 eb02 }
- $sequence_53 = { 894504 68f0ff0000 59 8bf7 8bd7 }
- $sequence_54 = { 8bc7 e8???????? 85c0 0f849f000000 }
- $sequence_55 = { 8bf7 8bd7 fc 8bc1 }
- $sequence_56 = { 59 50 e2fd 8bc7 }
- $sequence_57 = { 8dbf00500310 8bd6 897d08 3bc8 }
- $sequence_58 = { 6a00 ff15???????? 6a00 6a00 6a00 8d45dc }
- $sequence_59 = { 8b7d10 2bf9 53 50 }
- $sequence_60 = { 83c001 8945d4 8b4dfc 51 8b55d4 }
- $sequence_61 = { 8b4dd0 894dd8 837dd840 760b 8b55d8 }
- $sequence_62 = { 8d3c0e 2b75f8 33c7 2bd0 ff4dfc 75ba 8b4508 }
- $sequence_63 = { 42 42 3b5508 7202 8bd6 83c104 }
- $sequence_64 = { bf31e7bf31 e7bf 31e7 bf31e7bf31 e7bf }
- $sequence_65 = { 8b01 3302 52 8bd0 51 03cf 51 }
- $sequence_66 = { 56 57 33f6 bf???????? 833cf594f3000101 }
- $sequence_67 = { 8945cc ebee 8b45d8 48 50 8b45cc 40 }
- $sequence_68 = { ff75f8 ff15???????? 8945fc 837dfc00 750d }
- $sequence_69 = { 6a00 6858020000 ff15???????? 837dfc00 74ce }
- $sequence_70 = { e8???????? 03c6 50 e8???????? 8b7710 83c40c 2bf3 }
- $sequence_71 = { 55 8bec 83ec34 c745cc00000000 6a00 685b020000 6a00 }
- $sequence_72 = { 42 42 8b01 83c202 33c3 890439 }
- $sequence_73 = { 8945e4 3bc6 7305 8b750c }
- $sequence_74 = { 9c 000f 9c 000f 9c f7a053f7a053 }
- $sequence_75 = { 8bec e8???????? 8b4d08 e8???????? 5d c20400 }
- $sequence_76 = { c705????????ad380001 8935???????? a3???????? ff15???????? a3???????? 83f8ff 0f84c1000000 }
+ $sequence_0 = { 68???????? ffd3 834dfcff 8d4dd8 56 6a01 e8???????? }
+ $sequence_1 = { 8bc7 8bcf c1f805 83e11f c1e106 030c8580b54300 eb05 }
+ $sequence_2 = { 8d4dc0 56 e8???????? 59 6a0e 33f6 5b }
+ $sequence_3 = { c705????????70484300 c705????????8cbf4300 890d???????? 8935???????? }
+ $sequence_4 = { 50 ff15???????? 83c8ff e9???????? 57 6a09 59 }
+ $sequence_5 = { ff15???????? 85c0 7507 68???????? ffd6 895de4 837dd000 }
+ $sequence_6 = { 68???????? e8???????? 83ec18 c745fc15000000 8bcc 8965d4 53 }
+ $sequence_7 = { c645fc0e 837db800 7519 68???????? 8d8d78ffffff e8???????? }
+ $sequence_8 = { e8???????? 68???????? 8d8d84feffff c645fc08 e8???????? 68???????? 8d8d9cfeffff }
+ $sequence_9 = { e8???????? c645fc01 8b5de0 85db 7404 8b13 }
condition:
- 7 of them and filesize <712704
+ 7 of them and filesize <6160384
}
-rule MALPEDIA_Win_Unidentified_070_Auto : FILE
+rule MALPEDIA_Win_Shakti_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7ae3ca74-0486-51ae-ba4c-20ff0ab01fe5"
+ id = "535cf33d-f06d-5859-b025-0ff160716ffb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_070"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_070_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shakti"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shakti_auto.yar#L1-L172"
license_url = "N/A"
- logic_hash = "bd634ade531926df7fb9636e5fb1e66cb3297f9900a01fa2493788383a51b75e"
+ logic_hash = "6f5489cc7281ed05aa1395fcaba968324612a285b4f1d07b39699fdb3c984697"
score = 75
quality = 75
tags = "FILE"
@@ -170304,32 +177400,38 @@ rule MALPEDIA_Win_Unidentified_070_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a04 50 ff15???????? 8945fc 85c0 }
- $sequence_1 = { 6a00 6a00 6a04 50 ff15???????? 8945fc 85c0 }
- $sequence_2 = { 33c0 c20400 3b0d???????? 7502 }
- $sequence_3 = { 6a00 6a04 50 ff15???????? 8945fc }
- $sequence_4 = { 6a00 6a04 50 ff15???????? 8945fc 85c0 }
- $sequence_5 = { 6a00 6a00 6a00 6a04 50 ff15???????? 8945fc }
- $sequence_6 = { 6a00 6a00 6a04 50 ff15???????? 8945fc }
- $sequence_7 = { 6a00 8d45f4 50 ff75fc 57 56 }
- $sequence_8 = { 8bf9 c78424cc00000000000000 66c78424d00000000010 e8???????? 83c40c 8d442424 50 }
- $sequence_9 = { 6a00 56 ff15???????? 8945f8 85c0 0f8493000000 6a00 }
+ $sequence_0 = { 8945ec 8b4dd4 83c102 894dd4 e9???????? 8b55c0 }
+ $sequence_1 = { 0fb711 81fa4d5a0000 752e 8b45c0 8b483c }
+ $sequence_2 = { 8b45fc 8b4dd8 0308 894df0 8b55fc }
+ $sequence_3 = { 0fb7c2 83f801 753d b9ff0f0000 8b55f0 66230a 0fb7c1 }
+ $sequence_4 = { 8b45c0 03423c 8945f8 6a40 }
+ $sequence_5 = { 52 6a00 ff55e4 8945d8 8b45f8 8b4854 894de0 }
+ $sequence_6 = { 8b45e0 8b0c10 034dc0 baff0f0000 8b45f0 }
+ $sequence_7 = { 8b55f8 0355c0 8955f8 8b45f8 }
+ $sequence_8 = { 8b742408 85f6 741e 803e00 7512 ff760c e8???????? }
+ $sequence_9 = { ff34c5b4a24000 53 57 e8???????? 83c40c 85c0 }
+ $sequence_10 = { 50 ff759c ff15???????? 85c0 740d 837d9000 }
+ $sequence_11 = { 8bff 55 8bec 8b4508 33c9 3b04cd10a04000 7413 }
+ $sequence_12 = { ff15???????? 89459c 83f8ff 7507 32c0 e9???????? 57 }
+ $sequence_13 = { bf04010000 57 8d860e080000 50 6a00 }
+ $sequence_14 = { 6a08 50 890d???????? ff15???????? }
+ $sequence_15 = { 837dd400 a1???????? 7423 c700b8000000 a1???????? }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <191488
}
-rule MALPEDIA_Win_Yanluowang_Auto : FILE
+rule MALPEDIA_Win_Unidentified_109_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f8b88dbc-f363-5fc7-a947-363c58e30984"
+ id = "c4f891e4-f77b-5dbc-bacf-3b1d550b883c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yanluowang"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yanluowang_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_109"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_109_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "6b0c4fbf1cf464112256b7ec1836b8a801dfd07954f33f682759e2bccef6aa82"
+ logic_hash = "553f5c1aaae307ba70f86b75a4cbec28cc4c8b523dbd68b695bc6b2028248608"
score = 75
quality = 75
tags = "FILE"
@@ -170343,32 +177445,32 @@ rule MALPEDIA_Win_Yanluowang_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 c745c8eca14400 c745cc02000000 e8???????? 8d45f8 50 8d8578ffffff }
- $sequence_1 = { 7402 8913 8d510c 33ff 85d2 7402 }
- $sequence_2 = { 85c1 750c 3bd1 1bd2 23d0 23542430 }
- $sequence_3 = { 85c0 7402 8908 8b55d8 8d4804 33d6 85c9 }
- $sequence_4 = { 8b048528c44500 6975d007536554 33048d28c04500 8945c0 8b45f8 8b4dc0 c1e808 }
- $sequence_5 = { 8b4508 8bd6 33d7 f7d6 }
- $sequence_6 = { 83c438 c645fc14 8d8d78eeffff ffb5e8eeffff ffb5b8eeffff ffb5b4eeffff ffb57ceeffff }
- $sequence_7 = { 8b01 85c0 0f84cc2b0200 83f808 7d0f 6bc018 }
- $sequence_8 = { 84ff 7557 8b95acf5ffff 8bc2 8b8da8f5ffff 2bc1 }
- $sequence_9 = { 337dc8 8b4514 85c0 7402 8938 8d7904 33d2 }
+ $sequence_0 = { 488d55df 488d4df7 4c8d45f7 e8???????? 8bf0 85c0 }
+ $sequence_1 = { 7405 85db 0f44d8 0fb68fa2030000 0fbe45ab 3bc1 7e11 }
+ $sequence_2 = { e8???????? 488bcb e8???????? 488bdf 4885ff 75b5 488b742430 }
+ $sequence_3 = { 8b07 418b09 4883c704 4d8d4904 480fafcd 4803c8 418bc0 }
+ $sequence_4 = { 2b8300010000 3bc5 7312 8bd5 488bcb e8???????? 85c0 }
+ $sequence_5 = { 4c8b3a 4c8be1 4c8bea 488d4c2420 41b8a8040000 33d2 }
+ $sequence_6 = { 23c6 440bf0 8d040a 418bd3 4403f0 418bc3 c1c80b }
+ $sequence_7 = { eb77 418d41ff 4863c8 488d048f 33ff 4d8d048a }
+ $sequence_8 = { 0f8462020000 83b90001000000 7621 e8???????? 89834c020000 85c0 0f8550020000 }
+ $sequence_9 = { 4289449efc 4c3bdd 7c8b 8b442450 8b0b 4c8b742420 8903 }
condition:
- 7 of them and filesize <834560
+ 7 of them and filesize <723968
}
-rule MALPEDIA_Win_Mokes_Auto : FILE
+rule MALPEDIA_Win_Industroyer2_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5228f490-0d80-56e9-a8cc-72e35ac44ea7"
+ id = "01c28e59-8cb1-5bf1-9de6-64ce0dd77d4a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mokes"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mokes_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.industroyer2"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.industroyer2_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "be97fd0567c8d98c1350b6cf1d21361ab6916096a99c6915f04160ab0a34cb53"
+ logic_hash = "bbf01a0f560944dbb85cdfc8fdeff74a884348b77c6b1a1a74790ea421be78c4"
score = 75
quality = 75
tags = "FILE"
@@ -170382,32 +177484,32 @@ rule MALPEDIA_Win_Mokes_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f6c101 0f85b0000000 8b442424 8b00 3d???????? 0f849f000000 8b4804 }
- $sequence_1 = { f20f1001 660f2fc1 0f28c3 f20f5cc7 0f47c1 f20f1008 f20f59c2 }
- $sequence_2 = { ff9050010000 8b8bac010000 8d83ac010000 89442424 85c9 740b 83790400 }
- $sequence_3 = { ff5030 89442410 83f8ff 7512 8b4508 c700???????? 5f }
- $sequence_4 = { f20f1025???????? f30fe6db f30fe6d2 f30fe6c9 f30fe6c0 f20f59dc f20f59d4 }
- $sequence_5 = { ffd0 8d4900 3d???????? 0f84cb000000 8b00 85c0 75ef }
- $sequence_6 = { e8???????? 8d4e14 e8???????? 8d4e34 e8???????? 5f 5e }
- $sequence_7 = { ff750c c70000000000 e8???????? 8b4508 8bce c706???????? c74608???????? }
- $sequence_8 = { e8???????? 8b75e4 8b4e0c 03ce 8b4604 8d0445feffffff 50 }
- $sequence_9 = { f20f1005???????? 660f2fc1 0f82ac010000 f20f108e88000000 f20f109690000000 f20f5c9680000000 f20f5c4e78 }
+ $sequence_0 = { 732c 837df800 7426 8b45fc 8b4df4 8b1481 89559c }
+ $sequence_1 = { 89480c 8b55fc 8b451c 894210 694d18a0860100 034d1c }
+ $sequence_2 = { eb07 c745d000000000 8b4508 8a4dd0 888845000100 }
+ $sequence_3 = { 8b4d08 e8???????? 8945fc 68???????? 8b4508 50 }
+ $sequence_4 = { 885103 8b45fc 8b4804 8b551c 8b8238000100 894104 8b4dfc }
+ $sequence_5 = { c1e200 8b45fc 8b4d08 8a1411 885005 b801000000 d1e0 }
+ $sequence_6 = { 8b4df0 51 ff15???????? 85c0 7406 c645ff01 eb04 }
+ $sequence_7 = { c6400c00 8b4dfc c641140a 6a04 8b55fc 83c210 52 }
+ $sequence_8 = { 837df800 742c 8b55fc 8b45f4 8b0c90 898d78ffffff 8b9578ffffff }
+ $sequence_9 = { 8b45fc 50 e8???????? 0fb6c8 85c9 7444 68???????? }
condition:
- 7 of them and filesize <18505728
+ 7 of them and filesize <100352
}
-rule MALPEDIA_Win_Kgh_Spy_Auto : FILE
+rule MALPEDIA_Win_Andardoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "95e1000f-6599-59f6-ad77-7fb1f63fc7e2"
+ id = "a2062653-6e94-5023-8019-c5f17c84046c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kgh_spy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kgh_spy_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.andardoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.andardoor_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "c99afdfd1b207e301e0a54b515065ba98af784202a9cd5e6f9a55bcba5a38dab"
+ logic_hash = "3510472d198d8ac0d724063f8fb842ce0d2281170e5fd2c286cfefa5f50dca2c"
score = 75
quality = 75
tags = "FILE"
@@ -170421,32 +177523,32 @@ rule MALPEDIA_Win_Kgh_Spy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488b442428 8b4c2430 894808 e9???????? 4883c458 5f }
- $sequence_1 = { 75e2 488b842498000000 89442460 8b442468 8b4c2460 488b542470 4803d1 }
- $sequence_2 = { 488d8c24b0000000 ff15???????? 85c0 0f8547010000 0fb705???????? }
- $sequence_3 = { 488d8424300a0000 4889842488000000 48c7442450ffffffff 48ff442450 }
- $sequence_4 = { 488b4c2468 803c0800 75e8 488b442468 488d8c24c0000000 48898c2498000000 48c7442470ffffffff }
- $sequence_5 = { f3aa 488d4c2428 ff15???????? 0fb7442428 83f809 740a 0fb7442428 }
- $sequence_6 = { 488d8424f0030000 488bf8 33c0 b908020000 f3aa 4c8d0df7e30000 }
- $sequence_7 = { 4885c0 7403 f0ff00 488d4128 41b806000000 488d15b4a30000 483950f0 }
- $sequence_8 = { 8bc8 e8???????? 48898424d8000000 48c744242000000000 4c8d8c2470010000 448b442468 }
- $sequence_9 = { 488d1dddab0000 483bcb 740c e8???????? }
+ $sequence_0 = { 4c8d8c2400020000 33d2 0f1f8000000000 410fb60c11 880c10 488d5201 84c9 }
+ $sequence_1 = { 6690 488bcb ff15???????? a810 741f 40383d???????? 0f84d0000000 }
+ $sequence_2 = { 48895c2458 ff15???????? 85c0 752b 488b0d???????? 4885c9 7406 }
+ $sequence_3 = { 4881ecf0030000 0f2970d8 0f2978c8 488b05???????? }
+ $sequence_4 = { 0f2970d8 0f2978c8 488b05???????? 4833c4 488985c0020000 }
+ $sequence_5 = { 41b880000000 e8???????? 4533c9 4c8d442430 }
+ $sequence_6 = { b943150000 6689742468 ff15???????? 668944246a 41b810000000 }
+ $sequence_7 = { 488bf8 4885c0 0f84ed000000 b943150000 6689742468 ff15???????? }
+ $sequence_8 = { 488bf9 33d2 33c9 498bf0 ff15???????? 85c0 7407 }
+ $sequence_9 = { 488bcf ff15???????? 488bf8 488d4ffe }
condition:
- 7 of them and filesize <207872
+ 7 of them and filesize <339968
}
-rule MALPEDIA_Win_Royal_Dns_Auto : FILE
+rule MALPEDIA_Win_Gacrux_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8e27ee32-9aaf-59db-953d-0696af40bcce"
+ id = "0c66c13b-77d9-5c78-ab68-75b7e55560db"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.royal_dns"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.royal_dns_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gacrux"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gacrux_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "f281d4e3be759adcb32b06448d83aa5fdafcb96a4b912bbb46b43de4955e29ec"
+ logic_hash = "bb1a910d98caf8e19645b8aead4c6d896507b388f794dfe868a61d77f59f135d"
score = 75
quality = 75
tags = "FILE"
@@ -170460,32 +177562,32 @@ rule MALPEDIA_Win_Royal_Dns_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 e8???????? 8b4dfc 8b85b4fcffff 83c404 }
- $sequence_1 = { e8???????? 83c40c 8bc6 eb15 8d8da1f1ffff }
- $sequence_2 = { ff15???????? 3d02010000 8b85e0fdffff 7533 6a00 50 }
- $sequence_3 = { 4a 759a 8b55fc 85ff 7468 0fb606 c1e802 }
- $sequence_4 = { 0fb61406 c1ea03 0fb69248132500 8811 0fb61c06 0fb6540601 c1ea06 }
- $sequence_5 = { 80e301 0ac3 8845ed 8a45f8 8ad8 8345e805 }
- $sequence_6 = { 8d8dfcfeffff 83c40c 33c0 2bd1 }
- $sequence_7 = { 7504 33c0 eb0a 0fb6c8 }
- $sequence_8 = { 0fb61c30 0fb6543001 03db 03db c1ea06 0bd3 }
- $sequence_9 = { 8a17 8816 47 46 48 }
+ $sequence_0 = { 0f848e000000 41 83482120 49 8b01 49 83c108 }
+ $sequence_1 = { 894808 48 8b4c2430 48 894810 8b4c2444 }
+ $sequence_2 = { 48 03ca 849c013c010000 740b 41 81cb00300000 45 }
+ $sequence_3 = { 6bc838 48 8b05???????? 8b540120 c1ea02 1bd2 3bd6 }
+ $sequence_4 = { 7543 48 85db 7409 }
+ $sequence_5 = { 8b3a 48 8bcd 48 c1e91d 48 8bc5 }
+ $sequence_6 = { 41 ffc1 49 83c204 41 81f900010000 }
+ $sequence_7 = { 0fb7ee 66c1ed08 45 8a780c 45 8bda 45 }
+ $sequence_8 = { 56 41 57 48 83ec50 49 63e8 }
+ $sequence_9 = { 4d 033e 45 0fb6ed 49 8bcf }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <122880
}
-rule MALPEDIA_Win_Stresspaint_Auto : FILE
+rule MALPEDIA_Win_Troldesh_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1abc90df-5501-5268-be5d-9ffd5264cf78"
+ id = "7a3f582f-20a8-506d-8165-0b2ca7b385f0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stresspaint"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stresspaint_auto.yar#L1-L151"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.troldesh"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.troldesh_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "34d2cc78b8a1b3b96faf71dac1e0e5a144bca4946a3f4a475da9ab8b6bdc6c9b"
+ logic_hash = "0484cce0fd00b2a95d24b675e3e6f5f144cbe86411aeac4268060b95d7df46bc"
score = 75
quality = 75
tags = "FILE"
@@ -170499,38 +177601,32 @@ rule MALPEDIA_Win_Stresspaint_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0103 014510 294514 83665800 }
- $sequence_1 = { 8d540208 8908 8d4a04 8a5202 51 }
- $sequence_2 = { 8d540203 3bea 7e4d 8b6c241c }
- $sequence_3 = { 0106 83560400 837d1c00 7494 }
- $sequence_4 = { 0103 ebaa 8b442408 56 }
- $sequence_5 = { 0103 014510 294674 8b4674 }
- $sequence_6 = { 0107 115f04 3bcb 7508 }
- $sequence_7 = { 0108 8b8e44010000 114804 8b4f18 }
- $sequence_8 = { 0107 83570400 85c9 7508 }
- $sequence_9 = { 010b 8945fc 8bc2 83530400 }
- $sequence_10 = { 8d5318 c7432400200000 66897312 c6431100 890a }
- $sequence_11 = { 8d540201 52 51 6a39 55 }
- $sequence_12 = { 8d540101 8bc5 89542430 8b542450 }
- $sequence_13 = { 8d5338 3b02 740a 41 83c250 3bcf }
- $sequence_14 = { 8d540201 8915???????? 33c0 8bd6 }
- $sequence_15 = { 8d540208 8b4500 c70100000000 8b4c2430 }
+ $sequence_0 = { ff74241c 8d44247c ff74241c 50 e8???????? 8b8e18050000 83c40c }
+ $sequence_1 = { e8???????? 8b4510 8b4008 68ffffff7f 6a00 6a0a ff30 }
+ $sequence_2 = { eb17 51 50 8d45d8 50 e8???????? 8b4514 }
+ $sequence_3 = { ff7314 e8???????? 59 8b4df4 89431c 85c0 7511 }
+ $sequence_4 = { e9???????? 8b4ddc e8???????? 33c0 83c604 8975f8 8b7508 }
+ $sequence_5 = { e8???????? a3???????? e8???????? 8bf0 8974242c e8???????? 6a00 }
+ $sequence_6 = { ff7720 89742414 56 e8???????? 59 59 85c0 }
+ $sequence_7 = { ff7508 8bcf 56 ffb754010000 6a04 e8???????? 83c410 }
+ $sequence_8 = { e8???????? 85c0 7419 6a14 8d500c 8d4de0 e8???????? }
+ $sequence_9 = { e8???????? 8b4514 660fbe00 0fb7c0 50 6a01 e8???????? }
condition:
- 7 of them and filesize <1155072
+ 7 of them and filesize <3915776
}
-rule MALPEDIA_Win_Geminiduke_Auto : FILE
+rule MALPEDIA_Win_Miragefox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7571eb47-e456-5ff2-b8bf-b1898ddd8358"
+ id = "7d7cd6d5-44d9-5ffc-a5c9-9ff4ba40c5bc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.geminiduke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.geminiduke_auto.yar#L1-L156"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miragefox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.miragefox_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "e55c638d52ba8f741e7b2025242401b1531659829b54a8df50edaef39f23c4d8"
+ logic_hash = "f8d9e523d9895537a03eee9c6c67877c75001719916af13d5bd2cc1c1b329b5b"
score = 75
quality = 75
tags = "FILE"
@@ -170544,37 +177640,32 @@ rule MALPEDIA_Win_Geminiduke_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 57 8b7c2410 8b442414 }
- $sequence_1 = { 8b7c2410 8b442414 8b4c2418 f3aa }
- $sequence_2 = { 6a00 68???????? e8???????? 83c404 50 6801000080 ff15???????? }
- $sequence_3 = { 8b4c2418 f3aa 5f 59 }
- $sequence_4 = { 03459c 03c8 894ddc 8b45fc }
- $sequence_5 = { 034590 8b8d70ffffff c1e907 8b9570ffffff }
- $sequence_6 = { 034584 8b8d64ffffff c1e907 8b9564ffffff c1e219 0bca }
- $sequence_7 = { 034590 03c8 894dd0 8b45f8 }
- $sequence_8 = { f7f3 66894706 8bc2 c1e010 668b4604 33d2 f7f3 }
- $sequence_9 = { 0fb6f8 57 6a20 56 e8???????? 83c40c }
- $sequence_10 = { 337704 33e8 8b442410 c1ee12 83e601 33ee }
- $sequence_11 = { 33d2 f7f3 66894704 8bc2 }
- $sequence_12 = { e8???????? d1ee 33f3 c1ee03 337704 33e8 }
- $sequence_13 = { 0430 8ad1 80ea0a 80fa05 7705 }
- $sequence_14 = { 8a442404 8ac8 80e961 80f919 7703 b001 }
+ $sequence_0 = { 53 50 c6450805 e8???????? be1c810000 8d4508 56 }
+ $sequence_1 = { 7509 0fb68340f62a00 eb02 8bc3 5b c9 c3 }
+ $sequence_2 = { 8985f07fffff 6a00 0f94c0 83c023 8885ec7fffff 8d85e0f7feff }
+ $sequence_3 = { 7417 8bf9 c1ff05 83e11f 8b3cbd20f52a00 }
+ $sequence_4 = { 57 e8???????? 8d4604 6a19 }
+ $sequence_5 = { 6a00 50 e8???????? 8b4510 83c40c 8985147cffff }
+ $sequence_6 = { 6802800000 8d8520010000 53 50 e8???????? 8b4510 83c418 }
+ $sequence_7 = { 6800400000 50 ff75fc ff15???????? 8b8514010000 2b75f4 }
+ $sequence_8 = { b820080100 e8???????? 53 56 ff7518 6a00 6a01 }
+ $sequence_9 = { e8???????? 834dfcff 8d4dec e8???????? e9???????? bf18800000 }
condition:
- 7 of them and filesize <327680
+ 7 of them and filesize <286720
}
-rule MALPEDIA_Win_Penco_Auto : FILE
+rule MALPEDIA_Win_Socelars_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0506b7c6-0597-5673-b29d-0e2e4b0bbb8c"
+ id = "b06c7ac2-d920-55f6-9edd-c06a57d2d404"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.penco"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.penco_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.socelars"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.socelars_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "b907c123e9f48e051972fa4ccfde76e3114fafc16984b4ff739806928ca43da4"
+ logic_hash = "29f15e383674389295d6d5d873e2a8fae68e30508b53f5e863e0aef43fe3264f"
score = 75
quality = 75
tags = "FILE"
@@ -170588,32 +177679,32 @@ rule MALPEDIA_Win_Penco_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 6a01 6800000080 8d9500010000 52 8b1d???????? }
- $sequence_1 = { 3334bd00d83400 0fb67c2414 3334bd00d43400 8b4c241c 33700c 83c010 8bde }
- $sequence_2 = { 40 89442418 3b442414 0f82fffeffff eb13 8d042e 68???????? }
- $sequence_3 = { 741c 68???????? 68ff010f00 56 ff15???????? 56 85c0 }
- $sequence_4 = { 0fbe80e8983400 83e00f 33f6 eb04 33f6 33c0 }
- $sequence_5 = { 8d4598 50 6a00 6a00 8d4db8 51 8b55a4 }
- $sequence_6 = { 33c0 84c9 7428 8d642400 80f930 7c1c 80f939 }
- $sequence_7 = { 894c2418 8b4c2444 f7f1 33d2 c744242001000000 03442410 89442414 }
- $sequence_8 = { 7504 8bf0 eb3e 6a0a }
- $sequence_9 = { 8b349528e83400 8b542428 0fb6f9 3334bd00d83400 8b4c241c c1ea18 33349528ec3400 }
+ $sequence_0 = { f6462808 894618 7515 8b4c243c ba14000000 e8???????? 89842430010000 }
+ $sequence_1 = { 8b4dfc 83b9cc03000020 7409 c745c00c000000 eb07 c745c00e000000 8b55fc }
+ $sequence_2 = { ff460c 807e0a00 750a 8bce e8???????? 8a4e09 8b430c }
+ $sequence_3 = { ff730c ff7308 e8???????? 8bf8 83c410 85ff 0f8480000000 }
+ $sequence_4 = { 8b542410 8b5248 f6421c20 0f8437050000 8b4214 ff4878 8b8888000000 }
+ $sequence_5 = { e9???????? 8b4c243c 33c0 89842430010000 ba43000000 8b472c 40 }
+ $sequence_6 = { f7da 56 1bd2 83c235 eb55 6a00 ff77c4 }
+ $sequence_7 = { e8???????? 83c40c eb36 8d4201 898188000000 8d0c92 8b442438 }
+ $sequence_8 = { fe4613 8a4619 fec8 0fb6c8 884619 3bf9 7d24 }
+ $sequence_9 = { ff742424 e8???????? 83c40c eb32 8b54241c 8d4101 898688000000 }
condition:
- 7 of them and filesize <319488
+ 7 of them and filesize <2151424
}
-rule MALPEDIA_Win_Taleret_Auto : FILE
+rule MALPEDIA_Win_Banatrix_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "90652d3d-3308-5c4e-91b0-de6f7ec4ea56"
+ id = "dddc42c8-ebb5-5b25-8e19-698be8f181ff"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.taleret"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.taleret_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.banatrix"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.banatrix_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "0af9ed1f3725609b54a6e19f400c5abe16095e727614fae56d9f4e23ded04fd2"
+ logic_hash = "ad75928262b7ab312e9d49af768e2651c88b8c026115565bb62125e134a2e0bd"
score = 75
quality = 75
tags = "FILE"
@@ -170627,32 +177718,32 @@ rule MALPEDIA_Win_Taleret_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c68424b40300000d e8???????? 50 8d4b18 }
- $sequence_1 = { 8b44240c 8b4c2408 8b542404 6a00 6a00 6a03 68???????? }
- $sequence_2 = { 51 50 68???????? 890d???????? }
- $sequence_3 = { 8d442408 c744242401000000 50 ff15???????? 85c0 7528 8b4c2438 }
- $sequence_4 = { 8d4e3c c644241c05 e8???????? 8d4e40 c644241c06 e8???????? }
- $sequence_5 = { c60600 e8???????? 83c40c 85c0 7526 57 8d8c24e8000000 }
- $sequence_6 = { 85c0 0f85b2000000 a1???????? 668b0d???????? 8a15???????? 89842480000000 }
- $sequence_7 = { c684247016000001 e8???????? 8b9c247c160000 8b6c241c e9???????? 8b442424 8b4c2414 }
- $sequence_8 = { 8a440444 eb02 b03d 83fd01 884301 7e33 }
- $sequence_9 = { e8???????? 83c408 33f6 e8???????? 8a96f0700010 32d0 }
+ $sequence_0 = { 83ec10 894208 89f7 31c0 f3aa }
+ $sequence_1 = { e8???????? 8b4304 85c0 741b c744240800800000 c744240400000000 }
+ $sequence_2 = { c744240806000000 893c24 c1e804 40 0fb7c0 }
+ $sequence_3 = { 8b5320 0345d0 89542404 890424 }
+ $sequence_4 = { e9???????? e8???????? c744240824000000 c744240400000000 }
+ $sequence_5 = { 51 c9 c3 55 89e5 57 }
+ $sequence_6 = { 83ec10 85c0 8945d4 7542 8b45d0 c744240c04000000 c744240800300000 }
+ $sequence_7 = { 8b75d0 8b7dd4 2b7e34 897dcc 7514 8b7304 }
+ $sequence_8 = { 83787c00 7511 c704247f000000 e8???????? 31c0 51 eb66 }
+ $sequence_9 = { 85c0 56 56 7416 8b03 c745d000000000 }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <180224
}
-rule MALPEDIA_Win_Akira_Auto : FILE
+rule MALPEDIA_Win_Vsingle_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5047b686-dc46-5a3e-aa74-fc92a34b0f3e"
+ id = "39c4d7b9-45d8-55fa-afdc-e3bdbe3bcacd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.akira"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.akira_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vsingle"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vsingle_auto.yar#L1-L182"
license_url = "N/A"
- logic_hash = "c1ae7dbc4a382b6e7a49f30242c48e32f0bd119ae1ed5e26b8c812d114457836"
+ logic_hash = "83d89a8e2f1a1d70a66e028468bac58cc5e5d328eca56cc57ee9f6d9e54be732"
score = 75
quality = 75
tags = "FILE"
@@ -170666,34 +177757,40 @@ rule MALPEDIA_Win_Akira_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b01 85c0 7e18 ffc8 8901 498b4840 488b11 }
- $sequence_1 = { 418bc9 83c902 41f6c108 410f44c9 81e13bffffff 390d???????? 741d }
- $sequence_2 = { 90 488b4b60 48894c2430 4885c9 7445 488b5370 4889542440 }
- $sequence_3 = { 7cee 488bcb 488b5c2430 4883c420 5f e9???????? 0fb6043b }
- $sequence_4 = { ff5208 90 488b4b60 48894c2430 4885c9 7445 488b5370 }
- $sequence_5 = { e8???????? 488975d0 488b4dd8 488975d8 48894808 0f1045e0 0f114010 }
- $sequence_6 = { 4488443c6e 48ffc7 4883ff0a 72ac 0f57c0 0f118590020000 0f57c9 }
- $sequence_7 = { 740a e8???????? 488bd8 eb03 498bdd 49897e18 }
- $sequence_8 = { e8???????? 33f6 41897578 49397568 744d 488b0f 40387128 }
- $sequence_9 = { c645bf01 4883ef01 75b4 0f2845bf 33ff 4c8d75cf 48837de710 }
+ $sequence_0 = { 83c408 8945ec 8b4dec 8b550c 8d440a01 89450c 8b4d0c }
+ $sequence_1 = { 8955b8 eb14 8b45c0 83c004 8945c0 8b4dbc 83c102 }
+ $sequence_2 = { 83c408 8985f0feffff 83bdf0feffff00 7507 33c0 e9???????? 8b95f0feffff }
+ $sequence_3 = { 52 680c030000 8b4508 50 }
+ $sequence_4 = { 83c408 8985f4eeffff 8b95f4eeffff 8995f0eeffff c745fc00000000 8b85f0eeffff }
+ $sequence_5 = { 8955b8 8b45d0 83c001 8945d0 837db803 7d0c 6a3d }
+ $sequence_6 = { 83c408 898500efffff 83bd00efffffff 7529 8b9504efffff 52 8d8524f7ffff }
+ $sequence_7 = { 33c0 8945e9 8945ed 8945f1 8945f5 8845f9 }
+ $sequence_8 = { 50 b807752b15 81f0467f1fbf 81f08c7668e6 81e8d57c5c4c 8b0c28 }
+ $sequence_9 = { 82e8ef e9???????? 52 53 bb4c969f2a 81f3b4d3bba6 81c3c02d0a2f }
+ $sequence_10 = { 81c7745e2200 81c736b60a42 81c7b551a68d 81f7e7564bc6 897c2404 }
+ $sequence_11 = { bbf93d64ba 81f345ba76fc 81f381c713f5 81f34d7b2ffd 81f346dc0990 81c33217d821 8b142b }
+ $sequence_12 = { 5b 57 50 b86a45ae9f 81c07b6673f5 81f081118d0d }
+ $sequence_13 = { bb86d72160 e9???????? 59 51 b9cf4a22af }
+ $sequence_14 = { 81eb96c3a483 668b0c18 5b 53 bbd7e0d126 81f3b7cf22ba 81c3282d094f }
+ $sequence_15 = { e9???????? bf756ddf55 81f7960c0426 eb36 81c7745e2200 81c736b60a42 }
condition:
- 7 of them and filesize <1286144
+ 7 of them and filesize <940032
}
-rule MALPEDIA_Win_Aresloader_Auto : FILE
+rule MALPEDIA_Win_Smanager_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "aecf8195-bc3f-5d42-bd81-bfa1c242c64d"
+ id = "7788af6d-844d-509b-90a8-b8ca5df742b1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aresloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aresloader_auto.yar#L1-L109"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.smanager"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.smanager_auto.yar#L1-L224"
license_url = "N/A"
- logic_hash = "3fed3bf2cf5088e9a8f4396999f890e21fa81afee0e4b5adddfaf27ad4b3888c"
- score = 60
- quality = 25
+ logic_hash = "7070ed4ef9fc0031fffb8ae0d3a2a122913a3a51a0e1a419190de42eef9b5039"
+ score = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -170705,32 +177802,46 @@ rule MALPEDIA_Win_Aresloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85db 7435 85f6 7431 }
- $sequence_1 = { c744241410000000 c744241000000000 c744240c00000000 c744240800000000 c744240400000000 }
- $sequence_2 = { 8b6c243c 3d???????? 741d 896c243c }
- $sequence_3 = { a1???????? 8b5c2430 8b742434 8b7c2438 8b6c243c 3d???????? }
- $sequence_4 = { 8b7c2438 8b6c243c 85db 7435 }
- $sequence_5 = { 7431 896c240c 897c2408 895c2404 893424 }
- $sequence_6 = { 8b6c243c 85db 7435 85f6 }
- $sequence_7 = { 8b7c2438 8b6c243c 3d???????? 741d 896c243c }
- $sequence_8 = { 893424 e8???????? 85c0 7831 }
- $sequence_9 = { 7431 896c240c 897c2408 895c2404 }
+ $sequence_0 = { 6a0d e8???????? 83c404 8bf0 }
+ $sequence_1 = { 51 ffd0 83c40c c7460800000000 }
+ $sequence_2 = { 7410 6a00 6a00 6830001100 }
+ $sequence_3 = { 8b7604 6a00 6a00 56 68???????? 6a00 6a00 }
+ $sequence_4 = { 8b4608 85c0 7420 a801 7515 }
+ $sequence_5 = { 8b4510 85c0 7407 50 ff15???????? }
+ $sequence_6 = { 68???????? 6a00 6a00 ff15???????? 8bf8 897e28 }
+ $sequence_7 = { 83c602 6a22 56 e8???????? 83c408 }
+ $sequence_8 = { ff15???????? 32c0 e9???????? 0f1005???????? }
+ $sequence_9 = { 0007 b15a 0007 b15a }
+ $sequence_10 = { 0000 80ed4a 0044feff ff900100008c }
+ $sequence_11 = { 4c8d9c24d0010000 498b5b28 498b7330 498b7b38 498be3 415f }
+ $sequence_12 = { 41c7430800000000 488d59b0 488d0532730100 498943e0 488d0537730100 }
+ $sequence_13 = { 0008 53 4f 00ef }
+ $sequence_14 = { 4885c0 7463 41b80f000000 488d159ab90100 488bc8 e8???????? }
+ $sequence_15 = { 44894de9 66448955f1 418bc8 8bc2 4c8d0de10b0100 c1e918 }
+ $sequence_16 = { 488bf8 448b842480000000 33d2 488bc8 e8???????? 4533f6 }
+ $sequence_17 = { 0007 b15a 00c4 b15a }
+ $sequence_18 = { 41b803000000 488d0d908e0000 4533c9 ba00000040 4489442420 ff15???????? }
+ $sequence_19 = { 0003 b157 0000 0c0c }
+ $sequence_20 = { 0007 b15a 0089b05a0089 b05a }
+ $sequence_21 = { 7404 b301 eb03 448937 }
+ $sequence_22 = { 0001 ce 50 0008 }
+ $sequence_23 = { 0000 0c0c 0c0c 0c0c 0c0c 0c0c 0102 }
condition:
- 7 of them and filesize <2657280
+ 7 of them and filesize <10013696
}
-rule MALPEDIA_Win_Absentloader_Auto : FILE
+rule MALPEDIA_Win_Squirrelwaffle_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9aab04f2-7678-5cf8-8d74-f6db3f7fcf22"
+ id = "67d18a0f-cebe-56e6-8b79-40dff03f1fb3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.absentloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.absentloader_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.squirrelwaffle"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.squirrelwaffle_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "77496690e6eb66a44354cd3e27ded72ee59f2468546d53e2a80ae68b108dd0bf"
+ logic_hash = "2fb7fd7c7f2885b81fdacc79e3b0b0578babd5d7d5854f31f47508825bacd6eb"
score = 75
quality = 75
tags = "FILE"
@@ -170744,32 +177855,32 @@ rule MALPEDIA_Win_Absentloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { fe81b89406fd 89148d909406fd 8d4dfc e8???????? 5e c9 c3 }
- $sequence_1 = { eb16 66c704375c6e eb0e 66c704375c74 eb06 66c704375c62 83c602 }
- $sequence_2 = { e8???????? c645fc12 8bcb 0f2805???????? 0f1145b4 6a7f }
- $sequence_3 = { 740f 33c0 80b034a606fd2e 40 83f814 72f3 8b0d???????? }
- $sequence_4 = { 8bec 56 ff7508 8bf1 e8???????? c706841e05fd }
- $sequence_5 = { 7408 3a8ac05d05fd 755a 8b06 8a08 40 42 }
- $sequence_6 = { 7e37 68f8aa06fd e8???????? 833d????????ff 59 7523 bffcaa06fd }
- $sequence_7 = { 7417 6827130000 6830f405fd 68341606fd e8???????? 83c40c 837f2c00 }
- $sequence_8 = { c9 c3 6a08 b8a30305fd e8???????? 8bf1 8975ec }
- $sequence_9 = { 84db 743b 8b4608 8378fc00 7432 83ec10 8d4668 }
+ $sequence_0 = { ffd6 85c0 0f85d9000000 8b458c }
+ $sequence_1 = { 0f431d???????? 8a00 85c9 7416 51 }
+ $sequence_2 = { 83c40c 8b36 ba???????? 85f6 0f853cffffff 8b7d88 }
+ $sequence_3 = { 85c0 0f8453020000 8b4a14 48 8945f0 8bc2 }
+ $sequence_4 = { 8b7310 2bc6 8975f8 57 3bc2 0f8214010000 8d0416 }
+ $sequence_5 = { b803000000 0f438d10fefeff ba???????? 83fe03 }
+ $sequence_6 = { 0f1185f8fdfeff f30f7e4710 660fd68508fefeff c7471000000000 c747140f000000 }
+ $sequence_7 = { 8db5f8fbffff 8d34c6 837e1410 8bc6 7202 }
+ $sequence_8 = { 897714 eb26 8b0d???????? 0f57c0 }
+ $sequence_9 = { c645cc00 8d4dd8 ff75cc 6a08 }
condition:
- 7 of them and filesize <794624
+ 7 of them and filesize <147456
}
-rule MALPEDIA_Win_Arefty_Auto : FILE
+rule MALPEDIA_Win_Sappycache_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "290417d3-5ee5-5229-8624-fd994b33b5b6"
+ id = "ad4dab53-cb13-5a84-86d5-edc74e26f321"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.arefty"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.arefty_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sappycache"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sappycache_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "f5f9e554cdcd0132916bd1281d9476767533aa9af2658a9193107a622555119f"
+ logic_hash = "f4483696db263dfbbabb83dfce8ccde9309b112a65cf425cc63ed3dc1fcead40"
score = 75
quality = 75
tags = "FILE"
@@ -170783,34 +177894,34 @@ rule MALPEDIA_Win_Arefty_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 e8???????? 83c404 83fbff 7407 53 }
- $sequence_1 = { 50 53 ff15???????? 680000a000 e8???????? }
- $sequence_2 = { 680000a000 57 53 ff15???????? 85c0 }
- $sequence_3 = { 680000a000 57 53 ff15???????? }
- $sequence_4 = { 57 e8???????? 83c404 83fbff 7407 53 ff15???????? }
- $sequence_5 = { ff15???????? 680000a000 e8???????? 8bf8 }
- $sequence_6 = { 0fb6041e 50 8b07 68???????? 6a03 8d04b0 }
- $sequence_7 = { 8b07 68???????? 6a03 8d04b0 50 e8???????? 46 }
- $sequence_8 = { 50 53 ff15???????? 680000a000 e8???????? 8bf8 83c404 }
- $sequence_9 = { 50 53 ff15???????? 680000a000 }
+ $sequence_0 = { 448bcf 895c2428 33d2 33c9 4889442420 488bf0 ff15???????? }
+ $sequence_1 = { ff15???????? 85c0 7428 488bcd 488d1545f80000 }
+ $sequence_2 = { 488b8188000000 488d0d16fa0000 4883c018 7452 8bd7 0f1000 }
+ $sequence_3 = { ff15???????? 41b904000000 c7452060ea0000 4c8d4520 }
+ $sequence_4 = { 4c8d0dd6860000 c5f35cca c4c173590cc1 4c8d0da5760000 c5f359c1 }
+ $sequence_5 = { 49ffc0 47382c04 75f7 488d157c1f0100 }
+ $sequence_6 = { 4c89742430 448bcf 895c2428 33d2 33c9 4889442420 }
+ $sequence_7 = { f20f1000 8b7808 e9???????? 488d05eed70000 4a8b0ce8 42f644313880 744d }
+ $sequence_8 = { 4c8d0d136d0000 8bf9 488d15ba4d0000 b906000000 4c8d05f66c0000 e8???????? }
+ $sequence_9 = { 4180e003 80e30f 41c0e004 440ac0 }
condition:
- 7 of them and filesize <237568
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Maze_Auto : FILE
+rule MALPEDIA_Win_Snatchcrypto_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "107fc7f0-df43-5a49-b2af-87c958bef91f"
+ id = "8e680a41-0fdc-5ac7-bc9f-3f795f28f0bb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maze"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.maze_auto.yar#L1-L201"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.snatchcrypto"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.snatchcrypto_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "114687adcaa31dee32acfd0d8a276547892002fc6701cc69c1544ebdb3b57221"
+ logic_hash = "276b735298fc8584b98457d3cb267661e785fa3122c696ae64ba4741a5859a9d"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -170822,41 +177933,32 @@ rule MALPEDIA_Win_Maze_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 57 56 83ec10 8b4510 8b4d0c }
- $sequence_1 = { 8945f0 c745f000000000 8b45f0 83c410 5e 5f }
- $sequence_2 = { 60 8b7d08 8b4d10 8b450c f3aa 61 8945f0 }
- $sequence_3 = { 83ec10 8b4510 8b4d0c 8b5508 837d0800 8945ec }
- $sequence_4 = { 8945ec 894de8 8955e4 7509 c745f000000000 eb17 60 }
- $sequence_5 = { 89c8 0500000001 83d200 89d7 }
- $sequence_6 = { 89c7 e8???????? 83c40c 57 55 8dbc24f4000000 }
- $sequence_7 = { 89c8 01d6 ba53c6f0ff f7e2 }
- $sequence_8 = { 41 41 41 41 41 41 41 }
- $sequence_9 = { 83ec20 56 be???????? 56 6a00 6801001200 }
- $sequence_10 = { 8d45ec 56 8945f8 6a00 8d45f4 50 c745f40c000000 }
- $sequence_11 = { b904000000 6bd109 8b4d08 8b941100100000 c1ea0a }
- $sequence_12 = { b948040000 b8cccccccc f3ab a1???????? 33c5 8945ec 50 }
- $sequence_13 = { 898d6cfeffff 8b4dfc 8b5508 8b848a10080000 }
- $sequence_14 = { 8b8c1040100000 c1e10a ba04000000 c1e200 8b4508 8b941040100000 c1ea16 }
- $sequence_15 = { 899594fdffff 8b8d9cfdffff 338d98fdffff 038d94fdffff 8b55fc }
- $sequence_16 = { 8b54813c c1e209 8b45fc 8b4d08 8b44813c }
- $sequence_17 = { 8985e4feffff 8b45fc 8b4d08 8b548134 }
- $sequence_18 = { 8b4dfc 8b5508 8b848a1c080000 c1e017 8b4dfc 8b5508 8b8c8a1c080000 }
+ $sequence_0 = { 7528 488bd3 488bcf e8???????? 448b87a8020000 488d15d43f0200 448906 }
+ $sequence_1 = { 4c8d442430 e8???????? 85c0 0f8533010000 8d7058 8d6814 eb36 }
+ $sequence_2 = { ff15???????? 488bf8 4885c0 750f ff15???????? 488d15f7730200 eb27 }
+ $sequence_3 = { 0fb74348 ff4320 448b4b20 ffc0 488d1586a70200 440fb7c0 e8???????? }
+ $sequence_4 = { 48894598 4889442458 4889442460 0fb6474d 41c1e608 440bf0 0fb6474e }
+ $sequence_5 = { 440fb64c3580 4c8d05a73f0100 ba03000000 488bcf e8???????? 48ffc6 4883c702 }
+ $sequence_6 = { 4883ec38 ffca 744c 81faff1f0000 754b 33c0 4c8905???????? }
+ $sequence_7 = { e8???????? 8bf8 85c0 7907 b8c0feffff eb3f 0fb78394030000 }
+ $sequence_8 = { 83c702 3ac1 760a b8bafeffff e9???????? 7368 0fb78b94030000 }
+ $sequence_9 = { 488d15e98d0200 498bce 4c8bc0 e8???????? 8d7e3e 448be3 e9???????? }
condition:
- 7 of them and filesize <2318336
+ 7 of them and filesize <1400832
}
-rule MALPEDIA_Win_Milkmaid_Auto : FILE
+rule MALPEDIA_Win_Hesperbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7c60d500-9a52-5cea-8bfb-4d836c40072e"
+ id = "a7df8c05-0ba7-5df5-beac-3b2d7fa2a54e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.milkmaid"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.milkmaid_auto.yar#L1-L100"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hesperbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hesperbot_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "c4a5987f68f519192a013c67faec02935457872f835e55aadbf7cdc1a7483580"
+ logic_hash = "791429e92dde914e6ba42c9451f8338c991a26d1b1d12ebf3b674c1fb1ca0de1"
score = 75
quality = 75
tags = "FILE"
@@ -170870,30 +177972,32 @@ rule MALPEDIA_Win_Milkmaid_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7440 56 ff15???????? 8d4c2414 }
- $sequence_1 = { c68424dc28010002 e8???????? 8d4c2410 c68424dc28010001 }
- $sequence_2 = { 50 53 ff15???????? 8d4c2478 c68424dc28010002 }
- $sequence_3 = { 6a00 ff15???????? 6aff 8d4c2408 e8???????? 68???????? 8d4c2408 }
- $sequence_4 = { 895c2428 7513 8b5508 52 53 }
- $sequence_5 = { 8d442408 57 50 e8???????? 83c404 33db }
- $sequence_6 = { 8be9 896c2420 8a8528280100 84c0 7528 8b4d04 }
- $sequence_7 = { 51 8d8c2480000000 c68424e428010003 e8???????? b911000000 }
+ $sequence_0 = { 33f0 8b442440 0b442438 33cf 23442448 8b7c2444 8b5c2440 }
+ $sequence_1 = { f60602 740e 8bc6 e8???????? 85c0 7403 8326fd }
+ $sequence_2 = { 85f6 7454 817d0818040000 724b 57 8b3e }
+ $sequence_3 = { 59 59 85c0 741e ff7510 8b450c 8d4ddc }
+ $sequence_4 = { 8d45ec b975382414 46 e8???????? 8d45ec 6a10 50 }
+ $sequence_5 = { 03f3 837f1800 7639 8b0e 03cb e8???????? 3b4508 }
+ $sequence_6 = { 8b01 eb0b 8b5008 3b54240c }
+ $sequence_7 = { c9 c3 64a130000000 c3 55 8bec 83ec48 }
+ $sequence_8 = { 56 33f6 85c0 741a 0fb71471 83fa41 720c }
+ $sequence_9 = { 7308 e8???????? 33d2 42 }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Bitter_Rat_Auto : FILE
+rule MALPEDIA_Win_Ldr4_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "48708c16-f954-55fa-bcb7-85a1e067df06"
+ id = "ccab43fe-6663-5ab0-9f9d-f8403f8cf5d7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bitter_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bitter_rat_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ldr4"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ldr4_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "cf289391c2e8c84704b0f60fd200159e5bca809a29a5213fda197ca45567e744"
+ logic_hash = "78a7719e8cf0704f5c76c874cc1f41ecbae742c2d4a4b3ef70df1b0258c1fe71"
score = 75
quality = 75
tags = "FILE"
@@ -170907,32 +178011,32 @@ rule MALPEDIA_Win_Bitter_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bf4 6830750000 ff15???????? 3bf4 e8???????? e9???????? }
- $sequence_1 = { e8???????? 8d856cf8ffff 50 8b8da8feffff 51 e8???????? }
- $sequence_2 = { ff15???????? 3bf4 e8???????? 898574d8ffff 8bf4 8d858cd8ffff }
- $sequence_3 = { 83c408 8d85fcd8ffff 50 e8???????? 83c404 898558d9ffff 8b8558d9ffff }
- $sequence_4 = { ff15???????? 3bf4 e8???????? 8945a0 8bf4 6a01 }
- $sequence_5 = { eb12 8b45f4 83e801 8945f4 8b4de8 83c101 894de8 }
- $sequence_6 = { 89859cdbffff 8b8d9cdbffff 81e9d3070000 898d9cdbffff 83bd9cdbffff15 0f872b020000 8b959cdbffff }
- $sequence_7 = { 8d1c8d00124700 8bf0 83e61f c1e606 8b0b 0fbe4c3104 83e101 }
- $sequence_8 = { e8???????? 83c404 85c0 7420 e8???????? 8bf4 68d0070000 }
- $sequence_9 = { 3b05???????? 0f8688000000 a1???????? d1e0 3945f8 760b 8b4df8 }
+ $sequence_0 = { ff750c 0fb745f0 ff7508 50 0fb745ee 50 0fb745ec }
+ $sequence_1 = { c9 c20c00 56 6a2f ff74240c e8???????? 6a3f }
+ $sequence_2 = { 6a00 53 ff15???????? 837df800 0f8528010000 8d45f4 }
+ $sequence_3 = { 53 56 57 8945f8 33c0 33db 6a3e }
+ $sequence_4 = { 7506 6683f901 7723 83c720 66893b eb04 8365fc00 }
+ $sequence_5 = { 8d442410 50 8b442420 358555f261 50 8bc3 e8???????? }
+ $sequence_6 = { ff15???????? 8bf0 85f6 742c 33c9 85db 7622 }
+ $sequence_7 = { 8d8d00feffff 51 e8???????? 85c0 757e }
+ $sequence_8 = { 8d42f8 d1e8 3955fc 7c3e 85c0 }
+ $sequence_9 = { 0f84f1010000 8b3d???????? 50 ffd7 ff750c 8945e8 ffd7 }
condition:
- 7 of them and filesize <1130496
+ 7 of them and filesize <117760
}
-rule MALPEDIA_Win_Lurk_Auto : FILE
+rule MALPEDIA_Win_Lookback_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "67fdecf6-fece-5b5e-aa84-6821eaa887bc"
+ id = "5641bb4f-38a9-52e1-a4b7-204dc4620521"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lurk"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lurk_auto.yar#L1-L180"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lookback"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lookback_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "1d68cad8f119a971efeb0a8c788b3983d9ce03607f838f5c4c4d29840d917af1"
+ logic_hash = "68449af30b767d5c82dfe8271f4bbe8c83972fe98d28065e60e3bffd1a6dc166"
score = 75
quality = 75
tags = "FILE"
@@ -170946,38 +178050,32 @@ rule MALPEDIA_Win_Lurk_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff7508 ff15???????? 8b35???????? 50 ff7508 }
- $sequence_1 = { 8b4508 5b 5f 5e c9 c3 55 }
- $sequence_2 = { 8b4d08 8b5110 83c201 8b4508 895010 8b4dac 51 }
- $sequence_3 = { f3a5 66a5 33db 395d08 }
- $sequence_4 = { 72cc 33c9 8bc1 99 6a0b 5f f7ff }
- $sequence_5 = { c1ee03 33ce eb0e c1e60b 33ce 8bf0 c1ee05 }
- $sequence_6 = { 59 3bc7 7534 0fbe4203 }
- $sequence_7 = { 8b3d???????? 33f6 bb24080000 53 6a40 8975ec }
- $sequence_8 = { ff750c 83ceff ff7508 ff7510 e8???????? 83c418 85c0 }
- $sequence_9 = { ff750c 57 ff15???????? 85c0 7411 395dfc 750c }
- $sequence_10 = { 68???????? 8d85ecfeffff 50 ff15???????? 8d85ecfeffff 50 }
- $sequence_11 = { ebf8 56 8bf0 33c0 85d2 8bca 740c }
- $sequence_12 = { 8945fc 8b4d10 8b91a4000000 8955f8 837df800 7661 }
- $sequence_13 = { c9 c3 55 8bec 81ec08010000 6a35 6a40 }
- $sequence_14 = { 744d 56 8d4508 50 }
- $sequence_15 = { 83f866 7567 3bf0 7563 0fbe4205 50 e8???????? }
+ $sequence_0 = { 53 8944241a 57 66894c2416 89442422 8bfa }
+ $sequence_1 = { 8b7c241c 33ed 8b473c 8b443878 03c7 8b5024 }
+ $sequence_2 = { 55 8bec 51 53 c745fc00000000 b801000000 }
+ $sequence_3 = { c3 5e 5d 33c0 5b 81c410070000 c3 }
+ $sequence_4 = { 3c01 893d???????? 893d???????? 752e }
+ $sequence_5 = { c644240800 88442415 e8???????? 8d4c240c 89442408 51 }
+ $sequence_6 = { 8d5108 d1e8 85c0 7e33 }
+ $sequence_7 = { 74a7 8b06 85c0 757b }
+ $sequence_8 = { 52 8d442418 57 50 68???????? 57 57 }
+ $sequence_9 = { 55 8bec 51 53 c745fc00000000 b801000000 0fa2 }
condition:
- 7 of them and filesize <5316608
+ 7 of them and filesize <131072
}
-rule MALPEDIA_Win_Whitebird_Auto : FILE
+rule MALPEDIA_Win_Remy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "18c8f315-82f9-5211-979b-cd91dd0f89f6"
+ id = "7ce97943-cfc3-5429-92c7-f07c9ff48391"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.whitebird"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.whitebird_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.remy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.remy_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "9614af5c53f8ac08af22eb37dac785c96bbf80265ac7367d1874d42f77f5a2ec"
+ logic_hash = "8cc4f887faa36fa3ebf369fe88c2b140d588410f99b73c322f37daf8b5d5619a"
score = 75
quality = 75
tags = "FILE"
@@ -170991,32 +178089,32 @@ rule MALPEDIA_Win_Whitebird_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8a4302 84c0 7408 3c01 7404 }
- $sequence_1 = { 8a4301 3c01 7404 3c02 }
- $sequence_2 = { 8a4302 84c0 7408 3c01 7404 3c02 }
- $sequence_3 = { eb09 80f92f 0f95c1 80c13f }
- $sequence_4 = { 8a4302 84c0 7408 3c01 }
- $sequence_5 = { ffb5c0fbffff 8930 ff15???????? 01b5c4fbffff ff8dbcfbffff 75dd ffb5c0fbffff }
- $sequence_6 = { ff15???????? 488bcb ff15???????? b801000000 488b8c2480040000 4833cc e8???????? }
- $sequence_7 = { 8b4d08 836d0808 d3e3 095d0c 46 3bf7 72ec }
- $sequence_8 = { 488d542468 498bcd ffd0 3bc3 8bd0 7c28 8b442478 }
- $sequence_9 = { 4833c4 4889842450250000 418bf9 458be0 448bf2 89542454 4c8be9 }
+ $sequence_0 = { 83c404 3bc3 7420 50 8bc6 8d7c241c }
+ $sequence_1 = { 56 81c30f010000 53 e8???????? 8d46f0 }
+ $sequence_2 = { 3dc8000000 0f85c50b0000 6a28 8d742424 895c2424 895c2428 895c242c }
+ $sequence_3 = { 5d c3 8b7dfc 8d4fff 81f9ffff0000 7728 }
+ $sequence_4 = { 7451 8d4634 898638100000 8d8634100000 c70000100000 895d0c 895d08 }
+ $sequence_5 = { 51 8d570c 52 e8???????? 83c40c 8b4508 83c010 }
+ $sequence_6 = { 8b5604 2bc8 2bd0 c1f902 c1fa02 3bd1 }
+ $sequence_7 = { 8d8748100000 57 8908 8d4da4 51 8d55a0 52 }
+ $sequence_8 = { 8d4d90 e8???????? 83c41c c645fc02 895e40 8bff 8b4d94 }
+ $sequence_9 = { 50 ff15???????? 8b95b4feffff 52 ff15???????? 8b4df4 64890d00000000 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <507904
}
-rule MALPEDIA_Win_Kivars_Auto : FILE
+rule MALPEDIA_Win_Atharvan_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "81082c3d-5064-55a3-8cee-83fb88e85d6c"
+ id = "90143155-ec04-5a1a-8f1d-cad8e690d20c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kivars"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kivars_auto.yar#L1-L170"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atharvan"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.atharvan_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "57db268647853b0be399381edf4cd6dc1a86ac28f0c0a8c22aae4b45830a7fb0"
+ logic_hash = "4ab12aee6394d0021e81333c85382f01af297ccebc032a8d7f39b0ec61d7b92e"
score = 75
quality = 75
tags = "FILE"
@@ -171030,38 +178128,32 @@ rule MALPEDIA_Win_Kivars_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c705????????00000000 c644245423 c744245002000000 488d4c2450 e8???????? }
- $sequence_1 = { 8d542440 8944244c 894c243c 6a14 }
- $sequence_2 = { 8d8c247c010000 51 e8???????? 83c404 33c0 5f 5e }
- $sequence_3 = { 44894c2420 4c89442418 89542410 48894c2408 4881eca8000000 488b05???????? }
- $sequence_4 = { ff15???????? 8bc8 8d7308 83e908 8dbc2492000000 8bd1 }
- $sequence_5 = { 4889842470020000 ff15???????? 89842430020000 c784242002000001000000 c784242c02000002000000 c64424707d }
- $sequence_6 = { 755d 4c8b8424e0050000 488d942460020000 488d8c2450010000 e8???????? }
- $sequence_7 = { 4883c005 4889442428 488b842470100000 4883c009 }
- $sequence_8 = { 894c2430 89442444 894c2434 89442448 894c2438 8d542440 8944244c }
- $sequence_9 = { 488d942440010000 488d4c2430 e8???????? 8b442434 83e001 85c0 }
- $sequence_10 = { 50 8b4d18 51 8d5514 }
- $sequence_11 = { 7476 eb09 80fb3d 0f8489000000 0fbe5c2412 c0e202 8a5c1c14 }
- $sequence_12 = { 488bc8 ff15???????? 8b842460110000 ffc0 }
- $sequence_13 = { 83fffe 741b 83ffff 0f858c000000 8d8c247c010000 }
- $sequence_14 = { 8bf0 83c609 33ff 6a74 897c2414 e8???????? 83c404 }
- $sequence_15 = { 48894c2408 4881ec68030000 48c7842448030000feffffff 488d8c2430010000 e8???????? }
+ $sequence_0 = { 4c8d05ee7a0000 488b9540070000 488bce e8???????? 85c0 750b eb9e }
+ $sequence_1 = { 423a9401d4ab0100 7566 488b03 48ffc1 8a10 48ffc0 488903 }
+ $sequence_2 = { 498784f6105c0200 4885c0 7409 488bcb ff15???????? 4885db }
+ $sequence_3 = { 8d0480 03c0 442be8 0f84cffbffff 418d45ff 8b848228aa0100 }
+ $sequence_4 = { 750d 4c8bc6 e8???????? e9???????? 4c8bce 4c8d05e1dd0100 }
+ $sequence_5 = { 498bcf ff15???????? 498bcf ff15???????? 488b4c2440 4833cc e8???????? }
+ $sequence_6 = { b903000000 4c8d0564a10000 488d1565a10000 e8???????? }
+ $sequence_7 = { 498bcf ff15???????? 488bd8 eb02 33db 4c8d3d028cffff 4885db }
+ $sequence_8 = { 7528 48833d????????00 741e 488d0d943e0100 e8???????? 85c0 }
+ $sequence_9 = { 83f801 751f 488b0d???????? 488d1d356c0100 483bcb 740c }
condition:
- 7 of them and filesize <196608
+ 7 of them and filesize <348160
}
-rule MALPEDIA_Win_Hikit_Auto : FILE
+rule MALPEDIA_Win_Dadstache_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bd6e764b-576f-54ee-bfa6-5e7a42269dfd"
+ id = "1b258f10-8f88-5091-9d8a-b7cbb1e4a0e5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hikit"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hikit_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dadstache"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dadstache_auto.yar#L1-L168"
license_url = "N/A"
- logic_hash = "dc92a800adf1985c32a4ddd1d9a2bce0a144c5995b6902cad53971cf4e90fb53"
+ logic_hash = "77711feda2c16f34186a4f1ae2717975593af55ed7e01d177132f4e333f94d90"
score = 75
quality = 75
tags = "FILE"
@@ -171075,32 +178167,38 @@ rule MALPEDIA_Win_Hikit_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33c0 e9???????? 48 8d44244e 48 898424b8000000 48 }
- $sequence_1 = { 89442428 48 837c242800 747e 33c0 83f801 7444 }
- $sequence_2 = { c7432000000000 48 8b442430 48 83781800 741c 48 }
- $sequence_3 = { e8???????? 8bf8 85ff 7408 81ff20a00400 7508 8b06 }
- $sequence_4 = { 6a00 50 ff15???????? 85c0 0f84a3000000 33ff }
- $sequence_5 = { 8bd5 8bce e8???????? f7d8 1bc0 40 894608 }
- $sequence_6 = { 6689046e 8b2d???????? 53 ffd5 56 68???????? 8d4c2410 }
- $sequence_7 = { 8d05b2210000 48 89442428 eb0d 48 8b442428 }
- $sequence_8 = { 894120 48 8b4c2460 8b44240c 894104 48 8b4c2460 }
- $sequence_9 = { 4c 8d442478 baffff1f00 ff15???????? 898424b0000000 83bc24b000000000 7444 }
+ $sequence_0 = { 8d442414 50 6a1f ff35???????? }
+ $sequence_1 = { 8b470c 8bf9 31460c 0f1006 c7450c09000000 0f1145e8 }
+ $sequence_2 = { 85c0 7550 8b0d???????? 8b35???????? 85c9 7403 }
+ $sequence_3 = { 53 8d4d08 895d08 51 53 50 53 }
+ $sequence_4 = { 837c242c10 8d442418 51 0f4344241c }
+ $sequence_5 = { 8d5201 8842ff 83e901 75f2 8bd3 c1ea04 }
+ $sequence_6 = { 6aff 6a00 8d442438 c74424340f000000 50 }
+ $sequence_7 = { 6a1f ff35???????? ff15???????? a1???????? }
+ $sequence_8 = { 741b 8b45f0 47 83c628 3bf8 }
+ $sequence_9 = { 7405 8b4718 8901 8b731c 57 }
+ $sequence_10 = { 42 83c628 8955f0 3b55e4 0f8c66ffffff }
+ $sequence_11 = { 7325 8b7c240c 4a 03d7 8d4fff }
+ $sequence_12 = { 8b4485b0 85d2 8b56f8 7405 0d00020000 8d5de4 53 }
+ $sequence_13 = { e8???????? 85c0 741d 8bce e8???????? 8bce }
+ $sequence_14 = { c3 8b4e04 8d4604 8945fc 8b06 }
+ $sequence_15 = { 84c9 740e 3aca 74ef 0fb6c2 0fb6c9 }
condition:
- 7 of them and filesize <573440
+ 7 of them and filesize <580608
}
-rule MALPEDIA_Win_Woody_Auto : FILE
+rule MALPEDIA_Win_Ghole_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "35fc0a5e-5caa-5b81-a357-ce6a48801a6d"
+ id = "4005edf0-acd5-5930-97fb-055e6ab03b5d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.woody"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.woody_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ghole"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ghole_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "d359ba0a50d4da9f9c37f195345e1d8ee165deec7ea255ed2ce67ccf9ad5785a"
+ logic_hash = "a19f9cff11c120a5d0a63f0160508dc83f879d2586d9f0ffa0e72d02e6aa023f"
score = 75
quality = 75
tags = "FILE"
@@ -171114,34 +178212,34 @@ rule MALPEDIA_Win_Woody_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 59 7412 8d4604 50 8d85e4feffff }
- $sequence_1 = { 0f8501ffffff 53 ff15???????? a1???????? 85c0 7410 6860ea0000 }
- $sequence_2 = { 8975ec 3bce 8b35???????? 894ddc 0f86b1000000 8d580a 8b4df4 }
- $sequence_3 = { 8d8e10010000 c645fc01 e8???????? 8d8e18010000 c645fc02 e8???????? 8d8e20010000 }
- $sequence_4 = { 50 e8???????? 8b45f4 83c424 813800000080 7239 8b75c8 }
- $sequence_5 = { 59 5b 0f94c0 5f 5e c9 c20c00 }
- $sequence_6 = { 48 0f8592000000 6a00 6a00 6a00 ff15???????? }
- $sequence_7 = { 85db 7503 57 eb15 8d45fc 6a00 50 }
- $sequence_8 = { 8945e0 294de0 894d14 8b45e0 8b4d14 03c1 8d4db0 }
- $sequence_9 = { 3bcb 89442450 7412 8b8e0c010000 c74424540e000000 3bcb 7504 }
+ $sequence_0 = { 740d 8b55fc 48 8b45e8 89908c000000 48 8b55e0 }
+ $sequence_1 = { 3b45ec 7591 48 8b05???????? 48 8b00 8b15???????? }
+ $sequence_2 = { 89c7 e8???????? 85c0 0f85ac160000 8b850cfdffff 48 8d9518fdffff }
+ $sequence_3 = { 90 8b4dc8 8b55c4 48 8b5d98 48 8b4598 }
+ $sequence_4 = { 8910 48 8b45e8 48 83c018 48 8b55e8 }
+ $sequence_5 = { 85c0 7518 8b45e0 89c7 e8???????? 85c0 750a }
+ $sequence_6 = { 48 8b45e0 48 895010 48 8d55d4 48 }
+ $sequence_7 = { 894c2408 48 83ec78 c744242050000000 c744242403000000 48 8d0540feffff }
+ $sequence_8 = { 4c 8945c0 c745ec00000000 8b05???????? 85c0 750a b800000000 }
+ $sequence_9 = { 0f847d0f0000 48 8d95a0faffff 48 8d8520fdffff 48 89d6 }
condition:
- 7 of them and filesize <409600
+ 7 of them and filesize <622592
}
-rule MALPEDIA_Win_Red_Gambler_Auto : FILE
+rule MALPEDIA_Win_Lpeclient_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4317a3dc-c3fe-56b3-9554-1937ca266fd2"
+ id = "ff5559d0-76ba-5f50-8136-3eeb9fa351f1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.red_gambler"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.red_gambler_auto.yar#L1-L292"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lpeclient"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lpeclient_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "7119f21e00db57c2b9d697114a153bc44616294e27589a57d490b5463e3562f7"
+ logic_hash = "cc71b8a0d92e690c3547182b96989e3a466b7b3af36dfae852a2105f4c91b9a4"
score = 75
- quality = 71
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -171153,56 +178251,34 @@ rule MALPEDIA_Win_Red_Gambler_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 807e01a2 7535 807e02c3 752f 68???????? 68???????? ff15???????? }
- $sequence_1 = { 68???????? c745ece80f13fc ffd6 a3???????? }
- $sequence_2 = { 68ff000000 8d8df0fcffff 51 ff15???????? 85c0 }
- $sequence_3 = { 3bf1 72bf 5e 33c0 5b }
- $sequence_4 = { e8???????? 8bf8 83c404 83ffff 74e1 57 8d4c244c }
- $sequence_5 = { 8d4c2414 51 6a40 6a07 }
- $sequence_6 = { 68???????? 68???????? ffd6 5e 85c0 7505 }
- $sequence_7 = { 894dec 8955f0 8945f4 ff15???????? }
- $sequence_8 = { 2b2a bee7eee947 7c26 0e }
- $sequence_9 = { 8d4d98 51 ff15???????? 8d5598 52 8d8598fdffff }
- $sequence_10 = { 7456 7b78 cd50 d46e }
- $sequence_11 = { bc340e65bc 691fd8727fcf 14cf fd }
- $sequence_12 = { 9e e779 9e 54 }
- $sequence_13 = { 51 ff15???????? 83c414 6a00 6a00 8d9598fbffff }
- $sequence_14 = { ff15???????? 6800010000 8d8d98fdffff 51 8d9598feffff 52 }
- $sequence_15 = { 52 8d8598fdffff 50 68???????? }
- $sequence_16 = { 3c3d 9e e7bd e600 3e3e25162f062d }
- $sequence_17 = { 6a00 6a00 8d9598fbffff 52 68???????? 6a00 6a00 }
- $sequence_18 = { 50 4c 48 44 40 6c }
- $sequence_19 = { 6800010000 8d8dfcfdffff 51 6a00 }
- $sequence_20 = { 68???????? 8d8d98fbffff 68???????? 51 ff15???????? 83c414 }
- $sequence_21 = { 7c0e 07 642827 3ccf }
- $sequence_22 = { 8d9598feffff 52 ff15???????? 8d8594fbffff 50 8d4d98 51 }
- $sequence_23 = { 6800010000 8d85fcfeffff 50 6a00 ff15???????? }
- $sequence_24 = { 2f 74be 6f 665b }
- $sequence_25 = { 68???????? ff15???????? 8b7508 c7465c486b4000 83660800 }
- $sequence_26 = { 6888130000 ffd7 6800010000 8d95fcfeffff }
- $sequence_27 = { 55 8bec 8b4508 ff34c5d0814000 }
- $sequence_28 = { 8bf8 ffd3 8bd8 ffd7 8b3d???????? 6aff ffd7 }
- $sequence_29 = { 83f805 7d10 668b4c4310 66890c4580974000 40 ebe8 }
- $sequence_30 = { 6a5c 8d8dfcfeffff 51 ff15???????? }
- $sequence_31 = { 8bec 8b4508 33c9 3b04cd10804000 }
+ $sequence_0 = { f0ff03 8bce e8???????? eb2b 83f8ff 7526 4c8d2567f60000 }
+ $sequence_1 = { 33c0 80f90a 0f94c0 8944244c 488d054a1b0100 }
+ $sequence_2 = { 33c0 488bfe 66f2af 48f7d1 48ffc9 0f8456010000 }
+ $sequence_3 = { e8???????? c1eb03 85db 0f8e52130000 8b4c2450 8b542450 4c8d5e02 }
+ $sequence_4 = { 498be3 5f c3 48895c2410 4889742418 57 4881ec30020000 }
+ $sequence_5 = { 7406 81f1783bf682 48ffc7 48ffca 75e6 443bc1 410f94c5 }
+ $sequence_6 = { 0fb64c38ff 4132c8 880a 4183c10b 41ffc2 }
+ $sequence_7 = { 0bd8 418b0424 8d0c03 8bfb 448bc1 48c1e918 83e10f }
+ $sequence_8 = { 488d0d0f570100 ff15???????? 4c8b4308 488d1546e90000 488d0df74e0100 ff15???????? 488d0d9a480100 }
+ $sequence_9 = { 33db c74424646b000000 ff15???????? 448d4b01 448d4307 488d95a00b0000 }
condition:
- 7 of them and filesize <327680
+ 7 of them and filesize <289792
}
-rule MALPEDIA_Win_Lorenz_Auto : FILE
+rule MALPEDIA_Win_Huskloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "10a95bcc-414b-5fdc-ba6f-70234a4a7232"
+ id = "2b71c66f-6603-595c-99bb-89c942583260"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lorenz"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lorenz_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.huskloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.huskloader_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "b3150a02c51834520c50a8abe1ab216fe79abbf33e7abc68b4a01a1cc4acdf52"
- score = 60
- quality = 45
+ logic_hash = "0b5c5ed5027920c73090f364afb1f0be41c97145cf9de72e357bac2712d50fca"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -171214,32 +178290,32 @@ rule MALPEDIA_Win_Lorenz_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4de8 e8???????? 898568ffffff eb15 8b55fc 8b4258 8b4df4 }
- $sequence_1 = { c6412901 837df800 7423 8b55fc c7420c00000000 8b45f8 8b08 }
- $sequence_2 = { 8b8800080000 e8???????? 8945f0 8b4dfc 8b8900080000 e8???????? 8945e0 }
- $sequence_3 = { 8b55fc 8b4214 8b08 83e901 8b55fc 8b4214 8908 }
- $sequence_4 = { ff55e4 8b55f0 89828c000000 8b45f0 8b888c000000 51 8b4dec }
- $sequence_5 = { 8b4dfc e8???????? 85c0 7426 68???????? 68???????? 6a00 }
- $sequence_6 = { 8b4dfc e8???????? 8bc8 e8???????? 0fb6c8 85c9 7460 }
- $sequence_7 = { 8b4df8 83e904 e8???????? 8bc8 e8???????? 0fb6c8 85c9 }
- $sequence_8 = { 50 e8???????? 8945d8 837dd800 0f8445010000 8b4dd8 d1e1 }
- $sequence_9 = { 8b4dec 8b11 895004 8b45ec 8945e8 8b4de8 51 }
+ $sequence_0 = { 8bc7 83e03f 6bc838 8b0495e88d0110 }
+ $sequence_1 = { 59 e9???????? c745e003000000 e9???????? c745e4c05e0110 ebb8 d9e8 }
+ $sequence_2 = { 6a00 681f000f00 50 ff15???????? 85c0 }
+ $sequence_3 = { 740e 50 e8???????? 83a6e88d011000 59 83c604 81fe00020000 }
+ $sequence_4 = { 8d043b 8b3485601f0110 8d4601 8945fc 8a06 46 }
+ $sequence_5 = { 57 8bb81c060000 6a40 6800300000 56 6a00 ff15???????? }
+ $sequence_6 = { 85c0 7411 8b35???????? b98b010000 }
+ $sequence_7 = { 7420 6bc618 57 8db8288c0110 57 ff15???????? }
+ $sequence_8 = { 8b35???????? 85f6 7420 6bc618 57 8db8288c0110 57 }
+ $sequence_9 = { 0fb704850c3b0110 8d048508320110 50 8d8590faffff 03c7 50 }
condition:
- 7 of them and filesize <2254848
+ 7 of them and filesize <229376
}
-rule MALPEDIA_Win_Poortry_Auto : FILE
+rule MALPEDIA_Win_Headertip_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2cf345f6-6c65-548f-9e1e-6a67040df1b7"
+ id = "85fa344d-9a7e-5c14-be69-b6cdc5f3bcac"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poortry"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poortry_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.headertip"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.headertip_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "3ea6c4ba39d0058f0069c86346c9de0810387b212bcc1f7c57e5a516c20ae9ad"
+ logic_hash = "4007b2c1a7322a986be26c8429a660608ab1b4d0812b16868306a2db8cbc4c12"
score = 75
quality = 75
tags = "FILE"
@@ -171253,32 +178329,32 @@ rule MALPEDIA_Win_Poortry_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 41f7d2 f9 4181f80255e860 4181f225619d1f 41f7da f8 4181c2174c0279 }
- $sequence_1 = { 66f7c4e120 310424 5e 41f6c105 443af4 4863c0 f5 }
- $sequence_2 = { 66443bf0 56 0fbae697 c1e61f 311424 f9 660fbafec8 }
- $sequence_3 = { 41f7d3 4151 450aca 6641d3e1 44311c24 4180d1a2 }
- $sequence_4 = { f8 81f79e0d521c f8 d1cf 81c71d19891d f8 f5 }
- $sequence_5 = { 4151 41c0e937 4d0fb7c9 313424 450fc0c9 66450fabf1 66410fbae1d7 }
- $sequence_6 = { 4484c7 81c33f50eb3f 664181f8ec0e f7db 4153 311c24 6641c1c318 }
- $sequence_7 = { 56 401af3 40d2e6 66f7c4e120 310424 5e 41f6c105 }
- $sequence_8 = { 4123ea 48c1d5cd 5d f9 4d63c9 4881f98925786f 664185d3 }
- $sequence_9 = { f6dd 4159 4084ee 40b5c4 9d 66400fbecd 59 }
+ $sequence_0 = { 85c0 7434 8b07 ff4d08 03c3 56 }
+ $sequence_1 = { 57 ff15???????? 59 eb32 ffd6 }
+ $sequence_2 = { c645d274 c645d36f c645d472 c645d579 c645d657 885dd7 c645ac47 }
+ $sequence_3 = { c6458d75 c6458e65 c6458f72 c6459079 c645914f c6459270 c6459374 }
+ $sequence_4 = { 56 8d45ec 50 8d45f0 50 6813000020 }
+ $sequence_5 = { 894df4 8955fc f7c60000ffff 7513 81e6ffff0000 2b7010 }
+ $sequence_6 = { 03c6 ebea 56 8b742410 57 }
+ $sequence_7 = { 58 668945f8 6a32 58 668945fa 33c0 668945fc }
+ $sequence_8 = { ff15???????? a3???????? 3bc6 0f84c0000000 53 8d4df4 }
+ $sequence_9 = { 50 ff15???????? 83c414 56 b80013e084 50 56 }
condition:
- 7 of them and filesize <8078336
+ 7 of them and filesize <174080
}
-rule MALPEDIA_Win_Chinad_Auto : FILE
+rule MALPEDIA_Win_Socksbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "55179322-c960-5946-aa14-87280de490d7"
+ id = "9bcf8cfe-6674-56a4-ae23-27a14bd76431"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chinad"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chinad_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.socksbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.socksbot_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "f63725bd92056d22834dfb19b05368c2071df890649a72d3254d014778d263a0"
+ logic_hash = "751966a23ad60ac8819a9938a949afcb7d6a09a99a37898a0110d849f807b7bf"
score = 75
quality = 75
tags = "FILE"
@@ -171292,34 +178368,34 @@ rule MALPEDIA_Win_Chinad_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c7850cffffff00000000 eb55 c78550ffffffbc264300 8b9550ffffff 83c201 8995b4feffff 8b8550ffffff }
- $sequence_1 = { 8b85a8feffff 899485acfeffff e9???????? b904000000 6bd100 8b4508 8b0c10 }
- $sequence_2 = { 2bf8 8bc2 c1f819 03f0 897dec c1e019 }
- $sequence_3 = { 895de8 1bde 0145f4 8b75ac 119d7cffffff 8b5dec 81c300001000 }
- $sequence_4 = { 0fa4c119 c1ee07 c1e019 0bd1 0bf0 31b514fdffff }
- $sequence_5 = { 0fa4f701 6a13 03f6 03b55cffffff 89b560ffffff 137dcc 81c600000001 }
- $sequence_6 = { c1c802 33c8 8b85d4feffff 8bd8 03ca 2385d8feffff }
- $sequence_7 = { 81d7745dbe72 019d14fdffff 11bd38fdffff 33d2 0facc81c c1e604 }
- $sequence_8 = { 8b4e24 83c40c c1e903 b838000000 83e13f 83f938 7205 }
- $sequence_9 = { b894280000 e8???????? a1???????? 33c5 8945fc c78570d7ffff80280000 8d8570d7ffff }
+ $sequence_0 = { 6a50 ff7508 33f6 8975fc e8???????? 8bd8 59 }
+ $sequence_1 = { 59 e9???????? 55 8bec ff4d0c 7509 ff7508 }
+ $sequence_2 = { 46 8a1c39 41 3b4d0c 7cce 5f 8935???????? }
+ $sequence_3 = { 6a00 ff7508 6a03 e8???????? 83c410 ff7704 }
+ $sequence_4 = { 48 741b 48 7536 53 }
+ $sequence_5 = { e8???????? 8bd8 8b45fc 8945f0 83c008 }
+ $sequence_6 = { 8b75fc 53 ff15???????? 57 e8???????? }
+ $sequence_7 = { 75ed ff7508 6bc94c 8b5dfc 03cf 51 53 }
+ $sequence_8 = { 8a0c37 880e 4a 75f7 }
+ $sequence_9 = { 81c60c000100 4b 75d2 68???????? ff15???????? a0???????? }
condition:
- 7 of them and filesize <598016
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Neutrino_Auto : FILE
+rule MALPEDIA_Win_Ryuk_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b9eb1524-9975-578b-ab6d-93138480d1f6"
+ id = "129184de-8948-5274-9e65-221045ceab9c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.neutrino"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.neutrino_auto.yar#L1-L324"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ryuk_stealer_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "b8cd6770a3479380c0f958a2776eccb26f589975e6ef7e101cff7469e248afc4"
- score = 60
- quality = 43
+ logic_hash = "32617ac72ab27e6e0bdc0cedf044a04c83b7c2ead314f2e254d4a430611a1927"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -171331,57 +178407,34 @@ rule MALPEDIA_Win_Neutrino_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? c1e010 50 ff15???????? }
- $sequence_1 = { 50 6a0b 6a07 e8???????? }
- $sequence_2 = { 50 6a05 6a03 e8???????? }
- $sequence_3 = { 85c9 7439 8b550c 8955fc 8b45fc 0fbe08 85c9 }
- $sequence_4 = { 0fbe02 85c0 7447 8b4df4 0fbe11 8b45fc 0fbe08 }
- $sequence_5 = { 0404 0404 0404 0402 0202 0202 }
- $sequence_6 = { 8b4d0c 894dfc 8b55f4 83c201 8955f4 ebaf 8b45f4 }
- $sequence_7 = { 0404 0404 010404 0202 }
- $sequence_8 = { 020402 0404 0404 0404 0404 0404 0403 }
- $sequence_9 = { 51 0fb655e7 52 8b45e0 50 e8???????? }
- $sequence_10 = { 0fbe08 85c9 741b 8b55fc 0fbe02 8b4df8 0fbe11 }
- $sequence_11 = { 894dfc 8b55fc 0fbe02 85c0 750f 8b4d0c 894dfc }
- $sequence_12 = { 6a00 ff15???????? 6880000000 ff15???????? }
- $sequence_13 = { 010404 0202 020402 0404 }
- $sequence_14 = { e9???????? 6a01 ff15???????? 85c0 }
- $sequence_15 = { 52 ff15???????? 83f8ff 7504 32c0 eb02 b001 }
- $sequence_16 = { 894d08 0fb6550c 83fa01 7509 8b4508 83c001 894508 }
- $sequence_17 = { 7407 814a1800300000 f645fe01 0f8494020000 834a1801 8b45f4 }
- $sequence_18 = { 6a1c 5b 8d4de0 51 50 895de0 ff15???????? }
- $sequence_19 = { 8a00 ff45f4 8b7218 8ad8 c0eb06 885dfc }
- $sequence_20 = { 7354 8b3b 0fb6f2 6a05 58 2bc6 8d1437 }
- $sequence_21 = { 51 ff35???????? c7460480000000 ff15???????? 8906 }
- $sequence_22 = { 33d2 81e100f0ffff eb08 3bc1 7409 8bd0 }
- $sequence_23 = { f645fe02 740a 834a1804 8a03 884210 43 f645fe40 }
- $sequence_24 = { 83c120 81fae00f0000 76ea 8b0d???????? 8908 a3???????? 5f }
- $sequence_25 = { 8d85b8feffff 50 68???????? ff15???????? 8945fc }
- $sequence_26 = { 83c40c 6804010000 8d85f8fdffff 50 }
- $sequence_27 = { 7507 68???????? eb05 68???????? 50 ff510c }
- $sequence_28 = { 7522 be???????? ff15???????? 57 8906 ff15???????? 83c604 }
- $sequence_29 = { 7412 68???????? 50 ff15???????? f7d8 1bc0 }
- $sequence_30 = { 57 33ff 393d???????? 7522 be???????? }
- $sequence_31 = { ff15???????? 50 ff15???????? 837dfc00 0f95c0 c9 }
- $sequence_32 = { ff750c ff7508 ff15???????? 83f8ff 0f95c0 }
+ $sequence_0 = { 7410 83ff01 755d 8bcb }
+ $sequence_1 = { ff15???????? 33ff 0fb60437 50 }
+ $sequence_2 = { 75f5 2bd1 8d8db4fdffff d1fa 8d7102 }
+ $sequence_3 = { 50 e8???????? 83c40c ff15???????? 33d2 b910270000 }
+ $sequence_4 = { 83ff01 755d 8bcb e8???????? }
+ $sequence_5 = { 50 ff15???????? 8bf0 ff15???????? 85c0 7518 }
+ $sequence_6 = { 83ff01 755d 8bcb e8???????? 3bc7 }
+ $sequence_7 = { 99 b9a0860100 f7f9 81c2f8240100 52 ff15???????? }
+ $sequence_8 = { 7560 8d85b4fdffff 68???????? 50 }
+ $sequence_9 = { ff15???????? 8d442454 50 ff15???????? 50 }
condition:
- 7 of them and filesize <507904
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Sienna_Purple_Auto : FILE
+rule MALPEDIA_Win_Silence_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cf85ec2b-384f-56db-af6a-79031e73a14e"
+ id = "f44b3bc4-8edd-502b-bd51-3105b7335797"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sienna_purple"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sienna_purple_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.silence"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.silence_auto.yar#L1-L413"
license_url = "N/A"
- logic_hash = "ba62dd8b8de50fe0a193f425d94a0b3b25a4b9e54845758b6f1fb176e28dc859"
+ logic_hash = "c771c849ed5f5e02e308e7f1e45bb9b0766da378108a761728400240a10fde1e"
score = 75
- quality = 75
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -171393,32 +178446,69 @@ rule MALPEDIA_Win_Sienna_Purple_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 8d4e08 c645fc02 c706???????? e8???????? 8bc6 8b4df4 }
- $sequence_1 = { b8e5040000 5e 5d c3 68???????? 56 e8???????? }
- $sequence_2 = { e8???????? 50 8d8f84040000 e8???????? b301 8d4db0 c745fcffffffff }
- $sequence_3 = { 8d5729 f30f7f4728 f30f6f4310 f30f7f4738 f30f6f4320 f30f7f4748 f30f6f4330 }
- $sequence_4 = { ff5014 8d8570ffffff 8bcf 50 68???????? e8???????? 8bce }
- $sequence_5 = { f30f6f40f0 660fefc8 f30f7f48f0 3bd1 72c4 8bb540ffffff 8b8d6cffffff }
- $sequence_6 = { c1e81f 23c8 8b421c 35ff000000 48 c1e81f 23c8 }
- $sequence_7 = { c7072e000000 e9???????? 80be2501000000 7418 8b8d84fdffff e8???????? 50 }
- $sequence_8 = { eb09 50 56 8bcb e8???????? 8b4df4 64890d00000000 }
- $sequence_9 = { c1c70a 0bc8 8d83dcbc1b8f 034db4 03c1 8b5de8 c1c005 }
+ $sequence_0 = { 8d45fc 50 6a00 6a00 68???????? c745fc00000000 }
+ $sequence_1 = { 740a 8a4801 40 84c9 75f4 eb05 803800 }
+ $sequence_2 = { 8b4908 e8???????? cc 8325????????00 c3 6a08 }
+ $sequence_3 = { 683f020f00 6a00 68???????? 6801000080 ff15???????? 68???????? }
+ $sequence_4 = { 3b0d???????? 7502 f3c3 e9???????? e8???????? e9???????? 6a14 }
+ $sequence_5 = { 68???????? ffd6 8b45fc 85c0 }
+ $sequence_6 = { ff15???????? 6a00 6800000004 6a00 }
+ $sequence_7 = { 46 56 8d85f8feffff 50 }
+ $sequence_8 = { 6801000080 ff15???????? 56 8d85f8feffff }
+ $sequence_9 = { 8bd8 68???????? 53 ff15???????? 6a00 }
+ $sequence_10 = { 8b35???????? 6a00 6a00 6a00 6a00 8d45fc 50 }
+ $sequence_11 = { 6a00 8bf8 6a00 57 ff15???????? 8d45fc 50 }
+ $sequence_12 = { 40 84c9 75f4 eb0d 803800 7408 }
+ $sequence_13 = { 803800 7408 8a5a01 42 84db }
+ $sequence_14 = { 5e 5b 5d c3 c60200 42 }
+ $sequence_15 = { 8d85b8f7ffff 50 6800080000 8d85bcf7ffff }
+ $sequence_16 = { 8b85b8f7ffff 85c0 75b6 ffb5acf7ffff }
+ $sequence_17 = { 83c41c 895ef8 897ef0 5b 5f }
+ $sequence_18 = { 8bf9 e8???????? ff37 8b35???????? }
+ $sequence_19 = { ff501c 8b17 8bcf ff5210 8b17 }
+ $sequence_20 = { 7412 8b01 52 8d95f0fdffff 52 ff10 }
+ $sequence_21 = { 8d8dfcfbffff 51 ffb5f0fbffff 8bcb ff5038 }
+ $sequence_22 = { 0346f4 57 ff7508 50 e8???????? 83c40c }
+ $sequence_23 = { 03d7 3b56f0 7611 8b46ec }
+ $sequence_24 = { 85c9 7408 8b06 51 8bce ff501c }
+ $sequence_25 = { d3e0 0fb6c8 8b05???????? d3e0 }
+ $sequence_26 = { ff15???????? ba180c0000 b940000000 ff15???????? }
+ $sequence_27 = { ff15???????? 488d542430 488d8c2440020000 ff15???????? }
+ $sequence_28 = { 8b05???????? d3e0 8b0d???????? 03c8 }
+ $sequence_29 = { e8???????? ba00040000 b940000000 ff15???????? }
+ $sequence_30 = { ff15???????? 41b804010000 488d542430 488d4c2430 ff15???????? 85c0 }
+ $sequence_31 = { d3f8 0fb60d???????? d3e0 85c0 }
+ $sequence_32 = { 99 83e203 03c2 c1f802 89442440 }
+ $sequence_33 = { ff15???????? c20800 53 8b1d???????? 57 0f57c0 }
+ $sequence_34 = { 5e 85c0 7507 68???????? ffd7 5f }
+ $sequence_35 = { 7507 68???????? ffd7 6a00 6a00 6a01 6a00 }
+ $sequence_36 = { 750e 68???????? ff15???????? c20800 }
+ $sequence_37 = { 8d0441 33d2 b905000000 f7f1 }
+ $sequence_38 = { c705????????00000000 c705????????00000000 ffd3 8b3d???????? 85c0 7507 }
+ $sequence_39 = { 68???????? ff15???????? a3???????? 85c0 750e 68???????? }
+ $sequence_40 = { 8bec ff4d08 755d 833d????????04 7554 }
+ $sequence_41 = { c705????????04000000 ff15???????? 85c0 750b 68???????? ff15???????? }
+ $sequence_42 = { ff15???????? 68c0d40100 ff15???????? e9???????? }
+ $sequence_43 = { 03048db0354200 50 ff15???????? 5d }
+ $sequence_44 = { 0305???????? 0b45f0 3305???????? a3???????? }
+ $sequence_45 = { 03048db0354200 eb02 8bc6 80782900 }
+ $sequence_46 = { 03048db0354200 eb05 b8???????? f6402820 }
condition:
- 7 of them and filesize <2930688
+ 7 of them and filesize <70128640
}
-rule MALPEDIA_Win_Rover_Auto : FILE
+rule MALPEDIA_Win_Synflooder_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1dedd2f8-89d8-5b82-937e-e4187a543962"
+ id = "355e06d2-d319-5e82-9247-ae8f46ddbac0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rover"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rover_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.synflooder"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.synflooder_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "6367e2cdf56f70609689c8633064a076a7b96ec3143349e9ae15d5e0ca66c168"
+ logic_hash = "95bdce90d0fd23dc18864dd54db497d62acdb308355c11b707eb697b526800c1"
score = 75
quality = 75
tags = "FILE"
@@ -171432,32 +178522,32 @@ rule MALPEDIA_Win_Rover_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6800120000 885c247b ff15???????? 85c0 0f8422010000 8b35???????? 8d542460 }
- $sequence_1 = { ff15???????? 8d4c2404 c684249c00000000 ff15???????? 8d8c24a4000000 c784249c000000ffffffff }
- $sequence_2 = { 83ed01 0f8464010000 83ed04 0f845b010000 83bba402000000 8b6a28 896c240c }
- $sequence_3 = { 85db 0f856f030000 8b471c 85c0 7421 50 8d442414 }
- $sequence_4 = { 8bf0 83c404 3bf3 7537 a1???????? 8b4824 8d542438 }
- $sequence_5 = { 50 8b442458 68???????? 50 e8???????? 83c410 85c0 }
- $sequence_6 = { 8b8fb0050000 8d6b50 89442410 8987b0050000 8b85a8000000 8bd0 80e215 }
- $sequence_7 = { 83e802 7426 83e815 740f 683f270000 ff15???????? 83c8ff }
- $sequence_8 = { 83c40c c3 6a2f 57 ffd6 83c408 85c0 }
- $sequence_9 = { 57 e8???????? 56 e8???????? 83c40c c744242c04000000 }
+ $sequence_0 = { ff35???????? ff15???????? 85c0 7442 8b7df4 85ff }
+ $sequence_1 = { 83e61f 8d3c8520fc4000 8b07 c1e606 }
+ $sequence_2 = { 750b 56 e8???????? 59 85c0 7407 }
+ $sequence_3 = { e8???????? 83c408 8b542420 52 68???????? e8???????? }
+ $sequence_4 = { 53 56 57 7408 33c0 40 e9???????? }
+ $sequence_5 = { c7465c20b04000 83660800 33ff 47 }
+ $sequence_6 = { 55 8bec 81ec98050000 a1???????? 33c5 8945fc 8d8568faffff }
+ $sequence_7 = { 8bf0 89742414 83feff 7524 68???????? e8???????? 83c404 }
+ $sequence_8 = { ff15???????? 83f8ff 7524 68???????? e8???????? 83c404 }
+ $sequence_9 = { 33db 85db 7466 8d45f4 50 ff75f8 53 }
condition:
- 7 of them and filesize <704512
+ 7 of them and filesize <163840
}
-rule MALPEDIA_Win_Gaudox_Auto : FILE
+rule MALPEDIA_Win_Nimbo_C2_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1eecaa5e-0125-509a-9dab-e8ce2f4b63fe"
+ id = "89998246-cbee-55ef-81ba-46cc3fd70d1a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gaudox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gaudox_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nimbo_c2"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nimbo_c2_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "7eb2982f230b20ae36bb88377d3dc0b3ae4c2623263daca498d5416d3995e6aa"
+ logic_hash = "8c39050d61f289d245bf6365ffd110e7ad73787b347fdf5526ee916f50a01d10"
score = 75
quality = 75
tags = "FILE"
@@ -171471,32 +178561,32 @@ rule MALPEDIA_Win_Gaudox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7403 c60000 8bce e8???????? 8b45f8 85c0 7410 }
- $sequence_1 = { 837df000 0f849a000000 6a00 8d95c4feffff 52 b804000000 6bc800 }
- $sequence_2 = { 8d8c2458030000 e8???????? 8bf0 85f6 0f88df000000 a1???????? 8d8c2450030000 }
- $sequence_3 = { a1???????? 57 ffb0b8000000 eb26 8bb8b0000000 83ff54 }
- $sequence_4 = { 13c9 66f3ab 8b450c 03f0 8bc6 5f 5e }
- $sequence_5 = { 56 8b7014 81feb8000000 7729 68???????? b9???????? e8???????? }
- $sequence_6 = { ff75fc 8bf0 6a08 6a00 e8???????? 85f6 782a }
- $sequence_7 = { 8b45f4 8b5018 85d2 74ec 6a00 6a00 68d113282e }
- $sequence_8 = { 57 85c0 0f84ad010000 85d2 0f84a5010000 8b7d08 85ff }
- $sequence_9 = { 8d442460 50 6a27 6a00 e8???????? 85c0 781c }
+ $sequence_0 = { 741a 488b4960 ba22000000 e8???????? 488d4b60 4889c2 e8???????? }
+ $sequence_1 = { 7434 498b07 b902000000 4899 48f7f9 498b17 31c9 }
+ $sequence_2 = { e8???????? 4883c470 5b 5e 5f 415c 415d }
+ $sequence_3 = { 488b4c2428 84c0 740f 4883c430 415c 415d 415e }
+ $sequence_4 = { 4889f1 4889442420 e8???????? 48ff4608 4883c440 5b 5e }
+ $sequence_5 = { 7d45 eb49 488b4a10 488b5218 48894810 4889d9 48895018 }
+ $sequence_6 = { 4d8b2c24 31ff 4c39ef 7de9 498b54fc10 4889f1 48ffc7 }
+ $sequence_7 = { e8???????? 31d2 4c89e1 498907 e8???????? 4c89e9 488906 }
+ $sequence_8 = { c1fa0c 83e23f 83ca80 885012 89da 83e33f c1fa06 }
+ $sequence_9 = { 807c33102d 0f94c0 48ffc6 ebd4 4c89e0 4883c428 5b }
condition:
- 7 of them and filesize <155648
+ 7 of them and filesize <1141760
}
-rule MALPEDIA_Win_Nokki_Auto : FILE
+rule MALPEDIA_Win_Tinymet_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "02120b2b-1366-521d-89f5-fe0cec012c20"
+ id = "a6e31398-6f4b-5407-9dd6-cb73f522ca46"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nokki"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nokki_auto.yar#L1-L156"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinymet"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tinymet_auto.yar#L1-L104"
license_url = "N/A"
- logic_hash = "e29386a66940956320f6fdb11113fafeb375dcdfcfa05926d55033ad903bf7f3"
+ logic_hash = "08c0faf51104b44743d7b565703ff1ffe8a5a90a54db8ef44d5f821b9f74a23a"
score = 75
quality = 75
tags = "FILE"
@@ -171510,36 +178600,30 @@ rule MALPEDIA_Win_Nokki_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 33d2 68ce070000 52 }
- $sequence_1 = { e8???????? 33c9 68ce070000 51 }
- $sequence_2 = { 8b420c 898d08f8ffff b9???????? 89b518f8ffff ffd0 }
- $sequence_3 = { 884c0204 8b06 8bd0 83e01f c1fa05 8b149580054100 c1e006 }
- $sequence_4 = { 8d8daaddffff 51 668985a8ddffff e8???????? 6800010000 8d95f0feffff 6a00 }
- $sequence_5 = { 6a01 6a00 ff15???????? 8bf8 85ff 0f848a000000 6a00 }
- $sequence_6 = { 51 8d9520f8ffff 52 e8???????? 83c408 85c0 744a }
- $sequence_7 = { ffd6 57 ffd6 68a0bb0d00 }
- $sequence_8 = { 8a8c181d010000 888888054100 40 ebe6 ff35???????? }
- $sequence_9 = { 33ff ffb7d4ec4000 ff15???????? 8987d4ec4000 83c704 83ff28 }
- $sequence_10 = { 83c40c 6804010000 8d95f4fdffff 52 6a00 ffd6 }
- $sequence_11 = { 8d7810 89bd68e8ffff 8b8d60e8ffff 8b9564e8ffff 8d856ce8ffff 50 }
- $sequence_12 = { 8bce e8???????? 33d2 6806020000 52 8d85eafdffff 50 }
- $sequence_13 = { 8d8df4fdffff 51 ffd3 8d95f4fdffff 68???????? }
+ $sequence_0 = { 68???????? e9???????? 8d45ec 6a10 50 }
+ $sequence_1 = { 8bf0 83feff 751b 68???????? e9???????? ff15???????? }
+ $sequence_2 = { 56 ff15???????? 8b4df8 03d9 85c0 75df 8bc7 }
+ $sequence_3 = { 6a00 ff35???????? ff35???????? e8???????? 83c40c a3???????? ffd0 }
+ $sequence_4 = { 8bec 81eca4010000 8d855cfeffff 53 }
+ $sequence_5 = { 6a3e 59 f7f1 8a821c104000 88041f 47 3bfe }
+ $sequence_6 = { 741d 48 7416 68???????? e8???????? }
+ $sequence_7 = { 56 57 6a5c ff30 e8???????? }
condition:
- 7 of them and filesize <454656
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Sierras_Auto : FILE
+rule MALPEDIA_Win_Acbackdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "605d6eab-f109-574e-b05c-a9ae83591a9c"
+ id = "3b37a750-d7e0-5ba6-b796-2dbd4d0ee414"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sierras"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sierras_auto.yar#L1-L167"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acbackdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.acbackdoor_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "a564c7fabb45cfabecce73bb6168ff37faec379b0995b89fe8defbd9d38cf80c"
+ logic_hash = "429f71da1516445c35871fa605cbaf3bc00568c9cb40515ab43ec3dc7a2d0a3f"
score = 75
quality = 75
tags = "FILE"
@@ -171553,38 +178637,32 @@ rule MALPEDIA_Win_Sierras_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f3a4 8d8c2424050000 8d942430080000 51 }
- $sequence_1 = { 56 8bf1 57 68???????? 8d4604 50 }
- $sequence_2 = { 50 8d45e0 50 e8???????? eb0f 8b4dec }
- $sequence_3 = { e8???????? 50 8d442430 50 8d8c24ec000000 }
- $sequence_4 = { 0f8480030000 8b4dfc ff4df8 0fb611 8bcf }
- $sequence_5 = { 7507 e8???????? eb05 e8???????? 0175f0 }
- $sequence_6 = { 8bf1 e8???????? 8b8698010000 5e }
- $sequence_7 = { 8bc8 83e103 f3a4 8bbc2410040000 }
- $sequence_8 = { 03fb 3b7d10 72b0 8b5df0 834dfcff 8d4de0 }
- $sequence_9 = { 8bf1 33db 6a01 6a78 }
- $sequence_10 = { f2ae f7d1 2bf9 8d942480000000 8bf7 8bd9 8bfa }
- $sequence_11 = { 8bf1 e8???????? 8b8608010000 5e c3 56 }
- $sequence_12 = { 397d08 897dfc 0f8cc0000000 837d0801 7e58 }
- $sequence_13 = { c7401880dd4000 e9???????? 83e00f c70613000000 894648 8b4648 85c0 }
- $sequence_14 = { 58 0fb688c88c4000 6683bc8e7e0a000000 7506 }
- $sequence_15 = { 3bf8 7cce 8b442418 83c520 40 83f803 89442418 }
+ $sequence_0 = { ba04000000 e9???????? 8b542448 8b4c244c 8b742440 89542420 894c2424 }
+ $sequence_1 = { ebbd 8b442440 890424 ff15???????? 83ec04 89c3 83c42c }
+ $sequence_2 = { c744240c76070000 c7442408???????? c744240404000000 892c24 e8???????? 8b442438 892c24 }
+ $sequence_3 = { 8b7904 895c2408 894c2404 890424 e8???????? 8b4c243c 0fb64500 }
+ $sequence_4 = { e8???????? 85c0 7e06 83c414 5b 5e c3 }
+ $sequence_5 = { e8???????? 8b06 8b5054 85d2 0f8415fdffff 8b4050 85c0 }
+ $sequence_6 = { c744241087934a00 c744240cc8000000 c7442408???????? c744240401000000 892c24 e8???????? 8b85c4000000 }
+ $sequence_7 = { 89c8 8b4c2430 31de 8b5c2434 8987d0000000 894f50 895f54 }
+ $sequence_8 = { e8???????? 8b83c4000000 c783cc00000004000000 c783c800000016000000 c60000 891c24 e8???????? }
+ $sequence_9 = { e8???????? 8bbc241c020000 8d742434 31db 85ff 7e1e 8b86f0010000 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <1704960
}
-rule MALPEDIA_Win_Necurs_Auto : FILE
+rule MALPEDIA_Win_Kgh_Spy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3d1b7316-0e79-5ade-97ef-8f3ac3ffb54d"
+ id = "95e1000f-6599-59f6-ad77-7fb1f63fc7e2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.necurs"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.necurs_auto.yar#L1-L159"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kgh_spy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kgh_spy_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "75c1414f6695a00e2fea038874de3164067ad0287567965dcfd36d5ca522d078"
+ logic_hash = "c99afdfd1b207e301e0a54b515065ba98af784202a9cd5e6f9a55bcba5a38dab"
score = 75
quality = 75
tags = "FILE"
@@ -171598,38 +178676,32 @@ rule MALPEDIA_Win_Necurs_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 13f2 a3???????? 8935???????? 890d???????? 8bc1 5e }
- $sequence_1 = { 030d???????? a3???????? a1???????? 13f2 a3???????? }
- $sequence_2 = { 13f2 33d2 030d???????? a3???????? }
- $sequence_3 = { 8bc2 034508 5e 5d c3 55 }
- $sequence_4 = { 03c8 a1???????? 13f2 33d2 }
- $sequence_5 = { 56 8bf2 ba06e0a636 f7e2 }
- $sequence_6 = { 397508 7604 33c0 eb12 }
- $sequence_7 = { 2b7508 33d2 46 f7f6 8bc2 034508 }
- $sequence_8 = { 8d85ecfbffff 57 50 e8???????? 83c410 }
- $sequence_9 = { 33d7 33c1 52 50 }
- $sequence_10 = { 6a7d 50 ffd6 59 }
- $sequence_11 = { 8bc1 0bc7 7409 8bc1 8bd7 e9???????? }
- $sequence_12 = { 57 57 8d8574ffffff 50 }
- $sequence_13 = { 6a7b 50 ffd6 8bf8 59 59 }
- $sequence_14 = { 53 ff15???????? 59 33c0 5e }
- $sequence_15 = { a1???????? 33d2 f7f1 ff05???????? }
+ $sequence_0 = { 488b442428 8b4c2430 894808 e9???????? 4883c458 5f }
+ $sequence_1 = { 75e2 488b842498000000 89442460 8b442468 8b4c2460 488b542470 4803d1 }
+ $sequence_2 = { 488d8c24b0000000 ff15???????? 85c0 0f8547010000 0fb705???????? }
+ $sequence_3 = { 488d8424300a0000 4889842488000000 48c7442450ffffffff 48ff442450 }
+ $sequence_4 = { 488b4c2468 803c0800 75e8 488b442468 488d8c24c0000000 48898c2498000000 48c7442470ffffffff }
+ $sequence_5 = { f3aa 488d4c2428 ff15???????? 0fb7442428 83f809 740a 0fb7442428 }
+ $sequence_6 = { 488d8424f0030000 488bf8 33c0 b908020000 f3aa 4c8d0df7e30000 }
+ $sequence_7 = { 4885c0 7403 f0ff00 488d4128 41b806000000 488d15b4a30000 483950f0 }
+ $sequence_8 = { 8bc8 e8???????? 48898424d8000000 48c744242000000000 4c8d8c2470010000 448b442468 }
+ $sequence_9 = { 488d1dddab0000 483bcb 740c e8???????? }
condition:
- 7 of them and filesize <475136
+ 7 of them and filesize <207872
}
-rule MALPEDIA_Win_Gopuram_Auto : FILE
+rule MALPEDIA_Win_Session_Manager_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "886a3e56-99e6-5544-870d-cee2f3bf23a6"
+ id = "dc2cef80-2dcf-5809-93bd-82c69da769f0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gopuram"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gopuram_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.session_manager"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.session_manager_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "4e587acafeaded148024e517c8ecf7276743814969e25e84b3cedf8d114b44f9"
+ logic_hash = "603fcab78a4336ae9ff58b2ce6e64cc670272e944fe82c789ba11945e145dd5d"
score = 75
quality = 75
tags = "FILE"
@@ -171643,34 +178715,34 @@ rule MALPEDIA_Win_Gopuram_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 48894308 4885c0 7412 418d562f 488bc8 e8???????? }
- $sequence_1 = { 448bfb 48895dc7 8bcb 48895d9f 48895db7 48895d97 48895da7 }
- $sequence_2 = { 8bc1 83e010 c1e804 898508010000 f6c104 7507 f6c108 }
- $sequence_3 = { e8???????? eb21 c7442420210e0480 41b99e100000 4c8d05938b0600 8bd7 488bce }
- $sequence_4 = { ff05???????? b801000000 4883c428 c3 ff0d???????? 751a 488b0d???????? }
- $sequence_5 = { e9???????? 488b0d???????? 488b01 ff90f8000000 83f805 0f84e1fdffff 488b0d???????? }
- $sequence_6 = { 66094354 8b8597000000 83c0fc 83f801 0f8755010000 488b742448 418bf9 }
- $sequence_7 = { 89543104 488d051c8b0300 48898698040000 4889aea0040000 4889aea8040000 4889aeb0040000 488d8eb8040000 }
- $sequence_8 = { 890d???????? c705????????09000380 8bcf 488d05ce350900 6690 3b70fc 7508 }
- $sequence_9 = { bf01000000 e9???????? 488b0d???????? 488b01 ff90f8000000 83f805 7463 }
+ $sequence_0 = { 4c89b848240000 4c89b850240000 4c89b858240000 4c89b860240000 4c89b868240000 4c89b870240000 }
+ $sequence_1 = { 4c8d35fb2d0100 83e63f 488beb 48c1fd06 48c1e606 498b04ee }
+ $sequence_2 = { 4c89b838060000 4c89b840060000 4c89b848060000 4c89b850060000 4c89b858060000 4c89b860060000 4c89b868060000 }
+ $sequence_3 = { 4c89b8100b0000 4c89b8180b0000 4c89b8200b0000 4c89b8280b0000 4c89b8300b0000 4c89b8380b0000 }
+ $sequence_4 = { 4c89b8c8180000 4c89b8d0180000 4c89b8d8180000 4c89b8e0180000 4c89b8e8180000 4c89b8f0180000 }
+ $sequence_5 = { 4c89b890030000 4c89b898030000 4c89b8a0030000 4c89b8a8030000 4c89b8b0030000 4c89b8b8030000 4c89b8c0030000 }
+ $sequence_6 = { 4c89b820220000 4c89b828220000 4c89b830220000 4c89b838220000 4c89b840220000 4c89b848220000 4c89b850220000 }
+ $sequence_7 = { ff15???????? 488d0df81b0200 ff15???????? 488d0d7b170200 ff15???????? }
+ $sequence_8 = { 488d0dd7070000 e8???????? e8???????? 488d0d42070000 e8???????? }
+ $sequence_9 = { 4533c9 458d4101 488d542450 488bcb ff90a8000000 }
condition:
- 7 of them and filesize <1591296
+ 7 of them and filesize <372736
}
-rule MALPEDIA_Win_Graphdrop_Auto : FILE
+rule MALPEDIA_Win_Cuba_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9b2ea7f1-3511-52b3-a5e3-7dff660f4219"
+ id = "8e1fe25d-f2c0-551f-8e41-a3623d0fa4f8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphdrop"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graphdrop_auto.yar#L1-L112"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cuba"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cuba_auto.yar#L1-L166"
license_url = "N/A"
- logic_hash = "f69680c5241d19c09af86db48aaa89e34bb562d83e95c226a91b7e2e978f1c7f"
+ logic_hash = "9f0de113045e5c6c763dd8b7a39764d54e03c53f19ccc2d0320fdbbeb66fa89e"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -171682,34 +178754,40 @@ rule MALPEDIA_Win_Graphdrop_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4154 90 415c 90 }
- $sequence_1 = { 4155 49c7c501000000 4150 4152 415a }
- $sequence_2 = { 52 0f77 90 5a }
- $sequence_3 = { 0f77 0f77 5b 0f77 }
- $sequence_4 = { 49c7c501000000 4150 4152 415a 4158 }
- $sequence_5 = { 52 50 58 5a 49ffc9 }
- $sequence_6 = { 49c7c501000000 4150 4152 415a 4158 49ffcd }
- $sequence_7 = { 4150 4152 415a 4158 }
- $sequence_8 = { 4155 49c7c501000000 4150 4152 415a 4158 49ffcd }
- $sequence_9 = { 4152 415a 4158 49ffcd }
+ $sequence_0 = { 0019 43 41 00444341 }
+ $sequence_1 = { ffb5fcfeffff ffb5fcfdffff ff15???????? 85c0 750d 8b95c0fbffff 53 }
+ $sequence_2 = { 33d2 85c0 7e0c 807c95bc19 740c 42 3bd0 }
+ $sequence_3 = { 85c0 0f84b4000000 8bbdc8fbffff 53 68???????? 8d85f0fbffff 50 }
+ $sequence_4 = { 000d???????? 384100 b538 41 }
+ $sequence_5 = { 0026 45 41 003a }
+ $sequence_6 = { 85c0 750c 57 ff15???????? e9???????? 56 ff15???????? }
+ $sequence_7 = { 0012 45 41 0026 }
+ $sequence_8 = { 6a02 6a00 688b010000 ff75f4 ff15???????? ff75f4 f7d8 }
+ $sequence_9 = { 757a ffb5d4fbffff 50 6800040000 }
+ $sequence_10 = { 8945f4 8b4514 40 c745ecac9c4000 894df8 8945fc }
+ $sequence_11 = { 0026 43 41 00b043410062 }
+ $sequence_12 = { 000c43 41 0035???????? 43 }
+ $sequence_13 = { 003a 45 41 004245 }
+ $sequence_14 = { 03f0 c1ca16 8b85e0feffff 03b40510ffffff 03b0f4b14100 03b5e8feffff 8d0437 }
+ $sequence_15 = { 000446 41 00d1 45 }
condition:
- 7 of them and filesize <4186112
+ 7 of them and filesize <1094656
}
-rule MALPEDIA_Win_Winnti_Auto : FILE
+rule MALPEDIA_Win_Tabmsgsql_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3bce81c4-b806-55af-b179-e7a33535f793"
+ id = "95969567-7681-52bb-9f9f-efce304f47a8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winnti"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.winnti_auto.yar#L1-L247"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tabmsgsql"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tabmsgsql_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "bb0b6cf106deb97c4eb44fec946685f152141bb95569eea2bec56d5f75cb75c8"
+ logic_hash = "7b59d9e77530877005ccccefb5d251d16423422a57046d3f1c0987aa86d57fc9"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -171721,46 +178799,32 @@ rule MALPEDIA_Win_Winnti_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 52 8bce e8???????? 53 8bf8 ff15???????? }
- $sequence_1 = { ff15???????? 663dffff 747b 663dfeff 7475 8b942494020000 83c9ff }
- $sequence_2 = { c22000 8b4d00 56 6a03 68c8000000 51 ff15???????? }
- $sequence_3 = { 8bf0 83c404 85f6 7509 5f 5e 83c8ff }
- $sequence_4 = { 807a025c 75bf 83c203 8a0a 56 33f6 b801000000 }
- $sequence_5 = { 895e08 895e0c ffd7 50 }
- $sequence_6 = { 83c404 85db 0f84da000000 55 8b6c2430 56 57 }
- $sequence_7 = { 6a01 52 6a02 8974243c 89742430 c644244800 ff15???????? }
- $sequence_8 = { 488d8a40000000 e9???????? 488b8a40000000 4883c108 e9???????? 488b8a80000000 e9???????? }
- $sequence_9 = { 48037c2470 48897c2478 488b8c2400010000 4885c9 741f 4183fe01 7513 }
- $sequence_10 = { 4c8d25b6f10000 498b0c24 4d8bc5 488bd3 e8???????? 85c0 }
- $sequence_11 = { 4803f7 4c03f7 41ffca 660f1f840000000000 478d0c1a }
- $sequence_12 = { 75f8 488d15e1160000 b12e 482bd0 }
- $sequence_13 = { 4963f9 48897db7 453bc5 0f8e4f020000 418bc0 412bc5 448be0 }
- $sequence_14 = { 3918 0f4c18 3bcb 0f8d87000000 488d3d979c0a00 ba58000000 488bcd }
- $sequence_15 = { 4c2bc1 0f1f00 410fb6440801 8811 }
- $sequence_16 = { 4d85ed 7429 488d15fcd70a00 498bcd }
- $sequence_17 = { 4c8bc7 48894768 488d4567 ba18822200 }
- $sequence_18 = { 4889542410 53 4881ecb0000000 33db }
- $sequence_19 = { 488d542450 4438742450 740a 6690 48ffc2 }
- $sequence_20 = { 488d1debad0000 488d3d64ae0000 eb0e 488b03 4885c0 7402 }
- $sequence_21 = { 8a45d9 4b8b8cf800a20b00 88443139 4b8b84f800a20b00 8854303a eb4c 493bde }
- $sequence_22 = { 57 4156 4157 4883ec30 4c8bf1 33ff }
- $sequence_23 = { 44895c391c 4963cb 488bd1 48c1fa10 498b8680000000 }
+ $sequence_0 = { 33c0 f2ae f7d1 2bf9 8bd1 8bf7 8bbc24a4010000 }
+ $sequence_1 = { 8a443901 c0fb02 8a80c8244100 c0e004 02c3 880416 }
+ $sequence_2 = { 8882c8254100 48 42 83f841 }
+ $sequence_3 = { 8bf8 75ce 8b6c2414 8b542418 b8ad8bdb68 }
+ $sequence_4 = { 6804010000 8b842478030000 52 c744242844000000 c744245401010000 8b08 8b400c }
+ $sequence_5 = { f2ae f7d1 49 8d85c8f7ffff }
+ $sequence_6 = { 0f8eb2000000 8b7c2414 0fbe05???????? 33db 8a1c39 3bd8 }
+ $sequence_7 = { ff15???????? b940000000 33c0 bf???????? 68???????? f3ab 68???????? }
+ $sequence_8 = { a1???????? 50 ff15???????? b940000000 33c0 bf???????? }
+ $sequence_9 = { 33c0 8a443901 c0fb02 8a80c8244100 c0e004 02c3 880416 }
condition:
- 7 of them and filesize <1581056
+ 7 of them and filesize <163840
}
-rule MALPEDIA_Win_Badflick_Auto : FILE
+rule MALPEDIA_Win_Breakthrough_Loader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "24a1778a-a3eb-561a-a408-849c5f96759c"
+ id = "c04a79be-d1c6-5097-81f4-9cd0a78c5ca6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badflick"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.badflick_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.breakthrough_loader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.breakthrough_loader_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "416482f46b00136f041d59b3fa9a5b2a608db531874355803fb74761c46fd686"
+ logic_hash = "6b4d6b03c6e2480f390e69c1bdad99aa25aa8d566c5f76108e42a507f3962675"
score = 75
quality = 75
tags = "FILE"
@@ -171774,32 +178838,32 @@ rule MALPEDIA_Win_Badflick_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 74e2 6800800000 53 ff75f8 ff75e4 ff15???????? }
- $sequence_1 = { 56 ff75fc ff15???????? 53 ff15???????? 33c0 5f }
- $sequence_2 = { 8d4598 53 50 c7459044000000 895d94 e8???????? 33c0 }
- $sequence_3 = { 8bec 51 51 8b4d0c 8b4101 53 56 }
- $sequence_4 = { 68???????? 50 ffd7 be???????? 56 }
- $sequence_5 = { 8945fc ffd6 8bf0 8d85e8fcffff 50 }
- $sequence_6 = { 5d c3 b001 c3 55 8bec }
- $sequence_7 = { 50 8b4704 03450c 50 8b47fc 0345f8 }
- $sequence_8 = { 85c0 0f85e7000000 6a01 ff7305 }
- $sequence_9 = { ff750c e8???????? 50 e8???????? 59 59 56 }
+ $sequence_0 = { 7e2a 8b7df8 660f1f840000000000 0fb7444e08 a900300000 740a }
+ $sequence_1 = { 5d c3 8b4d14 890e 8b4d24 }
+ $sequence_2 = { 8945e8 8945f8 8b4508 56 be???????? c745eca07d4400 57 }
+ $sequence_3 = { 8b450c 0fb68401d86a4400 c1e804 5d }
+ $sequence_4 = { 85f6 742d 83f910 8d442420 0f43442420 881418 }
+ $sequence_5 = { e8???????? 33c0 c744242c07000000 8d8c2490000000 }
+ $sequence_6 = { 8bc7 83e03f 6bc830 8b049540354500 f644082801 7421 57 }
+ $sequence_7 = { 83e03f 6bc030 59 59 0304bd40354500 5f eb05 }
+ $sequence_8 = { 8b0cbd40354500 83c410 8b7de8 89440f20 8bc6 }
+ $sequence_9 = { 8b3e 8d0417 3bd0 731d 8d47ff 8906 8b4b20 }
condition:
- 7 of them and filesize <81920
+ 7 of them and filesize <753664
}
-rule MALPEDIA_Win_Poweliks_Auto : FILE
+rule MALPEDIA_Win_Bravonc_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "14491e8d-2d96-5692-9946-38a18e40eb85"
+ id = "e1447c3c-8c4c-54e5-9d2c-b00b52d2dc03"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poweliks"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poweliks_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bravonc"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bravonc_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "38ca9b6ecbf4df7389b1ea24aaf1d7d4d015a732f44c61342f6c9c25d4c2ea48"
+ logic_hash = "76468ca1f8266a49d1bb0da33f680bf0a2046353d9d66d58507a76281c00d1b6"
score = 75
quality = 75
tags = "FILE"
@@ -171813,32 +178877,32 @@ rule MALPEDIA_Win_Poweliks_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb0b 8b5118 ebc9 8b5dec 8b75e8 8b45f8 8b0c87 }
- $sequence_1 = { c745b4726f6341 c745b864647265 66c745bc7373 c645be00 8bc8 57 }
- $sequence_2 = { 83ff0c 7439 3bc8 75ce 8b5508 }
- $sequence_3 = { 8d5598 33ff 2bf2 8d147e 8a541598 32547d98 }
- $sequence_4 = { 7415 8b7d08 8b720c 81c704110000 03f7 8b7a04 }
- $sequence_5 = { 663b4b06 7333 8b4a08 8b32 3bce 7602 8bce }
- $sequence_6 = { 33c9 663b4b06 7333 8b4a08 8b32 3bce 7602 }
- $sequence_7 = { 57 0fb65dfe 81e307000080 7905 4b }
- $sequence_8 = { 8b3486 8365fc00 03ca 894df4 8d45d0 03f2 2945f4 }
- $sequence_9 = { 3a5c0db0 7506 40 83f80f }
+ $sequence_0 = { 0f8c05040000 8b06 3b7804 0f8dfa030000 395e04 7407 50 }
+ $sequence_1 = { 5b c3 55 8bec 53 33db 395d0c }
+ $sequence_2 = { 57 ff75ec 334dec 030a 034df0 8d8401d6c162ca 8945f0 }
+ $sequence_3 = { 8907 8b45f4 2bfb 59 59 8907 8b45fc }
+ $sequence_4 = { 83c430 8bce 53 56 e8???????? 5f 5e }
+ $sequence_5 = { e8???????? 8b0e 030f c1e104 2bc1 eb08 8d4de0 }
+ $sequence_6 = { ff75f0 e8???????? 8b4df8 83c440 334dec 57 }
+ $sequence_7 = { 335dfc 3175fc 83c118 ff4df0 8bf2 8b55fc 8955f8 }
+ $sequence_8 = { 83450c08 ebd2 d36d08 8b0c8590b24000 234d08 014df0 8bc8 }
+ $sequence_9 = { 03f3 2bfb 03f3 890f }
condition:
- 7 of them and filesize <115712
+ 7 of them and filesize <131072
}
-rule MALPEDIA_Win_Devopt_Auto : FILE
+rule MALPEDIA_Win_Agfspy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b2799a63-9237-56b1-b622-1d4cf3bf7ea8"
+ id = "aa314a06-4040-546e-b9cd-d5bfa676b734"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.devopt"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.devopt_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.agfspy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.agfspy_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "f040e8bf75c02b10fb9ecd2b3e85bb747221bae38ed54254a620b66ea3085268"
+ logic_hash = "e751bb17a85204a5afd3cbca773cdafd25186332344d59ffe01d62696a3fda9d"
score = 75
quality = 75
tags = "FILE"
@@ -171852,32 +178916,32 @@ rule MALPEDIA_Win_Devopt_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb42 8b45fc f7402810000000 7402 eb34 8b45fc 80b8a900000000 }
- $sequence_1 = { eb11 3b5df0 7e02 eba3 8d7600 c745f0ffffffff 8b45f0 }
- $sequence_2 = { eb0b 8b45fc 8b4034 8945d4 eb25 8b45d0 83e00f }
- $sequence_3 = { ff9240040000 84c0 7502 eb0b 8b55f8 8b45fc e8???????? }
- $sequence_4 = { e8???????? 8b45f4 ba???????? 8955e8 8945ec 8d55e8 31c0 }
- $sequence_5 = { 8b4240 8b55f4 8b4a40 8b11 ff5268 8945f0 89d7 }
- $sequence_6 = { ff93a8020000 8b45d4 8d40fc 50 8b45d0 8d48fc 8b45f8 }
- $sequence_7 = { 8d6424e0 53 8945f4 8955fc 894df8 837dfc00 7e02 }
- $sequence_8 = { ff75f0 ff75fc e8???????? 31d2 58 83c40c 648902 }
- $sequence_9 = { eb1e 8b45f8 a9ffffffff 7402 eb12 8b45f4 e8???????? }
+ $sequence_0 = { 7527 83fefd 7431 8a4101 3a4201 751a 83fefe }
+ $sequence_1 = { 85f6 7539 8d45c0 50 8d45d4 50 e8???????? }
+ $sequence_2 = { 731d 8d4101 83fe10 8945d0 8d45c0 0f4345c0 881408 }
+ $sequence_3 = { c645fc04 8d45b0 837dc408 51 0f4345b0 8d4d84 50 }
+ $sequence_4 = { e8???????? eb46 8b4720 85c0 741f 837e1410 8bce }
+ $sequence_5 = { 2bc1 83c0fc 83f81f 7724 e9???????? 32c0 8b4df4 }
+ $sequence_6 = { 837de808 0f4375d4 3b55cc 752f 85d2 7413 2bf0 }
+ $sequence_7 = { 50 e8???????? 8ac8 8b45b4 83f80c 74e7 }
+ $sequence_8 = { 0fb602 eb05 8b01 ff501c 83f8ff 742f 8b0e }
+ $sequence_9 = { d1f8 51 8bcb 8d0442 50 52 }
condition:
- 7 of them and filesize <4645888
+ 7 of them and filesize <1482752
}
-rule MALPEDIA_Win_Unidentified_095_Auto : FILE
+rule MALPEDIA_Win_Shimrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "37abc0ea-ddce-59f3-9ad7-8e440d8ff0bb"
+ id = "9f2cf600-46fb-5fe2-9403-91a4ffe5dc91"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_095"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_095_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shimrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shimrat_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "2ccf7caa3b3d5540a5f23128f7d00405bc7a6134a0c6b4f4e250221b4826e780"
+ logic_hash = "4e378ef30b6703953f18ff74f4c2d2ea366c27ea22af1636e2d889f102c09783"
score = 75
quality = 75
tags = "FILE"
@@ -171891,32 +178955,32 @@ rule MALPEDIA_Win_Unidentified_095_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffc8 6641833c465c 7505 6641892c46 4c8bbc24e8000000 }
- $sequence_1 = { 85c0 7553 488bcf ff15???????? 488d4c2430 }
- $sequence_2 = { 488bd0 48d3ca 4933d0 4b8794fe90440200 eb2d }
- $sequence_3 = { 48c7c102000080 897c2420 ff15???????? 85c0 740c 8bc8 ff15???????? }
- $sequence_4 = { 488d1519de0000 488d0df2dd0000 e8???????? 488d1516de0000 488d0d07de0000 e8???????? 488b4308 }
- $sequence_5 = { 4881c490000000 5d c3 4053 4883ec20 488bd9 }
- $sequence_6 = { 660f28c1 4c8d0dfb9e0000 f20f101d???????? f20f100d???????? f20f59da }
- $sequence_7 = { 85c0 0f8502010000 837c243c04 7516 }
- $sequence_8 = { eb19 488d3d3a440100 eb10 488d3d41440100 eb07 488d3d20440100 4883a4248000000000 }
- $sequence_9 = { 75ed 488bcb 85d2 7507 e8???????? eb08 498bd1 }
+ $sequence_0 = { e8???????? 59 59 6a01 8d452c }
+ $sequence_1 = { eb1a 83f802 7513 83ec0c 8d4660 8bcc 50 }
+ $sequence_2 = { ff7508 8d85fcfeffff 50 e8???????? 59 59 85c0 }
+ $sequence_3 = { ff15???????? 8d4df4 e8???????? 8d4d08 e8???????? 5e }
+ $sequence_4 = { e8???????? 59 59 895e1c ff15???????? 8bce 899ec0000000 }
+ $sequence_5 = { ff15???????? 8bce 899ec0000000 e8???????? 85c0 750e }
+ $sequence_6 = { 837d0800 7424 837d0c00 741e ff7510 ff750c }
+ $sequence_7 = { 50 8bce e8???????? 85c0 74d9 ff75e8 8d4df0 }
+ $sequence_8 = { 6a00 68???????? 53 ffd7 ff7570 ff15???????? e9???????? }
+ $sequence_9 = { 83c414 50 8d4f6c e8???????? }
condition:
- 7 of them and filesize <339968
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Onhat_Auto : FILE
+rule MALPEDIA_Win_Ahtapot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "59032243-71bc-5ccf-a304-ec07259d2d04"
+ id = "b3228dcd-5cf8-5afe-a611-92ad75d7ce7a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.onhat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.onhat_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ahtapot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ahtapot_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "0a14e4700b595808dab4fc1d09b95f2e90fdba52a26f4d889c5bc554e4997af3"
+ logic_hash = "69c00171f493e14b569002ab8197f5ff4c272ce4e4b6b3103d5b52b14a5be8a4"
score = 75
quality = 75
tags = "FILE"
@@ -171930,32 +178994,32 @@ rule MALPEDIA_Win_Onhat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? e8???????? 83c404 b806000080 5f 5e 5d }
- $sequence_1 = { c684242c01000048 889c242d010000 c684242e01000045 c684242f0100004e }
- $sequence_2 = { 8d7c2414 bee8030000 f3ab 8b8c2424010000 b8d34d6210 f7e1 c1ea06 }
- $sequence_3 = { 88542408 f3ab 8b8c240c200000 88542406 66ab aa 8d842410200000 }
- $sequence_4 = { 57 32d2 b9ff070000 33c0 8d7c2409 88542408 }
- $sequence_5 = { 53 ff15???????? 8bf0 3bf3 7526 }
- $sequence_6 = { 33c9 8a4c2432 8ac7 52 50 c1eb18 51 }
- $sequence_7 = { 8d7710 6a00 8d842424010000 56 50 51 e8???????? }
- $sequence_8 = { 8d54241c 55 55 52 68???????? 55 55 }
- $sequence_9 = { c644242852 c644242955 885c242a c644242b41 c644242c44 c644242d44 c644242e52 }
+ $sequence_0 = { 80e17f 3008 8b06 8bc8 c1f905 8b0c8dc0f24200 83e01f }
+ $sequence_1 = { c686c312000001 e9???????? 6a00 6a00 56 68???????? 6a00 }
+ $sequence_2 = { 740b 8d85f0fdffff e8???????? 56 8d95f0fdffff 68???????? 52 }
+ $sequence_3 = { 8d95f0fdffff 52 ff15???????? 83f8ff 0f8585000000 8d837c060000 50 }
+ $sequence_4 = { 8d8e6c020000 51 8d95acf1ffff 68???????? }
+ $sequence_5 = { 8d3c85c0f24200 8bf3 83e61f c1e606 8b07 0fbe440604 83e001 }
+ $sequence_6 = { 8b958cf3ffff 8b8578f3ffff 8d8da8f3ffff 51 52 68???????? }
+ $sequence_7 = { 8b5df0 8bf0 8b45ec 8d140b 52 50 56 }
+ $sequence_8 = { 83c404 8b1d???????? 8d95bcf9ffff 52 ffd3 8b859cf1ffff }
+ $sequence_9 = { e8???????? 68???????? 8d55ec 52 8975f8 897dfc c745ec20a04200 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <430080
}
-rule MALPEDIA_Win_Stealer_0X3401_Auto : FILE
+rule MALPEDIA_Win_Diavol_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bb4f4861-3b94-5ae9-a941-991186118cf0"
+ id = "fdab7e4d-8bbf-526f-9dd1-9c3eccb8a369"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stealer_0x3401"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stealer_0x3401_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.diavol"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.diavol_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "5581efed5fdecbce8348574e847d7eb07ab8e38c2ac3e166eb58c72b5a5419d5"
+ logic_hash = "8bc41d08eecdbb842d56f4530baf282b624ea1b70952493cedafeb9a5a3b5234"
score = 75
quality = 75
tags = "FILE"
@@ -171969,34 +179033,34 @@ rule MALPEDIA_Win_Stealer_0X3401_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 03f2 8bd6 85f6 7e37 8d8d5cfeffff e8???????? }
- $sequence_1 = { 53 e8???????? 83c41c c74424280f000000 c744242400000000 c644241400 803b00 }
- $sequence_2 = { 5f 894df0 8b34cd50fa0110 8b4d08 6a5a 2bce }
- $sequence_3 = { 83781410 7202 8b00 ffb57cfdffff }
- $sequence_4 = { c745fc05000000 8d8d5cffffff e8???????? c645fc06 83781410 7202 }
- $sequence_5 = { 8b8db87dffff 40 3d00100000 722a f6c11f }
- $sequence_6 = { 64a300000000 8b35???????? 8d8574ffffff 50 6a00 }
- $sequence_7 = { 8d8598feffff 3bc3 7435 8bc8 e8???????? }
- $sequence_8 = { 8d4c2434 e8???????? 53 e8???????? 83c404 8d44242c 8bcf }
- $sequence_9 = { ffb5843fffff ffd7 83bd803fffff00 0f84ec000000 6a12 68???????? b9???????? }
+ $sequence_0 = { ff15???????? 8bf0 83feff 0f8474010000 }
+ $sequence_1 = { 8d8df8fdffff 51 b9???????? e8???????? 83c404 84c0 }
+ $sequence_2 = { 74cf 8bc7 ebce 66833800 7520 }
+ $sequence_3 = { e8???????? 8b4df8 83c40c 5f 5e 33cd b001 }
+ $sequence_4 = { 83fb01 7503 894df8 8b4d10 8bc3 }
+ $sequence_5 = { 752c 6a02 53 ff15???????? }
+ $sequence_6 = { e8???????? 83c40c 8b4dfc 5f 5e 33cd b001 }
+ $sequence_7 = { 6a10 46 8d843594f7ffff 68???????? 50 e8???????? }
+ $sequence_8 = { 8d45e4 50 8bc8 51 57 8bd0 }
+ $sequence_9 = { 0f84ee000000 53 57 33db 8d9b00000000 }
condition:
- 7 of them and filesize <357376
+ 7 of them and filesize <191488
}
-rule MALPEDIA_Win_Karius_Auto : FILE
+rule MALPEDIA_Win_Cryptic_Convo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ed0a7186-5551-553c-ac59-b131d3af72d8"
+ id = "c0d84b8c-dd86-5e0b-b294-081ee84952b7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.karius"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.karius_auto.yar#L1-L249"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptic_convo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptic_convo_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "b146425f067402ca1aeb5e04aa4caed2d124eb5c4ba40f66c5f112d8e9115a94"
+ logic_hash = "39890a4d7eaef0b28d86a0d6d65ec4ed011fdfc3e00013a201ada7ffacfd1cd9"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -172008,49 +179072,32 @@ rule MALPEDIA_Win_Karius_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4c8b8424a0000000 bf01000000 8bd7 498bce ffd3 4183bf8c00000000 }
- $sequence_1 = { 4d03d6 448bcd 85db 0f8477000000 8bb424b0000000 }
- $sequence_2 = { 0f84b3000000 458b9f88000000 4d03de 418b5b18 85db }
- $sequence_3 = { ffd3 4183bf8c00000000 0f84b3000000 458b9f88000000 }
- $sequence_4 = { 488b05???????? 4885c0 7512 ff15???????? 488905???????? }
- $sequence_5 = { 8bb424b0000000 418b10 8bcd 4903d6 0fb602 }
- $sequence_6 = { c3 85c0 7505 e8???????? b801000000 }
- $sequence_7 = { 85db 0f849d000000 41837b1400 0f8492000000 }
- $sequence_8 = { 0f8492000000 458b4320 458b5324 33ed 4d03c6 4d03d6 }
- $sequence_9 = { 8d7b01 448bfb 448be3 4885c9 }
- $sequence_10 = { 56 be???????? 33d2 8a040a 3a06 7522 }
- $sequence_11 = { 83e830 89450c db450c 8a07 d9ca d8c9 }
- $sequence_12 = { b801000000 8702 83f801 74f4 }
- $sequence_13 = { 752c 8a4701 3c30 7c25 3c39 }
- $sequence_14 = { 488d4b10 488d542450 41b804000000 c6430f68 }
- $sequence_15 = { 4d8bcf 33d2 41b800001000 488bce }
- $sequence_16 = { 803e5d 7508 5f 5b 8d4601 5e }
- $sequence_17 = { 7505 8d7b02 eb09 6685c0 }
- $sequence_18 = { 8d7308 56 ffd7 50 56 e8???????? }
- $sequence_19 = { ff15???????? 4c8be8 498bce ff15???????? 4d85ed }
- $sequence_20 = { 8b4dfc 83c404 8945f4 83c706 050024ffff }
- $sequence_21 = { 4d8bc7 488bd0 488bce ff15???????? }
- $sequence_22 = { e9???????? 8b45f8 5f 5b 5e }
- $sequence_23 = { 8b4508 85c0 7417 8b4008 85c0 7412 8b4d0c }
- $sequence_24 = { 7405 f60001 7502 33c0 }
- $sequence_25 = { 448bc0 33d2 488bce ff15???????? 4c8bf0 4885c0 }
- $sequence_26 = { 48895c2420 4d8bcc 4d8bc7 488bd0 }
+ $sequence_0 = { 8bf8 ffd6 85ff 7515 8d45e8 68???????? }
+ $sequence_1 = { 75f9 8dbddcfaffff 2bc2 4f 8a4f01 }
+ $sequence_2 = { 399e88000000 7445 399e8c000000 743d 6a40 6800300000 ff7510 }
+ $sequence_3 = { c20400 0fb7442404 ff742408 50 e8???????? c20800 }
+ $sequence_4 = { 50 6a01 6a00 68???????? 57 ffd3 85c0 }
+ $sequence_5 = { a4 33c0 8a88d0474000 884c05e8 40 84c9 }
+ $sequence_6 = { f3a4 8dbddcfaffff 4f 8a4701 47 84c0 75f8 }
+ $sequence_7 = { 85c0 7407 c605????????01 be???????? 8d7d98 a5 66a5 }
+ $sequence_8 = { 894584 ffd6 53 57 89458c ff15???????? }
+ $sequence_9 = { 8d45c8 66a5 50 53 }
condition:
- 7 of them and filesize <434176
+ 7 of them and filesize <97280
}
-rule MALPEDIA_Win_Webc2_Greencat_Auto : FILE
+rule MALPEDIA_Win_Upatre_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "60cc7c89-f223-5f05-b50e-ef8d73401362"
+ id = "1628c1f9-1d48-5501-a98b-2c8f976e35eb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_greencat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_greencat_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.upatre"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.upatre_auto.yar#L1-L164"
license_url = "N/A"
- logic_hash = "e9fd4938930988d9b35f1bca39290f31fad2f360914fa390eec34fabf9934b56"
+ logic_hash = "ec286f640db5a5b7bffd2eededa524e0947ea3452d78b30e2aeb2f315c32ce53"
score = 75
quality = 75
tags = "FILE"
@@ -172064,32 +179111,38 @@ rule MALPEDIA_Win_Webc2_Greencat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 50 e8???????? 59 8bd8 59 eb03 }
- $sequence_1 = { 59 59 e9???????? ff35???????? ff15???????? 3bc6 }
- $sequence_2 = { 33f6 895df4 8d450c 50 ff35???????? ff15???????? 817d0c03010000 }
- $sequence_3 = { 395ddc 752d 391d???????? 7525 3bf3 7521 }
- $sequence_4 = { e8???????? 83c418 53 6a02 }
- $sequence_5 = { 8d85fcfeffff 33ff 6804010000 50 }
- $sequence_6 = { 50 53 ff15???????? 33c9 8945f0 }
- $sequence_7 = { 8bf0 395ddc 752d 391d???????? 7525 3bf3 7521 }
- $sequence_8 = { ff75fc ff15???????? 83c428 53 6880000000 }
- $sequence_9 = { 0fbe4007 83e830 8945f8 8d85f8fdffff 50 }
+ $sequence_0 = { 66ab 33c0 66ab bbff0f0000 8b75f0 }
+ $sequence_1 = { 8945fc 8bd8 03c1 8bf8 33c0 }
+ $sequence_2 = { 894d90 8b4d8c 85c9 7501 c3 57 }
+ $sequence_3 = { 7414 4e 56 ff75f0 }
+ $sequence_4 = { 0430 66ab 81c60e010000 ac }
+ $sequence_5 = { 8945ec 6a00 8d4dc0 51 ff75e0 ff75bc ff75ec }
+ $sequence_6 = { 895d98 8bfb 03d8 b91c010000 }
+ $sequence_7 = { b900100000 03c1 8945f0 03c1 }
+ $sequence_8 = { 83c008 8945bc 8b4dbc 8b5104 52 }
+ $sequence_9 = { 8b55d4 8b440a1c 8945f4 8b4df0 }
+ $sequence_10 = { 0f94c0 85c0 7436 8b4dd8 83c102 2b4de8 }
+ $sequence_11 = { e3c9 1bb6aeaca844 bbcdcc70e8 739c d4ef }
+ $sequence_12 = { eb2b 8b4df4 8b510c 52 e8???????? 83c404 0fb7c0 }
+ $sequence_13 = { 8b4508 0345f0 0fbe08 8b5510 0faf55f8 0faf55f0 33ca }
+ $sequence_14 = { 8945dc 8b4ddc 668b11 668955f0 0fb745f0 }
+ $sequence_15 = { 894df4 8b55f4 3b550c 7d28 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <294912
}
-rule MALPEDIA_Win_Clambling_Auto : FILE
+rule MALPEDIA_Win_Carrotball_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "55c68f1e-9478-508c-963a-a6b0515c5aac"
+ id = "8d1dffb9-f801-5b51-998b-8e4431af5d29"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.clambling"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.clambling_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.carrotball"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.carrotball_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "bda71815f9f64d048a93fa253b5199d20d6e6d47cb677b3884b8c43571e95a8e"
+ logic_hash = "8cb2e3b01c31931d0c5f23b61551aa799de8dd787a3493373f0ac01ba6f109d9"
score = 75
quality = 75
tags = "FILE"
@@ -172103,32 +179156,32 @@ rule MALPEDIA_Win_Clambling_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6689bc24b0000000 ff15???????? 3bc7 7508 }
- $sequence_1 = { 488bd9 498d53e8 418d4802 498943f0 ff15???????? }
- $sequence_2 = { 751b e9???????? bb46270000 eb0f ff15???????? 8bd8 eb05 }
- $sequence_3 = { 3bc3 751f 8b4c2428 488d942490020000 ff15???????? }
- $sequence_4 = { eb0f ff15???????? 8bd8 eb05 bbc7040000 }
- $sequence_5 = { 7507 66893d???????? 488b0d???????? 488d542430 ff15???????? 448b442430 }
- $sequence_6 = { 7408 488bcb e8???????? 488b5c2458 }
- $sequence_7 = { 4c8d442430 33d2 c744243001000000 c744243c02000000 ff15???????? 85c0 }
- $sequence_8 = { b8b4050000 eb13 488b03 488bd7 488bcb }
- $sequence_9 = { 41b805000000 48894c2420 33c9 8bd5 }
+ $sequence_0 = { ff15???????? eb36 68???????? 56 ff15???????? }
+ $sequence_1 = { 6a04 58 6bc000 c7807430001002000000 6a04 }
+ $sequence_2 = { 5f 8b4dfc 33cd 33c0 e8???????? 8be5 5d }
+ $sequence_3 = { ffd6 5e 5f 8b4dfc 33cd 33c0 }
+ $sequence_4 = { 68???????? ff15???????? eb36 68???????? 56 }
+ $sequence_5 = { 8bf0 85f6 0f84ac000000 68???????? }
+ $sequence_6 = { 56 ff15???????? 85c0 7432 8d85ecfdffff }
+ $sequence_7 = { ff15???????? 8bf8 85ff 0f84d9000000 56 }
+ $sequence_8 = { ff15???????? 8bf0 85f6 0f84ac000000 68???????? 56 ff15???????? }
+ $sequence_9 = { 6bc000 c7807430001002000000 6a04 58 6bc000 }
condition:
- 7 of them and filesize <412672
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Rekoobew_Auto : FILE
+rule MALPEDIA_Win_Killdisk_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "73ccfc35-4eed-5955-a644-c948264eda18"
+ id = "fd586ea1-d41c-50af-ab00-4c3fd6d8b593"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rekoobew"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rekoobew_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.killdisk"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.killdisk_auto.yar#L1-L172"
license_url = "N/A"
- logic_hash = "445ddabcfd3896aee22b87d60b9d2106a9693bf00a56789028f0bf36c80e8900"
+ logic_hash = "5e0faf26e496f52d500cc74a0d402009c944ca198565834d2511070577fb34d3"
score = 75
quality = 75
tags = "FILE"
@@ -172142,32 +179195,38 @@ rule MALPEDIA_Win_Rekoobew_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 337dec 337dd0 d1c7 897db8 8d8c39dcbc1b8f 894df0 89c1 }
- $sequence_1 = { 89e5 57 56 53 81ecbc000000 e8???????? 8945e0 }
- $sequence_2 = { 89df 0fb63482 c1e618 0fb65c8201 }
- $sequence_3 = { 8b1c9de0944000 c1e310 31df 8b4dd8 0fb6dd 8b1c9de0944000 c1e308 }
- $sequence_4 = { 7409 3b7510 0f8fd3000000 0fb645e8 c1e004 89c7 b8ffffffff }
- $sequence_5 = { c744240808000000 89742404 891c24 e8???????? c744240804000000 897c2404 891c24 }
- $sequence_6 = { 8b3c95e07c4000 33bb54010000 8b55f0 c1ea18 333c95e0704000 89f2 c1ea10 }
- $sequence_7 = { 56 53 83ec5c 8b450c 0fb65003 0fb638 }
- $sequence_8 = { 89f1 31d1 31d9 8d0c0f 89c7 c1c705 01f9 }
- $sequence_9 = { 895008 8b500c 89d6 c1ee18 8b3cb5e0944000 89d6 }
+ $sequence_0 = { 8d4604 7204 8b08 eb02 8bc8 66891c51 }
+ $sequence_1 = { 0f8424020000 8d4c245c b8???????? 8d642400 668b10 }
+ $sequence_2 = { 881438 e8???????? 9c c6442408cf 894508 e9???????? }
+ $sequence_3 = { 88742408 c70424ba7bbfa4 660fbae408 662dca11 e8???????? 881438 e8???????? }
+ $sequence_4 = { 83c40c 68???????? 68e08fc201 e8???????? 8bf0 }
+ $sequence_5 = { 8f44241c c64424148e c644240426 e8???????? 4e e8???????? 54 }
+ $sequence_6 = { c3 50 ff15???????? 8b8c24d41a0000 }
+ $sequence_7 = { 872d???????? 0fc1c2 89e2 66d3c9 66d3c0 }
+ $sequence_8 = { e8???????? 84c0 751a a1???????? 50 6802000080 }
+ $sequence_9 = { b001 5e 59 c3 837f1800 7413 }
+ $sequence_10 = { e8???????? 83c420 6a00 8d442414 }
+ $sequence_11 = { 46 66892c24 9c 8d64244c e9???????? 9c 9c }
+ $sequence_12 = { 9c 8d642430 e9???????? ff742404 66894500 }
+ $sequence_13 = { 8d642454 e9???????? 880424 8774242c 9c 68a12348dd e8???????? }
+ $sequence_14 = { 66897c240c 882c24 c64424044f 8d642454 e9???????? }
+ $sequence_15 = { 56 e8???????? c1f805 56 8d3c85a098c201 }
condition:
- 7 of them and filesize <248832
+ 7 of them and filesize <10817536
}
-rule MALPEDIA_Win_Unidentified_092_Auto : FILE
+rule MALPEDIA_Win_Betabot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7e18dd30-6337-5c36-a898-b23460fa3b1e"
+ id = "66328af7-8459-5b35-88d1-7e63b7ee5eb4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_092"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_092_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.betabot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.betabot_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "2159e4ff6c9c542892316c91029887360b4aa3e31c90494be3422bea5bef7c7b"
+ logic_hash = "51b7b8c3c50a8d4a628d1b4c5d49a49007142cba41644cf909b7bfdb76b9cbc5"
score = 75
quality = 75
tags = "FILE"
@@ -172181,32 +179240,32 @@ rule MALPEDIA_Win_Unidentified_092_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c78520ffffff00000000 c68510ffffff00 83f810 7241 8b8df8feffff 40 3d00100000 }
- $sequence_1 = { 723f 8b4c2464 40 3d00100000 722a f6c11f 0f850b010000 }
- $sequence_2 = { 33f1 8b7df8 0375a4 8bd3 8b5dfc f7d2 8b4de8 }
- $sequence_3 = { 8b41fc 3bc1 0f83de020000 2bc8 83f904 0f82d3020000 83f923 }
- $sequence_4 = { 0155ec c1c107 33f1 8bcb 8bd3 }
- $sequence_5 = { 56 52 50 8b08 ff511c c745fcffffffff 83ceff }
- $sequence_6 = { 8d8558ffffff 50 0f118568ffffff ffd3 c645fc03 83ec10 }
- $sequence_7 = { 8bc3 c1c007 8bcb 33d0 897508 f7d1 8bc3 }
- $sequence_8 = { 83ee01 75e9 8b85e4fbffff 83f814 }
- $sequence_9 = { 50 56 ffd3 85c0 7f38 68???????? }
+ $sequence_0 = { 8d85e4f7ffff 89bde8f7ffff 50 33ff 56 47 56 }
+ $sequence_1 = { 8d44244c 50 ff15???????? 8d442448 50 e8???????? 8d442448 }
+ $sequence_2 = { 32c0 e9???????? 6a40 5e e8???????? a3???????? }
+ $sequence_3 = { 884617 2407 80fa40 7413 80fa80 7404 }
+ $sequence_4 = { 85c0 7503 6afd 58 5f 5e 5b }
+ $sequence_5 = { c20400 55 8bec 83ec18 53 56 8365f800 }
+ $sequence_6 = { a1???????? 85c0 740b 8d4dfc 51 ff7508 ffd0 }
+ $sequence_7 = { bbb0040000 85f6 7433 a1???????? 48 50 }
+ $sequence_8 = { 8a460a 3cb9 740c 3c33 7408 c70302000000 eb34 }
+ $sequence_9 = { 7470 66397508 746a 6a02 59 ff7508 66894de8 }
condition:
- 7 of them and filesize <10202112
+ 7 of them and filesize <835584
}
-rule MALPEDIA_Win_Unidentified_104_Auto : FILE
+rule MALPEDIA_Win_Merdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e8a556d0-f78d-5a2d-8efe-d7e4f2e8c4f0"
+ id = "a99af5cd-bc04-5bf5-95d0-af03ff89050f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_104"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_104_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.merdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.merdoor_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "e638b20b38ac304bb33832304ee0b9b7e6ee0e08465f3d2f98dbc6a372f89d7d"
+ logic_hash = "b95cd242972456e72e114f53ab84ee24aaf18f568fbe98e73f19f67ea1e8459f"
score = 75
quality = 75
tags = "FILE"
@@ -172220,32 +179279,32 @@ rule MALPEDIA_Win_Unidentified_104_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4c8d0d20070100 33c9 4c8d050f070100 488d1510070100 e8???????? 4885c0 }
- $sequence_1 = { 4c03e9 4d33cd 498bd9 49c1e918 48c1e328 4933d9 4803c3 }
- $sequence_2 = { 410fb6401b 4c0bc8 410fb6401a 49c1e108 4c0bc8 49c1e104 4c03c9 }
- $sequence_3 = { 48c1e128 4933c9 4c8b8c2490000000 498b8180000000 4803c1 4803e8 4c33c5 }
- $sequence_4 = { 4883fa10 0f8288000000 48ffc2 488b4dc7 488bc1 483bd7 728f }
- $sequence_5 = { 415d 415c 5f 5e 5d c3 488d5ed8 }
- $sequence_6 = { 418848fe c1e810 c1e918 418800 41884801 4d8d4004 4983e901 }
- $sequence_7 = { e8???????? 33c0 4883c420 5b c3 8bd3 488bc8 }
- $sequence_8 = { 49c1e330 4c33da 4903f3 4889b424a0000000 4833ce 488b742418 488bd1 }
- $sequence_9 = { 7230 48ffc2 488b8dc0000000 488bc1 4881fa00100000 7215 }
+ $sequence_0 = { 5e 3bc8 7215 50 8d8398000000 50 6aff }
+ $sequence_1 = { 8d85f0fdffff 8bcb 50 e8???????? 8b4dfc f7d8 5f }
+ $sequence_2 = { 8ac1 eb04 b011 2ac1 f6d0 fec1 }
+ $sequence_3 = { 0f87af000000 8d8ee4020000 894df4 7443 8b01 8bf0 8bd0 }
+ $sequence_4 = { ffd7 8986c0000000 83bec400000000 750f 8d4588 }
+ $sequence_5 = { 3044159c 42 80f90f 72da 660f6f05???????? 32c9 f30f7f853cffffff }
+ $sequence_6 = { 85c0 751c 8d85ecfeffff 50 ff15???????? 8b400c 8b00 }
+ $sequence_7 = { 85c0 7403 8d3410 8b440b10 85c0 7438 }
+ $sequence_8 = { 53 56 8bf1 57 83cfff 8d9eec020000 53 }
+ $sequence_9 = { 8986c0000000 83bec400000000 750f 8d4588 50 ff7604 ffd7 }
condition:
- 7 of them and filesize <263168
+ 7 of them and filesize <307200
}
-rule MALPEDIA_Win_Tflower_Auto : FILE
+rule MALPEDIA_Win_Icedid_Downloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b4660b68-51d0-51ac-bbdd-acf4449bc6d1"
+ id = "1dc8b5e6-58e8-56f8-b32a-539ebf38d462"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tflower"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tflower_auto.yar#L1-L158"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.icedid_downloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.icedid_downloader_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "82eb88790bbfb711d9ea01573d045bd4c38f5ceb308c5ccacf5ea018abeab10b"
+ logic_hash = "f3e7c7707c4dd480b8c042e3891161f91628584450f48860513befa5fa6f9a3b"
score = 75
quality = 75
tags = "FILE"
@@ -172259,38 +179318,32 @@ rule MALPEDIA_Win_Tflower_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0001 0200 0103 0303 }
- $sequence_1 = { 0001 7708 00f3 7608 }
- $sequence_2 = { 0002 7408 00f7 7308 }
- $sequence_3 = { 001a 0c05 003c0c 05004e0c05 }
- $sequence_4 = { 0008 7408 0002 7408 }
- $sequence_5 = { c1e104 0fb6d0 8b84248c000000 c1e204 8baa406f4f00 }
- $sequence_6 = { 000f 7708 0001 7708 }
- $sequence_7 = { c7405420164600 eb5e 57 e8???????? }
- $sequence_8 = { 3bf7 72e3 5b 5f b001 5e }
- $sequence_9 = { 0010 740b 0021 740b }
- $sequence_10 = { 0fb6c0 330c85c0fe4e00 0fb6c3 8b5f28 330c85c0fa4e00 33f1 8d0411 }
- $sequence_11 = { 8b75fc 8b7df4 c60301 eb06 8b75fc 8b7df4 }
- $sequence_12 = { 894c2448 7436 8b442410 8d90c8795000 }
- $sequence_13 = { 330c8520dd4e00 8b442414 c1e818 330c8520d94e00 8b44242c 0fb6c0 }
- $sequence_14 = { 6a35 eb2b 8bfb eb04 8b442414 ff742420 }
- $sequence_15 = { 000b 8605???????? 007885 0500788605 }
+ $sequence_0 = { eb1c 83f803 7519 8b06 }
+ $sequence_1 = { e8???????? 8365f400 8d45b0 8945f8 64a118000000 59 59 }
+ $sequence_2 = { 8d4568 50 8d4558 50 8d45c8 6a04 }
+ $sequence_3 = { 8d75d4 33c0 c745dc00330000 6a16 }
+ $sequence_4 = { ff7508 895dfc 895df4 895df8 895dec 895de4 }
+ $sequence_5 = { ffd7 ff15???????? 83f87a 0f85e9000000 8b442410 85c0 0f84dd000000 }
+ $sequence_6 = { 894528 8d4518 50 ff15???????? }
+ $sequence_7 = { 89442408 8944240c 8bf0 8944241c 8d442408 }
+ $sequence_8 = { 50 53 53 53 6a04 ff75fc e8???????? }
+ $sequence_9 = { 6689442434 8d54242c 8b442414 52 57 }
condition:
- 7 of them and filesize <6578176
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Karma_Auto : FILE
+rule MALPEDIA_Win_Fuwuqidrama_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7f63a996-b29b-562f-996a-826393522cf0"
+ id = "2e69e70e-5601-5931-bcd7-e645b5b9c52f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.karma"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.karma_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fuwuqidrama"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fuwuqidrama_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "2f60ce68960b60e178a1e413eabfae876f08564938fc3ab9af48ba4bf8caac6e"
+ logic_hash = "8de556fe8f63afd7a879ecce2fdbb1a150474ddb330c86740527423f92305d9c"
score = 75
quality = 75
tags = "FILE"
@@ -172304,32 +179357,32 @@ rule MALPEDIA_Win_Karma_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b7f08 8bc7 d3e8 8b4d08 }
- $sequence_1 = { 8bf9 8955f0 33c0 663907 7408 40 66833c4700 }
- $sequence_2 = { 0f1006 0f114318 e8???????? 5f }
- $sequence_3 = { ebc5 33ff 6690 0fb78ffc434000 }
- $sequence_4 = { ff15???????? 6a00 8d442444 50 6800710200 }
- $sequence_5 = { 660fefc8 0f1148f0 83e901 75e7 8d55e0 }
- $sequence_6 = { 894dfc 894dc0 894dc4 894dc8 894dcc }
- $sequence_7 = { 8b4c2418 8b44241c 83c140 6a00 6a00 83d000 }
- $sequence_8 = { 8d4e20 0f47ce 2bca 750e 6685db 0f84c5000000 }
- $sequence_9 = { 66833c45f051400000 75f4 33d2 663915???????? 7415 660f1f840000000000 }
+ $sequence_0 = { 8b44241c 8db08c000000 8b8314140000 83f802 764a 8d6b1a 85ed }
+ $sequence_1 = { 8b842490020000 52 50 8d4c2444 68???????? 51 }
+ $sequence_2 = { 8917 8b542414 894704 b801000000 894f08 89570c 5f }
+ $sequence_3 = { 57 33ff 8bd9 57 57 8d4c2430 }
+ $sequence_4 = { 8bdf 036908 c1c305 036c2424 c1c61e 89742418 8b712c }
+ $sequence_5 = { 83c508 55 ffd7 8a542412 899ec8030000 8896c4030000 899ecc030000 }
+ $sequence_6 = { 8bdf 036918 c1c305 036c2410 c1c61e 89742428 8d9c2bd6c162ca }
+ $sequence_7 = { ff5220 8d460c 50 ff15???????? 8b4624 }
+ $sequence_8 = { 50 ffd6 8d4c242c 6a02 8d542418 51 52 }
+ $sequence_9 = { 3d10270000 0f87e7020000 8b5708 8b4704 52 50 8bcf }
condition:
- 7 of them and filesize <49208
+ 7 of them and filesize <245760
}
-rule MALPEDIA_Win_Applejeus_Auto : FILE
+rule MALPEDIA_Win_Dispcashbr_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2b213dd7-4b0e-53d6-9398-7bec043b88e3"
+ id = "02a73395-ac12-50d4-b2ec-e868c4b1a459"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.applejeus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.applejeus_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dispcashbr"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dispcashbr_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "0a3d67a5753a00f446b4f5eec17ef4a4499de52aeb8e82581c3d643c4e67e3d2"
+ logic_hash = "60c8be22bea8462dd56c514e62576b626445f5aa18aea505cf9cb5c5983fb848"
score = 75
quality = 75
tags = "FILE"
@@ -172343,32 +179396,32 @@ rule MALPEDIA_Win_Applejeus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8902 8b4608 8b08 8b4604 810044f3ffff 8100bc0c0000 }
- $sequence_1 = { 8b4604 8b00 33c2 0f8583000000 c745f45b000000 8b45f4 83f032 }
- $sequence_2 = { 8945dc 8d45d0 c745d0a08e4200 897dd4 8975d8 0f1145b0 }
- $sequence_3 = { 8b4a04 50 0f1145c8 c745a8e0294200 0f1145d8 897dac 8975b0 }
- $sequence_4 = { e8???????? 8b4dc8 83c414 8945cc 89851cffffff c700???????? 897004 }
- $sequence_5 = { c745e400000000 8b410c 50 6a00 51 8b04851cfb4600 ffd0 }
- $sequence_6 = { c68589f5ffff7d c6858af5ffff85 c6858bf5ffff72 c6858cf5ffff83 c6858df5ffff59 c6858ef5ffff3a c6858ff5ffff77 }
- $sequence_7 = { 8d4db0 e9???????? 8d4db4 e9???????? 8d4dac e9???????? 8b542408 }
- $sequence_8 = { e8???????? 8b7588 8d4d94 83c418 e8???????? c78568ffffffd5030000 8b8568ffffff }
- $sequence_9 = { 8d85d42e0000 50 ff15???????? 57 ff15???????? e9???????? ff15???????? }
+ $sequence_0 = { e8???????? 83ec08 c7442408ceffffff c7442404???????? }
+ $sequence_1 = { e8???????? 83ec08 c7442408eaffffff c7442404???????? }
+ $sequence_2 = { e8???????? 83ec08 c7442408ceffffff c7442404???????? a1???????? 83c020 }
+ $sequence_3 = { a1???????? 83c020 890424 e8???????? eb45 c70424f5ffffff e8???????? }
+ $sequence_4 = { 83ec08 c7442408f2ffffff c7442404???????? a1???????? 83c020 890424 e8???????? }
+ $sequence_5 = { 83ec08 c7442408d9ffffff c7442404???????? a1???????? 83c020 890424 }
+ $sequence_6 = { 890424 e8???????? 83ec08 c7442408d7ffffff }
+ $sequence_7 = { 890424 e8???????? 83ec08 c7442408c9ffffff c7442404???????? }
+ $sequence_8 = { 83ec04 c744240404000000 890424 e8???????? 83ec08 c7442408f2ffffff c7442404???????? }
+ $sequence_9 = { c70424f5ffffff e8???????? 83ec04 c744240404000000 }
condition:
- 7 of them and filesize <1245184
+ 7 of them and filesize <123904
}
-rule MALPEDIA_Win_Imprudentcook_Auto : FILE
+rule MALPEDIA_Win_Ramnit_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "da16e08a-4583-5528-aff9-b355b3ccc1ad"
+ id = "9f7bb136-c877-5703-86ba-5c3c0993dd1e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.imprudentcook"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.imprudentcook_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ramnit"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ramnit_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "dc1ba99de715ff44414f303429509d324c0251135a2ef150545d89588c26b553"
+ logic_hash = "a743fa525eb529644f7aae0eeccbdf2bcc4af05febdbf59986022c9547272ab4"
score = 75
quality = 75
tags = "FILE"
@@ -172382,34 +179435,34 @@ rule MALPEDIA_Win_Imprudentcook_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d3c0b 483bf9 4983d200 4883ee18 4d03da 4d03d9 48ffcd }
- $sequence_1 = { 4983c708 4983c508 48ffc9 75ec 49894500 488b5520 488d4fff }
- $sequence_2 = { 4d8bc4 498bd2 eb08 4c89642420 4c8bc7 }
- $sequence_3 = { 488d04ed00000000 4c03f5 4803f5 48ffc3 4c03f8 4c3bf7 7ec8 }
- $sequence_4 = { 4c8bcf 4d8bc5 498bd4 e8???????? 488b9580000000 41b901000000 4d8bc6 }
- $sequence_5 = { 4d3bfe 0f8c45ffffff 4c8bac2488000000 4f8d7c2d00 498bde 4d3bf7 }
- $sequence_6 = { 8807 e9???????? 81fb0b000100 0f8dfb030000 81fb0000007e 0f87f7030000 85db }
- $sequence_7 = { 4803c2 48c1f806 488bf8 488bd8 488b8424c0000000 4c8d1cf8 48c1e306 }
- $sequence_8 = { 4833c2 482bc2 488bd3 493bc2 7d1a 4c895c2428 4c89442420 }
- $sequence_9 = { e9???????? 48ffcd b938000000 90 488bc3 48d3e8 84c0 }
+ $sequence_0 = { 3a06 7512 47 46 e2f6 b801000000 59 }
+ $sequence_1 = { 750b 4f 3b7d08 73e7 bf00000000 }
+ $sequence_2 = { 57 56 fc 807d1401 }
+ $sequence_3 = { 5f 59 5a 5b c9 c20800 55 }
+ $sequence_4 = { ff750c ff75fc e8???????? 0bc0 7429 }
+ $sequence_5 = { 8bc7 5a 5b 59 5f }
+ $sequence_6 = { 8bc1 f7d0 48 59 5f 5e }
+ $sequence_7 = { f3a4 fc 5e 5f 59 5a }
+ $sequence_8 = { 8bd7 2b5508 59 5f 5e }
+ $sequence_9 = { 8b5d0c 4b f7d3 23c3 }
condition:
- 7 of them and filesize <864256
+ 7 of them and filesize <470016
}
-rule MALPEDIA_Win_Gootkit_Auto : FILE
+rule MALPEDIA_Win_Mbrlocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "50659808-58ce-5271-8f0d-8034418275c7"
+ id = "6a472526-8a03-5ccc-a5eb-10b46b34c6da"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gootkit"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gootkit_auto.yar#L1-L327"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mbrlocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mbrlocker_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "a2cf121428fb2173dc07901e77686f48303de5dc8bfa584df38195e7a090200e"
+ logic_hash = "2abe677d378843746aa6479444a4219927906b009fff2766ade4f081783dbae6"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -172421,60 +179474,34 @@ rule MALPEDIA_Win_Gootkit_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a04 6800300000 57 6a00 897df8 }
- $sequence_1 = { 50 ff75fc ffd7 33c9 c745f804000000 41 33f6 }
- $sequence_2 = { 8945f0 85c0 7435 8b01 ff75f4 03c3 }
- $sequence_3 = { e8???????? 8bd8 85db 0f45f3 33c0 50 }
- $sequence_4 = { 83feff 7509 57 ff15???????? 8bf0 53 }
- $sequence_5 = { 895de8 2bf1 75d5 8b5df0 8b5508 51 }
- $sequence_6 = { 6a00 53 ff15???????? eb06 8b7dd8 }
- $sequence_7 = { 8bd6 e8???????? 8b7dfc 59 59 85c0 }
- $sequence_8 = { f3aa 68???????? ff15???????? 50 }
- $sequence_9 = { 8b7df4 32c0 8b4de4 f3aa }
- $sequence_10 = { 50 e8???????? 83c40c 68fd000000 }
- $sequence_11 = { 50 68???????? ff15???????? 85c0 7505 e8???????? }
- $sequence_12 = { 50 8b4508 8b00 99 }
- $sequence_13 = { c705????????01000000 c705????????02000000 8be5 5d c3 }
- $sequence_14 = { 833d????????00 750a 6a32 ff15???????? }
- $sequence_15 = { 6808020000 6a00 ff15???????? 50 }
- $sequence_16 = { e8???????? 6a0c 6a08 ff15???????? 50 ff15???????? }
- $sequence_17 = { 50 6a02 ff15???????? 6888130000 }
- $sequence_18 = { e8???????? 8d45fc 50 6a01 6a01 }
- $sequence_19 = { e8???????? 85c0 750c c705????????03000000 }
- $sequence_20 = { 8b4508 8b00 99 52 50 6a00 }
- $sequence_21 = { 68???????? 51 51 ff15???????? 50 }
- $sequence_22 = { 53 53 53 8901 }
- $sequence_23 = { 83faff 7508 ff15???????? 8bd0 }
- $sequence_24 = { e8???????? 3935???????? 7412 83ec0c ba???????? b9???????? }
- $sequence_25 = { 6a40 6a00 8bf7 57 81e60000ffff e8???????? 8b4608 }
- $sequence_26 = { ff15???????? a3???????? 391d???????? 7428 85c0 }
- $sequence_27 = { 8d4204 3bc8 7344 2bca 898de4fdffff 034e0c }
- $sequence_28 = { ff15???????? 85c0 7510 8d4864 }
- $sequence_29 = { 0f114710 0f104030 0f114f20 0f104840 0f114730 0f104050 }
- $sequence_30 = { 85c0 7550 ff15???????? 8bf8 893d???????? }
- $sequence_31 = { 6a1c 50 56 ff15???????? 8b4de8 }
- $sequence_32 = { 0f104010 0f110f 0f104820 0f114710 }
- $sequence_33 = { 0f114f50 0f104060 0f114760 8b4070 894770 be01000000 }
- $sequence_34 = { 8d4864 ff15???????? ffc3 83fb0a 7cd5 }
- $sequence_35 = { 0f104050 0f114f40 0f104860 0f114750 0f114f60 b801000000 }
+ $sequence_0 = { 50 8b35???????? 8b3d???????? 6a10 68???????? }
+ $sequence_1 = { 68fe000000 68???????? ffd7 83c408 }
+ $sequence_2 = { 68ac000000 68???????? e8???????? 68ac000000 68???????? ffd7 83c408 }
+ $sequence_3 = { c705????????ba514000 c705????????00020000 68fe000000 68???????? ffd6 83c408 68ff000000 }
+ $sequence_4 = { 68ac000000 68???????? e8???????? e8???????? }
+ $sequence_5 = { 68ff000000 68ac000000 68???????? e8???????? e8???????? 68ff000000 68ac000000 }
+ $sequence_6 = { ac 30c8 aa 4a 75f9 61 c9 }
+ $sequence_7 = { 68fe000000 68???????? e8???????? 68fe000000 }
+ $sequence_8 = { 68fe000000 68???????? e8???????? e8???????? 68ff000000 68fe000000 }
+ $sequence_9 = { 31c8 e8???????? 68ac000000 68???????? }
condition:
- 7 of them and filesize <516096
+ 7 of them and filesize <43008
}
-rule MALPEDIA_Win_Helminth_Auto : FILE
+rule MALPEDIA_Win_Microcin_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e8458d0c-0e53-5434-b94f-d27e99b6a572"
+ id = "7e85e39e-7daa-514d-802c-54d6ff85c6e9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.helminth"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.helminth_auto.yar#L1-L159"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.microcin"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.microcin_auto.yar#L1-L465"
license_url = "N/A"
- logic_hash = "40475479d37d8203c72424a48ad87a8ce641700a54f37b53283dc8f7df269c35"
+ logic_hash = "3f18992fe004fbfcac38bd4eed04ab5733b0957df603607ba4dee35273474322"
score = 75
- quality = 75
+ quality = 44
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -172486,37 +179513,72 @@ rule MALPEDIA_Win_Helminth_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { a1???????? 68e8030000 8907 e8???????? }
- $sequence_1 = { 83e61f c1e606 57 8b3c9d70750110 8a4c3704 }
- $sequence_2 = { 894c2408 8d9b00000000 668b02 83c202 6685c0 }
- $sequence_3 = { c1e106 899528e5ffff 53 8b149570750110 898d24e5ffff 8a5c1124 02db }
- $sequence_4 = { 85ff 0f84be000000 897de0 8b049d70750110 0500080000 3bf8 }
- $sequence_5 = { 03f2 eb5c 8b45f4 8b0c8570750110 f644190448 }
- $sequence_6 = { 80c980 884c3704 8b0c9d70750110 8a443124 2481 }
- $sequence_7 = { 2c2c 2c2c 232425???????? 2c2c 2c2c 2c2c }
- $sequence_8 = { e8???????? 59 6a64 ff15???????? 57 57 }
- $sequence_9 = { 8bf9 897c2410 e8???????? 8bcf }
- $sequence_10 = { 8a02 8b9524e5ffff 8b0c9d28eb4100 88440a34 8b049d28eb4100 c744023801000000 }
- $sequence_11 = { 663bc1 75f4 6a18 59 be???????? }
- $sequence_12 = { a1???????? eb0c c745e4a4ee4100 a1???????? 33db }
- $sequence_13 = { 83c102 663bc3 75f4 a1???????? 8bd7 }
- $sequence_14 = { 6a03 68???????? 8d0c458ce44100 8bc1 2d???????? d1f8 }
+ $sequence_0 = { 50 56 ff15???????? 85c0 0f45f7 }
+ $sequence_1 = { 442bc3 4803d6 4533c9 ff15???????? 85c0 75d9 488b742438 }
+ $sequence_2 = { ff15???????? 488bcb ff15???????? 448bc0 }
+ $sequence_3 = { 57 4154 4156 4157 488dac2400fbffff 4881ec00060000 488b05???????? }
+ $sequence_4 = { e8???????? 83c40c 8d85f8feffff 6804010000 50 ff15???????? 8d85f8feffff }
+ $sequence_5 = { 488b09 418bf8 488bf2 33db }
+ $sequence_6 = { ff15???????? 8b3d???????? 8d85e0feffff 50 }
+ $sequence_7 = { 488bcb 664489642438 488bf0 ff15???????? }
+ $sequence_8 = { 68ffff0000 56 8b35???????? ffd6 }
+ $sequence_9 = { 85c0 7e18 80bc35a8feffff3a 741f 8d85a8feffff 46 50 }
+ $sequence_10 = { c6840d8002000033 488d8d80020000 ff15???????? 4863c8 c6840d8002000079 }
+ $sequence_11 = { ff15???????? 8b1d???????? 8d85a8feffff 50 ffd3 }
+ $sequence_12 = { ff15???????? 4863c8 c6840d7002000062 488d8d70020000 ff15???????? 4863c8 }
+ $sequence_13 = { ff15???????? 85c0 7426 8b400c }
+ $sequence_14 = { 33f6 50 ffd3 85c0 7e18 }
+ $sequence_15 = { 488d4c2460 ff15???????? 4863c8 807c0c5f5c 7413 488d4c2460 ff15???????? }
+ $sequence_16 = { 41bc14030000 4c8d0574130100 488bcd 418bd4 e8???????? 33c9 85c0 }
+ $sequence_17 = { 83c108 51 ff15???????? 8b4dfc }
+ $sequence_18 = { 7370 696465726167656e 742e 657865 }
+ $sequence_19 = { 6e 6d 656e 7400 }
+ $sequence_20 = { 8b4510 8b8c8d78feffff 890c90 ebc8 e9???????? }
+ $sequence_21 = { 7647 498bcd e8???????? 4c8d05b7120100 41b903000000 }
+ $sequence_22 = { fa fa fa fa fa fa }
+ $sequence_23 = { 8b4df0 e8???????? 8d45f8 50 6a00 }
+ $sequence_24 = { 6828010000 8d85ccfeffff 6a00 50 }
+ $sequence_25 = { 418d7c24e7 85c0 752a 4c8d0502130100 8bd7 498bcd }
+ $sequence_26 = { 4c8d056c120100 498bd4 488bcd e8???????? 85c0 7541 4c8bc3 }
+ $sequence_27 = { 636373 7673 6873742e65 7865 }
+ $sequence_28 = { ff15???????? 8b45f4 8b4824 894dfc 8b55f4 83c208 }
+ $sequence_29 = { 8945fc eb42 8b45f8 33d2 }
+ $sequence_30 = { 8bd9 488d0d950c0100 ff15???????? 4885c0 7419 488d15730c0100 488bc8 }
+ $sequence_31 = { 488d15f8110100 41b810200100 488bcd e8???????? e9???????? 4533c9 4533c0 }
+ $sequence_32 = { 8b8504ffffff 898574feffff 8b4d0c 8b91fc020000 8b4508 0390f0040000 8b4d10 }
+ $sequence_33 = { 488bcd e8???????? 85c0 751a 488d15f8110100 41b810200100 }
+ $sequence_34 = { 8b55fc 83c208 52 ff15???????? 8b45fc c7400421000000 }
+ $sequence_35 = { 33c9 4889742420 e8???????? cc 4c8d056c120100 }
+ $sequence_36 = { 83ec08 894df8 c745fc00a40000 6a40 6800100000 6800a40000 6a00 }
+ $sequence_37 = { 49 53 53 56 43 }
+ $sequence_38 = { 8b4c2414 33cc e8???????? 8be5 5d c21000 57 }
+ $sequence_39 = { 0115???????? 1515151503 1515151515 1515041515 1515050607 0809 }
+ $sequence_40 = { 8d85e8feffff 50 ff95e4feffff 59 59 837d1c00 7513 }
+ $sequence_41 = { 8b8431f4dfffff 44 2bd8 45 2b9c31f8dfffff 45 895c2404 }
+ $sequence_42 = { 6a00 8d442448 50 ff15???????? 85c0 7420 }
+ $sequence_43 = { 8b4c2408 49 8b542410 e8???????? 85c0 74db 89c0 }
+ $sequence_44 = { f7f7 8365ec00 85c0 0f8e94010000 8365f000 8b7e44 }
+ $sequence_45 = { 89f1 48 8d5510 e8???????? 90 e8???????? bab3c4b3c4 }
+ $sequence_46 = { 6a00 8d85b0feffff 50 56 }
+ $sequence_47 = { 6a00 56 c785b4feffff00000000 ff15???????? 50 56 }
+ $sequence_48 = { 8d44245c 50 ff15???????? 33c0 5f }
+ $sequence_49 = { c744241030000000 c744241403000000 c7442418d0114000 c744241c00000000 c744242000000000 89742424 c744242800000000 }
condition:
- 7 of them and filesize <479232
+ 7 of them and filesize <417792
}
-rule MALPEDIA_Win_Sappycache_Auto : FILE
+rule MALPEDIA_Win_Cookiebag_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ad4dab53-cb13-5a84-86d5-edc74e26f321"
+ id = "c260d983-1fb1-5187-bb1e-a30d172d6701"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sappycache"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sappycache_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cookiebag"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cookiebag_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "f4483696db263dfbbabb83dfce8ccde9309b112a65cf425cc63ed3dc1fcead40"
+ logic_hash = "74595c8c00c27ebea5fcf6294fdb19b48126392d3364dc5a9bcc9f574cb25599"
score = 75
quality = 75
tags = "FILE"
@@ -172530,32 +179592,32 @@ rule MALPEDIA_Win_Sappycache_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 448bcf 895c2428 33d2 33c9 4889442420 488bf0 ff15???????? }
- $sequence_1 = { ff15???????? 85c0 7428 488bcd 488d1545f80000 }
- $sequence_2 = { 488b8188000000 488d0d16fa0000 4883c018 7452 8bd7 0f1000 }
- $sequence_3 = { ff15???????? 41b904000000 c7452060ea0000 4c8d4520 }
- $sequence_4 = { 4c8d0dd6860000 c5f35cca c4c173590cc1 4c8d0da5760000 c5f359c1 }
- $sequence_5 = { 49ffc0 47382c04 75f7 488d157c1f0100 }
- $sequence_6 = { 4c89742430 448bcf 895c2428 33d2 33c9 4889442420 }
- $sequence_7 = { f20f1000 8b7808 e9???????? 488d05eed70000 4a8b0ce8 42f644313880 744d }
- $sequence_8 = { 4c8d0d136d0000 8bf9 488d15ba4d0000 b906000000 4c8d05f66c0000 e8???????? }
- $sequence_9 = { 4180e003 80e30f 41c0e004 440ac0 }
+ $sequence_0 = { 0f8e39050000 8a442437 bf???????? 88442424 83c9ff 33c0 33ed }
+ $sequence_1 = { 51 8b4c2414 55 e8???????? 84c0 7412 8b442418 }
+ $sequence_2 = { 51 e8???????? 83c404 eb1d 8b4608 8b7604 3bf3 }
+ $sequence_3 = { 50 53 52 e8???????? 8bce e8???????? 8b4c2428 }
+ $sequence_4 = { 83c1fe 51 e8???????? 83c404 8b4c242c 897c243c 3bcf }
+ $sequence_5 = { e8???????? 68???????? e8???????? 83c404 8bd8 8dbe14010000 6a01 }
+ $sequence_6 = { 895c2428 e8???????? 84c0 7427 8b7c2418 8bcd }
+ $sequence_7 = { 85c0 7454 8b87dc000000 85c0 764a 8b44240c }
+ $sequence_8 = { e8???????? 83c414 b001 5f 5e c20400 5f }
+ $sequence_9 = { 6a01 8d4c241c c7442444ffffffff e8???????? 8b4c2438 64890d00000000 }
condition:
- 7 of them and filesize <262144
+ 7 of them and filesize <311296
}
-rule MALPEDIA_Elf_Hideandseek_Auto : FILE
+rule MALPEDIA_Win_Shareip_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8886e955-536d-56f5-a630-bf2b9ef8b07e"
+ id = "1e2be420-f7e3-538b-a25d-892f460d058e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.hideandseek"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.hideandseek_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shareip"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shareip_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "c312d2a4b534a00f51e15be6e1572c868a1bf84ffb4d93cf13ce0449e347f5bb"
+ logic_hash = "22b55834a3d563030497f1fde153bdd0a045ee32bc87427f1091c9e8cd08bbb9"
score = 75
quality = 75
tags = "FILE"
@@ -172569,32 +179631,32 @@ rule MALPEDIA_Elf_Hideandseek_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 83ec14 8b44242c 8a5c2430 ff7004 ff74242c e8???????? }
- $sequence_1 = { e8???????? 83c410 84c0 752e 83ec0c 8d84241c120000 50 }
- $sequence_2 = { 8d44244c 50 e8???????? 5b 8d442440 50 e8???????? }
- $sequence_3 = { 89ca 8b0424 0fa4d91e 31c8 8b4c2430 0fa4d31e 8b542404 }
- $sequence_4 = { 7411 0f821e040000 83f802 0f8508040000 eb04 50 50 }
- $sequence_5 = { be00000000 b800000000 c1e210 09c6 c1e718 31db 0fb64504 }
- $sequence_6 = { 50 e8???????? 83c410 84c0 741a 8b542414 c7434403000000 }
- $sequence_7 = { 817e0c00010000 751a 8d5610 8d4650 53 68c0000000 50 }
- $sequence_8 = { 56 53 8b7c2410 803d????????00 7561 83ec0c 6800000011 }
- $sequence_9 = { 50 8b8424ec000000 ff7008 e8???????? 89f2 8b8424f0000000 }
+ $sequence_0 = { 8d8534feffff e9???????? 8d8da8feffff e9???????? 8d8558feffff e9???????? 8d8544ffffff }
+ $sequence_1 = { 894638 85c9 740f 8bd0 8d4900 8a01 8802 }
+ $sequence_2 = { 8a8064954500 08443b1d 0fb64601 47 3bf8 76ea 8b7d08 }
+ $sequence_3 = { 395c2444 7426 3bc3 7422 50 e8???????? 8b4c2444 }
+ $sequence_4 = { 834dfcff 894614 83c40c 8d45e4 50 e8???????? 8b07 }
+ $sequence_5 = { 8b44241c 50 8d8c24a0010000 51 53 53 53 }
+ $sequence_6 = { 55 8d4c245c e8???????? 8bd8 895c2414 83fbff 7541 }
+ $sequence_7 = { 837de800 7e50 8b03 8b4804 0fb7541930 8d0419 8b4828 }
+ $sequence_8 = { 8b9a80f34400 33f3 8b4538 33db 8b553c 33c6 33d6 }
+ $sequence_9 = { 33c0 eb05 1bc0 83d8ff 3bc3 7506 895c2418 }
condition:
- 7 of them and filesize <196608
+ 7 of them and filesize <811008
}
-rule MALPEDIA_Win_Darkrat_Auto : FILE
+rule MALPEDIA_Win_Asruex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "73555b6d-cd36-53aa-b241-54638d6391a7"
+ id = "899abd0f-c835-5f70-819c-92570cc9b462"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkrat_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.asruex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.asruex_auto.yar#L1-L112"
license_url = "N/A"
- logic_hash = "e98d828b961bffb4ad606aad50a055367532a60432b86ca76a8c360da1aac44b"
+ logic_hash = "a14db0e4e44f1156fe16afe843345aa29b9b1f1eb3cc060b10e0bcdf06eb97d4"
score = 75
quality = 75
tags = "FILE"
@@ -172608,34 +179670,34 @@ rule MALPEDIA_Win_Darkrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 837de810 895510 8b4804 8d45d4 0f4345d4 2975b4 }
- $sequence_1 = { 51 03f8 52 57 e8???????? 8b45c8 83c40c }
- $sequence_2 = { 51 56 e8???????? 83c40c c6043e00 eb17 57 }
- $sequence_3 = { 8b7dd4 0f8514ffffff 8b55ec 83fa10 }
- $sequence_4 = { 8bd0 b805000000 2bd6 8a0e 8d7601 884c32ff 83e801 }
- $sequence_5 = { e8???????? 83c408 c745e800000000 8d4dd8 }
- $sequence_6 = { 0b510c 52 e8???????? c745fc04000000 e8???????? 84c0 7507 }
- $sequence_7 = { 83c408 c745e800000000 8d4dd8 c745ec0f000000 c645d800 }
- $sequence_8 = { ff75d0 51 8bcb e8???????? 8b75b8 c645fc01 }
- $sequence_9 = { 895510 8b4804 8d45d4 0f4345d4 2975b4 03c6 ff75b4 }
+ $sequence_0 = { 85c0 740e 85ed 740a }
+ $sequence_1 = { 7408 3c0d 7404 3c0a 7516 }
+ $sequence_2 = { 83f801 740e 83f803 7409 83f802 }
+ $sequence_3 = { ff15???????? 85c0 7407 3d14270000 }
+ $sequence_4 = { 740c 3c09 7408 3c0d 7404 3c0a 7516 }
+ $sequence_5 = { 7404 3c58 7505 bb01000000 }
+ $sequence_6 = { 3c09 7408 3c0d 7404 3c0a 7516 }
+ $sequence_7 = { 3c78 7404 3c58 7505 bb01000000 }
+ $sequence_8 = { 3c0d 7404 3c0a 7516 }
+ $sequence_9 = { e8???????? 83f8ff 7407 3d0000a000 }
condition:
- 7 of them and filesize <884736
+ 7 of them and filesize <1564672
}
-rule MALPEDIA_Win_Nymaim_Auto : FILE
+rule MALPEDIA_Win_Makadocs_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6fe09b40-4e7e-5960-9e2c-823057d831db"
+ id = "a9ee5e42-4244-5209-b209-43e241078b80"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nymaim"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nymaim_auto.yar#L1-L281"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.makadocs"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.makadocs_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "0c0c73586cb65f92c931bae46a77127eb659bbbab03ac07a837f2712a17a227b"
+ logic_hash = "9e569b2ca005ed56a66b13fc4754517215725a380988d948b175ea6348c2d54c"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -172647,51 +179709,32 @@ rule MALPEDIA_Win_Nymaim_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89d8 01c8 31d2 f7f7 }
- $sequence_1 = { 0f94c1 09c8 6bc064 09c0 }
- $sequence_2 = { 31d2 f7f7 92 31d2 }
- $sequence_3 = { 92 31d2 bf64000000 f7f7 }
- $sequence_4 = { c1e105 01c8 c1c307 30c3 }
- $sequence_5 = { 31c9 38f0 83d100 38d0 83d900 c1e105 }
- $sequence_6 = { c1eb13 331d???????? 31c3 c1e808 }
- $sequence_7 = { 00d3 8a16 301e 46 01fb }
- $sequence_8 = { 8b12 8b4d0c 8b5d18 8b1b 4f 31c0 fec2 }
- $sequence_9 = { 8b4e08 014e04 8b5e0c 015e08 }
- $sequence_10 = { c1e808 31c3 895e0c 89d8 }
- $sequence_11 = { f7e0 0fc8 01d0 894704 }
- $sequence_12 = { 8b06 c1e00b 3306 8b5604 0116 8b4e08 014e04 }
- $sequence_13 = { 53 56 57 83ec44 8b4508 8d0d2030d201 }
- $sequence_14 = { 4409df 4531d0 813d????????7147ed3a 0f84c06efdff 4421da 4431c7 c1c703 }
- $sequence_15 = { 0f84e0bffcff 443b642460 72b4 85ff 7439 837c246000 7628 }
- $sequence_16 = { 4531c9 488d442440 813d????????00e8e23a 0f84c1f7feff 31d2 48b9????????00000000 488903 }
- $sequence_17 = { 448915???????? 8b4548 89442448 488b8588000000 4889442440 488b8580000000 4889442438 }
- $sequence_18 = { 56 83ec28 8b450c 8b4d08 8d154e30d201 }
- $sequence_19 = { 55 89e5 83ec10 8b4508 8d0d3430d201 }
- $sequence_20 = { 83ec44 8b4508 8d0d2030d201 31d2 890c24 c744240400000000 }
- $sequence_21 = { 0f9e05???????? 4c89fa e8???????? 488d542440 488d8da0000000 890d???????? 8805???????? }
- $sequence_22 = { 4439a19c000000 0f8456bffcff 4439a194000000 48c705????????b2228979 0f8545bffcff 8b7108 458d6c2401 }
- $sequence_23 = { 31ed e8???????? 0fb7542430 488d4c2420 0fb7442432 4189d8 c1e209 }
- $sequence_24 = { 5b 5d c3 8b45f0 8b0c850440d201 }
- $sequence_25 = { 890424 894c2404 e8???????? 8d0d3430d201 }
- $sequence_26 = { 31c9 8b55f4 8b75ec 89723c c7424003000000 }
- $sequence_27 = { 4529d8 4489da 4801ca e8???????? 66813d????????a8c1 0f848bbe0000 44295b68 }
- $sequence_28 = { 31d2 890c24 c744240400000000 8945f4 8955f0 e8???????? 8d0d8630d201 }
+ $sequence_0 = { 8b5d08 56 57 33f6 33ff 897dfc 3b1cfdf0524200 }
+ $sequence_1 = { 8bc6 89a554ffffff 8bfc e8???????? 83c010 8907 51 }
+ $sequence_2 = { 8b42f4 8d7001 8b42f8 b901000000 2b4afc 2bc6 0bc1 }
+ $sequence_3 = { 83c408 52 8b54243c 8d442438 50 8d4c2478 51 }
+ $sequence_4 = { 83c408 c644246834 8b00 8d4c2420 51 8bc8 e8???????? }
+ $sequence_5 = { 8b442410 56 e8???????? 85f6 7409 }
+ $sequence_6 = { c645fc41 8bc4 89a54cffffff 50 b9???????? e8???????? 8dbd54ffffff }
+ $sequence_7 = { ffd5 8b06 3b78f8 7f0f 8978f4 8b0e c6040f00 }
+ $sequence_8 = { 8b4c2410 51 ffd7 85c0 744c 8b44241c 50 }
+ $sequence_9 = { 3c09 0fb6c0 7605 83c037 eb03 83c030 8806 }
condition:
- 7 of them and filesize <2375680
+ 7 of them and filesize <344064
}
-rule MALPEDIA_Win_Carbanak_Auto : FILE
+rule MALPEDIA_Win_Lazarloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c07fe935-504c-5c98-a746-fcd9d2cd2656"
+ id = "eeec4f28-0f22-51be-ae2e-de44f3255986"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.carbanak"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.carbanak_auto.yar#L1-L108"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lazarloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lazarloader_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "71119e0e8f2ea511e845d7f70364c6b521841c48aa27c3226400782c05c0bf22"
+ logic_hash = "2c7bcf20b8b4c12e652b091953d52f7cafa589f18b8b9e18e7eefdba4a60b648"
score = 75
quality = 75
tags = "FILE"
@@ -172705,34 +179748,34 @@ rule MALPEDIA_Win_Carbanak_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7f05 83c061 eb03 83c027 }
- $sequence_1 = { 7907 32c0 e9???????? 7507 b001 }
- $sequence_2 = { 32c0 e9???????? 7507 b001 }
- $sequence_3 = { 2bd1 81e921100000 8bc1 c1f80e 0cc0 }
- $sequence_4 = { 8b4608 eb02 8bc3 85c0 }
- $sequence_5 = { c3 8d4120 3c1f 7705 0fb6c1 }
- $sequence_6 = { 7c0d e8???????? 84c0 7504 }
- $sequence_7 = { 7c0d e8???????? 84c0 7504 33c0 }
- $sequence_8 = { e9???????? 3d2c5c0700 750a e8???????? }
- $sequence_9 = { 3d2c5c0700 750a e8???????? e9???????? }
+ $sequence_0 = { 483b0d???????? 7417 488d059c4f0100 483bc8 }
+ $sequence_1 = { 7528 48833d????????00 741e 488d0d30a80100 e8???????? 85c0 740e }
+ $sequence_2 = { 8bc2 488d154241ffff c1e803 89442438 448be0 89442440 85c0 }
+ $sequence_3 = { 488d0563810000 488bd9 483bc8 7417 8b815c010000 }
+ $sequence_4 = { 4889542410 48894c2408 57 4881ece0080000 33c0 66898424a0000000 488d8424a2000000 }
+ $sequence_5 = { 4c8bea 4b8b8cf770c10100 4c8b15???????? 4883cfff 418bc2 498bd2 4833d1 }
+ $sequence_6 = { 8bcf e8???????? 488bd7 4c8d05fecd0000 83e23f 488bcf 48c1f906 }
+ $sequence_7 = { 48897018 48897820 4156 33ed 4c8d35e6900000 448bd5 488bf1 }
+ $sequence_8 = { e8???????? 488bd7 4c8d05fecd0000 83e23f }
+ $sequence_9 = { 488bda 4c8d0d6bad0000 8bf9 488d15a2930000 b906000000 }
condition:
- 7 of them and filesize <658432
+ 7 of them and filesize <364544
}
-rule MALPEDIA_Win_Daserf_Auto : FILE
+rule MALPEDIA_Win_Beepservice_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fffb2935-58a7-5828-bf22-dd469fea2b59"
+ id = "1d7d7c47-2c0e-5f10-8d42-753504cd309b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.daserf"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.daserf_auto.yar#L1-L167"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.beepservice"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.beepservice_auto.yar#L1-L282"
license_url = "N/A"
- logic_hash = "194f8b1f42d6928a216ace153b63a40c6d813ea5df60a79ed82a9b2168ff69ee"
+ logic_hash = "1b28ba46a772486fbc8465a9c3e2af5f383317dc6efaca43bb04db774c11995d"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -172744,38 +179787,51 @@ rule MALPEDIA_Win_Daserf_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945cc ff15???????? 8945d0 8d45b4 }
- $sequence_1 = { b808380000 e8???????? 53 56 }
- $sequence_2 = { 81eb7ee5b031 81c30d782341 81c3db5d1091 81eb73ad763b 054ce1128c 81c3cc3c3014 }
- $sequence_3 = { 81c3ad482863 81eb8c570d21 2d21583cc4 2da932ed1b 81c3f8ff2857 81eb46159323 }
- $sequence_4 = { 81eb4e0e3377 87c0 81ebfb04024c 87ff 2dfaa67876 }
- $sequence_5 = { 81c394c7d041 81eb6afed62a 81c3bed1834b 81eb826387e9 81c3d7e98170 2d844df6b2 }
- $sequence_6 = { 50 ffd6 ffb56814ffff 8d85bc4fffff 50 }
- $sequence_7 = { 2d4936916d f7d1 f7d1 2d99d06187 f7d1 f7d1 }
- $sequence_8 = { 8bc9 81c3c9920a05 95 89ac2400f2ffff }
- $sequence_9 = { 7500 81c3e109e0f6 8bc0 0537d68276 9b 81c38da225f6 87c9 }
- $sequence_10 = { eb0e ff75fc ffd7 3bf3 7403 56 }
- $sequence_11 = { 81c327f27a10 7500 81ebc884a519 7500 81eb3a0de80d 87db 81c3b119330a }
- $sequence_12 = { 2d4abc1884 90 2dea9bf526 7500 }
- $sequence_13 = { 81ebf74ea63a f7d1 f7d1 81eb199760ae 9b }
- $sequence_14 = { 2d966cdd4c 2d81c26ac5 81c32b73f252 81c32bef6e96 81c3b4dacce0 }
- $sequence_15 = { 81eb075e2ddb 9b 81c35a11e727 97 89bc2440f5ffff }
+ $sequence_0 = { ffd6 8bc8 ff15???????? 50 }
+ $sequence_1 = { 8b0d???????? 68???????? ffd6 8bc8 }
+ $sequence_2 = { e8???????? 83f801 7505 e8???????? 68???????? 68???????? }
+ $sequence_3 = { 7512 6888130000 68???????? e8???????? 83c408 }
+ $sequence_4 = { 83c408 e9???????? 68???????? e8???????? 83c404 6a00 }
+ $sequence_5 = { 683f000f00 6a00 68???????? ff15???????? }
+ $sequence_6 = { ff7604 68???????? e8???????? ff7608 e8???????? 83c40c }
+ $sequence_7 = { 83ffff 750e ff15???????? 50 68???????? eb43 }
+ $sequence_8 = { 68???????? 57 ff15???????? 85c0 741c 3975fc }
+ $sequence_9 = { ff7604 e8???????? 83f814 59 }
+ $sequence_10 = { e8???????? 83f820 59 730f ff7618 68???????? e8???????? }
+ $sequence_11 = { e8???????? ff7610 e8???????? 50 ff7610 53 e8???????? }
+ $sequence_12 = { 83c410 8d4c2408 6a00 6a00 }
+ $sequence_13 = { bf???????? a3???????? 83c404 a3???????? a3???????? 66a3???????? f3ab }
+ $sequence_14 = { 85c0 742b 817c240400240000 7521 56 }
+ $sequence_15 = { ffd7 8d442414 50 56 }
+ $sequence_16 = { 8bca 83e103 f3a4 8b7314 83c9ff 8bfe }
+ $sequence_17 = { e8???????? 83c404 50 8b4d0c 8b5114 }
+ $sequence_18 = { e8???????? 83c408 33c0 e9???????? c785f8fdffff00240000 6a00 8d95f4fdffff }
+ $sequence_19 = { 8b0d???????? ff15???????? 8bc8 ff15???????? 8b15???????? 52 }
+ $sequence_20 = { 8b511c 52 e8???????? 83c404 83f820 }
+ $sequence_21 = { 6a01 6a00 6a00 6a05 e8???????? 83c414 }
+ $sequence_22 = { e8???????? 6a00 6a00 b907000000 6a00 }
+ $sequence_23 = { c3 68e8030000 6a02 6a00 6a00 6a02 }
+ $sequence_24 = { 6a04 e8???????? 83c414 85c0 7510 ff15???????? }
+ $sequence_25 = { 50 53 c744241428010000 e8???????? }
+ $sequence_26 = { bf???????? 83c9ff 33d2 b301 f2ae f7d1 49 }
+ $sequence_27 = { b90a000000 be???????? bf???????? 33c0 f3a5 bf???????? 83c9ff }
+ $sequence_28 = { 52 89442424 ff15???????? 8bf0 85f6 7505 }
condition:
- 7 of them and filesize <245760
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Ransoc_Auto : FILE
+rule MALPEDIA_Win_Pipemon_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "961c0c93-e6c6-5111-8367-8742ed436406"
+ id = "fb1257dc-1899-57a8-9bb3-37873100ec17"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ransoc"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ransoc_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pipemon"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pipemon_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "2d366ed2132c1270c1bab4c471d75e367a89089f653123f697fac204fd95b124"
+ logic_hash = "a7cf49399560b8b73200f34644a487f3922c8589009d7d641339ef3a3238ec7b"
score = 75
quality = 75
tags = "FILE"
@@ -172789,32 +179845,32 @@ rule MALPEDIA_Win_Ransoc_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b573c 50 57 ffd2 ff4e3c 8b462c 8b4e3c }
- $sequence_1 = { 8bf0 8b5630 57 8d7e30 }
- $sequence_2 = { 894240 8b5040 895140 3bd7 741e }
- $sequence_3 = { 89703c 8b5134 895030 3bd7 7406 8b5134 }
- $sequence_4 = { 85c0 75f2 8b7140 85f6 758b 68???????? }
- $sequence_5 = { 740f 83f907 740a 83f906 }
- $sequence_6 = { 89462c a820 7406 8b4604 014804 8b462c a900080000 }
- $sequence_7 = { 895148 8b4830 85c9 7406 8b5034 895134 8b4834 }
- $sequence_8 = { 83c408 c3 6a00 6a01 55 }
- $sequence_9 = { 8b56e4 89542414 8d5c2410 891a 89442410 8b5004 8956e4 }
+ $sequence_0 = { 418bf8 4903fe 85db 0f84a1000000 6690 49634e3c }
+ $sequence_1 = { 7516 488d05bd360100 488b4c2430 483bc8 7405 e8???????? 488b05???????? }
+ $sequence_2 = { 85c0 7427 488b4c2438 488d1526d90000 ff15???????? }
+ $sequence_3 = { b906000000 48898620020000 0fb7c0 66f3ab 488d3d2c3b0100 }
+ $sequence_4 = { 488d4c2438 e8???????? 4c8d4820 4889442420 4c8bc3 488d5590 488d4c2438 }
+ $sequence_5 = { 4881c458010000 c3 83f801 7529 b803000000 488b8c2440010000 4833cc }
+ $sequence_6 = { 458d4d02 458bc7 488d542450 488bc8 }
+ $sequence_7 = { e8???????? 4881c498000000 c3 448b442430 488d1543fe0100 33c0 488d4c2440 }
+ $sequence_8 = { ffc8 3d03010000 7734 488d44244c 488bd7 }
+ $sequence_9 = { 80bd8008000000 0f84b6010000 4d85ed 0f84b6000000 }
condition:
- 7 of them and filesize <958464
+ 7 of them and filesize <389120
}
-rule MALPEDIA_Win_Ramdo_Auto : FILE
+rule MALPEDIA_Win_Oni_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5b8e6fef-0e3b-5ed2-888f-7434293b69d6"
+ id = "ffe7d6a1-e7f2-579d-b056-7e9412d8f38a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ramdo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ramdo_auto.yar#L1-L104"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.oni"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.oni_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "915394834672872c9dd5e507ba31a9e70d058b5fc9e0d5522912234c2f6ee339"
+ logic_hash = "ef51460421d5bc54251bcf8ac5edcdde6a15b31e2116a2189b470d64d9b9ae34"
score = 75
quality = 75
tags = "FILE"
@@ -172828,32 +179884,32 @@ rule MALPEDIA_Win_Ramdo_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6813299e13 6a00 6a00 e8???????? }
- $sequence_1 = { ff55f8 8945fc 837dfcff 7411 }
- $sequence_2 = { 688fe57c18 6a03 6a00 e8???????? }
- $sequence_3 = { 681186933f 6a03 6a00 e8???????? }
- $sequence_4 = { 68b20cdc96 6a03 6a00 e8???????? }
- $sequence_5 = { 6a00 6a00 ff95dcfeffff 8945fc }
- $sequence_6 = { e8???????? 3db7000000 7405 8b45fc }
- $sequence_7 = { 681b313f7d 6a03 6a00 e8???????? }
- $sequence_8 = { 68e9b528b6 6a03 6a00 e8???????? }
- $sequence_9 = { 68c29e34ea 6a03 6a00 e8???????? }
+ $sequence_0 = { 50 8d4db0 c645b000 e8???????? 8b0d???????? b8abaaaa2a 8b3d???????? }
+ $sequence_1 = { 83f904 0f828d000000 83f923 0f8789000000 8bc8 }
+ $sequence_2 = { ff75ec 51 ff36 8b55e8 8bcb e8???????? 83c410 }
+ $sequence_3 = { 7f07 3bc7 0f4fd8 8bfb 6aff 8d4701 }
+ $sequence_4 = { 3a45ec 753e 8b45f0 8b048590884300 }
+ $sequence_5 = { 8d0dc0254300 ba1b000000 e9???????? a900000080 }
+ $sequence_6 = { 660fd685c8feffff 33ff 6800010000 899dc8feffff 89bdccfeffff 899dd0feffff ff15???????? }
+ $sequence_7 = { 8901 0fb602 5f 5e 5b 8b4c2430 33cc }
+ $sequence_8 = { 8b542428 8b442414 85f6 0f8422ffffff }
+ $sequence_9 = { f6c104 7519 f6c102 8d4df8 7540 eb6a }
condition:
- 7 of them and filesize <548864
+ 7 of them and filesize <499712
}
-rule MALPEDIA_Win_Newcore_Rat_Auto : FILE
+rule MALPEDIA_Win_Powerduke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "665a19c1-0b9c-5837-8284-a9e9fed7fabd"
+ id = "6d856194-c9fe-5330-9bd8-d5a96e01d2f2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.newcore_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.newcore_rat_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.powerduke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.powerduke_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "bc0ab135cc137a5ffe441affd5712e460cc93f003c5dd205f806c56bc27b56a3"
+ logic_hash = "8396f645fb90ff46635658086ca415f6d857b1da2dac7ff489b34d4ef5885286"
score = 75
quality = 75
tags = "FILE"
@@ -172867,32 +179923,32 @@ rule MALPEDIA_Win_Newcore_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b08 8b11 50 8b4204 ffd0 8d4c2414 e8???????? }
- $sequence_1 = { 898670300000 e8???????? 5f 5d b801000000 }
- $sequence_2 = { 51 8d4c243c e8???????? 8d4c2414 e8???????? 8b542448 52 }
- $sequence_3 = { 50 8d4c245e 51 6689442460 e8???????? 83c40c 6a30 }
- $sequence_4 = { 6a00 6a00 8d542478 52 6a00 ff15???????? 85c0 }
- $sequence_5 = { 8b442450 e9???????? 6830020000 8d442458 6a00 50 }
- $sequence_6 = { 8b8610100000 85c0 740d 50 ffd7 c7861010000000000000 }
- $sequence_7 = { 5b c21000 8d9344020000 68???????? 52 e8???????? 8bf0 }
- $sequence_8 = { 83c40c 03f9 014c2414 eb04 8b5c240c 014c242c b81f85eb51 }
- $sequence_9 = { 68???????? 8d9424ac060000 e8???????? 83c408 53 8d8c24a8060000 }
+ $sequence_0 = { c705????????00000000 6a04 6800300000 ff7518 }
+ $sequence_1 = { ff75e4 ff75bc ff15???????? 09c0 7473 }
+ $sequence_2 = { 6a00 ff15???????? 09c0 0f8412010000 8945e4 53 50 }
+ $sequence_3 = { b801000000 c9 c20c00 55 89e5 81ec080c0000 }
+ $sequence_4 = { 89f7 31c9 803c0f3a 7409 }
+ $sequence_5 = { 09c0 7505 b850000000 8945ec c6040e00 }
+ $sequence_6 = { c70000000000 837d2000 740f 8b4520 }
+ $sequence_7 = { c20400 55 89e5 56 57 8b750c }
+ $sequence_8 = { 0f8493000000 c745f901000000 89c3 be???????? }
+ $sequence_9 = { 6a00 57 ff15???????? 09c0 }
condition:
- 7 of them and filesize <581632
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Veiledsignal_Auto : FILE
+rule MALPEDIA_Win_Makloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "caf6fec1-c7fc-5e46-9ec5-501cbcaa1f6a"
+ id = "66719c32-80e8-5417-8026-25e6d48fb7fe"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.veiledsignal"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.veiledsignal_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.makloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.makloader_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "36bfcf538a747481c06e92b8c775b0fad665f748b3dccf3367e494f75f4840ed"
+ logic_hash = "5f1f26214c5086a379f59348aefd7c2032c0ef40c82a5b49aca00ae5277c9d78"
score = 75
quality = 75
tags = "FILE"
@@ -172906,32 +179962,32 @@ rule MALPEDIA_Win_Veiledsignal_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7516 488d05c7390400 4a8b04e8 42385cf839 0f84c2000000 488d05b1390400 }
- $sequence_1 = { 488d0dbabb0400 48c7040102000000 b808000000 486bc000 488b0d???????? 48894c0420 b808000000 }
- $sequence_2 = { 0f1f440000 488d54244c 488bce e8???????? 488bcb }
- $sequence_3 = { 4881c458010000 c3 83f802 7571 488d0516010000 488905???????? 488d0529010000 }
- $sequence_4 = { 7ec4 83c8ff eb0b 4803f6 418b84f7a8140100 85c0 }
- $sequence_5 = { 81f95a290000 752b 488d0df8030000 b801000000 48890d???????? }
- $sequence_6 = { 4c8d0d97960000 498bd1 448d4008 3b0a 742b ffc0 }
- $sequence_7 = { e8???????? 488bd7 4c8d05e3270400 83e23f 488bcf 48c1f906 }
- $sequence_8 = { 4883ec20 8b1d???????? eb1d 488d0573b10400 ffcb }
- $sequence_9 = { ff15???????? 488b55cf 488bc8 ff15???????? 488b4dd7 }
+ $sequence_0 = { 8a11 88955ce6ffff 838530e6ffff01 80bd5ce6ffff00 }
+ $sequence_1 = { 8d45f0 64a300000000 f2c3 8b4de4 33cd f2e8a8e9feff }
+ $sequence_2 = { 8d8de4fcffff 898d30e5ffff 8d95d8e5ffff 899534e5ffff 8d8530e5ffff 50 }
+ $sequence_3 = { 8b45d4 50 e8???????? 83c408 8945d4 837dd000 }
+ $sequence_4 = { 8b9540e5ffff 8bca c1e902 f3a5 8bca }
+ $sequence_5 = { 68???????? e8???????? 83c404 83f0ff 50 0fb695e5e5ffff }
+ $sequence_6 = { 3bf3 72e9 5f 5e 5b c3 56 }
+ $sequence_7 = { 51 e8???????? 83c404 ba01000000 6bca05 8b5508 }
+ $sequence_8 = { 8d95e0f3ffff 52 8d8d70e6ffff e8???????? 8d8570ffffff }
+ $sequence_9 = { 89856ce6ffff 6a4b 6a00 8d55b0 52 e8???????? 83c40c }
condition:
- 7 of them and filesize <667648
+ 7 of them and filesize <335872
}
-rule MALPEDIA_Win_Turnedup_Auto : FILE
+rule MALPEDIA_Win_Dircrypt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "317b79ff-9d3d-5ba0-8921-2dd0758e0502"
+ id = "b395b5b7-d790-5f9f-ab3c-658138d51b34"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.turnedup"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.turnedup_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dircrypt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dircrypt_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "41dd089d435e4495b4c527e58471affc57ceb5820e7069ad3a735daa64e32911"
+ logic_hash = "9b92693268fddc2e1dd801012d692fa19a40b6fbb8b33ec64e384964127e0228"
score = 75
quality = 75
tags = "FILE"
@@ -172945,32 +180001,32 @@ rule MALPEDIA_Win_Turnedup_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4dfc 5f 5e 33cd 895004 5b }
- $sequence_1 = { 7706 891d???????? ff0d???????? 7506 891d???????? 6a01 }
- $sequence_2 = { 8b07 8b4004 03c7 33d2 8955dc c645e001 8b4838 }
- $sequence_3 = { 895dfc 752b 6a00 8d4df8 e8???????? 833d????????00 }
- $sequence_4 = { 68???????? 8819 e8???????? 8d7dac }
- $sequence_5 = { c746180f000000 894614 56 884604 e8???????? 83c404 }
- $sequence_6 = { 830801 8b4dd8 394dc0 741e 837dd000 }
- $sequence_7 = { 8945bc 8975b0 8b55f4 8b45e0 83fa10 7303 8d45e0 }
- $sequence_8 = { 8ad5 c0ea04 80e203 02d0 8a45f6 8855f8 8ad0 }
- $sequence_9 = { 8b45bc 8a11 8810 8b0b 40 }
+ $sequence_0 = { 7531 c705????????01000000 e8???????? e8???????? 833d????????00 7514 68???????? }
+ $sequence_1 = { e8???????? e8???????? 68???????? ff15???????? 833d????????00 751a }
+ $sequence_2 = { 68???????? e8???????? 05d2070000 50 e8???????? a3???????? 6a13 }
+ $sequence_3 = { 8bec 51 6a00 6a00 8d45fc 50 68???????? }
+ $sequence_4 = { 68???????? 8d45dc 50 e8???????? 6a00 e8???????? }
+ $sequence_5 = { 6801000080 e8???????? e8???????? e8???????? e8???????? }
+ $sequence_6 = { e8???????? 05d5070000 50 6a01 6a02 6a08 }
+ $sequence_7 = { 68???????? 8d45dc 50 e8???????? 6a00 e8???????? 05d6070000 }
+ $sequence_8 = { 833d????????00 7514 68???????? 68???????? e8???????? a3???????? 833d????????00 }
+ $sequence_9 = { 51 6a00 6a00 8d45fc 50 68???????? 6802000080 }
condition:
- 7 of them and filesize <892928
+ 7 of them and filesize <671744
}
-rule MALPEDIA_Win_Bit_Rat_Auto : FILE
+rule MALPEDIA_Win_Sidewinder_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "49210a4b-5430-57e8-a054-5667e0ae3196"
+ id = "476f112b-78c8-59d9-8623-54ca0fa7fd69"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bit_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bit_rat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sidewinder"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sidewinder_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "eb9ba4fd39163b3bb9047c43b4366afc9171afe908b68fc3b3d7fbbef1990e08"
+ logic_hash = "eff1c6e4779cf645096e1bcfd05e39d6cbab1c4bd8a928e81992c305a580a163"
score = 75
quality = 75
tags = "FILE"
@@ -172984,32 +180040,32 @@ rule MALPEDIA_Win_Bit_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c9 753f 6a00 6a00 68c1000000 6809020000 6a28 }
- $sequence_1 = { ff7608 ff74241c e8???????? 8be8 83c408 85ed 7425 }
- $sequence_2 = { e8???????? 8be8 83c408 85ed 7930 6a00 6a00 }
- $sequence_3 = { 8be5 5d c3 8b4510 8320b7 c7400400000000 33c0 }
- $sequence_4 = { e8???????? 83c408 85c0 74cf 894704 8b450c 895f10 }
- $sequence_5 = { f20f114af8 f20f1142f0 0fbf06 660f6ec8 0fbf46fe 83c608 f30fe6c9 }
- $sequence_6 = { f644242401 895c2410 7413 83faff 0f84f5000000 42 89542414 }
- $sequence_7 = { eb12 6a00 6a00 6a06 6a79 6a2c e8???????? }
- $sequence_8 = { f00fc14108 48 7505 8b01 ff5004 8b4df4 64890d00000000 }
- $sequence_9 = { c70100000000 83c104 83c204 3bce 75e8 8bc2 5e }
+ $sequence_0 = { 83a570fdffff00 8b45c4 89853cffffff 8d8544ffffff 50 8b853cffffff 8b00 }
+ $sequence_1 = { 50 e8???????? 89852cfbffff e8???????? 8d8568fbffff 50 e8???????? }
+ $sequence_2 = { e8???????? 8d45c4 50 8d45a0 50 e8???????? 8d45a0 }
+ $sequence_3 = { 8d45e0 50 e8???????? 0fbf45e8 50 ff75e0 e8???????? }
+ $sequence_4 = { 7d20 6a30 68???????? ff35???????? ffb534ffffff e8???????? 898504ffffff }
+ $sequence_5 = { 8b00 ff7508 ff5004 8b450c 832000 8d45e8 50 }
+ $sequence_6 = { e8???????? 8bd0 8d4de8 e8???????? 8d45c8 50 8d45d8 }
+ $sequence_7 = { ff5020 dbe2 898528ffffff 83bd28ffffff00 7d1d 6a20 68???????? }
+ $sequence_8 = { 8945dc 8d45e4 50 8b45dc 8b00 ff75dc ff5024 }
+ $sequence_9 = { ff75b8 ff75d8 6aff 6820110000 e8???????? 83650c00 eb27 }
condition:
- 7 of them and filesize <19405824
+ 7 of them and filesize <679936
}
-rule MALPEDIA_Win_Arik_Keylogger_Auto : FILE
+rule MALPEDIA_Win_Aperetif_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "85657a12-5353-59c6-96c2-3cad36ac8818"
+ id = "dd57eb34-4374-5f40-adeb-74673af556ba"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.arik_keylogger"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.arik_keylogger_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aperetif"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aperetif_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "f00c46b1c19068a9b1d9eb23a1cbe0ffd294a87bebb3732b435039b4cebfac37"
+ logic_hash = "cb1f1d595273c378c0af7214424a9c75d431ec33b0d3744330f8349a67692fb4"
score = 75
quality = 75
tags = "FILE"
@@ -173023,32 +180079,32 @@ rule MALPEDIA_Win_Arik_Keylogger_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b45fc f7402801000000 755a 8b45fc 8b55fc 8b12 ff927c040000 }
- $sequence_1 = { dd5df8 e8???????? ba???????? 8d45c0 e8???????? 58 85c0 }
- $sequence_2 = { 8b804c010000 e8???????? e8???????? 84c0 7424 8b45f8 8b804c010000 }
- $sequence_3 = { b003 e9???????? b004 e9???????? b005 e9???????? b006 }
- $sequence_4 = { e8???????? 8b45ec 8908 8b45f0 8b08 034df4 7105 }
- $sequence_5 = { e8???????? 50 85c0 0f8528010000 8b45b8 e8???????? c745b400000000 }
- $sequence_6 = { eb16 8b45fc 8b4004 0d00001000 0d00002000 8b55fc 894204 }
- $sequence_7 = { f3a5 8b45f4 83b8d002000000 7432 8b45f8 50 8b4518 }
- $sequence_8 = { 8b45f4 e8???????? 8b45f4 83c024 8a4d08 8d55ec e8???????? }
- $sequence_9 = { 8d45d4 e8???????? c745d400000000 8d45d0 e8???????? c745d000000000 8b4614 }
+ $sequence_0 = { 8b4108 8975e4 c70100000000 c7410400000000 8945ec c7410800000000 c645f301 }
+ $sequence_1 = { e8???????? 8a45d8 884524 8b0e c645fc02 85c9 0f8412010000 }
+ $sequence_2 = { 50 8d45f4 64a300000000 8bd9 895db8 8b7508 837e1000 }
+ $sequence_3 = { f20f118424f8080000 8b0cb0 85c9 7422 8b742464 90 0fb7047e }
+ $sequence_4 = { ff74242c 57 e8???????? 83c410 eb14 8b8724000800 b900000200 }
+ $sequence_5 = { 8954242c 660f1f440000 53 ff742424 68c0000000 56 55 }
+ $sequence_6 = { ff742410 ff742424 e8???????? 83c408 897c2410 89742450 8b44245c }
+ $sequence_7 = { e8???????? ff742434 53 e8???????? ff742428 53 e8???????? }
+ $sequence_8 = { ff5210 8b4dc8 c7451803000000 85c9 7418 8b11 8d45a4 }
+ $sequence_9 = { e8???????? c7868400000000000000 8b37 8b8e84000000 85c9 7506 8b8e88000000 }
condition:
- 7 of them and filesize <4947968
+ 7 of them and filesize <10500096
}
-rule MALPEDIA_Win_Cryptowall_Auto : FILE
+rule MALPEDIA_Win_Http_Troy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4b008ce5-4135-5555-ab2d-ce0ccd0475ff"
+ id = "e1b34482-29c1-5d78-b5ec-9dc58faf8306"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptowall"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptowall_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.http_troy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.http_troy_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "496e72f17aa4e054ce74cb3a6412cb731c4d48c85c6550891be7fb095dff5a0a"
+ logic_hash = "772a93ccc4b452bdc4c7e0291c378f7eec15f191b5f119cfc79098a0f26a733e"
score = 75
quality = 75
tags = "FILE"
@@ -173062,32 +180118,32 @@ rule MALPEDIA_Win_Cryptowall_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7504 33c0 eb21 0fb74d08 83f961 }
- $sequence_1 = { b979000000 66894de6 ba73000000 668955e8 }
- $sequence_2 = { e8???????? 83c408 8b0d???????? 898164010000 }
- $sequence_3 = { 55 8bec 51 837d0800 7441 837d0c00 }
- $sequence_4 = { 7d1f 6a09 6a00 e8???????? }
- $sequence_5 = { e8???????? 83c408 8b0d???????? 8901 68f2793618 }
- $sequence_6 = { 8b4508 668910 8b4d08 83c102 894d08 eb02 eba1 }
- $sequence_7 = { 668955e8 b874000000 668945ea b965000000 }
- $sequence_8 = { 7511 6aff 8b4508 50 }
- $sequence_9 = { 6a00 6a00 6a40 6a01 6a01 6880000000 }
+ $sequence_0 = { dd45f8 dae9 59 59 dfe0 f6c444 7a05 }
+ $sequence_1 = { c3 8b8384400000 85c0 0f84bd010000 8b54240c 52 8b542414 }
+ $sequence_2 = { ff00 85d2 744e 8d45ec 50 53 8bcf }
+ $sequence_3 = { 8b4c2420 b801000000 89410c 8b4c2418 5f 5e e8???????? }
+ $sequence_4 = { 56 57 e8???????? 59 59 eb7d dd4508 }
+ $sequence_5 = { 83c604 3b742408 72ef 5e c3 56 8bf0 }
+ $sequence_6 = { 6a01 68???????? ffd3 85c0 0f857afeffff 393cb5c8540310 742e }
+ $sequence_7 = { 50 8d4c240c 51 6a00 683f000f00 6a00 }
+ $sequence_8 = { e8???????? 8b0d???????? 83c408 3bc1 741f 83c702 }
+ $sequence_9 = { e8???????? 83c41c 8d942418010000 52 ffd3 85c0 7430 }
condition:
- 7 of them and filesize <417792
+ 7 of them and filesize <475136
}
-rule MALPEDIA_Win_Jupiter_Auto : FILE
+rule MALPEDIA_Win_Kins_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "36445056-0ae8-5be8-adc6-1a78abf2ec58"
+ id = "4907ff1e-c41f-5c86-b473-4fc349042db0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jupiter"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jupiter_auto.yar#L1-L112"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kins"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kins_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "f1911af4b4fd9bd3e29d91af55822bde97c05f4b517de64421dfe8b0d1264d94"
+ logic_hash = "f9718717a3f75dea9d210a3bb9fec1b2557a6447053917656440c5e0062c5092"
score = 75
quality = 75
tags = "FILE"
@@ -173101,34 +180157,34 @@ rule MALPEDIA_Win_Jupiter_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8a4147 884104 8a4146 884105 8b4144 c1f808 884106 }
- $sequence_1 = { c605????????01 66c705????????0101 c605????????01 c605????????01 66c705????????0101 }
- $sequence_2 = { 8b4144 c1f808 884106 8a4144 884107 }
- $sequence_3 = { 884105 8b4144 c1f808 884106 8a4144 }
- $sequence_4 = { 50 6802000000 ff35???????? ff35???????? }
- $sequence_5 = { 66c705????????0101 c605????????01 c605????????01 c605????????01 }
- $sequence_6 = { 884105 8b4144 c1f808 884106 8a4144 884107 }
- $sequence_7 = { c1f808 884106 8a4144 884107 }
- $sequence_8 = { c605????????01 66c705????????0101 c605????????01 c605????????01 }
- $sequence_9 = { 884104 8a4146 884105 8b4144 }
+ $sequence_0 = { e9???????? 8d45dc 8d75cc e8???????? 83f8ff 741f 8bc6 }
+ $sequence_1 = { 8bfe 337dfc 23f8 33fe 037df0 8d9417937198fd 8b7dfc }
+ $sequence_2 = { e8???????? 83f8ff 743d 47 3bfa }
+ $sequence_3 = { f7d3 0bde 33d8 035df4 8dbc3ba72394ab c1c70f 8bd8 }
+ $sequence_4 = { c1e008 0bc2 0fb65116 0fb64917 c1e008 0bc2 }
+ $sequence_5 = { 0fb6c0 83e07f 8bf2 746f 0fb61c39 c1e608 48 }
+ $sequence_6 = { 40 85f6 75d8 8b7510 3b16 7719 }
+ $sequence_7 = { 33de 23df 33da 035908 8d840378a46ad7 c1c007 03c7 }
+ $sequence_8 = { 8d8578fcffff 50 8d857cfdffff 50 }
+ $sequence_9 = { ff4118 8b4118 83f838 762b eb0b c644081c00 }
condition:
- 7 of them and filesize <224112
+ 7 of them and filesize <548864
}
-rule MALPEDIA_Win_Concealment_Troy_Auto : FILE
+rule MALPEDIA_Win_Flawedammyy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e9475a7d-b707-5e2f-9e3a-86f91b19814e"
+ id = "3bd73c1c-99e8-572f-ab1b-fa9278709331"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.concealment_troy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.concealment_troy_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.flawedammyy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.flawedammyy_auto.yar#L1-L298"
license_url = "N/A"
- logic_hash = "b699251c533e7fec5531f5ef6172ec9300c9329b32d1137bef102f716d43b763"
+ logic_hash = "4dc76e66643bc2a94f8c1ec04c44669739ca4e00a00102a02a05781e927a5ab3"
score = 75
- quality = 75
+ quality = 33
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -173140,32 +180196,54 @@ rule MALPEDIA_Win_Concealment_Troy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 6a04 6a00 6aff ff15???????? e8???????? 50 }
- $sequence_1 = { 56 57 b900000000 8b7508 0fb68600010000 0fb69e01010000 33d2 }
- $sequence_2 = { 894d80 c7458410000000 33c0 88440590 40 3d00010000 }
- $sequence_3 = { 50 8d8c2438050000 51 e8???????? 8d942434030000 }
- $sequence_4 = { 75f6 80bc242001000022 0f854e040000 6808020000 8d942434090000 }
- $sequence_5 = { 51 e8???????? 8bf0 83c408 85f6 7523 }
- $sequence_6 = { e8???????? 8d8c243c030000 68???????? 51 e8???????? }
- $sequence_7 = { 50 ffd5 bb???????? 8bf8 e8???????? 8b35???????? 50 }
- $sequence_8 = { 55 8bec 83e4f8 b834130000 e8???????? a1???????? 33c4 }
- $sequence_9 = { 8b1495a0774100 c1e006 8d440224 802080 884dfd 8065fd48 884dff }
+ $sequence_0 = { 0000 0404 0404 0404 0401 }
+ $sequence_1 = { 8bc4 83ec10 660fd600 f30f7e45ac }
+ $sequence_2 = { 00b3854200e5 854200 37 864200 }
+ $sequence_3 = { 8d85bcfcffff 68???????? 50 ffd3 68dff0f081 6a01 e8???????? }
+ $sequence_4 = { ffd6 8d8594f3ffff 50 68???????? 68???????? }
+ $sequence_5 = { 004bbf 42 0062bf 42 }
+ $sequence_6 = { 0039 e342 0048e3 42 }
+ $sequence_7 = { ff05???????? f7460c0c010000 7554 833cbd7cae410000 53 }
+ $sequence_8 = { 8d85bcfdffff 50 ffd3 8b45fc 80384d 0f85a7000000 8078015a }
+ $sequence_9 = { e8???????? 53 8d85c0fdffff 50 56 e8???????? }
+ $sequence_10 = { 0018 874200 58 874200 }
+ $sequence_11 = { 8b35???????? 8d85a0f6ffff 50 8d85a8f8ffff }
+ $sequence_12 = { 002a e342 0039 e342 }
+ $sequence_13 = { 8bf0 ff5208 85f6 0f8818feffff ff7508 8d4df0 e8???????? }
+ $sequence_14 = { 0022 8a4200 828a4200bb8a42 00ff }
+ $sequence_15 = { 0062bf 42 0079bf 42 }
+ $sequence_16 = { ff15???????? 8b75d8 e9???????? 8d85d0feffff 68???????? 50 ff15???????? }
+ $sequence_17 = { 8b46f8 834de4ff 49 c745e8ff000000 8b3c857c303400 c745ecffff0000 0faff9 }
+ $sequence_18 = { 4e 48 75f7 68???????? 57 ff15???????? }
+ $sequence_19 = { 8bdf 8b06 83661c00 83f807 0f87c9000000 ff248580233400 }
+ $sequence_20 = { 8b46f8 8b04855c303400 c1e002 50 6a40 }
+ $sequence_21 = { 8b4ef8 83f907 0f8781000000 ff248dfd243400 }
+ $sequence_22 = { 7330 ff75f8 ff15???????? 81c600040000 6a42 56 }
+ $sequence_23 = { eb0e 8b14957c303400 49 0fafd1 0155fc }
+ $sequence_24 = { 83f937 7f2a 8d44c1d0 0fbe0a }
+ $sequence_25 = { 33db 83f855 0f872affffff 0fb6805a213400 ff2485f6203400 8b8614080000 }
+ $sequence_26 = { 56 8a0a 80f930 7569 }
+ $sequence_27 = { 395d08 88987830ca01 0f8484010000 ff75fc 8b35???????? ffd6 f6450802 }
+ $sequence_28 = { 50 e8???????? ff75ac 8b3d???????? ffd7 ff75a8 ffd7 }
+ $sequence_29 = { ff248580233400 832700 e9???????? 55 e8???????? eb1a }
+ $sequence_30 = { 895df0 ffd6 53 ff75dc 6813100000 ff35???????? }
+ $sequence_31 = { 0f8781000000 ff248dfd243400 881f eb76 }
condition:
- 7 of them and filesize <229376
+ 7 of them and filesize <1350656
}
-rule MALPEDIA_Win_Darkpink_Auto : FILE
+rule MALPEDIA_Win_Remcom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5843ba22-3e12-5b07-a302-af204fd4f478"
+ id = "a3eb8b2b-3833-5f4e-a476-a250aeb73992"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkpink"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkpink_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.remcom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.remcom_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "f794d5918ecf33b4e0beff127be6289d027ab1ea81bf4922e3a718a3afdf8df9"
+ logic_hash = "4f3e16a0ac97921c2fcb2fdd27863c94129d85212bc306f9915a79a291488cb1"
score = 75
quality = 75
tags = "FILE"
@@ -173179,32 +180257,32 @@ rule MALPEDIA_Win_Darkpink_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b048d442a4000 ffe0 f7c703000000 7413 }
- $sequence_1 = { 57 50 683f000f00 6a00 68???????? 6801000080 }
- $sequence_2 = { c3 c705????????08924100 b001 c3 68???????? e8???????? c70424???????? }
- $sequence_3 = { 8d41fc 50 56 57 e8???????? 57 }
- $sequence_4 = { 8b85b0f8ffff 0fb70485c43c4100 8d0485c0334100 50 8d8590faffff 03c7 50 }
- $sequence_5 = { 33f6 8b86f09d4100 85c0 740e }
- $sequence_6 = { 68???????? ff75f4 ffd6 85c0 0f85ca000000 50 8d45f8 }
- $sequence_7 = { 8b0495f09d4100 f644082801 7421 57 }
- $sequence_8 = { e8???????? 6a44 8d45ac 6a00 50 }
- $sequence_9 = { 6a26 58 0fb60c85c63c4100 0fb63485c73c4100 8bf9 8985b0f8ffff c1e702 }
+ $sequence_0 = { 8be5 5d c3 53 56 8d95f8feffff }
+ $sequence_1 = { 83c8ff 89463c 894638 894640 8b8708110000 50 8d9f0c110000 }
+ $sequence_2 = { e8???????? a1???????? 33c5 8945fc 56 8b7508 68???????? }
+ $sequence_3 = { 50 8d9f0c110000 53 68???????? 8d55e0 68???????? }
+ $sequence_4 = { 008891400023 d18a0688078a 46 018847018a46 }
+ $sequence_5 = { 52 ffd3 85c0 7507 ffd7 8945f0 eb78 }
+ $sequence_6 = { 6a00 6a01 8d4de0 51 ffd3 8d45f4 50 }
+ $sequence_7 = { 8d8e00100000 f7d8 1bc0 23c1 8d8de4feffff }
+ $sequence_8 = { 8b7508 8d34f528e54000 391e 7404 8bc7 }
+ $sequence_9 = { 6a00 51 ffd7 8b4638 6a00 50 ffd7 }
condition:
- 7 of them and filesize <237568
+ 7 of them and filesize <155648
}
-rule MALPEDIA_Win_Firechili_Auto : FILE
+rule MALPEDIA_Win_Webc2_Rave_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1e675a4c-a97c-5312-b559-588fd9dfae94"
+ id = "ea4a2e95-f571-5243-9ef5-0d9d72800185"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.firechili"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.firechili_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_rave"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_rave_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "39f362d1cc29968bda0685edf846cfad0cc3545d7d80fc48d26a5fd5a4bdf9c6"
+ logic_hash = "2cbb2512779b7c01486a2ad87d98dfe34ac5aeaa8fcccabe432ae13b764de599"
score = 75
quality = 75
tags = "FILE"
@@ -173218,34 +180296,34 @@ rule MALPEDIA_Win_Firechili_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7d11 48837c242000 7509 b201 33c9 e8???????? 33c0 }
- $sequence_1 = { 488b7c2458 488b6c2460 4885f6 744e }
- $sequence_2 = { 4533c0 4889742420 488d55f7 ff15???????? }
- $sequence_3 = { c744242866730000 4533c0 33d2 48c744242008020000 ff15???????? c605????????01 488bd7 }
- $sequence_4 = { 488b7c2430 488b742438 4c8b6c2428 498b442408 }
- $sequence_5 = { c3 4c8bdc 4d894318 49895310 53 56 4883ec68 }
- $sequence_6 = { 418bc6 81c200040000 4a393400 740c ffc1 48ffc0 483bc2 }
- $sequence_7 = { 4889742458 418d5020 48897c2460 ff15???????? 8bf8 85c0 784b }
- $sequence_8 = { 4c8bc1 488bc1 6690 66833800 }
- $sequence_9 = { 488d05ff500000 c605????????01 488905???????? 488905???????? 4883c420 }
+ $sequence_0 = { 0f8454010000 8b35???????? 8d542414 6a00 }
+ $sequence_1 = { 0f84ea000000 8d542414 6a00 52 8d44241a 6a01 }
+ $sequence_2 = { 56 68???????? 53 52 ffd7 3bc3 894614 }
+ $sequence_3 = { f7d1 49 3bd9 72e5 }
+ $sequence_4 = { 8d442418 50 51 e8???????? 85c0 74b1 }
+ $sequence_5 = { 895c2448 ffd7 3bc3 894610 7517 }
+ $sequence_6 = { 7418 8b742418 46 4f }
+ $sequence_7 = { 33c9 33f6 85ed 7e45 8b942414020000 53 }
+ $sequence_8 = { 03d1 8bca 894c2414 7872 }
+ $sequence_9 = { e8???????? 83c404 ff15???????? 85ff }
condition:
- 7 of them and filesize <91136
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Coreshell_Auto : FILE
+rule MALPEDIA_Win_Unidentified_023_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f8b1ab7a-5e3f-5f01-8787-4d480849e1bc"
+ id = "f77c5286-0b1f-561f-8f58-a27a0408436a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.coreshell"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.coreshell_auto.yar#L1-L424"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_023"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_023_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "23addbe4ab3205859c50e41702fa9e9c554a336132b182d2582fda2f9387a324"
+ logic_hash = "1eec10f2afa6bd7e6a1d69558f2f25a771bedb385bd839fc0b4d5b578eec4086"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -173257,70 +180335,32 @@ rule MALPEDIA_Win_Coreshell_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? 52 ffd7 ffd0 }
- $sequence_1 = { 56 6810270000 ff15???????? be06000000 e8???????? 85c0 7401 }
- $sequence_2 = { 56 ff15???????? 83c40c 3bc6 }
- $sequence_3 = { c20400 50 a1???????? 6a00 }
- $sequence_4 = { 8b15???????? 6a01 51 68???????? 52 }
- $sequence_5 = { 50 57 6a08 51 ff15???????? 8bf8 85ff }
- $sequence_6 = { 50 ff15???????? 83c404 32db }
- $sequence_7 = { 56 6a00 6a00 681c800000 6a00 }
- $sequence_8 = { 6a00 6a00 ff15???????? 8bf0 ff15???????? 50 }
- $sequence_9 = { 6804010000 6a08 8b15???????? 52 ff15???????? }
- $sequence_10 = { 8d4c2400 56 51 6a00 }
- $sequence_11 = { 85c0 7402 eb14 c745f000000000 68e0930400 }
- $sequence_12 = { 68???????? 50 a3???????? ffd6 a3???????? a1???????? }
- $sequence_13 = { 8bf1 8b4604 85c0 7407 50 ff15???????? 8b36 }
- $sequence_14 = { ff15???????? ffd0 85c0 7508 ff15???????? }
- $sequence_15 = { 68???????? 6800080000 8d85fcefffff 50 ff15???????? }
- $sequence_16 = { 68???????? 50 ffd6 6a00 6a00 6a00 }
- $sequence_17 = { 51 56 8d442404 6a00 8bf1 50 }
- $sequence_18 = { 51 8b0d???????? 52 50 57 68???????? 51 }
- $sequence_19 = { 81e1ffff0000 81e1ffff0000 81e1ff000000 81e1ff000000 }
- $sequence_20 = { 8d55f0 52 e8???????? 83c408 33c0 8b4df0 64890d00000000 }
- $sequence_21 = { ff15???????? 50 68???????? 68???????? 8985f0fdffff 8d85f4fdffff 6804010000 }
- $sequence_22 = { 85ed 7476 85ff 7516 8b5c241c 8b0d???????? 53 }
- $sequence_23 = { 8b15???????? 57 6a00 52 ff15???????? 8b0d???????? 8bf0 }
- $sequence_24 = { 8985f0fdffff 8d85f4fdffff 6804010000 50 ff15???????? 83c414 }
- $sequence_25 = { c1e908 81e1ff000000 0fb6d1 52 }
- $sequence_26 = { 8b8dd8edffff 51 8d95f4edffff 52 68???????? }
- $sequence_27 = { 81e2ffff0000 81e2ffff0000 c1ea08 81e2ff000000 }
- $sequence_28 = { 83c414 8d8df4fdffff 51 ff15???????? }
- $sequence_29 = { 50 68???????? 8b0d???????? 51 ff15???????? ffd0 }
- $sequence_30 = { 6888130000 ff15???????? c745f000000000 c745f400000000 }
- $sequence_31 = { 56 51 56 6a01 }
- $sequence_32 = { 8be8 8b442410 50 e8???????? }
- $sequence_33 = { 8d8dfcefffff 51 ff15???????? ba00080000 }
- $sequence_34 = { 50 ff15???????? a1???????? 83c418 }
- $sequence_35 = { ffd6 ffd0 68???????? a3???????? }
- $sequence_36 = { 57 8b3d???????? 68???????? ffd7 8b35???????? 68???????? 50 }
- $sequence_37 = { 8908 813800000000 0f94c2 8b35???????? 8b3d???????? 0faff6 81c601000000 }
- $sequence_38 = { 8908 813800000000 0f95c2 8b35???????? }
- $sequence_39 = { a3???????? ffd7 8bd8 68???????? 53 }
- $sequence_40 = { 53 a3???????? ffd6 68???????? a3???????? }
- $sequence_41 = { 5f 5d c3 89e0 c70010270000 }
- $sequence_42 = { 5f 5b 5d c3 b81c000000 }
- $sequence_43 = { 8908 8b15???????? 89d6 81c609000000 }
- $sequence_44 = { bf04010000 57 6a08 ff35???????? ff15???????? }
- $sequence_45 = { 29d6 01f0 a3???????? e9???????? }
- $sequence_46 = { 8908 8b00 8b5004 8b35???????? }
- $sequence_47 = { 29d6 0faff0 31d2 f7f6 }
+ $sequence_0 = { 68???????? ff15???????? 3bf4 e8???????? b801000000 52 }
+ $sequence_1 = { 894df4 8a15???????? 8855f8 837d0c01 7514 8bf4 68???????? }
+ $sequence_2 = { 8855f8 837d0c01 7514 8bf4 }
+ $sequence_3 = { 8945f0 8b0d???????? 894df4 8a15???????? 8855f8 837d0c01 }
+ $sequence_4 = { 8855f8 837d0c01 7514 8bf4 68???????? }
+ $sequence_5 = { 68???????? ff15???????? 3bf4 e8???????? b801000000 52 8bcd }
+ $sequence_6 = { 0909 0909 0407 0807 8d4900 4f }
+ $sequence_7 = { 8a15???????? 8855f8 837d0c01 7514 8bf4 }
+ $sequence_8 = { 8945f0 8b0d???????? 894df4 8a15???????? 8855f8 837d0c01 7514 }
+ $sequence_9 = { 7514 8bf4 68???????? ff15???????? 3bf4 e8???????? b801000000 }
condition:
- 7 of them and filesize <303100
+ 7 of them and filesize <1433600
}
-rule MALPEDIA_Win_Gameover_Dga_Auto : FILE
+rule MALPEDIA_Win_Ziyangrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "49ca0960-3057-5b3f-bfaa-26bec43ff964"
+ id = "61b87837-dc98-50eb-8916-bc6cbc20d03f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gameover_dga"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gameover_dga_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ziyangrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ziyangrat_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "04f58b9dead2fa0c3d00122a20892474bd44e61e3b7f09f6fdc5edfc6227d8a8"
+ logic_hash = "63664fb49a7b130cd77da76446f0977d6b37fb6657ee0279b7de100f4571b771"
score = 75
quality = 75
tags = "FILE"
@@ -173334,32 +180374,32 @@ rule MALPEDIA_Win_Gameover_Dga_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 884617 33c0 40 e9???????? 8a4601 33db 8b6c2434 }
- $sequence_1 = { 397e08 0f84f0000000 8be9 894c2414 8bd1 8b4604 8a0c03 }
- $sequence_2 = { 48 7544 397714 763f 8b4710 ff34b0 }
- $sequence_3 = { 833d????????00 7566 8d8de8fdffff e8???????? 51 be???????? 56 }
- $sequence_4 = { 5f 5b c20c00 8bcf e8???????? 8bf0 }
- $sequence_5 = { 56 ff15???????? 85c0 7443 56 be???????? 8d85f8fdffff }
- $sequence_6 = { 8b84245c010000 40 e9???????? 8b476c 33c9 2bc3 }
- $sequence_7 = { ff760c ff7608 6a10 e8???????? 84c0 0f847a010000 8364241c00 }
- $sequence_8 = { e8???????? a1???????? ff7064 ff15???????? 6a53 8d55b8 8bf0 }
- $sequence_9 = { 7510 8b4f10 e8???????? 85c0 75e5 32c0 }
+ $sequence_0 = { 89442405 89442409 668944240d 8844240f 8b11 8d442410 }
+ $sequence_1 = { c3 8b9c24a4000000 68???????? 53 8d4c2444 }
+ $sequence_2 = { c68424e200000069 888424e3000000 889c24e4000000 888c24eb000000 c68424ec00000047 c68424ed00000020 }
+ $sequence_3 = { b93f000000 33c0 8dbc2441010000 889c2440010000 b265 f3ab }
+ $sequence_4 = { 8dbd48f7ffff 83c9ff 33c0 f2ae f7d1 83c1ff 51 }
+ $sequence_5 = { 889c2410020000 89442461 889c2410070000 6689442465 889c2410030000 }
+ $sequence_6 = { 8b4c2410 56 50 51 e8???????? 68???????? 8d542420 }
+ $sequence_7 = { 48 0d0000ffff 40 6689442408 25ffff0000 8d1440 }
+ $sequence_8 = { 50 e8???????? 83c40c 85c0 752a e8???????? }
+ $sequence_9 = { 8b7c240c 8b04bd10894000 8d1cbd10894000 3d00100000 0f84c8000000 8b04bd20094100 56 }
condition:
- 7 of them and filesize <540672
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Darkmegi_Auto : FILE
+rule MALPEDIA_Win_Netsupportmanager_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b4298044-373c-5ebc-af72-71a8178891f9"
+ id = "cef2dd3b-0f7d-59a7-a048-7ced175e981a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkmegi"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkmegi_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.netsupportmanager_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.netsupportmanager_rat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "594b35440f1c502a0c2d0a5e3fa86f0d3dc6b2f476ed2e839ff20aa39301e384"
+ logic_hash = "79986ba5845ddb197c2cbb664d974c015a806cc2574092a014c092c0439de61a"
score = 75
quality = 75
tags = "FILE"
@@ -173373,32 +180413,32 @@ rule MALPEDIA_Win_Darkmegi_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 81c43c010000 c3 8b442448 6a00 6a00 50 }
- $sequence_1 = { c3 8b44244c 56 3d50450000 7411 }
- $sequence_2 = { 3db7000000 7517 56 ff15???????? 56 }
- $sequence_3 = { ff15???????? 83c40c 8d4c2464 8d942478050000 8d442444 }
- $sequence_4 = { 8b548c2c 668b02 50 ffd5 }
- $sequence_5 = { 0fb6d2 f6820196b40204 7403 40 }
- $sequence_6 = { 49 6a01 8dbc0ca9030000 ffd6 6a01 }
- $sequence_7 = { 81e1ffff0000 3bc1 0f8c9bfeffff 33db 8b94249e030000 }
- $sequence_8 = { 52 e8???????? 83c404 8bd8 85f6 7426 }
- $sequence_9 = { 33c0 5e 83c468 c21000 e8???????? }
+ $sequence_0 = { ff15???????? 8b7df0 3bfb c745fcffffffff 7410 8bcf e8???????? }
+ $sequence_1 = { f3a4 8d4dfc 51 e8???????? 83c404 663dffff 668945dc }
+ $sequence_2 = { e8???????? 8bcb e8???????? 8b4510 8b08 894b34 8b5004 }
+ $sequence_3 = { ff15???????? 85ff 7417 8b1b 81e7ffff0000 6a00 57 }
+ $sequence_4 = { c644020400 e8???????? 8b8558ffffff 83c404 85c0 7514 8b9550ffffff }
+ $sequence_5 = { e8???????? 8b9750030000 52 e8???????? 8b450c 8b7510 83c408 }
+ $sequence_6 = { ff15???????? 85c0 750e 8b45e8 8b4de4 50 51 }
+ $sequence_7 = { e8???????? eb02 33c0 c645fc01 8bf0 3bf3 7547 }
+ $sequence_8 = { e9???????? 686c010000 e8???????? 8bf0 83c404 897508 85f6 }
+ $sequence_9 = { 8d4df0 c745fc00000000 e8???????? 8b4704 85c0 7609 83f8ff }
condition:
- 7 of them and filesize <90304
+ 7 of them and filesize <4734976
}
-rule MALPEDIA_Win_Mydogs_Auto : FILE
+rule MALPEDIA_Win_Navrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8e0c4ca1-c33b-55e0-bdee-122873680dc3"
+ id = "267e4534-59a3-5746-9f05-524cfafc2ef1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mydogs"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mydogs_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.navrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.navrat_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "64d7e86bc2c7d2208d4e1b71baa972c2ebb11908509ae447cb6fe3a57912500e"
+ logic_hash = "d02406512a8ed4f24033286c28dfca048100e2bb166bb80aa3e9acab2e4b74d3"
score = 75
quality = 75
tags = "FILE"
@@ -173412,32 +180452,32 @@ rule MALPEDIA_Win_Mydogs_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3db7000000 0f8444010000 68???????? 6804010000 68???????? e8???????? }
- $sequence_1 = { 884df3 c1fa18 8b5364 8bc2 8bce 0facc108 c1f808 }
- $sequence_2 = { 5d e9???????? 6a18 68???????? e8???????? 8b4508 8bd8 }
- $sequence_3 = { 894e64 8b4dec 894650 894658 894660 8b45ee 8d49c4 }
- $sequence_4 = { 50 ffb5e4eeffff ffb5f8eeffff ff15???????? 85c0 7515 5f }
- $sequence_5 = { 8bf9 53 895ddc 897de0 e8???????? }
- $sequence_6 = { 8b4dfc 33cd e8???????? 8be5 5d c3 8d85f4eeffff }
- $sequence_7 = { 50 8bcf c645ff4b e8???????? 6a01 8d450b 50 }
- $sequence_8 = { 1ddeb19d01 50 51 89530c e8???????? 894310 }
- $sequence_9 = { e8???????? 50 6800080000 53 89442434 e8???????? 83c414 }
+ $sequence_0 = { 0fbec0 83e847 c3 8d48d0 80f909 }
+ $sequence_1 = { 56 68???????? 50 8d85f0feffff 8bf1 50 }
+ $sequence_2 = { f7de 1bf6 f7de 56 68???????? }
+ $sequence_3 = { 8bf0 f7de 1bf6 f7de 56 }
+ $sequence_4 = { 0fbec0 83e847 c3 8d48d0 80f909 7707 }
+ $sequence_5 = { 7707 0fbec0 83c004 c3 3c2b 7503 }
+ $sequence_6 = { c3 3c2f 0f95c0 fec8 2440 fec8 }
+ $sequence_7 = { 85f6 7407 8b7608 83461c02 }
+ $sequence_8 = { c745dc726f736f c745e066745c57 c745e4696e646f c745e877735c43 c745ec75727265 c745f06e745665 }
+ $sequence_9 = { 51 56 50 57 a3???????? ff15???????? 57 }
condition:
- 7 of them and filesize <313344
+ 7 of them and filesize <352256
}
-rule MALPEDIA_Win_Radamant_Auto : FILE
+rule MALPEDIA_Win_Daserf_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1ede87f9-320c-576f-9524-930f09ad6207"
+ id = "fffb2935-58a7-5828-bf22-dd469fea2b59"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.radamant"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.radamant_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.daserf"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.daserf_auto.yar#L1-L167"
license_url = "N/A"
- logic_hash = "add6ca5b01c9d6d8dad27d0b268d58bbdb18019e152c79d40b24c8426bcce310"
+ logic_hash = "194f8b1f42d6928a216ace153b63a40c6d813ea5df60a79ed82a9b2168ff69ee"
score = 75
quality = 75
tags = "FILE"
@@ -173451,34 +180491,40 @@ rule MALPEDIA_Win_Radamant_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8802 8b5510 42 8b45f8 }
- $sequence_1 = { 890424 e8???????? 8b85c8f6ffff 890424 e8???????? 8b85d4f6ffff 890424 }
- $sequence_2 = { 8d45f0 ff00 eb9b c9 }
- $sequence_3 = { 01d0 8d148500000000 01d0 29c1 89c8 83c061 8945b0 }
- $sequence_4 = { 331485b0164100 89d0 8945e8 8b55fc 83c204 8b45f4 c1e818 }
- $sequence_5 = { 8d148500000000 01d0 29c1 89c8 83c061 8945b0 }
- $sequence_6 = { c1e818 0fb6c0 0fb680b0094100 31d0 8901 8b4df4 83c124 }
- $sequence_7 = { 8b8520feffff 890424 e8???????? 83ec0c 83f8ff 752a 8b45c4 }
- $sequence_8 = { e8???????? 8b45f4 890424 e8???????? 83c424 5b 5d }
- $sequence_9 = { 8d45e8 c1000a 8b55f4 8d45e8 0110 8b45f0 f7d0 }
+ $sequence_0 = { 8945cc ff15???????? 8945d0 8d45b4 }
+ $sequence_1 = { b808380000 e8???????? 53 56 }
+ $sequence_2 = { 81eb7ee5b031 81c30d782341 81c3db5d1091 81eb73ad763b 054ce1128c 81c3cc3c3014 }
+ $sequence_3 = { 81c3ad482863 81eb8c570d21 2d21583cc4 2da932ed1b 81c3f8ff2857 81eb46159323 }
+ $sequence_4 = { 81eb4e0e3377 87c0 81ebfb04024c 87ff 2dfaa67876 }
+ $sequence_5 = { 81c394c7d041 81eb6afed62a 81c3bed1834b 81eb826387e9 81c3d7e98170 2d844df6b2 }
+ $sequence_6 = { 50 ffd6 ffb56814ffff 8d85bc4fffff 50 }
+ $sequence_7 = { 2d4936916d f7d1 f7d1 2d99d06187 f7d1 f7d1 }
+ $sequence_8 = { 8bc9 81c3c9920a05 95 89ac2400f2ffff }
+ $sequence_9 = { 7500 81c3e109e0f6 8bc0 0537d68276 9b 81c38da225f6 87c9 }
+ $sequence_10 = { eb0e ff75fc ffd7 3bf3 7403 56 }
+ $sequence_11 = { 81c327f27a10 7500 81ebc884a519 7500 81eb3a0de80d 87db 81c3b119330a }
+ $sequence_12 = { 2d4abc1884 90 2dea9bf526 7500 }
+ $sequence_13 = { 81ebf74ea63a f7d1 f7d1 81eb199760ae 9b }
+ $sequence_14 = { 2d966cdd4c 2d81c26ac5 81c32b73f252 81c32bef6e96 81c3b4dacce0 }
+ $sequence_15 = { 81eb075e2ddb 9b 81c35a11e727 97 89bc2440f5ffff }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <245760
}
-rule MALPEDIA_Win_Chinotto_Auto : FILE
+rule MALPEDIA_Win_Redalpha_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "eb163619-c453-5aad-acb2-63f8cb2fc096"
+ id = "18d7b39f-1fe8-5b57-91e8-72bb40b0300f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chinotto"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chinotto_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redalpha"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redalpha_auto.yar#L1-L286"
license_url = "N/A"
- logic_hash = "68ff4e71579a9ee7d4f8a0767737ed2f326ba91b5ade5aa40e96479fa8db4fb8"
+ logic_hash = "062f534aa7bc989cb92a0f507bdc74bdcfcc089d3142c94dc9dd9b9510e4dbdc"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -173490,32 +180536,53 @@ rule MALPEDIA_Win_Chinotto_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 034d0c 53 56 57 8b7848 8b774c }
- $sequence_1 = { 6a1a e8???????? 8bd8 b906000000 be???????? 8bfb f3a5 }
- $sequence_2 = { c745f800000000 8955c8 85d2 7505 ba02000000 8b461c 8bf8 }
- $sequence_3 = { 57 8945f0 8d5801 740e 8b4e1c 2b4e40 }
- $sequence_4 = { 837dfc00 7514 837dd000 0f8421080000 837e2000 0f8417080000 }
- $sequence_5 = { 8d8dd0fbffff 68???????? 51 ffd6 83c418 8d95a4f1ffff 52 }
- $sequence_6 = { 8b5620 57 8b7e24 8bc2 0bc7 7412 8bc2 }
- $sequence_7 = { 8a08 40 84c9 75f9 2bc7 8b7d18 }
- $sequence_8 = { 83c434 5f 5e 33cd 8d85e0fdfcff 5b }
- $sequence_9 = { 8b471c 50 0fafc1 034710 8d55f8 }
+ $sequence_0 = { e8???????? 83c40c c0e304 0fb6c3 50 }
+ $sequence_1 = { 8b3e 8bce e8???????? 8b4df8 }
+ $sequence_2 = { 4585c0 7417 0f1f4000 410fb602 4d8d5201 03c8 }
+ $sequence_3 = { 443bd3 7d0b 6645019489a40a0000 eb33 }
+ $sequence_4 = { 8b4004 c74408e840d24300 8b41e8 8b5004 }
+ $sequence_5 = { 8b3d???????? eb96 8b8b48010000 e8???????? 8bce e8???????? 8b7e04 }
+ $sequence_6 = { 8b3f ff750c 53 6aff }
+ $sequence_7 = { 8b3e 897df4 0fb607 0fb64f01 }
+ $sequence_8 = { 42803c0000 75f6 49ffc0 488d4f0d 488d542450 }
+ $sequence_9 = { e8???????? 488d043b 4d63c4 488d8dea020000 }
+ $sequence_10 = { 498d4505 894208 d3e5 ffcd 23dd }
+ $sequence_11 = { 488b4b10 488b5010 410fb60411 41880408 ff4328 ff4338 }
+ $sequence_12 = { 448d4858 e8???????? 85c0 7556 }
+ $sequence_13 = { 8b3e 8bcb d3e8 83e001 895d08 }
+ $sequence_14 = { 488d542458 4803d0 488bcb e8???????? }
+ $sequence_15 = { 8b3d???????? ffd7 ffb548f7ffff ffd7 }
+ $sequence_16 = { 50 e8???????? 83c418 c785f0fdffff00000000 8d85f0fdffff 50 6a0b }
+ $sequence_17 = { 0f8413050000 8b3c8d8c864000 85ff 755d 33c0 89859cf6ffff 89855cfcffff }
+ $sequence_18 = { c3 55 8bec 81ec04010000 56 68cf010040 6a00 }
+ $sequence_19 = { 8d7608 660fd60f 8d7f08 8b048d74e84000 }
+ $sequence_20 = { 50 8d45f4 64a300000000 683f000f00 }
+ $sequence_21 = { 897c2428 e8???????? 83c410 8d442424 50 }
+ $sequence_22 = { 50 e8???????? 6aff c645fc01 ff75dc }
+ $sequence_23 = { 8b5df4 8bf7 8b4b04 85c9 0f85f2000000 33c0 }
+ $sequence_24 = { 7605 e8???????? 8b4f14 8bf0 }
+ $sequence_25 = { e8???????? 83f801 7512 68d0070000 ff15???????? e8???????? eb39 }
+ $sequence_26 = { 7512 8b04bd30744100 807c302900 7504 }
+ $sequence_27 = { 8b8fbc000000 52 ff7730 8b01 ff5004 ff75ec }
+ $sequence_28 = { c1f806 83e13f 6bc930 53 56 8b048530744100 33db }
+ $sequence_29 = { 89b8bc000000 ff15???????? 894708 ff7518 8b4514 }
+ $sequence_30 = { 6bc830 894de0 8b049d581f4000 0fb6440828 83e001 7469 }
condition:
- 7 of them and filesize <300032
+ 7 of them and filesize <606208
}
-rule MALPEDIA_Win_Dadstache_Auto : FILE
+rule MALPEDIA_Win_Zedhou_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1b258f10-8f88-5091-9d8a-b7cbb1e4a0e5"
+ id = "2aa4d978-6d48-5f72-a16b-4b6ea617b5b6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dadstache"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dadstache_auto.yar#L1-L168"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zedhou"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zedhou_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "77711feda2c16f34186a4f1ae2717975593af55ed7e01d177132f4e333f94d90"
+ logic_hash = "b60fc9437fc4bcd4e7a504c33358b6d6c8b7b5e0237aab2ee62dd854e5c508d6"
score = 75
quality = 75
tags = "FILE"
@@ -173529,38 +180596,32 @@ rule MALPEDIA_Win_Dadstache_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d442414 50 6a1f ff35???????? }
- $sequence_1 = { 8b470c 8bf9 31460c 0f1006 c7450c09000000 0f1145e8 }
- $sequence_2 = { 85c0 7550 8b0d???????? 8b35???????? 85c9 7403 }
- $sequence_3 = { 53 8d4d08 895d08 51 53 50 53 }
- $sequence_4 = { 837c242c10 8d442418 51 0f4344241c }
- $sequence_5 = { 8d5201 8842ff 83e901 75f2 8bd3 c1ea04 }
- $sequence_6 = { 6aff 6a00 8d442438 c74424340f000000 50 }
- $sequence_7 = { 6a1f ff35???????? ff15???????? a1???????? }
- $sequence_8 = { 741b 8b45f0 47 83c628 3bf8 }
- $sequence_9 = { 7405 8b4718 8901 8b731c 57 }
- $sequence_10 = { 42 83c628 8955f0 3b55e4 0f8c66ffffff }
- $sequence_11 = { 7325 8b7c240c 4a 03d7 8d4fff }
- $sequence_12 = { 8b4485b0 85d2 8b56f8 7405 0d00020000 8d5de4 53 }
- $sequence_13 = { e8???????? 85c0 741d 8bce e8???????? 8bce }
- $sequence_14 = { c3 8b4e04 8d4604 8945fc 8b06 }
- $sequence_15 = { 84c9 740e 3aca 74ef 0fb6c2 0fb6c9 }
+ $sequence_0 = { 8b4dac 894dd8 8d55d0 52 8d45d4 50 }
+ $sequence_1 = { ff5030 5f 5e 5b c9 c22400 }
+ $sequence_2 = { 57 ff7508 56 ff15???????? ff7508 ff15???????? 8bc6 }
+ $sequence_3 = { 8d4da4 51 8b5508 8b02 8b4d08 51 ff9008070000 }
+ $sequence_4 = { ff15???????? 8d4dc0 ff15???????? 0fbf4598 85c0 742a c745fc06000000 }
+ $sequence_5 = { 68???????? 8b85acfeffff 50 8b8da8feffff 51 ff15???????? 8985c4fdffff }
+ $sequence_6 = { 33c0 f3a6 0f85653a0000 85d2 }
+ $sequence_7 = { ff15???????? 83c41c c745fc04000000 8b5508 8b02 8b4d08 51 }
+ $sequence_8 = { ff15???????? c745fc7f000000 8b5508 8b4238 50 68???????? ff15???????? }
+ $sequence_9 = { e8???????? 894604 8b430c 59 8b04c5fc201822 59 6a01 }
condition:
- 7 of them and filesize <580608
+ 7 of them and filesize <499712
}
-rule MALPEDIA_Win_Racket_Auto : FILE
+rule MALPEDIA_Win_Plurox_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7cb28a65-c30c-589f-a924-680f6f853124"
+ id = "6592f7da-a1c0-54df-8b9b-d6d4f0de3577"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.racket"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.racket_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.plurox"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.plurox_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "d1589a59b0768c1bd03360a8449d283c6a3783d8d4ace18ebd09610946148618"
+ logic_hash = "2767330918862f71924876620bde24f2504b741e0c74e8fbd24789f747d1fbb9"
score = 75
quality = 75
tags = "FILE"
@@ -173574,32 +180635,32 @@ rule MALPEDIA_Win_Racket_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ffd3 8b8eec000000 8bf8 8b1d???????? 8d45ec 57 50 }
- $sequence_1 = { 807d0800 743b e8???????? 6a00 ff7604 6845090000 ff35???????? }
- $sequence_2 = { 57 0f1f840000000000 8bc1 c745fc02000000 2bc2 8dbb78fdffff 81c680fdffff }
- $sequence_3 = { 0f44c1 50 ff75f4 8b473c 68a2090000 ff34856cb30610 ff15???????? }
- $sequence_4 = { 40 50 68???????? 6aff 8d85fcfdffff 6800010000 50 }
- $sequence_5 = { 0f8433020000 833d????????00 0f8426020000 833d????????00 0f8419020000 833d????????00 0f840c020000 }
- $sequence_6 = { 83c430 3945cc 8b45b8 7501 40 8b4dc0 }
- $sequence_7 = { 8b4e04 85c9 7537 8b4510 8b7838 85ff 7e75 }
- $sequence_8 = { ff740e08 68ac080000 ff35???????? ff15???????? 83c420 2bd8 7418 }
- $sequence_9 = { 6a00 68d6070000 897ddc ff34856cb30610 8975d0 ff15???????? 83c410 }
+ $sequence_0 = { 90 f9 0925???????? 0000 }
+ $sequence_1 = { 1a6e00 0000 94 624a8b 0416 }
+ $sequence_2 = { 6f b804000000 4e 4f b84e4f3dd9 }
+ $sequence_3 = { 94 f8 21480e 2a15???????? 6f b804000000 }
+ $sequence_4 = { e9???????? e408 6873d30808 94 e519 e8???????? 0000 }
+ $sequence_5 = { 8918 43 0416 0a20 0816 ec bbf2000000 }
+ $sequence_6 = { 8a00 46 0c83 47 }
+ $sequence_7 = { 624a8b 0416 128bc606091a f6870f1a000000 e10d }
+ $sequence_8 = { 07 f3cf 6b0000 0025???????? 7171 6805245f07 40 }
+ $sequence_9 = { 64841a 6c 2432 3449 }
condition:
- 7 of them and filesize <985088
+ 7 of them and filesize <475136
}
-rule MALPEDIA_Win_Bamital_Auto : FILE
+rule MALPEDIA_Win_Chewbacca_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3baca492-b609-5d4f-80bb-c68e186e995b"
+ id = "222f6780-8c77-5a93-9b3a-f1a76242c8a5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bamital"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bamital_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chewbacca"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chewbacca_auto.yar#L1-L95"
license_url = "N/A"
- logic_hash = "80aaa696b23b77db92b802971fab9d7fd90e414992e8440ec6c57f40448ba374"
+ logic_hash = "026e724d28dad06de27f1ece049f17b6c66ca8975467e2769de70691ea3bc834"
score = 75
quality = 75
tags = "FILE"
@@ -173613,32 +180674,30 @@ rule MALPEDIA_Win_Bamital_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb05 83c001 ebe0 52 ff75fc e8???????? }
- $sequence_1 = { 8ac4 8807 83c701 e2d8 c9 c20800 55 }
- $sequence_2 = { ff75dc ff75d4 57 e8???????? 8b55fc 8945fc 0bd2 }
- $sequence_3 = { e8???????? 8b55fc 8945fc 0bd2 }
- $sequence_4 = { 0bc0 741f 50 83c001 50 }
- $sequence_5 = { b800000000 c9 c20400 55 8bec 83c4f0 }
- $sequence_6 = { 56 57 53 8b5d0c 8b7508 }
- $sequence_7 = { ff7508 ff75f4 e8???????? 68e8070000 }
- $sequence_8 = { 6a28 e8???????? 8945fc ff7508 e8???????? 8945f8 e8???????? }
- $sequence_9 = { 8a07 3c39 7208 3c7e 7704 2c19 eb13 }
+ $sequence_0 = { e8???????? c645f401 8a45f4 5b c9 }
+ $sequence_1 = { e8???????? c645c800 8b45cc 8b10 }
+ $sequence_2 = { e8???????? c645f000 8b45f4 8b80b4010000 }
+ $sequence_3 = { e8???????? c645a400 c645f400 806df401 }
+ $sequence_4 = { e8???????? c645d001 8a45d0 5f }
+ $sequence_5 = { e8???????? c645ec01 e9???????? 8b55dc }
+ $sequence_6 = { e8???????? c645f401 e8???????? 8d4590 e8???????? 58 }
+ $sequence_7 = { e8???????? c645a400 6a00 8b45f8 8b00 898554ffffff }
condition:
- 7 of them and filesize <90112
+ 7 of them and filesize <9764864
}
-rule MALPEDIA_Win_Matsnu_Auto : FILE
+rule MALPEDIA_Win_Xiangoop_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c9a7bdf6-1deb-5130-82f0-9b1058e504ad"
+ id = "bc98151f-3c19-5785-9ae3-c69b23dbc040"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.matsnu"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.matsnu_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xiangoop"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xiangoop_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "e4de93852a1879de4977ea1cd375165f9dcf6c32de8c352e98b35973d623758e"
+ logic_hash = "94fbd52db4d5481176ad7bfd7bb74c96cb0ad2e3aa8f7b123dd0955d4f95f88c"
score = 75
quality = 75
tags = "FILE"
@@ -173652,32 +180711,32 @@ rule MALPEDIA_Win_Matsnu_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 8985bcfbffff 83bdb0fbffff01 0f8588000000 8b85bcfbffff 8985c4fbffff 8b85c0fbffff }
- $sequence_1 = { eb04 c647023d 837d1003 7213 }
- $sequence_2 = { eb04 c647023d 837d1003 7213 31c0 8a4602 243f }
- $sequence_3 = { 8b45e0 3b450c 0f8391000000 c745e800000000 }
- $sequence_4 = { 750f c785a4fbffff02000000 e9???????? 8985bcfbffff 83bdb0fbffff01 0f8588000000 8b85bcfbffff }
- $sequence_5 = { 85c0 0f84a6000000 8945fc 8b45e0 3b450c }
- $sequence_6 = { c78570f3ffff00000000 c78574f3ffff00000000 c78578f3ffff00000000 c7857cf3ffff00000000 }
- $sequence_7 = { 751d ff45da ba00000000 8b45da }
- $sequence_8 = { 3b45ba 7228 8b7d08 8b4704 3b45ba 751d }
- $sequence_9 = { 89e5 81ec18020000 c785e8fdffff00000000 c785ecfdffff00000000 c785f0fdffff00000000 }
+ $sequence_0 = { b801000000 d1e0 8b55f4 0fb6440208 25ff000000 }
+ $sequence_1 = { c1e903 8d540906 8b4508 8990e0010000 c745ec00000000 8b4d08 }
+ $sequence_2 = { ebe3 8b45f0 8b0c85a8b00110 8b45ec 807c082800 }
+ $sequence_3 = { c1e008 0bc8 ba01000000 6bc203 8b550c 0fb644020c 25ff000000 }
+ $sequence_4 = { 8955c8 6804010000 8d85bcfdffff 50 8b4dc8 }
+ $sequence_5 = { 81e2ff000000 b801000000 6bc800 8b4510 8854080c 8b4dec }
+ $sequence_6 = { c3 b001 c3 c705????????80a50110 b001 c3 68???????? }
+ $sequence_7 = { 8b45fc 8b4dfc 034804 894dfc e9???????? b801000000 8be5 }
+ $sequence_8 = { 890c02 8b45ec 83c001 8945ec 837dec08 7502 }
+ $sequence_9 = { 8b45f4 83c028 8945f4 ebcb }
condition:
- 7 of them and filesize <606992
+ 7 of them and filesize <246784
}
-rule MALPEDIA_Win_Rhysida_Auto : FILE
+rule MALPEDIA_Win_Felismus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "64a6dc82-3050-56af-987a-eca5c9c0ccdc"
+ id = "5818ed3f-2431-5f26-88a0-82a8f566adf3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rhysida"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rhysida_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.felismus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.felismus_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "c700e285aaa62eb845c4c4a22ba3b4990a79a21d47e9845ba892bd45fa758d74"
+ logic_hash = "dea5875d596c4ef87d002c63282ac83d0f7df95527f5e0d6e66faa21ccc2e20e"
score = 75
quality = 75
tags = "FILE"
@@ -173691,32 +180750,32 @@ rule MALPEDIA_Win_Rhysida_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ba28000000 4889c1 e8???????? 8945f8 837df800 7407 b804000000 }
- $sequence_1 = { 4863d0 488b4510 4801d0 0fb600 0fb6c0 8b55f4 c1ea06 }
- $sequence_2 = { f6431920 0f84c7feffff 4983c101 e9???????? 4531c0 4889f2 89e9 }
- $sequence_3 = { 8b45fc 4863c8 4889c8 48c1e002 4801c8 48c1e003 4889c1 }
- $sequence_4 = { baafa96e5e 89c8 f7ea c1fa0b 89c8 c1f81f 29c2 }
- $sequence_5 = { 8b45f8 4863d0 488b4510 4801d0 0fb600 0fb6d0 8b45f8 }
- $sequence_6 = { e8???????? eb01 90 8b45f0 0faf45b8 89c2 488d45a0 }
- $sequence_7 = { 85c0 74da 85db 4889742428 0f848d010000 8d4bff 488d742460 }
- $sequence_8 = { c1e903 f348ab ff15???????? 83f812 7472 488b8b38020000 e8???????? }
- $sequence_9 = { 5f 5d 415c 415d c3 b80d000000 ebd7 }
+ $sequence_0 = { ff15???????? 8b35???????? 83c404 53 ffd6 8b442410 }
+ $sequence_1 = { 8b4e08 8b560c 89442418 8b4610 894c241c 89442424 }
+ $sequence_2 = { 89542410 8b5110 56 2be8 57 89542420 bb01000000 }
+ $sequence_3 = { 8d5640 8bfa f3ab 8b4618 33c9 85c0 7e24 }
+ $sequence_4 = { 66ab aa b940000000 33c0 8dbc24b1050000 }
+ $sequence_5 = { 85c0 740f 8d8c2414010000 68???????? 51 eb0d 8d942414010000 }
+ $sequence_6 = { 8b442424 50 56 ff15???????? 56 ff15???????? 83f8ff }
+ $sequence_7 = { 7cd0 8b461c 8bce 50 e8???????? 8b7e1c }
+ $sequence_8 = { 51 8bfb 83c9ff 33c0 895514 f2ae f7d1 }
+ $sequence_9 = { 83c408 85ff 742b 57 ff15???????? 83f816 7e1f }
condition:
- 7 of them and filesize <2369536
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Cadelspy_Auto : FILE
+rule MALPEDIA_Win_Dubrute_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4b5e300d-757a-5fee-8d04-bdd6cbf72a64"
+ id = "91c95b88-1aba-547d-a2e7-1c5fddf4a9b5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cadelspy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cadelspy_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dubrute"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dubrute_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "7f3bdf0fe810a37a01bcc3fbdfdc1fe97ab8b02a604549fa04a7da715441b0c6"
+ logic_hash = "96123f7850603b9e3ec4473b7e8755ea7a00903c8750eba6148228fb5b3de4ca"
score = 75
quality = 75
tags = "FILE"
@@ -173730,32 +180789,32 @@ rule MALPEDIA_Win_Cadelspy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? c7042408020000 33f6 56 ff7514 e8???????? 83c40c }
- $sequence_1 = { e8???????? 68???????? 8d9c2464020000 e8???????? 6828020000 }
- $sequence_2 = { 46 66833e5c 74f8 8bc6 8d5002 }
- $sequence_3 = { 59 59 85c0 7524 837d8c05 }
- $sequence_4 = { ff15???????? ff75fc 8bd8 ff15???????? 5e 8bc3 5b }
- $sequence_5 = { 57 33ff 893a 8d4802 668b30 40 }
- $sequence_6 = { 8b0c8d004c0110 83e01f c1e006 8d440124 }
- $sequence_7 = { 741b 8b07 8bc8 c1f905 83e01f c1e006 8b0c8d004c0110 }
- $sequence_8 = { 8d442418 50 e8???????? eb0b 50 }
- $sequence_9 = { 7507 e8???????? eb5f 57 8b7d08 85ff 750a }
+ $sequence_0 = { 8d45dc dd5de4 50 c645fc0d ff15???????? 8d4df0 c645fc08 }
+ $sequence_1 = { 83c410 83f8ff 743b 85c0 741c 03f0 56 }
+ $sequence_2 = { 83e906 7426 49 741a 49 740e 49 }
+ $sequence_3 = { 7427 48 7413 48 48 7551 57 }
+ $sequence_4 = { 5e 5d c3 8b4c2408 81f9ff000000 7e1b 8b442404 }
+ $sequence_5 = { e8???????? 83c410 ff866c090000 5e c3 55 8bec }
+ $sequence_6 = { 7520 8b06 8b4018 8b00 ff30 e8???????? 6a06 }
+ $sequence_7 = { 57 53 ff15???????? 8b3d???????? 8325????????00 8b37 3bf7 }
+ $sequence_8 = { 56 53 68???????? e8???????? 83c40c 837d1400 }
+ $sequence_9 = { 8a48ff 884e01 83c603 837df000 7fd4 e9???????? f745f0f8ffffff }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <598016
}
-rule MALPEDIA_Win_Abaddon_Pos_Auto : FILE
+rule MALPEDIA_Win_Explosive_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8a8bfe7b-07a3-507a-8985-62178b8d7d5d"
+ id = "863a5681-ec58-58c3-aa41-9d8844c2c73c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.abaddon_pos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.abaddon_pos_auto.yar#L1-L170"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.explosive_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.explosive_rat_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "e2d8547af0d263d117f46abc9755b5a7e9f77ec4346ade26de1285350cf4f083"
+ logic_hash = "e75d842c394fc045ddd0745106b1430d3dd968c3b7d21e3af7bbb4c3b56a96a4"
score = 75
quality = 75
tags = "FILE"
@@ -173769,38 +180828,32 @@ rule MALPEDIA_Win_Abaddon_Pos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7402 eb27 8b8600010000 03860c010000 89867c010000 8b8684010000 }
- $sequence_1 = { ba00000000 eb05 ba01000000 0186ac010000 }
- $sequence_2 = { 80beb801000001 751b 80fa30 7205 80fa39 7605 80fa20 }
- $sequence_3 = { 41 89c0 49 c7c100000000 ff15???????? 48 83c420 }
- $sequence_4 = { 48 8986d0050000 48 83ec20 48 c7c100000000 }
- $sequence_5 = { 89d8 69c080000000 3d002d0000 7602 eb22 }
- $sequence_6 = { 7318 807c1e2c41 720c 807c1e2c5a }
- $sequence_7 = { 81bea001000000dc0500 740c 81bea001000000d60600 7508 6a05 ff15???????? 8b86a0010000 }
- $sequence_8 = { 31c9 31d2 80beb401000001 7505 }
- $sequence_9 = { ffc3 ebd1 48 31db }
- $sequence_10 = { 8986b0050000 48 83ec20 48 8b8eb0050000 48 }
- $sequence_11 = { 0504d00700 48 8986c8050000 48 0504d00700 48 8986d0050000 }
- $sequence_12 = { 83f800 7502 ebe4 50 ff15???????? 6a00 6a00 }
- $sequence_13 = { 83c000 48 8b9eb8050000 48 8918 48 }
- $sequence_14 = { 0500040000 3b19 730f 311418 }
- $sequence_15 = { 720b 803939 7706 fe86a8010000 }
+ $sequence_0 = { 8945c4 8b4514 8945c8 7611 33c0 8a03 8d4dc4 }
+ $sequence_1 = { 7445 6a03 8bc7 e8???????? 8b8648af0100 8bae44af0100 83c00a }
+ $sequence_2 = { 66832300 33c0 c9 c3 85c0 7515 }
+ $sequence_3 = { eb60 807e0400 7507 8bce e8???????? 807e0530 7c62 }
+ $sequence_4 = { 53 55 8b6c2448 8b4d04 8b4104 56 8bf1 }
+ $sequence_5 = { 85ed 75e5 83f808 896b14 720f 8b4304 5f }
+ $sequence_6 = { 68???????? 51 e8???????? 8b4c2468 8b7c245c 50 8b442470 }
+ $sequence_7 = { 8b442430 83c408 3bc7 720d 8b4c2414 51 e8???????? }
+ $sequence_8 = { 8d5dd0 e8???????? 46 ebb8 b8???????? e8???????? be???????? }
+ $sequence_9 = { 89ae88af0600 8bfa 7d2e 8a5c0aff 8a140a 885c241c 8854240f }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <855040
}
-rule MALPEDIA_Win_Pslogger_Auto : FILE
+rule MALPEDIA_Win_Croxloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "15c6e79e-2171-5604-b7eb-21f0a1c9eae7"
+ id = "4c54923c-05d0-5bcf-b03e-4330bb61dd7a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pslogger"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pslogger_auto.yar#L1-L171"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.croxloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.croxloader_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "8992cc308f36218b8fec7cd3351151cd41f7bbe9e5dc91614732d13ffd45e45b"
+ logic_hash = "c88e829bb61a0a12fc0c92bdb08f88ad90c78cd22176146404aa71918162c3b2"
score = 75
quality = 75
tags = "FILE"
@@ -173814,38 +180867,32 @@ rule MALPEDIA_Win_Pslogger_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7463 488bc8 e8???????? 8bc8 e8???????? 85c0 }
- $sequence_1 = { 488d8c2480030000 e8???????? 488d542420 488bcd }
- $sequence_2 = { e8???????? e9???????? 4c8bc5 33d2 488bc8 }
- $sequence_3 = { b9b80b0000 e8???????? 33d2 41b8b80b0000 488bc8 4c8be0 e8???????? }
- $sequence_4 = { 57 4883ec20 488b19 488bf9 483b5908 7418 }
- $sequence_5 = { 483bc8 740e 4885c9 7406 ff15???????? }
- $sequence_6 = { e9???????? 8d4601 4863e8 488bcd }
- $sequence_7 = { e8???????? b9b80b0000 e8???????? 33d2 }
- $sequence_8 = { 85c0 0f844c030000 83f826 7603 6a26 58 0fb60c85d64b4200 }
- $sequence_9 = { 6a00 53 e8???????? ffb5e0feffff 56 ffb5e4feffff 68???????? }
- $sequence_10 = { 8b7c2410 2bd6 83c7fe 668b4702 }
- $sequence_11 = { 7504 8816 eb3e c6060d 8b048d88b14200 8854382a }
- $sequence_12 = { c1fa06 6bc830 8b049588b14200 8a440828 a848 7404 33c0 }
- $sequence_13 = { 894606 8d4594 50 8d4676 }
- $sequence_14 = { 6bf830 894df8 6a0a 8b048d88b14200 5b 8b543818 8955ec }
- $sequence_15 = { 8b049d88b14200 8945d8 85c0 7553 e8???????? 89049d88b14200 }
+ $sequence_0 = { 488d0dd0590100 eb0c 83f901 750d 488d0dda590100 }
+ $sequence_1 = { 498b84ff18910100 90 493bc6 0f84eb000000 4885c0 }
+ $sequence_2 = { 4883ec20 488364243800 4c8d442438 8bd9 488d157aa80000 33c9 }
+ $sequence_3 = { 4b8b84e010970100 42804cf03d04 38558f ebcc ff15???????? }
+ $sequence_4 = { 488d0d09520100 e8???????? 488d0d05520100 e8???????? 488b0d???????? e8???????? 488b0d???????? }
+ $sequence_5 = { 4883f9ff 7406 ff15???????? 48832300 4883c308 488d05fc240100 }
+ $sequence_6 = { 4c8d0562eb0000 83e23f 488bcb 48c1f906 488d14d2 498b0cc8 8064d138fd }
+ $sequence_7 = { 8938 e8???????? 488d1db32f0100 4885c0 }
+ $sequence_8 = { 4c8d05c9890100 ba920e0332 b95595db6d e8???????? 4c8d05038a0100 ba436a459e b9edb0da1e }
+ $sequence_9 = { 3b1d???????? 736a 488bc3 4c8d35de000100 83e03f 488bf3 48c1fe06 }
condition:
- 7 of them and filesize <475136
+ 7 of them and filesize <241664
}
-rule MALPEDIA_Win_Qaccel_Auto : FILE
+rule MALPEDIA_Win_Nvisospit_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1dd927f1-4f29-5825-9031-a85900b0d7a3"
+ id = "824469e0-98f2-5eab-b839-ba6db77c2d16"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.qaccel"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.qaccel_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nvisospit"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nvisospit_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "fe81ee4455e2d861af0930707bfdb209646482eb98d90e9c040e2aaf3beb1c92"
+ logic_hash = "385fb86660d71ea6f219554af1885e2ee67e8307dd338d6dbd8b2f326f4be091"
score = 75
quality = 75
tags = "FILE"
@@ -173859,34 +180906,34 @@ rule MALPEDIA_Win_Qaccel_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? 50 64892500000000 56 57 8bf9 0f8816000000 }
- $sequence_1 = { 5f 5f 5f 5f 5f b801000000 5e }
- $sequence_2 = { 53 03c6 51 50 c7450c00000000 }
- $sequence_3 = { 83cbff 0f8819000000 0f8913000000 5f 5f 5f 5f }
- $sequence_4 = { 8b4020 6a05 50 ffd6 50 e8???????? 8b4820 }
- $sequence_5 = { 8d55e8 51 52 ff15???????? 8b45fc 8b4df8 6a00 }
- $sequence_6 = { 50 ffd6 50 e8???????? 0fbe4dff 8b5020 6801001c00 }
- $sequence_7 = { 5f 5f 5f 68???????? ff15???????? 85c0 }
- $sequence_8 = { 5f 5f 5f 5f 6a00 50 }
- $sequence_9 = { 5f 5f 5f 66a1???????? 8b3d???????? 6800010000 668903 }
+ $sequence_0 = { 83f801 0f851e010000 8d710c 81fe???????? 0f8350feffff 895dbc }
+ $sequence_1 = { a1???????? ffd0 83ec04 0fb785a2f9ffff 0fb7c0 8d959cf9ffff 89542410 }
+ $sequence_2 = { c70424???????? e8???????? 85db c705????????02000000 0f85d1fdffff }
+ $sequence_3 = { a1???????? 31c9 c705????????00004000 8b00 85c0 }
+ $sequence_4 = { 89442404 c70424???????? e8???????? 0fb785a8f9ffff }
+ $sequence_5 = { 0f8e16010000 85d2 0f8493010000 b9???????? 81f9???????? }
+ $sequence_6 = { 0fb7c0 8d959cf9ffff 89542410 c744240c00000000 8d958ef9ffff 89542408 }
+ $sequence_7 = { 83ec0c 8945bc 8b45bc 89442404 }
+ $sequence_8 = { e8???????? c7442404b0feffff c70424???????? e8???????? c7442404ccffffff c70424???????? }
+ $sequence_9 = { 8d9dacfbffff 81c307010000 895c2414 8d9dacfbffff 83c306 895c2410 894c240c }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <66560
}
-rule MALPEDIA_Elf_Gobrat_Auto : FILE
+rule MALPEDIA_Win_Linseningsvr_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4556c50c-642d-5e08-a37f-0bca17aca318"
+ id = "acba9094-ad6f-5dc3-983b-34f0b25c68ba"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.gobrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.gobrat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.linseningsvr"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.linseningsvr_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "d983e645d32d0df64baf254a8f8a69a3323d191b1dd7ae64a36bbf4746335d3e"
- score = 60
- quality = 35
+ logic_hash = "2644e1e1ca2803e3e5ff6eb23f753be414d9d9a67fa2dca1bfd8c0b76cd44619"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -173898,32 +180945,32 @@ rule MALPEDIA_Elf_Gobrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 48833800 0f8f28020000 488b942428010000 4885d2 7508 e8???????? }
- $sequence_1 = { 84c0 745c 488b542430 488b5a30 488b742428 488b4630 488b4e38 }
- $sequence_2 = { c644242903 488d055aca3200 488d5c2418 e8???????? 4889c3 488d0546ca3200 e8???????? }
- $sequence_3 = { eb41 488d059c311e00 e8???????? 48c740081c000000 488d0d39a62300 488908 31db }
- $sequence_4 = { e8???????? 488b942460020000 488b7218 48897020 48837a7000 7542 488d1df7fc3200 }
- $sequence_5 = { c3 31c0 488b6c2478 4883ec80 c3 488b8c2488000000 488b4110 }
- $sequence_6 = { f7da 410fafd1 89d2 480fafd3 48c1ea2f 4489c6 41c1e008 }
- $sequence_7 = { ffd2 b91a000000 4889c7 4889de 31c0 488d1dd7ce2d00 e8???????? }
- $sequence_8 = { b825010000 e8???????? 4885c9 745d 4883f902 7712 753c }
- $sequence_9 = { e8???????? 48c7400822000000 488d0de4212200 488908 31db 4889d9 488d3d244d2a00 }
+ $sequence_0 = { 81c4cc0d0000 c3 68ffffff7f 56 ff15???????? 83f8ff }
+ $sequence_1 = { 5d b801000000 5b 81c4cc0d0000 }
+ $sequence_2 = { 8b4c2428 6a24 8d542464 6a01 52 89442464 }
+ $sequence_3 = { 7e16 8b742414 8bd1 8d7c1f18 c1e902 f3a5 8bca }
+ $sequence_4 = { f6c202 7410 8088????????20 8a9405ecfcffff ebe3 80a0808b400000 40 }
+ $sequence_5 = { 0f858b030000 33c9 8acc 3ac8 }
+ $sequence_6 = { 55 6800010000 8d942464040000 6a01 52 e8???????? }
+ $sequence_7 = { 8acc 3ac8 0f857f030000 33d2 55 89542432 }
+ $sequence_8 = { 66895c2411 89442419 885c2418 8944241d 89442421 6689442425 88442427 }
+ $sequence_9 = { 7514 ff15???????? 50 68???????? e8???????? 83c408 55 }
condition:
- 7 of them and filesize <12853248
+ 7 of them and filesize <81360
}
-rule MALPEDIA_Win_Joao_Auto : FILE
+rule MALPEDIA_Win_Isspace_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d37cc5ea-3d73-5336-a732-17564803dcb9"
+ id = "6de2cc9e-3c1b-5d82-85e8-a409082de585"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.joao"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.joao_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.isspace"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.isspace_auto.yar#L1-L100"
license_url = "N/A"
- logic_hash = "86dd7ba6af2ece0f6d3df07328920c1e2520bb8d3e325d921ed8a0a42914959d"
+ logic_hash = "e463ab51553d0208df8251abb329c162f866232bb82c29826d5e55ecd0eb426f"
score = 75
quality = 75
tags = "FILE"
@@ -173937,32 +180984,30 @@ rule MALPEDIA_Win_Joao_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bce 897dfc e8???????? 837de810 c745fcffffffff 720c 8b45d4 }
- $sequence_1 = { 8b4e08 2b0e c1f905 3bc8 }
- $sequence_2 = { 8d4dd0 51 8bce 897dfc e8???????? }
- $sequence_3 = { 50 6a0f 68???????? e8???????? 8b5510 8d8df8feffff }
- $sequence_4 = { 8b4804 8b4c3138 c645ef01 4b }
- $sequence_5 = { 8d45f8 50 8bce c745f809000000 897dfc e8???????? 8d4df8 }
- $sequence_6 = { e8???????? 8b4604 83e7e0 033e }
- $sequence_7 = { 8b4c3224 8b443220 c645fc03 85c9 7c15 7f04 }
- $sequence_8 = { 8d4dd4 e8???????? 8d4dd0 51 8bce 897dfc e8???????? }
- $sequence_9 = { 8b4e08 2b0e c1f905 3bc8 736a 8d7e0c 50 }
+ $sequence_0 = { 57 50 8d45f0 64a300000000 8965e8 c745fc00000000 c785505cffff00a20000 }
+ $sequence_1 = { 46 8bc6 c1e004 03c6 }
+ $sequence_2 = { ff15???????? 50 eb05 68???????? 68???????? ff15???????? }
+ $sequence_3 = { 6800010000 8d8600010000 6a00 50 e8???????? 83c418 8bc6 }
+ $sequence_4 = { e8???????? 83c418 83c60a 56 }
+ $sequence_5 = { 85c0 7507 68???????? eb04 83c007 }
+ $sequence_6 = { c78548ffffff9c000000 e8???????? 8ad8 c745fc00000000 }
+ $sequence_7 = { eb0a 6a00 6a23 eb04 6a00 }
condition:
- 7 of them and filesize <2867200
+ 7 of them and filesize <434176
}
-rule MALPEDIA_Win_Mikoponi_Auto : FILE
+rule MALPEDIA_Win_Microbackdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e1f9d663-47fc-536a-afed-a18f76559a32"
+ id = "32768709-e0c4-568e-99b5-4d92498e8c97"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mikoponi"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mikoponi_auto.yar#L1-L105"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.microbackdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.microbackdoor_auto.yar#L1-L174"
license_url = "N/A"
- logic_hash = "e53726bff6b275a8cbfe6479d201a659d381061025ff16663204532183241afc"
+ logic_hash = "d87bae84a1434eb391a7ebc0d4af12aee586692c39928b7bf8d060b1c97f49c6"
score = 75
quality = 75
tags = "FILE"
@@ -173976,30 +181021,38 @@ rule MALPEDIA_Win_Mikoponi_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b0f 51 e8???????? 83c404 5d 5f 83c408 }
- $sequence_1 = { e8???????? 83c404 eb15 8d942464020000 52 8d442418 }
- $sequence_2 = { 33ed 391d???????? 743d bf???????? }
- $sequence_3 = { b9???????? 66895010 c7004418a150 e8???????? 8d3c47 }
- $sequence_4 = { 53 55 e8???????? 83c40c 84c0 7506 83c3ff }
- $sequence_5 = { 803d????????01 56 7527 8b742408 56 ff15???????? }
- $sequence_6 = { e8???????? 81c470040000 c3 8b542430 3b542420 750e }
- $sequence_7 = { 7543 3805???????? 753b 8d8c2464020000 51 68???????? }
+ $sequence_0 = { 0fb74510 50 ff750c ff15???????? }
+ $sequence_1 = { ffd7 eb06 ff15???????? 8bc6 eb06 }
+ $sequence_2 = { 488bcd 418bdc 4d8bfc e8???????? 85db 755b 488d842478020000 }
+ $sequence_3 = { 8939 488d4c2430 41b89c000000 e8???????? 488d4c2430 }
+ $sequence_4 = { 74df 8d047506000000 50 6a40 ff15???????? 8bc8 894d0c }
+ $sequence_5 = { 85c0 751d 837c247001 7516 395c2478 7610 488b4c2430 }
+ $sequence_6 = { 4885db 7417 0fb7445ffe 6683f85c 7406 6683f82f }
+ $sequence_7 = { 498bce 33f6 e8???????? 85ed }
+ $sequence_8 = { 498bce 4489bc2488000000 453bc4 4c897c2420 }
+ $sequence_9 = { 56 6a00 6a00 68???????? ff75f8 ff15???????? 85c0 }
+ $sequence_10 = { ff15???????? 8d4336 50 6a40 ff15???????? 8bf8 }
+ $sequence_11 = { 8bf8 897dd4 85ff 7498 837df800 b9???????? 8b5dfc }
+ $sequence_12 = { ff15???????? 488bd8 4885c0 7512 ff15???????? 488d0d503e0000 }
+ $sequence_13 = { 8bf8 e9???????? 33c0 40 e9???????? ff15???????? }
+ $sequence_14 = { 83feff 743b 8b4d0c ff7510 894df4 ff15???????? 668945f2 }
+ $sequence_15 = { 85c0 0f84bb010000 66833d????????00 0f84ad010000 }
condition:
- 7 of them and filesize <330752
+ 7 of them and filesize <123904
}
-rule MALPEDIA_Win_Jaff_Auto : FILE
+rule MALPEDIA_Win_Loup_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "05c08a02-2b7b-5977-8a51-2a2090077d3b"
+ id = "f9d1b576-d285-5231-afcb-2e4f16800d77"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jaff"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jaff_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.loup"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.loup_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "af5ef67353fca994a67e82aadde11782d5e684720bb76ef0f2df38c565071742"
+ logic_hash = "ff0573e37f479d8813fb50aaed8f812906a0bad4de56fabb213fa961c6890498"
score = 75
quality = 75
tags = "FILE"
@@ -174013,32 +181066,32 @@ rule MALPEDIA_Win_Jaff_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c746080a000000 c6460c01 ffd7 8b1d???????? 50 ffd3 6a14 }
- $sequence_1 = { 8bf8 e8???????? 8b4704 48 7818 }
- $sequence_2 = { 8b4514 8b4d10 6a00 8d55fc 52 50 51 }
- $sequence_3 = { 72ed 8b45dc 50 6a00 ffd7 50 }
- $sequence_4 = { ffd3 8945f0 8b450c 8d5de0 8d4df0 e8???????? 8b45e0 }
- $sequence_5 = { 3b4510 0f82a5feffff 8b4d14 51 6a00 }
- $sequence_6 = { 8d5598 52 8d45cc 50 e8???????? 8d7da8 }
- $sequence_7 = { 33c2 2bc2 50 8d95f8fbffff 68???????? }
- $sequence_8 = { 8d4584 e8???????? 8d7da4 8d75e4 e8???????? 8b55a4 8b3d???????? }
- $sequence_9 = { c745f00a000000 c645f401 ffd3 50 ff15???????? 8945e8 }
+ $sequence_0 = { 83c404 85c0 741c 0fb745f4 50 e8???????? }
+ $sequence_1 = { 81781422059319 740c 8b4dfc 81791400409901 7522 e8???????? 8b55fc }
+ $sequence_2 = { 8b0d???????? 898dc8fbffff 8b15???????? 8995ccfbffff a1???????? 8985d0fbffff }
+ $sequence_3 = { 8b85d0f1ffff 53 56 ff3485647b4100 50 }
+ $sequence_4 = { 8b7508 57 85d2 744f 33ff 393a }
+ $sequence_5 = { 81f247656e75 b804000000 6bc803 8b440de0 35696e6549 }
+ $sequence_6 = { 8b4df4 84c0 0f84defeffff c745dc01000000 e9???????? 5f 5e }
+ $sequence_7 = { 668945e8 33c0 668945ea c745ee01000000 b804000000 668945ec }
+ $sequence_8 = { b804000000 c1e002 c784055cffffff01000000 8d855cffffff 8945d5 }
+ $sequence_9 = { 85c0 7443 0fb745f4 50 }
condition:
- 7 of them and filesize <106496
+ 7 of them and filesize <257024
}
-rule MALPEDIA_Win_Grok_Auto : FILE
+rule MALPEDIA_Win_Farseer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "870cf4c1-459b-52f4-a686-b281f5585948"
+ id = "bdb1b674-d96e-50d4-8dbe-83cb253d9330"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grok"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grok_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.farseer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.farseer_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "f55e3b1924db1bff1757dac784f11d8f8a3020681a2893ba57b274944ef08137"
+ logic_hash = "17f8792326231b41b2e91221ee87a535fdccf3e2e964ba78d0722fea338c91a0"
score = 75
quality = 75
tags = "FILE"
@@ -174052,32 +181105,32 @@ rule MALPEDIA_Win_Grok_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 39702c 7413 56 ff702c ffd3 a1???????? 89702c }
- $sequence_1 = { 7c62 a1???????? 397044 7412 56 ff7044 ff15???????? }
- $sequence_2 = { 51 57 50 e8???????? 83c40c 57 53 }
- $sequence_3 = { 33ff 897dd8 81ff00010000 7d28 8d0c17 8b4514 03c7 }
- $sequence_4 = { a1???????? 895820 a1???????? 395824 }
- $sequence_5 = { 894df4 eb09 8b55f4 83c201 8955f4 8b45f8 83c009 }
- $sequence_6 = { 5f 56 56 6a22 6a01 56 }
- $sequence_7 = { 50 e8???????? 3bc3 7d7e 395d08 7479 3d430000c0 }
- $sequence_8 = { 33ff 47 3bc3 8945fc 0f8c9c000000 391d???????? 7410 }
- $sequence_9 = { 53 51 03c6 50 e8???????? 8b463c 8d8c3080000000 }
+ $sequence_0 = { 8d4c2434 e8???????? eb10 6a06 68???????? 8d4c2438 }
+ $sequence_1 = { 50 8d4c2440 51 8d542478 }
+ $sequence_2 = { e8???????? 8d742414 e8???????? 53 50 83c8ff 8d742438 }
+ $sequence_3 = { 8d442434 50 e8???????? c68424c402000002 8b8424cc000000 bb10000000 399c24e0000000 }
+ $sequence_4 = { 0f8c6cffffff 33ed 8d9424ac010000 68???????? 52 e8???????? 83c408 }
+ $sequence_5 = { 33db 6aff 899c2498000000 53 8d8424a4000000 be0f000000 50 }
+ $sequence_6 = { 7510 8bc1 eb0c 0fb6c9 0fbe8940454200 03c1 40 }
+ $sequence_7 = { 83c404 83bc24e402000010 7210 8b9424d0020000 52 e8???????? 83c404 }
+ $sequence_8 = { 85410c 7405 e8???????? 8d742440 e8???????? 85c0 }
+ $sequence_9 = { e9???????? 8bc3 c1f805 8d048520634200 83e31f 8985e4efffff 8b00 }
condition:
- 7 of them and filesize <84992
+ 7 of them and filesize <347328
}
-rule MALPEDIA_Win_Miancha_Auto : FILE
+rule MALPEDIA_Win_Dinodas_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5e7fc19e-d4d3-5751-a42a-778cf2bcb637"
+ id = "0c2a0c7f-3a72-55a1-acff-1cca63da0ecc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miancha"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.miancha_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dinodas_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dinodas_rat_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "1f67b71b2562c78fd331e78fe99dcc1e4206e3c62481b807645f41343dd343bc"
+ logic_hash = "146f67c88b1bd9a83aac7a1be7e8f308bd7d506106d4fba538a0dc2d1ddf0d08"
score = 75
quality = 75
tags = "FILE"
@@ -174091,32 +181144,32 @@ rule MALPEDIA_Win_Miancha_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7412 8d542418 52 ff15???????? }
- $sequence_1 = { 6803000080 ff15???????? 85c0 741f 6a00 }
- $sequence_2 = { 8b15???????? 894808 8a0d???????? 89500c 884810 }
- $sequence_3 = { 40 50 56 8b35???????? 6a02 6a00 }
- $sequence_4 = { 85f6 7412 8d542418 52 ff15???????? 50 }
- $sequence_5 = { ff15???????? 50 ffd6 85c0 741a }
- $sequence_6 = { 8d542418 52 ff15???????? 50 ffd6 85c0 }
- $sequence_7 = { 50 68???????? e8???????? 33f6 83c408 }
- $sequence_8 = { 8910 8b15???????? 894804 8b0d???????? 895008 8a15???????? }
- $sequence_9 = { 8910 8b15???????? 894804 8b0d???????? 895008 8a15???????? 89480c }
+ $sequence_0 = { 85c9 743b 8b10 8b04b2 8b400c 85c0 7409 }
+ $sequence_1 = { 6a18 c705????????acff4300 c705????????00000000 e8???????? 83c404 85c0 }
+ $sequence_2 = { 50 51 ffd3 83bdb85fffff00 75af 837e2c00 }
+ $sequence_3 = { 833c0e00 755b 8b5dd4 8b4304 80781500 8bd3 7522 }
+ $sequence_4 = { df6df8 df6de0 def9 dc0d???????? dd45d8 d8d9 dfe0 }
+ $sequence_5 = { 83bdd4c3ffff10 7306 8d85c0c3ffff 56 50 57 e8???????? }
+ $sequence_6 = { 8344241408 894c2420 83e908 89542434 8b542430 33db 8bf7 }
+ $sequence_7 = { 8b55d0 8b45cc 8b4dec 2bd0 41 c1fa02 894dec }
+ $sequence_8 = { e8???????? 8b8d6cffffff 8bb568ffffff 2bce b893244992 f7e9 03d1 }
+ $sequence_9 = { 7546 8b15???????? 6aff 52 ffd7 8d5d08 8d45f8 }
condition:
- 7 of them and filesize <376832
+ 7 of them and filesize <638976
}
-rule MALPEDIA_Win_Grimplant_Auto : FILE
+rule MALPEDIA_Win_Kerrdown_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c3eab5e9-e64a-5697-878f-14199bbf7239"
+ id = "4e6c0456-511b-5ce5-b1ea-436b1b2f6672"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grimplant"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grimplant_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kerrdown"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kerrdown_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "eec64e00f45245d4dee8d091e0d2ebea0088235a6d441087ed38c039f05955af"
+ logic_hash = "a33ff3dd3ba2b88105d1e9461a66c5947186b615b759549afa7c04ba76dcfedd"
score = 75
quality = 75
tags = "FILE"
@@ -174129,33 +181182,33 @@ rule MALPEDIA_Win_Grimplant_Auto : FILE
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
- strings:
- $sequence_0 = { e9???????? 3c08 7465 eb15 3c0e 0f8ff5000000 90 }
- $sequence_1 = { ffd2 eb3d 488b4c2428 488b91d0000000 488b442438 ffd2 4885c0 }
- $sequence_2 = { eb1f 488db8486a0100 488d15ac5c5000 e8???????? 488db8506a0100 e8???????? 440f11b8586a0100 }
- $sequence_3 = { ffd2 b914000000 4889c7 4889de 31c0 488d1da6514200 e8???????? }
- $sequence_4 = { ffd1 4883f805 0f85f2100000 0f1005???????? 0f11442478 0f1005???????? 0f11842488000000 }
- $sequence_5 = { 746c 4c8b4018 49ffc0 4c394020 7d5f 488d05a3ab1d00 0f1f00 }
- $sequence_6 = { 90 488d05cbd28b00 e8???????? 488b442470 4c8b442440 4c8b4c2458 e9???????? }
- $sequence_7 = { c6401801 440f113c24 48c744241000000000 488b9c2480000000 4889c1 488bbc24a0000000 488bb424a8000000 }
- $sequence_8 = { 90 488d0567839000 e8???????? 8b542440 448b8424b0000000 448b4c2444 89d0 }
- $sequence_9 = { eb0f 4889c7 488d159ceb1300 e8???????? 488d0588670a00 488b5c2448 b906000000 }
-
+ strings:
+ $sequence_0 = { 5d c20800 85f6 75b2 83ff10 8935???????? b8???????? }
+ $sequence_1 = { 8bec 8b0d???????? b8???????? 8b15???????? 57 8b3d???????? 83ff10 }
+ $sequence_2 = { 8aca c0e206 c0e902 80e10f 02c8 8a45eb 243f }
+ $sequence_3 = { b8???????? 0f43d1 b9???????? 2bc2 50 }
+ $sequence_4 = { 0f43c1 3d???????? 773e 83ff10 }
+ $sequence_5 = { 83ff10 ba???????? b8???????? 0f43d1 b9???????? 2bc2 }
+ $sequence_6 = { 80e10f 02c8 8a45eb 243f }
+ $sequence_7 = { ff750c 83ff10 ba???????? b8???????? 0f43d1 b9???????? 2bc2 }
+ $sequence_8 = { e8???????? 46 83fe03 7cec 8b4de0 }
+ $sequence_9 = { 0f854d0d0000 eb00 f30f7e442404 660f2815???????? 660f28c8 }
+
condition:
- 7 of them and filesize <19940352
+ 7 of them and filesize <278528
}
-rule MALPEDIA_Win_Montysthree_Auto : FILE
+rule MALPEDIA_Win_Gophe_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5df0d300-da50-5a49-9998-41d773ee6c8b"
+ id = "16e0cb01-a4d6-50a6-a1a9-0b51a47ac5bb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.montysthree"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.montysthree_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gophe"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gophe_auto.yar#L1-L156"
license_url = "N/A"
- logic_hash = "00fdc41dcd00cadf758a1f9a8aa235f12bbf1e307fd238ef7d6a32ae7dd0988d"
+ logic_hash = "76443f258bf0b4ec57a2e148e70e44580d537156fff783e9c0d09eeae8abd68d"
score = 75
quality = 75
tags = "FILE"
@@ -174169,32 +181222,38 @@ rule MALPEDIA_Win_Montysthree_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8bf0 3bf3 89754c }
- $sequence_1 = { 8bd4 46 62807013e64e 13e6 d1b660d40c3e }
- $sequence_2 = { 8d4d70 e8???????? ff30 687b020000 57 68???????? e8???????? }
- $sequence_3 = { ff75f0 ffd6 8bc7 f7d8 }
- $sequence_4 = { 50 bf00040000 57 ff15???????? 85c0 8d8574f7ffff 7405 }
- $sequence_5 = { ff7508 53 ff15???????? 53 8d83080a0000 50 }
- $sequence_6 = { 8d4d28 e8???????? 50 68???????? e8???????? }
- $sequence_7 = { 8933 39753c 8b457c 8930 753d 39756c }
- $sequence_8 = { e8???????? 8d8570fdffff 50 8d4dc4 }
- $sequence_9 = { ff756c ff15???????? 8d4524 50 8d4d4c e8???????? eb25 }
+ $sequence_0 = { 833902 0f94c0 84c0 7407 }
+ $sequence_1 = { b905000000 ff15???????? 8b05???????? 85c0 }
+ $sequence_2 = { 56 8b7510 57 68???????? c70605000000 }
+ $sequence_3 = { b801000000 eb09 83c8ff eb04 }
+ $sequence_4 = { 51 a1???????? 33c5 50 8d45f4 64a300000000 68e0000000 }
+ $sequence_5 = { 5b 8be5 5d c3 b896ffffff }
+ $sequence_6 = { 64a300000000 68e0000000 e8???????? 83c404 }
+ $sequence_7 = { 6805010000 8d85e0fdffff 50 68???????? }
+ $sequence_8 = { 85c9 0f94c0 89431c 85c9 }
+ $sequence_9 = { 7838 488b4c2440 ff15???????? 8bf8 }
+ $sequence_10 = { 2bf0 b8abaaaa2a f7ee c1fa03 8bf2 }
+ $sequence_11 = { 8bf8 488b4c2440 488b01 ff5010 85ff }
+ $sequence_12 = { e8???????? 488d942488000000 488d4c2460 e8???????? }
+ $sequence_13 = { c684249000000000 488b542440 488b4a10 668379300b }
+ $sequence_14 = { 6a00 56 e8???????? 83c40c c706ffffffff }
+ $sequence_15 = { 5d c3 b896ffffff 5f 5e 5b }
condition:
- 7 of them and filesize <458752
+ 7 of them and filesize <1582080
}
-rule MALPEDIA_Win_Keylogger_Apt3_Auto : FILE
+rule MALPEDIA_Win_Helauto_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0f9f82cd-fdec-56a7-a0cb-1e9762492ad7"
+ id = "8190d0b6-60e2-55b8-bbd3-4f8143a5c37c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.keylogger_apt3"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.keylogger_apt3_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.helauto"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.helauto_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "d74e9ef23a0b946252054fc1985382779e2408df3e68ecb0420a27d04cacd609"
+ logic_hash = "4d9d81740e3a201d5c095a9d2008fa9ef0381381c707cf34a732c2ace99e1c38"
score = 75
quality = 75
tags = "FILE"
@@ -174208,34 +181267,34 @@ rule MALPEDIA_Win_Keylogger_Apt3_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8be8 8d442458 50 55 57 }
- $sequence_1 = { 3bf3 7523 68???????? ff15???????? 5f }
- $sequence_2 = { 8b35???????? 8d6b08 55 50 ffd6 }
- $sequence_3 = { 7453 53 8b5c240c 55 56 8b35???????? 8d6b08 }
- $sequence_4 = { 89442420 3bf8 7216 5b 5f }
- $sequence_5 = { ffd6 50 ffd7 ffd3 89442420 83f8ff 7551 }
- $sequence_6 = { 0fb69695010000 50 0fb68694010000 51 52 50 }
- $sequence_7 = { 84c0 75f8 2be9 8d5501 52 }
- $sequence_8 = { e8???????? 68???????? 68???????? 8d4d7c e8???????? 8b45dc }
- $sequence_9 = { c7442434d8174300 ffd6 8d542404 52 89442434 }
+ $sequence_0 = { 8b45d4 83c40c 898568ffffff 8b45d0 }
+ $sequence_1 = { ff75ec ffd6 6830750000 eb48 }
+ $sequence_2 = { 69c060ea0000 83c430 3d60ea0000 a3???????? }
+ $sequence_3 = { 85c0 0f841f010000 8b3d???????? 6a05 8d85a8f3ffff 68???????? }
+ $sequence_4 = { 59 50 8d8574ffffff 50 53 53 ff75fc }
+ $sequence_5 = { 85c0 7508 53 ff15???????? 59 33c0 }
+ $sequence_6 = { 50 ff15???????? 83c40c 85c0 0f8593000000 50 }
+ $sequence_7 = { 68???????? 50 ff15???????? 83c40c 85c0 0f8593000000 }
+ $sequence_8 = { 8d4608 50 68???????? 53 e8???????? 83c418 83feff }
+ $sequence_9 = { 51 8d4df0 e8???????? 8365fc00 8d4df0 }
condition:
- 7 of them and filesize <761856
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Tinynuke_Auto : FILE
+rule MALPEDIA_Win_Zeoticus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d780fd7f-583b-590f-a92f-7ac4fac52f1d"
+ id = "c2a18f25-bc43-5657-ba7f-277a7d143bb2"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinynuke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tinynuke_auto.yar#L1-L294"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeoticus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeoticus_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "f182ca1cbc1a4db59bec12699d68404bb9da6364ccc0407277f19ab284be21eb"
+ logic_hash = "a4d1e69467730f44a44fc31899a04b37f3c67c9d35561598e18a4009fa030896"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -174247,54 +181306,32 @@ rule MALPEDIA_Win_Tinynuke_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c3 55 8bec 817d0c00040000 }
- $sequence_1 = { 6aff ff7508 6a00 68e9fd0000 ff15???????? 8bc3 5b }
- $sequence_2 = { 7625 53 8b5d08 57 8b7d10 57 }
- $sequence_3 = { ff35???????? a3???????? 57 ff15???????? ff35???????? 8b7dfc }
- $sequence_4 = { 50 56 57 ff35???????? c745f801000000 }
- $sequence_5 = { 8d8530f6ffff 50 6802020000 ff15???????? 85c0 }
- $sequence_6 = { 8945f4 8d85d4feffff 50 ff15???????? }
- $sequence_7 = { 6a03 53 53 6800000080 50 ff15???????? a3???????? }
- $sequence_8 = { ff75ec ff75fc e8???????? 83c40c 5f }
- $sequence_9 = { ff15???????? ff35???????? 8d85a4feffff 50 }
- $sequence_10 = { 8d85a4feffff 50 ff15???????? ff35???????? }
- $sequence_11 = { ff15???????? a3???????? ff35???????? ff75f8 }
- $sequence_12 = { a3???????? 68e2010000 68???????? 68???????? e8???????? }
- $sequence_13 = { e8???????? eb18 83f803 7519 }
- $sequence_14 = { 59 a3???????? c9 c3 55 }
- $sequence_15 = { 6a2a 50 8945fc ff15???????? }
- $sequence_16 = { a3???????? ff35???????? ff75ec ff15???????? }
- $sequence_17 = { 8a00 3c0a 7409 3c0d }
- $sequence_18 = { 50 8d85f0fdffff 50 ff15???????? ff75fc 8d85f0fdffff }
- $sequence_19 = { ff15???????? 8d85d0fcffff 50 e8???????? 59 }
- $sequence_20 = { ff15???????? 8b35???????? 8d430c 50 }
- $sequence_21 = { 8b0f 85c9 742a 8d440b02 85c9 }
- $sequence_22 = { 8b44241c 8bb0a0000000 2b6834 01de 8b16 85d2 }
- $sequence_23 = { 8bb90000e06e 0f848e000000 83fa20 0f84f0000000 83fa08 0f84b4000000 }
- $sequence_24 = { 890424 89442418 e8???????? 89c3 }
- $sequence_25 = { ffd6 57 53 ffd6 5f 5e 8bc3 }
- $sequence_26 = { 8b06 85c0 75b7 8b7c241c 8b8780000000 }
- $sequence_27 = { c744240840000000 891c24 89dd 8944240c 8b442418 89442404 e8???????? }
- $sequence_28 = { 745c 01d8 890424 e8???????? 83ec04 89c6 }
- $sequence_29 = { a1???????? 83c014 03c7 894df8 8945f4 7417 }
- $sequence_30 = { 03c7 83f864 0f873f010000 8b45c0 8b7dbc }
- $sequence_31 = { c744241000000000 c744240c50c30000 c744240850c30000 c744240400000000 e8???????? }
+ $sequence_0 = { b901000000 8b442404 0f44f1 85c0 7407 50 ff15???????? }
+ $sequence_1 = { 6a00 6a02 6a01 6a00 6a00 6a00 6890010000 }
+ $sequence_2 = { 53 68???????? 50 89048d00574300 ff15???????? a1???????? 83c410 }
+ $sequence_3 = { 8b0d???????? 8d442420 6a00 6a00 6a00 6a25 6800800000 }
+ $sequence_4 = { 8d4c2430 6a18 51 ffd0 a1???????? 83c408 85c0 }
+ $sequence_5 = { 42 88440e14 8b4c2424 41 894c2424 83fa0b }
+ $sequence_6 = { 56 57 8b7c2414 894c2418 390f 0f86df010000 }
+ $sequence_7 = { a3???????? c705????????00000000 c705????????00000000 c705????????00000000 e8???????? 8b4c2408 8b542404 }
+ $sequence_8 = { 56 57 894c2410 8b7810 8bf7 90 }
+ $sequence_9 = { 83c408 a3???????? ff742420 ffd0 85c0 754a }
condition:
- 7 of them and filesize <1196032
+ 7 of them and filesize <468992
}
-rule MALPEDIA_Win_Poslurp_Auto : FILE
+rule MALPEDIA_Win_Sidetwist_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7a8f0443-88b1-5a4f-a35b-b7bc9acf8924"
+ id = "234f5e67-21ea-563f-a765-16d670746925"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poslurp"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poslurp_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sidetwist"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sidetwist_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "95156f0f62f3b9458f6ba6ac285abaa70aca50d75127c0a8cc32d91b8191c0ea"
+ logic_hash = "5b593ac062a3ee588643c8e2045ef28da674c3f54189c5d0eebe42dcfcc6f71f"
score = 75
quality = 75
tags = "FILE"
@@ -174308,32 +181345,32 @@ rule MALPEDIA_Win_Poslurp_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f87fd000000 668378203d 0f85f2000000 498bce }
- $sequence_1 = { cc 33c9 ff15???????? cc 488bac2440010000 }
- $sequence_2 = { 488bf5 498bfc f3a4 498bcc e8???????? }
- $sequence_3 = { ff15???????? 4c8be8 4885c0 0f84c2000000 4863453c }
- $sequence_4 = { 488d15a9100000 41b93f000f00 4533c0 48c7c102000080 }
- $sequence_5 = { 418bc1 41ffc0 486bc022 4803c2 48ffc2 }
- $sequence_6 = { 0f8301010000 418bd6 498bcf 8bfb 412bd7 }
- $sequence_7 = { 0f84ae000000 80393d 0f85a5000000 418bd6 }
- $sequence_8 = { 418bc8 ffce 488bd5 2bcd 8bfb }
- $sequence_9 = { 488bd8 4883f8ff 0f84c8010000 448b05???????? 4889ac24a0020000 4889b424a8020000 4889bc24b0020000 }
+ $sequence_0 = { c644244600 4839d0 0f833a020000 488b4c2450 837c2458ff 0f94c0 4885c9 }
+ $sequence_1 = { e8???????? 807e2000 48898424b0000000 7412 488d8c24b0000000 ba20000000 e8???????? }
+ $sequence_2 = { 4488742457 0fb6442457 4c8db42494000000 4c8d4c2460 4889fa 4c89742440 488d8c2480000000 }
+ $sequence_3 = { 89c8 884520 807d2040 7612 807d205a 770c 0fb64520 }
+ $sequence_4 = { 896e18 4809c3 4889f8 488917 48895f08 4883c458 5b }
+ $sequence_5 = { bfffffffff 41bfffffffff e9???????? c644246c00 8844246e e9???????? 488b03 }
+ $sequence_6 = { 4c29cb 4c39c3 490f47d8 4885db 7411 480310 4883fb01 }
+ $sequence_7 = { 7218 4c8b05???????? 458b08 4585c9 755e 448b41f8 4585c0 }
+ $sequence_8 = { 89c7 440fb603 29df c1e702 4885c0 b800000000 0f44f8 }
+ $sequence_9 = { 6690 4885d2 7521 448b1e 4585db 0f8524020000 8b05???????? }
condition:
- 7 of them and filesize <50176
+ 7 of them and filesize <2002944
}
-rule MALPEDIA_Win_Halfrig_Auto : FILE
+rule MALPEDIA_Win_Varenyky_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4f3cbac9-fb70-5f5f-a1a6-aa00243a3db8"
+ id = "799963a3-0366-58c7-b923-0a51c9db342a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.halfrig"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.halfrig_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.varenyky"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.varenyky_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "fd3e289580ee05538ff1447ee4a76bbaba1a2cf6f44fe795cbd300f7fc8296a1"
+ logic_hash = "9e07244b9e5d336f26b69f46ff4024108fa6443c2648edcc9fb5aa11d967154b"
score = 75
quality = 75
tags = "FILE"
@@ -174347,32 +181384,32 @@ rule MALPEDIA_Win_Halfrig_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 833d????????ff 752a 488d0dee900400 c705????????679f9b01 c705????????6680ec92 c705????????3f7d27f5 e8???????? }
- $sequence_1 = { 833d????????ff 7539 488d0d67740400 66c705????????fd01 c705????????6881e28d }
- $sequence_2 = { e8???????? 488d0d6c950700 e8???????? 40383d???????? 7435 660f1f440000 }
- $sequence_3 = { 75ad 0fb600 498bcf 8802 488d542420 e8???????? 488d0d58c70600 }
- $sequence_4 = { 48c1e008 488bd1 49ffc0 4833d0 4983f80f 72db 408835???????? }
- $sequence_5 = { 8802 488d542420 e8???????? 488d0d4cef0900 e8???????? 40383d???????? }
- $sequence_6 = { 488d542420 e8???????? 488d0d08830600 e8???????? 40383d???????? 7435 488bd3 }
- $sequence_7 = { 75ad 0fb600 498bcf 8802 488d542420 e8???????? 488d0df8da0500 }
- $sequence_8 = { 8802 488d542420 e8???????? 488d0df8930600 e8???????? 40383d???????? }
- $sequence_9 = { 488d0d88080800 e8???????? 40383d???????? 7435 }
+ $sequence_0 = { 8b3d???????? 8b542418 6a00 52 8d8424c0130000 50 55 }
+ $sequence_1 = { 8d542435 6a00 52 c644243c00 e8???????? }
+ $sequence_2 = { 6880000000 8bd6 52 ff15???????? 6803010000 8d842485020000 }
+ $sequence_3 = { 83c40c 6a40 898424a4010000 898c249c010000 8a0d???????? 899424a0010000 8d442450 }
+ $sequence_4 = { 03f0 0fbe01 3bc3 75f0 }
+ $sequence_5 = { 57 e8???????? 83c404 3c32 }
+ $sequence_6 = { 8d84244d030000 53 50 c744242404010000 889c2454030000 e8???????? }
+ $sequence_7 = { 51 ffd6 68???????? 8d542474 52 ffd7 }
+ $sequence_8 = { 56 57 6803010000 8d44243d 53 50 885c2444 }
+ $sequence_9 = { 41 03e8 0fbe01 3bc3 75f0 0fbe842440020000 }
condition:
- 7 of them and filesize <1369088
+ 7 of them and filesize <24846336
}
-rule MALPEDIA_Win_Slickshoes_Auto : FILE
+rule MALPEDIA_Win_Cloudwizard_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "86c839b6-e5b0-5f50-b2eb-341682181175"
+ id = "429d1e4e-ef3f-5d58-8bf0-a0b83d6be71f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.slickshoes"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.slickshoes_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cloudwizard"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cloudwizard_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "a30adc8e9bcf8ed13fec8919d0e4389d7fc505e3cf19302dcab25ec63fa5bcd2"
+ logic_hash = "1171accd4a2881e0996da43d7ff173c5cb1938e75ca585c448a0136c0ce6d102"
score = 75
quality = 75
tags = "FILE"
@@ -174386,32 +181423,32 @@ rule MALPEDIA_Win_Slickshoes_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? 81c204000000 55 bd2a3bff63 81e5fb17be7f e9???????? 57 }
- $sequence_1 = { e9???????? f7d2 50 e9???????? b87073f77f f7d8 0d90f1fe6f }
- $sequence_2 = { 81f61f000000 2d01000000 6681ebb987 81f704000000 b800020000 89fa b800000000 }
- $sequence_3 = { e9???????? b804000000 01c1 58 81c104000000 e9???????? 83c404 }
- $sequence_4 = { e9???????? b931bbb979 81e13b81af7f e9???????? 5a 01d1 81e91dadf56e }
- $sequence_5 = { ff3424 5f 83c404 50 54 58 0504000000 }
- $sequence_6 = { e9???????? bd40d86e7e 81c74b047f7d 29ef 81ef4b047f7d 5d 81f75adb6482 }
- $sequence_7 = { e9???????? 81c104000000 57 52 68f987eb16 8b1424 81c404000000 }
- $sequence_8 = { 89ee b80a000000 81cf40000000 2d04000000 09c7 81c302000000 01d7 }
- $sequence_9 = { 8b12 81c206000000 0fb732 81f128000000 09d1 01d1 31c3 }
+ $sequence_0 = { c3 8d85d4fdffff 50 57 c785d4fdffff2c020000 e8???????? }
+ $sequence_1 = { 668945ee 58 6a7c 668945f0 58 6a6d }
+ $sequence_2 = { 8d45ec 663118 40 40 }
+ $sequence_3 = { 8bc8 8d8618060000 8d7802 668b18 40 40 6685db }
+ $sequence_4 = { ebd6 55 8bec 81ecb80e0000 }
+ $sequence_5 = { 6a01 897dfc 57 c706???????? 897e30 ff15???????? 894634 }
+ $sequence_6 = { 8d4530 d1f9 50 8d044e 50 e8???????? }
+ $sequence_7 = { 668945b8 8d45a0 663108 40 40 663918 }
+ $sequence_8 = { 40 6685d2 75f6 2bc1 8d8e18060000 }
+ $sequence_9 = { 6a5b 6689451e 58 6a5c 66894520 58 6a4d }
condition:
- 7 of them and filesize <11198464
+ 7 of them and filesize <134144
}
-rule MALPEDIA_Win_Turla_Silentmoon_Auto : FILE
+rule MALPEDIA_Win_Lemonduck_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "74286b0f-5712-5890-afe4-259cc8765b9b"
+ id = "731c6313-f288-5766-8bd2-365369510b0a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.turla_silentmoon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.turla_silentmoon_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lemonduck"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lemonduck_auto.yar#L1-L114"
license_url = "N/A"
- logic_hash = "f84d11e90ac1422010cde8ffffe4ee94ce33e7fe9731643e241a69ac7f1c820c"
+ logic_hash = "45ef0f5ff171ed9ba03997994f483fd024a13ee436b3a8cb1b81df72104021e2"
score = 75
quality = 75
tags = "FILE"
@@ -174425,32 +181462,30 @@ rule MALPEDIA_Win_Turla_Silentmoon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 88442453 a1???????? 89442430 a0???????? 53 56 88442444 }
- $sequence_1 = { 8b4508 85c0 0f84f9010000 8938 5e 5b 8be5 }
- $sequence_2 = { 51 6800001000 53 56 ff15???????? 83f801 }
- $sequence_3 = { b950000000 e8???????? 83c404 6a08 b990000000 e8???????? }
- $sequence_4 = { 8b94bd28feffff 8d441001 8b55f0 8955d4 8b94bd28feffff 8955d8 8b55f0 }
- $sequence_5 = { 3bd1 7c9a 0fb608 3bd1 7e66 83be5c02000008 7c2f }
- $sequence_6 = { 48 83f803 0f878a000000 ff248588344000 8bc3 e8???????? }
- $sequence_7 = { 85ff 0f8f82fcffff 5f 5b }
- $sequence_8 = { 7e0a 8b4df0 8b7dd8 33c0 f3ab 8145d808040000 }
- $sequence_9 = { 741f 8b4508 85c0 7406 c700faffffff c787c4130000faffffff 5e }
+ $sequence_0 = { 41c1e018 42330c22 450bc8 46334c2204 4433d9 410fb64625 4533d1 }
+ $sequence_1 = { 488b7c2430 33c0 488983a0000000 488983a8000000 488983b0000000 488983b8000000 488983c0000000 }
+ $sequence_2 = { 418bc0 80f909 410f47c2 02c1 41884102 410fb64d01 80e10f }
+ $sequence_3 = { 488b89d8000000 48896c2438 4889742440 4883f9ff 7414 ff15???????? 8b4758 }
+ $sequence_4 = { 488d15d2280a00 488bcb ff15???????? 488905???????? 4885c0 0f8474010000 488d159a280a00 }
+ $sequence_5 = { 488d05c6ba0000 488905???????? 488d0558c70000 488905???????? 488d05bad20000 488905???????? 488d054ce30000 }
+ $sequence_6 = { 41c1e908 410fb6c7 41c1ef08 418bb48a50951600 400fb6cf 458ba48250951600 410fb6c6 }
+ $sequence_7 = { 482bc1 4883c0f8 4883f81f 0f8798000000 ba4f000100 e8???????? 90 }
condition:
- 7 of them and filesize <204800
+ 7 of them and filesize <10011648
}
-rule MALPEDIA_Win_Nefilim_Auto : FILE
+rule MALPEDIA_Win_Rokrat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7c9bb815-6478-5f57-9a80-3013a8b5a537"
+ id = "529b23ea-5ccb-5314-a032-246562122609"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nefilim"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nefilim_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rokrat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rokrat_auto.yar#L1-L152"
license_url = "N/A"
- logic_hash = "0637c290ac474507dfbf7c46615faaf644551a1824ee3d111eec4b7aaf27ae12"
+ logic_hash = "99c55c71740e0234c84ec3f4624ede5be8b8eb4baac41c4a1538d8db05d1af41"
score = 75
quality = 75
tags = "FILE"
@@ -174464,32 +181499,38 @@ rule MALPEDIA_Win_Nefilim_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { be00010000 56 e8???????? 56 8944244c }
- $sequence_1 = { 8945e4 3d00010000 7d10 8a8c181d010000 8888c0e64000 40 }
- $sequence_2 = { c1f802 6bc003 50 6a00 ff15???????? 50 }
- $sequence_3 = { 85c0 7506 ff15???????? 8d45d4 50 57 ffd3 }
- $sequence_4 = { 397c2428 7304 8d442414 68???????? 50 ffd6 85c0 }
- $sequence_5 = { 50 ffd6 85c0 0f84cf020000 f68424a000000010 8d8424cc000000 }
- $sequence_6 = { 7421 68???????? 8d442444 e8???????? }
- $sequence_7 = { 8b3d???????? 8b1d???????? 33c9 8945e4 894de8 8b45e4 d3e8 }
- $sequence_8 = { 8944244c e8???????? ff74244c 8b542440 89442454 e8???????? }
- $sequence_9 = { c745eceb7f4000 894df8 8945fc 64a100000000 8945e8 }
+ $sequence_0 = { 50 e8???????? 6a04 33c0 }
+ $sequence_1 = { 50 8bcf e8???????? 8d4538 3bd8 }
+ $sequence_2 = { 50 0fb74208 c1e910 51 50 }
+ $sequence_3 = { 50 8bcb e8???????? 8d4550 }
+ $sequence_4 = { 50 e8???????? 8d8edc000000 8d4520 }
+ $sequence_5 = { 56 8d4dc0 c745d000000000 668945c0 e8???????? c645fc03 8b45bc }
+ $sequence_6 = { 50 ff15???????? e8???????? 40 }
+ $sequence_7 = { 51 50 0fb74212 50 }
+ $sequence_8 = { 770a 68???????? e8???????? 837e1408 }
+ $sequence_9 = { ff15???????? 50 e8???????? 59 6a64 }
+ $sequence_10 = { 897dfc e8???????? 68???????? 8d4dd8 }
+ $sequence_11 = { c145f41e 8b5dfc 8db4339979825a 8975fc }
+ $sequence_12 = { c145f01e 8db4339979825a 8975f4 8b772c }
+ $sequence_13 = { c145f41e 8d9c3bd6c162ca 8b792c 337924 }
+ $sequence_14 = { c145f41e 8d8c0bdcbc1b8f 894dfc 8bca }
+ $sequence_15 = { c145f41e 8d9c1fd6c162ca 8b793c 337930 }
condition:
- 7 of them and filesize <142336
+ 7 of them and filesize <2932736
}
-rule MALPEDIA_Win_Ketrum_Auto : FILE
+rule MALPEDIA_Win_Dispenserxfs_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "675a5c68-35f7-5e7a-83cc-0627e32f2bf0"
+ id = "49bf9fde-27a7-5a52-b363-6d4c360f5198"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ketrum"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ketrum_auto.yar#L1-L174"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dispenserxfs"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dispenserxfs_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "b179771de79024de54f910e3eea2ec187acafed93fd395a9caebde5421ab28f1"
+ logic_hash = "0ae97d732c7fee9f1fd4b6377f2a916fed962748494ab51169af7ce6e36e4229"
score = 75
quality = 75
tags = "FILE"
@@ -174503,40 +181544,34 @@ rule MALPEDIA_Win_Ketrum_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83e13f 5f 3bc8 7203 }
- $sequence_1 = { 8d85fcebffff 50 8d85fcd3ffff 68???????? 50 ffd7 }
- $sequence_2 = { ff15???????? ffb5f0cbffff ff15???????? ffb5e8cbffff ffb5f4cbffff }
- $sequence_3 = { ab ab ab ab 68???????? 6a15 bf???????? }
- $sequence_4 = { e8???????? 59 85db 7e15 57 8b7d08 2bfe }
- $sequence_5 = { 33c0 0fb7f0 8bc6 c1e610 ba???????? }
- $sequence_6 = { 7434 b9???????? 8bc1 8d7001 8a10 40 }
- $sequence_7 = { 85c0 7404 33c0 eb5e 6880000000 56 }
- $sequence_8 = { 397010 7699 837b1408 7204 8b13 eb02 }
- $sequence_9 = { 8a4c181c 8888b0f74100 40 ebe9 33c0 8945e4 }
- $sequence_10 = { 6a04 8d8520efffff 50 6a1f 57 }
- $sequence_11 = { 8b8da4fdffff 2bc1 2bc6 50 03ce 51 }
- $sequence_12 = { 3bf9 732c 8b16 3bd7 7726 8bc7 2bc2 }
- $sequence_13 = { 8365fc00 83c074 50 8b4508 e8???????? }
- $sequence_14 = { 89a570feffff 6a0f 5f 897e14 895e10 }
- $sequence_15 = { 33ff 8d759c e8???????? 33c0 40 e8???????? }
+ $sequence_0 = { 8975c0 8975c4 8b35???????? 57 c745b430000000 c745b803000000 }
+ $sequence_1 = { 68???????? e8???????? c7042410270000 ff15???????? 6a00 }
+ $sequence_2 = { 6a02 ff15???????? 8bf0 83feff 74ef 8d85d4fdffff c785d4fdffff2c020000 }
+ $sequence_3 = { 7c08 8d50ec e8???????? 57 ff15???????? }
+ $sequence_4 = { 7451 33c9 33c0 8bd9 663b422e 731f 8b4230 }
+ $sequence_5 = { 50 ffd6 53 6a03 58 50 8d8555ffffff }
+ $sequence_6 = { 898de0feffff 89b5e4feffff 89b5e8feffff 89b5ecfeffff 89b5f0feffff 66899df6feffff }
+ $sequence_7 = { 8945f0 0f823cffffff 8b4df4 8b45e4 }
+ $sequence_8 = { 8bcf e8???????? 8d8548feffff 8bd3 50 8bcf }
+ $sequence_9 = { 8d55c4 83c414 8bf2 8a02 42 }
condition:
- 7 of them and filesize <4599808
+ 7 of them and filesize <114688
}
-rule MALPEDIA_Win_Polyglot_Ransom_Auto : FILE
+rule MALPEDIA_Win_Korlia_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d8c62ea3-2069-58e5-94bb-e4265ed7677c"
+ id = "d35af9df-a058-5a30-a77f-8fa81b1625c9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.polyglot_ransom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.polyglot_ransom_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.korlia"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.korlia_auto.yar#L1-L481"
license_url = "N/A"
- logic_hash = "ecee7d25f676a4e4884cb2efcc0294d55515d4c6450d9ce1a59e043bd0d80704"
+ logic_hash = "17b5ea46685442b751a30de5596fa43f96dfb43c44e790391afede4018d6463a"
score = 75
- quality = 73
+ quality = 50
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -174548,32 +181583,75 @@ rule MALPEDIA_Win_Polyglot_Ransom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff74244c e8???????? 8944241c 894c2448 6a07 895c2450 }
- $sequence_1 = { 6a30 e8???????? 59 59 8d4d80 51 6801010000 }
- $sequence_2 = { ff5004 83c328 ff4d10 75ad ff75f0 ff15???????? }
- $sequence_3 = { be???????? 66f7c30040 6a04 5a 747a 6681fb0b40 756c }
- $sequence_4 = { 50 68???????? e8???????? 8b85f0fdffff 59 59 8b08 }
- $sequence_5 = { 627265 206f20 656c 696d696e617220 61 7263 6869766f73 }
- $sequence_6 = { eb4f 8bf3 8bf9 a5 a5 a5 a5 }
- $sequence_7 = { 59 59 751c 8b45fc 8b4020 85c0 }
- $sequence_8 = { 5e c20400 68???????? 6a20 33c0 }
- $sequence_9 = { 40 5e eb02 32c0 8b4d74 33cd }
+ $sequence_0 = { 52 68???????? 51 ffd6 }
+ $sequence_1 = { 6a32 50 ff15???????? 85c0 7521 }
+ $sequence_2 = { 33c0 f2ae f7d1 49 83f90f 7604 }
+ $sequence_3 = { f7ef c1fa14 8bc2 c1e81f 03d0 52 }
+ $sequence_4 = { 8965e8 c645e401 c745fc00000000 52 }
+ $sequence_5 = { 59 5a c745fcffffffff 8a45e4 8b4df0 64890d00000000 5f }
+ $sequence_6 = { 81fb68584d56 0f9445e4 5b 59 5a c745fcffffffff }
+ $sequence_7 = { 7410 6a28 68???????? 6aff 53 6a00 }
+ $sequence_8 = { 6a00 ffd6 68???????? c705????????1c010000 ff15???????? }
+ $sequence_9 = { 6a01 53 53 53 51 ff15???????? 85c0 }
+ $sequence_10 = { 8b442404 56 6a00 6a00 6a01 6a00 }
+ $sequence_11 = { 6a01 6a00 6a00 6800000040 50 ff15???????? 8bf0 }
+ $sequence_12 = { e8???????? 8a4c2404 6a01 884814 8b4c240c 898840200000 }
+ $sequence_13 = { 8b4c240c 898840200000 58 c20800 e9???????? 6800060000 }
+ $sequence_14 = { 8bf0 83feff 7423 8b542410 8b44240c 8d4c2408 }
+ $sequence_15 = { 59 59 c3 8b65e8 ff7588 ff15???????? 833d????????ff }
+ $sequence_16 = { 50 56 ff15???????? 56 ff15???????? b001 5e }
+ $sequence_17 = { ff15???????? 833d????????ff 750c ff742404 ff15???????? }
+ $sequence_18 = { ff742410 ff742410 ff742410 e8???????? c21000 e8???????? 8a4c2404 }
+ $sequence_19 = { 6a00 680030c800 6a00 6a00 }
+ $sequence_20 = { b8447c0000 e8???????? 53 56 }
+ $sequence_21 = { 8d442444 894d00 8b542438 83c504 50 895500 }
+ $sequence_22 = { 6880000000 6800000400 8bce e8???????? }
+ $sequence_23 = { 8bf9 81e7ff000000 03f2 03f7 }
+ $sequence_24 = { ffd6 8d44240c 6804010000 50 }
+ $sequence_25 = { 83c504 50 895500 83c504 e8???????? d1e0 }
+ $sequence_26 = { 6a00 6a00 50 8bce e8???????? 6a00 }
+ $sequence_27 = { 51 ff15???????? a1???????? b981000000 }
+ $sequence_28 = { 750c ff15???????? 53 e9???????? }
+ $sequence_29 = { 0f8599000000 53 56 57 b940000000 }
+ $sequence_30 = { ffd6 eb06 8b35???????? a1???????? 3bc3 7403 50 }
+ $sequence_31 = { 68ff0f1f00 ff15???????? 85c0 740a }
+ $sequence_32 = { 8d542414 6a00 52 68???????? 6a00 ff15???????? }
+ $sequence_33 = { 85c0 740a 56 50 ff15???????? 8bf0 }
+ $sequence_34 = { 33c0 8dbc245e020000 66899c245c020000 f3ab }
+ $sequence_35 = { 7403 50 ffd6 b912010000 33c0 }
+ $sequence_36 = { f3ab aa b9f9000000 33c0 }
+ $sequence_37 = { 56 3bc3 57 740b 8b35???????? 50 }
+ $sequence_38 = { 6801000080 ff15???????? 85c0 0f8599000000 53 }
+ $sequence_39 = { 68???????? 51 ff15???????? 8b54240c 8bf0 }
+ $sequence_40 = { 40 81c408010000 c3 83c8ff }
+ $sequence_41 = { 5e 24fe 5b 40 }
+ $sequence_42 = { 83c9ff 33c0 68003e0000 f2ae f7d1 2bf9 }
+ $sequence_43 = { 50 8b4308 6a02 57 ffd0 85c0 750c }
+ $sequence_44 = { a0???????? 884102 ba???????? 8bf2 8a02 42 }
+ $sequence_45 = { 51 8b0d???????? 8d85c4f0ffff 6a05 6a04 50 }
+ $sequence_46 = { 8bc7 83e03f 6bc830 8b049578c14100 f644082801 7421 57 }
+ $sequence_47 = { 85f6 7439 8d4dd0 68???????? 51 c745d0306e4000 }
+ $sequence_48 = { ff15???????? 85c0 7421 6a3f 8d85fcfeffff }
+ $sequence_49 = { 6a00 ff15???????? 8bf8 85ff 7503 5f 5e }
+ $sequence_50 = { 5d c20c00 ffb5f8efffff 8b35???????? }
+ $sequence_51 = { 51 e8???????? 8d942404030000 68???????? 52 }
+ $sequence_52 = { 50 51 e8???????? 8b742430 83c41c }
condition:
- 7 of them and filesize <1392640
+ 7 of them and filesize <263168
}
-rule MALPEDIA_Win_Mpkbot_Auto : FILE
+rule MALPEDIA_Win_Pittytiger_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "72738a74-041e-590e-bcbe-fef59ce6d7c8"
+ id = "9764afd8-8e4e-54dd-9ad2-bd1903f5455d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mpkbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mpkbot_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pittytiger_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pittytiger_rat_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "84a9c41e42e448fecfbe039fb747c3f04c473f008e3e19f5ee4ba318bc990491"
+ logic_hash = "a2f2e591a5e3a3c37398ec723056984b2fa4039658f61ff9463c257a6584be3f"
score = 75
quality = 75
tags = "FILE"
@@ -174587,34 +181665,34 @@ rule MALPEDIA_Win_Mpkbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? 50 ff15???????? a3???????? 8d45fc 50 683f000f00 }
- $sequence_1 = { a3???????? 8d45fc 50 683f000f00 6a00 }
- $sequence_2 = { 38450c 740a eb05 38450c 7503 }
- $sequence_3 = { 8d55f8 52 56 6a20 68???????? }
- $sequence_4 = { 55 8bec 56 57 6a00 ff15???????? 8bf0 }
- $sequence_5 = { 0fb630 8975d4 db45d4 d84dc4 }
- $sequence_6 = { 8bf0 0fb7450c 50 0fb74508 50 56 }
- $sequence_7 = { 7507 38450c 740a eb05 }
- $sequence_8 = { ff15???????? ff7508 a3???????? ffd0 5d c3 55 }
- $sequence_9 = { ff15???????? ffd6 50 ffd7 }
+ $sequence_0 = { 8175ec90b48f19 8175f0596f62d6 885df4 50 8d85d4ffffff }
+ $sequence_1 = { a3???????? 0f8451feffff 8d45b8 c745b84f70656e 50 57 }
+ $sequence_2 = { ab ab aa 8d7dc8 33c0 a5 }
+ $sequence_3 = { 397df8 7678 3bf7 7474 }
+ $sequence_4 = { 8bf8 83ffff 7512 ff15???????? }
+ $sequence_5 = { 3bc3 a3???????? 0f8476ffffff 8d459c c745ac65416500 50 }
+ $sequence_6 = { 7512 ff15???????? 50 53 }
+ $sequence_7 = { 50 895df8 ff7510 ff750c ff75fc }
+ $sequence_8 = { ff15???????? 85c0 741c 6a40 ff75f0 ffd7 6af1 }
+ $sequence_9 = { 8d85dcfdffff 50 8d85e0feffff 50 7407 68???????? eb05 }
condition:
- 7 of them and filesize <139264
+ 7 of them and filesize <2162688
}
-rule MALPEDIA_Win_Fireball_Auto : FILE
+rule MALPEDIA_Win_Slingshot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "41b2d4de-af91-5e95-ba91-5bc661ef7417"
+ id = "bf558dcd-c863-525d-b34a-1a56d33f94ec"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fireball"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fireball_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.slingshot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.slingshot_auto.yar#L1-L218"
license_url = "N/A"
- logic_hash = "0f627ea55086f489b8cd11c65d68f2e0680aa8b1619660718f20b28106c4357c"
+ logic_hash = "1e413348df71e72118297c6913e2a6da9548aa658d39b7dcd425460f21f929c0"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -174626,34 +181704,47 @@ rule MALPEDIA_Win_Fireball_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 8bce e8???????? b101 e8???????? }
- $sequence_1 = { 30a830ac30b0 30b830cc30e8 30f0 30f4 3010 3118 311c31 }
- $sequence_2 = { 8b0f 8bc1 c1f805 83e11f 8b0485000a2500 c1e106 80640804fe }
- $sequence_3 = { 68???????? 8d8c24a4000000 c78424b800000007000000 c78424b400000000000000 }
- $sequence_4 = { c78424a400000000000000 6689842494000000 837c247808 720c ff742464 e8???????? }
- $sequence_5 = { 53 ff15???????? 85c0 0f85c2feffff }
- $sequence_6 = { c78518f5ffff07000000 c78514f5ffff00000000 66898504f5ffff 83bdf4f5ffff08 720e }
- $sequence_7 = { c68558fbffff00 7504 33c9 eb12 8d8d64f9ffff }
- $sequence_8 = { 8d442417 50 8d542434 8d8c2498000000 c744244c07000000 c744244800000000 e8???????? }
- $sequence_9 = { 8bf1 c785e8fbffff00000000 e8???????? 83c40c 8d85ecfbffff 6808020000 }
+ $sequence_0 = { 50 33db 53 ff15???????? 8bf0 3bf3 }
+ $sequence_1 = { 3bcb 7512 ff7708 ff37 }
+ $sequence_2 = { 48 8bf0 66895804 66897806 85ed }
+ $sequence_3 = { e8???????? e8???????? 8945d8 8955dc 3bc3 7d09 52 }
+ $sequence_4 = { e8???????? ff7004 8d742420 ff30 e8???????? 395c241c 7523 }
+ $sequence_5 = { 8be8 49 3bc6 750f baec040000 b90e000780 }
+ $sequence_6 = { e8???????? 59 8d75a4 e8???????? 8d7594 }
+ $sequence_7 = { 3bcb 7442 395dfc 7414 }
+ $sequence_8 = { 3bcb 7504 6a08 eb7a }
+ $sequence_9 = { 3919 740a 48 83c102 48 83e801 75f0 }
+ $sequence_10 = { 833d????????00 7546 b918000000 e8???????? 48 }
+ $sequence_11 = { 0f848a050000 45 33e4 0fb74c2448 83e961 }
+ $sequence_12 = { 3bcb 7552 dd45f0 dd4720 }
+ $sequence_13 = { 8bce 49 3bfe 741a }
+ $sequence_14 = { 59 c20400 8b4608 83f8ff }
+ $sequence_15 = { 3bcb 7461 8b01 83f807 }
+ $sequence_16 = { 3bcb 753c ff7708 eb28 }
+ $sequence_17 = { eb29 48 8d4c2448 e8???????? }
+ $sequence_18 = { e9???????? 8d85d0fdffff 50 ff15???????? }
+ $sequence_19 = { 894c9a08 8b5df8 03cb 8b5d0c 23c8 }
+ $sequence_20 = { ff7508 ffd7 85c0 7516 ff15???????? 6843458a04 }
+ $sequence_21 = { 0d00000780 8906 e8???????? 48 8bd6 48 }
+ $sequence_22 = { 3bcb 743b 6afe 58 8901 }
condition:
- 7 of them and filesize <335872
+ 7 of them and filesize <663552
}
-rule MALPEDIA_Win_Hive_Auto : FILE
+rule MALPEDIA_Win_Cryptoshuffler_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d6a0e69c-8ba3-5e7b-a7ea-75f1727a32de"
+ id = "04846f99-89cf-54cb-88bc-877d2656a7fa"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hive"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hive_auto.yar#L1-L183"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptoshuffler"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptoshuffler_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "6114f2e9f03828db87c71adf2ad1d3eed20f57d01fa9bb999ecd2843927df4e0"
+ logic_hash = "1d3d096bc8fe94bfe59d829c11ff29d324542295a6195d59ed4b925f302177ea"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -174665,43 +181756,32 @@ rule MALPEDIA_Win_Hive_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 31c0 b91d000000 31d2 31db }
- $sequence_1 = { b807000000 b9d4000000 31d2 31db }
- $sequence_2 = { 89c2 e8???????? b801000000 e8???????? }
- $sequence_3 = { 31c9 31d2 bb54000000 31f6 }
- $sequence_4 = { 89d1 e8???????? b802000000 e8???????? }
- $sequence_5 = { 31c9 31d2 bb08000000 becb000000 31ff }
- $sequence_6 = { 89d0 b90d000000 e8???????? b90d000000 }
- $sequence_7 = { 31db 31ff eb31 31c0 }
- $sequence_8 = { 31ff e8???????? 833d????????00 7511 }
- $sequence_9 = { 89d1 e8???????? b901000000 e8???????? }
- $sequence_10 = { 81c4b0000000 c3 e8???????? 90 }
- $sequence_11 = { 31c9 31d2 bb09000000 bee0000000 }
- $sequence_12 = { 31c0 eb17 0fb6940496000000 0fb674041c 31d6 }
- $sequence_13 = { 01c1 83c101 83f90c 0f820fffffff }
- $sequence_14 = { 01c1 c1e106 400fb6d6 01ca }
- $sequence_15 = { 01c8 c1e006 400fb6cf 01c1 }
- $sequence_16 = { 01c1 c1e106 0fb6c2 01c8 }
- $sequence_17 = { 01c2 b8ffffff03 21c5 21c3 }
- $sequence_18 = { 01c0 4000f8 0fb6c0 48898424b0000000 }
- $sequence_19 = { 01ca c1e206 0fb6c3 01d0 }
- $sequence_20 = { 01c8 89c1 c1e91f ffc9 }
+ $sequence_0 = { 03fb e8???????? 8bf0 3b35???????? 7430 }
+ $sequence_1 = { 83c408 85c0 0f8496040000 6aff 6a00 8d442430 50 }
+ $sequence_2 = { 6bc830 8b049578f60210 f644082801 7421 57 }
+ $sequence_3 = { 0f57c0 c78424f400000000000000 68???????? 8d8c24e8000000 0f298424e8000000 e8???????? }
+ $sequence_4 = { c745ec10f80010 894df8 8945fc 64a100000000 8945e8 }
+ $sequence_5 = { e9???????? c745dc03000000 eb7c c745e0e04d0210 ebbb }
+ $sequence_6 = { 50 ff15???????? 8d842410030000 50 8d84248c010000 50 }
+ $sequence_7 = { e8???????? 8904bd78f60210 85c0 7514 6a0c }
+ $sequence_8 = { 0f851b010000 8b01 c6400c01 8b31 c6410c00 }
+ $sequence_9 = { 0f1f4000 8b06 8b4e08 3bc1 }
condition:
- 7 of them and filesize <7946240
+ 7 of them and filesize <425984
}
-rule MALPEDIA_Win_Daxin_Auto : FILE
+rule MALPEDIA_Win_Cryptoshield_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f296881b-770d-5563-abfb-71fa7b0b574a"
+ id = "96d07897-e994-52cb-aaa7-059e98a50194"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.daxin"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.daxin_auto.yar#L1-L156"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptoshield"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptoshield_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "474b282908002ac6ff5a401d8cd2ee0d1c71eaec687bd0f7b672c512154787e2"
+ logic_hash = "306896178ef65ef3c9170a20c235107c29dca1bfe925c06dc43c71750e345a6d"
score = 75
quality = 75
tags = "FILE"
@@ -174715,37 +181795,32 @@ rule MALPEDIA_Win_Daxin_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 2bc2 d1f8 99 f7f9 }
- $sequence_1 = { ff15???????? 488b0d???????? 483bcb 7458 895c2448 48895c2440 895c2438 }
- $sequence_2 = { 751a baea050000 33c9 41b84d4b4353 }
- $sequence_3 = { ff15???????? 488983f8000000 4883a3d800000000 33d2 488d8bb0000000 448d4220 e8???????? }
- $sequence_4 = { 83e21f 03c2 8bc8 83e01f c1f905 2bc2 488b5328 }
- $sequence_5 = { ff15???????? 488b0d???????? 48832700 33d2 4533c0 }
- $sequence_6 = { 83e27f 03c2 83e07f 2bc2 4863c8 8a8419c5010000 }
- $sequence_7 = { 83e3e0 41b84d4b4353 83c320 83e203 03c2 895910 c1f802 }
- $sequence_8 = { 88480d 8b5368 42 895368 }
- $sequence_9 = { 884c241b c744241c08000000 c783b401000001000000 ff93f0020000 }
- $sequence_10 = { 884c2450 83c9ff 33c0 f2ae }
- $sequence_11 = { 885004 33c0 f2ae f7d1 }
- $sequence_12 = { 88480d 8b4500 50 ff5018 }
- $sequence_13 = { 884805 8b0b b807000000 c6410600 8b4b04 3bc8 }
- $sequence_14 = { 88482b 81c6a1000000 8990b0000000 3bf2 }
+ $sequence_0 = { 8b18 8b45fc 85c0 740e }
+ $sequence_1 = { 50 ffd7 83c40c 8d442418 50 8d84242c020000 68???????? }
+ $sequence_2 = { 50 8d442428 50 ff15???????? 8d842430040000 }
+ $sequence_3 = { 85c0 7461 ff7508 6a40 ff15???????? }
+ $sequence_4 = { 750b 83c202 66833a00 75ce eb08 }
+ $sequence_5 = { 6a00 6a23 50 6a00 ff15???????? 8d85f4fdffff 50 }
+ $sequence_6 = { b90a000000 83f801 0f44f1 8b4dfc }
+ $sequence_7 = { be09000000 8bc6 5e 8b4dfc 33cd e8???????? 8be5 }
+ $sequence_8 = { 56 6814010000 33f6 8d85e0feffff 56 }
+ $sequence_9 = { 56 ff15???????? 85ff 0f45df 5f 5e 8bc3 }
condition:
- 7 of them and filesize <3475456
+ 7 of them and filesize <131072
}
-rule MALPEDIA_Win_Icedid_Downloader_Auto : FILE
+rule MALPEDIA_Win_Outlook_Backdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1dc8b5e6-58e8-56f8-b32a-539ebf38d462"
+ id = "10b67e6b-fced-54a6-8f30-b2a0d20f49ea"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.icedid_downloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.icedid_downloader_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.outlook_backdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.outlook_backdoor_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "f3e7c7707c4dd480b8c042e3891161f91628584450f48860513befa5fa6f9a3b"
+ logic_hash = "373fe304abbc2faa8be0b7ba3a307d5b5d4cb0051b5dde767cca54332adde2f8"
score = 75
quality = 75
tags = "FILE"
@@ -174759,32 +181834,32 @@ rule MALPEDIA_Win_Icedid_Downloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb1c 83f803 7519 8b06 }
- $sequence_1 = { e8???????? 8365f400 8d45b0 8945f8 64a118000000 59 59 }
- $sequence_2 = { 8d4568 50 8d4558 50 8d45c8 6a04 }
- $sequence_3 = { 8d75d4 33c0 c745dc00330000 6a16 }
- $sequence_4 = { ff7508 895dfc 895df4 895df8 895dec 895de4 }
- $sequence_5 = { ffd7 ff15???????? 83f87a 0f85e9000000 8b442410 85c0 0f84dd000000 }
- $sequence_6 = { 894528 8d4518 50 ff15???????? }
- $sequence_7 = { 89442408 8944240c 8bf0 8944241c 8d442408 }
- $sequence_8 = { 50 53 53 53 6a04 ff75fc e8???????? }
- $sequence_9 = { 6689442434 8d54242c 8b442414 52 57 }
+ $sequence_0 = { ff753c 53 68e9fd0000 ffd6 8d4d00 894568 e8???????? }
+ $sequence_1 = { ff10 8b4c2408 ff74240c 8d04c8 8b4804 85c9 740b }
+ $sequence_2 = { c9 c20800 56 8bf7 e8???????? 8d771c e8???????? }
+ $sequence_3 = { c745e01f000130 895d0c ff15???????? 8b450c 8945f0 895dfc 33c9 }
+ $sequence_4 = { 6898000000 e8???????? 59 8945ec c645fc01 }
+ $sequence_5 = { f6455404 740e 836554fb 57 56 8d4dbc e8???????? }
+ $sequence_6 = { c3 57 6a2c e8???????? 8bf8 59 85ff }
+ $sequence_7 = { 5f 5e 8d4302 5b c3 53 8bd9 }
+ $sequence_8 = { 50 e8???????? 834d1004 f6451002 740f 836510fd }
+ $sequence_9 = { e8???????? 83ec38 56 57 8bf1 8b4604 33ff }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <2912256
}
-rule MALPEDIA_Win_Entryshell_Auto : FILE
+rule MALPEDIA_Win_Darkdew_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "602f60d0-cc33-528b-8fdb-8d928745f559"
+ id = "0ed49e32-b5ea-5f63-b18e-3ccfdc3576f0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.entryshell"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.entryshell_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkdew"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkdew_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "870b124d6520583c6a18845739a5248302a0431048dbb7822501065378b2f353"
+ logic_hash = "0cd505ddc1a03cf19308335c9ef43a0054cd013c3658d925b20aa0cf71f6aa36"
score = 75
quality = 75
tags = "FILE"
@@ -174798,34 +181873,34 @@ rule MALPEDIA_Win_Entryshell_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85db 7517 53 8d95e4dfffff 8b8d8cddffff }
- $sequence_1 = { 771d 8d8290c72501 8d5001 660f1f440000 }
- $sequence_2 = { 83c40c 8d8424a8080000 50 6804010000 ff15???????? 8d442450 50 }
- $sequence_3 = { 8b46f8 0fb684054fffffff 8842fd 83ef01 75a1 0f1003 53 }
- $sequence_4 = { 83c404 84c0 0f8495010000 8bbdf4efffff 85ff 0f84eefcffff 6a20 }
- $sequence_5 = { e8???????? 59 83cfff 897de4 33c9 894dfc 8b049d78512501 }
- $sequence_6 = { 8945f8 53 8b5d08 0f57c0 56 57 895de8 }
- $sequence_7 = { 83c40c 8d4ffe 668b4102 8d4902 6685c0 75f4 e9???????? }
- $sequence_8 = { 8a0445399f2401 eb02 32c0 0fb64d0c 0fb6c0 6bc009 03c1 }
- $sequence_9 = { 02d2 029013800000 02d2 029014800000 02d2 029015800000 02d2 }
+ $sequence_0 = { 8b55d0 c745b400000000 c745b80f000000 c645a400 83fa08 722e 8b4dbc }
+ $sequence_1 = { 03c0 660f283485c0840110 baef7f0000 2bd1 }
+ $sequence_2 = { 7202 8b12 8bca c745ac00000000 33c0 c745b007000000 }
+ $sequence_3 = { 8d4d9c 8d45d4 c78586feffff00000000 0f434d9c ba14060000 }
+ $sequence_4 = { c645fc11 8b55cc 83fa08 7232 8b4db8 8d145502000000 8bc1 }
+ $sequence_5 = { 6a00 ff15???????? cc 55 8bec 64a100000000 6aff }
+ $sequence_6 = { b991000000 8dbc2470020000 8bf3 f3a5 8bf0 8dbc24b4040000 8d842480030000 }
+ $sequence_7 = { e8???????? 8bf8 c645fc19 8d55d4 837de810 }
+ $sequence_8 = { 85c0 0f8488000000 8b4df8 8d5823 8b55fc }
+ $sequence_9 = { 8db3d0feffff 8bce 83e210 8d7901 0f1f4000 }
condition:
- 7 of them and filesize <663552
+ 7 of them and filesize <279552
}
-rule MALPEDIA_Win_Konni_Auto : FILE
+rule MALPEDIA_Win_Stabuniq_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7138d9e1-4213-5d32-a401-6f7ceedaf286"
+ id = "fc58cf81-e26c-5be2-91a6-3fbb3fc72d52"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.konni"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.konni_auto.yar#L1-L461"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stabuniq"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stabuniq_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "81aa3927272d55dae2dfea8fc0fbd2614b2bb50237cc36185301dfe759c8d64e"
+ logic_hash = "97aa7344abd98ffc46d944f3c78f102b277bbba8d700aca31756ce2df1f26cfc"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -174837,72 +181912,32 @@ rule MALPEDIA_Win_Konni_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7908 4e 81ce00ffffff 46 8a9c35f8feffff 8819 889435f8feffff }
- $sequence_1 = { 8945fc 53 56 57 b910000000 be???????? 8d7db0 }
- $sequence_2 = { 7527 0fb655eb 0fb645ea 52 }
- $sequence_3 = { 889435f8feffff 0fb609 0fb6d2 03ca 81e1ff000080 7908 }
- $sequence_4 = { 0fbef1 d0f9 83e601 884c15f4 8970e8 42 }
- $sequence_5 = { 49 81c900ffffff 41 8a940df8feffff 8d8c0df8feffff 0fb6da 03f3 }
- $sequence_6 = { 83e601 897004 d0f9 0fbef1 83e601 8930 }
- $sequence_7 = { 68b6030000 6a0d 50 ff15???????? }
- $sequence_8 = { 6a01 ff15???????? 50 a3???????? }
- $sequence_9 = { 33c9 83f802 7508 890d???????? }
- $sequence_10 = { eb1e 83f804 740f c705????????02000000 }
- $sequence_11 = { 740f c705????????02000000 83f801 750a c705????????01000000 890d???????? }
- $sequence_12 = { 7508 890d???????? eb1e 83f804 }
- $sequence_13 = { 8916 56 e8???????? 8a8c30dec44600 }
- $sequence_14 = { e8???????? 83c40c 6804010000 8d8df4fdffff 51 ff15???????? }
- $sequence_15 = { 83e203 83f908 7229 f3a5 ff2495f0444000 8bc7 }
- $sequence_16 = { 8d85f8feffff 50 ffd6 68???????? 8d8df0faffff }
- $sequence_17 = { 4c89742420 ff15???????? 488bd8 4885c0 744f }
- $sequence_18 = { bbedffffff 03dd 81eb00200200 83bd9404000000 899d94040000 0f85d7030000 }
- $sequence_19 = { e9???????? 8b35???????? 68???????? 8d85f8feffff }
- $sequence_20 = { ff95b50f0000 898598040000 8bf0 8d7d51 }
- $sequence_21 = { 6804010000 8d95f8feffff 52 50 ff15???????? }
- $sequence_22 = { 50 038594040000 59 0bc9 89851a040000 61 7508 }
- $sequence_23 = { 8b4e08 33db 56 e8???????? 8a9c30c2c44600 }
- $sequence_24 = { 8bf0 8d7d51 57 56 ff95b10f0000 ab }
- $sequence_25 = { 33d2 56 e8???????? 8a9435dec44600 5e 84c0 8bfa }
- $sequence_26 = { 56 33d2 898ddcfeffff 40 57 }
- $sequence_27 = { 6808020000 6a00 56 c745fc00010000 e8???????? 83c40c 8d45fc }
- $sequence_28 = { ebab c745e428614000 817de42c614000 7311 8b45e4 }
- $sequence_29 = { 6a00 6a00 8d8df8feffff 51 8d95f0fcffff }
- $sequence_30 = { 68???????? 8d8df0faffff 51 ffd6 8b35???????? }
- $sequence_31 = { 51 6689442414 e8???????? 6808020000 8d942420020000 6a00 }
- $sequence_32 = { e8???????? 8a8c30a6c44600 5e 8b442414 03ca 03c1 89442414 }
- $sequence_33 = { 33c0 56 51 668985e8fdffff e8???????? }
- $sequence_34 = { 488bda 488b15???????? 4889442458 89442450 488b05???????? 482bc2 }
- $sequence_35 = { 48ffc9 48ffc1 7440 488d542448 458d4e2e }
- $sequence_36 = { 8bd9 e8???????? 4885c0 7509 488d051f390100 }
- $sequence_37 = { 4883ec20 488bd9 e8???????? 4c8d1d4b9b0000 }
- $sequence_38 = { 488b01 8b08 ff15???????? 488d15f3170100 488bcb }
- $sequence_39 = { e8???????? 59 3bc7 59 a3???????? 7419 68???????? }
- $sequence_40 = { 743e 8305????????20 8d0c9de0a30010 8d9080040000 8901 3bc2 }
- $sequence_41 = { 4885c0 7438 33c0 4883c9ff 4c8d8600010000 488bfb }
- $sequence_42 = { 8d04c0 8b0c8de0a30010 8a448104 83e040 c3 55 8bec }
- $sequence_43 = { 83c410 837dfc08 752f 68???????? 53 e8???????? }
- $sequence_44 = { 448d5bf0 498d4e10 4963d3 4d8bcd 4d8bc4 }
- $sequence_45 = { 8b8fa8af0100 488b87a0af0100 400fb6d6 f6d2 881401 ff87a8af0100 8b97a8af0100 }
- $sequence_46 = { 59 8a4dff 8d3c85e0a30010 8bc3 80c901 83e01f 884d0b }
- $sequence_47 = { 488905???????? 8905???????? 488b05???????? 4533c0 48c7c102000080 488905???????? }
- $sequence_48 = { 8bc3 c1f905 83e01f 8b0c8de0a30010 8d04c0 }
- $sequence_49 = { 8b442448 448b6e4c 448b7e44 c1e808 4c8bf3 8b5e48 }
+ $sequence_0 = { 50 8b4d08 ff91a8000000 6a00 6a00 }
+ $sequence_1 = { 8b8df4feffff 51 6aff 8b5508 81c2a2050000 }
+ $sequence_2 = { 52 8b4510 ff503c 8b4d10 33d2 668b9106020000 }
+ $sequence_3 = { 6a00 8b4d08 8b91f8010000 52 8b4508 ff9018010000 837de4ff }
+ $sequence_4 = { 8985c8fbffff 8b4d14 51 6a08 8b550c }
+ $sequence_5 = { 8b4df8 8b11 035508 8955f4 eb0c 8b45f8 8b4810 }
+ $sequence_6 = { 51 e8???????? 8b5508 83c220 895508 c785bcfcffff00000000 8b4510 }
+ $sequence_7 = { 51 8b550c ff524c 8945fc 8b45fc 50 }
+ $sequence_8 = { 8d85c0fcffff 50 8b4d0c 51 e8???????? eb16 8b5510 }
+ $sequence_9 = { 81c155030000 51 e8???????? 6a00 8b5514 52 8b85e8feffff }
condition:
- 7 of them and filesize <330752
+ 7 of them and filesize <57344
}
-rule MALPEDIA_Win_Jasus_Auto : FILE
+rule MALPEDIA_Win_Electricfish_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f0f57156-3d71-51a0-8417-ea38ed1ea26d"
+ id = "b2332381-c1cc-58e9-8fab-7070fccf8e24"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jasus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jasus_auto.yar#L1-L128"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.electricfish"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.electricfish_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "8597018770d02606e940d401ffb7afc270f8035f09e3cd93e76c94000290c2f1"
+ logic_hash = "1f7cb8b65f3bb65395bc124290e1a31ce340990c85196e747881fa433bd41f37"
score = 75
quality = 75
tags = "FILE"
@@ -174916,32 +181951,32 @@ rule MALPEDIA_Win_Jasus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 51 6689956cffffff ffd3 83c40c 833d????????00 }
- $sequence_1 = { 8955f8 8955e8 8955ec c745f0ffffffff 84c0 7410 8d642400 }
- $sequence_2 = { 84c0 7543 8b45fc 85c0 745a 68???????? }
- $sequence_3 = { 39580c 0f828d000000 0fb71437 8b4e1a 33c0 89442414 89442418 }
- $sequence_4 = { 8945f0 894df8 b801000000 837dec00 745d 85c0 7559 }
- $sequence_5 = { 8b1481 40 89560c 8906 8b5e0c 895e14 8a03 }
- $sequence_6 = { 47 897e14 897e70 c686c800000043 c6864b01000043 c74668d0f24100 6a0d }
- $sequence_7 = { 894de8 8945e4 c745ec00c94100 c745f001010000 c745f41e010000 c745f80f000000 }
- $sequence_8 = { 8bc6 c1f805 8d1485809d4300 8b0a }
- $sequence_9 = { e8???????? 0fb71d???????? 8945fc 0fb705???????? 56 68???????? e8???????? }
+ $sequence_0 = { e8???????? 83c404 85c0 0f84e3fdffff 8b442410 6a00 50 }
+ $sequence_1 = { e8???????? 8bd8 83c404 85db 7523 683e010000 68???????? }
+ $sequence_2 = { c3 8b5104 57 6a77 68???????? 8910 8b39 }
+ $sequence_3 = { 8b442408 6855090000 68???????? 6a41 6896010000 6a14 c70050000000 }
+ $sequence_4 = { e8???????? 83c418 85c0 0f8fd7faffff 5f 5e 5d }
+ $sequence_5 = { 8945c4 8945c8 8945cc 8945d0 89a540ffffff 6aff 894110 }
+ $sequence_6 = { 689b010000 68???????? 6a08 e8???????? 83c40c 85c0 751f }
+ $sequence_7 = { 51 55 e8???????? 83c408 3bc3 7504 6a6e }
+ $sequence_8 = { c3 57 56 e8???????? 83c408 6893000000 68???????? }
+ $sequence_9 = { 0fb74550 c7459418001800 c7459848000000 84db 7402 03c0 0fb74d18 }
condition:
- 7 of them and filesize <507904
+ 7 of them and filesize <3162112
}
-rule MALPEDIA_Win_Scout_Auto : FILE
+rule MALPEDIA_Win_Godzilla_Loader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "782e8973-04d4-5ac6-ba73-37d8fadd11cc"
+ id = "0aa53e21-de31-5ee8-9359-dc9a54a6a8e0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scout"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.scout_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.godzilla_loader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.godzilla_loader_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "5102c52e17a0c63528d1a50969c6684ed49d0991b2b60fe184c02299aec673c2"
+ logic_hash = "2d34f8359c26dd7b822a9bcedc09c50858c69dbe831cef14ec0430298405abb3"
score = 75
quality = 75
tags = "FILE"
@@ -174955,32 +181990,32 @@ rule MALPEDIA_Win_Scout_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d537c 41b888140000 488d4df0 e8???????? 41b904000000 }
- $sequence_1 = { 498bf9 8b0a e8???????? 90 488d1d86780100 488d356f630100 }
- $sequence_2 = { 736b 488bc3 488bf3 48c1fe06 4c8d2d4ef80000 }
- $sequence_3 = { 4d8bf8 488bc6 48894df7 488945ef 488d0d36fbfeff 83e03f 458be9 }
- $sequence_4 = { 488d1520d50000 b805000000 894520 894528 }
- $sequence_5 = { 7566 b804000000 660f1f840000000000 488d8980000000 }
- $sequence_6 = { e8???????? 33c0 488b8d90140000 4833cc e8???????? }
- $sequence_7 = { c745dca8837182 0f1045d0 c744242801000000 8905???????? }
- $sequence_8 = { 4c89742438 4c897c2430 ff15???????? 33d2 }
- $sequence_9 = { 75dd 488d05e31b0100 483bd8 74d1 488bcb }
+ $sequence_0 = { 50 a5 ff512c 85c0 756c }
+ $sequence_1 = { a5 50 a5 ff512c 85c0 756c }
+ $sequence_2 = { 7406 8b08 50 ff511c }
+ $sequence_3 = { a5 ff512c 85c0 756c }
+ $sequence_4 = { 6a00 8bf8 8d45fc 50 57 6a01 56 }
+ $sequence_5 = { 51 56 57 ff7508 ff15???????? 8bf0 56 }
+ $sequence_6 = { 52 50 ff91f0000000 85c0 7813 }
+ $sequence_7 = { 6a00 6a00 8bf8 8d45fc 50 57 }
+ $sequence_8 = { 57 6a01 56 ff7508 8975fc }
+ $sequence_9 = { 8b08 50 ff11 85c0 7527 }
condition:
- 7 of them and filesize <315392
+ 7 of them and filesize <155648
}
-rule MALPEDIA_Win_Makop_Auto : FILE
+rule MALPEDIA_Win_Artfulpie_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0ddd5ad6-ed99-5e37-bafe-b552882375b1"
+ id = "76593040-a588-559b-a14b-1edef48802a1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.makop"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.makop_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.artfulpie"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.artfulpie_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "153590702efa562c07e5adda47cdb1581820d31e1d121adbb82083fd02f6f827"
+ logic_hash = "61512abd96fd629a35a0b2673ca4f2027db7aa6e8bcee3bfbea21b9b36b003b2"
score = 75
quality = 75
tags = "FILE"
@@ -174994,32 +182029,32 @@ rule MALPEDIA_Win_Makop_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 55 8bec 83e4f8 81ec10040000 53 55 56 }
- $sequence_1 = { 8b84244c010000 8bcb 51 8b8c244c010000 52 50 51 }
- $sequence_2 = { 117c241c 8bb840080000 017c2420 8bb844080000 117c2424 8b8050080000 3bc3 }
- $sequence_3 = { 3d11010000 0f8567030000 0fb7442444 0517fcffff 83f806 0f8754030000 ff24859c4f4000 }
- $sequence_4 = { 53 ff15???????? 85c0 0f84f1000000 6a00 8d442418 }
- $sequence_5 = { 8d442418 50 51 e8???????? 85c0 0f85cb000000 }
- $sequence_6 = { bb01000000 395d08 7571 b8???????? 668b08 83c002 6685c9 }
- $sequence_7 = { 5e 5b 83c41c c3 ff15???????? 50 }
- $sequence_8 = { 33db 3bf3 740f 56 895e18 895e1c }
- $sequence_9 = { 895c241c 895c2420 895c2424 745e 90 8b06 }
+ $sequence_0 = { 894ddc c745e0a8204100 e9???????? c745e0a4204100 }
+ $sequence_1 = { 8d1c8568524100 8b03 8b15???????? 83cfff 8bca 8bf2 }
+ $sequence_2 = { 23c1 83c008 5d c3 8b04c544ec4000 5d }
+ $sequence_3 = { 7514 8b7830 8b00 397838 740a 33d2 }
+ $sequence_4 = { 6a00 8d854cfcffff c745fc2a2f2a00 50 }
+ $sequence_5 = { 660f282d???????? 660f59f5 660f28aa101f4100 660f54e5 660f58fe 660f58fc 660f59c8 }
+ $sequence_6 = { e8???????? 85c0 7432 8bcb e8???????? }
+ $sequence_7 = { 8b5d10 8b0485984e4100 56 8b7508 57 8b4c0818 }
+ $sequence_8 = { 50 53 ff15???????? 85c0 7455 8b7df0 }
+ $sequence_9 = { 6a41 5f 894df0 8b34cdf00e4100 8b4d08 6a5a }
condition:
- 7 of them and filesize <107520
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Sslmm_Auto : FILE
+rule MALPEDIA_Win_Mirage_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "66fe7984-4fbf-52ff-a40d-1ce2823f2352"
+ id = "1bf63709-182f-50be-a8ab-e40f87c0e4e9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sslmm"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sslmm_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mirage"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mirage_auto.yar#L1-L173"
license_url = "N/A"
- logic_hash = "d75465397d6b8b1866eed0e7ec1b8ff2d24536787a6f5113faf56887d0bb752f"
+ logic_hash = "dc6fe884f3e04eb4b8ba5e715519d9f15ffa67807a8e3bc171df65981afb64ab"
score = 75
quality = 75
tags = "FILE"
@@ -175033,32 +182068,38 @@ rule MALPEDIA_Win_Sslmm_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89542440 8d4c2418 89442414 89542444 }
- $sequence_1 = { 8b8c2484000000 8bbc2480000000 8b54247c 51 57 52 8bcb }
- $sequence_2 = { 8b442438 89742418 89542468 89442460 8b44241c 33f6 8d542428 }
- $sequence_3 = { e9???????? ff15???????? 50 eb13 5f 5e }
- $sequence_4 = { 8b868c000000 68???????? 85c0 7413 6800000200 6a00 }
- $sequence_5 = { 83c40c 899374010000 33ed 8b8374010000 }
- $sequence_6 = { 83f8ff 0f8477020000 3bc5 0f84fb010000 8b9374010000 55 03d0 }
- $sequence_7 = { 83c414 3bc3 770a 6a0a }
- $sequence_8 = { 8db120010000 8b780c 42 897814 8b7808 897810 }
- $sequence_9 = { 8b7c2424 e9???????? 50 8bcf eb2e }
+ $sequence_0 = { 6801000080 ff15???????? 85c0 7556 }
+ $sequence_1 = { 50 6a01 6a06 c645ff01 }
+ $sequence_2 = { a0???????? 8d8d90feffff ff35???????? 50 ff75ec ff75e8 e8???????? }
+ $sequence_3 = { 50 8d857cfdffff 50 e8???????? 59 59 8d8580feffff }
+ $sequence_4 = { 3b4510 894514 731f 6802800000 8d8520010000 53 }
+ $sequence_5 = { ff7518 e8???????? 83c41c 85ff 7613 8b4518 57 }
+ $sequence_6 = { 50 53 68???????? c745f804010000 ff75fc ff15???????? }
+ $sequence_7 = { 395df4 0f85b1000000 3bf3 0f85a9000000 381f }
+ $sequence_8 = { ff7518 03fb e8???????? 33db 59 }
+ $sequence_9 = { 57 8b7d18 8bf1 8d5f19 88461c 53 e8???????? }
+ $sequence_10 = { e8???????? 50 8d8520f9ffff e9???????? }
+ $sequence_11 = { 85c0 5e 7507 8b45f8 }
+ $sequence_12 = { 50 8b08 ff517c 8b06 8d55f4 52 50 }
+ $sequence_13 = { e8???????? 8d45e4 56 83c704 }
+ $sequence_14 = { ff15???????? 8d85f4f0ffff 53 50 68???????? 56 e8???????? }
+ $sequence_15 = { 56 50 e8???????? 83c414 e9???????? ff75f0 e8???????? }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <1695744
}
-rule MALPEDIA_Win_Starsypound_Auto : FILE
+rule MALPEDIA_Win_Yahoyah_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "70e37162-3a73-596a-8d7d-42b9d85b78f7"
+ id = "8071f7bc-1af0-58b6-8984-8add890e5a04"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.starsypound"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.starsypound_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yahoyah"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yahoyah_auto.yar#L1-L158"
license_url = "N/A"
- logic_hash = "abf4ae91c4287e1227ba24bd55f61dc3c1250c1b8b21f760166157e29806933f"
+ logic_hash = "5a0539481a7f5653801a561ffa29165f1f4bf92248a27b13820a8f2035c6eb1c"
score = 75
quality = 75
tags = "FILE"
@@ -175072,32 +182113,37 @@ rule MALPEDIA_Win_Starsypound_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 8dbc2458010000 83c9ff 33c0 }
- $sequence_1 = { 68???????? 52 e8???????? 83c420 85c0 7444 8b5304 }
- $sequence_2 = { 53 56 57 6a18 e8???????? 8bb42424040000 }
- $sequence_3 = { 8d4c2428 68???????? 51 e8???????? 56 8d542434 }
- $sequence_4 = { 8bfd 8d44240c f3a5 8b5500 8b3d???????? 6a00 }
- $sequence_5 = { 885c3438 c744241804010000 ff15???????? 8dbc2458010000 83c9ff 33c0 }
- $sequence_6 = { 50 8d4c2424 56 51 52 }
- $sequence_7 = { f3a4 885c0444 bf???????? 83c9ff 33c0 33f6 }
- $sequence_8 = { 83c40c 85c0 7e2b eb08 }
- $sequence_9 = { e8???????? 68c0270900 ff15???????? e8???????? 5f }
+ $sequence_0 = { ff15???????? 6a02 53 6af0 }
+ $sequence_1 = { 50 6800080000 ff15???????? ff15???????? }
+ $sequence_2 = { 53 53 56 53 ff15???????? 68d0070000 }
+ $sequence_3 = { 50 e8???????? 83c418 6a02 53 }
+ $sequence_4 = { ff15???????? 6a2e 68???????? e8???????? }
+ $sequence_5 = { e8???????? 59 53 53 6a03 0fb7c8 }
+ $sequence_6 = { 52 c1e808 23c1 50 68???????? }
+ $sequence_7 = { ff15???????? 85c0 7501 c3 56 }
+ $sequence_8 = { 23d1 52 8bd0 c1ea18 52 0fb6d0 }
+ $sequence_9 = { eb19 ff15???????? 0fb7c0 50 68???????? }
+ $sequence_10 = { 6a1a 50 e8???????? bf???????? }
+ $sequence_11 = { ff15???????? 6a3a 56 e8???????? 8bf0 83c410 }
+ $sequence_12 = { 90 33c9 33c0 648b3530000000 8b760c }
+ $sequence_13 = { 90 68add13441 ffb53ffbffff 6a00 e8???????? 898521f1ffff e8???????? }
+ $sequence_14 = { 90 90 90 90 90 68add13441 ffb53ffbffff }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <483328
}
-rule MALPEDIA_Win_Socelars_Auto : FILE
+rule MALPEDIA_Win_Unidentified_053_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b06c7ac2-d920-55f6-9edd-c06a57d2d404"
+ id = "b8635dce-dc5b-565f-a079-d654a222f110"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.socelars"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.socelars_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_053"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_053_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "29f15e383674389295d6d5d873e2a8fae68e30508b53f5e863e0aef43fe3264f"
+ logic_hash = "466de537792d4c8cf5922d9a48018d257023e4a1753f3d834debb6d43be45c35"
score = 75
quality = 75
tags = "FILE"
@@ -175111,34 +182157,34 @@ rule MALPEDIA_Win_Socelars_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f6462808 894618 7515 8b4c243c ba14000000 e8???????? 89842430010000 }
- $sequence_1 = { 8b4dfc 83b9cc03000020 7409 c745c00c000000 eb07 c745c00e000000 8b55fc }
- $sequence_2 = { ff460c 807e0a00 750a 8bce e8???????? 8a4e09 8b430c }
- $sequence_3 = { ff730c ff7308 e8???????? 8bf8 83c410 85ff 0f8480000000 }
- $sequence_4 = { 8b542410 8b5248 f6421c20 0f8437050000 8b4214 ff4878 8b8888000000 }
- $sequence_5 = { e9???????? 8b4c243c 33c0 89842430010000 ba43000000 8b472c 40 }
- $sequence_6 = { f7da 56 1bd2 83c235 eb55 6a00 ff77c4 }
- $sequence_7 = { e8???????? 83c40c eb36 8d4201 898188000000 8d0c92 8b442438 }
- $sequence_8 = { fe4613 8a4619 fec8 0fb6c8 884619 3bf9 7d24 }
- $sequence_9 = { ff742424 e8???????? 83c40c eb32 8b54241c 8d4101 898688000000 }
+ $sequence_0 = { 753c ff75e4 68???????? e8???????? 85c0 59 }
+ $sequence_1 = { c1c603 81ea584dff93 8915???????? e8???????? 42 }
+ $sequence_2 = { 8d3c85a8914100 833f00 bb00100000 7520 53 e8???????? }
+ $sequence_3 = { ff75f0 50 ff91c4010000 8945f4 85c0 }
+ $sequence_4 = { f7d7 c1c30e ffd0 890d???????? 87c7 2bc3 f7da }
+ $sequence_5 = { f7db c1c017 e8???????? f7d1 }
+ $sequence_6 = { 03f7 46 f7d8 81ebd4b243e9 c1c80c }
+ $sequence_7 = { 3b8e50894100 0f8515010000 a1???????? 83f801 0f84df000000 3bc2 }
+ $sequence_8 = { 81f669d8509c f7d2 686c6c6f63 e8???????? 4e 03c1 890d???????? }
+ $sequence_9 = { 8b048588814100 234508 8b4e14 8d04c1 0fb64801 8b5004 83fa10 }
condition:
- 7 of them and filesize <2151424
+ 7 of them and filesize <294912
}
-rule MALPEDIA_Win_Unidentified_074_Auto : FILE
+rule MALPEDIA_Win_Vidar_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0d21a50a-0481-57c8-ac0f-f7fe46c9359f"
+ id = "82d78950-07cb-574b-bd37-68a5c755b922"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_074"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_074_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vidar_auto.yar#L1-L344"
license_url = "N/A"
- logic_hash = "e6b5821f00996c51a196dd1c4d62a76bb0e0925ea653a38d0c3db163875f48e7"
+ logic_hash = "a393071c5079ff4f7beb96e2467045a96573fe4c259d05f0ce07fde763d7466d"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -175150,32 +182196,60 @@ rule MALPEDIA_Win_Unidentified_074_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ffb578dfffff e8???????? 33c0 c7858cdfffff07000000 c78588dfffff00000000 66898578dfffff }
- $sequence_1 = { 50 e8???????? 6aff 6a01 83ec08 c745fc00000000 8d4dd8 }
- $sequence_2 = { 3bc1 7432 8b4d08 8d041e 8a0408 3a02 7516 }
- $sequence_3 = { 50 ff15???????? 8bf0 85f6 0f84c4010000 837f1000 }
- $sequence_4 = { 50 899d6cdfffff c78568dfffff00000000 660fd645e4 e8???????? }
- $sequence_5 = { c78524e7ffff07000000 66898510e7ffff 8d85f8e6ffff 50 8d8540e7ffff c78520e7ffff00000000 50 }
- $sequence_6 = { 8d4e01 8a06 46 84c0 75f9 8d4588 }
- $sequence_7 = { e8???????? 83c40c 019dc4feffff 8b85c4feffff }
- $sequence_8 = { 83ec08 8845f0 8d45f0 50 e8???????? 884435e8 }
- $sequence_9 = { 8d8d70e7ffff 6a12 33c0 c78584e7ffff07000000 }
+ $sequence_0 = { 25ff7f0000 c3 e8???????? 8b486c 3b0d???????? 7410 }
+ $sequence_1 = { 05c39e2600 894114 c1e810 25ff7f0000 c3 e8???????? }
+ $sequence_2 = { 8d8d68fdffff 51 50 ff15???????? }
+ $sequence_3 = { 7202 8b00 8d8d68fdffff 51 }
+ $sequence_4 = { 740a b800000500 e9???????? 57 }
+ $sequence_5 = { 56 8b742408 8b865caf0100 57 }
+ $sequence_6 = { 895dd0 c746140f000000 895e10 8975cc }
+ $sequence_7 = { 8b8648af0100 c1e803 038644af0100 5e 5d c3 }
+ $sequence_8 = { 895dfc e8???????? 83781408 c645fc01 }
+ $sequence_9 = { 8b7508 33ff 89b55cfdffff 89bd60fdffff }
+ $sequence_10 = { 5f c6043300 8bc6 5e 5b c20400 }
+ $sequence_11 = { 50 ff15???????? 8b4da0 8901 85c0 }
+ $sequence_12 = { 83781410 7202 8b00 50 8b45a0 }
+ $sequence_13 = { eb02 33c0 5f 5e c9 c3 6a04 }
+ $sequence_14 = { 5e c20400 ff742408 e8???????? 59 83f8ff 7503 }
+ $sequence_15 = { c9 c3 8b542408 85d2 7503 }
+ $sequence_16 = { 0fb605???????? 50 0fb605???????? 50 0fb605???????? 50 6a01 }
+ $sequence_17 = { 53 50 899e6caf0600 e8???????? }
+ $sequence_18 = { 53 68???????? 8d8da8000000 e8???????? }
+ $sequence_19 = { c3 55 8bec 83ec0c 8365fc00 8365f400 8365f800 }
+ $sequence_20 = { c20400 56 8bf1 e8???????? 6a00 ff74240c 8bce }
+ $sequence_21 = { 0faf450c 50 e8???????? 59 }
+ $sequence_22 = { 8b4508 8906 8b450c 894608 }
+ $sequence_23 = { 8b4120 8910 8b4130 8910 c3 56 }
+ $sequence_24 = { e8???????? c9 c3 55 8bec 83ec18 8b450c }
+ $sequence_25 = { 8d852cffffff 50 8d459c 50 }
+ $sequence_26 = { 6860ea0000 6a00 ff15???????? 50 }
+ $sequence_27 = { 50 ff15???????? 6a1a e8???????? }
+ $sequence_28 = { 5f c21000 8bff 55 8bec 6a0a }
+ $sequence_29 = { e8???????? 83c410 85c0 7404 6a99 ebcc }
+ $sequence_30 = { 7410 84c0 7406 3ac8 7c14 }
+ $sequence_31 = { 7408 ff36 e8???????? 59 834e04ff 8b06 }
+ $sequence_32 = { e8???????? 83c408 84c0 740e 68???????? }
+ $sequence_33 = { 6a0b 6a10 e8???????? 83c41c 8be5 }
+ $sequence_34 = { eb0b 8b45f4 0500040000 8945f4 }
+ $sequence_35 = { 83ec08 dd4508 dd1c24 6a0b 6a08 }
+ $sequence_36 = { 8bc6 8b35???????? 99 2bc2 }
+ $sequence_37 = { 8bc6 5f 5e 5d 5b 81c460010000 c3 }
condition:
- 7 of them and filesize <335872
+ 7 of them and filesize <2793472
}
-rule MALPEDIA_Win_Citadel_Auto : FILE
+rule MALPEDIA_Win_Lolsnif_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cf6cb189-c7d7-5571-b2ec-c3b6f165f615"
+ id = "1d5fbfc8-0217-55f5-a391-424b7e7d3b81"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.citadel"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.citadel_auto.yar#L1-L167"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lolsnif"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lolsnif_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "8e88ac7355b3e3defd358849e38b9e68e570cd840f3a9a1ae754cb483f4c91f5"
+ logic_hash = "9bce9d984017297751bb54a3f5eaf0b3b4bc516f4f45f71420e0fbe5f0438c0a"
score = 75
quality = 75
tags = "FILE"
@@ -175189,40 +182263,34 @@ rule MALPEDIA_Win_Citadel_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb0e 6800800000 53 57 }
- $sequence_1 = { 55 8bec ff7508 e8???????? e8???????? 5d }
- $sequence_2 = { eb03 83c002 68???????? 50 ff15???????? }
- $sequence_3 = { e8???????? e8???????? 5d ff25???????? 55 8bec ff7508 }
- $sequence_4 = { 33c0 5f 5e c20400 55 8bec 8b4d0c }
- $sequence_5 = { e8???????? 8d7c0201 8bc7 e8???????? }
- $sequence_6 = { 50 e8???????? 6a44 5a 52 }
- $sequence_7 = { 50 8d5dfc e8???????? 8b4dfc }
- $sequence_8 = { 884601 33c0 6689460c ff4df8 }
- $sequence_9 = { 8a5602 8b4e10 8a5e14 fec8 32d0 8ac2 3245fe }
- $sequence_10 = { 8845fe c645ff00 763c 8a06 }
- $sequence_11 = { 3aca 73fa 0fb6c9 8b04c8 ebae 32c0 5f }
- $sequence_12 = { 33c0 6689460e 0fb74606 6685c0 7432 }
- $sequence_13 = { 85c0 7409 3255fd 8a0f ffd0 8807 }
- $sequence_14 = { 6685c0 7432 66ff460e 6639460e }
- $sequence_15 = { 6639460c 7228 8b4610 8a4e05 8a5614 85c0 }
+ $sequence_0 = { c745ecebfecccc 8945f8 895dfc e8???????? 85c0 0f84e6000000 c745fc10000000 }
+ $sequence_1 = { 8d4510 50 ff35???????? e8???????? 8bf8 85ff 0f8576010000 }
+ $sequence_2 = { 8945fc 7460 894508 ff35???????? 8b450c ff7510 e8???????? }
+ $sequence_3 = { 6817010000 1bc0 51 23c6 50 e8???????? e9???????? }
+ $sequence_4 = { 3bf1 742b 53 8b5f04 }
+ $sequence_5 = { 8bf8 85ff 754c 8b45fc }
+ $sequence_6 = { 6a20 50 ff15???????? 3bc3 0f84eb000000 68???????? 50 }
+ $sequence_7 = { 8b471c 3bc3 7411 50 53 ff35???????? ff15???????? }
+ $sequence_8 = { 85c0 0f841b020000 50 ff7320 e8???????? 8bf0 }
+ $sequence_9 = { bf02010000 eb08 ff15???????? 8bf8 }
condition:
- 7 of them and filesize <1236992
+ 7 of them and filesize <425984
}
-rule MALPEDIA_Win_Unidentified_077_Auto : FILE
+rule MALPEDIA_Win_Industroyer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "882d313e-f7f0-5285-8af9-6252268fd85d"
+ id = "9c6bfb9f-c466-5000-a18a-b1782556f295"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_077"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_077_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.industroyer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.industroyer_auto.yar#L1-L379"
license_url = "N/A"
- logic_hash = "40d4971486b6904e4039a2237673f8c9270e32fac79f99c950b8e92b2f7aa0ab"
+ logic_hash = "10be42e3e137c59c80c36fac63f4d878185befa45cbf0b3714b0e9925e862e84"
score = 75
- quality = 75
+ quality = 73
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -175234,32 +182302,62 @@ rule MALPEDIA_Win_Unidentified_077_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89442420 488bcf ff15???????? 85c0 }
- $sequence_1 = { 488bcf ff15???????? 498bce ff15???????? 488bce }
- $sequence_2 = { 488bb424f00d0000 488b8dd00c0000 4833cc e8???????? 4881c4f80d0000 }
- $sequence_3 = { 0f8559ffffff 488bcf ff15???????? 498bce ff15???????? 488bce ff15???????? }
- $sequence_4 = { 498784f180bf0100 eb25 488bc3 498784f180bf0100 4885c0 }
- $sequence_5 = { 4d8be1 498be8 4c8bea 4b8b8cf7e0c70100 4c8b15???????? }
- $sequence_6 = { 33db 33ff 4c8bea 4c8be1 4883fa40 7312 }
- $sequence_7 = { f30f6f0418 660fefc1 f30f7f0418 8d4210 83c220 f30f6f0418 660fefc1 }
- $sequence_8 = { 0f8559ffffff 488bcf ff15???????? 498bce }
- $sequence_9 = { e8???????? 85c0 0f85c6000000 448b442468 }
+ $sequence_0 = { 50 50 ff750c ff15???????? 8d45fc 50 8d45f8 }
+ $sequence_1 = { 68f4010000 ff15???????? 33c0 50 }
+ $sequence_2 = { 50 8945e0 e8???????? 8945f8 e8???????? 50 8945e4 }
+ $sequence_3 = { 6808020000 50 ff7710 ff15???????? }
+ $sequence_4 = { ff7710 6a03 56 e8???????? 83c424 894708 85c0 }
+ $sequence_5 = { ff15???????? 8bd8 8d8598fdffff 6804010000 50 68???????? ff15???????? }
+ $sequence_6 = { 6a02 50 53 68000000c0 56 c745f40c000000 895dfc }
+ $sequence_7 = { 6a4c e8???????? 8bf0 8d8510ffffff 6a4c }
+ $sequence_8 = { 8bf9 ff15???????? 3bf8 0f84bb000000 }
+ $sequence_9 = { 8b7508 ff7604 8b06 ffd0 56 e8???????? }
+ $sequence_10 = { ffd6 85c0 7431 ff35???????? }
+ $sequence_11 = { 8bd8 85db 0f849d000000 8d85d0fdffff c785d0fdffff2c020000 50 53 }
+ $sequence_12 = { 683f010f00 6a00 8d85a0f3ffff 50 6802000080 ff15???????? 85c0 }
+ $sequence_13 = { 85c0 0f85bb000000 6800020000 8d85a0fbffff 50 }
+ $sequence_14 = { bfffff0000 0f46f9 3d00005000 b900400000 }
+ $sequence_15 = { 8d8c2468020000 e8???????? 8d442418 50 ff742414 ff15???????? }
+ $sequence_16 = { eb07 8b0cc5dc084100 894de4 85c9 }
+ $sequence_17 = { 0f8501010000 c745e0e4ff4000 8b4508 8bcf }
+ $sequence_18 = { 6a0a 8854382a 8b048dd01f0210 8874382b 8b048dd01f0210 5a }
+ $sequence_19 = { 0f8580000000 8b4508 dd00 ebc6 c745e0e8ff4000 }
+ $sequence_20 = { 6689823e020000 0fb68340020000 888240020000 8d8344020000 50 e8???????? }
+ $sequence_21 = { 50 ff15???????? 6a02 ff15???????? 50 ffd6 ff770c }
+ $sequence_22 = { 0fb605???????? 88413e 0f1005???????? 0f118133010000 a1???????? 898143010000 }
+ $sequence_23 = { 83e901 740d 83e902 7521 }
+ $sequence_24 = { 660f28b820004100 660f54f0 660f5cc6 660f59f4 660f5cf2 f20f58fe }
+ $sequence_25 = { 807b0100 0f85fc000000 a840 0f85d5000000 ff35???????? ff15???????? }
+ $sequence_26 = { 89422c 0fb64330 884230 0fb64331 884231 0fb64332 }
+ $sequence_27 = { 746a ff7508 8b15???????? 51 8bcb e8???????? }
+ $sequence_28 = { 85c0 7450 6aff 56 ff15???????? }
+ $sequence_29 = { ba???????? 0f94c1 884b32 84c9 a1???????? f30f7e05???????? }
+ $sequence_30 = { 8b442418 89442440 8d44243c 50 ff15???????? 50 }
+ $sequence_31 = { ff15???????? 68???????? ff15???????? 85c0 7417 68???????? }
+ $sequence_32 = { 83c410 84c0 0f84b9010000 8b8520ffffff 8bbd1cffffff 2bc7 }
+ $sequence_33 = { 8d4dc8 ff30 e8???????? 8d4d84 83ff02 0f86a4000000 }
+ $sequence_34 = { e8???????? 6a00 56 8d8d08feffff e8???????? }
+ $sequence_35 = { 8bce 8907 53 894704 e8???????? 8b4308 }
+ $sequence_36 = { 53 8b1c85205e4400 56 6800080000 }
+ $sequence_37 = { 8945e4 8d83bc000000 50 e8???????? 6a28 e8???????? }
+ $sequence_38 = { 0fb7c1 8945f8 3905???????? 7f26 663b4df4 7320 }
+ $sequence_39 = { 33c5 8945fc 8365e000 53 8b5d0c 56 }
condition:
- 7 of them and filesize <270336
+ 7 of them and filesize <983040
}
-rule MALPEDIA_Win_Torrentlocker_Auto : FILE
+rule MALPEDIA_Win_Action_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "56bf47db-a6d1-5792-b5b6-3656138ac949"
+ id = "b171bb40-9b64-5f84-b8a8-e9db33470a7a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.torrentlocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.torrentlocker_auto.yar#L1-L170"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.action_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.action_rat_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "9124185b3dba8eb6288bd309dcd17a816c52adb0e1e08ff17bcd23b3d53099e4"
+ logic_hash = "d6b5f7381b8e2ad2725999fb927500f671ba77c3542ba9198900375907d98a2d"
score = 75
quality = 75
tags = "FILE"
@@ -175273,38 +182371,32 @@ rule MALPEDIA_Win_Torrentlocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c3 83f801 7405 83f802 }
- $sequence_1 = { 8b0d???????? 5f c7000c000000 894804 }
- $sequence_2 = { 85c0 7514 e8???????? 3d00000600 }
- $sequence_3 = { 50 56 6a00 6a01 6a02 ff15???????? }
- $sequence_4 = { 8b0d???????? 890e e8???????? 8bd8 e8???????? 6a00 6a01 }
- $sequence_5 = { 83ec24 6a00 6a01 68???????? ff15???????? 85c0 7551 }
- $sequence_6 = { 56 ff15???????? 83f802 740f 83f803 740a }
- $sequence_7 = { e8???????? 3d00000600 1bc0 40 a3???????? eb05 }
- $sequence_8 = { 83c002 6685c9 75f5 2bc2 d1f8 8d440014 }
- $sequence_9 = { 52 50 ff15???????? 85c0 7519 8b0d???????? 51 }
- $sequence_10 = { 51 6a01 6a00 0d00800000 50 6a00 }
- $sequence_11 = { 8b0d???????? 5f 894e0c 5e }
- $sequence_12 = { 8b0d???????? 6a00 6a00 57 }
- $sequence_13 = { 48 85c0 7ff4 5f 33c0 5e c3 }
- $sequence_14 = { 8b0d???????? 57 6a00 51 ff15???????? 8bc6 }
- $sequence_15 = { c705????????00000000 e8???????? 8bf0 e8???????? }
+ $sequence_0 = { 8d4d0c e8???????? 8b4508 8b4df4 64890d00000000 59 5b }
+ $sequence_1 = { 8b55f8 52 8b4dfc 83c134 e8???????? 8b00 50 }
+ $sequence_2 = { 83c270 52 8b4dfc 83c170 }
+ $sequence_3 = { e8???????? c745d400000000 eb09 8b4dd4 83c101 894dd4 8d4d0c }
+ $sequence_4 = { 7420 0fb645fb 50 8b4df4 8b4918 e8???????? 0fb6d0 }
+ $sequence_5 = { 0fb74202 50 ff15???????? 0fb7c8 8b5514 890a }
+ $sequence_6 = { 6a00 8b45fc 50 8b4d08 51 e8???????? 83c418 }
+ $sequence_7 = { e8???????? 8d8ddcfbffff e8???????? c645fc0e 6a00 68e0930400 6a00 }
+ $sequence_8 = { 0de0000000 b901000000 6bd100 8b4d0c 880411 8b5508 c1fa06 }
+ $sequence_9 = { 8b4df4 3b4df8 750b 68???????? ff15???????? 8b55ec 833a22 }
condition:
- 7 of them and filesize <933888
+ 7 of them and filesize <480256
}
-rule MALPEDIA_Win_Ployx_Auto : FILE
+rule MALPEDIA_Win_Tempedreve_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7a9ae933-1e52-56f8-912b-cfaf3c1a4d79"
+ id = "e62cef01-6d44-587e-a3de-2c290fdad6d7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ployx"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ployx_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tempedreve"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tempedreve_auto.yar#L1-L163"
license_url = "N/A"
- logic_hash = "92d48577836748eb447c5a838f0c9893d40b34aa95d5979c4991a0399ec4439d"
+ logic_hash = "5e6b4c6e2f4e0f76996895055b92463fa9cea8a31f828bb15d4eb02a56497fa3"
score = 75
quality = 75
tags = "FILE"
@@ -175318,32 +182410,38 @@ rule MALPEDIA_Win_Ployx_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bc3 25ff000000 59 3bf0 59 7443 }
- $sequence_1 = { 33db 897df8 e8???????? 397dfc 59 59 }
- $sequence_2 = { 33ff 59 85c0 7e19 8bf0 8bfe 6a20 }
- $sequence_3 = { 66ab ff35???????? aa 8d8588faffff 68???????? 50 }
- $sequence_4 = { 8d3c78 8d0437 50 e8???????? 8b4d08 8d3c78 8d0437 }
- $sequence_5 = { b9???????? b800020000 8d5f02 99 f7fb 47 8901 }
- $sequence_6 = { 33ff 99 59 f7f9 8bc2 03c1 99 }
- $sequence_7 = { 59 8945f4 0f848f000000 8d45e8 50 }
- $sequence_8 = { e8???????? 83c40c 8d85a4fcffff 6a00 50 ff15???????? 8945e8 }
- $sequence_9 = { 740f 3b7df8 7503 8975f8 57 }
+ $sequence_0 = { 011e 015e10 015e0c 0fb75706 }
+ $sequence_1 = { 011a 8b87dc000000 83c204 03c6 }
+ $sequence_2 = { 01042f 034c2ff8 8d45ec 894c2ff8 }
+ $sequence_3 = { 754f 85f6 744b 214524 8d4520 }
+ $sequence_4 = { 011a 45 8d14a9 8b02 }
+ $sequence_5 = { 0103 a1???????? 83c004 50 ff15???????? }
+ $sequence_6 = { 0104b7 8b8424a8000000 83c704 4d }
+ $sequence_7 = { 010f 8b07 83c704 3bc1 }
+ $sequence_8 = { 89542430 eb09 83f801 0f86c8010000 0fb64500 0fb64d01 }
+ $sequence_9 = { 85c0 0f85a9090000 53 8916 8d4e04 }
+ $sequence_10 = { 8bc8 c1e903 8d440140 c20400 }
+ $sequence_11 = { 899e1c040000 895c2458 3bc3 0f86eb070000 8d9b00000000 8b44245c 85c0 }
+ $sequence_12 = { 55 51 8bce 8d5c0301 e8???????? 3bd8 8b5c2458 }
+ $sequence_13 = { 72f3 8b4c2414 8b6c2428 3bda 0f84e1000000 }
+ $sequence_14 = { 8b6c2410 8bd3 2bd7 52 55 8bce e8???????? }
+ $sequence_15 = { 8b542430 3bda 7320 8d4d02 8be8 2b6c2428 }
condition:
- 7 of them and filesize <229376
+ 7 of them and filesize <155648
}
-rule MALPEDIA_Win_Acronym_Auto : FILE
+rule MALPEDIA_Elf_Mirai_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3a02b0db-7dab-59f7-8844-7d3e20bbfec7"
+ id = "99bf67bb-d881-5d1d-9ccf-8805d4c126fc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acronym"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.acronym_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/elf.mirai_auto.yar#L1-L92"
license_url = "N/A"
- logic_hash = "f0c8874a39c6e7d48d0efb9f6335d89bb8e6f6e657bab8b7e1fc238f6642ecb8"
+ logic_hash = "53d684afadf5b7afddedfe71964fc5273146fef2945717259a3274aa2e1d04ee"
score = 75
quality = 75
tags = "FILE"
@@ -175357,32 +182455,30 @@ rule MALPEDIA_Win_Acronym_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89550c 8b4510 034508 8a08 884dff 8b5510 03550c }
- $sequence_1 = { 8b55e8 8a45f4 88040a ebac 33c9 75fc 8be5 }
- $sequence_2 = { 50 ff15???????? 8945f8 8b4dfc 8b5110 52 8b45fc }
- $sequence_3 = { e8???????? 8bc8 e8???????? 0fb6d0 85d2 0f85d4000000 8b450c }
- $sequence_4 = { c745fc00000000 eb09 8b45fc 83c001 8945fc 8b4df4 83c104 }
- $sequence_5 = { 6a00 6a00 ff15???????? b901000000 85c9 0f84fd000000 c745f000000000 }
- $sequence_6 = { 2b55bc 8955b8 8b45b8 8945cc 33c9 75fc 8b55dc }
- $sequence_7 = { 8b0c90 83c101 8b55f4 8b45f0 0fb754505e 8b45ec 69c008040000 }
- $sequence_8 = { 8b4508 50 e8???????? 83c410 ebaa 8b45c4 69c0c51d0000 }
- $sequence_9 = { 69d208040000 8b7508 8d941660b10000 89048a 8b45f4 8b4df0 0fb754411c }
+ $sequence_0 = { 6689432a e8???????? c7433400000000 894330 }
+ $sequence_1 = { 89d0 c1e005 01d0 89ca }
+ $sequence_2 = { 894330 c6433801 c6433903 c6433a03 c6433b06 }
+ $sequence_3 = { 66c1e808 d0e8 8d04c0 28c2 }
+ $sequence_4 = { 3c19 7705 8d42e0 8801 }
+ $sequence_5 = { 807c242b00 66894304 7406 66c743064000 c643092f }
+ $sequence_6 = { 66894104 7406 66c741064000 c6410911 }
+ $sequence_7 = { 8b1408 895310 8b54080c 66895314 }
condition:
- 7 of them and filesize <466944
+ 7 of them and filesize <2228224
}
-rule MALPEDIA_Win_Morto_Auto : FILE
+rule MALPEDIA_Win_Allaple_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b4e2fdf6-28d4-5bb0-a9a0-1ea448c5566e"
+ id = "3189c357-03ca-579b-a008-778eac3a8556"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.morto"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.morto_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.allaple"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.allaple_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "a9b63fda2800565a4b4486897d85bf042e81c5ab64e52d3f79cf07bf3408f96f"
+ logic_hash = "415071fc213b7748f93f2d59f832b2786979b53afe7fe779d13e0c2bb9460bfe"
score = 75
quality = 75
tags = "FILE"
@@ -175396,34 +182492,34 @@ rule MALPEDIA_Win_Morto_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 280c30 40 3b450c 72f4 8b4608 6a40 }
- $sequence_1 = { 50 e8???????? 83c40c 8945e4 8d45cc }
- $sequence_2 = { 03d0 8911 ffd2 5f 5e }
- $sequence_3 = { 03f5 42 8a1e 46 }
- $sequence_4 = { ff35???????? c745ec04000000 c745fce8030000 ff15???????? }
- $sequence_5 = { 8bf0 c1ee08 83e601 8d3c56 }
- $sequence_6 = { 41 8d441201 8bd0 c1ea08 83e201 a87f 8d3c7a }
- $sequence_7 = { c745d0636c6965 c745d46e745c61 8945d8 c745dc44726f70 }
- $sequence_8 = { 6802000080 ff55e0 85c0 755f 8d45f8 50 }
- $sequence_9 = { 894dfc 895508 eb03 8b75f4 b980000000 33c0 8dbdf0fdffff }
+ $sequence_0 = { 50 ff75a0 e8???????? 83f8ff 756a e8???????? 3d33270000 }
+ $sequence_1 = { 7708 2b7b0c 037b14 eb0f 83c328 83c628 }
+ $sequence_2 = { 6a40 8b55a8 8d4db0 e8???????? 8b55f8 2355f4 8b45f8 }
+ $sequence_3 = { 6a14 ff7508 57 e8???????? 83c714 c70701000000 83c704 }
+ $sequence_4 = { 6800800000 6a00 ff75e0 e8???????? eb09 0bc0 7505 }
+ $sequence_5 = { 55 8bec 83ec24 8955e0 894de4 c745fc00000000 8b45fc }
+ $sequence_6 = { 894174 8b55fc 8b4278 3345f4 8b4df8 894178 8b55fc }
+ $sequence_7 = { 0f8539010000 8145f8bc020000 ff75f8 e8???????? 8945f4 ff75fc ff75f4 }
+ $sequence_8 = { ff45fc 8b45fc 3b4510 7ce5 8be5 5d c3 }
+ $sequence_9 = { 8b4df8 894178 8b55fc 8b427c 3345f4 8b4df8 89417c }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Korlia_Auto : FILE
+rule MALPEDIA_Win_Virlock_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d35af9df-a058-5a30-a77f-8fa81b1625c9"
+ id = "a53ad870-36e8-5483-a3c7-250260a5d06b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.korlia"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.korlia_auto.yar#L1-L481"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.virlock"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.virlock_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "17b5ea46685442b751a30de5596fa43f96dfb43c44e790391afede4018d6463a"
+ logic_hash = "2251c81b77f733b642183ccf22ad3a25fb0df2e83278219ff44fcff0baf92b0d"
score = 75
- quality = 50
+ quality = 69
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -175435,75 +182531,32 @@ rule MALPEDIA_Win_Korlia_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 68???????? 51 ffd6 }
- $sequence_1 = { 6a32 50 ff15???????? 85c0 7521 }
- $sequence_2 = { 33c0 f2ae f7d1 49 83f90f 7604 }
- $sequence_3 = { f7ef c1fa14 8bc2 c1e81f 03d0 52 }
- $sequence_4 = { 8965e8 c645e401 c745fc00000000 52 }
- $sequence_5 = { 59 5a c745fcffffffff 8a45e4 8b4df0 64890d00000000 5f }
- $sequence_6 = { 81fb68584d56 0f9445e4 5b 59 5a c745fcffffffff }
- $sequence_7 = { 7410 6a28 68???????? 6aff 53 6a00 }
- $sequence_8 = { 6a00 ffd6 68???????? c705????????1c010000 ff15???????? }
- $sequence_9 = { 6a01 53 53 53 51 ff15???????? 85c0 }
- $sequence_10 = { 8b442404 56 6a00 6a00 6a01 6a00 }
- $sequence_11 = { 6a01 6a00 6a00 6800000040 50 ff15???????? 8bf0 }
- $sequence_12 = { e8???????? 8a4c2404 6a01 884814 8b4c240c 898840200000 }
- $sequence_13 = { 8b4c240c 898840200000 58 c20800 e9???????? 6800060000 }
- $sequence_14 = { 8bf0 83feff 7423 8b542410 8b44240c 8d4c2408 }
- $sequence_15 = { 59 59 c3 8b65e8 ff7588 ff15???????? 833d????????ff }
- $sequence_16 = { 50 56 ff15???????? 56 ff15???????? b001 5e }
- $sequence_17 = { ff15???????? 833d????????ff 750c ff742404 ff15???????? }
- $sequence_18 = { ff742410 ff742410 ff742410 e8???????? c21000 e8???????? 8a4c2404 }
- $sequence_19 = { 6a00 680030c800 6a00 6a00 }
- $sequence_20 = { b8447c0000 e8???????? 53 56 }
- $sequence_21 = { 8d442444 894d00 8b542438 83c504 50 895500 }
- $sequence_22 = { 6880000000 6800000400 8bce e8???????? }
- $sequence_23 = { 8bf9 81e7ff000000 03f2 03f7 }
- $sequence_24 = { ffd6 8d44240c 6804010000 50 }
- $sequence_25 = { 83c504 50 895500 83c504 e8???????? d1e0 }
- $sequence_26 = { 6a00 6a00 50 8bce e8???????? 6a00 }
- $sequence_27 = { 51 ff15???????? a1???????? b981000000 }
- $sequence_28 = { 750c ff15???????? 53 e9???????? }
- $sequence_29 = { 0f8599000000 53 56 57 b940000000 }
- $sequence_30 = { ffd6 eb06 8b35???????? a1???????? 3bc3 7403 50 }
- $sequence_31 = { 68ff0f1f00 ff15???????? 85c0 740a }
- $sequence_32 = { 8d542414 6a00 52 68???????? 6a00 ff15???????? }
- $sequence_33 = { 85c0 740a 56 50 ff15???????? 8bf0 }
- $sequence_34 = { 33c0 8dbc245e020000 66899c245c020000 f3ab }
- $sequence_35 = { 7403 50 ffd6 b912010000 33c0 }
- $sequence_36 = { f3ab aa b9f9000000 33c0 }
- $sequence_37 = { 56 3bc3 57 740b 8b35???????? 50 }
- $sequence_38 = { 6801000080 ff15???????? 85c0 0f8599000000 53 }
- $sequence_39 = { 68???????? 51 ff15???????? 8b54240c 8bf0 }
- $sequence_40 = { 40 81c408010000 c3 83c8ff }
- $sequence_41 = { 5e 24fe 5b 40 }
- $sequence_42 = { 83c9ff 33c0 68003e0000 f2ae f7d1 2bf9 }
- $sequence_43 = { 50 8b4308 6a02 57 ffd0 85c0 750c }
- $sequence_44 = { a0???????? 884102 ba???????? 8bf2 8a02 42 }
- $sequence_45 = { 51 8b0d???????? 8d85c4f0ffff 6a05 6a04 50 }
- $sequence_46 = { 8bc7 83e03f 6bc830 8b049578c14100 f644082801 7421 57 }
- $sequence_47 = { 85f6 7439 8d4dd0 68???????? 51 c745d0306e4000 }
- $sequence_48 = { ff15???????? 85c0 7421 6a3f 8d85fcfeffff }
- $sequence_49 = { 6a00 ff15???????? 8bf8 85ff 7503 5f 5e }
- $sequence_50 = { 5d c20c00 ffb5f8efffff 8b35???????? }
- $sequence_51 = { 51 e8???????? 8d942404030000 68???????? 52 }
- $sequence_52 = { 50 51 e8???????? 8b742430 83c41c }
+ $sequence_0 = { e8???????? e8???????? ff15???????? 61 3bcb 7532 60 }
+ $sequence_1 = { 9d cde6 81b4e570805c4af32b0cf0 e602 a4 b592 9c }
+ $sequence_2 = { 68???????? eb0a 68???????? 68???????? e8???????? 83fa00 751b }
+ $sequence_3 = { 81f2???????? 81f35e473bfc 81f308f661fc 81f37dc97000 e8???????? bb8aedf4f9 baf2edecff }
+ $sequence_4 = { 45 58 58 46 54 4f 53 }
+ $sequence_5 = { eb07 3106 83c604 ebea 83f901 754a }
+ $sequence_6 = { 42 4b 4e 53 47 4b 56 }
+ $sequence_7 = { 44 56 53 49 4f 45 }
+ $sequence_8 = { 8bf8 90 e9???????? 8807 90 42 90 }
+ $sequence_9 = { bb53203dfd 3106 83c604 bb975ea4f7 ebb5 83f901 }
condition:
- 7 of them and filesize <263168
+ 7 of them and filesize <4202496
}
-rule MALPEDIA_Win_Mars_Stealer_Auto : FILE
+rule MALPEDIA_Win_Suncrypt_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d22235ef-5968-5e10-be47-3cfb22c5f1b3"
+ id = "93d1d1b0-e368-5e85-941c-a502b4af6a15"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mars_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mars_stealer_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.suncrypt"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.suncrypt_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "b25b9578c7efb2902b746c00b6410a6cd2ad1c64e90ea264af3674a130d6b800"
+ logic_hash = "3fd8ca759efc6a63a6777db0d881129a01860e6b4243db4bd8968c844a421043"
score = 75
quality = 75
tags = "FILE"
@@ -175517,32 +182570,32 @@ rule MALPEDIA_Win_Mars_Stealer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 33049508674100 894508 8b4d0c 83c101 894d0c 8b550c }
- $sequence_1 = { 8b5118 52 8b853cfbffff 8b4814 }
- $sequence_2 = { 898564e6ffff 83bd64e6ffff00 0f8405030000 6a00 }
- $sequence_3 = { a1???????? 50 8b4d08 51 e8???????? 83c410 6a04 }
- $sequence_4 = { 8b5508 c1ea08 33148d08674100 895508 8b450c }
- $sequence_5 = { 52 8d85e8feffff 50 68???????? 8b4df8 51 }
- $sequence_6 = { 837df820 0f8d61030000 6804010000 8d8de8feffff 51 e8???????? }
- $sequence_7 = { 2b4d08 c681407c410000 8b550c 8955f8 }
- $sequence_8 = { 8b953cfbffff 8b4214 83c020 50 6a00 }
- $sequence_9 = { 52 8b85fcfbffff 50 ff15???????? 89857cdeffff }
+ $sequence_0 = { ff15???????? 6a00 6a00 6a03 6a00 6a00 ff75b8 }
+ $sequence_1 = { 8b8d60ffffff 8945c8 8b856cffffff 8945ac 8b8564ffffff 8945cc 8b855cffffff }
+ $sequence_2 = { c645f84c c645f90e c645fa44 c645fb4c c645fc4c 8a45f4 c645fd00 }
+ $sequence_3 = { 02ca 0fbec0 33c8 884c15ec 42 83fa11 72e8 }
+ $sequence_4 = { 894dd0 034d98 8bf9 337dcc c1c70c 03c7 898534ffffff }
+ $sequence_5 = { c3 8b07 0fb74f0e 8b4004 8b0488 894724 }
+ $sequence_6 = { 8b7308 83c140 8b7da0 894df4 8b4df0 eb7e }
+ $sequence_7 = { 8b45a8 0411 c645be00 83f00a 33d2 8845bd 8a45ac }
+ $sequence_8 = { 660f6dec 660fefd8 660f6ccc 0f28a500feffff 0f1118 83c010 0f1007 }
+ $sequence_9 = { 7324 8d0c10 2bf2 894df0 8b4df8 2bca }
condition:
- 7 of them and filesize <219136
+ 7 of them and filesize <172032
}
-rule MALPEDIA_Win_Httpbrowser_Auto : FILE
+rule MALPEDIA_Win_Bandit_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "86ed1f1e-9c83-5189-8446-3be88e9701cf"
+ id = "4242f486-f361-5c1c-837c-874b9d2592eb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.httpbrowser"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.httpbrowser_auto.yar#L1-L178"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bandit"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bandit_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "5b5149262889d64634c3067408a546cd5b0c2e08f2004303b6cf9132eb7eeb82"
+ logic_hash = "e59306c04a92c7c36290cce1b84004757d2fea7b6a860dd6621dd5fc2300ad60"
score = 75
quality = 75
tags = "FILE"
@@ -175556,38 +182609,32 @@ rule MALPEDIA_Win_Httpbrowser_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 ff7508 6a00 53 ffd6 8b45fc 33c9 }
- $sequence_1 = { 50 895de0 ff5604 8945f0 85db 0f8489010000 }
- $sequence_2 = { 33c5 8945fc 53 56 57 8d859cfeffff 33ff }
- $sequence_3 = { 8d85f0fdffff 50 8d85d0f5ffff 50 ff15???????? }
- $sequence_4 = { 56 6a03 6800000040 8d85f4fdffff 50 ff15???????? }
- $sequence_5 = { e8???????? 83c40c 33c0 56 668985c8f3ffff 8d85caf3ffff }
- $sequence_6 = { 83c438 ff15???????? 8d85f4fdffff 50 53 57 }
- $sequence_7 = { ffb5f4edffff 8d85fcfdffff ffb5f8edffff 68???????? 50 }
- $sequence_8 = { e8???????? 68c20ddf13 56 a3???????? e8???????? 83c438 }
- $sequence_9 = { 6a00 6810040000 ff15???????? 8bf0 57 6a0e 56 }
- $sequence_10 = { 83c414 c745ec00000000 68???????? 50 9c b80a000000 51 }
- $sequence_11 = { b905000000 8db524ffffff 8dbda4feffff 8945e4 }
- $sequence_12 = { 33c0 8dbd26ffffff 66899524ffffff f3ab 8955e8 8955f8 8955fc }
- $sequence_13 = { 40 0068ae 224000 50 b822010000 }
- $sequence_14 = { 8895a0c5ffff f3ab aa b91f000000 33c0 8dbd4affffff 66899548ffffff }
- $sequence_15 = { 8b15???????? 8945d8 a1???????? 894ddc 668b0d???????? }
+ $sequence_0 = { e8???????? 488d0d9ca6a100 48894820 833d????????00 750b 488b4c2478 48894828 }
+ $sequence_1 = { c3 4889d0 e8???????? 84c0 744e 488b4c2428 488b11 }
+ $sequence_2 = { 83c301 4883c604 4501f1 e8???????? 4139df 75d6 8b742460 }
+ $sequence_3 = { e9???????? 488d5f01 4839da 731d 4889f0 4889d1 bf01000000 }
+ $sequence_4 = { e8???????? 48c7401801000000 488d0d1c9c5e00 48894810 4889c3 488d0530636a00 488b6c2440 }
+ $sequence_5 = { ffd2 4889442438 48895c2440 48894c2448 48897c2450 90 488b7c2430 }
+ $sequence_6 = { c644242701 488b4210 488b5c2428 488b4c2430 488b7c2438 6690 e8???????? }
+ $sequence_7 = { 8894249d000000 0fb654246c 4129d7 4488bc249e000000 0fb6542474 440fb6442425 4429c2 }
+ $sequence_8 = { e8???????? 4889d7 c60700 488d050e9a6b00 e8???????? 488b4c2438 488b542448 }
+ $sequence_9 = { c604085c 49f7d9 49c1f93f 4c8d5101 4d21ca 4e8d0c10 48f7df }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <29914112
}
-rule MALPEDIA_Win_Micrass_Auto : FILE
+rule MALPEDIA_Win_Bubblewrap_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4db1798a-2c39-50c7-84da-46ea64acd353"
+ id = "72aba578-e67d-518b-a6f8-45bcf7609dfd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.micrass"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.micrass_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bubblewrap"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bubblewrap_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "9dffdea8c321d05076908df0f614e54842a8e7b97f4db09cebeac9dcb66ebdaa"
+ logic_hash = "461e952cc7ab9a2107d029741d486c2b8296d9f39ea5fcdb3208aa0e3f3d47fd"
score = 75
quality = 75
tags = "FILE"
@@ -175601,32 +182648,32 @@ rule MALPEDIA_Win_Micrass_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 59 89442424 8d442408 6a50 }
- $sequence_1 = { 66890c45c4cc4000 40 ebe8 33c0 8945e4 3d01010000 7d0d }
- $sequence_2 = { 8dbdccfdffff a5 a5 a5 a5 }
- $sequence_3 = { 6a06 89430c 8d4310 8d8984194000 5a 668b31 }
- $sequence_4 = { 8d85f8afffff 6a00 50 e8???????? 68???????? 57 e8???????? }
- $sequence_5 = { 53 8985b83fffff 8d85c03fffff 57 50 89bddc9fffff }
- $sequence_6 = { 56 b9???????? 8bf2 2bc8 2bf0 8a1401 }
- $sequence_7 = { 8985e4fbffff 6a05 59 be???????? }
- $sequence_8 = { 50 c744244801010000 e8???????? 59 50 89442414 }
- $sequence_9 = { 8bcb e8???????? 59 837e4400 57 bf???????? }
+ $sequence_0 = { 68???????? 68???????? e8???????? 8b08 83c408 890d???????? 8b5004 }
+ $sequence_1 = { ffd6 8d542464 68???????? 52 ffd6 b900020000 }
+ $sequence_2 = { 56 57 6a02 8d442418 33f6 55 50 }
+ $sequence_3 = { 880c1a 83c9ff f2ae f7d1 49 8d7c1a01 8bd1 }
+ $sequence_4 = { 81ec08020000 53 56 57 ff15???????? }
+ $sequence_5 = { f3a5 6870010000 e8???????? 8d442448 50 6870010000 }
+ $sequence_6 = { 8d6ced00 89542418 c1e503 8bc5 8bdd 25ff030000 }
+ $sequence_7 = { 880f 8810 7c89 5d 5f 5e 5b }
+ $sequence_8 = { c644241f78 c644242011 c644242106 c644242274 }
+ $sequence_9 = { 83c404 a801 740d 8d54240c 52 e8???????? 83c404 }
condition:
- 7 of them and filesize <163840
+ 7 of them and filesize <57136
}
-rule MALPEDIA_Win_Stegoloader_Auto : FILE
+rule MALPEDIA_Win_Nestegg_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e9d6ede2-9401-5de2-b06b-905a99f741c9"
+ id = "01b2e0f8-b92c-591f-a2fe-591e7cf3b6b4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stegoloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stegoloader_auto.yar#L1-L174"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nestegg"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nestegg_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "b778718a0682061dce35a7f47c0081e22977d884e10f4fca4ca7c1e5214e1ed2"
+ logic_hash = "d01d8400ee78b6e2d5585ed1b0eb91726b08169614c693b823bb545acd7b28b3"
score = 75
quality = 75
tags = "FILE"
@@ -175640,38 +182687,32 @@ rule MALPEDIA_Win_Stegoloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f7db 1bdb f7d3 235dfc 3bdf 7409 }
- $sequence_1 = { 4a 75f0 8a043e 46 84c0 7669 0fb6c0 }
- $sequence_2 = { 59 eb32 8bc8 837db806 }
- $sequence_3 = { 59 7422 43 3b5e14 76e2 ff45fc 837dfc02 }
- $sequence_4 = { 0f84f9010000 c645a443 c645a54d c645a644 }
- $sequence_5 = { c645e968 c645ea65 c645eb6c c645ec6c c645ed5f c645ee54 c645ef72 }
- $sequence_6 = { 7415 ff75f4 8bcb ff7604 }
- $sequence_7 = { 8d0481 8b0438 03c7 3bc6 720e 8b4df0 03ce }
- $sequence_8 = { ff742414 8bce ff5004 84c0 }
- $sequence_9 = { 03df 8b03 03c7 33c9 3808 7407 }
- $sequence_10 = { 8d0448 0fb70438 eb07 662b5e10 0fb7c3 8b4e1c }
- $sequence_11 = { 83c604 4b 890411 75db eb0a }
- $sequence_12 = { 33db 56 668945f4 83c002 33f6 3bd3 }
- $sequence_13 = { 7e68 8b4d0c 8b4508 53 56 57 8b7d10 }
- $sequence_14 = { 7409 8b01 6a01 ff10 897d0c }
- $sequence_15 = { 8a4510 f6d8 1bc0 83e004 894510 e8???????? 3bc3 }
+ $sequence_0 = { e8???????? 8d5710 6a02 52 8bce e8???????? }
+ $sequence_1 = { 83c40c 83feff 7417 ffd7 }
+ $sequence_2 = { 8b0d???????? 81c120030000 51 ff15???????? 8b0d???????? 39991c030000 }
+ $sequence_3 = { 83f80e 0f84d8000000 83f80f 7520 8d4c2430 56 }
+ $sequence_4 = { 56 8bf1 89742404 c706???????? 8b8e24030000 c744241000000000 }
+ $sequence_5 = { 85c9 740c 8a09 83e107 8d14c1 89542410 }
+ $sequence_6 = { 8b10 6a10 51 8bc8 885c2458 ff5214 }
+ $sequence_7 = { c644242f6e c644243065 c644243233 884c2433 885c2434 88542435 }
+ $sequence_8 = { c644240d73 884c240e c644240f5f c644241033 }
+ $sequence_9 = { e8???????? 8d4c2410 6a04 51 8bce c7442418ff020001 e8???????? }
condition:
- 7 of them and filesize <802816
+ 7 of them and filesize <221184
}
-rule MALPEDIA_Win_Phoenix_Locker_Auto : FILE
+rule MALPEDIA_Win_Lambert_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "34d54537-0c22-56ee-a952-e063e1672ba8"
+ id = "1c692e32-84a7-5d90-ba02-61a84edfcff0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phoenix_locker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.phoenix_locker_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lambert"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lambert_auto.yar#L1-L166"
license_url = "N/A"
- logic_hash = "30c99eed67f01ec94c0d1a86e9de20b1f5e3b05899cb4448846bf96ce3ca2f7f"
+ logic_hash = "9e5ed22ba49a751e07cf4ea652d26902b7b8b831105840a55340dbe6f75e09b9"
score = 75
quality = 75
tags = "FILE"
@@ -175685,32 +182726,38 @@ rule MALPEDIA_Win_Phoenix_Locker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 480fabc8 48ffc8 4180d05d 488d542420 488b01 66442bc4 }
- $sequence_1 = { b91d692dbc 4d0f45e7 4533c9 e8???????? 4c8b6c2438 4c8d442440 413bc7 }
- $sequence_2 = { 6681942400000000c64d 66c18c2400000000d9 66c184240000000074 e8???????? e2ac 1234ca 99 }
- $sequence_3 = { 4d8d8424b602a3ea 660fbeca 488bcb e9???????? e8???????? 8bd5 498d8c1cb602a3ea }
- $sequence_4 = { e9???????? ff15???????? 33c9 4180fa13 3bc1 0f8417000000 488b4c2468 }
- $sequence_5 = { 68d30f1c2f 4881842430000000bd5eeb17 66c1bc245800000025 4159 415f 4159 4159 }
- $sequence_6 = { 0f8539000000 8d4d39 664181d42122 f9 8d455b 4d63e0 }
- $sequence_7 = { 68d701373c 48818424080000003feaebff 55 c0e254 5a 5a c3 }
- $sequence_8 = { e8???????? 4881842418000000aa78f72a 488b7c2428 48c74424281256ce88 68d72a8642 48c1a42400000000ef 689b25ad02 }
- $sequence_9 = { e8???????? 4155 4151 9c 49b98059c32d64378851 e8???????? 4c0fbbea }
+ $sequence_0 = { 33f2 8b55e8 33ce 33d1 }
+ $sequence_1 = { 4e 8b1f 8919 2bf0 }
+ $sequence_2 = { 3bd8 0f826f010000 8a07 8801 41 47 }
+ $sequence_3 = { 3bd8 0f82a4000000 83fe06 0f822cffffff }
+ $sequence_4 = { 55 8bec 56 8b7510 c1fe04 }
+ $sequence_5 = { 2bc1 3bc7 0f82e5010000 8b4508 2bc2 8d7701 }
+ $sequence_6 = { 33f1 8b4de4 33ce 314de8 }
+ $sequence_7 = { 3b7d10 724d 3bf9 7349 8bc3 2bc1 }
+ $sequence_8 = { 6a00 e8???????? 8945fc 8b45fc 8945f4 8b4df4 8b55f4 }
+ $sequence_9 = { 50 e8???????? 8945e8 8b4de8 3b4d10 750f }
+ $sequence_10 = { 83ec18 8b450c 8b4814 894df0 8b550c 8b4508 }
+ $sequence_11 = { 741f 8b4df8 c1e90d 8b55f8 }
+ $sequence_12 = { ebce 8b45f8 8be5 5d c20400 55 8bec }
+ $sequence_13 = { 8b510c 8b421c 8945f4 8b4df4 894df0 }
+ $sequence_14 = { 3b5118 7334 8b45fc 8b4dec }
+ $sequence_15 = { e8???????? 8945f8 8b4df8 3b4d08 7508 8b55f4 }
condition:
- 7 of them and filesize <3702784
+ 7 of them and filesize <1212416
}
-rule MALPEDIA_Win_Domino_Auto : FILE
+rule MALPEDIA_Win_Comebacker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "eddf3fd4-b67b-5548-8ce8-44ad7e57875e"
+ id = "af10d661-f74a-5650-87c7-273e1e7e9537"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.domino"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.domino_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.comebacker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.comebacker_auto.yar#L1-L159"
license_url = "N/A"
- logic_hash = "bd7ff729d0491d94e0d98300cebe034f3949530bba7c0c3abfe7de162ca0ef3c"
+ logic_hash = "4674cd33cc3ed96f3f2fa7f30959d540c5b651afcce920e84c014122f3c7af23"
score = 75
quality = 75
tags = "FILE"
@@ -175724,32 +182771,37 @@ rule MALPEDIA_Win_Domino_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b940000000 488bd8 ff15???????? 4c63c3 }
- $sequence_1 = { 8bc6 4881c470010000 415f 415e 415d 415c }
- $sequence_2 = { 41b800300000 488bd6 33c9 4c8bf6 ff15???????? }
- $sequence_3 = { 498bd0 492bc8 4963c1 4c8d1d622e0000 428a0418 320411 }
- $sequence_4 = { 7d07 ffc8 83c8f0 ffc0 48ffc2 }
- $sequence_5 = { 4889742410 57 4883ec20 4863fa 488bf1 4885c9 750e }
- $sequence_6 = { 488b1a 488bfa 488bf1 8b13 488bce e8???????? }
- $sequence_7 = { 895c2420 66899c24b0000000 ff15???????? 85c0 741a 488b4c2458 }
- $sequence_8 = { 7f20 488b0b 4885c9 7406 ff15???????? 48832300 83c8ff }
- $sequence_9 = { e8???????? 4533c9 448bc7 488bd6 488bcb e8???????? 488b5c2438 }
+ $sequence_0 = { 6683f809 7f04 0430 eb02 }
+ $sequence_1 = { 4c8d0d7ad60300 8d5049 8d48e0 448d4013 c7442420bb020000 e8???????? }
+ $sequence_2 = { 41894704 418bc4 48c1e810 0fb6c8 418bc0 0fb6943170e30400 }
+ $sequence_3 = { 4c8d0dc2a10300 8d5078 8d4803 448d4041 }
+ $sequence_4 = { 4c8d9db0070000 488d8580020000 4c895c2440 89742438 4489742430 }
+ $sequence_5 = { 3241ff 48ffca 88440bff 75ed 488bfe }
+ $sequence_6 = { 4c8d0daf4d0300 baca000000 b910000000 e8???????? 488bcf }
+ $sequence_7 = { 4c89ac2408290300 664489b5a0050000 e8???????? 488d8d92030000 }
+ $sequence_8 = { ff15???????? 83bdc4f8ffff00 741c 68???????? e8???????? 69c0e8030000 83c404 }
+ $sequence_9 = { c74424183ba7ca84 c744241c85ae67bb c74424202bf894fe c744242472f36e3c }
+ $sequence_10 = { 8a44242a 8b1c8d38640410 8b048538600410 8bca 33c3 }
+ $sequence_11 = { 8d1433 52 50 ff15???????? 85c0 0f8435ffffff 8b15???????? }
+ $sequence_12 = { 68???????? 52 ffd7 8d85fcf7ffff 83c408 8d5002 668b08 }
+ $sequence_13 = { 83f906 0f87c1000000 ff248d302a0210 8b4810 85c9 74d6 8b490c }
+ $sequence_14 = { 8b8dacfeffff 51 e8???????? 8b9db0feffff }
condition:
- 7 of them and filesize <50176
+ 7 of them and filesize <1429504
}
-rule MALPEDIA_Win_Satellite_Turla_Auto : FILE
+rule MALPEDIA_Win_Cryptbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "79b83503-3c79-5740-8814-f6490a13be5c"
+ id = "1c6d7eb4-b0bc-5398-a1c7-a56c78dd600a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.satellite_turla"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.satellite_turla_auto.yar#L1-L160"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptbot_auto.yar#L1-L150"
license_url = "N/A"
- logic_hash = "5508d48c958832fbb5bd1d9983eb0158b4a79197acb610f43056e5475e8173ec"
+ logic_hash = "09f972034d92b74b2b134cacc0a51ffba015046eb0d41dcfb99ea848a8d7ad71"
score = 75
quality = 75
tags = "FILE"
@@ -175763,38 +182815,37 @@ rule MALPEDIA_Win_Satellite_Turla_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0105???????? 81c3b0020000 2945e0 75ae 837dd400 }
- $sequence_1 = { 51 8d9514fbffff 52 a1???????? }
- $sequence_2 = { 0108 833e00 7fc7 db46fc }
- $sequence_3 = { 0105???????? 83c410 29442418 75a9 }
- $sequence_4 = { 0108 833e00 7c1f 8b542410 }
- $sequence_5 = { 0105???????? 83c410 29442420 75aa }
- $sequence_6 = { 0108 833a00 7c23 8b442428 }
- $sequence_7 = { 0108 833e00 7cc7 7e39 }
- $sequence_8 = { c645da14 c645db14 e8???????? 83c40c 8d45d0 }
- $sequence_9 = { c645de47 c645df5b c645e04d c645e160 c645e249 c645e346 c645e44c }
- $sequence_10 = { 6a0a 50 e8???????? 83c40c 8d45f4 885dfd 50 }
- $sequence_11 = { 8d7da0 f3ab 8d459c 50 ff15???????? }
- $sequence_12 = { 3bf8 72ee 6880000000 56 ff15???????? }
- $sequence_13 = { c645ac05 c645ad07 c645ae07 c645af0b c645b004 c645b10e c645b226 }
- $sequence_14 = { 7506 46 47 3bf8 }
- $sequence_15 = { 6a55 8d45b8 6a0c 50 c645b816 }
+ $sequence_0 = { 33c0 85ed 0f94c0 8be8 }
+ $sequence_1 = { 33c0 eb0a b917d90000 e8???????? }
+ $sequence_2 = { e9???????? b949dc0000 e9???????? b944dc0000 e9???????? b964dc0000 }
+ $sequence_3 = { e8???????? 85c0 750c b961030200 e8???????? }
+ $sequence_4 = { 0f9cc0 eb02 32c0 84c0 }
+ $sequence_5 = { eb0c b99fed0000 e8???????? 8907 }
+ $sequence_6 = { e8???????? 85c0 750e b9ca070200 e8???????? 8bc8 }
+ $sequence_7 = { e8???????? 85c0 750f b955960100 e8???????? e9???????? }
+ $sequence_8 = { 744e 0fb74802 83e103 3bcb }
+ $sequence_9 = { 750b 8bce e8???????? 8b4c2428 }
+ $sequence_10 = { 7508 85f6 7404 c6464101 5e c3 }
+ $sequence_11 = { 7518 8b542414 83c718 8bcd }
+ $sequence_12 = { 7409 33d2 e8???????? 8bf8 43 }
+ $sequence_13 = { 2403 80e110 8ad1 3c02 7509 }
+ $sequence_14 = { 751f 8bd5 8bce e8???????? }
condition:
- 7 of them and filesize <1040384
+ 7 of them and filesize <11116544
}
-rule MALPEDIA_Win_Saint_Bot_Auto : FILE
+rule MALPEDIA_Win_Karma_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "714c3147-1158-5cc4-a0a2-d44deb9955a4"
+ id = "7f63a996-b29b-562f-996a-826393522cf0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.saint_bot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.saint_bot_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.karma"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.karma_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "74c58e6c0a61984f0e7d1e5e39218efbc9c3b95b70a89e37e515f61493396398"
+ logic_hash = "2f60ce68960b60e178a1e413eabfae876f08564938fc3ab9af48ba4bf8caac6e"
score = 75
quality = 75
tags = "FILE"
@@ -175808,32 +182859,32 @@ rule MALPEDIA_Win_Saint_Bot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85f6 7432 837d10ff 7405 3b5d10 744f 6a04 }
- $sequence_1 = { 894df8 894dec ff15???????? 8d45ec 50 8d45f8 50 }
- $sequence_2 = { 668945e8 83c002 668945ea 8d45e0 8945d0 }
- $sequence_3 = { c3 55 8bec 8b550c 53 0fb71a 6685db }
- $sequence_4 = { 6a78 68f0000000 b800000080 50 50 680000cf00 }
- $sequence_5 = { 85c0 0f84c7000000 85ff 7404 c6043800 }
- $sequence_6 = { 58 6a63 668945cc 58 6a30 }
- $sequence_7 = { 56 57 e8???????? ff75f0 56 57 e8???????? }
- $sequence_8 = { 57 ff15???????? 56 6880000000 6a02 56 }
- $sequence_9 = { 8bf0 ff15???????? 6a00 6a06 56 6a04 50 }
+ $sequence_0 = { 8b7f08 8bc7 d3e8 8b4d08 }
+ $sequence_1 = { 8bf9 8955f0 33c0 663907 7408 40 66833c4700 }
+ $sequence_2 = { 0f1006 0f114318 e8???????? 5f }
+ $sequence_3 = { ebc5 33ff 6690 0fb78ffc434000 }
+ $sequence_4 = { ff15???????? 6a00 8d442444 50 6800710200 }
+ $sequence_5 = { 660fefc8 0f1148f0 83e901 75e7 8d55e0 }
+ $sequence_6 = { 894dfc 894dc0 894dc4 894dc8 894dcc }
+ $sequence_7 = { 8b4c2418 8b44241c 83c140 6a00 6a00 83d000 }
+ $sequence_8 = { 8d4e20 0f47ce 2bca 750e 6685db 0f84c5000000 }
+ $sequence_9 = { 66833c45f051400000 75f4 33d2 663915???????? 7415 660f1f840000000000 }
condition:
- 7 of them and filesize <93184
+ 7 of them and filesize <49208
}
-rule MALPEDIA_Win_Ave_Maria_Auto : FILE
+rule MALPEDIA_Win_Bundestrojaner_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "410b5f16-91ac-5311-b6ab-598dd1954c39"
+ id = "f8dcad82-5285-5492-8b50-3aca915a7d86"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ave_maria"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ave_maria_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bundestrojaner"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bundestrojaner_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "d6a2fe1f05fe69e9ea5ce04e4093200d3e962df5b8f3c4c00fc93efedbc85567"
+ logic_hash = "14c57bb4c31bed67bf98bb86f0286f3377181b876957cd1f8d67f51314c230ea"
score = 75
quality = 75
tags = "FILE"
@@ -175847,34 +182898,34 @@ rule MALPEDIA_Win_Ave_Maria_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b07 ff740610 8d4614 50 8d45f8 50 }
- $sequence_1 = { 52 8b08 6a01 50 ff510c 85c0 74c1 }
- $sequence_2 = { 6a0a 03c1 59 8bf8 f3a5 8d4d30 }
- $sequence_3 = { 0f57c0 c745e015000000 50 8d4de0 0f1145e8 e8???????? 8bc8 }
- $sequence_4 = { 803800 7509 33c0 5b c3 33c0 40 }
- $sequence_5 = { 8bc7 99 2bc1 8bcf 1bd6 52 50 }
- $sequence_6 = { ff500c 8b06 68???????? ff37 8b08 }
- $sequence_7 = { 51 54 8bce e8???????? 8b4d08 e8???????? 83c410 }
- $sequence_8 = { 300431 41 3bcf 7ced 5f 8bc6 5e }
- $sequence_9 = { 83ec18 53 8bd9 56 57 895df8 }
+ $sequence_0 = { 894c2414 33ff 85c0 897c2410 741f 47 d1f8 }
+ $sequence_1 = { 3bc8 7cc3 8b5608 8b4e70 d9442460 42 897e04 }
+ $sequence_2 = { 50 8d55fc 51 52 e8???????? 8b87c0000000 b980000000 }
+ $sequence_3 = { 56 8b742438 57 8b7c242c 8bc7 c744241000000000 }
+ $sequence_4 = { 8b4e34 8d1482 52 50 8b460c 50 51 }
+ $sequence_5 = { 83c420 8b5104 85d2 0f95c2 83f806 885114 }
+ $sequence_6 = { d9c9 d959fc 3b5610 7cdb ddd8 8b4610 8b5c2418 }
+ $sequence_7 = { 75fb 83fe0b 7e15 8b442414 50 8b08 c7411406000000 }
+ $sequence_8 = { 8d54241c 89442420 8b44240c 6a00 52 6a00 }
+ $sequence_9 = { dd1c24 e8???????? 83c408 e8???????? 85c0 8944241c 7d04 }
condition:
- 7 of them and filesize <237568
+ 7 of them and filesize <729088
}
-rule MALPEDIA_Win_Hookinjex_Auto : FILE
+rule MALPEDIA_Win_Powershellrunner_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "cc81917a-8c1e-59eb-8738-a94445516bc1"
+ id = "52f34db7-4f5a-5a7d-b993-5b0a17757274"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hookinjex"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hookinjex_auto.yar#L1-L148"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.powershellrunner"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.powershellrunner_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "afb96fa06c3548b099102aa92aa51777edafb1bb6fe4920aba390d45066ccc62"
- score = 60
- quality = 25
+ logic_hash = "c0bbeb809fa33bde57fda2fd6bac480ecf51cfd19b2b4c46994cda378bb784a0"
+ score = 75
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -175886,38 +182937,32 @@ rule MALPEDIA_Win_Hookinjex_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 85c0 740c b913e40000 }
- $sequence_1 = { e8???????? b964000000 ff15???????? 0fb705???????? }
- $sequence_2 = { e8???????? 85c0 7507 b80e000000 }
- $sequence_3 = { e9???????? 488b4c2458 e8???????? 488b4c2450 }
- $sequence_4 = { e8???????? b95b730100 e8???????? e9???????? }
- $sequence_5 = { e8???????? 85c0 750f b9dc550100 }
- $sequence_6 = { e8???????? 833d????????00 7411 b903000000 e8???????? }
- $sequence_7 = { e8???????? 85c0 7408 803b00 }
- $sequence_8 = { 48817c243000100000 0f82dc020000 488b442460 4889442438 }
- $sequence_9 = { 2500180000 3d00080000 750d c78424e800000001000000 eb0b }
- $sequence_10 = { 25001b0000 3d00100000 750a c744244401000000 }
- $sequence_11 = { 25001b0000 3d00110000 750d c784243c01000001000000 }
- $sequence_12 = { 25001b0000 3d00100000 750d c784242401000001000000 }
- $sequence_13 = { 2500180000 3d00180000 750a c744247c01000000 }
- $sequence_14 = { 25001b0000 3d00110000 750a c744245c01000000 }
- $sequence_15 = { 48817c243800100000 0f82f5000000 488b442438 4883c02f }
+ $sequence_0 = { 4889442440 488b442420 488b8c2498000000 482bc8 488bc1 4c8bc0 488b542440 }
+ $sequence_1 = { 488d4c2448 e8???????? 0fb6c0 85c0 7439 }
+ $sequence_2 = { 668984240e020000 b828000000 6689842410020000 b828000000 6689842412020000 b867000000 6689842414020000 }
+ $sequence_3 = { 488bcd 488d1529b20100 83e13f 488bc5 48c1f806 48c1e106 48030cc2 }
+ $sequence_4 = { 6689842488000000 b865000000 668984248a000000 b872000000 668984248c000000 b86e000000 668984248e000000 }
+ $sequence_5 = { 4833c4 4889842428010000 48c744245800000000 48c744246800000000 c744244c00000000 c744244800000000 b853000000 }
+ $sequence_6 = { f30f6f0f 4883f80e 7773 8b848654da0100 4803c6 ffe0 }
+ $sequence_7 = { e8???????? 4889442458 488b8c2490000000 e8???????? 4889442448 }
+ $sequence_8 = { 48894c2408 48b8ffffffffffffff1f c3 48894c2408 48b8ffffffffffffff3f c3 4c894c2420 }
+ $sequence_9 = { 4c8d0df9b30000 488be9 4c8d05e7b30000 488d15e8b30000 b914000000 e8???????? 4885c0 }
condition:
- 7 of them and filesize <6545408
+ 7 of them and filesize <458752
}
-rule MALPEDIA_Win_Sysget_Auto : FILE
+rule MALPEDIA_Win_Dharma_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "950c6328-1de5-5d85-b009-d36eceeda441"
+ id = "e57e8a97-3ba4-55fc-8a7a-2d2cd02d04a4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sysget"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sysget_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dharma"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dharma_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "98d11ad376be93c301b2c1f8309ca9e93b58254eeadefcb865a1a57e18934a28"
+ logic_hash = "7cad44063f19785eb5f21218749fc586efdec21afeaf1b9147edb5d8331036bc"
score = 75
quality = 75
tags = "FILE"
@@ -175931,32 +182976,32 @@ rule MALPEDIA_Win_Sysget_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 56 6a20 8d45cc 50 53 53 }
- $sequence_1 = { f3a5 33f6 8d4435f0 8a08 f6d1 80f15f }
- $sequence_2 = { 58 6a00 ff15???????? 6a01 8d85ecf9ffff 50 8d85ecf1ffff }
- $sequence_3 = { 8985c8f9ffff 83c032 50 66a5 e8???????? 83c428 }
- $sequence_4 = { 33f6 8d4435f0 8a08 f6d1 80f15f 46 }
- $sequence_5 = { 75f5 8dbdecfeffff 2bc2 83ef02 668b4f02 83c702 6685c9 }
- $sequence_6 = { 83c424 6800010000 ffb5f8feffff c1e306 8d841dfcfeffff 50 ff15???????? }
- $sequence_7 = { 6a50 68???????? 50 ff15???????? a3???????? a1???????? }
- $sequence_8 = { 51 ff36 897d0c 50 53 }
- $sequence_9 = { 8d459c 50 56 56 6a20 53 }
+ $sequence_0 = { 8945e8 8b45ec 8b4808 8b55ec }
+ $sequence_1 = { 8b4824 8b5508 8b4218 8d0c48 51 68ff7f0000 }
+ $sequence_2 = { 68???????? 6a00 6a00 e8???????? eb0e 8b4dfc 51 }
+ $sequence_3 = { 8b45e4 034530 8945e4 8b4dfc 034d30 894dfc 6a06 }
+ $sequence_4 = { a1???????? 898574ffffff 6880000000 68???????? 8b8d74ffffff 51 68???????? }
+ $sequence_5 = { 8945fc 8b4d08 0fb711 d1fa 8955e0 8b45f8 c1e818 }
+ $sequence_6 = { 741a 8b5508 83c22c 8b4dfc 8b8108000100 }
+ $sequence_7 = { 8b0c85b8bf4000 81e10000ff00 33d1 8b45f4 }
+ $sequence_8 = { d1f8 8d4c0002 51 e8???????? 83c404 8b55ec 8b4a08 }
+ $sequence_9 = { 8b55f4 83c201 8955f4 eba3 8b45f8 50 e8???????? }
condition:
- 7 of them and filesize <352256
+ 7 of them and filesize <204800
}
-rule MALPEDIA_Win_Mapiget_Auto : FILE
+rule MALPEDIA_Win_Locky_Decryptor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "51e9978a-f3a2-5a57-b2db-e31705d960d6"
+ id = "7272c171-5952-5404-84f8-64d1272487e9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mapiget"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mapiget_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.locky_decryptor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.locky_decryptor_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "0c633dd4b3de0327e913721fdea6a98365647ad6509020036346423432ca814a"
+ logic_hash = "608b3ec7b9a67c8bdfea65d7f94d3ac9056bb8fb93478235380693008ad0bb57"
score = 75
quality = 75
tags = "FILE"
@@ -175970,32 +183015,32 @@ rule MALPEDIA_Win_Mapiget_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 773c 33d2 8a9178154000 ff24956c154000 6683780400 }
- $sequence_1 = { 75f4 8d0c49 5e 8d0c8dd8ea4000 3bc1 }
- $sequence_2 = { 52 e8???????? 83c404 6683bc456effffff0a 7517 8d8570ffffff }
- $sequence_3 = { 8d95f0f9ffff 6800020000 52 e8???????? 83c40c 85c0 0f84c1010000 }
- $sequence_4 = { 741e 8bc7 8bcf c1f805 83e11f 8b048520174100 8d04c8 }
- $sequence_5 = { e8???????? 8b54240c 83c408 52 }
- $sequence_6 = { 8d85f0feffff 8d8d70ffffff 50 8d95f0fdffff }
- $sequence_7 = { 85c0 7520 8d8df0f9ffff 8d95f0fdffff 51 52 }
- $sequence_8 = { 83c404 3bf7 0f846bfdffff 56 }
- $sequence_9 = { c705????????0d000000 c3 8b04d5540c4100 a3???????? c3 81f9bc000000 }
+ $sequence_0 = { 8d7c2420 c684249000000001 e8???????? 6a01 33ff }
+ $sequence_1 = { 56 6a5c 8bf0 e8???????? }
+ $sequence_2 = { 58 33db 33c9 8945e0 }
+ $sequence_3 = { 8d45e0 50 33ff 6880000000 897dc0 ff15???????? 50 }
+ $sequence_4 = { 66890e 56 8d8ddcfbffff e8???????? 8bc6 }
+ $sequence_5 = { 50 e8???????? 8364247800 56 50 8d442420 }
+ $sequence_6 = { 68???????? 8d8504ffffff e9???????? 015ddc 6a00 5b }
+ $sequence_7 = { 56 e8???????? 8b4df4 83c40c 5f 5e 8bc3 }
+ $sequence_8 = { 894c2410 3bda 7e6c 33d2 c7442418f0ffffff }
+ $sequence_9 = { ff15???????? c745fc0a000000 395de4 740f }
condition:
- 7 of them and filesize <163840
+ 7 of them and filesize <278528
}
-rule MALPEDIA_Win_Powershellrunner_Auto : FILE
+rule MALPEDIA_Win_Duuzer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "52f34db7-4f5a-5a7d-b993-5b0a17757274"
+ id = "df8c3768-3cdc-5b0e-a660-661bdb978bfa"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.powershellrunner"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.powershellrunner_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.duuzer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.duuzer_auto.yar#L1-L145"
license_url = "N/A"
- logic_hash = "c0bbeb809fa33bde57fda2fd6bac480ecf51cfd19b2b4c46994cda378bb784a0"
+ logic_hash = "13aac089d76bc4f63a9fe69893726cbd97eb78875b3161a00634aa641d0ec8d3"
score = 75
quality = 75
tags = "FILE"
@@ -176009,32 +183054,37 @@ rule MALPEDIA_Win_Powershellrunner_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4889442440 488b442420 488b8c2498000000 482bc8 488bc1 4c8bc0 488b542440 }
- $sequence_1 = { 488d4c2448 e8???????? 0fb6c0 85c0 7439 }
- $sequence_2 = { 668984240e020000 b828000000 6689842410020000 b828000000 6689842412020000 b867000000 6689842414020000 }
- $sequence_3 = { 488bcd 488d1529b20100 83e13f 488bc5 48c1f806 48c1e106 48030cc2 }
- $sequence_4 = { 6689842488000000 b865000000 668984248a000000 b872000000 668984248c000000 b86e000000 668984248e000000 }
- $sequence_5 = { 4833c4 4889842428010000 48c744245800000000 48c744246800000000 c744244c00000000 c744244800000000 b853000000 }
- $sequence_6 = { f30f6f0f 4883f80e 7773 8b848654da0100 4803c6 ffe0 }
- $sequence_7 = { e8???????? 4889442458 488b8c2490000000 e8???????? 4889442448 }
- $sequence_8 = { 48894c2408 48b8ffffffffffffff1f c3 48894c2408 48b8ffffffffffffff3f c3 4c894c2420 }
- $sequence_9 = { 4c8d0df9b30000 488be9 4c8d05e7b30000 488d15e8b30000 b914000000 e8???????? 4885c0 }
+ $sequence_0 = { 83f804 7408 83c8ff e9???????? }
+ $sequence_1 = { 0145f0 1155f4 85c9 7533 }
+ $sequence_2 = { 57 4154 4155 4881ec88080000 488b05???????? 4833c4 }
+ $sequence_3 = { 00f4 c640001c c740008a460323 d188470383ee }
+ $sequence_4 = { 56 57 b830910000 e8???????? }
+ $sequence_5 = { 56 57 b8a0010100 e8???????? }
+ $sequence_6 = { 56 57 488dac2410fcffff 4881ecf0040000 }
+ $sequence_7 = { 01442410 3bfb 75c4 8b4630 }
+ $sequence_8 = { 57 4154 4883ec20 448be2 }
+ $sequence_9 = { 57 4154 4155 4156 4883ec30 488b05???????? }
+ $sequence_10 = { 014dec 83bf8400000000 7708 398780000000 }
+ $sequence_11 = { 57 4154 4155 4883ec20 33f6 488bd9 }
+ $sequence_12 = { 014dec 66837dec00 0f8efc010000 0fbf45ec }
+ $sequence_13 = { 00e0 3541000436 41 0023 }
+ $sequence_14 = { 010b 014e4c 014e48 014e54 }
condition:
- 7 of them and filesize <458752
+ 7 of them and filesize <491520
}
-rule MALPEDIA_Win_5T_Downloader_Auto : FILE
+rule MALPEDIA_Win_Sysraw_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fe4393a3-e3cd-5e60-a348-fa50df874e7a"
+ id = "a9e810a6-264f-569e-b3d3-a9931864293b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.5t_downloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.5t_downloader_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sysraw_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sysraw_stealer_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "708a5991b6f83db848239b1110cc9bc587325f0c0450305b55a83b6de5bbd18e"
+ logic_hash = "a25f6b3ba819f069101fb648f9516e51ed0f5298199445e1b66fa7cef9e138d8"
score = 75
quality = 75
tags = "FILE"
@@ -176048,32 +183098,32 @@ rule MALPEDIA_Win_5T_Downloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7409 83781800 7403 5d }
- $sequence_1 = { 85c9 7409 83781800 7403 5d }
- $sequence_2 = { 85c9 7409 83781800 7403 }
- $sequence_3 = { 85c0 7416 83781400 7510 }
- $sequence_4 = { 85c9 7409 83781800 7403 5d ffe1 83c8ff }
- $sequence_5 = { 8b4508 85c0 7416 83781400 7510 }
- $sequence_6 = { 55 8bec 8b4508 85c0 7416 83781400 7510 }
- $sequence_7 = { 85c9 7409 83781800 7403 5d ffe1 }
- $sequence_8 = { 7409 83781800 7403 5d ffe1 83c8ff }
- $sequence_9 = { 8bec 8b4508 85c0 7416 83781400 7510 }
+ $sequence_0 = { 50 8d9504ffffff 51 8d8508ffffff 52 8d8d0cffffff }
+ $sequence_1 = { ffd6 a1???????? ba???????? 8b4814 c1e102 8bf9 8b480c }
+ $sequence_2 = { 51 89558c ffd7 8b558c f7d8 1bc0 f7d8 }
+ $sequence_3 = { 7507 c745ec01000000 8b4514 8b7de8 2bc7 6800000040 }
+ $sequence_4 = { ff15???????? 8b4dc0 894dd4 8d55c4 52 }
+ $sequence_5 = { c7400807000000 c7400c0f000000 c740101f000000 c740143f000000 c740187f000000 }
+ $sequence_6 = { 89bde0feffff ffd6 8b3d???????? 50 }
+ $sequence_7 = { c7420485ae67bb 8b4590 c7400872f36e3c 8b4d90 c7410c3af54fa5 }
+ $sequence_8 = { 53 56 57 8bd0 8bf1 8bf8 8bd9 }
+ $sequence_9 = { 8975c8 8975b8 8975a8 ff15???????? 8b45d0 8975cc 50 }
condition:
- 7 of them and filesize <539648
+ 7 of them and filesize <1540096
}
-rule MALPEDIA_Win_Mistcloak_Auto : FILE
+rule MALPEDIA_Win_Deathransom_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bcb29aaa-c37e-5c55-be1e-5d06aa41cabd"
+ id = "4e39de37-0fee-5b21-a4db-fc348269215e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mistcloak"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mistcloak_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.deathransom"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.deathransom_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "6962ced189f702e03fc18d236cee46a2a0844476537e8c819ea6f1c43f9c0922"
+ logic_hash = "8362ae87c1f20555b6e75c6240bf76604d10b1d1a7af4c90e341b81be4a45543"
score = 75
quality = 75
tags = "FILE"
@@ -176087,32 +183137,32 @@ rule MALPEDIA_Win_Mistcloak_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b049590500110 f644082801 740b 56 e8???????? 59 8bf0 }
- $sequence_1 = { 660f282d???????? 660f59f5 660f28aa70100110 660f54e5 660f58fe 660f58fc }
- $sequence_2 = { 8b0c8590500110 8b45f8 807c012800 7d46 }
- $sequence_3 = { 0f85b1000000 8b4508 dd00 ebc2 c745e418120110 eb19 }
- $sequence_4 = { 6bc618 57 8db8104e0110 57 }
- $sequence_5 = { 7429 83e805 7415 83e801 0f8595010000 c745e408120110 }
- $sequence_6 = { c745e408120110 e9???????? c745e404120110 e9???????? 894de0 c745e404120110 e9???????? }
- $sequence_7 = { 85f6 7420 6bc618 57 8db8104e0110 57 }
- $sequence_8 = { 8bc1 3914c5781a0110 7408 40 }
- $sequence_9 = { 8b45b4 8b0c8590500110 8a043b 03ce 8b75dc 03cb 43 }
+ $sequence_0 = { 8b55d8 33c3 03c1 81c216c1a419 03d0 8bcf 0155ec }
+ $sequence_1 = { 03d1 c1c007 0355a8 8bcf c1c90b 33c8 8955d8 }
+ $sequence_2 = { 742d 8b45f8 ba20000000 2bd6 8bca d3e8 8bce }
+ $sequence_3 = { 0f8278010000 8b5df4 8d4dd8 56 8bd3 837b0400 }
+ $sequence_4 = { c3 83f802 7546 6820020000 6a08 c745fc20020000 ff15???????? }
+ $sequence_5 = { 8d8d90fdffff e8???????? 8d8d90fdffff e8???????? 8d8d90fdffff e8???????? 6a50 }
+ $sequence_6 = { 0b7de4 237ddc 8b55f4 0bf8 897de0 8bc6 014de0 }
+ $sequence_7 = { 8b45dc 8bc8 0155e8 c1c00a }
+ $sequence_8 = { 85c9 0f95c0 2bc8 33c0 c1e905 }
+ $sequence_9 = { c1e810 884311 8bc1 c1e808 884312 884b13 8b4f1c }
condition:
- 7 of them and filesize <196608
+ 7 of them and filesize <133120
}
-rule MALPEDIA_Win_Orpcbackdoor_Auto : FILE
+rule MALPEDIA_Win_Rising_Sun_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "605ecf11-b36e-51cd-8e37-c406fe5ee743"
+ id = "61449700-41c3-5e72-bc5d-1e423597afa4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.orpcbackdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.orpcbackdoor_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rising_sun"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rising_sun_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "a975ab0f24495978f9e8b667b3f6b02066e8ac424646b3588e19f69238c5dbdd"
+ logic_hash = "76c0e1eaf3dacaaaa1a31e893606959ffd6d8a46f21e1d7c2864ee68d388c2cb"
score = 75
quality = 75
tags = "FILE"
@@ -176126,32 +183176,32 @@ rule MALPEDIA_Win_Orpcbackdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b45fc 83e818 50 e8???????? 59 59 }
- $sequence_1 = { 59 ffb5e4f6feff ffb568f5feff 8d8594f9ffff 50 e8???????? 83c40c }
- $sequence_2 = { 6a0c 59 be???????? 8dbdc0faffff f3a5 66a5 a4 }
- $sequence_3 = { 8b45c4 0fbe00 83f87f 7452 8b45c4 0fbe00 85c0 }
- $sequence_4 = { 753e 8b45c8 40 40 3b4524 7734 8b4520 }
- $sequence_5 = { 83a5b0fdffff00 8d85b0fdffff 50 6a02 8b85b4fdffff 8b00 ffb5b4fdffff }
- $sequence_6 = { 8841fd eb0e a1???????? 0345f4 c640fd00 eb05 }
- $sequence_7 = { 6a01 6a40 6a01 6a01 8d8da8fcfeff e8???????? 50 }
- $sequence_8 = { 3c5a 7712 0fbec1 83e820 83e07f 8a044589700310 }
- $sequence_9 = { 0fbe4001 83f858 7508 8b45c4 40 40 }
+ $sequence_0 = { c745b03414d384 c745b418f4ff64 c745b851d4c644 c745bcabb43c24 c745c099945804 c745c4c4746ce4 c745c8dd544ec4 }
+ $sequence_1 = { 4889742418 48897c2420 55 488dac24a0e4ffff b8601c0000 }
+ $sequence_2 = { c745dcd3515290 c745e00358c000 c745e4c80ae51e c745e804d34ed7 c745ec3e3054ad c745f046c2e664 c745f418a189fe }
+ $sequence_3 = { c785100200000358c000 c78514020000c80ae51e c7851802000004d34ed7 c7851c0200003e3054ad c7852002000046c2e664 }
+ $sequence_4 = { e8???????? 48898588000000 488d05c298feff 4883c420 }
+ $sequence_5 = { c78514020000c80ae51e c7851802000004d34ed7 c7851c0200003e3054ad c7852002000046c2e664 c7852402000018a189fe c7852802000003f29cea c7852c0200000bbce179 }
+ $sequence_6 = { c785440600001def57f7 c785480600003bf5679d c7854c0600000989ec8d c78550060000fd9e1cf3 66c785540600002657 664489ad60060000 e8???????? }
+ $sequence_7 = { 4c8d41ff 488bce e8???????? 488b542450 b89fffffff }
+ $sequence_8 = { 660f1f440000 0fb602 48ffc2 88440aff 84c0 75f2 }
+ $sequence_9 = { e8???????? cc 48895c2408 48896c2418 56 57 4154 }
condition:
- 7 of them and filesize <918528
+ 7 of them and filesize <409600
}
-rule MALPEDIA_Win_Explosive_Rat_Auto : FILE
+rule MALPEDIA_Win_Fatduke_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "863a5681-ec58-58c3-aa41-9d8844c2c73c"
+ id = "1df82884-dd37-5110-97a3-f389ea498843"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.explosive_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.explosive_rat_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fatduke"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fatduke_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "e75d842c394fc045ddd0745106b1430d3dd968c3b7d21e3af7bbb4c3b56a96a4"
+ logic_hash = "40661bdfa7c29a9f9d4cfc7da5ee8f1460f5e36e7c11bd94001d922b76261842"
score = 75
quality = 75
tags = "FILE"
@@ -176165,34 +183215,34 @@ rule MALPEDIA_Win_Explosive_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8945c4 8b4514 8945c8 7611 33c0 8a03 8d4dc4 }
- $sequence_1 = { 7445 6a03 8bc7 e8???????? 8b8648af0100 8bae44af0100 83c00a }
- $sequence_2 = { 66832300 33c0 c9 c3 85c0 7515 }
- $sequence_3 = { eb60 807e0400 7507 8bce e8???????? 807e0530 7c62 }
- $sequence_4 = { 53 55 8b6c2448 8b4d04 8b4104 56 8bf1 }
- $sequence_5 = { 85ed 75e5 83f808 896b14 720f 8b4304 5f }
- $sequence_6 = { 68???????? 51 e8???????? 8b4c2468 8b7c245c 50 8b442470 }
- $sequence_7 = { 8b442430 83c408 3bc7 720d 8b4c2414 51 e8???????? }
- $sequence_8 = { 8d5dd0 e8???????? 46 ebb8 b8???????? e8???????? be???????? }
- $sequence_9 = { 89ae88af0600 8bfa 7d2e 8a5c0aff 8a140a 885c241c 8854240f }
+ $sequence_0 = { 807b0d00 7552 ff7608 8bc8 e8???????? 8b36 8d7b10 }
+ $sequence_1 = { 8bcb 85f6 7455 83ee04 7211 8b01 3b02 }
+ $sequence_2 = { ff75f0 c746140f000000 c7461000000000 c60600 e8???????? 8b4b04 83c404 }
+ $sequence_3 = { e8???????? c745c000000000 c745c400000000 c745c40f000000 c745c000000000 c645b000 3bc1 }
+ $sequence_4 = { e8???????? 83c404 c745bc0f000000 c745b800000000 c645a800 c745fcffffffff 837dec10 }
+ $sequence_5 = { c7864c01000000000000 c6863c01000000 c645fc0b 83be3801000010 720e ffb624010000 e8???????? }
+ $sequence_6 = { f7d3 23da 7419 2bf9 8bff 8a040f 8d4901 }
+ $sequence_7 = { 83ec1c a1???????? 33c5 8945fc 8b4508 8b4910 8945e4 }
+ $sequence_8 = { 8d4e08 51 e8???????? c745fcffffffff 8bc6 8b4df4 64890d00000000 }
+ $sequence_9 = { ff75c0 e8???????? 83c404 c745d40f000000 8ac3 c745d000000000 c645c000 }
condition:
- 7 of them and filesize <855040
+ 7 of them and filesize <9012224
}
-rule MALPEDIA_Win_Sality_Auto : FILE
+rule MALPEDIA_Win_Tmanger_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c4fe3bef-4213-5d7d-913a-2b05b77a4928"
+ id = "78f3e107-dd73-5ac6-8162-9004595db040"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sality"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sality_auto.yar#L1-L213"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tmanger"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tmanger_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "0193eaeac2f20f17789979ee8ced6eebd2afd20c9546863e594d136342d3a2ff"
+ logic_hash = "3ce75b695b98335702f80c133e38f084863185b63bd0e2de7bf59d414a1dae17"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -176204,46 +183254,32 @@ rule MALPEDIA_Win_Sality_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0302 50 6878563412 e8???????? }
- $sequence_1 = { 0255fc 8855ec 8b45ec 25ff000000 }
- $sequence_2 = { 02040a 8845fc 8b4dfc 81e1ff000000 }
- $sequence_3 = { 0302 50 6a00 e8???????? }
- $sequence_4 = { 837da000 751b 8b551c 52 8b4514 50 8b4d10 }
- $sequence_5 = { 02c8 884dec 8b55f0 83c201 }
- $sequence_6 = { 0311 52 6878563412 e8???????? }
- $sequence_7 = { 0302 8945fc 8b4d10 8b55fc }
- $sequence_8 = { 52 50 ff9539154000 58 6a00 }
- $sequence_9 = { 8b5678 0354240c 8b5a20 035c240c 33c0 8b3b }
- $sequence_10 = { 240f 3c0a 1c69 2f 8803 43 }
- $sequence_11 = { f3a6 61 7513 8bc2 83e804 8b00 }
- $sequence_12 = { eb0c 58 e8???????? b801000000 c3 }
- $sequence_13 = { 7461 8bc8 48 c6857b27400000 }
- $sequence_14 = { 8b00 0344240c eb02 33c0 }
- $sequence_15 = { ff95bc154000 85c0 7415 58 }
- $sequence_16 = { 010d???????? 83c004 5f 5e }
- $sequence_17 = { 0007 7307 c607ff 8ac1 }
- $sequence_18 = { 031e ff7608 ff7604 e8???????? }
- $sequence_19 = { 00fb fb 804880bc 280d???????? }
- $sequence_20 = { 0306 50 8d5604 e8???????? }
- $sequence_21 = { 0306 50 8b4e04 8d5608 }
- $sequence_22 = { 0202 7466 0fb77202 8b7a04 }
- $sequence_23 = { 014304 c3 53 56 }
+ $sequence_0 = { c7415d382cd7bd c74161d47bdb0f c741651f013f62 c74169388b8e92 c7416d9b14f6a0 }
+ $sequence_1 = { c741103a71c135 c74114c2a02ab0 c74118d95dc845 c7411cf8f0564e c7412066b8276e }
+ $sequence_2 = { c74169388b8e92 c7416d9b14f6a0 c7417180fcd6bb c74175d7401d36 }
+ $sequence_3 = { c7410c16d9fdf8 c741103a71c135 c74114c2a02ab0 c74118d95dc845 c7411cf8f0564e }
+ $sequence_4 = { c7412425d933d1 c7412861fdc72a c7412cdf9134d2 c74130324d251d c74134375ec19d }
+ $sequence_5 = { c74169388b8e92 c7416d9b14f6a0 c7417180fcd6bb c74175d7401d36 c7417958fffa19 66c7417dfc19 }
+ $sequence_6 = { c7412066b8276e c7412425d933d1 c7412861fdc72a c7412cdf9134d2 c74130324d251d c74134375ec19d }
+ $sequence_7 = { c741594d68b93a c7415d382cd7bd c74161d47bdb0f c741651f013f62 }
+ $sequence_8 = { c741510f9f2997 c7415565449eac c741594d68b93a c7415d382cd7bd c74161d47bdb0f c741651f013f62 }
+ $sequence_9 = { c741594d68b93a c7415d382cd7bd c74161d47bdb0f c741651f013f62 c74169388b8e92 }
condition:
- 7 of them and filesize <1523712
+ 7 of them and filesize <8252416
}
-rule MALPEDIA_Win_Bluehaze_Auto : FILE
+rule MALPEDIA_Win_Dropshot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b806577a-57c1-570d-aa1c-22fa8aae198a"
+ id = "f835fd17-f919-5a07-a5c9-cff4292c1163"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bluehaze"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bluehaze_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dropshot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dropshot_auto.yar#L1-L98"
license_url = "N/A"
- logic_hash = "e848ac1af15ccfaaa261b6df2c92e0cbc62750d10a2cd1c781f26efdf23885e7"
+ logic_hash = "98ce90f78c6e888102f62c73a346864796873af9c7b795369b519cebc67a4ac6"
score = 75
quality = 75
tags = "FILE"
@@ -176257,32 +183293,30 @@ rule MALPEDIA_Win_Bluehaze_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d85f0feffff 50 8bcf ff15???????? 8b08 8b4904 }
- $sequence_1 = { 745f 6a30 c7460800000000 e8???????? 83c404 85c0 }
- $sequence_2 = { 0fbe56ff 4e 51 52 57 ffd3 83c40c }
- $sequence_3 = { e8???????? 83c408 8bc8 ff15???????? 397314 7204 }
- $sequence_4 = { 8d4f04 894e30 894e34 8d4708 8d4d10 894610 894614 }
- $sequence_5 = { 68???????? 64a100000000 50 81ecec050000 a1???????? 33c5 8945ec }
- $sequence_6 = { 83c420 8d14c500000000 2bd0 8b06 5b 8d0cd0 }
- $sequence_7 = { 03c2 894508 753d 8b4604 8b0e 3bc8 0f8466010000 }
- $sequence_8 = { 0b0b 010b 0b0b 0b0b 0b0b 0b0b 0b0b }
- $sequence_9 = { 33db 8bc7 8bf1 c745e80f000000 895de4 885dd4 8d5001 }
+ $sequence_0 = { e8???????? 83c40c 6a04 6800100000 6804010000 6a00 ff15???????? }
+ $sequence_1 = { ff15???????? 5d c3 3b0d???????? f27502 }
+ $sequence_2 = { 6a64 ff15???????? 6800800000 6a00 }
+ $sequence_3 = { 6a05 ff15???????? ff15???????? 6a00 }
+ $sequence_4 = { eb05 e8???????? 68e8030000 ff15???????? }
+ $sequence_5 = { ff15???????? 6a04 6800100000 6808020000 }
+ $sequence_6 = { ff15???????? 6a00 ff15???????? 6a00 ff15???????? 6a05 }
+ $sequence_7 = { 6a00 6a00 68???????? 6a00 ff15???????? b801000000 }
condition:
- 7 of them and filesize <424960
+ 7 of them and filesize <483328
}
-rule MALPEDIA_Win_Fonix_Auto : FILE
+rule MALPEDIA_Win_Zeus_Action_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bd0f7338-d5ae-57b4-8254-a4a394cfa806"
+ id = "65e8f438-ad6b-5cc2-8433-22cd51967cfc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fonix"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fonix_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus_action"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeus_action_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "a1de19ea9d27789030065bff520751643f536c0deae9fbccf8fe2c31cafb92ef"
+ logic_hash = "d578cc91c04661eaf2cc2ee8b8d1f82a11b119d1521d38f5e03bfba5cd5d37a6"
score = 75
quality = 75
tags = "FILE"
@@ -176296,84 +183330,77 @@ rule MALPEDIA_Win_Fonix_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 8d5508 c645fc0e 8d8df4fbffff e8???????? 51 51 }
- $sequence_1 = { 83c408 85ff 0f8533ffffff 0f1045a8 8bb56cffffff 0f114590 f30f7e45b8 }
- $sequence_2 = { c1c107 894c2434 8b4c2428 03ca 33f1 c1c610 03c6 }
- $sequence_3 = { 8b7d74 8d4500 57 50 ff7578 8d4530 c645fc0a }
- $sequence_4 = { c645fc1e e8???????? c645fc1f 68???????? 8d8d68fdffff e8???????? 68???????? }
- $sequence_5 = { e8???????? bf6e060000 c645fc0a 57 e8???????? 59 8bf0 }
- $sequence_6 = { 8bf0 ff5208 0faff0 8d4b0c 56 e8???????? }
- $sequence_7 = { 8d8d0cfcffff e8???????? 83ec18 8d4508 }
- $sequence_8 = { 8d4101 898d7cffffff 50 8d4dd8 e8???????? 8bd0 8b856cffffff }
- $sequence_9 = { 50 56 e8???????? 83c40c 84c0 7404 }
+ $sequence_0 = { 668945fa 8d75f4 a5 a5 a5 8383d87500000c 33f6 }
+ $sequence_1 = { 7417 8b01 57 51 ff5034 8b4de8 85c9 }
+ $sequence_2 = { ff15???????? b800080000 663b05???????? 7510 e8???????? 84c0 7407 }
+ $sequence_3 = { 894508 3bf0 7433 8d7b14 85f6 7504 33c0 }
+ $sequence_4 = { 0f84d0020000 395df8 0f84c7020000 395df4 0f84be020000 395dd0 0f84b5020000 }
+ $sequence_5 = { 49 3bc6 7509 8b7dd8 894de8 }
+ $sequence_6 = { 59 85c0 0f8479010000 837ddc00 740f 53 e8???????? }
+ $sequence_7 = { 83c0fb 83f803 7740 f745d000080000 7416 03f9 03d9 }
+ $sequence_8 = { 50 8b4618 83c004 50 ff15???????? 8b761c 83c40c }
+ $sequence_9 = { ff15???????? 85c0 7817 56 8d85f8fdffff 50 8d85f0fbffff }
condition:
- 7 of them and filesize <2226176
+ 7 of them and filesize <827392
}
-rule MALPEDIA_Win_Ketrican_Auto : FILE
+rule MALPEDIA_Win_Ariabody_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "03c6cec7-6d12-51a2-b1a9-8239f834bf9b"
+ id = "58204a37-6e57-54ad-a9ad-f1e207420b64"
date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ketrican"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ketrican_auto.yar#L1-L227"
- license_url = "N/A"
- logic_hash = "c6a0e9c9ef6d7c9c9c9505df3e47863f2b32a94701647f7dc167a7885087d327"
- score = 75
- quality = 71
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { 8965f0 33db 895dfc 33c0 }
- $sequence_1 = { 7417 6a0a 6a1f 68???????? }
- $sequence_2 = { e8???????? 83c010 8906 c3 56 }
- $sequence_3 = { 8bd1 e8???????? 5f 5e c3 55 8bec }
- $sequence_4 = { 8b06 5d c20400 55 8bec 8b4508 894508 }
- $sequence_5 = { 8bc1 8945f0 834dfcff e8???????? }
- $sequence_6 = { 8901 5b 5d c20800 680e000780 e8???????? cc }
- $sequence_7 = { 680e000780 e8???????? cc 8b06 83e810 8b08 }
- $sequence_8 = { 48 7445 48 743a 48 }
- $sequence_9 = { 884603 83c604 8345f804 8b45f8 5f }
- $sequence_10 = { 58 668945d8 6a72 58 }
- $sequence_11 = { 6a00 8d85f1fbffff 50 e8???????? 83c40c 6800040000 }
- $sequence_12 = { ff7508 53 53 ffd6 5f 5e }
- $sequence_13 = { 740a 48 754a e8???????? }
- $sequence_14 = { 83c002 663bd3 75f5 2bc1 d1f8 8d7001 6800080200 }
- $sequence_15 = { e8???????? 8b8a8c2f0000 33c8 e8???????? b8???????? }
- $sequence_16 = { ff15???????? 68???????? c705????????98824100 a3???????? }
- $sequence_17 = { 8d420c 8b4ae8 33c8 e8???????? 8b8a4c010000 }
- $sequence_18 = { 33c8 e8???????? 8b8ae8080000 33c8 e8???????? }
- $sequence_19 = { 8d4dd0 e9???????? 8d4de0 e9???????? 8d4db8 e9???????? 8d4ddc }
- $sequence_20 = { b8???????? e9???????? 8b542408 8d420c 8b8aa4feffff 33c8 }
- $sequence_21 = { c705????????98824100 a3???????? c605????????00 e8???????? 59 }
- $sequence_22 = { 8b8a54ffffff 33c8 e8???????? 8b8adc090000 33c8 e8???????? }
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ariabody"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ariabody_auto.yar#L1-L175"
+ license_url = "N/A"
+ logic_hash = "eeda1b828c38fb501f5c05c0fadc1525e86a5abb54edde2f591e92fd62c5dd82"
+ score = 75
+ quality = 75
+ tags = "FILE"
+ version = "1"
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { eb13 8b16 8bcf e8???????? 8906 85c0 }
+ $sequence_1 = { 8bcf 0fb6c0 50 ff75fc e8???????? }
+ $sequence_2 = { 7402 32c3 88040a 41 }
+ $sequence_3 = { 8a01 84c0 7406 3ac3 7402 }
+ $sequence_4 = { 56 8d0c30 ffd1 8bc6 5f }
+ $sequence_5 = { 8bf2 56 8d55fc 03f9 e8???????? 59 85c0 }
+ $sequence_6 = { 83ec50 53 57 8bd9 e8???????? 8bf8 893b }
+ $sequence_7 = { ff5304 8bf8 893e eb13 8b16 8bcf }
+ $sequence_8 = { 33d2 488d8c2498000000 41b800010000 41ffc7 ff9510020000 }
+ $sequence_9 = { 48895c2408 57 4883ec20 4863d9 488d3da4d30000 4803db 48833cdf00 }
+ $sequence_10 = { eb17 83f802 7512 488d4c2430 488d942420060000 e8???????? }
+ $sequence_11 = { 33ff 488d0480 418b4cc60c 418b54c614 4903cc 458b44c610 4803d3 }
+ $sequence_12 = { e8???????? 3d5595db6d 741d 4d8b7f18 }
+ $sequence_13 = { 41b820000000 488d942444010000 4c8d8c2468010000 48c7402000000000 41ff96d0000000 85c0 7429 }
+ $sequence_14 = { 4c89e1 4533c9 8b942464010000 41ff96c0000000 4889e0 4c89e1 41b820000000 }
+ $sequence_15 = { 8b0b e8???????? 48630b 4c8d2dd59f0000 488bc1 }
condition:
- 7 of them and filesize <1449984
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Monero_Miner_Auto : FILE
+rule MALPEDIA_Win_Ironwind_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e4c7050e-9186-5f1e-9d47-976e6a4001a0"
+ id = "59e0122b-e237-5b83-a993-a2711164e0ad"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.monero_miner"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.monero_miner_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ironwind"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ironwind_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "7e4796fa5a31551e9b057737783d58401a472a7bae7889a290c988c1aea0c1dd"
+ logic_hash = "db36742cc3e5372580f85bcac0b5325edc83e1defe6a3dbe06584de3a3fb0586"
score = 75
quality = 75
tags = "FILE"
@@ -176387,32 +183414,32 @@ rule MALPEDIA_Win_Monero_Miner_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fb65508 034d04 035d00 01d0 e9???????? 0fb77508 034d04 }
- $sequence_1 = { 8b842490000000 895f40 338424ac000000 8b9c2444010000 31cd 8b8c2440010000 31de }
- $sequence_2 = { 8b442460 31f5 8bb42488000000 03742460 896c2438 89c5 897c243c }
- $sequence_3 = { 8b4c2424 c7042400000000 89442404 8b442420 e8???????? 85c0 89c3 }
- $sequence_4 = { 8b54245c 09ce 89b424f0010000 897738 89ac24f4010000 896f3c 0fa4c204 }
- $sequence_5 = { 8d4c2427 89742414 895c240c 897c2408 c744240400000000 83e1f0 8b7de0 }
- $sequence_6 = { 89bc24c0010000 89ac24c4010000 8bac24c8040000 036c2420 8b742460 8bbc24cc040000 137c2424 }
- $sequence_7 = { c744240423000000 8b85c0040000 890424 e8???????? 85c0 7403 c60000 }
- $sequence_8 = { e8???????? 8d4b50 8d5705 c7435c00000000 c7435800000000 c7435400000000 895350 }
- $sequence_9 = { 8b8424b0010000 899424c4010000 8b9424b4010000 89ac24c0010000 01c1 89c5 11d3 }
+ $sequence_0 = { be01000000 8bc6 e9???????? 4803c9 488b6cca08 4885ed 74e7 }
+ $sequence_1 = { c3 4533c0 418d5002 8d4a15 ff15???????? 4883f8ff }
+ $sequence_2 = { e9???????? 488d0d823e0300 4889bc24a0000000 e8???????? 488bf8 4885c0 7508 }
+ $sequence_3 = { ff15???????? 488b742460 4885db 7409 488bcb ff15???????? 8bc7 }
+ $sequence_4 = { 80b85011000001 488d152cc40400 488d0d4dc40400 480f45d1 488bc8 e8???????? 488bf8 }
+ $sequence_5 = { 8d5001 8d4838 ff15???????? 488bf8 4885c0 7508 8d471b }
+ $sequence_6 = { f20f1101 e9???????? 0f57c0 f2480f2a87100b0000 f20f1101 e9???????? 0f57c0 }
+ $sequence_7 = { bf05000000 8bc7 eb53 bf02000000 8bc7 eb4a 664183f804 }
+ $sequence_8 = { 85c0 742e 0fbe03 4c8d156f8ffdff 83c0e0 83f85a 0f8765020000 }
+ $sequence_9 = { e8???????? 488b8f50070000 4885c9 7469 ff15???????? 488983d0060000 4885c0 }
condition:
- 7 of them and filesize <1425408
+ 7 of them and filesize <995328
}
-rule MALPEDIA_Win_Gpcode_Auto : FILE
+rule MALPEDIA_Win_Typehash_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d8b81e5a-8691-5b0a-9c29-2fe185a250cc"
+ id = "edf296ed-fbc4-5bd8-b180-ef55e989c944"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gpcode"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gpcode_auto.yar#L1-L188"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.typehash"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.typehash_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "47d13f6f4636c7a610d9f5f6fa6bfc46db8fee0da3e7f134864d9085143c9558"
+ logic_hash = "9451e6a97a0b537ea280e22049617c90fd5aa93257a4b129bfda6427a2eb4eeb"
score = 75
quality = 75
tags = "FILE"
@@ -176426,43 +183453,34 @@ rule MALPEDIA_Win_Gpcode_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? a1???????? a3???????? 6800001000 68???????? ff35???????? }
- $sequence_1 = { 68???????? e8???????? 91 6a00 }
- $sequence_2 = { e8???????? e8???????? c705????????01000000 c3 55 8bec }
- $sequence_3 = { 85c0 7479 33c0 50 50 6a03 50 }
- $sequence_4 = { ff35???????? 68???????? ff75f8 ff15???????? 8945f4 85c0 7425 }
- $sequence_5 = { 8906 83c608 e2e6 59 e2dc }
- $sequence_6 = { 83c40c 8d45fc 50 8d450c ff30 e8???????? }
- $sequence_7 = { e8???????? 0bc0 7504 33c0 c9 c3 8945f0 }
- $sequence_8 = { c60000 2d???????? 50 8d85e8feffff 50 68???????? }
- $sequence_9 = { 68???????? 6a00 e8???????? 6a0a 68???????? 6a00 e8???????? }
- $sequence_10 = { e8???????? 83f8ff 7505 5a }
- $sequence_11 = { 001438 eb06 80c107 000c38 }
- $sequence_12 = { 0005???????? 0fb605???????? 8ad3 8d80b8fee014 }
- $sequence_13 = { 0016 40 3bc3 72de }
- $sequence_14 = { 0145f0 8b4df0 3b4d14 0f8263feffff }
- $sequence_15 = { 000c38 40 3b45f8 72e3 }
- $sequence_16 = { 0144240c 85f6 7fdd 33c0 }
- $sequence_17 = { 0106 eb94 55 8bec }
- $sequence_18 = { 000e eb08 02c9 b2f9 }
+ $sequence_0 = { 83e11f 8b0485e03d4100 8d04c8 eb05 b8???????? f6400420 740d }
+ $sequence_1 = { c3 8bc8 83e01f c1f905 8b0c8de03d4100 8a44c104 }
+ $sequence_2 = { e8???????? 6a01 8d4c2450 c68424cc00000001 e8???????? bf???????? }
+ $sequence_3 = { 8944240c c744241004000000 7460 8b2d???????? 8b3d???????? }
+ $sequence_4 = { c1f805 c1e603 8d1c85e03d4100 8b0485e03d4100 03c6 8a5004 }
+ $sequence_5 = { 50 51 6813000020 56 c744242000000000 c744242404000000 ffd7 }
+ $sequence_6 = { 03c8 3bc1 7d1e 8d1440 2bc8 8d1495e8294100 832200 }
+ $sequence_7 = { 3bf3 7505 be???????? 8b54242c 8b442430 8bcf 55 }
+ $sequence_8 = { 837d1805 7538 837d1000 7508 8bb6b42b4100 }
+ $sequence_9 = { e8???????? 68???????? 8d45c8 c745c8e4e74000 50 }
condition:
- 7 of them and filesize <761856
+ 7 of them and filesize <180224
}
-rule MALPEDIA_Win_Vobfus_Auto : FILE
+rule MALPEDIA_Win_Hi_Zor_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "379cd9d3-d698-58d1-90c1-aa0d12f74cc4"
+ id = "3dc62db9-3a05-5424-a3c8-d6fd9e595782"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vobfus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vobfus_auto.yar#L1-L221"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hi_zor_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hi_zor_rat_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "87942ff8c467cfeb6529bdba1fb2a14574a28472aae2c0f0acabf5e6455fc919"
+ logic_hash = "3acb0fc19d1323e3198577328eeef1259397f6589eae60512b85396f5cbd245b"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -176474,45 +183492,32 @@ rule MALPEDIA_Win_Vobfus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b5508 8b92e8000000 8b82841d0000 50 50 8b10 }
- $sequence_1 = { 8b5508 8b92e8000000 8b825c1e0000 50 }
- $sequence_2 = { 8bec 8b5508 8b92e8000000 8b82c8150000 }
- $sequence_3 = { 8b8220000000 50 50 8b10 ff5204 58 }
- $sequence_4 = { 8b5508 8b92e8000000 8b8200080000 50 }
- $sequence_5 = { 8b5508 8b92e8000000 8b82b4230000 50 }
- $sequence_6 = { 8b5508 8b92e8000000 8b82d0130000 50 }
- $sequence_7 = { 8b5508 8b92e8000000 8b829c0e0000 50 }
- $sequence_8 = { f3ed ebf2 ed ec }
- $sequence_9 = { ec f2ed ec f2ed ec f3ed }
- $sequence_10 = { f2e8fae6d5f6 d2b5f2bb8ff3 ae 73f3 aa 5c f6ac4ff8b54ffb }
- $sequence_11 = { 801800 0808 0006 3401 41 06 }
- $sequence_12 = { 7cc8 dc7acd e291 d2e8 }
- $sequence_13 = { 8631 96 0a7f25 7a43 92 9afc9e5780451f }
- $sequence_14 = { 0c38 a95bedb2e5 759e 3a9b423ceb9d 65be2dafffcd 3624e4 6bee88 }
- $sequence_15 = { 4b ce 8ca4b11e13b793 73aa fa }
- $sequence_16 = { 48 0008 78ff 0d50004900 3e3cff 46 }
- $sequence_17 = { 5c f6ac4ff8b54ffb c058fcca 61 }
- $sequence_18 = { 46 14ff 0470 fe0a }
- $sequence_19 = { e752 47 625403a7 78f5 06 95 }
- $sequence_20 = { 6c 74ff 801800 0808 }
- $sequence_21 = { b909dfd18c 9d 7454 2bcd 8ab411746337ed 80ab931e2e5e88 }
- $sequence_22 = { c8ed9459 ef 60 226aa3 60 8907 6bdd97 }
+ $sequence_0 = { c644303080 8b4e24 83e13f 80f937 7614 8bc6 e8???????? }
+ $sequence_1 = { ff15???????? 8b4d08 57 8bf0 51 56 }
+ $sequence_2 = { e8???????? 8b1d???????? 83c418 6804010000 8d8df4fdffff 51 }
+ $sequence_3 = { 23da 8bfa 8b5014 f7d7 }
+ $sequence_4 = { 8b5818 8db41e604b0000 c1e610 c1ef10 0bfe }
+ $sequence_5 = { 037018 f7d2 8975f8 897014 8bfa 0b55f8 }
+ $sequence_6 = { 57 51 50 8945f4 e8???????? 8b450c }
+ $sequence_7 = { 50 51 e8???????? 83c424 893e 5f 5e }
+ $sequence_8 = { ffd6 8b55ec 83c404 52 ffd6 83c404 }
+ $sequence_9 = { 83c40c 6a00 8d450c 50 6800e00100 8d4608 50 }
condition:
- 7 of them and filesize <409600
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Darktequila_Auto : FILE
+rule MALPEDIA_Win_Electric_Powder_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "24336c6c-1ca4-5e88-a6d8-a7828b6362d5"
+ id = "6da8b24a-07fd-5fc6-a509-6cbc31d92594"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darktequila"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darktequila_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.electric_powder"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.electric_powder_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "cfa088d1d1871ddb38182a8cfb5b3421267e6793e63357e090f59bf6001f73cc"
+ logic_hash = "38cd56e857c27f71ed9be956ee8235c5f49da7b5b360cadbe53a42a73ba8199e"
score = 75
quality = 75
tags = "FILE"
@@ -176526,71 +183531,71 @@ rule MALPEDIA_Win_Darktequila_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c3 85c9 7414 8b5b10 85c0 }
- $sequence_1 = { 85c0 740d 894610 b801000000 897e04 }
- $sequence_2 = { 8b45fc 50 ff15???????? 8b0d???????? 8b5508 }
- $sequence_3 = { e8???????? 83c410 897b08 5f }
- $sequence_4 = { 8bd3 e8???????? 8b4310 56 }
- $sequence_5 = { 740d 894610 b801000000 897e04 5b }
- $sequence_6 = { 72dc b8???????? c3 33d2 3915???????? 0f857c000000 }
- $sequence_7 = { 8945f8 85c0 7467 8b4b0c 8b5310 894df4 }
- $sequence_8 = { 83c410 897b08 5f b801000000 5e }
- $sequence_9 = { c705????????02000000 8b45fc 50 ff15???????? 8b0d???????? 8b5508 a1???????? }
+ $sequence_0 = { 3b4e08 0f8324010000 8b4604 c704c810000000 8b4608 83e801 8945fc }
+ $sequence_1 = { 03c0 660f289800904300 660f2835???????? 660f59cf 660f58d1 660f70caee f20f59d7 }
+ $sequence_2 = { 8d8d20fdffff c78530fdffff00000000 c78534fdffff0f000000 c68520fdffff00 e8???????? c745fc00000000 8d8d20fdffff }
+ $sequence_3 = { 7202 8b39 8b4110 85c0 7449 48 83ceff }
+ $sequence_4 = { 0f8389010000 8b5604 3bc8 0f8388010000 8b44fa04 8944ca04 }
+ $sequence_5 = { c645fc20 51 8bd0 8d8d78fcffff e8???????? 83c404 68???????? }
+ $sequence_6 = { 50 51 8d8d68faffff e8???????? 83bd7cfaffff08 8d8568faffff }
+ $sequence_7 = { 7202 8b3f 83fa08 731a }
+ $sequence_8 = { 83c404 89b518efffff 85f6 0f84be000000 8b8d40efffff 03c9 }
+ $sequence_9 = { 83f8ff 773b 83f8ef 7736 8b4f04 83c010 50 }
condition:
- 7 of them and filesize <1827840
+ 7 of them and filesize <565248
}
-rule MALPEDIA_Win_Unidentified_073_Auto : FILE
+rule MALPEDIA_Win_Morto_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0ba61f73-e46a-5f54-853f-f1f3b502ee26"
- date = "2022-08-05"
- modified = "2022-08-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_073"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_073_auto.yar#L1-L125"
+ id = "b4e2fdf6-28d4-5bb0-a9a0-1ea448c5566e"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.morto"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.morto_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "8100472ca712d569bbcdb570af72e3f13986092b4d8ee8e3873da55bef76232d"
+ logic_hash = "a9b63fda2800565a4b4486897d85bf042e81c5ab64e52d3f79cf07bf3408f96f"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20220805"
- malpedia_hash = "6ec06c64bcfdbeda64eff021c766b4ce34542b71"
- malpedia_version = "20220808"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8538ffffff 6a00 c746180f000000 8bce }
- $sequence_1 = { c684242801000019 e8???????? 68???????? 8d8c24c0000000 e8???????? 6aff }
- $sequence_2 = { 8bce c7461400000000 50 c6460400 e8???????? 83ec1c 8bf4 }
- $sequence_3 = { 7846 8b451c 8b0e 2bc1 3bc3 7c53 }
- $sequence_4 = { 8b0d???????? 894df8 eb09 8b55f8 83ea01 8955f8 837df800 }
- $sequence_5 = { 6a00 8d8424dc000000 50 8d4c2454 e8???????? 83ec1c 8d84240c010000 }
- $sequence_6 = { 8bec 51 894dfc c705????????90664a00 833d????????00 741c }
- $sequence_7 = { 6bd103 8982a0784a00 68???????? 8b45fc 50 ff15???????? }
- $sequence_8 = { 0fb74df8 894de0 668b55e0 668955f8 0fb745fc 0fb74df8 3bc1 }
- $sequence_9 = { 57 6aff 68???????? 50 ff15???????? }
+ $sequence_0 = { 280c30 40 3b450c 72f4 8b4608 6a40 }
+ $sequence_1 = { 50 e8???????? 83c40c 8945e4 8d45cc }
+ $sequence_2 = { 03d0 8911 ffd2 5f 5e }
+ $sequence_3 = { 03f5 42 8a1e 46 }
+ $sequence_4 = { ff35???????? c745ec04000000 c745fce8030000 ff15???????? }
+ $sequence_5 = { 8bf0 c1ee08 83e601 8d3c56 }
+ $sequence_6 = { 41 8d441201 8bd0 c1ea08 83e201 a87f 8d3c7a }
+ $sequence_7 = { c745d0636c6965 c745d46e745c61 8945d8 c745dc44726f70 }
+ $sequence_8 = { 6802000080 ff55e0 85c0 755f 8d45f8 50 }
+ $sequence_9 = { 894dfc 895508 eb03 8b75f4 b980000000 33c0 8dbdf0fdffff }
condition:
- 7 of them and filesize <1974272
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Cuegoe_Auto : FILE
+rule MALPEDIA_Win_Sdbbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "eccb0436-f9ed-5e03-8d27-4464cf8de9a1"
+ id = "6668321a-45c2-56a4-8219-52041c66e0ea"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cuegoe"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cuegoe_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sdbbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sdbbot_auto.yar#L1-L188"
license_url = "N/A"
- logic_hash = "9bdbb34dedb6d213b915fa268b74e0986ed09811af8e7637c05b65b2310f3a18"
+ logic_hash = "0618d5957379edb357e3ce8de647ff0724885b87e782036bd514add2c7f2cbe6"
score = 75
quality = 75
tags = "FILE"
@@ -176604,32 +183609,40 @@ rule MALPEDIA_Win_Cuegoe_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 397d68 7409 ff7568 e8???????? 59 6a57 5e }
- $sequence_1 = { 50 895de4 e8???????? 837d2808 8b4514 }
- $sequence_2 = { 0f8390feffff 8b0488 0fb6c8 894538 c16d3808 894d3c }
- $sequence_3 = { 6a00 50 e8???????? 83c40c 33c0 89442410 e9???????? }
- $sequence_4 = { 6a0a 8d45e8 8975e4 e8???????? 8d5dd0 e8???????? }
- $sequence_5 = { 50 e8???????? 8d4570 50 ff750c 8d85d0030000 56 }
- $sequence_6 = { 69c0a0860100 8a563c c7460c01000000 885608 89442410 3bd8 0f8387050000 }
- $sequence_7 = { 8b0488 0fb6c8 894538 c16d3808 894d3c 899d40040000 8b15???????? }
- $sequence_8 = { 8d858c000000 50 8d8574ffffff 6a4c 50 e8???????? 59 }
- $sequence_9 = { 0f94c1 888c286c0d0000 03c7 89442410 837c241010 0f8c7affffff }
+ $sequence_0 = { e8???????? 8bf8 ba4d5a0000 6690 }
+ $sequence_1 = { 803e61 7203 83c1e0 81c2ffff0000 03cf }
+ $sequence_2 = { 8bcf 85d2 7418 8bfe 2b7df8 }
+ $sequence_3 = { 8d4901 8841ff 8d5201 83ee01 }
+ $sequence_4 = { 2bd1 03c1 8955ec 8945e4 85d2 0f8560ffffff }
+ $sequence_5 = { 8b7028 33c9 0fb75024 0f1f8000000000 0fb63e }
+ $sequence_6 = { 8b01 03c6 8945e8 eb2e 3daafc0d7c }
+ $sequence_7 = { 6683f803 750b 81e1ff0f0000 013c31 eb27 6683f801 7511 }
+ $sequence_8 = { c3 803d????????00 750c c605????????01 }
+ $sequence_9 = { 33f6 8a27 83c702 84e4 7437 }
+ $sequence_10 = { 7419 0f1f8000000000 0fb602 48ffc2 8801 488d4901 4983e801 }
+ $sequence_11 = { 0f1f840000000000 418b49f8 49ffca 418b11 4903ce 458b41fc }
+ $sequence_12 = { 7204 4883c0e0 4803c1 48ffc2 664503c1 75e5 3d5bbc4a6a }
+ $sequence_13 = { 48833f00 488bd8 75a4 4883c514 837d0000 0f856dffffff }
+ $sequence_14 = { 4903ce 41ffd5 488bf0 4885c0 7474 }
+ $sequence_15 = { 85c0 0f84bb000000 418b9fb0000000 8bf8 4903de }
+ $sequence_16 = { 4d2bc5 0fb601 41880408 488d4901 4883ea01 75ef 450fb74f14 }
+ $sequence_17 = { 4d03fd 41b800300000 448d4940 418b5750 ffd6 418b5750 488bc8 }
condition:
- 7 of them and filesize <540672
+ 7 of them and filesize <1015808
}
-rule MALPEDIA_Win_Tandfuy_Auto : FILE
+rule MALPEDIA_Win_Portdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "38730032-1555-50d4-b759-37b770d675ac"
+ id = "84ef053f-8b45-5899-91c4-5c0973d7e3db"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tandfuy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tandfuy_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.portdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.portdoor_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "7ea6bc2b0de15e30b85cc41fe9dae28b9e373e31fa36302d55838d87545cc73b"
+ logic_hash = "23b6dfc496aede71e92bc63441565950d5591602bef8ef2eba1715ff0ea58fc2"
score = 75
quality = 75
tags = "FILE"
@@ -176643,32 +183656,32 @@ rule MALPEDIA_Win_Tandfuy_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 8b942458010000 25ff000000 81e1ff000000 50 }
- $sequence_1 = { f68221eb6e0004 7403 40 ff01 ff01 40 e9???????? }
- $sequence_2 = { e8???????? 83c404 85c0 0f8440010000 b93e000000 33c0 8dbdd8f9ffff }
- $sequence_3 = { 8bec 8b4508 ff3485a0d66e00 ff15???????? 5d c3 55 }
- $sequence_4 = { 6a00 51 6a02 52 56 ff15???????? 56 }
- $sequence_5 = { 52 33c9 8a4801 51 33d2 8a10 }
- $sequence_6 = { f3ab 8dbc2474020000 83c9ff f2ae f7d1 2bf9 8bc1 }
- $sequence_7 = { 7562 b8???????? 81c49c000000 c3 83f806 7551 }
- $sequence_8 = { 8d95e8feffff 8b7d08 83c9ff 33c0 f2ae f7d1 }
- $sequence_9 = { 6800000080 56 f3ab ff15???????? 8bd8 }
+ $sequence_0 = { 50 e8???????? 83f8ff 8906 0f95c0 eb2f 807e5100 }
+ $sequence_1 = { 50 8d85fcf3ffff 50 e8???????? 8bf0 }
+ $sequence_2 = { ff5718 8903 6a04 59 8d4102 33d2 }
+ $sequence_3 = { 8945a8 eb04 8365a800 8b45a8 894590 834dfcff 8b4590 }
+ $sequence_4 = { 50 8b8528e5ffff 0f94c1 898d3ce5ffff 8b8d24e5ffff 8b0485b80f0210 ff3401 }
+ $sequence_5 = { 894224 6689424c 894248 88424e 8a01 88040b }
+ $sequence_6 = { 7e21 8b450c 6a00 2bc6 }
+ $sequence_7 = { 51 51 8d45f8 895df8 }
+ $sequence_8 = { e8???????? 8bf8 b8eeff0000 59 668907 8b450c 885f02 }
+ $sequence_9 = { e8???????? a1???????? 33c5 8945fc 53 8b5d08 8d85fdfbffff }
condition:
- 7 of them and filesize <155648
+ 7 of them and filesize <297984
}
-rule MALPEDIA_Win_Polyglotduke_Auto : FILE
+rule MALPEDIA_Win_8T_Dropper_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "afe4cb05-aa94-5225-84e8-b6489c3e26d1"
+ id = "62f20b6c-23f8-52e5-8f38-7d977c3fc023"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.polyglotduke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.polyglotduke_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.8t_dropper"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.8t_dropper_auto.yar#L1-L115"
license_url = "N/A"
- logic_hash = "37a5b9867f5de08a35688f7a9273792487d4c60d613dec2d499a53b9323d3f00"
+ logic_hash = "f24ad3d6bfd5a20c8c809ac43affb0600d938cb9b1cb9cd8c47771e603e82a25"
score = 75
quality = 75
tags = "FILE"
@@ -176682,32 +183695,32 @@ rule MALPEDIA_Win_Polyglotduke_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 488b5608 448bc7 488bc8 488bd8 e8???????? }
- $sequence_1 = { 0fb7f9 492bf3 498bcb 33d2 33c0 }
- $sequence_2 = { 48895c2408 57 4883ec20 488bfa 488bd9 488d0595970000 488981a0000000 }
- $sequence_3 = { 4c8be8 e8???????? 488d0d88120100 e8???????? 488d4c2430 8bd3 4c8bc0 }
- $sequence_4 = { 488be8 498bcc e8???????? 488bcf e8???????? }
- $sequence_5 = { 48894518 e8???????? 488d0dbae30000 48894520 e8???????? 488d0daee30000 }
- $sequence_6 = { 42392c3e 0f849bfaffff 428b143e 4a8d4c3e04 e8???????? 488d0dec0c0100 ba10000000 }
- $sequence_7 = { e8???????? b8cdcccccc f7e5 c1ea02 8d0492 2be8 }
- $sequence_8 = { 99 f77c2428 4863c2 410fb70c46 488b442440 4533f6 66894c4450 }
- $sequence_9 = { 488bf1 8d4301 ba02000000 498be8 }
+ $sequence_0 = { 741b 56 6800700000 6a01 68???????? }
+ $sequence_1 = { ff74240c e8???????? 83c40c c3 8b442408 83f801 }
+ $sequence_2 = { c6440c0e6e 8d4c2408 51 683f000f00 50 }
+ $sequence_3 = { 68???????? 50 ff15???????? 85c0 7559 8b4c2408 51 }
+ $sequence_4 = { 50 ff15???????? 85c0 7559 8b4c2408 }
+ $sequence_5 = { 49 c6440c0c52 c6440c0d75 c6440c0e6e }
+ $sequence_6 = { 68???????? 6a02 50 8b442418 }
+ $sequence_7 = { 7559 8b4c2408 51 ff15???????? }
+ $sequence_8 = { 6800700000 6a01 68???????? e8???????? 56 e8???????? }
+ $sequence_9 = { ff15???????? 8d942410010000 6804010000 52 68???????? }
condition:
- 7 of them and filesize <222784
+ 7 of them and filesize <147456
}
-rule MALPEDIA_Win_Nvisospit_Auto : FILE
+rule MALPEDIA_Win_Snatch_Loader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "824469e0-98f2-5eab-b839-ba6db77c2d16"
+ id = "27465de5-7033-587f-a756-9377f064a810"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nvisospit"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nvisospit_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.snatch_loader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.snatch_loader_auto.yar#L1-L176"
license_url = "N/A"
- logic_hash = "385fb86660d71ea6f219554af1885e2ee67e8307dd338d6dbd8b2f326f4be091"
+ logic_hash = "0092d0e62ac35cefc4568a8a8fbdf579b918d859e448f714bc73aa915417d36e"
score = 75
quality = 75
tags = "FILE"
@@ -176721,32 +183734,38 @@ rule MALPEDIA_Win_Nvisospit_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83f801 0f851e010000 8d710c 81fe???????? 0f8350feffff 895dbc }
- $sequence_1 = { a1???????? ffd0 83ec04 0fb785a2f9ffff 0fb7c0 8d959cf9ffff 89542410 }
- $sequence_2 = { c70424???????? e8???????? 85db c705????????02000000 0f85d1fdffff }
- $sequence_3 = { a1???????? 31c9 c705????????00004000 8b00 85c0 }
- $sequence_4 = { 89442404 c70424???????? e8???????? 0fb785a8f9ffff }
- $sequence_5 = { 0f8e16010000 85d2 0f8493010000 b9???????? 81f9???????? }
- $sequence_6 = { 0fb7c0 8d959cf9ffff 89542410 c744240c00000000 8d958ef9ffff 89542408 }
- $sequence_7 = { 83ec0c 8945bc 8b45bc 89442404 }
- $sequence_8 = { e8???????? c7442404b0feffff c70424???????? e8???????? c7442404ccffffff c70424???????? }
- $sequence_9 = { 8d9dacfbffff 81c307010000 895c2414 8d9dacfbffff 83c306 895c2410 894c240c }
+ $sequence_0 = { 66894606 a1???????? 85c0 7522 6a02 59 }
+ $sequence_1 = { 8bc8 8b45fc 33d2 85c9 5e 0f45c2 8be5 }
+ $sequence_2 = { 51 56 56 ffd0 8bc8 8b45fc 33d2 }
+ $sequence_3 = { 33f6 8bd9 57 85c0 7522 6a02 }
+ $sequence_4 = { ffd0 5f 85c0 7509 8bce e8???????? }
+ $sequence_5 = { ffd0 85c0 8bce 0f457dfc }
+ $sequence_6 = { 85c0 7505 8b45fc eb0d 53 53 }
+ $sequence_7 = { 33f6 8bd6 8975fc 66397102 740b 42 }
+ $sequence_8 = { 46 3bf3 76d8 33c0 48 5a 59 }
+ $sequence_9 = { 741f 3a0439 7514 41 3b4df8 }
+ $sequence_10 = { 68???????? 58 ffd0 8945f0 0bc0 }
+ $sequence_11 = { 33d2 33c9 8a0431 0ac0 741f }
+ $sequence_12 = { 52 ff750c e8???????? 8945fc 0bc0 7454 394508 }
+ $sequence_13 = { 55 8bec 83c4fc 53 33db 837d0800 }
+ $sequence_14 = { 3b45fc 773b 8b750c 8b7d10 037508 8bde }
+ $sequence_15 = { 7206 3c5a 7702 0c20 c1c210 }
condition:
- 7 of them and filesize <66560
+ 7 of them and filesize <262144
}
-rule MALPEDIA_Win_Zedhou_Auto : FILE
+rule MALPEDIA_Win_Neddnloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2aa4d978-6d48-5f72-a16b-4b6ea617b5b6"
+ id = "8eecbeb9-33c7-5f00-852d-691f303c8b89"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zedhou"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zedhou_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.neddnloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.neddnloader_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "b60fc9437fc4bcd4e7a504c33358b6d6c8b7b5e0237aab2ee62dd854e5c508d6"
+ logic_hash = "318d1d367a3335dce76e46790f71f42f9c5ddb3e28ec2c109117f64c52aadcd2"
score = 75
quality = 75
tags = "FILE"
@@ -176760,34 +183779,40 @@ rule MALPEDIA_Win_Zedhou_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b4dac 894dd8 8d55d0 52 8d45d4 50 }
- $sequence_1 = { ff5030 5f 5e 5b c9 c22400 }
- $sequence_2 = { 57 ff7508 56 ff15???????? ff7508 ff15???????? 8bc6 }
- $sequence_3 = { 8d4da4 51 8b5508 8b02 8b4d08 51 ff9008070000 }
- $sequence_4 = { ff15???????? 8d4dc0 ff15???????? 0fbf4598 85c0 742a c745fc06000000 }
- $sequence_5 = { 68???????? 8b85acfeffff 50 8b8da8feffff 51 ff15???????? 8985c4fdffff }
- $sequence_6 = { 33c0 f3a6 0f85653a0000 85d2 }
- $sequence_7 = { ff15???????? 83c41c c745fc04000000 8b5508 8b02 8b4d08 51 }
- $sequence_8 = { ff15???????? c745fc7f000000 8b5508 8b4238 50 68???????? ff15???????? }
- $sequence_9 = { e8???????? 894604 8b430c 59 8b04c5fc201822 59 6a01 }
+ $sequence_0 = { 83c204 3bcf 72f0 8d43ff }
+ $sequence_1 = { 69c0b179379e c1e813 03c9 0fb73411 }
+ $sequence_2 = { 8b5508 69c0b179379e c1e813 33c9 66890c42 }
+ $sequence_3 = { 8d43ff 3bc8 7311 0fb702 }
+ $sequence_4 = { 8bc1 2b45fc 5f 5e }
+ $sequence_5 = { eb02 0008 8b45f8 83c0f4 897dfc }
+ $sequence_6 = { 663bc6 7506 83c102 83c202 3bcb 7307 }
+ $sequence_7 = { 7311 0fb702 0fb731 663bc6 7506 83c102 }
+ $sequence_8 = { 488bf2 41c1ed04 492bf0 41ffc5 488bd3 488bcf }
+ $sequence_9 = { 410fb6c0 4133b48e803c0100 4133b48680480100 418bc0 41337530 c1e808 0fb6d0 }
+ $sequence_10 = { 0fb6c8 410fb6c0 4133bc8e803c0100 4133bc8680480100 41337d60 418bc0 }
+ $sequence_11 = { 448bce 448bc7 488bd0 498bce e8???????? 448bf0 }
+ $sequence_12 = { 488d3d24570000 eb0e 488b03 4885c0 7402 }
+ $sequence_13 = { 0fb6d0 418bc6 458b949480440100 c1e810 0fb6c8 8bc5 }
+ $sequence_14 = { 488d0d14100100 baa00f0000 488bc5 83e51f 48c1f805 486bed58 }
+ $sequence_15 = { ff5348 b97f000000 ff15???????? eb1e 488b5350 498bcd ff5348 }
condition:
- 7 of them and filesize <499712
+ 7 of them and filesize <3438592
}
-rule MALPEDIA_Win_Cobint_Auto : FILE
+rule MALPEDIA_Win_Satan_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "817f690c-d59f-5f8a-a3d9-41671b2ba114"
+ id = "ddfd46bc-87c6-53ce-9595-be9a6a99e4e0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cobint"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cobint_auto.yar#L1-L246"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.satan"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.satan_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "138f47bd93e47d27bded8ff6cb142802d64943eb32ae6054eb04266b57a32a5b"
+ logic_hash = "6170986a4237acbed4cbbf775dbbfb72e2b63776fab2b68ba052c6ad44853238"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -176799,46 +183824,32 @@ rule MALPEDIA_Win_Cobint_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c410 5e 5d c3 a1???????? 56 33f6 }
- $sequence_1 = { 3931 740d 40 83c110 83f820 }
- $sequence_2 = { 57 ff15???????? 8b15???????? 8bc6 8bca }
- $sequence_3 = { ff7508 e8???????? 83c40c 0fb6c0 5d c3 ff751c }
- $sequence_4 = { 33f6 a1???????? 03c6 3938 }
- $sequence_5 = { ffd6 f7d8 c745f404000000 1bc0 }
- $sequence_6 = { 6a65 eb31 85db 743a 3bde 7336 53 }
- $sequence_7 = { 59 5d c3 ff7508 6a00 ff35???????? }
- $sequence_8 = { 90 90 e10b 96 7c90 90 }
- $sequence_9 = { 90 90 749b 807ce19a80 7c90 }
- $sequence_10 = { 807c909090 90 90 90 90 90 }
- $sequence_11 = { 3c2e 7404 3c2c 7506 41 8a0431 2c20 }
- $sequence_12 = { ffd6 6a04 8d45c0 c745c001000000 }
- $sequence_13 = { 7202 04e0 8bcf 0fb6c0 c1c108 03c7 }
- $sequence_14 = { c745c001000000 50 6a41 53 ffd6 baf608f7a4 }
- $sequence_15 = { 837d1000 740d 8b5508 0355f0 }
- $sequence_16 = { 0355f0 8a45ec 8802 eb0b 8b4d08 034df0 8a55ed }
- $sequence_17 = { 83c005 c3 31b7807c30ae 807c909090 90 bdfd807c90 90 }
- $sequence_18 = { 3bcf 7ce2 8b4dbc 8d9524feffff e8???????? 8d8524feffff 50 }
- $sequence_19 = { 8d3c08 66391e 75e3 8b5df4 }
- $sequence_20 = { 749b 807ce19a80 7c90 90 90 90 }
- $sequence_21 = { 8bcf 8bf0 e8???????? 8945f8 8d45c4 50 8d45f0 }
- $sequence_22 = { 90 90 bffc807c28 1a807c170e81 7cd7 9b }
- $sequence_23 = { 8b75f8 85c0 7412 814df080330000 8d45f0 6a04 50 }
+ $sequence_0 = { e8???????? 8be5 5d c20800 8b45e4 c745b800000000 c745bc00000000 }
+ $sequence_1 = { 52 ff15???????? 8b4508 8b0c85e8c24700 83e102 740d 8d95e4dfffff }
+ $sequence_2 = { ffb5c4e7ffff 8985a0e7ffff ffb5bce7ffff c745ec04000000 }
+ $sequence_3 = { 57 50 8d45f4 64a300000000 8d4dd0 e8???????? }
+ $sequence_4 = { e8???????? 8b85acfeffff 83f810 7212 40 6a01 }
+ $sequence_5 = { eb9b 8b4dfc c1f906 8b55fc 83e23f 6bc230 03048d40e04700 }
+ $sequence_6 = { e8???????? 8845dc c745fc01000000 84c0 0f84b3010000 8d45d0 50 }
+ $sequence_7 = { 8d0c8584d64700 51 e8???????? 83c408 }
+ $sequence_8 = { 64a300000000 68b8000000 8d8598fdffff 6a00 50 e8???????? 68???????? }
+ $sequence_9 = { 8b5508 83e23f 6bd230 8b0c8d40e04700 8844112d 8b45ec d1e0 }
condition:
- 7 of them and filesize <65536
+ 7 of them and filesize <1163264
}
-rule MALPEDIA_Win_Fakerean_Auto : FILE
+rule MALPEDIA_Win_Shadowpad_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a7ea6f88-76f7-54f5-a9b5-14fd4ef8d3d9"
+ id = "c7d36336-f736-58f8-9fa1-3e3ab1239351"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fakerean"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fakerean_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shadowpad"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shadowpad_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "7dfee10ceca58c69279376a54d184530389bbd0c9b8b6dd9a398c5796de2f6f3"
+ logic_hash = "af53d025dfe83e5b7a4ca7b9e68b22a960854fdb5b48b2d1cee2b2ef3fbc15f2"
score = 75
quality = 75
tags = "FILE"
@@ -176852,32 +183863,32 @@ rule MALPEDIA_Win_Fakerean_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 752e 8945fc eb29 395dfc 7524 57 8bce }
- $sequence_1 = { 49 6a01 ff750c 50 57 ff7514 40 }
- $sequence_2 = { ff15???????? 3d14050000 74e5 ff7508 56 57 ff15???????? }
- $sequence_3 = { ff7508 ff15???????? 3bc3 0f8495000000 8b400c 8b00 }
- $sequence_4 = { 59 3bc3 7419 8d5010 e8???????? 8945e0 3bc3 }
- $sequence_5 = { ff35???????? ff15???????? 6800000500 6aec ff35???????? ff15???????? 680000cf06 }
- $sequence_6 = { 741a 81fe00020000 7d12 56 8bc7 e8???????? }
- $sequence_7 = { 8b4df0 6bc018 6bc918 8b4c190c 2b4c1804 f7df }
- $sequence_8 = { f7d8 1bc0 25bfe0ffff 05401f0000 50 ff35???????? ff15???????? }
- $sequence_9 = { 8d45f0 50 8d450c 50 ff15???????? 85c0 7431 }
+ $sequence_0 = { e8???????? 59 8d75dc a3???????? e8???????? 53 ff15???????? }
+ $sequence_1 = { 5b c9 c3 55 8bec b8f8100000 e8???????? }
+ $sequence_2 = { 8bec 53 57 ff7508 ff15???????? 8d7801 }
+ $sequence_3 = { 8d45e8 50 53 8d75d0 }
+ $sequence_4 = { 7e25 8a0c56 8a445601 80e961 2c6a }
+ $sequence_5 = { 50 6a04 5f e8???????? 85c0 75ae 8d4310 }
+ $sequence_6 = { 83ec24 53 56 57 33ff 393d???????? }
+ $sequence_7 = { e8???????? 8b1d???????? 50 ffd3 6800010000 668945f0 }
+ $sequence_8 = { 8bfe 8d45e8 895de8 895dec 895df4 895df0 885df8 }
+ $sequence_9 = { 0fb639 c1ce08 83cf20 03f7 83c102 81f6a3d9357c 663919 }
condition:
- 7 of them and filesize <4071424
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Asruex_Auto : FILE
+rule MALPEDIA_Win_Unidentified_099_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "899abd0f-c835-5f70-819c-92570cc9b462"
+ id = "855e4e32-6d4e-59ad-a575-6df1a0196662"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.asruex"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.asruex_auto.yar#L1-L112"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_099"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_099_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "a14db0e4e44f1156fe16afe843345aa29b9b1f1eb3cc060b10e0bcdf06eb97d4"
+ logic_hash = "258a0ad9f77598150260878a992142883eda125a250cf06189b6139c76537e6e"
score = 75
quality = 75
tags = "FILE"
@@ -176891,32 +183902,32 @@ rule MALPEDIA_Win_Asruex_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 740e 85ed 740a }
- $sequence_1 = { 7408 3c0d 7404 3c0a 7516 }
- $sequence_2 = { 83f801 740e 83f803 7409 83f802 }
- $sequence_3 = { ff15???????? 85c0 7407 3d14270000 }
- $sequence_4 = { 740c 3c09 7408 3c0d 7404 3c0a 7516 }
- $sequence_5 = { 7404 3c58 7505 bb01000000 }
- $sequence_6 = { 3c09 7408 3c0d 7404 3c0a 7516 }
- $sequence_7 = { 3c78 7404 3c58 7505 bb01000000 }
- $sequence_8 = { 3c0d 7404 3c0a 7516 }
- $sequence_9 = { e8???????? 83f8ff 7407 3d0000a000 }
+ $sequence_0 = { 4d8bc4 418bd6 498bcf e8???????? 4c8d8df0010000 458bc6 498bd7 }
+ $sequence_1 = { 488d4808 e8???????? 488d057dec0000 488903 488bc3 }
+ $sequence_2 = { 488d0deb1effff 48c1e602 0fb784b910600100 488d9100570100 488d8d24030000 4c8bc6 4803cb }
+ $sequence_3 = { 0fb6842930ef0100 4883c103 8802 488d5201 4881f959010000 7ce5 4533c9 }
+ $sequence_4 = { 443820 75e4 8bca ffc2 4803c9 }
+ $sequence_5 = { 488bd6 488be8 4d8d4715 488d442468 488bcd 4889442420 e8???????? }
+ $sequence_6 = { 85c0 7424 8b15???????? 33c0 85d2 7418 }
+ $sequence_7 = { 488d5b01 4883ef01 75d8 33c0 488dbdf0010000 }
+ $sequence_8 = { ba02000000 660f1f440000 488d8980000000 0f1000 0f104810 }
+ $sequence_9 = { c7442470fedcba98 c744247476543210 660f1f440000 49ffc0 42803c0000 75f6 488d55d0 }
condition:
- 7 of them and filesize <1564672
+ 7 of them and filesize <314368
}
-rule MALPEDIA_Win_Avast_Disabler_Auto : FILE
+rule MALPEDIA_Win_Magniber_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6a09cca4-7cb6-5c97-b15b-4f7311a6621b"
+ id = "05f5671a-f33b-5211-a81c-43695f05ea5d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.avast_disabler"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.avast_disabler_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.magniber"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.magniber_auto.yar#L1-L164"
license_url = "N/A"
- logic_hash = "19754a7bc503b1b28bdfc059b6eb230f6f3e29b2e990d8ace51bd954a83ec439"
+ logic_hash = "a03ae86175c535bb9d3d882302b08d3c7bb8579783b2000a5224d25eaa155af3"
score = 75
quality = 75
tags = "FILE"
@@ -176930,32 +183941,37 @@ rule MALPEDIA_Win_Avast_Disabler_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7404 3bc1 7515 0f31 35???????? }
- $sequence_1 = { 7534 837c371400 752d 89443714 6a08 8d45f4 50 }
- $sequence_2 = { b94ee640bb 85c0 7404 3bc1 7515 }
- $sequence_3 = { 2b4c3718 51 53 53 50 e8???????? 8b4dfc }
- $sequence_4 = { 50 ff15???????? 6a01 8d45f8 50 ff750c ff15???????? }
- $sequence_5 = { 33c0 40 394510 7534 837c371400 752d }
- $sequence_6 = { 8b5c3718 83c112 03d9 837d1000 }
- $sequence_7 = { 75a9 5f 5e 5b 5d c21000 55 }
- $sequence_8 = { 51 803d????????00 7520 c605????????01 }
- $sequence_9 = { 5f 5e 5b 8be5 5d c20c00 3b0d???????? }
+ $sequence_0 = { 50 e8???????? 83c408 837dfc00 7502 eb31 6a00 }
+ $sequence_1 = { 8b45e8 50 ff15???????? 8b4df4 51 }
+ $sequence_2 = { c785a0fafffff0934000 c785a4fafffff8934000 c785a8faffff00944000 c785acfaffff08944000 }
+ $sequence_3 = { 50 8b4df4 51 ff15???????? 8b45f8 99 }
+ $sequence_4 = { 83c408 8b4dfc 8b55f8 6689044a }
+ $sequence_5 = { c7852cfbffff14954000 c78530fbffff1c954000 c78534fbffff24954000 c78538fbffff2c954000 c7853cfbffff34954000 c78540fbffff40954000 }
+ $sequence_6 = { 66894da4 ba2f000000 668955a6 b853000000 668945a8 b943000000 }
+ $sequence_7 = { 0f842e010000 660f57c0 660f1345b0 6a00 8d4df8 51 6a10 }
+ $sequence_8 = { f76e9f 32d8 2d7a350e78 95 }
+ $sequence_9 = { 4834b0 184026 e221 a1????????05eef081 e0f8 29aed0515fa6 8d4f0e }
+ $sequence_10 = { 56 18cb 52 fc 285f44 c1c70d 11fb }
+ $sequence_11 = { e8???????? 32cb 5a b3b1 }
+ $sequence_12 = { 4e4e54 70ac 52 f8 a6 6e }
+ $sequence_13 = { 29aed0515fa6 8d4f0e 7f4c c82cd1c6 1a32 b636 }
+ $sequence_14 = { 5a b3b1 3e6c 21746c2e 4834b0 184026 }
condition:
- 7 of them and filesize <41984
+ 7 of them and filesize <117760
}
-rule MALPEDIA_Win_Acehash_Auto : FILE
+rule MALPEDIA_Win_Fonix_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "14f9c3a4-6e4e-554e-b1b7-7826b028e7e0"
+ id = "bd0f7338-d5ae-57b4-8254-a4a394cfa806"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acehash"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.acehash_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fonix"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fonix_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "a82974d1f4758bd3335b7cc99825d249f1ec423d226c32410d6047b493cb8d39"
+ logic_hash = "a1de19ea9d27789030065bff520751643f536c0deae9fbccf8fe2c31cafb92ef"
score = 75
quality = 75
tags = "FILE"
@@ -176969,32 +183985,32 @@ rule MALPEDIA_Win_Acehash_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4885c0 7420 488d1599dc0200 488bcb ff15???????? 488bc8 }
- $sequence_1 = { 85c0 0f85e6000000 4c8b470c 488b55d0 488b4f04 ff15???????? 8bd8 }
- $sequence_2 = { 488b7d98 8b742440 8b542458 41bb00020000 4c8d0d4e23feff 448a3f 4584ff }
- $sequence_3 = { 7510 b810000000 488b5c2430 4883c420 5f c3 4885db }
- $sequence_4 = { 85ff 0f8513ffffff 33c0 4c8b642450 4c8b6c2458 488b5c2460 4883c430 }
- $sequence_5 = { 442b8486a0e10300 4533d8 83bf800000000a 0f863c010000 8b4730 8b4f70 458d0c03 }
- $sequence_6 = { 8bc3 483bd0 0f871a050000 4c8d151995fdff 4403f2 4b8b8ceaa0511100 8a443108 }
- $sequence_7 = { 8bfd 66895802 410fb78704100000 0fbfcb }
- $sequence_8 = { 7cda 440fbf4302 418bd4 488bce 468d048508000000 e8???????? 488d0d33240300 }
- $sequence_9 = { 48833d????????00 488d0581900300 740f 3908 740e 4883c010 4883780800 }
+ $sequence_0 = { 50 8d5508 c645fc0e 8d8df4fbffff e8???????? 51 51 }
+ $sequence_1 = { 83c408 85ff 0f8533ffffff 0f1045a8 8bb56cffffff 0f114590 f30f7e45b8 }
+ $sequence_2 = { c1c107 894c2434 8b4c2428 03ca 33f1 c1c610 03c6 }
+ $sequence_3 = { 8b7d74 8d4500 57 50 ff7578 8d4530 c645fc0a }
+ $sequence_4 = { c645fc1e e8???????? c645fc1f 68???????? 8d8d68fdffff e8???????? 68???????? }
+ $sequence_5 = { e8???????? bf6e060000 c645fc0a 57 e8???????? 59 8bf0 }
+ $sequence_6 = { 8bf0 ff5208 0faff0 8d4b0c 56 e8???????? }
+ $sequence_7 = { 8d8d0cfcffff e8???????? 83ec18 8d4508 }
+ $sequence_8 = { 8d4101 898d7cffffff 50 8d4dd8 e8???????? 8bd0 8b856cffffff }
+ $sequence_9 = { 50 56 e8???????? 83c40c 84c0 7404 }
condition:
- 7 of them and filesize <2318336
+ 7 of them and filesize <2226176
}
-rule MALPEDIA_Win_Mirai_Auto : FILE
+rule MALPEDIA_Win_Darkshell_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "81ec826d-82b4-5432-816d-754db384603c"
+ id = "54238af5-7449-55bf-9dc2-08b5916a169b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mirai"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mirai_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkshell"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkshell_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "141eec0723c6032d1109e3ff4e6c77adfb4c0eb70a7f0ab199e555f3b3d9eb19"
+ logic_hash = "b58c1bc2e0988d2ff26125d2777445ac18dab56ca2991d83e57c5d570ae3c235"
score = 75
quality = 75
tags = "FILE"
@@ -177008,32 +184024,32 @@ rule MALPEDIA_Win_Mirai_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 83c408 85c0 7535 8b742408 50 68???????? }
- $sequence_1 = { 8b8d48feffff e8???????? 8d4db0 e8???????? 8365fc00 83a578feffff00 8d8554feffff }
- $sequence_2 = { e8???????? 83c40c 5d c3 8b5510 8b450c 8b4904 }
- $sequence_3 = { 8bf3 c1ee18 334cb500 8b2d???????? 0fb6f2 334cb500 8b35???????? }
- $sequence_4 = { 8bcd e8???????? 8bc8 e8???????? 8b10 8b12 6a5c }
- $sequence_5 = { e8???????? 8b54244c 56 53 52 53 ff15???????? }
- $sequence_6 = { c3 55 8bec 51 51 6a17 68???????? }
- $sequence_7 = { c20400 55 8bec 83ec14 894df0 c745f401000000 837df400 }
- $sequence_8 = { 8bbcbd00100000 81e70000ff00 33f7 0fb6fd 8bbcbd00100000 81e700ff0000 33f7 }
- $sequence_9 = { e8???????? 8365f800 8b45fc c9 c3 55 8bec }
+ $sequence_0 = { 83c004 8901 83c014 8902 6681380b01 7511 }
+ $sequence_1 = { 6a00 6a00 50 53 ffd5 8be8 }
+ $sequence_2 = { 7413 8b4c2410 8b54240c 51 52 ffd0 }
+ $sequence_3 = { ff542414 53 ff542414 56 ff15???????? }
+ $sequence_4 = { 8d542418 6a04 52 684be12200 50 }
+ $sequence_5 = { e8???????? 8b4c2414 8bf0 8b442418 6800400000 50 }
+ $sequence_6 = { 89442418 ffd7 6a00 6a00 6a00 6a00 }
+ $sequence_7 = { 55 ff542424 55 ff542414 53 }
+ $sequence_8 = { 8902 6681380b01 7511 8b4c2410 05e0000000 8901 b801000000 }
+ $sequence_9 = { ff15???????? 8b542410 8d4c2414 51 6a04 52 }
condition:
- 7 of them and filesize <7086080
+ 7 of them and filesize <344064
}
-rule MALPEDIA_Win_Logpos_Auto : FILE
+rule MALPEDIA_Win_Unidentified_077_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1863375d-233c-50fe-9230-efcb27bcbb2c"
+ id = "882d313e-f7f0-5285-8af9-6252268fd85d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.logpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.logpos_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_077"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_077_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "c3acfde126a6fa182645fe56f6caf8ed6c2b8f53215730338bb39d48d6bd3dac"
+ logic_hash = "40d4971486b6904e4039a2237673f8c9270e32fac79f99c950b8e92b2f7aa0ab"
score = 75
quality = 75
tags = "FILE"
@@ -177047,32 +184063,32 @@ rule MALPEDIA_Win_Logpos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 89e5 0fb64508 83f830 0f8c13000000 83f839 0f8f0a000000 }
- $sequence_1 = { 89ec 5d c3 55 89e5 83ec20 53 }
- $sequence_2 = { 884c2408 0fb6442408 83f841 0f8c09000000 83f85a 0f8e37000000 0fb6442408 }
- $sequence_3 = { 53 e8???????? 894330 682a5a9294 ff33 ff7370 }
- $sequence_4 = { 8b4d10 8a450c 8b7d08 fc f3aa 61 }
- $sequence_5 = { ff9380000000 48 83c420 48 85f6 7409 48 }
- $sequence_6 = { c785f8fbffff01000000 68f4010000 ff15???????? 0fb69507fcffff b90f000000 }
- $sequence_7 = { 83f800 0f8537000000 833d????????00 0f852a000000 837d1400 0f848c000000 }
- $sequence_8 = { 5a c9 c3 41 52 }
- $sequence_9 = { 0f8549000000 8b45fc c680a360400000 8b45fc }
+ $sequence_0 = { 89442420 488bcf ff15???????? 85c0 }
+ $sequence_1 = { 488bcf ff15???????? 498bce ff15???????? 488bce }
+ $sequence_2 = { 488bb424f00d0000 488b8dd00c0000 4833cc e8???????? 4881c4f80d0000 }
+ $sequence_3 = { 0f8559ffffff 488bcf ff15???????? 498bce ff15???????? 488bce ff15???????? }
+ $sequence_4 = { 498784f180bf0100 eb25 488bc3 498784f180bf0100 4885c0 }
+ $sequence_5 = { 4d8be1 498be8 4c8bea 4b8b8cf7e0c70100 4c8b15???????? }
+ $sequence_6 = { 33db 33ff 4c8bea 4c8be1 4883fa40 7312 }
+ $sequence_7 = { f30f6f0418 660fefc1 f30f7f0418 8d4210 83c220 f30f6f0418 660fefc1 }
+ $sequence_8 = { 0f8559ffffff 488bcf ff15???????? 498bce }
+ $sequence_9 = { e8???????? 85c0 0f85c6000000 448b442468 }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <270336
}
-rule MALPEDIA_Win_Croxloader_Auto : FILE
+rule MALPEDIA_Win_Bluenoroff_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4c54923c-05d0-5bcf-b03e-4330bb61dd7a"
+ id = "c5a8ede1-c77a-5a4b-899a-3e41c1e4e510"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.croxloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.croxloader_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bluenoroff"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bluenoroff_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "c88e829bb61a0a12fc0c92bdb08f88ad90c78cd22176146404aa71918162c3b2"
+ logic_hash = "65b6fe6298815292c6af264e82e027897f56c9c87e000fed42924fa12c98e75b"
score = 75
quality = 75
tags = "FILE"
@@ -177086,32 +184102,32 @@ rule MALPEDIA_Win_Croxloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488d0dd0590100 eb0c 83f901 750d 488d0dda590100 }
- $sequence_1 = { 498b84ff18910100 90 493bc6 0f84eb000000 4885c0 }
- $sequence_2 = { 4883ec20 488364243800 4c8d442438 8bd9 488d157aa80000 33c9 }
- $sequence_3 = { 4b8b84e010970100 42804cf03d04 38558f ebcc ff15???????? }
- $sequence_4 = { 488d0d09520100 e8???????? 488d0d05520100 e8???????? 488b0d???????? e8???????? 488b0d???????? }
- $sequence_5 = { 4883f9ff 7406 ff15???????? 48832300 4883c308 488d05fc240100 }
- $sequence_6 = { 4c8d0562eb0000 83e23f 488bcb 48c1f906 488d14d2 498b0cc8 8064d138fd }
- $sequence_7 = { 8938 e8???????? 488d1db32f0100 4885c0 }
- $sequence_8 = { 4c8d05c9890100 ba920e0332 b95595db6d e8???????? 4c8d05038a0100 ba436a459e b9edb0da1e }
- $sequence_9 = { 3b1d???????? 736a 488bc3 4c8d35de000100 83e03f 488bf3 48c1fe06 }
+ $sequence_0 = { 83f802 750e 8d95fcfffeff 52 68???????? }
+ $sequence_1 = { 8d8df8feffff 51 ff15???????? 0fbe95f8feffff 68???????? }
+ $sequence_2 = { 85f6 743a 8d85fcfffeff 50 }
+ $sequence_3 = { 894e04 e8???????? 83c40c 5f }
+ $sequence_4 = { eb10 85c0 7514 8d85fcfffeff 50 68???????? }
+ $sequence_5 = { 83feff 7433 8d4e01 51 6a40 }
+ $sequence_6 = { 68ffff0000 50 e8???????? 33c0 }
+ $sequence_7 = { 56 6a10 68???????? e8???????? 83c410 813ed0c0b0a0 }
+ $sequence_8 = { 33ff 53 ff15???????? 8b450c 85c0 7402 }
+ $sequence_9 = { 50 0fb785f4fffeff 51 52 }
condition:
- 7 of them and filesize <241664
+ 7 of them and filesize <303104
}
-rule MALPEDIA_Win_Nautilus_Auto : FILE
+rule MALPEDIA_Win_Chinad_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bd0f8568-9347-5c4b-aef6-8e7929cf6017"
+ id = "55179322-c960-5946-aa14-87280de490d7"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nautilus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nautilus_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chinad"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chinad_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "6e0983236c8ba852bb2af3aa295c07b825fa6ac12512321743324e3ea59238a7"
+ logic_hash = "f63725bd92056d22834dfb19b05368c2071df890649a72d3254d014778d263a0"
score = 75
quality = 75
tags = "FILE"
@@ -177125,34 +184141,34 @@ rule MALPEDIA_Win_Nautilus_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8bcf e8???????? 8bd8 8bcd e8???????? 85db 8bce }
- $sequence_1 = { 85c0 740c 488b4598 4833c7 e9???????? c74424200f000000 e9???????? }
- $sequence_2 = { 8bfe 486313 488d0dcc340600 f6040a02 744b 418d46fa 488bcb }
- $sequence_3 = { 85c0 7892 488d4c2430 498bd4 e8???????? 85c0 7981 }
- $sequence_4 = { ba03000000 4d8bc5 8d4aff e8???????? 4c8be0 4885c0 7509 }
- $sequence_5 = { 85f6 750c 33c0 eb3a 488b0b 49890e eb30 }
- $sequence_6 = { 85c0 79d6 4c8d45cf 488d55cf 488d4db7 e8???????? 8bd8 }
- $sequence_7 = { eb07 c745e006000000 488d45e0 41b912000000 4d8bc4 498bd5 488bcf }
- $sequence_8 = { 4883f803 0f8cef010000 488bd3 488bcd ff95c8010000 85c0 0f8599feffff }
- $sequence_9 = { e8???????? 85c0 7531 488d4db0 33d2 e8???????? 85c0 }
+ $sequence_0 = { c7850cffffff00000000 eb55 c78550ffffffbc264300 8b9550ffffff 83c201 8995b4feffff 8b8550ffffff }
+ $sequence_1 = { 8b85a8feffff 899485acfeffff e9???????? b904000000 6bd100 8b4508 8b0c10 }
+ $sequence_2 = { 2bf8 8bc2 c1f819 03f0 897dec c1e019 }
+ $sequence_3 = { 895de8 1bde 0145f4 8b75ac 119d7cffffff 8b5dec 81c300001000 }
+ $sequence_4 = { 0fa4c119 c1ee07 c1e019 0bd1 0bf0 31b514fdffff }
+ $sequence_5 = { 0fa4f701 6a13 03f6 03b55cffffff 89b560ffffff 137dcc 81c600000001 }
+ $sequence_6 = { c1c802 33c8 8b85d4feffff 8bd8 03ca 2385d8feffff }
+ $sequence_7 = { 81d7745dbe72 019d14fdffff 11bd38fdffff 33d2 0facc81c c1e604 }
+ $sequence_8 = { 8b4e24 83c40c c1e903 b838000000 83e13f 83f938 7205 }
+ $sequence_9 = { b894280000 e8???????? a1???????? 33c5 8945fc c78570d7ffff80280000 8d8570d7ffff }
condition:
- 7 of them and filesize <1302528
+ 7 of them and filesize <598016
}
-rule MALPEDIA_Win_Ghostemperor_Auto : FILE
+rule MALPEDIA_Win_Zumanek_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "22543585-64e5-59d9-a95f-0fb017ff004e"
+ id = "87aee693-fd24-5045-ad68-bbf967fca577"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ghostemperor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ghostemperor_auto.yar#L1-L228"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zumanek"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zumanek_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "91e3702f968d398f5f44f42cafec6cc32480eb0e4729b0b5f30643c45ff1a402"
+ logic_hash = "692948458546aa7f1172f720f7a047815fbd39df276c694923c84a71f1135e40"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -177164,45 +184180,32 @@ rule MALPEDIA_Win_Ghostemperor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { b801000000 4883c428 5b 5d 5f 5e }
- $sequence_1 = { 31d2 41b801000000 4531c9 ff15???????? }
- $sequence_2 = { 41c1ea03 4183e007 4585d2 0f84b9000000 }
- $sequence_3 = { 8b5b10 4885db 7431 c7471800000000 89d9 }
- $sequence_4 = { e8???????? 48c7470800000000 c7471000000000 4c8d7e18 4c89f9 ff15???????? 448b4648 }
- $sequence_5 = { 4885c9 740d e8???????? 48c7460800000000 }
- $sequence_6 = { 4989c9 4889d0 458d5aff 41f6c203 7427 4489d1 83e103 }
- $sequence_7 = { 4883c410 c3 ff25???????? ff25???????? ff25???????? ff25???????? ff25???????? }
- $sequence_8 = { 4889c1 4863c6 488d0440 48c1e004 4801c8 eb02 31c0 }
- $sequence_9 = { 31f6 31d2 660f1f440000 488b3cf0 49313cf1 }
- $sequence_10 = { c74424504900df00 c744245436004d00 c74424586b007100 c744245cf5003400 }
- $sequence_11 = { 0f8883020000 33d2 c78594000000f1008500 c78598000000a8003f00 448d630e c7859c000000f7003100 }
- $sequence_12 = { 01c1 89ca c1ea1f c1f904 }
- $sequence_13 = { 488d4dd0 48895dd8 895de0 4c8bea e8???????? be08020000 8bce }
- $sequence_14 = { 00c2 488b8568020000 8854080c 488b85b0020000 }
- $sequence_15 = { 00c1 488b8568020000 488b95b0020000 884c100c 488b85b0020000 488b85b0020000 488b85b0020000 }
- $sequence_16 = { 85c0 7417 418bce 448bc7 48034e08 488bd5 e8???????? }
- $sequence_17 = { 7212 4d8b5a10 4d85db 7409 48895c2448 5b }
- $sequence_18 = { 01c3 69cbe8030000 81c130750000 4883ec20 }
- $sequence_19 = { 01d1 89ca c1e205 89cb }
- $sequence_20 = { 7449 8b5c2448 488bc7 d1eb ffcb }
- $sequence_21 = { 48895c2408 57 4883ec20 488d0557540000 488bd9 488901 }
- $sequence_22 = { c3 83c8ff ebf5 b801000000 ebee }
+ $sequence_0 = { fc 81fe382e9330 97 e412 3dd16312c9 103f 0800 }
+ $sequence_1 = { 8802 98 811212242434 48 3c91 4a }
+ $sequence_2 = { 894612 4d 2454 48 5b 91 }
+ $sequence_3 = { 71ef 1a6f35 e30b 5d fc 77f2 f1 }
+ $sequence_4 = { 1dba45e22f 91 7c8b e459 0920 122424 }
+ $sequence_5 = { 386b95 4c 53 196a17 }
+ $sequence_6 = { 4a e8???????? 86b71986f742 06 58 4c 8812 }
+ $sequence_7 = { c101f6 53 32b879629b65 76a2 43 fc }
+ $sequence_8 = { d9c3 ab 5f c50f 9d 54 f233591b }
+ $sequence_9 = { 5a c59cd53a93a658 98 9f f5 6b80e7fa856bb2 55 }
condition:
- 7 of them and filesize <1115136
+ 7 of them and filesize <58867712
}
-rule MALPEDIA_Win_Shipshape_Auto : FILE
+rule MALPEDIA_Win_Banjori_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "77ebf79f-670a-594a-bd26-db4684807e7a"
+ id = "0d7b2a6e-e2ca-5160-9081-9a7cfdf5e1be"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shipshape"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shipshape_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.banjori"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.banjori_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "d30091c6ebd49f11de789ea622fcb4cbfab75e230e1b049ba06177bb5b7dc7cb"
+ logic_hash = "9dcfb5d77d585c9251303d49a0603c551cff0efcfccd66cc7c87519a0e64ecdd"
score = 75
quality = 75
tags = "FILE"
@@ -177216,32 +184219,32 @@ rule MALPEDIA_Win_Shipshape_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? 68???????? 8d942440020000 68???????? 52 }
- $sequence_1 = { 83e103 50 f3a4 ffd3 e9???????? 56 e8???????? }
- $sequence_2 = { 68???????? 8d942440020000 68???????? 52 e8???????? 83c434 }
- $sequence_3 = { c1f905 8b0c8d60d54000 f644c10401 8d04c1 7403 8b00 }
- $sequence_4 = { 8d542438 8d842400070000 52 50 }
- $sequence_5 = { 8d84244c040000 68???????? 50 e8???????? 8d8c2454040000 51 }
- $sequence_6 = { 8d4c2414 50 51 6a00 6a00 6a00 }
- $sequence_7 = { 5b 81c440060000 c3 56 57 }
- $sequence_8 = { 50 51 ffd3 5f 5e 33c0 }
- $sequence_9 = { 83c418 3bc6 7e0f 5f 5e }
+ $sequence_0 = { 6800010000 e8???????? 8945f4 81f9000c0000 7308 e8???????? 8945f0 }
+ $sequence_1 = { 50 ff15???????? ffb5a0feffff e8???????? 53 53 53 }
+ $sequence_2 = { 68???????? ff75fc ff15???????? 53 ff75fc ff15???????? 68???????? }
+ $sequence_3 = { ff750c 53 53 53 53 ff7508 ff35???????? }
+ $sequence_4 = { 78e1 8945e8 eb18 8d85aafeffff 50 ff75e8 ff15???????? }
+ $sequence_5 = { 85c0 7539 68???????? e8???????? 85c0 752b }
+ $sequence_6 = { 6802000080 e8???????? 85c0 0f85fe000000 895df0 8d45f0 50 }
+ $sequence_7 = { 8945f4 8d45f8 50 6819000200 6a00 68???????? 6802000080 }
+ $sequence_8 = { 50 ff35???????? e8???????? e9???????? c745f864000000 68???????? ff15???????? }
+ $sequence_9 = { 6a10 8d45b4 50 ff75c4 ff15???????? 85c0 0f883a020000 }
condition:
- 7 of them and filesize <338386
+ 7 of them and filesize <139264
}
-rule MALPEDIA_Win_Nexster_Bot_Auto : FILE
+rule MALPEDIA_Win_Halfrig_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f3849f7f-92fa-5a27-8fce-5cf70a6092f1"
+ id = "4f3cbac9-fb70-5f5f-a1a6-aa00243a3db8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nexster_bot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nexster_bot_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.halfrig"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.halfrig_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "68d99297d7676950ef20645c2f54f180e697aada925cf75041287d48b2b4b344"
+ logic_hash = "fd3e289580ee05538ff1447ee4a76bbaba1a2cf6f44fe795cbd300f7fc8296a1"
score = 75
quality = 75
tags = "FILE"
@@ -177255,32 +184258,32 @@ rule MALPEDIA_Win_Nexster_Bot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 e8???????? 68ff030000 8d85bd090000 }
- $sequence_1 = { ff15???????? 668985ae010000 6a10 8d85ac010000 50 57 }
- $sequence_2 = { 7d10 668b4c4310 66890c45186e4100 40 ebe8 33c0 }
- $sequence_3 = { 03f9 837d1810 7208 8b5d04 }
- $sequence_4 = { 33c0 8da42400000000 8a1485d0604100 889405000e0000 40 83f80b }
- $sequence_5 = { 731a 8bc8 83e01f c1f905 8b0c8d20804100 c1e006 03c1 }
- $sequence_6 = { 81c404040000 c3 53 56 57 8bf8 }
- $sequence_7 = { 66898c24bc010000 e9???????? 8b15???????? a1???????? 8b0d???????? 899424b0010000 }
- $sequence_8 = { 68???????? 52 e8???????? 68???????? 8d85bc110000 50 }
- $sequence_9 = { 8a08 40 84c9 75f9 8dbdbc150000 2bc6 4f }
+ $sequence_0 = { 833d????????ff 752a 488d0dee900400 c705????????679f9b01 c705????????6680ec92 c705????????3f7d27f5 e8???????? }
+ $sequence_1 = { 833d????????ff 7539 488d0d67740400 66c705????????fd01 c705????????6881e28d }
+ $sequence_2 = { e8???????? 488d0d6c950700 e8???????? 40383d???????? 7435 660f1f440000 }
+ $sequence_3 = { 75ad 0fb600 498bcf 8802 488d542420 e8???????? 488d0d58c70600 }
+ $sequence_4 = { 48c1e008 488bd1 49ffc0 4833d0 4983f80f 72db 408835???????? }
+ $sequence_5 = { 8802 488d542420 e8???????? 488d0d4cef0900 e8???????? 40383d???????? }
+ $sequence_6 = { 488d542420 e8???????? 488d0d08830600 e8???????? 40383d???????? 7435 488bd3 }
+ $sequence_7 = { 75ad 0fb600 498bcf 8802 488d542420 e8???????? 488d0df8da0500 }
+ $sequence_8 = { 8802 488d542420 e8???????? 488d0df8930600 e8???????? 40383d???????? }
+ $sequence_9 = { 488d0d88080800 e8???????? 40383d???????? 7435 }
condition:
- 7 of them and filesize <245760
+ 7 of them and filesize <1369088
}
-rule MALPEDIA_Win_Apocalypse_Ransom_Auto : FILE
+rule MALPEDIA_Win_7Ev3N_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d42c3028-47d8-5c2a-8245-ee48597fdb68"
+ id = "cf231267-d18f-5fab-bbdf-ab3bf00ba51c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.apocalypse_ransom"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.apocalypse_ransom_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.7ev3n"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.7ev3n_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "3006a8aede4427b243aedfb686311f3de66b1be38f627de23e7cfc996b17033d"
+ logic_hash = "3d3793244c4ff8a9f87ce7ce50051977c17fdc03ef0f8a315973a688f14f4ceb"
score = 75
quality = 75
tags = "FILE"
@@ -177294,32 +184297,32 @@ rule MALPEDIA_Win_Apocalypse_Ransom_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 68???????? 8d84240c040000 50 ff15???????? 85c0 742f }
- $sequence_1 = { 83f8ff 755f 6a01 8d44240c 50 8d8c2410040000 }
- $sequence_2 = { 0bfb ff15???????? 33d2 83f802 }
- $sequence_3 = { 8d4c2410 68???????? 51 ff15???????? 83c410 6a00 6a00 }
- $sequence_4 = { ffd6 b801000000 5e 83c418 c3 33c0 }
- $sequence_5 = { 68???????? 6a00 ffd7 8bf0 85f6 7504 5f }
- $sequence_6 = { 83f8ff 7411 50 ff15???????? 8d0424 50 ff15???????? }
- $sequence_7 = { 83c40c 57 53 ff15???????? 6800800000 }
- $sequence_8 = { ffd7 85c0 7440 8b1d???????? 8b2d???????? 8b542410 8d4c2410 }
- $sequence_9 = { 6a03 6800000040 52 ffd6 }
+ $sequence_0 = { 8d8dd0cdffff e8???????? 8bce 2bcf 3bc1 0f8402b10000 }
+ $sequence_1 = { 8bd4 89a50cf9ffff c7421407000000 c7421000000000 668902 66398560ffffff 7504 }
+ $sequence_2 = { 894104 a0???????? 884108 6a00 8d8504ffffff 50 }
+ $sequence_3 = { c785e4fdffff00000000 6a00 c785e0fdffffd0a54500 ff15???????? 33c0 c705????????07000000 }
+ $sequence_4 = { 8d85acefffff 50 8d8dd0cdffff e8???????? 8bce 2bcf }
+ $sequence_5 = { 6a00 8d85fcfeffff 50 8d8dd0cdffff e8???????? 8bce 2bcb }
+ $sequence_6 = { 8dbd38f1ffff 8d4f02 0f1f840000000000 668b07 83c702 6685c0 75f5 }
+ $sequence_7 = { 8b0c8d20934500 80643128fd 5f 5e 8be5 5d c3 }
+ $sequence_8 = { f30f7e05???????? 660fd68564e6ffff 0fb705???????? 6689856ce6ffff f30f7e05???????? 660fd68558e6ffff 0fb705???????? }
+ $sequence_9 = { 0f84724c0000 8dbda0ddffff 8d4f02 0f1f840000000000 668b07 83c702 6685c0 }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <803840
}
-rule MALPEDIA_Win_Ncctrojan_Auto : FILE
+rule MALPEDIA_Win_Moonbounce_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "964a63a1-2a33-5eff-ac10-defb358349c1"
+ id = "c186ffa8-3b28-566b-9f82-5819628ca523"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ncctrojan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ncctrojan_auto.yar#L1-L159"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moonbounce"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moonbounce_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "ca1178d41ac898e0a6dcd72371fc848e91a6cf3f5857a4b6b78db9de7f47f454"
+ logic_hash = "081fa4bc70b28c3a98dc6caeb9104489e42b513d1d76e6dfbd571155c86ff551"
score = 75
quality = 75
tags = "FILE"
@@ -177333,38 +184336,32 @@ rule MALPEDIA_Win_Ncctrojan_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7536 8b85e8feffff 85c0 750a 68???????? }
- $sequence_1 = { 68???????? e9???????? 83f801 750a }
- $sequence_2 = { 83f801 750a 68???????? e9???????? 83f802 }
- $sequence_3 = { 68e9fd0000 ffd6 8d8decfdffff 5f 8d5102 5e 668b01 }
- $sequence_4 = { 8b442420 83c40c 83c008 836c240c01 89442414 0f85fffdffff }
- $sequence_5 = { 8d4a10 0f1f840000000000 0f1041f0 83c020 }
- $sequence_6 = { ffd6 50 8d85dcfdffff 50 }
- $sequence_7 = { e8???????? 83c40c 85c0 752f 6a06 8d85c4bfffff }
- $sequence_8 = { 51 f2c3 8b4df0 33cd f2e8bef6ffff }
- $sequence_9 = { 83c414 e8???????? 84c0 7517 }
- $sequence_10 = { 33c5 8945fc 56 6890010000 }
- $sequence_11 = { 83faff 0f94c0 84c0 7405 }
- $sequence_12 = { 83c418 83c008 03c6 8bcf }
- $sequence_13 = { 0fb601 50 8d45d0 68???????? 50 }
- $sequence_14 = { 83ec14 c645fc1f 8d95e8feffff 8bcc }
- $sequence_15 = { 668bc1 8be5 5d c3 56 8bf1 }
+ $sequence_0 = { 7413 8d041e 85c0 0f8407feffff ff7704 6a01 }
+ $sequence_1 = { 3bfe 7426 56 56 56 56 }
+ $sequence_2 = { 6a04 6800200000 ff7650 50 ff5708 8bd8 85db }
+ $sequence_3 = { 8b5de8 5e 5f 8bc3 5b }
+ $sequence_4 = { 833800 7413 8345fc04 8b45fc 8b00 }
+ $sequence_5 = { 56 57 6a30 33ff 57 ff15???????? }
+ $sequence_6 = { a3???????? 3935???????? 7441 3935???????? }
+ $sequence_7 = { 8d45e8 50 ffd7 84c0 0f8482000000 }
+ $sequence_8 = { 8b400c 85c0 0f8495000000 03c3 50 ff570c }
+ $sequence_9 = { 3bfe 7426 56 56 56 56 68???????? }
condition:
- 7 of them and filesize <1160192
+ 7 of them and filesize <70912
}
-rule MALPEDIA_Win_Ghost_Rat_Auto : FILE
+rule MALPEDIA_Win_Vobfus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a811e919-423f-5da5-9744-a836ad0cfe7b"
+ id = "379cd9d3-d698-58d1-90c1-aa0d12f74cc4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ghost_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ghost_rat_auto.yar#L1-L294"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vobfus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vobfus_auto.yar#L1-L221"
license_url = "N/A"
- logic_hash = "566fcbf38da6404d1cfb5b85cb33273a727f786f21d6a86dff53a4e450ad50b1"
+ logic_hash = "87942ff8c467cfeb6529bdba1fb2a14574a28472aae2c0f0acabf5e6455fc919"
score = 75
quality = 73
tags = "FILE"
@@ -177378,56 +184375,47 @@ rule MALPEDIA_Win_Ghost_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a01 56 ff15???????? 5e c20800 }
- $sequence_1 = { 8bd9 e8???????? 8b4d08 3bc8 }
- $sequence_2 = { 8b400c 85c0 7505 a1???????? 50 8bce }
- $sequence_3 = { 8be5 5d c20400 894df4 }
- $sequence_4 = { 894df4 c745f800000000 df6df4 83ec08 dc0d???????? }
- $sequence_5 = { 6a6b 8bce e8???????? 5f }
- $sequence_6 = { e8???????? 8b8e549f0000 83c41c 89848e14030000 8b86549f0000 }
- $sequence_7 = { 8d7b01 c60396 f3a5 53 8bcd }
- $sequence_8 = { 8db714030000 8b06 6aff 50 }
- $sequence_9 = { 8b5614 8b02 8b400c 85c0 }
- $sequence_10 = { e9???????? 8d45dc 50 681f000200 }
- $sequence_11 = { 50 ff15???????? ffb6a8000000 ff15???????? ffb6ac000000 }
- $sequence_12 = { 8dbd85feffff f3ab 66ab aa }
- $sequence_13 = { 6a00 6a00 c705????????20010000 e8???????? 8b35???????? }
- $sequence_14 = { e8???????? 8d85c0feffff 50 57 ff15???????? 8bf8 83ffff }
- $sequence_15 = { 83c40c 8d85b8feffff 50 8d85b4fdffff }
- $sequence_16 = { 8bce e8???????? 8b4df4 5f b001 5e }
- $sequence_17 = { 8bf0 83c40c 46 750b 5f 5e 33c0 }
- $sequence_18 = { ff15???????? 6a01 ff7620 ff15???????? 8b4e04 e8???????? }
- $sequence_19 = { ff7510 ff75dc ff15???????? 85c0 7507 c745e401000000 834dfcff }
- $sequence_20 = { 56 53 e8???????? 83c408 84c0 750b }
- $sequence_21 = { 68???????? 50 6802000080 e8???????? 83c41c 5f 5e }
- $sequence_22 = { 6a00 50 e8???????? 83c40c ff7508 6a40 ff15???????? }
- $sequence_23 = { 8365fc00 ff7508 ff15???????? 40 50 ff15???????? 59 }
- $sequence_24 = { 8b4608 8b7e20 8b36 813f6b006500 7406 }
- $sequence_25 = { c7014c696272 83e9fc c70161727941 83e9fc }
- $sequence_26 = { 813f6b006500 7406 813f4b004500 75e8 }
- $sequence_27 = { c7014c6f6164 83e9fc c7014c696272 83e9fc }
- $sequence_28 = { 7475 8b45bc 8b08 894db4 }
- $sequence_29 = { 8911 eb26 8b45b4 8b4d08 8d540102 }
- $sequence_30 = { 8b55dc 8b7a18 8b7220 0375f8 33c9 }
- $sequence_31 = { 6bc928 8b9538ffffff 8b8560ffffff 03440a0c 8985fcfeffff }
+ $sequence_0 = { 8b5508 8b92e8000000 8b82841d0000 50 50 8b10 }
+ $sequence_1 = { 8b5508 8b92e8000000 8b825c1e0000 50 }
+ $sequence_2 = { 8bec 8b5508 8b92e8000000 8b82c8150000 }
+ $sequence_3 = { 8b8220000000 50 50 8b10 ff5204 58 }
+ $sequence_4 = { 8b5508 8b92e8000000 8b8200080000 50 }
+ $sequence_5 = { 8b5508 8b92e8000000 8b82b4230000 50 }
+ $sequence_6 = { 8b5508 8b92e8000000 8b82d0130000 50 }
+ $sequence_7 = { 8b5508 8b92e8000000 8b829c0e0000 50 }
+ $sequence_8 = { f3ed ebf2 ed ec }
+ $sequence_9 = { ec f2ed ec f2ed ec f3ed }
+ $sequence_10 = { f2e8fae6d5f6 d2b5f2bb8ff3 ae 73f3 aa 5c f6ac4ff8b54ffb }
+ $sequence_11 = { 801800 0808 0006 3401 41 06 }
+ $sequence_12 = { 7cc8 dc7acd e291 d2e8 }
+ $sequence_13 = { 8631 96 0a7f25 7a43 92 9afc9e5780451f }
+ $sequence_14 = { 0c38 a95bedb2e5 759e 3a9b423ceb9d 65be2dafffcd 3624e4 6bee88 }
+ $sequence_15 = { 4b ce 8ca4b11e13b793 73aa fa }
+ $sequence_16 = { 48 0008 78ff 0d50004900 3e3cff 46 }
+ $sequence_17 = { 5c f6ac4ff8b54ffb c058fcca 61 }
+ $sequence_18 = { 46 14ff 0470 fe0a }
+ $sequence_19 = { e752 47 625403a7 78f5 06 95 }
+ $sequence_20 = { 6c 74ff 801800 0808 }
+ $sequence_21 = { b909dfd18c 9d 7454 2bcd 8ab411746337ed 80ab931e2e5e88 }
+ $sequence_22 = { c8ed9459 ef 60 226aa3 60 8907 6bdd97 }
condition:
- 7 of them and filesize <357376
+ 7 of them and filesize <409600
}
-rule MALPEDIA_Win_Darkpulsar_Auto : FILE
+rule MALPEDIA_Win_Highnote_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b29c7cf0-59bf-59a4-b8c5-d1ee53d551a4"
+ id = "9754f7b1-01be-5dce-8939-9dbedbd321d3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkpulsar"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkpulsar_auto.yar#L1-L401"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.highnote"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.highnote_auto.yar#L1-L128"
license_url = "N/A"
- logic_hash = "07b3040533891d5ece5d93ef76c617792a76fc1b169e5d22dab675082baad80b"
+ logic_hash = "63e3b329a81995d654d7d4235beb319e224a0ea782f84de7ddd9bdcbead90225"
score = 75
- quality = 50
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -177438,67 +184426,33 @@ rule MALPEDIA_Win_Darkpulsar_Auto : FILE
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
- strings:
- $sequence_0 = { ff25???????? 33c0 40 c20c00 68???????? 64ff3500000000 }
- $sequence_1 = { c20c00 68???????? 64ff3500000000 8b442410 896c2410 8d6c2410 2be0 }
- $sequence_2 = { c21000 ff25???????? ff25???????? ff25???????? 33c0 }
- $sequence_3 = { 3a01 1bc0 83e0fe 40 5f }
- $sequence_4 = { 803f00 742e 47 ff450c 0fbe07 }
- $sequence_5 = { 56 8b35???????? 57 8b7d08 eb09 }
- $sequence_6 = { 59 59 3bd8 74e0 0fb607 }
- $sequence_7 = { 50 ffd6 8bd8 8b450c 0fbe00 50 ffd6 }
- $sequence_8 = { 56 e8???????? ff742414 50 e8???????? 83c410 }
- $sequence_9 = { 6a01 50 ff15???????? 8bf0 59 }
- $sequence_10 = { 83c410 83f8ff 0f95c1 49 8bc1 }
- $sequence_11 = { 53 33d2 56 57 33c0 }
- $sequence_12 = { ffd7 59 5f 5e c3 8b4c2404 85c9 }
- $sequence_13 = { 8d45cc 50 57 e8???????? 83c410 85c0 }
- $sequence_14 = { ffd6 59 59 8945f8 }
- $sequence_15 = { f7d8 59 1bc0 59 40 c3 e9???????? }
- $sequence_16 = { 8b5d10 56 8b7508 33d2 }
- $sequence_17 = { e8???????? ff7514 89460c e8???????? }
- $sequence_18 = { ff15???????? 8bf8 59 59 85ff 7502 }
- $sequence_19 = { 8bc1 c3 8b442404 85c0 7501 c3 }
- $sequence_20 = { 33c0 33d2 c3 8bff 55 8bec b863736de0 }
- $sequence_21 = { e8???????? 59 5e 83f8ff }
- $sequence_22 = { 59 5e 8b45fc c9 c3 }
- $sequence_23 = { 56 e8???????? 59 85c0 7625 }
- $sequence_24 = { e8???????? 8bf0 46 56 ff15???????? 59 }
- $sequence_25 = { 40 894588 83659800 85c0 }
- $sequence_26 = { 8903 894304 5f 8bc6 }
- $sequence_27 = { ff75f0 56 57 ff15???????? 83c40c }
- $sequence_28 = { 00db 7313 752f 3b742404 0f830b010000 }
- $sequence_29 = { 8945cc 8945d0 8b4608 6a05 50 885dec }
- $sequence_30 = { 66894df5 c745f702000000 e8???????? 83c408 }
- $sequence_31 = { 0fb606 50 ff15???????? 83c41c 85c0 }
- $sequence_32 = { 48 4e 897c2414 75eb 5f 8d4240 }
- $sequence_33 = { 668903 8b45e8 8930 33c0 ebdc ff742408 ff15???????? }
- $sequence_34 = { 00db 7309 75f4 8a1e 46 10db }
- $sequence_35 = { 00db 7313 75e1 3b742404 0f8318010000 }
- $sequence_36 = { 51 51 8b4508 8b4d0c 894dfc }
- $sequence_37 = { 0facf908 c1ef08 48 4e }
- $sequence_38 = { 8945e0 8945e4 8945d4 8945d8 8b450c 897de8 897ddc }
- $sequence_39 = { 8d8df9feffff 53 51 899d5ceeffff 899d60eeffff }
- $sequence_40 = { 8b4d08 8d7d0c 31c0 f3aa }
- $sequence_41 = { ffd3 ff7594 ff15???????? 83c414 837d9c00 741c 837d0c07 }
- $sequence_42 = { 33d7 c1ea10 5f 33d1 }
- $sequence_43 = { 8bec 8b4508 894508 d94508 5d }
+ strings:
+ $sequence_0 = { b3a7 8cd7 a5 329ea1afa9a5 5d b5a5 }
+ $sequence_1 = { 2d620a682c fd 9d 8945ec 8945f0 8945f4 9c }
+ $sequence_2 = { 3665017cf341 14b0 63c5 ef d550 3362db }
+ $sequence_3 = { 0fb6c9 8a1408 0fb6da 03de 81e3ff000080 }
+ $sequence_4 = { 98 fd bfb47ea0c6 ddbb690cc1af 6595 fa 6a23 }
+ $sequence_5 = { 115542 305421f0 d438 bd4dae2b31 b1f7 }
+ $sequence_6 = { 90 9e a4 3634a1 6594 2424 e230 }
+ $sequence_7 = { 2ca7 33e6 7479 1e 0477 ed 7cb1 }
+ $sequence_8 = { 8636 35cfd6d703 b368 321e 4a 727d 51 }
+ $sequence_9 = { 000b 2920 da927a3741d4 7e5b a7 5a 40 }
condition:
- 7 of them and filesize <491520
+ 7 of them and filesize <321536
}
-rule MALPEDIA_Win_Torisma_Auto : FILE
+rule MALPEDIA_Win_Backbend_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a1ed0c86-448e-5725-a3d9-4e9a8d06915c"
+ id = "0c0e6fe8-d4e7-5b73-ab9b-71a979b7c8b3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.torisma"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.torisma_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.backbend"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.backbend_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "5ec5e797b8010193d7caa6926dd920962119b17c8339298b3be41306fc75b6f7"
+ logic_hash = "b7d55ae6e8faf28a826a20f0c2aeb325ce5a40ba350e055022c2b2475be4953d"
score = 75
quality = 75
tags = "FILE"
@@ -177512,35 +184466,32 @@ rule MALPEDIA_Win_Torisma_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 3d83490000 7507 b883490000 }
- $sequence_1 = { 7402 eb05 e9???????? b833280000 }
- $sequence_2 = { e8???????? 3d514b0000 7504 33c0 }
- $sequence_3 = { 488b4c2470 e8???????? 89442458 817c245870100000 }
- $sequence_4 = { 030cb540ef0110 eb02 8bca f641247f 759b }
- $sequence_5 = { b833280000 5f 5e 8be5 5d }
- $sequence_6 = { 8b55fc 833a00 740c 8b45fc 8b08 51 }
- $sequence_7 = { 488d442440 488bf8 33c0 b928000000 }
- $sequence_8 = { 8b4c2430 488b542450 89048a ebb5 }
- $sequence_9 = { 817dd833280000 7507 c745f433280000 eb07 c745f433280000 }
- $sequence_10 = { c68424e1000000e9 c68424e2000000c3 c68424e3000000a5 c68424e400000090 }
- $sequence_11 = { ff2495c0d50010 8bc7 ba03000000 83e904 720c 83e003 }
- $sequence_12 = { c1e006 0b442414 88442410 8b442440 }
+ $sequence_0 = { ff15???????? 80a40500ffffff00 8d8500ffffff 56 50 ff15???????? }
+ $sequence_1 = { 58 5f 5e c3 ff25???????? ff25???????? }
+ $sequence_2 = { ffd6 ff7510 ffd3 8d8500feffff }
+ $sequence_3 = { ff15???????? 85c0 7416 8d8500fbffff }
+ $sequence_4 = { 56 e8???????? 8d8500fdffff 56 50 e8???????? 68???????? }
+ $sequence_5 = { 90 90 90 bf???????? 57 e8???????? c70424???????? }
+ $sequence_6 = { 8d8500f9ffff 50 e8???????? 8d8500f9ffff 50 e8???????? 83c424 }
+ $sequence_7 = { ffd3 8d8500feffff 6800010000 50 ff15???????? 8d8500feffff 68???????? }
+ $sequence_8 = { 56 ffd3 6a00 8d8500ffffff 56 50 ff15???????? }
+ $sequence_9 = { 7416 8d8500fbffff 6a00 50 }
condition:
- 7 of them and filesize <322560
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Waterminer_Auto : FILE
+rule MALPEDIA_Win_Usbferry_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a6c61a63-af94-546a-ae52-fcf958232615"
+ id = "62065071-13fe-542b-a291-fb80bd43202d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.waterminer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.waterminer_auto.yar#L1-L159"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.usbferry"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.usbferry_auto.yar#L1-L169"
license_url = "N/A"
- logic_hash = "3dbc2a8def87fd5744e5b18617b0d65739b7ff2d0b5a69125fd601baee65e3fe"
+ logic_hash = "886d5513793c468df6b8e0477647a179848882846be144ad6058e6cfbd13a26d"
score = 75
quality = 75
tags = "FILE"
@@ -177554,38 +184505,38 @@ rule MALPEDIA_Win_Waterminer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b8514f3ffff e9???????? 83bda4f5ffff00 0f8532010000 8b8db8f5ffff c1e104 83bc0dbcf9ffff00 }
- $sequence_1 = { 03442410 4403e8 428b4405e7 418bd5 }
- $sequence_2 = { 03bc24a8000000 488bcd 4c8d0d35cb0300 83e13f }
- $sequence_3 = { 51 b804000000 6bc019 8b8880434b00 330d???????? 894dfc 740d }
- $sequence_4 = { 8b8da4fbffff 83e901 898da4fbffff 83bd10fbffff00 }
- $sequence_5 = { 8bcd 50 8d15b0854300 e8???????? }
- $sequence_6 = { 03c0 2bc8 0f84ec040000 8d41ff 8b848288d20600 }
- $sequence_7 = { 0344240c 4403d0 488d051a560500 418b0400 }
- $sequence_8 = { 03c1 03d0 488d051e580500 418b0400 }
- $sequence_9 = { 83bd60ffffff0b 0f8711060000 8b8d60ffffff ff248d74304800 0fbe55d3 }
- $sequence_10 = { 02c8 41880c18 418a03 240f }
- $sequence_11 = { 0344240c 4403d0 428b4405e7 418bd2 }
- $sequence_12 = { 02d0 49ffc3 418d4001 881418 }
- $sequence_13 = { c78538fbffff01000000 eb0a c78538fbffff00000000 8b8538fbffff 898530fbffff }
- $sequence_14 = { 8b95c4fbffff 8995f0fbffff 8b85ecfbffff 055d010000 898580fbffff }
- $sequence_15 = { 33c5 8945fc 8bf4 6a00 8bfc ff15???????? 3bfc }
+ $sequence_0 = { 52 8b45e0 50 ff15???????? 85c0 742c }
+ $sequence_1 = { 8b9598f5ffff 2b9588f5ffff 8b8588f5ffff 89857cf5ffff 899578f5ffff }
+ $sequence_2 = { e9???????? ff75e0 a1???????? ff5060 8d45e0 }
+ $sequence_3 = { c3 3b0d???????? f27502 f2c3 f2e960030000 55 }
+ $sequence_4 = { 8b525c e8???????? 8b15???????? 8b4d84 ff7210 89425c }
+ $sequence_5 = { 803f2e 7402 33ff 85ff 7407 8d45e9 }
+ $sequence_6 = { c645df6f c645e06e c645e100 c685a4f5ffff00 68ff030000 }
+ $sequence_7 = { 2b858cf5ffff 8b8d8cf5ffff 898d84f5ffff 898580f5ffff 8d95a8feffff 83c2ff }
+ $sequence_8 = { 8b7d0c 33db 895ddc c745e000040000 895dfc 8d45dc }
+ $sequence_9 = { 89814c010000 8b09 e8???????? 8b0d???????? ff7110 8b9154010000 }
+ $sequence_10 = { ff7110 8b517c 894178 8b09 e8???????? 8b0d???????? }
+ $sequence_11 = { 8a460e 8bcf 8845fb 8d45fb }
+ $sequence_12 = { 33c5 8945fc c685fcfffeff00 68ffff0000 }
+ $sequence_13 = { 8885a0f5ffff 838590f5ffff01 80bda0f5ffff00 75e1 }
+ $sequence_14 = { 0f2805???????? 0f1145c8 6a00 0f2805???????? 0f1145d8 50 }
+ $sequence_15 = { 50 8d45f0 64a300000000 c745e000000000 c745fc00000000 837d2000 }
condition:
- 7 of them and filesize <1556480
+ 7 of them and filesize <638976
}
-rule MALPEDIA_Win_Unidentified_071_Auto : FILE
+rule MALPEDIA_Win_Glooxmail_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9e4ae8e5-b01b-5dfb-9ebf-d96081ff094b"
+ id = "9fc08289-2c15-5e6a-a020-5e3374a227b0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_071"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_071_auto.yar#L1-L129"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.glooxmail"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.glooxmail_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "cf757bc05d123f04b705025eb8059bfc6f948c6a237ae24790160c041569438f"
+ logic_hash = "3f9c49f2bcdac7dc8871b003117cb741dd79fa085062dcf8b6237e67caf4dc2a"
score = 75
quality = 75
tags = "FILE"
@@ -177599,32 +184550,32 @@ rule MALPEDIA_Win_Unidentified_071_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? ff35???????? a3???????? a1???????? 0faf05???????? a3???????? e8???????? }
- $sequence_1 = { 6a20 8901 83c8ff 5a 895104 894108 d1e8 }
- $sequence_2 = { 8bd9 8b4b10 2bc1 894c2404 3bc2 0f82a7000000 8b4314 }
- $sequence_3 = { 6a10 5a 0f44ca 51 50 ff15???????? }
- $sequence_4 = { c3 33c0 c3 8b5108 b8ffffff0f }
- $sequence_5 = { ff36 e8???????? 8b0e 8b4608 2bc1 894df8 6a18 }
- $sequence_6 = { 8b4c2420 8d346d00000000 8b542428 56 ff742428 8d044a }
- $sequence_7 = { c20400 55 8bec 8b450c ff7510 2b4508 c1f804 }
- $sequence_8 = { 0f8290000000 8b4314 55 56 57 8d3c11 }
- $sequence_9 = { 85c0 8b4314 740d 25ffffff82 0d00000002 894314 0fb64b01 }
+ $sequence_0 = { 834dfcff 6a00 53 8d4d38 }
+ $sequence_1 = { e8???????? 899c2460800000 895c240c 895c2410 68ff7f0000 8d442451 53 }
+ $sequence_2 = { 57 8d8c24f4030000 e8???????? 8d8c2418080000 51 8d8c24f4030000 c684246408000030 }
+ $sequence_3 = { 0f840c000000 8365f0fe 8d4dc4 e9???????? c3 8b542408 8d420c }
+ $sequence_4 = { b8???????? e9???????? 8d4d00 e9???????? 8d4dd4 e9???????? 8d4dd4 }
+ $sequence_5 = { 59 c3 8b85acf7ffff 2500000400 0f8415000000 81a5acf7fffffffffbff }
+ $sequence_6 = { e8???????? 8bd9 895de8 8d7b04 8d7308 c703???????? c707???????? }
+ $sequence_7 = { c700???????? c74004???????? c74008???????? c7400cb04a4400 c74010bc4a4400 c74014c84a4400 c74018d44a4400 }
+ $sequence_8 = { 8d8d2cffffff e9???????? c3 8b542408 8d82acfbffff 8b8aa8fbffff 33c8 }
+ $sequence_9 = { ff750c 8b01 ff5044 84c0 7504 b301 eb02 }
condition:
- 7 of them and filesize <1220608
+ 7 of them and filesize <761856
}
-rule MALPEDIA_Win_Krbanker_Auto : FILE
+rule MALPEDIA_Win_Netspy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "236e4eb3-f9a9-5a5c-939d-2dd344c94ac6"
+ id = "59f8d53f-335b-5ed2-a6be-e28bbbbbcf22"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.krbanker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.krbanker_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.netspy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.netspy_auto.yar#L1-L104"
license_url = "N/A"
- logic_hash = "d1369d0e33548d319048c3c036e2e47c22a922a80b7ada061139a11ddd9f8b91"
+ logic_hash = "5f6115aa578488570bf6917737e346bbf4658a865ab8c32a6d3ce07b27ad566b"
score = 75
quality = 75
tags = "FILE"
@@ -177638,34 +184589,32 @@ rule MALPEDIA_Win_Krbanker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c404 58 8945dc 837ddc00 }
- $sequence_1 = { 83c404 58 8945fc b8???????? 50 }
- $sequence_2 = { 6801000000 bb40010000 e8???????? 83c410 8945c8 6801010080 6a00 }
- $sequence_3 = { 0faf03 ebf5 8bc8 c3 55 8bec 83c4f4 }
- $sequence_4 = { 75a4 dd442410 e8???????? 8ad8 }
- $sequence_5 = { 7762 7415 3d04000080 7417 3d01010080 }
- $sequence_6 = { bb40010000 e8???????? 83c410 8945cc ff75cc ff75d0 }
- $sequence_7 = { 8a5c2410 8ac3 5e 5b c3 8b542410 83ec0c }
- $sequence_8 = { 8b5dfc 83c304 895df8 8965f4 ff7514 }
- $sequence_9 = { 03d8 895dd4 8b5df8 e8???????? }
+ $sequence_0 = { 0f45c8 488b85e8330000 8908 8b15???????? 833d????????0a 0f9cc1 }
+ $sequence_1 = { 4989e1 4c898d905b0000 e8???????? 4829c4 488b85f81e0000 4989e1 }
+ $sequence_2 = { e9???????? 488b85003a0000 8b10 89d1 }
+ $sequence_3 = { c3 488b4df0 b810000000 e8???????? 4829c4 }
+ $sequence_4 = { 488b8578430000 8b00 898580430000 8b15???????? 833d????????0a 0f9cc1 }
+ $sequence_5 = { 4889e1 e8???????? 4829c4 488b85d8310000 4889e2 458910 }
+ $sequence_6 = { e8???????? 4829c4 488b8540150000 4989e1 4c898d00600000 e8???????? }
+ $sequence_7 = { a801 0f8515000000 65488b042560000000 488985406b0000 e9???????? 488b85406b0000 488b4018 }
condition:
- 7 of them and filesize <1826816
+ 7 of them and filesize <12033024
}
-rule MALPEDIA_Win_Smanager_Auto : FILE
+rule MALPEDIA_Win_Sienna_Purple_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7788af6d-844d-509b-90a8-b8ca5df742b1"
+ id = "cf85ec2b-384f-56db-af6a-79031e73a14e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.smanager"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.smanager_auto.yar#L1-L224"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sienna_purple"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sienna_purple_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "7070ed4ef9fc0031fffb8ae0d3a2a122913a3a51a0e1a419190de42eef9b5039"
+ logic_hash = "ba62dd8b8de50fe0a193f425d94a0b3b25a4b9e54845758b6f1fb176e28dc859"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -177677,46 +184626,32 @@ rule MALPEDIA_Win_Smanager_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a0d e8???????? 83c404 8bf0 }
- $sequence_1 = { 51 ffd0 83c40c c7460800000000 }
- $sequence_2 = { 7410 6a00 6a00 6830001100 }
- $sequence_3 = { 8b7604 6a00 6a00 56 68???????? 6a00 6a00 }
- $sequence_4 = { 8b4608 85c0 7420 a801 7515 }
- $sequence_5 = { 8b4510 85c0 7407 50 ff15???????? }
- $sequence_6 = { 68???????? 6a00 6a00 ff15???????? 8bf8 897e28 }
- $sequence_7 = { 83c602 6a22 56 e8???????? 83c408 }
- $sequence_8 = { ff15???????? 32c0 e9???????? 0f1005???????? }
- $sequence_9 = { 0007 b15a 0007 b15a }
- $sequence_10 = { 0000 80ed4a 0044feff ff900100008c }
- $sequence_11 = { 4c8d9c24d0010000 498b5b28 498b7330 498b7b38 498be3 415f }
- $sequence_12 = { 41c7430800000000 488d59b0 488d0532730100 498943e0 488d0537730100 }
- $sequence_13 = { 0008 53 4f 00ef }
- $sequence_14 = { 4885c0 7463 41b80f000000 488d159ab90100 488bc8 e8???????? }
- $sequence_15 = { 44894de9 66448955f1 418bc8 8bc2 4c8d0de10b0100 c1e918 }
- $sequence_16 = { 488bf8 448b842480000000 33d2 488bc8 e8???????? 4533f6 }
- $sequence_17 = { 0007 b15a 00c4 b15a }
- $sequence_18 = { 41b803000000 488d0d908e0000 4533c9 ba00000040 4489442420 ff15???????? }
- $sequence_19 = { 0003 b157 0000 0c0c }
- $sequence_20 = { 0007 b15a 0089b05a0089 b05a }
- $sequence_21 = { 7404 b301 eb03 448937 }
- $sequence_22 = { 0001 ce 50 0008 }
- $sequence_23 = { 0000 0c0c 0c0c 0c0c 0c0c 0c0c 0102 }
+ $sequence_0 = { e8???????? 8d4e08 c645fc02 c706???????? e8???????? 8bc6 8b4df4 }
+ $sequence_1 = { b8e5040000 5e 5d c3 68???????? 56 e8???????? }
+ $sequence_2 = { e8???????? 50 8d8f84040000 e8???????? b301 8d4db0 c745fcffffffff }
+ $sequence_3 = { 8d5729 f30f7f4728 f30f6f4310 f30f7f4738 f30f6f4320 f30f7f4748 f30f6f4330 }
+ $sequence_4 = { ff5014 8d8570ffffff 8bcf 50 68???????? e8???????? 8bce }
+ $sequence_5 = { f30f6f40f0 660fefc8 f30f7f48f0 3bd1 72c4 8bb540ffffff 8b8d6cffffff }
+ $sequence_6 = { c1e81f 23c8 8b421c 35ff000000 48 c1e81f 23c8 }
+ $sequence_7 = { c7072e000000 e9???????? 80be2501000000 7418 8b8d84fdffff e8???????? 50 }
+ $sequence_8 = { eb09 50 56 8bcb e8???????? 8b4df4 64890d00000000 }
+ $sequence_9 = { c1c70a 0bc8 8d83dcbc1b8f 034db4 03c1 8b5de8 c1c005 }
condition:
- 7 of them and filesize <10013696
+ 7 of them and filesize <2930688
}
-rule MALPEDIA_Win_Andardoor_Auto : FILE
+rule MALPEDIA_Win_Poscardstealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a2062653-6e94-5023-8019-c5f17c84046c"
+ id = "30b86ec5-11cf-5ead-8d33-f96f4fd997a4"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.andardoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.andardoor_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.poscardstealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.poscardstealer_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "3510472d198d8ac0d724063f8fb842ce0d2281170e5fd2c286cfefa5f50dca2c"
+ logic_hash = "e2bc29fc53d916c8c6261d35dc13ec4aa0c9f6d2e8252ac3a60894a094beda3f"
score = 75
quality = 75
tags = "FILE"
@@ -177730,32 +184665,32 @@ rule MALPEDIA_Win_Andardoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4c8d8c2400020000 33d2 0f1f8000000000 410fb60c11 880c10 488d5201 84c9 }
- $sequence_1 = { 6690 488bcb ff15???????? a810 741f 40383d???????? 0f84d0000000 }
- $sequence_2 = { 48895c2458 ff15???????? 85c0 752b 488b0d???????? 4885c9 7406 }
- $sequence_3 = { 4881ecf0030000 0f2970d8 0f2978c8 488b05???????? }
- $sequence_4 = { 0f2970d8 0f2978c8 488b05???????? 4833c4 488985c0020000 }
- $sequence_5 = { 41b880000000 e8???????? 4533c9 4c8d442430 }
- $sequence_6 = { b943150000 6689742468 ff15???????? 668944246a 41b810000000 }
- $sequence_7 = { 488bf8 4885c0 0f84ed000000 b943150000 6689742468 ff15???????? }
- $sequence_8 = { 488bf9 33d2 33c9 498bf0 ff15???????? 85c0 7407 }
- $sequence_9 = { 488bcf ff15???????? 488bf8 488d4ffe }
+ $sequence_0 = { c645fc01 e8???????? 8d4db8 51 50 8d55d4 }
+ $sequence_1 = { 33d2 bb07000000 895de8 8975e4 }
+ $sequence_2 = { 50 ff15???????? 8bf0 8d45b0 50 }
+ $sequence_3 = { 03c8 83fb10 7303 8d55d4 }
+ $sequence_4 = { 8bd1 c1fa05 c1e006 030495e0794200 eb05 b8???????? f6400420 }
+ $sequence_5 = { c785e8feffff7ce74100 8b8520ffffff c645fc07 894598 }
+ $sequence_6 = { 8b4da4 8b5590 8bc2 83f908 7303 }
+ $sequence_7 = { 885dd4 e8???????? 8b0d???????? 8b35???????? 2bce b893244992 f7e9 }
+ $sequence_8 = { 6800000040 50 ff15???????? 8bf0 8d45c4 50 }
+ $sequence_9 = { e9???????? 8d8d58feffff e9???????? 8d8d10ffffff e9???????? 8d8d48ffffff e9???????? }
condition:
- 7 of them and filesize <339968
+ 7 of them and filesize <362496
}
-rule MALPEDIA_Win_Spyeye_Auto : FILE
+rule MALPEDIA_Win_Computrace_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4b228779-0f96-5a8e-b676-8a6d855d1452"
+ id = "4429b6f7-4609-5864-be9b-bd86b296052a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spyeye"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spyeye_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.computrace"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.computrace_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "54f45a6b713b51a15663c9347e916cec35361fbd1f12608b97d32ef9d0a49fb7"
+ logic_hash = "d8751f69a58562c91660e3060ff3b6e112f846c07b191aab11a4034542037b61"
score = 75
quality = 75
tags = "FILE"
@@ -177769,32 +184704,32 @@ rule MALPEDIA_Win_Spyeye_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4de8 51 8d4de0 51 50 e8???????? 85c0 }
- $sequence_1 = { 6a07 6800000040 57 e8???????? 8bf8 83ffff }
- $sequence_2 = { 6889000000 ff7508 33db 897df8 }
- $sequence_3 = { 57 6800000002 6a03 57 6a01 56 }
- $sequence_4 = { 56 6880000000 6a02 eb08 56 6880000000 6a04 }
- $sequence_5 = { 85c0 7407 c745f801000000 397dfc 740e }
- $sequence_6 = { be80000000 56 6a03 57 6a01 6889000000 ff7508 }
- $sequence_7 = { 53 e8???????? 85c0 7407 c745f801000000 397dfc 740e }
- $sequence_8 = { 8965fc ff7510 ff750c ff7508 ffd0 8b65fc }
- $sequence_9 = { 7454 57 56 6a03 }
+ $sequence_0 = { ff75cc e8???????? 3975e4 753a }
+ $sequence_1 = { e8???????? 8a4002 8b0d???????? 8801 ff35???????? }
+ $sequence_2 = { 740e 837de400 7408 037de4 897dd8 eba6 8b4514 }
+ $sequence_3 = { 7503 800e08 e8???????? 894604 ff750c 8f4618 }
+ $sequence_4 = { e30d 83c00a 51 ff750c 50 e8???????? }
+ $sequence_5 = { e8???????? 837de400 0f8593feffff 8b86481b0000 83786c00 0f8483feffff }
+ $sequence_6 = { 8b7508 80665cfe 33c0 8945fc 8845fb 6689461a 48 }
+ $sequence_7 = { 7414 c745dc01000000 897d8c 6af1 }
+ $sequence_8 = { e8???????? 8945e4 3bc6 7417 }
+ $sequence_9 = { ff15???????? f7d8 1bc0 40 57 }
condition:
- 7 of them and filesize <741376
+ 7 of them and filesize <73728
}
-rule MALPEDIA_Win_Proto8_Rat_Auto : FILE
+rule MALPEDIA_Win_Ransoc_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "67c17406-b8bd-51d3-bd06-6c282d2d9ba4"
+ id = "961c0c93-e6c6-5111-8367-8742ed436406"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.proto8_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.proto8_rat_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ransoc"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ransoc_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "b74b2b80c633a7bf227b4dcb10a54e0eaa49fb3d590fb7e951e6a918637cc88c"
+ logic_hash = "2d366ed2132c1270c1bab4c471d75e367a89089f653123f697fac204fd95b124"
score = 75
quality = 75
tags = "FILE"
@@ -177808,32 +184743,32 @@ rule MALPEDIA_Win_Proto8_Rat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7819 8d4a01 0f1f00 488b5b08 4883e901 75f6 eb07 }
- $sequence_1 = { f04e0fb13409 483bd0 752b 4885d2 7426 440fb68c24c8000000 498bcc }
- $sequence_2 = { 488b4008 48894708 488b4630 488907 488b4630 488b4808 488939 }
- $sequence_3 = { 764f 6666660f1f840000000000 458bc1 8bd5 49c1e006 4c034360 4183780800 }
- $sequence_4 = { 0f10442428 488b842488000000 0f1100 f20f104c2438 f20f114810 b001 eb02 }
- $sequence_5 = { e8???????? 84c0 751d 488b03 488bcb ff5018 488bf0 }
- $sequence_6 = { 4053 4883ec20 488d05634f0400 488bd9 488901 f6c201 740a }
- $sequence_7 = { f20f114808 0f28cf 488b41e0 f20f594020 f20f114008 488b41e8 f20f594820 }
- $sequence_8 = { ff15???????? 85c0 757f ff15???????? 3d002f0000 74be 488b4c2440 }
- $sequence_9 = { 8b842490000000 03ce 894c2428 3bc8 0f829afdffff 4c8b7c2440 4c8b642448 }
+ $sequence_0 = { 8b573c 50 57 ffd2 ff4e3c 8b462c 8b4e3c }
+ $sequence_1 = { 8bf0 8b5630 57 8d7e30 }
+ $sequence_2 = { 894240 8b5040 895140 3bd7 741e }
+ $sequence_3 = { 89703c 8b5134 895030 3bd7 7406 8b5134 }
+ $sequence_4 = { 85c0 75f2 8b7140 85f6 758b 68???????? }
+ $sequence_5 = { 740f 83f907 740a 83f906 }
+ $sequence_6 = { 89462c a820 7406 8b4604 014804 8b462c a900080000 }
+ $sequence_7 = { 895148 8b4830 85c9 7406 8b5034 895134 8b4834 }
+ $sequence_8 = { 83c408 c3 6a00 6a01 55 }
+ $sequence_9 = { 8b56e4 89542414 8d5c2410 891a 89442410 8b5004 8956e4 }
condition:
- 7 of them and filesize <2537472
+ 7 of them and filesize <958464
}
-rule MALPEDIA_Win_Rockloader_Auto : FILE
+rule MALPEDIA_Win_Compfun_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "175eaa7b-da5b-50b8-b46d-cecd53211dcf"
+ id = "b70b97d4-0cf0-525a-92ea-8899bccf1319"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rockloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rockloader_auto.yar#L1-L117"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.compfun"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.compfun_auto.yar#L1-L161"
license_url = "N/A"
- logic_hash = "8a75e6c1f9302fef80e04ef409ea5d10afc0d829be15769e71fe72b02405b4ff"
+ logic_hash = "a0b696c7a840205849cf5ac2e95df1021718fd8d1c1053a2c6b648baa042ec58"
score = 75
quality = 75
tags = "FILE"
@@ -177847,32 +184782,38 @@ rule MALPEDIA_Win_Rockloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? dc1d???????? dfe0 f6c441 740f }
- $sequence_1 = { e8???????? 85c0 74b4 c6002c 40 837d0c00 7404 }
- $sequence_2 = { 8a06 3c22 750c ff7508 8bc6 e8???????? }
- $sequence_3 = { 8b45f4 8945e8 8d45f8 50 8d45e4 }
- $sequence_4 = { eb05 68???????? e8???????? 8bf8 8bc7 }
- $sequence_5 = { e8???????? 33f6 53 8975f8 }
- $sequence_6 = { 3975f4 7e55 53 8b45f8 }
- $sequence_7 = { ff4608 8b7f08 85ff 7452 8b4508 }
- $sequence_8 = { d9ee 53 56 dd55ec d9e8 33f6 }
- $sequence_9 = { 8975f8 db45f8 8365f800 dec1 dd5ddc 9b }
+ $sequence_0 = { 8d857cfeffff 50 8d857cffffff 50 e8???????? 59 50 }
+ $sequence_1 = { c7460c65726174 c746106f722063 c746146c617373 c6461800 8bc6 5e }
+ $sequence_2 = { 56 e8???????? 83c40c c74608697a6520 c70647657446 c74604696c6553 c6460b00 }
+ $sequence_3 = { c7460472656174 c7460865557365 c7460c72546872 c6461300 }
+ $sequence_4 = { e8???????? 83c40c c7460c33322020 c706496e7072 }
+ $sequence_5 = { 6880000000 6a00 56 e8???????? 83c40c c70647657446 c74604756c6c50 }
+ $sequence_6 = { c6460f00 8bc6 5e 5d c3 55 }
+ $sequence_7 = { c7460825202020 c70625415050 c7460444415441 c6460900 8bc6 5e }
+ $sequence_8 = { 034c2460 488b442450 894820 488b4c2450 }
+ $sequence_9 = { 03c1 4863d0 488b4c2430 488b442438 }
+ $sequence_10 = { 03c1 89442420 8b442420 83c001 }
+ $sequence_11 = { 03c1 89442420 8b4c2438 488b442450 }
+ $sequence_12 = { 03c1 89442420 8b542438 486bd218 }
+ $sequence_13 = { 034c242c 488b442470 894820 488d542440 }
+ $sequence_14 = { 03c1 89442434 8b442430 39442434 }
+ $sequence_15 = { 0344242c 8bc8 e8???????? 4889442448 }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <402432
}
-rule MALPEDIA_Win_Uacme_Auto : FILE
+rule MALPEDIA_Win_Calmthorn_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f5c3a5f2-a252-5543-b1be-134e5f419833"
+ id = "8cbb3f25-515c-5fed-8b4e-4a931d9bfb1a"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.uacme"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.uacme_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.calmthorn"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.calmthorn_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "9cc750a1f13cae79bcf2cd2e379aedeb4cbdf45f9813c77d239c596ff07109f6"
+ logic_hash = "98170ddc8dfcd366956427aafd69264166f05ad426e5dc909d0630e51620ea92"
score = 75
quality = 75
tags = "FILE"
@@ -177886,32 +184827,32 @@ rule MALPEDIA_Win_Uacme_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ba???????? e8???????? 8d8df0fbffff e8???????? 8bf8 85ff 741b }
- $sequence_1 = { ff9620060000 33c0 5e 8be5 5d c20400 }
- $sequence_2 = { eb23 8b4d08 e8???????? 03c0 }
- $sequence_3 = { 8d45d8 50 6804900000 56 ff15???????? 6808700000 56 }
- $sequence_4 = { ba???????? 8d8940040000 e8???????? 8b45fc ff7010 ffd6 }
- $sequence_5 = { 8bd8 85db 74d3 8b5508 8bcb e8???????? }
- $sequence_6 = { 668974242e ff15???????? 85c0 0f88c9040000 ff15???????? b940040000 }
- $sequence_7 = { e8???????? 8bce 8d85e0fbffff 8818 40 83e901 }
- $sequence_8 = { b9???????? e8???????? 6683bdf0fbffff00 8bf0 740d 8d85f0fbffff 50 }
- $sequence_9 = { 8d85f0fbffff 50 8d85e0f7ffff 50 e8???????? 8bd8 }
+ $sequence_0 = { c78548adffff00000000 eb0f 8b8548adffff 83c001 898548adffff 8b8d68f9ffff 51 }
+ $sequence_1 = { e8???????? 83c404 3985dcf3ffff 7d20 8b954cfaffff 83c201 89954cfaffff }
+ $sequence_2 = { 0f57c0 660f13857498ffff eb1e 8b957498ffff 83c201 8b857898ffff 83d000 }
+ $sequence_3 = { eb1e 8b85bc86ffff 83c001 8b8dc086ffff 83d100 8985bc86ffff 898dc086ffff }
+ $sequence_4 = { 8b959875ffff 83d200 898d9475ffff 89959875ffff 83bd9875ffff00 7722 720c }
+ $sequence_5 = { ebb7 0fb6952cfdffff 83fa01 7552 c7855cbdffff00000000 eb0f 8b855cbdffff }
+ $sequence_6 = { ebba 0fb68d5efdffff 83f901 7556 0f57c0 660f1385c472ffff eb1e }
+ $sequence_7 = { 8a95b7fdffff 80c201 8895b7fdffff ebbd 0fb6859efdffff 83f801 7552 }
+ $sequence_8 = { 8b8518f8ffff 0fbe08 85c9 7502 eb02 ebba 0fb69591fdffff }
+ $sequence_9 = { eb0f 8b8d34f0ffff 83c101 898d34f0ffff 8b9564f6ffff 52 e8???????? }
condition:
- 7 of them and filesize <565248
+ 7 of them and filesize <2322432
}
-rule MALPEDIA_Win_Lazardoor_Auto : FILE
+rule MALPEDIA_Win_Helminth_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2eb37290-3e1c-5665-a83e-f5adb7297910"
+ id = "e8458d0c-0e53-5434-b94f-d27e99b6a572"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lazardoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lazardoor_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.helminth"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.helminth_auto.yar#L1-L159"
license_url = "N/A"
- logic_hash = "0bf4197e05236eb2be49432405132a9996b398c538e39f55b3ceea025a90e3ab"
+ logic_hash = "40475479d37d8203c72424a48ad87a8ce641700a54f37b53283dc8f7df269c35"
score = 75
quality = 75
tags = "FILE"
@@ -177925,32 +184866,37 @@ rule MALPEDIA_Win_Lazardoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 488bd1 488bc1 48c1f806 4c8d05f4f60000 }
- $sequence_1 = { 428a8c3998a50100 482bd0 8b42fc d3e8 443bc8 0f8d09010000 488b4b28 }
- $sequence_2 = { 4053 4883ec20 488d05575a0100 488bd9 488901 f6c201 740a }
- $sequence_3 = { 8905???????? 0f1105???????? 8b15???????? 4533c9 488b0d???????? 4533c0 }
- $sequence_4 = { 4d85c0 7410 488d15615b0200 488bc8 }
- $sequence_5 = { 44392d???????? 743d 4533c9 4c896c2430 c744242880000000 }
- $sequence_6 = { 660f6e5cc610 660f62d8 660f6fc7 660f6cda 660ffec4 660f76de }
- $sequence_7 = { 33d2 e8???????? 3bc3 7565 03fb 8b1d???????? 3bfb }
- $sequence_8 = { ba5a540000 e9???????? 8b05???????? 85c0 }
- $sequence_9 = { 4c8bc1 b84d5a0000 66390525b6ffff 7578 48630d58b6ffff 488d1515b6ffff 4803ca }
+ $sequence_0 = { a1???????? 68e8030000 8907 e8???????? }
+ $sequence_1 = { 83e61f c1e606 57 8b3c9d70750110 8a4c3704 }
+ $sequence_2 = { 894c2408 8d9b00000000 668b02 83c202 6685c0 }
+ $sequence_3 = { c1e106 899528e5ffff 53 8b149570750110 898d24e5ffff 8a5c1124 02db }
+ $sequence_4 = { 85ff 0f84be000000 897de0 8b049d70750110 0500080000 3bf8 }
+ $sequence_5 = { 03f2 eb5c 8b45f4 8b0c8570750110 f644190448 }
+ $sequence_6 = { 80c980 884c3704 8b0c9d70750110 8a443124 2481 }
+ $sequence_7 = { 2c2c 2c2c 232425???????? 2c2c 2c2c 2c2c }
+ $sequence_8 = { e8???????? 59 6a64 ff15???????? 57 57 }
+ $sequence_9 = { 8bf9 897c2410 e8???????? 8bcf }
+ $sequence_10 = { 8a02 8b9524e5ffff 8b0c9d28eb4100 88440a34 8b049d28eb4100 c744023801000000 }
+ $sequence_11 = { 663bc1 75f4 6a18 59 be???????? }
+ $sequence_12 = { a1???????? eb0c c745e4a4ee4100 a1???????? 33db }
+ $sequence_13 = { 83c102 663bc3 75f4 a1???????? 8bd7 }
+ $sequence_14 = { 6a03 68???????? 8d0c458ce44100 8bc1 2d???????? d1f8 }
condition:
- 7 of them and filesize <405504
+ 7 of them and filesize <479232
}
-rule MALPEDIA_Win_Quickmute_Auto : FILE
+rule MALPEDIA_Win_Apocalipto_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3ebd5405-d3fe-5b1c-9991-79b28ea4d116"
+ id = "ee7a0f0d-5a8b-59ea-a6c9-35fc5d51d457"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.quickmute"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.quickmute_auto.yar#L1-L113"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.apocalipto"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.apocalipto_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "94d7bee668e9656185345d12aa56e27e4c1baa2644d60d5f43d4b597af8c5206"
+ logic_hash = "ab10b935b7f8e9ea80933c4818fa1b5859216a7e2d022a7818f118074140bb2a"
score = 75
quality = 75
tags = "FILE"
@@ -177964,71 +184910,71 @@ rule MALPEDIA_Win_Quickmute_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6a00 ff15???????? 50 ff15???????? 5f c3 }
- $sequence_1 = { 750c 8d4dd8 51 56 }
- $sequence_2 = { 8d55c0 52 56 ffd7 a3???????? 833d????????00 c6854cffffff54 }
- $sequence_3 = { 8d9578edffff 52 6a03 ff15???????? 3bc3 745c }
- $sequence_4 = { 885dae 391d???????? 750c 8d4da8 }
- $sequence_5 = { 56 68???????? ff15???????? 83c408 8b751c }
- $sequence_6 = { 7510 53 6a40 ff15???????? 53 }
- $sequence_7 = { c7459030002900 c7459420006c00 c7459869006b00 c7459c65002000 }
- $sequence_8 = { 6a00 50 8946f8 ff15???????? }
- $sequence_9 = { c78542ffffff63746f72 66c78546ffffff7957 c68548ffffff00 750f }
+ $sequence_0 = { 880e b967666666 89d8 f7e9 89d1 c1f902 }
+ $sequence_1 = { 8817 41 47 39f1 75f5 c6040800 5b }
+ $sequence_2 = { c7042400000000 ff15???????? 52 8985ccf3ffff e8???????? 2500f0ffff 8d9800f0ffff }
+ $sequence_3 = { 8b5584 29f2 89542404 893c24 e8???????? c745e400000000 }
+ $sequence_4 = { 8b4154 89442408 895c2404 893424 }
+ $sequence_5 = { 83ec2c 8b4d08 8b450c 85c0 0f849d000000 }
+ $sequence_6 = { e8???????? 8d95e8f7ffff 89542404 893c24 e8???????? 89c2 85c0 }
+ $sequence_7 = { 8d3c10 31c9 8a140b 8817 }
+ $sequence_8 = { 891c24 ff15???????? 83ec08 a3???????? 85c0 0f8497080000 }
+ $sequence_9 = { 0f84cb080000 c7442404???????? 891c24 ff15???????? 83ec08 a3???????? 85c0 }
condition:
- 7 of them and filesize <146432
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Unidentified_102_Auto : FILE
+rule MALPEDIA_Win_Webc2_Bolid_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "68f5ede2-e772-5b9c-86c7-72da7d6ddaff"
- date = "2023-07-11"
- modified = "2023-07-15"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_102"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_102_auto.yar#L1-L130"
+ id = "05fc3e6a-bc1e-5e27-996e-6357de6a9e2c"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_bolid"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_bolid_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "7cf959abf8b06a75a101a66334f27ae5601df812c1ddb140fd9298ef735bb0dc"
+ logic_hash = "938464f6c09d72401fc04aa41413a321a3c389b634663fb70512029f39441d8b"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20230705"
- malpedia_hash = "42d0574f4405bd7d2b154d321d345acb18834a41"
- malpedia_version = "20230715"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 6bd238 8b0c8d187b0410 88441129 8b0b 8bc1 c1f806 }
- $sequence_1 = { 83c408 8bb5e8fdffff 8dbdd8fdffff 83bdecfdffff10 c745b000000000 0f43bdd8fdffff }
- $sequence_2 = { 8bf3 6bf938 c1fe06 6a00 8b0cb5187b0410 ff740f24 }
- $sequence_3 = { 894610 c7461407000000 668906 e9???????? 837f1410 8bcf 7202 }
- $sequence_4 = { c785e4fbffff07000000 8d5102 668985d0fbffff 6690 668b01 83c102 6685c0 }
- $sequence_5 = { 8d85e8e7ffff 68???????? 50 ff15???????? 83c410 8d8594e7ffff 50 }
- $sequence_6 = { 0f1085b0fcffff 0f1100 8bc4 0f108590fcffff 51 0f1100 ff5228 }
- $sequence_7 = { 83c408 8b95dcfeffff 83fa10 722f 8b8dc8feffff 42 8bc1 }
- $sequence_8 = { 6a00 68???????? 6802000080 c785c8e7ffff3f000f00 ff15???????? 85c0 0f84ef000000 }
- $sequence_9 = { 8d45f4 64a300000000 8965f0 8b4510 8b4d18 8b5d0c }
+ $sequence_0 = { 741e 8b4c240c 51 ff15???????? 56 68???????? e8???????? }
+ $sequence_1 = { e8???????? 8d8c24d4000000 c684242c02000004 51 8bcd e8???????? 8b15???????? }
+ $sequence_2 = { 8bcb e8???????? 85c0 0f84fa000000 8b550c 42 }
+ $sequence_3 = { 49 885c2454 51 68???????? 8d4c2444 }
+ $sequence_4 = { 83c40c 8b15???????? 8d4de4 52 }
+ $sequence_5 = { e8???????? 6a01 8d4c2440 c644245800 e8???????? 8b4c2460 }
+ $sequence_6 = { f3a4 8b35???????? 8d4c2410 51 6a26 52 89442420 }
+ $sequence_7 = { 8b458c 3bc3 7505 b8???????? }
+ $sequence_8 = { 50 ff5104 33db 6a01 }
+ $sequence_9 = { 53 880e 8bce e8???????? 8b15???????? 8d44245c }
condition:
- 7 of them and filesize <626688
+ 7 of them and filesize <163840
}
-rule MALPEDIA_Win_Bunitu_Auto : FILE
+rule MALPEDIA_Win_Orangeade_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fdd29b03-d926-5cbf-98be-29b287d71b21"
+ id = "a790e493-320f-57de-9b62-d13796c94676"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bunitu"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bunitu_auto.yar#L1-L119"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.orangeade"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.orangeade_auto.yar#L1-L116"
license_url = "N/A"
- logic_hash = "c3bd7c13018c7a8c4646040c13e12026479d672a4bbef2d99f41e09a2ac2f388"
+ logic_hash = "bc9cfd6680cc4f32cd41e9edf43afa43b54975c598906df96ea95e31fa6c1612"
score = 75
quality = 75
tags = "FILE"
@@ -178042,32 +184988,32 @@ rule MALPEDIA_Win_Bunitu_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68???????? 50 6a00 68???????? 6a00 50 ff15???????? }
- $sequence_1 = { 58 6a02 ffb524fdffff ff15???????? ffb524fdffff }
- $sequence_2 = { 50 ff75ec e8???????? 0bc0 7e18 50 }
- $sequence_3 = { 48 40 8d443825 668b00 }
- $sequence_4 = { c70003000000 ffb524fdffff 8f4004 ffb528fdffff 8f4008 }
- $sequence_5 = { ffb524fdffff e8???????? eb12 6a08 68???????? ffb524fdffff e8???????? }
- $sequence_6 = { 59 8bd0 8bdf b82f000000 }
- $sequence_7 = { 895004 b9???????? 8d55fc 52 6800000100 50 51 }
- $sequence_8 = { c70003000000 ff75f0 8f4004 ff75ec 8f4008 }
- $sequence_9 = { 837df000 7614 6a02 ff75f0 ff15???????? }
+ $sequence_0 = { 8bb42428050000 50 8bce e8???????? c744241001000000 }
+ $sequence_1 = { 50 8d942470020000 51 52 ff15???????? }
+ $sequence_2 = { f3ab 66ab aa 8d842468020000 50 }
+ $sequence_3 = { 6881000000 6a00 c784249428010000000000 ff15???????? 8bf0 56 }
+ $sequence_4 = { aa b93f000000 33c0 8dbc2465010000 }
+ $sequence_5 = { 8d4c2424 c684248828010002 e8???????? 8d4c2410 c684248828010001 e8???????? 8d4c2414 }
+ $sequence_6 = { b93f000000 33c0 8d7c2479 885c2478 f3ab }
+ $sequence_7 = { 68???????? 8d4c2410 e8???????? 68???????? 6884000000 53 ff15???????? }
+ $sequence_8 = { e8???????? 83c404 8d4c2424 c684248828010002 }
+ $sequence_9 = { 50 8d4c2410 c684248400000001 e8???????? }
condition:
- 7 of them and filesize <221184
+ 7 of them and filesize <139264
}
-rule MALPEDIA_Win_Zeus_Action_Auto : FILE
+rule MALPEDIA_Win_Pitou_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "65e8f438-ad6b-5cc2-8433-22cd51967cfc"
+ id = "8ffbef2d-72c2-5fd0-bc80-d9aaff0b569e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus_action"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeus_action_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pitou"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pitou_auto.yar#L1-L113"
license_url = "N/A"
- logic_hash = "d578cc91c04661eaf2cc2ee8b8d1f82a11b119d1521d38f5e03bfba5cd5d37a6"
+ logic_hash = "e9d79d3aa0dabaeee54f58f2a742dc54ca18da56fbfe8d220d28635b8791c96b"
score = 75
quality = 75
tags = "FILE"
@@ -178081,32 +185027,32 @@ rule MALPEDIA_Win_Zeus_Action_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 668945fa 8d75f4 a5 a5 a5 8383d87500000c 33f6 }
- $sequence_1 = { 7417 8b01 57 51 ff5034 8b4de8 85c9 }
- $sequence_2 = { ff15???????? b800080000 663b05???????? 7510 e8???????? 84c0 7407 }
- $sequence_3 = { 894508 3bf0 7433 8d7b14 85f6 7504 33c0 }
- $sequence_4 = { 0f84d0020000 395df8 0f84c7020000 395df4 0f84be020000 395dd0 0f84b5020000 }
- $sequence_5 = { 49 3bc6 7509 8b7dd8 894de8 }
- $sequence_6 = { 59 85c0 0f8479010000 837ddc00 740f 53 e8???????? }
- $sequence_7 = { 83c0fb 83f803 7740 f745d000080000 7416 03f9 03d9 }
- $sequence_8 = { 50 8b4618 83c004 50 ff15???????? 8b761c 83c40c }
- $sequence_9 = { ff15???????? 85c0 7817 56 8d85f8fdffff 50 8d85f0fbffff }
+ $sequence_0 = { 8bda c1e305 03c3 8bda }
+ $sequence_1 = { ac 8bda c1e305 03c3 8bda c1eb02 03c3 }
+ $sequence_2 = { c1e305 03c3 8bda c1eb02 }
+ $sequence_3 = { 8a6201 80f457 8acc 80e103 }
+ $sequence_4 = { 8bda c1e305 03c3 8bda c1eb02 03c3 33d0 }
+ $sequence_5 = { 8a12 80f257 8ada c0eb02 }
+ $sequence_6 = { c1e305 03c3 8bda c1eb02 03c3 33d0 }
+ $sequence_7 = { 53 80ef18 80ff10 5b }
+ $sequence_8 = { 80f457 8acc 80e103 8aec }
+ $sequence_9 = { ac 8bda c1e305 03c3 8bda }
condition:
- 7 of them and filesize <827392
+ 7 of them and filesize <1106944
}
-rule MALPEDIA_Win_Misha_Auto : FILE
+rule MALPEDIA_Win_Doublepulsar_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3791b368-7721-59e9-a6c9-80386ca3e3f7"
+ id = "e4212e3d-0371-55d3-984d-e0909a78bc0f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.misha"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.misha_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.doublepulsar"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.doublepulsar_auto.yar#L1-L175"
license_url = "N/A"
- logic_hash = "20e70ebbe7343afb7f42cf249a2a9fa16b58c61214c6be715dfea2d371ecbbbb"
+ logic_hash = "dd8758cb2c036e196362248313c65a128ef51c3148638e90157034cf0392e7be"
score = 75
quality = 75
tags = "FILE"
@@ -178120,32 +185066,38 @@ rule MALPEDIA_Win_Misha_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fbe09 03c1 894510 8b45f8 40 8945f8 8b4510 }
- $sequence_1 = { c20400 55 8bec 51 837d0802 7448 837d0804 }
- $sequence_2 = { 8945dc 817d140000007e 7607 33c0 e9???????? 8b4524 }
- $sequence_3 = { 32c0 5d c3 56 8bf0 eb0a 8bce }
- $sequence_4 = { c78510ffffff04040404 c78514ffffff04040404 c78518ffffff04040404 c7851cffffff04040404 c78520ffffff05050505 c78524ffffff05050505 c78528ffffff05050505 }
- $sequence_5 = { 85c0 7404 2bf3 8930 b001 }
- $sequence_6 = { 8b450c 0590010000 50 e8???????? 83c414 b001 e9???????? }
- $sequence_7 = { 8b4dcc 8d440104 8945cc 837d900f 0f829e000000 837d1c00 741d }
- $sequence_8 = { 50 e8???????? 8b5508 56 6a1c 59 }
- $sequence_9 = { 8b4514 e8???????? 0fb64524 85c0 7456 6a00 68ffffff7f }
+ $sequence_0 = { 731b 8a44144d 8d7c244c 8844144c }
+ $sequence_1 = { 8d41ff 85c0 7c10 8a1430 80fa5c 7408 }
+ $sequence_2 = { 8bc1 8bf7 8bfa 89ac245c020000 c1e902 f3a5 8b542410 }
+ $sequence_3 = { 0f8423010000 8b13 68???????? 52 ffd6 83c408 85c0 }
+ $sequence_4 = { e8???????? 48 8b4520 48 8b4878 48 }
+ $sequence_5 = { 5b 81c4c8040000 c20800 a0???????? }
+ $sequence_6 = { 8bc3 5f 5e 5b c3 b8???????? 83f901 }
+ $sequence_7 = { 83c410 85c0 740a 68???????? e9???????? 8b442408 53 }
+ $sequence_8 = { 53 33c0 56 8b742420 }
+ $sequence_9 = { 83c151 57 51 ff5618 85c0 7404 31c0 }
+ $sequence_10 = { ffd6 83c408 85c0 0f84990e0000 8b03 68???????? }
+ $sequence_11 = { 7414 8b5640 8b4c2414 52 51 }
+ $sequence_12 = { 55 e8???????? 8bd8 85db 0f84a0000000 56 }
+ $sequence_13 = { 33c0 bade47773f 8d4848 f3aa }
+ $sequence_14 = { c1ea18 33c3 8b1c95f0354000 8b56fc 33c3 8b1c8df0414000 }
+ $sequence_15 = { 52 ff15???????? 8b4518 83c404 85c0 7517 a1???????? }
condition:
- 7 of them and filesize <710656
+ 7 of them and filesize <140288
}
-rule MALPEDIA_Win_Bughatch_Auto : FILE
+rule MALPEDIA_Win_Stealbit_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "35614cb3-a7b5-53cc-adaa-ae210fa4a880"
+ id = "ba610849-1495-5151-b945-327f0dc5f838"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bughatch"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bughatch_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stealbit"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stealbit_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "5b28b48c5896cf30a835a51ee080a086478b951d2bf5768e0498fb91c61b534d"
+ logic_hash = "0ba0bc4f1da3f2dc67b8b88d21908b92c199e11ae8a3f814064895150fd93270"
score = 75
quality = 75
tags = "FILE"
@@ -178159,32 +185111,32 @@ rule MALPEDIA_Win_Bughatch_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 ff15???????? 68???????? 8d9594f7ffff 52 ff15???????? }
- $sequence_1 = { 8d8594f7ffff 50 ff15???????? c745d80c000000 c745e001000000 c745dc00000000 8d4d94 }
- $sequence_2 = { 52 6a00 8b45f8 50 ff15???????? 8945ec 837dec00 }
- $sequence_3 = { 55 8bec 81ec30010000 c745e000000000 c745e860524000 }
- $sequence_4 = { 894df4 8d55e4 52 8d4594 50 6a00 6a00 }
- $sequence_5 = { 8b55ec 52 ff15???????? c745f801000000 8b45fc }
- $sequence_6 = { 7308 8b45f8 8945f0 eb06 8b4d14 894df0 8b55f0 }
- $sequence_7 = { ff15???????? 8b4de0 51 ff15???????? 8b45dc }
- $sequence_8 = { 55 8bec 81ec60030000 837d0800 0f84d2000000 6a44 6a00 }
- $sequence_9 = { e8???????? 83c40c 85c0 7407 c745fc01000000 8b45f8 50 }
+ $sequence_0 = { 8b4e30 e8???????? 8b4e30 e8???????? 83663000 8d562c }
+ $sequence_1 = { 8d8580fbffff 50 e8???????? 8bc8 e8???????? ffd0 8bd8 }
+ $sequence_2 = { 8bfa 8bd9 e8???????? 8bc8 e8???????? ffd0 8bf0 }
+ $sequence_3 = { e8???????? 8bc8 e8???????? ffd0 6a02 68bf000000 53 }
+ $sequence_4 = { c786a802000000000000 8d7e50 33db 8b4620 }
+ $sequence_5 = { 6a6f 66898546ffffff 33c0 66898548ffffff 58 6a63 668985d2fcffff }
+ $sequence_6 = { 66899570feffff 66899574feffff 5a 6a6d 58 6a69 66898500feffff }
+ $sequence_7 = { 6689859afeffff 33c0 668955de 5a 6a61 6689bd86feffff }
+ $sequence_8 = { 8945f8 e8???????? 03c0 8bce 8bd0 e8???????? 6a0c }
+ $sequence_9 = { e8???????? 8bc8 e8???????? 3d15cffdb1 740b 46 3bf7 }
condition:
- 7 of them and filesize <75776
+ 7 of them and filesize <131072
}
-rule MALPEDIA_Win_Isspace_Auto : FILE
+rule MALPEDIA_Win_Nokoyawa_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6de2cc9e-3c1b-5d82-85e8-a409082de585"
+ id = "71f47de5-b877-5435-a43f-09577ab6e252"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.isspace"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.isspace_auto.yar#L1-L100"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nokoyawa"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nokoyawa_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "e463ab51553d0208df8251abb329c162f866232bb82c29826d5e55ecd0eb426f"
+ logic_hash = "a3e5835d9868e848c4cf7b1e58144cc15b3f0d5c2b0274b447bdec70231f3ad8"
score = 75
quality = 75
tags = "FILE"
@@ -178198,30 +185150,32 @@ rule MALPEDIA_Win_Isspace_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 50 8d45f0 64a300000000 8965e8 c745fc00000000 c785505cffff00a20000 }
- $sequence_1 = { 46 8bc6 c1e004 03c6 }
- $sequence_2 = { ff15???????? 50 eb05 68???????? 68???????? ff15???????? }
- $sequence_3 = { 6800010000 8d8600010000 6a00 50 e8???????? 83c418 8bc6 }
- $sequence_4 = { e8???????? 83c418 83c60a 56 }
- $sequence_5 = { 85c0 7507 68???????? eb04 83c007 }
- $sequence_6 = { c78548ffffff9c000000 e8???????? 8ad8 c745fc00000000 }
- $sequence_7 = { eb0a 6a00 6a23 eb04 6a00 }
+ $sequence_0 = { 33c8 8bc1 8b4c2420 488b9424c0000000 88040a e9???????? 33c0 }
+ $sequence_1 = { 488b4c2460 e8???????? 488b442468 4883e0c0 }
+ $sequence_2 = { 890424 8b0424 83c003 99 83e203 03c2 c1f802 }
+ $sequence_3 = { 488b4c2448 488b0c01 e8???????? 85c0 7511 c605????????01 e8???????? }
+ $sequence_4 = { 89442434 e8???????? 488905???????? 8b442434 }
+ $sequence_5 = { 48894c2408 4883ec18 48c7042400000000 488b442420 488b0c24 0fb70448 }
+ $sequence_6 = { 8b442420 83c014 89442420 837c242040 }
+ $sequence_7 = { 880424 488b442410 48c1e005 4803442410 0fb60c24 4803c1 4889442410 }
+ $sequence_8 = { 486bc907 8b4c0c20 8b440420 33c1 b904000000 }
+ $sequence_9 = { 8b9424a0000000 03d1 8bca 8d8408a1ebd96e 8b4c2414 03c8 }
condition:
- 7 of them and filesize <434176
+ 7 of them and filesize <92160
}
-rule MALPEDIA_Win_Tapaoux_Auto : FILE
+rule MALPEDIA_Win_Stinger_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "68d778fd-5462-5b8a-898a-2fe57f5f9d68"
+ id = "03e2d1ca-b846-5787-b683-28feb74dae3e"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tapaoux"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tapaoux_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stinger"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stinger_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "f82a0c342c816d1880cfb31489fc94204aa3933a5341062512dc21730819514f"
+ logic_hash = "64d2d0bb18e9f4889ac80d1e49c5ab473a950fa26645e6f561f71db4e8eb08f3"
score = 75
quality = 75
tags = "FILE"
@@ -178235,32 +185189,32 @@ rule MALPEDIA_Win_Tapaoux_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c404 8d9424d0020000 33f6 52 55 ffd3 85c0 }
- $sequence_1 = { f7d1 49 8d7c2454 894c2418 83c9ff f2ae f7d1 }
- $sequence_2 = { 52 50 8d4c2420 68???????? 51 eb49 b900010000 }
- $sequence_3 = { 68???????? 52 ffd6 8d44245c 68???????? 50 }
- $sequence_4 = { 8be8 83fdff 0f84b0000000 8b3d???????? }
- $sequence_5 = { 83c404 8d4c2414 50 51 e8???????? 8d54241c }
- $sequence_6 = { 8d442408 55 50 8d8c241c040000 6800040000 51 56 }
- $sequence_7 = { c3 8d442408 8d4c240c 50 53 53 }
- $sequence_8 = { 68???????? 50 e8???????? 8b07 83c418 85c0 7526 }
- $sequence_9 = { aa 8bb424200c0000 b900010000 33c0 }
+ $sequence_0 = { 8bec 81ec10000000 6804000080 6a00 8b5d08 }
+ $sequence_1 = { f6c441 0f854d010000 8b45f4 50 8b5d08 ff33 }
+ $sequence_2 = { 895df8 8965f4 ff75fc ff15???????? 90 90 }
+ $sequence_3 = { 6806000000 e8???????? 83c404 e9???????? 8be5 5d c21000 }
+ $sequence_4 = { e9???????? 68???????? 8b5d0c ff33 e8???????? 83c408 }
+ $sequence_5 = { a1???????? 85c0 891c85ecbe4000 750a }
+ $sequence_6 = { 6806000000 e8???????? 83c404 a3???????? 8965f8 68???????? }
+ $sequence_7 = { ff75fc 6802000000 bb94020000 e8???????? 83c41c 8945e8 }
+ $sequence_8 = { 6800000000 6800000000 68???????? ff35???????? 6800000000 ff15???????? 90 }
+ $sequence_9 = { 8b5d08 ff33 b902000000 e8???????? 83c408 8945f0 ff750c }
condition:
- 7 of them and filesize <294912
+ 7 of them and filesize <197096
}
-rule MALPEDIA_Win_Nosu_Auto : FILE
+rule MALPEDIA_Win_Selfmake_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d0493836-076e-53ac-80d2-093749a42975"
+ id = "ca04d6b7-e045-5526-8793-d9e1e0d359e9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nosu"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nosu_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.selfmake"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.selfmake_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "8ab8c6afe29bf167cf16b426bd8eca0dcd4e462cdef53cd757a920fd1f6ec318"
+ logic_hash = "c57531acfc321c5fdc74a4f21330394c8edf44f2f30ab3dcaf573b2b773dc0b6"
score = 75
quality = 75
tags = "FILE"
@@ -178274,32 +185228,32 @@ rule MALPEDIA_Win_Nosu_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 50 8d4730 50 ff15???????? 03c0 8d5730 50 }
- $sequence_1 = { 399628040000 7438 399648010000 7430 3996b8020000 7428 8b8e48060000 }
- $sequence_2 = { 8bcf 8938 e8???????? 894500 85c0 }
- $sequence_3 = { e8???????? 59 85c0 7444 8b7c2410 bd???????? 55 }
- $sequence_4 = { 0f45cf 03ce 84c0 8b4508 51 ff742420 0f45d7 }
- $sequence_5 = { 7462 803b22 0f85d4010000 8d470c 50 8d5708 8d4c2418 }
- $sequence_6 = { 53 50 53 a5 8d942440080000 53 53 }
- $sequence_7 = { 8b442434 59 c60004 8b442430 c640010e }
- $sequence_8 = { 50 8d8e280a0000 e8???????? 59 8d442468 50 8d442424 }
- $sequence_9 = { 8d96a8000000 8d4e48 e8???????? 59 59 84c0 742c }
+ $sequence_0 = { 83c104 3bf0 7ce3 68???????? }
+ $sequence_1 = { 83e107 894df4 8b55f4 52 ff15???????? a1???????? 8be5 }
+ $sequence_2 = { 8d742430 742e e8???????? 6aff }
+ $sequence_3 = { 47 84c0 75f8 66a1???????? 668907 8d44243c 8bd0 }
+ $sequence_4 = { 8945f8 837df800 7408 8b45f8 e9???????? e8???????? }
+ $sequence_5 = { 8b4b2c 6a00 6a01 51 ffd0 8b16 83c604 }
+ $sequence_6 = { 7604 2bf1 eb02 33f6 8b4310 25c0010000 83f840 }
+ $sequence_7 = { 81fa???????? 7209 83c014 3bc1 72eb }
+ $sequence_8 = { 51 e8???????? 8b742418 8bbc2418020000 }
+ $sequence_9 = { e8???????? 56 e8???????? 8b442424 8b35???????? 83c414 50 }
condition:
- 7 of them and filesize <513024
+ 7 of them and filesize <932864
}
-rule MALPEDIA_Win_Bid_Ransomware_Auto : FILE
+rule MALPEDIA_Win_Dimnie_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "123f6d77-eca2-5400-ac56-e3f30e76b796"
+ id = "8c590346-8ec4-5fdf-b560-136be983395f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bid_ransomware"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bid_ransomware_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dimnie"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dimnie_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "040b1903110ce367e4f39e634882ebba58d8e30bf0983ec0eaeaeca56a956f74"
+ logic_hash = "0f3f067f034444fcc73a96e10a6a53b5dc6ee2b790aaefb3f5f862bcac5e875a"
score = 75
quality = 75
tags = "FILE"
@@ -178313,32 +185267,32 @@ rule MALPEDIA_Win_Bid_Ransomware_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c705????????20202020 68???????? 50 e8???????? }
- $sequence_1 = { 6a00 e8???????? ff75fc e8???????? c9 c3 }
- $sequence_2 = { ff75b0 e8???????? ff75b0 e8???????? 6800800000 ff75a8 }
- $sequence_3 = { 55 8bec 83c4f4 6800800000 6a40 }
- $sequence_4 = { 881f 83c701 83f800 77e3 eb0e }
- $sequence_5 = { 8b4d08 80c141 c745c05c5c3f5c 884dc4 c745c53a5c2a2e }
- $sequence_6 = { 53 6a00 6a00 6a00 ff75e4 e8???????? }
- $sequence_7 = { 8945f0 eb15 ff75f4 e8???????? }
- $sequence_8 = { 68ea030000 ff35???????? e8???????? 8945fc }
- $sequence_9 = { e8???????? 8b85acfdffff 83e001 7414 8b7508 }
+ $sequence_0 = { 7605 8b450c eb54 8b550c 2b5508 83fa01 751c }
+ $sequence_1 = { 33c0 eb6e 8b4508 3b450c 7505 8b4508 }
+ $sequence_2 = { 8945f4 8b45f4 c1e804 8945f4 8b4df8 83c101 }
+ $sequence_3 = { 8b550c 2b5508 8955f8 0f31 8945f4 8b45f4 c1e804 }
+ $sequence_4 = { eb6e 8b4508 3b450c 7505 8b4508 eb61 }
+ $sequence_5 = { 2b5508 83fa01 751c 0f31 }
+ $sequence_6 = { 8b4508 eb61 8b4d08 3b4d0c 7605 8b450c }
+ $sequence_7 = { 8b4d0c 8a55af 885102 837d1002 7e13 8b4508 0fb64802 }
+ $sequence_8 = { 8b4510 8b08 83e107 8b5510 890a }
+ $sequence_9 = { c70201000000 8b4508 8b08 83e10f 8b5508 890a 8b450c }
condition:
- 7 of them and filesize <57344
+ 7 of them and filesize <212992
}
-rule MALPEDIA_Win_Darkbit_Auto : FILE
+rule MALPEDIA_Win_Mount_Locker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "58b27aad-7d48-54be-9cff-6269fdf4ce6e"
+ id = "6832e6a1-eaa1-5e1c-99c0-2c5304573141"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkbit"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkbit_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mount_locker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mount_locker_auto.yar#L1-L152"
license_url = "N/A"
- logic_hash = "06c0013c639973d9f2d79cd394915657a8e01f1fe7c56128c97a4b11c48d29ab"
+ logic_hash = "bff6076907046250738924c00fe6ba5da63e4a09d46fe90acd3aa54210bff35b"
score = 75
quality = 75
tags = "FILE"
@@ -178352,32 +185306,38 @@ rule MALPEDIA_Win_Darkbit_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 48898424f0140000 48899c2498020000 488b0d???????? 48898c2478100000 488d05c1742500 90 }
- $sequence_1 = { eb23 4889c7 488b8c24d0180000 e8???????? 488d7810 488b8424c8180000 6690 }
- $sequence_2 = { e8???????? 4889842410010000 48899c2418070000 488b442460 48c7c3feffffff e8???????? 4889842470010000 }
- $sequence_3 = { eb11 488d7818 488b8c24f0110000 e8???????? 488b8c24e8030000 48894810 833d????????00 }
- $sequence_4 = { 833d????????00 7515 488b8c24a81e0000 488908 488905???????? 90 eb1c }
- $sequence_5 = { e8???????? 488b542440 48895008 833d????????00 750d 488b9424c0000000 488910 }
- $sequence_6 = { e8???????? 4889842428080000 48899c2480110000 488b8424a0080000 48c7c3ffffffff 0f1f440000 e8???????? }
- $sequence_7 = { e8???????? 488d8424d8000000 488b9c2408010000 90 e8???????? b801000000 eb21 }
- $sequence_8 = { e8???????? 803d????????00 7431 488d1543fa1a00 488915???????? 833d????????00 7509 }
- $sequence_9 = { ffd2 84c0 7556 488d0509aa3000 488b5c2430 488b4c2438 e8???????? }
+ $sequence_0 = { 81f900000780 7503 0fb7c0 3d2e050000 }
+ $sequence_1 = { f30f5905???????? 0f5ad0 66490f7ed0 e8???????? }
+ $sequence_2 = { 4d8bc8 4c8bc2 4c8bf2 8bf1 }
+ $sequence_3 = { 8bc8 81e10000ffff 81f900000780 7503 }
+ $sequence_4 = { 488b0b 41b902000000 4533c0 33d2 }
+ $sequence_5 = { 488d4df0 4889442428 4533c9 4533c0 }
+ $sequence_6 = { 488bcb 488b15???????? e8???????? 85c0 }
+ $sequence_7 = { 488364242000 4533c9 488b4c2458 33d2 c744243001000000 c744243c02000000 }
+ $sequence_8 = { 4c8bf2 8bf1 33d2 33c9 }
+ $sequence_9 = { ff15???????? 85c0 7509 f0ff05???????? }
+ $sequence_10 = { b905000000 ff15???????? 3d040000c0 7494 85c0 }
+ $sequence_11 = { 7505 e8???????? 833d????????00 7409 833d????????00 }
+ $sequence_12 = { 8d442430 68???????? 50 ffd7 }
+ $sequence_13 = { a1???????? 83f804 7515 68???????? }
+ $sequence_14 = { 8bf0 85f6 7424 6800010000 }
+ $sequence_15 = { ff15???????? 85c0 7409 f0ff05???????? eb1e 56 }
condition:
- 7 of them and filesize <11612160
+ 7 of them and filesize <368640
}
-rule MALPEDIA_Win_Sidetwist_Auto : FILE
+rule MALPEDIA_Win_Rhino_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "234f5e67-21ea-563f-a765-16d670746925"
+ id = "11a60875-723d-53d2-ab23-e9023e9a450c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sidetwist"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sidetwist_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rhino"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rhino_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "5b593ac062a3ee588643c8e2045ef28da674c3f54189c5d0eebe42dcfcc6f71f"
+ logic_hash = "06d154dd08a9cc876dd4f55564b3f05b1da55b4793bd9c16429a3bb1cbe16dda"
score = 75
quality = 75
tags = "FILE"
@@ -178391,32 +185351,32 @@ rule MALPEDIA_Win_Sidetwist_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c644244600 4839d0 0f833a020000 488b4c2450 837c2458ff 0f94c0 4885c9 }
- $sequence_1 = { e8???????? 807e2000 48898424b0000000 7412 488d8c24b0000000 ba20000000 e8???????? }
- $sequence_2 = { 4488742457 0fb6442457 4c8db42494000000 4c8d4c2460 4889fa 4c89742440 488d8c2480000000 }
- $sequence_3 = { 89c8 884520 807d2040 7612 807d205a 770c 0fb64520 }
- $sequence_4 = { 896e18 4809c3 4889f8 488917 48895f08 4883c458 5b }
- $sequence_5 = { bfffffffff 41bfffffffff e9???????? c644246c00 8844246e e9???????? 488b03 }
- $sequence_6 = { 4c29cb 4c39c3 490f47d8 4885db 7411 480310 4883fb01 }
- $sequence_7 = { 7218 4c8b05???????? 458b08 4585c9 755e 448b41f8 4585c0 }
- $sequence_8 = { 89c7 440fb603 29df c1e702 4885c0 b800000000 0f44f8 }
- $sequence_9 = { 6690 4885d2 7521 448b1e 4585db 0f8524020000 8b05???????? }
+ $sequence_0 = { 8b4160 c3 6a40 58 c3 b8???????? e8???????? }
+ $sequence_1 = { c745f00f000000 885ddc 53 be04010000 895dfc 56 8d4ddc }
+ $sequence_2 = { c1c105 8b400c 89442440 8bc5 034c2440 33c3 23c6 }
+ $sequence_3 = { 2b16 b8ffffff03 c1fa06 2bc2 3bc1 7217 8d040a }
+ $sequence_4 = { e8???????? 8bf9 897df0 8b7508 8d4f0c c74704???????? 56 }
+ $sequence_5 = { e8???????? 895d60 897d64 8b06 8d4de0 51 8bce }
+ $sequence_6 = { 890496 85c9 75e6 42 3b54240c 72ec 33c0 }
+ $sequence_7 = { 74af 8b4634 8d4d08 51 50 50 894508 }
+ $sequence_8 = { 5e 64890d00000000 c9 c3 8b514c 395148 57 }
+ $sequence_9 = { 8b4f14 8b4114 3b410c 7507 8bcf e8???????? 33c0 }
condition:
- 7 of them and filesize <2002944
+ 7 of them and filesize <1288192
}
-rule MALPEDIA_Win_Banatrix_Auto : FILE
+rule MALPEDIA_Win_Brbbot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dddc42c8-ebb5-5b25-8e19-698be8f181ff"
+ id = "e240fcbc-2659-5f11-92b2-f24493c78ffd"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.banatrix"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.banatrix_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.brbbot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.brbbot_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "ad75928262b7ab312e9d49af768e2651c88b8c026115565bb62125e134a2e0bd"
+ logic_hash = "d23aa206f76a72b99ca843cfc9c1f11b947cf7f249b06e1b49eb77df3aca0670"
score = 75
quality = 75
tags = "FILE"
@@ -178430,32 +185390,32 @@ rule MALPEDIA_Win_Banatrix_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83ec10 894208 89f7 31c0 f3aa }
- $sequence_1 = { e8???????? 8b4304 85c0 741b c744240800800000 c744240400000000 }
- $sequence_2 = { c744240806000000 893c24 c1e804 40 0fb7c0 }
- $sequence_3 = { 8b5320 0345d0 89542404 890424 }
- $sequence_4 = { e9???????? e8???????? c744240824000000 c744240400000000 }
- $sequence_5 = { 51 c9 c3 55 89e5 57 }
- $sequence_6 = { 83ec10 85c0 8945d4 7542 8b45d0 c744240c04000000 c744240800300000 }
- $sequence_7 = { 8b75d0 8b7dd4 2b7e34 897dcc 7514 8b7304 }
- $sequence_8 = { 83787c00 7511 c704247f000000 e8???????? 31c0 51 eb66 }
- $sequence_9 = { 85c0 56 56 7416 8b03 c745d000000000 }
+ $sequence_0 = { 7509 488d0daad10000 eb02 33c9 e8???????? 4883c438 }
+ $sequence_1 = { f2ae 48f7d1 48ffc9 4c8bc1 498d8e10040000 488bd5 e8???????? }
+ $sequence_2 = { 48f7d1 4c8d41ff 488d8b04010000 e8???????? }
+ $sequence_3 = { 885c2470 448bee 448bfe e8???????? 488b05???????? 4889442458 }
+ $sequence_4 = { 48895808 488970e8 33ff 488978b8 4c8960e0 }
+ $sequence_5 = { 48f7d1 48ffc9 4881f904010000 0f8724010000 4883c9ff }
+ $sequence_6 = { 81fa01010000 7d13 4863ca 8a44191c 42888401c0230100 }
+ $sequence_7 = { 488bfa ff15???????? 4c8d4704 488bc8 ba08000000 ff15???????? }
+ $sequence_8 = { 4c8b7540 8bd8 85c0 0f88d6020000 4c8d4da8 }
+ $sequence_9 = { 33d2 488bce e8???????? ff15???????? 4c8bc6 488bc8 33d2 }
condition:
- 7 of them and filesize <180224
+ 7 of them and filesize <198656
}
-rule MALPEDIA_Win_Shapeshift_Auto : FILE
+rule MALPEDIA_Win_Banpolmex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "08e6a360-def4-58d5-989a-762ada20c1ff"
+ id = "f5c73e0b-c575-562f-9127-4bdfc5c88735"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shapeshift"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shapeshift_auto.yar#L1-L105"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.banpolmex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.banpolmex_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "c522b147cc687acbd3ced32f880a4cbfad89b8f069e6c6ec7d0ae0159c8619d1"
+ logic_hash = "5c80d00898c7981631095abf56b16c379bf161bce0c3d518d50cadc7dd22c1a6"
score = 75
quality = 75
tags = "FILE"
@@ -178469,32 +185429,34 @@ rule MALPEDIA_Win_Shapeshift_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 33d2 b93b110f00 f7f1 68???????? 8915???????? e8???????? }
- $sequence_1 = { 6a00 6a07 68000000c0 51 ff15???????? }
- $sequence_2 = { 8b45fc 817848d0f74100 7409 ff7048 e8???????? }
- $sequence_3 = { 394508 7c1f 3934bd38054200 7531 e8???????? 8904bd38054200 }
- $sequence_4 = { 6a00 57 e8???????? 8b5dfc 83c410 8b35???????? 53 }
- $sequence_5 = { 8365fc00 8b049d38054200 8b4de0 f644082801 7515 e8???????? c70009000000 }
- $sequence_6 = { c3 3b0d???????? f27502 f2c3 f2e987080000 }
- $sequence_7 = { 6a0c 7550 e8???????? 83c404 8bf8 }
+ $sequence_0 = { 7419 4c8b0f 8bd0 41b801000000 498bcc e8???????? 4883f801 }
+ $sequence_1 = { ff15???????? 488d1530980800 488bcb 488905???????? ff15???????? 488d1529980800 488bcb }
+ $sequence_2 = { c3 488d15ea560200 488bcf e8???????? b80a000000 488b5c2460 4883c420 }
+ $sequence_3 = { 0f97c0 890d???????? 4883c428 c3 8b0d???????? 44891d???????? 3bc1 }
+ $sequence_4 = { 448d4201 4d8bb4c5a8010000 488bcb e8???????? 85c0 7919 488d156ca70100 }
+ $sequence_5 = { 4d016810 4d016018 49017020 49017828 49015830 4d015838 4d015040 }
+ $sequence_6 = { 660f1f440000 483bd5 7733 488bca 4869c988000000 4903c9 428b44210c }
+ $sequence_7 = { 4883ec28 488b0d???????? 4885c9 7409 83caff ff15???????? 33c0 }
+ $sequence_8 = { 4c8b5c2420 488b442428 4c011b 480107 0fb7442438 66ffc0 6689442438 }
+ $sequence_9 = { 4c897c2458 3c02 0f85a4000000 41b803000000 4533ff 898c24a8000000 44898424b0000000 }
condition:
- 7 of them and filesize <303104
+ 7 of them and filesize <1555456
}
-rule MALPEDIA_Win_Spedear_Auto : FILE
+rule MALPEDIA_Win_Backswap_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "064ca511-db37-50e7-a5f5-98bdd145296d"
+ id = "8b9036c3-1342-5fdd-b202-655dad83c8d1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spedear"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spedear_auto.yar#L1-L246"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.backswap"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.backswap_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "3ab20c94a066f6f4783dff8cb4bf09780239780b3bd9f55c80bdf4166aa7a997"
+ logic_hash = "a378488e042d6e06f37e68439e6beddf9b3f11fc0a2449d478058f24368f291d"
score = 75
- quality = 71
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -178506,48 +185468,32 @@ rule MALPEDIA_Win_Spedear_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83e207 03c2 c1f803 83c40c }
- $sequence_1 = { 8b4718 8a5f06 50 894608 e8???????? }
- $sequence_2 = { 53 50 e8???????? 8b7e0c 895e10 }
- $sequence_3 = { 894618 ffd7 89461c 5f }
- $sequence_4 = { 33f6 8b4704 8b4f08 53 50 8bde e8???????? }
- $sequence_5 = { 8b44240c 8b08 8b442410 53 55 }
- $sequence_6 = { c1e208 40 0bca 3bc3 7c02 }
- $sequence_7 = { 5b c20400 8b4c240c 57 53 51 }
- $sequence_8 = { 6a00 68???????? e8???????? 83c40c 68d0070000 }
- $sequence_9 = { 833e00 741e 8b5608 8b4604 6a00 }
- $sequence_10 = { 833e00 741a 6a00 6a00 ff7608 }
- $sequence_11 = { 6a00 ff7608 ff5604 6800800000 }
- $sequence_12 = { 394878 7456 39487c 7451 }
- $sequence_13 = { 8bc7 5e 5f 5b 5d c3 6a08 }
- $sequence_14 = { ff5604 6800800000 6a00 ff7608 }
- $sequence_15 = { 74ce 56 53 ff7510 ff75d8 6a00 6a00 }
- $sequence_16 = { 4154 4883ec20 4c8b5120 4d8be0 488bea 410fb74206 488bf1 }
- $sequence_17 = { 418d5001 488bcf 4803c7 48894308 }
- $sequence_18 = { 50 8d4de0 e8???????? 83781410 59 5b 7202 }
- $sequence_19 = { 750b 488bcf ff15???????? eb07 488bd5 }
- $sequence_20 = { 488bc3 488d152bd50000 48c1f805 83e11f 488b04c2 486bc958 }
- $sequence_21 = { 723a 488d05349b0000 483bd8 772e }
- $sequence_22 = { 488364242000 40886c245c 488d0d10d10000 4c8d4c244c }
- $sequence_23 = { 8a80b4182400 08443b1d 0fb64601 47 3bf8 76ea }
- $sequence_24 = { 4883ec20 488d05fe690000 488bfa 488bd9 488901 }
- $sequence_25 = { 488d15032e0000 488bce 488905???????? ff15???????? }
+ $sequence_0 = { 5f 5a 5b c9 c21000 83f0ff 5e }
+ $sequence_1 = { 8b7508 ff4508 8bfb 3bd3 0f8572ffffff 33c9 e9???????? }
+ $sequence_2 = { 33d2 8bdf 4b eb1c 85c9 }
+ $sequence_3 = { eb1c 85c9 7508 3bdf 7404 }
+ $sequence_4 = { ebd4 3c3f 74c4 3c2a 7508 8bdf 897508 }
+ $sequence_5 = { f366a5 59 5f 5e c9 c20c00 55 }
+ $sequence_6 = { 74ed 33c0 eb04 8bc6 }
+ $sequence_7 = { 4b eb1c 85c9 7508 3bdf 7404 8bce }
+ $sequence_8 = { 83f0ff 5e 5f 5a 5b }
+ $sequence_9 = { 7482 8b7508 ff4508 8bfb 3bd3 0f8572ffffff 33c9 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <122880
}
-rule MALPEDIA_Win_Kronos_Auto : FILE
+rule MALPEDIA_Win_Wannacryptor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8d31fd16-d4f2-5a2a-96ec-ac39493ba957"
+ id = "e56d2000-fe42-59bd-8926-478b3a54b7b3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kronos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kronos_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wannacryptor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wannacryptor_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "9add781f31640b82e44b92fb87f47ac9fbcee8b3e1525e4790235c25c58c2848"
+ logic_hash = "c696b2074a3cd60e9575143d9577c550babed6e9c2f46c424c5b90d1a1647723"
score = 75
quality = 75
tags = "FILE"
@@ -178561,32 +185507,32 @@ rule MALPEDIA_Win_Kronos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d542450 52 03c6 50 57 ffd3 85c0 }
- $sequence_1 = { 813e50450000 7549 57 56 ff75fc e8???????? 8b450c }
- $sequence_2 = { e8???????? 33db 6a40 8d4628 53 50 }
- $sequence_3 = { e8???????? 85db 0f854fffffff eb1c 8d4dd0 be02000000 e8???????? }
- $sequence_4 = { 897804 8930 ff461c 6a00 }
- $sequence_5 = { 803d????????01 56 750f 33f6 8d4df0 e8???????? 8bc6 }
- $sequence_6 = { eb1d 8b0f e8???????? 8b0f 8b30 6a04 e8???????? }
- $sequence_7 = { 0355dc 8b45e8 2b45ec 03ca 3b450c 7356 29450c }
- $sequence_8 = { c3 55 8bec 83ec5c 56 8d45a4 50 }
- $sequence_9 = { 3b7104 7505 8b06 894104 3b7108 7506 8b5604 }
+ $sequence_0 = { 56 8bf1 57 8b7c241c 8b4670 }
+ $sequence_1 = { 8854243c 8b44243c 50 51 8bce }
+ $sequence_2 = { b801000000 33ff 85c0 7e76 8bd8 8b5500 03cf }
+ $sequence_3 = { 8bce e8???????? 8a4649 84c0 7419 8b4620 }
+ $sequence_4 = { ff15???????? 50 e8???????? 85c0 742e 8b4004 8d542404 }
+ $sequence_5 = { 8b4674 c6464801 85c0 7509 6a00 }
+ $sequence_6 = { 50 ff15???????? 50 e8???????? 8b4820 6a00 6a00 }
+ $sequence_7 = { 8b4678 8d7e44 85c0 755f 8b17 }
+ $sequence_8 = { e8???????? 8d4648 8d4c2410 50 c744243000000000 }
+ $sequence_9 = { 57 8b7c241c 8b4670 85c0 7503 }
condition:
- 7 of them and filesize <1302528
+ 7 of them and filesize <540672
}
-rule MALPEDIA_Win_Coinminer_Auto : FILE
+rule MALPEDIA_Win_Buhtrap_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "05a9b3c6-9a1c-50a2-a943-afdee621f718"
+ id = "25eb4b11-3715-52d0-a7c7-9dac6aa80ccc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.coinminer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.coinminer_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.buhtrap"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.buhtrap_auto.yar#L1-L162"
license_url = "N/A"
- logic_hash = "254b4cb9ab983948d36cfb896be0834484f66bd70a718e15bb65a41d1319a142"
+ logic_hash = "d4e0c8ac83aa0b6c13a2f72737ffccb143e82cce7ba2ea9d1a844cc8381c4b50"
score = 75
quality = 75
tags = "FILE"
@@ -178600,34 +185546,78 @@ rule MALPEDIA_Win_Coinminer_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85d2 750d 8b45f8 8b55fc 5f 5e }
- $sequence_1 = { 8d7f04 73ef 83c104 8a10 7410 48 ffc0 }
- $sequence_2 = { e9???????? 6a00 ff742414 ffd6 ff742414 8b3d???????? ffd7 }
- $sequence_3 = { c3 8bc6 c745f200000000 99 0f57c0 66c745f60000 660fd645ea }
- $sequence_4 = { 8bf0 e8???????? 8bf8 8d842450130000 }
- $sequence_5 = { 53 56 8b35???????? 8bd9 57 8b3d???????? }
- $sequence_6 = { 57 ff15???????? c70300000000 8b4510 5f c70600000000 5e }
- $sequence_7 = { 9b 53 83473220 2c6a }
- $sequence_8 = { 8d842434010000 50 ff15???????? 56 e8???????? 57 }
- $sequence_9 = { 83c408 890d???????? 8bf2 8935???????? 85c9 7504 85f6 }
+ $sequence_0 = { 59 59 84c0 0f8435010000 }
+ $sequence_1 = { 7423 8b44240c 33d2 6a64 59 f7f1 }
+ $sequence_2 = { c3 b301 ebe1 55 8bec 83ec18 }
+ $sequence_3 = { 6a00 50 8d442414 c744242c04000000 }
+ $sequence_4 = { 6a06 8bce e8???????? 8a1d???????? 56 }
+ $sequence_5 = { 0f8489000000 837d1400 747b 6a09 59 33c0 8d7c242c }
+ $sequence_6 = { 7405 e8???????? 85f6 7907 32c0 e9???????? 8365f000 }
+ $sequence_7 = { ffd6 57 ffd6 33c0 85db 0f94c0 5f }
+ $sequence_8 = { 754e 6a01 53 50 }
+ $sequence_9 = { 53 68???????? 890e 894604 e8???????? 50 }
+ $sequence_10 = { 897dfc e8???????? 59 84c0 0f8497000000 3bdf }
+ $sequence_11 = { 6aff ff742420 ff7624 ffd7 ff742418 e8???????? }
+ $sequence_12 = { ffd7 6a00 689385e784 6a28 68???????? }
+ $sequence_13 = { 894624 8b442414 894604 a808 7466 }
+ $sequence_14 = { 753d 8b4e2c 83c104 e8???????? e8???????? }
+
+ condition:
+ 7 of them and filesize <131072
+}
+rule MALPEDIA_Win_Mrdec_Auto : FILE
+{
+ meta:
+ description = "autogenerated rule brought to you by yara-signator"
+ author = "Felix Bilstein - yara-signator at cocacoding dot com"
+ id = "5cd525b0-3fcd-5de1-aa88-bd5dca592c29"
+ date = "2023-12-06"
+ modified = "2023-12-08"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mrdec"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mrdec_auto.yar#L1-L126"
+ license_url = "N/A"
+ logic_hash = "c22120d79fe39ae9d27a4d21c75a9bbd9a26aee0b664e8fa2f821d0411c6aa0d"
+ score = 75
+ quality = 75
+ tags = "FILE"
+ version = "1"
+ tool = "yara-signator v0.6.0"
+ signator_config = "callsandjumps;datarefs;binvalue"
+ malpedia_rule_date = "20231130"
+ malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
+ malpedia_version = "20230808"
+ malpedia_license = "CC BY-SA 4.0"
+ malpedia_sharing = "TLP:WHITE"
+
+ strings:
+ $sequence_0 = { c64446fa00 57 56 e8???????? 68???????? 56 e8???????? }
+ $sequence_1 = { 6a00 8d45cc 50 68ef000000 68???????? }
+ $sequence_2 = { 50 ff75f0 6a00 6a00 6a00 ff75e8 e8???????? }
+ $sequence_3 = { 7532 68dc050000 ff75dc 68???????? e8???????? }
+ $sequence_4 = { 6a00 6814010000 68???????? ff75d8 e8???????? 8d3550514000 }
+ $sequence_5 = { 8bec ff7508 6a40 e8???????? 0bc0 750c 68c8000000 }
+ $sequence_6 = { 81c700020000 68???????? 57 e8???????? 68???????? 57 e8???????? }
+ $sequence_7 = { 59 51 80c141 884808 ff05???????? 6a00 6a00 }
+ $sequence_8 = { 6a02 e8???????? 0bc0 0f8530010000 c745f000400000 ff75f0 }
+ $sequence_9 = { 6a00 6a00 e8???????? ff75dc e8???????? }
condition:
- 7 of them and filesize <1523712
+ 7 of them and filesize <44864
}
-rule MALPEDIA_Win_Vsingle_Auto : FILE
+rule MALPEDIA_Win_Blister_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "39c4d7b9-45d8-55fa-afdc-e3bdbe3bcacd"
+ id = "e15c5b26-46b1-50a6-b793-c24acb88c7d0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vsingle"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vsingle_auto.yar#L1-L182"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blister"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blister_auto.yar#L1-L129"
license_url = "N/A"
- logic_hash = "83d89a8e2f1a1d70a66e028468bac58cc5e5d328eca56cc57ee9f6d9e54be732"
- score = 75
- quality = 75
+ logic_hash = "2e7268df1a1003febf7615ed82849d5ba6785115864de7e2d3f4d8bf888a50fc"
+ score = 60
+ quality = 25
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -178639,38 +185629,32 @@ rule MALPEDIA_Win_Vsingle_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83c408 8945ec 8b4dec 8b550c 8d440a01 89450c 8b4d0c }
- $sequence_1 = { 8955b8 eb14 8b45c0 83c004 8945c0 8b4dbc 83c102 }
- $sequence_2 = { 83c408 8985f0feffff 83bdf0feffff00 7507 33c0 e9???????? 8b95f0feffff }
- $sequence_3 = { 52 680c030000 8b4508 50 }
- $sequence_4 = { 83c408 8985f4eeffff 8b95f4eeffff 8995f0eeffff c745fc00000000 8b85f0eeffff }
- $sequence_5 = { 8955b8 8b45d0 83c001 8945d0 837db803 7d0c 6a3d }
- $sequence_6 = { 83c408 898500efffff 83bd00efffffff 7529 8b9504efffff 52 8d8524f7ffff }
- $sequence_7 = { 33c0 8945e9 8945ed 8945f1 8945f5 8845f9 }
- $sequence_8 = { 50 b807752b15 81f0467f1fbf 81f08c7668e6 81e8d57c5c4c 8b0c28 }
- $sequence_9 = { 82e8ef e9???????? 52 53 bb4c969f2a 81f3b4d3bba6 81c3c02d0a2f }
- $sequence_10 = { 81c7745e2200 81c736b60a42 81c7b551a68d 81f7e7564bc6 897c2404 }
- $sequence_11 = { bbf93d64ba 81f345ba76fc 81f381c713f5 81f34d7b2ffd 81f346dc0990 81c33217d821 8b142b }
- $sequence_12 = { 5b 57 50 b86a45ae9f 81c07b6673f5 81f081118d0d }
- $sequence_13 = { bb86d72160 e9???????? 59 51 b9cf4a22af }
- $sequence_14 = { 81eb96c3a483 668b0c18 5b 53 bbd7e0d126 81f3b7cf22ba 81c3282d094f }
- $sequence_15 = { e9???????? bf756ddf55 81f7960c0426 eb36 81c7745e2200 81c736b60a42 }
+ $sequence_0 = { 33f6 8d4447fe 8975fc 8945f8 3bfe 0f8447010000 }
+ $sequence_1 = { 57 ff75fc ffd6 85c0 7529 33c9 41 }
+ $sequence_2 = { e8???????? 8bf0 85f6 7c2e 6a04 58 8d4d08 }
+ $sequence_3 = { 8bff 55 8bec b8dc140000 e8???????? a1???????? 33c5 }
+ $sequence_4 = { 8b3d???????? 6870010000 684c040000 ff7604 ffd7 8b1d???????? }
+ $sequence_5 = { 8d45a0 50 ff750c c745a060000000 6891100000 ff36 }
+ $sequence_6 = { ff7604 ff75f4 ff75e8 6a02 ff75fc ff15???????? 85c0 }
+ $sequence_7 = { 8b4e28 8d45f8 50 895df8 e8???????? }
+ $sequence_8 = { ff15???????? 8bc8 0fb701 f7d8 1bc0 23c1 5e }
+ $sequence_9 = { 50 8b859cf7ffff 8b8c052cf7ffff e8???????? 8985a8f7ffff 85c0 0f8cf9010000 }
condition:
- 7 of them and filesize <940032
+ 7 of them and filesize <1822720
}
-rule MALPEDIA_Win_Purelocker_Auto : FILE
+rule MALPEDIA_Win_Lockbit_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d1d522a1-058f-5ee5-85f2-56e8688f09bf"
+ id = "945a5bdc-50cc-5372-b470-aafc3e12d474"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.purelocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.purelocker_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lockbit"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lockbit_auto.yar#L1-L203"
license_url = "N/A"
- logic_hash = "42140169d70d3c64021f0eb71e13968d0cb2f62e4e2540159ee39f96b2cca71d"
+ logic_hash = "ef292234a38c5f85ea42d6220d555a65163be7c7bef94693195ea2cefdb10cc0"
score = 75
quality = 75
tags = "FILE"
@@ -178684,32 +185668,42 @@ rule MALPEDIA_Win_Purelocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c7042400000000 8d442434 50 8d842440040000 50 8d842440020000 }
- $sequence_1 = { c1e908 81e1ff000000 331c85201c0110 8b442414 8b148d20180110 335f08 }
- $sequence_2 = { 8b442410 0fb6c0 330c8520300110 8bc6 }
- $sequence_3 = { 6a00 85c9 59 751a 8bda 53 }
- $sequence_4 = { 53 ba17000000 83ec04 c7042400000000 4a 75f3 e8???????? }
- $sequence_5 = { 8d1524400110 59 e8???????? 741e 8b542468 52 }
- $sequence_6 = { 50 31c0 50 8b15???????? 52 e8???????? 5a }
- $sequence_7 = { e8???????? 8d1524400110 8d0d285e0110 e8???????? 8d1524400110 8d0d845d0110 }
- $sequence_8 = { e8???????? e8???????? 011424 e8???????? 58 8b542408 52 }
- $sequence_9 = { 50 680a000000 ff742418 e8???????? e8???????? 52 e8???????? }
+ $sequence_0 = { 0f28c8 660f73f904 660fefc8 0f28c1 660f73f804 }
+ $sequence_1 = { 50 e8???????? 8d858cfeffff 50 8d45c0 50 8d45a0 }
+ $sequence_2 = { fec1 47 4e 85f6 75d2 5d }
+ $sequence_3 = { 56 57 8d9d84fcffff b900c2eb0b e2fe e8???????? 53 }
+ $sequence_4 = { 6683f866 7706 6683e857 eb17 6683f830 720c 6683f839 }
+ $sequence_5 = { 33db 55 8b6d10 8bc1 }
+ $sequence_6 = { 8d8550fdffff 50 6a00 ff15???????? }
+ $sequence_7 = { 33c0 8d7df0 33c9 53 0fa2 }
+ $sequence_8 = { f745f800000002 740c 5f 5e }
+ $sequence_9 = { 02d3 8a5c1500 8a541d00 8a541500 fec2 8a441500 }
+ $sequence_10 = { 33d0 8bc1 c1e810 0fb6c0 c1e208 }
+ $sequence_11 = { 53 56 57 33c0 8b5d14 33c9 33d2 }
+ $sequence_12 = { 8d45f8 50 8d45fc 50 ff75fc ff75f4 }
+ $sequence_13 = { e9???????? 6683f841 720c 6683f846 7706 6683e837 }
+ $sequence_14 = { 6a00 6a00 6800000040 ff75d4 }
+ $sequence_15 = { 5b 8907 897704 894f08 89570c f745f800000002 740c }
+ $sequence_16 = { 214493fc 8b5df8 8bc3 43 }
+ $sequence_17 = { 7407 8bce e8???????? 837b0402 }
+ $sequence_18 = { 7414 663901 740f 0f1f440000 }
+ $sequence_19 = { 1bdb 83e30b 83c328 ff7518 8b7d08 8d049500000000 ff7514 }
condition:
- 7 of them and filesize <193536
+ 7 of them and filesize <2049024
}
-rule MALPEDIA_Win_Lookback_Auto : FILE
+rule MALPEDIA_Win_Fishmaster_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5641bb4f-38a9-52e1-a4b7-204dc4620521"
+ id = "ac4d1a12-e633-54d1-8952-cc6fd81de034"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lookback"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lookback_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fishmaster"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fishmaster_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "68449af30b767d5c82dfe8271f4bbe8c83972fe98d28065e60e3bffd1a6dc166"
+ logic_hash = "ee895ce428e3021476e31fc5a4cbc7a0e07349c7fde3100efce8681f3e034d54"
score = 75
quality = 75
tags = "FILE"
@@ -178723,32 +185717,32 @@ rule MALPEDIA_Win_Lookback_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 8944241a 57 66894c2416 89442422 8bfa }
- $sequence_1 = { 8b7c241c 33ed 8b473c 8b443878 03c7 8b5024 }
- $sequence_2 = { 55 8bec 51 53 c745fc00000000 b801000000 }
- $sequence_3 = { c3 5e 5d 33c0 5b 81c410070000 c3 }
- $sequence_4 = { 3c01 893d???????? 893d???????? 752e }
- $sequence_5 = { c644240800 88442415 e8???????? 8d4c240c 89442408 51 }
- $sequence_6 = { 8d5108 d1e8 85c0 7e33 }
- $sequence_7 = { 74a7 8b06 85c0 757b }
- $sequence_8 = { 52 8d442418 57 50 68???????? 57 57 }
- $sequence_9 = { 55 8bec 51 53 c745fc00000000 b801000000 0fa2 }
+ $sequence_0 = { 4883f81f 7736 498bc8 e8???????? 48c7471000000000 }
+ $sequence_1 = { e8???????? 488bc3 4c8b4318 4983f810 }
+ $sequence_2 = { 7203 498b06 40883c08 c644080100 e9???????? 440fb6cf }
+ $sequence_3 = { 488d156e220000 488bcb ff15???????? 488d156e220000 488bcb ff15???????? 4c8be8 }
+ $sequence_4 = { 4157 4883ec60 488bfa 488bd9 33f6 897098 488970b0 }
+ $sequence_5 = { 48837f1810 7203 488b07 488d4c2438 }
+ $sequence_6 = { 0fb65310 8d42ff 3cfd 7718 88940d84000000 4883c314 }
+ $sequence_7 = { 46383400 75f7 488d9580000000 488d4d20 e8???????? }
+ $sequence_8 = { 480f434c2440 420fb6440803 4288440904 488d442440 48837c245810 480f43442440 488d4c2440 }
+ $sequence_9 = { 4c8b45f8 488d15ce200000 488bcf ff15???????? 488bf8 4c89742430 4489742428 }
condition:
- 7 of them and filesize <131072
+ 7 of them and filesize <812032
}
-rule MALPEDIA_Win_Hunter_Auto : FILE
+rule MALPEDIA_Win_Dratzarus_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a2ce8975-358a-5feb-855e-0c18799189f7"
+ id = "3e7875e3-7e0c-5dea-9e90-8b6135466b8c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hunter"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hunter_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dratzarus"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dratzarus_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "4840112788d43f80efa44bf4553c38cceb240b146b43c82ea7ba535d388455f9"
+ logic_hash = "5f92bffb1ff676600291544ee9f45d8f2036c734b0601a5e03b740f618ff0f21"
score = 75
quality = 75
tags = "FILE"
@@ -178762,32 +185756,32 @@ rule MALPEDIA_Win_Hunter_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d4323 03c8 8d83b5000000 038d3cffffff 03c8 8d83ae000000 03ce }
- $sequence_1 = { 8b5f08 8b440104 8945f0 8b13 8bc8 e8???????? 85c0 }
- $sequence_2 = { 8d4b38 0faf4dbc 898d34fdffff 8b8d1cffffff 0fafce 8d7375 898d8cfeffff }
- $sequence_3 = { 8bf9 6b1f14 8b743b0c eb38 0fbf0475080f4700 83f8c2 7433 }
- $sequence_4 = { 8b4c2440 6aff e8???????? 59 8b4c2448 33c0 89442424 }
- $sequence_5 = { 53 6a68 5a e8???????? 83c40c b208 8bce }
- $sequence_6 = { 8b4630 8b14b8 85d2 7405 e8???????? b980000000 e8???????? }
- $sequence_7 = { c3 51 56 57 8bf1 33c0 8b7e1c }
- $sequence_8 = { 8b4614 89442418 85c0 750c 385c2431 7506 885c2430 }
- $sequence_9 = { 8d8d04f8ffff e9???????? 8d8d1cf8ffff e9???????? 8d8de0feffff e9???????? 8d8d34f8ffff }
+ $sequence_0 = { 740a 488b1b 4885db 75c2 eb2f 8b8398010000 }
+ $sequence_1 = { f6c201 7403 66ffc3 66ffc0 6683f81a }
+ $sequence_2 = { e8???????? f20f5ef0 f20f1005???????? f20f2cd6 660f6eca 4863c2 488d0c40 }
+ $sequence_3 = { ff15???????? 488d4d68 ba13000000 488905???????? e8???????? }
+ $sequence_4 = { 488d8dc8000000 ba1c000000 488905???????? e8???????? 488bcb 488bd0 ff15???????? }
+ $sequence_5 = { 3c41 7c04 3c5a 7e08 3c30 7c19 3c39 }
+ $sequence_6 = { 6683f81a 72e3 0fb7c3 4883c420 }
+ $sequence_7 = { c745303ae47159 c7453474b06493 c745380897878b c6453c5b e8???????? 488bc8 }
+ $sequence_8 = { c7450f86f5e3e6 c74513a93633c4 c7451793554020 c7451b48549c39 c7451faaa5f9c7 }
+ $sequence_9 = { 488d4dc8 ba0c000000 488905???????? e8???????? 488bcb 488bd0 ff15???????? }
condition:
- 7 of them and filesize <1056768
+ 7 of them and filesize <1606656
}
-rule MALPEDIA_Win_Diztakun_Auto : FILE
+rule MALPEDIA_Win_Racket_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7edd86e4-2270-51c2-83a8-ad0918813862"
+ id = "7cb28a65-c30c-589f-a924-680f6f853124"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.diztakun"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.diztakun_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.racket"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.racket_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "6061dd34695b43b9aac4a4105a7b2b736c3a3c9564c659ddb77165c4b09e4e8b"
+ logic_hash = "d1589a59b0768c1bd03360a8449d283c6a3783d8d4ace18ebd09610946148618"
score = 75
quality = 75
tags = "FILE"
@@ -178801,32 +185795,32 @@ rule MALPEDIA_Win_Diztakun_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 4a 85d2 0f8fb3010000 8b08 8b11 50 }
- $sequence_1 = { 51 ff15???????? 8d742408 e8???????? 5f }
- $sequence_2 = { 8b08 8b11 50 8b4204 ffd0 c68424d807000019 8b442430 }
- $sequence_3 = { 83e01f c1f905 8b0c8d60d74400 c1e006 03c1 f6400401 7524 }
- $sequence_4 = { 8945f4 8b4514 40 c745ec3f344200 894df8 }
- $sequence_5 = { 50 889c24e4070000 e8???????? 83c40c c68424d807000011 }
- $sequence_6 = { 8b4c240c 8b5720 8d442408 50 51 }
- $sequence_7 = { 85d2 740b 8b450c 8b80a4914400 eb09 8b450c 8b8070914400 }
- $sequence_8 = { e8???????? 59 59 85c0 0f84d9000000 68???????? 53 }
- $sequence_9 = { e8???????? 83bfac00000000 755e 8d4c2474 51 8d54241c 52 }
+ $sequence_0 = { ffd3 8b8eec000000 8bf8 8b1d???????? 8d45ec 57 50 }
+ $sequence_1 = { 807d0800 743b e8???????? 6a00 ff7604 6845090000 ff35???????? }
+ $sequence_2 = { 57 0f1f840000000000 8bc1 c745fc02000000 2bc2 8dbb78fdffff 81c680fdffff }
+ $sequence_3 = { 0f44c1 50 ff75f4 8b473c 68a2090000 ff34856cb30610 ff15???????? }
+ $sequence_4 = { 40 50 68???????? 6aff 8d85fcfdffff 6800010000 50 }
+ $sequence_5 = { 0f8433020000 833d????????00 0f8426020000 833d????????00 0f8419020000 833d????????00 0f840c020000 }
+ $sequence_6 = { 83c430 3945cc 8b45b8 7501 40 8b4dc0 }
+ $sequence_7 = { 8b4e04 85c9 7537 8b4510 8b7838 85ff 7e75 }
+ $sequence_8 = { ff740e08 68ac080000 ff35???????? ff15???????? 83c420 2bd8 7418 }
+ $sequence_9 = { 6a00 68d6070000 897ddc ff34856cb30610 8975d0 ff15???????? 83c410 }
condition:
- 7 of them and filesize <688128
+ 7 of them and filesize <985088
}
-rule MALPEDIA_Win_Dnspionage_Auto : FILE
+rule MALPEDIA_Win_Taidoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "80d80ee2-7c3c-5a6f-84fc-982c0a0f58b9"
+ id = "ede5ce97-d13f-50cf-a7ae-7678b51deb4c"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dnspionage"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dnspionage_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.taidoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.taidoor_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "6f236089a9c79217d1f5a567e48544242146a1c819e624fb6aad3710206efaec"
+ logic_hash = "9a08978fbb3ba0f91c4ac24abe796c18c68bd8ea90cbb67ac44eb5676631b436"
score = 75
quality = 75
tags = "FILE"
@@ -178840,34 +185834,34 @@ rule MALPEDIA_Win_Dnspionage_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { f7470c00020000 7507 8bc8 e8???????? 894320 85c0 }
- $sequence_1 = { 50 8d45f4 50 6a13 57 }
- $sequence_2 = { 0f1f8000000000 8bc7 8d5001 8a08 40 84c9 75f9 }
- $sequence_3 = { c7450c00000000 8d4d0c ba???????? 51 8d4df4 51 }
- $sequence_4 = { 83f97f 7307 be7f000000 eb11 8bf7 8d4e01 0f1f00 }
- $sequence_5 = { 33f6 397510 762c 8b45f0 }
- $sequence_6 = { 8b4810 e8???????? a3???????? e9???????? }
- $sequence_7 = { 57 8bfa 85f6 0f8487000000 85ff 0f847f000000 }
- $sequence_8 = { 7202 8b12 56 52 8d8518feffff }
- $sequence_9 = { 8bce 8903 83c408 c1e902 }
+ $sequence_0 = { 7cf5 c745fcfcffffff 33ff 33db }
+ $sequence_1 = { f775fc 8bf2 8d04f6 ffb485f4b7ffff ff15???????? 85c0 }
+ $sequence_2 = { 59 8d85a0fdffff 59 50 e8???????? }
+ $sequence_3 = { 57 a0???????? c745fc01000000 8ac8 f6d9 1bc9 33db }
+ $sequence_4 = { 66ab aa 895dfc ffd6 40 85c0 7e29 }
+ $sequence_5 = { b940420f00 f7f9 8d45e0 52 ff35???????? ff35???????? }
+ $sequence_6 = { ff75f0 ffd6 8d4d08 885dfc e8???????? 834dfcff 8d4d10 }
+ $sequence_7 = { ff75ec 8d4df0 e8???????? 8b450c 46 3b70f8 7cdc }
+ $sequence_8 = { e8???????? ff75ec 8d85a0fdffff 50 51 8bcc 8965f4 }
+ $sequence_9 = { bf80020000 57 c745fc01000000 ffd3 8bf0 }
condition:
- 7 of them and filesize <786432
+ 7 of them and filesize <49152
}
-rule MALPEDIA_Win_Cryptoluck_Auto : FILE
+rule MALPEDIA_Win_Winmm_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a59fe2e6-4321-5ca6-b53f-4f7ee8914f9a"
+ id = "e5922e79-076b-5a5c-ba27-8c0bb532ca1f"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptoluck"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptoluck_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winmm"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.winmm_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "6db6bc0e7d4030ac1b4c7c7367ac728b4b155db8cbff6f59645d89ef531abf3a"
- score = 75
- quality = 75
+ logic_hash = "9d8038e46a83e5b1250014db0840b8d665afb5078d6d9005cce493b4024246af"
+ score = 60
+ quality = 35
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -178879,32 +185873,32 @@ rule MALPEDIA_Win_Cryptoluck_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7409 c745d880720010 eb07 c745d878720010 837d1000 7409 c745d475720010 }
- $sequence_1 = { 44 15f40010ff 35ec001eff 20d7 59 392d???????? 1288ff35d403 }
- $sequence_2 = { 8b85e4fbffff 50 e8???????? 83c408 8985c4fbffff 83bdc4fbffff00 }
- $sequence_3 = { 8b4df8 51 ff15???????? 85c0 7431 8b550c }
- $sequence_4 = { 85c0 0f84e8000000 c745ec00000000 8d45ec 50 8d4df0 51 }
- $sequence_5 = { ff15???????? 85c0 7419 8b4d14 }
- $sequence_6 = { 99 2bc2 8bc8 d1f9 8b45ac 99 2bc2 }
- $sequence_7 = { ff15???????? 8b0d???????? 51 8b95c8fdffff 52 68ff0f0000 }
- $sequence_8 = { c60000 8b4de0 83c101 894de0 8b55dc }
- $sequence_9 = { ff15???????? 8985e8faffff 83bde8faffffff 0f84d9000000 b8424d0000 668985d4faffff 8b8df4faffff }
+ $sequence_0 = { 740c 663d3000 7406 663d2000 750b 668b042e 03f5 }
+ $sequence_1 = { 03ce 7504 33c0 5e }
+ $sequence_2 = { 7d03 6a01 5f 85ff 0f8449ffffff }
+ $sequence_3 = { 89462c ff15???????? 8bce 894604 e8???????? 85c0 }
+ $sequence_4 = { 8bc8 ff5274 c3 33c0 c3 c3 56 }
+ $sequence_5 = { 83c308 bf80000000 eb1d 83e86e }
+ $sequence_6 = { e8???????? 59 eb1d 6a02 83c304 5f }
+ $sequence_7 = { 663d2000 750b 668b042e 03f5 663bc7 75c0 397c2428 }
+ $sequence_8 = { 7c02 8bfd 3b7c2428 7f5a 8b7c2428 }
+ $sequence_9 = { 83c40c 85c0 752d 83c606 }
condition:
- 7 of them and filesize <229376
+ 7 of them and filesize <278528
}
-rule MALPEDIA_Win_Ratankbapos_Auto : FILE
+rule MALPEDIA_Win_Sidewalk_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5159f055-afb3-5653-8c2e-8b4cd00d6051"
+ id = "14b78b08-c08d-56d8-91d9-454c97efb0a9"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ratankbapos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ratankbapos_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sidewalk"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sidewalk_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "307bbc2928c4233a295ed19557340191e5f9ae029ac3d7d89bb25a026e5ae32e"
+ logic_hash = "db7fd110ccdf76bd73169627fa283b7d029f717432de6e469dcea6c6c2ec5ed7"
score = 75
quality = 75
tags = "FILE"
@@ -178918,32 +185912,35 @@ rule MALPEDIA_Win_Ratankbapos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d542444 56 52 e8???????? 8d44244c 83c424 33d2 }
- $sequence_1 = { 83c424 33d2 8d7001 8d4900 8a08 40 3acb }
- $sequence_2 = { 897304 8d7901 90 8a01 41 84c0 }
- $sequence_3 = { 8b4b0c 03f0 c68405fcdfffff00 8d85fcdfffff 89b5f4dfffff c6040e00 }
- $sequence_4 = { e8???????? 8b4510 33c9 8a4801 8d14cdd8ea0010 }
- $sequence_5 = { ffb7c03d0110 ff15???????? 8987c03d0110 83c704 83ff28 72e6 5f }
- $sequence_6 = { ff15???????? 83c41c 8bf0 ff15???????? 50 }
- $sequence_7 = { 8b4dfc 33cd 83c408 b001 }
- $sequence_8 = { b801000000 894588 8945a4 33c9 8bc2 c78574ffffff3c000000 }
- $sequence_9 = { 8bc8 c1f905 8d3c8de04d0110 8bf0 }
+ $sequence_0 = { 4403e8 4133db 418bcd c1c307 }
+ $sequence_1 = { 0bc8 41890c10 488d5204 4983e901 75d4 }
+ $sequence_2 = { 33c3 c1c207 c1c00c 4403c8 4533d1 }
+ $sequence_3 = { 488b05???????? 83780c00 7405 e8???????? }
+ $sequence_4 = { 488d040a 483bc6 7ce2 4883c640 }
+ $sequence_5 = { 8bc2 33c6 c1c010 4403d8 4133db }
+ $sequence_6 = { 750e 488bcf ff15???????? 4885c0 }
+ $sequence_7 = { c1c610 4433f2 c1c710 4403df 41c1c610 4503e6 }
+ $sequence_8 = { 41c1c610 4503e6 4403cb 4533d1 4403ee 41c1c210 418bc3 }
+ $sequence_9 = { 884202 884a03 4183f810 7ccc }
+ $sequence_10 = { 0fb642fe c1e108 0bc8 41890c10 }
+ $sequence_11 = { ff15???????? 4885c0 750e 488bcf }
+ $sequence_12 = { 8a040f 3201 41880408 48ffc1 }
condition:
- 7 of them and filesize <327680
+ 7 of them and filesize <237568
}
-rule MALPEDIA_Win_Hellokitty_Auto : FILE
+rule MALPEDIA_Win_Gpcode_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "deb7a825-f579-50f4-a7a3-d6eebbf360da"
+ id = "d8b81e5a-8691-5b0a-9c29-2fe185a250cc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hellokitty"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hellokitty_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gpcode"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gpcode_auto.yar#L1-L188"
license_url = "N/A"
- logic_hash = "aa8f4a4903065b9814083d80e7b1fe6c3f259f31453cf2a2b84676c3d1765b58"
+ logic_hash = "47d13f6f4636c7a610d9f5f6fa6bfc46db8fee0da3e7f134864d9085143c9558"
score = 75
quality = 75
tags = "FILE"
@@ -178957,32 +185954,41 @@ rule MALPEDIA_Win_Hellokitty_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8975fc 8d4e08 c706???????? e8???????? 6818010000 8d86d0030000 6a00 }
- $sequence_1 = { 23df 234df0 8bc7 c1c802 0bd9 33d0 03de }
- $sequence_2 = { 7509 0fb64702 3a4604 7411 83c32c 41 83c72c }
- $sequence_3 = { 33d2 8b45ec 8bf1 0fa4c11e c1ee02 0bd1 c1e01e }
- $sequence_4 = { 8b048520364200 56 8b7508 57 8b4c0818 8b4514 832600 }
- $sequence_5 = { 33ca 8bd1 894dec 8988a8000000 33d3 }
- $sequence_6 = { 8b759c 03c2 8bd1 8945f8 8bc1 c1c807 c1c20e }
- $sequence_7 = { 8b45c0 3175c4 8bf0 0facc81c c1e604 0bd0 c1e91c }
- $sequence_8 = { 8bf8 83c020 59 f3a5 8b7508 83ee20 89450c }
- $sequence_9 = { c1ce02 8b45d0 03cf 3345ec 3345c4 3345f0 8b7df4 }
+ $sequence_0 = { e8???????? a1???????? a3???????? 6800001000 68???????? ff35???????? }
+ $sequence_1 = { 68???????? e8???????? 91 6a00 }
+ $sequence_2 = { e8???????? e8???????? c705????????01000000 c3 55 8bec }
+ $sequence_3 = { 85c0 7479 33c0 50 50 6a03 50 }
+ $sequence_4 = { ff35???????? 68???????? ff75f8 ff15???????? 8945f4 85c0 7425 }
+ $sequence_5 = { 8906 83c608 e2e6 59 e2dc }
+ $sequence_6 = { 83c40c 8d45fc 50 8d450c ff30 e8???????? }
+ $sequence_7 = { e8???????? 0bc0 7504 33c0 c9 c3 8945f0 }
+ $sequence_8 = { c60000 2d???????? 50 8d85e8feffff 50 68???????? }
+ $sequence_9 = { 68???????? 6a00 e8???????? 6a0a 68???????? 6a00 e8???????? }
+ $sequence_10 = { e8???????? 83f8ff 7505 5a }
+ $sequence_11 = { 001438 eb06 80c107 000c38 }
+ $sequence_12 = { 0005???????? 0fb605???????? 8ad3 8d80b8fee014 }
+ $sequence_13 = { 0016 40 3bc3 72de }
+ $sequence_14 = { 0145f0 8b4df0 3b4d14 0f8263feffff }
+ $sequence_15 = { 000c38 40 3b45f8 72e3 }
+ $sequence_16 = { 0144240c 85f6 7fdd 33c0 }
+ $sequence_17 = { 0106 eb94 55 8bec }
+ $sequence_18 = { 000e eb08 02c9 b2f9 }
condition:
- 7 of them and filesize <319488
+ 7 of them and filesize <761856
}
-rule MALPEDIA_Win_Webbytea_Auto : FILE
+rule MALPEDIA_Win_Moriya_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b6cb62e5-1486-5f7a-9ab4-363544b06e24"
+ id = "b9f54a0c-1b70-575c-9b58-fd559fcd85cb"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webbytea"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webbytea_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moriya"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moriya_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "a39ccb63aa5f0dcb105213662a0cd0fec06d0e89771a8eab5add75ac05faf27d"
+ logic_hash = "ab28f31770f9afce25a3c5b829bb0d33a4cf408b2c3f7c40efc1893d68c2419a"
score = 75
quality = 75
tags = "FILE"
@@ -178996,32 +186002,32 @@ rule MALPEDIA_Win_Webbytea_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e9???????? c744242000000000 4533c9 4533c0 33d2 33c9 }
- $sequence_1 = { c68424f100000072 c68424f200000065 c68424f300000061 c68424f400000074 }
- $sequence_2 = { 8b00 ffc0 488b8c2488020000 8901 488d542430 488b4c2420 }
- $sequence_3 = { 488b8c2488020000 8901 488d542430 488b4c2420 ff15???????? 85c0 }
- $sequence_4 = { 488b842488020000 8b00 ffc0 488b8c2488020000 }
- $sequence_5 = { eb08 8b0424 ffc0 890424 8b442438 390424 }
- $sequence_6 = { 488b842488020000 8b00 ffc0 488b8c2488020000 8901 488d542430 488b4c2420 }
- $sequence_7 = { c7042400000000 eb08 8b0424 ffc0 890424 8b442438 }
- $sequence_8 = { 488b8c2488020000 8901 488d542430 488b4c2420 }
- $sequence_9 = { c68424f100000072 c68424f200000065 c68424f300000061 c68424f400000074 c68424f500000065 }
+ $sequence_0 = { 8bce ff15???????? 4533c0 488d0dcf260000 33d2 }
+ $sequence_1 = { 488bfa 4c8d051c0d0000 33d2 8d5a4d 8bcb ff15???????? 4c8d05280d0000 }
+ $sequence_2 = { 8b4f10 8d81fffeffff 83f801 7608 81f910010000 7564 ba28000000 }
+ $sequence_3 = { 448d724d 418bce 0f114dc0 0f1145d0 ff15???????? }
+ $sequence_4 = { 4885c0 7509 4c8d05b60f0000 eba3 4c8d05dd0f0000 ff15???????? }
+ $sequence_5 = { ff15???????? 488b8c2498000000 4885c9 7405 e8???????? }
+ $sequence_6 = { ff15???????? 8bc3 488b8c2488000000 4833cc e8???????? 4881c490000000 415f }
+ $sequence_7 = { 33d2 ff15???????? 4883673800 488b0d???????? 4885c9 7467 }
+ $sequence_8 = { 4c8bc3 49ffc0 42803c0000 75f6 488b15???????? }
+ $sequence_9 = { 488b0d???????? 4885c9 7405 e8???????? 8bc7 488b4df0 }
condition:
- 7 of them and filesize <552960
+ 7 of them and filesize <58368
}
-rule MALPEDIA_Win_Mailto_Auto : FILE
+rule MALPEDIA_Win_Mylobot_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ea0d0ed3-d3ad-5738-b388-39bdea82080a"
+ id = "7a067cd7-af50-5d95-bc8a-c729265f1a45"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mailto"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mailto_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mylobot"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mylobot_auto.yar#L1-L164"
license_url = "N/A"
- logic_hash = "f253c860f2dfd876ea6c63e66e3d4bfe3e95a5b5178079f30b977b373576f89e"
+ logic_hash = "e9a5b8dbe1c5cc719187453536536d6ca11df9a61a8a5853882ca3075e6106f0"
score = 75
quality = 75
tags = "FILE"
@@ -179035,34 +186041,40 @@ rule MALPEDIA_Win_Mailto_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 47 3bfb 7297 8b44241c 8930 8b442420 85c0 }
- $sequence_1 = { 83c404 85f6 7429 85ed 7419 8b742414 }
- $sequence_2 = { 8b442418 8938 8b44241c 85c0 7402 8930 }
- $sequence_3 = { 55 56 57 8b7c2424 c744241400000000 85ff 7457 }
- $sequence_4 = { 85f6 0f8477010000 e8???????? 3b7014 0f8469010000 8b0d???????? 85c9 }
- $sequence_5 = { 8b08 ff5130 85c0 7822 ff74242c e8???????? }
- $sequence_6 = { 897c242c 8bc8 89442420 c1f81a c1f91f 23c8 8bc1 }
- $sequence_7 = { 40 eb64 83ff01 7522 0fb6d1 bf02000000 83e203 }
- $sequence_8 = { 0fb6466b 884118 0fb6466f 88411c 0fb64652 884101 0fb64656 }
- $sequence_9 = { 0f84ef000000 6a20 e8???????? 83c404 89442410 85c0 }
+ $sequence_0 = { ff5014 56 6a00 50 8947f8 }
+ $sequence_1 = { 89442414 75c7 eb02 33f6 85f6 741c }
+ $sequence_2 = { 0f8344030000 8b0c83 8b442428 3bc8 0f823e020000 03442418 }
+ $sequence_3 = { 83c41c 2b4734 7409 50 53 e8???????? }
+ $sequence_4 = { 898108010000 8d442414 50 68???????? }
+ $sequence_5 = { 51 ff742410 50 8d84248c020000 50 }
+ $sequence_6 = { a1???????? 53 ff507c 8bf8 85ff 0f8491000000 8d442410 }
+ $sequence_7 = { 81eccc000000 8b450c 53 56 57 8b00 }
+ $sequence_8 = { 75cc 80bdfcfdffff01 0f8581000000 68???????? ff15???????? }
+ $sequence_9 = { c785d4fdffff28010000 ff15???????? 8d8dd4fdffff 8bf8 }
+ $sequence_10 = { 2bc2 8bc8 8bc3 8d7801 }
+ $sequence_11 = { 83bd48ffffff00 0f85e9000000 807dda01 0f95c0 }
+ $sequence_12 = { 7857 8b07 85c0 7462 }
+ $sequence_13 = { ffd3 68???????? 8d742414 e8???????? 83c404 85c0 }
+ $sequence_14 = { 897df4 3bc7 743d 8d55f4 }
+ $sequence_15 = { 8bf0 81fed0040000 750e 8b4718 50 57 }
condition:
- 7 of them and filesize <180224
+ 7 of them and filesize <8028160
}
-rule MALPEDIA_Win_Rikamanu_Auto : FILE
+rule MALPEDIA_Win_Roseam_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "08f5de79-f86c-592e-8a15-71782197d327"
+ id = "88276476-b18b-5edc-880f-eae459b2a660"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rikamanu"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rikamanu_auto.yar#L1-L297"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.roseam"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.roseam_auto.yar#L1-L120"
license_url = "N/A"
- logic_hash = "3cf2bc6d93646710c8204bdc714006eac60fd0ca80947c5c7ae6ad8dcd343296"
+ logic_hash = "3438063035004ab07a2e8d6bda2a389a18e5085289cc780bdf790db5294b5e20"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -179074,52 +186086,32 @@ rule MALPEDIA_Win_Rikamanu_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 6a14 ff15???????? a801 }
- $sequence_1 = { 50 ff15???????? 8b35???????? 3d80969800 }
- $sequence_2 = { 8b85e4fdffff 8d8dccfdffff 51 8d9588fdffff 52 8b95f0fdffff 53 }
- $sequence_3 = { 68???????? 51 c744241c6c714000 e8???????? 33d2 6a0c 8954240a }
- $sequence_4 = { 0fb6442404 8a4c240c 848821ae4000 751c 837c240800 740e 0fb70445faa64000 }
- $sequence_5 = { 83c42c 5f eb26 8d4508 8db62c724000 6a00 }
- $sequence_6 = { 8088????????10 8ac8 80c120 888820ad4000 eb1f 83f861 }
- $sequence_7 = { 0fbe05???????? 83e802 7413 83e806 7407 bf???????? eb0c }
- $sequence_8 = { 57 ff15???????? 33c0 40 ebcc }
- $sequence_9 = { eba1 8b85f0fdffff 6a04 8d95ecfdffff }
- $sequence_10 = { 51 68???????? 55 ffd3 bf???????? 83c9ff 33c0 }
- $sequence_11 = { 6a04 55 83e103 6a01 8d44246c }
- $sequence_12 = { 6a00 6a00 55 ffd7 55 }
- $sequence_13 = { 56 ff15???????? 8b842470020000 03f8 57 56 ff15???????? }
- $sequence_14 = { 8987709a2400 83c704 83ff28 72e6 5f }
- $sequence_15 = { 83c40c 33c0 6808020000 8d95f4fdffff 52 }
- $sequence_16 = { 8d34c570902400 833e00 7513 50 }
- $sequence_17 = { 8d4508 8db62c724000 6a00 50 ff36 e8???????? 59 }
- $sequence_18 = { 891d???????? 891d???????? ff15???????? 8d85f8feffff }
- $sequence_19 = { 7373 8bc8 8bf0 c1f905 83e61f 8d3c8de0b84000 c1e603 }
- $sequence_20 = { 391d???????? 0f849e000000 33c0 663bcb 0f95c0 }
- $sequence_21 = { 8bec 8b450c 56 beff000000 3bc6 7518 }
- $sequence_22 = { 8945e4 3d00010000 7d10 8a8c181d010000 888808972400 40 ebe6 }
- $sequence_23 = { 85c0 74c9 33c9 33c0 890d???????? bf???????? 890d???????? }
- $sequence_24 = { ebe3 80a0a0a6400000 40 41 41 3bc6 }
- $sequence_25 = { ff15???????? ff750c e8???????? 59 3bc3 }
- $sequence_26 = { 40 3acb 75f9 2bc2 8d95f8feffff }
- $sequence_27 = { 8b54240c 81fa80000000 7c0e 0fba25????????01 0f820b070000 57 }
- $sequence_28 = { 7457 68???????? 56 ffd5 85c0 744b 8a0e }
- $sequence_29 = { c1e106 8b0485383f4100 f644080401 7405 8b0408 5d }
+ $sequence_0 = { 895514 eb38 895514 68???????? 68???????? 50 }
+ $sequence_1 = { 8b8c2490000000 89442408 8d44240c 6a0a }
+ $sequence_2 = { 8b12 66c745ec0200 8955f0 c745fc20000000 68???????? 50 9c }
+ $sequence_3 = { f2ae f7d1 49 894dec 8d0489 99 }
+ $sequence_4 = { 81fbff000000 895de8 0f84e2010000 8b4df8 83f903 }
+ $sequence_5 = { 57 b914000000 be???????? 8d7d90 f3a5 33d2 a4 }
+ $sequence_6 = { 58 68???????? ffd6 b91f000000 33c0 }
+ $sequence_7 = { 5d 58 8d8d58ffffff 8d95f4fcffff 51 }
+ $sequence_8 = { 83c40c f3ab 66ab aa e8???????? 8985f4fcffff }
+ $sequence_9 = { 894df0 eb0d 33c9 894dec 894df0 }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <221184
}
-rule MALPEDIA_Win_Backbend_Auto : FILE
+rule MALPEDIA_Win_Voidoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0c0e6fe8-d4e7-5b73-ab9b-71a979b7c8b3"
+ id = "71f97a7b-09b8-5977-a64d-26462fe6285b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.backbend"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.backbend_auto.yar#L1-L123"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.voidoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.voidoor_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "b7d55ae6e8faf28a826a20f0c2aeb325ce5a40ba350e055022c2b2475be4953d"
+ logic_hash = "c8a62c7797e4a86d80b8a858487a45d1e5042e60b70ed193ca612e4172a00dd8"
score = 75
quality = 75
tags = "FILE"
@@ -179133,32 +186125,32 @@ rule MALPEDIA_Win_Backbend_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { ff15???????? 80a40500ffffff00 8d8500ffffff 56 50 ff15???????? }
- $sequence_1 = { 58 5f 5e c3 ff25???????? ff25???????? }
- $sequence_2 = { ffd6 ff7510 ffd3 8d8500feffff }
- $sequence_3 = { ff15???????? 85c0 7416 8d8500fbffff }
- $sequence_4 = { 56 e8???????? 8d8500fdffff 56 50 e8???????? 68???????? }
- $sequence_5 = { 90 90 90 bf???????? 57 e8???????? c70424???????? }
- $sequence_6 = { 8d8500f9ffff 50 e8???????? 8d8500f9ffff 50 e8???????? 83c424 }
- $sequence_7 = { ffd3 8d8500feffff 6800010000 50 ff15???????? 8d8500feffff 68???????? }
- $sequence_8 = { 56 ffd3 6a00 8d8500ffffff 56 50 ff15???????? }
- $sequence_9 = { 7416 8d8500fbffff 6a00 50 }
+ $sequence_0 = { e8???????? 83c410 83bfb40b000000 752e ff33 83bf500b000000 ffb608400000 }
+ $sequence_1 = { c645fc10 e8???????? c78574feffff0f000000 c78570feffff00000000 c68560feffff00 8d9560feffff 8d8d78feffff }
+ $sequence_2 = { 03f5 7458 803e2f 7509 83f804 7d04 40 }
+ $sequence_3 = { 55 8bd8 ff15???????? 83c414 85db 0f85c3010000 8b542440 }
+ $sequence_4 = { 8b742414 c744240800000000 83bec802000000 8b1e 57 8b834c010000 8dbe68050000 }
+ $sequence_5 = { c60201 8b10 2bca 83f906 7d0a b801000000 5e }
+ $sequence_6 = { 33c0 5f 59 c3 56 57 e8???????? }
+ $sequence_7 = { b91b000000 5e 0f44d9 5d 8bc3 5b 83c408 }
+ $sequence_8 = { e8???????? 83c40c 89442418 8983ac030000 68???????? 53 e8???????? }
+ $sequence_9 = { c6434501 3944241c 7520 85f6 0f8565ffffff 837c243020 7337 }
condition:
- 7 of them and filesize <49152
+ 7 of them and filesize <1744896
}
-rule MALPEDIA_Win_Defray_Auto : FILE
+rule MALPEDIA_Win_Unidentified_104_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ee2cc914-ed1c-504f-bf38-50caf0bf4350"
+ id = "e8a556d0-f78d-5a2d-8efe-d7e4f2e8c4f0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.defray"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.defray_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_104"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_104_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "6779b35681313abc4956d5610d5c5eb736ab6b4450531cda5b5e81d10fef89b6"
+ logic_hash = "e638b20b38ac304bb33832304ee0b9b7e6ee0e08465f3d2f98dbc6a372f89d7d"
score = 75
quality = 75
tags = "FILE"
@@ -179172,32 +186164,32 @@ rule MALPEDIA_Win_Defray_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3bc1 75c3 894db4 8d8d60ffffff e8???????? 84c0 7419 }
- $sequence_1 = { 8b0b 8bc1 83e13f c1f806 6bc930 8b048568f34800 }
- $sequence_2 = { 33c0 8dbd94f5ffff a5 a5 a5 8dbda0f5ffff be???????? }
- $sequence_3 = { 2bf2 8d7b1f c1ef05 c1fe02 897d08 3bfe 7322 }
- $sequence_4 = { 83c9f8 41 0f2825???????? 8bd6 0f282d???????? 2bd1 0f57db }
- $sequence_5 = { 33c6 03d0 8b85e0feffff 03940514ffffff 039008d54700 03d7 8bbde4feffff }
- $sequence_6 = { 56 6a02 51 8975fc 8975f8 ff15???????? }
- $sequence_7 = { 663907 7407 83c702 3bfe 75f4 3bfe 0f8434feffff }
- $sequence_8 = { 8bf0 85f6 0f8528050000 8b45d8 c745f4006d4100 8945f8 837d1000 }
- $sequence_9 = { 6a0c 99 5f f7ff 8365e000 8b7508 85c0 }
+ $sequence_0 = { 4c8d0d20070100 33c9 4c8d050f070100 488d1510070100 e8???????? 4885c0 }
+ $sequence_1 = { 4c03e9 4d33cd 498bd9 49c1e918 48c1e328 4933d9 4803c3 }
+ $sequence_2 = { 410fb6401b 4c0bc8 410fb6401a 49c1e108 4c0bc8 49c1e104 4c03c9 }
+ $sequence_3 = { 48c1e128 4933c9 4c8b8c2490000000 498b8180000000 4803c1 4803e8 4c33c5 }
+ $sequence_4 = { 4883fa10 0f8288000000 48ffc2 488b4dc7 488bc1 483bd7 728f }
+ $sequence_5 = { 415d 415c 5f 5e 5d c3 488d5ed8 }
+ $sequence_6 = { 418848fe c1e810 c1e918 418800 41884801 4d8d4004 4983e901 }
+ $sequence_7 = { e8???????? 33c0 4883c420 5b c3 8bd3 488bc8 }
+ $sequence_8 = { 49c1e330 4c33da 4903f3 4889b424a0000000 4833ce 488b742418 488bd1 }
+ $sequence_9 = { 7230 48ffc2 488b8dc0000000 488bc1 4881fa00100000 7215 }
condition:
- 7 of them and filesize <1253376
+ 7 of them and filesize <263168
}
-rule MALPEDIA_Win_Mozart_Auto : FILE
+rule MALPEDIA_Win_Turnedup_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1438b6f5-0fc9-5eca-9ae3-36eb59239394"
+ id = "317b79ff-9d3d-5ba0-8921-2dd0758e0502"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mozart"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mozart_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.turnedup"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.turnedup_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "94b0456ee335dcdb1592bd3a0f2b861e74a91bd5433e8fc753965fb9891ac5e3"
+ logic_hash = "41dd089d435e4495b4c527e58471affc57ceb5820e7069ad3a735daa64e32911"
score = 75
quality = 75
tags = "FILE"
@@ -179211,32 +186203,32 @@ rule MALPEDIA_Win_Mozart_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7c26 80fb39 7f21 885c3418 46 }
- $sequence_1 = { 66ab e8???????? 8d44242c 50 e8???????? 8d8c2430010000 51 }
- $sequence_2 = { c1f805 8d1c85c0db4000 8b03 8bf1 83e61f c1e603 8a443004 }
- $sequence_3 = { 49 7438 49 7471 c1e006 0bc7 }
- $sequence_4 = { 55 8bec 83e4f8 81ec20020000 a1???????? 8b0d???????? 668b15???????? }
- $sequence_5 = { 8bf0 83e61f 8d3c8dc0db4000 8b0f c1e603 f644310401 7455 }
- $sequence_6 = { 8a08 40 84c9 75f9 8b8c2420100000 }
- $sequence_7 = { 2bc7 3bf0 7202 33f6 8bc5 43 42 }
- $sequence_8 = { 8b0a 83c502 3be9 7728 }
- $sequence_9 = { 751a 84c0 7426 8b5608 47 }
+ $sequence_0 = { 8b4dfc 5f 5e 33cd 895004 5b }
+ $sequence_1 = { 7706 891d???????? ff0d???????? 7506 891d???????? 6a01 }
+ $sequence_2 = { 8b07 8b4004 03c7 33d2 8955dc c645e001 8b4838 }
+ $sequence_3 = { 895dfc 752b 6a00 8d4df8 e8???????? 833d????????00 }
+ $sequence_4 = { 68???????? 8819 e8???????? 8d7dac }
+ $sequence_5 = { c746180f000000 894614 56 884604 e8???????? 83c404 }
+ $sequence_6 = { 830801 8b4dd8 394dc0 741e 837dd000 }
+ $sequence_7 = { 8945bc 8975b0 8b55f4 8b45e0 83fa10 7303 8d45e0 }
+ $sequence_8 = { 8ad5 c0ea04 80e203 02d0 8a45f6 8855f8 8ad0 }
+ $sequence_9 = { 8b45bc 8a11 8810 8b0b 40 }
condition:
- 7 of them and filesize <114688
+ 7 of them and filesize <892928
}
-rule MALPEDIA_Win_Dyepack_Auto : FILE
+rule MALPEDIA_Win_Oddjob_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "66b3574f-c7a6-53f0-85d5-ab2a32e5f41d"
+ id = "05ff5b48-0b07-5c37-b3fa-78979fc46d1b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dyepack"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dyepack_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.oddjob"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.oddjob_auto.yar#L1-L124"
license_url = "N/A"
- logic_hash = "9d7b8dddf2871fef90109ccabdb579a142d1f80f2c5a6a3cb7a4f53499a52084"
+ logic_hash = "cba635f9b22031c02deb6504fbb70476906689529cb50c775ead5481738df2df"
score = 75
quality = 75
tags = "FILE"
@@ -179250,32 +186242,32 @@ rule MALPEDIA_Win_Dyepack_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 53 53 56 ffd7 8b442414 8b4c2410 33ed }
- $sequence_1 = { 7cb2 7f08 8b4c2410 3be9 }
- $sequence_2 = { 8b442414 8b4c2410 33ed 33ff 3bc3 7c60 7f0a }
- $sequence_3 = { 741e 8b442418 3bc3 7416 03e8 8b442414 13fb }
- $sequence_4 = { 1bc7 7815 7f08 81f900100000 }
- $sequence_5 = { 56 ff15???????? 8b8c2428100000 53 51 }
- $sequence_6 = { 3bcb 765a eb04 8b4c2410 2bcd }
- $sequence_7 = { ff15???????? 85c0 741e 8b442418 3bc3 7416 03e8 }
- $sequence_8 = { 5f 5e 5b 81c414100000 c3 8b3d???????? }
- $sequence_9 = { ffd7 8d4c2418 53 51 8d54242c }
+ $sequence_0 = { e8???????? 59 8d9530ffffff 6a01 8bcb 8bc2 }
+ $sequence_1 = { c68552fbffff43 c68553fbffff5e c68554fbffff5b c68555fbffff8b c68556fbffff4b }
+ $sequence_2 = { 663d3600 751f 66837f0234 7518 }
+ $sequence_3 = { 50 bf???????? 57 6a04 53 68???????? ffd6 }
+ $sequence_4 = { 8bc3 4b 85c0 0f8498000000 0fb7c1 83f841 7c05 }
+ $sequence_5 = { c68596faffff24 c68597faffff08 c68598faffff8b c68599faffff43 }
+ $sequence_6 = { c685f8f9ffff40 c685f9f9ffff68 889dfaf9ffff c685fbf9ffff10 889dfcf9ffff 889dfdf9ffff c685fef9ffff51 }
+ $sequence_7 = { 889d12f8ffff 889d13f8ffff 889d14f8ffff 889d15f8ffff 889d16f8ffff 889d17f8ffff 889d18f8ffff }
+ $sequence_8 = { 85c0 7503 897dfc 397de8 7409 ff75e8 ff15???????? }
+ $sequence_9 = { 53 68???????? ffd6 85c0 741c 8d85a094ffff }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <221184
}
-rule MALPEDIA_Win_Kikothac_Auto : FILE
+rule MALPEDIA_Win_Ismdoor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "48840edd-1eda-587e-96d1-699222be4802"
+ id = "e9177277-98bb-546b-913b-803dfeefda39"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kikothac"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kikothac_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ismdoor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ismdoor_auto.yar#L1-L156"
license_url = "N/A"
- logic_hash = "ddecb618114edd432a6ac40a5ecfd59b3208358e4b28a6940c432c46b4921216"
+ logic_hash = "489ff4b41f2f5bc83c56e62265d852f18476e83488ad914ef361d6d410139690"
score = 75
quality = 75
tags = "FILE"
@@ -179289,32 +186281,37 @@ rule MALPEDIA_Win_Kikothac_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7516 8b86942f4100 b301 85c0 740a }
- $sequence_1 = { 50 ff15???????? a3???????? 3bc3 7507 32c0 5b }
- $sequence_2 = { 56 33f6 57 8975fc ffd3 85c0 }
- $sequence_3 = { c60424cd 8d642438 e9???????? c64424046e 895500 9c 6689742408 }
- $sequence_4 = { c1c80a e9???????? 66894500 9c }
- $sequence_5 = { 8b441604 51 50 ff15???????? 85c0 7516 }
- $sequence_6 = { 51 68102ba40e ff3424 9c 8f442438 }
- $sequence_7 = { 6820040000 57 57 57 }
- $sequence_8 = { 60 f6c356 c6442404ab 20d0 }
- $sequence_9 = { e9???????? 8b7c242c 66c70424dc83 98 9f 8b442430 660fbeeb }
+ $sequence_0 = { 83f8ff 7504 32c0 eb05 c0e804 2401 84c0 }
+ $sequence_1 = { 90 48897c2428 488d4da0 48894c2420 4c8d4d80 4c8bc3 }
+ $sequence_2 = { 7405 488b00 ebdd 48894500 }
+ $sequence_3 = { 89442420 48c7411807000000 48894110 668901 c744242001000000 }
+ $sequence_4 = { 7613 498d4970 418bc2 41ffc2 }
+ $sequence_5 = { 41ffc7 0f1f4000 418b16 488d4d38 e8???????? }
+ $sequence_6 = { 8bd8 33c9 ff15???????? 488bc8 }
+ $sequence_7 = { 488bd6 488bcf ff5030 488bc8 }
+ $sequence_8 = { 884c0dd8 41 83f910 7cf6 }
+ $sequence_9 = { 83f802 7506 c6473c00 eb04 40 }
+ $sequence_10 = { 8b4804 83b9ec97480000 0f94c0 8845e4 c745fc01000000 }
+ $sequence_11 = { c745f804000000 57 8a68fe 8d4004 8a48fb 8a78fc }
+ $sequence_12 = { 886dff 81e61f000080 7905 4e 83cee0 46 }
+ $sequence_13 = { e8???????? 83c404 c744246c0f000000 c744246800000000 c644245800 837c243c08 }
+ $sequence_14 = { 75f2 8b7d10 8b07 3bf0 7421 8b4f04 }
condition:
- 7 of them and filesize <581632
+ 7 of them and filesize <1933312
}
-rule MALPEDIA_Win_Phandoor_Auto : FILE
+rule MALPEDIA_Win_Pocodown_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1f3ac76b-bd09-5712-8c06-9b7787ce6d6a"
+ id = "57027d9b-6e81-5ca8-a0ac-bbfd288eda02"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phandoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.phandoor_auto.yar#L1-L152"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pocodown"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pocodown_auto.yar#L1-L101"
license_url = "N/A"
- logic_hash = "bcca1bd5fcc5f942c80e8300ebd91840d93d57fc52bf130291de8a118788c527"
+ logic_hash = "d2d2c3510515a24653939603c26fb696816a72e2a82e1c859f658b0238b45291"
score = 75
quality = 75
tags = "FILE"
@@ -179328,37 +186325,30 @@ rule MALPEDIA_Win_Phandoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0f8482000000 833d????????00 7479 833d????????00 7470 833d????????00 }
- $sequence_1 = { 833d????????00 0f8452010000 833d????????00 0f8445010000 833d????????00 }
- $sequence_2 = { 83c40c 83c302 3bbe90010000 72d7 }
- $sequence_3 = { 83c404 8d55fc 8bf0 52 56 }
- $sequence_4 = { 0f84c7010000 833d????????00 0f84ba010000 833d????????00 0f84ad010000 833d????????00 }
- $sequence_5 = { 50 8bf9 c645f400 c745f500000000 e8???????? }
- $sequence_6 = { 32d3 32d0 8b45f4 81e1fe010000 c1e018 0b45f8 }
- $sequence_7 = { a3???????? a3???????? a3???????? a3???????? 898de8feffff }
- $sequence_8 = { 83c404 893e 8b4604 3bc7 740c }
- $sequence_9 = { 6a01 51 52 8b5508 }
- $sequence_10 = { 668901 5e c3 33d2 }
- $sequence_11 = { 33c0 3b35???????? 7327 57 }
- $sequence_12 = { 56 8b35???????? 57 68???????? 50 c705????????03000000 }
- $sequence_13 = { 6a01 53 51 8bc8 }
- $sequence_14 = { 56 8b7308 85f6 7420 }
+ $sequence_0 = { 8b84248c000000 ffc8 898424a0010000 c784248800000000000000 ba01000000 488b8c24e0010000 }
+ $sequence_1 = { 8b84248c000000 ffc8 8984248c000000 83bc248c00000007 0f875d010000 486384248c000000 }
+ $sequence_2 = { 8b842490000000 25ff000000 488b4c2430 884101 }
+ $sequence_3 = { 8b84248c020000 8944244c 488b8c2420030000 e8???????? }
+ $sequence_4 = { 8b842490000000 2500040000 85c0 740a c744245000000000 eb0a 8b442448 }
+ $sequence_5 = { 8b84248c020000 448bc0 ba5c000000 488d8c24f0010000 e8???????? }
+ $sequence_6 = { 8b84248c020000 448bc0 488d9424f0010000 488d8c24a0020000 e8???????? }
+ $sequence_7 = { 8b842490000000 39442420 0f83e0000000 488d442438 41b808000000 488b542440 }
condition:
- 7 of them and filesize <2124800
+ 7 of them and filesize <6703104
}
-rule MALPEDIA_Win_Rising_Sun_Auto : FILE
+rule MALPEDIA_Win_Webmonitor_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "61449700-41c3-5e72-bc5d-1e423597afa4"
+ id = "aca2309c-f3e7-5982-bcd7-9e22f09c3e41"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rising_sun"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rising_sun_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webmonitor"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webmonitor_auto.yar#L1-L158"
license_url = "N/A"
- logic_hash = "76c0e1eaf3dacaaaa1a31e893606959ffd6d8a46f21e1d7c2864ee68d388c2cb"
+ logic_hash = "7913959618328b6198214b581f33ca34a8ffc8b00c2415ca23bf0e5f2e066370"
score = 75
quality = 75
tags = "FILE"
@@ -179372,32 +186362,38 @@ rule MALPEDIA_Win_Rising_Sun_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c745b03414d384 c745b418f4ff64 c745b851d4c644 c745bcabb43c24 c745c099945804 c745c4c4746ce4 c745c8dd544ec4 }
- $sequence_1 = { 4889742418 48897c2420 55 488dac24a0e4ffff b8601c0000 }
- $sequence_2 = { c745dcd3515290 c745e00358c000 c745e4c80ae51e c745e804d34ed7 c745ec3e3054ad c745f046c2e664 c745f418a189fe }
- $sequence_3 = { c785100200000358c000 c78514020000c80ae51e c7851802000004d34ed7 c7851c0200003e3054ad c7852002000046c2e664 }
- $sequence_4 = { e8???????? 48898588000000 488d05c298feff 4883c420 }
- $sequence_5 = { c78514020000c80ae51e c7851802000004d34ed7 c7851c0200003e3054ad c7852002000046c2e664 c7852402000018a189fe c7852802000003f29cea c7852c0200000bbce179 }
- $sequence_6 = { c785440600001def57f7 c785480600003bf5679d c7854c0600000989ec8d c78550060000fd9e1cf3 66c785540600002657 664489ad60060000 e8???????? }
- $sequence_7 = { 4c8d41ff 488bce e8???????? 488b542450 b89fffffff }
- $sequence_8 = { 660f1f440000 0fb602 48ffc2 88440aff 84c0 75f2 }
- $sequence_9 = { e8???????? cc 48895c2408 48896c2418 56 57 4154 }
+ $sequence_0 = { 06 000b 3a58ff 1b03 fd 006cff1e e00e }
+ $sequence_1 = { 41 0080cd41009c d34100 e8???????? }
+ $sequence_2 = { 0094be4100d891 41 0084e84100a872 42 00a06a4200f8 }
+ $sequence_3 = { 0028 fa 41 0014b4 42 }
+ $sequence_4 = { b9???????? ffe1 ba???????? b9???????? ffe1 ba???????? b9???????? }
+ $sequence_5 = { 000e 6c 74ff f5 }
+ $sequence_6 = { ff05???????? 000d???????? 04b8 fe04e4 fd 04e0 fd }
+ $sequence_7 = { 00dc 7442 000477 42 0028 }
+ $sequence_8 = { 00e8 dd7000 008bf98b5d1c 8d4de4 }
+ $sequence_9 = { 00d1 6848007269 48 00856948008b }
+ $sequence_10 = { 0108 eb5a 8b4508 83ceff }
+ $sequence_11 = { 0108 8b442410 891e 894604 }
+ $sequence_12 = { 00d1 6848004069 48 00d1 }
+ $sequence_13 = { 000f b681 fc b84500ff24 }
+ $sequence_14 = { 00e8 f61c00 008bd9895df0 8b451c }
+ $sequence_15 = { 00856948008b ff558b ec 83ec0c }
condition:
- 7 of them and filesize <409600
+ 7 of them and filesize <1867776
}
-rule MALPEDIA_Win_Carrotbat_Auto : FILE
+rule MALPEDIA_Win_Vyveva_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b4eb53a6-f964-58c0-a140-244bef4847cc"
+ id = "5f920383-d05c-5c69-8d2c-6a773f2538b6"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.carrotbat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.carrotbat_auto.yar#L1-L121"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vyveva"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vyveva_auto.yar#L1-L130"
license_url = "N/A"
- logic_hash = "c457876e0174827e0c750e3be442dfc99dddf6a42b624668fe26e525a3bccc83"
+ logic_hash = "9d5c74e05efbe3ba7525bfb04e432ddba69e01227882b7ebe7ef3564991f92e2"
score = 75
quality = 75
tags = "FILE"
@@ -179411,32 +186407,32 @@ rule MALPEDIA_Win_Carrotbat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b7c2404 66c1c60c 8b742408 f6d7 33cd f7d3 }
- $sequence_1 = { 8f442434 51 887c2404 66890424 890424 }
- $sequence_2 = { 8b0c8d20ee4000 8d440104 8020fe ff36 e8???????? 59 }
- $sequence_3 = { c3 8bff 56 57 33f6 bf???????? 833cf5a4d5400001 }
- $sequence_4 = { 8b0c8d20ee4000 c1e006 8d440104 8020fe ff36 }
- $sequence_5 = { c1f805 8d3c8520ee4000 8bf3 83e61f c1e606 8b07 0fbe440604 }
- $sequence_6 = { 888c05f4fdffff 40 84c9 75ed 8d85f8feffff 6a5c }
- $sequence_7 = { 50 66a5 ff15???????? 6810270000 ff15???????? }
- $sequence_8 = { 5b c21000 ff25???????? c705????????6ca14000 }
- $sequence_9 = { 8f442434 9c 57 ff74243c c24000 686d3f4f6e }
+ $sequence_0 = { 58 ff7008 5a 8916 3b4808 7405 }
+ $sequence_1 = { 51 8f00 8b4c2408 85c9 7407 51 8f4004 }
+ $sequence_2 = { 57 56 51 55 59 e8???????? ff30 }
+ $sequence_3 = { 56 59 50 e8???????? 8d8c2494010000 6a04 }
+ $sequence_4 = { 740a 394424fc 7404 894424fc 83ec04 5d 83fdff }
+ $sequence_5 = { 83ec38 8b15???????? 8d442404 55 56 }
+ $sequence_6 = { 2bce 59 7409 33c9 8d4c0e04 83e904 ff5004 }
+ $sequence_7 = { 6a00 52 50 6a06 e8???????? 83c404 ffd0 }
+ $sequence_8 = { 59 c644247801 e8???????? 8b4c2434 8b442430 8d542428 894c242c }
+ $sequence_9 = { 7408 c70100000000 0101 83c008 85c0 7403 55 }
condition:
7 of them and filesize <360448
}
-rule MALPEDIA_Win_Sykipot_Auto : FILE
+rule MALPEDIA_Win_Cueisfry_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6685d9d7-6a5e-5dd1-be8d-f9a06a5df784"
+ id = "7fd15319-e895-59d1-bc47-6c7854fd0773"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sykipot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sykipot_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cueisfry"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cueisfry_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "fc1ea45bf7dc961b3986859ea4bfe6fc9a7dfe7e53218e4f87e591fa79b5c1da"
+ logic_hash = "312c24021c3e8bf9c6e0d5e58840583a4541e92e9f141ae7391f901c409f9736"
score = 75
quality = 75
tags = "FILE"
@@ -179450,32 +186446,32 @@ rule MALPEDIA_Win_Sykipot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8c2488000000 51 ffd5 68???????? 68???????? ffd3 83c408 }
- $sequence_1 = { 56 c744246004000000 ffd7 8b4c244c 6a04 }
- $sequence_2 = { 50 51 8bcd e8???????? 8b13 8d442414 52 }
- $sequence_3 = { 50 8db42498000000 83ec44 8bfc }
- $sequence_4 = { 5d b80e000000 5b 81c45c180000 c3 56 8b35???????? }
- $sequence_5 = { 8bcc 8911 8b94244c060000 894104 895108 8bcd }
- $sequence_6 = { 55 56 ff15???????? 85c0 57 7513 ff15???????? }
- $sequence_7 = { bf???????? a3???????? f3ab b941000000 bf???????? f3ab b941000000 }
- $sequence_8 = { 83ec44 b911000000 8db424e8000000 8bfc f3a5 8bcd e8???????? }
- $sequence_9 = { c24800 8b442404 56 57 }
+ $sequence_0 = { ff15???????? b8???????? c3 8b45ec c745fcffffffff 85c0 7406 }
+ $sequence_1 = { f3a5 52 e8???????? 8d44241c }
+ $sequence_2 = { e8???????? 85c0 750c 55 ff15???????? e9???????? }
+ $sequence_3 = { 8944241c 7c0d 80f95a 7f08 0fbee9 }
+ $sequence_4 = { 8975dc e8???????? 8b45ec 3bc7 750d }
+ $sequence_5 = { 8d4c2408 50 e8???????? b91f000000 33c0 8d7c2431 c644243000 }
+ $sequence_6 = { ff15???????? 8bb424a8010000 8d4c240c 51 8bce }
+ $sequence_7 = { 5f 5e 5d 32c0 5b 81c424030000 c3 }
+ $sequence_8 = { 8d4c240c c68424a001000001 e8???????? 8d8c24ac010000 889c24a0010000 e8???????? }
+ $sequence_9 = { 6a00 ff15???????? 68d0070000 ff15???????? 8d94249c000000 6a00 }
condition:
- 7 of them and filesize <286720
+ 7 of them and filesize <81920
}
-rule MALPEDIA_Win_Danbot_Auto : FILE
+rule MALPEDIA_Win_Komprogo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2c585571-1377-525b-81df-f475b9f7d032"
+ id = "c2da7eb7-9058-5d5c-a1b3-cf7ec20183b8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.danbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.danbot_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.komprogo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.komprogo_auto.yar#L1-L125"
license_url = "N/A"
- logic_hash = "7b636202f57d607cd3195402deda2493294df662e32f18cd69328119b0c63f1c"
+ logic_hash = "9104f7103ef4ffc58ac248efbbf51156333295a0a474355899a4b0ca03e1b39e"
score = 75
quality = 75
tags = "FILE"
@@ -179489,32 +186485,32 @@ rule MALPEDIA_Win_Danbot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 66893c48 448b4374 488b4b68 41ffc8 4d03c0 e8???????? 48638bac000000 }
- $sequence_1 = { 8a4004 88040a 44016b28 8b5328 488b4330 488b4b10 8a4005 }
- $sequence_2 = { 483bd7 7213 48ffc2 4c8bc3 488b8c2480030000 e8???????? 4c89b42490030000 }
- $sequence_3 = { e9???????? 488b8a80000000 e9???????? 488b8a78000000 e9???????? 488b8a28000000 e9???????? }
- $sequence_4 = { 4154 4155 4157 4881ec10060000 48c780a8fafffffeffffff 48895808 48897010 }
- $sequence_5 = { 488b9424f0000000 4883fa10 7214 48ffc2 4d8bc4 488b8c24d8000000 e8???????? }
- $sequence_6 = { 48ffc2 4d8bc6 488b8c2428010000 e8???????? 48899c2438010000 4889bc2440010000 889c2428010000 }
- $sequence_7 = { 488b55df 4883fa08 7212 48ffc2 41b802000000 488b4dc7 e8???????? }
- $sequence_8 = { 0fb6442420 84db 410f44c4 8ad8 895c2420 eb25 4c8b742460 }
- $sequence_9 = { ffd3 99 33c2 2bc2 89442430 448be0 4c89642450 }
+ $sequence_0 = { 8d8670720300 89861b630000 8d96f0a80300 8996e51d0300 8d8e40490400 }
+ $sequence_1 = { 8d86a82f0400 89862cb50200 8d86a8700300 89862cd50000 8d86f0380400 898616410200 8d8680720300 }
+ $sequence_2 = { 51 8d8618cf0300 8bcf e8???????? 83c404 }
+ $sequence_3 = { 8d96e4970300 899625080100 898633080100 8d96d0700300 8996e5650200 8d96f4380400 899643080100 }
+ $sequence_4 = { 8d9614790300 899694e70300 8d86242c0400 8986c1210300 8d86e15c0300 898636ca0000 8d86a8ad0300 }
+ $sequence_5 = { 0f859e000000 85f6 0f8496000000 8b433c 0fb7541814 }
+ $sequence_6 = { 898e47bd0200 8d8e20e20300 898e4f7e0200 8d9694a30300 899674750300 8d8ea82f0400 898e897e0200 }
+ $sequence_7 = { ff15???????? 8b95f0fdffff 8902 33db 85f6 7445 8bb5f0fdffff }
+ $sequence_8 = { 52 ffd7 8b85d0f3ffff 50 ffd7 8b4df8 5f }
+ $sequence_9 = { 8d86e0930200 8986d4930200 8d8ec1610300 898e14b20300 }
condition:
- 7 of them and filesize <1492992
+ 7 of them and filesize <1045504
}
-rule MALPEDIA_Win_Unidentified_080_Auto : FILE
+rule MALPEDIA_Win_Newpass_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b4f490ab-c91a-5e77-9e61-88b48864f732"
+ id = "dfd78470-0c07-5107-9bdf-99560c1551b3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_080"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_080_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.newpass"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.newpass_auto.yar#L1-L131"
license_url = "N/A"
- logic_hash = "a554ba61b72496370ffd16dee0c3f2b6444ec6fc0c35b79b5428032562bbd4cc"
+ logic_hash = "18487b3a938727b19644b6d1320bc7ccc85217d142f24fc2488ac5f5fe73de66"
score = 75
quality = 75
tags = "FILE"
@@ -179528,32 +186524,32 @@ rule MALPEDIA_Win_Unidentified_080_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 51 53 8bd8 837b2c00 56 7571 8b4324 }
- $sequence_1 = { 0bf2 89701c 83c020 83c120 ff8d74ffffff 0f8560feffff 8b8570ffffff }
- $sequence_2 = { 8b4508 8b4808 8b500c 2bd1 894dfc 3bd3 7277 }
- $sequence_3 = { 3bd6 7312 8b03 833c9000 8d0490 7402 }
- $sequence_4 = { 8dbd40ffffff e8???????? 8bb53cffffff 83c620 c645fc0f 8b06 33ff }
- $sequence_5 = { 83e73f 0b0cbdb8840210 83e03f 0b0c85b8860210 8b42f4 33c6 8bf8 }
- $sequence_6 = { 8bec 83ec10 53 8bd8 ff4320 56 33f6 }
- $sequence_7 = { 8bf0 83feff 7509 c68568ffffff0b eb66 8b4dbc }
- $sequence_8 = { 57 50 8d45f4 64a300000000 33ff 33f6 }
- $sequence_9 = { 8b4e30 8d5508 52 8b562c 50 51 52 }
+ $sequence_0 = { 4d8bc4 eb0f 4983c8ff 49ffc0 6642833c4700 75f5 488bd7 }
+ $sequence_1 = { 488d542470 48837d8810 480f43542470 488b5910 4883791810 7203 }
+ $sequence_2 = { 85c0 792e 488b842490000000 4889442428 4c8bce 440fb6c7 488d542470 }
+ $sequence_3 = { eb09 418bc7 493bf6 0f95c0 85c0 7906 488b7f10 }
+ $sequence_4 = { 7503 488b07 483bc8 741b 448bc2 488bd0 e8???????? }
+ $sequence_5 = { c7411006160000 8b4110 0f49c2 488939 894110 b001 }
+ $sequence_6 = { 488bcb e8???????? 84c0 753d 488bcb e8???????? 3a4500 }
+ $sequence_7 = { 4c0f44ca 41397920 7340 498b4110 488bd3 498bca }
+ $sequence_8 = { 7410 4c8bce 488bc8 e8???????? 488bd8 eb03 498bdd }
+ $sequence_9 = { 807a1900 7525 488bc2 488b12 807a1900 7539 6666660f1f840000000000 }
condition:
- 7 of them and filesize <392192
+ 7 of them and filesize <2654208
}
-rule MALPEDIA_Win_Greetingghoul_Auto : FILE
+rule MALPEDIA_Win_Nimplant_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b976275f-692f-5ebe-b54a-1ebae523b638"
+ id = "c6b47fc0-6c54-5733-accf-0312881d8593"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.greetingghoul"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.greetingghoul_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nimplant"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nimplant_auto.yar#L1-L133"
license_url = "N/A"
- logic_hash = "0a3e95007607705383664f43202a90a64da5b8da6ba3c7b7040fd8c369e8d944"
+ logic_hash = "1d2dbc7055590af657485c9c8d5afa6cd108c9897c8a3274dd24779cb78842a6"
score = 75
quality = 75
tags = "FILE"
@@ -179567,32 +186563,32 @@ rule MALPEDIA_Win_Greetingghoul_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 56 57 8bf9 33f6 8a17 80fa20 }
- $sequence_1 = { 750d 8a5702 83c702 bb10000000 }
- $sequence_2 = { 03f1 eb03 83ceff 8a17 84d2 75a9 }
- $sequence_3 = { 2bc8 7409 8b7df8 4e 43 }
- $sequence_4 = { 751f 41 84c0 7405 83ea01 75eb 8b5dfc }
- $sequence_5 = { 43 895dfc 47 eba7 5f 5e 83c8ff }
- $sequence_6 = { 8a1a 8d5201 8a08 3acb 750c 40 84c9 }
- $sequence_7 = { 33db 895dfc 8945f4 3806 740b }
- $sequence_8 = { 83c404 891e 85db 746f 8b7508 0f57c0 57 }
- $sequence_9 = { 7457 8d42d0 3c09 7708 }
+ $sequence_0 = { 4c89e9 0f11642440 e8???????? 803b00 0f8515ffffff 488b4c2468 4885c9 }
+ $sequence_1 = { 894c2430 4889ac24b0000000 e9???????? 4981ffff7f0000 4c89f2 488b4b08 490f4ed7 }
+ $sequence_2 = { 488d051e3a0800 48895110 48894120 48c741183a000000 48c7410800000000 48c7442420a1060000 e8???????? }
+ $sequence_3 = { e8???????? 488b442440 488b542448 44886c0208 4883c001 0f8093040000 488b542448 }
+ $sequence_4 = { e8???????? 4c8b442430 48ba0000000000000040 4889f1 4c01e9 0f80b1000000 4885c9 }
+ $sequence_5 = { f30f6f25???????? 4889ea 41b8a94d975e 4c89e9 4c899c2408010000 4c89942400010000 0f11a42410010000 }
+ $sequence_6 = { 488b9424f0000000 4889d1 4883e904 0f80de0f0000 4839ca 0f8e58100000 4885c9 }
+ $sequence_7 = { e8???????? 803b00 488b942488000000 488b842480000000 0f8599feffff 4c8b4e58 4c89f1 }
+ $sequence_8 = { 80f90b 0f873b1a0000 0fb6f2 83ee01 4863f6 4883c60c 48c1e604 }
+ $sequence_9 = { 4889eb 48897c2440 488b7c2438 4889c5 4c89ee 4c897c2460 }
condition:
- 7 of them and filesize <696320
+ 7 of them and filesize <1811456
}
-rule MALPEDIA_Win_Zeus_Openssl_Auto : FILE
+rule MALPEDIA_Win_Breach_Rat_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8c3065fc-d922-5a5a-97bb-f5578c899954"
+ id = "f70ab09f-8643-5192-b966-55a3dab88920"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus_openssl"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zeus_openssl_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.breach_rat"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.breach_rat_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "87e8b70576343bf43fa1d91175bc18c4648aa0bc5e7b7de2b8eae5131a311e26"
+ logic_hash = "8cb7f4b75bac273a3c54152da1b9e63a78dde17954dfd874b266899e47404327"
score = 75
quality = 75
tags = "FILE"
@@ -179606,32 +186602,32 @@ rule MALPEDIA_Win_Zeus_Openssl_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { c1e205 2bd1 8bce c7460471000000 }
- $sequence_1 = { eb04 807dfd05 7607 814a1800100100 8a4dfe }
- $sequence_2 = { 8b45f4 8b4850 8b45d0 23c2 894dcc 8b0481 8bc8 }
- $sequence_3 = { 895df0 0fb6de 0145f8 0fb745d2 0fb6ca 03cb bf01000000 }
- $sequence_4 = { 48 7526 804dff04 884a01 eb19 804dff02 884a01 }
- $sequence_5 = { 894a04 83c620 83c120 81fee00f0000 }
- $sequence_6 = { 83c608 03d0 895dfc 8955f8 897df0 3b75cc 72dc }
- $sequence_7 = { 8b8d7cffffff 830204 5e c70101000000 33c0 5b }
- $sequence_8 = { 898bc41b0000 8b5dfc 2bf1 8b7df4 8bc8 c1e908 0fb6c9 }
- $sequence_9 = { d1e8 83fe1f 7eeb 6683bfb800000000 7537 6683bfbc00000000 752d }
+ $sequence_0 = { 5e 5b 8be5 5d c20400 884c240f 8d442418 }
+ $sequence_1 = { 50 8bce e8???????? 8bc8 e8???????? 8d8dacf6ffff c745fcffffffff }
+ $sequence_2 = { c1e81f 03c2 8985d8feffff 0f8479080000 83c724 89bde0feffff 8d9b00000000 }
+ $sequence_3 = { c741140f000000 c7411000000000 c60100 e8???????? ff7510 8d4dd4 ff750c }
+ $sequence_4 = { 8be5 5d c3 68???????? 8bce e8???????? b001 }
+ $sequence_5 = { 8b5508 8bcb 0fb712 8bff 663910 7408 83c002 }
+ $sequence_6 = { 42 8b5de0 3bd6 72f2 8b45a4 2bc6 50 }
+ $sequence_7 = { c7471800010000 8b4df4 8bc7 c7470400000000 c7470800000000 5f 5e }
+ $sequence_8 = { eb20 84c9 74ed 8b4df0 8d45d8 50 e8???????? }
+ $sequence_9 = { e8???????? 68???????? 8d859cf4ffff c745fc5c000000 50 8bce e8???????? }
condition:
- 7 of them and filesize <4546560
+ 7 of them and filesize <645120
}
-rule MALPEDIA_Win_Wormhole_Auto : FILE
+rule MALPEDIA_Win_Tinyloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "02cb6b4c-3f82-593d-8995-30894f37de3e"
+ id = "0d2fde25-ff7d-54ba-a2fe-e20fb626403d"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wormhole"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wormhole_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinyloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tinyloader_auto.yar#L1-L168"
license_url = "N/A"
- logic_hash = "468c0b29b40a7f8149923ac2555699892601064a2e38020dd68e3cf5b3d71577"
+ logic_hash = "544c827393b5f9a7c28206644605d3c060467a9b94170d9210a95463f44b3867"
score = 75
quality = 75
tags = "FILE"
@@ -179645,32 +186641,38 @@ rule MALPEDIA_Win_Wormhole_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { eb1b 3d04000100 752a a1???????? 68???????? 6a06 }
- $sequence_1 = { 50 56 e8???????? 83c40c 8d4c2408 8d942414010000 }
- $sequence_2 = { ffd3 6a00 6a00 89442418 8d442428 }
- $sequence_3 = { e8???????? a1???????? 83c404 50 ff15???????? c705????????00000000 c705????????00000000 }
- $sequence_4 = { 75f0 a1???????? 85c0 74d5 e8???????? }
- $sequence_5 = { c705????????01000000 68f4010000 ff15???????? 8b15???????? 52 e8???????? }
- $sequence_6 = { 85f6 7512 6a04 68???????? 6a28 57 e8???????? }
- $sequence_7 = { 6a78 6a28 57 50 e8???????? }
- $sequence_8 = { 8b442404 56 57 8b7c2410 6a78 6a28 }
- $sequence_9 = { 7564 8b442418 3dff000000 7f59 6a0f }
+ $sequence_0 = { 90 8bbb97114000 90 8938 90 }
+ $sequence_1 = { 6689c8 90 6a40 6800300000 6800800200 6a00 }
+ $sequence_2 = { 039d58080000 6a00 6800040000 53 ffb5b8050000 ff15???????? }
+ $sequence_3 = { 31db 90 31c9 90 }
+ $sequence_4 = { 8b5510 01da 8b12 8b4500 }
+ $sequence_5 = { 81c300040000 6a00 ff33 ff7500 ffb5b8050000 ff15???????? 83f8ff }
+ $sequence_6 = { 8b4500 83c008 c70000000000 c7855808000000000000 8b5d00 039d58080000 }
+ $sequence_7 = { 83bd580800000c 7302 ebc3 8b5d00 }
+ $sequence_8 = { ff15???????? 8985b8050000 6832a00000 ff15???????? 8b9da8050000 66894302 66c7030200 }
+ $sequence_9 = { 90 89c6 90 0500400100 }
+ $sequence_10 = { ffb5a0050000 6802020000 ff15???????? 6a06 6a01 6a02 ff15???????? }
+ $sequence_11 = { c705????????00010000 68???????? 68???????? ff15???????? 68???????? ff15???????? }
+ $sequence_12 = { 6a10 ffb5a8050000 ffb5b8050000 ff15???????? }
+ $sequence_13 = { 81fb04030000 730c 90 83c004 }
+ $sequence_14 = { 31c9 90 3108 90 813890909090 }
+ $sequence_15 = { 637574 6541 0050ff 15???????? c705????????00010000 68???????? 68???????? }
condition:
- 7 of them and filesize <99576
+ 7 of them and filesize <40960
}
-rule MALPEDIA_Win_Mrac_Auto : FILE
+rule MALPEDIA_Win_Vhd_Ransomware_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f610a0ea-21d4-5420-9cb8-a0ef900d553a"
+ id = "1b802015-a125-5833-acd7-30aed08841d8"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mrac"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mrac_auto.yar#L1-L133"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vhd_ransomware"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vhd_ransomware_auto.yar#L1-L126"
license_url = "N/A"
- logic_hash = "39e0c8c23990eee898b7d74c2127c69decfcb303742ac7378812e728f22f2f91"
+ logic_hash = "32d97d3009fbca3c4f84bd22721b2479eac7cefb08b428240c2e9ebde9b435cb"
score = 75
quality = 75
tags = "FILE"
@@ -179684,32 +186686,32 @@ rule MALPEDIA_Win_Mrac_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d8c24d40a0000 6a0f 888424ea0a0000 e8???????? 346c 8d8c24d40a0000 6a10 }
- $sequence_1 = { 8d8c24c8030000 e8???????? 046e 8d8c24c4030000 6a77 888424c8030000 e8???????? }
- $sequence_2 = { 6a0a 88842475060000 e8???????? 3451 8d8c2464060000 6a0b 88842476060000 }
- $sequence_3 = { c684240b07000079 c684240c07000079 c684240d0700007b c684240e0700007e c684240f0700007e c684241007000032 c68424110700003d }
- $sequence_4 = { 8d8c249c000000 6a27 888424a8000000 e8???????? 0454 8d8c249c000000 6a27 }
- $sequence_5 = { 041d 342f 8885a1fbffff 8b8580fbffff 041e 3471 8885a2fbffff }
- $sequence_6 = { 8d4c2460 6a4f 88442470 e8???????? 0456 8d4c2460 6a4f }
- $sequence_7 = { 3462 8845b0 8b459c 0411 346a 8845b1 8b459c }
- $sequence_8 = { 3474 8d8c2414050000 6a06 88842421050000 e8???????? 346f 8d8c2414050000 }
- $sequence_9 = { 040f 3472 88842433140000 8b842420140000 0410 3469 }
+ $sequence_0 = { 8b450c 4a 3bd0 7d10 8bc8 }
+ $sequence_1 = { 68???????? 8d45f4 50 c745f4d8514100 e8???????? cc 8bff }
+ $sequence_2 = { e8???????? 8b8514e6ffff 48 83c404 4b 898514e6ffff 85c0 }
+ $sequence_3 = { f3ab 8b8dccfcffff 890a 85c9 7e98 8d4a04 }
+ $sequence_4 = { c1eb18 0fb69b98744100 c1e308 0bda 8b55cc c1ea08 0fb6d2 }
+ $sequence_5 = { 66895c2460 897c241c c7442420c05d4000 897c2424 897c2428 }
+ $sequence_6 = { 7d10 895c8204 ff02 8bde 33f6 8bcb 0bce }
+ $sequence_7 = { e8???????? b9c9000000 8bf0 8dbd7cf6ffff }
+ $sequence_8 = { 46 83fe40 7cee 8d4d9c 51 8d8d84baffff e8???????? }
+ $sequence_9 = { ff15???????? 32c0 e9???????? 6a00 8d8588b4ffff 50 6800200000 }
condition:
- 7 of them and filesize <745472
+ 7 of them and filesize <275456
}
-rule MALPEDIA_Win_Recordbreaker_Auto : FILE
+rule MALPEDIA_Win_Sagerunex_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "242c0c11-6eb0-5e72-beaa-aa71c863ae8a"
+ id = "f1b502b3-b120-59e0-983f-cafb93914bcc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.recordbreaker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.recordbreaker_auto.yar#L1-L114"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sagerunex"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sagerunex_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "600e9d6aeb0913499891accea4667949930b0cff9e2a09c3687c79439815914b"
+ logic_hash = "08cdcbbbd6ca868eddb1becc5a51582d041936061352010bb8c3c5ac48e633a5"
score = 75
quality = 75
tags = "FILE"
@@ -179723,32 +186725,32 @@ rule MALPEDIA_Win_Recordbreaker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 2bf7 8bcf d1fe 56 53 e8???????? }
- $sequence_1 = { 42 66890c38 8d0412 0fb70c30 663bcb }
- $sequence_2 = { 59 85c0 7408 6afe }
- $sequence_3 = { 6a02 ff75fc ff15???????? 6a03 ff75fc ff15???????? 6a04 }
- $sequence_4 = { 8bd7 8bc8 e8???????? 8b15???????? 8bc8 e8???????? 8bd3 }
- $sequence_5 = { 6a1a 53 6a00 8bf8 }
- $sequence_6 = { 881e 46 49 83ea01 }
- $sequence_7 = { 8b15???????? 8bc8 e8???????? 8b55ec }
- $sequence_8 = { 2bc6 d1f8 56 8d3c46 33c0 }
- $sequence_9 = { 8b4d0c 8b07 5f 5e }
+ $sequence_0 = { 4c8bb424d8010000 c744245001000000 4c896c2458 4c896c2460 4885c9 742c 4a8d04fd00000000 }
+ $sequence_1 = { 72d1 498bd4 483bd7 488d4de7 480f42fa 488bd7 e8???????? }
+ $sequence_2 = { c74324a44ffabe 488bcb 89b3e8000000 c70340000000 e8???????? 488d442420 c60000 }
+ $sequence_3 = { 498bcc e8???????? 85c0 7849 488d45b0 488d55f0 498bcf }
+ $sequence_4 = { e8???????? e8???????? ffc7 448bc0 b84fecc44e 41f7e8 c1fa03 }
+ $sequence_5 = { 4d894838 4c8b5340 458bca 4983d300 49c1ea20 418bc9 4d0fafcf }
+ $sequence_6 = { 894260 33d2 e8???????? 488d442470 488d15d0230300 }
+ $sequence_7 = { 83f803 7cc5 eb04 897c2450 443bfe 752a 448b7c2444 }
+ $sequence_8 = { 498bcf c745df02000000 c745fb01000000 c745e301000000 ff15???????? 85c0 7507 }
+ $sequence_9 = { 4403c0 418bc6 4503c2 c1c007 c1ca0b 33d0 418bc6 }
condition:
- 7 of them and filesize <232312
+ 7 of them and filesize <619520
}
-rule MALPEDIA_Win_Navrat_Auto : FILE
+rule MALPEDIA_Win_Ceeloader_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "267e4534-59a3-5746-9f05-524cfafc2ef1"
+ id = "385139d5-6e1c-5e2f-90c3-04a312f22353"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.navrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.navrat_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ceeloader"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ceeloader_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "d02406512a8ed4f24033286c28dfca048100e2bb166bb80aa3e9acab2e4b74d3"
+ logic_hash = "5733aa6d7aff1d1a6c42de98107a30359cd04782474df0d5ddf09cf2979a826e"
score = 75
quality = 75
tags = "FILE"
@@ -179762,32 +186764,32 @@ rule MALPEDIA_Win_Navrat_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 0fbec0 83e847 c3 8d48d0 80f909 }
- $sequence_1 = { 56 68???????? 50 8d85f0feffff 8bf1 50 }
- $sequence_2 = { f7de 1bf6 f7de 56 68???????? }
- $sequence_3 = { 8bf0 f7de 1bf6 f7de 56 }
- $sequence_4 = { 0fbec0 83e847 c3 8d48d0 80f909 7707 }
- $sequence_5 = { 7707 0fbec0 83c004 c3 3c2b 7503 }
- $sequence_6 = { c3 3c2f 0f95c0 fec8 2440 fec8 }
- $sequence_7 = { 85f6 7407 8b7608 83461c02 }
- $sequence_8 = { c745dc726f736f c745e066745c57 c745e4696e646f c745e877735c43 c745ec75727265 c745f06e745665 }
- $sequence_9 = { 51 56 50 57 a3???????? ff15???????? 57 }
+ $sequence_0 = { 3bce 33f6 23c7 0bda 8bde c3 0bd3 }
+ $sequence_1 = { 448b15???????? 4489c6 4431de 4589c3 4101f3 44891d???????? 4589c3 }
+ $sequence_2 = { 664589c2 664489942490030000 440fbe05???????? 4183f074 664589c2 664489942492030000 440fbe05???????? }
+ $sequence_3 = { 0bda 8bde 0bd3 3bce 23f3 7a04 0bda }
+ $sequence_4 = { 8b842420010000 3b84241c010000 0f8433000000 8b842420010000 898424dc000000 e8???????? 8b8c241c010000 }
+ $sequence_5 = { 3bdd 23fd 0bda 8bde 0bd3 3bce 5a }
+ $sequence_6 = { 741d 4885ff c6435401 488d0d53880800 480f45cf 48894b48 e8???????? }
+ $sequence_7 = { 88542433 0fbe05???????? 83f064 88c2 88542434 0fbe05???????? 83f076 }
+ $sequence_8 = { 4489a42464020000 4403bc2464020000 4489bc2460020000 448bbc2460020000 4589dc 4181e45d386101 4489a4245c020000 }
+ $sequence_9 = { 41c1e204 4489942448050000 44038c2448050000 44898c2444050000 448b8c2444050000 4189d2 4181e235913d02 }
condition:
- 7 of them and filesize <352256
+ 7 of them and filesize <2321408
}
-rule MALPEDIA_Win_Dimnie_Auto : FILE
+rule MALPEDIA_Win_Temp_Stealer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8c590346-8ec4-5fdf-b560-136be983395f"
+ id = "f2cc61b5-19bf-56a2-9eca-3f40739e6ccc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dimnie"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dimnie_auto.yar#L1-L125"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.temp_stealer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.temp_stealer_auto.yar#L1-L132"
license_url = "N/A"
- logic_hash = "0f3f067f034444fcc73a96e10a6a53b5dc6ee2b790aaefb3f5f862bcac5e875a"
+ logic_hash = "225e1e9fc27831c15c6655569f2cde4ac7e8ac8903eef398ab726a5dfa80c059"
score = 75
quality = 75
tags = "FILE"
@@ -179801,32 +186803,32 @@ rule MALPEDIA_Win_Dimnie_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7605 8b450c eb54 8b550c 2b5508 83fa01 751c }
- $sequence_1 = { 33c0 eb6e 8b4508 3b450c 7505 8b4508 }
- $sequence_2 = { 8945f4 8b45f4 c1e804 8945f4 8b4df8 83c101 }
- $sequence_3 = { 8b550c 2b5508 8955f8 0f31 8945f4 8b45f4 c1e804 }
- $sequence_4 = { eb6e 8b4508 3b450c 7505 8b4508 eb61 }
- $sequence_5 = { 2b5508 83fa01 751c 0f31 }
- $sequence_6 = { 8b4508 eb61 8b4d08 3b4d0c 7605 8b450c }
- $sequence_7 = { 8b4d0c 8a55af 885102 837d1002 7e13 8b4508 0fb64802 }
- $sequence_8 = { 8b4510 8b08 83e107 8b5510 890a }
- $sequence_9 = { c70201000000 8b4508 8b08 83e10f 8b5508 890a 8b450c }
+ $sequence_0 = { 4d8bc7 498bce e8???????? 4885c0 7405 492bc6 eb04 }
+ $sequence_1 = { 488d4c2430 e8???????? 488b442430 48635004 488d051a730300 4889441430 488b442430 }
+ $sequence_2 = { 5e 5d c3 4889542410 48894c2408 55 53 }
+ $sequence_3 = { 488d4dc0 e8???????? 0f10442460 0f1145c0 0f104c2470 0f114dd0 660f6f05???????? }
+ $sequence_4 = { 418ac7 84c0 0f8408010000 8b4c2448 488d154240fdff 2b4c244c 41b826000000 }
+ $sequence_5 = { 488d4c2430 e8???????? 488d542430 488d4c2470 e8???????? 90 }
+ $sequence_6 = { 488d4c2450 e8???????? 660f6f05???????? 488d152a670300 488d4de0 4c896de0 f30f7f45f0 }
+ $sequence_7 = { 4183f805 0f8582000000 8b470c 458d487a c744243001000000 4c8d05ee7f0100 89442428 }
+ $sequence_8 = { ff15???????? 4c8be0 488985a0000000 488d15b9a30300 488bcb ff15???????? 4c8bf8 }
+ $sequence_9 = { 488d4c2458 e8???????? 90 488d8d48010000 e8???????? 488d45a8 }
condition:
- 7 of them and filesize <212992
+ 7 of them and filesize <652288
}
-rule MALPEDIA_Win_Donot_Auto : FILE
+rule MALPEDIA_Win_Sneepy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "38387986-3cf2-52ef-b35f-48e7a3ada73a"
+ id = "92a9a098-af3e-565a-a77d-ae1e4fe61438"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.donot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.donot_auto.yar#L1-L130"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sneepy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sneepy_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "856eb217efb67c7a23eb4ad0af50dccbe8bb723a98d81632999df9a793bf3e4e"
+ logic_hash = "0102a60e328cb3b8b2c7928ec4f988725df8b07a3b2131190567958f6bfcc033"
score = 75
quality = 75
tags = "FILE"
@@ -179840,32 +186842,32 @@ rule MALPEDIA_Win_Donot_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b04c580b80310 5d c3 33c0 }
- $sequence_1 = { c7461400000000 0f1106 f30f7e45e4 660fd64610 c745e400000000 c745e80f000000 85d2 }
- $sequence_2 = { 03d3 d1fa 8d4102 894738 8b4710 8918 8b4720 }
- $sequence_3 = { e8???????? 8b15???????? b910000000 2bd6 8a0432 8d7601 3046ff }
- $sequence_4 = { 7361 8bc6 8bde 83e03f c1fb06 6bc838 8b049d187b0410 }
- $sequence_5 = { c645fc02 8d4dbc e8???????? 8bf8 83c404 3bf7 7465 }
- $sequence_6 = { 0f438540ffffff 50 ff15???????? c645fc1b 8b559c 83fa10 722c }
- $sequence_7 = { c6861002000000 8b8e0c020000 83f910 722f 8b86f8010000 41 81f900100000 }
- $sequence_8 = { c685bcedffff00 8d5101 8a01 41 84c0 75f9 }
- $sequence_9 = { c6863801000000 8b8e34010000 83f910 722f 8b8620010000 41 81f900100000 }
+ $sequence_0 = { e8???????? 83c40c 33c0 8a8810234100 }
+ $sequence_1 = { 83f8ff 0f85abfeffff 5f 5e }
+ $sequence_2 = { 8945e4 8845e8 e8???????? 8d55e4 83c404 2bd0 8a08 }
+ $sequence_3 = { ffd6 85c0 740d 8b85b8feffff 50 ffd6 }
+ $sequence_4 = { e8???????? 83c40c 32c0 5e 8b4dfc }
+ $sequence_5 = { 68???????? 8945f4 8845f8 e8???????? 8d55f4 83c404 }
+ $sequence_6 = { ff15???????? 8bc8 8a10 40 }
+ $sequence_7 = { 33c0 8b4d08 3b0cc520de4000 740a 40 83f816 72ee }
+ $sequence_8 = { 668b0d???????? 8a15???????? 668908 6a50 }
+ $sequence_9 = { 33c0 8945e4 83f805 7d10 668b4c4310 66890c4514314100 }
condition:
- 7 of them and filesize <626688
+ 7 of them and filesize <188416
}
-rule MALPEDIA_Win_Nabucur_Auto : FILE
+rule MALPEDIA_Win_Eternal_Petya_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "01e16fcc-e93c-502a-bf23-e97657c28f28"
+ id = "bf49aeac-2e4f-5384-8db1-b43fb4139322"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nabucur"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.nabucur_auto.yar#L1-L161"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.eternal_petya"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.eternal_petya_auto.yar#L1-L162"
license_url = "N/A"
- logic_hash = "6100efc8bca15f40de853b2fa2bd4731e512123d488b941f31d2f09287a69887"
+ logic_hash = "715ae6ddfaceb7ac967a454caeda07039960e25d99f3dc3f83571a182c2a56de"
score = 75
quality = 75
tags = "FILE"
@@ -179879,38 +186881,38 @@ rule MALPEDIA_Win_Nabucur_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 48 49 85c0 75fa }
- $sequence_1 = { 48 5f 894500 5d }
- $sequence_2 = { 48 83e908 85c0 75f0 57 }
- $sequence_3 = { 48 83e904 85c0 7ff3 8bf0 8b442448 }
- $sequence_4 = { 48 83f801 89442418 0f8f15ffffff }
- $sequence_5 = { 33ff 33f6 4a c744244001000000 }
- $sequence_6 = { 009eaa030000 0fb686aa030000 57 83f80a 0f876d010000 }
- $sequence_7 = { 48 8906 8d442410 50 }
- $sequence_8 = { ba86a33ffb 83e904 ba575a2bfd eb69 83f901 7519 }
- $sequence_9 = { 3f 71e3 0c42 869576f1896a 86f6 }
- $sequence_10 = { 732e 5c 54 7346 b654 8c534c }
- $sequence_11 = { 141b 46 ec 54 732e }
- $sequence_12 = { 01e4 01f4 1481 0491 00850cf41196 }
- $sequence_13 = { ff75f8 ff35???????? ff15???????? 8b7520 8b45e4 }
- $sequence_14 = { 8b4608 50 ff15???????? 61 eb11 }
- $sequence_15 = { 06 e409 9a1496099a1581 0d911c9060 9d 01e4 }
+ $sequence_0 = { 55 8bec 51 57 68000000f0 }
+ $sequence_1 = { 53 8d4644 50 53 }
+ $sequence_2 = { 57 68000000f0 6a18 33ff }
+ $sequence_3 = { 53 6a21 8d460c 50 }
+ $sequence_4 = { 68f0000000 6a40 ff15???????? 8bd8 }
+ $sequence_5 = { 49 75f2 8b4364 034360 8b4b68 894dd4 }
+ $sequence_6 = { 8945d0 8bc7 8b7df8 d3e8 8b4de0 03c1 8d3c87 }
+ $sequence_7 = { 55 8bec 8b4d0c baff000000 }
+ $sequence_8 = { 8d4508 50 53 ff750c 897508 }
+ $sequence_9 = { 68???????? e8???????? 85c0 7403 83ce02 }
+ $sequence_10 = { 68e8030000 ff15???????? 3bfe 75d3 }
+ $sequence_11 = { 55 8bec 8b5508 53 56 57 8b721c }
+ $sequence_12 = { 8b07 85c0 75c3 8b75f4 }
+ $sequence_13 = { e8???????? 894610 895614 8bc6 5f 5e }
+ $sequence_14 = { 898502fcffff 8b85e8fbffff 99 81e2ff010000 }
+ $sequence_15 = { 56 51 ffd3 8b15???????? 56 52 8985f0fbffff }
condition:
- 7 of them and filesize <1949696
+ 7 of them and filesize <851968
}
-rule MALPEDIA_Win_Classfon_Auto : FILE
+rule MALPEDIA_Win_Hotcroissant_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "68a5b428-fba0-5238-83c9-3255bfbb3ff5"
+ id = "250e256f-bf01-5062-b0b5-f902754e1ec1"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.classfon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.classfon_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hotcroissant"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hotcroissant_auto.yar#L1-L117"
license_url = "N/A"
- logic_hash = "752d9b4933679b22e7a2ada3974321921c7722355427af1c70ee3b8ff2e5df5f"
+ logic_hash = "2f7df521e2093bda16bb20427bf0af1885ac8e8db0533585bb878e9befdcfdd1"
score = 75
quality = 75
tags = "FILE"
@@ -179924,71 +186926,69 @@ rule MALPEDIA_Win_Classfon_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 85c0 7462 8b542408 8b8e00020000 8b44240c }
- $sequence_1 = { 8b742418 83f8ff 898600020000 7508 5f 33c0 }
- $sequence_2 = { 50 ffd3 89be04020000 8b8600020000 3bc7 740e }
- $sequence_3 = { 8b1d???????? a1???????? 50 57 ff15???????? }
- $sequence_4 = { 8d4c241c 8d542424 51 8b4c2414 8d442424 52 }
- $sequence_5 = { 8d842430020000 50 ffd7 8d8c2430010000 51 ffd7 8b542424 }
- $sequence_6 = { 6a00 6a00 6a00 6802000004 6a00 899610020000 }
- $sequence_7 = { 68???????? 51 c744242802000000 c744242c2c010000 ff15???????? }
- $sequence_8 = { 50 ff15???????? 8bd8 83fbff 0f849c000000 8b470c 8b5708 }
- $sequence_9 = { 0f85c3000000 8b460c 85c0 0f84c0000000 03c5 }
+ $sequence_0 = { c705????????01000000 ffd6 6800040000 68???????? }
+ $sequence_1 = { 68???????? 68???????? 68???????? c705????????0c000000 c705????????00000000 c705????????01000000 }
+ $sequence_2 = { 25ff7f0000 33c9 7707 3d00400000 7608 6a0a ff15???????? }
+ $sequence_3 = { 83e780 c1e307 33fb c1e711 c1e808 46 0bc7 }
+ $sequence_4 = { 85c0 7506 6a0a ffd6 }
+ $sequence_5 = { 6a00 68703a0000 6a00 50 ffd7 85c0 }
+ $sequence_6 = { e8???????? 6a00 c705????????00000000 ff15???????? 6a00 }
+ $sequence_7 = { 8d958cc5ffff 52 50 ff15???????? 85c0 }
+ $sequence_8 = { ff15???????? 85c0 7506 6a0a }
+ $sequence_9 = { 56 6a01 50 ff15???????? a1???????? }
condition:
- 7 of them and filesize <73728
+ 7 of them and filesize <591872
}
-rule MALPEDIA_Win_Dratzarus_Auto : FILE
+rule MALPEDIA_Win_Unidentified_089_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3e7875e3-7e0c-5dea-9e90-8b6135466b8c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dratzarus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dratzarus_auto.yar#L1-L123"
+ id = "f61e4a77-808b-5e07-801b-03e57ce838b5"
+ date = "2023-07-11"
+ modified = "2023-07-15"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_089"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_089_auto.yar#L1-L98"
license_url = "N/A"
- logic_hash = "5f92bffb1ff676600291544ee9f45d8f2036c734b0601a5e03b740f618ff0f21"
+ logic_hash = "f9666eb88fbd91e0eb2e4b4c8812230b36d73d66192fed407aecfaa8f0ed362a"
score = 75
quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
+ malpedia_rule_date = "20230705"
+ malpedia_hash = "42d0574f4405bd7d2b154d321d345acb18834a41"
+ malpedia_version = "20230715"
malpedia_license = "CC BY-SA 4.0"
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 740a 488b1b 4885db 75c2 eb2f 8b8398010000 }
- $sequence_1 = { f6c201 7403 66ffc3 66ffc0 6683f81a }
- $sequence_2 = { e8???????? f20f5ef0 f20f1005???????? f20f2cd6 660f6eca 4863c2 488d0c40 }
- $sequence_3 = { ff15???????? 488d4d68 ba13000000 488905???????? e8???????? }
- $sequence_4 = { 488d8dc8000000 ba1c000000 488905???????? e8???????? 488bcb 488bd0 ff15???????? }
- $sequence_5 = { 3c41 7c04 3c5a 7e08 3c30 7c19 3c39 }
- $sequence_6 = { 6683f81a 72e3 0fb7c3 4883c420 }
- $sequence_7 = { c745303ae47159 c7453474b06493 c745380897878b c6453c5b e8???????? 488bc8 }
- $sequence_8 = { c7450f86f5e3e6 c74513a93633c4 c7451793554020 c7451b48549c39 c7451faaa5f9c7 }
- $sequence_9 = { 488d4dc8 ba0c000000 488905???????? e8???????? 488bcb 488bd0 ff15???????? }
+ $sequence_0 = { 889dd4feffff 899d84feffff 898588feffff 889d74feffff 33c0 }
+ $sequence_1 = { 8b4508 e8???????? c20c00 e8???????? cc 6a30 }
+ $sequence_2 = { f2e9e3000000 55 8bec eb0d ff7508 e8???????? }
+ $sequence_3 = { 83f904 0f8582000000 8b75d0 8bfb }
+ $sequence_4 = { eb0f ff7634 57 ff562c }
+ $sequence_5 = { 88041e 880c1f 0fb6041e 8b4dfc 03c2 8b550c }
+ $sequence_6 = { 3dffffff7f 0f87a2000000 03c0 3d00100000 7227 }
+ $sequence_7 = { 56 6a01 8d4dec 8975d8 }
condition:
- 7 of them and filesize <1606656
+ 7 of them and filesize <389120
}
-rule MALPEDIA_Win_Chthonic_Auto : FILE
+rule MALPEDIA_Win_Punkey_Pos_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a742c49c-6e3e-5872-bf95-e2e0adb04114"
+ id = "846510df-399c-5c73-991a-33d5b6390d78"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chthonic"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chthonic_auto.yar#L1-L120"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.punkey_pos"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.punkey_pos_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "836fdc80a654c12e0017df0790b315dbe177f1e5fd0fa5cd260efc9eb4af2475"
+ logic_hash = "afbb6da5e69098feb647a1b39faf19c917a9fcb87281ef711eecf3479b712e35"
score = 75
quality = 75
tags = "FILE"
@@ -180002,32 +187002,32 @@ rule MALPEDIA_Win_Chthonic_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 7459 4f 8bf0 8bcf d3ee 83e601 }
- $sequence_1 = { 0f845d010000 4f 8bf0 8bcf }
- $sequence_2 = { 81cf00ffffff 47 8a01 8845ff 8d84bdfcfbffff 8b10 }
- $sequence_3 = { 80e17f 8808 b001 5b c3 55 }
- $sequence_4 = { 8b75f8 83fe02 0f850d010000 8b4df0 }
- $sequence_5 = { 016e04 83c703 013e 8b36 83c410 }
- $sequence_6 = { 5e 0f94c0 5b c9 c3 8b041a }
- $sequence_7 = { 53 ff7510 ff7508 e8???????? 85c0 }
- $sequence_8 = { 80e17f 8808 b001 5b c3 55 8bec }
- $sequence_9 = { ff751c ff7518 ff7514 53 ff7510 ff7508 e8???????? }
+ $sequence_0 = { ffd7 a3???????? 85c0 74ae 5f }
+ $sequence_1 = { 8bec 837d0c01 56 57 756b }
+ $sequence_2 = { 837d0c01 56 57 756b 8b4508 }
+ $sequence_3 = { ff15???????? 8bf0 85f6 7508 5f 33c0 5e }
+ $sequence_4 = { 33c0 5e 5d c20c00 8b3d???????? }
+ $sequence_5 = { 68e7070000 50 ff15???????? ff05???????? 8b0d???????? }
+ $sequence_6 = { 55 8bec 8b4508 85c0 7919 8b4d10 8b550c }
+ $sequence_7 = { 6a02 a3???????? ff15???????? a3???????? 33c0 }
+ $sequence_8 = { 52 50 a1???????? 50 ff15???????? 5d c20c00 }
+ $sequence_9 = { 8bf0 85f6 7508 5f 33c0 5e }
condition:
- 7 of them and filesize <425984
+ 7 of them and filesize <499712
}
-rule MALPEDIA_Win_Lightneuron_Auto : FILE
+rule MALPEDIA_Win_Gazer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "539cc86b-948c-5a39-97ed-a3902d358bcb"
+ id = "4f697767-8c05-5c0d-bde5-d6a7fdfb5341"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lightneuron"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lightneuron_auto.yar#L1-L132"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gazer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.gazer_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "eb817806e099f7ab1d4d5a04d338d80185e8c65715cfe2e18f8deb16ab95898d"
+ logic_hash = "9d7c4a164f0a9c13470f23ca334f1d2575ebac4454f4b53ffe47ee33d23ce84e"
score = 75
quality = 75
tags = "FILE"
@@ -180041,32 +187041,32 @@ rule MALPEDIA_Win_Lightneuron_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? 488d8c2434010000 33d2 41b800010000 89b42430010000 e8???????? 488bcf }
- $sequence_1 = { 0f4ed9 3bc5 770b 3beb 7707 b801000000 eb02 }
- $sequence_2 = { 85d2 7e24 488b8f80000000 e8???????? 488b8f80000000 4885c9 740c }
- $sequence_3 = { e8???????? 8bf0 85c0 7502 893b 85f6 754c }
- $sequence_4 = { 4503c1 453bc1 4183d200 4403c0 443bc0 45894304 }
- $sequence_5 = { 448bc3 e8???????? 448bc3 33d2 498bcd e8???????? 498bcd }
- $sequence_6 = { 4c0f45c0 488b05???????? 4885c0 480f45d0 488d442448 4889442430 4c896c2428 }
- $sequence_7 = { 488bd0 498bcc e8???????? 4d8b0c24 458b44240c 33d2 }
- $sequence_8 = { 48895c2428 89442420 e8???????? 448b05???????? 4533c9 ba9d010000 b900001000 }
- $sequence_9 = { 4533c9 4533c0 babf000000 b900001000 48895c2428 89442420 e8???????? }
+ $sequence_0 = { 85c0 7511 e8???????? 84c0 7508 }
+ $sequence_1 = { 85c0 7511 e8???????? 84c0 7508 83c8ff e9???????? }
+ $sequence_2 = { 85c0 7511 e8???????? 84c0 }
+ $sequence_3 = { ff15???????? 85c0 7511 e8???????? 84c0 7508 83c8ff }
+ $sequence_4 = { 7511 e8???????? 84c0 7508 83c8ff e9???????? }
+ $sequence_5 = { ff15???????? 85c0 7511 e8???????? 84c0 7508 }
+ $sequence_6 = { 7511 e8???????? 84c0 7508 83c8ff }
+ $sequence_7 = { ff15???????? 85c0 7511 e8???????? 84c0 }
+ $sequence_8 = { 85c0 7511 e8???????? 84c0 7508 83c8ff }
+ $sequence_9 = { 4133c0 23c1 33c2 4103c1 }
condition:
- 7 of them and filesize <573440
+ 7 of them and filesize <950272
}
-rule MALPEDIA_Win_Neutrino_Pos_Auto : FILE
+rule MALPEDIA_Win_Ddkeylogger_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3a77c0fc-cd49-5986-b2b4-8a8639992c93"
+ id = "32af4d2e-12e0-5512-a4a7-e09c0d4c8550"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.neutrino_pos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.neutrino_pos_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ddkeylogger"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ddkeylogger_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "d3da7317997b76876b14e53b428d397cde821604c2c6da81c73b18c8b2dd677f"
+ logic_hash = "03458a2b11f7d3c85fa0851f46b24d084521ba159cb6b960088359db4227b8a0"
score = 75
quality = 75
tags = "FILE"
@@ -180080,32 +187080,32 @@ rule MALPEDIA_Win_Neutrino_Pos_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 68fbd5fba3 43 53 897dfc e8???????? 83c40c 56 }
- $sequence_1 = { 5a 6a71 6689955affffff 5a 6a61 6689955cffffff }
- $sequence_2 = { 6863ad115b 6a04 c745e801000000 8945f4 e8???????? 59 }
- $sequence_3 = { e8???????? 59 59 6a00 56 e9???????? }
- $sequence_4 = { 6a62 66898556ffffff 58 6a53 66898558ffffff }
- $sequence_5 = { 59 6a64 66898d6cffffff 59 6a68 66898d6effffff 59 }
- $sequence_6 = { 6a63 6689854cffffff 58 6a62 6689854effffff 58 6a69 }
- $sequence_7 = { 66895db2 6a64 8bd9 66895db4 8bd8 66895db6 5b }
- $sequence_8 = { 8b45e0 8b08 6a03 50 ff5138 }
- $sequence_9 = { 66894dd6 66894dd8 66894dda 66894ddc 66894dde 66894de0 66894de2 }
+ $sequence_0 = { 8bf7 83e61f c1e606 03348580ee4500 }
+ $sequence_1 = { 51 894df4 8955fc 8945f8 e8???????? 83c408 }
+ $sequence_2 = { 8bc8 c1e902 f3a5 8bc8 8d95e8faffff 83e103 52 }
+ $sequence_3 = { 0fb64f08 80cbff d2e3 40 f6d3 205c30ff 0fb64f08 }
+ $sequence_4 = { 0405 c3 f6c20c 7409 f6c208 0f95c0 }
+ $sequence_5 = { 52 50 8b81e0000000 ffd0 837df804 75e8 }
+ $sequence_6 = { c745fc00000000 e8???????? 83c40c 8d85ccfaffff 50 8d8df0fdffff 51 }
+ $sequence_7 = { 50 57 ffd3 8945bc 8d45c8 50 }
+ $sequence_8 = { ff248d4cf74000 8d48cf 80f908 7706 6a03 }
+ $sequence_9 = { 6bc930 8975e0 8db1c0624100 8975e4 }
condition:
- 7 of them and filesize <188416
+ 7 of them and filesize <808960
}
-rule MALPEDIA_Win_Forest_Tiger_Auto : FILE
+rule MALPEDIA_Win_Unidentified_088_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2947155f-bcbc-5d27-b13d-2d3d872fe248"
+ id = "008a08cf-eb70-5951-921d-71ebeefbb775"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.forest_tiger"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.forest_tiger_auto.yar#L1-L127"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_088"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_088_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "baf01183ad62d9cfadf21ee10ad4e3a50b3d3f1c1788ceb5d46999aa5751e1b0"
+ logic_hash = "edb29cf74a1f7930c182d8621bb40052ec38cc60668c8de3f80bbb2fb8759321"
score = 75
quality = 75
tags = "FILE"
@@ -180119,32 +187119,32 @@ rule MALPEDIA_Win_Forest_Tiger_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 833f01 0f94c0 84c0 7407 }
- $sequence_1 = { 833f01 0f94c0 84c0 7407 e8???????? eb05 }
- $sequence_2 = { 833f01 0f94c0 84c0 7407 e8???????? }
- $sequence_3 = { 833f01 0f94c0 84c0 7407 e8???????? eb05 e8???????? }
- $sequence_4 = { 6a0c 51 e8???????? 83c410 8b858cf8ffff 3bc3 746e }
- $sequence_5 = { 4885c9 740c e8???????? 4c8935???????? 488d0ddf710200 ff15???????? }
- $sequence_6 = { 741b 498d8c243a250000 458ac6 b213 e8???????? f7d8 1bdb }
- $sequence_7 = { 51 e8???????? 83c410 81c6a8000000 8bc6 8d5002 668b08 }
- $sequence_8 = { c20400 8b4508 c7462c00000080 c74644ffffffff 85c0 7403 894644 }
- $sequence_9 = { 7416 4883ffff 7410 8bcd e8???????? 488bcf ffd0 }
+ $sequence_0 = { c642e801 894af4 83f807 75df c705????????06000000 c705????????11000000 c705????????12000000 }
+ $sequence_1 = { c705????????208d4200 c705????????62eb4100 c705????????90154200 c605????????01 c705????????10000000 c705????????20a94200 c705????????40eb4100 }
+ $sequence_2 = { c605????????01 c705????????04000000 c705????????80a94200 c705????????61e04100 c705????????30054200 c705????????00000000 }
+ $sequence_3 = { 8b10 8d4a01 8d3490 8908 8b4de4 8b5e08 }
+ $sequence_4 = { 0f8438010000 8b00 39c7 720d 48 893c24 }
+ $sequence_5 = { 8b7de4 e9???????? 8d65f4 5b 5e 5f 5d }
+ $sequence_6 = { e9???????? c705????????08000000 c705????????04000000 c605????????12 c705????????00000000 c705????????d80f4200 }
+ $sequence_7 = { c705????????a0ad4200 c705????????4ce84100 c705????????100d4200 c605????????01 c705????????04000000 }
+ $sequence_8 = { e8???????? 89d9 89c2 e8???????? 8d65f4 5b }
+ $sequence_9 = { 894c2408 89f1 89542404 895c240c e8???????? b904000000 83ec10 }
condition:
- 7 of them and filesize <709632
+ 7 of them and filesize <919552
}
-rule MALPEDIA_Win_Compfun_Auto : FILE
+rule MALPEDIA_Win_Stealer_0X3401_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b70b97d4-0cf0-525a-92ea-8899bccf1319"
+ id = "bb4f4861-3b94-5ae9-a941-991186118cf0"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.compfun"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.compfun_auto.yar#L1-L161"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stealer_0x3401"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stealer_0x3401_auto.yar#L1-L122"
license_url = "N/A"
- logic_hash = "a0b696c7a840205849cf5ac2e95df1021718fd8d1c1053a2c6b648baa042ec58"
+ logic_hash = "5581efed5fdecbce8348574e847d7eb07ab8e38c2ac3e166eb58c72b5a5419d5"
score = 75
quality = 75
tags = "FILE"
@@ -180158,38 +187158,32 @@ rule MALPEDIA_Win_Compfun_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8d857cfeffff 50 8d857cffffff 50 e8???????? 59 50 }
- $sequence_1 = { c7460c65726174 c746106f722063 c746146c617373 c6461800 8bc6 5e }
- $sequence_2 = { 56 e8???????? 83c40c c74608697a6520 c70647657446 c74604696c6553 c6460b00 }
- $sequence_3 = { c7460472656174 c7460865557365 c7460c72546872 c6461300 }
- $sequence_4 = { e8???????? 83c40c c7460c33322020 c706496e7072 }
- $sequence_5 = { 6880000000 6a00 56 e8???????? 83c40c c70647657446 c74604756c6c50 }
- $sequence_6 = { c6460f00 8bc6 5e 5d c3 55 }
- $sequence_7 = { c7460825202020 c70625415050 c7460444415441 c6460900 8bc6 5e }
- $sequence_8 = { 034c2460 488b442450 894820 488b4c2450 }
- $sequence_9 = { 03c1 4863d0 488b4c2430 488b442438 }
- $sequence_10 = { 03c1 89442420 8b442420 83c001 }
- $sequence_11 = { 03c1 89442420 8b4c2438 488b442450 }
- $sequence_12 = { 03c1 89442420 8b542438 486bd218 }
- $sequence_13 = { 034c242c 488b442470 894820 488d542440 }
- $sequence_14 = { 03c1 89442434 8b442430 39442434 }
- $sequence_15 = { 0344242c 8bc8 e8???????? 4889442448 }
+ $sequence_0 = { 03f2 8bd6 85f6 7e37 8d8d5cfeffff e8???????? }
+ $sequence_1 = { 53 e8???????? 83c41c c74424280f000000 c744242400000000 c644241400 803b00 }
+ $sequence_2 = { 5f 894df0 8b34cd50fa0110 8b4d08 6a5a 2bce }
+ $sequence_3 = { 83781410 7202 8b00 ffb57cfdffff }
+ $sequence_4 = { c745fc05000000 8d8d5cffffff e8???????? c645fc06 83781410 7202 }
+ $sequence_5 = { 8b8db87dffff 40 3d00100000 722a f6c11f }
+ $sequence_6 = { 64a300000000 8b35???????? 8d8574ffffff 50 6a00 }
+ $sequence_7 = { 8d8598feffff 3bc3 7435 8bc8 e8???????? }
+ $sequence_8 = { 8d4c2434 e8???????? 53 e8???????? 83c404 8d44242c 8bcf }
+ $sequence_9 = { ffb5843fffff ffd7 83bd803fffff00 0f84ec000000 6a12 68???????? b9???????? }
condition:
- 7 of them and filesize <402432
+ 7 of them and filesize <357376
}
-rule MALPEDIA_Win_Unidentified_091_Auto : FILE
+rule MALPEDIA_Win_Sendsafe_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8c2d9d9b-cb98-5dfc-90ce-01312105d94f"
+ id = "cb217c22-cbf0-508f-ac96-405f94d46039"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_091"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_091_auto.yar#L1-L134"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sendsafe"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sendsafe_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "5f25d4d54583311a39cbead5d516e9dd7eb57b96b31eb59a9b18d068eb7148c5"
+ logic_hash = "e90570bf37f8e67b125b5c0e63f782c1ecedcd1e6ef21243ea37efff8deeb91b"
score = 75
quality = 75
tags = "FILE"
@@ -180203,34 +187197,34 @@ rule MALPEDIA_Win_Unidentified_091_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { e8???????? c744244801000000 488d4c2460 48895c2440 4c8d8734030000 48894c2438 4c8d0ddf721400 }
- $sequence_1 = { e8???????? 482be0 8b3a 488bd9 8b89d4050000 488bf2 85c9 }
- $sequence_2 = { e9???????? 488d8ab00e0000 e9???????? 488d8ad00e0000 e9???????? 488d8af00e0000 e9???????? }
- $sequence_3 = { 89742420 498b06 48634804 33d2 4a89543128 eb41 488b01 }
- $sequence_4 = { eb6f 4c8b5048 4d85d2 7514 c74424207a020000 418d527c 41b884000000 }
- $sequence_5 = { 742e c7814007000000000000 488d15b7081400 488b8938060000 41b895030000 e8???????? 48c7833806000000000000 }
- $sequence_6 = { eb0f 488bd3 488d0dabf12500 e8???????? 488b85d0010000 48634804 488d0524fe2500 }
- $sequence_7 = { e8???????? 90 488bcb e8???????? 85c0 7525 488b4c2438 }
- $sequence_8 = { ffc3 e8???????? 3bd8 7cc6 41f6c708 0f85d0000000 4c8d058d0c1100 }
- $sequence_9 = { eb03 890c90 8b4df3 48ffc2 4983c002 483bd1 72db }
+ $sequence_0 = { ff36 f30f6f442438 8d442428 50 660fefc8 50 8b4608 }
+ $sequence_1 = { f20f5e15???????? f20f59ca f20f58c1 f20f2cc8 894dd4 8b550c 83ba381c000000 }
+ $sequence_2 = { e8???????? 8b8510feffff e9???????? 6800010000 8b9588feffff 52 e8???????? }
+ $sequence_3 = { c1e000 8b4dfc 0fbe1401 85d2 7409 8b45f8 83c001 }
+ $sequence_4 = { e8???????? 83c40c 8983b0010000 85c0 750a 6815060000 e9???????? }
+ $sequence_5 = { e8???????? 83c414 85c0 0f84e1010000 ff7518 8d4704 57 }
+ $sequence_6 = { eb07 c745fc00000000 8b5508 8b4204 3b45fc 7404 33c0 }
+ $sequence_7 = { 8b783c 037904 8b8610010000 8bef c1f808 896c2414 8807 }
+ $sequence_8 = { 8b4620 83c408 314500 8b4624 314504 8b4628 314648 }
+ $sequence_9 = { eb06 8b55f4 8955f0 b801000000 6bc800 8b55f0 0fbe040a }
condition:
- 7 of them and filesize <5777408
+ 7 of them and filesize <3743744
}
-rule MALPEDIA_Win_Ccleaner_Backdoor_Auto : FILE
+rule MALPEDIA_Win_Zebrocy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fc5d42e4-2b09-51e8-9476-e6d57b9f6fbe"
+ id = "ddee4b03-585f-5184-85a4-c6cc1e810bdc"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ccleaner_backdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ccleaner_backdoor_auto.yar#L1-L264"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zebrocy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zebrocy_auto.yar#L1-L161"
license_url = "N/A"
- logic_hash = "437c1ac4e0723d85ccca29c304bbc711ed3ae66fbe1eeb3f8d5172b567e72b6c"
+ logic_hash = "619394d96ac2748c82d29651fdad853561cf847222687873937db9b64b7f21e0"
score = 75
- quality = 73
+ quality = 75
tags = "FILE"
version = "1"
tool = "yara-signator v0.6.0"
@@ -180242,51 +187236,38 @@ rule MALPEDIA_Win_Ccleaner_Backdoor_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 57 ffd6 50 ff15???????? 8b3d???????? }
- $sequence_1 = { ff15???????? 8b3d???????? 59 ffd7 }
- $sequence_2 = { 750a b857000780 e9???????? e8???????? }
- $sequence_3 = { 01460c 488b3f 493bfc 0f8554ffffff }
- $sequence_4 = { 00cc cc 4883ec28 488b11 }
- $sequence_5 = { 49 75f9 ffd3 6800400000 }
- $sequence_6 = { ff75f0 ff15???????? 85c0 0f850c010000 8b35???????? 53 }
- $sequence_7 = { 01442424 eb30 8b4508 897518 }
- $sequence_8 = { 03c0 894340 8b7340 418bc4 }
- $sequence_9 = { 03c6 4863d0 4c8d0c12 4c8d4718 }
- $sequence_10 = { 03c6 85c0 7f09 488b0a 488b01 ff5008 488b4b28 }
- $sequence_11 = { 891d???????? 68???????? 6a03 53 68???????? ff742424 891d???????? }
- $sequence_12 = { 6a04 50 8d45e0 6a04 50 8d85e0feffff 50 }
- $sequence_13 = { c1e008 8d8418a1000000 50 e8???????? 85c0 7545 }
- $sequence_14 = { 012e 33c0 5f 5e 5d }
- $sequence_15 = { 00cc cc 4057 4883ec50 4533db }
- $sequence_16 = { 8b7df8 0faff8 ffd6 33f8 }
- $sequence_17 = { 01442454 03d1 294c2450 8b4c2410 }
- $sequence_18 = { 50 68???????? ff742418 ff15???????? 85c0 0f8579010000 }
- $sequence_19 = { c7471854b40210 c1e803 3bc1 7302 8bc8 6afd }
- $sequence_20 = { 3bc2 7661 89450c 8a06 46 50 e8???????? }
- $sequence_21 = { 013d???????? 8b04b5d8970210 0500080000 3bc8 }
- $sequence_22 = { 3b7d10 0f8264010000 3bfa 0f835c010000 2bda 8d4602 }
- $sequence_23 = { 013e 33c0 8b16 83c410 }
- $sequence_24 = { e8???????? 8b4510 59 f7d8 }
- $sequence_25 = { 01442418 03c8 8954242c 8b542470 }
- $sequence_26 = { 01461c 8b542424 85d2 7405 }
- $sequence_27 = { 01cc cc 48895c2408 57 }
- $sequence_28 = { 4c 8bca c1e002 4c 03d5 48 }
+ $sequence_0 = { 014158 11515c e8???????? dc6360 }
+ $sequence_1 = { 8bc6 33d2 66891478 8bc6 5f c3 8bff }
+ $sequence_2 = { 0103 83c41c 5b 5e }
+ $sequence_3 = { 83c438 68581b0000 ff15???????? 83bd00f7ffff08 8b85ecf6ffff 7306 8d85ecf6ffff }
+ $sequence_4 = { 8b7508 837e0800 7610 8b4608 8d808c994200 fe08 }
+ $sequence_5 = { 0110 8b7dd4 ba???????? 89470c }
+ $sequence_6 = { 0103 8b0e ba???????? e8???????? }
+ $sequence_7 = { 8b441a20 85c9 7f0d 7c05 83f801 7706 }
+ $sequence_8 = { 0102 8b45d4 89500c 89c1 }
+ $sequence_9 = { 014150 8b550c 115154 014158 }
+ $sequence_10 = { 0f8553010000 837de400 7c5d 7f04 85f6 }
+ $sequence_11 = { 0103 31d2 85ff 8b03 }
+ $sequence_12 = { 7303 8d45b8 8b4dc8 03c8 8bc6 83fa10 }
+ $sequence_13 = { 68???????? 6888000800 ff15???????? 8bf0 85f6 }
+ $sequence_14 = { 0110 5e 5f 5d }
+ $sequence_15 = { 3bc1 0f87c8090000 ff2485689c4100 33c0 838de8fdffffff }
condition:
- 7 of them and filesize <377856
+ 7 of them and filesize <393216
}
-rule MALPEDIA_Win_Fakeword_Auto : FILE
+rule MALPEDIA_Win_Kingminer_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dff35d24-3d8a-5dd3-be0c-60e6ee2ac528"
+ id = "13b82737-eb1a-51ab-9795-8340f262e7e5"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fakeword"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fakeword_auto.yar#L1-L122"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kingminer"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kingminer_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "ba7599fef3200798ceac9b8a2a397ab651b3acac17ae30ecdd8eedb5f787592d"
+ logic_hash = "f79d58fb6043de2ccd7faac7ea9ed3b2513556edb2a1cd9df8f496a155aebade"
score = 75
quality = 75
tags = "FILE"
@@ -180300,32 +187281,32 @@ rule MALPEDIA_Win_Fakeword_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 52 68???????? a3???????? 890d???????? c744240c10000000 c605????????11 c605????????22 }
- $sequence_1 = { eb03 8b7de8 8d14b6 893d???????? }
- $sequence_2 = { 7516 8b0a 8b6f34 25ff0f0000 03c3 03c1 }
- $sequence_3 = { 6a00 6a10 8d7e14 56 6a04 }
- $sequence_4 = { c684247603000031 754d 8d442454 8d8c2477030000 50 56 }
- $sequence_5 = { 03c3 89442410 8b4804 85c9 750b 8b480c }
- $sequence_6 = { 8b4701 8d4f09 8d743809 56 51 ff15???????? 83c408 }
- $sequence_7 = { 8d1c02 3bd9 72f1 c6040f00 }
- $sequence_8 = { b808000000 5e 83c440 c3 81fea1000000 7528 }
- $sequence_9 = { 57 33c0 85d2 7e19 8bca 8bf3 8be9 }
+ $sequence_0 = { a1???????? 885c30fe a1???????? 0fb64c30f9 884c30fc }
+ $sequence_1 = { ff15???????? 6a01 ff15???????? 6a00 ff15???????? 8b4508 }
+ $sequence_2 = { 83c40c 807c30ff62 8d4c30ff 0f8599010000 }
+ $sequence_3 = { ff15???????? 6a00 ff15???????? 8b80c0000000 85c0 7422 }
+ $sequence_4 = { 6a00 ff15???????? 6a00 ff15???????? 6a01 ff15???????? 6a00 }
+ $sequence_5 = { 3bf0 741e 68c1000000 ff15???????? 5b }
+ $sequence_6 = { ff15???????? a1???????? 50 ffd7 ff15???????? 6a01 ff15???????? }
+ $sequence_7 = { 6a04 6800100000 51 52 ffd0 83c414 85c0 }
+ $sequence_8 = { 8d4dec 51 8d580c 56 8bc7 c745ec89480489 }
+ $sequence_9 = { 8b95d0feffff 2b4234 7419 83b9a000000000 7466 50 }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <165888
}
-rule MALPEDIA_Win_Dexter_Auto : FILE
+rule MALPEDIA_Win_Longwatch_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5ebe4c09-da98-582c-8eed-df32a16fd066"
+ id = "9cbc3845-247e-5088-802c-974faf2556c3"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dexter"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.dexter_auto.yar#L1-L115"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.longwatch"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.longwatch_auto.yar#L1-L118"
license_url = "N/A"
- logic_hash = "88383a20a07c3308fad4494ea352148cf37f604e3e0c05d6e635ee453d38e768"
+ logic_hash = "f16a1609422dbff4c114599f67e44a3d80148789c090def0703b76643a40482b"
score = 75
quality = 75
tags = "FILE"
@@ -180339,32 +187320,32 @@ rule MALPEDIA_Win_Dexter_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 8b5508 83c201 895508 8d45f4 }
- $sequence_1 = { c705????????00000000 a1???????? 0305???????? 8945fc 8b4d0c }
- $sequence_2 = { eb17 837df400 7511 6a01 e8???????? }
- $sequence_3 = { 50 e8???????? 83c410 8b4df8 51 6a00 8b15???????? }
- $sequence_4 = { 7507 b801000000 eb0d 8b4dfc 83c101 }
- $sequence_5 = { 52 6a00 ff15???????? 68???????? 68???????? }
- $sequence_6 = { e8???????? 83c404 0fbed8 c1e304 }
- $sequence_7 = { 68e8030000 ff15???????? e9???????? 833d????????00 741e 8b0d???????? }
- $sequence_8 = { 8b5510 8a45f9 8802 8b4d10 83c101 }
- $sequence_9 = { 8b0d???????? 51 ff15???????? 6aff 8b15???????? }
+ $sequence_0 = { 68???????? e8???????? 83c404 833d????????ff 7546 6a00 }
+ $sequence_1 = { 8bec 53 8b5d08 33c9 57 33c0 8d3c9d2c074300 }
+ $sequence_2 = { 0f8cf8030000 68a1000000 ff15???????? 6683f888 0f8ce3030000 8d46fe }
+ $sequence_3 = { eb29 8b55d4 8a07 8b0c95a00b4300 }
+ $sequence_4 = { 53 8b5d08 33c9 57 33c0 8d3c9d2c074300 f00fb10f }
+ $sequence_5 = { 6bc618 57 8db874074300 57 }
+ $sequence_6 = { 8ad3 b9???????? e8???????? 837d9400 8db548ffffff }
+ $sequence_7 = { e8???????? ff7364 33c9 8d7b18 84c0 0f44f9 }
+ $sequence_8 = { 56 68a0000000 8bf1 ff15???????? }
+ $sequence_9 = { c74634d46e4200 6a00 57 8bce e8???????? }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <647168
}
-rule MALPEDIA_Win_Ragnarlocker_Auto : FILE
+rule MALPEDIA_Win_Pwndlocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e474a54c-f0e2-58cf-8fb5-f5efe389dd86"
+ id = "68fbdce5-97ba-5b4c-a728-8efe50c54b3b"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ragnarlocker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ragnarlocker_auto.yar#L1-L131"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pwndlocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pwndlocker_auto.yar#L1-L119"
license_url = "N/A"
- logic_hash = "0ce73fa8ff409c8b46cae101a5ed771c097f4c9fb16c4b873e6cf25053373d48"
+ logic_hash = "035ce763bc16632a928a77294057e290950a177cc8c2678dfab31b46c9b29c9e"
score = 75
quality = 75
tags = "FILE"
@@ -180378,32 +187359,32 @@ rule MALPEDIA_Win_Ragnarlocker_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 898df4feffff 894dc0 8b4f14 898decfeffff 894df8 8b4d0c 0fb601 }
- $sequence_1 = { 33f1 8b4de8 8bd0 2345d4 3355d4 2355c8 33d0 }
- $sequence_2 = { 0fb6c5 6a04 0bd0 0fb6c1 6800300000 c1e208 53 }
- $sequence_3 = { 039d28ffffff 13bd24ffffff 035d94 137d98 81c338b548f3 81d75bc25639 015df4 }
- $sequence_4 = { 0fa4ca17 c1ee09 c1e117 0bda 8b55dc 0bf1 8b4de0 }
- $sequence_5 = { 8bfa 8b4dd4 8bf1 337de8 3375f4 237dac 2355e8 }
- $sequence_6 = { 897dfc 8bbd34ffffff 8bf7 8bcf c1e618 0facd108 }
- $sequence_7 = { 3375ec 8b55e8 2355c0 2375d4 33fa 8b4df4 234dec }
- $sequence_8 = { 03c3 8945b8 13cf 33ff 894de0 }
- $sequence_9 = { c1e108 0bc8 0fb64604 c1e108 0bc8 894b14 0f114318 }
+ $sequence_0 = { c1cf0d 01c7 ebf4 3b7df0 75e0 5a }
+ $sequence_1 = { 01d8 83c078 8b00 8d3403 8b4e18 }
+ $sequence_2 = { c1cf0d 01c7 ebf4 3b7df0 }
+ $sequence_3 = { ebf4 3b7df0 75e0 5a 8b7224 01de 31c0 }
+ $sequence_4 = { 31ff 31c0 fc ac 84c0 7407 }
+ $sequence_5 = { c1cf0d 01c7 ebf4 3b7df0 75e0 5a 8b7224 }
+ $sequence_6 = { 01de 31ff 31c0 fc }
+ $sequence_7 = { 668b044e 8b721c 01de 8b0486 }
+ $sequence_8 = { fc ac 84c0 7407 c1cf0d 01c7 ebf4 }
+ $sequence_9 = { 01da 56 e334 49 8d348a }
condition:
- 7 of them and filesize <147456
+ 7 of them and filesize <65536
}
-rule MALPEDIA_Win_Plurox_Auto : FILE
+rule MALPEDIA_Win_Roopy_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "6592f7da-a1c0-54df-8b9b-d6d4f0de3577"
+ id = "18fd31da-7cad-5b5e-9e3e-b0b112556109"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.plurox"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.plurox_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.roopy"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.roopy_auto.yar#L1-L127"
license_url = "N/A"
- logic_hash = "2767330918862f71924876620bde24f2504b741e0c74e8fbd24789f747d1fbb9"
+ logic_hash = "6efa923735d84ae0bbc14d021be45ac1298053ce08c8f542f6e92d8a3dac3a28"
score = 75
quality = 75
tags = "FILE"
@@ -180417,32 +187398,32 @@ rule MALPEDIA_Win_Plurox_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 90 f9 0925???????? 0000 }
- $sequence_1 = { 1a6e00 0000 94 624a8b 0416 }
- $sequence_2 = { 6f b804000000 4e 4f b84e4f3dd9 }
- $sequence_3 = { 94 f8 21480e 2a15???????? 6f b804000000 }
- $sequence_4 = { e9???????? e408 6873d30808 94 e519 e8???????? 0000 }
- $sequence_5 = { 8918 43 0416 0a20 0816 ec bbf2000000 }
- $sequence_6 = { 8a00 46 0c83 47 }
- $sequence_7 = { 624a8b 0416 128bc606091a f6870f1a000000 e10d }
- $sequence_8 = { 07 f3cf 6b0000 0025???????? 7171 6805245f07 40 }
- $sequence_9 = { 64841a 6c 2432 3449 }
+ $sequence_0 = { 8d45d8 30c9 6631d2 e8???????? 6a00 8b45ec 8945c0 }
+ $sequence_1 = { 89e5 8da42478fdffff 53 56 8945fc }
+ $sequence_2 = { 68???????? 64ff30 648920 8d431c 8b55fc e8???????? 89d8 }
+ $sequence_3 = { 85db 7403 8b40fc 3d04010000 0f8e91000000 89da }
+ $sequence_4 = { e9???????? 8d8decfeffff 8d95a0fcffff b810010000 e8???????? e8???????? }
+ $sequence_5 = { c745f800000000 c7859cfeffff00000000 c78598feffff00000000 c78594feffff00000000 c78578fdffff00000000 c7857cfdffff00000000 c78580fdffff00000000 }
+ $sequence_6 = { e8???????? 6a00 a1???????? 8945d8 }
+ $sequence_7 = { 30d2 e8???????? 6a00 8d45e4 e8???????? 6a00 a1???????? }
+ $sequence_8 = { e8???????? 8d8d8cfcffff 6631d2 8d8570fbffff e8???????? 8d858cfcffff 30c9 }
+ $sequence_9 = { 8b45dc 8d70ff f745e401000000 740d f745dcffffffff 0f856fffffff 8b45f0 }
condition:
- 7 of them and filesize <475136
+ 7 of them and filesize <739328
}
-rule MALPEDIA_Win_Lazarloader_Auto : FILE
+rule MALPEDIA_Win_Laturo_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "eeec4f28-0f22-51be-ae2e-de44f3255986"
+ id = "a099051d-06cc-5747-80aa-ce74001854da"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lazarloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lazarloader_auto.yar#L1-L124"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.laturo"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.laturo_auto.yar#L1-L179"
license_url = "N/A"
- logic_hash = "2c7bcf20b8b4c12e652b091953d52f7cafa589f18b8b9e18e7eefdba4a60b648"
+ logic_hash = "5c5686ac498628ddacc2bb584f3ee57bf281fd85acd0c0e6dfbd3f9934f8bef4"
score = 75
quality = 75
tags = "FILE"
@@ -180456,32 +187437,38 @@ rule MALPEDIA_Win_Lazarloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 483b0d???????? 7417 488d059c4f0100 483bc8 }
- $sequence_1 = { 7528 48833d????????00 741e 488d0d30a80100 e8???????? 85c0 740e }
- $sequence_2 = { 8bc2 488d154241ffff c1e803 89442438 448be0 89442440 85c0 }
- $sequence_3 = { 488d0563810000 488bd9 483bc8 7417 8b815c010000 }
- $sequence_4 = { 4889542410 48894c2408 57 4881ece0080000 33c0 66898424a0000000 488d8424a2000000 }
- $sequence_5 = { 4c8bea 4b8b8cf770c10100 4c8b15???????? 4883cfff 418bc2 498bd2 4833d1 }
- $sequence_6 = { 8bcf e8???????? 488bd7 4c8d05fecd0000 83e23f 488bcf 48c1f906 }
- $sequence_7 = { 48897018 48897820 4156 33ed 4c8d35e6900000 448bd5 488bf1 }
- $sequence_8 = { e8???????? 488bd7 4c8d05fecd0000 83e23f }
- $sequence_9 = { 488bda 4c8d0d6bad0000 8bf9 488d15a2930000 b906000000 }
+ $sequence_0 = { 486bc038 488b0d???????? 8b440120 c1e01e c1f81f 3b442450 741a }
+ $sequence_1 = { e8???????? 33db 8bf8 85c0 0f8453020000 4c8d2dea040100 }
+ $sequence_2 = { 884814 0fb644243c 83f805 7511 0fb6442405 83e001 85c0 }
+ $sequence_3 = { 48837c242000 7432 488b442430 4839442420 720c }
+ $sequence_4 = { 488d0d13800100 33c0 8b542420 f00fb111 85c0 742c 48837c242820 }
+ $sequence_5 = { 4c8d34c0 49c1fc06 4a8b84e1f0a50100 4a8b44f028 488945bf }
+ $sequence_6 = { 488b09 448b0481 33d2 b95a000000 ff15???????? }
+ $sequence_7 = { 4883f9fd 7706 ff15???????? 488364243000 488d0dfc7b0000 8364242800 41b803000000 }
+ $sequence_8 = { 8bc2 8955e4 c1e802 8bf2 8b55f0 83e603 }
+ $sequence_9 = { b803000000 50 68???????? ff763c e8???????? 83c40c 85c0 }
+ $sequence_10 = { 7510 46 83c028 3bf2 }
+ $sequence_11 = { 8a4dfe 84c0 8a45ff 7909 }
+ $sequence_12 = { 53 ff15???????? 50 ff15???????? 834f1406 8b15???????? 8b4df4 }
+ $sequence_13 = { 6bd730 8b0c8d30430110 c644112800 85f6 740c 56 e8???????? }
+ $sequence_14 = { 8945fc ff15???????? 85c0 7460 c603e9 8b4704 2bc3 }
+ $sequence_15 = { 83feff 0f8432010000 57 6a01 83caff 8d4de8 }
condition:
- 7 of them and filesize <364544
+ 7 of them and filesize <253952
}
-rule MALPEDIA_Win_Campoloader_Auto : FILE
+rule MALPEDIA_Win_Thumbthief_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "00b62c88-0d38-56b9-90a5-7c85290ffbe9"
+ id = "37aaa405-1531-5214-b674-b08465e47533"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.campoloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.campoloader_auto.yar#L1-L116"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thumbthief"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.thumbthief_auto.yar#L1-L134"
license_url = "N/A"
- logic_hash = "dae472a7090c99e8a9ce136356f9bc867c42c508ecb59c9f6aa0187832a15e3c"
+ logic_hash = "f526be6ecad90c989de9ad949776796071b33db6ed80435843c6bf3aac7a3492"
score = 75
quality = 75
tags = "FILE"
@@ -180495,32 +187482,32 @@ rule MALPEDIA_Win_Campoloader_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83ec1c a1???????? 33c5 8945fc a1???????? 8945e4 }
- $sequence_1 = { 898d58efffff c78584efffff00000000 8d55f4 52 8b8558efffff 50 }
- $sequence_2 = { ff15???????? ff15???????? 8b8584efffff 8b4dfc 33cd e8???????? }
- $sequence_3 = { 8b9584efffff 039574efffff c60200 8b450c }
- $sequence_4 = { ff15???????? 898550efffff 0fb78554efffff 50 }
- $sequence_5 = { 038d8cefffff 898d74efffff e9???????? 8b9584efffff 039574efffff c60200 8b450c }
- $sequence_6 = { ff15???????? 8945f8 68???????? 8b45fc 50 }
- $sequence_7 = { 6a01 6a00 6a00 6800000040 8b4510 }
- $sequence_8 = { 8b8558efffff 50 8d8df0feffff 51 }
- $sequence_9 = { 8b8d70efffff 51 8b9584efffff 52 ff15???????? }
+ $sequence_0 = { e9???????? 689c000000 b8???????? e8???????? 33db 8d4db4 895dec }
+ $sequence_1 = { f6431002 0f85e1000000 85f6 0f44f3 89758c b800040000 66854310 }
+ $sequence_2 = { ffb58cfeffff 8d8d30ffffff e8???????? 8d8de0feffff 807def00 7408 ffb5acfeffff }
+ $sequence_3 = { f20f1085ecfeffff 8d8574ffffff 51 51 f20f110424 50 8d85f4feffff }
+ $sequence_4 = { e8???????? c645fc02 8d8d58ffffff e8???????? c645fc03 8d8d18ffffff e8???????? }
+ $sequence_5 = { bf48030000 8d85a4fcffff 57 6a00 50 e8???????? 83c40c }
+ $sequence_6 = { eb77 68???????? eb70 68???????? eb69 8bc3 2d04130400 }
+ $sequence_7 = { ff75f8 85c0 743c ff75f4 ba07000000 8bcf e8???????? }
+ $sequence_8 = { e8???????? b8???????? e9???????? 8d4ddc e9???????? 8d4dbc e9???????? }
+ $sequence_9 = { ff15???????? 8b4704 5f 85c0 740a 894508 5d }
condition:
- 7 of them and filesize <66560
+ 7 of them and filesize <4235264
}
-rule MALPEDIA_Win_Interception_Auto : FILE
+rule MALPEDIA_Win_Astralocker_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f1a298d5-70e2-5f27-b6ee-691574cd9abf"
+ id = "0d5879c8-ffd6-54eb-8701-3a0bd5bd2437"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.interception"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.interception_auto.yar#L1-L118"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.astralocker"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.astralocker_auto.yar#L1-L121"
license_url = "N/A"
- logic_hash = "3520af3329a4b24d818d777e1e8f70b92d9cafa69a1f58bf6db64da9ed00530f"
+ logic_hash = "04cf0865e55d3f7d37324f7ff4a5b3ef42183f756ec3ed69d17a248a6814ecfc"
score = 75
quality = 75
tags = "FILE"
@@ -180534,32 +187521,32 @@ rule MALPEDIA_Win_Interception_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 83e61f 8d1c8520ae0010 c1e603 8b03 f644300401 7469 57 }
- $sequence_1 = { 72f1 56 8bf1 c1e603 3b96e8710010 }
- $sequence_2 = { c1f805 83e61f 8d1c8520ae0010 c1e603 8b03 }
- $sequence_3 = { ffb6ec710010 8d8560ffffff 50 e8???????? 6810200100 8d8560ffffff }
- $sequence_4 = { 8bd0 c1f905 83e21f 8b0c8d20ae0010 f644d10401 }
- $sequence_5 = { 8d3c8520ae0010 c1e603 8b07 03c6 f6400401 7437 }
- $sequence_6 = { f683c19c001004 7406 8816 46 }
- $sequence_7 = { 8d542434 f3ab 66ab aa }
- $sequence_8 = { 8bc8 83e01f c1f905 8b0c8d20ae0010 8a44c104 }
- $sequence_9 = { 731c 8bc8 83e01f c1f905 8b0c8d20ae0010 f644c10401 8d04c1 }
+ $sequence_0 = { 8b5508 8b440a04 50 8b0c0a 51 e8???????? }
+ $sequence_1 = { 83c102 894dfc 837dfc0a 0f83dc000000 8b55fc 8b4508 }
+ $sequence_2 = { 6bc20a 8b4d08 33d2 33f6 891401 }
+ $sequence_3 = { 6bc20a 8b4d08 33d2 33f6 }
+ $sequence_4 = { 8b440a04 50 8b0c0a 51 e8???????? 83c408 8945ec }
+ $sequence_5 = { 894dfc 837dfc0a 0f83dc000000 8b55fc 8b4508 8b4cd004 }
+ $sequence_6 = { 8b4508 8b4cd004 51 8b14d0 52 e8???????? }
+ $sequence_7 = { 33c0 33f6 89040a 89740a04 }
+ $sequence_8 = { ba08000000 6bc20a 8b4d08 33d2 33f6 891401 89740104 }
+ $sequence_9 = { 33c0 33f6 89040a 89740a04 c745fc00000000 eb09 }
condition:
- 7 of them and filesize <98304
+ 7 of them and filesize <191488
}
-rule MALPEDIA_Win_Moure_Auto : FILE
+rule MALPEDIA_Win_Hotwax_Auto : FILE
{
meta:
description = "autogenerated rule brought to you by yara-signator"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d5ea53f7-d6a1-5284-9152-98034607f388"
+ id = "34df7b39-b5de-5d0e-aea3-1ec834745896"
date = "2023-12-06"
modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moure"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moure_auto.yar#L1-L126"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hotwax"
+ source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.hotwax_auto.yar#L1-L123"
license_url = "N/A"
- logic_hash = "e394b210e6ac1eaa6569608ddb349d4dd1ae50231f20d0924074c460f1fa6782"
+ logic_hash = "f7aa59232edd43ba4670389edd9f2f755cdf2f70e16334cd9db9000bdc1ab730"
score = 75
quality = 75
tags = "FILE"
@@ -180573,12723 +187560,11775 @@ rule MALPEDIA_Win_Moure_Auto : FILE
malpedia_sharing = "TLP:WHITE"
strings:
- $sequence_0 = { 3454 43 1558c950cb 0d487b0d4c 36a373801f1e }
- $sequence_1 = { bf55602540 006b05 bc7d506700 0033 58 bf35b8bf55 58 }
- $sequence_2 = { 8b35???????? 57 00d6 0075f0 894508 0075fc 00d6 }
- $sequence_3 = { 51 51 8b0d???????? 56 33f6 85c9 7509 }
- $sequence_4 = { 837dbc00 7436 0075bc 8d4ddc e8???????? a1???????? 3bc6 }
- $sequence_5 = { 82a8a200b000c1 8b00 e100 9e d28bd3977e8d 98 }
- $sequence_6 = { 68b0704000 007014 007010 e8???????? }
- $sequence_7 = { 5e 53 43 c1c361 5b c9 51 }
- $sequence_8 = { 8b01 83e03f 3c02 751c 8b4514 8b10 83e23f }
- $sequence_9 = { 42 c3 874226 c58035b4fe70 5e }
+ $sequence_0 = { 7e74 817d0063736de0 7528 48833d????????00 741e 488d0d5dee0000 }
+ $sequence_1 = { 488bd7 ff15???????? 418d8770050000 4489bdcc040000 c745a400080000 8945a0 }
+ $sequence_2 = { 4889842410030000 488bf9 488d8c2401020000 33d2 41b803010000 c684240002000000 }
+ $sequence_3 = { 488bd9 4885c0 7479 488d0d7fe50000 483bc1 746d 488b8310010000 }
+ $sequence_4 = { 4533db 488d9424f0000000 41b803010000 44895c2440 4c895c2448 ff15???????? 833d????????00 }
+ $sequence_5 = { 486bd258 490394c1a04b0100 f6423880 742c }
+ $sequence_6 = { 488bcb 488905???????? ff15???????? 488d1547d20000 488bcb 488905???????? ff15???????? }
+ $sequence_7 = { cc 4c8d05f8530000 498bd4 488bcd e8???????? 85c0 }
+ $sequence_8 = { 488b0d???????? eb7c 4c8d256a830000 488b0d???????? eb6c e8???????? }
+ $sequence_9 = { 488d0d50bf0000 ba01000000 e8???????? 4c8d442440 }
+
+ condition:
+ 7 of them and filesize <198656
+}
+/*
+ * YARA Rule Set
+ * Repository Name: Trellix ARC
+ * Repository: https://github.com/advanced-threat-research/Yara-Rules/
+ * Retrieval Date: 2024-09-01
+ * Git Commit: fc51a3fe3b450838614a5a5aa327c6bd8689cbb2
+ * Number of Rules: 162
+ * Skipped: 0 (age), 5 (quality), 0 (score), 0 (importance)
+ *
+ *
+ * LICENSE
+ *
+ * Apache License
+ Version 2.0, January 2004
+ http://www.apache.org/licenses/
+
+ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
+
+ 1. Definitions.
+
+ "License" shall mean the terms and conditions for use, reproduction,
+ and distribution as defined by Sections 1 through 9 of this document.
+
+ "Licensor" shall mean the copyright owner or entity authorized by
+ the copyright owner that is granting the License.
+
+ "Legal Entity" shall mean the union of the acting entity and all
+ other entities that control, are controlled by, or are under common
+ control with that entity. For the purposes of this definition,
+ "control" means (i) the power, direct or indirect, to cause the
+ direction or management of such entity, whether by contract or
+ otherwise, or (ii) ownership of fifty percent (50%) or more of the
+ outstanding shares, or (iii) beneficial ownership of such entity.
+
+ "You" (or "Your") shall mean an individual or Legal Entity
+ exercising permissions granted by this License.
+
+ "Source" form shall mean the preferred form for making modifications,
+ including but not limited to software source code, documentation
+ source, and configuration files.
+
+ "Object" form shall mean any form resulting from mechanical
+ transformation or translation of a Source form, including but
+ not limited to compiled object code, generated documentation,
+ and conversions to other media types.
+
+ "Work" shall mean the work of authorship, whether in Source or
+ Object form, made available under the License, as indicated by a
+ copyright notice that is included in or attached to the work
+ (an example is provided in the Appendix below).
+
+ "Derivative Works" shall mean any work, whether in Source or Object
+ form, that is based on (or derived from) the Work and for which the
+ editorial revisions, annotations, elaborations, or other modifications
+ represent, as a whole, an original work of authorship. For the purposes
+ of this License, Derivative Works shall not include works that remain
+ separable from, or merely link (or bind by name) to the interfaces of,
+ the Work and Derivative Works thereof.
+
+ "Contribution" shall mean any work of authorship, including
+ the original version of the Work and any modifications or additions
+ to that Work or Derivative Works thereof, that is intentionally
+ submitted to Licensor for inclusion in the Work by the copyright owner
+ or by an individual or Legal Entity authorized to submit on behalf of
+ the copyright owner. For the purposes of this definition, "submitted"
+ means any form of electronic, verbal, or written communication sent
+ to the Licensor or its representatives, including but not limited to
+ communication on electronic mailing lists, source code control systems,
+ and issue tracking systems that are managed by, or on behalf of, the
+ Licensor for the purpose of discussing and improving the Work, but
+ excluding communication that is conspicuously marked or otherwise
+ designated in writing by the copyright owner as "Not a Contribution."
+
+ "Contributor" shall mean Licensor and any individual or Legal Entity
+ on behalf of whom a Contribution has been received by Licensor and
+ subsequently incorporated within the Work.
+
+ 2. Grant of Copyright License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ copyright license to reproduce, prepare Derivative Works of,
+ publicly display, publicly perform, sublicense, and distribute the
+ Work and such Derivative Works in Source or Object form.
+
+ 3. Grant of Patent License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ (except as stated in this section) patent license to make, have made,
+ use, offer to sell, sell, import, and otherwise transfer the Work,
+ where such license applies only to those patent claims licensable
+ by such Contributor that are necessarily infringed by their
+ Contribution(s) alone or by combination of their Contribution(s)
+ with the Work to which such Contribution(s) was submitted. If You
+ institute patent litigation against any entity (including a
+ cross-claim or counterclaim in a lawsuit) alleging that the Work
+ or a Contribution incorporated within the Work constitutes direct
+ or contributory patent infringement, then any patent licenses
+ granted to You under this License for that Work shall terminate
+ as of the date such litigation is filed.
+
+ 4. Redistribution. You may reproduce and distribute copies of the
+ Work or Derivative Works thereof in any medium, with or without
+ modifications, and in Source or Object form, provided that You
+ meet the following conditions:
+
+ (a) You must give any other recipients of the Work or
+ Derivative Works a copy of this License; and
+
+ (b) You must cause any modified files to carry prominent notices
+ stating that You changed the files; and
+
+ (c) You must retain, in the Source form of any Derivative Works
+ that You distribute, all copyright, patent, trademark, and
+ attribution notices from the Source form of the Work,
+ excluding those notices that do not pertain to any part of
+ the Derivative Works; and
+
+ (d) If the Work includes a "NOTICE" text file as part of its
+ distribution, then any Derivative Works that You distribute must
+ include a readable copy of the attribution notices contained
+ within such NOTICE file, excluding those notices that do not
+ pertain to any part of the Derivative Works, in at least one
+ of the following places: within a NOTICE text file distributed
+ as part of the Derivative Works; within the Source form or
+ documentation, if provided along with the Derivative Works; or,
+ within a display generated by the Derivative Works, if and
+ wherever such third-party notices normally appear. The contents
+ of the NOTICE file are for informational purposes only and
+ do not modify the License. You may add Your own attribution
+ notices within Derivative Works that You distribute, alongside
+ or as an addendum to the NOTICE text from the Work, provided
+ that such additional attribution notices cannot be construed
+ as modifying the License.
+
+ You may add Your own copyright statement to Your modifications and
+ may provide additional or different license terms and conditions
+ for use, reproduction, or distribution of Your modifications, or
+ for any such Derivative Works as a whole, provided Your use,
+ reproduction, and distribution of the Work otherwise complies with
+ the conditions stated in this License.
+
+ 5. Submission of Contributions. Unless You explicitly state otherwise,
+ any Contribution intentionally submitted for inclusion in the Work
+ by You to the Licensor shall be under the terms and conditions of
+ this License, without any additional terms or conditions.
+ Notwithstanding the above, nothing herein shall supersede or modify
+ the terms of any separate license agreement you may have executed
+ with Licensor regarding such Contributions.
+
+ 6. Trademarks. This License does not grant permission to use the trade
+ names, trademarks, service marks, or product names of the Licensor,
+ except as required for reasonable and customary use in describing the
+ origin of the Work and reproducing the content of the NOTICE file.
+
+ 7. Disclaimer of Warranty. Unless required by applicable law or
+ agreed to in writing, Licensor provides the Work (and each
+ Contributor provides its Contributions) on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+ implied, including, without limitation, any warranties or conditions
+ of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
+ PARTICULAR PURPOSE. You are solely responsible for determining the
+ appropriateness of using or redistributing the Work and assume any
+ risks associated with Your exercise of permissions under this License.
+
+ 8. Limitation of Liability. In no event and under no legal theory,
+ whether in tort (including negligence), contract, or otherwise,
+ unless required by applicable law (such as deliberate and grossly
+ negligent acts) or agreed to in writing, shall any Contributor be
+ liable to You for damages, including any direct, indirect, special,
+ incidental, or consequential damages of any character arising as a
+ result of this License or out of the use or inability to use the
+ Work (including but not limited to damages for loss of goodwill,
+ work stoppage, computer failure or malfunction, or any and all
+ other commercial damages or losses), even if such Contributor
+ has been advised of the possibility of such damages.
+
+ 9. Accepting Warranty or Additional Liability. While redistributing
+ the Work or Derivative Works thereof, You may choose to offer,
+ and charge a fee for, acceptance of support, warranty, indemnity,
+ or other liability obligations and/or rights consistent with this
+ License. However, in accepting such obligations, You may act only
+ on Your own behalf and on Your sole responsibility, not on behalf
+ of any other Contributor, and only if You agree to indemnify,
+ defend, and hold each Contributor harmless for any liability
+ incurred by, or claims asserted against, such Contributor by reason
+ of your accepting any such warranty or additional liability.
+
+ END OF TERMS AND CONDITIONS
+
+ APPENDIX: How to apply the Apache License to your work.
+
+ To apply the Apache License to your work, attach the following
+ boilerplate notice, with the fields enclosed by brackets "[]"
+ replaced with your own identifying information. (Don't include
+ the brackets!) The text should be enclosed in the appropriate
+ comment syntax for the file format. We also recommend that a
+ file or class name and description of purpose be included on the
+ same "printed page" as the copyright notice for easier
+ identification within third-party archives.
+
+ Copyright [yyyy] [name of copyright owner]
+
+ Licensed under the Apache License, Version 2.0 (the "License");
+ you may not use this file except in compliance with the License.
+ You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing, software
+ distributed under the License is distributed on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ See the License for the specific language governing permissions and
+ limitations under the License.
+
+ */
+private rule TRELLIX_ARC_Ransom_Xinof_Chunk_PRIVATE : RANSOMWARE
+{
+ meta:
+ description = "Detect chunk of Xinof ransomware"
+ author = "Thomas Roccia | McAfee ATR Team"
+ id = "243c39fd-b5f6-5f64-8058-43da182480c0"
+ date = "2020-11-20"
+ date = "2020-11-20"
+ modified = "2020-11-20"
+ reference = "https://labs.sentinelone.com/the-fonix-raas-new-low-key-threat-with-unnecessary-complexities/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_xinof.yar#L1-L51"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "0c1e6299a2392239dbe7fead33ef4146"
+ logic_hash = "f0266962357a7cb26995cdbfcc99749b73fc4ed09c813fa8e2ed0f5143cde554"
+ score = 75
+ quality = 70
+ tags = "RANSOMWARE"
+ rule_version = "v1"
+ malware_type = "ransomware"
+ malware_family = "Ransom/XINOF"
+ actor_type = "Cybercrime"
+ actor_group = "FONIX"
+
+ strings:
+ $chunk1 = {
+ C6 45 ?? ??
+ 68 ?? ?? ?? ??
+ 50
+ E8 ?? ?? ?? ??
+ 53
+ 50
+ 8D 85 ?? ?? ?? ??
+ C6 45 ?? ??
+ 50
+ E8 ?? ?? ?? ??
+ 56
+ 50
+ 8D 85 ?? ?? ?? ??
+ C6 45 ?? ??
+ 50
+ E8 ?? ?? ?? ??
+ 83 C4 ??
+ C6 45 ?? ??
+ 8B CC
+ 57
+ 50
+ 51
+ E8 ?? ?? ?? ??
+ 83 C4 ??
+ 8D 8D ?? ?? ?? ??
+ E8 ?? ?? ?? ??
+ 83 C4 ??
+ 8D 8D ?? ?? ?? ??
+ E8 ?? ?? ?? ??
+ }
+
+ condition:
+ any of them
+}
+rule TRELLIX_ARC_Apt_Blackenergy_Pdb : TROJAN FILE
+{
+ meta:
+ description = "Rule to detect the BlackEnergy trojan"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "55c96b66-a8bf-5390-a75a-f3d2441c2a55"
+ date = "2013-02-15"
+ modified = "2020-08-14"
+ reference = "https://www.kaspersky.com.au/resource-center/threats/blackenergy"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_blackenergy_pdb.yar#L1-L38"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "4b2efcda5269f4b80dc417a2b01332185f2fafabd8ba7114fa0306baaab5a72d"
+ logic_hash = "7bb85d03d8f2a4d91554f7fea96e9bbe36b153cfa4a91fd13fb99d41d430c9e9"
+ score = 75
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/BlackEngergy"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
+
+ strings:
+ $s1 = "msiexec.exe /i \"%s\" %s REBOOT=\"ReallySuppress\"" fullword wide
+ $s2 = "InstallUpdate: CreateProcess failed, Cmdline=%s Error=%d ." fullword wide
+ $s3 = "Portuguese=Instalando o Tempo de Execu" fullword wide
+ $s4 = "Initialization: Failed to initialize - Unable to get Upgrade Code." fullword wide
+ $s5 = "This version of Internet Explorer is not supported. You should upgrade Internet Explorer to version %s and run setup again. Se" wide
+ $s6 = "Initialization: Failed to open %s file, Make sure the file is not used by another process." fullword wide
+ $s7 = "o %s e execute a configura" fullword wide
+ $s8 = "Initialization: Failed to initialize - Unable to get Product Version." fullword wide
+ $s9 = "f:\\CB\\11X_Security\\Acrobat\\Installers\\BootStrapExe_Small\\Release\\Setup.pdb" fullword ascii
+ $s10 = "BootStrap.log" fullword wide
+ $s11 = "ACDownloaderDlg" fullword ascii
+ $s12 = "Initialization: Failed to initialize Product - msi key not specified." fullword wide
+ $s13 = "rio atualizar para o Service Pack %s e executar a instala" fullword wide
+ $s14 = "\\Msi.dll" fullword wide
+
+ condition:
+ uint16(0)==0x5a4d and filesize <2000KB and all of them
+}
+rule TRELLIX_ARC_Hermeticwiper : TROJAN FILE
+{
+ meta:
+ description = "Detecting variants of Hermetic Wiper malware discovered in UA"
+ author = " cb @ Trellix ATR"
+ id = "fc6d9238-b732-541d-b083-11b43fe8770d"
+ date = "2022-02-24"
+ modified = "2022-02-24"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Troj_HermWiper.yar#L1-L27"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "b48e91afa19e09c7035ccda1b9293448e834d612b9a953b593f9412acb78faac"
+ score = 75
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "Trojan"
+
+ strings:
+ $0 = {E4B5518CD941310A015E4AF8E5968C8231492FE19246A293A569D5D7A36F56EB2FC5B68FFF6F3359C19AF6806920C3FE6628F90A75440E6616297A031BA6075100D72DFAA9829E772E45D77B89F862081EAFDB19B4B2DCEF3F273FF645ACCEAA4B991F98373973C0FB25829E860D9BC195EF1A0AD9219456AD077D42868EE03EE00E88D04C434BA97E88DF99273A35E2C668A1C69954B4762390ABDFBE4CD4AF}
+ $1 = {90506F1C825F7AE0D8605F5C627CA325BFF199AB60A63DE8A90E923F4B18D7FB039E1DEC89D573AAB0A14C1D4BA70EB444753A41C03082A60CB4DB551393F2C50988A3181E7F31D01B5AAD94070432D98F18655AB8A555919FEFEA9DE1EDF1}
+ $2 = {D5EEF61336015A85FF04ED298A6BDD6742FF153E33DAF9B383A5FFDCE7E64D47748DB5FF2609DF9BD5C66735FF6916797B2D365313FF1461EAEB9DAEA754FF6D4D55D1956CC8CBFF75C10CE74BF88C8DFF3B553B839D42609FFF2916227230}
+ $3 = {6C750DDC932124500CE9B5AB91CE101BE9AD348220E9423124512282373675152281023428825C51770FE9841F853375125382F732750A5B83F60FEB6AEE2282647462228269745AEE22826F7452228275744AEE2282787442}
+ $4 = {19A8A063FFAAAF6C1E7F78A896FFFA5C8F30BA98B69CFF1961E107BEB7636AFF9EA56A4FC4EDE3F1FF295235ACD0185726FFADA6B8CB54B342C9FF86F58524DC91617BFFB4388DBE01B6CF86}
+ $5 = {50C449606B20184A6328556032197660AAF9507861609F6160640560B4546160C3A194056070C4A09EC4A01A0461A4C4A0831B16600561916069A291607061C09160AA1CB6204A}
+ $6 = {FFEB19D2636B8B95273156BB63E8C78470D55970F47CF26574B46DE86EE084704590CA8053F15320258BBD1AACF18B04F2E965C6605CB10880B7E8FCF53DF5EB0621635EFF}
+ $7 = {7E31126E14B8FF98554F6FCFB64207FFCF8D93B2573609C2FF99E4409F73BB9322FF1E5E380DC0BBABCAFF4B901EDF61BD6A68FFEE3253728C7769ABFF7BCDA939C959A282}
+ $8 = {1970FFC6F8AA7C32EE693CFF369579E5355EF62CFF682CEAF20BA3EA1CFF1AAC638666431B20FF54293D1E709C231AFFCD11B55599F64CB9FF1E5A9015DC867F}
+ $9 = {8DFF93B2573609C299E4FF409F73BB93221E5EFF380DC0BBABCA4B90FF1EDF61BD6A68EE32FF53728C7769AB7BCDFFA939C959A282D312FF5DD04F0370CE811F}
+ $10 = {DF5519064E31101CF3DA96C15FF96728B708F358F51759E3A22FFA1CF1BB986A2038D6753E6BF037945B8469ADF20BAB71E10F3DE27735F640704C970DFE8672}
condition:
- 7 of them and filesize <188416
+ uint16(0)==0x5a4d and filesize <200KB and all of them
}
-rule MALPEDIA_Win_Tarsip_Auto : FILE
+rule TRELLIX_ARC_APT_Acidbox_Kernelmode_Module : KERNELDRIVER FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4ad2adc0-f292-5e9b-b3e6-4bd61bcff987"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tarsip"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tarsip_auto.yar#L1-L122"
- license_url = "N/A"
- logic_hash = "228c42e725c96bb3ed688957a36bb59d0b21035a6d52aae02eb400f7262ce8f7"
+ description = "Rule to detect the kernel mode component of AcidBox"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "80b60307-5431-5f21-9e6f-06adaab0519d"
+ date = "2020-07-24"
+ modified = "2020-08-14"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_acidbox.yar#L1-L32"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "e39da89d0da22115ac7889bc73ff183973a6c5334e304df955362bde76694d42"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "KERNELDRIVER, FILE"
+ rule_version = "v1"
+ malware_type = "kerneldriver"
+ malware_family = "Rootkit:W32/Acidbox"
+ actor_type = "APT"
+ actor_group = "Turla"
+ hash1 = "3ef071e0327e7014dd374d96bed023e6c434df6f98cce88a1e7335a667f6749d"
strings:
- $sequence_0 = { 8884244f840000 e8???????? 8d94240c840000 52 }
- $sequence_1 = { ff15???????? 89ae14420100 8b8610420100 3bc5 }
- $sequence_2 = { ff15???????? 898614420100 85c0 754f }
- $sequence_3 = { 80fa2f 7505 b83f000000 8d148500000000 8b442420 c1fa02 c1e106 }
- $sequence_4 = { ff15???????? 5b 33c0 5e c3 57 6a00 }
- $sequence_5 = { 8b08 038ea4830000 8b54240c 8a02 8801 }
- $sequence_6 = { e8???????? 50 e8???????? e8???????? 99 b980841e00 }
- $sequence_7 = { e8???????? 83c404 c746180f000000 895e14 885e04 8b4c240c 64890d00000000 }
- $sequence_8 = { 8b442418 0374241c 53 8d542418 52 53 53 }
- $sequence_9 = { 83bc240c01000010 7210 8b9424f8000000 52 e8???????? 83c404 c784240c0100000f000000 }
+ $pattern_0 = { 897c2434 8978b8 8d5f28 448bc3 33d2 }
+ $pattern_1 = { 4c8d842470010000 488d942418010000 498bcf e8???????? 8bd8 89442460 }
+ $pattern_2 = { 4c8bf1 49d1eb 4585c9 0f88a2000000 440fb717 498bd0 }
+ $pattern_3 = { ff15???????? 4c8d9c2480000000 498b5b10 498b7318 498b7b20 4d8b7328 498be3 }
+ $pattern_4 = { 33d2 41b8???????? 895c2420 e8???????? }
+ $pattern_5 = { 895c2420 4885ff 0f8424010000 440f20c0 84c0 0f8518010000 }
+ $pattern_6 = { 85f6 0f8469fdffff 488d8424c8010000 41b9???????? }
+ $pattern_7 = { 894c2404 750a ffc7 893c24 41ffc3 ebcb 85c9 }
+ $pattern_8 = { 488b5c2450 488b742458 488b7c2460 4883c430 }
+ $pattern_9 = { 33d2 488b4c2428 e8???????? 448b842450040000 4503c0 4c8d8c2450040000 488bd7 }
condition:
- 7 of them and filesize <360448
+ 7 of them and filesize <78848
}
-rule MALPEDIA_Win_Tinyloader_Auto : FILE
+rule TRELLIX_ARC_APT_Acidbox_Main_Module_Dll : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0d2fde25-ff7d-54ba-a2fe-e20fb626403d"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinyloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tinyloader_auto.yar#L1-L168"
- license_url = "N/A"
- logic_hash = "544c827393b5f9a7c28206644605d3c060467a9b94170d9210a95463f44b3867"
+ description = "Rule to detect the Main mode component of AcidBox"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "8c9beb0f-62f7-5788-8340-0b1ecdf54253"
+ date = "2020-07-24"
+ modified = "2020-08-14"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_acidbox.yar#L34-L65"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "db98e204742b8629074d47df301ffcbb2dfb977a4da91557fb50838aae79e777"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Acidbox"
+ actor_type = "APT"
+ actor_group = "Turla"
+ hash1 = "eb30a1822bd6f503f8151cb04bfd315a62fa67dbfe1f573e6fcfd74636ecedd5"
strings:
- $sequence_0 = { 90 8bbb97114000 90 8938 90 }
- $sequence_1 = { 6689c8 90 6a40 6800300000 6800800200 6a00 }
- $sequence_2 = { 039d58080000 6a00 6800040000 53 ffb5b8050000 ff15???????? }
- $sequence_3 = { 31db 90 31c9 90 }
- $sequence_4 = { 8b5510 01da 8b12 8b4500 }
- $sequence_5 = { 81c300040000 6a00 ff33 ff7500 ffb5b8050000 ff15???????? 83f8ff }
- $sequence_6 = { 8b4500 83c008 c70000000000 c7855808000000000000 8b5d00 039d58080000 }
- $sequence_7 = { 83bd580800000c 7302 ebc3 8b5d00 }
- $sequence_8 = { ff15???????? 8985b8050000 6832a00000 ff15???????? 8b9da8050000 66894302 66c7030200 }
- $sequence_9 = { 90 89c6 90 0500400100 }
- $sequence_10 = { ffb5a0050000 6802020000 ff15???????? 6a06 6a01 6a02 ff15???????? }
- $sequence_11 = { c705????????00010000 68???????? 68???????? ff15???????? 68???????? ff15???????? }
- $sequence_12 = { 6a10 ffb5a8050000 ffb5b8050000 ff15???????? }
- $sequence_13 = { 81fb04030000 730c 90 83c004 }
- $sequence_14 = { 31c9 90 3108 90 813890909090 }
- $sequence_15 = { 637574 6541 0050ff 15???????? c705????????00010000 68???????? 68???????? }
+ $pattern_0 = { 7707 b8022d03a0 eb05 e8???????? }
+ $pattern_1 = { 4403c8 8bc3 41d1c6 33c6 81c6d6c162ca c1cb02 33c7 }
+ $pattern_2 = { e9???????? 412b5c2418 8b45dc 412b442408 41015c241c 410144240c 015f1c }
+ $pattern_3 = { 48895c2408 57 4883ec30 488bfa 33db 4885c9 7479 }
+ $pattern_4 = { 48895c2408 57 4883ec30 498bd8 488bfa 488364245800 85c9 }
+ $pattern_5 = { 488987e0010000 e9???????? 81cb001003a0 e9???????? 488b87a0010000 44847806 742e }
+ $pattern_6 = { 4d8bcc 4c8d0596c50100 498bd4 488bce e8???????? 498b9de0010000 c74605aa993355 }
+ $pattern_7 = { 4533c0 8d5608 e8???????? 488bf0 4889442460 4885c0 750b }
+ $pattern_8 = { 488d5558 41c1ee08 41b802000000 44887559 e8???????? 4c8b4de0 894718 }
+ $pattern_9 = { 4d03c2 4d3bc2 4d13cc 4d0303 4d3b03 4d8903 4c8b13 }
condition:
- 7 of them and filesize <40960
+ 7 of them and filesize <550912
}
-rule MALPEDIA_Win_Blacklotus_Auto : FILE
+rule TRELLIX_ARC_APT_Acidbox_Ssp_Dll_Module : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "84ef9a0b-6544-5450-8b66-292ec2ba5dbd"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blacklotus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.blacklotus_auto.yar#L1-L123"
- license_url = "N/A"
- logic_hash = "94ccc2d7ff61cb6463b78893aadb2549c584433629bcbab33ca8298790f40cde"
+ description = "Rule to detect the SSP DLL component of AcidBox"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "ef1511c5-f650-5e65-937c-466f00932183"
+ date = "2020-07-24"
+ modified = "2020-08-14"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_acidbox.yar#L67-L98"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "4c9b9de11d73587ca1ad1efa5455598e41edc5a9a59fc0339c429a212c1c7941"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Acidbox"
+ actor_type = "APT"
+ actor_group = "Turla"
+ hash1 = "003669761229d3e1db0f5a5b333ef62b3dffcc8e27c821ce9018362e0a2df7e9"
strings:
- $sequence_0 = { 443bca 7319 69c03f000100 4883c102 4103c0 41ffc1 440fb701 }
- $sequence_1 = { c745cfc1afbd03 c745d301138a6b c745d73a911141 c745db4f67dcea c745df97f2cfce }
- $sequence_2 = { 448bc6 488d155b1d0000 488bcb e8???????? 488bf0 }
- $sequence_3 = { 770b 418b4908 03ca 413bcb 770e 6641ffc2 4983c128 }
- $sequence_4 = { 42883c10 4183fb3c 0f8c45ffffff 498d8af0000000 41b810000000 498bd6 }
- $sequence_5 = { 488d1588f7ffff e8???????? 488b05???????? 488bcb ff5020 488b5c2430 488b742438 }
- $sequence_6 = { 4632440c30 eb1b 418af1 83f804 }
- $sequence_7 = { 4889442428 4c8bc5 488bd3 48897c2420 }
- $sequence_8 = { 740b 4883c602 483bf7 72bd eb0c bb03000000 eb05 }
- $sequence_9 = { 48897010 48897818 4c897020 55 488d68c8 4881ec30010000 4c8bd1 }
+ $pattern_0 = { 49897ba0 8bc7 49894398 49897ba8 33c9 49894bb0 }
+ $pattern_1 = { 8b8424a8000000 c1e818 88443108 66895c310a 498b0e }
+ $pattern_2 = { 8b5f48 413bdd 410f47dd 85db 0f84f1000000 488b4720 4885c0 }
+ $pattern_3 = { e8???????? 85c0 78c7 488d9424a0020000 488d8c24e0030000 ff15???????? 4c8bf8 }
+ $pattern_4 = { ff15???????? 488bc8 4c8bc6 33d2 ff15???????? 8bfb 895c2420 }
+ $pattern_5 = { 415f c3 4c8bdc 49895b10 }
+ $pattern_6 = { 488d842488010000 4889442420 41bf???????? 458bcf 4c8bc7 418bd7 488d8c2490000000 }
+ $pattern_7 = { c1e908 0fb6c9 3bce 77b6 8bd0 b9???????? c1ea10 }
+ $pattern_8 = { 4c8bc3 ba???????? 488d4c2438 e8???????? 89442430 85c0 7508 }
+ $pattern_9 = { bb02160480 8bc3 488b5c2440 488b742448 488b7c2450 4883c430 }
condition:
- 7 of them and filesize <181248
+ 7 of them and filesize <199680
}
-rule MALPEDIA_Win_Unidentified_105_Auto : FILE
+rule TRELLIX_ARC_Apt_Babar_Malware : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "80a8f5ec-0d23-5074-b907-8dcd99006ffb"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_105"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_105_auto.yar#L1-L114"
- license_url = "N/A"
- logic_hash = "03b63f792ccab1aa0e70284622fef7dcf74ab6cde5a0b9206fdbab8d689a2bd1"
+ description = "Rule to detect Babar malware"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "3cbb63ce-ff93-51ee-93aa-2594fa1f8dad"
+ date = "2015-02-18"
+ modified = "2020-08-14"
+ reference = "http://motherboard.vice.com/read/meet-babar-a-new-malware-almost-certainly-created-by-france"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_babar_pdb.yar#L1-L35"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "c72a055b677cd9e5e2b2dcbba520425d023d906e6ee609b79c643d9034938ebf"
+ logic_hash = "02acef92691caed4573b609c111302427b9c27c5ef93f9199c52d75cb13e8615"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 45
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Babar"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 85c0 0f95c0 84c0 742c }
- $sequence_1 = { 8bf8 8d4f02 b856555555 f7e9 8bc2 c1e81f 03c2 }
- $sequence_2 = { 6a00 8d8dd0feffff 51 8d95fcfeffff }
- $sequence_3 = { 8d8d94feffff 51 6800000010 50 52 ff15???????? 85c0 }
- $sequence_4 = { e8???????? 83c404 50 e8???????? a1???????? 6800020000 }
- $sequence_5 = { 83f8ff 7459 8d9424a0010000 52 }
- $sequence_6 = { 68???????? 56 e8???????? 8bc6 83c454 }
- $sequence_7 = { 8bf8 8d4f02 b856555555 f7e9 8bc2 }
- $sequence_8 = { 8b3d???????? 8d45e4 50 33f6 }
- $sequence_9 = { 6800100000 8d85f8efffff 50 51 }
+ $s1 = "c:\\Documents and Settings\\admin\\Desktop\\Babar64\\Babar64\\obj\\DllWrapper Release\\Release.pdb" fullword ascii
+ $s2 = "%COMMON_APPDATA%" fullword ascii
+ $s3 = "%%WINDIR%%\\%s\\%s" fullword ascii
+ $s4 = "/s /n %s \"%s\"" fullword ascii
+ $s5 = "/c start /wait " fullword ascii
+ $s6 = "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\" fullword ascii
+ $s7 = "constructor or from DllMain." fullword ascii
+ $s8 = "ComSpec" fullword ascii
+ $s9 = "APPDATA" fullword ascii
+ $s10 = "WINDIR" fullword ascii
+ $s11 = "USERPROFILE" fullword ascii
condition:
- 7 of them and filesize <253952
+ uint16(0)==0x5a4d and filesize <2000KB and all of them
}
-rule MALPEDIA_Win_Rook_Auto : FILE
+rule TRELLIX_ARC_Apt_Mirage_Pdb : TROJAN FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "18a58274-365f-5d90-8056-28a56db76f76"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rook"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rook_auto.yar#L1-L129"
- license_url = "N/A"
- logic_hash = "8b05af9f0d6f5102cdf2e062676438cba9dcdb9d6b25adc560d5025ee81a7b52"
+ description = "Rule to detect Mirage samples based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "49b7623f-a2c9-52e4-8679-d62f6aae99ca"
+ date = "2012-09-18"
+ modified = "2020-08-14"
+ reference = "https://www.secureworks.com/research/the-mirage-campaign"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_mirage_pdb.yar#L1-L26"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "0107a12f05bea4040a467dd5bc5bd130fd8a4206a09135d452875da89f121019"
+ logic_hash = "cb88dc787d9964451ea93f5574d9c73ae6a820d81e20d41c3c8ee44c3fee032d"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/Mirage"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 488d05478d0200 c7470801000000 48c7471003000000 48894748 488d05c59e0200 }
- $sequence_1 = { 0f8521ffffff 44882b eb7b 488b9540070000 4c8d05979e0000 498bce }
- $sequence_2 = { 85c0 0f85f5020000 488b8d08080000 488d85f8070000 4c89a424c0080000 488d15ffb90400 }
- $sequence_3 = { ff15???????? 488bd3 488d0d82ac0400 448bc0 e8???????? 488b0d???????? 4c8bc3 }
- $sequence_4 = { 4433d0 418bc1 48c1e808 0fb6c8 41c1e208 420fb6843170990500 4433d0 }
- $sequence_5 = { 488d85f8070000 4c89a424c0080000 488d15ffb90400 4889442428 4c8d25d3450500 4c89ac24b8080000 }
- $sequence_6 = { 488d542460 488d0d1c380500 e8???????? 488d9510020000 498bcc ff15???????? 4839bd10020000 }
- $sequence_7 = { 48894760 488d0535980200 c7475001000000 48c7475804000000 48894778 488d050b710300 c7476801000000 }
- $sequence_8 = { 4898 4d8d3446 83ed01 7586 4885f6 0f84d3000000 488bce }
- $sequence_9 = { 4c8d05f7140300 488986b0000000 488d8e98000000 e8???????? 8bd8 85c0 0f8517ffffff }
+ $pdb = "\\MF-v1.2\\Server\\Debug\\Server.pdb"
+ $pdb1 = "\\fox_1.2 20110307\\MF-v1.2\\Server\\Release\\MirageFox_Server.pdb"
condition:
- 7 of them and filesize <843776
+ uint16(0)==0x5a4d and filesize <150KB and any of them
}
-rule MALPEDIA_Win_Cryptomix_Auto : FILE
+rule TRELLIX_ARC_Apt_Auriga_Driver : KERNELDRIVER FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9865a2c1-f352-5196-8a74-a585373e6231"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptomix"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cryptomix_auto.yar#L1-L173"
- license_url = "N/A"
- logic_hash = "2b59fc336b11257878a1c3e0c2e35ea57cb53b57126b62f006b040ede13bda6d"
+ description = "Rule to detect the Auriga driver"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "b61058a1-1b48-5be1-ba2f-74a7c3d38825"
+ date = "2013-03-13"
+ modified = "2020-08-14"
+ reference = "https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_auriga_biscuit.yar#L1-L39"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "207eee627a76449ac6d2ca43338d28087c8b184e7b7b50fdc60a11950c8283ec"
+ logic_hash = "c027073ba398fe89d418be67f0850c8d9e4d4c50a991c45b84cdb416497ccf1c"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "KERNELDRIVER, FILE"
+ rule_version = "v1"
+ malware_type = "kerneldriver"
+ malware_family = "Driver:W32/Auriga"
+ actor_type = "APT"
+ actor_group = "APT1"
strings:
- $sequence_0 = { c3 68f0767c2a 6a04 e8???????? 59 59 }
- $sequence_1 = { 02f8 0fb6cf 8d7601 0fb60439 8846ff 881439 33c9 }
- $sequence_2 = { e8???????? 59 eb03 8b5df0 ff75f8 e8???????? }
- $sequence_3 = { 7504 6a08 eb35 83f804 }
- $sequence_4 = { ff4d08 8b4dfc 8ad8 75cc 5f }
- $sequence_5 = { 59 59 ffd0 83f87a 7413 56 57 }
- $sequence_6 = { 56 683f000f00 56 56 56 53 57 }
- $sequence_7 = { ffd0 c3 686ea4ffa5 6a05 }
- $sequence_8 = { ffd6 85c0 0f856a010000 68???????? 8d85c4f9ffff }
- $sequence_9 = { 837d0c01 8bbdb8f9ffff a1???????? 68???????? }
- $sequence_10 = { 68???????? 57 ffd0 ff75fc e8???????? }
- $sequence_11 = { 8bf1 6a01 899584efffff 89b58cefffff 898588efffff ff15???????? 6808020000 }
- $sequence_12 = { 8d85c4f9ffff 50 ffd7 85c0 7460 68???????? }
- $sequence_13 = { 8b35???????? 68007d0000 6a40 c745f8e8030000 }
- $sequence_14 = { 6a00 6a00 ff15???????? 6896000000 ff15???????? 8b9d80efffff 8d8598f9ffff }
- $sequence_15 = { 68???????? 56 e8???????? 59 59 85c0 7759 }
+ $s1 = "\\SystemRoot\\System32\\netui.dll" fullword wide
+ $s2 = "\\SystemRoot\\System32\\drivers\\riodrv32.sys" fullword wide
+ $s3 = "\\SystemRoot\\System32\\arp.exe" fullword wide
+ $s4 = "netui.dll" fullword ascii
+ $s5 = "riodrv32.sys" fullword wide
+ $s6 = "\\netui.dll" fullword wide
+ $s7 = "d:\\drizt\\projects\\auriga\\branches\\stone_~1\\server\\exe\\i386\\riodrv32.pdb" fullword ascii
+ $s8 = "\\riodrv32.sys" fullword wide
+ $s9 = "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\riodrv32" fullword wide
+ $s10 = "\\DosDevices\\rio32drv" fullword wide
+ $s11 = "e\\Driver\\nsiproxy" fullword wide
+ $s12 = "(C) S3/Diamond Multimedia Systems. All rights reserved." fullword wide
+ $s13 = "\\Device\\rio32drv" fullword wide
+ $s14 = "\\Registry\\Machine\\SOFTWARE\\riodrv" fullword wide
+ $s15 = "\\Registry\\Machine\\SOFTWARE\\riodrv32" fullword wide
condition:
- 7 of them and filesize <188416
+ uint16(0)==0x5a4d and filesize <50KB and all of them
}
-rule MALPEDIA_Win_Graphical_Neutrino_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Pwnlnx_Backdoor_Variant_1 : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b16102ee-c7a4-5abc-870b-b75814e7493c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphical_neutrino"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graphical_neutrino_auto.yar#L1-L123"
- license_url = "N/A"
- logic_hash = "650397c4d3167e6ec1c66b8947fe66982f57b8190e3a878616091180b7325b66"
+ description = "Rule to detect the backdoor pwnlnx variant 1"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "5b76ca62-460c-5c36-a239-700cc509f2b0"
+ date = "2020-04-17"
+ modified = "2020-08-14"
+ reference = "https://www.blackberry.com/content/dam/blackberry-com/asset/enterprise/pdf/direct/report-bb-decade-of-the-rats.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_decade_of_RATs.yar#L3-L33"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "0f6033d6f82ce758b576e2d8c483815e908e323d0b700040fbdab5593fb5282b"
+ logic_hash = "1487890494dde891a6dbe7dff7ebd5660ee01fe10220215e680115f168c2ae4a"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Pwnlnx"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 4489c7 4889f2 48c7410800000000 4531c0 4889d9 4c8d6c2450 e8???????? }
- $sequence_1 = { ff15???????? 4883fe10 7f1c 41b828400000 }
- $sequence_2 = { 48c78424c800000002000000 48898424c0000000 e8???????? 4c8da424c0000000 488d842460050000 48c78424c800000002000000 }
- $sequence_3 = { eb07 b001 80fa09 7478 }
- $sequence_4 = { 8806 488d4602 885601 eb2d b964000000 }
- $sequence_5 = { 53 4883ec20 4c8b6108 4889cb 4c3b6110 740f }
- $sequence_6 = { ebcc 31db 4c89ea 4c89e1 4189de ffc3 }
- $sequence_7 = { 7430 c605????????01 31c0 8a1403 881406 48ffc0 4883f81f }
- $sequence_8 = { 4155 4154 53 4883ec20 c60100 4889cb 4989d5 }
- $sequence_9 = { bd07000000 eb32 41b9a0860100 bd06000000 eb25 41b910270000 bd05000000 }
+ $bp = { 7F??4C4602??01??000000000000000002??3E????0000????1A????0000000040000000000000??????0000000000000000000040??????????????1D????????0000????????????000000000000??????4000000000??????4000000000????01??00000000????01??00000000????000000000000????0000??????0000????000000000000????4000000000000002????000000001C??0000000000001C??00000000000001??00000000000001??000005????????0000000000000000??????0000000000004000000000????76??00000000????76??000000000000????00000000????0000????0000000080????00000000????????????0000????????????000038??00000000000080??????00000000000020??0000000002??0000060000????80????0000000028??????????000028??????????0000A0????????0000????????????0000????000000000000??????000004??00001C??0000000000001C??4000000000??????4000000000????000000000000????000000000000??????00000000000050E5??6404??00009C6D0000000000009C6D4000000000??????????????0000DC??000000000000DC??00000000000004??00000000000051E5??64??000000000000000000000000000000000000000000000000000000000000000000000000000000000000????000000000000????6C69????????????2D????????78??78??362D????????6F2E32??04??000010??000001??0000474E5500000000????0000????0000????000000000000????0000??????000001??000006000000000000????000020??0000??????00007D??5A580000000000000000000000000000000000000000000000000000000015????????00000000000000000000??????00000000000082????????00000000000000000000????????????0000????????????00000000000000000000????????????0000??????000012??0000000000000000000062??0000000000006A??000012??000000000000000000001B??0000000000007E??000012??000000000000000000008B??0000000000004902??????00000000000000000000????????????0000????????????00000000000000000000????????00000000??????000012??000000000000000000008E??000000000000F401??????00000000000000000000????????????0000????????????00000000000000000000????000000000000????01??????00000000000000000000????????????0000????0000????000000000000000000000000000000000000????0000????000000000000000000000000000000000000??????000012??0000000000000000000025????????0000????????????00000000000000000000????000000000000????0000????00000000000000000000????000000000000????01??????00000000000000000000????????????0000????0000????00000000000000000000????000000000000????02??????00000000000000000000????????????0000????01??????00000000000000000000??????0000000000006602??????00000000000000000000????????????0000??????000012??0000000000000000000025????????0000????01??????00000000000000000000????000000000000????????????00000000000000000000????000000000000????01??????00000000000000000000????000000000000????0000????00000000000000000000????01??00000000????????????00000000000000000000????????????0000????????????00000000000000000000??????000000000000EC01??????00000000000000000000??????0000000000004B01??????00000000000000000000????????????0000??????000012??0000000000000000000025????????0000????01??????00000000000000000000????????????0000??????000012??0000000000000000000008??0000000000004302??????00000000000000000000????????????0000??????????????000000000000000000000A??0000000000003F01??????00000000000000000000????????????0000??????000012??00000000000000000000F0????00000000????01??????00000000000000000000??????????????00002F02??????00000000000000000000????01??00000000????????????00000000000000000000????000000000000??????????????0000000000000000000080????00000000????02??????00000000000000000000????000000000000??????000012??0000000000000000000074??000000000000BF????????00000000000000000000????????????0000????02??????00000000000000000000??????000000000000FA0000????00000000000000000000????????????0000??????000012??0000000000000000000011??000000000000A8??000012??0000000000000000000044000000000000??????000012??000000000000000000005A000000000000??????000012??0000000000000000000029??000000000000C6????????00000000000000000000????000000000000????????????00000000000000000000????000000000000????0000????00000000000000000000????????00000000????????????00000000000000000000??????000000000000BC????????00000000000000000000????02??00000000????01??????00000000000000000000??????00000000000034??000012??00000000000000000000A1????????0000????????????00000000000000000000????????????0000??????????????000000000000000000004B000000000000????0000????00000000000000000000????000000000000??????000012??0000000000000000000005????????0000??????000012??0000000000000000000031??00000000000074??000012??00000000000000000000FF??0000000000005E02??????00000000000000000000????000000000000????????????00000000000000000000????????????0000??????000012??0000000000000000000025????????0000????02??????00000000000000000000??????000000000000DE??000012??000000000000000000007B??00000000000030??000012??0000000000000000000075??000000000000D9??000012??000000000000000000000E000000000000????????????00000000000000000000????000000000000????02??????00000000000000000000????????????0000????????????00000000000000000000????????????0000????????????00000000000000000000????000000000000????02??????00000000000000000000????000000000000????01??????00000000000000000000????????????0000????????????00000000000000000000????000000000000????????????00000000000000000000??????0000000000005201??????0000????174000000000????00000000000000005F5F676D6F6E5F73??6172??5F5F??????76??52656769????????????6173??6573??6C69????????????61642E????2E30??72??63????72??6D??????68????????5F63????6174????????6E6474????????75??65??????69??????????????6E6F5F6C6F63????69????????????6B????74??72??6164??73??676D6173????????6E6E6563??????74??72??6164??73??6C66??????63????74??70??68????????5F6465????63????6663????6C????????63??73??2E????????63????74??73??72??70????????69????????????????????616E64??????6574??6174??6E??????74??77??69??????????????6469????????????5F6E74??61??????74??72??69??????????????70??????????6D6F6E????????74??6E??????6C6563??????6B????????72??616C6C6F63??676574??69??????????????73??72??6F6B????63????77????????70??6173??72??3634??73??67656D70??79??6574??6D656D73??74??72??6469??????????????????6565??????68????????6173??74??6D65??????74??6F63????70????????616E74??74??6475??32??73??67616464????74??69????????????6472??6663??????65??????74??6F63????70????????6C6C6F63??73??72??6174??72??616C70??74????????6D6F76????????656E6469????????????6C??????74??6F73??62????616D65??????6563??????????72??74????????656164??????6C6F63????74??6C6F63????74??6D65??????616E6469????????????616464??????????????6565????73??74??69????????????????????6D6D6F76????????70??6E3634??5F5F6C69????????????72??5F6D6169????????????73??73??70??69????????????65????????78??74??74??34??474C4942435F32??32??35????????42435F32??33??000002??02??02??03??02??02??02??03??03??02??02??02??0000000002??02??02??02??02??03??02??02??02??02??02??02??02??02??03??02??02??02??04??02??02??03??02??03??02??02??02??03??02??02??02??02??02??03??02??02??02??02??02??02??03??02??02??03??02??02??02??03??02??03??02??03??02??02??02??02??02??02??03??03??03??02??02??02??02??02??000001??01??24??000010??000020??000075??69??????????9602??00000000????????????????????000000000000????69????????????A2????????0000??????69??????????9602??00000000????81????????????060000????????????000000000000????81????????????070000????00000000000000000000????81????????????070000????00000000000000000000????81????????????070000????00000000000000000000000082??????0000????0000??????0000000000000000000008??????????0000070000????????????000000000000????82??????0000????0000????00000000000000000000????82??????0000????0000????00000000000000000000????82??????0000????0000????00000000000000000000????82??????0000????0000????00000000000000000000????82??????0000????0000????00000000000000000000????82??????0000????0000????00000000000000000000??????6000000000????0000??????000000000000000000004882??????0000????0000????00000000000000000000??????6000000000????0000????00000000000000000000??????6000000000????0000????00000000000000000000??????6000000000????0000????00000000000000000000??????6000000000????0000????00000000000000000000??????6000000000????0000?????? }
condition:
- 7 of them and filesize <674816
+ uint16(0)==0x457f and filesize <100KB and all of them
}
-rule MALPEDIA_Win_Floxif_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Pwnlnx_Backdoor_Variant_2 : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dcbc6afb-5640-594e-8001-abd00982f671"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.floxif"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.floxif_auto.yar#L1-L126"
- license_url = "N/A"
- logic_hash = "0032adeaefefb80d7e1e935d3a462c453aec0c986c2f0bdf2924a1a8da50b164"
+ description = "Rule to detect the backdoor pwnlnx variant 2"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "c4ee686b-49d9-5566-b749-1144a19c1fee"
+ date = "2020-04-17"
+ modified = "2020-08-14"
+ reference = "https://www.blackberry.com/content/dam/blackberry-com/asset/enterprise/pdf/direct/report-bb-decade-of-the-rats.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_decade_of_RATs.yar#L35-L65"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "08cc67002782cbafd97a4bff549d25dd72d6976d2fdf79339aaf5a3ff7c3107e"
+ logic_hash = "08ea40ba72677263a41f62097fc38040361ba595d67cb04979b66548c7f4d271"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Pwnlnx"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { e8???????? 8945fc 837dfc02 7709 c745f401000000 eb09 8b45fc }
- $sequence_1 = { 3955f4 0f83c9000000 68???????? e8???????? }
- $sequence_2 = { 8b55fc c70200000000 8b45fc c7401000000000 8b45fc 8be5 }
- $sequence_3 = { c645e500 c645e6e1 c645e700 c645e87d c645e973 c645ea7a c645eb30 }
- $sequence_4 = { c645e500 c645e6bb c645e700 c645e828 c645e92b c645ea23 }
- $sequence_5 = { 7505 e9???????? 837dd800 7406 837dd805 7502 eb92 }
- $sequence_6 = { 83ec14 894df8 8b45f8 8b4808 }
- $sequence_7 = { ebaa 8d4d08 e8???????? 3945fc 7526 8d4d18 e8???????? }
- $sequence_8 = { 8b55fc 837a0400 7507 e8???????? eb11 8b4dfc e8???????? }
- $sequence_9 = { e8???????? e8???????? 83c410 eb44 83ec10 8bcc 8d5508 }
+ $bp = { 7F??4C4602??01??000000000000000002??3E????0000000004??00000000??????00000000000088????????????00000000??????38??05????????????????0000????????????0000000000000000??????0000000000004000000000??????0D??????????????0D????????0000????00000000????0000????0000????????????0000????????????0000????????????0000????12??00000000????????????00000000????00000000??????000004??00005801??00000000??????4000000000??????4000000000????????00000000????????00000000??????000000000000070000??????000080??????0000000080??????0000000080??????0000000028??00000000000070??00000000000008??00000000000051E5??64??000000000000000000000000000000000000000000000000000000000000000000000000000000000000????000000000000??????000010??000001??0000474E5500000000????0000????0000????0000??????000014??000003??0000474E55????????????CC78??78??83????????????CB371F0000000080??????0000000025????????0000????7E??00000000????????????0000????????????0000??????4200000000????????????0000????????????0000????????????0000????????????0000????????????0000????????????0000????????????0000????????????0000????????????0000????????????0000????????????0000??????4200000000????????????0000????????????0000??????4200000000????????????0000????????????0000????????????0000????76??00000000????????????0000????8B????00000000C8??????0000000025????????0000??????4200000000????76??00000000????????????0000????444200000000????76??00000000????????????0000??????4900000000????76??00000000????????????0000??????4600000000????76??00000000????????????0000????424200000000??????EC08??33??0000E8????????E8????????4883????C3FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????00000000000000000000000000000000000000000000000031??4989??5E4889??4883????505449C7??????????48C7??????????48C7??????????E8????????F490904883????488B??????????4885??74??FF??4883????C390909090909090909090909090554889??534883????80????????????75??BB????????488B??????????4881??????????48C1????4883????4839??73??660F1F??????4883????4889??????????FF????????????488B??????????4839??72??B8????????4885??74??BF????????E8????????C6????????????4883????5BC9C30F1F????????????55B8????????4885??4889??74??BE????????BF????????E8????????4883????????????74??B8????????4885??74??BF????????C9FF??0F1F??????????C9C39090554889??534881??????????89??????????48C7????????????8B????3D????????0F87????????8B????89??488D??????????8B??????????4889??89??E8????????85??0F84????????8B????89??488D??????????89??4889??E8????????BA????????488D??????????4889??4889??E8????????4889????4883??????0F84????????488D??????????488D??????????4889??4889??E8????????85??0F85????????488B??????????4889????C7????????????488B????89????488B????48C1????89????488B????4889????488B????4889??????488B????4889??????E8????????89????BE????????488D????E8????????488D????8B??????????BA????????4889??89??E8????????85??0F84????????488D????8B??????????BA????????4889??89??E8????????85??0F84????????BE????????488D????E8????????8B????488B????4889????488B????4889??????488B????4889??????E8????????39??0F85????????8B????89??4889??48C1????8B????89??488D????4889????488B????488B????BA????????4889??4889??E8????????488B????4889????EB??488B????488D??????????4889??BA????????BE????????4889??E8????????89????83??????7E??8B????488D??????????89??4889??E8????????8B????4863??488D??????????8B??????????4889??89??E8????????85??74??8B????48984801????488B????483B????7C??EB??90EB??90EB??90EB??90EB??90EB??90488B????4889??E8????????EB??90EB??90EB??90B8????????4881??????????5BC9C3554889??534881??????????4889??????????E8????????4889??E8????????C7????????????488B??????????8B????89????488B??????????8B??89????488B??????????8B????89????8B????8B????BA????????89??89??E8????????89????83??????0F84????????488D????BA????????BE????????4889??E8????????C7????????????C7????????????8B????89????488B????4889????488B????4889??????488B????4889??????E8????????89????488D????BE????????4889??E8????????488D????8B????BA????????4889??89??E8????????85??0F84????????488D??????????4889??E8????????488D??????????BE????????4889??E8????????488D??????????8B????BA????????4889??89??E8????????85??0F84????????488D????8B????BA????????4889??89??E8????????85??74??488D????BE????????4889??E8????????8B????488B????4889????488B????4889??????488B????4889??????E8????????39??75??8B????83????75??8B????488B????4889????488B????4889??????488B????4889??????89??E8????????EB??90EB??90EB??90EB??90EB??908B????89??E8????????B8????????4881??????????5BC9C390554889??4889????89????C7????????????488B????4889????C7????????????EB??488B????0FB6??8B????89??C1????F7????89??48980FB6??????????89??31??488B????88??83??????4883??????8B????3B????7C??488B????C9C3554889??4889????89????488B????4889????C7????????????EB??488B????0FB6??0FB6??????????31??488B????88??83??????4883??????8B????3B????7C??488B????C9C39090554889??534881??????????89??????????48C7????????????48C7????????????48C7????????????8B????89??488D??????????8B??????????4889??89??E8????????85??0F84????????8B????89??488D??????????89??4889??E8????????488D??????????488D??????????4889??4889??E8????????BA????????488D??????????488D??????????BE????????4889??B8????????E8????????488D??????????4889??E8????????4883????4889??E8????????4889????4883??????0F84????????488D??????????488B????4889??4889??E8????????488D??????????488D????B9????????BA????????4889??4889??E8????????89????83??????0F8E????????C7????????????E9????????488B????8B????4863??48C1????4801??488B??488D????BA????????488D??????????488D??????????4989??BE????????4889??B8????????E8????????488D??????????488D??????????4889??4889??E8????????85??0F85????????48C7????????????48C7????????????488D??????????4883????4889??E8????????4889??E8????????488B??????????8B??????????4189??4181??????????8B??????????89??81??????????488B????8B????4863??48C1????4801??488B??488D????BA????????488D??????????4889??????4889??????488B????4889??????488B????4889????4589??4189??4889??BE????????4889?? }
condition:
- 7 of them and filesize <352256
+ uint16(0)==0x457f and filesize <1000KB and all of them
}
-rule MALPEDIA_Win_Buzus_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Pwnlnx_Backdoor_Variant_3 : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "abeb46d7-6b5d-534d-9d29-46b219047b43"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.buzus"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.buzus_auto.yar#L1-L130"
- license_url = "N/A"
- logic_hash = "4ce965d715abb7623aae188d8dd7527d9c7207cb501cc27ac457187efef652e0"
+ description = "Rule to detect the backdoor pwnlnx variant"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "02ea1eb2-7235-5ed5-86ba-19d52e8fb428"
+ date = "2020-04-17"
+ modified = "2020-08-14"
+ reference = "https://www.blackberry.com/content/dam/blackberry-com/asset/enterprise/pdf/direct/report-bb-decade-of-the-rats.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_decade_of_RATs.yar#L67-L97"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "08f29e234f0ce3bded1771d702f8b5963b144141727e48b8a0594f58317aac75"
+ logic_hash = "8a1405f430ce57810577f65ef43a1425601bf49b5adb4f6f935505427ad9dc94"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Pwnlnx"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 5d 7413 68???????? 50 ffd6 3bc3 a3???????? }
- $sequence_1 = { 4e 46 897508 ebbd 803e2a 750b 83f801 }
- $sequence_2 = { ff75c0 ff75bc 50 e8???????? 83c40c 83f801 0f85e4000000 }
- $sequence_3 = { e8???????? 8d8554fdffff 50 8d85ccfdffff 50 68???????? }
- $sequence_4 = { 68???????? 6a01 56 68???????? 33ff 8975f0 8975f4 }
- $sequence_5 = { 50 ff15???????? be???????? 8d84242c280000 }
- $sequence_6 = { 898524ffffff 8b45bc 89850cffffff 8b45d8 898514ffffff 6bc03c 6a31 }
- $sequence_7 = { 385802 750e 0fbe5001 c68415b0feffff01 eb28 80fa2d 7539 }
- $sequence_8 = { 6a03 58 8945b8 6a3c 59 3bc1 7603 }
- $sequence_9 = { 68???????? 50 ff7508 e8???????? 83c41c 8b45d4 68b80b0000 }
+ $bp = { 7F??4C4602??01??000000000000000002??3E????0000000004??00000000??????000000000000B0??3A??000000000000000040??????????????????????01??000005????????0000000000000000??????0000000000004000000000????????????0000????????????00000000????00000000????0000????0000????A40C??00000000C0??????????????C0??????????????5013??00000000????????????00000000????00000000??????000004??00005801??00000000??????4000000000??????4000000000????000000000000????000000000000??????000000000000070000??????0000C0??????????????C0??????????????C0??????????????28??00000000000078??00000000000008??00000000000051E5??64??000000000000000000000000000000000000000000000000000000000000000000000000000000000000????000000000000??????000010??000001??0000474E5500000000????0000??????000000000000C0????????????????????????0000????84????00000000C8??????0000000025????????0000????374200000000????A56C00000000????????????0000????????????0000????A56C00000000????????????0000??????4200000000????A56C00000000????????????0000????24??00000000????A56C00000000????????????0000????????????0000????A56C00000000????????????0000????83??????0000????A56C00000000????????????0000????5E42000000000000A66C00000000????????????0000??????4200000000????A66C00000000????????????0000????914200000000????A66C00000000????????????0000??????4200000000????A66C00000000????????????0000????????????0000????A66C00000000????????????0000????????????0000????A66C00000000????????????0000??????4200000000????A66C00000000????????????0000??????4200000000??????EC08??4301??????62??0000E8????????4883????C3FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????00000000000000000000000000000000000000000000000031??4989??5E4889??4883????505449C7??????????48C7??????????48C7??????????E8????????F490904883????488B??????????4885??74??FF??4883????C390909090909090909090909090B8????????55482D????????4883????4889??76??B8????????4885??74??5DBF????????FF??660F1F????????????5DC366666666????????????????????BE????????554881??????????48C1????4889??4889??48C1????4801??48D1??74??B8????????4885??74??5DBF????????FF??0F1F??5DC3660F1F??????80????????????75??554889??53BB????????4881??????????4883????488B??????????48C1????4883????4839??73??660F1F??????4883????4889??????????FF????????????488B??????????4839??72??E8????????B8????????4885??74??BF????????E8????????C6????????????4883????5B5DF3??669055B8????????4885??4889??74??BE????????BF????????E8????????BF????????4883????75??5DE9????????6690B8????????4885??74??FF??EB??9090554889??534881??????????89??????????48C7????????????8B????3D????????76??E9????????8B????89??488D??????????8B??????????4889??89??E8????????85??75??E9????????8B????89??488D??????????89??4889??E8????????488D??????????BE????????4889??E8????????4889????4883??????75??E9????????488D??????????488D??????????4889??4889??E8????????85??74??E9????????488B??????????4889????C7????????????488B????89????488B????48C1????89????4883????FF????FF????FF????E8????????4883????89????BE????????488D????E8????????8B??????????BA????????488D????89??E8????????85??75??E9????????8B??????????BA????????488D????89??E8????????85??75??E9????????BE????????488D????E8????????8B????4883????FF????FF????FF????E8????????4883????39??74??E9????????8B????89??48C1????4889??8B????89??4801??4889????488B????488B????BA????????4889??4889??E8????????488B????4889????EB??488B????488D??????????4889??BA????????BE????????4889??E8????????89????83??????7F??EB??8B????488D??????????89??4889??E8????????8B????4863??488D??????????8B??????????4889??89??E8????????85??75??EB??8B????48984801????488B????483B????7C??488B????4889??E8????????B8????????488B????C9C3554889??534881??????????4889??????????E8????????4889??E8????????C7????????????488B??????????8B????89????488B??????????8B??89????488B??????????8B????89????8B????8B????BA????????89??89??E8????????89????83??????75??E9????????488D????BA????????BE????????4889??E8????????C7????????????C7????????????8B????89????4883????FF????FF????FF????E8????????4883????89????488D????BE????????4889??E8????????488D????8B????BA????????4889??89??E8????????85??75??E9????????488D??????????4889??E8????????488D??????????BE????????4889??E8????????488D??????????8B????BA????????4889??89??E8????????85??75??EB??488D????8B????BA????????4889??89??E8????????85??75??EB??488D????BE????????4889??E8????????8B????4883????FF????FF????FF????E8????????4883????39??74??EB??8B????83????74??EB??8B????4883????FF????FF????FF????89??E8????????4883????908B????89??E8????????B8????????488B????C9C3554889??4889????89????C7????????????488B????4889????C7????????????EB??488B????0FB6??8B????99F7????89??48980FB6??????????31??89??488B????88??83??????4883??????8B????3B????7C??488B????5DC3554889??4889????89????488B????4889????C7????????????EB??488B????0FB6??0FB6??????????31??488B????88??83??????4883??????8B????3B????7C??488B????5DC39090554889??534881??????????89??????????48C7????????????48C7????????????48C7????????????8B????89??488D??????????8B??????????4889??89??E8????????85??75??E9????????8B????89??488D??????????89??4889??E8????????488D??????????488D??????????4889??4889??E8????????488D??????????488D??????????4889??BA????????BE????????4889??B8????????E8????????488D??????????4889??E8????????4883????4889??E8????????4889????4883??????75??E9????????488D??????????488B????4889??4889??E8????????488D????488D??????????B9????????BA????????4889??E8????????89????83??????0F8E????????C7????????????E9????????488B????8B????4863??48C1????4801??488B??488D????488D??????????488D??????????4989??4889??BA????????BE????????4889??B8????????E8????????488D??????????488D??????????4889??4889??E8????????85??0F85????????48C7????????????48C7????????????488D??????????4883????4889??E8????????4889??E8????????4989??488B??????????8B??????????25????????89??8B??????????25????????89??488B????8B????4863??48C1????4801??488B??488D????488D??????????415052FF????FF????4189??4189??BA????????BE????????4889??B8????????E8????????4883????488B????4889??E8????????4889??488D?????????? }
condition:
- 7 of them and filesize <679936
+ uint16(0)==0x457f and filesize <4000KB and all of them
}
-rule MALPEDIA_Win_Unidentified_068_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Pwnlnx_Backdoor_Variant_4 : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5159a6d8-1e34-506d-99d9-cd809f096743"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_068"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_068_auto.yar#L1-L133"
- license_url = "N/A"
- logic_hash = "89cc05fc50aa07230f88b9a05ad2adeb94c446a13f619795648893388c9d8285"
+ description = "Rule to detect the backdoor pwnlnx variant 4"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "199bb534-f0f6-5b67-aedd-3eada5e45cc6"
+ date = "2020-04-17"
+ modified = "2020-08-14"
+ reference = "https://www.blackberry.com/content/dam/blackberry-com/asset/enterprise/pdf/direct/report-bb-decade-of-the-rats.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_decade_of_RATs.yar#L99-L129"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "2590ab56d46ff344f2aa4998efd1db216850bdddfc146d5d37e4b7d07c7336fc"
+ logic_hash = "11203beee446aaf0783d3a8d3839a88ef16c27d52be8670d650ebf6a1de2c3aa"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Pwnlnx"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 75ee 394624 7417 50 8bce e8???????? }
- $sequence_1 = { 43 8bc8 3bde 72e6 8b75e0 8b5df4 8b55f8 }
- $sequence_2 = { 85ff 741b 8b4674 ff7514 8b0c98 83c118 e8???????? }
- $sequence_3 = { 59 57 8bd8 c745fc04000000 8d45fc 50 53 }
- $sequence_4 = { 7406 8b08 50 ff5108 885d94 895df0 8d4df0 }
- $sequence_5 = { 8d5648 8d4d88 e8???????? 59 83781408 7202 8b00 }
- $sequence_6 = { 660f13442450 8b4c2454 894c2458 8b4c2450 894c2450 8b4c2464 894c2428 }
- $sequence_7 = { d1f9 6a41 5f 894df0 8b34cd18aa4400 8b4d08 6a5a }
- $sequence_8 = { 72ba 33f6 81fb10000020 0f45f3 85f6 7523 33db }
- $sequence_9 = { 8d4948 e8???????? 33c0 5d c20800 55 8bec }
+ $bp = { 7F??4C4602??01??000000000000000001??3E????000000000000000000000000000000000000????????????000000000000??????0000000040??????????????000014??000003??0000474E55????9FECFBE5??F973??EB??2A??????????71??BD????????0000000000000000554889??53E8????????FF????????????4889??4889??4881??????????FF????????????4889??5BC9C30F1F??????554889??E8????????FF????????????C9C366666666????????????????????554889??E8????????4885??74??4C8B????4D85??74??65??8B????????????8B??????????4889??????????48C7??????????89??C1????C1????01??25????????29??48984C89????????????FF??????????C9C3660F1F????????????31??C9C36666662E????????????????554889??E8????????4889??????????48C7??????????FF??????????C9C390554889??E8????????8B??????????488B??????????488D????0FB6????3C??400F94??3C??410F94??74??4084??75??B8????????C9C30F1F????????????8B??????????39????74??3B????74??4584??74??8B??????????4801??0FB7??????????66????74??66??????75??4889??41FF??B8????????C9C30F1F??4084??74??8B??????????4801??0FB7??????????66????75??EB??0F1F????554889??534883????E8????????31??4889??31??E8????????483D????????77??4885??74??488B????488B????488B????488B????4889??????????31??4889??E8????????31??4883????5BC9C383????EB??662E0F1F????????????554889??415453E8????????4989??4889??31??31??E8????????483D????????77??488B????31??4889??488B????488B????488B????488B??????????4989????4889??????????E8????????31??5B415CC9C383????EB??0F1F??????554889??534883????E8????????31??4889??31??E8????????483D????????77??4885??74??488B????488B????488B????488B????4889??????????31??4889??E8????????31??4883????5BC9C383????EB??662E0F1F????????????554889??415453E8????????4989??4889??31??31??E8????????483D????????77??488B????31??4889??488B????488B????488B????488B??????????4989????4889??????????E8????????31??5B415CC9C383????EB??0F1F??????554889??534883????E8????????31??4889??BE????????E8????????483D????????77??4885??74??488B????4889????31??4889??E8????????31??4883????5BC9C383????EB??660F1F??????554889??415453E8????????4989??4889??BE????????31??E8????????483D????????77??488B????31??4889??488B????4989????488B????4889????E8????????31??5B415CC9C383????EB??554889??4157415641554154534883????E8????????4889??488D????4989??4189??4889??BA????????4989??4489????4D89??E8????????488B??????????448B????4881??????????488D????75??EB??0F1F????488B????4881??????????488D????74??0FB7????4839??75??4883????31??5B415C415D415E415FC9C30F1F??????4D89??4C89??4489??4889??4C89??FF??????????4883????5B415C415D415E415FC9C30F1F????554889??4157415641554154534883????E8????????65??8B????????????4889????4889????4189??8B??????????4889??B9????????48C7??????????4889??4D89??4589??89??C1????C1????01??25????????29??F3A648984C8B????????????0F84????????B9????????48C7??????????4889??F3A60F84????????31??4585??4889??4889????4489????74??418D??????31??488D??????0FB6??4883????4889??48C1????48C1????4801??4801??4839??488D????488D????75??89????488D????4C89??E8????????4885??4889??0F84????????488B????4885??74??81????????????0F84????????488B??????????483D????????4C8D????75??EB??0F1F??????498B????483D????????4C8D????74??498B??4889??E8????????85??75??31??4883????5B415C415D415E415FC9C34589??4D89??488B????4489??4889??488B????FF??????????4883????5B415C415D415E415FC9C30F1F??????????81????????????0F85????????31??EB??488D????4C89??E8????????4885??4889??74??498B????488B??????????488B????4885??74??31??4889??4889????FF??4885??488B????0F84????????31??E9????????0F1F????????????554889??534883????E8????????89??488B??????????4881??????????488D????74??66??????75??EB??0F1F????66??????74??488B????483D????????488D????4889??75??4883????5BC9C3E8????????4889??E8????????4883????5BC9C36666662E????????????????554889??534883????E8????????89??488B??????????4881??????????488D????74??66??????75??EB??0F1F????66??????74??488B????483D????????488D????4889??75??4883????5BC9C3E8????????4889??E8????????4883????5BC9C36666662E????????????????554889??534883????E8????????89??488B??????????4881??????????488D????74??66??????75??EB??0F1F????66??????74??488B????483D????????488D????4889??75??4883????5BC9C3E8????????4889??E8????????4883????5BC9C36666662E????????????????554889??534883????E8????????89??488B??????????4881??????????488D????74??66??????75??EB??0F1F????66??????74??488B????483D????????488D????4889??75??4883????5BC9C3E8????????4889??E8????????4883????5BC9C36666662E????????????????554889??534883????E8????????89??488B??????????4881??????????488D????74??66??????75??EB??0F1F????66??????74??488B????483D????????488D????4889??75??4883????5BC9C3E8????????4889??E8????????4883????5BC9C36666662E????????????????554889??41554154534883????E8????????4C8B??????????4989??4981??????????498D??????75??EB??0F1F????4C8B????4981??????????498D??????74??488B??4C89??E8????????85??75??4C89??E8????????488B??E8????????4889??E8????????4883????5B415C415DC9C36666662E????????????????554889??534883????E8????????488B??????????BA????????89??BF????????E8????????4885??74??66????488B??????????488D????48C7??????????E8????????4883????5BC9C30F1F????554889??534883????E8????????488B??????????BA????????89??BF????????E8????????4885??74??66????488B??????????488D????48C7??????????E8????????4883????5BC9C30F1F????554889??534883????E8????????488B??????????BA????????89??BF????????E8????????4885??74??66????488B??????????488D????48C7??????????E8????????4883????5BC9C30F1F????554889??534883????E8????????488B??????????BA????????89??BF????????E8????????4885??74??66????488B??????????488D????48C7??????????E8????????4883????5BC9C30F1F????554889?? }
condition:
- 7 of them and filesize <862208
+ uint16(0)==0x457f and filesize <400KB and all of them
}
-rule MALPEDIA_Win_Unidentified_041_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Pwnlnx_Backdoor_Variant_6 : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "54c40e17-80e5-57a5-babe-281dfc0f14df"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_041"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_041_auto.yar#L1-L133"
- license_url = "N/A"
- logic_hash = "72336cc9bc2b4e7b40dbb912cf40721cd5c8d54310aa5ce8f7ef42d8a402b398"
+ description = "Rule to detect the backdoor pwnlnx variant 6"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "56bfe9c7-4cd4-51f6-a469-da8af52d64c2"
+ date = "2020-04-17"
+ modified = "2020-08-14"
+ reference = "https://www.blackberry.com/content/dam/blackberry-com/asset/enterprise/pdf/direct/report-bb-decade-of-the-rats.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_decade_of_RATs.yar#L131-L161"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "d29254ab907c9ef54349de3ec0dd8b22b4692c58ed7a7b340afbc6e44363f96a"
+ logic_hash = "29423135a46ee7b9aa1bd8f1e6f7ffad09725787ad6e75312e1d34b18e3917d4"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Pwnlnx"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { ff761c ff7618 ff7304 e8???????? 8d45bf c645bf0d 50 }
- $sequence_1 = { 885d9b e9???????? 391f 75c7 385e04 752e }
- $sequence_2 = { 8b3f 8d44242c 50 53 68???????? 57 6a02 }
- $sequence_3 = { c645fc02 8b08 52 53 50 ff5118 85c0 }
- $sequence_4 = { eb05 be57000780 5f 8bc6 5e 5b c20400 }
- $sequence_5 = { 85c0 7509 56 e8???????? 59 eba7 8d47ff }
- $sequence_6 = { ff75e0 e8???????? 8b45f0 83c418 2b06 8bce c1f802 }
- $sequence_7 = { 7430 ff7508 8bfe 33c0 ab ab ab }
- $sequence_8 = { ff5024 85c0 0f8889040000 33c0 8dbd22fdffff 66898520fdffff ab }
- $sequence_9 = { 8d8d54ffffff e8???????? 8bc6 e9???????? ff15???????? 50 8d8d28ffffff }
+ $bp = { 7F??4C4602??01??000000000000000001??3E????000000000000000000000000000000000000??????09??00000000000000004000000000??????2B??28??04??000014??000003??0000474E55????4D9585????AB6522????52AD3B??EC9B4BE8????????0000000000000000????00000000554889??????????4889??41544989??534889??488B??????????E8????????4C89??4889??48C7??????????FF??????????488B??????????89??E8????????89??5B415C5DC30F1F??E8????????554889??????????4889??41544989??534889??488B??????????E8????????4C89??4889??48C7??????????FF??????????488B??????????89??E8????????89??5B415C5DC30F1F??E8????????554889??415541544989??534889??4883????488B??????????65??8B????????????4889????31??E8????????4889??4C89??FF??????????488B??????????4189??E8????????488B??????????483D????????488D????75??EB??0F1F??????488B????4881??????????488D????74??0FB7??488D????48C7??????????31??E8????????498B????498B??????488D????488D????????????BA????????E8????????4885??74??4981??????????????488B????65??33????????????4489??75??4883????5B415C415D5DC3E8????????0F1F??E8????????554889??415541544989??534889??4883????488B??????????65??8B????????????4889????31??E8????????4889??4C89??FF??????????488B??????????4189??E8????????488B??????????483D????????488D????75??EB??0F1F??????488B????4881??????????488D????74??0FB7??488D????48C7??????????31??E8????????498B????498B??????488D????488D????????????BA????????E8????????4885??74??4981??????????????488B????65??33????????????4489??75??4883????5B415C415D5DC3E8????????0F1F??E8????????554889??415541544989??534889??4883????488B??????????65??8B????????????4889????31??E8????????4889??4C89??FF??????????488B??????????4189??E8????????488B??????????483D????????488D????75??EB??0F1F??????488B????4881??????????488D????74??0FB7??488D????48C7??????????31??E8????????498B????498B??????488D????488D????????????BA????????E8????????4885??74??4981??????????????488B????65??33????????????4489??75??4883????5B415C415D5DC3E8????????0F1F??E8????????554889??415541544989??534889??4883????488B??????????65??8B????????????4889????31??E8????????4889??4C89??FF??????????488B??????????4189??E8????????488B??????????483D????????488D????75??EB??0F1F??????488B????4881??????????488D????74??0FB7??488D????48C7??????????31??E8????????498B????498B??????488D????488D????????????BA????????E8????????4885??74??4981??????????????488B????65??33????????????4489??75??4883????5B415C415D5DC3E8????????0F1F??E8????????554889??41574589??415641554189??4154534889??4883????488B??????????4889????4889????4C89????483D????????4C8D????74??4C63??EB??0F1F??????498B????483D????????4C8D????74??498B??4C89??4889??E8????????85??75??4883????5B415C415D415E415F5DC30F1F??????????4589??4C8B????488B????4489??4889??488B????FF??????????4883????5B415C415D415E415F5DC3660F1F??????E8????????554889??41574589??41564D89??41554989??41544189??BA????????534889??488D????4883????4889????4889??65??8B????????????4889????31??E8????????488B??????????4881??????????488D????74??0FB7????4839??75??EB??0F1F????????????410FB7????4839??74??4C8B????4981??????????498D????75??4589??4D89??4C89??4489??4889??488B????FF??????????488B????65??33????????????75??4883????5B415C415D415E415F5DC3660F1F??????31??EB??E8????????0F1F??????662E0F1F????????????E8????????55BF????????4889??4881??????????65??8B????????????4889????31??488D??????????FF????????????B9????????4889??488D??????????F3??A5488D??????????48C7??????????BE????????B1??E8????????4885??74??48BA???????? }
condition:
- 7 of them and filesize <1097728
+ uint16(0)==0x457f and filesize <700KB and all of them
}
-rule MALPEDIA_Win_Strongpity_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Mirai_Casper_Variant : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "74f27818-19f0-5cf0-92fb-64e00785ec08"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.strongpity"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.strongpity_auto.yar#L1-L169"
- license_url = "N/A"
- logic_hash = "61a3d3556929a6d92379ea8e74c4d3e507b020fc18a8d58904a2026c1434bfed"
- score = 60
- quality = 45
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ description = "Rule to detect the Mirai Casper variant"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "0f3a028c-9514-51cd-ad82-415e8ac2dee7"
+ date = "2020-04-17"
+ modified = "2020-08-14"
+ reference = "https://www.blackberry.com/content/dam/blackberry-com/asset/enterprise/pdf/direct/report-bb-decade-of-the-rats.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_decade_of_RATs.yar#L163-L193"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "57cc422a6a90c571198a2d1c3db13c31fbdb48ba2f0f4356846d6d636d0f9300"
+ logic_hash = "5449d1ef0c4977c6151fc194ad5f526b6be414c1efb7fd4bacb77d4bcd89c703"
+ score = 75
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Pwnlnx"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 50 33c0 d1f9 50 51 53 }
- $sequence_1 = { 75f8 ff75d0 68???????? ff36 e8???????? }
- $sequence_2 = { 41 83ea01 75f7 50 e8???????? 59 }
- $sequence_3 = { e8???????? 8b4608 83c418 6a2f 59 }
- $sequence_4 = { 8945f8 f7d8 56 57 }
- $sequence_5 = { 33db c745f804000000 53 ff7710 895df4 ff770c }
- $sequence_6 = { ba???????? f3a5 8bf2 668b02 83c202 }
- $sequence_7 = { 83e801 7408 6a02 58 884612 }
- $sequence_8 = { 0107 83be8800000002 8b07 0f85ad000000 83f814 }
- $sequence_9 = { 012e 885c240a e9???????? 84db 0f8434020000 }
- $sequence_10 = { 5f 8d4503 5d 5b 8b4c2428 }
- $sequence_11 = { 7417 48 7545 39812c020000 7433 8b8124020000 }
- $sequence_12 = { 5f 8b4c2408 5e 5b }
- $sequence_13 = { 5f 8d4502 5d 5e 5b 8b4c2468 }
- $sequence_14 = { 012e 885c240a ebc3 80fb5d 7520 837c240c00 0f85fe020000 }
- $sequence_15 = { 5f 8bc3 5b c3 8d4638 50 e8???????? }
+ $bp = { 7F??4C4601??01??000000000000000002??03??01??0000E0??04??34??000088??????????000034??20??05????????????????000000000000000080??????80??????15????????0C??05????????10??????0000??????0C??40A510??40A510??80??????904A0000060000000010????????0000D4??0000D4??04??D4??04??440000??????????????000004??0000070000??????0C??40A510??40A510??14??000030??000004??000004??000051E5??64????000000000000000000000000000000000000060000??????000004??000010??000001??0000474E5500000000????0000????0000????0000??????000014??000003??0000474E55??????3A??87????529723????2C??08??????AB35????????2A??0000BC????????0000????A510??2A??0000C4??????????0000C8??????2A??0000CCA510??2A??00005589??5383????E8????????5B81??????????8B??????????85??74??E8????????E8????????E8????????585BC9C3FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????FF??????????68????????E9????????000000000000000031??5E89??83????50545268????????68????????515668????????E8????????F490909090909090909090909090905589??538D??????80????????????75??BB????????A1????????81??????????C1????83????39??73??908D??????83????A3????????FF????????????A1????????39??72??B8????????85??74??C7????????????E8????????C6????????????8D??????5B5DC3908D??????55B8????????89??8D??????E8????????5A81??????????85??74??89??????C7??????????????C7??????????????C7????????????E8????????A1????????85??74??B8????????85??74??C7????????????FF??C9C39090905589??83????8B????88????A1????????85??74??A1????????0FB6????88??83????A3????????EB??C7??????????????8D????89??????C7????????????E8????????C9C35589??83????EB??8B????0FB6??0FBE??83??????89????E8????????8B????0FB6??84??75??C9C35589??83????8B????0FB6??88????83??????80??????0F84????????80??????74??0FBE????89????E8????????E9????????C7????????????8B????0FB6??88????83??????80??????75??C7????????????8B????0FB6??88????83??????EB??80??????75??C7????????????8B????0FB6??88????83??????C7????????????EB??8B????89??C1????01??01??89??0FBE????8D????83????89????8B????0FB6??88????83??????80??????7E??80??????7E??80??????74??80??????75??83??????8B????0FB6??88????83??????80??????0F84????????0FB6????88????80??????7E??0FB6????83????88????0FBE????83????83????0F87????????8B????????????FF??8B????8D????89????8B??89????C7????????????EB??83??????8B????8B????8D????0FB6??84??75??EB??C7????????????E8????????8B????83????85??75??8B????3B????0F92??83??????84??75??8B????89????E8????????EB??C7????????????E8????????8B????3B????0F92??83??????84??75??E9????????8B????8D????89????8B??0FBE??89????E8????????E9????????C7????????????EB??C7????????????EB??C7????????????EB??C7????????????EB??0FBE????89????E8????????E9????????8B????83????85??74??8B????8D????89????8B??EB??80??????75??8B????8D????89????8B??EB??8B????8D????89????8B??89????80??????75??8B????85??79??F7????83??????C7????????????8B????BA????????F7????89??88????8B????BA????????F7????89????80??????7E??80??????75??B8????????EB??B8????????0FB6????01??88????8B????0FB6????83????88??????83??????83??????74??83??????76??8B????83????85??74??8B????C6????????83??????8B????89????8B????83????84??74??B8????????EB??B8????????88????EB??0FBE????89????E8????????8B????83????85??75??8B????3B????0F92??83??????84??75??83??????8B????0FB6??????0FBE??89????E8????????83??????75??EB??C7????????????E8????????8B????3B????0F92??83??????84??75??E9????????E9????????90EB??90C9C35589??83????8D????89????8B????89??????8B????89????E8????????C9C35589??83????8B????8B????88????88????C9C35589??57565381??????????8B????8B????88??????????88??????????C7??????????????????C7??????????????????0FB6??????????C7??????????????C7??????????????8B????89??????89????E8????????89??????????0FB6??????????C7??????????????C7??????????????8B????89??????89????E8????????89??????????0FB6??????????C7??????????????C7??????????????8B????89??????89????E8????????89??????????0FB6??????????C7??????????????C7??????????????8B????89??????89????E8????????89??????????0FB6??????????C7??????????????C7??????????????8B????89??????89????E8????????89??????????0FB6??????????C7??????????????C7??????????????8B????89??????89????E8????????66????????????8D??????????BA????????89??????C7??????????????89????E8????????83????????????0F84????????83????????????0F84????????8B??????????89????E8????????3D????????0F8F????????8B??????????89????E8????????83????0F8F????????8B??????????89????E8????????83????0F8F????????C7??????????????????EB??8B??????????03??????????0FB6??3C??7E??8B??????????03??????????0FB6??3C??7F??8B??????????03??????????8B??????????03??????????0FB6??83????88??8B??????????83????89??????????8B??????????89????E8????????8B??????????39??7F??81??????????????????7E??C7??????????????????C7????????????E8????????C7????????????E8????????C7????????????E8????????C7????????????E8????????C7????????????E8????????C7????????????E8????????C7????????????E8????????C7????????????E8????????C7????????????E8????????C7????????????E8????????C7????????????E8????????8B??????????C7??????????????89????E8????????89??????????C7??????????????????E9????????8B??????????69??????????03??????????C6??????8B??????????69??????????03??????????C7??????????8B??????????69??????????89??03??????????0FB6??????????8B??????????89??C1????F7??89??89??89??01??01??C1????03????8B????89????8B??????????69??????????03??????????8D??????????8B??????????89??????89????E8????????8B??????????69??????????03??????????0FB6??????????3C??74??8B??????????69??????????03??????????05????????89????E8????????8B??????????69??????????03??????????8D??????????8B??????????69??????????03??????????81??????????83????89??????89??????89????E8????????8B??????????69??????????03??????????C6????????????8B??????????69??????????03??????????8D??????????8B??????????89??????89????E8????????8B??????????69??????????03??????????8D??????????8B??????????89??????89????E8????????8B??????????69??????????03??????????8D??????????8B??????????89??????89????E8????????0FB6??????????8B??????????89??C1????F7??89??89??89??01??01??C1????03????0FB6????3C??0F87????????8B??????????69??????????89??03??????????0FB6??????????8B??????????89??C1????F7??89??89??89??01??01??C1????03????8B????89????E8????????89??E8????????89??0FB6??????????8B??????????89??C1????F7??89??89??89??01??01??C1????03????0FB6????0FB6??89??89??D3??89??8D????89????E8????????89????E8????????89??BA????????89??F7??89??C1????89??C1????01??89??29??83????0F87????????8B????????????FF??C7????????????E8????????C7??????????????C7????????????E8????????8B??????????69??????????03??????????83????89??????89????E8????????C7????????????E8????????E9????????C7????????????E8????????C7??????????????C7????????????E8????????8B??????????69??????????03??????????83????89??????89????E8????????C7????????????E8????????E9????????C7????????????E8????????C7??????????????C7????????????E8????????8B??????????69??????????03??????????83????89??????89????E8????????C7???????????? }
condition:
- 7 of them and filesize <999424
+ uint16(0)==0x457f and filesize <3000KB and all of them
}
-rule MALPEDIA_Win_Spyder_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_APT_Stolen_Certificates : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3ab12f00-3358-5020-939c-e2c585a1665c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spyder"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.spyder_auto.yar#L1-L176"
- license_url = "N/A"
- logic_hash = "bab678e49456b3f7ffea3f1f145c31d0ca13e5400d7a321bcd98016f59a4377c"
+ description = "Rule to detect samples digitally signed from these stolen certificates"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "57051977-780c-5c8e-bc66-0f1d8b3bbd93"
+ date = "2020-04-17"
+ modified = "2020-08-14"
+ reference = "https://www.blackberry.com/content/dam/blackberry-com/asset/enterprise/pdf/direct/report-bb-decade-of-the-rats.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_decade_of_RATs.yar#L196-L221"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "ce3424524fd1f482a0339a3f92e440532cff97c104769837fa6ae52869013558"
+ logic_hash = "9b700e4889349d0203bdd4e00035ee9c9aba5025ccc57eef915b2c78996f8160"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { 4053 4883ec20 8bd9 488d0da5a40000 ff15???????? 4885c0 7419 }
- $sequence_1 = { 0f8493010000 488d156a5f0000 488bc8 ff15???????? 4885c0 0f847a010000 }
- $sequence_2 = { 756e 488d4b04 4c8d05563e0000 418d5216 e8???????? 85c0 7437 }
- $sequence_3 = { eb17 488b5638 498bcc ff5630 b97f000000 ff15???????? }
- $sequence_4 = { 7422 488d15795e0000 488bce ff15???????? 488bc8 }
- $sequence_5 = { 496374243c 4903f4 813e50450000 740b b9c1000000 }
- $sequence_6 = { 7647 498bcd e8???????? 4c8d05478a0000 41b903000000 488d4c45bc 488bc1 }
- $sequence_7 = { 85c0 7408 8bcb ff15???????? e8???????? 488d15faa20000 }
- $sequence_8 = { 8b7d0c 8d0540460910 83780800 754e b741 b35a }
- $sequence_9 = { 50 a3???????? e8???????? 8db6843d0910 bf???????? }
- $sequence_10 = { 888800490910 eb1f 83f861 7213 83f87a 770e 8088????????20 }
- $sequence_11 = { 83c424 aa 8d842484000000 6804010000 50 53 }
- $sequence_12 = { 81e1ffff0000 50 51 68???????? 8d54243c }
- $sequence_13 = { 68???????? 8d44242c 8d8c2494050000 50 68???????? }
- $sequence_14 = { b801000000 5b 81c47c150000 c3 5f 5e 33c0 }
- $sequence_15 = { 0fb6d2 f682014a091004 7403 40 }
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Pwnlnx"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
condition:
- 7 of them and filesize <1458176
+ uint16(0)==0x5a4d and for any i in (0..pe.number_of_signatures) : (pe.signatures[i].subject contains "/C=KR/ST=Seoul/L=Gangnam-gu/O=LivePlex Corp/CN=LivePlex Corp" and pe.signatures[i].serial=="3f:55:42:e2:e7:1d:8d:b3:57:04:1c:9d:d4:5b:95:0a" or pe.signatures[i].subject contains "/C=KR/ST=Seoul/L=Gangnam-gu/O=LivePlex Corp/CN=LivePlex Corp" and pe.signatures[i].serial=="3f:55:42:e2:e7:1d:8d:b3:57:04:1c:9d:d4:5b:95:0a" or pe.signatures[i].subject contains "/C=KR/ST=Seoul/L=Gangnam-gu/O=LivePlex Corp/CN=LivePlex Corp" or pe.signatures[i].serial=="3f:55:42:e2:e7:1d:8d:b3:57:04:1c:9d:d4:5b:95:0a")
}
-rule MALPEDIA_Win_Unidentified_039_Auto : FILE
+rule TRELLIX_ARC_Chimera_Recordedtv_Modified : TROJAN FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "79803854-9c28-5ee4-826a-7f1227d74ba5"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_039"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_039_auto.yar#L1-L126"
- license_url = "N/A"
- logic_hash = "58c8fb21d6ae978d62ed7528cfbdb8da381c56d520ca5623fbbc73c80d3173d3"
+ description = "Rule to detect the modified version of RecordedTV.ms found in the Operation Skeleton"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "b0969713-41a4-550c-9545-f02783fa8d02"
+ date = "2020-04-21"
+ modified = "2020-08-14"
+ reference = "https://medium.com/@cycraft_corp/taiwan-high-tech-ecosystem-targeted-by-foreign-apt-group-5473d2ad8730"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_operation_skeleton.yar#L1-L33"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "66f13964c87fc6fe093a9d8cc0de0bf2b3bdaea9564210283fdb97a1dde9893b"
+ logic_hash = "7165779b66999259a079fa68f898c5f9fb634adcb9d249366d321dff1014184b"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/RecordedTV"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { b8???????? e8???????? 8365fc00 8365cc00 c745dce7600000 c745ec89640000 }
- $sequence_1 = { c745f00b090000 c745f089000000 8975c0 c745f4b76e0000 c745fc9e540000 c745f8a7600000 }
- $sequence_2 = { c74530284c0000 c7453425120000 c745281f480000 c74538136b0000 c74520825d0000 c7451c84360000 8b4530 }
- $sequence_3 = { 69c9de3f0000 33c1 8945dc 8b4510 8b4d0c 3bc8 7d0c }
- $sequence_4 = { 8bec 51 51 c745f81d2d0000 c745f8d33a0000 c745fc9a790000 }
- $sequence_5 = { c745d0e5720000 8b45d0 8b4dd4 0fafc1 8b4dd8 8b55dc }
- $sequence_6 = { 6bc01f c1e704 83c30c 03fa 33d2 }
- $sequence_7 = { 69c0295a0000 8945e4 e8???????? c745e0f9750000 c745f0b56c0000 c745ec29110000 }
- $sequence_8 = { 8d45f4 64a300000000 c3 6a00 6a01 ff74240c }
- $sequence_9 = { c745e863430000 8b45e4 59 8b4df8 23c1 8b4de8 81e931570000 }
+ $byte = { C0 0E 5B C3 }
+ $s1 = "Encrypted file: CRC failed in %s (password incorrect ?)" fullword wide
+ $s2 = "EBorland C++ - Copyright 1999 Inprise Corporation" fullword ascii
+ $s3 = " MacOS file type: %c%c%c%c ; " fullword wide
+ $s4 = "rar.lng" fullword ascii
condition:
- 7 of them and filesize <262144
+ uint16(0)==0x5a4d and filesize <900KB and all of them
}
-rule MALPEDIA_Win_Xxmm_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Syskit : FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2f4f20e9-d761-523e-a241-a1e4f366495b"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xxmm"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xxmm_auto.yar#L1-L120"
- license_url = "N/A"
- logic_hash = "0f663d162fed444e7f08fa4fe0acf57f92808d6dc37ba8437dff740dddaf561a"
+ description = "SYSkit backdoor"
+ author = "Christiaan @ McAfee ATR"
+ id = "f06db38f-52d5-51b5-a17f-63e285dd5f80"
+ date = "2019-09-17"
+ modified = "2020-04-02"
+ reference = "https://www.symantec.com/blogs/threat-intelligence/tortoiseshell-apt-supply-chain"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Tortoiseshell_Syskit.yar#L3-L40"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "5b489d47d56de5c770b6ff6d6d56bf0fb87174f4a8428052b28fb392d9ac3f87"
score = 75
- quality = 75
+ quality = 68
tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ hash1 = "07d123364d8d04e3fe0bfa4e0e23ddc7050ef039602ecd72baed70e6553c3ae4"
+ hash2 = "f71732f997c53fa45eef5c988697eb4aa62c8655d8f0be3268636fc23addd193"
+ hash3 = "02a3296238a3d127a2e517f4949d31914c15d96726fb4902322c065153b364b2"
strings:
- $sequence_0 = { 6a00 ff15???????? 53 57 50 8945fc e8???????? }
- $sequence_1 = { 6a00 ff55ec ff7650 8bf8 }
- $sequence_2 = { 8b7c0e20 8b440e24 03f9 03c1 }
- $sequence_3 = { 897d10 3bdf 7673 8b4508 2bc6 }
- $sequence_4 = { c3 55 8bec 51 51 8b03 8b08 }
- $sequence_5 = { 0f84bc000000 397d10 0f84b3000000 3bf7 }
- $sequence_6 = { 034df8 83c0f8 d1e8 8d7a08 897df4 7450 }
- $sequence_7 = { 0fb74606 8945e8 85c0 7429 8b47f8 }
- $sequence_8 = { 3b7114 7303 8bc6 c3 53 0fb75806 57 }
- $sequence_9 = { 41 4a 75f7 8b5dfc 83c728 837de800 75d7 }
+ $x1 = "timeout /t 10 & sc stop dllhost & timeout /t 10 & del C:\\Windows\\Temp\\BAK.exe" fullword wide
+ $s2 = "lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.R" ascii
+ $s3 = "C:\\Windows\\Temp\\rconfig.xml" fullword wide
+ $s4 = "Add-Type -AssemblyName System.IO.Compression.FileSystem" fullword wide
+ $s5 = "serviceProcessInstaller1" fullword ascii
+ $s6 = " [System.IO.Compression.ZipFile]::ExtractToDirectory($zipfile, $outpath)" fullword wide
+ $s7 = "exec_cmd2" fullword ascii
+ $s8 = "exec_cmd" fullword ascii
+ $s9 = "send_command_result" fullword ascii
+ $s10 = "mycontent" fullword ascii
+ $s11 = "Diagnostic Server Host" fullword wide
+ $s12 = "bytesToBeEncrypted" fullword ascii
+ $s13 = "createPostRequest" fullword ascii
+ $s14 = "myhash" fullword ascii
+ $s15 = "DD5783BCF1E9002BC00AD5B83A95ED6E4EBB4AD5" ascii
+ $s16 = "circle_time" fullword ascii
+ $s17 = "ServiceStart_AfterInstall" fullword ascii
+ $s18 = "serviceInstaller1" fullword ascii
+ $s19 = "BAK.ProjectInstaller.resources" fullword ascii
+ $s20 = "Dll host" fullword wide
+ $op0 = { 96 00 f1 0a 57 02 05 00 34 25 }
+ $op1 = { 96 00 83 05 5a 01 0e 00 38 28 }
+ $op2 = { 06 00 00 11 28 4d 00 00 0a 02 6f 4e 00 00 0a 28 }
condition:
- 7 of them and filesize <540672
+ ( uint16(0)==0x5a4d and filesize <50KB and pe.imphash()=="f34d5f2d4577ed6d9ceec516c1f5a744" and (1 of ($x*) and 4 of them ) and all of ($op*)) or ( all of them )
}
-rule MALPEDIA_Win_Aperetif_Auto : FILE
+rule TRELLIX_ARC_Apt_Elise_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "dd57eb34-4374-5f40-adeb-74673af556ba"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aperetif"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.aperetif_auto.yar#L1-L134"
- license_url = "N/A"
- logic_hash = "cb1f1d595273c378c0af7214424a9c75d431ec33b0d3744330f8349a67692fb4"
+ description = "Rule to detect Elise APT based on the PDB reference"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "cc8dd203-baad-5800-ba2c-f9c47d8ca6f0"
+ date = "2017-05-31"
+ modified = "2020-08-14"
+ reference = "https://attack.mitre.org/software/S0081/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_elise_pdb.yar#L1-L29"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "b426dbe0f281fe44495c47b35c0fb61b28558b5c8d9418876e22ec3de4df9e7b"
+ logic_hash = "bb7eee8082aa0f6634a8c4cdb9cbe0e2a7f00b97e48609c81a21bdaac64a5496"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Elise"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8b4108 8975e4 c70100000000 c7410400000000 8945ec c7410800000000 c645f301 }
- $sequence_1 = { e8???????? 8a45d8 884524 8b0e c645fc02 85c9 0f8412010000 }
- $sequence_2 = { 50 8d45f4 64a300000000 8bd9 895db8 8b7508 837e1000 }
- $sequence_3 = { f20f118424f8080000 8b0cb0 85c9 7422 8b742464 90 0fb7047e }
- $sequence_4 = { ff74242c 57 e8???????? 83c410 eb14 8b8724000800 b900000200 }
- $sequence_5 = { 8954242c 660f1f440000 53 ff742424 68c0000000 56 55 }
- $sequence_6 = { ff742410 ff742424 e8???????? 83c408 897c2410 89742450 8b44245c }
- $sequence_7 = { e8???????? ff742434 53 e8???????? ff742428 53 e8???????? }
- $sequence_8 = { ff5210 8b4dc8 c7451803000000 85c9 7418 8b11 8d45a4 }
- $sequence_9 = { e8???????? c7868400000000000000 8b37 8b8e84000000 85c9 7506 8b8e88000000 }
+ $pdb = "\\lstudio\\projects\\lotus\\elise\\Release\\EliseDLL\\i386\\EliseDLL.pdb"
+ $pdb1 = "\\LStudio\\Projects\\Lotus\\Elise\\Release\\SetElise.pdb"
+ $pdb2 = "\\lstudio\\projects\\lotus\\elise\\Release\\SetElise\\i386\\SetElise.pdb"
+ $pdb3 = "\\LStudio\\Projects\\Lotus\\Elise\\Release\\Uninstaller.pdb"
+ $pdb4 = "\\lstudio\\projects\\lotus\\evora\\Release\\EvoraDLL\\i386\\EvoraDLL.pdb"
condition:
- 7 of them and filesize <10500096
+ uint16(0)==0x5a4d and filesize <50KB and any of them
}
-rule MALPEDIA_Win_Kardonloader_Auto : FILE
+rule TRELLIX_ARC_Apt_Manitsme_Trojan : TROJAN FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3f6a3bad-df12-536d-9e36-cfe1dc9fa562"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kardonloader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kardonloader_auto.yar#L1-L127"
- license_url = "N/A"
- logic_hash = "4fe311b419f6bafe180c85c33e9d2d9d1da43b3315ab993943a70f218a823338"
+ description = "Rule to detect the Manitsme trojan"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "49e0c934-6920-5e49-837c-27ebbbd5a1a2"
+ date = "2013-03-08"
+ modified = "2020-08-14"
+ reference = "https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_manitsme_trojan_pdb.yar#L1-L36"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "c1c0ea096ec4d36c1312171de2a9ebe258c588528a20dbb06a7e3cf97bf1e197"
+ logic_hash = "584053145249a930d3eae5e291d3553c57fa427dbecac9f04e7c0169f153b7af"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/Manitsme"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 83e13f c1e806 03c3 8a0490 88443702 8a0419 8b4d0c }
- $sequence_1 = { 5e 8be5 5d c3 6a00 ff15???????? cc }
- $sequence_2 = { e8???????? 83c438 85c0 7405 83c004 }
- $sequence_3 = { 56 ff7508 68???????? e8???????? 85c0 0f8421010000 }
- $sequence_4 = { 50 56 e8???????? 83c40c 894714 b001 5f }
- $sequence_5 = { e8???????? 59 50 8d8550faffff 50 }
- $sequence_6 = { 50 ff35???????? ff35???????? e8???????? 83c438 e9???????? 5f }
- $sequence_7 = { 750b c74704???????? 0fb7720a 6a05 58 663bf0 750e }
- $sequence_8 = { c0e204 8b45fc 880c30 0fb6441f02 8a8018314000 c0e802 }
- $sequence_9 = { 50 8d85e4fdffff 50 8d85e8feffff 68???????? 50 }
+ $s1 = "SvcMain.dll" fullword ascii
+ $s2 = "rj.soft.misecure.com" fullword ascii
+ $s3 = "d:\\rouji\\SvcMain.pdb" fullword ascii
+ $s4 = "constructor or from DllMain." fullword ascii
+ $s5 = "Open File Error" fullword ascii
+ $s6 = "nRet == SOCKET_ERROR" fullword ascii
+ $s7 = "Oh,shit" fullword ascii
+ $s8 = "Paraing" fullword ascii
+ $s9 = "Hallelujah" fullword ascii
+ $s10 = "ComSpec" fullword ascii
+ $s11 = "ServiceMain" fullword ascii
+ $s12 = "SendTo(s,(char *)&sztop,sizeof(sztop),FILETYPE) == ERRTYPE" fullword ascii
condition:
- 7 of them and filesize <57344
+ uint16(0)==0x5a4d and filesize <200KB and all of them
}
-rule MALPEDIA_Win_Unidentified_111_Auto : FILE
-{
- meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "761c3c1a-627b-5adf-b1c2-f96f11c05a94"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_111"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_111_auto.yar#L1-L125"
- license_url = "N/A"
- logic_hash = "8a86a6eb9509e0a5b4e912cde53abfcabb23f3644fc565d69ca8396c5dc5d7c9"
+rule TRELLIX_ARC_Apt_Gdocupload_Glooxmail : BACKDOOR FILE
+{
+ meta:
+ description = "Rule to detect gdocupload tool used by APT1"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "deb20196-65e6-5dac-af0c-2f16e5926715"
+ date = "2013-02-19"
+ modified = "2020-08-14"
+ reference = "https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_gdocupload_pdb.yar#L1-L32"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "295c5c7aa5fa29628dec9f42ed657fce0bc789079c4e51932bcbc99a28dfd440"
+ logic_hash = "e016bb636af22fae79875bebaf1b4bd4f2a403e797d7ee52ea0691b4d7a54cf8"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 45
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Gdocupload"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 488b4c2428 0fbe09 3bc1 7512 }
- $sequence_1 = { c744242002000000 e9???????? 837c243406 7511 837c243801 750a }
- $sequence_2 = { 8b00 488b4c2430 488b09 0fbe0401 48634c2404 488b542428 0fbe0c0a }
- $sequence_3 = { eb43 41b901000000 448b442424 488b542428 488b4c2448 e8???????? }
- $sequence_4 = { eb1f c744242000000000 4533c9 4533c0 }
- $sequence_5 = { 488b4c2448 ff15???????? 89442444 837c244400 7502 eb11 }
- $sequence_6 = { 488d8c0c60020000 ba02000000 486bd200 4803ca 448bc0 488b542420 e8???????? }
- $sequence_7 = { 66c1ca08 0fb7d2 4c8b8424a0000000 450fb74006 6641c1c808 450fb7c0 4c8b8c24a0000000 }
- $sequence_8 = { e8???????? b910000000 e8???????? 4889442448 488b442448 488b4c2450 488908 }
- $sequence_9 = { 4889542410 48894c2408 4883ec78 c744243000000000 c744243400000000 488b942488000000 488d4c2448 }
+ $s1 = "https://www.google.com/accounts/ServiceLogin?service=writely&passive=1209600&continue=http://docs.google.com/&followup=http://do" ascii
+ $s2 = "Referer: http://sn114w.snt114.mail.live.com/mail/AttachmentUploader.aspx?_ec=1" fullword ascii
+ $s3 = "User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET " ascii
+ $s4 = "e:\\Project\\mm\\Webmail\\Bin\\gdocs.pdb" fullword ascii
+ $s5 = "http://docs.google.com/?auth=" fullword ascii
+ $s6 = "x-guploader-client-info: mechanism=scotty flash; clientVersion=18067216" fullword ascii
+ $s7 = "http://docs.google.com/" fullword ascii
+ $s8 = "Referer: http://sn114w.snt114.mail.live.com/mail/EditMessageLight.aspx?n=%s" fullword ascii
condition:
- 7 of them and filesize <148480
+ uint16(0)==0x5a4d and filesize <300KB and all of them
}
-rule MALPEDIA_Win_Buterat_Auto : FILE
+rule TRELLIX_ARC_Apt_Hikit_Rootkit : ROOTKIT FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3e97b50a-971b-5a6b-945e-3e34fedb231a"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.buterat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.buterat_auto.yar#L1-L129"
- license_url = "N/A"
- logic_hash = "eb64ab06f54c3ecee14053c6efd01e298ad3b6ab4366443760576f0899003a4d"
+ description = "Rule to detect the rootkit hikit based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "c53acbc6-8f4a-590b-8dd7-ce4da6d79cf8"
+ date = "2012-08-20"
+ modified = "2020-08-14"
+ reference = "https://www.fireeye.com/blog/threat-research/2012/08/hikit-rootkit-advanced-persistent-attack-techniques-part-1.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_hikit_rootkit_pdb.yar#L1-L28"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "8a425ababdfbe95bd8ac7d4f519be16c0f1fd0b7eea2874124db2f00dd6eb56d"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "ROOTKIT, FILE"
+ rule_version = "v1"
+ malware_type = "rootkit"
+ malware_family = "Rootkit:W32/Hikit"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 56 8d4dfc 51 57 50 53 }
- $sequence_1 = { 750a 56 6a07 e8???????? 59 59 ff750c }
- $sequence_2 = { ff15???????? 8b5d75 53 33c0 e8???????? 85c0 59 }
- $sequence_3 = { 56 57 33f6 e8???????? 85c0 59 0f868b000000 }
- $sequence_4 = { 750b e8???????? 99 f77dfc 8bda 837d6806 }
- $sequence_5 = { 8d8564dfffff 50 8bc3 e8???????? 83c40c ff75f4 ffd7 }
- $sequence_6 = { 8bec b800100000 e8???????? 8b4d08 }
- $sequence_7 = { e8???????? 83c40c 85c0 0f8424010000 68???????? 53 68???????? }
- $sequence_8 = { 41 41 47 3b7d0c 72cd 5b 33c0 }
- $sequence_9 = { 33db 385d1c 56 57 895df0 750d 8a4518 }
+ $pdb = "\\JmVodServer\\hikit\\bin32\\RServer.pdb"
+ $pdb1 = "\\JmVodServer\\hikit\\bin32\\w7fw.pdb"
+ $pdb2 = "\\JmVodServer\\hikit\\bin32\\w7fw_2k.pdb"
+ $pdb3 = "\\JmVodServer\\hikit\\bin64\\w7fw_x64.pdb"
condition:
- 7 of them and filesize <278528
+ uint16(0)==0x5a4d and filesize <100KB and any of them
}
-rule MALPEDIA_Win_Svcready_Auto : FILE
+rule TRELLIX_ARC_Apt_Lagulon_Trojan_Pdb : TROJAN FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "18ab3505-c0ef-5267-b797-184b8eb52424"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.svcready"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.svcready_auto.yar#L1-L131"
- license_url = "N/A"
- logic_hash = "e011f730891f501adbcafbb04605066e1d9bcba49b0031ae67a9bae5fc387ad9"
+ description = "Rule to detect trojan Lagulon based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "a31a465d-1f16-5c3e-a62d-ea15c11253c3"
+ date = "2013-08-31"
+ modified = "2020-08-14"
+ reference = "https://www.cylance.com/operation-cleaver-cylance"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_lagulon_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "e401340020688cdd0f5051b7553815eee6bc04a5a962900883f1b3676bf1de53"
+ logic_hash = "dad04c2deb990f253f952b768b74349dc9afb5f6db91ea3afff889f4c9f3230b"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/lagulon"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 33c8 c1ca0d 33ce 8bc3 33c1 c1ce03 894c2418 }
- $sequence_1 = { 83611000 c741140f000000 68???????? c60100 e8???????? 8365fc00 }
- $sequence_2 = { 59 59 895dc0 895dc4 895dc8 8b4df4 8bc6 }
- $sequence_3 = { 8904d1 56 ff742410 8d4f04 e8???????? 8b44240c 5f }
- $sequence_4 = { 8bd8 8a0b 80f97f 0f855fffffff 8b54240c 8b4d18 }
- $sequence_5 = { d1cb 33d5 8bc7 c1e003 33da c1cd07 }
- $sequence_6 = { 33c3 8bd7 33c5 0bd3 8bda 0bd1 33d9 }
- $sequence_7 = { e8???????? 83c414 eb1a 53 57 e8???????? 668b442430 }
- $sequence_8 = { c645fc01 8d45d8 ff7508 53 6a10 83ec18 8bcc }
- $sequence_9 = { 7607 bbffffff7f eb0a b816000000 3bd8 0f42d8 8d4b01 }
+ $pdb = "\\proj\\wndTest\\Release\\wndTest.pdb"
condition:
- 7 of them and filesize <1187840
+ uint16(0)==0x5a4d and filesize <50KB and any of them
}
-rule MALPEDIA_Win_Tor_Loader_Auto : FILE
+rule TRELLIX_ARC_Apt_Miniasp_Pdb : TROJAN FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a70795d3-ed07-58b1-af1f-1705de4529bb"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tor_loader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tor_loader_auto.yar#L1-L134"
- license_url = "N/A"
- logic_hash = "5d8db358e57884a4955f1fc346221e8831cd43555daaec59fcf000e4dc8835e4"
+ description = "Rule to detect MiniASP based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "2e7e2990-5e7f-52b0-884a-fcb54b2f5488"
+ date = "2012-07-12"
+ modified = "2020-08-14"
+ reference = "https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_MiniASP_pdb.yar#L1-L26"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "42334f2119069b8c0ececfb14a7030e480b5d18ca1cc35f1ceaee847bc040e53"
+ logic_hash = "8ee6f93aaae2c48cc5835269fd526371040cd33cc309220f92a150444ba21055"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/MiniASP"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { eb29 488d7a38 e8???????? 4889df 488b4c2440 6690 e8???????? }
- $sequence_1 = { eb15 4c8d8f88000000 4889f8 4c89cf e8???????? 4889c7 488b4740 }
- $sequence_2 = { e8???????? 48c7400810000000 488d0da0490c00 488908 833d????????00 6690 7509 }
- $sequence_3 = { eb0c 41bc00000000 41bb00000000 0f8573feffff 4c8bac2480000000 4883bc248800000004 0f855cfeffff }
- $sequence_4 = { e9???????? 4c89542478 4983f901 7560 488d05a10e1900 bb01000000 4889d9 }
- $sequence_5 = { e8???????? 833d????????00 750e 488b8c24800d0000 48894818 eb11 488d7818 }
- $sequence_6 = { e8???????? 488d05ca2e1300 e8???????? 48c7400826000000 488d0d358f1800 488908 4889c3 }
- $sequence_7 = { e8???????? 488d05dc0e3100 bb04000000 e8???????? 488b8424d0000000 e8???????? 488d050b203100 }
- $sequence_8 = { eb38 488b8c24c0020000 488b11 488b4238 6690 e8???????? 83f001 }
- $sequence_9 = { e8???????? 48895c2450 4889c1 488d053fe00500 4889cb e8???????? 488b5c2450 }
+ $pdb = "\\Project\\mm\\Wininet\\Attack\\MiniAsp4\\Release\\MiniAsp.pdb"
+ $pdb1 = "\\XiaoME\\AiH\\20120410\\Attack\\MiniAsp3\\Release\\MiniAsp.pdb"
condition:
- 7 of them and filesize <13050880
+ uint16(0)==0x5a4d and filesize <80KB and any of them
}
-rule MALPEDIA_Win_Contopee_Auto : FILE
+rule TRELLIX_ARC_Enfal_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "77374f1e-6c89-5026-9b9e-741c43271a9e"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.contopee"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.contopee_auto.yar#L1-L123"
- license_url = "N/A"
- logic_hash = "887c3d1e6d8d0ed992ba95d9f863595a093876d8864d3c96b3a6d6d4a8e08fbb"
+ description = "Rule to detect Enfal malware"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "09b9667c-cf58-5438-958d-19a99fe91e32"
+ date = "2013-08-27"
+ modified = "2020-08-14"
+ reference = "https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/enfal"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/enfal_pdb.yar#L1-L29"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "6756808313359cbd7c50cd779f809bc9e2d83c08da90dbd80f5157936673d0bf"
+ logic_hash = "1f7785a4c54981c3e7cb417718312e0ed82132b9bd9288f7b0f322cbeafbaecd"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Enfal"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { c3 8bac244c020000 55 6a00 }
- $sequence_1 = { 83c41c eb35 8b5614 8b442430 6a00 6aff 42 }
- $sequence_2 = { 6880000000 50 8d8e6a050000 6880000000 51 }
- $sequence_3 = { 66896c240c 8d842414020000 50 57 ff15???????? }
- $sequence_4 = { 7510 ff15???????? 5f 5d 5b 81c4dc040000 c3 }
- $sequence_5 = { 8bf8 ebc8 ff15???????? 8bf8 ebd1 5f }
- $sequence_6 = { 7432 6a0f 51 50 e8???????? 8bf0 }
- $sequence_7 = { 8bd8 8b4608 83f802 8b44242c 0f858e000000 eb04 8b7c2418 }
- $sequence_8 = { 68???????? 51 ff15???????? 8b84243c020000 8d542428 52 50 }
- $sequence_9 = { 52 e8???????? 83c430 5f 5e }
+ $pdb = "\\Documents and Settings\\Administrator\\My Documents\\Work\\EtenFalcon\\Release\\DllServiceTrojan.pdb"
+ $pdb1 = "\\Documents and Settings\\Administrator\\My Documents\\Work\\EtenFalcon\\Release\\ServiceDll.pdb"
+ $pdb2 = "\\Release\\ServiceDll.pdb"
+ $pdb3 = "\\muma\\0511\\Release\\ServiceDll.pdb"
+ $pdb4 = "\\programs\\LuridDownLoader\\LuridDownloader for Falcon\\ServiceDll\\Release\\ServiceDll.pdb"
condition:
- 7 of them and filesize <180224
+ uint16(0)==0x5a4d and filesize <150KB and any of them
}
-rule MALPEDIA_Win_Sys10_Auto : FILE
+rule TRELLIX_ARC_Apt_Nix_Elf_Derusbi : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "01030a4d-1840-51b2-a9d0-6bbc4385fa1e"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sys10"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sys10_auto.yar#L1-L123"
- license_url = "N/A"
- logic_hash = "6943a43537b8ee069df094c74ea397f99150d4b78d4cfd8ed6ddb44f86656e07"
+ description = "Rule to detect the APT Derusbi ELF file"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "3b1c9644-7279-5e2c-8891-f03ca78cf3b7"
+ date = "2017-05-31"
+ modified = "2020-08-14"
+ reference = "https://attack.mitre.org/software/S0021/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Derusbi.yar#L1-L61"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "0a83566a0540d28d1cc0ebee01d29d15ddc86cabff9044fd8a198b847ba24c50"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 68
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:ELF/Derusbi"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 6a03 68???????? 68???????? 51 52 50 ff15???????? }
- $sequence_1 = { 837e04ff 740b 8b16 52 e8???????? 83c404 }
- $sequence_2 = { 8b4e0c 51 ff15???????? 8b5608 6aff 52 ff15???????? }
- $sequence_3 = { 56 e8???????? 83c404 85c0 74c6 8b4c2410 896e10 }
- $sequence_4 = { 6810270000 ff15???????? 33c0 59 }
- $sequence_5 = { 837e04ff 740b 8b16 52 }
- $sequence_6 = { 56 89442414 e8???????? 83c404 85c0 7541 }
- $sequence_7 = { 52 6a05 50 ffd6 8b5308 }
- $sequence_8 = { 8d4c2413 51 6800400000 52 50 e8???????? }
- $sequence_9 = { 8b13 52 ffd7 8b4304 50 ffd7 8b4b08 }
+ $s1 = "LxMain"
+ $s2 = "execve"
+ $s3 = "kill"
+ $s4 = "cp -a %s %s"
+ $s5 = "%s &"
+ $s6 = "dbus-daemon"
+ $s7 = "--noprofile"
+ $s8 = "--norc"
+ $s9 = "TERM=vt100"
+ $s10 = "/proc/%u/cmdline"
+ $s11 = "loadso"
+ $s12 = "/proc/self/exe"
+ $s13 = "Proxy-Connection: Keep-Alive"
+ $s14 = "Connection: Keep-Alive"
+ $s15 = "CONNECT %s"
+ $s16 = "HOST: %s:%d"
+ $s17 = "User-Agent: Mozilla/4.0"
+ $s18 = "Proxy-Authorization: Basic %s"
+ $s19 = "Server: Apache"
+ $s20 = "Proxy-Authenticate"
+ $s21 = "gettimeofday"
+ $s22 = "pthread_create"
+ $s23 = "pthread_join"
+ $s24 = "pthread_mutex_init"
+ $s25 = "pthread_mutex_destroy"
+ $s26 = "pthread_mutex_lock"
+ $s27 = "getsockopt"
+ $s28 = "socket"
+ $s29 = "setsockopt"
+ $s30 = "select"
+ $s31 = "bind"
+ $s32 = "shutdown"
+ $s33 = "listen"
+ $s34 = "opendir"
+ $s35 = "readdir"
+ $s36 = "closedir"
+ $s37 = "rename"
condition:
- 7 of them and filesize <286720
+ ( uint32(0)==0x4464c457f) and filesize <200KB and all of them
}
-rule MALPEDIA_Win_Unidentified_076_Auto : FILE
+rule TRELLIX_ARC_Apt_Nix_Elf_Derusbi_Kernelmodule : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c76f9b8e-5a48-5b08-ae0b-831af19ce579"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_076"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_076_auto.yar#L1-L134"
- license_url = "N/A"
- logic_hash = "afb3d60b25322ebd0dc1ef4a0c20812c54fa6c9c843b7734da080ace48ec2894"
+ description = "Rule to detect the Derusbi ELK Kernel module"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "1614a63d-c5d1-5ce1-a5b8-eb48325f60e6"
+ date = "2017-05-31"
+ modified = "2020-08-14"
+ reference = "https://attack.mitre.org/software/S0021/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Derusbi.yar#L63-L105"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "0b86e96ef616e926f0d665e2bd013f2773461483176c68bd5e7c7d059ac13d78"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:ELF/Derusbi"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 488b5370 488d4520 488bcb 4889442420 e8???????? 8bc8 eb7c }
- $sequence_1 = { 747b 8d5620 448bce 448bc5 33c9 ff97f8000000 48898748020000 }
- $sequence_2 = { 488bcf ff9080000000 33d2 33c9 4c63c0 85c0 7e29 }
- $sequence_3 = { 48894178 488b8f80000000 488b4618 48034f50 48898880000000 488b8f90000000 488b4618 }
- $sequence_4 = { 458d6502 448bc7 488bce 4489642428 89442420 e8???????? 85c0 }
- $sequence_5 = { 488d8d40150000 e8???????? 488d1587720000 488d8d14090000 8985d4000000 488d05c3130000 c7853001000000080000 }
- $sequence_6 = { 4533c9 488bcf 448d420c 48895c2420 e8???????? eb05 bb01000000 }
- $sequence_7 = { 7f0b 41b907000000 e9???????? 488b83c8000000 488b9360020000 488d8b5c060000 ff90f0070000 }
- $sequence_8 = { 89442420 e8???????? eb56 83f801 7529 8b8714120000 448b8f10120000 }
- $sequence_9 = { 415e 415c c3 817d0c08020000 7c05 458bcc eba2 }
+ $s1 = "__this_module"
+ $s2 = "init_module"
+ $s3 = "unhide_pid"
+ $s4 = "is_hidden_pid"
+ $s5 = "clear_hidden_pid"
+ $s6 = "hide_pid"
+ $s7 = "license"
+ $s8 = "description"
+ $s9 = "srcversion="
+ $s10 = "depends="
+ $s11 = "vermagic="
+ $s12 = "current_task"
+ $s13 = "sock_release"
+ $s14 = "module_layout"
+ $s15 = "init_uts_ns"
+ $s16 = "init_net"
+ $s17 = "init_task"
+ $s18 = "filp_open"
+ $s19 = "__netlink_kernel_create"
+ $s20 = "kfree_skb"
condition:
- 7 of them and filesize <114688
+ ( uint32(0)==0x4464c457f) and filesize <200KB and all of them
}
-rule MALPEDIA_Win_Scranos_Auto : FILE
+rule TRELLIX_ARC_Apt_Nix_Elf_Derusbi_Linux_Sharedmemcreation : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "366bbb3b-fd76-5e48-ad2c-11dfe56c53aa"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scranos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.scranos_auto.yar#L1-L134"
- license_url = "N/A"
- logic_hash = "5a9a306a889eeb594e8f9ae05b85780def5b0ff2c4ea6f54823c4b6d5baa27b1"
+ description = "Rule to detect Derusbi Linux Shared Memory creation"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "8d2db62e-22fa-5bbe-ab65-f294fc911b82"
+ date = "2017-05-31"
+ modified = "2020-08-14"
+ reference = "https://attack.mitre.org/software/S0021/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Derusbi.yar#L107-L130"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "095af979728f3b71e3192140306e4aa76011e07a25b20b0c5b3b98db41411714"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:ELF/Derusbi"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { e8???????? 83c404 8b55cc 8d440201 8945cc ebb5 8b4de4 }
- $sequence_1 = { 8b8e70010000 8d542430 52 8b966c010000 8d442438 50 8d86b0030000 }
- $sequence_2 = { eb13 8b4608 8b4e04 8b16 50 51 52 }
- $sequence_3 = { e8???????? 83c428 e9???????? 8b55ec 8b42e4 50 8b4df4 }
- $sequence_4 = { e8???????? 83c40c 85c0 0f8515070000 8b54241c 52 56 }
- $sequence_5 = { 89834c010000 7523 8b542410 52 8d442420 50 8d8bc8000000 }
- $sequence_6 = { 8b4d24 e8???????? 8945a0 8b4da0 894d9c c745fc00000000 8d55ac }
- $sequence_7 = { 8b55e8 8b849544ffffff 89448d8c 8b4de8 8b948d30ffffff 8b4248 8b4de8 }
- $sequence_8 = { 8b6c2410 57 8b7d00 8b87840c0000 81c7680c0000 8d4f0c 8944240c }
- $sequence_9 = { c645fc00 8d4dc8 e8???????? c745fcffffffff 8d4da8 e8???????? 8b4594 }
+ $byte1 = { B6 03 00 00 ?? 40 00 00 00 ?? 0D 5F 01 82 }
condition:
- 7 of them and filesize <2859008
+ ( uint32(0)==0x464C457F) and filesize <200KB and all of them
}
-rule MALPEDIA_Win_Sphijacker_Auto : FILE
+rule TRELLIX_ARC_Apt_Nix_Elf_Derusbi_Linux_Strings : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "02bebd5c-3234-51fc-b1c7-c2b759df0e10"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sphijacker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sphijacker_auto.yar#L1-L124"
- license_url = "N/A"
- logic_hash = "b2eaf40d7ebf7c9c6d61e8db2a040734266a57e7998ddc628afd90d30231d5ef"
+ description = "Rule to detect APT Derusbi Linux Strings"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "09e47580-9b20-5461-943e-32b932c36214"
+ date = "2017-05-31"
+ modified = "2020-08-14"
+ reference = "https://attack.mitre.org/software/S0021/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Derusbi.yar#L132-L173"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "0e95497c44a0c1d85936a6a072063720a771b7e1eb8da2377e54577e3fc2764e"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 68
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:ELF/Derusbi"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 488b0d???????? 488d1d19080200 483bcb 740c }
- $sequence_1 = { 8b7808 e9???????? 488b55c8 4c8d05cbb10100 }
- $sequence_2 = { 4c8d056b740100 83e23f 488bcf 48c1f906 488d14d2 498b0cc8 8064d138fd }
- $sequence_3 = { 7c68 488b4718 488b08 420fb70451 2500800000 7455 488b8360040000 }
- $sequence_4 = { 488bd1 488bc1 48c1f806 4c8d05e4bd0100 83e23f 488d14d2 498b04c0 }
- $sequence_5 = { 33d2 f20f100d???????? 41b8ee010000 66898dc8070000 }
- $sequence_6 = { e8???????? 448ba560010000 8b4c2440 488d15d9e8feff 2b4c2444 41b826000000 894c2440 }
- $sequence_7 = { c744242804000000 488d1585e10100 41b904000000 4889442420 4533c0 c7451088888888 ff15???????? }
- $sequence_8 = { ff15???????? 488b4d18 4c8d4520 488d159ee00100 ff15???????? 488b4d20 }
- $sequence_9 = { 8b4814 c1e90c 4184cd 740e 488b8360040000 4883780800 7419 }
+ $a1 = "loadso" wide ascii fullword
+ $a2 = "\nuname -a\n\n" wide ascii
+ $a3 = "/dev/shm/.x11.id" wide ascii
+ $a4 = "LxMain64" wide ascii nocase
+ $a5 = "# \\u@\\h:\\w \\$ " wide ascii
+ $b1 = "0123456789abcdefghijklmnopqrstuvwxyz" wide
+ $b2 = "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ" wide
+ $b3 = "ret %d" wide fullword
+ $b4 = "uname -a\n\n" wide ascii
+ $b5 = "/proc/%u/cmdline" wide ascii
+ $b6 = "/proc/self/exe" wide ascii
+ $b7 = "cp -a %s %s" wide ascii
+ $c1 = "/dev/pts/4" wide ascii fullword
+ $c2 = "/tmp/1408.log" wide ascii fullword
condition:
- 7 of them and filesize <808960
+ uint32(0)==0x464C457F and filesize <200KB and ((1 of ($a*) and 4 of ($b*)) or (1 of ($a*) and 1 of ($c*)) or 2 of ($a*) or all of ($b*))
}
-rule MALPEDIA_Win_Iispy_Auto : FILE
+rule TRELLIX_ARC_Troy_Malware_Campaign_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "204a2c38-8895-5ac0-a1fb-2cdf3f008fea"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.iispy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.iispy_auto.yar#L1-L130"
- license_url = "N/A"
- logic_hash = "7326802c4105c66879b54e4bc2a70df2a9f75047a51ff2245fe60a57fbe51d36"
+ description = "Rule to detect the Operation Troy based on the PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "c1fc5b9c-104f-5d07-86ee-5a54d9731f04"
+ date = "2013-06-23"
+ modified = "2020-08-14"
+ reference = "https://www.mcafee.com/enterprise/en-us/assets/white-papers/wp-dissecting-operation-troy.pdf"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_operation_troy.yar#L1-L26"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "2ca6b7e9488c1e9f39392e696704ad3f2b82069e35bc8001d620024ebbf2d65a"
+ logic_hash = "a64b4aa082c45d1753ad30ba2f67df0ef5b7658c3c99e031ef747eb4e6c7bb00"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/OperationTroy"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { ebdc 837b1800 0f85f6000000 3bce 7436 8a01 3c5d }
- $sequence_1 = { d1e8 03d0 8b5e0c 8b7d08 2bd9 03fb }
- $sequence_2 = { 85c0 755e f7459c00100000 7503 8b7608 }
- $sequence_3 = { ff2485887a0010 51 8bcf e8???????? 8b17 8b4210 2b420c }
- $sequence_4 = { 6a00 ff75e4 c745e800000000 ffd6 85c0 0f856effffff eb0c }
- $sequence_5 = { 85f6 0f84c1010000 0fb7460e 8bc8 c1e90a f6c101 }
- $sequence_6 = { 0f1145c8 8b4810 894dc4 b903000000 0f1100 6689480e 8d4dc8 }
- $sequence_7 = { 8955b4 8d0409 50 6a00 52 e8???????? b800100000 }
- $sequence_8 = { f6430801 7411 8d5304 8bcf e8???????? 5f 5e }
- $sequence_9 = { 8b742424 8b7c2420 884c240b 89742410 897c241c e9???????? 3bf8 }
+ $pdb = "\\Work\\Make Troy\\Concealment Troy\\Exe_Concealment_Troy(Winlogon_Shell)\\SetKey_WinlogOn_Shell_Modify\\BD_Installer\\Release\\BD_Installer.pdb"
+ $pdb1 = "\\Work\\Make Troy\\Concealment Troy\\Exe_Concealment_Troy(Winlogon_Shell)\\Dll\\Concealment_Troy(Dll)\\Release\\Concealment_Troy.pdb"
condition:
- 7 of them and filesize <397312
+ uint16(0)==0x5a4d and filesize <500KB and any of them
}
-rule MALPEDIA_Win_9002_Auto : FILE
+rule TRELLIX_ARC_Apt_Aurora_Pdb_Samples : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "49e80af5-ef9d-5bf8-b3b9-b7af1f356471"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.9002"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.9002_auto.yar#L1-L290"
- license_url = "N/A"
- logic_hash = "9d293b5dc33eac56c2e3f0cda3054624c24835d742e33a63df2c2aa725e52d40"
+ description = "Aurora APT Malware 2006-2010"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "51b080b7-671b-592b-ba52-7fdd0ddf0294"
+ date = "2010-01-11"
+ modified = "2020-08-14"
+ reference = "https://en.wikipedia.org/wiki/Operation_Aurora"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_operation_aurora.yar#L1-L26"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "ce7debbcf1ca3a390083fe5753f231e632017ca041dfa662ad56095a500f2364"
+ logic_hash = "5791ae7b96f2b59d0cca1ab97455bb4745edad8980ac4aff22aa36e0bc4f240e"
score = 75
- quality = 73
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Aurora"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 7514 8b4714 8b08 51 e8???????? 8b5714 }
- $sequence_1 = { 51 8944241c c744241801000000 ff15???????? 3d02010000 }
- $sequence_2 = { 7504 33ed eb04 2bc8 }
- $sequence_3 = { 8bd1 2bd0 3bda 7223 }
- $sequence_4 = { 6a02 ff15???????? 68???????? ff15???????? 6a00 }
- $sequence_5 = { 8b5c2408 6bdb08 03c3 8b00 }
- $sequence_6 = { 33c9 3bc8 1bd2 f7da 8915???????? }
- $sequence_7 = { 03c3 8b00 5b ffd0 8945fc }
- $sequence_8 = { 51 e8???????? 6a06 6a01 6a02 e8???????? }
- $sequence_9 = { 8be9 53 50 e8???????? }
- $sequence_10 = { 7504 33d2 eb05 8b5608 2bd0 3bfa }
- $sequence_11 = { 682c010000 50 ffd3 3d02010000 7508 }
- $sequence_12 = { 6a00 6a02 6a03 6a00 e8???????? }
- $sequence_13 = { 75f6 eb2f 8b542430 8b7c2414 8b6c2430 }
- $sequence_14 = { 668b3c59 730d 33c9 8a0a }
- $sequence_15 = { 59 8b0485e0d50010 8d0cf6 8064880400 85ff }
- $sequence_16 = { 0311 8955fc 837df800 0f86e3000000 8b4508 03450c 2b45f8 }
- $sequence_17 = { 68???????? 8d4610 50 8d4c2418 51 ff15???????? }
- $sequence_18 = { 896f2c 8b4748 3bc5 740c 50 }
- $sequence_19 = { 8d4c240c c644243002 ff15???????? 8bc6 }
- $sequence_20 = { 6a00 8bd8 51 57 53 }
- $sequence_21 = { 8b4c242c 5f 89411c 8b442410 895118 8b542434 894124 }
- $sequence_22 = { 33c4 50 8d442428 64a300000000 8bf1 89742408 68???????? }
- $sequence_23 = { 8939 89742410 e9???????? 33f6 83ff14 }
- $sequence_24 = { 0fb74e08 0fafcf 5f 03c1 5e }
- $sequence_25 = { 031481 52 8b450c 50 }
- $sequence_26 = { 5d 83c410 c3 8b4508 85c0 7499 }
- $sequence_27 = { 2bc5 c1ef05 2bcf 2bf5 66898c5a98010000 33c9 }
- $sequence_28 = { 64a300000000 8b7c2444 8bf1 33db 57 8d4e10 89742414 }
- $sequence_29 = { 8b742408 57 85f6 742e 0fb74602 8b7c2410 3bf8 }
- $sequence_30 = { 8b5c2424 3bcb 0f83f6040000 33db }
+ $pdb = "\\AuroraVNC\\VedioDriver\\Release\\VedioDriver.pdb"
+ $pdb1 = "\\Aurora_Src\\AuroraVNC\\Avc\\Release\\AVC.pdb"
condition:
- 7 of them and filesize <204800
+ uint16(0)==0x5a4d and filesize <150KB and any of them
}
-rule MALPEDIA_Win_Unidentified_042_Auto : FILE
+rule TRELLIX_ARC_Ixeshe_Bled_Malware_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9e093b61-c910-5742-8226-775531f91d9d"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_042"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_042_auto.yar#L1-L132"
- license_url = "N/A"
- logic_hash = "7aca5d090ae8281044c7e148c75c276642daf90859ffb2907ade4921d2dec5c9"
+ description = "Rule to detect Ixeshe_bled malware based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "93356eab-5bb3-5b85-acc6-9a247554aa2d"
+ date = "2012-05-30"
+ modified = "2020-08-14"
+ reference = "https://attack.mitre.org/software/S0015/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/ixeshe_bled_pdb.yar#L1-L24"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "d1be51ef9a873de85fb566d157b034234377a4a1f24dfaf670e6b94b29f35482"
+ logic_hash = "7d2ce7644e25a56c101c148a32f7b0f7c3185c0c17f4d65eaef257f6ac7f8ffb"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Ixeshe"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 85c0 754f 6a02 53 56 8d8d9cfeffff 57 }
- $sequence_1 = { 56 8d8d68e1ffff 51 8d9554f7ffff 52 89b550f7ffff }
- $sequence_2 = { 5b 85c0 78dd 8b45fc 8b55f8 0fb64c3801 4a }
- $sequence_3 = { 8b4db8 895640 8b9518fdffff 895620 8b9520fdffff 894e44 8b8d1cfdffff }
- $sequence_4 = { 8d8580cbffff 50 6a00 ff15???????? 85c0 7527 8b1d???????? }
- $sequence_5 = { 5e 8bc7 5f 5d c3 8b7514 85f6 }
- $sequence_6 = { 8bc3 2bc2 8d0c91 2bf0 42 8d3c87 3bf2 }
- $sequence_7 = { 85db 0f85af000000 8d45ac 8bf0 8d5d9c 50 }
- $sequence_8 = { 8d4df8 51 8d5df4 e8???????? 83c408 85c0 780d }
- $sequence_9 = { 52 50 8d4b70 e8???????? 83c408 85c0 0f850b020000 }
+ $pdb = "\\code\\Blade2009.6.30\\Blade2009.6.30\\EdgeEXE_20003OC\\Debug\\EdgeEXE.pdb"
condition:
- 7 of them and filesize <516096
+ uint16(0)==0x5a4d and filesize <200KB and any of them
}
-rule MALPEDIA_Win_Moriya_Auto : FILE
+rule TRELLIX_ARC_Apt_Hanover_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b9f54a0c-1b70-575c-9b58-fd559fcd85cb"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moriya"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.moriya_auto.yar#L1-L123"
- license_url = "N/A"
- logic_hash = "ab28f31770f9afce25a3c5b829bb0d33a4cf408b2c3f7c40efc1893d68c2419a"
+ description = "Rule to detect hanover samples based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "e2476ae8-d284-58f5-8bcb-9313a5b4d756"
+ date = "2012-01-05"
+ modified = "2020-08-14"
+ reference = "https://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_hangover.yar#L1-L39"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "a2460412575cdc187dfb69eb2847c5b43156af7f7d94b71422e7f771e8adb51e"
+ logic_hash = "a37d528e4dacddcabe55261f16b51aec626f6180107f154d3ae34cdfa71e2c58"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Hanover"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8bce ff15???????? 4533c0 488d0dcf260000 33d2 }
- $sequence_1 = { 488bfa 4c8d051c0d0000 33d2 8d5a4d 8bcb ff15???????? 4c8d05280d0000 }
- $sequence_2 = { 8b4f10 8d81fffeffff 83f801 7608 81f910010000 7564 ba28000000 }
- $sequence_3 = { 448d724d 418bce 0f114dc0 0f1145d0 ff15???????? }
- $sequence_4 = { 4885c0 7509 4c8d05b60f0000 eba3 4c8d05dd0f0000 ff15???????? }
- $sequence_5 = { ff15???????? 488b8c2498000000 4885c9 7405 e8???????? }
- $sequence_6 = { ff15???????? 8bc3 488b8c2488000000 4833cc e8???????? 4881c490000000 415f }
- $sequence_7 = { 33d2 ff15???????? 4883673800 488b0d???????? 4885c9 7467 }
- $sequence_8 = { 4c8bc3 49ffc0 42803c0000 75f6 488b15???????? }
- $sequence_9 = { 488b0d???????? 4885c9 7405 e8???????? 8bc7 488b4df0 }
+ $pdb = "\\andrew\\Key\\Release\\Keylogger_32.pdb"
+ $pdb1 = "\\BACK_UP_RELEASE_28_1_13\\General\\KG\\Release\\winsvcr.pdb"
+ $pdb2 = "\\BackUP-Important\\PacketCapAndUpload_Backup\\voipsvcr\\Release\\voipsvcr.pdb"
+ $pdb3 = "\\BNaga\\kaam\\New_FTP_2\\Release\\ftpback.pdb"
+ $pdb4 = "\\DD0\\DD\\u\\Release\\dataup.pdb"
+ $pdb5 = "\\Documents and Settings\\Admin\\Desktop\\Newuploader\\Release\\Newuploader.pdb"
+ $pdb6 = "\\Documents and Settings\\Admin\\Desktop\\Uploader Code\\Release\\Newuploader.pdb"
+ $pdb7 = "\\Documents and Settings\\Administrator\\Desktop\\nn\\Release\\nn.pdb"
+ $pdb8 = "\\smse\\Debug\\smse.pdb"
+ $pdb9 = "\\Users\\admin\\Documents\\Visual Studio 2008\\Projects\\DNLDR-no-ip\\Release\\DNLDR.pdb"
+ $pdb10 = "\\final exe\\check\\Release\\check.pdb"
+ $pdb11 = "\\Projects\\Elance\\AppInSecurityGroup\\FtpBackup\\Release\\Backup.pdb"
+ $pdb12 = "\\projects\\windows\\MailPasswordDecryptor\\Release\\MailPasswordDecryptor.pdb"
+ $pdb13 = "\\final project backup\\UPLODER FTP BASED\\New folder\\Tron 1.2.1(Ftp n Startup)\\Release\\Http_t.pdb"
condition:
- 7 of them and filesize <58368
+ uint16(0)==0x5a4d and filesize <1000KB and any of them
}
-rule MALPEDIA_Win_Magic_Rat_Auto : FILE
+rule TRELLIX_ARC_Apt_Hanover_Appinbot_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fef12775-f5d4-5648-9916-cb915f91f28b"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.magic_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.magic_rat_auto.yar#L1-L111"
- license_url = "N/A"
- logic_hash = "d23de63f3611a6306ebe3970ddd7285c351120d5c12dbd45ba2d1d594ef068a3"
- score = 60
- quality = 45
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ description = "Rule to detect hanover appinbot samples based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "fb201000-ca8b-57e0-b560-5082477d8ee7"
+ date = "2012-01-05"
+ modified = "2020-08-14"
+ reference = "https://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_hangover.yar#L41-L77"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "6ad56d64444fa76e1ad43a8c260c493b9086d4116eb18af630e65d3fd39bf6d6"
+ logic_hash = "56cdd22efd81bcdda445242257b2418c6941bf9e5e68065d8b8d73d0f9c27df5"
+ score = 75
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Hanover"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 85c0 7407 3dffff0000 756f }
- $sequence_1 = { f20f2ac9 f20f5cc1 f20f58c3 f20f2cc0 }
- $sequence_2 = { 0f84b8000000 83faff 7408 f0830001 }
- $sequence_3 = { 660f2ec2 7308 660f5705???????? 660f2ee2 f20f59c5 7308 660f5725???????? }
- $sequence_4 = { 29c2 89d0 c1f80e f7d8 eb08 }
- $sequence_5 = { 8b01 81e20080ffff 25ff7f0000 09d0 }
- $sequence_6 = { 8b4500 85c0 0f8472010000 83f8ff 740b f0836d0001 }
- $sequence_7 = { f20f58c3 f20f2cd0 01ca e9???????? }
- $sequence_8 = { 85d2 740b 83faff 74ad f0832801 }
- $sequence_9 = { 81fa???????? 7442 81fa???????? 744a }
+ $pdb = "\\BNaga\\backup_28_09_2010\\threads tut\\pen-backup\\BB_FUD_23\\Copy of client\\Copy of client\\appinbot_1.2_120308\\Build\\Win32\\Release\\appinclient.pdb"
+ $pdb1 = "\\BNaga\\SCode\\BOT\\MATRIX_1.2.2.0\\appinbot_1.2_120308\\Build\\Win32\\Release\\deleter.pdb"
+ $pdb2 = "\\Documents and Settings\\Admin\\Desktop\\appinbot_1.2_120308\\appinclient\\Build\\Win32\\Release\\appinclient.pdb"
+ $pdb3 = "\\Documents and Settings\\Administrator\\Desktop\\Backup\\17_8_2011\\MATRIX_1.3.4\\ CLIENT\\Build\\Win32\\Release\\appinclient.pdb"
+ $pdb4 = "\\Documents and Settings\\Administrator\\Desktop\\Backup\\17_8_2011\\MATRIX_1.3.4\\ MATRIX_1.3.4\\CLIENT\\Build\\Win32\\Release\\appinclient.pdb"
+ $pdb5 = "\\Documents and Settings\\Administrator\\Desktop\\Backup\\17_8_2011\\MATRIX_1.3.4\\MATRIX_1.3.4\\ CLIENT\\Build\\Win32\\Release\\deleter.pdb"
+ $pdb6 = "\\pen-backup\\Copy of client\\Copy of client\\appinbot_1.2_120308\\Build\\Win32\\Release\\appinclient.pdb"
+ $pdb7 = "\\pen-backup\\Copy of client\\Copy of client\\appinbot_1.2_120308\\Build\\Win32\\Release\\deleter.pdb"
+ $pdb8 = "\\temp\\elance\\PROTOCOL_1.2\\Build\\Win32\\Release\\deleter.pdb"
+ $pdb9 = "\\Users\\PRED@TOR\\Desktop\\appinbot_1.2_120308\\Build\\Win32\\Release\\deleter.pdb"
+ $pdb10 = "\\Users\\PRED@TOR\\Desktop\\MODIFIED PROJECT LAB\\admin\\Build\\Win32\\Release\\appinclient.pdb"
+ $pdb11 = "\\Desktop backup\\Copy\\appinbot_1.2_120308\\Build\\Win32\\Release\\appinclient.pdb"
+ $pdb12 = "\\Datahelp\\SCode\\BOT\\MATRIX_1.3.3\\CLIENT\\Build\\Win32\\Release\\appinclient.pdb"
condition:
- 7 of them and filesize <41843712
+ uint16(0)==0x5a4d and filesize <440KB and any of them
}
-rule MALPEDIA_Win_Miniblindingcan_Auto : FILE
+rule TRELLIX_ARC_Apt_Hanover_Foler_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "92bc3e0e-6544-5def-8326-ac0c583fd403"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miniblindingcan"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.miniblindingcan_auto.yar#L1-L129"
- license_url = "N/A"
- logic_hash = "7b8607880b97335be49c71c4d350efefeb788c1420c4ead3bd8ed006de1090db"
+ description = "Rule to detect hanover foler samples"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "064b12a1-7a6a-5a19-bc9a-c98c1dbc6631"
+ date = "2012-01-05"
+ modified = "2020-08-14"
+ reference = "https://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_hangover.yar#L79-L106"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "bd77d7f8af8329dfb0bcc0624d6d824d427fbaf859ab2dedd8629aa2f3b7ae0d"
+ logic_hash = "cd2bd6a4c8084c02af5aaba81529cdb67aab7c2db397e2757d383534123c5227"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Hanover"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 899424b0000000 81faff000000 7c37 b881808080 488bce f7e2 c1ea07 }
- $sequence_1 = { 8bc6 45338c8c600a0200 c1e808 c1eb08 41c1ea10 0fb6c8 410fb6c0 }
- $sequence_2 = { 48ffc1 49ffc8 75ed 488b542428 4c8d442420 488bce e8???????? }
- $sequence_3 = { 660f6e7310 488d4c2438 f30fe6f6 ff15???????? 488d542430 488d4c2438 ff15???????? }
- $sequence_4 = { 483b442420 0f8710040000 4883fd0f 0f82e7030000 488d7df1 c606f0 }
- $sequence_5 = { 488d0579340000 488905???????? e9???????? 81fb39380000 7513 488d0553340000 488905???????? }
- $sequence_6 = { 48ffc6 448bc1 f7e1 c1ea07 4c89442430 8bc2 }
- $sequence_7 = { 488bc8 ff15???????? 488d1528a70000 488bce 488905???????? ff15???????? 488bc8 }
- $sequence_8 = { 488b4590 83a0c8000000fd 83c8ff e9???????? 4183cfff f6431840 4c8d0dc50dffff }
- $sequence_9 = { 740a b801000000 e9???????? 4533c9 }
+ $pdb = "\\Documents and Settings\\Administrator\\Desktop\\nn\\Release\\nn.pdb"
+ $pdb1 = "\\Documents and Settings\\Administrator\\Desktop\\UsbP\\Release\\UsbP.pdb"
+ $pdb2 = "\\Documents and Settings\\Administrator\\Desktop\\UsbP\\UsbP - u\\Release\\UsbP.pdb"
+ $pdb3 = "\\Monthly Task\\August 2011\\USB Prop\\Usb Propagator.09-24\\nn\\Release\\nn.pdb"
condition:
- 7 of them and filesize <453632
+ uint16(0)==0x5a4d and filesize <480KB and any of them
}
-rule MALPEDIA_Win_Cosmicduke_Auto : FILE
+rule TRELLIX_ARC_Apt_Hanover_Linog_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a26b55b5-f92c-59e0-aeb7-97b4045e507d"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cosmicduke"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cosmicduke_auto.yar#L1-L131"
- license_url = "N/A"
- logic_hash = "ac4cc48798cdbb14b22137cd5139a9905a17da02e3b6c8aa744a86c9cd8ba953"
+ description = "Rule to detect hanover linog samples based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "2f4d30ad-aadc-5c90-8234-d1b5802f4781"
+ date = "2012-01-05"
+ modified = "2020-08-14"
+ reference = "https://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_hangover.yar#L108-L132"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "f6319fd0e1d3b9d3694c46f80208e70b389e7dcc6aaad2508b80575c604c5dba"
+ logic_hash = "3aebafc80ca2e187bdcae3750162d94ce9419988ffd451ba4762b2d299a04ed7"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Hanover"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { ff542418 83c602 47 3b742428 72ce 8b4514 }
- $sequence_1 = { ff8688050000 b001 5f c3 6a1f 5a 8bc1 }
- $sequence_2 = { c1e104 03cb 898439142c0000 e9???????? 3975e4 7408 ff75e4 }
- $sequence_3 = { 8d7c241c e8???????? 3ac3 0f84ac010000 8b442420 89442430 8d842438200000 }
- $sequence_4 = { 85db 7507 32c0 e9???????? 837d1400 74f3 807d1000 }
- $sequence_5 = { 6a01 68???????? 56 53 e8???????? b001 5f }
- $sequence_6 = { 8bc7 8d4c2414 e8???????? 53 8d44243c 50 }
- $sequence_7 = { e8???????? 0fb7c0 894510 6685c0 7512 33c0 40 }
- $sequence_8 = { ff7508 8bf0 8d85ecfdffff 50 ff15???????? 8b3d???????? }
- $sequence_9 = { e8???????? 84c0 742f 838c244c300000ff 8d74240c e8???????? 8b4508 }
+ $pdb = "\\Users\\hp\\Desktop\\download\\Release\\download.pdb"
+ $pdb1 = "\\Backup-HP-ABCD-PC\\download\\Release\\download.pdb"
condition:
- 7 of them and filesize <456704
+ uint16(0)==0x5a4d and filesize <165KB and any of them
}
-rule MALPEDIA_Win_Apocalipto_Auto : FILE
+rule TRELLIX_ARC_Apt_Hanover_Ron_Babylon_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ee7a0f0d-5a8b-59ea-a6c9-35fc5d51d457"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.apocalipto"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.apocalipto_auto.yar#L1-L123"
- license_url = "N/A"
- logic_hash = "ab10b935b7f8e9ea80933c4818fa1b5859216a7e2d022a7818f118074140bb2a"
+ description = "apt_hanover_ron_babylon"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "2637bba5-67be-5e71-9ce3-570ea14a96df"
+ date = "2012-01-05"
+ modified = "2020-08-14"
+ reference = "https://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_hangover.yar#L134-L200"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "784cfb1bfdd7080c658fad08b1f679bbb0c94e6e468a3605ea47cdce533df815"
+ logic_hash = "212de25a555335eb4dc24052702ee30d71039f44b448079f19f12fcb775d5298"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 45
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Hanover"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 880e b967666666 89d8 f7e9 89d1 c1f902 }
- $sequence_1 = { 8817 41 47 39f1 75f5 c6040800 5b }
- $sequence_2 = { c7042400000000 ff15???????? 52 8985ccf3ffff e8???????? 2500f0ffff 8d9800f0ffff }
- $sequence_3 = { 8b5584 29f2 89542404 893c24 e8???????? c745e400000000 }
- $sequence_4 = { 8b4154 89442408 895c2404 893424 }
- $sequence_5 = { 83ec2c 8b4d08 8b450c 85c0 0f849d000000 }
- $sequence_6 = { e8???????? 8d95e8f7ffff 89542404 893c24 e8???????? 89c2 85c0 }
- $sequence_7 = { 8d3c10 31c9 8a140b 8817 }
- $sequence_8 = { 891c24 ff15???????? 83ec08 a3???????? 85c0 0f8497080000 }
- $sequence_9 = { 0f84cb080000 c7442404???????? 891c24 ff15???????? 83ec08 a3???????? 85c0 }
+ $pdb = "\\Users\\hp\\Desktop\\download\\Release\\download.pdb"
+ $pdb1 = "\\26_10_2010\\demoMusic\\Release\\demoMusic.pdb"
+ $pdb2 = "\\26_10_2010\\New_FTP_HttpWithLatestfile2\\Release\\httpbackup.pdb"
+ $pdb3 = "\\26_10_2010\\New_FTP_HttpWithLatestfile2_FirstBlood_Released\\ New_FTP_HttpWithLatestfile2\\Release\\FirstBloodA1.pdb"
+ $pdb4 = "\\app\\Http_t\\Release\\Crveter.pdb"
+ $pdb5 = "\\BNaga\\kaam\\Appin SOFWARES\\RON 2.0.0\\Release\\Ron.pdb"
+ $pdb6 = "\\BNaga\\kaam\\kaam\\NEW SOFWARES\\firstblood\\Release\\FirstBloodA1.pdb"
+ $pdb7 = "\\BNaga\\kaam\\kaam\\New_FTP_HttpWithLatestfile2_FirstBlood_Released\\ New_FTP_HttpWithLatestfile2\\Release\\Ron.pdb"
+ $pdb8 = "\\BNaga\\kaam\\New_FTP_HttpWithLatestfile2_FirstBlood_Released\\ New_FTP_HttpWithLatestfile2\\Release\\FirstBloodA1.pdb"
+ $pdb9 = "\\BNaga\\My Office kaam\\Appin SOFWARES\\HTTP\\RON 2.0.0\\Release\\Ron.pdb"
+ $pdb10 = "\\Documents and Settings\\abc\\Desktop\\Dragonball 1.0.2(WITHOUT DOWNLOAD LINK)\\Release\\Ron.pdb"
+ $pdb11 = "\\Documents and Settings\\Administrator\\Desktop\\Feb 2012\\kmail(httpform1.1) 02.09\\Release\\kmail.pdb"
+ $pdb12 = "\\MNaga\\My Office kaam\\Appin SOFWARES\\HTTP\\RON 2.0.0\\Release\\Ron.pdb"
+ $pdb13 = "\\N\\kl\\Release\\winlsa.pdb"
+ $pdb14 = "\\N\\sr\\Release\\waulct.pdb"
+ $pdb15 = "\\Release\\wauclt.pdb"
+ $pdb16 = "\\Users\\neeru rana\\Desktop\\Klogger- 30 may\\Klogger- 30 may\\Release\\Klogger.pdb"
+ $pdb17 = "\\december task backup\\TRINITY PAYLOAD\\Dragonball 1.0.0(WITHOUT DOWNLOAD LINK)\\Release\\Ron.pdb"
+ $pdb18 = "\\Documents and Settings\\appin\\Desktop\\New_FTP_1\\New_FTP_1\\Release\\HTTP_MyService.pdb"
+ $pdb19 = "\\May Payload\\new keylogger\\Flashdance1.0.2\\kmail(http) 01.20\\Release\\kmail.pdb"
+ $pdb20 = "\\Monthly Task\\September 2011\\HangOver 1.3.2 (Startup)\\Release\\Http_t.pdb"
+ $pdb21 = "\\Sept 2012\\Keylogger\\Release\\Crveter.pdb"
+ $pdb22 = "\\Datahelp\\keytest1\\keytest\\taskmng.pdb"
+ $pdb23 = "\\Datahelp\\UPLO\\HTTP\\HTTP_T\\17_05_2011\\Release\\Http_t.pdb"
+ $pdb24 = "\\Datahelp\\UPLO\\HTTP\\HTTP_T\\20_05_2011\\Release\\Http_t.pdb"
+ $pdb25 = "\\June mac paylods\\final Klogger-1 june-Fud from eset5.0\\Klogger- 30 may\\Klogger- 30 may\\Release\\Klogger.pdb"
+ $pdb26 = "\\June mac paylods\\Keylo ger backup\\final Klogger-1 june-Fud from eset5.0\\Klogger- 30 may\\Klogger- 30 may\\Release\\kquant.pdb"
+ $pdb27 = "\\June mac paylods\\Keylogger backup\\final Klogger-1 june-Fud from eset5.0\\Klogger- 30 may\\Klogger- 30 may\\Release\\kquant.pdb"
+ $pdb28 = "\\My\\lan scanner\\Task\\HangOver 1.2.2\\Release\\Http_t.pdb"
+ $pdb29 = "\\New folder\\paylod backup\\OTHER\\Uploder\\HangOver 1.5.7 (Startup)\\HangOver 1.5.7 (Startup)\\Release\\Http_t.pdb"
+ $pdb30 = "\\keyloger\\KeyLog\\keytest1\\keytest\\taskmng.pdb"
+ $pdb31 = "\\august\\13 aug\\HangOver 1.5.7 (Startup) uploader\\Release\\Http_t.pdb"
+ $pdb32 = "\\backup E\\SourceCodeBackup\\september\\aradhana\\HangOver 1.5.3 (Startup)\\Release\\Http_t.pdb"
+ $pdb33 = "\\payloads\\new backup feb\\SUNDAY\\kmail(http) 01.20\\kmail(http) 01.20\\Release\\kmail.pdb"
+ $pdb34 = "\\payloads\\ita nagar\\Uploader\\HangOver 1.5.7 (Startup)\\HangOver 1.5.7 (Startup)\\Release\\Http_t.pdb"
+ $pdb35 = "\\final project backup\\task information\\task of september\\Tourist 2.4.3 (Down Link On Resource) -L\\Release\\Ron.pdb"
+ $pdb36 = "\\final project backup\\complete task of ad downloader & usb grabber&uploader\\New folder\\with icon +shortcut link\\HangOver 1.5.3 (Startup)\\Release\\Http_t.pdb"
+ $pdb37 = "\\final project backup\\uploader version backup\\fud all av hangover1.5.4\\with icon +shortcut link\\HangOver 1.5.3 (Startup)\\Release\\Http_t.pdb"
+ $pdb38 = "\\final project backup\\uploader version backup\\HangOver 1.5.3 (Startup)\\Release\\Http_t.pdb"
+ $pdb39 = "\\New folder\\with icon +shortcut link\\HangOver 1.5.3 (Startup)\\Release\\Http_t.pdb"
+ $pdb40 = "\\Http uploader limited account\\Http uploader limited account\\RON 2.0.0\\Release\\Ron.pdb"
+ $pdb41 = "\\Uploader\\HTTP\\HTTP Babylon 5.1.1\\HTTP Babylon 5.1.1\\Httpbackup\\Release\\HttpUploader.pdb"
+ $pdb42 = "\\Uploader\\HTTP\\ron uplo\\RON 2.0.0\\Release\\Ron.pdb"
condition:
- 7 of them and filesize <212992
+ uint16(0)==0x5a4d and filesize <330KB and any of them
}
-rule MALPEDIA_Win_Seduploader_Auto : FILE
+rule TRELLIX_ARC_Apt_Hanover_Slidewin_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7f16d7a9-71b0-5c84-ab55-9cb76a2d5976"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.seduploader"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.seduploader_auto.yar#L1-L113"
- license_url = "N/A"
- logic_hash = "59b0ef9c5ade0664bc2e5b83dd5075b45d913aac7ac67fc4cf5358fb404425b7"
+ description = "Rule to detect hanover slidewin samples"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "aefa1a2b-6a6f-5209-b1e2-90f1817442da"
+ date = "2012-01-05"
+ modified = "2020-08-14"
+ reference = "https://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_hangover.yar#L202-L229"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "89b80267f9c7fc291474e5751c2e42838fdab7a5cbd50a322ed8f8efc3d2ce83"
+ logic_hash = "28922d75109cf3da4807e08588e076f1496c14ea462a1c8dedb1d1a734f1fb48"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Hanover"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 50 ff7630 e8???????? 83c40c 3b4508 }
- $sequence_1 = { c6411001 c3 55 8bec }
- $sequence_2 = { 8b4510 83c6fe 8930 8d4601 }
- $sequence_3 = { 8b4510 83c6fe 8930 8d4601 50 e8???????? }
- $sequence_4 = { 5e c3 55 8bec e8???????? 8b4d0c }
- $sequence_5 = { 8b4510 83c6fe 8930 8d4601 50 }
- $sequence_6 = { e8???????? 8b4510 83c6fe 8930 }
- $sequence_7 = { ff763c e8???????? 83c40c 3b4508 }
- $sequence_8 = { ff7630 e8???????? 83c40c 3b4508 }
- $sequence_9 = { 50 e8???????? 8b4510 83c6fe 8930 8d4601 50 }
+ $pdb = "\\Users\\God\\Desktop\\ThreadScheduler-aapnews-Catroot2\\Release\\ThreadScheduler.pdb"
+ $pdb1 = "\\Data\\User\\MFC-Projects\\KeyLoggerWin32-hostzi\\Release\\slidebar.pdb"
+ $pdb2 = "\\Data\\User\\MFC-Projects\\KeyLoggerWin32-spectram\\Release\\slidebar.pdb"
+ $pdb3 = "\\Data\\User\\MFC-Projects\\KeyLoggerWin32-zendossier\\Release\\slidebar.pdb"
condition:
- 7 of them and filesize <401408
+ uint16(0)==0x5a4d and filesize <100KB and any of them
}
-rule MALPEDIA_Win_Pillowmint_Auto : FILE
+rule TRELLIX_ARC_Apt_Gauss_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f86758a5-97c5-5c70-a000-bfe6ecf0e5d4"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pillowmint"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.pillowmint_auto.yar#L1-L131"
- license_url = "N/A"
- logic_hash = "33c9d52674ffef90debdc06a4a267346eaf178ee863fdca6106f4bbf407b2817"
+ description = "Rule to detect Gauss based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "209223cc-16e5-5596-8744-21ad71b5ec2a"
+ date = "2012-08-14"
+ modified = "2020-08-14"
+ reference = "https://securelist.com/the-mystery-of-the-encrypted-gauss-payload-5/33561/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/gauss_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "7b0d0612b4ecc889a901115c2e77776ef0ea65c056b283d12e80f863062cea28"
+ logic_hash = "cb20c87ea976f395e000f2c631ffd52b09dca2af37adceafe5be72b37f75a997"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Gauss"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 4883ec48 488b05???????? 4833c4 4889442438 83fa01 0f8580000000 }
- $sequence_1 = { 90 4c8bc0 488d1533c00000 488d4d40 e8???????? 90 4c8d051ec00000 }
- $sequence_2 = { 488bd8 488b00 80781900 74e9 493bd8 741e 8b4320 }
- $sequence_3 = { 4889bc2418010000 c684240801000000 41b810000000 488d155dc00200 488d8c2408010000 e8???????? }
- $sequence_4 = { 49c1f803 498bc0 48c1e83f 4c03c0 0f84e0050000 498bd1 4c3bc3 }
- $sequence_5 = { ff15???????? ba04010000 488d4c2430 4c8d05a2630300 395c2420 7507 4c8d05ad630300 }
- $sequence_6 = { 0f95c0 48ffc0 480faf45df 48ffc8 48014368 48837de710 7209 }
- $sequence_7 = { 488bd6 488d4d97 e8???????? 90 4c8d6597 48837daf10 4c0f436597 }
- $sequence_8 = { ff15???????? 833d????????04 0f8cf6030000 48c785980000000f000000 4533f6 4c89b590000000 }
- $sequence_9 = { 3b3d???????? 0f8392000000 488bc7 4c8bf7 49c1fe05 4c8d2d4bd30100 83e01f }
+ $pdb = "\\projects\\gauss\\bin\\release\\winshell.pdb"
condition:
- 7 of them and filesize <4667392
+ uint16(0)==0x5a4d and filesize <550KB and any of them
}
-rule MALPEDIA_Win_Outlook_Backdoor_Auto : FILE
+rule TRELLIX_ARC_Apt_Turla_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "10b67e6b-fced-54a6-8f30-b2a0d20f49ea"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.outlook_backdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.outlook_backdoor_auto.yar#L1-L131"
- license_url = "N/A"
- logic_hash = "373fe304abbc2faa8be0b7ba3a307d5b5d4cb0051b5dde767cca54332adde2f8"
+ description = "Rule to detect a component of the APT Turla"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "b39ac7fc-16dd-559e-8ab0-76da5cbbc719"
+ date = "2017-05-31"
+ modified = "2020-08-14"
+ reference = "https://attack.mitre.org/groups/G0010/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_turla_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "3b8bd0a0c6069f2d27d759340721b78fd289f92e0a13965262fea4e8907af122"
+ logic_hash = "d519317c936a38f189bf0de908902ec4e3e079c8c7463c8881ceb332c0a82a26"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Turla"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { ff753c 53 68e9fd0000 ffd6 8d4d00 894568 e8???????? }
- $sequence_1 = { ff10 8b4c2408 ff74240c 8d04c8 8b4804 85c9 740b }
- $sequence_2 = { c9 c20800 56 8bf7 e8???????? 8d771c e8???????? }
- $sequence_3 = { c745e01f000130 895d0c ff15???????? 8b450c 8945f0 895dfc 33c9 }
- $sequence_4 = { 6898000000 e8???????? 59 8945ec c645fc01 }
- $sequence_5 = { f6455404 740e 836554fb 57 56 8d4dbc e8???????? }
- $sequence_6 = { c3 57 6a2c e8???????? 8bf8 59 85ff }
- $sequence_7 = { 5f 5e 8d4302 5b c3 53 8bd9 }
- $sequence_8 = { 50 e8???????? 834d1004 f6451002 740f 836510fd }
- $sequence_9 = { e8???????? 83ec38 56 57 8bf1 8b4604 33ff }
+ $pdb = "\\Workshop\\Projects\\cobra\\carbon_system\\x64\\Release\\carbon_system.pdb"
condition:
- 7 of them and filesize <2912256
+ uint16(0)==0x5a4d and filesize <650KB and any of them
}
-rule MALPEDIA_Win_Adylkuzz_Auto : FILE
-{
- meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "092d1cf3-18b6-52f1-b243-99d6007e2b3c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.adylkuzz"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.adylkuzz_auto.yar#L1-L134"
- license_url = "N/A"
- logic_hash = "de89fec9458f93b8b7ae503a1f8b6b5fd97e3b1bb1f58b10dd0b4e8fc16d178d"
- score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { f5 f8 0fb7bc79b0010000 81fa00000001 0f833a000000 3b45fc 0f83c3fc0100 }
- $sequence_1 = { 8b44242c 8b4804 894c2428 8b4a04 894c2430 8b08 8b02 }
- $sequence_2 = { e8???????? 807e053d 8944240c 8d4340 754b 89e9 bafe00008d }
- $sequence_3 = { 891c24 e8???????? c744240401000000 891c24 e8???????? 85c0 7518 }
- $sequence_4 = { f9 663bc9 33d8 03f8 e9???????? 8b442500 660fbdd5 }
- $sequence_5 = { f8 f5 03f8 e9???????? ff742500 055a2dd112 8dad04000000 }
- $sequence_6 = { 89442408 8b4510 89442404 8b03 890424 e8???????? 8b550c }
- $sequence_7 = { f6c3d8 2dc4275e67 2bce 660fc8 66d3c0 fec8 8d440aa4 }
- $sequence_8 = { e9???????? 8b4c2500 80c4f7 d2d8 648b01 89442500 81ee04000000 }
- $sequence_9 = { c7442404ffffffff 891c24 e8???????? 8974240c 89442408 c7442404???????? 891c24 }
+import "pe"
- condition:
- 7 of them and filesize <6438912
-}
-rule MALPEDIA_Win_Photofork_Auto : FILE
+rule TRELLIX_ARC_Shadowspawn_Utility : UTILITY FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f7484eb7-9c89-5a31-aecd-73c9087aa29d"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.photofork"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.photofork_auto.yar#L1-L116"
- license_url = "N/A"
- logic_hash = "ff7473e2612dfba9efd366e89c657d77862d4c88088d1b5f47bab69cec947ba6"
+ description = "Rule to detect ShadowSpawn utility used in the SoftCell operation"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "0a325f5c-2750-5354-b920-f7e1510a8b71"
+ date = "2019-06-25"
+ modified = "2020-08-14"
+ reference = "https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Operation_SoftCell.yar#L3-L32"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "0f2805aee60cdb4eb932768849c845052c92131d0b25a511b822b79b2ac93e24"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "UTILITY, FILE"
+ rule_version = "v1"
+ malware_type = "utility"
+ malware_family = "Trojan:W32/ShadowSpawn"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 33c9 4c8d85f0010000 ff15???????? 33db }
- $sequence_1 = { 4885d2 7431 488b9278010000 4885d2 753a ba01000000 33c9 }
- $sequence_2 = { 4d85c9 7535 8d5301 33c9 }
- $sequence_3 = { ff15???????? 4863c8 48ffc6 4803f9 493bf7 0f825fffffff }
- $sequence_4 = { 4c8b0d???????? 4d85c9 7430 4d8b8910110000 4d85c9 }
- $sequence_5 = { 488d55e8 498bcc e8???????? 4c8bbc2498000000 }
- $sequence_6 = { 5e 5d c3 498bdf 6690 80bbc001000030 }
- $sequence_7 = { 48ffc1 4883f903 72ea 448b4df8 488d0c7e }
- $sequence_8 = { 488bd0 488b05???????? 48899040060000 488d4dc0 ffd2 66837dc009 b840000000 }
- $sequence_9 = { 8b44246c 0fb6442468 84c0 7520 }
+ $pdb = "C:\\data\\projects\\shadowspawn\\src\\bin\\Release-W2K3\\x64\\ShadowSpawn.pdb" fullword ascii
+ $op0 = { e9 34 ea ff ff cc cc cc cc 48 8d 8a 20 }
+ $op1 = { 48 8b 85 e0 06 00 00 48 8d 34 00 48 8d 46 02 48 }
+ $op2 = { e9 34 c1 ff ff cc cc cc cc 48 8b 8a 68 }
condition:
- 7 of them and filesize <99328
+ uint16(0)==0x5a4d and filesize <200KB and (pe.imphash()=="eaae87b11d2ebdd286af419682037b4c" and all of them )
}
-rule MALPEDIA_Win_Darkcloud_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Poison_Ivy_Softcell : RAT FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "b0268fec-89c8-5323-9f85-c9d45089af7c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkcloud"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.darkcloud_auto.yar#L1-L133"
- license_url = "N/A"
- logic_hash = "500bafad0751f0834ef38cd2423929e4bf071aa68fdd5512e97c403f17f02fd3"
+ description = "Rule to detect Poison Ivy used in the SoftCell operation"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "c362b116-4cb6-5393-9c64-28e8d2886dc7"
+ date = "2019-06-25"
+ modified = "2020-08-14"
+ reference = "https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Operation_SoftCell.yar#L34-L72"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "ac84023404d76adf8cfd8d26bb59fb51f29057748806c4f5ea0634803fd937cd"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "RAT, FILE"
+ rule_version = "v1"
+ malware_type = "rat"
+ malware_family = "Rat:W32/PoisonIvy"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 83c414 8d4db0 ff15???????? c745fc23000000 8b4d08 894da8 }
- $sequence_1 = { 894598 894db0 8945a8 894dc0 8945b8 ff15???????? 50 }
- $sequence_2 = { 6a00 51 8bf0 ff15???????? 50 56 6a00 }
- $sequence_3 = { 8d8d68ffffff 51 ff15???????? c745fc06000000 ba???????? 8d4dcc ff15???????? }
- $sequence_4 = { 8d855cffffff 8d8df8feffff 50 8d954cffffff 51 52 c7851cffffff08000000 }
- $sequence_5 = { 668b55dc 663b954cffffff 0f8ff4000000 c745fc0c000000 8d45dc 894584 c7857cffffff02400000 }
- $sequence_6 = { ff15???????? 8bd0 8d8df0feffff ff15???????? 50 8b559c 52 }
- $sequence_7 = { 668b00 8975dc 662d0100 8975cc 0f80e4000000 8975ac 894584 }
- $sequence_8 = { 50 8d4d94 51 e8???????? 8bd0 8d4d84 ff15???????? }
- $sequence_9 = { ff15???????? 8bd0 8d4da8 ff15???????? 8d5588 52 8d458c }
+ $s1 = "Cannot create folder %sDCRC failed in the encrypted file %s. Corrupt file or wrong password." fullword wide
+ $s2 = "Extracting files to %s folder$Extracting files to temporary folder" fullword wide
+ $s3 = "&Enter password for the encrypted file:" fullword wide
+ $s4 = "start \"\" \"%CD%\\mcoemcpy.exe\"" fullword ascii
+ $s5 = "setup.bat" fullword ascii
+ $s6 = "ErroraErrors encountered while performing the operation" fullword wide
+ $s7 = "Please download a fresh copy and retry the installation" fullword wide
+ $s8 = "antivir.dat" fullword ascii
+ $s9 = "The required volume is absent2The archive is either in unknown format or damaged" fullword wide
+ $s10 = "=Total path and file name length must not exceed %d characters" fullword wide
+ $s11 = "Please close all applications, reboot Windows and restart this installation\\Some installation files are corrupt." fullword wide
+ $op0 = { e8 6f 12 00 00 84 c0 74 04 32 c0 eb 34 56 ff 75 }
+ $op1 = { 53 68 b0 34 41 00 57 e8 61 44 00 00 57 e8 31 44 }
+ $op2 = { 56 ff 75 08 8d b5 f4 ef ff ff e8 17 ff ff ff 8d }
condition:
- 7 of them and filesize <622592
+ uint16(0)==0x5a4d and filesize <500KB and (pe.imphash()=="dbb1eb5c3476069287a73206929932fd" and all of them )
}
-rule MALPEDIA_Win_Stop_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Trochilus_Softcell : TROJAN FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fe824146-93e4-5101-ac02-1276fa1eda55"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stop"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.stop_auto.yar#L1-L121"
- license_url = "N/A"
- logic_hash = "d919a89d4ce45439e081288fd345725318b761c87669a03e35d3c6db03d1320c"
+ description = "Rule to detect Trochilus malware used in the SoftCell operation"
+ author = "Trellix ARC Team"
+ id = "81e942ae-936f-5952-8d50-ee8cec74520b"
+ date = "2019-06-25"
+ modified = "2020-08-14"
+ reference = "https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Operation_SoftCell.yar#L74-L106"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "80a0841a08627acf11707f3aeef4e7c3777aecf04b932755efa618d7e92b0cda"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/Trochilus"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 6a00 8d45e0 50 ffd6 85c0 75e2 6a64 }
- $sequence_1 = { ffd0 5d c3 8b0d???????? 33d2 85c9 }
- $sequence_2 = { 57 6a00 8bd9 6a00 6a12 ff33 }
- $sequence_3 = { 56 57 6a00 8bd9 6a00 6a12 }
- $sequence_4 = { ff750c ff7508 ffd0 5d c3 8b0d???????? }
- $sequence_5 = { ff15???????? 50 e8???????? c745fc00000000 }
- $sequence_6 = { 75e2 6a64 ff15???????? ffd3 }
- $sequence_7 = { 68???????? 6a00 6a00 ff15???????? 33c9 894604 85c0 }
- $sequence_8 = { 6a00 ff15???????? 33c9 894604 }
- $sequence_9 = { 6a00 ff15???????? 33c9 894604 85c0 5e 0f95c1 }
+ $s1 = "Shell.dll" fullword ascii
+ $s2 = "photo.dat" fullword wide
+ $s3 = "VW9HxtV9H|tQ9" fullword ascii
+ $s4 = "G6uEGRich7uEG" fullword ascii
+ $op0 = { e8 9d ad ff ff ff b6 a8 }
+ $op1 = { e8 d4 ad ff ff ff b6 94 }
+ $op2 = { e8 ea ad ff ff ff b6 8c }
condition:
- 7 of them and filesize <6029312
+ uint16(0)==0x5a4d and filesize <200KB and (pe.imphash()=="8e13ebc144667958722686cb04ee16f8" and (pe.exports("Entry") and pe.exports("Main")) and all of them )
}
-rule MALPEDIA_Win_Mirrorkey_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Lg_Utility_Lateral_Movement_Softcell : UTILITY FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e800f2ca-d12e-53d0-a0d8-c0a956e2c2e3"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mirrorkey"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mirrorkey_auto.yar#L1-L123"
- license_url = "N/A"
- logic_hash = "63df7495a525d1f228b934ad2c4fefa8fb21a89fd4e60713963ec70e2cb5c67e"
+ description = "Rule to detect the utility LG from Joeware to do Lateral Movement in the SoftCell operation"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "4f435348-427a-5f35-9545-5582033eb043"
+ date = "2019-06-25"
+ modified = "2020-08-14"
+ reference = "https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Operation_SoftCell.yar#L108-L143"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "f88781b9632cd31bb9e3d68730c63c3fcd0ebe4a09b70b5b54d456cdc9ae8d01"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "UTILITY, FILE"
+ rule_version = "v1"
+ malware_type = "utility"
+ malware_family = "Utility:W32/Joeware"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 0f57c0 0f1145d8 ff15???????? c70016000000 ff15???????? 8d45d4 50 }
- $sequence_1 = { 895914 0fb77806 85ff 7414 8d4b10 8b4104 0301 }
- $sequence_2 = { ff15???????? 83c40c c744241000000000 33c0 c644242c00 8944242d 8d742433 }
- $sequence_3 = { 8bf9 8b7508 8d45a4 50 }
- $sequence_4 = { 83c004 8b7dfc 83ff01 7f87 5f }
- $sequence_5 = { 730b 68???????? ff15???????? 894610 837e1410 }
- $sequence_6 = { 897508 2bda ebaa 8d5aff 83c704 eba2 }
- $sequence_7 = { 8d4dd8 50 e8???????? 8d4d8c e8???????? 837de808 7d15 }
- $sequence_8 = { 6a00 51 89542414 ff15???????? 83c408 83f8ff }
- $sequence_9 = { 53 8b5d0c 894dfc 8b4d08 56 }
+ $s1 = "lg \\\\comp1\\users louise -add -r comp3" fullword ascii
+ $s2 = "lg \\\\comp1\\users S-1-5-567-678-89765-456 -sid -add" fullword ascii
+ $s3 = "lg \\\\comp1\\users -sidsout" fullword ascii
+ $s4 = "Enumerates members of localgroup users on localhost" fullword ascii
+ $s5 = "Adds SID resolved at comp3 for louise to localgroup users on comp1" fullword ascii
+ $s6 = "CodeGear C++ - Copyright 2008 Embarcadero Technologies" fullword ascii
+ $s7 = "Lists members of localgroup users on comp1 in SID format" fullword ascii
+ $s8 = "ERROR: Verify that CSV lines are available in PIPE input. " fullword ascii
+ $op0 = { 89 43 24 c6 85 6f ff ff ff 00 83 7b 24 10 72 05 }
+ $op1 = { 68 f8 0e 43 00 e8 8d ff ff ff 83 c4 20 68 f8 0e }
+ $op2 = { 66 c7 85 74 ff ff ff 0c 00 8d 55 d8 52 e8 e9 eb }
condition:
- 7 of them and filesize <117760
+ uint16(0)==0x5a4d and filesize <600KB and (pe.imphash()=="327ce3f883a5b59e966b5d0e3a321156" and all of them )
}
-rule MALPEDIA_Win_Arkei_Stealer_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Mangzamel_Softcell : TROJAN FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "d30a73fa-e439-581b-821f-0f94e7403477"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.arkei_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.arkei_stealer_auto.yar#L1-L125"
- license_url = "N/A"
- logic_hash = "9f5b37522725bf35fb4c723079a0799c573d27f50c2c2a0cc7a8a66eafb6f502"
+ description = "Rule to detect Mangzamel used in the SoftCell operation"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "b0473362-7e03-5127-aee5-b5a4f05bcc8e"
+ date = "2019-06-25"
+ modified = "2020-08-14"
+ reference = "https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Operation_SoftCell.yar#L145-L176"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "3666c645943eb8469096b8093c74e4d819299d3ffc2b99e37a506d8ef09e90c4"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/Mangzamel"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8d55c4 52 6a18 50 ff15???????? 85c0 }
- $sequence_1 = { 8be5 5d c3 50 8b45e8 }
- $sequence_2 = { 894614 897e24 ff15???????? 8bd8 3bdf 0f84e3feffff }
- $sequence_3 = { 8bf0 ffd3 8bd8 53 56 }
- $sequence_4 = { 56 53 52 57 50 51 ff15???????? }
- $sequence_5 = { 8b00 50 ff15???????? 83f8ff 740b a810 7507 }
- $sequence_6 = { 85c0 0f8458feffff 8b4e20 6a00 8d45e4 50 8d148d28000000 }
- $sequence_7 = { 8bf0 c70628000000 8b4dc8 894e04 8b55cc 895608 668b45d4 }
- $sequence_8 = { 8b7614 6a00 8d45e4 50 56 }
- $sequence_9 = { 56 894590 ff15???????? 8bf8 897d94 83ffff }
+ $s1 = "Change Service Mode to user logon failure.code:%d" fullword ascii
+ $s2 = "spoolsvs.exe" fullword wide
+ $s3 = "System\\CurrentControlSet\\Services\\%s\\parameters\\%s" fullword ascii
+ $s4 = "Please Correct [-s %s]" fullword ascii
+ $s5 = "Please Correct [-m %s]" fullword ascii
+ $op0 = { 59 8d 85 64 ff ff ff 50 c7 85 64 ff ff ff 94 }
+ $op1 = { c9 c2 08 00 81 c1 30 34 00 00 e9 cf 9b ff ff 55 }
+ $op2 = { 80 0f b6 b5 68 ff ff ff c1 e2 04 0b d6 0f b6 b5 }
condition:
- 7 of them and filesize <1744896
+ uint16(0)==0x5a4d and filesize <300KB and (pe.imphash()=="ef64bb4aa42ef5a8a2e3858a636bce40" and all of them )
}
-rule MALPEDIA_Win_Tiger_Rat_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Nbtscan_Utility_Softcell : UTILITY FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c2ea69b5-54d0-5c61-bb49-4f65b838d0af"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tiger_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tiger_rat_auto.yar#L1-L165"
- license_url = "N/A"
- logic_hash = "bed3ce3d252a7d616792a16e358ffda1357857c1fa2b5862a7f71cbabe456650"
+ description = "Rule to detect nbtscan utility used in the SoftCell operation"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "a2a8dd43-0d30-5da5-9dd3-6ba9f6473c40"
+ date = "2019-06-25"
+ modified = "2020-08-14"
+ reference = "https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Operation_SoftCell.yar#L178-L209"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "6079f1363578f82fd38971d0c8f69cc156f7f678c3f2be22c5d9c3748dc80b1f"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 45
+ tags = "UTILITY, FILE"
+ rule_version = "v1"
+ malware_type = "utility"
+ malware_family = "Utility:W32/NbtScan"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 4883c128 4889742448 48897c2450 ff15???????? }
- $sequence_1 = { 0f11400c 488b4e28 488b5618 488b01 ff5010 }
- $sequence_2 = { 4883c108 e8???????? 4d8b4618 41b901000000 }
- $sequence_3 = { 33d2 41b80c000100 488bd8 e8???????? 4c63442430 488b4f08 }
- $sequence_4 = { 4883c108 413bc0 7cef eb06 4898 }
- $sequence_5 = { 4883c110 e8???????? 896e30 381f }
- $sequence_6 = { 4883c10c e8???????? 488b4f28 488b5718 }
- $sequence_7 = { 4883c110 48c741180f000000 33ed 48896910 408829 48c746500f000000 }
- $sequence_8 = { 7ce0 488bce ff15???????? 8b0d???????? }
- $sequence_9 = { ff15???????? 488bc8 ff15???????? ba0a000000 }
- $sequence_10 = { 0b05???????? 8905???????? ff15???????? ff15???????? b9e8030000 8bd8 }
- $sequence_11 = { 4c2bf3 8905???????? 493bf7 0f83c8000000 48896c2478 4c896c2430 41bd00f00000 }
- $sequence_12 = { c705????????02000000 488905???????? 488d0556eb0100 48891d???????? 488905???????? 33c0 488905???????? }
- $sequence_13 = { 8b05???????? 4d8bf4 2305???????? 4c03fe 4c2bf3 8905???????? }
- $sequence_14 = { 4c8d35046c0100 49833cde00 7407 b801000000 eb5e }
- $sequence_15 = { 8bd8 e8???????? 2bc3 3d70170000 7cf2 e8???????? }
+ $s1 = "nbtscan 1.0.35 - 2008-04-08 - http://www.unixwiz.net/tools/" fullword ascii
+ $s2 = "parse_target_cb.c" fullword ascii
+ $s3 = "ranges. Ranges can be in /nbits notation (\"192.168.12.0/24\")" fullword ascii
+ $s4 = "or with a range in the last octet (\"192.168.12.64-97\")" fullword ascii
+ $op0 = { 52 68 d4 66 40 00 8b 85 58 ff ff ff 50 ff 15 a0 }
+ $op1 = { e9 1c ff ff ff 8b 45 fc 8b e5 5d c3 cc cc cc cc }
+ $op2 = { 59 59 c3 8b 65 e8 ff 75 d0 ff 15 34 60 40 00 ff }
condition:
- 7 of them and filesize <557056
+ uint16(0)==0x5a4d and filesize <100KB and (pe.imphash()=="2fa43c5392ec7923ababced078c2f98d" and all of them )
}
-rule MALPEDIA_Win_Startpage_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Mimikatz_Utility_Softcell : HACKTOOL FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bf47ff90-3238-555c-bf4a-537084ae22d6"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.startpage"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.startpage_auto.yar#L1-L133"
- license_url = "N/A"
- logic_hash = "9dae8bd02cc42718a63c04f81edbd9a29e9f4300c24f882a2c1fba0669713697"
+ description = "Rule to detect Mimikatz utility used in the SoftCell operation"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "0c01a2f6-cf3c-57b3-8f19-94d320422658"
+ date = "2019-06-25"
+ modified = "2020-08-14"
+ reference = "https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Operation_SoftCell.yar#L211-L258"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "4ccb44bf0d490a18e35290d904326ce14cdc92c96be1a38e6059431645233e37"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 68
+ tags = "HACKTOOL, FILE"
+ rule_version = "v1"
+ malware_type = "hacktool"
+ malware_family = "Hacktool:W32/Mimikatz"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8945ec 85db 740c 8b0b 85c9 7406 0fb701 }
- $sequence_1 = { 83eb01 75f1 8b75f8 8b06 33c9 663b08 759d }
- $sequence_2 = { 75f5 2bd1 d1fa 5b 52 ff7508 8bcf }
- $sequence_3 = { 8901 89742410 eb06 8931 8b742410 8b44241c 85c0 }
- $sequence_4 = { 8bec a1???????? 85c0 740e 50 e8???????? 8325????????00 }
- $sequence_5 = { 722e 8b4dc0 40 3d00100000 721a f6c11f 759c }
- $sequence_6 = { 8b03 8bfb 53 ff5004 8b7508 33c9 8bc3 }
- $sequence_7 = { e8???????? 59 c645fc01 8b8de0feffff 83c1f0 e8???????? 51 }
- $sequence_8 = { 755f 8a0a 8d4201 8907 80f975 7553 8b4db8 }
- $sequence_9 = { 8907 50 50 8945fc ff35???????? ff31 }
+ $s1 = "livessp.dll" fullword wide
+ $s2 = "\\system32\\tapi32.dll" fullword wide
+ $s3 = " * Process Token : " fullword wide
+ $s4 = "lsadump" fullword wide
+ $s5 = "-nl - skip lsa dump..." fullword wide
+ $s6 = "lsadump::sam" fullword wide
+ $s7 = "lsadump::lsa" fullword wide
+ $s8 = "* NL$IterCount %u, %u real iter(s)" fullword wide
+ $s9 = "* Iter to def (%d)" fullword wide
+ $s10 = " * Thread Token : " fullword wide
+ $s11 = " * RootKey : " fullword wide
+ $s12 = "lsadump::cache" fullword wide
+ $s13 = "sekurlsa::logonpasswords" fullword wide
+ $s14 = "(commandline) # %s" fullword wide
+ $s15 = ">>> %s of '%s' module failed : %08x" fullword wide
+ $s16 = "UndefinedLogonType" fullword wide
+ $s17 = " * Username : %wZ" fullword wide
+ $s18 = "logonPasswords" fullword wide
+ $s19 = "privilege::debug" fullword wide
+ $s20 = "token::elevate" fullword wide
+ $op0 = { e8 0b f5 00 00 90 39 35 30 c7 02 00 75 34 48 8b }
+ $op1 = { eb 34 48 8b 4d cf 48 8d 45 c7 45 33 c9 48 89 44 }
+ $op2 = { 48 3b 0d 34 26 01 00 74 05 e8 a9 31 ff ff 48 8b }
condition:
- 7 of them and filesize <2277376
+ uint16(0)==0x5a4d and filesize <500KB and (pe.imphash()=="169e02f00c6fb64587297444b6c41ff4" and all of them )
}
-rule MALPEDIA_Win_Bbsrat_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Sfx_Winrar_Plugx : BUILDER FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1bf7f125-76bf-51d8-8714-b1f4351a2fc5"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bbsrat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bbsrat_auto.yar#L1-L131"
- license_url = "N/A"
- logic_hash = "d09c46b568c20e6cc1497fd9b00b10dfec3bd249a240c9cb1f2d27667bcf264d"
+ description = "Rule to detect the SFX WinRAR delivering a possible Plugx sample"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "ac975a58-6a8a-515e-b27f-327a7bfc7686"
+ date = "2019-06-25"
+ modified = "2020-08-14"
+ reference = "https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_Operation_SoftCell.yar#L260-L307"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "8231f46330762cecf8a796d1a29c8fa6ba1c10b527fa86bf6c73130349558dad"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 68
+ tags = "BUILDER, FILE"
+ rule_version = "v1"
+ malware_type = "builder"
+ malware_family = "Builder:W32/Plugx"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { e8???????? 8b7c2410 81c610020000 d1eb 45 85db 75b5 }
- $sequence_1 = { 83c8ff 898e44020000 899648020000 57 894308 894304 8903 }
- $sequence_2 = { 03c0 03c0 50 898374010000 e8???????? 8b8b74010000 83c404 }
- $sequence_3 = { 8be5 5d c20c00 51 e8???????? 5e 5b }
- $sequence_4 = { ffd7 895e24 8b461c 3bc3 741a 53 50 }
- $sequence_5 = { eb21 83f805 7529 8d8c243c010000 51 8d842448030000 e8???????? }
- $sequence_6 = { ff15???????? 8bf8 6a10 56 6861001100 }
- $sequence_7 = { 52 8d6e18 55 8d7e0c 57 894608 e8???????? }
- $sequence_8 = { ffd7 a3???????? 85c0 7412 8d4c2408 51 }
- $sequence_9 = { 6a00 52 8bd8 56 895c2428 ff15???????? 8b4f0c }
+ $s1 = "Cannot create folder %sDCRC failed in the encrypted file %s. Corrupt file or wrong password." fullword wide
+ $s2 = "Wrong password for %s5Write error in the file %s. Probably the disk is full" fullword wide
+ $s3 = "mcutil.dll" fullword ascii
+ $s4 = "Unexpected end of archiveThe file \"%s\" header is corrupt%The archive comment header is corrupt" fullword wide
+ $s5 = "mcoemcpy.exe" fullword ascii
+ $s6 = "Extracting files to %s folder$Extracting files to temporary folder" fullword wide
+ $s7 = "&Enter password for the encrypted file:" fullword wide
+ $s8 = "start \"\" \"%CD%\\mcoemcpy.exe\"" fullword ascii
+ $s9 = "setup.bat" fullword ascii
+ $s10 = "ErroraErrors encountered while performing the operation" fullword wide
+ $s11 = "Please download a fresh copy and retry the installation" fullword wide
+ $s12 = "antivir.dat" fullword ascii
+ $s13 = "The required volume is absent2The archive is either in unknown format or damaged" fullword wide
+ $s14 = "=Total path and file name length must not exceed %d characters" fullword wide
+ $s15 = "Please close all applications, reboot Windows and restart this installation\\Some installation files are corrupt." fullword wide
+ $s16 = "folder is not accessiblelSome files could not be created." fullword wide
+ $s17 = "Packed data CRC failed in %s" fullword wide
+ $s18 = "DDTTDTTDTTDTTDTTDTTDTTDTTDTQ" fullword ascii
+ $s19 = "File close error" fullword wide
+ $s20 = "CRC failed in %s" fullword wide
+ $op0 = { e8 6f 12 00 00 84 c0 74 04 32 c0 eb 34 56 ff 75 }
+ $op1 = { 53 68 b0 34 41 00 57 e8 61 44 00 00 57 e8 31 44 }
+ $op2 = { 56 ff 75 08 8d b5 f4 ef ff ff e8 17 ff ff ff 8d }
condition:
- 7 of them and filesize <434176
+ uint16(0)==0x5a4d and filesize <500KB and (pe.imphash()=="dbb1eb5c3476069287a73206929932fd" and all of them )
}
-rule MALPEDIA_Win_Jolob_Auto : FILE
+rule TRELLIX_ARC_APT_Winnti : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a7a30cc7-8517-58f2-b42f-ed67321f20be"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jolob"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jolob_auto.yar#L1-L126"
- license_url = "N/A"
- logic_hash = "7066e8000a5c7d67ee5c483efa94c88c66463d1307008135462062b7827f4ff2"
+ description = "Detects Winnti variants"
+ author = "McAfee ATR Team"
+ id = "f12b039a-2508-580f-b777-428bbda2c666"
+ date = "2020-06-04"
+ modified = "2020-10-14"
+ reference = "https://attack.mitre.org/software/S0141/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_winnti.yar#L1-L27"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "fd539d345821d9ac9b885811b1f642aa1817ba8501d47bc1de575f5bef2fbf9e"
+ logic_hash = "f94b2c552fbb30e1005e5c75a2f449d60b9558a0916197bed41bf32c6477daef"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Winnti"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8bf7 668954242a 668974242e 6683fa0d 750c 66ff442428 }
- $sequence_1 = { 57 ff7318 e8???????? eb2d 8b7c2428 83c70c 57 }
- $sequence_2 = { ff15???????? eb2e 8b7e1c e8???????? }
- $sequence_3 = { 8d45e4 6a10 48 c745f401000000 5b 8945f0 8365f800 }
- $sequence_4 = { 8d45f0 50 ffb714080000 e8???????? 85c0 75df 40 }
- $sequence_5 = { 8b442404 85c0 7501 40 50 6842200000 ff15???????? }
- $sequence_6 = { 8b17 895648 83671000 894714 895f18 890f 8b5104 }
- $sequence_7 = { 6683fa0b 741a 6683fa02 7532 }
- $sequence_8 = { 77f5 8bc7 5e c3 33c0 5e c3 }
- $sequence_9 = { 83ec28 8365f400 53 56 8bf0 8d461c }
+ $pattern = { 9090909090909090909090909090C7????????????C2????90909090909081??????????E9????????CCCCCCCCCC8A??????8B??????538A??8A??568B??578B??????8B??C1????66????8B??C1????F3AB8B??83????F3AA8B??5F5E5BC390909090909090909090909090909083????5333??568D??????535089??????89??????E8????????8A??33??3A??8D??????0F94??83????5389??????528B??89??????C6????????E8????????8B??33??81??????????8D??????0F94??6A??89??????5223??89??????C6????????C6????????E8????????33??66????8D??????6A??0F94??89??????89??????5223??C6????????C6????????E8????????8B??83????33??3B??0F94??23??5E495BF7??1B??8B??83????C38B??????8B??????03??C390909090908B??????85??0F84????????8B??????83????74??83????75??8B??????83????74??83????75??8B??????83????74??83????75??8B??????83????74??83????75??8B??????83????74??83????75??8B??????83????74??83????75??8B??????83????74??83????75??8B??????83????74??83????75??8B??????83????74??83????75??E9????????83????C39090909090909090909090909083????8B??????53558B??????33??568B??????83????5789??????76??81??????????8B??76??BF????????8B??????8D????03??C1????03??89??????3B??76??8B??????68????????6A??52E8????????8B??????8B??????8B??????505351565752E8????????8B??????8B??8B??????2B??8B??83????03??8B??????83????89??????77??03??0F84????????8B??????8B??????2B??03??3B??89??????75??81??????????77??8A??04??EB??83????77??08????EB??83????77??8A??80????88??EB??8D????C6????463D????????89??????76??8D????B8????????F7??C1????8B??33??8B??8B??C1????F3AB8B??83????03??F3AA8B??????81??????????4A89??????75??8B??????8B??88??468A??88??46424B75??8B??????C6????465FC6????46C6????2B??8B??????4633??89??5E5D5B83????C390909090909090909083????8B??????53558B??????568B??????8D????5789??????8B??????83????73??B8????????2B??EB??33??03??8B??2B??C1????8D??????89??????8B??????8B??????8D????3B??0F83????????8B??8B??69??????????8B??????8B??????C1????33??66??????03??8B??????2B??????89??????66??????8B??3B??0F85????????8B??????C7??????????????2B??8B??????8B??2B??0F84????????83????77??8A????0A??88????8B????89??03??E9????????83????77??8A??2C??88??468B????89??8B????89????8B????89????8B????89????03??E9????????83????77??8A??80????88??46EB??8D????C6????463D????????89??????76??8D????B8????????F7??8B??33??C1????89??????8B??8B??C1????F3AB8B??83????F3AA8B??03??8B??????81??????????4889??????75??8B??????8B??8B??????88??468B????89??8B????89????8B????89????8B????89????83????83????83????83????73??85??76??8A????88??46454B75??BB????????8B????8B????33??75??BB????????03??8B????8B??33??8B??????83????3B??73??8B??2B??????85??75??83????83????8B????8B??33??8B??????3B??72??EB??84??75??C1????4384??74??8B??????8B??03??2B??83????89??????77??3D????????77??4880????8A??80????C0????C0????0A??88??46C1????88??46E9????????3D????????77??4883????89??????77??80????80????EB??83????C6????4681??????????76??8D????B8????????F7??8B??33??C1????89??????8B??8B??C1????F3AB8B??83????F3AA8B??03??81??????????4875??8B??????88??8A??46C0????88??46C1????88??46E9????????2D????????83????89??????77??8B??80????C1????80????8A??0A??80????88??46C0????88??46C1????88??46E9????????8B??83????C1????80????80????88??4681??????????76??8D????B8????????F7??8B??33??C1????89??????8B??8B??C1????F3AB8B??83????F3AA8B??03??81??????????4875??8B??????88??8A??46C0????88??46C1????88??46E9????????8B??????E9????????8B??????8B??????8B??????2B??89??8B??5F2B??5E5D03??5B83????C390909090909090909090908B??????538B??????55568B??????C7??????????578A??8D????8B??????80????8B??76??81??????????8D????83????8B??83????0F82????????8A??88??40414F75??EB??33??8A??418B??83????0F83????????85??75??80????75??8A????81??????????4184??74??33??8A??418D??????8B??89??83????83????4E74??83????72??8B??89??83????83????83????83????73??85??76??8A??88??40414E75??EB??8A??88??40414E75??33??8A??418B??83????73??33??8B??8A??C1????2B??C1????2B??8A??????????81??????????4188??40478A??88??8A????4088??408A????83????8B??0F84????????8A??88??404183????76??8A??88??404183????76??8A??88??404133??8A??418B??83????72??8B??8B??C1????83????2B??33??8A??C1????2B??4F41C1????4E8A??88??8A????404788??40478A??88??40474E75??EB??83????72??83????75??80????75??8A????81??????????4184??74??33??8A??418D??????8D????66????81??????????C1????2B??83????EB??83????0F82????????8B??8B??83????C1????2B??83????75??80????75??8A????81??????????4184??74??33??8A??418D??????66????81??????????C1????2B??83????3B??74??81??????????83????0F82????????8B??2B??83????0F8C????????8B??89??83????83????83????8B??89??83????83????83????83????73??85??0F86????????8A??88??40474E75??E9????????33??8B??8A??C1????2B??C1????2B??4F41E9????????8B??????2B??3B??89??75??5F5E5D33??5BC31B??5F24??5E5D83????5BC39090909090909090909090909081??????????568B??68????????C7??????????FF??????????83????75??57B9????????33??8D??????66????????????F3AB66AB8D??????5068????????FF??????????83????5F75??6A??68????????FF??????????8B??5E81??????????C390909090909090909090909090568B??E8????????F6????????74??56E8????????83????8B??5EC2????909068????????C7??????????FF??????????85??75??FF??????????C39090909053558B??????5685??5774??8B??????85??74??33??33??33??85??76??8A??????????8A??????????32??80????32??8A????32??33??88????8D????BE????????F7??8D????BF????????8B??33??F7??413B??8B??72??5F5E5D5BC39083????538B??????55565768????????68????????5333??FF??????????8B??85??0F84????????68????????FF??????????8B??B0??88??????88??????8D??????B1??5056C6????????88??????C6????????C6????????C6????????C6????????88??????C6????????C6????????C6????????C6????????FF??????????5753FF??568B??FF??????????85??74??57FF??????????8B??8B??????B9????????8B??68????????50F3A5E8????????83????B8????????5F5E5D5B83????C35F8B??5E5D5B83????C39090538B??????????5657C7??????????8D????BF???????? }
condition:
- 7 of them and filesize <196608
+ uint16(0)==0x5a4d and filesize <400KB and all of them
}
-rule MALPEDIA_Win_Narilam_Auto : FILE
+rule TRELLIX_ARC_Karkoff_Dnspionaje : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "da9d4048-8edf-5bad-820f-4e60bf8a1167"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.narilam"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.narilam_auto.yar#L1-L134"
- license_url = "N/A"
- logic_hash = "9c97c97f1983ca4888bd0ceffb3db6cc9301c52fb6e7adafbcc7af03cf7073fe"
+ description = "Rule to detect the Karkoff malware"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "a5cdc65f-3a4c-5d97-9d88-8d60b14dfb9a"
+ date = "2019-04-23"
+ modified = "2020-08-14"
+ reference = "https://blog.talosintelligence.com/2019/04/dnspionage-brings-out-karkoff.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_karkoff_dnspionaje.yar#L1-L30"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "5b102bf4d997688268bab45336cead7cdf188eb0d6355764e53b4f62e1cdf30c"
+ logic_hash = "79dd0087f1197cb1b2cd98416302363951479ba5ebf82289768585b56ed21c3a"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Karkoff"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { e8???????? f645f801 7518 8d55f4 a1???????? e8???????? 8b45f4 }
- $sequence_1 = { 8d8550ffffff ba02000000 e8???????? 66c785dcfeffffe801 ba???????? 8d854cffffff e8???????? }
- $sequence_2 = { e8???????? 8b55fc 8bc6 e8???????? 8bf8 e9???????? 8d5308 }
- $sequence_3 = { eb83 e9???????? 66b86801 ebf5 66b86901 ebef 66b86a01 }
- $sequence_4 = { e8???????? eb08 8b45fc e8???????? 33c0 5a 59 }
- $sequence_5 = { e8???????? c3 3a90e2020000 740b 8890e2020000 e8???????? c3 }
- $sequence_6 = { e8???????? 8bc8 8bd3 8b831c020000 ff9318020000 33c0 8a45ff }
- $sequence_7 = { a5 a5 a5 8d4584 8d4dd4 ba04000000 e8???????? }
- $sequence_8 = { ff852cffffff 8d5588 8d45fc e8???????? ff8d2cffffff 8d4588 ba02000000 }
- $sequence_9 = { 8d8580feffff e8???????? ff854cfeffff 8d9580feffff 8d45fc e8???????? ff8d4cfeffff }
+ $s1 = "DropperBackdoor.Newtonsoft.Json.dll" fullword wide
+ $s2 = "C:\\Windows\\Temp\\MSEx_log.txt" fullword wide
+ $s3 = "DropperBackdoor.exe" fullword wide
+ $s4 = "get_ProcessExtensionDataNames" fullword ascii
+ $s5 = "get_ProcessDictionaryKeys" fullword ascii
+ $s6 = "https://www.newtonsoft.com/json 0" fullword ascii
condition:
- 7 of them and filesize <3325952
+ uint16(0)==0x5a4d and filesize <1000KB and all of them
}
-rule MALPEDIA_Win_Plaintee_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Milum_Trojan : TROJAN FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "e3bbe66b-b26a-510d-8a1b-05b2e6f7426c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.plaintee"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.plaintee_auto.yar#L1-L116"
- license_url = "N/A"
- logic_hash = "8bcc878fa501588c97ae4d4926e84d32a4619fd799353944068271d6d4e36727"
+ description = "Rule to detect Milum trojan from the Wildpressure operation"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "acc56237-a93a-55c0-a90c-11ca1da683db"
+ date = "2020-04-24"
+ modified = "2020-08-14"
+ reference = "https://securelist.com/wildpressure-targets-industrial-in-the-middle-east/96360/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/APT_milum_wildpressure.yar#L3-L28"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "86456ebf6b807e8253faf1262e7a2b673131c80174f6133b253b2e5f0da442a9"
+ logic_hash = "3ab1ff129517cb4a829edac289c00d7701d6f667ba2ef5a28024fd01a3a52e8e"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/Milum"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8d4c2404 6a00 8d542404 51 52 ffd0 8b4c2400 }
- $sequence_1 = { 8bf1 6802020000 ff15???????? 85c0 740a b001 }
- $sequence_2 = { 50 8d853c010000 50 8b8538010000 6a5a 52 }
- $sequence_3 = { 8d442400 56 50 8bf1 6802020000 ff15???????? }
- $sequence_4 = { 5e 81c490010000 c3 8bce }
- $sequence_5 = { 85f6 74c6 8bce e8???????? }
- $sequence_6 = { f3ab 66ab b900010000 33c0 }
- $sequence_7 = { eb02 33f6 8bce e8???????? 8a8669010000 }
- $sequence_8 = { 68ac010000 e8???????? 83c404 85c0 7412 }
- $sequence_9 = { 750a b001 5e 81c490010000 c3 }
+ $pattern = { 558B??6A??68????????64??????????5081??????????A1????????33??89????535657508D????64??????????8B????89??????????C7????????????8D????C7??????????33??6A??89??????????89????E8????????83????3B??0F84????????89????89??8B????89????8B????89????8B????C6??????8B????C6??????C6??????8B??????????BE????????89????89????88????C6??????6A??68????????8D??????????89??????????89??????????88??????????E8????????C6??????6A??538D????528D??????????89??????????89??????????88??????????E8????????C6??????8D??????????508B??E8????????508D??????????5157E8????????C6??????83????????????72??8B??????????52E8????????83????89??????????89??????????88??????????C6??????83????????????72??8B??????????50E8????????83????6A??68????????8D????89??????????89??????????88??????????89????89????88????E8????????C6??????6A??538D????518D????89????89????88????E8????????C6??????8D????528B??E8????????508D??????????5057E8????????C6??????83??????72??8B????51E8????????83????89????89????88????C6??????83??????72??8B????52E8????????83????6A??68????????8D????89????89????88????89????89????88????E8????????C6??????6A??538D????508D????89????89????88????E8????????C6??????83????8B??89??????????6A??89????89????68????????88??E8????????C6??????83????8B??89??????????6A??538D????89????89????5288??E8????????C6??????8D??????????50C6??????E8????????83????C6??????8B??????????2B??????????B8????????F7??03??C1????8B??C1????03??83????75??8B??????????6A??53528D????E8????????8B??????????6A??83????53508D????E8????????6A??538D????508D????89????89????88????E8????????C6??????6A??538D????518D????89????89????88????E8????????C6??????8D????528B??E8????????508D??????????5057E8????????C6??????BF????????39????72??8B????51E8????????83????89????89????88????C6??????39????72??8B????52E8????????83????89????89????88????C6??????8B??????????3B??74??8B??????????E8????????8B??????????50E8????????83????BF????????89??????????89??????????89??????????C6??????39????72??8B????51E8????????83????89????89????88????C6??????39????72??8B????52E8????????83????89????89????88????C6??????39????72??8B????50E8????????83????89????89????88????88????39????72??8B????51E8????????83????89????89????88????C7????????????39????72??8B????52E8????????83????8B??????????89????89????88????8B????64????????????595F5E5B8B????33??E8????????8B??5DC2????8D??????????508D??????????89??????????E8????????C6??????C7??????????????????C6??????68????????8D??????????51E8????????CCCC558B??6A??68????????64??????????5051535657A1????????33??508D????64??????????8B????C7??????????C7????????????8D????33??83??????89????72??8B??EB??8B??8D????88??8B????8B????518B??E8????????8B????89????8B????89??8B????89????89????88????83??????72??8B??50E8????????83????89????C7????????????88??83????89????89????C7????????????8B????8B??50518D????E8????????89????8B????52E8????????83????8B????64????????????595F5E5B8B??5DC2????CCCCCCCCCCCCCCCCCCCCCCCCCC558B??6A??68????????64??????????505156A1????????33??508D????64??????????83????C7????????????8B????5156E8????????C7????????????C7????????????8B??8B????64????????????595E8B??5DC2????CCCCCCCCCCCC558B??6A??68????????64??????????5081??????????A1????????33??89????535657508D????64??????????8B????33??8B??89??????????8B????8B??89??????????89??????????89??????????3B??0F84????????8D????39??????????0F85????????68????????8D????5750E8????????C7????????????83????8D????57518B??E8????????83????C6??????8B??????????6A??535083????E8????????C6??????BF????????39????72??8B????52E8????????83????C7????????????89????88????88????39????72??8B????50E8????????83????C7????????????89????88????E9????????578D????68????????51E8????????C7????????????508D??????????52BA????????E8????????C6??????83????8D????57518B??E8????????83????C6??????8B??????????6A??535083????E8????????C6??????BF????????39????72??8B????52E8????????83????C7????????????89????88????C6??????39??????????72??8B??????????50E8????????83????C7??????????????????89??????????88??????????88????39????72??8B????51E8????????83????C7????????????89????88????FF??????????38????75??8B????38????75??8B??8B??38????75??8D????8B??8B??38????74??EB??8B????38????75??3B????75??8B??8B????38????74??8B??8B??????????3B????0F85????????8B??????????8B??6A??5383????C7????????????89????508B??88??E8????????89????C7??????????????????8B??8B????64????????????595F5E5B8B????33??E8????????8B??5DC2????CCCCCCCCCCCCCCCCCCCCCCCCCCCC558B??6A??68????????64??????????50515356A1????????33??508D????64??????????8B??89????C7??????????33??89????83??????72??8B????50E8????????83????C7????????????89????88????C7????????????83??????72??8B????50E8????????83????C7????????????89????88????8B????64????????????595E5B8B??5DC3CCCCCCCCCC558B??6A??68????????64??????????5083????A1????????33??89????5356508D????64??????????33??89????538B??68????????8D????89????C7????????????89????88????E8????????C7????????????6A??8D????38????74??68????????EB??68????????E8????????8D????5083????8D????5651E8????????C6??????8D????52578B??E8????????83????C7????????????C6??????BE????????39????72??8B????50E8????????83????C7????????????89????88????88????39????72??8B????51E8????????83????C7????????????89????88????8B??8B????64????????????595E5B8B????33??E8????????8B??5DC3CCCCCCCCCCCCCCCCCCCCCCCCCCCCCC558B??6A??68????????64??????????50515356A1????????33??508D????64??????????8B??89????C7??????????33??89????83??????72??8B????50E8????????83????C7????????????89????88????C7????????????83??????72??8B????50E8????????83????F6??????C7????????????89????88????74??56E8????????83????8B??8B????64????????????595E5B8B??5DC2????CCCC558B??6A??68????????64??????????50A1????????33??508D????64??????????C7????????????6A??6A??8D????5083????E8????????C7????????????83??????72??8B????51E8????????83????C7????????????C7????????????C6??????8B????64????????????598B??5DC2????CCCCCCCCCCCCCCCCCCCCCC558B??6A??68????????64??????????5083????A1????????33??89????535657508D????64??????????33??89????8B????89????89????B8????????89????C7????????????89????88??89????8D????BF????????39????72??8B??8B????39????73??8D????8B????518D????518B??E8????????C6??????508B??E8????????C6??????39????72??8B????52E8????????83????C7????????????89????88????88????39????72??8B????50E8????????83????C7????????????89????88????8B??8B????64????????????595F5E5B8B????33??E8????????8B??5DC2????CCCCCCCCCCCCCCCC558B??6A??68????????64??????????5081??????????A1????????33??89????535657508D????64??????????8B??33??89????8B????89??????????89?????????? }
condition:
- 7 of them and filesize <73728
+ uint16(0)==0x5a4d and filesize <2000KB and pe.imphash()=="548d9f5f1e74f34b85612667335d41f2" and all of them
}
-rule MALPEDIA_Win_Kingminer_Auto : FILE
+rule TRELLIX_ARC_Apt_Flamer_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "13b82737-eb1a-51ab-9795-8340f262e7e5"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kingminer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kingminer_auto.yar#L1-L123"
- license_url = "N/A"
- logic_hash = "f79d58fb6043de2ccd7faac7ea9ed3b2513556edb2a1cd9df8f496a155aebade"
+ description = "Rule to detect Flamer based on the PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "3bbe043d-c0dc-5aa2-b985-800a6d9038fd"
+ date = "2012-05-29"
+ modified = "2020-08-14"
+ reference = "https://www.forcepoint.com/ko/blog/x-labs/flameflamerskywiper-one-most-advanced-malware-found-yet"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/APT/flamer_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "554924ebdde8e68cb8d367b8e9a016c5908640954ec9fb936ece07ac4c5e1b75"
+ logic_hash = "3c1d3d015e086cff1f3d5add39397d8ed251b12144b31d8547165cbd0217735c"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Flamer"
+ actor_type = "Apt"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { a1???????? 885c30fe a1???????? 0fb64c30f9 884c30fc }
- $sequence_1 = { ff15???????? 6a01 ff15???????? 6a00 ff15???????? 8b4508 }
- $sequence_2 = { 83c40c 807c30ff62 8d4c30ff 0f8599010000 }
- $sequence_3 = { ff15???????? 6a00 ff15???????? 8b80c0000000 85c0 7422 }
- $sequence_4 = { 6a00 ff15???????? 6a00 ff15???????? 6a01 ff15???????? 6a00 }
- $sequence_5 = { 3bf0 741e 68c1000000 ff15???????? 5b }
- $sequence_6 = { ff15???????? a1???????? 50 ffd7 ff15???????? 6a01 ff15???????? }
- $sequence_7 = { 6a04 6800100000 51 52 ffd0 83c414 85c0 }
- $sequence_8 = { 8d4dec 51 8d580c 56 8bc7 c745ec89480489 }
- $sequence_9 = { 8b95d0feffff 2b4234 7419 83b9a000000000 7466 50 }
+ $pdb = "\\Projects\\Jimmy\\jimmydll_v2.0\\JimmyForClan\\Jimmy\\bin\\srelease\\jimmydll\\indsvc32.pdb"
condition:
- 7 of them and filesize <165888
+ uint16(0)==0x5a4d and filesize <500KB and any of them
}
-rule MALPEDIA_Win_Vapor_Rage_Auto : FILE
+rule TRELLIX_ARC_Kelihos_Botnet_Pdb : BOTNET FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "11bddf4b-6d86-5af5-ae51-c6d26a16eb1c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vapor_rage"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.vapor_rage_auto.yar#L1-L122"
- license_url = "N/A"
- logic_hash = "be731f13a1ff78238c54efa2479336e60a09907f2a709db9a3ea573dd84f70f8"
+ description = "Rule to detect Kelihos malware based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "2b6683a1-ba19-586b-8a92-89d4764efa12"
+ date = "2013-09-04"
+ modified = "2020-08-14"
+ reference = "https://www.malwaretech.com/2017/04/the-kelihos-botnet.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_kelhios_botnet_pdb.yar#L1-L26"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "f0a6d09b5f6dbe93a4cf02e120a846073da2afb09604b7c9c12b2e162dfe7090"
+ logic_hash = "f60fb85161f86653f390b444d568da24cf07b3be99856230156741e8451e2a3f"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BOTNET, FILE"
+ rule_version = "v1"
+ malware_type = "botnet"
+ malware_family = "Botnet:W32/Kelihos"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 6a07 e8???????? e8???????? e8???????? e8???????? 8325????????00 c745fcfeffffff }
- $sequence_1 = { 6a00 0fb755b0 52 8b45ac 50 }
- $sequence_2 = { 5f 5e c3 68???????? ff15???????? c3 }
- $sequence_3 = { 32db 885de7 c745fcfeffffff e8???????? 84db 0f8564ffffff }
- $sequence_4 = { 885de7 c745fcfeffffff e8???????? 84db 0f8564ffffff e8???????? }
- $sequence_5 = { 6a1f 8b4de4 51 ff15???????? }
- $sequence_6 = { 8b55f8 81ca80000000 8955f8 6a04 8d45f8 50 6a1f }
- $sequence_7 = { eb59 48 a3???????? e8???????? }
- $sequence_8 = { 894df8 8b55f8 81ca80000000 8955f8 6a04 8d45f8 }
- $sequence_9 = { f2c3 f2e94e030000 55 8bec 5d e9???????? 55 }
+ $pdb = "\\Only\\Must\\Not\\And.pdb"
+ $pdb1 = "\\To\\Access\\Do.pdb"
condition:
- 7 of them and filesize <296960
+ uint16(0)==0x5a4d and filesize <1440KB and any of them
}
-rule MALPEDIA_Win_Holerun_Auto : FILE
+rule TRELLIX_ARC_Festi_Botnet_Pdb : BOTNET FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3860635a-d58f-5696-9faf-227bf0bff05b"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.holerun"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.holerun_auto.yar#L1-L117"
- license_url = "N/A"
- logic_hash = "5a5dd43f05b56cbfa86f75c5f65da136c78c894cffec56359e16aa1bc679245f"
+ description = "Rule to detect the Festi botnet based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "02f4149d-b8ac-5852-8cbe-c47f4cddcba6"
+ date = "2013-03-04"
+ modified = "2020-08-14"
+ reference = "https://www.welivesecurity.com/2012/05/11/king-of-spam-festi-botnet-analysis/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_festi_botnet_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "e55913523f5ae67593681ecb28d0fa1accee6739fdc3d52860615e1bc70dcb99"
+ logic_hash = "46e2576900fe94d614a683d4f09079b7ac78654079b2e558d076bcb42db4bf11"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
-
- strings:
- $sequence_0 = { 85c0 740c c785ec00000000000000 eb63 488b05???????? }
- $sequence_1 = { e8???????? 8b45c4 83f840 7472 8b45c4 83f804 }
- $sequence_2 = { c744242000010000 41b901000000 41b800000000 ba03000000 4889c1 }
- $sequence_3 = { 488b85e0000000 488b4020 4889c1 488b05???????? ffd0 }
- $sequence_4 = { ffd0 488b85e0000000 488b4020 4889c1 488b05???????? }
- $sequence_5 = { ffd0 8b85cc030000 4881c458040000 5b 5d c3 }
- $sequence_6 = { 4883c00f 48c1e804 48c1e004 e8???????? 4829c4 }
- $sequence_7 = { eb1e 8345f401 488345f828 488b45e8 0fb74006 0fb7c0 }
- $sequence_8 = { c705????????00000000 c705????????00000000 8b45fc 8905???????? }
- $sequence_9 = { 488b4d10 e8???????? 4885c0 7507 b8ffffffff eb05 }
+ quality = 70
+ tags = "BOTNET, FILE"
+ rule_version = "v1"
+ malware_type = "botnet"
+ malware_family = "Botnet:W32/Festi"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
+
+ strings:
+ $pdb = "\\eclipse\\botnet\\drivers\\Bin\\i386\\kernel.pdb"
condition:
- 7 of them and filesize <156672
+ uint16(0)==0x5a4d and filesize <80KB and any of them
}
-rule MALPEDIA_Win_Unidentified_106_Auto : FILE
+rule TRELLIX_ARC_Redline_Payload : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "149fd261-d790-5329-9f62-f83b72c17c68"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_106"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_106_auto.yar#L1-L134"
- license_url = "N/A"
- logic_hash = "b7794c4f304d97457540366e3546931a6b0930939bfed6f5754198d0fc46abff"
+ description = "Rule to detect the RedLine payload"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "61c2032f-1e6b-5123-8f99-ff83ae95e8a9"
+ date = "2020-04-16"
+ modified = "2020-08-14"
+ reference = "https://www.proofpoint.com/us/threat-insight/post/new-redline-stealer-distributed-using-coronavirus-themed-email-campaign"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_redline.yar#L1-L38"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "5df956f08d6ad0559efcdb7b7a59b2f3b95dee9e2aa6b76602c46e2aba855eff"
+ logic_hash = "44df161b7434b9137ca5bb919eb314f8447b216b3f6e1214606a898fb36ee4f4"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/RedLine"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8bc2 3bd5 7d14 2bea 33d2 448bc5 49c1e002 }
- $sequence_1 = { d0250000ffff 3d00000d00 740e 8b4b04 53 e8???????? 413bc7 }
- $sequence_2 = { e8???????? 488b8bf8000000 4889bbf0000000 e8???????? 488b8b00010000 4889bbf8000000 e8???????? }
- $sequence_3 = { e8???????? e8???????? 8bc8 b881808080 f7e9 03d1 c1fa07 }
- $sequence_4 = { 8bc1 418d140e 4803c6 41b800100000 66440b833c040000 4889442438 8bc2 }
- $sequence_5 = { a806 0f85cf020000 bafbff0000 6623c2 6683c802 66898108030000 33c0 }
- $sequence_6 = { 488d442448 4889442428 4c8bcb 488d442430 418bd7 498bce 4889442420 }
- $sequence_7 = { e8???????? 85c0 7920 488b0f 488d5710 4885d2 0f8454fbffff }
- $sequence_8 = { e9???????? 498b5f08 be02000000 440fb7f5 4d03f3 4180fc06 7508 }
- $sequence_9 = { 90 eb02 eb00 498bc4 488b5c2478 488bac2480000000 4883c440 }
+ $s1 = "Cambrel.exe" fullword ascii
+ $s2 = { 22 00 54 00 65 00 78 00 74 00 49 00 6e 00 70 00 75 00 74 00 46 00 72 00 61 00 6d 00 65 00 77 00 6f 00 72 00 6b 00 2e 00 44 00 59 00 4e 00 4c 00 49 00 4e 00 4b 00 22 00 }
+ $op0 = { 06 7c 34 00 00 04 7b 17 00 00 04 7e 21 00 00 0a }
+ $op1 = { 96 00 92 0e 83 02 02 00 f4 20 }
+ $op2 = { 03 00 c6 01 d9 08 1b 03 44 }
+ $p0 = { 80 00 96 20 83 11 b7 02 10 }
+ $p1 = { 20 01 00 72 0f 00 20 02 00 8a 0f 00 20 03 00 61 }
+ $p2 = { 03 00 c6 01 cd 06 13 03 79 }
condition:
- 7 of them and filesize <27402240
+ uint16(0)==0x5a4d and filesize <60KB and all of ($s*) and all of ($op*) or all of ($p*)
}
-rule MALPEDIA_Win_Zebrocy_Auto : FILE
+rule TRELLIX_ARC_Malw_Likseput_Backdoor_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ddee4b03-585f-5184-85a4-c6cc1e810bdc"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zebrocy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.zebrocy_auto.yar#L1-L161"
- license_url = "N/A"
- logic_hash = "619394d96ac2748c82d29651fdad853561cf847222687873937db9b64b7f21e0"
+ description = "Rule to detect Likseput backdoor based on the PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "2193daf8-016b-5f49-97ec-b821c8da22f6"
+ date = "2011-03-26"
+ modified = "2020-08-14"
+ reference = "https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/bkdr_likseput.e"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_likseput_backdoor_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "993b36370854587f4eef3366562f01ab87bc4f7b88a21f07b44bd5051340386d"
+ logic_hash = "2afc4b7e6a5f0d9fed9a075aebaac8157e843c83c55c3f2255431bb6a03459ec"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Likseput"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 014158 11515c e8???????? dc6360 }
- $sequence_1 = { 8bc6 33d2 66891478 8bc6 5f c3 8bff }
- $sequence_2 = { 0103 83c41c 5b 5e }
- $sequence_3 = { 83c438 68581b0000 ff15???????? 83bd00f7ffff08 8b85ecf6ffff 7306 8d85ecf6ffff }
- $sequence_4 = { 8b7508 837e0800 7610 8b4608 8d808c994200 fe08 }
- $sequence_5 = { 0110 8b7dd4 ba???????? 89470c }
- $sequence_6 = { 0103 8b0e ba???????? e8???????? }
- $sequence_7 = { 8b441a20 85c9 7f0d 7c05 83f801 7706 }
- $sequence_8 = { 0102 8b45d4 89500c 89c1 }
- $sequence_9 = { 014150 8b550c 115154 014158 }
- $sequence_10 = { 0f8553010000 837de400 7c5d 7f04 85f6 }
- $sequence_11 = { 0103 31d2 85ff 8b03 }
- $sequence_12 = { 7303 8d45b8 8b4dc8 03c8 8bc6 83fa10 }
- $sequence_13 = { 68???????? 6888000800 ff15???????? 8bf0 85f6 }
- $sequence_14 = { 0110 5e 5f 5d }
- $sequence_15 = { 3bc1 0f87c8090000 ff2485689c4100 33c0 838de8fdffffff }
+ $pdb = "\\work\\code\\2008-7-8muma\\mywork\\winInet_winApplication2009-8-7\\mywork\\aaaaaaa\\Release\\aaaaaaa.pdb"
condition:
- 7 of them and filesize <393216
+ uint16(0)==0x5a4d and filesize <40KB and any of them
}
-rule MALPEDIA_Win_Sanny_Auto : FILE
+rule TRELLIX_ARC_Nionspy : FILEINFECTOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "de370068-b36d-54a3-8d87-5388d41e6079"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sanny"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sanny_auto.yar#L1-L125"
- license_url = "N/A"
- logic_hash = "d17095442c6476759b49de20e09af803b9389d5106c74ad1d4cc2616aa104b23"
+ description = "Triggers on old and new variants of W32/NionSpy file infector"
+ author = "Trellix ARC Team"
+ id = "86051ef8-a18b-553c-b06c-490f8d6df5cf"
+ date = "2024-09-01"
+ modified = "2020-08-14"
+ reference = "https://blogs.mcafee.com/mcafee-labs/taking-a-close-look-at-data-stealing-nionspy-file-infector"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_NionSpy.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "982ba52f39352aee9e2d2dcadfb0816c439e92d0e5947afa7860630720913742"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "FILEINFECTOR, FILE"
+ malware_type = "fileinfector"
+ malware_family = "FileInfector:W32/NionSpy"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 51 8bcb e8???????? 8b5310 68???????? 8d442a08 }
- $sequence_1 = { 8b842430060000 8d742410 8d5901 b987000000 53 81ec1c020000 8bfc }
- $sequence_2 = { ebd3 53 55 56 57 }
- $sequence_3 = { 52 68???????? 56 e8???????? 8b44244c }
- $sequence_4 = { 8bc2 c1c60a 03f1 f7d0 0bc6 33c1 }
- $sequence_5 = { ae 40 00bcae4000e0ae 40 0023 d18a0688078a }
- $sequence_6 = { 55 68???????? 55 e8???????? 8b4c2424 83c410 55 }
- $sequence_7 = { 663918 747f 668b11 6683fa41 720c }
- $sequence_8 = { f3ab 8b0d???????? aa 898c2408010000 b906000000 33c0 8dbc240d010000 }
- $sequence_9 = { 8b44241c 8d9424dc000000 52 50 ffd5 b925000000 33c0 }
+ $variant2015_infmarker = "aCfG92KXpcSo4Y94BnUrFmnNk27EhW6CqP5EnT"
+ $variant2013_infmarker = "ad6af8bd5835d19cc7fdc4c62fdf02a1"
+ $variant2013_string = "%s?cstorage=shell&comp=%s"
condition:
- 7 of them and filesize <253952
+ uint16(0)==0x5A4D and uint32( uint32(0x3C))==0x00004550 and 1 of ($variant*)
}
-rule MALPEDIA_Win_Xagent_Auto : FILE
+rule TRELLIX_ARC_Msworldexploit_Builder_Doc : MALDOC FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bde2508f-cfa2-522c-bf18-0bedb23d3501"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xagent"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xagent_auto.yar#L1-L231"
- license_url = "N/A"
- logic_hash = "1ef231aa11dc012f9839829c886b5e479b3c99a501478ca77ee155ba663fd5ac"
+ description = "Rule to detect RTF/Docs files created by MsWordExploit Builder"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "6c4c091b-5fce-583a-bc17-31830251892c"
+ date = "2024-09-01"
+ modified = "2020-08-14"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_MsWordExploit_DOC.yar#L1-L24"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "f85c6d79e5ed20084d35f9de92a9d9ce20cf4b3100b1226d64147e366934585d"
score = 75
- quality = 73
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 68
+ tags = "MALDOC, FILE"
+ malware_type = "maldoc"
+ malware_family = "Maldoc:W32/MSwordExploit"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { c1ea02 6bd20d b801000000 2bc2 }
- $sequence_1 = { ff15???????? 8bd8 e8???????? 03d8 }
- $sequence_2 = { 5b 8be5 5d c20400 8d4de4 e8???????? b8???????? }
- $sequence_3 = { 8b4604 85c0 7407 8b4d08 8b11 }
- $sequence_4 = { 2bc7 8b5204 8b0482 8b0488 8b4e10 }
- $sequence_5 = { 85c9 7423 8b7e08 ff460c 03ff }
- $sequence_6 = { 33d2 eb02 8b11 8b4808 8bc1 57 }
- $sequence_7 = { 3b7e0c 7707 c7460c00000000 49 }
- $sequence_8 = { 894e10 7507 c7460c00000000 5f }
- $sequence_9 = { 55 8bec 33c0 83ec0c 39412c }
- $sequence_10 = { 384b02 0f92c3 488d4c2430 e8???????? 90 }
- $sequence_11 = { e8???????? 90 0fb705???????? 6689442420 }
- $sequence_12 = { e8???????? 488b4328 4c8bcf 4c8bc6 }
- $sequence_13 = { 84c0 740c 488b07 488b0b }
- $sequence_14 = { 8bd8 e8???????? 8d0c18 e8???????? }
- $sequence_15 = { 48896c2410 4889742418 57 4883ec30 4883792800 }
- $sequence_16 = { e8???????? 498bce 4e8d0437 482bcf }
- $sequence_17 = { 740c 488b07 4c8b13 488903 }
- $sequence_18 = { b803b57ea5 f7e6 c1ea06 6bd263 }
- $sequence_19 = { ff15???????? baf4010000 488bcb ff15???????? 85c0 }
- $sequence_20 = { c1ea07 69d295000000 2bca 8bd1 }
- $sequence_21 = { 75f8 482bc3 4d8bc6 498bd7 }
- $sequence_22 = { 75f8 482bc3 4c8bc6 488bd7 }
- $sequence_23 = { 75f8 482bc3 498bd7 488d0c18 }
- $sequence_24 = { 75f8 482bc5 4533e4 488bbc2480000000 }
- $sequence_25 = { 75f8 482bc3 498bd6 488d0c18 e8???????? 488bd7 4885ff }
+ $s1 = { 68 74 74 70 3A 2F 2F 61 70 69 2E 6D 73 77 6F 72 64 65 78 70 6C 6F 69 74 2E 63 6F 6D }
+ $s2 = "{\\*\\generator mswordexploit 6.3.9600}" fullword ascii
condition:
- 7 of them and filesize <729088
+ uint16(0)==0x3030 and filesize <4000KB and any of them
}
-rule MALPEDIA_Win_Highnote_Auto : FILE
+rule TRELLIX_ARC_Malw_Inabot_Worm : WORM FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9754f7b1-01be-5dce-8939-9dbedbd321d3"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.highnote"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.highnote_auto.yar#L1-L128"
- license_url = "N/A"
- logic_hash = "63e3b329a81995d654d7d4235beb319e224a0ea782f84de7ddd9bdcbead90225"
+ description = "Rule to detect inabot worm based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "b899d2d6-000a-5363-9efe-527dcd0cea17"
+ date = "2013-04-19"
+ modified = "2020-08-14"
+ reference = "http://verwijderspyware.blogspot.com/2013/04/elimineren-w32inabot-worm-hoe-te.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_inabot_worm_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "c9c010228254aae222e31c669dda639cdd30695729b8ef2b6ece06d899a496aa"
+ logic_hash = "70485de4e071b684faa87484ce2a53a8b2a29d0a2954e785b858c7ff1d908de0"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "WORM, FILE"
+ rule_version = "v1"
+ malware_type = "worm"
+ malware_family = "Worm:W32/Inabot"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { b3a7 8cd7 a5 329ea1afa9a5 5d b5a5 }
- $sequence_1 = { 2d620a682c fd 9d 8945ec 8945f0 8945f4 9c }
- $sequence_2 = { 3665017cf341 14b0 63c5 ef d550 3362db }
- $sequence_3 = { 0fb6c9 8a1408 0fb6da 03de 81e3ff000080 }
- $sequence_4 = { 98 fd bfb47ea0c6 ddbb690cc1af 6595 fa 6a23 }
- $sequence_5 = { 115542 305421f0 d438 bd4dae2b31 b1f7 }
- $sequence_6 = { 90 9e a4 3634a1 6594 2424 e230 }
- $sequence_7 = { 2ca7 33e6 7479 1e 0477 ed 7cb1 }
- $sequence_8 = { 8636 35cfd6d703 b368 321e 4a 727d 51 }
- $sequence_9 = { 000b 2920 da927a3741d4 7e5b a7 5a 40 }
+ $pdb = "\\trasser\\portland.pdb"
+ $pdb1 = "\\mainstream\\archive.pdb"
condition:
- 7 of them and filesize <321536
+ uint16(0)==0x5a4d and filesize <180KB and any of them
}
-rule MALPEDIA_Win_Prestige_Auto : FILE
+rule TRELLIX_ARC_Jatboss : PHISHING FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "554de8b7-e6ad-5535-8c14-f95b90ec653d"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.prestige"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.prestige_auto.yar#L1-L129"
- license_url = "N/A"
- logic_hash = "3d9139c6507e377e5a1b52cf299e6f205e8499ed341925da786360ebd802ec9b"
+ description = "Rule to detect PDF files from Jatboss campaign and MSG files that contained those attachents"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "009a7486-2ee8-57ef-8dfd-fcbd035b4e85"
+ date = "2019-12-04"
+ modified = "2020-08-14"
+ reference = "https://exchange.xforce.ibmcloud.com/collection/JATBOSS-Phishing-Kit-17c74b38860de5cb9fc727e6c0b6d5b5"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_jatboss.yar#L1-L36"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "b81fb37dc48812f6ad61984ecf2a8dbbfe581120257cb4becad5375a12e755bb"
+ logic_hash = "5e6e4c8f6c0896623f166a98eb83a9a4f23139306671cf2e35ba239b2dc191fc"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 66
+ tags = "PHISHING, FILE"
+ rule_version = "v1"
+ malware_type = "phishing"
+ malware_family = "Phishing:W32/Jatboss"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 894648 8b7a4c 897e4c 837a4c10 7706 }
- $sequence_1 = { 03f3 c706652b3030 8d4604 33d2 e9???????? 8bd1 c745c409000000 }
- $sequence_2 = { 83f826 7603 6a26 58 0fb60c85be534700 0fb63485bf534700 }
- $sequence_3 = { b9fe020000 3bc1 0f4fc1 8d8decfcffff 50 8985e8fcffff e8???????? }
- $sequence_4 = { 3bf0 730a 8bc6 89742410 897c2414 50 ff7508 }
- $sequence_5 = { 8d45fc 50 8bd6 e8???????? 8b7508 8bf8 59 }
- $sequence_6 = { 8bf2 57 8bf9 8d4e02 668b06 83c602 6685c0 }
- $sequence_7 = { 85c0 740c 8d432c 8945f8 8b00 }
- $sequence_8 = { 8945d8 8b45e8 5e 13ce f765e0 6a00 8945ec }
- $sequence_9 = { 59 c3 8b4c240c 68???????? e8???????? 8b44240c 5e }
+ $jat = { 3C 3C 2F 41 75 74 68 6F 72 28 4A 41 54 29 20 2F 43 72 65 61 74 6F 72 28 }
+ $jatboss = { 3C 3C 2F 41 75 74 68 6F 72 28 4A 41 54 29 20 2F 43 72 65 61 74 6F 72 28 }
+ $spam = { 54 00 68 00 69 00 73 00 20 00 65 00 2D 00 6D 00 61 00 69 00 6C 00 20 00 61 00 6E 00 64 00 20 00 61 00 6E 00 79 00 20 00 61 00 74 00 74 00 61 00 63 00 68 00 6D 00 65 00 6E 00 74 00 20 00 61 00 72 00 65 00 20 00 43 00 6F 00 6E 00 66 00 69 00 64 00 65 00 6E 00 74 00 69 00 61 00 6C 00 2E 00 }
condition:
- 7 of them and filesize <1518592
+ ( uint16(0)==0x5025 and filesize <1000KB and ($jat or $jatboss)) or ( uint16(0)==0xcfd0 and $spam and any of ($jat*))
}
-rule MALPEDIA_Win_Screencap_Auto : FILE
+rule TRELLIX_ARC_Shifu : FINANCIAL
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "104aba67-45fe-5a81-add7-5f096073514f"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.screencap"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.screencap_auto.yar#L1-L125"
- license_url = "N/A"
- logic_hash = "d12bc6cdd7eeaf3c014435658ac08460e21def542afb74f89d01054fc70f3f9a"
+ description = "No description has been set in the source file - Trellix ARC"
+ author = "McAfee Labs"
+ id = "81e9ad25-1df0-5196-be8b-1d1d5d8e4387"
+ date = "2024-09-01"
+ modified = "2020-08-14"
+ reference = "https://blogs.mcafee.com/mcafee-labs/japanese-banking-trojan-shifu-combines-malware-tools/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_Shifu.yar#L1-L24"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "dfa6165f8d2750330c71dedbde293780d2bb27e8eb3635e47ca770ff7b9a9d63"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "FINANCIAL"
+ malware_type = "financial"
+ malware_family = "Backdoor:W32/Shifu"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 488b4c2450 488364242000 488d0591e90000 488b0cc8 4c8d4c2458 488d542460 498b0c0f }
- $sequence_1 = { 41c1eb05 418d5f01 41c1e302 83fe08 }
- $sequence_2 = { 4883ec20 4c8d25a09c0000 33f6 33db 498bfc 837f0801 7526 }
- $sequence_3 = { 39842420100000 0f869f010000 6a04 687c334700 55 e8???????? }
- $sequence_4 = { 488bce ff15???????? bf00080000 3bdf 7702 }
- $sequence_5 = { 72ed 48833d????????00 741f 488d0d06130100 e8???????? }
- $sequence_6 = { 8bdf e8???????? 85ff 741c 488d4c2450 0fb601 84c0 }
- $sequence_7 = { 3bf8 0f869c000000 6a04 687c334700 55 e8???????? }
- $sequence_8 = { 8d854c100000 50 ff15???????? 8bf0 8975e0 85f6 0f84bb030000 }
- $sequence_9 = { 89470c 894710 894714 8d854c2c0000 50 e8???????? 6805040000 }
+ $b = "RegCreateKeyA"
+ $a = "CryptCreateHash"
+ $c = {2F 00 63 00 20 00 73 00 74 00 61 00 72 00 74 00 20 00 22 00 22 00 20 00 22 00 25 00 73 00 22 00 20 00 25 00 73 00 00 00 00 00 63 00 6D 00 64 00 2E 00 65 00 78 00 65 00 00 00 72 00 75 00 6E}
+ $d = {53 00 6E 00 64 00 56 00 6F 00 6C 00 2E 00 65 00 78 00 65}
+ $e = {52 00 65 00 64 00 69 00 72 00 65 00 63 00 74 00 45 00 58 00 45}
condition:
- 7 of them and filesize <1391616
+ all of them
}
-rule MALPEDIA_Win_Acbackdoor_Auto : FILE
+rule TRELLIX_ARC_MALW_Emotet : FINANCIAL FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "3b37a750-d7e0-5ba6-b796-2dbd4d0ee414"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acbackdoor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.acbackdoor_auto.yar#L1-L134"
- license_url = "N/A"
- logic_hash = "429f71da1516445c35871fa605cbaf3bc00568c9cb40515ab43ec3dc7a2d0a3f"
+ description = "Rule to detect unpacked Emotet"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "5bc83065-dfdd-56b7-9983-200bff35c8b1"
+ date = "2020-07-21"
+ modified = "2020-08-14"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_emotet.yar#L1-L32"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "223e4453a6c3b56b0bc0f91147fa55ea59582d64b8a5c08f1f8d06026044065e"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "FINANCIAL, FILE"
+ rule_version = "v1"
+ malware_type = "financial"
+ malware_family = "Backdoor:W32/Emotet"
+ actor_type = "Cybercrime"
+ hash1 = "a6621c093047446e0e8ae104769af93a5a8ed147ab8865afaafbbd22adbd052d"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { ba04000000 e9???????? 8b542448 8b4c244c 8b742440 89542420 894c2424 }
- $sequence_1 = { ebbd 8b442440 890424 ff15???????? 83ec04 89c3 83c42c }
- $sequence_2 = { c744240c76070000 c7442408???????? c744240404000000 892c24 e8???????? 8b442438 892c24 }
- $sequence_3 = { 8b7904 895c2408 894c2404 890424 e8???????? 8b4c243c 0fb64500 }
- $sequence_4 = { e8???????? 85c0 7e06 83c414 5b 5e c3 }
- $sequence_5 = { e8???????? 8b06 8b5054 85d2 0f8415fdffff 8b4050 85c0 }
- $sequence_6 = { c744241087934a00 c744240cc8000000 c7442408???????? c744240401000000 892c24 e8???????? 8b85c4000000 }
- $sequence_7 = { 89c8 8b4c2430 31de 8b5c2434 8987d0000000 894f50 895f54 }
- $sequence_8 = { e8???????? 8b83c4000000 c783cc00000004000000 c783c800000016000000 c60000 891c24 e8???????? }
- $sequence_9 = { e8???????? 8bbc241c020000 8d742434 31db 85ff 7e1e 8b86f0010000 }
+ $pattern_0 = { 8b45fc 8be5 5d c3 55 8bec }
+ $pattern_1 = { 3c39 7e13 3c61 7c04 3c7a 7e0b 3c41 }
+ $pattern_2 = { 7c04 3c39 7e13 3c61 7c04 3c7a 7e0b }
+ $pattern_3 = { 5f 8bc6 5e 5b 8be5 }
+ $pattern_4 = { 5f 668906 5e 5b }
+ $pattern_5 = { 3c30 7c04 3c39 7e13 3c61 7c04 }
+ $pattern_6 = { 53 56 57 8bfa 8bf1 }
+ $pattern_7 = { 3c39 7e13 3c61 7c04 3c7a 7e0b }
+ $pattern_8 = { 55 8bec 83ec14 53 }
+ $pattern_9 = { 5e 8be5 5d c3 55 8bec }
condition:
- 7 of them and filesize <1704960
+ 7 of them and filesize <180224
}
-rule MALPEDIA_Win_Solarbot_Auto : FILE
+rule TRELLIX_ARC_Kartoxa_Malware_Pdb : POS FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8e3c74e1-0da4-57ab-ab5f-74e62e2d1f7c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.solarbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.solarbot_auto.yar#L1-L115"
- license_url = "N/A"
- logic_hash = "2b058f45b0c5077e371ef262d327c05a0be6ae89bd9fed8f4379a07e0dfd6a86"
+ description = "Rule to detect Kartoxa POS based on the PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "3d2dbf22-5d8f-5f19-9048-2d021ada22c8"
+ date = "2010-10-09"
+ modified = "2020-08-14"
+ reference = "https://securitynews.sonicwall.com/xmlpost/guatambu-new-multi-component-infostealer-drops-kartoxa-pos-malware-apr-08-2016/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_backdoor_katorxa_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "86dd21b8388f23371d680e2632d0855b442f0fa7e93cd009d6e762715ba2d054"
+ logic_hash = "6e1810af386f3aada4cd1d72f76d8210d201808c8fe1d21d379ff1a825d93710"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "POS, FILE"
+ rule_version = "v1"
+ malware_type = "pos"
+ malware_family = "Pos:W32/Kartoxa"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 0f8407feffff bb01000000 4b 90 43 8b854cfeffff }
- $sequence_1 = { 50 8d8500fcffff 50 6a00 }
- $sequence_2 = { 85db 7463 ff75f8 e8???????? 84c0 7457 }
- $sequence_3 = { 8d85f4fdffff 50 e8???????? 6a0c 8d85e8fdffff 50 e8???????? }
- $sequence_4 = { 50 e8???????? 680c010000 8d85f4faffff }
- $sequence_5 = { 8b4508 8945cc 8b7d0c 8b4510 }
- $sequence_6 = { 53 e8???????? 83fe0c 7509 ff75f0 }
- $sequence_7 = { 85c0 0f847d000000 ff75f4 e8???????? }
- $sequence_8 = { c645c401 eb23 6a00 6a00 6a00 }
- $sequence_9 = { 83c040 8985e4fdffff 8b85e0fdffff 0385d0fdffff 8b583c 83bdccfdffff0c }
+ $pdb = "\\vm\\devel\\dark\\mmon\\Release\\mmon.pdb"
condition:
- 7 of them and filesize <204800
+ uint16(0)==0x5a4d and filesize <200KB and any of them
}
-rule MALPEDIA_Win_Cloudwizard_Auto : FILE
+rule TRELLIX_ARC_Cyaxsharp_Rezer0 : LOADER
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "429d1e4e-ef3f-5d58-8bf0-a0b83d6be71f"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cloudwizard"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cloudwizard_auto.yar#L1-L122"
- license_url = "N/A"
- logic_hash = "1171accd4a2881e0996da43d7ff173c5cb1938e75ca585c448a0136c0ce6d102"
+ description = "Detects CyaX-Sharp/ReZer0 loader samples based on the embedded scheduled task template"
+ author = "Max 'Libra' Kersten for McAfee's Advanced Threat Research Team"
+ id = "7a1addcf-4e8f-5290-8788-9b0738128160"
+ date = "2021-04-08"
+ modified = "2021-08-04"
+ reference = "This rule was published in combination with the following McAfee ATR blog: https://www.mcafee.com/blogs/enterprise/mcafee-enterprise-atr/see-ya-sharp-a-loaders-tale/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MAL_cyax_sharp_loader.yar#L1-L16"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "3d6daaf7a85a9b3898e4ce5d5293b09f26965f9f7280b34ba8f6814b7f14dec2"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "LOADER"
+ version = "1.0"
+ malware_type = "loader"
strings:
- $sequence_0 = { c3 8d85d4fdffff 50 57 c785d4fdffff2c020000 e8???????? }
- $sequence_1 = { 668945ee 58 6a7c 668945f0 58 6a6d }
- $sequence_2 = { 8d45ec 663118 40 40 }
- $sequence_3 = { 8bc8 8d8618060000 8d7802 668b18 40 40 6685db }
- $sequence_4 = { ebd6 55 8bec 81ecb80e0000 }
- $sequence_5 = { 6a01 897dfc 57 c706???????? 897e30 ff15???????? 894634 }
- $sequence_6 = { 8d4530 d1f9 50 8d044e 50 e8???????? }
- $sequence_7 = { 668945b8 8d45a0 663108 40 40 663918 }
- $sequence_8 = { 40 6685d2 75f6 2bc1 8d8e18060000 }
- $sequence_9 = { 6a5b 6689451e 58 6a5c 66894520 58 6a4d }
+ $template = { 01A10C3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3136223F3E0D0A3C5461736B2076657273696F6E3D22312E322220786D6C6E733D22687474703A2F2F736368656D61732E6D6963726F736F66742E636F6D2F77696E646F77732F323030342F30322F6D69742F7461736B223E0D0A20203C526567697374726174696F6E496E666F3E0D0A202020203C446174653E323031342D31302D32355431343A32373A34342E383932393032373C2F446174653E0D0A202020203C417574686F723E5B5553455249445D3C2F417574686F723E0D0A20203C2F526567697374726174696F6E496E666F3E0D0A20203C54726967676572733E0D0A202020203C4C6F676F6E547269676765723E0D0A2020202020203C456E61626C65643E747275653C2F456E61626C65643E0D0A2020202020203C5573657249643E5B5553455249445D3C2F5573657249643E0D0A202020203C2F4C6F676F6E547269676765723E0D0A202020203C526567697374726174696F6E547269676765723E0D0A2020202020203C456E61626C65643E66616C73653C2F456E61626C65643E0D0A202020203C2F526567697374726174696F6E547269676765723E0D0A20203C2F54726967676572733E0D0A20203C5072696E636970616C733E0D0A202020203C5072696E636970616C2069643D22417574686F72223E0D0A2020202020203C5573657249643E5B5553455249445D3C2F5573657249643E0D0A2020202020203C4C6F676F6E547970653E496E746572616374697665546F6B656E3C2F4C6F676F6E547970653E0D0A2020202020203C52756E4C6576656C3E4C6561737450726976696C6567653C2F52756E4C6576656C3E0D0A202020203C2F5072696E636970616C3E0D0A20203C2F5072696E636970616C733E0D0A20203C53657474696E67733E0D0A202020203C4D756C7469706C65496E7374616E636573506F6C6963793E53746F704578697374696E673C2F4D756C7469706C65496E7374616E636573506F6C6963793E0D0A202020203C446973616C6C6F77537461727449664F6E4261747465726965733E66616C73653C2F446973616C6C6F77537461727449664F6E4261747465726965733E0D0A202020203C53746F704966476F696E674F6E4261747465726965733E747275653C2F53746F704966476F696E674F6E4261747465726965733E0D0A202020203C416C6C6F77486172645465726D696E6174653E66616C73653C2F416C6C6F77486172645465726D696E6174653E0D0A202020203C53746172745768656E417661696C61626C653E747275653C2F53746172745768656E417661696C61626C653E0D0A202020203C52756E4F6E6C7949664E6574776F726B417661696C61626C653E66616C73653C2F52756E4F6E6C7949664E6574776F726B417661696C61626C653E0D0A202020203C49646C6553657474696E67733E0D0A2020202020203C53746F704F6E49646C65456E643E747275653C2F53746F704F6E49646C65456E643E0D0A2020202020203C526573746172744F6E49646C653E66616C73653C2F526573746172744F6E49646C653E0D0A202020203C2F49646C6553657474696E67733E0D0A202020203C416C6C6F7753746172744F6E44656D616E643E747275653C2F416C6C6F7753746172744F6E44656D616E643E0D0A202020203C456E61626C65643E747275653C2F456E61626C65643E0D0A202020203C48696464656E3E66616C73653C2F48696464656E3E0D0A202020203C52756E4F6E6C79496649646C653E66616C73653C2F52756E4F6E6C79496649646C653E0D0A202020203C57616B65546F52756E3E66616C73653C2F57616B65546F52756E3E0D0A202020203C457865637574696F6E54696D654C696D69743E505430533C2F457865637574696F6E54696D654C696D69743E0D0A202020203C5072696F726974793E373C2F5072696F726974793E0D0A20203C2F53657474696E67733E0D0A20203C416374696F6E7320436F6E746578743D22417574686F72223E0D0A202020203C457865633E0D0A2020202020203C436F6D6D616E643E5B4C4F434154494F4E5D3C2F436F6D6D616E643E0D0A202020203C2F457865633E0D0A20203C2F416374696F6E733E0D0A3C2F5461736B3E }
condition:
- 7 of them and filesize <134144
+ $template
}
-rule MALPEDIA_Win_Exaramel_Auto : FILE
+rule TRELLIX_ARC_Shellcode_Mykins_Botnet : SHELLCODE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "55f2eda2-5892-5031-b695-0db68fb2d622"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.exaramel"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.exaramel_auto.yar#L1-L120"
- license_url = "N/A"
- logic_hash = "746a3a522250db31852461e3a3a31996745122c83c94633343076460de517b9c"
+ description = "Rule to detect the shellcode used in the MyKins Botnet"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "9dc80b27-59e2-5925-9bb7-64a54241f52b"
+ date = "2018-01-24"
+ modified = "2020-08-14"
+ reference = "https://blog.netlab.360.com/mykings-the-botnet-behind-multiple-active-spreading-botnets/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_shellcode_mykins_botnet.yar#L1-L27"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "5fa54c41a423d776d05bdac5b171ee685f54372b4e6aa41b57cce769ac2c6976"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "SHELLCODE, FILE"
+ rule_version = "v1"
+ malware_type = "shellcode"
+ malware_family = "ShellCode:W32/MyKins"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8bf0 85f6 7425 8d4e02 51 e8???????? 8b4d0c }
- $sequence_1 = { 83c408 85c0 7834 ff750c ff7508 ff75fc }
- $sequence_2 = { 3934bd60dd4100 7531 e8???????? 8904bd60dd4100 }
- $sequence_3 = { 8be5 5d c3 81f903000080 7519 ff35???????? b8???????? }
- $sequence_4 = { 7439 6aff 50 ff15???????? 85c0 7538 56 }
- $sequence_5 = { 50 e8???????? ffb5f0fdffff e8???????? 83c414 8b4dfc }
- $sequence_6 = { ffb5a4faffff ff15???????? 85c0 0f85c1feffff 33f6 }
- $sequence_7 = { 5d c3 f68594f7ffff10 746d }
- $sequence_8 = { 744b 817df4e8030000 b801000000 68f0030000 0f42f0 }
- $sequence_9 = { c3 8b03 8d4dec 51 6800040000 }
+ $a = { 4883EC28E847000000488D0DF0FFFFFF488D1539000000482BCA4803C14883C428C3CCCC488D05D5FFFFFF482BC8488BC1C3CCCC4883EC28E83F0D000033C04883C428C3CCCCCCCCCCCCCCCCCCCCCCCCE8000000005848B95510004001000000482BC148B950100040010000004803C1C3CCCCCC48897C24084C8BC94D85C0740C488BF9480FBEC2498BC8F3AA488B7C2408498BC1C3CCCC40534883EC20488BD9E85AFFFFFF488D0D53FFFFFF482BD94803C34883C4205BC3CCCCCC33D28BC2EB06FFC04883C10266391175F5F3C3CC668339004C8BC1740B4983C002664183380075F54C2BC20FB70266418904104883C2026685C075EF488BC1C34C8BC14C2BC20FB70266418904104883C2026685C075EF488BC1C3CC4C8BC14C2BC28A024188041048FFC284C075F3488BC1C3CC8039004C8BC1740949FFC04180380075F74C2BC28A024188041048FFC284C075F3488BC1C3CCCCCC48895C24084533D2458BCA4585C07E320FB702663901741A0FB719440FB7D88BC3412BC383F8207409442BDB4183FB20751041FFC14883C1024883C202453BC87CCE488B5C2408453BC8410F95C2418BC2C3CCCC4533C948895108458BC16644390A740D41FFC04963C06644390C4275F3664503C066448901664183C0026644894102C34883EC3833C04C8BD233D248895424228954242A668954242E66894424204885C9741A4D85D27415488BD1488D4C2420E89BFFFFFF488D4C242041FFD24883C438C3CCCC4883EC284863C14C8BCA4C8D44243833D233C94869C0F0D8FFFF488944243841FFD14883C428C3CC48895C241048897C241855488BEC4883EC604883651000488365C800488365D800488365E000488365F000488365F800498BD9498BF848894DC0488BC24C8D4DC04C8D45D0488D4D10BAFFFF1F00C745D030000000C745E840020000FFD0488B4D104885C9740DBA01000000FFD7488B4D10FFD34C8D5C2460498B5B18498B7B20498BE35DC3CCCC488BC44889580848896810565741544883EC308360D80083601800498BF18BEA4C8BE1498BD833FF4C8D4818488D50D88D4F054533C0FFD3894424208B44246085C0750733C0E9C20000008D14004533C033C9FFD6448B4424604C8D4C2460488BD0B9050000004503C0488BF0FFD38944242085C0740B33D2488BCEFF542470EBC28B4C246048B81986611886611886488BDE48F7E1482BCA48D1E94803CA48C1E908894C2460488B4B404885C9742E0FB743383BC57C262BC5992BC2D1F84C63C8781A8BC54A8D0C49992BC2498BD4D1F8448BC0E8AEFDFFFF85C0740B393B740B8B034803D8EBBE488B7B50488B4424784885C0740A4885FF7405488918EB0933D2488BCEFF542470488BC7488B5C2450488B6C24584883C430415C5F5EC3C20000CC4585C07410482BCA8A0288041148FFC241FFC875F3F3C3CC40534883EC20488BD9E8E6FBFFFF488D0DDFFBFFFF482BD94803C34883C4205BC3CCCCCC48895C2408488974241048897C24185541544155488BEC4883EC404863413C4C8BC1B90B020000488BF2C745E04D6D4765C745E474537973C745E874656D52C745EC6F757469C745F06E654164C745F46472657366C745F873006642394C00180F8584000000428B8400880000004533D24903C08B50208B58248B781C448B68184903D04903D84903F84585ED745B8B024533C94903C044380874234C8D5DE0488BC84C2BD8458A240B4584E47410443821750B48FFC149FFC180390075E741803C0100750842807C0DE000740E41FFC24883C204453BD57310EBB3420FB70C538B048F4903C0488906488B1E4885DB750883C8FFE9E1020000488D0D47340000E8D6FEFFFF488BD3488BC8E89BFCFFFF488D0D5034000048898690000000E8B8FEFFFF488B16488BC8E87DFCFFFF488D0D5A34000048898698000000E89AFEFFFF488B16488BC8E85FFCFFFF488D0D6C34000048894608E87FFEFFFF488B16488BC8E844FCFFFF488D0D8934000048894610E864FEFFFF488B16488BC8E829FCFFFF488D0D9E34000048894618E849FEFFFF488B16488BC8E80EFCFFFF488D0DAB34000048894620E82EFEFFFF488B16488BC8E8F3FBFFFF488D0DC834000048894628E813FEFFFF488B16488BC8E8D8FBFFFF488D0DE534000048894630E8F8FDFFFF488B16488BC8E8BDFBFFFF488D0D0235000048894638E8DDFDFFFF488B16488BC8E8A2FBFFFF488D0DF734000048894640E8C2FDFFFF488B16488BC8E887FBFFFF488D0DFC34000048894648E8A7FDFFFF488B16488BC8E86CFBFFFF488D0D0935000048894650E88CFDFFFF488B16488BC8E851FBFFFF488D0D0E35000048894658E871FDFFFF488BC8488B16E836FBFFFF488D0D2B35000048894660E856FDFFFF488B16488BC8E81BFBFFFF488D0D5035000048894668E83BFDFFFF488B16488BC8E800FBFFFF488D0D5D35000048894670E820FDFFFF488B16488BC8E8E5FAFFFF488D0D7235000048894678E805FDFFFF488B16488BC8E8CAFAFFFF488D0D8735000048898680000000E8E7FCFFFF488B16488BC8E8ACFAFFFF488D0D8935000048898688000000E8C9FCFFFF488B16488BC8E88EFAFFFF488D0D8B350000488986A0000000E8ABFCFFFF488B16488BC8E870FAFFFF488D0D95350000488986A8000000E88DFCFFFF488B16488BC8E852FAFFFF488D0DA7350000488986B0000000E86FFCFFFF488B16488BC8E834FAFFFF488D0DA1350000488986B8000000E851FCFFFF488B16488BC8E816FAFFFF488D0DA3350000488986C0000000E833FCFFFF488B16488BC8E8F8F9FFFF488D0DA5350000488986C8000000E815FCFFFF488B16488BC8E8DAF9FFFF488986D000000033C0488B5C2460488B742468488B7C24704883C440415D415C5DC348895C24085556574154415541564157488DAC2410FEFFFF4881ECF00200004533FF488BD9498BF8488BF2488D8DE100000041B80301000033D24C897C24504C897C24604C897C24704C897C24684C89BD480200004488BDE0000000E8EFF7FFFF488D4DC0C745C01C010000FF9688000000837DC40675488B45C885C0752780BDDA00000001754D83C8FF488B9C24300300004881C4F0020000415F415E415D415C5F5E5DC383F801742A83F802740583F80375D380BDDA000000017517EBC8837DC40A75C244397DC875BC80BDDA0000000175B3488BD7488BCBFF56384C393F74A541BD300000004C897C243041BE000000084C8D8D380200004C8D442478488D4C2460418D55DEBB00020000448974242848C785380200004729000044896C24784C897D80895D904C897D884C897D984C897DA0C744242040000000FF96900000004C397C24607509418D45CEE937FFFFFF895D90BB040000004C897C24304C8D8D380200004C8D442478488D4C24708D530241BC1F4C1000448974242844896C24784C897D804C897D884C89A5380200004C897D984C897DA0895C2420FF9690000000488B0F4C8D7708498BD64C8975B0FF5678488B4C2460C74424484000000044897C2440C744243802000000488D44245048894424304C8D85480200004533C94883CAFF4C897C242848C744242000200000FF9698000000488B4C2470895C244844897C2440C744243802000000488D44245048894424304C8D4424684533C94883CAFF4C897C24284C897C24504C89642420 }
+ $b = { E800000000582D051040000500104000C3558BEC8B45082D001040005DC20400558BECFF7508E80A0A000033C05DC20400558BEC8B4D1085C9741F0FB6450C69C0010101018BD153578B7D08C1E902F3AB8BCA83E103F3AA5F5B8B45085DC3558BECE899FFFFFF8B4D0881E90010400003C15DC20400558BEC8B4D0833C066390174084066833C410075F85DC20400558BEC8B450866833800568BF0740983C60266833E0075F78B4D0C2BF10FB7116689140E83C1026685D275F15E5DC20800558BEC8B55088B450C2BD00FB70866890C0283C0026685C975F18B45085DC20800558BEC8B55088B450C2BD08A08880C024084C975F68B45085DC20800558BEC8B4508803800568BF0740646803E0075FA8B4D0C2BF18A1188140E4184D275F65E5DC20800558BEC5633F63975107E2D8B45088B4D0C0FB704700FB70C71663BC174148BD08BC18BCA2BC883F92074072BC283F8207506463B75107CD333C03B75105E0F95C05DC20C00558BEC8B450C8B550850894204E8FAFEFFFF03C066890283C002668942025DC20800558BEC51515733C0668945F88D7DFAAB33C966AB5F394D08741A394D0C7415FF75088D45F850E8B3FFFFFF8D45F850FF550C8BC88BC1C9C20800558BEC51518B45086AFF9968F0D8FFFF5250E8730A00008945F88D45F8506A006A008955FCFF550CC9C20800558BEC83EC248B4508568945F48D45F4508D45DC5033F668FFFF1F008D45FC508975FC8975F8C745DC180000008975E0C745E8400200008975E48975EC8975F0FF550C3975FC5E740E6A01FF75FCFF5510FF75FCFF5514C9C21000558BEC83EC0C538D45FC5033DB538D45F8506A05895DF8895DFCFF55108945F88B45FC3BC3750733C0E99E000000565303C05053FF55148BF08D45FC508B45FC03C050566A05897514FF55108945F83BC374095356FF551833C0EB6F8B45FC33D2B9F8000000F7F1578945FC8B7E3C3BFB742E0FB746383B450C7C252B450C992BC28BC8D1F978198B450C992BC2D1F850FF75088D044F50E83BFEFFFF85C0740A8B063BC3740903F0EBC18B7E44EB028BFB8B451C3BC374083BFB74048930EB0753FF7514FF55188BC75F5E5BC9C21800C21400558BEC837D100074178B4D088B450C2BC88A10FF4D1088140140837D100075F15DC20C00558BECE8B3FCFFFF8B4D0881E90010400003C15DC20400558BEC83EC2C538B5D088B433CB90B010000568B750CC745D44D6D4765C745D874537973C745DC74656D52C745E06F757469C745E46E654164C745E86472657366C745EC730066394C18180F858F0000008B44187803C38B501C8B482003D3578B78248B40188955F033D203CB03FB8955FC8945F485C07466EB038B5D088B149183650C0003D3803A0074238D5DD42BDA8BC2895DF8EB038B5DF88A1C0384DB740D38187509FF450C4080380075E98B450C803C10007507807C05D400740E8B55FC428955FC3B55F472B0EB128B45FC0FB704478B4DF08B048103450889065F8B0685C0750883C8FFE9230200005068D0414000E8F0FEFFFF50E831FDFFFFFF3689464868F0414000E8DBFEFFFF50E81CFDFFFFFF3689464C6818424000E8C6FEFFFF50E807FDFFFFFF368946046844424000E8B1FEFFFF50E8F2FCFFFFFF368946086878424000E89CFEFFFF50E8DDFCFFFFFF3689460C68A8424000E887FEFFFF50E8C8FCFFFFFF3689461068CC424000E872FEFFFF50E8B3FCFFFFFF368946146800434000E85DFEFFFF50E89EFCFFFFFF368946186834434000E848FEFFFF50E889FCFFFFFF3689461C686C434000E833FEFFFF50E874FCFFFFFF36894620687C434000E81EFEFFFF50E85FFCFFFFFF36894624689C434000E809FEFFFF50E84AFCFFFFFF3689462868C0434000E8F4FDFFFF50E835FCFFFFFF3689462C68DC434000E8DFFDFFFF50E820FCFFFFFF368946306810444000E8CAFDFFFF50E80BFCFFFFFF36894634684C444000E8B5FDFFFF50E8F6FBFFFFFF368946386874444000E8A0FDFFFF50E8E1FBFFFFFF3689463C68A0444000E88BFDFFFF50E8CCFBFFFFFF3689464068D0444000E876FDFFFF50E8B7FBFFFFFF3689464468EC444000E861FDFFFF50E8A2FBFFFFFF368946506808454000E84CFDFFFF50E88DFBFFFFFF368946546830454000E837FDFFFF50E878FBFFFFFF36894658685C454000E822FDFFFF50E863FBFFFFFF3689465C6870454000E80DFDFFFF50E84EFBFFFFFF368946606890454000E8F8FCFFFF50E839FBFFFFFF3689466468AC454000E8E3FCFFFF50E824FBFFFF89466833C05E5BC9C20800558BEC81EC5C020000535633DB5768030100008D85A5FDFFFF5350895DF8895DE8895DDC895DF4895DFC889DA4FDFFFFE889F9FFFF8B7D0C83C40C8D85A8FEFFFF50C785A8FEFFFF1C010000FF574483BDACFEFFFF05751283BDB0FEFFFF02743983BDB0FEFFFF01EB2E83BDACFEFFFF06750E399DB0FEFFFF7510807DC201751983C8FF5F5E5BC9C20C0083BDB0FEFFFF0175ED807DC20175E78B751056FF7508FF571C391E74D95368000000086A408D45EC508D45C4506A0E8D45E850C745EC47250000895DF0C745C418000000895DC8C745D000020000895DCC895DD4895DD8FF5748395DE875056AFE58EB955368000000086A048D45EC508D45C4506A068D45DCBE0B4C1000508975EC895DF0C745C418000000895DC8C745D000020000895DCC895DD4895DD8FF57488B45108D480451FF30894DE0FF573C6A40536A028D45F850536800200000538D45FC506AFFFF75E8FF574C6A04536A028D45F8505356538D45F4506AFFFF75DC895DF88975EC895DF0FF574C395DFC0F84330200008B75F43BF30F8428020000895E048B85B4FEFFFF8946108B85ACFEFFFF8946088B85B0FEFFFF89460C6A0C5889462C8946308B4510C7060C3C1000C7462830000000C746342C000000C7463818000000C7463CA80100008B401C894618895D0C6840464000E800F8FFFF8BC88B450C8A0C0180F10D888C05A4FDFFFF4089450C3D040100007CD98D8DA4FDFFFF8D46405150E855F8FFFF6844474000E8C9F7FFFF508D464050E85DF8FFFF8B45108B40283BC3742C8B4E1883F902750A8B40200504020000EB0D83F90375158B40200500010000508D860001000050E80BF8FFFFE825F7FFFFB9881C400081E90010400003C189450C33C9EB038B450C8A04088B55FC88040A4181F94825000072EB535353680C3C100056FF572C8BF03BF37460536A0156FF57386A1053536A015356FF57348B75108946203BC37447C680040200004E8B4620C68005020000538B4620C680060200002E8B4620C68007020000658B4620C68008020000788B4620C68009020000658B462088980A020000EB038B75108B46243BC30F8497000000895D083958040F868B000000895D0C8B46248B4D0C8B8401DC0000008D4D105150895D10FF5714395D107455FF7510FF57683B06754B536A3053FF57048945E43BC3743DE833F6FFFF53B91E13400081E90010400003C18B4DFC6A0183C12051535053FF7510FF75E4FF57245353FF75F4FF75E4FF5728FF770C6A01E8C1F7FFFFFF45088B46248B4D0883450C403B48040F8278FFFFFFFF75E0FF574033C0E9CFFCFFFFFF75E0FF57406AFDE92AFDFFFF558BEC81EC0C020000565733F66A688D8540FFFFFF565089B53CFFFFFFE8DAF5FFFF83C40C6A0A5933C06A0A8975A88D7DACF3AB5989B510FFFFFF8DBD14FFFFFFF3AB8D45A8898538FFFFFF8D853CFFFFFF50FF7508C745C401000000C7852CFFFFFF02000000E8BBF8FFFF85C00F8582010000538D85F4FDFFFF50C785F4FDFFFF1C010000FF5580BBEC45400083BDF8FDFFFF05750353EB0568D0454000E86CF8FFFF8D4DCC51FFB54CFFFFFFFFB540FFFFFFFFB544FFFFFF6A1850E856F7FFFFFFB548FFFFFF8BF83BFE750C68D0070000E8B9F6FFFFEBB46888130000E8ADF6FFFF8D45A8508D853CFFFFFF5057E849FBFFFF85C00F85F8000000EB10FFB548FFFFFF68D0070000E882F6FFFF8B45C883781C0175E783BDF8FDFFFF05750E6808464000E8E5F7FFFF6A16EB0C68D0454000E8D7F7FFFF6A18598D9534FFFFFF52FFB54CFFFFFFFFB540FFFFFFFFB544FFFFFF5150E8BCF6FFFF }
condition:
- 7 of them and filesize <294912
+ filesize <1KB and any of them
}
-rule MALPEDIA_Win_Amadey_Auto : FILE
+rule TRELLIX_ARC_Malw_Eicar : EICAR
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bcbf3802-d510-5a36-b69a-5e392988dabd"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.amadey_auto.yar#L1-L208"
- license_url = "N/A"
- logic_hash = "c915860f91ad45f2eb5b15d5deb4fc25f32146851585f24cbb18a6984390dbf0"
+ description = "Rule to detect the EICAR pattern"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "16307b03-7fab-5d68-ad3b-0efcea952fcf"
+ date = "2024-09-01"
+ modified = "2020-08-14"
+ reference = "https://www.eicar.org/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_Eicar.yar#L1-L22"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f"
+ logic_hash = "564b0592f40582fe71e2dab0c0f25c168462f9297c13e7c9f06ac51b492e4533"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "EICAR"
+ malware_type = "eicar"
+ malware_family = "W32/Eicar"
+ actor_type = "Unknown"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { ebb0 b8???????? 83c410 5b }
- $sequence_1 = { e8???????? 89c2 8b45f4 89d1 ba00000000 f7f1 }
- $sequence_2 = { c744240805000000 c744240402000000 890424 e8???????? }
- $sequence_3 = { c9 c3 55 89e5 81ecc8010000 }
- $sequence_4 = { c70424???????? e8???????? 8b45fc 89442408 c7442404???????? 8b4508 890424 }
- $sequence_5 = { c744240800020000 8d85f8fdffff 89442404 891424 e8???????? 83ec20 }
- $sequence_6 = { c70424???????? e8???????? 890424 e8???????? 84c0 7407 c745fc05000000 }
- $sequence_7 = { 83ec04 8945f4 837df400 7454 8b4508 890424 }
- $sequence_8 = { 83fa10 722f 8b8d78feffff 42 }
- $sequence_9 = { 8b8d78feffff 42 8bc1 81fa00100000 7214 8b49fc }
- $sequence_10 = { 68???????? e8???????? 8d4dcc e8???????? 83c418 }
- $sequence_11 = { 68???????? e8???????? 8d4db4 e8???????? 83c418 }
- $sequence_12 = { 52 6a02 6a00 51 ff75f8 ff15???????? ff75f8 }
- $sequence_13 = { 8bce e8???????? e8???????? 83c418 e8???????? e9???????? 52 }
- $sequence_14 = { c705????????0c000000 eb31 c705????????0d000000 eb25 83f901 750c }
- $sequence_15 = { 50 68???????? 83ec18 8bcc 68???????? e8???????? }
- $sequence_16 = { 8bcc 68???????? e8???????? 8d8d78feffff e8???????? 83c418 }
- $sequence_17 = { c78584fdffff0f000000 c68570fdffff00 83fa10 722f 8b8d58fdffff 42 }
- $sequence_18 = { c78520fdffff00000000 c78524fdffff0f000000 c68510fdffff00 83fa10 722f }
- $sequence_19 = { 51 e8???????? 83c408 8b950cfdffff c78520fdffff00000000 c78524fdffff0f000000 }
+ $s1 = "X5O!P%@AP[4\\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*" fullword ascii
condition:
- 7 of them and filesize <529408
+ any of them
}
-rule MALPEDIA_Win_Redyms_Auto : FILE
+rule TRELLIX_ARC_MALW_Liquorbot : MALWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "da0046e8-7d1d-55ff-bc47-8c4a49be473c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.redyms"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.redyms_auto.yar#L1-L127"
- license_url = "N/A"
- logic_hash = "5d36da1238e7bd61b571d2194e775b3f30f76bd59bc3908f725087cbecb38f2e"
+ description = "Rule to detect LiquorBot malware"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "73898df8-b5eb-50ac-a2fe-ef9233c251c5"
+ date = "2020-08-19"
+ modified = "2020-08-19"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_liquorbot.yar#L1-L23"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "2448e3ede809331b2370fe9d42d603ad6508be6531a1a8764e0e0621867b6e89"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "MALWARE, FILE"
+ rule_version = "v1"
+ malware_type = "malware"
+ malware_family = "Botnet:W32/LiquorBot"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
+ hash1 = "5b2a9cbda99ed903f75c3b37f0a6b1b9f6c39671a76ed652f3ddba117fd43bc9"
strings:
- $sequence_0 = { 32d8 80f3fb 8819 40 41 6683f805 72ee }
- $sequence_1 = { 8b4604 50 6a00 ffd3 50 ffd7 56 }
- $sequence_2 = { 33c5 8945fc 56 8b35???????? 8d4ddc 8bd1 }
- $sequence_3 = { 85f6 0f84e4000000 8b3d???????? 8d4de8 8bd1 33c0 }
- $sequence_4 = { a1???????? 33c5 8945fc 56 c785ccfeffff04010000 7203 }
- $sequence_5 = { c745d000000000 ff15???????? 5f 85c0 }
- $sequence_6 = { 7417 8b45f4 8b4df8 50 51 56 ff15???????? }
- $sequence_7 = { 8b4608 8b4e04 50 6a00 e8???????? 83c408 }
- $sequence_8 = { 83c8ff 5b 8be5 5d c3 8bc6 5f }
- $sequence_9 = { 8d5828 53 8945fc ffd7 83caff 8bc6 f00fc110 }
+ $pattern = { 7F454C4602010100000000000000000002003E0001000000605A4600000000004000000000000000700200000000000000000000400038000A0040001B00090006000000040000004000000000000000400040000000000040004000000000003002000000000000300200000000000000100000000000000300000004000000E00F000000000000E00F400000000000E00F40000000000020000000000000002000000000000000010000000000000004000000040000007C0F0000000000007C0F4000000000007C0F400000000000640000000000000064000000000000000400000000000000010000000500000000000000000000000000400000000000000040000000000040FB29000000000040FB2900000000000010000000000000010000000400000000002A000000000000006A000000000000006A0000000000E4492C0000000000E4492C000000000000100000000000000100000006000000005056000000000000509600000000000050960000000000E014040000000000681307000000000000100000000000000200000006000000405156000000000040519600000000004051960000000000300100000000000030010000000000000800000000000000070000000400000000000000000000000000000000000000000000000000000000000000000000000800000000000000080000000000000051E574640600000000000000000000000000000000000000000000000000000000000000000000000000000000000000080000000000000080150465002A00000000000000000000000000000000000000000000000000000000000000000000000000000000000008000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000010000000600000000000000001040000000000000100000000000001FE9290000000000000000000000000010000000000000000000000000000000F000000001000000060000000000000020F969000000000020F929000000000020020000000000000000000000000000100000000000000010000000000000007000000001000000020000000000000000006A000000000000002A0000000000A678110000000000000000000000000020000000000000000000000000000000E0000000040000000200000000000000A8787B0000000000A8783B000000000018000000000000000B0000000000000008000000000000001800000000000000E6000000040000000200000000000000C0787B0000000000C0783B000000000018030000000000000B0000000200000008000000000000001800000000000000F5000000FF }
condition:
- 7 of them and filesize <98304
+ uint16(0)==0x457f and all of them
}
-rule MALPEDIA_Win_Revenant_Auto : FILE
+rule TRELLIX_ARC_Chikdos_Malware_Pdb : DOS FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a1374c5f-49ed-5419-afea-48c7289282d4"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.revenant"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.revenant_auto.yar#L1-L117"
- license_url = "N/A"
- logic_hash = "c5089ea5b4a1f250ceb154edb995f0fd96a084eb423c884f131dc135f20dbca0"
+ description = "Chikdos PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "0174ff2b-57fc-5578-b45e-c08bf8528ee8"
+ date = "2013-12-02"
+ modified = "2020-08-14"
+ reference = "http://hackermedicine.com/tag/trojan-chickdos/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_chickdos_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "c2a0e9f8e880ac22098d550a74940b1d81bc9fda06cebcf67f74782e55e9d9cc"
+ logic_hash = "150bf809a61aad00df0c49fb6a609b909c84ffb9ca442e143a6c5bf3dfc39314"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "DOS, FILE"
+ rule_version = "v1"
+ malware_type = "dos"
+ malware_family = "Dos:W32/ChickDos"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 4c8d4c2458 4889f1 4889c3 31c0 4889442420 4889da ff15???????? }
- $sequence_1 = { 4c89e1 e8???????? 488906 31c0 48894608 }
- $sequence_2 = { ba28000000 b940000000 ffd6 31d2 }
- $sequence_3 = { eb3a 4c89e1 e8???????? 488906 31c0 }
- $sequence_4 = { 4889442450 e8???????? 85c0 4189c7 }
- $sequence_5 = { 4c01c2 31c9 49f7d0 48ffc9 4939c8 740a 448a140a }
- $sequence_6 = { 41b842000000 4c89e1 ff15???????? 8b4c246c 4989c4 }
- $sequence_7 = { 8b00 41390424 7592 41c744240801000000 }
- $sequence_8 = { 4883c328 4839fb 7427 41b808000000 4889f2 4889d9 }
- $sequence_9 = { e8???????? ba04010000 b940000000 48c744242804010000 41ffd6 4885c0 }
+ $pdb = "\\IntergrateCHK\\Release\\IntergrateCHK.pdb"
condition:
- 7 of them and filesize <99328
+ uint16(0)==0x5a4d and filesize <600KB and any of them
}
-rule MALPEDIA_Win_Taurus_Stealer_Auto : FILE
+rule TRELLIX_ARC_Malw_Mangzamel_Trojan : TROJAN FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1d04f49a-1251-5bc9-a2e1-54ed739ba752"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.taurus_stealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.taurus_stealer_auto.yar#L1-L133"
- license_url = "N/A"
- logic_hash = "5a56120ca5bf111c092d7e02323e7c3983f49990178f81f0fd9b64062b85cfef"
+ description = "Rule to detect Mangzamel trojan based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "ca77180f-6133-5edb-a36b-78bc6f18d80c"
+ date = "2014-06-25"
+ modified = "2020-08-14"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mangzamel"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_mangzamel_trojan_pdb.yar#L1-L26"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "4324580ea162a636b7db1efb3a3ba38ce772b7168b4eb3a149df880a47bd72b7"
+ logic_hash = "bab103c671445e0ea916fae290689d30d45021bdca58a495ebd3d6ca9ca55051"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/Mangzamel"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 56 8b7508 eb12 8d4e1c e8???????? 8bce e8???????? }
- $sequence_1 = { 8d4de8 e8???????? 85f6 7408 8d4dd0 e8???????? 8b4508 }
- $sequence_2 = { 88550f 88450e 8d450e 51 50 8d4d8c e8???????? }
- $sequence_3 = { 51 50 8bce e8???????? 8d4dcc e8???????? 8d4db4 }
- $sequence_4 = { 7305 8a5df3 ebf1 8d45f4 c645ff00 50 8bd6 }
- $sequence_5 = { 8bc2 c1e802 c1e103 8b0483 d3e8 880432 42 }
- $sequence_6 = { 8d4ddc e8???????? 8d4d90 e8???????? 8d4d84 e8???????? }
- $sequence_7 = { c74610fe33b90f c7461465dc040b c74618e3804800 c7461cb5492c0d c7462045909c0f c74624dd90c504 c7462870e8f00e }
- $sequence_8 = { 0f1145c1 885ddf 0fbe4581 250f000080 7905 48 83c8f0 }
- $sequence_9 = { 40 83f806 7305 8a5df2 ebf1 8d45f3 c645f900 }
+ $pdb = "\\svn\\sys\\binary\\i386\\agony.pdb"
+ $pdb1 = "\\Windows\\i386\\ndisdrv.pdb"
condition:
- 7 of them and filesize <524288
+ uint16(0)==0x5a4d and filesize <360KB and any of them
}
-rule MALPEDIA_Win_Bernhardpos_Auto : FILE
+rule TRELLIX_ARC_Rtf_Bluetea_Builder : MALDOC FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7b2918eb-6e4b-588b-9817-19ede384242f"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bernhardpos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bernhardpos_auto.yar#L1-L122"
- license_url = "N/A"
- logic_hash = "b0e71b787dda9e2d7e79e7ddddae77406aa6aa8d138e23e43da621be02324cd1"
+ description = "Rule to detect the RTF files created to distribute BlueTea trojan"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "20e4f7b2-b36c-5724-a3aa-4216ed6265ab"
+ date = "2020-04-21"
+ modified = "2020-08-14"
+ reference = "https://blog.360totalsecurity.com/en/bluetea-action-drive-the-life-trojan-update-email-worm-module-and-spread-through-covid-19-outbreak/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALDOC_rtf_bluetea_builder.yar#L1-L30"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "4a3eeaed22342967a95302a4f087b25f50d61314facc6791f756dcd113d4f277"
+ logic_hash = "6c4007fb7ef4819141db63050215dcbb3d2c17e7cdcdbb6cfb4f4b045bb5736b"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "MALDOC, FILE"
+ rule_version = "v1"
+ malware_type = "maldoc"
+ malware_family = "Maldoc:W32/BlueTea"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 0f840a010000 8d85ecfbffff 50 682a020000 68???????? 8b8df0fbffff }
- $sequence_1 = { ff15???????? 8b8d54feffff 668901 6a10 8d855cfeffff 50 }
- $sequence_2 = { 0fbe5415f8 33ca 8b4508 0345f4 8808 ebc7 5f }
- $sequence_3 = { 8945fc 8b45fc 8b4d08 03483c 894df4 }
- $sequence_4 = { 8808 ebc7 5f 5e 5b }
- $sequence_5 = { 668b0d???????? 66894dfc 8a15???????? 8855fe 8d45f8 50 ff15???????? }
- $sequence_6 = { 83e863 5f 5e 5b }
- $sequence_7 = { 51 ff15???????? 8d85ecfeffff 50 e8???????? 83c404 85c0 }
- $sequence_8 = { eb2c 33c0 eb2d 33c0 eb29 }
- $sequence_9 = { e8???????? 83c404 6a01 8d85d0feffff 50 ff15???????? }
+ $sequence = { 7B??72??6631??????65666C616E6731??32??????????69??????????????67????36??75??32??????656666????35????????656666????????73??666462????33??35????????74??68????????68????????36??73??73??66??????68????????36??73??73??6662????5C646566??616E6731??33??5C646566??616E67666532??35????????656D656C616E6731??33??5C74??656D656C616E67666532??35????????656D656C616E6763????7B??666F6E74??62??????6630??????69??????????????6D616E5C6663????72??6574??5C6670??71??7B??2A??????6E6F73??20??32??32??3630??30??????????30??30??30????????????73??4E6577??526F6D616E3B????0A????6631??5C6662????69??????????6C5C6663????72??6574??33????6670??71??7B??2A??????6E6F73??20??32??31??3630??30??30??30??30??30??30??7D??2763????2763????2763????276535????????66616C74??5369????????????7D??5C6633????6662????69??????????6D616E5C6663????72??6574??5C6670??71??7B??2A??????6E6F73??20??32??34??35????????30????3630??30??30????????????72??6120????74??3B????0A????6633??5C6662????69??????????69????????????6172??6574??5C6670??71??7B??2A??????6E6F73??20??32??6630??????????30??30????33??32??34??43616C69????????????5C6633??5C6662????69??????????6C5C6663????72??6574??33????6670??71??7B??2A??????6E6F73??20??32??31??3630??30??30??30??30??30??30??7D??5C2763????2763????2763????276535????????7B??666C6F6D616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??5C6670??71??7B??2A??????6E6F73??20??32??32??3630??30??????????30??30??30????????????73??4E6577??526F6D616E3B????5C666462????6A??72??6633??35????????62????69??????????6C5C6663????72??6574??33????6670??71??7B??2A??????6E6F73??20??32??31??3630??30??30??30??30??30??30??7D??2763????2763????2763????276535????????66616C74??5369????????????7D??0A????66??????616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??5C6670??71??7B??2A??????6E6F73??20??32??34??35????????30????3630??30??30????????????72??613B????5C6662????616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??5C6670??71??7B??2A??????6E6F73??20??32??32??3630??30??????????30??30??30????????????73??4E6577??526F6D616E3B????0A????666C6F6D69????????????31??????????62????69??????????6D616E5C6663????72??6574??5C6670??71??7B??2A??????6E6F73??20??32??32??3630??30??????????30??30??30????????????73??4E6577??526F6D616E3B????5C666462????6E6F72??6633??35????????62????69??????????6C5C6663????72??6574??33????6670??71??7B??2A??????6E6F73??20??32??31??3630??30??30??30??30??30??30??7D??2763????2763????2763????276535????????66616C74??5369????????????7D??0A????66??????69????????????31??????????62????69??????????69????????????6172??6574??5C6670??71??7B??2A??????6E6F73??20??32??6630??????????30??30????33??32??34??43616C69????????????5C6662????69????????????31??????????62????69??????????6D616E5C6663????72??6574??5C6670??71??7B??2A??????6E6F73??20??32??32??3630??30??????????30??30??30????????????73??4E6577??526F6D616E3B????5C6634??5C6662????69??????????6D616E5C6663????72??6574??33??5C6670??71??20??????6573??4E6577??526F6D616E20????3B????0A????6634??5C6662????69??????????6D616E5C6663????72??6574??30????6670??71??20??????6573??4E6577??526F6D616E20????72??7D??5C6634??5C6662????69??????????6D616E5C6663????72??6574??3631??????72??32??5469????????????77??526F6D616E20????6565??????7B??6634??5C6662????69??????????6D616E5C6663????72??6574??3632??????72??32??5469????????????77??526F6D616E20??????3B????5C6634??5C6662????69??????????6D616E5C6663????72??6574??37375C6670??71??20??????6573??4E6577??526F6D616E20??486562????77??3B????0A????6634??5C6662????69??????????6D616E5C6663????72??6574??3738??????72??32??5469????????????77??526F6D616E20??4172??62????29??7D??5C6634??5C6662????69??????????6D616E5C6663????72??6574??38??5C6670??71??20??????6573??4E6577??526F6D616E20????6C74??63??7D??5C6634??5C6662????69??????????6D616E5C6663????72??6574??3633??????72??32??5469????????????77??526F6D616E20??5669????????????73??29??7D??0A????6631??32??????69??????????????6C5C6663????72??6574??5C6670??71??20????6D5375??20????73??6572??7B??2A??????6C74??5369????????????7D??5C6633??30??????69??????????????6D616E5C6663????72??6574??33??5C6670??71??20????6D62????6120????74??20????3B????5C6633??31??????69??????????????6D616E5C6663????72??6574??30????6670??71??20????6D62????6120????74??20????72??7D??5C6633??33??????69??????????????6D616E5C6663????72??6574??3631??????72??32??43616D62????6120????74??20????6565??????0D????????33??34??6662????69??????????6D616E5C6663????72??6574??3632??????72??32??43616D62????6120????74??20??????3B????5C6633??375C6662????69??????????6D616E5C6663????72??6574??38??5C6670??71??20????6D62????6120????74??20????6C74??63??7D??5C6633??38??????69??????????????6D616E5C6663????72??6574??3633??????72??32??43616D62????6120????74??20??5669????????????73??29??7D??5C6634??30??????69??????????????69????????????6172??6574??33??5C6670??71??20????6C69????????????3B????0A????6634??31??????69??????????????69????????????6172??6574??30????6670??71??20????6C69????????????72??7D??5C6634??33??????69??????????????69????????????6172??6574??3631??????72??32??43616C69????????????6565??????7B??6634??34??6662????69??????????69????????????6172??6574??3632??????72??32??43616C69????????????72??7D??5C6634??375C6662????69??????????69????????????6172??6574??38??5C6670??71??20????6C69????????????6C74??63??7D??0A????6634??38??????69??????????????69????????????6172??6574??3633??????72??32??43616C69????????????69????????????73??29??7D??5C6634??32??????69??????????????6C5C6663????72??6574??5C6670??71??20????2763????2763????2763????276535????????74??72??3B????5C666C6F6D616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??33??5C6670??71??20??????6573??4E6577??526F6D616E20????3B????0A????666C6F6D616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??30????6670??71??20??????6573??4E6577??526F6D616E20????72??7D??5C666C6F6D616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??3631??????72??32??5469????????????77??526F6D616E20????6565??????7B??666C6F6D616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??3632??????72??32??5469????????????77??526F6D616E20??????3B????0A????666C6F6D616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??37375C6670??71??20??????6573??4E6577??526F6D616E20??486562????77??3B????5C666C6F6D616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??3738??????72??32??5469????????????77??526F6D616E20??4172??62????29??7D??5C666C6F6D616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??38??5C6670??71??20??????6573??4E6577??526F6D616E20????6C74??63??7D??0A????666C6F6D616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??3633??????72??32??5469????????????77??526F6D616E20??5669????????????73??29??7D??5C666462????6A??72??6633??35????????62????69??????????6C5C6663????72??6574??5C6670??71??20????6D5375??20????73??6572??7B??2A??????6C74??5369????????????7D??5C66??????616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??33??5C6670??71??20????6D62????6120????3B????0A????66??????616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??30????6670??71??20????6D62????6120????72??7D??5C66??????616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??3631??????72??32??43616D62????6120????6565??????7B??66??????616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??3632??????72??32??43616D62????6120??????3B????0A????66??????616A??72??6633??35????????62????69??????????6D616E5C6663????72??6574??38??5C6670??71??20????6D62????6120????6C74??63??7D??5C66??????616A?? }
condition:
- 7 of them and filesize <368640
+ uint16(0)==0x5c7b and filesize <100KB and all of them
}
-rule MALPEDIA_Win_Fancyfilter_Auto : FILE
+rule TRELLIX_ARC_MALW_Fritzfrog : BOTNET FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "80aed11c-235c-5a1c-926a-79da2aeef3b0"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fancyfilter"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.fancyfilter_auto.yar#L1-L112"
- license_url = "N/A"
- logic_hash = "3c31ea55e7982b34390b9c81f5913450958243c449d75663ce6d5f15ca3bbd38"
+ description = "Rule to detect Fritzfrog"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "4c553279-7e0c-5602-944d-ad8a47edf4ea"
+ date = "2020-08-20"
+ modified = "2020-08-20"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_fritzfrog.yar#L1-L26"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "488c807ecf0a9e981b2c1f2f5bb2e3072952d11f7cbf3a354bc85dc8e88b8b09"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BOTNET, FILE"
+ rule_version = "v1"
+ malware_type = "botnet"
+ malware_family = "Botnet:W32/Fritzfrog"
+ actor_type = "Cybercrime"
+ hash1 = "103b8404dc64c9a44511675981a09fd01395ee837452d114f1350c295357c046"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 740a 66833800 7404 b001 eb02 }
- $sequence_1 = { a1???????? 83c012 50 ff15???????? }
- $sequence_2 = { 8b07 83e810 50 83c610 56 }
- $sequence_3 = { ff15???????? 83c420 83f803 7409 83f806 }
- $sequence_4 = { 83c012 50 ffd6 a1???????? }
- $sequence_5 = { 85c0 750d 8b472c a801 7406 83c804 }
- $sequence_6 = { 85c0 740a 66833800 7404 b001 eb02 }
- $sequence_7 = { 81e3ffffff00 ff15???????? 50 ff15???????? }
- $sequence_8 = { 85c0 740a 66833800 7404 b001 }
- $sequence_9 = { b805400080 c20400 56 8b742408 }
+ $pattern = { 7F454C4602010100000000000000000002003E000100000090D34500000000004000000000000000C8010000000000000000000040003800070040000D000300060000000400000040000000000000004000400000000000400040000000000088010000000000008801000000000000001000000000000004000000040000009C0F0000000000009C0F4000000000009C0F400000000000640000000000000064000000000000000400000000000000010000000500000000000000000000000000400000000000000040000000000083F23E000000000083F23E00000000000010000000000000010000000400000000003F000000000000007F000000000000007F00000000006C834500000000006C834500000000000010000000000000010000000600000000908400000000000090C400000000000090C4000000000060EC0400000000005809070000000000001000000000000051E574640600000000000000000000000000000000000000000000000000000000000000000000000000000000000000080000000000000080150465002A000000000000000000000000000000000000000000000000000000000000000000000000000000000000080000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000100000006000000000000000010400000000000001000000000000083E23E00000000000000000000000000100000000000000000000000000000004100000001000000020000000000000000007F000000000000003F0000000000C0271B0000000000000000000000000020000000000000000000000000000000720000000300000000000000000000000000000000000000C0275A00000000007C000000000000000000000000000000010000000000000000000000000000004900000001000000020000000000000040289A000000000040285A0000000000D83600000000000000000000000000002000000000000000000000000000000053000000010000000200000000000000185F9A0000000000185F5A0000000000380D0000000000000000000000000000080000000000000000000000000000005D000000010000000200000000000000506C9A0000000000506C5A0000000000000000000000000000000000000000000100000000000000000000000000000067000000010000000200000000000000606C9A0000000000606C5A00000000000C172A0000000000000000000000000020000000000000000000000000000000070000000100000003000000000000000090C400000000000090840000000000004B0300000000000000000000000000200000000000000000000000000000001200000001000000030000000000000000DBC7000000000000DB87000000000050A101000000000000000000000000002000000000000000000000000000000018000000080000000300000000000000607CC90000000000607C890000000000D0E80100000000000000000000000000200000000000000000000000000000001D0000000800000003000000000000004065CB000000000040658B00000000001834000000000000000000000000000020000000000000000000000000000000270000000700000002000000000000009C0F4000000000009C0F00000000000064000000000000000000000000000000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 }
condition:
- 7 of them and filesize <169984
+ uint16(0)==0x457f and filesize <26000KB and all of them
}
-rule MALPEDIA_Win_Rtm_Locker_Auto : FILE
+rule TRELLIX_ARC_Malw_Medfos : TROJAN FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a8f49436-bcde-542d-92ad-a9016371f8b8"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rtm_locker"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.rtm_locker_auto.yar#L1-L127"
- license_url = "N/A"
- logic_hash = "61d8b5fbf492d5b9d06c2052f9a6a3111c4e3f003fd0450ca27ee699de4151fc"
+ description = "Rule to detect Medfos trojan based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "07ad0227-ca8f-5071-8ef7-8c3e087fcc35"
+ date = "2013-04-19"
+ modified = "2020-08-14"
+ reference = "https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=win32%2Fmedfos"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_medfos_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "3582e242f62598445ca297c389cae532613afccf48b16e9c1dcf1bfedaa6e14f"
+ logic_hash = "1726462a806f5cb3f0b80596623cebc51a7a9f866ded0cb59ea1c43034ce2819"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "TROJAN, FILE"
+ rule_version = "v1"
+ malware_type = "trojan"
+ malware_family = "Trojan:W32/Medfos"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8d8d2cfeffff e8???????? 0f108d64fcffff 33c9 0f109574fcffff 0f109d84fcffff 0f10a594fcffff }
- $sequence_1 = { 0f104630 660fefd0 0f1006 660fefc8 0f110f 0f116710 0f115f20 }
- $sequence_2 = { 0f29442470 0f28842470010000 0f29842420010000 0f28842480010000 89442458 83c004 894c245c }
- $sequence_3 = { e8???????? 8d8d68ffffff e8???????? 0f108568ffffff be18000000 0f1185c8feffff }
- $sequence_4 = { 0fbe8098074200 40 8945cc 2b45dc 8945d4 3bc2 0f8f10020000 }
- $sequence_5 = { 50 6af5 eb03 50 6af6 ff15???????? 8b04bd500f4200 }
- $sequence_6 = { c1f910 884e02 8b4de0 0ac1 884603 8bc1 c1f808 }
- $sequence_7 = { 897dfc 897db8 894508 85c0 0f8f3ffeffff }
- $sequence_8 = { 8d442430 50 ff15???????? 8bf0 83feff 7431 }
- $sequence_9 = { 8b0c85500f4200 8b45f8 807c012800 7d46 }
+ $pdb = "\\som\\bytguqne\\jzexsaf\\gyin.pdb"
condition:
- 7 of them and filesize <598016
+ uint16(0)==0x5a4d and filesize <150KB and any of them
}
-rule MALPEDIA_Win_Wscspl_Auto : FILE
+rule TRELLIX_ARC_Malw_Cutwail_Pdb : BOTNET FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f31d95be-4f0b-51e3-8f5f-15d1afc6eb9e"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.wscspl"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.wscspl_auto.yar#L1-L117"
- license_url = "N/A"
- logic_hash = "4a0c5de1937bca874bba721d790f101d8b394ac870591bd7e9ae3e7dc3c9255d"
+ description = "Rule to detect cutwail based on the PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "62058ff9-acb5-5f71-b6bb-4c64e51442ba"
+ date = "2008-04-16"
+ modified = "2020-08-14"
+ reference = "https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/CUTWAIL"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_cutwail.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "d702f823eefb50d9ea5b336c638f65a40c2342f8eb88278da60aa8a498c75010"
+ logic_hash = "f53626e6085509ddf9268b69e54a138e64cd5d3fbad119e6e9473179decd7927"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BOTNET, FILE"
+ rule_version = "v1"
+ malware_type = "botnet"
+ malware_family = "Botnet:W32/Cutwail"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 740b b855000000 66a3???????? 8b4c2404 51 }
- $sequence_1 = { 8bcd 8d742414 8d442418 e8???????? 0fbf442414 50 8d4c241c }
- $sequence_2 = { 8d442430 50 68???????? 6a00 6a00 c744244000000000 }
- $sequence_3 = { 8b74240c 3bf7 7435 8b3d???????? 8d4900 8b4618 8b4004 }
- $sequence_4 = { 8d642400 8b0c18 8d1418 bf05000000 }
- $sequence_5 = { 3bc1 763a 03c9 3bc1 }
- $sequence_6 = { 663bf8 752f e8???????? 8b0d???????? }
- $sequence_7 = { 51 ff15???????? ff15???????? 6888130000 }
- $sequence_8 = { 8b1d???????? 55 33c0 56 83c1fb }
- $sequence_9 = { 687c230000 8d44240c 6a01 50 ff15???????? 687c230000 68c10b0000 }
+ $pdb = "\\0bulknet\\FLASH\\Release\\flashldr.pdb"
condition:
- 7 of them and filesize <901120
+ uint16(0)==0x5a4d and filesize <440KB and any of them
}
-rule MALPEDIA_Win_Sasfis_Auto : FILE
+rule TRELLIX_ARC_Screenlocker_5H311_1Nj3C706 : SCREENLOCKER FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5e363129-1d9b-5d5a-8006-da18dff7062a"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sasfis"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.sasfis_auto.yar#L1-L115"
- license_url = "N/A"
- logic_hash = "7eee2ccd93eb9390961368e951e0384a076b29fc7a953a6afc5b8df0aa798b71"
+ description = "Rule to detect the screenlocker 5h311_1nj3c706"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "50bbe8e1-4721-5277-b786-d2a2d9acf917"
+ date = "2018-08-07"
+ modified = "2020-08-14"
+ reference = "https://twitter.com/demonslay335/status/1038060120461266944"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_screenlocker_5h311_1nj3c706.yar#L1-L33"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "016ee638bd4fccd5ca438c2e0abddc4b070f59269c08f11c5313ba9c37190718"
+ logic_hash = "61b4495841c77053ba2631f087197719f3ee45cd93add022f23b87ece8563619"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "SCREENLOCKER, FILE"
+ rule_version = "v1"
+ malware_type = "screenlocker"
+ malware_family = "ScreenLocker:W32/5h311_1nj3c706"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8433 a6 0d60ca8b0c 646b1a5c }
- $sequence_1 = { d7 4b 7ca9 bc74460651 130d???????? 37 d502 }
- $sequence_2 = { 157e2808b7 0016 2038 2410 }
- $sequence_3 = { 60 0c1c 0430 00242c 1838 3c00 3808 }
- $sequence_4 = { 84df 66ffc5 8b742448 66f7df }
- $sequence_5 = { f9 f6c77d 660fbae10b 83c504 }
- $sequence_6 = { 657326 6e 346f 6f 68432b3501 }
- $sequence_7 = { 6681cf5b01 81ec9c000000 57 60 5f }
- $sequence_8 = { 2909 26df6883 95 7800 e8???????? 15afb28a60 38342c }
- $sequence_9 = { 260c16 005220 0410 1400 }
+ $s1 = "C:\\Users\\Hoang Nam\\source\\repos\\WindowsApp22\\WindowsApp22\\obj\\Debug\\WindowsApp22.pdb" fullword ascii
+ $s2 = "cmd.exe /cREG add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\ActiveDesktop /v NoChangingWallPaper /t REG_DWOR" wide
+ $s3 = "C:\\Users\\file1.txt" fullword wide
+ $s4 = "C:\\Users\\file2.txt" fullword wide
+ $s5 = "C:\\Users\\file.txt" fullword wide
+ $s6 = " /v Wallpaper /t REG_SZ /d %temp%\\IMG.jpg /f" fullword wide
+ $s7 = " /v DisableAntiSpyware /t REG_DWORD /d 1 /f" fullword wide
+ $s8 = "All your file has been locked. You must pay money to have a key." fullword wide
+ $s9 = "After we receive Bitcoin from you. We will send key to your email." fullword wide
condition:
- 7 of them and filesize <8060928
+ uint16(0)==0x5a4d and filesize <200KB and all of them
}
-rule MALPEDIA_Win_Anchor_Auto : FILE
+rule TRELLIX_ARC_Masslogger_Stealer : STEALER FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "1c11ed2a-15a5-596e-9198-01902495df6c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.anchor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.anchor_auto.yar#L1-L193"
- license_url = "N/A"
- logic_hash = "886cb58595403596c3f5d2209b3ab4ffe1064302e9312c9e2ca7e76025f4d7c9"
+ description = "Rule to detect unpacked MassLogger stealer"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "c3a40108-3f0c-5949-9201-95c3c38b352a"
+ date = "2020-07-02"
+ modified = "2020-08-14"
+ reference = "https://urlhaus.abuse.ch/browse/signature/MassLogger/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_masslogger_stealer.yar#L1-L63"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "343873155b6950386f7d9bcd8d2b2e81088521aedf8ff1333d20229426d8145c"
+ logic_hash = "476b3f3a54a4616058a2aef01adbe429a38eacc8ee58881d31bd28e795a27575"
score = 75
- quality = 73
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 66
+ tags = "STEALER, FILE"
+ rule_version = "v1"
+ malware_type = "stealer"
+ malware_family = "Stealer:W32/MassLogger"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 740c 66c740016578 c6400365 eb0a }
- $sequence_1 = { c6400365 eb0a 66c74001646c c640036c }
- $sequence_2 = { 56 8d8dbcfeffff e8???????? 68???????? 8d8dbcfeffff }
- $sequence_3 = { b101 e8???????? e8???????? 84c0 }
- $sequence_4 = { 56 e8???????? 8b30 837e0c00 }
- $sequence_5 = { 8b4638 5f 66894812 33c9 8b4638 }
- $sequence_6 = { f2e965020000 e9???????? 53 56 57 }
- $sequence_7 = { 0f90c1 f7d9 0bc8 51 e8???????? 8b0d???????? c1e102 }
- $sequence_8 = { 0fb7c1 6641 66890d???????? 50 }
- $sequence_9 = { 7509 33d2 33c9 e8???????? }
- $sequence_10 = { 488d0d520b0400 e8???????? 488b8500010000 488b8d08010000 }
- $sequence_11 = { 488d0d516d0200 e8???????? 488d8d680e0000 e8???????? }
- $sequence_12 = { 488d0d50840200 e8???????? 488d0d48840200 e8???????? }
- $sequence_13 = { 4903c7 c64405b079 4903c7 c64405b073 4903c7 c64405b074 4903c7 }
- $sequence_14 = { 488d0d528a0300 e8???????? 488b8de0000000 e8???????? }
- $sequence_15 = { 488b4318 66894802 8d4f6e 488b4318 66894804 }
- $sequence_16 = { 488d0d52b90200 e8???????? e8???????? 48894508 }
- $sequence_17 = { e8???????? 4c8d442468 48837d8010 4c0f43442468 }
- $sequence_18 = { 488d0d50480300 e8???????? 90 488b8500010000 488da5e8000000 5f }
- $sequence_19 = { 4889442428 488d85d0030000 4889442420 4c8d4c2448 }
- $sequence_20 = { 488d0d52cd0300 e8???????? 90 488b8d00010000 }
+ $pattern_0 = { 6437 3e2585829c88 ec ec 1bc8 }
+ $pattern_1 = { d7 b9513e1ba7 195ab6 e6df 7e2a 5a b6cc }
+ $pattern_2 = { 80aee281aae280 8ee2 808ce2808ee2808e e280 ae 00436f 6e }
+ $pattern_3 = { 6d e586 4c 40 }
+ $pattern_4 = { e281 ab e280 8ee2 80aee281aae280 8ee2 }
+ $pattern_5 = { 6c 69636b65644576 656e 7441 7267 7300 }
+ $pattern_6 = { 6e 7e81 d86aaf 61 93 7c2b 832b62 }
+ $pattern_7 = { 8b1c87 e7ed 24a2 3218 73df 53 }
+ $pattern_8 = { ee 9a357f9a475399 3188eef97d50 3f ef c9 }
+ $pattern_9 = { 44 a2???????? 92 7526 42 208fb5ca7050 }
+ $pattern_10 = { f2bbafb0d5f8 d524 0d48c906ba 7977 5d }
+ $pattern_11 = { 748f 46 4e 49 2af2 ee 9a357f9a475399 }
+ $pattern_12 = { 237ddb e200 95 46 99 37 }
+ $pattern_13 = { d9ae1d19ec3b 01db c5615c ec }
+ $pattern_14 = { 304a8a e2f4 bde7a84f79 c038d3 197ceae6 }
+ $pattern_15 = { 291f ff84c3bd55d8dc f331f2 1a3a 9c 7d78 }
+ $pattern_16 = { 3f 7af1 77a2 24ae 7ff3 }
+ $pattern_17 = { d1655d 7236 3873c1 b59e }
+ $pattern_18 = { 2aff 95 55 28ff 94 53 }
+ $pattern_19 = { e6b1 43 08d2 ef 43 3c38 }
+ $pattern_20 = { 6964427275736800 43 6f 6c 6f 7200 e281 }
+ $pattern_21 = { 37 005400a7 877f08 54 00e1 875303 5c }
+ $pattern_22 = { 6a45 e42c d3ba76c4f058 ce 3037 }
+ $pattern_23 = { b59e 59 f1 f1 }
+ $pattern_24 = { 7988 cd09 91 0099664e0391 008288490061 008c88d3099900 }
+ $pattern_25 = { 1e e3c2 00ff 698876be8fb365b13eb7 45 }
+ $pattern_26 = { 3d4c9deadf 57 ddeb 97 }
+ $pattern_27 = { e280 8ee2 808ee281aee280 8ee2 81ace281ace280ade280ab e281 }
+ $pattern_28 = { 4d 9c 8e5753 32414f d28a7173e2c4 7ee4 d9ae1d19ec3b }
+ $pattern_29 = { 7472 69704d656e755f 53 61 }
+ $pattern_30 = { 79bc fa ad 49 }
+ $pattern_31 = { 875303 5c 00140a 37 005c00a7 }
+ $pattern_32 = { 7265 5f 43 6c 69636b00746f6f 6c 53 }
+ $pattern_33 = { 36e633 2b2b 3673d1 d480 124d2d }
+ $pattern_34 = { 19b3e7ab29db 51 e1f3 dd3a 266f b884c4b53b }
+ $pattern_35 = { 7467 43 f332d2 84bf3df2e66b 4a ba5a20d9f5 3dbf2a3753 }
+ $pattern_36 = { f271f3 8877f7 a8e5 6437 3e2585829c88 }
+ $pattern_37 = { ce 84604c 3f 8cc6 56 bf165fdec5 4a }
+ $pattern_38 = { ad 49 a2???????? 4c e15b 8b1c87 }
+ $pattern_39 = { 3400 b687 bc083c00cd 87ce 083400 }
condition:
- 7 of them and filesize <778240
+ 7 of them and filesize <3834880
}
-rule MALPEDIA_Win_Thunderx_Auto : FILE
+rule TRELLIX_ARC_Havex_Backdoor_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bd791591-7f4e-54f3-bf78-0dd306ad53b2"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thunderx"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.thunderx_auto.yar#L1-L128"
- license_url = "N/A"
- logic_hash = "088c8f2e806c5cf8226a8db8f2cdc4a3ddd2da7bdf68b4f2265db3773cd1c842"
+ description = "Rule to detect backdoor Havex based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "a667bb4e-8c38-59a6-8ae0-09c44961a687"
+ date = "2012-11-17"
+ modified = "2020-08-14"
+ reference = "https://www.f-secure.com/v-descs/backdoor_w32_havex.shtml"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_backdoor_havex_pdb.yar#L1-L26"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "0f4046be5de15727e8ac786e54ad7230807d26ef86c3e8c0e997ea76ab3de255"
+ logic_hash = "dc50475b1ff2194306a0295f71860e4cc5ae7e126daa5d401b98cd2a0aadf1dd"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Havex"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 50 e8???????? c9 c3 c705????????58004200 b001 c3 }
- $sequence_1 = { b9???????? e8???????? 0fb60d???????? 84c0 6a01 58 0f45c8 }
- $sequence_2 = { 51 53 8b5d10 8bd1 56 57 8955fc }
- $sequence_3 = { 8d8d9cfbffff e8???????? 8d8d84fbffff e8???????? 8d8d6cfbffff e8???????? }
- $sequence_4 = { 6a02 8d44241c 895c2424 50 53 53 }
- $sequence_5 = { e8???????? 84c0 7558 83c718 3b7da0 75ea 8d4de0 }
- $sequence_6 = { 89459c 8945a0 e8???????? 84c0 0f858d000000 395f10 }
- $sequence_7 = { 03d1 8b0c85701b4200 8a0433 43 88440a2e 8b4dd8 8b55b4 }
- $sequence_8 = { 8932 897204 897208 5e 5d c20400 6a18 }
- $sequence_9 = { 8d8dd0fdffff e8???????? 8d4dac c645fc06 }
+ $pdb = "\\Workspace\\PhalangX 3D\\Src\\Build\\Release\\Phalanx-3d.ServerAgent.pdb"
+ $pdb1 = "\\Workspace\\PhalangX 3D\\Src\\Build\\Release\\Tmprovider.pdb"
condition:
- 7 of them and filesize <319488
+ uint16(0)==0x5a4d and filesize <500KB and any of them
}
-rule MALPEDIA_Win_Boxcaon_Auto : FILE
+rule TRELLIX_ARC_Dropper_Demekaf_Pdb : DROPPER FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "a730ae2b-b623-5088-86a7-4d1a4eb89ea5"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.boxcaon"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.boxcaon_auto.yar#L1-L120"
- license_url = "N/A"
- logic_hash = "5b71da83cc61472fd3b6239fea0178674ab4b3cf9a9678dbeeda07cdd88e683a"
+ description = "Rule to detect Demekaf dropper based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "b49f42c1-d737-5afa-b547-7268e4cde360"
+ date = "2011-03-26"
+ modified = "2020-08-14"
+ reference = "https://v.virscan.org/Trojan-Dropper.Win32.Demekaf.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_dropper_demekaf_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "fab320fceb38ba2c5398debdc828a413a41672ce9745afc0d348a0e96c5de56e"
+ logic_hash = "89c0c1da1f8997b12a446c93bbde200e62fac9cab2a9a17147b268d435bdc3b6"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "DROPPER, FILE"
+ rule_version = "v1"
+ malware_type = "dropper"
+ malware_family = "Dropper:W32/Demekaf"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 897e14 897e70 c686c800000043 c6864b01000043 c7466890b54000 6a0d e8???????? }
- $sequence_1 = { 8bd3 66899424e0000000 5a 6a50 66899424e2000000 8bd1 66899424e4000000 }
- $sequence_2 = { 8888b8b84000 40 ebe6 ff35???????? }
- $sequence_3 = { 8bec 33c0 8b4d08 3b0cc5408a4000 740a }
- $sequence_4 = { c78424980000003c000000 ff15???????? 56 33ff }
- $sequence_5 = { e8???????? 84c0 741a 8d4c2410 8d8424d8020000 2bc1 }
- $sequence_6 = { 89bc24ac000000 89b424b4000000 c78424980000003c000000 ff15???????? }
- $sequence_7 = { 33c9 66890c06 68???????? 8d442414 50 e8???????? }
- $sequence_8 = { 0020 1f 40 00441f40 0023 d18a0688078a 46 }
- $sequence_9 = { 33c0 c7461407000000 668906 8b4508 8b5810 57 }
+ $pdb = "\\vc\\res\\fake1.19-jpg\\fake\\Release\\fake.pdb"
condition:
- 7 of them and filesize <256000
+ uint16(0)==0x5a4d and filesize <150KB and any of them
}
-rule MALPEDIA_Win_Graftor_Auto : FILE
+rule TRELLIX_ARC_Dridex_P2P_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7d45e232-2e70-5f76-b127-1013459f5457"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graftor"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.graftor_auto.yar#L1-L132"
- license_url = "N/A"
- logic_hash = "2d0bf0ad42127878b7c1f7be3bcb33cc3ba27a99993b023e29cc91abed5bec59"
+ description = "Rule to detect Dridex P2P based on the PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "57350c96-877e-57de-9465-df9f7eb6d656"
+ date = "2014-11-29"
+ modified = "2020-08-14"
+ reference = "https://www.us-cert.gov/ncas/alerts/aa19-339a"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_dridex_p2p_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "5345a9405212f3b8ef565d5d793e407ae8db964865a85c97e096295ba3f39a78"
+ logic_hash = "c9c4db48435203cdb882eef8082efd8424bd13f1aa512cfb3082f365b9bc6e83"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Dridex"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8d742434 c684245803000069 e8???????? 8b54241c 53 e8???????? 59 }
- $sequence_1 = { 55 8bec 51 8365fc00 56 0528010000 }
- $sequence_2 = { ff750c 8d7de0 ff7508 e8???????? 8b45e8 8945f0 8b45ec }
- $sequence_3 = { 8d44247c 50 c684245c03000070 e8???????? 83c40c c684245003000071 8b4c241c }
- $sequence_4 = { 6a00 eb8b 8b7d0c 8b0f 8b4514 394810 7641 }
- $sequence_5 = { 55 8bec 83e4f8 6aff 687e634c00 64a100000000 }
- $sequence_6 = { 8901 33c0 40 e9???????? 8365d800 c745dc34ad4800 a1???????? }
- $sequence_7 = { ff75ec 8d45e0 53 50 8bc6 e8???????? 8b18 }
- $sequence_8 = { eb05 a1???????? 8b4dfc 33cd e8???????? c9 c3 }
- $sequence_9 = { 3bc3 0f8686010000 8b87d0000000 6a64 99 5e f7fe }
+ $pdb = "\\c0da\\j.pdb"
condition:
- 7 of them and filesize <294912
+ uint16(0)==0x5a4d and filesize <400KB and any of them
}
-rule MALPEDIA_Win_Cookiebag_Auto : FILE
+rule TRELLIX_ARC_Rietspoof_Loader : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c260d983-1fb1-5187-bb1e-a30d172d6701"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cookiebag"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.cookiebag_auto.yar#L1-L131"
- license_url = "N/A"
- logic_hash = "74595c8c00c27ebea5fcf6294fdb19b48126392d3364dc5a9bcc9f574cb25599"
+ description = "Rule to detect the Rietspoof loader"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "f306e381-e2ae-528e-937b-aced72356d77"
+ date = "2024-09-01"
+ modified = "2020-08-14"
+ reference = "https://blog.avast.com/rietspoof-malware-increases-activity"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_rietspoof_loader.yar#L1-L22"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "d72b58ff452070e03d0b25bc433ef5c677df77dd440adc1ecdb592cee24235fb"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "RANSOMWARE, FILE"
+ malware_type = "ransomware"
+ malware_family = "Loader:W32/Rietspoof"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 0f8e39050000 8a442437 bf???????? 88442424 83c9ff 33c0 33ed }
- $sequence_1 = { 51 8b4c2414 55 e8???????? 84c0 7412 8b442418 }
- $sequence_2 = { 51 e8???????? 83c404 eb1d 8b4608 8b7604 3bf3 }
- $sequence_3 = { 50 53 52 e8???????? 8bce e8???????? 8b4c2428 }
- $sequence_4 = { 83c1fe 51 e8???????? 83c404 8b4c242c 897c243c 3bcf }
- $sequence_5 = { e8???????? 68???????? e8???????? 83c404 8bd8 8dbe14010000 6a01 }
- $sequence_6 = { 895c2428 e8???????? 84c0 7427 8b7c2418 8bcd }
- $sequence_7 = { 85c0 7454 8b87dc000000 85c0 764a 8b44240c }
- $sequence_8 = { e8???????? 83c414 b001 5f 5e c20400 5f }
- $sequence_9 = { 6a01 8d4c241c c7442444ffffffff e8???????? 8b4c2438 64890d00000000 }
+ $x1 = "\\Work\\d2Od7s43\\techloader\\loader" fullword ascii
condition:
- 7 of them and filesize <311296
+ uint16(0)==0x5a4d and all of them
}
-rule MALPEDIA_Win_Webc2_Yahoo_Auto : FILE
+rule TRELLIX_ARC_Backdoor_Kankan_Pdb : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "63230a4f-7913-5b93-bb9a-30d89db03d73"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.webc2_yahoo"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.webc2_yahoo_auto.yar#L1-L118"
- license_url = "N/A"
- logic_hash = "f89dfba6353885aa09b69faf5df0db1655d3acae8a14a8bbfd9acb6fd6fd17df"
+ description = "Rule to detect kankan PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "6910ecc7-3c31-569b-a7ff-2dcbccff88f9"
+ date = "2013-08-01"
+ modified = "2020-08-14"
+ reference = "https://threatpoint.checkpoint.com/ThreatPortal/threat?threatType=malwarefamily&threatId=650"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_backdoor_kankan_pdb.yar#L1-L27"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "73f9e28d2616ee990762ab8e0a280d513f499a5ab2cae9f8cf467701f810b98a"
+ logic_hash = "3d2e45631dfca0e76e98eee4bb5c4ce1631906f497c052d8c41cc37637cb2760"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/Kankan"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 59 7513 ff15???????? 8986a0841e00 }
- $sequence_1 = { 56 ff15???????? 802000 56 e8???????? }
- $sequence_2 = { 53 50 50 53 ff750c ff15???????? 57 }
- $sequence_3 = { 39be9c841e00 59 7513 ff15???????? 8986a0841e00 33c0 }
- $sequence_4 = { c745fc01000000 aa e8???????? 59 8d85f4d7ffff 50 8d45f8 }
- $sequence_5 = { 50 8d45f8 50 8d85f4afffff }
- $sequence_6 = { 8b7518 83c414 8d85fcd7ffff 8bcb }
- $sequence_7 = { 8b4d08 e8???????? 85c0 53 }
- $sequence_8 = { 59 50 ff75f8 ff75fc ffb69c841e00 ff15???????? }
- $sequence_9 = { 8d85c8fcffff 68???????? 50 e8???????? 83c410 85c0 7466 }
+ $pdb = "\\Projects\\OfficeAddin\\INPEnhSvc\\Release\\INPEnhSvc.pdb"
+ $pdb1 = "\\Projects\\OfficeAddin\\OfficeAddin\\Release\\INPEn.pdb"
+ $pdb2 = "\\Projects\\OfficeAddinXJ\\VOCEnhUD\\Release\\VOCEnhUD.pdb"
condition:
- 7 of them and filesize <8060928
+ uint16(0)==0x5a4d and filesize <500KB and any of them
}
-rule MALPEDIA_Win_Shylock_Auto : FILE
+rule TRELLIX_ARC_Rovnix_Downloader : DOWNLOADER
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "c0c6612f-064a-5f55-82bb-f58e63a548a1"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shylock"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.shylock_auto.yar#L1-L134"
- license_url = "N/A"
- logic_hash = "2cab0a97d5d39d5cf87c312cbde6ff184fa1776200cc626b918f5dce9951a83d"
+ description = "Rovnix downloader with sinkhole checks"
+ author = "Intel Security"
+ id = "d51f8f73-7a3a-5ccf-9122-86061b5399f1"
+ date = "2024-09-01"
+ modified = "2020-08-14"
+ reference = "https://blogs.mcafee.com/mcafee-labs/rovnix-downloader-sinkhole-time-checks/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_Rovnix.yar#L1-L38"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "52cde40c95436129b7d48b4bd5e78b66deb84fdc84a76cc9ac72f24e0777e540"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 43
+ tags = "DOWNLOADER"
+ malware_type = "downloader"
+ malware_family = "Downloader:W32/Rovnix"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { e8???????? 8d8534ffffff 50 b8???????? e8???????? 59 50 }
- $sequence_1 = { 8db544ffffff e8???????? 8bc6 50 8d45f8 e8???????? ff30 }
- $sequence_2 = { c22c00 0fb64001 50 8d45c8 50 8b45d4 8b30 }
- $sequence_3 = { c745fc04010000 ff75e4 e8???????? 83c410 ff45f8 3d03010000 0f8559ffffff }
- $sequence_4 = { e8???????? 3c01 743b 8d8588feffff 50 b8???????? e8???????? }
- $sequence_5 = { 57 8b7d08 8b4d0c 8a4510 fc f2ae 7504 }
- $sequence_6 = { 8945b0 8d856cffffff 50 8b45fc ff7018 ff9540ffffff 898534ffffff }
- $sequence_7 = { 8d75f8 8bfc e8???????? 8d8504ffffff 50 ff7508 e8???????? }
- $sequence_8 = { 51 33d2 8d5df8 e8???????? 8d45ec e8???????? 8bf8 }
- $sequence_9 = { e8???????? e8???????? 59 59 8bf0 e8???????? 8d75fc }
+ $sink1 = "control"
+ $sink2 = "sink"
+ $sink3 = "hole"
+ $sink4 = "dynadot"
+ $sink5 = "block"
+ $sink6 = "malw"
+ $sink7 = "anti"
+ $sink8 = "googl"
+ $sink9 = "hack"
+ $sink10 = "trojan"
+ $sink11 = "abuse"
+ $sink12 = "virus"
+ $sink13 = "black"
+ $sink14 = "spam"
+ $boot = "BOOTKIT_DLL.dll"
+ $mz = { 4D 5A }
condition:
- 7 of them and filesize <630784
+ $mz in (0..2) and all of ($sink*) and $boot
}
-rule MALPEDIA_Win_Unidentified_088_Auto : FILE
+rule TRELLIX_ARC_MALWARE_Blackpos_Pdb : POS FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "008a08cf-eb70-5951-921d-71ebeefbb775"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_088"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.unidentified_088_auto.yar#L1-L127"
- license_url = "N/A"
- logic_hash = "edb29cf74a1f7930c182d8621bb40052ec38cc60668c8de3f80bbb2fb8759321"
+ description = "BlackPOS PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "f37e1522-49c4-5369-bc2c-33b070e9eae7"
+ date = "2014-01-24"
+ modified = "2020-08-14"
+ reference = "https://en.wikipedia.org/wiki/BlackPOS_Malware"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_blackpos_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "5a963e8aca62f3cf5872c6bff02d6dee0399728554c6ac3f5cb312b2ba7d7dbf"
+ logic_hash = "d8f3fa380ca15f0fae432849b8c16cb8a0a9d1427d3e72fbf89cbbd63b0849c9"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "POS, FILE"
+ rule_version = "v1"
+ malware_type = "pos"
+ malware_family = "Pos:W32/BlackPos"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { c642e801 894af4 83f807 75df c705????????06000000 c705????????11000000 c705????????12000000 }
- $sequence_1 = { c705????????208d4200 c705????????62eb4100 c705????????90154200 c605????????01 c705????????10000000 c705????????20a94200 c705????????40eb4100 }
- $sequence_2 = { c605????????01 c705????????04000000 c705????????80a94200 c705????????61e04100 c705????????30054200 c705????????00000000 }
- $sequence_3 = { 8b10 8d4a01 8d3490 8908 8b4de4 8b5e08 }
- $sequence_4 = { 0f8438010000 8b00 39c7 720d 48 893c24 }
- $sequence_5 = { 8b7de4 e9???????? 8d65f4 5b 5e 5f 5d }
- $sequence_6 = { e9???????? c705????????08000000 c705????????04000000 c605????????12 c705????????00000000 c705????????d80f4200 }
- $sequence_7 = { c705????????a0ad4200 c705????????4ce84100 c705????????100d4200 c605????????01 c705????????04000000 }
- $sequence_8 = { e8???????? 89d9 89c2 e8???????? 8d65f4 5b }
- $sequence_9 = { 894c2408 89f1 89542404 895c240c e8???????? b904000000 83ec10 }
+ $pdb = "\\Projects\\Rescator\\MmonNew\\Debug\\mmon.pdb"
condition:
- 7 of them and filesize <919552
+ uint16(0)==0x5a4d and filesize <300KB and any of them
}
-rule MALPEDIA_Win_Mariposa_Auto : FILE
+rule TRELLIX_ARC_MALW_Cobaltrike : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
+ description = "Rule to detect CobaltStrike beacon"
author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "2a3a2192-1985-5afb-a3c8-457f3f4c729c"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mariposa"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.mariposa_auto.yar#L1-L118"
- license_url = "N/A"
- logic_hash = "343ac33f57cd9cc9bfc1841bf1bd211734de245f417ee554220587a46ed4086f"
+ id = "a7dae4c7-672e-58fb-8542-90fa90d991a4"
+ date = "2020-07-19"
+ modified = "2021-08-30"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cobalt_strike"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_cobaltstrike.yar#L1-L38"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "fc91d40c6544c7ab7c60b3cb8fc542bd4a6fac79dbe00cad8f612854f2a6dcd1"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/CobaltStrike"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
+ hash1 = "f47a627880bfa4a117fec8be74ab206690e5eb0e9050331292e032cd22883f5b"
strings:
- $sequence_0 = { 55 8bec 53 56 bb???????? 43 }
- $sequence_1 = { ffd3 33c0 50 e8???????? 33c0 }
- $sequence_2 = { 53 56 bb???????? 43 }
- $sequence_3 = { 885c0cff e2f1 ba???????? 2bd6 8bdc 03da 4b }
- $sequence_4 = { 8a1c0e 02d8 32dc fec0 885c0cff e2f1 }
- $sequence_5 = { 8bdc 03da 4b 54 ffd3 33c0 }
- $sequence_6 = { 885c0cff e2f1 ba???????? 2bd6 }
- $sequence_7 = { 8a4301 8a6302 f6d0 02c4 d0f8 8a1c0e }
- $sequence_8 = { 53 56 bb???????? 43 803b00 }
- $sequence_9 = { 03da 4b 54 ffd3 33c0 }
+ $pattern_0 = { e9???????? eb0a b801000000 e9???????? }
+ $pattern_1 = { 3bc7 750d ff15???????? 3d33270000 }
+ $pattern_2 = { 8bd0 e8???????? 85c0 7e0e }
+ $pattern_3 = { 50 8d8d24efffff 51 e8???????? }
+ $pattern_4 = { 03b5d4eeffff 89b5c8eeffff 3bf7 72bd 3bf7 }
+ $pattern_5 = { 8b450c 8945f4 8d45f4 50 }
+ $pattern_6 = { 33c5 8945fc 8b4508 53 56 ff750c 33db }
+ $pattern_7 = { e8???????? e9???????? 833d????????01 7505 e8???????? }
+ $pattern_8 = { 53 53 8d85f4faffff 50 }
+ $pattern_9 = { 68???????? 53 50 e8???????? 83c424 }
+ $pattern_10 = { 488b4c2420 8b0401 8b4c2408 33c8 8bc1 89442408 }
+ $pattern_11 = { 488d4d97 e8???????? 4c8d9c24d0000000 418bc7 498b5b20 498b7328 498b7b30 }
+ $pattern_12 = { bd08000000 85d2 7459 ffcf 4d85ed }
+ $pattern_13 = { 4183c9ff 33d2 ff15???????? 4c63c0 4983f8ff }
+ $pattern_14 = { 49c1e002 e8???????? 03f3 4d8d349e 3bf5 7d13 }
+ $pattern_15 = { 752c 4c8d45af 488d55af 488d4d27 }
condition:
- 7 of them and filesize <311296
+ 7 of them and filesize <696320
}
-rule MALPEDIA_Win_Chinoxy_Auto : FILE
+rule TRELLIX_ARC_Alina_POS_PDB : POS FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "916e0861-f860-58c8-9808-fcfac5c4f41d"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chinoxy"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.chinoxy_auto.yar#L1-L133"
- license_url = "N/A"
- logic_hash = "eeb7ce09274161abdb807fd23b8c72ae21763a7e3cd9b91cd84dd2d99cf4e640"
+ description = "Rule to detect Alina POS"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "9588aa10-d5e4-55f4-998c-a01503a53d3a"
+ date = "2013-08-08"
+ modified = "2020-08-14"
+ reference = "https://www.pandasecurity.com/mediacenter/pandalabs/alina-pos-malware/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_alina_pos_pdb.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "28b0c52c0630c15adcc857d0957b3b8002a4aeda3c7ec40049014ce33c7f67c3"
+ logic_hash = "9bb8260e3a47567e2460dd474fb74e57987e3d79eb30cdbc2a45b88a16ba1ca2"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "POS, FILE"
+ rule_version = "v1"
+ malware_type = "pos"
+ malware_family = "Pos:W32/Alina"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8d4704 50 ff15???????? 8d8e90200000 c744241800000000 e8???????? 85c0 }
- $sequence_1 = { 8d842424010000 50 e8???????? 8b9318040000 8d8c2428010000 51 52 }
- $sequence_2 = { 2bcd c1e013 c1ef0d 0bc7 03ee 33c1 8bf8 }
- $sequence_3 = { 897e18 8b4c2410 895e10 895e14 8bc6 5f 5e }
- $sequence_4 = { e8???????? 85c0 741f 668b4c242c 6a08 66894802 50 }
- $sequence_5 = { 8b8ef0000000 8d86e8000000 3bc8 c744241c00000000 7405 394004 7538 }
- $sequence_6 = { 8d4c2410 6689542414 66895c2424 6689542430 66895c2438 66895c245c }
- $sequence_7 = { 8d8ec8020000 e8???????? 8d86d4020000 8b4c240c 894004 894008 c700???????? }
- $sequence_8 = { 894b10 03f2 8bd1 8bf8 c1e902 f3a5 8bca }
- $sequence_9 = { 17 08cb 8291975b9c2acc 8f81509c02d5 96 9e 664e }
+ $pdb = "\\Users\\dice\\Desktop\\SRC_adobe\\src\\grab\\Release\\Alina.pdb"
condition:
- 7 of them and filesize <1138688
+ uint16(0)==0x5a4d and filesize <100KB and any of them
}
-rule MALPEDIA_Win_Ryuk_Auto : FILE
+rule TRELLIX_ARC_Downloader_Darkmegi_Pdb : DOWNLOADER FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "9762637f-3260-5c34-b846-45fb6634f5b4"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ryuk_auto.yar#L1-L425"
- license_url = "N/A"
- logic_hash = "b1841a1134c1a11658d85f36006ba9e8e5ed64f6492350418145712079afb53f"
+ description = "Rule to detect DarkMegi downloader based on PDB"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "3ccc3685-e05b-5620-9198-24733fb1e7eb"
+ date = "2013-03-06"
+ modified = "2020-08-14"
+ reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkmegi"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_downloader_darkmegi.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "bf849b1e8f170142176d2a3b4f0f34b40c16d0870833569824809b5c65b99fc1"
+ logic_hash = "47faf8c5296e651f82726a6e8a7843dfa0f98e7be7257d2c03efcff550f52140"
score = 75
- quality = 50
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "DOWNLOADER, FILE"
+ rule_version = "v1"
+ malware_type = "downloader"
+ malware_family = "Downloader:W32/DarkMegi"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 68???????? 6a01 6a00 6814010000 }
- $sequence_1 = { ff15???????? 85c0 7508 6a01 ff15???????? 68???????? 6a01 }
- $sequence_2 = { 6a08 6a18 68???????? 68???????? 68???????? ff15???????? }
- $sequence_3 = { 754c b90b010000 66398818000035 753e 8b4508 b9???????? 2bc1 }
- $sequence_4 = { 68???????? ff15???????? 85c0 7578 6a10 6a18 }
- $sequence_5 = { 755d a1???????? 81b8????????50450000 754c b90b010000 66398818000035 }
- $sequence_6 = { 68???????? ff15???????? 85c0 7542 6a28 6a18 }
- $sequence_7 = { 68c0cf6a00 ff15???????? 6a01 ff15???????? }
- $sequence_8 = { 7407 b801000000 eb0b eb04 }
- $sequence_9 = { e8???????? 68e8030000 ff15???????? 68???????? e8???????? }
- $sequence_10 = { 720f b901000000 6bd103 8b45fc c6041000 }
- $sequence_11 = { 83c101 ba01000000 d1e2 8b45fc }
- $sequence_12 = { 8908 895004 837df800 7709 }
- $sequence_13 = { 89459c 8955a0 8b55a0 3b55f8 0f870b020000 }
- $sequence_14 = { ba01000000 6bc203 8b55fc 880c02 b804000000 }
- $sequence_15 = { ff15???????? b811000000 e9???????? e9???????? }
- $sequence_16 = { ff15???????? 833d????????00 6a10 6a18 }
- $sequence_17 = { 6a00 6814010000 ff7508 ff35???????? }
- $sequence_18 = { 7407 48 85c0 7ff0 }
- $sequence_19 = { ff15???????? b803000000 eb05 b805000000 }
- $sequence_20 = { 2bf0 33c0 66890473 83ffff }
- $sequence_21 = { 751b ff35???????? ff35???????? 6a01 68???????? e8???????? }
- $sequence_22 = { eb0b 8bc1 99 f7fe }
- $sequence_23 = { 56 ff15???????? 8bcb 8d5102 }
- $sequence_24 = { 7714 7212 81f9d0070000 770a 85d2 }
- $sequence_25 = { e8???????? e8???????? b9e8030000 ff15???????? }
- $sequence_26 = { 668b02 83c202 6685c0 75f5 8d7bfe 2bd6 }
- $sequence_27 = { 0f9fc0 5d c3 8bff 55 8bec 8b4508 }
- $sequence_28 = { 5d c3 8bcb 8d5102 }
- $sequence_29 = { d1fa 2bca 33c0 6689444bfe e9???????? 33c0 }
- $sequence_30 = { 488bc3 4883c430 5b c3 48895c2408 48896c2410 4889742418 }
- $sequence_31 = { 68???????? 53 d1fe e8???????? 83c408 8d5002 }
- $sequence_32 = { 498bc1 c3 4053 4883ec20 8bc1 498bd8 }
- $sequence_33 = { 50 51 e8???????? 6a00 6840420f00 52 50 }
- $sequence_34 = { 83c602 6685c9 75f5 2bf2 68???????? 53 }
- $sequence_35 = { f3a4 8d7afe 668b4702 8d7f02 6685c0 75f4 a1???????? }
- $sequence_36 = { 4883c428 c3 48895c2408 57 4883ec30 8364242000 }
- $sequence_37 = { 33c9 ba10270000 41b800100000 448d4904 ff15???????? }
- $sequence_38 = { f7e1 8bc1 2bc2 d1e8 03c2 c1e806 6bc05a }
- $sequence_39 = { ff15???????? 41b900300000 c744242040000000 448bc3 488bd6 488bcf }
- $sequence_40 = { c744242802000000 4533c9 4533c0 c744242002000000 ba000000c0 }
- $sequence_41 = { ff15???????? 488bd8 ff15???????? 83f820 7510 488bcb ff15???????? }
- $sequence_42 = { 4533c9 4533c0 c744242003000000 ba00000040 ff15???????? 488bd8 ff15???????? }
- $sequence_43 = { 66837f0254 750f 66837f0641 7508 }
- $sequence_44 = { 4889442420 4c8bc6 488bd3 488bcf ff15???????? }
- $sequence_45 = { ff15???????? 66833f4e 7516 66837f0254 750f }
- $sequence_46 = { 84c0 746c e8???????? 488d0d63080000 e8???????? e8???????? }
+ $pdb = "\\RKTDOW~1\\RKTDRI~1\\RKTDRI~1\\objchk\\i386\\RktDriver.pdb"
condition:
- 7 of them and filesize <7450624
+ uint16(0)==0x5a4d and filesize >20000KB and any of them
}
-rule MALPEDIA_Win_Ironwind_Auto : FILE
+rule TRELLIX_ARC_Malw_Browser_Fox_Adware : ADWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "59e0122b-e237-5b83-a993-a2711164e0ad"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ironwind"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.ironwind_auto.yar#L1-L133"
- license_url = "N/A"
- logic_hash = "db36742cc3e5372580f85bcac0b5325edc83e1defe6a3dbe06584de3a3fb0586"
+ description = "Rule to detect Browser Fox Adware based on the PDB reference"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "67d20c3a-4e9d-5fbf-b26a-d7b5fb270d12"
+ date = "2015-01-15"
+ modified = "2020-08-14"
+ reference = "https://www.sophos.com/en-us/threat-center/threat-analyses/adware-and-puas/Browse%20Fox.aspx"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_browser_fox_adware.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "c6f3d6024339940896dd18f32064c0773d51f0261ecbee8b0534fdd9a149ac64"
+ logic_hash = "462a05de46ec0d710cac80a05d4935279a43f49cbd5ef49c072f277982a76fce"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "ADWARE, FILE"
+ rule_version = "v1"
+ malware_type = "adware"
+ malware_family = "Adware:W32/BrowserFox"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { be01000000 8bc6 e9???????? 4803c9 488b6cca08 4885ed 74e7 }
- $sequence_1 = { c3 4533c0 418d5002 8d4a15 ff15???????? 4883f8ff }
- $sequence_2 = { e9???????? 488d0d823e0300 4889bc24a0000000 e8???????? 488bf8 4885c0 7508 }
- $sequence_3 = { ff15???????? 488b742460 4885db 7409 488bcb ff15???????? 8bc7 }
- $sequence_4 = { 80b85011000001 488d152cc40400 488d0d4dc40400 480f45d1 488bc8 e8???????? 488bf8 }
- $sequence_5 = { 8d5001 8d4838 ff15???????? 488bf8 4885c0 7508 8d471b }
- $sequence_6 = { f20f1101 e9???????? 0f57c0 f2480f2a87100b0000 f20f1101 e9???????? 0f57c0 }
- $sequence_7 = { bf05000000 8bc7 eb53 bf02000000 8bc7 eb4a 664183f804 }
- $sequence_8 = { 85c0 742e 0fbe03 4c8d156f8ffdff 83c0e0 83f85a 0f8765020000 }
- $sequence_9 = { e8???????? 488b8f50070000 4885c9 7469 ff15???????? 488983d0060000 4885c0 }
+ $pdb = "\\Utilities\\130ijkfv.o4g\\Desktop\\Desktop.OptChecker\\bin\\Release\\ BooZaka.Opt"
condition:
- 7 of them and filesize <995328
+ uint16(0)==0x5a4d and filesize <800KB and any of them
}
-rule MALPEDIA_Win_Lethic_Auto : FILE
+rule TRELLIX_ARC_Vpnfilter : BACKDOOR FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "89881c0c-ddd2-5773-9144-03db6590b3cc"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lethic"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.lethic_auto.yar#L1-L121"
- license_url = "N/A"
- logic_hash = "3125ec39e54752d0947a08a6149f6c0dbb19d9ccd38ebef90b278b6227c3cc5c"
+ description = "Filter for 2nd stage malware used in VPNfilter attack"
+ author = "Christiaan Beek @ McAfee Advanced Threat Research"
+ id = "89bd7f94-d73c-5c5c-a3ec-0331f79e61fd"
+ date = "2018-05-23"
+ modified = "2020-08-14"
+ reference = "https://blog.talosintelligence.com/2018/05/VPNFilter.html"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/malware/MALW_VPNfilter.yar#L1-L40"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "9eb6c779dbad1b717caa462d8e040852759436ed79cc2172692339bc62432387"
+ logic_hash = "88f08765dff632f0c08e985181309e5c3ac9cdaa51d05d8485c411fb1a183cca"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "BACKDOOR, FILE"
+ rule_version = "v1"
+ malware_type = "backdoor"
+ malware_family = "Backdoor:W32/VPNfilter"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 837df400 7507 33c0 e9???????? 8b55f4 8b4218 }
- $sequence_1 = { 33c0 e9???????? 8b45fc 8b4d10 894804 }
- $sequence_2 = { 50 8b4dfc 83c108 51 8b55f4 }
- $sequence_3 = { 8b45fc 8b08 894dfc ebec 8b55fc }
- $sequence_4 = { eb42 6a10 8b55fc 83c208 52 }
- $sequence_5 = { ebec 8b55fc 8b45f4 8b08 890a 8b55fc }
- $sequence_6 = { 8945fc c745f801000000 837dfc00 7507 33c0 e9???????? 8b45fc }
- $sequence_7 = { 3b55f8 7411 8b45fc c60000 }
- $sequence_8 = { 8b08 890a 8b55fc 8b02 8945fc 8b4df4 51 }
- $sequence_9 = { eb42 6a10 8b55fc 83c208 52 8b45fc 8b4818 }
+ $s1 = "id-at-postalAddress" fullword ascii
+ $s2 = "/bin/shell" fullword ascii
+ $s3 = "/DZrtenNLQNiTrM9AM+vdqBpVoNq0qjU51Bx5rU2BXcFbXvI5MT9TNUhXwIDAQAB" fullword ascii
+ $s4 = "Usage does not match the keyUsage extension" fullword ascii
+ $s5 = "id-at-postalCode" fullword ascii
+ $s6 = "vTeY4KZMaUrveEel5tWZC94RSMKgxR6cyE1nBXyTQnDOGbfpNNgBKxyKbINWoOJU" fullword ascii
+ $s7 = "id-ce-extKeyUsage" fullword ascii
+ $s8 = "/f8wYwYDVR0jBFwwWoAUtFrkpbPe0lL2udWmlQ/rPrzH/f+hP6Q9MDsxCzAJBgNV" fullword ascii
+ $s9 = "/etc/config/hosts" fullword ascii
+ $s10 = "%s%-18s: %d bits" fullword ascii
+ $s11 = "id-ce-keyUsage" fullword ascii
+ $s12 = "Machine is not on the network" fullword ascii
+ $s13 = "No XENIX semaphores available" fullword ascii
+ $s14 = "No CSI structure available" fullword ascii
+ $s15 = "Name not unique on network" fullword ascii
condition:
- 7 of them and filesize <81920
+ ( uint16(0)==0x457f and filesize <500KB and (8 of them )) or ( all of them )
}
-rule MALPEDIA_Win_Yty_Auto : FILE
+rule TRELLIX_ARC_Unpacked_Shiva_Ransomware : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "02d4730a-30ed-52fc-baae-eabe1247d262"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yty"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.yty_auto.yar#L1-L501"
- license_url = "N/A"
- logic_hash = "379d5918b4988ca6f478472e8b6e04b973c7dd65b7661d4073d168551cfe004f"
+ description = "Rule to detect an unpacked sample of Shiva ransomware"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "c6cd4421-216f-5c1f-bb8d-fc8ab00bb72d"
+ date = "2018-09-05"
+ modified = "2020-08-14"
+ reference = "https://twitter.com/malwrhunterteam/status/1037424962569732096"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_Shiva.yar#L1-L37"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "299bebcb18e218254960ef96c2e65a4dc1945dcdfe9fc68550022f99a474f56d"
+ logic_hash = "8a6a1d9f3b75617d8f07489ecf2867f90ddcf9fbe1db1e7c0f5c26833f88be3f"
score = 75
- quality = 50
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 66
+ tags = "RANSOMWARE, FILE"
+ rule_version = "v1"
+ malware_type = "ransomware"
+ malware_family = "Ransom:W32/Shiva"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 0f840c000000 8365d8fe 8b7508 e9???????? }
- $sequence_1 = { 8d45f4 64a300000000 8b7508 33ff 897dd8 }
- $sequence_2 = { 8975e0 85c9 7407 8b11 8b4204 ffd0 c745fc00000000 }
- $sequence_3 = { 668910 8bc6 5b 8be5 5d c20400 }
- $sequence_4 = { ffd2 8b8568ffffff 8b08 8b5108 50 }
- $sequence_5 = { eb69 8a1402 2ad1 8bfe 80ea13 }
- $sequence_6 = { 6a00 8d4508 c746140f000000 c7461000000000 }
- $sequence_7 = { 750c 680e000780 e8???????? 33ff c745fcffffffff }
- $sequence_8 = { 80ea04 b904000000 eb23 8b5508 397d1c 7303 }
- $sequence_9 = { 85c0 52 0f95c3 ffd6 }
- $sequence_10 = { 2ad1 8bfe 80ea04 b901000000 e9???????? }
- $sequence_11 = { 40 3b4610 0f82dbfeffff 397d1c }
- $sequence_12 = { 83c40c 8d8de8fdffff 51 53 53 }
- $sequence_13 = { 8b4e10 397e14 7211 8a1402 8b3e }
- $sequence_14 = { 894608 8945fc 56 c745f001000000 }
- $sequence_15 = { 8bcf e8???????? 8b0e 8b5104 8b443238 }
- $sequence_16 = { 53 50 e8???????? 83c40c 8d8de8fdffff }
- $sequence_17 = { 7303 8d5508 8b4e10 397e14 7214 }
- $sequence_18 = { 8bfe 8a1402 2ad1 80ea13 33c9 881407 }
- $sequence_19 = { 8b4c3138 33db 895de8 885def 8975e0 }
- $sequence_20 = { 807def00 8b5de8 7503 83cb02 8b16 8b4a04 }
- $sequence_21 = { c0ea02 8ac4 80e20f c0e004 }
- $sequence_22 = { 8b07 eb02 8bc7 8b4de0 }
- $sequence_23 = { 8b4c1938 895dd4 85c9 7405 8b01 ff5004 c745fc00000000 }
- $sequence_24 = { 8b85c4f5ffff 50 e8???????? 83c404 8d95c0f5ffff 33c9 52 }
- $sequence_25 = { 8bcc 8975f4 50 e8???????? ff7510 8d4dd4 }
- $sequence_26 = { 762a 8b4d08 8b5108 8a8210a04600 2c01 8845ff 8b4d08 }
- $sequence_27 = { 68???????? ff15???????? 3bf4 e8???????? 8bf4 8b4594 50 }
- $sequence_28 = { b9???????? e8???????? 51 8d8d90bcf0ff }
- $sequence_29 = { 6bf630 8b0c8d60cb4300 80643128fd 5f }
- $sequence_30 = { 8bec 8b4508 8bc8 83e01f c1f905 8b0c8da0244300 }
- $sequence_31 = { 83e61f 8d3c8da0244300 8b0f c1e606 833c0eff 7535 833d????????01 }
- $sequence_32 = { c745e401000000 e9???????? c745e000000000 8b15???????? a1???????? 01d0 }
- $sequence_33 = { ff15???????? 85c0 0f85e3020000 68???????? 50 50 ff15???????? }
- $sequence_34 = { 8b4804 8d4190 89840df0b8f0ff 8d8d04b9f0ff e8???????? 8b85f4b8f0ff 8b4004 }
- $sequence_35 = { 0f851f040000 8d853cfeffff 83c01c 890424 }
- $sequence_36 = { 8b4d0c 83e13f 6bd130 8b048500b04600 }
- $sequence_37 = { 3bf4 e8???????? 8bf4 8b8574fcffff 50 ff15???????? 3bf4 }
- $sequence_38 = { 01ca 0fb612 89d1 8b550c 01ca 8810 }
- $sequence_39 = { 740c c785d4ddffffac084500 eb0a c785d4ddffffd4d44400 8b85a4ddffff 50 }
- $sequence_40 = { 8b4508 890424 e8???????? 8945d8 837dd800 0f847a050000 }
- $sequence_41 = { e8???????? c78562feffff00000000 8d8566feffff b960000000 bb00000000 }
- $sequence_42 = { 8d8da8efffff e8???????? 50 8d8dd0efffff e8???????? 8d8da8efffff e9???????? }
- $sequence_43 = { e8???????? 83ec0c 8d8ddcfbffff 0f1000 0f1105???????? f30f7e4010 }
- $sequence_44 = { f3ab c745f800000000 c745d400000000 8b450c }
- $sequence_45 = { e8???????? c78324020000ffffffff c78328020000ffffffff 83c414 5b }
- $sequence_46 = { 56 53 83ec14 8b5c2420 e8???????? 85db c70000000000 }
- $sequence_47 = { e9???????? 8975e4 33c0 39b880f94200 }
- $sequence_48 = { 750c c785bcddffff60084500 eb0a c785bcddffffd4d44400 b802000000 }
- $sequence_49 = { 83e63f c1ff06 6bf630 8b04bd60cb4300 f644302880 741f e8???????? }
- $sequence_50 = { 8d15f0224100 e8???????? 58 5a }
- $sequence_51 = { 83e826 89c2 a1???????? c744240800000000 89542404 890424 e8???????? }
- $sequence_52 = { 0f87b1030000 ff24bd41574200 8b41e4 3b42e4 7478 0fb642e4 0fb671e4 }
- $sequence_53 = { 57 897de8 ff15???????? 8bd0 8955ec c645fc01 c746140f000000 }
- $sequence_54 = { c745dc03000000 eb7c c745e088044300 ebbb d9e8 }
+ $s1 = "c:\\Users\\sys\\Desktop\\v 0.5\\Shiva\\Shiva\\obj\\Debug\\shiva.pdb" fullword ascii
+ $s2 = "This email will be as confirmation you are ready to pay for decryption key." fullword wide
+ $s3 = "Your important files are now encrypted due to a security problem with your PC!" fullword wide
+ $s4 = "write.php?info=" fullword wide
+ $s5 = " * Do not try to decrypt your data using third party software, it may cause permanent data loss." fullword wide
+ $s6 = " * Do not rename encrypted files." fullword wide
+ $s7 = ".compositiontemplate" fullword wide
+ $s8 = "You have to pay for decryption in Bitcoins. The price depends on how fast you write to us." fullword wide
+ $s9 = "\\READ_IT.txt" fullword wide
+ $s10 = ".lastlogin" fullword wide
+ $s11 = ".logonxp" fullword wide
+ $s12 = " * Decryption of your files with the help of third parties may cause increased price" fullword wide
+ $s13 = "After payment we will send you the decryption tool that will decrypt all your files." fullword wide
condition:
- 7 of them and filesize <1097728
+ ( uint16(0)==0x5a4d and filesize <800KB) and all of them
}
-rule MALPEDIA_Win_Innaput_Rat_Auto : FILE
+rule TRELLIX_ARC_Ransom_Babuk : RANSOM T1027 T1083 T1057 T1082 T1129 T1490 T1543_003 FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "bdbf07bd-d4a4-5362-b354-c606ef8af022"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.innaput_rat"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.innaput_rat_auto.yar#L1-L115"
- license_url = "N/A"
- logic_hash = "f6067a2a0e56ef408d96b72de49c1461531d24eb998121258442401a90d43684"
+ description = "Rule to detect Babuk Locker"
+ author = "TS @ McAfee ATR"
+ id = "7c0a3b4e-90aa-5442-aa5e-1a7fcae9bec8"
+ date = "2021-01-19"
+ modified = "2021-02-24"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_BabukLocker_Jan2021.yar#L1-L25"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "e10713a4a5f635767dcd54d609bed977"
+ logic_hash = "123cebd1c2e66f3e91ee235cb9288df63dfaeba02e6df45f896cb50f38851a8f"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "RANSOM, T1027, T1083, T1057, T1082, T1129, T1490, T1543.003, FILE"
+ rule_version = "v2"
+ malware_family = "Ransom:Win/Babuk"
+ malware_type = "Ransom"
+ mitre_attack = "T1027, T1083, T1057, T1082, T1129, T1490, T1543.003"
strings:
- $sequence_0 = { e8???????? 59 85c0 7427 ffb720060000 }
- $sequence_1 = { ffd7 8b4510 898618060000 8b4514 8b00 }
- $sequence_2 = { 8b06 894710 ff7604 035e08 ff5708 56 ff5708 }
- $sequence_3 = { 8d7710 eb02 8b36 391e 75fa 6a0c }
- $sequence_4 = { 8945fc ff15???????? 33db 395f10 }
- $sequence_5 = { ff15???????? ffb718060000 ff15???????? 85c0 }
- $sequence_6 = { 8b460c 83f8ff 7404 3bc3 751b }
- $sequence_7 = { eb02 8b36 391e 75fa 6a0c ff5704 59 }
- $sequence_8 = { 83f8ff 7404 3bc3 751b }
- $sequence_9 = { b001 ebd3 55 8bec }
+ $s1 = {005C0048006F007700200054006F00200052006500730074006F0072006500200059006F00750072002000460069006C00650073002E007400780074}
+ $s2 = "delete shadows /all /quiet" fullword wide
+ $pattern1 = {006D656D74617300006D65706F63730000736F70686F730000766565616D0000006261636B7570000047785673730000004778426C7200000047784657440000004778435644000000477843494D67720044656657617463680000000063634576744D67720000000063635365744D677200000000536176526F616D005254567363616E0051424643536572766963650051424944505365727669636500000000496E747569742E517569636B426F6F6B732E46435300}
+ $pattern2 = {004163725363683253766300004163726F6E69734167656E74000000004341534144324457656253766300000043414152435570646174655376630000730071}
+ $pattern3 = {FFB0154000C78584FDFFFFB8154000C78588FDFFFFC0154000C7858CFDFFFFC8154000C78590FDFFFFD0154000C78594FDFFFFD8154000C78598FDFFFFE0154000C7859CFDFFFFE8154000C785A0FDFFFFF0154000C785A4FDFFFFF8154000C785A8FDFFFF00164000C785ACFDFFFF08164000C785B0FDFFFF10164000C785B4FDFFFF18164000C785B8FDFFFF20164000C785BCFDFFFF28164000C785C0FDFFFF30164000C785C4FDFFFF38164000C785C8FDFFFF40164000C785CCFDFFFF48164000C785D0FDFFFF50164000C785D4FDFFFF581640}
+ $pattern4 = {400010104000181040002010400028104000301040003810400040104000481040005010400058104000601040006C10400078104000841040008C10400094104000A0104000B0104000C8104000DC104000E8104000F01040000011400008114000181140002411400038114000501140005C11400064114000741140008C114000A8114000C0114000E0114000F4114000101240002812400034124000441240005412400064124000741240008C124000A0124000B8124000D4124000EC1240000C1340002813400054134000741340008C134000A4134000C4134000E8134000FC134000141440003C144000501440006C144000881440009C144000B4144000CC144000E8144000FC144000141540003415400048154000601540007815}
condition:
- 7 of them and filesize <73728
+ filesize >=15KB and filesize <=90KB and 1 of ($s*) and 3 of ($pattern*)
}
-rule MALPEDIA_Win_Bruh_Wiper_Auto : FILE
-{
- meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "8004678f-c7f1-56db-b368-30e9334ba4b0"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bruh_wiper"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.bruh_wiper_auto.yar#L1-L119"
- license_url = "N/A"
- logic_hash = "26b32a2c0d923fc99fb91e4beb18e36e72d9c523fef8bdb0bb63ddd5fd11ff5a"
+import "pe"
+
+rule TRELLIX_ARC_Sodinokobi : RANSOMWARE
+{
+ meta:
+ description = "This rule detect Sodinokobi Ransomware in memory in old samples and perhaps future."
+ author = "McAfee ATR team"
+ id = "dd05ce31-9699-50a9-944c-5883340791af"
+ date = "2024-09-01"
+ modified = "2020-08-14"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_Sodinokibi.yar#L33-L54"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "f25039ac743223756461bbeeb349c674473608f9959bf3c79ce4a7587fde3ab2"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "RANSOMWARE"
+ malware_type = "ransomware"
+ malware_family = "Ransom:W32/Sodinokibi"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
+ version = "1.0"
strings:
- $sequence_0 = { e8???????? 83c40c be01080000 0f1f8000000000 }
- $sequence_1 = { 83ee01 75e3 8b4dfc 5f 5e }
- $sequence_2 = { 8d45f4 57 50 ff15???????? ff15???????? }
- $sequence_3 = { 68b40200c0 ffd6 8b4dfc 5f 33cd 5e }
- $sequence_4 = { 6a00 8d85f8fdffff 50 6800020000 8d85fcfdffff 50 }
- $sequence_5 = { 68???????? 57 ffd3 6800020000 8d85fcfdffff 6a00 }
- $sequence_6 = { 50 ffd6 8bf0 8d45fb 50 6a00 6a01 }
- $sequence_7 = { 6800200000 68???????? 57 ffd3 6800020000 8d85fcfdffff }
- $sequence_8 = { e8???????? 83c40c be01080000 0f1f8000000000 6a00 }
- $sequence_9 = { 50 ffd6 68???????? 68???????? 8bf8 }
+ $a = { 40 0F B6 C8 89 4D FC 8A 94 0D FC FE FF FF 0F B6 C2 03 C6 0F B6 F0 8A 84 35 FC FE FF FF 88 84 0D FC FE FF FF 88 94 35 FC FE FF FF 0F B6 8C 0D FC FE FF FF }
+ $b = { 0F B6 C2 03 C8 8B 45 14 0F B6 C9 8A 8C 0D FC FE FF FF 32 0C 07 88 08 40 89 45 14 8B 45 FC 83 EB 01 75 AA }
condition:
- 7 of them and filesize <65536
+ all of them
}
-rule MALPEDIA_Win_Remcos_Auto : FILE
+rule TRELLIX_ARC_Ransom_Monglock : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "0b71eaff-61b4-55ab-a8af-3cf13e03dd61"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.remcos_auto.yar#L1-L113"
- license_url = "N/A"
- logic_hash = "d80be2f75bdd44294476100f6767031142d9f2872cceaebec5f1ed9745e8779f"
+ description = "Ransomware encrypting Mongo Databases "
+ author = "Christiaan Beek - McAfee ATR team"
+ id = "4350a874-dd76-5379-af9f-f1d190385706"
+ date = "2019-04-25"
+ modified = "2020-08-14"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_MONGOLOCK.yar#L1-L41"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "245a7377a410828ed8bc7148f36af6d143ad20d16840238ed5b6d6f94f015984"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "RANSOMWARE, FILE"
+ rule_version = "v1"
+ malware_type = "ransomware"
+ malware_family = "Ransom:W32/MongLock"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
+ hash5 = "c4de2d485ec862b308d00face6b98a7801ce4329a8fc10c63cf695af537194a8"
strings:
- $sequence_0 = { 7410 6a00 ff35???????? ff15???????? }
- $sequence_1 = { 50 ff15???????? 8d45f0 33f6 }
- $sequence_2 = { 6a09 ff35???????? ff15???????? ff35???????? ff15???????? }
- $sequence_3 = { 8d45f8 50 ff15???????? ff7508 }
- $sequence_4 = { 7508 ff15???????? 33c0 5f }
- $sequence_5 = { 6a09 ff35???????? ff15???????? ff35???????? }
- $sequence_6 = { ff15???????? 50 ff15???????? 8d45f0 33f6 }
- $sequence_7 = { 50 6a28 ff15???????? 50 ff15???????? 8d45f0 33f6 }
- $sequence_8 = { 51 51 8d45f8 c745f808000000 50 ff15???????? ff15???????? }
- $sequence_9 = { 85c0 7410 6a00 ff35???????? ff15???????? }
+ $x1 = "C:\\Windows\\system32\\cmd.exe" fullword wide
+ $s1 = "and a Proof of Payment together will be ignored. We will drop the backup after 24 hours. You are welcome! " fullword ascii
+ $s2 = "Your File and DataBase is downloaded and backed up on our secured servers. To recover your lost data : Send 0.1 BTC to our BitCoin" ascii
+ $s3 = "No valid port number in connect to host string (%s)" fullword ascii
+ $s4 = "SOCKS4%s: connecting to HTTP proxy %s port %d" fullword ascii
+ $s5 = "# https://curl.haxx.se/docs/http-cookies.html" fullword ascii
+ $s6 = "Connection closure while negotiating auth (HTTP 1.0?)" fullword ascii
+ $s7 = "detail may be available in the Windows System event log." fullword ascii
+ $s8 = "Found bundle for host %s: %p [%s]" fullword ascii
+ $s9 = "No valid port number in proxy string (%s)" fullword ascii
+ $op0 = { 50 8d 85 78 f6 ff ff 50 ff b5 70 f6 ff ff ff 15 }
+ $op1 = { 83 fb 01 75 45 83 7e 14 08 72 34 8b 0e 66 8b 45 }
+ $op2 = { c7 41 0c df ff ff ff c7 41 10 }
condition:
- 7 of them and filesize <1054720
+ ( uint16(0)==0x5a4d and filesize <2000KB and (1 of ($x*) and 4 of them ) and all of ($op*)) or ( all of them )
}
-rule MALPEDIA_Win_Appleseed_Auto : FILE
+rule TRELLIX_ARC_Ransom_Win_Blackcat : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5111027d-aef3-530a-baef-816a96e705d5"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.appleseed"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.appleseed_auto.yar#L1-L131"
- license_url = "N/A"
- logic_hash = "a810d449fba9d18767008ae79deb61edb7dc0a7b0fedfb1cf50aff52e06540b9"
+ description = "Detecting variants of Windows BlackCat malware"
+ author = " Trellix ATR"
+ id = "65483ffb-6b10-5fd5-8a5f-fc885a5f2e98"
+ date = "2022-01-06"
+ modified = "2022-01-19"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/Ransom_Win_BlackCat_public.yar#L2-L24"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "8faad28ab26690221f6e2130c886446615dbd505f76490cfaf999d130d0de6e3"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "RANSOMWARE, FILE"
+ malware_type = "Ransomware"
+ detection_name = "Ransom_Win_BlackCat"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 448bc6 442bc0 488b442450 488d0d65d30100 488b0cc1 4c8d4c244c 488d9520060000 }
- $sequence_1 = { 4c89b590000000 c6858000000000 4883bde000000010 720c 488b8dc8000000 e8???????? 8bc7 }
- $sequence_2 = { 90 488d4db8 e8???????? 48833d????????00 0f84b10c0000 }
- $sequence_3 = { 488bcb ff15???????? ff15???????? 33ff 8bf0 0f1f8000000000 ff15???????? }
- $sequence_4 = { 90 488d4db8 e8???????? 48833d????????00 0f84c0040000 488d157e170200 488d4db8 }
- $sequence_5 = { 488bce ff15???????? 4885c0 7411 83caff 488bc8 }
- $sequence_6 = { e9???????? 488d8af0000000 e9???????? 488b8a60000000 e9???????? 488d8a10010000 e9???????? }
- $sequence_7 = { 0f8490000000 85db 0f8488000000 41880f 4b8b84e900670300 4183caff 4103da }
- $sequence_8 = { 48ffc7 803c3a00 75f7 488d4c2450 4c8bc7 e8???????? 488d4c2450 }
- $sequence_9 = { 48895dc8 c645b800 41b838000000 488d15b81d0200 488d4db8 e8???????? 90 }
+ $URL1 = "zujgzbu5y64xbmvc42addp4lxkoosb4tslf5mehnh7pvqjpwxn5gokyd.onion" ascii wide
+ $URL2 = "mu75ltv3lxd24dbyu6gtvmnwybecigs5auki7fces437xvvflzva2nqd.onion" ascii wide
+ $API = { 3a 7c d8 3f }
condition:
- 7 of them and filesize <497664
+ uint16(0)==0x5a4d and filesize <3500KB and 1 of ($URL*) and $API
}
-rule MALPEDIA_Win_Tonedeaf_Auto : FILE
+rule TRELLIX_ARC_Screenlocker_Acroware : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5115d077-589f-5849-9e66-466eacfeb8fa"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tonedeaf"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.tonedeaf_auto.yar#L1-L120"
- license_url = "N/A"
- logic_hash = "05f38897859076fdc96710dcc7b02a4e168a1e7a497536a51feb5fc01846d4dd"
+ description = "Rule to detect the ScreenLocker Acroware"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "76eb69eb-dfe7-5629-bf2d-d20574efd662"
+ date = "2018-08-28"
+ modified = "2020-08-14"
+ reference = "https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-august-31st-2018-devs-on-vacation/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_acroware.yar#L1-L29"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "f9efcfc5328e6502cbbbff752a940ac221e437d8732052fc265618f6a6ad72ae"
+ logic_hash = "582f3544cf1f8066b1e9ac04c3a4cc9f0ba96804ca53bc3746b433df9c33e0a1"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "RANSOMWARE, FILE"
+ rule_version = "v1"
+ malware_type = "ransomware"
+ malware_family = "Ransom:W32/Acroware"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { ff15???????? 56 ff15???????? 56 ff15???????? 56 e8???????? }
- $sequence_1 = { 2bf1 8bc3 46 d1e8 }
- $sequence_2 = { 8bc3 46 d1e8 33d2 }
- $sequence_3 = { 8b45ec 85c0 740b 6a08 50 }
- $sequence_4 = { 884c32ff 84c9 75f3 8bf3 8a03 43 84c0 }
- $sequence_5 = { 8b5004 8d4af8 898c153cffffff 8d45a8 c745fc01000000 50 }
- $sequence_6 = { 56 6a00 ff15???????? 56 ff15???????? 56 ff15???????? }
- $sequence_7 = { 83f801 732f 8b0f 8bc1 }
- $sequence_8 = { 0f57c0 c745dc00000000 33c0 660fd645d4 33db 8945d8 }
- $sequence_9 = { 75f3 8bf3 8a03 43 84c0 75f9 }
+ $s1 = "C:\\Users\\patri\\Documents\\Visual Studio 2015\\Projects\\Advanced Ransi\\Advanced Ransi\\obj\\Debug\\Advanced Ransi.pdb" fullword ascii
+ $s2 = "All your Personal Data got encrypted and the decryption key is stored on a hidden" fullword ascii
+ $s3 = "alphaoil@mail2tor.com any try of removing this Ransomware will result in an instantly " fullword ascii
+ $s4 = "HKEY_CURRENT_USER\\SoftwareE\\Microsoft\\Windows\\CurrentVersion\\Run" fullword wide
+ $s5 = "webserver, after 72 hours thedecryption key will get removed and your personal" fullword ascii
condition:
- 7 of them and filesize <851968
+ ( uint16(0)==0x5a4d and filesize <2000KB) and all of them
}
-rule MALPEDIA_Win_Xbot_Pos_Auto : FILE
+rule TRELLIX_ARC_Installer_Coronavirus : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "4fe5918d-28da-56d9-a11a-0daee8e0859e"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xbot_pos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.xbot_pos_auto.yar#L1-L128"
- license_url = "N/A"
- logic_hash = "ca7b720c096face03c032566840e8484d5e37cc5bc6f6baf53fbffd9b36ce27d"
+ description = "Rule to detect the Corona Virus Installer"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "2a224529-bfc7-57ed-91c3-426cae4b7895"
+ date = "2020-03-25"
+ modified = "2020-08-14"
+ reference = "https://twitter.com/malwrhunterteam/status/1238056503493505024"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_coronavirus.yar#L1-L41"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "5987a6e42c3412086b7c9067dc25f1aaa659b2b123581899e9df92cb7907a3ed"
+ logic_hash = "26be8bbfbf615967cc2a0e2d4179cd5f444c53f170a681d2ec236244881dc629"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 62
+ tags = "RANSOMWARE, FILE"
+ rule_version = "v1"
+ malware_type = "ransomware"
+ malware_family = "Ransom:W32/CoronaVirus"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 8b8d50fcffff 8d148d34935500 899558fcffff 8d8d2cfeffff e8???????? 8b8558fcffff 0fb64803 }
- $sequence_1 = { 46 4c 002c46 4c }
- $sequence_2 = { 83e23f 6bc230 8b0c8de0465600 8b540118 8955f4 837df4ff 7412 }
- $sequence_3 = { 8d8d74fcffff e8???????? eb1f 6a00 8d8560fcffff 50 8d8decfeffff }
- $sequence_4 = { 8b4d08 51 8b4df8 e8???????? 8bf0 8b4df8 }
- $sequence_5 = { 837d1800 740c c785d8deffffe8905400 eb0a c785d8deffff88905400 8b85a8deffff 50 }
- $sequence_6 = { f3ab 0fb64508 85c0 741b 837d0c00 7515 8b4514 }
- $sequence_7 = { 8b00 50 8b4df8 e8???????? 8b08 51 8b4df8 }
- $sequence_8 = { 85db 7552 68???????? 68???????? 56 6a41 68???????? }
- $sequence_9 = { 8b4508 8b0c853c255600 51 ff15???????? 8b5508 }
+ $s1 = { 61 63 68 65 6C 6C 69 65 73 40 68 6F 74 6D 61 69 6C 2E 63 6F 6D }
+ $s2 = { 74 6F 6A 65 6E 2E 6D 65 40 67 6D 61 69 6C 2E 63 6F 6D }
+ $s4 = { 77 61 6E 67 63 68 79 7A 40 67 6D 61 69 6C 2E 63 6F 6D }
+ $s5 = { 54 00 6F 00 64 00 6F 00 73 00 20 00 6C 00 6F 00 73 00 20 00 74 00 69 00 70 00 6F 00 73 00 20 00 64 00 65 00 20 00 69 00 6D 00 61 00 67 00 65 00 6E 00 7C 00 2A 00 2E 00 62 00 6D 00 70 00 3B 00 2A 00 2E 00 63 00 75 00 72 00 3B 00 2A 00 2E 00 64 00 69 00 62 00 3B 00 2A 00 2E 00 65 00 6D 00 66 00 3B 00 2A 00 2E 00 69 00 63 00 6F 00 3B 00 2A 00 2E 00 77 00 6D 00 66 00 7C 00 4D 00 61 00 70 00 61 00 73 00 20 00 64 00 65 00 20 00 62 00 69 00 74 00 73 00 20 00 28 00 2A 00 2E 00 62 00 6D 00 70 00 3B 00 2A 00 2E 00 64 00 69 00 62 00 29 00 7C 00 2A 00 2E 00 62 00 6D 00 70 00 3B 00 2A 00 2E 00 64 00 69 00 62 00 7C 00 49 00 63 00 6F 00 6E 00 6F 00 73 00 2F 00 63 00 75 00 72 00 73 00 6F 00 72 00 65 00 73 00 20 00 28 00 2A 00 2E 00 69 00 63 00 6F 00 3B 00 2A 00 2E 00 63 00 75 00 72 00 29 00 7C 00 2A 00 2E 00 69 00 63 00 6F 00 3B 00 2A 00 2E 00 63 00 75 00 72 00 7C 00 4D 00 65 00 74 00 61 00 61 00 72 00 63 00 68 00 69 00 76 00 6F 00 73 00 20 00 28 00 2A 00 2E 00 77 00 6D 00 66 00 3B 00 2A 00 2E 00 65 00 6D 00 66 00 29 00 7C 00 2A 00 2E 00 77 00 6D 00 66 00 3B 00 2A 00 2E 00 65 00 6D 00 66 00 7C 00 54 00 6F 00 64 00 6F 00 73 00 20 00 6C 00 6F 00 73 00 20 00 61 00 72 00 63 00 68 00 69 00 76 00 6F 00 73 00 20 00 28 00 2A 00 2E 00 2A 00 29 00 7C 00 2A 00 2E 00 2A 00 7C 00 7C 00 }
+ $s6 = { 48 00 54 00 4D 00 4C 00 5F 00 49 00 4D 00 47 00 23 00 49 00 44 00 52 00 5F 00 48 00 54 00 4D 00 5F 00 49 00 4D 00 41 00 47 00 45 00 53 00 5F 00 4C 00 49 00 5F 00 43 00 41 00 50 00 54 00 49 00 4F 00 4E 00 5F 00 48 00 4F 00 56 00 45 00 52 00 5F 00 50 00 4E 00 47 00 29 00 49 00 44 00 52 00 5F 00 48 00 54 00 4D 00 5F 00 49 00 4D 00 41 00 47 00 45 00 53 00 5F 00 53 00 42 00 5F 00 48 00 5F 00 53 00 43 00 52 00 4F 00 4C 00 4C 00 5F 00 50 00 52 00 45 00 56 00 5F 00 48 00 4F 00 56 00 45 00 52 00 5F 00 50 00 4E 00 47 00 31 00 49 00 44 00 52 00 5F 00 48 00 54 00 4D 00 5F 00 49 00 4D 00 47 00 5F 00 50 00 41 00 47 00 45 00 5F 00 54 00 49 00 54 00 4C 00 45 00 5F 00 49 00 43 00 4F 00 4E 00 5F 00 4D 00 45 00 4E 00 55 00 5F 00 4F 00 52 00 41 00 4E 00 47 00 45 00 5F 00 43 00 4C 00 4F 00 53 00 45 00 5F 00 50 00 4E 00 47 00 32 00 49 00 44 00 52 00 5F 00 48 00 54 00 4D 00 5F 00 49 00 4D 00 47 00 5F 00 50 00 41 00 47 00 45 00 5F 00 54 00 49 00 54 00 4C 00 45 00 5F 00 49 00 43 00 4F 00 4E 00 5F 00 4D 00 45 00 4E 00 55 00 5F 00 50 00 41 00 49 00 44 00 5F 00 53 00 45 00 54 00 54 00 49 00 4E 00 47 00 53 00 5F 00 50 00 4E 00 47 00 }
+ $s7 = { 25 73 5C 6C 6F 67 5F 25 30 34 64 25 30 32 64 25 30 32 64 5F 25 64 2E 6C 6F 67 }
condition:
- 7 of them and filesize <3031040
+ uint16(0)==0x5a4d and filesize <3000KB and all of them
}
-rule MALPEDIA_Win_Brambul_Auto : FILE
+rule TRELLIX_ARC_Ransomware_Coronavirus : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "fb37501d-8a53-5cc7-864b-a2eff1ebf028"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.brambul"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.brambul_auto.yar#L1-L167"
- license_url = "N/A"
- logic_hash = "b2fcad7678e1145848466f51e53045ab3d4628142b8e9b03697218392aef0c7d"
+ description = "Rule to detect the Corona Virus ransomware"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "4195a57b-cd51-5050-861a-6436f7ec4eca"
+ date = "2020-03-25"
+ modified = "2020-08-14"
+ reference = "https://twitter.com/malwrhunterteam/status/1238056503493505024"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_coronavirus.yar#L43-L80"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "3299f07bc0711b3587fe8a1c6bf3ee6bcbc14cb775f64b28a61d72ebcb8968d3"
+ logic_hash = "2a7e1676a20f30b0cb0321579bb85e4836e2aee5f56b838d2ff2bec7a08c489f"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 64
+ tags = "RANSOMWARE, FILE"
+ rule_version = "v1"
+ malware_type = "ransomware"
+ malware_family = "Ransom:W32/CoronaVirus"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 66390a 750c 663908 8dbc5dc4000000 }
- $sequence_1 = { d3e0 48 234508 8d0440 }
- $sequence_2 = { 83f801 7269 6a08 6a40 ff15???????? 8b542414 }
- $sequence_3 = { 8bd9 33ee c1eb14 c1e10c }
- $sequence_4 = { c1e311 0bf3 8b5824 03f2 23ee 33e9 }
- $sequence_5 = { 6800400000 6a00 ff15???????? 50 ff15???????? 8bd8 }
- $sequence_6 = { 6a05 89b5b049ffff 58 8985a849ffff }
- $sequence_7 = { 25ffff0000 3bf8 7cc9 8bc6 5f 5e 5d }
- $sequence_8 = { 8d54242c c1e902 f3a5 8bc8 8d442470 }
- $sequence_9 = { 68???????? ff15???????? 83c408 b804000000 5f 5e 5d }
- $sequence_10 = { 8b8c2480010000 89942418010000 8984241c010000 8d942418010000 51 8d84245c010000 }
- $sequence_11 = { 8d45e8 50 8bf3 8d85be49ffff 83e31f 83a5b85dffff00 }
- $sequence_12 = { 89b404bc000000 83c004 83f840 7cd0 b910000000 }
- $sequence_13 = { 8d7c2420 f3ab 8d442424 50 56 53 }
- $sequence_14 = { 50 e8???????? 83f8ff 7517 8d4c2410 }
- $sequence_15 = { c3 8b442404 c74050f0864000 c7401401000000 }
+ $s1 = { 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 25 73 }
+ $s2 = { 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 00 }
+ $s3 = { 2F 00 75 00 70 00 6C 00 6F 00 61 00 64 00 2F 00 25 00 73 00 5F 00 25 00 64 00 5F 00 25 00 73 00 }
+ $s4 = { 53 59 53 54 45 4D 5C 43 75 72 72 65 6E 74 43 6F 6E 74 72 6F 6C 53 65 74 5C 43 6F 6E 74 72 6F 6C 5C 53 65 73 73 69 6F 6E 20 4D 61 6E 61 67 65 72 }
+ $s5 = { 5C 5C 2E 5C 50 68 79 73 69 63 61 6C 44 72 69 76 65 25 64 }
condition:
- 7 of them and filesize <188416
+ uint16(0)==0x5a4d and filesize <100KB and all of them
}
-rule MALPEDIA_Win_Windealer_Auto : FILE
+import "pe"
+
+rule TRELLIX_ARC_Ragnarlocker_Ransomware : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "f3b71a3e-a02a-5dce-bc43-cb374750ce4e"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.windealer"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.windealer_auto.yar#L1-L113"
- license_url = "N/A"
- logic_hash = "d82b81175389182c804642799536612f0047302d818841ec0b2b4fd9f2036f88"
+ description = "Rule to detect RagnarLocker samples"
+ author = "McAfee ATR Team"
+ id = "58874f27-3070-52c9-bd96-337fdaa4499b"
+ date = "2020-04-15"
+ modified = "2020-10-12"
+ reference = "https://www.bleepingcomputer.com/news/security/ragnar-locker-ransomware-targets-msp-enterprise-support-tools/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_ragnarlocker.yar#L3-L45"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ hash = "9706a97ffa43a0258571def8912dc2b8bf1ee207676052ad1b9c16ca9953fc2c"
+ logic_hash = "2f31da9182a1b47fb1e7e4459461de4c496ec323ff13e622d3ce27ac8cce1912"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 68
+ tags = "RANSOMWARE, FILE"
+ rule_version = "v1"
+ malware_type = "ransomware"
+ malware_family = "Ransom:W32/RagnarLocker"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 50 56 e8???????? 83c410 8b4618 }
- $sequence_1 = { 6a00 ff15???????? 85c0 7407 50 ff15???????? 6a01 }
- $sequence_2 = { 6a04 50 6a04 68???????? 68???????? }
- $sequence_3 = { 50 56 e8???????? 83c410 8b4610 }
- $sequence_4 = { 53 56 57 68da070000 }
- $sequence_5 = { 56 57 68da070000 e8???????? }
- $sequence_6 = { 56 e8???????? 83c410 8b4610 }
- $sequence_7 = { 6a01 50 56 e8???????? 83c410 8bc7 }
- $sequence_8 = { 668b91d2070000 8a89d0070000 52 51 }
- $sequence_9 = { 8b4d08 668b91d2070000 8a89d0070000 52 51 }
+ $s1 = {2D 2D 2D 52 41 47 4E 41 52 20 53 45 43 52 45 54 2D 2D 2D}
+ $s2 = { 66 ?? ?? ?? ?? ?? ?? 66 ?? ?? ?? B8 ?? ?? ?? ?? 0F 44 }
+ $s3 = { 5? 8B ?? 5? 5? 8B ?? ?? 8B ?? 85 ?? 0F 84 }
+ $s4 = { FF 1? ?? ?? ?? ?? 3D ?? ?? ?? ?? 0F 85 }
+ $s5 = { 8D ?? ?? ?? ?? ?? 5? FF 7? ?? E8 ?? ?? ?? ?? 85 ?? 0F 85 }
+ $op1 = { 0f 11 85 70 ff ff ff 8b b5 74 ff ff ff 0f 10 41 }
+ $p0 = { 72 eb fe ff 55 8b ec 81 ec 00 01 00 00 53 56 57 }
+ $p1 = { 60 be 00 00 41 00 8d be 00 10 ff ff 57 eb 0b 90 }
+ $bp0 = { e8 b7 d2 ff ff ff b6 84 }
+ $bp1 = { c7 85 7c ff ff ff 24 d2 00 00 8b 8d 7c ff ff ff }
+ $bp2 = { 8d 85 7c ff ff ff 89 85 64 ff ff ff 8d 4d 84 89 }
condition:
- 7 of them and filesize <770048
+ uint16(0)==0x5a4d and filesize <100KB and (4 of ($s*) and $op1) or all of ($p*) and pe.imphash()=="9f611945f0fe0109fe728f39aad47024" or all of ($bp*) and pe.imphash()=="489a2424d7a14a26bfcfb006de3cd226"
}
-rule MALPEDIA_Win_Threebyte_Auto : FILE
+rule TRELLIX_ARC_RANSOM_Mountlocker : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "ce3faee0-35b6-5807-9d64-6a9a343be0ab"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.threebyte"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.threebyte_auto.yar#L1-L127"
- license_url = "N/A"
- logic_hash = "ea76c04ceecd329a1dbc8646fe87d0982e2f7a41db170c209ba00ee2ed2e0d90"
+ description = "Rule to detect Mount Locker ransomware"
+ author = "McAfee ATR Team"
+ id = "8451b78c-3cef-557a-a2e3-0767a0b0eddb"
+ date = "2020-09-25"
+ modified = "2020-10-12"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_mountlocker.yar#L1-L32"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "fb332a6725b9276cca379dd3621943c69f88570fb317da27a857a2544d2aa4e0"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 64
+ tags = "RANSOMWARE, FILE"
+ rule_version = "v1"
+ malware_type = "ransomware"
+ malware_family = "Ransomware:W32/MountLocker"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
+ hash1 = "4b917b60f4df6d6d08e895d179a22dcb7c38c6a6a6f39c96c3ded10368d86273"
+ hash2 = "f570d5b17671e6f3e56eae6ad87be3a6bbfac46c677e478618afd9f59bf35963"
strings:
- $sequence_0 = { 85c0 0f8511010000 c68514ffffff5b c68515ffffff3e c68516ffffff3e c68517ffffff20 }
- $sequence_1 = { 8a8415fcfeffff 88840dfcfeffff 8b8df0feffff 8a95f8feffff 88940dfcfeffff }
- $sequence_2 = { 6a00 8d4dbc 51 6801000080 ff15???????? 85c0 7407 }
- $sequence_3 = { e8???????? 83c404 83c8ff eb44 8b8d24f7ffff 038d14f7ffff 898d24f7ffff }
- $sequence_4 = { 8b8d10f7ffff ff510c 8b9564f7ffff 52 8b8510f7ffff ff500c 8b4df4 }
- $sequence_5 = { 8d8d68f3ffff e8???????? e9???????? c78568f2ffff00000000 c645fc00 8d4df0 e8???????? }
- $sequence_6 = { 33c0 8dbddefcffff f3ab 66ab c78594faffff00010000 8d9594faffff 52 }
- $sequence_7 = { 8b4d10 894df8 c745ec00000000 eb09 8b55ec }
- $sequence_8 = { e8???????? 8985a8fbffff 668b15???????? 668995ecfbffff b9ff000000 }
- $sequence_9 = { e8???????? 83c404 e9???????? c7459801010000 8b9564ffffff 8955a4 8b45ec }
+ $s1 = {63 69 64 3d 25 43 4c 49 45 4e 54 5f 49 44}
+ $s2 = {7a 73 61 33 77 78 76 62 62 37 67 76 36 35 77 6e 6c 37 6c 65 72 73 6c 65 65 33 63 37 69 32 37 6e 64 71 67 68 71 6d 36 6a 74 32 70 72 69 76 61 32 71 63 64 70 6f 6e 61 64 2e 6f 6e 69 6f 6e}
+ $s3 = {36 6d 6c 7a 61 68 6b 63 37 76 65 6a 79 74 70 70 62 71 68 71 6a 6f 75 34 69 70 66 74 67 73 33 67 69 7a 6f 66 32 78 34 7a 6b 6c 62 6c 6c 69 61 79 68 73 71 62 33 77 61 64 2e 6f 6e 69 6f 6e}
condition:
- 7 of them and filesize <180224
+ uint16(0)==0x5a4d and filesize <300KB and ($s1 and $s2) or ($s1 and $s3) or $s1
}
-rule MALPEDIA_Win_Jripbot_Auto : FILE
+rule TRELLIX_ARC_Cryptonar_Ransomware : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "7b1d247f-7cbb-5615-a25c-7a029e86230e"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jripbot"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.jripbot_auto.yar#L1-L133"
- license_url = "N/A"
- logic_hash = "e485f4c42ec7ab7e0d2df3f1cd3bb910f7710773a4391061675b3c77a4acf337"
+ description = "Rule to detect CryptoNar Ransomware"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "0911250f-fc1f-58bc-ac09-d77d2a2ed3ce"
+ date = "2024-09-01"
+ modified = "2020-08-14"
+ reference = "https://www.bleepingcomputer.com/news/security/cryptonar-ransomware-discovered-and-quickly-decrypted/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_CryptoNar.yar#L1-L36"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "04c1c4f45ad3552aa0876c3b645c6ca92493018f7fdc5d9d9ed26cf67199d21b"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "RANSOMWARE, FILE"
+ malware_type = "ransomware"
+ malware_family = "Ransom:W32/CryptoNar"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 48 3b442418 0f822bffffff 8b8c24fc010000 5f 5e 5b }
- $sequence_1 = { c1e807 8807 02d2 885701 66c7060100 33c9 837b0401 }
- $sequence_2 = { 8b5d08 c1eb08 23d8 0fb69b38834200 c1e608 33f3 8b5d0c }
- $sequence_3 = { 8d742414 e8???????? 59 59 eb06 895c240c 33c0 }
- $sequence_4 = { 33c0 8b8eb8000000 3bc7 0f95c0 6a02 884105 33db }
- $sequence_5 = { 51 50 56 56 ff750c ff75fc ffd7 }
- $sequence_6 = { 50 e8???????? 8b1d???????? 83c40c 8d442438 50 ff15???????? }
- $sequence_7 = { 8b4004 894604 33c0 8b8c242c010000 5f 5e 5b }
- $sequence_8 = { eb04 8b442430 8b4c241c 2b4c2418 ff742418 8b5c2438 }
- $sequence_9 = { 7443 3bf8 743f 8b4368 397008 7537 8b4df4 }
+ $s1 = "C:\\narnar\\CryptoNar\\CryptoNarDecryptor\\obj\\Debug\\CryptoNar.pdb" fullword ascii
+ $s2 = "CryptoNarDecryptor.exe" fullword wide
+ $s3 = "server will eliminate the key after 72 hours since its generation (since the moment your computer was infected). Once this has " fullword ascii
+ $s4 = "Do not delete this file, else the decryption process will be broken" fullword wide
+ $s5 = "key you received, and wait until the decryption process is done." fullword ascii
+ $s6 = "In order to receive your decryption key, you will have to pay $200 in bitcoins to this bitcoin address: [bitcoin address]" fullword ascii
+ $s7 = "Decryption process failed" fullword wide
+ $s8 = "CryptoNarDecryptor.KeyValidationWindow.resources" fullword ascii
+ $s9 = "Important note: Removing CryptoNar will not restore access to your encrypted files." fullword ascii
+ $s10 = "johnsmith987654@tutanota.com" fullword wide
+ $s11 = "Decryption process will start soon" fullword wide
+ $s12 = "CryptoNarDecryptor.DecryptionProgressBarForm.resources" fullword ascii
+ $s13 = "DecryptionProcessProgressBar" fullword wide
+ $s14 = "CryptoNarDecryptor.Properties.Resources.resources" fullword ascii
condition:
- 7 of them and filesize <507904
+ ( uint16(0)==0x5a4d and filesize <2000KB) and all of them
}
-rule MALPEDIA_Win_Grillmark_Auto : FILE
+rule TRELLIX_ARC_Bitpaymer_Ransomware : RANSOMWARE FILE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "891e7259-5469-58d4-a39e-a516f4f2c7d3"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grillmark"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.grillmark_auto.yar#L1-L127"
- license_url = "N/A"
- logic_hash = "fc8f047bb79d7c6ba82d87162ce46a1dc6555c1672864dfce07f64d88dd917ae"
+ description = "Rule to detect BitPaymer Ransomware"
+ author = "Marc Rivero | McAfee ATR Team"
+ id = "20b91cf2-2a84-55d9-8230-90d7b20a461f"
+ date = "2019-11-08"
+ modified = "2020-08-14"
+ reference = "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/spanish-mssp-targeted-by-bitpaymer-ransomware/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_Bitpaymer.yar#L1-L72"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "527cdbdf51e6f3f5d58e805cf4a1bc09c9d24880c2323046acef6ee03c92d62f"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 66
+ tags = "RANSOMWARE, FILE"
+ rule_version = "v1"
+ malware_type = "ransomware"
+ malware_family = "Ransom:W32/BitPaymer"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { 83bd44ffffff04 7705 bb???????? 83bd44ffffff05 8b8548ffffff 7528 85c0 }
- $sequence_1 = { 5e 5d c21400 55 8bec 56 68???????? }
- $sequence_2 = { 59 7e13 50 57 6800000002 ff15???????? 8bd8 }
- $sequence_3 = { 7409 ff75fc ff15???????? 56 56 56 }
- $sequence_4 = { 66895dc4 50 c745c001010000 e8???????? ff7508 8d8590feffff 50 }
- $sequence_5 = { 6a09 ab 59 8d7dc0 8975bc 8975f8 }
- $sequence_6 = { 8dbdfdfeffff 889dfcfeffff 53 f3ab 66ab aa 8d85fcfeffff }
- $sequence_7 = { 8d85f8fdffff 50 750d ffd7 8d85f4fcffff 50 }
- $sequence_8 = { ff75f8 56 ff7508 ff75fc e8???????? 83c418 }
- $sequence_9 = { ffd6 85c0 7473 8d45c8 }
+ $s1 = "IEncrypt.dll" fullword wide
+ $op0 = { e8 5f f3 ff ff ff b6 e0 }
+ $op1 = { e8 ad e3 ff ff 59 59 8b 75 08 8d 34 f5 38 eb 42 }
+ $op2 = { e9 45 ff ff ff 33 ff 8b 75 0c 6a 04 e8 c1 d1 ff }
+ $pdb = "S:\\Work\\_bin\\Release-Win32\\wp_encrypt.pdb" fullword ascii
+ $oj0 = { 39 74 24 34 75 53 8d 4c 24 18 e8 b8 d1 ff ff ba }
+ $oj1 = { 5f 8b c6 5e c2 08 00 56 8b f1 8d 4e 34 e8 91 af }
+ $oj2 = { 8b cb 8d bd 50 ff ff ff 8b c1 89 5f 04 99 83 c1 }
+ $t1 = ".C:\\aaa_TouchMeNot_.txt" fullword wide
+ $ok0 = { e8 b5 34 00 00 ff 74 24 18 8d 4c 24 54 e8 80 39 }
+ $ok1 = { 8b 5d 04 33 ff 8b 44 24 34 89 44 24 5c 85 db 7e }
+ $ok2 = { 55 55 ff 74 24 20 8d 4c 24 34 e8 31 bf 00 00 55 }
+ $random = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+" fullword ascii
+ $oi0 = { a1 04 30 ac 00 8b ce 0f af c2 03 c0 99 8b e8 89 }
+ $oi1 = { e8 64 a2 ff ff 85 c0 74 0c 8d 4d d8 51 ff 35 64 }
+ $oi2 = { c7 03 d4 21 ac 00 e8 86 53 00 00 89 73 10 89 7b }
+ $ou0 = { e8 64 a2 ff ff 85 c0 74 0c 8d 4d d8 51 ff 35 60 }
+ $ou1 = { a1 04 30 04 00 8b ce 0f af c2 03 c0 99 8b e8 89 }
+ $ou2 = { 8d 4c 24 10 e8 a0 da ff ff 68 d0 21 04 00 8d 4c }
+ $oa1 = { 56 52 ba 00 10 0c 00 8b f1 e8 28 63 00 00 8b c6 }
+ $oa2 = { 81 3d 50 30 0c 00 53 c6 d2 43 56 8b f1 75 23 ba }
+ $oy0 = { c7 06 cc 21 a6 00 c7 46 08 }
+ $oy1 = { c7 06 cc 21 a6 00 c7 46 08 }
+ $oy2 = { c7 06 cc 21 a6 00 c7 46 08 }
+ $oh1 = { e8 74 37 00 00 a3 00 30 fe 00 8d 4c 24 1c 8d 84 }
+ $oh2 = { 56 52 ba 00 10 fe 00 8b f1 e8 28 63 00 00 8b c6 }
condition:
- 7 of them and filesize <212992
+ ( uint16(0)==0x5a4d and filesize <1000KB) and ($s1 and all of ($op*)) or ($pdb and all of ($oj*)) or ($t1 and all of ($ok*)) or ($random and all of ($oi*)) or ($random and all of ($ou*)) or ($random and all of ($oa*) and $ou0) or ($random and all of ($oy*)) or ($random and all of ($oh*)) or ($random and $ou0) or ($random and $oi1)
}
-rule MALPEDIA_Win_Kelihos_Auto : FILE
+rule TRELLIX_ARC_Cryptolocker_Set1 : RANSOMWARE
{
meta:
- description = "autogenerated rule brought to you by yara-signator"
- author = "Felix Bilstein - yara-signator at cocacoding dot com"
- id = "5eeb2760-12b0-5f38-935d-d1f5e018b5d9"
- date = "2023-12-06"
- modified = "2023-12-08"
- reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kelihos"
- source_url = "https://github.com/malpedia/signator-rules//blob/fbacfc09b84d53d410385e66a8e56f25016c588a/rules/win.kelihos_auto.yar#L1-L134"
- license_url = "N/A"
- logic_hash = "0a57f5287680233f80bcd1391dc843be1b51717107a9ac1743ac21e2bb163525"
+ description = "Detection of Cryptolocker Samples"
+ author = "Christiaan Beek, Christiaan_Beek@McAfee.com"
+ id = "13ccc6d3-c2cc-59ac-81af-ec11fb78cd41"
+ date = "2014-04-13"
+ modified = "2020-08-14"
+ reference = "https://github.com/advanced-threat-research/Yara-Rules/"
+ source_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/ransomware/RANSOM_Cryptolocker.yar#L1-L40"
+ license_url = "https://github.com/advanced-threat-research/Yara-Rules//blob/fc51a3fe3b450838614a5a5aa327c6bd8689cbb2/LICENSE"
+ logic_hash = "5be8d077537a59d860a972392be186d2697e55778f750d03b0fd3b0a73f714d9"
score = 75
- quality = 75
- tags = "FILE"
- version = "1"
- tool = "yara-signator v0.6.0"
- signator_config = "callsandjumps;datarefs;binvalue"
- malpedia_rule_date = "20231130"
- malpedia_hash = "fc8a0e9f343f6d6ded9e7df1a64dac0cc68d7351"
- malpedia_version = "20230808"
- malpedia_license = "CC BY-SA 4.0"
- malpedia_sharing = "TLP:WHITE"
+ quality = 70
+ tags = "RANSOMWARE"
+ rule_version = "v1"
+ malware_type = "ransomware"
+ malware_family = "Ransom:W32/Cryptolocker"
+ actor_type = "Cybercrime"
+ actor_group = "Unknown"
strings:
- $sequence_0 = { e8???????? 59 59 c644241701 84c0 7505 c644241700 }
- $sequence_1 = { ff7508 ff75fc ff7508 50 51 ff750c 56 }
- $sequence_2 = { e8???????? 6a00 6a01 8d4dc0 e8???????? 8a45ef e8???????? }
- $sequence_3 = { e8???????? b001 e8???????? c20800 6a18 b8???????? e8???????? }
- $sequence_4 = { e8???????? 83c40c 53 6a01 8d8ddcfdffff e8???????? 53 }
- $sequence_5 = { e8???????? c645fc02 807dd800 0f84f7000000 8b06 8b4004 03c6 }
- $sequence_6 = { ff75ac 8d7db8 895da8 e8???????? 83c40c 84c0 0f840b010000 }
- $sequence_7 = { 8b4d0c 8b5508 6a00 6a10 50 51 52 }
- $sequence_8 = { c3 6a10 b8???????? e8???????? 8b7d08 33db 53 }
- $sequence_9 = { e8???????? eb02 33c0 e8???????? c20400 83c1f8 8b01 }
+ $string0 = "static"
+ $string1 = " kscdS"
+ $string2 = "Romantic"
+ $string3 = "CompanyName" wide
+ $string4 = "ProductVersion" wide
+ $string5 = "9%9R9f9q9"
+ $string6 = "IDR_VERSION1" wide
+ $string7 = " "
+ $string8 = "LookFor" wide
+ $string9 = ":n;t;y;"
+ $string10 = "